[
  {
    "path": ".config/dotnet-tools.json",
    "content": "{\n  \"version\": 1,\n  \"isRoot\": true,\n  \"tools\": {\n    \"signclient\": {\n      \"version\": \"1.2.17\",\n      \"commands\": [\n        \"SignClient\"\n      ]\n    },\n    \"dotnet-ef\": {\n      \"version\": \"3.1.0\",\n      \"commands\": [\n        \"dotnet-ef\"\n      ]\n    }\n  }\n}"
  },
  {
    "path": ".editorconfig",
    "content": "root=true\n# Remove the line below if you want to inherit .editorconfig settings from higher directories\n\n# C# files\n[*.cs]\n\n#### Core EditorConfig Options ####\n\n# Indentation and spacing\nindent_size=4\nindent_style=space\ntab_width=4\n\n# New line preferences\nend_of_line=crlf\ninsert_final_newline=false\n\n#### .NET Coding Conventions ####\n\n# this. and Me. preferences\ndotnet_style_qualification_for_event=false:warning\ndotnet_style_qualification_for_field=false:warning\ndotnet_style_qualification_for_method=false:warning\ndotnet_style_qualification_for_property=false:warning\n\n# Language keywords vs BCL types preferences\ndotnet_style_predefined_type_for_locals_parameters_members=true:silent\ndotnet_style_predefined_type_for_member_access=true:silent\n\n# Parentheses preferences\ndotnet_style_parentheses_in_arithmetic_binary_operators=always_for_clarity:silent\ndotnet_style_parentheses_in_other_binary_operators=always_for_clarity:silent\ndotnet_style_parentheses_in_other_operators=never_if_unnecessary:silent\ndotnet_style_parentheses_in_relational_binary_operators=always_for_clarity:silent\n\n# Modifier preferences\ndotnet_style_require_accessibility_modifiers=for_non_interface_members:silent\n\n# Expression-level preferences\ncsharp_style_deconstructed_variable_declaration=true:suggestion\ncsharp_style_inlined_variable_declaration=true:suggestion\ncsharp_style_throw_expression=true:suggestion\ndotnet_style_coalesce_expression=true:suggestion\ndotnet_style_collection_initializer=true:suggestion\ndotnet_style_explicit_tuple_names=true:suggestion\ndotnet_style_null_propagation=true:suggestion\ndotnet_style_object_initializer=true:suggestion\ndotnet_style_prefer_auto_properties=true:silent\ndotnet_style_prefer_compound_assignment=true:suggestion\ndotnet_style_prefer_conditional_expression_over_assignment=true:silent\ndotnet_style_prefer_conditional_expression_over_return=true:silent\ndotnet_style_prefer_inferred_anonymous_type_member_names=true:suggestion\ndotnet_style_prefer_inferred_tuple_names=true:suggestion\ndotnet_style_prefer_is_null_check_over_reference_equality_method=true:suggestion\n\n# Field preferences\ndotnet_style_readonly_field=true:suggestion\n\n# Parameter preferences\ndotnet_code_quality_unused_parameters=all:suggestion\n\n#### C# Coding Conventions ####\n\n# var preferences\ncsharp_style_var_elsewhere=false:silent\ncsharp_style_var_for_built_in_types=false:silent\ncsharp_style_var_when_type_is_apparent=false:silent\n\n# Expression-bodied members\ncsharp_style_expression_bodied_accessors=true:silent\ncsharp_style_expression_bodied_constructors=false:silent\ncsharp_style_expression_bodied_indexers=true:silent\ncsharp_style_expression_bodied_lambdas=true:silent\ncsharp_style_expression_bodied_local_functions=false:silent\ncsharp_style_expression_bodied_methods=false:silent\ncsharp_style_expression_bodied_operators=false:silent\ncsharp_style_expression_bodied_properties=true:silent\n\n# Pattern matching preferences\ncsharp_style_pattern_matching_over_as_with_null_check=true:suggestion\ncsharp_style_pattern_matching_over_is_with_cast_check=true:suggestion\n\n# Null-checking preferences\ncsharp_style_conditional_delegate_call=true:suggestion\n\n# Modifier preferences\ncsharp_preferred_modifier_order=public,private,protected,internal,static,extern,new,virtual,abstract,sealed,override,readonly,unsafe,volatile,async\n\n# Code-block preferences\ncsharp_prefer_braces=true:silent\n\n# Expression-level preferences\ncsharp_prefer_simple_default_expression=true:suggestion\ncsharp_style_pattern_local_over_anonymous_function=true:suggestion\ncsharp_style_prefer_index_operator=true:suggestion\ncsharp_style_prefer_range_operator=true:suggestion\ncsharp_style_unused_value_assignment_preference=discard_variable:suggestion\ncsharp_style_unused_value_expression_statement_preference=discard_variable:silent\n\n#### C# Formatting Rules ####\n\n# New line preferences\ncsharp_new_line_before_catch=true\ncsharp_new_line_before_else=true\ncsharp_new_line_before_finally=true\ncsharp_new_line_before_members_in_anonymous_types=true\ncsharp_new_line_before_members_in_object_initializers=true\ncsharp_new_line_before_open_brace=all\ncsharp_new_line_between_query_expression_clauses=true\n\n# Indentation preferences\ncsharp_indent_block_contents=true\ncsharp_indent_braces=false\ncsharp_indent_case_contents=true\ncsharp_indent_case_contents_when_block=true\ncsharp_indent_labels=one_less_than_current\ncsharp_indent_switch_labels=true\n\n# Space preferences\ncsharp_space_after_cast=false\ncsharp_space_after_colon_in_inheritance_clause=true\ncsharp_space_after_comma=true\ncsharp_space_after_dot=false\ncsharp_space_after_keywords_in_control_flow_statements=true\ncsharp_space_after_semicolon_in_for_statement=true\ncsharp_space_around_binary_operators=before_and_after\ncsharp_space_around_declaration_statements=false\ncsharp_space_before_colon_in_inheritance_clause=true\ncsharp_space_before_comma=false\ncsharp_space_before_dot=false\ncsharp_space_before_open_square_brackets=false\ncsharp_space_before_semicolon_in_for_statement=false\ncsharp_space_between_empty_square_brackets=false\ncsharp_space_between_method_call_empty_parameter_list_parentheses=false\ncsharp_space_between_method_call_name_and_opening_parenthesis=false\ncsharp_space_between_method_call_parameter_list_parentheses=false\ncsharp_space_between_method_declaration_empty_parameter_list_parentheses=false\ncsharp_space_between_method_declaration_name_and_open_parenthesis=false\ncsharp_space_between_method_declaration_parameter_list_parentheses=false\ncsharp_space_between_parentheses=false\ncsharp_space_between_square_brackets=false\n\n# Wrapping preferences\ncsharp_preserve_single_line_blocks=true\ncsharp_preserve_single_line_statements=true\n\n\n[*]\ncharset=utf-8\nend_of_line=lf\ntrim_trailing_whitespace=false\ninsert_final_newline=false\nindent_style=space\nindent_size=4\n\n# Microsoft .NET properties\ncsharp_indent_braces=false\ncsharp_indent_switch_labels=true\ncsharp_new_line_before_catch=true\ncsharp_new_line_before_else=true\ncsharp_new_line_before_finally=true\ncsharp_new_line_before_members_in_object_initializers=false\ncsharp_new_line_before_open_brace=all\ncsharp_new_line_between_query_expression_clauses=true\ncsharp_preferred_modifier_order=public, private, protected, internal, new, abstract, virtual, sealed, override, static, readonly, extern, unsafe, volatile, async:suggestion\ncsharp_preserve_single_line_blocks=true\ncsharp_space_after_cast=true\ncsharp_space_after_colon_in_inheritance_clause=true\ncsharp_space_after_comma=true\ncsharp_space_after_dot=false\ncsharp_space_after_keywords_in_control_flow_statements=true\ncsharp_space_after_semicolon_in_for_statement=true\ncsharp_space_around_binary_operators=before_and_after\ncsharp_space_before_colon_in_inheritance_clause=true\ncsharp_space_before_comma=false\ncsharp_space_before_dot=false\ncsharp_space_before_open_square_brackets=false\ncsharp_space_before_semicolon_in_for_statement=false\ncsharp_space_between_empty_square_brackets=false\ncsharp_space_between_method_call_empty_parameter_list_parentheses=false\ncsharp_space_between_method_call_name_and_opening_parenthesis=false\ncsharp_space_between_method_call_parameter_list_parentheses=false\ncsharp_space_between_method_declaration_empty_parameter_list_parentheses=false\ncsharp_space_between_method_declaration_name_and_open_parenthesis=false\ncsharp_space_between_method_declaration_parameter_list_parentheses=false\ncsharp_space_between_parentheses=false\ncsharp_space_between_square_brackets=false\ncsharp_style_var_elsewhere=true:suggestion\ncsharp_style_var_for_built_in_types=true:suggestion\ncsharp_style_var_when_type_is_apparent=true:suggestion\ncsharp_using_directive_placement=outside_namespace:silent\ndotnet_naming_rule.constants_rule.severity=warning\ndotnet_naming_rule.constants_rule.style=upper_camel_case_style\ndotnet_naming_rule.constants_rule.symbols=constants_symbols\ndotnet_naming_rule.event_rule.severity=warning\ndotnet_naming_rule.event_rule.style=upper_camel_case_style\ndotnet_naming_rule.event_rule.symbols=event_symbols\ndotnet_naming_rule.interfaces_rule.severity=warning\ndotnet_naming_rule.interfaces_rule.style=i_upper_camel_case_style\ndotnet_naming_rule.interfaces_rule.symbols=interfaces_symbols\ndotnet_naming_rule.locals_rule.severity=warning\ndotnet_naming_rule.locals_rule.style=lower_camel_case_style_1\ndotnet_naming_rule.locals_rule.symbols=locals_symbols\ndotnet_naming_rule.local_constants_rule.severity=warning\ndotnet_naming_rule.local_constants_rule.style=lower_camel_case_style_1\ndotnet_naming_rule.local_constants_rule.symbols=local_constants_symbols\ndotnet_naming_rule.local_functions_rule.severity=warning\ndotnet_naming_rule.local_functions_rule.style=upper_camel_case_style\ndotnet_naming_rule.local_functions_rule.symbols=local_functions_symbols\ndotnet_naming_rule.method_rule.severity=warning\ndotnet_naming_rule.method_rule.style=upper_camel_case_style\ndotnet_naming_rule.method_rule.symbols=method_symbols\ndotnet_naming_rule.parameters_rule.severity=warning\ndotnet_naming_rule.parameters_rule.style=lower_camel_case_style_1\ndotnet_naming_rule.parameters_rule.symbols=parameters_symbols\ndotnet_naming_rule.private_constants_rule.severity=warning\ndotnet_naming_rule.private_constants_rule.style=upper_camel_case_style\ndotnet_naming_rule.private_constants_rule.symbols=private_constants_symbols\ndotnet_naming_rule.private_instance_fields_rule.severity=warning\ndotnet_naming_rule.private_instance_fields_rule.style=lower_camel_case_style\ndotnet_naming_rule.private_instance_fields_rule.symbols=private_instance_fields_symbols\ndotnet_naming_rule.private_static_fields_rule.severity=warning\ndotnet_naming_rule.private_static_fields_rule.style=lower_camel_case_style\ndotnet_naming_rule.private_static_fields_rule.symbols=private_static_fields_symbols\ndotnet_naming_rule.private_static_readonly_rule.severity=warning\ndotnet_naming_rule.private_static_readonly_rule.style=upper_camel_case_style\ndotnet_naming_rule.private_static_readonly_rule.symbols=private_static_readonly_symbols\ndotnet_naming_rule.property_rule.severity=warning\ndotnet_naming_rule.property_rule.style=upper_camel_case_style\ndotnet_naming_rule.property_rule.symbols=property_symbols\ndotnet_naming_rule.public_fields_rule.severity=warning\ndotnet_naming_rule.public_fields_rule.style=upper_camel_case_style\ndotnet_naming_rule.public_fields_rule.symbols=public_fields_symbols\ndotnet_naming_rule.static_readonly_rule.severity=warning\ndotnet_naming_rule.static_readonly_rule.style=upper_camel_case_style\ndotnet_naming_rule.static_readonly_rule.symbols=static_readonly_symbols\ndotnet_naming_rule.types_and_namespaces_rule.severity=warning\ndotnet_naming_rule.types_and_namespaces_rule.style=upper_camel_case_style\ndotnet_naming_rule.types_and_namespaces_rule.symbols=types_and_namespaces_symbols\ndotnet_naming_rule.type_parameters_rule.severity=warning\ndotnet_naming_rule.type_parameters_rule.style=t_upper_camel_case_style\ndotnet_naming_rule.type_parameters_rule.symbols=type_parameters_symbols\ndotnet_naming_style.i_upper_camel_case_style.capitalization=pascal_case\ndotnet_naming_style.i_upper_camel_case_style.required_prefix=I\ndotnet_naming_style.lower_camel_case_style.capitalization=camel_case\ndotnet_naming_style.lower_camel_case_style.required_prefix=_\ndotnet_naming_style.lower_camel_case_style_1.capitalization=camel_case\ndotnet_naming_style.t_upper_camel_case_style.capitalization=pascal_case\ndotnet_naming_style.t_upper_camel_case_style.required_prefix=T\ndotnet_naming_style.upper_camel_case_style.capitalization=pascal_case\ndotnet_naming_symbols.constants_symbols.applicable_accessibilities=public,internal,protected,protected_internal,private_protected\ndotnet_naming_symbols.constants_symbols.applicable_kinds=field\ndotnet_naming_symbols.constants_symbols.required_modifiers=const\ndotnet_naming_symbols.event_symbols.applicable_accessibilities=*\ndotnet_naming_symbols.event_symbols.applicable_kinds=event\ndotnet_naming_symbols.interfaces_symbols.applicable_accessibilities=*\ndotnet_naming_symbols.interfaces_symbols.applicable_kinds=interface\ndotnet_naming_symbols.locals_symbols.applicable_accessibilities=*\ndotnet_naming_symbols.locals_symbols.applicable_kinds=local\ndotnet_naming_symbols.local_constants_symbols.applicable_accessibilities=*\ndotnet_naming_symbols.local_constants_symbols.applicable_kinds=local\ndotnet_naming_symbols.local_constants_symbols.required_modifiers=const\ndotnet_naming_symbols.local_functions_symbols.applicable_accessibilities=*\ndotnet_naming_symbols.local_functions_symbols.applicable_kinds=local_function\ndotnet_naming_symbols.method_symbols.applicable_accessibilities=*\ndotnet_naming_symbols.method_symbols.applicable_kinds=method\ndotnet_naming_symbols.parameters_symbols.applicable_accessibilities=*\ndotnet_naming_symbols.parameters_symbols.applicable_kinds=parameter\ndotnet_naming_symbols.private_constants_symbols.applicable_accessibilities=private\ndotnet_naming_symbols.private_constants_symbols.applicable_kinds=field\ndotnet_naming_symbols.private_constants_symbols.required_modifiers=const\ndotnet_naming_symbols.private_instance_fields_symbols.applicable_accessibilities=private\ndotnet_naming_symbols.private_instance_fields_symbols.applicable_kinds=field\ndotnet_naming_symbols.private_static_fields_symbols.applicable_accessibilities=private\ndotnet_naming_symbols.private_static_fields_symbols.applicable_kinds=field\ndotnet_naming_symbols.private_static_fields_symbols.required_modifiers=static\ndotnet_naming_symbols.private_static_readonly_symbols.applicable_accessibilities=private\ndotnet_naming_symbols.private_static_readonly_symbols.applicable_kinds=field\ndotnet_naming_symbols.private_static_readonly_symbols.required_modifiers=static,readonly\ndotnet_naming_symbols.property_symbols.applicable_accessibilities=*\ndotnet_naming_symbols.property_symbols.applicable_kinds=property\ndotnet_naming_symbols.public_fields_symbols.applicable_accessibilities=public,internal,protected,protected_internal,private_protected\ndotnet_naming_symbols.public_fields_symbols.applicable_kinds=field\ndotnet_naming_symbols.static_readonly_symbols.applicable_accessibilities=public,internal,protected,protected_internal,private_protected\ndotnet_naming_symbols.static_readonly_symbols.applicable_kinds=field\ndotnet_naming_symbols.static_readonly_symbols.required_modifiers=static,readonly\ndotnet_naming_symbols.types_and_namespaces_symbols.applicable_accessibilities=*\ndotnet_naming_symbols.types_and_namespaces_symbols.applicable_kinds=namespace,class,struct,enum,delegate\ndotnet_naming_symbols.type_parameters_symbols.applicable_accessibilities=*\ndotnet_naming_symbols.type_parameters_symbols.applicable_kinds=type_parameter\ndotnet_style_parentheses_in_arithmetic_binary_operators=never_if_unnecessary:none\ndotnet_style_parentheses_in_other_binary_operators=never_if_unnecessary:none\ndotnet_style_parentheses_in_relational_binary_operators=never_if_unnecessary:none\ndotnet_style_predefined_type_for_locals_parameters_members=true:suggestion\ndotnet_style_predefined_type_for_member_access=true:suggestion\ndotnet_style_qualification_for_event=false:suggestion\ndotnet_style_qualification_for_field=false:suggestion\ndotnet_style_qualification_for_method=false:suggestion\ndotnet_style_qualification_for_property=false:suggestion\ndotnet_style_require_accessibility_modifiers=for_non_interface_members:suggestion\n\n# ReSharper properties\nresharper_accessor_owner_body=expression_body\nresharper_alignment_tab_fill_style=use_spaces\nresharper_align_first_arg_by_paren=false\nresharper_align_linq_query=false\nresharper_align_multiline_array_and_object_initializer=false\nresharper_align_multiline_array_initializer=true\nresharper_align_multiline_binary_expressions_chain=true\nresharper_align_multiline_calls_chain=false\nresharper_align_multiline_extends_list=false\nresharper_align_multiline_for_stmt=false\nresharper_align_multiline_implements_list=true\nresharper_align_multiline_switch_expression=false\nresharper_align_multline_type_parameter_constrains=false\nresharper_align_multline_type_parameter_list=false\nresharper_align_tuple_components=false\nresharper_allow_alias=true\nresharper_allow_comment_after_lbrace=false\nresharper_always_use_end_of_line_brace_style=false\nresharper_apply_auto_detected_rules=true\nresharper_apply_on_completion=false\nresharper_arguments_anonymous_function=positional\nresharper_arguments_literal=positional\nresharper_arguments_named=positional\nresharper_arguments_other=positional\nresharper_arguments_skip_single=false\nresharper_arguments_string_literal=positional\nresharper_attribute_style=do_not_touch\nresharper_autodetect_indent_settings=true\nresharper_blank_lines_after_block_statements=1\nresharper_blank_lines_after_case=0\nresharper_blank_lines_after_control_transfer_statements=0\nresharper_blank_lines_after_imports=1\nresharper_blank_lines_after_multiline_statements=0\nresharper_blank_lines_after_options=1\nresharper_blank_lines_after_start_comment=1\nresharper_blank_lines_after_using_list=1\nresharper_blank_lines_around_auto_property=1\nresharper_blank_lines_around_block_case_section=0\nresharper_blank_lines_around_field=1\nresharper_blank_lines_around_global_attribute=0\nresharper_blank_lines_around_invocable=1\nresharper_blank_lines_around_local_method=1\nresharper_blank_lines_around_multiline_case_section=0\nresharper_blank_lines_around_namespace=1\nresharper_blank_lines_around_property=1\nresharper_blank_lines_around_razor_functions=1\nresharper_blank_lines_around_razor_helpers=1\nresharper_blank_lines_around_razor_sections=1\nresharper_blank_lines_around_region=1\nresharper_blank_lines_around_single_line_auto_property=0\nresharper_blank_lines_around_single_line_field=0\nresharper_blank_lines_around_single_line_invocable=0\nresharper_blank_lines_around_single_line_local_method=0\nresharper_blank_lines_around_single_line_property=0\nresharper_blank_lines_around_type=1\nresharper_blank_lines_before_block_statements=0\nresharper_blank_lines_before_case=0\nresharper_blank_lines_before_control_transfer_statements=0\nresharper_blank_lines_before_multiline_statements=0\nresharper_blank_lines_before_single_line_comment=0\nresharper_blank_lines_between_using_groups=0\nresharper_blank_lines_inside_namespace=0\nresharper_blank_lines_inside_region=1\nresharper_blank_lines_inside_type=0\nresharper_blank_line_after_pi=true\nresharper_braces_for_dowhile=required\nresharper_braces_for_fixed=required\nresharper_braces_for_for=not_required\nresharper_braces_for_foreach=not_required\nresharper_braces_for_ifelse=not_required_for_both\nresharper_braces_for_lock=required\nresharper_braces_for_using=required\nresharper_braces_for_while=not_required\nresharper_braces_redundant=true\nresharper_can_use_global_alias=true\nresharper_constructor_or_destructor_body=block_body\nresharper_continuous_indent_multiplier=1\nresharper_csharp_align_multiline_argument=false\nresharper_csharp_align_multiline_expression=false\nresharper_csharp_align_multiline_parameter=false\nresharper_csharp_align_multiple_declaration=false\nresharper_csharp_max_line_length=120\nresharper_csharp_naming_rule.enum_member=AaBb\nresharper_csharp_naming_rule.method_property_event=AaBb\nresharper_csharp_naming_rule.other=AaBb\nresharper_csharp_prefer_qualified_reference=false\nresharper_csharp_wrap_lines=true\nresharper_default_exception_variable_name=e\nresharper_delete_quotes_from_solid_values=false\nresharper_disable_blank_line_changes=false\nresharper_disable_formatter=false\nresharper_disable_indenter=false\nresharper_disable_int_align=false\nresharper_disable_line_break_changes=false\nresharper_disable_line_break_removal=false\nresharper_disable_space_changes=false\nresharper_empty_block_style=multiline\nresharper_enable_wrapping=false\nresharper_enforce_line_ending_style=false\nresharper_event_handler_pattern_long=$object$On$event$\nresharper_event_handler_pattern_short=On$event$\nresharper_extra_spaces=remove_all\nresharper_force_attribute_style=separate\nresharper_force_chop_compound_do_expression=false\nresharper_force_chop_compound_if_expression=false\nresharper_force_chop_compound_while_expression=false\nresharper_format_leading_spaces_decl=false\nresharper_html_attribute_indent=align_by_first_attribute\nresharper_html_linebreak_before_elements=body,div,p,form,h1,h2,h3\nresharper_html_max_blank_lines_between_tags=2\nresharper_html_max_line_length=120\nresharper_html_pi_attribute_style=on_single_line\nresharper_html_space_before_self_closing=false\nresharper_html_wrap_lines=true\nresharper_ignore_space_preservation=false\nresharper_include_prefix_comment_in_indent=false\nresharper_indent_anonymous_method_block=false\nresharper_indent_case_from_select=true\nresharper_indent_child_elements=OneIndent\nresharper_indent_inside_namespace=true\nresharper_indent_invocation_pars=inside\nresharper_indent_method_decl_pars=inside\nresharper_indent_nested_fixed_stmt=false\nresharper_indent_nested_foreach_stmt=false\nresharper_indent_nested_for_stmt=false\nresharper_indent_nested_lock_stmt=false\nresharper_indent_nested_usings_stmt=false\nresharper_indent_nested_while_stmt=false\nresharper_indent_pars=inside\nresharper_indent_preprocessor_if=no_indent\nresharper_indent_preprocessor_other=no_indent\nresharper_indent_preprocessor_region=usual_indent\nresharper_indent_statement_pars=inside\nresharper_indent_text=OneIndent\nresharper_indent_typearg_angles=inside\nresharper_indent_typeparam_angles=inside\nresharper_indent_type_constraints=true\nresharper_instance_members_qualify_declared_in=this_class, base_class\nresharper_int_align=false\nresharper_keep_blank_lines_in_code=2\nresharper_keep_blank_lines_in_declarations=2\nresharper_keep_existing_attribute_arrangement=false\nresharper_keep_existing_declaration_block_arrangement=false\nresharper_keep_existing_declaration_parens_arrangement=true\nresharper_keep_existing_embedded_arrangement=true\nresharper_keep_existing_embedded_block_arrangement=false\nresharper_keep_existing_enum_arrangement=false\nresharper_keep_existing_expr_member_arrangement=true\nresharper_keep_existing_invocation_parens_arrangement=true\nresharper_keep_existing_switch_expression_arrangement=true\nresharper_keep_nontrivial_alias=true\nresharper_keep_user_linebreaks=true\nresharper_keep_user_wrapping=true\nresharper_linebreaks_around_razor_statements=true\nresharper_linebreaks_inside_tags_for_elements_longer_than=2147483647\nresharper_linebreaks_inside_tags_for_elements_with_child_elements=true\nresharper_linebreaks_inside_tags_for_multiline_elements=true\nresharper_linebreak_before_all_elements=false\nresharper_linebreak_before_multiline_elements=true\nresharper_linebreak_before_singleline_elements=false\nresharper_local_function_body=block_body\nresharper_max_array_initializer_elements_on_line=10000\nresharper_max_attribute_length_for_same_line=38\nresharper_max_enum_members_on_line=3\nresharper_max_formal_parameters_on_line=10000\nresharper_max_initializer_elements_on_line=4\nresharper_max_invocation_arguments_on_line=10000\nresharper_method_or_operator_body=block_body\nresharper_nested_ternary_style=autodetect\nresharper_new_line_before_while=false\nresharper_normalize_tag_names=false\nresharper_no_indent_inside_elements=html,body,thead,tbody,tfoot\nresharper_no_indent_inside_if_element_longer_than=200\nresharper_old_engine=false\nresharper_outdent_binary_ops=false\nresharper_outdent_commas=false\nresharper_outdent_dots=false\nresharper_outdent_ternary_ops=false\nresharper_parentheses_non_obvious_operations=none, shift, bitwise_and, bitwise_exclusive_or, bitwise_inclusive_or, bitwise\nresharper_parentheses_redundancy_style=remove_if_not_clarifies_precedence\nresharper_pi_attributes_indent=align_by_first_attribute\nresharper_place_accessorholder_attribute_on_same_line=if_owner_is_single_line\nresharper_place_accessor_attribute_on_same_line=if_owner_is_single_line\nresharper_place_comments_at_first_column=false\nresharper_place_constructor_initializer_on_same_line=true\nresharper_place_event_attribute_on_same_line=false\nresharper_place_expr_accessor_on_single_line=if_owner_is_single_line\nresharper_place_expr_method_on_single_line=if_owner_is_single_line\nresharper_place_expr_property_on_single_line=if_owner_is_single_line\nresharper_place_field_attribute_on_same_line=true\nresharper_place_linq_into_on_new_line=true\nresharper_place_method_attribute_on_same_line=false\nresharper_place_property_attribute_on_same_line=false\nresharper_place_simple_case_statement_on_same_line=false\nresharper_place_simple_embedded_statement_on_same_line=if_owner_is_single_line\nresharper_place_simple_initializer_on_single_line=true\nresharper_place_simple_switch_expression_on_single_line=false\nresharper_place_type_attribute_on_same_line=false\nresharper_place_type_constraints_on_same_line=true\nresharper_prefer_explicit_discard_declaration=false\nresharper_prefer_separate_deconstructed_variables_declaration=false\nresharper_preserve_spaces_inside_tags=pre,textarea\nresharper_qualified_using_at_nested_scope=false\nresharper_quote_style=doublequoted\nresharper_razor_prefer_qualified_reference=true\nresharper_remove_blank_lines_near_braces=false\nresharper_remove_blank_lines_near_braces_in_code=true\nresharper_remove_blank_lines_near_braces_in_declarations=true\nresharper_remove_this_qualifier=true\nresharper_resx_attribute_indent=single_indent\nresharper_resx_linebreak_before_elements=\nresharper_resx_max_blank_lines_between_tags=0\nresharper_resx_max_line_length=2147483647\nresharper_resx_pi_attribute_style=do_not_touch\nresharper_resx_space_before_self_closing=false\nresharper_resx_wrap_lines=false\nresharper_resx_wrap_tags_and_pi=false\nresharper_resx_wrap_text=false\nresharper_show_autodetect_configure_formatting_tip=true\nresharper_sort_attributes=false\nresharper_sort_class_selectors=false\nresharper_sort_usings=true\nresharper_sort_usings_lowercase_first=false\nresharper_sort_usings_with_system_first=true\nresharper_spaces_around_eq_in_attribute=false\nresharper_spaces_around_eq_in_pi_attribute=false\nresharper_spaces_inside_tags=false\nresharper_space_after_attributes=true\nresharper_space_after_attribute_target_colon=true\nresharper_space_after_colon=true\nresharper_space_after_colon_in_case=true\nresharper_space_after_comma=true\nresharper_space_after_last_attribute=false\nresharper_space_after_last_pi_attribute=false\nresharper_space_after_operator_keyword=true\nresharper_space_after_triple_slash=true\nresharper_space_after_type_parameter_constraint_colon=true\nresharper_space_after_unary_operator=false\nresharper_space_around_additive_op=true\nresharper_space_around_alias_eq=true\nresharper_space_around_assignment_op=true\nresharper_space_around_lambda_arrow=true\nresharper_space_around_member_access_operator=false\nresharper_space_around_relational_op=true\nresharper_space_around_shift_op=true\nresharper_space_around_stmt_colon=true\nresharper_space_around_ternary_operator=true\nresharper_space_before_array_rank_parentheses=false\nresharper_space_before_attribute_target_colon=false\nresharper_space_before_checked_parentheses=false\nresharper_space_before_colon=false\nresharper_space_before_colon_in_case=false\nresharper_space_before_comma=false\nresharper_space_before_default_parentheses=false\nresharper_space_before_empty_invocation_parentheses=false\nresharper_space_before_empty_method_parentheses=false\nresharper_space_before_invocation_parentheses=false\nresharper_space_before_label_colon=false\nresharper_space_before_method_parentheses=false\nresharper_space_before_nameof_parentheses=false\nresharper_space_before_nullable_mark=false\nresharper_space_before_pointer_asterik_declaration=false\nresharper_space_before_semicolon=false\nresharper_space_before_singleline_accessorholder=true\nresharper_space_before_sizeof_parentheses=false\nresharper_space_before_trailing_comment=true\nresharper_space_before_typeof_parentheses=false\nresharper_space_before_type_argument_angle=false\nresharper_space_before_type_parameter_angle=false\nresharper_space_before_type_parameter_constraint_colon=true\nresharper_space_before_type_parameter_parentheses=true\nresharper_space_between_accessors_in_singleline_property=true\nresharper_space_between_attribute_sections=true\nresharper_space_between_keyword_and_expression=true\nresharper_space_between_keyword_and_type=true\nresharper_space_in_singleline_accessorholder=true\nresharper_space_in_singleline_anonymous_method=true\nresharper_space_in_singleline_method=true\nresharper_space_near_postfix_and_prefix_op=false\nresharper_space_within_array_initialization_braces=false\nresharper_space_within_array_rank_empty_parentheses=false\nresharper_space_within_array_rank_parentheses=false\nresharper_space_within_attribute_angles=false\nresharper_space_within_checked_parentheses=false\nresharper_space_within_default_parentheses=false\nresharper_space_within_empty_braces=true\nresharper_space_within_empty_invocation_parentheses=false\nresharper_space_within_empty_method_parentheses=false\nresharper_space_within_expression_parentheses=false\nresharper_space_within_invocation_parentheses=false\nresharper_space_within_method_parentheses=false\nresharper_space_within_nameof_parentheses=false\nresharper_space_within_single_line_array_initializer_braces=true\nresharper_space_within_sizeof_parentheses=false\nresharper_space_within_tuple_parentheses=false\nresharper_space_within_typeof_parentheses=false\nresharper_space_within_type_argument_angles=false\nresharper_space_within_type_parameter_angles=false\nresharper_space_within_type_parameter_parentheses=false\nresharper_special_else_if_treatment=true\nresharper_static_members_qualify_members=none\nresharper_static_members_qualify_with=do_not_change, declared_type\nresharper_stick_comment=true\nresharper_support_vs_event_naming_pattern=true\nresharper_trailing_comma_in_multiline_lists=false\nresharper_trailing_comma_in_singleline_lists=false\nresharper_use_continuous_indent_inside_initializer_braces=true\nresharper_use_continuous_indent_inside_parens=true\nresharper_use_heuristics_for_body_style=true\nresharper_use_indents_from_main_language_in_file=true\nresharper_use_indent_from_previous_element=true\nresharper_use_indent_from_vs=false\nresharper_use_roslyn_logic_for_evident_types=false\nresharper_vb_align_multiline_argument=true\nresharper_vb_align_multiline_expression=true\nresharper_vb_align_multiline_parameter=true\nresharper_vb_align_multiple_declaration=true\nresharper_vb_max_line_length=120\nresharper_vb_place_field_attribute_on_same_line=true\nresharper_vb_place_method_attribute_on_same_line=false\nresharper_vb_place_type_attribute_on_same_line=false\nresharper_vb_prefer_qualified_reference=false\nresharper_vb_space_around_multiplicative_op=false\nresharper_vb_wrap_lines=true\nresharper_wrap_after_declaration_lpar=false\nresharper_wrap_after_dot_in_method_calls=false\nresharper_wrap_after_invocation_lpar=false\nresharper_wrap_arguments_style=wrap_if_long\nresharper_wrap_around_elements=true\nresharper_wrap_array_initializer_style=wrap_if_long\nresharper_wrap_before_arrow_with_expressions=false\nresharper_wrap_before_binary_opsign=false\nresharper_wrap_before_comma=false\nresharper_wrap_before_declaration_lpar=false\nresharper_wrap_before_declaration_rpar=false\nresharper_wrap_before_extends_colon=false\nresharper_wrap_before_first_type_parameter_constraint=false\nresharper_wrap_before_invocation_lpar=false\nresharper_wrap_before_invocation_rpar=false\nresharper_wrap_before_linq_expression=false\nresharper_wrap_before_ternary_opsigns=true\nresharper_wrap_before_type_parameter_langle=false\nresharper_wrap_chained_binary_expressions=wrap_if_long\nresharper_wrap_chained_method_calls=wrap_if_long\nresharper_wrap_enum_declaration=chop_always\nresharper_wrap_extends_list_style=wrap_if_long\nresharper_wrap_for_stmt_header_style=chop_if_long\nresharper_wrap_multiple_declaration_style=chop_if_long\nresharper_wrap_multiple_type_parameter_constraints_style=chop_if_long\nresharper_wrap_object_and_collection_initializer_style=chop_if_long\nresharper_wrap_parameters_style=wrap_if_long\nresharper_wrap_switch_expression=chop_always\nresharper_wrap_ternary_expr_style=chop_if_long\nresharper_wrap_verbatim_interpolated_strings=no_wrap\nresharper_xmldoc_attribute_indent=single_indent\nresharper_xmldoc_linebreak_before_elements=summary,remarks,example,returns,param,typeparam,value,para\nresharper_xmldoc_max_blank_lines_between_tags=0\nresharper_xmldoc_max_line_length=120\nresharper_xmldoc_pi_attribute_style=do_not_touch\nresharper_xmldoc_space_before_self_closing=true\nresharper_xmldoc_wrap_lines=true\nresharper_xmldoc_wrap_tags_and_pi=true\nresharper_xmldoc_wrap_text=true\nresharper_xml_attribute_indent=align_by_first_attribute\nresharper_xml_linebreak_before_elements=\nresharper_xml_max_blank_lines_between_tags=2\nresharper_xml_max_line_length=120\nresharper_xml_pi_attribute_style=do_not_touch\nresharper_xml_space_before_self_closing=true\nresharper_xml_wrap_lines=true\nresharper_xml_wrap_tags_and_pi=true\nresharper_xml_wrap_text=false\n\n# ReSharper inspection severities\nresharper_abstract_class_constructor_can_be_made_protected_highlighting=hint\nresharper_access_rights_in_text_highlighting=warning\nresharper_access_to_disposed_closure_highlighting=warning\nresharper_access_to_for_each_variable_in_closure_highlighting=warning\nresharper_access_to_modified_closure_highlighting=warning\nresharper_access_to_static_member_via_derived_type_highlighting=warning\nresharper_address_of_marshal_by_ref_object_highlighting=warning\nresharper_amd_dependency_path_problem_highlighting=none\nresharper_angular_html_banana_highlighting=warning\nresharper_annotate_can_be_null_parameter_highlighting=none\nresharper_annotate_can_be_null_type_member_highlighting=none\nresharper_annotate_not_null_parameter_highlighting=none\nresharper_annotate_not_null_type_member_highlighting=none\nresharper_annotation_conflict_in_hierarchy_highlighting=warning\nresharper_annotation_redundancy_at_value_type_highlighting=warning\nresharper_annotation_redundancy_in_hierarchy_highlighting=warning\nresharper_arguments_style_anonymous_function_highlighting=hint\nresharper_arguments_style_literal_highlighting=hint\nresharper_arguments_style_named_expression_highlighting=hint\nresharper_arguments_style_other_highlighting=hint\nresharper_arguments_style_string_literal_highlighting=hint\nresharper_arrange_accessor_owner_body_highlighting=suggestion\nresharper_arrange_attributes_highlighting=none\nresharper_arrange_constructor_or_destructor_body_highlighting=none\nresharper_arrange_local_function_body_highlighting=none\nresharper_arrange_method_or_operator_body_highlighting=none\nresharper_arrange_redundant_parentheses_highlighting=hint\nresharper_arrange_static_member_qualifier_highlighting=hint\nresharper_arrange_this_qualifier_highlighting=hint\nresharper_arrange_trailing_comma_in_multiline_lists_highlighting=hint\nresharper_arrange_trailing_comma_in_singleline_lists_highlighting=hint\nresharper_arrange_type_member_modifiers_highlighting=hint\nresharper_arrange_type_modifiers_highlighting=hint\nresharper_arrange_var_keywords_in_deconstructing_declaration_highlighting=suggestion\nresharper_asp0000_highlighting=warning\nresharper_asp0001_highlighting=warning\nresharper_asp_content_placeholder_not_resolved_highlighting=error\nresharper_asp_custom_page_parser_filter_type_highlighting=warning\nresharper_asp_dead_code_highlighting=warning\nresharper_asp_entity_highlighting=warning\nresharper_asp_image_highlighting=warning\nresharper_asp_invalid_control_type_highlighting=error\nresharper_asp_not_resolved_highlighting=error\nresharper_asp_ods_method_reference_resolve_error_highlighting=error\nresharper_asp_resolve_warning_highlighting=warning\nresharper_asp_skin_not_resolved_highlighting=error\nresharper_asp_tag_attribute_with_optional_value_highlighting=warning\nresharper_asp_theme_not_resolved_highlighting=error\nresharper_asp_unused_register_directive_highlighting_highlighting=warning\nresharper_asp_warning_highlighting=warning\nresharper_assigned_value_is_never_used_highlighting=warning\nresharper_assigned_value_wont_be_assigned_to_corresponding_field_highlighting=warning\nresharper_assignment_in_conditional_expression_highlighting=warning\nresharper_assignment_in_condition_expression_highlighting=warning\nresharper_assignment_is_fully_discarded_highlighting=warning\nresharper_assign_null_to_not_null_attribute_highlighting=warning\nresharper_assign_to_constant_highlighting=error\nresharper_assign_to_implicit_global_in_function_scope_highlighting=warning\nresharper_asxx_path_error_highlighting=warning\nresharper_async_iterator_invocation_without_await_foreach_highlighting=warning\nresharper_auto_property_can_be_made_get_only_global_highlighting=suggestion\nresharper_auto_property_can_be_made_get_only_local_highlighting=suggestion\nresharper_bad_attribute_brackets_spaces_highlighting=none\nresharper_bad_braces_spaces_highlighting=none\nresharper_bad_child_statement_indent_highlighting=warning\nresharper_bad_colon_spaces_highlighting=none\nresharper_bad_comma_spaces_highlighting=none\nresharper_bad_control_braces_indent_highlighting=suggestion\nresharper_bad_control_braces_line_breaks_highlighting=none\nresharper_bad_declaration_braces_indent_highlighting=none\nresharper_bad_declaration_braces_line_breaks_highlighting=none\nresharper_bad_empty_braces_line_breaks_highlighting=none\nresharper_bad_expression_braces_indent_highlighting=none\nresharper_bad_expression_braces_line_breaks_highlighting=none\nresharper_bad_generic_brackets_spaces_highlighting=none\nresharper_bad_indent_highlighting=none\nresharper_bad_linq_line_breaks_highlighting=none\nresharper_bad_list_line_breaks_highlighting=none\nresharper_bad_member_access_spaces_highlighting=none\nresharper_bad_namespace_braces_indent_highlighting=none\nresharper_bad_parens_line_breaks_highlighting=none\nresharper_bad_parens_spaces_highlighting=none\nresharper_bad_preprocessor_indent_highlighting=none\nresharper_bad_semicolon_spaces_highlighting=none\nresharper_bad_spaces_after_keyword_highlighting=none\nresharper_bad_square_brackets_spaces_highlighting=none\nresharper_bad_switch_braces_indent_highlighting=none\nresharper_bad_symbol_spaces_highlighting=none\nresharper_base_member_has_params_highlighting=warning\nresharper_base_method_call_with_default_parameter_highlighting=warning\nresharper_base_object_equals_is_object_equals_highlighting=warning\nresharper_base_object_get_hash_code_call_in_get_hash_code_highlighting=warning\nresharper_bitwise_operator_on_enum_without_flags_highlighting=warning\nresharper_bl0001_highlighting=error\nresharper_bl0002_highlighting=warning\nresharper_bl0003_highlighting=warning\nresharper_bl0004_highlighting=error\nresharper_bl0005_highlighting=warning\nresharper_bl0006_highlighting=warning\nresharper_block_scope_redeclaration_highlighting=error\nresharper_built_in_type_reference_style_for_member_access_highlighting=hint\nresharper_built_in_type_reference_style_highlighting=hint\nresharper_by_ref_argument_is_volatile_field_highlighting=warning\nresharper_caller_callee_using_error_highlighting=error\nresharper_caller_callee_using_highlighting=warning\nresharper_cannot_apply_equality_operator_to_type_highlighting=warning\nresharper_center_tag_is_obsolete_highlighting=warning\nresharper_check_for_reference_equality_instead_1_highlighting=suggestion\nresharper_check_for_reference_equality_instead_2_highlighting=suggestion\nresharper_check_for_reference_equality_instead_3_highlighting=suggestion\nresharper_check_for_reference_equality_instead_4_highlighting=suggestion\nresharper_check_namespace_highlighting=warning\nresharper_class_cannot_be_instantiated_highlighting=warning\nresharper_class_can_be_sealed_global_highlighting=none\nresharper_class_can_be_sealed_local_highlighting=none\nresharper_class_never_instantiated_global_highlighting=suggestion\nresharper_class_never_instantiated_local_highlighting=suggestion\nresharper_class_with_virtual_members_never_inherited_global_highlighting=suggestion\nresharper_class_with_virtual_members_never_inherited_local_highlighting=suggestion\nresharper_clear_attribute_is_obsolete_all_highlighting=warning\nresharper_clear_attribute_is_obsolete_highlighting=warning\nresharper_closure_on_modified_variable_highlighting=warning\nresharper_coerced_equals_using_highlighting=warning\nresharper_coerced_equals_using_with_null_undefined_highlighting=none\nresharper_collection_never_queried_global_highlighting=warning\nresharper_collection_never_queried_local_highlighting=warning\nresharper_collection_never_updated_global_highlighting=warning\nresharper_collection_never_updated_local_highlighting=warning\nresharper_comma_not_valid_here_highlighting=error\nresharper_comment_typo_highlighting=suggestion\nresharper_compare_non_constrained_generic_with_null_highlighting=none\nresharper_compare_of_floats_by_equality_operator_highlighting=warning\nresharper_conditional_ternary_equal_branch_highlighting=warning\nresharper_condition_is_always_const_highlighting=warning\nresharper_condition_is_always_true_or_false_highlighting=warning\nresharper_confusing_char_as_integer_in_constructor_highlighting=warning\nresharper_constant_conditional_access_qualifier_highlighting=warning\nresharper_constant_null_coalescing_condition_highlighting=warning\nresharper_constructor_call_not_used_highlighting=warning\nresharper_constructor_initializer_loop_highlighting=warning\nresharper_container_annotation_redundancy_highlighting=warning\nresharper_context_value_is_provided_highlighting=none\nresharper_contract_annotation_not_parsed_highlighting=warning\nresharper_convert_closure_to_method_group_highlighting=suggestion\nresharper_convert_conditional_ternary_expression_to_switch_expression_highlighting=hint\nresharper_convert_if_do_to_while_highlighting=suggestion\nresharper_convert_if_statement_to_conditional_ternary_expression_highlighting=suggestion\nresharper_convert_if_statement_to_null_coalescing_assignment_highlighting=suggestion\nresharper_convert_if_statement_to_null_coalescing_expression_highlighting=suggestion\nresharper_convert_if_statement_to_return_statement_highlighting=hint\nresharper_convert_if_statement_to_switch_expression_highlighting=hint\nresharper_convert_if_statement_to_switch_statement_highlighting=hint\nresharper_convert_if_to_or_expression_highlighting=suggestion\nresharper_convert_nullable_to_short_form_highlighting=suggestion\nresharper_convert_switch_statement_to_switch_expression_highlighting=hint\nresharper_convert_to_auto_property_highlighting=suggestion\nresharper_convert_to_auto_property_when_possible_highlighting=hint\nresharper_convert_to_auto_property_with_private_setter_highlighting=hint\nresharper_convert_to_compound_assignment_highlighting=hint\nresharper_convert_to_constant_global_highlighting=hint\nresharper_convert_to_constant_local_highlighting=hint\nresharper_convert_to_lambda_expression_highlighting=suggestion\nresharper_convert_to_lambda_expression_when_possible_highlighting=none\nresharper_convert_to_local_function_highlighting=suggestion\nresharper_convert_to_null_coalescing_compound_assignment_highlighting=suggestion\nresharper_convert_to_static_class_highlighting=suggestion\nresharper_convert_to_using_declaration_highlighting=suggestion\nresharper_convert_to_vb_auto_property_highlighting=suggestion\nresharper_convert_to_vb_auto_property_when_possible_highlighting=hint\nresharper_convert_to_vb_auto_property_with_private_setter_highlighting=hint\nresharper_co_variant_array_conversion_highlighting=warning\nresharper_create_specialized_overload_highlighting=hint\nresharper_css_browser_compatibility_highlighting=warning\nresharper_css_caniuse_feature_requires_prefix_highlighting=hint\nresharper_css_caniuse_unsupported_feature_highlighting=hint\nresharper_css_not_resolved_highlighting=error\nresharper_css_obsolete_highlighting=hint\nresharper_css_property_does_not_override_vendor_property_highlighting=warning\nresharper_cyclic_reference_comment_highlighting=none\nresharper_c_sharp_warnings_cs0078_highlighting=warning\nresharper_c_sharp_warnings_cs0108_cs0114_highlighting=warning\nresharper_c_sharp_warnings_cs0109_highlighting=warning\nresharper_c_sharp_warnings_cs0162_highlighting=warning\nresharper_c_sharp_warnings_cs0183_highlighting=warning\nresharper_c_sharp_warnings_cs0184_highlighting=warning\nresharper_c_sharp_warnings_cs0197_highlighting=warning\nresharper_c_sharp_warnings_cs0252_cs0253_highlighting=warning\nresharper_c_sharp_warnings_cs0420_highlighting=warning\nresharper_c_sharp_warnings_cs0465_highlighting=warning\nresharper_c_sharp_warnings_cs0469_highlighting=warning\nresharper_c_sharp_warnings_cs0612_highlighting=warning\nresharper_c_sharp_warnings_cs0618_highlighting=warning\nresharper_c_sharp_warnings_cs0628_highlighting=warning\nresharper_c_sharp_warnings_cs0642_highlighting=warning\nresharper_c_sharp_warnings_cs0657_highlighting=warning\nresharper_c_sharp_warnings_cs0658_highlighting=warning\nresharper_c_sharp_warnings_cs0659_highlighting=warning\nresharper_c_sharp_warnings_cs0660_cs0661_highlighting=warning\nresharper_c_sharp_warnings_cs0665_highlighting=warning\nresharper_c_sharp_warnings_cs0672_highlighting=warning\nresharper_c_sharp_warnings_cs0693_highlighting=warning\nresharper_c_sharp_warnings_cs1030_highlighting=warning\nresharper_c_sharp_warnings_cs1058_highlighting=warning\nresharper_c_sharp_warnings_cs1066_highlighting=warning\nresharper_c_sharp_warnings_cs1522_highlighting=warning\nresharper_c_sharp_warnings_cs1570_highlighting=warning\nresharper_c_sharp_warnings_cs1571_highlighting=warning\nresharper_c_sharp_warnings_cs1572_highlighting=warning\nresharper_c_sharp_warnings_cs1573_highlighting=warning\nresharper_c_sharp_warnings_cs1574_cs1584_cs1581_cs1580_highlighting=warning\nresharper_c_sharp_warnings_cs1574_highlighting=warning\nresharper_c_sharp_warnings_cs1580_highlighting=warning\nresharper_c_sharp_warnings_cs1584_highlighting=warning\nresharper_c_sharp_warnings_cs1587_highlighting=warning\nresharper_c_sharp_warnings_cs1589_highlighting=warning\nresharper_c_sharp_warnings_cs1590_highlighting=warning\nresharper_c_sharp_warnings_cs1591_highlighting=warning\nresharper_c_sharp_warnings_cs1592_highlighting=warning\nresharper_c_sharp_warnings_cs1710_highlighting=warning\nresharper_c_sharp_warnings_cs1711_highlighting=warning\nresharper_c_sharp_warnings_cs1712_highlighting=warning\nresharper_c_sharp_warnings_cs1717_highlighting=warning\nresharper_c_sharp_warnings_cs1723_highlighting=warning\nresharper_c_sharp_warnings_cs1911_highlighting=warning\nresharper_c_sharp_warnings_cs1957_highlighting=warning\nresharper_c_sharp_warnings_cs1981_highlighting=warning\nresharper_c_sharp_warnings_cs1998_highlighting=warning\nresharper_c_sharp_warnings_cs4014_highlighting=warning\nresharper_c_sharp_warnings_cs7095_highlighting=warning\nresharper_c_sharp_warnings_cs8094_highlighting=warning\nresharper_c_sharp_warnings_cs8123_highlighting=warning\nresharper_c_sharp_warnings_cs8383_highlighting=warning\nresharper_c_sharp_warnings_cs8416_highlighting=warning\nresharper_c_sharp_warnings_cs8417_highlighting=warning\nresharper_c_sharp_warnings_cs8425_highlighting=warning\nresharper_c_sharp_warnings_cs8509_highlighting=warning\nresharper_c_sharp_warnings_cs8597_highlighting=warning\nresharper_c_sharp_warnings_cs8600_highlighting=warning\nresharper_c_sharp_warnings_cs8601_highlighting=warning\nresharper_c_sharp_warnings_cs8602_highlighting=warning\nresharper_c_sharp_warnings_cs8603_highlighting=warning\nresharper_c_sharp_warnings_cs8604_highlighting=warning\nresharper_c_sharp_warnings_cs8605_highlighting=warning\nresharper_c_sharp_warnings_cs8606_highlighting=warning\nresharper_c_sharp_warnings_cs8608_highlighting=warning\nresharper_c_sharp_warnings_cs8609_highlighting=warning\nresharper_c_sharp_warnings_cs8610_highlighting=warning\nresharper_c_sharp_warnings_cs8611_highlighting=warning\nresharper_c_sharp_warnings_cs8612_highlighting=warning\nresharper_c_sharp_warnings_cs8613_highlighting=warning\nresharper_c_sharp_warnings_cs8614_highlighting=warning\nresharper_c_sharp_warnings_cs8615_highlighting=warning\nresharper_c_sharp_warnings_cs8616_highlighting=warning\nresharper_c_sharp_warnings_cs8617_highlighting=warning\nresharper_c_sharp_warnings_cs8618_highlighting=warning\nresharper_c_sharp_warnings_cs8619_highlighting=warning\nresharper_c_sharp_warnings_cs8620_highlighting=warning\nresharper_c_sharp_warnings_cs8621_highlighting=warning\nresharper_c_sharp_warnings_cs8622_highlighting=warning\nresharper_c_sharp_warnings_cs8624_highlighting=warning\nresharper_c_sharp_warnings_cs8625_highlighting=warning\nresharper_c_sharp_warnings_cs8629_highlighting=warning\nresharper_c_sharp_warnings_cs8631_highlighting=warning\nresharper_c_sharp_warnings_cs8632_highlighting=warning\nresharper_c_sharp_warnings_cs8633_highlighting=warning\nresharper_c_sharp_warnings_cs8634_highlighting=warning\nresharper_c_sharp_warnings_cs8643_highlighting=warning\nresharper_c_sharp_warnings_cs8644_highlighting=warning\nresharper_c_sharp_warnings_cs8645_highlighting=warning\nresharper_c_sharp_warnings_cs8656_highlighting=warning\nresharper_c_sharp_warnings_cs8667_highlighting=warning\nresharper_c_sharp_warnings_cs8714_highlighting=warning\nresharper_c_sharp_warnings_wme006_highlighting=warning\nresharper_declaration_hides_highlighting=hint\nresharper_declaration_is_empty_highlighting=warning\nresharper_declaration_visibility_error_highlighting=error\nresharper_default_value_attribute_for_optional_parameter_highlighting=warning\nresharper_delegate_subtraction_highlighting=warning\nresharper_deleting_non_qualified_reference_highlighting=error\nresharper_dl_tag_contains_non_dt_or_dd_elements_highlighting=hint\nresharper_double_colons_expected_highlighting=error\nresharper_double_colons_preferred_highlighting=suggestion\nresharper_double_negation_of_boolean_highlighting=warning\nresharper_double_negation_operator_highlighting=suggestion\nresharper_duplicate_identifier_error_highlighting=error\nresharper_duplicate_reference_comment_highlighting=warning\nresharper_duplicate_resource_highlighting=warning\nresharper_duplicating_local_declaration_highlighting=warning\nresharper_duplicating_parameter_declaration_error_highlighting=error\nresharper_duplicating_property_declaration_error_highlighting=error\nresharper_duplicating_property_declaration_highlighting=warning\nresharper_duplicating_switch_label_highlighting=warning\nresharper_dynamic_shift_right_op_is_not_int_highlighting=warning\nresharper_ef1001_highlighting=warning\nresharper_elided_trailing_element_highlighting=warning\nresharper_empty_constructor_highlighting=warning\nresharper_empty_destructor_highlighting=warning\nresharper_empty_embedded_statement_highlighting=warning\nresharper_empty_for_statement_highlighting=warning\nresharper_empty_general_catch_clause_highlighting=warning\nresharper_empty_namespace_highlighting=warning\nresharper_empty_object_property_declaration_highlighting=error\nresharper_empty_return_value_for_type_annotated_function_highlighting=warning\nresharper_empty_statement_highlighting=warning\nresharper_empty_title_tag_highlighting=hint\nresharper_enc0001_highlighting=info\nresharper_enc0002_highlighting=info\nresharper_enc0003_highlighting=info\nresharper_enc0004_highlighting=info\nresharper_enc0005_highlighting=info\nresharper_enc0006_highlighting=info\nresharper_enc0007_highlighting=info\nresharper_enc0008_highlighting=info\nresharper_enc0009_highlighting=info\nresharper_enc0010_highlighting=info\nresharper_enc0011_highlighting=info\nresharper_enc0012_highlighting=info\nresharper_enc0013_highlighting=info\nresharper_enc0014_highlighting=info\nresharper_enc0015_highlighting=info\nresharper_enc0016_highlighting=info\nresharper_enc0017_highlighting=info\nresharper_enc0018_highlighting=info\nresharper_enc0019_highlighting=info\nresharper_enc0020_highlighting=info\nresharper_enc0021_highlighting=info\nresharper_enc0023_highlighting=info\nresharper_enc0024_highlighting=info\nresharper_enc0025_highlighting=info\nresharper_enc0026_highlighting=info\nresharper_enc0028_highlighting=info\nresharper_enc0029_highlighting=info\nresharper_enc0030_highlighting=info\nresharper_enc0031_highlighting=info\nresharper_enc0032_highlighting=info\nresharper_enc0033_highlighting=info\nresharper_enc0034_highlighting=info\nresharper_enc0035_highlighting=info\nresharper_enc0036_highlighting=info\nresharper_enc0037_highlighting=info\nresharper_enc0038_highlighting=info\nresharper_enc0039_highlighting=info\nresharper_enc0040_highlighting=info\nresharper_enc0041_highlighting=info\nresharper_enc0044_highlighting=info\nresharper_enc0045_highlighting=info\nresharper_enc0046_highlighting=info\nresharper_enc0047_highlighting=info\nresharper_enc0048_highlighting=info\nresharper_enc0049_highlighting=info\nresharper_enc0050_highlighting=info\nresharper_enc0051_highlighting=info\nresharper_enc0052_highlighting=info\nresharper_enc0053_highlighting=info\nresharper_enc0054_highlighting=info\nresharper_enc0055_highlighting=info\nresharper_enc0056_highlighting=info\nresharper_enc0057_highlighting=info\nresharper_enc0058_highlighting=info\nresharper_enc0059_highlighting=info\nresharper_enc0060_highlighting=info\nresharper_enc0061_highlighting=info\nresharper_enc0062_highlighting=info\nresharper_enc0063_highlighting=info\nresharper_enc0064_highlighting=info\nresharper_enc0065_highlighting=info\nresharper_enc0066_highlighting=info\nresharper_enc0067_highlighting=info\nresharper_enc0068_highlighting=info\nresharper_enc0069_highlighting=info\nresharper_enc0070_highlighting=info\nresharper_enc0071_highlighting=info\nresharper_enc0072_highlighting=info\nresharper_enc0073_highlighting=info\nresharper_enc0074_highlighting=info\nresharper_enc0075_highlighting=info\nresharper_enc0076_highlighting=info\nresharper_enc0080_highlighting=info\nresharper_enc0081_highlighting=info\nresharper_enc0082_highlighting=info\nresharper_enc0083_highlighting=info\nresharper_enc0084_highlighting=info\nresharper_enc0085_highlighting=info\nresharper_enc0086_highlighting=info\nresharper_enc1001_highlighting=info\nresharper_enc1002_highlighting=info\nresharper_enc1003_highlighting=info\nresharper_enc1004_highlighting=info\nresharper_enforce_do_while_statement_braces_highlighting=none\nresharper_enforce_fixed_statement_braces_highlighting=none\nresharper_enforce_foreach_statement_braces_highlighting=none\nresharper_enforce_for_statement_braces_highlighting=none\nresharper_enforce_if_statement_braces_highlighting=none\nresharper_enforce_lock_statement_braces_highlighting=none\nresharper_enforce_using_statement_braces_highlighting=none\nresharper_enforce_while_statement_braces_highlighting=none\nresharper_enumerable_sum_in_explicit_unchecked_context_highlighting=warning\nresharper_enum_underlying_type_is_int_highlighting=warning\nresharper_equal_expression_comparison_highlighting=warning\nresharper_error_in_xml_doc_reference_highlighting=error\nresharper_es6_feature_highlighting=error\nresharper_es7_feature_highlighting=error\nresharper_escaped_keyword_highlighting=warning\nresharper_eval_arguments_name_error_highlighting=error\nresharper_event_never_invoked_global_highlighting=suggestion\nresharper_event_never_invoked_highlighting=warning\nresharper_event_never_subscribed_to_global_highlighting=suggestion\nresharper_event_never_subscribed_to_local_highlighting=suggestion\nresharper_event_unsubscription_via_anonymous_delegate_highlighting=warning\nresharper_experimental_feature_highlighting=error\nresharper_explicit_caller_info_argument_highlighting=warning\nresharper_expression_is_always_const_highlighting=warning\nresharper_expression_is_always_null_highlighting=warning\nresharper_field_can_be_made_read_only_global_highlighting=suggestion\nresharper_field_can_be_made_read_only_local_highlighting=suggestion\nresharper_foreach_can_be_converted_to_query_using_another_get_enumerator_highlighting=hint\nresharper_foreach_can_be_partly_converted_to_query_using_another_get_enumerator_highlighting=hint\nresharper_format_string_placeholders_mismatch_highlighting=warning\nresharper_format_string_problem_highlighting=warning\nresharper_for_can_be_converted_to_foreach_highlighting=suggestion\nresharper_for_statement_condition_is_true_highlighting=warning\nresharper_functions_used_before_declared_highlighting=none\nresharper_function_complexity_overflow_highlighting=none\nresharper_function_never_returns_highlighting=warning\nresharper_function_parameter_named_arguments_highlighting=warning\nresharper_function_recursive_on_all_paths_highlighting=warning\nresharper_function_used_out_of_scope_highlighting=warning\nresharper_gc_suppress_finalize_for_type_without_destructor_highlighting=warning\nresharper_generic_enumerator_not_disposed_highlighting=warning\nresharper_heuristically_unreachable_code_highlighting=warning\nresharper_heuristic_unreachable_code_highlighting=warning\nresharper_hex_color_value_with_alpha_highlighting=error\nresharper_html_attributes_quotes_highlighting=hint\nresharper_html_attribute_not_resolved_highlighting=warning\nresharper_html_attribute_value_not_resolved_highlighting=warning\nresharper_html_dead_code_highlighting=warning\nresharper_html_event_not_resolved_highlighting=warning\nresharper_html_id_duplication_highlighting=warning\nresharper_html_id_not_resolved_highlighting=warning\nresharper_html_obsolete_highlighting=warning\nresharper_html_path_error_highlighting=warning\nresharper_html_tag_not_closed_highlighting=error\nresharper_html_tag_not_resolved_highlighting=warning\nresharper_html_tag_should_be_self_closed_highlighting=warning\nresharper_html_tag_should_not_be_self_closed_highlighting=warning\nresharper_html_warning_highlighting=warning\nresharper_identifier_typo_highlighting=suggestion\nresharper_ignored_directive_highlighting=warning\nresharper_implicit_any_error_highlighting=error\nresharper_implicit_any_type_warning_highlighting=warning\nresharper_import_keyword_not_with_invocation_highlighting=error\nresharper_inactive_preprocessor_branch_highlighting=warning\nresharper_inconsistently_synchronized_field_highlighting=warning\nresharper_inconsistent_function_returns_highlighting=warning\nresharper_inconsistent_naming_highlighting=warning\nresharper_incorrect_blank_lines_near_braces_highlighting=none\nresharper_incorrect_operand_in_type_of_comparison_highlighting=warning\nresharper_incorrect_triple_slash_location_highlighting=warning\nresharper_indexing_by_invalid_range_highlighting=warning\nresharper_inheritdoc_consider_usage_highlighting=none\nresharper_inheritdoc_invalid_usage_highlighting=warning\nresharper_inline_out_variable_declaration_highlighting=suggestion\nresharper_internal_or_private_member_not_documented_highlighting=none\nresharper_interpolated_string_expression_is_not_i_formattable_highlighting=warning\nresharper_introduce_optional_parameters_global_highlighting=suggestion\nresharper_introduce_optional_parameters_local_highlighting=suggestion\nresharper_introduce_variable_to_apply_guard_highlighting=hint\nresharper_int_division_by_zero_highlighting=warning\nresharper_int_relational_or_equality_expression_always_same_value_highlighting=warning\nresharper_int_variable_overflow_highlighting=warning\nresharper_int_variable_overflow_in_checked_context_highlighting=warning\nresharper_int_variable_overflow_in_unchecked_context_highlighting=warning\nresharper_invalid_attribute_value_highlighting=warning\nresharper_invalid_json_syntax_highlighting=error\nresharper_invalid_task_element_highlighting=none\nresharper_invalid_value_highlighting=error\nresharper_invalid_value_type_highlighting=warning\nresharper_invalid_xml_doc_comment_highlighting=warning\nresharper_invert_condition_1_highlighting=hint\nresharper_invert_if_highlighting=hint\nresharper_invocation_is_skipped_highlighting=hint\nresharper_invocation_of_non_function_highlighting=warning\nresharper_invoked_expression_maybe_non_function_highlighting=warning\nresharper_invoke_as_extension_method_highlighting=suggestion\nresharper_is_expression_always_false_highlighting=warning\nresharper_is_expression_always_of_type_highlighting=warning\nresharper_is_expression_always_true_highlighting=warning\nresharper_iterator_method_result_is_ignored_highlighting=warning\nresharper_iterator_never_returns_highlighting=warning\nresharper_join_declaration_and_initializer_highlighting=suggestion\nresharper_join_declaration_and_initializer_js_highlighting=suggestion\nresharper_join_null_check_with_usage_highlighting=suggestion\nresharper_join_null_check_with_usage_when_possible_highlighting=none\nresharper_json_validation_failed_highlighting=error\nresharper_js_path_not_found_highlighting=error\nresharper_js_unreachable_code_highlighting=warning\nresharper_jump_must_be_in_loop_highlighting=warning\nresharper_label_or_semicolon_expected_highlighting=error\nresharper_less_specific_overload_than_main_signature_highlighting=warning\nresharper_lexical_declaration_needs_block_highlighting=error\nresharper_localizable_element_highlighting=warning\nresharper_local_function_can_be_made_static_highlighting=hint\nresharper_local_function_redefined_later_highlighting=warning\nresharper_local_name_captured_only_highlighting=warning\nresharper_local_variable_hides_member_highlighting=warning\nresharper_long_literal_ending_lower_l_highlighting=warning\nresharper_loop_can_be_converted_to_query_highlighting=hint\nresharper_loop_can_be_partly_converted_to_query_highlighting=none\nresharper_loop_variable_is_never_changed_inside_loop_highlighting=warning\nresharper_l_value_is_expected_highlighting=error\nresharper_markup_attribute_typo_highlighting=suggestion\nresharper_markup_text_typo_highlighting=suggestion\nresharper_meaningless_default_parameter_value_highlighting=warning\nresharper_member_can_be_internal_highlighting=none\nresharper_member_can_be_made_static_global_highlighting=hint\nresharper_member_can_be_made_static_local_highlighting=hint\nresharper_member_can_be_private_global_highlighting=suggestion\nresharper_member_can_be_private_local_highlighting=suggestion\nresharper_member_can_be_protected_global_highlighting=suggestion\nresharper_member_can_be_protected_local_highlighting=suggestion\nresharper_member_hides_static_from_outer_class_highlighting=warning\nresharper_member_initializer_value_ignored_highlighting=warning\nresharper_merge_cast_with_type_check_highlighting=suggestion\nresharper_merge_conditional_expression_highlighting=suggestion\nresharper_merge_conditional_expression_when_possible_highlighting=none\nresharper_merge_sequential_checks_highlighting=suggestion\nresharper_merge_sequential_checks_when_possible_highlighting=none\nresharper_method_has_async_overload_highlighting=suggestion\nresharper_method_has_async_overload_with_cancellation_highlighting=suggestion\nresharper_method_overload_with_optional_parameter_highlighting=warning\nresharper_method_supports_cancellation_highlighting=suggestion\nresharper_missing_alt_attribute_in_img_tag_highlighting=hint\nresharper_missing_attribute_highlighting=warning\nresharper_missing_blank_lines_highlighting=none\nresharper_missing_body_tag_highlighting=warning\nresharper_missing_has_own_property_in_foreach_highlighting=warning\nresharper_missing_head_and_body_tags_highlighting=warning\nresharper_missing_head_tag_highlighting=warning\nresharper_missing_indent_highlighting=none\nresharper_missing_linebreak_highlighting=none\nresharper_missing_space_highlighting=none\nresharper_missing_title_tag_highlighting=hint\nresharper_misuse_of_owner_function_this_highlighting=warning\nresharper_more_specific_foreach_variable_type_available_highlighting=suggestion\nresharper_more_specific_signature_after_less_specific_highlighting=warning\nresharper_multiple_declarations_in_foreach_highlighting=error\nresharper_multiple_nullable_attributes_usage_highlighting=warning\nresharper_multiple_order_by_highlighting=warning\nresharper_multiple_output_tags_highlighting=warning\nresharper_multiple_resolve_candidates_in_text_highlighting=warning\nresharper_multiple_spaces_highlighting=none\nresharper_multiple_statements_on_one_line_highlighting=none\nresharper_multiple_type_members_on_one_line_highlighting=none\nresharper_must_use_return_value_highlighting=warning\nresharper_mvc1000_highlighting=warning\nresharper_mvc1001_highlighting=warning\nresharper_mvc1002_highlighting=warning\nresharper_mvc1003_highlighting=warning\nresharper_mvc1004_highlighting=warning\nresharper_mvc1005_highlighting=warning\nresharper_mvc1006_highlighting=error\nresharper_mvc_action_not_resolved_highlighting=error\nresharper_mvc_area_not_resolved_highlighting=error\nresharper_mvc_controller_not_resolved_highlighting=error\nresharper_mvc_invalid_model_type_highlighting=error\nresharper_mvc_masterpage_not_resolved_highlighting=error\nresharper_mvc_partial_view_not_resolved_highlighting=error\nresharper_mvc_template_not_resolved_highlighting=error\nresharper_mvc_view_component_not_resolved_highlighting=error\nresharper_mvc_view_component_view_not_resolved_highlighting=error\nresharper_mvc_view_not_resolved_highlighting=error\nresharper_native_type_prototype_extending_highlighting=warning\nresharper_native_type_prototype_overwriting_highlighting=warning\nresharper_negative_equality_expression_highlighting=suggestion\nresharper_negative_index_highlighting=warning\nresharper_nested_string_interpolation_highlighting=suggestion\nresharper_non_assigned_constant_highlighting=error\nresharper_non_constant_equality_expression_has_constant_result_highlighting=warning\nresharper_non_readonly_member_in_get_hash_code_highlighting=warning\nresharper_non_volatile_field_in_double_check_locking_highlighting=warning\nresharper_not_accessed_field_compiler_highlighting=warning\nresharper_not_accessed_field_global_highlighting=suggestion\nresharper_not_accessed_field_local_highlighting=warning\nresharper_not_accessed_variable_compiler_highlighting=warning\nresharper_not_accessed_variable_highlighting=warning\nresharper_not_all_paths_return_value_highlighting=warning\nresharper_not_assigned_out_parameter_highlighting=warning\nresharper_not_declared_in_parent_culture_highlighting=warning\nresharper_not_null_member_is_not_initialized_highlighting=warning\nresharper_not_observable_annotation_redundancy_highlighting=warning\nresharper_not_overridden_in_specific_culture_highlighting=warning\nresharper_not_resolved_highlighting=warning\nresharper_not_resolved_in_text_highlighting=warning\nresharper_no_support_for_vb_highlighting=warning\nresharper_n_unit_async_method_must_be_task_highlighting=warning\nresharper_n_unit_incorrect_argument_type_highlighting=warning\nresharper_n_unit_incorrect_expected_result_type_highlighting=warning\nresharper_n_unit_method_with_parameters_and_test_attribute_highlighting=warning\nresharper_n_unit_missing_arguments_in_test_case_attribute_highlighting=warning\nresharper_n_unit_non_public_method_with_test_attribute_highlighting=warning\nresharper_n_unit_redundant_argument_instead_of_expected_result_highlighting=warning\nresharper_n_unit_redundant_argument_in_test_case_attribute_highlighting=warning\nresharper_n_unit_redundant_expected_result_in_test_case_attribute_highlighting=warning\nresharper_n_unit_test_case_attribute_requires_expected_result_highlighting=warning\nresharper_n_unit_test_case_result_property_duplicates_expected_result_highlighting=warning\nresharper_n_unit_test_case_result_property_is_obsolete_highlighting=warning\nresharper_n_unit_test_case_source_cannot_be_resolved_highlighting=warning\nresharper_n_unit_test_case_source_must_be_field_property_method_highlighting=warning\nresharper_n_unit_test_case_source_must_be_static_highlighting=warning\nresharper_n_unit_test_case_source_should_implement_i_enumerable_highlighting=warning\nresharper_object_creation_as_statement_highlighting=warning\nresharper_object_destructuring_without_parentheses_highlighting=error\nresharper_object_literals_are_not_comma_free_highlighting=error\nresharper_obsolete_element_error_highlighting=error\nresharper_obsolete_element_highlighting=warning\nresharper_octal_literals_not_allowed_error_highlighting=error\nresharper_ol_tag_contains_non_li_elements_highlighting=hint\nresharper_one_way_operation_contract_with_return_type_highlighting=warning\nresharper_operation_contract_without_service_contract_highlighting=warning\nresharper_operator_is_can_be_used_highlighting=warning\nresharper_optional_parameter_hierarchy_mismatch_highlighting=warning\nresharper_optional_parameter_ref_out_highlighting=warning\nresharper_other_tags_inside_script1_highlighting=error\nresharper_other_tags_inside_script2_highlighting=error\nresharper_other_tags_inside_unclosed_script_highlighting=error\nresharper_outdent_is_off_prev_level_highlighting=none\nresharper_output_tag_required_highlighting=warning\nresharper_overridden_with_empty_value_highlighting=warning\nresharper_overridden_with_same_value_highlighting=suggestion\nresharper_parameter_doesnt_make_any_sense_highlighting=warning\nresharper_parameter_hides_member_highlighting=warning\nresharper_parameter_only_used_for_precondition_check_global_highlighting=suggestion\nresharper_parameter_only_used_for_precondition_check_local_highlighting=warning\nresharper_parameter_type_can_be_enumerable_global_highlighting=hint\nresharper_parameter_type_can_be_enumerable_local_highlighting=hint\nresharper_parameter_value_is_not_used_highlighting=warning\nresharper_partial_method_parameter_name_mismatch_highlighting=warning\nresharper_partial_method_with_single_part_highlighting=warning\nresharper_partial_type_with_single_part_highlighting=warning\nresharper_path_not_resolved_highlighting=error\nresharper_pattern_always_matches_highlighting=warning\nresharper_pattern_always_of_type_highlighting=warning\nresharper_pattern_never_matches_highlighting=warning\nresharper_polymorphic_field_like_event_invocation_highlighting=warning\nresharper_possible_infinite_inheritance_highlighting=warning\nresharper_possible_intended_rethrow_highlighting=warning\nresharper_possible_interface_member_ambiguity_highlighting=warning\nresharper_possible_invalid_cast_exception_highlighting=warning\nresharper_possible_invalid_cast_exception_in_foreach_loop_highlighting=warning\nresharper_possible_invalid_operation_exception_highlighting=warning\nresharper_possible_loss_of_fraction_highlighting=warning\nresharper_possible_mistaken_argument_highlighting=warning\nresharper_possible_mistaken_call_to_get_type_1_highlighting=warning\nresharper_possible_mistaken_call_to_get_type_2_highlighting=warning\nresharper_possible_multiple_enumeration_highlighting=warning\nresharper_possible_multiple_write_access_in_double_check_locking_highlighting=warning\nresharper_possible_null_reference_exception_highlighting=warning\nresharper_possible_struct_member_modification_of_non_variable_struct_highlighting=warning\nresharper_possible_unintended_linear_search_in_set_highlighting=warning\nresharper_possible_unintended_queryable_as_enumerable_highlighting=suggestion\nresharper_possible_unintended_reference_comparison_highlighting=warning\nresharper_possible_write_to_me_highlighting=warning\nresharper_possibly_impure_method_call_on_readonly_variable_highlighting=warning\nresharper_possibly_incorrectly_broken_statement_highlighting=warning\nresharper_possibly_missing_indexer_initializer_comma_highlighting=warning\nresharper_possibly_mistaken_use_of_interpolated_string_insert_highlighting=warning\nresharper_possibly_mistaken_use_of_params_method_highlighting=warning\nresharper_possibly_unassigned_property_highlighting=hint\nresharper_private_field_can_be_converted_to_local_variable_highlighting=warning\nresharper_private_variable_can_be_made_readonly_highlighting=hint\nresharper_property_getter_cannot_have_parameters_highlighting=error\nresharper_property_not_resolved_highlighting=error\nresharper_property_setter_must_have_single_parameter_highlighting=error\nresharper_public_constructor_in_abstract_class_highlighting=suggestion\nresharper_pure_attribute_on_void_method_highlighting=warning\nresharper_qualified_expression_is_null_highlighting=warning\nresharper_qualified_expression_maybe_null_highlighting=warning\nresharper_razor_layout_not_resolved_highlighting=error\nresharper_razor_section_not_resolved_highlighting=error\nresharper_read_access_in_double_check_locking_highlighting=warning\nresharper_redundant_abstract_modifier_highlighting=warning\nresharper_redundant_anonymous_type_property_name_highlighting=warning\nresharper_redundant_argument_default_value_highlighting=warning\nresharper_redundant_array_creation_expression_highlighting=hint\nresharper_redundant_array_lower_bound_specification_highlighting=warning\nresharper_redundant_assignment_highlighting=warning\nresharper_redundant_attribute_parentheses_highlighting=hint\nresharper_redundant_attribute_usage_property_highlighting=suggestion\nresharper_redundant_base_constructor_call_highlighting=warning\nresharper_redundant_base_qualifier_highlighting=warning\nresharper_redundant_blank_lines_highlighting=none\nresharper_redundant_block_highlighting=warning\nresharper_redundant_bool_compare_highlighting=warning\nresharper_redundant_case_label_highlighting=warning\nresharper_redundant_cast_0_highlighting=warning\nresharper_redundant_cast_highlighting=warning\nresharper_redundant_catch_clause_highlighting=warning\nresharper_redundant_check_before_assignment_highlighting=warning\nresharper_redundant_collection_initializer_element_braces_highlighting=hint\nresharper_redundant_comparison_with_boolean_highlighting=warning\nresharper_redundant_css_hack_highlighting=warning\nresharper_redundant_declaration_semicolon_highlighting=hint\nresharper_redundant_default_member_initializer_highlighting=warning\nresharper_redundant_delegate_creation_highlighting=warning\nresharper_redundant_disable_warning_comment_highlighting=warning\nresharper_redundant_discarded_pattern_highlighting=suggestion\nresharper_redundant_discard_designation_highlighting=suggestion\nresharper_redundant_else_block_highlighting=warning\nresharper_redundant_empty_case_else_highlighting=warning\nresharper_redundant_empty_constructor_highlighting=warning\nresharper_redundant_empty_finally_block_highlighting=warning\nresharper_redundant_empty_object_creation_argument_list_highlighting=hint\nresharper_redundant_empty_object_or_collection_initializer_highlighting=warning\nresharper_redundant_empty_switch_section_highlighting=warning\nresharper_redundant_enumerable_cast_call_highlighting=warning\nresharper_redundant_explicit_array_creation_highlighting=warning\nresharper_redundant_explicit_array_size_highlighting=warning\nresharper_redundant_explicit_nullable_creation_highlighting=warning\nresharper_redundant_explicit_params_array_creation_highlighting=suggestion\nresharper_redundant_explicit_tuple_component_name_highlighting=warning\nresharper_redundant_extends_list_entry_highlighting=warning\nresharper_redundant_fixed_pointer_declaration_highlighting=suggestion\nresharper_redundant_highlighting=warning\nresharper_redundant_if_else_block_highlighting=hint\nresharper_redundant_if_statement_then_keyword_highlighting=none\nresharper_redundant_immediate_delegate_invocation_highlighting=suggestion\nresharper_redundant_include_highlighting=warning\nresharper_redundant_intermediate_variable_highlighting=hint\nresharper_redundant_iterator_keyword_highlighting=warning\nresharper_redundant_jump_statement_highlighting=warning\nresharper_redundant_lambda_parameter_type_highlighting=warning\nresharper_redundant_lambda_signature_parentheses_highlighting=hint\nresharper_redundant_linebreak_highlighting=none\nresharper_redundant_local_class_name_highlighting=hint\nresharper_redundant_local_function_name_highlighting=hint\nresharper_redundant_logical_conditional_expression_operand_highlighting=warning\nresharper_redundant_me_qualifier_highlighting=warning\nresharper_redundant_my_base_qualifier_highlighting=warning\nresharper_redundant_my_class_qualifier_highlighting=warning\nresharper_redundant_name_qualifier_highlighting=warning\nresharper_redundant_not_null_constraint_highlighting=warning\nresharper_redundant_nullable_annotation_on_reference_type_constraint_highlighting=warning\nresharper_redundant_nullable_annotation_on_type_constraint_has_non_nullable_base_type_highlighting=warning\nresharper_redundant_nullable_annotation_on_type_constraint_has_non_nullable_type_kind_highlighting=warning\nresharper_redundant_nullable_type_mark_highlighting=warning\nresharper_redundant_overflow_checking_context_highlighting=warning\nresharper_redundant_overload_global_highlighting=suggestion\nresharper_redundant_overload_local_highlighting=suggestion\nresharper_redundant_overridden_member_highlighting=warning\nresharper_redundant_params_highlighting=warning\nresharper_redundant_parentheses_highlighting=none\nresharper_redundant_parent_type_declaration_highlighting=warning\nresharper_redundant_property_parentheses_highlighting=hint\nresharper_redundant_property_pattern_clause_highlighting=suggestion\nresharper_redundant_qualifier_highlighting=warning\nresharper_redundant_query_order_by_ascending_keyword_highlighting=hint\nresharper_redundant_range_bound_highlighting=suggestion\nresharper_redundant_readonly_modifier_highlighting=suggestion\nresharper_redundant_setter_value_parameter_declaration_highlighting=hint\nresharper_redundant_space_highlighting=none\nresharper_redundant_string_format_call_highlighting=warning\nresharper_redundant_string_interpolation_highlighting=suggestion\nresharper_redundant_string_to_char_array_call_highlighting=warning\nresharper_redundant_string_type_highlighting=suggestion\nresharper_redundant_ternary_expression_highlighting=warning\nresharper_redundant_to_string_call_for_value_type_highlighting=hint\nresharper_redundant_to_string_call_highlighting=warning\nresharper_redundant_type_arguments_of_method_highlighting=warning\nresharper_redundant_type_cast_highlighting=warning\nresharper_redundant_type_cast_structural_highlighting=warning\nresharper_redundant_type_specification_in_default_expression_highlighting=suggestion\nresharper_redundant_units_highlighting=warning\nresharper_redundant_unsafe_context_highlighting=warning\nresharper_redundant_using_directive_highlighting=warning\nresharper_redundant_variable_type_specification_highlighting=hint\nresharper_redundant_verbatim_prefix_highlighting=suggestion\nresharper_redundant_verbatim_string_prefix_highlighting=suggestion\nresharper_reference_equals_with_value_type_highlighting=warning\nresharper_reg_exp_inspections_highlighting=warning\nresharper_remove_constructor_invocation_highlighting=none\nresharper_remove_redundant_braces_highlighting=none\nresharper_remove_redundant_or_statement_false_highlighting=suggestion\nresharper_remove_redundant_or_statement_true_highlighting=suggestion\nresharper_remove_to_list_1_highlighting=suggestion\nresharper_remove_to_list_2_highlighting=suggestion\nresharper_replace_indicing_with_array_destructuring_highlighting=hint\nresharper_replace_indicing_with_short_hand_properties_after_destructuring_highlighting=hint\nresharper_replace_undefined_checking_series_with_object_destructuring_highlighting=hint\nresharper_replace_with_destructuring_swap_highlighting=hint\nresharper_replace_with_first_or_default_1_highlighting=suggestion\nresharper_replace_with_first_or_default_2_highlighting=suggestion\nresharper_replace_with_first_or_default_3_highlighting=suggestion\nresharper_replace_with_first_or_default_4_highlighting=suggestion\nresharper_replace_with_last_or_default_1_highlighting=suggestion\nresharper_replace_with_last_or_default_2_highlighting=suggestion\nresharper_replace_with_last_or_default_3_highlighting=suggestion\nresharper_replace_with_last_or_default_4_highlighting=suggestion\nresharper_replace_with_of_type_1_highlighting=suggestion\nresharper_replace_with_of_type_2_highlighting=suggestion\nresharper_replace_with_of_type_3_highlighting=suggestion\nresharper_replace_with_of_type_any_1_highlighting=suggestion\nresharper_replace_with_of_type_any_2_highlighting=suggestion\nresharper_replace_with_of_type_count_1_highlighting=suggestion\nresharper_replace_with_of_type_count_2_highlighting=suggestion\nresharper_replace_with_of_type_first_1_highlighting=suggestion\nresharper_replace_with_of_type_first_2_highlighting=suggestion\nresharper_replace_with_of_type_first_or_default_1_highlighting=suggestion\nresharper_replace_with_of_type_first_or_default_2_highlighting=suggestion\nresharper_replace_with_of_type_last_1_highlighting=suggestion\nresharper_replace_with_of_type_last_2_highlighting=suggestion\nresharper_replace_with_of_type_last_or_default_1_highlighting=suggestion\nresharper_replace_with_of_type_last_or_default_2_highlighting=suggestion\nresharper_replace_with_of_type_long_count_highlighting=suggestion\nresharper_replace_with_of_type_single_1_highlighting=suggestion\nresharper_replace_with_of_type_single_2_highlighting=suggestion\nresharper_replace_with_of_type_single_or_default_1_highlighting=suggestion\nresharper_replace_with_of_type_single_or_default_2_highlighting=suggestion\nresharper_replace_with_of_type_where_highlighting=suggestion\nresharper_replace_with_simple_assignment_false_highlighting=suggestion\nresharper_replace_with_simple_assignment_true_highlighting=suggestion\nresharper_replace_with_single_assignment_false_highlighting=suggestion\nresharper_replace_with_single_assignment_true_highlighting=suggestion\nresharper_replace_with_single_call_to_any_highlighting=suggestion\nresharper_replace_with_single_call_to_count_highlighting=suggestion\nresharper_replace_with_single_call_to_first_highlighting=suggestion\nresharper_replace_with_single_call_to_first_or_default_highlighting=suggestion\nresharper_replace_with_single_call_to_last_highlighting=suggestion\nresharper_replace_with_single_call_to_last_or_default_highlighting=suggestion\nresharper_replace_with_single_call_to_single_highlighting=suggestion\nresharper_replace_with_single_call_to_single_or_default_highlighting=suggestion\nresharper_replace_with_single_or_default_1_highlighting=suggestion\nresharper_replace_with_single_or_default_2_highlighting=suggestion\nresharper_replace_with_single_or_default_3_highlighting=suggestion\nresharper_replace_with_single_or_default_4_highlighting=suggestion\nresharper_replace_with_string_is_null_or_empty_highlighting=suggestion\nresharper_required_base_types_conflict_highlighting=warning\nresharper_required_base_types_direct_conflict_highlighting=warning\nresharper_required_base_types_is_not_inherited_highlighting=warning\nresharper_requires_fallback_color_highlighting=warning\nresharper_resource_item_not_resolved_highlighting=error\nresharper_resource_not_resolved_highlighting=error\nresharper_resx_not_resolved_highlighting=warning\nresharper_return_from_global_scopet_with_value_highlighting=warning\nresharper_return_type_can_be_enumerable_global_highlighting=hint\nresharper_return_type_can_be_enumerable_local_highlighting=hint\nresharper_return_value_of_pure_method_is_not_used_highlighting=warning\nresharper_safe_cast_is_used_as_type_check_highlighting=suggestion\nresharper_same_imports_with_different_name_highlighting=warning\nresharper_same_variable_assignment_highlighting=warning\nresharper_script_tag_has_both_src_and_content_attributes_highlighting=error\nresharper_script_tag_with_content_before_includes_highlighting=hint\nresharper_sealed_member_in_sealed_class_highlighting=warning\nresharper_sensitive_data_api_usage_tag_highlighting=warning\nresharper_separate_control_transfer_statement_highlighting=none\nresharper_service_contract_without_operations_highlighting=warning\nresharper_shift_expression_real_shift_count_is_zero_highlighting=warning\nresharper_shift_expression_result_equals_zero_highlighting=warning\nresharper_shift_expression_right_operand_not_equal_real_count_highlighting=warning\nresharper_shift_expression_zero_left_operand_highlighting=warning\nresharper_similar_anonymous_type_nearby_highlighting=hint\nresharper_similar_expressions_comparison_highlighting=warning\nresharper_simplify_conditional_operator_highlighting=suggestion\nresharper_simplify_conditional_ternary_expression_highlighting=suggestion\nresharper_simplify_i_if_highlighting=suggestion\nresharper_simplify_linq_expression_highlighting=suggestion\nresharper_specify_a_culture_in_string_conversion_explicitly_highlighting=warning\nresharper_specify_string_comparison_highlighting=hint\nresharper_specify_variable_type_explicitly_highlighting=hint\nresharper_stack_alloc_inside_loop_highlighting=warning\nresharper_statement_termination_highlighting=warning\nresharper_static_member_initializer_referes_to_member_below_highlighting=warning\nresharper_static_member_in_generic_type_highlighting=warning\nresharper_static_problem_in_text_highlighting=warning\nresharper_string_compare_is_culture_specific_1_highlighting=warning\nresharper_string_compare_is_culture_specific_2_highlighting=warning\nresharper_string_compare_is_culture_specific_3_highlighting=warning\nresharper_string_compare_is_culture_specific_4_highlighting=warning\nresharper_string_compare_is_culture_specific_5_highlighting=warning\nresharper_string_compare_is_culture_specific_6_highlighting=warning\nresharper_string_compare_to_is_culture_specific_highlighting=warning\nresharper_string_concatenation_to_template_string_highlighting=hint\nresharper_string_ends_with_is_culture_specific_highlighting=none\nresharper_string_index_of_is_culture_specific_1_highlighting=warning\nresharper_string_index_of_is_culture_specific_2_highlighting=warning\nresharper_string_index_of_is_culture_specific_3_highlighting=warning\nresharper_string_last_index_of_is_culture_specific_1_highlighting=warning\nresharper_string_last_index_of_is_culture_specific_2_highlighting=warning\nresharper_string_last_index_of_is_culture_specific_3_highlighting=warning\nresharper_string_literal_as_interpolation_argument_highlighting=suggestion\nresharper_string_literal_typo_highlighting=suggestion\nresharper_string_literal_wrong_quotes_highlighting=hint\nresharper_string_starts_with_is_culture_specific_highlighting=none\nresharper_struct_can_be_made_read_only_highlighting=suggestion\nresharper_struct_member_can_be_made_read_only_highlighting=none\nresharper_suggest_base_type_for_parameter_highlighting=hint\nresharper_suggest_discard_declaration_var_style_highlighting=hint\nresharper_suggest_var_or_type_built_in_types_highlighting=hint\nresharper_suggest_var_or_type_deconstruction_declarations_highlighting=hint\nresharper_suggest_var_or_type_elsewhere_highlighting=hint\nresharper_suggest_var_or_type_simple_types_highlighting=hint\nresharper_super_call_prohibits_this_highlighting=error\nresharper_suspicious_instanceof_check_highlighting=warning\nresharper_suspicious_lambda_block_highlighting=warning\nresharper_suspicious_this_usage_highlighting=warning\nresharper_suspicious_typeof_check_highlighting=warning\nresharper_suspicious_type_conversion_global_highlighting=warning\nresharper_switch_expression_handles_some_known_enum_values_with_exception_in_default_highlighting=hint\nresharper_switch_statement_for_enum_misses_default_section_highlighting=hint\nresharper_switch_statement_handles_some_known_enum_values_with_default_highlighting=hint\nresharper_switch_statement_missing_some_enum_cases_no_default_highlighting=hint\nresharper_symbol_from_not_copied_locally_reference_used_warning_highlighting=warning\nresharper_syntax_is_not_allowed_highlighting=warning\nresharper_tabs_and_spaces_mismatch_highlighting=none\nresharper_tabs_are_disallowed_highlighting=none\nresharper_tabs_outside_indent_highlighting=none\nresharper_tail_recursive_call_highlighting=hint\nresharper_tasks_not_loaded_highlighting=warning\nresharper_ternary_can_be_replaced_by_its_condition_highlighting=warning\nresharper_this_in_global_context_highlighting=warning\nresharper_thread_static_at_instance_field_highlighting=warning\nresharper_thread_static_field_has_initializer_highlighting=warning\nresharper_throw_must_be_followed_by_expression_highlighting=error\nresharper_too_wide_local_variable_scope_highlighting=suggestion\nresharper_tree_node_enumerable_can_be_used_tag_highlighting=none\nresharper_try_cast_always_succeeds_highlighting=suggestion\nresharper_try_statements_can_be_merged_highlighting=hint\nresharper_ts_not_resolved_highlighting=error\nresharper_ts_resolved_from_inaccessible_module_highlighting=error\nresharper_type_guard_doesnt_affect_anything_highlighting=warning\nresharper_type_guard_produces_never_type_highlighting=warning\nresharper_type_parameter_can_be_variant_highlighting=suggestion\nresharper_type_parameter_hides_type_param_from_outer_scope_highlighting=warning\nresharper_ul_tag_contains_non_li_elements_highlighting=hint\nresharper_unassigned_field_compiler_highlighting=warning\nresharper_unassigned_field_global_highlighting=suggestion\nresharper_unassigned_field_local_highlighting=warning\nresharper_unassigned_get_only_auto_property_highlighting=warning\nresharper_unassigned_readonly_field_compiler_highlighting=warning\nresharper_unassigned_readonly_field_highlighting=warning\nresharper_unclosed_script_highlighting=error\nresharper_undeclared_global_variable_using_highlighting=warning\nresharper_unexpected_attribute_highlighting=warning\nresharper_unexpected_directive_highlighting=warning\nresharper_unexpected_value_highlighting=error\nresharper_unknown_css_class_highlighting=warning\nresharper_unknown_css_variable_highlighting=warning\nresharper_unknown_css_vendor_extension_highlighting=hint\nresharper_unknown_item_group_highlighting=warning\nresharper_unknown_metadata_highlighting=warning\nresharper_unknown_output_parameter_highlighting=warning\nresharper_unknown_property_highlighting=warning\nresharper_unknown_target_highlighting=warning\nresharper_unknown_task_attribute_highlighting=warning\nresharper_unknown_task_highlighting=warning\nresharper_unnecessary_whitespace_highlighting=none\nresharper_unreachable_code_highlighting=warning\nresharper_unreachable_switch_arm_due_to_integer_analysis_highlighting=warning\nresharper_unreachable_switch_case_due_to_integer_analysis_highlighting=warning\nresharper_unresolved_assembly_highlighting=warning\nresharper_unresolved_include_highlighting=warning\nresharper_unsafe_comma_in_object_properties_list_highlighting=warning\nresharper_unsupported_required_base_type_highlighting=warning\nresharper_unused_anonymous_method_signature_highlighting=warning\nresharper_unused_auto_property_accessor_global_highlighting=warning\nresharper_unused_auto_property_accessor_local_highlighting=warning\nresharper_unused_field_compiler_highlighting=warning\nresharper_unused_import_clause_highlighting=warning\nresharper_unused_inherited_parameter_highlighting=hint\nresharper_unused_label_highlighting=warning\nresharper_unused_locals_highlighting=warning\nresharper_unused_local_function_compiler_highlighting=warning\nresharper_unused_local_function_highlighting=warning\nresharper_unused_local_function_parameter_highlighting=warning\nresharper_unused_local_function_return_value_highlighting=warning\nresharper_unused_local_import_highlighting=warning\nresharper_unused_member_global_highlighting=suggestion\nresharper_unused_member_hierarchy_global_highlighting=suggestion\nresharper_unused_member_hierarchy_local_highlighting=warning\nresharper_unused_member_in_super_global_highlighting=suggestion\nresharper_unused_member_in_super_local_highlighting=warning\nresharper_unused_member_local_highlighting=warning\nresharper_unused_method_return_value_global_highlighting=suggestion\nresharper_unused_method_return_value_local_highlighting=warning\nresharper_unused_parameter_global_highlighting=suggestion\nresharper_unused_parameter_highlighting=warning\nresharper_unused_parameter_in_partial_method_highlighting=warning\nresharper_unused_parameter_local_highlighting=warning\nresharper_unused_property_highlighting=warning\nresharper_unused_tuple_component_in_return_value_highlighting=warning\nresharper_unused_type_global_highlighting=suggestion\nresharper_unused_type_local_highlighting=warning\nresharper_unused_type_parameter_highlighting=warning\nresharper_unused_variable_compiler_highlighting=warning\nresharper_unused_variable_highlighting=warning\nresharper_usage_of_definitely_unassigned_value_highlighting=warning\nresharper_usage_of_possibly_unassigned_value_highlighting=warning\nresharper_useless_binary_operation_highlighting=warning\nresharper_use_array_creation_expression_1_highlighting=suggestion\nresharper_use_array_creation_expression_2_highlighting=suggestion\nresharper_use_as_instead_of_type_cast_highlighting=hint\nresharper_use_await_using_highlighting=suggestion\nresharper_use_cancellation_token_for_i_async_enumerable_highlighting=suggestion\nresharper_use_collection_count_property_highlighting=suggestion\nresharper_use_deconstruction_highlighting=hint\nresharper_use_deconstruction_on_parameter_highlighting=hint\nresharper_use_format_specifier_in_format_string_highlighting=suggestion\nresharper_use_format_specifier_in_interpolation_highlighting=suggestion\nresharper_use_implicitly_typed_variable_evident_highlighting=hint\nresharper_use_implicitly_typed_variable_highlighting=none\nresharper_use_implicit_by_val_modifier_highlighting=hint\nresharper_use_indexed_property_highlighting=suggestion\nresharper_use_index_from_end_expression_highlighting=suggestion\nresharper_use_is_operator_1_highlighting=suggestion\nresharper_use_is_operator_2_highlighting=suggestion\nresharper_use_method_any_0_highlighting=suggestion\nresharper_use_method_any_1_highlighting=suggestion\nresharper_use_method_any_2_highlighting=suggestion\nresharper_use_method_any_3_highlighting=suggestion\nresharper_use_method_any_4_highlighting=suggestion\nresharper_use_method_is_instance_of_type_highlighting=suggestion\nresharper_use_nameof_expression_highlighting=suggestion\nresharper_use_name_of_instead_of_type_of_highlighting=suggestion\nresharper_use_negated_pattern_matching_highlighting=hint\nresharper_use_null_propagation_highlighting=suggestion\nresharper_use_null_propagation_when_possible_highlighting=none\nresharper_use_object_or_collection_initializer_highlighting=suggestion\nresharper_use_of_implicit_global_in_function_scope_highlighting=warning\nresharper_use_of_possibly_unassigned_property_highlighting=warning\nresharper_use_pattern_matching_highlighting=suggestion\nresharper_use_string_interpolation_highlighting=suggestion\nresharper_use_switch_case_pattern_variable_highlighting=suggestion\nresharper_use_verbatim_string_highlighting=hint\nresharper_using_of_reserved_word_error_highlighting=error\nresharper_using_of_reserved_word_highlighting=warning\nresharper_value_parameter_not_used_highlighting=warning\nresharper_value_should_have_units_highlighting=error\nresharper_variable_can_be_made_const_highlighting=hint\nresharper_variable_can_be_made_let_highlighting=hint\nresharper_variable_can_be_moved_to_inner_block_highlighting=hint\nresharper_variable_hides_outer_variable_highlighting=warning\nresharper_variable_used_before_declared_highlighting=warning\nresharper_variable_used_in_inner_scope_before_declared_highlighting=warning\nresharper_variable_used_out_of_scope_highlighting=warning\nresharper_vb_check_for_reference_equality_instead_1_highlighting=suggestion\nresharper_vb_check_for_reference_equality_instead_2_highlighting=suggestion\nresharper_vb_possible_mistaken_argument_highlighting=warning\nresharper_vb_possible_mistaken_call_to_get_type_1_highlighting=warning\nresharper_vb_possible_mistaken_call_to_get_type_2_highlighting=warning\nresharper_vb_remove_to_list_1_highlighting=suggestion\nresharper_vb_remove_to_list_2_highlighting=suggestion\nresharper_vb_replace_with_first_or_default_highlighting=suggestion\nresharper_vb_replace_with_last_or_default_highlighting=suggestion\nresharper_vb_replace_with_of_type_1_highlighting=suggestion\nresharper_vb_replace_with_of_type_2_highlighting=suggestion\nresharper_vb_replace_with_of_type_any_1_highlighting=suggestion\nresharper_vb_replace_with_of_type_any_2_highlighting=suggestion\nresharper_vb_replace_with_of_type_count_1_highlighting=suggestion\nresharper_vb_replace_with_of_type_count_2_highlighting=suggestion\nresharper_vb_replace_with_of_type_first_1_highlighting=suggestion\nresharper_vb_replace_with_of_type_first_2_highlighting=suggestion\nresharper_vb_replace_with_of_type_first_or_default_1_highlighting=suggestion\nresharper_vb_replace_with_of_type_first_or_default_2_highlighting=suggestion\nresharper_vb_replace_with_of_type_last_1_highlighting=suggestion\nresharper_vb_replace_with_of_type_last_2_highlighting=suggestion\nresharper_vb_replace_with_of_type_last_or_default_1_highlighting=suggestion\nresharper_vb_replace_with_of_type_last_or_default_2_highlighting=suggestion\nresharper_vb_replace_with_of_type_single_1_highlighting=suggestion\nresharper_vb_replace_with_of_type_single_2_highlighting=suggestion\nresharper_vb_replace_with_of_type_single_or_default_1_highlighting=suggestion\nresharper_vb_replace_with_of_type_single_or_default_2_highlighting=suggestion\nresharper_vb_replace_with_of_type_where_highlighting=suggestion\nresharper_vb_replace_with_single_assignment_1_highlighting=suggestion\nresharper_vb_replace_with_single_assignment_2_highlighting=suggestion\nresharper_vb_replace_with_single_call_to_any_highlighting=suggestion\nresharper_vb_replace_with_single_call_to_count_highlighting=suggestion\nresharper_vb_replace_with_single_call_to_first_highlighting=suggestion\nresharper_vb_replace_with_single_call_to_first_or_default_highlighting=suggestion\nresharper_vb_replace_with_single_call_to_last_highlighting=suggestion\nresharper_vb_replace_with_single_call_to_last_or_default_highlighting=suggestion\nresharper_vb_replace_with_single_call_to_single_highlighting=suggestion\nresharper_vb_replace_with_single_call_to_single_or_default_highlighting=suggestion\nresharper_vb_replace_with_single_or_default_highlighting=suggestion\nresharper_vb_simplify_linq_expression_10_highlighting=hint\nresharper_vb_simplify_linq_expression_1_highlighting=suggestion\nresharper_vb_simplify_linq_expression_2_highlighting=suggestion\nresharper_vb_simplify_linq_expression_3_highlighting=suggestion\nresharper_vb_simplify_linq_expression_4_highlighting=suggestion\nresharper_vb_simplify_linq_expression_5_highlighting=suggestion\nresharper_vb_simplify_linq_expression_6_highlighting=suggestion\nresharper_vb_simplify_linq_expression_7_highlighting=hint\nresharper_vb_simplify_linq_expression_8_highlighting=hint\nresharper_vb_simplify_linq_expression_9_highlighting=hint\nresharper_vb_string_compare_is_culture_specific_1_highlighting=warning\nresharper_vb_string_compare_is_culture_specific_2_highlighting=warning\nresharper_vb_string_compare_is_culture_specific_3_highlighting=warning\nresharper_vb_string_compare_is_culture_specific_4_highlighting=warning\nresharper_vb_string_compare_is_culture_specific_5_highlighting=warning\nresharper_vb_string_compare_is_culture_specific_6_highlighting=warning\nresharper_vb_string_compare_to_is_culture_specific_highlighting=warning\nresharper_vb_string_ends_with_is_culture_specific_highlighting=none\nresharper_vb_string_index_of_is_culture_specific_1_highlighting=warning\nresharper_vb_string_index_of_is_culture_specific_2_highlighting=warning\nresharper_vb_string_index_of_is_culture_specific_3_highlighting=warning\nresharper_vb_string_last_index_of_is_culture_specific_1_highlighting=warning\nresharper_vb_string_last_index_of_is_culture_specific_2_highlighting=warning\nresharper_vb_string_last_index_of_is_culture_specific_3_highlighting=warning\nresharper_vb_string_starts_with_is_culture_specific_highlighting=none\nresharper_vb_unreachable_code_highlighting=warning\nresharper_vb_use_array_creation_expression_1_highlighting=suggestion\nresharper_vb_use_array_creation_expression_2_highlighting=suggestion\nresharper_vb_use_first_instead_highlighting=warning\nresharper_vb_use_method_any_1_highlighting=suggestion\nresharper_vb_use_method_any_2_highlighting=suggestion\nresharper_vb_use_method_any_3_highlighting=suggestion\nresharper_vb_use_method_any_4_highlighting=suggestion\nresharper_vb_use_method_any_5_highlighting=suggestion\nresharper_vb_use_method_is_instance_of_type_highlighting=suggestion\nresharper_vb_use_type_of_is_operator_1_highlighting=suggestion\nresharper_vb_use_type_of_is_operator_2_highlighting=suggestion\nresharper_vb_warnings_bc400005_highlighting=warning\nresharper_vb_warnings_bc40000_highlighting=warning\nresharper_vb_warnings_bc40008_highlighting=warning\nresharper_vb_warnings_bc40056_highlighting=warning\nresharper_vb_warnings_bc42016_highlighting=warning\nresharper_vb_warnings_bc42025_highlighting=warning\nresharper_vb_warnings_bc42104_highlighting=warning\nresharper_vb_warnings_bc42105_bc42106_bc42107_highlighting=warning\nresharper_vb_warnings_bc42304_highlighting=warning\nresharper_vb_warnings_bc42309_highlighting=warning\nresharper_vb_warnings_bc42322_highlighting=warning\nresharper_vb_warnings_bc42349_highlighting=warning\nresharper_vb_warnings_bc42353_bc42354_bc42355_highlighting=warning\nresharper_vb_warnings_bc42356_highlighting=warning\nresharper_vb_warnings_bc42358_highlighting=warning\nresharper_vb_warnings_wme006_highlighting=warning\nresharper_virtual_member_call_in_constructor_highlighting=warning\nresharper_virtual_member_never_overridden_global_highlighting=suggestion\nresharper_virtual_member_never_overridden_local_highlighting=suggestion\nresharper_void_method_with_must_use_return_value_attribute_highlighting=warning\nresharper_web_config_module_not_resolved_highlighting=warning\nresharper_web_config_module_qualification_resolve_highlighting=warning\nresharper_web_config_redundant_add_namespace_tag_highlighting=warning\nresharper_web_config_redundant_location_tag_highlighting=warning\nresharper_web_config_tag_prefix_redundand_highlighting=warning\nresharper_web_config_type_not_resolved_highlighting=warning\nresharper_web_config_unused_add_tag_highlighting=warning\nresharper_web_config_unused_element_due_to_config_source_attribute_highlighting=warning\nresharper_web_config_unused_remove_or_clear_tag_highlighting=warning\nresharper_web_config_web_config_path_warning_highlighting=warning\nresharper_web_config_wrong_module_highlighting=warning\nresharper_web_ignored_path_highlighting=none\nresharper_web_mapped_path_highlighting=hint\nresharper_with_statement_using_error_highlighting=error\nresharper_wrong_expression_statement_highlighting=warning\nresharper_wrong_indent_size_highlighting=none\nresharper_wrong_metadata_use_highlighting=none\nresharper_wrong_public_modifier_specification_highlighting=hint\nresharper_wrong_require_relative_path_highlighting=hint\nresharper_xaml_binding_without_context_not_resolved_highlighting=hint\nresharper_xaml_binding_with_context_not_resolved_highlighting=warning\nresharper_xaml_constructor_warning_highlighting=warning\nresharper_xaml_dependency_property_resolve_error_highlighting=warning\nresharper_xaml_duplicate_style_setter_highlighting=warning\nresharper_xaml_dynamic_resource_error_highlighting=error\nresharper_xaml_element_name_reference_not_resolved_highlighting=error\nresharper_xaml_ignored_path_highlighting_highlighting=none\nresharper_xaml_index_out_of_grid_definition_highlighting=warning\nresharper_xaml_invalid_member_type_highlighting=error\nresharper_xaml_invalid_resource_target_type_highlighting=error\nresharper_xaml_invalid_resource_type_highlighting=error\nresharper_xaml_invalid_type_highlighting=error\nresharper_xaml_language_level_highlighting=error\nresharper_xaml_mapped_path_highlighting_highlighting=hint\nresharper_xaml_missing_grid_index_highlighting=warning\nresharper_xaml_path_error_highlighting=warning\nresharper_xaml_redundant_attached_property_highlighting=warning\nresharper_xaml_redundant_collection_property_highlighting=warning\nresharper_xaml_redundant_freeze_attribute_highlighting=warning\nresharper_xaml_redundant_grid_definitions_highlighting=warning\nresharper_xaml_redundant_grid_span_highlighting=warning\nresharper_xaml_redundant_modifiers_attribute_highlighting=warning\nresharper_xaml_redundant_namespace_alias_highlighting=warning\nresharper_xaml_redundant_name_attribute_highlighting=warning\nresharper_xaml_redundant_property_type_qualifier_highlighting=warning\nresharper_xaml_redundant_resource_highlighting=warning\nresharper_xaml_redundant_styled_value_highlighting=warning\nresharper_xaml_redundant_xamarin_forms_class_declaration_highlighting=warning\nresharper_xaml_routed_event_resolve_error_highlighting=warning\nresharper_xaml_static_resource_not_resolved_highlighting=warning\nresharper_xaml_style_invalid_target_type_highlighting=error\nresharper_xaml_unexpected_text_token_highlighting=error\nresharper_xaml_xaml_duplicate_device_family_type_view_highlighting_highlighting=error\nresharper_xaml_xaml_mismatched_device_family_view_clr_name_highlighting_highlighting=warning\nresharper_xaml_xaml_relative_source_default_mode_warning_highlighting_highlighting=warning\nresharper_xaml_xaml_unknown_device_family_type_highlighting_highlighting=warning\nresharper_xaml_xaml_xamarin_forms_data_type_and_binding_context_type_mismatched_highlighting_highlighting=warning\nresharper_xaml_x_key_attribute_disallowed_highlighting=error\nresharper_xml_doc_comment_syntax_problem_highlighting=warning\nresharper_xunit_xunit_test_with_console_output_highlighting=warning\nresharper_x_unit1000_highlighting=error\nresharper_x_unit1001_highlighting=error\nresharper_x_unit1002_highlighting=error\nresharper_x_unit1003_highlighting=error\nresharper_x_unit1004_highlighting=hint\nresharper_x_unit1005_highlighting=warning\nresharper_x_unit1006_highlighting=warning\nresharper_x_unit1007_highlighting=error\nresharper_x_unit1008_highlighting=warning\nresharper_x_unit1009_highlighting=error\nresharper_x_unit1010_highlighting=error\nresharper_x_unit1011_highlighting=error\nresharper_x_unit1012_highlighting=warning\nresharper_x_unit1013_highlighting=warning\nresharper_x_unit1014_highlighting=warning\nresharper_x_unit1015_highlighting=error\nresharper_x_unit1016_highlighting=error\nresharper_x_unit1017_highlighting=error\nresharper_x_unit1018_highlighting=error\nresharper_x_unit1019_highlighting=error\nresharper_x_unit1020_highlighting=error\nresharper_x_unit1021_highlighting=warning\nresharper_x_unit1022_highlighting=error\nresharper_x_unit1023_highlighting=error\nresharper_x_unit1024_highlighting=error\nresharper_x_unit1025_highlighting=warning\nresharper_x_unit1026_highlighting=warning\nresharper_x_unit2000_highlighting=warning\nresharper_x_unit2001_highlighting=none\nresharper_x_unit2002_highlighting=warning\nresharper_x_unit2003_highlighting=warning\nresharper_x_unit2004_highlighting=warning\nresharper_x_unit2005_highlighting=warning\nresharper_x_unit2006_highlighting=warning\nresharper_x_unit2007_highlighting=warning\nresharper_x_unit2008_highlighting=warning\nresharper_x_unit2009_highlighting=warning\nresharper_x_unit2010_highlighting=warning\nresharper_x_unit2011_highlighting=warning\nresharper_x_unit2012_highlighting=warning\nresharper_x_unit2013_highlighting=warning\nresharper_x_unit2014_highlighting=error\nresharper_x_unit2015_highlighting=warning\nresharper_x_unit2016_highlighting=error\nresharper_x_unit2017_highlighting=warning\nresharper_x_unit2018_highlighting=warning\nresharper_x_unit2019_highlighting=none\nresharper_x_unit3000_highlighting=error\nresharper_x_unit3001_highlighting=error\n\n[{*.har,*.jsb2,*.jsb3,*.json,.babelrc,.eslintrc,.stylelintrc,bowerrc,jest.config}]\nindent_style=space\nindent_size=2\n\n[*.scss]\nindent_style=space\nindent_size=2\n\n[*.js.map]\nindent_style=space\nindent_size=2\n\n[*.{appxmanifest,asax,ascx,aspx,build,cs,cshtml,dtd,master,nuspec,razor,resw,resx,skin,vb,xaml,xamlx,xoml,xsd}]\nindent_style=space\nindent_size=4\ntab_width=4\n"
  },
  {
    "path": ".gitattributes",
    "content": "###############################################################################\n# Set default behavior to automatically normalize line endings.\n###############################################################################\n* text=auto\n\n###############################################################################\n# Set default behavior for command prompt diff.\n#\n# This is need for earlier builds of msysgit that does not have it on by\n# default for csharp files.\n# Note: This is only used by command line\n###############################################################################\n#*.cs     diff=csharp\n\n###############################################################################\n# Set the merge driver for project and solution files\n#\n# Merging from the command prompt will add diff markers to the files if there\n# are conflicts (Merging from VS is not affected by the settings below, in VS\n# the diff markers are never inserted). Diff markers may cause the following \n# file extensions to fail to load in VS. An alternative would be to treat\n# these files as binary and thus will always conflict and require user\n# intervention with every merge. To do so, just uncomment the entries below\n###############################################################################\n#*.sln       merge=binary\n#*.csproj    merge=binary\n#*.vbproj    merge=binary\n#*.vcxproj   merge=binary\n#*.vcproj    merge=binary\n#*.dbproj    merge=binary\n#*.fsproj    merge=binary\n#*.lsproj    merge=binary\n#*.wixproj   merge=binary\n#*.modelproj merge=binary\n#*.sqlproj   merge=binary\n#*.wwaproj   merge=binary\n\n###############################################################################\n# behavior for image files\n#\n# image files are treated as binary by default.\n###############################################################################\n#*.jpg   binary\n#*.png   binary\n#*.gif   binary\n\n###############################################################################\n# diff behavior for common document formats\n# \n# Convert binary document formats to text before diffing them. This feature\n# is only available from the command line. Turn it on by uncommenting the \n# entries below.\n###############################################################################\n#*.doc   diff=astextplain\n#*.DOC   diff=astextplain\n#*.docx  diff=astextplain\n#*.DOCX  diff=astextplain\n#*.dot   diff=astextplain\n#*.DOT   diff=astextplain\n#*.pdf   diff=astextplain\n#*.PDF   diff=astextplain\n#*.rtf   diff=astextplain\n#*.RTF   diff=astextplain\n"
  },
  {
    "path": ".github/CONTRIBUTING.md",
    "content": "# How to contribute\n\nThe easiest way to contribute is to open an issue and start a discussion. \nThen we can decide if and how a feature or a change could be implemented and if you should submit a pull requests with code changes.\n\nAlso read this first: [Being a good open source citizen](https://hackernoon.com/being-a-good-open-source-citizen-9060d0ab9732#.x3hocgw85)\n\n## Found an issue or a bug?\nPlease start a discussion on the [core repo issue tracker](https://github.com/alexhiggins732/IdentityServer4/issues).\n\n## Filing issues\nThe best way to get your bug fixed is to be as detailed as you can be about the problem.\nProviding a minimal project with steps to reproduce the problem is ideal.\nHere are questions you can answer before you file a bug to make sure you're not missing any important information.\n\n1. Did you read the [documentation](https://identityserver8.readthedocs.io/en/latest/)?\n2. Did you include the snippet of broken code in the issue?\n3. What are the *EXACT* steps to reproduce this problem?\n4. Did you enable [logging](https://identityserver8.readthedocs.io/en/latest/topics/logging.html)?\n\nGitHub supports [markdown](http://github.github.com/github-flavored-markdown/), so when filing bugs make sure you check the formatting before clicking submit.\n\n## Contributing code and content\nYou will need to sign a contributor license agreement (CLA) before submitting your pull request. The first time you submit a PR, a bot will take you through that process.\n\nPlease make sure to include tests, that cover the changes/additions you made to the code base.\n\nMake sure you can build the code. Familiarize yourself with the project workflow and our coding conventions. If you don't know what a pull request is read this article: https://help.github.com/articles/using-pull-requests.\n\nBefore submitting a feature or substantial code contribution please discuss it with the team and ensure it follows the product roadmap. Here's a list of blog posts that are worth reading before doing a pull request:\n\n* [Open Source Contribution Etiquette](http://tirania.org/blog/archive/2010/Dec-31.html) by Miguel de Icaza\n* [Don't \"Push\" Your Pull Requests](http://www.igvita.com/2011/12/19/dont-push-your-pull-requests/) by Ilya Grigorik.\n* [10 tips for better Pull Requests](http://blog.ploeh.dk/2015/01/15/10-tips-for-better-pull-requests/) by Mark Seemann\n* [How to write the perfect pull request](https://github.com/blog/1943-how-to-write-the-perfect-pull-request) by GitHub\n"
  },
  {
    "path": ".github/FUNDING.yml",
    "content": "# These are supported funding model platforms\n\ngithub: alexhiggins732\npatreon: alexhiggins732\nopen_collective: # Replace with a single Open Collective username\nko_fi: # Replace with a single Ko-fi username\ntidelift: # Replace with a single Tidelift platform-name/package-name e.g., npm/babel\ncommunity_bridge: # Replace with a single Community Bridge project-name e.g., cloud-foundry\nliberapay: # Replace with a single Liberapay username\nissuehunt: # Replace with a single IssueHunt username\notechie: # Replace with a single Otechie username\ncustom: https://www.paypal.me/alexhiggins732\n"
  },
  {
    "path": ".github/ISSUE_TEMPLATE/Question.md",
    "content": "<!--\n  ⚠️ ⚠️ ⚠️ ⚠️ ⚠️ ⚠️\nQuestions are community supported only and the authors/maintainers may or may not have time to reply. If you or your company would like commercial support, please see [here](https://identityserver8.readthedocs.io/en/latest/intro/support.html#commercial-support) for more information.\n  ⚠️ ⚠️ ⚠️ ⚠️ ⚠️ ⚠️\n-->\n\n---\nname: Question\nabout: Ask a question.\ntitle: ''\nlabels: question\nassignees: skoruba\n\n---\n\n### Question\n\n\n### Minimal working example\n\n```csharp\n   // <code goes here>\n```\n\n### Relevant parts of the log file\n\n```\n   <log goes here>\n```\n"
  },
  {
    "path": ".github/ISSUE_TEMPLATE/bug_report.md",
    "content": "---\nname: Bug report\nabout: Create a report to help us improve\ntitle: ''\nlabels: bug report\n\n\n---\n\n### Describe the bug\nA clear and concise description of what the bug is.\n\n### To Reproduce\nSteps to reproduce the behavior:\n\n### Relevant parts of the log file\n\n```\n<log goes here>\n```\n"
  },
  {
    "path": ".github/ISSUE_TEMPLATE/feature_request.md",
    "content": "---\nname: Feature request\nabout: Suggest an idea for this project\ntitle: ''\nlabels: enhancement\n\n\n---\n\n**Is your feature request related to a problem? Please describe.**\nA clear and concise description of what the problem is. Ex. I'm always frustrated when [...]\n\n**Describe the solution you'd like**\nA clear and concise description of what you want to happen.\n\n**Describe alternatives you've considered**\nA clear and concise description of any alternative solutions or features you've considered.\n\n**Additional context**\nAdd any other context or screenshots about the feature request here.\n"
  },
  {
    "path": ".github/PULL_REQUEST_TEMPLATE.md",
    "content": "---\nname: Bug report\nabout: Create a report to help us improve\nlabels: bug report\n---\n\n**We can only help you if you are on the latest version.**\n\nPlease only use the issue tracker for bug reports and/or feature requests. For general security questions, or free or commercial support options do __not__ use the issue tracker and instead see [here](http://identityserver8.readthedocs.io/en/latest/intro/support.html) for more details.\n\nFor bug reports,  include the relevant log files related to your issue. See here how to enable [logging](https://identityserver8.readthedocs.io/en/latest/topics/logging.html). Delete this line once you have.\n\nFinally, please keep the issue concise and to the point. If you paste in more code than the text for the issue you are reporting then we will most likely not read it. \n\n### Issue / Steps to reproduce the problem\n\n\n\n### Relevant parts of the log file\n\n```\n<log goes here>\n```"
  },
  {
    "path": ".github/dependabot.yml",
    "content": "# To get started with Dependabot version updates, you'll need to specify which\n# package ecosystems to update and where the package manifests are located.\n# Please see the documentation for all configuration options:\n# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file\n\nversion: 2\nupdates:\n  - package-ecosystem: \"nuget\" # See documentation for possible values\n    directory: \"/\" # Location of package manifests\n    schedule:\n      interval: \"daily\"\n    open-pull-requests-limit: 25\n"
  },
  {
    "path": ".github/workflows/codeql.yml",
    "content": "# For most projects, this workflow file will not need changing; you simply need\n# to commit it to your repository.\n#\n# You may wish to alter this file to override the set of languages analyzed,\n# or to provide custom queries or build logic.\n#\n# ******** NOTE ********\n# We have attempted to detect the languages in your repository. Please check\n# the `language` matrix defined below to confirm you have the correct set of\n# supported CodeQL languages.\n#\nname: \"CodeQL\"\n\non:\n  push:\n    branches: [ \"master\", \"develop\", \"release/*\" ]\n    paths-ignore:\n    - '**/README.md'\n    - '**/docs'\n    - '.github/**'\n    - \"docs/**\"\n    - \".git/*\"\n    - \".vs/*\"\n    - \".config/*\"\n    - \".github/*\"\n    - \"Directory.Build.props\"\n    - \"Directory.Build.targets\"\n    - \"Directory.Build.props\"\n    - \"docker-compose.yml\"\n    - \"docker-compose.override.yml\"\n    - \"docker-compose.vs.debug.yml\"\n    - \"docker-compose.vs.release.yml\"\n    - \"docker-compose.dcrpoj\"\n    - \"**/*.sln\"\n    - \"global.json\"\n    - \"IdentityServer8.DotNet.ruleset\"\n    - \"LICENSCE\"\n    - \"version.json\"\n    - \"Nuget.config\"\n    - \"SECURITY.md\"\n    - \"SPONSORS.md\"\n    - \"README.md\"\n    - \"samples\"\n    - \"nuget\"\n  pull_request:\n    branches: [ \"master\", \"develop\", \"release/*\" ]\n\n  schedule:\n    - cron: '23 4 * * 1'\n\njobs:\n  analyze:\n    name: Analyze\n    # Runner size impacts CodeQL analysis time. To learn more, please see:\n    #   - https://gh.io/recommended-hardware-resources-for-running-codeql\n    #   - https://gh.io/supported-runners-and-hardware-resources\n    #   - https://gh.io/using-larger-runners\n    # Consider using larger runners for possible analysis time improvements.\n    runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}\n    timeout-minutes: ${{ (matrix.language == 'swift' && 120) || 360 }}\n    permissions:\n      # required for all workflows\n      security-events: write\n\n      # only required for workflows in private repositories\n      actions: read\n      contents: read\n\n    strategy:\n      fail-fast: false\n      matrix:\n        language: [ 'csharp', 'javascript-typescript' ]\n        # CodeQL supports [ 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'swift' ]\n        # Use only 'java-kotlin' to analyze code written in Java, Kotlin or both\n        # Use only 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both\n        # Learn more about CodeQL language support at https://aka.ms/codeql-docs/language-support\n\n    steps:\n    - name: Checkout repository\n      uses: actions/checkout@v4\n\n    # Initializes the CodeQL tools for scanning.\n    - name: Initialize CodeQL\n      uses: github/codeql-action/init@v3\n      with:\n        languages: ${{ matrix.language }}\n        # If you wish to specify custom queries, you can do so here or in a config file.\n        # By default, queries listed here will override any specified in a config file.\n        # Prefix the list here with \"+\" to use these queries and those in the config file.\n\n        # For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs\n        # queries: security-extended,security-and-quality\n\n\n    # Autobuild attempts to build any compiled languages (C/C++, C#, Go, Java, or Swift).\n    # If this step fails, then you should remove it and run the build manually (see below)\n    #- name: Autobuild\n    #  uses: github/codeql-action/autobuild@v3\n\n    # ℹ️ Command-line programs to run using the OS shell.\n    # 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun\n\n    #   If the Autobuild fails above, remove it and uncomment the following three lines.\n    #   modify them (or add more) to build your code if your project, please refer to the EXAMPLE below for guidance.\n\n    - name: Restore dependencies\n      if: ${{ (matrix.language == 'csharp') }} \n      run: dotnet restore src/IdentityServer8.sln\n    - name: Build\n      if: ${{ (matrix.language == 'csharp') }} \n      run: dotnet build src/IdentityServer8.sln --configuration Release --no-restore\n\n    - name: Perform CodeQL Analysis\n      uses: github/codeql-action/analyze@v3\n      with:\n        category: \"/language:${{matrix.language}}\"\n"
  },
  {
    "path": ".github/workflows/develop.yml",
    "content": "# This workflow will build a .NET project\n# For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-net\n\nname: Develop\n\non:\n  push:\n    branches:\n    - develop\n    paths-ignore:\n    - '**/README.md'\n    - '**/docs'\n    - '.github/**'\n    - \"docs/**\"\n    - \".git/*\"\n    - \".vs/*\"\n    - \".config/*\"\n    - \".github/*\"\n    - \"Directory.Build.props\"\n    - \"Directory.Build.targets\"\n    - \"Directory.Build.props\"\n    - \"docker-compose.yml\"\n    - \"docker-compose.override.yml\"\n    - \"docker-compose.vs.debug.yml\"\n    - \"docker-compose.vs.release.yml\"\n    - \"docker-compose.dcrpoj\"\n    - \"**/*.sln\"\n    - \"global.json\"\n    - \"IdentityServer8.DotNet.ruleset\"\n    - \"LICENSCE\"\n    - \"Nuget.config\"\n    - \"SECURITY.md\"\n    - \"SPONSORS.md\"\n    - \"README.md\"\n    - \"samples\"\n    - \"nuget\"\n\njobs:\n  build:\n    strategy:\n      fail-fast: false\n      matrix:\n        runs-on: [macOS-latest, ubuntu-latest, windows-latest]\n    name: ${{ matrix.runs-on }}\n    runs-on: ${{ matrix.runs-on }}\n    steps:\n    - uses: actions/checkout@v3\n      with:        \n        fetch-depth: 0\n    - name: Setup .NET\n      uses: actions/setup-dotnet@v3\n      with:\n        dotnet-version: 8.0.x\n\n\n    - uses: dotnet/nbgv@master\n      id: nbgv\n\n    - name: Display Package Version\n      run: echo \"PackageVersion=${{ steps.nbgv.outputs.SemVer2 }}\"\n\n    - name: Restore dependencies\n      run: dotnet restore src/IdentityServer8.sln\n    - name: Build\n      run: dotnet build src/IdentityServer8.sln --configuration Release --no-restore -p:Version=${{ steps.nbgv.outputs.SemVer2 }}\n    - name: Test\n      run: dotnet test src/IdentityServer8.sln --configuration Release --no-build --verbosity normal /p:CollectCoverage=true --collect:\"XPlat Code Coverage\" -- DataCollectionRunSettings.DataCollectors.DataCollector.Configuration.Format=cobertura\n\n    - name: Upload coverage reports to Codecov\n      uses: codecov/codecov-action@v4.0.1\n      env:\n        token: ${{ secrets.CODECOV_TOKEN }}\n        slug: alexhiggins732/IdentityServer8\n        CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}\n\n    - name: Push\n      if: ${{ (github.event_name == 'push') && (runner.os == 'Windows') }} \n      run: dotnet nuget push .\\nuget\\*.nupkg  --skip-duplicate --source https://api.nuget.org/v3/index.json --api-key ${{ secrets.NUGET_API_KEY }}\n\n"
  },
  {
    "path": ".github/workflows/master.yml",
    "content": "# This workflow will build a .NET project\n# For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-net\n\nname: Master\n\non:\n  push:\n    branches:\n    - master\n    paths-ignore:\n    - '**/README.md'\n    - '**/docs'\n    - '.github/**'\n    - \"docs/**\"\n    - \".git/*\"\n    - \".vs/*\"\n    - \".config/*\"\n    - \".github/*\"\n    - \"Directory.Build.props\"\n    - \"Directory.Build.targets\"\n    - \"Directory.Build.props\"\n    - \"docker-compose.yml\"\n    - \"docker-compose.override.yml\"\n    - \"docker-compose.vs.debug.yml\"\n    - \"docker-compose.vs.release.yml\"\n    - \"docker-compose.dcrpoj\"\n    - \"**/*.sln\"\n    - \"global.json\"\n    - \"IdentityServer8.DotNet.ruleset\"\n    - \"LICENSCE\"\n    - \"Nuget.config\"\n    - \"SECURITY.md\"\n    - \"SPONSORS.md\"\n    - \"README.md\"\n    - \"samples\"\n    - \"nuget\"\n\njobs:\n  build:\n    strategy:\n      fail-fast: false\n      matrix:\n        runs-on: [macOS-latest, ubuntu-latest, windows-latest]\n    name: ${{ matrix.runs-on }}\n    runs-on: ${{ matrix.runs-on }}\n    steps:\n    - uses: actions/checkout@v3\n      with:        \n        fetch-depth: 0\n    - name: Setup .NET\n      uses: actions/setup-dotnet@v3\n      with:\n        dotnet-version: 8.0.x\n\n\n    - uses: dotnet/nbgv@master\n      id: nbgv\n    - name: Display Package Version\n      run: echo \"PackageVersion=${{ steps.nbgv.outputs.SimpleVersion }}\"\n\n    - name: Restore dependencies\n      run: dotnet restore src/IdentityServer8.sln\n    - name: Build\n      run: dotnet build src/IdentityServer8.sln --configuration Release --no-restore -p:Version=${{ steps.nbgv.outputs.SimpleVersion }}\n    - name: Test\n      run: dotnet test src/IdentityServer8.sln --configuration Release --no-build --verbosity normal /p:CollectCoverage=true --collect:\"XPlat Code Coverage\" -- DataCollectionRunSettings.DataCollectors.DataCollector.Configuration.Format=cobertura\n\n    - name: Upload coverage reports to Codecov\n      uses: codecov/codecov-action@v4.0.1\n      env:\n        token: ${{ secrets.CODECOV_TOKEN }}\n        slug: alexhiggins732/IdentityServer8\n        CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}\n\n    - name: Push\n      if: ${{ (github.event_name == 'push') && (runner.os == 'Windows') }} \n      run: dotnet nuget push .\\nuget\\*.nupkg  --skip-duplicate --source https://api.nuget.org/v3/index.json --api-key ${{ secrets.NUGET_API_KEY }}\n\n"
  },
  {
    "path": ".github/workflows/pre-release.yml",
    "content": "# This workflow will build a .NET project\n# For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-net\n\nname: CI\n\non:\n  push:\n    branches-ignore:\n    - develop\n    - release/*\n    - master\n    paths-ignore:\n    - '**/README.md'\n    - '**/docs'\n    - '.github/**'\n    - \"docs/**\"\n    - \".git/*\"\n    - \".vs/*\"\n    - \".config/*\"\n    - \".github/*\"\n    - \"Directory.Build.props\"\n    - \"Directory.Build.targets\"\n    - \"Directory.Build.props\"\n    - \"docker-compose.yml\"\n    - \"docker-compose.override.yml\"\n    - \"docker-compose.vs.debug.yml\"\n    - \"docker-compose.vs.release.yml\"\n    - \"docker-compose.dcrpoj\"\n    - \"**/*.sln\"\n    - \"global.json\"\n    - \"IdentityServer8.DotNet.ruleset\"\n    - \"LICENSCE\"\n    - \"Nuget.config\"\n    - \"SECURITY.md\"\n    - \"SPONSORS.md\"\n    - \"README.md\"\n    - \"samples\"\n    - \"nuget\"\n\njobs:\n  build:\n    strategy:\n      fail-fast: false\n      matrix:\n        runs-on: [macOS-latest, ubuntu-latest, windows-latest]\n    name: ${{ matrix.runs-on }}\n    runs-on: ${{ matrix.runs-on }}\n    steps:\n    - uses: actions/checkout@v3\n      with:        \n        fetch-depth: 0\n    - name: Setup .NET\n      uses: actions/setup-dotnet@v3\n      with:\n        dotnet-version: 8.0.x\n\n\n    - uses: dotnet/nbgv@master\n      id: nbgv\n\n    - name: Display Package Version\n      run: echo \"PackageVersion=${{ steps.nbgv.outputs.SimpleVersion }}-ci.${{ steps.nbgv.outputs.VersionRevision }}\"\n\n\n\n    - name: Restore dependencies\n      run: dotnet restore src/IdentityServer8.sln\n    - name: Build\n      run: dotnet build src/IdentityServer8.sln --configuration Release --no-restore -p:Version=${{ steps.nbgv.outputs.SimpleVersion }}-ci.${{ steps.nbgv.outputs.VersionRevision }}\n    - name: Test\n      run: dotnet test src/IdentityServer8.sln --configuration Release --no-build --verbosity normal /p:CollectCoverage=true --collect:\"XPlat Code Coverage\" -- DataCollectionRunSettings.DataCollectors.DataCollector.Configuration.Format=cobertura\n\n    - name: Upload coverage reports to Codecov\n      uses: codecov/codecov-action@v4.0.1\n      env:\n        token: ${{ secrets.CODECOV_TOKEN }}\n        slug: alexhiggins732/IdentityServer8\n        CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}\n\n"
  },
  {
    "path": ".github/workflows/release.yml",
    "content": "# This workflow will build a .NET project\n# For more information see: https://docs.github.com/en/actions/automating-builds-and-tests/building-and-testing-net\n\nname: Release\n\non:\n  push:\n    branches:\n    - release/*\n    paths-ignore:\n    - '**/README.md'\n    - '**/docs'\n    - '.github/**'\n    - \"docs/**\"\n    - \".git/*\"\n    - \".vs/*\"\n    - \".config/*\"\n    - \".github/*\"\n    - \"Directory.Build.props\"\n    - \"Directory.Build.targets\"\n    - \"Directory.Build.props\"\n    - \"docker-compose.yml\"\n    - \"docker-compose.override.yml\"\n    - \"docker-compose.vs.debug.yml\"\n    - \"docker-compose.vs.release.yml\"\n    - \"docker-compose.dcrpoj\"\n    - \"**/*.sln\"\n    - \"global.json\"\n    - \"IdentityServer8.DotNet.ruleset\"\n    - \"LICENSCE\"\n    - \"Nuget.config\"\n    - \"SECURITY.md\"\n    - \"SPONSORS.md\"\n    - \"README.md\"\n    - \"samples\"\n    - \"nuget\"\n\njobs:\n  build:\n    strategy:\n      fail-fast: false\n      matrix:\n        runs-on: [macOS-latest, ubuntu-latest, windows-latest]\n    name: ${{ matrix.runs-on }}\n    runs-on: ${{ matrix.runs-on }}\n    steps:\n    - uses: actions/checkout@v3\n      with:        \n        fetch-depth: 0\n    - name: Setup .NET\n      uses: actions/setup-dotnet@v3\n      with:\n        dotnet-version: 8.0.x\n\n\n    - uses: dotnet/nbgv@master\n      id: nbgv\n \n    - name: Display Package Version\n      run: echo \"PackageVersion=${{ steps.nbgv.outputs.SemVer2 }}\"\n\n\n\n    - name: Restore dependencies\n      run: dotnet restore src/IdentityServer8.sln\n    - name: Build\n      run: dotnet build src/IdentityServer8.sln --configuration Release --no-restore -p:Version=${{ steps.nbgv.outputs.SemVer2 }}\n    - name: Test\n      run: dotnet test src/IdentityServer8.sln --configuration Release --no-build --verbosity normal /p:CollectCoverage=true --collect:\"XPlat Code Coverage\" -- DataCollectionRunSettings.DataCollectors.DataCollector.Configuration.Format=cobertura\n\n    - name: Upload coverage reports to Codecov\n      uses: codecov/codecov-action@v4.0.1\n      env:\n        token: ${{ secrets.CODECOV_TOKEN }}\n        slug: alexhiggins732/IdentityServer8\n        CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }}\n\n\n    - name: Push\n      if: ${{ (github.event_name == 'push') && (runner.os == 'Windows') }} \n      run: dotnet nuget push .\\nuget\\*.nupkg  --skip-duplicate --source https://api.nuget.org/v3/index.json --api-key ${{ secrets.NUGET_API_KEY }}\n\n"
  },
  {
    "path": ".gitignore",
    "content": "## Ignore Visual Studio temporary files, build results, and\n## files generated by popular Visual Studio add-ons.\n\n# Rider\n.idea\n\n# User-specific files\n*.suo\n*.user\n*.userosscache\n*.sln.docstates\n\n# User-specific files (MonoDevelop/Xamarin Studio)\n*.userprefs\n\n# Build results\n[Dd]ebug/\n[Dd]ebugPublic/\n[Rr]elease/\n[Rr]eleases/\nx64/\nx86/\n\nbld/\n[Bb]in/\n[Oo]bj/\n[Ll]og/\n\n# Visual Studio cache/options directory\n.vs/\nproject.lock.json\n\n# Uncomment if you have tasks that create the project's static files in wwwroot\n#wwwroot/\n\n# MSTest test Results\n[Tt]est[Rr]esult*/\n[Bb]uild[Ll]og.*\n\n# NUNIT\n*.VisualState.xml\nTestResult.xml\n\n# Build Results of an ATL Project\n[Dd]ebugPS/\n[Rr]eleasePS/\ndlldata.c\n\n# DNX\nproject.lock.json\nproject.fragment.lock.json\nartifacts/\nProperties/launchSettings.json\n\n*_i.c\n*_p.c\n*_i.h\n*.ilk\n*.meta\n*.obj\n*.pch\n*.pdb\n*.pgc\n*.pgd\n*.rsp\n*.sbr\n*.tlb\n*.tli\n*.tlh\n*.tmp\n*.tmp_proj\n*.log\n*.vspscc\n*.vssscc\n.builds\n*.pidb\n*.svclog\n*.scc\n\n# Chutzpah Test files\n_Chutzpah*\n\n# Visual C++ cache files\nipch/\n*.aps\n*.ncb\n*.opendb\n*.opensdf\n*.sdf\n*.cachefile\n*.VC.db\n*.VC.VC.opendb\n\n# Visual Studio profiler\n*.psess\n*.vsp\n*.vspx\n*.sap\n\n# TFS 2012 Local Workspace\n$tf/\n\n# Guidance Automation Toolkit\n*.gpState\n\n# ReSharper is a .NET coding add-in\n_ReSharper*/\n*.[Rr]e[Ss]harper\n*.DotSettings.user\n\n# JustCode is a .NET coding add-in\n.JustCode\n\n# TeamCity is a build add-in\n_TeamCity*\n\n# DotCover is a Code Coverage Tool\n*.dotCover\n\n# Visual Studio code coverage results\n*.coverage\n*.coveragexml\n\n# NCrunch\n_NCrunch_*\n.*crunch*.local.xml\nnCrunchTemp_*\n\n# MightyMoose\n*.mm.*\nAutoTest.Net/\n\n# Web workbench (sass)\n.sass-cache/\n\n# Installshield output folder\n[Ee]xpress/\n\n# DocProject is a documentation generator add-in\nDocProject/buildhelp/\nDocProject/Help/*.HxT\nDocProject/Help/*.HxC\nDocProject/Help/*.hhc\nDocProject/Help/*.hhk\nDocProject/Help/*.hhp\nDocProject/Help/Html2\nDocProject/Help/html\n\n# Click-Once directory\npublish/\n\n# Publish Web Output\n*.[Pp]ublish.xml\n*.azurePubxml\n# TODO: Comment the next line if you want to checkin your web deploy settings\n# but database connection strings (with potential passwords) will be unencrypted\n*.pubxml\n*.publishproj\n\n# Microsoft Azure Web App publish settings. Comment the next line if you want to\n# checkin your Azure Web App publish settings, but sensitive information contained\n# in these scripts will be unencrypted\nPublishScripts/\n\n# NuGet Packages\n*.nupkg\n# The packages folder can be ignored because of Package Restore\n**/packages/*\n# except build/, which is used as an MSBuild target.\n!**/packages/build/\n# Uncomment if necessary however generally it will be regenerated when needed\n#!**/packages/repositories.config\n# NuGet v3's project.json files produces more ignoreable files\n*.nuget.props\n*.nuget.targets\n\n# Microsoft Azure Build Output\ncsx/\n*.build.csdef\n\n# Microsoft Azure Emulator\necf/\nrcf/\n\n# Windows Store app package directories and files\nAppPackages/\nBundleArtifacts/\nPackage.StoreAssociation.xml\n_pkginfo.txt\n\n# Visual Studio cache files\n# files ending in .cache can be ignored\n*.[Cc]ache\n# but keep track of directories ending in .cache\n!*.[Cc]ache/\n\n# Others\nClientBin/\n\n~$*\n*~\n*.dbmdl\n*.dbproj.schemaview\n*.jfm\n*.pfx\n*.publishsettings\nnode_modules/\nbower_components/\norleans.codegen.cs\n\n# RIA/Silverlight projects\nGenerated_Code/\n\n# Backup & report files from converting an old project file\n# to a newer Visual Studio version. Backup files are not needed,\n# because we have git ;-)\n_UpgradeReport_Files/\nBackup*/\nUpgradeLog*.XML\nUpgradeLog*.htm\n\n# SQL Server files\n*.mdf\n*.ldf\n\n# Business Intelligence projects\n*.rdl.data\n*.bim.layout\n*.bim_*.settings\n\n# Microsoft Fakes\nFakesAssemblies/\n\n# GhostDoc plugin setting file\n*.GhostDoc.xml\n\n# Node.js Tools for Visual Studio\n.ntvs_analysis.dat\n\n# Visual Studio 6 build log\n*.plg\n\n# Visual Studio 6 workspace options file\n*.opt\ndocs/_build/\n\n# Local .NET CLI tools\ntools/\n\n# Visual Studio Code workspace options\n.vscode\n\n# IdentityServer temp files\nIdentityServer8_log.txt\ntempkey.rsa\nsamples/KeyManagement/FileSystem/dataprotectionkeys/\nsamples/KeyManagement/FileSystem/signingkeys/\nworkspace.xml\n\nsrc/IdentityServer8/host/identityserver.db\ntempkey.jwk\n/nuget\n\n# Paket dependency manager\n.paket/paket.exe\npaket-files/\n\n# FAKE - F# Make\n.fake/\n\n# JetBrains Rider\n.idea/\n*.sln.iml\n\n# CodeRush\n.cr/\n\n# Python Tools for Visual Studio (PTVS)\n__pycache__/\n*.pyc\n\n# Cake - Uncomment if you are using it\n# tools/\n/src/IdentityServer8.Admin/appsettings.production.json\n/src/IdentityServer8.Admin/Scripts/Libs/\n/src/IdentityServer8.Admin/Data/Migrations/\n\n# Don't ignore these log folders\n!/src/IdentityServer8.Admin.UI/Resources/Views/Log/\n!/src/IdentityServer8.Admin.BusinessLogic/Dtos/Log/\n!**/Views/Log/\n!/src/IdentityServer8.Admin.BusinessLogic/Events/Log/\n/src/IdentityServer8.Admin.Api/appsettings.Production.json\n\n\n\n/shared/nginx/certs/\nlib/\n\n"
  },
  {
    "path": ".readthedocs.yaml",
    "content": "# .readthedocs.yaml\n# Read the Docs configuration file\n# See https://docs.readthedocs.io/en/stable/config-file/v2.html for details\n\n# Required\nversion: 2\n\n# Set the OS, Python version and other tools you might need\nbuild:\n  os: ubuntu-22.04\n  tools:\n    python: \"3.12\"\n    # You can also specify other tool versions:\n    # nodejs: \"19\"\n    # rust: \"1.64\"\n    # golang: \"1.19\"\n\n# Build documentation in the \"docs/\" directory with Sphinx\nsphinx:\n  configuration: docs/conf.py\n\n# Optionally build your docs in additional formats such as PDF and ePub\n# formats:\n#    - pdf\n#    - epub\n\n# Optional but recommended, declare the Python requirements required\n# to build your documentation\n# See https://docs.readthedocs.io/en/stable/guides/reproducible-builds.html\npython:\n  install:\n  - requirements: docs/requirements.txt\n"
  },
  {
    "path": "Directory.Build.props",
    "content": "<Project>\n\n    <PropertyGroup>\n        <TargetFramework>net8.0</TargetFramework>\n        <!--always bump /version.json and /docs/conf.py to <Version>X.Y.Z</Version>to keep nuget, build and document versions in sync-->\n        <Version>8.0.4</Version>\n\t\t<IdentityServerVersion>8.0.4</IdentityServerVersion>\n        <PackageId>HigginsSoft.$(MSBuildProjectName)</PackageId>\n        <Title>$(MSBuildProjectName)</Title>\n        <ImplicitUsings>enable</ImplicitUsings>\n\n        <PackageLicenseFile>LICENSE</PackageLicenseFile>\n\n        <AppendTargetFrameworkToOutputPath>false</AppendTargetFrameworkToOutputPath>\n        <NoWarn>$(NoWarn);CS0618;SYSLIB0023;SYSLIB0020;EF1001</NoWarn>\n\n\t\t<SignAssembly>true</SignAssembly>\n\t\t<AssemblyOriginatorKeyFile>$(SolutionDir)../key.snk</AssemblyOriginatorKeyFile>\n\n\n        <Description>OpenID Connect and OAuth 2.0 Framework for ASP.NET Core</Description>\n        <Copyright>Copyright 2024 HigginsSoft. Alexander Higgins</Copyright>\n        <Authors>HigginsSoft, Alexander Higgins, Brock Allen, Dominick Baier</Authors>\n  \n        <PackageTags>OAuth2 OAuth 2.0 OpenID Connect Security Identity IdentityServer Admin IdentityServer8 OpenIDConnect </PackageTags>\n\n\n        <PackageProjectUrl>https://github.com/alexhiggins732/IdentityServer8</PackageProjectUrl>\n        <RepositoryType>git</RepositoryType>\n        <PackageReleaseNotes>https://github.com/alexhiggins732/IdentityServer8/releases</PackageReleaseNotes>\n\n        <!-- Declare that the Repository URL can be published to NuSpec -->\n        <PublishRepositoryUrl>true</PublishRepositoryUrl>\n        <!-- Embed source files that are not tracked by the source control manager to the PDB -->\n\n\n        <!-- Include PDB in the built .nupkg -->\n        <AllowedOutputExtensionsInPackageBuildOutputFolder>$(AllowedOutputExtensionsInPackageBuildOutputFolder);.pdb</AllowedOutputExtensionsInPackageBuildOutputFolder>\n\n        <PackageIcon>icon.jpg</PackageIcon>\n\n\n        <GenerateBindingRedirectsOutputType>true</GenerateBindingRedirectsOutputType>\n\n        <!--<CodeAnalysisRuleset>$(MSBuildThisFileDirectory)IdentityServer8.DotNet.ruleset</CodeAnalysisRuleset>-->\n\n        <IsTrimmable>false</IsTrimmable>\n        <EnableAOTAnalyzer>false</EnableAOTAnalyzer>\n\n        <EmbedUntrackedSources>true</EmbedUntrackedSources>\n        <Deterministic>true</Deterministic>\n\t\t<ImplicitUsings>Enable</ImplicitUsings>\n        <LangVersion>latest</LangVersion>\n        <GenerateDocumentationFile>false</GenerateDocumentationFile>\n        <AppendTargetFrameworkToOutputPath>false</AppendTargetFrameworkToOutputPath>\n        <PackageOutputPath>$(SolutionDir)../nuget</PackageOutputPath>\n\n\n        <IsPackable>false</IsPackable>\n        <GeneratePackageOnBuild>false</GeneratePackageOnBuild>\n        <PackageReadmeFile>README.md</PackageReadmeFile>\n        <DebugSymbols>true</DebugSymbols>\n        <DebugType>portable</DebugType>\n        <IncludeSymbols>true</IncludeSymbols>\n        <SymbolPackageFormat>snupkg</SymbolPackageFormat>\n        <IncludeBuildOutput>true</IncludeBuildOutput>\n    </PropertyGroup>\n\n    <ItemGroup>\n \n        <PackageReference Include=\"Microsoft.CodeAnalysis.NetAnalyzers\" Version=\"$(MicrosoftCodeAnalysisNetAnalyzersPackageVersion)\" PrivateAssets=\"All\" />\n        <PackageReference Include=\"Microsoft.SourceLink.GitHub\" Version=\"$(MicrosoftSourceLinkGitHubPackageVersion)\" PrivateAssets=\"All\" />\n    </ItemGroup>\n\n    <ItemGroup>\n        <None Include=\"$(SolutionDir)../LICENSE\">\n            <Pack>True</Pack>\n            <PackagePath>\\</PackagePath>\n        </None>\n    </ItemGroup>\n    <ItemGroup>\n        <None Include=\"$(SolutionDir)../README.md\">\n            <Pack>True</Pack>\n            <PackagePath>\\</PackagePath>\n        </None>\n\n    </ItemGroup>\n    <ItemGroup>\n        <None Include=\"$(SolutionDir)../icon.jpg\">\n            <Pack>True</Pack>\n            <PackagePath>\\</PackagePath>\n        </None>\n\n    </ItemGroup>\n\n\n</Project>\n"
  },
  {
    "path": "Directory.Build.targets",
    "content": "<Project>\n    <!-- \n    Make a netstandard2.1 copy of the .net ILLinkPack to work around a trimming issue.\n    See https://github.com/dotnet/linker/issues/3175\n    TODO: Remove once .NET 8 + trimming + netstandard2.1 is fixed.\n  -->\n    <Target Name=\"_FixKnownILLinkPack\"\n            BeforeTargets=\"ProcessFrameworkReferences\">\n        <ItemGroup>\n            <KnownILLinkPack Include=\"@(KnownILLinkPack)\"\n                             Condition=\"'%(TargetFramework)' == 'net8.0'\"\n                             TargetFramework=\"netstandard2.1\"\n                             ILLinkPackVersion=\"%(KnownILLinkPack.ILLinkPackVersion)\" />\n        </ItemGroup>\n    </Target>\n\n</Project>\n"
  },
  {
    "path": "Directory.Packages.props",
    "content": "<Project>\n  <PropertyGroup>\n    <ManagePackageVersionsCentrally>true</ManagePackageVersionsCentrally>\n    <CentralPackageTransitivePinningEnabled>true</CentralPackageTransitivePinningEnabled>\n    <AspnetVersion>8.0.0</AspnetVersion>\n    <AspnetMinorVersion>8.0.1</AspnetMinorVersion>\n    <MicrosoftExtensionsVersion>8.0.0</MicrosoftExtensionsVersion>\n    <EfVersion>8.0.0</EfVersion>\n    <RuntimeVersion>8.0.0</RuntimeVersion>\n    <AspireVersion>8.0.0-preview.2.23619.3</AspireVersion>\n    <GrpcVersion>2.59.0</GrpcVersion>\n    <SerilogVersion>8.0.0</SerilogVersion>\n    <NoWarn>$(NoWarn);AD0001;ASP0003;ASP0004;ASP0005;ASP0007;ASP0020;ASP0021;ASP0022;ASP0024</NoWarn>\n    <AutoGenerateBindingRedirects>true</AutoGenerateBindingRedirects>\n  </PropertyGroup>\n  <ItemGroup>\n    <PackageVersion Include=\"AspNet.Security.OAuth.GitHub\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"AspNetCore.HealthChecks.UI\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"AspNetCore.HealthChecks.MySql\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"AspNetCore.HealthChecks.NpgSql\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"AspNetCore.HealthChecks.OpenIdConnectServer\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"AspNetCore.HealthChecks.SqlServer\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"AspNetCore.HealthChecks.UI.Client\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"AutoMapper\" Version=\"13.0.1 \" />\n    <PackageVersion Include=\"Azure.Extensions.AspNetCore.DataProtection.Keys\" Version=\"1.1.0\" />\n    <PackageVersion Include=\"Azure.Identity\" Version=\"1.10.4\" />\n    <PackageVersion Include=\"Azure.Security.KeyVault.Certificates\" Version=\"4.2.0\" />\n    <PackageVersion Include=\"Bogus\" Version=\"34.0.1\" />\n    <PackageVersion Include=\"bootstrap\" Version=\"5.3.2\" />\n    <PackageVersion Include=\"coverlet.collector\" Version=\"6.0.0\">\n      <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n      <PrivateAssets>all</PrivateAssets>\n    </PackageVersion>\n    <PackageVersion Include=\"Dapper\" Version=\"2.1.28\" />\n    <PackageVersion Include=\"EntityFramework\" Version=\"6.4.4\" />\n    <PackageVersion Include=\"FluentAssertions\" Version=\"6.11.0\" />\n    <PackageVersion Include=\"FluentValidation\" Version=\"11.9.0\" />\n    <PackageVersion Include=\"FluentValidation.AspNetCore\" Version=\"11.3.0\" />\n    <PackageVersion Include=\"Google.Protobuf\" Version=\"3.23.4\" />\n    <PackageVersion Include=\"Grpc\" Version=\"$(GrpcVersion)\" />\n    <PackageVersion Include=\"Grpc.AspNetCore\" Version=\"$(GrpcVersion)\" />\n    <PackageVersion Include=\"Grpc.AspNetCore.Server\" Version=\"$(GrpcVersion)\" />\n    <PackageVersion Include=\"Grpc.Core\" Version=\"$(GrpcVersion)\" />\n    <PackageVersion Include=\"Grpc.Core.Api\" Version=\"$(GrpcVersion)\" />\n    <PackageVersion Include=\"Grpc.Net.Client\" Version=\"$(GrpcVersion)\" />\n    <PackageVersion Include=\"Grpc.Net.ClientFactory\" Version=\"$(GrpcVersion)\" />\n    <PackageVersion Include=\"Grpc.Tools\" Version=\"$(GrpcVersion)\" PrivateAssets=\"All\" />\n    <PackageVersion Include=\"HtmlAgilityPack\" Version=\"1.11.40\" />\n    <PackageVersion Include=\"Humanizer.Core\" Version=\"2.14.1\" />\n    <PackageVersion Include=\"IdentityModel\" Version=\"6.2.0\" />\n    <PackageVersion Include=\"IdentityModel.OidcClient\" Version=\"5.3.0-preview.1\" />\n    <PackageVersion Include=\"IdentityModel.AspNetCore\" Version=\"4.3.0\" />\n    <PackageVersion Include=\"IdentityModel.AspNetCore.AccessTokenValidation\" Version=\"1.0.0-preview.3\" />\n    <PackageVersion Include=\"IdentityModel.AspNetCore.OAuth2Introspection\" Version=\"4.0.1\" />\n    <PackageVersion Include=\"IdentityServer4.KeyManagement\" Version=\"2.1.0\" />\n    <PackageVersion Include=\"jQuery\" Version=\"3.7.1\" />\n    <PackageVersion Include=\"jQuery.validation\" Version=\"1.19.5\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Authentication.Certificate\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Authentication.Google\" Version=\"3.1.5\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Authentication.JwtBearer\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Authentication.MicrosoftAccount\" Version=\"$(AspnetMinorVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Authentication.OpenIdConnect\" Version=\"8.0.0\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Components.Web\" Version=\"$(AspnetMinorVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.DataProtection.EntityFrameworkCore\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Diagnostics.EntityFrameworkCore\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Http.Abstractions\" Version=\"2.2.0\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Identity.UI\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Identity.EntityFrameworkCore\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Mvc.Abstractions\" Version=\"2.2.0\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Mvc.NewtonsoftJson\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Mvc.Razor.RuntimeCompilation\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Mvc.Testing\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.OpenApi\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.TestHost\" Version=\"8.0.1\" />\n    <PackageVersion Include=\"Microsoft.AspNetCore.Server.Kestrel\" Version=\"2.2.0\" />\n    <PackageVersion Include=\"Microsoft.Data.SqlClient\" Version=\"5.1.5\" />\n    <PackageVersion Include=\"Microsoft.EntityFrameworkCore.Design\" Version=\"8.0.1\">\n      <PrivateAssets>all</PrivateAssets>\n      <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n    </PackageVersion>\n    <PackageVersion Include=\"Microsoft.EntityFrameworkCore.InMemory\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.EntityFrameworkCore.Relational\" Version=\"$(AspnetMinorVersion)\" />\n    <PackageVersion Include=\"Microsoft.EntityFrameworkCore.Sqlite\" Version=\"$(AspnetMinorVersion)\" />\n    <PackageVersion Include=\"Microsoft.EntityFrameworkCore.SqlServer\" Version=\"$(AspnetMinorVersion)\" />\n    <PackageVersion Include=\"Microsoft.EntityFrameworkCore.Tools\" Version=\"$(AspnetMinorVersion)\">\n      <PrivateAssets>all</PrivateAssets>\n      <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n    </PackageVersion>\n    <PackageVersion Include=\"Microsoft.EntityFrameworkCore.Tools.DotNet\" Version=\"2.0.3\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Configuration\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Configuration.Abstractions\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Configuration.AzureKeyVault\" Version=\"3.1.22\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Configuration.Binder\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Configuration.EnvironmentVariables\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Configuration.FileExtensions\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Configuration.Json\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Configuration.UserSecrets\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.DependencyInjection\" Version=\"8.0.0\" />\n    <PackageVersion Include=\"Microsoft.Extensions.DependencyInjection.Abstractions\" Version=\"8.0.0\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Diagnostics.HealthChecks\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Diagnostics.HealthChecks.EntityFrameworkCore\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Http\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Http.Resilience\" Version=\"$(MicrosoftExtensionsVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Hosting\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Logging\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Logging.Abstractions\" Version=\"8.0.0\" />\n    <PackageVersion Include=\"Microsoft.Extensions.Options\" Version=\"$(AspnetMinorVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.ServiceDiscovery\" Version=\"$(AspireVersion)\" />\n    <PackageVersion Include=\"Microsoft.Extensions.ServiceDiscovery.Yarp\" Version=\"$(AspireVersion)\" />\n    <PackageVersion Include=\"Microsoft.Identity.Web\" Version=\"1.22.1\" />\n    <PackageVersion Include=\"Microsoft.Identity.Web.UI\" Version=\"1.16.0\" />\n    <PackageVersion Include=\"Microsoft.IdentityModel.Logging\" Version=\"7.3.1\" />\n    <PackageVersion Include=\"Microsoft.IdentityModel.Protocols.OpenIdConnect\" Version=\"7.3.1\" />\n    <PackageVersion Include=\"Microsoft.jQuery.Unobtrusive.Validation\" Version=\"4.0.0\" />\n    <PackageVersion Include=\"Microsoft.NET.Test.Sdk\" Version=\"17.8.0\" />\n    <PackageVersion Include=\"Microsoft.OpenApi\" Version=\"1.6.10\" />\n    <PackageVersion Include=\"Microsoft.Web.LibraryManager.Build\" Version=\"2.1.175\" />\n    <PackageVersion Include=\"Microsoft.VisualStudio.Azure.Containers.Tools.Targets\" Version=\"1.19.6\" />\n    <PackageVersion Include=\"Microsoft.VisualStudio.Web.CodeGeneration.Design\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"Moq\" Version=\"4.20.70\" />\n    <PackageVersion Include=\"MSTest.TestAdapter\" Version=\"3.1.1\" />\n    <PackageVersion Include=\"MSTest.TestFramework\" Version=\"3.1.1\" />\n    <PackageVersion Include=\"Nerdbank.GitVersioning\" Version=\"3.6.133\" />\n    <PackageVersion Include=\"Newtonsoft.Json\" Version=\"13.0.3\" />\n    <PackageVersion Include=\"Npgsql.EntityFrameworkCore.PostgreSQL\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"NWebsec.AspNetCore.Middleware\" Version=\"3.0.0\" />\n    <PackageVersion Include=\"Persante.Blazor.SharedUI\" Version=\"1.0.11\" />\n    <PackageVersion Include=\"Persante.Common.Api\" Version=\"1.1.4\" />\n    <PackageVersion Include=\"Persante.Common.Infrastructure\" Version=\"1.1.1\" />\n    <PackageVersion Include=\"Persante.Identity.Iam\" Version=\"1.1.30-alpha.5\" />\n    <PackageVersion Include=\"Persante.Identity.Iam.Blazor\" Version=\"1.1.24-alpha.5\" />\n    <PackageVersion Include=\"Persante.Logging\" Version=\"1.0.8\" />\n    <PackageVersion Include=\"Persante.Security.Authentication\" Version=\"1.1.26-alpha.3\" />\n    <PackageVersion Include=\"Pomelo.EntityFrameworkCore.MySql\" Version=\"7.0.0\" />\n    <PackageVersion Include=\"Pomelo.EntityFrameworkCore.MySql.Design\" Version=\"1.1.2\" />\n    <PackageVersion Include=\"protobuf-net\" Version=\"3.2.26\" />\n    <PackageVersion Include=\"protobuf-net.BuildTools\" Version=\"3.2.27\" />\n    <PackageVersion Include=\"protobuf-net.Core\" Version=\"3.2.26\" />\n    <PackageVersion Include=\"protobuf-net.Grpc\" Version=\"1.1.1\" />\n    <PackageVersion Include=\"protobuf-net.Grpc.AspNetCore\" Version=\"1.1.1\" />\n    <PackageVersion Include=\"protobuf-net.Reflection\" Version=\"3.2.12\" />\n    <PackageVersion Include=\"Refit\" Version=\"7.0.0\" />\n    <PackageVersion Include=\"Refit.HttpClientFactory\" Version=\"7.0.0\" />\n    <PackageVersion Include=\"Refit.Newtonsoft.Json\" Version=\"7.0.0\" />\n    <PackageVersion Include=\"Sendgrid\" Version=\"9.25.2\" />\n    <PackageVersion Include=\"Serilog\" Version=\"3.1.1\" />\n    <PackageVersion Include=\"Serilog.AspNetCore\" Version=\"$(AspnetMinorVersion)\" />\n    <PackageVersion Include=\"Serilog.Enrichers.Environment\" Version=\"2.3.0\" />\n    <PackageVersion Include=\"Serilog.Enrichers.Thread\" Version=\"3.1.0\" />\n    <PackageVersion Include=\"Serilog.Extensions.Hosting\" Version=\"$(SerilogVersion)\" />\n    <PackageVersion Include=\"Serilog.Extensions.Logging\" Version=\"$(SerilogVersion)\" />\n    <PackageVersion Include=\"Serilog.Settings.Configuration\" Version=\"$(SerilogVersion)\" />\n    <PackageVersion Include=\"Serilog.Sinks.Console\" Version=\"5.0.1\" />\n    <PackageVersion Include=\"Serilog.Sinks.File\" Version=\"5.0.0\" />\n    <PackageVersion Include=\"Serilog.Sinks.MSSqlServer\" Version=\"6.5.0\" />\n    <PackageVersion Include=\"Serilog.Sinks.Seq\" Version=\"6.0.0\" />\n    <PackageVersion Include=\"Skoruba.AuditLogging.EntityFramework\" Version=\"1.0.0\" />\n    <PackageVersion Include=\"Spectre.Console\" Version=\"0.47.0\" />\n    <PackageVersion Include=\"Swashbuckle.AspNetCore\" Version=\"6.5.0\" />\n    <PackageVersion Include=\"Swashbuckle.AspNetCore.Swagger\" Version=\"6.5.0\" />\n    <PackageVersion Include=\"Swashbuckle.AspNetCore.Annotations\" Version=\"6.5.0\" />\n    <PackageVersion Include=\"System.Configuration.ConfigurationManager\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"System.IdentityModel.Tokens.Jwt\" Version=\"7.3.1\" />\n    <PackageVersion Include=\"System.Reactive\" Version=\"6.0.0\" />\n    <PackageVersion Include=\"System.Security.Principal.Windows\" Version=\"5.0.0\" />\n    <PackageVersion Include=\"System.ServiceModel.Primitives\" Version=\"$(AspnetVersion)\" />\n    <PackageVersion Include=\"WireMock.Net\" Version=\"1.5.39\" />\n    <PackageVersion Include=\"xunit\" Version=\"2.6.4\" />\n    <PackageVersion Include=\"xunit.runner.visualstudio\" Version=\"2.5.6\">\n      <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n      <PrivateAssets>all</PrivateAssets>\n    </PackageVersion>\n    <PackageVersion Include=\"Microsoft.CodeAnalysis.NetAnalyzers\" Version=\"$(AspnetVersion)\" PrivateAssets=\"All\" />\n    <PackageVersion Include=\"Microsoft.SourceLink.GitHub\" Version=\"$(AspnetVersion)\" PrivateAssets=\"All\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "GitReleaseManager.yaml",
    "content": "create:\n  include-footer: false\n  footer-heading:\n  footer-content:\n  footer-includes-milestone: false\n  milestone-replace-text:\nexport:\n  include-created-date-in-title: false\n  created-date-string-format:\n  perform-regex-removal: false\n  regex-text:\n  multiline-regex: false\nissue-labels-include:\n- bug\n- new feature\n- enhancement\n- breaking change\nissue-labels-exclude:\n- Internal Refactoring\n"
  },
  {
    "path": "IdentityServer8.DotNet.ruleset",
    "content": "﻿<?xml version=\"1.0\"?>\n<RuleSet Name=\"All Rules Disabled\" Description=\"All Rules are disabled.\" ToolsVersion=\"15.0\">\n   <Rules AnalyzerId=\"Microsoft.CodeAnalysis.VersionCheckAnalyzer\" RuleNamespace=\"Microsoft.CodeAnalysis.VersionCheckAnalyzer\">\n      <Rule Id=\"CA9999\" Action=\"None\" />             <!-- Analyzer version mismatch -->\n   </Rules>\n   <Rules AnalyzerId=\"Microsoft.CodeQuality.Analyzers\" RuleNamespace=\"Microsoft.CodeQuality.Analyzers\">\n      <Rule Id=\"CA1000\" Action=\"None\" />             <!-- Do not declare static members on generic types -->\n      <Rule Id=\"CA1008\" Action=\"None\" />             <!-- Enums should have zero value -->\n      <Rule Id=\"CA1010\" Action=\"None\" />             <!-- Collections should implement generic interface -->\n      <Rule Id=\"CA1012\" Action=\"None\" />             <!-- Abstract types should not have constructors -->\n      <Rule Id=\"CA1014\" Action=\"None\" />             <!-- Mark assemblies with CLSCompliant -->\n      <Rule Id=\"CA1016\" Action=\"None\" />             <!-- Mark assemblies with assembly version -->\n      <Rule Id=\"CA1017\" Action=\"None\" />             <!-- Mark assemblies with ComVisible -->\n      <Rule Id=\"CA1018\" Action=\"None\" />             <!-- Mark attributes with AttributeUsageAttribute -->\n      <Rule Id=\"CA1024\" Action=\"None\" />             <!-- Use properties where appropriate -->\n      <Rule Id=\"CA1027\" Action=\"None\" />             <!-- Mark enums with FlagsAttribute -->\n      <Rule Id=\"CA1028\" Action=\"None\" />             <!-- Enum Storage should be Int32 -->\n      <Rule Id=\"CA1030\" Action=\"None\" />             <!-- Use events where appropriate -->\n      <Rule Id=\"CA1031\" Action=\"None\" />             <!-- Do not catch general exception types -->\n      <Rule Id=\"CA1033\" Action=\"None\" />             <!-- Interface methods should be callable by child types -->\n      <Rule Id=\"CA1034\" Action=\"None\" />             <!-- Nested types should not be visible -->\n      <Rule Id=\"CA1036\" Action=\"None\" />             <!-- Override methods on comparable types -->\n      <Rule Id=\"CA1040\" Action=\"None\" />             <!-- Avoid empty interfaces -->\n      <Rule Id=\"CA1041\" Action=\"None\" />             <!-- Provide ObsoleteAttribute message -->\n      <Rule Id=\"CA1043\" Action=\"None\" />             <!-- Use Integral Or String Argument For Indexers -->\n      <Rule Id=\"CA1044\" Action=\"None\" />             <!-- Properties should not be write only -->\n      <Rule Id=\"CA1050\" Action=\"None\" />             <!-- Declare types in namespaces -->\n      <Rule Id=\"CA1051\" Action=\"None\" />             <!-- Do not declare visible instance fields -->\n      <Rule Id=\"CA1052\" Action=\"None\" />             <!-- Static holder types should be Static or NotInheritable -->\n      <Rule Id=\"CA1054\" Action=\"None\" />             <!-- Uri parameters should not be strings -->\n      <Rule Id=\"CA1055\" Action=\"None\" />             <!-- Uri return values should not be strings -->\n      <Rule Id=\"CA1056\" Action=\"None\" />             <!-- Uri properties should not be strings -->\n      <Rule Id=\"CA1060\" Action=\"None\" />             <!-- Move pinvokes to native methods class -->\n      <Rule Id=\"CA1061\" Action=\"None\" />             <!-- Do not hide base class methods -->\n      <Rule Id=\"CA1062\" Action=\"None\" />             <!-- Validate arguments of public methods -->\n      <Rule Id=\"CA1063\" Action=\"None\" />             <!-- Implement IDisposable Correctly -->\n      <Rule Id=\"CA1064\" Action=\"None\" />             <!-- Exceptions should be public -->\n      <Rule Id=\"CA1066\" Action=\"None\" />             <!-- Type {0} should implement IEquatable<T> because it overrides Equals -->\n      <Rule Id=\"CA1067\" Action=\"None\" />             <!-- Override Object.Equals(object) when implementing IEquatable<T> -->\n      <Rule Id=\"CA1068\" Action=\"None\" />             <!-- CancellationToken parameters must come last -->\n      <Rule Id=\"CA1501\" Action=\"None\" />             <!-- Avoid excessive inheritance -->\n      <Rule Id=\"CA1502\" Action=\"None\" />             <!-- Avoid excessive complexity -->\n      <Rule Id=\"CA1505\" Action=\"None\" />             <!-- Avoid unmaintainable code -->\n      <Rule Id=\"CA1506\" Action=\"None\" />             <!-- Avoid excessive class coupling -->\n      <Rule Id=\"CA1508\" Action=\"None\" />             <!-- Avoid dead conditional code -->\n      <Rule Id=\"CA1509\" Action=\"None\" />             <!-- Invalid entry in code metrics rule specification file -->\n      <Rule Id=\"CA1707\" Action=\"None\" />             <!-- Identifiers should not contain underscores -->\n      <Rule Id=\"CA1708\" Action=\"None\" />             <!-- Identifiers should differ by more than case -->\n      <Rule Id=\"CA1710\" Action=\"None\" />             <!-- Identifiers should have correct suffix -->\n      <Rule Id=\"CA1711\" Action=\"None\" />             <!-- Identifiers should not have incorrect suffix -->\n      <Rule Id=\"CA1712\" Action=\"None\" />             <!-- Do not prefix enum values with type name -->\n      <Rule Id=\"CA1714\" Action=\"None\" />             <!-- Flags enums should have plural names -->\n      <Rule Id=\"CA1715\" Action=\"None\" />             <!-- Identifiers should have correct prefix -->\n      <Rule Id=\"CA1716\" Action=\"None\" />             <!-- Identifiers should not match keywords -->\n      <Rule Id=\"CA1717\" Action=\"None\" />             <!-- Only FlagsAttribute enums should have plural names -->\n      <Rule Id=\"CA1720\" Action=\"None\" />             <!-- Identifier contains type name -->\n      <Rule Id=\"CA1721\" Action=\"None\" />             <!-- Property names should not match get methods -->\n      <Rule Id=\"CA1724\" Action=\"None\" />             <!-- Type names should not match namespaces -->\n      <Rule Id=\"CA1725\" Action=\"None\" />             <!-- Parameter names should match base declaration -->\n      <Rule Id=\"CA1801\" Action=\"None\" />             <!-- Review unused parameters -->\n      <Rule Id=\"CA1802\" Action=\"None\" />             <!-- Use literals where appropriate -->\n      <Rule Id=\"CA1806\" Action=\"None\" />             <!-- Do not ignore method results -->\n      <Rule Id=\"CA1812\" Action=\"Warning\" />          <!-- Avoid uninstantiated internal classes -->\n      <Rule Id=\"CA1814\" Action=\"None\" />             <!-- Prefer jagged arrays over multidimensional -->\n      <Rule Id=\"CA1815\" Action=\"None\" />             <!-- Override equals and operator equals on value types -->\n      <Rule Id=\"CA1819\" Action=\"None\" />             <!-- Properties should not return arrays -->\n      <Rule Id=\"CA1822\" Action=\"None\" />             <!-- Mark members as static -->\n      <Rule Id=\"CA1823\" Action=\"Warning\" />          <!-- Avoid unused private fields -->\n      <Rule Id=\"CA2007\" Action=\"Error\" />            <!-- Do not directly await a Task -->\n      <Rule Id=\"CA2119\" Action=\"None\" />             <!-- Seal methods that satisfy private interfaces -->\n      <Rule Id=\"CA2211\" Action=\"None\" />             <!-- Non-constant fields should not be visible -->\n      <Rule Id=\"CA2214\" Action=\"None\" />             <!-- Do not call overridable methods in constructors -->\n      <Rule Id=\"CA2217\" Action=\"None\" />             <!-- Do not mark enums with FlagsAttribute -->\n      <Rule Id=\"CA2219\" Action=\"None\" />             <!-- Do not raise exceptions in finally clauses -->\n      <Rule Id=\"CA2225\" Action=\"None\" />             <!-- Operator overloads have named alternates -->\n      <Rule Id=\"CA2226\" Action=\"None\" />             <!-- Operators should have symmetrical overloads -->\n      <Rule Id=\"CA2227\" Action=\"None\" />             <!-- Collection properties should be read only -->\n      <Rule Id=\"CA2231\" Action=\"None\" />             <!-- Overload operator equals on overriding value type Equals -->\n      <Rule Id=\"CA2244\" Action=\"None\" />             <!-- Do not duplicate indexed element initializations -->\n   </Rules>\n   <Rules AnalyzerId=\"Microsoft.CodeQuality.CSharp.Analyzers\" RuleNamespace=\"Microsoft.CodeQuality.CSharp.Analyzers\">\n      <Rule Id=\"CA1001\" Action=\"None\" />             <!-- Types that own disposable fields should be disposable -->\n      <Rule Id=\"CA1003\" Action=\"None\" />             <!-- Use generic event handler instances -->\n      <Rule Id=\"CA1019\" Action=\"None\" />             <!-- Define accessors for attribute arguments -->\n      <Rule Id=\"CA1032\" Action=\"None\" />             <!-- Implement standard exception constructors -->\n      <Rule Id=\"CA1065\" Action=\"None\" />             <!-- Do not raise exceptions in unexpected locations -->\n      <Rule Id=\"CA1200\" Action=\"None\" />             <!-- Avoid using cref tags with a prefix -->\n      <Rule Id=\"CA1507\" Action=\"None\" />             <!-- Use nameof to express symbol names -->\n      <Rule Id=\"CA1821\" Action=\"None\" />             <!-- Remove empty Finalizers -->\n      <Rule Id=\"CA2200\" Action=\"None\" />             <!-- Rethrow to preserve stack details. -->\n      <Rule Id=\"CA2234\" Action=\"None\" />             <!-- Pass system uri objects instead of strings -->\n   </Rules>\n   <Rules AnalyzerId=\"Microsoft.CodeQuality.VisualBasic.Analyzers\" RuleNamespace=\"Microsoft.CodeQuality.VisualBasic.Analyzers\">\n      <Rule Id=\"CA1001\" Action=\"None\" />             <!-- Types that own disposable fields should be disposable -->\n      <Rule Id=\"CA1003\" Action=\"None\" />             <!-- Use generic event handler instances -->\n      <Rule Id=\"CA1019\" Action=\"None\" />             <!-- Define accessors for attribute arguments -->\n      <Rule Id=\"CA1032\" Action=\"None\" />             <!-- Implement standard exception constructors -->\n      <Rule Id=\"CA1065\" Action=\"None\" />             <!-- Do not raise exceptions in unexpected locations -->\n      <Rule Id=\"CA1200\" Action=\"None\" />             <!-- Avoid using cref tags with a prefix -->\n      <Rule Id=\"CA1507\" Action=\"None\" />             <!-- Use nameof to express symbol names -->\n      <Rule Id=\"CA1821\" Action=\"None\" />             <!-- Remove empty Finalizers -->\n      <Rule Id=\"CA2200\" Action=\"None\" />             <!-- Rethrow to preserve stack details. -->\n      <Rule Id=\"CA2218\" Action=\"None\" />             <!-- Override GetHashCode on overriding Equals -->\n      <Rule Id=\"CA2224\" Action=\"None\" />             <!-- Override Equals on overloading operator equals -->\n      <Rule Id=\"CA2234\" Action=\"None\" />             <!-- Pass system uri objects instead of strings -->\n   </Rules>\n   <Rules AnalyzerId=\"Microsoft.NetCore.Analyzers\" RuleNamespace=\"Microsoft.NetCore.Analyzers\">\n      <Rule Id=\"CA1303\" Action=\"None\" />             <!-- Do not pass literals as localized parameters -->\n      <Rule Id=\"CA1304\" Action=\"Error\" />            <!-- Specify CultureInfo -->\n      <Rule Id=\"CA1305\" Action=\"Error\" />            <!-- Specify IFormatProvider -->\n      <Rule Id=\"CA1307\" Action=\"Error\" />            <!-- Specify StringComparison -->\n      <Rule Id=\"CA1308\" Action=\"None\" />             <!-- Normalize strings to uppercase -->\n      <Rule Id=\"CA1401\" Action=\"None\" />             <!-- P/Invokes should not be visible -->\n      <Rule Id=\"CA1813\" Action=\"None\" />             <!-- Avoid unsealed attributes -->\n      <Rule Id=\"CA1816\" Action=\"None\" />             <!-- Dispose methods should call SuppressFinalize -->\n      <Rule Id=\"CA1820\" Action=\"None\" />             <!-- Test for empty strings using string length -->\n      <Rule Id=\"CA1826\" Action=\"None\" />             <!-- Do not use Enumerable methods on indexable collections. Instead use the collection directly -->\n      <Rule Id=\"CA2000\" Action=\"None\" />             <!-- Dispose objects before losing scope -->\n      <Rule Id=\"CA2002\" Action=\"None\" />             <!-- Do not lock on objects with weak identity -->\n      <Rule Id=\"CA2008\" Action=\"None\" />             <!-- Do not create tasks without passing a TaskScheduler -->\n      <Rule Id=\"CA2009\" Action=\"None\" />             <!-- Do not call ToImmutableCollection on an ImmutableCollection value -->\n      <Rule Id=\"CA2100\" Action=\"None\" />             <!-- Review SQL queries for security vulnerabilities -->\n      <Rule Id=\"CA2101\" Action=\"None\" />             <!-- Specify marshaling for P/Invoke string arguments -->\n      <Rule Id=\"CA2208\" Action=\"None\" />             <!-- Instantiate argument exceptions correctly -->\n      <Rule Id=\"CA2213\" Action=\"None\" />             <!-- Disposable fields should be disposed -->\n      <Rule Id=\"CA2216\" Action=\"None\" />             <!-- Disposable types should declare finalizer -->\n      <Rule Id=\"CA2229\" Action=\"None\" />             <!-- Implement serialization constructors -->\n      <Rule Id=\"CA2235\" Action=\"None\" />             <!-- Mark all non-serializable fields -->\n      <Rule Id=\"CA2237\" Action=\"None\" />             <!-- Mark ISerializable types with serializable -->\n      <Rule Id=\"CA2241\" Action=\"None\" />             <!-- Provide correct arguments to formatting methods -->\n      <Rule Id=\"CA2242\" Action=\"None\" />             <!-- Test for NaN correctly -->\n      <Rule Id=\"CA2243\" Action=\"None\" />             <!-- Attribute string literals should parse correctly -->\n      <Rule Id=\"CA2300\" Action=\"None\" />             <!-- Do not use insecure deserializer BinaryFormatter -->\n      <Rule Id=\"CA2301\" Action=\"None\" />             <!-- Do not call BinaryFormatter.Deserialize without first setting BinaryFormatter.Binder -->\n      <Rule Id=\"CA2302\" Action=\"None\" />             <!-- Ensure BinaryFormatter.Binder is set before calling BinaryFormatter.Deserialize -->\n      <Rule Id=\"CA2305\" Action=\"None\" />             <!-- Do not use insecure deserializer LosFormatter -->\n      <Rule Id=\"CA2310\" Action=\"None\" />             <!-- Do not use insecure deserializer NetDataContractSerializer -->\n      <Rule Id=\"CA2311\" Action=\"None\" />             <!-- Do not deserialize without first setting NetDataContractSerializer.Binder -->\n      <Rule Id=\"CA2312\" Action=\"None\" />             <!-- Ensure NetDataContractSerializer.Binder is set before deserializing -->\n      <Rule Id=\"CA2315\" Action=\"None\" />             <!-- Do not use insecure deserializer ObjectStateFormatter -->\n      <Rule Id=\"CA3001\" Action=\"None\" />             <!-- Review code for SQL injection vulnerabilities -->\n      <Rule Id=\"CA3002\" Action=\"None\" />             <!-- Review code for XSS vulnerabilities -->\n      <Rule Id=\"CA3003\" Action=\"None\" />             <!-- Review code for file path injection vulnerabilities -->\n      <Rule Id=\"CA3004\" Action=\"None\" />             <!-- Review code for information disclosure vulnerabilities -->\n      <Rule Id=\"CA3005\" Action=\"None\" />             <!-- Review code for LDAP injection vulnerabilities -->\n      <Rule Id=\"CA3006\" Action=\"None\" />             <!-- Review code for process command injection vulnerabilities -->\n      <Rule Id=\"CA3007\" Action=\"None\" />             <!-- Review code for open redirect vulnerabilities -->\n      <Rule Id=\"CA3008\" Action=\"None\" />             <!-- Review code for XPath injection vulnerabilities -->\n      <Rule Id=\"CA3009\" Action=\"None\" />             <!-- Review code for XML injection vulnerabilities -->\n      <Rule Id=\"CA3010\" Action=\"None\" />             <!-- Review code for XAML injection vulnerabilities -->\n      <Rule Id=\"CA3011\" Action=\"None\" />             <!-- Review code for DLL injection vulnerabilities -->\n      <Rule Id=\"CA3012\" Action=\"None\" />             <!-- Review code for regex injection vulnerabilities -->\n      <Rule Id=\"CA3061\" Action=\"None\" />             <!-- Do Not Add Schema By URL -->\n      <Rule Id=\"CA5350\" Action=\"None\" />             <!-- Do Not Use Weak Cryptographic Algorithms -->\n      <Rule Id=\"CA5351\" Action=\"None\" />             <!-- Do Not Use Broken Cryptographic Algorithms -->\n      <Rule Id=\"CA5358\" Action=\"None\" />             <!-- Do Not Use Unsafe Cipher Modes -->\n      <Rule Id=\"CA5359\" Action=\"None\" />             <!-- Do Not Disable Certificate Validation -->\n      <Rule Id=\"CA5360\" Action=\"None\" />             <!-- Do Not Call Dangerous Methods In Deserialization -->\n      <Rule Id=\"CA5361\" Action=\"None\" />             <!-- Do Not Disable SChannel Use of Strong Crypto -->\n      <Rule Id=\"CA5362\" Action=\"None\" />             <!-- Do Not Refer Self In Serializable Class -->\n      <Rule Id=\"CA5363\" Action=\"None\" />             <!-- Do Not Disable Request Validation -->\n      <Rule Id=\"CA5364\" Action=\"None\" />             <!-- Do Not Use Deprecated Security Protocols -->\n      <Rule Id=\"CA5365\" Action=\"None\" />             <!-- Do Not Disable HTTP Header Checking -->\n      <Rule Id=\"CA5367\" Action=\"None\" />             <!-- Do Not Serialize Types With Pointer Fields -->\n      <Rule Id=\"CA5368\" Action=\"None\" />             <!-- Set ViewStateUserKey For Classes Derived From Page -->\n   </Rules>\n   <Rules AnalyzerId=\"Microsoft.NetCore.CSharp.Analyzers\" RuleNamespace=\"Microsoft.NetCore.CSharp.Analyzers\">\n      <Rule Id=\"CA1309\" Action=\"Error\" />            <!-- Use ordinal stringcomparison -->\n      <Rule Id=\"CA1810\" Action=\"None\" />             <!-- Initialize reference type static fields inline -->\n      <Rule Id=\"CA1824\" Action=\"None\" />             <!-- Mark assemblies with NeutralResourcesLanguageAttribute -->\n      <Rule Id=\"CA1825\" Action=\"Warning\" />          <!-- Avoid zero-length array allocations. -->\n      <Rule Id=\"CA2010\" Action=\"None\" />             <!-- Always consume the value returned by methods marked with PreserveSigAttribute -->\n      <Rule Id=\"CA2201\" Action=\"None\" />             <!-- Do not raise reserved exception types -->\n      <Rule Id=\"CA2207\" Action=\"None\" />             <!-- Initialize value type static fields inline -->\n   </Rules>\n   <Rules AnalyzerId=\"Microsoft.NetCore.VisualBasic.Analyzers\" RuleNamespace=\"Microsoft.NetCore.VisualBasic.Analyzers\">\n      <Rule Id=\"CA1309\" Action=\"Error\" />            <!-- Use ordinal stringcomparison -->\n      <Rule Id=\"CA1810\" Action=\"None\" />             <!-- Initialize reference type static fields inline -->\n      <Rule Id=\"CA1824\" Action=\"None\" />             <!-- Mark assemblies with NeutralResourcesLanguageAttribute -->\n      <Rule Id=\"CA1825\" Action=\"Warning\" />          <!-- Avoid zero-length array allocations. -->\n      <Rule Id=\"CA2010\" Action=\"None\" />             <!-- Always consume the value returned by methods marked with PreserveSigAttribute -->\n      <Rule Id=\"CA2201\" Action=\"None\" />             <!-- Do not raise reserved exception types -->\n      <Rule Id=\"CA2207\" Action=\"None\" />             <!-- Initialize value type static fields inline -->\n   </Rules>\n   <Rules AnalyzerId=\"Microsoft.NetFramework.Analyzers\" RuleNamespace=\"Microsoft.NetFramework.Analyzers\">\n      <Rule Id=\"CA1058\" Action=\"None\" />             <!-- Types should not extend certain base types -->\n      <Rule Id=\"CA2153\" Action=\"None\" />             <!-- Do Not Catch Corrupted State Exceptions -->\n      <Rule Id=\"CA3075\" Action=\"None\" />             <!-- Insecure DTD processing in XML -->\n      <Rule Id=\"CA3147\" Action=\"None\" />             <!-- Mark Verb Handlers With Validate Antiforgery Token -->\n   </Rules>\n   <Rules AnalyzerId=\"Microsoft.NetFramework.CSharp.Analyzers\" RuleNamespace=\"Microsoft.NetFramework.CSharp.Analyzers\">\n      <Rule Id=\"CA3076\" Action=\"None\" />             <!-- Insecure XSLT script processing. -->\n      <Rule Id=\"CA3077\" Action=\"None\" />             <!-- Insecure Processing in API Design, XmlDocument and XmlTextReader -->\n   </Rules>\n   <Rules AnalyzerId=\"Microsoft.NetFramework.VisualBasic.Analyzers\" RuleNamespace=\"Microsoft.NetFramework.VisualBasic.Analyzers\">\n      <Rule Id=\"CA3076\" Action=\"None\" />             <!-- Insecure XSLT script processing. -->\n      <Rule Id=\"CA3077\" Action=\"None\" />             <!-- Insecure Processing in API Design, XmlDocument and XmlTextReader -->\n   </Rules>\n</RuleSet>\n"
  },
  {
    "path": "LICENSE",
    "content": "                                 Apache License\n                           Version 2.0, January 2004\n                        http://www.apache.org/licenses/\n\n   TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION\n\n   1. Definitions.\n\n      \"License\" shall mean the terms and conditions for use, reproduction,\n      and distribution as defined by Sections 1 through 9 of this document.\n\n      \"Licensor\" shall mean the copyright owner or entity authorized by\n      the copyright owner that is granting the License.\n\n      \"Legal Entity\" shall mean the union of the acting entity and all\n      other entities that control, are controlled by, or are under common\n      control with that entity. For the purposes of this definition,\n      \"control\" means (i) the power, direct or indirect, to cause the\n      direction or management of such entity, whether by contract or\n      otherwise, or (ii) ownership of fifty percent (50%) or more of the\n      outstanding shares, or (iii) beneficial ownership of such entity.\n\n      \"You\" (or \"Your\") shall mean an individual or Legal Entity\n      exercising permissions granted by this License.\n\n      \"Source\" form shall mean the preferred form for making modifications,\n      including but not limited to software source code, documentation\n      source, and configuration files.\n\n      \"Object\" form shall mean any form resulting from mechanical\n      transformation or translation of a Source form, including but\n      not limited to compiled object code, generated documentation,\n      and conversions to other media types.\n\n      \"Work\" shall mean the work of authorship, whether in Source or\n      Object form, made available under the License, as indicated by a\n      copyright notice that is included in or attached to the work\n      (an example is provided in the Appendix below).\n\n      \"Derivative Works\" shall mean any work, whether in Source or Object\n      form, that is based on (or derived from) the Work and for which the\n      editorial revisions, annotations, elaborations, or other modifications\n      represent, as a whole, an original work of authorship. For the purposes\n      of this License, Derivative Works shall not include works that remain\n      separable from, or merely link (or bind by name) to the interfaces of,\n      the Work and Derivative Works thereof.\n\n      \"Contribution\" shall mean any work of authorship, including\n      the original version of the Work and any modifications or additions\n      to that Work or Derivative Works thereof, that is intentionally\n      submitted to Licensor for inclusion in the Work by the copyright owner\n      or by an individual or Legal Entity authorized to submit on behalf of\n      the copyright owner. For the purposes of this definition, \"submitted\"\n      means any form of electronic, verbal, or written communication sent\n      to the Licensor or its representatives, including but not limited to\n      communication on electronic mailing lists, source code control systems,\n      and issue tracking systems that are managed by, or on behalf of, the\n      Licensor for the purpose of discussing and improving the Work, but\n      excluding communication that is conspicuously marked or otherwise\n      designated in writing by the copyright owner as \"Not a Contribution.\"\n\n      \"Contributor\" shall mean Licensor and any individual or Legal Entity\n      on behalf of whom a Contribution has been received by Licensor and\n      subsequently incorporated within the Work.\n\n   2. Grant of Copyright License. Subject to the terms and conditions of\n      this License, each Contributor hereby grants to You a perpetual,\n      worldwide, non-exclusive, no-charge, royalty-free, irrevocable\n      copyright license to reproduce, prepare Derivative Works of,\n      publicly display, publicly perform, sublicense, and distribute the\n      Work and such Derivative Works in Source or Object form.\n\n   3. Grant of Patent License. Subject to the terms and conditions of\n      this License, each Contributor hereby grants to You a perpetual,\n      worldwide, non-exclusive, no-charge, royalty-free, irrevocable\n      (except as stated in this section) patent license to make, have made,\n      use, offer to sell, sell, import, and otherwise transfer the Work,\n      where such license applies only to those patent claims licensable\n      by such Contributor that are necessarily infringed by their\n      Contribution(s) alone or by combination of their Contribution(s)\n      with the Work to which such Contribution(s) was submitted. If You\n      institute patent litigation against any entity (including a\n      cross-claim or counterclaim in a lawsuit) alleging that the Work\n      or a Contribution incorporated within the Work constitutes direct\n      or contributory patent infringement, then any patent licenses\n      granted to You under this License for that Work shall terminate\n      as of the date such litigation is filed.\n\n   4. Redistribution. You may reproduce and distribute copies of the\n      Work or Derivative Works thereof in any medium, with or without\n      modifications, and in Source or Object form, provided that You\n      meet the following conditions:\n\n      (a) You must give any other recipients of the Work or\n          Derivative Works a copy of this License; and\n\n      (b) You must cause any modified files to carry prominent notices\n          stating that You changed the files; and\n\n      (c) You must retain, in the Source form of any Derivative Works\n          that You distribute, all copyright, patent, trademark, and\n          attribution notices from the Source form of the Work,\n          excluding those notices that do not pertain to any part of\n          the Derivative Works; and\n\n      (d) If the Work includes a \"NOTICE\" text file as part of its\n          distribution, then any Derivative Works that You distribute must\n          include a readable copy of the attribution notices contained\n          within such NOTICE file, excluding those notices that do not\n          pertain to any part of the Derivative Works, in at least one\n          of the following places: within a NOTICE text file distributed\n          as part of the Derivative Works; within the Source form or\n          documentation, if provided along with the Derivative Works; or,\n          within a display generated by the Derivative Works, if and\n          wherever such third-party notices normally appear. The contents\n          of the NOTICE file are for informational purposes only and\n          do not modify the License. You may add Your own attribution\n          notices within Derivative Works that You distribute, alongside\n          or as an addendum to the NOTICE text from the Work, provided\n          that such additional attribution notices cannot be construed\n          as modifying the License.\n\n      You may add Your own copyright statement to Your modifications and\n      may provide additional or different license terms and conditions\n      for use, reproduction, or distribution of Your modifications, or\n      for any such Derivative Works as a whole, provided Your use,\n      reproduction, and distribution of the Work otherwise complies with\n      the conditions stated in this License.\n\n   5. Submission of Contributions. Unless You explicitly state otherwise,\n      any Contribution intentionally submitted for inclusion in the Work\n      by You to the Licensor shall be under the terms and conditions of\n      this License, without any additional terms or conditions.\n      Notwithstanding the above, nothing herein shall supersede or modify\n      the terms of any separate license agreement you may have executed\n      with Licensor regarding such Contributions.\n\n   6. Trademarks. This License does not grant permission to use the trade\n      names, trademarks, service marks, or product names of the Licensor,\n      except as required for reasonable and customary use in describing the\n      origin of the Work and reproducing the content of the NOTICE file.\n\n   7. Disclaimer of Warranty. Unless required by applicable law or\n      agreed to in writing, Licensor provides the Work (and each\n      Contributor provides its Contributions) on an \"AS IS\" BASIS,\n      WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or\n      implied, including, without limitation, any warranties or conditions\n      of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A\n      PARTICULAR PURPOSE. You are solely responsible for determining the\n      appropriateness of using or redistributing the Work and assume any\n      risks associated with Your exercise of permissions under this License.\n\n   8. Limitation of Liability. In no event and under no legal theory,\n      whether in tort (including negligence), contract, or otherwise,\n      unless required by applicable law (such as deliberate and grossly\n      negligent acts) or agreed to in writing, shall any Contributor be\n      liable to You for damages, including any direct, indirect, special,\n      incidental, or consequential damages of any character arising as a\n      result of this License or out of the use or inability to use the\n      Work (including but not limited to damages for loss of goodwill,\n      work stoppage, computer failure or malfunction, or any and all\n      other commercial damages or losses), even if such Contributor\n      has been advised of the possibility of such damages.\n\n   9. Accepting Warranty or Additional Liability. While redistributing\n      the Work or Derivative Works thereof, You may choose to offer,\n      and charge a fee for, acceptance of support, warranty, indemnity,\n      or other liability obligations and/or rights consistent with this\n      License. However, in accepting such obligations, You may act only\n      on Your own behalf and on Your sole responsibility, not on behalf\n      of any other Contributor, and only if You agree to indemnify,\n      defend, and hold each Contributor harmless for any liability\n      incurred by, or claims asserted against, such Contributor by reason\n      of your accepting any such warranty or additional liability.\n\n   END OF TERMS AND CONDITIONS\n\n   APPENDIX: How to apply the Apache License to your work.\n\n      To apply the Apache License to your work, attach the following\n      boilerplate notice, with the fields enclosed by brackets \"{}\"\n      replaced with your own identifying information. (Don't include\n      the brackets!)  The text should be enclosed in the appropriate\n      comment syntax for the file format. We also recommend that a\n      file or class name and description of purpose be included on the\n      same \"printed page\" as the copyright notice for easier\n      identification within third-party archives.\n\n   Copyright 2018, Brock Allen, Dominick Baier\n\n   Copyright 2024, HigginsSoft, Alexander Higgins\n\n   Licensed under the Apache License, Version 2.0 (the \"License\");\n   you may not use this file except in compliance with the License.\n   You may obtain a copy of the License at\n\n       http://www.apache.org/licenses/LICENSE-2.0\n\n   Unless required by applicable law or agreed to in writing, software\n   distributed under the License is distributed on an \"AS IS\" BASIS,\n   WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n   See the License for the specific language governing permissions and\n   limitations under the License.\n\n"
  },
  {
    "path": "LicenseHeader.txt",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/"
  },
  {
    "path": "NuGet.config",
    "content": "<?xml version=\"1.0\" encoding=\"utf-8\"?>\n<configuration>\n  <packageSources>\n\t<clear/>\n    <add key=\"NuGet\" value=\"https://api.nuget.org/v3/index.json\" />\n  </packageSources>\n</configuration>"
  },
  {
    "path": "README.md",
    "content": "# Identity Server 8 update\nThis project is a DotNet 8 revival of the Identity Server 4 and Identity Server 4 Admin UI, for Open ID Connect (OIDC) and OAuth, which was archived when .NET Core 3.1 reached end of support.\n\nThe latest verion, 8.0.4, is now available on NuGet. It contains [hundreds of security and bug fixes](https://github.com/alexhiggins732/IdentityServer8/blob/master/docs/CHANGELOG.md) from the original Identity Server 4 project.\n\nIt is recommend you update all previous version, 4 or 8, to the latest version to ensure you have the latest security updates. \n\n- [Documentation](http://identityserver8.readthedocs.io/)\n- [Support](https://identityserver8.readthedocs.io/en/latest/into/support.html)\n- [Gitter Chat](https://app.gitter.im/#/room/#identityserver8:gitter.im)\n\n[HigginsSoft.IdentityServer8 and Admin UI Nuget Packages](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8) are available here for use in DotNet 8.\n\nAll new development in the archived repository has moved to a paid commercial version in the [Duende Software](https://github.com/duendesoftware) organization. \n\nSee [here](https://duendesoftware.com/products/identityserver) for more details on the commerica version.\n\nThis repository will be maintained for bug fixes and security updates for the .NET 8 version of Identity Server 4.\n\nThe source code and unit tests will be updated to use the latest .NET 8 features and best practices.\n\nOnce the source code and unit tests are stabilized, the documentation will be updated to reflect the changes.\n\nGeneral speaking, the existing documentation for Identity Server 4 will be valid for this repository, but the new features and changes will be documented in the new documentation.\n\nIn the meantime, NuGet packages will be published to the [IdentityServer8 NuGet feed](https://www.nuget.org/profiles/IdentityServer8) and the [IdentityServer8 MyGet feed](https://www.myget.org/F/identityserver8/api/v3/index.json).\n\n\n## Build Status And Stats\n\n[![Master | Build](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/master.yml/badge.svg)](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/master.yml)\n[![Release|Build](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/release.yml/badge.svg)](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/release.yml)\n\n[![Develop|Build](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/develop.yml/badge.svg)](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/develop.yml)\n[![CI/CD|Build](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/pre-release.yml/badge.svg)](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/pre-release.yml)\n\n## Code Coverage\n[![Master | Build](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/master.yml/badge.svg)](https://img.shields.io/codecov/c/github/alexhiggins732/identityserver8) [![Master|CodeQL](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/codeql.yml/badge.svg)](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/codeql.yml)\n\n[![Develop|Build](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/develop.yml/badge.svg)](https://img.shields.io/codecov/c/github/alexhiggins732/identityserver8/tree/develop)\n[![Master|CodeQL](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/codeql.yml/badge.svg?branch=develop)](https://github.com/alexhiggins732/IdentityServer8/actions/workflows/codeql.yml?branch=develop)\n\n## Documentation\n[![Documentation Status](https://readthedocs.org/projects/identityserver8/badge/?version=latest)](https://identityserver8.readthedocs.io/en/latest/?badge=latest)\n[Read the docs - identityserver8.readthedocs.io ](http://identityserver8.readthedocs.io/)\n\n## Nuget Packages\n\n### Identity Server 8\n|Package||\n| ------------- | ------------- |\n|[HigginsSoft.IdentityServer8](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8)|\n|[HigginsSoft.IdentityServer8.Storage](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Storage)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Storage)|\n|[HigginsSoft.IdentityServer8.EntityFramework](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.EntityFramework)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.EntityFramework)|\n|[HigginsSoft.IdentityServer8.EntityFramework.Storage](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.EntityFramework.Storage)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.EntityFramework.Storage)|\n|[HigginsSoft.IdentityServer8.AspNetIdentity](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.AspNetIdentity)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.AspNetIdentity)|\n| | |\n\n### Identity Server 8 Administration UI\n|Package||\n| ------------- | ------------- |\n|[HigginsSoft.IdentityServer8.Shared](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Shared)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Shared)|\n|[HigginsSoft.IdentityServer8.Admin.UI](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.UI)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.UI)|\n|[HigginsSoft.IdentityServer8.Shared.Configuration](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Shared.Configuration)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Shared.Configuration)|\n|[HigginsSoft.IdentityServer8.Admin.Api](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.Api)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.Api)|\n|[HigginsSoft.IdentityServer8.Admin](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin)|\n|[HigginsSoft.IdentityServer8.Admin.BusinessLogic.Identity](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.BusinessLogic.Identity)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.BusinessLogic.Identity)|\n|[HigginsSoft.IdentityServer8.Admin.EntityFramework](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.EntityFramework)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.EntityFramework)|\n|[HigginsSoft.IdentityServer8.Admin.EntityFramework.Identity](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.EntityFramework.Identity)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.EntityFramework.Identity)|\n|[HigginsSoft.IdentityServer8.Admin.BusinessLogic.Shared](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.BusinessLogic.Shared)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.BusinessLogic.Shared)|\n|[HigginsSoft.IdentityServer8.Admin.EntityFramework.Extensions](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.EntityFramework.Extensions)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.EntityFramework.Extensions)|\n|[HigginsSoft.IdentityServer8.Admin.EntityFramework.PostgreSQL](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.EntityFramework.PostgreSQL)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.EntityFramework.PostgreSQL)|\n|[HigginsSoft.IdentityServer8.Admin.EntityFramework.MySql](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.EntityFramework.MySql)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.EntityFramework.MySql)|\n|[HigginsSoft.IdentityServer8.Admin.EntityFramework.SqlServer](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.EntityFramework.SqlServer)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.EntityFramework.SqlServer)|\n|[HigginsSoft.IdentityServer8.Admin.EntityFramework.Shared](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.EntityFramework.Shared)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.EntityFramework.Shared)|\n|[HigginsSoft.IdentityServer8.Admin.BusinessLogic](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.BusinessLogic)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.BusinessLogic)|\n|[HigginsSoft.IdentityServer8.Admin.EntityFramework.Configuration](https://www.nuget.org/packages?q=HigginsSoft.IdentityServer8.Admin.EntityFramework.Configuration)|![NuGet Downloads](https://img.shields.io/nuget/dt/HigginsSoft.IdentityServer8.Admin.EntityFramework.Configuration)|\n| | |\n\n\n## What's New\n\nView the [CHANGELOG](docs/CHANGELOG.md) for the latest changes.\n\n## About IdentityServer8\n[<img align=\"right\" width=\"100px\" src=\"https://dotnetfoundation.org/img/logo_big.svg\" />](https://dotnetfoundation.org/projects?searchquery=IdentityServer&type=project)\n\nIdentityServer is a free, open source [OpenID Connect](http://openid.net/connect/) and [OAuth 2.0](https://tools.ietf.org/html/rfc6749) framework for ASP.NET Core.\nFounded and maintained by [Dominick Baier](https://twitter.com/leastprivilege) and [Brock Allen](https://twitter.com/brocklallen), IdentityServer8 incorporates all the protocol implementations and extensibility points needed to integrate token-based authentication, single-sign-on and API access control in your applications.\nIdentityServer8 is officially [certified](https://openid.net/certification/) by the [OpenID Foundation](https://openid.net) and thus spec-compliant and interoperable.\nIt is part of the [.NET Foundation](https://www.dotnetfoundation.org/), and operates under their [code of conduct](https://www.dotnetfoundation.org/code-of-conduct). It is licensed under [Apache 2](https://opensource.org/licenses/Apache-2.0) (an OSI approved license).\n\nFor project documentation, please visit [readthedocs](https://IdentityServer8.readthedocs.io).\n\n## Branch structure\nActive development happens on the main branch. This always contains the latest version. Each (pre-) release is tagged with the corresponding version. The [aspnetcore1](https://github.com/alexhiggins732/IdentityServer8/tree/aspnetcore1) and [aspnetcore2](https://github.com/alexhiggins732/IdentityServer8/tree/aspnetcore2) branches contain the latest versions of the older ASP.NET Core based versions.\n\n## How to build\n\n* [Install]([https://www.microsoft.com/net/download/core#/current](https://dotnet.microsoft.com/en-us/download#/current) the latest .NET 8 SDK\n* Install Git\n* Clone this repo\n* Run `dotnet build src/identityserver8.slm` or `build.sh` in the root of the cloned repo.\n\n## Documentation\nFor project documentation, please visit [readthedocs](https://IdentityServer8.readthedocs.io).\n\nSee [here](http://docs.identityserver8.io/en/aspnetcore1/) for the 1.x docs, and [here](http://docs.identityserver8.io/en/aspnetcore2/) for the 2.x docs.\n\n## Bug reports and feature requests\nPlease use the [issue tracker](https://github.com/alexhiggins732/IdentityServer8/issues) for that. We only support the latest version for free. For older versions, you can get a commercial support agreement with us.\n\n## Commercial and Community Support\nIf you need help with implementing IdentityServer8 or your security architecture in general, there are both free and commercial support options.\nSee [here](https://IdentityServer8.readthedocs.io/en/latest/intro/support.html) for more details.\n\n## Sponsorship\nIf you are a fan of the project or a company that relies on IdentityServer, you might want to consider sponsoring.\nThis will help us devote more time to answering questions and doing feature development. If you are interested please head to our [Patreon](https://www.patreon.com/identityserver) page which has further details.\n\n### Platinum Sponsors\n[<img src=\"https://user-images.githubusercontent.com/1454075/62819413-39550c00-bb55-11e9-8f2f-a268c3552c71.png\" width=\"200\">](https://udelt.no)\n\n[<img src=\"https://user-images.githubusercontent.com/1454075/66454740-fb973580-ea68-11e9-9993-6c1014881528.png\" width=\"200\">](https://github.com/dotnet-at-microsoft)\n\n### Corporate Sponsors\n[Ritter Insurance Marketing](https://www.ritterim.com)  \n[ExtraNetUserManager](https://www.extranetusermanager.com/)  \n[Knab](https://www.knab.nl/)\n\nYou can see a list of our current sponsors [here](https://github.com/alexhiggins732/IdentityServer8/blob/main/SPONSORS.md) - and for companies we have some nice advertisement options as well.\n\n## Acknowledgements\nIdentityServer8 is built using the following great open source projects and free services:\n\n* [ASP.NET Core](https://github.com/dotnet/aspnetcore)\n* [Bullseye](https://github.com/adamralph/bullseye)\n* [SimpleExec](https://github.com/adamralph/simple-exec)\n* [MinVer](https://github.com/adamralph/minver)\n* [Json.Net](http://www.newtonsoft.com/json)\n* [XUnit](https://xunit.github.io/)\n* [Fluent Assertions](http://www.fluentassertions.com/)\n* [GitReleaseManager](https://github.com/GitTools/GitReleaseManager)\n\n..and last but not least a big thanks to all our [contributors](https://github.com/alexhiggins732/IdentityServer8/graphs/contributors)!\n"
  },
  {
    "path": "SECURITY.MD",
    "content": "# Reporting Security Issues\n\nIf you discover a security issue in IdentityServer, please report it by sending an email to contact@identityserver8.io\n\nThis will allow us to assess the risk, and make a fix available before we add a bug report to the GitHub repository.\n\nThanks!\n"
  },
  {
    "path": "SPONSORS.md",
    "content": "# Sponsors\n\nWe thank those who [support](https://www.patreon.com/identityserver) IdentityServer!\n\n## Corporate\n\n### Platinum\n[Udelt](https://udelt.no/)  \n[Microsoft .NET](https://github.com/dotnet-at-microsoft)\n\n### Gold\n[Ritter Insurance Marketing](https://www.ritterim.com) ([@RitterIM](https://twitter.com/ritterim))   \n[ExtranetUserManager](https://www.extranetusermanager.com) ([@eumgr](https://twitter.com/eumgr))  \n[Knab](https://www.knab.nl/) ([@knab_nl](https://twitter.com/knab_nl))  \n\n### Silver\n\nJacobus Roos  \nSoluto ([@SolutoEng](https://twitter.com/SolutoEng))  \nSteinar\tNoem  \nEffectory ([@effectory](https://twitter.com/effectory))  \nReal Page ([@RealPage](https://twitter.com/RealPage))  \nJustify ([@justify_legal](https://twitter.com/justify_legal))\n\n## Individuals\n\nKhalid Abuhakmeh ([@buhakmeh](https://twitter.com/buhakmeh))  \nRasika Weliwita ([@rasikaweliwita](https://twitter.com/rasikaweliwita))  \nArun David Shelly  \nTobias Höft ([@tobiashoeft](https://twitter.com/tobiashoeft))  \nWilliam Grow  \nJames Roberts  \nChris Simmons ([@netchrisdotcom](https://twitter.com/netchrisdotcom))  \nShawn Wildermuth  \nJohan Boström ([@zarx](https://twitter.com/zarx))  \nAlbert ([@DerAlbert](https://twitter.com/DerAlbert))  \nHugo Biarge ([@hbiarge](https://twitter.com/hbiarge))  \nIbrahim Šuta ([@ibrahimsuta](https://twitter.com/ibrahimsuta))  \nVIJAYA PAL NALLALA  \nMartijn Boland  \nGiuseppe Turitto  \nMauricio Schneider  \nNorman L Covington  \nRyan Mendoza  ([@elryry](https://twitter.com/elryry))  \nColin Blair  \nErik Gulbrandsen  \nOlga Klimova  \nAlexandru Puiu  \nMichael Calasanz  \nFredrik Karlsson ([@fredrik_zenit](https://twitter.com/fredrik_zenit))  \nJeremy Sinclair ([@sinclairinator](https://twitter.com/sinclairinator))  \nBruno Brito  \nJames Hough  \nvanbukin  \n"
  },
  {
    "path": "docker-compose.dcproj",
    "content": "<?xml version=\"1.0\" encoding=\"utf-8\"?>\n<Project ToolsVersion=\"15.0\" Sdk=\"Microsoft.Docker.Sdk\">\n  <PropertyGroup Label=\"Globals\">\n    <ProjectVersion>2.1</ProjectVersion>\n    <DockerTargetOS>Linux</DockerTargetOS>\n    <ProjectGuid>f817047f-018d-4f93-bda5-58602073b634</ProjectGuid>\n    <DockerLaunchAction>None</DockerLaunchAction>\n    <DockerServiceUrl>{Scheme}://localhost:{ServicePort}</DockerServiceUrl>\n    <DockerServiceName>IdentityServer8.Admin</DockerServiceName>\n  </PropertyGroup>\n  <ItemGroup>\n    <None Include=\"docker-compose.vs.debug.yml\">\n      <DependentUpon>docker-compose.yml</DependentUpon>\n    </None>\n    <None Include=\"docker-compose.override.yml\">\n      <DependentUpon>docker-compose.yml</DependentUpon>\n    </None>\n    <None Include=\"docker-compose.vs.release.yml\">\n      <DependentUpon>docker-compose.yml</DependentUpon>\n    </None>\n    <None Include=\"docker-compose.yml\" />\n    <None Include=\".dockerignore\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "docker-compose.override.yml",
    "content": "version: '3.4'\n\nservices:\n  IdentityServer8.Admin:\n    environment:\n      - ASPNETCORE_ENVIRONMENT=Development\n    volumes:\n      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro\n  \n  IdentityServer8.Admin.api:\n    environment:\n      - ASPNETCORE_ENVIRONMENT=Development\n    volumes:\n      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro\n\n  higginssoft.identityserver4.sts.identity:\n    environment:\n      - ASPNETCORE_ENVIRONMENT=Development\n    volumes:\n      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro\n"
  },
  {
    "path": "docker-compose.vs.debug.yml",
    "content": "version: '3.4'\n\nservices:\n  IdentityServer8.Admin:\n    volumes:\n      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro\n    labels:\n      com.microsoft.visualstudio.debuggee.arguments: ' --additionalProbingPath /root/.nuget/packages --additionalProbingPath /root/.nuget/fallbackpackages  \"bin/Debug/net6.0/IdentityServer8.Admin.dll\" /seed'\n\n  IdentityServer8.Admin.api:\n    volumes:\n      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro\n\n  higginssoft.identityserver4.sts.identity:\n    volumes:\n      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro\n"
  },
  {
    "path": "docker-compose.vs.release.yml",
    "content": "version: '3.4'\n\nservices:\n  IdentityServer8.Admin:\n    volumes:\n      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro\n    labels:\n      com.microsoft.visualstudio.debuggee.arguments: ' --additionalProbingPath /root/.nuget/packages --additionalProbingPath /root/.nuget/fallbackpackages  \"bin/Debug/net6.0/IdentityServer8.Admin.dll\" /seed'\n\n  IdentityServer8.Admin.api:\n    volumes:\n      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro\n\n  higginssoft.identityserver4.sts.identity:\n    volumes:\n      - ${APPDATA}/Microsoft/UserSecrets:/root/.microsoft/usersecrets:ro\n"
  },
  {
    "path": "docker-compose.yml",
    "content": "version: '3.4'\nservices:\n  nginx-proxy:\n    image: jwilder/nginx-proxy\n    container_name: nginx\n    ports:\n      - '80:80'\n      - '443:443'\n    volumes:\n      - '/var/run/docker.sock:/tmp/docker.sock:ro'\n      - './shared/nginx/vhost.d:/etc/nginx/vhost.d'\n      - './shared/nginx/certs:/etc/nginx/certs:ro'\n    networks:\n      proxy: null\n      identityserverui:\n        aliases:\n          - sts.higginssoft.local\n          - admin.higginssoft.local\n          - admin-api.higginssoft.local\n    restart: always\n  IdentityServer8.Admin:\n    image: '${DOCKER_REGISTRY-}higginssoft-identityserver4-admin'\n    build:\n      context: .\n      dockerfile: src/IdentityServer8.Admin/Dockerfile\n    container_name: higginssoft-identityserver4-admin\n    environment:\n      - VIRTUAL_HOST=admin.higginssoft.local\n      - 'ConnectionStrings__ConfigurationDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__PersistedGrantDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__IdentityDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__AdminLogDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__AdminAuditLogDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__DataProtectionDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'AdminConfiguration__IdentityAdminBaseUrl=https://admin.higginssoft.local'\n      - 'AdminConfiguration__IdentityAdminRedirectUri=https://admin.higginssoft.local/signin-oidc'\n      - 'AdminConfiguration__IdentityServerBaseUrl=https://sts.higginssoft.local'\n      - AdminConfiguration__RequireHttpsMetadata=false\n      - 'IdentityServerData__Clients__0__ClientUri=https://admin.higginssoft.local'\n      - 'IdentityServerData__Clients__0__RedirectUris__0=https://admin.higginssoft.local/signin-oidc'\n      - 'IdentityServerData__Clients__0__FrontChannelLogoutUri=https://admin.higginssoft.local/signin-oidc'\n      - 'IdentityServerData__Clients__0__PostLogoutRedirectUris__0=https://admin.higginssoft.local/signout-callback-oidc'\n      - 'IdentityServerData__Clients__0__AllowedCorsOrigins__0=https://admin.higginssoft.local'\n      - 'IdentityServerData__Clients__1__RedirectUris__0=https://admin-api.higginssoft.local/swagger/oauth2-redirect.html'\n      - 'Serilog__WriteTo__1__Args__connectionString=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - DockerConfiguration__UpdateCaCertificate=true\n      - ASPNETCORE_ENVIRONMENT=Development\n    command: dotnet IdentityServer8.Admin.dll /seed\n    depends_on:\n      - db\n      - higginssoft.identityserver4.sts.identity\n    volumes:\n      - './shared/serilog.json:/app/serilog.json'\n      - './shared/identitydata.json:/app/identitydata.json'\n      - './shared/identityserverdata.json:/app/identityserverdata.json'\n      - './shared/nginx/certs/cacerts.crt:/usr/local/share/ca-certificates/cacerts.crt'\n    networks:\n      identityserverui: null\n  IdentityServer8.Admin.api:\n    image: '${DOCKER_REGISTRY-}higginssoft-identityserver4-admin-api'\n    build:\n      context: .\n      dockerfile: src/IdentityServer8.Admin.Api/Dockerfile\n    container_name: higginssoft-identityserver4-admin-api\n    environment:\n      - VIRTUAL_HOST=admin-api.higginssoft.local\n      - AdminApiConfiguration__RequireHttpsMetadata=false\n      - 'AdminApiConfiguration__ApiBaseUrl=https://admin-api.higginssoft.local'\n      - 'AdminApiConfiguration__IdentityServerBaseUrl=https://sts.higginssoft.local'\n      - 'ConnectionStrings__ConfigurationDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__PersistedGrantDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__IdentityDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__AdminLogDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__AdminAuditLogDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__DataProtectionDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - DockerConfiguration__UpdateCaCertificate=true\n      - ASPNETCORE_ENVIRONMENT=Development\n    volumes:\n      - './shared/serilog.json:/app/serilog.json'\n      - './shared/nginx/certs/cacerts.crt:/usr/local/share/ca-certificates/cacerts.crt'\n    networks:\n      identityserverui: null\n  higginssoft.identityserver4.sts.identity:\n    image: '${DOCKER_REGISTRY-}higginssoft-identityserver4-sts-identity'\n    build:\n      context: .\n      dockerfile: src/IdentityServer8.STS.Identity/Dockerfile\n    container_name: higginssoft-identityserver4-sts-identity\n    environment:\n      - VIRTUAL_HOST=sts.higginssoft.local\n      - 'ConnectionStrings__ConfigurationDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__PersistedGrantDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__IdentityDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'ConnectionStrings__DataProtectionDbConnection=Server=db;Database=IdentityServer8Admin;User Id=sa;Password=${DB_PASSWORD:-Password_123};MultipleActiveResultSets=true'\n      - 'AdminConfiguration__IdentityAdminBaseUrl=https://admin.higginssoft.local'\n      - 'IdentityServerOptions__IssuerUri=https://sts.higginssoft.local'\n      - IdentityServerOptions__Events__RaiseErrorEvents=true\n      - IdentityServerOptions__Events__RaiseInformationEvents=true\n      - IdentityServerOptions__Events__RaiseFailureEvents=true\n      - IdentityServerOptions__Events__RaiseSuccessEvents=true\n      - DockerConfiguration__UpdateCaCertificate=true\n      - ASPNETCORE_ENVIRONMENT=Development\n    depends_on:\n      - db\n    volumes:\n      - './shared/serilog.json:/app/serilog.json'\n      - './shared/nginx/certs/cacerts.crt:/usr/local/share/ca-certificates/cacerts.crt'\n    networks:\n      identityserverui:\n        aliases:\n          - sts.higginssoft.local\n  db:\n    image: 'mcr.microsoft.com/mssql/server:2017-CU20-ubuntu-16.04'\n    ports:\n      - '7900:1433'\n    container_name: higginssoft-identityserver4-db\n    environment:\n      SA_PASSWORD: '${DB_PASSWORD:-Password_123}'\n      ACCEPT_EULA: 'Y'\n    volumes:\n      - 'dbdata:/var/opt/mssql'\n    networks:\n      identityserverui: null\nvolumes:\n  dbdata:\n    driver: local\nnetworks:\n  proxy:\n    driver: bridge\n  identityserverui:\n    driver: bridge\n"
  },
  {
    "path": "docs/CHANGELOG.md",
    "content": "# Change Log\nAll notable changes to this project will be documented in this file.\n \nThe format is based on [Keep a Changelog](http://keepachangelog.com/)\nand this project adheres to [Semantic Versioning 2](http://semver.org/).\n \n## [Unreleased] - 2024-02-17\n\n- Current templates and quickstarts being added to seperate template and quickstart repositories to continue previous version functionality.\n- DotNet tool to install template currently under development.\n- \n## [8.0.4] - 2024-02-17\n\nIdentity Server 8.0.4 is a security release that addresses hundreds of security vulnerabilities in the IdentityServer8 code base. We recommend that you update to this version.\n\n- Fix over 100+ security vulnerabilities in the IdentityServer8 code base:\n - #17 Unsafe expansion of self-closing HTML tag\n - #18 URL redirection from remote source\n - #19 DOM text reinterpreted as HTML\n - #20 Incomplete string escaping or encoding\n - #21 Inefficient regular expression bug dependencies\n - #22 Bad HTML filtering regexp bug dependencies\n - #23 User-controlled bypass of sensitive method bug\n - #24 Unsafe jQuery plugins bug dependencies\n\nAdditional the codebase has been refactored to use the latest DotNet 8 features and best practices. \n\nThis includes refactroing in #25 and consolidation of reused code that remove some nearly 1 million lines of code from the base.:\n- Convert Top Level usings\n- Convert Implicit usings.\n- Samples use shared API and MVC projects to reduce code duplication and need to maintain dozens of copies of the same code.\n\n## [8.0.3] - 2024-02-12\n\n- Security Updates: Addtional priority critical security patches addressing issues outline in #9 and #10.\n - [Security: User-controlled bypass of sensitive method] - Login Controller and view have have explicit methods to handle login and cancel to address User-controlled bypass of sensitive method\n - [Security: Logging of user-controlled data] - Unsanitized user input could be used to forge logs and inject arbitrary commands, including server side includes, xss and sql injection into log files.\n- [Maitenance]: Removed over half a million lines of code from the orginal Identity Server 4 code base using packages and libaries.\n - This will allow for easier maintenance and updates to the code base.\n - Developrs can now focus on the core functionality of Identity Server 8 and use LibMan to manage client side packages and keep packages up to date.\n- Documentation Website: identityserver8.readthedocs.io has been created and is now the official documentation website for IdentityServer8\n- Gitter: A Gitter chat room has been created for IdentityServer8. You can join the chat at https://app.gitter.im/#/room/#identityserver8:gitter.im\n- Framework Upgrade: Upgrade Samples, including Clients, Quickstarts, and Key Management, to use DotNet 8 sdk style.\n- [Quickstarts] (https://github.com/alexhiggins732/IdentityServer8/tree/master/samples/Quickstarts) - Updated Quickstart samples to use Dotnet 8 startup with implicit usings and minimal Api.\n- [Clients] (https://github.com/alexhiggins732/IdentityServer8/tree/master/samples/Clients) - Updated client samples to use Dotnet 8 startup with implicit usings and minimal Api.\n- [Key Management] (https://github.com/alexhiggins732/IdentityServer8/tree/master/samples/KeyManagement) - Updated Key management samples to use Dotnet 8 startup with implicit usings and minimal Api. Changed default Entity Framework storage to file system storage as original Key Management is a paid solution. Roadmap: Add DbContext implementation fof key management.\n- Client Side Packages: Client Side packages have now been ignored in source and are now installed using LibMan during the build process. This will allow for easier updates and management of client side packages.\n\n## [8.0.2] - 2024-02-12\n\n- Security Updates: Addtional priority critical security patches addressing issues outline in #9 and #10.\n\n## [8.0.1] - 2024-02-10\n \n- Security Update: High priority critical security patches addressing issues outline in #9 and #10.\n\n \n### Added\n- `IdentityServer8.Security` nuget packages with services to sanitize user input including html, json, xml, javascript, scripts, urls, logs, css, and style sheets.\n\n### Changed\n- [Account Login Controller] (https://github.com/alexhiggins732/IdentityServer8/issues/9) \n- [Account Login View] (https://github.com/alexhiggins732/IdentityServer8/issues/9)  \n \n### Fixed\n- [Security: User-controlled bypass of sensitive method]\n  Login Controller and view have have explicit methods to handle login and cancel to address User-controlled bypass of sensitive method\n- [Security: Logging of user-controlled data]\n  Unsanitized user input could be used to forge logs and inject arbitrary commands, including server side includes, xss and sql injection into log files.\n  \n## [8.0.1] - 2024-02-10\n  \nUpdated build scripts to use Git Flow branching for SemVer2 compatible nuget packages.\n \n### Added\n\n- CodeQl Security scanning\n- Dependabot Package scanning. \n### Changed\n  \n- [IdentityServer8 8.0.1 changes]https://github.com/alexhiggins732/IdentityServer8/pull/7) \n\n### Fixed\n \n- Nuget Package version conflicts.\n \n## [8.0.0] - 2024-02-09\n \n### Added\nBuild scripts and readme documentation for initial port from Identity Server 4 and Identity Server 4 Admin   \n### Changed\nUpgraded Main Identity Server projects and Nuget packages to DotNet 8 \n### Fixed\n \n- Changed mixed dependencies on `System.Text.Json` and `Newtonsoft.Json` to use `System.Text.Json` which resolved several bugs.\n- Change package dependencies and version requirements to run on the latest DotNet 8 packages, resolving many security vulnerablities."
  },
  {
    "path": "docs/Makefile",
    "content": "# Makefile for Sphinx documentation\n#\n\n# You can set these variables from the command line.\nSPHINXOPTS    =\nSPHINXBUILD   = sphinx-build\nPAPER         =\nBUILDDIR      = _build\n\n# Internal variables.\nPAPEROPT_a4     = -D latex_paper_size=a4\nPAPEROPT_letter = -D latex_paper_size=letter\nALLSPHINXOPTS   = -d $(BUILDDIR)/doctrees $(PAPEROPT_$(PAPER)) $(SPHINXOPTS) .\n# the i18n builder cannot share the environment and doctrees with the others\nI18NSPHINXOPTS  = $(PAPEROPT_$(PAPER)) $(SPHINXOPTS) .\n\n.PHONY: help\nhelp:\n\t@echo \"Please use \\`make <target>' where <target> is one of\"\n\t@echo \"  html       to make standalone HTML files\"\n\t@echo \"  dirhtml    to make HTML files named index.html in directories\"\n\t@echo \"  singlehtml to make a single large HTML file\"\n\t@echo \"  pickle     to make pickle files\"\n\t@echo \"  json       to make JSON files\"\n\t@echo \"  htmlhelp   to make HTML files and a HTML help project\"\n\t@echo \"  qthelp     to make HTML files and a qthelp project\"\n\t@echo \"  applehelp  to make an Apple Help Book\"\n\t@echo \"  devhelp    to make HTML files and a Devhelp project\"\n\t@echo \"  epub       to make an epub\"\n\t@echo \"  epub3      to make an epub3\"\n\t@echo \"  latex      to make LaTeX files, you can set PAPER=a4 or PAPER=letter\"\n\t@echo \"  latexpdf   to make LaTeX files and run them through pdflatex\"\n\t@echo \"  latexpdfja to make LaTeX files and run them through platex/dvipdfmx\"\n\t@echo \"  text       to make text files\"\n\t@echo \"  man        to make manual pages\"\n\t@echo \"  texinfo    to make Texinfo files\"\n\t@echo \"  info       to make Texinfo files and run them through makeinfo\"\n\t@echo \"  gettext    to make PO message catalogs\"\n\t@echo \"  changes    to make an overview of all changed/added/deprecated items\"\n\t@echo \"  xml        to make Docutils-native XML files\"\n\t@echo \"  pseudoxml  to make pseudoxml-XML files for display purposes\"\n\t@echo \"  linkcheck  to check all external links for integrity\"\n\t@echo \"  doctest    to run all doctests embedded in the documentation (if enabled)\"\n\t@echo \"  coverage   to run coverage check of the documentation (if enabled)\"\n\t@echo \"  dummy      to check syntax errors of document sources\"\n\n.PHONY: clean\nclean:\n\trm -rf $(BUILDDIR)/*\n\n.PHONY: html\nhtml:\n\t$(SPHINXBUILD) -b html $(ALLSPHINXOPTS) $(BUILDDIR)/html\n\t@echo\n\t@echo \"Build finished. The HTML pages are in $(BUILDDIR)/html.\"\n\n.PHONY: dirhtml\ndirhtml:\n\t$(SPHINXBUILD) -b dirhtml $(ALLSPHINXOPTS) $(BUILDDIR)/dirhtml\n\t@echo\n\t@echo \"Build finished. The HTML pages are in $(BUILDDIR)/dirhtml.\"\n\n.PHONY: singlehtml\nsinglehtml:\n\t$(SPHINXBUILD) -b singlehtml $(ALLSPHINXOPTS) $(BUILDDIR)/singlehtml\n\t@echo\n\t@echo \"Build finished. The HTML page is in $(BUILDDIR)/singlehtml.\"\n\n.PHONY: pickle\npickle:\n\t$(SPHINXBUILD) -b pickle $(ALLSPHINXOPTS) $(BUILDDIR)/pickle\n\t@echo\n\t@echo \"Build finished; now you can process the pickle files.\"\n\n.PHONY: json\njson:\n\t$(SPHINXBUILD) -b json $(ALLSPHINXOPTS) $(BUILDDIR)/json\n\t@echo\n\t@echo \"Build finished; now you can process the JSON files.\"\n\n.PHONY: htmlhelp\nhtmlhelp:\n\t$(SPHINXBUILD) -b htmlhelp $(ALLSPHINXOPTS) $(BUILDDIR)/htmlhelp\n\t@echo\n\t@echo \"Build finished; now you can run HTML Help Workshop with the\" \\\n\t      \".hhp project file in $(BUILDDIR)/htmlhelp.\"\n\n.PHONY: qthelp\nqthelp:\n\t$(SPHINXBUILD) -b qthelp $(ALLSPHINXOPTS) $(BUILDDIR)/qthelp\n\t@echo\n\t@echo \"Build finished; now you can run \"qcollectiongenerator\" with the\" \\\n\t      \".qhcp project file in $(BUILDDIR)/qthelp, like this:\"\n\t@echo \"# qcollectiongenerator $(BUILDDIR)/qthelp/IdentityServer8.qhcp\"\n\t@echo \"To view the help file:\"\n\t@echo \"# assistant -collectionFile $(BUILDDIR)/qthelp/IdentityServer8.qhc\"\n\n.PHONY: applehelp\napplehelp:\n\t$(SPHINXBUILD) -b applehelp $(ALLSPHINXOPTS) $(BUILDDIR)/applehelp\n\t@echo\n\t@echo \"Build finished. The help book is in $(BUILDDIR)/applehelp.\"\n\t@echo \"N.B. You won't be able to view it unless you put it in\" \\\n\t      \"~/Library/Documentation/Help or install it in your application\" \\\n\t      \"bundle.\"\n\n.PHONY: devhelp\ndevhelp:\n\t$(SPHINXBUILD) -b devhelp $(ALLSPHINXOPTS) $(BUILDDIR)/devhelp\n\t@echo\n\t@echo \"Build finished.\"\n\t@echo \"To view the help file:\"\n\t@echo \"# mkdir -p $$HOME/.local/share/devhelp/IdentityServer8\"\n\t@echo \"# ln -s $(BUILDDIR)/devhelp $$HOME/.local/share/devhelp/IdentityServer8\"\n\t@echo \"# devhelp\"\n\n.PHONY: epub\nepub:\n\t$(SPHINXBUILD) -b epub $(ALLSPHINXOPTS) $(BUILDDIR)/epub\n\t@echo\n\t@echo \"Build finished. The epub file is in $(BUILDDIR)/epub.\"\n\n.PHONY: epub3\nepub3:\n\t$(SPHINXBUILD) -b epub3 $(ALLSPHINXOPTS) $(BUILDDIR)/epub3\n\t@echo\n\t@echo \"Build finished. The epub3 file is in $(BUILDDIR)/epub3.\"\n\n.PHONY: latex\nlatex:\n\t$(SPHINXBUILD) -b latex $(ALLSPHINXOPTS) $(BUILDDIR)/latex\n\t@echo\n\t@echo \"Build finished; the LaTeX files are in $(BUILDDIR)/latex.\"\n\t@echo \"Run \\`make' in that directory to run these through (pdf)latex\" \\\n\t      \"(use \\`make latexpdf' here to do that automatically).\"\n\n.PHONY: latexpdf\nlatexpdf:\n\t$(SPHINXBUILD) -b latex $(ALLSPHINXOPTS) $(BUILDDIR)/latex\n\t@echo \"Running LaTeX files through pdflatex...\"\n\t$(MAKE) -C $(BUILDDIR)/latex all-pdf\n\t@echo \"pdflatex finished; the PDF files are in $(BUILDDIR)/latex.\"\n\n.PHONY: latexpdfja\nlatexpdfja:\n\t$(SPHINXBUILD) -b latex $(ALLSPHINXOPTS) $(BUILDDIR)/latex\n\t@echo \"Running LaTeX files through platex and dvipdfmx...\"\n\t$(MAKE) -C $(BUILDDIR)/latex all-pdf-ja\n\t@echo \"pdflatex finished; the PDF files are in $(BUILDDIR)/latex.\"\n\n.PHONY: text\ntext:\n\t$(SPHINXBUILD) -b text $(ALLSPHINXOPTS) $(BUILDDIR)/text\n\t@echo\n\t@echo \"Build finished. The text files are in $(BUILDDIR)/text.\"\n\n.PHONY: man\nman:\n\t$(SPHINXBUILD) -b man $(ALLSPHINXOPTS) $(BUILDDIR)/man\n\t@echo\n\t@echo \"Build finished. The manual pages are in $(BUILDDIR)/man.\"\n\n.PHONY: texinfo\ntexinfo:\n\t$(SPHINXBUILD) -b texinfo $(ALLSPHINXOPTS) $(BUILDDIR)/texinfo\n\t@echo\n\t@echo \"Build finished. The Texinfo files are in $(BUILDDIR)/texinfo.\"\n\t@echo \"Run \\`make' in that directory to run these through makeinfo\" \\\n\t      \"(use \\`make info' here to do that automatically).\"\n\n.PHONY: info\ninfo:\n\t$(SPHINXBUILD) -b texinfo $(ALLSPHINXOPTS) $(BUILDDIR)/texinfo\n\t@echo \"Running Texinfo files through makeinfo...\"\n\tmake -C $(BUILDDIR)/texinfo info\n\t@echo \"makeinfo finished; the Info files are in $(BUILDDIR)/texinfo.\"\n\n.PHONY: gettext\ngettext:\n\t$(SPHINXBUILD) -b gettext $(I18NSPHINXOPTS) $(BUILDDIR)/locale\n\t@echo\n\t@echo \"Build finished. The message catalogs are in $(BUILDDIR)/locale.\"\n\n.PHONY: changes\nchanges:\n\t$(SPHINXBUILD) -b changes $(ALLSPHINXOPTS) $(BUILDDIR)/changes\n\t@echo\n\t@echo \"The overview file is in $(BUILDDIR)/changes.\"\n\n.PHONY: linkcheck\nlinkcheck:\n\t$(SPHINXBUILD) -b linkcheck $(ALLSPHINXOPTS) $(BUILDDIR)/linkcheck\n\t@echo\n\t@echo \"Link check complete; look for any errors in the above output \" \\\n\t      \"or in $(BUILDDIR)/linkcheck/output.txt.\"\n\n.PHONY: doctest\ndoctest:\n\t$(SPHINXBUILD) -b doctest $(ALLSPHINXOPTS) $(BUILDDIR)/doctest\n\t@echo \"Testing of doctests in the sources finished, look at the \" \\\n\t      \"results in $(BUILDDIR)/doctest/output.txt.\"\n\n.PHONY: coverage\ncoverage:\n\t$(SPHINXBUILD) -b coverage $(ALLSPHINXOPTS) $(BUILDDIR)/coverage\n\t@echo \"Testing of coverage in the sources finished, look at the \" \\\n\t      \"results in $(BUILDDIR)/coverage/python.txt.\"\n\n.PHONY: xml\nxml:\n\t$(SPHINXBUILD) -b xml $(ALLSPHINXOPTS) $(BUILDDIR)/xml\n\t@echo\n\t@echo \"Build finished. The XML files are in $(BUILDDIR)/xml.\"\n\n.PHONY: pseudoxml\npseudoxml:\n\t$(SPHINXBUILD) -b pseudoxml $(ALLSPHINXOPTS) $(BUILDDIR)/pseudoxml\n\t@echo\n\t@echo \"Build finished. The pseudo-XML files are in $(BUILDDIR)/pseudoxml.\"\n\n.PHONY: dummy\ndummy:\n\t$(SPHINXBUILD) -b dummy $(ALLSPHINXOPTS) $(BUILDDIR)/dummy\n\t@echo\n\t@echo \"Build finished. Dummy builder generates no files.\"\n"
  },
  {
    "path": "docs/autobuild.bat",
    "content": "sphinx-autobuild.exe . .\\_build\\html\\"
  },
  {
    "path": "docs/build-documentation.ps1",
    "content": ".\\docker-build.ps1\ndocker run --rm -v .:/docs sphinx-doc/sphinx_rtd_theme make html\n"
  },
  {
    "path": "docs/conf.py",
    "content": "#!/usr/bin/env python3\n# -*- coding: utf-8 -*-\n#\n# IdentityServer8 documentation build configuration file, created by\n# sphinx-quickstart on Wed Jul 20 08:57:27 2016.\n#\n# This file is execfile()d with the current directory set to its\n# containing dir.\n#\n# Note that not all possible configuration values are present in this\n# autogenerated file.\n#\n# All configuration values have a default; values that are commented out\n# serve to show the default.\n\n# If extensions (or modules to document with autodoc) are in another directory,\n# add these directories to sys.path here. If the directory is relative to the\n# documentation root, use os.path.abspath to make it absolute, like shown here.\n#\n# import os\n# import sys\n# sys.path.insert(0, os.path.abspath('.'))\n\n# -- General configuration ------------------------------------------------\n\n# If your documentation needs a minimal Sphinx version, state it here.\n#\n# needs_sphinx = '1.0'\n\n# Add any Sphinx extension module names here, as strings. They can be\n# extensions coming with Sphinx (named 'sphinx.ext.*') or your custom\n# ones.\nextensions = [\n    'sphinx_rtd_theme',\n]\n\n# Add any paths that contain templates here, relative to this directory.\ntemplates_path = ['_templates']\n\n# The suffix(es) of source filenames.\n# You can specify multiple suffix as a list of string:\n#\n# source_suffix = ['.rst', '.md']\n\n# markdown support\n#from recommonmark.parser import CommonMarkParser\n\n#source_parsers = {\n#    '.md': CommonMarkParser,\n#}\n\nsource_suffix = ['.rst']\n\n\n# The encoding of source files.\n#\n# source_encoding = 'utf-8-sig'\n\n# The master toctree document.\nmaster_doc = 'index'\n\n# General information about the project.\nproject = 'IdentityServer8'\ncopyright = '2024 HigginsSoft, Alexander Higgins'\nauthor = 'Alexander Higgins'\n\n# The version info for the project you're documenting, acts as replacement for\n# |version| and |release|, also used in various other places throughout the\n# built documents.\n#\n# The short X.Y version.\nversion = '8.0.0'\n# The full version, including alpha/beta/rc tags.\nrelease = '8.0.4'\n\n# The language for content autogenerated by Sphinx. Refer to documentation\n# for a list of supported languages.\n#\n# This is also used if you do content translation via gettext catalogs.\n# Usually you set \"language\" from the command line for these cases.\nlanguage = None\n\n# There are two options for replacing |today|: either, you set today to some\n# non-false value, then it is used:\n#\n# today = ''\n#\n# Else, today_fmt is used as the format for a strftime call.\n#\n# today_fmt = '%B %d, %Y'\n\n# List of patterns, relative to source directory, that match files and\n# directories to ignore when looking for source files.\n# This patterns also effect to html_static_path and html_extra_path\nexclude_patterns = ['_build', 'Thumbs.db', '.DS_Store']\n\n# The reST default role (used for this markup: `text`) to use for all\n# documents.\n#\n# default_role = None\n\n# If true, '()' will be appended to :func: etc. cross-reference text.\n#\n# add_function_parentheses = True\n\n# If true, the current module name will be prepended to all description\n# unit titles (such as .. function::).\n#\n# add_module_names = True\n\n# If true, sectionauthor and moduleauthor directives will be shown in the\n# output. They are ignored by default.\n#\n# show_authors = False\n\n# The name of the Pygments (syntax highlighting) style to use.\npygments_style = 'default'\nhighlight_language = 'csharp'\n\n# A list of ignored prefixes for module index sorting.\n# modindex_common_prefix = []\n\n# If true, keep warnings as \"system message\" paragraphs in the built documents.\n# keep_warnings = False\n\n# If true, `todo` and `todoList` produce output, else they produce nothing.\ntodo_include_todos = False\n\n\n# -- Options for HTML output ----------------------------------------------\n\n# The theme to use for HTML and HTML Help pages.  See the documentation for\n# a list of builtin themes.\n#\nhtml_theme = 'sphinx_rtd_theme'\n\n# on_rtd is whether we are on readthedocs.org, this line of code grabbed from docs.readthedocs.org\nimport os\non_rtd = os.environ.get('READTHEDOCS', None) == 'True'\nif not on_rtd:  # only import and set the theme if we're building docs locally\n#    import sphinx_rtd_theme\n   html_theme = 'sphinx_rtd_theme'\n#    html_theme_path = [sphinx_rtd_theme.get_html_theme_path()]\n\n# otherwise, readthedocs.org uses their theme by default, so no need to specify it\n\n# Theme options are theme-specific and customize the look and feel of a theme\n# further.  For a list of options available for each theme, see the\n# documentation.\n#\n# html_theme_options = {}\n\n# Add any paths that contain custom themes here, relative to this directory.\n# html_theme_path = []\n\n# The name for this set of Sphinx documents.\n# \"<project> v<release> documentation\" by default.\n#\n# html_title = 'IdentityServer8 v1.0.0'\n\n# A shorter title for the navigation bar.  Default is the same as html_title.\n#\n# html_short_title = None\n\n# The name of an image file (relative to this directory) to place at the top\n# of the sidebar.\n#\n# html_logo = None\n\n# The name of an image file (relative to this directory) to use as a favicon of\n# the docs.  This file should be a Windows icon file (.ico) being 16x16 or 32x32\n# pixels large.\n#\nhtml_favicon = 'favicon.ico'\n\n# Add any paths that contain custom static files (such as style sheets) here,\n# relative to this directory. They are copied after the builtin static files,\n# so a file named \"default.css\" will overwrite the builtin \"default.css\".\nhtml_static_path = ['_static']\n\n# Add any extra paths that contain custom files (such as robots.txt or\n# .htaccess) here, relative to this directory. These files are copied\n# directly to the root of the documentation.\n#\n# html_extra_path = []\n\n# If not None, a 'Last updated on:' timestamp is inserted at every page\n# bottom, using the given strftime format.\n# The empty string is equivalent to '%b %d, %Y'.\n#\n# html_last_updated_fmt = None\n\n# If true, SmartyPants will be used to convert quotes and dashes to\n# typographically correct entities.\n#\n# html_use_smartypants = True\n\n# Custom sidebar templates, maps document names to template names.\n#\n# html_sidebars = {}\n\n# Additional templates that should be rendered to pages, maps page names to\n# template names.\n#\n# html_additional_pages = {}\n\n# If false, no module index is generated.\n#\n# html_domain_indices = True\n\n# If false, no index is generated.\n#\n# html_use_index = True\n\n# If true, the index is split into individual pages for each letter.\n#\n# html_split_index = False\n\n# If true, links to the reST sources are added to the pages.\n#\n# html_show_sourcelink = True\n\n# If true, \"Created using Sphinx\" is shown in the HTML footer. Default is True.\n#\n# html_show_sphinx = True\n\n# If true, \"(C) Copyright ...\" is shown in the HTML footer. Default is True.\n#\n# html_show_copyright = True\n\n# If true, an OpenSearch description file will be output, and all pages will\n# contain a <link> tag referring to it.  The value of this option must be the\n# base URL from which the finished HTML is served.\n#\n# html_use_opensearch = ''\n\n# This is the file name suffix for HTML files (e.g. \".xhtml\").\n# html_file_suffix = None\n\n# Language to be used for generating the HTML full-text search index.\n# Sphinx supports the following languages:\n#   'da', 'de', 'en', 'es', 'fi', 'fr', 'h', 'it', 'ja'\n#   'nl', 'no', 'pt', 'ro', 'r', 'sv', 'tr', 'zh'\n#\n# html_search_language = 'en'\n\n# A dictionary with options for the search language support, empty by default.\n# 'ja' uses this config value.\n# 'zh' user can custom change `jieba` dictionary path.\n#\n# html_search_options = {'type': 'default'}\n\n# The name of a javascript file (relative to the configuration directory) that\n# implements a search results scorer. If empty, the default will be used.\n#\n# html_search_scorer = 'scorer.js'\n\n# Output file base name for HTML help builder.\nhtmlhelp_basename = 'IdentityServer8doc'\n\n# -- Options for LaTeX output ---------------------------------------------\n\nlatex_elements = {\n     # The paper size ('letterpaper' or 'a4paper').\n     #\n     # 'papersize': 'letterpaper',\n\n     # The font size ('10pt', '11pt' or '12pt').\n     #\n     # 'pointsize': '10pt',\n\n     # Additional stuff for the LaTeX preamble.\n     #\n     # 'preamble': '',\n\n     # Latex figure (float) alignment\n     #\n     # 'figure_align': 'htbp',\n}\n\n# Grouping the document tree into LaTeX files. List of tuples\n# (source start file, target name, title,\n#  author, documentclass [howto, manual, or own class]).\nlatex_documents = [\n    (master_doc, 'IdentityServer8.tex', 'IdentityServer8 Documentation',\n     'HigginsSoft, Alexander Higgins', 'manual'),\n]\n\n# The name of an image file (relative to this directory) to place at the top of\n# the title page.\n#\n# latex_logo = None\n\n# For \"manual\" documents, if this is true, then toplevel headings are parts,\n# not chapters.\n#\n# latex_use_parts = False\n\n# If true, show page references after internal links.\n#\n# latex_show_pagerefs = False\n\n# If true, show URL addresses after external links.\n#\n# latex_show_urls = False\n\n# Documents to append as an appendix to all manuals.\n#\n# latex_appendices = []\n\n# It false, will not define \\strong, \\code, \titleref, \\crossref ... but only\n# \\sphinxstrong, ..., \\sphinxtitleref, ... To help avoid clash with user added\n# packages.\n#\n# latex_keep_old_macro_names = True\n\n# If false, no module index is generated.\n#\n# latex_domain_indices = True\n\n\n# -- Options for manual page output ---------------------------------------\n\n# One entry per manual page. List of tuples\n# (source start file, name, description, authors, manual section).\nman_pages = [\n    (master_doc, 'IdentityServer8', 'IdentityServer8 Documentation',\n     [author], 1)\n]\n\n# If true, show URL addresses after external links.\n#\n# man_show_urls = False\n\n\n# -- Options for Texinfo output -------------------------------------------\n\n# Grouping the document tree into Texinfo files. List of tuples\n# (source start file, target name, title, author,\n#  dir menu entry, description, category)\ntexinfo_documents = [\n    (master_doc, 'IdentityServer8', 'IdentityServer8 Documentation',\n     author, 'IdentityServer8', 'One line description of project.',\n     'Miscellaneous'),\n]\n\n# Documents to append as an appendix to all manuals.\n#\n# texinfo_appendices = []\n\n# If false, no module index is generated.\n#\n# texinfo_domain_indices = True\n\n# How to display URL addresses: 'footnote', 'no', or 'inline'.\n#\n# texinfo_show_urls = 'footnote'\n\n# If true, do not generate a @detailmenu in the \"Top\" node's menu.\n#\n# texinfo_no_detailmenu = False\n"
  },
  {
    "path": "docs/docker-build.ps1",
    "content": "docker build -t sphinx-doc/sphinx_rtd_theme ."
  },
  {
    "path": "docs/dockerfile",
    "content": "FROM sphinxdoc/sphinx\n\nRUN pip install sphinx_rtd_theme"
  },
  {
    "path": "docs/endpoints/authorize.rst",
    "content": "Authorize Endpoint\n==================\n\nThe authorize endpoint can be used to request tokens or authorization codes via the browser.\nThis process typically involves authentication of the end-user and optionally consent.\n\n.. Note:: IdentityServer supports a subset of the OpenID Connect and OAuth 2.0 authorize request parameters. For a full list, see `here <https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest>`_.\n\n``client_id``\n    identifier of the client (required).\n``request``\n    instead of providing all parameters as individual query string parameters, you can provide a subset or all of them as a JWT\n``request_uri``\n    URL of a pre-packaged JWT containing request parameters\n``scope``\n    one or more registered scopes (required)\n``redirect_uri`` \n    must exactly match one of the allowed redirect URIs for that client (required)\n``response_type`` \n    ``id_token`` requests an identity token (only identity scopes are allowed)\n\n    ``token`` requests an access token (only resource scopes are allowed)\n\n    ``id_token token`` requests an identity token and an access token\n\n    ``code`` requests an authorization code\n\n    ``code id_token`` requests an authorization code and identity token\n\n    ``code id_token token`` requests an authorization code, identity token and access token\n    \n``response_mode``\n    ``form_post`` sends the token response as a form post instead of a fragment encoded redirect (optional)\n``state`` \n    identityserver will echo back the state value on the token response, \n    this is for round tripping state between client and provider, correlating request and response and CSRF/replay protection. (recommended)\n``nonce`` \n    identityserver will echo back the nonce value in the identity token, this is for replay protection)\n\n    *Required for identity tokens via implicit grant.*\n``prompt``\n    ``none`` no UI will be shown during the request. If this is not possible (e.g. because the user has to sign in or consent) an error is returned\n    \n    ``login`` the login UI will be shown, even if the user is already signed-in and has a valid session\n``code_challenge``\n    sends the code challenge for PKCE\n``code_challenge_method``\n    ``plain`` indicates that the challenge is using plain text (not recommended)\n    ``S256`` indicates the challenge is hashed with SHA256\n``login_hint``\n    can be used to pre-fill the username field on the login page\n``ui_locales``\n    gives a hint about the desired display language of the login UI\n``max_age``\n    if the user's logon session exceeds the max age (in seconds), the login UI will be shown\n``acr_values``\n    allows passing in additional authentication related information - identityserver special cases the following proprietary acr_values:\n        \n        ``idp:name_of_idp`` bypasses the login/home realm screen and forwards the user directly to the selected identity provider (if allowed per client configuration)\n        \n        ``tenant:name_of_tenant`` can be used to pass a tenant name to the login UI\n\n**Example**\n\n::\n\n    GET /connect/authorize?\n        client_id=client1&\n        scope=openid email api1&\n        response_type=id_token token&\n        redirect_uri=https://myapp/callback&\n        state=abc&\n        nonce=xyz \n\n(URL encoding removed, and line breaks added for readability)\n\n.. Note:: You can use the `IdentityModel <https://github.com/IdentityModel/IdentityModel2>`_ client library to programmatically create authorize requests .NET code. For more information check the IdentityModel `docs <https://identitymodel.readthedocs.io/en/latest/client/authorize.html>`_.\n"
  },
  {
    "path": "docs/endpoints/device_authorization.rst",
    "content": "Device Authorization Endpoint\n=============================\n\nThe device authorization endpoint can be used to request device and user codes.\nThis endpoint is used to start the device flow authorization process.\n\n.. Note:: The URL for the end session endpoint is available via the :ref:`discovery endpoint <refDiscovery>`.\n\n``client_id``\n    client identifier (required)\n``client_secret``\n    client secret either in the post body, or as a basic authentication header. Optional.\n``scope``\n    one or more registered scopes. If not specified, a token for all explicitly allowed scopes will be issued.\n\nExample\n^^^^^^^\n\n::\n\n    POST /connect/deviceauthorization\n\n        client_id=client1&\n        client_secret=secret&\n        scope=openid api1\n\n(Form-encoding removed and line breaks added for readability)\n\n.. Note:: You can use the `IdentityModel <https://github.com/IdentityModel/IdentityModel2>`_ client library to programmatically access the device authorization endpoint from .NET code. For more information check the IdentityModel `docs <https://identitymodel.readthedocs.io/en/latest/client/device_authorize.html>`_."
  },
  {
    "path": "docs/endpoints/discovery.rst",
    "content": ".. _refDiscovery:\nDiscovery Endpoint\n==================\n\nThe discovery endpoint can be used to retrieve metadata about your IdentityServer - \nit returns information like the issuer name, key material, supported scopes etc. See the `spec <https://openid.net/specs/openid-connect-discovery-1_0.html>`_ for more details.\n\nThe discovery endpoint is available via `/.well-known/openid-configuration` relative to the base address, e.g.::\n\n    https://demo.identityserver8.io/.well-known/openid-configuration\n\n.. Note:: You can use the `IdentityModel <https://github.com/IdentityModel/IdentityModel2>`_ client library to programmatically access the discovery endpoint from .NET code. For more information check the IdentityModel `docs <https://identitymodel.readthedocs.io/en/latest/client/discovery.html>`_.\n"
  },
  {
    "path": "docs/endpoints/endsession.rst",
    "content": ".. _refEndSession:\nEnd Session Endpoint\n====================\n\nThe end session endpoint can be used to trigger single sign-out (see `spec <https://openid.net/specs/openid-connect-rpinitiated-1_0.html>`_).\n\nTo use the end session endpoint a client application will redirect the user's browser to the end session URL.\nAll applications that the user has logged into via the browser during the user's session can participate in the sign-out.\n\n.. Note:: The URL for the end session endpoint is available via the :ref:`discovery endpoint <refDiscovery>`.\n\nParameters\n^^^^^^^^^^\n\n**id_token_hint**\n\nWhen the user is redirected to the endpoint, they will be prompted if they really want to sign-out. \nThis prompt can be bypassed by a client sending the original *id_token* received from authentication.\nThis is passed as a query string parameter called ``id_token_hint``.\n\n**post_logout_redirect_uri**\n\nIf a valid ``id_token_hint`` is passed, then the client may also send a ``post_logout_redirect_uri`` parameter.\nThis can be used to allow the user to redirect back to the client after sign-out.\nThe value must match one of the client's pre-configured `PostLogoutRedirectUris` (:ref:`client docs <refClient>`).\n\n**state**\n\nIf a valid ``post_logout_redirect_uri`` is passed, then the client may also send a ``state`` parameter.\nThis will be returned back to the client as a query string parameter after the user redirects back to the client.\nThis is typically used by clients to round-trip state across the redirect.\n\nExample\n^^^^^^^\n\n::\n\n    GET /connect/endsession?id_token_hint=eyJhbGciOiJSUzI1NiIsImtpZCI6IjdlOGFkZmMzMjU1OTEyNzI0ZDY4NWZmYmIwOThjNDEyIiwidHlwIjoiSldUIn0.eyJuYmYiOjE0OTE3NjUzMjEsImV4cCI6MTQ5MTc2NTYyMSwiaXNzIjoiaHR0cDovL2xvY2FsaG9zdDo1MDAwIiwiYXVkIjoianNfb2lkYyIsIm5vbmNlIjoiYTQwNGFjN2NjYWEwNGFmNzkzNmJjYTkyNTJkYTRhODUiLCJpYXQiOjE0OTE3NjUzMjEsInNpZCI6IjI2YTYzNWVmOTQ2ZjRiZGU3ZWUzMzQ2ZjFmMWY1NTZjIiwic3ViIjoiODg0MjExMTMiLCJhdXRoX3RpbWUiOjE0OTE3NjUzMTksImlkcCI6ImxvY2FsIiwiYW1yIjpbInB3ZCJdfQ.STzOWoeVYMtZdRAeRT95cMYEmClixWkmGwVH2Yyiks9BETotbSZiSfgE5kRh72kghN78N3-RgCTUmM2edB3bZx4H5ut3wWsBnZtQ2JLfhTwJAjaLE9Ykt68ovNJySbm8hjZhHzPWKh55jzshivQvTX0GdtlbcDoEA1oNONxHkpDIcr3pRoGi6YveEAFsGOeSQwzT76aId-rAALhFPkyKnVc-uB8IHtGNSyRWLFhwVqAdS3fRNO7iIs5hYRxeFSU7a5ZuUqZ6RRi-bcDhI-djKO5uAwiyhfpbpYcaY_TxXWoCmq8N8uAw9zqFsQUwcXymfOAi2UF3eFZt02hBu-shKA&post_logout_redirect_uri=http%3A%2F%2Flocalhost%3A7017%2Findex.html\n\n.. Note:: You can use the `IdentityModel <https://github.com/IdentityModel/IdentityModel2>`_ client library to programmatically create end_session requests .NET code. For more information check the IdentityModel `docs <https://identitymodel.readthedocs.io/en/latest/client/end_session.html>`_.\n"
  },
  {
    "path": "docs/endpoints/introspection.rst",
    "content": "Introspection Endpoint\n======================\n\nThe introspection endpoint is an implementation of `RFC 7662 <https://tools.ietf.org/html/rfc7662>`_.\n\nIt can be used to validate reference tokens (or JWTs if the consumer does not have support for appropriate JWT or cryptographic libraries).\nThe introspection endpoint requires authentication - since the client of an introspection endpoint is an API, you configure the secret on the ``ApiResource``.\n\nExample\n^^^^^^^\n\n::\n\n\n    POST /connect/introspect\n    Authorization: Basic xxxyyy\n\n    token=<token>\n\n\nA successful response will return a status code of 200 and either an active or inactive token::\n\n\n    {\n        \"active\": true,\n        \"sub\": \"123\"\n    }\n\n\nUnknown or expired tokens will be marked as inactive::\n\n\n    {\n        \"active\": false,\n    }\n\n\nAn invalid request will return a 400, an unauthorized request 401.\n\n.. Note:: You can use the `IdentityModel <https://github.com/IdentityModel/IdentityModel2>`_ client library to programmatically access the introspection endpoint from .NET code. For more information check the IdentityModel `docs <https://identitymodel.readthedocs.io/en/latest/client/introspection.html>`_."
  },
  {
    "path": "docs/endpoints/revocation.rst",
    "content": "Revocation Endpoint\n===================\n\nThis endpoint allows revoking access tokens (reference tokens only) and refresh token. \nIt implements the token revocation specification `(RFC 7009) <https://tools.ietf.org/html/rfc7009>`_.\n\n``token``\n    the token to revoke (required)\n``token_type_hint``\n    either ``access_token`` or ``refresh_token`` (optional)\n\nExample\n^^^^^^^\n\n::\n\n    POST /connect/revocation HTTP/1.1\n    Host: server.example.com\n    Content-Type: application/x-www-form-urlencoded\n    Authorization: Basic czZCaGRSa3F0MzpnWDFmQmF0M2JW\n\n    token=45ghiukldjahdnhzdauz&token_type_hint=refresh_token\n\n.. Note:: You can use the `IdentityModel <https://github.com/IdentityModel/IdentityModel2>`_ client library to programmatically access the revocation endpoint from .NET code. For more information check the IdentityModel `docs <https://identitymodel.readthedocs.io/en/latest/client/revocation.html>`_."
  },
  {
    "path": "docs/endpoints/token.rst",
    "content": "Token Endpoint\n==============\n\nThe token endpoint can be used to programmatically request tokens.\nIt supports the ``password``, ``authorization_code``, ``client_credentials``, ``refresh_token`` and ``urn:ietf:params:oauth:grant-type:device_code`` grant types.\nFurthermore the token endpoint can be extended to support extension grant types.\n\n.. Note:: IdentityServer supports a subset of the OpenID Connect and OAuth 2.0 token request parameters. For a full list, see `here <http://openid.net/specs/openid-connect-core-1_0.html#TokenRequest>`_.\n\n``client_id``\n    client identifier (required – Either in the body or as part of the authorization header.)\n``client_secret``\n    client secret either in the post body, or as a basic authentication header. Optional.\n``grant_type``\n    ``authorization_code``, ``client_credentials``, ``password``, ``refresh_token``, ``urn:ietf:params:oauth:grant-type:device_code`` or custom\n``scope``\n    one or more registered scopes. If not specified, a token for all explicitly allowed scopes will be issued.\n``redirect_uri`` \n    required for the ``authorization_code`` grant type\n``code``\n    the authorization code (required for ``authorization_code`` grant type)\n``code_verifier``\n    PKCE proof key\n``username`` \n    resource owner username (required for ``password`` grant type)\n``password``\n    resource owner password (required for ``password`` grant type)\n``acr_values``\n   allows passing in additional authentication related information for the ``password`` grant type - identityserver special cases the following proprietary acr_values:\n        \n        ``idp:name_of_idp`` bypasses the login/home realm screen and forwards the user directly to the selected identity provider (if allowed per client configuration)\n        \n        ``tenant:name_of_tenant`` can be used to pass a tenant name to the token endpoint\n``refresh_token``\n    the refresh token (required for ``refresh_token`` grant type)\n``device_code``\n    the device code (required for ``urn:ietf:params:oauth:grant-type:device_code`` grant type)\n\nExample\n^^^^^^^\n\n::\n\n    POST /connect/token\n    CONTENT-TYPE application/x-www-form-urlencoded\n\n        client_id=client1&\n        client_secret=secret&\n        grant_type=authorization_code&\n        code=hdh922&\n        redirect_uri=https://myapp.com/callback\n\n(Form-encoding removed and line breaks added for readability)\n\n.. Note:: You can use the `IdentityModel <https://github.com/IdentityModel/IdentityModel>`_ client library to programmatically access the token endpoint from .NET code. For more information check the IdentityModel `docs <https://identitymodel.readthedocs.io/en/latest/client/token.html>`_.\n"
  },
  {
    "path": "docs/endpoints/userinfo.rst",
    "content": "UserInfo Endpoint\n=================\n\nThe UserInfo endpoint can be used to retrieve identity information about a user (see `spec <http://openid.net/specs/openid-connect-core-1_0.html#UserInfo>`_). \n\nThe caller needs to send a valid access token representing the user.\nDepending on the granted scopes, the UserInfo endpoint will return the mapped claims (at least the `openid` scope is required).\n\nExample\n^^^^^^^\n\n::\n\n    GET /connect/userinfo\n    Authorization: Bearer <access_token>\n\n::\n\n    HTTP/1.1 200 OK\n    Content-Type: application/json\n\n    {\n        \"sub\": \"248289761001\",\n        \"name\": \"Bob Smith\",\n        \"given_name\": \"Bob\",\n        \"family_name\": \"Smith\",\n        \"role\": [\n            \"user\",\n            \"admin\"\n        ]\n    }\n\n.. Note:: You can use the `IdentityModel <https://github.com/IdentityModel/IdentityModel2>`_ client library to programmatically access the userinfo endpoint from .NET code. For more information check the IdentityModel `docs <https://identitymodel.readthedocs.io/en/latest/client/userinfo.html>`_."
  },
  {
    "path": "docs/index.rst",
    "content": "Welcome to IdentityServer8 (latest)\n=============================================\n\n.. image:: images/logo.png\n   :align: center\n\nIdentityServer8 is an OpenID Connect and OAuth 2.0 framework for ASP.NET DotNet 8.\n\nBrowse the latest `IdentityServer8 source code onGitHub <https://github.com/alexhiggins732/IdentityServer8>`_ or download the `latest IdentyServer8 packages <https://www.nuget.org/packages/HigginsSoft.IdentityServer8//>`_ on NuGet.\n\n.. warning:: \n   This is a revival of the archived IdentityServer4 project which started a new `company <https://duendesoftware.com/>`_ as of Oct, 1st 2020. \n   The new Duende IdentityServer is not longer free open source, but now has various commercial licenses and paid upgrade package.\n   IdentityServer8 and dependenices have been upgraded to DotNet 8 and will be maintained by HigginsSoft, Alexander Higgins and the community as an Open Source project. \n\n.. note:: This docs cover the latest version on main branch. This might not be released yet. Use the version picker in the lower left corner to select docs for a specific version.\n\nIt enables the following features in your applications:\n\n\n| **Authentication as a Service** \n| Centralized login logic and workflow for all of your applications (web, native, mobile, services). IdentityServer is an officially `certified <https://openid.net/certification/>`_ implementation of OpenID Connect.\n\n| **Single Sign-on / Sign-out** \n| Single sign-on (and out) over multiple application types.\n\n| **Access Control for APIs** \n| Issue access tokens for APIs for various types of clients, e.g. server to server, web applications, SPAs and native/mobile apps.\n\n| **Federation Gateway**\n| Support for external identity providers like Azure Active Directory, Google, Facebook etc. This shields your applications from the details of how to connect to these external providers.\n\n| **Focus on Customization**\n| The most important part - many aspects of IdentityServer can be customized to fit **your** needs. Since IdentityServer is a framework and not a boxed product or a SaaS, you can write code to adapt the system the way it makes sense for your scenarios.\n\n| **Mature Open Source**\n| IdentityServer uses the permissive `Apache 2 <https://www.apache.org/licenses/LICENSE-2.0>`_ license that allows building commercial products on top of it. It is also part of the `.NET Foundation <https://dotnetfoundation.org/>`_ which provides governance and legal backing.\n\n| **Free and Commercial Support**\n| If you need help building or running your identity platform, :ref:`let us know <refSupport>`. There are several ways we can help you out.\n\n.. toctree::\n   :maxdepth: 3\n   :hidden:\n   :caption: Introduction\n\n   intro/big_picture\n   intro/architecture\n   intro/terminology\n   intro/specs\n   intro/packaging\n   intro/support\n   intro/test\n   intro/contributing\n\n.. toctree::\n   :maxdepth: 3\n   :hidden:\n   :caption: Quickstarts\n\n   quickstarts/0_overview\n   quickstarts/1_client_credentials\n   quickstarts/2_interactive_aspnetcore\n   quickstarts/3_aspnetcore_and_apis\n   quickstarts/4_javascript_client\n   quickstarts/5_entityframework\n   quickstarts/6_aspnet_identity\n   \n.. toctree::\n   :maxdepth: 3\n   :hidden:\n   :caption: Configuration\n\n   configuration/startup\n   configuration/resources\n   configuration/clients\n   configuration/mvc\n   configuration/apis\n\n.. toctree::\n   :maxdepth: 3\n   :hidden:\n   :caption: Topics\n\n   topics/startup\n   topics/resources\n   topics/clients\n   topics/signin\n   topics/signin_external_providers\n   topics/windows\n   topics/signout\n   topics/signout_external_providers\n   topics/signout_federated\n   topics/federation_gateway\n   topics/consent\n   topics/apis\n   topics/deployment\n   topics/logging\n   topics/events\n   topics/crypto\n   topics/grant_types\n   topics/client_authentication\n   topics/extension_grants\n   topics/resource_owner\n   topics/refresh_tokens\n   topics/reference_tokens\n   topics/persisted_grants\n   topics/pop\n   topics/mtls\n   topics/request_object\n   topics/custom_token_request_validation\n   topics/cors\n   topics/discovery\n   topics/add_apis\n   topics/add_protocols\n   topics/tools\n\n.. toctree::\n   :maxdepth: 3\n   :hidden:\n   :caption: Endpoints\n\n   endpoints/discovery\n   endpoints/authorize\n   endpoints/token\n   endpoints/userinfo\n   endpoints/device_authorization\n   endpoints/introspection\n   endpoints/revocation\n   endpoints/endsession\n\n.. toctree::\n   :maxdepth: 3\n   :hidden:\n   :caption: Reference\n\n   reference/options\n   reference/identity_resource\n   reference/api_scope\n   reference/api_resource\n   reference/client\n   reference/grant_validation_result\n   reference/profileservice\n   reference/interactionservice\n   reference/deviceflow_interactionservice\n   reference/ef\n   reference/aspnet_identity\n\n.. toctree::\n   :maxdepth: 3\n   :hidden:\n   :caption: Misc\n\n   misc/training\n   misc/blogs\n   misc/videos\n"
  },
  {
    "path": "docs/intro/big_picture.rst",
    "content": "The Big Picture\n===============\n\nMost modern applications look more or less like this:\n\n.. image:: images/appArch.png\n\nThe most common interactions are:\n\n* Browsers communicate with web applications\n\n* Web applications communicate with web APIs (sometimes on their own, sometimes on behalf of a user)\n\n* Browser-based applications communicate with web APIs\n\n* Native applications communicate with web APIs\n\n* Server-based applications communicate with web APIs\n\n* Web APIs communicate with web APIs (sometimes on their own, sometimes on behalf of a user)\n\nTypically each and every layer (front-end, middle-tier and back-end) has to protect resources and\nimplement authentication and/or authorization – often against the same user store.\n\nOutsourcing these fundamental security functions to a security token service prevents duplicating that functionality across those applications and endpoints.\n\nRestructuring the application to support a security token service leads to the following architecture and protocols:\n\n.. image:: images/protocols.png\n\nSuch a design divides security concerns into two parts:\n\nAuthentication\n^^^^^^^^^^^^^^\nAuthentication is needed when an application needs to know the identity of the current user.\nTypically these applications manage data on behalf of that user and need to make sure that this user can only\naccess the data for which he is allowed. The most common example for that is (classic) web applications –\nbut native and JS-based applications also have a need for authentication.\n\nThe most common authentication protocols are SAML2p, WS-Federation and OpenID Connect – SAML2p being the\nmost popular and the most widely deployed.\n\nOpenID Connect is the newest of the three, but is considered to be the future because it has the\nmost potential for modern applications. It was built for mobile application scenarios right from the start\nand is designed to be API friendly.\n\nAPI Access\n^^^^^^^^^^\nApplications have two fundamental ways with which they communicate with APIs – using the application identity,\nor delegating the user’s identity. Sometimes both methods need to be combined.\n\nOAuth2 is a protocol that allows applications to request access tokens from a security token service and use them\nto communicate with APIs. This delegation reduces complexity in both the client applications as well as the APIs since\nauthentication and authorization can be centralized.\n\nOpenID Connect and OAuth 2.0 – better together\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nOpenID Connect and OAuth 2.0 are very similar – in fact OpenID Connect is an extension on top of OAuth 2.0.\nThe two fundamental security concerns, authentication and API access, are combined into a  single protocol - often with a single round trip to the security token service. \n\nWe believe that the combination of OpenID Connect and OAuth 2.0 is the best approach to secure modern\napplications for the foreseeable future. IdentityServer8 is an implementation of these two protocols and is\nhighly optimized to solve the typical security problems of today’s mobile, native and web applications.\n\nHow IdentityServer8 can help\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nIdentityServer is middleware that adds the spec compliant OpenID Connect and OAuth 2.0 endpoints to an arbitrary ASP.NET Core application.\n\nTypically, you build (or re-use) an application that contains a login and logout page (and maybe consent - depending on your needs),\nand the IdentityServer middleware adds the necessary protocol heads to it, so that client applications can talk to it using those standard protocols.\n\n.. image:: images/middleware.png\n\nThe hosting application can be as complex as you want, but we typically recommend to keep the attack surface as small as possible by including\nauthentication related UI only.\n"
  },
  {
    "path": "docs/intro/contributing.rst",
    "content": "Contributing\n============\nWe are very open to community contributions, but there are a couple of guidelines you should follow so we can handle this without too much effort.\n\nHow to contribute?\n^^^^^^^^^^^^^^^^^^\nThe easiest way to contribute is to open an issue and start a discussion. \nThen we can decide if and how a feature or a change could be implemented. \nIf you should submit a pull request with code changes, start with a description, only make the minimal changes to start with and provide tests that cover those changes.\n\nAlso read this first: `Being a good open source citizen <https://hackernoon.com/being-a-good-open-source-citizen-9060d0ab9732#.x3hocgw85>`_\n\nGeneral feedback and discussions?\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nPlease start a discussion on the `core repo issue tracker <https://github.com/alexhiggins732/IdentityServer8/issues>`_.\n\nBugs and feature requests?\n^^^^^^^^^^^^^^^^^^^^^^^^^^\nPlease log a new issue in the appropriate GitHub repo:\n\n* `Core <https://github.com/alexhiggins732/IdentityServer8>`_\n* `AccessTokenValidation <https://github.com/alexhiggins732/IdentityServer8.AccessTokenValidation>`_\n\nContributing code and content\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nYou will need to sign a Contributor License Agreement before you can contribute any code or content.\nThis is an automated process that will start after you opened a pull request. \n\nContribution projects\n^^^^^^^^^^^^^^^^^^^^^\nWe very much appreciate if you start a contribution project (e.g. support for Database X or Configuration Store Y). \nTell us about it so we can tweet and link it in our docs.\n\nWe generally don't want to take ownership of those contribution libraries, we are already really busy supporting the core projects.\n\n**Naming conventions**\n\nAs of October 2017, the IdentityServer8.* nuget namespace is reserved for our packages. Please use the following naming conventions:\n\n``YourProjectName.IdentityServer8``\n\nor\n\n``IdentityServer8.Contrib.YourProjectName``\n"
  },
  {
    "path": "docs/intro/packaging.rst",
    "content": "Packaging and Builds\n====================\n\nIdentityServer consists of a number of nuget packages.\n\nIdentityServer8 main repo\n^^^^^^^^^^^^^^^\n`github <https://github.com/alexhiggins732/IdentityServer8>`_\n\nContains the core IdentityServer object model, services and middleware as well as the EntityFramework and ASP.NET Identity integration.\n\nnugets:\n\n* `HigginsSoft.IdentityServer8 <https://www.nuget.org/packages/HigginsSoft.IdentityServer8/>`_\n* `HigginsSoft.IdentityServer8.EntityFramework <https://www.nuget.org/packages/HigginsSoft.IdentityServer8.EntityFramework>`_\n* `HigginsSoft.IdentityServer8.AspNetIdentity <https://www.nuget.org/packages/HigginsSoft.IdentityServer8.AspNetIdentity>`_\n\nQuickstart UI\n^^^^^^^^^^^^^\n`github <https://github.com/alexhiggins732/IdentityServer8.Quickstart.UI>`_\n\nContains a simple starter UI including login, logout and consent pages.\n\nAccess token validation handler\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n`nuget <https://www.nuget.org/packages/HigginsSoft.IdentityServer8.AccessTokenValidation>`_ | `github <https://github.com/alexhiggins732/IdentityServer8.AccessTokenValidation>`_\n\nASP.NET Core authentication handler for validating tokens in APIs. The handler allows supporting both JWT and reference tokens in the same API.\n\nTemplates\n^^^^^^^^^\n`nuget <https://www.nuget.org/packages/HigginsSoft.IdentityServer8.Templates>`_ | `github <https://github.com/alexhiggins732/IdentityServer8.Templates>`_\n\nContains templates for the dotnet CLI.\n\nDev builds\n^^^^^^^^^^\nIn addition we publish CI builds to our package repository.\nAdd the following ``nuget.config`` to your project::\n\n    <?xml version=\"1.0\" encoding=\"utf-8\"?>\n        <configuration>\n            <packageSources>\n                <clear />\n                <add key=\"IdentityServer CI\" value=\"https://www.myget.org/F/identity/api/v3/index.json\" />\n            </packageSources>\n        </configuration>\n"
  },
  {
    "path": "docs/intro/specs.rst",
    "content": "Supported Specifications\n========================\n\nIdentityServer implements the following specifications:\n\nOpenID Connect\n^^^^^^^^^^^^^^\n\n* OpenID Connect Core 1.0 (`spec <http://openid.net/specs/openid-connect-core-1_0.html>`_)\n* OpenID Connect Discovery 1.0 (`spec <http://openid.net/specs/openid-connect-discovery-1_0.html>`_)\n* OpenID Connect RP-Initiated Logout 1.0 - draft 01 (`spec <https://openid.net/specs/openid-connect-rpinitiated-1_0.html>`_)\n* OpenID Connect Session Management 1.0 - draft 30 (`spec <http://openid.net/specs/openid-connect-session-1_0.html>`_)\n* OpenID Connect Front-Channel Logout 1.0 - draft 04 (`spec <https://openid.net/specs/openid-connect-frontchannel-1_0.html>`_)\n* OpenID Connect Back-Channel Logout 1.0 - draft 06 (`spec <https://openid.net/specs/openid-connect-backchannel-1_0.html>`_)\n\nOAuth 2.0\n^^^^^^^^^\n\n* OAuth 2.0 (`RFC 6749 <http://tools.ietf.org/html/rfc6749>`_)\n* OAuth 2.0 Bearer Token Usage (`RFC 6750 <http://tools.ietf.org/html/rfc6750>`_)\n* OAuth 2.0 Multiple Response Types (`spec <http://openid.net/specs/oauth-v2-multiple-response-types-1_0.html>`_)\n* OAuth 2.0 Form Post Response Mode (`spec <http://openid.net/specs/oauth-v2-form-post-response-mode-1_0.html>`_)\n* OAuth 2.0 Token Revocation (`RFC 7009 <https://tools.ietf.org/html/rfc7009>`_)\n* OAuth 2.0 Token Introspection (`RFC 7662 <https://tools.ietf.org/html/rfc7662>`_)\n* Proof Key for Code Exchange (`RFC 7636 <https://tools.ietf.org/html/rfc7636>`_)\n* JSON Web Tokens for Client Authentication (`RFC 7523 <https://tools.ietf.org/html/rfc7523>`_)\n* OAuth 2.0 Device Authorization Grant (`RFC 8628 <https://tools.ietf.org/html/rfc8628>`_)\n* OAuth 2.0 Mutual TLS Client Authentication and Certificate-Bound Access Tokens (`RFC 8705 <https://tools.ietf.org/html/rfc8705>`_)\n* JWT Secured Authorization Request (`draft <https://tools.ietf.org/html/draft-ietf-oauth-jwsreq>`_)\n"
  },
  {
    "path": "docs/intro/support.rst",
    "content": ".. _refSupport:\nSupport and Consulting Options\n==============================\n\nWe have several free and commercial support and consulting options for IdentityServer.\n\nFree support\n^^^^^^^^^^^^\nFree support is community-based and uses public forums\n\n**StackOverflow**\n\nThere's an ever growing community of people using IdentityServer that monitor questions on StackOverflow. \nIf time permits, we also try to answer as many questions as possible\n\nYou can subscribe to all IdentityServer8 related questions using this feed:\n\nhttps://stackoverflow.com/questions/tagged/?tagnames=IdentityServer8&sort=newest\n\nPlease use the ``IdentityServer8`` tag when asking new questions\n\n**Gitter**\n\nYou can chat with other IdentityServer8 users in our Gitter chat room:\n\nhttps://app.gitter.im/#/room/#identityserver8:gitter.im\n\n**Reporting a bug**\n\nIf you think you have found a bug or unexpected behavior, please open an issue on the Github `issue tracker <https://github.com/alexhiggins732/IdentityServer8/issues>`_.\nWe try to get back to you ASAP. Please understand that we also have day jobs, and might be too busy to reply immediately.\n\nAlso check the `contribution <https://github.com/alexhiggins732/IdentityServer8/blob/dev/CONTRIBUTING.md>`_ guidelines before posting.\n\nCommercial support\n^^^^^^^^^^^^^^^^^^\nWe are doing consulting, mentoring and custom software development around identity & access control architecture in general, and IdentityServer in particular.\nPlease `get in touch <mailto:contact@identityserver8.io>`_ with us to discuss possible options.\n\n**Training**\n\nWe are regularly doing workshops around identity & access control for modern applications.\nCheck the agenda and upcoming public dates  `here <https://identityserver8.io/training>`_.\nWe can also perform the training privately at your company. \n`Contact us <mailto:contact@identityserver8.io>`_ to request the training on-site. \n\n**AdminUI, WS-Federation, SAML2p, and FIDO2 support**\n\nThere are commercial add-on products available from our partners, Rock Solid Knowledge, on `identityserver8.com <https://www.identityserver8.com/products>`_.\n"
  },
  {
    "path": "docs/intro/terminology.rst",
    "content": "Terminology\n===========\n\nThe specs, documentation and object model use a certain terminology that you should be aware of.\n\n.. image:: images/terminology.png\n\nIdentityServer\n^^^^^^^^^^^^^^\nIdentityServer is an OpenID Connect provider - it implements the OpenID Connect and OAuth 2.0 protocols.\n\nDifferent literature uses different terms for the same role - you probably also find security token service,\nidentity provider, authorization server, IP-STS and more.\n\nBut they are in a nutshell all the same: a piece of software that issues security tokens to clients.\n\nIdentityServer has a number of jobs and features - including:\n\n* protect your resources\n\n* authenticate users using a local account store or via an external identity provider\n\n* provide session management and single sign-on\n\n* manage and authenticate clients\n\n* issue identity and access tokens to clients\n\n* validate tokens\n\nUser\n^^^^\nA user is a human that is using a registered client to access resources.\n\nClient\n^^^^^^\nA client is a piece of software that requests tokens from IdentityServer - either for authenticating a user (requesting an identity token) \nor for accessing a resource (requesting an access token). A client must be first registered with IdentityServer before it can request tokens.\n\nExamples for clients are web applications, native mobile or desktop applications, SPAs, server processes etc.\n\nResources\n^^^^^^^^^\nResources are something you want to protect with IdentityServer - either identity data of your users, or APIs. \n\nEvery resource has a unique name - and clients use this name to specify to which resources they want to get access to.\n\n**Identity data**\nIdentity information (aka claims) about a user, e.g. name or email address.\n\n**APIs**\nAPIs resources represent functionality a client wants to invoke - typically modelled as Web APIs, but not necessarily.\n\nIdentity Token\n^^^^^^^^^^^^^^\nAn identity token represents the outcome of an authentication process. It contains at a bare minimum an identifier for the user \n(called the `sub` aka subject claim) and information about how and when the user authenticated.  It can contain additional identity data.\n\nAccess Token\n^^^^^^^^^^^^\nAn access token allows access to an API resource. Clients request access tokens and forward them to the API. \nAccess tokens contain information about the client and the user (if present).\nAPIs use that information to authorize access to their data.\n"
  },
  {
    "path": "docs/intro/test.rst",
    "content": "Demo Server\n===========\n\nYou can try IdentityServer8 with your favourite client library. We have a test instance at `demo.identityserver8.io <https://demo.identityserver8.io>`_. \nOn the main page you can find instructions on how to configure your client and how to call an API.\n"
  },
  {
    "path": "docs/make.bat",
    "content": "@ECHO OFF\n\nREM Command file for Sphinx documentation\n\nif \"%SPHINXBUILD%\" == \"\" (\n\tset SPHINXBUILD=sphinx-build\n)\nset BUILDDIR=_build\nset ALLSPHINXOPTS=-d %BUILDDIR%/doctrees %SPHINXOPTS% .\nset I18NSPHINXOPTS=%SPHINXOPTS% .\nif NOT \"%PAPER%\" == \"\" (\n\tset ALLSPHINXOPTS=-D latex_paper_size=%PAPER% %ALLSPHINXOPTS%\n\tset I18NSPHINXOPTS=-D latex_paper_size=%PAPER% %I18NSPHINXOPTS%\n)\n\nif \"%1\" == \"\" goto help\n\nif \"%1\" == \"help\" (\n\t:help\n\techo.Please use `make ^<target^>` where ^<target^> is one of\n\techo.  html       to make standalone HTML files\n\techo.  dirhtml    to make HTML files named index.html in directories\n\techo.  singlehtml to make a single large HTML file\n\techo.  pickle     to make pickle files\n\techo.  json       to make JSON files\n\techo.  htmlhelp   to make HTML files and a HTML help project\n\techo.  qthelp     to make HTML files and a qthelp project\n\techo.  devhelp    to make HTML files and a Devhelp project\n\techo.  epub       to make an epub\n\techo.  epub3      to make an epub3\n\techo.  latex      to make LaTeX files, you can set PAPER=a4 or PAPER=letter\n\techo.  text       to make text files\n\techo.  man        to make manual pages\n\techo.  texinfo    to make Texinfo files\n\techo.  gettext    to make PO message catalogs\n\techo.  changes    to make an overview over all changed/added/deprecated items\n\techo.  xml        to make Docutils-native XML files\n\techo.  pseudoxml  to make pseudoxml-XML files for display purposes\n\techo.  linkcheck  to check all external links for integrity\n\techo.  doctest    to run all doctests embedded in the documentation if enabled\n\techo.  coverage   to run coverage check of the documentation if enabled\n\techo.  dummy      to check syntax errors of document sources\n\tgoto end\n)\n\nif \"%1\" == \"clean\" (\n\tfor /d %%i in (%BUILDDIR%\\*) do rmdir /q /s %%i\n\tdel /q /s %BUILDDIR%\\*\n\tgoto end\n)\n\n\nREM Check if sphinx-build is available and fallback to Python version if any\n%SPHINXBUILD% 1>NUL 2>NUL\nif errorlevel 9009 goto sphinx_python\ngoto sphinx_ok\n\n:sphinx_python\n\nset SPHINXBUILD=python -m sphinx.__init__\n%SPHINXBUILD% 2> nul\nif errorlevel 9009 (\n\techo.\n\techo.The 'sphinx-build' command was not found. Make sure you have Sphinx\n\techo.installed, then set the SPHINXBUILD environment variable to point\n\techo.to the full path of the 'sphinx-build' executable. Alternatively you\n\techo.may add the Sphinx directory to PATH.\n\techo.\n\techo.If you don't have Sphinx installed, grab it from\n\techo.http://sphinx-doc.org/\n\texit /b 1\n)\n\n:sphinx_ok\n\n\nif \"%1\" == \"html\" (\n\t%SPHINXBUILD% -b html %ALLSPHINXOPTS% %BUILDDIR%/html\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The HTML pages are in %BUILDDIR%/html.\n\tgoto end\n)\n\nif \"%1\" == \"dirhtml\" (\n\t%SPHINXBUILD% -b dirhtml %ALLSPHINXOPTS% %BUILDDIR%/dirhtml\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The HTML pages are in %BUILDDIR%/dirhtml.\n\tgoto end\n)\n\nif \"%1\" == \"singlehtml\" (\n\t%SPHINXBUILD% -b singlehtml %ALLSPHINXOPTS% %BUILDDIR%/singlehtml\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The HTML pages are in %BUILDDIR%/singlehtml.\n\tgoto end\n)\n\nif \"%1\" == \"pickle\" (\n\t%SPHINXBUILD% -b pickle %ALLSPHINXOPTS% %BUILDDIR%/pickle\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished; now you can process the pickle files.\n\tgoto end\n)\n\nif \"%1\" == \"json\" (\n\t%SPHINXBUILD% -b json %ALLSPHINXOPTS% %BUILDDIR%/json\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished; now you can process the JSON files.\n\tgoto end\n)\n\nif \"%1\" == \"htmlhelp\" (\n\t%SPHINXBUILD% -b htmlhelp %ALLSPHINXOPTS% %BUILDDIR%/htmlhelp\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished; now you can run HTML Help Workshop with the ^\n.hhp project file in %BUILDDIR%/htmlhelp.\n\tgoto end\n)\n\nif \"%1\" == \"qthelp\" (\n\t%SPHINXBUILD% -b qthelp %ALLSPHINXOPTS% %BUILDDIR%/qthelp\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished; now you can run \"qcollectiongenerator\" with the ^\n.qhcp project file in %BUILDDIR%/qthelp, like this:\n\techo.^> qcollectiongenerator %BUILDDIR%\\qthelp\\IdentityServer8.qhcp\n\techo.To view the help file:\n\techo.^> assistant -collectionFile %BUILDDIR%\\qthelp\\IdentityServer8.ghc\n\tgoto end\n)\n\nif \"%1\" == \"devhelp\" (\n\t%SPHINXBUILD% -b devhelp %ALLSPHINXOPTS% %BUILDDIR%/devhelp\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished.\n\tgoto end\n)\n\nif \"%1\" == \"epub\" (\n\t%SPHINXBUILD% -b epub %ALLSPHINXOPTS% %BUILDDIR%/epub\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The epub file is in %BUILDDIR%/epub.\n\tgoto end\n)\n\nif \"%1\" == \"epub3\" (\n\t%SPHINXBUILD% -b epub3 %ALLSPHINXOPTS% %BUILDDIR%/epub3\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The epub3 file is in %BUILDDIR%/epub3.\n\tgoto end\n)\n\nif \"%1\" == \"latex\" (\n\t%SPHINXBUILD% -b latex %ALLSPHINXOPTS% %BUILDDIR%/latex\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished; the LaTeX files are in %BUILDDIR%/latex.\n\tgoto end\n)\n\nif \"%1\" == \"latexpdf\" (\n\t%SPHINXBUILD% -b latex %ALLSPHINXOPTS% %BUILDDIR%/latex\n\tcd %BUILDDIR%/latex\n\tmake all-pdf\n\tcd %~dp0\n\techo.\n\techo.Build finished; the PDF files are in %BUILDDIR%/latex.\n\tgoto end\n)\n\nif \"%1\" == \"latexpdfja\" (\n\t%SPHINXBUILD% -b latex %ALLSPHINXOPTS% %BUILDDIR%/latex\n\tcd %BUILDDIR%/latex\n\tmake all-pdf-ja\n\tcd %~dp0\n\techo.\n\techo.Build finished; the PDF files are in %BUILDDIR%/latex.\n\tgoto end\n)\n\nif \"%1\" == \"text\" (\n\t%SPHINXBUILD% -b text %ALLSPHINXOPTS% %BUILDDIR%/text\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The text files are in %BUILDDIR%/text.\n\tgoto end\n)\n\nif \"%1\" == \"man\" (\n\t%SPHINXBUILD% -b man %ALLSPHINXOPTS% %BUILDDIR%/man\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The manual pages are in %BUILDDIR%/man.\n\tgoto end\n)\n\nif \"%1\" == \"texinfo\" (\n\t%SPHINXBUILD% -b texinfo %ALLSPHINXOPTS% %BUILDDIR%/texinfo\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The Texinfo files are in %BUILDDIR%/texinfo.\n\tgoto end\n)\n\nif \"%1\" == \"gettext\" (\n\t%SPHINXBUILD% -b gettext %I18NSPHINXOPTS% %BUILDDIR%/locale\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The message catalogs are in %BUILDDIR%/locale.\n\tgoto end\n)\n\nif \"%1\" == \"changes\" (\n\t%SPHINXBUILD% -b changes %ALLSPHINXOPTS% %BUILDDIR%/changes\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.The overview file is in %BUILDDIR%/changes.\n\tgoto end\n)\n\nif \"%1\" == \"linkcheck\" (\n\t%SPHINXBUILD% -b linkcheck %ALLSPHINXOPTS% %BUILDDIR%/linkcheck\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Link check complete; look for any errors in the above output ^\nor in %BUILDDIR%/linkcheck/output.txt.\n\tgoto end\n)\n\nif \"%1\" == \"doctest\" (\n\t%SPHINXBUILD% -b doctest %ALLSPHINXOPTS% %BUILDDIR%/doctest\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Testing of doctests in the sources finished, look at the ^\nresults in %BUILDDIR%/doctest/output.txt.\n\tgoto end\n)\n\nif \"%1\" == \"coverage\" (\n\t%SPHINXBUILD% -b coverage %ALLSPHINXOPTS% %BUILDDIR%/coverage\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Testing of coverage in the sources finished, look at the ^\nresults in %BUILDDIR%/coverage/python.txt.\n\tgoto end\n)\n\nif \"%1\" == \"xml\" (\n\t%SPHINXBUILD% -b xml %ALLSPHINXOPTS% %BUILDDIR%/xml\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The XML files are in %BUILDDIR%/xml.\n\tgoto end\n)\n\nif \"%1\" == \"pseudoxml\" (\n\t%SPHINXBUILD% -b pseudoxml %ALLSPHINXOPTS% %BUILDDIR%/pseudoxml\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. The pseudo-XML files are in %BUILDDIR%/pseudoxml.\n\tgoto end\n)\n\nif \"%1\" == \"dummy\" (\n\t%SPHINXBUILD% -b dummy %ALLSPHINXOPTS% %BUILDDIR%/dummy\n\tif errorlevel 1 exit /b 1\n\techo.\n\techo.Build finished. Dummy builder generates no files.\n\tgoto end\n)\n\n:end\n"
  },
  {
    "path": "docs/misc/blogs.rst",
    "content": "Blog posts\n==========\n\nTeam posts\n^^^^^^^^^^\n2020\n----\n* `Flexible Access Token Validation in ASP.NET Core <https://leastprivilege.com/2020/07/06/flexible-access-token-validation-in-asp-net-core/>`_\n* `Resource Access in IdentityServer8 v4 and going forward <https://leastprivilege.com/2020/06/18/resource-access-in-IdentityServer8-v4-and-going-forward/>`_\n* `Automatic Token Management for ASP.NET Core and Worker Services 1.0 <https://leastprivilege.com/2020/05/18/automatic-token-management-for-asp-net-core-and-worker-services-1-0/>`_\n* `Mutual TLS and Proof-of-Possession Tokens: Summary <https://leastprivilege.com/2020/02/12/mutual-tls-and-proof-of-possession-tokens-summary/>`_\n* `Mutual TLS and Proof-of-Possession Access Tokens – Part 1: Setup <https://leastprivilege.com/2020/02/07/mutual-tls-and-proof-of-possession-access-tokens-part-1-setup/>`_\n* `Hardening OpenID Connect/OAuth Authorize Requests (and Responses) <https://leastprivilege.com/2020/02/04/hardening-openid-connect-oauth-authorize-requests-and-responses/>`_\n* `Hardening Refresh Tokens <https://leastprivilege.com/2020/01/21/hardening-refresh-tokens/>`_\n* `OAuth 2.0: The long Road to Proof-of-Possession Access Tokens <https://leastprivilege.com/2020/01/15/oauth-2-0-the-long-road-to-proof-of-possession-access-tokens/>`_\n* `Outsourcing IdentityServer8 Token Signing to Azure Key Vault <https://www.scottbrady91.com/Identity-Server/Outsourcing-IdentityServer8-Token-Signing-to-Azure-Key-Vault>`_\n* `Using ECDSA in IdentityServer8 <https://www.scottbrady91.com/Identity-Server/Using-ECDSA-in-IdentityServer8>`_\n\n2019\n----\n* `Scope and claims design in IdentityServer <https://brockallen.com/2019/02/25/scope-and-claims-design-in-identityserver/>`_\n* `Try Device Flow with IdentityServer8 <https://leastprivilege.com/2019/02/08/try-device-flow-with-IdentityServer8/>`_\n* `The State of the Implicit Flow in OAuth2 <https://brockallen.com/2019/01/03/the-state-of-the-implicit-flow-in-oauth2/>`_\n* `An alternative way to secure SPAs (with ASP.NET Core, OpenID Connect, OAuth 2.0 and ProxyKit) <https://leastprivilege.com/2019/01/18/an-alternative-way-to-secure-spas-with-asp-net-core-openid-connect-oauth-2-0-and-proxykit/>`_\n* `Automatic OAuth 2.0 Token Management in ASP.NET Core <https://leastprivilege.com/2019/01/14/automatic-oauth-2-0-token-management-in-asp-net-core/>`_\n* `Encrypting Identity Tokens in IdentityServer8 <https://www.scottbrady91.com/Identity-Server/Encrypting-Identity-Tokens-in-IdentityServer8>`_\n\n2018\n----\n* `IdentityServer8 Update <https://leastprivilege.com/2018/01/17/ndc-london-2018-identityserver-update/>`_ \n* `IdentityServer and Swagger <https://www.scottbrady91.com/Identity-Server/ASPNET-Core-Swagger-UI-Authorization-using-IdentityServer8>`_\n* `Removing Shared Secrets for OAuth Client Authentication <https://www.scottbrady91.com/OAuth/Removing-Shared-Secrets-for-OAuth-Client-Authentication>`_\n* `Creating Your Own IdentityServer8 Storage Library <https://www.scottbrady91.com/Identity-Server/Creating-Your-Own-IdentityServer8-Storage-Library>`_\n\n2017\n----\n* `Platforms where you can run IdentityServer8 <https://leastprivilege.com/2017/01/15/platforms-where-you-can-run-IdentityServer8/>`_ \n* `Optimizing Tokens for size <https://leastprivilege.com/2016/12/14/optimizing-identity-tokens-for-size/>`_\n* `Identity vs Permissions <https://leastprivilege.com/2016/12/16/identity-vs-permissions/>`_\n* `Bootstraping OpenID Connect: Discovery <https://leastprivilege.com/2017/01/06/bootstrapping-openid-connect-discovery/>`_\n* `Extending IdentityServer8 with WS-Federation Support <https://leastprivilege.com/2017/03/03/extending-IdentityServer8-with-ws-federation-support/>`_\n* `Announcing IdentityServer8 RC1 <https://leastprivilege.com/2016/09/06/IdentityServer8-rc1/>`_\n* `Getting Started with IdentityServer 4 <https://www.scottbrady91.com/Identity-Server/Getting-Started-with-IdentityServer-4>`_\n* `IdentityServer 4 SharePoint Integration using WS-Federation <https://www.scottbrady91.com/Identity-Server/IdentityServer-4-SharePoint-Integration-using-WS-Federation>`_\n\nCommunity posts\n^^^^^^^^^^^^^^^\n* `Blazor WebAssembly authentication and authorization with IdentityServer8 <https://nahidfa.com/posts/blazor-webassembly-authentication-and-authorization-with-IdentityServer8/>`_\n* `Additional API Endpoints to IdentityServer 4 <https://lurumad.github.io/aditional-api-endpoints-to-IdentityServer8>`_\n* `Securing Hangfire Dashboard using an OpenID Connect server (IdentityServer 4) <https://lurumad.github.io/securing-hangfire-dashboard-using-an-openid-connect-server-identityserver-4>`_\n* `OAuth 2.0 - OpenID Connect & IdentityServer <https://wp.me/p3mRWu-1Ag/>`_\n* `Running IdentityServer8 in a Docker Container <https://espressocoder.com/2019/01/29/running-IdentityServer8-in-a-docker-container/>`_\n* `Connecting Zendesk and IdentityServer 4 SAML 2.0 Identity Provider <https://lurumad.github.io/connecting-zendesk-and-identityserver-4-saml2p-identity-provider>`_\n* `IdentityServer localization using ui_locales <https://damienbod.com/2017/11/11/IdentityServer8-localization-using-ui_locales-and-the-query-string>`_\n* `Self-issuing an IdentityServer8 token in an IdentityServer8 service <https://www.strathweb.com/2017/10/self-issuing-an-IdentityServer8-token-in-an-IdentityServer8-service/>`_\n* `IdentityServer8 on the ASP.NET Team Blog <https://blogs.msdn.microsoft.com/webdev/2017/01/23/asp-net-core-authentication-with-IdentityServer8/>`_\n* `Angular2 OpenID Connect Implicit Flow with IdentityServer8 <https://damienbod.com/2016/03/02/angular2-openid-connect-implicit-flow-with-IdentityServer8/>`_\n* `Full Server Logout with IdentityServer8 and OpenID Connect Implicit Flow <https://damienbod.com/2016/09/16/full-server-logout-with-IdentityServer8-and-openid-connect-implicit-flow/>`_\n* `IdentityServer8, ASP.NET Identity, Web API and Angular in a single Project <https://damienbod.com/2016/10/01/IdentityServer8-webapi-and-angular2-in-a-single-asp-net-core-project/>`_\n* `Secure your .NETCore web applications using IdentityServer 4 <https://social.technet.microsoft.com/wiki/contents/articles/37169.secure-your-netcore-web-applications-using-identityserver-4.aspx>`_\n* `ASP.NET Core IdentityServer8 Resource Owner Password Flow with custom UserRepository <https://damienbod.com/2017/04/14/asp-net-core-IdentityServer8-resource-owner-password-flow-with-custom-userrepository/>`_\n* `Secure ASP.NET Core MVC with Angular using IdentityServer8 OpenID Connect Hybrid Flow <https://damienbod.com/2017/05/06/secure-asp-net-core-mvc-with-angular-using-IdentityServer8-openid-connect-hybrid-flow//>`_\n* `Adding an external Microsoft login to IdentityServer8 <https://damienbod.com/2017/07/11/adding-an-external-microsoft-login-to-IdentityServer8/>`_\n* `Implementing Two-factor authentication with IdentityServer8 and Twilio <https://damienbod.com/2017/07/14/implementing-two-factor-authentication-with-IdentityServer8-and-twilio/>`_\n* `Security Experiments with gRPC and ASP.NET Core 3.0 <https://damienbod.com/2019/03/06/security-experiments-with-grpc-and-asp-net-core-3-0/>`_\n* `ASP.NET Core OAuth Device Flow Client with IdentityServer8 <https://damienbod.com/2019/02/20/asp-net-core-oauth-device-flow-client-with-IdentityServer8/>`_\n* `Securing a Vue.js app using OpenID Connect Code Flow with PKCE and IdentityServer8 <https://damienbod.com/2019/01/29/securing-a-vue-js-app-using-openid-connect-code-flow-with-pkce-and-IdentityServer8/>`_\n* `Using an OData Client with an ASP.NET Core API <https://damienbod.com/2018/10/18/using-an-odata-client-with-an-asp-net-core-api/>`_\n* `OpenID Connect back-channel logout using Azure Redis Cache and IdentityServer8 <https://damienbod.com/2018/12/18/openid-connect-back-channel-logout-using-azure-redis-cache-and-IdentityServer8/>`_\n* `Single Sign Out in IdentityServer8 with Back Channel Logout <https://blog.tretainfotech.com/posts/2018/august/single-sign-out-in-IdentityServer8-with-back-channel-logout>`_\n\n\n\n"
  },
  {
    "path": "docs/misc/training.rst",
    "content": "Training\n========\nHere are some online, remote and classroom training options to learn more about ASP.NET Core identity & IdentityServer8.\n\nIdentity & Access Control for modern Applications (using ASP.NET Core 2 and IdentityServer8)\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThat's our own three day flagship course (including extensive hands-on labs) that we deliver as part of conferences, on-sites and remote.\n\nThe agenda and dates for public training can be found `here <https://identityserver8.io/training>`_,\n`contact <mailto:identity@leastprivilege.com>`_ us for private workshops.\n\nPluralSight courses\n^^^^^^^^^^^^^^^^^^^\nThere are some good courses on PluralSight around identity, ASP.NET Core and IdentityServer.\n\n**new**\n\n* `Securing Angular Apps with OpenID and OAuth2 <https://www.pluralsight.com/courses/openid-and-oauth2-securing-angular-apps>`_\n* `ASP.NET Core Identity Management Playbook <https://app.pluralsight.com/library/courses/aspnet-core-identity-management-playbook/table-of-contents>`_\n* `Getting Started with ASP.NET Core and OAuth <https://www.pluralsight.com/courses/asp-dot-net-core-oauth/>`_\n* `Securing ASP.NET Core with OAuth2 and OpenID Connect <https://app.pluralsight.com/library/courses/asp-dotnet-core-oauth2-openid-connect-securing/>`_\n* `Understanding ASP.NET Core Security (Centralized Authentication with a Token Service) <https://app.pluralsight.com/library/courses/asp-dot-net-core-security-understanding/>`_\n\n**older**\n\n* `Introduction to OAuth2, OpenID Connect and JSON Web Tokens (JWT) <https://app.pluralsight.com/library/courses/oauth2-json-web-tokens-openid-connect-introduction/table-of-contents>`_\n* `Web API v2 Security <https://app.pluralsight.com/library/courses/webapi-v2-security/table-of-contents>`_\n* `Using OAuth to Secure Your ASP.NET API <https://app.pluralsight.com/library/courses/oauth-secure-asp-dot-net-api/table-of-contents>`_\n* `OAuth2 and OpenID Connect Strategies for Angular and ASP.NET <https://app.pluralsight.com/library/courses/oauth2-openid-connect-angular-aspdotnet/table-of-contents>`_\n"
  },
  {
    "path": "docs/misc/videos.rst",
    "content": "Videos\n======\n2020\n^^^^\n* `January [NDC London] -- Implementing OpenID Connect and OAuth 2.0 – Tips from the Trenches  <https://www.youtube.com/watch?v=QpkVnB-N20c>`_\n* `January [NDC London] -- OpenID Connect & OAuth 2.0 – Security Best Practices  <https://www.youtube.com/watch?v=AUgZffkurK0>`_\n\n2019\n^^^^\n* `October [TDC] -- Securing Web Applications and APIs with ASP.NET Core 3.0  <https://vimeo.com/369311388>`_\n* `January [NDC] -- Securing Web Applications and APIs with ASP.NET Core 2.2 and 3.0  <https://www.youtube.com/watch?v=EYk3KTwwbFA>`_\n* `January [NDC] -- Building Clients for OpenID Connect/OAuth 2-based Systems  <https://www.youtube.com/watch?v=BM091_OlX3o>`_\n\n2018\n^^^^\n* `26/09 [DevConf] -- Authorization for modern Applications <https://www.youtube.com/watch?v=Dlrf85NTuAU&feature=youtu.be>`_\n* `17/01 [NDC London] -- IdentityServer v2 on ASP.NET Core v2 - an Update <https://vimeo.com/254635632>`_\n* `17/01 [NDC London] -- Implementing authorization for web apps and APIs (aka PolicyServer announcement) <https://vimeo.com/254635640>`_\n* `17/01 [DotNetRocks] -- IdentityServer and PolicyServer on DotNetRocks <https://dotnetrocks.com/?show=1515>`_\n\n2017\n^^^^\n* `14/09 [Microsoft Learning] -- Introduction to IdentityServer for ASP.NET Core - Brock Allen <https://mva.microsoft.com/en-US/training-courses/introduction-to-identityserver-for-aspnet-core-17945>`_\n* `14/06 [NDC Oslo] -- Implementing Authorization for Web Applications and APIs <https://vimeo.com/223982185>`_\n* `22/02 [NDC Mini Copenhagen] -- IdentityServer8: New & Improved for ASP.NET Core - Dominick Baier <https://vimeo.com/215352044>`_\n* `02/02 [DotNetRocks] -- IdentityServer8 on DotNetRocks <https://www.dotnetrocks.com/?show=1409>`_\n* `16/01 [NDC London] -- IdentityServer8: New and Improved for ASP.NET Core <https://vimeo.com/204141878>`_\n* `16/01 [NDC London] -- Building JavaScript and mobile/native Clients for Token-based Architectures <https://vimeo.com/205451987>`_\n\n2016\n^^^^\n* `The history of .NET identity and IdentityServer Channel9 interview <https://channel9.msdn.com/events/Seth-on-the-Road/NDC-London-2016/Dominick-Baier-on-Identity-Server>`_ \n* `Authentication & secure API access for native & mobile Applications - Dominick Baier <https://vimeo.com/171942749>`_\n* `ASP.NET Identity 3 - Brock Allen <https://vimeo.com/172009501>`_\n* `Introduction to IdentityServer3 - Brock Allen <https://vimeo.com/154172925>`_\n\n2015\n^^^^\n* `Securing Web APIs – Patterns & Anti-Patterns - Dominick Baier <https://vimeo.com/131635255>`_\n* `Authentication and authorization in modern JavaScript web applications – how hard can it be? - Brock Allen <https://vimeo.com/131636653>`_\n\n2014\n^^^^\n* `Unifying Authentication & Delegated API Access for Mobile, Web and the Desktop with OpenID Connect and OAuth 2 - Dominick Baier <https://vimeo.com/113604459>`_\n"
  },
  {
    "path": "docs/quickstarts/0_overview.rst",
    "content": ".. _refQuickstartOverview:\nOverview\n========\nThe quickstarts provide step by step instructions for various common IdentityServer scenarios.\nThey start with the absolute basics and become more complex - \nit is recommended you do them in order.\n\n* adding IdentityServer to an ASP.NET Core application\n* configuring IdentityServer\n* issuing tokens for various clients\n* securing web applications and APIs\n* adding support for EntityFramework based configuration\n* adding support for ASP.NET Identity\n\nEvery quickstart has a reference solution - you can find the code in the \n`samples <https://github.com/alexhiggins732/IdentityServer8/tree/main/samples/Quickstarts>`_ folder.\n\nPreparation\n^^^^^^^^^^^\nThe first thing you should do is install our templates::\n\n    dotnet new -i IdentityServer8.Templates\n\nThey will be used as a starting point for the various tutorials.\n\n.. note:: If you are using private NuGet sources do not forget to add the --nuget-source parameter: --nuget-source https://api.nuget.org/v3/index.json\n\nOK - let's get started!\n\n.. note:: The quickstarts target the IdentityServer 4.x and ASP.NET Core 3.1.x - there are also quickstarts for `ASP.NET Core 2 <http://docs.identityserver8.io/en/aspnetcore2/quickstarts/0_overview.html>`_ and `ASP.NET Core 1 <http://docs.identityserver8.io/en/aspnetcore1/quickstarts/0_overview.html>`_.\n"
  },
  {
    "path": "docs/quickstarts/1_client_credentials.rst",
    "content": ".. _refClientCredentialsQuickstart:\n\nProtecting an API using Client Credentials\n==========================================\nThe following Identity Server 4 quickstart provides step by step instructions for various common IdentityServer scenarios. \nThese start with the absolute basics and become more complex as they progress. We recommend that you follow them in sequence.  \n\nTo see the full list, please go to `IdentityServer8 Quickstarts Overview <https://IdentityServer8.readthedocs.io/en/latest/quickstarts/0_overview.html>`_\n\nThis first quickstart is the most basic scenario for protecting APIs using IdentityServer. \nIn this quickstart you define an API and a Client with which to access it. \nThe client will request an access token from the Identity Server using its client ID and secret and then use the token to gain access to the API.\n\nSource Code\n^^^^^^^^^^^\nAs with all of these quickstarts you can find the source code for it in the `IdentityServer8 <https://github.com/alexhiggins732/IdentityServer8/blob/main/samples>`_ repository. The project for this quickstart is `Quickstart #1: Securing an API using Client Credentials <https://github.com/alexhiggins732/IdentityServer8/tree/main/samples/Quickstarts/1_ClientCredentials>`_\n\nPreparation\n^^^^^^^^^^^\nThe IdentityServer templates for the dotnet CLI are a good starting point for the quickstarts.\nTo install the templates open a console window and type the following command::\n\n    dotnet new -i IdentityServer8.Templates\n\nThey will be used as a starting point for the various tutorials.\n\nSetting up the ASP.NET Core application\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nFirst create a directory for the application - then use our template to create an ASP.NET Core application that includes a basic IdentityServer setup, e.g.::\n\n    md quickstart\n    cd quickstart\n\n    md src\n    cd src\n\n    dotnet new is4empty -n IdentityServer\n\nThis will create the following files:\n\n* ``IdentityServer.csproj`` - the project file and a ``Properties\\launchSettings.json`` file\n* ``Program.cs`` and ``Startup.cs`` - the main application entry point\n* ``Config.cs`` - IdentityServer resources and clients configuration file\n\nYou can now use your favorite text editor to edit or view the files. If you want to have Visual Studio support, you can add a solution file like this::\n\n    cd ..\n    dotnet new sln -n Quickstart\n\nand let it add your IdentityServer project (keep this command in mind as we will create other projects below)::\n\n    dotnet sln add .\\src\\IdentityServer\\IdentityServer.csproj\n\n.. note:: The protocol used in this Template is ``https`` and the port is set to 5001 when running on Kestrel or a random one on IISExpress. You can change that in the ``Properties\\launchSettings.json`` file. For production scenarios you should always use ``https``.\n\nDefining an API Scope\n^^^^^^^^^^^^^^^^^^^^^\nAn API is a resource in your system that you want to protect. \nResource definitions can be loaded in many ways, the template you used to create the project above shows how to use a \"code as configuration\" approach.\n\nThe Config.cs is already created for you. Open it, update the code to look like this::\n\n    public static class Config\n    {\n        public static IEnumerable<ApiScope> ApiScopes =>\n            new List<ApiScope>\n            {\n                new ApiScope(\"api1\", \"My API\")\n            };\n    }\n\n(see the full file `here <https://github.com/alexhiggins732/IdentityServer8/blob/main/samples/Quickstarts/1_ClientCredentials/src/IdentityServer/Config.cs>`_).\n\t\n.. note:: If you will be using this in production it is important to give your API a logical name. Developers will be using this to connect to your api though your Identity server.  It should describe your api in simple terms to both developers and users.\n\nDefining the client\n^^^^^^^^^^^^^^^^^^^\nThe next step is to define a client application that we will use to access our new API.\n\nFor this scenario, the client will not have an interactive user, and will authenticate using the so called client secret with IdentityServer.\n\nFor this, add a client definition:: \n\n    public static IEnumerable<Client> Clients =>\n        new List<Client>\n        {\n            new Client\n            {\n                ClientId = \"client\",\n\n                // no interactive user, use the clientid/secret for authentication\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n\n                // secret for authentication\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                // scopes that client has access to\n                AllowedScopes = { \"api1\" }\n            }\n        };\n\nYou can think of the ClientId and the ClientSecret as the login and password for your application itself.  \nIt identifies your application to the identity server so that it knows which application is trying to connect to it.\t\n\n\t\nConfiguring IdentityServer\n^^^^^^^^^^^^^^^^^^^^^^^^^^\nLoading the resource and client definitions happens in `Startup.cs <https://github.com/alexhiggins732/IdentityServer8/blob/main/samples/Quickstarts/1_ClientCredentials/src/IdentityServer/Startup.cs>`_ - update the code to look like this::\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        var builder = services.AddIdentityServer()\n            .AddDeveloperSigningCredential()        //This is for dev only scenarios when you don’t have a certificate to use.\n            .AddInMemoryApiScopes(Config.ApiScopes)\n            .AddInMemoryClients(Config.Clients);\n\n        // omitted for brevity\n    }\n\nThat's it - your identity server should now be configured. If you run the server and navigate the browser to ``https://localhost:5001/.well-known/openid-configuration``, you should see the so-called discovery document. \nThe discovery document is a standard endpoint in identity servers.  The discovery document will be used by your clients and APIs to download the necessary configuration data.\n\n.. image:: images/1_discovery.png\n\nAt first startup, IdentityServer will create a developer signing key for you, it's a file called ``tempkey.jwk``.\nYou don't have to check that file into your source control, it will be re-created if it is not present.\n\nAdding an API\n^^^^^^^^^^^^^\nNext, add an API to your solution. \n\nYou can either use the ASP.NET Core Web API template from Visual Studio or use the .NET CLI to create the API project as we do here.\nRun from within the ``src`` folder the following command::\n\n    dotnet new webapi -n Api\n\nThen add it to the solution by running the following commands::\n\n    cd ..\n    dotnet sln add .\\src\\Api\\Api.csproj\n\nConfigure the API application to run on ``https://localhost:6001`` only. You can do this by editing the `launchSettings.json <https://github.com/alexhiggins732/IdentityServer8/blob/main/samples/Quickstarts/1_ClientCredentials/src/Api/Properties/launchSettings.json>`_ file inside the Properties folder. Change the application URL setting to be::\n\n    \"applicationUrl\": \"https://localhost:6001\"\n\nThe controller\n--------------\nAdd a new class called ``IdentityController``::\n\n    [Route(\"identity\")]\n    [Authorize]\n    public class IdentityController : ControllerBase\n    {\n        [HttpGet]\n        public IActionResult Get()\n        {\n            return new JsonResult(from c in User.Claims select new { c.Type, c.Value });\n        }\n    }\n\nThis controller will be used later to test the authorization requirement, as well as visualize the claims identity through the eyes of the API.\n\nAdding a Nuget Dependency\n-------------------------\nIn order for the configuration step to work the nuget package dependency has to be added, run this command in the root directory::\n\n    dotnet add .\\\\src\\\\api\\\\Api.csproj package Microsoft.AspNetCore.Authentication.JwtBearer\n\nConfiguration\n-------------\nThe last step is to add the authentication services to DI (dependency injection) and the authentication middleware to the pipeline.\nThese will:\n\n* validate the incoming token to make sure it is coming from a trusted issuer\n* validate that the token is valid to be used with this api (aka audience)\n\nUpdate `Startup` to look like this::\n\n    public class Startup\n    {\n        public void ConfigureServices(IServiceCollection services)\n        {\n            services.AddControllers();\n\n            services.AddAuthentication(\"Bearer\")\n                .AddJwtBearer(\"Bearer\", options =>\n                {\n                    options.Authority = \"https://localhost:5001\";\n\n                    options.TokenValidationParameters = new TokenValidationParameters\n                    {\n                        ValidateAudience = false\n                    };\n                });\n        }\n\n        public void Configure(IApplicationBuilder app)\n        {\n            app.UseRouting();\n\n            app.UseAuthentication();\n            app.UseAuthorization();\n\n            app.UseEndpoints(endpoints =>\n            {\n                endpoints.MapControllers();\n            });\n        }\n    }\n\n* ``AddAuthentication`` adds the authentication services to DI and configures ``Bearer`` as the default scheme. \n* ``UseAuthentication`` adds the authentication middleware to the pipeline so authentication will be performed automatically on every call into the host.\n* ``UseAuthorization`` adds the authorization middleware to make sure, our API endpoint cannot be accessed by anonymous clients.\n\nNavigating to the controller ``https://localhost:6001/identity`` on a browser should return a 401 status code. \nThis means your API requires a credential and is now protected by IdentityServer.\n\n.. note:: If you are wondering, why the above code disables audience validation, have a look :ref:`here <refResources>` for a more in-depth discussion.\n\nCreating the client\n^^^^^^^^^^^^^^^^^^^\nThe last step is to write a client that requests an access token, and then uses this token to access the API. For that, add a console project to your solution, remember to create it in the ``src``::\n\n    dotnet new console -n Client\n    \nThen as before, add it to your solution using::\n\n    cd ..\n    dotnet sln add .\\src\\Client\\Client.csproj\n\nThe token endpoint at IdentityServer implements the OAuth 2.0 protocol, and you could use raw HTTP to access it. \nHowever, we have a client library called IdentityModel, that encapsulates the protocol interaction in an easy to use API.\n\nAdd the ``IdentityModel`` NuGet package to your client. \nThis can be done either via Visual Studio's Nuget Package manager or dotnet CLI::\n\n    cd src\n    cd client\n    dotnet add package IdentityModel\n\nIdentityModel includes a client library to use with the discovery endpoint. This way you only need to know the base-address of IdentityServer - the actual endpoint addresses can be read from the metadata::\n\n    // discover endpoints from metadata\n    var client = new HttpClient();\n    var disco = await client.GetDiscoveryDocumentAsync(\"https://localhost:5001\");\n    if (disco.IsError)\n    {\n        Console.WriteLine(disco.Error);\n        return;\n    }\n.. note:: If you get an error connecting it may be that you are running `https` and the development certificate for ``localhost`` is not trusted. You can run ``dotnet dev-certs https --trust`` in order to trust the development certificate. This only needs to be done once.\n\nNext you can use the information from the discovery document to request a token to IdentityServer to access ``api1``::\n\n    // request token\n    var tokenResponse = await client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n\n        ClientId = \"client\",\n        ClientSecret = \"secret\",\n        Scope = \"api1\"\n    });\n    \n    if (tokenResponse.IsError)\n    {\n        Console.WriteLine(tokenResponse.Error);\n        return;\n    }\n\n    Console.WriteLine(tokenResponse.Json);\n\n(full file can be found `here <https://github.com/alexhiggins732/IdentityServer8/blob/main/samples/Quickstarts/1_ClientCredentials/src/Client/Program.cs>`_)\n\n.. note:: Copy and paste the access token from the console to `jwt.ms <https://jwt.ms>`_ to inspect the raw token.\n\nCalling the API\n^^^^^^^^^^^^^^^\nTo send the access token to the API you typically use the HTTP Authorization header. This is done using the ``SetBearerToken`` extension method::\n\n    // call api\n    var apiClient = new HttpClient();\n    apiClient.SetBearerToken(tokenResponse.AccessToken);\n\n    var response = await apiClient.GetAsync(\"https://localhost:6001/identity\");\n    if (!response.IsSuccessStatusCode)\n    {\n        Console.WriteLine(response.StatusCode);\n    }\n    else\n    {\n        var content = await response.Content.ReadAsStringAsync();\n        Console.WriteLine(JArray.Parse(content));\n    }\n\n(If you are in Visual Studio you can right-click on the solution and select \"Multiple Startup Projects\", and ensure the Api and IdentityServer will start; then run the solution; then, to step through the Client code, you can right-click on the \"Client\" project and select Debug... Start New Instance).\nThe output should look like this:\n\n.. image:: images/1_client_screenshot.png\n\n.. note:: By default an access token will contain claims about the scope, lifetime (nbf and exp), the client ID (client_id) and the issuer name (iss).\n\nAuthorization at the API\n^^^^^^^^^^^^^^^^^^^^^^^^\nRight now, the API accepts any access token issued by your identity server.\n\nIn the following we will add code that allows checking for the presence of the scope in the access token that the client asked for (and got granted).\nFor this we will use the ASP.NET Core authorization policy system. Add the following to the ``ConfigureServices`` method in ``Startup``::\n\n    services.AddAuthorization(options =>\n    {\n        options.AddPolicy(\"ApiScope\", policy =>\n        {\n            policy.RequireAuthenticatedUser();\n            policy.RequireClaim(\"scope\", \"api1\");\n        });\n    });\n\nYou can now enforce this policy at various levels, e.g.\n\n* globally\n* for all API endpoints\n* for specific controllers/actions\n\nTypically you setup the policy for all API endpoints in the routing system::\n\n    app.UseEndpoints(endpoints =>\n    {\n        endpoints.MapControllers()\n            .RequireAuthorization(\"ApiScope\");\n    });\n\n\nFurther experiments\n^^^^^^^^^^^^^^^^^^^\nThis walkthrough focused on the success path so far\n\n* client was able to request token\n* client could use the token to access the API\n\nYou can now try to provoke errors to learn how the system behaves, e.g.\n\n* try to connect to IdentityServer when it is not running (unavailable)\n* try to use an invalid client id or secret to request the token\n* try to ask for an invalid scope during the token request\n* try to call the API when it is not running (unavailable)\n* don't send the token to the API\n* configure the API to require a different scope than the one in the token\n"
  },
  {
    "path": "docs/quickstarts/2_interactive_aspnetcore.rst",
    "content": ".. _refInteractiveQuickstart:\nInteractive Applications with ASP.NET Core\n==========================================\n\n.. note:: For any pre-requisites (like e.g. templates) have a look at the :ref:`overview <refQuickstartOverview>` first.\n\nIn this quickstart we want to add support for interactive user authentication via the\nOpenID Connect protocol to our IdentityServer we built in the previous chapter.\n\nOnce that is in place, we will create an MVC application that will use IdentityServer for \nauthentication.\n\nAdding the UI\n^^^^^^^^^^^^^\nAll the protocol support needed for OpenID Connect is already built into IdentityServer.\nYou need to provide the necessary UI parts for login, logout, consent and error.\n\nWhile the look & feel as well as the exact workflows will probably always differ in every\nIdentityServer implementation, we provide an MVC-based sample UI that you can use as a starting point.\n\nThis UI can be found in the `Quickstart UI repo <https://github.com/alexhiggins732/IdentityServer8.Quickstart.UI/tree/main>`_.\nYou can clone or download this repo and drop the controllers, views, models and CSS into your IdentityServer web application.\n\nAlternatively you can use the .NET CLI (run from within the ``src/IdentityServer`` folder)::\n\n    dotnet new is4ui\n\nOnce you have added the MVC UI, you will also need to enable MVC, both in the DI system and in the pipeline.\nWhen you look at ``Startup.cs`` you will find comments in the ``ConfigureServices`` and ``Configure`` method that tell you how to enable MVC.\n\n.. note:: There is also a template called ``is4inmem`` which combines a basic IdentityServer including the standard UI.\n\nRun the IdentityServer application, you should now see a home page.\n\nSpend some time inspecting the controllers and models - especially the ``AccountController`` which is the main UI entry point.\nThe better you understand them, the easier it will be to make future modifications. \nMost of the code lives in the \"Quickstart\" folder using a \"feature folder\" style. \nIf this style doesn't suit you, feel free to organize the code in any way you want.\n\nCreating an MVC client\n^^^^^^^^^^^^^^^^^^^^^^\nNext you will create an MVC application.\nUse the ASP.NET Core \"Web Application\" (i.e. MVC) template for that. \n\nrun from the src folder::\n\n    dotnet new mvc -n MvcClient\n    cd ..\n    dotnet sln add .\\src\\MvcClient\\MvcClient.csproj\n\n.. note:: We recommend using the self-host option over IIS Express. The rest of the docs assume you are using self-hosting on port 5002.\n\nTo add support for OpenID Connect authentication to the MVC application, you first need to add the nuget package containing the OpenID Connect handler to your project, e.g.::\n\n    dotnet add package Microsoft.AspNetCore.Authentication.OpenIdConnect\n\n..then add the following to ``ConfigureServices`` in ``Startup``::\n\n    using System.IdentityModel.Tokens.Jwt;\n    \n    // ...\n    \n    JwtSecurityTokenHandler.DefaultMapInboundClaims = false;\n\n    services.AddAuthentication(options =>\n        {\n            options.DefaultScheme = \"Cookies\";\n            options.DefaultChallengeScheme = \"oidc\";\n        })\n        .AddCookie(\"Cookies\")\n        .AddOpenIdConnect(\"oidc\", options =>\n        {\n            options.Authority = \"https://localhost:5001\";\n\n            options.ClientId = \"mvc\";\n            options.ClientSecret = \"secret\";\n            options.ResponseType = \"code\";\n\n            options.SaveTokens = true;\n        });\n\n``AddAuthentication`` adds the authentication services to DI.\n\nWe are using a cookie to locally sign-in the user (via ``\"Cookies\"`` as the ``DefaultScheme``),\nand we set the ``DefaultChallengeScheme`` to ``oidc`` because when we need the user to login, we will be using the OpenID Connect protocol.\n\nWe then use ``AddCookie`` to add the handler that can process cookies.\n\nFinally, ``AddOpenIdConnect`` is used to configure the handler that performs the OpenID Connect protocol.\nThe ``Authority`` indicates where the trusted token service is located.\nWe then identify this client via the ``ClientId`` and the ``ClientSecret``. \n``SaveTokens`` is used to persist the tokens from IdentityServer in the cookie (as they will be needed later).\n\n.. note:: We use the so called ``authorization code`` flow with PKCE to connect to the OpenID Connect provider. See :ref:`here <refGrantTypes>` for more information on protocol flows.\n\nAnd then to ensure the execution of the authentication services on each request, add ``UseAuthentication`` to ``Configure`` in ``Startup``::\n\n    app.UseStaticFiles();\n\n    app.UseRouting();\n    app.UseAuthentication();\n    app.UseAuthorization();\n\n    app.UseEndpoints(endpoints =>\n    {\n        endpoints.MapDefaultControllerRoute()\n            .RequireAuthorization();\n    });\n\n.. note:: The ``RequireAuthorization`` method disables anonymous access for the entire application. \nYou can also use the ``[Authorize]`` attribute, if you want to specify authorization on a per controller or action method basis.\n\nAlso modify the home view to display the claims of the user as well as the cookie properties::\n\n    @using Microsoft.AspNetCore.Authentication\n\n    <h2>Claims</h2>\n\n    <dl>\n        @foreach (var claim in User.Claims)\n        {\n            <dt>@claim.Type</dt>\n            <dd>@claim.Value</dd>\n        }\n    </dl>\n\n    <h2>Properties</h2>\n\n    <dl>\n        @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n        {\n            <dt>@prop.Key</dt>\n            <dd>@prop.Value</dd>\n        }\n    </dl>\n\nIf you now navigate to the application using the browser, a redirect attempt will be made\nto IdentityServer - this will result in an error because the MVC client is not registered yet.\n\nAdding support for OpenID Connect Identity Scopes\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nSimilar to OAuth 2.0, OpenID Connect also uses the scopes concept.\nAgain, scopes represent something you want to protect and that clients want to access.\nIn contrast to OAuth, scopes in OIDC don't represent APIs, but identity data like user id, \nname or email address.\n\nAdd support for the standard ``openid`` (subject id) and ``profile`` (first name, last name etc..) scopes\nby amending the ``IdentityResources`` property in ``Config.cs``::\n\n    public static IEnumerable<IdentityResource> IdentityResources =>\n        new List<IdentityResource>\n        {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n        };\n\nRegister the identity resources with IdentityServer in ``startup.cs``::\n\n    var builder = services.AddIdentityServer()\n        .AddInMemoryIdentityResources(Config.IdentityResources)\n        .AddInMemoryApiScopes(Config.ApiScopes)\n        .AddInMemoryClients(Config.Clients);\n\n.. note:: All standard scopes and their corresponding claims can be found in the OpenID Connect `specification <https://openid.net/specs/openid-connect-core-1_0.html#ScopeClaims>`_\n\nAdding Test Users\n^^^^^^^^^^^^^^^^^\nThe sample UI also comes with an in-memory \"user database\". You can enable this in IdentityServer by adding the ``AddTestUsers`` extension method::\n\n    var builder = services.AddIdentityServer()\n        .AddInMemoryIdentityResources(Config.IdentityResources)\n        .AddInMemoryApiScopes(Config.ApiScopes)\n        .AddInMemoryClients(Config.Clients)\n        .AddTestUsers(TestUsers.Users);\n\nWhen you navigate to the ``TestUsers`` class, you can see that two users called ``alice`` and ``bob`` as well as some identity claims are defined.\nYou can use those users to login.\n\nAdding the MVC Client to the IdentityServer Configuration\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThe last step is to add a new configuration entry for the MVC client to the IdentityServer.\n\nOpenID Connect-based clients are very similar to the OAuth 2.0 clients we added so far.\nBut since the flows in OIDC are always interactive, we need to add some redirect URLs to our configuration.\n\nThe client list should look like this::\n\n    public static IEnumerable<Client> Clients =>\n        new List<Client>\n        {\n            // machine to machine client (from quickstart 1)\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                // scopes that client has access to\n                AllowedScopes = { \"api1\" }\n            },\n            // interactive ASP.NET Core MVC client\n            new Client\n            {\n                ClientId = \"mvc\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.Code,\n                \n                // where to redirect to after login\n                RedirectUris = { \"https://localhost:5002/signin-oidc\" },\n\n                // where to redirect to after logout\n                PostLogoutRedirectUris = { \"https://localhost:5002/signout-callback-oidc\" },\n\n                AllowedScopes = new List<string>\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile\n                }\n            }\n        };\n\nTesting the client\n^^^^^^^^^^^^^^^^^^\nNow finally everything should be in place for the new MVC client.\n\nTrigger the authentication handshake by navigating to the protected controller action.\nYou should see a redirect to the login page of the IdentityServer.\n\n.. image:: images/3_login.png\n\nAfter that, the IdentityServer will redirect back to the MVC client, where the OpenID Connect authentication handler processes the response and signs-in the user locally by setting a cookie.\nFinally the MVC view will show the contents of the cookie.\n\n.. image:: images/3_claims.png\n\nAs you can see, the cookie has two parts, the claims of the user, and some metadata. This metadata also contains the original token that was issued by the IdentityServer.\nFeel free to copy this token to `jwt.ms <https://jwt.ms>`_ to inspect its content.\n\nAdding sign-out\n^^^^^^^^^^^^^^^\nThe very last step is to add sign-out to the MVC client.\n\nWith an authentication service like IdentityServer, it is not enough to clear the local application cookies.\nIn addition you also need to make a roundtrip to the IdentityServer to clear the central single sign-on session.\n\nThe exact protocol steps are implemented inside the OpenID Connect handler, \nsimply add the following code to some controller to trigger the sign-out::\n\n    public IActionResult Logout()\n    {\n        return SignOut(\"Cookies\", \"oidc\");\n    }\n\nThis will clear the local cookie and then redirect to the IdentityServer.\nThe IdentityServer will clear its cookies and then give the user a link to return back to the MVC application.\n\nGetting claims from the UserInfo endpoint\n^^^^^^^^^^^^^^^\nYou might have noticed that even though we've configured the client to be allowed to retrieve the ``profile`` identity scope, the claims associated with that scope (such as ``name``, ``family_name``, ``website`` etc.) don't appear in the returned token. We need to tell the client to pull remaining claims from the `UserInfo <https://IdentityServer8.readthedocs.io/en/latest/endpoints/userinfo.html>`_ endpoint by specifying scopes that the client application needs to access and setting the ``GetClaimsFromUserInfoEndpoint`` option. In the following example we're requesting the ``profile`` scope, but it could be any scope (or scopes) that the client is authorized to access::\n\n    .AddOpenIdConnect(\"oidc\", options =>\n    {\n        // ...\n        options.Scope.Add(\"profile\");\n        options.GetClaimsFromUserInfoEndpoint = true;\n        // ...\n    });\n\nAfter restarting the client app, logging out, and logging back in you should see additional user claims associated with the ``profile`` identity scope displayed on the page.\n\n.. image:: images/3_additional_claims.png\n\nFurther Experiments\n^^^^^^^^^^^^^^^^^^^\nFeel free to add more claims to the test users - and also more identity resources. \n\nThe process for defining an identity resource is as follows:\n\n* add a new identity resource to the list - give it a name and specify which claims should be returned when this resource is requested\n* give the client access to the resource via the ``AllowedScopes`` property on the client configuration\n* request the resource by adding it to the ``Scopes`` collection on the OpenID Connect handler configuration in the client\n* (optional) if the identity resource is associated with a non-standard claim (e.g. ``myclaim1``), on the client side add the `ClaimAction <https://docs.microsoft.com/en-us/dotnet/api/microsoft.aspnetcore.authentication.openidconnect.openidconnectoptions.claimactions?view=aspnetcore-3.0>`_ mapping between the claim appearing in JSON (returned from the UserInfo endpoint) and the User `Claim <https://docs.microsoft.com/en-us/dotnet/api/system.security.claims.claim>`_ ::\n\n    using Microsoft.AspNetCore.Authentication\n    // ...\n    .AddOpenIdConnect(\"oidc\", options =>\n    {\n        // ...\n        options.ClaimActions.MapUniqueJsonKey(\"myclaim1\", \"myclaim1\");\n        // ...\n    });\n\nIt is also noteworthy, that the retrieval of claims for tokens is an extensibility point - ``IProfileService``.\nSince we are using ``AddTestUsers``, the ``TestUserProfileService`` is used by default.\nYou can inspect the source code `here <https://github.com/alexhiggins732/IdentityServer8/blob/main/src/IdentityServer8/src/Test/TestUserProfileService.cs>`_\nto see how it works.\n\n.. _refExternalAuthenticationQuickstart:\nAdding Support for External Authentication\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nNext we will add support for external authentication.\nThis is really easy, because all you really need is an ASP.NET Core compatible authentication handler.\n\nASP.NET Core itself ships with support for Google, Facebook, Twitter, Microsoft Account and OpenID Connect.\nIn addition you can find implementations for many other authentication providers `here <https://github.com/aspnet-contrib/AspNet.Security.OAuth.Providers>`_.\n\nAdding Google support\n^^^^^^^^^^^^^^^^^^^^^\nTo be able to use Google for authentication, you first need to register with them.\nThis is done at their developer `console <https://console.developers.google.com/>`_.\nCreate a new project, enable the Google+ API and configure the callback address of your\nlocal IdentityServer by adding the */signin-google* path to your base-address (e.g. https://localhost:5001/signin-google).\n\nThe developer console will show you a client ID and secret issued by Google - you will need that in the next step.\n\nAdd the Google authentication handler to the DI of the IdentityServer host.\nThis is done by first adding the ``Microsoft.AspNetCore.Authentication.Google`` nuget package and then adding this snippet to ``ConfigureServices`` in ``Startup``::\n\n    services.AddAuthentication()\n        .AddGoogle(\"Google\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n            options.ClientId = \"<insert here>\";\n            options.ClientSecret = \"<insert here>\";\n        });\n    \nBy default, IdentityServer configures a cookie handler specifically for the results of external authentication (with the scheme based on the constant ``IdentityServerConstants.ExternalCookieAuthenticationScheme``).\nThe configuration for the Google handler is then using that cookie handler.\n\nNow run the MVC client and try to authenticate - you will see a Google button on the login page:\n\n.. image:: images/4_login_page.png\n\nAfter authentication with the MVC client, you can see that the claims are now being sourced from Google data.\n\n.. note:: If you are interested in the magic that automatically renders the Google button on the login page, inspect the ``BuildLoginViewModel`` method on the ``AccountController``.\n\nFurther experiments\n^^^^^^^^^^^^^^^^^^^\nYou can add an additional external provider.\nWe have a `cloud-hosted demo <https://demo.identityserver8.io>`_ version of IdentityServer8 which you can integrate using OpenID Connect.\n\nAdd the OpenId Connect handler to DI::\n\n    services.AddAuthentication()\n        .AddGoogle(\"Google\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n            options.ClientId = \"<insert here>\";\n            options.ClientSecret = \"<insert here>\";\n        })\n        .AddOpenIdConnect(\"oidc\", \"Demo IdentityServer\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n            options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n            options.SaveTokens = true;\n\n            options.Authority = \"https://demo.identityserver8.io/\";\n            options.ClientId = \"interactive.confidential\";\n            options.ClientSecret = \"secret\";\n            options.ResponseType = \"code\";\n\n            options.TokenValidationParameters = new TokenValidationParameters\n            {\n                NameClaimType = \"name\",\n                RoleClaimType = \"role\"\n            };\n        });\n\nAnd now a user should be able to use the cloud-hosted demo identity provider.\n\n.. note:: The quickstart UI auto-provisions external users. As an external user logs in for the first time, a new local user is created, and all the external claims are copied over and associated with the new user. The way you deal with such a situation is completely up to you though. Maybe you want to show some sort of registration UI first. The source code for the default quickstart can be found `here <https://github.com/alexhiggins732/IdentityServer8.Quickstart.UI>`_. The controller where auto-provisioning is executed can be found `here <https://github.com/alexhiggins732/IdentityServer8.Quickstart.UI/blob/main/Quickstart/Account/ExternalController.cs>`_.\n"
  },
  {
    "path": "docs/quickstarts/3_aspnetcore_and_apis.rst",
    "content": ".. _refAspNetCoreAndApis:\nASP.NET Core and API access\n===========================\nIn the previous quickstarts we explored both API access and user authentication. \nNow we want to bring the two parts together.\n\nThe beauty of the OpenID Connect & OAuth 2.0 combination is, that you can achieve both with a single protocol and a single exchange with the token service.\n\nSo far we only asked for identity resources during the token request, once we start also including API resources, IdentityServer will return two tokens:\nthe identity token containing the information about the authentication and session, and the access token to access APIs on behalf of the logged on user.\n\nModifying the client configuration\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nUpdating the client configuration in IdentityServer is straightforward - we simply need to add the ``api1`` resource to the allowed scopes list.\nIn addition we enable support for refresh tokens via the ``AllowOfflineAccess`` property::\n\n    new Client\n    {\n        ClientId = \"mvc\",\n        ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n        AllowedGrantTypes = GrantTypes.Code,\n                \n        // where to redirect to after login\n        RedirectUris = { \"https://localhost:5002/signin-oidc\" },\n\n        // where to redirect to after logout\n        PostLogoutRedirectUris = { \"https://localhost:5002/signout-callback-oidc\" },\n        \n        AllowOfflineAccess = true,\n\n        AllowedScopes = new List<string>\n        {\n            IdentityServerConstants.StandardScopes.OpenId,\n            IdentityServerConstants.StandardScopes.Profile,\n            \"api1\"\n        }\n    }\n\nModifying the MVC client\n^^^^^^^^^^^^^^^^^^^^^^^^\nAll that's left to do now in the client is to ask for the additional resources via the scope parameter. This is done in the OpenID Connect handler configuration::\n\n    services.AddAuthentication(options =>\n    {\n        options.DefaultScheme = \"Cookies\";\n        options.DefaultChallengeScheme = \"oidc\";\n    })\n        .AddCookie(\"Cookies\")\n        .AddOpenIdConnect(\"oidc\", options =>\n        {\n            options.Authority = \"https://localhost:5001\";\n\n            options.ClientId = \"mvc\";\n            options.ClientSecret = \"secret\";\n            options.ResponseType = \"code\";\n\n            options.SaveTokens = true;\n\n            options.Scope.Add(\"api1\");\n            options.Scope.Add(\"offline_access\");\n        });\n\nSince ``SaveTokens`` is enabled, ASP.NET Core will automatically store the resulting access and refresh token in the authentication session.\nYou should be able to inspect the data on the page that prints out the contents of the session that you created earlier.\n\nUsing the access token\n^^^^^^^^^^^^^^^^^^^^^^\nYou can access the tokens in the session using the standard ASP.NET Core extension methods \nthat you can find in the ``Microsoft.AspNetCore.Authentication`` namespace::\n\n    var accessToken = await HttpContext.GetTokenAsync(\"access_token\");\n\nFor accessing the API using the access token, all you need to do is retrieve the token, and set it on your HttpClient::\n\n    public async Task<IActionResult> CallApi()\n    {\n        var accessToken = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = new HttpClient();\n        client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue(\"Bearer\", accessToken);\n        var content = await client.GetStringAsync(\"https://localhost:6001/identity\");\n\n        ViewBag.Json = JArray.Parse(content).ToString();\n        return View(\"json\");\n    }\n\nCreate a view called json.cshtml that outputs the json like this::\n\n    <pre>@ViewBag.Json</pre>\n\nMake sure the API is running, start the MVC client and call ``/home/CallApi`` after authentication.\n\nManaging the access token\n^^^^^^^^^^^^^^^^^^^^^^^^^\nBy far the most complex task for a typical client is to manage the access token. You typically want to \n\n* request the access and refresh token at login time\n* cache those tokens\n* use the access token to call APIs until it expires\n* use the refresh token to get a new access token\n* start over\n\nASP.NET Core has many built-in facility that can help you with those tasks (like caching or sessions), \nbut there is still quite some work left to do. \nFeel free to have a look at `this <https://github.com/IdentityModel/IdentityModel.AspNetCore>`_ library, which can automate \nmany of the boilerplate tasks.\n"
  },
  {
    "path": "docs/quickstarts/4_javascript_client.rst",
    "content": ".. _refJavaScriptQuickstart:\nAdding a JavaScript client\n==========================\n\n.. note:: For any pre-requisites (like e.g. templates) have a look at the :ref:`overview <refQuickstartOverview>` first.\n\nThis quickstart will show how to build a browser-based JavaScript client application (sometimes referred to as a \"Single Page Application\" or \"`SPA`\").\n\nThe user will login to IdentityServer, invoke the web API with an access token issued by IdentityServer, and logout of IdentityServer. \nAll of this will be driven from the JavaScript running in the browser.\n\nNew Project for the JavaScript client\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nCreate a new project for the JavaScript application.\nIt can simply be an empty web project, an empty ASP.NET Core application, or something else like a Node.js application.\nThis quickstart will use an ASP.NET Core application.\n\nCreate a new \"Empty\" ASP.NET Core web application in the `~/src` directory.\nYou can use Visual Studio or do this from the command line::\n\n    md JavaScriptClient\n    cd JavaScriptClient\n    dotnet new web\n\nAs we have done before, with other client projects, add this project also to your solution. Run this from the root folder which has the sln file::\n\n    dotnet sln add .\\src\\JavaScriptClient\\JavaScriptClient.csproj\n    \nModify hosting\n^^^^^^^^^^^^^^^\n\nModify the `JavaScriptClient` project to run on https://localhost:5003.\n\nAdd the static file middleware\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nGiven that this project is designed to run client-side, all we need ASP.NET Core to do is to serve up the static HTML and JavaScript files that will make up our application.\nThe static file middleware is designed to do this.\n\nRegister the static file middleware in `Startup.cs` in the ``Configure`` method (and at the same time remove everything else)::\n\n    public void Configure(IApplicationBuilder app)\n    {\n        app.UseDefaultFiles();\n        app.UseStaticFiles();\n    }\n\nThis middleware will now serve up static files from the application's `~/wwwroot` folder.\nThis is where we will put our HTML and JavaScript files.\nIf that folder does not exist in your project, create it now.\n\nReference oidc-client\n^^^^^^^^^^^^^^^^^^^^^\n\nIn one of the previous quickstarts in the ASP.NET Core MVC-based client project we used a library to handle the OpenID Connect protocol. \nIn this quickstart in the `JavaScriptClient` project we need a similar library, except one that works in JavaScript and is designed to run in the browser.\nThe `oidc-client library <https://github.com/IdentityModel/oidc-client-js>`_ is one such library. \nIt is available via `NPM <https://github.com/IdentityModel/oidc-client-js>`_, `Bower <https://bower.io/search/?q=oidc-client>`_,  as well as a `direct download <https://github.com/IdentityModel/oidc-client-js/tree/release/dist>`_ from github.\n\n**NPM**\n\nIf you want to use NPM to download `oidc-client`, then run these commands from your `JavaScriptClient` project directory::\n\n    npm i oidc-client\n    copy node_modules\\oidc-client\\dist\\* wwwroot\n\nThis downloads the latest `oidc-client` package locally, and then copies the relevant JavaScript files into `~/wwwroot` so they can be served up by your application.\n\n**Manual download**\n\nIf you want to simply download the `oidc-client` JavaScript files manually, browse to `the GitHub repository <https://github.com/IdentityModel/oidc-client-js/tree/release/dist>`_  and download the JavaScript files. Once downloaded, copy them into `~/wwwroot` so they can be served up by your application.\n\nAdd your HTML and JavaScript files\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nNext is to add your HTML and JavaScript files to `~/wwwroot`.\nWe will have two HTML files and one application-specific JavaScript file (in addition to the `oidc-client.js` library).\nIn `~/wwwroot`, add a HTML file named `index.html` and `callback.html`, and add a JavaScript file called `app.js`.\n\n**index.html**\n\nThis will be the main page in our application. \nIt will simply contain the HTML for the buttons for the user to login, logout, and call the web API.\nIt will also contain the ``<script>`` tags to include our two JavaScript files.\nIt will also contain a ``<pre>`` used for showing messages to the user.\n\nIt should look like this::\n\n    <!DOCTYPE html>\n    <html>\n    <head>\n        <meta charset=\"utf-8\" />\n        <title></title>\n    </head>\n    <body>\n        <button id=\"login\">Login</button>\n        <button id=\"api\">Call API</button>\n        <button id=\"logout\">Logout</button>\n\n        <pre id=\"results\"></pre>\n\n        <script src=\"oidc-client.js\"></script>\n        <script src=\"app.js\"></script>\n    </body>\n    </html>\n\n**app.js**\n\nThis will contain the main code for our application.\nThe first thing is to add a helper function to log messages to the ``<pre>``::\n\n    function log() {\n        document.getElementById('results').innerText = '';\n\n        Array.prototype.forEach.call(arguments, function (msg) {\n            if (msg instanceof Error) {\n                msg = \"Error: \" + msg.message;\n            }\n            else if (typeof msg !== 'string') {\n                msg = JSON.stringify(msg, null, 2);\n            }\n            document.getElementById('results').innerHTML += msg + '\\r\\n';\n        });\n    }\n\nNext, add code to register ``click`` event handlers to the three buttons::\n\n    document.getElementById(\"login\").addEventListener(\"click\", login, false);\n    document.getElementById(\"api\").addEventListener(\"click\", api, false);\n    document.getElementById(\"logout\").addEventListener(\"click\", logout, false);\n\nNext, we can use the ``UserManager`` class from the `oidc-client` library to manage the OpenID Connect protocol. \nIt requires similar configuration that was necessary in the MVC Client (albeit with different values). \nAdd this code to configure and instantiate the ``UserManager``::\n\n    var config = {\n        authority: \"https://localhost:5001\",\n        client_id: \"js\",\n        redirect_uri: \"https://localhost:5003/callback.html\",\n        response_type: \"code\",\n        scope:\"openid profile api1\",\n        post_logout_redirect_uri : \"https://localhost:5003/index.html\",\n    };\n    var mgr = new Oidc.UserManager(config);\n\nNext, the ``UserManager`` provides a ``getUser`` API to know if the user is logged into the JavaScript application.\nIt uses a JavaScript ``Promise`` to return the results asynchronously. \nThe returned ``User`` object has a ``profile`` property which contains the claims for the user.\nAdd this code to detect if the user is logged into the JavaScript application::\n\n    mgr.getUser().then(function (user) {\n        if (user) {\n            log(\"User logged in\", user.profile);\n        }\n        else {\n            log(\"User not logged in\");\n        }\n    });\n\nNext, we want to implement the ``login``, ``api``, and ``logout`` functions. \nThe ``UserManager`` provides a ``signinRedirect`` to log the user in, and a ``signoutRedirect`` to log the user out.\nThe ``User`` object that we obtained in the above code also has an ``access_token`` property which can be used to authenticate to a web API.\nThe ``access_token`` will be passed to the web API via the `Authorization` header with the `Bearer` scheme.\nAdd this code to implement those three functions in our application::\n\n    function login() {\n        mgr.signinRedirect();\n    }\n\n    function api() {\n        mgr.getUser().then(function (user) {\n            var url = \"https://localhost:6001/identity\";\n\n            var xhr = new XMLHttpRequest();\n            xhr.open(\"GET\", url);\n            xhr.onload = function () {\n                log(xhr.status, JSON.parse(xhr.responseText));\n            }\n            xhr.setRequestHeader(\"Authorization\", \"Bearer \" + user.access_token);\n            xhr.send();\n        });\n    }\n\n    function logout() {\n        mgr.signoutRedirect();\n    }\n\n.. Note:: See the :ref:`client credentials quickstart <refClientCredentialsQuickstart>` for information on how to create the api used in the code above.\n\n**callback.html**\n\nThis HTML file is the designated ``redirect_uri`` page once the user has logged into IdentityServer.\nIt will complete the OpenID Connect protocol sign-in handshake with IdentityServer. \nThe code for this is all provided by the ``UserManager`` class we used earlier. \nOnce the sign-in is complete, we can then redirect the user back to the main `index.html` page. \nAdd this code to complete the signin process::\n\n    <!DOCTYPE html>\n    <html>\n    <head>\n        <meta charset=\"utf-8\" />\n        <title></title>\n    </head>\n    <body>\n        <script src=\"oidc-client.js\"></script>\n        <script>\n            new Oidc.UserManager({response_mode:\"query\"}).signinRedirectCallback().then(function() {\n                window.location = \"index.html\";\n            }).catch(function(e) {\n                console.error(e);\n            });\n        </script>\n    </body>\n    </html>\n\nAdd a client registration to IdentityServer for the JavaScript client\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nNow that the client application is ready to go, we need to define a configuration entry in IdentityServer for this new JavaScript client.\nIn the IdentityServer project locate the client configuration (in `Config.cs`).\nAdd a new `Client` to the list for our new JavaScript application.\nIt should have the configuration listed below::\n\n    // JavaScript Client\n    new Client\n    {\n        ClientId = \"js\",\n        ClientName = \"JavaScript Client\",\n        AllowedGrantTypes = GrantTypes.Code,\n        RequireClientSecret = false,\n        \n        RedirectUris =           { \"https://localhost:5003/callback.html\" },\n        PostLogoutRedirectUris = { \"https://localhost:5003/index.html\" },\n        AllowedCorsOrigins =     { \"https://localhost:5003\" },\n\n        AllowedScopes = \n        {\n            IdentityServerConstants.StandardScopes.OpenId,\n            IdentityServerConstants.StandardScopes.Profile,\n            \"api1\"\n        }\n    }\n\nAllowing Ajax calls to the Web API with CORS\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nOne last bit of configuration that is necessary is to configure CORS in the web API project. \nThis will allow Ajax calls to be made from `https://localhost:5003` to `https://localhost:6001`.\n\n**Configure CORS**\n\nAdd the CORS services to the dependency injection system in ``ConfigureServices`` in `Startup.cs`::\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        // ...\n\n        services.AddCors(options =>\n        {\n            // this defines a CORS policy called \"default\"\n            options.AddPolicy(\"default\", policy =>\n            {\n                policy.WithOrigins(\"https://localhost:5003\")\n                    .AllowAnyHeader()\n                    .AllowAnyMethod();\n            });\n        });\n    }\n\nAdd the CORS middleware to the pipeline in ``Configure`` (just after routing)::\n\n    public void Configure(IApplicationBuilder app)\n    {\n        app.UseRouting();\n\n        app.UseCors(\"default\");\n\n        // ...\n    }\n\nRun the JavaScript application\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nNow you should be able to run the JavaScript client application:\n\n.. image:: images/jsclient_not_logged_in.png\n\nClick the \"Login\" button to sign the user in.\nOnce the user is returned back to the JavaScript application, you should see their profile information:\n \n.. image:: images/jsclient_logged_in.png\n\nAnd click the \"API\" button to invoke the web API:\n\n.. image:: images/jsclient_api_results.png\n\nAnd finally click \"Logout\" to sign the user out.\n\n.. image:: images/jsclient_signed_out.png\n\nYou now have the start of a JavaScript client application that uses IdentityServer for sign-in, sign-out, and authenticating calls to web APIs.\n"
  },
  {
    "path": "docs/quickstarts/5_entityframework.rst",
    "content": ".. _refEntityFrameworkQuickstart:\nUsing EntityFramework Core for configuration and operational data\n=================================================================\n\nIn the previous quickstarts, we created our client and scope data in code.\nOn startup, IdentityServer loaded this configuration data into memory.\nIf we wanted to modify this configuration data, we had to stop and start IdentityServer.\n\nIdentityServer also generates temporary data, such as authorization codes, consent choices, and refresh tokens.\nBy default, these are also stored in-memory.\n\nTo move this data into a database that is persistent between restarts and across multiple IdentityServer instances, we can use the IdentityServer8 Entity Framework library.\n\n.. Note:: In addition to manually configuring EF support, there is also an IdentityServer template to create a new project with EF support, using ``dotnet new is4ef``.\n\nIdentityServer8.EntityFramework\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n``IdentityServer8.EntityFramework`` implements the required stores and services using the following DbContexts:\n\n    * ConfigurationDbContext - used for configuration data such as clients, resources, and scopes\n    * PersistedGrantDbContext - used for temporary operational data such as authorization codes, and refresh tokens\n\nThese contexts are suitable for any Entity Framework Core compatible relational database.\n\nYou can find these contexts, their entities, and the IdentityServer8 stores that use them in the ``IdentityServer8.EntityFramework.Storage`` nuget package.\n\nYou can find the extension methods to register them in your IdentityServer in ``IdentityServer8.EntityFramework``, which we will do now::\n\n    dotnet add package IdentityServer8.EntityFramework\n\nUsing SqlServer\n^^^^^^^^^^^^^^^\n\nFor this quickstart, we will use the LocalDb version of SQLServer that comes with Visual Studio.\nTo add SQL Server support to our IdentityServer project, you’ll need the following nuget package::\n\n    dotnet add package Microsoft.EntityFrameworkCore.SqlServer\n\nDatabase Schema Changes and Using EF Migrations\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nThe ``IdentityServer8.EntityFramework.Storage`` package contains entity classes that map from IdentityServer’s models.\nAs IdentityServer’s models change, so will the entity classes in ``IdentityServer8.EntityFramework.Storage``.\nAs you use ``IdentityServer8.EntityFramework.Storage`` and upgrade over time, you are responsible for your database schema and changes necessary to that schema as the entity classes change.\nOne approach for managing those changes is to use `EF migrations <https://docs.microsoft.com/en-us/ef/core/managing-schemas/migrations/index>`_, which is what we’ll use in this quickstart.\nIf migrations are not your preference, then you can manage the schema changes in any way you see fit.\n\n.. Note:: You can find the `latest SQL scripts <https://github.com/alexhiggins732/IdentityServer8/tree/main/src/EntityFramework.Storage/migrations/SqlServer/Migrations>`_ for SqlServer in the IdentityServer8.EntityFramework.Storage repository.\n\nConfiguring the Stores\n^^^^^^^^^^^^^^^^^^^^^^\n\nTo start using these stores, you’ll need to replace any existing calls to ``AddInMemoryClients``, ``AddInMemoryIdentityResources``, ``AddInMemoryApiScopes``, ``AddInMemoryApiResources``, and ``AddInMemoryPersistedGrants`` in your ``ConfigureServices`` method in `Startup.cs` with ``AddConfigurationStore`` and ``AddOperationalStore``.\n\nThese methods each require a ``DbContextOptionsBuilder``, meaning your code will look something like this::\n\n    var migrationsAssembly = typeof(Startup).GetTypeInfo().Assembly.GetName().Name;\n    const string connectionString = @\"Data Source=(LocalDb)\\MSSQLLocalDB;database=IdentityServer8.Quickstart.EntityFramework-4.0.0;trusted_connection=yes;\";\n\n    services.AddIdentityServer()\n        .AddTestUsers(TestUsers.Users)\n        .AddConfigurationStore(options =>\n        {\n            options.ConfigureDbContext = b => b.UseSqlServer(connectionString,\n                sql => sql.MigrationsAssembly(migrationsAssembly));\n        })\n        .AddOperationalStore(options =>\n        {\n            options.ConfigureDbContext = b => b.UseSqlServer(connectionString,\n                sql => sql.MigrationsAssembly(migrationsAssembly));\n        });\n\nYou might need these namespaces added to the file::\n\n    using Microsoft.EntityFrameworkCore;\n    using System.Reflection;\n\n\nBecause we are using EF migrations in this quickstart, the call to ``MigrationsAssembly`` is used to inform Entity Framework that the host project will contain the migrations code.\nThis is necessary since the host project is in a different assembly than the one that contains the ``DbContext`` classes.\n\nAdding Migrations\n^^^^^^^^^^^^^^^^^\n\nOnce the IdentityServer has been configured to use Entity Framework, we’ll need to generate some migrations.\n\nTo create migrations, you will need to install the Entity Framework Core CLI on your machine and the ``Microsoft.EntityFrameworkCore.Design`` nuget package in IdentityServer::\n\n    dotnet tool install --global dotnet-ef\n    dotnet add package Microsoft.EntityFrameworkCore.Design\n\nTo create the migrations, open a command prompt in the IdentityServer project directory and run the following two commands::\n\n    dotnet ef migrations add InitialIdentityServerPersistedGrantDbMigration -c PersistedGrantDbContext -o Data/Migrations/IdentityServer/PersistedGrantDb\n    dotnet ef migrations add InitialIdentityServerConfigurationDbMigration -c ConfigurationDbContext -o Data/Migrations/IdentityServer/ConfigurationDb\n\nYou should now see a ``~/Data/Migrations/IdentityServer`` folder in your project containing the code for your newly created migrations.\n\nInitializing the Database\n^^^^^^^^^^^^^^^^^^^^^^^^^\n\nNow that we have the migrations, we can write code to create the database from the migrations.\nWe can also seed the database with the in-memory configuration data that we already defined in the previous quickstarts.\n\n.. Note:: The approach used in this quickstart is used to make it easy to get IdentityServer up and running. You should devise your own database creation and maintenance strategy that is appropriate for your architecture.\n\nIn `Startup.cs` add this method to help initialize the database::\n\n    private void InitializeDatabase(IApplicationBuilder app)\n    {\n        using (var serviceScope = app.ApplicationServices.GetService<IServiceScopeFactory>().CreateScope())\n        {\n            serviceScope.ServiceProvider.GetRequiredService<PersistedGrantDbContext>().Database.Migrate();\n\n            var context = serviceScope.ServiceProvider.GetRequiredService<ConfigurationDbContext>();\n            context.Database.Migrate();\n            if (!context.Clients.Any())\n            {\n                foreach (var client in Config.Clients)\n                {\n                    context.Clients.Add(client.ToEntity());\n                }\n                context.SaveChanges();\n            }\n\n            if (!context.IdentityResources.Any())\n            {\n                foreach (var resource in Config.IdentityResources)\n                {\n                    context.IdentityResources.Add(resource.ToEntity());\n                }\n                context.SaveChanges();\n            }\n\n            if (!context.ApiScopes.Any())\n            {\n                foreach (var resource in Config.ApiScopes)\n                {\n                    context.ApiScopes.Add(resource.ToEntity());\n                }\n                context.SaveChanges();\n            }\n        }\n    }\n\nThe above code may require you to add the following namespaces to your file::\n\n    using System.Linq;\n    using IdentityServer8.EntityFramework.DbContexts;\n    using IdentityServer8.EntityFramework.Mappers;\n\nAnd then we can invoke this from the ``Configure`` method::\n\n    public void Configure(IApplicationBuilder app)\n    {\n        // this will do the initial DB population\n        InitializeDatabase(app);\n\n        // the rest of the code that was already here\n        // ...\n    }\n\nNow if you run the IdentityServer project, the database should be created and seeded with the quickstart configuration data.\nYou should be able to use SQL Server Management Studio or Visual Studio to connect and inspect the data.\n\n.. image:: images/ef_database.png\n\n.. Note:: The above ``InitializeDatabase`` helper API is convenient to seed the database, but this approach is not ideal to leave in to execute each time the application runs. Once your database is populated, consider removing the call to the API.\n\nRun the client applications\n^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nYou should now be able to run any of the existing client applications and sign-in, get tokens, and call the API -- all based upon the database configuration.\n"
  },
  {
    "path": "docs/quickstarts/6_aspnet_identity.rst",
    "content": ".. _refAspNetIdentityQuickstart:\nUsing ASP.NET Core Identity\n===========================\n\n.. note:: For any pre-requisites (like e.g. templates) have a look at the :ref:`overview <refQuickstartOverview>` first.\n\nIdentityServer is designed for flexibility and part of that is allowing you to use any database you want for your users and their data (including passwords).\nIf you are starting with a new user database, then ASP.NET Core Identity is one option you could choose.\nThis quickstart shows how to use ASP.NET Core Identity with IdentityServer.\n\nThe approach this quickstart takes to using ASP.NET Core Identity is to create a new project for the IdentityServer host.\nThis new project will replace the prior IdentityServer project we built up in the previous quickstarts.\nThe reason for this new project is due to the differences in UI assets when using ASP.NET Core Identity (mainly around the differences in login and logout).\nAll the other projects in this solution (for the clients and the API) will remain the same.\n\n.. Note:: This quickstart assumes you are familiar with how ASP.NET Core Identity works. If you are not, it is recommended that you first `learn about it <https://docs.microsoft.com/en-us/aspnet/core/security/authentication/identity>`_.\n\nNew Project for ASP.NET Core Identity\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nThe first step is to add a new project for ASP.NET Core Identity to your solution.\nWe provide a template that contains the minimal UI assets needed to ASP.NET Core Identity with IdentityServer.\nYou will eventually delete the old project for IdentityServer, but there are some items that you will need to migrate over.\n\nStart by creating a new IdentityServer project that will use ASP.NET Core Identity::\n    \n    cd quickstart/src\n    dotnet new is4aspid -n IdentityServerAspNetIdentity\n\nWhen prompted to \"seed\" the user database, choose \"Y\" for \"yes\".\nThis populates the user database with our \"alice\" and \"bob\" users. \nTheir passwords are \"Pass123$\".\n\n.. Note:: The template uses Sqlite as the database for the users, and EF migrations are pre-created in the template. If you wish to use a different database provider, you will need to change the provider used in the code and re-create the EF migrations.\n\nInspect the new project\n^^^^^^^^^^^^^^^^^^^^^^^\n\nOpen the new project in the editor of your choice, and inspect the generated code.\nBe sure to look at:\n\nIdentityServerAspNetIdentity.csproj\n-----------------------------------\n\nNotice the reference to `IdentityServer8.AspNetIdentity`. \nThis NuGet package contains the ASP.NET Core Identity integration components for IdentityServer.\n\nStartup.cs\n----------\n\nIn `ConfigureServices` notice the necessary ``AddDbContext<ApplicationDbContext>`` and ``AddIdentity<ApplicationUser, IdentityRole>`` calls are done to configure ASP.NET Core Identity.\n\nAlso notice that much of the same IdentityServer configuration you did in the previous quickstarts is already done.\nThe template uses the in-memory style for clients and resources, and those are sourced from `Config.cs`.\n\nFinally, notice the addition of the new call to ``AddAspNetIdentity<ApplicationUser>``.\n``AddAspNetIdentity`` adds the integration layer to allow IdentityServer to access the user data for the ASP.NET Core Identity user database.\nThis is needed when IdentityServer must add claims for the users into tokens.\n\nNote that ``AddIdentity<ApplicationUser, IdentityRole>`` must be invoked before ``AddIdentityServer``.\n\nConfig.cs\n-----------\n\n`Config.cs` contains the hard-coded in-memory clients and resource definitions.\nTo keep the same clients and API working as the prior quickstarts, we need to copy over the configuration data from the old IdentityServer project into this one.\nDo that now, and afterwards `Config.cs` should look like this::\n\n    public static class Config\n    {\n        public static IEnumerable<IdentityResource> IdentityResources =>\n            new List<IdentityResource>\n            {\n                new IdentityResources.OpenId(),\n                new IdentityResources.Profile(),\n            };\n\n        public static IEnumerable<ApiScope> ApiScopes =>\n            new List<ApiScope>\n            {\n                new ApiScope(\"api1\", \"My API\")\n            };\n\n        public static IEnumerable<Client> Clients =>\n            new List<Client>\n            {\n                // machine to machine client\n                new Client\n                {\n                    ClientId = \"client\",\n                    ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                    AllowedGrantTypes = GrantTypes.ClientCredentials,\n                    // scopes that client has access to\n                    AllowedScopes = { \"api1\" }\n                },\n                \n                // interactive ASP.NET Core MVC client\n                new Client\n                {\n                    ClientId = \"mvc\",\n                    ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                    AllowedGrantTypes = GrantTypes.Code,\n                    \n                    // where to redirect to after login\n                    RedirectUris = { \"https://localhost:5002/signin-oidc\" },\n\n                    // where to redirect to after logout\n                    PostLogoutRedirectUris = { \"https://localhost:5002/signout-callback-oidc\" },\n\n                    AllowedScopes = new List<string>\n                    {\n                        IdentityServerConstants.StandardScopes.OpenId,\n                        IdentityServerConstants.StandardScopes.Profile,\n                        \"api1\"\n                    }\n                }\n            };\n    }\n\n\nAt this point, you no longer need the old IdentityServer project.\n\nProgram.cs and SeedData.cs\n--------------------------\n\n`Program.cs`'s ``Main`` is a little different than most ASP.NET Core projects.\nNotice how this looks for a command line argument called `/seed` which is used as a flag to seed the users in the ASP.NET Core Identity database.\n\nLook at the ``SeedData`` class' code to see how the database is created and the first users are created.\n\nAccountController\n-----------------\n\nThe last code to inspect in this template is the ``AccountController``. \nThis contains a slightly different login and logout code than the prior quickstart and templates.\nNotice the use of the ``SignInManager<ApplicationUser>`` and ``UserManager<ApplicationUser>`` from ASP.NET Core Identity to validate credentials and manage the authentication session.\n\nMuch of the rest of the code is the same from the prior quickstarts and templates.\n\nLogging in with the MVC client\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nAt this point, you should be able to run all of the existing clients and samples.\nOne exception is the `ResourceOwnerClient` -- the password will need to be updated to ``Pass123$`` from ``password``.\n\nLaunch the MVC client application, and you should be able to click the \"Secure\" link to get logged in.\n\n.. image:: images/aspid_mvc_client.png\n\nYou should be redirected to the ASP.NET Core Identity login page.\nLogin with your newly created user:\n\n.. image:: images/aspid_login.png\n\nAfter login you see the normal consent page. \nAfter consent you will be redirected back to the MVC client application where your user's claims should be listed.\n\n.. image:: images/aspid_claims.png\n\nYou should also be able to click \"Call API using application identity\" to invoke the API on behalf of the user:\n\n.. image:: images/aspid_api_claims.png\n\nAnd now you're using users from ASP.NET Core Identity in IdentityServer.\n\nWhat's Missing?\n^^^^^^^^^^^^^^^\n\nMuch of the rest of the code in this template is similar to the other quickstart and templates we provide.\nThe one thing you will notice that is missing from this template is UI code for user registration, password reset, and the other things you might expect from the Visual Studio ASP.NET Core Identity template.\n\nGiven the variety of requirements and different approaches to using ASP.NET Core Identity, our template deliberately does not provide those features.\nYou are expected to know how ASP.NET Core Identity works sufficiently well to add those features to your project.\nAlternatively, you can create a new project based on the Visual Studio ASP.NET Core Identity template and add the IdentityServer features you have learned about in these quickstarts to that project.\n"
  },
  {
    "path": "docs/quickstarts/community.rst",
    "content": "Community quickstarts & samples\n===============================\nThese samples are not maintained by the IdentityServer organization.\nThe IdentityServer organization happily links to community samples, but can't make any guarantees about the samples.\nPlease contact the authors directly.\n\nVarious ASP.NET Core security samples\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nhttps://github.com/leastprivilege/AspNetCoreSecuritySamples\n\nCo-hosting IdentityServer8 and a Web API\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThis sample shows how to host an API in the same host as the IdentityServer that is protecting the API.\n\nhttps://github.com/brockallen/IdentityServerAndApi\n\nIdentityServer8 samples for MongoDB\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n* IdentityServer8-mongo: Similar to Quickstart EntityFramework configuration but using MongoDB for the configuration data.\n* IdentityServer8-mongo-AspIdentity: More elaborated sample based on uses ASP.NET Identity for identity management that uses using MongoDB for the configuration data\n\nhttps://github.com/souzartn/IdentityServer8.Samples.Mongo\n\nExchanging external tokens from Facebook, Google and Twitter\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n* Shows how to exchange an external authentication token to an identity server acesss token using an extension grant\n\nhttps://github.com/waqaskhan540/IdentityServerExternalAuth\n\n\n.NET Core and ASP.NET Core \"Platform\" scenario\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n* Shows an interaction of trusted \"internal\" applications and \"external\" applications with .NET Core 2.0 and ASP.NET Core 2.0 applications\nhttps://github.com/BenjaminAbt/Samples.AspNetCore-IdentityServer8\n\n\nSecuring a Node API with tokens from IdentityServer8 using JWKS\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n* Shows how to secure a Node (Express) API using the JWKS endpoint and RS256 algorithm from IdentityServer8.\n* Provides an alternative to the NodeJsApi sample from IdentityServer samples using higher quality - production ready modules.\n\nhttps://github.com/lyphtec/idsvr4-node-jwks\n"
  },
  {
    "path": "docs/readme.md",
    "content": "# IdentityServer8 documentation\n\nThe folder contains the documentation for IdentityServer8.\n\nWe are using [Read the docs](https://readthedocs.org/) to host the documentation and the rendered version\ncan be found [here](https://IdentityServer8.readthedocs.io).\n\nDoc pages are authored in ReStructuredText (RST) - you can find a primer [here](http://www.sphinx-doc.org/en/stable/rest.html).\n\nYou can find more information about RTD and Sphinx under the following links:\n\n* [Read the Docs documentation](https://docs.readthedocs.io/en/latest/index.html)\n* [Sphinx](http://www.sphinx-doc.org/)\n* [Getting started Screencast](https://www.youtube.com/watch?feature=player_embedded&v=oJsUvBQyHBs)\n"
  },
  {
    "path": "docs/reference/api_resource.rst",
    "content": ".. _refApiResource:\nAPI Resource\n=================\nThis class models an API resource.\n\n``Enabled``\n    Indicates if this resource is enabled and can be requested. Defaults to true.\n``Name``\n    The unique name of the API. This value is used for authentication with introspection and will be added to the audience of the outgoing access token.\n``DisplayName``\n    This value can be used e.g. on the consent screen.\n``Description``\n    This value can be used e.g. on the consent screen.\n``ApiSecrets``\n    The API secret is used for the introspection endpoint. The API can authenticate with introspection using the API name and secret.\n``AllowedAccessTokenSigningAlgorithms``\n    List of allowed signing algorithms for access token. If empty, will use the server default signing algorithm.\n``UserClaims``\n    List of associated user claim types that should be included in the access token.\n``Scopes``\n    List of API scope names.\n\nDefining API resources in appsettings.json\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThe ``AddInMemoryApiResource`` extensions method also supports adding API resources from the ASP.NET Core configuration file::\n\n    \"IdentityServer\": {\n        \"IssuerUri\": \"urn:sso.company.com\",\n        \"ApiResources\": [\n            {\n                \"Name\": \"resource1\",\n                \"DisplayName\": \"Resource #1\",\n\n                \"Scopes\": [\n                    \"resource1.scope1\",\n                    \"shared.scope\"\n                ]\n            },\n            {\n                \"Name\": \"resource2\",\n                \"DisplayName\": \"Resource #2\",\n                \n                \"UserClaims\": [\n                    \"name\",\n                    \"email\"\n                ],\n\n                \"Scopes\": [\n                    \"resource2.scope1\",\n                    \"shared.scope\"\n                ]\n            }\n        ]\n    }\n\nThen pass the configuration section to the ``AddInMemoryApiResource`` method::\n\n    AddInMemoryApiResources(configuration.GetSection(\"IdentityServer:ApiResources\"))\n"
  },
  {
    "path": "docs/reference/api_scope.rst",
    "content": ".. _refApiScope:\nAPI Scope\n=================\nThis class models an OAuth scope.\n\n``Enabled``\n    Indicates if this resource is enabled and can be requested. Defaults to true.\n``Name``\n    The unique name of the API. This value is used for authentication with introspection and will be added to the audience of the outgoing access token.\n``DisplayName``\n    This value can be used e.g. on the consent screen.\n``Description``\n    This value can be used e.g. on the consent screen.\n``UserClaims``\n    List of associated user claim types that should be included in the access token.\n\nDefining API scope in appsettings.json\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nThe ``AddInMemoryApiResource`` extension method also supports adding clients from the ASP.NET Core configuration file::\n\n    \"IdentityServer\": {\n        \"IssuerUri\": \"urn:sso.company.com\",\n        \"ApiScopes\": [\n            {\n                \"Name\": \"IdentityServerApi\"\n            },\n            {\n                \"Name\": \"resource1.scope1\"\n            },\n            {\n                \"Name\": \"resource2.scope1\"\n            },\n            {\n                \"Name\": \"scope3\"\n            },\n            {\n                \"Name\": \"shared.scope\"\n            },\n            {\n                \"Name\": \"transaction\",\n                \"DisplayName\": \"Transaction\",\n                \"Description\": \"A transaction\"\n            }\n        ]\n    }\n\nThen pass the configuration section to the ``AddInMemoryApiScopes`` method::\n\n    AddInMemoryApiScopes(configuration.GetSection(\"IdentityServer:ApiScopes\"))\n"
  },
  {
    "path": "docs/reference/aspnet_identity.rst",
    "content": ".. _refAspNetId:\nASP.NET Identity Support\n========================\n\nAn ASP.NET Identity-based implementation is provided for managing the identity database for users of IdentityServer.\nThis implementation implements the extensibility points in IdentityServer needed to load identity data for your users to emit claims into tokens.\n\nThe repo for this support is located `here <https://github.com/alexhiggins732/IdentityServer8.AspNetIdentity/>`_ and the NuGet package is `here <https://www.nuget.org/packages/HigginsSoft.IdentityServer8.AspNetIdentity>`_.\n\nTo use this library, configure ASP.NET Identity normally. \nThen use the ``AddAspNetIdentity`` extension method after the call to ``AddIdentityServer``::\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        services.AddIdentity<ApplicationUser, IdentityRole>()\n            .AddEntityFrameworkStores<ApplicationDbContext>()\n            .AddDefaultTokenProviders();\n\n        services.AddIdentityServer()\n            .AddAspNetIdentity<ApplicationUser>();\n    }\n\n``AddAspNetIdentity`` requires as a generic parameter the class that models your user for ASP.NET Identity (and the same one passed to ``AddIdentity`` to configure ASP.NET Identity).\nThis configures IdentityServer to use the ASP.NET Identity implementations of ``IUserClaimsPrincipalFactory``, ``IResourceOwnerPasswordValidator``, and ``IProfileService``.\nIt also configures some of ASP.NET Identity's options for use with IdentityServer (such as claim types to use and authentication cookie settings).\n\nWhen using your own implementation of ``IUserClaimsPrincipalFactory``, make sure that you register it before calling the IdentityServer ``AddAspNetIdentity`` extension method."
  },
  {
    "path": "docs/reference/client.rst",
    "content": ".. _refClient:\nClient\n======\nThe ``Client`` class models an OpenID Connect or OAuth 2.0 client - \ne.g. a native application, a web application or a JS-based application.\n\nBasics\n^^^^^^\n``Enabled``\n    Specifies if client is enabled. Defaults to `true`.\n``ClientId``\n    Unique ID of the client\n``ClientSecrets``\n    List of client secrets - credentials to access the token endpoint.\n``RequireClientSecret``\n    Specifies whether this client needs a secret to request tokens from the token endpoint (defaults to ``true``)\n``RequireRequestObject``\n    Specifies whether this client needs to wrap the authorize request parameters in a JWT (defaults to ``false``)\n``AllowedGrantTypes``\n    Specifies the grant types the client is allowed to use. Use the ``GrantTypes`` class for common combinations.\n``RequirePkce``\n    Specifies whether clients using an authorization code based grant type must send a proof key (defaults to ``true``).\n``AllowPlainTextPkce``\n    Specifies whether clients using PKCE can use a plain text code challenge (not recommended - and default to ``false``)\n``RedirectUris``\n    Specifies the allowed URIs to return tokens or authorization codes to\n``AllowedScopes``\n    By default a client has no access to any resources - specify the allowed resources by adding the corresponding scopes names\n``AllowOfflineAccess``\n    Specifies whether this client can request refresh tokens (be requesting the ``offline_access`` scope)\n``AllowAccessTokensViaBrowser``\n    Specifies whether this client is allowed to receive access tokens via the browser. \n    This is useful to harden flows that allow multiple response types \n    (e.g. by disallowing a hybrid flow client that is supposed to use `code id_token` to add the `token` response type \n    and thus leaking the token to the browser.\n``Properties``\n    Dictionary to hold any custom client-specific values as needed.\n\nAuthentication/Logout\n^^^^^^^^^^^^^^^^^^^^^\n``PostLogoutRedirectUris``\n    Specifies allowed URIs to redirect to after logout. See the `OIDC Connect Session Management spec <https://openid.net/specs/openid-connect-session-1_0.html>`_ for more details.\n``FrontChannelLogoutUri``\n    Specifies logout URI at client for HTTP based front-channel logout. See the `OIDC Front-Channel spec <https://openid.net/specs/openid-connect-frontchannel-1_0.html>`_ for more details.\n``FrontChannelLogoutSessionRequired``\n    Specifies if the user's session id should be sent to the FrontChannelLogoutUri. Defaults to true.\n``BackChannelLogoutUri``\n    Specifies logout URI at client for HTTP based back-channel logout. See the `OIDC Back-Channel spec <https://openid.net/specs/openid-connect-backchannel-1_0.html>`_ for more details.\n``BackChannelLogoutSessionRequired``\n    Specifies if the user's session id should be sent in the request to the BackChannelLogoutUri. Defaults to true.\n``EnableLocalLogin``\n    Specifies if this client can use local accounts, or external IdPs only. Defaults to `true`.\n``IdentityProviderRestrictions``\n    Specifies which external IdPs can be used with this client (if list is empty all IdPs are allowed). Defaults to empty.\n``UserSsoLifetime`` `added in 2.3`\n    The maximum duration (in seconds) since the last time the user authenticated. Defaults to ``null``.\n    You can adjust the lifetime of a session token to control when and how often a user is required to reenter credentials instead of being silently authenticated, when using a web application.\n\nToken\n^^^^^\n``IdentityTokenLifetime``\n    Lifetime to identity token in seconds (defaults to 300 seconds / 5 minutes)\n``AllowedIdentityTokenSigningAlgorithms``\n    List of allowed signing algorithms for identity token. If empty, will use the server default signing algorithm.\n``AccessTokenLifetime``\n    Lifetime of access token in seconds (defaults to 3600 seconds / 1 hour)\n``AuthorizationCodeLifetime``\n    Lifetime of authorization code in seconds (defaults to 300 seconds / 5 minutes)\n``AbsoluteRefreshTokenLifetime``\n    Maximum lifetime of a refresh token in seconds. Defaults to 2592000 seconds / 30 days\n``SlidingRefreshTokenLifetime``\n    Sliding lifetime of a refresh token in seconds. Defaults to 1296000 seconds / 15 days\n``RefreshTokenUsage``\n    ``ReUse`` the refresh token handle will stay the same when refreshing tokens\n    \n    ``OneTime`` the refresh token handle will be updated when refreshing tokens. This is the default.\n``RefreshTokenExpiration``\n    ``Absolute`` the refresh token will expire on a fixed point in time (specified by the AbsoluteRefreshTokenLifetime). This is the default.\n    \n    ``Sliding`` when refreshing the token, the lifetime of the refresh token will be renewed (by the amount specified in SlidingRefreshTokenLifetime). The lifetime will not exceed `AbsoluteRefreshTokenLifetime`.\n``UpdateAccessTokenClaimsOnRefresh``\n    Gets or sets a value indicating whether the access token (and its claims) should be updated on a refresh token request.\n``AccessTokenType``\n    Specifies whether the access token is a reference token or a self contained JWT token (defaults to `Jwt`).\n``IncludeJwtId``\n    Specifies whether JWT access tokens should have an embedded unique ID (via the `jti` claim). Defaults to ``true``.\n``AllowedCorsOrigins``\n    If specified, will be used by the default CORS policy service implementations (In-Memory and EF) to build a CORS policy for JavaScript clients.\n``Claims``\n    Allows settings claims for the client (will be included in the access token).\n``AlwaysSendClientClaims``\n    If set, the client claims will be sent for every flow. If not, only for client credentials flow (default is `false`)\n``AlwaysIncludeUserClaimsInIdToken``\n    When requesting both an id token and access token, should the user claims always be added to the id token instead of requiring the client to use the userinfo endpoint. Default is `false`.\n``ClientClaimsPrefix``\n    If set, the prefix client claim types will be prefixed with. Defaults to `client_`. The intent is to make sure they don't accidentally collide with user claims.\n``PairWiseSubjectSalt``\n    Salt value used in pair-wise subjectId generation for users of this client.\n\nConsent Screen\n^^^^^^^^^^^^^^\n``RequireConsent``\n    Specifies whether a consent screen is required. Defaults to ``false``.\n``AllowRememberConsent``\n    Specifies whether user can choose to store consent decisions. Defaults to ``true``.\n``ConsentLifetime``\n    Lifetime of a user consent in seconds. Defaults to null (no expiration).\n``ClientName``\n    Client display name (used for logging and consent screen)\n``ClientUri``\n    URI to further information about client (used on consent screen)\n``LogoUri``\n    URI to client logo (used on consent screen)\n\nDevice flow\n^^^^^^^^^^^\n``UserCodeType``\n    Specifies the type of user code to use for the client. Otherwise falls back to default.\n``DeviceCodeLifetime``\n    Lifetime to device code in seconds (defaults to 300 seconds / 5 minutes)\n"
  },
  {
    "path": "docs/reference/deviceflow_interactionservice.rst",
    "content": "Device Flow Interaction Service\n==================================\n\nThe ``IDeviceFlowInteractionService`` interface is intended to provide services to be used by the user interface to communicate with IdentityServer during device flow authorization.\nIt is available from the dependency injection system and would normally be injected as a constructor parameter into your MVC controllers for the user interface of IdentityServer.\n\nIDeviceFlowInteractionService APIs\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\n``GetAuthorizationContextAsync``\n    Returns the ``DeviceFlowAuthorizationRequest`` based on the ``userCode`` passed to the login or consent pages.\n\n``DeviceFlowInteractionResult``\n    Completes device authorization for the given ``userCode``.\n\nDeviceFlowAuthorizationRequest\n^^^^^^^^^^^^^^^^^^^^\n``ClientId``\n    The client identifier that initiated the request.\n``ScopesRequested``\n    The scopes requested from the authorization request.\n\nDeviceFlowInteractionResult\n^^^^^^^^^^^^^^^^^^^^^^^^^^^\n``IsError``\n    Specifies if the authorization request errored.\n``ErrorDescription``\n    Error description upon failure.\n"
  },
  {
    "path": "docs/reference/ef.rst",
    "content": ".. _refEF:\nEntity Framework Support\n========================\n\nAn EntityFramework-based implementation is provided for the configuration and operational data extensibility points in IdentityServer.\nThe use of EntityFramework allows any EF-supported database to be used with this library.\n\nThe code for this library is located `here <https://github.com/alexhiggins732/IdentityServer8/tree/main/src/EntityFramework>`_ (with the underlying storage code `here <https://github.com/alexhiggins732/IdentityServer8/tree/main/src/EntityFramework.Storage>`_) and the NuGet package is `here <https://www.nuget.org/packages/HigginsSoft.IdentityServer8.EntityFramework>`_.\n\nThe features provided by this library are broken down into two main areas: configuration store and operational store support.\nThese two different areas can be used independently or together, based upon the needs of the hosting application.\n\nConfiguration Store support for Clients, Resources, and CORS settings\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nIf client, identity resource, API resource, or CORS data is desired to be loaded from a EF-supported database \n(rather than use in-memory configuration), then the configuration store can be used.\nThis support provides implementations of the ``IClientStore``, ``IResourceStore``, and the ``ICorsPolicyService`` extensibility points.\nThese implementations use a ``DbContext``-derived class called ``ConfigurationDbContext`` to model the tables in the database.\n\nTo use the configuration store support, use the ``AddConfigurationStore`` extension method after the call to ``AddIdentityServer``::\n\n    public IServiceProvider ConfigureServices(IServiceCollection services)\n    {\n        const string connectionString = @\"Data Source=(LocalDb)\\MSSQLLocalDB;database=IdentityServer8.EntityFramework-2.0.0;trusted_connection=yes;\";\n        var migrationsAssembly = typeof(Startup).GetTypeInfo().Assembly.GetName().Name;\n        \n        services.AddIdentityServer()\n            // this adds the config data from DB (clients, resources, CORS)\n            .AddConfigurationStore(options =>\n            {\n                options.ConfigureDbContext = builder =>\n                    builder.UseSqlServer(connectionString,\n                        sql => sql.MigrationsAssembly(migrationsAssembly));\n            });\n    }\n\nTo configure the configuration store, use the ``ConfigurationStoreOptions`` options object passed to the configuration callback.\n\nConfigurationStoreOptions\n^^^^^^^^^^^^^^^^^^^^^^^^^\nThis options class contains properties to control the configuration store and ``ConfigurationDbContext``.\n\n``ConfigureDbContext``\n    Delegate of type ``Action<DbContextOptionsBuilder>`` used as a callback to configure the underlying ``ConfigurationDbContext``.\n    The delegate can configure the ``ConfigurationDbContext`` in the same way if EF were being used directly with ``AddDbContext``, which allows any EF-supported database to be used.\n``DefaultSchema``\n    Allows setting the default database schema name for all the tables in the ``ConfigurationDbContext``\n    ::\n            options.DefaultSchema = \"myConfigurationSchema\";      \n\nIf you need to change the schema for the Migration History Table, you can chain another action to the ``UseSqlServer``::\n\n    options.ConfigureDbContext = b =>\n        b.UseSqlServer(connectionString,\n            sql => sql.MigrationsAssembly(migrationsAssembly).MigrationsHistoryTable(\"MyConfigurationMigrationTable\", \"myConfigurationSchema\"));\n\nOperational Store support for persisted grants\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nIf :ref:`persisted grants <refPersistedGrants>` are desired to be loaded from a EF-supported database (rather than the default in-memory database), then the operational store can be used.\nThis support provides implementations of the ``IPersistedGrantStore`` extensibility point.\nThe implementation uses a ``DbContext``-derived class called ``PersistedGrantDbContext`` to model the table in the database.\n\nTo use the operational store support, use the ``AddOperationalStore`` extension method after the call to ``AddIdentityServer``::\n\n    public IServiceProvider ConfigureServices(IServiceCollection services)\n    {\n        const string connectionString = @\"Data Source=(LocalDb)\\MSSQLLocalDB;database=IdentityServer8.EntityFramework-2.0.0;trusted_connection=yes;\";\n        var migrationsAssembly = typeof(Startup).GetTypeInfo().Assembly.GetName().Name;\n        \n        services.AddIdentityServer()\n            // this adds the operational data from DB (codes, tokens, consents)\n            .AddOperationalStore(options =>\n            {\n                options.ConfigureDbContext = builder =>\n                    builder.UseSqlServer(connectionString,\n                        sql => sql.MigrationsAssembly(migrationsAssembly));\n\n                // this enables automatic token cleanup. this is optional.\n                options.EnableTokenCleanup = true;\n                options.TokenCleanupInterval = 3600; // interval in seconds (default is 3600)\n            });\n    }\n\nTo configure the operational store, use the ``OperationalStoreOptions`` options object passed to the configuration callback.\n\nOperationalStoreOptions\n^^^^^^^^^^^^^^^^^^^^^^^\nThis options class contains properties to control the operational store and ``PersistedGrantDbContext``.\n\n``ConfigureDbContext``\n    Delegate of type ``Action<DbContextOptionsBuilder>`` used as a callback to configure the underlying ``PersistedGrantDbContext``.\n    The delegate can configure the ``PersistedGrantDbContext`` in the same way if EF were being used directly with ``AddDbContext``, which allows any EF-supported database to be used.\n``DefaultSchema``\n    Allows setting the default database schema name for all the tables in the ``PersistedGrantDbContext``.\n``EnableTokenCleanup``\n    Indicates whether expired grants will be automatically cleaned up from the database. The default is ``false``.\n``TokenCleanupInterval``\n    The token cleanup interval (in seconds). The default is 3600 (1 hour).\n\n.. note:: The token cleanup feature does *not* remove persisted grants that are *consumed* (see :ref:`persisted grants <refPersistedGrants>`).\n\nDatabase creation and schema changes across different versions of IdentityServer\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nIt is very likely that across different versions of IdentityServer (and the EF support) that the database schema will change to accommodate new and changing features.\n\nWe do not provide any support for creating your database or migrating your data from one version to another. \nYou are expected to manage the database creation, schema changes, and data migration in any way your organization sees fit.\n\nUsing EF migrations is one possible approach to this. \nIf you do wish to use migrations, then see the :ref:`EF quickstart <refEntityFrameworkQuickstart>` for samples on how to get started, or consult the Microsoft `documentation on EF migrations <https://docs.microsoft.com/en-us/ef/core/managing-schemas/migrations/index>`_.\n\nWe also publish `sample SQL scripts <https://github.com/alexhiggins732/IdentityServer8/tree/main/src/EntityFramework.Storage/migrations/SqlServer/Migrations>`_ for the current version of the database schema.\n"
  },
  {
    "path": "docs/reference/grant_validation_result.rst",
    "content": ".. _refGrantValidationResult:\nGrantValidationResult\n=====================\n\nThe ``GrantValidationResult`` class models the outcome of grant validation for extensions grants and resource owner password grants.\n\nThe most common usage is to either new it up using an identity (success case)::\n\n    context.Result = new GrantValidationResult(\n        subject: \"818727\", \n        authenticationMethod: \"custom\", \n        claims: optionalClaims);\n\n...or using an error and description (failure case)::\n\n    context.Result = new GrantValidationResult(\n        TokenRequestErrors.InvalidGrant, \n        \"invalid custom credential\");\n\nIn both case you can pass additional custom values that will be included in the token response."
  },
  {
    "path": "docs/reference/identity_resource.rst",
    "content": ".. _refIdentityResource:\nIdentity Resource\n=================\n\nThis class models an identity resource.\n\n``Enabled``\n    Indicates if this resource is enabled and can be requested. Defaults to true.\n``Name``\n    The unique name of the identity resource. This is the value a client will use for the scope parameter in the authorize request.\n``DisplayName``\n    This value will be used e.g. on the consent screen.\n``Description``\n    This value will be used e.g. on the consent screen.\n``Required``\n    Specifies whether the user can de-select the scope on the consent screen (if the consent screen wants to implement such a feature). Defaults to false.\n``Emphasize``\n    Specifies whether the consent screen will emphasize this scope (if the consent screen wants to implement such a feature). Use this setting for sensitive or important scopes. Defaults to false.\n``ShowInDiscoveryDocument``\n    Specifies whether this scope is shown in the discovery document. Defaults to true.\n``UserClaims``\n    List of associated user claim types that should be included in the identity token."
  },
  {
    "path": "docs/reference/interactionservice.rst",
    "content": ".. _refInteractionService:\nIdentityServer Interaction Service\n==================================\n\nThe ``IIdentityServerInteractionService`` interface is intended to provide services to be used by the user interface to communicate with IdentityServer, mainly pertaining to user interaction.\nIt is available from the dependency injection system and would normally be injected as a constructor parameter into your MVC controllers for the user interface of IdentityServer.\n\nIIdentityServerInteractionService APIs\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\n``GetAuthorizationContextAsync``\n    Returns the ``AuthorizationRequest`` based on the ``returnUrl`` passed to the login or consent pages.\n\n``IsValidReturnUrl``\n    Indicates if the ``returnUrl`` is a valid URL for redirect after login or consent.\n\n``GetErrorContextAsync``\n    Returns the ``ErrorMessage`` based on the ``errorId`` passed to the error page.\n\n``GetLogoutContextAsync``\n    Returns the ``LogoutRequest`` based on the ``logoutId`` passed to the logout page.\n\n``CreateLogoutContextAsync``\n    Used to create a ``logoutId`` if there is not one presently.\n    This creates a cookie capturing all the current state needed for signout and the ``logoutId`` identifies that cookie.\n    This is typically used when there is no current ``logoutId`` and the logout page must capture the current user's state needed for sign-out prior to redirecting to an external identity provider for signout.\n    The newly created ``logoutId`` would need to be round-tripped to the external identity provider at signout time, and then used on the signout callback page in the same way it would be on the normal logout page.\n\n``GrantConsentAsync``\n    Accepts a ``ConsentResponse`` to inform IdentityServer of the user's consent to a particular ``AuthorizationRequest``.\n\n``DenyAuthorizationAsync``\n    Accepts a ``AuthorizationError`` to inform IdentityServer of the error to return to the client for a particular ``AuthorizationRequest``.\n\n``GetAllUserGrantsAsync``\n    Returns a collection of ``Grant`` for the user. These represent a user's consent or a clients access to a user's resource.\n\n``RevokeUserConsentAsync``\n    Revokes all of a user's consents and grants for a client.\n\n``RevokeTokensForCurrentSessionAsync``\n    Revokes all of a user's consents and grants for clients the user has signed into during their current session.\n\nAuthorizationRequest\n^^^^^^^^^^^^^^^^^^^^\n``Client``\n    The client that initiated the request.\n``RedirectUri``\n    The URI to redirect the user to after successful authorization.\n``DisplayMode``\n    The display mode passed from the authorization request.\n``UiLocales``\n    The UI locales passed from the authorization request.\n``IdP``\n    The external identity provider requested.\n    This is used to bypass home realm discovery (HRD).\n    This is provided via the \"idp:\" prefix to the ``acr_values`` parameter on the authorize request.\n``Tenant``\n    The tenant requested.\n    This is provided via the \"tenant:\" prefix to the ``acr_values`` parameter on the authorize request.\n``LoginHint``\n    The expected username the user will use to login.\n    This is requested from the client via the ``login_hint`` parameter on the authorize request.\n``PromptMode``\n    The prompt mode requested from the authorization request.\n``AcrValues``\n    The acr values passed from the authorization request.\n``ValidatedResources``\n    The ``ResourceValidationResult`` which represents the validated resources from the authorization request.\n``Parameters``\n    The entire parameter collection passed to the authorization request.\n``RequestObjectValues``\n    The validated contents of the request object (if present).\n\nResourceValidationResult\n^^^^^^^^^^^^^^^^^^^^^^^^\n``Resources``\n    The resources of the result.\n``ParsedScopes``\n    The parsed scopes represented by the result.\n``RawScopeValues``\n    The original (raw) scope values represented by the validated result.\n\nErrorMessage\n^^^^^^^^^^^^\n``DisplayMode``\n    The display mode passed from the authorization request.\n``UiLocales``\n    The UI locales passed from the authorization request.\n``Error``\n    The error code.\n``RequestId``\n    The per-request identifier. This can be used to display to the end user and can be used in diagnostics.\n\nLogoutRequest\n^^^^^^^^^^^^^\n``ClientId``\n    The client identifier that initiated the request.\n``PostLogoutRedirectUri``\n    The URL to redirect the user to after they have logged out.\n``SessionId``\n    The user's current session id.\n``SignOutIFrameUrl``\n    The URL to render in an ``<iframe>`` on the logged out page to enable single sign-out.\n``Parameters``\n    The entire parameter collection passed to the end session endpoint.\n``ShowSignoutPrompt``\n    Indicates if the user should be prompted for signout based upon the parameters passed to the end session endpoint.\n\nConsentResponse\n^^^^^^^^^^^^^^^\n``ScopesValuesConsented``\n    The collection of scopes the user consented to.\n``RememberConsent``\n    Flag indicating if the user's consent is to be persisted.\n``Description``\n    Optional description the user can set for the grant (e.g. the name of the device being used when consent is given). This can be presented back to the user from the :ref:`persisted grant service <refPersistedGrants>`.\n``Error``\n    Error, if any, for the consent response. This will be returned to the client in the authorization response.\n``ErrorDescription``\n    Error description. This will be returned to the client in the authorization response.\n\nGrant\n^^^^^\n``SubjectId``\n    The subject id that allowed the grant.\n``ClientId``\n    The client identifier for the grant.\n``Description``\n    The description the user assigned to the client or device being authorized.\n``Scopes``\n    The collection of scopes granted.\n``CreationTime``\n    The date and time when the grant was granted.\n``Expiration``\n    The date and time when the grant will expire.\n"
  },
  {
    "path": "docs/reference/options.rst",
    "content": ".. _refOptions:\nIdentityServer Options\n======================\n\n* ``IssuerUri``\n    Set the issuer name that will appear in the discovery document and the issued JWT tokens.\n    It is recommended to not set this property, which infers the issuer name from the host name that is used by the clients.\n\n* ``LowerCaseIssuerUri``\n    Set to ``false`` to preserve the original casing of the IssuerUri. Defaults to ``true``.\n\n* ``AccessTokenJwtType``\n    Specifies the value used for the JWT typ header for access tokens (defaults to ``at+jwt``).\n\n* ``EmitScopesAsSpaceDelimitedStringInJwt``\n    Specifies whether scopes in JWTs are emitted as array or string\n\n* ``EmitStaticAudienceClaim``\n    Emits an ``aud`` claim with the format issuer/resources. Defaults to false.\n\nEndpoints\n^^^^^^^^^\nAllows enabling/disabling individual endpoints, e.g. token, authorize, userinfo etc.\n\nBy default all endpoints are enabled, but you can lock down your server by disabling endpoint that you don't need.\n\n* ``EnableJwtRequestUri``\n    JWT request_uri processing is enabled on the authorize endpoint. Defaults to ``false``.\n\nDiscovery\n^^^^^^^^^\nAllows enabling/disabling various sections of the discovery document, e.g. endpoints, scopes, claims, grant types etc.\n\nThe ``CustomEntries`` dictionary allows adding custom elements to the discovery document.\n\nAuthentication\n^^^^^^^^^^^^^^\n* ``CookieAuthenticationScheme``\n    Sets the cookie authentication scheme configured by the host used for interactive users. If not set, the scheme will be inferred from the host's default authentication scheme. This setting is typically used when AddPolicyScheme is used in the host as the default scheme.\n\n* ``CookieLifetime``\n    The authentication cookie lifetime (only effective if the IdentityServer-provided cookie handler is used).\n\n* ``CookieSlidingExpiration``\n    Specifies if the cookie should be sliding or not (only effective if the IdentityServer-provided cookie handler is used).\n\n* ``CookieSameSiteMode``\n    Specifies the SameSite mode for the internal cookies.\n\n* ``RequireAuthenticatedUserForSignOutMessage``\n    Indicates if user must be authenticated to accept parameters to end session endpoint. Defaults to false.\n\n* ``CheckSessionCookieName``\n    The name of the cookie used for the check session endpoint.\n\n* ``CheckSessionCookieDomain``\n    The domain of the cookie used for the check session endpoint.\n\n* ``CheckSessionCookieSameSiteMode``\n    The SameSite mode of the cookie used for the check session endpoint.\n\n* ``RequireCspFrameSrcForSignout``\n    If set, will require frame-src CSP headers being emitting on the end session callback endpoint which renders iframes to clients for front-channel signout notification. Defaults to true.\n\nEvents\n^^^^^^\nAllows configuring if and which events should be submitted to a registered event sink. See :ref:`here <refEvents>` for more information on events.\n\nInputLengthRestrictions\n^^^^^^^^^^^^^^^^^^^^^^^\nAllows setting length restrictions on various protocol parameters like client id, scope, redirect URI etc.\n\nUserInteraction\n^^^^^^^^^^^^^^^\n\n* ``LoginUrl``, ``LogoutUrl``, ``ConsentUrl``, ``ErrorUrl``, ``DeviceVerificationUrl``\n    Sets the URLs for the login, logout, consent, error and device verification pages.\n* ``LoginReturnUrlParameter``\n    Sets the name of the return URL parameter passed to the login page. Defaults to *returnUrl*.\n* ``LogoutIdParameter``\n    Sets the name of the logout message id parameter passed to the logout page. Defaults to *logoutId*.\n* ``ConsentReturnUrlParameter``\n    Sets the name of the return URL parameter passed to the consent page. Defaults to *returnUrl*.\n* ``ErrorIdParameter``\n    Sets the name of the error message id parameter passed to the error page. Defaults to *errorId*.\n* ``CustomRedirectReturnUrlParameter``\n    Sets the name of the return URL parameter passed to a custom redirect from the authorization endpoint. Defaults to *returnUrl*.\n* ``DeviceVerificationUserCodeParameter``\n    Sets the name of the user code parameter passed to the device verification page. Defaults to *userCode*.\n* ``CookieMessageThreshold``\n    Certain interactions between IdentityServer and some UI pages require a cookie to pass state and context (any of the pages above that have a configurable \"message id\" parameter).\n    Since browsers have limits on the number of cookies and their size, this setting is used to prevent too many cookies being created. \n    The value sets the maximum number of message cookies of any type that will be created.\n    The oldest message cookies will be purged once the limit has been reached.\n    This effectively indicates how many tabs can be opened by a user when using IdentityServer.\n\nCaching\n^^^^^^^\nThese settings only apply if the respective caching has been enabled in the services configuration in startup.\n\n* ``ClientStoreExpiration``\n    Cache duration of client configuration loaded from the client store.\n\n* ``ResourceStoreExpiration``\n    Cache duration of identity and API resource configuration loaded from the resource store.\n\nCORS\n^^^^\nIdentityServer supports CORS for some of its endpoints.\nThe underlying CORS implementation is provided from ASP.NET Core, and as such it is automatically registered in the dependency injection system.\n\n* ``CorsPolicyName``\n    Name of the CORS policy that will be evaluated for CORS requests into IdentityServer (defaults to ``\"IdentityServer8\"``).\n    The policy provider that handles this is implemented in terms of the ``ICorsPolicyService`` registered in the dependency injection system.\n    If you wish to customize the set of CORS origins allowed to connect, then it is recommended that you provide a custom implementation of ``ICorsPolicyService``.\n\n* ``CorsPaths``\n    The endpoints within IdentityServer where CORS is supported. \n    Defaults to the discovery, user info, token, and revocation endpoints.\n\n* ``PreflightCacheDuration``\n    `Nullable<TimeSpan>` indicating the value to be used in the preflight `Access-Control-Max-Age` response header.\n    Defaults to `null` indicating no caching header is set on the response.\n\nCSP (Content Security Policy)\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nIdentityServer emits CSP headers for some responses, where appropriate.\n\n* ``Level``\n    The level of CSP to use. CSP Level 2 is used by default, but if older browsers must be supported then this be changed to ``CspLevel.One`` to accommodate them.\n\n* ``AddDeprecatedHeader``\n    Indicates if the older ``X-Content-Security-Policy`` CSP header should also be emitted (in addition to the standards-based header value). Defaults to true.\n\nDevice Flow\n^^^^^^^^^^^\n\n* ``DefaultUserCodeType``\n    The user code type to use, unless set at the client level. Defaults to *Numeric*, a 9-digit code.\n* ``Interval``\n    Defines the minimum allowed polling interval on the token endpoint. Defaults to *5*.\n\nMutual TLS\n^^^^^^^^^^\n\n* ``Enabled``\n    Specifies if MTLS support should be enabled. Defaults to ``false``.\n* ``ClientCertificateAuthenticationScheme``\n    Specifies the name of the authentication handler for X.509 client certificates. Defaults to ``\"Certificate\"``.\n* ``DomainName``\n    Specifies either the name of the sub-domain or full domain for running the MTLS endpoints (will use path-based endpoints if not set).\n    Use a simple string (e.g. \"mtls\") to set a sub-domain, use a full domain name (e.g. \"identityserver-mtls.io\") to set a full domain name.\n    When a full domain name is used, you also need to set the ``IssuerName`` to a fixed value.\n* ``AlwaysEmitConfirmationClaim``\n    Specifies whether a cnf claim gets emitted for access tokens if a client certificate was present.\n    Normally the cnf claims only gets emitted if the client used the client certificate for authentication,\n    setting this to true, will set the claim regardless of the authentication method. (defaults to false).\n"
  },
  {
    "path": "docs/reference/profileservice.rst",
    "content": ".. _refProfileService:\nProfile Service\n===============\n\nOften IdentityServer requires identity information about users when creating tokens or when handling requests to the userinfo or introspection endpoints.\nBy default, IdentityServer only has the claims in the authentication cookie to draw upon for this identity data.\n\nIt is impractical to put all of the possible claims needed for users into the cookie, so IdentityServer defines an extensibility point for allowing claims to be dynamically loaded as needed for a user.\nThis extensibility point is the ``IProfileService`` and it is common for a developer to implement this interface to access a custom database or API that contains the identity data for users.\n\nIProfileService APIs\n^^^^^^^^^^^^^^^^^^^^\n\n``GetProfileDataAsync``\n    The API that is expected to load claims for a user. It is passed an instance of ``ProfileDataRequestContext``.\n\n``IsActiveAsync``\n    The API that is expected to indicate if a user is currently allowed to obtain tokens. It is passed an instance of ``IsActiveContext``.\n\nProfileDataRequestContext\n^^^^^^^^^^^^^^^^^^^^^^^^^\n\nModels the request for user claims and is the vehicle to return those claims. It contains these properties:\n\n``Subject``\n    The ``ClaimsPrincipal`` modeling the user.\n``Client``\n    The ``Client`` for which the claims are being requested.\n``RequestedClaimTypes``\n    The collection of claim types being requested.\n``Caller``\n    An identifier for the context in which the claims are being requested (e.g. an identity token, an access token, or the user info endpoint). The constant ``IdentityServerConstants.ProfileDataCallers`` contains the different constant values.\n``IssuedClaims``\n    The list of ``Claim`` s that will be returned. This is expected to be populated by the custom ``IProfileService`` implementation.\n``AddRequestedClaims``\n    Extension method on the ``ProfileDataRequestContext`` to populate the ``IssuedClaims``, but first filters the claims based on ``RequestedClaimTypes``.\n\nRequested scopes and claims mapping\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nThe scopes requested by the client control what user claims are returned in the tokens to the client. \nThe ``GetProfileDataAsync`` method is responsible for dynamically obtaining those claims based on the ``RequestedClaimTypes`` collection on the ``ProfileDataRequestContext``.\n\nThe ``RequestedClaimTypes`` collection is populated based on the user claims defined on the :ref:`resources <refResources>` that model the scopes.\nIf requesting an identity token and the scopes requested are an :ref:`identity resources <refIdentityResource>`, then the claims in the ``RequestedClaimTypes`` will be populated based on the user claim types defined in the ``IdentityResource``.\nIf requesting an access token and the scopes requested are an :ref:`API resources <refApiResource>`, then the claims in the ``RequestedClaimTypes`` will be populated based on the user claim types defined in the ``ApiResource`` and/or the ``Scope``.\n\nIsActiveContext\n^^^^^^^^^^^^^^^\n\nModels the request to determine if the user is currently allowed to obtain tokens. It contains these properties:\n\n``Subject``\n    The ``ClaimsPrincipal`` modeling the user.\n``Client``\n    The ``Client`` for which the claims are being requested.\n``Caller``\n    An identifier for the context in which the claims are being requested (e.g. an identity token, an access token, or the user info endpoint). The constant ``IdentityServerConstants.ProfileDataCallers`` contains the different constant values.\n``IsActive``\n    The flag indicating if the user is allowed to obtain tokens. This is expected to be assigned by the custom ``IProfileService`` implementation.\n"
  },
  {
    "path": "docs/requirements.txt",
    "content": "sphinx==7.1.2\nsphinx-rtd-theme==1.3.0rc1"
  },
  {
    "path": "docs/topics/add_apis.rst",
    "content": "Adding more API Endpoints\n=========================\nIt's a common scenario to add additional API endpoints to the application hosting IdentityServer.\nThese endpoints are typically protected by IdentityServer itself.\n\nFor simple scenarios, we give you some helpers. See the advanced section to understand more of the internal plumbing.\n\n.. note:: You could achieve the same by using either our ``IdentityServerAuthentication`` handler or Microsoft's ``JwtBearer`` handler. But this is not recommended since it requires more configuration and creates dependencies on external libraries that might lead to conflicts in future updates.\n\nStart by registering your API as an ``ApiResource``, e.g.::\n\n    public static IEnumerable<ApiResource> Apis = new List<ApiResource>\n    {\n        // local API\n        new ApiResource(IdentityServerConstants.LocalApi.ScopeName),\n    };\n\n..and give your clients access to this API, e.g.::\n\n    new Client\n    {\n        // rest omitted\n        AllowedScopes = { IdentityServerConstants.LocalApi.ScopeName },   \n    }\n\n.. note:: The value of ``IdentityServerConstants.LocalApi.ScopeName`` is ``IdentityServerApi``.\n\nTo enable token validation for local APIs, add the following to your IdentityServer startup::\n\n    services.AddLocalApiAuthentication();\n\nTo protect an API controller, decorate it with an ``Authorize`` attribute using the ``LocalApi.PolicyName`` policy::\n\n    [Route(\"localApi\")]\n    [Authorize(LocalApi.PolicyName)]\n    public class LocalApiController : ControllerBase\n    {\n        public IActionResult Get()\n        {\n            // omitted\n        }\n    }\n\nAuthorized clients can then request a token for the ``IdentityServerApi`` scope and use it to call the API.\n\nDiscovery\n^^^^^^^^^\nYou can also add your endpoints to the discovery document if you want, e.g like this::\n\n    services.AddIdentityServer(options =>\n    {\n        options.Discovery.CustomEntries.Add(\"local_api\", \"~/localapi\");\n    })\n\nAdvanced\n^^^^^^^^\nUnder the covers, the ``AddLocalApiAuthentication`` helper does a couple of things:\n\n* adds an authentication handler that validates incoming tokens using IdentityServer's built-in token validation engine (the name of this handler is ``IdentityServerAccessToken`` or ``IdentityServerConstants.LocalApi.AuthenticationScheme``\n* configures the authentication handler to require a scope claim inside the access token of value ``IdentityServerApi``\n* sets up an authorization policy that checks for a scope claim of value ``IdentityServerApi``\n\nThis covers the most common scenarios. You can customize this behavior in the following ways:\n\n* Add the authentication handler yourself by calling ``services.AddAuthentication().AddLocalApi(...)``\n    * this way you can specify the required scope name yourself, or (by specifying no scope at all) accept any token from the current IdentityServer instance\n* Do your own scope validation/authorization in your controllers using custom policies or code, e.g.::\n\n    services.AddAuthorization(options =>\n    {\n        options.AddPolicy(IdentityServerConstants.LocalApi.PolicyName, policy =>\n        {\n            policy.AddAuthenticationSchemes(IdentityServerConstants.LocalApi.AuthenticationScheme);\n            policy.RequireAuthenticatedUser();\n            // custom requirements\n        });\n    });\n\nClaims Transformation\n^^^^^^^^^^^^^^^^^^^^^\nYou can provide a callback to transform the claims of the incoming token after validation.\nEither use the helper method, e.g.::\n\n    services.AddLocalApiAuthentication(principal =>\n    {\n        principal.Identities.First().AddClaim(new Claim(\"additional_claim\", \"additional_value\"));\n\n        return Task.FromResult(principal);\n    });\n    \n...or implement the event on the options if you add the authentication handler manually.\n"
  },
  {
    "path": "docs/topics/add_protocols.rst",
    "content": "Adding new Protocols\n====================\n\nIdentityServer8 allows adding support for other protocols besides the built-in \nsupport for OpenID Connect and OAuth 2.0.\n\nYou can add those additional protocol endpoints either as middleware or using e.g. MVC controllers.\nIn both cases you have access to the ASP.NET Core DI system which allows re-using our\ninternal services like access to client definitions or key material.\n\nA sample for adding WS-Federation support can be found `here <https://github.com/alexhiggins732/IdentityServer8.WsFederation>`_.\n\nTypical authentication workflow\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nAn authentication request typically works like this:\n\n* authentication request arrives at protocol endpoint\n* protocol endpoint does input validation\n* redirection to login page with a return URL set back to protocol endpoint (if user is anonymous)\n    * access to current request details via the ``IIdentityServerInteractionService``\n    * authentication of user (either locally or via external authentication middleware)\n    * signing in the user\n    * redirect back to protocol endpoint\n* creation of protocol response (token creation and redirect back to client)\n\nUseful IdentityServer services\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nTo achieve the above workflow, some interaction points with IdentityServer are needed.\n\n**Access to configuration and redirecting to the login page**\n\nYou can get access to the IdentityServer configuration by injecting the ``IdentityServerOptions``\nclass into your code. This, e.g. has the configured path to the login page::\n\n    var returnUrl = Url.Action(\"Index\");\n    returnUrl = returnUrl.AddQueryString(Request.QueryString.Value);\n\n    var loginUrl = _options.UserInteraction.LoginUrl;\n    var url = loginUrl.AddQueryString(_options.UserInteraction.LoginReturnUrlParameter, returnUrl);\n\n    return Redirect(url);\n\n**Interaction between the login page and current protocol request**\n\nThe ``IIdentityServerInteractionService`` supports turning a protocol return URL into a \nparsed and validated context object::\n\n    var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n\nBy default the interaction service only understands OpenID Connect protocol messages.\nTo extend support, you can write your own ``IReturnUrlParser``::\n\n    public interface IReturnUrlParser\n    {\n        bool IsValidReturnUrl(string returnUrl);\n        Task<AuthorizationRequest> ParseAsync(string returnUrl);\n    }\n\n..and then register the parser in DI::\n\n    builder.Services.AddTransient<IReturnUrlParser, WsFederationReturnUrlParser>();\n\nThis allows the login page to get to information like the client configuration and other \nprotocol parameters.\n\n**Access to configuration and key material for creating the protocol response**\n\nBy injecting the ``IKeyMaterialService`` into your code, you get access to the configured \nsigning credential and validation keys::\n\n    var credential = await _keys.GetSigningCredentialsAsync();\n    var key = credential.Key as Microsoft.IdentityModel.Tokens.X509SecurityKey; \n        \n    var descriptor = new SecurityTokenDescriptor\n    {\n        AppliesToAddress = result.Client.ClientId,\n        Lifetime = new Lifetime(DateTime.UtcNow, DateTime.UtcNow.AddSeconds(result.Client.IdentityTokenLifetime)),\n        ReplyToAddress = result.Client.RedirectUris.First(),\n        SigningCredentials = new X509SigningCredentials(key.Certificate, result.RelyingParty.SignatureAlgorithm, result.RelyingParty.DigestAlgorithm),\n        Subject = outgoingSubject,\n        TokenIssuerName = _contextAccessor.HttpContext.GetIdentityServerIssuerUri(),\n        TokenType = result.RelyingParty.TokenType\n    };"
  },
  {
    "path": "docs/topics/apis.rst",
    "content": ".. _refProtectingApis:\nProtecting APIs\n===============\nIdentityServer issues access tokens in the `JWT <https://tools.ietf.org/html/rfc7519>`_ (JSON Web Token) format by default.\n\nEvery relevant platform today has support for validating JWT tokens, a good list of JWT libraries can be found `here <https://jwt.io>`_.\nPopular libraries are e.g.:\n\n* `JWT bearer authentication handler <https://www.nuget.org/packages/Microsoft.AspNetCore.Authentication.JwtBearer/>`_ for ASP.NET Core\n* `JWT bearer authentication middleware <https://www.nuget.org/packages/Microsoft.Owin.Security.Jwt>`_ for Katana\n\nProtecting an ASP.NET Core-based API is only a matter of adding the JWT bearer authentication handler::\n\n    public class Startup\n    {\n        public void ConfigureServices(IServiceCollection services)\n        {\n            services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)\n                .AddJwtBearer(options =>\n                {\n                    // base-address of your identityserver\n                    options.Authority = \"https://demo.identityserver8.io\";\n\n                    // if you are using API resources, you can specify the name here\n                    options.Audience = \"resource1\";\n\n                    // IdentityServer emits a typ header by default, recommended extra check\n                    options.TokenValidationParameters.ValidTypes = new[] { \"at+jwt\" };\n                });\n        }\n    }\n\n.. note:: If you are not using the audience claim, you can turn off the audience check via ``options.TokenValidationParameters.ValidateAudience = false;``. See :ref:`here <refApiResources>` for more information on resources, scopes, audiences and authorization.\n\nValidating reference tokens\n^^^^^^^^^^^^^^^^^^^^^^^^^^^\nIf you are using reference tokens, you need an authentication handler that implements `OAuth 2.0 token introspection <https://tools.ietf.org/html/rfc7662>`_, \ne.g. `this one <https://github.com/IdentityModel/IdentityModel.AspNetCore.OAuth2Introspection>`_:: \n\n    services.AddAuthentication(\"token\")\n        .AddOAuth2Introspection(\"token\", options =>\n        {\n            options.Authority = Constants.Authority;\n\n            // this maps to the API resource name and secret\n            options.ClientId = \"resource1\";\n            options.ClientSecret = \"secret\";\n        });\n\nSupporting both JWTs and reference tokens\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nYou can setup ASP.NET Core to dispatch to the right handler based on the incoming token, see `this <https://leastprivilege.com/2020/07/06/flexible-access-token-validation-in-asp-net-core/>`_ blog post for more information.\nIn this case you setup one default handler, and some forwarding logic, e.g.::\n\n    services.AddAuthentication(\"token\")\n\n        // JWT tokens\n        .AddJwtBearer(\"token\", options =>\n        {\n            options.Authority = Constants.Authority;\n            options.Audience = \"resource1\";\n\n            options.TokenValidationParameters.ValidTypes = new[] { \"at+jwt\" };\n\n            // if token does not contain a dot, it is a reference token\n            options.ForwardDefaultSelector = Selector.ForwardReferenceToken(\"introspection\");\n        })\n\n        // reference tokens\n        .AddOAuth2Introspection(\"introspection\", options =>\n        {\n            options.Authority = Constants.Authority;\n\n            options.ClientId = \"resource1\";\n            options.ClientSecret = \"secret\";\n        });"
  },
  {
    "path": "docs/topics/client_authentication.rst",
    "content": "Client Authentication\n=====================\nIn certain situations, clients need to authenticate with IdentityServer, e.g.\n\n* confidential applications (aka clients) requesting tokens at the token endpoint\n* APIs validating reference tokens at the introspection endpoint\n\nFor that purpose you can assign a list of secrets to a client or an API resource.\n\nSecret parsing and validation is an extensibility point in identityserver, out of the box it supports shared secrets\nas well as transmitting the shared secret via a basic authentication header or the POST body.\n\nCreating a shared secret\n^^^^^^^^^^^^^^^^^^^^^^^^\nThe following code sets up a hashed shared secret::\n\n    var secret = new Secret(\"secret\".Sha256());\n\nThis secret can now be assigned to either a ``Client`` or an ``ApiResource``. \nNotice that both do not only support a single secret, but multiple. This is useful for secret rollover and rotation::\n\n    var client = new Client\n    {\n        ClientId = \"client\",\n        ClientSecrets = new List<Secret> { secret },\n\n        AllowedGrantTypes = GrantTypes.ClientCredentials,\n        AllowedScopes = \n        {\n            \"api1\", \"api2\"\n        }\n    };\n\nIn fact you can also assign a description and an expiration date to a secret. The description will be used for logging, and \nthe expiration date for enforcing a secret lifetime::\n\n    var secret = new Secret(\n        \"secret\".Sha256(), \n        \"2016 secret\", \n        new DateTime(2016, 12, 31));  \n\nAuthentication using a shared secret\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nYou can either send the client id/secret combination as part of the POST body::\n\n    POST /connect/token\n    \n    client_id=client1&\n    client_secret=secret&\n    ...\n\n..or as a basic authentication header::\n\n    POST /connect/token\n    \n    Authorization: Basic xxxxx\n\n    ...\n\nYou can manually create a basic authentication header using the following C# code::\n\n    var credentials = string.Format(\"{0}:{1}\", clientId, clientSecret);\n    var headerValue = Convert.ToBase64String(Encoding.UTF8.GetBytes(credentials));\n\n    var client = new HttpClient();\n    client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue(\"Basic\", headerValue);\n\nThe `IdentityModel <https://github.com/IdentityModel/IdentityModel>`_ library has helper classes called ``TokenClient`` and ``IntrospectionClient`` that encapsulate\nboth authentication and protocol messages.\n\nAuthentication using an asymmetric Key\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThere are other techniques to authenticate clients, e.g. based on public/private key cryptography.\nIdentityServer includes support for private key JWT client secrets (see `RFC 7523 <https://tools.ietf.org/html/rfc7523>`_\nand `here <https://openid.net/specs/openid-connect-core-1_0.html#ClientAuthentication>`_).\n\nSecret extensibility typically consists of three things:\n\n* a secret definition\n* a secret parser that knows how to extract the secret from the incoming request\n* a secret validator that knows how to validate the parsed secret based on the definition\n\nSecret parsers and validators are implementations of the ``ISecretParser`` and ``ISecretValidator`` interfaces. \nTo make them available to IdentityServer, you need to register them with the DI container, e.g.::\n\n    builder.AddSecretParser<JwtBearerClientAssertionSecretParser>()\n    builder.AddSecretValidator<PrivateKeyJwtSecretValidator>()\n\nOur default private key JWT secret validator expects the full (leaf) certificate as base64 on the secret definition \nor an ESA/EC JSON web key::\n\n    var client = new Client\n    {\n        ClientId = \"client.jwt\",\n        ClientSecrets =\n        {\n            new Secret\n            {\n                Type = IdentityServerConstants.SecretTypes.X509CertificateBase64,\n                Value = \"MIIDATCCAe2gAwIBAgIQoHUYAquk9rBJcq8W+F0FAzAJBgUrDgMCHQUAMBIxEDAOBgNVBAMTB0RldlJvb3QwHhcNMTAwMTIwMjMwMDAwWhcNMjAwMTIwMjMwMDAwWjARMQ8wDQYDVQQDEwZDbGllbnQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDSaY4x1eXqjHF1iXQcF3pbFrIbmNw19w/IdOQxbavmuPbhY7jX0IORu/GQiHjmhqWt8F4G7KGLhXLC1j7rXdDmxXRyVJBZBTEaSYukuX7zGeUXscdpgODLQVay/0hUGz54aDZPAhtBHaYbog+yH10sCXgV1Mxtzx3dGelA6pPwiAmXwFxjJ1HGsS/hdbt+vgXhdlzud3ZSfyI/TJAnFeKxsmbJUyqMfoBl1zFKG4MOvgHhBjekp+r8gYNGknMYu9JDFr1ue0wylaw9UwG8ZXAkYmYbn2wN/CpJl3gJgX42/9g87uLvtVAmz5L+rZQTlS1ibv54ScR2lcRpGQiQav/LAgMBAAGjXDBaMBMGA1UdJQQMMAoGCCsGAQUFBwMCMEMGA1UdAQQ8MDqAENIWANpX5DZ3bX3WvoDfy0GhFDASMRAwDgYDVQQDEwdEZXZSb290ghAsWTt7E82DjU1E1p427Qj2MAkGBSsOAwIdBQADggEBADLje0qbqGVPaZHINLn+WSM2czZk0b5NG80btp7arjgDYoWBIe2TSOkkApTRhLPfmZTsaiI3Ro/64q+Dk3z3Kt7w+grHqu5nYhsn7xQFAQUf3y2KcJnRdIEk0jrLM4vgIzYdXsoC6YO+9QnlkNqcN36Y8IpSVSTda6gRKvGXiAhu42e2Qey/WNMFOL+YzMXGt/nDHL/qRKsuXBOarIb++43DV3YnxGTx22llhOnPpuZ9/gnNY7KLjODaiEciKhaKqt/b57mTEz4jTF4kIg6BP03MUfDXeVlM1Qf1jB43G2QQ19n5lUiqTpmQkcfLfyci2uBZ8BkOhXr3Vk9HIk/xBXQ=\"\n            }\n            new Secret\n            {\n                Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                Value = \"{'e':'AQAB','kid':'ZzAjSnraU3bkWGnnAqLapYGpTyNfLbjbzgAPbbW2GEA','kty':'RSA','n':'wWwQFtSzeRjjerpEM5Rmqz_DsNaZ9S1Bw6UbZkDLowuuTCjBWUax0vBMMxdy6XjEEK4Oq9lKMvx9JzjmeJf1knoqSNrox3Ka0rnxXpNAz6sATvme8p9mTXyp0cX4lF4U2J54xa2_S9NF5QWvpXvBeC4GAJx7QaSw4zrUkrc6XyaAiFnLhQEwKJCwUw4NOqIuYvYp_IXhw-5Ti_icDlZS-282PcccnBeOcX7vc21pozibIdmZJKqXNsL1Ibx5Nkx1F1jLnekJAmdaACDjYRLL_6n3W4wUp19UvzB1lGtXcJKLLkqB6YDiZNu16OSiSprfmrRXvYmvD8m6Fnl5aetgKw'}\"\n            }\n        },\n\n        AllowedGrantTypes = GrantTypes.ClientCredentials,\n        AllowedScopes = { \"api1\", \"api2\" }\n    };\n"
  },
  {
    "path": "docs/topics/clients.rst",
    "content": "Defining Clients\n================\nClients represent applications that can request tokens from your identityserver.\n\nThe details vary, but you typically define the following common settings for a client:\n\n* a unique client ID\n* a secret if needed\n* the allowed interactions with the token service (called a grant type)\n* a network location where identity and/or access token gets sent to (called a redirect URI)\n* a list of scopes (aka resources) the client is allowed to access\n\n.. Note:: At runtime, clients are retrieved via an implementation of the ``IClientStore``. This allows loading them from arbitrary data sources like config files or databases. For this document we will use the in-memory version of the client store. You can wire up the in-memory store in ``ConfigureServices`` via the ``AddInMemoryClients`` extensions method.\n\nDefining a client for server to server communication\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nIn this scenario no interactive user is present - a service (aka client) wants to communicate with an API (aka scope)::\n\n    public class Clients\n    {\n        public static IEnumerable<Client> Get()\n        {\n            return new List<Client>\n            {\n                new Client\n                {\n                    ClientId = \"service.client\",                    \n                    ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                    AllowedGrantTypes = GrantTypes.ClientCredentials,\n                    AllowedScopes = { \"api1\", \"api2.read_only\" }\n                }\n            };\n        }\n    }\n\n.. _startClientsMVC:\nDefining an interactive application for use authentication and delegated API access\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nInteractive applications (e.g. web applications or native desktop/mobile) applications use the authorization code flow.\nThis flow gives you the best security because the access tokens are transmitted via back-channel calls only (and gives you access to refresh tokens)::\n\n    var interactiveClient = new Client\n    {\n        ClientId = \"interactive\",\n\n        AllowedGrantTypes = GrantTypes.Code,\n        AllowOfflineAccess = true,\n        ClientSecrets = { new Secret(\"secret\".Sha256()) },\n        \n        RedirectUris =           { \"http://localhost:21402/signin-oidc\" },\n        PostLogoutRedirectUris = { \"http://localhost:21402/\" },\n        FrontChannelLogoutUri =    \"http://localhost:21402/signout-oidc\",\n\n        AllowedScopes = \n        {\n            IdentityServerConstants.StandardScopes.OpenId,\n            IdentityServerConstants.StandardScopes.Profile,\n            IdentityServerConstants.StandardScopes.Email,\n\n            \"api1\", \"api2.read_only\"\n        },\n    };\n\n.. Note:: see the :ref:`grant types <refGrantTypes>` topic for more information on choosing the right grant type for your client.\n\nDefining clients in appsettings.json\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nThe ``AddInMemoryClients`` extensions method also supports adding clients from the ASP.NET Core configuration file. This allows you to define static clients directly from the appsettings.json file::\n\n    \"IdentityServer\": {\n      \"IssuerUri\": \"urn:sso.company.com\",\n      \"Clients\": [\n        {\n          \"Enabled\": true,\n          \"ClientId\": \"local-dev\",\n          \"ClientName\": \"Local Development\",\n          \"ClientSecrets\": [ { \"Value\": \"<Insert Sha256 hash of the secret encoded as Base64 string>\" } ],\n          \"AllowedGrantTypes\": [ \"client_credentials\" ],\n          \"AllowedScopes\": [ \"api1\" ],\n        }\n      ]\n    }\n    \nThen pass the configuration section to the ``AddInMemoryClients`` method::\n\n    AddInMemoryClients(configuration.GetSection(\"IdentityServer:Clients\"))\n"
  },
  {
    "path": "docs/topics/consent.rst",
    "content": ".. _refConsent:\nConsent\n=======\n\nDuring an authorization request, if IdentityServer requires user consent the browser will be redirected to the consent page.\n\nConsent is used to allow an end user to grant a client access to resources (:ref:`identity <refIdentityResource>` or :ref:`API <refApiResource>`).\nThis is typically only necessary for third-party clients, and can be enabled/disabled per-client on the :ref:`client settings <refClient>`.\n\nConsent Page\n^^^^^^^^^^^^\nIn order for the user to grant consent, a consent page must be provided by the hosting application.\nThe `quickstart UI <https://github.com/alexhiggins732/IdentityServer8.Quickstart.UI>`_ has a basic implementation of a consent page.\n\nA consent page normally renders the display name of the current user, \nthe display name of the client requesting access, \nthe logo of the client, \na link for more information about the client, \nand the list of resources the client is requesting access to.\nIt's also common to allow the user to indicate that their consent should be \"remembered\" so they are not prompted again in the future for the same client.\n\nOnce the user has provided consent, the consent page must inform IdentityServer of the consent, and then the browser must be redirected back to the authorization endpoint. \n\nAuthorization Context\n^^^^^^^^^^^^^^^^^^^^^\n\nIdentityServer will pass a `returnUrl` parameter (configurable on the :ref:`user interaction options <refOptions>`) to the consent page which contains the parameters of the authorization request.\nThese parameters provide the context for the consent page, and can be read with help from the :ref:`interaction service <refInteractionService>`.\nThe ``GetAuthorizationContextAsync`` API will return an instance of ``AuthorizationRequest``.\n\nAdditional details about the client or resources can be obtained using the ``IClientStore`` and ``IResourceStore`` interfaces. \n\nInforming IdentityServer of the consent result\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nThe ``GrantConsentAsync`` API on the :ref:`interaction service <refInteractionService>` allows the consent page to inform IdentityServer of the outcome of consent (which might also be to deny the client access).\n\nIdentityServer will temporarily persist the outcome of the consent.\nThis persistence uses a cookie by default, as it only needs to last long enough to convey the outcome back to the authorization endpoint.\nThis temporary persistence is different than the persistence used for the \"remember my consent\" feature (and it is the authorization endpoint which persists the \"remember my consent\" for the user).\nIf you wish to use some other persistence between the consent page and the authorization redirect, then you can implement ``IMessageStore<ConsentResponse>`` and register the implementation in DI.\n\nReturning the user to the authorization endpoint\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nOnce the consent page has informed IdentityServer of the outcome, the user can be redirected back to the `returnUrl`. \nYour consent page should protect against open redirects by verifying that the `returnUrl` is valid.\nThis can be done by calling ``IsValidReturnUrl`` on the :ref:`interaction service <refInteractionService>`.\nAlso, if ``GetAuthorizationContextAsync`` returns a non-null result, then you can also trust that the `returnUrl` is valid.\n\n\n\n"
  },
  {
    "path": "docs/topics/cors.rst",
    "content": ".. _refCors:\nCORS\n====\n\nMany endpoints in IdentityServer will be accessed via Ajax calls from JavaScript-based clients.\nGiven that IdentityServer will most likely be hosted on a different origin than these clients, this implies that `Cross-Origin Resource Sharing <http://www.html5rocks.com/en/tutorials/cors/>`_ (CORS) will need to be configured.\n\nClient-based CORS Configuration\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nOne approach to configuring CORS is to use the ``AllowedCorsOrigins`` collection on the :ref:`client configuration <refClient>`.\nSimply add the origin of the client to the collection and the default configuration in IdentityServer will consult these values to allow cross-origin calls from the origins.\n\n.. Note:: Be sure to use an origin (not a URL) when configuring CORS. For example: ``https://foo:123/`` is a URL, whereas ``https://foo:123`` is an origin.\n\nThis default CORS implementation will be in use if you are using either the \"in-memory\" or EF-based client configuration that we provide.\nIf you define your own ``IClientStore``, then you will need to implement your own custom CORS policy service (see below).\n\nCustom Cors Policy Service\n^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nIdentityServer allows the hosting application to implement the ``ICorsPolicyService`` to completely control the CORS policy.\n\nThe single method to implement is: ``Task<bool> IsOriginAllowedAsync(string origin)``. \nReturn ``true`` if the `origin` is allowed, ``false`` otherwise.\n\nOnce implemented, simply register the implementation in DI and IdentityServer will then use your custom implementation.\n\n**DefaultCorsPolicyService**\n\nIf you simply wish to hard-code a set of allowed origins, then there is a pre-built ``ICorsPolicyService`` implementation you can use called ``DefaultCorsPolicyService``.\nThis would be configured as a singleton in DI, and hard-coded with its ``AllowedOrigins`` collection, or setting the flag ``AllowAll`` to ``true`` to allow all origins.\nFor example, in ``ConfigureServices``::\n\n    services.AddSingleton<ICorsPolicyService>((container) => {\n        var logger = container.GetRequiredService<ILogger<DefaultCorsPolicyService>>();\n        return new DefaultCorsPolicyService(logger) {\n            AllowedOrigins = { \"https://foo\", \"https://bar\" }\n        };\n    });\n\n.. Note:: Use ``AllowAll`` with caution.\n\n\nMixing IdentityServer's CORS policy with ASP.NET Core's CORS policies\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nIdentityServer uses the CORS middleware from ASP.NET Core to provide its CORS implementation.\nIt is possible that your application that hosts IdentityServer might also require CORS for its own custom endpoints.\nIn general, both should work together in the same application.\n\nYour code should use the documented CORS features from ASP.NET Core without regard to IdentityServer.\nThis means you should define policies and register the middleware as normal.\nIf your application defines policies in ``ConfigureServices``, then those should continue to work in the same places you are using them (either where you configure the CORS middleware or where you use the MVC ``EnableCors`` attributes in your controller code).\nIf instead you define an inline policy in the use of the CORS middleware (via the policy builder callback), then that too should continue to work normally.\n\nThe one scenario where there might be a conflict between your use of the ASP.NET Core CORS services and IdentityServer is if you decide to create a custom ``ICorsPolicyProvider``.\nGiven the design of the ASP.NET Core's CORS services and middleware, IdentityServer implements its own custom ``ICorsPolicyProvider`` and registers it in the DI system.\nFortunately, the IdentityServer implementation is designed to use the decorator pattern to wrap any existing  ``ICorsPolicyProvider`` that is already registered in DI.\nWhat this means is that you can also implement the ``ICorsPolicyProvider``, but it simply needs to be registered prior to IdentityServer in DI (e.g. in ``ConfigureServices``).\n"
  },
  {
    "path": "docs/topics/crypto.rst",
    "content": ".. _refCrypto:\nCryptography, Keys and HTTPS\n============================\n\nIdentityServer relies on a couple of crypto mechanisms to do its job.\n\nToken signing and validation\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nIdentityServer needs an asymmetric key pair to sign and validate JWTs. \nThis keymaterial can be either packaged as a certificate or just raw keys.\nBoth RSA and ECDSA keys are supported and the supported signing algorithms are: RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384 and ES512.\n\nYou can use multiple signing keys simultaneously, but only one signing key per algorithm is supported.\nThe first signing key you register is considered the default signing key.\n\nBoth :ref:`clients <refClient>` and :ref:`API resources <refApiResource>` can express preferences on the signing algorithm.\nIf you request a single token for multiple API resources, all resources need to agree on at least one allowed signing algorithm.\n\nLoading of signing key and the corresponding validation part is done by implementations of ``ISigningCredentialStore`` and ``IValidationKeysStore``.\nIf you want to customize the loading of the keys, you can implement those interfaces and register them with DI.\n\nThe DI builder extensions has a couple of convenience methods to set signing and validation keys - see :ref:`here <refStartupKeyMaterial>`.\n\nSigning key rollover\n^^^^^^^^^^^^^^^^^^^^\nWhile you can only use one signing key at a time, you can publish more than one validation key to the discovery document.\nThis is useful for key rollover.\n\nIn a nutshell, a rollover typically works like this:\n\n1. you request/create new key material\n2. you publish the new validation key in addition to the current one. You can use the ``AddValidationKey`` builder extension method for that.\n3. all clients and APIs now have a chance to learn about the new key the next time they update their local copy of the discovery document\n4. after a certain amount of time (e.g. 24h) all clients and APIs should now accept both the old and the new key material\n5. keep the old key material around for as long as you like, maybe you have long-lived tokens that need validation\n6. retire the old key material when it is not used anymore\n7. all clients and APIs will \"forget\" the old key next time they update their local copy of the discovery document\n\nThis requires that clients and APIs use the discovery document, and also have a feature to periodically refresh their configuration.\n\nBrock wrote a more detailed `blog post <https://brockallen.com/2019/08/09/identityserver-and-signing-key-rotation/>`_ about key rotation, and also\ncreated a `commercial component <https://www.identityserver8.com/products/keymanagement>`_, that can automatically take care of all those details.\n\nData protection\n^^^^^^^^^^^^^^^\nCookie authentication in ASP.NET Core (or anti-forgery in MVC) use the ASP.NET Core data protection feature.\nDepending on your deployment scenario, this might require additional configuration. See the Microsoft `docs <https://docs.microsoft.com/en-us/aspnet/core/security/data-protection/configuration/overview>`_ for more information.\n\nHTTPS\n^^^^^\nWe don't enforce the use of HTTPS, but for production it is mandatory for every interaction with IdentityServer.\n"
  },
  {
    "path": "docs/topics/custom_token_request_validation.rst",
    "content": ".. _refCustomTokenRequestValidation:\nCustom Token Request Validation and Issuance\n============================================\n\nYou can run custom code as part of the token issuance pipeline at the token endpoint.\nThis allows e.g. for\n\n* adding additional validation logic\n* changing certain parameters (e.g. token lifetime) dynamically\n\nFor this purpose, implement (and register) the ``ICustomTokenRequestValidator`` interface::\n\n    /// <summary>\n    /// Allows inserting custom validation logic into token requests\n    /// </summary>\n    public interface ICustomTokenRequestValidator\n    {\n        /// <summary>\n        /// Custom validation logic for a token request.\n        /// </summary>\n        /// <param name=\"context\">The context.</param>\n        /// <returns>\n        /// The validation result\n        /// </returns>\n        Task ValidateAsync(CustomTokenRequestValidationContext context);\n    }\n\nThe context object gives you access to:\n\n* adding custom response parameters\n* return an error and error description\n* modifying the request parameters, e.g. access token lifetime and type, client claims, and the confirmation method\n\nYou can register your implementation of the validator using the ``AddCustomTokenRequestValidator`` extension method on the configuration builder.\n"
  },
  {
    "path": "docs/topics/deployment.rst",
    "content": "Deployment\n==========\nYour identity server is `just` a standard ASP.NET Core application including the IdentityServer middleware.\nRead the official Microsoft `documentation <https://docs.microsoft.com/en-us/aspnet/core/publishing>`_ on publishing and deployment first\n(and especially the `section <https://docs.microsoft.com/en-us/aspnet/core/host-and-deploy/proxy-load-balancer?view=aspnetcore-2.2#scenarios-and-use-cases>`_ about load balancers and proxies).\n\nTypical architecture\n^^^^^^^^^^^^^^^^^^^^\nTypically you will design your IdentityServer deployment for high availability:\n\n.. image:: images/deployment.png\n\nIdentityServer itself is stateless and does not require server affinity - but there is data that needs to be shared between the instances.\n\nConfiguration data\n^^^^^^^^^^^^^^^^^^\nThis typically includes:\n\n* resources\n* clients\n* startup configuration, e.g. key material, external provider settings etc...\n\nThe way you store that data depends on your environment. In situations where configuration data rarely changes we recommend using the in-memory stores and code or configuration files.\n\nIn highly dynamic environments (e.g. Saas) we recommend using a database or configuration service to load configuration dynamically.\n\nIdentityServer supports code configuration and configuration files (see `here <https://docs.microsoft.com/en-us/aspnet/core/fundamentals/configuration>`_) out of the box.\nFor databases we provide support for `Entity Framework Core <https://github.com/alexhiggins732/IdentityServer8.EntityFramework>`_ based databases.\n\nYou can also build your own configuration stores by implementing ``IResourceStore`` and ``IClientStore``.\n\nKey material\n^^^^^^^^^^^^\n\nAnother important piece of startup configuration is your key material, see :ref:`here <refCrypto>` for more details on key material and cryptography.\n\nOperational data\n^^^^^^^^^^^^^^^^\nFor certain operations, IdentityServer needs a persistence store to keep state, this includes:\n\n* issuing authorization codes\n* issuing reference and refresh tokens\n* storing consent\n\nYou can either use a traditional database for storing operational data, or use a cache with persistence features like Redis.\nThe EF Core implementation mentioned above has also support for operational data.\n\nYou can also implement support for your own custom storage mechanism by implementing ``IPersistedGrantStore`` - by default IdentityServer injects an in-memory version.\n\nASP.NET Core data protection\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nASP.NET Core itself needs shared key material for protecting sensitive data like cookies, state strings etc.\nSee the official docs `here <https://docs.microsoft.com/en-us/aspnet/core/security/data-protection/>`_.\n\nYou can either re-use one of the above persistence store or use something simple like a shared file if possible.\n\nASP.NET Core distributed caching\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nSome components rely on ASP.NET Core distributed caching. In order to work in a multi server environment, this needs to be set up correctly. \nThe `official docs <https://docs.microsoft.com/en-us/aspnet/core/performance/caching/distributed/>`_ describe several options.\n\nThe following components rely on ``IDistributedCache``:\n\n* ``services.AddOidcStateDataFormatterCache()`` configures the OpenIdConnect handlers to persist the state parameter into the server-side ``IDistributedCache``.\n* ``DefaultReplayCache``\n* ``DistributedDeviceFlowThrottlingService``\n* ``DistributedCacheAuthorizationParametersMessageStore``\n"
  },
  {
    "path": "docs/topics/discovery.rst",
    "content": "Discovery\n=========\n\nThe discovery document can be found at *https://baseaddress/.well-known/openid-configuration*. \nIt contains information about the endpoints, key material and features of your IdentityServer.\n\nBy default all information is included in the discovery document, but by using configuration options, you can hide\nindividual sections, e.g.::\n\n    services.AddIdentityServer(options =>\n    {\n        options.Discovery.ShowIdentityScopes = false;\n        options.Discovery.ShowApiScopes = false;\n        options.Discovery.ShowClaims = false;\n        options.Discovery.ShowExtensionGrantTypes = false;\n    });\n\nExtending discovery\n^^^^^^^^^^^^^^^^^^^\nYou can add custom entries to the discovery document, e.g::\n\n    services.AddIdentityServer(options =>\n    {\n        options.Discovery.CustomEntries.Add(\"my_setting\", \"foo\");\n        options.Discovery.CustomEntries.Add(\"my_complex_setting\", \n            new\n            {\n                foo = \"foo\",\n                bar = \"bar\"\n            });\n    });\n\nWhen you add a custom value that starts with ~/ it will be expanded to an absolute path below the IdentityServer base address, e.g.::\n\n    options.Discovery.CustomEntries.Add(\"my_custom_endpoint\", \"~/custom\");\n\nIf you want to take full control over the rendering of the discovery (and jwks) document, you can implement the ``IDiscoveryResponseGenerator``\ninterface (or derive from our default implementation)."
  },
  {
    "path": "docs/topics/events.rst",
    "content": ".. _refEvents:\nEvents\n======\nWhile logging is more low level \"printf\" style - events represent higher level information about certain operations in IdentityServer.\nEvents are structured data and include event IDs, success/failure information, categories and details.\nThis makes it easy to query and analyze them and extract useful information that can be used for further processing.\n\nEvents work great with event stores like `ELK <https://www.elastic.co/webinars/introduction-elk-stack>`_, `Seq <https://getseq.net/>`_ or `Splunk <https://www.splunk.com/>`_.\n\nEmitting events\n^^^^^^^^^^^^^^^\nEvents are not turned on by default - but can be globally configured in the ``ConfigureServices`` method, e.g.::\n\n    services.AddIdentityServer(options =>\n    {\n        options.Events.RaiseSuccessEvents = true;\n        options.Events.RaiseFailureEvents = true;\n        options.Events.RaiseErrorEvents = true;\n    });\n\nTo emit an event use the ``IEventService`` from the DI container and call the ``RaiseAsync`` method, e.g.::\n\n    public async Task<IActionResult> Login(LoginInputModel model)\n    {\n        if (_users.ValidateCredentials(model.Username, model.Password))\n        {\n            // issue authentication cookie with subject ID and username\n            var user = _users.FindByUsername(model.Username);\n            await _events.RaiseAsync(new UserLoginSuccessEvent(user.Username, user.SubjectId, user.Username));\n        }\n        else\n        {\n            await _events.RaiseAsync(new UserLoginFailureEvent(model.Username, \"invalid credentials\"));\n        }\n    }\n\nCustom sinks\n^^^^^^^^^^^^\nOur default event sink will simply serialize the event class to JSON and forward it to the ASP.NET Core logging system.\nIf you want to connect to a custom event store, implement the ``IEventSink`` interface and register it with DI.\n\nThe following example uses `Seq <https://getseq.net/>`_ to emit events::\n\n     public class SeqEventSink : IEventSink\n    {\n        private readonly Logger _log;\n\n        public SeqEventSink()\n        {\n            _log = new LoggerConfiguration()\n                .WriteTo.Seq(\"http://localhost:5341\")\n                .CreateLogger();\n        }\n\n        public Task PersistAsync(Event evt)\n        {\n            if (evt.EventType == EventTypes.Success ||\n                evt.EventType == EventTypes.Information)\n            {\n                _log.Information(\"{Name} ({Id}), Details: {@details}\",\n                    evt.Name,\n                    evt.Id,\n                    evt);\n            }\n            else\n            {\n                _log.Error(\"{Name} ({Id}), Details: {@details}\",\n                    evt.Name,\n                    evt.Id,\n                    evt);\n            }\n\n            return Task.CompletedTask;\n        }\n    }\n\nAdd the ``Serilog.Sinks.Seq`` package to your host to make the above code work.\n\nBuilt-in events\n^^^^^^^^^^^^^^^\nThe following events are defined in IdentityServer:\n\n``ApiAuthenticationFailureEvent`` & ``ApiAuthenticationSuccessEvent``\n    Gets raised for successful/failed API authentication at the introspection endpoint.\n``ClientAuthenticationSuccessEvent`` & ``ClientAuthenticationFailureEvent``\n    Gets raised for successful/failed client authentication at the token endpoint.\n``TokenIssuedSuccessEvent`` & ``TokenIssuedFailureEvent``\n    Gets raised for successful/failed attempts to request identity tokens, access tokens, refresh tokens and authorization codes.\n``TokenIntrospectionSuccessEvent`` & ``TokenIntrospectionFailureEvent``\n    Gets raised for successful token introspection requests.\n``TokenRevokedSuccessEvent``\n    Gets raised for successful token revocation requests.\n``UserLoginSuccessEvent`` & ``UserLoginFailureEvent``\n    Gets raised by the quickstart UI for successful/failed user logins.\n``UserLogoutSuccessEvent``\n    Gets raised for successful logout requests.\n``ConsentGrantedEvent`` & ``ConsentDeniedEvent``\n    Gets raised in the consent UI.\n``UnhandledExceptionEvent``\n    Gets raised for unhandled exceptions.\n``DeviceAuthorizationFailureEvent`` & ``DeviceAuthorizationSuccessEvent``\n    Gets raised for successful/failed device authorization requests.\n\nCustom events\n^^^^^^^^^^^^^\nYou can create your own events and emit them via our infrastructure.\n\nYou need to derive from our base ``Event`` class which injects contextual information like activity ID, timestamp, etc.\nYour derived class can then add arbitrary data fields specific to the event context::\n\n    public class UserLoginFailureEvent : Event\n    {\n        public UserLoginFailureEvent(string username, string error)\n            : base(EventCategories.Authentication,\n                    \"User Login Failure\",\n                    EventTypes.Failure, \n                    EventIds.UserLoginFailure,\n                    error)\n        {\n            Username = username;\n        }\n\n        public string Username { get; set; }\n    }\n"
  },
  {
    "path": "docs/topics/extension_grants.rst",
    "content": ".. _refExtensionGrants:\nExtension Grants\n================\n\nOAuth 2.0 defines standard grant types for the token endpoint, such as ``password``, ``authorization_code`` and ``refresh_token``. Extension grants are a way to add support for non-standard token issuance scenarios like token translation, delegation, or custom credentials.\n\nYou can add support for additional grant types by implementing the ``IExtensionGrantValidator`` interface::\n\n    public interface IExtensionGrantValidator\n    {\n        /// <summary>\n        /// Handles the custom grant request.\n        /// </summary>\n        /// <param name=\"request\">The validation context.</param>\n        Task ValidateAsync(ExtensionGrantValidationContext context);\n\n        /// <summary>\n        /// Returns the grant type this validator can deal with\n        /// </summary>\n        /// <value>\n        /// The type of the grant.\n        /// </value>\n        string GrantType { get; }\n    }\n\nThe ``ExtensionGrantValidationContext`` object gives you access to:\n\n* the incoming token request - both the well-known validated values, as well as any custom values (via the ``Raw`` collection)\n* the result - either error or success\n* custom response parameters\n\nTo register the extension grant, add it to DI::\n\n    builder.AddExtensionGrantValidator<MyExtensionsGrantValidator>();\n\n\nExample: Simple delegation using an extension grant\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nImagine the following scenario - a front end client calls a middle tier API using a token acquired via an interactive flow (e.g. hybrid flow).\nThis middle tier API (API 1) now wants to call a back end API (API 2) on behalf of the interactive user:\n\n.. image:: images/delegation.png\n\nIn other words, the middle tier API (API 1) needs an access token containing the user's identity, but with the scope of the back end API (API 2).\n\n.. note:: You might have heard of the term *poor man's delegation* where the access token from the front end is simply forwarded to the back end. This has some shortcomings, e.g. *API 2* must now accept the *API 1* scope which would allow the user to call *API 2* directly. Also - you might want to add some delegation specific claims into the token, e.g. the fact that the call path is via *API 1*.\n\n**Implementing the extension grant**\n\nThe front end would send the token to API 1, and now this token needs to be exchanged at IdentityServer with a new token for API 2.\n\nOn the wire the call to token service for the exchange could look like this::\n\n    POST /connect/token\n\n    grant_type=delegation&\n    scope=api2&\n    token=...&\n    client_id=api1.client\n    client_secret=secret\n\nIt's the job of the extension grant validator to handle that request by validating the incoming token, and returning a result that represents the new token::\n\n    public class DelegationGrantValidator : IExtensionGrantValidator\n    {\n        private readonly ITokenValidator _validator;\n\n        public DelegationGrantValidator(ITokenValidator validator)\n        {\n            _validator = validator;\n        }\n\n        public string GrantType => \"delegation\";\n\n        public async Task ValidateAsync(ExtensionGrantValidationContext context)\n        {\n            var userToken = context.Request.Raw.Get(\"token\");\n\n            if (string.IsNullOrEmpty(userToken))\n            {\n                context.Result = new GrantValidationResult(TokenRequestErrors.InvalidGrant);\n                return;\n            }\n\n            var result = await _validator.ValidateAccessTokenAsync(userToken);\n            if (result.IsError)\n            {\n                context.Result = new GrantValidationResult(TokenRequestErrors.InvalidGrant);\n                return;\n            }\n\n            // get user's identity\n            var sub = result.Claims.FirstOrDefault(c => c.Type == \"sub\").Value;\n\n            context.Result = new GrantValidationResult(sub, GrantType);\n            return;\n        }\n    }\n\nDon't forget to register the validator with DI.\n\n**Registering the delegation client**\n\nYou need a client registration in IdentityServer that allows a client to use this new extension grant, e.g.::\n\n    var client = new Client\n    {\n        ClientId = \"api1.client\",\n        ClientSecrets = new List<Secret>\n        {\n            new Secret(\"secret\".Sha256())\n        },\n        \n        AllowedGrantTypes = { \"delegation\" },\n\n        AllowedScopes = new List<string>\n        {\n            \"api2\"\n        }\n    }\n\n**Calling the token endpoint**\n\nIn API 1 you can now construct the HTTP payload yourself, or use the *IdentityModel* helper library::\n\n\n    public async Task<TokenResponse> DelegateAsync(string userToken)\n    {\n        var client = _httpClientFactory.CreateClient();\n        // or \n        // var client = new HttpClient();\n\n        // send custom grant to token endpoint, return response\n        return await client.RequestTokenAsync(new TokenRequest\n        {\n            Address = disco.TokenEndpoint,\n            GrantType = \"delegation\",\n\n            ClientId = \"api1.client\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api2\" },\n                { \"token\", userToken}\n            }                \n        });\n    }\n\nThe ``TokenResponse.AccessToken`` will now contain the delegation access token.\n"
  },
  {
    "path": "docs/topics/federation_gateway.rst",
    "content": "Federation Gateway\n==================\n\nA common architecture is the so-called federation gateway. In this approach IdentityServer acts as a gateway to one or more external identity providers.\n\n.. image:: images/federation_gateway.png\n\nThis architecture has the following advantages\n\n* your applications only need to know about the one token service (the gateway) and are shielded from all the details about connecting to the external provider(s). This also means that you can add or change those external providers without needing to update your applications.\n* you control the gateway (as opposed to some external service provider) - this means you can make any changes to it and can protect your applications from changes those external providers might do to their own services.\n* most external providers only support a fixed set of claims and claim types - having a gateway in the middle allows post-processing the response from the providers to transform/add/amend domain specific identity information.\n* some providers don't support access tokens (e.g. social providers) - since the gateway knows about your APIs, it can issue access tokens based on the external identities.\n* some providers charge by the number of applications you connect to them. The gateway acts as a single application to the external provider. Internally you can connect as many applications as you want.\n* some providers use proprietary protocols or made proprietary modifications to standard protocols - with a gateway there is only one place you need to deal with that.\n* forcing every authentication (internal or external) through one single place gives you tremendous flexibility with regards to identity mapping, providing a stable identity to all your applications and dealing with new requirements\n\nIn other words - owning your federation gateway gives you a lot of control over your identity infrastructure. And since the identity of your users is one of your most important assets, we recommend taking control over the gateway.\n\nImplementation\n^^^^^^^^^^^^^^\nOur `quick start UI <https://github.com/alexhiggins732/IdentityServer8.Quickstart.UI>`_ utilizes some of the below features. Also check out the :ref:`external authentication quickstart <refExternalAuthenticationQuickstart>` and the \ndocs about :ref:`external providers <refExternalIdentityProviders>`.\n\n* You can add support for external identity providers by adding authentication handlers to your IdentityServer application.\n* You can programmatically query those external providers by calling ``IAuthenticationSchemeProvider``. This allows to dynamically render your login page based on the registered external providers.\n* Our client configuration model allows restricting the available providers on a per client basis (use the ``IdentityProviderRestrictions`` property).\n* You can also use the ``EnableLocalLogin`` property on the client to tell your UI whether the username/password input should be rendered.\n* Our quickstart UI funnels all external authentication calls through a single callback (see ``ExternalLoginCallback`` on the ``AccountController`` class). This allows for a single point for post-processing.\n"
  },
  {
    "path": "docs/topics/grant_types.rst",
    "content": ".. _refGrantTypes:\nGrant Types\n^^^^^^^^^^^\nThe OpenID Connect and OAuth 2.0 specifications define so-called grant types (often also called flows - or protocol flows).\nGrant types specify how a client can interact with the token service.\n\nYou need to specify which grant types a client can use via the ``AllowedGrantTypes`` property on the ``Client`` configuration.\nThis allows locking down the protocol interactions that are allowed for a given client.\n\nA client can be configured to use more than a single grant type (e.g. Authorization Code flow for user centric operations and client credentials for server to server communication).\nThe ``GrantTypes`` class can be used to pick from typical grant type combinations::\n\n    Client.AllowedGrantTypes = GrantTypes.CodeAndClientCredentials;\n\nYou can also specify the grant types list manually::\n\n    Client.AllowedGrantTypes = \n    {\n        GrantType.Code, \n        GrantType.ClientCredentials,\n        \"my_custom_grant_type\" \n    };\n\nWhile IdentityServer supports all standard grant types, you really only need to know two of them for common application scenarios.\n\nMachine to Machine Communication\n================================\nThis is the simplest type of communication. Tokens are always requested on behalf of a client, no interactive user is present.\n\nIn this scenario, you send a token request to the token endpoint using the ``client credentials`` grant type.\nThe client typically has to authenticate with the token endpoint using its client ID and secret.\n\nSee the :ref:`Client Credentials Quick Start <refClientCredentialsQuickstart>` for a sample how to use it. \n\nInteractive Clients\n===================\nThis is the most common type of client scenario: web applications, SPAs or native/mobile apps with interactive users.\n\n.. Note:: Feel free to skip to the summary, if you don't care about all the technical details.\n\nFor this type of clients, the ``authorization code`` flow was designed. That flow consists of two physical operations:\n\n* a front-channel step via the browser where all \"interactive\" things happen, e.g. login page, consent etc. This step results in an authorization code that represents the outcome of the front-channel operation.\n* a back-channel step where the authorization code from step 1 gets exchanged with the requested tokens. Confidential clients need to authenticate at this point.\n\nThis flow has the following security properties:\n\n* no data (besides the authorization code which is basically a random string) gets leaked over the browser channel\n* authorization codes can only be used once\n* the authorization code can only be turned into tokens when (for confidential clients - more on that later) the client secret is known\n\nThis sounds all very good - still there is one problem called `code substitution attack <https://nat.sakimura.org/2016/01/25/cut-and-pasted-code-attack-in-oauth-2-0-rfc6749/>`_.\nThere are two modern mitigation techniques for this:\n\n**OpenID Connect Hybrid Flow**\n\nThis uses a response type of ``code id_token`` to add an additional identity token to the response. This token is signed and protected against substitution.\nIn addition it contains the hash of the code via the ``c_hash`` claim. This allows checking that you indeed got the right code (experts call this a detached signature).\n\nThis solves the problem but has the following down-sides:\n\n* the ``id_token`` gets transmitted over the front-channel and might leak additional (personal identifiable) data\n* all the mitigation steps (e.g. crypto) need to be implemented by the client. This results in more complicated client library implementations.\n\n**RFC 7636 - Proof Key for Code Exchange (PKCE)**\n\nThis essentially introduces a per-request secret for code flow (please read up on the details `here <https://tools.ietf.org/html/rfc7636>`_).\nAll the client has to implement for this, is creating a random string and hashing it using SHA256.\n\nThis also solves the substitution problem, because the client can prove that it is the same client on front and back-channel, and has the following additional advantages:\n\n* the client implementation is very simple compared to hybrid flow\n* it also solves the problem of the absence of a static secret for public clients\n* no additional front-channel response artifacts are needed\n\n**Summary**\n\nInteractive clients should use an authorization code-based flow. To protect against code substitution, either hybrid flow or PKCE should be used.\nIf PKCE is available, this is the simpler solution to the problem.\n\nPKCE is already the official recommendation for `native <https://tools.ietf.org/html/rfc8252#section-6>`_ applications \nand `SPAs <https://tools.ietf.org/html/draft-ietf-oauth-browser-based-apps-03#section-4>`_ - and with the release of ASP.NET Core 3 also by default supported in the OpenID Connect handler as well.\n\nThis is how you would configure an interactive client::\n\n    var client = new Client\n    {\n        ClientId = \"...\",\n\n        // set client secret for confidential clients\n        ClientSecret = { ... },\n\n        // ...or turn off for public clients\n        RequireClientSecret = false,\n\n        AllowedGrantTypes = GrantTypes.Code,\n        RequirePkce = true\n    };\n\n\nInteractive clients without browsers or with constrained input devices\n======================================================================\nThis grant type is detailed `RFC 8628 <https://tools.ietf.org/html/rfc8628>`_.\n\nThis flow outsources user authentication and consent to an external device (e.g. a smart phone).\nIt is typically used by devices that don't have proper keyboards (e.g. TVs, gaming consoles...) and can request both identity and API resources.\n\nCustom scenarios\n================\nExtension grants allow extending the token endpoint with new grant types. See :ref:`this <refExtensionGrants>` for more details. \n"
  },
  {
    "path": "docs/topics/logging.rst",
    "content": "\nLogging\n=======\nIdentityServer uses the standard logging facilities provided by ASP.NET Core.\nThe Microsoft `documentation <https://docs.microsoft.com/en-us/aspnet/core/fundamentals/logging>`_ has a good intro and a description of the built-in logging providers.\n\nWe are roughly following the Microsoft guidelines for usage of log levels:\n\n* ``Trace`` For information that is valuable only to a developer troubleshooting an issue. These messages may contain sensitive application data like tokens and should not be enabled in a production environment.\n* ``Debug`` For following the internal flow and understanding why certain decisions are made. Has short-term usefulness during development and debugging.\n* ``Information`` For tracking the general flow of the application. These logs typically have some long-term value.\n* ``Warning`` For abnormal or unexpected events in the application flow. These may include errors or other conditions that do not cause the application to stop, but which may need to be investigated.\n* ``Error`` For errors and exceptions that cannot be handled. Examples: failed validation of a protocol request.\n* ``Critical`` For failures that require immediate attention. Examples: missing store implementation, invalid key material...\n\nSetup for Serilog\n^^^^^^^^^^^^^^^^^\nWe personally like `Serilog <https://serilog.net/>`_ and the ``Serilog.AspNetCore`` package a lot. Give it a try::\n\n    public class Program\n    {\n        public static int Main(string[] args)\n        {\n            Activity.DefaultIdFormat = ActivityIdFormat.W3C;\n\n            Log.Logger = new LoggerConfiguration()\n                .MinimumLevel.Debug()\n                .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n                .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n                .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n                .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n                .Enrich.FromLogContext()\n                .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n                .CreateLogger();\n\n            try\n            {\n                Log.Information(\"Starting host...\");\n                CreateHostBuilder(args).Build().Run();\n                return 0;\n            }\n            catch (Exception ex)\n            {\n                Log.Fatal(ex, \"Host terminated unexpectedly.\");\n                return 1;\n            }\n            finally\n            {\n                Log.CloseAndFlush();\n            }\n        }\n\n        public static IHostBuilder CreateHostBuilder(string[] args) =>\n            Microsoft.Extensions.Hosting.Host.CreateDefaultBuilder(args)\n                .UseSerilog()\n                .ConfigureWebHostDefaults(webBuilder =>\n                {\n                    webBuilder.UseStartup<Startup>();\n                });\n    }"
  },
  {
    "path": "docs/topics/mtls.rst",
    "content": ".. _refMutualTLS:\nMutual TLS\n==========\nMutual TLS support in IdentityServer allows for two features:\n\n* Client authentication to IdentityServer endpoints using a TLS X.509 client certificate\n* Binding of access tokens to clients using a TLS X.509 client certificate\n\n.. Note:: See the `\"OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens\" <https://tools.ietf.org/html/rfc8705>`_ spec for more information\n\nSetting up MTLS involves a couple of steps.\n\nServer setup\n^^^^^^^^^^^^\nIt's the hosting layer's responsibility to do the actual validation of the client certificate.\nIdentityServer will then use that information to associate the certificate with a client and embed the certificate information in the access tokens.\n\nDepending which server you are using, those steps are different. See `this <https://leastprivilege.com/2020/02/07/mutual-tls-and-proof-of-possession-access-tokens-part-1-setup/>`_ blog post for more information.\n\n.. Note:: `mkcert <https://github.com/FiloSottile/mkcert>`_ is a nice utility for creating certificates for development purposes.\n\nASP.NET Core setup\n^^^^^^^^^^^^^^^^^^\nDepending on the server setup, there are different ways how the ASP.NET Core host will receive the client certificate. While for IIS and pure Kestrel hosting, there are no additional steps, \ntypically you have a reverse proxy in front of the application server. \n\nThis means that in addition to the typical forwarded headers handling, you also need to process the header that contains the client certificate.\nAdd a call to ``app.UseCertificateForwarding();`` in the beginning of your middleware pipeline for that.\n\nThe exact format how proxies transmit the certificates is not standardized, that's why you need to register a callback to do the actual header parsing.\nThe Microsoft `docs <https://docs.microsoft.com/en-us/aspnet/core/security/authentication/certauth?view=aspnetcore-3.1>`_ show how that would work for Azure Web Apps.\n\nIf you are using Nginx (which we found is the most flexible hosting option), you need to register the following service in ``ConfigureServices``::\n\n    services.AddCertificateForwarding(options =>\n    {\n        // header name might be different, based on your nginx config\n        options.CertificateHeader = \"X-SSL-CERT\";\n\n        options.HeaderConverter = (headerValue) =>\n        {\n            X509Certificate2 clientCertificate = null;\n\n            if(!string.IsNullOrWhiteSpace(headerValue))\n            {\n                var bytes = Encoding.UTF8.GetBytes(Uri.UnescapeDataString(headerValue));\n                clientCertificate = new X509Certificate2(bytes);\n            }\n\n            return clientCertificate;\n        };\n    });\n\nOnce, the certificate has been loaded, you also need to setup the authentication handler.\nIn this scenario we want to support self-signed certificates, hence the ``CertificateType.All`` and no revocation checking.\nThese settings might be different in your environment:: \n\n    services.AddAuthentication()\n        .AddCertificate(options =>\n        {\n            options.AllowedCertificateTypes = CertificateTypes.All;\n            options.RevocationMode = X509RevocationMode.NoCheck;\n        });\n\nIdentityServer setup\n^^^^^^^^^^^^^^^^^^^^\nNext step is to enable MTLS in IdentityServer. For that you need to specify the name of the certificate authentication handler you set-up in the last step (defaults to ``Certificate``),\nand the MTLS hosting strategy.\n\nIn IdentityServer, the mutual TLS endpoints, can be configured in three ways (assuming IdentityServer is running on ``https://identityserver8.io``:\n\n* path-based - endpoints located beneath the path ``~/connect/mtls``, e.g. ``https://identityserver8.io/connect/mtls/token``.\n* sub-domain based - endpoints are on a sub-domain of the main server, e.g. ``https://mtls.identityserver8.io/connect/token``.\n* domain-based - endpoints are on a different domain, e.g. ``https://identityserver-mtls.io``.  \n\nFor example::\n\n    var builder = services.AddIdentityServer(options =>\n    {\n        options.MutualTls.Enabled = true;\n        options.MutualTls.ClientCertificateAuthenticationScheme = \"Certificate\";\n        \n        // uses sub-domain hosting\n        options.MutualTls.DomainName = \"mtls\";\n    });\n\nIdentityServer's discovery document reflects those endpoints:\n\n.. image:: images/mtls_endpoints.png\n\n\nClient authentication\n^^^^^^^^^^^^^^^^^^^^^\nClients can use a X.509 client certificate as an authentication mechanism to endpoints in IdentityServer.\n\nFor this you need to associate a client certificate with a client in IdentityServer.\nUse the :ref:`IdentityServer builder <refStartup>` to add the services to DI which contain a default implementation to do that either thumbprint or common-name based::\n\n    builder.AddMutualTlsSecretValidators();\n\nFinally, for the :ref:`client configuration <refClient>` add to the ``ClientSecrets`` collection a secret type of either ``SecretTypes.X509CertificateName`` \nif you wish to authenticate the client from the certificate distinguished name or ``SecretTypes.X509CertificateThumbprint`` if you wish to authenticate the client by certificate thumbprint.\n\nFor example::\n\n    new Client\n    {\n        ClientId = \"mtls\",\n        AllowedGrantTypes = GrantTypes.ClientCredentials,\n        AllowedScopes = { \"api1\" }\n        ClientSecrets = \n        {\n            // name based\n            new Secret(@\"CN=mtls.test, OU=ROO\\ballen@roo, O=mkcert development certificate\", \"mtls.test\")\n            {\n                Type = SecretTypes.X509CertificateName\n            },\n            // or thumbprint based\n            //new Secret(\"bca0d040847f843c5ee0fa6eb494837470155868\", \"mtls.test\")\n            //{\n            //    Type = SecretTypes.X509CertificateThumbprint\n            //},\n        },\n    }\n\nUsing a client certificate to authenticate to IdentityServer\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nWhen writing a client to connect to IdentityServer, the ``SocketsHttpHandler`` (or ``HttpClientHandler`` if you are on older .NET Framework versions) \nclass provides a convenient mechanism to add a client certificate to outgoing requests.\n\nAnd then HTTP calls (including using the various `IdentityModel <https://github.com/IdentityModel/IdentityModel2>`_ extension methods) with the ``HttpClient`` \nwill perform client certificate authentication at the TLS channel.\n\nFor example::\n\n    static async Task<TokenResponse> RequestTokenAsync()\n    {\n        var handler = new SocketsHttpHandler();\n        var cert = new X509Certificate2(\"client.p12\", \"password\");\n        handler.SslOptions.ClientCertificates = new X509CertificateCollection { cert };\n\n        var client = new HttpClient(handler);\n\n        var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n        if (disco.IsError) throw new Exception(disco.Error);\n\n        var response = await client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = disco\n                            .TryGetValue(OidcConstants.Discovery.MtlsEndpointAliases)\n                            .Value<string>(OidcConstants.Discovery.TokenEndpoint)\n                            .ToString(),\n                            \n            ClientId = \"mtls\",\n            Scope = \"api1\"\n        });\n\n        if (response.IsError) throw new Exception(response.Error);\n        return response;\n    }\n\n\nSender-constrained access tokens\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nWhenever a client authenticates to IdentityServer using a client certificate, the thumbprint of that certificate will be embedded in the access token.\n\nClients can use a X.509 client certificate as a mechanism for sender-constrained access tokens when authenticating to APIs.\nThe use of these sender-constrained access tokens requires the client to use the same X.509 client certificate to authenticate to the API as the one used for IdentityServer.\n\nConfirmation claim\n~~~~~~~~~~~~~~~~~~\nWhen a client obtains an access token and has authenticated with mutual TLS, IdentityServer issues a confirmation claim (or ``cnf``) in the access token.\nThis value is a hash of the thumbprint of the client certificate used to authenticate with IdentityServer.\n\nThis value can be seen in this screen shot of a decoded access token:\n\n.. image:: images/mtls_access_token_with_cnf.png\n\nThe API will then use this value to ensure the client certificate being used at the API matches the confirmation value in the access token.\n\nValidating and accepting a client certificate in APIs\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nAs mentioned above for client authentication in IdentityServer, in the API the web server is expected to perform the client certificate validation at the TLS layer.\n\nAdditionally, the API hosting application will need a mechanism to accept the client certificate in order to obtain the thumbprint to perform the confirmation claim validation.\nBelow is an example how an API in ASP.NET Core might be configured for both access tokens and client certificates::\n\n    services.AddAuthentication(\"token\")\n        .AddIdentityServerAuthentication(\"token\", options =>\n        {\n            options.Authority = \"https://identityserver8.io\";\n            options.ApiName = \"api1\";\n\n        })\n        .AddCertificate(options =>\n        {\n            options.AllowedCertificateTypes = CertificateTypes.All;\n        });\n\nFinally, a mechanism is needed that runs after the authentication middleware to authenticate the client certificate and compare the thumbprint to the ``cnf`` from the access token.\n\nBelow is a simple middleware that checks the claims::\n\n    public class ConfirmationValidationMiddlewareOptions\n    {\n        public string CertificateSchemeName { get; set; } = CertificateAuthenticationDefaults.AuthenticationScheme;\n        public string JwtBearerSchemeName { get; set; } = JwtBearerDefaults.AuthenticationScheme;\n    }\n    \n    // this middleware validate the cnf claim (if present) against the thumbprint of the X.509 client certificate for the current client\n    public class ConfirmationValidationMiddleware\n    {\n        private readonly RequestDelegate _next;\n        private readonly ConfirmationValidationMiddlewareOptions _options;\n\n        public ConfirmationValidationMiddleware(RequestDelegate next, ConfirmationValidationMiddlewareOptions options = null)\n        {\n            _next = next;\n            _options = options ?? new ConfirmationValidationMiddlewareOptions();\n        }\n\n        public async Task Invoke(HttpContext ctx)\n        {\n            if (ctx.User.Identity.IsAuthenticated)\n            {\n                var cnfJson = ctx.User.FindFirst(\"cnf\")?.Value;\n                if (!String.IsNullOrWhiteSpace(cnfJson))\n                {\n                    var certResult = await ctx.AuthenticateAsync(_options.CertificateSchemeName);\n                    if (!certResult.Succeeded)\n                    {\n                        await ctx.ChallengeAsync(_options.CertificateSchemeName);\n                        return;\n                    }\n\n                    var certificate = await ctx.Connection.GetClientCertificateAsync();\n                    var thumbprint = Base64UrlTextEncoder.Encode(certificate.GetCertHash(HashAlgorithmName.SHA256));\n\n                    var cnf = JObject.Parse(cnfJson);\n                    var sha256 = cnf.Value<string>(\"x5t#S256\");\n\n                    if (String.IsNullOrWhiteSpace(sha256) ||\n                        !thumbprint.Equals(sha256, StringComparison.Ordinal))\n                    {\n                        await ctx.ChallengeAsync(_options.JwtBearerSchemeName);\n                        return;\n                    }\n                }\n            }\n\n            await _next(ctx);\n        }\n\nBelow is an example pipeline for an API::\n\n    app.UseForwardedHeaders(new ForwardedHeadersOptions\n        {\n            ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto\n        });\n        \n    app.UseCertificateForwarding();\n    app.UseRouting();\n    app.UseAuthentication();\n    \n    app.UseMiddleware<ConfirmationValidationMiddleware>(new ConfirmationValidationMiddlewareOptions\n    {\n        CertificateSchemeName = CertificateAuthenticationDefaults.AuthenticationScheme,\n        JwtBearerSchemeName = \"token\"\n    });\n\n    app.UseAuthorization();\n    \n    app.UseEndpoints(endpoints =>\n    {\n        endpoints.MapControllers();\n    });\n\nOnce the above middleware succeeds, then the caller has been authenticated with a sender-constrained access token.\n\nIntrospection and the confirmation claim\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nWhen the access token is a JWT, then the confirmation claim is contained in the token as a claim.\nWhen using reference tokens, the claims that the access token represents must be obtained via introspection.\nThe introspection endpoint in IdentityServer will return a ``cnf`` claim for reference tokens obtained via mutual TLS.\n\nEphemeral client certificates\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nYou can use the IdentityServer MTLS support also to create sender-constrained access tokens without using the client certificate for client authentication.\nThis is useful for situations where you already have client secrets in place that you don't want to change, e.g. shared secrets, or better private key JWTs. \n\nStill, if a client certificate is present, the confirmation claim can be embedded in outgoing access tokens. And as long as the client is using the same client certificate to \nrequest the token and calling the API, this will give you the desired proof-of-possession properties.\n\nFor this enable the following setting in the options::\n\n    var builder = services.AddIdentityServer(options =>\n    {\n        // other settings\n        \n        options.MutualTls.AlwaysEmitConfirmationClaim = true;\n    });\n\nUsing an ephemeral certificate to request a token\n~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~\nIn this scenario, the client uses *some* client secret (a shared secret in the below sample), but attaches an additional client certificate to the token request.\nSince this certificate does not need to be associated with the client at the token services, it can be created on the fly::\n\n    static X509Certificate2 CreateClientCertificate(string name)\n    {\n        X500DistinguishedName distinguishedName = new X500DistinguishedName($\"CN={name}\");\n\n        using (RSA rsa = RSA.Create(2048))\n        {\n            var request = new CertificateRequest(distinguishedName, rsa, HashAlgorithmName.SHA256,RSASignaturePadding.Pkcs1);\n\n            request.CertificateExtensions.Add(\n                new X509KeyUsageExtension(X509KeyUsageFlags.DataEncipherment | X509KeyUsageFlags.KeyEncipherment | X509KeyUsageFlags.DigitalSignature , false));\n\n            request.CertificateExtensions.Add(\n                new X509EnhancedKeyUsageExtension(\n                    new OidCollection { new Oid(\"1.3.6.1.5.5.7.3.2\") }, false));\n\n            return request.CreateSelfSigned(new DateTimeOffset(DateTime.UtcNow.AddDays(-1)), new DateTimeOffset(DateTime.UtcNow.AddDays(10)));\n        }\n    }\n\nThen use this client certificate in addition to the already setup-up client secret::\n\n    static async Task<TokenResponse> RequestTokenAsync()\n    {\n        var client = new HttpClient(GetHandler(ClientCertificate));\n\n        var disco = await client.GetDiscoveryDocumentAsync(\"https://identityserver.local\");\n        if (disco.IsError) throw new Exception(disco.Error);\n\n        var endpoint = disco\n            .TryGetValue(OidcConstants.Discovery.MtlsEndpointAliases)\n            .Value<string>(OidcConstants.Discovery.TokenEndpoint)\n            .ToString();\n        \n        var response = await client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = endpoint,\n\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\"\n        });\n\n        if (response.IsError) throw new Exception(response.Error);\n        return response;\n    }\n\n    static SocketsHttpHandler GetHandler(X509Certificate2 certificate)\n    {\n        var handler = new SocketsHttpHandler();\n        handler.SslOptions.ClientCertificates = new X509CertificateCollection { certificate };\n\n        return handler;\n    }\n"
  },
  {
    "path": "docs/topics/persisted_grants.rst",
    "content": ".. _refPersistedGrants:\nPersisted Grants\n================\nMany grant types require persistence in IdentityServer.\nThese include authorization codes, refresh tokens, reference tokens, and remembered user consents.\nInternally in IdentityServer, the default storage for these grants is in a common store called the persisted grants store.\n\nPersisted Grant\n^^^^^^^^^^^^^^^\nThe persisted grant is the data type that maintains the values for a grant. \nIt has these properties:\n\n``Key``\n    The unique identifier for the persisted grant in the store.\n``Type``\n    The type of the grant.\n``SubjectId``\n    The subject id to which the grant belongs.\n``ClientId``\n    The client identifier for which the grant was created.\n``Description``\n    The description the user assigned to the grant or device being authorized.\n``CreationTime``\n    The date/time the grant was created.\n``Expiration``\n    The expiration of the grant.\n``ConsumedTime``\n    The date/time the grant was \"consumed\" (see below).\n``Data``\n    The grant specific serialized data.\n\n.. note:: The ``Data`` property contains a copy of all of the values (and more) and is considered authoritative by IdentityServer, thus the above values, by default, are considered informational and read-only.\n\nThe presence of the record in the store without a ``ConsumedTime`` and while still within the ``Expiration`` represents the validity of the grant.\nSetting either of these two values, or removing the record from the store effectively revokes the grant.\n\nGrant Consumption\n^^^^^^^^^^^^^^^^^\nSome grant types are one-time use only (either by definition or configuration).\nOnce they are \"used\", rather than deleting the record, the ``ConsumedTime`` value is set in the database marking them as having been used.\nThis \"soft delete\" allows for custom implementations to either have flexibility in allowing a grant to be re-used (typically within a short window of time),\nor to be used in risk assessment and threat mitigation scenarios (where suspicious activity is detected) to revoke access.\nFor refresh tokens, this sort of custom logic would be performed in the ``IRefreshTokenService``.\n\nPersisted Grant Service\n^^^^^^^^^^^^^^^^^^^^^^^\nWorking with the grants store directly might be too low level. \nAs such, a higher level service called ``IPersistedGrantService`` is provided.\nIt abstracts and aggregates the different grant types into one concept, and allows querying and revoking the persisted grants for a user.\n\nIt contains these APIs:\n\n``GetAllGrantsAsync``\n    Gets all the grants for a user based upon subject id. \n``RemoveAllGrantsAsync``\n    Removes grants from the store based on the subject id and optionally a client id and/or a session id.\n"
  },
  {
    "path": "docs/topics/pop.rst",
    "content": "Proof-of-Possession Access Tokens\n=================================\nBy default, OAuth access tokens are so called *bearer* tokens. This means they are not bound to a client and anybody who possess the token can use it (compare to cash).\n\n*Proof-of-Possession* (short PoP) tokens are bound to the client that requested the token. \nIf that token leaks, it cannot be used by anyone else (compare to a credit card - well at least in an ideal world).\n\nSee `this <https://leastprivilege.com/2020/01/15/oauth-2-0-the-long-road-to-proof-of-possession-access-tokens/>`_ blog post for more history and motivation.\n\nIdentityServer supports PoP tokens by using the :ref:`Mutual TLS mechanism <refMutualTLS>`."
  },
  {
    "path": "docs/topics/reference_tokens.rst",
    "content": "Reference Tokens\n================\nAccess tokens can come in two flavours - self-contained or reference.\n\nA JWT token would be a self-contained access token - it's a protected data structure with claims and an expiration.\nOnce an API has learned about the key material, it can validate self-contained tokens without needing to communicate with the issuer.\nThis makes JWTs hard to revoke. They will stay valid until they expire.\n\nWhen using reference tokens - IdentityServer will store the contents of the token in a data store and will only issue a unique identifier for this token back to the client.\nThe API receiving this reference must then open a back-channel communication to IdentityServer to validate the token.\n\n.. image:: images/reference_tokens.png\n\nYou can switch the token type of a client using the following setting::\n\n    client.AccessTokenType = AccessTokenType.Reference;\n\nIdentityServer provides an implementation of the OAuth 2.0 introspection specification which allows APIs to dereference the tokens.\nYou can either use our dedicated `introspection handler <https://github.com/IdentityModel/IdentityModel.AspNetCore.OAuth2Introspection>`_\nor use the `identity server authentication handler <https://github.com/alexhiggins732/IdentityServer8.AccessTokenValidation>`_ which can validate both JWTs and reference tokens.\n\nThe introspection endpoint requires authentication - since the client of an introspection endpoint is an API, you configure the secret on the ``ApiResource``::\n\n    var api = new ApiResource(\"api1\")\n    {\n        ApiSecrets = { new Secret(\"secret\".Sha256()) }\n    }\n\nSee :ref:`here <refProtectingApis>` for more information on how to configure the IdentityServer authentication middleware for APIs.\n"
  },
  {
    "path": "docs/topics/refresh_tokens.rst",
    "content": "Refresh Tokens\n==============\nSince access tokens have finite lifetimes, refresh tokens allow requesting new access tokens without user interaction.\n\nRefresh tokens are supported for the following flows: authorization code, hybrid and resource owner password credential flow.\nThe clients needs to be explicitly authorized to request refresh tokens by setting ``AllowOfflineAccess`` to ``true``.\n\nAdditional client settings\n^^^^^^^^^^^^^^^^^^^^^^^^^^\n``AbsoluteRefreshTokenLifetime``\n    Maximum lifetime of a refresh token in seconds. Defaults to 2592000 seconds / 30 days. Zero allows refresh tokens that, when used with ``RefreshTokenExpiration = Sliding`` only expire after the SlidingRefreshTokenLifetime is passed.\n``SlidingRefreshTokenLifetime``\n    Sliding lifetime of a refresh token in seconds. Defaults to 1296000 seconds / 15 days\n``RefreshTokenUsage``\n    ``ReUse`` the refresh token handle will stay the same when refreshing tokens\n    \n    ``OneTimeOnly`` the refresh token handle will be updated when refreshing tokens\n``RefreshTokenExpiration``\n    ``Absolute`` the refresh token will expire on a fixed point in time (specified by the AbsoluteRefreshTokenLifetime). This is the default.\n    \n    ``Sliding`` when refreshing the token, the lifetime of the refresh token will be renewed (by the amount specified in SlidingRefreshTokenLifetime). The lifetime will not exceed `AbsoluteRefreshTokenLifetime`.\n``UpdateAccessTokenClaimsOnRefresh``\n    Gets or sets a value indicating whether the access token (and its claims) should be updated on a refresh token request.\n\n.. note:: Public clients (clients without a client secret) should rotate their refresh tokens. Set the ``RefreshTokenUsage`` to ``OneTimeOnly``.\n\nRequesting a refresh token\n^^^^^^^^^^^^^^^^^^^^^^^^^^\nYou can request a refresh token by adding a scope called ``offline_access`` to the scope parameter.\n\nRequesting an access token using a refresh token\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nTo get a new access token, you send the refresh token to the token endpoint.\nThis will result in a new token response containing a new access token and its expiration and potentially also a new refresh token depending on the client configuration (see above).\n\n::\n\n    POST /connect/token\n\n        client_id=client&\n        client_secret=secret&\n        grant_type=refresh_token&\n        refresh_token=hdh922\n        \n(Form-encoding removed and line breaks added for readability)\n\n.. Note:: You can use the `IdentityModel <https://github.com/IdentityModel/IdentityModel>`_ client library to programmatically access the token endpoint from .NET code. For more information check the IdentityModel `docs <https://identitymodel.readthedocs.io/en/latest/client/token.html>`_.\n\n.. Note:: The refresh token, must be valid or an invalid_grant error is returned.  By default, a refresh_token can only be used once.  Using an already used refresh_token will result in an invalid_grant error.\n\nCustomizing refresh token behavior\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nAll refresh token handling is implemented in the ``DefaultRefreshTokenService`` (which is the default implementation of the ``IRefreshTokenService`` interface)::\n\n    public interface IRefreshTokenService\n    {\n        /// <summary>\n        /// Validates a refresh token.\n        /// </summary>\n        Task<TokenValidationResult> ValidateRefreshTokenAsync(string token, Client client);\n        \n        /// <summary>\n        /// Creates the refresh token.\n        /// </summary>\n        Task<string> CreateRefreshTokenAsync(ClaimsPrincipal subject, Token accessToken, Client client);\n\n        /// <summary>\n        /// Updates the refresh token.\n        /// </summary>\n        Task<string> UpdateRefreshTokenAsync(string handle, RefreshToken refreshToken, Client client);\n    }\n\nThe logic around refresh token handling is pretty involved, and we don't recommend implementing the interface from scratch,\nunless you exactly know what you are doing.\nIf you want to customize certain behavior, it is more recommended to derive from the default implementation and call the base checks first.\n\nThe most common customization that you probably want to do is how to deal with refresh token replays.\nThis is for situations where the token usage has been set to one-time only, but the same token gets sent more than once.\nThis could either point to a replay attack of the refresh token, or to faulty client code like logic bugs or race conditions.\n\nIt is important to note, that a refresh token is never deleted in the database. \nOnce it has been used, the ``ConsumedTime`` property will be set.\nIf a token is received that has already been consumed, the default service will call a virtual method called ``AcceptConsumedTokenAsync``.\n\nThe default implementation will reject the request, but here you can implement custom logic like grace periods, \nor revoking additional refresh or access tokens.\n"
  },
  {
    "path": "docs/topics/request_object.rst",
    "content": "Authorize Request Objects\n=========================\nInstead of providing the parameters for an authorize request as individual query string key/value pairs, you can package them up in signed JWTs.\nThis makes the parameters tamper proof and you can authenticate the client already on the front-channel.\n\nYou can either transmit them by value or by reference to the authorize endpoint - see the `spec <https://openid.net/specs/openid-connect-core-1_0.html#JWTRequests>`_ for more details.\n\nIdentityServer requires the request JWTs to be signed. We support X509 certificates and JSON web keys, e.g.::\n\n    var client = new Client\n    {\n        ClientId = \"foo\",\n        \n        // set this to true to accept signed requests only\n        RequireRequestObject = true,\n\n        ClientSecrets = \n        {\n            new Secret\n            {\n                // X509 cert base64-encoded\n                Type = IdentityServerConstants.SecretTypes.X509CertificateBase64,\n                Value = Convert.ToBase64String(cert.Export(X509ContentType.Cert))\n            },\n            new Secret\n            {\n                // RSA key as JWK\n                Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                Value =\n                    \"{'e':'AQAB','kid':'ZzAjSnraU3bkWGnnAqLapYGpTyNfLbjbzgAPbbW2GEA','kty':'RSA','n':'wWwQFtSzeRjjerpEM5Rmqz_DsNaZ9S1Bw6UbZkDLowuuTCjBWUax0vBMMxdy6XjEEK4Oq9lKMvx9JzjmeJf1knoqSNrox3Ka0rnxXpNAz6sATvme8p9mTXyp0cX4lF4U2J54xa2_S9NF5QWvpXvBeC4GAJx7QaSw4zrUkrc6XyaAiFnLhQEwKJCwUw4NOqIuYvYp_IXhw-5Ti_icDlZS-282PcccnBeOcX7vc21pozibIdmZJKqXNsL1Ibx5Nkx1F1jLnekJAmdaACDjYRLL_6n3W4wUp19UvzB1lGtXcJKLLkqB6YDiZNu16OSiSprfmrRXvYmvD8m6Fnl5aetgKw'}\"\n            }\n        }\n    }\n\n.. note:: Microsoft.IdentityModel.Tokens.JsonWebKeyConverter has various helpers to convert keys to JWKs\n\nPassing request JWTs by reference\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nIf the ``request_uri`` parameter is used, IdentityServer will make an outgoing HTTP call to fetch the JWT from the specified URL.\n\nYou can customize the HTTP client used for this outgoing connection, e.g. to add caching or retry logic (e.g. via the Polly library)::\n\n    builder.AddJwtRequestUriHttpClient(client =>\n    {\n        client.Timeout = TimeSpan.FromSeconds(30);\n    })\n        .AddTransientHttpErrorPolicy(policy => policy.WaitAndRetryAsync(new[]\n        {\n            TimeSpan.FromSeconds(1),\n            TimeSpan.FromSeconds(2),\n            TimeSpan.FromSeconds(3)\n        }));\n\n.. note:: Request URI processing is disabled by default. Enable on the :ref:`IdentityServer Options <refOptions>` under ``Endpoints``. Also see the security considerations from the JAR `specification <https://tools.ietf.org/html/draft-ietf-oauth-jwsreq-23#section-10.4>`_.\n\nAccessing the request object data\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nYou can access the validated data from the request object in two ways\n\n* wherever you have access to the ``ValidatedAuthorizeRequest``, the ``RequestObjectValues`` dictionary holds the values\n* in the UI code you can call ``IIdentityServerInteractionService.GetAuthorizationContextAsync``, the resulting ``AuthorizationRequest`` object contains the ``RequestObjectValues`` dictionary as well\n"
  },
  {
    "path": "docs/topics/resource_owner.rst",
    "content": ".. _refResourceOwnerPasswordValidator:\nResource Owner Password Validation\n===================================\n\nIf you want to use the OAuth 2.0 resource owner password credential grant (aka ``password``), you need to implement and register the ``IResourceOwnerPasswordValidator`` interface::\n\n    public interface IResourceOwnerPasswordValidator\n    {\n        /// <summary>\n        /// Validates the resource owner password credential\n        /// </summary>\n        /// <param name=\"context\">The context.</param>\n        Task ValidateAsync(ResourceOwnerPasswordValidationContext context);\n    }\n\nOn the context you will find already parsed protocol parameters like ``UserName`` and ``Password``, but also the raw request if you want to look at other input data.\n\nYour job is then to implement the password validation and set the ``Result`` on the context accordingly. See the :ref:`GrantValidationResult <refGrantValidationResult>` documentation."
  },
  {
    "path": "docs/topics/resources.rst",
    "content": ".. _refResources:\nDefining Resources\n==================\nThe ultimate job of an OpenID Connect/OAuth token service is to control access to resources.\n\nThe two fundamental resource types in IdentityServer are:\n\n* **identity resources:** represent claims about a user like user ID, display name, email address etc…\n* **API resources:** represent functionality a client wants to access. Typically, they are HTTP-based endpoints (aka APIs), but could be also message queuing endpoints or similar.\n\n.. note:: You can define resources using a C# object model - or load them from a data store. An implementation of ``IResourceStore`` deals with these low-level details. For this document we are using the in-memory implementation.\n\nIdentity Resources\n------------------\nAn identity resource is a named group of claims that can be requested using the *scope* parameter.\n\nThe OpenID Connect specification `suggests <https://openid.net/specs/openid-connect-core-1_0.html#ScopeClaims>`_ a couple of standard \nscope name to claim type mappings that might be useful to you for inspiration, but you can freely design them yourself.\n\nOne of them is actually mandatory, the *openid* scope, which tells the provider to return the *sub* (subject id) claim in the identity token.\n\nThis is how you could define the openid scope in code::\n\n    public static IEnumerable<IdentityResource> GetIdentityResources()\n    {\n        return new List<IdentityResource>\n        {\n            new IdentityResource(\n                name: \"openid\",\n                userClaims: new[] { \"sub\" },\n                displayName: \"Your user identifier\")\n        };\n    }\n\nBut since this is one of the standard scopes from the spec you can shorten that to::\n\n    public static IEnumerable<IdentityResource> GetIdentityResources()\n    {\n        return new List<IdentityResource>\n        {\n            new IdentityResources.OpenId()\n        };\n    }\n\n.. note:: see the reference section for more information on ``IdentityResource``.\n\nThe following example shows a custom identity resource called *profile* that represents the display name, email address and website claim::\n\n    public static IEnumerable<IdentityResource> GetIdentityResources()\n    {\n        return new List<IdentityResource>\n        {\n            new IdentityResource(\n                name: \"profile\",\n                userClaims: new[] { \"name\", \"email\", \"website\" },\n                displayName: \"Your profile data\")\n        };\n    }\n\nOnce the resource is defined, you can give access to it to a client via the ``AllowedScopes`` option (other properties omitted)::\n\n    var client = new Client\n    {\n        ClientId = \"client\",\n        \n        AllowedScopes = { \"openid\", \"profile\" }\n    };\n\n\nThe client can then request the resource using the scope parameter (other parameters omitted)::\n\n    https://demo.identityserver8.io/connect/authorize?client_id=client&scope=openid profile\n\nIdentityServer will then use the scope names to create a list of requested claim types, \nand present that to your implementation of the :ref:`profile service <refProfileService>`.\n\n.. _refApiResources:\nAPIs\n----\nDesigning your API surface can be a complicated task. IdentityServer provides a couple of primitives to help you with that.\n\nThe original OAuth 2.0 specification has the concept of scopes, which is just defined as *the scope of access* that the client requests.\nTechnically speaking, the *scope* parameter is a list of space delimited values - you need to provide the structure and semantics of it.\n\nIn more complex systems, often the notion of a *resource* is introduced. This might be e.g. a physical or logical API. \nIn turn each API can potentially have scopes as well. Some scopes might be exclusive to that resource, and some scopes might be shared.\n\nLet's start with simple scopes first, and then we'll have a look how resources can help structure scopes.\n\nScopes\n^^^^^^\nLet's model something very simple - a system that has three logical operations *read*, *write*, and *delete*.\n\nYou can define them using the ``ApiScope`` class::\n\n    public static IEnumerable<ApiScope> GetApiScopes()\n    {\n        return new List<ApiScope>\n        {\n            new ApiScope(name: \"read\",   displayName: \"Read your data.\"),\n            new ApiScope(name: \"write\",  displayName: \"Write your data.\"),\n            new ApiScope(name: \"delete\", displayName: \"Delete your data.\")\n        };\n    }\n\nYou can then assign the scopes to various clients, e.g.::\n\n    var webViewer = new Client\n    {\n        ClientId = \"web_viewer\",\n        \n        AllowedScopes = { \"openid\", \"profile\", \"read\" }\n    };\n\n    var mobileApp = new Client\n    {\n        ClientId = \"mobile_app\",\n        \n        AllowedScopes = { \"openid\", \"profile\", \"read\", \"write\", \"delete\" }\n    }\n\nAuthorization based on Scopes\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nWhen a client asks for a scope (and that scope is allowed via configuration and not denied via consent), \nthe value of that scope will be included in the resulting access token as a claim of type *scope* (for both JWTs and introspection), e.g.::\n\n    {\n        \"typ\": \"at+jwt\"\n    }.\n    {\n        \"client_id\": \"mobile_app\",\n        \"sub\": \"123\",\n\n        \"scope\": \"read write delete\"\n    }\n\nThe consumer of the access token can use that data to make sure that the client is actually allowed to invoke the corresponding functionality.\n\n.. note:: Be aware, that scopes are purely for authorizing clients - not users. IOW - the *write* scope allows the client to invoke the functionality associated with that. Still that client can most probably only write the data the belongs to the current user. This additional user centric authorization is application logic and not covered by OAuth.\n\nYou can add more identity information about the user by deriving additional claims from the scope request. The following scope definition tells the configuration system,\nthat when a *write* scope gets granted, the *user_level* claim should be added to the access token::\n\n    var writeScope = new ApiScope(\n        name: \"write\",\n        displayName: \"Write your data.\",\n        userClaims: new[] { \"user_level\" });\n\nThis will pass the *user_level* claim as a requested claim type to the profile service, \nso that the consumer of the access token can use this data as input for authorization decisions or business logic.\n\n.. note:: When using the scope-only model, no aud (audience) claim will be added to the token, since this concept does not apply. If you need an aud claim, you can enable the ``EmitStaticAudience`` setting on the options. This will emit an aud claim in the ``issuer_name/resources`` format. If you need more control of the aud claim, use API resources.\n\nParameterized Scopes\n^^^^^^^^^^^^^^^^^^^^\nSometimes scopes have a certain structure, e.g. a scope name with an additional parameter: *transaction:id* or *read_patient:patientid*.\n\nIn this case you would create a scope without the parameter part and assign that name to a client, but in addition provide some logic to parse the structure\nof the scope at runtime using the ``IScopeParser`` interface or by deriving from our default implementation, e.g.::\n\n    public class ParameterizedScopeParser : DefaultScopeParser\n    {\n        public ParameterizedScopeParser(ILogger<DefaultScopeParser> logger) : base(logger)\n        {\n        }\n\n        public override void ParseScopeValue(ParseScopeContext scopeContext)\n        {\n            const string transactionScopeName = \"transaction\";\n            const string separator = \":\";\n            const string transactionScopePrefix = transactionScopeName + separator;\n\n            var scopeValue = scopeContext.RawValue;\n\n            if (scopeValue.StartsWith(transactionScopePrefix))\n            {\n                // we get in here with a scope like \"transaction:something\"\n                var parts = scopeValue.Split(separator, StringSplitOptions.RemoveEmptyEntries);\n                if (parts.Length == 2)\n                {\n                    scopeContext.SetParsedValues(transactionScopeName, parts[1]);\n                }\n                else\n                {\n                    scopeContext.SetError(\"transaction scope missing transaction parameter value\");\n                }\n            }\n            else if (scopeValue != transactionScopeName)\n            {\n                // we get in here with a scope not like \"transaction\"\n                base.ParseScopeValue(scopeContext);\n            }\n            else\n            {\n                // we get in here with a scope exactly \"transaction\", which is to say we're ignoring it \n                // and not including it in the results\n                scopeContext.SetIgnore();\n            }\n        }\n    }\n\nYou then have access to the parsed value throughout the pipeline, e.g. in the profile service::\n\n    public class HostProfileService : IProfileService\n    {\n        public override async Task GetProfileDataAsync(ProfileDataRequestContext context)\n        {\n            var transaction = context.RequestedResources.ParsedScopes.FirstOrDefault(x => x.ParsedName == \"transaction\");\n            if (transaction?.ParsedParameter != null)\n            {\n                context.IssuedClaims.Add(new Claim(\"transaction_id\", transaction.ParsedParameter));\n            }\n        }\n    }\n\nAPI Resources\n^^^^^^^^^^^^^\nWhen the API surface gets larger, a flat list of scopes like the one used above might not be feasible.\n\nYou typically need to introduce some sort of namespacing to organize the scope names, and maybe you also want to group them together and \nget some higher-level constructs like an *audience* claim in access tokens.\nYou might also have scenarios, where multiple resources should support the same scope names, whereas sometime you explicitly want to isolate a scope to a certain resource.\n\nIn IdentityServer, the ``ApiResource`` class allows some additional organization. Let's use the following scope definition::\n\n    public static IEnumerable<ApiScope> GetApiScopes()\n    {\n        return new List<ApiScope>\n        {\n            // invoice API specific scopes\n            new ApiScope(name: \"invoice.read\",   displayName: \"Reads your invoices.\"),\n            new ApiScope(name: \"invoice.pay\",    displayName: \"Pays your invoices.\"),\n\n            // customer API specific scopes\n            new ApiScope(name: \"customer.read\",    displayName: \"Reads you customers information.\"),\n            new ApiScope(name: \"customer.contact\", displayName: \"Allows contacting one of your customers.\"),\n\n            // shared scope\n            new ApiScope(name: \"manage\", displayName: \"Provides administrative access to invoice and customer data.\")\n        };\n    }\n\nWith ``ApiResource`` you can now create two logical APIs and their corresponding scopes::\n\n    public static readonly IEnumerable<ApiResource> GetApiResources()\n    { \n        return new List<ApiResource>\n        {\n            new ApiResource(\"invoice\", \"Invoice API\")\n            {\n                Scopes = { \"invoice.read\", \"invoice.pay\", \"manage\" }\n            },\n            \n            new ApiResource(\"customer\", \"Customer API\")\n            {\n                Scopes = { \"customer.read\", \"customer.contact\", \"manage\" }\n            }\n        };\n    }\n\nUsing the API resource grouping gives you the following additional features\n\n* support for the JWT *aud* claim. The value(s) of the audience claim will be the name of the API resource(s)\n* support for adding common user claims across all contained scopes\n* support for introspection by assigning an API secret to the resource\n* support for configuring the access token signing algorithm for the resource\n\nLet's have a look at some example access tokens for the above resource configuration.\n\n**Client requests** invoice.read and invoice.pay::\n\n    {\n        \"typ\": \"at+jwt\"\n    }.\n    {\n        \"client_id\": \"client\",\n        \"sub\": \"123\",\n\n        \"aud\": \"invoice\",\n        \"scope\": \"invoice.read invoice.pay\"\n    }\n\n**Client requests** invoice.read and customer.read::\n\n    {\n        \"typ\": \"at+jwt\"\n    }.\n    {\n        \"client_id\": \"client\",\n        \"sub\": \"123\",\n\n        \"aud\": [ \"invoice\", \"customer\" ]\n        \"scope\": \"invoice.read customer.read\"\n    }\n\n**Client requests** manage::\n\n    {\n        \"typ\": \"at+jwt\"\n    }.\n    {\n        \"client_id\": \"client\",\n        \"sub\": \"123\",\n\n        \"aud\": [ \"invoice\", \"customer\" ]\n        \"scope\": \"manage\"\n    }\n\nMigration steps to v4\n^^^^^^^^^^^^^^^^^^^^^\nAs described above, starting with v4, scopes have their own definition and can optionally be referenced by resources. \nBefore v4, scopes were always contained within a resource.\n\nTo migrate to v4 you need to split up scope and resource registration, typically by first registering all your scopes\n(e.g. using the ``AddInMemoryApiScopes`` method), and then register the API resources (if any) afterwards.\nThe API resources will then reference the prior registered scopes by name.\n"
  },
  {
    "path": "docs/topics/signin.rst",
    "content": ".. _refSignIn:\nSign-in\n=======\n\nIn order for IdentityServer to issue tokens on behalf of a user, that user must sign-in to IdentityServer.\n\nCookie authentication\n^^^^^^^^^^^^^^^^^^^^^\nAuthentication is tracked with a cookie managed by the `cookie authentication <https://docs.microsoft.com/en-us/aspnet/core/security/authentication/cookie>`_ handler from ASP.NET Core.\n\nIdentityServer registers two cookie handlers (one for the authentication session and one for temporary external cookies). These are used by default and you can get their\nnames from the ``IdentityServerConstants`` class (``DefaultCookieAuthenticationScheme`` and ``ExternalCookieAuthenticationScheme``) if you want to reference them manually.\n\nOnly the basic settings are exposed for these cookies (expiration and sliding), but you can register your own cookie handlers if you need more control.\nIdentityServer uses whichever cookie handler matches the ``DefaultAuthenticateScheme`` as configured on the ``AuthenticationOptions`` when using ``AddAuthentication`` from ASP.NET Core.\n\n.. note:: In addition to the authentication cookie, IdentityServer will issue an additional cookie which defaults to the name \"idsrv.session\". This cookie is derived from the main authentication cookie, and it used for the check session endpoint for :ref:`browser-based JavaScript clients at signout time <refSignOut>`. It is kept in sync with the authentication cookie, and is removed when the user signs out.\n\nOverriding cookie handler configuration\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nIf you wish to use your own cookie authentication handler, then you must configure it yourself.\nThis must be done in ``ConfigureServices`` after registering IdentityServer in DI (with ``AddIdentityServer``).\nFor example::\n\n    services.AddIdentityServer()\n        .AddInMemoryClients(Clients.Get())\n        .AddInMemoryIdentityResources(Resources.GetIdentityResources())\n        .AddInMemoryApiResources(Resources.GetApiResources())\n        .AddDeveloperSigningCredential()\n        .AddTestUsers(TestUsers.Users);\n\n    services.AddAuthentication(\"MyCookie\")\n        .AddCookie(\"MyCookie\", options =>\n        {\n            options.ExpireTimeSpan = ...;\n        });\n\n.. note:: IdentityServer internally calls both ``AddAuthentication`` and ``AddCookie`` with a custom scheme (via the constant ``IdentityServerConstants.DefaultCookieAuthenticationScheme``), so to override them you must make the same calls after ``AddIdentityServer``.\n\nLogin User Interface and Identity Management System\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nIdentityServer does not provide any user-interface or user database for user authentication.\nThese are things you are expected to provide or develop yourself.\n\nIf you need a starting point for a basic UI (login, logout, consent and manage grants), \nyou can use our `quickstart UI <https://github.com/alexhiggins732/IdentityServer8.Quickstart.UI>`_.\n\nThe quickstart UI authenticates users against an in-memory database. You would replace those bits with access to your real user store.\nWe have samples that use :ref:`ASP.NET Identity <refAspNetIdentityQuickstart>`.\n\nLogin Workflow\n^^^^^^^^^^^^^^\nWhen IdentityServer receives a request at the authorization endpoint and the user is not authenticated, the user will be redirected to the configured login page.\nYou must inform IdentityServer of the path to your login page via the ``UserInteraction`` settings on the :ref:`options <refOptions>` (the default is ``/account/login``).\nA ``returnUrl`` parameter will be passed informing your login page where the user should be redirected once login is complete.\n\n.. image:: images/signin_flow.png\n\n.. Note:: Beware `open-redirect attacks <https://en.wikipedia.org/wiki/URL_redirection#Security_issues>`_ via the ``returnUrl`` parameter. You should validate that the ``returnUrl`` refers to well-known location. See the :ref:`interaction service <refInteractionService>` for APIs to validate the ``returnUrl`` parameter.\n\nLogin Context\n^^^^^^^^^^^^^\nOn your login page you might require information about the context of the request in order to customize the login experience \n(such as client, prompt parameter, IdP hint, or something else).\nThis is made available via the ``GetAuthorizationContextAsync`` API on the :ref:`interaction service <refInteractionService>`.\n\nIssuing a cookie and Claims\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThere are authentication-related extension methods on the ``HttpContext`` from ASP.NET Core to issue the authentication cookie and sign a user in. \nThe authentication scheme used must match the cookie handler you are using (see above).\n\nWhen you sign the user in you must issue at least a ``sub`` claim and a ``name`` claim.\nIdentityServer also provides a few ``SignInAsync`` extension methods on the ``HttpContext`` to make this more convenient.\n\nYou can also optionally issue an ``idp`` claim (for the identity provider name), an ``amr`` claim (for the authentication method used), and/or an ``auth_time`` claim (for the epoch time a user authenticated).\nIf you do not provide these, then IdentityServer will provide default values.\n"
  },
  {
    "path": "docs/topics/signin_external_providers.rst",
    "content": ".. _refExternalIdentityProviders:\nSign-in with External Identity Providers\n========================================\n\nASP.NET Core has a flexible way to deal with external authentication. This involves a couple of steps.\n\n.. Note:: If you are using ASP.NET Identity, many of the underlying technical details are hidden from you. It is recommended that you also read the Microsoft `docs <https://docs.microsoft.com/en-us/aspnet/core/security/authentication/social/>`_ and do the ASP.NET Identity :ref:`quickstart <refAspNetIdentityQuickstart>`.\n\nAdding authentication handlers for external providers\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThe protocol implementation that is needed to talk to an external provider is encapsulated in an *authentication handler*.\nSome providers use proprietary protocols (e.g. social providers like Facebook) and some use standard protocols, e.g. OpenID Connect, WS-Federation or SAML2p.\n\nSee this :ref:`quickstart <refExternalAuthenticationQuickstart>` for step-by-step instructions for adding external authentication and configuring it.\n\nThe role of cookies\n^^^^^^^^^^^^^^^^^^^\nOne option on an external authentication handlers is called ``SignInScheme``, e.g.::\n\n    services.AddAuthentication()\n        .AddGoogle(\"Google\", options =>\n        {\n            options.SignInScheme = \"scheme of cookie handler to use\";\n\n            options.ClientId = \"...\";\n            options.ClientSecret = \"...\";\n        })\n\nThe signin scheme specifies the name of the cookie handler that will temporarily store the outcome of the external authentication, \ne.g. the claims that got sent by the external provider. This is necessary, since there are typically a couple of redirects involved until you are done with the \nexternal authentication process.\n\nGiven that this is such a common practise, IdentityServer registers a cookie handler specifically for this external provider workflow.\nThe scheme is represented via the ``IdentityServerConstants.ExternalCookieAuthenticationScheme`` constant.\nIf you were to use our external cookie handler, then for the ``SignInScheme`` above you'd assign the value to be the ``IdentityServerConstants.ExternalCookieAuthenticationScheme`` constant::\n\n    services.AddAuthentication()\n        .AddGoogle(\"Google\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n            options.ClientId = \"...\";\n            options.ClientSecret = \"...\";\n        })\n\nYou can also register your own custom cookie handler instead, like this::\n\n    services.AddAuthentication()\n        .AddCookie(\"YourCustomScheme\")\n        .AddGoogle(\"Google\", options =>\n        {\n            options.SignInScheme = \"YourCustomScheme\";\n\n            options.ClientId = \"...\";\n            options.ClientSecret = \"...\";\n        })\n\n.. Note:: For specialized scenarios, you can also short-circuit the external cookie mechanism and forward the external user directly to the main cookie handler. This typically involves handling events on the external handler to make sure you do the correct claims transformation from the external identity source.\n\nTriggering the authentication handler\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nYou invoke an external authentication handler via the ``ChallengeAsync`` extension method on the ``HttpContext`` (or using the MVC ``ChallengeResult``).\n\nYou typically want to pass in some options to the challenge operation, e.g. the path to your callback page and the name of the provider for bookkeeping, e.g.::\n\n    var callbackUrl = Url.Action(\"ExternalLoginCallback\");\n    \n    var props = new AuthenticationProperties\n    {\n        RedirectUri = callbackUrl,\n        Items = \n        { \n            { \"scheme\", provider },\n            { \"returnUrl\", returnUrl }\n        }\n    };\n    \n    return Challenge(provider, props);\n\nHandling the callback and signing in the user\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nOn the callback page your typical tasks are:\n\n* inspect the identity returned by the external provider.\n* make a decision how you want to deal with that user. This might be different based on the fact if this is a new user or a returning user.\n* new users might need additional steps and UI before they are allowed in.\n* probably create a new internal user account that is linked to the external provider.\n* store the external claims that you want to keep.\n* delete the temporary cookie\n* sign-in the user\n\n**Inspecting the external identity**::\n\n    // read external identity from the temporary cookie\n    var result = await HttpContext.AuthenticateAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n    if (result?.Succeeded != true)\n    {\n        throw new Exception(\"External authentication error\");\n    }\n\n    // retrieve claims of the external user\n    var externalUser = result.Principal;\n    if (externalUser == null)\n    {\n        throw new Exception(\"External authentication error\");\n    }\n\n    // retrieve claims of the external user\n    var claims = externalUser.Claims.ToList();\n\n    // try to determine the unique id of the external user - the most common claim type for that are the sub claim and the NameIdentifier\n    // depending on the external provider, some other claim type might be used\n    var userIdClaim = claims.FirstOrDefault(x => x.Type == JwtClaimTypes.Subject);\n    if (userIdClaim == null)\n    {\n        userIdClaim = claims.FirstOrDefault(x => x.Type == ClaimTypes.NameIdentifier);\n    }\n    if (userIdClaim == null)\n    {\n        throw new Exception(\"Unknown userid\");\n    }\n    \n    var externalUserId = userIdClaim.Value;\n    var externalProvider = userIdClaim.Issuer;\n\n    // use externalProvider and externalUserId to find your user, or provision a new user\n\n**Clean-up and sign-in**::\n\n    // issue authentication cookie for user\n    await HttpContext.SignInAsync(new IdentityServerUser(user.SubjectId) {\n        DisplayName = user.Username,\n        IdentityProvider = provider,\n        AdditionalClaims = additionalClaims,\n        AuthenticationTime = DateTime.Now\n    });\n\n    // delete temporary cookie used during external authentication\n    await HttpContext.SignOutAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n    // validate return URL and redirect back to authorization endpoint or a local page\n    if (_interaction.IsValidReturnUrl(returnUrl) || Url.IsLocalUrl(returnUrl))\n    {\n        return Redirect(returnUrl);\n    }\n\n    return Redirect(\"~/\");\n\nState, URL length, and ISecureDataFormat\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nWhen redirecting to an external provider for sign-in, frequently state from the client application must be round-tripped.\nThis means that state is captured prior to leaving the client and preserved until the user has returned to the client application.\nMany protocols, including OpenID Connect, allow passing some sort of state as a parameter as part of the request, and the identity provider will return that state on the response.\nThe OpenID Connect authentication handler provided by ASP.NET Core utilizes this feature of the protocol, and that is how it implements the ``returnUrl`` feature mentioned above.\n\nThe problem with storing state in a request parameter is that the request URL can get too large (over the common limit of 2000 characters).\nThe OpenID Connect authentication handler does provide an extensibility point to store the state in your server, rather than in the request URL. \nYou can implement this yourself by implementing ``ISecureDataFormat<AuthenticationProperties>`` and configuring it on the `OpenIdConnectOptions <https://github.com/aspnet/AspNetCore/blob/main/src/Security/Authentication/OpenIdConnect/src/OpenIdConnectOptions.cs#L249>`_.\n\nFortunately, IdentityServer provides an implementation of this for you, backed by the ``IDistributedCache`` implementation registered in the DI container (e.g. the standard ``MemoryDistributedCache``).\nTo use the IdentityServer provided secure data format implementation, simply call the ``AddOidcStateDataFormatterCache`` extension method on the ``IServiceCollection`` when configuring DI.\nIf no parameters are passed, then all OpenID Connect handlers configured will use the IdentityServer provided secure data format implementation::\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        // configures the OpenIdConnect handlers to persist the state parameter into the server-side IDistributedCache.\n        services.AddOidcStateDataFormatterCache();\n\n        services.AddAuthentication()\n            .AddOpenIdConnect(\"demoidsrv\", \"IdentityServer\", options =>\n            {\n                // ...\n            })\n            .AddOpenIdConnect(\"aad\", \"Azure AD\", options =>\n            {\n                // ...\n            })\n            .AddOpenIdConnect(\"adfs\", \"ADFS\", options =>\n            {\n                // ...\n            });\n    }\n\n\nIf only particular schemes are to be configured, then pass those schemes as parameters::\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        // configures the OpenIdConnect handlers to persist the state parameter into the server-side IDistributedCache.\n        services.AddOidcStateDataFormatterCache(\"aad\", \"demoidsrv\");\n\n        services.AddAuthentication()\n            .AddOpenIdConnect(\"demoidsrv\", \"IdentityServer\", options =>\n            {\n                // ...\n            })\n            .AddOpenIdConnect(\"aad\", \"Azure AD\", options =>\n            {\n                // ...\n            })\n            .AddOpenIdConnect(\"adfs\", \"ADFS\", options =>\n            {\n                // ...\n            });\n    }\n\n"
  },
  {
    "path": "docs/topics/signout.rst",
    "content": ".. _refSignOut:\nSign-out\n========\n\nSigning out of IdentityServer is as simple as removing the authentication cookie, \nbut for doing a complete federated sign-out, we must consider signing the user out of the client applications (and maybe even up-stream identity providers) as well.\n\nRemoving the authentication cookie\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nTo remove the authentication cookie, simply use the ``SignOutAsync`` extension method on the ``HttpContext``.\nYou will need to pass the scheme used (which is provided by ``IdentityServerConstants.DefaultCookieAuthenticationScheme`` unless you have changed it)::\n\n    await HttpContext.SignOutAsync(IdentityServerConstants.DefaultCookieAuthenticationScheme);\n\nOr you can use the convenience extension method that is provided by IdentityServer::\n\n    await HttpContext.SignOutAsync();\n\n.. Note:: Typically you should prompt the user for signout (meaning require a POST), otherwise an attacker could hotlink to your logout page causing the user to be automatically logged out.\n\nNotifying clients that the user has signed-out\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nAs part of the signout process you will want to ensure client applications are informed that the user has signed out.\nIdentityServer supports the `front-channel <https://openid.net/specs/openid-connect-frontchannel-1_0.html>`_ specification for server-side clients (e.g. MVC),\nthe `back-channel <https://openid.net/specs/openid-connect-backchannel-1_0.html>`_  specification for server-side clients (e.g. MVC),\nand the `session management <https://openid.net/specs/openid-connect-session-1_0.html>`_ specification for browser-based JavaScript clients (e.g. SPA, React, Angular, etc.).\n\n**Front-channel server-side clients**\n\nTo signout the user from the server-side client applications via the front-channel spec, the \"logged out\" page in IdentityServer must render an ``<iframe>`` to notify the clients that the user has signed out.\nClients that wish to be notified must have the ``FrontChannelLogoutUri`` configuration value set.\nIdentityServer tracks which clients the user has signed into, and provides an API called ``GetLogoutContextAsync`` on the ``IIdentityServerInteractionService`` (:ref:`details <refInteractionService>`). \nThis API returns a ``LogoutRequest`` object with a ``SignOutIFrameUrl`` property that your logged out page must render into an ``<iframe>``.\n\n**Back-channel server-side clients**\n\nTo signout the user from the server-side client applications via the back-channel spec the ``IBackChannelLogoutService`` service can be used. \nIdentityServer will automatically use this service when your logout page removes the user's authentication cookie via a call to ``HttpContext.SignOutAsync``.\nClients that wish to be notified must have the ``BackChannelLogoutUri`` configuration value set.\n\n**Browser-based JavaScript clients**\n\nGiven how the `session management <https://openid.net/specs/openid-connect-session-1_0.html>`_ specification is designed, there is nothing special in IdentityServer that you need to do to notify these clients that the user has signed out.\nThe clients, though, must perform monitoring on the `check_session_iframe`, and this is implemented by the `oidc-client JavaScript library <https://github.com/IdentityModel/oidc-client-js/>`_.\n\nSign-out initiated by a client application\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nIf sign-out was initiated by a client application, then the client first redirected the user to the :ref:`end session endpoint <refEndSession>`.\nProcessing at the end session endpoint might require some temporary state to be maintained (e.g. the client's post logout redirect uri) across the redirect to the logout page.\nThis state might be of use to the logout page, and the identifier for the state is passed via a `logoutId` parameter to the logout page.\n\nThe ``GetLogoutContextAsync`` API on the :ref:`interaction service <refInteractionService>` can be used to load the state.\nOf interest on the ``LogoutRequest`` model context class is the ``ShowSignoutPrompt`` which indicates if the request for sign-out has been authenticated, and therefore it's safe to not prompt the user for sign-out.\n\nBy default this state is managed as a protected data structure passed via the `logoutId` value.\nIf you wish to use some other persistence between the end session endpoint and the logout page, then you can implement ``IMessageStore<LogoutMessage>`` and register the implementation in DI.\n"
  },
  {
    "path": "docs/topics/signout_external_providers.rst",
    "content": ".. _refSignOutExternal:\nSign-out of External Identity Providers\n=======================================\n\nWhen a user is :ref:`signing-out <refSignOut>` of IdentityServer, and they have used an :ref:`external identity provider <refExternalIdentityProviders>` to sign-in then it is likely that they should be redirected to also sign-out of the external provider.\nNot all external providers support sign-out, as it depends on the protocol and features they support.\n\nTo detect that a user must be redirected to an external identity provider for sign-out is typically done by using a ``idp`` claim issued into the cookie at IdentityServer.\nThe value set into this claim is the ``AuthenticationScheme`` of the corresponding authentication middleware.\nAt sign-out time this claim is consulted to know if an external sign-out is required.\n\nRedirecting the user to an external identity provider is problematic due to the cleanup and state management already required by the normal sign-out workflow.\nThe only way to then complete the normal sign-out and cleanup process at IdentityServer is to then request from the external identity provider that after its logout that the user be redirected back to IdentityServer.\nNot all external providers support post-logout redirects, as it depends on the protocol and features they support.\n\nThe workflow at sign-out is then to revoke IdentityServer's authentication cookie, and then redirect to the external provider requesting a post-logout redirect.\nThe post-logout redirect should maintain the necessary sign-out state described :ref:`here <refSignOut>` (i.e. the ``logoutId`` parameter value).\nTo redirect back to IdentityServer after the external provider sign-out, the ``RedirectUri`` should be used on the ``AuthenticationProperties`` when using ASP.NET Core's ``SignOutAsync`` API, for example::\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Logout(LogoutInputModel model)\n    {\n        // build a model so the logged out page knows what to display\n        var vm = await _account.BuildLoggedOutViewModelAsync(model.LogoutId);\n\n        var user = HttpContext.User;\n        if (user?.Identity.IsAuthenticated == true)\n        {\n            // delete local authentication cookie\n            await HttpContext.SignOutAsync();\n\n            // raise the logout event\n            await _events.RaiseAsync(new UserLogoutSuccessEvent(user.GetSubjectId(), user.GetName()));\n        }\n\n        // check if we need to trigger sign-out at an upstream identity provider\n        if (vm.TriggerExternalSignout)\n        {\n            // build a return URL so the upstream provider will redirect back\n            // to us after the user has logged out. this allows us to then\n            // complete our single sign-out processing.\n            string url = Url.Action(\"Logout\", new { logoutId = vm.LogoutId });\n\n            // this triggers a redirect to the external provider for sign-out\n            return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);\n        }\n\n        return View(\"LoggedOut\", vm);\n    }\n\nOnce the user is signed-out of the external provider and then redirected back, the normal sign-out processing at IdentityServer should execute which involves processing the ``logoutId`` and doing all necessary cleanup.\n"
  },
  {
    "path": "docs/topics/signout_federated.rst",
    "content": ".. _refSignOutFederated:\nFederated Sign-out\n==================\n\nFederated sign-out is the situation where a user has used an external identity provider to log into IdentityServer, and then the user logs out of that external identity provider via a workflow unknown to IdentityServer.\nWhen the user signs out, it will be useful for IdentityServer to be notified so that it can sign the user out of IdentityServer and all of the applications that use IdentityServer.\n\nNot all external identity providers support federated sign-out, but those that do will provide a mechanism to notify clients that the user has signed out.\nThis notification usually comes in the form of a request in an ``<iframe>`` from the external identity provider's \"logged out\" page.\nIdentityServer must then notify all of its clients (as discussed :ref:`here <refSignOut>`), also typically in the form of a request in an ``<iframe>`` from within the external identity provider's ``<iframe>``.\n\nWhat makes federated sign-out a special case (when compared to a normal :ref:`sign-out <refSignOut>`) is that the federated sign-out request is not to the normal sign-out endpoint in IdentityServer.\nIn fact, each external IdentityProvider will have a different endpoint into your IdentityServer host. \nThis is due to that fact that each external identity provider might use a different protocol, and each middleware listens on different endpoints.\n\nThe net effect of all of these factors is that there is no \"logged out\" page being rendered as we would on the normal sign-out workflow, \nwhich means we are missing the sign-out notifications to IdentityServer's clients.\nWe must add code for each of these federated sign-out endpoints to render the necessary notifications to achieve federated sign-out.\n\nFortunately IdentityServer already contains this code. \nWhen requests come into IdentityServer and invoke the handlers for external authentication providers, IdentityServer detects if these are federated signout requests and if they are it will automatically render the same ``<iframe>`` as :ref:`described here for signout <refSignOut>`.\nIn short, federated signout is automatically supported.\n"
  },
  {
    "path": "docs/topics/startup.rst",
    "content": ".. _refStartup:\nStartup\n=======\n\nIdentityServer is a combination of middleware and services.\nAll configuration is done in your startup class.\n\nConfiguring services\n^^^^^^^^^^^^^^^^^^^^\nYou add the IdentityServer services to the DI system by calling::\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        var builder = services.AddIdentityServer();\n    }\n\nOptionally you can pass in options into this call. See :ref:`here <refOptions>` for details on options.\n\nThis will return you a builder object that in turn has a number of convenience methods to wire up additional services.\n\n.. _refStartupKeyMaterial:\nKey material\n^^^^^^^^^^^^\nIdentityServer supports X.509 certificates (both raw files and a reference to the Windows certificate store), \nRSA keys and EC keys for token signatures and validation. Each key can be configured with a (compatible) signing algorithm, \ne.g. RS256, RS384, RS512, PS256, PS384, PS512, ES256, ES384 or ES512.\n\nYou can configure the key material with the following methods:\n\n* ``AddSigningCredential``\n    Adds a signing key that provides the specified key material to the various token creation/validation services.\n* ``AddDeveloperSigningCredential``\n    Creates temporary key material at startup time. This is for dev scenarios. The generated key will be persisted in the local directory by default.\n* ``AddValidationKey``\n    Adds a key for validating tokens. They will be used by the internal token validator and will show up in the discovery document.\n\nIn-Memory configuration stores\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^\n\nThe various \"in-memory\" configuration APIs allow for configuring IdentityServer from an in-memory list of configuration objects.\nThese \"in-memory\" collections can be hard-coded in the hosting application, or could be loaded dynamically from a configuration file or a database.\nBy design, though, these collections are only created when the hosting application is starting up.\n\nUse of these configuration APIs are designed for use when prototyping, developing, and/or testing where it is not necessary to dynamically consult database at runtime for the configuration data.\nThis style of configuration might also be appropriate for production scenarios if the configuration rarely changes, or it is not inconvenient to require restarting the application if the value must be changed.\n\n* ``AddInMemoryClients``\n    Registers ``IClientStore`` and ``ICorsPolicyService`` implementations based on the in-memory collection of ``Client`` configuration objects.\n* ``AddInMemoryIdentityResources``\n    Registers ``IResourceStore`` implementation based on the in-memory collection of ``IdentityResource`` configuration objects.\n* ``AddInMemoryApiScopes``\n    Registers ``IResourceStore`` implementation based on the in-memory collection of ``ApiScope`` configuration objects.\n* ``AddInMemoryApiResources``\n    Registers ``IResourceStore`` implementation based on the in-memory collection of ``ApiResource`` configuration objects.\n\nTest stores\n^^^^^^^^^^^\n\nThe ``TestUser`` class models a user, their credentials, and claims in IdentityServer. \nUse of ``TestUser`` is similar to the use of the \"in-memory\" stores in that it is intended for when prototyping, developing, and/or testing.\nThe use of ``TestUser`` is not recommended in production.\n\n* ``AddTestUsers``\n    Registers ``TestUserStore`` based on a collection of ``TestUser`` objects.\n    ``TestUserStore`` is used by the default quickstart UI.\n    Also registers implementations of ``IProfileService`` and ``IResourceOwnerPasswordValidator``.\n\nAdditional services\n^^^^^^^^^^^^^^^^^^^\n\n* ``AddExtensionGrantValidator``\n    Adds ``IExtensionGrantValidator`` implementation for use with extension grants.\n\n* ``AddSecretParser``\n    Adds ``ISecretParser`` implementation for parsing client or API resource credentials.\n\n* ``AddSecretValidator``\n    Adds ``ISecretValidator`` implementation for validating client or API resource credentials against a credential store.\n\n* ``AddResourceOwnerValidator``\n    Adds ``IResourceOwnerPasswordValidator`` implementation for validating user credentials for the resource owner password credentials grant type.\n\n* ``AddProfileService``\n    Adds ``IProfileService`` implementation for connecting to your :ref:`custom user profile store<refProfileService>`.\n    The ``DefaultProfileService`` class provides the default implementation which relies upon the authentication cookie as the only source of claims for issuing in tokens.\n\n* ``AddAuthorizeInteractionResponseGenerator``\n    Adds ``IAuthorizeInteractionResponseGenerator`` implementation to customize logic at authorization endpoint for when a user must be shown a UI for error, login, consent, or any other custom page.\n    The ``AuthorizeInteractionResponseGenerator`` class provides a default implementation, so consider deriving from this existing class if you need to augment the existing behavior.\n\n* ``AddCustomAuthorizeRequestValidator``\n    Adds ``ICustomAuthorizeRequestValidator`` implementation to customize request parameter validation at the authorization endpoint.\n\n* ``AddCustomTokenRequestValidator``\n    Adds ``ICustomTokenRequestValidator`` implementation to customize request parameter validation at the token endpoint.\n\n* ``AddRedirectUriValidator``\n    Adds ``IRedirectUriValidator`` implementation to customize redirect URI validation.\n\n* ``AddAppAuthRedirectUriValidator``\n    Adds a an \"AppAuth\" (OAuth 2.0 for Native Apps) compliant redirect URI validator (does strict validation but also allows http://127.0.0.1 with random port).\n\n* ``AddJwtBearerClientAuthentication``\n    Adds support for client authentication using JWT bearer assertions.\n\n* ``AddMutualTlsSecretValidators``\n    Adds the X509 secret validators for mutual TLS.\n\nCaching\n^^^^^^^\n\nClient and resource configuration data is used frequently by IdentityServer.\nIf this data is being loaded from a database or other external store, then it might be expensive to frequently re-load the same data.\n\n* ``AddInMemoryCaching``\n    To use any of the caches described below, an implementation of ``ICache<T>`` must be registered in DI.\n    This API registers a default in-memory implementation of ``ICache<T>`` that's based on ASP.NET Core's ``MemoryCache``.\n\n* ``AddClientStoreCache``\n    Registers a ``IClientStore`` decorator implementation which will maintain an in-memory cache of ``Client`` configuration objects.\n    The cache duration is configurable on the ``Caching`` configuration options on the ``IdentityServerOptions``.\n\n* ``AddResourceStoreCache``\n    Registers a ``IResourceStore`` decorator implementation which will maintain an in-memory cache of ``IdentityResource`` and ``ApiResource`` configuration objects.\n    The cache duration is configurable on the ``Caching`` configuration options on the ``IdentityServerOptions``.\n\n* ``AddCorsPolicyCache``\n    Registers a ``ICorsPolicyService`` decorator implementation which will maintain an in-memory cache of the results of the CORS policy service evaluation.\n    The cache duration is configurable on the ``Caching`` configuration options on the ``IdentityServerOptions``.\n\nFurther customization of the cache is possible:\n\nThe default caching relies upon the ``ICache<T>`` implementation.\nIf you wish to customize the caching behavior for the specific configuration objects, you can replace this implementation in the dependency injection system.\n\nThe default implementation of the ``ICache<T>`` itself relies upon the ``IMemoryCache`` interface (and ``MemoryCache`` implementation) provided by .NET.\nIf you wish to customize the in-memory caching behavior, you can replace the ``IMemoryCache`` implementation in the dependency injection system.\n\nConfiguring the pipeline\n^^^^^^^^^^^^^^^^^^^^^^^^\nYou need to add IdentityServer to the pipeline by calling::\n\n    public void Configure(IApplicationBuilder app)\n    {\n        app.UseIdentityServer();\n    }\n\n.. note:: ``UseIdentityServer`` includes a call to ``UseAuthentication``, so it's not necessary to have both.\n\nThere is no additional configuration for the middleware.\n\nBe aware that order matters in the pipeline. \nFor example, you will want to add IdentitySever before the UI framework that implements the login screen.\n"
  },
  {
    "path": "docs/topics/tools.rst",
    "content": "Tools\n=====\n\nThe ``IdentityServerTools`` class is a collection of useful internal tools that you might need when writing extensibility code\nfor IdentityServer. To use it, inject it into your code, e.g. a controller::\n\n    public MyController(IdentityServerTools tools)\n    {\n        _tools = tools;\n    }\n\nThe ``IssueJwtAsync`` method allows creating JWT tokens using the IdentityServer token creation engine. The ``IssueClientJwtAsync`` is an easier\nversion of that for creating tokens for server-to-server communication (e.g. when you have to call an IdentityServer protected API from your code)::\n\n    public async Task<IActionResult> MyAction()\n    {\n        var token = await _tools.IssueClientJwtAsync(\n            clientId: \"client_id\",\n            lifetime: 3600,\n            audiences: new[] { \"backend.api\" });\n\n        // more code\n    }"
  },
  {
    "path": "docs/topics/windows.rst",
    "content": "Windows Authentication\n======================\nThere are several ways how you can enable Windows authentication in ASP.NET Core (and thus in IdentityServer).\n\n* On Windows using IIS hosting (both in- and out-of process)\n* On Windows using HTTP.SYS hosting\n* On any platform using the Negotiate authentication handler (added in ASP.NET Core 3.0)\n\n.. Note:: We only have documentation for IIS hosting. If you want to contribute to the docs, please open a PR. thanks!\n\nOn Windows using IIS hosting\n^^^^^^^^^^^^^^^^^^^^^^^^^^^^\nThe typical ``CreateDefaultBuilder`` host setup enables support for IIS-based Windows authentication when hosting in IIS.\nMake sure that Windows authentication is enabled in ``launchSettings.json`` or your IIS configuration.\n\nThe IIS integration layer will configure a Windows authentication handler into DI that can be invoked via the authentication service.\nTypically in IdentityServer it is advisable to disable the automatic behavior. \n\nThis is done in ``ConfigureServices`` (details vary depending on in-proc vs out-of-proc hosting)::\n\n    // configures IIS out-of-proc settings (see https://github.com/aspnet/AspNetCore/issues/14882)\n    services.Configure<IISOptions>(iis =>\n    {\n        iis.AuthenticationDisplayName = \"Windows\";\n        iis.AutomaticAuthentication = false;\n    });\n\n    // ..or configures IIS in-proc settings\n    services.Configure<IISServerOptions>(iis =>\n    {\n        iis.AuthenticationDisplayName = \"Windows\";\n        iis.AutomaticAuthentication = false;\n    });\n\nYou trigger Windows authentication by calling ``ChallengeAsync`` on the ``Windows`` scheme (or if you want to use a constant: ``Microsoft.AspNetCore.Server.IISIntegration.IISDefaults.AuthenticationScheme``).\n\nThis will send the ``Www-Authenticate`` header back to the browser which will then re-load the current URL including the Windows identity.\nYou can tell that Windows authentication was successful, when you call ``AuthenticateAsync`` on the ``Windows`` scheme and the principal returned\nis of type ``WindowsPrincipal``.\n\nThe principal will have information like user and group SID and the Windows account name. The following snippet shows how to\ntrigger authentication, and if successful convert the information into a standard ``ClaimsPrincipal`` for the temp-Cookie approach::\n\n    private async Task<IActionResult> ChallengeWindowsAsync(string returnUrl)\n    {\n        // see if windows auth has already been requested and succeeded\n        var result = await HttpContext.AuthenticateAsync(\"Windows\");\n        if (result?.Principal is WindowsPrincipal wp)\n        {\n            // we will issue the external cookie and then redirect the\n            // user back to the external callback, in essence, treating windows\n            // auth the same as any other external authentication mechanism\n            var props = new AuthenticationProperties()\n            {\n                RedirectUri = Url.Action(\"Callback\"),\n                Items =\n                {\n                    { \"returnUrl\", returnUrl },\n                    { \"scheme\", \"Windows\" },\n                }\n            };\n\n            var id = new ClaimsIdentity(\"Windows\");\n\n            // the sid is a good sub value\n            id.AddClaim(new Claim(JwtClaimTypes.Subject, wp.FindFirst(ClaimTypes.PrimarySid).Value));\n\n            // the account name is the closest we have to a display name\n            id.AddClaim(new Claim(JwtClaimTypes.Name, wp.Identity.Name));\n\n            // add the groups as claims -- be careful if the number of groups is too large\n            var wi = wp.Identity as WindowsIdentity;\n\n            // translate group SIDs to display names\n            var groups = wi.Groups.Translate(typeof(NTAccount));\n            var roles = groups.Select(x => new Claim(JwtClaimTypes.Role, x.Value));\n            id.AddClaims(roles);\n            \n\n            await HttpContext.SignInAsync(\n                IdentityServerConstants.ExternalCookieAuthenticationScheme,\n                new ClaimsPrincipal(id),\n                props);\n            return Redirect(props.RedirectUri);\n        }\n        else\n        {\n            // trigger windows auth\n            // since windows auth don't support the redirect uri,\n            // this URL is re-triggered when we call challenge\n            return Challenge(\"Windows\");\n        }\n    }\n"
  },
  {
    "path": "global.json",
    "content": "{\n  \"sdk\": {\n    \"version\": \"8.0.100\"\n  }\n}"
  },
  {
    "path": "main.cmd",
    "content": "start ./src/IdentityServer8/IdentityServer8.sln"
  },
  {
    "path": "samples/Clients/Clients.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft\n Written by Alexander Higgins https://github.com/alexhiggins732/ \n \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code for this software can be found at https://github.com/alexhiggins732/IdentityServer8\n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n\n*/\n"
  },
  {
    "path": "samples/Clients/ClientsGlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Clients;"
  },
  {
    "path": "samples/Clients/Directory.Build.props",
    "content": "<Project>\n    <ImportGroup>\n        <Import Project=\"../Directory.Build.props\" />\n    </ImportGroup>\n\t<ItemGroup>\n        <Compile Include=\"$(SolutionDir)..\\ClientsGlobalUsings.cs\" Link=\"ClientsGlobalUsings.cs\" />\n    </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/old/Clients.sln",
    "content": "﻿\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 10.0.40219.1\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Solution Items\", \"Solution Items\", \"{179A2A2C-3B3D-437C-B5F3-3B81472C8335}\"\n\tProjectSection(SolutionItems) = preProject\n\t\tDirectory.Build.props = Directory.Build.props\n\tEndProjectSection\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcHybrid\", \"MvcHybrid\\MvcHybrid.csproj\", \"{926ACA55-AA27-475D-90CB-AC6D4B113322}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcHybridAutomaticRefresh\", \"MvcHybridAutomaticRefresh\\MvcHybridAutomaticRefresh.csproj\", \"{AF1E5A26-F1DC-4B71-988D-F3B69F47D604}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcImplicit\", \"MvcImplicit\\MvcImplicit.csproj\", \"{24B7CDFC-87B7-4C45-A73B-AA0D9FAD25B8}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcImplicitJwtRequest\", \"MvcImplicitJwtRequest\\MvcImplicitJwtRequest.csproj\", \"{DD2BC29A-9874-4953-8AAC-9ABF8DE97F2F}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcManual\", \"MvcManual\\MvcManual.csproj\", \"{B3757E48-9817-4390-9A35-58D106C2D6E2}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"root\", \"root\", \"{3CDFF45B-4773-419E-99DA-BE8545B7DECB}\"\n\tProjectSection(SolutionItems) = preProject\n\t\t..\\..\\..\\Directory.Build.props = ..\\..\\..\\Directory.Build.props\n\t\t..\\..\\..\\Directory.Packages.props = ..\\..\\..\\Directory.Packages.props\n\tEndProjectSection\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Constants\", \"..\\shared\\Constants\\Constants.csproj\", \"{F2D39DF0-367D-456B-820F-2A081F7C1CC7}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"samples\", \"samples\", \"{66694F08-6E72-4D7B-A555-D4EB25A9CCC8}\"\n\tProjectSection(SolutionItems) = preProject\n\t\t..\\..\\Directory.Build.props = ..\\..\\Directory.Build.props\n\t\t..\\..\\SamplesGlobalUsings.cs = ..\\..\\SamplesGlobalUsings.cs\n\tEndProjectSection\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Clients\", \"Clients\", \"{97D760DC-D81F-43D4-93D0-B81BD2112705}\"\n\tProjectSection(SolutionItems) = preProject\n\t\t..\\ClientsGlobalUsings.cs = ..\\ClientsGlobalUsings.cs\n\t\t..\\..\\Directory.Build.props = ..\\..\\Directory.Build.props\n\tEndProjectSection\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"old\", \"old\", \"{B729491B-30F9-4DB3-B871-77BA9BA8BE8D}\"\n\tProjectSection(SolutionItems) = preProject\n\t\tDirectory.Build.props = Directory.Build.props\n\t\tMvcUsings.cs = MvcUsings.cs\n\tEndProjectSection\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tRelease|Any CPU = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{926ACA55-AA27-475D-90CB-AC6D4B113322}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{926ACA55-AA27-475D-90CB-AC6D4B113322}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{926ACA55-AA27-475D-90CB-AC6D4B113322}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{926ACA55-AA27-475D-90CB-AC6D4B113322}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{AF1E5A26-F1DC-4B71-988D-F3B69F47D604}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{AF1E5A26-F1DC-4B71-988D-F3B69F47D604}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{AF1E5A26-F1DC-4B71-988D-F3B69F47D604}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{AF1E5A26-F1DC-4B71-988D-F3B69F47D604}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{24B7CDFC-87B7-4C45-A73B-AA0D9FAD25B8}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{24B7CDFC-87B7-4C45-A73B-AA0D9FAD25B8}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{24B7CDFC-87B7-4C45-A73B-AA0D9FAD25B8}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{24B7CDFC-87B7-4C45-A73B-AA0D9FAD25B8}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{DD2BC29A-9874-4953-8AAC-9ABF8DE97F2F}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{DD2BC29A-9874-4953-8AAC-9ABF8DE97F2F}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{DD2BC29A-9874-4953-8AAC-9ABF8DE97F2F}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{DD2BC29A-9874-4953-8AAC-9ABF8DE97F2F}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{B3757E48-9817-4390-9A35-58D106C2D6E2}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{B3757E48-9817-4390-9A35-58D106C2D6E2}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{B3757E48-9817-4390-9A35-58D106C2D6E2}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{B3757E48-9817-4390-9A35-58D106C2D6E2}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{F2D39DF0-367D-456B-820F-2A081F7C1CC7}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{F2D39DF0-367D-456B-820F-2A081F7C1CC7}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{F2D39DF0-367D-456B-820F-2A081F7C1CC7}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{F2D39DF0-367D-456B-820F-2A081F7C1CC7}.Release|Any CPU.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{3CDFF45B-4773-419E-99DA-BE8545B7DECB} = {179A2A2C-3B3D-437C-B5F3-3B81472C8335}\n\t\t{66694F08-6E72-4D7B-A555-D4EB25A9CCC8} = {3CDFF45B-4773-419E-99DA-BE8545B7DECB}\n\t\t{97D760DC-D81F-43D4-93D0-B81BD2112705} = {66694F08-6E72-4D7B-A555-D4EB25A9CCC8}\n\t\t{B729491B-30F9-4DB3-B871-77BA9BA8BE8D} = {97D760DC-D81F-43D4-93D0-B81BD2112705}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {BAD78470-3D66-466E-9C17-2A67F0905B18}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "samples/Clients/old/Clients.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft\n Written by Alexander Higgins https://github.com/alexhiggins732/ \n \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code for this software can be found at https://github.com/alexhiggins732/IdentityServer8\n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n\n*/\n"
  },
  {
    "path": "samples/Clients/old/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n  <ItemGroup>\n      <Compile Include=\"$(SolutionDir)MvcUsings.cs\" Link=\"MvcUsings.cs\" />\n     <ProjectReference Include=\"$(SolutionDir)..\\shared\\Constants\\Constants.csproj\" Condition=\"$(MSBuildProjectName) != 'Constants' \" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly IHttpClientFactory _httpClientFactory;\n    private readonly IDiscoveryCache _discoveryCache;\n\n    public HomeController(IHttpClientFactory httpClientFactory, IDiscoveryCache discoveryCache)\n    {\n        _httpClientFactory = httpClientFactory;\n        _discoveryCache = discoveryCache;\n    }\n\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    [Authorize]\n    public IActionResult Secure()\n    {\n        return View();\n    }\n\n    [Authorize]\n    public async Task<IActionResult> CallApi()\n    {\n        var token = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = _httpClientFactory.CreateClient();\n        client.SetBearerToken(token);\n\n        var response = await client.GetStringAsync(Constants.SampleApi + \"identity\");\n        ViewBag.Json = JsonSerializer.Deserialize<JsonElement>(response).ToString();\n\n        return View();\n    }\n\n    public async Task<IActionResult> RenewTokens()\n    {\n        var disco = await _discoveryCache.GetAsync();\n        if (disco.IsError) throw new Exception(disco.Error);\n\n        var rt = await HttpContext.GetTokenAsync(\"refresh_token\");\n        var tokenClient = _httpClientFactory.CreateClient();\n\n        var tokenResult = await tokenClient.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = disco.TokenEndpoint,\n\n            ClientId = \"mvc.hybrid\",\n            ClientSecret = \"secret\",\n            RefreshToken = rt\n        });\n\n        if (!tokenResult.IsError)\n        {\n            var old_id_token = await HttpContext.GetTokenAsync(\"id_token\");\n            var new_access_token = tokenResult.AccessToken;\n            var new_refresh_token = tokenResult.RefreshToken;\n            var expiresAt = DateTime.UtcNow + TimeSpan.FromSeconds(tokenResult.ExpiresIn);\n\n            var info = await HttpContext.AuthenticateAsync(\"Cookies\");\n\n            info.Properties.UpdateTokenValue(\"refresh_token\", new_refresh_token);\n            info.Properties.UpdateTokenValue(\"access_token\", new_access_token);\n            info.Properties.UpdateTokenValue(\"expires_at\", expiresAt.ToString(\"o\", CultureInfo.InvariantCulture));\n\n            await HttpContext.SignInAsync(\"Cookies\", info.Principal, info.Properties);\n            return Redirect(\"~/Home/Secure\");\n        }\n\n        ViewData[\"Error\"] = tokenResult.Error;\n        return View(\"Error\");\n    }\n\n    public IActionResult Logout()\n    {\n        return new SignOutResult(new[] { \"Cookies\", \"oidc\" });\n    }\n\n    public IActionResult Error()\n    {\n        return View();\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/MvcHybrid.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nWebHost.CreateDefaultBuilder(args)\n    .UseStartup<Startup>()\n    .Build();"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:21402/\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"IIS Express\": {\n      \"commandName\": \"IISExpress\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      }\n    }\n  }\n}"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\npublic class Startup\n{\n    public Startup()\n    {\n        JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        services.AddControllersWithViews();\n        services.AddHttpClient();\n\n        services.AddSingleton<IDiscoveryCache>(r =>\n        {\n            var factory = r.GetRequiredService<IHttpClientFactory>();\n            return new DiscoveryCache(Constants.Authority, () => factory.CreateClient());\n        });\n\n        services.AddAuthentication(options =>\n        {\n            options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;\n            options.DefaultChallengeScheme = \"oidc\";\n        })\n            .AddCookie(options =>\n            {\n                options.ExpireTimeSpan = TimeSpan.FromMinutes(60);\n                options.Cookie.Name = \"mvchybrid\";\n            })\n            .AddOpenIdConnect(\"oidc\", options =>\n            {\n                options.Authority = Constants.Authority;\n                options.RequireHttpsMetadata = false;\n\n                options.ClientSecret = \"secret\";\n                options.ClientId = \"mvc.hybrid\";\n\n                options.ResponseType = \"code id_token\";\n\n                options.Scope.Clear();\n                options.Scope.Add(\"openid\");\n                options.Scope.Add(\"profile\");\n                options.Scope.Add(\"email\");\n                options.Scope.Add(\"api1\");\n                options.Scope.Add(\"offline_access\");\n               \n                options.ClaimActions.MapAllExcept(\"iss\", \"nbf\", \"exp\", \"aud\", \"nonce\", \"iat\", \"c_hash\");\n\n                options.GetClaimsFromUserInfoEndpoint = true;\n                options.SaveTokens = true;\n\n                options.TokenValidationParameters = new TokenValidationParameters\n                {\n                    NameClaimType = JwtClaimTypes.Name,\n                    RoleClaimType = JwtClaimTypes.Role,\n                };\n            });\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n        app.UseDeveloperExceptionPage();\n        app.UseStaticFiles();\n\n        app.UseRouting();\n        app.UseAuthentication();\n        app.UseAuthorization();\n\n        app.UseEndpoints(endpoints =>\n        {\n            endpoints.MapDefaultControllerRoute();\n        });\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Views/Home/CallApi.cshtml",
    "content": "﻿<h1>API Response</h1>\n\n<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Views/Home/Index.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Home Page\";\n}\n\n@if(User.Identity.IsAuthenticated)\n{\n    <h1>Logged in as: @User.Identity.Name</h1>\n}\nelse\n{\n    <h1>Not Logged In</h1>\n}"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Views/Home/Secure.cshtml",
    "content": "﻿@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<div class=\"panel\">\n    <a class=\"btn btn-primary\" href=\"~/home/callapi\">Call API</a>\n    <a class=\"btn btn-primary\" href=\"~/home/renewtokens\">Renew Tokens</a>\n</div>\n\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Views/Shared/Error.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n\n<h3>Development Mode</h3>\n<p>\n    Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.\n</p>\n<p>\n    <strong>Development environment should not be enabled in deployed applications</strong>, as it can result in sensitive information from exceptions being displayed to end users. For local debugging, development environment can be enabled by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>, and restarting the application.\n</p>\n"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html>\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcHybrid</title>\n\n    <environment names=\"Development\">\n        <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.css\" />\n        <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n    </environment>\n    <environment names=\"Staging,Production\">\n        <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n        <link rel=\"stylesheet\" href=\"~/css/site.min.css\" asp-append-version=\"true\" />\n    </environment>\n</head>\n<body>\n    <div class=\"navbar navbar-inverse navbar-fixed-top\">\n        <div class=\"container\">\n            <div class=\"navbar-header\">\n                <button type=\"button\" class=\"navbar-toggle\" data-toggle=\"collapse\" data-target=\".navbar-collapse\">\n                    <span class=\"sr-only\">Toggle navigation</span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                </button>\n                <a asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\" class=\"navbar-brand\">MvcHybrid</a>\n            </div>\n            <div class=\"navbar-collapse collapse\">\n                <ul class=\"nav navbar-nav\">\n                    <li><a asp-controller=\"Home\" asp-action=\"Secure\">Secure</a></li>\n                    <li><a asp-controller=\"Home\" asp-action=\"Logout\">Logout</a></li>\n                </ul>\n            </div>\n        </div>\n    </div>\n    <div class=\"container body-content\">\n        @RenderBody()\n        <hr />\n        <footer>\n            <p>&copy; 2016 - MvcHybrid</p>\n        </footer>\n    </div>\n\n    <environment names=\"Development\">\n        <script src=\"~/lib/jquery/dist/jquery.js\"></script>\n        <script src=\"~/lib/bootstrap/dist/js/bootstrap.js\"></script>\n        <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    </environment>\n    <environment names=\"Staging,Production\">\n        <script src=\"~/lib/jquery/dist/jquery.js\"></script>\n        <script src=\"~/lib/bootstrap/dist/js/bootstrap.min.js\"></script>\n        <script src=\"~/js/site.min.js\" asp-append-version=\"true\"></script>\n    </environment>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/appsettings.json",
    "content": "﻿{\n  \"Logging\": {\n    \"IncludeScopes\": false,\n    \"LogLevel\": {\n      \"Default\": \"Debug\",\n      \"System\": \"Information\",\n      \"Microsoft\": \"Information\"\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/wwwroot/css/site.css",
    "content": "﻿body {\n    padding-top: 50px;\n    padding-bottom: 20px;\n}\n\n/* Wrapping element */\n/* Set some basic padding to keep content from hitting the edges */\n.body-content {\n    padding-left: 15px;\n    padding-right: 15px;\n}\n\n/* Set widths on the form inputs since otherwise they're 100% wide */\ninput,\nselect,\ntextarea {\n    max-width: 280px;\n}\n\n/* Carousel */\n.carousel-caption p {\n    font-size: 20px;\n    line-height: 1.4;\n}\n\n/* Make .svg files in the carousel display properly in older browsers */\n.carousel-inner .item img[src$=\".svg\"]\n{\n    width: 100%;\n}\n\n/* Hide/rearrange for smaller screens */\n@media screen and (max-width: 767px) {\n  /* Hide captions */\n  .carousel-caption {\n    display: none\n  }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybrid/wwwroot/js/site.js",
    "content": "﻿// Write your Javascript code.\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/AutomaticTokenManagement/AutomaticTokenManagementBuilderExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityModel.AspNetCore\n{\n    public static class AutomaticTokenManagementBuilderExtensions\n    {\n        public static AuthenticationBuilder AddAutomaticTokenManagement(this AuthenticationBuilder builder, Action<AutomaticTokenManagementOptions> options)\n        {\n            builder.Services.Configure(options);\n            return builder.AddAutomaticTokenManagement();\n        }\n\n        public static AuthenticationBuilder AddAutomaticTokenManagement(this AuthenticationBuilder builder)\n        {\n            builder.Services.AddHttpClient(\"tokenClient\");\n            builder.Services.AddTransient<TokenEndpointService>();\n\n            builder.Services.AddTransient<AutomaticTokenManagementCookieEvents>();\n            builder.Services.AddSingleton<IConfigureOptions<CookieAuthenticationOptions>, AutomaticTokenManagementConfigureCookieOptions>();\n\n            return builder;\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/AutomaticTokenManagement/AutomaticTokenManagementConfigureCookieOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityModel.AspNetCore\n{\n    public class AutomaticTokenManagementConfigureCookieOptions : IConfigureNamedOptions<CookieAuthenticationOptions>\n    {\n        private readonly AuthenticationScheme _scheme;\n\n        public AutomaticTokenManagementConfigureCookieOptions(IAuthenticationSchemeProvider provider)\n        {\n            _scheme = provider.GetDefaultSignInSchemeAsync().GetAwaiter().GetResult();\n        }\n\n        public void Configure(CookieAuthenticationOptions options)\n        { }\n\n        public void Configure(string name, CookieAuthenticationOptions options)\n        {\n            if (name == _scheme.Name)\n            {\n                options.EventsType = typeof(AutomaticTokenManagementCookieEvents);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/AutomaticTokenManagement/AutomaticTokenManagementCookieEvents.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityModel.AspNetCore\n{\n    public class AutomaticTokenManagementCookieEvents : CookieAuthenticationEvents\n    {\n        private readonly TokenEndpointService _service;\n        private readonly AutomaticTokenManagementOptions _options;\n        private readonly ILogger _logger;\n        private readonly ISystemClock _clock;\n        \n        private static readonly ConcurrentDictionary<string, bool> _pendingRefreshTokenRequests =\n            new ConcurrentDictionary<string, bool>();\n\n        public AutomaticTokenManagementCookieEvents(\n            TokenEndpointService service,\n            IOptions<AutomaticTokenManagementOptions> options,\n            ILogger<AutomaticTokenManagementCookieEvents> logger,\n            ISystemClock clock)\n        {\n            _service = service;\n            _options = options.Value;\n            _logger = logger;\n            _clock = clock;\n        }\n\n        public override async Task ValidatePrincipal(CookieValidatePrincipalContext context)\n        {\n            var tokens = context.Properties.GetTokens();\n            if (tokens == null || !tokens.Any())\n            {\n                _logger.LogDebug(\"No tokens found in cookie properties. SaveTokens must be enabled for automatic token refresh.\");\n                return;\n            }\n\n            var refreshToken = tokens.SingleOrDefault(t => t.Name == OpenIdConnectParameterNames.RefreshToken);\n            if (refreshToken == null)\n            {\n                _logger.LogWarning(\"No refresh token found in cookie properties. A refresh token must be requested and SaveTokens must be enabled.\");\n                return;\n            }\n\n            var expiresAt = tokens.SingleOrDefault(t => t.Name == \"expires_at\");\n            if (expiresAt == null)\n            {\n                _logger.LogWarning(\"No expires_at value found in cookie properties.\");\n                return;\n            }\n\n            var dtExpires = DateTimeOffset.Parse(expiresAt.Value, CultureInfo.InvariantCulture);\n            var dtRefresh = dtExpires.Subtract(_options.RefreshBeforeExpiration);\n\n            if (dtRefresh < _clock.UtcNow)\n            {\n                var shouldRefresh = _pendingRefreshTokenRequests.TryAdd(refreshToken.Value, true);\n                if (shouldRefresh)\n                {\n                    try\n                    {\n                        var response = await _service.RefreshTokenAsync(refreshToken.Value);\n\n                        if (response.IsError)\n                        {\n                            _logger.LogWarning(\"Error refreshing token: {error}\", response.Error);\n                            context.RejectPrincipal();\n                            return;\n                        }\n\n                        context.Properties.UpdateTokenValue(\"access_token\", response.AccessToken);\n                        context.Properties.UpdateTokenValue(\"refresh_token\", response.RefreshToken);\n\n                        var newExpiresAt = DateTime.UtcNow + TimeSpan.FromSeconds(response.ExpiresIn);\n                        context.Properties.UpdateTokenValue(\"expires_at\", newExpiresAt.ToString(\"o\", CultureInfo.InvariantCulture));\n\n                        await context.HttpContext.SignInAsync(context.Principal, context.Properties);\n                    }\n                    finally\n                    {\n                        _pendingRefreshTokenRequests.TryRemove(refreshToken.Value, out _);\n                    }\n                }\n            }\n        }\n\n        public override async Task SigningOut(CookieSigningOutContext context)\n        {\n            if (_options.RevokeRefreshTokenOnSignout == false) return;\n\n            var result = await context.HttpContext.AuthenticateAsync();\n\n            if (!result.Succeeded)\n            {\n                _logger.LogDebug(\"Can't find cookie for default scheme. Might have been deleted already.\");\n                return;\n            }\n\n            var tokens = result.Properties.GetTokens();\n            if (tokens == null || !tokens.Any())\n            {\n                _logger.LogDebug(\"No tokens found in cookie properties. SaveTokens must be enabled for automatic token revocation.\");\n                return;\n            }\n\n            var refreshToken = tokens.SingleOrDefault(t => t.Name == OpenIdConnectParameterNames.RefreshToken);\n            if (refreshToken == null)\n            {\n                _logger.LogWarning(\"No refresh token found in cookie properties. A refresh token must be requested and SaveTokens must be enabled.\");\n                return;\n            }\n\n            var response = await _service.RevokeTokenAsync(refreshToken.Value);\n\n            if (response.IsError)\n            {\n                _logger.LogWarning(\"Error revoking token: {error}\", response.Error);\n                return;\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/AutomaticTokenManagement/AutomaticTokenManagementOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityModel.AspNetCore\n{\n    public class AutomaticTokenManagementOptions\n    {\n        public string Scheme { get; set; }\n        public TimeSpan RefreshBeforeExpiration { get; set; } = TimeSpan.FromMinutes(1);\n        public bool RevokeRefreshTokenOnSignout { get; set; } = true;\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/AutomaticTokenManagement/TokenEndpointService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityModel.AspNetCore\n{\n    public class TokenEndpointService\n    {\n        private readonly AutomaticTokenManagementOptions _managementOptions;\n        private readonly IOptionsSnapshot<OpenIdConnectOptions> _oidcOptions;\n        private readonly IAuthenticationSchemeProvider _schemeProvider;\n        private readonly IHttpClientFactory _httpClientFactory;\n        private readonly ILogger<TokenEndpointService> _logger;\n\n        public TokenEndpointService(\n            IOptions<AutomaticTokenManagementOptions> managementOptions,\n            IOptionsSnapshot<OpenIdConnectOptions> oidcOptions,\n            IAuthenticationSchemeProvider schemeProvider,\n            IHttpClientFactory httpClientFactory,\n            ILogger<TokenEndpointService> logger)\n        {\n            _managementOptions = managementOptions.Value;\n            _oidcOptions = oidcOptions;\n            _schemeProvider = schemeProvider;\n            _httpClientFactory = httpClientFactory;\n            _logger = logger;\n        }\n\n        public async Task<TokenResponse> RefreshTokenAsync(string refreshToken)\n        {\n            var oidcOptions = await GetOidcOptionsAsync();\n            var configuration = await oidcOptions.ConfigurationManager.GetConfigurationAsync(default(CancellationToken));\n\n            var tokenClient = _httpClientFactory.CreateClient(\"tokenClient\");\n\n            return await tokenClient.RequestRefreshTokenAsync(new RefreshTokenRequest\n            {\n                Address = configuration.TokenEndpoint,\n\n                ClientId = oidcOptions.ClientId,\n                ClientSecret = oidcOptions.ClientSecret,\n                RefreshToken = refreshToken\n            });\n        }\n\n        public async Task<TokenRevocationResponse> RevokeTokenAsync(string refreshToken)\n        {\n            var oidcOptions = await GetOidcOptionsAsync();\n            var configuration = await oidcOptions.ConfigurationManager.GetConfigurationAsync(default(CancellationToken));\n\n            var tokenClient = _httpClientFactory.CreateClient(\"tokenClient\");\n\n            return await tokenClient.RevokeTokenAsync(new TokenRevocationRequest\n            {\n                Address = configuration.AdditionalData[OidcConstants.Discovery.RevocationEndpoint].ToString(),\n                ClientId = oidcOptions.ClientId,\n                ClientSecret = oidcOptions.ClientSecret,\n                Token = refreshToken,\n                TokenTypeHint = OidcConstants.TokenTypes.RefreshToken\n            });\n        }\n\n        private async Task<OpenIdConnectOptions> GetOidcOptionsAsync()\n        {\n            if (string.IsNullOrEmpty(_managementOptions.Scheme))\n            {\n                var scheme = await _schemeProvider.GetDefaultChallengeSchemeAsync();\n                return _oidcOptions.Get(scheme.Name);\n            }\n            else\n            {\n                return _oidcOptions.Get(_managementOptions.Scheme);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly IHttpClientFactory _httpClientFactory;\n    \n    public HomeController(IHttpClientFactory httpClientFactory)\n    {\n        _httpClientFactory = httpClientFactory;\n    }\n\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    [Authorize]\n    public IActionResult Secure()\n    {\n        return View();\n    }\n\n    [Authorize]\n    public async Task<IActionResult> CallApi()\n    {\n        var token = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = _httpClientFactory.CreateClient();\n        client.SetBearerToken(token);\n\n        var response = await client.GetStringAsync(Constants.SampleApi + \"identity\");\n        ViewBag.Json = JsonSerializer.Deserialize<JsonElement>(response).ToString();\n\n        return View();\n    }\n\n    public IActionResult Logout()\n    {\n        return new SignOutResult(new[] { \"Cookies\", \"oidc\" });\n    }\n\n    public IActionResult Error()\n    {\n        return View();\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/MvcHybridAutomaticRefresh.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nvar builder = WebApplication.CreateBuilder(args);\n\nJwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();\n\nvar services = builder.Services;\n\nservices.AddMvc();\nservices.AddHttpClient();\n\nservices.AddAuthentication(options =>\n{\n    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;\n    options.DefaultChallengeScheme = \"oidc\";\n})\n    .AddCookie(options =>\n    {\n        options.ExpireTimeSpan = TimeSpan.FromMinutes(60);\n        options.Cookie.Name = \"mvchybridautorefresh\";\n    })\n    .AddAutomaticTokenManagement()\n    .AddOpenIdConnect(\"oidc\", options =>\n    {\n        options.Authority = Constants.Authority;\n        options.RequireHttpsMetadata = false;\n\n        options.ClientSecret = \"secret\";\n        options.ClientId = \"mvc.hybrid.autorefresh\";\n\n        options.ResponseType = \"code id_token\";\n\n        options.Scope.Clear();\n        options.Scope.Add(\"openid\");\n        options.Scope.Add(\"profile\");\n        options.Scope.Add(\"email\");\n        options.Scope.Add(\"api1\");\n        options.Scope.Add(\"offline_access\");\n\n        options.ClaimActions.MapAllExcept(\"iss\", \"nbf\", \"exp\", \"aud\", \"nonce\", \"iat\", \"c_hash\");\n\n        options.GetClaimsFromUserInfoEndpoint = true;\n        options.SaveTokens = true;\n\n        options.TokenValidationParameters = new TokenValidationParameters\n        {\n            NameClaimType = JwtClaimTypes.Name,\n            RoleClaimType = JwtClaimTypes.Role,\n        };\n    });\n       \n\n\n\nusing (var app = builder.Build())\n{\n    app.UseDeveloperExceptionPage();\n    app.UseStaticFiles();\n\n    app.UseRouting();\n    app.UseAuthentication();\n    app.UseAuthorization();\n\n    app.UseDeveloperExceptionPage();\n    app.UseStaticFiles();\n    app.UseAuthentication();\n\n\n\n    app.MapControllerRoute(\n               name: \"default\",\n                      pattern: \"{controller=Home}/{action=Index}/{id?}\");\n\n    await app.RunAsync();\n}\n\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:21404/\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"IIS Express\": {\n      \"commandName\": \"IISExpress\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      }\n    }\n  }\n}"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/Views/Home/CallApi.cshtml",
    "content": "﻿<h1>API Response</h1>\n\n<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/Views/Home/Index.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Home Page\";\n}\n\n@if(User.Identity.IsAuthenticated)\n{\n    <h1>Logged in as: @User.Identity.Name</h1>\n}\nelse\n{\n    <h1>Not Logged In</h1>\n}"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/Views/Home/Secure.cshtml",
    "content": "﻿@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<div class=\"panel\">\n    <a class=\"btn btn-primary\" href=\"~/home/callapi\">Call API</a>\n</div>\n\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/Views/Shared/Error.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n\n<h3>Development Mode</h3>\n<p>\n    Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.\n</p>\n<p>\n    <strong>Development environment should not be enabled in deployed applications</strong>, as it can result in sensitive information from exceptions being displayed to end users. For local debugging, development environment can be enabled by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>, and restarting the application.\n</p>\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html>\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcHybrid</title>\n\n    <environment names=\"Development\">\n        <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.css\" />\n        <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n    </environment>\n    <environment names=\"Staging,Production\">\n        <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n        <link rel=\"stylesheet\" href=\"~/css/site.min.css\" asp-append-version=\"true\" />\n    </environment>\n</head>\n<body>\n    <div class=\"navbar navbar-inverse navbar-fixed-top\">\n        <div class=\"container\">\n            <div class=\"navbar-header\">\n                <button type=\"button\" class=\"navbar-toggle\" data-toggle=\"collapse\" data-target=\".navbar-collapse\">\n                    <span class=\"sr-only\">Toggle navigation</span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                </button>\n                <a asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\" class=\"navbar-brand\">MvcHybrid</a>\n            </div>\n            <div class=\"navbar-collapse collapse\">\n                <ul class=\"nav navbar-nav\">\n                    <li><a asp-controller=\"Home\" asp-action=\"Secure\">Secure</a></li>\n                    <li><a asp-controller=\"Home\" asp-action=\"Logout\">Logout</a></li>\n                </ul>\n            </div>\n        </div>\n    </div>\n    <div class=\"container body-content\">\n        @RenderBody()\n        <hr />\n        <footer>\n            <p>&copy; 2016 - MvcHybrid</p>\n        </footer>\n    </div>\n\n    <environment names=\"Development\">\n        <script src=\"~/lib/jquery/dist/jquery.js\"></script>\n        <script src=\"~/lib/bootstrap/dist/js/bootstrap.js\"></script>\n        <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    </environment>\n    <environment names=\"Staging,Production\">\n        <script src=\"~/lib/jquery/dist/jquery.js\"></script>\n        <script src=\"~/lib/bootstrap/dist/js/bootstrap.min.js\"></script>\n        <script src=\"~/js/site.min.js\" asp-append-version=\"true\"></script>\n    </environment>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/appsettings.json",
    "content": "﻿{\n  \"Logging\": {\n    \"IncludeScopes\": false,\n    \"LogLevel\": {\n      \"Default\": \"Debug\",\n      \"System\": \"Information\",\n      \"Microsoft\": \"Information\"\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/wwwroot/css/site.css",
    "content": "﻿body {\n    padding-top: 50px;\n    padding-bottom: 20px;\n}\n\n/* Wrapping element */\n/* Set some basic padding to keep content from hitting the edges */\n.body-content {\n    padding-left: 15px;\n    padding-right: 15px;\n}\n\n/* Set widths on the form inputs since otherwise they're 100% wide */\ninput,\nselect,\ntextarea {\n    max-width: 280px;\n}\n\n/* Carousel */\n.carousel-caption p {\n    font-size: 20px;\n    line-height: 1.4;\n}\n\n/* Make .svg files in the carousel display properly in older browsers */\n.carousel-inner .item img[src$=\".svg\"]\n{\n    width: 100%;\n}\n\n/* Hide/rearrange for smaller screens */\n@media screen and (max-width: 767px) {\n  /* Hide captions */\n  .carousel-caption {\n    display: none\n  }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcHybridAutomaticRefresh/wwwroot/js/site.js",
    "content": "﻿// Write your Javascript code.\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    [Authorize]\n    public IActionResult Secure()\n    {\n        return View();\n    }\n\n    public IActionResult Logout()\n    {\n        return new SignOutResult(new string[] { \"oidc\", \"Cookies\" });\n    }\n\n    public IActionResult Error()\n    {\n        return View();\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/MvcImplicit.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nWebHost.CreateDefaultBuilder(args)\n    .UseStartup<Startup>()\n    .Build();"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:44077/\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"IIS Express\": {\n      \"commandName\": \"IISExpress\",\n      \"launchBrowser\": true\n    }\n  }\n}"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class Startup\n{\n    public Startup()\n    {\n        JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        services.AddControllersWithViews();\n\n        services.AddAuthentication(options =>\n        {\n            options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;\n            options.DefaultChallengeScheme = \"oidc\";\n        })\n            .AddCookie(options =>\n            {\n                options.ExpireTimeSpan = TimeSpan.FromMinutes(60);\n                options.Cookie.Name = \"mvcimplicit\";\n            })\n            .AddOpenIdConnect(\"oidc\", options =>\n            {\n                options.Authority = Constants.Authority;\n                options.RequireHttpsMetadata = false;\n\n                options.ClientId = \"mvc.implicit\";\n\n                options.Scope.Clear();\n                options.Scope.Add(\"openid\");\n                options.Scope.Add(\"profile\");\n                options.Scope.Add(\"email\");\n\n                options.SaveTokens = true;\n\n                options.TokenValidationParameters = new TokenValidationParameters\n                {\n                    NameClaimType = JwtClaimTypes.Name,\n                    RoleClaimType = JwtClaimTypes.Role,\n                };\n            });\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n        app.UseDeveloperExceptionPage();\n        app.UseStaticFiles();\n\n        app.UseRouting();\n        app.UseAuthentication();\n        app.UseAuthorization();\n\n        app.UseEndpoints(endpoints =>\n        {\n            endpoints.MapDefaultControllerRoute();\n        });\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/Views/Home/Index.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Home Page\";\n}\n\n@if(User.Identity.IsAuthenticated)\n{\n    <h1>Logged in as: @User.Identity.Name</h1>\n}\nelse\n{\n    <h1>Not Logged In</h1>\n}"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/Views/Home/Secure.cshtml",
    "content": "﻿@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/Views/Shared/Error.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html>\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcImplicit</title>\n\n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <div class=\"navbar navbar-inverse navbar-fixed-top\">\n        <div class=\"container\">\n            <div class=\"navbar-header\">\n                <button type=\"button\" class=\"navbar-toggle\" data-toggle=\"collapse\" data-target=\".navbar-collapse\">\n                    <span class=\"sr-only\">Toggle navigation</span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                </button>\n                <a asp-controller=\"Home\" asp-action=\"Index\" class=\"navbar-brand\">MvcImplicit</a>\n            </div>\n            <div class=\"navbar-collapse collapse\">\n                <ul class=\"nav navbar-nav\">\n                    <li><a asp-controller=\"Home\" asp-action=\"Secure\">Secure</a></li>\n                    <li><a asp-controller=\"Home\" asp-action=\"Logout\">Logout</a></li>\n                </ul>\n            </div>\n        </div>\n    </div>\n    <div class=\"container body-content\">\n        @RenderBody()\n        <hr />\n        <footer>\n            <p>&copy; 2016 - MvcImplicit</p>\n        </footer>\n    </div>\n    <environment names=\"Development\">\n        <script src=\"~/lib/jquery/dist/jquery.js\"></script>\n        <script src=\"~/lib/bootstrap/dist/js/bootstrap.js\"></script>\n        <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    </environment>\n    <environment names=\"Staging,Production\">\n        <script src=\"~/lib/jquery/dist/jquery.js\"></script>\n        <script src=\"~/lib/bootstrap/dist/js/bootstrap.min.js\"></script>\n        <script src=\"~/js/site.min.js\" asp-append-version=\"true\"></script>\n    </environment>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/Views/_ViewImports.cshtml",
    "content": "\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/wwwroot/css/site.css",
    "content": "﻿body {\n    padding-top: 50px;\n    padding-bottom: 20px;\n}\n\n/* Wrapping element */\n/* Set some basic padding to keep content from hitting the edges */\n.body-content {\n    padding-left: 15px;\n    padding-right: 15px;\n}\n\n/* Set widths on the form inputs since otherwise they're 100% wide */\ninput,\nselect,\ntextarea {\n    max-width: 280px;\n}\n\n/* Carousel */\n.carousel-caption {\n    z-index: 10 !important;\n}\n\n    .carousel-caption p {\n        font-size: 20px;\n        line-height: 1.4;\n    }\n\n@media (min-width: 768px) {\n    .carousel-caption {\n        z-index: 10 !important;\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicit/wwwroot/js/site.js",
    "content": "﻿// Write your Javascript code.\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\npublic class HomeController : Controller\n{\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    [Authorize]\n    public IActionResult Secure()\n    {\n        return View();\n    }\n\n    public IActionResult Logout()\n    {\n        return new SignOutResult(new string[] { \"oidc\", \"Cookies\" });\n    }\n\n    public IActionResult Error()\n    {\n        return View();\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/MvcImplicitJwtRequest.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n  <ItemGroup>\n    <None Update=\"Client.pfx\">\n      <CopyToOutputDirectory>PreserveNewest</CopyToOutputDirectory>\n    </None>\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nWebHost.CreateDefaultBuilder(args)\n    .UseStartup<Startup>()\n    .Build();"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:44077/\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"IIS Express\": {\n      \"commandName\": \"IISExpress\",\n      \"launchBrowser\": true\n    }\n  }\n}"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class Startup\n{\n    public Startup()\n    {\n        JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        services.AddControllersWithViews();\n\n        services.AddAuthentication(options =>\n        {\n            options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;\n            options.DefaultChallengeScheme = \"oidc\";\n        })\n            .AddCookie(options =>\n            {\n                options.ExpireTimeSpan = TimeSpan.FromMinutes(60);\n                options.Cookie.Name = \"mvcimplicit\";\n            })\n            .AddOpenIdConnect(\"oidc\", options =>\n            {\n                options.Authority = Constants.Authority;\n                options.RequireHttpsMetadata = false;\n\n                options.ClientId = \"mvc.implicit\";\n\n                options.Scope.Clear();\n                options.Scope.Add(\"openid\");\n                options.Scope.Add(\"profile\");\n                options.Scope.Add(\"email\");\n\n                options.SaveTokens = true;\n\n                options.TokenValidationParameters = new TokenValidationParameters\n                {\n                    NameClaimType = JwtClaimTypes.Name,\n                    RoleClaimType = JwtClaimTypes.Role,\n                };\n\n                options.Events.OnRedirectToIdentityProvider = e =>\n                {\n                    var jwt = CreateJwtRequest(\n                        options.ClientId,\n                        options.Authority,\n                        new Claim(\"additional_data\", \"data\"));\n\n                    e.ProtocolMessage.SetParameter(\"request\", jwt);\n\n                    return Task.CompletedTask;\n                };\n            });\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n        app.UseDeveloperExceptionPage();\n        app.UseStaticFiles();\n\n        app.UseRouting();\n        app.UseAuthentication();\n        app.UseAuthorization();\n\n        app.UseEndpoints(endpoints =>\n        {\n            endpoints.MapDefaultControllerRoute();\n        });\n    }\n\n    private static string CreateJwtRequest(string clientId, string audience, params Claim[] claims)\n    {\n        var certificate = new X509Certificate2(\"client.pfx\");\n        var now = DateTime.UtcNow;\n\n        var token = new JwtSecurityToken(\n                clientId,\n                audience,\n                claims,\n                now,\n                now.AddMinutes(1),\n                new SigningCredentials(\n                    new X509SecurityKey(certificate),\n                    SecurityAlgorithms.RsaSha256\n                )\n            );\n\n        var tokenHandler = new JwtSecurityTokenHandler();\n        return tokenHandler.WriteToken(token);\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/Views/Home/Index.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Home Page\";\n}\n\n@if(User.Identity.IsAuthenticated)\n{\n    <h1>Logged in as: @User.Identity.Name</h1>\n}\nelse\n{\n    <h1>Not Logged In</h1>\n}"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/Views/Home/Secure.cshtml",
    "content": "﻿@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/Views/Shared/Error.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/Views/Shared/_Layout.cshtml",
    "content": "﻿<!DOCTYPE html>\n<html>\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcImplicit</title>\n\n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <div class=\"navbar navbar-inverse navbar-fixed-top\">\n        <div class=\"container\">\n            <div class=\"navbar-header\">\n                <button type=\"button\" class=\"navbar-toggle\" data-toggle=\"collapse\" data-target=\".navbar-collapse\">\n                    <span class=\"sr-only\">Toggle navigation</span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                </button>\n                <a asp-controller=\"Home\" asp-action=\"Index\" class=\"navbar-brand\">MvcImplicit</a>\n            </div>\n            <div class=\"navbar-collapse collapse\">\n                <ul class=\"nav navbar-nav\">\n                    <li><a asp-controller=\"Home\" asp-action=\"Secure\">Secure</a></li>\n                    <li><a asp-controller=\"Home\" asp-action=\"Logout\">Logout</a></li>\n                </ul>\n            </div>\n        </div>\n    </div>\n    <div class=\"container body-content\">\n        @RenderBody()\n        <hr />\n        <footer>\n            <p>&copy; 2016 - MvcImplicit</p>\n        </footer>\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.js\"></script>\n    <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/wwwroot/css/site.css",
    "content": "﻿body {\n    padding-top: 50px;\n    padding-bottom: 20px;\n}\n\n/* Wrapping element */\n/* Set some basic padding to keep content from hitting the edges */\n.body-content {\n    padding-left: 15px;\n    padding-right: 15px;\n}\n\n/* Set widths on the form inputs since otherwise they're 100% wide */\ninput,\nselect,\ntextarea {\n    max-width: 280px;\n}\n\n/* Carousel */\n.carousel-caption {\n    z-index: 10 !important;\n}\n\n    .carousel-caption p {\n        font-size: 20px;\n        line-height: 1.4;\n    }\n\n@media (min-width: 768px) {\n    .carousel-caption {\n        z-index: 10 !important;\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcImplicitJwtRequest/wwwroot/js/site.js",
    "content": "﻿// Write your Javascript code.\n"
  },
  {
    "path": "samples/Clients/old/MvcManual/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    public async Task<IActionResult> Secure()\n    {\n        if (User.Identity.IsAuthenticated) return View();\n\n        return await StartAuthentication();\n    }\n\n    public async Task <IActionResult> Logout()\n    {\n        await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);\n\n        var client = new HttpClient();\n        var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n\n        return Redirect(disco.EndSessionEndpoint);\n    }\n\n    public async Task<IActionResult> FrontChannelLogout(string sid)\n    {\n        if (User.Identity.IsAuthenticated)\n        {\n            var currentSid = User.FindFirst(\"sid\")?.Value ?? \"\";\n            if (string.Equals(currentSid, sid, StringComparison.Ordinal))\n            {\n                await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);\n            }\n        }\n\n        return NoContent();\n    }\n\n    [HttpPost]\n    [AllowAnonymous]\n    public async Task<IActionResult> BackChannelLogout(string logout_token)\n    {\n        Response.Headers.Append(\"Cache-Control\", \"no-cache, no-store\");\n        Response.Headers.Append(\"Pragma\", \"no-cache\");\n\n        try\n        {\n            var user = await ValidateLogoutToken(logout_token);\n\n            // these are the sub & sid to signout\n            var sub = user.FindFirst(\"sub\")?.Value;\n            var sid = user.FindFirst(\"sid\")?.Value;\n\n            return Ok();\n        }\n        catch { }\n\n        return BadRequest();\n    }\n\n    public IActionResult Error()\n    {\n        return View();\n    }\n\n    private async Task<IActionResult> StartAuthentication()\n    {\n        // read discovery document to find authorize endpoint\n        var client = new HttpClient();\n        var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n\n        var authorizeUrl = new RequestUrl(disco.AuthorizeEndpoint).CreateAuthorizeUrl(\n            clientId: \"mvc.manual\",\n            responseType: \"id_token\",\n            scope: \"openid profile\",\n            redirectUri: \"http://localhost:44078/home/callback\",\n            state: \"random_state\",\n            nonce: \"random_nonce\",\n            responseMode: \"form_post\");\n\n        return Redirect(authorizeUrl);\n    }\n\n    public async Task<IActionResult> Callback()\n    {\n        var state = Request.Form[\"state\"].FirstOrDefault();\n        var idToken = Request.Form[\"id_token\"].FirstOrDefault();\n        var error = Request.Form[\"error\"].FirstOrDefault();\n\n        if (!string.IsNullOrEmpty(error)) throw new Exception(error);\n        if (!string.Equals(state, \"random_state\")) throw new Exception(\"invalid state\");\n\n        var user = await ValidateIdentityToken(idToken);\n\n        await HttpContext.SignInAsync(CookieAuthenticationDefaults.AuthenticationScheme, user);\n        return Redirect(\"/home/secure\");\n    }\n\n    private async Task<ClaimsPrincipal> ValidateIdentityToken(string idToken)\n    {\n        var user = await ValidateJwt(idToken);\n\n        var nonce = user.FindFirst(\"nonce\")?.Value ?? \"\";\n        if (!string.Equals(nonce, \"random_nonce\")) throw new Exception(\"invalid nonce\");\n\n        return user;\n    }\n\n    private async Task<ClaimsPrincipal> ValidateLogoutToken(string logoutToken)\n    {\n        var claims = await ValidateJwt(logoutToken);\n\n        if (claims.FindFirst(\"sub\") == null && claims.FindFirst(\"sid\") == null) throw new Exception(\"Invalid logout token\");\n\n        var nonce = claims.FindFirstValue(\"nonce\");\n        if (!String.IsNullOrWhiteSpace(nonce)) throw new Exception(\"Invalid logout token\");\n\n        var eventsJson = claims.FindFirst(\"events\")?.Value;\n        if (String.IsNullOrWhiteSpace(eventsJson)) throw new Exception(\"Invalid logout token\");\n\n        var events = JsonSerializer.Deserialize<JsonElement>(eventsJson);\n        var logoutEvent = events.TryGetValue(\"http://schemas.openid.net/event/backchannel-logout\");\n        if (logoutEvent.ValueKind== JsonValueKind.Null) throw new Exception(\"Invalid logout token\");\n\n        return claims;\n    }\n\n    private static async Task<ClaimsPrincipal> ValidateJwt(string jwt)\n    {\n        // read discovery document to find issuer and key material\n        var client = new HttpClient();\n        var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n\n        var keys = new List<SecurityKey>();\n        foreach (var webKey in disco.KeySet.Keys)\n        {\n            var e = Base64Url.Decode(webKey.E);\n            var n = Base64Url.Decode(webKey.N);\n\n            var key = new RsaSecurityKey(new RSAParameters { Exponent = e, Modulus = n })\n            {\n                KeyId = webKey.Kid\n            };\n\n            keys.Add(key);\n        }\n\n        var parameters = new TokenValidationParameters\n        {\n            ValidIssuer = disco.Issuer,\n            ValidAudience = \"mvc.manual\",\n            IssuerSigningKeys = keys,\n\n            NameClaimType = JwtClaimTypes.Name,\n            RoleClaimType = JwtClaimTypes.Role,\n\n            RequireSignedTokens = true\n        };\n\n        var handler = new JwtSecurityTokenHandler();\n        handler.InboundClaimTypeMap.Clear();\n\n        var user = handler.ValidateToken(jwt, parameters, out var _);\n        return user;\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcManual/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n"
  },
  {
    "path": "samples/Clients/old/MvcManual/MvcManual.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n</Project>\n"
  },
  {
    "path": "samples/Clients/old/MvcManual/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nWebHost.CreateDefaultBuilder(args)\n    .UseStartup<Startup>()\n    .Build();"
  },
  {
    "path": "samples/Clients/old/MvcManual/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:44078/\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"IIS Express\": {\n      \"commandName\": \"IISExpress\",\n      \"launchBrowser\": true\n    }\n  }\n}"
  },
  {
    "path": "samples/Clients/old/MvcManual/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class Startup\n{\n    public void ConfigureServices(IServiceCollection services)\n    {\n        services.AddMvc();\n\n        services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme)\n            .AddCookie(options =>\n            {\n                options.Cookie.Name = \"mvcmanual\";\n            });\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n        app.UseDeveloperExceptionPage();\n        app.UseStaticFiles();\n\n        app.UseRouting();\n        app.UseAuthentication();\n        app.UseAuthorization();\n\n        app.UseEndpoints(endpoints =>\n        {\n            endpoints.MapDefaultControllerRoute();\n        });\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcManual/Views/Home/Index.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Home Page\";\n}\n\n@if(User.Identity.IsAuthenticated)\n{\n    <h1>Logged in as: @User.Identity.Name</h1>\n}\nelse\n{\n    <h1>Not Logged In</h1>\n}"
  },
  {
    "path": "samples/Clients/old/MvcManual/Views/Home/Secure.cshtml",
    "content": "﻿<h1>Secure</h1>\n\n<div>\n    <dl>\n        @foreach (var claim in User.Claims)\n        {\n            <dt>@claim.Type</dt>\n            <dd>@claim.Value</dd>\n        }\n    </dl>\n</div>"
  },
  {
    "path": "samples/Clients/old/MvcManual/Views/Shared/Error.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n"
  },
  {
    "path": "samples/Clients/old/MvcManual/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html>\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MVC Manual</title>\n\n    <environment names=\"Development\">\n        <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.css\" />\n        <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n    </environment>\n    <environment names=\"Staging,Production\">\n        <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    </environment>\n</head>\n<body>\n    <div class=\"navbar navbar-inverse navbar-fixed-top\">\n        <div class=\"container\">\n            <div class=\"navbar-header\">\n                <button type=\"button\" class=\"navbar-toggle\" data-toggle=\"collapse\" data-target=\".navbar-collapse\">\n                    <span class=\"sr-only\">Toggle navigation</span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                </button>\n                <a asp-controller=\"Home\" asp-action=\"Index\" class=\"navbar-brand\">MVC Manual</a>\n            </div>\n            <div class=\"navbar-collapse collapse\">\n                <ul class=\"nav navbar-nav\">\n                    <li><a asp-controller=\"Home\" asp-action=\"Secure\">Secure</a></li>\n                    <li><a asp-controller=\"Home\" asp-action=\"Logout\">Logout</a></li>\n                </ul>\n            </div>\n        </div>\n    </div>\n    <div class=\"container body-content\">\n        @RenderBody()\n        <hr />\n        <footer>\n            <p>&copy; 2016 - MVC Manual</p>\n        </footer>\n    </div>\n\n    <environment names=\"Development\">\n        <script src=\"~/lib/jquery/dist/jquery.js\"></script>\n        <script src=\"~/lib/bootstrap/dist/js/bootstrap.js\"></script>\n    </environment>\n    <environment names=\"Staging,Production\">\n        <script src=\"~/lib/jquery/dist/jquery.js\"></script>\n        <script src=\"~/lib/bootstrap/dist/js/bootstrap.min.js\"></script>\n    </environment>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Clients/old/MvcManual/Views/_ViewImports.cshtml",
    "content": "\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Clients/old/MvcManual/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcManual/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Clients/old/MvcManual/wwwroot/css/site.css",
    "content": "﻿body {\n    padding-top: 50px;\n    padding-bottom: 20px;\n}\n\n/* Wrapping element */\n/* Set some basic padding to keep content from hitting the edges */\n.body-content {\n    padding-left: 15px;\n    padding-right: 15px;\n}\n\n/* Set widths on the form inputs since otherwise they're 100% wide */\ninput,\nselect,\ntextarea {\n    max-width: 280px;\n}\n\n/* Carousel */\n.carousel-caption {\n    z-index: 10 !important;\n}\n\n    .carousel-caption p {\n        font-size: 20px;\n        line-height: 1.4;\n    }\n\n@media (min-width: 768px) {\n    .carousel-caption {\n        z-index: 10 !important;\n    }\n}\n"
  },
  {
    "path": "samples/Clients/old/MvcManual/wwwroot/js/site.js",
    "content": "// Write your Javascript code.\n"
  },
  {
    "path": "samples/Clients/old/MvcUsings.cs",
    "content": "global using IdentityModel;\nglobal using IdentityModel.AspNetCore;\nglobal using IdentityModel.Client;\nglobal using Microsoft.AspNetCore;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authentication.Cookies;\nglobal using Microsoft.AspNetCore.Authentication.OpenIdConnect;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Http;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.Extensions.DependencyInjection;\nglobal using Microsoft.Extensions.Options;\nglobal using Microsoft.IdentityModel.Protocols.OpenIdConnect;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using System;\nglobal using System.Collections.Concurrent;\nglobal using System.Globalization;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Net.Http;\nglobal using System.Security.Cryptography;\nglobal using System.Text.Json;\nglobal using System.Threading.Tasks;\n"
  },
  {
    "path": "samples/Clients/readme.md",
    "content": "The client samples are designed to be used with the host in this repo:\n\nhttps://github.com/alexhiggins732/IdentityServer8/tree/main/src/IdentityServer8\n"
  },
  {
    "path": "samples/Clients/shared/Constants/ConsoleExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic static class ConsoleExtensions\n{\n    /// <summary>\n    /// Writes green text to the console.\n    /// </summary>\n    /// <param name=\"text\">The text.</param>\n    [DebuggerStepThrough]\n    public static void ConsoleGreen(this string text)\n    {\n        text.ColoredWriteLine(ConsoleColor.Green);\n    }\n\n    /// <summary>\n    /// Writes red text to the console.\n    /// </summary>\n    /// <param name=\"text\">The text.</param>\n    [DebuggerStepThrough]\n    public static void ConsoleRed(this string text)\n    {\n        text.ColoredWriteLine(ConsoleColor.Red);\n    }\n\n    /// <summary>\n    /// Writes yellow text to the console.\n    /// </summary>\n    /// <param name=\"text\">The text.</param>\n    [DebuggerStepThrough]\n    public static void ConsoleYellow(this string text)\n    {\n        text.ColoredWriteLine(ConsoleColor.Yellow);\n    }\n\n    /// <summary>\n    /// Writes out text with the specified ConsoleColor.\n    /// </summary>\n    /// <param name=\"text\">The text.</param>\n    /// <param name=\"color\">The color.</param>\n    [DebuggerStepThrough]\n    public static void ColoredWriteLine(this string text, ConsoleColor color)\n    {\n        Console.ForegroundColor = color;\n        Console.WriteLine(text);\n        Console.ResetColor();\n    }\n}\n"
  },
  {
    "path": "samples/Clients/shared/Constants/Constants.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class Constants\n{\n    public const string Authority = \"https://localhost:5001\";\n    public const string AuthorityMtls = \"https://identityserver.local\";\n\n    public const string SampleApi = \"https://localhost:5005/\";\n    public const string SampleApiMtls = \"https://api.identityserver.local/\";\n}\n"
  },
  {
    "path": "samples/Clients/shared/Constants/Constants.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n</Project>"
  },
  {
    "path": "samples/Clients/shared/Constants/TokenResponseExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Clients;\n\npublic static class TokenResponseExtensions\n{\n    public static void Show(this TokenResponse response)\n    {\n        if (!response.IsError)\n        {\n            \"Token response:\".ConsoleGreen();\n            Console.WriteLine(response.Json);\n\n            if (response.AccessToken.Contains(\".\"))\n            {\n                \"\\nAccess Token (decoded):\".ConsoleGreen();\n\n                var parts = response.AccessToken.Split('.');\n                var header = parts[0];\n                var claims = parts[1];\n\n                var headerJson = Encoding.UTF8.GetString(Base64Url.Decode(header));\n                var claimsJson = Encoding.UTF8.GetString(Base64Url.Decode(claims));\n                Console.WriteLine(JsonSerializer.Deserialize<JsonElement>(headerJson));\n                Console.WriteLine(JsonSerializer.Deserialize<JsonElement>(claimsJson));\n            }\n        }\n        else\n        {\n            if (response.ErrorType == ResponseErrorType.Http)\n            {\n                \"HTTP error: \".ConsoleGreen();\n                Console.WriteLine(response.Error);\n                \"HTTP status code: \".ConsoleGreen();\n                Console.WriteLine(response.HttpStatusCode);\n            }\n            else\n            {\n                \"Protocol error response:\".ConsoleGreen();\n                Console.WriteLine(response.Raw);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/APIs/ResourceBasedApi/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConfigureLogger();\n\nConsole.Title = \"Resource API\";\n\nvar builder = WebApplication.CreateBuilder(args);\nbuilder.Host.UseSerilog();\n\nvar services = builder.Services;\n\nservices.AddControllers();\n\nservices.AddCors()\n    .AddDistributedMemoryCache()\n    .AddScopeTransformation()\n    .AddAuthentication(\"token\")\n\n    // JWT tokens\n    .AddJwtBearer(\"token\", options =>\n    {\n        options.Authority = Constants.Authority;\n        options.Audience = \"resource1\";\n\n        options.TokenValidationParameters.ValidTypes = new[] { \"at+jwt\" };\n\n        // if token does not contain a dot, it is a reference token\n        options.ForwardDefaultSelector = Selector.ForwardReferenceToken(\"introspection\");\n    })\n\n    // reference tokens\n    .AddOAuth2Introspection(\"introspection\", options =>\n    {\n        options.Authority = Constants.Authority;\n\n        options.ClientId = \"resource1\";\n        options.ClientSecret = \"secret\";\n    });\n\n\n\nusing (var app = builder.Build())\n{\n    app\n        .UseRouting()\n        .UseAuthentication()\n        .UseAuthorization()\n        .UseCors(policy =>\n        {\n            policy.WithOrigins(\"https://localhost:44300\");\n\n            policy.AllowAnyHeader();\n            policy.AllowAnyMethod();\n            policy.WithExposedHeaders(\"WWW-Authenticate\");\n        });\n\n    app.MapControllers().RequireAuthorization();\n\n    app.MapGet(\"/identity\", (HttpContext ctx, ILogger logger) =>\n    {\n        var claims = ctx.User.Claims.Select(c => new { c.Type, c.Value });\n        logger.LogInformation(\"claims: {claims}\", claims);\n        return Results.Json(claims);\n    });\n\n    await app.RunAsync();\n}\n\n\nvoid ConfigureLogger()\n{\n    Log.Logger = new LoggerConfiguration()\n        .MinimumLevel.Verbose()\n        .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n        .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n        .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n        .Enrich.FromLogContext()\n        .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n        .CreateLogger();\n}\n"
  },
  {
    "path": "samples/Clients/src/APIs/ResourceBasedApi/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"Api\": {\n      \"commandName\": \"Project\",\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5005\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Clients/src/APIs/ResourceBasedApi/ResourceBasedApi.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n</Project>"
  },
  {
    "path": "samples/Clients/src/APIs/SimpleApi/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConfigureLogger();\n\nConsole.Title = \"Resource API\";\n\nvar builder = WebApplication.CreateBuilder(args);\nbuilder.Host.UseSerilog();\n\nvar services = builder.Services;\n\nservices.AddControllers();\n\nservices.AddCors()\n    .AddDistributedMemoryCache()\n    .AddScopeTransformation()\n    .AddAuthentication(\"token\")\n\n    // JWT tokens\n    .AddJwtBearer(\"token\", options =>\n    {\n        options.Authority = Constants.Authority;\n        options.TokenValidationParameters.ValidateAudience = false;\n        options.TokenValidationParameters.ValidTypes = new[] { \"at+jwt\" };\n    })\n\n    // Use multiple token validation handlers:\n    // https://stackoverflow.com/questions/63399810/can-i-create-an-identity-server-4-asp-net-core-api-using-2-different-token-authe\n    //https://leastprivilege.com/2020/07/06/flexible-access-token-validation-in-asp-net-core/\n    //https://leastprivilege.com/2020/06/15/the-jwt-profile-for-oauth-2-0-access-tokens-and-identityserver/\n    // reference tokens\n    .AddOAuth2Introspection(\"introspection\", options =>\n    {\n        options.Authority = Constants.Authority;\n        options.ClientId = \"resource1\";\n        options.ClientSecret = \"secret\";\n    });\n\n\n\nusing (var app = builder.Build())\n{\n    app\n        .UseRouting()\n        .UseAuthentication()\n        .UseAuthorization()\n        .UseCors(policy =>\n        {\n            policy.WithOrigins(\"https://localhost:44300\");\n\n            policy.AllowAnyHeader();\n            policy.AllowAnyMethod();\n            policy.WithExposedHeaders(\"WWW-Authenticate\");\n        });\n\n\n\n    app.MapGet(\"/identity\", (HttpContext ctx, ILogger logger) =>\n    {\n        var claims = ctx.User.Claims.Select(c => new { c.Type, c.Value });\n        logger.LogInformation(\"claims: {claims}\", claims);\n        return Results.Json(claims);\n    });\n\n    await app.RunAsync();\n}\n\n\nvoid ConfigureLogger()\n{\n    Log.Logger = new LoggerConfiguration()\n        .MinimumLevel.Verbose()\n        .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n        .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n        .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n        .Enrich.FromLogContext()\n        .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n        .CreateLogger();\n}\n"
  },
  {
    "path": "samples/Clients/src/APIs/SimpleApi/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"Api\": {\n      \"commandName\": \"Project\",\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5005\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Clients/src/APIs/SimpleApi/SimpleApi.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n</Project>"
  },
  {
    "path": "samples/Clients/src/Clients.sln",
    "content": "﻿\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 10.0.40219.1\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Solution Items\", \"Solution Items\", \"{179A2A2C-3B3D-437C-B5F3-3B81472C8335}\"\n\tProjectSection(SolutionItems) = preProject\n\t\t..\\shared\\Constants\\Constants.csproj = ..\\shared\\Constants\\Constants.csproj\n\t\t..\\Directory.Build.props = ..\\Directory.Build.props\n\t\t..\\SolutionUsings.cs = ..\\SolutionUsings.cs\n\tEndProjectSection\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"APIs\", \"APIs\", \"{AFE7085F-051E-4829-955F-3426FE643BDD}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleClientCredentialsFlow\", \"ConsoleClientCredentialsFlow\\ConsoleClientCredentialsFlow.csproj\", \"{6729A51B-A7D9-43F3-8F48-D55478254AB7}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleResourceOwnerFlow\", \"ConsoleResourceOwnerFlow\\ConsoleResourceOwnerFlow.csproj\", \"{9BFE1F4E-C2F4-49FC-917E-BE25C0F42D84}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleClientCredentialsFlowPostBody\", \"ConsoleClientCredentialsFlowPostBody\\ConsoleClientCredentialsFlowPostBody.csproj\", \"{BEA2C25F-0551-4AFC-9961-7DB934724FF1}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleResourceOwnerFlowRefreshToken\", \"ConsoleResourceOwnerFlowRefreshToken\\ConsoleResourceOwnerFlowRefreshToken.csproj\", \"{2952A3E3-8831-419B-B14C-448C409961A7}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleResourceOwnerFlowUserInfo\", \"ConsoleResourceOwnerFlowUserInfo\\ConsoleResourceOwnerFlowUserInfo.csproj\", \"{120F561D-5670-4C80-8CAB-4D770204DC91}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleIntrospectionClient\", \"ConsoleIntrospectionClient\\ConsoleIntrospectionClient.csproj\", \"{395F9DF7-AE5A-403E-BE7A-4AF045B21BB3}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleResourceOwnerFlowReference\", \"ConsoleResourceOwnerFlowReference\\ConsoleResourceOwnerFlowReference.csproj\", \"{0E9145DB-CC70-44F9-B52B-1D7D4C2B2E5F}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleExtensionGrant\", \"ConsoleCustomGrant\\ConsoleExtensionGrant.csproj\", \"{546267CD-BE21-44E1-A06E-C7558864EE4F}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"JsOidc\", \"JsOidc\\JsOidc.csproj\", \"{A29115B9-30E4-4967-AD5A-C32394B8A64C}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleResourceOwnerFlowPublic\", \"ConsoleResourceOwnerFlowPublic\\ConsoleResourceOwnerFlowPublic.csproj\", \"{8648122C-EE91-4B3B-98CD-355C3F1B9FDF}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsolePrivateKeyJwtClient\", \"ConsolePrivateKeyJwtClient\\ConsolePrivateKeyJwtClient.csproj\", \"{1EC25581-781E-4FEA-A8AC-72BBD599FB87}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleCode\", \"ConsoleCode\\ConsoleCode.csproj\", \"{BB38F47A-1BBF-47E1-9872-088FC81DC825}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcHybridBackChannel\", \"MvcHybridBackChannel\\MvcHybridBackChannel.csproj\", \"{57F395AD-48D2-48BF-A117-881E112D947E}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleDeviceFlow\", \"ConsoleDeviceFlow\\ConsoleDeviceFlow.csproj\", \"{879689CC-38F7-418F-9721-9D4158302B69}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleClientCredentialsFlowCallingIdentityServerApi\", \"ConsoleClientCredentialsFlowCallingIdentityServerApi\\ConsoleClientCredentialsFlowCallingIdentityServerApi.csproj\", \"{141BD303-CD29-472F-B5D8-C1F28ED0621A}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleMTLSClient\", \"ConsoleMTLSClient\\ConsoleMTLSClient.csproj\", \"{EA1583D5-80DE-4A11-9530-26A0ED1FBA2C}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcCode\", \"MvcCode\\MvcCode.csproj\", \"{9FB83FF6-5A75-4036-80E6-11B302B921BE}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcAutomaticTokenManagement\", \"MvcAutomaticTokenManagement\\MvcAutomaticTokenManagement.csproj\", \"{8302E4DD-2A99-439C-9D0C-A4BCF48E3FA3}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"WindowsConsoleSystemBrowser\", \"WindowsConsoleSystemBrowser\\WindowsConsoleSystemBrowser.csproj\", \"{43BF1DCB-7343-471E-A53C-D59F19E2EB74}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleEphemeralMtlsClient\", \"ConsoleEphemeralMtlsClient\\ConsoleEphemeralMtlsClient.csproj\", \"{47A706D4-4DF6-437E-9401-61878ECA243C}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Web\", \"Web\", \"{158628D7-8B68-451E-AF22-B64F473C5943}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Console\", \"Console\", \"{D027D36B-262B-450A-B444-5B7893B5142E}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleParameterizedScopeClient\", \"ConsoleParameterizedScopeClient\\ConsoleParameterizedScopeClient.csproj\", \"{AE8D301D-BDDD-4E04-A487-FD08BAF18B75}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"SimpleApi\", \"APIs\\SimpleApi\\SimpleApi.csproj\", \"{215D863E-9D87-42F4-AD17-209C330C6ECB}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ResourceBasedApi\", \"APIs\\ResourceBasedApi\\ResourceBasedApi.csproj\", \"{933613BD-35B0-4F79-A7A7-02F663C55B61}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{EF723CAE-AB9F-4FFB-A36A-D56F9F1DC1B3}\"\n\tProjectSection(SolutionItems) = preProject\n\t\t..\\..\\Directory.Build.props = ..\\..\\Directory.Build.props\n\t\t..\\..\\Directory.Packages.props = ..\\..\\Directory.Packages.props\n\tEndProjectSection\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Constants\", \"..\\shared\\Constants\\Constants.csproj\", \"{DB7A49D0-27E5-4B20-A153-D132BE9655D3}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tRelease|Any CPU = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{6729A51B-A7D9-43F3-8F48-D55478254AB7}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{6729A51B-A7D9-43F3-8F48-D55478254AB7}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{6729A51B-A7D9-43F3-8F48-D55478254AB7}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{6729A51B-A7D9-43F3-8F48-D55478254AB7}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{9BFE1F4E-C2F4-49FC-917E-BE25C0F42D84}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{9BFE1F4E-C2F4-49FC-917E-BE25C0F42D84}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{9BFE1F4E-C2F4-49FC-917E-BE25C0F42D84}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{9BFE1F4E-C2F4-49FC-917E-BE25C0F42D84}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{BEA2C25F-0551-4AFC-9961-7DB934724FF1}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{BEA2C25F-0551-4AFC-9961-7DB934724FF1}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{BEA2C25F-0551-4AFC-9961-7DB934724FF1}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{BEA2C25F-0551-4AFC-9961-7DB934724FF1}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{2952A3E3-8831-419B-B14C-448C409961A7}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{2952A3E3-8831-419B-B14C-448C409961A7}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{2952A3E3-8831-419B-B14C-448C409961A7}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{2952A3E3-8831-419B-B14C-448C409961A7}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{120F561D-5670-4C80-8CAB-4D770204DC91}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{120F561D-5670-4C80-8CAB-4D770204DC91}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{120F561D-5670-4C80-8CAB-4D770204DC91}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{120F561D-5670-4C80-8CAB-4D770204DC91}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{395F9DF7-AE5A-403E-BE7A-4AF045B21BB3}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{395F9DF7-AE5A-403E-BE7A-4AF045B21BB3}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{395F9DF7-AE5A-403E-BE7A-4AF045B21BB3}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{395F9DF7-AE5A-403E-BE7A-4AF045B21BB3}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{0E9145DB-CC70-44F9-B52B-1D7D4C2B2E5F}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{0E9145DB-CC70-44F9-B52B-1D7D4C2B2E5F}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{0E9145DB-CC70-44F9-B52B-1D7D4C2B2E5F}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{0E9145DB-CC70-44F9-B52B-1D7D4C2B2E5F}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{546267CD-BE21-44E1-A06E-C7558864EE4F}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{546267CD-BE21-44E1-A06E-C7558864EE4F}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{546267CD-BE21-44E1-A06E-C7558864EE4F}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{546267CD-BE21-44E1-A06E-C7558864EE4F}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{A29115B9-30E4-4967-AD5A-C32394B8A64C}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{A29115B9-30E4-4967-AD5A-C32394B8A64C}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{A29115B9-30E4-4967-AD5A-C32394B8A64C}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{A29115B9-30E4-4967-AD5A-C32394B8A64C}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{8648122C-EE91-4B3B-98CD-355C3F1B9FDF}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{8648122C-EE91-4B3B-98CD-355C3F1B9FDF}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{8648122C-EE91-4B3B-98CD-355C3F1B9FDF}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{8648122C-EE91-4B3B-98CD-355C3F1B9FDF}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{1EC25581-781E-4FEA-A8AC-72BBD599FB87}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{1EC25581-781E-4FEA-A8AC-72BBD599FB87}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{1EC25581-781E-4FEA-A8AC-72BBD599FB87}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{1EC25581-781E-4FEA-A8AC-72BBD599FB87}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{BB38F47A-1BBF-47E1-9872-088FC81DC825}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{BB38F47A-1BBF-47E1-9872-088FC81DC825}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{BB38F47A-1BBF-47E1-9872-088FC81DC825}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{BB38F47A-1BBF-47E1-9872-088FC81DC825}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{57F395AD-48D2-48BF-A117-881E112D947E}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{57F395AD-48D2-48BF-A117-881E112D947E}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{57F395AD-48D2-48BF-A117-881E112D947E}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{57F395AD-48D2-48BF-A117-881E112D947E}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{879689CC-38F7-418F-9721-9D4158302B69}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{879689CC-38F7-418F-9721-9D4158302B69}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{879689CC-38F7-418F-9721-9D4158302B69}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{879689CC-38F7-418F-9721-9D4158302B69}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{141BD303-CD29-472F-B5D8-C1F28ED0621A}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{141BD303-CD29-472F-B5D8-C1F28ED0621A}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{141BD303-CD29-472F-B5D8-C1F28ED0621A}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{141BD303-CD29-472F-B5D8-C1F28ED0621A}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{EA1583D5-80DE-4A11-9530-26A0ED1FBA2C}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{EA1583D5-80DE-4A11-9530-26A0ED1FBA2C}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{EA1583D5-80DE-4A11-9530-26A0ED1FBA2C}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{EA1583D5-80DE-4A11-9530-26A0ED1FBA2C}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{9FB83FF6-5A75-4036-80E6-11B302B921BE}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{9FB83FF6-5A75-4036-80E6-11B302B921BE}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{9FB83FF6-5A75-4036-80E6-11B302B921BE}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{9FB83FF6-5A75-4036-80E6-11B302B921BE}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{8302E4DD-2A99-439C-9D0C-A4BCF48E3FA3}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{8302E4DD-2A99-439C-9D0C-A4BCF48E3FA3}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{8302E4DD-2A99-439C-9D0C-A4BCF48E3FA3}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{8302E4DD-2A99-439C-9D0C-A4BCF48E3FA3}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{43BF1DCB-7343-471E-A53C-D59F19E2EB74}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{43BF1DCB-7343-471E-A53C-D59F19E2EB74}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{43BF1DCB-7343-471E-A53C-D59F19E2EB74}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{43BF1DCB-7343-471E-A53C-D59F19E2EB74}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{47A706D4-4DF6-437E-9401-61878ECA243C}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{47A706D4-4DF6-437E-9401-61878ECA243C}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{47A706D4-4DF6-437E-9401-61878ECA243C}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{47A706D4-4DF6-437E-9401-61878ECA243C}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{AE8D301D-BDDD-4E04-A487-FD08BAF18B75}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{AE8D301D-BDDD-4E04-A487-FD08BAF18B75}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{AE8D301D-BDDD-4E04-A487-FD08BAF18B75}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{AE8D301D-BDDD-4E04-A487-FD08BAF18B75}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{215D863E-9D87-42F4-AD17-209C330C6ECB}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{215D863E-9D87-42F4-AD17-209C330C6ECB}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{215D863E-9D87-42F4-AD17-209C330C6ECB}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{215D863E-9D87-42F4-AD17-209C330C6ECB}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{933613BD-35B0-4F79-A7A7-02F663C55B61}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{933613BD-35B0-4F79-A7A7-02F663C55B61}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{933613BD-35B0-4F79-A7A7-02F663C55B61}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{933613BD-35B0-4F79-A7A7-02F663C55B61}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{DB7A49D0-27E5-4B20-A153-D132BE9655D3}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{DB7A49D0-27E5-4B20-A153-D132BE9655D3}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{DB7A49D0-27E5-4B20-A153-D132BE9655D3}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{DB7A49D0-27E5-4B20-A153-D132BE9655D3}.Release|Any CPU.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{6729A51B-A7D9-43F3-8F48-D55478254AB7} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{9BFE1F4E-C2F4-49FC-917E-BE25C0F42D84} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{BEA2C25F-0551-4AFC-9961-7DB934724FF1} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{2952A3E3-8831-419B-B14C-448C409961A7} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{120F561D-5670-4C80-8CAB-4D770204DC91} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{395F9DF7-AE5A-403E-BE7A-4AF045B21BB3} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{0E9145DB-CC70-44F9-B52B-1D7D4C2B2E5F} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{546267CD-BE21-44E1-A06E-C7558864EE4F} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{A29115B9-30E4-4967-AD5A-C32394B8A64C} = {158628D7-8B68-451E-AF22-B64F473C5943}\n\t\t{8648122C-EE91-4B3B-98CD-355C3F1B9FDF} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{1EC25581-781E-4FEA-A8AC-72BBD599FB87} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{BB38F47A-1BBF-47E1-9872-088FC81DC825} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{57F395AD-48D2-48BF-A117-881E112D947E} = {158628D7-8B68-451E-AF22-B64F473C5943}\n\t\t{879689CC-38F7-418F-9721-9D4158302B69} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{141BD303-CD29-472F-B5D8-C1F28ED0621A} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{EA1583D5-80DE-4A11-9530-26A0ED1FBA2C} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{9FB83FF6-5A75-4036-80E6-11B302B921BE} = {158628D7-8B68-451E-AF22-B64F473C5943}\n\t\t{8302E4DD-2A99-439C-9D0C-A4BCF48E3FA3} = {158628D7-8B68-451E-AF22-B64F473C5943}\n\t\t{43BF1DCB-7343-471E-A53C-D59F19E2EB74} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{47A706D4-4DF6-437E-9401-61878ECA243C} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{AE8D301D-BDDD-4E04-A487-FD08BAF18B75} = {D027D36B-262B-450A-B444-5B7893B5142E}\n\t\t{215D863E-9D87-42F4-AD17-209C330C6ECB} = {AFE7085F-051E-4829-955F-3426FE643BDD}\n\t\t{933613BD-35B0-4F79-A7A7-02F663C55B61} = {AFE7085F-051E-4829-955F-3426FE643BDD}\n\t\t{EF723CAE-AB9F-4FFB-A36A-D56F9F1DC1B3} = {179A2A2C-3B3D-437C-B5F3-3B81472C8335}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {BAD78470-3D66-466E-9C17-2A67F0905B18}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "samples/Clients/src/ConsoleClientCredentialsFlow/ConsoleClientCredentialsFlow.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n    <PropertyGroup>\n        <OutputType>Exe</OutputType>\n    </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleClientCredentialsFlow/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConsole.Title = \"Console Client Credentials Flow\";\n\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\n\n\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var client = new HttpClient();\n\n    var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var response = await client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n\n        ClientId = \"client\",\n        ClientSecret = \"secret\",\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.SampleApi;\n\n    var client = new HttpClient\n    {\n        BaseAddress = new Uri(baseAddress)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var obj = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(obj);\n}"
  },
  {
    "path": "samples/Clients/src/ConsoleClientCredentialsFlowCallingIdentityServerApi/ConsoleClientCredentialsFlowCallingIdentityServerApi.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n  </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleClientCredentialsFlowCallingIdentityServerApi/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n\nConsole.Title = \"Console Client Credentials Flow calling IdentityServer API\";\n\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\n\n\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var client = new HttpClient();\n\n    var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var response = await client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n\n        ClientId = \"client\",\n        ClientSecret = \"secret\",\n        Scope = \"IdentityServerApi\"\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.Authority;\n\n    var client = new HttpClient\n    {\n        BaseAddress = new Uri(baseAddress)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"localApi\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var obj = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(obj);\n}\n\n"
  },
  {
    "path": "samples/Clients/src/ConsoleClientCredentialsFlowPostBody/ConsoleClientCredentialsFlowPostBody.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n    <PropertyGroup>\n        <OutputType>Exe</OutputType>\n    </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleClientCredentialsFlowPostBody/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConsole.Title = \"Console ClientCredentials Flow PostBody\";\n\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\n\n\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var client = new HttpClient();\n\n    var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var response = await client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n        ClientCredentialStyle = ClientCredentialStyle.PostBody,\n\n        ClientId = \"client\",\n        ClientSecret = \"secret\",\n        Scope = \"resource1.scope1\"\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.SampleApi;\n\n    var client = new HttpClient\n    {\n        BaseAddress = new Uri(baseAddress)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var obj = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(obj);\n}"
  },
  {
    "path": "samples/Clients/src/ConsoleCode/ConsoleCode.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n    <PropertyGroup>\n        <OutputType>Exe</OutputType>\n    </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleCode/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nOidcClient oidcClient = null!;\nHttpClient apiClient = new HttpClient { BaseAddress = new Uri(Constants.SampleApi) };\n\n\nConsole.WriteLine(\"+-----------------------+\");\nConsole.WriteLine(\"|  Sign in with OIDC    |\");\nConsole.WriteLine(\"+-----------------------+\");\nConsole.WriteLine(\"\");\nConsole.WriteLine(\"Press any key to sign in...\");\nConsole.ReadKey();\n\nawait SignIn();\n\n async Task SignIn()\n{\n    // create a redirect URI using an available port on the loopback address.\n    // requires the OP to allow random ports on 127.0.0.1 - otherwise set a static port\n    var browser = new SystemBrowser();\n    string redirectUri = string.Format($\"http://127.0.0.1:{browser.Port}\");\n\n    var options = new OidcClientOptions\n    {\n        Authority = Constants.Authority,\n\n        ClientId = \"console.pkce\",\n\n        RedirectUri = redirectUri,\n        Scope = \"openid profile resource1.scope1\",\n        FilterClaims = false,\n        Browser = browser\n    };\n\n    var serilog = new LoggerConfiguration()\n        .MinimumLevel.Error()\n        .Enrich.FromLogContext()\n        .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message}{NewLine}{Exception}{NewLine}\")\n        .CreateLogger();\n\n    options.LoggerFactory.AddSerilog(serilog);\n\n    oidcClient = new OidcClient(options);\n    var result = await oidcClient.LoginAsync(new LoginRequest());\n\n    ShowResult(result);\n    await NextSteps(result);\n}\n\nvoid ShowResult(LoginResult result)\n{\n    if (result.IsError)\n    {\n        Console.WriteLine(\"\\n\\nError:\\n{0}\", result.Error);\n        return;\n    }\n\n    Console.WriteLine(\"\\n\\nClaims:\");\n    foreach (var claim in result.User.Claims)\n    {\n        Console.WriteLine(\"{0}: {1}\", claim.Type, claim.Value);\n    }\n\n    Console.WriteLine($\"\\nidentity token: {result.IdentityToken}\");\n    Console.WriteLine($\"access token:   {result.AccessToken}\");\n    Console.WriteLine($\"refresh token:  {result?.RefreshToken ?? \"none\"}\");\n}\n\nasync Task NextSteps(LoginResult result)\n{\n    var currentAccessToken = result.AccessToken;\n    var currentRefreshToken = result.RefreshToken;\n\n    var menu = \"  x...exit  c...call api   \";\n    if (currentRefreshToken != null) menu += \"r...refresh token   \";\n\n    while (true)\n    {\n        Console.WriteLine(\"\\n\\n\");\n\n        Console.Write(menu);\n        var key = Console.ReadKey();\n\n        if (key.Key == ConsoleKey.X) return;\n        if (key.Key == ConsoleKey.C) await CallApi(currentAccessToken);\n        if (key.Key == ConsoleKey.R)\n        {\n            var refreshResult = await oidcClient.RefreshTokenAsync(currentRefreshToken);\n            if (result.IsError)\n            {\n                Console.WriteLine($\"Error: {refreshResult.Error}\");\n            }\n            else\n            {\n                currentRefreshToken = refreshResult.RefreshToken;\n                currentAccessToken = refreshResult.AccessToken;\n\n                Console.WriteLine(\"\\n\\n\");\n                Console.WriteLine($\"access token:   {result.AccessToken}\");\n                Console.WriteLine($\"refresh token:  {result?.RefreshToken ?? \"none\"}\");\n            }\n        }\n    }\n}\n\nasync Task CallApi(string currentAccessToken)\n{\n    apiClient.SetBearerToken(currentAccessToken);\n    var response = await apiClient.GetAsync(\"identity\");\n\n    if (response.IsSuccessStatusCode)\n    {\n        var json = JsonSerializer.Deserialize<JsonElement>(await response.Content.ReadAsStringAsync());\n        Console.WriteLine(\"\\n\\n\");\n        Console.WriteLine(json);\n    }\n    else\n    {\n        Console.WriteLine($\"Error: {response.ReasonPhrase}\");\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/ConsoleCode/SystemBrowser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class SystemBrowser : IBrowser\n{\n    public int Port { get; }\n    private readonly string _path;\n\n    public SystemBrowser(int? port = null, string path = null)\n    {\n        _path = path;\n\n        if (!port.HasValue)\n        {\n            Port = GetRandomUnusedPort();\n        }\n        else\n        {\n            Port = port.Value;\n        }\n    }\n\n    private int GetRandomUnusedPort()\n    {\n        var listener = new TcpListener(IPAddress.Loopback, 0);\n        listener.Start();\n        var port = ((IPEndPoint)listener.LocalEndpoint).Port;\n        listener.Stop();\n        return port;\n    }\n\n    public async Task<BrowserResult> InvokeAsync(BrowserOptions options, CancellationToken cancellationToken = default)\n    {\n        using (var listener = new LoopbackHttpListener(Port, _path))\n        {\n            OpenBrowser(options.StartUrl);\n\n            try\n            {\n                var result = await listener.WaitForCallbackAsync();\n                if (String.IsNullOrWhiteSpace(result))\n                {\n                    return new BrowserResult { ResultType = BrowserResultType.UnknownError, Error = \"Empty response.\" };\n                }\n\n                return new BrowserResult { Response = result, ResultType = BrowserResultType.Success };\n            }\n            catch (TaskCanceledException ex)\n            {\n                return new BrowserResult { ResultType = BrowserResultType.Timeout, Error = ex.Message };\n            }\n            catch (Exception ex)\n            {\n                return new BrowserResult { ResultType = BrowserResultType.UnknownError, Error = ex.Message };\n            }\n        }\n    }\n\n    public static void OpenBrowser(string url)\n    {\n        try\n        {\n            Process.Start(url);\n        }\n        catch\n        {\n            // hack because of this: https://github.com/dotnet/corefx/issues/10361\n            if (RuntimeInformation.IsOSPlatform(OSPlatform.Windows))\n            {\n                url = url.Replace(\"&\", \"^&\");\n                Process.Start(new ProcessStartInfo(\"cmd\", $\"/c start {url}\") { CreateNoWindow = true });\n            }\n            else if (RuntimeInformation.IsOSPlatform(OSPlatform.Linux))\n            {\n                Process.Start(\"xdg-open\", url);\n            }\n            else if (RuntimeInformation.IsOSPlatform(OSPlatform.OSX))\n            {\n                Process.Start(\"open\", url);\n            }\n            else\n            {\n                throw;\n            }\n        }\n    }\n}\n\npublic class LoopbackHttpListener : IDisposable\n{\n    const int DefaultTimeout = 60 * 5; // 5 mins (in seconds)\n\n    IWebHost _host;\n    TaskCompletionSource<string> _source = new TaskCompletionSource<string>();\n    string _url;\n\n    public string Url => _url;\n\n    public LoopbackHttpListener(int port, string path = null)\n    {\n        path = path ?? String.Empty;\n        if (path.StartsWith(\"/\")) path = path.Substring(1);\n\n        _url = $\"http://127.0.0.1:{port}/{path}\";\n\n        _host = new WebHostBuilder()\n            .UseKestrel()\n            .UseUrls(_url)\n            .Configure(Configure)\n            .Build();\n        _host.Start();\n    }\n\n    public void Dispose()\n    {\n        Task.Run(async () =>\n        {\n            await Task.Delay(500);\n            _host.Dispose();\n        });\n    }\n\n    void Configure(IApplicationBuilder app)\n    {\n        app.Run(async ctx =>\n        {\n            if (ctx.Request.Method == \"GET\")\n            {\n                SetResult(ctx.Request.QueryString.Value, ctx);\n            }\n            else if (ctx.Request.Method == \"POST\")\n            {\n                if (!ctx.Request.ContentType.Equals(\"application/x-www-form-urlencoded\", StringComparison.OrdinalIgnoreCase))\n                {\n                    ctx.Response.StatusCode = 415;\n                }\n                else\n                {\n                    using (var sr = new StreamReader(ctx.Request.Body, Encoding.UTF8))\n                    {\n                        var body = await sr.ReadToEndAsync();\n                        SetResult(body, ctx);\n                    }\n                }\n            }\n            else\n            {\n                ctx.Response.StatusCode = 405;\n            }\n        });\n    }\n\n    private void SetResult(string value, HttpContext ctx)\n    {\n        try\n        {\n            ctx.Response.StatusCode = 200;\n            ctx.Response.ContentType = \"text/html\";\n            ctx.Response.WriteAsync(\"<h1>You can now return to the application.</h1>\");\n            ctx.Response.Body.Flush();\n\n            _source.TrySetResult(value);\n        }\n        catch\n        {\n            ctx.Response.StatusCode = 400;\n            ctx.Response.ContentType = \"text/html\";\n            ctx.Response.WriteAsync(\"<h1>Invalid request.</h1>\");\n            ctx.Response.Body.Flush();\n        }\n    }\n\n    public Task<string> WaitForCallbackAsync(int timeoutInSeconds = DefaultTimeout)\n    {\n        Task.Run(async () =>\n        {\n            await Task.Delay(timeoutInSeconds * 1000);\n            _source.TrySetCanceled();\n        });\n\n        return _source.Task;\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/ConsoleCustomGrant/ConsoleExtensionGrant.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n  </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleCustomGrant/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nIDiscoveryCache cache = new DiscoveryCache(Constants.Authority);\n\n\nConsole.Title = \"Console Custom Grant\";\n\n// custom grant type with subject support\nvar response = await RequestTokenAsync(\"custom\");\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\n\nConsole.ReadLine();\n\n// custom grant type without subject support\nresponse = await RequestTokenAsync(\"custom.nosubject\");\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\n\n\nasync Task<TokenResponse> RequestTokenAsync(string grantType)\n{\n    var client = new HttpClient();\n\n    var disco = await cache.GetAsync();\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var response = await client.RequestTokenAsync(new TokenRequest\n    {\n        Address = disco.TokenEndpoint,\n        GrantType = grantType,\n\n        ClientId = \"client.custom\",\n        ClientSecret = \"secret\",\n\n        Parameters =\n                {\n                    { \"scope\", \"resource1.scope1\" },\n                    { \"custom_credential\", \"custom credential\"}\n                }\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.SampleApi;\n\n    var client = new HttpClient\n    {\n        BaseAddress = new Uri(baseAddress)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var json = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(json);\n}\n"
  },
  {
    "path": "samples/Clients/src/ConsoleDeviceFlow/ConsoleDeviceFlow.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n  </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleDeviceFlow/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nIDiscoveryCache cache = new DiscoveryCache(Constants.Authority);\n\nConsole.Title = \"Console Device Flow\";\n\nvar authorizeResponse = await RequestAuthorizationAsync();\n\nvar tokenResponse = await RequestTokenAsync(authorizeResponse);\ntokenResponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(tokenResponse.AccessToken);\n\n\nasync Task<DeviceAuthorizationResponse> RequestAuthorizationAsync()\n{\n    var disco = await cache.GetAsync();\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var client = new HttpClient();\n    var response = await client.RequestDeviceAuthorizationAsync(new DeviceAuthorizationRequest\n    {\n        Address = disco.DeviceAuthorizationEndpoint,\n        ClientId = \"device\"\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n\n    Console.WriteLine($\"user code   : {response.UserCode}\");\n    Console.WriteLine($\"device code : {response.DeviceCode}\");\n    Console.WriteLine($\"URL         : {response.VerificationUri}\");\n    Console.WriteLine($\"Complete URL: {response.VerificationUriComplete}\");\n\n    Console.WriteLine($\"\\nPress enter to launch browser ({response.VerificationUri})\");\n    Console.ReadLine();\n\n    Process.Start(new ProcessStartInfo(response.VerificationUriComplete) { UseShellExecute = true });\n    return response;\n}\n\nasync Task<TokenResponse> RequestTokenAsync(DeviceAuthorizationResponse authorizeResponse)\n{\n    var disco = await cache.GetAsync();\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var client = new HttpClient();\n\n    while (true)\n    {\n        var response = await client.RequestDeviceTokenAsync(new DeviceTokenRequest\n        {\n            Address = disco.TokenEndpoint,\n            ClientId = \"device\",\n            DeviceCode = authorizeResponse.DeviceCode\n        });\n\n        if (response.IsError)\n        {\n            if (response.Error == OidcConstants.TokenErrors.AuthorizationPending || response.Error == OidcConstants.TokenErrors.SlowDown)\n            {\n                Console.WriteLine($\"{response.Error}...waiting.\");\n                Thread.Sleep(authorizeResponse.Interval * 1000);\n            }\n            else\n            {\n                throw new Exception(response.Error);\n            }\n        }\n        else\n        {\n            return response;\n        }\n    }\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.SampleApi;\n\n    var client = new HttpClient\n    {\n        BaseAddress = new Uri(baseAddress)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var json = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(json);\n}\n"
  },
  {
    "path": "samples/Clients/src/ConsoleEphemeralMtlsClient/ConsoleEphemeralMtlsClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n    <PropertyGroup>\n        <OutputType>Exe</OutputType>\n    </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleEphemeralMtlsClient/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Clients;\nglobal using IdentityModel.Client;\nglobal using System.Security.Cryptography;\nglobal using System.Security.Cryptography.X509Certificates;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Clients/src/ConsoleEphemeralMtlsClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nX509Certificate2 clientCertificate = null!;\n\n\nclientCertificate = CreateClientCertificate(\"client\");\n\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\n\n\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var client = new HttpClient(GetHandler(clientCertificate));\n\n    var disco = await client.GetDiscoveryDocumentAsync(Constants.AuthorityMtls);\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var endpoint = disco.TokenEndpoint;\n    //.TryGetValue(OidcConstants.Discovery.MtlsEndpointAliases)\n    //.TryGetValue<string>(OidcConstants.Discovery.TokenEndpoint)\n    ////.Value<string>(OidcConstants.Discovery.TokenEndpoint)\n    //.ToString();\n\n    var response = await client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n    {\n        Address = endpoint,\n\n        ClientId = \"client\",\n        ClientSecret = \"secret\",\n        Scope = \"resource1.scope1\"\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var client = new HttpClient(GetHandler(clientCertificate))\n    {\n        BaseAddress = new Uri(Constants.SampleApiMtls)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var json = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(json);\n}\n\nX509Certificate2 CreateClientCertificate(string name)\n{\n    X500DistinguishedName distinguishedName = new X500DistinguishedName($\"CN={name}\");\n\n    using (var rsa = RSA.Create(2048))\n    {\n        var request = new CertificateRequest(distinguishedName, rsa, HashAlgorithmName.SHA256, RSASignaturePadding.Pkcs1);\n\n        request.CertificateExtensions.Add(\n            new X509KeyUsageExtension(X509KeyUsageFlags.DataEncipherment | X509KeyUsageFlags.KeyEncipherment | X509KeyUsageFlags.DigitalSignature, false));\n\n        request.CertificateExtensions.Add(\n            new X509EnhancedKeyUsageExtension(\n                new OidCollection { new Oid(\"1.3.6.1.5.5.7.3.2\") }, false));\n\n        return request.CreateSelfSigned(new DateTimeOffset(DateTime.UtcNow.AddDays(-1)), new DateTimeOffset(DateTime.UtcNow.AddDays(3650)));\n    }\n}\n\nSocketsHttpHandler GetHandler(X509Certificate2 certificate)\n{\n    var handler = new SocketsHttpHandler\n    {\n        SslOptions =\n                {\n                    ClientCertificates = new X509CertificateCollection {certificate}\n                }\n    };\n\n    return handler;\n}\n"
  },
  {
    "path": "samples/Clients/src/ConsoleIntrospectionClient/ConsoleIntrospectionClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n    <PropertyGroup>\n        <OutputType>Exe</OutputType>\n    </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleIntrospectionClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nIDiscoveryCache cached = new DiscoveryCache(Constants.Authority);\n\n\nConsole.Title = \"Console Introspection Client\";\n\nvar response = await RequestTokenAsync();\nawait IntrospectAsync(response.AccessToken);\n\n\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var disco = await cached.GetAsync();\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var client = new HttpClient();\n    var response = await client.RequestPasswordTokenAsync(new PasswordTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n\n        ClientId = \"roclient.reference\",\n        ClientSecret = \"secret\",\n\n        UserName = \"bob\",\n        Password = \"bob\",\n        Scope = \"resource1.scope1 resource2.scope1\"\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n async Task IntrospectAsync(string accessToken)\n{\n    var disco = await cached.GetAsync();\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var client = new HttpClient();\n    var result = await client.IntrospectTokenAsync(new TokenIntrospectionRequest\n    {\n        Address = disco.IntrospectionEndpoint,\n\n        ClientId = \"api1\",\n        ClientSecret = \"secret\",\n        Token = accessToken\n    });\n\n    if (result.IsError)\n    {\n        Console.WriteLine(result.Error);\n    }\n    else\n    {\n        if (result.IsActive)\n        {\n            result.Claims.ToList().ForEach(c => Console.WriteLine(\"{0}: {1}\",\n                c.Type, c.Value));\n        }\n        else\n        {\n            Console.WriteLine(\"token is not active\");\n        }\n    }\n}"
  },
  {
    "path": "samples/Clients/src/ConsoleMTLSClient/ConsoleMTLSClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n  <PropertyGroup> \n    <OutputType>Exe</OutputType>\n  </PropertyGroup>\n  <ItemGroup>\n    <None Update=\"client.p12\">\n      <CopyToOutputDirectory>PreserveNewest</CopyToOutputDirectory>\n    </None>\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleMTLSClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n\nConsole.Title = \"Console mTLS Client\";\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var client = new HttpClient(GetHandler());\n\n    var disco = await client.GetDiscoveryDocumentAsync(\"https://identityserver.local\");\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var endpoint = disco.TokenEndpoint;\n    //.TryGetValue(OidcConstants.Discovery.MtlsEndpointAliases)\n    //.Value<string>(OidcConstants.Discovery.TokenEndpoint)\n    //.ToString();\n\n    var response = await client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n    {\n        Address = endpoint,\n\n        ClientId = \"mtls\",\n        Scope = \"resource1.scope1\"\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var client = new HttpClient(GetHandler())\n    {\n        BaseAddress = new Uri(Constants.SampleApi)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var json = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(json);\n}\n\nSocketsHttpHandler GetHandler()\n{\n    var handler = new SocketsHttpHandler();\n\n    var cert = new X509Certificate2(\"client.p12\", \"changeit\");\n    handler.SslOptions.ClientCertificates = new X509CertificateCollection { cert };\n\n    return handler;\n}\n"
  },
  {
    "path": "samples/Clients/src/ConsoleParameterizedScopeClient/ConsoleParameterizedScopeClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n    <PropertyGroup>\n        <OutputType>Exe</OutputType>\n    </PropertyGroup>\n</Project>\n"
  },
  {
    "path": "samples/Clients/src/ConsoleParameterizedScopeClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConsole.Title = \"Console Parameterized Scope Client\";\n\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var client = new HttpClient();\n\n    var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var response = await client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n        ClientId = \"parameterized.client\",\n        ClientSecret = \"secret\",\n        Scope = \"transaction:123\"\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.SampleApi;\n\n    var client = new HttpClient { BaseAddress = new Uri(baseAddress) };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var json = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(json);\n}\n"
  },
  {
    "path": "samples/Clients/src/ConsolePrivateKeyJwtClient/ConsolePrivateKeyJwtClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n  </PropertyGroup>\n  <ItemGroup>\n    <None Update=\"client.p12\">\n      <CopyToOutputDirectory>PreserveNewest</CopyToOutputDirectory>\n    </None>\n  </ItemGroup>\n</Project>\n"
  },
  {
    "path": "samples/Clients/src/ConsolePrivateKeyJwtClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nstring rsaKey = \"{'d':'GmiaucNIzdvsEzGjZjd43SDToy1pz-Ph-shsOUXXh-dsYNGftITGerp8bO1iryXh_zUEo8oDK3r1y4klTonQ6bLsWw4ogjLPmL3yiqsoSjJa1G2Ymh_RY_sFZLLXAcrmpbzdWIAkgkHSZTaliL6g57vA7gxvd8L4s82wgGer_JmURI0ECbaCg98JVS0Srtf9GeTRHoX4foLWKc1Vq6NHthzqRMLZe-aRBNU9IMvXNd7kCcIbHCM3GTD_8cFj135nBPP2HOgC_ZXI1txsEf-djqJj8W5vaM7ViKU28IDv1gZGH3CatoysYx6jv1XJVvb2PH8RbFKbJmeyUm3Wvo-rgQ','dp':'YNjVBTCIwZD65WCht5ve06vnBLP_Po1NtL_4lkholmPzJ5jbLYBU8f5foNp8DVJBdFQW7wcLmx85-NC5Pl1ZeyA-Ecbw4fDraa5Z4wUKlF0LT6VV79rfOF19y8kwf6MigyrDqMLcH_CRnRGg5NfDsijlZXffINGuxg6wWzhiqqE','dq':'LfMDQbvTFNngkZjKkN2CBh5_MBG6Yrmfy4kWA8IC2HQqID5FtreiY2MTAwoDcoINfh3S5CItpuq94tlB2t-VUv8wunhbngHiB5xUprwGAAnwJ3DL39D2m43i_3YP-UO1TgZQUAOh7Jrd4foatpatTvBtY3F1DrCrUKE5Kkn770M','e':'AQAB','kid':'ZzAjSnraU3bkWGnnAqLapYGpTyNfLbjbzgAPbbW2GEA','kty':'RSA','n':'wWwQFtSzeRjjerpEM5Rmqz_DsNaZ9S1Bw6UbZkDLowuuTCjBWUax0vBMMxdy6XjEEK4Oq9lKMvx9JzjmeJf1knoqSNrox3Ka0rnxXpNAz6sATvme8p9mTXyp0cX4lF4U2J54xa2_S9NF5QWvpXvBeC4GAJx7QaSw4zrUkrc6XyaAiFnLhQEwKJCwUw4NOqIuYvYp_IXhw-5Ti_icDlZS-282PcccnBeOcX7vc21pozibIdmZJKqXNsL1Ibx5Nkx1F1jLnekJAmdaACDjYRLL_6n3W4wUp19UvzB1lGtXcJKLLkqB6YDiZNu16OSiSprfmrRXvYmvD8m6Fnl5aetgKw','p':'7enorp9Pm9XSHaCvQyENcvdU99WCPbnp8vc0KnY_0g9UdX4ZDH07JwKu6DQEwfmUA1qspC-e_KFWTl3x0-I2eJRnHjLOoLrTjrVSBRhBMGEH5PvtZTTThnIY2LReH-6EhceGvcsJ_MhNDUEZLykiH1OnKhmRuvSdhi8oiETqtPE','q':'0CBLGi_kRPLqI8yfVkpBbA9zkCAshgrWWn9hsq6a7Zl2LcLaLBRUxH0q1jWnXgeJh9o5v8sYGXwhbrmuypw7kJ0uA3OgEzSsNvX5Ay3R9sNel-3Mqm8Me5OfWWvmTEBOci8RwHstdR-7b9ZT13jk-dsZI7OlV_uBja1ny9Nz9ts','qi':'pG6J4dcUDrDndMxa-ee1yG4KjZqqyCQcmPAfqklI2LmnpRIjcK78scclvpboI3JQyg6RCEKVMwAhVtQM6cBcIO3JrHgqeYDblp5wXHjto70HVW6Z8kBruNx1AH9E8LzNvSRL-JVTFzBkJuNgzKQfD0G77tQRgJ-Ri7qu3_9o1M4'}\";\n\nConsole.Title = \"Console Client Credentials Flow with JWT Assertion\";\n\n// X.509 cert\nvar certificate = new X509Certificate2(\"client.p12\", \"changeit\");\nvar x509Credential = new X509SigningCredentials(certificate);\n\nvar response = await RequestTokenAsync(x509Credential);\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\n\n// RSA JsonWebkey\nvar jwk = new JsonWebKey(rsaKey);\nresponse = await RequestTokenAsync(new SigningCredentials(jwk, \"RS256\"));\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\nasync Task<TokenResponse> RequestTokenAsync(SigningCredentials credential)\n{\n    var client = new HttpClient();\n\n    var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var clientToken = CreateClientToken(credential, \"client.jwt\", disco.TokenEndpoint);\n\n    var response = await client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n        Scope = \"resource1.scope1\",\n\n        ClientAssertion =\n        {\n            Type = OidcConstants.ClientAssertionTypes.JwtBearer,\n            Value = clientToken\n        }\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.SampleApi;\n\n    var client = new HttpClient\n    {\n        BaseAddress = new Uri(baseAddress)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var json = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(json);\n}\n\nstatic string CreateClientToken(SigningCredentials credential, string clientId, string audience)\n{\n\n    var now = DateTime.UtcNow;\n\n    var token = new JwtSecurityToken\n    (\n        clientId,\n        audience,\n        new List<Claim>()\n        {\n            new Claim(JwtClaimTypes.JwtId, Guid.NewGuid().ToString()),\n            new Claim(JwtClaimTypes.Subject, clientId),\n            new Claim(JwtClaimTypes.IssuedAt, now.ToEpochTime().ToString(), ClaimValueTypes.Integer64)\n        },\n        now,\n        now.AddMinutes(1),\n        credential\n    );\n\n    var tokenHandler = new JwtSecurityTokenHandler();\n    return tokenHandler.WriteToken(token);\n}"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlow/ConsoleResourceOwnerFlow.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n  </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlow/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConsole.Title = \"Console ResourceOwner Flow\";\n\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\n\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var client = new HttpClient();\n\n    var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var response = await client.RequestPasswordTokenAsync(new PasswordTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n\n        ClientId = \"roclient\",\n        ClientSecret = \"secret\",\n\n        UserName = \"bob\",\n        Password = \"bob\",\n\n        Scope = \"resource1.scope1 resource2.scope1\",\n\n        Parameters =\n                {\n                    { \"acr_values\", \"tenant:custom_account_store1 foo bar quux\" }\n                }\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.SampleApi;\n\n    var client = new HttpClient\n    {\n        BaseAddress = new Uri(baseAddress)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var json = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(json);\n}"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlowPublic/ConsoleResourceOwnerFlowPublic.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n  </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlowPublic/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n\nConsole.Title = \"Console ResourceOwner Flow Public\";\n\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\n\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var client = new HttpClient();\n\n    var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var response = await client.RequestPasswordTokenAsync(new PasswordTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n\n        ClientId = \"roclient.public\",\n\n        UserName = \"bob\",\n        Password = \"bob\",\n\n        Scope = \"resource1.scope1 resource2.scope1\",\n\n        Parameters =\n                {\n                    { \"acr_values\", \"tenant:custom_account_store1 foo bar quux\" }\n                }\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.SampleApi;\n\n    var client = new HttpClient\n    {\n        BaseAddress = new Uri(baseAddress)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var json = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(json);\n}"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlowReference/ConsoleResourceOwnerFlowReference.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n    <PropertyGroup>\n        <OutputType>Exe</OutputType>\n    </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlowReference/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConsole.Title = \"Console ResourceOwner Flow Reference\";\n\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nConsole.ReadLine();\nawait CallServiceAsync(response.AccessToken);\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var client = new HttpClient();\n\n    var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var response = await client.RequestPasswordTokenAsync(new PasswordTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n\n        ClientId = \"roclient.reference\",\n        ClientSecret = \"secret\",\n\n        UserName = \"bob\",\n        Password = \"bob\",\n\n        Scope = \"resource1.scope1 resource2.scope1 scope3\"\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.SampleApi;\n\n    var client = new HttpClient\n    {\n        BaseAddress = new Uri(baseAddress)\n    };\n\n    client.SetBearerToken(token);\n\n    while (true)\n    {\n        var response = await client.GetStringAsync(\"identity\");\n\n        \"\\n\\nService claims:\".ConsoleGreen();\n        var json = JsonSerializer.Deserialize<JsonElement>(response);\n        Console.WriteLine(json);\n\n        Console.ReadLine();\n    }\n}"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlowRefreshToken/ConsoleResourceOwnerFlowRefreshToken.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n    <PropertyGroup>\n        <OutputType>Exe</OutputType>\n    </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlowRefreshToken/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Clients;\nglobal using IdentityModel;\nglobal using IdentityModel.Client;\nglobal using System.Text;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlowRefreshToken/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n\nHttpClient tokenClient = new HttpClient();\nDiscoveryCache cache = new DiscoveryCache(Constants.Authority);\n\n\nConsole.Title = \"Console ResourceOwner Flow RefreshToken\";\n\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nConsole.ReadLine();\n\nvar refresh_token = response.RefreshToken;\n\nwhile (true)\n{\n    response = await RefreshTokenAsync(refresh_token);\n    ShowResponse(response);\n\n    Console.ReadLine();\n    await CallServiceAsync(response.AccessToken);\n\n    if (response.RefreshToken != refresh_token)\n    {\n        refresh_token = response.RefreshToken;\n    }\n}\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var disco = await cache.GetAsync();\n\n    var response = await tokenClient.RequestPasswordTokenAsync(new PasswordTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n\n        ClientId = \"roclient\",\n        ClientSecret = \"secret\",\n\n        UserName = \"bob\",\n        Password = \"bob\",\n\n        Scope = \"resource1.scope1 offline_access\",\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n async Task<TokenResponse> RefreshTokenAsync(string refreshToken)\n{\n    Console.WriteLine(\"Using refresh token: {0}\", refreshToken);\n\n    var disco = await cache.GetAsync();\n    var response = await tokenClient.RequestRefreshTokenAsync(new RefreshTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n\n        ClientId = \"roclient\",\n        ClientSecret = \"secret\",\n        RefreshToken = refreshToken\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task CallServiceAsync(string token)\n{\n    var baseAddress = Constants.SampleApi;\n\n    var client = new HttpClient\n    {\n        BaseAddress = new Uri(baseAddress)\n    };\n\n    client.SetBearerToken(token);\n    var response = await client.GetStringAsync(\"identity\");\n\n    \"\\n\\nService claims:\".ConsoleGreen();\n    var json = JsonSerializer.Deserialize<JsonElement>(response);\n    Console.WriteLine(json);\n}\n\nstatic void ShowResponse(TokenResponse response)\n{\n    if (!response.IsError)\n    {\n        \"Token response:\".ConsoleGreen();\n        Console.WriteLine(response.Json);\n\n        if (response.AccessToken.Contains(\".\"))\n        {\n            \"\\nAccess Token (decoded):\".ConsoleGreen();\n\n            var parts = response.AccessToken.Split('.');\n            var header = parts[0];\n            var claims = parts[1];\n\n            var headerJson = Encoding.UTF8.GetString(Base64Url.Decode(header));\n            Console.WriteLine(JsonSerializer.Deserialize<JsonElement>(header));\n            var claimsJson = Encoding.UTF8.GetString(Base64Url.Decode(claims));\n            Console.WriteLine(JsonSerializer.Deserialize<JsonElement>(claims));\n        }\n    }\n    else\n    {\n        if (response.ErrorType == ResponseErrorType.Http)\n        {\n            \"HTTP error: \".ConsoleGreen();\n            Console.WriteLine(response.Error);\n            \"HTTP status code: \".ConsoleGreen();\n            Console.WriteLine(response.HttpStatusCode);\n        }\n        else\n        {\n            \"Protocol error response:\".ConsoleGreen();\n            Console.WriteLine(response.Json);\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlowUserInfo/ConsoleResourceOwnerFlowUserInfo.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n    <PropertyGroup>\n        <OutputType>Exe</OutputType>\n    </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/ConsoleResourceOwnerFlowUserInfo/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n\nHttpClient tokenClient = new HttpClient();\nDiscoveryCache cache = new DiscoveryCache(Constants.Authority);\n\n\nConsole.Title = \"Console ResourceOwner Flow UserInfo\";\n\nvar response = await RequestTokenAsync();\nresponse.Show();\n\nawait GetClaimsAsync(response.AccessToken);\n\n\nasync Task<TokenResponse> RequestTokenAsync()\n{\n    var disco = await cache.GetAsync();\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var response = await tokenClient.RequestPasswordTokenAsync(new PasswordTokenRequest\n    {\n        Address = disco.TokenEndpoint,\n\n        ClientId = \"roclient\",\n        ClientSecret = \"secret\",\n\n        UserName = \"bob\",\n        Password = \"bob\",\n\n        Scope = \"openid custom.profile\"\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n    return response;\n}\n\nasync Task GetClaimsAsync(string token)\n{\n    var disco = await cache.GetAsync();\n    if (disco.IsError) throw new Exception(disco.Error);\n\n    var response = await tokenClient.GetUserInfoAsync(new UserInfoRequest\n    {\n        Address = disco.UserInfoEndpoint,\n        Token = token\n    });\n\n    if (response.IsError) throw new Exception(response.Error);\n\n    \"\\n\\nUser claims:\".ConsoleGreen();\n    foreach (var claim in response.Claims)\n    {\n        Console.WriteLine(\"{0}\\n {1}\", claim.Type, claim.Value);\n    }\n}"
  },
  {
    "path": "samples/Clients/src/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n  <ItemGroup>\n     <ProjectReference Include=\"$(SolutionDir)..\\shared\\Constants\\Constants.csproj\" Condition=\"$(MSBuildProjectName) != 'Constants' \" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/JsOidc/JsOidc.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n</Project>"
  },
  {
    "path": "samples/Clients/src/JsOidc/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n\n// run a static files web server\nvar app = WebApplication.Create(args);\napp\n    .UseDefaultFiles()\n    .UseStaticFiles();\n\n// uncomment to enable to test w/ CSP (Content-Security-Policy)\n/*\napp.Use(async (ctx, next) =>\n{\n    ctx.Response.OnStarting(() =>\n    {\n        if (ctx.Response.ContentType?.StartsWith(\"text/html\") == true)\n        {\n            ctx.Response.Headers.Add(\"Content-Security-Policy\", \"default-src 'self'; connect-src http://localhost:5000 http://localhost:3721; frame-src 'self' http://localhost:5000\");\n        }\n        return Task.CompletedTask;\n    });\n\n    await next();\n});\n*/\n\nawait app.RunAsync();"
  },
  {
    "path": "samples/Clients/src/JsOidc/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"Host\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:44300/\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Clients/src/JsOidc/web.config",
    "content": "﻿<?xml version=\"1.0\" encoding=\"utf-8\"?>\n<configuration>\n  <system.webServer>\n    <handlers>\n      <add name=\"aspNetCore\" path=\"*\" verb=\"*\" modules=\"AspNetCoreModuleV2\" resourceType=\"Unspecified\" />\n    </handlers>\n    <aspNetCore processPath=\"%LAUNCHER_PATH%\" arguments=\"%LAUNCHER_ARGS%\" forwardWindowsAuthToken=\"false\" stdoutLogEnabled=\"false\" hostingModel=\"InProcess\">\n      <environmentVariables>\n        <environmentVariable name=\"ASPNETCORE_ENVIRONMENT\" value=\"Development\" />\n      </environmentVariables>\n    </aspNetCore>\n  </system.webServer>\n</configuration>"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/StyleSheet.css",
    "content": "﻿pre:empty {\n    display: none;\n}\n"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/app.js",
    "content": "﻿/// <reference path=\"libs/oidc-client.js\" />\n\nvar config = {\n    authority: \"https://localhost:5001/\",\n    client_id: \"js_oidc\",\n    redirect_uri: window.location.origin + \"/callback.html\",\n    post_logout_redirect_uri: window.location.origin + \"/index.html\",\n\n    // if we choose to use popup window instead for logins\n    popup_redirect_uri: window.location.origin + \"/popup.html\",\n    popupWindowFeatures: \"menubar=yes,location=yes,toolbar=yes,width=1200,height=800,left=100,top=100;resizable=yes\",\n\n    // these two will be done dynamically from the buttons clicked, but are\n    // needed if you want to use the silent_renew\n    response_type: \"code\",\n    scope: \"openid profile email resource1.scope1 resource2.scope1\",\n\n    // this will toggle if profile endpoint is used\n    loadUserInfo: true,\n\n    // silent renew will get a new access_token via an iframe \n    // just prior to the old access_token expiring (60 seconds prior)\n    silent_redirect_uri: window.location.origin + \"/silent.html\",\n    automaticSilentRenew: true,\n\n    monitorAnonymousSession: true,\n\n    // will revoke (reference) access tokens at logout time\n    revokeAccessTokenOnSignout: true,\n\n    // this will allow all the OIDC protocol claims to be visible in the window. normally a client app \n    // wouldn't care about them or want them taking up space\n    filterProtocolClaims: false\n};\nOidc.Log.logger = window.console;\nOidc.Log.level = Oidc.Log.DEBUG;\n\nvar mgr = new Oidc.UserManager(config);\n\nmgr.events.addUserLoaded(function (user) {\n    log(\"User loaded\");\n    showTokens();\n});\nmgr.events.addUserUnloaded(function () {\n    log(\"User logged out locally\");\n    showTokens();\n});\nmgr.events.addAccessTokenExpiring(function () {\n    log(\"Access token expiring...\");\n});\nmgr.events.addSilentRenewError(function (err) {\n    log(\"Silent renew error: \" + err.message);\n});\nmgr.events.addUserSignedIn(function (e) {\n    log(\"user logged in to the token server\");\n});\nmgr.events.addUserSignedOut(function () {\n    log(\"User signed out of OP\");\n});\n\nfunction login() {\n    mgr.signinRedirect();\n}\n\nfunction popup() {\n    mgr.signinPopup().then(function () {\n        log(\"Logged In\");\n    });\n}\n\nfunction logout() {\n    mgr.signoutRedirect();\n}\n\nfunction revoke() {\n    mgr.revokeAccessToken().then(function () {\n        log(\"Access Token Revoked.\")\n    }).catch(function (err) {\n        log(err);\n    });\n}\n\nfunction renewToken() {\n    mgr.signinSilent()\n        .then(function () {\n            log(\"silent renew success\");\n            showTokens();\n        }).catch(function (err) {\n            log(\"silent renew error\", err);\n        });\n}\nfunction callApi() {\n    mgr.getUser().then(function (user) {\n        var xhr = new XMLHttpRequest();\n        xhr.onload = function (e) {\n            if (xhr.status >= 400) {\n                display(\"#ajax-result\", {\n                    status: xhr.status,\n                    statusText: xhr.statusText,\n                    wwwAuthenticate: xhr.getResponseHeader(\"WWW-Authenticate\")\n                });\n            }\n            else {\n                display(\"#ajax-result\", xhr.response);\n            }\n        };\n        xhr.open(\"GET\", \"https://localhost:5005/identity\", true);\n        xhr.setRequestHeader(\"Authorization\", \"Bearer \" + user.access_token);\n        xhr.send();\n    });\n}\n\nif (window.location.hash) {\n    handleCallback();\n}\n\ndocument.querySelector(\".login\").addEventListener(\"click\", login, false);\ndocument.querySelector(\".popup\").addEventListener(\"click\", popup, false);\ndocument.querySelector(\".renew\").addEventListener(\"click\", renewToken, false);\ndocument.querySelector(\".call\").addEventListener(\"click\", callApi, false);\ndocument.querySelector(\".revoke\").addEventListener(\"click\", revoke, false);\ndocument.querySelector(\".logout\").addEventListener(\"click\", logout, false);\n\n\nfunction log(data) {\n    document.getElementById('response').innerText = '';\n\n    Array.prototype.forEach.call(arguments, function (msg) {\n        if (msg instanceof Error) {\n            msg = \"Error: \" + msg.message;\n        }\n        else if (typeof msg !== 'string') {\n            msg = JSON.stringify(msg, null, 2);\n        }\n        document.getElementById('response').innerText += msg + '\\r\\n';\n    });\n}\n\nfunction display(selector, data) {\n    if (data && typeof data === 'string') {\n        try {\n            data = JSON.parse(data);\n        }\n        catch (e) { }\n    }\n    if (data && typeof data !== 'string') {\n        data = JSON.stringify(data, null, 2);\n    }\n    document.querySelector(selector).textContent = data;\n}\n\nfunction showTokens() {\n    mgr.getUser().then(function (user) {\n        if (user) {\n            display(\"#id-token\", user);\n        }\n        else {\n            log(\"Not logged in\");\n        }\n    });\n}\nshowTokens();\n\nfunction handleCallback() {\n    mgr.signinRedirectCallback().then(function (user) {\n        var hash = window.location.hash.substr(1);\n        var result = hash.split('&').reduce(function (result, item) {\n            var parts = item.split('=');\n            result[parts[0]] = parts[1];\n            return result;\n        }, {});\n\n        log(result);\n        showTokens();\n\n        window.history.replaceState({},\n            window.document.title,\n            window.location.origin + window.location.pathname);\n\n    }, function (error) {\n        log(error);\n    });\n}"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/callback.html",
    "content": "﻿<!DOCTYPE html>\n<html>\n<head>\n    <title></title>\n    <link href=\"libs/bootstrap.min.css\" rel=\"stylesheet\" />\n</head>\n<body>\n    <div class=\"container\">\n        <header class=\"page-header\">\n            <h1>Processing callback...</h1>\n        </header>\n\n        <div class=\"row\">\n            <div class=\"col-md-2\">\n                <a href=\"index.html\" class=\"btn btn-primary\">Back to index</a>\n            </div>\n        </div>\n    </div>\n\n    <script src=\"libs/oidc-client.js\"></script>\n    <script src=\"callback.js\"></script>\n</body>\n</html>\n\n"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/callback.js",
    "content": "﻿var mgr = new Oidc.UserManager({ loadUserInfo: true, filterProtocolClaims: true, response_mode:\"query\" });\nmgr.signinRedirectCallback().then(function (user) {\n    console.log(user);\n    window.history.replaceState({},\n        window.document.title,\n        window.location.origin + window.location.pathname);\n    window.location = \"index.html\";\n});\n"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/index.html",
    "content": "﻿<!DOCTYPE html>\n<html xmlns=\"http://www.w3.org/1999/xhtml\">\n<head>\n    <title></title>\n    <link href=\"libs/bootstrap.min.css\" rel=\"stylesheet\" />\n    <link href=\"StyleSheet.css\" rel=\"stylesheet\" />\n</head>\n<body>\n    <div class=\"container\">\n        <header class=\"page-header\">\n            <h1>JavaScript Oidc Client</h1>\n        </header>\n\n        <div class=\"row\">\n            <ul class=\"list-unstyled list-inline\">\n                <li><a class=\"btn btn-primary\" href=\"index.html\">Home</a></li>\n                <li><button class=\"btn btn-default login\">Login</button></li>\n                <li><button class=\"btn btn-default popup\">Login with popup</button></li>\n                <li><button class=\"btn btn-primary renew\">Renew Token</button></li>\n                <li><button class=\"btn btn-primary call\">Call Service</button></li>\n                <li><button class=\"btn btn-info revoke\">Revoke Access Token</button></li>\n                <li><button class=\"btn btn-info logout\">Logout</button></li>\n            </ul>\n        </div>\n\n        <div class=\"row\">\n            <ul class=\"list-unstyled list-inline\">\n            </ul>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"panel panel-default\">\n                <div class=\"panel-heading\">Message</div>\n                <div class=\"panel-body\">\n                    <pre id=\"response\"></pre>\n                </div>\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-6\">\n                <div class=\"panel panel-default\">\n                    <div class=\"panel-heading\">Current User</div>\n                    <div class=\"panel-body\">\n                        <pre id=\"id-token\"></pre>\n                    </div>\n                </div>\n            </div>\n\n            <!--<div class=\"col-sm-4\">\n                <div class=\"panel panel-default\">\n                    <div class=\"panel-heading\">Access Token</div>\n                    <div class=\"panel-body\">\n                        <pre id=\"access-token\"></pre>\n                    </div>\n                </div>\n            </div>-->\n\n            <div class=\"col-sm-6\">\n                <div class=\"panel panel-default\">\n                    <div class=\"panel-heading\">Ajax Result</div>\n                    <div class=\"panel-body\">\n                        <pre id=\"ajax-result\"></pre>\n                    </div>\n                </div>\n            </div>\n        </div>\n    </div>\n\n    <script src=\"libs/oidc-client.js\"></script>\n    <script src=\"app.js\"></script>\n</body>\n</html>\n"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/libs/oidc-client.d.ts",
    "content": "/* Provides a namespace for when the library is loaded outside a module loader environment */\nexport as namespace Oidc;\n\nexport const Version: string;\n\nexport interface Logger {\n  error(message?: any, ...optionalParams: any[]): void;\n  info(message?: any, ...optionalParams: any[]): void;\n  debug(message?: any, ...optionalParams: any[]): void;\n  warn(message?: any, ...optionalParams: any[]): void;\n}\n\nexport interface AccessTokenEvents {\n\n  load(container: User): void;\n\n  unload(): void;\n\n  /** Subscribe to events raised prior to the access token expiring */\n  addAccessTokenExpiring(callback: (...ev: any[]) => void): void;\n  removeAccessTokenExpiring(callback: (...ev: any[]) => void): void;\n\n  /** Subscribe to events raised after the access token has expired */\n  addAccessTokenExpired(callback: (...ev: any[]) => void): void;\n  removeAccessTokenExpired(callback: (...ev: any[]) => void): void;\n}\n\nexport class InMemoryWebStorage {\n  getItem(key: string): any;\n\n  setItem(key: string, value: any): any;\n\n  removeItem(key: string): any;\n\n  key(index: number): any;\n\n  length?: number;\n}\n\nexport class Log {\n  static readonly NONE: 0;\n  static readonly ERROR: 1;\n  static readonly WARN: 2;\n  static readonly INFO: 3;\n  static readonly DEBUG: 4;\n\n  static reset(): void;\n\n  static level: number;\n\n  static logger: Logger;\n\n  static debug(message?: any, ...optionalParams: any[]): void;\n  static info(message?: any, ...optionalParams: any[]): void;\n  static warn(message?: any, ...optionalParams: any[]): void;\n  static error(message?: any, ...optionalParams: any[]): void;\n}\n\nexport interface MetadataService {\n  new (settings: OidcClientSettings): MetadataService;\n\n  metadataUrl?: string;\n\n  getMetadata(): Promise<OidcMetadata>;\n\n  getIssuer(): Promise<string>;\n\n  getAuthorizationEndpoint(): Promise<string>;\n\n  getUserInfoEndpoint(): Promise<string>;\n\n  getTokenEndpoint(): Promise<string | undefined>;\n\n  getCheckSessionIframe(): Promise<string | undefined>;\n\n  getEndSessionEndpoint(): Promise<string | undefined>;\n\n  getRevocationEndpoint(): Promise<string | undefined>;\n\n  getKeysEndpoint(): Promise<string | undefined>;\n\n  getSigningKeys(): Promise<any[]>;\n}\n\nexport interface MetadataServiceCtor {\n  (settings: OidcClientSettings, jsonServiceCtor?: any): MetadataService;\n}\n\nexport interface ResponseValidator {\n  validateSigninResponse(state: any, response: any): Promise<SigninResponse>;\n  validateSignoutResponse(state: any, response: any): Promise<SignoutResponse>;\n}\n\nexport interface ResponseValidatorCtor {\n  (settings: OidcClientSettings, metadataServiceCtor?: MetadataServiceCtor, userInfoServiceCtor?: any): ResponseValidator;\n}\n\nexport interface SigninRequest {\n  url: string;\n  state: any;\n}\n\nexport interface SignoutRequest {\n  url: string;\n  state?: any;\n}\n\nexport class OidcClient {\n  constructor(settings: OidcClientSettings);\n\n  readonly settings: OidcClientSettings;\n\n  createSigninRequest(args?: any): Promise<SigninRequest>;\n  processSigninResponse(url?: string, stateStore?: StateStore): Promise<SigninResponse>;\n\n  createSignoutRequest(args?: any): Promise<SignoutRequest>;\n  processSignoutResponse(url?: string, stateStore?: StateStore): Promise<SignoutResponse>;\n\n  clearStaleState(stateStore: StateStore): Promise<any>;\n\n  readonly metadataService: MetadataService;\n}\n\nexport interface OidcClientSettings {\n  /** The URL of the OIDC/OAuth2 provider */\n  authority?: string;\n  readonly metadataUrl?: string;\n  /** Provide metadata when authority server does not allow CORS on the metadata endpoint */\n  metadata?: Partial<OidcMetadata>;\n  /** Provide signingKeys when authority server does not allow CORS on the jwks uri */\n  signingKeys?: any[];\n  /** Your client application's identifier as registered with the OIDC/OAuth2 */\n  client_id?: string;\n  client_secret?: string;\n  /** The type of response desired from the OIDC/OAuth2 provider (default: 'id_token') */\n  readonly response_type?: string;\n  readonly response_mode?: string;\n  /** The scope being requested from the OIDC/OAuth2 provider (default: 'openid') */\n  readonly scope?: string;\n  /** The redirect URI of your client application to receive a response from the OIDC/OAuth2 provider */\n  readonly redirect_uri?: string;\n  /** The OIDC/OAuth2 post-logout redirect URI */\n  readonly post_logout_redirect_uri?: string;\n  /** The OIDC/OAuth2 post-logout redirect URI when using popup */\n  readonly popup_post_logout_redirect_uri?: string;\n  readonly prompt?: string;\n  readonly display?: string;\n  readonly max_age?: number;\n  readonly ui_locales?: string;\n  readonly acr_values?: string;\n  /** Should OIDC protocol claims be removed from profile (default: true) */\n  readonly filterProtocolClaims?: boolean;\n  /** Flag to control if additional identity data is loaded from the user info endpoint in order to populate the user's profile (default: true) */\n  readonly loadUserInfo?: boolean;\n  /** Number (in seconds) indicating the age of state entries in storage for authorize requests that are considered abandoned and thus can be cleaned up (default: 300) */\n  readonly staleStateAge?: number;\n  /** The window of time (in seconds) to allow the current time to deviate when validating id_token's iat, nbf, and exp values (default: 300) */\n  readonly clockSkew?: number;\n  readonly stateStore?: StateStore;\n  readonly userInfoJwtIssuer?: 'ANY' | 'OP' | string;\n  ResponseValidatorCtor?: ResponseValidatorCtor;\n  MetadataServiceCtor?: MetadataServiceCtor;\n  /** An object containing additional query string parameters to be including in the authorization request */\n  extraQueryParams?: Record<string, any>;\n}\n\nexport class UserManager extends OidcClient {\n  constructor(settings: UserManagerSettings);\n\n  readonly settings: UserManagerSettings;\n\n  /** Removes stale state entries in storage for incomplete authorize requests */\n  clearStaleState(): Promise<void>;\n\n  /** Load the User object for the currently authenticated user */\n  getUser(): Promise<User | null>;\n  storeUser(user: User): Promise<void>;\n  /** Remove from any storage the currently authenticated user */\n  removeUser(): Promise<void>;\n\n  /** Trigger a request (via a popup window) to the authorization endpoint. The result of the promise is the authenticated User */\n  signinPopup(args?: any): Promise<User>;\n  /** Notify the opening window of response from the authorization endpoint */\n  signinPopupCallback(url?: string): Promise<User | undefined>;\n\n  /** Trigger a silent request (via an iframe or refreshtoken if available) to the authorization endpoint */\n  signinSilent(args?: any): Promise<User>;\n  /** Notify the parent window of response from the authorization endpoint */\n  signinSilentCallback(url?: string): Promise<User | undefined>;\n\n  /** Trigger a redirect of the current window to the authorization endpoint */\n  signinRedirect(args?: any): Promise<void>;\n  /** Process response from the authorization endpoint. */\n  signinRedirectCallback(url?: string): Promise<User>;\n\n  /** Trigger a redirect of the current window to the end session endpoint */\n  signoutRedirect(args?: any): Promise<void>;\n  /** Process response from the end session endpoint */\n  signoutRedirectCallback(url?: string): Promise<SignoutResponse>;\n\n  /** Trigger a redirect of a popup window window to the end session endpoint */\n  signoutPopup(args?: any): Promise<void>;\n  /** Process response from the end session endpoint from a popup window */\n  signoutPopupCallback(url?: string, keepOpen?: boolean): Promise<void>;\n  signoutPopupCallback(keepOpen?: boolean): Promise<void>;\n\n  /** Proxy to Popup, Redirect and Silent callbacks */\n  signinCallback(url?: string): Promise<User>;\n\n  /** Proxy to Popup and Redirect callbacks */\n  signoutCallback(url?: string): Promise<SignoutResponse | void>;\n\n  /** Query OP for user's current signin status */\n  querySessionStatus(args?: any): Promise<SessionStatus>;\n\n  revokeAccessToken(): Promise<void>;\n\n  /** Enables silent renew  */\n  startSilentRenew(): void;\n  /** Disables silent renew */\n  stopSilentRenew(): void;\n\n  events: UserManagerEvents;\n}\n\nexport interface SessionStatus {\n  /** Opaque session state used to validate if session changed (monitorSession) */\n  session_state: string;\n  /** Subject identifier */\n  sub: string;\n  /** Session ID */\n  sid?: string;\n}\n\nexport interface UserManagerEvents extends AccessTokenEvents {\n  load(user: User): any;\n  unload(): any;\n\n  /** Subscribe to events raised when user session has been established (or re-established) */\n  addUserLoaded(callback: UserManagerEvents.UserLoadedCallback): void;\n  removeUserLoaded(callback: UserManagerEvents.UserLoadedCallback): void;\n\n  /** Subscribe to events raised when a user session has been terminated */\n  addUserUnloaded(callback: UserManagerEvents.UserUnloadedCallback): void;\n  removeUserUnloaded(callback: UserManagerEvents.UserUnloadedCallback): void;\n\n  /** Subscribe to events raised when the automatic silent renew has failed */\n  addSilentRenewError(callback: UserManagerEvents.SilentRenewErrorCallback): void;\n  removeSilentRenewError(callback: UserManagerEvents.SilentRenewErrorCallback): void;\n\n  /** Subscribe to events raised when the user's sign-in status at the OP has changed */\n  addUserSignedOut(callback: UserManagerEvents.UserSignedOutCallback): void;\n  removeUserSignedOut(callback: UserManagerEvents.UserSignedOutCallback): void;\n\n  /** When `monitorSession` subscribe to events raised when the user session changed */\n  addUserSessionChanged(callback: UserManagerEvents.UserSessionChangedCallback): void;\n  removeUserSessionChanged(callback: UserManagerEvents.UserSessionChangedCallback): void;\n}\n\nexport namespace UserManagerEvents {\n  export type UserLoadedCallback = (user: User) => void;\n  export type UserUnloadedCallback = () => void;\n  export type SilentRenewErrorCallback = (error: Error) => void;\n  export type UserSignedOutCallback = () => void;\n  export type UserSessionChangedCallback = () => void;\n}\n\nexport interface UserManagerSettings extends OidcClientSettings {\n  /** The URL for the page containing the call to signinPopupCallback to handle the callback from the OIDC/OAuth2 */\n  readonly popup_redirect_uri?: string;\n  /** The features parameter to window.open for the popup signin window.\n   *  default: 'location=no,toolbar=no,width=500,height=500,left=100,top=100'\n   */\n  readonly popupWindowFeatures?: string;\n  /** The target parameter to window.open for the popup signin window (default: '_blank') */\n  readonly popupWindowTarget?: any;\n  /** The URL for the page containing the code handling the silent renew */\n  readonly silent_redirect_uri?: any;\n  /** Number of milliseconds to wait for the silent renew to return before assuming it has failed or timed out (default: 10000) */\n  readonly silentRequestTimeout?: any;\n  /** Flag to indicate if there should be an automatic attempt to renew the access token prior to its expiration (default: false) */\n  readonly automaticSilentRenew?: boolean;\n  readonly validateSubOnSilentRenew?: boolean;\n  /** Flag to control if id_token is included as id_token_hint in silent renew calls (default: true) */\n  readonly includeIdTokenInSilentRenew?: boolean;\n  /** Will raise events for when user has performed a signout at the OP (default: true) */\n  readonly monitorSession?: boolean;\n  /** Interval, in ms, to check the user's session (default: 2000) */\n  readonly checkSessionInterval?: number;\n  readonly query_status_response_type?: string;\n  readonly stopCheckSessionOnError?: boolean;\n  /** Will invoke the revocation endpoint on signout if there is an access token for the user (default: false) */\n  readonly revokeAccessTokenOnSignout?: boolean;\n  /** The number of seconds before an access token is to expire to raise the accessTokenExpiring event (default: 60) */\n  readonly accessTokenExpiringNotificationTime?: number;\n  readonly redirectNavigator?: any;\n  readonly popupNavigator?: any;\n  readonly iframeNavigator?: any;\n  /** Storage object used to persist User for currently authenticated user (default: session storage) */\n  readonly userStore?: WebStorageStateStore;\n}\n\nexport interface WebStorageStateStoreSettings {\n  prefix?: string;\n  store?: any;\n}\n\nexport interface StateStore {\n  set(key: string, value: any): Promise<void>;\n\n  get(key: string): Promise<any>;\n\n  remove(key: string): Promise<any>;\n\n  getAllKeys(): Promise<string[]>;\n}\n\nexport class WebStorageStateStore implements StateStore {\n  constructor(settings: WebStorageStateStoreSettings);\n\n  set(key: string, value: any): Promise<void>;\n\n  get(key: string): Promise<any>;\n\n  remove(key: string): Promise<any>;\n\n  getAllKeys(): Promise<string[]>;\n}\n\nexport interface SigninResponse {\n  new (url: string, delimiter?: string): SigninResponse;\n\n  access_token: string;\n  code: string;\n  error: string;\n  error_description: string;\n  error_uri: string;\n  id_token: string;\n  profile: any;\n  scope: string;\n  session_state: string;\n  state: any;\n  token_type: string;\n\n  readonly expired: boolean | undefined;\n  readonly expires_in: number | undefined;\n  readonly isOpenIdConnect: boolean;\n  readonly scopes: string[];\n}\n\nexport interface SignoutResponse {\n  new (url: string): SignoutResponse;\n\n  error?: string;\n  error_description?: string;\n  error_uri?: string;\n  state?: any;\n}\n\nexport interface UserSettings {\n  id_token: string;\n  session_state: string;\n  access_token: string;\n  refresh_token: string;\n  token_type: string;\n  scope: string;\n  profile: Profile;\n  expires_at: number;\n  state: any;\n}\n\nexport class User {\n  constructor(settings: UserSettings);\n\n  /** The id_token returned from the OIDC provider */\n  id_token: string;\n  /** The session state value returned from the OIDC provider (opaque) */\n  session_state?: string;\n  /** The access token returned from the OIDC provider. */\n  access_token: string;\n  /** Refresh token returned from the OIDC provider (if requested) */\n  refresh_token?: string;\n  /** The token_type returned from the OIDC provider */\n  token_type: string;\n  /** The scope returned from the OIDC provider */\n  scope: string;\n  /** The claims represented by a combination of the id_token and the user info endpoint */\n  profile: Profile;\n  /** The expires at returned from the OIDC provider */\n  expires_at: number;\n  /** The custom state transferred in the last signin */\n  state: any;\n\n  toStorageString(): string;\n  static fromStorageString(storageString: string): User;\n\n  /** Calculated number of seconds the access token has remaining */\n  readonly expires_in: number;\n  /** Calculated value indicating if the access token is expired */\n  readonly expired: boolean;\n  /** Array representing the parsed values from the scope */\n  readonly scopes: string[];\n}\n\nexport type Profile = IDTokenClaims & ProfileStandardClaims;\n\ninterface IDTokenClaims {\n  /** Issuer Identifier */\n  iss: string;\n  /** Subject identifier */\n  sub: string;\n  /** Audience(s): client_id ... */\n  aud: string;\n  /** Expiration time */\n  exp: number;\n  /** Issued at */\n  iat: number;\n  /** Time when the End-User authentication occurred */\n  auth_time?: number;\n  /** Time when the End-User authentication occurred */\n  nonce?: number;\n  /** Access Token hash value */\n  at_hash?: string;\n  /** Authentication Context Class Reference */\n  acr?: string;\n  /** Authentication Methods References */\n  amr?: string[];\n  /** Authorized Party - the party to which the ID Token was issued */\n  azp?: string;\n  /** Session ID - String identifier for a Session */\n  sid?: string;\n\n  /** Other custom claims */\n  [claimKey: string]: any;\n}\n\ninterface ProfileStandardClaims {\n  /** End-User's full name */\n  name?: string;\n  /** Given name(s) or first name(s) of the End-User */\n  given_name?: string;\n  /** Surname(s) or last name(s) of the End-User */\n  family_name?: string;\n  /** Middle name(s) of the End-User */\n  middle_name?: string;\n  /** Casual name of the End-User that may or may not be the same as the given_name. */\n  nickname?: string;\n  /** Shorthand name that the End-User wishes to be referred to at the RP, such as janedoe or j.doe. */\n  preferred_username?: string;\n  /** URL of the End-User's profile page */\n  profile?: string;\n  /** URL of the End-User's profile picture */\n  picture?: string;\n  /** URL of the End-User's Web page or blog */\n  website?: string;\n  /** End-User's preferred e-mail address */\n  email?: string;\n  /** True if the End-User's e-mail address has been verified; otherwise false. */\n  email_verified?: boolean;\n  /** End-User's gender. Values defined by this specification are female and male. */\n  gender?: string;\n  /** End-User's birthday, represented as an ISO 8601:2004 [ISO8601‑2004] YYYY-MM-DD format */\n  birthdate?: string;\n  /** String from zoneinfo [zoneinfo] time zone database representing the End-User's time zone. */\n  zoneinfo?: string;\n  /** End-User's locale, represented as a BCP47 [RFC5646] language tag. */\n  locale?: string;\n  /** End-User's preferred telephone number. */\n  phone_number?: string;\n  /** True if the End-User's phone number has been verified; otherwise false. */\n  phone_number_verified?: boolean;\n  /** object \tEnd-User's preferred address in JSON [RFC4627] */\n  address?: OidcAddress;\n  /** Time the End-User's information was last updated. */\n  updated_at?: number;\n}\n\ninterface OidcAddress {\n  /** Full mailing address, formatted for display or use on a mailing label */\n  formatted?: string;\n  /** Full street address component, which MAY include house number, street name, Post Office Box, and multi-line extended street address information */\n  street_address?: string;\n  /** City or locality component */\n  locality?: string;\n  /** State, province, prefecture, or region component */\n  region?: string;\n  /** Zip code or postal code component */\n  postal_code?: string;\n  /** Country name component */\n  country?: string;\n}\n\nexport class CordovaPopupWindow {\n  constructor(params: any);\n  navigate(params: any): Promise<any>;\n  promise: Promise<any>;\n}\n\nexport class CordovaPopupNavigator {\n  prepare(params: any): Promise<CordovaPopupWindow>;\n}\n\nexport class CordovaIFrameNavigator {\n  prepare(params: any): Promise<CordovaPopupWindow>;\n}\n\nexport interface OidcMetadata {\n  issuer: string;\n  authorization_endpoint:string;\n  token_endpoint: string;\n  token_endpoint_auth_methods_supported:string[];\n  token_endpoint_auth_signing_alg_values_supported: string[];\n  userinfo_endpoint: string;\n  check_session_iframe: string;\n  end_session_endpoint: string;\n  jwks_uri: string;\n  registration_endpoint: string;\n  scopes_supported: string[];\n  response_types_supported: string[];\n  acr_values_supported: string[];\n  subject_types_supported: string[];\n  userinfo_signing_alg_values_supported: string[];\n  userinfo_encryption_alg_values_supported: string[];\n  userinfo_encryption_enc_values_supported: string[];\n  id_token_signing_alg_values_supported: string[];\n  id_token_encryption_alg_values_supported: string[];\n  id_token_encryption_enc_values_supported: string[];\n  request_object_signing_alg_values_supported: string[];\n  display_values_supported: string[];\n  claim_types_supported: string[];\n  claims_supported: string[];\n  claims_parameter_supported: boolean;\n  service_documentation: string;\n  ui_locales_supported: string[];\n\n  revocation_endpoint: string;\n  introspection_endpoint: string;\n  frontchannel_logout_supported: boolean;\n  frontchannel_logout_session_supported: boolean;\n  backchannel_logout_supported: boolean;\n  backchannel_logout_session_supported: boolean;\n  grant_types_supported: string[];\n  response_modes_supported: string[];\n  code_challenge_methods_supported: string[];\n}\n\nexport interface CheckSessionIFrame {\n  new (callback: () => void, client_id: string, url: string, interval?: number, stopOnError?: boolean): CheckSessionIFrame\n\n  load(): Promise<void>;\n\n  start(session_state: string): void;\n\n  stop(): void;\n}\n\nexport interface CheckSessionIFrameCtor {\n  (callback: () => void, client_id: string, url: string, interval?: number, stopOnError?: boolean): CheckSessionIFrame;\n}\n\nexport class SessionMonitor {\n  constructor(userManager: UserManager, CheckSessionIFrameCtor: CheckSessionIFrameCtor);\n}\n"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/libs/oidc-client.js",
    "content": "var Oidc =\n/******/ (function(modules) { // webpackBootstrap\n/******/ \t// The module cache\n/******/ \tvar installedModules = {};\n/******/\n/******/ \t// The require function\n/******/ \tfunction __webpack_require__(moduleId) {\n/******/\n/******/ \t\t// Check if module is in cache\n/******/ \t\tif(installedModules[moduleId]) {\n/******/ \t\t\treturn installedModules[moduleId].exports;\n/******/ \t\t}\n/******/ \t\t// Create a new module (and put it into the cache)\n/******/ \t\tvar module = installedModules[moduleId] = {\n/******/ \t\t\ti: moduleId,\n/******/ \t\t\tl: false,\n/******/ \t\t\texports: {}\n/******/ \t\t};\n/******/\n/******/ \t\t// Execute the module function\n/******/ \t\tmodules[moduleId].call(module.exports, module, module.exports, __webpack_require__);\n/******/\n/******/ \t\t// Flag the module as loaded\n/******/ \t\tmodule.l = true;\n/******/\n/******/ \t\t// Return the exports of the module\n/******/ \t\treturn module.exports;\n/******/ \t}\n/******/\n/******/\n/******/ \t// expose the modules object (__webpack_modules__)\n/******/ \t__webpack_require__.m = modules;\n/******/\n/******/ \t// expose the module cache\n/******/ \t__webpack_require__.c = installedModules;\n/******/\n/******/ \t// define getter function for harmony exports\n/******/ \t__webpack_require__.d = function(exports, name, getter) {\n/******/ \t\tif(!__webpack_require__.o(exports, name)) {\n/******/ \t\t\tObject.defineProperty(exports, name, { enumerable: true, get: getter });\n/******/ \t\t}\n/******/ \t};\n/******/\n/******/ \t// define __esModule on exports\n/******/ \t__webpack_require__.r = function(exports) {\n/******/ \t\tif(typeof Symbol !== 'undefined' && Symbol.toStringTag) {\n/******/ \t\t\tObject.defineProperty(exports, Symbol.toStringTag, { value: 'Module' });\n/******/ \t\t}\n/******/ \t\tObject.defineProperty(exports, '__esModule', { value: true });\n/******/ \t};\n/******/\n/******/ \t// create a fake namespace object\n/******/ \t// mode & 1: value is a module id, require it\n/******/ \t// mode & 2: merge all properties of value into the ns\n/******/ \t// mode & 4: return value when already ns object\n/******/ \t// mode & 8|1: behave like require\n/******/ \t__webpack_require__.t = function(value, mode) {\n/******/ \t\tif(mode & 1) value = __webpack_require__(value);\n/******/ \t\tif(mode & 8) return value;\n/******/ \t\tif((mode & 4) && typeof value === 'object' && value && value.__esModule) return value;\n/******/ \t\tvar ns = Object.create(null);\n/******/ \t\t__webpack_require__.r(ns);\n/******/ \t\tObject.defineProperty(ns, 'default', { enumerable: true, value: value });\n/******/ \t\tif(mode & 2 && typeof value != 'string') for(var key in value) __webpack_require__.d(ns, key, function(key) { return value[key]; }.bind(null, key));\n/******/ \t\treturn ns;\n/******/ \t};\n/******/\n/******/ \t// getDefaultExport function for compatibility with non-harmony modules\n/******/ \t__webpack_require__.n = function(module) {\n/******/ \t\tvar getter = module && module.__esModule ?\n/******/ \t\t\tfunction getDefault() { return module['default']; } :\n/******/ \t\t\tfunction getModuleExports() { return module; };\n/******/ \t\t__webpack_require__.d(getter, 'a', getter);\n/******/ \t\treturn getter;\n/******/ \t};\n/******/\n/******/ \t// Object.prototype.hasOwnProperty.call\n/******/ \t__webpack_require__.o = function(object, property) { return Object.prototype.hasOwnProperty.call(object, property); };\n/******/\n/******/ \t// __webpack_public_path__\n/******/ \t__webpack_require__.p = \"\";\n/******/\n/******/\n/******/ \t// Load entry module and return exports\n/******/ \treturn __webpack_require__(__webpack_require__.s = 0);\n/******/ })\n/************************************************************************/\n/******/ ({\n\n/***/ \"./index.js\":\n/*!******************!*\\\n  !*** ./index.js ***!\n  \\******************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _Log = __webpack_require__(/*! ./src/Log.js */ \"./src/Log.js\");\n\nvar _OidcClient = __webpack_require__(/*! ./src/OidcClient.js */ \"./src/OidcClient.js\");\n\nvar _OidcClientSettings = __webpack_require__(/*! ./src/OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./src/WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _InMemoryWebStorage = __webpack_require__(/*! ./src/InMemoryWebStorage.js */ \"./src/InMemoryWebStorage.js\");\n\nvar _UserManager = __webpack_require__(/*! ./src/UserManager.js */ \"./src/UserManager.js\");\n\nvar _AccessTokenEvents = __webpack_require__(/*! ./src/AccessTokenEvents.js */ \"./src/AccessTokenEvents.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./src/MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _CordovaPopupNavigator = __webpack_require__(/*! ./src/CordovaPopupNavigator.js */ \"./src/CordovaPopupNavigator.js\");\n\nvar _CordovaIFrameNavigator = __webpack_require__(/*! ./src/CordovaIFrameNavigator.js */ \"./src/CordovaIFrameNavigator.js\");\n\nvar _CheckSessionIFrame = __webpack_require__(/*! ./src/CheckSessionIFrame.js */ \"./src/CheckSessionIFrame.js\");\n\nvar _TokenRevocationClient = __webpack_require__(/*! ./src/TokenRevocationClient.js */ \"./src/TokenRevocationClient.js\");\n\nvar _SessionMonitor = __webpack_require__(/*! ./src/SessionMonitor.js */ \"./src/SessionMonitor.js\");\n\nvar _Global = __webpack_require__(/*! ./src/Global.js */ \"./src/Global.js\");\n\nvar _User = __webpack_require__(/*! ./src/User.js */ \"./src/User.js\");\n\nvar _version = __webpack_require__(/*! ./version.js */ \"./version.js\");\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nexports.default = {\n    Version: _version.Version,\n    Log: _Log.Log,\n    OidcClient: _OidcClient.OidcClient,\n    OidcClientSettings: _OidcClientSettings.OidcClientSettings,\n    WebStorageStateStore: _WebStorageStateStore.WebStorageStateStore,\n    InMemoryWebStorage: _InMemoryWebStorage.InMemoryWebStorage,\n    UserManager: _UserManager.UserManager,\n    AccessTokenEvents: _AccessTokenEvents.AccessTokenEvents,\n    MetadataService: _MetadataService.MetadataService,\n    CordovaPopupNavigator: _CordovaPopupNavigator.CordovaPopupNavigator,\n    CordovaIFrameNavigator: _CordovaIFrameNavigator.CordovaIFrameNavigator,\n    CheckSessionIFrame: _CheckSessionIFrame.CheckSessionIFrame,\n    TokenRevocationClient: _TokenRevocationClient.TokenRevocationClient,\n    SessionMonitor: _SessionMonitor.SessionMonitor,\n    Global: _Global.Global,\n    User: _User.User\n};\nmodule.exports = exports['default'];\n\n/***/ }),\n\n/***/ \"./jsrsasign/dist/jsrsasign.js\":\n/*!*************************************!*\\\n  !*** ./jsrsasign/dist/jsrsasign.js ***!\n  \\*************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n/* WEBPACK VAR INJECTION */(function(Buffer) {\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\n/*\n * jsrsasign(all) 8.0.12 (2018-04-22) (c) 2010-2018 Kenji Urushima | kjur.github.com/jsrsasign/license\n */\n\nvar navigator = {};\nnavigator.userAgent = false;\n\nvar window = {};\n\n/*!\nCopyright (c) 2011, Yahoo! Inc. All rights reserved.\nCode licensed under the BSD License:\nhttp://developer.yahoo.com/yui/license.html\nversion: 2.9.0\n*/\nif (YAHOO === undefined) {\n  var YAHOO = {};\n}YAHOO.lang = { extend: function extend(g, h, f) {\n    if (!h || !g) {\n      throw new Error(\"YAHOO.lang.extend failed, please check that all dependencies are included.\");\n    }var d = function d() {};d.prototype = h.prototype;g.prototype = new d();g.prototype.constructor = g;g.superclass = h.prototype;if (h.prototype.constructor == Object.prototype.constructor) {\n      h.prototype.constructor = h;\n    }if (f) {\n      var b;for (b in f) {\n        g.prototype[b] = f[b];\n      }var e = function e() {},\n          c = [\"toString\", \"valueOf\"];try {\n        if (/MSIE/.test(navigator.userAgent)) {\n          e = function e(j, i) {\n            for (b = 0; b < c.length; b = b + 1) {\n              var l = c[b],\n                  k = i[l];if (typeof k === \"function\" && k != Object.prototype[l]) {\n                j[l] = k;\n              }\n            }\n          };\n        }\n      } catch (a) {}e(g.prototype, f);\n    }\n  } };\n/*! CryptoJS v3.1.2 core-fix.js\n * code.google.com/p/crypto-js\n * (c) 2009-2013 by Jeff Mott. All rights reserved.\n * code.google.com/p/crypto-js/wiki/License\n * THIS IS FIX of 'core.js' to fix Hmac issue.\n * https://code.google.com/p/crypto-js/issues/detail?id=84\n * https://crypto-js.googlecode.com/svn-history/r667/branches/3.x/src/core.js\n */\nvar CryptoJS = CryptoJS || function (e, g) {\n  var a = {};var b = a.lib = {};var j = b.Base = function () {\n    function n() {}return { extend: function extend(p) {\n        n.prototype = this;var o = new n();if (p) {\n          o.mixIn(p);\n        }if (!o.hasOwnProperty(\"init\")) {\n          o.init = function () {\n            o.$super.init.apply(this, arguments);\n          };\n        }o.init.prototype = o;o.$super = this;return o;\n      }, create: function create() {\n        var o = this.extend();o.init.apply(o, arguments);return o;\n      }, init: function init() {}, mixIn: function mixIn(p) {\n        for (var o in p) {\n          if (p.hasOwnProperty(o)) {\n            this[o] = p[o];\n          }\n        }if (p.hasOwnProperty(\"toString\")) {\n          this.toString = p.toString;\n        }\n      }, clone: function clone() {\n        return this.init.prototype.extend(this);\n      } };\n  }();var l = b.WordArray = j.extend({ init: function init(o, n) {\n      o = this.words = o || [];if (n != g) {\n        this.sigBytes = n;\n      } else {\n        this.sigBytes = o.length * 4;\n      }\n    }, toString: function toString(n) {\n      return (n || h).stringify(this);\n    }, concat: function concat(t) {\n      var q = this.words;var p = t.words;var n = this.sigBytes;var s = t.sigBytes;this.clamp();if (n % 4) {\n        for (var r = 0; r < s; r++) {\n          var o = p[r >>> 2] >>> 24 - r % 4 * 8 & 255;q[n + r >>> 2] |= o << 24 - (n + r) % 4 * 8;\n        }\n      } else {\n        for (var r = 0; r < s; r += 4) {\n          q[n + r >>> 2] = p[r >>> 2];\n        }\n      }this.sigBytes += s;return this;\n    }, clamp: function clamp() {\n      var o = this.words;var n = this.sigBytes;o[n >>> 2] &= 4294967295 << 32 - n % 4 * 8;o.length = e.ceil(n / 4);\n    }, clone: function clone() {\n      var n = j.clone.call(this);n.words = this.words.slice(0);return n;\n    }, random: function random(p) {\n      var o = [];for (var n = 0; n < p; n += 4) {\n        o.push(e.random() * 4294967296 | 0);\n      }return new l.init(o, p);\n    } });var m = a.enc = {};var h = m.Hex = { stringify: function stringify(p) {\n      var r = p.words;var o = p.sigBytes;var q = [];for (var n = 0; n < o; n++) {\n        var s = r[n >>> 2] >>> 24 - n % 4 * 8 & 255;q.push((s >>> 4).toString(16));q.push((s & 15).toString(16));\n      }return q.join(\"\");\n    }, parse: function parse(p) {\n      var n = p.length;var q = [];for (var o = 0; o < n; o += 2) {\n        q[o >>> 3] |= parseInt(p.substr(o, 2), 16) << 24 - o % 8 * 4;\n      }return new l.init(q, n / 2);\n    } };var d = m.Latin1 = { stringify: function stringify(q) {\n      var r = q.words;var p = q.sigBytes;var n = [];for (var o = 0; o < p; o++) {\n        var s = r[o >>> 2] >>> 24 - o % 4 * 8 & 255;n.push(String.fromCharCode(s));\n      }return n.join(\"\");\n    }, parse: function parse(p) {\n      var n = p.length;var q = [];for (var o = 0; o < n; o++) {\n        q[o >>> 2] |= (p.charCodeAt(o) & 255) << 24 - o % 4 * 8;\n      }return new l.init(q, n);\n    } };var c = m.Utf8 = { stringify: function stringify(n) {\n      try {\n        return decodeURIComponent(escape(d.stringify(n)));\n      } catch (o) {\n        throw new Error(\"Malformed UTF-8 data\");\n      }\n    }, parse: function parse(n) {\n      return d.parse(unescape(encodeURIComponent(n)));\n    } };var i = b.BufferedBlockAlgorithm = j.extend({ reset: function reset() {\n      this._data = new l.init();this._nDataBytes = 0;\n    }, _append: function _append(n) {\n      if (typeof n == \"string\") {\n        n = c.parse(n);\n      }this._data.concat(n);this._nDataBytes += n.sigBytes;\n    }, _process: function _process(w) {\n      var q = this._data;var x = q.words;var n = q.sigBytes;var t = this.blockSize;var v = t * 4;var u = n / v;if (w) {\n        u = e.ceil(u);\n      } else {\n        u = e.max((u | 0) - this._minBufferSize, 0);\n      }var s = u * t;var r = e.min(s * 4, n);if (s) {\n        for (var p = 0; p < s; p += t) {\n          this._doProcessBlock(x, p);\n        }var o = x.splice(0, s);q.sigBytes -= r;\n      }return new l.init(o, r);\n    }, clone: function clone() {\n      var n = j.clone.call(this);n._data = this._data.clone();return n;\n    }, _minBufferSize: 0 });var f = b.Hasher = i.extend({ cfg: j.extend(), init: function init(n) {\n      this.cfg = this.cfg.extend(n);this.reset();\n    }, reset: function reset() {\n      i.reset.call(this);this._doReset();\n    }, update: function update(n) {\n      this._append(n);this._process();return this;\n    }, finalize: function finalize(n) {\n      if (n) {\n        this._append(n);\n      }var o = this._doFinalize();return o;\n    }, blockSize: 512 / 32, _createHelper: function _createHelper(n) {\n      return function (p, o) {\n        return new n.init(o).finalize(p);\n      };\n    }, _createHmacHelper: function _createHmacHelper(n) {\n      return function (p, o) {\n        return new k.HMAC.init(n, o).finalize(p);\n      };\n    } });var k = a.algo = {};return a;\n}(Math);\n/*\nCryptoJS v3.1.2 x64-core-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function (g) {\n  var a = CryptoJS,\n      f = a.lib,\n      e = f.Base,\n      h = f.WordArray,\n      a = a.x64 = {};a.Word = e.extend({ init: function init(b, c) {\n      this.high = b;this.low = c;\n    } });a.WordArray = e.extend({ init: function init(b, c) {\n      b = this.words = b || [];this.sigBytes = c != g ? c : 8 * b.length;\n    }, toX32: function toX32() {\n      for (var b = this.words, c = b.length, a = [], d = 0; d < c; d++) {\n        var e = b[d];a.push(e.high);a.push(e.low);\n      }return h.create(a, this.sigBytes);\n    }, clone: function clone() {\n      for (var b = e.clone.call(this), c = b.words = this.words.slice(0), a = c.length, d = 0; d < a; d++) {\n        c[d] = c[d].clone();\n      }return b;\n    } });\n})();\n\n/*\nCryptoJS v3.1.2 enc-base64.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function () {\n  var h = CryptoJS,\n      j = h.lib.WordArray;h.enc.Base64 = { stringify: function stringify(b) {\n      var e = b.words,\n          f = b.sigBytes,\n          c = this._map;b.clamp();b = [];for (var a = 0; a < f; a += 3) {\n        for (var d = (e[a >>> 2] >>> 24 - 8 * (a % 4) & 255) << 16 | (e[a + 1 >>> 2] >>> 24 - 8 * ((a + 1) % 4) & 255) << 8 | e[a + 2 >>> 2] >>> 24 - 8 * ((a + 2) % 4) & 255, g = 0; 4 > g && a + 0.75 * g < f; g++) {\n          b.push(c.charAt(d >>> 6 * (3 - g) & 63));\n        }\n      }if (e = c.charAt(64)) for (; b.length % 4;) {\n        b.push(e);\n      }return b.join(\"\");\n    }, parse: function parse(b) {\n      var e = b.length,\n          f = this._map,\n          c = f.charAt(64);c && (c = b.indexOf(c), -1 != c && (e = c));for (var c = [], a = 0, d = 0; d < e; d++) {\n        if (d % 4) {\n          var g = f.indexOf(b.charAt(d - 1)) << 2 * (d % 4),\n              h = f.indexOf(b.charAt(d)) >>> 6 - 2 * (d % 4);c[a >>> 2] |= (g | h) << 24 - 8 * (a % 4);a++;\n        }\n      }return j.create(c, a);\n    }, _map: \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=\" };\n})();\n\n/*\nCryptoJS v3.1.2 sha256-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function (k) {\n  for (var g = CryptoJS, h = g.lib, v = h.WordArray, j = h.Hasher, h = g.algo, s = [], t = [], u = function u(q) {\n    return 4294967296 * (q - (q | 0)) | 0;\n  }, l = 2, b = 0; 64 > b;) {\n    var d;a: {\n      d = l;for (var w = k.sqrt(d), r = 2; r <= w; r++) {\n        if (!(d % r)) {\n          d = !1;break a;\n        }\n      }d = !0;\n    }d && (8 > b && (s[b] = u(k.pow(l, 0.5))), t[b] = u(k.pow(l, 1 / 3)), b++);l++;\n  }var n = [],\n      h = h.SHA256 = j.extend({ _doReset: function _doReset() {\n      this._hash = new v.init(s.slice(0));\n    }, _doProcessBlock: function _doProcessBlock(q, h) {\n      for (var a = this._hash.words, c = a[0], d = a[1], b = a[2], k = a[3], f = a[4], g = a[5], j = a[6], l = a[7], e = 0; 64 > e; e++) {\n        if (16 > e) n[e] = q[h + e] | 0;else {\n          var m = n[e - 15],\n              p = n[e - 2];n[e] = ((m << 25 | m >>> 7) ^ (m << 14 | m >>> 18) ^ m >>> 3) + n[e - 7] + ((p << 15 | p >>> 17) ^ (p << 13 | p >>> 19) ^ p >>> 10) + n[e - 16];\n        }m = l + ((f << 26 | f >>> 6) ^ (f << 21 | f >>> 11) ^ (f << 7 | f >>> 25)) + (f & g ^ ~f & j) + t[e] + n[e];p = ((c << 30 | c >>> 2) ^ (c << 19 | c >>> 13) ^ (c << 10 | c >>> 22)) + (c & d ^ c & b ^ d & b);l = j;j = g;g = f;f = k + m | 0;k = b;b = d;d = c;c = m + p | 0;\n      }a[0] = a[0] + c | 0;a[1] = a[1] + d | 0;a[2] = a[2] + b | 0;a[3] = a[3] + k | 0;a[4] = a[4] + f | 0;a[5] = a[5] + g | 0;a[6] = a[6] + j | 0;a[7] = a[7] + l | 0;\n    }, _doFinalize: function _doFinalize() {\n      var d = this._data,\n          b = d.words,\n          a = 8 * this._nDataBytes,\n          c = 8 * d.sigBytes;\n      b[c >>> 5] |= 128 << 24 - c % 32;b[(c + 64 >>> 9 << 4) + 14] = k.floor(a / 4294967296);b[(c + 64 >>> 9 << 4) + 15] = a;d.sigBytes = 4 * b.length;this._process();return this._hash;\n    }, clone: function clone() {\n      var b = j.clone.call(this);b._hash = this._hash.clone();return b;\n    } });g.SHA256 = j._createHelper(h);g.HmacSHA256 = j._createHmacHelper(h);\n})(Math);\n\n/*\nCryptoJS v3.1.2 sha512-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function () {\n  function a() {\n    return d.create.apply(d, arguments);\n  }for (var n = CryptoJS, r = n.lib.Hasher, e = n.x64, d = e.Word, T = e.WordArray, e = n.algo, ea = [a(1116352408, 3609767458), a(1899447441, 602891725), a(3049323471, 3964484399), a(3921009573, 2173295548), a(961987163, 4081628472), a(1508970993, 3053834265), a(2453635748, 2937671579), a(2870763221, 3664609560), a(3624381080, 2734883394), a(310598401, 1164996542), a(607225278, 1323610764), a(1426881987, 3590304994), a(1925078388, 4068182383), a(2162078206, 991336113), a(2614888103, 633803317), a(3248222580, 3479774868), a(3835390401, 2666613458), a(4022224774, 944711139), a(264347078, 2341262773), a(604807628, 2007800933), a(770255983, 1495990901), a(1249150122, 1856431235), a(1555081692, 3175218132), a(1996064986, 2198950837), a(2554220882, 3999719339), a(2821834349, 766784016), a(2952996808, 2566594879), a(3210313671, 3203337956), a(3336571891, 1034457026), a(3584528711, 2466948901), a(113926993, 3758326383), a(338241895, 168717936), a(666307205, 1188179964), a(773529912, 1546045734), a(1294757372, 1522805485), a(1396182291, 2643833823), a(1695183700, 2343527390), a(1986661051, 1014477480), a(2177026350, 1206759142), a(2456956037, 344077627), a(2730485921, 1290863460), a(2820302411, 3158454273), a(3259730800, 3505952657), a(3345764771, 106217008), a(3516065817, 3606008344), a(3600352804, 1432725776), a(4094571909, 1467031594), a(275423344, 851169720), a(430227734, 3100823752), a(506948616, 1363258195), a(659060556, 3750685593), a(883997877, 3785050280), a(958139571, 3318307427), a(1322822218, 3812723403), a(1537002063, 2003034995), a(1747873779, 3602036899), a(1955562222, 1575990012), a(2024104815, 1125592928), a(2227730452, 2716904306), a(2361852424, 442776044), a(2428436474, 593698344), a(2756734187, 3733110249), a(3204031479, 2999351573), a(3329325298, 3815920427), a(3391569614, 3928383900), a(3515267271, 566280711), a(3940187606, 3454069534), a(4118630271, 4000239992), a(116418474, 1914138554), a(174292421, 2731055270), a(289380356, 3203993006), a(460393269, 320620315), a(685471733, 587496836), a(852142971, 1086792851), a(1017036298, 365543100), a(1126000580, 2618297676), a(1288033470, 3409855158), a(1501505948, 4234509866), a(1607167915, 987167468), a(1816402316, 1246189591)], v = [], w = 0; 80 > w; w++) {\n    v[w] = a();\n  }e = e.SHA512 = r.extend({ _doReset: function _doReset() {\n      this._hash = new T.init([new d.init(1779033703, 4089235720), new d.init(3144134277, 2227873595), new d.init(1013904242, 4271175723), new d.init(2773480762, 1595750129), new d.init(1359893119, 2917565137), new d.init(2600822924, 725511199), new d.init(528734635, 4215389547), new d.init(1541459225, 327033209)]);\n    }, _doProcessBlock: function _doProcessBlock(a, d) {\n      for (var f = this._hash.words, F = f[0], e = f[1], n = f[2], r = f[3], G = f[4], H = f[5], I = f[6], f = f[7], w = F.high, J = F.low, X = e.high, K = e.low, Y = n.high, L = n.low, Z = r.high, M = r.low, $ = G.high, N = G.low, aa = H.high, O = H.low, ba = I.high, P = I.low, ca = f.high, Q = f.low, k = w, g = J, z = X, x = K, A = Y, y = L, U = Z, B = M, l = $, h = N, R = aa, C = O, S = ba, D = P, V = ca, E = Q, m = 0; 80 > m; m++) {\n        var s = v[m];if (16 > m) var j = s.high = a[d + 2 * m] | 0,\n            b = s.low = a[d + 2 * m + 1] | 0;else {\n          var j = v[m - 15],\n              b = j.high,\n              p = j.low,\n              j = (b >>> 1 | p << 31) ^ (b >>> 8 | p << 24) ^ b >>> 7,\n              p = (p >>> 1 | b << 31) ^ (p >>> 8 | b << 24) ^ (p >>> 7 | b << 25),\n              u = v[m - 2],\n              b = u.high,\n              c = u.low,\n              u = (b >>> 19 | c << 13) ^ (b << 3 | c >>> 29) ^ b >>> 6,\n              c = (c >>> 19 | b << 13) ^ (c << 3 | b >>> 29) ^ (c >>> 6 | b << 26),\n              b = v[m - 7],\n              W = b.high,\n              t = v[m - 16],\n              q = t.high,\n              t = t.low,\n              b = p + b.low,\n              j = j + W + (b >>> 0 < p >>> 0 ? 1 : 0),\n              b = b + c,\n              j = j + u + (b >>> 0 < c >>> 0 ? 1 : 0),\n              b = b + t,\n              j = j + q + (b >>> 0 < t >>> 0 ? 1 : 0);s.high = j;s.low = b;\n        }var W = l & R ^ ~l & S,\n            t = h & C ^ ~h & D,\n            s = k & z ^ k & A ^ z & A,\n            T = g & x ^ g & y ^ x & y,\n            p = (k >>> 28 | g << 4) ^ (k << 30 | g >>> 2) ^ (k << 25 | g >>> 7),\n            u = (g >>> 28 | k << 4) ^ (g << 30 | k >>> 2) ^ (g << 25 | k >>> 7),\n            c = ea[m],\n            fa = c.high,\n            da = c.low,\n            c = E + ((h >>> 14 | l << 18) ^ (h >>> 18 | l << 14) ^ (h << 23 | l >>> 9)),\n            q = V + ((l >>> 14 | h << 18) ^ (l >>> 18 | h << 14) ^ (l << 23 | h >>> 9)) + (c >>> 0 < E >>> 0 ? 1 : 0),\n            c = c + t,\n            q = q + W + (c >>> 0 < t >>> 0 ? 1 : 0),\n            c = c + da,\n            q = q + fa + (c >>> 0 < da >>> 0 ? 1 : 0),\n            c = c + b,\n            q = q + j + (c >>> 0 < b >>> 0 ? 1 : 0),\n            b = u + T,\n            s = p + s + (b >>> 0 < u >>> 0 ? 1 : 0),\n            V = S,\n            E = D,\n            S = R,\n            D = C,\n            R = l,\n            C = h,\n            h = B + c | 0,\n            l = U + q + (h >>> 0 < B >>> 0 ? 1 : 0) | 0,\n            U = A,\n            B = y,\n            A = z,\n            y = x,\n            z = k,\n            x = g,\n            g = c + b | 0,\n            k = q + s + (g >>> 0 < c >>> 0 ? 1 : 0) | 0;\n      }J = F.low = J + g;F.high = w + k + (J >>> 0 < g >>> 0 ? 1 : 0);K = e.low = K + x;e.high = X + z + (K >>> 0 < x >>> 0 ? 1 : 0);L = n.low = L + y;n.high = Y + A + (L >>> 0 < y >>> 0 ? 1 : 0);M = r.low = M + B;r.high = Z + U + (M >>> 0 < B >>> 0 ? 1 : 0);N = G.low = N + h;G.high = $ + l + (N >>> 0 < h >>> 0 ? 1 : 0);O = H.low = O + C;H.high = aa + R + (O >>> 0 < C >>> 0 ? 1 : 0);P = I.low = P + D;\n      I.high = ba + S + (P >>> 0 < D >>> 0 ? 1 : 0);Q = f.low = Q + E;f.high = ca + V + (Q >>> 0 < E >>> 0 ? 1 : 0);\n    }, _doFinalize: function _doFinalize() {\n      var a = this._data,\n          d = a.words,\n          f = 8 * this._nDataBytes,\n          e = 8 * a.sigBytes;d[e >>> 5] |= 128 << 24 - e % 32;d[(e + 128 >>> 10 << 5) + 30] = Math.floor(f / 4294967296);d[(e + 128 >>> 10 << 5) + 31] = f;a.sigBytes = 4 * d.length;this._process();return this._hash.toX32();\n    }, clone: function clone() {\n      var a = r.clone.call(this);a._hash = this._hash.clone();return a;\n    }, blockSize: 32 });n.SHA512 = r._createHelper(e);n.HmacSHA512 = r._createHmacHelper(e);\n})();\n\n/*\nCryptoJS v3.1.2 sha384-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function () {\n  var c = CryptoJS,\n      a = c.x64,\n      b = a.Word,\n      e = a.WordArray,\n      a = c.algo,\n      d = a.SHA512,\n      a = a.SHA384 = d.extend({ _doReset: function _doReset() {\n      this._hash = new e.init([new b.init(3418070365, 3238371032), new b.init(1654270250, 914150663), new b.init(2438529370, 812702999), new b.init(355462360, 4144912697), new b.init(1731405415, 4290775857), new b.init(2394180231, 1750603025), new b.init(3675008525, 1694076839), new b.init(1203062813, 3204075428)]);\n    }, _doFinalize: function _doFinalize() {\n      var a = d._doFinalize.call(this);a.sigBytes -= 16;return a;\n    } });c.SHA384 = d._createHelper(a);c.HmacSHA384 = d._createHmacHelper(a);\n})();\n\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nvar b64map = \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\";var b64pad = \"=\";function hex2b64(d) {\n  var b;var e;var a = \"\";for (b = 0; b + 3 <= d.length; b += 3) {\n    e = parseInt(d.substring(b, b + 3), 16);a += b64map.charAt(e >> 6) + b64map.charAt(e & 63);\n  }if (b + 1 == d.length) {\n    e = parseInt(d.substring(b, b + 1), 16);a += b64map.charAt(e << 2);\n  } else {\n    if (b + 2 == d.length) {\n      e = parseInt(d.substring(b, b + 2), 16);a += b64map.charAt(e >> 2) + b64map.charAt((e & 3) << 4);\n    }\n  }if (b64pad) {\n    while ((a.length & 3) > 0) {\n      a += b64pad;\n    }\n  }return a;\n}function b64tohex(f) {\n  var d = \"\";var e;var b = 0;var c;var a;for (e = 0; e < f.length; ++e) {\n    if (f.charAt(e) == b64pad) {\n      break;\n    }a = b64map.indexOf(f.charAt(e));if (a < 0) {\n      continue;\n    }if (b == 0) {\n      d += int2char(a >> 2);c = a & 3;b = 1;\n    } else {\n      if (b == 1) {\n        d += int2char(c << 2 | a >> 4);c = a & 15;b = 2;\n      } else {\n        if (b == 2) {\n          d += int2char(c);d += int2char(a >> 2);c = a & 3;b = 3;\n        } else {\n          d += int2char(c << 2 | a >> 4);d += int2char(a & 15);b = 0;\n        }\n      }\n    }\n  }if (b == 1) {\n    d += int2char(c << 2);\n  }return d;\n}function b64toBA(e) {\n  var d = b64tohex(e);var c;var b = new Array();for (c = 0; 2 * c < d.length; ++c) {\n    b[c] = parseInt(d.substring(2 * c, 2 * c + 2), 16);\n  }return b;\n};\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nvar dbits;var canary = 244837814094590;var j_lm = (canary & 16777215) == 15715070;function BigInteger(e, d, f) {\n  if (e != null) {\n    if (\"number\" == typeof e) {\n      this.fromNumber(e, d, f);\n    } else {\n      if (d == null && \"string\" != typeof e) {\n        this.fromString(e, 256);\n      } else {\n        this.fromString(e, d);\n      }\n    }\n  }\n}function nbi() {\n  return new BigInteger(null);\n}function am1(f, a, b, e, h, g) {\n  while (--g >= 0) {\n    var d = a * this[f++] + b[e] + h;h = Math.floor(d / 67108864);b[e++] = d & 67108863;\n  }return h;\n}function am2(f, q, r, e, o, a) {\n  var k = q & 32767,\n      p = q >> 15;while (--a >= 0) {\n    var d = this[f] & 32767;var g = this[f++] >> 15;var b = p * d + g * k;d = k * d + ((b & 32767) << 15) + r[e] + (o & 1073741823);o = (d >>> 30) + (b >>> 15) + p * g + (o >>> 30);r[e++] = d & 1073741823;\n  }return o;\n}function am3(f, q, r, e, o, a) {\n  var k = q & 16383,\n      p = q >> 14;while (--a >= 0) {\n    var d = this[f] & 16383;var g = this[f++] >> 14;var b = p * d + g * k;d = k * d + ((b & 16383) << 14) + r[e] + o;o = (d >> 28) + (b >> 14) + p * g;r[e++] = d & 268435455;\n  }return o;\n}if (j_lm && navigator.appName == \"Microsoft Internet Explorer\") {\n  BigInteger.prototype.am = am2;dbits = 30;\n} else {\n  if (j_lm && navigator.appName != \"Netscape\") {\n    BigInteger.prototype.am = am1;dbits = 26;\n  } else {\n    BigInteger.prototype.am = am3;dbits = 28;\n  }\n}BigInteger.prototype.DB = dbits;BigInteger.prototype.DM = (1 << dbits) - 1;BigInteger.prototype.DV = 1 << dbits;var BI_FP = 52;BigInteger.prototype.FV = Math.pow(2, BI_FP);BigInteger.prototype.F1 = BI_FP - dbits;BigInteger.prototype.F2 = 2 * dbits - BI_FP;var BI_RM = \"0123456789abcdefghijklmnopqrstuvwxyz\";var BI_RC = new Array();var rr, vv;rr = \"0\".charCodeAt(0);for (vv = 0; vv <= 9; ++vv) {\n  BI_RC[rr++] = vv;\n}rr = \"a\".charCodeAt(0);for (vv = 10; vv < 36; ++vv) {\n  BI_RC[rr++] = vv;\n}rr = \"A\".charCodeAt(0);for (vv = 10; vv < 36; ++vv) {\n  BI_RC[rr++] = vv;\n}function int2char(a) {\n  return BI_RM.charAt(a);\n}function intAt(b, a) {\n  var d = BI_RC[b.charCodeAt(a)];return d == null ? -1 : d;\n}function bnpCopyTo(b) {\n  for (var a = this.t - 1; a >= 0; --a) {\n    b[a] = this[a];\n  }b.t = this.t;b.s = this.s;\n}function bnpFromInt(a) {\n  this.t = 1;this.s = a < 0 ? -1 : 0;if (a > 0) {\n    this[0] = a;\n  } else {\n    if (a < -1) {\n      this[0] = a + this.DV;\n    } else {\n      this.t = 0;\n    }\n  }\n}function nbv(a) {\n  var b = nbi();b.fromInt(a);return b;\n}function bnpFromString(h, c) {\n  var e;if (c == 16) {\n    e = 4;\n  } else {\n    if (c == 8) {\n      e = 3;\n    } else {\n      if (c == 256) {\n        e = 8;\n      } else {\n        if (c == 2) {\n          e = 1;\n        } else {\n          if (c == 32) {\n            e = 5;\n          } else {\n            if (c == 4) {\n              e = 2;\n            } else {\n              this.fromRadix(h, c);return;\n            }\n          }\n        }\n      }\n    }\n  }this.t = 0;this.s = 0;var g = h.length,\n      d = false,\n      f = 0;while (--g >= 0) {\n    var a = e == 8 ? h[g] & 255 : intAt(h, g);if (a < 0) {\n      if (h.charAt(g) == \"-\") {\n        d = true;\n      }continue;\n    }d = false;if (f == 0) {\n      this[this.t++] = a;\n    } else {\n      if (f + e > this.DB) {\n        this[this.t - 1] |= (a & (1 << this.DB - f) - 1) << f;this[this.t++] = a >> this.DB - f;\n      } else {\n        this[this.t - 1] |= a << f;\n      }\n    }f += e;if (f >= this.DB) {\n      f -= this.DB;\n    }\n  }if (e == 8 && (h[0] & 128) != 0) {\n    this.s = -1;if (f > 0) {\n      this[this.t - 1] |= (1 << this.DB - f) - 1 << f;\n    }\n  }this.clamp();if (d) {\n    BigInteger.ZERO.subTo(this, this);\n  }\n}function bnpClamp() {\n  var a = this.s & this.DM;while (this.t > 0 && this[this.t - 1] == a) {\n    --this.t;\n  }\n}function bnToString(c) {\n  if (this.s < 0) {\n    return \"-\" + this.negate().toString(c);\n  }var e;if (c == 16) {\n    e = 4;\n  } else {\n    if (c == 8) {\n      e = 3;\n    } else {\n      if (c == 2) {\n        e = 1;\n      } else {\n        if (c == 32) {\n          e = 5;\n        } else {\n          if (c == 4) {\n            e = 2;\n          } else {\n            return this.toRadix(c);\n          }\n        }\n      }\n    }\n  }var g = (1 << e) - 1,\n      l,\n      a = false,\n      h = \"\",\n      f = this.t;var j = this.DB - f * this.DB % e;if (f-- > 0) {\n    if (j < this.DB && (l = this[f] >> j) > 0) {\n      a = true;h = int2char(l);\n    }while (f >= 0) {\n      if (j < e) {\n        l = (this[f] & (1 << j) - 1) << e - j;l |= this[--f] >> (j += this.DB - e);\n      } else {\n        l = this[f] >> (j -= e) & g;if (j <= 0) {\n          j += this.DB;--f;\n        }\n      }if (l > 0) {\n        a = true;\n      }if (a) {\n        h += int2char(l);\n      }\n    }\n  }return a ? h : \"0\";\n}function bnNegate() {\n  var a = nbi();BigInteger.ZERO.subTo(this, a);return a;\n}function bnAbs() {\n  return this.s < 0 ? this.negate() : this;\n}function bnCompareTo(b) {\n  var d = this.s - b.s;if (d != 0) {\n    return d;\n  }var c = this.t;d = c - b.t;if (d != 0) {\n    return this.s < 0 ? -d : d;\n  }while (--c >= 0) {\n    if ((d = this[c] - b[c]) != 0) {\n      return d;\n    }\n  }return 0;\n}function nbits(a) {\n  var c = 1,\n      b;if ((b = a >>> 16) != 0) {\n    a = b;c += 16;\n  }if ((b = a >> 8) != 0) {\n    a = b;c += 8;\n  }if ((b = a >> 4) != 0) {\n    a = b;c += 4;\n  }if ((b = a >> 2) != 0) {\n    a = b;c += 2;\n  }if ((b = a >> 1) != 0) {\n    a = b;c += 1;\n  }return c;\n}function bnBitLength() {\n  if (this.t <= 0) {\n    return 0;\n  }return this.DB * (this.t - 1) + nbits(this[this.t - 1] ^ this.s & this.DM);\n}function bnpDLShiftTo(c, b) {\n  var a;for (a = this.t - 1; a >= 0; --a) {\n    b[a + c] = this[a];\n  }for (a = c - 1; a >= 0; --a) {\n    b[a] = 0;\n  }b.t = this.t + c;b.s = this.s;\n}function bnpDRShiftTo(c, b) {\n  for (var a = c; a < this.t; ++a) {\n    b[a - c] = this[a];\n  }b.t = Math.max(this.t - c, 0);b.s = this.s;\n}function bnpLShiftTo(j, e) {\n  var b = j % this.DB;var a = this.DB - b;var g = (1 << a) - 1;var f = Math.floor(j / this.DB),\n      h = this.s << b & this.DM,\n      d;for (d = this.t - 1; d >= 0; --d) {\n    e[d + f + 1] = this[d] >> a | h;h = (this[d] & g) << b;\n  }for (d = f - 1; d >= 0; --d) {\n    e[d] = 0;\n  }e[f] = h;e.t = this.t + f + 1;e.s = this.s;e.clamp();\n}function bnpRShiftTo(g, d) {\n  d.s = this.s;var e = Math.floor(g / this.DB);if (e >= this.t) {\n    d.t = 0;return;\n  }var b = g % this.DB;var a = this.DB - b;var f = (1 << b) - 1;d[0] = this[e] >> b;for (var c = e + 1; c < this.t; ++c) {\n    d[c - e - 1] |= (this[c] & f) << a;d[c - e] = this[c] >> b;\n  }if (b > 0) {\n    d[this.t - e - 1] |= (this.s & f) << a;\n  }d.t = this.t - e;d.clamp();\n}function bnpSubTo(d, f) {\n  var e = 0,\n      g = 0,\n      b = Math.min(d.t, this.t);while (e < b) {\n    g += this[e] - d[e];f[e++] = g & this.DM;g >>= this.DB;\n  }if (d.t < this.t) {\n    g -= d.s;while (e < this.t) {\n      g += this[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g += this.s;\n  } else {\n    g += this.s;while (e < d.t) {\n      g -= d[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g -= d.s;\n  }f.s = g < 0 ? -1 : 0;if (g < -1) {\n    f[e++] = this.DV + g;\n  } else {\n    if (g > 0) {\n      f[e++] = g;\n    }\n  }f.t = e;f.clamp();\n}function bnpMultiplyTo(c, e) {\n  var b = this.abs(),\n      f = c.abs();var d = b.t;e.t = d + f.t;while (--d >= 0) {\n    e[d] = 0;\n  }for (d = 0; d < f.t; ++d) {\n    e[d + b.t] = b.am(0, f[d], e, d, 0, b.t);\n  }e.s = 0;e.clamp();if (this.s != c.s) {\n    BigInteger.ZERO.subTo(e, e);\n  }\n}function bnpSquareTo(d) {\n  var a = this.abs();var b = d.t = 2 * a.t;while (--b >= 0) {\n    d[b] = 0;\n  }for (b = 0; b < a.t - 1; ++b) {\n    var e = a.am(b, a[b], d, 2 * b, 0, 1);if ((d[b + a.t] += a.am(b + 1, 2 * a[b], d, 2 * b + 1, e, a.t - b - 1)) >= a.DV) {\n      d[b + a.t] -= a.DV;d[b + a.t + 1] = 1;\n    }\n  }if (d.t > 0) {\n    d[d.t - 1] += a.am(b, a[b], d, 2 * b, 0, 1);\n  }d.s = 0;d.clamp();\n}function bnpDivRemTo(n, h, g) {\n  var w = n.abs();if (w.t <= 0) {\n    return;\n  }var k = this.abs();if (k.t < w.t) {\n    if (h != null) {\n      h.fromInt(0);\n    }if (g != null) {\n      this.copyTo(g);\n    }return;\n  }if (g == null) {\n    g = nbi();\n  }var d = nbi(),\n      a = this.s,\n      l = n.s;var v = this.DB - nbits(w[w.t - 1]);if (v > 0) {\n    w.lShiftTo(v, d);k.lShiftTo(v, g);\n  } else {\n    w.copyTo(d);k.copyTo(g);\n  }var p = d.t;var b = d[p - 1];if (b == 0) {\n    return;\n  }var o = b * (1 << this.F1) + (p > 1 ? d[p - 2] >> this.F2 : 0);var A = this.FV / o,\n      z = (1 << this.F1) / o,\n      x = 1 << this.F2;var u = g.t,\n      s = u - p,\n      f = h == null ? nbi() : h;d.dlShiftTo(s, f);if (g.compareTo(f) >= 0) {\n    g[g.t++] = 1;g.subTo(f, g);\n  }BigInteger.ONE.dlShiftTo(p, f);f.subTo(d, d);while (d.t < p) {\n    d[d.t++] = 0;\n  }while (--s >= 0) {\n    var c = g[--u] == b ? this.DM : Math.floor(g[u] * A + (g[u - 1] + x) * z);if ((g[u] += d.am(0, c, g, s, 0, p)) < c) {\n      d.dlShiftTo(s, f);g.subTo(f, g);while (g[u] < --c) {\n        g.subTo(f, g);\n      }\n    }\n  }if (h != null) {\n    g.drShiftTo(p, h);if (a != l) {\n      BigInteger.ZERO.subTo(h, h);\n    }\n  }g.t = p;g.clamp();if (v > 0) {\n    g.rShiftTo(v, g);\n  }if (a < 0) {\n    BigInteger.ZERO.subTo(g, g);\n  }\n}function bnMod(b) {\n  var c = nbi();this.abs().divRemTo(b, null, c);if (this.s < 0 && c.compareTo(BigInteger.ZERO) > 0) {\n    b.subTo(c, c);\n  }return c;\n}function Classic(a) {\n  this.m = a;\n}function cConvert(a) {\n  if (a.s < 0 || a.compareTo(this.m) >= 0) {\n    return a.mod(this.m);\n  } else {\n    return a;\n  }\n}function cRevert(a) {\n  return a;\n}function cReduce(a) {\n  a.divRemTo(this.m, null, a);\n}function cMulTo(a, c, b) {\n  a.multiplyTo(c, b);this.reduce(b);\n}function cSqrTo(a, b) {\n  a.squareTo(b);this.reduce(b);\n}Classic.prototype.convert = cConvert;Classic.prototype.revert = cRevert;Classic.prototype.reduce = cReduce;Classic.prototype.mulTo = cMulTo;Classic.prototype.sqrTo = cSqrTo;function bnpInvDigit() {\n  if (this.t < 1) {\n    return 0;\n  }var a = this[0];if ((a & 1) == 0) {\n    return 0;\n  }var b = a & 3;b = b * (2 - (a & 15) * b) & 15;b = b * (2 - (a & 255) * b) & 255;b = b * (2 - ((a & 65535) * b & 65535)) & 65535;b = b * (2 - a * b % this.DV) % this.DV;return b > 0 ? this.DV - b : -b;\n}function Montgomery(a) {\n  this.m = a;this.mp = a.invDigit();this.mpl = this.mp & 32767;this.mph = this.mp >> 15;this.um = (1 << a.DB - 15) - 1;this.mt2 = 2 * a.t;\n}function montConvert(a) {\n  var b = nbi();a.abs().dlShiftTo(this.m.t, b);b.divRemTo(this.m, null, b);if (a.s < 0 && b.compareTo(BigInteger.ZERO) > 0) {\n    this.m.subTo(b, b);\n  }return b;\n}function montRevert(a) {\n  var b = nbi();a.copyTo(b);this.reduce(b);return b;\n}function montReduce(a) {\n  while (a.t <= this.mt2) {\n    a[a.t++] = 0;\n  }for (var c = 0; c < this.m.t; ++c) {\n    var b = a[c] & 32767;var d = b * this.mpl + ((b * this.mph + (a[c] >> 15) * this.mpl & this.um) << 15) & a.DM;b = c + this.m.t;a[b] += this.m.am(0, d, a, c, 0, this.m.t);while (a[b] >= a.DV) {\n      a[b] -= a.DV;a[++b]++;\n    }\n  }a.clamp();a.drShiftTo(this.m.t, a);if (a.compareTo(this.m) >= 0) {\n    a.subTo(this.m, a);\n  }\n}function montSqrTo(a, b) {\n  a.squareTo(b);this.reduce(b);\n}function montMulTo(a, c, b) {\n  a.multiplyTo(c, b);this.reduce(b);\n}Montgomery.prototype.convert = montConvert;Montgomery.prototype.revert = montRevert;Montgomery.prototype.reduce = montReduce;Montgomery.prototype.mulTo = montMulTo;Montgomery.prototype.sqrTo = montSqrTo;function bnpIsEven() {\n  return (this.t > 0 ? this[0] & 1 : this.s) == 0;\n}function bnpExp(h, j) {\n  if (h > 4294967295 || h < 1) {\n    return BigInteger.ONE;\n  }var f = nbi(),\n      a = nbi(),\n      d = j.convert(this),\n      c = nbits(h) - 1;d.copyTo(f);while (--c >= 0) {\n    j.sqrTo(f, a);if ((h & 1 << c) > 0) {\n      j.mulTo(a, d, f);\n    } else {\n      var b = f;f = a;a = b;\n    }\n  }return j.revert(f);\n}function bnModPowInt(b, a) {\n  var c;if (b < 256 || a.isEven()) {\n    c = new Classic(a);\n  } else {\n    c = new Montgomery(a);\n  }return this.exp(b, c);\n}BigInteger.prototype.copyTo = bnpCopyTo;BigInteger.prototype.fromInt = bnpFromInt;BigInteger.prototype.fromString = bnpFromString;BigInteger.prototype.clamp = bnpClamp;BigInteger.prototype.dlShiftTo = bnpDLShiftTo;BigInteger.prototype.drShiftTo = bnpDRShiftTo;BigInteger.prototype.lShiftTo = bnpLShiftTo;BigInteger.prototype.rShiftTo = bnpRShiftTo;BigInteger.prototype.subTo = bnpSubTo;BigInteger.prototype.multiplyTo = bnpMultiplyTo;BigInteger.prototype.squareTo = bnpSquareTo;BigInteger.prototype.divRemTo = bnpDivRemTo;BigInteger.prototype.invDigit = bnpInvDigit;BigInteger.prototype.isEven = bnpIsEven;BigInteger.prototype.exp = bnpExp;BigInteger.prototype.toString = bnToString;BigInteger.prototype.negate = bnNegate;BigInteger.prototype.abs = bnAbs;BigInteger.prototype.compareTo = bnCompareTo;BigInteger.prototype.bitLength = bnBitLength;BigInteger.prototype.mod = bnMod;BigInteger.prototype.modPowInt = bnModPowInt;BigInteger.ZERO = nbv(0);BigInteger.ONE = nbv(1);\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction bnClone() {\n  var a = nbi();this.copyTo(a);return a;\n}function bnIntValue() {\n  if (this.s < 0) {\n    if (this.t == 1) {\n      return this[0] - this.DV;\n    } else {\n      if (this.t == 0) {\n        return -1;\n      }\n    }\n  } else {\n    if (this.t == 1) {\n      return this[0];\n    } else {\n      if (this.t == 0) {\n        return 0;\n      }\n    }\n  }return (this[1] & (1 << 32 - this.DB) - 1) << this.DB | this[0];\n}function bnByteValue() {\n  return this.t == 0 ? this.s : this[0] << 24 >> 24;\n}function bnShortValue() {\n  return this.t == 0 ? this.s : this[0] << 16 >> 16;\n}function bnpChunkSize(a) {\n  return Math.floor(Math.LN2 * this.DB / Math.log(a));\n}function bnSigNum() {\n  if (this.s < 0) {\n    return -1;\n  } else {\n    if (this.t <= 0 || this.t == 1 && this[0] <= 0) {\n      return 0;\n    } else {\n      return 1;\n    }\n  }\n}function bnpToRadix(c) {\n  if (c == null) {\n    c = 10;\n  }if (this.signum() == 0 || c < 2 || c > 36) {\n    return \"0\";\n  }var f = this.chunkSize(c);var e = Math.pow(c, f);var i = nbv(e),\n      j = nbi(),\n      h = nbi(),\n      g = \"\";this.divRemTo(i, j, h);while (j.signum() > 0) {\n    g = (e + h.intValue()).toString(c).substr(1) + g;j.divRemTo(i, j, h);\n  }return h.intValue().toString(c) + g;\n}function bnpFromRadix(m, h) {\n  this.fromInt(0);if (h == null) {\n    h = 10;\n  }var f = this.chunkSize(h);var g = Math.pow(h, f),\n      e = false,\n      a = 0,\n      l = 0;for (var c = 0; c < m.length; ++c) {\n    var k = intAt(m, c);if (k < 0) {\n      if (m.charAt(c) == \"-\" && this.signum() == 0) {\n        e = true;\n      }continue;\n    }l = h * l + k;if (++a >= f) {\n      this.dMultiply(g);this.dAddOffset(l, 0);a = 0;l = 0;\n    }\n  }if (a > 0) {\n    this.dMultiply(Math.pow(h, a));this.dAddOffset(l, 0);\n  }if (e) {\n    BigInteger.ZERO.subTo(this, this);\n  }\n}function bnpFromNumber(f, e, h) {\n  if (\"number\" == typeof e) {\n    if (f < 2) {\n      this.fromInt(1);\n    } else {\n      this.fromNumber(f, h);if (!this.testBit(f - 1)) {\n        this.bitwiseTo(BigInteger.ONE.shiftLeft(f - 1), op_or, this);\n      }if (this.isEven()) {\n        this.dAddOffset(1, 0);\n      }while (!this.isProbablePrime(e)) {\n        this.dAddOffset(2, 0);if (this.bitLength() > f) {\n          this.subTo(BigInteger.ONE.shiftLeft(f - 1), this);\n        }\n      }\n    }\n  } else {\n    var d = new Array(),\n        g = f & 7;d.length = (f >> 3) + 1;e.nextBytes(d);if (g > 0) {\n      d[0] &= (1 << g) - 1;\n    } else {\n      d[0] = 0;\n    }this.fromString(d, 256);\n  }\n}function bnToByteArray() {\n  var b = this.t,\n      c = new Array();c[0] = this.s;var e = this.DB - b * this.DB % 8,\n      f,\n      a = 0;if (b-- > 0) {\n    if (e < this.DB && (f = this[b] >> e) != (this.s & this.DM) >> e) {\n      c[a++] = f | this.s << this.DB - e;\n    }while (b >= 0) {\n      if (e < 8) {\n        f = (this[b] & (1 << e) - 1) << 8 - e;f |= this[--b] >> (e += this.DB - 8);\n      } else {\n        f = this[b] >> (e -= 8) & 255;if (e <= 0) {\n          e += this.DB;--b;\n        }\n      }if ((f & 128) != 0) {\n        f |= -256;\n      }if (a == 0 && (this.s & 128) != (f & 128)) {\n        ++a;\n      }if (a > 0 || f != this.s) {\n        c[a++] = f;\n      }\n    }\n  }return c;\n}function bnEquals(b) {\n  return this.compareTo(b) == 0;\n}function bnMin(b) {\n  return this.compareTo(b) < 0 ? this : b;\n}function bnMax(b) {\n  return this.compareTo(b) > 0 ? this : b;\n}function bnpBitwiseTo(c, h, e) {\n  var d,\n      g,\n      b = Math.min(c.t, this.t);for (d = 0; d < b; ++d) {\n    e[d] = h(this[d], c[d]);\n  }if (c.t < this.t) {\n    g = c.s & this.DM;for (d = b; d < this.t; ++d) {\n      e[d] = h(this[d], g);\n    }e.t = this.t;\n  } else {\n    g = this.s & this.DM;for (d = b; d < c.t; ++d) {\n      e[d] = h(g, c[d]);\n    }e.t = c.t;\n  }e.s = h(this.s, c.s);e.clamp();\n}function op_and(a, b) {\n  return a & b;\n}function bnAnd(b) {\n  var c = nbi();this.bitwiseTo(b, op_and, c);return c;\n}function op_or(a, b) {\n  return a | b;\n}function bnOr(b) {\n  var c = nbi();this.bitwiseTo(b, op_or, c);return c;\n}function op_xor(a, b) {\n  return a ^ b;\n}function bnXor(b) {\n  var c = nbi();this.bitwiseTo(b, op_xor, c);return c;\n}function op_andnot(a, b) {\n  return a & ~b;\n}function bnAndNot(b) {\n  var c = nbi();this.bitwiseTo(b, op_andnot, c);return c;\n}function bnNot() {\n  var b = nbi();for (var a = 0; a < this.t; ++a) {\n    b[a] = this.DM & ~this[a];\n  }b.t = this.t;b.s = ~this.s;return b;\n}function bnShiftLeft(b) {\n  var a = nbi();if (b < 0) {\n    this.rShiftTo(-b, a);\n  } else {\n    this.lShiftTo(b, a);\n  }return a;\n}function bnShiftRight(b) {\n  var a = nbi();if (b < 0) {\n    this.lShiftTo(-b, a);\n  } else {\n    this.rShiftTo(b, a);\n  }return a;\n}function lbit(a) {\n  if (a == 0) {\n    return -1;\n  }var b = 0;if ((a & 65535) == 0) {\n    a >>= 16;b += 16;\n  }if ((a & 255) == 0) {\n    a >>= 8;b += 8;\n  }if ((a & 15) == 0) {\n    a >>= 4;b += 4;\n  }if ((a & 3) == 0) {\n    a >>= 2;b += 2;\n  }if ((a & 1) == 0) {\n    ++b;\n  }return b;\n}function bnGetLowestSetBit() {\n  for (var a = 0; a < this.t; ++a) {\n    if (this[a] != 0) {\n      return a * this.DB + lbit(this[a]);\n    }\n  }if (this.s < 0) {\n    return this.t * this.DB;\n  }return -1;\n}function cbit(a) {\n  var b = 0;while (a != 0) {\n    a &= a - 1;++b;\n  }return b;\n}function bnBitCount() {\n  var c = 0,\n      a = this.s & this.DM;for (var b = 0; b < this.t; ++b) {\n    c += cbit(this[b] ^ a);\n  }return c;\n}function bnTestBit(b) {\n  var a = Math.floor(b / this.DB);if (a >= this.t) {\n    return this.s != 0;\n  }return (this[a] & 1 << b % this.DB) != 0;\n}function bnpChangeBit(c, b) {\n  var a = BigInteger.ONE.shiftLeft(c);this.bitwiseTo(a, b, a);return a;\n}function bnSetBit(a) {\n  return this.changeBit(a, op_or);\n}function bnClearBit(a) {\n  return this.changeBit(a, op_andnot);\n}function bnFlipBit(a) {\n  return this.changeBit(a, op_xor);\n}function bnpAddTo(d, f) {\n  var e = 0,\n      g = 0,\n      b = Math.min(d.t, this.t);while (e < b) {\n    g += this[e] + d[e];f[e++] = g & this.DM;g >>= this.DB;\n  }if (d.t < this.t) {\n    g += d.s;while (e < this.t) {\n      g += this[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g += this.s;\n  } else {\n    g += this.s;while (e < d.t) {\n      g += d[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g += d.s;\n  }f.s = g < 0 ? -1 : 0;if (g > 0) {\n    f[e++] = g;\n  } else {\n    if (g < -1) {\n      f[e++] = this.DV + g;\n    }\n  }f.t = e;f.clamp();\n}function bnAdd(b) {\n  var c = nbi();this.addTo(b, c);return c;\n}function bnSubtract(b) {\n  var c = nbi();this.subTo(b, c);return c;\n}function bnMultiply(b) {\n  var c = nbi();this.multiplyTo(b, c);return c;\n}function bnSquare() {\n  var a = nbi();this.squareTo(a);return a;\n}function bnDivide(b) {\n  var c = nbi();this.divRemTo(b, c, null);return c;\n}function bnRemainder(b) {\n  var c = nbi();this.divRemTo(b, null, c);return c;\n}function bnDivideAndRemainder(b) {\n  var d = nbi(),\n      c = nbi();this.divRemTo(b, d, c);return new Array(d, c);\n}function bnpDMultiply(a) {\n  this[this.t] = this.am(0, a - 1, this, 0, 0, this.t);++this.t;this.clamp();\n}function bnpDAddOffset(b, a) {\n  if (b == 0) {\n    return;\n  }while (this.t <= a) {\n    this[this.t++] = 0;\n  }this[a] += b;while (this[a] >= this.DV) {\n    this[a] -= this.DV;if (++a >= this.t) {\n      this[this.t++] = 0;\n    }++this[a];\n  }\n}function NullExp() {}function nNop(a) {\n  return a;\n}function nMulTo(a, c, b) {\n  a.multiplyTo(c, b);\n}function nSqrTo(a, b) {\n  a.squareTo(b);\n}NullExp.prototype.convert = nNop;NullExp.prototype.revert = nNop;NullExp.prototype.mulTo = nMulTo;NullExp.prototype.sqrTo = nSqrTo;function bnPow(a) {\n  return this.exp(a, new NullExp());\n}function bnpMultiplyLowerTo(b, f, e) {\n  var d = Math.min(this.t + b.t, f);e.s = 0;e.t = d;while (d > 0) {\n    e[--d] = 0;\n  }var c;for (c = e.t - this.t; d < c; ++d) {\n    e[d + this.t] = this.am(0, b[d], e, d, 0, this.t);\n  }for (c = Math.min(b.t, f); d < c; ++d) {\n    this.am(0, b[d], e, d, 0, f - d);\n  }e.clamp();\n}function bnpMultiplyUpperTo(b, e, d) {\n  --e;var c = d.t = this.t + b.t - e;d.s = 0;while (--c >= 0) {\n    d[c] = 0;\n  }for (c = Math.max(e - this.t, 0); c < b.t; ++c) {\n    d[this.t + c - e] = this.am(e - c, b[c], d, 0, 0, this.t + c - e);\n  }d.clamp();d.drShiftTo(1, d);\n}function Barrett(a) {\n  this.r2 = nbi();this.q3 = nbi();BigInteger.ONE.dlShiftTo(2 * a.t, this.r2);this.mu = this.r2.divide(a);this.m = a;\n}function barrettConvert(a) {\n  if (a.s < 0 || a.t > 2 * this.m.t) {\n    return a.mod(this.m);\n  } else {\n    if (a.compareTo(this.m) < 0) {\n      return a;\n    } else {\n      var b = nbi();a.copyTo(b);this.reduce(b);return b;\n    }\n  }\n}function barrettRevert(a) {\n  return a;\n}function barrettReduce(a) {\n  a.drShiftTo(this.m.t - 1, this.r2);if (a.t > this.m.t + 1) {\n    a.t = this.m.t + 1;a.clamp();\n  }this.mu.multiplyUpperTo(this.r2, this.m.t + 1, this.q3);this.m.multiplyLowerTo(this.q3, this.m.t + 1, this.r2);while (a.compareTo(this.r2) < 0) {\n    a.dAddOffset(1, this.m.t + 1);\n  }a.subTo(this.r2, a);while (a.compareTo(this.m) >= 0) {\n    a.subTo(this.m, a);\n  }\n}function barrettSqrTo(a, b) {\n  a.squareTo(b);this.reduce(b);\n}function barrettMulTo(a, c, b) {\n  a.multiplyTo(c, b);this.reduce(b);\n}Barrett.prototype.convert = barrettConvert;Barrett.prototype.revert = barrettRevert;Barrett.prototype.reduce = barrettReduce;Barrett.prototype.mulTo = barrettMulTo;Barrett.prototype.sqrTo = barrettSqrTo;function bnModPow(q, f) {\n  var o = q.bitLength(),\n      h,\n      b = nbv(1),\n      v;if (o <= 0) {\n    return b;\n  } else {\n    if (o < 18) {\n      h = 1;\n    } else {\n      if (o < 48) {\n        h = 3;\n      } else {\n        if (o < 144) {\n          h = 4;\n        } else {\n          if (o < 768) {\n            h = 5;\n          } else {\n            h = 6;\n          }\n        }\n      }\n    }\n  }if (o < 8) {\n    v = new Classic(f);\n  } else {\n    if (f.isEven()) {\n      v = new Barrett(f);\n    } else {\n      v = new Montgomery(f);\n    }\n  }var p = new Array(),\n      d = 3,\n      s = h - 1,\n      a = (1 << h) - 1;p[1] = v.convert(this);if (h > 1) {\n    var A = nbi();v.sqrTo(p[1], A);while (d <= a) {\n      p[d] = nbi();v.mulTo(A, p[d - 2], p[d]);d += 2;\n    }\n  }var l = q.t - 1,\n      x,\n      u = true,\n      c = nbi(),\n      y;o = nbits(q[l]) - 1;while (l >= 0) {\n    if (o >= s) {\n      x = q[l] >> o - s & a;\n    } else {\n      x = (q[l] & (1 << o + 1) - 1) << s - o;if (l > 0) {\n        x |= q[l - 1] >> this.DB + o - s;\n      }\n    }d = h;while ((x & 1) == 0) {\n      x >>= 1;--d;\n    }if ((o -= d) < 0) {\n      o += this.DB;--l;\n    }if (u) {\n      p[x].copyTo(b);u = false;\n    } else {\n      while (d > 1) {\n        v.sqrTo(b, c);v.sqrTo(c, b);d -= 2;\n      }if (d > 0) {\n        v.sqrTo(b, c);\n      } else {\n        y = b;b = c;c = y;\n      }v.mulTo(c, p[x], b);\n    }while (l >= 0 && (q[l] & 1 << o) == 0) {\n      v.sqrTo(b, c);y = b;b = c;c = y;if (--o < 0) {\n        o = this.DB - 1;--l;\n      }\n    }\n  }return v.revert(b);\n}function bnGCD(c) {\n  var b = this.s < 0 ? this.negate() : this.clone();var h = c.s < 0 ? c.negate() : c.clone();if (b.compareTo(h) < 0) {\n    var e = b;b = h;h = e;\n  }var d = b.getLowestSetBit(),\n      f = h.getLowestSetBit();if (f < 0) {\n    return b;\n  }if (d < f) {\n    f = d;\n  }if (f > 0) {\n    b.rShiftTo(f, b);h.rShiftTo(f, h);\n  }while (b.signum() > 0) {\n    if ((d = b.getLowestSetBit()) > 0) {\n      b.rShiftTo(d, b);\n    }if ((d = h.getLowestSetBit()) > 0) {\n      h.rShiftTo(d, h);\n    }if (b.compareTo(h) >= 0) {\n      b.subTo(h, b);b.rShiftTo(1, b);\n    } else {\n      h.subTo(b, h);h.rShiftTo(1, h);\n    }\n  }if (f > 0) {\n    h.lShiftTo(f, h);\n  }return h;\n}function bnpModInt(e) {\n  if (e <= 0) {\n    return 0;\n  }var c = this.DV % e,\n      b = this.s < 0 ? e - 1 : 0;if (this.t > 0) {\n    if (c == 0) {\n      b = this[0] % e;\n    } else {\n      for (var a = this.t - 1; a >= 0; --a) {\n        b = (c * b + this[a]) % e;\n      }\n    }\n  }return b;\n}function bnModInverse(f) {\n  var j = f.isEven();if (this.isEven() && j || f.signum() == 0) {\n    return BigInteger.ZERO;\n  }var i = f.clone(),\n      h = this.clone();var g = nbv(1),\n      e = nbv(0),\n      l = nbv(0),\n      k = nbv(1);while (i.signum() != 0) {\n    while (i.isEven()) {\n      i.rShiftTo(1, i);if (j) {\n        if (!g.isEven() || !e.isEven()) {\n          g.addTo(this, g);e.subTo(f, e);\n        }g.rShiftTo(1, g);\n      } else {\n        if (!e.isEven()) {\n          e.subTo(f, e);\n        }\n      }e.rShiftTo(1, e);\n    }while (h.isEven()) {\n      h.rShiftTo(1, h);if (j) {\n        if (!l.isEven() || !k.isEven()) {\n          l.addTo(this, l);k.subTo(f, k);\n        }l.rShiftTo(1, l);\n      } else {\n        if (!k.isEven()) {\n          k.subTo(f, k);\n        }\n      }k.rShiftTo(1, k);\n    }if (i.compareTo(h) >= 0) {\n      i.subTo(h, i);if (j) {\n        g.subTo(l, g);\n      }e.subTo(k, e);\n    } else {\n      h.subTo(i, h);if (j) {\n        l.subTo(g, l);\n      }k.subTo(e, k);\n    }\n  }if (h.compareTo(BigInteger.ONE) != 0) {\n    return BigInteger.ZERO;\n  }if (k.compareTo(f) >= 0) {\n    return k.subtract(f);\n  }if (k.signum() < 0) {\n    k.addTo(f, k);\n  } else {\n    return k;\n  }if (k.signum() < 0) {\n    return k.add(f);\n  } else {\n    return k;\n  }\n}var lowprimes = [2, 3, 5, 7, 11, 13, 17, 19, 23, 29, 31, 37, 41, 43, 47, 53, 59, 61, 67, 71, 73, 79, 83, 89, 97, 101, 103, 107, 109, 113, 127, 131, 137, 139, 149, 151, 157, 163, 167, 173, 179, 181, 191, 193, 197, 199, 211, 223, 227, 229, 233, 239, 241, 251, 257, 263, 269, 271, 277, 281, 283, 293, 307, 311, 313, 317, 331, 337, 347, 349, 353, 359, 367, 373, 379, 383, 389, 397, 401, 409, 419, 421, 431, 433, 439, 443, 449, 457, 461, 463, 467, 479, 487, 491, 499, 503, 509, 521, 523, 541, 547, 557, 563, 569, 571, 577, 587, 593, 599, 601, 607, 613, 617, 619, 631, 641, 643, 647, 653, 659, 661, 673, 677, 683, 691, 701, 709, 719, 727, 733, 739, 743, 751, 757, 761, 769, 773, 787, 797, 809, 811, 821, 823, 827, 829, 839, 853, 857, 859, 863, 877, 881, 883, 887, 907, 911, 919, 929, 937, 941, 947, 953, 967, 971, 977, 983, 991, 997];var lplim = (1 << 26) / lowprimes[lowprimes.length - 1];function bnIsProbablePrime(e) {\n  var d,\n      b = this.abs();if (b.t == 1 && b[0] <= lowprimes[lowprimes.length - 1]) {\n    for (d = 0; d < lowprimes.length; ++d) {\n      if (b[0] == lowprimes[d]) {\n        return true;\n      }\n    }return false;\n  }if (b.isEven()) {\n    return false;\n  }d = 1;while (d < lowprimes.length) {\n    var a = lowprimes[d],\n        c = d + 1;while (c < lowprimes.length && a < lplim) {\n      a *= lowprimes[c++];\n    }a = b.modInt(a);while (d < c) {\n      if (a % lowprimes[d++] == 0) {\n        return false;\n      }\n    }\n  }return b.millerRabin(e);\n}function bnpMillerRabin(f) {\n  var g = this.subtract(BigInteger.ONE);var c = g.getLowestSetBit();if (c <= 0) {\n    return false;\n  }var h = g.shiftRight(c);f = f + 1 >> 1;if (f > lowprimes.length) {\n    f = lowprimes.length;\n  }var b = nbi();for (var e = 0; e < f; ++e) {\n    b.fromInt(lowprimes[Math.floor(Math.random() * lowprimes.length)]);var l = b.modPow(h, this);if (l.compareTo(BigInteger.ONE) != 0 && l.compareTo(g) != 0) {\n      var d = 1;while (d++ < c && l.compareTo(g) != 0) {\n        l = l.modPowInt(2, this);if (l.compareTo(BigInteger.ONE) == 0) {\n          return false;\n        }\n      }if (l.compareTo(g) != 0) {\n        return false;\n      }\n    }\n  }return true;\n}BigInteger.prototype.chunkSize = bnpChunkSize;BigInteger.prototype.toRadix = bnpToRadix;BigInteger.prototype.fromRadix = bnpFromRadix;BigInteger.prototype.fromNumber = bnpFromNumber;BigInteger.prototype.bitwiseTo = bnpBitwiseTo;BigInteger.prototype.changeBit = bnpChangeBit;BigInteger.prototype.addTo = bnpAddTo;BigInteger.prototype.dMultiply = bnpDMultiply;BigInteger.prototype.dAddOffset = bnpDAddOffset;BigInteger.prototype.multiplyLowerTo = bnpMultiplyLowerTo;BigInteger.prototype.multiplyUpperTo = bnpMultiplyUpperTo;BigInteger.prototype.modInt = bnpModInt;BigInteger.prototype.millerRabin = bnpMillerRabin;BigInteger.prototype.clone = bnClone;BigInteger.prototype.intValue = bnIntValue;BigInteger.prototype.byteValue = bnByteValue;BigInteger.prototype.shortValue = bnShortValue;BigInteger.prototype.signum = bnSigNum;BigInteger.prototype.toByteArray = bnToByteArray;BigInteger.prototype.equals = bnEquals;BigInteger.prototype.min = bnMin;BigInteger.prototype.max = bnMax;BigInteger.prototype.and = bnAnd;BigInteger.prototype.or = bnOr;BigInteger.prototype.xor = bnXor;BigInteger.prototype.andNot = bnAndNot;BigInteger.prototype.not = bnNot;BigInteger.prototype.shiftLeft = bnShiftLeft;BigInteger.prototype.shiftRight = bnShiftRight;BigInteger.prototype.getLowestSetBit = bnGetLowestSetBit;BigInteger.prototype.bitCount = bnBitCount;BigInteger.prototype.testBit = bnTestBit;BigInteger.prototype.setBit = bnSetBit;BigInteger.prototype.clearBit = bnClearBit;BigInteger.prototype.flipBit = bnFlipBit;BigInteger.prototype.add = bnAdd;BigInteger.prototype.subtract = bnSubtract;BigInteger.prototype.multiply = bnMultiply;BigInteger.prototype.divide = bnDivide;BigInteger.prototype.remainder = bnRemainder;BigInteger.prototype.divideAndRemainder = bnDivideAndRemainder;BigInteger.prototype.modPow = bnModPow;BigInteger.prototype.modInverse = bnModInverse;BigInteger.prototype.pow = bnPow;BigInteger.prototype.gcd = bnGCD;BigInteger.prototype.isProbablePrime = bnIsProbablePrime;BigInteger.prototype.square = bnSquare;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction Arcfour() {\n  this.i = 0;this.j = 0;this.S = new Array();\n}function ARC4init(d) {\n  var c, a, b;for (c = 0; c < 256; ++c) {\n    this.S[c] = c;\n  }a = 0;for (c = 0; c < 256; ++c) {\n    a = a + this.S[c] + d[c % d.length] & 255;b = this.S[c];this.S[c] = this.S[a];this.S[a] = b;\n  }this.i = 0;this.j = 0;\n}function ARC4next() {\n  var a;this.i = this.i + 1 & 255;this.j = this.j + this.S[this.i] & 255;a = this.S[this.i];this.S[this.i] = this.S[this.j];this.S[this.j] = a;return this.S[a + this.S[this.i] & 255];\n}Arcfour.prototype.init = ARC4init;Arcfour.prototype.next = ARC4next;function prng_newstate() {\n  return new Arcfour();\n}var rng_psize = 256;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nvar rng_state;var rng_pool;var rng_pptr;function rng_seed_int(a) {\n  rng_pool[rng_pptr++] ^= a & 255;rng_pool[rng_pptr++] ^= a >> 8 & 255;rng_pool[rng_pptr++] ^= a >> 16 & 255;rng_pool[rng_pptr++] ^= a >> 24 & 255;if (rng_pptr >= rng_psize) {\n    rng_pptr -= rng_psize;\n  }\n}function rng_seed_time() {\n  rng_seed_int(new Date().getTime());\n}if (rng_pool == null) {\n  rng_pool = new Array();rng_pptr = 0;var t;if (window !== undefined && (window.crypto !== undefined || window.msCrypto !== undefined)) {\n    var crypto = window.crypto || window.msCrypto;if (crypto.getRandomValues) {\n      var ua = new Uint8Array(32);crypto.getRandomValues(ua);for (t = 0; t < 32; ++t) {\n        rng_pool[rng_pptr++] = ua[t];\n      }\n    } else {\n      if (navigator.appName == \"Netscape\" && navigator.appVersion < \"5\") {\n        var z = window.crypto.random(32);for (t = 0; t < z.length; ++t) {\n          rng_pool[rng_pptr++] = z.charCodeAt(t) & 255;\n        }\n      }\n    }\n  }while (rng_pptr < rng_psize) {\n    t = Math.floor(65536 * Math.random());rng_pool[rng_pptr++] = t >>> 8;rng_pool[rng_pptr++] = t & 255;\n  }rng_pptr = 0;rng_seed_time();\n}function rng_get_byte() {\n  if (rng_state == null) {\n    rng_seed_time();rng_state = prng_newstate();rng_state.init(rng_pool);for (rng_pptr = 0; rng_pptr < rng_pool.length; ++rng_pptr) {\n      rng_pool[rng_pptr] = 0;\n    }rng_pptr = 0;\n  }return rng_state.next();\n}function rng_get_bytes(b) {\n  var a;for (a = 0; a < b.length; ++a) {\n    b[a] = rng_get_byte();\n  }\n}function SecureRandom() {}SecureRandom.prototype.nextBytes = rng_get_bytes;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction parseBigInt(b, a) {\n  return new BigInteger(b, a);\n}function linebrk(c, d) {\n  var a = \"\";var b = 0;while (b + d < c.length) {\n    a += c.substring(b, b + d) + \"\\n\";b += d;\n  }return a + c.substring(b, c.length);\n}function byte2Hex(a) {\n  if (a < 16) {\n    return \"0\" + a.toString(16);\n  } else {\n    return a.toString(16);\n  }\n}function pkcs1pad2(e, h) {\n  if (h < e.length + 11) {\n    throw \"Message too long for RSA\";return null;\n  }var g = new Array();var d = e.length - 1;while (d >= 0 && h > 0) {\n    var f = e.charCodeAt(d--);if (f < 128) {\n      g[--h] = f;\n    } else {\n      if (f > 127 && f < 2048) {\n        g[--h] = f & 63 | 128;g[--h] = f >> 6 | 192;\n      } else {\n        g[--h] = f & 63 | 128;g[--h] = f >> 6 & 63 | 128;g[--h] = f >> 12 | 224;\n      }\n    }\n  }g[--h] = 0;var b = new SecureRandom();var a = new Array();while (h > 2) {\n    a[0] = 0;while (a[0] == 0) {\n      b.nextBytes(a);\n    }g[--h] = a[0];\n  }g[--h] = 2;g[--h] = 0;return new BigInteger(g);\n}function oaep_mgf1_arr(c, a, e) {\n  var b = \"\",\n      d = 0;while (b.length < a) {\n    b += e(String.fromCharCode.apply(String, c.concat([(d & 4278190080) >> 24, (d & 16711680) >> 16, (d & 65280) >> 8, d & 255])));d += 1;\n  }return b;\n}function oaep_pad(q, a, f, l) {\n  var c = KJUR.crypto.MessageDigest;var o = KJUR.crypto.Util;var b = null;if (!f) {\n    f = \"sha1\";\n  }if (typeof f === \"string\") {\n    b = c.getCanonicalAlgName(f);l = c.getHashLength(b);f = function f(i) {\n      return hextorstr(o.hashHex(rstrtohex(i), b));\n    };\n  }if (q.length + 2 * l + 2 > a) {\n    throw \"Message too long for RSA\";\n  }var k = \"\",\n      e;for (e = 0; e < a - q.length - 2 * l - 2; e += 1) {\n    k += \"\\x00\";\n  }var h = f(\"\") + k + \"\\x01\" + q;var g = new Array(l);new SecureRandom().nextBytes(g);var j = oaep_mgf1_arr(g, h.length, f);var p = [];for (e = 0; e < h.length; e += 1) {\n    p[e] = h.charCodeAt(e) ^ j.charCodeAt(e);\n  }var m = oaep_mgf1_arr(p, g.length, f);var d = [0];for (e = 0; e < g.length; e += 1) {\n    d[e + 1] = g[e] ^ m.charCodeAt(e);\n  }return new BigInteger(d.concat(p));\n}function RSAKey() {\n  this.n = null;this.e = 0;this.d = null;this.p = null;this.q = null;this.dmp1 = null;this.dmq1 = null;this.coeff = null;\n}function RSASetPublic(b, a) {\n  this.isPublic = true;this.isPrivate = false;if (typeof b !== \"string\") {\n    this.n = b;this.e = a;\n  } else {\n    if (b != null && a != null && b.length > 0 && a.length > 0) {\n      this.n = parseBigInt(b, 16);this.e = parseInt(a, 16);\n    } else {\n      throw \"Invalid RSA public key\";\n    }\n  }\n}function RSADoPublic(a) {\n  return a.modPowInt(this.e, this.n);\n}function RSAEncrypt(d) {\n  var a = pkcs1pad2(d, this.n.bitLength() + 7 >> 3);if (a == null) {\n    return null;\n  }var e = this.doPublic(a);if (e == null) {\n    return null;\n  }var b = e.toString(16);if ((b.length & 1) == 0) {\n    return b;\n  } else {\n    return \"0\" + b;\n  }\n}function RSAEncryptOAEP(f, e, b) {\n  var a = oaep_pad(f, this.n.bitLength() + 7 >> 3, e, b);if (a == null) {\n    return null;\n  }var g = this.doPublic(a);if (g == null) {\n    return null;\n  }var d = g.toString(16);if ((d.length & 1) == 0) {\n    return d;\n  } else {\n    return \"0\" + d;\n  }\n}RSAKey.prototype.doPublic = RSADoPublic;RSAKey.prototype.setPublic = RSASetPublic;RSAKey.prototype.encrypt = RSAEncrypt;RSAKey.prototype.encryptOAEP = RSAEncryptOAEP;RSAKey.prototype.type = \"RSA\";\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction ECFieldElementFp(b, a) {\n  this.x = a;this.q = b;\n}function feFpEquals(a) {\n  if (a == this) {\n    return true;\n  }return this.q.equals(a.q) && this.x.equals(a.x);\n}function feFpToBigInteger() {\n  return this.x;\n}function feFpNegate() {\n  return new ECFieldElementFp(this.q, this.x.negate().mod(this.q));\n}function feFpAdd(a) {\n  return new ECFieldElementFp(this.q, this.x.add(a.toBigInteger()).mod(this.q));\n}function feFpSubtract(a) {\n  return new ECFieldElementFp(this.q, this.x.subtract(a.toBigInteger()).mod(this.q));\n}function feFpMultiply(a) {\n  return new ECFieldElementFp(this.q, this.x.multiply(a.toBigInteger()).mod(this.q));\n}function feFpSquare() {\n  return new ECFieldElementFp(this.q, this.x.square().mod(this.q));\n}function feFpDivide(a) {\n  return new ECFieldElementFp(this.q, this.x.multiply(a.toBigInteger().modInverse(this.q)).mod(this.q));\n}ECFieldElementFp.prototype.equals = feFpEquals;ECFieldElementFp.prototype.toBigInteger = feFpToBigInteger;ECFieldElementFp.prototype.negate = feFpNegate;ECFieldElementFp.prototype.add = feFpAdd;ECFieldElementFp.prototype.subtract = feFpSubtract;ECFieldElementFp.prototype.multiply = feFpMultiply;ECFieldElementFp.prototype.square = feFpSquare;ECFieldElementFp.prototype.divide = feFpDivide;function ECPointFp(c, a, d, b) {\n  this.curve = c;this.x = a;this.y = d;if (b == null) {\n    this.z = BigInteger.ONE;\n  } else {\n    this.z = b;\n  }this.zinv = null;\n}function pointFpGetX() {\n  if (this.zinv == null) {\n    this.zinv = this.z.modInverse(this.curve.q);\n  }return this.curve.fromBigInteger(this.x.toBigInteger().multiply(this.zinv).mod(this.curve.q));\n}function pointFpGetY() {\n  if (this.zinv == null) {\n    this.zinv = this.z.modInverse(this.curve.q);\n  }return this.curve.fromBigInteger(this.y.toBigInteger().multiply(this.zinv).mod(this.curve.q));\n}function pointFpEquals(a) {\n  if (a == this) {\n    return true;\n  }if (this.isInfinity()) {\n    return a.isInfinity();\n  }if (a.isInfinity()) {\n    return this.isInfinity();\n  }var c, b;c = a.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(a.z)).mod(this.curve.q);if (!c.equals(BigInteger.ZERO)) {\n    return false;\n  }b = a.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(a.z)).mod(this.curve.q);return b.equals(BigInteger.ZERO);\n}function pointFpIsInfinity() {\n  if (this.x == null && this.y == null) {\n    return true;\n  }return this.z.equals(BigInteger.ZERO) && !this.y.toBigInteger().equals(BigInteger.ZERO);\n}function pointFpNegate() {\n  return new ECPointFp(this.curve, this.x, this.y.negate(), this.z);\n}function pointFpAdd(l) {\n  if (this.isInfinity()) {\n    return l;\n  }if (l.isInfinity()) {\n    return this;\n  }var p = l.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(l.z)).mod(this.curve.q);var o = l.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(l.z)).mod(this.curve.q);if (BigInteger.ZERO.equals(o)) {\n    if (BigInteger.ZERO.equals(p)) {\n      return this.twice();\n    }return this.curve.getInfinity();\n  }var j = new BigInteger(\"3\");var e = this.x.toBigInteger();var n = this.y.toBigInteger();var c = l.x.toBigInteger();var k = l.y.toBigInteger();var m = o.square();var i = m.multiply(o);var d = e.multiply(m);var g = p.square().multiply(this.z);var a = g.subtract(d.shiftLeft(1)).multiply(l.z).subtract(i).multiply(o).mod(this.curve.q);var h = d.multiply(j).multiply(p).subtract(n.multiply(i)).subtract(g.multiply(p)).multiply(l.z).add(p.multiply(i)).mod(this.curve.q);var f = i.multiply(this.z).multiply(l.z).mod(this.curve.q);return new ECPointFp(this.curve, this.curve.fromBigInteger(a), this.curve.fromBigInteger(h), f);\n}function pointFpTwice() {\n  if (this.isInfinity()) {\n    return this;\n  }if (this.y.toBigInteger().signum() == 0) {\n    return this.curve.getInfinity();\n  }var g = new BigInteger(\"3\");var c = this.x.toBigInteger();var h = this.y.toBigInteger();var e = h.multiply(this.z);var j = e.multiply(h).mod(this.curve.q);var i = this.curve.a.toBigInteger();var k = c.square().multiply(g);if (!BigInteger.ZERO.equals(i)) {\n    k = k.add(this.z.square().multiply(i));\n  }k = k.mod(this.curve.q);var b = k.square().subtract(c.shiftLeft(3).multiply(j)).shiftLeft(1).multiply(e).mod(this.curve.q);var f = k.multiply(g).multiply(c).subtract(j.shiftLeft(1)).shiftLeft(2).multiply(j).subtract(k.square().multiply(k)).mod(this.curve.q);var d = e.square().multiply(e).shiftLeft(3).mod(this.curve.q);return new ECPointFp(this.curve, this.curve.fromBigInteger(b), this.curve.fromBigInteger(f), d);\n}function pointFpMultiply(b) {\n  if (this.isInfinity()) {\n    return this;\n  }if (b.signum() == 0) {\n    return this.curve.getInfinity();\n  }var g = b;var f = g.multiply(new BigInteger(\"3\"));var l = this.negate();var d = this;var c;for (c = f.bitLength() - 2; c > 0; --c) {\n    d = d.twice();var a = f.testBit(c);var j = g.testBit(c);if (a != j) {\n      d = d.add(a ? this : l);\n    }\n  }return d;\n}function pointFpMultiplyTwo(c, a, b) {\n  var d;if (c.bitLength() > b.bitLength()) {\n    d = c.bitLength() - 1;\n  } else {\n    d = b.bitLength() - 1;\n  }var f = this.curve.getInfinity();var e = this.add(a);while (d >= 0) {\n    f = f.twice();if (c.testBit(d)) {\n      if (b.testBit(d)) {\n        f = f.add(e);\n      } else {\n        f = f.add(this);\n      }\n    } else {\n      if (b.testBit(d)) {\n        f = f.add(a);\n      }\n    }--d;\n  }return f;\n}ECPointFp.prototype.getX = pointFpGetX;ECPointFp.prototype.getY = pointFpGetY;ECPointFp.prototype.equals = pointFpEquals;ECPointFp.prototype.isInfinity = pointFpIsInfinity;ECPointFp.prototype.negate = pointFpNegate;ECPointFp.prototype.add = pointFpAdd;ECPointFp.prototype.twice = pointFpTwice;ECPointFp.prototype.multiply = pointFpMultiply;ECPointFp.prototype.multiplyTwo = pointFpMultiplyTwo;function ECCurveFp(e, d, c) {\n  this.q = e;this.a = this.fromBigInteger(d);this.b = this.fromBigInteger(c);this.infinity = new ECPointFp(this, null, null);\n}function curveFpGetQ() {\n  return this.q;\n}function curveFpGetA() {\n  return this.a;\n}function curveFpGetB() {\n  return this.b;\n}function curveFpEquals(a) {\n  if (a == this) {\n    return true;\n  }return this.q.equals(a.q) && this.a.equals(a.a) && this.b.equals(a.b);\n}function curveFpGetInfinity() {\n  return this.infinity;\n}function curveFpFromBigInteger(a) {\n  return new ECFieldElementFp(this.q, a);\n}function curveFpDecodePointHex(d) {\n  switch (parseInt(d.substr(0, 2), 16)) {case 0:\n      return this.infinity;case 2:case 3:\n      return null;case 4:case 6:case 7:\n      var a = (d.length - 2) / 2;var c = d.substr(2, a);var b = d.substr(a + 2, a);return new ECPointFp(this, this.fromBigInteger(new BigInteger(c, 16)), this.fromBigInteger(new BigInteger(b, 16)));default:\n      return null;}\n}ECCurveFp.prototype.getQ = curveFpGetQ;ECCurveFp.prototype.getA = curveFpGetA;ECCurveFp.prototype.getB = curveFpGetB;ECCurveFp.prototype.equals = curveFpEquals;ECCurveFp.prototype.getInfinity = curveFpGetInfinity;ECCurveFp.prototype.fromBigInteger = curveFpFromBigInteger;ECCurveFp.prototype.decodePointHex = curveFpDecodePointHex;\n/*! (c) Stefan Thomas | https://github.com/bitcoinjs/bitcoinjs-lib\n */\nECFieldElementFp.prototype.getByteLength = function () {\n  return Math.floor((this.toBigInteger().bitLength() + 7) / 8);\n};ECPointFp.prototype.getEncoded = function (c) {\n  var d = function d(h, f) {\n    var g = h.toByteArrayUnsigned();if (f < g.length) {\n      g = g.slice(g.length - f);\n    } else {\n      while (f > g.length) {\n        g.unshift(0);\n      }\n    }return g;\n  };var a = this.getX().toBigInteger();var e = this.getY().toBigInteger();var b = d(a, 32);if (c) {\n    if (e.isEven()) {\n      b.unshift(2);\n    } else {\n      b.unshift(3);\n    }\n  } else {\n    b.unshift(4);b = b.concat(d(e, 32));\n  }return b;\n};ECPointFp.decodeFrom = function (g, c) {\n  var f = c[0];var e = c.length - 1;var d = c.slice(1, 1 + e / 2);var b = c.slice(1 + e / 2, 1 + e);d.unshift(0);b.unshift(0);var a = new BigInteger(d);var h = new BigInteger(b);return new ECPointFp(g, g.fromBigInteger(a), g.fromBigInteger(h));\n};ECPointFp.decodeFromHex = function (g, c) {\n  var f = c.substr(0, 2);var e = c.length - 2;var d = c.substr(2, e / 2);var b = c.substr(2 + e / 2, e / 2);var a = new BigInteger(d, 16);var h = new BigInteger(b, 16);return new ECPointFp(g, g.fromBigInteger(a), g.fromBigInteger(h));\n};ECPointFp.prototype.add2D = function (c) {\n  if (this.isInfinity()) {\n    return c;\n  }if (c.isInfinity()) {\n    return this;\n  }if (this.x.equals(c.x)) {\n    if (this.y.equals(c.y)) {\n      return this.twice();\n    }return this.curve.getInfinity();\n  }var g = c.x.subtract(this.x);var e = c.y.subtract(this.y);var a = e.divide(g);var d = a.square().subtract(this.x).subtract(c.x);var f = a.multiply(this.x.subtract(d)).subtract(this.y);return new ECPointFp(this.curve, d, f);\n};ECPointFp.prototype.twice2D = function () {\n  if (this.isInfinity()) {\n    return this;\n  }if (this.y.toBigInteger().signum() == 0) {\n    return this.curve.getInfinity();\n  }var b = this.curve.fromBigInteger(BigInteger.valueOf(2));var e = this.curve.fromBigInteger(BigInteger.valueOf(3));var a = this.x.square().multiply(e).add(this.curve.a).divide(this.y.multiply(b));var c = a.square().subtract(this.x.multiply(b));var d = a.multiply(this.x.subtract(c)).subtract(this.y);return new ECPointFp(this.curve, c, d);\n};ECPointFp.prototype.multiply2D = function (b) {\n  if (this.isInfinity()) {\n    return this;\n  }if (b.signum() == 0) {\n    return this.curve.getInfinity();\n  }var g = b;var f = g.multiply(new BigInteger(\"3\"));var l = this.negate();var d = this;var c;for (c = f.bitLength() - 2; c > 0; --c) {\n    d = d.twice();var a = f.testBit(c);var j = g.testBit(c);if (a != j) {\n      d = d.add2D(a ? this : l);\n    }\n  }return d;\n};ECPointFp.prototype.isOnCurve = function () {\n  var d = this.getX().toBigInteger();var i = this.getY().toBigInteger();var f = this.curve.getA().toBigInteger();var c = this.curve.getB().toBigInteger();var h = this.curve.getQ();var e = i.multiply(i).mod(h);var g = d.multiply(d).multiply(d).add(f.multiply(d)).add(c).mod(h);return e.equals(g);\n};ECPointFp.prototype.toString = function () {\n  return \"(\" + this.getX().toBigInteger().toString() + \",\" + this.getY().toBigInteger().toString() + \")\";\n};ECPointFp.prototype.validate = function () {\n  var c = this.curve.getQ();if (this.isInfinity()) {\n    throw new Error(\"Point is at infinity.\");\n  }var a = this.getX().toBigInteger();var b = this.getY().toBigInteger();if (a.compareTo(BigInteger.ONE) < 0 || a.compareTo(c.subtract(BigInteger.ONE)) > 0) {\n    throw new Error(\"x coordinate out of bounds\");\n  }if (b.compareTo(BigInteger.ONE) < 0 || b.compareTo(c.subtract(BigInteger.ONE)) > 0) {\n    throw new Error(\"y coordinate out of bounds\");\n  }if (!this.isOnCurve()) {\n    throw new Error(\"Point is not on the curve.\");\n  }if (this.multiply(c).isInfinity()) {\n    throw new Error(\"Point is not a scalar multiple of G.\");\n  }return true;\n};\n/*! Mike Samuel (c) 2009 | code.google.com/p/json-sans-eval\n */\nvar jsonParse = function () {\n  var e = \"(?:-?\\\\b(?:0|[1-9][0-9]*)(?:\\\\.[0-9]+)?(?:[eE][+-]?[0-9]+)?\\\\b)\";var j = '(?:[^\\\\0-\\\\x08\\\\x0a-\\\\x1f\"\\\\\\\\]|\\\\\\\\(?:[\"/\\\\\\\\bfnrt]|u[0-9A-Fa-f]{4}))';var i = '(?:\"' + j + '*\")';var d = new RegExp(\"(?:false|true|null|[\\\\{\\\\}\\\\[\\\\]]|\" + e + \"|\" + i + \")\", \"g\");var k = new RegExp(\"\\\\\\\\(?:([^u])|u(.{4}))\", \"g\");var g = { '\"': '\"', \"/\": \"/\", \"\\\\\": \"\\\\\", b: \"\\b\", f: \"\\f\", n: \"\\n\", r: \"\\r\", t: \"\\t\" };function h(l, m, n) {\n    return m ? g[m] : String.fromCharCode(parseInt(n, 16));\n  }var c = new String(\"\");var a = \"\\\\\";var f = { \"{\": Object, \"[\": Array };var b = Object.hasOwnProperty;return function (u, q) {\n    var p = u.match(d);var x;var v = p[0];var l = false;if (\"{\" === v) {\n      x = {};\n    } else {\n      if (\"[\" === v) {\n        x = [];\n      } else {\n        x = [];l = true;\n      }\n    }var t;var r = [x];for (var o = 1 - l, m = p.length; o < m; ++o) {\n      v = p[o];var w;switch (v.charCodeAt(0)) {default:\n          w = r[0];w[t || w.length] = +v;t = void 0;break;case 34:\n          v = v.substring(1, v.length - 1);if (v.indexOf(a) !== -1) {\n            v = v.replace(k, h);\n          }w = r[0];if (!t) {\n            if (w instanceof Array) {\n              t = w.length;\n            } else {\n              t = v || c;break;\n            }\n          }w[t] = v;t = void 0;break;case 91:\n          w = r[0];r.unshift(w[t || w.length] = []);t = void 0;break;case 93:\n          r.shift();break;case 102:\n          w = r[0];w[t || w.length] = false;t = void 0;break;case 110:\n          w = r[0];w[t || w.length] = null;t = void 0;break;case 116:\n          w = r[0];w[t || w.length] = true;t = void 0;break;case 123:\n          w = r[0];r.unshift(w[t || w.length] = {});t = void 0;break;case 125:\n          r.shift();break;}\n    }if (l) {\n      if (r.length !== 1) {\n        throw new Error();\n      }x = x[0];\n    } else {\n      if (r.length) {\n        throw new Error();\n      }\n    }if (q) {\n      var s = function s(C, B) {\n        var D = C[B];if (D && (typeof D === \"undefined\" ? \"undefined\" : _typeof(D)) === \"object\") {\n          var n = null;for (var z in D) {\n            if (b.call(D, z) && D !== C) {\n              var y = s(D, z);if (y !== void 0) {\n                D[z] = y;\n              } else {\n                if (!n) {\n                  n = [];\n                }n.push(z);\n              }\n            }\n          }if (n) {\n            for (var A = n.length; --A >= 0;) {\n              delete D[n[A]];\n            }\n          }\n        }return q.call(C, B, D);\n      };x = s({ \"\": x }, \"\");\n    }return x;\n  };\n}();\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.asn1 == \"undefined\" || !KJUR.asn1) {\n  KJUR.asn1 = {};\n}KJUR.asn1.ASN1Util = new function () {\n  this.integerToByteHex = function (a) {\n    var b = a.toString(16);if (b.length % 2 == 1) {\n      b = \"0\" + b;\n    }return b;\n  };this.bigIntToMinTwosComplementsHex = function (j) {\n    var f = j.toString(16);if (f.substr(0, 1) != \"-\") {\n      if (f.length % 2 == 1) {\n        f = \"0\" + f;\n      } else {\n        if (!f.match(/^[0-7]/)) {\n          f = \"00\" + f;\n        }\n      }\n    } else {\n      var a = f.substr(1);var e = a.length;if (e % 2 == 1) {\n        e += 1;\n      } else {\n        if (!f.match(/^[0-7]/)) {\n          e += 2;\n        }\n      }var g = \"\";for (var d = 0; d < e; d++) {\n        g += \"f\";\n      }var c = new BigInteger(g, 16);var b = c.xor(j).add(BigInteger.ONE);f = b.toString(16).replace(/^-/, \"\");\n    }return f;\n  };this.getPEMStringFromHex = function (a, b) {\n    return hextopem(a, b);\n  };this.newObject = function (k) {\n    var D = KJUR,\n        n = D.asn1,\n        z = n.DERBoolean,\n        e = n.DERInteger,\n        s = n.DERBitString,\n        h = n.DEROctetString,\n        v = n.DERNull,\n        w = n.DERObjectIdentifier,\n        l = n.DEREnumerated,\n        g = n.DERUTF8String,\n        f = n.DERNumericString,\n        y = n.DERPrintableString,\n        u = n.DERTeletexString,\n        p = n.DERIA5String,\n        C = n.DERUTCTime,\n        j = n.DERGeneralizedTime,\n        m = n.DERSequence,\n        c = n.DERSet,\n        r = n.DERTaggedObject,\n        o = n.ASN1Util.newObject;var t = Object.keys(k);if (t.length != 1) {\n      throw \"key of param shall be only one.\";\n    }var F = t[0];if (\":bool:int:bitstr:octstr:null:oid:enum:utf8str:numstr:prnstr:telstr:ia5str:utctime:gentime:seq:set:tag:\".indexOf(\":\" + F + \":\") == -1) {\n      throw \"undefined key: \" + F;\n    }if (F == \"bool\") {\n      return new z(k[F]);\n    }if (F == \"int\") {\n      return new e(k[F]);\n    }if (F == \"bitstr\") {\n      return new s(k[F]);\n    }if (F == \"octstr\") {\n      return new h(k[F]);\n    }if (F == \"null\") {\n      return new v(k[F]);\n    }if (F == \"oid\") {\n      return new w(k[F]);\n    }if (F == \"enum\") {\n      return new l(k[F]);\n    }if (F == \"utf8str\") {\n      return new g(k[F]);\n    }if (F == \"numstr\") {\n      return new f(k[F]);\n    }if (F == \"prnstr\") {\n      return new y(k[F]);\n    }if (F == \"telstr\") {\n      return new u(k[F]);\n    }if (F == \"ia5str\") {\n      return new p(k[F]);\n    }if (F == \"utctime\") {\n      return new C(k[F]);\n    }if (F == \"gentime\") {\n      return new j(k[F]);\n    }if (F == \"seq\") {\n      var d = k[F];var E = [];for (var x = 0; x < d.length; x++) {\n        var B = o(d[x]);E.push(B);\n      }return new m({ array: E });\n    }if (F == \"set\") {\n      var d = k[F];var E = [];for (var x = 0; x < d.length; x++) {\n        var B = o(d[x]);E.push(B);\n      }return new c({ array: E });\n    }if (F == \"tag\") {\n      var A = k[F];if (Object.prototype.toString.call(A) === \"[object Array]\" && A.length == 3) {\n        var q = o(A[2]);return new r({ tag: A[0], explicit: A[1], obj: q });\n      } else {\n        var b = {};if (A.explicit !== undefined) {\n          b.explicit = A.explicit;\n        }if (A.tag !== undefined) {\n          b.tag = A.tag;\n        }if (A.obj === undefined) {\n          throw \"obj shall be specified for 'tag'.\";\n        }b.obj = o(A.obj);return new r(b);\n      }\n    }\n  };this.jsonToASN1HEX = function (b) {\n    var a = this.newObject(b);return a.getEncodedHex();\n  };\n}();KJUR.asn1.ASN1Util.oidHexToInt = function (a) {\n  var j = \"\";var k = parseInt(a.substr(0, 2), 16);var d = Math.floor(k / 40);var c = k % 40;var j = d + \".\" + c;var e = \"\";for (var f = 2; f < a.length; f += 2) {\n    var g = parseInt(a.substr(f, 2), 16);var h = (\"00000000\" + g.toString(2)).slice(-8);e = e + h.substr(1, 7);if (h.substr(0, 1) == \"0\") {\n      var b = new BigInteger(e, 2);j = j + \".\" + b.toString(10);e = \"\";\n    }\n  }return j;\n};KJUR.asn1.ASN1Util.oidIntToHex = function (f) {\n  var e = function e(a) {\n    var k = a.toString(16);if (k.length == 1) {\n      k = \"0\" + k;\n    }return k;\n  };var d = function d(o) {\n    var n = \"\";var k = new BigInteger(o, 10);var a = k.toString(2);var l = 7 - a.length % 7;if (l == 7) {\n      l = 0;\n    }var q = \"\";for (var m = 0; m < l; m++) {\n      q += \"0\";\n    }a = q + a;for (var m = 0; m < a.length - 1; m += 7) {\n      var p = a.substr(m, 7);if (m != a.length - 7) {\n        p = \"1\" + p;\n      }n += e(parseInt(p, 2));\n    }return n;\n  };if (!f.match(/^[0-9.]+$/)) {\n    throw \"malformed oid string: \" + f;\n  }var g = \"\";var b = f.split(\".\");var j = parseInt(b[0]) * 40 + parseInt(b[1]);g += e(j);b.splice(0, 2);for (var c = 0; c < b.length; c++) {\n    g += d(b[c]);\n  }return g;\n};KJUR.asn1.ASN1Object = function () {\n  var c = true;var b = null;var d = \"00\";var e = \"00\";var a = \"\";this.getLengthHexFromValue = function () {\n    if (typeof this.hV == \"undefined\" || this.hV == null) {\n      throw \"this.hV is null or undefined.\";\n    }if (this.hV.length % 2 == 1) {\n      throw \"value hex must be even length: n=\" + a.length + \",v=\" + this.hV;\n    }var i = this.hV.length / 2;var h = i.toString(16);if (h.length % 2 == 1) {\n      h = \"0\" + h;\n    }if (i < 128) {\n      return h;\n    } else {\n      var g = h.length / 2;if (g > 15) {\n        throw \"ASN.1 length too long to represent by 8x: n = \" + i.toString(16);\n      }var f = 128 + g;return f.toString(16) + h;\n    }\n  };this.getEncodedHex = function () {\n    if (this.hTLV == null || this.isModified) {\n      this.hV = this.getFreshValueHex();this.hL = this.getLengthHexFromValue();this.hTLV = this.hT + this.hL + this.hV;this.isModified = false;\n    }return this.hTLV;\n  };this.getValueHex = function () {\n    this.getEncodedHex();return this.hV;\n  };this.getFreshValueHex = function () {\n    return \"\";\n  };\n};KJUR.asn1.DERAbstractString = function (c) {\n  KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var b = null;var a = null;this.getString = function () {\n    return this.s;\n  };this.setString = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = d;this.hV = utf8tohex(this.s).toLowerCase();\n  };this.setStringHex = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = null;this.hV = d;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof c != \"undefined\") {\n    if (typeof c == \"string\") {\n      this.setString(c);\n    } else {\n      if (typeof c.str != \"undefined\") {\n        this.setString(c.str);\n      } else {\n        if (typeof c.hex != \"undefined\") {\n          this.setStringHex(c.hex);\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERAbstractString, KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractTime = function (c) {\n  KJUR.asn1.DERAbstractTime.superclass.constructor.call(this);var b = null;var a = null;this.localDateToUTC = function (f) {\n    utc = f.getTime() + f.getTimezoneOffset() * 60000;var e = new Date(utc);return e;\n  };this.formatDate = function (m, o, e) {\n    var g = this.zeroPadding;var n = this.localDateToUTC(m);var p = String(n.getFullYear());if (o == \"utc\") {\n      p = p.substr(2, 2);\n    }var l = g(String(n.getMonth() + 1), 2);var q = g(String(n.getDate()), 2);var h = g(String(n.getHours()), 2);var i = g(String(n.getMinutes()), 2);var j = g(String(n.getSeconds()), 2);var r = p + l + q + h + i + j;if (e === true) {\n      var f = n.getMilliseconds();if (f != 0) {\n        var k = g(String(f), 3);k = k.replace(/[0]+$/, \"\");r = r + \".\" + k;\n      }\n    }return r + \"Z\";\n  };this.zeroPadding = function (e, d) {\n    if (e.length >= d) {\n      return e;\n    }return new Array(d - e.length + 1).join(\"0\") + e;\n  };this.getString = function () {\n    return this.s;\n  };this.setString = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = d;this.hV = stohex(d);\n  };this.setByDateValue = function (h, j, e, d, f, g) {\n    var i = new Date(Date.UTC(h, j - 1, e, d, f, g, 0));this.setByDate(i);\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };\n};YAHOO.lang.extend(KJUR.asn1.DERAbstractTime, KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractStructured = function (b) {\n  KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var a = null;this.setByASN1ObjectArray = function (c) {\n    this.hTLV = null;this.isModified = true;this.asn1Array = c;\n  };this.appendASN1Object = function (c) {\n    this.hTLV = null;this.isModified = true;this.asn1Array.push(c);\n  };this.asn1Array = new Array();if (typeof b != \"undefined\") {\n    if (typeof b.array != \"undefined\") {\n      this.asn1Array = b.array;\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERAbstractStructured, KJUR.asn1.ASN1Object);KJUR.asn1.DERBoolean = function () {\n  KJUR.asn1.DERBoolean.superclass.constructor.call(this);this.hT = \"01\";this.hTLV = \"0101ff\";\n};YAHOO.lang.extend(KJUR.asn1.DERBoolean, KJUR.asn1.ASN1Object);KJUR.asn1.DERInteger = function (a) {\n  KJUR.asn1.DERInteger.superclass.constructor.call(this);this.hT = \"02\";this.setByBigInteger = function (b) {\n    this.hTLV = null;this.isModified = true;this.hV = KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b);\n  };this.setByInteger = function (c) {\n    var b = new BigInteger(String(c), 10);this.setByBigInteger(b);\n  };this.setValueHex = function (b) {\n    this.hV = b;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a.bigint != \"undefined\") {\n      this.setByBigInteger(a.bigint);\n    } else {\n      if (typeof a[\"int\"] != \"undefined\") {\n        this.setByInteger(a[\"int\"]);\n      } else {\n        if (typeof a == \"number\") {\n          this.setByInteger(a);\n        } else {\n          if (typeof a.hex != \"undefined\") {\n            this.setValueHex(a.hex);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERInteger, KJUR.asn1.ASN1Object);KJUR.asn1.DERBitString = function (b) {\n  if (b !== undefined && typeof b.obj !== \"undefined\") {\n    var a = KJUR.asn1.ASN1Util.newObject(b.obj);b.hex = \"00\" + a.getEncodedHex();\n  }KJUR.asn1.DERBitString.superclass.constructor.call(this);this.hT = \"03\";this.setHexValueIncludingUnusedBits = function (c) {\n    this.hTLV = null;this.isModified = true;this.hV = c;\n  };this.setUnusedBitsAndHexValue = function (c, e) {\n    if (c < 0 || 7 < c) {\n      throw \"unused bits shall be from 0 to 7: u = \" + c;\n    }var d = \"0\" + c;this.hTLV = null;this.isModified = true;this.hV = d + e;\n  };this.setByBinaryString = function (e) {\n    e = e.replace(/0+$/, \"\");var f = 8 - e.length % 8;if (f == 8) {\n      f = 0;\n    }for (var g = 0; g <= f; g++) {\n      e += \"0\";\n    }var j = \"\";for (var g = 0; g < e.length - 1; g += 8) {\n      var d = e.substr(g, 8);var c = parseInt(d, 2).toString(16);if (c.length == 1) {\n        c = \"0\" + c;\n      }j += c;\n    }this.hTLV = null;this.isModified = true;this.hV = \"0\" + f + j;\n  };this.setByBooleanArray = function (e) {\n    var d = \"\";for (var c = 0; c < e.length; c++) {\n      if (e[c] == true) {\n        d += \"1\";\n      } else {\n        d += \"0\";\n      }\n    }this.setByBinaryString(d);\n  };this.newFalseArray = function (e) {\n    var c = new Array(e);for (var d = 0; d < e; d++) {\n      c[d] = false;\n    }return c;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof b != \"undefined\") {\n    if (typeof b == \"string\" && b.toLowerCase().match(/^[0-9a-f]+$/)) {\n      this.setHexValueIncludingUnusedBits(b);\n    } else {\n      if (typeof b.hex != \"undefined\") {\n        this.setHexValueIncludingUnusedBits(b.hex);\n      } else {\n        if (typeof b.bin != \"undefined\") {\n          this.setByBinaryString(b.bin);\n        } else {\n          if (typeof b.array != \"undefined\") {\n            this.setByBooleanArray(b.array);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERBitString, KJUR.asn1.ASN1Object);KJUR.asn1.DEROctetString = function (b) {\n  if (b !== undefined && typeof b.obj !== \"undefined\") {\n    var a = KJUR.asn1.ASN1Util.newObject(b.obj);b.hex = a.getEncodedHex();\n  }KJUR.asn1.DEROctetString.superclass.constructor.call(this, b);this.hT = \"04\";\n};YAHOO.lang.extend(KJUR.asn1.DEROctetString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERNull = function () {\n  KJUR.asn1.DERNull.superclass.constructor.call(this);this.hT = \"05\";this.hTLV = \"0500\";\n};YAHOO.lang.extend(KJUR.asn1.DERNull, KJUR.asn1.ASN1Object);KJUR.asn1.DERObjectIdentifier = function (c) {\n  var b = function b(d) {\n    var e = d.toString(16);if (e.length == 1) {\n      e = \"0\" + e;\n    }return e;\n  };var a = function a(k) {\n    var j = \"\";var e = new BigInteger(k, 10);var d = e.toString(2);var f = 7 - d.length % 7;if (f == 7) {\n      f = 0;\n    }var m = \"\";for (var g = 0; g < f; g++) {\n      m += \"0\";\n    }d = m + d;for (var g = 0; g < d.length - 1; g += 7) {\n      var l = d.substr(g, 7);if (g != d.length - 7) {\n        l = \"1\" + l;\n      }j += b(parseInt(l, 2));\n    }return j;\n  };KJUR.asn1.DERObjectIdentifier.superclass.constructor.call(this);this.hT = \"06\";this.setValueHex = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = null;this.hV = d;\n  };this.setValueOidString = function (f) {\n    if (!f.match(/^[0-9.]+$/)) {\n      throw \"malformed oid string: \" + f;\n    }var g = \"\";var d = f.split(\".\");var j = parseInt(d[0]) * 40 + parseInt(d[1]);g += b(j);d.splice(0, 2);for (var e = 0; e < d.length; e++) {\n      g += a(d[e]);\n    }this.hTLV = null;this.isModified = true;this.s = null;this.hV = g;\n  };this.setValueName = function (e) {\n    var d = KJUR.asn1.x509.OID.name2oid(e);if (d !== \"\") {\n      this.setValueOidString(d);\n    } else {\n      throw \"DERObjectIdentifier oidName undefined: \" + e;\n    }\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (c !== undefined) {\n    if (typeof c === \"string\") {\n      if (c.match(/^[0-2].[0-9.]+$/)) {\n        this.setValueOidString(c);\n      } else {\n        this.setValueName(c);\n      }\n    } else {\n      if (c.oid !== undefined) {\n        this.setValueOidString(c.oid);\n      } else {\n        if (c.hex !== undefined) {\n          this.setValueHex(c.hex);\n        } else {\n          if (c.name !== undefined) {\n            this.setValueName(c.name);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERObjectIdentifier, KJUR.asn1.ASN1Object);KJUR.asn1.DEREnumerated = function (a) {\n  KJUR.asn1.DEREnumerated.superclass.constructor.call(this);this.hT = \"0a\";this.setByBigInteger = function (b) {\n    this.hTLV = null;this.isModified = true;this.hV = KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b);\n  };this.setByInteger = function (c) {\n    var b = new BigInteger(String(c), 10);this.setByBigInteger(b);\n  };this.setValueHex = function (b) {\n    this.hV = b;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a[\"int\"] != \"undefined\") {\n      this.setByInteger(a[\"int\"]);\n    } else {\n      if (typeof a == \"number\") {\n        this.setByInteger(a);\n      } else {\n        if (typeof a.hex != \"undefined\") {\n          this.setValueHex(a.hex);\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DEREnumerated, KJUR.asn1.ASN1Object);KJUR.asn1.DERUTF8String = function (a) {\n  KJUR.asn1.DERUTF8String.superclass.constructor.call(this, a);this.hT = \"0c\";\n};YAHOO.lang.extend(KJUR.asn1.DERUTF8String, KJUR.asn1.DERAbstractString);KJUR.asn1.DERNumericString = function (a) {\n  KJUR.asn1.DERNumericString.superclass.constructor.call(this, a);this.hT = \"12\";\n};YAHOO.lang.extend(KJUR.asn1.DERNumericString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERPrintableString = function (a) {\n  KJUR.asn1.DERPrintableString.superclass.constructor.call(this, a);this.hT = \"13\";\n};YAHOO.lang.extend(KJUR.asn1.DERPrintableString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERTeletexString = function (a) {\n  KJUR.asn1.DERTeletexString.superclass.constructor.call(this, a);this.hT = \"14\";\n};YAHOO.lang.extend(KJUR.asn1.DERTeletexString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERIA5String = function (a) {\n  KJUR.asn1.DERIA5String.superclass.constructor.call(this, a);this.hT = \"16\";\n};YAHOO.lang.extend(KJUR.asn1.DERIA5String, KJUR.asn1.DERAbstractString);KJUR.asn1.DERUTCTime = function (a) {\n  KJUR.asn1.DERUTCTime.superclass.constructor.call(this, a);this.hT = \"17\";this.setByDate = function (b) {\n    this.hTLV = null;this.isModified = true;this.date = b;this.s = this.formatDate(this.date, \"utc\");this.hV = stohex(this.s);\n  };this.getFreshValueHex = function () {\n    if (typeof this.date == \"undefined\" && typeof this.s == \"undefined\") {\n      this.date = new Date();this.s = this.formatDate(this.date, \"utc\");this.hV = stohex(this.s);\n    }return this.hV;\n  };if (a !== undefined) {\n    if (a.str !== undefined) {\n      this.setString(a.str);\n    } else {\n      if (typeof a == \"string\" && a.match(/^[0-9]{12}Z$/)) {\n        this.setString(a);\n      } else {\n        if (a.hex !== undefined) {\n          this.setStringHex(a.hex);\n        } else {\n          if (a.date !== undefined) {\n            this.setByDate(a.date);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERUTCTime, KJUR.asn1.DERAbstractTime);KJUR.asn1.DERGeneralizedTime = function (a) {\n  KJUR.asn1.DERGeneralizedTime.superclass.constructor.call(this, a);this.hT = \"18\";this.withMillis = false;this.setByDate = function (b) {\n    this.hTLV = null;this.isModified = true;this.date = b;this.s = this.formatDate(this.date, \"gen\", this.withMillis);this.hV = stohex(this.s);\n  };this.getFreshValueHex = function () {\n    if (this.date === undefined && this.s === undefined) {\n      this.date = new Date();this.s = this.formatDate(this.date, \"gen\", this.withMillis);this.hV = stohex(this.s);\n    }return this.hV;\n  };if (a !== undefined) {\n    if (a.str !== undefined) {\n      this.setString(a.str);\n    } else {\n      if (typeof a == \"string\" && a.match(/^[0-9]{14}Z$/)) {\n        this.setString(a);\n      } else {\n        if (a.hex !== undefined) {\n          this.setStringHex(a.hex);\n        } else {\n          if (a.date !== undefined) {\n            this.setByDate(a.date);\n          }\n        }\n      }\n    }if (a.millis === true) {\n      this.withMillis = true;\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERGeneralizedTime, KJUR.asn1.DERAbstractTime);KJUR.asn1.DERSequence = function (a) {\n  KJUR.asn1.DERSequence.superclass.constructor.call(this, a);this.hT = \"30\";this.getFreshValueHex = function () {\n    var c = \"\";for (var b = 0; b < this.asn1Array.length; b++) {\n      var d = this.asn1Array[b];c += d.getEncodedHex();\n    }this.hV = c;return this.hV;\n  };\n};YAHOO.lang.extend(KJUR.asn1.DERSequence, KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERSet = function (a) {\n  KJUR.asn1.DERSet.superclass.constructor.call(this, a);this.hT = \"31\";this.sortFlag = true;this.getFreshValueHex = function () {\n    var b = new Array();for (var c = 0; c < this.asn1Array.length; c++) {\n      var d = this.asn1Array[c];b.push(d.getEncodedHex());\n    }if (this.sortFlag == true) {\n      b.sort();\n    }this.hV = b.join(\"\");return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a.sortflag != \"undefined\" && a.sortflag == false) {\n      this.sortFlag = false;\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERSet, KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERTaggedObject = function (a) {\n  KJUR.asn1.DERTaggedObject.superclass.constructor.call(this);this.hT = \"a0\";this.hV = \"\";this.isExplicit = true;this.asn1Object = null;this.setASN1Object = function (b, c, d) {\n    this.hT = c;this.isExplicit = b;this.asn1Object = d;if (this.isExplicit) {\n      this.hV = this.asn1Object.getEncodedHex();this.hTLV = null;this.isModified = true;\n    } else {\n      this.hV = null;this.hTLV = d.getEncodedHex();this.hTLV = this.hTLV.replace(/^../, c);this.isModified = false;\n    }\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a.tag != \"undefined\") {\n      this.hT = a.tag;\n    }if (typeof a.explicit != \"undefined\") {\n      this.isExplicit = a.explicit;\n    }if (typeof a.obj != \"undefined\") {\n      this.asn1Object = a.obj;this.setASN1Object(this.isExplicit, this.hT, this.asn1Object);\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERTaggedObject, KJUR.asn1.ASN1Object);\nvar ASN1HEX = new function () {}();ASN1HEX.getLblen = function (c, a) {\n  if (c.substr(a + 2, 1) != \"8\") {\n    return 1;\n  }var b = parseInt(c.substr(a + 3, 1));if (b == 0) {\n    return -1;\n  }if (0 < b && b < 10) {\n    return b + 1;\n  }return -2;\n};ASN1HEX.getL = function (c, b) {\n  var a = ASN1HEX.getLblen(c, b);if (a < 1) {\n    return \"\";\n  }return c.substr(b + 2, a * 2);\n};ASN1HEX.getVblen = function (d, a) {\n  var c, b;c = ASN1HEX.getL(d, a);if (c == \"\") {\n    return -1;\n  }if (c.substr(0, 1) === \"8\") {\n    b = new BigInteger(c.substr(2), 16);\n  } else {\n    b = new BigInteger(c, 16);\n  }return b.intValue();\n};ASN1HEX.getVidx = function (c, b) {\n  var a = ASN1HEX.getLblen(c, b);if (a < 0) {\n    return a;\n  }return b + (a + 1) * 2;\n};ASN1HEX.getV = function (d, a) {\n  var c = ASN1HEX.getVidx(d, a);var b = ASN1HEX.getVblen(d, a);return d.substr(c, b * 2);\n};ASN1HEX.getTLV = function (b, a) {\n  return b.substr(a, 2) + ASN1HEX.getL(b, a) + ASN1HEX.getV(b, a);\n};ASN1HEX.getNextSiblingIdx = function (d, a) {\n  var c = ASN1HEX.getVidx(d, a);var b = ASN1HEX.getVblen(d, a);return c + b * 2;\n};ASN1HEX.getChildIdx = function (e, f) {\n  var j = ASN1HEX;var g = new Array();var i = j.getVidx(e, f);if (e.substr(f, 2) == \"03\") {\n    g.push(i + 2);\n  } else {\n    g.push(i);\n  }var l = j.getVblen(e, f);var c = i;var d = 0;while (1) {\n    var b = j.getNextSiblingIdx(e, c);if (b == null || b - i >= l * 2) {\n      break;\n    }if (d >= 200) {\n      break;\n    }g.push(b);c = b;d++;\n  }return g;\n};ASN1HEX.getNthChildIdx = function (d, b, e) {\n  var c = ASN1HEX.getChildIdx(d, b);return c[e];\n};ASN1HEX.getIdxbyList = function (e, d, c, i) {\n  var g = ASN1HEX;var f, b;if (c.length == 0) {\n    if (i !== undefined) {\n      if (e.substr(d, 2) !== i) {\n        throw \"checking tag doesn't match: \" + e.substr(d, 2) + \"!=\" + i;\n      }\n    }return d;\n  }f = c.shift();b = g.getChildIdx(e, d);return g.getIdxbyList(e, b[f], c, i);\n};ASN1HEX.getTLVbyList = function (d, c, b, f) {\n  var e = ASN1HEX;var a = e.getIdxbyList(d, c, b);if (a === undefined) {\n    throw \"can't find nthList object\";\n  }if (f !== undefined) {\n    if (d.substr(a, 2) != f) {\n      throw \"checking tag doesn't match: \" + d.substr(a, 2) + \"!=\" + f;\n    }\n  }return e.getTLV(d, a);\n};ASN1HEX.getVbyList = function (e, c, b, g, i) {\n  var f = ASN1HEX;var a, d;a = f.getIdxbyList(e, c, b, g);if (a === undefined) {\n    throw \"can't find nthList object\";\n  }d = f.getV(e, a);if (i === true) {\n    d = d.substr(2);\n  }return d;\n};ASN1HEX.hextooidstr = function (e) {\n  var h = function h(b, a) {\n    if (b.length >= a) {\n      return b;\n    }return new Array(a - b.length + 1).join(\"0\") + b;\n  };var l = [];var o = e.substr(0, 2);var f = parseInt(o, 16);l[0] = new String(Math.floor(f / 40));l[1] = new String(f % 40);var m = e.substr(2);var k = [];for (var g = 0; g < m.length / 2; g++) {\n    k.push(parseInt(m.substr(g * 2, 2), 16));\n  }var j = [];var d = \"\";for (var g = 0; g < k.length; g++) {\n    if (k[g] & 128) {\n      d = d + h((k[g] & 127).toString(2), 7);\n    } else {\n      d = d + h((k[g] & 127).toString(2), 7);j.push(new String(parseInt(d, 2)));d = \"\";\n    }\n  }var n = l.join(\".\");if (j.length > 0) {\n    n = n + \".\" + j.join(\".\");\n  }return n;\n};ASN1HEX.dump = function (t, c, l, g) {\n  var p = ASN1HEX;var j = p.getV;var y = p.dump;var w = p.getChildIdx;var e = t;if (t instanceof KJUR.asn1.ASN1Object) {\n    e = t.getEncodedHex();\n  }var q = function q(A, i) {\n    if (A.length <= i * 2) {\n      return A;\n    } else {\n      var v = A.substr(0, i) + \"..(total \" + A.length / 2 + \"bytes)..\" + A.substr(A.length - i, i);return v;\n    }\n  };if (c === undefined) {\n    c = { ommit_long_octet: 32 };\n  }if (l === undefined) {\n    l = 0;\n  }if (g === undefined) {\n    g = \"\";\n  }var x = c.ommit_long_octet;if (e.substr(l, 2) == \"01\") {\n    var h = j(e, l);if (h == \"00\") {\n      return g + \"BOOLEAN FALSE\\n\";\n    } else {\n      return g + \"BOOLEAN TRUE\\n\";\n    }\n  }if (e.substr(l, 2) == \"02\") {\n    var h = j(e, l);return g + \"INTEGER \" + q(h, x) + \"\\n\";\n  }if (e.substr(l, 2) == \"03\") {\n    var h = j(e, l);return g + \"BITSTRING \" + q(h, x) + \"\\n\";\n  }if (e.substr(l, 2) == \"04\") {\n    var h = j(e, l);if (p.isASN1HEX(h)) {\n      var k = g + \"OCTETSTRING, encapsulates\\n\";k = k + y(h, c, 0, g + \"  \");return k;\n    } else {\n      return g + \"OCTETSTRING \" + q(h, x) + \"\\n\";\n    }\n  }if (e.substr(l, 2) == \"05\") {\n    return g + \"NULL\\n\";\n  }if (e.substr(l, 2) == \"06\") {\n    var m = j(e, l);var a = KJUR.asn1.ASN1Util.oidHexToInt(m);var o = KJUR.asn1.x509.OID.oid2name(a);var b = a.replace(/\\./g, \" \");if (o != \"\") {\n      return g + \"ObjectIdentifier \" + o + \" (\" + b + \")\\n\";\n    } else {\n      return g + \"ObjectIdentifier (\" + b + \")\\n\";\n    }\n  }if (e.substr(l, 2) == \"0c\") {\n    return g + \"UTF8String '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"13\") {\n    return g + \"PrintableString '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"14\") {\n    return g + \"TeletexString '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"16\") {\n    return g + \"IA5String '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"17\") {\n    return g + \"UTCTime \" + hextoutf8(j(e, l)) + \"\\n\";\n  }if (e.substr(l, 2) == \"18\") {\n    return g + \"GeneralizedTime \" + hextoutf8(j(e, l)) + \"\\n\";\n  }if (e.substr(l, 2) == \"30\") {\n    if (e.substr(l, 4) == \"3000\") {\n      return g + \"SEQUENCE {}\\n\";\n    }var k = g + \"SEQUENCE\\n\";var d = w(e, l);var f = c;if ((d.length == 2 || d.length == 3) && e.substr(d[0], 2) == \"06\" && e.substr(d[d.length - 1], 2) == \"04\") {\n      var o = p.oidname(j(e, d[0]));var r = JSON.parse(JSON.stringify(c));r.x509ExtName = o;f = r;\n    }for (var u = 0; u < d.length; u++) {\n      k = k + y(e, f, d[u], g + \"  \");\n    }return k;\n  }if (e.substr(l, 2) == \"31\") {\n    var k = g + \"SET\\n\";var d = w(e, l);for (var u = 0; u < d.length; u++) {\n      k = k + y(e, c, d[u], g + \"  \");\n    }return k;\n  }var z = parseInt(e.substr(l, 2), 16);if ((z & 128) != 0) {\n    var n = z & 31;if ((z & 32) != 0) {\n      var k = g + \"[\" + n + \"]\\n\";var d = w(e, l);for (var u = 0; u < d.length; u++) {\n        k = k + y(e, c, d[u], g + \"  \");\n      }return k;\n    } else {\n      var h = j(e, l);if (h.substr(0, 8) == \"68747470\") {\n        h = hextoutf8(h);\n      }if (c.x509ExtName === \"subjectAltName\" && n == 2) {\n        h = hextoutf8(h);\n      }var k = g + \"[\" + n + \"] \" + h + \"\\n\";return k;\n    }\n  }return g + \"UNKNOWN(\" + e.substr(l, 2) + \") \" + j(e, l) + \"\\n\";\n};ASN1HEX.isASN1HEX = function (e) {\n  var d = ASN1HEX;if (e.length % 2 == 1) {\n    return false;\n  }var c = d.getVblen(e, 0);var b = e.substr(0, 2);var f = d.getL(e, 0);var a = e.length - b.length - f.length;if (a == c * 2) {\n    return true;\n  }return false;\n};ASN1HEX.oidname = function (a) {\n  var c = KJUR.asn1;if (KJUR.lang.String.isHex(a)) {\n    a = c.ASN1Util.oidHexToInt(a);\n  }var b = c.x509.OID.oid2name(a);if (b === \"\") {\n    b = a;\n  }return b;\n};\nvar KJUR;if (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.lang == \"undefined\" || !KJUR.lang) {\n  KJUR.lang = {};\n}KJUR.lang.String = function () {};function Base64x() {}function stoBA(d) {\n  var b = new Array();for (var c = 0; c < d.length; c++) {\n    b[c] = d.charCodeAt(c);\n  }return b;\n}function BAtos(b) {\n  var d = \"\";for (var c = 0; c < b.length; c++) {\n    d = d + String.fromCharCode(b[c]);\n  }return d;\n}function BAtohex(b) {\n  var e = \"\";for (var d = 0; d < b.length; d++) {\n    var c = b[d].toString(16);if (c.length == 1) {\n      c = \"0\" + c;\n    }e = e + c;\n  }return e;\n}function stohex(a) {\n  return BAtohex(stoBA(a));\n}function stob64(a) {\n  return hex2b64(stohex(a));\n}function stob64u(a) {\n  return b64tob64u(hex2b64(stohex(a)));\n}function b64utos(a) {\n  return BAtos(b64toBA(b64utob64(a)));\n}function b64tob64u(a) {\n  a = a.replace(/\\=/g, \"\");a = a.replace(/\\+/g, \"-\");a = a.replace(/\\//g, \"_\");return a;\n}function b64utob64(a) {\n  if (a.length % 4 == 2) {\n    a = a + \"==\";\n  } else {\n    if (a.length % 4 == 3) {\n      a = a + \"=\";\n    }\n  }a = a.replace(/-/g, \"+\");a = a.replace(/_/g, \"/\");return a;\n}function hextob64u(a) {\n  if (a.length % 2 == 1) {\n    a = \"0\" + a;\n  }return b64tob64u(hex2b64(a));\n}function b64utohex(a) {\n  return b64tohex(b64utob64(a));\n}var utf8tob64u, b64utoutf8;if (typeof Buffer === \"function\") {\n  exports.utf8tob64u = utf8tob64u = function utf8tob64u(a) {\n    return b64tob64u(new Buffer(a, \"utf8\").toString(\"base64\"));\n  };exports.b64utoutf8 = b64utoutf8 = function b64utoutf8(a) {\n    return new Buffer(b64utob64(a), \"base64\").toString(\"utf8\");\n  };\n} else {\n  exports.utf8tob64u = utf8tob64u = function utf8tob64u(a) {\n    return hextob64u(uricmptohex(encodeURIComponentAll(a)));\n  };exports.b64utoutf8 = b64utoutf8 = function b64utoutf8(a) {\n    return decodeURIComponent(hextouricmp(b64utohex(a)));\n  };\n}function utf8tob64(a) {\n  return hex2b64(uricmptohex(encodeURIComponentAll(a)));\n}function b64toutf8(a) {\n  return decodeURIComponent(hextouricmp(b64tohex(a)));\n}function utf8tohex(a) {\n  return uricmptohex(encodeURIComponentAll(a));\n}function hextoutf8(a) {\n  return decodeURIComponent(hextouricmp(a));\n}function hextorstr(c) {\n  var b = \"\";for (var a = 0; a < c.length - 1; a += 2) {\n    b += String.fromCharCode(parseInt(c.substr(a, 2), 16));\n  }return b;\n}function rstrtohex(c) {\n  var a = \"\";for (var b = 0; b < c.length; b++) {\n    a += (\"0\" + c.charCodeAt(b).toString(16)).slice(-2);\n  }return a;\n}function hextob64(a) {\n  return hex2b64(a);\n}function hextob64nl(b) {\n  var a = hextob64(b);var c = a.replace(/(.{64})/g, \"$1\\r\\n\");c = c.replace(/\\r\\n$/, \"\");return c;\n}function b64nltohex(b) {\n  var a = b.replace(/[^0-9A-Za-z\\/+=]*/g, \"\");var c = b64tohex(a);return c;\n}function hextopem(a, b) {\n  var c = hextob64nl(a);return \"-----BEGIN \" + b + \"-----\\r\\n\" + c + \"\\r\\n-----END \" + b + \"-----\\r\\n\";\n}function pemtohex(a, b) {\n  if (a.indexOf(\"-----BEGIN \") == -1) {\n    throw \"can't find PEM header: \" + b;\n  }if (b !== undefined) {\n    a = a.replace(\"-----BEGIN \" + b + \"-----\", \"\");a = a.replace(\"-----END \" + b + \"-----\", \"\");\n  } else {\n    a = a.replace(/-----BEGIN [^-]+-----/, \"\");a = a.replace(/-----END [^-]+-----/, \"\");\n  }return b64nltohex(a);\n}function hextoArrayBuffer(d) {\n  if (d.length % 2 != 0) {\n    throw \"input is not even length\";\n  }if (d.match(/^[0-9A-Fa-f]+$/) == null) {\n    throw \"input is not hexadecimal\";\n  }var b = new ArrayBuffer(d.length / 2);var a = new DataView(b);for (var c = 0; c < d.length / 2; c++) {\n    a.setUint8(c, parseInt(d.substr(c * 2, 2), 16));\n  }return b;\n}function ArrayBuffertohex(b) {\n  var d = \"\";var a = new DataView(b);for (var c = 0; c < b.byteLength; c++) {\n    d += (\"00\" + a.getUint8(c).toString(16)).slice(-2);\n  }return d;\n}function zulutomsec(n) {\n  var l, j, m, e, f, i, b, k;var a, h, g, c;c = n.match(/^(\\d{2}|\\d{4})(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(|\\.\\d+)Z$/);if (c) {\n    a = c[1];l = parseInt(a);if (a.length === 2) {\n      if (50 <= l && l < 100) {\n        l = 1900 + l;\n      } else {\n        if (0 <= l && l < 50) {\n          l = 2000 + l;\n        }\n      }\n    }j = parseInt(c[2]) - 1;m = parseInt(c[3]);e = parseInt(c[4]);f = parseInt(c[5]);i = parseInt(c[6]);b = 0;h = c[7];if (h !== \"\") {\n      g = (h.substr(1) + \"00\").substr(0, 3);b = parseInt(g);\n    }return Date.UTC(l, j, m, e, f, i, b);\n  }throw \"unsupported zulu format: \" + n;\n}function zulutosec(a) {\n  var b = zulutomsec(a);return ~~(b / 1000);\n}function zulutodate(a) {\n  return new Date(zulutomsec(a));\n}function datetozulu(g, e, f) {\n  var b;var a = g.getUTCFullYear();if (e) {\n    if (a < 1950 || 2049 < a) {\n      throw \"not proper year for UTCTime: \" + a;\n    }b = (\"\" + a).slice(-2);\n  } else {\n    b = (\"000\" + a).slice(-4);\n  }b += (\"0\" + (g.getUTCMonth() + 1)).slice(-2);b += (\"0\" + g.getUTCDate()).slice(-2);b += (\"0\" + g.getUTCHours()).slice(-2);b += (\"0\" + g.getUTCMinutes()).slice(-2);b += (\"0\" + g.getUTCSeconds()).slice(-2);if (f) {\n    var c = g.getUTCMilliseconds();if (c !== 0) {\n      c = (\"00\" + c).slice(-3);c = c.replace(/0+$/g, \"\");b += \".\" + c;\n    }\n  }b += \"Z\";return b;\n}function uricmptohex(a) {\n  return a.replace(/%/g, \"\");\n}function hextouricmp(a) {\n  return a.replace(/(..)/g, \"%$1\");\n}function ipv6tohex(g) {\n  var b = \"malformed IPv6 address\";if (!g.match(/^[0-9A-Fa-f:]+$/)) {\n    throw b;\n  }g = g.toLowerCase();var d = g.split(\":\").length - 1;if (d < 2) {\n    throw b;\n  }var e = \":\".repeat(7 - d + 2);g = g.replace(\"::\", e);var c = g.split(\":\");if (c.length != 8) {\n    throw b;\n  }for (var f = 0; f < 8; f++) {\n    c[f] = (\"0000\" + c[f]).slice(-4);\n  }return c.join(\"\");\n}function hextoipv6(e) {\n  if (!e.match(/^[0-9A-Fa-f]{32}$/)) {\n    throw \"malformed IPv6 address octet\";\n  }e = e.toLowerCase();var b = e.match(/.{1,4}/g);for (var d = 0; d < 8; d++) {\n    b[d] = b[d].replace(/^0+/, \"\");if (b[d] == \"\") {\n      b[d] = \"0\";\n    }\n  }e = \":\" + b.join(\":\") + \":\";var c = e.match(/:(0:){2,}/g);if (c === null) {\n    return e.slice(1, -1);\n  }var f = \"\";for (var d = 0; d < c.length; d++) {\n    if (c[d].length > f.length) {\n      f = c[d];\n    }\n  }e = e.replace(f, \"::\");return e.slice(1, -1);\n}function hextoip(b) {\n  var d = \"malformed hex value\";if (!b.match(/^([0-9A-Fa-f][0-9A-Fa-f]){1,}$/)) {\n    throw d;\n  }if (b.length == 8) {\n    var c;try {\n      c = parseInt(b.substr(0, 2), 16) + \".\" + parseInt(b.substr(2, 2), 16) + \".\" + parseInt(b.substr(4, 2), 16) + \".\" + parseInt(b.substr(6, 2), 16);return c;\n    } catch (a) {\n      throw d;\n    }\n  } else {\n    if (b.length == 32) {\n      return hextoipv6(b);\n    } else {\n      return b;\n    }\n  }\n}function iptohex(f) {\n  var j = \"malformed IP address\";f = f.toLowerCase(f);if (f.match(/^[0-9.]+$/)) {\n    var b = f.split(\".\");if (b.length !== 4) {\n      throw j;\n    }var g = \"\";try {\n      for (var e = 0; e < 4; e++) {\n        var h = parseInt(b[e]);g += (\"0\" + h.toString(16)).slice(-2);\n      }return g;\n    } catch (c) {\n      throw j;\n    }\n  } else {\n    if (f.match(/^[0-9a-f:]+$/) && f.indexOf(\":\") !== -1) {\n      return ipv6tohex(f);\n    } else {\n      throw j;\n    }\n  }\n}function encodeURIComponentAll(a) {\n  var d = encodeURIComponent(a);var b = \"\";for (var c = 0; c < d.length; c++) {\n    if (d[c] == \"%\") {\n      b = b + d.substr(c, 3);c = c + 2;\n    } else {\n      b = b + \"%\" + stohex(d[c]);\n    }\n  }return b;\n}function newline_toUnix(a) {\n  a = a.replace(/\\r\\n/mg, \"\\n\");return a;\n}function newline_toDos(a) {\n  a = a.replace(/\\r\\n/mg, \"\\n\");a = a.replace(/\\n/mg, \"\\r\\n\");return a;\n}KJUR.lang.String.isInteger = function (a) {\n  if (a.match(/^[0-9]+$/)) {\n    return true;\n  } else {\n    if (a.match(/^-[0-9]+$/)) {\n      return true;\n    } else {\n      return false;\n    }\n  }\n};KJUR.lang.String.isHex = function (a) {\n  if (a.length % 2 == 0 && (a.match(/^[0-9a-f]+$/) || a.match(/^[0-9A-F]+$/))) {\n    return true;\n  } else {\n    return false;\n  }\n};KJUR.lang.String.isBase64 = function (a) {\n  a = a.replace(/\\s+/g, \"\");if (a.match(/^[0-9A-Za-z+\\/]+={0,3}$/) && a.length % 4 == 0) {\n    return true;\n  } else {\n    return false;\n  }\n};KJUR.lang.String.isBase64URL = function (a) {\n  if (a.match(/[+/=]/)) {\n    return false;\n  }a = b64utob64(a);return KJUR.lang.String.isBase64(a);\n};KJUR.lang.String.isIntegerArray = function (a) {\n  a = a.replace(/\\s+/g, \"\");if (a.match(/^\\[[0-9,]+\\]$/)) {\n    return true;\n  } else {\n    return false;\n  }\n};function hextoposhex(a) {\n  if (a.length % 2 == 1) {\n    return \"0\" + a;\n  }if (a.substr(0, 1) > \"7\") {\n    return \"00\" + a;\n  }return a;\n}function intarystrtohex(b) {\n  b = b.replace(/^\\s*\\[\\s*/, \"\");b = b.replace(/\\s*\\]\\s*$/, \"\");b = b.replace(/\\s*/g, \"\");try {\n    var c = b.split(/,/).map(function (g, e, h) {\n      var f = parseInt(g);if (f < 0 || 255 < f) {\n        throw \"integer not in range 0-255\";\n      }var d = (\"00\" + f.toString(16)).slice(-2);return d;\n    }).join(\"\");return c;\n  } catch (a) {\n    throw \"malformed integer array string: \" + a;\n  }\n}var strdiffidx = function strdiffidx(c, a) {\n  var d = c.length;if (c.length > a.length) {\n    d = a.length;\n  }for (var b = 0; b < d; b++) {\n    if (c.charCodeAt(b) != a.charCodeAt(b)) {\n      return b;\n    }\n  }if (c.length != a.length) {\n    return d;\n  }return -1;\n};\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.crypto == \"undefined\" || !KJUR.crypto) {\n  KJUR.crypto = {};\n}KJUR.crypto.Util = new function () {\n  this.DIGESTINFOHEAD = { sha1: \"3021300906052b0e03021a05000414\", sha224: \"302d300d06096086480165030402040500041c\", sha256: \"3031300d060960864801650304020105000420\", sha384: \"3041300d060960864801650304020205000430\", sha512: \"3051300d060960864801650304020305000440\", md2: \"3020300c06082a864886f70d020205000410\", md5: \"3020300c06082a864886f70d020505000410\", ripemd160: \"3021300906052b2403020105000414\" };this.DEFAULTPROVIDER = { md5: \"cryptojs\", sha1: \"cryptojs\", sha224: \"cryptojs\", sha256: \"cryptojs\", sha384: \"cryptojs\", sha512: \"cryptojs\", ripemd160: \"cryptojs\", hmacmd5: \"cryptojs\", hmacsha1: \"cryptojs\", hmacsha224: \"cryptojs\", hmacsha256: \"cryptojs\", hmacsha384: \"cryptojs\", hmacsha512: \"cryptojs\", hmacripemd160: \"cryptojs\", MD5withRSA: \"cryptojs/jsrsa\", SHA1withRSA: \"cryptojs/jsrsa\", SHA224withRSA: \"cryptojs/jsrsa\", SHA256withRSA: \"cryptojs/jsrsa\", SHA384withRSA: \"cryptojs/jsrsa\", SHA512withRSA: \"cryptojs/jsrsa\", RIPEMD160withRSA: \"cryptojs/jsrsa\", MD5withECDSA: \"cryptojs/jsrsa\", SHA1withECDSA: \"cryptojs/jsrsa\", SHA224withECDSA: \"cryptojs/jsrsa\", SHA256withECDSA: \"cryptojs/jsrsa\", SHA384withECDSA: \"cryptojs/jsrsa\", SHA512withECDSA: \"cryptojs/jsrsa\", RIPEMD160withECDSA: \"cryptojs/jsrsa\", SHA1withDSA: \"cryptojs/jsrsa\", SHA224withDSA: \"cryptojs/jsrsa\", SHA256withDSA: \"cryptojs/jsrsa\", MD5withRSAandMGF1: \"cryptojs/jsrsa\", SHA1withRSAandMGF1: \"cryptojs/jsrsa\", SHA224withRSAandMGF1: \"cryptojs/jsrsa\", SHA256withRSAandMGF1: \"cryptojs/jsrsa\", SHA384withRSAandMGF1: \"cryptojs/jsrsa\", SHA512withRSAandMGF1: \"cryptojs/jsrsa\", RIPEMD160withRSAandMGF1: \"cryptojs/jsrsa\" };this.CRYPTOJSMESSAGEDIGESTNAME = { md5: CryptoJS.algo.MD5, sha1: CryptoJS.algo.SHA1, sha224: CryptoJS.algo.SHA224, sha256: CryptoJS.algo.SHA256, sha384: CryptoJS.algo.SHA384, sha512: CryptoJS.algo.SHA512, ripemd160: CryptoJS.algo.RIPEMD160 };this.getDigestInfoHex = function (a, b) {\n    if (typeof this.DIGESTINFOHEAD[b] == \"undefined\") {\n      throw \"alg not supported in Util.DIGESTINFOHEAD: \" + b;\n    }return this.DIGESTINFOHEAD[b] + a;\n  };this.getPaddedDigestInfoHex = function (h, a, j) {\n    var c = this.getDigestInfoHex(h, a);var d = j / 4;if (c.length + 22 > d) {\n      throw \"key is too short for SigAlg: keylen=\" + j + \",\" + a;\n    }var b = \"0001\";var k = \"00\" + c;var g = \"\";var l = d - b.length - k.length;for (var f = 0; f < l; f += 2) {\n      g += \"ff\";\n    }var e = b + g + k;return e;\n  };this.hashString = function (a, c) {\n    var b = new KJUR.crypto.MessageDigest({ alg: c });return b.digestString(a);\n  };this.hashHex = function (b, c) {\n    var a = new KJUR.crypto.MessageDigest({ alg: c });return a.digestHex(b);\n  };this.sha1 = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha1\", prov: \"cryptojs\" });return b.digestString(a);\n  };this.sha256 = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha256\", prov: \"cryptojs\" });return b.digestString(a);\n  };this.sha256Hex = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha256\", prov: \"cryptojs\" });return b.digestHex(a);\n  };this.sha512 = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha512\", prov: \"cryptojs\" });return b.digestString(a);\n  };this.sha512Hex = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha512\", prov: \"cryptojs\" });return b.digestHex(a);\n  };\n}();KJUR.crypto.Util.md5 = function (a) {\n  var b = new KJUR.crypto.MessageDigest({ alg: \"md5\", prov: \"cryptojs\" });return b.digestString(a);\n};KJUR.crypto.Util.ripemd160 = function (a) {\n  var b = new KJUR.crypto.MessageDigest({ alg: \"ripemd160\", prov: \"cryptojs\" });return b.digestString(a);\n};KJUR.crypto.Util.SECURERANDOMGEN = new SecureRandom();KJUR.crypto.Util.getRandomHexOfNbytes = function (b) {\n  var a = new Array(b);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(a);return BAtohex(a);\n};KJUR.crypto.Util.getRandomBigIntegerOfNbytes = function (a) {\n  return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbytes(a), 16);\n};KJUR.crypto.Util.getRandomHexOfNbits = function (d) {\n  var c = d % 8;var a = (d - c) / 8;var b = new Array(a + 1);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(b);b[0] = (255 << c & 255 ^ 255) & b[0];return BAtohex(b);\n};KJUR.crypto.Util.getRandomBigIntegerOfNbits = function (a) {\n  return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbits(a), 16);\n};KJUR.crypto.Util.getRandomBigIntegerZeroToMax = function (b) {\n  var a = b.bitLength();while (1) {\n    var c = KJUR.crypto.Util.getRandomBigIntegerOfNbits(a);if (b.compareTo(c) != -1) {\n      return c;\n    }\n  }\n};KJUR.crypto.Util.getRandomBigIntegerMinToMax = function (e, b) {\n  var c = e.compareTo(b);if (c == 1) {\n    throw \"biMin is greater than biMax\";\n  }if (c == 0) {\n    return e;\n  }var a = b.subtract(e);var d = KJUR.crypto.Util.getRandomBigIntegerZeroToMax(a);return d.add(e);\n};KJUR.crypto.MessageDigest = function (c) {\n  var b = null;var a = null;var d = null;this.setAlgAndProvider = function (g, f) {\n    g = KJUR.crypto.MessageDigest.getCanonicalAlgName(g);if (g !== null && f === undefined) {\n      f = KJUR.crypto.Util.DEFAULTPROVIDER[g];\n    }if (\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g) != -1 && f == \"cryptojs\") {\n      try {\n        this.md = KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g].create();\n      } catch (e) {\n        throw \"setAlgAndProvider hash alg set fail alg=\" + g + \"/\" + e;\n      }this.updateString = function (h) {\n        this.md.update(h);\n      };this.updateHex = function (h) {\n        var i = CryptoJS.enc.Hex.parse(h);this.md.update(i);\n      };this.digest = function () {\n        var h = this.md.finalize();return h.toString(CryptoJS.enc.Hex);\n      };this.digestString = function (h) {\n        this.updateString(h);return this.digest();\n      };this.digestHex = function (h) {\n        this.updateHex(h);return this.digest();\n      };\n    }if (\":sha256:\".indexOf(g) != -1 && f == \"sjcl\") {\n      try {\n        this.md = new sjcl.hash.sha256();\n      } catch (e) {\n        throw \"setAlgAndProvider hash alg set fail alg=\" + g + \"/\" + e;\n      }this.updateString = function (h) {\n        this.md.update(h);\n      };this.updateHex = function (i) {\n        var h = sjcl.codec.hex.toBits(i);this.md.update(h);\n      };this.digest = function () {\n        var h = this.md.finalize();return sjcl.codec.hex.fromBits(h);\n      };this.digestString = function (h) {\n        this.updateString(h);return this.digest();\n      };this.digestHex = function (h) {\n        this.updateHex(h);return this.digest();\n      };\n    }\n  };this.updateString = function (e) {\n    throw \"updateString(str) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.updateHex = function (e) {\n    throw \"updateHex(hex) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.digest = function () {\n    throw \"digest() not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.digestString = function (e) {\n    throw \"digestString(str) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.digestHex = function (e) {\n    throw \"digestHex(hex) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };if (c !== undefined) {\n    if (c.alg !== undefined) {\n      this.algName = c.alg;if (c.prov === undefined) {\n        this.provName = KJUR.crypto.Util.DEFAULTPROVIDER[this.algName];\n      }this.setAlgAndProvider(this.algName, this.provName);\n    }\n  }\n};KJUR.crypto.MessageDigest.getCanonicalAlgName = function (a) {\n  if (typeof a === \"string\") {\n    a = a.toLowerCase();a = a.replace(/-/, \"\");\n  }return a;\n};KJUR.crypto.MessageDigest.getHashLength = function (c) {\n  var b = KJUR.crypto.MessageDigest;var a = b.getCanonicalAlgName(c);if (b.HASHLENGTH[a] === undefined) {\n    throw \"not supported algorithm: \" + c;\n  }return b.HASHLENGTH[a];\n};KJUR.crypto.MessageDigest.HASHLENGTH = { md5: 16, sha1: 20, sha224: 28, sha256: 32, sha384: 48, sha512: 64, ripemd160: 20 };KJUR.crypto.Mac = function (d) {\n  var f = null;var c = null;var a = null;var e = null;var b = null;this.setAlgAndProvider = function (k, i) {\n    k = k.toLowerCase();if (k == null) {\n      k = \"hmacsha1\";\n    }k = k.toLowerCase();if (k.substr(0, 4) != \"hmac\") {\n      throw \"setAlgAndProvider unsupported HMAC alg: \" + k;\n    }if (i === undefined) {\n      i = KJUR.crypto.Util.DEFAULTPROVIDER[k];\n    }this.algProv = k + \"/\" + i;var g = k.substr(4);if (\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g) != -1 && i == \"cryptojs\") {\n      try {\n        var j = KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g];this.mac = CryptoJS.algo.HMAC.create(j, this.pass);\n      } catch (h) {\n        throw \"setAlgAndProvider hash alg set fail hashAlg=\" + g + \"/\" + h;\n      }this.updateString = function (l) {\n        this.mac.update(l);\n      };this.updateHex = function (l) {\n        var m = CryptoJS.enc.Hex.parse(l);this.mac.update(m);\n      };this.doFinal = function () {\n        var l = this.mac.finalize();return l.toString(CryptoJS.enc.Hex);\n      };this.doFinalString = function (l) {\n        this.updateString(l);return this.doFinal();\n      };this.doFinalHex = function (l) {\n        this.updateHex(l);return this.doFinal();\n      };\n    }\n  };this.updateString = function (g) {\n    throw \"updateString(str) not supported for this alg/prov: \" + this.algProv;\n  };this.updateHex = function (g) {\n    throw \"updateHex(hex) not supported for this alg/prov: \" + this.algProv;\n  };this.doFinal = function () {\n    throw \"digest() not supported for this alg/prov: \" + this.algProv;\n  };this.doFinalString = function (g) {\n    throw \"digestString(str) not supported for this alg/prov: \" + this.algProv;\n  };this.doFinalHex = function (g) {\n    throw \"digestHex(hex) not supported for this alg/prov: \" + this.algProv;\n  };this.setPassword = function (h) {\n    if (typeof h == \"string\") {\n      var g = h;if (h.length % 2 == 1 || !h.match(/^[0-9A-Fa-f]+$/)) {\n        g = rstrtohex(h);\n      }this.pass = CryptoJS.enc.Hex.parse(g);return;\n    }if ((typeof h === \"undefined\" ? \"undefined\" : _typeof(h)) != \"object\") {\n      throw \"KJUR.crypto.Mac unsupported password type: \" + h;\n    }var g = null;if (h.hex !== undefined) {\n      if (h.hex.length % 2 != 0 || !h.hex.match(/^[0-9A-Fa-f]+$/)) {\n        throw \"Mac: wrong hex password: \" + h.hex;\n      }g = h.hex;\n    }if (h.utf8 !== undefined) {\n      g = utf8tohex(h.utf8);\n    }if (h.rstr !== undefined) {\n      g = rstrtohex(h.rstr);\n    }if (h.b64 !== undefined) {\n      g = b64tohex(h.b64);\n    }if (h.b64u !== undefined) {\n      g = b64utohex(h.b64u);\n    }if (g == null) {\n      throw \"KJUR.crypto.Mac unsupported password type: \" + h;\n    }this.pass = CryptoJS.enc.Hex.parse(g);\n  };if (d !== undefined) {\n    if (d.pass !== undefined) {\n      this.setPassword(d.pass);\n    }if (d.alg !== undefined) {\n      this.algName = d.alg;if (d.prov === undefined) {\n        this.provName = KJUR.crypto.Util.DEFAULTPROVIDER[this.algName];\n      }this.setAlgAndProvider(this.algName, this.provName);\n    }\n  }\n};KJUR.crypto.Signature = function (o) {\n  var q = null;var n = null;var r = null;var c = null;var l = null;var d = null;var k = null;var h = null;var p = null;var e = null;var b = -1;var g = null;var j = null;var a = null;var i = null;var f = null;this._setAlgNames = function () {\n    var s = this.algName.match(/^(.+)with(.+)$/);if (s) {\n      this.mdAlgName = s[1].toLowerCase();this.pubkeyAlgName = s[2].toLowerCase();\n    }\n  };this._zeroPaddingOfSignature = function (x, w) {\n    var v = \"\";var t = w / 4 - x.length;for (var u = 0; u < t; u++) {\n      v = v + \"0\";\n    }return v + x;\n  };this.setAlgAndProvider = function (u, t) {\n    this._setAlgNames();if (t != \"cryptojs/jsrsa\") {\n      throw \"provider not supported: \" + t;\n    }if (\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(this.mdAlgName) != -1) {\n      try {\n        this.md = new KJUR.crypto.MessageDigest({ alg: this.mdAlgName });\n      } catch (s) {\n        throw \"setAlgAndProvider hash alg set fail alg=\" + this.mdAlgName + \"/\" + s;\n      }this.init = function (w, x) {\n        var y = null;try {\n          if (x === undefined) {\n            y = KEYUTIL.getKey(w);\n          } else {\n            y = KEYUTIL.getKey(w, x);\n          }\n        } catch (v) {\n          throw \"init failed:\" + v;\n        }if (y.isPrivate === true) {\n          this.prvKey = y;this.state = \"SIGN\";\n        } else {\n          if (y.isPublic === true) {\n            this.pubKey = y;this.state = \"VERIFY\";\n          } else {\n            throw \"init failed.:\" + y;\n          }\n        }\n      };this.updateString = function (v) {\n        this.md.updateString(v);\n      };this.updateHex = function (v) {\n        this.md.updateHex(v);\n      };this.sign = function () {\n        this.sHashHex = this.md.digest();if (typeof this.ecprvhex != \"undefined\" && typeof this.eccurvename != \"undefined\") {\n          var v = new KJUR.crypto.ECDSA({ curve: this.eccurvename });this.hSign = v.signHex(this.sHashHex, this.ecprvhex);\n        } else {\n          if (this.prvKey instanceof RSAKey && this.pubkeyAlgName === \"rsaandmgf1\") {\n            this.hSign = this.prvKey.signWithMessageHashPSS(this.sHashHex, this.mdAlgName, this.pssSaltLen);\n          } else {\n            if (this.prvKey instanceof RSAKey && this.pubkeyAlgName === \"rsa\") {\n              this.hSign = this.prvKey.signWithMessageHash(this.sHashHex, this.mdAlgName);\n            } else {\n              if (this.prvKey instanceof KJUR.crypto.ECDSA) {\n                this.hSign = this.prvKey.signWithMessageHash(this.sHashHex);\n              } else {\n                if (this.prvKey instanceof KJUR.crypto.DSA) {\n                  this.hSign = this.prvKey.signWithMessageHash(this.sHashHex);\n                } else {\n                  throw \"Signature: unsupported private key alg: \" + this.pubkeyAlgName;\n                }\n              }\n            }\n          }\n        }return this.hSign;\n      };this.signString = function (v) {\n        this.updateString(v);return this.sign();\n      };this.signHex = function (v) {\n        this.updateHex(v);return this.sign();\n      };this.verify = function (v) {\n        this.sHashHex = this.md.digest();if (typeof this.ecpubhex != \"undefined\" && typeof this.eccurvename != \"undefined\") {\n          var w = new KJUR.crypto.ECDSA({ curve: this.eccurvename });return w.verifyHex(this.sHashHex, v, this.ecpubhex);\n        } else {\n          if (this.pubKey instanceof RSAKey && this.pubkeyAlgName === \"rsaandmgf1\") {\n            return this.pubKey.verifyWithMessageHashPSS(this.sHashHex, v, this.mdAlgName, this.pssSaltLen);\n          } else {\n            if (this.pubKey instanceof RSAKey && this.pubkeyAlgName === \"rsa\") {\n              return this.pubKey.verifyWithMessageHash(this.sHashHex, v);\n            } else {\n              if (KJUR.crypto.ECDSA !== undefined && this.pubKey instanceof KJUR.crypto.ECDSA) {\n                return this.pubKey.verifyWithMessageHash(this.sHashHex, v);\n              } else {\n                if (KJUR.crypto.DSA !== undefined && this.pubKey instanceof KJUR.crypto.DSA) {\n                  return this.pubKey.verifyWithMessageHash(this.sHashHex, v);\n                } else {\n                  throw \"Signature: unsupported public key alg: \" + this.pubkeyAlgName;\n                }\n              }\n            }\n          }\n        }\n      };\n    }\n  };this.init = function (s, t) {\n    throw \"init(key, pass) not supported for this alg:prov=\" + this.algProvName;\n  };this.updateString = function (s) {\n    throw \"updateString(str) not supported for this alg:prov=\" + this.algProvName;\n  };this.updateHex = function (s) {\n    throw \"updateHex(hex) not supported for this alg:prov=\" + this.algProvName;\n  };this.sign = function () {\n    throw \"sign() not supported for this alg:prov=\" + this.algProvName;\n  };this.signString = function (s) {\n    throw \"digestString(str) not supported for this alg:prov=\" + this.algProvName;\n  };this.signHex = function (s) {\n    throw \"digestHex(hex) not supported for this alg:prov=\" + this.algProvName;\n  };this.verify = function (s) {\n    throw \"verify(hSigVal) not supported for this alg:prov=\" + this.algProvName;\n  };this.initParams = o;if (o !== undefined) {\n    if (o.alg !== undefined) {\n      this.algName = o.alg;if (o.prov === undefined) {\n        this.provName = KJUR.crypto.Util.DEFAULTPROVIDER[this.algName];\n      } else {\n        this.provName = o.prov;\n      }this.algProvName = this.algName + \":\" + this.provName;this.setAlgAndProvider(this.algName, this.provName);this._setAlgNames();\n    }if (o.psssaltlen !== undefined) {\n      this.pssSaltLen = o.psssaltlen;\n    }if (o.prvkeypem !== undefined) {\n      if (o.prvkeypas !== undefined) {\n        throw \"both prvkeypem and prvkeypas parameters not supported\";\n      } else {\n        try {\n          var q = KEYUTIL.getKey(o.prvkeypem);this.init(q);\n        } catch (m) {\n          throw \"fatal error to load pem private key: \" + m;\n        }\n      }\n    }\n  }\n};KJUR.crypto.Cipher = function (a) {};KJUR.crypto.Cipher.encrypt = function (e, f, d) {\n  if (f instanceof RSAKey && f.isPublic) {\n    var c = KJUR.crypto.Cipher.getAlgByKeyAndName(f, d);if (c === \"RSA\") {\n      return f.encrypt(e);\n    }if (c === \"RSAOAEP\") {\n      return f.encryptOAEP(e, \"sha1\");\n    }var b = c.match(/^RSAOAEP(\\d+)$/);if (b !== null) {\n      return f.encryptOAEP(e, \"sha\" + b[1]);\n    }throw \"Cipher.encrypt: unsupported algorithm for RSAKey: \" + d;\n  } else {\n    throw \"Cipher.encrypt: unsupported key or algorithm\";\n  }\n};KJUR.crypto.Cipher.decrypt = function (e, f, d) {\n  if (f instanceof RSAKey && f.isPrivate) {\n    var c = KJUR.crypto.Cipher.getAlgByKeyAndName(f, d);if (c === \"RSA\") {\n      return f.decrypt(e);\n    }if (c === \"RSAOAEP\") {\n      return f.decryptOAEP(e, \"sha1\");\n    }var b = c.match(/^RSAOAEP(\\d+)$/);if (b !== null) {\n      return f.decryptOAEP(e, \"sha\" + b[1]);\n    }throw \"Cipher.decrypt: unsupported algorithm for RSAKey: \" + d;\n  } else {\n    throw \"Cipher.decrypt: unsupported key or algorithm\";\n  }\n};KJUR.crypto.Cipher.getAlgByKeyAndName = function (b, a) {\n  if (b instanceof RSAKey) {\n    if (\":RSA:RSAOAEP:RSAOAEP224:RSAOAEP256:RSAOAEP384:RSAOAEP512:\".indexOf(a) != -1) {\n      return a;\n    }if (a === null || a === undefined) {\n      return \"RSA\";\n    }throw \"getAlgByKeyAndName: not supported algorithm name for RSAKey: \" + a;\n  }throw \"getAlgByKeyAndName: not supported algorithm name: \" + a;\n};KJUR.crypto.OID = new function () {\n  this.oidhex2name = { \"2a864886f70d010101\": \"rsaEncryption\", \"2a8648ce3d0201\": \"ecPublicKey\", \"2a8648ce380401\": \"dsa\", \"2a8648ce3d030107\": \"secp256r1\", \"2b8104001f\": \"secp192k1\", \"2b81040021\": \"secp224r1\", \"2b8104000a\": \"secp256k1\", \"2b81040023\": \"secp521r1\", \"2b81040022\": \"secp384r1\", \"2a8648ce380403\": \"SHA1withDSA\", \"608648016503040301\": \"SHA224withDSA\", \"608648016503040302\": \"SHA256withDSA\" };\n}();\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.crypto == \"undefined\" || !KJUR.crypto) {\n  KJUR.crypto = {};\n}KJUR.crypto.ECDSA = function (h) {\n  var e = \"secp256r1\";var g = null;var b = null;var f = null;var a = new SecureRandom();var d = null;this.type = \"EC\";this.isPrivate = false;this.isPublic = false;function c(s, o, r, n) {\n    var j = Math.max(o.bitLength(), n.bitLength());var t = s.add2D(r);var q = s.curve.getInfinity();for (var p = j - 1; p >= 0; --p) {\n      q = q.twice2D();q.z = BigInteger.ONE;if (o.testBit(p)) {\n        if (n.testBit(p)) {\n          q = q.add2D(t);\n        } else {\n          q = q.add2D(s);\n        }\n      } else {\n        if (n.testBit(p)) {\n          q = q.add2D(r);\n        }\n      }\n    }return q;\n  }this.getBigRandom = function (i) {\n    return new BigInteger(i.bitLength(), a).mod(i.subtract(BigInteger.ONE)).add(BigInteger.ONE);\n  };this.setNamedCurve = function (i) {\n    this.ecparams = KJUR.crypto.ECParameterDB.getByName(i);this.prvKeyHex = null;this.pubKeyHex = null;this.curveName = i;\n  };this.setPrivateKeyHex = function (i) {\n    this.isPrivate = true;this.prvKeyHex = i;\n  };this.setPublicKeyHex = function (i) {\n    this.isPublic = true;this.pubKeyHex = i;\n  };this.getPublicKeyXYHex = function () {\n    var k = this.pubKeyHex;if (k.substr(0, 2) !== \"04\") {\n      throw \"this method supports uncompressed format(04) only\";\n    }var j = this.ecparams.keylen / 4;if (k.length !== 2 + j * 2) {\n      throw \"malformed public key hex length\";\n    }var i = {};i.x = k.substr(2, j);i.y = k.substr(2 + j);return i;\n  };this.getShortNISTPCurveName = function () {\n    var i = this.curveName;if (i === \"secp256r1\" || i === \"NIST P-256\" || i === \"P-256\" || i === \"prime256v1\") {\n      return \"P-256\";\n    }if (i === \"secp384r1\" || i === \"NIST P-384\" || i === \"P-384\") {\n      return \"P-384\";\n    }return null;\n  };this.generateKeyPairHex = function () {\n    var k = this.ecparams.n;var n = this.getBigRandom(k);var l = this.ecparams.G.multiply(n);var q = l.getX().toBigInteger();var o = l.getY().toBigInteger();var i = this.ecparams.keylen / 4;var m = (\"0000000000\" + n.toString(16)).slice(-i);var r = (\"0000000000\" + q.toString(16)).slice(-i);var p = (\"0000000000\" + o.toString(16)).slice(-i);var j = \"04\" + r + p;this.setPrivateKeyHex(m);this.setPublicKeyHex(j);return { ecprvhex: m, ecpubhex: j };\n  };this.signWithMessageHash = function (i) {\n    return this.signHex(i, this.prvKeyHex);\n  };this.signHex = function (o, j) {\n    var t = new BigInteger(j, 16);var l = this.ecparams.n;var q = new BigInteger(o, 16);do {\n      var m = this.getBigRandom(l);var u = this.ecparams.G;var p = u.multiply(m);var i = p.getX().toBigInteger().mod(l);\n    } while (i.compareTo(BigInteger.ZERO) <= 0);var v = m.modInverse(l).multiply(q.add(t.multiply(i))).mod(l);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(i, v);\n  };this.sign = function (m, u) {\n    var q = u;var j = this.ecparams.n;var p = BigInteger.fromByteArrayUnsigned(m);do {\n      var l = this.getBigRandom(j);var t = this.ecparams.G;var o = t.multiply(l);var i = o.getX().toBigInteger().mod(j);\n    } while (i.compareTo(BigInteger.ZERO) <= 0);var v = l.modInverse(j).multiply(p.add(q.multiply(i))).mod(j);return this.serializeSig(i, v);\n  };this.verifyWithMessageHash = function (j, i) {\n    return this.verifyHex(j, i, this.pubKeyHex);\n  };this.verifyHex = function (m, i, p) {\n    var l, j;var o = KJUR.crypto.ECDSA.parseSigHex(i);l = o.r;j = o.s;var k;k = ECPointFp.decodeFromHex(this.ecparams.curve, p);var n = new BigInteger(m, 16);return this.verifyRaw(n, l, j, k);\n  };this.verify = function (o, p, j) {\n    var l, i;if (Bitcoin.Util.isArray(p)) {\n      var n = this.parseSig(p);l = n.r;i = n.s;\n    } else {\n      if (\"object\" === (typeof p === \"undefined\" ? \"undefined\" : _typeof(p)) && p.r && p.s) {\n        l = p.r;i = p.s;\n      } else {\n        throw \"Invalid value for signature\";\n      }\n    }var k;if (j instanceof ECPointFp) {\n      k = j;\n    } else {\n      if (Bitcoin.Util.isArray(j)) {\n        k = ECPointFp.decodeFrom(this.ecparams.curve, j);\n      } else {\n        throw \"Invalid format for pubkey value, must be byte array or ECPointFp\";\n      }\n    }var m = BigInteger.fromByteArrayUnsigned(o);return this.verifyRaw(m, l, i, k);\n  };this.verifyRaw = function (o, i, w, m) {\n    var l = this.ecparams.n;var u = this.ecparams.G;if (i.compareTo(BigInteger.ONE) < 0 || i.compareTo(l) >= 0) {\n      return false;\n    }if (w.compareTo(BigInteger.ONE) < 0 || w.compareTo(l) >= 0) {\n      return false;\n    }var p = w.modInverse(l);var k = o.multiply(p).mod(l);var j = i.multiply(p).mod(l);var q = u.multiply(k).add(m.multiply(j));var t = q.getX().toBigInteger().mod(l);return t.equals(i);\n  };this.serializeSig = function (k, j) {\n    var l = k.toByteArraySigned();var i = j.toByteArraySigned();var m = [];m.push(2);m.push(l.length);m = m.concat(l);m.push(2);m.push(i.length);m = m.concat(i);m.unshift(m.length);m.unshift(48);return m;\n  };this.parseSig = function (n) {\n    var m;if (n[0] != 48) {\n      throw new Error(\"Signature not a valid DERSequence\");\n    }m = 2;if (n[m] != 2) {\n      throw new Error(\"First element in signature must be a DERInteger\");\n    }var l = n.slice(m + 2, m + 2 + n[m + 1]);m += 2 + n[m + 1];if (n[m] != 2) {\n      throw new Error(\"Second element in signature must be a DERInteger\");\n    }var i = n.slice(m + 2, m + 2 + n[m + 1]);m += 2 + n[m + 1];var k = BigInteger.fromByteArrayUnsigned(l);var j = BigInteger.fromByteArrayUnsigned(i);return { r: k, s: j };\n  };this.parseSigCompact = function (m) {\n    if (m.length !== 65) {\n      throw \"Signature has the wrong length\";\n    }var j = m[0] - 27;if (j < 0 || j > 7) {\n      throw \"Invalid signature type\";\n    }var o = this.ecparams.n;var l = BigInteger.fromByteArrayUnsigned(m.slice(1, 33)).mod(o);var k = BigInteger.fromByteArrayUnsigned(m.slice(33, 65)).mod(o);return { r: l, s: k, i: j };\n  };this.readPKCS5PrvKeyHex = function (l) {\n    var n = ASN1HEX;var m = KJUR.crypto.ECDSA.getName;var p = n.getVbyList;if (n.isASN1HEX(l) === false) {\n      throw \"not ASN.1 hex string\";\n    }var i, k, o;try {\n      i = p(l, 0, [2, 0], \"06\");k = p(l, 0, [1], \"04\");try {\n        o = p(l, 0, [3, 0], \"03\").substr(2);\n      } catch (j) {}\n    } catch (j) {\n      throw \"malformed PKCS#1/5 plain ECC private key\";\n    }this.curveName = m(i);if (this.curveName === undefined) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(o);this.setPrivateKeyHex(k);this.isPublic = false;\n  };this.readPKCS8PrvKeyHex = function (l) {\n    var q = ASN1HEX;var i = KJUR.crypto.ECDSA.getName;var n = q.getVbyList;if (q.isASN1HEX(l) === false) {\n      throw \"not ASN.1 hex string\";\n    }var j, p, m, k;try {\n      j = n(l, 0, [1, 0], \"06\");p = n(l, 0, [1, 1], \"06\");m = n(l, 0, [2, 0, 1], \"04\");try {\n        k = n(l, 0, [2, 0, 2, 0], \"03\").substr(2);\n      } catch (o) {}\n    } catch (o) {\n      throw \"malformed PKCS#8 plain ECC private key\";\n    }this.curveName = i(p);if (this.curveName === undefined) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(k);this.setPrivateKeyHex(m);this.isPublic = false;\n  };this.readPKCS8PubKeyHex = function (l) {\n    var n = ASN1HEX;var m = KJUR.crypto.ECDSA.getName;var p = n.getVbyList;if (n.isASN1HEX(l) === false) {\n      throw \"not ASN.1 hex string\";\n    }var k, i, o;try {\n      k = p(l, 0, [0, 0], \"06\");i = p(l, 0, [0, 1], \"06\");o = p(l, 0, [1], \"03\").substr(2);\n    } catch (j) {\n      throw \"malformed PKCS#8 ECC public key\";\n    }this.curveName = m(i);if (this.curveName === null) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(o);\n  };this.readCertPubKeyHex = function (k, p) {\n    if (p !== 5) {\n      p = 6;\n    }var m = ASN1HEX;var l = KJUR.crypto.ECDSA.getName;var o = m.getVbyList;if (m.isASN1HEX(k) === false) {\n      throw \"not ASN.1 hex string\";\n    }var i, n;try {\n      i = o(k, 0, [0, p, 0, 1], \"06\");n = o(k, 0, [0, p, 1], \"03\").substr(2);\n    } catch (j) {\n      throw \"malformed X.509 certificate ECC public key\";\n    }this.curveName = l(i);if (this.curveName === null) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(n);\n  };if (h !== undefined) {\n    if (h.curve !== undefined) {\n      this.curveName = h.curve;\n    }\n  }if (this.curveName === undefined) {\n    this.curveName = e;\n  }this.setNamedCurve(this.curveName);if (h !== undefined) {\n    if (h.prv !== undefined) {\n      this.setPrivateKeyHex(h.prv);\n    }if (h.pub !== undefined) {\n      this.setPublicKeyHex(h.pub);\n    }\n  }\n};KJUR.crypto.ECDSA.parseSigHex = function (a) {\n  var b = KJUR.crypto.ECDSA.parseSigHexInHexRS(a);var d = new BigInteger(b.r, 16);var c = new BigInteger(b.s, 16);return { r: d, s: c };\n};KJUR.crypto.ECDSA.parseSigHexInHexRS = function (f) {\n  var j = ASN1HEX;var i = j.getChildIdx;var g = j.getV;if (f.substr(0, 2) != \"30\") {\n    throw \"signature is not a ASN.1 sequence\";\n  }var h = i(f, 0);if (h.length != 2) {\n    throw \"number of signature ASN.1 sequence elements seem wrong\";\n  }var e = h[0];var d = h[1];if (f.substr(e, 2) != \"02\") {\n    throw \"1st item of sequene of signature is not ASN.1 integer\";\n  }if (f.substr(d, 2) != \"02\") {\n    throw \"2nd item of sequene of signature is not ASN.1 integer\";\n  }var c = g(f, e);var b = g(f, d);return { r: c, s: b };\n};KJUR.crypto.ECDSA.asn1SigToConcatSig = function (c) {\n  var d = KJUR.crypto.ECDSA.parseSigHexInHexRS(c);var b = d.r;var a = d.s;if (b.substr(0, 2) == \"00\" && b.length % 32 == 2) {\n    b = b.substr(2);\n  }if (a.substr(0, 2) == \"00\" && a.length % 32 == 2) {\n    a = a.substr(2);\n  }if (b.length % 32 == 30) {\n    b = \"00\" + b;\n  }if (a.length % 32 == 30) {\n    a = \"00\" + a;\n  }if (b.length % 32 != 0) {\n    throw \"unknown ECDSA sig r length error\";\n  }if (a.length % 32 != 0) {\n    throw \"unknown ECDSA sig s length error\";\n  }return b + a;\n};KJUR.crypto.ECDSA.concatSigToASN1Sig = function (a) {\n  if (a.length / 2 * 8 % (16 * 8) != 0) {\n    throw \"unknown ECDSA concatinated r-s sig  length error\";\n  }var c = a.substr(0, a.length / 2);var b = a.substr(a.length / 2);return KJUR.crypto.ECDSA.hexRSSigToASN1Sig(c, b);\n};KJUR.crypto.ECDSA.hexRSSigToASN1Sig = function (b, a) {\n  var d = new BigInteger(b, 16);var c = new BigInteger(a, 16);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(d, c);\n};KJUR.crypto.ECDSA.biRSSigToASN1Sig = function (f, d) {\n  var c = KJUR.asn1;var b = new c.DERInteger({ bigint: f });var a = new c.DERInteger({ bigint: d });var e = new c.DERSequence({ array: [b, a] });return e.getEncodedHex();\n};KJUR.crypto.ECDSA.getName = function (a) {\n  if (a === \"2a8648ce3d030107\") {\n    return \"secp256r1\";\n  }if (a === \"2b8104000a\") {\n    return \"secp256k1\";\n  }if (a === \"2b81040022\") {\n    return \"secp384r1\";\n  }if (\"|secp256r1|NIST P-256|P-256|prime256v1|\".indexOf(a) !== -1) {\n    return \"secp256r1\";\n  }if (\"|secp256k1|\".indexOf(a) !== -1) {\n    return \"secp256k1\";\n  }if (\"|secp384r1|NIST P-384|P-384|\".indexOf(a) !== -1) {\n    return \"secp384r1\";\n  }return null;\n};\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.crypto == \"undefined\" || !KJUR.crypto) {\n  KJUR.crypto = {};\n}KJUR.crypto.ECParameterDB = new function () {\n  var b = {};var c = {};function a(d) {\n    return new BigInteger(d, 16);\n  }this.getByName = function (e) {\n    var d = e;if (typeof c[d] != \"undefined\") {\n      d = c[e];\n    }if (typeof b[d] != \"undefined\") {\n      return b[d];\n    }throw \"unregistered EC curve name: \" + d;\n  };this.regist = function (A, l, o, g, m, e, j, f, k, u, d, x) {\n    b[A] = {};var s = a(o);var z = a(g);var y = a(m);var t = a(e);var w = a(j);var r = new ECCurveFp(s, z, y);var q = r.decodePointHex(\"04\" + f + k);b[A][\"name\"] = A;b[A][\"keylen\"] = l;b[A][\"curve\"] = r;b[A][\"G\"] = q;b[A][\"n\"] = t;b[A][\"h\"] = w;b[A][\"oid\"] = d;b[A][\"info\"] = x;for (var v = 0; v < u.length; v++) {\n      c[u[v]] = A;\n    }\n  };\n}();KJUR.crypto.ECParameterDB.regist(\"secp128r1\", 128, \"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF\", \"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFC\", \"E87579C11079F43DD824993C2CEE5ED3\", \"FFFFFFFE0000000075A30D1B9038A115\", \"1\", \"161FF7528B899B2D0C28607CA52C5B86\", \"CF5AC8395BAFEB13C02DA292DDED7A83\", [], \"\", \"secp128r1 : SECG curve over a 128 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160k1\", 160, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73\", \"0\", \"7\", \"0100000000000000000001B8FA16DFAB9ACA16B6B3\", \"1\", \"3B4C382CE37AA192A4019E763036F4F5DD4D7EBB\", \"938CF935318FDCED6BC28286531733C3F03C4FEE\", [], \"\", \"secp160k1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160r1\", 160, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFC\", \"1C97BEFC54BD7A8B65ACF89F81D4D4ADC565FA45\", \"0100000000000000000001F4C8F927AED3CA752257\", \"1\", \"4A96B5688EF573284664698968C38BB913CBFC82\", \"23A628553168947D59DCC912042351377AC5FB32\", [], \"\", \"secp160r1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp192k1\", 192, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFEE37\", \"0\", \"3\", \"FFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D\", \"1\", \"DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D\", \"9B2F2F6D9C5628A7844163D015BE86344082AA88D95E2F9D\", []);KJUR.crypto.ECParameterDB.regist(\"secp192r1\", 192, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC\", \"64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1\", \"FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831\", \"1\", \"188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012\", \"07192B95FFC8DA78631011ED6B24CDD573F977A11E794811\", []);KJUR.crypto.ECParameterDB.regist(\"secp224r1\", 224, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE\", \"B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D\", \"1\", \"B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21\", \"BD376388B5F723FB4C22DFE6CD4375A05A07476444D5819985007E34\", []);KJUR.crypto.ECParameterDB.regist(\"secp256k1\", 256, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F\", \"0\", \"7\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141\", \"1\", \"79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798\", \"483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8\", []);KJUR.crypto.ECParameterDB.regist(\"secp256r1\", 256, \"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF\", \"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFC\", \"5AC635D8AA3A93E7B3EBBD55769886BC651D06B0CC53B0F63BCE3C3E27D2604B\", \"FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551\", \"1\", \"6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296\", \"4FE342E2FE1A7F9B8EE7EB4A7C0F9E162BCE33576B315ECECBB6406837BF51F5\", [\"NIST P-256\", \"P-256\", \"prime256v1\"]);KJUR.crypto.ECParameterDB.regist(\"secp384r1\", 384, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFC\", \"B3312FA7E23EE7E4988E056BE3F82D19181D9C6EFE8141120314088F5013875AC656398D8A2ED19D2A85C8EDD3EC2AEF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973\", \"1\", \"AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7\", \"3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5f\", [\"NIST P-384\", \"P-384\"]);KJUR.crypto.ECParameterDB.regist(\"secp521r1\", 521, \"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF\", \"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC\", \"051953EB9618E1C9A1F929A21A0B68540EEA2DA725B99B315F3B8B489918EF109E156193951EC7E937B1652C0BD3BB1BF073573DF883D2C34F1EF451FD46B503F00\", \"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA51868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409\", \"1\", \"C6858E06B70404E9CD9E3ECB662395B4429C648139053FB521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66\", \"011839296a789a3bc0045c8a5fb42c7d1bd998f54449579b446817afbd17273e662c97ee72995ef42640c550b9013fad0761353c7086a272c24088be94769fd16650\", [\"NIST P-521\", \"P-521\"]);\nvar KEYUTIL = function () {\n  var d = function d(p, r, q) {\n    return k(CryptoJS.AES, p, r, q);\n  };var e = function e(p, r, q) {\n    return k(CryptoJS.TripleDES, p, r, q);\n  };var a = function a(p, r, q) {\n    return k(CryptoJS.DES, p, r, q);\n  };var k = function k(s, x, u, q) {\n    var r = CryptoJS.enc.Hex.parse(x);var w = CryptoJS.enc.Hex.parse(u);var p = CryptoJS.enc.Hex.parse(q);var t = {};t.key = w;t.iv = p;t.ciphertext = r;var v = s.decrypt(t, w, { iv: p });return CryptoJS.enc.Hex.stringify(v);\n  };var l = function l(p, r, q) {\n    return g(CryptoJS.AES, p, r, q);\n  };var o = function o(p, r, q) {\n    return g(CryptoJS.TripleDES, p, r, q);\n  };var f = function f(p, r, q) {\n    return g(CryptoJS.DES, p, r, q);\n  };var g = function g(t, y, v, q) {\n    var s = CryptoJS.enc.Hex.parse(y);var x = CryptoJS.enc.Hex.parse(v);var p = CryptoJS.enc.Hex.parse(q);var w = t.encrypt(s, x, { iv: p });var r = CryptoJS.enc.Hex.parse(w.toString());var u = CryptoJS.enc.Base64.stringify(r);return u;\n  };var i = { \"AES-256-CBC\": { proc: d, eproc: l, keylen: 32, ivlen: 16 }, \"AES-192-CBC\": { proc: d, eproc: l, keylen: 24, ivlen: 16 }, \"AES-128-CBC\": { proc: d, eproc: l, keylen: 16, ivlen: 16 }, \"DES-EDE3-CBC\": { proc: e, eproc: o, keylen: 24, ivlen: 8 }, \"DES-CBC\": { proc: a, eproc: f, keylen: 8, ivlen: 8 } };var c = function c(p) {\n    return i[p][\"proc\"];\n  };var m = function m(p) {\n    var r = CryptoJS.lib.WordArray.random(p);var q = CryptoJS.enc.Hex.stringify(r);return q;\n  };var n = function n(v) {\n    var w = {};var q = v.match(new RegExp(\"DEK-Info: ([^,]+),([0-9A-Fa-f]+)\", \"m\"));if (q) {\n      w.cipher = q[1];w.ivsalt = q[2];\n    }var p = v.match(new RegExp(\"-----BEGIN ([A-Z]+) PRIVATE KEY-----\"));if (p) {\n      w.type = p[1];\n    }var u = -1;var x = 0;if (v.indexOf(\"\\r\\n\\r\\n\") != -1) {\n      u = v.indexOf(\"\\r\\n\\r\\n\");x = 2;\n    }if (v.indexOf(\"\\n\\n\") != -1) {\n      u = v.indexOf(\"\\n\\n\");x = 1;\n    }var t = v.indexOf(\"-----END\");if (u != -1 && t != -1) {\n      var r = v.substring(u + x * 2, t - x);r = r.replace(/\\s+/g, \"\");w.data = r;\n    }return w;\n  };var j = function j(q, y, p) {\n    var v = p.substring(0, 16);var t = CryptoJS.enc.Hex.parse(v);var r = CryptoJS.enc.Utf8.parse(y);var u = i[q][\"keylen\"] + i[q][\"ivlen\"];var x = \"\";var w = null;for (;;) {\n      var s = CryptoJS.algo.MD5.create();if (w != null) {\n        s.update(w);\n      }s.update(r);s.update(t);w = s.finalize();x = x + CryptoJS.enc.Hex.stringify(w);if (x.length >= u * 2) {\n        break;\n      }\n    }var z = {};z.keyhex = x.substr(0, i[q][\"keylen\"] * 2);z.ivhex = x.substr(i[q][\"keylen\"] * 2, i[q][\"ivlen\"] * 2);return z;\n  };var b = function b(p, v, r, w) {\n    var s = CryptoJS.enc.Base64.parse(p);var q = CryptoJS.enc.Hex.stringify(s);var u = i[v][\"proc\"];var t = u(q, r, w);return t;\n  };var h = function h(p, s, q, u) {\n    var r = i[s][\"eproc\"];var t = r(p, q, u);return t;\n  };return { version: \"1.0.0\", parsePKCS5PEM: function parsePKCS5PEM(p) {\n      return n(p);\n    }, getKeyAndUnusedIvByPasscodeAndIvsalt: function getKeyAndUnusedIvByPasscodeAndIvsalt(q, p, r) {\n      return j(q, p, r);\n    }, decryptKeyB64: function decryptKeyB64(p, r, q, s) {\n      return b(p, r, q, s);\n    }, getDecryptedKeyHex: function getDecryptedKeyHex(y, x) {\n      var q = n(y);var t = q.type;var r = q.cipher;var p = q.ivsalt;var s = q.data;var w = j(r, x, p);var v = w.keyhex;var u = b(s, r, v, p);return u;\n    }, getEncryptedPKCS5PEMFromPrvKeyHex: function getEncryptedPKCS5PEMFromPrvKeyHex(x, s, A, t, r) {\n      var p = \"\";if (typeof t == \"undefined\" || t == null) {\n        t = \"AES-256-CBC\";\n      }if (typeof i[t] == \"undefined\") {\n        throw \"KEYUTIL unsupported algorithm: \" + t;\n      }if (typeof r == \"undefined\" || r == null) {\n        var v = i[t][\"ivlen\"];var u = m(v);r = u.toUpperCase();\n      }var z = j(t, A, r);var y = z.keyhex;var w = h(s, t, y, r);var q = w.replace(/(.{64})/g, \"$1\\r\\n\");var p = \"-----BEGIN \" + x + \" PRIVATE KEY-----\\r\\n\";p += \"Proc-Type: 4,ENCRYPTED\\r\\n\";p += \"DEK-Info: \" + t + \",\" + r + \"\\r\\n\";p += \"\\r\\n\";p += q;p += \"\\r\\n-----END \" + x + \" PRIVATE KEY-----\\r\\n\";return p;\n    }, parseHexOfEncryptedPKCS8: function parseHexOfEncryptedPKCS8(y) {\n      var B = ASN1HEX;var z = B.getChildIdx;var w = B.getV;var t = {};var r = z(y, 0);if (r.length != 2) {\n        throw \"malformed format: SEQUENCE(0).items != 2: \" + r.length;\n      }t.ciphertext = w(y, r[1]);var A = z(y, r[0]);if (A.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0).items != 2: \" + A.length;\n      }if (w(y, A[0]) != \"2a864886f70d01050d\") {\n        throw \"this only supports pkcs5PBES2\";\n      }var p = z(y, A[1]);if (A.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0.1).items != 2: \" + p.length;\n      }var q = z(y, p[1]);if (q.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0.1.1).items != 2: \" + q.length;\n      }if (w(y, q[0]) != \"2a864886f70d0307\") {\n        throw \"this only supports TripleDES\";\n      }t.encryptionSchemeAlg = \"TripleDES\";t.encryptionSchemeIV = w(y, q[1]);var s = z(y, p[0]);if (s.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0.1.0).items != 2: \" + s.length;\n      }if (w(y, s[0]) != \"2a864886f70d01050c\") {\n        throw \"this only supports pkcs5PBKDF2\";\n      }var x = z(y, s[1]);if (x.length < 2) {\n        throw \"malformed format: SEQUENCE(0.0.1.0.1).items < 2: \" + x.length;\n      }t.pbkdf2Salt = w(y, x[0]);var u = w(y, x[1]);try {\n        t.pbkdf2Iter = parseInt(u, 16);\n      } catch (v) {\n        throw \"malformed format pbkdf2Iter: \" + u;\n      }return t;\n    }, getPBKDF2KeyHexFromParam: function getPBKDF2KeyHexFromParam(u, p) {\n      var t = CryptoJS.enc.Hex.parse(u.pbkdf2Salt);var q = u.pbkdf2Iter;var s = CryptoJS.PBKDF2(p, t, { keySize: 192 / 32, iterations: q });var r = CryptoJS.enc.Hex.stringify(s);return r;\n    }, _getPlainPKCS8HexFromEncryptedPKCS8PEM: function _getPlainPKCS8HexFromEncryptedPKCS8PEM(x, y) {\n      var r = pemtohex(x, \"ENCRYPTED PRIVATE KEY\");var p = this.parseHexOfEncryptedPKCS8(r);var u = KEYUTIL.getPBKDF2KeyHexFromParam(p, y);var v = {};v.ciphertext = CryptoJS.enc.Hex.parse(p.ciphertext);var t = CryptoJS.enc.Hex.parse(u);var s = CryptoJS.enc.Hex.parse(p.encryptionSchemeIV);var w = CryptoJS.TripleDES.decrypt(v, t, { iv: s });var q = CryptoJS.enc.Hex.stringify(w);return q;\n    }, getKeyFromEncryptedPKCS8PEM: function getKeyFromEncryptedPKCS8PEM(s, q) {\n      var p = this._getPlainPKCS8HexFromEncryptedPKCS8PEM(s, q);var r = this.getKeyFromPlainPrivatePKCS8Hex(p);return r;\n    }, parsePlainPrivatePKCS8Hex: function parsePlainPrivatePKCS8Hex(s) {\n      var v = ASN1HEX;var u = v.getChildIdx;var t = v.getV;var q = {};q.algparam = null;if (s.substr(0, 2) != \"30\") {\n        throw \"malformed plain PKCS8 private key(code:001)\";\n      }var r = u(s, 0);if (r.length != 3) {\n        throw \"malformed plain PKCS8 private key(code:002)\";\n      }if (s.substr(r[1], 2) != \"30\") {\n        throw \"malformed PKCS8 private key(code:003)\";\n      }var p = u(s, r[1]);if (p.length != 2) {\n        throw \"malformed PKCS8 private key(code:004)\";\n      }if (s.substr(p[0], 2) != \"06\") {\n        throw \"malformed PKCS8 private key(code:005)\";\n      }q.algoid = t(s, p[0]);if (s.substr(p[1], 2) == \"06\") {\n        q.algparam = t(s, p[1]);\n      }if (s.substr(r[2], 2) != \"04\") {\n        throw \"malformed PKCS8 private key(code:006)\";\n      }q.keyidx = v.getVidx(s, r[2]);return q;\n    }, getKeyFromPlainPrivatePKCS8PEM: function getKeyFromPlainPrivatePKCS8PEM(q) {\n      var p = pemtohex(q, \"PRIVATE KEY\");var r = this.getKeyFromPlainPrivatePKCS8Hex(p);return r;\n    }, getKeyFromPlainPrivatePKCS8Hex: function getKeyFromPlainPrivatePKCS8Hex(p) {\n      var q = this.parsePlainPrivatePKCS8Hex(p);var r;if (q.algoid == \"2a864886f70d010101\") {\n        r = new RSAKey();\n      } else {\n        if (q.algoid == \"2a8648ce380401\") {\n          r = new KJUR.crypto.DSA();\n        } else {\n          if (q.algoid == \"2a8648ce3d0201\") {\n            r = new KJUR.crypto.ECDSA();\n          } else {\n            throw \"unsupported private key algorithm\";\n          }\n        }\n      }r.readPKCS8PrvKeyHex(p);return r;\n    }, _getKeyFromPublicPKCS8Hex: function _getKeyFromPublicPKCS8Hex(q) {\n      var p;var r = ASN1HEX.getVbyList(q, 0, [0, 0], \"06\");if (r === \"2a864886f70d010101\") {\n        p = new RSAKey();\n      } else {\n        if (r === \"2a8648ce380401\") {\n          p = new KJUR.crypto.DSA();\n        } else {\n          if (r === \"2a8648ce3d0201\") {\n            p = new KJUR.crypto.ECDSA();\n          } else {\n            throw \"unsupported PKCS#8 public key hex\";\n          }\n        }\n      }p.readPKCS8PubKeyHex(q);return p;\n    }, parsePublicRawRSAKeyHex: function parsePublicRawRSAKeyHex(r) {\n      var u = ASN1HEX;var t = u.getChildIdx;var s = u.getV;var p = {};if (r.substr(0, 2) != \"30\") {\n        throw \"malformed RSA key(code:001)\";\n      }var q = t(r, 0);if (q.length != 2) {\n        throw \"malformed RSA key(code:002)\";\n      }if (r.substr(q[0], 2) != \"02\") {\n        throw \"malformed RSA key(code:003)\";\n      }p.n = s(r, q[0]);if (r.substr(q[1], 2) != \"02\") {\n        throw \"malformed RSA key(code:004)\";\n      }p.e = s(r, q[1]);return p;\n    }, parsePublicPKCS8Hex: function parsePublicPKCS8Hex(t) {\n      var v = ASN1HEX;var u = v.getChildIdx;var s = v.getV;var q = {};q.algparam = null;var r = u(t, 0);if (r.length != 2) {\n        throw \"outer DERSequence shall have 2 elements: \" + r.length;\n      }var w = r[0];if (t.substr(w, 2) != \"30\") {\n        throw \"malformed PKCS8 public key(code:001)\";\n      }var p = u(t, w);if (p.length != 2) {\n        throw \"malformed PKCS8 public key(code:002)\";\n      }if (t.substr(p[0], 2) != \"06\") {\n        throw \"malformed PKCS8 public key(code:003)\";\n      }q.algoid = s(t, p[0]);if (t.substr(p[1], 2) == \"06\") {\n        q.algparam = s(t, p[1]);\n      } else {\n        if (t.substr(p[1], 2) == \"30\") {\n          q.algparam = {};q.algparam.p = v.getVbyList(t, p[1], [0], \"02\");q.algparam.q = v.getVbyList(t, p[1], [1], \"02\");q.algparam.g = v.getVbyList(t, p[1], [2], \"02\");\n        }\n      }if (t.substr(r[1], 2) != \"03\") {\n        throw \"malformed PKCS8 public key(code:004)\";\n      }q.key = s(t, r[1]).substr(2);return q;\n    } };\n}();KEYUTIL.getKey = function (l, k, n) {\n  var G = ASN1HEX,\n      L = G.getChildIdx,\n      v = G.getV,\n      d = G.getVbyList,\n      c = KJUR.crypto,\n      i = c.ECDSA,\n      C = c.DSA,\n      w = RSAKey,\n      M = pemtohex,\n      F = KEYUTIL;if (typeof w != \"undefined\" && l instanceof w) {\n    return l;\n  }if (typeof i != \"undefined\" && l instanceof i) {\n    return l;\n  }if (typeof C != \"undefined\" && l instanceof C) {\n    return l;\n  }if (l.curve !== undefined && l.xy !== undefined && l.d === undefined) {\n    return new i({ pub: l.xy, curve: l.curve });\n  }if (l.curve !== undefined && l.d !== undefined) {\n    return new i({ prv: l.d, curve: l.curve });\n  }if (l.kty === undefined && l.n !== undefined && l.e !== undefined && l.d === undefined) {\n    var P = new w();P.setPublic(l.n, l.e);return P;\n  }if (l.kty === undefined && l.n !== undefined && l.e !== undefined && l.d !== undefined && l.p !== undefined && l.q !== undefined && l.dp !== undefined && l.dq !== undefined && l.co !== undefined && l.qi === undefined) {\n    var P = new w();P.setPrivateEx(l.n, l.e, l.d, l.p, l.q, l.dp, l.dq, l.co);return P;\n  }if (l.kty === undefined && l.n !== undefined && l.e !== undefined && l.d !== undefined && l.p === undefined) {\n    var P = new w();P.setPrivate(l.n, l.e, l.d);return P;\n  }if (l.p !== undefined && l.q !== undefined && l.g !== undefined && l.y !== undefined && l.x === undefined) {\n    var P = new C();P.setPublic(l.p, l.q, l.g, l.y);return P;\n  }if (l.p !== undefined && l.q !== undefined && l.g !== undefined && l.y !== undefined && l.x !== undefined) {\n    var P = new C();P.setPrivate(l.p, l.q, l.g, l.y, l.x);return P;\n  }if (l.kty === \"RSA\" && l.n !== undefined && l.e !== undefined && l.d === undefined) {\n    var P = new w();P.setPublic(b64utohex(l.n), b64utohex(l.e));return P;\n  }if (l.kty === \"RSA\" && l.n !== undefined && l.e !== undefined && l.d !== undefined && l.p !== undefined && l.q !== undefined && l.dp !== undefined && l.dq !== undefined && l.qi !== undefined) {\n    var P = new w();P.setPrivateEx(b64utohex(l.n), b64utohex(l.e), b64utohex(l.d), b64utohex(l.p), b64utohex(l.q), b64utohex(l.dp), b64utohex(l.dq), b64utohex(l.qi));return P;\n  }if (l.kty === \"RSA\" && l.n !== undefined && l.e !== undefined && l.d !== undefined) {\n    var P = new w();P.setPrivate(b64utohex(l.n), b64utohex(l.e), b64utohex(l.d));return P;\n  }if (l.kty === \"EC\" && l.crv !== undefined && l.x !== undefined && l.y !== undefined && l.d === undefined) {\n    var j = new i({ curve: l.crv });var t = j.ecparams.keylen / 4;var B = (\"0000000000\" + b64utohex(l.x)).slice(-t);var z = (\"0000000000\" + b64utohex(l.y)).slice(-t);var u = \"04\" + B + z;j.setPublicKeyHex(u);return j;\n  }if (l.kty === \"EC\" && l.crv !== undefined && l.x !== undefined && l.y !== undefined && l.d !== undefined) {\n    var j = new i({ curve: l.crv });var t = j.ecparams.keylen / 4;var B = (\"0000000000\" + b64utohex(l.x)).slice(-t);var z = (\"0000000000\" + b64utohex(l.y)).slice(-t);var u = \"04\" + B + z;var b = (\"0000000000\" + b64utohex(l.d)).slice(-t);j.setPublicKeyHex(u);j.setPrivateKeyHex(b);return j;\n  }if (n === \"pkcs5prv\") {\n    var J = l,\n        G = ASN1HEX,\n        N,\n        P;N = L(J, 0);if (N.length === 9) {\n      P = new w();P.readPKCS5PrvKeyHex(J);\n    } else {\n      if (N.length === 6) {\n        P = new C();P.readPKCS5PrvKeyHex(J);\n      } else {\n        if (N.length > 2 && J.substr(N[1], 2) === \"04\") {\n          P = new i();P.readPKCS5PrvKeyHex(J);\n        } else {\n          throw \"unsupported PKCS#1/5 hexadecimal key\";\n        }\n      }\n    }return P;\n  }if (n === \"pkcs8prv\") {\n    var P = F.getKeyFromPlainPrivatePKCS8Hex(l);return P;\n  }if (n === \"pkcs8pub\") {\n    return F._getKeyFromPublicPKCS8Hex(l);\n  }if (n === \"x509pub\") {\n    return X509.getPublicKeyFromCertHex(l);\n  }if (l.indexOf(\"-END CERTIFICATE-\", 0) != -1 || l.indexOf(\"-END X509 CERTIFICATE-\", 0) != -1 || l.indexOf(\"-END TRUSTED CERTIFICATE-\", 0) != -1) {\n    return X509.getPublicKeyFromCertPEM(l);\n  }if (l.indexOf(\"-END PUBLIC KEY-\") != -1) {\n    var O = pemtohex(l, \"PUBLIC KEY\");return F._getKeyFromPublicPKCS8Hex(O);\n  }if (l.indexOf(\"-END RSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") == -1) {\n    var m = M(l, \"RSA PRIVATE KEY\");return F.getKey(m, null, \"pkcs5prv\");\n  }if (l.indexOf(\"-END DSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") == -1) {\n    var I = M(l, \"DSA PRIVATE KEY\");var E = d(I, 0, [1], \"02\");var D = d(I, 0, [2], \"02\");var K = d(I, 0, [3], \"02\");var r = d(I, 0, [4], \"02\");var s = d(I, 0, [5], \"02\");var P = new C();P.setPrivate(new BigInteger(E, 16), new BigInteger(D, 16), new BigInteger(K, 16), new BigInteger(r, 16), new BigInteger(s, 16));return P;\n  }if (l.indexOf(\"-END PRIVATE KEY-\") != -1) {\n    return F.getKeyFromPlainPrivatePKCS8PEM(l);\n  }if (l.indexOf(\"-END RSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") != -1) {\n    var o = F.getDecryptedKeyHex(l, k);var H = new RSAKey();H.readPKCS5PrvKeyHex(o);return H;\n  }if (l.indexOf(\"-END EC PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") != -1) {\n    var I = F.getDecryptedKeyHex(l, k);var P = d(I, 0, [1], \"04\");var f = d(I, 0, [2, 0], \"06\");var A = d(I, 0, [3, 0], \"03\").substr(2);var e = \"\";if (KJUR.crypto.OID.oidhex2name[f] !== undefined) {\n      e = KJUR.crypto.OID.oidhex2name[f];\n    } else {\n      throw \"undefined OID(hex) in KJUR.crypto.OID: \" + f;\n    }var j = new i({ curve: e });j.setPublicKeyHex(A);j.setPrivateKeyHex(P);j.isPublic = false;return j;\n  }if (l.indexOf(\"-END DSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") != -1) {\n    var I = F.getDecryptedKeyHex(l, k);var E = d(I, 0, [1], \"02\");var D = d(I, 0, [2], \"02\");var K = d(I, 0, [3], \"02\");var r = d(I, 0, [4], \"02\");var s = d(I, 0, [5], \"02\");var P = new C();P.setPrivate(new BigInteger(E, 16), new BigInteger(D, 16), new BigInteger(K, 16), new BigInteger(r, 16), new BigInteger(s, 16));return P;\n  }if (l.indexOf(\"-END ENCRYPTED PRIVATE KEY-\") != -1) {\n    return F.getKeyFromEncryptedPKCS8PEM(l, k);\n  }throw \"not supported argument\";\n};KEYUTIL.generateKeypair = function (a, c) {\n  if (a == \"RSA\") {\n    var b = c;var h = new RSAKey();h.generate(b, \"10001\");h.isPrivate = true;h.isPublic = true;var f = new RSAKey();var e = h.n.toString(16);var i = h.e.toString(16);f.setPublic(e, i);f.isPrivate = false;f.isPublic = true;var k = {};k.prvKeyObj = h;k.pubKeyObj = f;return k;\n  } else {\n    if (a == \"EC\") {\n      var d = c;var g = new KJUR.crypto.ECDSA({ curve: d });var j = g.generateKeyPairHex();var h = new KJUR.crypto.ECDSA({ curve: d });h.setPublicKeyHex(j.ecpubhex);h.setPrivateKeyHex(j.ecprvhex);h.isPrivate = true;h.isPublic = false;var f = new KJUR.crypto.ECDSA({ curve: d });f.setPublicKeyHex(j.ecpubhex);f.isPrivate = false;f.isPublic = true;var k = {};k.prvKeyObj = h;k.pubKeyObj = f;return k;\n    } else {\n      throw \"unknown algorithm: \" + a;\n    }\n  }\n};KEYUTIL.getPEM = function (b, D, y, m, q, j) {\n  var F = KJUR,\n      k = F.asn1,\n      z = k.DERObjectIdentifier,\n      f = k.DERInteger,\n      l = k.ASN1Util.newObject,\n      a = k.x509,\n      C = a.SubjectPublicKeyInfo,\n      e = F.crypto,\n      u = e.DSA,\n      r = e.ECDSA,\n      n = RSAKey;function A(s) {\n    var G = l({ seq: [{ \"int\": 0 }, { \"int\": { bigint: s.n } }, { \"int\": s.e }, { \"int\": { bigint: s.d } }, { \"int\": { bigint: s.p } }, { \"int\": { bigint: s.q } }, { \"int\": { bigint: s.dmp1 } }, { \"int\": { bigint: s.dmq1 } }, { \"int\": { bigint: s.coeff } }] });return G;\n  }function B(G) {\n    var s = l({ seq: [{ \"int\": 1 }, { octstr: { hex: G.prvKeyHex } }, { tag: [\"a0\", true, { oid: { name: G.curveName } }] }, { tag: [\"a1\", true, { bitstr: { hex: \"00\" + G.pubKeyHex } }] }] });return s;\n  }function x(s) {\n    var G = l({ seq: [{ \"int\": 0 }, { \"int\": { bigint: s.p } }, { \"int\": { bigint: s.q } }, { \"int\": { bigint: s.g } }, { \"int\": { bigint: s.y } }, { \"int\": { bigint: s.x } }] });return G;\n  }if ((n !== undefined && b instanceof n || u !== undefined && b instanceof u || r !== undefined && b instanceof r) && b.isPublic == true && (D === undefined || D == \"PKCS8PUB\")) {\n    var E = new C(b);var w = E.getEncodedHex();return hextopem(w, \"PUBLIC KEY\");\n  }if (D == \"PKCS1PRV\" && n !== undefined && b instanceof n && (y === undefined || y == null) && b.isPrivate == true) {\n    var E = A(b);var w = E.getEncodedHex();return hextopem(w, \"RSA PRIVATE KEY\");\n  }if (D == \"PKCS1PRV\" && r !== undefined && b instanceof r && (y === undefined || y == null) && b.isPrivate == true) {\n    var i = new z({ name: b.curveName });var v = i.getEncodedHex();var h = B(b);var t = h.getEncodedHex();var p = \"\";p += hextopem(v, \"EC PARAMETERS\");p += hextopem(t, \"EC PRIVATE KEY\");return p;\n  }if (D == \"PKCS1PRV\" && u !== undefined && b instanceof u && (y === undefined || y == null) && b.isPrivate == true) {\n    var E = x(b);var w = E.getEncodedHex();return hextopem(w, \"DSA PRIVATE KEY\");\n  }if (D == \"PKCS5PRV\" && n !== undefined && b instanceof n && y !== undefined && y != null && b.isPrivate == true) {\n    var E = A(b);var w = E.getEncodedHex();if (m === undefined) {\n      m = \"DES-EDE3-CBC\";\n    }return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"RSA\", w, y, m, j);\n  }if (D == \"PKCS5PRV\" && r !== undefined && b instanceof r && y !== undefined && y != null && b.isPrivate == true) {\n    var E = B(b);var w = E.getEncodedHex();if (m === undefined) {\n      m = \"DES-EDE3-CBC\";\n    }return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"EC\", w, y, m, j);\n  }if (D == \"PKCS5PRV\" && u !== undefined && b instanceof u && y !== undefined && y != null && b.isPrivate == true) {\n    var E = x(b);var w = E.getEncodedHex();if (m === undefined) {\n      m = \"DES-EDE3-CBC\";\n    }return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"DSA\", w, y, m, j);\n  }var o = function o(G, s) {\n    var I = c(G, s);var H = new l({ seq: [{ seq: [{ oid: { name: \"pkcs5PBES2\" } }, { seq: [{ seq: [{ oid: { name: \"pkcs5PBKDF2\" } }, { seq: [{ octstr: { hex: I.pbkdf2Salt } }, { \"int\": I.pbkdf2Iter }] }] }, { seq: [{ oid: { name: \"des-EDE3-CBC\" } }, { octstr: { hex: I.encryptionSchemeIV } }] }] }] }, { octstr: { hex: I.ciphertext } }] });return H.getEncodedHex();\n  };var c = function c(N, O) {\n    var H = 100;var M = CryptoJS.lib.WordArray.random(8);var L = \"DES-EDE3-CBC\";var s = CryptoJS.lib.WordArray.random(8);var I = CryptoJS.PBKDF2(O, M, { keySize: 192 / 32, iterations: H });var J = CryptoJS.enc.Hex.parse(N);var K = CryptoJS.TripleDES.encrypt(J, I, { iv: s }) + \"\";var G = {};G.ciphertext = K;G.pbkdf2Salt = CryptoJS.enc.Hex.stringify(M);G.pbkdf2Iter = H;G.encryptionSchemeAlg = L;G.encryptionSchemeIV = CryptoJS.enc.Hex.stringify(s);return G;\n  };if (D == \"PKCS8PRV\" && n != undefined && b instanceof n && b.isPrivate == true) {\n    var g = A(b);var d = g.getEncodedHex();var E = l({ seq: [{ \"int\": 0 }, { seq: [{ oid: { name: \"rsaEncryption\" } }, { \"null\": true }] }, { octstr: { hex: d } }] });var w = E.getEncodedHex();if (y === undefined || y == null) {\n      return hextopem(w, \"PRIVATE KEY\");\n    } else {\n      var t = o(w, y);return hextopem(t, \"ENCRYPTED PRIVATE KEY\");\n    }\n  }if (D == \"PKCS8PRV\" && r !== undefined && b instanceof r && b.isPrivate == true) {\n    var g = new l({ seq: [{ \"int\": 1 }, { octstr: { hex: b.prvKeyHex } }, { tag: [\"a1\", true, { bitstr: { hex: \"00\" + b.pubKeyHex } }] }] });var d = g.getEncodedHex();var E = l({ seq: [{ \"int\": 0 }, { seq: [{ oid: { name: \"ecPublicKey\" } }, { oid: { name: b.curveName } }] }, { octstr: { hex: d } }] });var w = E.getEncodedHex();if (y === undefined || y == null) {\n      return hextopem(w, \"PRIVATE KEY\");\n    } else {\n      var t = o(w, y);return hextopem(t, \"ENCRYPTED PRIVATE KEY\");\n    }\n  }if (D == \"PKCS8PRV\" && u !== undefined && b instanceof u && b.isPrivate == true) {\n    var g = new f({ bigint: b.x });var d = g.getEncodedHex();var E = l({ seq: [{ \"int\": 0 }, { seq: [{ oid: { name: \"dsa\" } }, { seq: [{ \"int\": { bigint: b.p } }, { \"int\": { bigint: b.q } }, { \"int\": { bigint: b.g } }] }] }, { octstr: { hex: d } }] });var w = E.getEncodedHex();if (y === undefined || y == null) {\n      return hextopem(w, \"PRIVATE KEY\");\n    } else {\n      var t = o(w, y);return hextopem(t, \"ENCRYPTED PRIVATE KEY\");\n    }\n  }throw \"unsupported object nor format\";\n};KEYUTIL.getKeyFromCSRPEM = function (b) {\n  var a = pemtohex(b, \"CERTIFICATE REQUEST\");var c = KEYUTIL.getKeyFromCSRHex(a);return c;\n};KEYUTIL.getKeyFromCSRHex = function (a) {\n  var c = KEYUTIL.parseCSRHex(a);var b = KEYUTIL.getKey(c.p8pubkeyhex, null, \"pkcs8pub\");return b;\n};KEYUTIL.parseCSRHex = function (d) {\n  var i = ASN1HEX;var f = i.getChildIdx;var c = i.getTLV;var b = {};var g = d;if (g.substr(0, 2) != \"30\") {\n    throw \"malformed CSR(code:001)\";\n  }var e = f(g, 0);if (e.length < 1) {\n    throw \"malformed CSR(code:002)\";\n  }if (g.substr(e[0], 2) != \"30\") {\n    throw \"malformed CSR(code:003)\";\n  }var a = f(g, e[0]);if (a.length < 3) {\n    throw \"malformed CSR(code:004)\";\n  }b.p8pubkeyhex = c(g, a[2]);return b;\n};KEYUTIL.getJWKFromKey = function (d) {\n  var b = {};if (d instanceof RSAKey && d.isPrivate) {\n    b.kty = \"RSA\";b.n = hextob64u(d.n.toString(16));b.e = hextob64u(d.e.toString(16));b.d = hextob64u(d.d.toString(16));b.p = hextob64u(d.p.toString(16));b.q = hextob64u(d.q.toString(16));b.dp = hextob64u(d.dmp1.toString(16));b.dq = hextob64u(d.dmq1.toString(16));b.qi = hextob64u(d.coeff.toString(16));return b;\n  } else {\n    if (d instanceof RSAKey && d.isPublic) {\n      b.kty = \"RSA\";b.n = hextob64u(d.n.toString(16));b.e = hextob64u(d.e.toString(16));return b;\n    } else {\n      if (d instanceof KJUR.crypto.ECDSA && d.isPrivate) {\n        var a = d.getShortNISTPCurveName();if (a !== \"P-256\" && a !== \"P-384\") {\n          throw \"unsupported curve name for JWT: \" + a;\n        }var c = d.getPublicKeyXYHex();b.kty = \"EC\";b.crv = a;b.x = hextob64u(c.x);b.y = hextob64u(c.y);b.d = hextob64u(d.prvKeyHex);return b;\n      } else {\n        if (d instanceof KJUR.crypto.ECDSA && d.isPublic) {\n          var a = d.getShortNISTPCurveName();if (a !== \"P-256\" && a !== \"P-384\") {\n            throw \"unsupported curve name for JWT: \" + a;\n          }var c = d.getPublicKeyXYHex();b.kty = \"EC\";b.crv = a;b.x = hextob64u(c.x);b.y = hextob64u(c.y);return b;\n        }\n      }\n    }\n  }throw \"not supported key object\";\n};\nRSAKey.getPosArrayOfChildrenFromHex = function (a) {\n  return ASN1HEX.getChildIdx(a, 0);\n};RSAKey.getHexValueArrayOfChildrenFromHex = function (f) {\n  var n = ASN1HEX;var i = n.getV;var k = RSAKey.getPosArrayOfChildrenFromHex(f);var e = i(f, k[0]);var j = i(f, k[1]);var b = i(f, k[2]);var c = i(f, k[3]);var h = i(f, k[4]);var g = i(f, k[5]);var m = i(f, k[6]);var l = i(f, k[7]);var d = i(f, k[8]);var k = new Array();k.push(e, j, b, c, h, g, m, l, d);return k;\n};RSAKey.prototype.readPrivateKeyFromPEMString = function (d) {\n  var c = pemtohex(d);var b = RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1], b[2], b[3], b[4], b[5], b[6], b[7], b[8]);\n};RSAKey.prototype.readPKCS5PrvKeyHex = function (c) {\n  var b = RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1], b[2], b[3], b[4], b[5], b[6], b[7], b[8]);\n};RSAKey.prototype.readPKCS8PrvKeyHex = function (e) {\n  var c, j, l, b, a, f, d, k;var m = ASN1HEX;var g = m.getVbyList;if (m.isASN1HEX(e) === false) {\n    throw \"not ASN.1 hex string\";\n  }try {\n    c = g(e, 0, [2, 0, 1], \"02\");j = g(e, 0, [2, 0, 2], \"02\");l = g(e, 0, [2, 0, 3], \"02\");b = g(e, 0, [2, 0, 4], \"02\");a = g(e, 0, [2, 0, 5], \"02\");f = g(e, 0, [2, 0, 6], \"02\");d = g(e, 0, [2, 0, 7], \"02\");k = g(e, 0, [2, 0, 8], \"02\");\n  } catch (i) {\n    throw \"malformed PKCS#8 plain RSA private key\";\n  }this.setPrivateEx(c, j, l, b, a, f, d, k);\n};RSAKey.prototype.readPKCS5PubKeyHex = function (c) {\n  var e = ASN1HEX;var b = e.getV;if (e.isASN1HEX(c) === false) {\n    throw \"keyHex is not ASN.1 hex string\";\n  }var a = e.getChildIdx(c, 0);if (a.length !== 2 || c.substr(a[0], 2) !== \"02\" || c.substr(a[1], 2) !== \"02\") {\n    throw \"wrong hex for PKCS#5 public key\";\n  }var f = b(c, a[0]);var d = b(c, a[1]);this.setPublic(f, d);\n};RSAKey.prototype.readPKCS8PubKeyHex = function (b) {\n  var c = ASN1HEX;if (c.isASN1HEX(b) === false) {\n    throw \"not ASN.1 hex string\";\n  }if (c.getTLVbyList(b, 0, [0, 0]) !== \"06092a864886f70d010101\") {\n    throw \"not PKCS8 RSA public key\";\n  }var a = c.getTLVbyList(b, 0, [1, 0]);this.readPKCS5PubKeyHex(a);\n};RSAKey.prototype.readCertPubKeyHex = function (b, d) {\n  var a, c;a = new X509();a.readCertHex(b);c = a.getPublicKeyHex();this.readPKCS8PubKeyHex(c);\n};\nvar _RE_HEXDECONLY = new RegExp(\"\");_RE_HEXDECONLY.compile(\"[^0-9a-f]\", \"gi\");function _rsasign_getHexPaddedDigestInfoForString(d, e, a) {\n  var b = function b(f) {\n    return KJUR.crypto.Util.hashString(f, a);\n  };var c = b(d);return KJUR.crypto.Util.getPaddedDigestInfoHex(c, a, e);\n}function _zeroPaddingOfSignature(e, d) {\n  var c = \"\";var a = d / 4 - e.length;for (var b = 0; b < a; b++) {\n    c = c + \"0\";\n  }return c + e;\n}RSAKey.prototype.sign = function (d, a) {\n  var b = function b(e) {\n    return KJUR.crypto.Util.hashString(e, a);\n  };var c = b(d);return this.signWithMessageHash(c, a);\n};RSAKey.prototype.signWithMessageHash = function (e, c) {\n  var f = KJUR.crypto.Util.getPaddedDigestInfoHex(e, c, this.n.bitLength());var b = parseBigInt(f, 16);var d = this.doPrivate(b);var a = d.toString(16);return _zeroPaddingOfSignature(a, this.n.bitLength());\n};function pss_mgf1_str(c, a, e) {\n  var b = \"\",\n      d = 0;while (b.length < a) {\n    b += hextorstr(e(rstrtohex(c + String.fromCharCode.apply(String, [(d & 4278190080) >> 24, (d & 16711680) >> 16, (d & 65280) >> 8, d & 255]))));d += 1;\n  }return b;\n}RSAKey.prototype.signPSS = function (e, a, d) {\n  var c = function c(f) {\n    return KJUR.crypto.Util.hashHex(f, a);\n  };var b = c(rstrtohex(e));if (d === undefined) {\n    d = -1;\n  }return this.signWithMessageHashPSS(b, a, d);\n};RSAKey.prototype.signWithMessageHashPSS = function (l, a, k) {\n  var b = hextorstr(l);var g = b.length;var m = this.n.bitLength() - 1;var c = Math.ceil(m / 8);var d;var o = function o(i) {\n    return KJUR.crypto.Util.hashHex(i, a);\n  };if (k === -1 || k === undefined) {\n    k = g;\n  } else {\n    if (k === -2) {\n      k = c - g - 2;\n    } else {\n      if (k < -2) {\n        throw \"invalid salt length\";\n      }\n    }\n  }if (c < g + k + 2) {\n    throw \"data too long\";\n  }var f = \"\";if (k > 0) {\n    f = new Array(k);new SecureRandom().nextBytes(f);f = String.fromCharCode.apply(String, f);\n  }var n = hextorstr(o(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" + b + f)));var j = [];for (d = 0; d < c - k - g - 2; d += 1) {\n    j[d] = 0;\n  }var e = String.fromCharCode.apply(String, j) + \"\\x01\" + f;var h = pss_mgf1_str(n, e.length, o);var q = [];for (d = 0; d < e.length; d += 1) {\n    q[d] = e.charCodeAt(d) ^ h.charCodeAt(d);\n  }var p = 65280 >> 8 * c - m & 255;q[0] &= ~p;for (d = 0; d < g; d++) {\n    q.push(n.charCodeAt(d));\n  }q.push(188);return _zeroPaddingOfSignature(this.doPrivate(new BigInteger(q)).toString(16), this.n.bitLength());\n};function _rsasign_getDecryptSignatureBI(a, d, c) {\n  var b = new RSAKey();b.setPublic(d, c);var e = b.doPublic(a);return e;\n}function _rsasign_getHexDigestInfoFromSig(a, c, b) {\n  var e = _rsasign_getDecryptSignatureBI(a, c, b);var d = e.toString(16).replace(/^1f+00/, \"\");return d;\n}function _rsasign_getAlgNameAndHashFromHexDisgestInfo(f) {\n  for (var e in KJUR.crypto.Util.DIGESTINFOHEAD) {\n    var d = KJUR.crypto.Util.DIGESTINFOHEAD[e];var b = d.length;if (f.substring(0, b) == d) {\n      var c = [e, f.substring(b)];return c;\n    }\n  }return [];\n}RSAKey.prototype.verify = function (f, j) {\n  j = j.replace(_RE_HEXDECONLY, \"\");j = j.replace(/[ \\n]+/g, \"\");var b = parseBigInt(j, 16);if (b.bitLength() > this.n.bitLength()) {\n    return 0;\n  }var i = this.doPublic(b);var e = i.toString(16).replace(/^1f+00/, \"\");var g = _rsasign_getAlgNameAndHashFromHexDisgestInfo(e);if (g.length == 0) {\n    return false;\n  }var d = g[0];var h = g[1];var a = function a(k) {\n    return KJUR.crypto.Util.hashString(k, d);\n  };var c = a(f);return h == c;\n};RSAKey.prototype.verifyWithMessageHash = function (e, a) {\n  a = a.replace(_RE_HEXDECONLY, \"\");a = a.replace(/[ \\n]+/g, \"\");var b = parseBigInt(a, 16);if (b.bitLength() > this.n.bitLength()) {\n    return 0;\n  }var h = this.doPublic(b);var g = h.toString(16).replace(/^1f+00/, \"\");var c = _rsasign_getAlgNameAndHashFromHexDisgestInfo(g);if (c.length == 0) {\n    return false;\n  }var d = c[0];var f = c[1];return f == e;\n};RSAKey.prototype.verifyPSS = function (c, b, a, f) {\n  var e = function e(g) {\n    return KJUR.crypto.Util.hashHex(g, a);\n  };var d = e(rstrtohex(c));if (f === undefined) {\n    f = -1;\n  }return this.verifyWithMessageHashPSS(d, b, a, f);\n};RSAKey.prototype.verifyWithMessageHashPSS = function (f, s, l, c) {\n  var k = new BigInteger(s, 16);if (k.bitLength() > this.n.bitLength()) {\n    return false;\n  }var r = function r(i) {\n    return KJUR.crypto.Util.hashHex(i, l);\n  };var j = hextorstr(f);var h = j.length;var g = this.n.bitLength() - 1;var m = Math.ceil(g / 8);var q;if (c === -1 || c === undefined) {\n    c = h;\n  } else {\n    if (c === -2) {\n      c = m - h - 2;\n    } else {\n      if (c < -2) {\n        throw \"invalid salt length\";\n      }\n    }\n  }if (m < h + c + 2) {\n    throw \"data too long\";\n  }var a = this.doPublic(k).toByteArray();for (q = 0; q < a.length; q += 1) {\n    a[q] &= 255;\n  }while (a.length < m) {\n    a.unshift(0);\n  }if (a[m - 1] !== 188) {\n    throw \"encoded message does not end in 0xbc\";\n  }a = String.fromCharCode.apply(String, a);var d = a.substr(0, m - h - 1);var e = a.substr(d.length, h);var p = 65280 >> 8 * m - g & 255;if ((d.charCodeAt(0) & p) !== 0) {\n    throw \"bits beyond keysize not zero\";\n  }var n = pss_mgf1_str(e, d.length, r);var o = [];for (q = 0; q < d.length; q += 1) {\n    o[q] = d.charCodeAt(q) ^ n.charCodeAt(q);\n  }o[0] &= ~p;var b = m - h - c - 2;for (q = 0; q < b; q += 1) {\n    if (o[q] !== 0) {\n      throw \"leftmost octets not zero\";\n    }\n  }if (o[b] !== 1) {\n    throw \"0x01 marker not found\";\n  }return e === hextorstr(r(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" + j + String.fromCharCode.apply(String, o.slice(-c)))));\n};RSAKey.SALT_LEN_HLEN = -1;RSAKey.SALT_LEN_MAX = -2;RSAKey.SALT_LEN_RECOVER = -2;\nfunction X509() {\n  var k = ASN1HEX,\n      j = k.getChildIdx,\n      h = k.getV,\n      b = k.getTLV,\n      f = k.getVbyList,\n      c = k.getTLVbyList,\n      g = k.getIdxbyList,\n      d = k.getVidx,\n      i = k.oidname,\n      a = X509,\n      e = pemtohex;this.hex = null;this.version = 0;this.foffset = 0;this.aExtInfo = null;this.getVersion = function () {\n    if (this.hex === null || this.version !== 0) {\n      return this.version;\n    }if (c(this.hex, 0, [0, 0]) !== \"a003020102\") {\n      this.version = 1;this.foffset = -1;return 1;\n    }this.version = 3;return 3;\n  };this.getSerialNumberHex = function () {\n    return f(this.hex, 0, [0, 1 + this.foffset], \"02\");\n  };this.getSignatureAlgorithmField = function () {\n    return i(f(this.hex, 0, [0, 2 + this.foffset, 0], \"06\"));\n  };this.getIssuerHex = function () {\n    return c(this.hex, 0, [0, 3 + this.foffset], \"30\");\n  };this.getIssuerString = function () {\n    return a.hex2dn(this.getIssuerHex());\n  };this.getSubjectHex = function () {\n    return c(this.hex, 0, [0, 5 + this.foffset], \"30\");\n  };this.getSubjectString = function () {\n    return a.hex2dn(this.getSubjectHex());\n  };this.getNotBefore = function () {\n    var l = f(this.hex, 0, [0, 4 + this.foffset, 0]);l = l.replace(/(..)/g, \"%$1\");l = decodeURIComponent(l);return l;\n  };this.getNotAfter = function () {\n    var l = f(this.hex, 0, [0, 4 + this.foffset, 1]);l = l.replace(/(..)/g, \"%$1\");l = decodeURIComponent(l);return l;\n  };this.getPublicKeyHex = function () {\n    return k.getTLVbyList(this.hex, 0, [0, 6 + this.foffset], \"30\");\n  };this.getPublicKeyIdx = function () {\n    return g(this.hex, 0, [0, 6 + this.foffset], \"30\");\n  };this.getPublicKeyContentIdx = function () {\n    var l = this.getPublicKeyIdx();return g(this.hex, l, [1, 0], \"30\");\n  };this.getPublicKey = function () {\n    return KEYUTIL.getKey(this.getPublicKeyHex(), null, \"pkcs8pub\");\n  };this.getSignatureAlgorithmName = function () {\n    return i(f(this.hex, 0, [1, 0], \"06\"));\n  };this.getSignatureValueHex = function () {\n    return f(this.hex, 0, [2], \"03\", true);\n  };this.verifySignature = function (n) {\n    var o = this.getSignatureAlgorithmName();var l = this.getSignatureValueHex();var m = c(this.hex, 0, [0], \"30\");var p = new KJUR.crypto.Signature({ alg: o });p.init(n);p.updateHex(m);return p.verify(l);\n  };this.parseExt = function () {\n    if (this.version !== 3) {\n      return -1;\n    }var p = g(this.hex, 0, [0, 7, 0], \"30\");var m = j(this.hex, p);this.aExtInfo = new Array();for (var n = 0; n < m.length; n++) {\n      var q = {};q.critical = false;var l = j(this.hex, m[n]);var r = 0;if (l.length === 3) {\n        q.critical = true;r = 1;\n      }q.oid = k.hextooidstr(f(this.hex, m[n], [0], \"06\"));var o = g(this.hex, m[n], [1 + r]);q.vidx = d(this.hex, o);this.aExtInfo.push(q);\n    }\n  };this.getExtInfo = function (n) {\n    var l = this.aExtInfo;var o = n;if (!n.match(/^[0-9.]+$/)) {\n      o = KJUR.asn1.x509.OID.name2oid(n);\n    }if (o === \"\") {\n      return undefined;\n    }for (var m = 0; m < l.length; m++) {\n      if (l[m].oid === o) {\n        return l[m];\n      }\n    }return undefined;\n  };this.getExtBasicConstraints = function () {\n    var n = this.getExtInfo(\"basicConstraints\");if (n === undefined) {\n      return n;\n    }var l = h(this.hex, n.vidx);if (l === \"\") {\n      return {};\n    }if (l === \"0101ff\") {\n      return { cA: true };\n    }if (l.substr(0, 8) === \"0101ff02\") {\n      var o = h(l, 6);var m = parseInt(o, 16);return { cA: true, pathLen: m };\n    }throw \"basicConstraints parse error\";\n  };this.getExtKeyUsageBin = function () {\n    var o = this.getExtInfo(\"keyUsage\");if (o === undefined) {\n      return \"\";\n    }var m = h(this.hex, o.vidx);if (m.length % 2 != 0 || m.length <= 2) {\n      throw \"malformed key usage value\";\n    }var l = parseInt(m.substr(0, 2));var n = parseInt(m.substr(2), 16).toString(2);return n.substr(0, n.length - l);\n  };this.getExtKeyUsageString = function () {\n    var n = this.getExtKeyUsageBin();var l = new Array();for (var m = 0; m < n.length; m++) {\n      if (n.substr(m, 1) == \"1\") {\n        l.push(X509.KEYUSAGE_NAME[m]);\n      }\n    }return l.join(\",\");\n  };this.getExtSubjectKeyIdentifier = function () {\n    var l = this.getExtInfo(\"subjectKeyIdentifier\");if (l === undefined) {\n      return l;\n    }return h(this.hex, l.vidx);\n  };this.getExtAuthorityKeyIdentifier = function () {\n    var p = this.getExtInfo(\"authorityKeyIdentifier\");if (p === undefined) {\n      return p;\n    }var l = {};var o = b(this.hex, p.vidx);var m = j(o, 0);for (var n = 0; n < m.length; n++) {\n      if (o.substr(m[n], 2) === \"80\") {\n        l.kid = h(o, m[n]);\n      }\n    }return l;\n  };this.getExtExtKeyUsageName = function () {\n    var p = this.getExtInfo(\"extKeyUsage\");if (p === undefined) {\n      return p;\n    }var l = new Array();var o = b(this.hex, p.vidx);if (o === \"\") {\n      return l;\n    }var m = j(o, 0);for (var n = 0; n < m.length; n++) {\n      l.push(i(h(o, m[n])));\n    }return l;\n  };this.getExtSubjectAltName = function () {\n    var m = this.getExtSubjectAltName2();var l = new Array();for (var n = 0; n < m.length; n++) {\n      if (m[n][0] === \"DNS\") {\n        l.push(m[n][1]);\n      }\n    }return l;\n  };this.getExtSubjectAltName2 = function () {\n    var p, s, r;var q = this.getExtInfo(\"subjectAltName\");if (q === undefined) {\n      return q;\n    }var l = new Array();var o = b(this.hex, q.vidx);var m = j(o, 0);for (var n = 0; n < m.length; n++) {\n      r = o.substr(m[n], 2);p = h(o, m[n]);if (r === \"81\") {\n        s = hextoutf8(p);l.push([\"MAIL\", s]);\n      }if (r === \"82\") {\n        s = hextoutf8(p);l.push([\"DNS\", s]);\n      }if (r === \"84\") {\n        s = X509.hex2dn(p, 0);l.push([\"DN\", s]);\n      }if (r === \"86\") {\n        s = hextoutf8(p);l.push([\"URI\", s]);\n      }if (r === \"87\") {\n        s = hextoip(p);l.push([\"IP\", s]);\n      }\n    }return l;\n  };this.getExtCRLDistributionPointsURI = function () {\n    var q = this.getExtInfo(\"cRLDistributionPoints\");if (q === undefined) {\n      return q;\n    }var l = new Array();var m = j(this.hex, q.vidx);for (var o = 0; o < m.length; o++) {\n      try {\n        var r = f(this.hex, m[o], [0, 0, 0], \"86\");var p = hextoutf8(r);l.push(p);\n      } catch (n) {}\n    }return l;\n  };this.getExtAIAInfo = function () {\n    var p = this.getExtInfo(\"authorityInfoAccess\");if (p === undefined) {\n      return p;\n    }var l = { ocsp: [], caissuer: [] };var m = j(this.hex, p.vidx);for (var n = 0; n < m.length; n++) {\n      var q = f(this.hex, m[n], [0], \"06\");var o = f(this.hex, m[n], [1], \"86\");if (q === \"2b06010505073001\") {\n        l.ocsp.push(hextoutf8(o));\n      }if (q === \"2b06010505073002\") {\n        l.caissuer.push(hextoutf8(o));\n      }\n    }return l;\n  };this.getExtCertificatePolicies = function () {\n    var o = this.getExtInfo(\"certificatePolicies\");if (o === undefined) {\n      return o;\n    }var l = b(this.hex, o.vidx);var u = [];var s = j(l, 0);for (var r = 0; r < s.length; r++) {\n      var t = {};var n = j(l, s[r]);t.id = i(h(l, n[0]));if (n.length === 2) {\n        var m = j(l, n[1]);for (var q = 0; q < m.length; q++) {\n          var p = f(l, m[q], [0], \"06\");if (p === \"2b06010505070201\") {\n            t.cps = hextoutf8(f(l, m[q], [1]));\n          } else {\n            if (p === \"2b06010505070202\") {\n              t.unotice = hextoutf8(f(l, m[q], [1, 0]));\n            }\n          }\n        }\n      }u.push(t);\n    }return u;\n  };this.readCertPEM = function (l) {\n    this.readCertHex(e(l));\n  };this.readCertHex = function (l) {\n    this.hex = l;this.getVersion();try {\n      g(this.hex, 0, [0, 7], \"a3\");this.parseExt();\n    } catch (m) {}\n  };this.getInfo = function () {\n    var m = X509;var B, u, z;B = \"Basic Fields\\n\";B += \"  serial number: \" + this.getSerialNumberHex() + \"\\n\";B += \"  signature algorithm: \" + this.getSignatureAlgorithmField() + \"\\n\";B += \"  issuer: \" + this.getIssuerString() + \"\\n\";B += \"  notBefore: \" + this.getNotBefore() + \"\\n\";B += \"  notAfter: \" + this.getNotAfter() + \"\\n\";B += \"  subject: \" + this.getSubjectString() + \"\\n\";B += \"  subject public key info: \\n\";u = this.getPublicKey();B += \"    key algorithm: \" + u.type + \"\\n\";if (u.type === \"RSA\") {\n      B += \"    n=\" + hextoposhex(u.n.toString(16)).substr(0, 16) + \"...\\n\";B += \"    e=\" + hextoposhex(u.e.toString(16)) + \"\\n\";\n    }z = this.aExtInfo;if (z !== undefined && z !== null) {\n      B += \"X509v3 Extensions:\\n\";for (var r = 0; r < z.length; r++) {\n        var n = z[r];var A = KJUR.asn1.x509.OID.oid2name(n.oid);if (A === \"\") {\n          A = n.oid;\n        }var x = \"\";if (n.critical === true) {\n          x = \"CRITICAL\";\n        }B += \"  \" + A + \" \" + x + \":\\n\";if (A === \"basicConstraints\") {\n          var v = this.getExtBasicConstraints();if (v.cA === undefined) {\n            B += \"    {}\\n\";\n          } else {\n            B += \"    cA=true\";if (v.pathLen !== undefined) {\n              B += \", pathLen=\" + v.pathLen;\n            }B += \"\\n\";\n          }\n        } else {\n          if (A === \"keyUsage\") {\n            B += \"    \" + this.getExtKeyUsageString() + \"\\n\";\n          } else {\n            if (A === \"subjectKeyIdentifier\") {\n              B += \"    \" + this.getExtSubjectKeyIdentifier() + \"\\n\";\n            } else {\n              if (A === \"authorityKeyIdentifier\") {\n                var l = this.getExtAuthorityKeyIdentifier();if (l.kid !== undefined) {\n                  B += \"    kid=\" + l.kid + \"\\n\";\n                }\n              } else {\n                if (A === \"extKeyUsage\") {\n                  var w = this.getExtExtKeyUsageName();B += \"    \" + w.join(\", \") + \"\\n\";\n                } else {\n                  if (A === \"subjectAltName\") {\n                    var t = this.getExtSubjectAltName2();B += \"    \" + t + \"\\n\";\n                  } else {\n                    if (A === \"cRLDistributionPoints\") {\n                      var y = this.getExtCRLDistributionPointsURI();B += \"    \" + y + \"\\n\";\n                    } else {\n                      if (A === \"authorityInfoAccess\") {\n                        var p = this.getExtAIAInfo();if (p.ocsp !== undefined) {\n                          B += \"    ocsp: \" + p.ocsp.join(\",\") + \"\\n\";\n                        }if (p.caissuer !== undefined) {\n                          B += \"    caissuer: \" + p.caissuer.join(\",\") + \"\\n\";\n                        }\n                      } else {\n                        if (A === \"certificatePolicies\") {\n                          var o = this.getExtCertificatePolicies();for (var q = 0; q < o.length; q++) {\n                            if (o[q].id !== undefined) {\n                              B += \"    policy oid: \" + o[q].id + \"\\n\";\n                            }if (o[q].cps !== undefined) {\n                              B += \"    cps: \" + o[q].cps + \"\\n\";\n                            }\n                          }\n                        }\n                      }\n                    }\n                  }\n                }\n              }\n            }\n          }\n        }\n      }\n    }B += \"signature algorithm: \" + this.getSignatureAlgorithmName() + \"\\n\";B += \"signature: \" + this.getSignatureValueHex().substr(0, 16) + \"...\\n\";return B;\n  };\n}X509.hex2dn = function (f, b) {\n  if (b === undefined) {\n    b = 0;\n  }if (f.substr(b, 2) !== \"30\") {\n    throw \"malformed DN\";\n  }var c = new Array();var d = ASN1HEX.getChildIdx(f, b);for (var e = 0; e < d.length; e++) {\n    c.push(X509.hex2rdn(f, d[e]));\n  }c = c.map(function (a) {\n    return a.replace(\"/\", \"\\\\/\");\n  });return \"/\" + c.join(\"/\");\n};X509.hex2rdn = function (f, b) {\n  if (b === undefined) {\n    b = 0;\n  }if (f.substr(b, 2) !== \"31\") {\n    throw \"malformed RDN\";\n  }var c = new Array();var d = ASN1HEX.getChildIdx(f, b);for (var e = 0; e < d.length; e++) {\n    c.push(X509.hex2attrTypeValue(f, d[e]));\n  }c = c.map(function (a) {\n    return a.replace(\"+\", \"\\\\+\");\n  });return c.join(\"+\");\n};X509.hex2attrTypeValue = function (d, i) {\n  var j = ASN1HEX;var h = j.getV;if (i === undefined) {\n    i = 0;\n  }if (d.substr(i, 2) !== \"30\") {\n    throw \"malformed attribute type and value\";\n  }var g = j.getChildIdx(d, i);if (g.length !== 2 || d.substr(g[0], 2) !== \"06\") {\n    \"malformed attribute type and value\";\n  }var b = h(d, g[0]);var f = KJUR.asn1.ASN1Util.oidHexToInt(b);var e = KJUR.asn1.x509.OID.oid2atype(f);var a = h(d, g[1]);var c = hextorstr(a);return e + \"=\" + c;\n};X509.getPublicKeyFromCertHex = function (b) {\n  var a = new X509();a.readCertHex(b);return a.getPublicKey();\n};X509.getPublicKeyFromCertPEM = function (b) {\n  var a = new X509();a.readCertPEM(b);return a.getPublicKey();\n};X509.getPublicKeyInfoPropOfCertPEM = function (c) {\n  var e = ASN1HEX;var g = e.getVbyList;var b = {};var a, f, d;b.algparam = null;a = new X509();a.readCertPEM(c);f = a.getPublicKeyHex();b.keyhex = g(f, 0, [1], \"03\").substr(2);b.algoid = g(f, 0, [0, 0], \"06\");if (b.algoid === \"2a8648ce3d0201\") {\n    b.algparam = g(f, 0, [0, 1], \"06\");\n  }return b;\n};X509.KEYUSAGE_NAME = [\"digitalSignature\", \"nonRepudiation\", \"keyEncipherment\", \"dataEncipherment\", \"keyAgreement\", \"keyCertSign\", \"cRLSign\", \"encipherOnly\", \"decipherOnly\"];\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.jws == \"undefined\" || !KJUR.jws) {\n  KJUR.jws = {};\n}KJUR.jws.JWS = function () {\n  var b = KJUR,\n      a = b.jws.JWS,\n      c = a.isSafeJSONString;this.parseJWS = function (g, j) {\n    if (this.parsedJWS !== undefined && (j || this.parsedJWS.sigvalH !== undefined)) {\n      return;\n    }var i = g.match(/^([^.]+)\\.([^.]+)\\.([^.]+)$/);if (i == null) {\n      throw \"JWS signature is not a form of 'Head.Payload.SigValue'.\";\n    }var k = i[1];var e = i[2];var l = i[3];var n = k + \".\" + e;this.parsedJWS = {};this.parsedJWS.headB64U = k;this.parsedJWS.payloadB64U = e;this.parsedJWS.sigvalB64U = l;this.parsedJWS.si = n;if (!j) {\n      var h = b64utohex(l);var f = parseBigInt(h, 16);this.parsedJWS.sigvalH = h;this.parsedJWS.sigvalBI = f;\n    }var d = b64utoutf8(k);var m = b64utoutf8(e);this.parsedJWS.headS = d;this.parsedJWS.payloadS = m;if (!c(d, this.parsedJWS, \"headP\")) {\n      throw \"malformed JSON string for JWS Head: \" + d;\n    }\n  };\n};KJUR.jws.JWS.sign = function (i, v, y, z, a) {\n  var w = KJUR,\n      m = w.jws,\n      q = m.JWS,\n      g = q.readSafeJSONString,\n      p = q.isSafeJSONString,\n      d = w.crypto,\n      k = d.ECDSA,\n      o = d.Mac,\n      c = d.Signature,\n      t = JSON;var s, j, n;if (typeof v != \"string\" && (typeof v === \"undefined\" ? \"undefined\" : _typeof(v)) != \"object\") {\n    throw \"spHeader must be JSON string or object: \" + v;\n  }if ((typeof v === \"undefined\" ? \"undefined\" : _typeof(v)) == \"object\") {\n    j = v;s = t.stringify(j);\n  }if (typeof v == \"string\") {\n    s = v;if (!p(s)) {\n      throw \"JWS Head is not safe JSON string: \" + s;\n    }j = g(s);\n  }n = y;if ((typeof y === \"undefined\" ? \"undefined\" : _typeof(y)) == \"object\") {\n    n = t.stringify(y);\n  }if ((i == \"\" || i == null) && j.alg !== undefined) {\n    i = j.alg;\n  }if (i != \"\" && i != null && j.alg === undefined) {\n    j.alg = i;s = t.stringify(j);\n  }if (i !== j.alg) {\n    throw \"alg and sHeader.alg doesn't match: \" + i + \"!=\" + j.alg;\n  }var r = null;if (q.jwsalg2sigalg[i] === undefined) {\n    throw \"unsupported alg name: \" + i;\n  } else {\n    r = q.jwsalg2sigalg[i];\n  }var e = utf8tob64u(s);var l = utf8tob64u(n);var b = e + \".\" + l;var x = \"\";if (r.substr(0, 4) == \"Hmac\") {\n    if (z === undefined) {\n      throw \"mac key shall be specified for HS* alg\";\n    }var h = new o({ alg: r, prov: \"cryptojs\", pass: z });h.updateString(b);x = h.doFinal();\n  } else {\n    if (r.indexOf(\"withECDSA\") != -1) {\n      var f = new c({ alg: r });f.init(z, a);f.updateString(b);hASN1Sig = f.sign();x = KJUR.crypto.ECDSA.asn1SigToConcatSig(hASN1Sig);\n    } else {\n      if (r != \"none\") {\n        var f = new c({ alg: r });f.init(z, a);f.updateString(b);x = f.sign();\n      }\n    }\n  }var u = hextob64u(x);return b + \".\" + u;\n};KJUR.jws.JWS.verify = function (w, B, n) {\n  var x = KJUR,\n      q = x.jws,\n      t = q.JWS,\n      i = t.readSafeJSONString,\n      e = x.crypto,\n      p = e.ECDSA,\n      s = e.Mac,\n      d = e.Signature,\n      m;if ((typeof RSAKey === \"undefined\" ? \"undefined\" : _typeof(RSAKey)) !== undefined) {\n    m = RSAKey;\n  }var y = w.split(\".\");if (y.length !== 3) {\n    return false;\n  }var f = y[0];var r = y[1];var c = f + \".\" + r;var A = b64utohex(y[2]);var l = i(b64utoutf8(y[0]));var k = null;var z = null;if (l.alg === undefined) {\n    throw \"algorithm not specified in header\";\n  } else {\n    k = l.alg;z = k.substr(0, 2);\n  }if (n != null && Object.prototype.toString.call(n) === \"[object Array]\" && n.length > 0) {\n    var b = \":\" + n.join(\":\") + \":\";if (b.indexOf(\":\" + k + \":\") == -1) {\n      throw \"algorithm '\" + k + \"' not accepted in the list\";\n    }\n  }if (k != \"none\" && B === null) {\n    throw \"key shall be specified to verify.\";\n  }if (typeof B == \"string\" && B.indexOf(\"-----BEGIN \") != -1) {\n    B = KEYUTIL.getKey(B);\n  }if (z == \"RS\" || z == \"PS\") {\n    if (!(B instanceof m)) {\n      throw \"key shall be a RSAKey obj for RS* and PS* algs\";\n    }\n  }if (z == \"ES\") {\n    if (!(B instanceof p)) {\n      throw \"key shall be a ECDSA obj for ES* algs\";\n    }\n  }if (k == \"none\") {}var u = null;if (t.jwsalg2sigalg[l.alg] === undefined) {\n    throw \"unsupported alg name: \" + k;\n  } else {\n    u = t.jwsalg2sigalg[k];\n  }if (u == \"none\") {\n    throw \"not supported\";\n  } else {\n    if (u.substr(0, 4) == \"Hmac\") {\n      var o = null;if (B === undefined) {\n        throw \"hexadecimal key shall be specified for HMAC\";\n      }var j = new s({ alg: u, pass: B });j.updateString(c);o = j.doFinal();return A == o;\n    } else {\n      if (u.indexOf(\"withECDSA\") != -1) {\n        var h = null;try {\n          h = p.concatSigToASN1Sig(A);\n        } catch (v) {\n          return false;\n        }var g = new d({ alg: u });g.init(B);g.updateString(c);return g.verify(h);\n      } else {\n        var g = new d({ alg: u });g.init(B);g.updateString(c);return g.verify(A);\n      }\n    }\n  }\n};KJUR.jws.JWS.parse = function (g) {\n  var c = g.split(\".\");var b = {};var f, e, d;if (c.length != 2 && c.length != 3) {\n    throw \"malformed sJWS: wrong number of '.' splitted elements\";\n  }f = c[0];e = c[1];if (c.length == 3) {\n    d = c[2];\n  }b.headerObj = KJUR.jws.JWS.readSafeJSONString(b64utoutf8(f));b.payloadObj = KJUR.jws.JWS.readSafeJSONString(b64utoutf8(e));b.headerPP = JSON.stringify(b.headerObj, null, \"  \");if (b.payloadObj == null) {\n    b.payloadPP = b64utoutf8(e);\n  } else {\n    b.payloadPP = JSON.stringify(b.payloadObj, null, \"  \");\n  }if (d !== undefined) {\n    b.sigHex = b64utohex(d);\n  }return b;\n};KJUR.jws.JWS.verifyJWT = function (e, l, r) {\n  var d = KJUR,\n      j = d.jws,\n      o = j.JWS,\n      n = o.readSafeJSONString,\n      p = o.inArray,\n      f = o.includedArray;var k = e.split(\".\");var c = k[0];var i = k[1];var q = c + \".\" + i;var m = b64utohex(k[2]);var h = n(b64utoutf8(c));var g = n(b64utoutf8(i));if (h.alg === undefined) {\n    return false;\n  }if (r.alg === undefined) {\n    throw \"acceptField.alg shall be specified\";\n  }if (!p(h.alg, r.alg)) {\n    return false;\n  }if (g.iss !== undefined && _typeof(r.iss) === \"object\") {\n    if (!p(g.iss, r.iss)) {\n      return false;\n    }\n  }if (g.sub !== undefined && _typeof(r.sub) === \"object\") {\n    if (!p(g.sub, r.sub)) {\n      return false;\n    }\n  }if (g.aud !== undefined && _typeof(r.aud) === \"object\") {\n    if (typeof g.aud == \"string\") {\n      if (!p(g.aud, r.aud)) {\n        return false;\n      }\n    } else {\n      if (_typeof(g.aud) == \"object\") {\n        if (!f(g.aud, r.aud)) {\n          return false;\n        }\n      }\n    }\n  }var b = j.IntDate.getNow();if (r.verifyAt !== undefined && typeof r.verifyAt === \"number\") {\n    b = r.verifyAt;\n  }if (r.gracePeriod === undefined || typeof r.gracePeriod !== \"number\") {\n    r.gracePeriod = 0;\n  }if (g.exp !== undefined && typeof g.exp == \"number\") {\n    if (g.exp + r.gracePeriod < b) {\n      return false;\n    }\n  }if (g.nbf !== undefined && typeof g.nbf == \"number\") {\n    if (b < g.nbf - r.gracePeriod) {\n      return false;\n    }\n  }if (g.iat !== undefined && typeof g.iat == \"number\") {\n    if (b < g.iat - r.gracePeriod) {\n      return false;\n    }\n  }if (g.jti !== undefined && r.jti !== undefined) {\n    if (g.jti !== r.jti) {\n      return false;\n    }\n  }if (!o.verify(e, l, r.alg)) {\n    return false;\n  }return true;\n};KJUR.jws.JWS.includedArray = function (b, a) {\n  var c = KJUR.jws.JWS.inArray;if (b === null) {\n    return false;\n  }if ((typeof b === \"undefined\" ? \"undefined\" : _typeof(b)) !== \"object\") {\n    return false;\n  }if (typeof b.length !== \"number\") {\n    return false;\n  }for (var d = 0; d < b.length; d++) {\n    if (!c(b[d], a)) {\n      return false;\n    }\n  }return true;\n};KJUR.jws.JWS.inArray = function (d, b) {\n  if (b === null) {\n    return false;\n  }if ((typeof b === \"undefined\" ? \"undefined\" : _typeof(b)) !== \"object\") {\n    return false;\n  }if (typeof b.length !== \"number\") {\n    return false;\n  }for (var c = 0; c < b.length; c++) {\n    if (b[c] == d) {\n      return true;\n    }\n  }return false;\n};KJUR.jws.JWS.jwsalg2sigalg = { HS256: \"HmacSHA256\", HS384: \"HmacSHA384\", HS512: \"HmacSHA512\", RS256: \"SHA256withRSA\", RS384: \"SHA384withRSA\", RS512: \"SHA512withRSA\", ES256: \"SHA256withECDSA\", ES384: \"SHA384withECDSA\", PS256: \"SHA256withRSAandMGF1\", PS384: \"SHA384withRSAandMGF1\", PS512: \"SHA512withRSAandMGF1\", none: \"none\" };KJUR.jws.JWS.isSafeJSONString = function (c, b, d) {\n  var e = null;try {\n    e = jsonParse(c);if ((typeof e === \"undefined\" ? \"undefined\" : _typeof(e)) != \"object\") {\n      return 0;\n    }if (e.constructor === Array) {\n      return 0;\n    }if (b) {\n      b[d] = e;\n    }return 1;\n  } catch (a) {\n    return 0;\n  }\n};KJUR.jws.JWS.readSafeJSONString = function (b) {\n  var c = null;try {\n    c = jsonParse(b);if ((typeof c === \"undefined\" ? \"undefined\" : _typeof(c)) != \"object\") {\n      return null;\n    }if (c.constructor === Array) {\n      return null;\n    }return c;\n  } catch (a) {\n    return null;\n  }\n};KJUR.jws.JWS.getEncodedSignatureValueFromJWS = function (b) {\n  var a = b.match(/^[^.]+\\.[^.]+\\.([^.]+)$/);if (a == null) {\n    throw \"JWS signature is not a form of 'Head.Payload.SigValue'.\";\n  }return a[1];\n};KJUR.jws.JWS.getJWKthumbprint = function (d) {\n  if (d.kty !== \"RSA\" && d.kty !== \"EC\" && d.kty !== \"oct\") {\n    throw \"unsupported algorithm for JWK Thumprint\";\n  }var a = \"{\";if (d.kty === \"RSA\") {\n    if (typeof d.n != \"string\" || typeof d.e != \"string\") {\n      throw \"wrong n and e value for RSA key\";\n    }a += '\"e\":\"' + d.e + '\",';a += '\"kty\":\"' + d.kty + '\",';a += '\"n\":\"' + d.n + '\"}';\n  } else {\n    if (d.kty === \"EC\") {\n      if (typeof d.crv != \"string\" || typeof d.x != \"string\" || typeof d.y != \"string\") {\n        throw \"wrong crv, x and y value for EC key\";\n      }a += '\"crv\":\"' + d.crv + '\",';a += '\"kty\":\"' + d.kty + '\",';a += '\"x\":\"' + d.x + '\",';a += '\"y\":\"' + d.y + '\"}';\n    } else {\n      if (d.kty === \"oct\") {\n        if (typeof d.k != \"string\") {\n          throw \"wrong k value for oct(symmetric) key\";\n        }a += '\"kty\":\"' + d.kty + '\",';a += '\"k\":\"' + d.k + '\"}';\n      }\n    }\n  }var b = rstrtohex(a);var c = KJUR.crypto.Util.hashHex(b, \"sha256\");var e = hextob64u(c);return e;\n};KJUR.jws.IntDate = {};KJUR.jws.IntDate.get = function (c) {\n  var b = KJUR.jws.IntDate,\n      d = b.getNow,\n      a = b.getZulu;if (c == \"now\") {\n    return d();\n  } else {\n    if (c == \"now + 1hour\") {\n      return d() + 60 * 60;\n    } else {\n      if (c == \"now + 1day\") {\n        return d() + 60 * 60 * 24;\n      } else {\n        if (c == \"now + 1month\") {\n          return d() + 60 * 60 * 24 * 30;\n        } else {\n          if (c == \"now + 1year\") {\n            return d() + 60 * 60 * 24 * 365;\n          } else {\n            if (c.match(/Z$/)) {\n              return a(c);\n            } else {\n              if (c.match(/^[0-9]+$/)) {\n                return parseInt(c);\n              }\n            }\n          }\n        }\n      }\n    }\n  }throw \"unsupported format: \" + c;\n};KJUR.jws.IntDate.getZulu = function (a) {\n  return zulutosec(a);\n};KJUR.jws.IntDate.getNow = function () {\n  var a = ~~(new Date() / 1000);return a;\n};KJUR.jws.IntDate.intDate2UTCString = function (a) {\n  var b = new Date(a * 1000);return b.toUTCString();\n};KJUR.jws.IntDate.intDate2Zulu = function (e) {\n  var i = new Date(e * 1000),\n      h = (\"0000\" + i.getUTCFullYear()).slice(-4),\n      g = (\"00\" + (i.getUTCMonth() + 1)).slice(-2),\n      b = (\"00\" + i.getUTCDate()).slice(-2),\n      a = (\"00\" + i.getUTCHours()).slice(-2),\n      c = (\"00\" + i.getUTCMinutes()).slice(-2),\n      f = (\"00\" + i.getUTCSeconds()).slice(-2);return h + g + b + a + c + f + \"Z\";\n};\nexports.SecureRandom = SecureRandom;\nexports.rng_seed_time = rng_seed_time;\nexports.BigInteger = BigInteger;\nexports.RSAKey = RSAKey;\nvar EDSA = KJUR.crypto.EDSA;\nexports.EDSA = EDSA;\nvar DSA = KJUR.crypto.DSA;\nexports.DSA = DSA;\nvar Signature = KJUR.crypto.Signature;\nexports.Signature = Signature;\nvar MessageDigest = KJUR.crypto.MessageDigest;\nexports.MessageDigest = MessageDigest;\nvar Mac = KJUR.crypto.Mac;\nexports.Mac = Mac;\nvar Cipher = KJUR.crypto.Cipher;\nexports.Cipher = Cipher;\nexports.KEYUTIL = KEYUTIL;\nexports.ASN1HEX = ASN1HEX;\nexports.X509 = X509;\nexports.CryptoJS = CryptoJS;\n\n// ext/base64.js\n\nexports.b64tohex = b64tohex;\nexports.b64toBA = b64toBA;\n\n// base64x.js\n\nexports.stoBA = stoBA;\nexports.BAtos = BAtos;\nexports.BAtohex = BAtohex;\nexports.stohex = stohex;\nexports.stob64 = stob64;\nexports.stob64u = stob64u;\nexports.b64utos = b64utos;\nexports.b64tob64u = b64tob64u;\nexports.b64utob64 = b64utob64;\nexports.hex2b64 = hex2b64;\nexports.hextob64u = hextob64u;\nexports.b64utohex = b64utohex;\nexports.utf8tob64u = utf8tob64u;\nexports.b64utoutf8 = b64utoutf8;\nexports.utf8tob64 = utf8tob64;\nexports.b64toutf8 = b64toutf8;\nexports.utf8tohex = utf8tohex;\nexports.hextoutf8 = hextoutf8;\nexports.hextorstr = hextorstr;\nexports.rstrtohex = rstrtohex;\nexports.hextob64 = hextob64;\nexports.hextob64nl = hextob64nl;\nexports.b64nltohex = b64nltohex;\nexports.hextopem = hextopem;\nexports.pemtohex = pemtohex;\nexports.hextoArrayBuffer = hextoArrayBuffer;\nexports.ArrayBuffertohex = ArrayBuffertohex;\nexports.zulutomsec = zulutomsec;\nexports.zulutosec = zulutosec;\nexports.zulutodate = zulutodate;\nexports.datetozulu = datetozulu;\nexports.uricmptohex = uricmptohex;\nexports.hextouricmp = hextouricmp;\nexports.ipv6tohex = ipv6tohex;\nexports.hextoipv6 = hextoipv6;\nexports.hextoip = hextoip;\nexports.iptohex = iptohex;\nexports.encodeURIComponentAll = encodeURIComponentAll;\nexports.newline_toUnix = newline_toUnix;\nexports.newline_toDos = newline_toDos;\nexports.hextoposhex = hextoposhex;\nexports.intarystrtohex = intarystrtohex;\nexports.strdiffidx = strdiffidx;\n\n// name spaces\n\nexports.KJUR = KJUR;\n\nvar _crypto = KJUR.crypto;\nexports.crypto = _crypto;\nvar _KJUR = KJUR;\nvar asn1 = _KJUR.asn1;\nexports.asn1 = asn1;\nvar _KJUR2 = KJUR;\nvar jws = _KJUR2.jws;\nexports.jws = jws;\nvar _KJUR3 = KJUR;\nvar lang = _KJUR3.lang;\nexports.lang = lang;\n/* WEBPACK VAR INJECTION */}.call(this, __webpack_require__(/*! ./../../node_modules/buffer/index.js */ \"./node_modules/buffer/index.js\").Buffer))\n\n/***/ }),\n\n/***/ \"./node_modules/babel-polyfill/lib/index.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/babel-polyfill/lib/index.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n/* WEBPACK VAR INJECTION */(function(global) {\n\n__webpack_require__(/*! core-js/shim */ \"./node_modules/core-js/shim.js\");\n\n__webpack_require__(/*! regenerator-runtime/runtime */ \"./node_modules/babel-polyfill/node_modules/regenerator-runtime/runtime.js\");\n\n__webpack_require__(/*! core-js/fn/regexp/escape */ \"./node_modules/core-js/fn/regexp/escape.js\");\n\nif (global._babelPolyfill) {\n  throw new Error(\"only one instance of babel-polyfill is allowed\");\n}\nglobal._babelPolyfill = true;\n\nvar DEFINE_PROPERTY = \"defineProperty\";\nfunction define(O, key, value) {\n  O[key] || Object[DEFINE_PROPERTY](O, key, {\n    writable: true,\n    configurable: true,\n    value: value\n  });\n}\n\ndefine(String.prototype, \"padLeft\", \"\".padStart);\ndefine(String.prototype, \"padRight\", \"\".padEnd);\n\n\"pop,reverse,shift,keys,values,entries,indexOf,every,some,forEach,map,filter,find,findIndex,includes,join,slice,concat,push,splice,unshift,sort,lastIndexOf,reduce,reduceRight,copyWithin,fill\".split(\",\").forEach(function (key) {\n  [][key] && define(Array, key, Function.call.bind([][key]));\n});\n/* WEBPACK VAR INJECTION */}.call(this, __webpack_require__(/*! ./../../webpack/buildin/global.js */ \"./node_modules/webpack/buildin/global.js\")))\n\n/***/ }),\n\n/***/ \"./node_modules/babel-polyfill/node_modules/regenerator-runtime/runtime.js\":\n/*!*********************************************************************************!*\\\n  !*** ./node_modules/babel-polyfill/node_modules/regenerator-runtime/runtime.js ***!\n  \\*********************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n/* WEBPACK VAR INJECTION */(function(global) {/**\n * Copyright (c) 2014, Facebook, Inc.\n * All rights reserved.\n *\n * This source code is licensed under the BSD-style license found in the\n * https://raw.github.com/facebook/regenerator/master/LICENSE file. An\n * additional grant of patent rights can be found in the PATENTS file in\n * the same directory.\n */\n\n!(function(global) {\n  \"use strict\";\n\n  var Op = Object.prototype;\n  var hasOwn = Op.hasOwnProperty;\n  var undefined; // More compressible than void 0.\n  var $Symbol = typeof Symbol === \"function\" ? Symbol : {};\n  var iteratorSymbol = $Symbol.iterator || \"@@iterator\";\n  var asyncIteratorSymbol = $Symbol.asyncIterator || \"@@asyncIterator\";\n  var toStringTagSymbol = $Symbol.toStringTag || \"@@toStringTag\";\n\n  var inModule = typeof module === \"object\";\n  var runtime = global.regeneratorRuntime;\n  if (runtime) {\n    if (inModule) {\n      // If regeneratorRuntime is defined globally and we're in a module,\n      // make the exports object identical to regeneratorRuntime.\n      module.exports = runtime;\n    }\n    // Don't bother evaluating the rest of this file if the runtime was\n    // already defined globally.\n    return;\n  }\n\n  // Define the runtime globally (as expected by generated code) as either\n  // module.exports (if we're in a module) or a new, empty object.\n  runtime = global.regeneratorRuntime = inModule ? module.exports : {};\n\n  function wrap(innerFn, outerFn, self, tryLocsList) {\n    // If outerFn provided and outerFn.prototype is a Generator, then outerFn.prototype instanceof Generator.\n    var protoGenerator = outerFn && outerFn.prototype instanceof Generator ? outerFn : Generator;\n    var generator = Object.create(protoGenerator.prototype);\n    var context = new Context(tryLocsList || []);\n\n    // The ._invoke method unifies the implementations of the .next,\n    // .throw, and .return methods.\n    generator._invoke = makeInvokeMethod(innerFn, self, context);\n\n    return generator;\n  }\n  runtime.wrap = wrap;\n\n  // Try/catch helper to minimize deoptimizations. Returns a completion\n  // record like context.tryEntries[i].completion. This interface could\n  // have been (and was previously) designed to take a closure to be\n  // invoked without arguments, but in all the cases we care about we\n  // already have an existing method we want to call, so there's no need\n  // to create a new function object. We can even get away with assuming\n  // the method takes exactly one argument, since that happens to be true\n  // in every case, so we don't have to touch the arguments object. The\n  // only additional allocation required is the completion record, which\n  // has a stable shape and so hopefully should be cheap to allocate.\n  function tryCatch(fn, obj, arg) {\n    try {\n      return { type: \"normal\", arg: fn.call(obj, arg) };\n    } catch (err) {\n      return { type: \"throw\", arg: err };\n    }\n  }\n\n  var GenStateSuspendedStart = \"suspendedStart\";\n  var GenStateSuspendedYield = \"suspendedYield\";\n  var GenStateExecuting = \"executing\";\n  var GenStateCompleted = \"completed\";\n\n  // Returning this object from the innerFn has the same effect as\n  // breaking out of the dispatch switch statement.\n  var ContinueSentinel = {};\n\n  // Dummy constructor functions that we use as the .constructor and\n  // .constructor.prototype properties for functions that return Generator\n  // objects. For full spec compliance, you may wish to configure your\n  // minifier not to mangle the names of these two functions.\n  function Generator() {}\n  function GeneratorFunction() {}\n  function GeneratorFunctionPrototype() {}\n\n  // This is a polyfill for %IteratorPrototype% for environments that\n  // don't natively support it.\n  var IteratorPrototype = {};\n  IteratorPrototype[iteratorSymbol] = function () {\n    return this;\n  };\n\n  var getProto = Object.getPrototypeOf;\n  var NativeIteratorPrototype = getProto && getProto(getProto(values([])));\n  if (NativeIteratorPrototype &&\n      NativeIteratorPrototype !== Op &&\n      hasOwn.call(NativeIteratorPrototype, iteratorSymbol)) {\n    // This environment has a native %IteratorPrototype%; use it instead\n    // of the polyfill.\n    IteratorPrototype = NativeIteratorPrototype;\n  }\n\n  var Gp = GeneratorFunctionPrototype.prototype =\n    Generator.prototype = Object.create(IteratorPrototype);\n  GeneratorFunction.prototype = Gp.constructor = GeneratorFunctionPrototype;\n  GeneratorFunctionPrototype.constructor = GeneratorFunction;\n  GeneratorFunctionPrototype[toStringTagSymbol] =\n    GeneratorFunction.displayName = \"GeneratorFunction\";\n\n  // Helper for defining the .next, .throw, and .return methods of the\n  // Iterator interface in terms of a single ._invoke method.\n  function defineIteratorMethods(prototype) {\n    [\"next\", \"throw\", \"return\"].forEach(function(method) {\n      prototype[method] = function(arg) {\n        return this._invoke(method, arg);\n      };\n    });\n  }\n\n  runtime.isGeneratorFunction = function(genFun) {\n    var ctor = typeof genFun === \"function\" && genFun.constructor;\n    return ctor\n      ? ctor === GeneratorFunction ||\n        // For the native GeneratorFunction constructor, the best we can\n        // do is to check its .name property.\n        (ctor.displayName || ctor.name) === \"GeneratorFunction\"\n      : false;\n  };\n\n  runtime.mark = function(genFun) {\n    if (Object.setPrototypeOf) {\n      Object.setPrototypeOf(genFun, GeneratorFunctionPrototype);\n    } else {\n      genFun.__proto__ = GeneratorFunctionPrototype;\n      if (!(toStringTagSymbol in genFun)) {\n        genFun[toStringTagSymbol] = \"GeneratorFunction\";\n      }\n    }\n    genFun.prototype = Object.create(Gp);\n    return genFun;\n  };\n\n  // Within the body of any async function, `await x` is transformed to\n  // `yield regeneratorRuntime.awrap(x)`, so that the runtime can test\n  // `hasOwn.call(value, \"__await\")` to determine if the yielded value is\n  // meant to be awaited.\n  runtime.awrap = function(arg) {\n    return { __await: arg };\n  };\n\n  function AsyncIterator(generator) {\n    function invoke(method, arg, resolve, reject) {\n      var record = tryCatch(generator[method], generator, arg);\n      if (record.type === \"throw\") {\n        reject(record.arg);\n      } else {\n        var result = record.arg;\n        var value = result.value;\n        if (value &&\n            typeof value === \"object\" &&\n            hasOwn.call(value, \"__await\")) {\n          return Promise.resolve(value.__await).then(function(value) {\n            invoke(\"next\", value, resolve, reject);\n          }, function(err) {\n            invoke(\"throw\", err, resolve, reject);\n          });\n        }\n\n        return Promise.resolve(value).then(function(unwrapped) {\n          // When a yielded Promise is resolved, its final value becomes\n          // the .value of the Promise<{value,done}> result for the\n          // current iteration. If the Promise is rejected, however, the\n          // result for this iteration will be rejected with the same\n          // reason. Note that rejections of yielded Promises are not\n          // thrown back into the generator function, as is the case\n          // when an awaited Promise is rejected. This difference in\n          // behavior between yield and await is important, because it\n          // allows the consumer to decide what to do with the yielded\n          // rejection (swallow it and continue, manually .throw it back\n          // into the generator, abandon iteration, whatever). With\n          // await, by contrast, there is no opportunity to examine the\n          // rejection reason outside the generator function, so the\n          // only option is to throw it from the await expression, and\n          // let the generator function handle the exception.\n          result.value = unwrapped;\n          resolve(result);\n        }, reject);\n      }\n    }\n\n    if (typeof global.process === \"object\" && global.process.domain) {\n      invoke = global.process.domain.bind(invoke);\n    }\n\n    var previousPromise;\n\n    function enqueue(method, arg) {\n      function callInvokeWithMethodAndArg() {\n        return new Promise(function(resolve, reject) {\n          invoke(method, arg, resolve, reject);\n        });\n      }\n\n      return previousPromise =\n        // If enqueue has been called before, then we want to wait until\n        // all previous Promises have been resolved before calling invoke,\n        // so that results are always delivered in the correct order. If\n        // enqueue has not been called before, then it is important to\n        // call invoke immediately, without waiting on a callback to fire,\n        // so that the async generator function has the opportunity to do\n        // any necessary setup in a predictable way. This predictability\n        // is why the Promise constructor synchronously invokes its\n        // executor callback, and why async functions synchronously\n        // execute code before the first await. Since we implement simple\n        // async functions in terms of async generators, it is especially\n        // important to get this right, even though it requires care.\n        previousPromise ? previousPromise.then(\n          callInvokeWithMethodAndArg,\n          // Avoid propagating failures to Promises returned by later\n          // invocations of the iterator.\n          callInvokeWithMethodAndArg\n        ) : callInvokeWithMethodAndArg();\n    }\n\n    // Define the unified helper method that is used to implement .next,\n    // .throw, and .return (see defineIteratorMethods).\n    this._invoke = enqueue;\n  }\n\n  defineIteratorMethods(AsyncIterator.prototype);\n  AsyncIterator.prototype[asyncIteratorSymbol] = function () {\n    return this;\n  };\n  runtime.AsyncIterator = AsyncIterator;\n\n  // Note that simple async functions are implemented on top of\n  // AsyncIterator objects; they just return a Promise for the value of\n  // the final result produced by the iterator.\n  runtime.async = function(innerFn, outerFn, self, tryLocsList) {\n    var iter = new AsyncIterator(\n      wrap(innerFn, outerFn, self, tryLocsList)\n    );\n\n    return runtime.isGeneratorFunction(outerFn)\n      ? iter // If outerFn is a generator, return the full iterator.\n      : iter.next().then(function(result) {\n          return result.done ? result.value : iter.next();\n        });\n  };\n\n  function makeInvokeMethod(innerFn, self, context) {\n    var state = GenStateSuspendedStart;\n\n    return function invoke(method, arg) {\n      if (state === GenStateExecuting) {\n        throw new Error(\"Generator is already running\");\n      }\n\n      if (state === GenStateCompleted) {\n        if (method === \"throw\") {\n          throw arg;\n        }\n\n        // Be forgiving, per 25.3.3.3.3 of the spec:\n        // https://people.mozilla.org/~jorendorff/es6-draft.html#sec-generatorresume\n        return doneResult();\n      }\n\n      context.method = method;\n      context.arg = arg;\n\n      while (true) {\n        var delegate = context.delegate;\n        if (delegate) {\n          var delegateResult = maybeInvokeDelegate(delegate, context);\n          if (delegateResult) {\n            if (delegateResult === ContinueSentinel) continue;\n            return delegateResult;\n          }\n        }\n\n        if (context.method === \"next\") {\n          // Setting context._sent for legacy support of Babel's\n          // function.sent implementation.\n          context.sent = context._sent = context.arg;\n\n        } else if (context.method === \"throw\") {\n          if (state === GenStateSuspendedStart) {\n            state = GenStateCompleted;\n            throw context.arg;\n          }\n\n          context.dispatchException(context.arg);\n\n        } else if (context.method === \"return\") {\n          context.abrupt(\"return\", context.arg);\n        }\n\n        state = GenStateExecuting;\n\n        var record = tryCatch(innerFn, self, context);\n        if (record.type === \"normal\") {\n          // If an exception is thrown from innerFn, we leave state ===\n          // GenStateExecuting and loop back for another invocation.\n          state = context.done\n            ? GenStateCompleted\n            : GenStateSuspendedYield;\n\n          if (record.arg === ContinueSentinel) {\n            continue;\n          }\n\n          return {\n            value: record.arg,\n            done: context.done\n          };\n\n        } else if (record.type === \"throw\") {\n          state = GenStateCompleted;\n          // Dispatch the exception by looping back around to the\n          // context.dispatchException(context.arg) call above.\n          context.method = \"throw\";\n          context.arg = record.arg;\n        }\n      }\n    };\n  }\n\n  // Call delegate.iterator[context.method](context.arg) and handle the\n  // result, either by returning a { value, done } result from the\n  // delegate iterator, or by modifying context.method and context.arg,\n  // setting context.delegate to null, and returning the ContinueSentinel.\n  function maybeInvokeDelegate(delegate, context) {\n    var method = delegate.iterator[context.method];\n    if (method === undefined) {\n      // A .throw or .return when the delegate iterator has no .throw\n      // method always terminates the yield* loop.\n      context.delegate = null;\n\n      if (context.method === \"throw\") {\n        if (delegate.iterator.return) {\n          // If the delegate iterator has a return method, give it a\n          // chance to clean up.\n          context.method = \"return\";\n          context.arg = undefined;\n          maybeInvokeDelegate(delegate, context);\n\n          if (context.method === \"throw\") {\n            // If maybeInvokeDelegate(context) changed context.method from\n            // \"return\" to \"throw\", let that override the TypeError below.\n            return ContinueSentinel;\n          }\n        }\n\n        context.method = \"throw\";\n        context.arg = new TypeError(\n          \"The iterator does not provide a 'throw' method\");\n      }\n\n      return ContinueSentinel;\n    }\n\n    var record = tryCatch(method, delegate.iterator, context.arg);\n\n    if (record.type === \"throw\") {\n      context.method = \"throw\";\n      context.arg = record.arg;\n      context.delegate = null;\n      return ContinueSentinel;\n    }\n\n    var info = record.arg;\n\n    if (! info) {\n      context.method = \"throw\";\n      context.arg = new TypeError(\"iterator result is not an object\");\n      context.delegate = null;\n      return ContinueSentinel;\n    }\n\n    if (info.done) {\n      // Assign the result of the finished delegate to the temporary\n      // variable specified by delegate.resultName (see delegateYield).\n      context[delegate.resultName] = info.value;\n\n      // Resume execution at the desired location (see delegateYield).\n      context.next = delegate.nextLoc;\n\n      // If context.method was \"throw\" but the delegate handled the\n      // exception, let the outer generator proceed normally. If\n      // context.method was \"next\", forget context.arg since it has been\n      // \"consumed\" by the delegate iterator. If context.method was\n      // \"return\", allow the original .return call to continue in the\n      // outer generator.\n      if (context.method !== \"return\") {\n        context.method = \"next\";\n        context.arg = undefined;\n      }\n\n    } else {\n      // Re-yield the result returned by the delegate method.\n      return info;\n    }\n\n    // The delegate iterator is finished, so forget it and continue with\n    // the outer generator.\n    context.delegate = null;\n    return ContinueSentinel;\n  }\n\n  // Define Generator.prototype.{next,throw,return} in terms of the\n  // unified ._invoke helper method.\n  defineIteratorMethods(Gp);\n\n  Gp[toStringTagSymbol] = \"Generator\";\n\n  // A Generator should always return itself as the iterator object when the\n  // @@iterator function is called on it. Some browsers' implementations of the\n  // iterator prototype chain incorrectly implement this, causing the Generator\n  // object to not be returned from this call. This ensures that doesn't happen.\n  // See https://github.com/facebook/regenerator/issues/274 for more details.\n  Gp[iteratorSymbol] = function() {\n    return this;\n  };\n\n  Gp.toString = function() {\n    return \"[object Generator]\";\n  };\n\n  function pushTryEntry(locs) {\n    var entry = { tryLoc: locs[0] };\n\n    if (1 in locs) {\n      entry.catchLoc = locs[1];\n    }\n\n    if (2 in locs) {\n      entry.finallyLoc = locs[2];\n      entry.afterLoc = locs[3];\n    }\n\n    this.tryEntries.push(entry);\n  }\n\n  function resetTryEntry(entry) {\n    var record = entry.completion || {};\n    record.type = \"normal\";\n    delete record.arg;\n    entry.completion = record;\n  }\n\n  function Context(tryLocsList) {\n    // The root entry object (effectively a try statement without a catch\n    // or a finally block) gives us a place to store values thrown from\n    // locations where there is no enclosing try statement.\n    this.tryEntries = [{ tryLoc: \"root\" }];\n    tryLocsList.forEach(pushTryEntry, this);\n    this.reset(true);\n  }\n\n  runtime.keys = function(object) {\n    var keys = [];\n    for (var key in object) {\n      keys.push(key);\n    }\n    keys.reverse();\n\n    // Rather than returning an object with a next method, we keep\n    // things simple and return the next function itself.\n    return function next() {\n      while (keys.length) {\n        var key = keys.pop();\n        if (key in object) {\n          next.value = key;\n          next.done = false;\n          return next;\n        }\n      }\n\n      // To avoid creating an additional object, we just hang the .value\n      // and .done properties off the next function object itself. This\n      // also ensures that the minifier will not anonymize the function.\n      next.done = true;\n      return next;\n    };\n  };\n\n  function values(iterable) {\n    if (iterable) {\n      var iteratorMethod = iterable[iteratorSymbol];\n      if (iteratorMethod) {\n        return iteratorMethod.call(iterable);\n      }\n\n      if (typeof iterable.next === \"function\") {\n        return iterable;\n      }\n\n      if (!isNaN(iterable.length)) {\n        var i = -1, next = function next() {\n          while (++i < iterable.length) {\n            if (hasOwn.call(iterable, i)) {\n              next.value = iterable[i];\n              next.done = false;\n              return next;\n            }\n          }\n\n          next.value = undefined;\n          next.done = true;\n\n          return next;\n        };\n\n        return next.next = next;\n      }\n    }\n\n    // Return an iterator with no values.\n    return { next: doneResult };\n  }\n  runtime.values = values;\n\n  function doneResult() {\n    return { value: undefined, done: true };\n  }\n\n  Context.prototype = {\n    constructor: Context,\n\n    reset: function(skipTempReset) {\n      this.prev = 0;\n      this.next = 0;\n      // Resetting context._sent for legacy support of Babel's\n      // function.sent implementation.\n      this.sent = this._sent = undefined;\n      this.done = false;\n      this.delegate = null;\n\n      this.method = \"next\";\n      this.arg = undefined;\n\n      this.tryEntries.forEach(resetTryEntry);\n\n      if (!skipTempReset) {\n        for (var name in this) {\n          // Not sure about the optimal order of these conditions:\n          if (name.charAt(0) === \"t\" &&\n              hasOwn.call(this, name) &&\n              !isNaN(+name.slice(1))) {\n            this[name] = undefined;\n          }\n        }\n      }\n    },\n\n    stop: function() {\n      this.done = true;\n\n      var rootEntry = this.tryEntries[0];\n      var rootRecord = rootEntry.completion;\n      if (rootRecord.type === \"throw\") {\n        throw rootRecord.arg;\n      }\n\n      return this.rval;\n    },\n\n    dispatchException: function(exception) {\n      if (this.done) {\n        throw exception;\n      }\n\n      var context = this;\n      function handle(loc, caught) {\n        record.type = \"throw\";\n        record.arg = exception;\n        context.next = loc;\n\n        if (caught) {\n          // If the dispatched exception was caught by a catch block,\n          // then let that catch block handle the exception normally.\n          context.method = \"next\";\n          context.arg = undefined;\n        }\n\n        return !! caught;\n      }\n\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        var record = entry.completion;\n\n        if (entry.tryLoc === \"root\") {\n          // Exception thrown outside of any try block that could handle\n          // it, so set the completion value of the entire function to\n          // throw the exception.\n          return handle(\"end\");\n        }\n\n        if (entry.tryLoc <= this.prev) {\n          var hasCatch = hasOwn.call(entry, \"catchLoc\");\n          var hasFinally = hasOwn.call(entry, \"finallyLoc\");\n\n          if (hasCatch && hasFinally) {\n            if (this.prev < entry.catchLoc) {\n              return handle(entry.catchLoc, true);\n            } else if (this.prev < entry.finallyLoc) {\n              return handle(entry.finallyLoc);\n            }\n\n          } else if (hasCatch) {\n            if (this.prev < entry.catchLoc) {\n              return handle(entry.catchLoc, true);\n            }\n\n          } else if (hasFinally) {\n            if (this.prev < entry.finallyLoc) {\n              return handle(entry.finallyLoc);\n            }\n\n          } else {\n            throw new Error(\"try statement without catch or finally\");\n          }\n        }\n      }\n    },\n\n    abrupt: function(type, arg) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.tryLoc <= this.prev &&\n            hasOwn.call(entry, \"finallyLoc\") &&\n            this.prev < entry.finallyLoc) {\n          var finallyEntry = entry;\n          break;\n        }\n      }\n\n      if (finallyEntry &&\n          (type === \"break\" ||\n           type === \"continue\") &&\n          finallyEntry.tryLoc <= arg &&\n          arg <= finallyEntry.finallyLoc) {\n        // Ignore the finally entry if control is not jumping to a\n        // location outside the try/catch block.\n        finallyEntry = null;\n      }\n\n      var record = finallyEntry ? finallyEntry.completion : {};\n      record.type = type;\n      record.arg = arg;\n\n      if (finallyEntry) {\n        this.method = \"next\";\n        this.next = finallyEntry.finallyLoc;\n        return ContinueSentinel;\n      }\n\n      return this.complete(record);\n    },\n\n    complete: function(record, afterLoc) {\n      if (record.type === \"throw\") {\n        throw record.arg;\n      }\n\n      if (record.type === \"break\" ||\n          record.type === \"continue\") {\n        this.next = record.arg;\n      } else if (record.type === \"return\") {\n        this.rval = this.arg = record.arg;\n        this.method = \"return\";\n        this.next = \"end\";\n      } else if (record.type === \"normal\" && afterLoc) {\n        this.next = afterLoc;\n      }\n\n      return ContinueSentinel;\n    },\n\n    finish: function(finallyLoc) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.finallyLoc === finallyLoc) {\n          this.complete(entry.completion, entry.afterLoc);\n          resetTryEntry(entry);\n          return ContinueSentinel;\n        }\n      }\n    },\n\n    \"catch\": function(tryLoc) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.tryLoc === tryLoc) {\n          var record = entry.completion;\n          if (record.type === \"throw\") {\n            var thrown = record.arg;\n            resetTryEntry(entry);\n          }\n          return thrown;\n        }\n      }\n\n      // The context.catch method must only be called with a location\n      // argument that corresponds to a known catch block.\n      throw new Error(\"illegal catch attempt\");\n    },\n\n    delegateYield: function(iterable, resultName, nextLoc) {\n      this.delegate = {\n        iterator: values(iterable),\n        resultName: resultName,\n        nextLoc: nextLoc\n      };\n\n      if (this.method === \"next\") {\n        // Deliberately forget the last sent value so that we don't\n        // accidentally pass it on to the delegate.\n        this.arg = undefined;\n      }\n\n      return ContinueSentinel;\n    }\n  };\n})(\n  // Among the various tricks for obtaining a reference to the global\n  // object, this seems to be the most reliable technique that does not\n  // use indirect eval (which violates Content Security Policy).\n  typeof global === \"object\" ? global :\n  typeof window === \"object\" ? window :\n  typeof self === \"object\" ? self : this\n);\n\n/* WEBPACK VAR INJECTION */}.call(this, __webpack_require__(/*! ./../../../webpack/buildin/global.js */ \"./node_modules/webpack/buildin/global.js\")))\n\n/***/ }),\n\n/***/ \"./node_modules/base64-js/index.js\":\n/*!*****************************************!*\\\n  !*** ./node_modules/base64-js/index.js ***!\n  \\*****************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nexports.byteLength = byteLength\nexports.toByteArray = toByteArray\nexports.fromByteArray = fromByteArray\n\nvar lookup = []\nvar revLookup = []\nvar Arr = typeof Uint8Array !== 'undefined' ? Uint8Array : Array\n\nvar code = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'\nfor (var i = 0, len = code.length; i < len; ++i) {\n  lookup[i] = code[i]\n  revLookup[code.charCodeAt(i)] = i\n}\n\n// Support decoding URL-safe base64 strings, as Node.js does.\n// See: https://en.wikipedia.org/wiki/Base64#URL_applications\nrevLookup['-'.charCodeAt(0)] = 62\nrevLookup['_'.charCodeAt(0)] = 63\n\nfunction getLens (b64) {\n  var len = b64.length\n\n  if (len % 4 > 0) {\n    throw new Error('Invalid string. Length must be a multiple of 4')\n  }\n\n  // Trim off extra bytes after placeholder bytes are found\n  // See: https://github.com/beatgammit/base64-js/issues/42\n  var validLen = b64.indexOf('=')\n  if (validLen === -1) validLen = len\n\n  var placeHoldersLen = validLen === len\n    ? 0\n    : 4 - (validLen % 4)\n\n  return [validLen, placeHoldersLen]\n}\n\n// base64 is 4/3 + up to two characters of the original data\nfunction byteLength (b64) {\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction _byteLength (b64, validLen, placeHoldersLen) {\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction toByteArray (b64) {\n  var tmp\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n\n  var arr = new Arr(_byteLength(b64, validLen, placeHoldersLen))\n\n  var curByte = 0\n\n  // if there are placeholders, only get up to the last complete 4 chars\n  var len = placeHoldersLen > 0\n    ? validLen - 4\n    : validLen\n\n  for (var i = 0; i < len; i += 4) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 18) |\n      (revLookup[b64.charCodeAt(i + 1)] << 12) |\n      (revLookup[b64.charCodeAt(i + 2)] << 6) |\n      revLookup[b64.charCodeAt(i + 3)]\n    arr[curByte++] = (tmp >> 16) & 0xFF\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 2) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 2) |\n      (revLookup[b64.charCodeAt(i + 1)] >> 4)\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 1) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 10) |\n      (revLookup[b64.charCodeAt(i + 1)] << 4) |\n      (revLookup[b64.charCodeAt(i + 2)] >> 2)\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  return arr\n}\n\nfunction tripletToBase64 (num) {\n  return lookup[num >> 18 & 0x3F] +\n    lookup[num >> 12 & 0x3F] +\n    lookup[num >> 6 & 0x3F] +\n    lookup[num & 0x3F]\n}\n\nfunction encodeChunk (uint8, start, end) {\n  var tmp\n  var output = []\n  for (var i = start; i < end; i += 3) {\n    tmp =\n      ((uint8[i] << 16) & 0xFF0000) +\n      ((uint8[i + 1] << 8) & 0xFF00) +\n      (uint8[i + 2] & 0xFF)\n    output.push(tripletToBase64(tmp))\n  }\n  return output.join('')\n}\n\nfunction fromByteArray (uint8) {\n  var tmp\n  var len = uint8.length\n  var extraBytes = len % 3 // if we have 1 byte left, pad 2 bytes\n  var parts = []\n  var maxChunkLength = 16383 // must be multiple of 3\n\n  // go through the array every three bytes, we'll deal with trailing stuff later\n  for (var i = 0, len2 = len - extraBytes; i < len2; i += maxChunkLength) {\n    parts.push(encodeChunk(\n      uint8, i, (i + maxChunkLength) > len2 ? len2 : (i + maxChunkLength)\n    ))\n  }\n\n  // pad the end with zeros, but make sure to not forget the extra bytes\n  if (extraBytes === 1) {\n    tmp = uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 2] +\n      lookup[(tmp << 4) & 0x3F] +\n      '=='\n    )\n  } else if (extraBytes === 2) {\n    tmp = (uint8[len - 2] << 8) + uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 10] +\n      lookup[(tmp >> 4) & 0x3F] +\n      lookup[(tmp << 2) & 0x3F] +\n      '='\n    )\n  }\n\n  return parts.join('')\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/buffer/index.js\":\n/*!**************************************!*\\\n  !*** ./node_modules/buffer/index.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n/* WEBPACK VAR INJECTION */(function(global) {/*!\n * The buffer module from node.js, for the browser.\n *\n * @author   Feross Aboukhadijeh <feross@feross.org> <http://feross.org>\n * @license  MIT\n */\n/* eslint-disable no-proto */\n\n\n\nvar base64 = __webpack_require__(/*! base64-js */ \"./node_modules/base64-js/index.js\")\nvar ieee754 = __webpack_require__(/*! ieee754 */ \"./node_modules/ieee754/index.js\")\nvar isArray = __webpack_require__(/*! isarray */ \"./node_modules/buffer/node_modules/isarray/index.js\")\n\nexports.Buffer = Buffer\nexports.SlowBuffer = SlowBuffer\nexports.INSPECT_MAX_BYTES = 50\n\n/**\n * If `Buffer.TYPED_ARRAY_SUPPORT`:\n *   === true    Use Uint8Array implementation (fastest)\n *   === false   Use Object implementation (most compatible, even IE6)\n *\n * Browsers that support typed arrays are IE 10+, Firefox 4+, Chrome 7+, Safari 5.1+,\n * Opera 11.6+, iOS 4.2+.\n *\n * Due to various browser bugs, sometimes the Object implementation will be used even\n * when the browser supports typed arrays.\n *\n * Note:\n *\n *   - Firefox 4-29 lacks support for adding new properties to `Uint8Array` instances,\n *     See: https://bugzilla.mozilla.org/show_bug.cgi?id=695438.\n *\n *   - Chrome 9-10 is missing the `TypedArray.prototype.subarray` function.\n *\n *   - IE10 has a broken `TypedArray.prototype.subarray` function which returns arrays of\n *     incorrect length in some situations.\n\n * We detect these buggy browsers and set `Buffer.TYPED_ARRAY_SUPPORT` to `false` so they\n * get the Object implementation, which is slower but behaves correctly.\n */\nBuffer.TYPED_ARRAY_SUPPORT = global.TYPED_ARRAY_SUPPORT !== undefined\n  ? global.TYPED_ARRAY_SUPPORT\n  : typedArraySupport()\n\n/*\n * Export kMaxLength after typed array support is determined.\n */\nexports.kMaxLength = kMaxLength()\n\nfunction typedArraySupport () {\n  try {\n    var arr = new Uint8Array(1)\n    arr.__proto__ = {__proto__: Uint8Array.prototype, foo: function () { return 42 }}\n    return arr.foo() === 42 && // typed array instances can be augmented\n        typeof arr.subarray === 'function' && // chrome 9-10 lack `subarray`\n        arr.subarray(1, 1).byteLength === 0 // ie10 has broken `subarray`\n  } catch (e) {\n    return false\n  }\n}\n\nfunction kMaxLength () {\n  return Buffer.TYPED_ARRAY_SUPPORT\n    ? 0x7fffffff\n    : 0x3fffffff\n}\n\nfunction createBuffer (that, length) {\n  if (kMaxLength() < length) {\n    throw new RangeError('Invalid typed array length')\n  }\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = new Uint8Array(length)\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    if (that === null) {\n      that = new Buffer(length)\n    }\n    that.length = length\n  }\n\n  return that\n}\n\n/**\n * The Buffer constructor returns instances of `Uint8Array` that have their\n * prototype changed to `Buffer.prototype`. Furthermore, `Buffer` is a subclass of\n * `Uint8Array`, so the returned instances will have all the node `Buffer` methods\n * and the `Uint8Array` methods. Square bracket notation works as expected -- it\n * returns a single octet.\n *\n * The `Uint8Array` prototype remains unmodified.\n */\n\nfunction Buffer (arg, encodingOrOffset, length) {\n  if (!Buffer.TYPED_ARRAY_SUPPORT && !(this instanceof Buffer)) {\n    return new Buffer(arg, encodingOrOffset, length)\n  }\n\n  // Common case.\n  if (typeof arg === 'number') {\n    if (typeof encodingOrOffset === 'string') {\n      throw new Error(\n        'If encoding is specified then the first argument must be a string'\n      )\n    }\n    return allocUnsafe(this, arg)\n  }\n  return from(this, arg, encodingOrOffset, length)\n}\n\nBuffer.poolSize = 8192 // not used by this implementation\n\n// TODO: Legacy, not needed anymore. Remove in next major version.\nBuffer._augment = function (arr) {\n  arr.__proto__ = Buffer.prototype\n  return arr\n}\n\nfunction from (that, value, encodingOrOffset, length) {\n  if (typeof value === 'number') {\n    throw new TypeError('\"value\" argument must not be a number')\n  }\n\n  if (typeof ArrayBuffer !== 'undefined' && value instanceof ArrayBuffer) {\n    return fromArrayBuffer(that, value, encodingOrOffset, length)\n  }\n\n  if (typeof value === 'string') {\n    return fromString(that, value, encodingOrOffset)\n  }\n\n  return fromObject(that, value)\n}\n\n/**\n * Functionally equivalent to Buffer(arg, encoding) but throws a TypeError\n * if value is a number.\n * Buffer.from(str[, encoding])\n * Buffer.from(array)\n * Buffer.from(buffer)\n * Buffer.from(arrayBuffer[, byteOffset[, length]])\n **/\nBuffer.from = function (value, encodingOrOffset, length) {\n  return from(null, value, encodingOrOffset, length)\n}\n\nif (Buffer.TYPED_ARRAY_SUPPORT) {\n  Buffer.prototype.__proto__ = Uint8Array.prototype\n  Buffer.__proto__ = Uint8Array\n  if (typeof Symbol !== 'undefined' && Symbol.species &&\n      Buffer[Symbol.species] === Buffer) {\n    // Fix subarray() in ES2016. See: https://github.com/feross/buffer/pull/97\n    Object.defineProperty(Buffer, Symbol.species, {\n      value: null,\n      configurable: true\n    })\n  }\n}\n\nfunction assertSize (size) {\n  if (typeof size !== 'number') {\n    throw new TypeError('\"size\" argument must be a number')\n  } else if (size < 0) {\n    throw new RangeError('\"size\" argument must not be negative')\n  }\n}\n\nfunction alloc (that, size, fill, encoding) {\n  assertSize(size)\n  if (size <= 0) {\n    return createBuffer(that, size)\n  }\n  if (fill !== undefined) {\n    // Only pay attention to encoding if it's a string. This\n    // prevents accidentally sending in a number that would\n    // be interpretted as a start offset.\n    return typeof encoding === 'string'\n      ? createBuffer(that, size).fill(fill, encoding)\n      : createBuffer(that, size).fill(fill)\n  }\n  return createBuffer(that, size)\n}\n\n/**\n * Creates a new filled Buffer instance.\n * alloc(size[, fill[, encoding]])\n **/\nBuffer.alloc = function (size, fill, encoding) {\n  return alloc(null, size, fill, encoding)\n}\n\nfunction allocUnsafe (that, size) {\n  assertSize(size)\n  that = createBuffer(that, size < 0 ? 0 : checked(size) | 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) {\n    for (var i = 0; i < size; ++i) {\n      that[i] = 0\n    }\n  }\n  return that\n}\n\n/**\n * Equivalent to Buffer(num), by default creates a non-zero-filled Buffer instance.\n * */\nBuffer.allocUnsafe = function (size) {\n  return allocUnsafe(null, size)\n}\n/**\n * Equivalent to SlowBuffer(num), by default creates a non-zero-filled Buffer instance.\n */\nBuffer.allocUnsafeSlow = function (size) {\n  return allocUnsafe(null, size)\n}\n\nfunction fromString (that, string, encoding) {\n  if (typeof encoding !== 'string' || encoding === '') {\n    encoding = 'utf8'\n  }\n\n  if (!Buffer.isEncoding(encoding)) {\n    throw new TypeError('\"encoding\" must be a valid string encoding')\n  }\n\n  var length = byteLength(string, encoding) | 0\n  that = createBuffer(that, length)\n\n  var actual = that.write(string, encoding)\n\n  if (actual !== length) {\n    // Writing a hex string, for example, that contains invalid characters will\n    // cause everything after the first invalid character to be ignored. (e.g.\n    // 'abxxcd' will be treated as 'ab')\n    that = that.slice(0, actual)\n  }\n\n  return that\n}\n\nfunction fromArrayLike (that, array) {\n  var length = array.length < 0 ? 0 : checked(array.length) | 0\n  that = createBuffer(that, length)\n  for (var i = 0; i < length; i += 1) {\n    that[i] = array[i] & 255\n  }\n  return that\n}\n\nfunction fromArrayBuffer (that, array, byteOffset, length) {\n  array.byteLength // this throws if `array` is not a valid ArrayBuffer\n\n  if (byteOffset < 0 || array.byteLength < byteOffset) {\n    throw new RangeError('\\'offset\\' is out of bounds')\n  }\n\n  if (array.byteLength < byteOffset + (length || 0)) {\n    throw new RangeError('\\'length\\' is out of bounds')\n  }\n\n  if (byteOffset === undefined && length === undefined) {\n    array = new Uint8Array(array)\n  } else if (length === undefined) {\n    array = new Uint8Array(array, byteOffset)\n  } else {\n    array = new Uint8Array(array, byteOffset, length)\n  }\n\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = array\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    that = fromArrayLike(that, array)\n  }\n  return that\n}\n\nfunction fromObject (that, obj) {\n  if (Buffer.isBuffer(obj)) {\n    var len = checked(obj.length) | 0\n    that = createBuffer(that, len)\n\n    if (that.length === 0) {\n      return that\n    }\n\n    obj.copy(that, 0, 0, len)\n    return that\n  }\n\n  if (obj) {\n    if ((typeof ArrayBuffer !== 'undefined' &&\n        obj.buffer instanceof ArrayBuffer) || 'length' in obj) {\n      if (typeof obj.length !== 'number' || isnan(obj.length)) {\n        return createBuffer(that, 0)\n      }\n      return fromArrayLike(that, obj)\n    }\n\n    if (obj.type === 'Buffer' && isArray(obj.data)) {\n      return fromArrayLike(that, obj.data)\n    }\n  }\n\n  throw new TypeError('First argument must be a string, Buffer, ArrayBuffer, Array, or array-like object.')\n}\n\nfunction checked (length) {\n  // Note: cannot use `length < kMaxLength()` here because that fails when\n  // length is NaN (which is otherwise coerced to zero.)\n  if (length >= kMaxLength()) {\n    throw new RangeError('Attempt to allocate Buffer larger than maximum ' +\n                         'size: 0x' + kMaxLength().toString(16) + ' bytes')\n  }\n  return length | 0\n}\n\nfunction SlowBuffer (length) {\n  if (+length != length) { // eslint-disable-line eqeqeq\n    length = 0\n  }\n  return Buffer.alloc(+length)\n}\n\nBuffer.isBuffer = function isBuffer (b) {\n  return !!(b != null && b._isBuffer)\n}\n\nBuffer.compare = function compare (a, b) {\n  if (!Buffer.isBuffer(a) || !Buffer.isBuffer(b)) {\n    throw new TypeError('Arguments must be Buffers')\n  }\n\n  if (a === b) return 0\n\n  var x = a.length\n  var y = b.length\n\n  for (var i = 0, len = Math.min(x, y); i < len; ++i) {\n    if (a[i] !== b[i]) {\n      x = a[i]\n      y = b[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\nBuffer.isEncoding = function isEncoding (encoding) {\n  switch (String(encoding).toLowerCase()) {\n    case 'hex':\n    case 'utf8':\n    case 'utf-8':\n    case 'ascii':\n    case 'latin1':\n    case 'binary':\n    case 'base64':\n    case 'ucs2':\n    case 'ucs-2':\n    case 'utf16le':\n    case 'utf-16le':\n      return true\n    default:\n      return false\n  }\n}\n\nBuffer.concat = function concat (list, length) {\n  if (!isArray(list)) {\n    throw new TypeError('\"list\" argument must be an Array of Buffers')\n  }\n\n  if (list.length === 0) {\n    return Buffer.alloc(0)\n  }\n\n  var i\n  if (length === undefined) {\n    length = 0\n    for (i = 0; i < list.length; ++i) {\n      length += list[i].length\n    }\n  }\n\n  var buffer = Buffer.allocUnsafe(length)\n  var pos = 0\n  for (i = 0; i < list.length; ++i) {\n    var buf = list[i]\n    if (!Buffer.isBuffer(buf)) {\n      throw new TypeError('\"list\" argument must be an Array of Buffers')\n    }\n    buf.copy(buffer, pos)\n    pos += buf.length\n  }\n  return buffer\n}\n\nfunction byteLength (string, encoding) {\n  if (Buffer.isBuffer(string)) {\n    return string.length\n  }\n  if (typeof ArrayBuffer !== 'undefined' && typeof ArrayBuffer.isView === 'function' &&\n      (ArrayBuffer.isView(string) || string instanceof ArrayBuffer)) {\n    return string.byteLength\n  }\n  if (typeof string !== 'string') {\n    string = '' + string\n  }\n\n  var len = string.length\n  if (len === 0) return 0\n\n  // Use a for loop to avoid recursion\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'ascii':\n      case 'latin1':\n      case 'binary':\n        return len\n      case 'utf8':\n      case 'utf-8':\n      case undefined:\n        return utf8ToBytes(string).length\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return len * 2\n      case 'hex':\n        return len >>> 1\n      case 'base64':\n        return base64ToBytes(string).length\n      default:\n        if (loweredCase) return utf8ToBytes(string).length // assume utf8\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\nBuffer.byteLength = byteLength\n\nfunction slowToString (encoding, start, end) {\n  var loweredCase = false\n\n  // No need to verify that \"this.length <= MAX_UINT32\" since it's a read-only\n  // property of a typed array.\n\n  // This behaves neither like String nor Uint8Array in that we set start/end\n  // to their upper/lower bounds if the value passed is out of range.\n  // undefined is handled specially as per ECMA-262 6th Edition,\n  // Section 13.3.3.7 Runtime Semantics: KeyedBindingInitialization.\n  if (start === undefined || start < 0) {\n    start = 0\n  }\n  // Return early if start > this.length. Done here to prevent potential uint32\n  // coercion fail below.\n  if (start > this.length) {\n    return ''\n  }\n\n  if (end === undefined || end > this.length) {\n    end = this.length\n  }\n\n  if (end <= 0) {\n    return ''\n  }\n\n  // Force coersion to uint32. This will also coerce falsey/NaN values to 0.\n  end >>>= 0\n  start >>>= 0\n\n  if (end <= start) {\n    return ''\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  while (true) {\n    switch (encoding) {\n      case 'hex':\n        return hexSlice(this, start, end)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Slice(this, start, end)\n\n      case 'ascii':\n        return asciiSlice(this, start, end)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Slice(this, start, end)\n\n      case 'base64':\n        return base64Slice(this, start, end)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return utf16leSlice(this, start, end)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = (encoding + '').toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\n// The property is used by `Buffer.isBuffer` and `is-buffer` (in Safari 5-7) to detect\n// Buffer instances.\nBuffer.prototype._isBuffer = true\n\nfunction swap (b, n, m) {\n  var i = b[n]\n  b[n] = b[m]\n  b[m] = i\n}\n\nBuffer.prototype.swap16 = function swap16 () {\n  var len = this.length\n  if (len % 2 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 16-bits')\n  }\n  for (var i = 0; i < len; i += 2) {\n    swap(this, i, i + 1)\n  }\n  return this\n}\n\nBuffer.prototype.swap32 = function swap32 () {\n  var len = this.length\n  if (len % 4 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 32-bits')\n  }\n  for (var i = 0; i < len; i += 4) {\n    swap(this, i, i + 3)\n    swap(this, i + 1, i + 2)\n  }\n  return this\n}\n\nBuffer.prototype.swap64 = function swap64 () {\n  var len = this.length\n  if (len % 8 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 64-bits')\n  }\n  for (var i = 0; i < len; i += 8) {\n    swap(this, i, i + 7)\n    swap(this, i + 1, i + 6)\n    swap(this, i + 2, i + 5)\n    swap(this, i + 3, i + 4)\n  }\n  return this\n}\n\nBuffer.prototype.toString = function toString () {\n  var length = this.length | 0\n  if (length === 0) return ''\n  if (arguments.length === 0) return utf8Slice(this, 0, length)\n  return slowToString.apply(this, arguments)\n}\n\nBuffer.prototype.equals = function equals (b) {\n  if (!Buffer.isBuffer(b)) throw new TypeError('Argument must be a Buffer')\n  if (this === b) return true\n  return Buffer.compare(this, b) === 0\n}\n\nBuffer.prototype.inspect = function inspect () {\n  var str = ''\n  var max = exports.INSPECT_MAX_BYTES\n  if (this.length > 0) {\n    str = this.toString('hex', 0, max).match(/.{2}/g).join(' ')\n    if (this.length > max) str += ' ... '\n  }\n  return '<Buffer ' + str + '>'\n}\n\nBuffer.prototype.compare = function compare (target, start, end, thisStart, thisEnd) {\n  if (!Buffer.isBuffer(target)) {\n    throw new TypeError('Argument must be a Buffer')\n  }\n\n  if (start === undefined) {\n    start = 0\n  }\n  if (end === undefined) {\n    end = target ? target.length : 0\n  }\n  if (thisStart === undefined) {\n    thisStart = 0\n  }\n  if (thisEnd === undefined) {\n    thisEnd = this.length\n  }\n\n  if (start < 0 || end > target.length || thisStart < 0 || thisEnd > this.length) {\n    throw new RangeError('out of range index')\n  }\n\n  if (thisStart >= thisEnd && start >= end) {\n    return 0\n  }\n  if (thisStart >= thisEnd) {\n    return -1\n  }\n  if (start >= end) {\n    return 1\n  }\n\n  start >>>= 0\n  end >>>= 0\n  thisStart >>>= 0\n  thisEnd >>>= 0\n\n  if (this === target) return 0\n\n  var x = thisEnd - thisStart\n  var y = end - start\n  var len = Math.min(x, y)\n\n  var thisCopy = this.slice(thisStart, thisEnd)\n  var targetCopy = target.slice(start, end)\n\n  for (var i = 0; i < len; ++i) {\n    if (thisCopy[i] !== targetCopy[i]) {\n      x = thisCopy[i]\n      y = targetCopy[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\n// Finds either the first index of `val` in `buffer` at offset >= `byteOffset`,\n// OR the last index of `val` in `buffer` at offset <= `byteOffset`.\n//\n// Arguments:\n// - buffer - a Buffer to search\n// - val - a string, Buffer, or number\n// - byteOffset - an index into `buffer`; will be clamped to an int32\n// - encoding - an optional encoding, relevant is val is a string\n// - dir - true for indexOf, false for lastIndexOf\nfunction bidirectionalIndexOf (buffer, val, byteOffset, encoding, dir) {\n  // Empty buffer means no match\n  if (buffer.length === 0) return -1\n\n  // Normalize byteOffset\n  if (typeof byteOffset === 'string') {\n    encoding = byteOffset\n    byteOffset = 0\n  } else if (byteOffset > 0x7fffffff) {\n    byteOffset = 0x7fffffff\n  } else if (byteOffset < -0x80000000) {\n    byteOffset = -0x80000000\n  }\n  byteOffset = +byteOffset  // Coerce to Number.\n  if (isNaN(byteOffset)) {\n    // byteOffset: it it's undefined, null, NaN, \"foo\", etc, search whole buffer\n    byteOffset = dir ? 0 : (buffer.length - 1)\n  }\n\n  // Normalize byteOffset: negative offsets start from the end of the buffer\n  if (byteOffset < 0) byteOffset = buffer.length + byteOffset\n  if (byteOffset >= buffer.length) {\n    if (dir) return -1\n    else byteOffset = buffer.length - 1\n  } else if (byteOffset < 0) {\n    if (dir) byteOffset = 0\n    else return -1\n  }\n\n  // Normalize val\n  if (typeof val === 'string') {\n    val = Buffer.from(val, encoding)\n  }\n\n  // Finally, search either indexOf (if dir is true) or lastIndexOf\n  if (Buffer.isBuffer(val)) {\n    // Special case: looking for empty string/buffer always fails\n    if (val.length === 0) {\n      return -1\n    }\n    return arrayIndexOf(buffer, val, byteOffset, encoding, dir)\n  } else if (typeof val === 'number') {\n    val = val & 0xFF // Search for a byte value [0-255]\n    if (Buffer.TYPED_ARRAY_SUPPORT &&\n        typeof Uint8Array.prototype.indexOf === 'function') {\n      if (dir) {\n        return Uint8Array.prototype.indexOf.call(buffer, val, byteOffset)\n      } else {\n        return Uint8Array.prototype.lastIndexOf.call(buffer, val, byteOffset)\n      }\n    }\n    return arrayIndexOf(buffer, [ val ], byteOffset, encoding, dir)\n  }\n\n  throw new TypeError('val must be string, number or Buffer')\n}\n\nfunction arrayIndexOf (arr, val, byteOffset, encoding, dir) {\n  var indexSize = 1\n  var arrLength = arr.length\n  var valLength = val.length\n\n  if (encoding !== undefined) {\n    encoding = String(encoding).toLowerCase()\n    if (encoding === 'ucs2' || encoding === 'ucs-2' ||\n        encoding === 'utf16le' || encoding === 'utf-16le') {\n      if (arr.length < 2 || val.length < 2) {\n        return -1\n      }\n      indexSize = 2\n      arrLength /= 2\n      valLength /= 2\n      byteOffset /= 2\n    }\n  }\n\n  function read (buf, i) {\n    if (indexSize === 1) {\n      return buf[i]\n    } else {\n      return buf.readUInt16BE(i * indexSize)\n    }\n  }\n\n  var i\n  if (dir) {\n    var foundIndex = -1\n    for (i = byteOffset; i < arrLength; i++) {\n      if (read(arr, i) === read(val, foundIndex === -1 ? 0 : i - foundIndex)) {\n        if (foundIndex === -1) foundIndex = i\n        if (i - foundIndex + 1 === valLength) return foundIndex * indexSize\n      } else {\n        if (foundIndex !== -1) i -= i - foundIndex\n        foundIndex = -1\n      }\n    }\n  } else {\n    if (byteOffset + valLength > arrLength) byteOffset = arrLength - valLength\n    for (i = byteOffset; i >= 0; i--) {\n      var found = true\n      for (var j = 0; j < valLength; j++) {\n        if (read(arr, i + j) !== read(val, j)) {\n          found = false\n          break\n        }\n      }\n      if (found) return i\n    }\n  }\n\n  return -1\n}\n\nBuffer.prototype.includes = function includes (val, byteOffset, encoding) {\n  return this.indexOf(val, byteOffset, encoding) !== -1\n}\n\nBuffer.prototype.indexOf = function indexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, true)\n}\n\nBuffer.prototype.lastIndexOf = function lastIndexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, false)\n}\n\nfunction hexWrite (buf, string, offset, length) {\n  offset = Number(offset) || 0\n  var remaining = buf.length - offset\n  if (!length) {\n    length = remaining\n  } else {\n    length = Number(length)\n    if (length > remaining) {\n      length = remaining\n    }\n  }\n\n  // must be an even number of digits\n  var strLen = string.length\n  if (strLen % 2 !== 0) throw new TypeError('Invalid hex string')\n\n  if (length > strLen / 2) {\n    length = strLen / 2\n  }\n  for (var i = 0; i < length; ++i) {\n    var parsed = parseInt(string.substr(i * 2, 2), 16)\n    if (isNaN(parsed)) return i\n    buf[offset + i] = parsed\n  }\n  return i\n}\n\nfunction utf8Write (buf, string, offset, length) {\n  return blitBuffer(utf8ToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nfunction asciiWrite (buf, string, offset, length) {\n  return blitBuffer(asciiToBytes(string), buf, offset, length)\n}\n\nfunction latin1Write (buf, string, offset, length) {\n  return asciiWrite(buf, string, offset, length)\n}\n\nfunction base64Write (buf, string, offset, length) {\n  return blitBuffer(base64ToBytes(string), buf, offset, length)\n}\n\nfunction ucs2Write (buf, string, offset, length) {\n  return blitBuffer(utf16leToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nBuffer.prototype.write = function write (string, offset, length, encoding) {\n  // Buffer#write(string)\n  if (offset === undefined) {\n    encoding = 'utf8'\n    length = this.length\n    offset = 0\n  // Buffer#write(string, encoding)\n  } else if (length === undefined && typeof offset === 'string') {\n    encoding = offset\n    length = this.length\n    offset = 0\n  // Buffer#write(string, offset[, length][, encoding])\n  } else if (isFinite(offset)) {\n    offset = offset | 0\n    if (isFinite(length)) {\n      length = length | 0\n      if (encoding === undefined) encoding = 'utf8'\n    } else {\n      encoding = length\n      length = undefined\n    }\n  // legacy write(string, encoding, offset, length) - remove in v0.13\n  } else {\n    throw new Error(\n      'Buffer.write(string, encoding, offset[, length]) is no longer supported'\n    )\n  }\n\n  var remaining = this.length - offset\n  if (length === undefined || length > remaining) length = remaining\n\n  if ((string.length > 0 && (length < 0 || offset < 0)) || offset > this.length) {\n    throw new RangeError('Attempt to write outside buffer bounds')\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'hex':\n        return hexWrite(this, string, offset, length)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Write(this, string, offset, length)\n\n      case 'ascii':\n        return asciiWrite(this, string, offset, length)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Write(this, string, offset, length)\n\n      case 'base64':\n        // Warning: maxLength not taken into account in base64Write\n        return base64Write(this, string, offset, length)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return ucs2Write(this, string, offset, length)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\nBuffer.prototype.toJSON = function toJSON () {\n  return {\n    type: 'Buffer',\n    data: Array.prototype.slice.call(this._arr || this, 0)\n  }\n}\n\nfunction base64Slice (buf, start, end) {\n  if (start === 0 && end === buf.length) {\n    return base64.fromByteArray(buf)\n  } else {\n    return base64.fromByteArray(buf.slice(start, end))\n  }\n}\n\nfunction utf8Slice (buf, start, end) {\n  end = Math.min(buf.length, end)\n  var res = []\n\n  var i = start\n  while (i < end) {\n    var firstByte = buf[i]\n    var codePoint = null\n    var bytesPerSequence = (firstByte > 0xEF) ? 4\n      : (firstByte > 0xDF) ? 3\n      : (firstByte > 0xBF) ? 2\n      : 1\n\n    if (i + bytesPerSequence <= end) {\n      var secondByte, thirdByte, fourthByte, tempCodePoint\n\n      switch (bytesPerSequence) {\n        case 1:\n          if (firstByte < 0x80) {\n            codePoint = firstByte\n          }\n          break\n        case 2:\n          secondByte = buf[i + 1]\n          if ((secondByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0x1F) << 0x6 | (secondByte & 0x3F)\n            if (tempCodePoint > 0x7F) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 3:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0xC | (secondByte & 0x3F) << 0x6 | (thirdByte & 0x3F)\n            if (tempCodePoint > 0x7FF && (tempCodePoint < 0xD800 || tempCodePoint > 0xDFFF)) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 4:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          fourthByte = buf[i + 3]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80 && (fourthByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0x12 | (secondByte & 0x3F) << 0xC | (thirdByte & 0x3F) << 0x6 | (fourthByte & 0x3F)\n            if (tempCodePoint > 0xFFFF && tempCodePoint < 0x110000) {\n              codePoint = tempCodePoint\n            }\n          }\n      }\n    }\n\n    if (codePoint === null) {\n      // we did not generate a valid codePoint so insert a\n      // replacement char (U+FFFD) and advance only 1 byte\n      codePoint = 0xFFFD\n      bytesPerSequence = 1\n    } else if (codePoint > 0xFFFF) {\n      // encode to utf16 (surrogate pair dance)\n      codePoint -= 0x10000\n      res.push(codePoint >>> 10 & 0x3FF | 0xD800)\n      codePoint = 0xDC00 | codePoint & 0x3FF\n    }\n\n    res.push(codePoint)\n    i += bytesPerSequence\n  }\n\n  return decodeCodePointsArray(res)\n}\n\n// Based on http://stackoverflow.com/a/22747272/680742, the browser with\n// the lowest limit is Chrome, with 0x10000 args.\n// We go 1 magnitude less, for safety\nvar MAX_ARGUMENTS_LENGTH = 0x1000\n\nfunction decodeCodePointsArray (codePoints) {\n  var len = codePoints.length\n  if (len <= MAX_ARGUMENTS_LENGTH) {\n    return String.fromCharCode.apply(String, codePoints) // avoid extra slice()\n  }\n\n  // Decode in chunks to avoid \"call stack size exceeded\".\n  var res = ''\n  var i = 0\n  while (i < len) {\n    res += String.fromCharCode.apply(\n      String,\n      codePoints.slice(i, i += MAX_ARGUMENTS_LENGTH)\n    )\n  }\n  return res\n}\n\nfunction asciiSlice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i] & 0x7F)\n  }\n  return ret\n}\n\nfunction latin1Slice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i])\n  }\n  return ret\n}\n\nfunction hexSlice (buf, start, end) {\n  var len = buf.length\n\n  if (!start || start < 0) start = 0\n  if (!end || end < 0 || end > len) end = len\n\n  var out = ''\n  for (var i = start; i < end; ++i) {\n    out += toHex(buf[i])\n  }\n  return out\n}\n\nfunction utf16leSlice (buf, start, end) {\n  var bytes = buf.slice(start, end)\n  var res = ''\n  for (var i = 0; i < bytes.length; i += 2) {\n    res += String.fromCharCode(bytes[i] + bytes[i + 1] * 256)\n  }\n  return res\n}\n\nBuffer.prototype.slice = function slice (start, end) {\n  var len = this.length\n  start = ~~start\n  end = end === undefined ? len : ~~end\n\n  if (start < 0) {\n    start += len\n    if (start < 0) start = 0\n  } else if (start > len) {\n    start = len\n  }\n\n  if (end < 0) {\n    end += len\n    if (end < 0) end = 0\n  } else if (end > len) {\n    end = len\n  }\n\n  if (end < start) end = start\n\n  var newBuf\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    newBuf = this.subarray(start, end)\n    newBuf.__proto__ = Buffer.prototype\n  } else {\n    var sliceLen = end - start\n    newBuf = new Buffer(sliceLen, undefined)\n    for (var i = 0; i < sliceLen; ++i) {\n      newBuf[i] = this[i + start]\n    }\n  }\n\n  return newBuf\n}\n\n/*\n * Need to make sure that buffer isn't trying to write out of bounds.\n */\nfunction checkOffset (offset, ext, length) {\n  if ((offset % 1) !== 0 || offset < 0) throw new RangeError('offset is not uint')\n  if (offset + ext > length) throw new RangeError('Trying to access beyond buffer length')\n}\n\nBuffer.prototype.readUIntLE = function readUIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUIntBE = function readUIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    checkOffset(offset, byteLength, this.length)\n  }\n\n  var val = this[offset + --byteLength]\n  var mul = 1\n  while (byteLength > 0 && (mul *= 0x100)) {\n    val += this[offset + --byteLength] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUInt8 = function readUInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  return this[offset]\n}\n\nBuffer.prototype.readUInt16LE = function readUInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return this[offset] | (this[offset + 1] << 8)\n}\n\nBuffer.prototype.readUInt16BE = function readUInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return (this[offset] << 8) | this[offset + 1]\n}\n\nBuffer.prototype.readUInt32LE = function readUInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return ((this[offset]) |\n      (this[offset + 1] << 8) |\n      (this[offset + 2] << 16)) +\n      (this[offset + 3] * 0x1000000)\n}\n\nBuffer.prototype.readUInt32BE = function readUInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] * 0x1000000) +\n    ((this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    this[offset + 3])\n}\n\nBuffer.prototype.readIntLE = function readIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readIntBE = function readIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var i = byteLength\n  var mul = 1\n  var val = this[offset + --i]\n  while (i > 0 && (mul *= 0x100)) {\n    val += this[offset + --i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readInt8 = function readInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  if (!(this[offset] & 0x80)) return (this[offset])\n  return ((0xff - this[offset] + 1) * -1)\n}\n\nBuffer.prototype.readInt16LE = function readInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset] | (this[offset + 1] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt16BE = function readInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset + 1] | (this[offset] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt32LE = function readInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset]) |\n    (this[offset + 1] << 8) |\n    (this[offset + 2] << 16) |\n    (this[offset + 3] << 24)\n}\n\nBuffer.prototype.readInt32BE = function readInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] << 24) |\n    (this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    (this[offset + 3])\n}\n\nBuffer.prototype.readFloatLE = function readFloatLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, true, 23, 4)\n}\n\nBuffer.prototype.readFloatBE = function readFloatBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, false, 23, 4)\n}\n\nBuffer.prototype.readDoubleLE = function readDoubleLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, true, 52, 8)\n}\n\nBuffer.prototype.readDoubleBE = function readDoubleBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, false, 52, 8)\n}\n\nfunction checkInt (buf, value, offset, ext, max, min) {\n  if (!Buffer.isBuffer(buf)) throw new TypeError('\"buffer\" argument must be a Buffer instance')\n  if (value > max || value < min) throw new RangeError('\"value\" argument is out of bounds')\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n}\n\nBuffer.prototype.writeUIntLE = function writeUIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var mul = 1\n  var i = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUIntBE = function writeUIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUInt8 = function writeUInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0xff, 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nfunction objectWriteUInt16 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 2); i < j; ++i) {\n    buf[offset + i] = (value & (0xff << (8 * (littleEndian ? i : 1 - i)))) >>>\n      (littleEndian ? i : 1 - i) * 8\n  }\n}\n\nBuffer.prototype.writeUInt16LE = function writeUInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeUInt16BE = function writeUInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nfunction objectWriteUInt32 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffffffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 4); i < j; ++i) {\n    buf[offset + i] = (value >>> (littleEndian ? i : 3 - i) * 8) & 0xff\n  }\n}\n\nBuffer.prototype.writeUInt32LE = function writeUInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset + 3] = (value >>> 24)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 1] = (value >>> 8)\n    this[offset] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeUInt32BE = function writeUInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeIntLE = function writeIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = 0\n  var mul = 1\n  var sub = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i - 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeIntBE = function writeIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  var sub = 0\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i + 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeInt8 = function writeInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0x7f, -0x80)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  if (value < 0) value = 0xff + value + 1\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nBuffer.prototype.writeInt16LE = function writeInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt16BE = function writeInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt32LE = function writeInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 3] = (value >>> 24)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeInt32BE = function writeInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (value < 0) value = 0xffffffff + value + 1\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nfunction checkIEEE754 (buf, value, offset, ext, max, min) {\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n  if (offset < 0) throw new RangeError('Index out of range')\n}\n\nfunction writeFloat (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 4, 3.4028234663852886e+38, -3.4028234663852886e+38)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 23, 4)\n  return offset + 4\n}\n\nBuffer.prototype.writeFloatLE = function writeFloatLE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeFloatBE = function writeFloatBE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, false, noAssert)\n}\n\nfunction writeDouble (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 8, 1.7976931348623157E+308, -1.7976931348623157E+308)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 52, 8)\n  return offset + 8\n}\n\nBuffer.prototype.writeDoubleLE = function writeDoubleLE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeDoubleBE = function writeDoubleBE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, false, noAssert)\n}\n\n// copy(targetBuffer, targetStart=0, sourceStart=0, sourceEnd=buffer.length)\nBuffer.prototype.copy = function copy (target, targetStart, start, end) {\n  if (!start) start = 0\n  if (!end && end !== 0) end = this.length\n  if (targetStart >= target.length) targetStart = target.length\n  if (!targetStart) targetStart = 0\n  if (end > 0 && end < start) end = start\n\n  // Copy 0 bytes; we're done\n  if (end === start) return 0\n  if (target.length === 0 || this.length === 0) return 0\n\n  // Fatal error conditions\n  if (targetStart < 0) {\n    throw new RangeError('targetStart out of bounds')\n  }\n  if (start < 0 || start >= this.length) throw new RangeError('sourceStart out of bounds')\n  if (end < 0) throw new RangeError('sourceEnd out of bounds')\n\n  // Are we oob?\n  if (end > this.length) end = this.length\n  if (target.length - targetStart < end - start) {\n    end = target.length - targetStart + start\n  }\n\n  var len = end - start\n  var i\n\n  if (this === target && start < targetStart && targetStart < end) {\n    // descending copy from end\n    for (i = len - 1; i >= 0; --i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else if (len < 1000 || !Buffer.TYPED_ARRAY_SUPPORT) {\n    // ascending copy from start\n    for (i = 0; i < len; ++i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else {\n    Uint8Array.prototype.set.call(\n      target,\n      this.subarray(start, start + len),\n      targetStart\n    )\n  }\n\n  return len\n}\n\n// Usage:\n//    buffer.fill(number[, offset[, end]])\n//    buffer.fill(buffer[, offset[, end]])\n//    buffer.fill(string[, offset[, end]][, encoding])\nBuffer.prototype.fill = function fill (val, start, end, encoding) {\n  // Handle string cases:\n  if (typeof val === 'string') {\n    if (typeof start === 'string') {\n      encoding = start\n      start = 0\n      end = this.length\n    } else if (typeof end === 'string') {\n      encoding = end\n      end = this.length\n    }\n    if (val.length === 1) {\n      var code = val.charCodeAt(0)\n      if (code < 256) {\n        val = code\n      }\n    }\n    if (encoding !== undefined && typeof encoding !== 'string') {\n      throw new TypeError('encoding must be a string')\n    }\n    if (typeof encoding === 'string' && !Buffer.isEncoding(encoding)) {\n      throw new TypeError('Unknown encoding: ' + encoding)\n    }\n  } else if (typeof val === 'number') {\n    val = val & 255\n  }\n\n  // Invalid ranges are not set to a default, so can range check early.\n  if (start < 0 || this.length < start || this.length < end) {\n    throw new RangeError('Out of range index')\n  }\n\n  if (end <= start) {\n    return this\n  }\n\n  start = start >>> 0\n  end = end === undefined ? this.length : end >>> 0\n\n  if (!val) val = 0\n\n  var i\n  if (typeof val === 'number') {\n    for (i = start; i < end; ++i) {\n      this[i] = val\n    }\n  } else {\n    var bytes = Buffer.isBuffer(val)\n      ? val\n      : utf8ToBytes(new Buffer(val, encoding).toString())\n    var len = bytes.length\n    for (i = 0; i < end - start; ++i) {\n      this[i + start] = bytes[i % len]\n    }\n  }\n\n  return this\n}\n\n// HELPER FUNCTIONS\n// ================\n\nvar INVALID_BASE64_RE = /[^+\\/0-9A-Za-z-_]/g\n\nfunction base64clean (str) {\n  // Node strips out invalid characters like \\n and \\t from the string, base64-js does not\n  str = stringtrim(str).replace(INVALID_BASE64_RE, '')\n  // Node converts strings with length < 2 to ''\n  if (str.length < 2) return ''\n  // Node allows for non-padded base64 strings (missing trailing ===), base64-js does not\n  while (str.length % 4 !== 0) {\n    str = str + '='\n  }\n  return str\n}\n\nfunction stringtrim (str) {\n  if (str.trim) return str.trim()\n  return str.replace(/^\\s+|\\s+$/g, '')\n}\n\nfunction toHex (n) {\n  if (n < 16) return '0' + n.toString(16)\n  return n.toString(16)\n}\n\nfunction utf8ToBytes (string, units) {\n  units = units || Infinity\n  var codePoint\n  var length = string.length\n  var leadSurrogate = null\n  var bytes = []\n\n  for (var i = 0; i < length; ++i) {\n    codePoint = string.charCodeAt(i)\n\n    // is surrogate component\n    if (codePoint > 0xD7FF && codePoint < 0xE000) {\n      // last char was a lead\n      if (!leadSurrogate) {\n        // no lead yet\n        if (codePoint > 0xDBFF) {\n          // unexpected trail\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        } else if (i + 1 === length) {\n          // unpaired lead\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        }\n\n        // valid lead\n        leadSurrogate = codePoint\n\n        continue\n      }\n\n      // 2 leads in a row\n      if (codePoint < 0xDC00) {\n        if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n        leadSurrogate = codePoint\n        continue\n      }\n\n      // valid surrogate pair\n      codePoint = (leadSurrogate - 0xD800 << 10 | codePoint - 0xDC00) + 0x10000\n    } else if (leadSurrogate) {\n      // valid bmp char, but last char was a lead\n      if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n    }\n\n    leadSurrogate = null\n\n    // encode utf8\n    if (codePoint < 0x80) {\n      if ((units -= 1) < 0) break\n      bytes.push(codePoint)\n    } else if (codePoint < 0x800) {\n      if ((units -= 2) < 0) break\n      bytes.push(\n        codePoint >> 0x6 | 0xC0,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x10000) {\n      if ((units -= 3) < 0) break\n      bytes.push(\n        codePoint >> 0xC | 0xE0,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x110000) {\n      if ((units -= 4) < 0) break\n      bytes.push(\n        codePoint >> 0x12 | 0xF0,\n        codePoint >> 0xC & 0x3F | 0x80,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else {\n      throw new Error('Invalid code point')\n    }\n  }\n\n  return bytes\n}\n\nfunction asciiToBytes (str) {\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    // Node's code seems to be doing this and not & 0x7F..\n    byteArray.push(str.charCodeAt(i) & 0xFF)\n  }\n  return byteArray\n}\n\nfunction utf16leToBytes (str, units) {\n  var c, hi, lo\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    if ((units -= 2) < 0) break\n\n    c = str.charCodeAt(i)\n    hi = c >> 8\n    lo = c % 256\n    byteArray.push(lo)\n    byteArray.push(hi)\n  }\n\n  return byteArray\n}\n\nfunction base64ToBytes (str) {\n  return base64.toByteArray(base64clean(str))\n}\n\nfunction blitBuffer (src, dst, offset, length) {\n  for (var i = 0; i < length; ++i) {\n    if ((i + offset >= dst.length) || (i >= src.length)) break\n    dst[i + offset] = src[i]\n  }\n  return i\n}\n\nfunction isnan (val) {\n  return val !== val // eslint-disable-line no-self-compare\n}\n\n/* WEBPACK VAR INJECTION */}.call(this, __webpack_require__(/*! ./../webpack/buildin/global.js */ \"./node_modules/webpack/buildin/global.js\")))\n\n/***/ }),\n\n/***/ \"./node_modules/buffer/node_modules/isarray/index.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/buffer/node_modules/isarray/index.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar toString = {}.toString;\n\nmodule.exports = Array.isArray || function (arr) {\n  return toString.call(arr) == '[object Array]';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/regexp/escape.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/fn/regexp/escape.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/core.regexp.escape */ \"./node_modules/core-js/modules/core.regexp.escape.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").RegExp.escape;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_a-function.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_a-function.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it) {\n  if (typeof it != 'function') throw TypeError(it + ' is not a function!');\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_a-number-value.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_a-number-value.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nmodule.exports = function (it, msg) {\n  if (typeof it != 'number' && cof(it) != 'Number') throw TypeError(msg);\n  return +it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_add-to-unscopables.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_add-to-unscopables.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.3.31 Array.prototype[@@unscopables]\nvar UNSCOPABLES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('unscopables');\nvar ArrayProto = Array.prototype;\nif (ArrayProto[UNSCOPABLES] == undefined) __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")(ArrayProto, UNSCOPABLES, {});\nmodule.exports = function (key) {\n  ArrayProto[UNSCOPABLES][key] = true;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_advance-string-index.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_advance-string-index.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar at = __webpack_require__(/*! ./_string-at */ \"./node_modules/core-js/modules/_string-at.js\")(true);\n\n // `AdvanceStringIndex` abstract operation\n// https://tc39.github.io/ecma262/#sec-advancestringindex\nmodule.exports = function (S, index, unicode) {\n  return index + (unicode ? at(S, index).length : 1);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_an-instance.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_an-instance.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it, Constructor, name, forbiddenField) {\n  if (!(it instanceof Constructor) || (forbiddenField !== undefined && forbiddenField in it)) {\n    throw TypeError(name + ': incorrect invocation!');\n  } return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_an-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_an-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nmodule.exports = function (it) {\n  if (!isObject(it)) throw TypeError(it + ' is not an object!');\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-copy-within.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-copy-within.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// 22.1.3.3 Array.prototype.copyWithin(target, start, end = this.length)\n\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\n\nmodule.exports = [].copyWithin || function copyWithin(target /* = 0 */, start /* = 0, end = @length */) {\n  var O = toObject(this);\n  var len = toLength(O.length);\n  var to = toAbsoluteIndex(target, len);\n  var from = toAbsoluteIndex(start, len);\n  var end = arguments.length > 2 ? arguments[2] : undefined;\n  var count = Math.min((end === undefined ? len : toAbsoluteIndex(end, len)) - from, len - to);\n  var inc = 1;\n  if (from < to && to < from + count) {\n    inc = -1;\n    from += count - 1;\n    to += count - 1;\n  }\n  while (count-- > 0) {\n    if (from in O) O[to] = O[from];\n    else delete O[to];\n    to += inc;\n    from += inc;\n  } return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-fill.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-fill.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// 22.1.3.6 Array.prototype.fill(value, start = 0, end = this.length)\n\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nmodule.exports = function fill(value /* , start = 0, end = @length */) {\n  var O = toObject(this);\n  var length = toLength(O.length);\n  var aLen = arguments.length;\n  var index = toAbsoluteIndex(aLen > 1 ? arguments[1] : undefined, length);\n  var end = aLen > 2 ? arguments[2] : undefined;\n  var endPos = end === undefined ? length : toAbsoluteIndex(end, length);\n  while (endPos > index) O[index++] = value;\n  return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-from-iterable.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-from-iterable.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\n\nmodule.exports = function (iter, ITERATOR) {\n  var result = [];\n  forOf(iter, false, result.push, result, ITERATOR);\n  return result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-includes.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-includes.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// false -> Array#indexOf\n// true  -> Array#includes\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nmodule.exports = function (IS_INCLUDES) {\n  return function ($this, el, fromIndex) {\n    var O = toIObject($this);\n    var length = toLength(O.length);\n    var index = toAbsoluteIndex(fromIndex, length);\n    var value;\n    // Array#includes uses SameValueZero equality algorithm\n    // eslint-disable-next-line no-self-compare\n    if (IS_INCLUDES && el != el) while (length > index) {\n      value = O[index++];\n      // eslint-disable-next-line no-self-compare\n      if (value != value) return true;\n    // Array#indexOf ignores holes, Array#includes - not\n    } else for (;length > index; index++) if (IS_INCLUDES || index in O) {\n      if (O[index] === el) return IS_INCLUDES || index || 0;\n    } return !IS_INCLUDES && -1;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-methods.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-methods.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 0 -> Array#forEach\n// 1 -> Array#map\n// 2 -> Array#filter\n// 3 -> Array#some\n// 4 -> Array#every\n// 5 -> Array#find\n// 6 -> Array#findIndex\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar asc = __webpack_require__(/*! ./_array-species-create */ \"./node_modules/core-js/modules/_array-species-create.js\");\nmodule.exports = function (TYPE, $create) {\n  var IS_MAP = TYPE == 1;\n  var IS_FILTER = TYPE == 2;\n  var IS_SOME = TYPE == 3;\n  var IS_EVERY = TYPE == 4;\n  var IS_FIND_INDEX = TYPE == 6;\n  var NO_HOLES = TYPE == 5 || IS_FIND_INDEX;\n  var create = $create || asc;\n  return function ($this, callbackfn, that) {\n    var O = toObject($this);\n    var self = IObject(O);\n    var f = ctx(callbackfn, that, 3);\n    var length = toLength(self.length);\n    var index = 0;\n    var result = IS_MAP ? create($this, length) : IS_FILTER ? create($this, 0) : undefined;\n    var val, res;\n    for (;length > index; index++) if (NO_HOLES || index in self) {\n      val = self[index];\n      res = f(val, index, O);\n      if (TYPE) {\n        if (IS_MAP) result[index] = res;   // map\n        else if (res) switch (TYPE) {\n          case 3: return true;             // some\n          case 5: return val;              // find\n          case 6: return index;            // findIndex\n          case 2: result.push(val);        // filter\n        } else if (IS_EVERY) return false; // every\n      }\n    }\n    return IS_FIND_INDEX ? -1 : IS_SOME || IS_EVERY ? IS_EVERY : result;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-reduce.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-reduce.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\n\nmodule.exports = function (that, callbackfn, aLen, memo, isRight) {\n  aFunction(callbackfn);\n  var O = toObject(that);\n  var self = IObject(O);\n  var length = toLength(O.length);\n  var index = isRight ? length - 1 : 0;\n  var i = isRight ? -1 : 1;\n  if (aLen < 2) for (;;) {\n    if (index in self) {\n      memo = self[index];\n      index += i;\n      break;\n    }\n    index += i;\n    if (isRight ? index < 0 : length <= index) {\n      throw TypeError('Reduce of empty array with no initial value');\n    }\n  }\n  for (;isRight ? index >= 0 : length > index; index += i) if (index in self) {\n    memo = callbackfn(memo, self[index], index, O);\n  }\n  return memo;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-species-constructor.js\":\n/*!********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-species-constructor.js ***!\n  \\********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar isArray = __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\n\nmodule.exports = function (original) {\n  var C;\n  if (isArray(original)) {\n    C = original.constructor;\n    // cross-realm fallback\n    if (typeof C == 'function' && (C === Array || isArray(C.prototype))) C = undefined;\n    if (isObject(C)) {\n      C = C[SPECIES];\n      if (C === null) C = undefined;\n    }\n  } return C === undefined ? Array : C;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-species-create.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-species-create.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 9.4.2.3 ArraySpeciesCreate(originalArray, length)\nvar speciesConstructor = __webpack_require__(/*! ./_array-species-constructor */ \"./node_modules/core-js/modules/_array-species-constructor.js\");\n\nmodule.exports = function (original, length) {\n  return new (speciesConstructor(original))(length);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_bind.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_bind.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar invoke = __webpack_require__(/*! ./_invoke */ \"./node_modules/core-js/modules/_invoke.js\");\nvar arraySlice = [].slice;\nvar factories = {};\n\nvar construct = function (F, len, args) {\n  if (!(len in factories)) {\n    for (var n = [], i = 0; i < len; i++) n[i] = 'a[' + i + ']';\n    // eslint-disable-next-line no-new-func\n    factories[len] = Function('F,a', 'return new F(' + n.join(',') + ')');\n  } return factories[len](F, args);\n};\n\nmodule.exports = Function.bind || function bind(that /* , ...args */) {\n  var fn = aFunction(this);\n  var partArgs = arraySlice.call(arguments, 1);\n  var bound = function (/* args... */) {\n    var args = partArgs.concat(arraySlice.call(arguments));\n    return this instanceof bound ? construct(fn, args.length, args) : invoke(fn, args, that);\n  };\n  if (isObject(fn.prototype)) bound.prototype = fn.prototype;\n  return bound;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_classof.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_classof.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// getting tag from 19.1.3.6 Object.prototype.toString()\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nvar TAG = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag');\n// ES3 wrong here\nvar ARG = cof(function () { return arguments; }()) == 'Arguments';\n\n// fallback for IE11 Script Access Denied error\nvar tryGet = function (it, key) {\n  try {\n    return it[key];\n  } catch (e) { /* empty */ }\n};\n\nmodule.exports = function (it) {\n  var O, T, B;\n  return it === undefined ? 'Undefined' : it === null ? 'Null'\n    // @@toStringTag case\n    : typeof (T = tryGet(O = Object(it), TAG)) == 'string' ? T\n    // builtinTag case\n    : ARG ? cof(O)\n    // ES3 arguments fallback\n    : (B = cof(O)) == 'Object' && typeof O.callee == 'function' ? 'Arguments' : B;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_cof.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_cof.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar toString = {}.toString;\n\nmodule.exports = function (it) {\n  return toString.call(it).slice(8, -1);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_collection-strong.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_collection-strong.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\nvar redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar $iterDefine = __webpack_require__(/*! ./_iter-define */ \"./node_modules/core-js/modules/_iter-define.js\");\nvar step = __webpack_require__(/*! ./_iter-step */ \"./node_modules/core-js/modules/_iter-step.js\");\nvar setSpecies = __webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar fastKey = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").fastKey;\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar SIZE = DESCRIPTORS ? '_s' : 'size';\n\nvar getEntry = function (that, key) {\n  // fast case\n  var index = fastKey(key);\n  var entry;\n  if (index !== 'F') return that._i[index];\n  // frozen object case\n  for (entry = that._f; entry; entry = entry.n) {\n    if (entry.k == key) return entry;\n  }\n};\n\nmodule.exports = {\n  getConstructor: function (wrapper, NAME, IS_MAP, ADDER) {\n    var C = wrapper(function (that, iterable) {\n      anInstance(that, C, NAME, '_i');\n      that._t = NAME;         // collection type\n      that._i = create(null); // index\n      that._f = undefined;    // first entry\n      that._l = undefined;    // last entry\n      that[SIZE] = 0;         // size\n      if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n    });\n    redefineAll(C.prototype, {\n      // 23.1.3.1 Map.prototype.clear()\n      // 23.2.3.2 Set.prototype.clear()\n      clear: function clear() {\n        for (var that = validate(this, NAME), data = that._i, entry = that._f; entry; entry = entry.n) {\n          entry.r = true;\n          if (entry.p) entry.p = entry.p.n = undefined;\n          delete data[entry.i];\n        }\n        that._f = that._l = undefined;\n        that[SIZE] = 0;\n      },\n      // 23.1.3.3 Map.prototype.delete(key)\n      // 23.2.3.4 Set.prototype.delete(value)\n      'delete': function (key) {\n        var that = validate(this, NAME);\n        var entry = getEntry(that, key);\n        if (entry) {\n          var next = entry.n;\n          var prev = entry.p;\n          delete that._i[entry.i];\n          entry.r = true;\n          if (prev) prev.n = next;\n          if (next) next.p = prev;\n          if (that._f == entry) that._f = next;\n          if (that._l == entry) that._l = prev;\n          that[SIZE]--;\n        } return !!entry;\n      },\n      // 23.2.3.6 Set.prototype.forEach(callbackfn, thisArg = undefined)\n      // 23.1.3.5 Map.prototype.forEach(callbackfn, thisArg = undefined)\n      forEach: function forEach(callbackfn /* , that = undefined */) {\n        validate(this, NAME);\n        var f = ctx(callbackfn, arguments.length > 1 ? arguments[1] : undefined, 3);\n        var entry;\n        while (entry = entry ? entry.n : this._f) {\n          f(entry.v, entry.k, this);\n          // revert to the last existing entry\n          while (entry && entry.r) entry = entry.p;\n        }\n      },\n      // 23.1.3.7 Map.prototype.has(key)\n      // 23.2.3.7 Set.prototype.has(value)\n      has: function has(key) {\n        return !!getEntry(validate(this, NAME), key);\n      }\n    });\n    if (DESCRIPTORS) dP(C.prototype, 'size', {\n      get: function () {\n        return validate(this, NAME)[SIZE];\n      }\n    });\n    return C;\n  },\n  def: function (that, key, value) {\n    var entry = getEntry(that, key);\n    var prev, index;\n    // change existing entry\n    if (entry) {\n      entry.v = value;\n    // create new entry\n    } else {\n      that._l = entry = {\n        i: index = fastKey(key, true), // <- index\n        k: key,                        // <- key\n        v: value,                      // <- value\n        p: prev = that._l,             // <- previous entry\n        n: undefined,                  // <- next entry\n        r: false                       // <- removed\n      };\n      if (!that._f) that._f = entry;\n      if (prev) prev.n = entry;\n      that[SIZE]++;\n      // add to index\n      if (index !== 'F') that._i[index] = entry;\n    } return that;\n  },\n  getEntry: getEntry,\n  setStrong: function (C, NAME, IS_MAP) {\n    // add .keys, .values, .entries, [@@iterator]\n    // 23.1.3.4, 23.1.3.8, 23.1.3.11, 23.1.3.12, 23.2.3.5, 23.2.3.8, 23.2.3.10, 23.2.3.11\n    $iterDefine(C, NAME, function (iterated, kind) {\n      this._t = validate(iterated, NAME); // target\n      this._k = kind;                     // kind\n      this._l = undefined;                // previous\n    }, function () {\n      var that = this;\n      var kind = that._k;\n      var entry = that._l;\n      // revert to the last existing entry\n      while (entry && entry.r) entry = entry.p;\n      // get next entry\n      if (!that._t || !(that._l = entry = entry ? entry.n : that._t._f)) {\n        // or finish the iteration\n        that._t = undefined;\n        return step(1);\n      }\n      // return step by kind\n      if (kind == 'keys') return step(0, entry.k);\n      if (kind == 'values') return step(0, entry.v);\n      return step(0, [entry.k, entry.v]);\n    }, IS_MAP ? 'entries' : 'values', !IS_MAP, true);\n\n    // add [@@species], 23.1.2.2, 23.2.2.2\n    setSpecies(NAME);\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_collection-to-json.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_collection-to-json.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar from = __webpack_require__(/*! ./_array-from-iterable */ \"./node_modules/core-js/modules/_array-from-iterable.js\");\nmodule.exports = function (NAME) {\n  return function toJSON() {\n    if (classof(this) != NAME) throw TypeError(NAME + \"#toJSON isn't generic\");\n    return from(this);\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_collection-weak.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_collection-weak.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\nvar getWeak = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").getWeak;\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar createArrayMethod = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\");\nvar $has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar arrayFind = createArrayMethod(5);\nvar arrayFindIndex = createArrayMethod(6);\nvar id = 0;\n\n// fallback for uncaught frozen keys\nvar uncaughtFrozenStore = function (that) {\n  return that._l || (that._l = new UncaughtFrozenStore());\n};\nvar UncaughtFrozenStore = function () {\n  this.a = [];\n};\nvar findUncaughtFrozen = function (store, key) {\n  return arrayFind(store.a, function (it) {\n    return it[0] === key;\n  });\n};\nUncaughtFrozenStore.prototype = {\n  get: function (key) {\n    var entry = findUncaughtFrozen(this, key);\n    if (entry) return entry[1];\n  },\n  has: function (key) {\n    return !!findUncaughtFrozen(this, key);\n  },\n  set: function (key, value) {\n    var entry = findUncaughtFrozen(this, key);\n    if (entry) entry[1] = value;\n    else this.a.push([key, value]);\n  },\n  'delete': function (key) {\n    var index = arrayFindIndex(this.a, function (it) {\n      return it[0] === key;\n    });\n    if (~index) this.a.splice(index, 1);\n    return !!~index;\n  }\n};\n\nmodule.exports = {\n  getConstructor: function (wrapper, NAME, IS_MAP, ADDER) {\n    var C = wrapper(function (that, iterable) {\n      anInstance(that, C, NAME, '_i');\n      that._t = NAME;      // collection type\n      that._i = id++;      // collection id\n      that._l = undefined; // leak store for uncaught frozen objects\n      if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n    });\n    redefineAll(C.prototype, {\n      // 23.3.3.2 WeakMap.prototype.delete(key)\n      // 23.4.3.3 WeakSet.prototype.delete(value)\n      'delete': function (key) {\n        if (!isObject(key)) return false;\n        var data = getWeak(key);\n        if (data === true) return uncaughtFrozenStore(validate(this, NAME))['delete'](key);\n        return data && $has(data, this._i) && delete data[this._i];\n      },\n      // 23.3.3.4 WeakMap.prototype.has(key)\n      // 23.4.3.4 WeakSet.prototype.has(value)\n      has: function has(key) {\n        if (!isObject(key)) return false;\n        var data = getWeak(key);\n        if (data === true) return uncaughtFrozenStore(validate(this, NAME)).has(key);\n        return data && $has(data, this._i);\n      }\n    });\n    return C;\n  },\n  def: function (that, key, value) {\n    var data = getWeak(anObject(key), true);\n    if (data === true) uncaughtFrozenStore(that).set(key, value);\n    else data[that._i] = value;\n    return that;\n  },\n  ufstore: uncaughtFrozenStore\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_collection.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_collection.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\nvar meta = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar $iterDetect = __webpack_require__(/*! ./_iter-detect */ \"./node_modules/core-js/modules/_iter-detect.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar inheritIfRequired = __webpack_require__(/*! ./_inherit-if-required */ \"./node_modules/core-js/modules/_inherit-if-required.js\");\n\nmodule.exports = function (NAME, wrapper, methods, common, IS_MAP, IS_WEAK) {\n  var Base = global[NAME];\n  var C = Base;\n  var ADDER = IS_MAP ? 'set' : 'add';\n  var proto = C && C.prototype;\n  var O = {};\n  var fixMethod = function (KEY) {\n    var fn = proto[KEY];\n    redefine(proto, KEY,\n      KEY == 'delete' ? function (a) {\n        return IS_WEAK && !isObject(a) ? false : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'has' ? function has(a) {\n        return IS_WEAK && !isObject(a) ? false : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'get' ? function get(a) {\n        return IS_WEAK && !isObject(a) ? undefined : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'add' ? function add(a) { fn.call(this, a === 0 ? 0 : a); return this; }\n        : function set(a, b) { fn.call(this, a === 0 ? 0 : a, b); return this; }\n    );\n  };\n  if (typeof C != 'function' || !(IS_WEAK || proto.forEach && !fails(function () {\n    new C().entries().next();\n  }))) {\n    // create collection constructor\n    C = common.getConstructor(wrapper, NAME, IS_MAP, ADDER);\n    redefineAll(C.prototype, methods);\n    meta.NEED = true;\n  } else {\n    var instance = new C();\n    // early implementations not supports chaining\n    var HASNT_CHAINING = instance[ADDER](IS_WEAK ? {} : -0, 1) != instance;\n    // V8 ~  Chromium 40- weak-collections throws on primitives, but should return false\n    var THROWS_ON_PRIMITIVES = fails(function () { instance.has(1); });\n    // most early implementations doesn't supports iterables, most modern - not close it correctly\n    var ACCEPT_ITERABLES = $iterDetect(function (iter) { new C(iter); }); // eslint-disable-line no-new\n    // for early implementations -0 and +0 not the same\n    var BUGGY_ZERO = !IS_WEAK && fails(function () {\n      // V8 ~ Chromium 42- fails only with 5+ elements\n      var $instance = new C();\n      var index = 5;\n      while (index--) $instance[ADDER](index, index);\n      return !$instance.has(-0);\n    });\n    if (!ACCEPT_ITERABLES) {\n      C = wrapper(function (target, iterable) {\n        anInstance(target, C, NAME);\n        var that = inheritIfRequired(new Base(), target, C);\n        if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n        return that;\n      });\n      C.prototype = proto;\n      proto.constructor = C;\n    }\n    if (THROWS_ON_PRIMITIVES || BUGGY_ZERO) {\n      fixMethod('delete');\n      fixMethod('has');\n      IS_MAP && fixMethod('get');\n    }\n    if (BUGGY_ZERO || HASNT_CHAINING) fixMethod(ADDER);\n    // weak collections should not contains .clear method\n    if (IS_WEAK && proto.clear) delete proto.clear;\n  }\n\n  setToStringTag(C, NAME);\n\n  O[NAME] = C;\n  $export($export.G + $export.W + $export.F * (C != Base), O);\n\n  if (!IS_WEAK) common.setStrong(C, NAME, IS_MAP);\n\n  return C;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_core.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_core.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar core = module.exports = { version: '2.6.4' };\nif (typeof __e == 'number') __e = core; // eslint-disable-line no-undef\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_create-property.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_create-property.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $defineProperty = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\n\nmodule.exports = function (object, index, value) {\n  if (index in object) $defineProperty.f(object, index, createDesc(0, value));\n  else object[index] = value;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_ctx.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_ctx.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// optional / simple context binding\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nmodule.exports = function (fn, that, length) {\n  aFunction(fn);\n  if (that === undefined) return fn;\n  switch (length) {\n    case 1: return function (a) {\n      return fn.call(that, a);\n    };\n    case 2: return function (a, b) {\n      return fn.call(that, a, b);\n    };\n    case 3: return function (a, b, c) {\n      return fn.call(that, a, b, c);\n    };\n  }\n  return function (/* ...args */) {\n    return fn.apply(that, arguments);\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_date-to-iso-string.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_date-to-iso-string.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 20.3.4.36 / 15.9.5.43 Date.prototype.toISOString()\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar getTime = Date.prototype.getTime;\nvar $toISOString = Date.prototype.toISOString;\n\nvar lz = function (num) {\n  return num > 9 ? num : '0' + num;\n};\n\n// PhantomJS / old WebKit has a broken implementations\nmodule.exports = (fails(function () {\n  return $toISOString.call(new Date(-5e13 - 1)) != '0385-07-25T07:06:39.999Z';\n}) || !fails(function () {\n  $toISOString.call(new Date(NaN));\n})) ? function toISOString() {\n  if (!isFinite(getTime.call(this))) throw RangeError('Invalid time value');\n  var d = this;\n  var y = d.getUTCFullYear();\n  var m = d.getUTCMilliseconds();\n  var s = y < 0 ? '-' : y > 9999 ? '+' : '';\n  return s + ('00000' + Math.abs(y)).slice(s ? -6 : -4) +\n    '-' + lz(d.getUTCMonth() + 1) + '-' + lz(d.getUTCDate()) +\n    'T' + lz(d.getUTCHours()) + ':' + lz(d.getUTCMinutes()) +\n    ':' + lz(d.getUTCSeconds()) + '.' + (m > 99 ? m : '0' + lz(m)) + 'Z';\n} : $toISOString;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_date-to-primitive.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_date-to-primitive.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar NUMBER = 'number';\n\nmodule.exports = function (hint) {\n  if (hint !== 'string' && hint !== NUMBER && hint !== 'default') throw TypeError('Incorrect hint');\n  return toPrimitive(anObject(this), hint != NUMBER);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_defined.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_defined.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 7.2.1 RequireObjectCoercible(argument)\nmodule.exports = function (it) {\n  if (it == undefined) throw TypeError(\"Can't call method on  \" + it);\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_descriptors.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_descriptors.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// Thank's IE8 for his funny defineProperty\nmodule.exports = !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return Object.defineProperty({}, 'a', { get: function () { return 7; } }).a != 7;\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_dom-create.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_dom-create.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar document = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").document;\n// typeof document.createElement is 'object' in old IE\nvar is = isObject(document) && isObject(document.createElement);\nmodule.exports = function (it) {\n  return is ? document.createElement(it) : {};\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_enum-bug-keys.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_enum-bug-keys.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// IE 8- don't enum bug keys\nmodule.exports = (\n  'constructor,hasOwnProperty,isPrototypeOf,propertyIsEnumerable,toLocaleString,toString,valueOf'\n).split(',');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_enum-keys.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_enum-keys.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// all enumerable object keys, includes symbols\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar gOPS = __webpack_require__(/*! ./_object-gops */ \"./node_modules/core-js/modules/_object-gops.js\");\nvar pIE = __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\");\nmodule.exports = function (it) {\n  var result = getKeys(it);\n  var getSymbols = gOPS.f;\n  if (getSymbols) {\n    var symbols = getSymbols(it);\n    var isEnum = pIE.f;\n    var i = 0;\n    var key;\n    while (symbols.length > i) if (isEnum.call(it, key = symbols[i++])) result.push(key);\n  } return result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_export.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_export.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar PROTOTYPE = 'prototype';\n\nvar $export = function (type, name, source) {\n  var IS_FORCED = type & $export.F;\n  var IS_GLOBAL = type & $export.G;\n  var IS_STATIC = type & $export.S;\n  var IS_PROTO = type & $export.P;\n  var IS_BIND = type & $export.B;\n  var target = IS_GLOBAL ? global : IS_STATIC ? global[name] || (global[name] = {}) : (global[name] || {})[PROTOTYPE];\n  var exports = IS_GLOBAL ? core : core[name] || (core[name] = {});\n  var expProto = exports[PROTOTYPE] || (exports[PROTOTYPE] = {});\n  var key, own, out, exp;\n  if (IS_GLOBAL) source = name;\n  for (key in source) {\n    // contains in native\n    own = !IS_FORCED && target && target[key] !== undefined;\n    // export native or passed\n    out = (own ? target : source)[key];\n    // bind timers to global for call from export context\n    exp = IS_BIND && own ? ctx(out, global) : IS_PROTO && typeof out == 'function' ? ctx(Function.call, out) : out;\n    // extend global\n    if (target) redefine(target, key, out, type & $export.U);\n    // export\n    if (exports[key] != out) hide(exports, key, exp);\n    if (IS_PROTO && expProto[key] != out) expProto[key] = out;\n  }\n};\nglobal.core = core;\n// type bitmap\n$export.F = 1;   // forced\n$export.G = 2;   // global\n$export.S = 4;   // static\n$export.P = 8;   // proto\n$export.B = 16;  // bind\n$export.W = 32;  // wrap\n$export.U = 64;  // safe\n$export.R = 128; // real proto method for `library`\nmodule.exports = $export;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_fails-is-regexp.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_fails-is-regexp.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar MATCH = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('match');\nmodule.exports = function (KEY) {\n  var re = /./;\n  try {\n    '/./'[KEY](re);\n  } catch (e) {\n    try {\n      re[MATCH] = false;\n      return !'/./'[KEY](re);\n    } catch (f) { /* empty */ }\n  } return true;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_fails.js\":\n/*!************************************************!*\\\n  !*** ./node_modules/core-js/modules/_fails.js ***!\n  \\************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (exec) {\n  try {\n    return !!exec();\n  } catch (e) {\n    return true;\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_fix-re-wks.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_fix-re-wks.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n__webpack_require__(/*! ./es6.regexp.exec */ \"./node_modules/core-js/modules/es6.regexp.exec.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nvar wks = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\nvar regexpExec = __webpack_require__(/*! ./_regexp-exec */ \"./node_modules/core-js/modules/_regexp-exec.js\");\n\nvar SPECIES = wks('species');\n\nvar REPLACE_SUPPORTS_NAMED_GROUPS = !fails(function () {\n  // #replace needs built-in support for named groups.\n  // #match works fine because it just return the exec results, even if it has\n  // a \"grops\" property.\n  var re = /./;\n  re.exec = function () {\n    var result = [];\n    result.groups = { a: '7' };\n    return result;\n  };\n  return ''.replace(re, '$<a>') !== '7';\n});\n\nvar SPLIT_WORKS_WITH_OVERWRITTEN_EXEC = (function () {\n  // Chrome 51 has a buggy \"split\" implementation when RegExp#exec !== nativeExec\n  var re = /(?:)/;\n  var originalExec = re.exec;\n  re.exec = function () { return originalExec.apply(this, arguments); };\n  var result = 'ab'.split(re);\n  return result.length === 2 && result[0] === 'a' && result[1] === 'b';\n})();\n\nmodule.exports = function (KEY, length, exec) {\n  var SYMBOL = wks(KEY);\n\n  var DELEGATES_TO_SYMBOL = !fails(function () {\n    // String methods call symbol-named RegEp methods\n    var O = {};\n    O[SYMBOL] = function () { return 7; };\n    return ''[KEY](O) != 7;\n  });\n\n  var DELEGATES_TO_EXEC = DELEGATES_TO_SYMBOL ? !fails(function () {\n    // Symbol-named RegExp methods call .exec\n    var execCalled = false;\n    var re = /a/;\n    re.exec = function () { execCalled = true; return null; };\n    if (KEY === 'split') {\n      // RegExp[@@split] doesn't call the regex's exec method, but first creates\n      // a new one. We need to return the patched regex when creating the new one.\n      re.constructor = {};\n      re.constructor[SPECIES] = function () { return re; };\n    }\n    re[SYMBOL]('');\n    return !execCalled;\n  }) : undefined;\n\n  if (\n    !DELEGATES_TO_SYMBOL ||\n    !DELEGATES_TO_EXEC ||\n    (KEY === 'replace' && !REPLACE_SUPPORTS_NAMED_GROUPS) ||\n    (KEY === 'split' && !SPLIT_WORKS_WITH_OVERWRITTEN_EXEC)\n  ) {\n    var nativeRegExpMethod = /./[SYMBOL];\n    var fns = exec(\n      defined,\n      SYMBOL,\n      ''[KEY],\n      function maybeCallNative(nativeMethod, regexp, str, arg2, forceStringMethod) {\n        if (regexp.exec === regexpExec) {\n          if (DELEGATES_TO_SYMBOL && !forceStringMethod) {\n            // The native String method already delegates to @@method (this\n            // polyfilled function), leasing to infinite recursion.\n            // We avoid it by directly calling the native @@method method.\n            return { done: true, value: nativeRegExpMethod.call(regexp, str, arg2) };\n          }\n          return { done: true, value: nativeMethod.call(str, regexp, arg2) };\n        }\n        return { done: false };\n      }\n    );\n    var strfn = fns[0];\n    var rxfn = fns[1];\n\n    redefine(String.prototype, KEY, strfn);\n    hide(RegExp.prototype, SYMBOL, length == 2\n      // 21.2.5.8 RegExp.prototype[@@replace](string, replaceValue)\n      // 21.2.5.11 RegExp.prototype[@@split](string, limit)\n      ? function (string, arg) { return rxfn.call(string, this, arg); }\n      // 21.2.5.6 RegExp.prototype[@@match](string)\n      // 21.2.5.9 RegExp.prototype[@@search](string)\n      : function (string) { return rxfn.call(string, this); }\n    );\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_flags.js\":\n/*!************************************************!*\\\n  !*** ./node_modules/core-js/modules/_flags.js ***!\n  \\************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 21.2.5.3 get RegExp.prototype.flags\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nmodule.exports = function () {\n  var that = anObject(this);\n  var result = '';\n  if (that.global) result += 'g';\n  if (that.ignoreCase) result += 'i';\n  if (that.multiline) result += 'm';\n  if (that.unicode) result += 'u';\n  if (that.sticky) result += 'y';\n  return result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_flatten-into-array.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_flatten-into-array.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/proposal-flatMap/#sec-FlattenIntoArray\nvar isArray = __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar IS_CONCAT_SPREADABLE = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('isConcatSpreadable');\n\nfunction flattenIntoArray(target, original, source, sourceLen, start, depth, mapper, thisArg) {\n  var targetIndex = start;\n  var sourceIndex = 0;\n  var mapFn = mapper ? ctx(mapper, thisArg, 3) : false;\n  var element, spreadable;\n\n  while (sourceIndex < sourceLen) {\n    if (sourceIndex in source) {\n      element = mapFn ? mapFn(source[sourceIndex], sourceIndex, original) : source[sourceIndex];\n\n      spreadable = false;\n      if (isObject(element)) {\n        spreadable = element[IS_CONCAT_SPREADABLE];\n        spreadable = spreadable !== undefined ? !!spreadable : isArray(element);\n      }\n\n      if (spreadable && depth > 0) {\n        targetIndex = flattenIntoArray(target, original, element, toLength(element.length), targetIndex, depth - 1) - 1;\n      } else {\n        if (targetIndex >= 0x1fffffffffffff) throw TypeError();\n        target[targetIndex] = element;\n      }\n\n      targetIndex++;\n    }\n    sourceIndex++;\n  }\n  return targetIndex;\n}\n\nmodule.exports = flattenIntoArray;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_for-of.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_for-of.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar call = __webpack_require__(/*! ./_iter-call */ \"./node_modules/core-js/modules/_iter-call.js\");\nvar isArrayIter = __webpack_require__(/*! ./_is-array-iter */ \"./node_modules/core-js/modules/_is-array-iter.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar getIterFn = __webpack_require__(/*! ./core.get-iterator-method */ \"./node_modules/core-js/modules/core.get-iterator-method.js\");\nvar BREAK = {};\nvar RETURN = {};\nvar exports = module.exports = function (iterable, entries, fn, that, ITERATOR) {\n  var iterFn = ITERATOR ? function () { return iterable; } : getIterFn(iterable);\n  var f = ctx(fn, that, entries ? 2 : 1);\n  var index = 0;\n  var length, step, iterator, result;\n  if (typeof iterFn != 'function') throw TypeError(iterable + ' is not iterable!');\n  // fast case for arrays with default iterator\n  if (isArrayIter(iterFn)) for (length = toLength(iterable.length); length > index; index++) {\n    result = entries ? f(anObject(step = iterable[index])[0], step[1]) : f(iterable[index]);\n    if (result === BREAK || result === RETURN) return result;\n  } else for (iterator = iterFn.call(iterable); !(step = iterator.next()).done;) {\n    result = call(iterator, f, step.value, entries);\n    if (result === BREAK || result === RETURN) return result;\n  }\n};\nexports.BREAK = BREAK;\nexports.RETURN = RETURN;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_function-to-string.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_function-to-string.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nmodule.exports = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('native-function-to-string', Function.toString);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_global.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_global.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// https://github.com/zloirock/core-js/issues/86#issuecomment-115759028\nvar global = module.exports = typeof window != 'undefined' && window.Math == Math\n  ? window : typeof self != 'undefined' && self.Math == Math ? self\n  // eslint-disable-next-line no-new-func\n  : Function('return this')();\nif (typeof __g == 'number') __g = global; // eslint-disable-line no-undef\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_has.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_has.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar hasOwnProperty = {}.hasOwnProperty;\nmodule.exports = function (it, key) {\n  return hasOwnProperty.call(it, key);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_hide.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_hide.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nmodule.exports = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? function (object, key, value) {\n  return dP.f(object, key, createDesc(1, value));\n} : function (object, key, value) {\n  object[key] = value;\n  return object;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_html.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_html.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar document = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").document;\nmodule.exports = document && document.documentElement;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_ie8-dom-define.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_ie8-dom-define.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nmodule.exports = !__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return Object.defineProperty(__webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\")('div'), 'a', { get: function () { return 7; } }).a != 7;\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_inherit-if-required.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_inherit-if-required.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar setPrototypeOf = __webpack_require__(/*! ./_set-proto */ \"./node_modules/core-js/modules/_set-proto.js\").set;\nmodule.exports = function (that, target, C) {\n  var S = target.constructor;\n  var P;\n  if (S !== C && typeof S == 'function' && (P = S.prototype) !== C.prototype && isObject(P) && setPrototypeOf) {\n    setPrototypeOf(that, P);\n  } return that;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_invoke.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_invoke.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// fast apply, http://jsperf.lnkit.com/fast-apply/5\nmodule.exports = function (fn, args, that) {\n  var un = that === undefined;\n  switch (args.length) {\n    case 0: return un ? fn()\n                      : fn.call(that);\n    case 1: return un ? fn(args[0])\n                      : fn.call(that, args[0]);\n    case 2: return un ? fn(args[0], args[1])\n                      : fn.call(that, args[0], args[1]);\n    case 3: return un ? fn(args[0], args[1], args[2])\n                      : fn.call(that, args[0], args[1], args[2]);\n    case 4: return un ? fn(args[0], args[1], args[2], args[3])\n                      : fn.call(that, args[0], args[1], args[2], args[3]);\n  } return fn.apply(that, args);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iobject.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iobject.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// fallback for non-array-like ES3 and non-enumerable old V8 strings\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\n// eslint-disable-next-line no-prototype-builtins\nmodule.exports = Object('z').propertyIsEnumerable(0) ? Object : function (it) {\n  return cof(it) == 'String' ? it.split('') : Object(it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-array-iter.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-array-iter.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// check on default Array iterator\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar ArrayProto = Array.prototype;\n\nmodule.exports = function (it) {\n  return it !== undefined && (Iterators.Array === it || ArrayProto[ITERATOR] === it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-array.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-array.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.2.2 IsArray(argument)\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nmodule.exports = Array.isArray || function isArray(arg) {\n  return cof(arg) == 'Array';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-integer.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-integer.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.3 Number.isInteger(number)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar floor = Math.floor;\nmodule.exports = function isInteger(it) {\n  return !isObject(it) && isFinite(it) && floor(it) === it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it) {\n  return typeof it === 'object' ? it !== null : typeof it === 'function';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-regexp.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-regexp.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.2.8 IsRegExp(argument)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nvar MATCH = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('match');\nmodule.exports = function (it) {\n  var isRegExp;\n  return isObject(it) && ((isRegExp = it[MATCH]) !== undefined ? !!isRegExp : cof(it) == 'RegExp');\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-call.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-call.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// call something on iterator step with safe closing on error\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nmodule.exports = function (iterator, fn, value, entries) {\n  try {\n    return entries ? fn(anObject(value)[0], value[1]) : fn(value);\n  // 7.4.6 IteratorClose(iterator, completion)\n  } catch (e) {\n    var ret = iterator['return'];\n    if (ret !== undefined) anObject(ret.call(iterator));\n    throw e;\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-create.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-create.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\nvar descriptor = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar IteratorPrototype = {};\n\n// 25.1.2.1.1 %IteratorPrototype%[@@iterator]()\n__webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")(IteratorPrototype, __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator'), function () { return this; });\n\nmodule.exports = function (Constructor, NAME, next) {\n  Constructor.prototype = create(IteratorPrototype, { next: descriptor(1, next) });\n  setToStringTag(Constructor, NAME + ' Iterator');\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-define.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-define.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar $iterCreate = __webpack_require__(/*! ./_iter-create */ \"./node_modules/core-js/modules/_iter-create.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar BUGGY = !([].keys && 'next' in [].keys()); // Safari has buggy iterators w/o `next`\nvar FF_ITERATOR = '@@iterator';\nvar KEYS = 'keys';\nvar VALUES = 'values';\n\nvar returnThis = function () { return this; };\n\nmodule.exports = function (Base, NAME, Constructor, next, DEFAULT, IS_SET, FORCED) {\n  $iterCreate(Constructor, NAME, next);\n  var getMethod = function (kind) {\n    if (!BUGGY && kind in proto) return proto[kind];\n    switch (kind) {\n      case KEYS: return function keys() { return new Constructor(this, kind); };\n      case VALUES: return function values() { return new Constructor(this, kind); };\n    } return function entries() { return new Constructor(this, kind); };\n  };\n  var TAG = NAME + ' Iterator';\n  var DEF_VALUES = DEFAULT == VALUES;\n  var VALUES_BUG = false;\n  var proto = Base.prototype;\n  var $native = proto[ITERATOR] || proto[FF_ITERATOR] || DEFAULT && proto[DEFAULT];\n  var $default = $native || getMethod(DEFAULT);\n  var $entries = DEFAULT ? !DEF_VALUES ? $default : getMethod('entries') : undefined;\n  var $anyNative = NAME == 'Array' ? proto.entries || $native : $native;\n  var methods, key, IteratorPrototype;\n  // Fix native\n  if ($anyNative) {\n    IteratorPrototype = getPrototypeOf($anyNative.call(new Base()));\n    if (IteratorPrototype !== Object.prototype && IteratorPrototype.next) {\n      // Set @@toStringTag to native iterators\n      setToStringTag(IteratorPrototype, TAG, true);\n      // fix for some old engines\n      if (!LIBRARY && typeof IteratorPrototype[ITERATOR] != 'function') hide(IteratorPrototype, ITERATOR, returnThis);\n    }\n  }\n  // fix Array#{values, @@iterator}.name in V8 / FF\n  if (DEF_VALUES && $native && $native.name !== VALUES) {\n    VALUES_BUG = true;\n    $default = function values() { return $native.call(this); };\n  }\n  // Define iterator\n  if ((!LIBRARY || FORCED) && (BUGGY || VALUES_BUG || !proto[ITERATOR])) {\n    hide(proto, ITERATOR, $default);\n  }\n  // Plug for library\n  Iterators[NAME] = $default;\n  Iterators[TAG] = returnThis;\n  if (DEFAULT) {\n    methods = {\n      values: DEF_VALUES ? $default : getMethod(VALUES),\n      keys: IS_SET ? $default : getMethod(KEYS),\n      entries: $entries\n    };\n    if (FORCED) for (key in methods) {\n      if (!(key in proto)) redefine(proto, key, methods[key]);\n    } else $export($export.P + $export.F * (BUGGY || VALUES_BUG), NAME, methods);\n  }\n  return methods;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-detect.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-detect.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar SAFE_CLOSING = false;\n\ntry {\n  var riter = [7][ITERATOR]();\n  riter['return'] = function () { SAFE_CLOSING = true; };\n  // eslint-disable-next-line no-throw-literal\n  Array.from(riter, function () { throw 2; });\n} catch (e) { /* empty */ }\n\nmodule.exports = function (exec, skipClosing) {\n  if (!skipClosing && !SAFE_CLOSING) return false;\n  var safe = false;\n  try {\n    var arr = [7];\n    var iter = arr[ITERATOR]();\n    iter.next = function () { return { done: safe = true }; };\n    arr[ITERATOR] = function () { return iter; };\n    exec(arr);\n  } catch (e) { /* empty */ }\n  return safe;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-step.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-step.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (done, value) {\n  return { value: value, done: !!done };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iterators.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iterators.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = {};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_library.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_library.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = false;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_math-expm1.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_math-expm1.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 20.2.2.14 Math.expm1(x)\nvar $expm1 = Math.expm1;\nmodule.exports = (!$expm1\n  // Old FF bug\n  || $expm1(10) > 22025.465794806719 || $expm1(10) < 22025.4657948067165168\n  // Tor Browser bug\n  || $expm1(-2e-17) != -2e-17\n) ? function expm1(x) {\n  return (x = +x) == 0 ? x : x > -1e-6 && x < 1e-6 ? x + x * x / 2 : Math.exp(x) - 1;\n} : $expm1;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_math-fround.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_math-fround.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.16 Math.fround(x)\nvar sign = __webpack_require__(/*! ./_math-sign */ \"./node_modules/core-js/modules/_math-sign.js\");\nvar pow = Math.pow;\nvar EPSILON = pow(2, -52);\nvar EPSILON32 = pow(2, -23);\nvar MAX32 = pow(2, 127) * (2 - EPSILON32);\nvar MIN32 = pow(2, -126);\n\nvar roundTiesToEven = function (n) {\n  return n + 1 / EPSILON - 1 / EPSILON;\n};\n\nmodule.exports = Math.fround || function fround(x) {\n  var $abs = Math.abs(x);\n  var $sign = sign(x);\n  var a, result;\n  if ($abs < MIN32) return $sign * roundTiesToEven($abs / MIN32 / EPSILON32) * MIN32 * EPSILON32;\n  a = (1 + EPSILON32 / EPSILON) * $abs;\n  result = a - (a - $abs);\n  // eslint-disable-next-line no-self-compare\n  if (result > MAX32 || result != result) return $sign * Infinity;\n  return $sign * result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_math-log1p.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_math-log1p.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 20.2.2.20 Math.log1p(x)\nmodule.exports = Math.log1p || function log1p(x) {\n  return (x = +x) > -1e-8 && x < 1e-8 ? x - x * x / 2 : Math.log(1 + x);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_math-scale.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_math-scale.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nmodule.exports = Math.scale || function scale(x, inLow, inHigh, outLow, outHigh) {\n  if (\n    arguments.length === 0\n      // eslint-disable-next-line no-self-compare\n      || x != x\n      // eslint-disable-next-line no-self-compare\n      || inLow != inLow\n      // eslint-disable-next-line no-self-compare\n      || inHigh != inHigh\n      // eslint-disable-next-line no-self-compare\n      || outLow != outLow\n      // eslint-disable-next-line no-self-compare\n      || outHigh != outHigh\n  ) return NaN;\n  if (x === Infinity || x === -Infinity) return x;\n  return (x - inLow) * (outHigh - outLow) / (inHigh - inLow) + outLow;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_math-sign.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_math-sign.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 20.2.2.28 Math.sign(x)\nmodule.exports = Math.sign || function sign(x) {\n  // eslint-disable-next-line no-self-compare\n  return (x = +x) == 0 || x != x ? x : x < 0 ? -1 : 1;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_meta.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_meta.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar META = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\")('meta');\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar setDesc = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar id = 0;\nvar isExtensible = Object.isExtensible || function () {\n  return true;\n};\nvar FREEZE = !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return isExtensible(Object.preventExtensions({}));\n});\nvar setMeta = function (it) {\n  setDesc(it, META, { value: {\n    i: 'O' + ++id, // object ID\n    w: {}          // weak collections IDs\n  } });\n};\nvar fastKey = function (it, create) {\n  // return primitive with prefix\n  if (!isObject(it)) return typeof it == 'symbol' ? it : (typeof it == 'string' ? 'S' : 'P') + it;\n  if (!has(it, META)) {\n    // can't set metadata to uncaught frozen object\n    if (!isExtensible(it)) return 'F';\n    // not necessary to add metadata\n    if (!create) return 'E';\n    // add missing metadata\n    setMeta(it);\n  // return object ID\n  } return it[META].i;\n};\nvar getWeak = function (it, create) {\n  if (!has(it, META)) {\n    // can't set metadata to uncaught frozen object\n    if (!isExtensible(it)) return true;\n    // not necessary to add metadata\n    if (!create) return false;\n    // add missing metadata\n    setMeta(it);\n  // return hash weak collections IDs\n  } return it[META].w;\n};\n// add metadata on freeze-family methods calling\nvar onFreeze = function (it) {\n  if (FREEZE && meta.NEED && isExtensible(it) && !has(it, META)) setMeta(it);\n  return it;\n};\nvar meta = module.exports = {\n  KEY: META,\n  NEED: false,\n  fastKey: fastKey,\n  getWeak: getWeak,\n  onFreeze: onFreeze\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_metadata.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_metadata.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar Map = __webpack_require__(/*! ./es6.map */ \"./node_modules/core-js/modules/es6.map.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar shared = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('metadata');\nvar store = shared.store || (shared.store = new (__webpack_require__(/*! ./es6.weak-map */ \"./node_modules/core-js/modules/es6.weak-map.js\"))());\n\nvar getOrCreateMetadataMap = function (target, targetKey, create) {\n  var targetMetadata = store.get(target);\n  if (!targetMetadata) {\n    if (!create) return undefined;\n    store.set(target, targetMetadata = new Map());\n  }\n  var keyMetadata = targetMetadata.get(targetKey);\n  if (!keyMetadata) {\n    if (!create) return undefined;\n    targetMetadata.set(targetKey, keyMetadata = new Map());\n  } return keyMetadata;\n};\nvar ordinaryHasOwnMetadata = function (MetadataKey, O, P) {\n  var metadataMap = getOrCreateMetadataMap(O, P, false);\n  return metadataMap === undefined ? false : metadataMap.has(MetadataKey);\n};\nvar ordinaryGetOwnMetadata = function (MetadataKey, O, P) {\n  var metadataMap = getOrCreateMetadataMap(O, P, false);\n  return metadataMap === undefined ? undefined : metadataMap.get(MetadataKey);\n};\nvar ordinaryDefineOwnMetadata = function (MetadataKey, MetadataValue, O, P) {\n  getOrCreateMetadataMap(O, P, true).set(MetadataKey, MetadataValue);\n};\nvar ordinaryOwnMetadataKeys = function (target, targetKey) {\n  var metadataMap = getOrCreateMetadataMap(target, targetKey, false);\n  var keys = [];\n  if (metadataMap) metadataMap.forEach(function (_, key) { keys.push(key); });\n  return keys;\n};\nvar toMetaKey = function (it) {\n  return it === undefined || typeof it == 'symbol' ? it : String(it);\n};\nvar exp = function (O) {\n  $export($export.S, 'Reflect', O);\n};\n\nmodule.exports = {\n  store: store,\n  map: getOrCreateMetadataMap,\n  has: ordinaryHasOwnMetadata,\n  get: ordinaryGetOwnMetadata,\n  set: ordinaryDefineOwnMetadata,\n  keys: ordinaryOwnMetadataKeys,\n  key: toMetaKey,\n  exp: exp\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_microtask.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_microtask.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar macrotask = __webpack_require__(/*! ./_task */ \"./node_modules/core-js/modules/_task.js\").set;\nvar Observer = global.MutationObserver || global.WebKitMutationObserver;\nvar process = global.process;\nvar Promise = global.Promise;\nvar isNode = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\")(process) == 'process';\n\nmodule.exports = function () {\n  var head, last, notify;\n\n  var flush = function () {\n    var parent, fn;\n    if (isNode && (parent = process.domain)) parent.exit();\n    while (head) {\n      fn = head.fn;\n      head = head.next;\n      try {\n        fn();\n      } catch (e) {\n        if (head) notify();\n        else last = undefined;\n        throw e;\n      }\n    } last = undefined;\n    if (parent) parent.enter();\n  };\n\n  // Node.js\n  if (isNode) {\n    notify = function () {\n      process.nextTick(flush);\n    };\n  // browsers with MutationObserver, except iOS Safari - https://github.com/zloirock/core-js/issues/339\n  } else if (Observer && !(global.navigator && global.navigator.standalone)) {\n    var toggle = true;\n    var node = document.createTextNode('');\n    new Observer(flush).observe(node, { characterData: true }); // eslint-disable-line no-new\n    notify = function () {\n      node.data = toggle = !toggle;\n    };\n  // environments with maybe non-completely correct, but existent Promise\n  } else if (Promise && Promise.resolve) {\n    // Promise.resolve without an argument throws an error in LG WebOS 2\n    var promise = Promise.resolve(undefined);\n    notify = function () {\n      promise.then(flush);\n    };\n  // for other environments - macrotask based on:\n  // - setImmediate\n  // - MessageChannel\n  // - window.postMessag\n  // - onreadystatechange\n  // - setTimeout\n  } else {\n    notify = function () {\n      // strange IE + webpack dev server bug - use .call(global)\n      macrotask.call(global, flush);\n    };\n  }\n\n  return function (fn) {\n    var task = { fn: fn, next: undefined };\n    if (last) last.next = task;\n    if (!head) {\n      head = task;\n      notify();\n    } last = task;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_new-promise-capability.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_new-promise-capability.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 25.4.1.5 NewPromiseCapability(C)\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\n\nfunction PromiseCapability(C) {\n  var resolve, reject;\n  this.promise = new C(function ($$resolve, $$reject) {\n    if (resolve !== undefined || reject !== undefined) throw TypeError('Bad Promise constructor');\n    resolve = $$resolve;\n    reject = $$reject;\n  });\n  this.resolve = aFunction(resolve);\n  this.reject = aFunction(reject);\n}\n\nmodule.exports.f = function (C) {\n  return new PromiseCapability(C);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-assign.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-assign.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 19.1.2.1 Object.assign(target, source, ...)\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar gOPS = __webpack_require__(/*! ./_object-gops */ \"./node_modules/core-js/modules/_object-gops.js\");\nvar pIE = __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar $assign = Object.assign;\n\n// should work with symbols and should have deterministic property order (V8 bug)\nmodule.exports = !$assign || __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  var A = {};\n  var B = {};\n  // eslint-disable-next-line no-undef\n  var S = Symbol();\n  var K = 'abcdefghijklmnopqrst';\n  A[S] = 7;\n  K.split('').forEach(function (k) { B[k] = k; });\n  return $assign({}, A)[S] != 7 || Object.keys($assign({}, B)).join('') != K;\n}) ? function assign(target, source) { // eslint-disable-line no-unused-vars\n  var T = toObject(target);\n  var aLen = arguments.length;\n  var index = 1;\n  var getSymbols = gOPS.f;\n  var isEnum = pIE.f;\n  while (aLen > index) {\n    var S = IObject(arguments[index++]);\n    var keys = getSymbols ? getKeys(S).concat(getSymbols(S)) : getKeys(S);\n    var length = keys.length;\n    var j = 0;\n    var key;\n    while (length > j) if (isEnum.call(S, key = keys[j++])) T[key] = S[key];\n  } return T;\n} : $assign;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-create.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-create.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar dPs = __webpack_require__(/*! ./_object-dps */ \"./node_modules/core-js/modules/_object-dps.js\");\nvar enumBugKeys = __webpack_require__(/*! ./_enum-bug-keys */ \"./node_modules/core-js/modules/_enum-bug-keys.js\");\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\nvar Empty = function () { /* empty */ };\nvar PROTOTYPE = 'prototype';\n\n// Create object with fake `null` prototype: use iframe Object with cleared prototype\nvar createDict = function () {\n  // Thrash, waste and sodomy: IE GC bug\n  var iframe = __webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\")('iframe');\n  var i = enumBugKeys.length;\n  var lt = '<';\n  var gt = '>';\n  var iframeDocument;\n  iframe.style.display = 'none';\n  __webpack_require__(/*! ./_html */ \"./node_modules/core-js/modules/_html.js\").appendChild(iframe);\n  iframe.src = 'javascript:'; // eslint-disable-line no-script-url\n  // createDict = iframe.contentWindow.Object;\n  // html.removeChild(iframe);\n  iframeDocument = iframe.contentWindow.document;\n  iframeDocument.open();\n  iframeDocument.write(lt + 'script' + gt + 'document.F=Object' + lt + '/script' + gt);\n  iframeDocument.close();\n  createDict = iframeDocument.F;\n  while (i--) delete createDict[PROTOTYPE][enumBugKeys[i]];\n  return createDict();\n};\n\nmodule.exports = Object.create || function create(O, Properties) {\n  var result;\n  if (O !== null) {\n    Empty[PROTOTYPE] = anObject(O);\n    result = new Empty();\n    Empty[PROTOTYPE] = null;\n    // add \"__proto__\" for Object.getPrototypeOf polyfill\n    result[IE_PROTO] = O;\n  } else result = createDict();\n  return Properties === undefined ? result : dPs(result, Properties);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-dp.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-dp.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar IE8_DOM_DEFINE = __webpack_require__(/*! ./_ie8-dom-define */ \"./node_modules/core-js/modules/_ie8-dom-define.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar dP = Object.defineProperty;\n\nexports.f = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? Object.defineProperty : function defineProperty(O, P, Attributes) {\n  anObject(O);\n  P = toPrimitive(P, true);\n  anObject(Attributes);\n  if (IE8_DOM_DEFINE) try {\n    return dP(O, P, Attributes);\n  } catch (e) { /* empty */ }\n  if ('get' in Attributes || 'set' in Attributes) throw TypeError('Accessors not supported!');\n  if ('value' in Attributes) O[P] = Attributes.value;\n  return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-dps.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-dps.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\n\nmodule.exports = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? Object.defineProperties : function defineProperties(O, Properties) {\n  anObject(O);\n  var keys = getKeys(Properties);\n  var length = keys.length;\n  var i = 0;\n  var P;\n  while (length > i) dP.f(O, P = keys[i++], Properties[P]);\n  return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-forced-pam.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-forced-pam.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// Forced replacement prototype accessors methods\nmodule.exports = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\") || !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  var K = Math.random();\n  // In FF throws only define methods\n  // eslint-disable-next-line no-undef, no-useless-call\n  __defineSetter__.call(null, K, function () { /* empty */ });\n  delete __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\")[K];\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gopd.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gopd.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar pIE = __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar IE8_DOM_DEFINE = __webpack_require__(/*! ./_ie8-dom-define */ \"./node_modules/core-js/modules/_ie8-dom-define.js\");\nvar gOPD = Object.getOwnPropertyDescriptor;\n\nexports.f = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? gOPD : function getOwnPropertyDescriptor(O, P) {\n  O = toIObject(O);\n  P = toPrimitive(P, true);\n  if (IE8_DOM_DEFINE) try {\n    return gOPD(O, P);\n  } catch (e) { /* empty */ }\n  if (has(O, P)) return createDesc(!pIE.f.call(O, P), O[P]);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gopn-ext.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gopn-ext.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// fallback for IE11 buggy Object.getOwnPropertyNames with iframe and window\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f;\nvar toString = {}.toString;\n\nvar windowNames = typeof window == 'object' && window && Object.getOwnPropertyNames\n  ? Object.getOwnPropertyNames(window) : [];\n\nvar getWindowNames = function (it) {\n  try {\n    return gOPN(it);\n  } catch (e) {\n    return windowNames.slice();\n  }\n};\n\nmodule.exports.f = function getOwnPropertyNames(it) {\n  return windowNames && toString.call(it) == '[object Window]' ? getWindowNames(it) : gOPN(toIObject(it));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gopn.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gopn.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.7 / 15.2.3.4 Object.getOwnPropertyNames(O)\nvar $keys = __webpack_require__(/*! ./_object-keys-internal */ \"./node_modules/core-js/modules/_object-keys-internal.js\");\nvar hiddenKeys = __webpack_require__(/*! ./_enum-bug-keys */ \"./node_modules/core-js/modules/_enum-bug-keys.js\").concat('length', 'prototype');\n\nexports.f = Object.getOwnPropertyNames || function getOwnPropertyNames(O) {\n  return $keys(O, hiddenKeys);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gops.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gops.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.f = Object.getOwnPropertySymbols;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gpo.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gpo.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.9 / 15.2.3.2 Object.getPrototypeOf(O)\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\nvar ObjectProto = Object.prototype;\n\nmodule.exports = Object.getPrototypeOf || function (O) {\n  O = toObject(O);\n  if (has(O, IE_PROTO)) return O[IE_PROTO];\n  if (typeof O.constructor == 'function' && O instanceof O.constructor) {\n    return O.constructor.prototype;\n  } return O instanceof Object ? ObjectProto : null;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-keys-internal.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-keys-internal.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar arrayIndexOf = __webpack_require__(/*! ./_array-includes */ \"./node_modules/core-js/modules/_array-includes.js\")(false);\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\n\nmodule.exports = function (object, names) {\n  var O = toIObject(object);\n  var i = 0;\n  var result = [];\n  var key;\n  for (key in O) if (key != IE_PROTO) has(O, key) && result.push(key);\n  // Don't enum bug & hidden keys\n  while (names.length > i) if (has(O, key = names[i++])) {\n    ~arrayIndexOf(result, key) || result.push(key);\n  }\n  return result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-keys.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-keys.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.14 / 15.2.3.14 Object.keys(O)\nvar $keys = __webpack_require__(/*! ./_object-keys-internal */ \"./node_modules/core-js/modules/_object-keys-internal.js\");\nvar enumBugKeys = __webpack_require__(/*! ./_enum-bug-keys */ \"./node_modules/core-js/modules/_enum-bug-keys.js\");\n\nmodule.exports = Object.keys || function keys(O) {\n  return $keys(O, enumBugKeys);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-pie.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-pie.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.f = {}.propertyIsEnumerable;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-sap.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-sap.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// most Object methods by ES6 should accept primitives\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nmodule.exports = function (KEY, exec) {\n  var fn = (core.Object || {})[KEY] || Object[KEY];\n  var exp = {};\n  exp[KEY] = exec(fn);\n  $export($export.S + $export.F * fails(function () { fn(1); }), 'Object', exp);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-to-array.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-to-array.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar isEnum = __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\").f;\nmodule.exports = function (isEntries) {\n  return function (it) {\n    var O = toIObject(it);\n    var keys = getKeys(O);\n    var length = keys.length;\n    var i = 0;\n    var result = [];\n    var key;\n    while (length > i) if (isEnum.call(O, key = keys[i++])) {\n      result.push(isEntries ? [key, O[key]] : O[key]);\n    } return result;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_own-keys.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_own-keys.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// all object keys, includes non-enumerable and symbols\nvar gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\");\nvar gOPS = __webpack_require__(/*! ./_object-gops */ \"./node_modules/core-js/modules/_object-gops.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar Reflect = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").Reflect;\nmodule.exports = Reflect && Reflect.ownKeys || function ownKeys(it) {\n  var keys = gOPN.f(anObject(it));\n  var getSymbols = gOPS.f;\n  return getSymbols ? keys.concat(getSymbols(it)) : keys;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_parse-float.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_parse-float.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $parseFloat = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").parseFloat;\nvar $trim = __webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\").trim;\n\nmodule.exports = 1 / $parseFloat(__webpack_require__(/*! ./_string-ws */ \"./node_modules/core-js/modules/_string-ws.js\") + '-0') !== -Infinity ? function parseFloat(str) {\n  var string = $trim(String(str), 3);\n  var result = $parseFloat(string);\n  return result === 0 && string.charAt(0) == '-' ? -0 : result;\n} : $parseFloat;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_parse-int.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_parse-int.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $parseInt = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").parseInt;\nvar $trim = __webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\").trim;\nvar ws = __webpack_require__(/*! ./_string-ws */ \"./node_modules/core-js/modules/_string-ws.js\");\nvar hex = /^[-+]?0[xX]/;\n\nmodule.exports = $parseInt(ws + '08') !== 8 || $parseInt(ws + '0x16') !== 22 ? function parseInt(str, radix) {\n  var string = $trim(String(str), 3);\n  return $parseInt(string, (radix >>> 0) || (hex.test(string) ? 16 : 10));\n} : $parseInt;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_perform.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_perform.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (exec) {\n  try {\n    return { e: false, v: exec() };\n  } catch (e) {\n    return { e: true, v: e };\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_promise-resolve.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_promise-resolve.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar newPromiseCapability = __webpack_require__(/*! ./_new-promise-capability */ \"./node_modules/core-js/modules/_new-promise-capability.js\");\n\nmodule.exports = function (C, x) {\n  anObject(C);\n  if (isObject(x) && x.constructor === C) return x;\n  var promiseCapability = newPromiseCapability.f(C);\n  var resolve = promiseCapability.resolve;\n  resolve(x);\n  return promiseCapability.promise;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_property-desc.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_property-desc.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (bitmap, value) {\n  return {\n    enumerable: !(bitmap & 1),\n    configurable: !(bitmap & 2),\n    writable: !(bitmap & 4),\n    value: value\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_redefine-all.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_redefine-all.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nmodule.exports = function (target, src, safe) {\n  for (var key in src) redefine(target, key, src[key], safe);\n  return target;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_redefine.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_redefine.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar SRC = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\")('src');\nvar $toString = __webpack_require__(/*! ./_function-to-string */ \"./node_modules/core-js/modules/_function-to-string.js\");\nvar TO_STRING = 'toString';\nvar TPL = ('' + $toString).split(TO_STRING);\n\n__webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\").inspectSource = function (it) {\n  return $toString.call(it);\n};\n\n(module.exports = function (O, key, val, safe) {\n  var isFunction = typeof val == 'function';\n  if (isFunction) has(val, 'name') || hide(val, 'name', key);\n  if (O[key] === val) return;\n  if (isFunction) has(val, SRC) || hide(val, SRC, O[key] ? '' + O[key] : TPL.join(String(key)));\n  if (O === global) {\n    O[key] = val;\n  } else if (!safe) {\n    delete O[key];\n    hide(O, key, val);\n  } else if (O[key]) {\n    O[key] = val;\n  } else {\n    hide(O, key, val);\n  }\n// add fake Function#toString for correct work wrapped methods / constructors with methods like LoDash isNative\n})(Function.prototype, TO_STRING, function toString() {\n  return typeof this == 'function' && this[SRC] || $toString.call(this);\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_regexp-exec-abstract.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_regexp-exec-abstract.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar builtinExec = RegExp.prototype.exec;\n\n // `RegExpExec` abstract operation\n// https://tc39.github.io/ecma262/#sec-regexpexec\nmodule.exports = function (R, S) {\n  var exec = R.exec;\n  if (typeof exec === 'function') {\n    var result = exec.call(R, S);\n    if (typeof result !== 'object') {\n      throw new TypeError('RegExp exec method returned something other than an Object or null');\n    }\n    return result;\n  }\n  if (classof(R) !== 'RegExp') {\n    throw new TypeError('RegExp#exec called on incompatible receiver');\n  }\n  return builtinExec.call(R, S);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_regexp-exec.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_regexp-exec.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar regexpFlags = __webpack_require__(/*! ./_flags */ \"./node_modules/core-js/modules/_flags.js\");\n\nvar nativeExec = RegExp.prototype.exec;\n// This always refers to the native implementation, because the\n// String#replace polyfill uses ./fix-regexp-well-known-symbol-logic.js,\n// which loads this file before patching the method.\nvar nativeReplace = String.prototype.replace;\n\nvar patchedExec = nativeExec;\n\nvar LAST_INDEX = 'lastIndex';\n\nvar UPDATES_LAST_INDEX_WRONG = (function () {\n  var re1 = /a/,\n      re2 = /b*/g;\n  nativeExec.call(re1, 'a');\n  nativeExec.call(re2, 'a');\n  return re1[LAST_INDEX] !== 0 || re2[LAST_INDEX] !== 0;\n})();\n\n// nonparticipating capturing group, copied from es5-shim's String#split patch.\nvar NPCG_INCLUDED = /()??/.exec('')[1] !== undefined;\n\nvar PATCH = UPDATES_LAST_INDEX_WRONG || NPCG_INCLUDED;\n\nif (PATCH) {\n  patchedExec = function exec(str) {\n    var re = this;\n    var lastIndex, reCopy, match, i;\n\n    if (NPCG_INCLUDED) {\n      reCopy = new RegExp('^' + re.source + '$(?!\\\\s)', regexpFlags.call(re));\n    }\n    if (UPDATES_LAST_INDEX_WRONG) lastIndex = re[LAST_INDEX];\n\n    match = nativeExec.call(re, str);\n\n    if (UPDATES_LAST_INDEX_WRONG && match) {\n      re[LAST_INDEX] = re.global ? match.index + match[0].length : lastIndex;\n    }\n    if (NPCG_INCLUDED && match && match.length > 1) {\n      // Fix browsers whose `exec` methods don't consistently return `undefined`\n      // for NPCG, like IE8. NOTE: This doesn' work for /(.?)?/\n      // eslint-disable-next-line no-loop-func\n      nativeReplace.call(match[0], reCopy, function () {\n        for (i = 1; i < arguments.length - 2; i++) {\n          if (arguments[i] === undefined) match[i] = undefined;\n        }\n      });\n    }\n\n    return match;\n  };\n}\n\nmodule.exports = patchedExec;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_replacer.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_replacer.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (regExp, replace) {\n  var replacer = replace === Object(replace) ? function (part) {\n    return replace[part];\n  } : replace;\n  return function (it) {\n    return String(it).replace(regExp, replacer);\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_same-value.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_same-value.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 7.2.9 SameValue(x, y)\nmodule.exports = Object.is || function is(x, y) {\n  // eslint-disable-next-line no-self-compare\n  return x === y ? x !== 0 || 1 / x === 1 / y : x != x && y != y;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-collection-from.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-collection-from.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/proposal-setmap-offrom/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\n\nmodule.exports = function (COLLECTION) {\n  $export($export.S, COLLECTION, { from: function from(source /* , mapFn, thisArg */) {\n    var mapFn = arguments[1];\n    var mapping, A, n, cb;\n    aFunction(this);\n    mapping = mapFn !== undefined;\n    if (mapping) aFunction(mapFn);\n    if (source == undefined) return new this();\n    A = [];\n    if (mapping) {\n      n = 0;\n      cb = ctx(mapFn, arguments[2], 2);\n      forOf(source, false, function (nextItem) {\n        A.push(cb(nextItem, n++));\n      });\n    } else {\n      forOf(source, false, A.push, A);\n    }\n    return new this(A);\n  } });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-collection-of.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-collection-of.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/proposal-setmap-offrom/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\nmodule.exports = function (COLLECTION) {\n  $export($export.S, COLLECTION, { of: function of() {\n    var length = arguments.length;\n    var A = new Array(length);\n    while (length--) A[length] = arguments[length];\n    return new this(A);\n  } });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-proto.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-proto.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// Works with __proto__ only. Old v8 can't work with null proto objects.\n/* eslint-disable no-proto */\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar check = function (O, proto) {\n  anObject(O);\n  if (!isObject(proto) && proto !== null) throw TypeError(proto + \": can't set as prototype!\");\n};\nmodule.exports = {\n  set: Object.setPrototypeOf || ('__proto__' in {} ? // eslint-disable-line\n    function (test, buggy, set) {\n      try {\n        set = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\")(Function.call, __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f(Object.prototype, '__proto__').set, 2);\n        set(test, []);\n        buggy = !(test instanceof Array);\n      } catch (e) { buggy = true; }\n      return function setPrototypeOf(O, proto) {\n        check(O, proto);\n        if (buggy) O.__proto__ = proto;\n        else set(O, proto);\n        return O;\n      };\n    }({}, false) : undefined),\n  check: check\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-species.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-species.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\n\nmodule.exports = function (KEY) {\n  var C = global[KEY];\n  if (DESCRIPTORS && C && !C[SPECIES]) dP.f(C, SPECIES, {\n    configurable: true,\n    get: function () { return this; }\n  });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-to-string-tag.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-to-string-tag.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar def = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar TAG = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag');\n\nmodule.exports = function (it, tag, stat) {\n  if (it && !has(it = stat ? it : it.prototype, TAG)) def(it, TAG, { configurable: true, value: tag });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_shared-key.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_shared-key.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar shared = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('keys');\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nmodule.exports = function (key) {\n  return shared[key] || (shared[key] = uid(key));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_shared.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_shared.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar SHARED = '__core-js_shared__';\nvar store = global[SHARED] || (global[SHARED] = {});\n\n(module.exports = function (key, value) {\n  return store[key] || (store[key] = value !== undefined ? value : {});\n})('versions', []).push({\n  version: core.version,\n  mode: __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\") ? 'pure' : 'global',\n  copyright: '© 2019 Denis Pushkarev (zloirock.ru)'\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_species-constructor.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_species-constructor.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.3.20 SpeciesConstructor(O, defaultConstructor)\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\nmodule.exports = function (O, D) {\n  var C = anObject(O).constructor;\n  var S;\n  return C === undefined || (S = anObject(C)[SPECIES]) == undefined ? D : aFunction(S);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_strict-method.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_strict-method.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\n\nmodule.exports = function (method, arg) {\n  return !!method && fails(function () {\n    // eslint-disable-next-line no-useless-call\n    arg ? method.call(null, function () { /* empty */ }, 1) : method.call(null);\n  });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-at.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-at.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\n// true  -> String#at\n// false -> String#codePointAt\nmodule.exports = function (TO_STRING) {\n  return function (that, pos) {\n    var s = String(defined(that));\n    var i = toInteger(pos);\n    var l = s.length;\n    var a, b;\n    if (i < 0 || i >= l) return TO_STRING ? '' : undefined;\n    a = s.charCodeAt(i);\n    return a < 0xd800 || a > 0xdbff || i + 1 === l || (b = s.charCodeAt(i + 1)) < 0xdc00 || b > 0xdfff\n      ? TO_STRING ? s.charAt(i) : a\n      : TO_STRING ? s.slice(i, i + 2) : (a - 0xd800 << 10) + (b - 0xdc00) + 0x10000;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-context.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-context.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// helper for String#{startsWith, endsWith, includes}\nvar isRegExp = __webpack_require__(/*! ./_is-regexp */ \"./node_modules/core-js/modules/_is-regexp.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\n\nmodule.exports = function (that, searchString, NAME) {\n  if (isRegExp(searchString)) throw TypeError('String#' + NAME + \" doesn't accept regex!\");\n  return String(defined(that));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-html.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-html.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nvar quot = /\"/g;\n// B.2.3.2.1 CreateHTML(string, tag, attribute, value)\nvar createHTML = function (string, tag, attribute, value) {\n  var S = String(defined(string));\n  var p1 = '<' + tag;\n  if (attribute !== '') p1 += ' ' + attribute + '=\"' + String(value).replace(quot, '&quot;') + '\"';\n  return p1 + '>' + S + '</' + tag + '>';\n};\nmodule.exports = function (NAME, exec) {\n  var O = {};\n  O[NAME] = exec(createHTML);\n  $export($export.P + $export.F * fails(function () {\n    var test = ''[NAME]('\"');\n    return test !== test.toLowerCase() || test.split('\"').length > 3;\n  }), 'String', O);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-pad.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-pad.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-string-pad-start-end\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar repeat = __webpack_require__(/*! ./_string-repeat */ \"./node_modules/core-js/modules/_string-repeat.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\n\nmodule.exports = function (that, maxLength, fillString, left) {\n  var S = String(defined(that));\n  var stringLength = S.length;\n  var fillStr = fillString === undefined ? ' ' : String(fillString);\n  var intMaxLength = toLength(maxLength);\n  if (intMaxLength <= stringLength || fillStr == '') return S;\n  var fillLen = intMaxLength - stringLength;\n  var stringFiller = repeat.call(fillStr, Math.ceil(fillLen / fillStr.length));\n  if (stringFiller.length > fillLen) stringFiller = stringFiller.slice(0, fillLen);\n  return left ? stringFiller + S : S + stringFiller;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-repeat.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-repeat.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\n\nmodule.exports = function repeat(count) {\n  var str = String(defined(this));\n  var res = '';\n  var n = toInteger(count);\n  if (n < 0 || n == Infinity) throw RangeError(\"Count can't be negative\");\n  for (;n > 0; (n >>>= 1) && (str += str)) if (n & 1) res += str;\n  return res;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-trim.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-trim.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar spaces = __webpack_require__(/*! ./_string-ws */ \"./node_modules/core-js/modules/_string-ws.js\");\nvar space = '[' + spaces + ']';\nvar non = '\\u200b\\u0085';\nvar ltrim = RegExp('^' + space + space + '*');\nvar rtrim = RegExp(space + space + '*$');\n\nvar exporter = function (KEY, exec, ALIAS) {\n  var exp = {};\n  var FORCE = fails(function () {\n    return !!spaces[KEY]() || non[KEY]() != non;\n  });\n  var fn = exp[KEY] = FORCE ? exec(trim) : spaces[KEY];\n  if (ALIAS) exp[ALIAS] = fn;\n  $export($export.P + $export.F * FORCE, 'String', exp);\n};\n\n// 1 -> String#trimLeft\n// 2 -> String#trimRight\n// 3 -> String#trim\nvar trim = exporter.trim = function (string, TYPE) {\n  string = String(defined(string));\n  if (TYPE & 1) string = string.replace(ltrim, '');\n  if (TYPE & 2) string = string.replace(rtrim, '');\n  return string;\n};\n\nmodule.exports = exporter;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-ws.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-ws.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = '\\x09\\x0A\\x0B\\x0C\\x0D\\x20\\xA0\\u1680\\u180E\\u2000\\u2001\\u2002\\u2003' +\n  '\\u2004\\u2005\\u2006\\u2007\\u2008\\u2009\\u200A\\u202F\\u205F\\u3000\\u2028\\u2029\\uFEFF';\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_task.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_task.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar invoke = __webpack_require__(/*! ./_invoke */ \"./node_modules/core-js/modules/_invoke.js\");\nvar html = __webpack_require__(/*! ./_html */ \"./node_modules/core-js/modules/_html.js\");\nvar cel = __webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar process = global.process;\nvar setTask = global.setImmediate;\nvar clearTask = global.clearImmediate;\nvar MessageChannel = global.MessageChannel;\nvar Dispatch = global.Dispatch;\nvar counter = 0;\nvar queue = {};\nvar ONREADYSTATECHANGE = 'onreadystatechange';\nvar defer, channel, port;\nvar run = function () {\n  var id = +this;\n  // eslint-disable-next-line no-prototype-builtins\n  if (queue.hasOwnProperty(id)) {\n    var fn = queue[id];\n    delete queue[id];\n    fn();\n  }\n};\nvar listener = function (event) {\n  run.call(event.data);\n};\n// Node.js 0.9+ & IE10+ has setImmediate, otherwise:\nif (!setTask || !clearTask) {\n  setTask = function setImmediate(fn) {\n    var args = [];\n    var i = 1;\n    while (arguments.length > i) args.push(arguments[i++]);\n    queue[++counter] = function () {\n      // eslint-disable-next-line no-new-func\n      invoke(typeof fn == 'function' ? fn : Function(fn), args);\n    };\n    defer(counter);\n    return counter;\n  };\n  clearTask = function clearImmediate(id) {\n    delete queue[id];\n  };\n  // Node.js 0.8-\n  if (__webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\")(process) == 'process') {\n    defer = function (id) {\n      process.nextTick(ctx(run, id, 1));\n    };\n  // Sphere (JS game engine) Dispatch API\n  } else if (Dispatch && Dispatch.now) {\n    defer = function (id) {\n      Dispatch.now(ctx(run, id, 1));\n    };\n  // Browsers with MessageChannel, includes WebWorkers\n  } else if (MessageChannel) {\n    channel = new MessageChannel();\n    port = channel.port2;\n    channel.port1.onmessage = listener;\n    defer = ctx(port.postMessage, port, 1);\n  // Browsers with postMessage, skip WebWorkers\n  // IE8 has postMessage, but it's sync & typeof its postMessage is 'object'\n  } else if (global.addEventListener && typeof postMessage == 'function' && !global.importScripts) {\n    defer = function (id) {\n      global.postMessage(id + '', '*');\n    };\n    global.addEventListener('message', listener, false);\n  // IE8-\n  } else if (ONREADYSTATECHANGE in cel('script')) {\n    defer = function (id) {\n      html.appendChild(cel('script'))[ONREADYSTATECHANGE] = function () {\n        html.removeChild(this);\n        run.call(id);\n      };\n    };\n  // Rest old browsers\n  } else {\n    defer = function (id) {\n      setTimeout(ctx(run, id, 1), 0);\n    };\n  }\n}\nmodule.exports = {\n  set: setTask,\n  clear: clearTask\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-absolute-index.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-absolute-index.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar max = Math.max;\nvar min = Math.min;\nmodule.exports = function (index, length) {\n  index = toInteger(index);\n  return index < 0 ? max(index + length, 0) : min(index, length);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-index.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-index.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/ecma262/#sec-toindex\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nmodule.exports = function (it) {\n  if (it === undefined) return 0;\n  var number = toInteger(it);\n  var length = toLength(number);\n  if (number !== length) throw RangeError('Wrong length!');\n  return length;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-integer.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-integer.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 7.1.4 ToInteger\nvar ceil = Math.ceil;\nvar floor = Math.floor;\nmodule.exports = function (it) {\n  return isNaN(it = +it) ? 0 : (it > 0 ? floor : ceil)(it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-iobject.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-iobject.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// to indexed object, toObject with fallback for non-array-like ES3 strings\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nmodule.exports = function (it) {\n  return IObject(defined(it));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-length.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-length.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.15 ToLength\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar min = Math.min;\nmodule.exports = function (it) {\n  return it > 0 ? min(toInteger(it), 0x1fffffffffffff) : 0; // pow(2, 53) - 1 == 9007199254740991\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.13 ToObject(argument)\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nmodule.exports = function (it) {\n  return Object(defined(it));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-primitive.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-primitive.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.1 ToPrimitive(input [, PreferredType])\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n// instead of the ES6 spec version, we didn't implement @@toPrimitive case\n// and the second argument - flag - preferred type is a string\nmodule.exports = function (it, S) {\n  if (!isObject(it)) return it;\n  var fn, val;\n  if (S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (typeof (fn = it.valueOf) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (!S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  throw TypeError(\"Can't convert object to primitive value\");\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_typed-array.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_typed-array.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nif (__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\")) {\n  var LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\n  var global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\n  var fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\n  var $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n  var $typed = __webpack_require__(/*! ./_typed */ \"./node_modules/core-js/modules/_typed.js\");\n  var $buffer = __webpack_require__(/*! ./_typed-buffer */ \"./node_modules/core-js/modules/_typed-buffer.js\");\n  var ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\n  var anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\n  var propertyDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\n  var hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\n  var redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\n  var toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\n  var toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\n  var toIndex = __webpack_require__(/*! ./_to-index */ \"./node_modules/core-js/modules/_to-index.js\");\n  var toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\n  var toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\n  var has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\n  var classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\n  var isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n  var toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\n  var isArrayIter = __webpack_require__(/*! ./_is-array-iter */ \"./node_modules/core-js/modules/_is-array-iter.js\");\n  var create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\n  var getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\n  var gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f;\n  var getIterFn = __webpack_require__(/*! ./core.get-iterator-method */ \"./node_modules/core-js/modules/core.get-iterator-method.js\");\n  var uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\n  var wks = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\n  var createArrayMethod = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\");\n  var createArrayIncludes = __webpack_require__(/*! ./_array-includes */ \"./node_modules/core-js/modules/_array-includes.js\");\n  var speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\n  var ArrayIterators = __webpack_require__(/*! ./es6.array.iterator */ \"./node_modules/core-js/modules/es6.array.iterator.js\");\n  var Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\n  var $iterDetect = __webpack_require__(/*! ./_iter-detect */ \"./node_modules/core-js/modules/_iter-detect.js\");\n  var setSpecies = __webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\");\n  var arrayFill = __webpack_require__(/*! ./_array-fill */ \"./node_modules/core-js/modules/_array-fill.js\");\n  var arrayCopyWithin = __webpack_require__(/*! ./_array-copy-within */ \"./node_modules/core-js/modules/_array-copy-within.js\");\n  var $DP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\n  var $GOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\n  var dP = $DP.f;\n  var gOPD = $GOPD.f;\n  var RangeError = global.RangeError;\n  var TypeError = global.TypeError;\n  var Uint8Array = global.Uint8Array;\n  var ARRAY_BUFFER = 'ArrayBuffer';\n  var SHARED_BUFFER = 'Shared' + ARRAY_BUFFER;\n  var BYTES_PER_ELEMENT = 'BYTES_PER_ELEMENT';\n  var PROTOTYPE = 'prototype';\n  var ArrayProto = Array[PROTOTYPE];\n  var $ArrayBuffer = $buffer.ArrayBuffer;\n  var $DataView = $buffer.DataView;\n  var arrayForEach = createArrayMethod(0);\n  var arrayFilter = createArrayMethod(2);\n  var arraySome = createArrayMethod(3);\n  var arrayEvery = createArrayMethod(4);\n  var arrayFind = createArrayMethod(5);\n  var arrayFindIndex = createArrayMethod(6);\n  var arrayIncludes = createArrayIncludes(true);\n  var arrayIndexOf = createArrayIncludes(false);\n  var arrayValues = ArrayIterators.values;\n  var arrayKeys = ArrayIterators.keys;\n  var arrayEntries = ArrayIterators.entries;\n  var arrayLastIndexOf = ArrayProto.lastIndexOf;\n  var arrayReduce = ArrayProto.reduce;\n  var arrayReduceRight = ArrayProto.reduceRight;\n  var arrayJoin = ArrayProto.join;\n  var arraySort = ArrayProto.sort;\n  var arraySlice = ArrayProto.slice;\n  var arrayToString = ArrayProto.toString;\n  var arrayToLocaleString = ArrayProto.toLocaleString;\n  var ITERATOR = wks('iterator');\n  var TAG = wks('toStringTag');\n  var TYPED_CONSTRUCTOR = uid('typed_constructor');\n  var DEF_CONSTRUCTOR = uid('def_constructor');\n  var ALL_CONSTRUCTORS = $typed.CONSTR;\n  var TYPED_ARRAY = $typed.TYPED;\n  var VIEW = $typed.VIEW;\n  var WRONG_LENGTH = 'Wrong length!';\n\n  var $map = createArrayMethod(1, function (O, length) {\n    return allocate(speciesConstructor(O, O[DEF_CONSTRUCTOR]), length);\n  });\n\n  var LITTLE_ENDIAN = fails(function () {\n    // eslint-disable-next-line no-undef\n    return new Uint8Array(new Uint16Array([1]).buffer)[0] === 1;\n  });\n\n  var FORCED_SET = !!Uint8Array && !!Uint8Array[PROTOTYPE].set && fails(function () {\n    new Uint8Array(1).set({});\n  });\n\n  var toOffset = function (it, BYTES) {\n    var offset = toInteger(it);\n    if (offset < 0 || offset % BYTES) throw RangeError('Wrong offset!');\n    return offset;\n  };\n\n  var validate = function (it) {\n    if (isObject(it) && TYPED_ARRAY in it) return it;\n    throw TypeError(it + ' is not a typed array!');\n  };\n\n  var allocate = function (C, length) {\n    if (!(isObject(C) && TYPED_CONSTRUCTOR in C)) {\n      throw TypeError('It is not a typed array constructor!');\n    } return new C(length);\n  };\n\n  var speciesFromList = function (O, list) {\n    return fromList(speciesConstructor(O, O[DEF_CONSTRUCTOR]), list);\n  };\n\n  var fromList = function (C, list) {\n    var index = 0;\n    var length = list.length;\n    var result = allocate(C, length);\n    while (length > index) result[index] = list[index++];\n    return result;\n  };\n\n  var addGetter = function (it, key, internal) {\n    dP(it, key, { get: function () { return this._d[internal]; } });\n  };\n\n  var $from = function from(source /* , mapfn, thisArg */) {\n    var O = toObject(source);\n    var aLen = arguments.length;\n    var mapfn = aLen > 1 ? arguments[1] : undefined;\n    var mapping = mapfn !== undefined;\n    var iterFn = getIterFn(O);\n    var i, length, values, result, step, iterator;\n    if (iterFn != undefined && !isArrayIter(iterFn)) {\n      for (iterator = iterFn.call(O), values = [], i = 0; !(step = iterator.next()).done; i++) {\n        values.push(step.value);\n      } O = values;\n    }\n    if (mapping && aLen > 2) mapfn = ctx(mapfn, arguments[2], 2);\n    for (i = 0, length = toLength(O.length), result = allocate(this, length); length > i; i++) {\n      result[i] = mapping ? mapfn(O[i], i) : O[i];\n    }\n    return result;\n  };\n\n  var $of = function of(/* ...items */) {\n    var index = 0;\n    var length = arguments.length;\n    var result = allocate(this, length);\n    while (length > index) result[index] = arguments[index++];\n    return result;\n  };\n\n  // iOS Safari 6.x fails here\n  var TO_LOCALE_BUG = !!Uint8Array && fails(function () { arrayToLocaleString.call(new Uint8Array(1)); });\n\n  var $toLocaleString = function toLocaleString() {\n    return arrayToLocaleString.apply(TO_LOCALE_BUG ? arraySlice.call(validate(this)) : validate(this), arguments);\n  };\n\n  var proto = {\n    copyWithin: function copyWithin(target, start /* , end */) {\n      return arrayCopyWithin.call(validate(this), target, start, arguments.length > 2 ? arguments[2] : undefined);\n    },\n    every: function every(callbackfn /* , thisArg */) {\n      return arrayEvery(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    fill: function fill(value /* , start, end */) { // eslint-disable-line no-unused-vars\n      return arrayFill.apply(validate(this), arguments);\n    },\n    filter: function filter(callbackfn /* , thisArg */) {\n      return speciesFromList(this, arrayFilter(validate(this), callbackfn,\n        arguments.length > 1 ? arguments[1] : undefined));\n    },\n    find: function find(predicate /* , thisArg */) {\n      return arrayFind(validate(this), predicate, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    findIndex: function findIndex(predicate /* , thisArg */) {\n      return arrayFindIndex(validate(this), predicate, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    forEach: function forEach(callbackfn /* , thisArg */) {\n      arrayForEach(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    indexOf: function indexOf(searchElement /* , fromIndex */) {\n      return arrayIndexOf(validate(this), searchElement, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    includes: function includes(searchElement /* , fromIndex */) {\n      return arrayIncludes(validate(this), searchElement, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    join: function join(separator) { // eslint-disable-line no-unused-vars\n      return arrayJoin.apply(validate(this), arguments);\n    },\n    lastIndexOf: function lastIndexOf(searchElement /* , fromIndex */) { // eslint-disable-line no-unused-vars\n      return arrayLastIndexOf.apply(validate(this), arguments);\n    },\n    map: function map(mapfn /* , thisArg */) {\n      return $map(validate(this), mapfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    reduce: function reduce(callbackfn /* , initialValue */) { // eslint-disable-line no-unused-vars\n      return arrayReduce.apply(validate(this), arguments);\n    },\n    reduceRight: function reduceRight(callbackfn /* , initialValue */) { // eslint-disable-line no-unused-vars\n      return arrayReduceRight.apply(validate(this), arguments);\n    },\n    reverse: function reverse() {\n      var that = this;\n      var length = validate(that).length;\n      var middle = Math.floor(length / 2);\n      var index = 0;\n      var value;\n      while (index < middle) {\n        value = that[index];\n        that[index++] = that[--length];\n        that[length] = value;\n      } return that;\n    },\n    some: function some(callbackfn /* , thisArg */) {\n      return arraySome(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    sort: function sort(comparefn) {\n      return arraySort.call(validate(this), comparefn);\n    },\n    subarray: function subarray(begin, end) {\n      var O = validate(this);\n      var length = O.length;\n      var $begin = toAbsoluteIndex(begin, length);\n      return new (speciesConstructor(O, O[DEF_CONSTRUCTOR]))(\n        O.buffer,\n        O.byteOffset + $begin * O.BYTES_PER_ELEMENT,\n        toLength((end === undefined ? length : toAbsoluteIndex(end, length)) - $begin)\n      );\n    }\n  };\n\n  var $slice = function slice(start, end) {\n    return speciesFromList(this, arraySlice.call(validate(this), start, end));\n  };\n\n  var $set = function set(arrayLike /* , offset */) {\n    validate(this);\n    var offset = toOffset(arguments[1], 1);\n    var length = this.length;\n    var src = toObject(arrayLike);\n    var len = toLength(src.length);\n    var index = 0;\n    if (len + offset > length) throw RangeError(WRONG_LENGTH);\n    while (index < len) this[offset + index] = src[index++];\n  };\n\n  var $iterators = {\n    entries: function entries() {\n      return arrayEntries.call(validate(this));\n    },\n    keys: function keys() {\n      return arrayKeys.call(validate(this));\n    },\n    values: function values() {\n      return arrayValues.call(validate(this));\n    }\n  };\n\n  var isTAIndex = function (target, key) {\n    return isObject(target)\n      && target[TYPED_ARRAY]\n      && typeof key != 'symbol'\n      && key in target\n      && String(+key) == String(key);\n  };\n  var $getDesc = function getOwnPropertyDescriptor(target, key) {\n    return isTAIndex(target, key = toPrimitive(key, true))\n      ? propertyDesc(2, target[key])\n      : gOPD(target, key);\n  };\n  var $setDesc = function defineProperty(target, key, desc) {\n    if (isTAIndex(target, key = toPrimitive(key, true))\n      && isObject(desc)\n      && has(desc, 'value')\n      && !has(desc, 'get')\n      && !has(desc, 'set')\n      // TODO: add validation descriptor w/o calling accessors\n      && !desc.configurable\n      && (!has(desc, 'writable') || desc.writable)\n      && (!has(desc, 'enumerable') || desc.enumerable)\n    ) {\n      target[key] = desc.value;\n      return target;\n    } return dP(target, key, desc);\n  };\n\n  if (!ALL_CONSTRUCTORS) {\n    $GOPD.f = $getDesc;\n    $DP.f = $setDesc;\n  }\n\n  $export($export.S + $export.F * !ALL_CONSTRUCTORS, 'Object', {\n    getOwnPropertyDescriptor: $getDesc,\n    defineProperty: $setDesc\n  });\n\n  if (fails(function () { arrayToString.call({}); })) {\n    arrayToString = arrayToLocaleString = function toString() {\n      return arrayJoin.call(this);\n    };\n  }\n\n  var $TypedArrayPrototype$ = redefineAll({}, proto);\n  redefineAll($TypedArrayPrototype$, $iterators);\n  hide($TypedArrayPrototype$, ITERATOR, $iterators.values);\n  redefineAll($TypedArrayPrototype$, {\n    slice: $slice,\n    set: $set,\n    constructor: function () { /* noop */ },\n    toString: arrayToString,\n    toLocaleString: $toLocaleString\n  });\n  addGetter($TypedArrayPrototype$, 'buffer', 'b');\n  addGetter($TypedArrayPrototype$, 'byteOffset', 'o');\n  addGetter($TypedArrayPrototype$, 'byteLength', 'l');\n  addGetter($TypedArrayPrototype$, 'length', 'e');\n  dP($TypedArrayPrototype$, TAG, {\n    get: function () { return this[TYPED_ARRAY]; }\n  });\n\n  // eslint-disable-next-line max-statements\n  module.exports = function (KEY, BYTES, wrapper, CLAMPED) {\n    CLAMPED = !!CLAMPED;\n    var NAME = KEY + (CLAMPED ? 'Clamped' : '') + 'Array';\n    var GETTER = 'get' + KEY;\n    var SETTER = 'set' + KEY;\n    var TypedArray = global[NAME];\n    var Base = TypedArray || {};\n    var TAC = TypedArray && getPrototypeOf(TypedArray);\n    var FORCED = !TypedArray || !$typed.ABV;\n    var O = {};\n    var TypedArrayPrototype = TypedArray && TypedArray[PROTOTYPE];\n    var getter = function (that, index) {\n      var data = that._d;\n      return data.v[GETTER](index * BYTES + data.o, LITTLE_ENDIAN);\n    };\n    var setter = function (that, index, value) {\n      var data = that._d;\n      if (CLAMPED) value = (value = Math.round(value)) < 0 ? 0 : value > 0xff ? 0xff : value & 0xff;\n      data.v[SETTER](index * BYTES + data.o, value, LITTLE_ENDIAN);\n    };\n    var addElement = function (that, index) {\n      dP(that, index, {\n        get: function () {\n          return getter(this, index);\n        },\n        set: function (value) {\n          return setter(this, index, value);\n        },\n        enumerable: true\n      });\n    };\n    if (FORCED) {\n      TypedArray = wrapper(function (that, data, $offset, $length) {\n        anInstance(that, TypedArray, NAME, '_d');\n        var index = 0;\n        var offset = 0;\n        var buffer, byteLength, length, klass;\n        if (!isObject(data)) {\n          length = toIndex(data);\n          byteLength = length * BYTES;\n          buffer = new $ArrayBuffer(byteLength);\n        } else if (data instanceof $ArrayBuffer || (klass = classof(data)) == ARRAY_BUFFER || klass == SHARED_BUFFER) {\n          buffer = data;\n          offset = toOffset($offset, BYTES);\n          var $len = data.byteLength;\n          if ($length === undefined) {\n            if ($len % BYTES) throw RangeError(WRONG_LENGTH);\n            byteLength = $len - offset;\n            if (byteLength < 0) throw RangeError(WRONG_LENGTH);\n          } else {\n            byteLength = toLength($length) * BYTES;\n            if (byteLength + offset > $len) throw RangeError(WRONG_LENGTH);\n          }\n          length = byteLength / BYTES;\n        } else if (TYPED_ARRAY in data) {\n          return fromList(TypedArray, data);\n        } else {\n          return $from.call(TypedArray, data);\n        }\n        hide(that, '_d', {\n          b: buffer,\n          o: offset,\n          l: byteLength,\n          e: length,\n          v: new $DataView(buffer)\n        });\n        while (index < length) addElement(that, index++);\n      });\n      TypedArrayPrototype = TypedArray[PROTOTYPE] = create($TypedArrayPrototype$);\n      hide(TypedArrayPrototype, 'constructor', TypedArray);\n    } else if (!fails(function () {\n      TypedArray(1);\n    }) || !fails(function () {\n      new TypedArray(-1); // eslint-disable-line no-new\n    }) || !$iterDetect(function (iter) {\n      new TypedArray(); // eslint-disable-line no-new\n      new TypedArray(null); // eslint-disable-line no-new\n      new TypedArray(1.5); // eslint-disable-line no-new\n      new TypedArray(iter); // eslint-disable-line no-new\n    }, true)) {\n      TypedArray = wrapper(function (that, data, $offset, $length) {\n        anInstance(that, TypedArray, NAME);\n        var klass;\n        // `ws` module bug, temporarily remove validation length for Uint8Array\n        // https://github.com/websockets/ws/pull/645\n        if (!isObject(data)) return new Base(toIndex(data));\n        if (data instanceof $ArrayBuffer || (klass = classof(data)) == ARRAY_BUFFER || klass == SHARED_BUFFER) {\n          return $length !== undefined\n            ? new Base(data, toOffset($offset, BYTES), $length)\n            : $offset !== undefined\n              ? new Base(data, toOffset($offset, BYTES))\n              : new Base(data);\n        }\n        if (TYPED_ARRAY in data) return fromList(TypedArray, data);\n        return $from.call(TypedArray, data);\n      });\n      arrayForEach(TAC !== Function.prototype ? gOPN(Base).concat(gOPN(TAC)) : gOPN(Base), function (key) {\n        if (!(key in TypedArray)) hide(TypedArray, key, Base[key]);\n      });\n      TypedArray[PROTOTYPE] = TypedArrayPrototype;\n      if (!LIBRARY) TypedArrayPrototype.constructor = TypedArray;\n    }\n    var $nativeIterator = TypedArrayPrototype[ITERATOR];\n    var CORRECT_ITER_NAME = !!$nativeIterator\n      && ($nativeIterator.name == 'values' || $nativeIterator.name == undefined);\n    var $iterator = $iterators.values;\n    hide(TypedArray, TYPED_CONSTRUCTOR, true);\n    hide(TypedArrayPrototype, TYPED_ARRAY, NAME);\n    hide(TypedArrayPrototype, VIEW, true);\n    hide(TypedArrayPrototype, DEF_CONSTRUCTOR, TypedArray);\n\n    if (CLAMPED ? new TypedArray(1)[TAG] != NAME : !(TAG in TypedArrayPrototype)) {\n      dP(TypedArrayPrototype, TAG, {\n        get: function () { return NAME; }\n      });\n    }\n\n    O[NAME] = TypedArray;\n\n    $export($export.G + $export.W + $export.F * (TypedArray != Base), O);\n\n    $export($export.S, NAME, {\n      BYTES_PER_ELEMENT: BYTES\n    });\n\n    $export($export.S + $export.F * fails(function () { Base.of.call(TypedArray, 1); }), NAME, {\n      from: $from,\n      of: $of\n    });\n\n    if (!(BYTES_PER_ELEMENT in TypedArrayPrototype)) hide(TypedArrayPrototype, BYTES_PER_ELEMENT, BYTES);\n\n    $export($export.P, NAME, proto);\n\n    setSpecies(NAME);\n\n    $export($export.P + $export.F * FORCED_SET, NAME, { set: $set });\n\n    $export($export.P + $export.F * !CORRECT_ITER_NAME, NAME, $iterators);\n\n    if (!LIBRARY && TypedArrayPrototype.toString != arrayToString) TypedArrayPrototype.toString = arrayToString;\n\n    $export($export.P + $export.F * fails(function () {\n      new TypedArray(1).slice();\n    }), NAME, { slice: $slice });\n\n    $export($export.P + $export.F * (fails(function () {\n      return [1, 2].toLocaleString() != new TypedArray([1, 2]).toLocaleString();\n    }) || !fails(function () {\n      TypedArrayPrototype.toLocaleString.call([1, 2]);\n    })), NAME, { toLocaleString: $toLocaleString });\n\n    Iterators[NAME] = CORRECT_ITER_NAME ? $nativeIterator : $iterator;\n    if (!LIBRARY && !CORRECT_ITER_NAME) hide(TypedArrayPrototype, ITERATOR, $iterator);\n  };\n} else module.exports = function () { /* empty */ };\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_typed-buffer.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_typed-buffer.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar $typed = __webpack_require__(/*! ./_typed */ \"./node_modules/core-js/modules/_typed.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar toIndex = __webpack_require__(/*! ./_to-index */ \"./node_modules/core-js/modules/_to-index.js\");\nvar gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f;\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar arrayFill = __webpack_require__(/*! ./_array-fill */ \"./node_modules/core-js/modules/_array-fill.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar ARRAY_BUFFER = 'ArrayBuffer';\nvar DATA_VIEW = 'DataView';\nvar PROTOTYPE = 'prototype';\nvar WRONG_LENGTH = 'Wrong length!';\nvar WRONG_INDEX = 'Wrong index!';\nvar $ArrayBuffer = global[ARRAY_BUFFER];\nvar $DataView = global[DATA_VIEW];\nvar Math = global.Math;\nvar RangeError = global.RangeError;\n// eslint-disable-next-line no-shadow-restricted-names\nvar Infinity = global.Infinity;\nvar BaseBuffer = $ArrayBuffer;\nvar abs = Math.abs;\nvar pow = Math.pow;\nvar floor = Math.floor;\nvar log = Math.log;\nvar LN2 = Math.LN2;\nvar BUFFER = 'buffer';\nvar BYTE_LENGTH = 'byteLength';\nvar BYTE_OFFSET = 'byteOffset';\nvar $BUFFER = DESCRIPTORS ? '_b' : BUFFER;\nvar $LENGTH = DESCRIPTORS ? '_l' : BYTE_LENGTH;\nvar $OFFSET = DESCRIPTORS ? '_o' : BYTE_OFFSET;\n\n// IEEE754 conversions based on https://github.com/feross/ieee754\nfunction packIEEE754(value, mLen, nBytes) {\n  var buffer = new Array(nBytes);\n  var eLen = nBytes * 8 - mLen - 1;\n  var eMax = (1 << eLen) - 1;\n  var eBias = eMax >> 1;\n  var rt = mLen === 23 ? pow(2, -24) - pow(2, -77) : 0;\n  var i = 0;\n  var s = value < 0 || value === 0 && 1 / value < 0 ? 1 : 0;\n  var e, m, c;\n  value = abs(value);\n  // eslint-disable-next-line no-self-compare\n  if (value != value || value === Infinity) {\n    // eslint-disable-next-line no-self-compare\n    m = value != value ? 1 : 0;\n    e = eMax;\n  } else {\n    e = floor(log(value) / LN2);\n    if (value * (c = pow(2, -e)) < 1) {\n      e--;\n      c *= 2;\n    }\n    if (e + eBias >= 1) {\n      value += rt / c;\n    } else {\n      value += rt * pow(2, 1 - eBias);\n    }\n    if (value * c >= 2) {\n      e++;\n      c /= 2;\n    }\n    if (e + eBias >= eMax) {\n      m = 0;\n      e = eMax;\n    } else if (e + eBias >= 1) {\n      m = (value * c - 1) * pow(2, mLen);\n      e = e + eBias;\n    } else {\n      m = value * pow(2, eBias - 1) * pow(2, mLen);\n      e = 0;\n    }\n  }\n  for (; mLen >= 8; buffer[i++] = m & 255, m /= 256, mLen -= 8);\n  e = e << mLen | m;\n  eLen += mLen;\n  for (; eLen > 0; buffer[i++] = e & 255, e /= 256, eLen -= 8);\n  buffer[--i] |= s * 128;\n  return buffer;\n}\nfunction unpackIEEE754(buffer, mLen, nBytes) {\n  var eLen = nBytes * 8 - mLen - 1;\n  var eMax = (1 << eLen) - 1;\n  var eBias = eMax >> 1;\n  var nBits = eLen - 7;\n  var i = nBytes - 1;\n  var s = buffer[i--];\n  var e = s & 127;\n  var m;\n  s >>= 7;\n  for (; nBits > 0; e = e * 256 + buffer[i], i--, nBits -= 8);\n  m = e & (1 << -nBits) - 1;\n  e >>= -nBits;\n  nBits += mLen;\n  for (; nBits > 0; m = m * 256 + buffer[i], i--, nBits -= 8);\n  if (e === 0) {\n    e = 1 - eBias;\n  } else if (e === eMax) {\n    return m ? NaN : s ? -Infinity : Infinity;\n  } else {\n    m = m + pow(2, mLen);\n    e = e - eBias;\n  } return (s ? -1 : 1) * m * pow(2, e - mLen);\n}\n\nfunction unpackI32(bytes) {\n  return bytes[3] << 24 | bytes[2] << 16 | bytes[1] << 8 | bytes[0];\n}\nfunction packI8(it) {\n  return [it & 0xff];\n}\nfunction packI16(it) {\n  return [it & 0xff, it >> 8 & 0xff];\n}\nfunction packI32(it) {\n  return [it & 0xff, it >> 8 & 0xff, it >> 16 & 0xff, it >> 24 & 0xff];\n}\nfunction packF64(it) {\n  return packIEEE754(it, 52, 8);\n}\nfunction packF32(it) {\n  return packIEEE754(it, 23, 4);\n}\n\nfunction addGetter(C, key, internal) {\n  dP(C[PROTOTYPE], key, { get: function () { return this[internal]; } });\n}\n\nfunction get(view, bytes, index, isLittleEndian) {\n  var numIndex = +index;\n  var intIndex = toIndex(numIndex);\n  if (intIndex + bytes > view[$LENGTH]) throw RangeError(WRONG_INDEX);\n  var store = view[$BUFFER]._b;\n  var start = intIndex + view[$OFFSET];\n  var pack = store.slice(start, start + bytes);\n  return isLittleEndian ? pack : pack.reverse();\n}\nfunction set(view, bytes, index, conversion, value, isLittleEndian) {\n  var numIndex = +index;\n  var intIndex = toIndex(numIndex);\n  if (intIndex + bytes > view[$LENGTH]) throw RangeError(WRONG_INDEX);\n  var store = view[$BUFFER]._b;\n  var start = intIndex + view[$OFFSET];\n  var pack = conversion(+value);\n  for (var i = 0; i < bytes; i++) store[start + i] = pack[isLittleEndian ? i : bytes - i - 1];\n}\n\nif (!$typed.ABV) {\n  $ArrayBuffer = function ArrayBuffer(length) {\n    anInstance(this, $ArrayBuffer, ARRAY_BUFFER);\n    var byteLength = toIndex(length);\n    this._b = arrayFill.call(new Array(byteLength), 0);\n    this[$LENGTH] = byteLength;\n  };\n\n  $DataView = function DataView(buffer, byteOffset, byteLength) {\n    anInstance(this, $DataView, DATA_VIEW);\n    anInstance(buffer, $ArrayBuffer, DATA_VIEW);\n    var bufferLength = buffer[$LENGTH];\n    var offset = toInteger(byteOffset);\n    if (offset < 0 || offset > bufferLength) throw RangeError('Wrong offset!');\n    byteLength = byteLength === undefined ? bufferLength - offset : toLength(byteLength);\n    if (offset + byteLength > bufferLength) throw RangeError(WRONG_LENGTH);\n    this[$BUFFER] = buffer;\n    this[$OFFSET] = offset;\n    this[$LENGTH] = byteLength;\n  };\n\n  if (DESCRIPTORS) {\n    addGetter($ArrayBuffer, BYTE_LENGTH, '_l');\n    addGetter($DataView, BUFFER, '_b');\n    addGetter($DataView, BYTE_LENGTH, '_l');\n    addGetter($DataView, BYTE_OFFSET, '_o');\n  }\n\n  redefineAll($DataView[PROTOTYPE], {\n    getInt8: function getInt8(byteOffset) {\n      return get(this, 1, byteOffset)[0] << 24 >> 24;\n    },\n    getUint8: function getUint8(byteOffset) {\n      return get(this, 1, byteOffset)[0];\n    },\n    getInt16: function getInt16(byteOffset /* , littleEndian */) {\n      var bytes = get(this, 2, byteOffset, arguments[1]);\n      return (bytes[1] << 8 | bytes[0]) << 16 >> 16;\n    },\n    getUint16: function getUint16(byteOffset /* , littleEndian */) {\n      var bytes = get(this, 2, byteOffset, arguments[1]);\n      return bytes[1] << 8 | bytes[0];\n    },\n    getInt32: function getInt32(byteOffset /* , littleEndian */) {\n      return unpackI32(get(this, 4, byteOffset, arguments[1]));\n    },\n    getUint32: function getUint32(byteOffset /* , littleEndian */) {\n      return unpackI32(get(this, 4, byteOffset, arguments[1])) >>> 0;\n    },\n    getFloat32: function getFloat32(byteOffset /* , littleEndian */) {\n      return unpackIEEE754(get(this, 4, byteOffset, arguments[1]), 23, 4);\n    },\n    getFloat64: function getFloat64(byteOffset /* , littleEndian */) {\n      return unpackIEEE754(get(this, 8, byteOffset, arguments[1]), 52, 8);\n    },\n    setInt8: function setInt8(byteOffset, value) {\n      set(this, 1, byteOffset, packI8, value);\n    },\n    setUint8: function setUint8(byteOffset, value) {\n      set(this, 1, byteOffset, packI8, value);\n    },\n    setInt16: function setInt16(byteOffset, value /* , littleEndian */) {\n      set(this, 2, byteOffset, packI16, value, arguments[2]);\n    },\n    setUint16: function setUint16(byteOffset, value /* , littleEndian */) {\n      set(this, 2, byteOffset, packI16, value, arguments[2]);\n    },\n    setInt32: function setInt32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packI32, value, arguments[2]);\n    },\n    setUint32: function setUint32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packI32, value, arguments[2]);\n    },\n    setFloat32: function setFloat32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packF32, value, arguments[2]);\n    },\n    setFloat64: function setFloat64(byteOffset, value /* , littleEndian */) {\n      set(this, 8, byteOffset, packF64, value, arguments[2]);\n    }\n  });\n} else {\n  if (!fails(function () {\n    $ArrayBuffer(1);\n  }) || !fails(function () {\n    new $ArrayBuffer(-1); // eslint-disable-line no-new\n  }) || fails(function () {\n    new $ArrayBuffer(); // eslint-disable-line no-new\n    new $ArrayBuffer(1.5); // eslint-disable-line no-new\n    new $ArrayBuffer(NaN); // eslint-disable-line no-new\n    return $ArrayBuffer.name != ARRAY_BUFFER;\n  })) {\n    $ArrayBuffer = function ArrayBuffer(length) {\n      anInstance(this, $ArrayBuffer);\n      return new BaseBuffer(toIndex(length));\n    };\n    var ArrayBufferProto = $ArrayBuffer[PROTOTYPE] = BaseBuffer[PROTOTYPE];\n    for (var keys = gOPN(BaseBuffer), j = 0, key; keys.length > j;) {\n      if (!((key = keys[j++]) in $ArrayBuffer)) hide($ArrayBuffer, key, BaseBuffer[key]);\n    }\n    if (!LIBRARY) ArrayBufferProto.constructor = $ArrayBuffer;\n  }\n  // iOS Safari 7.x bug\n  var view = new $DataView(new $ArrayBuffer(2));\n  var $setInt8 = $DataView[PROTOTYPE].setInt8;\n  view.setInt8(0, 2147483648);\n  view.setInt8(1, 2147483649);\n  if (view.getInt8(0) || !view.getInt8(1)) redefineAll($DataView[PROTOTYPE], {\n    setInt8: function setInt8(byteOffset, value) {\n      $setInt8.call(this, byteOffset, value << 24 >> 24);\n    },\n    setUint8: function setUint8(byteOffset, value) {\n      $setInt8.call(this, byteOffset, value << 24 >> 24);\n    }\n  }, true);\n}\nsetToStringTag($ArrayBuffer, ARRAY_BUFFER);\nsetToStringTag($DataView, DATA_VIEW);\nhide($DataView[PROTOTYPE], $typed.VIEW, true);\nexports[ARRAY_BUFFER] = $ArrayBuffer;\nexports[DATA_VIEW] = $DataView;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_typed.js\":\n/*!************************************************!*\\\n  !*** ./node_modules/core-js/modules/_typed.js ***!\n  \\************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nvar TYPED = uid('typed_array');\nvar VIEW = uid('view');\nvar ABV = !!(global.ArrayBuffer && global.DataView);\nvar CONSTR = ABV;\nvar i = 0;\nvar l = 9;\nvar Typed;\n\nvar TypedArrayConstructors = (\n  'Int8Array,Uint8Array,Uint8ClampedArray,Int16Array,Uint16Array,Int32Array,Uint32Array,Float32Array,Float64Array'\n).split(',');\n\nwhile (i < l) {\n  if (Typed = global[TypedArrayConstructors[i++]]) {\n    hide(Typed.prototype, TYPED, true);\n    hide(Typed.prototype, VIEW, true);\n  } else CONSTR = false;\n}\n\nmodule.exports = {\n  ABV: ABV,\n  CONSTR: CONSTR,\n  TYPED: TYPED,\n  VIEW: VIEW\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_uid.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_uid.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar id = 0;\nvar px = Math.random();\nmodule.exports = function (key) {\n  return 'Symbol('.concat(key === undefined ? '' : key, ')_', (++id + px).toString(36));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_user-agent.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_user-agent.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar navigator = global.navigator;\n\nmodule.exports = navigator && navigator.userAgent || '';\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_validate-collection.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_validate-collection.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nmodule.exports = function (it, TYPE) {\n  if (!isObject(it) || it._t !== TYPE) throw TypeError('Incompatible receiver, ' + TYPE + ' required!');\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_wks-define.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_wks-define.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar wksExt = __webpack_require__(/*! ./_wks-ext */ \"./node_modules/core-js/modules/_wks-ext.js\");\nvar defineProperty = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nmodule.exports = function (name) {\n  var $Symbol = core.Symbol || (core.Symbol = LIBRARY ? {} : global.Symbol || {});\n  if (name.charAt(0) != '_' && !(name in $Symbol)) defineProperty($Symbol, name, { value: wksExt.f(name) });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_wks-ext.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_wks-ext.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nexports.f = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_wks.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_wks.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar store = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('wks');\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nvar Symbol = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").Symbol;\nvar USE_SYMBOL = typeof Symbol == 'function';\n\nvar $exports = module.exports = function (name) {\n  return store[name] || (store[name] =\n    USE_SYMBOL && Symbol[name] || (USE_SYMBOL ? Symbol : uid)('Symbol.' + name));\n};\n\n$exports.store = store;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/core.get-iterator-method.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/core.get-iterator-method.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nmodule.exports = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\").getIteratorMethod = function (it) {\n  if (it != undefined) return it[ITERATOR]\n    || it['@@iterator']\n    || Iterators[classof(it)];\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/core.regexp.escape.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/core.regexp.escape.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/benjamingr/RexExp.escape\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $re = __webpack_require__(/*! ./_replacer */ \"./node_modules/core-js/modules/_replacer.js\")(/[\\\\^$*+?.()|[\\]{}]/g, '\\\\$&');\n\n$export($export.S, 'RegExp', { escape: function escape(it) { return $re(it); } });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.copy-within.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.copy-within.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.3.3 Array.prototype.copyWithin(target, start, end = this.length)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P, 'Array', { copyWithin: __webpack_require__(/*! ./_array-copy-within */ \"./node_modules/core-js/modules/_array-copy-within.js\") });\n\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")('copyWithin');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.every.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.every.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $every = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(4);\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].every, true), 'Array', {\n  // 22.1.3.5 / 15.4.4.16 Array.prototype.every(callbackfn [, thisArg])\n  every: function every(callbackfn /* , thisArg */) {\n    return $every(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.fill.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.fill.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.3.6 Array.prototype.fill(value, start = 0, end = this.length)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P, 'Array', { fill: __webpack_require__(/*! ./_array-fill */ \"./node_modules/core-js/modules/_array-fill.js\") });\n\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")('fill');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.filter.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.filter.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $filter = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(2);\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].filter, true), 'Array', {\n  // 22.1.3.7 / 15.4.4.20 Array.prototype.filter(callbackfn [, thisArg])\n  filter: function filter(callbackfn /* , thisArg */) {\n    return $filter(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.find-index.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.find-index.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 22.1.3.9 Array.prototype.findIndex(predicate, thisArg = undefined)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $find = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(6);\nvar KEY = 'findIndex';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  findIndex: function findIndex(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")(KEY);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.find.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.find.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 22.1.3.8 Array.prototype.find(predicate, thisArg = undefined)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $find = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(5);\nvar KEY = 'find';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  find: function find(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")(KEY);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.for-each.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.for-each.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $forEach = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(0);\nvar STRICT = __webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].forEach, true);\n\n$export($export.P + $export.F * !STRICT, 'Array', {\n  // 22.1.3.10 / 15.4.4.18 Array.prototype.forEach(callbackfn [, thisArg])\n  forEach: function forEach(callbackfn /* , thisArg */) {\n    return $forEach(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.from.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.from.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar call = __webpack_require__(/*! ./_iter-call */ \"./node_modules/core-js/modules/_iter-call.js\");\nvar isArrayIter = __webpack_require__(/*! ./_is-array-iter */ \"./node_modules/core-js/modules/_is-array-iter.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar createProperty = __webpack_require__(/*! ./_create-property */ \"./node_modules/core-js/modules/_create-property.js\");\nvar getIterFn = __webpack_require__(/*! ./core.get-iterator-method */ \"./node_modules/core-js/modules/core.get-iterator-method.js\");\n\n$export($export.S + $export.F * !__webpack_require__(/*! ./_iter-detect */ \"./node_modules/core-js/modules/_iter-detect.js\")(function (iter) { Array.from(iter); }), 'Array', {\n  // 22.1.2.1 Array.from(arrayLike, mapfn = undefined, thisArg = undefined)\n  from: function from(arrayLike /* , mapfn = undefined, thisArg = undefined */) {\n    var O = toObject(arrayLike);\n    var C = typeof this == 'function' ? this : Array;\n    var aLen = arguments.length;\n    var mapfn = aLen > 1 ? arguments[1] : undefined;\n    var mapping = mapfn !== undefined;\n    var index = 0;\n    var iterFn = getIterFn(O);\n    var length, result, step, iterator;\n    if (mapping) mapfn = ctx(mapfn, aLen > 2 ? arguments[2] : undefined, 2);\n    // if object isn't iterable or it's array with default iterator - use simple case\n    if (iterFn != undefined && !(C == Array && isArrayIter(iterFn))) {\n      for (iterator = iterFn.call(O), result = new C(); !(step = iterator.next()).done; index++) {\n        createProperty(result, index, mapping ? call(iterator, mapfn, [step.value, index], true) : step.value);\n      }\n    } else {\n      length = toLength(O.length);\n      for (result = new C(length); length > index; index++) {\n        createProperty(result, index, mapping ? mapfn(O[index], index) : O[index]);\n      }\n    }\n    result.length = index;\n    return result;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.index-of.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.index-of.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $indexOf = __webpack_require__(/*! ./_array-includes */ \"./node_modules/core-js/modules/_array-includes.js\")(false);\nvar $native = [].indexOf;\nvar NEGATIVE_ZERO = !!$native && 1 / [1].indexOf(1, -0) < 0;\n\n$export($export.P + $export.F * (NEGATIVE_ZERO || !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")($native)), 'Array', {\n  // 22.1.3.11 / 15.4.4.14 Array.prototype.indexOf(searchElement [, fromIndex])\n  indexOf: function indexOf(searchElement /* , fromIndex = 0 */) {\n    return NEGATIVE_ZERO\n      // convert -0 to +0\n      ? $native.apply(this, arguments) || 0\n      : $indexOf(this, searchElement, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.is-array.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.is-array.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.2.2 / 15.4.3.2 Array.isArray(arg)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Array', { isArray: __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.iterator.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.iterator.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar addToUnscopables = __webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\");\nvar step = __webpack_require__(/*! ./_iter-step */ \"./node_modules/core-js/modules/_iter-step.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\n\n// 22.1.3.4 Array.prototype.entries()\n// 22.1.3.13 Array.prototype.keys()\n// 22.1.3.29 Array.prototype.values()\n// 22.1.3.30 Array.prototype[@@iterator]()\nmodule.exports = __webpack_require__(/*! ./_iter-define */ \"./node_modules/core-js/modules/_iter-define.js\")(Array, 'Array', function (iterated, kind) {\n  this._t = toIObject(iterated); // target\n  this._i = 0;                   // next index\n  this._k = kind;                // kind\n// 22.1.5.2.1 %ArrayIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var kind = this._k;\n  var index = this._i++;\n  if (!O || index >= O.length) {\n    this._t = undefined;\n    return step(1);\n  }\n  if (kind == 'keys') return step(0, index);\n  if (kind == 'values') return step(0, O[index]);\n  return step(0, [index, O[index]]);\n}, 'values');\n\n// argumentsList[@@iterator] is %ArrayProto_values% (9.4.4.6, 9.4.4.7)\nIterators.Arguments = Iterators.Array;\n\naddToUnscopables('keys');\naddToUnscopables('values');\naddToUnscopables('entries');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.join.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.join.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 22.1.3.13 Array.prototype.join(separator)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar arrayJoin = [].join;\n\n// fallback for not array-like strings\n$export($export.P + $export.F * (__webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\") != Object || !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")(arrayJoin)), 'Array', {\n  join: function join(separator) {\n    return arrayJoin.call(toIObject(this), separator === undefined ? ',' : separator);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.last-index-of.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.last-index-of.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar $native = [].lastIndexOf;\nvar NEGATIVE_ZERO = !!$native && 1 / [1].lastIndexOf(1, -0) < 0;\n\n$export($export.P + $export.F * (NEGATIVE_ZERO || !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")($native)), 'Array', {\n  // 22.1.3.14 / 15.4.4.15 Array.prototype.lastIndexOf(searchElement [, fromIndex])\n  lastIndexOf: function lastIndexOf(searchElement /* , fromIndex = @[*-1] */) {\n    // convert -0 to +0\n    if (NEGATIVE_ZERO) return $native.apply(this, arguments) || 0;\n    var O = toIObject(this);\n    var length = toLength(O.length);\n    var index = length - 1;\n    if (arguments.length > 1) index = Math.min(index, toInteger(arguments[1]));\n    if (index < 0) index = length + index;\n    for (;index >= 0; index--) if (index in O) if (O[index] === searchElement) return index || 0;\n    return -1;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.map.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.map.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $map = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(1);\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].map, true), 'Array', {\n  // 22.1.3.15 / 15.4.4.19 Array.prototype.map(callbackfn [, thisArg])\n  map: function map(callbackfn /* , thisArg */) {\n    return $map(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.of.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.of.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar createProperty = __webpack_require__(/*! ./_create-property */ \"./node_modules/core-js/modules/_create-property.js\");\n\n// WebKit Array.of isn't generic\n$export($export.S + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  function F() { /* empty */ }\n  return !(Array.of.call(F) instanceof F);\n}), 'Array', {\n  // 22.1.2.3 Array.of( ...items)\n  of: function of(/* ...args */) {\n    var index = 0;\n    var aLen = arguments.length;\n    var result = new (typeof this == 'function' ? this : Array)(aLen);\n    while (aLen > index) createProperty(result, index, arguments[index++]);\n    result.length = aLen;\n    return result;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.reduce-right.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.reduce-right.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $reduce = __webpack_require__(/*! ./_array-reduce */ \"./node_modules/core-js/modules/_array-reduce.js\");\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].reduceRight, true), 'Array', {\n  // 22.1.3.19 / 15.4.4.22 Array.prototype.reduceRight(callbackfn [, initialValue])\n  reduceRight: function reduceRight(callbackfn /* , initialValue */) {\n    return $reduce(this, callbackfn, arguments.length, arguments[1], true);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.reduce.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.reduce.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $reduce = __webpack_require__(/*! ./_array-reduce */ \"./node_modules/core-js/modules/_array-reduce.js\");\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].reduce, true), 'Array', {\n  // 22.1.3.18 / 15.4.4.21 Array.prototype.reduce(callbackfn [, initialValue])\n  reduce: function reduce(callbackfn /* , initialValue */) {\n    return $reduce(this, callbackfn, arguments.length, arguments[1], false);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.slice.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.slice.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar html = __webpack_require__(/*! ./_html */ \"./node_modules/core-js/modules/_html.js\");\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar arraySlice = [].slice;\n\n// fallback for not array-like ES3 strings and DOM objects\n$export($export.P + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  if (html) arraySlice.call(html);\n}), 'Array', {\n  slice: function slice(begin, end) {\n    var len = toLength(this.length);\n    var klass = cof(this);\n    end = end === undefined ? len : end;\n    if (klass == 'Array') return arraySlice.call(this, begin, end);\n    var start = toAbsoluteIndex(begin, len);\n    var upTo = toAbsoluteIndex(end, len);\n    var size = toLength(upTo - start);\n    var cloned = new Array(size);\n    var i = 0;\n    for (; i < size; i++) cloned[i] = klass == 'String'\n      ? this.charAt(start + i)\n      : this[start + i];\n    return cloned;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.some.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.some.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $some = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(3);\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].some, true), 'Array', {\n  // 22.1.3.23 / 15.4.4.17 Array.prototype.some(callbackfn [, thisArg])\n  some: function some(callbackfn /* , thisArg */) {\n    return $some(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.sort.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.sort.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar $sort = [].sort;\nvar test = [1, 2, 3];\n\n$export($export.P + $export.F * (fails(function () {\n  // IE8-\n  test.sort(undefined);\n}) || !fails(function () {\n  // V8 bug\n  test.sort(null);\n  // Old WebKit\n}) || !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")($sort)), 'Array', {\n  // 22.1.3.25 Array.prototype.sort(comparefn)\n  sort: function sort(comparefn) {\n    return comparefn === undefined\n      ? $sort.call(toObject(this))\n      : $sort.call(toObject(this), aFunction(comparefn));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.species.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.species.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")('Array');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.date.now.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.date.now.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.3.3.1 / 15.9.4.4 Date.now()\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Date', { now: function () { return new Date().getTime(); } });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.date.to-iso-string.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.date.to-iso-string.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.3.4.36 / 15.9.5.43 Date.prototype.toISOString()\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toISOString = __webpack_require__(/*! ./_date-to-iso-string */ \"./node_modules/core-js/modules/_date-to-iso-string.js\");\n\n// PhantomJS / old WebKit has a broken implementations\n$export($export.P + $export.F * (Date.prototype.toISOString !== toISOString), 'Date', {\n  toISOString: toISOString\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.date.to-json.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.date.to-json.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\n\n$export($export.P + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return new Date(NaN).toJSON() !== null\n    || Date.prototype.toJSON.call({ toISOString: function () { return 1; } }) !== 1;\n}), 'Date', {\n  // eslint-disable-next-line no-unused-vars\n  toJSON: function toJSON(key) {\n    var O = toObject(this);\n    var pv = toPrimitive(O);\n    return typeof pv == 'number' && !isFinite(pv) ? null : O.toISOString();\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.date.to-primitive.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.date.to-primitive.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar TO_PRIMITIVE = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toPrimitive');\nvar proto = Date.prototype;\n\nif (!(TO_PRIMITIVE in proto)) __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")(proto, TO_PRIMITIVE, __webpack_require__(/*! ./_date-to-primitive */ \"./node_modules/core-js/modules/_date-to-primitive.js\"));\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.date.to-string.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.date.to-string.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar DateProto = Date.prototype;\nvar INVALID_DATE = 'Invalid Date';\nvar TO_STRING = 'toString';\nvar $toString = DateProto[TO_STRING];\nvar getTime = DateProto.getTime;\nif (new Date(NaN) + '' != INVALID_DATE) {\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(DateProto, TO_STRING, function toString() {\n    var value = getTime.call(this);\n    // eslint-disable-next-line no-self-compare\n    return value === value ? $toString.call(this) : INVALID_DATE;\n  });\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.function.bind.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.function.bind.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.2.3.2 / 15.3.4.5 Function.prototype.bind(thisArg, args...)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P, 'Function', { bind: __webpack_require__(/*! ./_bind */ \"./node_modules/core-js/modules/_bind.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.function.has-instance.js\":\n/*!*******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.function.has-instance.js ***!\n  \\*******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar HAS_INSTANCE = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('hasInstance');\nvar FunctionProto = Function.prototype;\n// 19.2.3.6 Function.prototype[@@hasInstance](V)\nif (!(HAS_INSTANCE in FunctionProto)) __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f(FunctionProto, HAS_INSTANCE, { value: function (O) {\n  if (typeof this != 'function' || !isObject(O)) return false;\n  if (!isObject(this.prototype)) return O instanceof this;\n  // for environment w/o native `@@hasInstance` logic enough `instanceof`, but add this:\n  while (O = getPrototypeOf(O)) if (this.prototype === O) return true;\n  return false;\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.function.name.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.function.name.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar FProto = Function.prototype;\nvar nameRE = /^\\s*function ([^ (]*)/;\nvar NAME = 'name';\n\n// 19.2.4.2 name\nNAME in FProto || __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && dP(FProto, NAME, {\n  configurable: true,\n  get: function () {\n    try {\n      return ('' + this).match(nameRE)[1];\n    } catch (e) {\n      return '';\n    }\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.map.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.map.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar strong = __webpack_require__(/*! ./_collection-strong */ \"./node_modules/core-js/modules/_collection-strong.js\");\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar MAP = 'Map';\n\n// 23.1 Map Objects\nmodule.exports = __webpack_require__(/*! ./_collection */ \"./node_modules/core-js/modules/_collection.js\")(MAP, function (get) {\n  return function Map() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.1.3.6 Map.prototype.get(key)\n  get: function get(key) {\n    var entry = strong.getEntry(validate(this, MAP), key);\n    return entry && entry.v;\n  },\n  // 23.1.3.9 Map.prototype.set(key, value)\n  set: function set(key, value) {\n    return strong.def(validate(this, MAP), key === 0 ? 0 : key, value);\n  }\n}, strong, true);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.acosh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.acosh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.3 Math.acosh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar log1p = __webpack_require__(/*! ./_math-log1p */ \"./node_modules/core-js/modules/_math-log1p.js\");\nvar sqrt = Math.sqrt;\nvar $acosh = Math.acosh;\n\n$export($export.S + $export.F * !($acosh\n  // V8 bug: https://code.google.com/p/v8/issues/detail?id=3509\n  && Math.floor($acosh(Number.MAX_VALUE)) == 710\n  // Tor Browser bug: Math.acosh(Infinity) -> NaN\n  && $acosh(Infinity) == Infinity\n), 'Math', {\n  acosh: function acosh(x) {\n    return (x = +x) < 1 ? NaN : x > 94906265.62425156\n      ? Math.log(x) + Math.LN2\n      : log1p(x - 1 + sqrt(x - 1) * sqrt(x + 1));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.asinh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.asinh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.5 Math.asinh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $asinh = Math.asinh;\n\nfunction asinh(x) {\n  return !isFinite(x = +x) || x == 0 ? x : x < 0 ? -asinh(-x) : Math.log(x + Math.sqrt(x * x + 1));\n}\n\n// Tor Browser bug: Math.asinh(0) -> -0\n$export($export.S + $export.F * !($asinh && 1 / $asinh(0) > 0), 'Math', { asinh: asinh });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.atanh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.atanh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.7 Math.atanh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $atanh = Math.atanh;\n\n// Tor Browser bug: Math.atanh(-0) -> 0\n$export($export.S + $export.F * !($atanh && 1 / $atanh(-0) < 0), 'Math', {\n  atanh: function atanh(x) {\n    return (x = +x) == 0 ? x : Math.log((1 + x) / (1 - x)) / 2;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.cbrt.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.cbrt.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.9 Math.cbrt(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar sign = __webpack_require__(/*! ./_math-sign */ \"./node_modules/core-js/modules/_math-sign.js\");\n\n$export($export.S, 'Math', {\n  cbrt: function cbrt(x) {\n    return sign(x = +x) * Math.pow(Math.abs(x), 1 / 3);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.clz32.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.clz32.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.11 Math.clz32(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  clz32: function clz32(x) {\n    return (x >>>= 0) ? 31 - Math.floor(Math.log(x + 0.5) * Math.LOG2E) : 32;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.cosh.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.cosh.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.12 Math.cosh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar exp = Math.exp;\n\n$export($export.S, 'Math', {\n  cosh: function cosh(x) {\n    return (exp(x = +x) + exp(-x)) / 2;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.expm1.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.expm1.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.14 Math.expm1(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $expm1 = __webpack_require__(/*! ./_math-expm1 */ \"./node_modules/core-js/modules/_math-expm1.js\");\n\n$export($export.S + $export.F * ($expm1 != Math.expm1), 'Math', { expm1: $expm1 });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.fround.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.fround.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.16 Math.fround(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { fround: __webpack_require__(/*! ./_math-fround */ \"./node_modules/core-js/modules/_math-fround.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.hypot.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.hypot.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.17 Math.hypot([value1[, value2[, … ]]])\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar abs = Math.abs;\n\n$export($export.S, 'Math', {\n  hypot: function hypot(value1, value2) { // eslint-disable-line no-unused-vars\n    var sum = 0;\n    var i = 0;\n    var aLen = arguments.length;\n    var larg = 0;\n    var arg, div;\n    while (i < aLen) {\n      arg = abs(arguments[i++]);\n      if (larg < arg) {\n        div = larg / arg;\n        sum = sum * div * div + 1;\n        larg = arg;\n      } else if (arg > 0) {\n        div = arg / larg;\n        sum += div * div;\n      } else sum += arg;\n    }\n    return larg === Infinity ? Infinity : larg * Math.sqrt(sum);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.imul.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.imul.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.18 Math.imul(x, y)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $imul = Math.imul;\n\n// some WebKit versions fails with big numbers, some has wrong arity\n$export($export.S + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return $imul(0xffffffff, 5) != -5 || $imul.length != 2;\n}), 'Math', {\n  imul: function imul(x, y) {\n    var UINT16 = 0xffff;\n    var xn = +x;\n    var yn = +y;\n    var xl = UINT16 & xn;\n    var yl = UINT16 & yn;\n    return 0 | xl * yl + ((UINT16 & xn >>> 16) * yl + xl * (UINT16 & yn >>> 16) << 16 >>> 0);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.log10.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.log10.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.21 Math.log10(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  log10: function log10(x) {\n    return Math.log(x) * Math.LOG10E;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.log1p.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.log1p.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.20 Math.log1p(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { log1p: __webpack_require__(/*! ./_math-log1p */ \"./node_modules/core-js/modules/_math-log1p.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.log2.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.log2.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.22 Math.log2(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  log2: function log2(x) {\n    return Math.log(x) / Math.LN2;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.sign.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.sign.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.28 Math.sign(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { sign: __webpack_require__(/*! ./_math-sign */ \"./node_modules/core-js/modules/_math-sign.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.sinh.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.sinh.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.30 Math.sinh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar expm1 = __webpack_require__(/*! ./_math-expm1 */ \"./node_modules/core-js/modules/_math-expm1.js\");\nvar exp = Math.exp;\n\n// V8 near Chromium 38 has a problem with very small numbers\n$export($export.S + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return !Math.sinh(-2e-17) != -2e-17;\n}), 'Math', {\n  sinh: function sinh(x) {\n    return Math.abs(x = +x) < 1\n      ? (expm1(x) - expm1(-x)) / 2\n      : (exp(x - 1) - exp(-x - 1)) * (Math.E / 2);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.tanh.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.tanh.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.33 Math.tanh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar expm1 = __webpack_require__(/*! ./_math-expm1 */ \"./node_modules/core-js/modules/_math-expm1.js\");\nvar exp = Math.exp;\n\n$export($export.S, 'Math', {\n  tanh: function tanh(x) {\n    var a = expm1(x = +x);\n    var b = expm1(-x);\n    return a == Infinity ? 1 : b == Infinity ? -1 : (a - b) / (exp(x) + exp(-x));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.trunc.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.trunc.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.34 Math.trunc(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  trunc: function trunc(it) {\n    return (it > 0 ? Math.floor : Math.ceil)(it);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.constructor.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.constructor.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nvar inheritIfRequired = __webpack_require__(/*! ./_inherit-if-required */ \"./node_modules/core-js/modules/_inherit-if-required.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f;\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f;\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar $trim = __webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\").trim;\nvar NUMBER = 'Number';\nvar $Number = global[NUMBER];\nvar Base = $Number;\nvar proto = $Number.prototype;\n// Opera ~12 has broken Object#toString\nvar BROKEN_COF = cof(__webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\")(proto)) == NUMBER;\nvar TRIM = 'trim' in String.prototype;\n\n// 7.1.3 ToNumber(argument)\nvar toNumber = function (argument) {\n  var it = toPrimitive(argument, false);\n  if (typeof it == 'string' && it.length > 2) {\n    it = TRIM ? it.trim() : $trim(it, 3);\n    var first = it.charCodeAt(0);\n    var third, radix, maxCode;\n    if (first === 43 || first === 45) {\n      third = it.charCodeAt(2);\n      if (third === 88 || third === 120) return NaN; // Number('+0x1') should be NaN, old V8 fix\n    } else if (first === 48) {\n      switch (it.charCodeAt(1)) {\n        case 66: case 98: radix = 2; maxCode = 49; break; // fast equal /^0b[01]+$/i\n        case 79: case 111: radix = 8; maxCode = 55; break; // fast equal /^0o[0-7]+$/i\n        default: return +it;\n      }\n      for (var digits = it.slice(2), i = 0, l = digits.length, code; i < l; i++) {\n        code = digits.charCodeAt(i);\n        // parseInt parses a string to a first unavailable symbol\n        // but ToNumber should return NaN if a string contains unavailable symbols\n        if (code < 48 || code > maxCode) return NaN;\n      } return parseInt(digits, radix);\n    }\n  } return +it;\n};\n\nif (!$Number(' 0o1') || !$Number('0b1') || $Number('+0x1')) {\n  $Number = function Number(value) {\n    var it = arguments.length < 1 ? 0 : value;\n    var that = this;\n    return that instanceof $Number\n      // check on 1..constructor(foo) case\n      && (BROKEN_COF ? fails(function () { proto.valueOf.call(that); }) : cof(that) != NUMBER)\n        ? inheritIfRequired(new Base(toNumber(it)), that, $Number) : toNumber(it);\n  };\n  for (var keys = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? gOPN(Base) : (\n    // ES3:\n    'MAX_VALUE,MIN_VALUE,NaN,NEGATIVE_INFINITY,POSITIVE_INFINITY,' +\n    // ES6 (in case, if modules with ES6 Number statics required before):\n    'EPSILON,isFinite,isInteger,isNaN,isSafeInteger,MAX_SAFE_INTEGER,' +\n    'MIN_SAFE_INTEGER,parseFloat,parseInt,isInteger'\n  ).split(','), j = 0, key; keys.length > j; j++) {\n    if (has(Base, key = keys[j]) && !has($Number, key)) {\n      dP($Number, key, gOPD(Base, key));\n    }\n  }\n  $Number.prototype = proto;\n  proto.constructor = $Number;\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(global, NUMBER, $Number);\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.epsilon.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.epsilon.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.1 Number.EPSILON\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Number', { EPSILON: Math.pow(2, -52) });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.is-finite.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.is-finite.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.2 Number.isFinite(number)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar _isFinite = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").isFinite;\n\n$export($export.S, 'Number', {\n  isFinite: function isFinite(it) {\n    return typeof it == 'number' && _isFinite(it);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.is-integer.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.is-integer.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.3 Number.isInteger(number)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Number', { isInteger: __webpack_require__(/*! ./_is-integer */ \"./node_modules/core-js/modules/_is-integer.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.is-nan.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.is-nan.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.4 Number.isNaN(number)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Number', {\n  isNaN: function isNaN(number) {\n    // eslint-disable-next-line no-self-compare\n    return number != number;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.is-safe-integer.js\":\n/*!********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.is-safe-integer.js ***!\n  \\********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.5 Number.isSafeInteger(number)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar isInteger = __webpack_require__(/*! ./_is-integer */ \"./node_modules/core-js/modules/_is-integer.js\");\nvar abs = Math.abs;\n\n$export($export.S, 'Number', {\n  isSafeInteger: function isSafeInteger(number) {\n    return isInteger(number) && abs(number) <= 0x1fffffffffffff;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.max-safe-integer.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.max-safe-integer.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.6 Number.MAX_SAFE_INTEGER\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Number', { MAX_SAFE_INTEGER: 0x1fffffffffffff });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.min-safe-integer.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.min-safe-integer.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.10 Number.MIN_SAFE_INTEGER\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Number', { MIN_SAFE_INTEGER: -0x1fffffffffffff });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.parse-float.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.parse-float.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $parseFloat = __webpack_require__(/*! ./_parse-float */ \"./node_modules/core-js/modules/_parse-float.js\");\n// 20.1.2.12 Number.parseFloat(string)\n$export($export.S + $export.F * (Number.parseFloat != $parseFloat), 'Number', { parseFloat: $parseFloat });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.parse-int.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.parse-int.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $parseInt = __webpack_require__(/*! ./_parse-int */ \"./node_modules/core-js/modules/_parse-int.js\");\n// 20.1.2.13 Number.parseInt(string, radix)\n$export($export.S + $export.F * (Number.parseInt != $parseInt), 'Number', { parseInt: $parseInt });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.to-fixed.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.to-fixed.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar aNumberValue = __webpack_require__(/*! ./_a-number-value */ \"./node_modules/core-js/modules/_a-number-value.js\");\nvar repeat = __webpack_require__(/*! ./_string-repeat */ \"./node_modules/core-js/modules/_string-repeat.js\");\nvar $toFixed = 1.0.toFixed;\nvar floor = Math.floor;\nvar data = [0, 0, 0, 0, 0, 0];\nvar ERROR = 'Number.toFixed: incorrect invocation!';\nvar ZERO = '0';\n\nvar multiply = function (n, c) {\n  var i = -1;\n  var c2 = c;\n  while (++i < 6) {\n    c2 += n * data[i];\n    data[i] = c2 % 1e7;\n    c2 = floor(c2 / 1e7);\n  }\n};\nvar divide = function (n) {\n  var i = 6;\n  var c = 0;\n  while (--i >= 0) {\n    c += data[i];\n    data[i] = floor(c / n);\n    c = (c % n) * 1e7;\n  }\n};\nvar numToString = function () {\n  var i = 6;\n  var s = '';\n  while (--i >= 0) {\n    if (s !== '' || i === 0 || data[i] !== 0) {\n      var t = String(data[i]);\n      s = s === '' ? t : s + repeat.call(ZERO, 7 - t.length) + t;\n    }\n  } return s;\n};\nvar pow = function (x, n, acc) {\n  return n === 0 ? acc : n % 2 === 1 ? pow(x, n - 1, acc * x) : pow(x * x, n / 2, acc);\n};\nvar log = function (x) {\n  var n = 0;\n  var x2 = x;\n  while (x2 >= 4096) {\n    n += 12;\n    x2 /= 4096;\n  }\n  while (x2 >= 2) {\n    n += 1;\n    x2 /= 2;\n  } return n;\n};\n\n$export($export.P + $export.F * (!!$toFixed && (\n  0.00008.toFixed(3) !== '0.000' ||\n  0.9.toFixed(0) !== '1' ||\n  1.255.toFixed(2) !== '1.25' ||\n  1000000000000000128.0.toFixed(0) !== '1000000000000000128'\n) || !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  // V8 ~ Android 4.3-\n  $toFixed.call({});\n})), 'Number', {\n  toFixed: function toFixed(fractionDigits) {\n    var x = aNumberValue(this, ERROR);\n    var f = toInteger(fractionDigits);\n    var s = '';\n    var m = ZERO;\n    var e, z, j, k;\n    if (f < 0 || f > 20) throw RangeError(ERROR);\n    // eslint-disable-next-line no-self-compare\n    if (x != x) return 'NaN';\n    if (x <= -1e21 || x >= 1e21) return String(x);\n    if (x < 0) {\n      s = '-';\n      x = -x;\n    }\n    if (x > 1e-21) {\n      e = log(x * pow(2, 69, 1)) - 69;\n      z = e < 0 ? x * pow(2, -e, 1) : x / pow(2, e, 1);\n      z *= 0x10000000000000;\n      e = 52 - e;\n      if (e > 0) {\n        multiply(0, z);\n        j = f;\n        while (j >= 7) {\n          multiply(1e7, 0);\n          j -= 7;\n        }\n        multiply(pow(10, j, 1), 0);\n        j = e - 1;\n        while (j >= 23) {\n          divide(1 << 23);\n          j -= 23;\n        }\n        divide(1 << j);\n        multiply(1, 1);\n        divide(2);\n        m = numToString();\n      } else {\n        multiply(0, z);\n        multiply(1 << -e, 0);\n        m = numToString() + repeat.call(ZERO, f);\n      }\n    }\n    if (f > 0) {\n      k = m.length;\n      m = s + (k <= f ? '0.' + repeat.call(ZERO, f - k) + m : m.slice(0, k - f) + '.' + m.slice(k - f));\n    } else {\n      m = s + m;\n    } return m;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.to-precision.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.to-precision.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar aNumberValue = __webpack_require__(/*! ./_a-number-value */ \"./node_modules/core-js/modules/_a-number-value.js\");\nvar $toPrecision = 1.0.toPrecision;\n\n$export($export.P + $export.F * ($fails(function () {\n  // IE7-\n  return $toPrecision.call(1, undefined) !== '1';\n}) || !$fails(function () {\n  // V8 ~ Android 4.3-\n  $toPrecision.call({});\n})), 'Number', {\n  toPrecision: function toPrecision(precision) {\n    var that = aNumberValue(this, 'Number#toPrecision: incorrect invocation!');\n    return precision === undefined ? $toPrecision.call(that) : $toPrecision.call(that, precision);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.assign.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.assign.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.3.1 Object.assign(target, source)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S + $export.F, 'Object', { assign: __webpack_require__(/*! ./_object-assign */ \"./node_modules/core-js/modules/_object-assign.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.create.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.create.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\n$export($export.S, 'Object', { create: __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.define-properties.js\":\n/*!**********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.define-properties.js ***!\n  \\**********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n// 19.1.2.3 / 15.2.3.7 Object.defineProperties(O, Properties)\n$export($export.S + $export.F * !__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\"), 'Object', { defineProperties: __webpack_require__(/*! ./_object-dps */ \"./node_modules/core-js/modules/_object-dps.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.define-property.js\":\n/*!********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.define-property.js ***!\n  \\********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n// 19.1.2.4 / 15.2.3.6 Object.defineProperty(O, P, Attributes)\n$export($export.S + $export.F * !__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\"), 'Object', { defineProperty: __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.freeze.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.freeze.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.5 Object.freeze(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar meta = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").onFreeze;\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('freeze', function ($freeze) {\n  return function freeze(it) {\n    return $freeze && isObject(it) ? $freeze(meta(it)) : it;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.get-own-property-descriptor.js\":\n/*!********************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.get-own-property-descriptor.js ***!\n  \\********************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.6 Object.getOwnPropertyDescriptor(O, P)\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar $getOwnPropertyDescriptor = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f;\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('getOwnPropertyDescriptor', function () {\n  return function getOwnPropertyDescriptor(it, key) {\n    return $getOwnPropertyDescriptor(toIObject(it), key);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.get-own-property-names.js\":\n/*!***************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.get-own-property-names.js ***!\n  \\***************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.7 Object.getOwnPropertyNames(O)\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('getOwnPropertyNames', function () {\n  return __webpack_require__(/*! ./_object-gopn-ext */ \"./node_modules/core-js/modules/_object-gopn-ext.js\").f;\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.get-prototype-of.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.get-prototype-of.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.9 Object.getPrototypeOf(O)\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar $getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('getPrototypeOf', function () {\n  return function getPrototypeOf(it) {\n    return $getPrototypeOf(toObject(it));\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.is-extensible.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.is-extensible.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.11 Object.isExtensible(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('isExtensible', function ($isExtensible) {\n  return function isExtensible(it) {\n    return isObject(it) ? $isExtensible ? $isExtensible(it) : true : false;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.is-frozen.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.is-frozen.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.12 Object.isFrozen(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('isFrozen', function ($isFrozen) {\n  return function isFrozen(it) {\n    return isObject(it) ? $isFrozen ? $isFrozen(it) : false : true;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.is-sealed.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.is-sealed.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.13 Object.isSealed(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('isSealed', function ($isSealed) {\n  return function isSealed(it) {\n    return isObject(it) ? $isSealed ? $isSealed(it) : false : true;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.is.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.is.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.3.10 Object.is(value1, value2)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n$export($export.S, 'Object', { is: __webpack_require__(/*! ./_same-value */ \"./node_modules/core-js/modules/_same-value.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.keys.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.keys.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.14 Object.keys(O)\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar $keys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('keys', function () {\n  return function keys(it) {\n    return $keys(toObject(it));\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.prevent-extensions.js\":\n/*!***********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.prevent-extensions.js ***!\n  \\***********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.15 Object.preventExtensions(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar meta = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").onFreeze;\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('preventExtensions', function ($preventExtensions) {\n  return function preventExtensions(it) {\n    return $preventExtensions && isObject(it) ? $preventExtensions(meta(it)) : it;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.seal.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.seal.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.17 Object.seal(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar meta = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").onFreeze;\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('seal', function ($seal) {\n  return function seal(it) {\n    return $seal && isObject(it) ? $seal(meta(it)) : it;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.set-prototype-of.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.set-prototype-of.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.3.19 Object.setPrototypeOf(O, proto)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n$export($export.S, 'Object', { setPrototypeOf: __webpack_require__(/*! ./_set-proto */ \"./node_modules/core-js/modules/_set-proto.js\").set });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.to-string.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.to-string.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 19.1.3.6 Object.prototype.toString()\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar test = {};\ntest[__webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag')] = 'z';\nif (test + '' != '[object z]') {\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(Object.prototype, 'toString', function toString() {\n    return '[object ' + classof(this) + ']';\n  }, true);\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.parse-float.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.parse-float.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $parseFloat = __webpack_require__(/*! ./_parse-float */ \"./node_modules/core-js/modules/_parse-float.js\");\n// 18.2.4 parseFloat(string)\n$export($export.G + $export.F * (parseFloat != $parseFloat), { parseFloat: $parseFloat });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.parse-int.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.parse-int.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $parseInt = __webpack_require__(/*! ./_parse-int */ \"./node_modules/core-js/modules/_parse-int.js\");\n// 18.2.5 parseInt(string, radix)\n$export($export.G + $export.F * (parseInt != $parseInt), { parseInt: $parseInt });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.promise.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.promise.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\nvar task = __webpack_require__(/*! ./_task */ \"./node_modules/core-js/modules/_task.js\").set;\nvar microtask = __webpack_require__(/*! ./_microtask */ \"./node_modules/core-js/modules/_microtask.js\")();\nvar newPromiseCapabilityModule = __webpack_require__(/*! ./_new-promise-capability */ \"./node_modules/core-js/modules/_new-promise-capability.js\");\nvar perform = __webpack_require__(/*! ./_perform */ \"./node_modules/core-js/modules/_perform.js\");\nvar userAgent = __webpack_require__(/*! ./_user-agent */ \"./node_modules/core-js/modules/_user-agent.js\");\nvar promiseResolve = __webpack_require__(/*! ./_promise-resolve */ \"./node_modules/core-js/modules/_promise-resolve.js\");\nvar PROMISE = 'Promise';\nvar TypeError = global.TypeError;\nvar process = global.process;\nvar versions = process && process.versions;\nvar v8 = versions && versions.v8 || '';\nvar $Promise = global[PROMISE];\nvar isNode = classof(process) == 'process';\nvar empty = function () { /* empty */ };\nvar Internal, newGenericPromiseCapability, OwnPromiseCapability, Wrapper;\nvar newPromiseCapability = newGenericPromiseCapability = newPromiseCapabilityModule.f;\n\nvar USE_NATIVE = !!function () {\n  try {\n    // correct subclassing with @@species support\n    var promise = $Promise.resolve(1);\n    var FakePromise = (promise.constructor = {})[__webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species')] = function (exec) {\n      exec(empty, empty);\n    };\n    // unhandled rejections tracking support, NodeJS Promise without it fails @@species test\n    return (isNode || typeof PromiseRejectionEvent == 'function')\n      && promise.then(empty) instanceof FakePromise\n      // v8 6.6 (Node 10 and Chrome 66) have a bug with resolving custom thenables\n      // https://bugs.chromium.org/p/chromium/issues/detail?id=830565\n      // we can't detect it synchronously, so just check versions\n      && v8.indexOf('6.6') !== 0\n      && userAgent.indexOf('Chrome/66') === -1;\n  } catch (e) { /* empty */ }\n}();\n\n// helpers\nvar isThenable = function (it) {\n  var then;\n  return isObject(it) && typeof (then = it.then) == 'function' ? then : false;\n};\nvar notify = function (promise, isReject) {\n  if (promise._n) return;\n  promise._n = true;\n  var chain = promise._c;\n  microtask(function () {\n    var value = promise._v;\n    var ok = promise._s == 1;\n    var i = 0;\n    var run = function (reaction) {\n      var handler = ok ? reaction.ok : reaction.fail;\n      var resolve = reaction.resolve;\n      var reject = reaction.reject;\n      var domain = reaction.domain;\n      var result, then, exited;\n      try {\n        if (handler) {\n          if (!ok) {\n            if (promise._h == 2) onHandleUnhandled(promise);\n            promise._h = 1;\n          }\n          if (handler === true) result = value;\n          else {\n            if (domain) domain.enter();\n            result = handler(value); // may throw\n            if (domain) {\n              domain.exit();\n              exited = true;\n            }\n          }\n          if (result === reaction.promise) {\n            reject(TypeError('Promise-chain cycle'));\n          } else if (then = isThenable(result)) {\n            then.call(result, resolve, reject);\n          } else resolve(result);\n        } else reject(value);\n      } catch (e) {\n        if (domain && !exited) domain.exit();\n        reject(e);\n      }\n    };\n    while (chain.length > i) run(chain[i++]); // variable length - can't use forEach\n    promise._c = [];\n    promise._n = false;\n    if (isReject && !promise._h) onUnhandled(promise);\n  });\n};\nvar onUnhandled = function (promise) {\n  task.call(global, function () {\n    var value = promise._v;\n    var unhandled = isUnhandled(promise);\n    var result, handler, console;\n    if (unhandled) {\n      result = perform(function () {\n        if (isNode) {\n          process.emit('unhandledRejection', value, promise);\n        } else if (handler = global.onunhandledrejection) {\n          handler({ promise: promise, reason: value });\n        } else if ((console = global.console) && console.error) {\n          console.error('Unhandled promise rejection', value);\n        }\n      });\n      // Browsers should not trigger `rejectionHandled` event if it was handled here, NodeJS - should\n      promise._h = isNode || isUnhandled(promise) ? 2 : 1;\n    } promise._a = undefined;\n    if (unhandled && result.e) throw result.v;\n  });\n};\nvar isUnhandled = function (promise) {\n  return promise._h !== 1 && (promise._a || promise._c).length === 0;\n};\nvar onHandleUnhandled = function (promise) {\n  task.call(global, function () {\n    var handler;\n    if (isNode) {\n      process.emit('rejectionHandled', promise);\n    } else if (handler = global.onrejectionhandled) {\n      handler({ promise: promise, reason: promise._v });\n    }\n  });\n};\nvar $reject = function (value) {\n  var promise = this;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  promise._v = value;\n  promise._s = 2;\n  if (!promise._a) promise._a = promise._c.slice();\n  notify(promise, true);\n};\nvar $resolve = function (value) {\n  var promise = this;\n  var then;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  try {\n    if (promise === value) throw TypeError(\"Promise can't be resolved itself\");\n    if (then = isThenable(value)) {\n      microtask(function () {\n        var wrapper = { _w: promise, _d: false }; // wrap\n        try {\n          then.call(value, ctx($resolve, wrapper, 1), ctx($reject, wrapper, 1));\n        } catch (e) {\n          $reject.call(wrapper, e);\n        }\n      });\n    } else {\n      promise._v = value;\n      promise._s = 1;\n      notify(promise, false);\n    }\n  } catch (e) {\n    $reject.call({ _w: promise, _d: false }, e); // wrap\n  }\n};\n\n// constructor polyfill\nif (!USE_NATIVE) {\n  // 25.4.3.1 Promise(executor)\n  $Promise = function Promise(executor) {\n    anInstance(this, $Promise, PROMISE, '_h');\n    aFunction(executor);\n    Internal.call(this);\n    try {\n      executor(ctx($resolve, this, 1), ctx($reject, this, 1));\n    } catch (err) {\n      $reject.call(this, err);\n    }\n  };\n  // eslint-disable-next-line no-unused-vars\n  Internal = function Promise(executor) {\n    this._c = [];             // <- awaiting reactions\n    this._a = undefined;      // <- checked in isUnhandled reactions\n    this._s = 0;              // <- state\n    this._d = false;          // <- done\n    this._v = undefined;      // <- value\n    this._h = 0;              // <- rejection state, 0 - default, 1 - handled, 2 - unhandled\n    this._n = false;          // <- notify\n  };\n  Internal.prototype = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\")($Promise.prototype, {\n    // 25.4.5.3 Promise.prototype.then(onFulfilled, onRejected)\n    then: function then(onFulfilled, onRejected) {\n      var reaction = newPromiseCapability(speciesConstructor(this, $Promise));\n      reaction.ok = typeof onFulfilled == 'function' ? onFulfilled : true;\n      reaction.fail = typeof onRejected == 'function' && onRejected;\n      reaction.domain = isNode ? process.domain : undefined;\n      this._c.push(reaction);\n      if (this._a) this._a.push(reaction);\n      if (this._s) notify(this, false);\n      return reaction.promise;\n    },\n    // 25.4.5.1 Promise.prototype.catch(onRejected)\n    'catch': function (onRejected) {\n      return this.then(undefined, onRejected);\n    }\n  });\n  OwnPromiseCapability = function () {\n    var promise = new Internal();\n    this.promise = promise;\n    this.resolve = ctx($resolve, promise, 1);\n    this.reject = ctx($reject, promise, 1);\n  };\n  newPromiseCapabilityModule.f = newPromiseCapability = function (C) {\n    return C === $Promise || C === Wrapper\n      ? new OwnPromiseCapability(C)\n      : newGenericPromiseCapability(C);\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Promise: $Promise });\n__webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\")($Promise, PROMISE);\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")(PROMISE);\nWrapper = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\")[PROMISE];\n\n// statics\n$export($export.S + $export.F * !USE_NATIVE, PROMISE, {\n  // 25.4.4.5 Promise.reject(r)\n  reject: function reject(r) {\n    var capability = newPromiseCapability(this);\n    var $$reject = capability.reject;\n    $$reject(r);\n    return capability.promise;\n  }\n});\n$export($export.S + $export.F * (LIBRARY || !USE_NATIVE), PROMISE, {\n  // 25.4.4.6 Promise.resolve(x)\n  resolve: function resolve(x) {\n    return promiseResolve(LIBRARY && this === Wrapper ? $Promise : this, x);\n  }\n});\n$export($export.S + $export.F * !(USE_NATIVE && __webpack_require__(/*! ./_iter-detect */ \"./node_modules/core-js/modules/_iter-detect.js\")(function (iter) {\n  $Promise.all(iter)['catch'](empty);\n})), PROMISE, {\n  // 25.4.4.1 Promise.all(iterable)\n  all: function all(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var resolve = capability.resolve;\n    var reject = capability.reject;\n    var result = perform(function () {\n      var values = [];\n      var index = 0;\n      var remaining = 1;\n      forOf(iterable, false, function (promise) {\n        var $index = index++;\n        var alreadyCalled = false;\n        values.push(undefined);\n        remaining++;\n        C.resolve(promise).then(function (value) {\n          if (alreadyCalled) return;\n          alreadyCalled = true;\n          values[$index] = value;\n          --remaining || resolve(values);\n        }, reject);\n      });\n      --remaining || resolve(values);\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  },\n  // 25.4.4.4 Promise.race(iterable)\n  race: function race(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var reject = capability.reject;\n    var result = perform(function () {\n      forOf(iterable, false, function (promise) {\n        C.resolve(promise).then(capability.resolve, reject);\n      });\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.apply.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.apply.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.1 Reflect.apply(target, thisArgument, argumentsList)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar rApply = (__webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").Reflect || {}).apply;\nvar fApply = Function.apply;\n// MS Edge argumentsList argument is optional\n$export($export.S + $export.F * !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  rApply(function () { /* empty */ });\n}), 'Reflect', {\n  apply: function apply(target, thisArgument, argumentsList) {\n    var T = aFunction(target);\n    var L = anObject(argumentsList);\n    return rApply ? rApply(T, thisArgument, L) : fApply.call(T, thisArgument, L);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.construct.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.construct.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.2 Reflect.construct(target, argumentsList [, newTarget])\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar bind = __webpack_require__(/*! ./_bind */ \"./node_modules/core-js/modules/_bind.js\");\nvar rConstruct = (__webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").Reflect || {}).construct;\n\n// MS Edge supports only 2 arguments and argumentsList argument is optional\n// FF Nightly sets third argument as `new.target`, but does not create `this` from it\nvar NEW_TARGET_BUG = fails(function () {\n  function F() { /* empty */ }\n  return !(rConstruct(function () { /* empty */ }, [], F) instanceof F);\n});\nvar ARGS_BUG = !fails(function () {\n  rConstruct(function () { /* empty */ });\n});\n\n$export($export.S + $export.F * (NEW_TARGET_BUG || ARGS_BUG), 'Reflect', {\n  construct: function construct(Target, args /* , newTarget */) {\n    aFunction(Target);\n    anObject(args);\n    var newTarget = arguments.length < 3 ? Target : aFunction(arguments[2]);\n    if (ARGS_BUG && !NEW_TARGET_BUG) return rConstruct(Target, args, newTarget);\n    if (Target == newTarget) {\n      // w/o altered newTarget, optimization for 0-4 arguments\n      switch (args.length) {\n        case 0: return new Target();\n        case 1: return new Target(args[0]);\n        case 2: return new Target(args[0], args[1]);\n        case 3: return new Target(args[0], args[1], args[2]);\n        case 4: return new Target(args[0], args[1], args[2], args[3]);\n      }\n      // w/o altered newTarget, lot of arguments case\n      var $args = [null];\n      $args.push.apply($args, args);\n      return new (bind.apply(Target, $args))();\n    }\n    // with altered newTarget, not support built-in constructors\n    var proto = newTarget.prototype;\n    var instance = create(isObject(proto) ? proto : Object.prototype);\n    var result = Function.apply.call(Target, instance, args);\n    return isObject(result) ? result : instance;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.define-property.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.define-property.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.3 Reflect.defineProperty(target, propertyKey, attributes)\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\n\n// MS Edge has broken Reflect.defineProperty - throwing instead of returning false\n$export($export.S + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  // eslint-disable-next-line no-undef\n  Reflect.defineProperty(dP.f({}, 1, { value: 1 }), 1, { value: 2 });\n}), 'Reflect', {\n  defineProperty: function defineProperty(target, propertyKey, attributes) {\n    anObject(target);\n    propertyKey = toPrimitive(propertyKey, true);\n    anObject(attributes);\n    try {\n      dP.f(target, propertyKey, attributes);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.delete-property.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.delete-property.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.4 Reflect.deleteProperty(target, propertyKey)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f;\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\n\n$export($export.S, 'Reflect', {\n  deleteProperty: function deleteProperty(target, propertyKey) {\n    var desc = gOPD(anObject(target), propertyKey);\n    return desc && !desc.configurable ? false : delete target[propertyKey];\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.enumerate.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.enumerate.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 26.1.5 Reflect.enumerate(target)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar Enumerate = function (iterated) {\n  this._t = anObject(iterated); // target\n  this._i = 0;                  // next index\n  var keys = this._k = [];      // keys\n  var key;\n  for (key in iterated) keys.push(key);\n};\n__webpack_require__(/*! ./_iter-create */ \"./node_modules/core-js/modules/_iter-create.js\")(Enumerate, 'Object', function () {\n  var that = this;\n  var keys = that._k;\n  var key;\n  do {\n    if (that._i >= keys.length) return { value: undefined, done: true };\n  } while (!((key = keys[that._i++]) in that._t));\n  return { value: key, done: false };\n});\n\n$export($export.S, 'Reflect', {\n  enumerate: function enumerate(target) {\n    return new Enumerate(target);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.get-own-property-descriptor.js\":\n/*!*********************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.get-own-property-descriptor.js ***!\n  \\*********************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.7 Reflect.getOwnPropertyDescriptor(target, propertyKey)\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\n\n$export($export.S, 'Reflect', {\n  getOwnPropertyDescriptor: function getOwnPropertyDescriptor(target, propertyKey) {\n    return gOPD.f(anObject(target), propertyKey);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.get-prototype-of.js\":\n/*!**********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.get-prototype-of.js ***!\n  \\**********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.8 Reflect.getPrototypeOf(target)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar getProto = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\n\n$export($export.S, 'Reflect', {\n  getPrototypeOf: function getPrototypeOf(target) {\n    return getProto(anObject(target));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.get.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.get.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.6 Reflect.get(target, propertyKey [, receiver])\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\n\nfunction get(target, propertyKey /* , receiver */) {\n  var receiver = arguments.length < 3 ? target : arguments[2];\n  var desc, proto;\n  if (anObject(target) === receiver) return target[propertyKey];\n  if (desc = gOPD.f(target, propertyKey)) return has(desc, 'value')\n    ? desc.value\n    : desc.get !== undefined\n      ? desc.get.call(receiver)\n      : undefined;\n  if (isObject(proto = getPrototypeOf(target))) return get(proto, propertyKey, receiver);\n}\n\n$export($export.S, 'Reflect', { get: get });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.has.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.has.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.9 Reflect.has(target, propertyKey)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Reflect', {\n  has: function has(target, propertyKey) {\n    return propertyKey in target;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.is-extensible.js\":\n/*!*******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.is-extensible.js ***!\n  \\*******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.10 Reflect.isExtensible(target)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar $isExtensible = Object.isExtensible;\n\n$export($export.S, 'Reflect', {\n  isExtensible: function isExtensible(target) {\n    anObject(target);\n    return $isExtensible ? $isExtensible(target) : true;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.own-keys.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.own-keys.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.11 Reflect.ownKeys(target)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Reflect', { ownKeys: __webpack_require__(/*! ./_own-keys */ \"./node_modules/core-js/modules/_own-keys.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.prevent-extensions.js\":\n/*!************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.prevent-extensions.js ***!\n  \\************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.12 Reflect.preventExtensions(target)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar $preventExtensions = Object.preventExtensions;\n\n$export($export.S, 'Reflect', {\n  preventExtensions: function preventExtensions(target) {\n    anObject(target);\n    try {\n      if ($preventExtensions) $preventExtensions(target);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.set-prototype-of.js\":\n/*!**********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.set-prototype-of.js ***!\n  \\**********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.14 Reflect.setPrototypeOf(target, proto)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar setProto = __webpack_require__(/*! ./_set-proto */ \"./node_modules/core-js/modules/_set-proto.js\");\n\nif (setProto) $export($export.S, 'Reflect', {\n  setPrototypeOf: function setPrototypeOf(target, proto) {\n    setProto.check(target, proto);\n    try {\n      setProto.set(target, proto);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.set.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.set.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.13 Reflect.set(target, propertyKey, V [, receiver])\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n\nfunction set(target, propertyKey, V /* , receiver */) {\n  var receiver = arguments.length < 4 ? target : arguments[3];\n  var ownDesc = gOPD.f(anObject(target), propertyKey);\n  var existingDescriptor, proto;\n  if (!ownDesc) {\n    if (isObject(proto = getPrototypeOf(target))) {\n      return set(proto, propertyKey, V, receiver);\n    }\n    ownDesc = createDesc(0);\n  }\n  if (has(ownDesc, 'value')) {\n    if (ownDesc.writable === false || !isObject(receiver)) return false;\n    if (existingDescriptor = gOPD.f(receiver, propertyKey)) {\n      if (existingDescriptor.get || existingDescriptor.set || existingDescriptor.writable === false) return false;\n      existingDescriptor.value = V;\n      dP.f(receiver, propertyKey, existingDescriptor);\n    } else dP.f(receiver, propertyKey, createDesc(0, V));\n    return true;\n  }\n  return ownDesc.set === undefined ? false : (ownDesc.set.call(receiver, V), true);\n}\n\n$export($export.S, 'Reflect', { set: set });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.constructor.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.constructor.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar inheritIfRequired = __webpack_require__(/*! ./_inherit-if-required */ \"./node_modules/core-js/modules/_inherit-if-required.js\");\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f;\nvar isRegExp = __webpack_require__(/*! ./_is-regexp */ \"./node_modules/core-js/modules/_is-regexp.js\");\nvar $flags = __webpack_require__(/*! ./_flags */ \"./node_modules/core-js/modules/_flags.js\");\nvar $RegExp = global.RegExp;\nvar Base = $RegExp;\nvar proto = $RegExp.prototype;\nvar re1 = /a/g;\nvar re2 = /a/g;\n// \"new\" creates a new object, old webkit buggy here\nvar CORRECT_NEW = new $RegExp(re1) !== re1;\n\nif (__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && (!CORRECT_NEW || __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  re2[__webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('match')] = false;\n  // RegExp constructor can alter flags and IsRegExp works correct with @@match\n  return $RegExp(re1) != re1 || $RegExp(re2) == re2 || $RegExp(re1, 'i') != '/a/i';\n}))) {\n  $RegExp = function RegExp(p, f) {\n    var tiRE = this instanceof $RegExp;\n    var piRE = isRegExp(p);\n    var fiU = f === undefined;\n    return !tiRE && piRE && p.constructor === $RegExp && fiU ? p\n      : inheritIfRequired(CORRECT_NEW\n        ? new Base(piRE && !fiU ? p.source : p, f)\n        : Base((piRE = p instanceof $RegExp) ? p.source : p, piRE && fiU ? $flags.call(p) : f)\n      , tiRE ? this : proto, $RegExp);\n  };\n  var proxy = function (key) {\n    key in $RegExp || dP($RegExp, key, {\n      configurable: true,\n      get: function () { return Base[key]; },\n      set: function (it) { Base[key] = it; }\n    });\n  };\n  for (var keys = gOPN(Base), i = 0; keys.length > i;) proxy(keys[i++]);\n  proto.constructor = $RegExp;\n  $RegExp.prototype = proto;\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(global, 'RegExp', $RegExp);\n}\n\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")('RegExp');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.exec.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.exec.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar regexpExec = __webpack_require__(/*! ./_regexp-exec */ \"./node_modules/core-js/modules/_regexp-exec.js\");\n__webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\")({\n  target: 'RegExp',\n  proto: true,\n  forced: regexpExec !== /./.exec\n}, {\n  exec: regexpExec\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.flags.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.flags.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 21.2.5.3 get RegExp.prototype.flags()\nif (__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && /./g.flags != 'g') __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f(RegExp.prototype, 'flags', {\n  configurable: true,\n  get: __webpack_require__(/*! ./_flags */ \"./node_modules/core-js/modules/_flags.js\")\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.match.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.match.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar advanceStringIndex = __webpack_require__(/*! ./_advance-string-index */ \"./node_modules/core-js/modules/_advance-string-index.js\");\nvar regExpExec = __webpack_require__(/*! ./_regexp-exec-abstract */ \"./node_modules/core-js/modules/_regexp-exec-abstract.js\");\n\n// @@match logic\n__webpack_require__(/*! ./_fix-re-wks */ \"./node_modules/core-js/modules/_fix-re-wks.js\")('match', 1, function (defined, MATCH, $match, maybeCallNative) {\n  return [\n    // `String.prototype.match` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.match\n    function match(regexp) {\n      var O = defined(this);\n      var fn = regexp == undefined ? undefined : regexp[MATCH];\n      return fn !== undefined ? fn.call(regexp, O) : new RegExp(regexp)[MATCH](String(O));\n    },\n    // `RegExp.prototype[@@match]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@match\n    function (regexp) {\n      var res = maybeCallNative($match, regexp, this);\n      if (res.done) return res.value;\n      var rx = anObject(regexp);\n      var S = String(this);\n      if (!rx.global) return regExpExec(rx, S);\n      var fullUnicode = rx.unicode;\n      rx.lastIndex = 0;\n      var A = [];\n      var n = 0;\n      var result;\n      while ((result = regExpExec(rx, S)) !== null) {\n        var matchStr = String(result[0]);\n        A[n] = matchStr;\n        if (matchStr === '') rx.lastIndex = advanceStringIndex(S, toLength(rx.lastIndex), fullUnicode);\n        n++;\n      }\n      return n === 0 ? null : A;\n    }\n  ];\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.replace.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.replace.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar advanceStringIndex = __webpack_require__(/*! ./_advance-string-index */ \"./node_modules/core-js/modules/_advance-string-index.js\");\nvar regExpExec = __webpack_require__(/*! ./_regexp-exec-abstract */ \"./node_modules/core-js/modules/_regexp-exec-abstract.js\");\nvar max = Math.max;\nvar min = Math.min;\nvar floor = Math.floor;\nvar SUBSTITUTION_SYMBOLS = /\\$([$&`']|\\d\\d?|<[^>]*>)/g;\nvar SUBSTITUTION_SYMBOLS_NO_NAMED = /\\$([$&`']|\\d\\d?)/g;\n\nvar maybeToString = function (it) {\n  return it === undefined ? it : String(it);\n};\n\n// @@replace logic\n__webpack_require__(/*! ./_fix-re-wks */ \"./node_modules/core-js/modules/_fix-re-wks.js\")('replace', 2, function (defined, REPLACE, $replace, maybeCallNative) {\n  return [\n    // `String.prototype.replace` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.replace\n    function replace(searchValue, replaceValue) {\n      var O = defined(this);\n      var fn = searchValue == undefined ? undefined : searchValue[REPLACE];\n      return fn !== undefined\n        ? fn.call(searchValue, O, replaceValue)\n        : $replace.call(String(O), searchValue, replaceValue);\n    },\n    // `RegExp.prototype[@@replace]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@replace\n    function (regexp, replaceValue) {\n      var res = maybeCallNative($replace, regexp, this, replaceValue);\n      if (res.done) return res.value;\n\n      var rx = anObject(regexp);\n      var S = String(this);\n      var functionalReplace = typeof replaceValue === 'function';\n      if (!functionalReplace) replaceValue = String(replaceValue);\n      var global = rx.global;\n      if (global) {\n        var fullUnicode = rx.unicode;\n        rx.lastIndex = 0;\n      }\n      var results = [];\n      while (true) {\n        var result = regExpExec(rx, S);\n        if (result === null) break;\n        results.push(result);\n        if (!global) break;\n        var matchStr = String(result[0]);\n        if (matchStr === '') rx.lastIndex = advanceStringIndex(S, toLength(rx.lastIndex), fullUnicode);\n      }\n      var accumulatedResult = '';\n      var nextSourcePosition = 0;\n      for (var i = 0; i < results.length; i++) {\n        result = results[i];\n        var matched = String(result[0]);\n        var position = max(min(toInteger(result.index), S.length), 0);\n        var captures = [];\n        // NOTE: This is equivalent to\n        //   captures = result.slice(1).map(maybeToString)\n        // but for some reason `nativeSlice.call(result, 1, result.length)` (called in\n        // the slice polyfill when slicing native arrays) \"doesn't work\" in safari 9 and\n        // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it.\n        for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j]));\n        var namedCaptures = result.groups;\n        if (functionalReplace) {\n          var replacerArgs = [matched].concat(captures, position, S);\n          if (namedCaptures !== undefined) replacerArgs.push(namedCaptures);\n          var replacement = String(replaceValue.apply(undefined, replacerArgs));\n        } else {\n          replacement = getSubstitution(matched, S, position, captures, namedCaptures, replaceValue);\n        }\n        if (position >= nextSourcePosition) {\n          accumulatedResult += S.slice(nextSourcePosition, position) + replacement;\n          nextSourcePosition = position + matched.length;\n        }\n      }\n      return accumulatedResult + S.slice(nextSourcePosition);\n    }\n  ];\n\n    // https://tc39.github.io/ecma262/#sec-getsubstitution\n  function getSubstitution(matched, str, position, captures, namedCaptures, replacement) {\n    var tailPos = position + matched.length;\n    var m = captures.length;\n    var symbols = SUBSTITUTION_SYMBOLS_NO_NAMED;\n    if (namedCaptures !== undefined) {\n      namedCaptures = toObject(namedCaptures);\n      symbols = SUBSTITUTION_SYMBOLS;\n    }\n    return $replace.call(replacement, symbols, function (match, ch) {\n      var capture;\n      switch (ch.charAt(0)) {\n        case '$': return '$';\n        case '&': return matched;\n        case '`': return str.slice(0, position);\n        case \"'\": return str.slice(tailPos);\n        case '<':\n          capture = namedCaptures[ch.slice(1, -1)];\n          break;\n        default: // \\d\\d?\n          var n = +ch;\n          if (n === 0) return match;\n          if (n > m) {\n            var f = floor(n / 10);\n            if (f === 0) return match;\n            if (f <= m) return captures[f - 1] === undefined ? ch.charAt(1) : captures[f - 1] + ch.charAt(1);\n            return match;\n          }\n          capture = captures[n - 1];\n      }\n      return capture === undefined ? '' : capture;\n    });\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.search.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.search.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar sameValue = __webpack_require__(/*! ./_same-value */ \"./node_modules/core-js/modules/_same-value.js\");\nvar regExpExec = __webpack_require__(/*! ./_regexp-exec-abstract */ \"./node_modules/core-js/modules/_regexp-exec-abstract.js\");\n\n// @@search logic\n__webpack_require__(/*! ./_fix-re-wks */ \"./node_modules/core-js/modules/_fix-re-wks.js\")('search', 1, function (defined, SEARCH, $search, maybeCallNative) {\n  return [\n    // `String.prototype.search` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.search\n    function search(regexp) {\n      var O = defined(this);\n      var fn = regexp == undefined ? undefined : regexp[SEARCH];\n      return fn !== undefined ? fn.call(regexp, O) : new RegExp(regexp)[SEARCH](String(O));\n    },\n    // `RegExp.prototype[@@search]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@search\n    function (regexp) {\n      var res = maybeCallNative($search, regexp, this);\n      if (res.done) return res.value;\n      var rx = anObject(regexp);\n      var S = String(this);\n      var previousLastIndex = rx.lastIndex;\n      if (!sameValue(previousLastIndex, 0)) rx.lastIndex = 0;\n      var result = regExpExec(rx, S);\n      if (!sameValue(rx.lastIndex, previousLastIndex)) rx.lastIndex = previousLastIndex;\n      return result === null ? -1 : result.index;\n    }\n  ];\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.split.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.split.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar isRegExp = __webpack_require__(/*! ./_is-regexp */ \"./node_modules/core-js/modules/_is-regexp.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\nvar advanceStringIndex = __webpack_require__(/*! ./_advance-string-index */ \"./node_modules/core-js/modules/_advance-string-index.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar callRegExpExec = __webpack_require__(/*! ./_regexp-exec-abstract */ \"./node_modules/core-js/modules/_regexp-exec-abstract.js\");\nvar regexpExec = __webpack_require__(/*! ./_regexp-exec */ \"./node_modules/core-js/modules/_regexp-exec.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar $min = Math.min;\nvar $push = [].push;\nvar $SPLIT = 'split';\nvar LENGTH = 'length';\nvar LAST_INDEX = 'lastIndex';\nvar MAX_UINT32 = 0xffffffff;\n\n// babel-minify transpiles RegExp('x', 'y') -> /x/y and it causes SyntaxError\nvar SUPPORTS_Y = !fails(function () { RegExp(MAX_UINT32, 'y'); });\n\n// @@split logic\n__webpack_require__(/*! ./_fix-re-wks */ \"./node_modules/core-js/modules/_fix-re-wks.js\")('split', 2, function (defined, SPLIT, $split, maybeCallNative) {\n  var internalSplit;\n  if (\n    'abbc'[$SPLIT](/(b)*/)[1] == 'c' ||\n    'test'[$SPLIT](/(?:)/, -1)[LENGTH] != 4 ||\n    'ab'[$SPLIT](/(?:ab)*/)[LENGTH] != 2 ||\n    '.'[$SPLIT](/(.?)(.?)/)[LENGTH] != 4 ||\n    '.'[$SPLIT](/()()/)[LENGTH] > 1 ||\n    ''[$SPLIT](/.?/)[LENGTH]\n  ) {\n    // based on es5-shim implementation, need to rework it\n    internalSplit = function (separator, limit) {\n      var string = String(this);\n      if (separator === undefined && limit === 0) return [];\n      // If `separator` is not a regex, use native split\n      if (!isRegExp(separator)) return $split.call(string, separator, limit);\n      var output = [];\n      var flags = (separator.ignoreCase ? 'i' : '') +\n                  (separator.multiline ? 'm' : '') +\n                  (separator.unicode ? 'u' : '') +\n                  (separator.sticky ? 'y' : '');\n      var lastLastIndex = 0;\n      var splitLimit = limit === undefined ? MAX_UINT32 : limit >>> 0;\n      // Make `global` and avoid `lastIndex` issues by working with a copy\n      var separatorCopy = new RegExp(separator.source, flags + 'g');\n      var match, lastIndex, lastLength;\n      while (match = regexpExec.call(separatorCopy, string)) {\n        lastIndex = separatorCopy[LAST_INDEX];\n        if (lastIndex > lastLastIndex) {\n          output.push(string.slice(lastLastIndex, match.index));\n          if (match[LENGTH] > 1 && match.index < string[LENGTH]) $push.apply(output, match.slice(1));\n          lastLength = match[0][LENGTH];\n          lastLastIndex = lastIndex;\n          if (output[LENGTH] >= splitLimit) break;\n        }\n        if (separatorCopy[LAST_INDEX] === match.index) separatorCopy[LAST_INDEX]++; // Avoid an infinite loop\n      }\n      if (lastLastIndex === string[LENGTH]) {\n        if (lastLength || !separatorCopy.test('')) output.push('');\n      } else output.push(string.slice(lastLastIndex));\n      return output[LENGTH] > splitLimit ? output.slice(0, splitLimit) : output;\n    };\n  // Chakra, V8\n  } else if ('0'[$SPLIT](undefined, 0)[LENGTH]) {\n    internalSplit = function (separator, limit) {\n      return separator === undefined && limit === 0 ? [] : $split.call(this, separator, limit);\n    };\n  } else {\n    internalSplit = $split;\n  }\n\n  return [\n    // `String.prototype.split` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.split\n    function split(separator, limit) {\n      var O = defined(this);\n      var splitter = separator == undefined ? undefined : separator[SPLIT];\n      return splitter !== undefined\n        ? splitter.call(separator, O, limit)\n        : internalSplit.call(String(O), separator, limit);\n    },\n    // `RegExp.prototype[@@split]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@split\n    //\n    // NOTE: This cannot be properly polyfilled in engines that don't support\n    // the 'y' flag.\n    function (regexp, limit) {\n      var res = maybeCallNative(internalSplit, regexp, this, limit, internalSplit !== $split);\n      if (res.done) return res.value;\n\n      var rx = anObject(regexp);\n      var S = String(this);\n      var C = speciesConstructor(rx, RegExp);\n\n      var unicodeMatching = rx.unicode;\n      var flags = (rx.ignoreCase ? 'i' : '') +\n                  (rx.multiline ? 'm' : '') +\n                  (rx.unicode ? 'u' : '') +\n                  (SUPPORTS_Y ? 'y' : 'g');\n\n      // ^(? + rx + ) is needed, in combination with some S slicing, to\n      // simulate the 'y' flag.\n      var splitter = new C(SUPPORTS_Y ? rx : '^(?:' + rx.source + ')', flags);\n      var lim = limit === undefined ? MAX_UINT32 : limit >>> 0;\n      if (lim === 0) return [];\n      if (S.length === 0) return callRegExpExec(splitter, S) === null ? [S] : [];\n      var p = 0;\n      var q = 0;\n      var A = [];\n      while (q < S.length) {\n        splitter.lastIndex = SUPPORTS_Y ? q : 0;\n        var z = callRegExpExec(splitter, SUPPORTS_Y ? S : S.slice(q));\n        var e;\n        if (\n          z === null ||\n          (e = $min(toLength(splitter.lastIndex + (SUPPORTS_Y ? 0 : q)), S.length)) === p\n        ) {\n          q = advanceStringIndex(S, q, unicodeMatching);\n        } else {\n          A.push(S.slice(p, q));\n          if (A.length === lim) return A;\n          for (var i = 1; i <= z.length - 1; i++) {\n            A.push(z[i]);\n            if (A.length === lim) return A;\n          }\n          q = p = e;\n        }\n      }\n      A.push(S.slice(p));\n      return A;\n    }\n  ];\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.to-string.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.to-string.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n__webpack_require__(/*! ./es6.regexp.flags */ \"./node_modules/core-js/modules/es6.regexp.flags.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar $flags = __webpack_require__(/*! ./_flags */ \"./node_modules/core-js/modules/_flags.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar TO_STRING = 'toString';\nvar $toString = /./[TO_STRING];\n\nvar define = function (fn) {\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(RegExp.prototype, TO_STRING, fn, true);\n};\n\n// 21.2.5.14 RegExp.prototype.toString()\nif (__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () { return $toString.call({ source: 'a', flags: 'b' }) != '/a/b'; })) {\n  define(function toString() {\n    var R = anObject(this);\n    return '/'.concat(R.source, '/',\n      'flags' in R ? R.flags : !DESCRIPTORS && R instanceof RegExp ? $flags.call(R) : undefined);\n  });\n// FF44- RegExp#toString has a wrong name\n} else if ($toString.name != TO_STRING) {\n  define(function toString() {\n    return $toString.call(this);\n  });\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.set.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.set.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar strong = __webpack_require__(/*! ./_collection-strong */ \"./node_modules/core-js/modules/_collection-strong.js\");\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar SET = 'Set';\n\n// 23.2 Set Objects\nmodule.exports = __webpack_require__(/*! ./_collection */ \"./node_modules/core-js/modules/_collection.js\")(SET, function (get) {\n  return function Set() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.2.3.1 Set.prototype.add(value)\n  add: function add(value) {\n    return strong.def(validate(this, SET), value = value === 0 ? 0 : value, value);\n  }\n}, strong);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.anchor.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.anchor.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.2 String.prototype.anchor(name)\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('anchor', function (createHTML) {\n  return function anchor(name) {\n    return createHTML(this, 'a', 'name', name);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.big.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.big.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.3 String.prototype.big()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('big', function (createHTML) {\n  return function big() {\n    return createHTML(this, 'big', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.blink.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.blink.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.4 String.prototype.blink()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('blink', function (createHTML) {\n  return function blink() {\n    return createHTML(this, 'blink', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.bold.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.bold.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.5 String.prototype.bold()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('bold', function (createHTML) {\n  return function bold() {\n    return createHTML(this, 'b', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.code-point-at.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.code-point-at.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $at = __webpack_require__(/*! ./_string-at */ \"./node_modules/core-js/modules/_string-at.js\")(false);\n$export($export.P, 'String', {\n  // 21.1.3.3 String.prototype.codePointAt(pos)\n  codePointAt: function codePointAt(pos) {\n    return $at(this, pos);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.ends-with.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.ends-with.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// 21.1.3.6 String.prototype.endsWith(searchString [, endPosition])\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar context = __webpack_require__(/*! ./_string-context */ \"./node_modules/core-js/modules/_string-context.js\");\nvar ENDS_WITH = 'endsWith';\nvar $endsWith = ''[ENDS_WITH];\n\n$export($export.P + $export.F * __webpack_require__(/*! ./_fails-is-regexp */ \"./node_modules/core-js/modules/_fails-is-regexp.js\")(ENDS_WITH), 'String', {\n  endsWith: function endsWith(searchString /* , endPosition = @length */) {\n    var that = context(this, searchString, ENDS_WITH);\n    var endPosition = arguments.length > 1 ? arguments[1] : undefined;\n    var len = toLength(that.length);\n    var end = endPosition === undefined ? len : Math.min(toLength(endPosition), len);\n    var search = String(searchString);\n    return $endsWith\n      ? $endsWith.call(that, search, end)\n      : that.slice(end - search.length, end) === search;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.fixed.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.fixed.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.6 String.prototype.fixed()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('fixed', function (createHTML) {\n  return function fixed() {\n    return createHTML(this, 'tt', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.fontcolor.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.fontcolor.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.7 String.prototype.fontcolor(color)\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('fontcolor', function (createHTML) {\n  return function fontcolor(color) {\n    return createHTML(this, 'font', 'color', color);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.fontsize.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.fontsize.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.8 String.prototype.fontsize(size)\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('fontsize', function (createHTML) {\n  return function fontsize(size) {\n    return createHTML(this, 'font', 'size', size);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.from-code-point.js\":\n/*!********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.from-code-point.js ***!\n  \\********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nvar fromCharCode = String.fromCharCode;\nvar $fromCodePoint = String.fromCodePoint;\n\n// length should be 1, old FF problem\n$export($export.S + $export.F * (!!$fromCodePoint && $fromCodePoint.length != 1), 'String', {\n  // 21.1.2.2 String.fromCodePoint(...codePoints)\n  fromCodePoint: function fromCodePoint(x) { // eslint-disable-line no-unused-vars\n    var res = [];\n    var aLen = arguments.length;\n    var i = 0;\n    var code;\n    while (aLen > i) {\n      code = +arguments[i++];\n      if (toAbsoluteIndex(code, 0x10ffff) !== code) throw RangeError(code + ' is not a valid code point');\n      res.push(code < 0x10000\n        ? fromCharCode(code)\n        : fromCharCode(((code -= 0x10000) >> 10) + 0xd800, code % 0x400 + 0xdc00)\n      );\n    } return res.join('');\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.includes.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.includes.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// 21.1.3.7 String.prototype.includes(searchString, position = 0)\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar context = __webpack_require__(/*! ./_string-context */ \"./node_modules/core-js/modules/_string-context.js\");\nvar INCLUDES = 'includes';\n\n$export($export.P + $export.F * __webpack_require__(/*! ./_fails-is-regexp */ \"./node_modules/core-js/modules/_fails-is-regexp.js\")(INCLUDES), 'String', {\n  includes: function includes(searchString /* , position = 0 */) {\n    return !!~context(this, searchString, INCLUDES)\n      .indexOf(searchString, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.italics.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.italics.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.9 String.prototype.italics()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('italics', function (createHTML) {\n  return function italics() {\n    return createHTML(this, 'i', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.iterator.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.iterator.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $at = __webpack_require__(/*! ./_string-at */ \"./node_modules/core-js/modules/_string-at.js\")(true);\n\n// 21.1.3.27 String.prototype[@@iterator]()\n__webpack_require__(/*! ./_iter-define */ \"./node_modules/core-js/modules/_iter-define.js\")(String, 'String', function (iterated) {\n  this._t = String(iterated); // target\n  this._i = 0;                // next index\n// 21.1.5.2.1 %StringIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var index = this._i;\n  var point;\n  if (index >= O.length) return { value: undefined, done: true };\n  point = $at(O, index);\n  this._i += point.length;\n  return { value: point, done: false };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.link.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.link.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.10 String.prototype.link(url)\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('link', function (createHTML) {\n  return function link(url) {\n    return createHTML(this, 'a', 'href', url);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.raw.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.raw.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\n\n$export($export.S, 'String', {\n  // 21.1.2.4 String.raw(callSite, ...substitutions)\n  raw: function raw(callSite) {\n    var tpl = toIObject(callSite.raw);\n    var len = toLength(tpl.length);\n    var aLen = arguments.length;\n    var res = [];\n    var i = 0;\n    while (len > i) {\n      res.push(String(tpl[i++]));\n      if (i < aLen) res.push(String(arguments[i]));\n    } return res.join('');\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.repeat.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.repeat.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P, 'String', {\n  // 21.1.3.13 String.prototype.repeat(count)\n  repeat: __webpack_require__(/*! ./_string-repeat */ \"./node_modules/core-js/modules/_string-repeat.js\")\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.small.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.small.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.11 String.prototype.small()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('small', function (createHTML) {\n  return function small() {\n    return createHTML(this, 'small', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.starts-with.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.starts-with.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// 21.1.3.18 String.prototype.startsWith(searchString [, position ])\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar context = __webpack_require__(/*! ./_string-context */ \"./node_modules/core-js/modules/_string-context.js\");\nvar STARTS_WITH = 'startsWith';\nvar $startsWith = ''[STARTS_WITH];\n\n$export($export.P + $export.F * __webpack_require__(/*! ./_fails-is-regexp */ \"./node_modules/core-js/modules/_fails-is-regexp.js\")(STARTS_WITH), 'String', {\n  startsWith: function startsWith(searchString /* , position = 0 */) {\n    var that = context(this, searchString, STARTS_WITH);\n    var index = toLength(Math.min(arguments.length > 1 ? arguments[1] : undefined, that.length));\n    var search = String(searchString);\n    return $startsWith\n      ? $startsWith.call(that, search, index)\n      : that.slice(index, index + search.length) === search;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.strike.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.strike.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.12 String.prototype.strike()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('strike', function (createHTML) {\n  return function strike() {\n    return createHTML(this, 'strike', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.sub.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.sub.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.13 String.prototype.sub()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('sub', function (createHTML) {\n  return function sub() {\n    return createHTML(this, 'sub', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.sup.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.sup.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.14 String.prototype.sup()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('sup', function (createHTML) {\n  return function sup() {\n    return createHTML(this, 'sup', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.trim.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.trim.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 21.1.3.25 String.prototype.trim()\n__webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\")('trim', function ($trim) {\n  return function trim() {\n    return $trim(this, 3);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.symbol.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.symbol.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// ECMAScript 6 symbols shim\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar META = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").KEY;\nvar $fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar shared = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nvar wks = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\nvar wksExt = __webpack_require__(/*! ./_wks-ext */ \"./node_modules/core-js/modules/_wks-ext.js\");\nvar wksDefine = __webpack_require__(/*! ./_wks-define */ \"./node_modules/core-js/modules/_wks-define.js\");\nvar enumKeys = __webpack_require__(/*! ./_enum-keys */ \"./node_modules/core-js/modules/_enum-keys.js\");\nvar isArray = __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nvar _create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\nvar gOPNExt = __webpack_require__(/*! ./_object-gopn-ext */ \"./node_modules/core-js/modules/_object-gopn-ext.js\");\nvar $GOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\nvar $DP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar $keys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar gOPD = $GOPD.f;\nvar dP = $DP.f;\nvar gOPN = gOPNExt.f;\nvar $Symbol = global.Symbol;\nvar $JSON = global.JSON;\nvar _stringify = $JSON && $JSON.stringify;\nvar PROTOTYPE = 'prototype';\nvar HIDDEN = wks('_hidden');\nvar TO_PRIMITIVE = wks('toPrimitive');\nvar isEnum = {}.propertyIsEnumerable;\nvar SymbolRegistry = shared('symbol-registry');\nvar AllSymbols = shared('symbols');\nvar OPSymbols = shared('op-symbols');\nvar ObjectProto = Object[PROTOTYPE];\nvar USE_NATIVE = typeof $Symbol == 'function';\nvar QObject = global.QObject;\n// Don't use setters in Qt Script, https://github.com/zloirock/core-js/issues/173\nvar setter = !QObject || !QObject[PROTOTYPE] || !QObject[PROTOTYPE].findChild;\n\n// fallback for old Android, https://code.google.com/p/v8/issues/detail?id=687\nvar setSymbolDesc = DESCRIPTORS && $fails(function () {\n  return _create(dP({}, 'a', {\n    get: function () { return dP(this, 'a', { value: 7 }).a; }\n  })).a != 7;\n}) ? function (it, key, D) {\n  var protoDesc = gOPD(ObjectProto, key);\n  if (protoDesc) delete ObjectProto[key];\n  dP(it, key, D);\n  if (protoDesc && it !== ObjectProto) dP(ObjectProto, key, protoDesc);\n} : dP;\n\nvar wrap = function (tag) {\n  var sym = AllSymbols[tag] = _create($Symbol[PROTOTYPE]);\n  sym._k = tag;\n  return sym;\n};\n\nvar isSymbol = USE_NATIVE && typeof $Symbol.iterator == 'symbol' ? function (it) {\n  return typeof it == 'symbol';\n} : function (it) {\n  return it instanceof $Symbol;\n};\n\nvar $defineProperty = function defineProperty(it, key, D) {\n  if (it === ObjectProto) $defineProperty(OPSymbols, key, D);\n  anObject(it);\n  key = toPrimitive(key, true);\n  anObject(D);\n  if (has(AllSymbols, key)) {\n    if (!D.enumerable) {\n      if (!has(it, HIDDEN)) dP(it, HIDDEN, createDesc(1, {}));\n      it[HIDDEN][key] = true;\n    } else {\n      if (has(it, HIDDEN) && it[HIDDEN][key]) it[HIDDEN][key] = false;\n      D = _create(D, { enumerable: createDesc(0, false) });\n    } return setSymbolDesc(it, key, D);\n  } return dP(it, key, D);\n};\nvar $defineProperties = function defineProperties(it, P) {\n  anObject(it);\n  var keys = enumKeys(P = toIObject(P));\n  var i = 0;\n  var l = keys.length;\n  var key;\n  while (l > i) $defineProperty(it, key = keys[i++], P[key]);\n  return it;\n};\nvar $create = function create(it, P) {\n  return P === undefined ? _create(it) : $defineProperties(_create(it), P);\n};\nvar $propertyIsEnumerable = function propertyIsEnumerable(key) {\n  var E = isEnum.call(this, key = toPrimitive(key, true));\n  if (this === ObjectProto && has(AllSymbols, key) && !has(OPSymbols, key)) return false;\n  return E || !has(this, key) || !has(AllSymbols, key) || has(this, HIDDEN) && this[HIDDEN][key] ? E : true;\n};\nvar $getOwnPropertyDescriptor = function getOwnPropertyDescriptor(it, key) {\n  it = toIObject(it);\n  key = toPrimitive(key, true);\n  if (it === ObjectProto && has(AllSymbols, key) && !has(OPSymbols, key)) return;\n  var D = gOPD(it, key);\n  if (D && has(AllSymbols, key) && !(has(it, HIDDEN) && it[HIDDEN][key])) D.enumerable = true;\n  return D;\n};\nvar $getOwnPropertyNames = function getOwnPropertyNames(it) {\n  var names = gOPN(toIObject(it));\n  var result = [];\n  var i = 0;\n  var key;\n  while (names.length > i) {\n    if (!has(AllSymbols, key = names[i++]) && key != HIDDEN && key != META) result.push(key);\n  } return result;\n};\nvar $getOwnPropertySymbols = function getOwnPropertySymbols(it) {\n  var IS_OP = it === ObjectProto;\n  var names = gOPN(IS_OP ? OPSymbols : toIObject(it));\n  var result = [];\n  var i = 0;\n  var key;\n  while (names.length > i) {\n    if (has(AllSymbols, key = names[i++]) && (IS_OP ? has(ObjectProto, key) : true)) result.push(AllSymbols[key]);\n  } return result;\n};\n\n// 19.4.1.1 Symbol([description])\nif (!USE_NATIVE) {\n  $Symbol = function Symbol() {\n    if (this instanceof $Symbol) throw TypeError('Symbol is not a constructor!');\n    var tag = uid(arguments.length > 0 ? arguments[0] : undefined);\n    var $set = function (value) {\n      if (this === ObjectProto) $set.call(OPSymbols, value);\n      if (has(this, HIDDEN) && has(this[HIDDEN], tag)) this[HIDDEN][tag] = false;\n      setSymbolDesc(this, tag, createDesc(1, value));\n    };\n    if (DESCRIPTORS && setter) setSymbolDesc(ObjectProto, tag, { configurable: true, set: $set });\n    return wrap(tag);\n  };\n  redefine($Symbol[PROTOTYPE], 'toString', function toString() {\n    return this._k;\n  });\n\n  $GOPD.f = $getOwnPropertyDescriptor;\n  $DP.f = $defineProperty;\n  __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f = gOPNExt.f = $getOwnPropertyNames;\n  __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\").f = $propertyIsEnumerable;\n  __webpack_require__(/*! ./_object-gops */ \"./node_modules/core-js/modules/_object-gops.js\").f = $getOwnPropertySymbols;\n\n  if (DESCRIPTORS && !__webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\")) {\n    redefine(ObjectProto, 'propertyIsEnumerable', $propertyIsEnumerable, true);\n  }\n\n  wksExt.f = function (name) {\n    return wrap(wks(name));\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Symbol: $Symbol });\n\nfor (var es6Symbols = (\n  // 19.4.2.2, 19.4.2.3, 19.4.2.4, 19.4.2.6, 19.4.2.8, 19.4.2.9, 19.4.2.10, 19.4.2.11, 19.4.2.12, 19.4.2.13, 19.4.2.14\n  'hasInstance,isConcatSpreadable,iterator,match,replace,search,species,split,toPrimitive,toStringTag,unscopables'\n).split(','), j = 0; es6Symbols.length > j;)wks(es6Symbols[j++]);\n\nfor (var wellKnownSymbols = $keys(wks.store), k = 0; wellKnownSymbols.length > k;) wksDefine(wellKnownSymbols[k++]);\n\n$export($export.S + $export.F * !USE_NATIVE, 'Symbol', {\n  // 19.4.2.1 Symbol.for(key)\n  'for': function (key) {\n    return has(SymbolRegistry, key += '')\n      ? SymbolRegistry[key]\n      : SymbolRegistry[key] = $Symbol(key);\n  },\n  // 19.4.2.5 Symbol.keyFor(sym)\n  keyFor: function keyFor(sym) {\n    if (!isSymbol(sym)) throw TypeError(sym + ' is not a symbol!');\n    for (var key in SymbolRegistry) if (SymbolRegistry[key] === sym) return key;\n  },\n  useSetter: function () { setter = true; },\n  useSimple: function () { setter = false; }\n});\n\n$export($export.S + $export.F * !USE_NATIVE, 'Object', {\n  // 19.1.2.2 Object.create(O [, Properties])\n  create: $create,\n  // 19.1.2.4 Object.defineProperty(O, P, Attributes)\n  defineProperty: $defineProperty,\n  // 19.1.2.3 Object.defineProperties(O, Properties)\n  defineProperties: $defineProperties,\n  // 19.1.2.6 Object.getOwnPropertyDescriptor(O, P)\n  getOwnPropertyDescriptor: $getOwnPropertyDescriptor,\n  // 19.1.2.7 Object.getOwnPropertyNames(O)\n  getOwnPropertyNames: $getOwnPropertyNames,\n  // 19.1.2.8 Object.getOwnPropertySymbols(O)\n  getOwnPropertySymbols: $getOwnPropertySymbols\n});\n\n// 24.3.2 JSON.stringify(value [, replacer [, space]])\n$JSON && $export($export.S + $export.F * (!USE_NATIVE || $fails(function () {\n  var S = $Symbol();\n  // MS Edge converts symbol values to JSON as {}\n  // WebKit converts symbol values to JSON as null\n  // V8 throws on boxed symbols\n  return _stringify([S]) != '[null]' || _stringify({ a: S }) != '{}' || _stringify(Object(S)) != '{}';\n})), 'JSON', {\n  stringify: function stringify(it) {\n    var args = [it];\n    var i = 1;\n    var replacer, $replacer;\n    while (arguments.length > i) args.push(arguments[i++]);\n    $replacer = replacer = args[1];\n    if (!isObject(replacer) && it === undefined || isSymbol(it)) return; // IE8 returns string on undefined\n    if (!isArray(replacer)) replacer = function (key, value) {\n      if (typeof $replacer == 'function') value = $replacer.call(this, key, value);\n      if (!isSymbol(value)) return value;\n    };\n    args[1] = replacer;\n    return _stringify.apply($JSON, args);\n  }\n});\n\n// 19.4.3.4 Symbol.prototype[@@toPrimitive](hint)\n$Symbol[PROTOTYPE][TO_PRIMITIVE] || __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")($Symbol[PROTOTYPE], TO_PRIMITIVE, $Symbol[PROTOTYPE].valueOf);\n// 19.4.3.5 Symbol.prototype[@@toStringTag]\nsetToStringTag($Symbol, 'Symbol');\n// 20.2.1.9 Math[@@toStringTag]\nsetToStringTag(Math, 'Math', true);\n// 24.3.3 JSON[@@toStringTag]\nsetToStringTag(global.JSON, 'JSON', true);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.array-buffer.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.array-buffer.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $typed = __webpack_require__(/*! ./_typed */ \"./node_modules/core-js/modules/_typed.js\");\nvar buffer = __webpack_require__(/*! ./_typed-buffer */ \"./node_modules/core-js/modules/_typed-buffer.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar ArrayBuffer = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").ArrayBuffer;\nvar speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\nvar $ArrayBuffer = buffer.ArrayBuffer;\nvar $DataView = buffer.DataView;\nvar $isView = $typed.ABV && ArrayBuffer.isView;\nvar $slice = $ArrayBuffer.prototype.slice;\nvar VIEW = $typed.VIEW;\nvar ARRAY_BUFFER = 'ArrayBuffer';\n\n$export($export.G + $export.W + $export.F * (ArrayBuffer !== $ArrayBuffer), { ArrayBuffer: $ArrayBuffer });\n\n$export($export.S + $export.F * !$typed.CONSTR, ARRAY_BUFFER, {\n  // 24.1.3.1 ArrayBuffer.isView(arg)\n  isView: function isView(it) {\n    return $isView && $isView(it) || isObject(it) && VIEW in it;\n  }\n});\n\n$export($export.P + $export.U + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return !new $ArrayBuffer(2).slice(1, undefined).byteLength;\n}), ARRAY_BUFFER, {\n  // 24.1.4.3 ArrayBuffer.prototype.slice(start, end)\n  slice: function slice(start, end) {\n    if ($slice !== undefined && end === undefined) return $slice.call(anObject(this), start); // FF fix\n    var len = anObject(this).byteLength;\n    var first = toAbsoluteIndex(start, len);\n    var fin = toAbsoluteIndex(end === undefined ? len : end, len);\n    var result = new (speciesConstructor(this, $ArrayBuffer))(toLength(fin - first));\n    var viewS = new $DataView(this);\n    var viewT = new $DataView(result);\n    var index = 0;\n    while (first < fin) {\n      viewT.setUint8(index++, viewS.getUint8(first++));\n    } return result;\n  }\n});\n\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")(ARRAY_BUFFER);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.data-view.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.data-view.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n$export($export.G + $export.W + $export.F * !__webpack_require__(/*! ./_typed */ \"./node_modules/core-js/modules/_typed.js\").ABV, {\n  DataView: __webpack_require__(/*! ./_typed-buffer */ \"./node_modules/core-js/modules/_typed-buffer.js\").DataView\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.float32-array.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.float32-array.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Float32', 4, function (init) {\n  return function Float32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.float64-array.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.float64-array.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Float64', 8, function (init) {\n  return function Float64Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.int16-array.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.int16-array.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Int16', 2, function (init) {\n  return function Int16Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.int32-array.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.int32-array.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Int32', 4, function (init) {\n  return function Int32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.int8-array.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.int8-array.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Int8', 1, function (init) {\n  return function Int8Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.uint16-array.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.uint16-array.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Uint16', 2, function (init) {\n  return function Uint16Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.uint32-array.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.uint32-array.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Uint32', 4, function (init) {\n  return function Uint32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.uint8-array.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.uint8-array.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Uint8', 1, function (init) {\n  return function Uint8Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.uint8-clamped-array.js\":\n/*!***********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.uint8-clamped-array.js ***!\n  \\***********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Uint8', 1, function (init) {\n  return function Uint8ClampedArray(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n}, true);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.weak-map.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.weak-map.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar each = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(0);\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar meta = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\");\nvar assign = __webpack_require__(/*! ./_object-assign */ \"./node_modules/core-js/modules/_object-assign.js\");\nvar weak = __webpack_require__(/*! ./_collection-weak */ \"./node_modules/core-js/modules/_collection-weak.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar NATIVE_WEAK_MAP = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar IS_IE11 = !global.ActiveXObject && 'ActiveXObject' in global;\nvar WEAK_MAP = 'WeakMap';\nvar getWeak = meta.getWeak;\nvar isExtensible = Object.isExtensible;\nvar uncaughtFrozenStore = weak.ufstore;\nvar InternalMap;\n\nvar wrapper = function (get) {\n  return function WeakMap() {\n    return get(this, arguments.length > 0 ? arguments[0] : undefined);\n  };\n};\n\nvar methods = {\n  // 23.3.3.3 WeakMap.prototype.get(key)\n  get: function get(key) {\n    if (isObject(key)) {\n      var data = getWeak(key);\n      if (data === true) return uncaughtFrozenStore(validate(this, WEAK_MAP)).get(key);\n      return data ? data[this._i] : undefined;\n    }\n  },\n  // 23.3.3.5 WeakMap.prototype.set(key, value)\n  set: function set(key, value) {\n    return weak.def(validate(this, WEAK_MAP), key, value);\n  }\n};\n\n// 23.3 WeakMap Objects\nvar $WeakMap = module.exports = __webpack_require__(/*! ./_collection */ \"./node_modules/core-js/modules/_collection.js\")(WEAK_MAP, wrapper, methods, weak, true, true);\n\n// IE11 WeakMap frozen keys fix\nif (NATIVE_WEAK_MAP && IS_IE11) {\n  InternalMap = weak.getConstructor(wrapper, WEAK_MAP);\n  assign(InternalMap.prototype, methods);\n  meta.NEED = true;\n  each(['delete', 'has', 'get', 'set'], function (key) {\n    var proto = $WeakMap.prototype;\n    var method = proto[key];\n    redefine(proto, key, function (a, b) {\n      // store frozen objects on internal weakmap shim\n      if (isObject(a) && !isExtensible(a)) {\n        if (!this._f) this._f = new InternalMap();\n        var result = this._f[key](a, b);\n        return key == 'set' ? this : result;\n      // store all the rest on native weakmap\n      } return method.call(this, a, b);\n    });\n  });\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.weak-set.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.weak-set.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar weak = __webpack_require__(/*! ./_collection-weak */ \"./node_modules/core-js/modules/_collection-weak.js\");\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar WEAK_SET = 'WeakSet';\n\n// 23.4 WeakSet Objects\n__webpack_require__(/*! ./_collection */ \"./node_modules/core-js/modules/_collection.js\")(WEAK_SET, function (get) {\n  return function WeakSet() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.4.3.1 WeakSet.prototype.add(value)\n  add: function add(value) {\n    return weak.def(validate(this, WEAK_SET), value, true);\n  }\n}, weak, false, true);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.array.flat-map.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.array.flat-map.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/proposal-flatMap/#sec-Array.prototype.flatMap\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar flattenIntoArray = __webpack_require__(/*! ./_flatten-into-array */ \"./node_modules/core-js/modules/_flatten-into-array.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar arraySpeciesCreate = __webpack_require__(/*! ./_array-species-create */ \"./node_modules/core-js/modules/_array-species-create.js\");\n\n$export($export.P, 'Array', {\n  flatMap: function flatMap(callbackfn /* , thisArg */) {\n    var O = toObject(this);\n    var sourceLen, A;\n    aFunction(callbackfn);\n    sourceLen = toLength(O.length);\n    A = arraySpeciesCreate(O, 0);\n    flattenIntoArray(A, O, O, sourceLen, 0, 1, callbackfn, arguments[1]);\n    return A;\n  }\n});\n\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")('flatMap');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.array.flatten.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.array.flatten.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/proposal-flatMap/#sec-Array.prototype.flatten\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar flattenIntoArray = __webpack_require__(/*! ./_flatten-into-array */ \"./node_modules/core-js/modules/_flatten-into-array.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar arraySpeciesCreate = __webpack_require__(/*! ./_array-species-create */ \"./node_modules/core-js/modules/_array-species-create.js\");\n\n$export($export.P, 'Array', {\n  flatten: function flatten(/* depthArg = 1 */) {\n    var depthArg = arguments[0];\n    var O = toObject(this);\n    var sourceLen = toLength(O.length);\n    var A = arraySpeciesCreate(O, 0);\n    flattenIntoArray(A, O, O, sourceLen, 0, depthArg === undefined ? 1 : toInteger(depthArg));\n    return A;\n  }\n});\n\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")('flatten');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.array.includes.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.array.includes.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/tc39/Array.prototype.includes\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $includes = __webpack_require__(/*! ./_array-includes */ \"./node_modules/core-js/modules/_array-includes.js\")(true);\n\n$export($export.P, 'Array', {\n  includes: function includes(el /* , fromIndex = 0 */) {\n    return $includes(this, el, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")('includes');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.asap.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.asap.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/rwaldron/tc39-notes/blob/master/es6/2014-09/sept-25.md#510-globalasap-for-enqueuing-a-microtask\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar microtask = __webpack_require__(/*! ./_microtask */ \"./node_modules/core-js/modules/_microtask.js\")();\nvar process = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").process;\nvar isNode = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\")(process) == 'process';\n\n$export($export.G, {\n  asap: function asap(fn) {\n    var domain = isNode && process.domain;\n    microtask(domain ? domain.bind(fn) : fn);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.error.is-error.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.error.is-error.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/ljharb/proposal-is-error\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\n\n$export($export.S, 'Error', {\n  isError: function isError(it) {\n    return cof(it) === 'Error';\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.global.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.global.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-global\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.G, { global: __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.map.from.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.map.from.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-map.from\n__webpack_require__(/*! ./_set-collection-from */ \"./node_modules/core-js/modules/_set-collection-from.js\")('Map');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.map.of.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.map.of.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-map.of\n__webpack_require__(/*! ./_set-collection-of */ \"./node_modules/core-js/modules/_set-collection-of.js\")('Map');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.map.to-json.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.map.to-json.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P + $export.R, 'Map', { toJSON: __webpack_require__(/*! ./_collection-to-json */ \"./node_modules/core-js/modules/_collection-to-json.js\")('Map') });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.clamp.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.clamp.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  clamp: function clamp(x, lower, upper) {\n    return Math.min(upper, Math.max(lower, x));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.deg-per-rad.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.deg-per-rad.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { DEG_PER_RAD: Math.PI / 180 });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.degrees.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.degrees.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar RAD_PER_DEG = 180 / Math.PI;\n\n$export($export.S, 'Math', {\n  degrees: function degrees(radians) {\n    return radians * RAD_PER_DEG;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.fscale.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.fscale.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar scale = __webpack_require__(/*! ./_math-scale */ \"./node_modules/core-js/modules/_math-scale.js\");\nvar fround = __webpack_require__(/*! ./_math-fround */ \"./node_modules/core-js/modules/_math-fround.js\");\n\n$export($export.S, 'Math', {\n  fscale: function fscale(x, inLow, inHigh, outLow, outHigh) {\n    return fround(scale(x, inLow, inHigh, outLow, outHigh));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.iaddh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.iaddh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  iaddh: function iaddh(x0, x1, y0, y1) {\n    var $x0 = x0 >>> 0;\n    var $x1 = x1 >>> 0;\n    var $y0 = y0 >>> 0;\n    return $x1 + (y1 >>> 0) + (($x0 & $y0 | ($x0 | $y0) & ~($x0 + $y0 >>> 0)) >>> 31) | 0;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.imulh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.imulh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  imulh: function imulh(u, v) {\n    var UINT16 = 0xffff;\n    var $u = +u;\n    var $v = +v;\n    var u0 = $u & UINT16;\n    var v0 = $v & UINT16;\n    var u1 = $u >> 16;\n    var v1 = $v >> 16;\n    var t = (u1 * v0 >>> 0) + (u0 * v0 >>> 16);\n    return u1 * v1 + (t >> 16) + ((u0 * v1 >>> 0) + (t & UINT16) >> 16);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.isubh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.isubh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  isubh: function isubh(x0, x1, y0, y1) {\n    var $x0 = x0 >>> 0;\n    var $x1 = x1 >>> 0;\n    var $y0 = y0 >>> 0;\n    return $x1 - (y1 >>> 0) - ((~$x0 & $y0 | ~($x0 ^ $y0) & $x0 - $y0 >>> 0) >>> 31) | 0;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.rad-per-deg.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.rad-per-deg.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { RAD_PER_DEG: 180 / Math.PI });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.radians.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.radians.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar DEG_PER_RAD = Math.PI / 180;\n\n$export($export.S, 'Math', {\n  radians: function radians(degrees) {\n    return degrees * DEG_PER_RAD;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.scale.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.scale.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { scale: __webpack_require__(/*! ./_math-scale */ \"./node_modules/core-js/modules/_math-scale.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.signbit.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.signbit.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// http://jfbastien.github.io/papers/Math.signbit.html\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { signbit: function signbit(x) {\n  // eslint-disable-next-line no-self-compare\n  return (x = +x) != x ? x : x == 0 ? 1 / x == Infinity : x > 0;\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.umulh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.umulh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  umulh: function umulh(u, v) {\n    var UINT16 = 0xffff;\n    var $u = +u;\n    var $v = +v;\n    var u0 = $u & UINT16;\n    var v0 = $v & UINT16;\n    var u1 = $u >>> 16;\n    var v1 = $v >>> 16;\n    var t = (u1 * v0 >>> 0) + (u0 * v0 >>> 16);\n    return u1 * v1 + (t >>> 16) + ((u0 * v1 >>> 0) + (t & UINT16) >>> 16);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.define-getter.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.define-getter.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar $defineProperty = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\n\n// B.2.2.2 Object.prototype.__defineGetter__(P, getter)\n__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && $export($export.P + __webpack_require__(/*! ./_object-forced-pam */ \"./node_modules/core-js/modules/_object-forced-pam.js\"), 'Object', {\n  __defineGetter__: function __defineGetter__(P, getter) {\n    $defineProperty.f(toObject(this), P, { get: aFunction(getter), enumerable: true, configurable: true });\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.define-setter.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.define-setter.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar $defineProperty = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\n\n// B.2.2.3 Object.prototype.__defineSetter__(P, setter)\n__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && $export($export.P + __webpack_require__(/*! ./_object-forced-pam */ \"./node_modules/core-js/modules/_object-forced-pam.js\"), 'Object', {\n  __defineSetter__: function __defineSetter__(P, setter) {\n    $defineProperty.f(toObject(this), P, { set: aFunction(setter), enumerable: true, configurable: true });\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.entries.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.entries.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-object-values-entries\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $entries = __webpack_require__(/*! ./_object-to-array */ \"./node_modules/core-js/modules/_object-to-array.js\")(true);\n\n$export($export.S, 'Object', {\n  entries: function entries(it) {\n    return $entries(it);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.get-own-property-descriptors.js\":\n/*!*********************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.get-own-property-descriptors.js ***!\n  \\*********************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-object-getownpropertydescriptors\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar ownKeys = __webpack_require__(/*! ./_own-keys */ \"./node_modules/core-js/modules/_own-keys.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\nvar createProperty = __webpack_require__(/*! ./_create-property */ \"./node_modules/core-js/modules/_create-property.js\");\n\n$export($export.S, 'Object', {\n  getOwnPropertyDescriptors: function getOwnPropertyDescriptors(object) {\n    var O = toIObject(object);\n    var getDesc = gOPD.f;\n    var keys = ownKeys(O);\n    var result = {};\n    var i = 0;\n    var key, desc;\n    while (keys.length > i) {\n      desc = getDesc(O, key = keys[i++]);\n      if (desc !== undefined) createProperty(result, key, desc);\n    }\n    return result;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.lookup-getter.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.lookup-getter.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar getOwnPropertyDescriptor = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f;\n\n// B.2.2.4 Object.prototype.__lookupGetter__(P)\n__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && $export($export.P + __webpack_require__(/*! ./_object-forced-pam */ \"./node_modules/core-js/modules/_object-forced-pam.js\"), 'Object', {\n  __lookupGetter__: function __lookupGetter__(P) {\n    var O = toObject(this);\n    var K = toPrimitive(P, true);\n    var D;\n    do {\n      if (D = getOwnPropertyDescriptor(O, K)) return D.get;\n    } while (O = getPrototypeOf(O));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.lookup-setter.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.lookup-setter.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar getOwnPropertyDescriptor = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f;\n\n// B.2.2.5 Object.prototype.__lookupSetter__(P)\n__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && $export($export.P + __webpack_require__(/*! ./_object-forced-pam */ \"./node_modules/core-js/modules/_object-forced-pam.js\"), 'Object', {\n  __lookupSetter__: function __lookupSetter__(P) {\n    var O = toObject(this);\n    var K = toPrimitive(P, true);\n    var D;\n    do {\n      if (D = getOwnPropertyDescriptor(O, K)) return D.set;\n    } while (O = getPrototypeOf(O));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.values.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.values.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-object-values-entries\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $values = __webpack_require__(/*! ./_object-to-array */ \"./node_modules/core-js/modules/_object-to-array.js\")(false);\n\n$export($export.S, 'Object', {\n  values: function values(it) {\n    return $values(it);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.observable.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.observable.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/zenparsing/es-observable\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar microtask = __webpack_require__(/*! ./_microtask */ \"./node_modules/core-js/modules/_microtask.js\")();\nvar OBSERVABLE = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('observable');\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar RETURN = forOf.RETURN;\n\nvar getMethod = function (fn) {\n  return fn == null ? undefined : aFunction(fn);\n};\n\nvar cleanupSubscription = function (subscription) {\n  var cleanup = subscription._c;\n  if (cleanup) {\n    subscription._c = undefined;\n    cleanup();\n  }\n};\n\nvar subscriptionClosed = function (subscription) {\n  return subscription._o === undefined;\n};\n\nvar closeSubscription = function (subscription) {\n  if (!subscriptionClosed(subscription)) {\n    subscription._o = undefined;\n    cleanupSubscription(subscription);\n  }\n};\n\nvar Subscription = function (observer, subscriber) {\n  anObject(observer);\n  this._c = undefined;\n  this._o = observer;\n  observer = new SubscriptionObserver(this);\n  try {\n    var cleanup = subscriber(observer);\n    var subscription = cleanup;\n    if (cleanup != null) {\n      if (typeof cleanup.unsubscribe === 'function') cleanup = function () { subscription.unsubscribe(); };\n      else aFunction(cleanup);\n      this._c = cleanup;\n    }\n  } catch (e) {\n    observer.error(e);\n    return;\n  } if (subscriptionClosed(this)) cleanupSubscription(this);\n};\n\nSubscription.prototype = redefineAll({}, {\n  unsubscribe: function unsubscribe() { closeSubscription(this); }\n});\n\nvar SubscriptionObserver = function (subscription) {\n  this._s = subscription;\n};\n\nSubscriptionObserver.prototype = redefineAll({}, {\n  next: function next(value) {\n    var subscription = this._s;\n    if (!subscriptionClosed(subscription)) {\n      var observer = subscription._o;\n      try {\n        var m = getMethod(observer.next);\n        if (m) return m.call(observer, value);\n      } catch (e) {\n        try {\n          closeSubscription(subscription);\n        } finally {\n          throw e;\n        }\n      }\n    }\n  },\n  error: function error(value) {\n    var subscription = this._s;\n    if (subscriptionClosed(subscription)) throw value;\n    var observer = subscription._o;\n    subscription._o = undefined;\n    try {\n      var m = getMethod(observer.error);\n      if (!m) throw value;\n      value = m.call(observer, value);\n    } catch (e) {\n      try {\n        cleanupSubscription(subscription);\n      } finally {\n        throw e;\n      }\n    } cleanupSubscription(subscription);\n    return value;\n  },\n  complete: function complete(value) {\n    var subscription = this._s;\n    if (!subscriptionClosed(subscription)) {\n      var observer = subscription._o;\n      subscription._o = undefined;\n      try {\n        var m = getMethod(observer.complete);\n        value = m ? m.call(observer, value) : undefined;\n      } catch (e) {\n        try {\n          cleanupSubscription(subscription);\n        } finally {\n          throw e;\n        }\n      } cleanupSubscription(subscription);\n      return value;\n    }\n  }\n});\n\nvar $Observable = function Observable(subscriber) {\n  anInstance(this, $Observable, 'Observable', '_f')._f = aFunction(subscriber);\n};\n\nredefineAll($Observable.prototype, {\n  subscribe: function subscribe(observer) {\n    return new Subscription(observer, this._f);\n  },\n  forEach: function forEach(fn) {\n    var that = this;\n    return new (core.Promise || global.Promise)(function (resolve, reject) {\n      aFunction(fn);\n      var subscription = that.subscribe({\n        next: function (value) {\n          try {\n            return fn(value);\n          } catch (e) {\n            reject(e);\n            subscription.unsubscribe();\n          }\n        },\n        error: reject,\n        complete: resolve\n      });\n    });\n  }\n});\n\nredefineAll($Observable, {\n  from: function from(x) {\n    var C = typeof this === 'function' ? this : $Observable;\n    var method = getMethod(anObject(x)[OBSERVABLE]);\n    if (method) {\n      var observable = anObject(method.call(x));\n      return observable.constructor === C ? observable : new C(function (observer) {\n        return observable.subscribe(observer);\n      });\n    }\n    return new C(function (observer) {\n      var done = false;\n      microtask(function () {\n        if (!done) {\n          try {\n            if (forOf(x, false, function (it) {\n              observer.next(it);\n              if (done) return RETURN;\n            }) === RETURN) return;\n          } catch (e) {\n            if (done) throw e;\n            observer.error(e);\n            return;\n          } observer.complete();\n        }\n      });\n      return function () { done = true; };\n    });\n  },\n  of: function of() {\n    for (var i = 0, l = arguments.length, items = new Array(l); i < l;) items[i] = arguments[i++];\n    return new (typeof this === 'function' ? this : $Observable)(function (observer) {\n      var done = false;\n      microtask(function () {\n        if (!done) {\n          for (var j = 0; j < items.length; ++j) {\n            observer.next(items[j]);\n            if (done) return;\n          } observer.complete();\n        }\n      });\n      return function () { done = true; };\n    });\n  }\n});\n\nhide($Observable.prototype, OBSERVABLE, function () { return this; });\n\n$export($export.G, { Observable: $Observable });\n\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")('Observable');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.promise.finally.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.promise.finally.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// https://github.com/tc39/proposal-promise-finally\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\nvar promiseResolve = __webpack_require__(/*! ./_promise-resolve */ \"./node_modules/core-js/modules/_promise-resolve.js\");\n\n$export($export.P + $export.R, 'Promise', { 'finally': function (onFinally) {\n  var C = speciesConstructor(this, core.Promise || global.Promise);\n  var isFunction = typeof onFinally == 'function';\n  return this.then(\n    isFunction ? function (x) {\n      return promiseResolve(C, onFinally()).then(function () { return x; });\n    } : onFinally,\n    isFunction ? function (e) {\n      return promiseResolve(C, onFinally()).then(function () { throw e; });\n    } : onFinally\n  );\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.promise.try.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.promise.try.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/tc39/proposal-promise-try\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar newPromiseCapability = __webpack_require__(/*! ./_new-promise-capability */ \"./node_modules/core-js/modules/_new-promise-capability.js\");\nvar perform = __webpack_require__(/*! ./_perform */ \"./node_modules/core-js/modules/_perform.js\");\n\n$export($export.S, 'Promise', { 'try': function (callbackfn) {\n  var promiseCapability = newPromiseCapability.f(this);\n  var result = perform(callbackfn);\n  (result.e ? promiseCapability.reject : promiseCapability.resolve)(result.v);\n  return promiseCapability.promise;\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.define-metadata.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.define-metadata.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toMetaKey = metadata.key;\nvar ordinaryDefineOwnMetadata = metadata.set;\n\nmetadata.exp({ defineMetadata: function defineMetadata(metadataKey, metadataValue, target, targetKey) {\n  ordinaryDefineOwnMetadata(metadataKey, metadataValue, anObject(target), toMetaKey(targetKey));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.delete-metadata.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.delete-metadata.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toMetaKey = metadata.key;\nvar getOrCreateMetadataMap = metadata.map;\nvar store = metadata.store;\n\nmetadata.exp({ deleteMetadata: function deleteMetadata(metadataKey, target /* , targetKey */) {\n  var targetKey = arguments.length < 3 ? undefined : toMetaKey(arguments[2]);\n  var metadataMap = getOrCreateMetadataMap(anObject(target), targetKey, false);\n  if (metadataMap === undefined || !metadataMap['delete'](metadataKey)) return false;\n  if (metadataMap.size) return true;\n  var targetMetadata = store.get(target);\n  targetMetadata['delete'](targetKey);\n  return !!targetMetadata.size || store['delete'](target);\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.get-metadata-keys.js\":\n/*!***********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.get-metadata-keys.js ***!\n  \\***********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar Set = __webpack_require__(/*! ./es6.set */ \"./node_modules/core-js/modules/es6.set.js\");\nvar from = __webpack_require__(/*! ./_array-from-iterable */ \"./node_modules/core-js/modules/_array-from-iterable.js\");\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar ordinaryOwnMetadataKeys = metadata.keys;\nvar toMetaKey = metadata.key;\n\nvar ordinaryMetadataKeys = function (O, P) {\n  var oKeys = ordinaryOwnMetadataKeys(O, P);\n  var parent = getPrototypeOf(O);\n  if (parent === null) return oKeys;\n  var pKeys = ordinaryMetadataKeys(parent, P);\n  return pKeys.length ? oKeys.length ? from(new Set(oKeys.concat(pKeys))) : pKeys : oKeys;\n};\n\nmetadata.exp({ getMetadataKeys: function getMetadataKeys(target /* , targetKey */) {\n  return ordinaryMetadataKeys(anObject(target), arguments.length < 2 ? undefined : toMetaKey(arguments[1]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.get-metadata.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.get-metadata.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar ordinaryHasOwnMetadata = metadata.has;\nvar ordinaryGetOwnMetadata = metadata.get;\nvar toMetaKey = metadata.key;\n\nvar ordinaryGetMetadata = function (MetadataKey, O, P) {\n  var hasOwn = ordinaryHasOwnMetadata(MetadataKey, O, P);\n  if (hasOwn) return ordinaryGetOwnMetadata(MetadataKey, O, P);\n  var parent = getPrototypeOf(O);\n  return parent !== null ? ordinaryGetMetadata(MetadataKey, parent, P) : undefined;\n};\n\nmetadata.exp({ getMetadata: function getMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryGetMetadata(metadataKey, anObject(target), arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.get-own-metadata-keys.js\":\n/*!***************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.get-own-metadata-keys.js ***!\n  \\***************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar ordinaryOwnMetadataKeys = metadata.keys;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ getOwnMetadataKeys: function getOwnMetadataKeys(target /* , targetKey */) {\n  return ordinaryOwnMetadataKeys(anObject(target), arguments.length < 2 ? undefined : toMetaKey(arguments[1]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.get-own-metadata.js\":\n/*!**********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.get-own-metadata.js ***!\n  \\**********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar ordinaryGetOwnMetadata = metadata.get;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ getOwnMetadata: function getOwnMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryGetOwnMetadata(metadataKey, anObject(target)\n    , arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.has-metadata.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.has-metadata.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar ordinaryHasOwnMetadata = metadata.has;\nvar toMetaKey = metadata.key;\n\nvar ordinaryHasMetadata = function (MetadataKey, O, P) {\n  var hasOwn = ordinaryHasOwnMetadata(MetadataKey, O, P);\n  if (hasOwn) return true;\n  var parent = getPrototypeOf(O);\n  return parent !== null ? ordinaryHasMetadata(MetadataKey, parent, P) : false;\n};\n\nmetadata.exp({ hasMetadata: function hasMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryHasMetadata(metadataKey, anObject(target), arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.has-own-metadata.js\":\n/*!**********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.has-own-metadata.js ***!\n  \\**********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar ordinaryHasOwnMetadata = metadata.has;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ hasOwnMetadata: function hasOwnMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryHasOwnMetadata(metadataKey, anObject(target)\n    , arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.metadata.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.metadata.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar toMetaKey = $metadata.key;\nvar ordinaryDefineOwnMetadata = $metadata.set;\n\n$metadata.exp({ metadata: function metadata(metadataKey, metadataValue) {\n  return function decorator(target, targetKey) {\n    ordinaryDefineOwnMetadata(\n      metadataKey, metadataValue,\n      (targetKey !== undefined ? anObject : aFunction)(target),\n      toMetaKey(targetKey)\n    );\n  };\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.set.from.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.set.from.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-set.from\n__webpack_require__(/*! ./_set-collection-from */ \"./node_modules/core-js/modules/_set-collection-from.js\")('Set');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.set.of.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.set.of.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-set.of\n__webpack_require__(/*! ./_set-collection-of */ \"./node_modules/core-js/modules/_set-collection-of.js\")('Set');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.set.to-json.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.set.to-json.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P + $export.R, 'Set', { toJSON: __webpack_require__(/*! ./_collection-to-json */ \"./node_modules/core-js/modules/_collection-to-json.js\")('Set') });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.at.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.at.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/mathiasbynens/String.prototype.at\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $at = __webpack_require__(/*! ./_string-at */ \"./node_modules/core-js/modules/_string-at.js\")(true);\n\n$export($export.P, 'String', {\n  at: function at(pos) {\n    return $at(this, pos);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.match-all.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.match-all.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/String.prototype.matchAll/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar isRegExp = __webpack_require__(/*! ./_is-regexp */ \"./node_modules/core-js/modules/_is-regexp.js\");\nvar getFlags = __webpack_require__(/*! ./_flags */ \"./node_modules/core-js/modules/_flags.js\");\nvar RegExpProto = RegExp.prototype;\n\nvar $RegExpStringIterator = function (regexp, string) {\n  this._r = regexp;\n  this._s = string;\n};\n\n__webpack_require__(/*! ./_iter-create */ \"./node_modules/core-js/modules/_iter-create.js\")($RegExpStringIterator, 'RegExp String', function next() {\n  var match = this._r.exec(this._s);\n  return { value: match, done: match === null };\n});\n\n$export($export.P, 'String', {\n  matchAll: function matchAll(regexp) {\n    defined(this);\n    if (!isRegExp(regexp)) throw TypeError(regexp + ' is not a regexp!');\n    var S = String(this);\n    var flags = 'flags' in RegExpProto ? String(regexp.flags) : getFlags.call(regexp);\n    var rx = new RegExp(regexp.source, ~flags.indexOf('g') ? flags : 'g' + flags);\n    rx.lastIndex = toLength(regexp.lastIndex);\n    return new $RegExpStringIterator(rx, S);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.pad-end.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.pad-end.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/tc39/proposal-string-pad-start-end\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $pad = __webpack_require__(/*! ./_string-pad */ \"./node_modules/core-js/modules/_string-pad.js\");\nvar userAgent = __webpack_require__(/*! ./_user-agent */ \"./node_modules/core-js/modules/_user-agent.js\");\n\n// https://github.com/zloirock/core-js/issues/280\n$export($export.P + $export.F * /Version\\/10\\.\\d+(\\.\\d+)? Safari\\//.test(userAgent), 'String', {\n  padEnd: function padEnd(maxLength /* , fillString = ' ' */) {\n    return $pad(this, maxLength, arguments.length > 1 ? arguments[1] : undefined, false);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.pad-start.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.pad-start.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/tc39/proposal-string-pad-start-end\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $pad = __webpack_require__(/*! ./_string-pad */ \"./node_modules/core-js/modules/_string-pad.js\");\nvar userAgent = __webpack_require__(/*! ./_user-agent */ \"./node_modules/core-js/modules/_user-agent.js\");\n\n// https://github.com/zloirock/core-js/issues/280\n$export($export.P + $export.F * /Version\\/10\\.\\d+(\\.\\d+)? Safari\\//.test(userAgent), 'String', {\n  padStart: function padStart(maxLength /* , fillString = ' ' */) {\n    return $pad(this, maxLength, arguments.length > 1 ? arguments[1] : undefined, true);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.trim-left.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.trim-left.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/sebmarkbage/ecmascript-string-left-right-trim\n__webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\")('trimLeft', function ($trim) {\n  return function trimLeft() {\n    return $trim(this, 1);\n  };\n}, 'trimStart');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.trim-right.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.trim-right.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/sebmarkbage/ecmascript-string-left-right-trim\n__webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\")('trimRight', function ($trim) {\n  return function trimRight() {\n    return $trim(this, 2);\n  };\n}, 'trimEnd');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.symbol.async-iterator.js\":\n/*!*******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.symbol.async-iterator.js ***!\n  \\*******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_wks-define */ \"./node_modules/core-js/modules/_wks-define.js\")('asyncIterator');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.symbol.observable.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.symbol.observable.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_wks-define */ \"./node_modules/core-js/modules/_wks-define.js\")('observable');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.system.global.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.system.global.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-global\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'System', { global: __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.weak-map.from.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.weak-map.from.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-weakmap.from\n__webpack_require__(/*! ./_set-collection-from */ \"./node_modules/core-js/modules/_set-collection-from.js\")('WeakMap');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.weak-map.of.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.weak-map.of.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-weakmap.of\n__webpack_require__(/*! ./_set-collection-of */ \"./node_modules/core-js/modules/_set-collection-of.js\")('WeakMap');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.weak-set.from.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.weak-set.from.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-weakset.from\n__webpack_require__(/*! ./_set-collection-from */ \"./node_modules/core-js/modules/_set-collection-from.js\")('WeakSet');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.weak-set.of.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.weak-set.of.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-weakset.of\n__webpack_require__(/*! ./_set-collection-of */ \"./node_modules/core-js/modules/_set-collection-of.js\")('WeakSet');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/web.dom.iterable.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/web.dom.iterable.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $iterators = __webpack_require__(/*! ./es6.array.iterator */ \"./node_modules/core-js/modules/es6.array.iterator.js\");\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar wks = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\nvar ITERATOR = wks('iterator');\nvar TO_STRING_TAG = wks('toStringTag');\nvar ArrayValues = Iterators.Array;\n\nvar DOMIterables = {\n  CSSRuleList: true, // TODO: Not spec compliant, should be false.\n  CSSStyleDeclaration: false,\n  CSSValueList: false,\n  ClientRectList: false,\n  DOMRectList: false,\n  DOMStringList: false,\n  DOMTokenList: true,\n  DataTransferItemList: false,\n  FileList: false,\n  HTMLAllCollection: false,\n  HTMLCollection: false,\n  HTMLFormElement: false,\n  HTMLSelectElement: false,\n  MediaList: true, // TODO: Not spec compliant, should be false.\n  MimeTypeArray: false,\n  NamedNodeMap: false,\n  NodeList: true,\n  PaintRequestList: false,\n  Plugin: false,\n  PluginArray: false,\n  SVGLengthList: false,\n  SVGNumberList: false,\n  SVGPathSegList: false,\n  SVGPointList: false,\n  SVGStringList: false,\n  SVGTransformList: false,\n  SourceBufferList: false,\n  StyleSheetList: true, // TODO: Not spec compliant, should be false.\n  TextTrackCueList: false,\n  TextTrackList: false,\n  TouchList: false\n};\n\nfor (var collections = getKeys(DOMIterables), i = 0; i < collections.length; i++) {\n  var NAME = collections[i];\n  var explicit = DOMIterables[NAME];\n  var Collection = global[NAME];\n  var proto = Collection && Collection.prototype;\n  var key;\n  if (proto) {\n    if (!proto[ITERATOR]) hide(proto, ITERATOR, ArrayValues);\n    if (!proto[TO_STRING_TAG]) hide(proto, TO_STRING_TAG, NAME);\n    Iterators[NAME] = ArrayValues;\n    if (explicit) for (key in $iterators) if (!proto[key]) redefine(proto, key, $iterators[key], true);\n  }\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/web.immediate.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/web.immediate.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $task = __webpack_require__(/*! ./_task */ \"./node_modules/core-js/modules/_task.js\");\n$export($export.G + $export.B, {\n  setImmediate: $task.set,\n  clearImmediate: $task.clear\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/web.timers.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/web.timers.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// ie9- setTimeout & setInterval additional parameters fix\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar userAgent = __webpack_require__(/*! ./_user-agent */ \"./node_modules/core-js/modules/_user-agent.js\");\nvar slice = [].slice;\nvar MSIE = /MSIE .\\./.test(userAgent); // <- dirty ie9- check\nvar wrap = function (set) {\n  return function (fn, time /* , ...args */) {\n    var boundArgs = arguments.length > 2;\n    var args = boundArgs ? slice.call(arguments, 2) : false;\n    return set(boundArgs ? function () {\n      // eslint-disable-next-line no-new-func\n      (typeof fn == 'function' ? fn : Function(fn)).apply(this, args);\n    } : fn, time);\n  };\n};\n$export($export.G + $export.B + $export.F * MSIE, {\n  setTimeout: wrap(global.setTimeout),\n  setInterval: wrap(global.setInterval)\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/shim.js\":\n/*!**************************************!*\\\n  !*** ./node_modules/core-js/shim.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./modules/es6.symbol */ \"./node_modules/core-js/modules/es6.symbol.js\");\n__webpack_require__(/*! ./modules/es6.object.create */ \"./node_modules/core-js/modules/es6.object.create.js\");\n__webpack_require__(/*! ./modules/es6.object.define-property */ \"./node_modules/core-js/modules/es6.object.define-property.js\");\n__webpack_require__(/*! ./modules/es6.object.define-properties */ \"./node_modules/core-js/modules/es6.object.define-properties.js\");\n__webpack_require__(/*! ./modules/es6.object.get-own-property-descriptor */ \"./node_modules/core-js/modules/es6.object.get-own-property-descriptor.js\");\n__webpack_require__(/*! ./modules/es6.object.get-prototype-of */ \"./node_modules/core-js/modules/es6.object.get-prototype-of.js\");\n__webpack_require__(/*! ./modules/es6.object.keys */ \"./node_modules/core-js/modules/es6.object.keys.js\");\n__webpack_require__(/*! ./modules/es6.object.get-own-property-names */ \"./node_modules/core-js/modules/es6.object.get-own-property-names.js\");\n__webpack_require__(/*! ./modules/es6.object.freeze */ \"./node_modules/core-js/modules/es6.object.freeze.js\");\n__webpack_require__(/*! ./modules/es6.object.seal */ \"./node_modules/core-js/modules/es6.object.seal.js\");\n__webpack_require__(/*! ./modules/es6.object.prevent-extensions */ \"./node_modules/core-js/modules/es6.object.prevent-extensions.js\");\n__webpack_require__(/*! ./modules/es6.object.is-frozen */ \"./node_modules/core-js/modules/es6.object.is-frozen.js\");\n__webpack_require__(/*! ./modules/es6.object.is-sealed */ \"./node_modules/core-js/modules/es6.object.is-sealed.js\");\n__webpack_require__(/*! ./modules/es6.object.is-extensible */ \"./node_modules/core-js/modules/es6.object.is-extensible.js\");\n__webpack_require__(/*! ./modules/es6.object.assign */ \"./node_modules/core-js/modules/es6.object.assign.js\");\n__webpack_require__(/*! ./modules/es6.object.is */ \"./node_modules/core-js/modules/es6.object.is.js\");\n__webpack_require__(/*! ./modules/es6.object.set-prototype-of */ \"./node_modules/core-js/modules/es6.object.set-prototype-of.js\");\n__webpack_require__(/*! ./modules/es6.object.to-string */ \"./node_modules/core-js/modules/es6.object.to-string.js\");\n__webpack_require__(/*! ./modules/es6.function.bind */ \"./node_modules/core-js/modules/es6.function.bind.js\");\n__webpack_require__(/*! ./modules/es6.function.name */ \"./node_modules/core-js/modules/es6.function.name.js\");\n__webpack_require__(/*! ./modules/es6.function.has-instance */ \"./node_modules/core-js/modules/es6.function.has-instance.js\");\n__webpack_require__(/*! ./modules/es6.parse-int */ \"./node_modules/core-js/modules/es6.parse-int.js\");\n__webpack_require__(/*! ./modules/es6.parse-float */ \"./node_modules/core-js/modules/es6.parse-float.js\");\n__webpack_require__(/*! ./modules/es6.number.constructor */ \"./node_modules/core-js/modules/es6.number.constructor.js\");\n__webpack_require__(/*! ./modules/es6.number.to-fixed */ \"./node_modules/core-js/modules/es6.number.to-fixed.js\");\n__webpack_require__(/*! ./modules/es6.number.to-precision */ \"./node_modules/core-js/modules/es6.number.to-precision.js\");\n__webpack_require__(/*! ./modules/es6.number.epsilon */ \"./node_modules/core-js/modules/es6.number.epsilon.js\");\n__webpack_require__(/*! ./modules/es6.number.is-finite */ \"./node_modules/core-js/modules/es6.number.is-finite.js\");\n__webpack_require__(/*! ./modules/es6.number.is-integer */ \"./node_modules/core-js/modules/es6.number.is-integer.js\");\n__webpack_require__(/*! ./modules/es6.number.is-nan */ \"./node_modules/core-js/modules/es6.number.is-nan.js\");\n__webpack_require__(/*! ./modules/es6.number.is-safe-integer */ \"./node_modules/core-js/modules/es6.number.is-safe-integer.js\");\n__webpack_require__(/*! ./modules/es6.number.max-safe-integer */ \"./node_modules/core-js/modules/es6.number.max-safe-integer.js\");\n__webpack_require__(/*! ./modules/es6.number.min-safe-integer */ \"./node_modules/core-js/modules/es6.number.min-safe-integer.js\");\n__webpack_require__(/*! ./modules/es6.number.parse-float */ \"./node_modules/core-js/modules/es6.number.parse-float.js\");\n__webpack_require__(/*! ./modules/es6.number.parse-int */ \"./node_modules/core-js/modules/es6.number.parse-int.js\");\n__webpack_require__(/*! ./modules/es6.math.acosh */ \"./node_modules/core-js/modules/es6.math.acosh.js\");\n__webpack_require__(/*! ./modules/es6.math.asinh */ \"./node_modules/core-js/modules/es6.math.asinh.js\");\n__webpack_require__(/*! ./modules/es6.math.atanh */ \"./node_modules/core-js/modules/es6.math.atanh.js\");\n__webpack_require__(/*! ./modules/es6.math.cbrt */ \"./node_modules/core-js/modules/es6.math.cbrt.js\");\n__webpack_require__(/*! ./modules/es6.math.clz32 */ \"./node_modules/core-js/modules/es6.math.clz32.js\");\n__webpack_require__(/*! ./modules/es6.math.cosh */ \"./node_modules/core-js/modules/es6.math.cosh.js\");\n__webpack_require__(/*! ./modules/es6.math.expm1 */ \"./node_modules/core-js/modules/es6.math.expm1.js\");\n__webpack_require__(/*! ./modules/es6.math.fround */ \"./node_modules/core-js/modules/es6.math.fround.js\");\n__webpack_require__(/*! ./modules/es6.math.hypot */ \"./node_modules/core-js/modules/es6.math.hypot.js\");\n__webpack_require__(/*! ./modules/es6.math.imul */ \"./node_modules/core-js/modules/es6.math.imul.js\");\n__webpack_require__(/*! ./modules/es6.math.log10 */ \"./node_modules/core-js/modules/es6.math.log10.js\");\n__webpack_require__(/*! ./modules/es6.math.log1p */ \"./node_modules/core-js/modules/es6.math.log1p.js\");\n__webpack_require__(/*! ./modules/es6.math.log2 */ \"./node_modules/core-js/modules/es6.math.log2.js\");\n__webpack_require__(/*! ./modules/es6.math.sign */ \"./node_modules/core-js/modules/es6.math.sign.js\");\n__webpack_require__(/*! ./modules/es6.math.sinh */ \"./node_modules/core-js/modules/es6.math.sinh.js\");\n__webpack_require__(/*! ./modules/es6.math.tanh */ \"./node_modules/core-js/modules/es6.math.tanh.js\");\n__webpack_require__(/*! ./modules/es6.math.trunc */ \"./node_modules/core-js/modules/es6.math.trunc.js\");\n__webpack_require__(/*! ./modules/es6.string.from-code-point */ \"./node_modules/core-js/modules/es6.string.from-code-point.js\");\n__webpack_require__(/*! ./modules/es6.string.raw */ \"./node_modules/core-js/modules/es6.string.raw.js\");\n__webpack_require__(/*! ./modules/es6.string.trim */ \"./node_modules/core-js/modules/es6.string.trim.js\");\n__webpack_require__(/*! ./modules/es6.string.iterator */ \"./node_modules/core-js/modules/es6.string.iterator.js\");\n__webpack_require__(/*! ./modules/es6.string.code-point-at */ \"./node_modules/core-js/modules/es6.string.code-point-at.js\");\n__webpack_require__(/*! ./modules/es6.string.ends-with */ \"./node_modules/core-js/modules/es6.string.ends-with.js\");\n__webpack_require__(/*! ./modules/es6.string.includes */ \"./node_modules/core-js/modules/es6.string.includes.js\");\n__webpack_require__(/*! ./modules/es6.string.repeat */ \"./node_modules/core-js/modules/es6.string.repeat.js\");\n__webpack_require__(/*! ./modules/es6.string.starts-with */ \"./node_modules/core-js/modules/es6.string.starts-with.js\");\n__webpack_require__(/*! ./modules/es6.string.anchor */ \"./node_modules/core-js/modules/es6.string.anchor.js\");\n__webpack_require__(/*! ./modules/es6.string.big */ \"./node_modules/core-js/modules/es6.string.big.js\");\n__webpack_require__(/*! ./modules/es6.string.blink */ \"./node_modules/core-js/modules/es6.string.blink.js\");\n__webpack_require__(/*! ./modules/es6.string.bold */ \"./node_modules/core-js/modules/es6.string.bold.js\");\n__webpack_require__(/*! ./modules/es6.string.fixed */ \"./node_modules/core-js/modules/es6.string.fixed.js\");\n__webpack_require__(/*! ./modules/es6.string.fontcolor */ \"./node_modules/core-js/modules/es6.string.fontcolor.js\");\n__webpack_require__(/*! ./modules/es6.string.fontsize */ \"./node_modules/core-js/modules/es6.string.fontsize.js\");\n__webpack_require__(/*! ./modules/es6.string.italics */ \"./node_modules/core-js/modules/es6.string.italics.js\");\n__webpack_require__(/*! ./modules/es6.string.link */ \"./node_modules/core-js/modules/es6.string.link.js\");\n__webpack_require__(/*! ./modules/es6.string.small */ \"./node_modules/core-js/modules/es6.string.small.js\");\n__webpack_require__(/*! ./modules/es6.string.strike */ \"./node_modules/core-js/modules/es6.string.strike.js\");\n__webpack_require__(/*! ./modules/es6.string.sub */ \"./node_modules/core-js/modules/es6.string.sub.js\");\n__webpack_require__(/*! ./modules/es6.string.sup */ \"./node_modules/core-js/modules/es6.string.sup.js\");\n__webpack_require__(/*! ./modules/es6.date.now */ \"./node_modules/core-js/modules/es6.date.now.js\");\n__webpack_require__(/*! ./modules/es6.date.to-json */ \"./node_modules/core-js/modules/es6.date.to-json.js\");\n__webpack_require__(/*! ./modules/es6.date.to-iso-string */ \"./node_modules/core-js/modules/es6.date.to-iso-string.js\");\n__webpack_require__(/*! ./modules/es6.date.to-string */ \"./node_modules/core-js/modules/es6.date.to-string.js\");\n__webpack_require__(/*! ./modules/es6.date.to-primitive */ \"./node_modules/core-js/modules/es6.date.to-primitive.js\");\n__webpack_require__(/*! ./modules/es6.array.is-array */ \"./node_modules/core-js/modules/es6.array.is-array.js\");\n__webpack_require__(/*! ./modules/es6.array.from */ \"./node_modules/core-js/modules/es6.array.from.js\");\n__webpack_require__(/*! ./modules/es6.array.of */ \"./node_modules/core-js/modules/es6.array.of.js\");\n__webpack_require__(/*! ./modules/es6.array.join */ \"./node_modules/core-js/modules/es6.array.join.js\");\n__webpack_require__(/*! ./modules/es6.array.slice */ \"./node_modules/core-js/modules/es6.array.slice.js\");\n__webpack_require__(/*! ./modules/es6.array.sort */ \"./node_modules/core-js/modules/es6.array.sort.js\");\n__webpack_require__(/*! ./modules/es6.array.for-each */ \"./node_modules/core-js/modules/es6.array.for-each.js\");\n__webpack_require__(/*! ./modules/es6.array.map */ \"./node_modules/core-js/modules/es6.array.map.js\");\n__webpack_require__(/*! ./modules/es6.array.filter */ \"./node_modules/core-js/modules/es6.array.filter.js\");\n__webpack_require__(/*! ./modules/es6.array.some */ \"./node_modules/core-js/modules/es6.array.some.js\");\n__webpack_require__(/*! ./modules/es6.array.every */ \"./node_modules/core-js/modules/es6.array.every.js\");\n__webpack_require__(/*! ./modules/es6.array.reduce */ \"./node_modules/core-js/modules/es6.array.reduce.js\");\n__webpack_require__(/*! ./modules/es6.array.reduce-right */ \"./node_modules/core-js/modules/es6.array.reduce-right.js\");\n__webpack_require__(/*! ./modules/es6.array.index-of */ \"./node_modules/core-js/modules/es6.array.index-of.js\");\n__webpack_require__(/*! ./modules/es6.array.last-index-of */ \"./node_modules/core-js/modules/es6.array.last-index-of.js\");\n__webpack_require__(/*! ./modules/es6.array.copy-within */ \"./node_modules/core-js/modules/es6.array.copy-within.js\");\n__webpack_require__(/*! ./modules/es6.array.fill */ \"./node_modules/core-js/modules/es6.array.fill.js\");\n__webpack_require__(/*! ./modules/es6.array.find */ \"./node_modules/core-js/modules/es6.array.find.js\");\n__webpack_require__(/*! ./modules/es6.array.find-index */ \"./node_modules/core-js/modules/es6.array.find-index.js\");\n__webpack_require__(/*! ./modules/es6.array.species */ \"./node_modules/core-js/modules/es6.array.species.js\");\n__webpack_require__(/*! ./modules/es6.array.iterator */ \"./node_modules/core-js/modules/es6.array.iterator.js\");\n__webpack_require__(/*! ./modules/es6.regexp.constructor */ \"./node_modules/core-js/modules/es6.regexp.constructor.js\");\n__webpack_require__(/*! ./modules/es6.regexp.exec */ \"./node_modules/core-js/modules/es6.regexp.exec.js\");\n__webpack_require__(/*! ./modules/es6.regexp.to-string */ \"./node_modules/core-js/modules/es6.regexp.to-string.js\");\n__webpack_require__(/*! ./modules/es6.regexp.flags */ \"./node_modules/core-js/modules/es6.regexp.flags.js\");\n__webpack_require__(/*! ./modules/es6.regexp.match */ \"./node_modules/core-js/modules/es6.regexp.match.js\");\n__webpack_require__(/*! ./modules/es6.regexp.replace */ \"./node_modules/core-js/modules/es6.regexp.replace.js\");\n__webpack_require__(/*! ./modules/es6.regexp.search */ \"./node_modules/core-js/modules/es6.regexp.search.js\");\n__webpack_require__(/*! ./modules/es6.regexp.split */ \"./node_modules/core-js/modules/es6.regexp.split.js\");\n__webpack_require__(/*! ./modules/es6.promise */ \"./node_modules/core-js/modules/es6.promise.js\");\n__webpack_require__(/*! ./modules/es6.map */ \"./node_modules/core-js/modules/es6.map.js\");\n__webpack_require__(/*! ./modules/es6.set */ \"./node_modules/core-js/modules/es6.set.js\");\n__webpack_require__(/*! ./modules/es6.weak-map */ \"./node_modules/core-js/modules/es6.weak-map.js\");\n__webpack_require__(/*! ./modules/es6.weak-set */ \"./node_modules/core-js/modules/es6.weak-set.js\");\n__webpack_require__(/*! ./modules/es6.typed.array-buffer */ \"./node_modules/core-js/modules/es6.typed.array-buffer.js\");\n__webpack_require__(/*! ./modules/es6.typed.data-view */ \"./node_modules/core-js/modules/es6.typed.data-view.js\");\n__webpack_require__(/*! ./modules/es6.typed.int8-array */ \"./node_modules/core-js/modules/es6.typed.int8-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.uint8-array */ \"./node_modules/core-js/modules/es6.typed.uint8-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.uint8-clamped-array */ \"./node_modules/core-js/modules/es6.typed.uint8-clamped-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.int16-array */ \"./node_modules/core-js/modules/es6.typed.int16-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.uint16-array */ \"./node_modules/core-js/modules/es6.typed.uint16-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.int32-array */ \"./node_modules/core-js/modules/es6.typed.int32-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.uint32-array */ \"./node_modules/core-js/modules/es6.typed.uint32-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.float32-array */ \"./node_modules/core-js/modules/es6.typed.float32-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.float64-array */ \"./node_modules/core-js/modules/es6.typed.float64-array.js\");\n__webpack_require__(/*! ./modules/es6.reflect.apply */ \"./node_modules/core-js/modules/es6.reflect.apply.js\");\n__webpack_require__(/*! ./modules/es6.reflect.construct */ \"./node_modules/core-js/modules/es6.reflect.construct.js\");\n__webpack_require__(/*! ./modules/es6.reflect.define-property */ \"./node_modules/core-js/modules/es6.reflect.define-property.js\");\n__webpack_require__(/*! ./modules/es6.reflect.delete-property */ \"./node_modules/core-js/modules/es6.reflect.delete-property.js\");\n__webpack_require__(/*! ./modules/es6.reflect.enumerate */ \"./node_modules/core-js/modules/es6.reflect.enumerate.js\");\n__webpack_require__(/*! ./modules/es6.reflect.get */ \"./node_modules/core-js/modules/es6.reflect.get.js\");\n__webpack_require__(/*! ./modules/es6.reflect.get-own-property-descriptor */ \"./node_modules/core-js/modules/es6.reflect.get-own-property-descriptor.js\");\n__webpack_require__(/*! ./modules/es6.reflect.get-prototype-of */ \"./node_modules/core-js/modules/es6.reflect.get-prototype-of.js\");\n__webpack_require__(/*! ./modules/es6.reflect.has */ \"./node_modules/core-js/modules/es6.reflect.has.js\");\n__webpack_require__(/*! ./modules/es6.reflect.is-extensible */ \"./node_modules/core-js/modules/es6.reflect.is-extensible.js\");\n__webpack_require__(/*! ./modules/es6.reflect.own-keys */ \"./node_modules/core-js/modules/es6.reflect.own-keys.js\");\n__webpack_require__(/*! ./modules/es6.reflect.prevent-extensions */ \"./node_modules/core-js/modules/es6.reflect.prevent-extensions.js\");\n__webpack_require__(/*! ./modules/es6.reflect.set */ \"./node_modules/core-js/modules/es6.reflect.set.js\");\n__webpack_require__(/*! ./modules/es6.reflect.set-prototype-of */ \"./node_modules/core-js/modules/es6.reflect.set-prototype-of.js\");\n__webpack_require__(/*! ./modules/es7.array.includes */ \"./node_modules/core-js/modules/es7.array.includes.js\");\n__webpack_require__(/*! ./modules/es7.array.flat-map */ \"./node_modules/core-js/modules/es7.array.flat-map.js\");\n__webpack_require__(/*! ./modules/es7.array.flatten */ \"./node_modules/core-js/modules/es7.array.flatten.js\");\n__webpack_require__(/*! ./modules/es7.string.at */ \"./node_modules/core-js/modules/es7.string.at.js\");\n__webpack_require__(/*! ./modules/es7.string.pad-start */ \"./node_modules/core-js/modules/es7.string.pad-start.js\");\n__webpack_require__(/*! ./modules/es7.string.pad-end */ \"./node_modules/core-js/modules/es7.string.pad-end.js\");\n__webpack_require__(/*! ./modules/es7.string.trim-left */ \"./node_modules/core-js/modules/es7.string.trim-left.js\");\n__webpack_require__(/*! ./modules/es7.string.trim-right */ \"./node_modules/core-js/modules/es7.string.trim-right.js\");\n__webpack_require__(/*! ./modules/es7.string.match-all */ \"./node_modules/core-js/modules/es7.string.match-all.js\");\n__webpack_require__(/*! ./modules/es7.symbol.async-iterator */ \"./node_modules/core-js/modules/es7.symbol.async-iterator.js\");\n__webpack_require__(/*! ./modules/es7.symbol.observable */ \"./node_modules/core-js/modules/es7.symbol.observable.js\");\n__webpack_require__(/*! ./modules/es7.object.get-own-property-descriptors */ \"./node_modules/core-js/modules/es7.object.get-own-property-descriptors.js\");\n__webpack_require__(/*! ./modules/es7.object.values */ \"./node_modules/core-js/modules/es7.object.values.js\");\n__webpack_require__(/*! ./modules/es7.object.entries */ \"./node_modules/core-js/modules/es7.object.entries.js\");\n__webpack_require__(/*! ./modules/es7.object.define-getter */ \"./node_modules/core-js/modules/es7.object.define-getter.js\");\n__webpack_require__(/*! ./modules/es7.object.define-setter */ \"./node_modules/core-js/modules/es7.object.define-setter.js\");\n__webpack_require__(/*! ./modules/es7.object.lookup-getter */ \"./node_modules/core-js/modules/es7.object.lookup-getter.js\");\n__webpack_require__(/*! ./modules/es7.object.lookup-setter */ \"./node_modules/core-js/modules/es7.object.lookup-setter.js\");\n__webpack_require__(/*! ./modules/es7.map.to-json */ \"./node_modules/core-js/modules/es7.map.to-json.js\");\n__webpack_require__(/*! ./modules/es7.set.to-json */ \"./node_modules/core-js/modules/es7.set.to-json.js\");\n__webpack_require__(/*! ./modules/es7.map.of */ \"./node_modules/core-js/modules/es7.map.of.js\");\n__webpack_require__(/*! ./modules/es7.set.of */ \"./node_modules/core-js/modules/es7.set.of.js\");\n__webpack_require__(/*! ./modules/es7.weak-map.of */ \"./node_modules/core-js/modules/es7.weak-map.of.js\");\n__webpack_require__(/*! ./modules/es7.weak-set.of */ \"./node_modules/core-js/modules/es7.weak-set.of.js\");\n__webpack_require__(/*! ./modules/es7.map.from */ \"./node_modules/core-js/modules/es7.map.from.js\");\n__webpack_require__(/*! ./modules/es7.set.from */ \"./node_modules/core-js/modules/es7.set.from.js\");\n__webpack_require__(/*! ./modules/es7.weak-map.from */ \"./node_modules/core-js/modules/es7.weak-map.from.js\");\n__webpack_require__(/*! ./modules/es7.weak-set.from */ \"./node_modules/core-js/modules/es7.weak-set.from.js\");\n__webpack_require__(/*! ./modules/es7.global */ \"./node_modules/core-js/modules/es7.global.js\");\n__webpack_require__(/*! ./modules/es7.system.global */ \"./node_modules/core-js/modules/es7.system.global.js\");\n__webpack_require__(/*! ./modules/es7.error.is-error */ \"./node_modules/core-js/modules/es7.error.is-error.js\");\n__webpack_require__(/*! ./modules/es7.math.clamp */ \"./node_modules/core-js/modules/es7.math.clamp.js\");\n__webpack_require__(/*! ./modules/es7.math.deg-per-rad */ \"./node_modules/core-js/modules/es7.math.deg-per-rad.js\");\n__webpack_require__(/*! ./modules/es7.math.degrees */ \"./node_modules/core-js/modules/es7.math.degrees.js\");\n__webpack_require__(/*! ./modules/es7.math.fscale */ \"./node_modules/core-js/modules/es7.math.fscale.js\");\n__webpack_require__(/*! ./modules/es7.math.iaddh */ \"./node_modules/core-js/modules/es7.math.iaddh.js\");\n__webpack_require__(/*! ./modules/es7.math.isubh */ \"./node_modules/core-js/modules/es7.math.isubh.js\");\n__webpack_require__(/*! ./modules/es7.math.imulh */ \"./node_modules/core-js/modules/es7.math.imulh.js\");\n__webpack_require__(/*! ./modules/es7.math.rad-per-deg */ \"./node_modules/core-js/modules/es7.math.rad-per-deg.js\");\n__webpack_require__(/*! ./modules/es7.math.radians */ \"./node_modules/core-js/modules/es7.math.radians.js\");\n__webpack_require__(/*! ./modules/es7.math.scale */ \"./node_modules/core-js/modules/es7.math.scale.js\");\n__webpack_require__(/*! ./modules/es7.math.umulh */ \"./node_modules/core-js/modules/es7.math.umulh.js\");\n__webpack_require__(/*! ./modules/es7.math.signbit */ \"./node_modules/core-js/modules/es7.math.signbit.js\");\n__webpack_require__(/*! ./modules/es7.promise.finally */ \"./node_modules/core-js/modules/es7.promise.finally.js\");\n__webpack_require__(/*! ./modules/es7.promise.try */ \"./node_modules/core-js/modules/es7.promise.try.js\");\n__webpack_require__(/*! ./modules/es7.reflect.define-metadata */ \"./node_modules/core-js/modules/es7.reflect.define-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.delete-metadata */ \"./node_modules/core-js/modules/es7.reflect.delete-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.get-metadata */ \"./node_modules/core-js/modules/es7.reflect.get-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.get-metadata-keys */ \"./node_modules/core-js/modules/es7.reflect.get-metadata-keys.js\");\n__webpack_require__(/*! ./modules/es7.reflect.get-own-metadata */ \"./node_modules/core-js/modules/es7.reflect.get-own-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.get-own-metadata-keys */ \"./node_modules/core-js/modules/es7.reflect.get-own-metadata-keys.js\");\n__webpack_require__(/*! ./modules/es7.reflect.has-metadata */ \"./node_modules/core-js/modules/es7.reflect.has-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.has-own-metadata */ \"./node_modules/core-js/modules/es7.reflect.has-own-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.metadata */ \"./node_modules/core-js/modules/es7.reflect.metadata.js\");\n__webpack_require__(/*! ./modules/es7.asap */ \"./node_modules/core-js/modules/es7.asap.js\");\n__webpack_require__(/*! ./modules/es7.observable */ \"./node_modules/core-js/modules/es7.observable.js\");\n__webpack_require__(/*! ./modules/web.timers */ \"./node_modules/core-js/modules/web.timers.js\");\n__webpack_require__(/*! ./modules/web.immediate */ \"./node_modules/core-js/modules/web.immediate.js\");\n__webpack_require__(/*! ./modules/web.dom.iterable */ \"./node_modules/core-js/modules/web.dom.iterable.js\");\nmodule.exports = __webpack_require__(/*! ./modules/_core */ \"./node_modules/core-js/modules/_core.js\");\n\n\n/***/ }),\n\n/***/ \"./node_modules/ieee754/index.js\":\n/*!***************************************!*\\\n  !*** ./node_modules/ieee754/index.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.read = function (buffer, offset, isLE, mLen, nBytes) {\n  var e, m\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var nBits = -7\n  var i = isLE ? (nBytes - 1) : 0\n  var d = isLE ? -1 : 1\n  var s = buffer[offset + i]\n\n  i += d\n\n  e = s & ((1 << (-nBits)) - 1)\n  s >>= (-nBits)\n  nBits += eLen\n  for (; nBits > 0; e = (e * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  m = e & ((1 << (-nBits)) - 1)\n  e >>= (-nBits)\n  nBits += mLen\n  for (; nBits > 0; m = (m * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  if (e === 0) {\n    e = 1 - eBias\n  } else if (e === eMax) {\n    return m ? NaN : ((s ? -1 : 1) * Infinity)\n  } else {\n    m = m + Math.pow(2, mLen)\n    e = e - eBias\n  }\n  return (s ? -1 : 1) * m * Math.pow(2, e - mLen)\n}\n\nexports.write = function (buffer, value, offset, isLE, mLen, nBytes) {\n  var e, m, c\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var rt = (mLen === 23 ? Math.pow(2, -24) - Math.pow(2, -77) : 0)\n  var i = isLE ? 0 : (nBytes - 1)\n  var d = isLE ? 1 : -1\n  var s = value < 0 || (value === 0 && 1 / value < 0) ? 1 : 0\n\n  value = Math.abs(value)\n\n  if (isNaN(value) || value === Infinity) {\n    m = isNaN(value) ? 1 : 0\n    e = eMax\n  } else {\n    e = Math.floor(Math.log(value) / Math.LN2)\n    if (value * (c = Math.pow(2, -e)) < 1) {\n      e--\n      c *= 2\n    }\n    if (e + eBias >= 1) {\n      value += rt / c\n    } else {\n      value += rt * Math.pow(2, 1 - eBias)\n    }\n    if (value * c >= 2) {\n      e++\n      c /= 2\n    }\n\n    if (e + eBias >= eMax) {\n      m = 0\n      e = eMax\n    } else if (e + eBias >= 1) {\n      m = ((value * c) - 1) * Math.pow(2, mLen)\n      e = e + eBias\n    } else {\n      m = value * Math.pow(2, eBias - 1) * Math.pow(2, mLen)\n      e = 0\n    }\n  }\n\n  for (; mLen >= 8; buffer[offset + i] = m & 0xff, i += d, m /= 256, mLen -= 8) {}\n\n  e = (e << mLen) | m\n  eLen += mLen\n  for (; eLen > 0; buffer[offset + i] = e & 0xff, i += d, e /= 256, eLen -= 8) {}\n\n  buffer[offset + i - d] |= s * 128\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/lib/bytesToUuid.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/uuid/lib/bytesToUuid.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n/**\n * Convert array of 16 byte values to UUID string format of the form:\n * XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX\n */\nvar byteToHex = [];\nfor (var i = 0; i < 256; ++i) {\n  byteToHex[i] = (i + 0x100).toString(16).substr(1);\n}\n\nfunction bytesToUuid(buf, offset) {\n  var i = offset || 0;\n  var bth = byteToHex;\n  // join used to fix memory issue caused by concatenation: https://bugs.chromium.org/p/v8/issues/detail?id=3175#c4\n  return ([bth[buf[i++]], bth[buf[i++]], \n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]]]).join('');\n}\n\nmodule.exports = bytesToUuid;\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/lib/rng-browser.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/uuid/lib/rng-browser.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// Unique ID creation requires a high quality random # generator.  In the\n// browser this is a little complicated due to unknown quality of Math.random()\n// and inconsistent support for the `crypto` API.  We do the best we can via\n// feature-detection\n\n// getRandomValues needs to be invoked in a context where \"this\" is a Crypto\n// implementation. Also, find the complete implementation of crypto on IE11.\nvar getRandomValues = (typeof(crypto) != 'undefined' && crypto.getRandomValues && crypto.getRandomValues.bind(crypto)) ||\n                      (typeof(msCrypto) != 'undefined' && typeof window.msCrypto.getRandomValues == 'function' && msCrypto.getRandomValues.bind(msCrypto));\n\nif (getRandomValues) {\n  // WHATWG crypto RNG - http://wiki.whatwg.org/wiki/Crypto\n  var rnds8 = new Uint8Array(16); // eslint-disable-line no-undef\n\n  module.exports = function whatwgRNG() {\n    getRandomValues(rnds8);\n    return rnds8;\n  };\n} else {\n  // Math.random()-based (RNG)\n  //\n  // If all else fails, use Math.random().  It's fast, but is of unspecified\n  // quality.\n  var rnds = new Array(16);\n\n  module.exports = function mathRNG() {\n    for (var i = 0, r; i < 16; i++) {\n      if ((i & 0x03) === 0) r = Math.random() * 0x100000000;\n      rnds[i] = r >>> ((i & 0x03) << 3) & 0xff;\n    }\n\n    return rnds;\n  };\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/v4.js\":\n/*!*********************************!*\\\n  !*** ./node_modules/uuid/v4.js ***!\n  \\*********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar rng = __webpack_require__(/*! ./lib/rng */ \"./node_modules/uuid/lib/rng-browser.js\");\nvar bytesToUuid = __webpack_require__(/*! ./lib/bytesToUuid */ \"./node_modules/uuid/lib/bytesToUuid.js\");\n\nfunction v4(options, buf, offset) {\n  var i = buf && offset || 0;\n\n  if (typeof(options) == 'string') {\n    buf = options === 'binary' ? new Array(16) : null;\n    options = null;\n  }\n  options = options || {};\n\n  var rnds = options.random || (options.rng || rng)();\n\n  // Per 4.4, set bits for version and `clock_seq_hi_and_reserved`\n  rnds[6] = (rnds[6] & 0x0f) | 0x40;\n  rnds[8] = (rnds[8] & 0x3f) | 0x80;\n\n  // Copy bytes to buffer, if provided\n  if (buf) {\n    for (var ii = 0; ii < 16; ++ii) {\n      buf[i + ii] = rnds[ii];\n    }\n  }\n\n  return buf || bytesToUuid(rnds);\n}\n\nmodule.exports = v4;\n\n\n/***/ }),\n\n/***/ \"./node_modules/webpack/buildin/global.js\":\n/*!***********************************!*\\\n  !*** (webpack)/buildin/global.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar g;\n\n// This works in non-strict mode\ng = (function() {\n\treturn this;\n})();\n\ntry {\n\t// This works if eval is allowed (see CSP)\n\tg = g || new Function(\"return this\")();\n} catch (e) {\n\t// This works if the window reference is available\n\tif (typeof window === \"object\") g = window;\n}\n\n// g can still be undefined, but nothing to do about it...\n// We return undefined, instead of nothing here, so it's\n// easier to handle this case. if(!global) { ...}\n\nmodule.exports = g;\n\n\n/***/ }),\n\n/***/ \"./src/AccessTokenEvents.js\":\n/*!**********************************!*\\\n  !*** ./src/AccessTokenEvents.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.AccessTokenEvents = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Timer = __webpack_require__(/*! ./Timer.js */ \"./src/Timer.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultAccessTokenExpiringNotificationTime = 60; // seconds\n\nvar AccessTokenEvents = exports.AccessTokenEvents = function () {\n    function AccessTokenEvents() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            _ref$accessTokenExpir = _ref.accessTokenExpiringNotificationTime,\n            accessTokenExpiringNotificationTime = _ref$accessTokenExpir === undefined ? DefaultAccessTokenExpiringNotificationTime : _ref$accessTokenExpir,\n            _ref$accessTokenExpir2 = _ref.accessTokenExpiringTimer,\n            accessTokenExpiringTimer = _ref$accessTokenExpir2 === undefined ? new _Timer.Timer(\"Access token expiring\") : _ref$accessTokenExpir2,\n            _ref$accessTokenExpir3 = _ref.accessTokenExpiredTimer,\n            accessTokenExpiredTimer = _ref$accessTokenExpir3 === undefined ? new _Timer.Timer(\"Access token expired\") : _ref$accessTokenExpir3;\n\n        _classCallCheck(this, AccessTokenEvents);\n\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\n\n        this._accessTokenExpiring = accessTokenExpiringTimer;\n        this._accessTokenExpired = accessTokenExpiredTimer;\n    }\n\n    AccessTokenEvents.prototype.load = function load(container) {\n        // only register events if there's an access token and it has an expiration\n        if (container.access_token && container.expires_in !== undefined) {\n            var duration = container.expires_in;\n            _Log.Log.debug(\"AccessTokenEvents.load: access token present, remaining duration:\", duration);\n\n            if (duration > 0) {\n                // only register expiring if we still have time\n                var expiring = duration - this._accessTokenExpiringNotificationTime;\n                if (expiring <= 0) {\n                    expiring = 1;\n                }\n\n                _Log.Log.debug(\"AccessTokenEvents.load: registering expiring timer in:\", expiring);\n                this._accessTokenExpiring.init(expiring);\n            } else {\n                _Log.Log.debug(\"AccessTokenEvents.load: canceling existing expiring timer becase we're past expiration.\");\n                this._accessTokenExpiring.cancel();\n            }\n\n            // if it's negative, it will still fire\n            var expired = duration + 1;\n            _Log.Log.debug(\"AccessTokenEvents.load: registering expired timer in:\", expired);\n            this._accessTokenExpired.init(expired);\n        } else {\n            this._accessTokenExpiring.cancel();\n            this._accessTokenExpired.cancel();\n        }\n    };\n\n    AccessTokenEvents.prototype.unload = function unload() {\n        _Log.Log.debug(\"AccessTokenEvents.unload: canceling existing access token timers\");\n        this._accessTokenExpiring.cancel();\n        this._accessTokenExpired.cancel();\n    };\n\n    AccessTokenEvents.prototype.addAccessTokenExpiring = function addAccessTokenExpiring(cb) {\n        this._accessTokenExpiring.addHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.removeAccessTokenExpiring = function removeAccessTokenExpiring(cb) {\n        this._accessTokenExpiring.removeHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.addAccessTokenExpired = function addAccessTokenExpired(cb) {\n        this._accessTokenExpired.addHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.removeAccessTokenExpired = function removeAccessTokenExpired(cb) {\n        this._accessTokenExpired.removeHandler(cb);\n    };\n\n    return AccessTokenEvents;\n}();\n\n/***/ }),\n\n/***/ \"./src/CheckSessionIFrame.js\":\n/*!***********************************!*\\\n  !*** ./src/CheckSessionIFrame.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CheckSessionIFrame = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultInterval = 2000;\n\nvar CheckSessionIFrame = exports.CheckSessionIFrame = function () {\n    function CheckSessionIFrame(callback, client_id, url, interval) {\n        var stopOnError = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : true;\n\n        _classCallCheck(this, CheckSessionIFrame);\n\n        this._callback = callback;\n        this._client_id = client_id;\n        this._url = url;\n        this._interval = interval || DefaultInterval;\n        this._stopOnError = stopOnError;\n\n        var idx = url.indexOf(\"/\", url.indexOf(\"//\") + 2);\n        this._frame_origin = url.substr(0, idx);\n\n        this._frame = window.document.createElement(\"iframe\");\n\n        // shotgun approach\n        this._frame.style.visibility = \"hidden\";\n        this._frame.style.position = \"absolute\";\n        this._frame.style.display = \"none\";\n        this._frame.style.width = 0;\n        this._frame.style.height = 0;\n\n        this._frame.src = url;\n    }\n\n    CheckSessionIFrame.prototype.load = function load() {\n        var _this = this;\n\n        return new Promise(function (resolve) {\n            _this._frame.onload = function () {\n                resolve();\n            };\n\n            window.document.body.appendChild(_this._frame);\n            _this._boundMessageEvent = _this._message.bind(_this);\n            window.addEventListener(\"message\", _this._boundMessageEvent, false);\n        });\n    };\n\n    CheckSessionIFrame.prototype._message = function _message(e) {\n        if (e.origin === this._frame_origin && e.source === this._frame.contentWindow) {\n            if (e.data === \"error\") {\n                _Log.Log.error(\"CheckSessionIFrame: error message from check session op iframe\");\n                if (this._stopOnError) {\n                    this.stop();\n                }\n            } else if (e.data === \"changed\") {\n                _Log.Log.debug(\"CheckSessionIFrame: changed message from check session op iframe\");\n                this.stop();\n                this._callback();\n            } else {\n                _Log.Log.debug(\"CheckSessionIFrame: \" + e.data + \" message from check session op iframe\");\n            }\n        }\n    };\n\n    CheckSessionIFrame.prototype.start = function start(session_state) {\n        var _this2 = this;\n\n        if (this._session_state !== session_state) {\n            _Log.Log.debug(\"CheckSessionIFrame.start\");\n\n            this.stop();\n\n            this._session_state = session_state;\n\n            var send = function send() {\n                _this2._frame.contentWindow.postMessage(_this2._client_id + \" \" + _this2._session_state, _this2._frame_origin);\n            };\n\n            // trigger now\n            send();\n\n            // and setup timer\n            this._timer = window.setInterval(send, this._interval);\n        }\n    };\n\n    CheckSessionIFrame.prototype.stop = function stop() {\n        this._session_state = null;\n\n        if (this._timer) {\n            _Log.Log.debug(\"CheckSessionIFrame.stop\");\n\n            window.clearInterval(this._timer);\n            this._timer = null;\n        }\n    };\n\n    return CheckSessionIFrame;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaIFrameNavigator.js\":\n/*!***************************************!*\\\n  !*** ./src/CordovaIFrameNavigator.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaIFrameNavigator = undefined;\n\nvar _CordovaPopupWindow = __webpack_require__(/*! ./CordovaPopupWindow.js */ \"./src/CordovaPopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar CordovaIFrameNavigator = exports.CordovaIFrameNavigator = function () {\n    function CordovaIFrameNavigator() {\n        _classCallCheck(this, CordovaIFrameNavigator);\n    }\n\n    CordovaIFrameNavigator.prototype.prepare = function prepare(params) {\n        params.popupWindowFeatures = 'hidden=yes';\n        var popup = new _CordovaPopupWindow.CordovaPopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    return CordovaIFrameNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaPopupNavigator.js\":\n/*!**************************************!*\\\n  !*** ./src/CordovaPopupNavigator.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaPopupNavigator = undefined;\n\nvar _CordovaPopupWindow = __webpack_require__(/*! ./CordovaPopupWindow.js */ \"./src/CordovaPopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar CordovaPopupNavigator = exports.CordovaPopupNavigator = function () {\n    function CordovaPopupNavigator() {\n        _classCallCheck(this, CordovaPopupNavigator);\n    }\n\n    CordovaPopupNavigator.prototype.prepare = function prepare(params) {\n        var popup = new _CordovaPopupWindow.CordovaPopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    return CordovaPopupNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaPopupWindow.js\":\n/*!***********************************!*\\\n  !*** ./src/CordovaPopupWindow.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaPopupWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar DefaultPopupFeatures = 'location=no,toolbar=no,zoom=no';\nvar DefaultPopupTarget = \"_blank\";\n\nvar CordovaPopupWindow = exports.CordovaPopupWindow = function () {\n    function CordovaPopupWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, CordovaPopupWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        this.features = params.popupWindowFeatures || DefaultPopupFeatures;\n        this.target = params.popupWindowTarget || DefaultPopupTarget;\n\n        this.redirect_uri = params.startUrl;\n        _Log.Log.debug(\"CordovaPopupWindow.ctor: redirect_uri: \" + this.redirect_uri);\n    }\n\n    CordovaPopupWindow.prototype._isInAppBrowserInstalled = function _isInAppBrowserInstalled(cordovaMetadata) {\n        return [\"cordova-plugin-inappbrowser\", \"cordova-plugin-inappbrowser.inappbrowser\", \"org.apache.cordova.inappbrowser\"].some(function (name) {\n            return cordovaMetadata.hasOwnProperty(name);\n        });\n    };\n\n    CordovaPopupWindow.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            this._error(\"No url provided\");\n        } else {\n            if (!window.cordova) {\n                return this._error(\"cordova is undefined\");\n            }\n\n            var cordovaMetadata = window.cordova.require(\"cordova/plugin_list\").metadata;\n            if (this._isInAppBrowserInstalled(cordovaMetadata) === false) {\n                return this._error(\"InAppBrowser plugin not found\");\n            }\n            this._popup = cordova.InAppBrowser.open(params.url, this.target, this.features);\n            if (this._popup) {\n                _Log.Log.debug(\"CordovaPopupWindow.navigate: popup successfully created\");\n\n                this._exitCallbackEvent = this._exitCallback.bind(this);\n                this._loadStartCallbackEvent = this._loadStartCallback.bind(this);\n\n                this._popup.addEventListener(\"exit\", this._exitCallbackEvent, false);\n                this._popup.addEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\n            } else {\n                this._error(\"Error opening popup window\");\n            }\n        }\n        return this.promise;\n    };\n\n    CordovaPopupWindow.prototype._loadStartCallback = function _loadStartCallback(event) {\n        if (event.url.indexOf(this.redirect_uri) === 0) {\n            this._success({ url: event.url });\n        }\n    };\n\n    CordovaPopupWindow.prototype._exitCallback = function _exitCallback(message) {\n        this._error(message);\n    };\n\n    CordovaPopupWindow.prototype._success = function _success(data) {\n        this._cleanup();\n\n        _Log.Log.debug(\"CordovaPopupWindow: Successful response from cordova popup window\");\n        this._resolve(data);\n    };\n\n    CordovaPopupWindow.prototype._error = function _error(message) {\n        this._cleanup();\n\n        _Log.Log.error(message);\n        this._reject(new Error(message));\n    };\n\n    CordovaPopupWindow.prototype.close = function close() {\n        this._cleanup();\n    };\n\n    CordovaPopupWindow.prototype._cleanup = function _cleanup() {\n        if (this._popup) {\n            _Log.Log.debug(\"CordovaPopupWindow: cleaning up popup\");\n            this._popup.removeEventListener(\"exit\", this._exitCallbackEvent, false);\n            this._popup.removeEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\n            this._popup.close();\n        }\n        this._popup = null;\n    };\n\n    _createClass(CordovaPopupWindow, [{\n        key: 'promise',\n        get: function get() {\n            return this._promise;\n        }\n    }]);\n\n    return CordovaPopupWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/ErrorResponse.js\":\n/*!******************************!*\\\n  !*** ./src/ErrorResponse.js ***!\n  \\******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n        value: true\n});\nexports.ErrorResponse = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar ErrorResponse = exports.ErrorResponse = function (_Error) {\n        _inherits(ErrorResponse, _Error);\n\n        function ErrorResponse() {\n                var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n                    error = _ref.error,\n                    error_description = _ref.error_description,\n                    error_uri = _ref.error_uri,\n                    state = _ref.state,\n                    session_state = _ref.session_state;\n\n                _classCallCheck(this, ErrorResponse);\n\n                if (!error) {\n                        _Log.Log.error(\"No error passed to ErrorResponse\");\n                        throw new Error(\"error\");\n                }\n\n                var _this = _possibleConstructorReturn(this, _Error.call(this, error_description || error));\n\n                _this.name = \"ErrorResponse\";\n\n                _this.error = error;\n                _this.error_description = error_description;\n                _this.error_uri = error_uri;\n\n                _this.state = state;\n                _this.session_state = session_state;\n                return _this;\n        }\n\n        return ErrorResponse;\n}(Error);\n\n/***/ }),\n\n/***/ \"./src/Event.js\":\n/*!**********************!*\\\n  !*** ./src/Event.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.Event = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar Event = exports.Event = function () {\n    function Event(name) {\n        _classCallCheck(this, Event);\n\n        this._name = name;\n        this._callbacks = [];\n    }\n\n    Event.prototype.addHandler = function addHandler(cb) {\n        this._callbacks.push(cb);\n    };\n\n    Event.prototype.removeHandler = function removeHandler(cb) {\n        var idx = this._callbacks.findIndex(function (item) {\n            return item === cb;\n        });\n        if (idx >= 0) {\n            this._callbacks.splice(idx, 1);\n        }\n    };\n\n    Event.prototype.raise = function raise() {\n        _Log.Log.debug(\"Event: Raising event: \" + this._name);\n        for (var i = 0; i < this._callbacks.length; i++) {\n            var _callbacks;\n\n            (_callbacks = this._callbacks)[i].apply(_callbacks, arguments);\n        }\n    };\n\n    return Event;\n}();\n\n/***/ }),\n\n/***/ \"./src/Global.js\":\n/*!***********************!*\\\n  !*** ./src/Global.js ***!\n  \\***********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar timer = {\n    setInterval: function (_setInterval) {\n        function setInterval(_x, _x2) {\n            return _setInterval.apply(this, arguments);\n        }\n\n        setInterval.toString = function () {\n            return _setInterval.toString();\n        };\n\n        return setInterval;\n    }(function (cb, duration) {\n        return setInterval(cb, duration);\n    }),\n    clearInterval: function (_clearInterval) {\n        function clearInterval(_x3) {\n            return _clearInterval.apply(this, arguments);\n        }\n\n        clearInterval.toString = function () {\n            return _clearInterval.toString();\n        };\n\n        return clearInterval;\n    }(function (handle) {\n        return clearInterval(handle);\n    })\n};\n\nvar testing = false;\nvar request = null;\n\nvar Global = exports.Global = function () {\n    function Global() {\n        _classCallCheck(this, Global);\n    }\n\n    Global._testing = function _testing() {\n        testing = true;\n    };\n\n    Global.setXMLHttpRequest = function setXMLHttpRequest(newRequest) {\n        request = newRequest;\n    };\n\n    _createClass(Global, null, [{\n        key: 'location',\n        get: function get() {\n            if (!testing) {\n                return location;\n            }\n        }\n    }, {\n        key: 'localStorage',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return localStorage;\n            }\n        }\n    }, {\n        key: 'sessionStorage',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return sessionStorage;\n            }\n        }\n    }, {\n        key: 'XMLHttpRequest',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return request || XMLHttpRequest;\n            }\n        }\n    }, {\n        key: 'timer',\n        get: function get() {\n            if (!testing) {\n                return timer;\n            }\n        }\n    }]);\n\n    return Global;\n}();\n\n/***/ }),\n\n/***/ \"./src/IFrameNavigator.js\":\n/*!********************************!*\\\n  !*** ./src/IFrameNavigator.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.IFrameNavigator = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _IFrameWindow = __webpack_require__(/*! ./IFrameWindow.js */ \"./src/IFrameWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar IFrameNavigator = exports.IFrameNavigator = function () {\n    function IFrameNavigator() {\n        _classCallCheck(this, IFrameNavigator);\n    }\n\n    IFrameNavigator.prototype.prepare = function prepare(params) {\n        var frame = new _IFrameWindow.IFrameWindow(params);\n        return Promise.resolve(frame);\n    };\n\n    IFrameNavigator.prototype.callback = function callback(url) {\n        _Log.Log.debug(\"IFrameNavigator.callback\");\n\n        try {\n            _IFrameWindow.IFrameWindow.notifyParent(url);\n            return Promise.resolve();\n        } catch (e) {\n            return Promise.reject(e);\n        }\n    };\n\n    return IFrameNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/IFrameWindow.js\":\n/*!*****************************!*\\\n  !*** ./src/IFrameWindow.js ***!\n  \\*****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.IFrameWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar DefaultTimeout = 10000;\n\nvar IFrameWindow = exports.IFrameWindow = function () {\n    function IFrameWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, IFrameWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        this._boundMessageEvent = this._message.bind(this);\n        window.addEventListener(\"message\", this._boundMessageEvent, false);\n\n        this._frame = window.document.createElement(\"iframe\");\n\n        // shotgun approach\n        this._frame.style.visibility = \"hidden\";\n        this._frame.style.position = \"absolute\";\n        this._frame.style.display = \"none\";\n        this._frame.style.width = 0;\n        this._frame.style.height = 0;\n\n        window.document.body.appendChild(this._frame);\n    }\n\n    IFrameWindow.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            this._error(\"No url provided\");\n        } else {\n            var timeout = params.silentRequestTimeout || DefaultTimeout;\n            _Log.Log.debug(\"IFrameWindow.navigate: Using timeout of:\", timeout);\n            this._timer = window.setTimeout(this._timeout.bind(this), timeout);\n            this._frame.src = params.url;\n        }\n\n        return this.promise;\n    };\n\n    IFrameWindow.prototype._success = function _success(data) {\n        this._cleanup();\n\n        _Log.Log.debug(\"IFrameWindow: Successful response from frame window\");\n        this._resolve(data);\n    };\n\n    IFrameWindow.prototype._error = function _error(message) {\n        this._cleanup();\n\n        _Log.Log.error(message);\n        this._reject(new Error(message));\n    };\n\n    IFrameWindow.prototype.close = function close() {\n        this._cleanup();\n    };\n\n    IFrameWindow.prototype._cleanup = function _cleanup() {\n        if (this._frame) {\n            _Log.Log.debug(\"IFrameWindow: cleanup\");\n\n            window.removeEventListener(\"message\", this._boundMessageEvent, false);\n            window.clearTimeout(this._timer);\n            window.document.body.removeChild(this._frame);\n\n            this._timer = null;\n            this._frame = null;\n            this._boundMessageEvent = null;\n        }\n    };\n\n    IFrameWindow.prototype._timeout = function _timeout() {\n        _Log.Log.debug(\"IFrameWindow.timeout\");\n        this._error(\"Frame window timed out\");\n    };\n\n    IFrameWindow.prototype._message = function _message(e) {\n        _Log.Log.debug(\"IFrameWindow.message\");\n\n        if (this._timer && e.origin === this._origin && e.source === this._frame.contentWindow) {\n            var url = e.data;\n            if (url) {\n                this._success({ url: url });\n            } else {\n                this._error(\"Invalid response from frame\");\n            }\n        }\n    };\n\n    IFrameWindow.notifyParent = function notifyParent(url) {\n        _Log.Log.debug(\"IFrameWindow.notifyParent\");\n        if (window.frameElement) {\n            url = url || window.location.href;\n            if (url) {\n                _Log.Log.debug(\"IFrameWindow.notifyParent: posting url message to parent\");\n                window.parent.postMessage(url, location.protocol + \"//\" + location.host);\n            }\n        }\n    };\n\n    _createClass(IFrameWindow, [{\n        key: \"promise\",\n        get: function get() {\n            return this._promise;\n        }\n    }, {\n        key: \"_origin\",\n        get: function get() {\n            return location.protocol + \"//\" + location.host;\n        }\n    }]);\n\n    return IFrameWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/InMemoryWebStorage.js\":\n/*!***********************************!*\\\n  !*** ./src/InMemoryWebStorage.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.InMemoryWebStorage = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar InMemoryWebStorage = exports.InMemoryWebStorage = function () {\n    function InMemoryWebStorage() {\n        _classCallCheck(this, InMemoryWebStorage);\n\n        this._data = {};\n    }\n\n    InMemoryWebStorage.prototype.getItem = function getItem(key) {\n        _Log.Log.debug(\"InMemoryWebStorage.getItem\", key);\n        return this._data[key];\n    };\n\n    InMemoryWebStorage.prototype.setItem = function setItem(key, value) {\n        _Log.Log.debug(\"InMemoryWebStorage.setItem\", key);\n        this._data[key] = value;\n    };\n\n    InMemoryWebStorage.prototype.removeItem = function removeItem(key) {\n        _Log.Log.debug(\"InMemoryWebStorage.removeItem\", key);\n        delete this._data[key];\n    };\n\n    InMemoryWebStorage.prototype.key = function key(index) {\n        return Object.getOwnPropertyNames(this._data)[index];\n    };\n\n    _createClass(InMemoryWebStorage, [{\n        key: \"length\",\n        get: function get() {\n            return Object.getOwnPropertyNames(this._data).length;\n        }\n    }]);\n\n    return InMemoryWebStorage;\n}();\n\n/***/ }),\n\n/***/ \"./src/JoseUtil.js\":\n/*!*************************!*\\\n  !*** ./src/JoseUtil.js ***!\n  \\*************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nexports.JoseUtil = undefined;\n\nvar _jsrsasign = __webpack_require__(/*! ./crypto/jsrsasign */ \"./src/crypto/jsrsasign.js\");\n\nvar _JoseUtilImpl = __webpack_require__(/*! ./JoseUtilImpl */ \"./src/JoseUtilImpl.js\");\n\nvar _JoseUtilImpl2 = _interopRequireDefault(_JoseUtilImpl);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nvar JoseUtil = exports.JoseUtil = (0, _JoseUtilImpl2.default)({ jws: _jsrsasign.jws, KeyUtil: _jsrsasign.KeyUtil, X509: _jsrsasign.X509, crypto: _jsrsasign.crypto, hextob64u: _jsrsasign.hextob64u, b64tohex: _jsrsasign.b64tohex, AllowedSigningAlgs: _jsrsasign.AllowedSigningAlgs });\n\n/***/ }),\n\n/***/ \"./src/JoseUtilImpl.js\":\n/*!*****************************!*\\\n  !*** ./src/JoseUtilImpl.js ***!\n  \\*****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.default = getJoseUtil;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nfunction getJoseUtil(_ref) {\n    var jws = _ref.jws,\n        KeyUtil = _ref.KeyUtil,\n        X509 = _ref.X509,\n        crypto = _ref.crypto,\n        hextob64u = _ref.hextob64u,\n        b64tohex = _ref.b64tohex,\n        AllowedSigningAlgs = _ref.AllowedSigningAlgs;\n\n    return function () {\n        function JoseUtil() {\n            _classCallCheck(this, JoseUtil);\n        }\n\n        JoseUtil.parseJwt = function parseJwt(jwt) {\n            _Log.Log.debug(\"JoseUtil.parseJwt\");\n            try {\n                var token = jws.JWS.parse(jwt);\n                return {\n                    header: token.headerObj,\n                    payload: token.payloadObj\n                };\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        JoseUtil.validateJwt = function validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\n            _Log.Log.debug(\"JoseUtil.validateJwt\");\n\n            try {\n                if (key.kty === \"RSA\") {\n                    if (key.e && key.n) {\n                        key = KeyUtil.getKey(key);\n                    } else if (key.x5c && key.x5c.length) {\n                        var hex = b64tohex(key.x5c[0]);\n                        key = X509.getPublicKeyFromCertHex(hex);\n                    } else {\n                        _Log.Log.error(\"JoseUtil.validateJwt: RSA key missing key material\", key);\n                        return Promise.reject(new Error(\"RSA key missing key material\"));\n                    }\n                } else if (key.kty === \"EC\") {\n                    if (key.crv && key.x && key.y) {\n                        key = KeyUtil.getKey(key);\n                    } else {\n                        _Log.Log.error(\"JoseUtil.validateJwt: EC key missing key material\", key);\n                        return Promise.reject(new Error(\"EC key missing key material\"));\n                    }\n                } else {\n                    _Log.Log.error(\"JoseUtil.validateJwt: Unsupported key type\", key && key.kty);\n                    return Promise.reject(new Error( true && key.kty));\n                }\n\n                return JoseUtil._validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive);\n            } catch (e) {\n                _Log.Log.error(e && e.message || e);\n                return Promise.reject(\"JWT validation failed\");\n            }\n        };\n\n        JoseUtil.validateJwtAttributes = function validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive) {\n            if (!clockSkew) {\n                clockSkew = 0;\n            }\n\n            if (!now) {\n                now = parseInt(Date.now() / 1000);\n            }\n\n            var payload = JoseUtil.parseJwt(jwt).payload;\n\n            if (!payload.iss) {\n                _Log.Log.error(\"JoseUtil._validateJwt: issuer was not provided\");\n                return Promise.reject(new Error(\"issuer was not provided\"));\n            }\n            if (payload.iss !== issuer) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid issuer in token\", payload.iss);\n                return Promise.reject(new Error(\"Invalid issuer in token: \" + payload.iss));\n            }\n\n            if (!payload.aud) {\n                _Log.Log.error(\"JoseUtil._validateJwt: aud was not provided\");\n                return Promise.reject(new Error(\"aud was not provided\"));\n            }\n            var validAudience = payload.aud === audience || Array.isArray(payload.aud) && payload.aud.indexOf(audience) >= 0;\n            if (!validAudience) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid audience in token\", payload.aud);\n                return Promise.reject(new Error(\"Invalid audience in token: \" + payload.aud));\n            }\n            if (payload.azp && payload.azp !== audience) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid azp in token\", payload.azp);\n                return Promise.reject(new Error(\"Invalid azp in token: \" + payload.azp));\n            }\n\n            if (!timeInsensitive) {\n                var lowerNow = now + clockSkew;\n                var upperNow = now - clockSkew;\n\n                if (!payload.iat) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: iat was not provided\");\n                    return Promise.reject(new Error(\"iat was not provided\"));\n                }\n                if (lowerNow < payload.iat) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: iat is in the future\", payload.iat);\n                    return Promise.reject(new Error(\"iat is in the future: \" + payload.iat));\n                }\n\n                if (payload.nbf && lowerNow < payload.nbf) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: nbf is in the future\", payload.nbf);\n                    return Promise.reject(new Error(\"nbf is in the future: \" + payload.nbf));\n                }\n\n                if (!payload.exp) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: exp was not provided\");\n                    return Promise.reject(new Error(\"exp was not provided\"));\n                }\n                if (payload.exp < upperNow) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: exp is in the past\", payload.exp);\n                    return Promise.reject(new Error(\"exp is in the past:\" + payload.exp));\n                }\n            }\n\n            return Promise.resolve(payload);\n        };\n\n        JoseUtil._validateJwt = function _validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\n\n            return JoseUtil.validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive).then(function (payload) {\n                try {\n                    if (!jws.JWS.verify(jwt, key, AllowedSigningAlgs)) {\n                        _Log.Log.error(\"JoseUtil._validateJwt: signature validation failed\");\n                        return Promise.reject(new Error(\"signature validation failed\"));\n                    }\n\n                    return payload;\n                } catch (e) {\n                    _Log.Log.error(e && e.message || e);\n                    return Promise.reject(new Error(\"signature validation failed\"));\n                }\n            });\n        };\n\n        JoseUtil.hashString = function hashString(value, alg) {\n            try {\n                return crypto.Util.hashString(value, alg);\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        JoseUtil.hexToBase64Url = function hexToBase64Url(value) {\n            try {\n                return hextob64u(value);\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        return JoseUtil;\n    }();\n}\nmodule.exports = exports[\"default\"];\n\n/***/ }),\n\n/***/ \"./src/JsonService.js\":\n/*!****************************!*\\\n  !*** ./src/JsonService.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.JsonService = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar JsonService = exports.JsonService = function () {\n    function JsonService() {\n        var additionalContentTypes = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : null;\n        var XMLHttpRequestCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.XMLHttpRequest;\n        var jwtHandler = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : null;\n\n        _classCallCheck(this, JsonService);\n\n        if (additionalContentTypes && Array.isArray(additionalContentTypes)) {\n            this._contentTypes = additionalContentTypes.slice();\n        } else {\n            this._contentTypes = [];\n        }\n        this._contentTypes.push('application/json');\n        if (jwtHandler) {\n            this._contentTypes.push('application/jwt');\n        }\n\n        this._XMLHttpRequest = XMLHttpRequestCtor;\n        this._jwtHandler = jwtHandler;\n    }\n\n    JsonService.prototype.getJson = function getJson(url, token) {\n        var _this = this;\n\n        if (!url) {\n            _Log.Log.error(\"JsonService.getJson: No url passed\");\n            throw new Error(\"url\");\n        }\n\n        _Log.Log.debug(\"JsonService.getJson, url: \", url);\n\n        return new Promise(function (resolve, reject) {\n\n            var req = new _this._XMLHttpRequest();\n            req.open('GET', url);\n\n            var allowedContentTypes = _this._contentTypes;\n            var jwtHandler = _this._jwtHandler;\n\n            req.onload = function () {\n                _Log.Log.debug(\"JsonService.getJson: HTTP response received, status\", req.status);\n\n                if (req.status === 200) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found == \"application/jwt\") {\n                            jwtHandler(req).then(resolve, reject);\n                            return;\n                        }\n\n                        if (found) {\n                            try {\n                                resolve(JSON.parse(req.responseText));\n                                return;\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.getJson: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\n                } else {\n                    reject(Error(req.statusText + \" (\" + req.status + \")\"));\n                }\n            };\n\n            req.onerror = function () {\n                _Log.Log.error(\"JsonService.getJson: network error\");\n                reject(Error(\"Network Error\"));\n            };\n\n            if (token) {\n                _Log.Log.debug(\"JsonService.getJson: token passed, setting Authorization header\");\n                req.setRequestHeader(\"Authorization\", \"Bearer \" + token);\n            }\n\n            req.send();\n        });\n    };\n\n    JsonService.prototype.postForm = function postForm(url, payload) {\n        var _this2 = this;\n\n        if (!url) {\n            _Log.Log.error(\"JsonService.postForm: No url passed\");\n            throw new Error(\"url\");\n        }\n\n        _Log.Log.debug(\"JsonService.postForm, url: \", url);\n\n        return new Promise(function (resolve, reject) {\n\n            var req = new _this2._XMLHttpRequest();\n            req.open('POST', url);\n\n            var allowedContentTypes = _this2._contentTypes;\n\n            req.onload = function () {\n                _Log.Log.debug(\"JsonService.postForm: HTTP response received, status\", req.status);\n\n                if (req.status === 200) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found) {\n                            try {\n                                resolve(JSON.parse(req.responseText));\n                                return;\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\n                    return;\n                }\n\n                if (req.status === 400) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found) {\n                            try {\n                                var payload = JSON.parse(req.responseText);\n                                if (payload && payload.error) {\n                                    _Log.Log.error(\"JsonService.postForm: Error from server: \", payload.error);\n                                    reject(new Error(payload.error));\n                                    return;\n                                }\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n                }\n\n                reject(Error(req.statusText + \" (\" + req.status + \")\"));\n            };\n\n            req.onerror = function () {\n                _Log.Log.error(\"JsonService.postForm: network error\");\n                reject(Error(\"Network Error\"));\n            };\n\n            var body = \"\";\n            for (var key in payload) {\n\n                var value = payload[key];\n\n                if (value) {\n\n                    if (body.length > 0) {\n                        body += \"&\";\n                    }\n\n                    body += encodeURIComponent(key);\n                    body += \"=\";\n                    body += encodeURIComponent(value);\n                }\n            }\n\n            req.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\n            req.send(body);\n        });\n    };\n\n    return JsonService;\n}();\n\n/***/ }),\n\n/***/ \"./src/Log.js\":\n/*!********************!*\\\n  !*** ./src/Log.js ***!\n  \\********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar nopLogger = {\n    debug: function debug() {},\n    info: function info() {},\n    warn: function warn() {},\n    error: function error() {}\n};\n\nvar NONE = 0;\nvar ERROR = 1;\nvar WARN = 2;\nvar INFO = 3;\nvar DEBUG = 4;\n\nvar logger = void 0;\nvar level = void 0;\n\nvar Log = exports.Log = function () {\n    function Log() {\n        _classCallCheck(this, Log);\n    }\n\n    Log.reset = function reset() {\n        level = INFO;\n        logger = nopLogger;\n    };\n\n    Log.debug = function debug() {\n        if (level >= DEBUG) {\n            for (var _len = arguments.length, args = Array(_len), _key = 0; _key < _len; _key++) {\n                args[_key] = arguments[_key];\n            }\n\n            logger.debug.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.info = function info() {\n        if (level >= INFO) {\n            for (var _len2 = arguments.length, args = Array(_len2), _key2 = 0; _key2 < _len2; _key2++) {\n                args[_key2] = arguments[_key2];\n            }\n\n            logger.info.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.warn = function warn() {\n        if (level >= WARN) {\n            for (var _len3 = arguments.length, args = Array(_len3), _key3 = 0; _key3 < _len3; _key3++) {\n                args[_key3] = arguments[_key3];\n            }\n\n            logger.warn.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.error = function error() {\n        if (level >= ERROR) {\n            for (var _len4 = arguments.length, args = Array(_len4), _key4 = 0; _key4 < _len4; _key4++) {\n                args[_key4] = arguments[_key4];\n            }\n\n            logger.error.apply(logger, Array.from(args));\n        }\n    };\n\n    _createClass(Log, null, [{\n        key: \"NONE\",\n        get: function get() {\n            return NONE;\n        }\n    }, {\n        key: \"ERROR\",\n        get: function get() {\n            return ERROR;\n        }\n    }, {\n        key: \"WARN\",\n        get: function get() {\n            return WARN;\n        }\n    }, {\n        key: \"INFO\",\n        get: function get() {\n            return INFO;\n        }\n    }, {\n        key: \"DEBUG\",\n        get: function get() {\n            return DEBUG;\n        }\n    }, {\n        key: \"level\",\n        get: function get() {\n            return level;\n        },\n        set: function set(value) {\n            if (NONE <= value && value <= DEBUG) {\n                level = value;\n            } else {\n                throw new Error(\"Invalid log level\");\n            }\n        }\n    }, {\n        key: \"logger\",\n        get: function get() {\n            return logger;\n        },\n        set: function set(value) {\n            if (!value.debug && value.info) {\n                // just to stay backwards compat. can remove in 2.0\n                value.debug = value.info;\n            }\n\n            if (value.debug && value.info && value.warn && value.error) {\n                logger = value;\n            } else {\n                throw new Error(\"Invalid logger\");\n            }\n        }\n    }]);\n\n    return Log;\n}();\n\nLog.reset();\n\n/***/ }),\n\n/***/ \"./src/MetadataService.js\":\n/*!********************************!*\\\n  !*** ./src/MetadataService.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.MetadataService = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcMetadataUrlPath = '.well-known/openid-configuration';\n\nvar MetadataService = exports.MetadataService = function () {\n    function MetadataService(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n\n        _classCallCheck(this, MetadataService);\n\n        if (!settings) {\n            _Log.Log.error(\"MetadataService: No settings passed to MetadataService\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor(['application/jwk-set+json']);\n    }\n\n    MetadataService.prototype.getMetadata = function getMetadata() {\n        var _this = this;\n\n        if (this._settings.metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadata: Returning metadata from settings\");\n            return Promise.resolve(this._settings.metadata);\n        }\n\n        if (!this.metadataUrl) {\n            _Log.Log.error(\"MetadataService.getMetadata: No authority or metadataUrl configured on settings\");\n            return Promise.reject(new Error(\"No authority or metadataUrl configured on settings\"));\n        }\n\n        _Log.Log.debug(\"MetadataService.getMetadata: getting metadata from\", this.metadataUrl);\n\n        return this._jsonService.getJson(this.metadataUrl).then(function (metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadata: json received\");\n            _this._settings.metadata = metadata;\n            return metadata;\n        });\n    };\n\n    MetadataService.prototype.getIssuer = function getIssuer() {\n        return this._getMetadataProperty(\"issuer\");\n    };\n\n    MetadataService.prototype.getAuthorizationEndpoint = function getAuthorizationEndpoint() {\n        return this._getMetadataProperty(\"authorization_endpoint\");\n    };\n\n    MetadataService.prototype.getUserInfoEndpoint = function getUserInfoEndpoint() {\n        return this._getMetadataProperty(\"userinfo_endpoint\");\n    };\n\n    MetadataService.prototype.getTokenEndpoint = function getTokenEndpoint() {\n        var optional = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : true;\n\n        return this._getMetadataProperty(\"token_endpoint\", optional);\n    };\n\n    MetadataService.prototype.getCheckSessionIframe = function getCheckSessionIframe() {\n        return this._getMetadataProperty(\"check_session_iframe\", true);\n    };\n\n    MetadataService.prototype.getEndSessionEndpoint = function getEndSessionEndpoint() {\n        return this._getMetadataProperty(\"end_session_endpoint\", true);\n    };\n\n    MetadataService.prototype.getRevocationEndpoint = function getRevocationEndpoint() {\n        return this._getMetadataProperty(\"revocation_endpoint\", true);\n    };\n\n    MetadataService.prototype.getKeysEndpoint = function getKeysEndpoint() {\n        return this._getMetadataProperty(\"jwks_uri\", true);\n    };\n\n    MetadataService.prototype._getMetadataProperty = function _getMetadataProperty(name) {\n        var optional = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : false;\n\n        _Log.Log.debug(\"MetadataService.getMetadataProperty for: \" + name);\n\n        return this.getMetadata().then(function (metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadataProperty: metadata recieved\");\n\n            if (metadata[name] === undefined) {\n\n                if (optional === true) {\n                    _Log.Log.warn(\"MetadataService.getMetadataProperty: Metadata does not contain optional property \" + name);\n                    return undefined;\n                } else {\n                    _Log.Log.error(\"MetadataService.getMetadataProperty: Metadata does not contain property \" + name);\n                    throw new Error(\"Metadata does not contain property \" + name);\n                }\n            }\n\n            return metadata[name];\n        });\n    };\n\n    MetadataService.prototype.getSigningKeys = function getSigningKeys() {\n        var _this2 = this;\n\n        if (this._settings.signingKeys) {\n            _Log.Log.debug(\"MetadataService.getSigningKeys: Returning signingKeys from settings\");\n            return Promise.resolve(this._settings.signingKeys);\n        }\n\n        return this._getMetadataProperty(\"jwks_uri\").then(function (jwks_uri) {\n            _Log.Log.debug(\"MetadataService.getSigningKeys: jwks_uri received\", jwks_uri);\n\n            return _this2._jsonService.getJson(jwks_uri).then(function (keySet) {\n                _Log.Log.debug(\"MetadataService.getSigningKeys: key set received\", keySet);\n\n                if (!keySet.keys) {\n                    _Log.Log.error(\"MetadataService.getSigningKeys: Missing keys on keyset\");\n                    throw new Error(\"Missing keys on keyset\");\n                }\n\n                _this2._settings.signingKeys = keySet.keys;\n                return _this2._settings.signingKeys;\n            });\n        });\n    };\n\n    _createClass(MetadataService, [{\n        key: 'metadataUrl',\n        get: function get() {\n            if (!this._metadataUrl) {\n                if (this._settings.metadataUrl) {\n                    this._metadataUrl = this._settings.metadataUrl;\n                } else {\n                    this._metadataUrl = this._settings.authority;\n\n                    if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\n                        if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\n                            this._metadataUrl += '/';\n                        }\n                        this._metadataUrl += OidcMetadataUrlPath;\n                    }\n                }\n            }\n\n            return this._metadataUrl;\n        }\n    }]);\n\n    return MetadataService;\n}();\n\n/***/ }),\n\n/***/ \"./src/OidcClient.js\":\n/*!***************************!*\\\n  !*** ./src/OidcClient.js ***!\n  \\***************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.OidcClient = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClientSettings = __webpack_require__(/*! ./OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _ErrorResponse = __webpack_require__(/*! ./ErrorResponse.js */ \"./src/ErrorResponse.js\");\n\nvar _SigninRequest = __webpack_require__(/*! ./SigninRequest.js */ \"./src/SigninRequest.js\");\n\nvar _SigninResponse = __webpack_require__(/*! ./SigninResponse.js */ \"./src/SigninResponse.js\");\n\nvar _SignoutRequest = __webpack_require__(/*! ./SignoutRequest.js */ \"./src/SignoutRequest.js\");\n\nvar _SignoutResponse = __webpack_require__(/*! ./SignoutResponse.js */ \"./src/SignoutResponse.js\");\n\nvar _SigninState = __webpack_require__(/*! ./SigninState.js */ \"./src/SigninState.js\");\n\nvar _State = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcClient = exports.OidcClient = function () {\n    function OidcClient() {\n        var settings = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        _classCallCheck(this, OidcClient);\n\n        if (settings instanceof _OidcClientSettings.OidcClientSettings) {\n            this._settings = settings;\n        } else {\n            this._settings = new _OidcClientSettings.OidcClientSettings(settings);\n        }\n    }\n\n    OidcClient.prototype.createSigninRequest = function createSigninRequest() {\n        var _this = this;\n\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            response_type = _ref.response_type,\n            scope = _ref.scope,\n            redirect_uri = _ref.redirect_uri,\n            data = _ref.data,\n            state = _ref.state,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            id_token_hint = _ref.id_token_hint,\n            login_hint = _ref.login_hint,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            request = _ref.request,\n            request_uri = _ref.request_uri,\n            response_mode = _ref.response_mode,\n            extraQueryParams = _ref.extraQueryParams,\n            extraTokenParams = _ref.extraTokenParams,\n            request_type = _ref.request_type,\n            skipUserInfo = _ref.skipUserInfo;\n\n        var stateStore = arguments[1];\n\n        _Log.Log.debug(\"OidcClient.createSigninRequest\");\n\n        var client_id = this._settings.client_id;\n        response_type = response_type || this._settings.response_type;\n        scope = scope || this._settings.scope;\n        redirect_uri = redirect_uri || this._settings.redirect_uri;\n\n        // id_token_hint, login_hint aren't allowed on _settings\n        prompt = prompt || this._settings.prompt;\n        display = display || this._settings.display;\n        max_age = max_age || this._settings.max_age;\n        ui_locales = ui_locales || this._settings.ui_locales;\n        acr_values = acr_values || this._settings.acr_values;\n        resource = resource || this._settings.resource;\n        response_mode = response_mode || this._settings.response_mode;\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\n        extraTokenParams = extraTokenParams || this._settings.extraTokenParams;\n\n        var authority = this._settings.authority;\n\n        if (_SigninRequest.SigninRequest.isCode(response_type) && response_type !== \"code\") {\n            return Promise.reject(new Error(\"OpenID Connect hybrid flow is not supported\"));\n        }\n\n        return this._metadataService.getAuthorizationEndpoint().then(function (url) {\n            _Log.Log.debug(\"OidcClient.createSigninRequest: Received authorization endpoint\", url);\n\n            var signinRequest = new _SigninRequest.SigninRequest({\n                url: url,\n                client_id: client_id,\n                redirect_uri: redirect_uri,\n                response_type: response_type,\n                scope: scope,\n                data: data || state,\n                authority: authority,\n                prompt: prompt, display: display, max_age: max_age, ui_locales: ui_locales, id_token_hint: id_token_hint, login_hint: login_hint, acr_values: acr_values,\n                resource: resource, request: request, request_uri: request_uri, extraQueryParams: extraQueryParams, extraTokenParams: extraTokenParams, request_type: request_type, response_mode: response_mode,\n                client_secret: _this._settings.client_secret,\n                skipUserInfo: skipUserInfo\n            });\n\n            var signinState = signinRequest.state;\n            stateStore = stateStore || _this._stateStore;\n\n            return stateStore.set(signinState.id, signinState.toStorageString()).then(function () {\n                return signinRequest;\n            });\n        });\n    };\n\n    OidcClient.prototype.readSigninResponseState = function readSigninResponseState(url, stateStore) {\n        var removeState = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : false;\n\n        _Log.Log.debug(\"OidcClient.readSigninResponseState\");\n\n        var useQuery = this._settings.response_mode === \"query\" || !this._settings.response_mode && _SigninRequest.SigninRequest.isCode(this._settings.response_type);\n        var delimiter = useQuery ? \"?\" : \"#\";\n\n        var response = new _SigninResponse.SigninResponse(url, delimiter);\n\n        if (!response.state) {\n            _Log.Log.error(\"OidcClient.readSigninResponseState: No state in response\");\n            return Promise.reject(new Error(\"No state in response\"));\n        }\n\n        stateStore = stateStore || this._stateStore;\n\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\n\n        return stateApi(response.state).then(function (storedStateString) {\n            if (!storedStateString) {\n                _Log.Log.error(\"OidcClient.readSigninResponseState: No matching state found in storage\");\n                throw new Error(\"No matching state found in storage\");\n            }\n\n            var state = _SigninState.SigninState.fromStorageString(storedStateString);\n            return { state: state, response: response };\n        });\n    };\n\n    OidcClient.prototype.processSigninResponse = function processSigninResponse(url, stateStore) {\n        var _this2 = this;\n\n        _Log.Log.debug(\"OidcClient.processSigninResponse\");\n\n        return this.readSigninResponseState(url, stateStore, true).then(function (_ref2) {\n            var state = _ref2.state,\n                response = _ref2.response;\n\n            _Log.Log.debug(\"OidcClient.processSigninResponse: Received state from storage; validating response\");\n            return _this2._validator.validateSigninResponse(state, response);\n        });\n    };\n\n    OidcClient.prototype.createSignoutRequest = function createSignoutRequest() {\n        var _this3 = this;\n\n        var _ref3 = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            id_token_hint = _ref3.id_token_hint,\n            data = _ref3.data,\n            state = _ref3.state,\n            post_logout_redirect_uri = _ref3.post_logout_redirect_uri,\n            extraQueryParams = _ref3.extraQueryParams,\n            request_type = _ref3.request_type;\n\n        var stateStore = arguments[1];\n\n        _Log.Log.debug(\"OidcClient.createSignoutRequest\");\n\n        post_logout_redirect_uri = post_logout_redirect_uri || this._settings.post_logout_redirect_uri;\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\n\n        return this._metadataService.getEndSessionEndpoint().then(function (url) {\n            if (!url) {\n                _Log.Log.error(\"OidcClient.createSignoutRequest: No end session endpoint url returned\");\n                throw new Error(\"no end session endpoint\");\n            }\n\n            _Log.Log.debug(\"OidcClient.createSignoutRequest: Received end session endpoint\", url);\n\n            var request = new _SignoutRequest.SignoutRequest({\n                url: url,\n                id_token_hint: id_token_hint,\n                post_logout_redirect_uri: post_logout_redirect_uri,\n                data: data || state,\n                extraQueryParams: extraQueryParams,\n                request_type: request_type\n            });\n\n            var signoutState = request.state;\n            if (signoutState) {\n                _Log.Log.debug(\"OidcClient.createSignoutRequest: Signout request has state to persist\");\n\n                stateStore = stateStore || _this3._stateStore;\n                stateStore.set(signoutState.id, signoutState.toStorageString());\n            }\n\n            return request;\n        });\n    };\n\n    OidcClient.prototype.readSignoutResponseState = function readSignoutResponseState(url, stateStore) {\n        var removeState = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : false;\n\n        _Log.Log.debug(\"OidcClient.readSignoutResponseState\");\n\n        var response = new _SignoutResponse.SignoutResponse(url);\n        if (!response.state) {\n            _Log.Log.debug(\"OidcClient.readSignoutResponseState: No state in response\");\n\n            if (response.error) {\n                _Log.Log.warn(\"OidcClient.readSignoutResponseState: Response was error: \", response.error);\n                return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n            }\n\n            return Promise.resolve({ undefined: undefined, response: response });\n        }\n\n        var stateKey = response.state;\n\n        stateStore = stateStore || this._stateStore;\n\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\n        return stateApi(stateKey).then(function (storedStateString) {\n            if (!storedStateString) {\n                _Log.Log.error(\"OidcClient.readSignoutResponseState: No matching state found in storage\");\n                throw new Error(\"No matching state found in storage\");\n            }\n\n            var state = _State.State.fromStorageString(storedStateString);\n\n            return { state: state, response: response };\n        });\n    };\n\n    OidcClient.prototype.processSignoutResponse = function processSignoutResponse(url, stateStore) {\n        var _this4 = this;\n\n        _Log.Log.debug(\"OidcClient.processSignoutResponse\");\n\n        return this.readSignoutResponseState(url, stateStore, true).then(function (_ref4) {\n            var state = _ref4.state,\n                response = _ref4.response;\n\n            if (state) {\n                _Log.Log.debug(\"OidcClient.processSignoutResponse: Received state from storage; validating response\");\n                return _this4._validator.validateSignoutResponse(state, response);\n            } else {\n                _Log.Log.debug(\"OidcClient.processSignoutResponse: No state from storage; skipping validating response\");\n                return response;\n            }\n        });\n    };\n\n    OidcClient.prototype.clearStaleState = function clearStaleState(stateStore) {\n        _Log.Log.debug(\"OidcClient.clearStaleState\");\n\n        stateStore = stateStore || this._stateStore;\n\n        return _State.State.clearStaleState(stateStore, this.settings.staleStateAge);\n    };\n\n    _createClass(OidcClient, [{\n        key: '_stateStore',\n        get: function get() {\n            return this.settings.stateStore;\n        }\n    }, {\n        key: '_validator',\n        get: function get() {\n            return this.settings.validator;\n        }\n    }, {\n        key: '_metadataService',\n        get: function get() {\n            return this.settings.metadataService;\n        }\n    }, {\n        key: 'settings',\n        get: function get() {\n            return this._settings;\n        }\n    }, {\n        key: 'metadataService',\n        get: function get() {\n            return this._metadataService;\n        }\n    }]);\n\n    return OidcClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/OidcClientSettings.js\":\n/*!***********************************!*\\\n  !*** ./src/OidcClientSettings.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.OidcClientSettings = undefined;\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _ResponseValidator = __webpack_require__(/*! ./ResponseValidator.js */ \"./src/ResponseValidator.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcMetadataUrlPath = '.well-known/openid-configuration';\n\nvar DefaultResponseType = \"id_token\";\nvar DefaultScope = \"openid\";\nvar DefaultStaleStateAge = 60 * 15; // seconds\nvar DefaultClockSkewInSeconds = 60 * 5;\n\nvar OidcClientSettings = exports.OidcClientSettings = function () {\n    function OidcClientSettings() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            authority = _ref.authority,\n            metadataUrl = _ref.metadataUrl,\n            metadata = _ref.metadata,\n            signingKeys = _ref.signingKeys,\n            client_id = _ref.client_id,\n            client_secret = _ref.client_secret,\n            _ref$response_type = _ref.response_type,\n            response_type = _ref$response_type === undefined ? DefaultResponseType : _ref$response_type,\n            _ref$scope = _ref.scope,\n            scope = _ref$scope === undefined ? DefaultScope : _ref$scope,\n            redirect_uri = _ref.redirect_uri,\n            post_logout_redirect_uri = _ref.post_logout_redirect_uri,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            response_mode = _ref.response_mode,\n            _ref$filterProtocolCl = _ref.filterProtocolClaims,\n            filterProtocolClaims = _ref$filterProtocolCl === undefined ? true : _ref$filterProtocolCl,\n            _ref$loadUserInfo = _ref.loadUserInfo,\n            loadUserInfo = _ref$loadUserInfo === undefined ? true : _ref$loadUserInfo,\n            _ref$staleStateAge = _ref.staleStateAge,\n            staleStateAge = _ref$staleStateAge === undefined ? DefaultStaleStateAge : _ref$staleStateAge,\n            _ref$clockSkew = _ref.clockSkew,\n            clockSkew = _ref$clockSkew === undefined ? DefaultClockSkewInSeconds : _ref$clockSkew,\n            _ref$userInfoJwtIssue = _ref.userInfoJwtIssuer,\n            userInfoJwtIssuer = _ref$userInfoJwtIssue === undefined ? 'OP' : _ref$userInfoJwtIssue,\n            _ref$stateStore = _ref.stateStore,\n            stateStore = _ref$stateStore === undefined ? new _WebStorageStateStore.WebStorageStateStore() : _ref$stateStore,\n            _ref$ResponseValidato = _ref.ResponseValidatorCtor,\n            ResponseValidatorCtor = _ref$ResponseValidato === undefined ? _ResponseValidator.ResponseValidator : _ref$ResponseValidato,\n            _ref$MetadataServiceC = _ref.MetadataServiceCtor,\n            MetadataServiceCtor = _ref$MetadataServiceC === undefined ? _MetadataService.MetadataService : _ref$MetadataServiceC,\n            _ref$extraQueryParams = _ref.extraQueryParams,\n            extraQueryParams = _ref$extraQueryParams === undefined ? {} : _ref$extraQueryParams,\n            _ref$extraTokenParams = _ref.extraTokenParams,\n            extraTokenParams = _ref$extraTokenParams === undefined ? {} : _ref$extraTokenParams;\n\n        _classCallCheck(this, OidcClientSettings);\n\n        this._authority = authority;\n        this._metadataUrl = metadataUrl;\n        this._metadata = metadata;\n        this._signingKeys = signingKeys;\n\n        this._client_id = client_id;\n        this._client_secret = client_secret;\n        this._response_type = response_type;\n        this._scope = scope;\n        this._redirect_uri = redirect_uri;\n        this._post_logout_redirect_uri = post_logout_redirect_uri;\n\n        this._prompt = prompt;\n        this._display = display;\n        this._max_age = max_age;\n        this._ui_locales = ui_locales;\n        this._acr_values = acr_values;\n        this._resource = resource;\n        this._response_mode = response_mode;\n\n        this._filterProtocolClaims = !!filterProtocolClaims;\n        this._loadUserInfo = !!loadUserInfo;\n        this._staleStateAge = staleStateAge;\n        this._clockSkew = clockSkew;\n        this._userInfoJwtIssuer = userInfoJwtIssuer;\n\n        this._stateStore = stateStore;\n        this._validator = new ResponseValidatorCtor(this);\n        this._metadataService = new MetadataServiceCtor(this);\n\n        this._extraQueryParams = (typeof extraQueryParams === 'undefined' ? 'undefined' : _typeof(extraQueryParams)) === 'object' ? extraQueryParams : {};\n        this._extraTokenParams = (typeof extraTokenParams === 'undefined' ? 'undefined' : _typeof(extraTokenParams)) === 'object' ? extraTokenParams : {};\n    }\n\n    // client config\n\n\n    _createClass(OidcClientSettings, [{\n        key: 'client_id',\n        get: function get() {\n            return this._client_id;\n        },\n        set: function set(value) {\n            if (!this._client_id) {\n                // one-time set only\n                this._client_id = value;\n            } else {\n                _Log.Log.error(\"OidcClientSettings.set_client_id: client_id has already been assigned.\");\n                throw new Error(\"client_id has already been assigned.\");\n            }\n        }\n    }, {\n        key: 'client_secret',\n        get: function get() {\n            return this._client_secret;\n        }\n    }, {\n        key: 'response_type',\n        get: function get() {\n            return this._response_type;\n        }\n    }, {\n        key: 'scope',\n        get: function get() {\n            return this._scope;\n        }\n    }, {\n        key: 'redirect_uri',\n        get: function get() {\n            return this._redirect_uri;\n        }\n    }, {\n        key: 'post_logout_redirect_uri',\n        get: function get() {\n            return this._post_logout_redirect_uri;\n        }\n\n        // optional protocol params\n\n    }, {\n        key: 'prompt',\n        get: function get() {\n            return this._prompt;\n        }\n    }, {\n        key: 'display',\n        get: function get() {\n            return this._display;\n        }\n    }, {\n        key: 'max_age',\n        get: function get() {\n            return this._max_age;\n        }\n    }, {\n        key: 'ui_locales',\n        get: function get() {\n            return this._ui_locales;\n        }\n    }, {\n        key: 'acr_values',\n        get: function get() {\n            return this._acr_values;\n        }\n    }, {\n        key: 'resource',\n        get: function get() {\n            return this._resource;\n        }\n    }, {\n        key: 'response_mode',\n        get: function get() {\n            return this._response_mode;\n        }\n\n        // metadata\n\n    }, {\n        key: 'authority',\n        get: function get() {\n            return this._authority;\n        },\n        set: function set(value) {\n            if (!this._authority) {\n                // one-time set only\n                this._authority = value;\n            } else {\n                _Log.Log.error(\"OidcClientSettings.set_authority: authority has already been assigned.\");\n                throw new Error(\"authority has already been assigned.\");\n            }\n        }\n    }, {\n        key: 'metadataUrl',\n        get: function get() {\n            if (!this._metadataUrl) {\n                this._metadataUrl = this.authority;\n\n                if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\n                    if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\n                        this._metadataUrl += '/';\n                    }\n                    this._metadataUrl += OidcMetadataUrlPath;\n                }\n            }\n\n            return this._metadataUrl;\n        }\n\n        // settable/cachable metadata values\n\n    }, {\n        key: 'metadata',\n        get: function get() {\n            return this._metadata;\n        },\n        set: function set(value) {\n            this._metadata = value;\n        }\n    }, {\n        key: 'signingKeys',\n        get: function get() {\n            return this._signingKeys;\n        },\n        set: function set(value) {\n            this._signingKeys = value;\n        }\n\n        // behavior flags\n\n    }, {\n        key: 'filterProtocolClaims',\n        get: function get() {\n            return this._filterProtocolClaims;\n        }\n    }, {\n        key: 'loadUserInfo',\n        get: function get() {\n            return this._loadUserInfo;\n        }\n    }, {\n        key: 'staleStateAge',\n        get: function get() {\n            return this._staleStateAge;\n        }\n    }, {\n        key: 'clockSkew',\n        get: function get() {\n            return this._clockSkew;\n        }\n    }, {\n        key: 'userInfoJwtIssuer',\n        get: function get() {\n            return this._userInfoJwtIssuer;\n        }\n    }, {\n        key: 'stateStore',\n        get: function get() {\n            return this._stateStore;\n        }\n    }, {\n        key: 'validator',\n        get: function get() {\n            return this._validator;\n        }\n    }, {\n        key: 'metadataService',\n        get: function get() {\n            return this._metadataService;\n        }\n\n        // extra query params\n\n    }, {\n        key: 'extraQueryParams',\n        get: function get() {\n            return this._extraQueryParams;\n        },\n        set: function set(value) {\n            if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                this._extraQueryParams = value;\n            } else {\n                this._extraQueryParams = {};\n            }\n        }\n\n        // extra token params\n\n    }, {\n        key: 'extraTokenParams',\n        get: function get() {\n            return this._extraTokenParams;\n        },\n        set: function set(value) {\n            if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                this._extraTokenParams = value;\n            } else {\n                this._extraTokenParams = {};\n            }\n        }\n    }]);\n\n    return OidcClientSettings;\n}();\n\n/***/ }),\n\n/***/ \"./src/PopupNavigator.js\":\n/*!*******************************!*\\\n  !*** ./src/PopupNavigator.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.PopupNavigator = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _PopupWindow = __webpack_require__(/*! ./PopupWindow.js */ \"./src/PopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar PopupNavigator = exports.PopupNavigator = function () {\n    function PopupNavigator() {\n        _classCallCheck(this, PopupNavigator);\n    }\n\n    PopupNavigator.prototype.prepare = function prepare(params) {\n        var popup = new _PopupWindow.PopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    PopupNavigator.prototype.callback = function callback(url, keepOpen, delimiter) {\n        _Log.Log.debug(\"PopupNavigator.callback\");\n\n        try {\n            _PopupWindow.PopupWindow.notifyOpener(url, keepOpen, delimiter);\n            return Promise.resolve();\n        } catch (e) {\n            return Promise.reject(e);\n        }\n    };\n\n    return PopupNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/PopupWindow.js\":\n/*!****************************!*\\\n  !*** ./src/PopupWindow.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.PopupWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar CheckForPopupClosedInterval = 500;\nvar DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;';\n//const DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;resizable=yes';\n\nvar DefaultPopupTarget = \"_blank\";\n\nvar PopupWindow = exports.PopupWindow = function () {\n    function PopupWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, PopupWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        var target = params.popupWindowTarget || DefaultPopupTarget;\n        var features = params.popupWindowFeatures || DefaultPopupFeatures;\n\n        this._popup = window.open('', target, features);\n        if (this._popup) {\n            _Log.Log.debug(\"PopupWindow.ctor: popup successfully created\");\n            this._checkForPopupClosedTimer = window.setInterval(this._checkForPopupClosed.bind(this), CheckForPopupClosedInterval);\n        }\n    }\n\n    PopupWindow.prototype.navigate = function navigate(params) {\n        if (!this._popup) {\n            this._error(\"PopupWindow.navigate: Error opening popup window\");\n        } else if (!params || !params.url) {\n            this._error(\"PopupWindow.navigate: no url provided\");\n            this._error(\"No url provided\");\n        } else {\n            _Log.Log.debug(\"PopupWindow.navigate: Setting URL in popup\");\n\n            this._id = params.id;\n            if (this._id) {\n                window[\"popupCallback_\" + params.id] = this._callback.bind(this);\n            }\n\n            this._popup.focus();\n            this._popup.window.location = params.url;\n        }\n\n        return this.promise;\n    };\n\n    PopupWindow.prototype._success = function _success(data) {\n        _Log.Log.debug(\"PopupWindow.callback: Successful response from popup window\");\n\n        this._cleanup();\n        this._resolve(data);\n    };\n\n    PopupWindow.prototype._error = function _error(message) {\n        _Log.Log.error(\"PopupWindow.error: \", message);\n\n        this._cleanup();\n        this._reject(new Error(message));\n    };\n\n    PopupWindow.prototype.close = function close() {\n        this._cleanup(false);\n    };\n\n    PopupWindow.prototype._cleanup = function _cleanup(keepOpen) {\n        _Log.Log.debug(\"PopupWindow.cleanup\");\n\n        window.clearInterval(this._checkForPopupClosedTimer);\n        this._checkForPopupClosedTimer = null;\n\n        delete window[\"popupCallback_\" + this._id];\n\n        if (this._popup && !keepOpen) {\n            this._popup.close();\n        }\n        this._popup = null;\n    };\n\n    PopupWindow.prototype._checkForPopupClosed = function _checkForPopupClosed() {\n        if (!this._popup || this._popup.closed) {\n            this._error(\"Popup window closed\");\n        }\n    };\n\n    PopupWindow.prototype._callback = function _callback(url, keepOpen) {\n        this._cleanup(keepOpen);\n\n        if (url) {\n            _Log.Log.debug(\"PopupWindow.callback success\");\n            this._success({ url: url });\n        } else {\n            _Log.Log.debug(\"PopupWindow.callback: Invalid response from popup\");\n            this._error(\"Invalid response from popup\");\n        }\n    };\n\n    PopupWindow.notifyOpener = function notifyOpener(url, keepOpen, delimiter) {\n        if (window.opener) {\n            url = url || window.location.href;\n            if (url) {\n                var data = _UrlUtility.UrlUtility.parseUrlFragment(url, delimiter);\n\n                if (data.state) {\n                    var name = \"popupCallback_\" + data.state;\n                    var callback = window.opener[name];\n                    if (callback) {\n                        _Log.Log.debug(\"PopupWindow.notifyOpener: passing url message to opener\");\n                        callback(url, keepOpen);\n                    } else {\n                        _Log.Log.warn(\"PopupWindow.notifyOpener: no matching callback found on opener\");\n                    }\n                } else {\n                    _Log.Log.warn(\"PopupWindow.notifyOpener: no state found in response url\");\n                }\n            }\n        } else {\n            _Log.Log.warn(\"PopupWindow.notifyOpener: no window.opener. Can't complete notification.\");\n        }\n    };\n\n    _createClass(PopupWindow, [{\n        key: 'promise',\n        get: function get() {\n            return this._promise;\n        }\n    }]);\n\n    return PopupWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/RedirectNavigator.js\":\n/*!**********************************!*\\\n  !*** ./src/RedirectNavigator.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.RedirectNavigator = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar RedirectNavigator = exports.RedirectNavigator = function () {\n    function RedirectNavigator() {\n        _classCallCheck(this, RedirectNavigator);\n    }\n\n    RedirectNavigator.prototype.prepare = function prepare() {\n        return Promise.resolve(this);\n    };\n\n    RedirectNavigator.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            _Log.Log.error(\"RedirectNavigator.navigate: No url provided\");\n            return Promise.reject(new Error(\"No url provided\"));\n        }\n\n        if (params.useReplaceToNavigate) {\n            window.location.replace(params.url);\n        } else {\n            window.location = params.url;\n        }\n\n        return Promise.resolve();\n    };\n\n    _createClass(RedirectNavigator, [{\n        key: \"url\",\n        get: function get() {\n            return window.location.href;\n        }\n    }]);\n\n    return RedirectNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/ResponseValidator.js\":\n/*!**********************************!*\\\n  !*** ./src/ResponseValidator.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.ResponseValidator = undefined;\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _UserInfoService = __webpack_require__(/*! ./UserInfoService.js */ \"./src/UserInfoService.js\");\n\nvar _TokenClient = __webpack_require__(/*! ./TokenClient.js */ \"./src/TokenClient.js\");\n\nvar _ErrorResponse = __webpack_require__(/*! ./ErrorResponse.js */ \"./src/ErrorResponse.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar ProtocolClaims = [\"nonce\", \"at_hash\", \"iat\", \"nbf\", \"exp\", \"aud\", \"iss\", \"c_hash\"];\n\nvar ResponseValidator = exports.ResponseValidator = function () {\n    function ResponseValidator(settings) {\n        var MetadataServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _MetadataService.MetadataService;\n        var UserInfoServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _UserInfoService.UserInfoService;\n        var joseUtil = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _JoseUtil.JoseUtil;\n        var TokenClientCtor = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : _TokenClient.TokenClient;\n\n        _classCallCheck(this, ResponseValidator);\n\n        if (!settings) {\n            _Log.Log.error(\"ResponseValidator.ctor: No settings passed to ResponseValidator\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._metadataService = new MetadataServiceCtor(this._settings);\n        this._userInfoService = new UserInfoServiceCtor(this._settings);\n        this._joseUtil = joseUtil;\n        this._tokenClient = new TokenClientCtor(this._settings);\n    }\n\n    ResponseValidator.prototype.validateSigninResponse = function validateSigninResponse(state, response) {\n        var _this = this;\n\n        _Log.Log.debug(\"ResponseValidator.validateSigninResponse\");\n\n        return this._processSigninParams(state, response).then(function (response) {\n            _Log.Log.debug(\"ResponseValidator.validateSigninResponse: state processed\");\n            return _this._validateTokens(state, response).then(function (response) {\n                _Log.Log.debug(\"ResponseValidator.validateSigninResponse: tokens validated\");\n                return _this._processClaims(state, response).then(function (response) {\n                    _Log.Log.debug(\"ResponseValidator.validateSigninResponse: claims processed\");\n                    return response;\n                });\n            });\n        });\n    };\n\n    ResponseValidator.prototype.validateSignoutResponse = function validateSignoutResponse(state, response) {\n        if (state.id !== response.state) {\n            _Log.Log.error(\"ResponseValidator.validateSignoutResponse: State does not match\");\n            return Promise.reject(new Error(\"State does not match\"));\n        }\n\n        // now that we know the state matches, take the stored data\n        // and set it into the response so callers can get their state\n        // this is important for both success & error outcomes\n        _Log.Log.debug(\"ResponseValidator.validateSignoutResponse: state validated\");\n        response.state = state.data;\n\n        if (response.error) {\n            _Log.Log.warn(\"ResponseValidator.validateSignoutResponse: Response was error\", response.error);\n            return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processSigninParams = function _processSigninParams(state, response) {\n        if (state.id !== response.state) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: State does not match\");\n            return Promise.reject(new Error(\"State does not match\"));\n        }\n\n        if (!state.client_id) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: No client_id on state\");\n            return Promise.reject(new Error(\"No client_id on state\"));\n        }\n\n        if (!state.authority) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: No authority on state\");\n            return Promise.reject(new Error(\"No authority on state\"));\n        }\n\n        // this allows the authority to be loaded from the signin state\n        if (!this._settings.authority) {\n            this._settings.authority = state.authority;\n        }\n        // ensure we're using the correct authority if the authority is not loaded from signin state\n        else if (this._settings.authority && this._settings.authority !== state.authority) {\n                _Log.Log.error(\"ResponseValidator._processSigninParams: authority mismatch on settings vs. signin state\");\n                return Promise.reject(new Error(\"authority mismatch on settings vs. signin state\"));\n            }\n        // this allows the client_id to be loaded from the signin state\n        if (!this._settings.client_id) {\n            this._settings.client_id = state.client_id;\n        }\n        // ensure we're using the correct client_id if the client_id is not loaded from signin state\n        else if (this._settings.client_id && this._settings.client_id !== state.client_id) {\n                _Log.Log.error(\"ResponseValidator._processSigninParams: client_id mismatch on settings vs. signin state\");\n                return Promise.reject(new Error(\"client_id mismatch on settings vs. signin state\"));\n            }\n\n        // now that we know the state matches, take the stored data\n        // and set it into the response so callers can get their state\n        // this is important for both success & error outcomes\n        _Log.Log.debug(\"ResponseValidator._processSigninParams: state validated\");\n        response.state = state.data;\n\n        if (response.error) {\n            _Log.Log.warn(\"ResponseValidator._processSigninParams: Response was error\", response.error);\n            return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n        }\n\n        if (state.nonce && !response.id_token) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Expecting id_token in response\");\n            return Promise.reject(new Error(\"No id_token in response\"));\n        }\n\n        if (!state.nonce && response.id_token) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Not expecting id_token in response\");\n            return Promise.reject(new Error(\"Unexpected id_token in response\"));\n        }\n\n        if (state.code_verifier && !response.code) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Expecting code in response\");\n            return Promise.reject(new Error(\"No code in response\"));\n        }\n\n        if (!state.code_verifier && response.code) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Not expecting code in response\");\n            return Promise.reject(new Error(\"Unexpected code in response\"));\n        }\n\n        if (!response.scope) {\n            // if there's no scope on the response, then assume all scopes granted (per-spec) and copy over scopes from original request\n            response.scope = state.scope;\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processClaims = function _processClaims(state, response) {\n        var _this2 = this;\n\n        if (response.isOpenIdConnect) {\n            _Log.Log.debug(\"ResponseValidator._processClaims: response is OIDC, processing claims\");\n\n            response.profile = this._filterProtocolClaims(response.profile);\n\n            if (state.skipUserInfo !== true && this._settings.loadUserInfo && response.access_token) {\n                _Log.Log.debug(\"ResponseValidator._processClaims: loading user info\");\n\n                return this._userInfoService.getClaims(response.access_token).then(function (claims) {\n                    _Log.Log.debug(\"ResponseValidator._processClaims: user info claims received from user info endpoint\");\n\n                    if (claims.sub !== response.profile.sub) {\n                        _Log.Log.error(\"ResponseValidator._processClaims: sub from user info endpoint does not match sub in access_token\");\n                        return Promise.reject(new Error(\"sub from user info endpoint does not match sub in access_token\"));\n                    }\n\n                    response.profile = _this2._mergeClaims(response.profile, claims);\n                    _Log.Log.debug(\"ResponseValidator._processClaims: user info claims received, updated profile:\", response.profile);\n\n                    return response;\n                });\n            } else {\n                _Log.Log.debug(\"ResponseValidator._processClaims: not loading user info\");\n            }\n        } else {\n            _Log.Log.debug(\"ResponseValidator._processClaims: response is not OIDC, not processing claims\");\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._mergeClaims = function _mergeClaims(claims1, claims2) {\n        var result = Object.assign({}, claims1);\n\n        for (var name in claims2) {\n            var values = claims2[name];\n            if (!Array.isArray(values)) {\n                values = [values];\n            }\n\n            for (var i = 0; i < values.length; i++) {\n                var value = values[i];\n                if (!result[name]) {\n                    result[name] = value;\n                } else if (Array.isArray(result[name])) {\n                    if (result[name].indexOf(value) < 0) {\n                        result[name].push(value);\n                    }\n                } else if (result[name] !== value) {\n                    if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                        result[name] = this._mergeClaims(result[name], value);\n                    } else {\n                        result[name] = [result[name], value];\n                    }\n                }\n            }\n        }\n\n        return result;\n    };\n\n    ResponseValidator.prototype._filterProtocolClaims = function _filterProtocolClaims(claims) {\n        _Log.Log.debug(\"ResponseValidator._filterProtocolClaims, incoming claims:\", claims);\n\n        var result = Object.assign({}, claims);\n\n        if (this._settings._filterProtocolClaims) {\n            ProtocolClaims.forEach(function (type) {\n                delete result[type];\n            });\n\n            _Log.Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims filtered\", result);\n        } else {\n            _Log.Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims not filtered\");\n        }\n\n        return result;\n    };\n\n    ResponseValidator.prototype._validateTokens = function _validateTokens(state, response) {\n        if (response.code) {\n            _Log.Log.debug(\"ResponseValidator._validateTokens: Validating code\");\n            return this._processCode(state, response);\n        }\n\n        if (response.id_token) {\n            if (response.access_token) {\n                _Log.Log.debug(\"ResponseValidator._validateTokens: Validating id_token and access_token\");\n                return this._validateIdTokenAndAccessToken(state, response);\n            }\n\n            _Log.Log.debug(\"ResponseValidator._validateTokens: Validating id_token\");\n            return this._validateIdToken(state, response);\n        }\n\n        _Log.Log.debug(\"ResponseValidator._validateTokens: No code to process or id_token to validate\");\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processCode = function _processCode(state, response) {\n        var _this3 = this;\n\n        var request = {\n            client_id: state.client_id,\n            client_secret: state.client_secret,\n            code: response.code,\n            redirect_uri: state.redirect_uri,\n            code_verifier: state.code_verifier\n        };\n\n        if (state.extraTokenParams && _typeof(state.extraTokenParams) === 'object') {\n            Object.assign(request, state.extraTokenParams);\n        }\n\n        return this._tokenClient.exchangeCode(request).then(function (tokenResponse) {\n\n            for (var key in tokenResponse) {\n                response[key] = tokenResponse[key];\n            }\n\n            if (response.id_token) {\n                _Log.Log.debug(\"ResponseValidator._processCode: token response successful, processing id_token\");\n                return _this3._validateIdTokenAttributes(state, response);\n            } else {\n                _Log.Log.debug(\"ResponseValidator._processCode: token response successful, returning response\");\n            }\n\n            return response;\n        });\n    };\n\n    ResponseValidator.prototype._validateIdTokenAttributes = function _validateIdTokenAttributes(state, response) {\n        var _this4 = this;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n\n            var audience = state.client_id;\n            var clockSkewInSeconds = _this4._settings.clockSkew;\n            _Log.Log.debug(\"ResponseValidator._validateIdTokenAttributes: Validaing JWT attributes; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n            return _this4._joseUtil.validateJwtAttributes(response.id_token, issuer, audience, clockSkewInSeconds).then(function (payload) {\n\n                if (state.nonce && state.nonce !== payload.nonce) {\n                    _Log.Log.error(\"ResponseValidator._validateIdTokenAttributes: Invalid nonce in id_token\");\n                    return Promise.reject(new Error(\"Invalid nonce in id_token\"));\n                }\n\n                if (!payload.sub) {\n                    _Log.Log.error(\"ResponseValidator._validateIdTokenAttributes: No sub present in id_token\");\n                    return Promise.reject(new Error(\"No sub present in id_token\"));\n                }\n\n                response.profile = payload;\n                return response;\n            });\n        });\n    };\n\n    ResponseValidator.prototype._validateIdTokenAndAccessToken = function _validateIdTokenAndAccessToken(state, response) {\n        var _this5 = this;\n\n        return this._validateIdToken(state, response).then(function (response) {\n            return _this5._validateAccessToken(response);\n        });\n    };\n\n    ResponseValidator.prototype._validateIdToken = function _validateIdToken(state, response) {\n        var _this6 = this;\n\n        if (!state.nonce) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: No nonce on state\");\n            return Promise.reject(new Error(\"No nonce on state\"));\n        }\n\n        var jwt = this._joseUtil.parseJwt(response.id_token);\n        if (!jwt || !jwt.header || !jwt.payload) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: Failed to parse id_token\", jwt);\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\n        }\n\n        if (state.nonce !== jwt.payload.nonce) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: Invalid nonce in id_token\");\n            return Promise.reject(new Error(\"Invalid nonce in id_token\"));\n        }\n\n        var kid = jwt.header.kid;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n            _Log.Log.debug(\"ResponseValidator._validateIdToken: Received issuer\");\n\n            return _this6._metadataService.getSigningKeys().then(function (keys) {\n                if (!keys) {\n                    _Log.Log.error(\"ResponseValidator._validateIdToken: No signing keys from metadata\");\n                    return Promise.reject(new Error(\"No signing keys from metadata\"));\n                }\n\n                _Log.Log.debug(\"ResponseValidator._validateIdToken: Received signing keys\");\n                var key = void 0;\n                if (!kid) {\n                    keys = _this6._filterByAlg(keys, jwt.header.alg);\n\n                    if (keys.length > 1) {\n                        _Log.Log.error(\"ResponseValidator._validateIdToken: No kid found in id_token and more than one key found in metadata\");\n                        return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\n                    } else {\n                        // kid is mandatory only when there are multiple keys in the referenced JWK Set document\n                        // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\n                        key = keys[0];\n                    }\n                } else {\n                    key = keys.filter(function (key) {\n                        return key.kid === kid;\n                    })[0];\n                }\n\n                if (!key) {\n                    _Log.Log.error(\"ResponseValidator._validateIdToken: No key matching kid or alg found in signing keys\");\n                    return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\n                }\n\n                var audience = state.client_id;\n\n                var clockSkewInSeconds = _this6._settings.clockSkew;\n                _Log.Log.debug(\"ResponseValidator._validateIdToken: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n                return _this6._joseUtil.validateJwt(response.id_token, key, issuer, audience, clockSkewInSeconds).then(function () {\n                    _Log.Log.debug(\"ResponseValidator._validateIdToken: JWT validation successful\");\n\n                    if (!jwt.payload.sub) {\n                        _Log.Log.error(\"ResponseValidator._validateIdToken: No sub present in id_token\");\n                        return Promise.reject(new Error(\"No sub present in id_token\"));\n                    }\n\n                    response.profile = jwt.payload;\n\n                    return response;\n                });\n            });\n        });\n    };\n\n    ResponseValidator.prototype._filterByAlg = function _filterByAlg(keys, alg) {\n        var kty = null;\n        if (alg.startsWith(\"RS\")) {\n            kty = \"RSA\";\n        } else if (alg.startsWith(\"PS\")) {\n            kty = \"PS\";\n        } else if (alg.startsWith(\"ES\")) {\n            kty = \"EC\";\n        } else {\n            _Log.Log.debug(\"ResponseValidator._filterByAlg: alg not supported: \", alg);\n            return [];\n        }\n\n        _Log.Log.debug(\"ResponseValidator._filterByAlg: Looking for keys that match kty: \", kty);\n\n        keys = keys.filter(function (key) {\n            return key.kty === kty;\n        });\n\n        _Log.Log.debug(\"ResponseValidator._filterByAlg: Number of keys that match kty: \", kty, keys.length);\n\n        return keys;\n    };\n\n    ResponseValidator.prototype._validateAccessToken = function _validateAccessToken(response) {\n        if (!response.profile) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No profile loaded from id_token\");\n            return Promise.reject(new Error(\"No profile loaded from id_token\"));\n        }\n\n        if (!response.profile.at_hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No at_hash in id_token\");\n            return Promise.reject(new Error(\"No at_hash in id_token\"));\n        }\n\n        if (!response.id_token) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No id_token\");\n            return Promise.reject(new Error(\"No id_token\"));\n        }\n\n        var jwt = this._joseUtil.parseJwt(response.id_token);\n        if (!jwt || !jwt.header) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Failed to parse id_token\", jwt);\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\n        }\n\n        var hashAlg = jwt.header.alg;\n        if (!hashAlg || hashAlg.length !== 5) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        var hashBits = hashAlg.substr(2, 3);\n        if (!hashBits) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        hashBits = parseInt(hashBits);\n        if (hashBits !== 256 && hashBits !== 384 && hashBits !== 512) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        var sha = \"sha\" + hashBits;\n        var hash = this._joseUtil.hashString(response.access_token, sha);\n        if (!hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: access_token hash failed:\", sha);\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\n        }\n\n        var left = hash.substr(0, hash.length / 2);\n        var left_b64u = this._joseUtil.hexToBase64Url(left);\n        if (left_b64u !== response.profile.at_hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Failed to validate at_hash\", left_b64u, response.profile.at_hash);\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\n        }\n\n        _Log.Log.debug(\"ResponseValidator._validateAccessToken: success\");\n\n        return Promise.resolve(response);\n    };\n\n    return ResponseValidator;\n}();\n\n/***/ }),\n\n/***/ \"./src/SessionMonitor.js\":\n/*!*******************************!*\\\n  !*** ./src/SessionMonitor.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SessionMonitor = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _CheckSessionIFrame = __webpack_require__(/*! ./CheckSessionIFrame.js */ \"./src/CheckSessionIFrame.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar SessionMonitor = exports.SessionMonitor = function () {\n    function SessionMonitor(userManager) {\n        var _this = this;\n\n        var CheckSessionIFrameCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _CheckSessionIFrame.CheckSessionIFrame;\n        var timer = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _Global.Global.timer;\n\n        _classCallCheck(this, SessionMonitor);\n\n        if (!userManager) {\n            _Log.Log.error(\"SessionMonitor.ctor: No user manager passed to SessionMonitor\");\n            throw new Error(\"userManager\");\n        }\n\n        this._userManager = userManager;\n        this._CheckSessionIFrameCtor = CheckSessionIFrameCtor;\n        this._timer = timer;\n\n        this._userManager.events.addUserLoaded(this._start.bind(this));\n        this._userManager.events.addUserUnloaded(this._stop.bind(this));\n\n        this._userManager.getUser().then(function (user) {\n            // doing this manually here since calling getUser \n            // doesn't trigger load event.\n            if (user) {\n                _this._start(user);\n            } else if (_this._settings.monitorAnonymousSession) {\n                _this._userManager.querySessionStatus().then(function (session) {\n                    var tmpUser = {\n                        session_state: session.session_state\n                    };\n                    if (session.sub && session.sid) {\n                        tmpUser.profile = {\n                            sub: session.sub,\n                            sid: session.sid\n                        };\n                    }\n                    _this._start(tmpUser);\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in a ctor\n                    _Log.Log.error(\"SessionMonitor ctor: error from querySessionStatus:\", err.message);\n                });\n            }\n        }).catch(function (err) {\n            // catch to suppress errors since we're in a ctor\n            _Log.Log.error(\"SessionMonitor ctor: error from getUser:\", err.message);\n        });\n    }\n\n    SessionMonitor.prototype._start = function _start(user) {\n        var _this2 = this;\n\n        var session_state = user.session_state;\n\n        if (session_state) {\n            if (user.profile) {\n                this._sub = user.profile.sub;\n                this._sid = user.profile.sid;\n                _Log.Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", sub:\", this._sub);\n            } else {\n                this._sub = undefined;\n                this._sid = undefined;\n                _Log.Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", anonymous user\");\n            }\n\n            if (!this._checkSessionIFrame) {\n                this._metadataService.getCheckSessionIframe().then(function (url) {\n                    if (url) {\n                        _Log.Log.debug(\"SessionMonitor._start: Initializing check session iframe\");\n\n                        var client_id = _this2._client_id;\n                        var interval = _this2._checkSessionInterval;\n                        var stopOnError = _this2._stopCheckSessionOnError;\n\n                        _this2._checkSessionIFrame = new _this2._CheckSessionIFrameCtor(_this2._callback.bind(_this2), client_id, url, interval, stopOnError);\n                        _this2._checkSessionIFrame.load().then(function () {\n                            _this2._checkSessionIFrame.start(session_state);\n                        });\n                    } else {\n                        _Log.Log.warn(\"SessionMonitor._start: No check session iframe found in the metadata\");\n                    }\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in non-promise callback\n                    _Log.Log.error(\"SessionMonitor._start: Error from getCheckSessionIframe:\", err.message);\n                });\n            } else {\n                this._checkSessionIFrame.start(session_state);\n            }\n        }\n    };\n\n    SessionMonitor.prototype._stop = function _stop() {\n        var _this3 = this;\n\n        this._sub = undefined;\n        this._sid = undefined;\n\n        if (this._checkSessionIFrame) {\n            _Log.Log.debug(\"SessionMonitor._stop\");\n            this._checkSessionIFrame.stop();\n        }\n\n        if (this._settings.monitorAnonymousSession) {\n            // using a timer to delay re-initialization to avoid race conditions during signout\n            var timerHandle = this._timer.setInterval(function () {\n                _this3._timer.clearInterval(timerHandle);\n\n                _this3._userManager.querySessionStatus().then(function (session) {\n                    var tmpUser = {\n                        session_state: session.session_state\n                    };\n                    if (session.sub && session.sid) {\n                        tmpUser.profile = {\n                            sub: session.sub,\n                            sid: session.sid\n                        };\n                    }\n                    _this3._start(tmpUser);\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in a callback\n                    _Log.Log.error(\"SessionMonitor: error from querySessionStatus:\", err.message);\n                });\n            }, 1000);\n        }\n    };\n\n    SessionMonitor.prototype._callback = function _callback() {\n        var _this4 = this;\n\n        this._userManager.querySessionStatus().then(function (session) {\n            var raiseEvent = true;\n\n            if (session) {\n                if (session.sub === _this4._sub) {\n                    raiseEvent = false;\n                    _this4._checkSessionIFrame.start(session.session_state);\n\n                    if (session.sid === _this4._sid) {\n                        _Log.Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, restarting check session iframe; session_state:\", session.session_state);\n                    } else {\n                        _Log.Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, session state has changed, restarting check session iframe; session_state:\", session.session_state);\n                        _this4._userManager.events._raiseUserSessionChanged();\n                    }\n                } else {\n                    _Log.Log.debug(\"SessionMonitor._callback: Different subject signed into OP:\", session.sub);\n                }\n            } else {\n                _Log.Log.debug(\"SessionMonitor._callback: Subject no longer signed into OP\");\n            }\n\n            if (raiseEvent) {\n                if (_this4._sub) {\n                    _Log.Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed out event\");\n                    _this4._userManager.events._raiseUserSignedOut();\n                } else {\n                    _Log.Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed in event\");\n                    _this4._userManager.events._raiseUserSignedIn();\n                }\n            }\n        }).catch(function (err) {\n            if (_this4._sub) {\n                _Log.Log.debug(\"SessionMonitor._callback: Error calling queryCurrentSigninSession; raising signed out event\", err.message);\n                _this4._userManager.events._raiseUserSignedOut();\n            }\n        });\n    };\n\n    _createClass(SessionMonitor, [{\n        key: '_settings',\n        get: function get() {\n            return this._userManager.settings;\n        }\n    }, {\n        key: '_metadataService',\n        get: function get() {\n            return this._userManager.metadataService;\n        }\n    }, {\n        key: '_client_id',\n        get: function get() {\n            return this._settings.client_id;\n        }\n    }, {\n        key: '_checkSessionInterval',\n        get: function get() {\n            return this._settings.checkSessionInterval;\n        }\n    }, {\n        key: '_stopCheckSessionOnError',\n        get: function get() {\n            return this._settings.stopCheckSessionOnError;\n        }\n    }]);\n\n    return SessionMonitor;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninRequest.js\":\n/*!******************************!*\\\n  !*** ./src/SigninRequest.js ***!\n  \\******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninRequest = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nvar _SigninState = __webpack_require__(/*! ./SigninState.js */ \"./src/SigninState.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SigninRequest = exports.SigninRequest = function () {\n    function SigninRequest(_ref) {\n        var url = _ref.url,\n            client_id = _ref.client_id,\n            redirect_uri = _ref.redirect_uri,\n            response_type = _ref.response_type,\n            scope = _ref.scope,\n            authority = _ref.authority,\n            data = _ref.data,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            id_token_hint = _ref.id_token_hint,\n            login_hint = _ref.login_hint,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            response_mode = _ref.response_mode,\n            request = _ref.request,\n            request_uri = _ref.request_uri,\n            extraQueryParams = _ref.extraQueryParams,\n            request_type = _ref.request_type,\n            client_secret = _ref.client_secret,\n            extraTokenParams = _ref.extraTokenParams,\n            skipUserInfo = _ref.skipUserInfo;\n\n        _classCallCheck(this, SigninRequest);\n\n        if (!url) {\n            _Log.Log.error(\"SigninRequest.ctor: No url passed\");\n            throw new Error(\"url\");\n        }\n        if (!client_id) {\n            _Log.Log.error(\"SigninRequest.ctor: No client_id passed\");\n            throw new Error(\"client_id\");\n        }\n        if (!redirect_uri) {\n            _Log.Log.error(\"SigninRequest.ctor: No redirect_uri passed\");\n            throw new Error(\"redirect_uri\");\n        }\n        if (!response_type) {\n            _Log.Log.error(\"SigninRequest.ctor: No response_type passed\");\n            throw new Error(\"response_type\");\n        }\n        if (!scope) {\n            _Log.Log.error(\"SigninRequest.ctor: No scope passed\");\n            throw new Error(\"scope\");\n        }\n        if (!authority) {\n            _Log.Log.error(\"SigninRequest.ctor: No authority passed\");\n            throw new Error(\"authority\");\n        }\n\n        var oidc = SigninRequest.isOidc(response_type);\n        var code = SigninRequest.isCode(response_type);\n\n        if (!response_mode) {\n            response_mode = SigninRequest.isCode(response_type) ? \"query\" : null;\n        }\n\n        this.state = new _SigninState.SigninState({ nonce: oidc,\n            data: data, client_id: client_id, authority: authority, redirect_uri: redirect_uri,\n            code_verifier: code,\n            request_type: request_type, response_mode: response_mode,\n            client_secret: client_secret, scope: scope, extraTokenParams: extraTokenParams, skipUserInfo: skipUserInfo });\n\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"client_id\", client_id);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"redirect_uri\", redirect_uri);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"response_type\", response_type);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"scope\", scope);\n\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"state\", this.state.id);\n        if (oidc) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"nonce\", this.state.nonce);\n        }\n        if (code) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"code_challenge\", this.state.code_challenge);\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"code_challenge_method\", \"S256\");\n        }\n\n        var optional = { prompt: prompt, display: display, max_age: max_age, ui_locales: ui_locales, id_token_hint: id_token_hint, login_hint: login_hint, acr_values: acr_values, resource: resource, request: request, request_uri: request_uri, response_mode: response_mode };\n        for (var key in optional) {\n            if (optional[key]) {\n                url = _UrlUtility.UrlUtility.addQueryParam(url, key, optional[key]);\n            }\n        }\n\n        for (var _key in extraQueryParams) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, _key, extraQueryParams[_key]);\n        }\n\n        this.url = url;\n    }\n\n    SigninRequest.isOidc = function isOidc(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"id_token\";\n        });\n        return !!result[0];\n    };\n\n    SigninRequest.isOAuth = function isOAuth(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"token\";\n        });\n        return !!result[0];\n    };\n\n    SigninRequest.isCode = function isCode(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"code\";\n        });\n        return !!result[0];\n    };\n\n    return SigninRequest;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninResponse.js\":\n/*!*******************************!*\\\n  !*** ./src/SigninResponse.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninResponse = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcScope = \"openid\";\n\nvar SigninResponse = exports.SigninResponse = function () {\n    function SigninResponse(url) {\n        var delimiter = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : \"#\";\n\n        _classCallCheck(this, SigninResponse);\n\n        var values = _UrlUtility.UrlUtility.parseUrlFragment(url, delimiter);\n\n        this.error = values.error;\n        this.error_description = values.error_description;\n        this.error_uri = values.error_uri;\n\n        this.code = values.code;\n        this.state = values.state;\n        this.id_token = values.id_token;\n        this.session_state = values.session_state;\n        this.access_token = values.access_token;\n        this.token_type = values.token_type;\n        this.scope = values.scope;\n        this.profile = undefined; // will be set from ResponseValidator\n\n        this.expires_in = values.expires_in;\n    }\n\n    _createClass(SigninResponse, [{\n        key: \"expires_in\",\n        get: function get() {\n            if (this.expires_at) {\n                var now = parseInt(Date.now() / 1000);\n                return this.expires_at - now;\n            }\n            return undefined;\n        },\n        set: function set(value) {\n            var expires_in = parseInt(value);\n            if (typeof expires_in === 'number' && expires_in > 0) {\n                var now = parseInt(Date.now() / 1000);\n                this.expires_at = now + expires_in;\n            }\n        }\n    }, {\n        key: \"expired\",\n        get: function get() {\n            var expires_in = this.expires_in;\n            if (expires_in !== undefined) {\n                return expires_in <= 0;\n            }\n            return undefined;\n        }\n    }, {\n        key: \"scopes\",\n        get: function get() {\n            return (this.scope || \"\").split(\" \");\n        }\n    }, {\n        key: \"isOpenIdConnect\",\n        get: function get() {\n            return this.scopes.indexOf(OidcScope) >= 0 || !!this.id_token;\n        }\n    }]);\n\n    return SigninResponse;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninState.js\":\n/*!****************************!*\\\n  !*** ./src/SigninState.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninState = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _State2 = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nvar _random = __webpack_require__(/*! ./random.js */ \"./src/random.js\");\n\nvar _random2 = _interopRequireDefault(_random);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SigninState = exports.SigninState = function (_State) {\n    _inherits(SigninState, _State);\n\n    function SigninState() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            nonce = _ref.nonce,\n            authority = _ref.authority,\n            client_id = _ref.client_id,\n            redirect_uri = _ref.redirect_uri,\n            code_verifier = _ref.code_verifier,\n            response_mode = _ref.response_mode,\n            client_secret = _ref.client_secret,\n            scope = _ref.scope,\n            extraTokenParams = _ref.extraTokenParams,\n            skipUserInfo = _ref.skipUserInfo;\n\n        _classCallCheck(this, SigninState);\n\n        var _this = _possibleConstructorReturn(this, _State.call(this, arguments[0]));\n\n        if (nonce === true) {\n            _this._nonce = (0, _random2.default)();\n        } else if (nonce) {\n            _this._nonce = nonce;\n        }\n\n        if (code_verifier === true) {\n            // random() produces 32 length\n            _this._code_verifier = (0, _random2.default)() + (0, _random2.default)() + (0, _random2.default)();\n        } else if (code_verifier) {\n            _this._code_verifier = code_verifier;\n        }\n\n        if (_this.code_verifier) {\n            var hash = _JoseUtil.JoseUtil.hashString(_this.code_verifier, \"SHA256\");\n            _this._code_challenge = _JoseUtil.JoseUtil.hexToBase64Url(hash);\n        }\n\n        _this._redirect_uri = redirect_uri;\n        _this._authority = authority;\n        _this._client_id = client_id;\n        _this._response_mode = response_mode;\n        _this._client_secret = client_secret;\n        _this._scope = scope;\n        _this._extraTokenParams = extraTokenParams;\n        _this._skipUserInfo = skipUserInfo;\n        return _this;\n    }\n\n    SigninState.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"SigninState.toStorageString\");\n        return JSON.stringify({\n            id: this.id,\n            data: this.data,\n            created: this.created,\n            request_type: this.request_type,\n            nonce: this.nonce,\n            code_verifier: this.code_verifier,\n            redirect_uri: this.redirect_uri,\n            authority: this.authority,\n            client_id: this.client_id,\n            response_mode: this.response_mode,\n            client_secret: this.client_secret,\n            scope: this.scope,\n            extraTokenParams: this.extraTokenParams,\n            skipUserInfo: this.skipUserInfo\n        });\n    };\n\n    SigninState.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"SigninState.fromStorageString\");\n        var data = JSON.parse(storageString);\n        return new SigninState(data);\n    };\n\n    _createClass(SigninState, [{\n        key: 'nonce',\n        get: function get() {\n            return this._nonce;\n        }\n    }, {\n        key: 'authority',\n        get: function get() {\n            return this._authority;\n        }\n    }, {\n        key: 'client_id',\n        get: function get() {\n            return this._client_id;\n        }\n    }, {\n        key: 'redirect_uri',\n        get: function get() {\n            return this._redirect_uri;\n        }\n    }, {\n        key: 'code_verifier',\n        get: function get() {\n            return this._code_verifier;\n        }\n    }, {\n        key: 'code_challenge',\n        get: function get() {\n            return this._code_challenge;\n        }\n    }, {\n        key: 'response_mode',\n        get: function get() {\n            return this._response_mode;\n        }\n    }, {\n        key: 'client_secret',\n        get: function get() {\n            return this._client_secret;\n        }\n    }, {\n        key: 'scope',\n        get: function get() {\n            return this._scope;\n        }\n    }, {\n        key: 'extraTokenParams',\n        get: function get() {\n            return this._extraTokenParams;\n        }\n    }, {\n        key: 'skipUserInfo',\n        get: function get() {\n            return this._skipUserInfo;\n        }\n    }]);\n\n    return SigninState;\n}(_State2.State);\n\n/***/ }),\n\n/***/ \"./src/SignoutRequest.js\":\n/*!*******************************!*\\\n  !*** ./src/SignoutRequest.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SignoutRequest = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nvar _State = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SignoutRequest = exports.SignoutRequest = function SignoutRequest(_ref) {\n    var url = _ref.url,\n        id_token_hint = _ref.id_token_hint,\n        post_logout_redirect_uri = _ref.post_logout_redirect_uri,\n        data = _ref.data,\n        extraQueryParams = _ref.extraQueryParams,\n        request_type = _ref.request_type;\n\n    _classCallCheck(this, SignoutRequest);\n\n    if (!url) {\n        _Log.Log.error(\"SignoutRequest.ctor: No url passed\");\n        throw new Error(\"url\");\n    }\n\n    if (id_token_hint) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"id_token_hint\", id_token_hint);\n    }\n\n    if (post_logout_redirect_uri) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"post_logout_redirect_uri\", post_logout_redirect_uri);\n\n        if (data) {\n            this.state = new _State.State({ data: data, request_type: request_type });\n\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"state\", this.state.id);\n        }\n    }\n\n    for (var key in extraQueryParams) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, key, extraQueryParams[key]);\n    }\n\n    this.url = url;\n};\n\n/***/ }),\n\n/***/ \"./src/SignoutResponse.js\":\n/*!********************************!*\\\n  !*** ./src/SignoutResponse.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n        value: true\n});\nexports.SignoutResponse = undefined;\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SignoutResponse = exports.SignoutResponse = function SignoutResponse(url) {\n        _classCallCheck(this, SignoutResponse);\n\n        var values = _UrlUtility.UrlUtility.parseUrlFragment(url, \"?\");\n\n        this.error = values.error;\n        this.error_description = values.error_description;\n        this.error_uri = values.error_uri;\n\n        this.state = values.state;\n};\n\n/***/ }),\n\n/***/ \"./src/SilentRenewService.js\":\n/*!***********************************!*\\\n  !*** ./src/SilentRenewService.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SilentRenewService = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SilentRenewService = exports.SilentRenewService = function () {\n    function SilentRenewService(userManager) {\n        _classCallCheck(this, SilentRenewService);\n\n        this._userManager = userManager;\n    }\n\n    SilentRenewService.prototype.start = function start() {\n        if (!this._callback) {\n            this._callback = this._tokenExpiring.bind(this);\n            this._userManager.events.addAccessTokenExpiring(this._callback);\n\n            // this will trigger loading of the user so the expiring events can be initialized\n            this._userManager.getUser().then(function (user) {\n                // deliberate nop\n            }).catch(function (err) {\n                // catch to suppress errors since we're in a ctor\n                _Log.Log.error(\"SilentRenewService.start: Error from getUser:\", err.message);\n            });\n        }\n    };\n\n    SilentRenewService.prototype.stop = function stop() {\n        if (this._callback) {\n            this._userManager.events.removeAccessTokenExpiring(this._callback);\n            delete this._callback;\n        }\n    };\n\n    SilentRenewService.prototype._tokenExpiring = function _tokenExpiring() {\n        var _this = this;\n\n        this._userManager.signinSilent().then(function (user) {\n            _Log.Log.debug(\"SilentRenewService._tokenExpiring: Silent token renewal successful\");\n        }, function (err) {\n            _Log.Log.error(\"SilentRenewService._tokenExpiring: Error from signinSilent:\", err.message);\n            _this._userManager.events._raiseSilentRenewError(err);\n        });\n    };\n\n    return SilentRenewService;\n}();\n\n/***/ }),\n\n/***/ \"./src/State.js\":\n/*!**********************!*\\\n  !*** ./src/State.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.State = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _random = __webpack_require__(/*! ./random.js */ \"./src/random.js\");\n\nvar _random2 = _interopRequireDefault(_random);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar State = exports.State = function () {\n    function State() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            id = _ref.id,\n            data = _ref.data,\n            created = _ref.created,\n            request_type = _ref.request_type;\n\n        _classCallCheck(this, State);\n\n        this._id = id || (0, _random2.default)();\n        this._data = data;\n\n        if (typeof created === 'number' && created > 0) {\n            this._created = created;\n        } else {\n            this._created = parseInt(Date.now() / 1000);\n        }\n        this._request_type = request_type;\n    }\n\n    State.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"State.toStorageString\");\n        return JSON.stringify({\n            id: this.id,\n            data: this.data,\n            created: this.created,\n            request_type: this.request_type\n        });\n    };\n\n    State.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"State.fromStorageString\");\n        return new State(JSON.parse(storageString));\n    };\n\n    State.clearStaleState = function clearStaleState(storage, age) {\n\n        var cutoff = Date.now() / 1000 - age;\n\n        return storage.getAllKeys().then(function (keys) {\n            _Log.Log.debug(\"State.clearStaleState: got keys\", keys);\n\n            var promises = [];\n\n            var _loop = function _loop(i) {\n                var key = keys[i];\n                p = storage.get(key).then(function (item) {\n                    var remove = false;\n\n                    if (item) {\n                        try {\n                            var state = State.fromStorageString(item);\n\n                            _Log.Log.debug(\"State.clearStaleState: got item from key: \", key, state.created);\n\n                            if (state.created <= cutoff) {\n                                remove = true;\n                            }\n                        } catch (e) {\n                            _Log.Log.error(\"State.clearStaleState: Error parsing state for key\", key, e.message);\n                            remove = true;\n                        }\n                    } else {\n                        _Log.Log.debug(\"State.clearStaleState: no item in storage for key: \", key);\n                        remove = true;\n                    }\n\n                    if (remove) {\n                        _Log.Log.debug(\"State.clearStaleState: removed item for key: \", key);\n                        return storage.remove(key);\n                    }\n                });\n\n\n                promises.push(p);\n            };\n\n            for (var i = 0; i < keys.length; i++) {\n                var p;\n\n                _loop(i);\n            }\n\n            _Log.Log.debug(\"State.clearStaleState: waiting on promise count:\", promises.length);\n            return Promise.all(promises);\n        });\n    };\n\n    _createClass(State, [{\n        key: 'id',\n        get: function get() {\n            return this._id;\n        }\n    }, {\n        key: 'data',\n        get: function get() {\n            return this._data;\n        }\n    }, {\n        key: 'created',\n        get: function get() {\n            return this._created;\n        }\n    }, {\n        key: 'request_type',\n        get: function get() {\n            return this._request_type;\n        }\n    }]);\n\n    return State;\n}();\n\n/***/ }),\n\n/***/ \"./src/Timer.js\":\n/*!**********************!*\\\n  !*** ./src/Timer.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.Timer = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nvar _Event2 = __webpack_require__(/*! ./Event.js */ \"./src/Event.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar TimerDuration = 5; // seconds\n\nvar Timer = exports.Timer = function (_Event) {\n    _inherits(Timer, _Event);\n\n    function Timer(name) {\n        var timer = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.timer;\n        var nowFunc = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : undefined;\n\n        _classCallCheck(this, Timer);\n\n        var _this = _possibleConstructorReturn(this, _Event.call(this, name));\n\n        _this._timer = timer;\n\n        if (nowFunc) {\n            _this._nowFunc = nowFunc;\n        } else {\n            _this._nowFunc = function () {\n                return Date.now() / 1000;\n            };\n        }\n        return _this;\n    }\n\n    Timer.prototype.init = function init(duration) {\n        if (duration <= 0) {\n            duration = 1;\n        }\n        duration = parseInt(duration);\n\n        var expiration = this.now + duration;\n        if (this.expiration === expiration && this._timerHandle) {\n            // no need to reinitialize to same expiration, so bail out\n            _Log.Log.debug(\"Timer.init timer \" + this._name + \" skipping initialization since already initialized for expiration:\", this.expiration);\n            return;\n        }\n\n        this.cancel();\n\n        _Log.Log.debug(\"Timer.init timer \" + this._name + \" for duration:\", duration);\n        this._expiration = expiration;\n\n        // we're using a fairly short timer and then checking the expiration in the\n        // callback to handle scenarios where the browser device sleeps, and then\n        // the timers end up getting delayed.\n        var timerDuration = TimerDuration;\n        if (duration < timerDuration) {\n            timerDuration = duration;\n        }\n        this._timerHandle = this._timer.setInterval(this._callback.bind(this), timerDuration * 1000);\n    };\n\n    Timer.prototype.cancel = function cancel() {\n        if (this._timerHandle) {\n            _Log.Log.debug(\"Timer.cancel: \", this._name);\n            this._timer.clearInterval(this._timerHandle);\n            this._timerHandle = null;\n        }\n    };\n\n    Timer.prototype._callback = function _callback() {\n        var diff = this._expiration - this.now;\n        _Log.Log.debug(\"Timer.callback; \" + this._name + \" timer expires in:\", diff);\n\n        if (this._expiration <= this.now) {\n            this.cancel();\n            _Event.prototype.raise.call(this);\n        }\n    };\n\n    _createClass(Timer, [{\n        key: 'now',\n        get: function get() {\n            return parseInt(this._nowFunc());\n        }\n    }, {\n        key: 'expiration',\n        get: function get() {\n            return this._expiration;\n        }\n    }]);\n\n    return Timer;\n}(_Event2.Event);\n\n/***/ }),\n\n/***/ \"./src/TokenClient.js\":\n/*!****************************!*\\\n  !*** ./src/TokenClient.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.TokenClient = undefined;\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar TokenClient = exports.TokenClient = function () {\n    function TokenClient(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n\n        _classCallCheck(this, TokenClient);\n\n        if (!settings) {\n            _Log.Log.error(\"TokenClient.ctor: No settings passed\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor();\n        this._metadataService = new MetadataServiceCtor(this._settings);\n    }\n\n    TokenClient.prototype.exchangeCode = function exchangeCode() {\n        var _this = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.grant_type = args.grant_type || \"authorization_code\";\n        args.client_id = args.client_id || this._settings.client_id;\n        args.redirect_uri = args.redirect_uri || this._settings.redirect_uri;\n\n        if (!args.code) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No code passed\");\n            return Promise.reject(new Error(\"A code is required\"));\n        }\n        if (!args.redirect_uri) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No redirect_uri passed\");\n            return Promise.reject(new Error(\"A redirect_uri is required\"));\n        }\n        if (!args.code_verifier) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No code_verifier passed\");\n            return Promise.reject(new Error(\"A code_verifier is required\"));\n        }\n        if (!args.client_id) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No client_id passed\");\n            return Promise.reject(new Error(\"A client_id is required\"));\n        }\n\n        return this._metadataService.getTokenEndpoint(false).then(function (url) {\n            _Log.Log.debug(\"TokenClient.exchangeCode: Received token endpoint\");\n\n            return _this._jsonService.postForm(url, args).then(function (response) {\n                _Log.Log.debug(\"TokenClient.exchangeCode: response received\");\n                return response;\n            });\n        });\n    };\n\n    TokenClient.prototype.exchangeRefreshToken = function exchangeRefreshToken() {\n        var _this2 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.grant_type = args.grant_type || \"refresh_token\";\n        args.client_id = args.client_id || this._settings.client_id;\n        args.client_secret = args.client_secret || this._settings.client_secret;\n\n        if (!args.refresh_token) {\n            _Log.Log.error(\"TokenClient.exchangeRefreshToken: No refresh_token passed\");\n            return Promise.reject(new Error(\"A refresh_token is required\"));\n        }\n        if (!args.client_id) {\n            _Log.Log.error(\"TokenClient.exchangeRefreshToken: No client_id passed\");\n            return Promise.reject(new Error(\"A client_id is required\"));\n        }\n\n        return this._metadataService.getTokenEndpoint(false).then(function (url) {\n            _Log.Log.debug(\"TokenClient.exchangeRefreshToken: Received token endpoint\");\n\n            return _this2._jsonService.postForm(url, args).then(function (response) {\n                _Log.Log.debug(\"TokenClient.exchangeRefreshToken: response received\");\n                return response;\n            });\n        });\n    };\n\n    return TokenClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/TokenRevocationClient.js\":\n/*!**************************************!*\\\n  !*** ./src/TokenRevocationClient.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.TokenRevocationClient = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar AccessTokenTypeHint = \"access_token\";\nvar RefreshTokenTypeHint = \"refresh_token\";\n\nvar TokenRevocationClient = exports.TokenRevocationClient = function () {\n    function TokenRevocationClient(settings) {\n        var XMLHttpRequestCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.XMLHttpRequest;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n\n        _classCallCheck(this, TokenRevocationClient);\n\n        if (!settings) {\n            _Log.Log.error(\"TokenRevocationClient.ctor: No settings provided\");\n            throw new Error(\"No settings provided.\");\n        }\n\n        this._settings = settings;\n        this._XMLHttpRequestCtor = XMLHttpRequestCtor;\n        this._metadataService = new MetadataServiceCtor(this._settings);\n    }\n\n    TokenRevocationClient.prototype.revoke = function revoke(token, required) {\n        var _this = this;\n\n        var type = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : \"access_token\";\n\n        if (!token) {\n            _Log.Log.error(\"TokenRevocationClient.revoke: No token provided\");\n            throw new Error(\"No token provided.\");\n        }\n\n        if (type !== AccessTokenTypeHint && type != RefreshTokenTypeHint) {\n            _Log.Log.error(\"TokenRevocationClient.revoke: Invalid token type\");\n            throw new Error(\"Invalid token type.\");\n        }\n\n        return this._metadataService.getRevocationEndpoint().then(function (url) {\n            if (!url) {\n                if (required) {\n                    _Log.Log.error(\"TokenRevocationClient.revoke: Revocation not supported\");\n                    throw new Error(\"Revocation not supported\");\n                }\n\n                // not required, so don't error and just return\n                return;\n            }\n\n            _Log.Log.debug(\"TokenRevocationClient.revoke: Revoking \" + type);\n            var client_id = _this._settings.client_id;\n            var client_secret = _this._settings.client_secret;\n            return _this._revoke(url, client_id, client_secret, token, type);\n        });\n    };\n\n    TokenRevocationClient.prototype._revoke = function _revoke(url, client_id, client_secret, token, type) {\n        var _this2 = this;\n\n        return new Promise(function (resolve, reject) {\n\n            var xhr = new _this2._XMLHttpRequestCtor();\n            xhr.open(\"POST\", url);\n\n            xhr.onload = function () {\n                _Log.Log.debug(\"TokenRevocationClient.revoke: HTTP response received, status\", xhr.status);\n\n                if (xhr.status === 200) {\n                    resolve();\n                } else {\n                    reject(Error(xhr.statusText + \" (\" + xhr.status + \")\"));\n                }\n            };\n            xhr.onerror = function () {\n                _Log.Log.debug(\"TokenRevocationClient.revoke: Network Error.\");\n                reject(\"Network Error\");\n            };\n\n            var body = \"client_id=\" + encodeURIComponent(client_id);\n            if (client_secret) {\n                body += \"&client_secret=\" + encodeURIComponent(client_secret);\n            }\n            body += \"&token_type_hint=\" + encodeURIComponent(type);\n            body += \"&token=\" + encodeURIComponent(token);\n\n            xhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\n            xhr.send(body);\n        });\n    };\n\n    return TokenRevocationClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/UrlUtility.js\":\n/*!***************************!*\\\n  !*** ./src/UrlUtility.js ***!\n  \\***************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UrlUtility = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UrlUtility = exports.UrlUtility = function () {\n    function UrlUtility() {\n        _classCallCheck(this, UrlUtility);\n    }\n\n    UrlUtility.addQueryParam = function addQueryParam(url, name, value) {\n        if (url.indexOf('?') < 0) {\n            url += \"?\";\n        }\n\n        if (url[url.length - 1] !== \"?\") {\n            url += \"&\";\n        }\n\n        url += encodeURIComponent(name);\n        url += \"=\";\n        url += encodeURIComponent(value);\n\n        return url;\n    };\n\n    UrlUtility.parseUrlFragment = function parseUrlFragment(value) {\n        var delimiter = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : \"#\";\n        var global = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _Global.Global;\n\n        if (typeof value !== 'string') {\n            value = global.location.href;\n        }\n\n        var idx = value.lastIndexOf(delimiter);\n        if (idx >= 0) {\n            value = value.substr(idx + 1);\n        }\n\n        if (delimiter === \"?\") {\n            // if we're doing query, then strip off hash fragment before we parse\n            idx = value.indexOf('#');\n            if (idx >= 0) {\n                value = value.substr(0, idx);\n            }\n        }\n\n        var params = {},\n            regex = /([^&=]+)=([^&]*)/g,\n            m;\n\n        var counter = 0;\n        while (m = regex.exec(value)) {\n            params[decodeURIComponent(m[1])] = decodeURIComponent(m[2]);\n            if (counter++ > 50) {\n                _Log.Log.error(\"UrlUtility.parseUrlFragment: response exceeded expected number of parameters\", value);\n                return {\n                    error: \"Response exceeded expected number of parameters\"\n                };\n            }\n        }\n\n        for (var prop in params) {\n            return params;\n        }\n\n        return {};\n    };\n\n    return UrlUtility;\n}();\n\n/***/ }),\n\n/***/ \"./src/User.js\":\n/*!*********************!*\\\n  !*** ./src/User.js ***!\n  \\*********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.User = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar User = exports.User = function () {\n    function User(_ref) {\n        var id_token = _ref.id_token,\n            session_state = _ref.session_state,\n            access_token = _ref.access_token,\n            refresh_token = _ref.refresh_token,\n            token_type = _ref.token_type,\n            scope = _ref.scope,\n            profile = _ref.profile,\n            expires_at = _ref.expires_at,\n            state = _ref.state;\n\n        _classCallCheck(this, User);\n\n        this.id_token = id_token;\n        this.session_state = session_state;\n        this.access_token = access_token;\n        this.refresh_token = refresh_token;\n        this.token_type = token_type;\n        this.scope = scope;\n        this.profile = profile;\n        this.expires_at = expires_at;\n        this.state = state;\n    }\n\n    User.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"User.toStorageString\");\n        return JSON.stringify({\n            id_token: this.id_token,\n            session_state: this.session_state,\n            access_token: this.access_token,\n            refresh_token: this.refresh_token,\n            token_type: this.token_type,\n            scope: this.scope,\n            profile: this.profile,\n            expires_at: this.expires_at\n        });\n    };\n\n    User.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"User.fromStorageString\");\n        return new User(JSON.parse(storageString));\n    };\n\n    _createClass(User, [{\n        key: 'expires_in',\n        get: function get() {\n            if (this.expires_at) {\n                var now = parseInt(Date.now() / 1000);\n                return this.expires_at - now;\n            }\n            return undefined;\n        },\n        set: function set(value) {\n            var expires_in = parseInt(value);\n            if (typeof expires_in === 'number' && expires_in > 0) {\n                var now = parseInt(Date.now() / 1000);\n                this.expires_at = now + expires_in;\n            }\n        }\n    }, {\n        key: 'expired',\n        get: function get() {\n            var expires_in = this.expires_in;\n            if (expires_in !== undefined) {\n                return expires_in <= 0;\n            }\n            return undefined;\n        }\n    }, {\n        key: 'scopes',\n        get: function get() {\n            return (this.scope || \"\").split(\" \");\n        }\n    }]);\n\n    return User;\n}();\n\n/***/ }),\n\n/***/ \"./src/UserInfoService.js\":\n/*!********************************!*\\\n  !*** ./src/UserInfoService.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserInfoService = undefined;\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserInfoService = exports.UserInfoService = function () {\n    function UserInfoService(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n        var joseUtil = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _JoseUtil.JoseUtil;\n\n        _classCallCheck(this, UserInfoService);\n\n        if (!settings) {\n            _Log.Log.error(\"UserInfoService.ctor: No settings passed\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor(undefined, undefined, this._getClaimsFromJwt.bind(this));\n        this._metadataService = new MetadataServiceCtor(this._settings);\n        this._joseUtil = joseUtil;\n    }\n\n    UserInfoService.prototype.getClaims = function getClaims(token) {\n        var _this = this;\n\n        if (!token) {\n            _Log.Log.error(\"UserInfoService.getClaims: No token passed\");\n            return Promise.reject(new Error(\"A token is required\"));\n        }\n\n        return this._metadataService.getUserInfoEndpoint().then(function (url) {\n            _Log.Log.debug(\"UserInfoService.getClaims: received userinfo url\", url);\n\n            return _this._jsonService.getJson(url, token).then(function (claims) {\n                _Log.Log.debug(\"UserInfoService.getClaims: claims received\", claims);\n                return claims;\n            });\n        });\n    };\n\n    UserInfoService.prototype._getClaimsFromJwt = function _getClaimsFromJwt(req) {\n        var _this2 = this;\n\n        try {\n            var jwt = this._joseUtil.parseJwt(req.responseText);\n            if (!jwt || !jwt.header || !jwt.payload) {\n                _Log.Log.error(\"UserInfoService._getClaimsFromJwt: Failed to parse JWT\", jwt);\n                return Promise.reject(new Error(\"Failed to parse id_token\"));\n            }\n\n            var kid = jwt.header.kid;\n\n            var issuerPromise = void 0;\n            switch (this._settings.userInfoJwtIssuer) {\n                case 'OP':\n                    issuerPromise = this._metadataService.getIssuer();\n                    break;\n                case 'ANY':\n                    issuerPromise = Promise.resolve(jwt.payload.iss);\n                    break;\n                default:\n                    issuerPromise = Promise.resolve(this._settings.userInfoJwtIssuer);\n                    break;\n            }\n\n            return issuerPromise.then(function (issuer) {\n                _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Received issuer:\" + issuer);\n\n                return _this2._metadataService.getSigningKeys().then(function (keys) {\n                    if (!keys) {\n                        _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No signing keys from metadata\");\n                        return Promise.reject(new Error(\"No signing keys from metadata\"));\n                    }\n\n                    _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Received signing keys\");\n                    var key = void 0;\n                    if (!kid) {\n                        keys = _this2._filterByAlg(keys, jwt.header.alg);\n\n                        if (keys.length > 1) {\n                            _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No kid found in id_token and more than one key found in metadata\");\n                            return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\n                        } else {\n                            // kid is mandatory only when there are multiple keys in the referenced JWK Set document\n                            // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\n                            key = keys[0];\n                        }\n                    } else {\n                        key = keys.filter(function (key) {\n                            return key.kid === kid;\n                        })[0];\n                    }\n\n                    if (!key) {\n                        _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No key matching kid or alg found in signing keys\");\n                        return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\n                    }\n\n                    var audience = _this2._settings.client_id;\n\n                    var clockSkewInSeconds = _this2._settings.clockSkew;\n                    _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n                    return _this2._joseUtil.validateJwt(req.responseText, key, issuer, audience, clockSkewInSeconds, undefined, true).then(function () {\n                        _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: JWT validation successful\");\n                        return jwt.payload;\n                    });\n                });\n            });\n            return;\n        } catch (e) {\n            _Log.Log.error(\"UserInfoService._getClaimsFromJwt: Error parsing JWT response\", e.message);\n            reject(e);\n            return;\n        }\n    };\n\n    UserInfoService.prototype._filterByAlg = function _filterByAlg(keys, alg) {\n        var kty = null;\n        if (alg.startsWith(\"RS\")) {\n            kty = \"RSA\";\n        } else if (alg.startsWith(\"PS\")) {\n            kty = \"PS\";\n        } else if (alg.startsWith(\"ES\")) {\n            kty = \"EC\";\n        } else {\n            _Log.Log.debug(\"UserInfoService._filterByAlg: alg not supported: \", alg);\n            return [];\n        }\n\n        _Log.Log.debug(\"UserInfoService._filterByAlg: Looking for keys that match kty: \", kty);\n\n        keys = keys.filter(function (key) {\n            return key.kty === kty;\n        });\n\n        _Log.Log.debug(\"UserInfoService._filterByAlg: Number of keys that match kty: \", kty, keys.length);\n\n        return keys;\n    };\n\n    return UserInfoService;\n}();\n\n/***/ }),\n\n/***/ \"./src/UserManager.js\":\n/*!****************************!*\\\n  !*** ./src/UserManager.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManager = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClient2 = __webpack_require__(/*! ./OidcClient.js */ \"./src/OidcClient.js\");\n\nvar _UserManagerSettings = __webpack_require__(/*! ./UserManagerSettings.js */ \"./src/UserManagerSettings.js\");\n\nvar _User = __webpack_require__(/*! ./User.js */ \"./src/User.js\");\n\nvar _UserManagerEvents = __webpack_require__(/*! ./UserManagerEvents.js */ \"./src/UserManagerEvents.js\");\n\nvar _SilentRenewService = __webpack_require__(/*! ./SilentRenewService.js */ \"./src/SilentRenewService.js\");\n\nvar _SessionMonitor = __webpack_require__(/*! ./SessionMonitor.js */ \"./src/SessionMonitor.js\");\n\nvar _TokenRevocationClient = __webpack_require__(/*! ./TokenRevocationClient.js */ \"./src/TokenRevocationClient.js\");\n\nvar _TokenClient = __webpack_require__(/*! ./TokenClient.js */ \"./src/TokenClient.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserManager = exports.UserManager = function (_OidcClient) {\n    _inherits(UserManager, _OidcClient);\n\n    function UserManager() {\n        var settings = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n        var SilentRenewServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _SilentRenewService.SilentRenewService;\n        var SessionMonitorCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _SessionMonitor.SessionMonitor;\n        var TokenRevocationClientCtor = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _TokenRevocationClient.TokenRevocationClient;\n        var TokenClientCtor = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : _TokenClient.TokenClient;\n        var joseUtil = arguments.length > 5 && arguments[5] !== undefined ? arguments[5] : _JoseUtil.JoseUtil;\n\n        _classCallCheck(this, UserManager);\n\n        if (!(settings instanceof _UserManagerSettings.UserManagerSettings)) {\n            settings = new _UserManagerSettings.UserManagerSettings(settings);\n        }\n\n        var _this = _possibleConstructorReturn(this, _OidcClient.call(this, settings));\n\n        _this._events = new _UserManagerEvents.UserManagerEvents(settings);\n        _this._silentRenewService = new SilentRenewServiceCtor(_this);\n\n        // order is important for the following properties; these services depend upon the events.\n        if (_this.settings.automaticSilentRenew) {\n            _Log.Log.debug(\"UserManager.ctor: automaticSilentRenew is configured, setting up silent renew\");\n            _this.startSilentRenew();\n        }\n\n        if (_this.settings.monitorSession) {\n            _Log.Log.debug(\"UserManager.ctor: monitorSession is configured, setting up session monitor\");\n            _this._sessionMonitor = new SessionMonitorCtor(_this);\n        }\n\n        _this._tokenRevocationClient = new TokenRevocationClientCtor(_this._settings);\n        _this._tokenClient = new TokenClientCtor(_this._settings);\n        _this._joseUtil = joseUtil;\n        return _this;\n    }\n\n    UserManager.prototype.getUser = function getUser() {\n        var _this2 = this;\n\n        return this._loadUser().then(function (user) {\n            if (user) {\n                _Log.Log.info(\"UserManager.getUser: user loaded\");\n\n                _this2._events.load(user, false);\n\n                return user;\n            } else {\n                _Log.Log.info(\"UserManager.getUser: user not found in storage\");\n                return null;\n            }\n        });\n    };\n\n    UserManager.prototype.removeUser = function removeUser() {\n        var _this3 = this;\n\n        return this.storeUser(null).then(function () {\n            _Log.Log.info(\"UserManager.removeUser: user removed from storage\");\n            _this3._events.unload();\n        });\n    };\n\n    UserManager.prototype.signinRedirect = function signinRedirect() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:r\";\n        var navParams = {\n            useReplaceToNavigate: args.useReplaceToNavigate\n        };\n        return this._signinStart(args, this._redirectNavigator, navParams).then(function () {\n            _Log.Log.info(\"UserManager.signinRedirect: successful\");\n        });\n    };\n\n    UserManager.prototype.signinRedirectCallback = function signinRedirectCallback(url) {\n        return this._signinEnd(url || this._redirectNavigator.url).then(function (user) {\n            if (user.profile && user.profile.sub) {\n                _Log.Log.info(\"UserManager.signinRedirectCallback: successful, signed in sub: \", user.profile.sub);\n            } else {\n                _Log.Log.info(\"UserManager.signinRedirectCallback: no sub\");\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinPopup = function signinPopup() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:p\";\n        var url = args.redirect_uri || this.settings.popup_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.signinPopup: No popup_redirect_uri or redirect_uri configured\");\n            return Promise.reject(new Error(\"No popup_redirect_uri or redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.display = \"popup\";\n\n        return this._signin(args, this._popupNavigator, {\n            startUrl: url,\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\n        }).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinPopup: signinPopup successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinPopup: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinPopupCallback = function signinPopupCallback(url) {\n        return this._signinCallback(url, this._popupNavigator).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinPopupCallback: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinPopupCallback: no sub\");\n                }\n            }\n\n            return user;\n        }).catch(function (err) {\n            _Log.Log.error( true && err.message);\n        });\n    };\n\n    UserManager.prototype.signinSilent = function signinSilent() {\n        var _this4 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:s\";\n        // first determine if we have a refresh token, or need to use iframe\n        return this._loadUser().then(function (user) {\n            if (user && user.refresh_token) {\n                args.refresh_token = user.refresh_token;\n                return _this4._useRefreshToken(args);\n            } else {\n                args.id_token_hint = args.id_token_hint || _this4.settings.includeIdTokenInSilentRenew && user && user.id_token;\n                if (user && _this4._settings.validateSubOnSilentRenew) {\n                    _Log.Log.debug(\"UserManager.signinSilent, subject prior to silent renew: \", user.profile.sub);\n                    args.current_sub = user.profile.sub;\n                }\n                return _this4._signinSilentIframe(args);\n            }\n        });\n    };\n\n    UserManager.prototype._useRefreshToken = function _useRefreshToken() {\n        var _this5 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        return this._tokenClient.exchangeRefreshToken(args).then(function (result) {\n            if (!result) {\n                _Log.Log.error(\"UserManager._useRefreshToken: No response returned from token endpoint\");\n                return Promise.reject(\"No response returned from token endpoint\");\n            }\n            if (!result.access_token) {\n                _Log.Log.error(\"UserManager._useRefreshToken: No access token returned from token endpoint\");\n                return Promise.reject(\"No access token returned from token endpoint\");\n            }\n\n            return _this5._loadUser().then(function (user) {\n                if (user) {\n                    var idTokenValidation = Promise.resolve();\n                    if (result.id_token) {\n                        idTokenValidation = _this5._validateIdTokenFromTokenRefreshToken(user.profile, result.id_token);\n                    }\n\n                    return idTokenValidation.then(function () {\n                        _Log.Log.debug(\"UserManager._useRefreshToken: refresh token response success\");\n                        user.id_token = result.id_token;\n                        user.access_token = result.access_token;\n                        user.refresh_token = result.refresh_token || user.refresh_token;\n                        user.expires_in = result.expires_in;\n\n                        return _this5.storeUser(user).then(function () {\n                            _this5._events.load(user);\n                            return user;\n                        });\n                    });\n                } else {\n                    return null;\n                }\n            });\n        });\n    };\n\n    UserManager.prototype._validateIdTokenFromTokenRefreshToken = function _validateIdTokenFromTokenRefreshToken(profile, id_token) {\n        var _this6 = this;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n            return _this6._joseUtil.validateJwtAttributes(id_token, issuer, _this6._settings.client_id, _this6._settings.clockSkew).then(function (payload) {\n                if (!payload) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: Failed to validate id_token\");\n                    return Promise.reject(new Error(\"Failed to validate id_token\"));\n                }\n                if (payload.sub !== profile.sub) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: sub in id_token does not match current sub\");\n                    return Promise.reject(new Error(\"sub in id_token does not match current sub\"));\n                }\n                if (payload.auth_time && payload.auth_time !== profile.auth_time) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: auth_time in id_token does not match original auth_time\");\n                    return Promise.reject(new Error(\"auth_time in id_token does not match original auth_time\"));\n                }\n                if (payload.azp && payload.azp !== profile.azp) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp in id_token does not match original azp\");\n                    return Promise.reject(new Error(\"azp in id_token does not match original azp\"));\n                }\n                if (!payload.azp && profile.azp) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp not in id_token, but present in original id_token\");\n                    return Promise.reject(new Error(\"azp not in id_token, but present in original id_token\"));\n                }\n            });\n        });\n    };\n\n    UserManager.prototype._signinSilentIframe = function _signinSilentIframe() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        var url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.signinSilent: No silent_redirect_uri configured\");\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.prompt = args.prompt || \"none\";\n\n        return this._signin(args, this._iframeNavigator, {\n            startUrl: url,\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\n        }).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinSilent: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinSilent: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinSilentCallback = function signinSilentCallback(url) {\n        return this._signinCallback(url, this._iframeNavigator).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinSilentCallback: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinSilentCallback: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinCallback = function signinCallback(url) {\n        var _this7 = this;\n\n        return this.readSigninResponseState(url).then(function (_ref) {\n            var state = _ref.state,\n                response = _ref.response;\n\n            if (state.request_type === \"si:r\") {\n                return _this7.signinRedirectCallback(url);\n            }\n            if (state.request_type === \"si:p\") {\n                return _this7.signinPopupCallback(url);\n            }\n            if (state.request_type === \"si:s\") {\n                return _this7.signinSilentCallback(url);\n            }\n            return Promise.reject(new Error(\"invalid response_type in state\"));\n        });\n    };\n\n    UserManager.prototype.signoutCallback = function signoutCallback(url, keepOpen) {\n        var _this8 = this;\n\n        return this.readSignoutResponseState(url).then(function (_ref2) {\n            var state = _ref2.state,\n                response = _ref2.response;\n\n            if (state) {\n                if (state.request_type === \"so:r\") {\n                    return _this8.signoutRedirectCallback(url);\n                }\n                if (state.request_type === \"so:p\") {\n                    return _this8.signoutPopupCallback(url, keepOpen);\n                }\n                return Promise.reject(new Error(\"invalid response_type in state\"));\n            }\n            return response;\n        });\n    };\n\n    UserManager.prototype.querySessionStatus = function querySessionStatus() {\n        var _this9 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:s\"; // this acts like a signin silent\n        var url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.querySessionStatus: No silent_redirect_uri configured\");\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.prompt = \"none\";\n        args.response_type = args.response_type || this.settings.query_status_response_type;\n        args.scope = args.scope || \"openid\";\n        args.skipUserInfo = true;\n\n        return this._signinStart(args, this._iframeNavigator, {\n            startUrl: url,\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\n        }).then(function (navResponse) {\n            return _this9.processSigninResponse(navResponse.url).then(function (signinResponse) {\n                _Log.Log.debug(\"UserManager.querySessionStatus: got signin response\");\n\n                if (signinResponse.session_state && signinResponse.profile.sub) {\n                    _Log.Log.info(\"UserManager.querySessionStatus: querySessionStatus success for sub: \", signinResponse.profile.sub);\n                    return {\n                        session_state: signinResponse.session_state,\n                        sub: signinResponse.profile.sub,\n                        sid: signinResponse.profile.sid\n                    };\n                } else {\n                    _Log.Log.info(\"querySessionStatus successful, user not authenticated\");\n                }\n            }).catch(function (err) {\n                if (err.session_state && _this9.settings.monitorAnonymousSession) {\n                    if (err.message == \"login_required\" || err.message == \"consent_required\" || err.message == \"interaction_required\" || err.message == \"account_selection_required\") {\n                        _Log.Log.info(\"UserManager.querySessionStatus: querySessionStatus success for anonymous user\");\n                        return {\n                            session_state: err.session_state\n                        };\n                    }\n                }\n\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signin = function _signin(args, navigator) {\n        var _this10 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return this._signinStart(args, navigator, navigatorParams).then(function (navResponse) {\n            return _this10._signinEnd(navResponse.url, args);\n        });\n    };\n\n    UserManager.prototype._signinStart = function _signinStart(args, navigator) {\n        var _this11 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n\n        return navigator.prepare(navigatorParams).then(function (handle) {\n            _Log.Log.debug(\"UserManager._signinStart: got navigator window handle\");\n\n            return _this11.createSigninRequest(args).then(function (signinRequest) {\n                _Log.Log.debug(\"UserManager._signinStart: got signin request\");\n\n                navigatorParams.url = signinRequest.url;\n                navigatorParams.id = signinRequest.state.id;\n\n                return handle.navigate(navigatorParams);\n            }).catch(function (err) {\n                if (handle.close) {\n                    _Log.Log.debug(\"UserManager._signinStart: Error after preparing navigator, closing navigator window\");\n                    handle.close();\n                }\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signinEnd = function _signinEnd(url) {\n        var _this12 = this;\n\n        var args = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {};\n\n        return this.processSigninResponse(url).then(function (signinResponse) {\n            _Log.Log.debug(\"UserManager._signinEnd: got signin response\");\n\n            var user = new _User.User(signinResponse);\n\n            if (args.current_sub) {\n                if (args.current_sub !== user.profile.sub) {\n                    _Log.Log.debug(\"UserManager._signinEnd: current user does not match user returned from signin. sub from signin: \", user.profile.sub);\n                    return Promise.reject(new Error(\"login_required\"));\n                } else {\n                    _Log.Log.debug(\"UserManager._signinEnd: current user matches user returned from signin\");\n                }\n            }\n\n            return _this12.storeUser(user).then(function () {\n                _Log.Log.debug(\"UserManager._signinEnd: user stored\");\n\n                _this12._events.load(user);\n\n                return user;\n            });\n        });\n    };\n\n    UserManager.prototype._signinCallback = function _signinCallback(url, navigator) {\n        _Log.Log.debug(\"UserManager._signinCallback\");\n        return navigator.callback(url);\n    };\n\n    UserManager.prototype.signoutRedirect = function signoutRedirect() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"so:r\";\n        var postLogoutRedirectUri = args.post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\n        if (postLogoutRedirectUri) {\n            args.post_logout_redirect_uri = postLogoutRedirectUri;\n        }\n        var navParams = {\n            useReplaceToNavigate: args.useReplaceToNavigate\n        };\n        return this._signoutStart(args, this._redirectNavigator, navParams).then(function () {\n            _Log.Log.info(\"UserManager.signoutRedirect: successful\");\n        });\n    };\n\n    UserManager.prototype.signoutRedirectCallback = function signoutRedirectCallback(url) {\n        return this._signoutEnd(url || this._redirectNavigator.url).then(function (response) {\n            _Log.Log.info(\"UserManager.signoutRedirectCallback: successful\");\n            return response;\n        });\n    };\n\n    UserManager.prototype.signoutPopup = function signoutPopup() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"so:p\";\n        var url = args.post_logout_redirect_uri || this.settings.popup_post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\n        args.post_logout_redirect_uri = url;\n        args.display = \"popup\";\n        if (args.post_logout_redirect_uri) {\n            // we're putting a dummy entry in here because we\n            // need a unique id from the state for notification\n            // to the parent window, which is necessary if we\n            // plan to return back to the client after signout\n            // and so we can close the popup after signout\n            args.state = args.state || {};\n        }\n\n        return this._signout(args, this._popupNavigator, {\n            startUrl: url,\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\n        }).then(function () {\n            _Log.Log.info(\"UserManager.signoutPopup: successful\");\n        });\n    };\n\n    UserManager.prototype.signoutPopupCallback = function signoutPopupCallback(url, keepOpen) {\n        if (typeof keepOpen === 'undefined' && typeof url === 'boolean') {\n            keepOpen = url;\n            url = null;\n        }\n\n        var delimiter = '?';\n        return this._popupNavigator.callback(url, keepOpen, delimiter).then(function () {\n            _Log.Log.info(\"UserManager.signoutPopupCallback: successful\");\n        });\n    };\n\n    UserManager.prototype._signout = function _signout(args, navigator) {\n        var _this13 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return this._signoutStart(args, navigator, navigatorParams).then(function (navResponse) {\n            return _this13._signoutEnd(navResponse.url);\n        });\n    };\n\n    UserManager.prototype._signoutStart = function _signoutStart() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        var _this14 = this;\n\n        var navigator = arguments[1];\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return navigator.prepare(navigatorParams).then(function (handle) {\n            _Log.Log.debug(\"UserManager._signoutStart: got navigator window handle\");\n\n            return _this14._loadUser().then(function (user) {\n                _Log.Log.debug(\"UserManager._signoutStart: loaded current user from storage\");\n\n                var revokePromise = _this14._settings.revokeAccessTokenOnSignout ? _this14._revokeInternal(user) : Promise.resolve();\n                return revokePromise.then(function () {\n\n                    var id_token = args.id_token_hint || user && user.id_token;\n                    if (id_token) {\n                        _Log.Log.debug(\"UserManager._signoutStart: Setting id_token into signout request\");\n                        args.id_token_hint = id_token;\n                    }\n\n                    return _this14.removeUser().then(function () {\n                        _Log.Log.debug(\"UserManager._signoutStart: user removed, creating signout request\");\n\n                        return _this14.createSignoutRequest(args).then(function (signoutRequest) {\n                            _Log.Log.debug(\"UserManager._signoutStart: got signout request\");\n\n                            navigatorParams.url = signoutRequest.url;\n                            if (signoutRequest.state) {\n                                navigatorParams.id = signoutRequest.state.id;\n                            }\n                            return handle.navigate(navigatorParams);\n                        });\n                    });\n                });\n            }).catch(function (err) {\n                if (handle.close) {\n                    _Log.Log.debug(\"UserManager._signoutStart: Error after preparing navigator, closing navigator window\");\n                    handle.close();\n                }\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signoutEnd = function _signoutEnd(url) {\n        return this.processSignoutResponse(url).then(function (signoutResponse) {\n            _Log.Log.debug(\"UserManager._signoutEnd: got signout response\");\n\n            return signoutResponse;\n        });\n    };\n\n    UserManager.prototype.revokeAccessToken = function revokeAccessToken() {\n        var _this15 = this;\n\n        return this._loadUser().then(function (user) {\n            return _this15._revokeInternal(user, true).then(function (success) {\n                if (success) {\n                    _Log.Log.debug(\"UserManager.revokeAccessToken: removing token properties from user and re-storing\");\n\n                    user.access_token = null;\n                    user.refresh_token = null;\n                    user.expires_at = null;\n                    user.token_type = null;\n\n                    return _this15.storeUser(user).then(function () {\n                        _Log.Log.debug(\"UserManager.revokeAccessToken: user stored\");\n                        _this15._events.load(user);\n                    });\n                }\n            });\n        }).then(function () {\n            _Log.Log.info(\"UserManager.revokeAccessToken: access token revoked successfully\");\n        });\n    };\n\n    UserManager.prototype._revokeInternal = function _revokeInternal(user, required) {\n        var _this16 = this;\n\n        if (user) {\n            var access_token = user.access_token;\n            var refresh_token = user.refresh_token;\n\n            return this._revokeAccessTokenInternal(access_token, required).then(function (atSuccess) {\n                return _this16._revokeRefreshTokenInternal(refresh_token, required).then(function (rtSuccess) {\n                    if (!atSuccess && !rtSuccess) {\n                        _Log.Log.debug(\"UserManager.revokeAccessToken: no need to revoke due to no token(s), or JWT format\");\n                    }\n\n                    return atSuccess || rtSuccess;\n                });\n            });\n        }\n\n        return Promise.resolve(false);\n    };\n\n    UserManager.prototype._revokeAccessTokenInternal = function _revokeAccessTokenInternal(access_token, required) {\n        // check for JWT vs. reference token\n        if (!access_token || access_token.indexOf('.') >= 0) {\n            return Promise.resolve(false);\n        }\n\n        return this._tokenRevocationClient.revoke(access_token, required).then(function () {\n            return true;\n        });\n    };\n\n    UserManager.prototype._revokeRefreshTokenInternal = function _revokeRefreshTokenInternal(refresh_token, required) {\n        if (!refresh_token) {\n            return Promise.resolve(false);\n        }\n\n        return this._tokenRevocationClient.revoke(refresh_token, required, \"refresh_token\").then(function () {\n            return true;\n        });\n    };\n\n    UserManager.prototype.startSilentRenew = function startSilentRenew() {\n        this._silentRenewService.start();\n    };\n\n    UserManager.prototype.stopSilentRenew = function stopSilentRenew() {\n        this._silentRenewService.stop();\n    };\n\n    UserManager.prototype._loadUser = function _loadUser() {\n        return this._userStore.get(this._userStoreKey).then(function (storageString) {\n            if (storageString) {\n                _Log.Log.debug(\"UserManager._loadUser: user storageString loaded\");\n                return _User.User.fromStorageString(storageString);\n            }\n\n            _Log.Log.debug(\"UserManager._loadUser: no user storageString\");\n            return null;\n        });\n    };\n\n    UserManager.prototype.storeUser = function storeUser(user) {\n        if (user) {\n            _Log.Log.debug(\"UserManager.storeUser: storing user\");\n\n            var storageString = user.toStorageString();\n            return this._userStore.set(this._userStoreKey, storageString);\n        } else {\n            _Log.Log.debug(\"storeUser.storeUser: removing user\");\n            return this._userStore.remove(this._userStoreKey);\n        }\n    };\n\n    _createClass(UserManager, [{\n        key: '_redirectNavigator',\n        get: function get() {\n            return this.settings.redirectNavigator;\n        }\n    }, {\n        key: '_popupNavigator',\n        get: function get() {\n            return this.settings.popupNavigator;\n        }\n    }, {\n        key: '_iframeNavigator',\n        get: function get() {\n            return this.settings.iframeNavigator;\n        }\n    }, {\n        key: '_userStore',\n        get: function get() {\n            return this.settings.userStore;\n        }\n    }, {\n        key: 'events',\n        get: function get() {\n            return this._events;\n        }\n    }, {\n        key: '_userStoreKey',\n        get: function get() {\n            return 'user:' + this.settings.authority + ':' + this.settings.client_id;\n        }\n    }]);\n\n    return UserManager;\n}(_OidcClient2.OidcClient);\n\n/***/ }),\n\n/***/ \"./src/UserManagerEvents.js\":\n/*!**********************************!*\\\n  !*** ./src/UserManagerEvents.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManagerEvents = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _AccessTokenEvents2 = __webpack_require__(/*! ./AccessTokenEvents.js */ \"./src/AccessTokenEvents.js\");\n\nvar _Event = __webpack_require__(/*! ./Event.js */ \"./src/Event.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserManagerEvents = exports.UserManagerEvents = function (_AccessTokenEvents) {\n    _inherits(UserManagerEvents, _AccessTokenEvents);\n\n    function UserManagerEvents(settings) {\n        _classCallCheck(this, UserManagerEvents);\n\n        var _this = _possibleConstructorReturn(this, _AccessTokenEvents.call(this, settings));\n\n        _this._userLoaded = new _Event.Event(\"User loaded\");\n        _this._userUnloaded = new _Event.Event(\"User unloaded\");\n        _this._silentRenewError = new _Event.Event(\"Silent renew error\");\n        _this._userSignedIn = new _Event.Event(\"User signed in\");\n        _this._userSignedOut = new _Event.Event(\"User signed out\");\n        _this._userSessionChanged = new _Event.Event(\"User session changed\");\n        return _this;\n    }\n\n    UserManagerEvents.prototype.load = function load(user) {\n        var raiseEvent = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : true;\n\n        _Log.Log.debug(\"UserManagerEvents.load\");\n        _AccessTokenEvents.prototype.load.call(this, user);\n        if (raiseEvent) {\n            this._userLoaded.raise(user);\n        }\n    };\n\n    UserManagerEvents.prototype.unload = function unload() {\n        _Log.Log.debug(\"UserManagerEvents.unload\");\n        _AccessTokenEvents.prototype.unload.call(this);\n        this._userUnloaded.raise();\n    };\n\n    UserManagerEvents.prototype.addUserLoaded = function addUserLoaded(cb) {\n        this._userLoaded.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserLoaded = function removeUserLoaded(cb) {\n        this._userLoaded.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype.addUserUnloaded = function addUserUnloaded(cb) {\n        this._userUnloaded.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserUnloaded = function removeUserUnloaded(cb) {\n        this._userUnloaded.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype.addSilentRenewError = function addSilentRenewError(cb) {\n        this._silentRenewError.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeSilentRenewError = function removeSilentRenewError(cb) {\n        this._silentRenewError.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseSilentRenewError = function _raiseSilentRenewError(e) {\n        _Log.Log.debug(\"UserManagerEvents._raiseSilentRenewError\", e.message);\n        this._silentRenewError.raise(e);\n    };\n\n    UserManagerEvents.prototype.addUserSignedIn = function addUserSignedIn(cb) {\n        this._userSignedIn.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSignedIn = function removeUserSignedIn(cb) {\n        this._userSignedIn.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSignedIn = function _raiseUserSignedIn() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSignedIn\");\n        this._userSignedIn.raise();\n    };\n\n    UserManagerEvents.prototype.addUserSignedOut = function addUserSignedOut(cb) {\n        this._userSignedOut.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSignedOut = function removeUserSignedOut(cb) {\n        this._userSignedOut.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSignedOut = function _raiseUserSignedOut() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSignedOut\");\n        this._userSignedOut.raise();\n    };\n\n    UserManagerEvents.prototype.addUserSessionChanged = function addUserSessionChanged(cb) {\n        this._userSessionChanged.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSessionChanged = function removeUserSessionChanged(cb) {\n        this._userSessionChanged.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSessionChanged = function _raiseUserSessionChanged() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSessionChanged\");\n        this._userSessionChanged.raise();\n    };\n\n    return UserManagerEvents;\n}(_AccessTokenEvents2.AccessTokenEvents);\n\n/***/ }),\n\n/***/ \"./src/UserManagerSettings.js\":\n/*!************************************!*\\\n  !*** ./src/UserManagerSettings.js ***!\n  \\************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManagerSettings = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClientSettings2 = __webpack_require__(/*! ./OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _RedirectNavigator = __webpack_require__(/*! ./RedirectNavigator.js */ \"./src/RedirectNavigator.js\");\n\nvar _PopupNavigator = __webpack_require__(/*! ./PopupNavigator.js */ \"./src/PopupNavigator.js\");\n\nvar _IFrameNavigator = __webpack_require__(/*! ./IFrameNavigator.js */ \"./src/IFrameNavigator.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nvar _SigninRequest = __webpack_require__(/*! ./SigninRequest.js */ \"./src/SigninRequest.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultAccessTokenExpiringNotificationTime = 60;\nvar DefaultCheckSessionInterval = 2000;\n\nvar UserManagerSettings = exports.UserManagerSettings = function (_OidcClientSettings) {\n    _inherits(UserManagerSettings, _OidcClientSettings);\n\n    function UserManagerSettings() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            popup_redirect_uri = _ref.popup_redirect_uri,\n            popup_post_logout_redirect_uri = _ref.popup_post_logout_redirect_uri,\n            popupWindowFeatures = _ref.popupWindowFeatures,\n            popupWindowTarget = _ref.popupWindowTarget,\n            silent_redirect_uri = _ref.silent_redirect_uri,\n            silentRequestTimeout = _ref.silentRequestTimeout,\n            _ref$automaticSilentR = _ref.automaticSilentRenew,\n            automaticSilentRenew = _ref$automaticSilentR === undefined ? false : _ref$automaticSilentR,\n            _ref$validateSubOnSil = _ref.validateSubOnSilentRenew,\n            validateSubOnSilentRenew = _ref$validateSubOnSil === undefined ? false : _ref$validateSubOnSil,\n            _ref$includeIdTokenIn = _ref.includeIdTokenInSilentRenew,\n            includeIdTokenInSilentRenew = _ref$includeIdTokenIn === undefined ? true : _ref$includeIdTokenIn,\n            _ref$monitorSession = _ref.monitorSession,\n            monitorSession = _ref$monitorSession === undefined ? true : _ref$monitorSession,\n            _ref$monitorAnonymous = _ref.monitorAnonymousSession,\n            monitorAnonymousSession = _ref$monitorAnonymous === undefined ? false : _ref$monitorAnonymous,\n            _ref$checkSessionInte = _ref.checkSessionInterval,\n            checkSessionInterval = _ref$checkSessionInte === undefined ? DefaultCheckSessionInterval : _ref$checkSessionInte,\n            _ref$stopCheckSession = _ref.stopCheckSessionOnError,\n            stopCheckSessionOnError = _ref$stopCheckSession === undefined ? true : _ref$stopCheckSession,\n            query_status_response_type = _ref.query_status_response_type,\n            _ref$revokeAccessToke = _ref.revokeAccessTokenOnSignout,\n            revokeAccessTokenOnSignout = _ref$revokeAccessToke === undefined ? false : _ref$revokeAccessToke,\n            _ref$accessTokenExpir = _ref.accessTokenExpiringNotificationTime,\n            accessTokenExpiringNotificationTime = _ref$accessTokenExpir === undefined ? DefaultAccessTokenExpiringNotificationTime : _ref$accessTokenExpir,\n            _ref$redirectNavigato = _ref.redirectNavigator,\n            redirectNavigator = _ref$redirectNavigato === undefined ? new _RedirectNavigator.RedirectNavigator() : _ref$redirectNavigato,\n            _ref$popupNavigator = _ref.popupNavigator,\n            popupNavigator = _ref$popupNavigator === undefined ? new _PopupNavigator.PopupNavigator() : _ref$popupNavigator,\n            _ref$iframeNavigator = _ref.iframeNavigator,\n            iframeNavigator = _ref$iframeNavigator === undefined ? new _IFrameNavigator.IFrameNavigator() : _ref$iframeNavigator,\n            _ref$userStore = _ref.userStore,\n            userStore = _ref$userStore === undefined ? new _WebStorageStateStore.WebStorageStateStore({ store: _Global.Global.sessionStorage }) : _ref$userStore;\n\n        _classCallCheck(this, UserManagerSettings);\n\n        var _this = _possibleConstructorReturn(this, _OidcClientSettings.call(this, arguments[0]));\n\n        _this._popup_redirect_uri = popup_redirect_uri;\n        _this._popup_post_logout_redirect_uri = popup_post_logout_redirect_uri;\n        _this._popupWindowFeatures = popupWindowFeatures;\n        _this._popupWindowTarget = popupWindowTarget;\n\n        _this._silent_redirect_uri = silent_redirect_uri;\n        _this._silentRequestTimeout = silentRequestTimeout;\n        _this._automaticSilentRenew = automaticSilentRenew;\n        _this._validateSubOnSilentRenew = validateSubOnSilentRenew;\n        _this._includeIdTokenInSilentRenew = includeIdTokenInSilentRenew;\n        _this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\n\n        _this._monitorSession = monitorSession;\n        _this._monitorAnonymousSession = monitorAnonymousSession;\n        _this._checkSessionInterval = checkSessionInterval;\n        _this._stopCheckSessionOnError = stopCheckSessionOnError;\n        if (query_status_response_type) {\n            _this._query_status_response_type = query_status_response_type;\n        } else if (arguments[0] && arguments[0].response_type) {\n            _this._query_status_response_type = _SigninRequest.SigninRequest.isOidc(arguments[0].response_type) ? \"id_token\" : \"code\";\n        } else {\n            _this._query_status_response_type = \"id_token\";\n        }\n        _this._revokeAccessTokenOnSignout = revokeAccessTokenOnSignout;\n\n        _this._redirectNavigator = redirectNavigator;\n        _this._popupNavigator = popupNavigator;\n        _this._iframeNavigator = iframeNavigator;\n\n        _this._userStore = userStore;\n        return _this;\n    }\n\n    _createClass(UserManagerSettings, [{\n        key: 'popup_redirect_uri',\n        get: function get() {\n            return this._popup_redirect_uri;\n        }\n    }, {\n        key: 'popup_post_logout_redirect_uri',\n        get: function get() {\n            return this._popup_post_logout_redirect_uri;\n        }\n    }, {\n        key: 'popupWindowFeatures',\n        get: function get() {\n            return this._popupWindowFeatures;\n        }\n    }, {\n        key: 'popupWindowTarget',\n        get: function get() {\n            return this._popupWindowTarget;\n        }\n    }, {\n        key: 'silent_redirect_uri',\n        get: function get() {\n            return this._silent_redirect_uri;\n        }\n    }, {\n        key: 'silentRequestTimeout',\n        get: function get() {\n            return this._silentRequestTimeout;\n        }\n    }, {\n        key: 'automaticSilentRenew',\n        get: function get() {\n            return this._automaticSilentRenew;\n        }\n    }, {\n        key: 'validateSubOnSilentRenew',\n        get: function get() {\n            return this._validateSubOnSilentRenew;\n        }\n    }, {\n        key: 'includeIdTokenInSilentRenew',\n        get: function get() {\n            return this._includeIdTokenInSilentRenew;\n        }\n    }, {\n        key: 'accessTokenExpiringNotificationTime',\n        get: function get() {\n            return this._accessTokenExpiringNotificationTime;\n        }\n    }, {\n        key: 'monitorSession',\n        get: function get() {\n            return this._monitorSession;\n        }\n    }, {\n        key: 'monitorAnonymousSession',\n        get: function get() {\n            return this._monitorAnonymousSession;\n        }\n    }, {\n        key: 'checkSessionInterval',\n        get: function get() {\n            return this._checkSessionInterval;\n        }\n    }, {\n        key: 'stopCheckSessionOnError',\n        get: function get() {\n            return this._stopCheckSessionOnError;\n        }\n    }, {\n        key: 'query_status_response_type',\n        get: function get() {\n            return this._query_status_response_type;\n        }\n    }, {\n        key: 'revokeAccessTokenOnSignout',\n        get: function get() {\n            return this._revokeAccessTokenOnSignout;\n        }\n    }, {\n        key: 'redirectNavigator',\n        get: function get() {\n            return this._redirectNavigator;\n        }\n    }, {\n        key: 'popupNavigator',\n        get: function get() {\n            return this._popupNavigator;\n        }\n    }, {\n        key: 'iframeNavigator',\n        get: function get() {\n            return this._iframeNavigator;\n        }\n    }, {\n        key: 'userStore',\n        get: function get() {\n            return this._userStore;\n        }\n    }]);\n\n    return UserManagerSettings;\n}(_OidcClientSettings2.OidcClientSettings);\n\n/***/ }),\n\n/***/ \"./src/WebStorageStateStore.js\":\n/*!*************************************!*\\\n  !*** ./src/WebStorageStateStore.js ***!\n  \\*************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.WebStorageStateStore = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar WebStorageStateStore = exports.WebStorageStateStore = function () {\n    function WebStorageStateStore() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            _ref$prefix = _ref.prefix,\n            prefix = _ref$prefix === undefined ? \"oidc.\" : _ref$prefix,\n            _ref$store = _ref.store,\n            store = _ref$store === undefined ? _Global.Global.localStorage : _ref$store;\n\n        _classCallCheck(this, WebStorageStateStore);\n\n        this._store = store;\n        this._prefix = prefix;\n    }\n\n    WebStorageStateStore.prototype.set = function set(key, value) {\n        _Log.Log.debug(\"WebStorageStateStore.set\", key);\n\n        key = this._prefix + key;\n\n        this._store.setItem(key, value);\n\n        return Promise.resolve();\n    };\n\n    WebStorageStateStore.prototype.get = function get(key) {\n        _Log.Log.debug(\"WebStorageStateStore.get\", key);\n\n        key = this._prefix + key;\n\n        var item = this._store.getItem(key);\n\n        return Promise.resolve(item);\n    };\n\n    WebStorageStateStore.prototype.remove = function remove(key) {\n        _Log.Log.debug(\"WebStorageStateStore.remove\", key);\n\n        key = this._prefix + key;\n\n        var item = this._store.getItem(key);\n        this._store.removeItem(key);\n\n        return Promise.resolve(item);\n    };\n\n    WebStorageStateStore.prototype.getAllKeys = function getAllKeys() {\n        _Log.Log.debug(\"WebStorageStateStore.getAllKeys\");\n\n        var keys = [];\n\n        for (var index = 0; index < this._store.length; index++) {\n            var key = this._store.key(index);\n\n            if (key.indexOf(this._prefix) === 0) {\n                keys.push(key.substr(this._prefix.length));\n            }\n        }\n\n        return Promise.resolve(keys);\n    };\n\n    return WebStorageStateStore;\n}();\n\n/***/ }),\n\n/***/ \"./src/crypto/jsrsasign.js\":\n/*!*********************************!*\\\n  !*** ./src/crypto/jsrsasign.js ***!\n  \\*********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.AllowedSigningAlgs = exports.b64tohex = exports.hextob64u = exports.crypto = exports.X509 = exports.KeyUtil = exports.jws = undefined;\n\nvar _jsrsasign = __webpack_require__(/*! ../../jsrsasign/dist/jsrsasign.js */ \"./jsrsasign/dist/jsrsasign.js\");\n\nvar AllowedSigningAlgs = ['RS256', 'RS384', 'RS512', 'PS256', 'PS384', 'PS512', 'ES256', 'ES384', 'ES512'];\n\nexports.jws = _jsrsasign.jws;\nexports.KeyUtil = _jsrsasign.KEYUTIL;\nexports.X509 = _jsrsasign.X509;\nexports.crypto = _jsrsasign.crypto;\nexports.hextob64u = _jsrsasign.hextob64u;\nexports.b64tohex = _jsrsasign.b64tohex;\nexports.AllowedSigningAlgs = AllowedSigningAlgs;\n\n/***/ }),\n\n/***/ \"./src/random.js\":\n/*!***********************!*\\\n  !*** ./src/random.js ***!\n  \\***********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nexports.default = random;\n\nvar _v = __webpack_require__(/*! uuid/v4 */ \"./node_modules/uuid/v4.js\");\n\nvar _v2 = _interopRequireDefault(_v);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\n/**\n * Generates RFC4122 version 4 guid ()\n */\n\nfunction random() {\n  return (0, _v2.default)().replace(/-/g, '');\n}\nmodule.exports = exports['default'];\n\n/***/ }),\n\n/***/ \"./version.js\":\n/*!********************!*\\\n  !*** ./version.js ***!\n  \\********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nvar Version = \"1.10.1\";exports.Version = Version;\n\n/***/ }),\n\n/***/ 0:\n/*!***************************************!*\\\n  !*** multi babel-polyfill ./index.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! babel-polyfill */\"./node_modules/babel-polyfill/lib/index.js\");\nmodule.exports = __webpack_require__(/*! ./index.js */\"./index.js\");\n\n\n/***/ })\n\n/******/ });\n//# sourceMappingURL=data:application/json;charset=utf-8;base64,{"version":3,"sources":["webpack://Oidc/webpack/bootstrap","webpack://Oidc/./index.js","webpack://Oidc/./jsrsasign/dist/jsrsasign.js","webpack://Oidc/./node_modules/babel-polyfill/lib/index.js","webpack://Oidc/./node_modules/babel-polyfill/node_modules/regenerator-runtime/runtime.js","webpack://Oidc/./node_modules/base64-js/index.js","webpack://Oidc/./node_modules/buffer/index.js","webpack://Oidc/./node_modules/buffer/node_modules/isarray/index.js","webpack://Oidc/./node_modules/core-js/fn/regexp/escape.js","webpack://Oidc/./node_modules/core-js/modules/_a-function.js","webpack://Oidc/./node_modules/core-js/modules/_a-number-value.js","webpack://Oidc/./node_modules/core-js/modules/_add-to-unscopables.js","webpack://Oidc/./node_modules/core-js/modules/_advance-string-index.js","webpack://Oidc/./node_modules/core-js/modules/_an-instance.js","webpack://Oidc/./node_modules/core-js/modules/_an-object.js","webpack://Oidc/./node_modules/core-js/modules/_array-copy-within.js","webpack://Oidc/./node_modules/core-js/modules/_array-fill.js","webpack://Oidc/./node_modules/core-js/modules/_array-from-iterable.js","webpack://Oidc/./node_modules/core-js/modules/_array-includes.js","webpack://Oidc/./node_modules/core-js/modules/_array-methods.js","webpack://Oidc/./node_modules/core-js/modules/_array-reduce.js","webpack://Oidc/./node_modules/core-js/modules/_array-species-constructor.js","webpack://Oidc/./node_modules/core-js/modules/_array-species-create.js","webpack://Oidc/./node_modules/core-js/modules/_bind.js","webpack://Oidc/./node_modules/core-js/modules/_classof.js","webpack://Oidc/./node_modules/core-js/modules/_cof.js","webpack://Oidc/./node_modules/core-js/modules/_collection-strong.js","webpack://Oidc/./node_modules/core-js/modules/_collection-to-json.js","webpack://Oidc/./node_modules/core-js/modules/_collection-weak.js","webpack://Oidc/./node_modules/core-js/modules/_collection.js","webpack://Oidc/./node_modules/core-js/modules/_core.js","webpack://Oidc/./node_modules/core-js/modules/_create-property.js","webpack://Oidc/./node_modules/core-js/modules/_ctx.js","webpack://Oidc/./node_modules/core-js/modules/_date-to-iso-string.js","webpack://Oidc/./node_modules/core-js/modules/_date-to-primitive.js","webpack://Oidc/./node_modules/core-js/modules/_defined.js","webpack://Oidc/./node_modules/core-js/modules/_descriptors.js","webpack://Oidc/./node_modules/core-js/modules/_dom-create.js","webpack://Oidc/./node_modules/core-js/modules/_enum-bug-keys.js","webpack://Oidc/./node_modules/core-js/modules/_enum-keys.js","webpack://Oidc/./node_modules/core-js/modules/_export.js","webpack://Oidc/./node_modules/core-js/modules/_fails-is-regexp.js","webpack://Oidc/./node_modules/core-js/modules/_fails.js","webpack://Oidc/./node_modules/core-js/modules/_fix-re-wks.js","webpack://Oidc/./node_modules/core-js/modules/_flags.js","webpack://Oidc/./node_modules/core-js/modules/_flatten-into-array.js","webpack://Oidc/./node_modules/core-js/modules/_for-of.js","webpack://Oidc/./node_modules/core-js/modules/_function-to-string.js","webpack://Oidc/./node_modules/core-js/modules/_global.js","webpack://Oidc/./node_modules/core-js/modules/_has.js","webpack://Oidc/./node_modules/core-js/modules/_hide.js","webpack://Oidc/./node_modules/core-js/modules/_html.js","webpack://Oidc/./node_modules/core-js/modules/_ie8-dom-define.js","webpack://Oidc/./node_modules/core-js/modules/_inherit-if-required.js","webpack://Oidc/./node_modules/core-js/modules/_invoke.js","webpack://Oidc/./node_modules/core-js/modules/_iobject.js","webpack://Oidc/./node_modules/core-js/modules/_is-array-iter.js","webpack://Oidc/./node_modules/core-js/modules/_is-array.js","webpack://Oidc/./node_modules/core-js/modules/_is-integer.js","webpack://Oidc/./node_modules/core-js/modules/_is-object.js","webpack://Oidc/./node_modules/core-js/modules/_is-regexp.js","webpack://Oidc/./node_modules/core-js/modules/_iter-call.js","webpack://Oidc/./node_modules/core-js/modules/_iter-create.js","webpack://Oidc/./node_modules/core-js/modules/_iter-define.js","webpack://Oidc/./node_modules/core-js/modules/_iter-detect.js","webpack://Oidc/./node_modules/core-js/modules/_iter-step.js","webpack://Oidc/./node_modules/core-js/modules/_iterators.js","webpack://Oidc/./node_modules/core-js/modules/_library.js","webpack://Oidc/./node_modules/core-js/modules/_math-expm1.js","webpack://Oidc/./node_modules/core-js/modules/_math-fround.js","webpack://Oidc/./node_modules/core-js/modules/_math-log1p.js","webpack://Oidc/./node_modules/core-js/modules/_math-scale.js","webpack://Oidc/./node_modules/core-js/modules/_math-sign.js","webpack://Oidc/./node_modules/core-js/modules/_meta.js","webpack://Oidc/./node_modules/core-js/modules/_metadata.js","webpack://Oidc/./node_modules/core-js/modules/_microtask.js","webpack://Oidc/./node_modules/core-js/modules/_new-promise-capability.js","webpack://Oidc/./node_modules/core-js/modules/_object-assign.js","webpack://Oidc/./node_modules/core-js/modules/_object-create.js","webpack://Oidc/./node_modules/core-js/modules/_object-dp.js","webpack://Oidc/./node_modules/core-js/modules/_object-dps.js","webpack://Oidc/./node_modules/core-js/modules/_object-forced-pam.js","webpack://Oidc/./node_modules/core-js/modules/_object-gopd.js","webpack://Oidc/./node_modules/core-js/modules/_object-gopn-ext.js","webpack://Oidc/./node_modules/core-js/modules/_object-gopn.js","webpack://Oidc/./node_modules/core-js/modules/_object-gops.js","webpack://Oidc/./node_modules/core-js/modules/_object-gpo.js","webpack://Oidc/./node_modules/core-js/modules/_object-keys-internal.js","webpack://Oidc/./node_modules/core-js/modules/_object-keys.js","webpack://Oidc/./node_modules/core-js/modules/_object-pie.js","webpack://Oidc/./node_modules/core-js/modules/_object-sap.js","webpack://Oidc/./node_modules/core-js/modules/_object-to-array.js","webpack://Oidc/./node_modules/core-js/modules/_own-keys.js","webpack://Oidc/./node_modules/core-js/modules/_parse-float.js","webpack://Oidc/./node_modules/core-js/modules/_parse-int.js","webpack://Oidc/./node_modules/core-js/modules/_perform.js","webpack://Oidc/./node_modules/core-js/modules/_promise-resolve.js","webpack://Oidc/./node_modules/core-js/modules/_property-desc.js","webpack://Oidc/./node_modules/core-js/modules/_redefine-all.js","webpack://Oidc/./node_modules/core-js/modules/_redefine.js","webpack://Oidc/./node_modules/core-js/modules/_regexp-exec-abstract.js","webpack://Oidc/./node_modules/core-js/modules/_regexp-exec.js","webpack://Oidc/./node_modules/core-js/modules/_replacer.js","webpack://Oidc/./node_modules/core-js/modules/_same-value.js","webpack://Oidc/./node_modules/core-js/modules/_set-collection-from.js","webpack://Oidc/./node_modules/core-js/modules/_set-collection-of.js","webpack://Oidc/./node_modules/core-js/modules/_set-proto.js","webpack://Oidc/./node_modules/core-js/modules/_set-species.js","webpack://Oidc/./node_modules/core-js/modules/_set-to-string-tag.js","webpack://Oidc/./node_modules/core-js/modules/_shared-key.js","webpack://Oidc/./node_modules/core-js/modules/_shared.js","webpack://Oidc/./node_modules/core-js/modules/_species-constructor.js","webpack://Oidc/./node_modules/core-js/modules/_strict-method.js","webpack://Oidc/./node_modules/core-js/modules/_string-at.js","webpack://Oidc/./node_modules/core-js/modules/_string-context.js","webpack://Oidc/./node_modules/core-js/modules/_string-html.js","webpack://Oidc/./node_modules/core-js/modules/_string-pad.js","webpack://Oidc/./node_modules/core-js/modules/_string-repeat.js","webpack://Oidc/./node_modules/core-js/modules/_string-trim.js","webpack://Oidc/./node_modules/core-js/modules/_string-ws.js","webpack://Oidc/./node_modules/core-js/modules/_task.js","webpack://Oidc/./node_modules/core-js/modules/_to-absolute-index.js","webpack://Oidc/./node_modules/core-js/modules/_to-index.js","webpack://Oidc/./node_modules/core-js/modules/_to-integer.js","webpack://Oidc/./node_modules/core-js/modules/_to-iobject.js","webpack://Oidc/./node_modules/core-js/modules/_to-length.js","webpack://Oidc/./node_modules/core-js/modules/_to-object.js","webpack://Oidc/./node_modules/core-js/modules/_to-primitive.js","webpack://Oidc/./node_modules/core-js/modules/_typed-array.js","webpack://Oidc/./node_modules/core-js/modules/_typed-buffer.js","webpack://Oidc/./node_modules/core-js/modules/_typed.js","webpack://Oidc/./node_modules/core-js/modules/_uid.js","webpack://Oidc/./node_modules/core-js/modules/_user-agent.js","webpack://Oidc/./node_modules/core-js/modules/_validate-collection.js","webpack://Oidc/./node_modules/core-js/modules/_wks-define.js","webpack://Oidc/./node_modules/core-js/modules/_wks-ext.js","webpack://Oidc/./node_modules/core-js/modules/_wks.js","webpack://Oidc/./node_modules/core-js/modules/core.get-iterator-method.js","webpack://Oidc/./node_modules/core-js/modules/core.regexp.escape.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.copy-within.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.every.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.fill.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.filter.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.find-index.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.find.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.for-each.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.from.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.index-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.is-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.iterator.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.join.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.last-index-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.map.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.of.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.reduce-right.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.reduce.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.slice.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.some.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.sort.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.species.js","webpack://Oidc/./node_modules/core-js/modules/es6.date.now.js","webpack://Oidc/./node_modules/core-js/modules/es6.date.to-iso-string.js","webpack://Oidc/./node_modules/core-js/modules/es6.date.to-json.js","webpack://Oidc/./node_modules/core-js/modules/es6.date.to-primitive.js","webpack://Oidc/./node_modules/core-js/modules/es6.date.to-string.js","webpack://Oidc/./node_modules/core-js/modules/es6.function.bind.js","webpack://Oidc/./node_modules/core-js/modules/es6.function.has-instance.js","webpack://Oidc/./node_modules/core-js/modules/es6.function.name.js","webpack://Oidc/./node_modules/core-js/modules/es6.map.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.acosh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.asinh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.atanh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.cbrt.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.clz32.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.cosh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.expm1.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.fround.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.hypot.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.imul.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.log10.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.log1p.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.log2.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.sign.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.sinh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.tanh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.trunc.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.constructor.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.epsilon.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.is-finite.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.is-integer.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.is-nan.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.is-safe-integer.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.max-safe-integer.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.min-safe-integer.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.parse-float.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.parse-int.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.to-fixed.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.to-precision.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.assign.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.create.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.define-properties.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.define-property.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.freeze.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.get-own-property-descriptor.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.get-own-property-names.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.get-prototype-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.is-extensible.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.is-frozen.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.is-sealed.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.is.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.keys.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.prevent-extensions.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.seal.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.set-prototype-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.to-string.js","webpack://Oidc/./node_modules/core-js/modules/es6.parse-float.js","webpack://Oidc/./node_modules/core-js/modules/es6.parse-int.js","webpack://Oidc/./node_modules/core-js/modules/es6.promise.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.apply.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.construct.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.define-property.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.delete-property.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.enumerate.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.get-own-property-descriptor.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.get-prototype-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.get.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.has.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.is-extensible.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.own-keys.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.prevent-extensions.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.set-prototype-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.set.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.constructor.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.exec.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.flags.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.match.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.replace.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.search.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.split.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.to-string.js","webpack://Oidc/./node_modules/core-js/modules/es6.set.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.anchor.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.big.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.blink.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.bold.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.code-point-at.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.ends-with.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.fixed.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.fontcolor.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.fontsize.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.from-code-point.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.includes.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.italics.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.iterator.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.link.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.raw.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.repeat.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.small.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.starts-with.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.strike.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.sub.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.sup.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.trim.js","webpack://Oidc/./node_modules/core-js/modules/es6.symbol.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.array-buffer.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.data-view.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.float32-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.float64-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.int16-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.int32-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.int8-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.uint16-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.uint32-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.uint8-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.uint8-clamped-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.weak-map.js","webpack://Oidc/./node_modules/core-js/modules/es6.weak-set.js","webpack://Oidc/./node_modules/core-js/modules/es7.array.flat-map.js","webpack://Oidc/./node_modules/core-js/modules/es7.array.flatten.js","webpack://Oidc/./node_modules/core-js/modules/es7.array.includes.js","webpack://Oidc/./node_modules/core-js/modules/es7.asap.js","webpack://Oidc/./node_modules/core-js/modules/es7.error.is-error.js","webpack://Oidc/./node_modules/core-js/modules/es7.global.js","webpack://Oidc/./node_modules/core-js/modules/es7.map.from.js","webpack://Oidc/./node_modules/core-js/modules/es7.map.of.js","webpack://Oidc/./node_modules/core-js/modules/es7.map.to-json.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.clamp.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.deg-per-rad.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.degrees.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.fscale.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.iaddh.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.imulh.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.isubh.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.rad-per-deg.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.radians.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.scale.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.signbit.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.umulh.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.define-getter.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.define-setter.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.entries.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.get-own-property-descriptors.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.lookup-getter.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.lookup-setter.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.values.js","webpack://Oidc/./node_modules/core-js/modules/es7.observable.js","webpack://Oidc/./node_modules/core-js/modules/es7.promise.finally.js","webpack://Oidc/./node_modules/core-js/modules/es7.promise.try.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.define-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.delete-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.get-metadata-keys.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.get-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.get-own-metadata-keys.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.get-own-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.has-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.has-own-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.set.from.js","webpack://Oidc/./node_modules/core-js/modules/es7.set.of.js","webpack://Oidc/./node_modules/core-js/modules/es7.set.to-json.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.at.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.match-all.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.pad-end.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.pad-start.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.trim-left.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.trim-right.js","webpack://Oidc/./node_modules/core-js/modules/es7.symbol.async-iterator.js","webpack://Oidc/./node_modules/core-js/modules/es7.symbol.observable.js","webpack://Oidc/./node_modules/core-js/modules/es7.system.global.js","webpack://Oidc/./node_modules/core-js/modules/es7.weak-map.from.js","webpack://Oidc/./node_modules/core-js/modules/es7.weak-map.of.js","webpack://Oidc/./node_modules/core-js/modules/es7.weak-set.from.js","webpack://Oidc/./node_modules/core-js/modules/es7.weak-set.of.js","webpack://Oidc/./node_modules/core-js/modules/web.dom.iterable.js","webpack://Oidc/./node_modules/core-js/modules/web.immediate.js","webpack://Oidc/./node_modules/core-js/modules/web.timers.js","webpack://Oidc/./node_modules/core-js/shim.js","webpack://Oidc/./node_modules/ieee754/index.js","webpack://Oidc/./node_modules/uuid/lib/bytesToUuid.js","webpack://Oidc/./node_modules/uuid/lib/rng-browser.js","webpack://Oidc/./node_modules/uuid/v4.js","webpack://Oidc/(webpack)/buildin/global.js","webpack://Oidc/./src/AccessTokenEvents.js","webpack://Oidc/./src/CheckSessionIFrame.js","webpack://Oidc/./src/CordovaIFrameNavigator.js","webpack://Oidc/./src/CordovaPopupNavigator.js","webpack://Oidc/./src/CordovaPopupWindow.js","webpack://Oidc/./src/ErrorResponse.js","webpack://Oidc/./src/Event.js","webpack://Oidc/./src/Global.js","webpack://Oidc/./src/IFrameNavigator.js","webpack://Oidc/./src/IFrameWindow.js","webpack://Oidc/./src/InMemoryWebStorage.js","webpack://Oidc/./src/JoseUtil.js","webpack://Oidc/./src/JoseUtilImpl.js","webpack://Oidc/./src/JsonService.js","webpack://Oidc/./src/Log.js","webpack://Oidc/./src/MetadataService.js","webpack://Oidc/./src/OidcClient.js","webpack://Oidc/./src/OidcClientSettings.js","webpack://Oidc/./src/PopupNavigator.js","webpack://Oidc/./src/PopupWindow.js","webpack://Oidc/./src/RedirectNavigator.js","webpack://Oidc/./src/ResponseValidator.js","webpack://Oidc/./src/SessionMonitor.js","webpack://Oidc/./src/SigninRequest.js","webpack://Oidc/./src/SigninResponse.js","webpack://Oidc/./src/SigninState.js","webpack://Oidc/./src/SignoutRequest.js","webpack://Oidc/./src/SignoutResponse.js","webpack://Oidc/./src/SilentRenewService.js","webpack://Oidc/./src/State.js","webpack://Oidc/./src/Timer.js","webpack://Oidc/./src/TokenClient.js","webpack://Oidc/./src/TokenRevocationClient.js","webpack://Oidc/./src/UrlUtility.js","webpack://Oidc/./src/User.js","webpack://Oidc/./src/UserInfoService.js","webpack://Oidc/./src/UserManager.js","webpack://Oidc/./src/UserManagerEvents.js","webpack://Oidc/./src/UserManagerSettings.js","webpack://Oidc/./src/WebStorageStateStore.js","webpack://Oidc/./src/crypto/jsrsasign.js","webpack://Oidc/./src/random.js","webpack://Oidc/./version.js"],"names":["Version","Log","OidcClient","OidcClientSettings","WebStorageStateStore","InMemoryWebStorage","UserManager","AccessTokenEvents","MetadataService","CordovaPopupNavigator","CordovaIFrameNavigator","CheckSessionIFrame","TokenRevocationClient","SessionMonitor","Global","User","navigator","userAgent","window","YAHOO","undefined","lang","extend","g","h","f","Error","d","prototype","constructor","superclass","Object","b","e","c","test","j","i","length","l","k","a","CryptoJS","lib","Base","n","p","o","mixIn","hasOwnProperty","init","$super","apply","arguments","create","toString","clone","WordArray","words","sigBytes","stringify","concat","t","q","s","clamp","r","ceil","call","slice","random","push","m","enc","Hex","join","parse","parseInt","substr","Latin1","String","fromCharCode","charCodeAt","Utf8","decodeURIComponent","escape","unescape","encodeURIComponent","BufferedBlockAlgorithm","reset","_data","_nDataBytes","_append","_process","w","x","blockSize","v","u","max","_minBufferSize","min","_doProcessBlock","splice","Hasher","cfg","_doReset","update","finalize","_doFinalize","_createHelper","_createHmacHelper","HMAC","algo","Math","x64","Word","high","low","toX32","Base64","_map","charAt","indexOf","sqrt","pow","SHA256","_hash","floor","HmacSHA256","T","ea","SHA512","F","G","H","I","J","X","K","Y","L","Z","M","$","N","aa","O","ba","P","ca","Q","z","A","y","U","B","R","C","S","D","V","E","W","fa","da","HmacSHA512","SHA384","HmacSHA384","b64map","b64pad","hex2b64","substring","b64tohex","int2char","b64toBA","Array","dbits","canary","j_lm","BigInteger","fromNumber","fromString","nbi","am1","am2","am3","appName","am","DB","DM","DV","BI_FP","FV","F1","F2","BI_RM","BI_RC","rr","vv","intAt","bnpCopyTo","bnpFromInt","nbv","fromInt","bnpFromString","fromRadix","ZERO","subTo","bnpClamp","bnToString","negate","toRadix","bnNegate","bnAbs","bnCompareTo","nbits","bnBitLength","bnpDLShiftTo","bnpDRShiftTo","bnpLShiftTo","bnpRShiftTo","bnpSubTo","bnpMultiplyTo","abs","bnpSquareTo","bnpDivRemTo","copyTo","lShiftTo","dlShiftTo","compareTo","ONE","drShiftTo","rShiftTo","bnMod","divRemTo","Classic","cConvert","mod","cRevert","cReduce","cMulTo","multiplyTo","reduce","cSqrTo","squareTo","convert","revert","mulTo","sqrTo","bnpInvDigit","Montgomery","mp","invDigit","mpl","mph","um","mt2","montConvert","montRevert","montReduce","montSqrTo","montMulTo","bnpIsEven","bnpExp","bnModPowInt","isEven","exp","bitLength","modPowInt","bnClone","bnIntValue","bnByteValue","bnShortValue","bnpChunkSize","LN2","log","bnSigNum","bnpToRadix","signum","chunkSize","intValue","bnpFromRadix","dMultiply","dAddOffset","bnpFromNumber","testBit","bitwiseTo","shiftLeft","op_or","isProbablePrime","nextBytes","bnToByteArray","bnEquals","bnMin","bnMax","bnpBitwiseTo","op_and","bnAnd","bnOr","op_xor","bnXor","op_andnot","bnAndNot","bnNot","bnShiftLeft","bnShiftRight","lbit","bnGetLowestSetBit","cbit","bnBitCount","bnTestBit","bnpChangeBit","bnSetBit","changeBit","bnClearBit","bnFlipBit","bnpAddTo","bnAdd","addTo","bnSubtract","bnMultiply","bnSquare","bnDivide","bnRemainder","bnDivideAndRemainder","bnpDMultiply","bnpDAddOffset","NullExp","nNop","nMulTo","nSqrTo","bnPow","bnpMultiplyLowerTo","bnpMultiplyUpperTo","Barrett","r2","q3","mu","divide","barrettConvert","barrettRevert","barrettReduce","multiplyUpperTo","multiplyLowerTo","barrettSqrTo","barrettMulTo","bnModPow","bnGCD","getLowestSetBit","bnpModInt","bnModInverse","subtract","add","lowprimes","lplim","bnIsProbablePrime","modInt","millerRabin","bnpMillerRabin","shiftRight","modPow","byteValue","shortValue","toByteArray","equals","and","or","xor","andNot","not","bitCount","setBit","clearBit","flipBit","multiply","remainder","divideAndRemainder","modInverse","gcd","square","Arcfour","ARC4init","ARC4next","next","prng_newstate","rng_psize","rng_state","rng_pool","rng_pptr","rng_seed_int","rng_seed_time","Date","getTime","crypto","msCrypto","getRandomValues","ua","Uint8Array","appVersion","rng_get_byte","rng_get_bytes","SecureRandom","parseBigInt","linebrk","byte2Hex","pkcs1pad2","oaep_mgf1_arr","oaep_pad","KJUR","MessageDigest","Util","getCanonicalAlgName","getHashLength","hextorstr","hashHex","rstrtohex","RSAKey","dmp1","dmq1","coeff","RSASetPublic","isPublic","isPrivate","RSADoPublic","RSAEncrypt","doPublic","RSAEncryptOAEP","setPublic","encrypt","encryptOAEP","type","ECFieldElementFp","feFpEquals","feFpToBigInteger","feFpNegate","feFpAdd","toBigInteger","feFpSubtract","feFpMultiply","feFpSquare","feFpDivide","ECPointFp","curve","zinv","pointFpGetX","fromBigInteger","pointFpGetY","pointFpEquals","isInfinity","pointFpIsInfinity","pointFpNegate","pointFpAdd","twice","getInfinity","pointFpTwice","pointFpMultiply","pointFpMultiplyTwo","getX","getY","multiplyTwo","ECCurveFp","infinity","curveFpGetQ","curveFpGetA","curveFpGetB","curveFpEquals","curveFpGetInfinity","curveFpFromBigInteger","curveFpDecodePointHex","getQ","getA","getB","decodePointHex","getByteLength","getEncoded","toByteArrayUnsigned","unshift","decodeFrom","decodeFromHex","add2D","twice2D","valueOf","multiply2D","isOnCurve","validate","jsonParse","RegExp","match","replace","shift","asn1","ASN1Util","integerToByteHex","bigIntToMinTwosComplementsHex","getPEMStringFromHex","hextopem","newObject","DERBoolean","DERInteger","DERBitString","DEROctetString","DERNull","DERObjectIdentifier","DEREnumerated","DERUTF8String","DERNumericString","DERPrintableString","DERTeletexString","DERIA5String","DERUTCTime","DERGeneralizedTime","DERSequence","DERSet","DERTaggedObject","keys","array","tag","explicit","obj","jsonToASN1HEX","getEncodedHex","oidHexToInt","oidIntToHex","split","ASN1Object","getLengthHexFromValue","hV","hTLV","isModified","getFreshValueHex","hL","hT","getValueHex","DERAbstractString","getString","setString","utf8tohex","toLowerCase","setStringHex","str","hex","DERAbstractTime","localDateToUTC","utc","getTimezoneOffset","formatDate","zeroPadding","getFullYear","getMonth","getDate","getHours","getMinutes","getSeconds","getMilliseconds","stohex","setByDateValue","UTC","setByDate","DERAbstractStructured","setByASN1ObjectArray","asn1Array","appendASN1Object","setByBigInteger","setByInteger","setValueHex","bigint","setHexValueIncludingUnusedBits","setUnusedBitsAndHexValue","setByBinaryString","setByBooleanArray","newFalseArray","bin","setValueOidString","setValueName","x509","OID","name2oid","oid","name","date","withMillis","millis","sortFlag","sort","sortflag","isExplicit","asn1Object","setASN1Object","ASN1HEX","getLblen","getL","getVblen","getVidx","getV","getTLV","getNextSiblingIdx","getChildIdx","getNthChildIdx","getIdxbyList","getTLVbyList","getVbyList","hextooidstr","dump","ommit_long_octet","isASN1HEX","oid2name","hextoutf8","oidname","JSON","x509ExtName","isHex","Base64x","stoBA","BAtos","BAtohex","stob64","stob64u","b64tob64u","b64utos","b64utob64","hextob64u","b64utohex","utf8tob64u","b64utoutf8","Buffer","uricmptohex","encodeURIComponentAll","hextouricmp","utf8tob64","b64toutf8","hextob64","hextob64nl","b64nltohex","pemtohex","hextoArrayBuffer","ArrayBuffer","DataView","setUint8","ArrayBuffertohex","byteLength","getUint8","zulutomsec","zulutosec","zulutodate","datetozulu","getUTCFullYear","getUTCMonth","getUTCDate","getUTCHours","getUTCMinutes","getUTCSeconds","getUTCMilliseconds","ipv6tohex","repeat","hextoipv6","hextoip","iptohex","newline_toUnix","newline_toDos","isInteger","isBase64","isBase64URL","isIntegerArray","hextoposhex","intarystrtohex","map","strdiffidx","DIGESTINFOHEAD","sha1","sha224","sha256","sha384","sha512","md2","md5","ripemd160","DEFAULTPROVIDER","hmacmd5","hmacsha1","hmacsha224","hmacsha256","hmacsha384","hmacsha512","hmacripemd160","MD5withRSA","SHA1withRSA","SHA224withRSA","SHA256withRSA","SHA384withRSA","SHA512withRSA","RIPEMD160withRSA","MD5withECDSA","SHA1withECDSA","SHA224withECDSA","SHA256withECDSA","SHA384withECDSA","SHA512withECDSA","RIPEMD160withECDSA","SHA1withDSA","SHA224withDSA","SHA256withDSA","MD5withRSAandMGF1","SHA1withRSAandMGF1","SHA224withRSAandMGF1","SHA256withRSAandMGF1","SHA384withRSAandMGF1","SHA512withRSAandMGF1","RIPEMD160withRSAandMGF1","CRYPTOJSMESSAGEDIGESTNAME","MD5","SHA1","SHA224","RIPEMD160","getDigestInfoHex","getPaddedDigestInfoHex","hashString","alg","digestString","digestHex","prov","sha256Hex","sha512Hex","SECURERANDOMGEN","getRandomHexOfNbytes","getRandomBigIntegerOfNbytes","getRandomHexOfNbits","getRandomBigIntegerOfNbits","getRandomBigIntegerZeroToMax","getRandomBigIntegerMinToMax","setAlgAndProvider","md","updateString","updateHex","digest","sjcl","hash","codec","toBits","fromBits","algName","provName","HASHLENGTH","Mac","algProv","mac","pass","doFinal","doFinalString","doFinalHex","setPassword","utf8","rstr","b64","b64u","Signature","_setAlgNames","mdAlgName","pubkeyAlgName","_zeroPaddingOfSignature","KEYUTIL","getKey","prvKey","state","pubKey","sign","sHashHex","ecprvhex","eccurvename","ECDSA","hSign","signHex","signWithMessageHashPSS","pssSaltLen","signWithMessageHash","DSA","signString","verify","ecpubhex","verifyHex","verifyWithMessageHashPSS","verifyWithMessageHash","algProvName","initParams","psssaltlen","prvkeypem","prvkeypas","Cipher","getAlgByKeyAndName","decrypt","decryptOAEP","oidhex2name","getBigRandom","setNamedCurve","ecparams","ECParameterDB","getByName","prvKeyHex","pubKeyHex","curveName","setPrivateKeyHex","setPublicKeyHex","getPublicKeyXYHex","keylen","getShortNISTPCurveName","generateKeyPairHex","biRSSigToASN1Sig","fromByteArrayUnsigned","serializeSig","parseSigHex","verifyRaw","Bitcoin","isArray","parseSig","toByteArraySigned","parseSigCompact","readPKCS5PrvKeyHex","getName","readPKCS8PrvKeyHex","readPKCS8PubKeyHex","readCertPubKeyHex","prv","pub","parseSigHexInHexRS","asn1SigToConcatSig","concatSigToASN1Sig","hexRSSigToASN1Sig","regist","AES","TripleDES","DES","key","iv","ciphertext","proc","eproc","ivlen","cipher","ivsalt","data","keyhex","ivhex","version","parsePKCS5PEM","getKeyAndUnusedIvByPasscodeAndIvsalt","decryptKeyB64","getDecryptedKeyHex","getEncryptedPKCS5PEMFromPrvKeyHex","toUpperCase","parseHexOfEncryptedPKCS8","encryptionSchemeAlg","encryptionSchemeIV","pbkdf2Salt","pbkdf2Iter","getPBKDF2KeyHexFromParam","PBKDF2","keySize","iterations","_getPlainPKCS8HexFromEncryptedPKCS8PEM","getKeyFromEncryptedPKCS8PEM","getKeyFromPlainPrivatePKCS8Hex","parsePlainPrivatePKCS8Hex","algparam","algoid","keyidx","getKeyFromPlainPrivatePKCS8PEM","_getKeyFromPublicPKCS8Hex","parsePublicRawRSAKeyHex","parsePublicPKCS8Hex","xy","kty","dp","dq","co","qi","setPrivateEx","setPrivate","crv","X509","getPublicKeyFromCertHex","getPublicKeyFromCertPEM","generateKeypair","generate","prvKeyObj","pubKeyObj","getPEM","SubjectPublicKeyInfo","seq","octstr","bitstr","getKeyFromCSRPEM","getKeyFromCSRHex","parseCSRHex","p8pubkeyhex","getJWKFromKey","getPosArrayOfChildrenFromHex","getHexValueArrayOfChildrenFromHex","readPrivateKeyFromPEMString","readPKCS5PubKeyHex","readCertHex","getPublicKeyHex","_RE_HEXDECONLY","compile","_rsasign_getHexPaddedDigestInfoForString","doPrivate","pss_mgf1_str","signPSS","_rsasign_getDecryptSignatureBI","_rsasign_getHexDigestInfoFromSig","_rsasign_getAlgNameAndHashFromHexDisgestInfo","verifyPSS","SALT_LEN_HLEN","SALT_LEN_MAX","SALT_LEN_RECOVER","foffset","aExtInfo","getVersion","getSerialNumberHex","getSignatureAlgorithmField","getIssuerHex","getIssuerString","hex2dn","getSubjectHex","getSubjectString","getNotBefore","getNotAfter","getPublicKeyIdx","getPublicKeyContentIdx","getPublicKey","getSignatureAlgorithmName","getSignatureValueHex","verifySignature","parseExt","critical","vidx","getExtInfo","getExtBasicConstraints","cA","pathLen","getExtKeyUsageBin","getExtKeyUsageString","KEYUSAGE_NAME","getExtSubjectKeyIdentifier","getExtAuthorityKeyIdentifier","kid","getExtExtKeyUsageName","getExtSubjectAltName","getExtSubjectAltName2","getExtCRLDistributionPointsURI","getExtAIAInfo","ocsp","caissuer","getExtCertificatePolicies","id","cps","unotice","readCertPEM","getInfo","hex2rdn","hex2attrTypeValue","oid2atype","getPublicKeyInfoPropOfCertPEM","jws","JWS","isSafeJSONString","parseJWS","parsedJWS","sigvalH","headB64U","payloadB64U","sigvalB64U","si","sigvalBI","headS","payloadS","readSafeJSONString","jwsalg2sigalg","hASN1Sig","headerObj","payloadObj","headerPP","payloadPP","sigHex","verifyJWT","inArray","includedArray","iss","sub","aud","IntDate","getNow","verifyAt","gracePeriod","nbf","iat","jti","HS256","HS384","HS512","RS256","RS384","RS512","ES256","ES384","PS256","PS384","PS512","none","getEncodedSignatureValueFromJWS","getJWKthumbprint","get","getZulu","intDate2UTCString","toUTCString","intDate2Zulu","EDSA","_crypto","DefaultAccessTokenExpiringNotificationTime","accessTokenExpiringNotificationTime","accessTokenExpiringTimer","Timer","accessTokenExpiredTimer","_accessTokenExpiringNotificationTime","_accessTokenExpiring","_accessTokenExpired","load","container","access_token","expires_in","duration","debug","expiring","cancel","expired","unload","addAccessTokenExpiring","cb","addHandler","removeAccessTokenExpiring","removeHandler","addAccessTokenExpired","removeAccessTokenExpired","DefaultInterval","callback","client_id","url","interval","stopOnError","_callback","_client_id","_url","_interval","_stopOnError","idx","_frame_origin","_frame","document","createElement","style","visibility","position","display","width","height","src","Promise","resolve","onload","body","appendChild","_boundMessageEvent","_message","bind","addEventListener","origin","source","contentWindow","error","stop","start","session_state","_session_state","send","postMessage","_timer","setInterval","clearInterval","prepare","params","popupWindowFeatures","popup","CordovaPopupWindow","DefaultPopupFeatures","DefaultPopupTarget","_promise","reject","_resolve","_reject","features","target","popupWindowTarget","redirect_uri","startUrl","_isInAppBrowserInstalled","cordovaMetadata","some","navigate","_error","cordova","require","metadata","_popup","InAppBrowser","open","_exitCallbackEvent","_exitCallback","_loadStartCallbackEvent","_loadStartCallback","promise","event","_success","message","_cleanup","close","removeEventListener","ErrorResponse","error_description","error_uri","Event","_name","_callbacks","findIndex","item","raise","timer","handle","testing","request","_testing","setXMLHttpRequest","newRequest","location","localStorage","sessionStorage","XMLHttpRequest","IFrameNavigator","frame","IFrameWindow","notifyParent","DefaultTimeout","timeout","silentRequestTimeout","setTimeout","_timeout","clearTimeout","removeChild","_origin","frameElement","href","parent","protocol","host","getItem","setItem","value","removeItem","index","getOwnPropertyNames","JoseUtil","KeyUtil","AllowedSigningAlgs","getJoseUtil","parseJwt","jwt","token","header","payload","validateJwt","issuer","audience","clockSkew","now","timeInsensitive","x5c","_validateJwt","validateJwtAttributes","validAudience","azp","lowerNow","upperNow","then","hexToBase64Url","JsonService","additionalContentTypes","XMLHttpRequestCtor","jwtHandler","_contentTypes","_XMLHttpRequest","_jwtHandler","getJson","req","allowedContentTypes","status","contentType","getResponseHeader","found","find","startsWith","responseText","statusText","onerror","setRequestHeader","postForm","nopLogger","info","warn","NONE","ERROR","WARN","INFO","DEBUG","logger","level","args","from","OidcMetadataUrlPath","settings","JsonServiceCtor","_settings","_jsonService","getMetadata","metadataUrl","getIssuer","_getMetadataProperty","getAuthorizationEndpoint","getUserInfoEndpoint","getTokenEndpoint","optional","getCheckSessionIframe","getEndSessionEndpoint","getRevocationEndpoint","getKeysEndpoint","getSigningKeys","signingKeys","jwks_uri","keySet","_metadataUrl","authority","createSigninRequest","response_type","scope","prompt","max_age","ui_locales","id_token_hint","login_hint","acr_values","resource","request_uri","response_mode","extraQueryParams","extraTokenParams","request_type","skipUserInfo","stateStore","SigninRequest","isCode","_metadataService","signinRequest","client_secret","signinState","_stateStore","set","toStorageString","readSigninResponseState","removeState","useQuery","delimiter","response","SigninResponse","stateApi","remove","storedStateString","SigninState","fromStorageString","processSigninResponse","_validator","validateSigninResponse","createSignoutRequest","post_logout_redirect_uri","SignoutRequest","signoutState","readSignoutResponseState","SignoutResponse","stateKey","State","processSignoutResponse","validateSignoutResponse","clearStaleState","staleStateAge","validator","metadataService","DefaultResponseType","DefaultScope","DefaultStaleStateAge","DefaultClockSkewInSeconds","filterProtocolClaims","loadUserInfo","userInfoJwtIssuer","ResponseValidatorCtor","ResponseValidator","MetadataServiceCtor","_authority","_metadata","_signingKeys","_client_secret","_response_type","_scope","_redirect_uri","_post_logout_redirect_uri","_prompt","_display","_max_age","_ui_locales","_acr_values","_resource","_response_mode","_filterProtocolClaims","_loadUserInfo","_staleStateAge","_clockSkew","_userInfoJwtIssuer","_extraQueryParams","_extraTokenParams","PopupNavigator","PopupWindow","keepOpen","notifyOpener","CheckForPopupClosedInterval","_checkForPopupClosedTimer","_checkForPopupClosed","_id","focus","closed","opener","UrlUtility","parseUrlFragment","RedirectNavigator","useReplaceToNavigate","ProtocolClaims","UserInfoServiceCtor","UserInfoService","joseUtil","TokenClientCtor","TokenClient","_userInfoService","_joseUtil","_tokenClient","_processSigninParams","_validateTokens","_processClaims","nonce","id_token","code_verifier","code","isOpenIdConnect","profile","getClaims","claims","_mergeClaims","claims1","claims2","result","assign","values","forEach","_processCode","_validateIdTokenAndAccessToken","_validateIdToken","exchangeCode","tokenResponse","_validateIdTokenAttributes","clockSkewInSeconds","_validateAccessToken","_filterByAlg","filter","at_hash","hashAlg","hashBits","sha","left","left_b64u","userManager","CheckSessionIFrameCtor","_userManager","_CheckSessionIFrameCtor","events","addUserLoaded","_start","addUserUnloaded","_stop","getUser","user","monitorAnonymousSession","querySessionStatus","tmpUser","session","sid","catch","err","_sub","_sid","_checkSessionIFrame","_checkSessionInterval","_stopCheckSessionOnError","timerHandle","raiseEvent","_raiseUserSessionChanged","_raiseUserSignedOut","_raiseUserSignedIn","checkSessionInterval","stopCheckSessionOnError","oidc","isOidc","addQueryParam","code_challenge","isOAuth","OidcScope","token_type","expires_at","scopes","_nonce","_code_verifier","_code_challenge","_skipUserInfo","created","storageString","SilentRenewService","_tokenExpiring","signinSilent","_raiseSilentRenewError","_created","_request_type","storage","age","cutoff","getAllKeys","promises","all","TimerDuration","nowFunc","_nowFunc","expiration","_timerHandle","_expiration","timerDuration","diff","grant_type","exchangeRefreshToken","refresh_token","AccessTokenTypeHint","RefreshTokenTypeHint","_XMLHttpRequestCtor","revoke","required","_revoke","xhr","global","lastIndexOf","regex","counter","exec","prop","_getClaimsFromJwt","issuerPromise","SilentRenewServiceCtor","SessionMonitorCtor","TokenRevocationClientCtor","UserManagerSettings","_events","UserManagerEvents","_silentRenewService","automaticSilentRenew","startSilentRenew","monitorSession","_sessionMonitor","_tokenRevocationClient","_loadUser","removeUser","storeUser","signinRedirect","navParams","_signinStart","_redirectNavigator","signinRedirectCallback","_signinEnd","signinPopup","popup_redirect_uri","_signin","_popupNavigator","signinPopupCallback","_signinCallback","_useRefreshToken","includeIdTokenInSilentRenew","validateSubOnSilentRenew","current_sub","_signinSilentIframe","idTokenValidation","_validateIdTokenFromTokenRefreshToken","auth_time","silent_redirect_uri","_iframeNavigator","signinSilentCallback","signinCallback","signoutCallback","signoutRedirectCallback","signoutPopupCallback","query_status_response_type","navResponse","signinResponse","navigatorParams","signoutRedirect","postLogoutRedirectUri","_signoutStart","_signoutEnd","signoutPopup","popup_post_logout_redirect_uri","_signout","revokePromise","revokeAccessTokenOnSignout","_revokeInternal","signoutRequest","signoutResponse","revokeAccessToken","success","_revokeAccessTokenInternal","_revokeRefreshTokenInternal","atSuccess","rtSuccess","stopSilentRenew","_userStore","_userStoreKey","redirectNavigator","popupNavigator","iframeNavigator","userStore","_userLoaded","_userUnloaded","_silentRenewError","_userSignedIn","_userSignedOut","_userSessionChanged","removeUserLoaded","removeUserUnloaded","addSilentRenewError","removeSilentRenewError","addUserSignedIn","removeUserSignedIn","addUserSignedOut","removeUserSignedOut","addUserSessionChanged","removeUserSessionChanged","DefaultCheckSessionInterval","store","_popup_redirect_uri","_popup_post_logout_redirect_uri","_popupWindowFeatures","_popupWindowTarget","_silent_redirect_uri","_silentRequestTimeout","_automaticSilentRenew","_validateSubOnSilentRenew","_includeIdTokenInSilentRenew","_monitorSession","_monitorAnonymousSession","_query_status_response_type","_revokeAccessTokenOnSignout","prefix","_store","_prefix"],"mappings":";;AAAA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;;AAGA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA,kDAA0C,gCAAgC;AAC1E;AACA;;AAEA;AACA;AACA;AACA,gEAAwD,kBAAkB;AAC1E;AACA,yDAAiD,cAAc;AAC/D;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,iDAAyC,iCAAiC;AAC1E,wHAAgH,mBAAmB,EAAE;AACrI;AACA;;AAEA;AACA;AACA;AACA,mCAA2B,0BAA0B,EAAE;AACvD,yCAAiC,eAAe;AAChD;AACA;AACA;;AAEA;AACA,8DAAsD,+DAA+D;;AAErH;AACA;;;AAGA;AACA;;;;;;;;;;;;;;;;;;;AC/EA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AAEA;;AAnBA;AACA;;kBAoBe;AACXA,6BADW;AAEXC,iBAFW;AAGXC,sCAHW;AAIXC,8DAJW;AAKXC,oEALW;AAMXC,8DANW;AAOXC,yCAPW;AAQXC,2DARW;AASXC,qDATW;AAUXC,uEAVW;AAWXC,0EAXW;AAYXC,8DAZW;AAaXC,uEAbW;AAcXC,kDAdW;AAeXC,0BAfW;AAgBXC;AAhBW,C;;;;;;;;;;;;;;;;;;;;;ACrBf;;;;AAIA,IAAIC,YAAY,EAAhB;AACAA,UAAUC,SAAV,GAAsB,KAAtB;;AAEA,IAAIC,SAAS,EAAb;;AAEA;;;;;;AAMA,IAAGC,UAAQC,SAAX,EAAqB;AAAC,MAAID,QAAM,EAAV;AAAa,OAAME,IAAN,GAAW,EAACC,QAAO,gBAASC,CAAT,EAAWC,CAAX,EAAaC,CAAb,EAAe;AAAC,QAAG,CAACD,CAAD,IAAI,CAACD,CAAR,EAAU;AAAC,YAAM,IAAIG,KAAJ,CAAU,4EAAV,CAAN;AAA8F,SAAIC,IAAE,SAAFA,CAAE,GAAU,CAAE,CAAlB,CAAmBA,EAAEC,SAAF,GAAYJ,EAAEI,SAAd,CAAwBL,EAAEK,SAAF,GAAY,IAAID,CAAJ,EAAZ,CAAoBJ,EAAEK,SAAF,CAAYC,WAAZ,GAAwBN,CAAxB,CAA0BA,EAAEO,UAAF,GAAaN,EAAEI,SAAf,CAAyB,IAAGJ,EAAEI,SAAF,CAAYC,WAAZ,IAAyBE,OAAOH,SAAP,CAAiBC,WAA7C,EAAyD;AAACL,QAAEI,SAAF,CAAYC,WAAZ,GAAwBL,CAAxB;AAA0B,SAAGC,CAAH,EAAK;AAAC,UAAIO,CAAJ,CAAM,KAAIA,CAAJ,IAASP,CAAT,EAAW;AAACF,UAAEK,SAAF,CAAYI,CAAZ,IAAeP,EAAEO,CAAF,CAAf;AAAoB,WAAIC,IAAE,aAAU,CAAE,CAAlB;AAAA,UAAmBC,IAAE,CAAC,UAAD,EAAY,SAAZ,CAArB,CAA4C,IAAG;AAAC,YAAG,OAAOC,IAAP,CAAYnB,UAAUC,SAAtB,CAAH,EAAoC;AAACgB,cAAE,WAASG,CAAT,EAAWC,CAAX,EAAa;AAAC,iBAAIL,IAAE,CAAN,EAAQA,IAAEE,EAAEI,MAAZ,EAAmBN,IAAEA,IAAE,CAAvB,EAAyB;AAAC,kBAAIO,IAAEL,EAAEF,CAAF,CAAN;AAAA,kBAAWQ,IAAEH,EAAEE,CAAF,CAAb,CAAkB,IAAG,OAAOC,CAAP,KAAW,UAAX,IAAuBA,KAAGT,OAAOH,SAAP,CAAiBW,CAAjB,CAA7B,EAAiD;AAACH,kBAAEG,CAAF,IAAKC,CAAL;AAAO;AAAC;AAAC,WAAvH;AAAwH;AAAC,OAAlK,CAAkK,OAAMC,CAAN,EAAQ,CAAE,GAAElB,EAAEK,SAAJ,EAAcH,CAAd;AAAiB;AAAC,GAA7lB,EAAX;AACnC;;;;;;;;AAQA,IAAIiB,WAASA,YAAW,UAAST,CAAT,EAAWV,CAAX,EAAa;AAAC,MAAIkB,IAAE,EAAN,CAAS,IAAIT,IAAES,EAAEE,GAAF,GAAM,EAAZ,CAAe,IAAIP,IAAEJ,EAAEY,IAAF,GAAQ,YAAU;AAAC,aAASC,CAAT,GAAY,CAAE,QAAM,EAACvB,QAAO,gBAASwB,CAAT,EAAW;AAACD,UAAEjB,SAAF,GAAY,IAAZ,CAAiB,IAAImB,IAAE,IAAIF,CAAJ,EAAN,CAAc,IAAGC,CAAH,EAAK;AAACC,YAAEC,KAAF,CAAQF,CAAR;AAAW,aAAG,CAACC,EAAEE,cAAF,CAAiB,MAAjB,CAAJ,EAA6B;AAACF,YAAEG,IAAF,GAAO,YAAU;AAACH,cAAEI,MAAF,CAASD,IAAT,CAAcE,KAAd,CAAoB,IAApB,EAAyBC,SAAzB;AAAoC,WAAtD;AAAuD,WAAEH,IAAF,CAAOtB,SAAP,GAAiBmB,CAAjB,CAAmBA,EAAEI,MAAF,GAAS,IAAT,CAAc,OAAOJ,CAAP;AAAS,OAAnM,EAAoMO,QAAO,kBAAU;AAAC,YAAIP,IAAE,KAAKzB,MAAL,EAAN,CAAoByB,EAAEG,IAAF,CAAOE,KAAP,CAAaL,CAAb,EAAeM,SAAf,EAA0B,OAAON,CAAP;AAAS,OAA7Q,EAA8QG,MAAK,gBAAU,CAAE,CAA/R,EAAgSF,OAAM,eAASF,CAAT,EAAW;AAAC,aAAI,IAAIC,CAAR,IAAaD,CAAb,EAAe;AAAC,cAAGA,EAAEG,cAAF,CAAiBF,CAAjB,CAAH,EAAuB;AAAC,iBAAKA,CAAL,IAAQD,EAAEC,CAAF,CAAR;AAAa;AAAC,aAAGD,EAAEG,cAAF,CAAiB,UAAjB,CAAH,EAAgC;AAAC,eAAKM,QAAL,GAAcT,EAAES,QAAhB;AAAyB;AAAC,OAAna,EAAoaC,OAAM,iBAAU;AAAC,eAAO,KAAKN,IAAL,CAAUtB,SAAV,CAAoBN,MAApB,CAA2B,IAA3B,CAAP;AAAwC,OAA7d,EAAN;AAAqe,GAA9f,EAAd,CAAghB,IAAIiB,IAAEP,EAAEyB,SAAF,GAAYrB,EAAEd,MAAF,CAAS,EAAC4B,MAAK,cAASH,CAAT,EAAWF,CAAX,EAAa;AAACE,UAAE,KAAKW,KAAL,GAAWX,KAAG,EAAhB,CAAmB,IAAGF,KAAGtB,CAAN,EAAQ;AAAC,aAAKoC,QAAL,GAAcd,CAAd;AAAgB,OAAzB,MAA6B;AAAC,aAAKc,QAAL,GAAcZ,EAAET,MAAF,GAAS,CAAvB;AAAyB;AAAC,KAA/F,EAAgGiB,UAAS,kBAASV,CAAT,EAAW;AAAC,aAAM,CAACA,KAAGrB,CAAJ,EAAOoC,SAAP,CAAiB,IAAjB,CAAN;AAA6B,KAAlJ,EAAmJC,QAAO,gBAASC,CAAT,EAAW;AAAC,UAAIC,IAAE,KAAKL,KAAX,CAAiB,IAAIZ,IAAEgB,EAAEJ,KAAR,CAAc,IAAIb,IAAE,KAAKc,QAAX,CAAoB,IAAIK,IAAEF,EAAEH,QAAR,CAAiB,KAAKM,KAAL,GAAa,IAAGpB,IAAE,CAAL,EAAO;AAAC,aAAI,IAAIqB,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,GAAhB,EAAoB;AAAC,cAAInB,IAAGD,EAAEoB,MAAI,CAAN,MAAY,KAAIA,IAAE,CAAH,GAAM,CAAtB,GAA0B,GAAhC,CAAoCH,EAAGlB,IAAEqB,CAAH,KAAQ,CAAV,KAAcnB,KAAI,KAAI,CAACF,IAAEqB,CAAH,IAAM,CAAP,GAAU,CAA/B;AAAkC;AAAC,OAApG,MAAwG;AAAC,aAAI,IAAIA,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,KAAG,CAAnB,EAAqB;AAACH,YAAGlB,IAAEqB,CAAH,KAAQ,CAAV,IAAapB,EAAEoB,MAAI,CAAN,CAAb;AAAsB;AAAC,YAAKP,QAAL,IAAeK,CAAf,CAAiB,OAAO,IAAP;AAAY,KAA1a,EAA2aC,OAAM,iBAAU;AAAC,UAAIlB,IAAE,KAAKW,KAAX,CAAiB,IAAIb,IAAE,KAAKc,QAAX,CAAoBZ,EAAEF,MAAI,CAAN,KAAU,cAAa,KAAIA,IAAE,CAAH,GAAM,CAAhC,CAAmCE,EAAET,MAAF,GAASL,EAAEkC,IAAF,CAAOtB,IAAE,CAAT,CAAT;AAAqB,KAAzhB,EAA0hBW,OAAM,iBAAU;AAAC,UAAIX,IAAET,EAAEoB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyBvB,EAAEa,KAAF,GAAQ,KAAKA,KAAL,CAAWW,KAAX,CAAiB,CAAjB,CAAR,CAA4B,OAAOxB,CAAP;AAAS,KAAzmB,EAA0mByB,QAAO,gBAASxB,CAAT,EAAW;AAAC,UAAIC,IAAE,EAAN,CAAS,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAEC,CAAd,EAAgBD,KAAG,CAAnB,EAAqB;AAACE,UAAEwB,IAAF,CAAQtC,EAAEqC,MAAF,KAAW,UAAZ,GAAwB,CAA/B;AAAkC,cAAO,IAAI/B,EAAEW,IAAN,CAAWH,CAAX,EAAaD,CAAb,CAAP;AAAuB,KAArtB,EAAT,CAAlB,CAAmvB,IAAI0B,IAAE/B,EAAEgC,GAAF,GAAM,EAAZ,CAAe,IAAIjD,IAAEgD,EAAEE,GAAF,GAAM,EAACd,WAAU,mBAASd,CAAT,EAAW;AAAC,UAAIoB,IAAEpB,EAAEY,KAAR,CAAc,IAAIX,IAAED,EAAEa,QAAR,CAAiB,IAAII,IAAE,EAAN,CAAS,KAAI,IAAIlB,IAAE,CAAV,EAAYA,IAAEE,CAAd,EAAgBF,GAAhB,EAAoB;AAAC,YAAImB,IAAGE,EAAErB,MAAI,CAAN,MAAY,KAAIA,IAAE,CAAH,GAAM,CAAtB,GAA0B,GAAhC,CAAoCkB,EAAEQ,IAAF,CAAO,CAACP,MAAI,CAAL,EAAQT,QAAR,CAAiB,EAAjB,CAAP,EAA6BQ,EAAEQ,IAAF,CAAO,CAACP,IAAE,EAAH,EAAOT,QAAP,CAAgB,EAAhB,CAAP;AAA4B,cAAOQ,EAAEY,IAAF,CAAO,EAAP,CAAP;AAAkB,KAAnM,EAAoMC,OAAM,eAAS9B,CAAT,EAAW;AAAC,UAAID,IAAEC,EAAER,MAAR,CAAe,IAAIyB,IAAE,EAAN,CAAS,KAAI,IAAIhB,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,KAAG,CAAnB,EAAqB;AAACgB,UAAEhB,MAAI,CAAN,KAAU8B,SAAS/B,EAAEgC,MAAF,CAAS/B,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,KAA6B,KAAIA,IAAE,CAAH,GAAM,CAAhD;AAAmD,cAAO,IAAIR,EAAEW,IAAN,CAAWa,CAAX,EAAalB,IAAE,CAAf,CAAP;AAAyB,KAAhV,EAAZ,CAA8V,IAAIlB,IAAE6C,EAAEO,MAAF,GAAS,EAACnB,WAAU,mBAASG,CAAT,EAAW;AAAC,UAAIG,IAAEH,EAAEL,KAAR,CAAc,IAAIZ,IAAEiB,EAAEJ,QAAR,CAAiB,IAAId,IAAE,EAAN,CAAS,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAED,CAAd,EAAgBC,GAAhB,EAAoB;AAAC,YAAIiB,IAAGE,EAAEnB,MAAI,CAAN,MAAY,KAAIA,IAAE,CAAH,GAAM,CAAtB,GAA0B,GAAhC,CAAoCF,EAAE0B,IAAF,CAAOS,OAAOC,YAAP,CAAoBjB,CAApB,CAAP;AAA+B,cAAOnB,EAAE8B,IAAF,CAAO,EAAP,CAAP;AAAkB,KAAzK,EAA0KC,OAAM,eAAS9B,CAAT,EAAW;AAAC,UAAID,IAAEC,EAAER,MAAR,CAAe,IAAIyB,IAAE,EAAN,CAAS,KAAI,IAAIhB,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,GAAhB,EAAoB;AAACgB,UAAEhB,MAAI,CAAN,KAAU,CAACD,EAAEoC,UAAF,CAAanC,CAAb,IAAgB,GAAjB,KAAwB,KAAIA,IAAE,CAAH,GAAM,CAA3C;AAA8C,cAAO,IAAIR,EAAEW,IAAN,CAAWa,CAAX,EAAalB,CAAb,CAAP;AAAuB,KAA9S,EAAf,CAA+T,IAAIX,IAAEsC,EAAEW,IAAF,GAAO,EAACvB,WAAU,mBAASf,CAAT,EAAW;AAAC,UAAG;AAAC,eAAOuC,mBAAmBC,OAAO1D,EAAEiC,SAAF,CAAYf,CAAZ,CAAP,CAAnB,CAAP;AAAkD,OAAtD,CAAsD,OAAME,CAAN,EAAQ;AAAC,cAAM,IAAIrB,KAAJ,CAAU,sBAAV,CAAN;AAAwC;AAAC,KAA/H,EAAgIkD,OAAM,eAAS/B,CAAT,EAAW;AAAC,aAAOlB,EAAEiD,KAAF,CAAQU,SAASC,mBAAmB1C,CAAnB,CAAT,CAAR,CAAP;AAAgD,KAAlM,EAAb,CAAiN,IAAIR,IAAEL,EAAEwD,sBAAF,GAAyBpD,EAAEd,MAAF,CAAS,EAACmE,OAAM,iBAAU;AAAC,WAAKC,KAAL,GAAW,IAAInD,EAAEW,IAAN,EAAX,CAAwB,KAAKyC,WAAL,GAAiB,CAAjB;AAAmB,KAA7D,EAA8DC,SAAQ,iBAAS/C,CAAT,EAAW;AAAC,UAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAACA,YAAEX,EAAE0C,KAAF,CAAQ/B,CAAR,CAAF;AAAa,YAAK6C,KAAL,CAAW7B,MAAX,CAAkBhB,CAAlB,EAAqB,KAAK8C,WAAL,IAAkB9C,EAAEc,QAApB;AAA6B,KAAxK,EAAyKkC,UAAS,kBAASC,CAAT,EAAW;AAAC,UAAI/B,IAAE,KAAK2B,KAAX,CAAiB,IAAIK,IAAEhC,EAAEL,KAAR,CAAc,IAAIb,IAAEkB,EAAEJ,QAAR,CAAiB,IAAIG,IAAE,KAAKkC,SAAX,CAAqB,IAAIC,IAAEnC,IAAE,CAAR,CAAU,IAAIoC,IAAErD,IAAEoD,CAAR,CAAU,IAAGH,CAAH,EAAK;AAACI,YAAEjE,EAAEkC,IAAF,CAAO+B,CAAP,CAAF;AAAY,OAAlB,MAAsB;AAACA,YAAEjE,EAAEkE,GAAF,CAAM,CAACD,IAAE,CAAH,IAAM,KAAKE,cAAjB,EAAgC,CAAhC,CAAF;AAAqC,WAAIpC,IAAEkC,IAAEpC,CAAR,CAAU,IAAII,IAAEjC,EAAEoE,GAAF,CAAMrC,IAAE,CAAR,EAAUnB,CAAV,CAAN,CAAmB,IAAGmB,CAAH,EAAK;AAAC,aAAI,IAAIlB,IAAE,CAAV,EAAYA,IAAEkB,CAAd,EAAgBlB,KAAGgB,CAAnB,EAAqB;AAAC,eAAKwC,eAAL,CAAqBP,CAArB,EAAuBjD,CAAvB;AAA0B,aAAIC,IAAEgD,EAAEQ,MAAF,CAAS,CAAT,EAAWvC,CAAX,CAAN,CAAoBD,EAAEJ,QAAF,IAAYO,CAAZ;AAAc,cAAO,IAAI3B,EAAEW,IAAN,CAAWH,CAAX,EAAamB,CAAb,CAAP;AAAuB,KAA/d,EAAgeV,OAAM,iBAAU;AAAC,UAAIX,IAAET,EAAEoB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyBvB,EAAE6C,KAAF,GAAQ,KAAKA,KAAL,CAAWlC,KAAX,EAAR,CAA2B,OAAOX,CAAP;AAAS,KAA9iB,EAA+iBuD,gBAAe,CAA9jB,EAAT,CAA/B,CAA0mB,IAAI3E,IAAEO,EAAEwE,MAAF,GAASnE,EAAEf,MAAF,CAAS,EAACmF,KAAIrE,EAAEd,MAAF,EAAL,EAAgB4B,MAAK,cAASL,CAAT,EAAW;AAAC,WAAK4D,GAAL,GAAS,KAAKA,GAAL,CAASnF,MAAT,CAAgBuB,CAAhB,CAAT,CAA4B,KAAK4C,KAAL;AAAa,KAA1E,EAA2EA,OAAM,iBAAU;AAACpD,QAAEoD,KAAF,CAAQrB,IAAR,CAAa,IAAb,EAAmB,KAAKsC,QAAL;AAAgB,KAA/H,EAAgIC,QAAO,gBAAS9D,CAAT,EAAW;AAAC,WAAK+C,OAAL,CAAa/C,CAAb,EAAgB,KAAKgD,QAAL,GAAgB,OAAO,IAAP;AAAY,KAA/L,EAAgMe,UAAS,kBAAS/D,CAAT,EAAW;AAAC,UAAGA,CAAH,EAAK;AAAC,aAAK+C,OAAL,CAAa/C,CAAb;AAAgB,WAAIE,IAAE,KAAK8D,WAAL,EAAN,CAAyB,OAAO9D,CAAP;AAAS,KAA7Q,EAA8QiD,WAAU,MAAI,EAA5R,EAA+Rc,eAAc,uBAASjE,CAAT,EAAW;AAAC,aAAO,UAASC,CAAT,EAAWC,CAAX,EAAa;AAAC,eAAO,IAAIF,EAAEK,IAAN,CAAWH,CAAX,EAAc6D,QAAd,CAAuB9D,CAAvB,CAAP;AAAiC,OAAtD;AAAuD,KAAhX,EAAiXiE,mBAAkB,2BAASlE,CAAT,EAAW;AAAC,aAAO,UAASC,CAAT,EAAWC,CAAX,EAAa;AAAC,eAAO,IAAIP,EAAEwE,IAAF,CAAO9D,IAAX,CAAgBL,CAAhB,EAAkBE,CAAlB,EAAqB6D,QAArB,CAA8B9D,CAA9B,CAAP;AAAwC,OAA7D;AAA8D,KAA7c,EAAT,CAAf,CAAwe,IAAIN,IAAEC,EAAEwE,IAAF,GAAO,EAAb,CAAgB,OAAOxE,CAAP;AAAS,CAAjxG,CAAkxGyE,IAAlxG,CAAxB;AACA;;;;;;AAMA,CAAC,UAAS3F,CAAT,EAAW;AAAC,MAAIkB,IAAEC,QAAN;AAAA,MAAejB,IAAEgB,EAAEE,GAAnB;AAAA,MAAuBV,IAAER,EAAEmB,IAA3B;AAAA,MAAgCpB,IAAEC,EAAEgC,SAApC;AAAA,MAA8ChB,IAAEA,EAAE0E,GAAF,GAAM,EAAtD,CAAyD1E,EAAE2E,IAAF,GAAOnF,EAAEX,MAAF,CAAS,EAAC4B,MAAK,cAASlB,CAAT,EAAWE,CAAX,EAAa;AAAC,WAAKmF,IAAL,GAAUrF,CAAV,CAAY,KAAKsF,GAAL,GAASpF,CAAT;AAAW,KAA3C,EAAT,CAAP,CAA8DO,EAAEgB,SAAF,GAAYxB,EAAEX,MAAF,CAAS,EAAC4B,MAAK,cAASlB,CAAT,EAAWE,CAAX,EAAa;AAACF,UAAE,KAAK0B,KAAL,GAAW1B,KAAG,EAAhB,CAAmB,KAAK2B,QAAL,GAAczB,KAAGX,CAAH,GAAKW,CAAL,GAAO,IAAEF,EAAEM,MAAzB;AAAgC,KAAvE,EAAwEiF,OAAM,iBAAU;AAAC,WAAI,IAAIvF,IAAE,KAAK0B,KAAX,EAAiBxB,IAAEF,EAAEM,MAArB,EAA4BG,IAAE,EAA9B,EAAiCd,IAAE,CAAvC,EAAyCA,IAAEO,CAA3C,EAA6CP,GAA7C,EAAiD;AAAC,YAAIM,IAAED,EAAEL,CAAF,CAAN,CAAWc,EAAE8B,IAAF,CAAOtC,EAAEoF,IAAT,EAAe5E,EAAE8B,IAAF,CAAOtC,EAAEqF,GAAT;AAAc,cAAO9F,EAAE8B,MAAF,CAASb,CAAT,EAAW,KAAKkB,QAAhB,CAAP;AAAiC,KAApN,EAAqNH,OAAM,iBAAU;AAAC,WAAI,IAAIxB,IAAEC,EAAEuB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,EAAyBlC,IAAEF,EAAE0B,KAAF,GAAQ,KAAKA,KAAL,CAAWW,KAAX,CAAiB,CAAjB,CAAnC,EAAuD5B,IAAEP,EAAEI,MAA3D,EAAkEX,IAAE,CAAxE,EAA0EA,IAAEc,CAA5E,EAA8Ed,GAA9E;AAAkFO,UAAEP,CAAF,IAAKO,EAAEP,CAAF,EAAK6B,KAAL,EAAL;AAAlF,OAAoG,OAAOxB,CAAP;AAAS,KAAnV,EAAT,CAAZ;AAA2W,CAA/e;;AAEA;;;;;;AAMA,CAAC,YAAU;AAAC,MAAIR,IAAEkB,QAAN;AAAA,MAAeN,IAAEZ,EAAEmB,GAAF,CAAMc,SAAvB,CAAiCjC,EAAEiD,GAAF,CAAM+C,MAAN,GAAa,EAAC5D,WAAU,mBAAS5B,CAAT,EAAW;AAAC,UAAIC,IAAED,EAAE0B,KAAR;AAAA,UAAcjC,IAAEO,EAAE2B,QAAlB;AAAA,UAA2BzB,IAAE,KAAKuF,IAAlC,CAAuCzF,EAAEiC,KAAF,GAAUjC,IAAE,EAAF,CAAK,KAAI,IAAIS,IAAE,CAAV,EAAYA,IAAEhB,CAAd,EAAgBgB,KAAG,CAAnB;AAAqB,aAAI,IAAId,IAAE,CAACM,EAAEQ,MAAI,CAAN,MAAW,KAAG,KAAGA,IAAE,CAAL,CAAd,GAAsB,GAAvB,KAA6B,EAA7B,GAAgC,CAACR,EAAEQ,IAAE,CAAF,KAAM,CAAR,MAAa,KAAG,KAAG,CAACA,IAAE,CAAH,IAAM,CAAT,CAAhB,GAA4B,GAA7B,KAAmC,CAAnE,GAAqER,EAAEQ,IAAE,CAAF,KAAM,CAAR,MAAa,KAAG,KAAG,CAACA,IAAE,CAAH,IAAM,CAAT,CAAhB,GAA4B,GAAvG,EAA2GlB,IAAE,CAAjH,EAAmH,IAAEA,CAAF,IAAKkB,IAAE,OAAKlB,CAAP,GAASE,CAAjI,EAAmIF,GAAnI;AAAuIS,YAAEuC,IAAF,CAAOrC,EAAEwF,MAAF,CAAS/F,MAAI,KAAG,IAAEJ,CAAL,CAAJ,GAAY,EAArB,CAAP;AAAvI;AAArB,OAA6L,IAAGU,IAAEC,EAAEwF,MAAF,CAAS,EAAT,CAAL,EAAkB,OAAK1F,EAAEM,MAAF,GAAS,CAAd;AAAiBN,UAAEuC,IAAF,CAAOtC,CAAP;AAAjB,OAA2B,OAAOD,EAAE2C,IAAF,CAAO,EAAP,CAAP;AAAkB,KAAzU,EAA0UC,OAAM,eAAS5C,CAAT,EAAW;AAAC,UAAIC,IAAED,EAAEM,MAAR;AAAA,UAAeb,IAAE,KAAKgG,IAAtB;AAAA,UAA2BvF,IAAET,EAAEiG,MAAF,CAAS,EAAT,CAA7B,CAA0CxF,MAAIA,IAAEF,EAAE2F,OAAF,CAAUzF,CAAV,CAAF,EAAe,CAAC,CAAD,IAAIA,CAAJ,KAAQD,IAAEC,CAAV,CAAnB,EAAiC,KAAI,IAAIA,IAAE,EAAN,EAASO,IAAE,CAAX,EAAad,IAAE,CAAnB,EAAqBA,IACtfM,CADie,EAC/dN,GAD+d;AAC3d,YAAGA,IAAE,CAAL,EAAO;AAAC,cAAIJ,IAAEE,EAAEkG,OAAF,CAAU3F,EAAE0F,MAAF,CAAS/F,IAAE,CAAX,CAAV,KAA0B,KAAGA,IAAE,CAAL,CAAhC;AAAA,cAAwCH,IAAEC,EAAEkG,OAAF,CAAU3F,EAAE0F,MAAF,CAAS/F,CAAT,CAAV,MAAyB,IAAE,KAAGA,IAAE,CAAL,CAArE,CAA6EO,EAAEO,MAAI,CAAN,KAAU,CAAClB,IAAEC,CAAH,KAAO,KAAG,KAAGiB,IAAE,CAAL,CAApB,CAA4BA;AAAI;AADsW,OACtW,OAAOL,EAAEkB,MAAF,CAASpB,CAAT,EAAWO,CAAX,CAAP;AAAqB,KADtF,EACuFgF,MAAK,mEAD5F,EAAb;AAC8K,CAD3N;;AAGA;;;;;;AAMA,CAAC,UAASjF,CAAT,EAAW;AAAC,OAAI,IAAIjB,IAAEmB,QAAN,EAAelB,IAAED,EAAEoB,GAAnB,EAAuBsD,IAAEzE,EAAEiC,SAA3B,EAAqCrB,IAAEZ,EAAEgF,MAAzC,EAAgDhF,IAAED,EAAE0F,IAApD,EAAyDjD,IAAE,EAA3D,EAA8DF,IAAE,EAAhE,EAAmEoC,IAAE,SAAFA,CAAE,CAASnC,CAAT,EAAW;AAAC,WAAO,cAAYA,KAAGA,IAAE,CAAL,CAAZ,IAAqB,CAA5B;AAA8B,GAA/G,EAAgHxB,IAAE,CAAlH,EAAoHP,IAAE,CAA1H,EAA4H,KAAGA,CAA/H,GAAkI;AAAC,QAAIL,CAAJ,CAAMc,GAAE;AAACd,UAAEY,CAAF,CAAI,KAAI,IAAIuD,IAAEtD,EAAEoF,IAAF,CAAOjG,CAAP,CAAN,EAAgBuC,IAAE,CAAtB,EAAwBA,KAAG4B,CAA3B,EAA6B5B,GAA7B;AAAiC,YAAG,EAAEvC,IAAEuC,CAAJ,CAAH,EAAU;AAACvC,cAAE,CAAC,CAAH,CAAK,MAAMc,CAAN;AAAQ;AAAzD,OAAyDd,IAAE,CAAC,CAAH;AAAK,WAAI,IAAEK,CAAF,KAAMgC,EAAEhC,CAAF,IAAKkE,EAAE1D,EAAEqF,GAAF,CAAMtF,CAAN,EAAQ,GAAR,CAAF,CAAX,GAA4BuB,EAAE9B,CAAF,IAAKkE,EAAE1D,EAAEqF,GAAF,CAAMtF,CAAN,EAAQ,IAAE,CAAV,CAAF,CAAjC,EAAiDP,GAArD,EAA0DO;AAAI,OAAIM,IAAE,EAAN;AAAA,MAASrB,IAAEA,EAAEsG,MAAF,GAAS1F,EAAEd,MAAF,CAAS,EAACoF,UAAS,oBAAU;AAAC,WAAKqB,KAAL,GAAW,IAAI9B,EAAE/C,IAAN,CAAWc,EAAEK,KAAF,CAAQ,CAAR,CAAX,CAAX;AAAkC,KAAvD,EAAwDiC,iBAAgB,yBAASvC,CAAT,EAAWvC,CAAX,EAAa;AAAC,WAAI,IAAIiB,IAAE,KAAKsF,KAAL,CAAWrE,KAAjB,EAAuBxB,IAAEO,EAAE,CAAF,CAAzB,EAA8Bd,IAAEc,EAAE,CAAF,CAAhC,EAAqCT,IAAES,EAAE,CAAF,CAAvC,EAA4CD,IAAEC,EAAE,CAAF,CAA9C,EAAmDhB,IAAEgB,EAAE,CAAF,CAArD,EAA0DlB,IAAEkB,EAAE,CAAF,CAA5D,EAAiEL,IAAEK,EAAE,CAAF,CAAnE,EAAwEF,IAAEE,EAAE,CAAF,CAA1E,EAA+ER,IAAE,CAArF,EAAuF,KAAGA,CAA1F,EAA4FA,GAA5F,EAAgG;AAAC,YAAG,KAAGA,CAAN,EAAQY,EAAEZ,CAAF,IACrf8B,EAAEvC,IAAES,CAAJ,IAAO,CAD8e,CAAR,KAChe;AAAC,cAAIuC,IAAE3B,EAAEZ,IAAE,EAAJ,CAAN;AAAA,cAAca,IAAED,EAAEZ,IAAE,CAAJ,CAAhB,CAAuBY,EAAEZ,CAAF,IAAK,CAAC,CAACuC,KAAG,EAAH,GAAMA,MAAI,CAAX,KAAeA,KAAG,EAAH,GAAMA,MAAI,EAAzB,IAA6BA,MAAI,CAAlC,IAAqC3B,EAAEZ,IAAE,CAAJ,CAArC,IAA6C,CAACa,KAAG,EAAH,GAAMA,MAAI,EAAX,KAAgBA,KAAG,EAAH,GAAMA,MAAI,EAA1B,IAA8BA,MAAI,EAA/E,IAAmFD,EAAEZ,IAAE,EAAJ,CAAxF;AAAgG,aAAEM,KAAG,CAACd,KAAG,EAAH,GAAMA,MAAI,CAAX,KAAeA,KAAG,EAAH,GAAMA,MAAI,EAAzB,KAA8BA,KAAG,CAAH,GAAKA,MAAI,EAAvC,CAAH,KAAgDA,IAAEF,CAAF,GAAI,CAACE,CAAD,GAAGW,CAAvD,IAA0D0B,EAAE7B,CAAF,CAA1D,GAA+DY,EAAEZ,CAAF,CAAjE,CAAsEa,IAAE,CAAC,CAACZ,KAAG,EAAH,GAAMA,MAAI,CAAX,KAAeA,KAAG,EAAH,GAAMA,MAAI,EAAzB,KAA8BA,KAAG,EAAH,GAAMA,MAAI,EAAxC,CAAD,KAA+CA,IAAEP,CAAF,GAAIO,IAAEF,CAAN,GAAQL,IAAEK,CAAzD,CAAF,CAA8DO,IAAEH,CAAF,CAAIA,IAAEb,CAAF,CAAIA,IAAEE,CAAF,CAAIA,IAAEe,IAAEgC,CAAF,GAAI,CAAN,CAAQhC,IAAER,CAAF,CAAIA,IAAEL,CAAF,CAAIA,IAAEO,CAAF,CAAIA,IAAEsC,IAAE1B,CAAF,GAAI,CAAN;AAAQ,SAAE,CAAF,IAAKL,EAAE,CAAF,IAAKP,CAAL,GAAO,CAAZ,CAAcO,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKd,CAAL,GAAO,CAAZ,CAAcc,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKT,CAAL,GAAO,CAAZ,CAAcS,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKD,CAAL,GAAO,CAAZ,CAAcC,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKhB,CAAL,GAAO,CAAZ,CAAcgB,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKlB,CAAL,GAAO,CAAZ,CAAckB,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKL,CAAL,GAAO,CAAZ,CAAcK,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKF,CAAL,GAAO,CAAZ;AAAc,KAD3G,EAC4GsE,aAAY,uBAAU;AAAC,UAAIlF,IAAE,KAAK+D,KAAX;AAAA,UAAiB1D,IAAEL,EAAE+B,KAArB;AAAA,UAA2BjB,IAAE,IAAE,KAAKkD,WAApC;AAAA,UAAgDzD,IAAE,IAAEP,EAAEgC,QAAtD;AACzb3B,QAAEE,MAAI,CAAN,KAAU,OAAK,KAAGA,IAAE,EAApB,CAAuBF,EAAE,CAACE,IAAE,EAAF,KAAO,CAAP,IAAU,CAAX,IAAc,EAAhB,IAAoBM,EAAEwF,KAAF,CAAQvF,IAAE,UAAV,CAApB,CAA0CT,EAAE,CAACE,IAAE,EAAF,KAAO,CAAP,IAAU,CAAX,IAAc,EAAhB,IAAoBO,CAApB,CAAsBd,EAAEgC,QAAF,GAAW,IAAE3B,EAAEM,MAAf,CAAsB,KAAKuD,QAAL,GAAgB,OAAO,KAAKkC,KAAZ;AAAkB,KAFuK,EAEtKvE,OAAM,iBAAU;AAAC,UAAIxB,IAAEI,EAAEoB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyBpC,EAAE+F,KAAF,GAAQ,KAAKA,KAAL,CAAWvE,KAAX,EAAR,CAA2B,OAAOxB,CAAP;AAAS,KAFwF,EAAT,CAApB,CAExDT,EAAEuG,MAAF,GAAS1F,EAAE0E,aAAF,CAAgBtF,CAAhB,CAAT,CAA4BD,EAAE0G,UAAF,GAAa7F,EAAE2E,iBAAF,CAAoBvF,CAApB,CAAb;AAAoC,CAFjS,EAEmS0F,IAFnS;;AAIA;;;;;;AAMA,CAAC,YAAU;AAAC,WAASzE,CAAT,GAAY;AAAC,WAAOd,EAAE2B,MAAF,CAASF,KAAT,CAAezB,CAAf,EAAiB0B,SAAjB,CAAP;AAAmC,QAAI,IAAIR,IAAEH,QAAN,EAAewB,IAAErB,EAAEF,GAAF,CAAM6D,MAAvB,EAA8BvE,IAAEY,EAAEsE,GAAlC,EAAsCxF,IAAEM,EAAEmF,IAA1C,EAA+Cc,IAAEjG,EAAEwB,SAAnD,EAA6DxB,IAAEY,EAAEoE,IAAjE,EAAsEkB,KAAG,CAAC1F,EAAE,UAAF,EAAa,UAAb,CAAD,EAA0BA,EAAE,UAAF,EAAa,SAAb,CAA1B,EAAkDA,EAAE,UAAF,EAAa,UAAb,CAAlD,EAA2EA,EAAE,UAAF,EAAa,UAAb,CAA3E,EAAoGA,EAAE,SAAF,EAAY,UAAZ,CAApG,EAA4HA,EAAE,UAAF,EAAa,UAAb,CAA5H,EAAqJA,EAAE,UAAF,EAAa,UAAb,CAArJ,EAA8KA,EAAE,UAAF,EAAa,UAAb,CAA9K,EAAuMA,EAAE,UAAF,EAAa,UAAb,CAAvM,EAAgOA,EAAE,SAAF,EAAY,UAAZ,CAAhO,EAAwPA,EAAE,SAAF,EAAY,UAAZ,CAAxP,EAAgRA,EAAE,UAAF,EAAa,UAAb,CAAhR,EAAySA,EAAE,UAAF,EAAa,UAAb,CAAzS,EAAkUA,EAAE,UAAF,EAAa,SAAb,CAAlU,EAA0VA,EAAE,UAAF,EAAa,SAAb,CAA1V,EACzIA,EAAE,UAAF,EAAa,UAAb,CADyI,EAChHA,EAAE,UAAF,EAAa,UAAb,CADgH,EACvFA,EAAE,UAAF,EAAa,SAAb,CADuF,EAC/DA,EAAE,SAAF,EAAY,UAAZ,CAD+D,EACvCA,EAAE,SAAF,EAAY,UAAZ,CADuC,EACfA,EAAE,SAAF,EAAY,UAAZ,CADe,EACSA,EAAE,UAAF,EAAa,UAAb,CADT,EACkCA,EAAE,UAAF,EAAa,UAAb,CADlC,EAC2DA,EAAE,UAAF,EAAa,UAAb,CAD3D,EACoFA,EAAE,UAAF,EAAa,UAAb,CADpF,EAC6GA,EAAE,UAAF,EAAa,SAAb,CAD7G,EACqIA,EAAE,UAAF,EAAa,UAAb,CADrI,EAC8JA,EAAE,UAAF,EAAa,UAAb,CAD9J,EACuLA,EAAE,UAAF,EAAa,UAAb,CADvL,EACgNA,EAAE,UAAF,EAAa,UAAb,CADhN,EACyOA,EAAE,SAAF,EAAY,UAAZ,CADzO,EACiQA,EAAE,SAAF,EAAY,SAAZ,CADjQ,EACwRA,EAAE,SAAF,EAAY,UAAZ,CADxR,EACgTA,EAAE,SAAF,EAAY,UAAZ,CADhT,EACwUA,EAAE,UAAF,EAAa,UAAb,CADxU,EACiWA,EAAE,UAAF,EAC1e,UAD0e,CADjW,EAE7HA,EAAE,UAAF,EAAa,UAAb,CAF6H,EAEpGA,EAAE,UAAF,EAAa,UAAb,CAFoG,EAE3EA,EAAE,UAAF,EAAa,UAAb,CAF2E,EAElDA,EAAE,UAAF,EAAa,SAAb,CAFkD,EAE1BA,EAAE,UAAF,EAAa,UAAb,CAF0B,EAEDA,EAAE,UAAF,EAAa,UAAb,CAFC,EAEwBA,EAAE,UAAF,EAAa,UAAb,CAFxB,EAEiDA,EAAE,UAAF,EAAa,SAAb,CAFjD,EAEyEA,EAAE,UAAF,EAAa,UAAb,CAFzE,EAEkGA,EAAE,UAAF,EAAa,UAAb,CAFlG,EAE2HA,EAAE,UAAF,EAAa,UAAb,CAF3H,EAEoJA,EAAE,SAAF,EAAY,SAAZ,CAFpJ,EAE2KA,EAAE,SAAF,EAAY,UAAZ,CAF3K,EAEmMA,EAAE,SAAF,EAAY,UAAZ,CAFnM,EAE2NA,EAAE,SAAF,EAAY,UAAZ,CAF3N,EAEmPA,EAAE,SAAF,EAAY,UAAZ,CAFnP,EAE2QA,EAAE,SAAF,EAAY,UAAZ,CAF3Q,EAEmSA,EAAE,UAAF,EAAa,UAAb,CAFnS,EAE4TA,EAAE,UAAF,EAAa,UAAb,CAF5T,EAEqVA,EAAE,UAAF,EAAa,UAAb,CAFrV,EAGzIA,EAAE,UAAF,EAAa,UAAb,CAHyI,EAGhHA,EAAE,UAAF,EAAa,UAAb,CAHgH,EAGvFA,EAAE,UAAF,EAAa,UAAb,CAHuF,EAG9DA,EAAE,UAAF,EAAa,SAAb,CAH8D,EAGtCA,EAAE,UAAF,EAAa,SAAb,CAHsC,EAGdA,EAAE,UAAF,EAAa,UAAb,CAHc,EAGWA,EAAE,UAAF,EAAa,UAAb,CAHX,EAGoCA,EAAE,UAAF,EAAa,UAAb,CAHpC,EAG6DA,EAAE,UAAF,EAAa,UAAb,CAH7D,EAGsFA,EAAE,UAAF,EAAa,SAAb,CAHtF,EAG8GA,EAAE,UAAF,EAAa,UAAb,CAH9G,EAGuIA,EAAE,UAAF,EAAa,UAAb,CAHvI,EAGgKA,EAAE,SAAF,EAAY,UAAZ,CAHhK,EAGwLA,EAAE,SAAF,EAAY,UAAZ,CAHxL,EAGgNA,EAAE,SAAF,EAAY,UAAZ,CAHhN,EAGwOA,EAAE,SAAF,EAAY,SAAZ,CAHxO,EAG+PA,EAAE,SAAF,EAAY,SAAZ,CAH/P,EAGsRA,EAAE,SAAF,EAAY,UAAZ,CAHtR,EAG8SA,EAAE,UAAF,EAAa,SAAb,CAH9S,EAGsUA,EAAE,UAAF,EAAa,UAAb,CAHtU,EAG+VA,EAAE,UAAF,EACxe,UADwe,CAH/V,EAI7HA,EAAE,UAAF,EAAa,UAAb,CAJ6H,EAIpGA,EAAE,UAAF,EAAa,SAAb,CAJoG,EAI5EA,EAAE,UAAF,EAAa,UAAb,CAJ4E,CAAzE,EAIuBwD,IAAE,EAJzB,EAI4BH,IAAE,CAJlC,EAIoC,KAAGA,CAJvC,EAIyCA,GAJzC;AAI6CG,MAAEH,CAAF,IAAKrD,GAAL;AAJ7C,GAIsDR,IAAEA,EAAEmG,MAAF,GAASlE,EAAE5C,MAAF,CAAS,EAACoF,UAAS,oBAAU;AAAC,WAAKqB,KAAL,GAAW,IAAIG,EAAEhF,IAAN,CAAW,CAAC,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAD,EAAmC,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAnC,EAAqE,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAArE,EAAuG,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAvG,EAAyI,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAzI,EAA2K,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAA3K,EAA4M,IAAIvB,EAAEuB,IAAN,CAAW,SAAX,EAAqB,UAArB,CAA5M,EAA6O,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAA7O,CAAX,CAAX;AAAsS,KAA3T,EAA4ToD,iBAAgB,yBAAS7D,CAAT,EAAWd,CAAX,EAAa;AAAC,WAAI,IAAIF,IAAE,KAAKsG,KAAL,CAAWrE,KAAjB,EACpe2E,IAAE5G,EAAE,CAAF,CADke,EAC7dQ,IAAER,EAAE,CAAF,CAD2d,EACtdoB,IAAEpB,EAAE,CAAF,CADod,EAC/cyC,IAAEzC,EAAE,CAAF,CAD6c,EACxc6G,IAAE7G,EAAE,CAAF,CADsc,EACjc8G,IAAE9G,EAAE,CAAF,CAD+b,EAC1b+G,IAAE/G,EAAE,CAAF,CADwb,EACnbA,IAAEA,EAAE,CAAF,CADib,EAC5aqE,IAAEuC,EAAEhB,IADwa,EACnaoB,IAAEJ,EAAEf,GAD+Z,EAC3ZoB,IAAEzG,EAAEoF,IADuZ,EAClZsB,IAAE1G,EAAEqF,GAD8Y,EAC1YsB,IAAE/F,EAAEwE,IADsY,EACjYwB,IAAEhG,EAAEyE,GAD6X,EACzXwB,IAAE5E,EAAEmD,IADqX,EAChX0B,IAAE7E,EAAEoD,GAD4W,EACxW0B,IAAEV,EAAEjB,IADoW,EAC/V4B,IAAEX,EAAEhB,GAD2V,EACvV4B,KAAGX,EAAElB,IADkV,EAC7U8B,IAAEZ,EAAEjB,GADyU,EACrU8B,KAAGZ,EAAEnB,IADgU,EAC3TgC,IAAEb,EAAElB,GADuT,EACnTgC,KAAG7H,EAAE4F,IAD8S,EACzSkC,IAAE9H,EAAE6F,GADqS,EACjS9E,IAAEsD,CAD+R,EAC7RvE,IAAEkH,CAD2R,EACzRe,IAAEd,CADuR,EACrR3C,IAAE4C,CADmR,EACjRc,IAAEb,CAD+Q,EAC7Qc,IAAEb,CAD2Q,EACzQc,IAAEb,CADuQ,EACrQc,IAAEb,CADmQ,EACjQxG,IAAEyG,CAD+P,EAC7PxH,IAAEyH,CAD2P,EACzPY,IAAEX,EADuP,EACpPY,IAAEX,CADkP,EAChPY,IAAEX,EAD8O,EAC3OY,IAAEX,CADyO,EACvOY,IAAEX,EADqO,EAClOY,IAAEX,CADgO,EAC9N/E,IAAE,CADwN,EACtN,KAAGA,CADmN,EACjNA,GADiN,EAC7M;AAAC,YAAIR,IAAEiC,EAAEzB,CAAF,CAAN,CAAW,IAAG,KAAGA,CAAN,EAAQ,IAAIpC,IAAE4B,EAAEqD,IAAF,GAAO5E,EAAEd,IAAE,IAAE6C,CAAN,IAAS,CAAtB;AAAA,YAAwBxC,IAAEgC,EAAEsD,GAAF,GAAM7E,EAAEd,IAAE,IAAE6C,CAAJ,GAAM,CAAR,IAAW,CAA3C,CAAR,KAAyD;AAAC,cAAIpC,IAAE6D,EAAEzB,IAAE,EAAJ,CAAN;AAAA,cAAcxC,IAAEI,EAAEiF,IAAlB;AAAA,cAAuBvE,IAAEV,EAAEkF,GAA3B;AAAA,cAA+BlF,IAAE,CAACJ,MAAI,CAAJ,GAAMc,KAAG,EAAV,KAAed,MAAI,CAAJ,GAAMc,KAAG,EAAxB,IAA4Bd,MAAI,CAAjE;AAAA,cAAmEc,IAAE,CAACA,MAAI,CAAJ,GAAMd,KAAG,EAAV,KAAec,MAAI,CAAJ,GAAMd,KAAG,EAAxB,KAA6Bc,MAAI,CAAJ,GAAMd,KAAG,EAAtC,CAArE;AAAA,cAA+GkE,IAAED,EAAEzB,IAAE,CAAJ,CAAjH;AAAA,cAAwHxC,IAAEkE,EAAEmB,IAA5H;AAAA,cAAiInF,IAAEgE,EAAEoB,GAArI;AAAA,cAAyIpB,IAAE,CAAClE,MAAI,EAAJ,GAAOE,KAAG,EAAX,KAAgBF,KACpf,CADof,GAClfE,MAAI,EAD8d,IAC1dF,MAAI,CAD2U;AAAA,cACzUE,IAAE,CAACA,MAAI,EAAJ,GAAOF,KAAG,EAAX,KAAgBE,KAAG,CAAH,GAAKF,MAAI,EAAzB,KAA8BE,MAAI,CAAJ,GAAMF,KAAG,EAAvC,CADuU;AAAA,cAC5RA,IAAEiE,EAAEzB,IAAE,CAAJ,CAD0R;AAAA,cACnR2F,IAAEnI,EAAEqF,IAD+Q;AAAA,cAC1QvD,IAAEmC,EAAEzB,IAAE,EAAJ,CADwQ;AAAA,cAChQT,IAAED,EAAEuD,IAD4P;AAAA,cACvPvD,IAAEA,EAAEwD,GADmP;AAAA,cAC/OtF,IAAEc,IAAEd,EAAEsF,GADyO;AAAA,cACrOlF,IAAEA,IAAE+H,CAAF,IAAKnI,MAAI,CAAJ,GAAMc,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADmO;AAAA,cAC7Md,IAAEA,IAAEE,CADyM;AAAA,cACvME,IAAEA,IAAE8D,CAAF,IAAKlE,MAAI,CAAJ,GAAME,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADqM;AAAA,cAC/KF,IAAEA,IAAE8B,CAD2K;AAAA,cACzK1B,IAAEA,IAAE2B,CAAF,IAAK/B,MAAI,CAAJ,GAAM8B,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADuK,CACjJE,EAAEqD,IAAF,GAAOjF,CAAP,CAAS4B,EAAEsD,GAAF,GAAMtF,CAAN;AAAQ,aAAImI,IAAE5H,IAAEsH,CAAF,GAAI,CAACtH,CAAD,GAAGwH,CAAb;AAAA,YAAejG,IAAEtC,IAAEsI,CAAF,GAAI,CAACtI,CAAD,GAAGwI,CAAxB;AAAA,YAA0BhG,IAAExB,IAAEgH,CAAF,GAAIhH,IAAEiH,CAAN,GAAQD,IAAEC,CAAtC;AAAA,YAAwCvB,IAAE3G,IAAEwE,CAAF,GAAIxE,IAAEmI,CAAN,GAAQ3D,IAAE2D,CAApD;AAAA,YAAsD5G,IAAE,CAACN,MAAI,EAAJ,GAAOjB,KAAG,CAAX,KAAeiB,KAAG,EAAH,GAAMjB,MAAI,CAAzB,KAA6BiB,KAAG,EAAH,GAAMjB,MAAI,CAAvC,CAAxD;AAAA,YAAkG2E,IAAE,CAAC3E,MAAI,EAAJ,GAAOiB,KAAG,CAAX,KAAejB,KAAG,EAAH,GAAMiB,MAAI,CAAzB,KAA6BjB,KAAG,EAAH,GAAMiB,MAAI,CAAvC,CAApG;AAAA,YAA8IN,IAAEiG,GAAG3D,CAAH,CAAhJ;AAAA,YAAsJ4F,KAAGlI,EAAEmF,IAA3J;AAAA,YAAgKgD,KAAGnI,EAAEoF,GAArK;AAAA,YAAyKpF,IAAEgI,KAAG,CAAC1I,MAAI,EAAJ,GAAOe,KAAG,EAAX,KAAgBf,MAAI,EAAJ,GAAOe,KAAG,EAA1B,KAA+Bf,KAAG,EAAH,GAAMe,MAAI,CAAzC,CAAH,CAA3K;AAAA,YAA2NwB,IAAEkG,KAAG,CAAC1H,MAAI,EAAJ,GAAOf,KAAG,EAAX,KAAgBe,MAAI,EAAJ,GAAOf,KAAG,EAA1B,KAA+Be,KAAG,EAAH,GAAMf,MAAI,CAAzC,CAAH,KAAiDU,MAAI,CAAJ,GAAMgI,MAAI,CAAV,GAAY,CAAZ,GACve,CADsb,CAA7N;AAAA,YACtNhI,IAAEA,IAAE4B,CADkN;AAAA,YAChNC,IAAEA,IAAEoG,CAAF,IAAKjI,MAAI,CAAJ,GAAM4B,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAD8M;AAAA,YACxL5B,IAAEA,IAAEmI,EADoL;AAAA,YACjLtG,IAAEA,IAAEqG,EAAF,IAAMlI,MAAI,CAAJ,GAAMmI,OAAK,CAAX,GAAa,CAAb,GAAe,CAArB,CAD+K;AAAA,YACvJnI,IAAEA,IAAEF,CADmJ;AAAA,YACjJ+B,IAAEA,IAAE3B,CAAF,IAAKF,MAAI,CAAJ,GAAMF,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAD+I;AAAA,YACzHA,IAAEkE,IAAEgC,CADqH;AAAA,YACnHlE,IAAElB,IAAEkB,CAAF,IAAKhC,MAAI,CAAJ,GAAMkE,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADiH;AAAA,YAC3F+D,IAAEF,CADyF;AAAA,YACvFG,IAAEF,CADqF;AAAA,YACnFD,IAAEF,CADiF;AAAA,YAC/EG,IAAEF,CAD6E;AAAA,YAC3ED,IAAEtH,CADyE;AAAA,YACvEuH,IAAEtI,CADqE;AAAA,YACnEA,IAAEoI,IAAE1H,CAAF,GAAI,CAD6D;AAAA,YAC3DK,IAAEoH,IAAE5F,CAAF,IAAKvC,MAAI,CAAJ,GAAMoI,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,IAAsB,CADmC;AAAA,YACjCD,IAAEF,CAD+B;AAAA,YAC7BG,IAAEF,CAD2B;AAAA,YACzBD,IAAED,CADuB;AAAA,YACrBE,IAAE3D,CADmB;AAAA,YACjByD,IAAEhH,CADe;AAAA,YACbuD,IAAExE,CADW;AAAA,YACTA,IAAEW,IAAEF,CAAF,GAAI,CADG;AAAA,YACDQ,IAAEuB,IAAEC,CAAF,IAAKzC,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,IAAsB,CADvB;AACyB,WAAEmG,EAAEf,GAAF,GAAMmB,IAAElH,CAAV,CAAY8G,EAAEhB,IAAF,GAAOvB,IAAEtD,CAAF,IAAKiG,MAAI,CAAJ,GAAMlH,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6BoH,IAAE1G,EAAEqF,GAAF,GAAMqB,IAAE5C,CAAV,CAAY9D,EAAEoF,IAAF,GAAOqB,IAAEc,CAAF,IAAKb,MAAI,CAAJ,GAAM5C,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6B8C,IAAEhG,EAAEyE,GAAF,GAAMuB,IAAEa,CAAV,CAAY7G,EAAEwE,IAAF,GAAOuB,IAAEa,CAAF,IAAKZ,MAAI,CAAJ,GAAMa,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6BX,IAAE7E,EAAEoD,GAAF,GAAMyB,IAAEa,CAAV,CAAY1F,EAAEmD,IAAF,GAAOyB,IAAEa,CAAF,IAAKZ,MAAI,CAAJ,GAAMa,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6BX,IAAEX,EAAEhB,GAAF,GAAM2B,IAAEzH,CAAV,CAAY8G,EAAEjB,IAAF,GAAO2B,IAAEzG,CAAF,IAAK0G,MAAI,CAAJ,GAAMzH,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6B2H,IAAEZ,EAAEjB,GAAF,GAAM6B,IAAEW,CAAV,CAAYvB,EAAElB,IAAF,GAAO6B,KAAGW,CAAH,IAAMV,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAApB,CAAP,CAA8BT,IAAEb,EAAElB,GAAF,GAAM+B,IAAEW,CAAV;AACzexB,QAAEnB,IAAF,GAAO+B,KAAGW,CAAH,IAAMV,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAApB,CAAP,CAA8BT,IAAE9H,EAAE6F,GAAF,GAAMiC,IAAEW,CAAV,CAAYzI,EAAE4F,IAAF,GAAOiC,KAAGW,CAAH,IAAMV,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAApB,CAAP;AAA8B,KAJ8D,EAI7DrD,aAAY,uBAAU;AAAC,UAAIpE,IAAE,KAAKiD,KAAX;AAAA,UAAiB/D,IAAEc,EAAEiB,KAArB;AAAA,UAA2BjC,IAAE,IAAE,KAAKkE,WAApC;AAAA,UAAgD1D,IAAE,IAAEQ,EAAEkB,QAAtD,CAA+DhC,EAAEM,MAAI,CAAN,KAAU,OAAK,KAAGA,IAAE,EAApB,CAAuBN,EAAE,CAACM,IAAE,GAAF,KAAQ,EAAR,IAAY,CAAb,IAAgB,EAAlB,IAAsBiF,KAAKc,KAAL,CAAWvG,IAAE,UAAb,CAAtB,CAA+CE,EAAE,CAACM,IAAE,GAAF,KAAQ,EAAR,IAAY,CAAb,IAAgB,EAAlB,IAAsBR,CAAtB,CAAwBgB,EAAEkB,QAAF,GAAW,IAAEhC,EAAEW,MAAf,CAAsB,KAAKuD,QAAL,GAAgB,OAAO,KAAKkC,KAAL,CAAWR,KAAX,EAAP;AAA0B,KAJvL,EAIwL/D,OAAM,iBAAU;AAAC,UAAIf,IAAEyB,EAAEV,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyB3B,EAAEsF,KAAF,GAAQ,KAAKA,KAAL,CAAWvE,KAAX,EAAR,CAA2B,OAAOf,CAAP;AAAS,KAJtQ,EAIuQuD,WAAU,EAJjR,EAAT,CAAX,CAI0SnD,EAAEuF,MAAF,GAASlE,EAAE4C,aAAF,CAAgB7E,CAAhB,CAAT,CAA4BY,EAAEyH,UAAF,GAAapG,EAAE6C,iBAAF,CAAoB9E,CAApB,CAAb;AAAoC,CAR5d;;AAUA;;;;;;AAMA,CAAC,YAAU;AAAC,MAAIC,IAAEQ,QAAN;AAAA,MAAeD,IAAEP,EAAEiF,GAAnB;AAAA,MAAuBnF,IAAES,EAAE2E,IAA3B;AAAA,MAAgCnF,IAAEQ,EAAEgB,SAApC;AAAA,MAA8ChB,IAAEP,EAAE+E,IAAlD;AAAA,MAAuDtF,IAAEc,EAAE2F,MAA3D;AAAA,MAAkE3F,IAAEA,EAAE8H,MAAF,GAAS5I,EAAEL,MAAF,CAAS,EAACoF,UAAS,oBAAU;AAAC,WAAKqB,KAAL,GAAW,IAAI9F,EAAEiB,IAAN,CAAW,CAAC,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAD,EAAmC,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAAnC,EAAoE,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAApE,EAAqG,IAAIlB,EAAEkB,IAAN,CAAW,SAAX,EAAqB,UAArB,CAArG,EAAsI,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAtI,EAAwK,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAxK,EAA0M,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAA1M,EAA4O,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAA5O,CAAX,CAAX;AAAsS,KAA3T,EAA4T2D,aAAY,uBAAU;AAAC,UAAIpE,IAAEd,EAAEkF,WAAF,CAAczC,IAAd,CAAmB,IAAnB,CAAN,CAA+B3B,EAAEkB,QAAF,IAAY,EAAZ,CAAe,OAAOlB,CAAP;AAAS,KAA1Y,EAAT,CAA7E,CAAmeP,EAAEqI,MAAF,GAC/e5I,EAAEmF,aAAF,CAAgBrE,CAAhB,CAD+e,CAC5dP,EAAEsI,UAAF,GAAa7I,EAAEoF,iBAAF,CAAoBtE,CAApB,CAAb;AAAoC,CADvD;;AAGA;;AAEA,IAAIgI,SAAO,kEAAX,CAA8E,IAAIC,SAAO,GAAX,CAAe,SAASC,OAAT,CAAiBhJ,CAAjB,EAAmB;AAAC,MAAIK,CAAJ,CAAM,IAAIC,CAAJ,CAAM,IAAIQ,IAAE,EAAN,CAAS,KAAIT,IAAE,CAAN,EAAQA,IAAE,CAAF,IAAKL,EAAEW,MAAf,EAAsBN,KAAG,CAAzB,EAA2B;AAACC,QAAE4C,SAASlD,EAAEiJ,SAAF,CAAY5I,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAF,CAAkCS,KAAGgI,OAAO/C,MAAP,CAAczF,KAAG,CAAjB,IAAoBwI,OAAO/C,MAAP,CAAczF,IAAE,EAAhB,CAAvB;AAA2C,OAAGD,IAAE,CAAF,IAAKL,EAAEW,MAAV,EAAiB;AAACL,QAAE4C,SAASlD,EAAEiJ,SAAF,CAAY5I,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAF,CAAkCS,KAAGgI,OAAO/C,MAAP,CAAczF,KAAG,CAAjB,CAAH;AAAuB,GAA3E,MAA+E;AAAC,QAAGD,IAAE,CAAF,IAAKL,EAAEW,MAAV,EAAiB;AAACL,UAAE4C,SAASlD,EAAEiJ,SAAF,CAAY5I,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAF,CAAkCS,KAAGgI,OAAO/C,MAAP,CAAczF,KAAG,CAAjB,IAAoBwI,OAAO/C,MAAP,CAAc,CAACzF,IAAE,CAAH,KAAO,CAArB,CAAvB;AAA+C;AAAC,OAAGyI,MAAH,EAAU;AAAC,WAAM,CAACjI,EAAEH,MAAF,GAAS,CAAV,IAAa,CAAnB,EAAqB;AAACG,WAAGiI,MAAH;AAAU;AAAC,UAAOjI,CAAP;AAAS,UAASoI,QAAT,CAAkBpJ,CAAlB,EAAoB;AAAC,MAAIE,IAAE,EAAN,CAAS,IAAIM,CAAJ,CAAM,IAAID,IAAE,CAAN,CAAQ,IAAIE,CAAJ,CAAM,IAAIO,CAAJ,CAAM,KAAIR,IAAE,CAAN,EAAQA,IAAER,EAAEa,MAAZ,EAAmB,EAAEL,CAArB,EAAuB;AAAC,QAAGR,EAAEiG,MAAF,CAASzF,CAAT,KAAayI,MAAhB,EAAuB;AAAC;AAAM,SAAED,OAAO9C,OAAP,CAAelG,EAAEiG,MAAF,CAASzF,CAAT,CAAf,CAAF,CAA8B,IAAGQ,IAAE,CAAL,EAAO;AAAC;AAAS,SAAGT,KAAG,CAAN,EAAQ;AAACL,WAAGmJ,SAASrI,KAAG,CAAZ,CAAH,CAAkBP,IAAEO,IAAE,CAAJ,CAAMT,IAAE,CAAF;AAAI,KAArC,MAAyC;AAAC,UAAGA,KAAG,CAAN,EAAQ;AAACL,aAAGmJ,SAAU5I,KAAG,CAAJ,GAAQO,KAAG,CAApB,CAAH,CAA2BP,IAAEO,IAAE,EAAJ,CAAOT,IAAE,CAAF;AAAI,OAA/C,MAAmD;AAAC,YAAGA,KAAG,CAAN,EAAQ;AAACL,eAAGmJ,SAAS5I,CAAT,CAAH,CAAeP,KAAGmJ,SAASrI,KAAG,CAAZ,CAAH,CAAkBP,IAAEO,IAAE,CAAJ,CAAMT,IAAE,CAAF;AAAI,SAApD,MAAwD;AAACL,eAAGmJ,SAAU5I,KAAG,CAAJ,GAAQO,KAAG,CAApB,CAAH,CAA2Bd,KAAGmJ,SAASrI,IAAE,EAAX,CAAH,CAAkBT,IAAE,CAAF;AAAI;AAAC;AAAC;AAAC,OAAGA,KAAG,CAAN,EAAQ;AAACL,SAAGmJ,SAAS5I,KAAG,CAAZ,CAAH;AAAkB,UAAOP,CAAP;AAAS,UAASoJ,OAAT,CAAiB9I,CAAjB,EAAmB;AAAC,MAAIN,IAAEkJ,SAAS5I,CAAT,CAAN,CAAkB,IAAIC,CAAJ,CAAM,IAAIF,IAAE,IAAIgJ,KAAJ,EAAN,CAAkB,KAAI9I,IAAE,CAAN,EAAQ,IAAEA,CAAF,GAAIP,EAAEW,MAAd,EAAqB,EAAEJ,CAAvB,EAAyB;AAACF,MAAEE,CAAF,IAAK2C,SAASlD,EAAEiJ,SAAF,CAAY,IAAE1I,CAAd,EAAgB,IAAEA,CAAF,GAAI,CAApB,CAAT,EAAgC,EAAhC,CAAL;AAAyC,UAAOF,CAAP;AAAS;AAC9+B;;AAEA,IAAIiJ,KAAJ,CAAU,IAAIC,SAAO,eAAX,CAA2B,IAAIC,OAAM,CAACD,SAAO,QAAR,KAAmB,QAA7B,CAAuC,SAASE,UAAT,CAAoBnJ,CAApB,EAAsBN,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,MAAGQ,KAAG,IAAN,EAAW;AAAC,QAAG,YAAU,OAAOA,CAApB,EAAsB;AAAC,WAAKoJ,UAAL,CAAgBpJ,CAAhB,EAAkBN,CAAlB,EAAoBF,CAApB;AAAuB,KAA9C,MAAkD;AAAC,UAAGE,KAAG,IAAH,IAAS,YAAU,OAAOM,CAA7B,EAA+B;AAAC,aAAKqJ,UAAL,CAAgBrJ,CAAhB,EAAkB,GAAlB;AAAuB,OAAvD,MAA2D;AAAC,aAAKqJ,UAAL,CAAgBrJ,CAAhB,EAAkBN,CAAlB;AAAqB;AAAC;AAAC;AAAC,UAAS4J,GAAT,GAAc;AAAC,SAAO,IAAIH,UAAJ,CAAe,IAAf,CAAP;AAA4B,UAASI,GAAT,CAAa/J,CAAb,EAAegB,CAAf,EAAiBT,CAAjB,EAAmBC,CAAnB,EAAqBT,CAArB,EAAuBD,CAAvB,EAAyB;AAAC,SAAM,EAAEA,CAAF,IAAK,CAAX,EAAa;AAAC,QAAII,IAAEc,IAAE,KAAKhB,GAAL,CAAF,GAAYO,EAAEC,CAAF,CAAZ,GAAiBT,CAAvB,CAAyBA,IAAE0F,KAAKc,KAAL,CAAWrG,IAAE,QAAb,CAAF,CAAyBK,EAAEC,GAAF,IAAON,IAAE,QAAT;AAAkB,UAAOH,CAAP;AAAS,UAASiK,GAAT,CAAahK,CAAb,EAAesC,CAAf,EAAiBG,CAAjB,EAAmBjC,CAAnB,EAAqBc,CAArB,EAAuBN,CAAvB,EAAyB;AAAC,MAAID,IAAEuB,IAAE,KAAR;AAAA,MAAcjB,IAAEiB,KAAG,EAAnB,CAAsB,OAAM,EAAEtB,CAAF,IAAK,CAAX,EAAa;AAAC,QAAId,IAAE,KAAKF,CAAL,IAAQ,KAAd,CAAoB,IAAIF,IAAE,KAAKE,GAAL,KAAW,EAAjB,CAAoB,IAAIO,IAAEc,IAAEnB,CAAF,GAAIJ,IAAEiB,CAAZ,CAAcb,IAAEa,IAAEb,CAAF,IAAK,CAACK,IAAE,KAAH,KAAW,EAAhB,IAAoBkC,EAAEjC,CAAF,CAApB,IAA0Bc,IAAE,UAA5B,CAAF,CAA0CA,IAAE,CAACpB,MAAI,EAAL,KAAUK,MAAI,EAAd,IAAkBc,IAAEvB,CAApB,IAAuBwB,MAAI,EAA3B,CAAF,CAAiCmB,EAAEjC,GAAF,IAAON,IAAE,UAAT;AAAoB,UAAOoB,CAAP;AAAS,UAAS2I,GAAT,CAAajK,CAAb,EAAesC,CAAf,EAAiBG,CAAjB,EAAmBjC,CAAnB,EAAqBc,CAArB,EAAuBN,CAAvB,EAAyB;AAAC,MAAID,IAAEuB,IAAE,KAAR;AAAA,MAAcjB,IAAEiB,KAAG,EAAnB,CAAsB,OAAM,EAAEtB,CAAF,IAAK,CAAX,EAAa;AAAC,QAAId,IAAE,KAAKF,CAAL,IAAQ,KAAd,CAAoB,IAAIF,IAAE,KAAKE,GAAL,KAAW,EAAjB,CAAoB,IAAIO,IAAEc,IAAEnB,CAAF,GAAIJ,IAAEiB,CAAZ,CAAcb,IAAEa,IAAEb,CAAF,IAAK,CAACK,IAAE,KAAH,KAAW,EAAhB,IAAoBkC,EAAEjC,CAAF,CAApB,GAAyBc,CAA3B,CAA6BA,IAAE,CAACpB,KAAG,EAAJ,KAASK,KAAG,EAAZ,IAAgBc,IAAEvB,CAApB,CAAsB2C,EAAEjC,GAAF,IAAON,IAAE,SAAT;AAAmB,UAAOoB,CAAP;AAAS,KAAGoI,QAAOnK,UAAU2K,OAAV,IAAmB,6BAA7B,EAA4D;AAACP,aAAWxJ,SAAX,CAAqBgK,EAArB,GAAwBH,GAAxB,CAA4BR,QAAM,EAAN;AAAS,CAAlG,MAAsG;AAAC,MAAGE,QAAOnK,UAAU2K,OAAV,IAAmB,UAA7B,EAAyC;AAACP,eAAWxJ,SAAX,CAAqBgK,EAArB,GAAwBJ,GAAxB,CAA4BP,QAAM,EAAN;AAAS,GAA/E,MAAmF;AAACG,eAAWxJ,SAAX,CAAqBgK,EAArB,GAAwBF,GAAxB,CAA4BT,QAAM,EAAN;AAAS;AAAC,YAAWrJ,SAAX,CAAqBiK,EAArB,GAAwBZ,KAAxB,CAA8BG,WAAWxJ,SAAX,CAAqBkK,EAArB,GAAyB,CAAC,KAAGb,KAAJ,IAAW,CAApC,CAAuCG,WAAWxJ,SAAX,CAAqBmK,EAArB,GAAyB,KAAGd,KAA5B,CAAmC,IAAIe,QAAM,EAAV,CAAaZ,WAAWxJ,SAAX,CAAqBqK,EAArB,GAAwB/E,KAAKW,GAAL,CAAS,CAAT,EAAWmE,KAAX,CAAxB,CAA0CZ,WAAWxJ,SAAX,CAAqBsK,EAArB,GAAwBF,QAAMf,KAA9B,CAAoCG,WAAWxJ,SAAX,CAAqBuK,EAArB,GAAwB,IAAElB,KAAF,GAAQe,KAAhC,CAAsC,IAAII,QAAM,sCAAV,CAAiD,IAAIC,QAAM,IAAIrB,KAAJ,EAAV,CAAsB,IAAIsB,EAAJ,EAAOC,EAAP,CAAUD,KAAG,IAAIpH,UAAJ,CAAe,CAAf,CAAH,CAAqB,KAAIqH,KAAG,CAAP,EAASA,MAAI,CAAb,EAAe,EAAEA,EAAjB,EAAoB;AAACF,QAAMC,IAAN,IAAYC,EAAZ;AAAe,MAAG,IAAIrH,UAAJ,CAAe,CAAf,CAAH,CAAqB,KAAIqH,KAAG,EAAP,EAAUA,KAAG,EAAb,EAAgB,EAAEA,EAAlB,EAAqB;AAACF,QAAMC,IAAN,IAAYC,EAAZ;AAAe,MAAG,IAAIrH,UAAJ,CAAe,CAAf,CAAH,CAAqB,KAAIqH,KAAG,EAAP,EAAUA,KAAG,EAAb,EAAgB,EAAEA,EAAlB,EAAqB;AAACF,QAAMC,IAAN,IAAYC,EAAZ;AAAe,UAASzB,QAAT,CAAkBrI,CAAlB,EAAoB;AAAC,SAAO2J,MAAM1E,MAAN,CAAajF,CAAb,CAAP;AAAuB,UAAS+J,KAAT,CAAexK,CAAf,EAAiBS,CAAjB,EAAmB;AAAC,MAAId,IAAE0K,MAAMrK,EAAEkD,UAAF,CAAazC,CAAb,CAAN,CAAN,CAA6B,OAAOd,KAAG,IAAJ,GAAU,CAAC,CAAX,GAAaA,CAAnB;AAAqB,UAAS8K,SAAT,CAAmBzK,CAAnB,EAAqB;AAAC,OAAI,IAAIS,IAAE,KAAKqB,CAAL,GAAO,CAAjB,EAAmBrB,KAAG,CAAtB,EAAwB,EAAEA,CAA1B,EAA4B;AAACT,MAAES,CAAF,IAAK,KAAKA,CAAL,CAAL;AAAa,KAAEqB,CAAF,GAAI,KAAKA,CAAT,CAAW9B,EAAEgC,CAAF,GAAI,KAAKA,CAAT;AAAW,UAAS0I,UAAT,CAAoBjK,CAApB,EAAsB;AAAC,OAAKqB,CAAL,GAAO,CAAP,CAAS,KAAKE,CAAL,GAAQvB,IAAE,CAAH,GAAM,CAAC,CAAP,GAAS,CAAhB,CAAkB,IAAGA,IAAE,CAAL,EAAO;AAAC,SAAK,CAAL,IAAQA,CAAR;AAAU,GAAlB,MAAsB;AAAC,QAAGA,IAAE,CAAC,CAAN,EAAQ;AAAC,WAAK,CAAL,IAAQA,IAAE,KAAKsJ,EAAf;AAAkB,KAA3B,MAA+B;AAAC,WAAKjI,CAAL,GAAO,CAAP;AAAS;AAAC;AAAC,UAAS6I,GAAT,CAAalK,CAAb,EAAe;AAAC,MAAIT,IAAEuJ,KAAN,CAAYvJ,EAAE4K,OAAF,CAAUnK,CAAV,EAAa,OAAOT,CAAP;AAAS,UAAS6K,aAAT,CAAuBrL,CAAvB,EAAyBU,CAAzB,EAA2B;AAAC,MAAID,CAAJ,CAAM,IAAGC,KAAG,EAAN,EAAS;AAACD,QAAE,CAAF;AAAI,GAAd,MAAkB;AAAC,QAAGC,KAAG,CAAN,EAAQ;AAACD,UAAE,CAAF;AAAI,KAAb,MAAiB;AAAC,UAAGC,KAAG,GAAN,EAAU;AAACD,YAAE,CAAF;AAAI,OAAf,MAAmB;AAAC,YAAGC,KAAG,CAAN,EAAQ;AAACD,cAAE,CAAF;AAAI,SAAb,MAAiB;AAAC,cAAGC,KAAG,EAAN,EAAS;AAACD,gBAAE,CAAF;AAAI,WAAd,MAAkB;AAAC,gBAAGC,KAAG,CAAN,EAAQ;AAACD,kBAAE,CAAF;AAAI,aAAb,MAAiB;AAAC,mBAAK6K,SAAL,CAAetL,CAAf,EAAiBU,CAAjB,EAAoB;AAAO;AAAC;AAAC;AAAC;AAAC;AAAC,QAAK4B,CAAL,GAAO,CAAP,CAAS,KAAKE,CAAL,GAAO,CAAP,CAAS,IAAIzC,IAAEC,EAAEc,MAAR;AAAA,MAAeX,IAAE,KAAjB;AAAA,MAAuBF,IAAE,CAAzB,CAA2B,OAAM,EAAEF,CAAF,IAAK,CAAX,EAAa;AAAC,QAAIkB,IAAGR,KAAG,CAAJ,GAAOT,EAAED,CAAF,IAAK,GAAZ,GAAgBiL,MAAMhL,CAAN,EAAQD,CAAR,CAAtB,CAAiC,IAAGkB,IAAE,CAAL,EAAO;AAAC,UAAGjB,EAAEkG,MAAF,CAASnG,CAAT,KAAa,GAAhB,EAAoB;AAACI,YAAE,IAAF;AAAO;AAAS,SAAE,KAAF,CAAQ,IAAGF,KAAG,CAAN,EAAQ;AAAC,WAAK,KAAKqC,CAAL,EAAL,IAAerB,CAAf;AAAiB,KAA1B,MAA8B;AAAC,UAAGhB,IAAEQ,CAAF,GAAI,KAAK4J,EAAZ,EAAe;AAAC,aAAK,KAAK/H,CAAL,GAAO,CAAZ,KAAgB,CAACrB,IAAG,CAAC,KAAI,KAAKoJ,EAAL,GAAQpK,CAAb,IAAiB,CAArB,KAA0BA,CAA1C,CAA4C,KAAK,KAAKqC,CAAL,EAAL,IAAgBrB,KAAI,KAAKoJ,EAAL,GAAQpK,CAA5B;AAAgC,OAA5F,MAAgG;AAAC,aAAK,KAAKqC,CAAL,GAAO,CAAZ,KAAgBrB,KAAGhB,CAAnB;AAAqB;AAAC,UAAGQ,CAAH,CAAK,IAAGR,KAAG,KAAKoK,EAAX,EAAc;AAACpK,WAAG,KAAKoK,EAAR;AAAW;AAAC,OAAG5J,KAAG,CAAH,IAAM,CAACT,EAAE,CAAF,IAAK,GAAN,KAAY,CAArB,EAAuB;AAAC,SAAKwC,CAAL,GAAO,CAAC,CAAR,CAAU,IAAGvC,IAAE,CAAL,EAAO;AAAC,WAAK,KAAKqC,CAAL,GAAO,CAAZ,KAAiB,CAAC,KAAI,KAAK+H,EAAL,GAAQpK,CAAb,IAAiB,CAAlB,IAAsBA,CAAtC;AAAwC;AAAC,QAAKwC,KAAL,GAAa,IAAGtC,CAAH,EAAK;AAACyJ,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsB,IAAtB,EAA2B,IAA3B;AAAiC;AAAC,UAASC,QAAT,GAAmB;AAAC,MAAIxK,IAAE,KAAKuB,CAAL,GAAO,KAAK8H,EAAlB,CAAqB,OAAM,KAAKhI,CAAL,GAAO,CAAP,IAAU,KAAK,KAAKA,CAAL,GAAO,CAAZ,KAAgBrB,CAAhC,EAAkC;AAAC,MAAE,KAAKqB,CAAP;AAAS;AAAC,UAASoJ,UAAT,CAAoBhL,CAApB,EAAsB;AAAC,MAAG,KAAK8B,CAAL,GAAO,CAAV,EAAY;AAAC,WAAM,MAAI,KAAKmJ,MAAL,GAAc5J,QAAd,CAAuBrB,CAAvB,CAAV;AAAoC,OAAID,CAAJ,CAAM,IAAGC,KAAG,EAAN,EAAS;AAACD,QAAE,CAAF;AAAI,GAAd,MAAkB;AAAC,QAAGC,KAAG,CAAN,EAAQ;AAACD,UAAE,CAAF;AAAI,KAAb,MAAiB;AAAC,UAAGC,KAAG,CAAN,EAAQ;AAACD,YAAE,CAAF;AAAI,OAAb,MAAiB;AAAC,YAAGC,KAAG,EAAN,EAAS;AAACD,cAAE,CAAF;AAAI,SAAd,MAAkB;AAAC,cAAGC,KAAG,CAAN,EAAQ;AAACD,gBAAE,CAAF;AAAI,WAAb,MAAiB;AAAC,mBAAO,KAAKmL,OAAL,CAAalL,CAAb,CAAP;AAAuB;AAAC;AAAC;AAAC;AAAC,OAAIX,IAAE,CAAC,KAAGU,CAAJ,IAAO,CAAb;AAAA,MAAeM,CAAf;AAAA,MAAiBE,IAAE,KAAnB;AAAA,MAAyBjB,IAAE,EAA3B;AAAA,MAA8BC,IAAE,KAAKqC,CAArC,CAAuC,IAAI1B,IAAE,KAAKyJ,EAAL,GAASpK,IAAE,KAAKoK,EAAR,GAAY5J,CAA1B,CAA4B,IAAGR,MAAI,CAAP,EAAS;AAAC,QAAGW,IAAE,KAAKyJ,EAAP,IAAW,CAACtJ,IAAE,KAAKd,CAAL,KAASW,CAAZ,IAAe,CAA7B,EAA+B;AAACK,UAAE,IAAF,CAAOjB,IAAEsJ,SAASvI,CAAT,CAAF;AAAc,YAAMd,KAAG,CAAT,EAAW;AAAC,UAAGW,IAAEH,CAAL,EAAO;AAACM,YAAE,CAAC,KAAKd,CAAL,IAAS,CAAC,KAAGW,CAAJ,IAAO,CAAjB,KAAuBH,IAAEG,CAA3B,CAA8BG,KAAG,KAAK,EAAEd,CAAP,MAAYW,KAAG,KAAKyJ,EAAL,GAAQ5J,CAAvB,CAAH;AAA6B,OAAnE,MAAuE;AAACM,YAAG,KAAKd,CAAL,MAAUW,KAAGH,CAAb,CAAD,GAAkBV,CAApB,CAAsB,IAAGa,KAAG,CAAN,EAAQ;AAACA,eAAG,KAAKyJ,EAAR,CAAW,EAAEpK,CAAF;AAAI;AAAC,WAAGc,IAAE,CAAL,EAAO;AAACE,YAAE,IAAF;AAAO,WAAGA,CAAH,EAAK;AAACjB,aAAGsJ,SAASvI,CAAT,CAAH;AAAe;AAAC;AAAC,UAAOE,IAAEjB,CAAF,GAAI,GAAX;AAAe,UAAS6L,QAAT,GAAmB;AAAC,MAAI5K,IAAE8I,KAAN,CAAYH,WAAW2B,IAAX,CAAgBC,KAAhB,CAAsB,IAAtB,EAA2BvK,CAA3B,EAA8B,OAAOA,CAAP;AAAS,UAAS6K,KAAT,GAAgB;AAAC,SAAO,KAAKtJ,CAAL,GAAO,CAAR,GAAW,KAAKmJ,MAAL,EAAX,GAAyB,IAA/B;AAAoC,UAASI,WAAT,CAAqBvL,CAArB,EAAuB;AAAC,MAAIL,IAAE,KAAKqC,CAAL,GAAOhC,EAAEgC,CAAf,CAAiB,IAAGrC,KAAG,CAAN,EAAQ;AAAC,WAAOA,CAAP;AAAS,OAAIO,IAAE,KAAK4B,CAAX,CAAanC,IAAEO,IAAEF,EAAE8B,CAAN,CAAQ,IAAGnC,KAAG,CAAN,EAAQ;AAAC,WAAO,KAAKqC,CAAL,GAAO,CAAR,GAAW,CAACrC,CAAZ,GAAcA,CAApB;AAAsB,UAAM,EAAEO,CAAF,IAAK,CAAX,EAAa;AAAC,QAAG,CAACP,IAAE,KAAKO,CAAL,IAAQF,EAAEE,CAAF,CAAX,KAAkB,CAArB,EAAuB;AAAC,aAAOP,CAAP;AAAS;AAAC,UAAO,CAAP;AAAS,UAAS6L,KAAT,CAAe/K,CAAf,EAAiB;AAAC,MAAIP,IAAE,CAAN;AAAA,MAAQF,CAAR,CAAU,IAAG,CAACA,IAAES,MAAI,EAAP,KAAY,CAAf,EAAiB;AAACA,QAAET,CAAF,CAAIE,KAAG,EAAH;AAAM,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,UAAOA,CAAP;AAAS,UAASuL,WAAT,GAAsB;AAAC,MAAG,KAAK3J,CAAL,IAAQ,CAAX,EAAa;AAAC,WAAO,CAAP;AAAS,UAAO,KAAK+H,EAAL,IAAS,KAAK/H,CAAL,GAAO,CAAhB,IAAmB0J,MAAM,KAAK,KAAK1J,CAAL,GAAO,CAAZ,IAAgB,KAAKE,CAAL,GAAO,KAAK8H,EAAlC,CAA1B;AAAiE,UAAS4B,YAAT,CAAsBxL,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,MAAIS,CAAJ,CAAM,KAAIA,IAAE,KAAKqB,CAAL,GAAO,CAAb,EAAerB,KAAG,CAAlB,EAAoB,EAAEA,CAAtB,EAAwB;AAACT,MAAES,IAAEP,CAAJ,IAAO,KAAKO,CAAL,CAAP;AAAe,QAAIA,IAAEP,IAAE,CAAR,EAAUO,KAAG,CAAb,EAAe,EAAEA,CAAjB,EAAmB;AAACT,MAAES,CAAF,IAAK,CAAL;AAAO,KAAEqB,CAAF,GAAI,KAAKA,CAAL,GAAO5B,CAAX,CAAaF,EAAEgC,CAAF,GAAI,KAAKA,CAAT;AAAW,UAAS2J,YAAT,CAAsBzL,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,OAAI,IAAIS,IAAEP,CAAV,EAAYO,IAAE,KAAKqB,CAAnB,EAAqB,EAAErB,CAAvB,EAAyB;AAACT,MAAES,IAAEP,CAAJ,IAAO,KAAKO,CAAL,CAAP;AAAe,KAAEqB,CAAF,GAAIoD,KAAKf,GAAL,CAAS,KAAKrC,CAAL,GAAO5B,CAAhB,EAAkB,CAAlB,CAAJ,CAAyBF,EAAEgC,CAAF,GAAI,KAAKA,CAAT;AAAW,UAAS4J,WAAT,CAAqBxL,CAArB,EAAuBH,CAAvB,EAAyB;AAAC,MAAID,IAAEI,IAAE,KAAKyJ,EAAb,CAAgB,IAAIpJ,IAAE,KAAKoJ,EAAL,GAAQ7J,CAAd,CAAgB,IAAIT,IAAE,CAAC,KAAGkB,CAAJ,IAAO,CAAb,CAAe,IAAIhB,IAAEyF,KAAKc,KAAL,CAAW5F,IAAE,KAAKyJ,EAAlB,CAAN;AAAA,MAA4BrK,IAAG,KAAKwC,CAAL,IAAQhC,CAAT,GAAY,KAAK8J,EAA/C;AAAA,MAAkDnK,CAAlD,CAAoD,KAAIA,IAAE,KAAKmC,CAAL,GAAO,CAAb,EAAenC,KAAG,CAAlB,EAAoB,EAAEA,CAAtB,EAAwB;AAACM,MAAEN,IAAEF,CAAF,GAAI,CAAN,IAAU,KAAKE,CAAL,KAASc,CAAV,GAAajB,CAAtB,CAAwBA,IAAE,CAAC,KAAKG,CAAL,IAAQJ,CAAT,KAAaS,CAAf;AAAiB,QAAIL,IAAEF,IAAE,CAAR,EAAUE,KAAG,CAAb,EAAe,EAAEA,CAAjB,EAAmB;AAACM,MAAEN,CAAF,IAAK,CAAL;AAAO,KAAEF,CAAF,IAAKD,CAAL,CAAOS,EAAE6B,CAAF,GAAI,KAAKA,CAAL,GAAOrC,CAAP,GAAS,CAAb,CAAeQ,EAAE+B,CAAF,GAAI,KAAKA,CAAT,CAAW/B,EAAEgC,KAAF;AAAU,UAAS4J,WAAT,CAAqBtM,CAArB,EAAuBI,CAAvB,EAAyB;AAACA,IAAEqC,CAAF,GAAI,KAAKA,CAAT,CAAW,IAAI/B,IAAEiF,KAAKc,KAAL,CAAWzG,IAAE,KAAKsK,EAAlB,CAAN,CAA4B,IAAG5J,KAAG,KAAK6B,CAAX,EAAa;AAACnC,MAAEmC,CAAF,GAAI,CAAJ,CAAM;AAAO,OAAI9B,IAAET,IAAE,KAAKsK,EAAb,CAAgB,IAAIpJ,IAAE,KAAKoJ,EAAL,GAAQ7J,CAAd,CAAgB,IAAIP,IAAE,CAAC,KAAGO,CAAJ,IAAO,CAAb,CAAeL,EAAE,CAAF,IAAK,KAAKM,CAAL,KAASD,CAAd,CAAgB,KAAI,IAAIE,IAAED,IAAE,CAAZ,EAAcC,IAAE,KAAK4B,CAArB,EAAuB,EAAE5B,CAAzB,EAA2B;AAACP,MAAEO,IAAED,CAAF,GAAI,CAAN,KAAU,CAAC,KAAKC,CAAL,IAAQT,CAAT,KAAagB,CAAvB,CAAyBd,EAAEO,IAAED,CAAJ,IAAO,KAAKC,CAAL,KAASF,CAAhB;AAAkB,OAAGA,IAAE,CAAL,EAAO;AAACL,MAAE,KAAKmC,CAAL,GAAO7B,CAAP,GAAS,CAAX,KAAe,CAAC,KAAK+B,CAAL,GAAOvC,CAAR,KAAYgB,CAA3B;AAA6B,KAAEqB,CAAF,GAAI,KAAKA,CAAL,GAAO7B,CAAX,CAAaN,EAAEsC,KAAF;AAAU,UAAS6J,QAAT,CAAkBnM,CAAlB,EAAoBF,CAApB,EAAsB;AAAC,MAAIQ,IAAE,CAAN;AAAA,MAAQV,IAAE,CAAV;AAAA,MAAYS,IAAEkF,KAAKb,GAAL,CAAS1E,EAAEmC,CAAX,EAAa,KAAKA,CAAlB,CAAd,CAAmC,OAAM7B,IAAED,CAAR,EAAU;AAACT,SAAG,KAAKU,CAAL,IAAQN,EAAEM,CAAF,CAAX,CAAgBR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,OAAGlK,EAAEmC,CAAF,GAAI,KAAKA,CAAZ,EAAc;AAACvC,SAAGI,EAAEqC,CAAL,CAAO,OAAM/B,IAAE,KAAK6B,CAAb,EAAe;AAACvC,WAAG,KAAKU,CAAL,CAAH,CAAWR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAG,KAAK7H,CAAR;AAAU,GAAxF,MAA4F;AAACzC,SAAG,KAAKyC,CAAR,CAAU,OAAM/B,IAAEN,EAAEmC,CAAV,EAAY;AAACvC,WAAGI,EAAEM,CAAF,CAAH,CAAQR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAGlK,EAAEqC,CAAL;AAAO,KAAEA,CAAF,GAAKzC,IAAE,CAAH,GAAM,CAAC,CAAP,GAAS,CAAb,CAAe,IAAGA,IAAE,CAAC,CAAN,EAAQ;AAACE,MAAEQ,GAAF,IAAO,KAAK8J,EAAL,GAAQxK,CAAf;AAAiB,GAA1B,MAA8B;AAAC,QAAGA,IAAE,CAAL,EAAO;AAACE,QAAEQ,GAAF,IAAOV,CAAP;AAAS;AAAC,KAAEuC,CAAF,GAAI7B,CAAJ,CAAMR,EAAEwC,KAAF;AAAU,UAAS8J,aAAT,CAAuB7L,CAAvB,EAAyBD,CAAzB,EAA2B;AAAC,MAAID,IAAE,KAAKgM,GAAL,EAAN;AAAA,MAAiBvM,IAAES,EAAE8L,GAAF,EAAnB,CAA2B,IAAIrM,IAAEK,EAAE8B,CAAR,CAAU7B,EAAE6B,CAAF,GAAInC,IAAEF,EAAEqC,CAAR,CAAU,OAAM,EAAEnC,CAAF,IAAK,CAAX,EAAa;AAACM,MAAEN,CAAF,IAAK,CAAL;AAAO,QAAIA,IAAE,CAAN,EAAQA,IAAEF,EAAEqC,CAAZ,EAAc,EAAEnC,CAAhB,EAAkB;AAACM,MAAEN,IAAEK,EAAE8B,CAAN,IAAS9B,EAAE4J,EAAF,CAAK,CAAL,EAAOnK,EAAEE,CAAF,CAAP,EAAYM,CAAZ,EAAcN,CAAd,EAAgB,CAAhB,EAAkBK,EAAE8B,CAApB,CAAT;AAAgC,KAAEE,CAAF,GAAI,CAAJ,CAAM/B,EAAEgC,KAAF,GAAU,IAAG,KAAKD,CAAL,IAAQ9B,EAAE8B,CAAb,EAAe;AAACoH,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsB/K,CAAtB,EAAwBA,CAAxB;AAA2B;AAAC,UAASgM,WAAT,CAAqBtM,CAArB,EAAuB;AAAC,MAAIc,IAAE,KAAKuL,GAAL,EAAN,CAAiB,IAAIhM,IAAEL,EAAEmC,CAAF,GAAI,IAAErB,EAAEqB,CAAd,CAAgB,OAAM,EAAE9B,CAAF,IAAK,CAAX,EAAa;AAACL,MAAEK,CAAF,IAAK,CAAL;AAAO,QAAIA,IAAE,CAAN,EAAQA,IAAES,EAAEqB,CAAF,GAAI,CAAd,EAAgB,EAAE9B,CAAlB,EAAoB;AAAC,QAAIC,IAAEQ,EAAEmJ,EAAF,CAAK5J,CAAL,EAAOS,EAAET,CAAF,CAAP,EAAYL,CAAZ,EAAc,IAAEK,CAAhB,EAAkB,CAAlB,EAAoB,CAApB,CAAN,CAA6B,IAAG,CAACL,EAAEK,IAAES,EAAEqB,CAAN,KAAUrB,EAAEmJ,EAAF,CAAK5J,IAAE,CAAP,EAAS,IAAES,EAAET,CAAF,CAAX,EAAgBL,CAAhB,EAAkB,IAAEK,CAAF,GAAI,CAAtB,EAAwBC,CAAxB,EAA0BQ,EAAEqB,CAAF,GAAI9B,CAAJ,GAAM,CAAhC,CAAX,KAAgDS,EAAEsJ,EAArD,EAAwD;AAACpK,QAAEK,IAAES,EAAEqB,CAAN,KAAUrB,EAAEsJ,EAAZ,CAAepK,EAAEK,IAAES,EAAEqB,CAAJ,GAAM,CAAR,IAAW,CAAX;AAAa;AAAC,OAAGnC,EAAEmC,CAAF,GAAI,CAAP,EAAS;AAACnC,MAAEA,EAAEmC,CAAF,GAAI,CAAN,KAAUrB,EAAEmJ,EAAF,CAAK5J,CAAL,EAAOS,EAAET,CAAF,CAAP,EAAYL,CAAZ,EAAc,IAAEK,CAAhB,EAAkB,CAAlB,EAAoB,CAApB,CAAV;AAAiC,KAAEgC,CAAF,GAAI,CAAJ,CAAMrC,EAAEsC,KAAF;AAAU,UAASiK,WAAT,CAAqBrL,CAArB,EAAuBrB,CAAvB,EAAyBD,CAAzB,EAA2B;AAAC,MAAIuE,IAAEjD,EAAEmL,GAAF,EAAN,CAAc,IAAGlI,EAAEhC,CAAF,IAAK,CAAR,EAAU;AAAC;AAAO,OAAItB,IAAE,KAAKwL,GAAL,EAAN,CAAiB,IAAGxL,EAAEsB,CAAF,GAAIgC,EAAEhC,CAAT,EAAW;AAAC,QAAGtC,KAAG,IAAN,EAAW;AAACA,QAAEoL,OAAF,CAAU,CAAV;AAAa,SAAGrL,KAAG,IAAN,EAAW;AAAC,WAAK4M,MAAL,CAAY5M,CAAZ;AAAe;AAAO,OAAGA,KAAG,IAAN,EAAW;AAACA,QAAEgK,KAAF;AAAQ,OAAI5J,IAAE4J,KAAN;AAAA,MAAY9I,IAAE,KAAKuB,CAAnB;AAAA,MAAqBzB,IAAEM,EAAEmB,CAAzB,CAA2B,IAAIiC,IAAE,KAAK4F,EAAL,GAAQ2B,MAAM1H,EAAEA,EAAEhC,CAAF,GAAI,CAAN,CAAN,CAAd,CAA8B,IAAGmC,IAAE,CAAL,EAAO;AAACH,MAAEsI,QAAF,CAAWnI,CAAX,EAAatE,CAAb,EAAgBa,EAAE4L,QAAF,CAAWnI,CAAX,EAAa1E,CAAb;AAAgB,GAAxC,MAA4C;AAACuE,MAAEqI,MAAF,CAASxM,CAAT,EAAYa,EAAE2L,MAAF,CAAS5M,CAAT;AAAY,OAAIuB,IAAEnB,EAAEmC,CAAR,CAAU,IAAI9B,IAAEL,EAAEmB,IAAE,CAAJ,CAAN,CAAa,IAAGd,KAAG,CAAN,EAAQ;AAAC;AAAO,OAAIe,IAAEf,KAAG,KAAG,KAAKkK,EAAX,KAAiBpJ,IAAE,CAAH,GAAMnB,EAAEmB,IAAE,CAAJ,KAAQ,KAAKqJ,EAAnB,GAAsB,CAAtC,CAAN,CAA+C,IAAI1C,IAAE,KAAKwC,EAAL,GAAQlJ,CAAd;AAAA,MAAgByG,IAAE,CAAC,KAAG,KAAK0C,EAAT,IAAanJ,CAA/B;AAAA,MAAiCgD,IAAE,KAAG,KAAKoG,EAA3C,CAA8C,IAAIjG,IAAE3E,EAAEuC,CAAR;AAAA,MAAUE,IAAEkC,IAAEpD,CAAd;AAAA,MAAgBrB,IAAGD,KAAG,IAAJ,GAAU+J,KAAV,GAAgB/J,CAAlC,CAAoCG,EAAE0M,SAAF,CAAYrK,CAAZ,EAAcvC,CAAd,EAAiB,IAAGF,EAAE+M,SAAF,CAAY7M,CAAZ,KAAgB,CAAnB,EAAqB;AAACF,MAAEA,EAAEuC,CAAF,EAAF,IAAS,CAAT,CAAWvC,EAAEyL,KAAF,CAAQvL,CAAR,EAAUF,CAAV;AAAa,cAAWgN,GAAX,CAAeF,SAAf,CAAyBvL,CAAzB,EAA2BrB,CAA3B,EAA8BA,EAAEuL,KAAF,CAAQrL,CAAR,EAAUA,CAAV,EAAa,OAAMA,EAAEmC,CAAF,GAAIhB,CAAV,EAAY;AAACnB,MAAEA,EAAEmC,CAAF,EAAF,IAAS,CAAT;AAAW,UAAM,EAAEE,CAAF,IAAK,CAAX,EAAa;AAAC,QAAI9B,IAAGX,EAAE,EAAE2E,CAAJ,KAAQlE,CAAT,GAAY,KAAK8J,EAAjB,GAAoB5E,KAAKc,KAAL,CAAWzG,EAAE2E,CAAF,IAAKuD,CAAL,GAAO,CAAClI,EAAE2E,IAAE,CAAJ,IAAOH,CAAR,IAAWyD,CAA7B,CAA1B,CAA0D,IAAG,CAACjI,EAAE2E,CAAF,KAAMvE,EAAEiK,EAAF,CAAK,CAAL,EAAO1J,CAAP,EAASX,CAAT,EAAWyC,CAAX,EAAa,CAAb,EAAelB,CAAf,CAAP,IAA0BZ,CAA7B,EAA+B;AAACP,QAAE0M,SAAF,CAAYrK,CAAZ,EAAcvC,CAAd,EAAiBF,EAAEyL,KAAF,CAAQvL,CAAR,EAAUF,CAAV,EAAa,OAAMA,EAAE2E,CAAF,IAAK,EAAEhE,CAAb,EAAe;AAACX,UAAEyL,KAAF,CAAQvL,CAAR,EAAUF,CAAV;AAAa;AAAC;AAAC,OAAGC,KAAG,IAAN,EAAW;AAACD,MAAEiN,SAAF,CAAY1L,CAAZ,EAActB,CAAd,EAAiB,IAAGiB,KAAGF,CAAN,EAAQ;AAAC6I,iBAAW2B,IAAX,CAAgBC,KAAhB,CAAsBxL,CAAtB,EAAwBA,CAAxB;AAA2B;AAAC,KAAEsC,CAAF,GAAIhB,CAAJ,CAAMvB,EAAE0C,KAAF,GAAU,IAAGgC,IAAE,CAAL,EAAO;AAAC1E,MAAEkN,QAAF,CAAWxI,CAAX,EAAa1E,CAAb;AAAgB,OAAGkB,IAAE,CAAL,EAAO;AAAC2I,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsBzL,CAAtB,EAAwBA,CAAxB;AAA2B;AAAC,UAASmN,KAAT,CAAe1M,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKyC,GAAL,GAAWW,QAAX,CAAoB3M,CAApB,EAAsB,IAAtB,EAA2BE,CAA3B,EAA8B,IAAG,KAAK8B,CAAL,GAAO,CAAP,IAAU9B,EAAEoM,SAAF,CAAYlD,WAAW2B,IAAvB,IAA6B,CAA1C,EAA4C;AAAC/K,MAAEgL,KAAF,CAAQ9K,CAAR,EAAUA,CAAV;AAAa,UAAOA,CAAP;AAAS,UAAS0M,OAAT,CAAiBnM,CAAjB,EAAmB;AAAC,OAAK+B,CAAL,GAAO/B,CAAP;AAAS,UAASoM,QAAT,CAAkBpM,CAAlB,EAAoB;AAAC,MAAGA,EAAEuB,CAAF,GAAI,CAAJ,IAAOvB,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,KAAqB,CAA/B,EAAiC;AAAC,WAAO/B,EAAEqM,GAAF,CAAM,KAAKtK,CAAX,CAAP;AAAqB,GAAvD,MAA2D;AAAC,WAAO/B,CAAP;AAAS;AAAC,UAASsM,OAAT,CAAiBtM,CAAjB,EAAmB;AAAC,SAAOA,CAAP;AAAS,UAASuM,OAAT,CAAiBvM,CAAjB,EAAmB;AAACA,IAAEkM,QAAF,CAAW,KAAKnK,CAAhB,EAAkB,IAAlB,EAAuB/B,CAAvB;AAA0B,UAASwM,MAAT,CAAgBxM,CAAhB,EAAkBP,CAAlB,EAAoBF,CAApB,EAAsB;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf,EAAkB,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,UAASoN,MAAT,CAAgB3M,CAAhB,EAAkBT,CAAlB,EAAoB;AAACS,IAAE4M,QAAF,CAAWrN,CAAX,EAAc,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,SAAQJ,SAAR,CAAkB0N,OAAlB,GAA0BT,QAA1B,CAAmCD,QAAQhN,SAAR,CAAkB2N,MAAlB,GAAyBR,OAAzB,CAAiCH,QAAQhN,SAAR,CAAkBuN,MAAlB,GAAyBH,OAAzB,CAAiCJ,QAAQhN,SAAR,CAAkB4N,KAAlB,GAAwBP,MAAxB,CAA+BL,QAAQhN,SAAR,CAAkB6N,KAAlB,GAAwBL,MAAxB,CAA+B,SAASM,WAAT,GAAsB;AAAC,MAAG,KAAK5L,CAAL,GAAO,CAAV,EAAY;AAAC,WAAO,CAAP;AAAS,OAAIrB,IAAE,KAAK,CAAL,CAAN,CAAc,IAAG,CAACA,IAAE,CAAH,KAAO,CAAV,EAAY;AAAC,WAAO,CAAP;AAAS,OAAIT,IAAES,IAAE,CAAR,CAAUT,IAAGA,KAAG,IAAE,CAACS,IAAE,EAAH,IAAOT,CAAZ,CAAD,GAAiB,EAAnB,CAAsBA,IAAGA,KAAG,IAAE,CAACS,IAAE,GAAH,IAAQT,CAAb,CAAD,GAAkB,GAApB,CAAwBA,IAAGA,KAAG,KAAI,CAACS,IAAE,KAAH,IAAUT,CAAX,GAAc,KAAjB,CAAH,CAAD,GAA8B,KAAhC,CAAsCA,IAAGA,KAAG,IAAES,IAAET,CAAF,GAAI,KAAK+J,EAAd,CAAD,GAAoB,KAAKA,EAA3B,CAA8B,OAAO/J,IAAE,CAAH,GAAM,KAAK+J,EAAL,GAAQ/J,CAAd,GAAgB,CAACA,CAAvB;AAAyB,UAAS2N,UAAT,CAAoBlN,CAApB,EAAsB;AAAC,OAAK+B,CAAL,GAAO/B,CAAP,CAAS,KAAKmN,EAAL,GAAQnN,EAAEoN,QAAF,EAAR,CAAqB,KAAKC,GAAL,GAAS,KAAKF,EAAL,GAAQ,KAAjB,CAAuB,KAAKG,GAAL,GAAS,KAAKH,EAAL,IAAS,EAAlB,CAAqB,KAAKI,EAAL,GAAQ,CAAC,KAAIvN,EAAEoJ,EAAF,GAAK,EAAV,IAAe,CAAvB,CAAyB,KAAKoE,GAAL,GAAS,IAAExN,EAAEqB,CAAb;AAAe,UAASoM,WAAT,CAAqBzN,CAArB,EAAuB;AAAC,MAAIT,IAAEuJ,KAAN,CAAY9I,EAAEuL,GAAF,GAAQK,SAAR,CAAkB,KAAK7J,CAAL,CAAOV,CAAzB,EAA2B9B,CAA3B,EAA8BA,EAAE2M,QAAF,CAAW,KAAKnK,CAAhB,EAAkB,IAAlB,EAAuBxC,CAAvB,EAA0B,IAAGS,EAAEuB,CAAF,GAAI,CAAJ,IAAOhC,EAAEsM,SAAF,CAAYlD,WAAW2B,IAAvB,IAA6B,CAAvC,EAAyC;AAAC,SAAKvI,CAAL,CAAOwI,KAAP,CAAahL,CAAb,EAAeA,CAAf;AAAkB,UAAOA,CAAP;AAAS,UAASmO,UAAT,CAAoB1N,CAApB,EAAsB;AAAC,MAAIT,IAAEuJ,KAAN,CAAY9I,EAAE0L,MAAF,CAASnM,CAAT,EAAY,KAAKmN,MAAL,CAAYnN,CAAZ,EAAe,OAAOA,CAAP;AAAS,UAASoO,UAAT,CAAoB3N,CAApB,EAAsB;AAAC,SAAMA,EAAEqB,CAAF,IAAK,KAAKmM,GAAhB,EAAoB;AAACxN,MAAEA,EAAEqB,CAAF,EAAF,IAAS,CAAT;AAAW,QAAI,IAAI5B,IAAE,CAAV,EAAYA,IAAE,KAAKsC,CAAL,CAAOV,CAArB,EAAuB,EAAE5B,CAAzB,EAA2B;AAAC,QAAIF,IAAES,EAAEP,CAAF,IAAK,KAAX,CAAiB,IAAIP,IAAGK,IAAE,KAAK8N,GAAP,IAAY,CAAE9N,IAAE,KAAK+N,GAAP,GAAW,CAACtN,EAAEP,CAAF,KAAM,EAAP,IAAW,KAAK4N,GAA5B,GAAiC,KAAKE,EAAvC,KAA4C,EAAxD,CAAD,GAA8DvN,EAAEqJ,EAAtE,CAAyE9J,IAAEE,IAAE,KAAKsC,CAAL,CAAOV,CAAX,CAAarB,EAAET,CAAF,KAAM,KAAKwC,CAAL,CAAOoH,EAAP,CAAU,CAAV,EAAYjK,CAAZ,EAAcc,CAAd,EAAgBP,CAAhB,EAAkB,CAAlB,EAAoB,KAAKsC,CAAL,CAAOV,CAA3B,CAAN,CAAoC,OAAMrB,EAAET,CAAF,KAAMS,EAAEsJ,EAAd,EAAiB;AAACtJ,QAAET,CAAF,KAAMS,EAAEsJ,EAAR,CAAWtJ,EAAE,EAAET,CAAJ;AAAS;AAAC,KAAEiC,KAAF,GAAUxB,EAAE+L,SAAF,CAAY,KAAKhK,CAAL,CAAOV,CAAnB,EAAqBrB,CAArB,EAAwB,IAAGA,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,KAAqB,CAAxB,EAA0B;AAAC/B,MAAEuK,KAAF,CAAQ,KAAKxI,CAAb,EAAe/B,CAAf;AAAkB;AAAC,UAAS4N,SAAT,CAAmB5N,CAAnB,EAAqBT,CAArB,EAAuB;AAACS,IAAE4M,QAAF,CAAWrN,CAAX,EAAc,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,UAASsO,SAAT,CAAmB7N,CAAnB,EAAqBP,CAArB,EAAuBF,CAAvB,EAAyB;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf,EAAkB,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,YAAWJ,SAAX,CAAqB0N,OAArB,GAA6BY,WAA7B,CAAyCP,WAAW/N,SAAX,CAAqB2N,MAArB,GAA4BY,UAA5B,CAAuCR,WAAW/N,SAAX,CAAqBuN,MAArB,GAA4BiB,UAA5B,CAAuCT,WAAW/N,SAAX,CAAqB4N,KAArB,GAA2Bc,SAA3B,CAAqCX,WAAW/N,SAAX,CAAqB6N,KAArB,GAA2BY,SAA3B,CAAqC,SAASE,SAAT,GAAoB;AAAC,SAAM,CAAE,KAAKzM,CAAL,GAAO,CAAR,GAAY,KAAK,CAAL,IAAQ,CAApB,GAAuB,KAAKE,CAA7B,KAAiC,CAAvC;AAAyC,UAASwM,MAAT,CAAgBhP,CAAhB,EAAkBY,CAAlB,EAAoB;AAAC,MAAGZ,IAAE,UAAF,IAAcA,IAAE,CAAnB,EAAqB;AAAC,WAAO4J,WAAWmD,GAAlB;AAAsB,OAAI9M,IAAE8J,KAAN;AAAA,MAAY9I,IAAE8I,KAAd;AAAA,MAAoB5J,IAAES,EAAEkN,OAAF,CAAU,IAAV,CAAtB;AAAA,MAAsCpN,IAAEsL,MAAMhM,CAAN,IAAS,CAAjD,CAAmDG,EAAEwM,MAAF,CAAS1M,CAAT,EAAY,OAAM,EAAES,CAAF,IAAK,CAAX,EAAa;AAACE,MAAEqN,KAAF,CAAQhO,CAAR,EAAUgB,CAAV,EAAa,IAAG,CAACjB,IAAG,KAAGU,CAAP,IAAW,CAAd,EAAgB;AAACE,QAAEoN,KAAF,CAAQ/M,CAAR,EAAUd,CAAV,EAAYF,CAAZ;AAAe,KAAhC,MAAoC;AAAC,UAAIO,IAAEP,CAAN,CAAQA,IAAEgB,CAAF,CAAIA,IAAET,CAAF;AAAI;AAAC,UAAOI,EAAEmN,MAAF,CAAS9N,CAAT,CAAP;AAAmB,UAASgP,WAAT,CAAqBzO,CAArB,EAAuBS,CAAvB,EAAyB;AAAC,MAAIP,CAAJ,CAAM,IAAGF,IAAE,GAAF,IAAOS,EAAEiO,MAAF,EAAV,EAAqB;AAACxO,QAAE,IAAI0M,OAAJ,CAAYnM,CAAZ,CAAF;AAAiB,GAAvC,MAA2C;AAACP,QAAE,IAAIyN,UAAJ,CAAelN,CAAf,CAAF;AAAoB,UAAO,KAAKkO,GAAL,CAAS3O,CAAT,EAAWE,CAAX,CAAP;AAAqB,YAAWN,SAAX,CAAqBuM,MAArB,GAA4B1B,SAA5B,CAAsCrB,WAAWxJ,SAAX,CAAqBgL,OAArB,GAA6BF,UAA7B,CAAwCtB,WAAWxJ,SAAX,CAAqB0J,UAArB,GAAgCuB,aAAhC,CAA8CzB,WAAWxJ,SAAX,CAAqBqC,KAArB,GAA2BgJ,QAA3B,CAAoC7B,WAAWxJ,SAAX,CAAqByM,SAArB,GAA+BX,YAA/B,CAA4CtC,WAAWxJ,SAAX,CAAqB4M,SAArB,GAA+Bb,YAA/B,CAA4CvC,WAAWxJ,SAAX,CAAqBwM,QAArB,GAA8BR,WAA9B,CAA0CxC,WAAWxJ,SAAX,CAAqB6M,QAArB,GAA8BZ,WAA9B,CAA0CzC,WAAWxJ,SAAX,CAAqBoL,KAArB,GAA2Bc,QAA3B,CAAoC1C,WAAWxJ,SAAX,CAAqBsN,UAArB,GAAgCnB,aAAhC,CAA8C3C,WAAWxJ,SAAX,CAAqByN,QAArB,GAA8BpB,WAA9B,CAA0C7C,WAAWxJ,SAAX,CAAqB+M,QAArB,GAA8BT,WAA9B,CAA0C9C,WAAWxJ,SAAX,CAAqBiO,QAArB,GAA8BH,WAA9B,CAA0CtE,WAAWxJ,SAAX,CAAqB8O,MAArB,GAA4BH,SAA5B,CAAsCnF,WAAWxJ,SAAX,CAAqB+O,GAArB,GAAyBH,MAAzB,CAAgCpF,WAAWxJ,SAAX,CAAqB2B,QAArB,GAA8B2J,UAA9B,CAAyC9B,WAAWxJ,SAAX,CAAqBuL,MAArB,GAA4BE,QAA5B,CAAqCjC,WAAWxJ,SAAX,CAAqBoM,GAArB,GAAyBV,KAAzB,CAA+BlC,WAAWxJ,SAAX,CAAqB0M,SAArB,GAA+Bf,WAA/B,CAA2CnC,WAAWxJ,SAAX,CAAqBgP,SAArB,GAA+BnD,WAA/B,CAA2CrC,WAAWxJ,SAAX,CAAqBkN,GAArB,GAAyBJ,KAAzB,CAA+BtD,WAAWxJ,SAAX,CAAqBiP,SAArB,GAA+BJ,WAA/B,CAA2CrF,WAAW2B,IAAX,GAAgBJ,IAAI,CAAJ,CAAhB,CAAuBvB,WAAWmD,GAAX,GAAe5B,IAAI,CAAJ,CAAf;AAClpS;;AAEA,SAASmE,OAAT,GAAkB;AAAC,MAAIrO,IAAE8I,KAAN,CAAY,KAAK4C,MAAL,CAAY1L,CAAZ,EAAe,OAAOA,CAAP;AAAS,UAASsO,UAAT,GAAqB;AAAC,MAAG,KAAK/M,CAAL,GAAO,CAAV,EAAY;AAAC,QAAG,KAAKF,CAAL,IAAQ,CAAX,EAAa;AAAC,aAAO,KAAK,CAAL,IAAQ,KAAKiI,EAApB;AAAuB,KAArC,MAAyC;AAAC,UAAG,KAAKjI,CAAL,IAAQ,CAAX,EAAa;AAAC,eAAO,CAAC,CAAR;AAAU;AAAC;AAAC,GAAjF,MAAqF;AAAC,QAAG,KAAKA,CAAL,IAAQ,CAAX,EAAa;AAAC,aAAO,KAAK,CAAL,CAAP;AAAe,KAA7B,MAAiC;AAAC,UAAG,KAAKA,CAAL,IAAQ,CAAX,EAAa;AAAC,eAAO,CAAP;AAAS;AAAC;AAAC,UAAO,CAAC,KAAK,CAAL,IAAS,CAAC,KAAI,KAAG,KAAK+H,EAAb,IAAkB,CAA5B,KAAiC,KAAKA,EAAvC,GAA2C,KAAK,CAAL,CAAjD;AAAyD,UAASmF,WAAT,GAAsB;AAAC,SAAO,KAAKlN,CAAL,IAAQ,CAAT,GAAY,KAAKE,CAAjB,GAAoB,KAAK,CAAL,KAAS,EAAV,IAAe,EAAxC;AAA2C,UAASiN,YAAT,GAAuB;AAAC,SAAO,KAAKnN,CAAL,IAAQ,CAAT,GAAY,KAAKE,CAAjB,GAAoB,KAAK,CAAL,KAAS,EAAV,IAAe,EAAxC;AAA2C,UAASkN,YAAT,CAAsBzO,CAAtB,EAAwB;AAAC,SAAOyE,KAAKc,KAAL,CAAWd,KAAKiK,GAAL,GAAS,KAAKtF,EAAd,GAAiB3E,KAAKkK,GAAL,CAAS3O,CAAT,CAA5B,CAAP;AAAgD,UAAS4O,QAAT,GAAmB;AAAC,MAAG,KAAKrN,CAAL,GAAO,CAAV,EAAY;AAAC,WAAO,CAAC,CAAR;AAAU,GAAvB,MAA2B;AAAC,QAAG,KAAKF,CAAL,IAAQ,CAAR,IAAY,KAAKA,CAAL,IAAQ,CAAR,IAAW,KAAK,CAAL,KAAS,CAAnC,EAAsC;AAAC,aAAO,CAAP;AAAS,KAAhD,MAAoD;AAAC,aAAO,CAAP;AAAS;AAAC;AAAC,UAASwN,UAAT,CAAoBpP,CAApB,EAAsB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAACA,QAAE,EAAF;AAAK,OAAG,KAAKqP,MAAL,MAAe,CAAf,IAAkBrP,IAAE,CAApB,IAAuBA,IAAE,EAA5B,EAA+B;AAAC,WAAM,GAAN;AAAU,OAAIT,IAAE,KAAK+P,SAAL,CAAetP,CAAf,CAAN,CAAwB,IAAID,IAAEiF,KAAKW,GAAL,CAAS3F,CAAT,EAAWT,CAAX,CAAN,CAAoB,IAAIY,IAAEsK,IAAI1K,CAAJ,CAAN;AAAA,MAAaG,IAAEmJ,KAAf;AAAA,MAAqB/J,IAAE+J,KAAvB;AAAA,MAA6BhK,IAAE,EAA/B,CAAkC,KAAKoN,QAAL,CAActM,CAAd,EAAgBD,CAAhB,EAAkBZ,CAAlB,EAAqB,OAAMY,EAAEmP,MAAF,KAAW,CAAjB,EAAmB;AAAChQ,QAAE,CAACU,IAAET,EAAEiQ,QAAF,EAAH,EAAiBlO,QAAjB,CAA0BrB,CAA1B,EAA6B4C,MAA7B,CAAoC,CAApC,IAAuCvD,CAAzC,CAA2Ca,EAAEuM,QAAF,CAAWtM,CAAX,EAAaD,CAAb,EAAeZ,CAAf;AAAkB,UAAOA,EAAEiQ,QAAF,GAAalO,QAAb,CAAsBrB,CAAtB,IAAyBX,CAAhC;AAAkC,UAASmQ,YAAT,CAAsBlN,CAAtB,EAAwBhD,CAAxB,EAA0B;AAAC,OAAKoL,OAAL,CAAa,CAAb,EAAgB,IAAGpL,KAAG,IAAN,EAAW;AAACA,QAAE,EAAF;AAAK,OAAIC,IAAE,KAAK+P,SAAL,CAAehQ,CAAf,CAAN,CAAwB,IAAID,IAAE2F,KAAKW,GAAL,CAASrG,CAAT,EAAWC,CAAX,CAAN;AAAA,MAAoBQ,IAAE,KAAtB;AAAA,MAA4BQ,IAAE,CAA9B;AAAA,MAAgCF,IAAE,CAAlC,CAAoC,KAAI,IAAIL,IAAE,CAAV,EAAYA,IAAEsC,EAAElC,MAAhB,EAAuB,EAAEJ,CAAzB,EAA2B;AAAC,QAAIM,IAAEgK,MAAMhI,CAAN,EAAQtC,CAAR,CAAN,CAAiB,IAAGM,IAAE,CAAL,EAAO;AAAC,UAAGgC,EAAEkD,MAAF,CAASxF,CAAT,KAAa,GAAb,IAAkB,KAAKqP,MAAL,MAAe,CAApC,EAAsC;AAACtP,YAAE,IAAF;AAAO;AAAS,SAAET,IAAEe,CAAF,GAAIC,CAAN,CAAQ,IAAG,EAAEC,CAAF,IAAKhB,CAAR,EAAU;AAAC,WAAKkQ,SAAL,CAAepQ,CAAf,EAAkB,KAAKqQ,UAAL,CAAgBrP,CAAhB,EAAkB,CAAlB,EAAqBE,IAAE,CAAF,CAAIF,IAAE,CAAF;AAAI;AAAC,OAAGE,IAAE,CAAL,EAAO;AAAC,SAAKkP,SAAL,CAAezK,KAAKW,GAAL,CAASrG,CAAT,EAAWiB,CAAX,CAAf,EAA8B,KAAKmP,UAAL,CAAgBrP,CAAhB,EAAkB,CAAlB;AAAqB,OAAGN,CAAH,EAAK;AAACmJ,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsB,IAAtB,EAA2B,IAA3B;AAAiC;AAAC,UAAS6E,aAAT,CAAuBpQ,CAAvB,EAAyBQ,CAAzB,EAA2BT,CAA3B,EAA6B;AAAC,MAAG,YAAU,OAAOS,CAApB,EAAsB;AAAC,QAAGR,IAAE,CAAL,EAAO;AAAC,WAAKmL,OAAL,CAAa,CAAb;AAAgB,KAAxB,MAA4B;AAAC,WAAKvB,UAAL,CAAgB5J,CAAhB,EAAkBD,CAAlB,EAAqB,IAAG,CAAC,KAAKsQ,OAAL,CAAarQ,IAAE,CAAf,CAAJ,EAAsB;AAAC,aAAKsQ,SAAL,CAAe3G,WAAWmD,GAAX,CAAeyD,SAAf,CAAyBvQ,IAAE,CAA3B,CAAf,EAA6CwQ,KAA7C,EAAmD,IAAnD;AAAyD,WAAG,KAAKvB,MAAL,EAAH,EAAiB;AAAC,aAAKkB,UAAL,CAAgB,CAAhB,EAAkB,CAAlB;AAAqB,cAAM,CAAC,KAAKM,eAAL,CAAqBjQ,CAArB,CAAP,EAA+B;AAAC,aAAK2P,UAAL,CAAgB,CAAhB,EAAkB,CAAlB,EAAqB,IAAG,KAAKhB,SAAL,KAAiBnP,CAApB,EAAsB;AAAC,eAAKuL,KAAL,CAAW5B,WAAWmD,GAAX,CAAeyD,SAAf,CAAyBvQ,IAAE,CAA3B,CAAX,EAAyC,IAAzC;AAA+C;AAAC;AAAC;AAAC,GAA9T,MAAkU;AAAC,QAAIE,IAAE,IAAIqJ,KAAJ,EAAN;AAAA,QAAkBzJ,IAAEE,IAAE,CAAtB,CAAwBE,EAAEW,MAAF,GAAS,CAACb,KAAG,CAAJ,IAAO,CAAhB,CAAkBQ,EAAEkQ,SAAF,CAAYxQ,CAAZ,EAAe,IAAGJ,IAAE,CAAL,EAAO;AAACI,QAAE,CAAF,KAAO,CAAC,KAAGJ,CAAJ,IAAO,CAAd;AAAiB,KAAzB,MAA6B;AAACI,QAAE,CAAF,IAAK,CAAL;AAAO,UAAK2J,UAAL,CAAgB3J,CAAhB,EAAkB,GAAlB;AAAuB;AAAC,UAASyQ,aAAT,GAAwB;AAAC,MAAIpQ,IAAE,KAAK8B,CAAX;AAAA,MAAa5B,IAAE,IAAI8I,KAAJ,EAAf,CAA2B9I,EAAE,CAAF,IAAK,KAAK8B,CAAV,CAAY,IAAI/B,IAAE,KAAK4J,EAAL,GAAS7J,IAAE,KAAK6J,EAAR,GAAY,CAA1B;AAAA,MAA4BpK,CAA5B;AAAA,MAA8BgB,IAAE,CAAhC,CAAkC,IAAGT,MAAI,CAAP,EAAS;AAAC,QAAGC,IAAE,KAAK4J,EAAP,IAAW,CAACpK,IAAE,KAAKO,CAAL,KAASC,CAAZ,KAAgB,CAAC,KAAK+B,CAAL,GAAO,KAAK8H,EAAb,KAAkB7J,CAAhD,EAAkD;AAACC,QAAEO,GAAF,IAAOhB,IAAG,KAAKuC,CAAL,IAAS,KAAK6H,EAAL,GAAQ5J,CAA3B;AAA+B,YAAMD,KAAG,CAAT,EAAW;AAAC,UAAGC,IAAE,CAAL,EAAO;AAACR,YAAE,CAAC,KAAKO,CAAL,IAAS,CAAC,KAAGC,CAAJ,IAAO,CAAjB,KAAuB,IAAEA,CAA3B,CAA8BR,KAAG,KAAK,EAAEO,CAAP,MAAYC,KAAG,KAAK4J,EAAL,GAAQ,CAAvB,CAAH;AAA6B,OAAnE,MAAuE;AAACpK,YAAG,KAAKO,CAAL,MAAUC,KAAG,CAAb,CAAD,GAAkB,GAApB,CAAwB,IAAGA,KAAG,CAAN,EAAQ;AAACA,eAAG,KAAK4J,EAAR,CAAW,EAAE7J,CAAF;AAAI;AAAC,WAAG,CAACP,IAAE,GAAH,KAAS,CAAZ,EAAc;AAACA,aAAG,CAAC,GAAJ;AAAQ,WAAGgB,KAAG,CAAH,IAAM,CAAC,KAAKuB,CAAL,GAAO,GAAR,MAAevC,IAAE,GAAjB,CAAT,EAA+B;AAAC,UAAEgB,CAAF;AAAI,WAAGA,IAAE,CAAF,IAAKhB,KAAG,KAAKuC,CAAhB,EAAkB;AAAC9B,UAAEO,GAAF,IAAOhB,CAAP;AAAS;AAAC;AAAC,UAAOS,CAAP;AAAS,UAASmQ,QAAT,CAAkBrQ,CAAlB,EAAoB;AAAC,SAAO,KAAKsM,SAAL,CAAetM,CAAf,KAAmB,CAA1B;AAA6B,UAASsQ,KAAT,CAAetQ,CAAf,EAAiB;AAAC,SAAO,KAAKsM,SAAL,CAAetM,CAAf,IAAkB,CAAnB,GAAsB,IAAtB,GAA2BA,CAAjC;AAAmC,UAASuQ,KAAT,CAAevQ,CAAf,EAAiB;AAAC,SAAO,KAAKsM,SAAL,CAAetM,CAAf,IAAkB,CAAnB,GAAsB,IAAtB,GAA2BA,CAAjC;AAAmC,UAASwQ,YAAT,CAAsBtQ,CAAtB,EAAwBV,CAAxB,EAA0BS,CAA1B,EAA4B;AAAC,MAAIN,CAAJ;AAAA,MAAMJ,CAAN;AAAA,MAAQS,IAAEkF,KAAKb,GAAL,CAASnE,EAAE4B,CAAX,EAAa,KAAKA,CAAlB,CAAV,CAA+B,KAAInC,IAAE,CAAN,EAAQA,IAAEK,CAAV,EAAY,EAAEL,CAAd,EAAgB;AAACM,MAAEN,CAAF,IAAKH,EAAE,KAAKG,CAAL,CAAF,EAAUO,EAAEP,CAAF,CAAV,CAAL;AAAqB,OAAGO,EAAE4B,CAAF,GAAI,KAAKA,CAAZ,EAAc;AAACvC,QAAEW,EAAE8B,CAAF,GAAI,KAAK8H,EAAX,CAAc,KAAInK,IAAEK,CAAN,EAAQL,IAAE,KAAKmC,CAAf,EAAiB,EAAEnC,CAAnB,EAAqB;AAACM,QAAEN,CAAF,IAAKH,EAAE,KAAKG,CAAL,CAAF,EAAUJ,CAAV,CAAL;AAAkB,OAAEuC,CAAF,GAAI,KAAKA,CAAT;AAAW,GAAhF,MAAoF;AAACvC,QAAE,KAAKyC,CAAL,GAAO,KAAK8H,EAAd,CAAiB,KAAInK,IAAEK,CAAN,EAAQL,IAAEO,EAAE4B,CAAZ,EAAc,EAAEnC,CAAhB,EAAkB;AAACM,QAAEN,CAAF,IAAKH,EAAED,CAAF,EAAIW,EAAEP,CAAF,CAAJ,CAAL;AAAe,OAAEmC,CAAF,GAAI5B,EAAE4B,CAAN;AAAQ,KAAEE,CAAF,GAAIxC,EAAE,KAAKwC,CAAP,EAAS9B,EAAE8B,CAAX,CAAJ,CAAkB/B,EAAEgC,KAAF;AAAU,UAASwO,MAAT,CAAgBhQ,CAAhB,EAAkBT,CAAlB,EAAoB;AAAC,SAAOS,IAAET,CAAT;AAAW,UAAS0Q,KAAT,CAAe1Q,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiByQ,MAAjB,EAAwBvQ,CAAxB,EAA2B,OAAOA,CAAP;AAAS,UAAS+P,KAAT,CAAexP,CAAf,EAAiBT,CAAjB,EAAmB;AAAC,SAAOS,IAAET,CAAT;AAAW,UAAS2Q,IAAT,CAAc3Q,CAAd,EAAgB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiBiQ,KAAjB,EAAuB/P,CAAvB,EAA0B,OAAOA,CAAP;AAAS,UAAS0Q,MAAT,CAAgBnQ,CAAhB,EAAkBT,CAAlB,EAAoB;AAAC,SAAOS,IAAET,CAAT;AAAW,UAAS6Q,KAAT,CAAe7Q,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiB4Q,MAAjB,EAAwB1Q,CAAxB,EAA2B,OAAOA,CAAP;AAAS,UAAS4Q,SAAT,CAAmBrQ,CAAnB,EAAqBT,CAArB,EAAuB;AAAC,SAAOS,IAAE,CAACT,CAAV;AAAY,UAAS+Q,QAAT,CAAkB/Q,CAAlB,EAAoB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiB8Q,SAAjB,EAA2B5Q,CAA3B,EAA8B,OAAOA,CAAP;AAAS,UAAS8Q,KAAT,GAAgB;AAAC,MAAIhR,IAAEuJ,KAAN,CAAY,KAAI,IAAI9I,IAAE,CAAV,EAAYA,IAAE,KAAKqB,CAAnB,EAAqB,EAAErB,CAAvB,EAAyB;AAACT,MAAES,CAAF,IAAK,KAAKqJ,EAAL,GAAQ,CAAC,KAAKrJ,CAAL,CAAd;AAAsB,KAAEqB,CAAF,GAAI,KAAKA,CAAT,CAAW9B,EAAEgC,CAAF,GAAI,CAAC,KAAKA,CAAV,CAAY,OAAOhC,CAAP;AAAS,UAASiR,WAAT,CAAqBjR,CAArB,EAAuB;AAAC,MAAIS,IAAE8I,KAAN,CAAY,IAAGvJ,IAAE,CAAL,EAAO;AAAC,SAAKyM,QAAL,CAAc,CAACzM,CAAf,EAAiBS,CAAjB;AAAoB,GAA5B,MAAgC;AAAC,SAAK2L,QAAL,CAAcpM,CAAd,EAAgBS,CAAhB;AAAmB,UAAOA,CAAP;AAAS,UAASyQ,YAAT,CAAsBlR,CAAtB,EAAwB;AAAC,MAAIS,IAAE8I,KAAN,CAAY,IAAGvJ,IAAE,CAAL,EAAO;AAAC,SAAKoM,QAAL,CAAc,CAACpM,CAAf,EAAiBS,CAAjB;AAAoB,GAA5B,MAAgC;AAAC,SAAKgM,QAAL,CAAczM,CAAd,EAAgBS,CAAhB;AAAmB,UAAOA,CAAP;AAAS,UAAS0Q,IAAT,CAAc1Q,CAAd,EAAgB;AAAC,MAAGA,KAAG,CAAN,EAAQ;AAAC,WAAO,CAAC,CAAR;AAAU,OAAIT,IAAE,CAAN,CAAQ,IAAG,CAACS,IAAE,KAAH,KAAW,CAAd,EAAgB;AAACA,UAAI,EAAJ,CAAOT,KAAG,EAAH;AAAM,OAAG,CAACS,IAAE,GAAH,KAAS,CAAZ,EAAc;AAACA,UAAI,CAAJ,CAAMT,KAAG,CAAH;AAAK,OAAG,CAACS,IAAE,EAAH,KAAQ,CAAX,EAAa;AAACA,UAAI,CAAJ,CAAMT,KAAG,CAAH;AAAK,OAAG,CAACS,IAAE,CAAH,KAAO,CAAV,EAAY;AAACA,UAAI,CAAJ,CAAMT,KAAG,CAAH;AAAK,OAAG,CAACS,IAAE,CAAH,KAAO,CAAV,EAAY;AAAC,MAAET,CAAF;AAAI,UAAOA,CAAP;AAAS,UAASoR,iBAAT,GAA4B;AAAC,OAAI,IAAI3Q,IAAE,CAAV,EAAYA,IAAE,KAAKqB,CAAnB,EAAqB,EAAErB,CAAvB,EAAyB;AAAC,QAAG,KAAKA,CAAL,KAAS,CAAZ,EAAc;AAAC,aAAOA,IAAE,KAAKoJ,EAAP,GAAUsH,KAAK,KAAK1Q,CAAL,CAAL,CAAjB;AAA+B;AAAC,OAAG,KAAKuB,CAAL,GAAO,CAAV,EAAY;AAAC,WAAO,KAAKF,CAAL,GAAO,KAAK+H,EAAnB;AAAsB,UAAO,CAAC,CAAR;AAAU,UAASwH,IAAT,CAAc5Q,CAAd,EAAgB;AAAC,MAAIT,IAAE,CAAN,CAAQ,OAAMS,KAAG,CAAT,EAAW;AAACA,SAAGA,IAAE,CAAL,CAAO,EAAET,CAAF;AAAI,UAAOA,CAAP;AAAS,UAASsR,UAAT,GAAqB;AAAC,MAAIpR,IAAE,CAAN;AAAA,MAAQO,IAAE,KAAKuB,CAAL,GAAO,KAAK8H,EAAtB,CAAyB,KAAI,IAAI9J,IAAE,CAAV,EAAYA,IAAE,KAAK8B,CAAnB,EAAqB,EAAE9B,CAAvB,EAAyB;AAACE,SAAGmR,KAAK,KAAKrR,CAAL,IAAQS,CAAb,CAAH;AAAmB,UAAOP,CAAP;AAAS,UAASqR,SAAT,CAAmBvR,CAAnB,EAAqB;AAAC,MAAIS,IAAEyE,KAAKc,KAAL,CAAWhG,IAAE,KAAK6J,EAAlB,CAAN,CAA4B,IAAGpJ,KAAG,KAAKqB,CAAX,EAAa;AAAC,WAAO,KAAKE,CAAL,IAAQ,CAAf;AAAkB,UAAO,CAAC,KAAKvB,CAAL,IAAS,KAAIT,IAAE,KAAK6J,EAArB,KAA4B,CAAnC;AAAsC,UAAS2H,YAAT,CAAsBtR,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,MAAIS,IAAE2I,WAAWmD,GAAX,CAAeyD,SAAf,CAAyB9P,CAAzB,CAAN,CAAkC,KAAK6P,SAAL,CAAetP,CAAf,EAAiBT,CAAjB,EAAmBS,CAAnB,EAAsB,OAAOA,CAAP;AAAS,UAASgR,QAAT,CAAkBhR,CAAlB,EAAoB;AAAC,SAAO,KAAKiR,SAAL,CAAejR,CAAf,EAAiBwP,KAAjB,CAAP;AAA+B,UAAS0B,UAAT,CAAoBlR,CAApB,EAAsB;AAAC,SAAO,KAAKiR,SAAL,CAAejR,CAAf,EAAiBqQ,SAAjB,CAAP;AAAmC,UAASc,SAAT,CAAmBnR,CAAnB,EAAqB;AAAC,SAAO,KAAKiR,SAAL,CAAejR,CAAf,EAAiBmQ,MAAjB,CAAP;AAAgC,UAASiB,QAAT,CAAkBlS,CAAlB,EAAoBF,CAApB,EAAsB;AAAC,MAAIQ,IAAE,CAAN;AAAA,MAAQV,IAAE,CAAV;AAAA,MAAYS,IAAEkF,KAAKb,GAAL,CAAS1E,EAAEmC,CAAX,EAAa,KAAKA,CAAlB,CAAd,CAAmC,OAAM7B,IAAED,CAAR,EAAU;AAACT,SAAG,KAAKU,CAAL,IAAQN,EAAEM,CAAF,CAAX,CAAgBR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,OAAGlK,EAAEmC,CAAF,GAAI,KAAKA,CAAZ,EAAc;AAACvC,SAAGI,EAAEqC,CAAL,CAAO,OAAM/B,IAAE,KAAK6B,CAAb,EAAe;AAACvC,WAAG,KAAKU,CAAL,CAAH,CAAWR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAG,KAAK7H,CAAR;AAAU,GAAxF,MAA4F;AAACzC,SAAG,KAAKyC,CAAR,CAAU,OAAM/B,IAAEN,EAAEmC,CAAV,EAAY;AAACvC,WAAGI,EAAEM,CAAF,CAAH,CAAQR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAGlK,EAAEqC,CAAL;AAAO,KAAEA,CAAF,GAAKzC,IAAE,CAAH,GAAM,CAAC,CAAP,GAAS,CAAb,CAAe,IAAGA,IAAE,CAAL,EAAO;AAACE,MAAEQ,GAAF,IAAOV,CAAP;AAAS,GAAjB,MAAqB;AAAC,QAAGA,IAAE,CAAC,CAAN,EAAQ;AAACE,QAAEQ,GAAF,IAAO,KAAK8J,EAAL,GAAQxK,CAAf;AAAiB;AAAC,KAAEuC,CAAF,GAAI7B,CAAJ,CAAMR,EAAEwC,KAAF;AAAU,UAAS6P,KAAT,CAAe9R,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwI,KAAL,CAAW/R,CAAX,EAAaE,CAAb,EAAgB,OAAOA,CAAP;AAAS,UAAS8R,UAAT,CAAoBhS,CAApB,EAAsB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKyB,KAAL,CAAWhL,CAAX,EAAaE,CAAb,EAAgB,OAAOA,CAAP;AAAS,UAAS+R,UAAT,CAAoBjS,CAApB,EAAsB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAK2D,UAAL,CAAgBlN,CAAhB,EAAkBE,CAAlB,EAAqB,OAAOA,CAAP;AAAS,UAASgS,QAAT,GAAmB;AAAC,MAAIzR,IAAE8I,KAAN,CAAY,KAAK8D,QAAL,CAAc5M,CAAd,EAAiB,OAAOA,CAAP;AAAS,UAAS0R,QAAT,CAAkBnS,CAAlB,EAAoB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKoD,QAAL,CAAc3M,CAAd,EAAgBE,CAAhB,EAAkB,IAAlB,EAAwB,OAAOA,CAAP;AAAS,UAASkS,WAAT,CAAqBpS,CAArB,EAAuB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKoD,QAAL,CAAc3M,CAAd,EAAgB,IAAhB,EAAqBE,CAArB,EAAwB,OAAOA,CAAP;AAAS,UAASmS,oBAAT,CAA8BrS,CAA9B,EAAgC;AAAC,MAAIL,IAAE4J,KAAN;AAAA,MAAYrJ,IAAEqJ,KAAd,CAAoB,KAAKoD,QAAL,CAAc3M,CAAd,EAAgBL,CAAhB,EAAkBO,CAAlB,EAAqB,OAAO,IAAI8I,KAAJ,CAAUrJ,CAAV,EAAYO,CAAZ,CAAP;AAAsB,UAASoS,YAAT,CAAsB7R,CAAtB,EAAwB;AAAC,OAAK,KAAKqB,CAAV,IAAa,KAAK8H,EAAL,CAAQ,CAAR,EAAUnJ,IAAE,CAAZ,EAAc,IAAd,EAAmB,CAAnB,EAAqB,CAArB,EAAuB,KAAKqB,CAA5B,CAAb,CAA4C,EAAE,KAAKA,CAAP,CAAS,KAAKG,KAAL;AAAa,UAASsQ,aAAT,CAAuBvS,CAAvB,EAAyBS,CAAzB,EAA2B;AAAC,MAAGT,KAAG,CAAN,EAAQ;AAAC;AAAO,UAAM,KAAK8B,CAAL,IAAQrB,CAAd,EAAgB;AAAC,SAAK,KAAKqB,CAAL,EAAL,IAAe,CAAf;AAAiB,QAAKrB,CAAL,KAAST,CAAT,CAAW,OAAM,KAAKS,CAAL,KAAS,KAAKsJ,EAApB,EAAuB;AAAC,SAAKtJ,CAAL,KAAS,KAAKsJ,EAAd,CAAiB,IAAG,EAAEtJ,CAAF,IAAK,KAAKqB,CAAb,EAAe;AAAC,WAAK,KAAKA,CAAL,EAAL,IAAe,CAAf;AAAiB,OAAE,KAAKrB,CAAL,CAAF;AAAU;AAAC,UAAS+R,OAAT,GAAkB,CAAE,UAASC,IAAT,CAAchS,CAAd,EAAgB;AAAC,SAAOA,CAAP;AAAS,UAASiS,MAAT,CAAgBjS,CAAhB,EAAkBP,CAAlB,EAAoBF,CAApB,EAAsB;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf;AAAkB,UAAS2S,MAAT,CAAgBlS,CAAhB,EAAkBT,CAAlB,EAAoB;AAACS,IAAE4M,QAAF,CAAWrN,CAAX;AAAc,SAAQJ,SAAR,CAAkB0N,OAAlB,GAA0BmF,IAA1B,CAA+BD,QAAQ5S,SAAR,CAAkB2N,MAAlB,GAAyBkF,IAAzB,CAA8BD,QAAQ5S,SAAR,CAAkB4N,KAAlB,GAAwBkF,MAAxB,CAA+BF,QAAQ5S,SAAR,CAAkB6N,KAAlB,GAAwBkF,MAAxB,CAA+B,SAASC,KAAT,CAAenS,CAAf,EAAiB;AAAC,SAAO,KAAKkO,GAAL,CAASlO,CAAT,EAAW,IAAI+R,OAAJ,EAAX,CAAP;AAAiC,UAASK,kBAAT,CAA4B7S,CAA5B,EAA8BP,CAA9B,EAAgCQ,CAAhC,EAAkC;AAAC,MAAIN,IAAEuF,KAAKb,GAAL,CAAS,KAAKvC,CAAL,GAAO9B,EAAE8B,CAAlB,EAAoBrC,CAApB,CAAN,CAA6BQ,EAAE+B,CAAF,GAAI,CAAJ,CAAM/B,EAAE6B,CAAF,GAAInC,CAAJ,CAAM,OAAMA,IAAE,CAAR,EAAU;AAACM,MAAE,EAAEN,CAAJ,IAAO,CAAP;AAAS,OAAIO,CAAJ,CAAM,KAAIA,IAAED,EAAE6B,CAAF,GAAI,KAAKA,CAAf,EAAiBnC,IAAEO,CAAnB,EAAqB,EAAEP,CAAvB,EAAyB;AAACM,MAAEN,IAAE,KAAKmC,CAAT,IAAY,KAAK8H,EAAL,CAAQ,CAAR,EAAU5J,EAAEL,CAAF,CAAV,EAAeM,CAAf,EAAiBN,CAAjB,EAAmB,CAAnB,EAAqB,KAAKmC,CAA1B,CAAZ;AAAyC,QAAI5B,IAAEgF,KAAKb,GAAL,CAASrE,EAAE8B,CAAX,EAAarC,CAAb,CAAN,EAAsBE,IAAEO,CAAxB,EAA0B,EAAEP,CAA5B,EAA8B;AAAC,SAAKiK,EAAL,CAAQ,CAAR,EAAU5J,EAAEL,CAAF,CAAV,EAAeM,CAAf,EAAiBN,CAAjB,EAAmB,CAAnB,EAAqBF,IAAEE,CAAvB;AAA0B,KAAEsC,KAAF;AAAU,UAAS6Q,kBAAT,CAA4B9S,CAA5B,EAA8BC,CAA9B,EAAgCN,CAAhC,EAAkC;AAAC,IAAEM,CAAF,CAAI,IAAIC,IAAEP,EAAEmC,CAAF,GAAI,KAAKA,CAAL,GAAO9B,EAAE8B,CAAT,GAAW7B,CAArB,CAAuBN,EAAEqC,CAAF,GAAI,CAAJ,CAAM,OAAM,EAAE9B,CAAF,IAAK,CAAX,EAAa;AAACP,MAAEO,CAAF,IAAK,CAAL;AAAO,QAAIA,IAAEgF,KAAKf,GAAL,CAASlE,IAAE,KAAK6B,CAAhB,EAAkB,CAAlB,CAAN,EAA2B5B,IAAEF,EAAE8B,CAA/B,EAAiC,EAAE5B,CAAnC,EAAqC;AAACP,MAAE,KAAKmC,CAAL,GAAO5B,CAAP,GAASD,CAAX,IAAc,KAAK2J,EAAL,CAAQ3J,IAAEC,CAAV,EAAYF,EAAEE,CAAF,CAAZ,EAAiBP,CAAjB,EAAmB,CAAnB,EAAqB,CAArB,EAAuB,KAAKmC,CAAL,GAAO5B,CAAP,GAASD,CAAhC,CAAd;AAAiD,KAAEgC,KAAF,GAAUtC,EAAE6M,SAAF,CAAY,CAAZ,EAAc7M,CAAd;AAAiB,UAASoT,OAAT,CAAiBtS,CAAjB,EAAmB;AAAC,OAAKuS,EAAL,GAAQzJ,KAAR,CAAc,KAAK0J,EAAL,GAAQ1J,KAAR,CAAcH,WAAWmD,GAAX,CAAeF,SAAf,CAAyB,IAAE5L,EAAEqB,CAA7B,EAA+B,KAAKkR,EAApC,EAAwC,KAAKE,EAAL,GAAQ,KAAKF,EAAL,CAAQG,MAAR,CAAe1S,CAAf,CAAR,CAA0B,KAAK+B,CAAL,GAAO/B,CAAP;AAAS,UAAS2S,cAAT,CAAwB3S,CAAxB,EAA0B;AAAC,MAAGA,EAAEuB,CAAF,GAAI,CAAJ,IAAOvB,EAAEqB,CAAF,GAAI,IAAE,KAAKU,CAAL,CAAOV,CAAvB,EAAyB;AAAC,WAAOrB,EAAEqM,GAAF,CAAM,KAAKtK,CAAX,CAAP;AAAqB,GAA/C,MAAmD;AAAC,QAAG/B,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,IAAoB,CAAvB,EAAyB;AAAC,aAAO/B,CAAP;AAAS,KAAnC,MAAuC;AAAC,UAAIT,IAAEuJ,KAAN,CAAY9I,EAAE0L,MAAF,CAASnM,CAAT,EAAY,KAAKmN,MAAL,CAAYnN,CAAZ,EAAe,OAAOA,CAAP;AAAS;AAAC;AAAC,UAASqT,aAAT,CAAuB5S,CAAvB,EAAyB;AAAC,SAAOA,CAAP;AAAS,UAAS6S,aAAT,CAAuB7S,CAAvB,EAAyB;AAACA,IAAE+L,SAAF,CAAY,KAAKhK,CAAL,CAAOV,CAAP,GAAS,CAArB,EAAuB,KAAKkR,EAA5B,EAAgC,IAAGvS,EAAEqB,CAAF,GAAI,KAAKU,CAAL,CAAOV,CAAP,GAAS,CAAhB,EAAkB;AAACrB,MAAEqB,CAAF,GAAI,KAAKU,CAAL,CAAOV,CAAP,GAAS,CAAb,CAAerB,EAAEwB,KAAF;AAAU,QAAKiR,EAAL,CAAQK,eAAR,CAAwB,KAAKP,EAA7B,EAAgC,KAAKxQ,CAAL,CAAOV,CAAP,GAAS,CAAzC,EAA2C,KAAKmR,EAAhD,EAAoD,KAAKzQ,CAAL,CAAOgR,eAAP,CAAuB,KAAKP,EAA5B,EAA+B,KAAKzQ,CAAL,CAAOV,CAAP,GAAS,CAAxC,EAA0C,KAAKkR,EAA/C,EAAmD,OAAMvS,EAAE6L,SAAF,CAAY,KAAK0G,EAAjB,IAAqB,CAA3B,EAA6B;AAACvS,MAAEmP,UAAF,CAAa,CAAb,EAAe,KAAKpN,CAAL,CAAOV,CAAP,GAAS,CAAxB;AAA2B,KAAEkJ,KAAF,CAAQ,KAAKgI,EAAb,EAAgBvS,CAAhB,EAAmB,OAAMA,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,KAAqB,CAA3B,EAA6B;AAAC/B,MAAEuK,KAAF,CAAQ,KAAKxI,CAAb,EAAe/B,CAAf;AAAkB;AAAC,UAASgT,YAAT,CAAsBhT,CAAtB,EAAwBT,CAAxB,EAA0B;AAACS,IAAE4M,QAAF,CAAWrN,CAAX,EAAc,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,UAAS0T,YAAT,CAAsBjT,CAAtB,EAAwBP,CAAxB,EAA0BF,CAA1B,EAA4B;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf,EAAkB,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,SAAQJ,SAAR,CAAkB0N,OAAlB,GAA0B8F,cAA1B,CAAyCL,QAAQnT,SAAR,CAAkB2N,MAAlB,GAAyB8F,aAAzB,CAAuCN,QAAQnT,SAAR,CAAkBuN,MAAlB,GAAyBmG,aAAzB,CAAuCP,QAAQnT,SAAR,CAAkB4N,KAAlB,GAAwBkG,YAAxB,CAAqCX,QAAQnT,SAAR,CAAkB6N,KAAlB,GAAwBgG,YAAxB,CAAqC,SAASE,QAAT,CAAkB5R,CAAlB,EAAoBtC,CAApB,EAAsB;AAAC,MAAIsB,IAAEgB,EAAE6M,SAAF,EAAN;AAAA,MAAoBpP,CAApB;AAAA,MAAsBQ,IAAE2K,IAAI,CAAJ,CAAxB;AAAA,MAA+B1G,CAA/B,CAAiC,IAAGlD,KAAG,CAAN,EAAQ;AAAC,WAAOf,CAAP;AAAS,GAAlB,MAAsB;AAAC,QAAGe,IAAE,EAAL,EAAQ;AAACvB,UAAE,CAAF;AAAI,KAAb,MAAiB;AAAC,UAAGuB,IAAE,EAAL,EAAQ;AAACvB,YAAE,CAAF;AAAI,OAAb,MAAiB;AAAC,YAAGuB,IAAE,GAAL,EAAS;AAACvB,cAAE,CAAF;AAAI,SAAd,MAAkB;AAAC,cAAGuB,IAAE,GAAL,EAAS;AAACvB,gBAAE,CAAF;AAAI,WAAd,MAAkB;AAACA,gBAAE,CAAF;AAAI;AAAC;AAAC;AAAC;AAAC,OAAGuB,IAAE,CAAL,EAAO;AAACkD,QAAE,IAAI2I,OAAJ,CAAYnN,CAAZ,CAAF;AAAiB,GAAzB,MAA6B;AAAC,QAAGA,EAAEiP,MAAF,EAAH,EAAc;AAACzK,UAAE,IAAI8O,OAAJ,CAAYtT,CAAZ,CAAF;AAAiB,KAAhC,MAAoC;AAACwE,UAAE,IAAI0J,UAAJ,CAAelO,CAAf,CAAF;AAAoB;AAAC,OAAIqB,IAAE,IAAIkI,KAAJ,EAAN;AAAA,MAAkBrJ,IAAE,CAApB;AAAA,MAAsBqC,IAAExC,IAAE,CAA1B;AAAA,MAA4BiB,IAAE,CAAC,KAAGjB,CAAJ,IAAO,CAArC,CAAuCsB,EAAE,CAAF,IAAKmD,EAAEqJ,OAAF,CAAU,IAAV,CAAL,CAAqB,IAAG9N,IAAE,CAAL,EAAO;AAAC,QAAIiI,IAAE8B,KAAN,CAAYtF,EAAEwJ,KAAF,CAAQ3M,EAAE,CAAF,CAAR,EAAa2G,CAAb,EAAgB,OAAM9H,KAAGc,CAAT,EAAW;AAACK,QAAEnB,CAAF,IAAK4J,KAAL,CAAWtF,EAAEuJ,KAAF,CAAQ/F,CAAR,EAAU3G,EAAEnB,IAAE,CAAJ,CAAV,EAAiBmB,EAAEnB,CAAF,CAAjB,EAAuBA,KAAG,CAAH;AAAK;AAAC,OAAIY,IAAEwB,EAAED,CAAF,GAAI,CAAV;AAAA,MAAYiC,CAAZ;AAAA,MAAcG,IAAE,IAAhB;AAAA,MAAqBhE,IAAEqJ,KAAvB;AAAA,MAA6B7B,CAA7B,CAA+B3G,IAAEyK,MAAMzJ,EAAExB,CAAF,CAAN,IAAY,CAAd,CAAgB,OAAMA,KAAG,CAAT,EAAW;AAAC,QAAGQ,KAAGiB,CAAN,EAAQ;AAAC+B,UAAGhC,EAAExB,CAAF,KAAOQ,IAAEiB,CAAV,GAAcvB,CAAhB;AAAkB,KAA3B,MAA+B;AAACsD,UAAE,CAAChC,EAAExB,CAAF,IAAM,CAAC,KAAIQ,IAAE,CAAP,IAAW,CAAlB,KAAwBiB,IAAEjB,CAA5B,CAA+B,IAAGR,IAAE,CAAL,EAAO;AAACwD,aAAGhC,EAAExB,IAAE,CAAJ,KAAS,KAAKsJ,EAAL,GAAQ9I,CAAR,GAAUiB,CAAtB;AAAyB;AAAC,SAAExC,CAAF,CAAI,OAAM,CAACuE,IAAE,CAAH,KAAO,CAAb,EAAe;AAACA,YAAI,CAAJ,CAAM,EAAEpE,CAAF;AAAI,SAAG,CAACoB,KAAGpB,CAAJ,IAAO,CAAV,EAAY;AAACoB,WAAG,KAAK8I,EAAR,CAAW,EAAEtJ,CAAF;AAAI,SAAG2D,CAAH,EAAK;AAACpD,QAAEiD,CAAF,EAAKoI,MAAL,CAAYnM,CAAZ,EAAekE,IAAE,KAAF;AAAQ,KAA7B,MAAiC;AAAC,aAAMvE,IAAE,CAAR,EAAU;AAACsE,UAAEwJ,KAAF,CAAQzN,CAAR,EAAUE,CAAV,EAAa+D,EAAEwJ,KAAF,CAAQvN,CAAR,EAAUF,CAAV,EAAaL,KAAG,CAAH;AAAK,WAAGA,IAAE,CAAL,EAAO;AAACsE,UAAEwJ,KAAF,CAAQzN,CAAR,EAAUE,CAAV;AAAa,OAArB,MAAyB;AAACwH,YAAE1H,CAAF,CAAIA,IAAEE,CAAF,CAAIA,IAAEwH,CAAF;AAAI,SAAE8F,KAAF,CAAQtN,CAAR,EAAUY,EAAEiD,CAAF,CAAV,EAAe/D,CAAf;AAAkB,YAAMO,KAAG,CAAH,IAAM,CAACwB,EAAExB,CAAF,IAAM,KAAGQ,CAAV,KAAe,CAA3B,EAA6B;AAACkD,QAAEwJ,KAAF,CAAQzN,CAAR,EAAUE,CAAV,EAAawH,IAAE1H,CAAF,CAAIA,IAAEE,CAAF,CAAIA,IAAEwH,CAAF,CAAI,IAAG,EAAE3G,CAAF,GAAI,CAAP,EAAS;AAACA,YAAE,KAAK8I,EAAL,GAAQ,CAAV,CAAY,EAAEtJ,CAAF;AAAI;AAAC;AAAC,UAAO0D,EAAEsJ,MAAF,CAASvN,CAAT,CAAP;AAAmB,UAAS4T,KAAT,CAAe1T,CAAf,EAAiB;AAAC,MAAIF,IAAG,KAAKgC,CAAL,GAAO,CAAR,GAAW,KAAKmJ,MAAL,EAAX,GAAyB,KAAK3J,KAAL,EAA/B,CAA4C,IAAIhC,IAAGU,EAAE8B,CAAF,GAAI,CAAL,GAAQ9B,EAAEiL,MAAF,EAAR,GAAmBjL,EAAEsB,KAAF,EAAzB,CAAmC,IAAGxB,EAAEsM,SAAF,CAAY9M,CAAZ,IAAe,CAAlB,EAAoB;AAAC,QAAIS,IAAED,CAAN,CAAQA,IAAER,CAAF,CAAIA,IAAES,CAAF;AAAI,OAAIN,IAAEK,EAAE6T,eAAF,EAAN;AAAA,MAA0BpU,IAAED,EAAEqU,eAAF,EAA5B,CAAgD,IAAGpU,IAAE,CAAL,EAAO;AAAC,WAAOO,CAAP;AAAS,OAAGL,IAAEF,CAAL,EAAO;AAACA,QAAEE,CAAF;AAAI,OAAGF,IAAE,CAAL,EAAO;AAACO,MAAEyM,QAAF,CAAWhN,CAAX,EAAaO,CAAb,EAAgBR,EAAEiN,QAAF,CAAWhN,CAAX,EAAaD,CAAb;AAAgB,UAAMQ,EAAEuP,MAAF,KAAW,CAAjB,EAAmB;AAAC,QAAG,CAAC5P,IAAEK,EAAE6T,eAAF,EAAH,IAAwB,CAA3B,EAA6B;AAAC7T,QAAEyM,QAAF,CAAW9M,CAAX,EAAaK,CAAb;AAAgB,SAAG,CAACL,IAAEH,EAAEqU,eAAF,EAAH,IAAwB,CAA3B,EAA6B;AAACrU,QAAEiN,QAAF,CAAW9M,CAAX,EAAaH,CAAb;AAAgB,SAAGQ,EAAEsM,SAAF,CAAY9M,CAAZ,KAAgB,CAAnB,EAAqB;AAACQ,QAAEgL,KAAF,CAAQxL,CAAR,EAAUQ,CAAV,EAAaA,EAAEyM,QAAF,CAAW,CAAX,EAAazM,CAAb;AAAgB,KAAnD,MAAuD;AAACR,QAAEwL,KAAF,CAAQhL,CAAR,EAAUR,CAAV,EAAaA,EAAEiN,QAAF,CAAW,CAAX,EAAajN,CAAb;AAAgB;AAAC,OAAGC,IAAE,CAAL,EAAO;AAACD,MAAE4M,QAAF,CAAW3M,CAAX,EAAaD,CAAb;AAAgB,UAAOA,CAAP;AAAS,UAASsU,SAAT,CAAmB7T,CAAnB,EAAqB;AAAC,MAAGA,KAAG,CAAN,EAAQ;AAAC,WAAO,CAAP;AAAS,OAAIC,IAAE,KAAK6J,EAAL,GAAQ9J,CAAd;AAAA,MAAgBD,IAAG,KAAKgC,CAAL,GAAO,CAAR,GAAW/B,IAAE,CAAb,GAAe,CAAjC,CAAmC,IAAG,KAAK6B,CAAL,GAAO,CAAV,EAAY;AAAC,QAAG5B,KAAG,CAAN,EAAQ;AAACF,UAAE,KAAK,CAAL,IAAQC,CAAV;AAAY,KAArB,MAAyB;AAAC,WAAI,IAAIQ,IAAE,KAAKqB,CAAL,GAAO,CAAjB,EAAmBrB,KAAG,CAAtB,EAAwB,EAAEA,CAA1B,EAA4B;AAACT,YAAE,CAACE,IAAEF,CAAF,GAAI,KAAKS,CAAL,CAAL,IAAcR,CAAhB;AAAkB;AAAC;AAAC,UAAOD,CAAP;AAAS,UAAS+T,YAAT,CAAsBtU,CAAtB,EAAwB;AAAC,MAAIW,IAAEX,EAAEiP,MAAF,EAAN,CAAiB,IAAI,KAAKA,MAAL,MAAetO,CAAhB,IAAoBX,EAAE8P,MAAF,MAAY,CAAnC,EAAqC;AAAC,WAAOnG,WAAW2B,IAAlB;AAAuB,OAAI1K,IAAEZ,EAAE+B,KAAF,EAAN;AAAA,MAAgBhC,IAAE,KAAKgC,KAAL,EAAlB,CAA+B,IAAIjC,IAAEoL,IAAI,CAAJ,CAAN;AAAA,MAAa1K,IAAE0K,IAAI,CAAJ,CAAf;AAAA,MAAsBpK,IAAEoK,IAAI,CAAJ,CAAxB;AAAA,MAA+BnK,IAAEmK,IAAI,CAAJ,CAAjC,CAAwC,OAAMtK,EAAEkP,MAAF,MAAY,CAAlB,EAAoB;AAAC,WAAMlP,EAAEqO,MAAF,EAAN,EAAiB;AAACrO,QAAEoM,QAAF,CAAW,CAAX,EAAapM,CAAb,EAAgB,IAAGD,CAAH,EAAK;AAAC,YAAG,CAACb,EAAEmP,MAAF,EAAD,IAAa,CAACzO,EAAEyO,MAAF,EAAjB,EAA4B;AAACnP,YAAEwS,KAAF,CAAQ,IAAR,EAAaxS,CAAb,EAAgBU,EAAE+K,KAAF,CAAQvL,CAAR,EAAUQ,CAAV;AAAa,WAAEwM,QAAF,CAAW,CAAX,EAAalN,CAAb;AAAgB,OAAhF,MAAoF;AAAC,YAAG,CAACU,EAAEyO,MAAF,EAAJ,EAAe;AAACzO,YAAE+K,KAAF,CAAQvL,CAAR,EAAUQ,CAAV;AAAa;AAAC,SAAEwM,QAAF,CAAW,CAAX,EAAaxM,CAAb;AAAgB,YAAMT,EAAEkP,MAAF,EAAN,EAAiB;AAAClP,QAAEiN,QAAF,CAAW,CAAX,EAAajN,CAAb,EAAgB,IAAGY,CAAH,EAAK;AAAC,YAAG,CAACG,EAAEmO,MAAF,EAAD,IAAa,CAAClO,EAAEkO,MAAF,EAAjB,EAA4B;AAACnO,YAAEwR,KAAF,CAAQ,IAAR,EAAaxR,CAAb,EAAgBC,EAAEwK,KAAF,CAAQvL,CAAR,EAAUe,CAAV;AAAa,WAAEiM,QAAF,CAAW,CAAX,EAAalM,CAAb;AAAgB,OAAhF,MAAoF;AAAC,YAAG,CAACC,EAAEkO,MAAF,EAAJ,EAAe;AAAClO,YAAEwK,KAAF,CAAQvL,CAAR,EAAUe,CAAV;AAAa;AAAC,SAAEiM,QAAF,CAAW,CAAX,EAAajM,CAAb;AAAgB,SAAGH,EAAEiM,SAAF,CAAY9M,CAAZ,KAAgB,CAAnB,EAAqB;AAACa,QAAE2K,KAAF,CAAQxL,CAAR,EAAUa,CAAV,EAAa,IAAGD,CAAH,EAAK;AAACb,UAAEyL,KAAF,CAAQzK,CAAR,EAAUhB,CAAV;AAAa,SAAEyL,KAAF,CAAQxK,CAAR,EAAUP,CAAV;AAAa,KAAnE,MAAuE;AAACT,QAAEwL,KAAF,CAAQ3K,CAAR,EAAUb,CAAV,EAAa,IAAGY,CAAH,EAAK;AAACG,UAAEyK,KAAF,CAAQzL,CAAR,EAAUgB,CAAV;AAAa,SAAEyK,KAAF,CAAQ/K,CAAR,EAAUO,CAAV;AAAa;AAAC,OAAGhB,EAAE8M,SAAF,CAAYlD,WAAWmD,GAAvB,KAA6B,CAAhC,EAAkC;AAAC,WAAOnD,WAAW2B,IAAlB;AAAuB,OAAGvK,EAAE8L,SAAF,CAAY7M,CAAZ,KAAgB,CAAnB,EAAqB;AAAC,WAAOe,EAAEwT,QAAF,CAAWvU,CAAX,CAAP;AAAqB,OAAGe,EAAE+O,MAAF,KAAW,CAAd,EAAgB;AAAC/O,MAAEuR,KAAF,CAAQtS,CAAR,EAAUe,CAAV;AAAa,GAA9B,MAAkC;AAAC,WAAOA,CAAP;AAAS,OAAGA,EAAE+O,MAAF,KAAW,CAAd,EAAgB;AAAC,WAAO/O,EAAEyT,GAAF,CAAMxU,CAAN,CAAP;AAAgB,GAAjC,MAAqC;AAAC,WAAOe,CAAP;AAAS;AAAC,KAAI0T,YAAU,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,EAAO,CAAP,EAAS,EAAT,EAAY,EAAZ,EAAe,EAAf,EAAkB,EAAlB,EAAqB,EAArB,EAAwB,EAAxB,EAA2B,EAA3B,EAA8B,EAA9B,EAAiC,EAAjC,EAAoC,EAApC,EAAuC,EAAvC,EAA0C,EAA1C,EAA6C,EAA7C,EAAgD,EAAhD,EAAmD,EAAnD,EAAsD,EAAtD,EAAyD,EAAzD,EAA4D,EAA5D,EAA+D,EAA/D,EAAkE,EAAlE,EAAqE,EAArE,EAAwE,GAAxE,EAA4E,GAA5E,EAAgF,GAAhF,EAAoF,GAApF,EAAwF,GAAxF,EAA4F,GAA5F,EAAgG,GAAhG,EAAoG,GAApG,EAAwG,GAAxG,EAA4G,GAA5G,EAAgH,GAAhH,EAAoH,GAApH,EAAwH,GAAxH,EAA4H,GAA5H,EAAgI,GAAhI,EAAoI,GAApI,EAAwI,GAAxI,EAA4I,GAA5I,EAAgJ,GAAhJ,EAAoJ,GAApJ,EAAwJ,GAAxJ,EAA4J,GAA5J,EAAgK,GAAhK,EAAoK,GAApK,EAAwK,GAAxK,EAA4K,GAA5K,EAAgL,GAAhL,EAAoL,GAApL,EAAwL,GAAxL,EAA4L,GAA5L,EAAgM,GAAhM,EAAoM,GAApM,EAAwM,GAAxM,EAA4M,GAA5M,EAAgN,GAAhN,EAAoN,GAApN,EAAwN,GAAxN,EAA4N,GAA5N,EAAgO,GAAhO,EAAoO,GAApO,EAAwO,GAAxO,EAA4O,GAA5O,EAAgP,GAAhP,EAAoP,GAApP,EAAwP,GAAxP,EAA4P,GAA5P,EAAgQ,GAAhQ,EAAoQ,GAApQ,EAAwQ,GAAxQ,EAA4Q,GAA5Q,EAAgR,GAAhR,EAAoR,GAApR,EAAwR,GAAxR,EAA4R,GAA5R,EAAgS,GAAhS,EAAoS,GAApS,EAAwS,GAAxS,EAA4S,GAA5S,EAAgT,GAAhT,EAAoT,GAApT,EAAwT,GAAxT,EAA4T,GAA5T,EAAgU,GAAhU,EAAoU,GAApU,EAAwU,GAAxU,EAA4U,GAA5U,EAAgV,GAAhV,EAAoV,GAApV,EAAwV,GAAxV,EAA4V,GAA5V,EAAgW,GAAhW,EAAoW,GAApW,EAAwW,GAAxW,EAA4W,GAA5W,EAAgX,GAAhX,EAAoX,GAApX,EAAwX,GAAxX,EAA4X,GAA5X,EAAgY,GAAhY,EAAoY,GAApY,EAAwY,GAAxY,EAA4Y,GAA5Y,EAAgZ,GAAhZ,EAAoZ,GAApZ,EAAwZ,GAAxZ,EAA4Z,GAA5Z,EAAga,GAAha,EAAoa,GAApa,EAAwa,GAAxa,EAA4a,GAA5a,EAAgb,GAAhb,EAAob,GAApb,EAAwb,GAAxb,EAA4b,GAA5b,EAAgc,GAAhc,EAAoc,GAApc,EAAwc,GAAxc,EAA4c,GAA5c,EAAgd,GAAhd,EAAod,GAApd,EAAwd,GAAxd,EAA4d,GAA5d,EAAge,GAAhe,EAAoe,GAApe,EAAwe,GAAxe,EAA4e,GAA5e,EAAgf,GAAhf,EAAof,GAApf,EAAwf,GAAxf,EAA4f,GAA5f,EAAggB,GAAhgB,EAAogB,GAApgB,EAAwgB,GAAxgB,EAA4gB,GAA5gB,EAAghB,GAAhhB,EAAohB,GAAphB,EAAwhB,GAAxhB,EAA4hB,GAA5hB,EAAgiB,GAAhiB,EAAoiB,GAApiB,EAAwiB,GAAxiB,EAA4iB,GAA5iB,EAAgjB,GAAhjB,EAAojB,GAApjB,EAAwjB,GAAxjB,EAA4jB,GAA5jB,EAAgkB,GAAhkB,EAAokB,GAApkB,EAAwkB,GAAxkB,EAA4kB,GAA5kB,EAAglB,GAAhlB,EAAolB,GAAplB,EAAwlB,GAAxlB,EAA4lB,GAA5lB,EAAgmB,GAAhmB,EAAomB,GAApmB,EAAwmB,GAAxmB,EAA4mB,GAA5mB,EAAgnB,GAAhnB,EAAonB,GAApnB,EAAwnB,GAAxnB,EAA4nB,GAA5nB,EAAgoB,GAAhoB,CAAd,CAAmpB,IAAIC,QAAM,CAAC,KAAG,EAAJ,IAAQD,UAAUA,UAAU5T,MAAV,GAAiB,CAA3B,CAAlB,CAAgD,SAAS8T,iBAAT,CAA2BnU,CAA3B,EAA6B;AAAC,MAAIN,CAAJ;AAAA,MAAMK,IAAE,KAAKgM,GAAL,EAAR,CAAmB,IAAGhM,EAAE8B,CAAF,IAAK,CAAL,IAAQ9B,EAAE,CAAF,KAAMkU,UAAUA,UAAU5T,MAAV,GAAiB,CAA3B,CAAjB,EAA+C;AAAC,SAAIX,IAAE,CAAN,EAAQA,IAAEuU,UAAU5T,MAApB,EAA2B,EAAEX,CAA7B,EAA+B;AAAC,UAAGK,EAAE,CAAF,KAAMkU,UAAUvU,CAAV,CAAT,EAAsB;AAAC,eAAO,IAAP;AAAY;AAAC,YAAO,KAAP;AAAa,OAAGK,EAAE0O,MAAF,EAAH,EAAc;AAAC,WAAO,KAAP;AAAa,OAAE,CAAF,CAAI,OAAM/O,IAAEuU,UAAU5T,MAAlB,EAAyB;AAAC,QAAIG,IAAEyT,UAAUvU,CAAV,CAAN;AAAA,QAAmBO,IAAEP,IAAE,CAAvB,CAAyB,OAAMO,IAAEgU,UAAU5T,MAAZ,IAAoBG,IAAE0T,KAA5B,EAAkC;AAAC1T,WAAGyT,UAAUhU,GAAV,CAAH;AAAkB,SAAEF,EAAEqU,MAAF,CAAS5T,CAAT,CAAF,CAAc,OAAMd,IAAEO,CAAR,EAAU;AAAC,UAAGO,IAAEyT,UAAUvU,GAAV,CAAF,IAAkB,CAArB,EAAuB;AAAC,eAAO,KAAP;AAAa;AAAC;AAAC,UAAOK,EAAEsU,WAAF,CAAcrU,CAAd,CAAP;AAAwB,UAASsU,cAAT,CAAwB9U,CAAxB,EAA0B;AAAC,MAAIF,IAAE,KAAKyU,QAAL,CAAc5K,WAAWmD,GAAzB,CAAN,CAAoC,IAAIrM,IAAEX,EAAEsU,eAAF,EAAN,CAA0B,IAAG3T,KAAG,CAAN,EAAQ;AAAC,WAAO,KAAP;AAAa,OAAIV,IAAED,EAAEiV,UAAF,CAAatU,CAAb,CAAN,CAAsBT,IAAGA,IAAE,CAAH,IAAO,CAAT,CAAW,IAAGA,IAAEyU,UAAU5T,MAAf,EAAsB;AAACb,QAAEyU,UAAU5T,MAAZ;AAAmB,OAAIN,IAAEuJ,KAAN,CAAY,KAAI,IAAItJ,IAAE,CAAV,EAAYA,IAAER,CAAd,EAAgB,EAAEQ,CAAlB,EAAoB;AAACD,MAAE4K,OAAF,CAAUsJ,UAAUhP,KAAKc,KAAL,CAAWd,KAAK5C,MAAL,KAAc4R,UAAU5T,MAAnC,CAAV,CAAV,EAAiE,IAAIC,IAAEP,EAAEyU,MAAF,CAASjV,CAAT,EAAW,IAAX,CAAN,CAAuB,IAAGe,EAAE+L,SAAF,CAAYlD,WAAWmD,GAAvB,KAA6B,CAA7B,IAAgChM,EAAE+L,SAAF,CAAY/M,CAAZ,KAAgB,CAAnD,EAAqD;AAAC,UAAII,IAAE,CAAN,CAAQ,OAAMA,MAAIO,CAAJ,IAAOK,EAAE+L,SAAF,CAAY/M,CAAZ,KAAgB,CAA7B,EAA+B;AAACgB,YAAEA,EAAEsO,SAAF,CAAY,CAAZ,EAAc,IAAd,CAAF,CAAsB,IAAGtO,EAAE+L,SAAF,CAAYlD,WAAWmD,GAAvB,KAA6B,CAAhC,EAAkC;AAAC,iBAAO,KAAP;AAAa;AAAC,WAAGhM,EAAE+L,SAAF,CAAY/M,CAAZ,KAAgB,CAAnB,EAAqB;AAAC,eAAO,KAAP;AAAa;AAAC;AAAC,UAAO,IAAP;AAAY,YAAWK,SAAX,CAAqB4P,SAArB,GAA+BN,YAA/B,CAA4C9F,WAAWxJ,SAAX,CAAqBwL,OAArB,GAA6BkE,UAA7B,CAAwClG,WAAWxJ,SAAX,CAAqBkL,SAArB,GAA+B4E,YAA/B,CAA4CtG,WAAWxJ,SAAX,CAAqByJ,UAArB,GAAgCwG,aAAhC,CAA8CzG,WAAWxJ,SAAX,CAAqBmQ,SAArB,GAA+BS,YAA/B,CAA4CpH,WAAWxJ,SAAX,CAAqB8R,SAArB,GAA+BF,YAA/B,CAA4CpI,WAAWxJ,SAAX,CAAqBmS,KAArB,GAA2BF,QAA3B,CAAoCzI,WAAWxJ,SAAX,CAAqB+P,SAArB,GAA+B2C,YAA/B,CAA4ClJ,WAAWxJ,SAAX,CAAqBgQ,UAArB,GAAgC2C,aAAhC,CAA8CnJ,WAAWxJ,SAAX,CAAqB4T,eAArB,GAAqCX,kBAArC,CAAwDzJ,WAAWxJ,SAAX,CAAqB2T,eAArB,GAAqCT,kBAArC,CAAwD1J,WAAWxJ,SAAX,CAAqByU,MAArB,GAA4BP,SAA5B,CAAsC1K,WAAWxJ,SAAX,CAAqB0U,WAArB,GAAiCC,cAAjC,CAAgDnL,WAAWxJ,SAAX,CAAqB4B,KAArB,GAA2BsN,OAA3B,CAAmC1F,WAAWxJ,SAAX,CAAqB6P,QAArB,GAA8BV,UAA9B,CAAyC3F,WAAWxJ,SAAX,CAAqB8U,SAArB,GAA+B1F,WAA/B,CAA2C5F,WAAWxJ,SAAX,CAAqB+U,UAArB,GAAgC1F,YAAhC,CAA6C7F,WAAWxJ,SAAX,CAAqB2P,MAArB,GAA4BF,QAA5B,CAAqCjG,WAAWxJ,SAAX,CAAqBgV,WAArB,GAAiCxE,aAAjC,CAA+ChH,WAAWxJ,SAAX,CAAqBiV,MAArB,GAA4BxE,QAA5B,CAAqCjH,WAAWxJ,SAAX,CAAqByE,GAArB,GAAyBiM,KAAzB,CAA+BlH,WAAWxJ,SAAX,CAAqBuE,GAArB,GAAyBoM,KAAzB,CAA+BnH,WAAWxJ,SAAX,CAAqBkV,GAArB,GAAyBpE,KAAzB,CAA+BtH,WAAWxJ,SAAX,CAAqBmV,EAArB,GAAwBpE,IAAxB,CAA6BvH,WAAWxJ,SAAX,CAAqBoV,GAArB,GAAyBnE,KAAzB,CAA+BzH,WAAWxJ,SAAX,CAAqBqV,MAArB,GAA4BlE,QAA5B,CAAqC3H,WAAWxJ,SAAX,CAAqBsV,GAArB,GAAyBlE,KAAzB,CAA+B5H,WAAWxJ,SAAX,CAAqBoQ,SAArB,GAA+BiB,WAA/B,CAA2C7H,WAAWxJ,SAAX,CAAqB4U,UAArB,GAAgCtD,YAAhC,CAA6C9H,WAAWxJ,SAAX,CAAqBiU,eAArB,GAAqCzC,iBAArC,CAAuDhI,WAAWxJ,SAAX,CAAqBuV,QAArB,GAA8B7D,UAA9B,CAAyClI,WAAWxJ,SAAX,CAAqBkQ,OAArB,GAA6ByB,SAA7B,CAAuCnI,WAAWxJ,SAAX,CAAqBwV,MAArB,GAA4B3D,QAA5B,CAAqCrI,WAAWxJ,SAAX,CAAqByV,QAArB,GAA8B1D,UAA9B,CAAyCvI,WAAWxJ,SAAX,CAAqB0V,OAArB,GAA6B1D,SAA7B,CAAuCxI,WAAWxJ,SAAX,CAAqBqU,GAArB,GAAyBnC,KAAzB,CAA+B1I,WAAWxJ,SAAX,CAAqBoU,QAArB,GAA8BhC,UAA9B,CAAyC5I,WAAWxJ,SAAX,CAAqB2V,QAArB,GAA8BtD,UAA9B,CAAyC7I,WAAWxJ,SAAX,CAAqBuT,MAArB,GAA4BhB,QAA5B,CAAqC/I,WAAWxJ,SAAX,CAAqB4V,SAArB,GAA+BpD,WAA/B,CAA2ChJ,WAAWxJ,SAAX,CAAqB6V,kBAArB,GAAwCpD,oBAAxC,CAA6DjJ,WAAWxJ,SAAX,CAAqB6U,MAArB,GAA4Bd,QAA5B,CAAqCvK,WAAWxJ,SAAX,CAAqB8V,UAArB,GAAgC3B,YAAhC,CAA6C3K,WAAWxJ,SAAX,CAAqBiG,GAArB,GAAyB+M,KAAzB,CAA+BxJ,WAAWxJ,SAAX,CAAqB+V,GAArB,GAAyB/B,KAAzB,CAA+BxK,WAAWxJ,SAAX,CAAqBsQ,eAArB,GAAqCkE,iBAArC,CAAuDhL,WAAWxJ,SAAX,CAAqBgW,MAArB,GAA4B1D,QAA5B;AACrgZ;;AAEA,SAAS2D,OAAT,GAAkB;AAAC,OAAKxV,CAAL,GAAO,CAAP,CAAS,KAAKD,CAAL,GAAO,CAAP,CAAS,KAAK2H,CAAL,GAAO,IAAIiB,KAAJ,EAAP;AAAmB,UAAS8M,QAAT,CAAkBnW,CAAlB,EAAoB;AAAC,MAAIO,CAAJ,EAAMO,CAAN,EAAQT,CAAR,CAAU,KAAIE,IAAE,CAAN,EAAQA,IAAE,GAAV,EAAc,EAAEA,CAAhB,EAAkB;AAAC,SAAK6H,CAAL,CAAO7H,CAAP,IAAUA,CAAV;AAAY,OAAE,CAAF,CAAI,KAAIA,IAAE,CAAN,EAAQA,IAAE,GAAV,EAAc,EAAEA,CAAhB,EAAkB;AAACO,QAAGA,IAAE,KAAKsH,CAAL,CAAO7H,CAAP,CAAF,GAAYP,EAAEO,IAAEP,EAAEW,MAAN,CAAb,GAA4B,GAA9B,CAAkCN,IAAE,KAAK+H,CAAL,CAAO7H,CAAP,CAAF,CAAY,KAAK6H,CAAL,CAAO7H,CAAP,IAAU,KAAK6H,CAAL,CAAOtH,CAAP,CAAV,CAAoB,KAAKsH,CAAL,CAAOtH,CAAP,IAAUT,CAAV;AAAY,QAAKK,CAAL,GAAO,CAAP,CAAS,KAAKD,CAAL,GAAO,CAAP;AAAS,UAAS2V,QAAT,GAAmB;AAAC,MAAItV,CAAJ,CAAM,KAAKJ,CAAL,GAAQ,KAAKA,CAAL,GAAO,CAAR,GAAW,GAAlB,CAAsB,KAAKD,CAAL,GAAQ,KAAKA,CAAL,GAAO,KAAK2H,CAAL,CAAO,KAAK1H,CAAZ,CAAR,GAAwB,GAA/B,CAAmCI,IAAE,KAAKsH,CAAL,CAAO,KAAK1H,CAAZ,CAAF,CAAiB,KAAK0H,CAAL,CAAO,KAAK1H,CAAZ,IAAe,KAAK0H,CAAL,CAAO,KAAK3H,CAAZ,CAAf,CAA8B,KAAK2H,CAAL,CAAO,KAAK3H,CAAZ,IAAeK,CAAf,CAAiB,OAAO,KAAKsH,CAAL,CAAQtH,IAAE,KAAKsH,CAAL,CAAO,KAAK1H,CAAZ,CAAH,GAAmB,GAA1B,CAAP;AAAsC,SAAQT,SAAR,CAAkBsB,IAAlB,GAAuB4U,QAAvB,CAAgCD,QAAQjW,SAAR,CAAkBoW,IAAlB,GAAuBD,QAAvB,CAAgC,SAASE,aAAT,GAAwB;AAAC,SAAO,IAAIJ,OAAJ,EAAP;AAAqB,KAAIK,YAAU,GAAd;AACphB;;AAEA,IAAIC,SAAJ,CAAc,IAAIC,QAAJ,CAAa,IAAIC,QAAJ,CAAa,SAASC,YAAT,CAAsB7V,CAAtB,EAAwB;AAAC2V,WAASC,UAAT,KAAsB5V,IAAE,GAAxB,CAA4B2V,SAASC,UAAT,KAAuB5V,KAAG,CAAJ,GAAO,GAA7B,CAAiC2V,SAASC,UAAT,KAAuB5V,KAAG,EAAJ,GAAQ,GAA9B,CAAkC2V,SAASC,UAAT,KAAuB5V,KAAG,EAAJ,GAAQ,GAA9B,CAAkC,IAAG4V,YAAUH,SAAb,EAAuB;AAACG,gBAAUH,SAAV;AAAoB;AAAC,UAASK,aAAT,GAAwB;AAACD,eAAa,IAAIE,IAAJ,GAAWC,OAAX,EAAb;AAAmC,KAAGL,YAAU,IAAb,EAAkB;AAACA,aAAS,IAAIpN,KAAJ,EAAT,CAAqBqN,WAAS,CAAT,CAAW,IAAIvU,CAAJ,CAAM,IAAG5C,WAASE,SAAT,KAAqBF,OAAOwX,MAAP,KAAgBtX,SAAhB,IAA2BF,OAAOyX,QAAP,KAAkBvX,SAAlE,CAAH,EAAgF;AAAC,QAAIsX,SAAOxX,OAAOwX,MAAP,IAAexX,OAAOyX,QAAjC,CAA0C,IAAGD,OAAOE,eAAV,EAA0B;AAAC,UAAIC,KAAG,IAAIC,UAAJ,CAAe,EAAf,CAAP,CAA0BJ,OAAOE,eAAP,CAAuBC,EAAvB,EAA2B,KAAI/U,IAAE,CAAN,EAAQA,IAAE,EAAV,EAAa,EAAEA,CAAf,EAAiB;AAACsU,iBAASC,UAAT,IAAqBQ,GAAG/U,CAAH,CAArB;AAA2B;AAAC,KAA9H,MAAkI;AAAC,UAAG9C,UAAU2K,OAAV,IAAmB,UAAnB,IAA+B3K,UAAU+X,UAAV,GAAqB,GAAvD,EAA2D;AAAC,YAAIvP,IAAEtI,OAAOwX,MAAP,CAAcpU,MAAd,CAAqB,EAArB,CAAN,CAA+B,KAAIR,IAAE,CAAN,EAAQA,IAAE0F,EAAElH,MAAZ,EAAmB,EAAEwB,CAArB,EAAuB;AAACsU,mBAASC,UAAT,IAAqB7O,EAAEtE,UAAF,CAAapB,CAAb,IAAgB,GAArC;AAAyC;AAAC;AAAC;AAAC,UAAMuU,WAASH,SAAf,EAAyB;AAACpU,QAAEoD,KAAKc,KAAL,CAAW,QAAMd,KAAK5C,MAAL,EAAjB,CAAF,CAAkC8T,SAASC,UAAT,IAAqBvU,MAAI,CAAzB,CAA2BsU,SAASC,UAAT,IAAqBvU,IAAE,GAAvB;AAA2B,cAAS,CAAT,CAAWyU;AAAgB,UAASS,YAAT,GAAuB;AAAC,MAAGb,aAAW,IAAd,EAAmB;AAACI,oBAAgBJ,YAAUF,eAAV,CAA0BE,UAAUjV,IAAV,CAAekV,QAAf,EAAyB,KAAIC,WAAS,CAAb,EAAeA,WAASD,SAAS9V,MAAjC,EAAwC,EAAE+V,QAA1C,EAAmD;AAACD,eAASC,QAAT,IAAmB,CAAnB;AAAqB,gBAAS,CAAT;AAAW,UAAOF,UAAUH,IAAV,EAAP;AAAwB,UAASiB,aAAT,CAAuBjX,CAAvB,EAAyB;AAAC,MAAIS,CAAJ,CAAM,KAAIA,IAAE,CAAN,EAAQA,IAAET,EAAEM,MAAZ,EAAmB,EAAEG,CAArB,EAAuB;AAACT,MAAES,CAAF,IAAKuW,cAAL;AAAoB;AAAC,UAASE,YAAT,GAAuB,CAAE,cAAatX,SAAb,CAAuBuQ,SAAvB,GAAiC8G,aAAjC;AAC/sC;;AAEA,SAASE,WAAT,CAAqBnX,CAArB,EAAuBS,CAAvB,EAAyB;AAAC,SAAO,IAAI2I,UAAJ,CAAepJ,CAAf,EAAiBS,CAAjB,CAAP;AAA2B,UAAS2W,OAAT,CAAiBlX,CAAjB,EAAmBP,CAAnB,EAAqB;AAAC,MAAIc,IAAE,EAAN,CAAS,IAAIT,IAAE,CAAN,CAAQ,OAAMA,IAAEL,CAAF,GAAIO,EAAEI,MAAZ,EAAmB;AAACG,SAAGP,EAAE0I,SAAF,CAAY5I,CAAZ,EAAcA,IAAEL,CAAhB,IAAmB,IAAtB,CAA2BK,KAAGL,CAAH;AAAK,UAAOc,IAAEP,EAAE0I,SAAF,CAAY5I,CAAZ,EAAcE,EAAEI,MAAhB,CAAT;AAAiC,UAAS+W,QAAT,CAAkB5W,CAAlB,EAAoB;AAAC,MAAGA,IAAE,EAAL,EAAQ;AAAC,WAAM,MAAIA,EAAEc,QAAF,CAAW,EAAX,CAAV;AAAyB,GAAlC,MAAsC;AAAC,WAAOd,EAAEc,QAAF,CAAW,EAAX,CAAP;AAAsB;AAAC,UAAS+V,SAAT,CAAmBrX,CAAnB,EAAqBT,CAArB,EAAuB;AAAC,MAAGA,IAAES,EAAEK,MAAF,GAAS,EAAd,EAAiB;AAAC,UAAK,0BAAL,CAAgC,OAAO,IAAP;AAAY,OAAIf,IAAE,IAAIyJ,KAAJ,EAAN,CAAkB,IAAIrJ,IAAEM,EAAEK,MAAF,GAAS,CAAf,CAAiB,OAAMX,KAAG,CAAH,IAAMH,IAAE,CAAd,EAAgB;AAAC,QAAIC,IAAEQ,EAAEiD,UAAF,CAAavD,GAAb,CAAN,CAAwB,IAAGF,IAAE,GAAL,EAAS;AAACF,QAAE,EAAEC,CAAJ,IAAOC,CAAP;AAAS,KAAnB,MAAuB;AAAC,UAAIA,IAAE,GAAH,IAAUA,IAAE,IAAf,EAAqB;AAACF,UAAE,EAAEC,CAAJ,IAAQC,IAAE,EAAH,GAAO,GAAd,CAAkBF,EAAE,EAAEC,CAAJ,IAAQC,KAAG,CAAJ,GAAO,GAAd;AAAkB,OAA1D,MAA8D;AAACF,UAAE,EAAEC,CAAJ,IAAQC,IAAE,EAAH,GAAO,GAAd,CAAkBF,EAAE,EAAEC,CAAJ,IAASC,KAAG,CAAJ,GAAO,EAAR,GAAY,GAAnB,CAAuBF,EAAE,EAAEC,CAAJ,IAAQC,KAAG,EAAJ,GAAQ,GAAf;AAAmB;AAAC;AAAC,KAAE,EAAED,CAAJ,IAAO,CAAP,CAAS,IAAIQ,IAAE,IAAIkX,YAAJ,EAAN,CAAyB,IAAIzW,IAAE,IAAIuI,KAAJ,EAAN,CAAkB,OAAMxJ,IAAE,CAAR,EAAU;AAACiB,MAAE,CAAF,IAAK,CAAL,CAAO,OAAMA,EAAE,CAAF,KAAM,CAAZ,EAAc;AAACT,QAAEmQ,SAAF,CAAY1P,CAAZ;AAAe,OAAE,EAAEjB,CAAJ,IAAOiB,EAAE,CAAF,CAAP;AAAY,KAAE,EAAEjB,CAAJ,IAAO,CAAP,CAASD,EAAE,EAAEC,CAAJ,IAAO,CAAP,CAAS,OAAO,IAAI4J,UAAJ,CAAe7J,CAAf,CAAP;AAAyB,UAASgY,aAAT,CAAuBrX,CAAvB,EAAyBO,CAAzB,EAA2BR,CAA3B,EAA6B;AAAC,MAAID,IAAE,EAAN;AAAA,MAASL,IAAE,CAAX,CAAa,OAAMK,EAAEM,MAAF,GAASG,CAAf,EAAiB;AAACT,SAAGC,EAAE+C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiC9C,EAAE2B,MAAF,CAAS,CAAC,CAAClC,IAAE,UAAH,KAAgB,EAAjB,EAAoB,CAACA,IAAE,QAAH,KAAc,EAAlC,EAAqC,CAACA,IAAE,KAAH,KAAW,CAAhD,EAAkDA,IAAE,GAApD,CAAT,CAAjC,CAAF,CAAH,CAA2GA,KAAG,CAAH;AAAK,UAAOK,CAAP;AAAS,UAASwX,QAAT,CAAkBzV,CAAlB,EAAoBtB,CAApB,EAAsBhB,CAAtB,EAAwBc,CAAxB,EAA0B;AAAC,MAAIL,IAAEuX,KAAKf,MAAL,CAAYgB,aAAlB,CAAgC,IAAI3W,IAAE0W,KAAKf,MAAL,CAAYiB,IAAlB,CAAuB,IAAI3X,IAAE,IAAN,CAAW,IAAG,CAACP,CAAJ,EAAM;AAACA,QAAE,MAAF;AAAS,OAAG,OAAOA,CAAP,KAAW,QAAd,EAAuB;AAACO,QAAEE,EAAE0X,mBAAF,CAAsBnY,CAAtB,CAAF,CAA2Bc,IAAEL,EAAE2X,aAAF,CAAgB7X,CAAhB,CAAF,CAAqBP,IAAE,WAASY,CAAT,EAAW;AAAC,aAAOyX,UAAU/W,EAAEgX,OAAF,CAAUC,UAAU3X,CAAV,CAAV,EAAuBL,CAAvB,CAAV,CAAP;AAA4C,KAA1D;AAA2D,OAAG+B,EAAEzB,MAAF,GAAS,IAAEC,CAAX,GAAa,CAAb,GAAeE,CAAlB,EAAoB;AAAC,UAAK,0BAAL;AAAgC,OAAID,IAAE,EAAN;AAAA,MAASP,CAAT,CAAW,KAAIA,IAAE,CAAN,EAAQA,IAAEQ,IAAEsB,EAAEzB,MAAJ,GAAW,IAAEC,CAAb,GAAe,CAAzB,EAA2BN,KAAG,CAA9B,EAAgC;AAACO,SAAG,MAAH;AAAU,OAAIhB,IAAEC,EAAE,EAAF,IAAMe,CAAN,GAAQ,MAAR,GAAeuB,CAArB,CAAuB,IAAIxC,IAAE,IAAIyJ,KAAJ,CAAUzI,CAAV,CAAN,CAAmB,IAAI2W,YAAJ,GAAmB/G,SAAnB,CAA6B5Q,CAA7B,EAAgC,IAAIa,IAAEmX,cAAchY,CAAd,EAAgBC,EAAEc,MAAlB,EAAyBb,CAAzB,CAAN,CAAkC,IAAIqB,IAAE,EAAN,CAAS,KAAIb,IAAE,CAAN,EAAQA,IAAET,EAAEc,MAAZ,EAAmBL,KAAG,CAAtB,EAAwB;AAACa,MAAEb,CAAF,IAAKT,EAAE0D,UAAF,CAAajD,CAAb,IAAgBG,EAAE8C,UAAF,CAAajD,CAAb,CAArB;AAAqC,OAAIuC,IAAE+U,cAAczW,CAAd,EAAgBvB,EAAEe,MAAlB,EAAyBb,CAAzB,CAAN,CAAkC,IAAIE,IAAE,CAAC,CAAD,CAAN,CAAU,KAAIM,IAAE,CAAN,EAAQA,IAAEV,EAAEe,MAAZ,EAAmBL,KAAG,CAAtB,EAAwB;AAACN,MAAEM,IAAE,CAAJ,IAAOV,EAAEU,CAAF,IAAKuC,EAAEU,UAAF,CAAajD,CAAb,CAAZ;AAA4B,UAAO,IAAImJ,UAAJ,CAAezJ,EAAEkC,MAAF,CAASf,CAAT,CAAf,CAAP;AAAmC,UAASmX,MAAT,GAAiB;AAAC,OAAKpX,CAAL,GAAO,IAAP,CAAY,KAAKZ,CAAL,GAAO,CAAP,CAAS,KAAKN,CAAL,GAAO,IAAP,CAAY,KAAKmB,CAAL,GAAO,IAAP,CAAY,KAAKiB,CAAL,GAAO,IAAP,CAAY,KAAKmW,IAAL,GAAU,IAAV,CAAe,KAAKC,IAAL,GAAU,IAAV,CAAe,KAAKC,KAAL,GAAW,IAAX;AAAgB,UAASC,YAAT,CAAsBrY,CAAtB,EAAwBS,CAAxB,EAA0B;AAAC,OAAK6X,QAAL,GAAc,IAAd,CAAmB,KAAKC,SAAL,GAAe,KAAf,CAAqB,IAAG,OAAOvY,CAAP,KAAW,QAAd,EAAuB;AAAC,SAAKa,CAAL,GAAOb,CAAP,CAAS,KAAKC,CAAL,GAAOQ,CAAP;AAAS,GAA1C,MAA8C;AAAC,QAAGT,KAAG,IAAH,IAASS,KAAG,IAAZ,IAAkBT,EAAEM,MAAF,GAAS,CAA3B,IAA8BG,EAAEH,MAAF,GAAS,CAA1C,EAA4C;AAAC,WAAKO,CAAL,GAAOsW,YAAYnX,CAAZ,EAAc,EAAd,CAAP,CAAyB,KAAKC,CAAL,GAAO4C,SAASpC,CAAT,EAAW,EAAX,CAAP;AAAsB,KAA5F,MAAgG;AAAC,YAAK,wBAAL;AAA8B;AAAC;AAAC,UAAS+X,WAAT,CAAqB/X,CAArB,EAAuB;AAAC,SAAOA,EAAEoO,SAAF,CAAY,KAAK5O,CAAjB,EAAmB,KAAKY,CAAxB,CAAP;AAAkC,UAAS4X,UAAT,CAAoB9Y,CAApB,EAAsB;AAAC,MAAIc,IAAE6W,UAAU3X,CAAV,EAAa,KAAKkB,CAAL,CAAO+N,SAAP,KAAmB,CAApB,IAAwB,CAApC,CAAN,CAA6C,IAAGnO,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAIR,IAAE,KAAKyY,QAAL,CAAcjY,CAAd,CAAN,CAAuB,IAAGR,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAID,IAAEC,EAAEsB,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG,CAACvB,EAAEM,MAAF,GAAS,CAAV,KAAc,CAAjB,EAAmB;AAAC,WAAON,CAAP;AAAS,GAA7B,MAAiC;AAAC,WAAM,MAAIA,CAAV;AAAY;AAAC,UAAS2Y,cAAT,CAAwBlZ,CAAxB,EAA0BQ,CAA1B,EAA4BD,CAA5B,EAA8B;AAAC,MAAIS,IAAE+W,SAAS/X,CAAT,EAAY,KAAKoB,CAAL,CAAO+N,SAAP,KAAmB,CAApB,IAAwB,CAAnC,EAAqC3O,CAArC,EAAuCD,CAAvC,CAAN,CAAgD,IAAGS,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAIlB,IAAE,KAAKmZ,QAAL,CAAcjY,CAAd,CAAN,CAAuB,IAAGlB,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAII,IAAEJ,EAAEgC,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG,CAAC5B,EAAEW,MAAF,GAAS,CAAV,KAAc,CAAjB,EAAmB;AAAC,WAAOX,CAAP;AAAS,GAA7B,MAAiC;AAAC,WAAM,MAAIA,CAAV;AAAY;AAAC,QAAOC,SAAP,CAAiB8Y,QAAjB,GAA0BF,WAA1B,CAAsCP,OAAOrY,SAAP,CAAiBgZ,SAAjB,GAA2BP,YAA3B,CAAwCJ,OAAOrY,SAAP,CAAiBiZ,OAAjB,GAAyBJ,UAAzB,CAAoCR,OAAOrY,SAAP,CAAiBkZ,WAAjB,GAA6BH,cAA7B,CAA4CV,OAAOrY,SAAP,CAAiBmZ,IAAjB,GAAsB,KAAtB;AAC3gF;;AAEA,SAASC,gBAAT,CAA0BhZ,CAA1B,EAA4BS,CAA5B,EAA8B;AAAC,OAAKsD,CAAL,GAAOtD,CAAP,CAAS,KAAKsB,CAAL,GAAO/B,CAAP;AAAS,UAASiZ,UAAT,CAAoBxY,CAApB,EAAsB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,UAAO,KAAKsB,CAAL,CAAO8S,MAAP,CAAcpU,EAAEsB,CAAhB,KAAoB,KAAKgC,CAAL,CAAO8Q,MAAP,CAAcpU,EAAEsD,CAAhB,CAA3B;AAA+C,UAASmV,gBAAT,GAA2B;AAAC,SAAO,KAAKnV,CAAZ;AAAc,UAASoV,UAAT,GAAqB;AAAC,SAAO,IAAIH,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOoH,MAAP,GAAgB2B,GAAhB,CAAoB,KAAK/K,CAAzB,CAA5B,CAAP;AAAgE,UAASqX,OAAT,CAAiB3Y,CAAjB,EAAmB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOkQ,GAAP,CAAWxT,EAAE4Y,YAAF,EAAX,EAA6BvM,GAA7B,CAAiC,KAAK/K,CAAtC,CAA5B,CAAP;AAA6E,UAASuX,YAAT,CAAsB7Y,CAAtB,EAAwB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOiQ,QAAP,CAAgBvT,EAAE4Y,YAAF,EAAhB,EAAkCvM,GAAlC,CAAsC,KAAK/K,CAA3C,CAA5B,CAAP;AAAkF,UAASwX,YAAT,CAAsB9Y,CAAtB,EAAwB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOwR,QAAP,CAAgB9U,EAAE4Y,YAAF,EAAhB,EAAkCvM,GAAlC,CAAsC,KAAK/K,CAA3C,CAA5B,CAAP;AAAkF,UAASyX,UAAT,GAAqB;AAAC,SAAO,IAAIR,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAO6R,MAAP,GAAgB9I,GAAhB,CAAoB,KAAK/K,CAAzB,CAA5B,CAAP;AAAgE,UAAS0X,UAAT,CAAoBhZ,CAApB,EAAsB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOwR,QAAP,CAAgB9U,EAAE4Y,YAAF,GAAiB3D,UAAjB,CAA4B,KAAK3T,CAAjC,CAAhB,EAAqD+K,GAArD,CAAyD,KAAK/K,CAA9D,CAA5B,CAAP;AAAqG,kBAAiBnC,SAAjB,CAA2BiV,MAA3B,GAAkCoE,UAAlC,CAA6CD,iBAAiBpZ,SAAjB,CAA2ByZ,YAA3B,GAAwCH,gBAAxC,CAAyDF,iBAAiBpZ,SAAjB,CAA2BuL,MAA3B,GAAkCgO,UAAlC,CAA6CH,iBAAiBpZ,SAAjB,CAA2BqU,GAA3B,GAA+BmF,OAA/B,CAAuCJ,iBAAiBpZ,SAAjB,CAA2BoU,QAA3B,GAAoCsF,YAApC,CAAiDN,iBAAiBpZ,SAAjB,CAA2B2V,QAA3B,GAAoCgE,YAApC,CAAiDP,iBAAiBpZ,SAAjB,CAA2BgW,MAA3B,GAAkC4D,UAAlC,CAA6CR,iBAAiBpZ,SAAjB,CAA2BuT,MAA3B,GAAkCsG,UAAlC,CAA6C,SAASC,SAAT,CAAmBxZ,CAAnB,EAAqBO,CAArB,EAAuBd,CAAvB,EAAyBK,CAAzB,EAA2B;AAAC,OAAK2Z,KAAL,GAAWzZ,CAAX,CAAa,KAAK6D,CAAL,GAAOtD,CAAP,CAAS,KAAKiH,CAAL,GAAO/H,CAAP,CAAS,IAAGK,KAAG,IAAN,EAAW;AAAC,SAAKwH,CAAL,GAAO4B,WAAWmD,GAAlB;AAAsB,GAAlC,MAAsC;AAAC,SAAK/E,CAAL,GAAOxH,CAAP;AAAS,QAAK4Z,IAAL,GAAU,IAAV;AAAe,UAASC,WAAT,GAAsB;AAAC,MAAG,KAAKD,IAAL,IAAW,IAAd,EAAmB;AAAC,SAAKA,IAAL,GAAU,KAAKpS,CAAL,CAAOkO,UAAP,CAAkB,KAAKiE,KAAL,CAAW5X,CAA7B,CAAV;AAA0C,UAAO,KAAK4X,KAAL,CAAWG,cAAX,CAA0B,KAAK/V,CAAL,CAAOsV,YAAP,GAAsB9D,QAAtB,CAA+B,KAAKqE,IAApC,EAA0C9M,GAA1C,CAA8C,KAAK6M,KAAL,CAAW5X,CAAzD,CAA1B,CAAP;AAA8F,UAASgY,WAAT,GAAsB;AAAC,MAAG,KAAKH,IAAL,IAAW,IAAd,EAAmB;AAAC,SAAKA,IAAL,GAAU,KAAKpS,CAAL,CAAOkO,UAAP,CAAkB,KAAKiE,KAAL,CAAW5X,CAA7B,CAAV;AAA0C,UAAO,KAAK4X,KAAL,CAAWG,cAAX,CAA0B,KAAKpS,CAAL,CAAO2R,YAAP,GAAsB9D,QAAtB,CAA+B,KAAKqE,IAApC,EAA0C9M,GAA1C,CAA8C,KAAK6M,KAAL,CAAW5X,CAAzD,CAA1B,CAAP;AAA8F,UAASiY,aAAT,CAAuBvZ,CAAvB,EAAyB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKwZ,UAAL,EAAH,EAAqB;AAAC,WAAOxZ,EAAEwZ,UAAF,EAAP;AAAsB,OAAGxZ,EAAEwZ,UAAF,EAAH,EAAkB;AAAC,WAAO,KAAKA,UAAL,EAAP;AAAyB,OAAI/Z,CAAJ,EAAMF,CAAN,CAAQE,IAAEO,EAAEiH,CAAF,CAAI2R,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKtM,CAAL,CAAO2R,YAAP,GAAsB9D,QAAtB,CAA+B9U,EAAE+G,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAF,CAAsG,IAAG,CAAC7B,EAAE2U,MAAF,CAASzL,WAAW2B,IAApB,CAAJ,EAA8B;AAAC,WAAO,KAAP;AAAa,OAAEtK,EAAEsD,CAAF,CAAIsV,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKjQ,CAAL,CAAOsV,YAAP,GAAsB9D,QAAtB,CAA+B9U,EAAE+G,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAF,CAAsG,OAAO/B,EAAE6U,MAAF,CAASzL,WAAW2B,IAApB,CAAP;AAAiC,UAASmP,iBAAT,GAA4B;AAAC,MAAI,KAAKnW,CAAL,IAAQ,IAAT,IAAiB,KAAK2D,CAAL,IAAQ,IAA5B,EAAkC;AAAC,WAAO,IAAP;AAAY,UAAO,KAAKF,CAAL,CAAOqN,MAAP,CAAczL,WAAW2B,IAAzB,KAAgC,CAAC,KAAKrD,CAAL,CAAO2R,YAAP,GAAsBxE,MAAtB,CAA6BzL,WAAW2B,IAAxC,CAAxC;AAAsF,UAASoP,aAAT,GAAwB;AAAC,SAAO,IAAIT,SAAJ,CAAc,KAAKC,KAAnB,EAAyB,KAAK5V,CAA9B,EAAgC,KAAK2D,CAAL,CAAOyD,MAAP,EAAhC,EAAgD,KAAK3D,CAArD,CAAP;AAA+D,UAAS4S,UAAT,CAAoB7Z,CAApB,EAAsB;AAAC,MAAG,KAAK0Z,UAAL,EAAH,EAAqB;AAAC,WAAO1Z,CAAP;AAAS,OAAGA,EAAE0Z,UAAF,EAAH,EAAkB;AAAC,WAAO,IAAP;AAAY,OAAInZ,IAAEP,EAAEmH,CAAF,CAAI2R,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKtM,CAAL,CAAO2R,YAAP,GAAsB9D,QAAtB,CAA+BhV,EAAEiH,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAN,CAA0G,IAAIhB,IAAER,EAAEwD,CAAF,CAAIsV,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKjQ,CAAL,CAAOsV,YAAP,GAAsB9D,QAAtB,CAA+BhV,EAAEiH,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAN,CAA0G,IAAGqH,WAAW2B,IAAX,CAAgB8J,MAAhB,CAAuB9T,CAAvB,CAAH,EAA6B;AAAC,QAAGqI,WAAW2B,IAAX,CAAgB8J,MAAhB,CAAuB/T,CAAvB,CAAH,EAA6B;AAAC,aAAO,KAAKuZ,KAAL,EAAP;AAAoB,YAAO,KAAKV,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAIla,IAAE,IAAIgJ,UAAJ,CAAe,GAAf,CAAN,CAA0B,IAAInJ,IAAE,KAAK8D,CAAL,CAAOsV,YAAP,EAAN,CAA4B,IAAIxY,IAAE,KAAK6G,CAAL,CAAO2R,YAAP,EAAN,CAA4B,IAAInZ,IAAEK,EAAEwD,CAAF,CAAIsV,YAAJ,EAAN,CAAyB,IAAI7Y,IAAED,EAAEmH,CAAF,CAAI2R,YAAJ,EAAN,CAAyB,IAAI7W,IAAEzB,EAAE6U,MAAF,EAAN,CAAiB,IAAIvV,IAAEmC,EAAE+S,QAAF,CAAWxU,CAAX,CAAN,CAAoB,IAAIpB,IAAEM,EAAEsV,QAAF,CAAW/S,CAAX,CAAN,CAAoB,IAAIjD,IAAEuB,EAAE8U,MAAF,GAAWL,QAAX,CAAoB,KAAK/N,CAAzB,CAAN,CAAkC,IAAI/G,IAAElB,EAAEyU,QAAF,CAAWrU,EAAEqQ,SAAF,CAAY,CAAZ,CAAX,EAA2BuF,QAA3B,CAAoChV,EAAEiH,CAAtC,EAAyCwM,QAAzC,CAAkD3T,CAAlD,EAAqDkV,QAArD,CAA8DxU,CAA9D,EAAiE+L,GAAjE,CAAqE,KAAK6M,KAAL,CAAW5X,CAAhF,CAAN,CAAyF,IAAIvC,IAAEG,EAAE4V,QAAF,CAAWnV,CAAX,EAAcmV,QAAd,CAAuBzU,CAAvB,EAA0BkT,QAA1B,CAAmCnT,EAAE0U,QAAF,CAAWlV,CAAX,CAAnC,EAAkD2T,QAAlD,CAA2DzU,EAAEgW,QAAF,CAAWzU,CAAX,CAA3D,EAA0EyU,QAA1E,CAAmFhV,EAAEiH,CAArF,EAAwFyM,GAAxF,CAA4FnT,EAAEyU,QAAF,CAAWlV,CAAX,CAA5F,EAA2GyM,GAA3G,CAA+G,KAAK6M,KAAL,CAAW5X,CAA1H,CAAN,CAAmI,IAAItC,IAAEY,EAAEkV,QAAF,CAAW,KAAK/N,CAAhB,EAAmB+N,QAAnB,CAA4BhV,EAAEiH,CAA9B,EAAiCsF,GAAjC,CAAqC,KAAK6M,KAAL,CAAW5X,CAAhD,CAAN,CAAyD,OAAO,IAAI2X,SAAJ,CAAc,KAAKC,KAAnB,EAAyB,KAAKA,KAAL,CAAWG,cAAX,CAA0BrZ,CAA1B,CAAzB,EAAsD,KAAKkZ,KAAL,CAAWG,cAAX,CAA0Bta,CAA1B,CAAtD,EAAmFC,CAAnF,CAAP;AAA6F,UAAS8a,YAAT,GAAuB;AAAC,MAAG,KAAKN,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKvS,CAAL,CAAO2R,YAAP,GAAsB9J,MAAtB,MAAgC,CAAnC,EAAqC;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAE,IAAI6J,UAAJ,CAAe,GAAf,CAAN,CAA0B,IAAIlJ,IAAE,KAAK6D,CAAL,CAAOsV,YAAP,EAAN,CAA4B,IAAI7Z,IAAE,KAAKkI,CAAL,CAAO2R,YAAP,EAAN,CAA4B,IAAIpZ,IAAET,EAAE+V,QAAF,CAAW,KAAK/N,CAAhB,CAAN,CAAyB,IAAIpH,IAAEH,EAAEsV,QAAF,CAAW/V,CAAX,EAAcsN,GAAd,CAAkB,KAAK6M,KAAL,CAAW5X,CAA7B,CAAN,CAAsC,IAAI1B,IAAE,KAAKsZ,KAAL,CAAWlZ,CAAX,CAAa4Y,YAAb,EAAN,CAAkC,IAAI7Y,IAAEN,EAAE0V,MAAF,GAAWL,QAAX,CAAoBhW,CAApB,CAAN,CAA6B,IAAG,CAAC6J,WAAW2B,IAAX,CAAgB8J,MAAhB,CAAuBxU,CAAvB,CAAJ,EAA8B;AAACG,QAAEA,EAAEyT,GAAF,CAAM,KAAKzM,CAAL,CAAOoO,MAAP,GAAgBL,QAAhB,CAAyBlV,CAAzB,CAAN,CAAF;AAAqC,OAAEG,EAAEsM,GAAF,CAAM,KAAK6M,KAAL,CAAW5X,CAAjB,CAAF,CAAsB,IAAI/B,IAAEQ,EAAEoV,MAAF,GAAW5B,QAAX,CAAoB9T,EAAE8P,SAAF,CAAY,CAAZ,EAAeuF,QAAf,CAAwBnV,CAAxB,CAApB,EAAgD4P,SAAhD,CAA0D,CAA1D,EAA6DuF,QAA7D,CAAsEtV,CAAtE,EAAyE6M,GAAzE,CAA6E,KAAK6M,KAAL,CAAW5X,CAAxF,CAAN,CAAiG,IAAItC,IAAEe,EAAE+U,QAAF,CAAWhW,CAAX,EAAcgW,QAAd,CAAuBrV,CAAvB,EAA0B8T,QAA1B,CAAmC5T,EAAE4P,SAAF,CAAY,CAAZ,CAAnC,EAAmDA,SAAnD,CAA6D,CAA7D,EAAgEuF,QAAhE,CAAyEnV,CAAzE,EAA4E4T,QAA5E,CAAqFxT,EAAEoV,MAAF,GAAWL,QAAX,CAAoB/U,CAApB,CAArF,EAA6GsM,GAA7G,CAAiH,KAAK6M,KAAL,CAAW5X,CAA5H,CAAN,CAAqI,IAAIpC,IAAEM,EAAE2V,MAAF,GAAWL,QAAX,CAAoBtV,CAApB,EAAuB+P,SAAvB,CAAiC,CAAjC,EAAoClD,GAApC,CAAwC,KAAK6M,KAAL,CAAW5X,CAAnD,CAAN,CAA4D,OAAO,IAAI2X,SAAJ,CAAc,KAAKC,KAAnB,EAAyB,KAAKA,KAAL,CAAWG,cAAX,CAA0B9Z,CAA1B,CAAzB,EAAsD,KAAK2Z,KAAL,CAAWG,cAAX,CAA0Bra,CAA1B,CAAtD,EAAmFE,CAAnF,CAAP;AAA6F,UAAS6a,eAAT,CAAyBxa,CAAzB,EAA2B;AAAC,MAAG,KAAKia,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAGja,EAAEuP,MAAF,MAAY,CAAf,EAAiB;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAES,CAAN,CAAQ,IAAIP,IAAEF,EAAEgW,QAAF,CAAW,IAAInM,UAAJ,CAAe,GAAf,CAAX,CAAN,CAAsC,IAAI7I,IAAE,KAAK4K,MAAL,EAAN,CAAoB,IAAIxL,IAAE,IAAN,CAAW,IAAIO,CAAJ,CAAM,KAAIA,IAAET,EAAEmP,SAAF,KAAc,CAApB,EAAsB1O,IAAE,CAAxB,EAA0B,EAAEA,CAA5B,EAA8B;AAACP,QAAEA,EAAE0a,KAAF,EAAF,CAAY,IAAI5Z,IAAEhB,EAAEqQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAIE,IAAEb,EAAEuQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAGO,KAAGL,CAAN,EAAQ;AAACT,UAAEA,EAAEsU,GAAF,CAAMxT,IAAE,IAAF,GAAOF,CAAb,CAAF;AAAkB;AAAC,UAAOZ,CAAP;AAAS,UAAS8a,kBAAT,CAA4Bva,CAA5B,EAA8BO,CAA9B,EAAgCT,CAAhC,EAAkC;AAAC,MAAIL,CAAJ,CAAM,IAAGO,EAAE0O,SAAF,KAAc5O,EAAE4O,SAAF,EAAjB,EAA+B;AAACjP,QAAEO,EAAE0O,SAAF,KAAc,CAAhB;AAAkB,GAAlD,MAAsD;AAACjP,QAAEK,EAAE4O,SAAF,KAAc,CAAhB;AAAkB,OAAInP,IAAE,KAAKka,KAAL,CAAWW,WAAX,EAAN,CAA+B,IAAIra,IAAE,KAAKgU,GAAL,CAASxT,CAAT,CAAN,CAAkB,OAAMd,KAAG,CAAT,EAAW;AAACF,QAAEA,EAAE4a,KAAF,EAAF,CAAY,IAAGna,EAAE4P,OAAF,CAAUnQ,CAAV,CAAH,EAAgB;AAAC,UAAGK,EAAE8P,OAAF,CAAUnQ,CAAV,CAAH,EAAgB;AAACF,YAAEA,EAAEwU,GAAF,CAAMhU,CAAN,CAAF;AAAW,OAA5B,MAAgC;AAACR,YAAEA,EAAEwU,GAAF,CAAM,IAAN,CAAF;AAAc;AAAC,KAAjE,MAAqE;AAAC,UAAGjU,EAAE8P,OAAF,CAAUnQ,CAAV,CAAH,EAAgB;AAACF,YAAEA,EAAEwU,GAAF,CAAMxT,CAAN,CAAF;AAAW;AAAC,OAAEd,CAAF;AAAI,UAAOF,CAAP;AAAS,WAAUG,SAAV,CAAoB8a,IAApB,GAAyBb,WAAzB,CAAqCH,UAAU9Z,SAAV,CAAoB+a,IAApB,GAAyBZ,WAAzB,CAAqCL,UAAU9Z,SAAV,CAAoBiV,MAApB,GAA2BmF,aAA3B,CAAyCN,UAAU9Z,SAAV,CAAoBqa,UAApB,GAA+BC,iBAA/B,CAAiDR,UAAU9Z,SAAV,CAAoBuL,MAApB,GAA2BgP,aAA3B,CAAyCT,UAAU9Z,SAAV,CAAoBqU,GAApB,GAAwBmG,UAAxB,CAAmCV,UAAU9Z,SAAV,CAAoBya,KAApB,GAA0BE,YAA1B,CAAuCb,UAAU9Z,SAAV,CAAoB2V,QAApB,GAA6BiF,eAA7B,CAA6Cd,UAAU9Z,SAAV,CAAoBgb,WAApB,GAAgCH,kBAAhC,CAAmD,SAASI,SAAT,CAAmB5a,CAAnB,EAAqBN,CAArB,EAAuBO,CAAvB,EAAyB;AAAC,OAAK6B,CAAL,GAAO9B,CAAP,CAAS,KAAKQ,CAAL,GAAO,KAAKqZ,cAAL,CAAoBna,CAApB,CAAP,CAA8B,KAAKK,CAAL,GAAO,KAAK8Z,cAAL,CAAoB5Z,CAApB,CAAP,CAA8B,KAAK4a,QAAL,GAAc,IAAIpB,SAAJ,CAAc,IAAd,EAAmB,IAAnB,EAAwB,IAAxB,CAAd;AAA4C,UAASqB,WAAT,GAAsB;AAAC,SAAO,KAAKhZ,CAAZ;AAAc,UAASiZ,WAAT,GAAsB;AAAC,SAAO,KAAKva,CAAZ;AAAc,UAASwa,WAAT,GAAsB;AAAC,SAAO,KAAKjb,CAAZ;AAAc,UAASkb,aAAT,CAAuBza,CAAvB,EAAyB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,UAAO,KAAKsB,CAAL,CAAO8S,MAAP,CAAcpU,EAAEsB,CAAhB,KAAoB,KAAKtB,CAAL,CAAOoU,MAAP,CAAcpU,EAAEA,CAAhB,CAApB,IAAwC,KAAKT,CAAL,CAAO6U,MAAP,CAAcpU,EAAET,CAAhB,CAA/C;AAAmE,UAASmb,kBAAT,GAA6B;AAAC,SAAO,KAAKL,QAAZ;AAAqB,UAASM,qBAAT,CAA+B3a,CAA/B,EAAiC;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4BtB,CAA5B,CAAP;AAAsC,UAAS4a,qBAAT,CAA+B1b,CAA/B,EAAiC;AAAC,UAAOkD,SAASlD,EAAEmD,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAP,GAAmC,KAAK,CAAL;AAAO,aAAO,KAAKgY,QAAZ,CAAqB,KAAK,CAAL,CAAO,KAAK,CAAL;AAAO,aAAO,IAAP,CAAY,KAAK,CAAL,CAAO,KAAK,CAAL,CAAO,KAAK,CAAL;AAAO,UAAIra,IAAE,CAACd,EAAEW,MAAF,GAAS,CAAV,IAAa,CAAnB,CAAqB,IAAIJ,IAAEP,EAAEmD,MAAF,CAAS,CAAT,EAAWrC,CAAX,CAAN,CAAoB,IAAIT,IAAEL,EAAEmD,MAAF,CAASrC,IAAE,CAAX,EAAaA,CAAb,CAAN,CAAsB,OAAO,IAAIiZ,SAAJ,CAAc,IAAd,EAAmB,KAAKI,cAAL,CAAoB,IAAI1Q,UAAJ,CAAelJ,CAAf,EAAiB,EAAjB,CAApB,CAAnB,EAA6D,KAAK4Z,cAAL,CAAoB,IAAI1Q,UAAJ,CAAepJ,CAAf,EAAiB,EAAjB,CAApB,CAA7D,CAAP,CAA+G;AAAQ,aAAO,IAAP,CAApS;AAAiT,WAAUJ,SAAV,CAAoB0b,IAApB,GAAyBP,WAAzB,CAAqCF,UAAUjb,SAAV,CAAoB2b,IAApB,GAAyBP,WAAzB,CAAqCH,UAAUjb,SAAV,CAAoB4b,IAApB,GAAyBP,WAAzB,CAAqCJ,UAAUjb,SAAV,CAAoBiV,MAApB,GAA2BqG,aAA3B,CAAyCL,UAAUjb,SAAV,CAAoB0a,WAApB,GAAgCa,kBAAhC,CAAmDN,UAAUjb,SAAV,CAAoBka,cAApB,GAAmCsB,qBAAnC,CAAyDP,UAAUjb,SAAV,CAAoB6b,cAApB,GAAmCJ,qBAAnC;AAClkM;;AAEArC,iBAAiBpZ,SAAjB,CAA2B8b,aAA3B,GAAyC,YAAU;AAAC,SAAOxW,KAAKc,KAAL,CAAW,CAAC,KAAKqT,YAAL,GAAoBzK,SAApB,KAAgC,CAAjC,IAAoC,CAA/C,CAAP;AAAyD,CAA7G,CAA8G8K,UAAU9Z,SAAV,CAAoB+b,UAApB,GAA+B,UAASzb,CAAT,EAAW;AAAC,MAAIP,IAAE,SAAFA,CAAE,CAASH,CAAT,EAAWC,CAAX,EAAa;AAAC,QAAIF,IAAEC,EAAEoc,mBAAF,EAAN,CAA8B,IAAGnc,IAAEF,EAAEe,MAAP,EAAc;AAACf,UAAEA,EAAE8C,KAAF,CAAQ9C,EAAEe,MAAF,GAASb,CAAjB,CAAF;AAAsB,KAArC,MAAyC;AAAC,aAAMA,IAAEF,EAAEe,MAAV,EAAiB;AAACf,UAAEsc,OAAF,CAAU,CAAV;AAAa;AAAC,YAAOtc,CAAP;AAAS,GAArI,CAAsI,IAAIkB,IAAE,KAAKia,IAAL,GAAYrB,YAAZ,EAAN,CAAiC,IAAIpZ,IAAE,KAAK0a,IAAL,GAAYtB,YAAZ,EAAN,CAAiC,IAAIrZ,IAAEL,EAAEc,CAAF,EAAI,EAAJ,CAAN,CAAc,IAAGP,CAAH,EAAK;AAAC,QAAGD,EAAEyO,MAAF,EAAH,EAAc;AAAC1O,QAAE6b,OAAF,CAAU,CAAV;AAAa,KAA5B,MAAgC;AAAC7b,QAAE6b,OAAF,CAAU,CAAV;AAAa;AAAC,GAArD,MAAyD;AAAC7b,MAAE6b,OAAF,CAAU,CAAV,EAAa7b,IAAEA,EAAE6B,MAAF,CAASlC,EAAEM,CAAF,EAAI,EAAJ,CAAT,CAAF;AAAoB,UAAOD,CAAP;AAAS,CAArW,CAAsW0Z,UAAUoC,UAAV,GAAqB,UAASvc,CAAT,EAAWW,CAAX,EAAa;AAAC,MAAIT,IAAES,EAAE,CAAF,CAAN,CAAW,IAAID,IAAEC,EAAEI,MAAF,GAAS,CAAf,CAAiB,IAAIX,IAAEO,EAAEmC,KAAF,CAAQ,CAAR,EAAU,IAAEpC,IAAE,CAAd,CAAN,CAAuB,IAAID,IAAEE,EAAEmC,KAAF,CAAQ,IAAEpC,IAAE,CAAZ,EAAc,IAAEA,CAAhB,CAAN,CAAyBN,EAAEkc,OAAF,CAAU,CAAV,EAAa7b,EAAE6b,OAAF,CAAU,CAAV,EAAa,IAAIpb,IAAE,IAAI2I,UAAJ,CAAezJ,CAAf,CAAN,CAAwB,IAAIH,IAAE,IAAI4J,UAAJ,CAAepJ,CAAf,CAAN,CAAwB,OAAO,IAAI0Z,SAAJ,CAAcna,CAAd,EAAgBA,EAAEua,cAAF,CAAiBrZ,CAAjB,CAAhB,EAAoClB,EAAEua,cAAF,CAAiBta,CAAjB,CAApC,CAAP;AAAgE,CAAzP,CAA0Pka,UAAUqC,aAAV,GAAwB,UAASxc,CAAT,EAAWW,CAAX,EAAa;AAAC,MAAIT,IAAES,EAAE4C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAI7C,IAAEC,EAAEI,MAAF,GAAS,CAAf,CAAiB,IAAIX,IAAEO,EAAE4C,MAAF,CAAS,CAAT,EAAW7C,IAAE,CAAb,CAAN,CAAsB,IAAID,IAAEE,EAAE4C,MAAF,CAAS,IAAE7C,IAAE,CAAb,EAAeA,IAAE,CAAjB,CAAN,CAA0B,IAAIQ,IAAE,IAAI2I,UAAJ,CAAezJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIH,IAAE,IAAI4J,UAAJ,CAAepJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,OAAO,IAAI0Z,SAAJ,CAAcna,CAAd,EAAgBA,EAAEua,cAAF,CAAiBrZ,CAAjB,CAAhB,EAAoClB,EAAEua,cAAF,CAAiBta,CAAjB,CAApC,CAAP;AAAgE,CAAjP,CAAkPka,UAAU9Z,SAAV,CAAoBoc,KAApB,GAA0B,UAAS9b,CAAT,EAAW;AAAC,MAAG,KAAK+Z,UAAL,EAAH,EAAqB;AAAC,WAAO/Z,CAAP;AAAS,OAAGA,EAAE+Z,UAAF,EAAH,EAAkB;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKlW,CAAL,CAAO8Q,MAAP,CAAc3U,EAAE6D,CAAhB,CAAH,EAAsB;AAAC,QAAG,KAAK2D,CAAL,CAAOmN,MAAP,CAAc3U,EAAEwH,CAAhB,CAAH,EAAsB;AAAC,aAAO,KAAK2S,KAAL,EAAP;AAAoB,YAAO,KAAKV,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAEW,EAAE6D,CAAF,CAAIiQ,QAAJ,CAAa,KAAKjQ,CAAlB,CAAN,CAA2B,IAAI9D,IAAEC,EAAEwH,CAAF,CAAIsM,QAAJ,CAAa,KAAKtM,CAAlB,CAAN,CAA2B,IAAIjH,IAAER,EAAEkT,MAAF,CAAS5T,CAAT,CAAN,CAAkB,IAAII,IAAEc,EAAEmV,MAAF,GAAW5B,QAAX,CAAoB,KAAKjQ,CAAzB,EAA4BiQ,QAA5B,CAAqC9T,EAAE6D,CAAvC,CAAN,CAAgD,IAAItE,IAAEgB,EAAE8U,QAAF,CAAW,KAAKxR,CAAL,CAAOiQ,QAAP,CAAgBrU,CAAhB,CAAX,EAA+BqU,QAA/B,CAAwC,KAAKtM,CAA7C,CAAN,CAAsD,OAAO,IAAIgS,SAAJ,CAAc,KAAKC,KAAnB,EAAyBha,CAAzB,EAA2BF,CAA3B,CAAP;AAAqC,CAAzZ,CAA0Zia,UAAU9Z,SAAV,CAAoBqc,OAApB,GAA4B,YAAU;AAAC,MAAG,KAAKhC,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKvS,CAAL,CAAO2R,YAAP,GAAsB9J,MAAtB,MAAgC,CAAnC,EAAqC;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAIta,IAAE,KAAK2Z,KAAL,CAAWG,cAAX,CAA0B1Q,WAAW8S,OAAX,CAAmB,CAAnB,CAA1B,CAAN,CAAuD,IAAIjc,IAAE,KAAK0Z,KAAL,CAAWG,cAAX,CAA0B1Q,WAAW8S,OAAX,CAAmB,CAAnB,CAA1B,CAAN,CAAuD,IAAIzb,IAAE,KAAKsD,CAAL,CAAO6R,MAAP,GAAgBL,QAAhB,CAAyBtV,CAAzB,EAA4BgU,GAA5B,CAAgC,KAAK0F,KAAL,CAAWlZ,CAA3C,EAA8C0S,MAA9C,CAAqD,KAAKzL,CAAL,CAAO6N,QAAP,CAAgBvV,CAAhB,CAArD,CAAN,CAA+E,IAAIE,IAAEO,EAAEmV,MAAF,GAAW5B,QAAX,CAAoB,KAAKjQ,CAAL,CAAOwR,QAAP,CAAgBvV,CAAhB,CAApB,CAAN,CAA8C,IAAIL,IAAEc,EAAE8U,QAAF,CAAW,KAAKxR,CAAL,CAAOiQ,QAAP,CAAgB9T,CAAhB,CAAX,EAA+B8T,QAA/B,CAAwC,KAAKtM,CAA7C,CAAN,CAAsD,OAAO,IAAIgS,SAAJ,CAAc,KAAKC,KAAnB,EAAyBzZ,CAAzB,EAA2BP,CAA3B,CAAP;AAAqC,CAArd,CAAsd+Z,UAAU9Z,SAAV,CAAoBuc,UAApB,GAA+B,UAASnc,CAAT,EAAW;AAAC,MAAG,KAAKia,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAGja,EAAEuP,MAAF,MAAY,CAAf,EAAiB;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAES,CAAN,CAAQ,IAAIP,IAAEF,EAAEgW,QAAF,CAAW,IAAInM,UAAJ,CAAe,GAAf,CAAX,CAAN,CAAsC,IAAI7I,IAAE,KAAK4K,MAAL,EAAN,CAAoB,IAAIxL,IAAE,IAAN,CAAW,IAAIO,CAAJ,CAAM,KAAIA,IAAET,EAAEmP,SAAF,KAAc,CAApB,EAAsB1O,IAAE,CAAxB,EAA0B,EAAEA,CAA5B,EAA8B;AAACP,QAAEA,EAAE0a,KAAF,EAAF,CAAY,IAAI5Z,IAAEhB,EAAEqQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAIE,IAAEb,EAAEuQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAGO,KAAGL,CAAN,EAAQ;AAACT,UAAEA,EAAEqc,KAAF,CAAQvb,IAAE,IAAF,GAAOF,CAAf,CAAF;AAAoB;AAAC,UAAOZ,CAAP;AAAS,CAA1U,CAA2U+Z,UAAU9Z,SAAV,CAAoBwc,SAApB,GAA8B,YAAU;AAAC,MAAIzc,IAAE,KAAK+a,IAAL,GAAYrB,YAAZ,EAAN,CAAiC,IAAIhZ,IAAE,KAAKsa,IAAL,GAAYtB,YAAZ,EAAN,CAAiC,IAAI5Z,IAAE,KAAKka,KAAL,CAAW4B,IAAX,GAAkBlC,YAAlB,EAAN,CAAuC,IAAInZ,IAAE,KAAKyZ,KAAL,CAAW6B,IAAX,GAAkBnC,YAAlB,EAAN,CAAuC,IAAI7Z,IAAE,KAAKma,KAAL,CAAW2B,IAAX,EAAN,CAAwB,IAAIrb,IAAEI,EAAEkV,QAAF,CAAWlV,CAAX,EAAcyM,GAAd,CAAkBtN,CAAlB,CAAN,CAA2B,IAAID,IAAEI,EAAE4V,QAAF,CAAW5V,CAAX,EAAc4V,QAAd,CAAuB5V,CAAvB,EAA0BsU,GAA1B,CAA8BxU,EAAE8V,QAAF,CAAW5V,CAAX,CAA9B,EAA6CsU,GAA7C,CAAiD/T,CAAjD,EAAoD4M,GAApD,CAAwDtN,CAAxD,CAAN,CAAiE,OAAOS,EAAE4U,MAAF,CAAStV,CAAT,CAAP;AAAmB,CAAhU,CAAiUma,UAAU9Z,SAAV,CAAoB2B,QAApB,GAA6B,YAAU;AAAC,SAAM,MAAI,KAAKmZ,IAAL,GAAYrB,YAAZ,GAA2B9X,QAA3B,EAAJ,GAA0C,GAA1C,GAA8C,KAAKoZ,IAAL,GAAYtB,YAAZ,GAA2B9X,QAA3B,EAA9C,GAAoF,GAA1F;AAA8F,CAAtI,CAAuImY,UAAU9Z,SAAV,CAAoByc,QAApB,GAA6B,YAAU;AAAC,MAAInc,IAAE,KAAKyZ,KAAL,CAAW2B,IAAX,EAAN,CAAwB,IAAG,KAAKrB,UAAL,EAAH,EAAqB;AAAC,UAAM,IAAIva,KAAJ,CAAU,uBAAV,CAAN;AAAyC,OAAIe,IAAE,KAAKia,IAAL,GAAYrB,YAAZ,EAAN,CAAiC,IAAIrZ,IAAE,KAAK2a,IAAL,GAAYtB,YAAZ,EAAN,CAAiC,IAAG5Y,EAAE6L,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+B9L,EAAE6L,SAAF,CAAYpM,EAAE8T,QAAF,CAAW5K,WAAWmD,GAAtB,CAAZ,IAAwC,CAA1E,EAA4E;AAAC,UAAM,IAAI7M,KAAJ,CAAU,4BAAV,CAAN;AAA8C,OAAGM,EAAEsM,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+BvM,EAAEsM,SAAF,CAAYpM,EAAE8T,QAAF,CAAW5K,WAAWmD,GAAtB,CAAZ,IAAwC,CAA1E,EAA4E;AAAC,UAAM,IAAI7M,KAAJ,CAAU,4BAAV,CAAN;AAA8C,OAAG,CAAC,KAAK0c,SAAL,EAAJ,EAAqB;AAAC,UAAM,IAAI1c,KAAJ,CAAU,4BAAV,CAAN;AAA8C,OAAG,KAAK6V,QAAL,CAAcrV,CAAd,EAAiB+Z,UAAjB,EAAH,EAAiC;AAAC,UAAM,IAAIva,KAAJ,CAAU,sCAAV,CAAN;AAAwD,UAAO,IAAP;AAAY,CAAjmB;AACnkF;;AAEA,IAAI4c,YAAW,YAAU;AAAC,MAAIrc,IAAE,iEAAN,CAAwE,IAAIG,IAAE,wEAAN,CAA+E,IAAIC,IAAE,SAAOD,CAAP,GAAS,KAAf,CAAqB,IAAIT,IAAE,IAAI4c,MAAJ,CAAW,uCAAqCtc,CAArC,GAAuC,GAAvC,GAA2CI,CAA3C,GAA6C,GAAxD,EAA4D,GAA5D,CAAN,CAAuE,IAAIG,IAAE,IAAI+b,MAAJ,CAAW,wBAAX,EAAoC,GAApC,CAAN,CAA+C,IAAIhd,IAAE,EAAC,KAAI,GAAL,EAAS,KAAI,GAAb,EAAiB,MAAK,IAAtB,EAA2BS,GAAE,IAA7B,EAAkCP,GAAE,IAApC,EAAyCoB,GAAE,IAA3C,EAAgDqB,GAAE,IAAlD,EAAuDJ,GAAE,IAAzD,EAAN,CAAqE,SAAStC,CAAT,CAAWe,CAAX,EAAaiC,CAAb,EAAe3B,CAAf,EAAiB;AAAC,WAAO2B,IAAEjD,EAAEiD,CAAF,CAAF,GAAOQ,OAAOC,YAAP,CAAoBJ,SAAShC,CAAT,EAAW,EAAX,CAApB,CAAd;AAAkD,OAAIX,IAAE,IAAI8C,MAAJ,CAAW,EAAX,CAAN,CAAqB,IAAIvC,IAAE,IAAN,CAAW,IAAIhB,IAAE,EAAC,KAAIM,MAAL,EAAY,KAAIiJ,KAAhB,EAAN,CAA6B,IAAIhJ,IAAED,OAAOkB,cAAb,CAA4B,OAAO,UAASiD,CAAT,EAAWnC,CAAX,EAAa;AAAC,QAAIjB,IAAEoD,EAAEsY,KAAF,CAAQ7c,CAAR,CAAN,CAAiB,IAAIoE,CAAJ,CAAM,IAAIE,IAAEnD,EAAE,CAAF,CAAN,CAAW,IAAIP,IAAE,KAAN,CAAY,IAAG,QAAM0D,CAAT,EAAW;AAACF,UAAE,EAAF;AAAK,KAAjB,MAAqB;AAAC,UAAG,QAAME,CAAT,EAAW;AAACF,YAAE,EAAF;AAAK,OAAjB,MAAqB;AAACA,YAAE,EAAF,CAAKxD,IAAE,IAAF;AAAO;AAAC,SAAIuB,CAAJ,CAAM,IAAII,IAAE,CAAC6B,CAAD,CAAN,CAAU,KAAI,IAAIhD,IAAE,IAAER,CAAR,EAAUiC,IAAE1B,EAAER,MAAlB,EAAyBS,IAAEyB,CAA3B,EAA6B,EAAEzB,CAA/B,EAAiC;AAACkD,UAAEnD,EAAEC,CAAF,CAAF,CAAO,IAAI+C,CAAJ,CAAM,QAAOG,EAAEf,UAAF,CAAa,CAAb,CAAP,GAAwB;AAAQY,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,CAAE2D,CAAjB,CAAoBnC,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,EAAL;AAAQmC,cAAEA,EAAE2E,SAAF,CAAY,CAAZ,EAAc3E,EAAE3D,MAAF,GAAS,CAAvB,CAAF,CAA4B,IAAG2D,EAAE0B,OAAF,CAAUlF,CAAV,MAAe,CAAC,CAAnB,EAAqB;AAACwD,gBAAEA,EAAEwY,OAAF,CAAUjc,CAAV,EAAYhB,CAAZ,CAAF;AAAiB,eAAE0C,EAAE,CAAF,CAAF,CAAO,IAAG,CAACJ,CAAJ,EAAM;AAAC,gBAAGgC,aAAakF,KAAhB,EAAsB;AAAClH,kBAAEgC,EAAExD,MAAJ;AAAW,aAAlC,MAAsC;AAACwB,kBAAEmC,KAAG/D,CAAL,CAAO;AAAM;AAAC,aAAE4B,CAAF,IAAKmC,CAAL,CAAOnC,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,EAAL;AAAQgC,cAAE5B,EAAE,CAAF,CAAF,CAAOA,EAAE2Z,OAAF,CAAU/X,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,EAAzB,EAA6BwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,EAAL;AAAQI,YAAEwa,KAAF,GAAU,MAAM,KAAK,GAAL;AAAS5Y,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,KAAf,CAAqBwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASgC,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,IAAf,CAAoBwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASgC,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,IAAf,CAAoBwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASgC,cAAE5B,EAAE,CAAF,CAAF,CAAOA,EAAE2Z,OAAF,CAAU/X,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,EAAzB,EAA6BwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASI,YAAEwa,KAAF,GAAU,MAA1iB;AAAijB,SAAGnc,CAAH,EAAK;AAAC,UAAG2B,EAAE5B,MAAF,KAAW,CAAd,EAAgB;AAAC,cAAM,IAAIZ,KAAJ,EAAN;AAAkB,WAAEqE,EAAE,CAAF,CAAF;AAAO,KAAhD,MAAoD;AAAC,UAAG7B,EAAE5B,MAAL,EAAY;AAAC,cAAM,IAAIZ,KAAJ,EAAN;AAAkB;AAAC,SAAGqC,CAAH,EAAK;AAAC,UAAIC,IAAE,SAAFA,CAAE,CAAS8F,CAAT,EAAWF,CAAX,EAAa;AAAC,YAAII,IAAEF,EAAEF,CAAF,CAAN,CAAW,IAAGI,KAAG,QAAOA,CAAP,yCAAOA,CAAP,OAAW,QAAjB,EAA0B;AAAC,cAAInH,IAAE,IAAN,CAAW,KAAI,IAAI2G,CAAR,IAAaQ,CAAb,EAAe;AAAC,gBAAGhI,EAAEoC,IAAF,CAAO4F,CAAP,EAASR,CAAT,KAAaQ,MAAIF,CAApB,EAAsB;AAAC,kBAAIJ,IAAE1F,EAAEgG,CAAF,EAAIR,CAAJ,CAAN,CAAa,IAAGE,MAAI,KAAK,CAAZ,EAAc;AAACM,kBAAER,CAAF,IAAKE,CAAL;AAAO,eAAtB,MAA0B;AAAC,oBAAG,CAAC7G,CAAJ,EAAM;AAACA,sBAAE,EAAF;AAAK,mBAAE0B,IAAF,CAAOiF,CAAP;AAAU;AAAC;AAAC,eAAG3G,CAAH,EAAK;AAAC,iBAAI,IAAI4G,IAAE5G,EAAEP,MAAZ,EAAmB,EAAEmH,CAAF,IAAK,CAAxB,GAA2B;AAAC,qBAAOO,EAAEnH,EAAE4G,CAAF,CAAF,CAAP;AAAe;AAAC;AAAC,gBAAO1F,EAAEK,IAAF,CAAO0F,CAAP,EAASF,CAAT,EAAWI,CAAX,CAAP;AAAqB,OAApP,CAAqPjE,IAAE/B,EAAE,EAAC,IAAG+B,CAAJ,EAAF,EAAS,EAAT,CAAF;AAAe,YAAOA,CAAP;AAAS,GAAplC;AAAqlC,CAArmD,EAAd;AACA,IAAG,OAAO0T,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UA6E3BA,IA7E2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKkF,IAAZ,IAAkB,WAAlB,IAA+B,CAAClF,KAAKkF,IAAxC,EAA6C;AAAClF,OAAKkF,IAAL,GAAU,EAAV;AAAa,MAAKA,IAAL,CAAUC,QAAV,GAAmB,IAAI,YAAU;AAAC,OAAKC,gBAAL,GAAsB,UAASpc,CAAT,EAAW;AAAC,QAAIT,IAAES,EAAEc,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAIvB,EAAEM,MAAF,GAAS,CAAV,IAAc,CAAjB,EAAmB;AAACN,UAAE,MAAIA,CAAN;AAAQ,YAAOA,CAAP;AAAS,GAA5F,CAA6F,KAAK8c,6BAAL,GAAmC,UAAS1c,CAAT,EAAW;AAAC,QAAIX,IAAEW,EAAEmB,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG9B,EAAEqD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,GAAlB,EAAsB;AAAC,UAAGrD,EAAEa,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACb,YAAE,MAAIA,CAAN;AAAQ,OAA1B,MAA8B;AAAC,YAAG,CAACA,EAAE+c,KAAF,CAAQ,QAAR,CAAJ,EAAsB;AAAC/c,cAAE,OAAKA,CAAP;AAAS;AAAC;AAAC,KAAxF,MAA4F;AAAC,UAAIgB,IAAEhB,EAAEqD,MAAF,CAAS,CAAT,CAAN,CAAkB,IAAI7C,IAAEQ,EAAEH,MAAR,CAAe,IAAGL,IAAE,CAAF,IAAK,CAAR,EAAU;AAACA,aAAG,CAAH;AAAK,OAAhB,MAAoB;AAAC,YAAG,CAACR,EAAE+c,KAAF,CAAQ,QAAR,CAAJ,EAAsB;AAACvc,eAAG,CAAH;AAAK;AAAC,WAAIV,IAAE,EAAN,CAAS,KAAI,IAAII,IAAE,CAAV,EAAYA,IAAEM,CAAd,EAAgBN,GAAhB,EAAoB;AAACJ,aAAG,GAAH;AAAO,WAAIW,IAAE,IAAIkJ,UAAJ,CAAe7J,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIS,IAAEE,EAAE8U,GAAF,CAAM5U,CAAN,EAAS6T,GAAT,CAAa7K,WAAWmD,GAAxB,CAAN,CAAmC9M,IAAEO,EAAEuB,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,IAAvB,EAA4B,EAA5B,CAAF;AAAkC,YAAOhd,CAAP;AAAS,GAAlY,CAAmY,KAAKsd,mBAAL,GAAyB,UAAStc,CAAT,EAAWT,CAAX,EAAa;AAAC,WAAOgd,SAASvc,CAAT,EAAWT,CAAX,CAAP;AAAqB,GAA5D,CAA6D,KAAKid,SAAL,GAAe,UAASzc,CAAT,EAAW;AAAC,QAAIwH,IAAEyP,IAAN;AAAA,QAAW5W,IAAEmH,EAAE2U,IAAf;AAAA,QAAoBnV,IAAE3G,EAAEqc,UAAxB;AAAA,QAAmCjd,IAAEY,EAAEsc,UAAvC;AAAA,QAAkDnb,IAAEnB,EAAEuc,YAAtD;AAAA,QAAmE5d,IAAEqB,EAAEwc,cAAvE;AAAA,QAAsFpZ,IAAEpD,EAAEyc,OAA1F;AAAA,QAAkGxZ,IAAEjD,EAAE0c,mBAAtG;AAAA,QAA0Hhd,IAAEM,EAAE2c,aAA9H;AAAA,QAA4Ije,IAAEsB,EAAE4c,aAAhJ;AAAA,QAA8Jhe,IAAEoB,EAAE6c,gBAAlK;AAAA,QAAmLhW,IAAE7G,EAAE8c,kBAAvL;AAAA,QAA0MzZ,IAAErD,EAAE+c,gBAA9M;AAAA,QAA+N9c,IAAED,EAAEgd,YAAnO;AAAA,QAAgP/V,IAAEjH,EAAEid,UAApP;AAAA,QAA+P1d,IAAES,EAAEkd,kBAAnQ;AAAA,QAAsRvb,IAAE3B,EAAEmd,WAA1R;AAAA,QAAsS9d,IAAEW,EAAEod,MAA1S;AAAA,QAAiT/b,IAAErB,EAAEqd,eAArT;AAAA,QAAqUnd,IAAEF,EAAE+b,QAAF,CAAWK,SAAlV,CAA4V,IAAInb,IAAE/B,OAAOoe,IAAP,CAAY3d,CAAZ,CAAN,CAAqB,IAAGsB,EAAExB,MAAF,IAAU,CAAb,EAAe;AAAC,YAAK,iCAAL;AAAuC,SAAI+F,IAAEvE,EAAE,CAAF,CAAN,CAAW,IAAG,yGAAyG6D,OAAzG,CAAiH,MAAIU,CAAJ,GAAM,GAAvH,KAA6H,CAAC,CAAjI,EAAmI;AAAC,YAAK,oBAAkBA,CAAvB;AAAyB,SAAGA,KAAG,MAAN,EAAa;AAAC,aAAO,IAAImB,CAAJ,CAAMhH,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,KAAN,EAAY;AAAC,aAAO,IAAIpG,CAAJ,CAAMO,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAIrE,CAAJ,CAAMxB,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAI7G,CAAJ,CAAMgB,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,MAAN,EAAa;AAAC,aAAO,IAAIpC,CAAJ,CAAMzD,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,KAAN,EAAY;AAAC,aAAO,IAAIvC,CAAJ,CAAMtD,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,MAAN,EAAa;AAAC,aAAO,IAAI9F,CAAJ,CAAMC,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,SAAN,EAAgB;AAAC,aAAO,IAAI9G,CAAJ,CAAMiB,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAI5G,CAAJ,CAAMe,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAIqB,CAAJ,CAAMlH,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAInC,CAAJ,CAAM1D,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAIvF,CAAJ,CAAMN,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,SAAN,EAAgB;AAAC,aAAO,IAAIyB,CAAJ,CAAMtH,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,SAAN,EAAgB;AAAC,aAAO,IAAIjG,CAAJ,CAAMI,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,KAAN,EAAY;AAAC,UAAI1G,IAAEa,EAAE6F,CAAF,CAAN,CAAW,IAAI6B,IAAE,EAAN,CAAS,KAAI,IAAInE,IAAE,CAAV,EAAYA,IAAEpE,EAAEW,MAAhB,EAAuByD,GAAvB,EAA2B;AAAC,YAAI6D,IAAE7G,EAAEpB,EAAEoE,CAAF,CAAF,CAAN,CAAcmE,EAAE3F,IAAF,CAAOqF,CAAP;AAAU,cAAO,IAAIpF,CAAJ,CAAM,EAAC4b,OAAMlW,CAAP,EAAN,CAAP;AAAwB,SAAG7B,KAAG,KAAN,EAAY;AAAC,UAAI1G,IAAEa,EAAE6F,CAAF,CAAN,CAAW,IAAI6B,IAAE,EAAN,CAAS,KAAI,IAAInE,IAAE,CAAV,EAAYA,IAAEpE,EAAEW,MAAhB,EAAuByD,GAAvB,EAA2B;AAAC,YAAI6D,IAAE7G,EAAEpB,EAAEoE,CAAF,CAAF,CAAN,CAAcmE,EAAE3F,IAAF,CAAOqF,CAAP;AAAU,cAAO,IAAI1H,CAAJ,CAAM,EAACke,OAAMlW,CAAP,EAAN,CAAP;AAAwB,SAAG7B,KAAG,KAAN,EAAY;AAAC,UAAIoB,IAAEjH,EAAE6F,CAAF,CAAN,CAAW,IAAGtG,OAAOH,SAAP,CAAiB2B,QAAjB,CAA0Ba,IAA1B,CAA+BqF,CAA/B,MAAoC,gBAApC,IAAsDA,EAAEnH,MAAF,IAAU,CAAnE,EAAqE;AAAC,YAAIyB,IAAEhB,EAAE0G,EAAE,CAAF,CAAF,CAAN,CAAc,OAAO,IAAIvF,CAAJ,CAAM,EAACmc,KAAI5W,EAAE,CAAF,CAAL,EAAU6W,UAAS7W,EAAE,CAAF,CAAnB,EAAwB8W,KAAIxc,CAA5B,EAAN,CAAP;AAA6C,OAAjI,MAAqI;AAAC,YAAI/B,IAAE,EAAN,CAAS,IAAGyH,EAAE6W,QAAF,KAAalf,SAAhB,EAA0B;AAACY,YAAEse,QAAF,GAAW7W,EAAE6W,QAAb;AAAsB,aAAG7W,EAAE4W,GAAF,KAAQjf,SAAX,EAAqB;AAACY,YAAEqe,GAAF,GAAM5W,EAAE4W,GAAR;AAAY,aAAG5W,EAAE8W,GAAF,KAAQnf,SAAX,EAAqB;AAAC,gBAAK,mCAAL;AAAyC,WAAEmf,GAAF,GAAMxd,EAAE0G,EAAE8W,GAAJ,CAAN,CAAe,OAAO,IAAIrc,CAAJ,CAAMlC,CAAN,CAAP;AAAgB;AAAC;AAAC,GAAhoD,CAAioD,KAAKwe,aAAL,GAAmB,UAASxe,CAAT,EAAW;AAAC,QAAIS,IAAE,KAAKwc,SAAL,CAAejd,CAAf,CAAN,CAAwB,OAAOS,EAAEge,aAAF,EAAP;AAAyB,GAAhF;AAAiF,CAA9vE,EAAnB,CAAkxEhH,KAAKkF,IAAL,CAAUC,QAAV,CAAmB8B,WAAnB,GAA+B,UAASje,CAAT,EAAW;AAAC,MAAIL,IAAE,EAAN,CAAS,IAAII,IAAEqC,SAASpC,EAAEqC,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAN,CAAiC,IAAInD,IAAEuF,KAAKc,KAAL,CAAWxF,IAAE,EAAb,CAAN,CAAuB,IAAIN,IAAEM,IAAE,EAAR,CAAW,IAAIJ,IAAET,IAAE,GAAF,GAAMO,CAAZ,CAAc,IAAID,IAAE,EAAN,CAAS,KAAI,IAAIR,IAAE,CAAV,EAAYA,IAAEgB,EAAEH,MAAhB,EAAuBb,KAAG,CAA1B,EAA4B;AAAC,QAAIF,IAAEsD,SAASpC,EAAEqC,MAAF,CAASrD,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAN,CAAiC,IAAID,IAAE,CAAC,aAAWD,EAAEgC,QAAF,CAAW,CAAX,CAAZ,EAA2Bc,KAA3B,CAAiC,CAAC,CAAlC,CAAN,CAA2CpC,IAAEA,IAAET,EAAEsD,MAAF,CAAS,CAAT,EAAW,CAAX,CAAJ,CAAkB,IAAGtD,EAAEsD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,GAAlB,EAAsB;AAAC,UAAI9C,IAAE,IAAIoJ,UAAJ,CAAenJ,CAAf,EAAiB,CAAjB,CAAN,CAA0BG,IAAEA,IAAE,GAAF,GAAMJ,EAAEuB,QAAF,CAAW,EAAX,CAAR,CAAuBtB,IAAE,EAAF;AAAK;AAAC,UAAOG,CAAP;AAAS,CAAhW,CAAiWqX,KAAKkF,IAAL,CAAUC,QAAV,CAAmB+B,WAAnB,GAA+B,UAASlf,CAAT,EAAW;AAAC,MAAIQ,IAAE,SAAFA,CAAE,CAASQ,CAAT,EAAW;AAAC,QAAID,IAAEC,EAAEc,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAGf,EAAEF,MAAF,IAAU,CAAb,EAAe;AAACE,UAAE,MAAIA,CAAN;AAAQ,YAAOA,CAAP;AAAS,GAAxE,CAAyE,IAAIb,IAAE,SAAFA,CAAE,CAASoB,CAAT,EAAW;AAAC,QAAIF,IAAE,EAAN,CAAS,IAAIL,IAAE,IAAI4I,UAAJ,CAAerI,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIN,IAAED,EAAEe,QAAF,CAAW,CAAX,CAAN,CAAoB,IAAIhB,IAAE,IAAEE,EAAEH,MAAF,GAAS,CAAjB,CAAmB,IAAGC,KAAG,CAAN,EAAQ;AAACA,UAAE,CAAF;AAAI,SAAIwB,IAAE,EAAN,CAAS,KAAI,IAAIS,IAAE,CAAV,EAAYA,IAAEjC,CAAd,EAAgBiC,GAAhB,EAAoB;AAACT,WAAG,GAAH;AAAO,SAAEA,IAAEtB,CAAJ,CAAM,KAAI,IAAI+B,IAAE,CAAV,EAAYA,IAAE/B,EAAEH,MAAF,GAAS,CAAvB,EAAyBkC,KAAG,CAA5B,EAA8B;AAAC,UAAI1B,IAAEL,EAAEqC,MAAF,CAASN,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAGA,KAAG/B,EAAEH,MAAF,GAAS,CAAf,EAAiB;AAACQ,YAAE,MAAIA,CAAN;AAAQ,YAAGb,EAAE4C,SAAS/B,CAAT,EAAW,CAAX,CAAF,CAAH;AAAoB,YAAOD,CAAP;AAAS,GAA/P,CAAgQ,IAAG,CAACpB,EAAE+c,KAAF,CAAQ,WAAR,CAAJ,EAAyB;AAAC,UAAK,2BAAyB/c,CAA9B;AAAgC,OAAIF,IAAE,EAAN,CAAS,IAAIS,IAAEP,EAAEmf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAIxe,IAAEyC,SAAS7C,EAAE,CAAF,CAAT,IAAe,EAAf,GAAkB6C,SAAS7C,EAAE,CAAF,CAAT,CAAxB,CAAuCT,KAAGU,EAAEG,CAAF,CAAH,CAAQJ,EAAEuE,MAAF,CAAS,CAAT,EAAW,CAAX,EAAc,KAAI,IAAIrE,IAAE,CAAV,EAAYA,IAAEF,EAAEM,MAAhB,EAAuBJ,GAAvB,EAA2B;AAACX,SAAGI,EAAEK,EAAEE,CAAF,CAAF,CAAH;AAAW,UAAOX,CAAP;AAAS,CAAvjB,CAAwjBkY,KAAKkF,IAAL,CAAUkC,UAAV,GAAqB,YAAU;AAAC,MAAI3e,IAAE,IAAN,CAAW,IAAIF,IAAE,IAAN,CAAW,IAAIL,IAAE,IAAN,CAAW,IAAIM,IAAE,IAAN,CAAW,IAAIQ,IAAE,EAAN,CAAS,KAAKqe,qBAAL,GAA2B,YAAU;AAAC,QAAG,OAAO,KAAKC,EAAZ,IAAgB,WAAhB,IAA6B,KAAKA,EAAL,IAAS,IAAzC,EAA8C;AAAC,YAAK,+BAAL;AAAqC,SAAG,KAAKA,EAAL,CAAQze,MAAR,GAAe,CAAf,IAAkB,CAArB,EAAuB;AAAC,YAAK,sCAAoCG,EAAEH,MAAtC,GAA6C,KAA7C,GAAmD,KAAKye,EAA7D;AAAgE,SAAI1e,IAAE,KAAK0e,EAAL,CAAQze,MAAR,GAAe,CAArB,CAAuB,IAAId,IAAEa,EAAEkB,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG/B,EAAEc,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACd,UAAE,MAAIA,CAAN;AAAQ,SAAGa,IAAE,GAAL,EAAS;AAAC,aAAOb,CAAP;AAAS,KAAnB,MAAuB;AAAC,UAAID,IAAEC,EAAEc,MAAF,GAAS,CAAf,CAAiB,IAAGf,IAAE,EAAL,EAAQ;AAAC,cAAK,mDAAiDc,EAAEkB,QAAF,CAAW,EAAX,CAAtD;AAAqE,WAAI9B,IAAE,MAAIF,CAAV,CAAY,OAAOE,EAAE8B,QAAF,CAAW,EAAX,IAAe/B,CAAtB;AAAwB;AAAC,GAApb,CAAqb,KAAKif,aAAL,GAAmB,YAAU;AAAC,QAAG,KAAKO,IAAL,IAAW,IAAX,IAAiB,KAAKC,UAAzB,EAAoC;AAAC,WAAKF,EAAL,GAAQ,KAAKG,gBAAL,EAAR,CAAgC,KAAKC,EAAL,GAAQ,KAAKL,qBAAL,EAAR,CAAqC,KAAKE,IAAL,GAAU,KAAKI,EAAL,GAAQ,KAAKD,EAAb,GAAgB,KAAKJ,EAA/B,CAAkC,KAAKE,UAAL,GAAgB,KAAhB;AAAsB,YAAO,KAAKD,IAAZ;AAAiB,GAAjN,CAAkN,KAAKK,WAAL,GAAiB,YAAU;AAAC,SAAKZ,aAAL,GAAqB,OAAO,KAAKM,EAAZ;AAAe,GAAhE,CAAiE,KAAKG,gBAAL,GAAsB,YAAU;AAAC,WAAM,EAAN;AAAS,GAA1C;AAA2C,CAAx0B,CAAy0BzH,KAAKkF,IAAL,CAAU2C,iBAAV,GAA4B,UAASpf,CAAT,EAAW;AAACuX,OAAKkF,IAAL,CAAU2C,iBAAV,CAA4Bxf,UAA5B,CAAuCD,WAAvC,CAAmDuC,IAAnD,CAAwD,IAAxD,EAA8D,IAAIpC,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,KAAK8e,SAAL,GAAe,YAAU;AAAC,WAAO,KAAKvd,CAAZ;AAAc,GAAxC,CAAyC,KAAKwd,SAAL,GAAe,UAAS7f,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAOrC,CAAP,CAAS,KAAKof,EAAL,GAAQU,UAAU,KAAKzd,CAAf,EAAkB0d,WAAlB,EAAR;AAAwC,GAAhH,CAAiH,KAAKC,YAAL,GAAkB,UAAShgB,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAO,IAAP,CAAY,KAAK+c,EAAL,GAAQpf,CAAR;AAAU,GAAxF,CAAyF,KAAKuf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAO7e,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,WAAKsf,SAAL,CAAetf,CAAf;AAAkB,KAAzC,MAA6C;AAAC,UAAG,OAAOA,EAAE0f,GAAT,IAAc,WAAjB,EAA6B;AAAC,aAAKJ,SAAL,CAAetf,EAAE0f,GAAjB;AAAsB,OAApD,MAAwD;AAAC,YAAG,OAAO1f,EAAE2f,GAAT,IAAc,WAAjB,EAA6B;AAAC,eAAKF,YAAL,CAAkBzf,EAAE2f,GAApB;AAAyB;AAAC;AAAC;AAAC;AAAC,CAA5lB,CAA6lB1gB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAU2C,iBAA5B,EAA8C7H,KAAKkF,IAAL,CAAUkC,UAAxD,EAAoEpH,KAAKkF,IAAL,CAAUmD,eAAV,GAA0B,UAAS5f,CAAT,EAAW;AAACuX,OAAKkF,IAAL,CAAUmD,eAAV,CAA0BhgB,UAA1B,CAAqCD,WAArC,CAAiDuC,IAAjD,CAAsD,IAAtD,EAA4D,IAAIpC,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,KAAKsf,cAAL,GAAoB,UAAStgB,CAAT,EAAW;AAACugB,UAAIvgB,EAAEgX,OAAF,KAAahX,EAAEwgB,iBAAF,KAAsB,KAAvC,CAA8C,IAAIhgB,IAAE,IAAIuW,IAAJ,CAASwJ,GAAT,CAAN,CAAoB,OAAO/f,CAAP;AAAS,GAA3G,CAA4G,KAAKigB,UAAL,GAAgB,UAAS1d,CAAT,EAAWzB,CAAX,EAAad,CAAb,EAAe;AAAC,QAAIV,IAAE,KAAK4gB,WAAX,CAAuB,IAAItf,IAAE,KAAKkf,cAAL,CAAoBvd,CAApB,CAAN,CAA6B,IAAI1B,IAAEkC,OAAOnC,EAAEuf,WAAF,EAAP,CAAN,CAA8B,IAAGrf,KAAG,KAAN,EAAY;AAACD,UAAEA,EAAEgC,MAAF,CAAS,CAAT,EAAW,CAAX,CAAF;AAAgB,SAAIvC,IAAEhB,EAAEyD,OAAOnC,EAAEwf,QAAF,KAAa,CAApB,CAAF,EAAyB,CAAzB,CAAN,CAAkC,IAAIte,IAAExC,EAAEyD,OAAOnC,EAAEyf,OAAF,EAAP,CAAF,EAAsB,CAAtB,CAAN,CAA+B,IAAI9gB,IAAED,EAAEyD,OAAOnC,EAAE0f,QAAF,EAAP,CAAF,EAAuB,CAAvB,CAAN,CAAgC,IAAIlgB,IAAEd,EAAEyD,OAAOnC,EAAE2f,UAAF,EAAP,CAAF,EAAyB,CAAzB,CAAN,CAAkC,IAAIpgB,IAAEb,EAAEyD,OAAOnC,EAAE4f,UAAF,EAAP,CAAF,EAAyB,CAAzB,CAAN,CAAkC,IAAIve,IAAEpB,IAAEP,CAAF,GAAIwB,CAAJ,GAAMvC,CAAN,GAAQa,CAAR,GAAUD,CAAhB,CAAkB,IAAGH,MAAI,IAAP,EAAY;AAAC,UAAIR,IAAEoB,EAAE6f,eAAF,EAAN,CAA0B,IAAGjhB,KAAG,CAAN,EAAQ;AAAC,YAAIe,IAAEjB,EAAEyD,OAAOvD,CAAP,CAAF,EAAY,CAAZ,CAAN,CAAqBe,IAAEA,EAAEic,OAAF,CAAU,OAAV,EAAkB,EAAlB,CAAF,CAAwBva,IAAEA,IAAE,GAAF,GAAM1B,CAAR;AAAU;AAAC,YAAO0B,IAAE,GAAT;AAAa,GAA3b,CAA4b,KAAKie,WAAL,GAAiB,UAASlgB,CAAT,EAAWN,CAAX,EAAa;AAAC,QAAGM,EAAEK,MAAF,IAAUX,CAAb,EAAe;AAAC,aAAOM,CAAP;AAAS,YAAO,IAAI+I,KAAJ,CAAUrJ,IAAEM,EAAEK,MAAJ,GAAW,CAArB,EAAwBqC,IAAxB,CAA6B,GAA7B,IAAkC1C,CAAzC;AAA2C,GAAnG,CAAoG,KAAKsf,SAAL,GAAe,YAAU;AAAC,WAAO,KAAKvd,CAAZ;AAAc,GAAxC,CAAyC,KAAKwd,SAAL,GAAe,UAAS7f,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAOrC,CAAP,CAAS,KAAKof,EAAL,GAAQ4B,OAAOhhB,CAAP,CAAR;AAAkB,GAA1F,CAA2F,KAAKihB,cAAL,GAAoB,UAASphB,CAAT,EAAWY,CAAX,EAAaH,CAAb,EAAeN,CAAf,EAAiBF,CAAjB,EAAmBF,CAAnB,EAAqB;AAAC,QAAIc,IAAE,IAAImW,IAAJ,CAASA,KAAKqK,GAAL,CAASrhB,CAAT,EAAWY,IAAE,CAAb,EAAeH,CAAf,EAAiBN,CAAjB,EAAmBF,CAAnB,EAAqBF,CAArB,EAAuB,CAAvB,CAAT,CAAN,CAA0C,KAAKuhB,SAAL,CAAezgB,CAAf;AAAkB,GAAtG,CAAuG,KAAK6e,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD;AAAiD,CAAhiC,CAAiiC5f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUmD,eAA5B,EAA4CrI,KAAKkF,IAAL,CAAUkC,UAAtD,EAAkEpH,KAAKkF,IAAL,CAAUoE,qBAAV,GAAgC,UAAS/gB,CAAT,EAAW;AAACyX,OAAKkF,IAAL,CAAU2C,iBAAV,CAA4Bxf,UAA5B,CAAuCD,WAAvC,CAAmDuC,IAAnD,CAAwD,IAAxD,EAA8D,IAAI3B,IAAE,IAAN,CAAW,KAAKugB,oBAAL,GAA0B,UAAS9gB,CAAT,EAAW;AAAC,SAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKgC,SAAL,GAAe/gB,CAAf;AAAiB,GAA3F,CAA4F,KAAKghB,gBAAL,GAAsB,UAAShhB,CAAT,EAAW;AAAC,SAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKgC,SAAL,CAAe1e,IAAf,CAAoBrC,CAApB;AAAuB,GAA7F,CAA8F,KAAK+gB,SAAL,GAAe,IAAIjY,KAAJ,EAAf,CAA2B,IAAG,OAAOhJ,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAEoe,KAAT,IAAgB,WAAnB,EAA+B;AAAC,WAAK6C,SAAL,GAAejhB,EAAEoe,KAAjB;AAAuB;AAAC;AAAC,CAA7Z,CAA8Zjf,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUoE,qBAA5B,EAAkDtJ,KAAKkF,IAAL,CAAUkC,UAA5D,EAAwEpH,KAAKkF,IAAL,CAAUO,UAAV,GAAqB,YAAU;AAACzF,OAAKkF,IAAL,CAAUO,UAAV,CAAqBpd,UAArB,CAAgCD,WAAhC,CAA4CuC,IAA5C,CAAiD,IAAjD,EAAuD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKJ,IAAL,GAAU,QAAV;AAAmB,CAAvH,CAAwH7f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUO,UAA5B,EAAuCzF,KAAKkF,IAAL,CAAUkC,UAAjD,EAA6DpH,KAAKkF,IAAL,CAAUQ,UAAV,GAAqB,UAAS1c,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUQ,UAAV,CAAqBrd,UAArB,CAAgCD,WAAhC,CAA4CuC,IAA5C,CAAiD,IAAjD,EAAuD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAK+B,eAAL,GAAqB,UAASnhB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQtH,KAAKkF,IAAL,CAAUC,QAAV,CAAmBE,6BAAnB,CAAiD9c,CAAjD,CAAR;AAA4D,GAAjI,CAAkI,KAAKohB,YAAL,GAAkB,UAASlhB,CAAT,EAAW;AAAC,QAAIF,IAAE,IAAIoJ,UAAJ,CAAepG,OAAO9C,CAAP,CAAf,EAAyB,EAAzB,CAAN,CAAmC,KAAKihB,eAAL,CAAqBnhB,CAArB;AAAwB,GAAzF,CAA0F,KAAKqhB,WAAL,GAAiB,UAASrhB,CAAT,EAAW;AAAC,SAAK+e,EAAL,GAAQ/e,CAAR;AAAU,GAAvC,CAAwC,KAAKkf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAE6gB,MAAT,IAAiB,WAApB,EAAgC;AAAC,WAAKH,eAAL,CAAqB1gB,EAAE6gB,MAAvB;AAA+B,KAAhE,MAAoE;AAAC,UAAG,OAAO7gB,EAAE,KAAF,CAAP,IAAiB,WAApB,EAAgC;AAAC,aAAK2gB,YAAL,CAAkB3gB,EAAE,KAAF,CAAlB;AAA4B,OAA7D,MAAiE;AAAC,YAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,eAAK2gB,YAAL,CAAkB3gB,CAAlB;AAAqB,SAA5C,MAAgD;AAAC,cAAG,OAAOA,EAAEof,GAAT,IAAc,WAAjB,EAA6B;AAAC,iBAAKwB,WAAL,CAAiB5gB,EAAEof,GAAnB;AAAwB;AAAC;AAAC;AAAC;AAAC;AAAC,CAAvqB,CAAwqB1gB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUQ,UAA5B,EAAuC1F,KAAKkF,IAAL,CAAUkC,UAAjD,EAA6DpH,KAAKkF,IAAL,CAAUS,YAAV,GAAuB,UAASpd,CAAT,EAAW;AAAC,MAAGA,MAAIZ,SAAJ,IAAe,OAAOY,EAAEue,GAAT,KAAe,WAAjC,EAA6C;AAAC,QAAI9d,IAAEgX,KAAKkF,IAAL,CAAUC,QAAV,CAAmBK,SAAnB,CAA6Bjd,EAAEue,GAA/B,CAAN,CAA0Cve,EAAE6f,GAAF,GAAM,OAAKpf,EAAEge,aAAF,EAAX;AAA6B,QAAK9B,IAAL,CAAUS,YAAV,CAAuBtd,UAAvB,CAAkCD,WAAlC,CAA8CuC,IAA9C,CAAmD,IAAnD,EAAyD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKmC,8BAAL,GAAoC,UAASrhB,CAAT,EAAW;AAAC,SAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQ7e,CAAR;AAAU,GAA9F,CAA+F,KAAKshB,wBAAL,GAA8B,UAASthB,CAAT,EAAWD,CAAX,EAAa;AAAC,QAAGC,IAAE,CAAF,IAAK,IAAEA,CAAV,EAAY;AAAC,YAAK,2CAAyCA,CAA9C;AAAgD,SAAIP,IAAE,MAAIO,CAAV,CAAY,KAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQpf,IAAEM,CAAV;AAAY,GAArK,CAAsK,KAAKwhB,iBAAL,GAAuB,UAASxhB,CAAT,EAAW;AAACA,QAAEA,EAAEwc,OAAF,CAAU,KAAV,EAAgB,EAAhB,CAAF,CAAsB,IAAIhd,IAAE,IAAEQ,EAAEK,MAAF,GAAS,CAAjB,CAAmB,IAAGb,KAAG,CAAN,EAAQ;AAACA,UAAE,CAAF;AAAI,UAAI,IAAIF,IAAE,CAAV,EAAYA,KAAGE,CAAf,EAAiBF,GAAjB,EAAqB;AAACU,WAAG,GAAH;AAAO,SAAIG,IAAE,EAAN,CAAS,KAAI,IAAIb,IAAE,CAAV,EAAYA,IAAEU,EAAEK,MAAF,GAAS,CAAvB,EAAyBf,KAAG,CAA5B,EAA8B;AAAC,UAAII,IAAEM,EAAE6C,MAAF,CAASvD,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAIW,IAAE2C,SAASlD,CAAT,EAAW,CAAX,EAAc4B,QAAd,CAAuB,EAAvB,CAAN,CAAiC,IAAGrB,EAAEI,MAAF,IAAU,CAAb,EAAe;AAACJ,YAAE,MAAIA,CAAN;AAAQ,YAAGA,CAAH;AAAK,UAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQ,MAAItf,CAAJ,GAAMW,CAAd;AAAgB,GAApS,CAAqS,KAAKshB,iBAAL,GAAuB,UAASzhB,CAAT,EAAW;AAAC,QAAIN,IAAE,EAAN,CAAS,KAAI,IAAIO,IAAE,CAAV,EAAYA,IAAED,EAAEK,MAAhB,EAAuBJ,GAAvB,EAA2B;AAAC,UAAGD,EAAEC,CAAF,KAAM,IAAT,EAAc;AAACP,aAAG,GAAH;AAAO,OAAtB,MAA0B;AAACA,aAAG,GAAH;AAAO;AAAC,UAAK8hB,iBAAL,CAAuB9hB,CAAvB;AAA0B,GAArI,CAAsI,KAAKgiB,aAAL,GAAmB,UAAS1hB,CAAT,EAAW;AAAC,QAAIC,IAAE,IAAI8I,KAAJ,CAAU/I,CAAV,CAAN,CAAmB,KAAI,IAAIN,IAAE,CAAV,EAAYA,IAAEM,CAAd,EAAgBN,GAAhB,EAAoB;AAACO,QAAEP,CAAF,IAAK,KAAL;AAAW,YAAOO,CAAP;AAAS,GAA3F,CAA4F,KAAKgf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAO/e,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,CAAP,IAAU,QAAV,IAAoBA,EAAE0f,WAAF,GAAgBlD,KAAhB,CAAsB,aAAtB,CAAvB,EAA4D;AAAC,WAAK+E,8BAAL,CAAoCvhB,CAApC;AAAuC,KAApG,MAAwG;AAAC,UAAG,OAAOA,EAAE6f,GAAT,IAAc,WAAjB,EAA6B;AAAC,aAAK0B,8BAAL,CAAoCvhB,EAAE6f,GAAtC;AAA2C,OAAzE,MAA6E;AAAC,YAAG,OAAO7f,EAAE4hB,GAAT,IAAc,WAAjB,EAA6B;AAAC,eAAKH,iBAAL,CAAuBzhB,EAAE4hB,GAAzB;AAA8B,SAA5D,MAAgE;AAAC,cAAG,OAAO5hB,EAAEoe,KAAT,IAAgB,WAAnB,EAA+B;AAAC,iBAAKsD,iBAAL,CAAuB1hB,EAAEoe,KAAzB;AAAgC;AAAC;AAAC;AAAC;AAAC;AAAC,CAAl3C,CAAm3Cjf,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUS,YAA5B,EAAyC3F,KAAKkF,IAAL,CAAUkC,UAAnD,EAA+DpH,KAAKkF,IAAL,CAAUU,cAAV,GAAyB,UAASrd,CAAT,EAAW;AAAC,MAAGA,MAAIZ,SAAJ,IAAe,OAAOY,EAAEue,GAAT,KAAe,WAAjC,EAA6C;AAAC,QAAI9d,IAAEgX,KAAKkF,IAAL,CAAUC,QAAV,CAAmBK,SAAnB,CAA6Bjd,EAAEue,GAA/B,CAAN,CAA0Cve,EAAE6f,GAAF,GAAMpf,EAAEge,aAAF,EAAN;AAAwB,QAAK9B,IAAL,CAAUU,cAAV,CAAyBvd,UAAzB,CAAoCD,WAApC,CAAgDuC,IAAhD,CAAqD,IAArD,EAA0DpC,CAA1D,EAA6D,KAAKof,EAAL,GAAQ,IAAR;AAAa,CAA/N,CAAgOjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUU,cAA5B,EAA2C5F,KAAKkF,IAAL,CAAU2C,iBAArD,EAAwE7H,KAAKkF,IAAL,CAAUW,OAAV,GAAkB,YAAU;AAAC7F,OAAKkF,IAAL,CAAUW,OAAV,CAAkBxd,UAAlB,CAA6BD,WAA7B,CAAyCuC,IAAzC,CAA8C,IAA9C,EAAoD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKJ,IAAL,GAAU,MAAV;AAAiB,CAA/G,CAAgH7f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUW,OAA5B,EAAoC7F,KAAKkF,IAAL,CAAUkC,UAA9C,EAA0DpH,KAAKkF,IAAL,CAAUY,mBAAV,GAA8B,UAASrd,CAAT,EAAW;AAAC,MAAIF,IAAE,SAAFA,CAAE,CAASL,CAAT,EAAW;AAAC,QAAIM,IAAEN,EAAE4B,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAGtB,EAAEK,MAAF,IAAU,CAAb,EAAe;AAACL,UAAE,MAAIA,CAAN;AAAQ,YAAOA,CAAP;AAAS,GAAxE,CAAyE,IAAIQ,IAAE,SAAFA,CAAE,CAASD,CAAT,EAAW;AAAC,QAAIJ,IAAE,EAAN,CAAS,IAAIH,IAAE,IAAImJ,UAAJ,CAAe5I,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIb,IAAEM,EAAEsB,QAAF,CAAW,CAAX,CAAN,CAAoB,IAAI9B,IAAE,IAAEE,EAAEW,MAAF,GAAS,CAAjB,CAAmB,IAAGb,KAAG,CAAN,EAAQ;AAACA,UAAE,CAAF;AAAI,SAAI+C,IAAE,EAAN,CAAS,KAAI,IAAIjD,IAAE,CAAV,EAAYA,IAAEE,CAAd,EAAgBF,GAAhB,EAAoB;AAACiD,WAAG,GAAH;AAAO,SAAEA,IAAE7C,CAAJ,CAAM,KAAI,IAAIJ,IAAE,CAAV,EAAYA,IAAEI,EAAEW,MAAF,GAAS,CAAvB,EAAyBf,KAAG,CAA5B,EAA8B;AAAC,UAAIgB,IAAEZ,EAAEmD,MAAF,CAASvD,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAGA,KAAGI,EAAEW,MAAF,GAAS,CAAf,EAAiB;AAACC,YAAE,MAAIA,CAAN;AAAQ,YAAGP,EAAE6C,SAAStC,CAAT,EAAW,CAAX,CAAF,CAAH;AAAoB,YAAOH,CAAP;AAAS,GAA/P,CAAgQqX,KAAKkF,IAAL,CAAUY,mBAAV,CAA8Bzd,UAA9B,CAAyCD,WAAzC,CAAqDuC,IAArD,CAA0D,IAA1D,EAAgE,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKiC,WAAL,GAAiB,UAAS1hB,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAO,IAAP,CAAY,KAAK+c,EAAL,GAAQpf,CAAR;AAAU,GAAvF,CAAwF,KAAKkiB,iBAAL,GAAuB,UAASpiB,CAAT,EAAW;AAAC,QAAG,CAACA,EAAE+c,KAAF,CAAQ,WAAR,CAAJ,EAAyB;AAAC,YAAK,2BAAyB/c,CAA9B;AAAgC,SAAIF,IAAE,EAAN,CAAS,IAAII,IAAEF,EAAEmf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAIxe,IAAEyC,SAASlD,EAAE,CAAF,CAAT,IAAe,EAAf,GAAkBkD,SAASlD,EAAE,CAAF,CAAT,CAAxB,CAAuCJ,KAAGS,EAAEI,CAAF,CAAH,CAAQT,EAAE4E,MAAF,CAAS,CAAT,EAAW,CAAX,EAAc,KAAI,IAAItE,IAAE,CAAV,EAAYA,IAAEN,EAAEW,MAAhB,EAAuBL,GAAvB,EAA2B;AAACV,WAAGkB,EAAEd,EAAEM,CAAF,CAAF,CAAH;AAAW,UAAK+e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAO,IAAP,CAAY,KAAK+c,EAAL,GAAQxf,CAAR;AAAU,GAAvR,CAAwR,KAAKuiB,YAAL,GAAkB,UAAS7hB,CAAT,EAAW;AAAC,QAAIN,IAAE8X,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmBC,QAAnB,CAA4BhiB,CAA5B,CAAN,CAAqC,IAAGN,MAAI,EAAP,EAAU;AAAC,WAAKkiB,iBAAL,CAAuBliB,CAAvB;AAA0B,KAArC,MAAyC;AAAC,YAAK,4CAA0CM,CAA/C;AAAiD;AAAC,GAA/J,CAAgK,KAAKif,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG7e,MAAId,SAAP,EAAiB;AAAC,QAAG,OAAOc,CAAP,KAAW,QAAd,EAAuB;AAAC,UAAGA,EAAEsc,KAAF,CAAQ,iBAAR,CAAH,EAA8B;AAAC,aAAKqF,iBAAL,CAAuB3hB,CAAvB;AAA0B,OAAzD,MAA6D;AAAC,aAAK4hB,YAAL,CAAkB5hB,CAAlB;AAAqB;AAAC,KAA5G,MAAgH;AAAC,UAAGA,EAAEgiB,GAAF,KAAQ9iB,SAAX,EAAqB;AAAC,aAAKyiB,iBAAL,CAAuB3hB,EAAEgiB,GAAzB;AAA8B,OAApD,MAAwD;AAAC,YAAGhiB,EAAE2f,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,eAAKiiB,WAAL,CAAiBnhB,EAAE2f,GAAnB;AAAwB,SAA9C,MAAkD;AAAC,cAAG3f,EAAEiiB,IAAF,KAAS/iB,SAAZ,EAAsB;AAAC,iBAAK0iB,YAAL,CAAkB5hB,EAAEiiB,IAApB;AAA0B;AAAC;AAAC;AAAC;AAAC;AAAC,CAAtyC,CAAuyChjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUY,mBAA5B,EAAgD9F,KAAKkF,IAAL,CAAUkC,UAA1D,EAAsEpH,KAAKkF,IAAL,CAAUa,aAAV,GAAwB,UAAS/c,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUa,aAAV,CAAwB1d,UAAxB,CAAmCD,WAAnC,CAA+CuC,IAA/C,CAAoD,IAApD,EAA0D,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAK+B,eAAL,GAAqB,UAASnhB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQtH,KAAKkF,IAAL,CAAUC,QAAV,CAAmBE,6BAAnB,CAAiD9c,CAAjD,CAAR;AAA4D,GAAjI,CAAkI,KAAKohB,YAAL,GAAkB,UAASlhB,CAAT,EAAW;AAAC,QAAIF,IAAE,IAAIoJ,UAAJ,CAAepG,OAAO9C,CAAP,CAAf,EAAyB,EAAzB,CAAN,CAAmC,KAAKihB,eAAL,CAAqBnhB,CAArB;AAAwB,GAAzF,CAA0F,KAAKqhB,WAAL,GAAiB,UAASrhB,CAAT,EAAW;AAAC,SAAK+e,EAAL,GAAQ/e,CAAR;AAAU,GAAvC,CAAwC,KAAKkf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAE,KAAF,CAAP,IAAiB,WAApB,EAAgC;AAAC,WAAK2gB,YAAL,CAAkB3gB,EAAE,KAAF,CAAlB;AAA4B,KAA7D,MAAiE;AAAC,UAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,aAAK2gB,YAAL,CAAkB3gB,CAAlB;AAAqB,OAA5C,MAAgD;AAAC,YAAG,OAAOA,EAAEof,GAAT,IAAc,WAAjB,EAA6B;AAAC,eAAKwB,WAAL,CAAiB5gB,EAAEof,GAAnB;AAAwB;AAAC;AAAC;AAAC;AAAC,CAAvmB,CAAwmB1gB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUa,aAA5B,EAA0C/F,KAAKkF,IAAL,CAAUkC,UAApD,EAAgEpH,KAAKkF,IAAL,CAAUc,aAAV,GAAwB,UAAShd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUc,aAAV,CAAwB3d,UAAxB,CAAmCD,WAAnC,CAA+CuC,IAA/C,CAAoD,IAApD,EAAyD3B,CAAzD,EAA4D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAA7G,CAA8GjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUc,aAA5B,EAA0ChG,KAAKkF,IAAL,CAAU2C,iBAApD,EAAuE7H,KAAKkF,IAAL,CAAUe,gBAAV,GAA2B,UAASjd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUe,gBAAV,CAA2B5d,UAA3B,CAAsCD,WAAtC,CAAkDuC,IAAlD,CAAuD,IAAvD,EAA4D3B,CAA5D,EAA+D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAAnH,CAAoHjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUe,gBAA5B,EAA6CjG,KAAKkF,IAAL,CAAU2C,iBAAvD,EAA0E7H,KAAKkF,IAAL,CAAUgB,kBAAV,GAA6B,UAASld,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUgB,kBAAV,CAA6B7d,UAA7B,CAAwCD,WAAxC,CAAoDuC,IAApD,CAAyD,IAAzD,EAA8D3B,CAA9D,EAAiE,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAAvH,CAAwHjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUgB,kBAA5B,EAA+ClG,KAAKkF,IAAL,CAAU2C,iBAAzD,EAA4E7H,KAAKkF,IAAL,CAAUiB,gBAAV,GAA2B,UAASnd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUiB,gBAAV,CAA2B9d,UAA3B,CAAsCD,WAAtC,CAAkDuC,IAAlD,CAAuD,IAAvD,EAA4D3B,CAA5D,EAA+D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAAnH,CAAoHjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUiB,gBAA5B,EAA6CnG,KAAKkF,IAAL,CAAU2C,iBAAvD,EAA0E7H,KAAKkF,IAAL,CAAUkB,YAAV,GAAuB,UAASpd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUkB,YAAV,CAAuB/d,UAAvB,CAAkCD,WAAlC,CAA8CuC,IAA9C,CAAmD,IAAnD,EAAwD3B,CAAxD,EAA2D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAA3G,CAA4GjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUkB,YAA5B,EAAyCpG,KAAKkF,IAAL,CAAU2C,iBAAnD,EAAsE7H,KAAKkF,IAAL,CAAUmB,UAAV,GAAqB,UAASrd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUmB,UAAV,CAAqBhe,UAArB,CAAgCD,WAAhC,CAA4CuC,IAA5C,CAAiD,IAAjD,EAAsD3B,CAAtD,EAAyD,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAK0B,SAAL,GAAe,UAAS9gB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKmD,IAAL,GAAUpiB,CAAV,CAAY,KAAKgC,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,CAAP,CAAwC,KAAKrD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,GAA1I,CAA2I,KAAKkd,gBAAL,GAAsB,YAAU;AAAC,QAAG,OAAO,KAAKkD,IAAZ,IAAkB,WAAlB,IAA+B,OAAO,KAAKpgB,CAAZ,IAAe,WAAjD,EAA6D;AAAC,WAAKogB,IAAL,GAAU,IAAI5L,IAAJ,EAAV,CAAqB,KAAKxU,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,CAAP,CAAwC,KAAKrD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,YAAO,KAAK+c,EAAZ;AAAe,GAAlM,CAAmM,IAAGte,MAAIrB,SAAP,EAAiB;AAAC,QAAGqB,EAAEmf,GAAF,KAAQxgB,SAAX,EAAqB;AAAC,WAAKogB,SAAL,CAAe/e,EAAEmf,GAAjB;AAAsB,KAA5C,MAAgD;AAAC,UAAG,OAAOnf,CAAP,IAAU,QAAV,IAAoBA,EAAE+b,KAAF,CAAQ,cAAR,CAAvB,EAA+C;AAAC,aAAKgD,SAAL,CAAe/e,CAAf;AAAkB,OAAlE,MAAsE;AAAC,YAAGA,EAAEof,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,eAAKugB,YAAL,CAAkBlf,EAAEof,GAApB;AAAyB,SAA/C,MAAmD;AAAC,cAAGpf,EAAE2hB,IAAF,KAAShjB,SAAZ,EAAsB;AAAC,iBAAK0hB,SAAL,CAAergB,EAAE2hB,IAAjB;AAAuB;AAAC;AAAC;AAAC;AAAC;AAAC,CAAtqB,CAAuqBjjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUmB,UAA5B,EAAuCrG,KAAKkF,IAAL,CAAUmD,eAAjD,EAAkErI,KAAKkF,IAAL,CAAUoB,kBAAV,GAA6B,UAAStd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUoB,kBAAV,CAA6Bje,UAA7B,CAAwCD,WAAxC,CAAoDuC,IAApD,CAAyD,IAAzD,EAA8D3B,CAA9D,EAAiE,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAKiD,UAAL,GAAgB,KAAhB,CAAsB,KAAKvB,SAAL,GAAe,UAAS9gB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKmD,IAAL,GAAUpiB,CAAV,CAAY,KAAKgC,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,EAAgC,KAAKC,UAArC,CAAP,CAAwD,KAAKtD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,GAA1J,CAA2J,KAAKkd,gBAAL,GAAsB,YAAU;AAAC,QAAG,KAAKkD,IAAL,KAAYhjB,SAAZ,IAAuB,KAAK4C,CAAL,KAAS5C,SAAnC,EAA6C;AAAC,WAAKgjB,IAAL,GAAU,IAAI5L,IAAJ,EAAV,CAAqB,KAAKxU,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,EAAgC,KAAKC,UAArC,CAAP,CAAwD,KAAKtD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,YAAO,KAAK+c,EAAZ;AAAe,GAAlM,CAAmM,IAAGte,MAAIrB,SAAP,EAAiB;AAAC,QAAGqB,EAAEmf,GAAF,KAAQxgB,SAAX,EAAqB;AAAC,WAAKogB,SAAL,CAAe/e,EAAEmf,GAAjB;AAAsB,KAA5C,MAAgD;AAAC,UAAG,OAAOnf,CAAP,IAAU,QAAV,IAAoBA,EAAE+b,KAAF,CAAQ,cAAR,CAAvB,EAA+C;AAAC,aAAKgD,SAAL,CAAe/e,CAAf;AAAkB,OAAlE,MAAsE;AAAC,YAAGA,EAAEof,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,eAAKugB,YAAL,CAAkBlf,EAAEof,GAApB;AAAyB,SAA/C,MAAmD;AAAC,cAAGpf,EAAE2hB,IAAF,KAAShjB,SAAZ,EAAsB;AAAC,iBAAK0hB,SAAL,CAAergB,EAAE2hB,IAAjB;AAAuB;AAAC;AAAC;AAAC,SAAG3hB,EAAE6hB,MAAF,KAAW,IAAd,EAAmB;AAAC,WAAKD,UAAL,GAAgB,IAAhB;AAAqB;AAAC;AAAC,CAArwB,CAAswBljB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUoB,kBAA5B,EAA+CtG,KAAKkF,IAAL,CAAUmD,eAAzD,EAA0ErI,KAAKkF,IAAL,CAAUqB,WAAV,GAAsB,UAASvd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUqB,WAAV,CAAsBle,UAAtB,CAAiCD,WAAjC,CAA6CuC,IAA7C,CAAkD,IAAlD,EAAuD3B,CAAvD,EAA0D,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAKF,gBAAL,GAAsB,YAAU;AAAC,QAAIhf,IAAE,EAAN,CAAS,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE,KAAKihB,SAAL,CAAe3gB,MAA7B,EAAoCN,GAApC,EAAwC;AAAC,UAAIL,IAAE,KAAKshB,SAAL,CAAejhB,CAAf,CAAN,CAAwBE,KAAGP,EAAE8e,aAAF,EAAH;AAAqB,UAAKM,EAAL,GAAQ7e,CAAR,CAAU,OAAO,KAAK6e,EAAZ;AAAe,GAAzJ;AAA0J,CAAnQ,CAAoQ5f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUqB,WAA5B,EAAwCvG,KAAKkF,IAAL,CAAUoE,qBAAlD,EAAyEtJ,KAAKkF,IAAL,CAAUsB,MAAV,GAAiB,UAASxd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUsB,MAAV,CAAiBne,UAAjB,CAA4BD,WAA5B,CAAwCuC,IAAxC,CAA6C,IAA7C,EAAkD3B,CAAlD,EAAqD,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAKmD,QAAL,GAAc,IAAd,CAAmB,KAAKrD,gBAAL,GAAsB,YAAU;AAAC,QAAIlf,IAAE,IAAIgJ,KAAJ,EAAN,CAAkB,KAAI,IAAI9I,IAAE,CAAV,EAAYA,IAAE,KAAK+gB,SAAL,CAAe3gB,MAA7B,EAAoCJ,GAApC,EAAwC;AAAC,UAAIP,IAAE,KAAKshB,SAAL,CAAe/gB,CAAf,CAAN,CAAwBF,EAAEuC,IAAF,CAAO5C,EAAE8e,aAAF,EAAP;AAA0B,SAAG,KAAK8D,QAAL,IAAe,IAAlB,EAAuB;AAACviB,QAAEwiB,IAAF;AAAS,UAAKzD,EAAL,GAAQ/e,EAAE2C,IAAF,CAAO,EAAP,CAAR,CAAmB,OAAO,KAAKoc,EAAZ;AAAe,GAAjN,CAAkN,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAEgiB,QAAT,IAAmB,WAAnB,IAAgChiB,EAAEgiB,QAAF,IAAY,KAA/C,EAAqD;AAAC,WAAKF,QAAL,GAAc,KAAd;AAAoB;AAAC;AAAC,CAA1a,CAA2apjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUsB,MAA5B,EAAmCxG,KAAKkF,IAAL,CAAUoE,qBAA7C,EAAoEtJ,KAAKkF,IAAL,CAAUuB,eAAV,GAA0B,UAASzd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUuB,eAAV,CAA0Bpe,UAA1B,CAAqCD,WAArC,CAAiDuC,IAAjD,CAAsD,IAAtD,EAA4D,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKL,EAAL,GAAQ,EAAR,CAAW,KAAK2D,UAAL,GAAgB,IAAhB,CAAqB,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKC,aAAL,GAAmB,UAAS5iB,CAAT,EAAWE,CAAX,EAAaP,CAAb,EAAe;AAAC,SAAKyf,EAAL,GAAQlf,CAAR,CAAU,KAAKwiB,UAAL,GAAgB1iB,CAAhB,CAAkB,KAAK2iB,UAAL,GAAgBhjB,CAAhB,CAAkB,IAAG,KAAK+iB,UAAR,EAAmB;AAAC,WAAK3D,EAAL,GAAQ,KAAK4D,UAAL,CAAgBlE,aAAhB,EAAR,CAAwC,KAAKO,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB;AAAqB,KAAhG,MAAoG;AAAC,WAAKF,EAAL,GAAQ,IAAR,CAAa,KAAKC,IAAL,GAAUrf,EAAE8e,aAAF,EAAV,CAA4B,KAAKO,IAAL,GAAU,KAAKA,IAAL,CAAUvC,OAAV,CAAkB,KAAlB,EAAwBvc,CAAxB,CAAV,CAAqC,KAAK+e,UAAL,GAAgB,KAAhB;AAAsB;AAAC,GAA3R,CAA4R,KAAKC,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAE4d,GAAT,IAAc,WAAjB,EAA6B;AAAC,WAAKe,EAAL,GAAQ3e,EAAE4d,GAAV;AAAc,SAAG,OAAO5d,EAAE6d,QAAT,IAAmB,WAAtB,EAAkC;AAAC,WAAKoE,UAAL,GAAgBjiB,EAAE6d,QAAlB;AAA2B,SAAG,OAAO7d,EAAE8d,GAAT,IAAc,WAAjB,EAA6B;AAAC,WAAKoE,UAAL,GAAgBliB,EAAE8d,GAAlB,CAAsB,KAAKqE,aAAL,CAAmB,KAAKF,UAAxB,EAAmC,KAAKtD,EAAxC,EAA2C,KAAKuD,UAAhD;AAA4D;AAAC;AAAC,CAAvuB,CAAwuBxjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUuB,eAA5B,EAA4CzG,KAAKkF,IAAL,CAAUkC,UAAtD;AAC5ne,IAAIgE,UAAQ,IAAI,YAAU,CAAE,CAAhB,EAAZ,CAA6BA,QAAQC,QAAR,GAAiB,UAAS5iB,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAGP,EAAE4C,MAAF,CAASrC,IAAE,CAAX,EAAa,CAAb,KAAiB,GAApB,EAAwB;AAAC,WAAO,CAAP;AAAS,OAAIT,IAAE6C,SAAS3C,EAAE4C,MAAF,CAASrC,IAAE,CAAX,EAAa,CAAb,CAAT,CAAN,CAAgC,IAAGT,KAAG,CAAN,EAAQ;AAAC,WAAO,CAAC,CAAR;AAAU,OAAG,IAAEA,CAAF,IAAKA,IAAE,EAAV,EAAa;AAAC,WAAOA,IAAE,CAAT;AAAW,UAAO,CAAC,CAAR;AAAU,CAAvJ,CAAwJ6iB,QAAQE,IAAR,GAAa,UAAS7iB,CAAT,EAAWF,CAAX,EAAa;AAAC,MAAIS,IAAEoiB,QAAQC,QAAR,CAAiB5iB,CAAjB,EAAmBF,CAAnB,CAAN,CAA4B,IAAGS,IAAE,CAAL,EAAO;AAAC,WAAM,EAAN;AAAS,UAAOP,EAAE4C,MAAF,CAAS9C,IAAE,CAAX,EAAaS,IAAE,CAAf,CAAP;AAAyB,CAAjG,CAAkGoiB,QAAQG,QAAR,GAAiB,UAASrjB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIP,CAAJ,EAAMF,CAAN,CAAQE,IAAE2iB,QAAQE,IAAR,CAAapjB,CAAb,EAAec,CAAf,CAAF,CAAoB,IAAGP,KAAG,EAAN,EAAS;AAAC,WAAO,CAAC,CAAR;AAAU,OAAGA,EAAE4C,MAAF,CAAS,CAAT,EAAW,CAAX,MAAgB,GAAnB,EAAuB;AAAC9C,QAAE,IAAIoJ,UAAJ,CAAelJ,EAAE4C,MAAF,CAAS,CAAT,CAAf,EAA2B,EAA3B,CAAF;AAAiC,GAAzD,MAA6D;AAAC9C,QAAE,IAAIoJ,UAAJ,CAAelJ,CAAf,EAAiB,EAAjB,CAAF;AAAuB,UAAOF,EAAEyP,QAAF,EAAP;AAAoB,CAAxL,CAAyLoT,QAAQI,OAAR,GAAgB,UAAS/iB,CAAT,EAAWF,CAAX,EAAa;AAAC,MAAIS,IAAEoiB,QAAQC,QAAR,CAAiB5iB,CAAjB,EAAmBF,CAAnB,CAAN,CAA4B,IAAGS,IAAE,CAAL,EAAO;AAAC,WAAOA,CAAP;AAAS,UAAOT,IAAE,CAACS,IAAE,CAAH,IAAM,CAAf;AAAiB,CAA5F,CAA6FoiB,QAAQK,IAAR,GAAa,UAASvjB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIP,IAAE2iB,QAAQI,OAAR,CAAgBtjB,CAAhB,EAAkBc,CAAlB,CAAN,CAA2B,IAAIT,IAAE6iB,QAAQG,QAAR,CAAiBrjB,CAAjB,EAAmBc,CAAnB,CAAN,CAA4B,OAAOd,EAAEmD,MAAF,CAAS5C,CAAT,EAAWF,IAAE,CAAb,CAAP;AAAuB,CAAzG,CAA0G6iB,QAAQM,MAAR,GAAe,UAASnjB,CAAT,EAAWS,CAAX,EAAa;AAAC,SAAOT,EAAE8C,MAAF,CAASrC,CAAT,EAAW,CAAX,IAAcoiB,QAAQE,IAAR,CAAa/iB,CAAb,EAAeS,CAAf,CAAd,GAAgCoiB,QAAQK,IAAR,CAAaljB,CAAb,EAAeS,CAAf,CAAvC;AAAyD,CAAtF,CAAuFoiB,QAAQO,iBAAR,GAA0B,UAASzjB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIP,IAAE2iB,QAAQI,OAAR,CAAgBtjB,CAAhB,EAAkBc,CAAlB,CAAN,CAA2B,IAAIT,IAAE6iB,QAAQG,QAAR,CAAiBrjB,CAAjB,EAAmBc,CAAnB,CAAN,CAA4B,OAAOP,IAAEF,IAAE,CAAX;AAAa,CAA5G,CAA6G6iB,QAAQQ,WAAR,GAAoB,UAASpjB,CAAT,EAAWR,CAAX,EAAa;AAAC,MAAIW,IAAEyiB,OAAN,CAAc,IAAItjB,IAAE,IAAIyJ,KAAJ,EAAN,CAAkB,IAAI3I,IAAED,EAAE6iB,OAAF,CAAUhjB,CAAV,EAAYR,CAAZ,CAAN,CAAqB,IAAGQ,EAAE6C,MAAF,CAASrD,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAACF,MAAEgD,IAAF,CAAOlC,IAAE,CAAT;AAAY,GAApC,MAAwC;AAACd,MAAEgD,IAAF,CAAOlC,CAAP;AAAU,OAAIE,IAAEH,EAAE4iB,QAAF,CAAW/iB,CAAX,EAAaR,CAAb,CAAN,CAAsB,IAAIS,IAAEG,CAAN,CAAQ,IAAIV,IAAE,CAAN,CAAQ,OAAM,CAAN,EAAQ;AAAC,QAAIK,IAAEI,EAAEgjB,iBAAF,CAAoBnjB,CAApB,EAAsBC,CAAtB,CAAN,CAA+B,IAAGF,KAAG,IAAH,IAAUA,IAAEK,CAAF,IAAME,IAAE,CAArB,EAAyB;AAAC;AAAM,SAAGZ,KAAG,GAAN,EAAU;AAAC;AAAM,OAAE4C,IAAF,CAAOvC,CAAP,EAAUE,IAAEF,CAAF,CAAIL;AAAI,UAAOJ,CAAP;AAAS,CAApS,CAAqSsjB,QAAQS,cAAR,GAAuB,UAAS3jB,CAAT,EAAWK,CAAX,EAAaC,CAAb,EAAe;AAAC,MAAIC,IAAE2iB,QAAQQ,WAAR,CAAoB1jB,CAApB,EAAsBK,CAAtB,CAAN,CAA+B,OAAOE,EAAED,CAAF,CAAP;AAAY,CAAlF,CAAmF4iB,QAAQU,YAAR,GAAqB,UAAStjB,CAAT,EAAWN,CAAX,EAAaO,CAAb,EAAeG,CAAf,EAAiB;AAAC,MAAId,IAAEsjB,OAAN,CAAc,IAAIpjB,CAAJ,EAAMO,CAAN,CAAQ,IAAGE,EAAEI,MAAF,IAAU,CAAb,EAAe;AAAC,QAAGD,MAAIjB,SAAP,EAAiB;AAAC,UAAGa,EAAE6C,MAAF,CAASnD,CAAT,EAAW,CAAX,MAAgBU,CAAnB,EAAqB;AAAC,cAAK,iCAA+BJ,EAAE6C,MAAF,CAASnD,CAAT,EAAW,CAAX,CAA/B,GAA6C,IAA7C,GAAkDU,CAAvD;AAAyD;AAAC,YAAOV,CAAP;AAAS,OAAEO,EAAEwc,KAAF,EAAF,CAAY1c,IAAET,EAAE8jB,WAAF,CAAcpjB,CAAd,EAAgBN,CAAhB,CAAF,CAAqB,OAAOJ,EAAEgkB,YAAF,CAAetjB,CAAf,EAAiBD,EAAEP,CAAF,CAAjB,EAAsBS,CAAtB,EAAwBG,CAAxB,CAAP;AAAkC,CAA3P,CAA4PwiB,QAAQW,YAAR,GAAqB,UAAS7jB,CAAT,EAAWO,CAAX,EAAaF,CAAb,EAAeP,CAAf,EAAiB;AAAC,MAAIQ,IAAE4iB,OAAN,CAAc,IAAIpiB,IAAER,EAAEsjB,YAAF,CAAe5jB,CAAf,EAAiBO,CAAjB,EAAmBF,CAAnB,CAAN,CAA4B,IAAGS,MAAIrB,SAAP,EAAiB;AAAC,UAAK,2BAAL;AAAiC,OAAGK,MAAIL,SAAP,EAAiB;AAAC,QAAGO,EAAEmD,MAAF,CAASrC,CAAT,EAAW,CAAX,KAAehB,CAAlB,EAAoB;AAAC,YAAK,iCAA+BE,EAAEmD,MAAF,CAASrC,CAAT,EAAW,CAAX,CAA/B,GAA6C,IAA7C,GAAkDhB,CAAvD;AAAyD;AAAC,UAAOQ,EAAEkjB,MAAF,CAASxjB,CAAT,EAAWc,CAAX,CAAP;AAAqB,CAA1P,CAA2PoiB,QAAQY,UAAR,GAAmB,UAASxjB,CAAT,EAAWC,CAAX,EAAaF,CAAb,EAAeT,CAAf,EAAiBc,CAAjB,EAAmB;AAAC,MAAIZ,IAAEojB,OAAN,CAAc,IAAIpiB,CAAJ,EAAMd,CAAN,CAAQc,IAAEhB,EAAE8jB,YAAF,CAAetjB,CAAf,EAAiBC,CAAjB,EAAmBF,CAAnB,EAAqBT,CAArB,CAAF,CAA0B,IAAGkB,MAAIrB,SAAP,EAAiB;AAAC,UAAK,2BAAL;AAAiC,OAAEK,EAAEyjB,IAAF,CAAOjjB,CAAP,EAASQ,CAAT,CAAF,CAAc,IAAGJ,MAAI,IAAP,EAAY;AAACV,QAAEA,EAAEmD,MAAF,CAAS,CAAT,CAAF;AAAc,UAAOnD,CAAP;AAAS,CAA5L,CAA6LkjB,QAAQa,WAAR,GAAoB,UAASzjB,CAAT,EAAW;AAAC,MAAIT,IAAE,SAAFA,CAAE,CAASQ,CAAT,EAAWS,CAAX,EAAa;AAAC,QAAGT,EAAEM,MAAF,IAAUG,CAAb,EAAe;AAAC,aAAOT,CAAP;AAAS,YAAO,IAAIgJ,KAAJ,CAAUvI,IAAET,EAAEM,MAAJ,GAAW,CAArB,EAAwBqC,IAAxB,CAA6B,GAA7B,IAAkC3C,CAAzC;AAA2C,GAAxF,CAAyF,IAAIO,IAAE,EAAN,CAAS,IAAIQ,IAAEd,EAAE6C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAIrD,IAAEoD,SAAS9B,CAAT,EAAW,EAAX,CAAN,CAAqBR,EAAE,CAAF,IAAK,IAAIyC,MAAJ,CAAWkC,KAAKc,KAAL,CAAWvG,IAAE,EAAb,CAAX,CAAL,CAAkCc,EAAE,CAAF,IAAK,IAAIyC,MAAJ,CAAWvD,IAAE,EAAb,CAAL,CAAsB,IAAI+C,IAAEvC,EAAE6C,MAAF,CAAS,CAAT,CAAN,CAAkB,IAAItC,IAAE,EAAN,CAAS,KAAI,IAAIjB,IAAE,CAAV,EAAYA,IAAEiD,EAAElC,MAAF,GAAS,CAAvB,EAAyBf,GAAzB,EAA6B;AAACiB,MAAE+B,IAAF,CAAOM,SAASL,EAAEM,MAAF,CAASvD,IAAE,CAAX,EAAa,CAAb,CAAT,EAAyB,EAAzB,CAAP;AAAqC,OAAIa,IAAE,EAAN,CAAS,IAAIT,IAAE,EAAN,CAAS,KAAI,IAAIJ,IAAE,CAAV,EAAYA,IAAEiB,EAAEF,MAAhB,EAAuBf,GAAvB,EAA2B;AAAC,QAAGiB,EAAEjB,CAAF,IAAK,GAAR,EAAY;AAACI,UAAEA,IAAEH,EAAE,CAACgB,EAAEjB,CAAF,IAAK,GAAN,EAAWgC,QAAX,CAAoB,CAApB,CAAF,EAAyB,CAAzB,CAAJ;AAAgC,KAA7C,MAAiD;AAAC5B,UAAEA,IAAEH,EAAE,CAACgB,EAAEjB,CAAF,IAAK,GAAN,EAAWgC,QAAX,CAAoB,CAApB,CAAF,EAAyB,CAAzB,CAAJ,CAAgCnB,EAAEmC,IAAF,CAAO,IAAIS,MAAJ,CAAWH,SAASlD,CAAT,EAAW,CAAX,CAAX,CAAP,EAAkCA,IAAE,EAAF;AAAK;AAAC,OAAIkB,IAAEN,EAAEoC,IAAF,CAAO,GAAP,CAAN,CAAkB,IAAGvC,EAAEE,MAAF,GAAS,CAAZ,EAAc;AAACO,QAAEA,IAAE,GAAF,GAAMT,EAAEuC,IAAF,CAAO,GAAP,CAAR;AAAoB,UAAO9B,CAAP;AAAS,CAAviB,CAAwiBgiB,QAAQc,IAAR,GAAa,UAAS7hB,CAAT,EAAW5B,CAAX,EAAaK,CAAb,EAAehB,CAAf,EAAiB;AAAC,MAAIuB,IAAE+hB,OAAN,CAAc,IAAIziB,IAAEU,EAAEoiB,IAAR,CAAa,IAAIxb,IAAE5G,EAAE6iB,IAAR,CAAa,IAAI7f,IAAEhD,EAAEuiB,WAAR,CAAoB,IAAIpjB,IAAE6B,CAAN,CAAQ,IAAGA,aAAa2V,KAAKkF,IAAL,CAAUkC,UAA1B,EAAqC;AAAC5e,QAAE6B,EAAE2c,aAAF,EAAF;AAAoB,OAAI1c,IAAE,SAAFA,CAAE,CAAS0F,CAAT,EAAWpH,CAAX,EAAa;AAAC,QAAGoH,EAAEnH,MAAF,IAAUD,IAAE,CAAf,EAAiB;AAAC,aAAOoH,CAAP;AAAS,KAA3B,MAA+B;AAAC,UAAIxD,IAAEwD,EAAE3E,MAAF,CAAS,CAAT,EAAWzC,CAAX,IAAc,WAAd,GAA0BoH,EAAEnH,MAAF,GAAS,CAAnC,GAAqC,UAArC,GAAgDmH,EAAE3E,MAAF,CAAS2E,EAAEnH,MAAF,GAASD,CAAlB,EAAoBA,CAApB,CAAtD,CAA6E,OAAO4D,CAAP;AAAS;AAAC,GAA3I,CAA4I,IAAG/D,MAAId,SAAP,EAAiB;AAACc,QAAE,EAAC0jB,kBAAiB,EAAlB,EAAF;AAAwB,OAAGrjB,MAAInB,SAAP,EAAiB;AAACmB,QAAE,CAAF;AAAI,OAAGhB,MAAIH,SAAP,EAAiB;AAACG,QAAE,EAAF;AAAK,OAAIwE,IAAE7D,EAAE0jB,gBAAR,CAAyB,IAAG3jB,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAGf,KAAG,IAAN,EAAW;AAAC,aAAOD,IAAE,iBAAT;AAA2B,KAAvC,MAA2C;AAAC,aAAOA,IAAE,gBAAT;AAA0B;AAAC,OAAGU,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,OAAOhB,IAAE,UAAF,GAAawC,EAAEvC,CAAF,EAAIuE,CAAJ,CAAb,GAAoB,IAA3B;AAAgC,OAAG9D,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,OAAOhB,IAAE,YAAF,GAAewC,EAAEvC,CAAF,EAAIuE,CAAJ,CAAf,GAAsB,IAA7B;AAAkC,OAAG9D,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAGO,EAAE+iB,SAAF,CAAYrkB,CAAZ,CAAH,EAAkB;AAAC,UAAIgB,IAAEjB,IAAE,6BAAR,CAAsCiB,IAAEA,IAAEkH,EAAElI,CAAF,EAAIU,CAAJ,EAAM,CAAN,EAAQX,IAAE,IAAV,CAAJ,CAAoB,OAAOiB,CAAP;AAAS,KAAtF,MAA0F;AAAC,aAAOjB,IAAE,cAAF,GAAiBwC,EAAEvC,CAAF,EAAIuE,CAAJ,CAAjB,GAAwB,IAA/B;AAAoC;AAAC,OAAG9D,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,QAAT;AAAkB,OAAGU,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIiC,IAAEpC,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAIE,IAAEgX,KAAKkF,IAAL,CAAUC,QAAV,CAAmB8B,WAAnB,CAA+Blc,CAA/B,CAAN,CAAwC,IAAIzB,IAAE0W,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmB8B,QAAnB,CAA4BrjB,CAA5B,CAAN,CAAqC,IAAIT,IAAES,EAAEgc,OAAF,CAAU,KAAV,EAAgB,GAAhB,CAAN,CAA2B,IAAG1b,KAAG,EAAN,EAAS;AAAC,aAAOxB,IAAE,mBAAF,GAAsBwB,CAAtB,GAAwB,IAAxB,GAA6Bf,CAA7B,GAA+B,KAAtC;AAA4C,KAAtD,MAA0D;AAAC,aAAOT,IAAE,oBAAF,GAAuBS,CAAvB,GAAyB,KAAhC;AAAsC;AAAC,OAAGC,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,cAAF,GAAiBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAjB,GAAmC,KAA1C;AAAgD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,mBAAF,GAAsBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAtB,GAAwC,KAA/C;AAAqD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,iBAAF,GAAoBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAApB,GAAsC,KAA7C;AAAmD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,aAAF,GAAgBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAhB,GAAkC,KAAzC;AAA+C,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,UAAF,GAAawkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAb,GAA+B,IAAtC;AAA2C,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,kBAAF,GAAqBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAArB,GAAuC,IAA9C;AAAmD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,aAAOhB,IAAE,eAAT;AAAyB,SAAIiB,IAAEjB,IAAE,YAAR,CAAqB,IAAII,IAAEmE,EAAE7D,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAId,IAAES,CAAN,CAAQ,IAAG,CAACP,EAAEW,MAAF,IAAU,CAAV,IAAaX,EAAEW,MAAF,IAAU,CAAxB,KAA4BL,EAAE6C,MAAF,CAASnD,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAA9C,IAAoDM,EAAE6C,MAAF,CAASnD,EAAEA,EAAEW,MAAF,GAAS,CAAX,CAAT,EAAuB,CAAvB,KAA2B,IAAlF,EAAuF;AAAC,UAAIS,IAAED,EAAEkjB,OAAF,CAAU5jB,EAAEH,CAAF,EAAIN,EAAE,CAAF,CAAJ,CAAV,CAAN,CAA2B,IAAIuC,IAAE+hB,KAAKrhB,KAAL,CAAWqhB,KAAKriB,SAAL,CAAe1B,CAAf,CAAX,CAAN,CAAoCgC,EAAEgiB,WAAF,GAAcnjB,CAAd,CAAgBtB,IAAEyC,CAAF;AAAI,UAAI,IAAIgC,IAAE,CAAV,EAAYA,IAAEvE,EAAEW,MAAhB,EAAuB4D,GAAvB,EAA2B;AAAC1D,UAAEA,IAAEkH,EAAEzH,CAAF,EAAIR,CAAJ,EAAME,EAAEuE,CAAF,CAAN,EAAW3E,IAAE,IAAb,CAAJ;AAAuB,YAAOiB,CAAP;AAAS,OAAGP,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIC,IAAEjB,IAAE,OAAR,CAAgB,IAAII,IAAEmE,EAAE7D,CAAF,EAAIM,CAAJ,CAAN,CAAa,KAAI,IAAI2D,IAAE,CAAV,EAAYA,IAAEvE,EAAEW,MAAhB,EAAuB4D,GAAvB,EAA2B;AAAC1D,UAAEA,IAAEkH,EAAEzH,CAAF,EAAIC,CAAJ,EAAMP,EAAEuE,CAAF,CAAN,EAAW3E,IAAE,IAAb,CAAJ;AAAuB,YAAOiB,CAAP;AAAS,OAAIgH,IAAE3E,SAAS5C,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAN,CAAiC,IAAG,CAACiH,IAAE,GAAH,KAAS,CAAZ,EAAc;AAAC,QAAI3G,IAAE2G,IAAE,EAAR,CAAW,IAAG,CAACA,IAAE,EAAH,KAAQ,CAAX,EAAa;AAAC,UAAIhH,IAAEjB,IAAE,GAAF,GAAMsB,CAAN,GAAQ,KAAd,CAAoB,IAAIlB,IAAEmE,EAAE7D,CAAF,EAAIM,CAAJ,CAAN,CAAa,KAAI,IAAI2D,IAAE,CAAV,EAAYA,IAAEvE,EAAEW,MAAhB,EAAuB4D,GAAvB,EAA2B;AAAC1D,YAAEA,IAAEkH,EAAEzH,CAAF,EAAIC,CAAJ,EAAMP,EAAEuE,CAAF,CAAN,EAAW3E,IAAE,IAAb,CAAJ;AAAuB,cAAOiB,CAAP;AAAS,KAA3G,MAA+G;AAAC,UAAIhB,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAGf,EAAEsD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,UAAlB,EAA6B;AAACtD,YAAEukB,UAAUvkB,CAAV,CAAF;AAAe,WAAGU,EAAEgkB,WAAF,KAAgB,gBAAhB,IAAkCrjB,KAAG,CAAxC,EAA0C;AAACrB,YAAEukB,UAAUvkB,CAAV,CAAF;AAAe,WAAIgB,IAAEjB,IAAE,GAAF,GAAMsB,CAAN,GAAQ,IAAR,GAAarB,CAAb,GAAe,IAArB,CAA0B,OAAOgB,CAAP;AAAS;AAAC,UAAOjB,IAAE,UAAF,GAAaU,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,CAAb,GAA2B,IAA3B,GAAgCH,EAAEH,CAAF,EAAIM,CAAJ,CAAhC,GAAuC,IAA9C;AAAmD,CAAv0E,CAAw0EsiB,QAAQgB,SAAR,GAAkB,UAAS5jB,CAAT,EAAW;AAAC,MAAIN,IAAEkjB,OAAN,CAAc,IAAG5iB,EAAEK,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAAC,WAAO,KAAP;AAAa,OAAIJ,IAAEP,EAAEqjB,QAAF,CAAW/iB,CAAX,EAAa,CAAb,CAAN,CAAsB,IAAID,IAAEC,EAAE6C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAIrD,IAAEE,EAAEojB,IAAF,CAAO9iB,CAAP,EAAS,CAAT,CAAN,CAAkB,IAAIQ,IAAER,EAAEK,MAAF,GAASN,EAAEM,MAAX,GAAkBb,EAAEa,MAA1B,CAAiC,IAAGG,KAAGP,IAAE,CAAR,EAAU;AAAC,WAAO,IAAP;AAAY,UAAO,KAAP;AAAa,CAA5M,CAA6M2iB,QAAQmB,OAAR,GAAgB,UAASvjB,CAAT,EAAW;AAAC,MAAIP,IAAEuX,KAAKkF,IAAX,CAAgB,IAAGlF,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBmhB,KAAjB,CAAuB1jB,CAAvB,CAAH,EAA6B;AAACA,QAAEP,EAAE0c,QAAF,CAAW8B,WAAX,CAAuBje,CAAvB,CAAF;AAA4B,OAAIT,IAAEE,EAAE6hB,IAAF,CAAOC,GAAP,CAAW8B,QAAX,CAAoBrjB,CAApB,CAAN,CAA6B,IAAGT,MAAI,EAAP,EAAU;AAACA,QAAES,CAAF;AAAI,UAAOT,CAAP;AAAS,CAA3J;AACp8J,IAAIyX,IAAJ,CAAS,IAAG,OAAOA,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UA2EpCA,IA3EoC,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKpY,IAAZ,IAAkB,WAAlB,IAA+B,CAACoY,KAAKpY,IAAxC,EAA6C;AAACoY,OAAKpY,IAAL,GAAU,EAAV;AAAa,MAAKA,IAAL,CAAU2D,MAAV,GAAiB,YAAU,CAAE,CAA7B,CAA8B,SAASohB,OAAT,GAAkB,CAAE,UAASC,KAAT,CAAe1kB,CAAf,EAAiB;AAAC,MAAIK,IAAE,IAAIgJ,KAAJ,EAAN,CAAkB,KAAI,IAAI9I,IAAE,CAAV,EAAYA,IAAEP,EAAEW,MAAhB,EAAuBJ,GAAvB,EAA2B;AAACF,MAAEE,CAAF,IAAKP,EAAEuD,UAAF,CAAahD,CAAb,CAAL;AAAqB,UAAOF,CAAP;AAAS,UAASskB,KAAT,CAAetkB,CAAf,EAAiB;AAAC,MAAIL,IAAE,EAAN,CAAS,KAAI,IAAIO,IAAE,CAAV,EAAYA,IAAEF,EAAEM,MAAhB,EAAuBJ,GAAvB,EAA2B;AAACP,QAAEA,IAAEqD,OAAOC,YAAP,CAAoBjD,EAAEE,CAAF,CAApB,CAAJ;AAA8B,UAAOP,CAAP;AAAS,UAAS4kB,OAAT,CAAiBvkB,CAAjB,EAAmB;AAAC,MAAIC,IAAE,EAAN,CAAS,KAAI,IAAIN,IAAE,CAAV,EAAYA,IAAEK,EAAEM,MAAhB,EAAuBX,GAAvB,EAA2B;AAAC,QAAIO,IAAEF,EAAEL,CAAF,EAAK4B,QAAL,CAAc,EAAd,CAAN,CAAwB,IAAGrB,EAAEI,MAAF,IAAU,CAAb,EAAe;AAACJ,UAAE,MAAIA,CAAN;AAAQ,SAAED,IAAEC,CAAJ;AAAM,UAAOD,CAAP;AAAS,UAAS0gB,MAAT,CAAgBlgB,CAAhB,EAAkB;AAAC,SAAO8jB,QAAQF,MAAM5jB,CAAN,CAAR,CAAP;AAAyB,UAAS+jB,MAAT,CAAgB/jB,CAAhB,EAAkB;AAAC,SAAOkI,QAAQgY,OAAOlgB,CAAP,CAAR,CAAP;AAA0B,UAASgkB,OAAT,CAAiBhkB,CAAjB,EAAmB;AAAC,SAAOikB,UAAU/b,QAAQgY,OAAOlgB,CAAP,CAAR,CAAV,CAAP;AAAqC,UAASkkB,OAAT,CAAiBlkB,CAAjB,EAAmB;AAAC,SAAO6jB,MAAMvb,QAAQ6b,UAAUnkB,CAAV,CAAR,CAAN,CAAP;AAAoC,UAASikB,SAAT,CAAmBjkB,CAAnB,EAAqB;AAACA,MAAEA,EAAEgc,OAAF,CAAU,KAAV,EAAgB,EAAhB,CAAF,CAAsBhc,IAAEA,EAAEgc,OAAF,CAAU,KAAV,EAAgB,GAAhB,CAAF,CAAuBhc,IAAEA,EAAEgc,OAAF,CAAU,KAAV,EAAgB,GAAhB,CAAF,CAAuB,OAAOhc,CAAP;AAAS,UAASmkB,SAAT,CAAmBnkB,CAAnB,EAAqB;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACG,QAAEA,IAAE,IAAJ;AAAS,GAA3B,MAA+B;AAAC,QAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACG,UAAEA,IAAE,GAAJ;AAAQ;AAAC,OAAEA,EAAEgc,OAAF,CAAU,IAAV,EAAe,GAAf,CAAF,CAAsBhc,IAAEA,EAAEgc,OAAF,CAAU,IAAV,EAAe,GAAf,CAAF,CAAsB,OAAOhc,CAAP;AAAS,UAASokB,SAAT,CAAmBpkB,CAAnB,EAAqB;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACG,QAAE,MAAIA,CAAN;AAAQ,UAAOikB,UAAU/b,QAAQlI,CAAR,CAAV,CAAP;AAA6B,UAASqkB,SAAT,CAAmBrkB,CAAnB,EAAqB;AAAC,SAAOoI,SAAS+b,UAAUnkB,CAAV,CAAT,CAAP;AAA8B,KAAIskB,UAAJ,EAAeC,UAAf,CAA0B,IAAG,OAAOC,MAAP,KAAgB,UAAnB,EAA8B;AAAC,UA0C1jCF,UA1C0jC,gBAAW,oBAAStkB,CAAT,EAAW;AAAC,WAAOikB,UAAU,IAAIO,MAAJ,CAAWxkB,CAAX,EAAa,MAAb,EAAqBc,QAArB,CAA8B,QAA9B,CAAV,CAAP;AAA0D,GAAjF,CAAkF,QA2C5oCyjB,UA3C4oC,gBAAW,oBAASvkB,CAAT,EAAW;AAAC,WAAO,IAAIwkB,MAAJ,CAAWL,UAAUnkB,CAAV,CAAX,EAAwB,QAAxB,EAAkCc,QAAlC,CAA2C,MAA3C,CAAP;AAA0D,GAAjF;AAAkF,CAAnM,MAAuM;AAAC,UA0CnuCwjB,UA1CmuC,gBAAW,oBAAStkB,CAAT,EAAW;AAAC,WAAOokB,UAAUK,YAAYC,sBAAsB1kB,CAAtB,CAAZ,CAAV,CAAP;AAAwD,GAA/E,CAAgF,QA2CnzCukB,UA3CmzC,gBAAW,oBAASvkB,CAAT,EAAW;AAAC,WAAO2C,mBAAmBgiB,YAAYN,UAAUrkB,CAAV,CAAZ,CAAnB,CAAP;AAAqD,GAA5E;AAA6E,UAAS4kB,SAAT,CAAmB5kB,CAAnB,EAAqB;AAAC,SAAOkI,QAAQuc,YAAYC,sBAAsB1kB,CAAtB,CAAZ,CAAR,CAAP;AAAsD,UAAS6kB,SAAT,CAAmB7kB,CAAnB,EAAqB;AAAC,SAAO2C,mBAAmBgiB,YAAYvc,SAASpI,CAAT,CAAZ,CAAnB,CAAP;AAAoD,UAASgf,SAAT,CAAmBhf,CAAnB,EAAqB;AAAC,SAAOykB,YAAYC,sBAAsB1kB,CAAtB,CAAZ,CAAP;AAA6C,UAASsjB,SAAT,CAAmBtjB,CAAnB,EAAqB;AAAC,SAAO2C,mBAAmBgiB,YAAY3kB,CAAZ,CAAnB,CAAP;AAA0C,UAASqX,SAAT,CAAmB5X,CAAnB,EAAqB;AAAC,MAAIF,IAAE,EAAN,CAAS,KAAI,IAAIS,IAAE,CAAV,EAAYA,IAAEP,EAAEI,MAAF,GAAS,CAAvB,EAAyBG,KAAG,CAA5B,EAA8B;AAACT,SAAGgD,OAAOC,YAAP,CAAoBJ,SAAS3C,EAAE4C,MAAF,CAASrC,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAApB,CAAH;AAAmD,UAAOT,CAAP;AAAS,UAASgY,SAAT,CAAmB9X,CAAnB,EAAqB;AAAC,MAAIO,IAAE,EAAN,CAAS,KAAI,IAAIT,IAAE,CAAV,EAAYA,IAAEE,EAAEI,MAAhB,EAAuBN,GAAvB,EAA2B;AAACS,SAAG,CAAC,MAAIP,EAAEgD,UAAF,CAAalD,CAAb,EAAgBuB,QAAhB,CAAyB,EAAzB,CAAL,EAAmCc,KAAnC,CAAyC,CAAC,CAA1C,CAAH;AAAgD,UAAO5B,CAAP;AAAS,UAAS8kB,QAAT,CAAkB9kB,CAAlB,EAAoB;AAAC,SAAOkI,QAAQlI,CAAR,CAAP;AAAkB,UAAS+kB,UAAT,CAAoBxlB,CAApB,EAAsB;AAAC,MAAIS,IAAE8kB,SAASvlB,CAAT,CAAN,CAAkB,IAAIE,IAAEO,EAAEgc,OAAF,CAAU,UAAV,EAAqB,QAArB,CAAN,CAAqCvc,IAAEA,EAAEuc,OAAF,CAAU,OAAV,EAAkB,EAAlB,CAAF,CAAwB,OAAOvc,CAAP;AAAS,UAASulB,UAAT,CAAoBzlB,CAApB,EAAsB;AAAC,MAAIS,IAAET,EAAEyc,OAAF,CAAU,oBAAV,EAA+B,EAA/B,CAAN,CAAyC,IAAIvc,IAAE2I,SAASpI,CAAT,CAAN,CAAkB,OAAOP,CAAP;AAAS,UAAS8c,QAAT,CAAkBvc,CAAlB,EAAoBT,CAApB,EAAsB;AAAC,MAAIE,IAAEslB,WAAW/kB,CAAX,CAAN,CAAoB,OAAM,gBAAcT,CAAd,GAAgB,WAAhB,GAA4BE,CAA5B,GAA8B,eAA9B,GAA8CF,CAA9C,GAAgD,WAAtD;AAAkE,UAAS0lB,QAAT,CAAkBjlB,CAAlB,EAAoBT,CAApB,EAAsB;AAAC,MAAGS,EAAEkF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAA9B,EAAgC;AAAC,UAAK,4BAA0B3F,CAA/B;AAAiC,OAAGA,MAAIZ,SAAP,EAAiB;AAACqB,QAAEA,EAAEgc,OAAF,CAAU,gBAAczc,CAAd,GAAgB,OAA1B,EAAkC,EAAlC,CAAF,CAAwCS,IAAEA,EAAEgc,OAAF,CAAU,cAAYzc,CAAZ,GAAc,OAAxB,EAAgC,EAAhC,CAAF;AAAsC,GAAhG,MAAoG;AAACS,QAAEA,EAAEgc,OAAF,CAAU,uBAAV,EAAkC,EAAlC,CAAF,CAAwChc,IAAEA,EAAEgc,OAAF,CAAU,qBAAV,EAAgC,EAAhC,CAAF;AAAsC,UAAOgJ,WAAWhlB,CAAX,CAAP;AAAqB,UAASklB,gBAAT,CAA0BhmB,CAA1B,EAA4B;AAAC,MAAGA,EAAEW,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAAC,UAAK,0BAAL;AAAgC,OAAGX,EAAE6c,KAAF,CAAQ,gBAAR,KAA2B,IAA9B,EAAmC;AAAC,UAAK,0BAAL;AAAgC,OAAIxc,IAAE,IAAI4lB,WAAJ,CAAgBjmB,EAAEW,MAAF,GAAS,CAAzB,CAAN,CAAkC,IAAIG,IAAE,IAAIolB,QAAJ,CAAa7lB,CAAb,CAAN,CAAsB,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEP,EAAEW,MAAF,GAAS,CAAvB,EAAyBJ,GAAzB,EAA6B;AAACO,MAAEqlB,QAAF,CAAW5lB,CAAX,EAAa2C,SAASlD,EAAEmD,MAAF,CAAS5C,IAAE,CAAX,EAAa,CAAb,CAAT,EAAyB,EAAzB,CAAb;AAA2C,UAAOF,CAAP;AAAS,UAAS+lB,gBAAT,CAA0B/lB,CAA1B,EAA4B;AAAC,MAAIL,IAAE,EAAN,CAAS,IAAIc,IAAE,IAAIolB,QAAJ,CAAa7lB,CAAb,CAAN,CAAsB,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEF,EAAEgmB,UAAhB,EAA2B9lB,GAA3B,EAA+B;AAACP,SAAG,CAAC,OAAKc,EAAEwlB,QAAF,CAAW/lB,CAAX,EAAcqB,QAAd,CAAuB,EAAvB,CAAN,EAAkCc,KAAlC,CAAwC,CAAC,CAAzC,CAAH;AAA+C,UAAO1C,CAAP;AAAS,UAASumB,UAAT,CAAoBrlB,CAApB,EAAsB;AAAC,MAAIN,CAAJ,EAAMH,CAAN,EAAQoC,CAAR,EAAUvC,CAAV,EAAYR,CAAZ,EAAcY,CAAd,EAAgBL,CAAhB,EAAkBQ,CAAlB,CAAoB,IAAIC,CAAJ,EAAMjB,CAAN,EAAQD,CAAR,EAAUW,CAAV,CAAYA,IAAEW,EAAE2b,KAAF,CAAQ,wDAAR,CAAF,CAAoE,IAAGtc,CAAH,EAAK;AAACO,QAAEP,EAAE,CAAF,CAAF,CAAOK,IAAEsC,SAASpC,CAAT,CAAF,CAAc,IAAGA,EAAEH,MAAF,KAAW,CAAd,EAAgB;AAAC,UAAG,MAAIC,CAAJ,IAAOA,IAAE,GAAZ,EAAgB;AAACA,YAAE,OAAKA,CAAP;AAAS,OAA1B,MAA8B;AAAC,YAAG,KAAGA,CAAH,IAAMA,IAAE,EAAX,EAAc;AAACA,cAAE,OAAKA,CAAP;AAAS;AAAC;AAAC,SAAEsC,SAAS3C,EAAE,CAAF,CAAT,IAAe,CAAjB,CAAmBsC,IAAEK,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBD,IAAE4C,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBT,IAAEoD,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBG,IAAEwC,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBF,IAAE,CAAF,CAAIR,IAAEU,EAAE,CAAF,CAAF,CAAO,IAAGV,MAAI,EAAP,EAAU;AAACD,UAAE,CAACC,EAAEsD,MAAF,CAAS,CAAT,IAAY,IAAb,EAAmBA,MAAnB,CAA0B,CAA1B,EAA4B,CAA5B,CAAF,CAAiC9C,IAAE6C,SAAStD,CAAT,CAAF;AAAc,YAAOiX,KAAKqK,GAAL,CAAStgB,CAAT,EAAWH,CAAX,EAAaoC,CAAb,EAAevC,CAAf,EAAiBR,CAAjB,EAAmBY,CAAnB,EAAqBL,CAArB,CAAP;AAA+B,SAAK,8BAA4Ba,CAAjC;AAAmC,UAASslB,SAAT,CAAmB1lB,CAAnB,EAAqB;AAAC,MAAIT,IAAEkmB,WAAWzlB,CAAX,CAAN,CAAoB,OAAO,CAAC,EAAET,IAAE,IAAJ,CAAR;AAAkB,UAASomB,UAAT,CAAoB3lB,CAApB,EAAsB;AAAC,SAAO,IAAI+V,IAAJ,CAAS0P,WAAWzlB,CAAX,CAAT,CAAP;AAA+B,UAAS4lB,UAAT,CAAoB9mB,CAApB,EAAsBU,CAAtB,EAAwBR,CAAxB,EAA0B;AAAC,MAAIO,CAAJ,CAAM,IAAIS,IAAElB,EAAE+mB,cAAF,EAAN,CAAyB,IAAGrmB,CAAH,EAAK;AAAC,QAAGQ,IAAE,IAAF,IAAQ,OAAKA,CAAhB,EAAkB;AAAC,YAAK,kCAAgCA,CAArC;AAAuC,SAAE,CAAC,KAAGA,CAAJ,EAAO4B,KAAP,CAAa,CAAC,CAAd,CAAF;AAAmB,GAAnF,MAAuF;AAACrC,QAAE,CAAC,QAAMS,CAAP,EAAU4B,KAAV,CAAgB,CAAC,CAAjB,CAAF;AAAsB,QAAG,CAAC,OAAK9C,EAAEgnB,WAAF,KAAgB,CAArB,CAAD,EAA0BlkB,KAA1B,CAAgC,CAAC,CAAjC,CAAH,CAAuCrC,KAAG,CAAC,MAAIT,EAAEinB,UAAF,EAAL,EAAqBnkB,KAArB,CAA2B,CAAC,CAA5B,CAAH,CAAkCrC,KAAG,CAAC,MAAIT,EAAEknB,WAAF,EAAL,EAAsBpkB,KAAtB,CAA4B,CAAC,CAA7B,CAAH,CAAmCrC,KAAG,CAAC,MAAIT,EAAEmnB,aAAF,EAAL,EAAwBrkB,KAAxB,CAA8B,CAAC,CAA/B,CAAH,CAAqCrC,KAAG,CAAC,MAAIT,EAAEonB,aAAF,EAAL,EAAwBtkB,KAAxB,CAA8B,CAAC,CAA/B,CAAH,CAAqC,IAAG5C,CAAH,EAAK;AAAC,QAAIS,IAAEX,EAAEqnB,kBAAF,EAAN,CAA6B,IAAG1mB,MAAI,CAAP,EAAS;AAACA,UAAE,CAAC,OAAKA,CAAN,EAASmC,KAAT,CAAe,CAAC,CAAhB,CAAF,CAAqBnC,IAAEA,EAAEuc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuBzc,KAAG,MAAIE,CAAP;AAAS;AAAC,QAAG,GAAH,CAAO,OAAOF,CAAP;AAAS,UAASklB,WAAT,CAAqBzkB,CAArB,EAAuB;AAAC,SAAOA,EAAEgc,OAAF,CAAU,IAAV,EAAe,EAAf,CAAP;AAA0B,UAAS2I,WAAT,CAAqB3kB,CAArB,EAAuB;AAAC,SAAOA,EAAEgc,OAAF,CAAU,OAAV,EAAkB,KAAlB,CAAP;AAAgC,UAASoK,SAAT,CAAmBtnB,CAAnB,EAAqB;AAAC,MAAIS,IAAE,wBAAN,CAA+B,IAAG,CAACT,EAAEid,KAAF,CAAQ,iBAAR,CAAJ,EAA+B;AAAC,UAAMxc,CAAN;AAAQ,OAAET,EAAEmgB,WAAF,EAAF,CAAkB,IAAI/f,IAAEJ,EAAEqf,KAAF,CAAQ,GAAR,EAAate,MAAb,GAAoB,CAA1B,CAA4B,IAAGX,IAAE,CAAL,EAAO;AAAC,UAAMK,CAAN;AAAQ,OAAIC,IAAE,IAAI6mB,MAAJ,CAAW,IAAEnnB,CAAF,GAAI,CAAf,CAAN,CAAwBJ,IAAEA,EAAEkd,OAAF,CAAU,IAAV,EAAexc,CAAf,CAAF,CAAoB,IAAIC,IAAEX,EAAEqf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAG1e,EAAEI,MAAF,IAAU,CAAb,EAAe;AAAC,UAAMN,CAAN;AAAQ,QAAI,IAAIP,IAAE,CAAV,EAAYA,IAAE,CAAd,EAAgBA,GAAhB,EAAoB;AAACS,MAAET,CAAF,IAAK,CAAC,SAAOS,EAAET,CAAF,CAAR,EAAc4C,KAAd,CAAoB,CAAC,CAArB,CAAL;AAA6B,UAAOnC,EAAEyC,IAAF,CAAO,EAAP,CAAP;AAAkB,UAASokB,SAAT,CAAmB9mB,CAAnB,EAAqB;AAAC,MAAG,CAACA,EAAEuc,KAAF,CAAQ,mBAAR,CAAJ,EAAiC;AAAC,UAAK,8BAAL;AAAoC,OAAEvc,EAAEyf,WAAF,EAAF,CAAkB,IAAI1f,IAAEC,EAAEuc,KAAF,CAAQ,SAAR,CAAN,CAAyB,KAAI,IAAI7c,IAAE,CAAV,EAAYA,IAAE,CAAd,EAAgBA,GAAhB,EAAoB;AAACK,MAAEL,CAAF,IAAKK,EAAEL,CAAF,EAAK8c,OAAL,CAAa,KAAb,EAAmB,EAAnB,CAAL,CAA4B,IAAGzc,EAAEL,CAAF,KAAM,EAAT,EAAY;AAACK,QAAEL,CAAF,IAAK,GAAL;AAAS;AAAC,OAAE,MAAIK,EAAE2C,IAAF,CAAO,GAAP,CAAJ,GAAgB,GAAlB,CAAsB,IAAIzC,IAAED,EAAEuc,KAAF,CAAQ,YAAR,CAAN,CAA4B,IAAGtc,MAAI,IAAP,EAAY;AAAC,WAAOD,EAAEoC,KAAF,CAAQ,CAAR,EAAU,CAAC,CAAX,CAAP;AAAqB,OAAI5C,IAAE,EAAN,CAAS,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEO,EAAEI,MAAhB,EAAuBX,GAAvB,EAA2B;AAAC,QAAGO,EAAEP,CAAF,EAAKW,MAAL,GAAYb,EAAEa,MAAjB,EAAwB;AAACb,UAAES,EAAEP,CAAF,CAAF;AAAO;AAAC,OAAEM,EAAEwc,OAAF,CAAUhd,CAAV,EAAY,IAAZ,CAAF,CAAoB,OAAOQ,EAAEoC,KAAF,CAAQ,CAAR,EAAU,CAAC,CAAX,CAAP;AAAqB,UAAS2kB,OAAT,CAAiBhnB,CAAjB,EAAmB;AAAC,MAAIL,IAAE,qBAAN,CAA4B,IAAG,CAACK,EAAEwc,KAAF,CAAQ,gCAAR,CAAJ,EAA8C;AAAC,UAAM7c,CAAN;AAAQ,OAAGK,EAAEM,MAAF,IAAU,CAAb,EAAe;AAAC,QAAIJ,CAAJ,CAAM,IAAG;AAACA,UAAE2C,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,IAA2B,GAA3B,GAA+BD,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAA/B,GAA0D,GAA1D,GAA8DD,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAA9D,GAAyF,GAAzF,GAA6FD,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAA/F,CAA0H,OAAO5C,CAAP;AAAS,KAAvI,CAAuI,OAAMO,CAAN,EAAQ;AAAC,YAAMd,CAAN;AAAQ;AAAC,GAA/K,MAAmL;AAAC,QAAGK,EAAEM,MAAF,IAAU,EAAb,EAAgB;AAAC,aAAOymB,UAAU/mB,CAAV,CAAP;AAAoB,KAArC,MAAyC;AAAC,aAAOA,CAAP;AAAS;AAAC;AAAC,UAASinB,OAAT,CAAiBxnB,CAAjB,EAAmB;AAAC,MAAIW,IAAE,sBAAN,CAA6BX,IAAEA,EAAEigB,WAAF,CAAcjgB,CAAd,CAAF,CAAmB,IAAGA,EAAE+c,KAAF,CAAQ,WAAR,CAAH,EAAwB;AAAC,QAAIxc,IAAEP,EAAEmf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAG5e,EAAEM,MAAF,KAAW,CAAd,EAAgB;AAAC,YAAMF,CAAN;AAAQ,SAAIb,IAAE,EAAN,CAAS,IAAG;AAAC,WAAI,IAAIU,IAAE,CAAV,EAAYA,IAAE,CAAd,EAAgBA,GAAhB,EAAoB;AAAC,YAAIT,IAAEqD,SAAS7C,EAAEC,CAAF,CAAT,CAAN,CAAqBV,KAAG,CAAC,MAAIC,EAAE+B,QAAF,CAAW,EAAX,CAAL,EAAqBc,KAArB,CAA2B,CAAC,CAA5B,CAAH;AAAkC,cAAO9C,CAAP;AAAS,KAAzF,CAAyF,OAAMW,CAAN,EAAQ;AAAC,YAAME,CAAN;AAAQ;AAAC,GAAzL,MAA6L;AAAC,QAAGX,EAAE+c,KAAF,CAAQ,cAAR,KAAyB/c,EAAEkG,OAAF,CAAU,GAAV,MAAiB,CAAC,CAA9C,EAAgD;AAAC,aAAOkhB,UAAUpnB,CAAV,CAAP;AAAoB,KAArE,MAAyE;AAAC,YAAMW,CAAN;AAAQ;AAAC;AAAC,UAAS+kB,qBAAT,CAA+B1kB,CAA/B,EAAiC;AAAC,MAAId,IAAE4D,mBAAmB9C,CAAnB,CAAN,CAA4B,IAAIT,IAAE,EAAN,CAAS,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEP,EAAEW,MAAhB,EAAuBJ,GAAvB,EAA2B;AAAC,QAAGP,EAAEO,CAAF,KAAM,GAAT,EAAa;AAACF,UAAEA,IAAEL,EAAEmD,MAAF,CAAS5C,CAAT,EAAW,CAAX,CAAJ,CAAkBA,IAAEA,IAAE,CAAJ;AAAM,KAAtC,MAA0C;AAACF,UAAEA,IAAE,GAAF,GAAM2gB,OAAOhhB,EAAEO,CAAF,CAAP,CAAR;AAAqB;AAAC,UAAOF,CAAP;AAAS,UAASknB,cAAT,CAAwBzmB,CAAxB,EAA0B;AAACA,MAAEA,EAAEgc,OAAF,CAAU,QAAV,EAAmB,IAAnB,CAAF,CAA2B,OAAOhc,CAAP;AAAS,UAAS0mB,aAAT,CAAuB1mB,CAAvB,EAAyB;AAACA,MAAEA,EAAEgc,OAAF,CAAU,QAAV,EAAmB,IAAnB,CAAF,CAA2Bhc,IAAEA,EAAEgc,OAAF,CAAU,MAAV,EAAiB,MAAjB,CAAF,CAA2B,OAAOhc,CAAP;AAAS,MAAKpB,IAAL,CAAU2D,MAAV,CAAiBokB,SAAjB,GAA2B,UAAS3mB,CAAT,EAAW;AAAC,MAAGA,EAAE+b,KAAF,CAAQ,UAAR,CAAH,EAAuB;AAAC,WAAO,IAAP;AAAY,GAApC,MAAwC;AAAC,QAAG/b,EAAE+b,KAAF,CAAQ,WAAR,CAAH,EAAwB;AAAC,aAAO,IAAP;AAAY,KAArC,MAAyC;AAAC,aAAO,KAAP;AAAa;AAAC;AAAC,CAAzI,CAA0I/E,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBmhB,KAAjB,GAAuB,UAAS1jB,CAAT,EAAW;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAZ,KAAgBG,EAAE+b,KAAF,CAAQ,aAAR,KAAwB/b,EAAE+b,KAAF,CAAQ,aAAR,CAAxC,CAAH,EAAmE;AAAC,WAAO,IAAP;AAAY,GAAhF,MAAoF;AAAC,WAAO,KAAP;AAAa;AAAC,CAAtI,CAAuI/E,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBqkB,QAAjB,GAA0B,UAAS5mB,CAAT,EAAW;AAACA,MAAEA,EAAEgc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB,IAAGhc,EAAE+b,KAAF,CAAQ,yBAAR,KAAoC/b,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAnD,EAAqD;AAAC,WAAO,IAAP;AAAY,GAAlE,MAAsE;AAAC,WAAO,KAAP;AAAa;AAAC,CAAlJ,CAAmJmX,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBskB,WAAjB,GAA6B,UAAS7mB,CAAT,EAAW;AAAC,MAAGA,EAAE+b,KAAF,CAAQ,OAAR,CAAH,EAAoB;AAAC,WAAO,KAAP;AAAa,OAAEoI,UAAUnkB,CAAV,CAAF,CAAe,OAAOgX,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBqkB,QAAjB,CAA0B5mB,CAA1B,CAAP;AAAoC,CAA9H,CAA+HgX,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBukB,cAAjB,GAAgC,UAAS9mB,CAAT,EAAW;AAACA,MAAEA,EAAEgc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB,IAAGhc,EAAE+b,KAAF,CAAQ,eAAR,CAAH,EAA4B;AAAC,WAAO,IAAP;AAAY,GAAzC,MAA6C;AAAC,WAAO,KAAP;AAAa;AAAC,CAA/H,CAAgI,SAASgL,WAAT,CAAqB/mB,CAArB,EAAuB;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAAC,WAAM,MAAIG,CAAV;AAAY,OAAGA,EAAEqC,MAAF,CAAS,CAAT,EAAW,CAAX,IAAc,GAAjB,EAAqB;AAAC,WAAM,OAAKrC,CAAX;AAAa,UAAOA,CAAP;AAAS,UAASgnB,cAAT,CAAwBznB,CAAxB,EAA0B;AAACA,MAAEA,EAAEyc,OAAF,CAAU,WAAV,EAAsB,EAAtB,CAAF,CAA4Bzc,IAAEA,EAAEyc,OAAF,CAAU,WAAV,EAAsB,EAAtB,CAAF,CAA4Bzc,IAAEA,EAAEyc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB,IAAG;AAAC,QAAIvc,IAAEF,EAAE4e,KAAF,CAAQ,GAAR,EAAa8I,GAAb,CAAiB,UAASnoB,CAAT,EAAWU,CAAX,EAAaT,CAAb,EAAe;AAAC,UAAIC,IAAEoD,SAAStD,CAAT,CAAN,CAAkB,IAAGE,IAAE,CAAF,IAAK,MAAIA,CAAZ,EAAc;AAAC,cAAK,4BAAL;AAAkC,WAAIE,IAAE,CAAC,OAAKF,EAAE8B,QAAF,CAAW,EAAX,CAAN,EAAsBc,KAAtB,CAA4B,CAAC,CAA7B,CAAN,CAAsC,OAAO1C,CAAP;AAAS,KAAnJ,EAAqJgD,IAArJ,CAA0J,EAA1J,CAAN,CAAoK,OAAOzC,CAAP;AAAS,GAAjL,CAAiL,OAAMO,CAAN,EAAQ;AAAC,UAAK,qCAAmCA,CAAxC;AAA0C;AAAC,KAAIknB,aAAW,SAAXA,UAAW,CAASznB,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAId,IAAEO,EAAEI,MAAR,CAAe,IAAGJ,EAAEI,MAAF,GAASG,EAAEH,MAAd,EAAqB;AAACX,QAAEc,EAAEH,MAAJ;AAAW,QAAI,IAAIN,IAAE,CAAV,EAAYA,IAAEL,CAAd,EAAgBK,GAAhB,EAAoB;AAAC,QAAGE,EAAEgD,UAAF,CAAalD,CAAb,KAAiBS,EAAEyC,UAAF,CAAalD,CAAb,CAApB,EAAoC;AAAC,aAAOA,CAAP;AAAS;AAAC,OAAGE,EAAEI,MAAF,IAAUG,EAAEH,MAAf,EAAsB;AAAC,WAAOX,CAAP;AAAS,UAAO,CAAC,CAAR;AAAU,CAA3L;AAClzN,IAAG,OAAO8X,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UA0E3BA,IA1E2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKf,MAAZ,IAAoB,WAApB,IAAiC,CAACe,KAAKf,MAA1C,EAAiD;AAACe,OAAKf,MAAL,GAAY,EAAZ;AAAe,MAAKA,MAAL,CAAYiB,IAAZ,GAAiB,IAAI,YAAU;AAAC,OAAKiQ,cAAL,GAAoB,EAACC,MAAK,gCAAN,EAAuCC,QAAO,wCAA9C,EAAuFC,QAAO,wCAA9F,EAAuIC,QAAO,wCAA9I,EAAuLC,QAAO,wCAA9L,EAAuOC,KAAI,sCAA3O,EAAkRC,KAAI,sCAAtR,EAA6TC,WAAU,gCAAvU,EAApB,CAA8X,KAAKC,eAAL,GAAqB,EAACF,KAAI,UAAL,EAAgBN,MAAK,UAArB,EAAgCC,QAAO,UAAvC,EAAkDC,QAAO,UAAzD,EAAoEC,QAAO,UAA3E,EAAsFC,QAAO,UAA7F,EAAwGG,WAAU,UAAlH,EAA6HE,SAAQ,UAArI,EAAgJC,UAAS,UAAzJ,EAAoKC,YAAW,UAA/K,EAA0LC,YAAW,UAArM,EAAgNC,YAAW,UAA3N,EAAsOC,YAAW,UAAjP,EAA4PC,eAAc,UAA1Q,EAAqRC,YAAW,gBAAhS,EAAiTC,aAAY,gBAA7T,EAA8UC,eAAc,gBAA5V,EAA6WC,eAAc,gBAA3X,EAA4YC,eAAc,gBAA1Z,EAA2aC,eAAc,gBAAzb,EAA0cC,kBAAiB,gBAA3d,EAA4eC,cAAa,gBAAzf,EAA0gBC,eAAc,gBAAxhB,EAAyiBC,iBAAgB,gBAAzjB,EAA0kBC,iBAAgB,gBAA1lB,EAA2mBC,iBAAgB,gBAA3nB,EAA4oBC,iBAAgB,gBAA5pB,EAA6qBC,oBAAmB,gBAAhsB,EAAitBC,aAAY,gBAA7tB,EAA8uBC,eAAc,gBAA5vB,EAA6wBC,eAAc,gBAA3xB,EAA4yBC,mBAAkB,gBAA9zB,EAA+0BC,oBAAmB,gBAAl2B,EAAm3BC,sBAAqB,gBAAx4B,EAAy5BC,sBAAqB,gBAA96B,EAA+7BC,sBAAqB,gBAAp9B,EAAq+BC,sBAAqB,gBAA1/B,EAA2gCC,yBAAwB,gBAAniC,EAArB,CAA2kC,KAAKC,yBAAL,GAA+B,EAAClC,KAAIznB,SAASuE,IAAT,CAAcqlB,GAAnB,EAAuBzC,MAAKnnB,SAASuE,IAAT,CAAcslB,IAA1C,EAA+CzC,QAAOpnB,SAASuE,IAAT,CAAculB,MAApE,EAA2EzC,QAAOrnB,SAASuE,IAAT,CAAca,MAAhG,EAAuGkiB,QAAOtnB,SAASuE,IAAT,CAAcsD,MAA5H,EAAmI0f,QAAOvnB,SAASuE,IAAT,CAAcmB,MAAxJ,EAA+JgiB,WAAU1nB,SAASuE,IAAT,CAAcwlB,SAAvL,EAA/B,CAAiO,KAAKC,gBAAL,GAAsB,UAASjqB,CAAT,EAAWT,CAAX,EAAa;AAAC,QAAG,OAAO,KAAK4nB,cAAL,CAAoB5nB,CAApB,CAAP,IAA+B,WAAlC,EAA8C;AAAC,YAAK,+CAA6CA,CAAlD;AAAoD,YAAO,KAAK4nB,cAAL,CAAoB5nB,CAApB,IAAuBS,CAA9B;AAAgC,GAAvK,CAAwK,KAAKkqB,sBAAL,GAA4B,UAASnrB,CAAT,EAAWiB,CAAX,EAAaL,CAAb,EAAe;AAAC,QAAIF,IAAE,KAAKwqB,gBAAL,CAAsBlrB,CAAtB,EAAwBiB,CAAxB,CAAN,CAAiC,IAAId,IAAES,IAAE,CAAR,CAAU,IAAGF,EAAEI,MAAF,GAAS,EAAT,GAAYX,CAAf,EAAiB;AAAC,YAAK,yCAAuCS,CAAvC,GAAyC,GAAzC,GAA6CK,CAAlD;AAAoD,SAAIT,IAAE,MAAN,CAAa,IAAIQ,IAAE,OAAKN,CAAX,CAAa,IAAIX,IAAE,EAAN,CAAS,IAAIgB,IAAEZ,IAAEK,EAAEM,MAAJ,GAAWE,EAAEF,MAAnB,CAA0B,KAAI,IAAIb,IAAE,CAAV,EAAYA,IAAEc,CAAd,EAAgBd,KAAG,CAAnB,EAAqB;AAACF,WAAG,IAAH;AAAQ,SAAIU,IAAED,IAAET,CAAF,GAAIiB,CAAV,CAAY,OAAOP,CAAP;AAAS,GAA7Q,CAA8Q,KAAK2qB,UAAL,GAAgB,UAASnqB,CAAT,EAAWP,CAAX,EAAa;AAAC,QAAIF,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI3qB,CAAL,EAA9B,CAAN,CAA6C,OAAOF,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAApG,CAAqG,KAAKsX,OAAL,GAAa,UAAS/X,CAAT,EAAWE,CAAX,EAAa;AAAC,QAAIO,IAAE,IAAIgX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI3qB,CAAL,EAA9B,CAAN,CAA6C,OAAOO,EAAEsqB,SAAF,CAAY/qB,CAAZ,CAAP;AAAsB,GAA9F,CAA+F,KAAK6nB,IAAL,GAAU,UAASpnB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,MAAL,EAAYG,MAAK,UAAjB,EAA9B,CAAN,CAAkE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAAjH,CAAkH,KAAKsnB,MAAL,GAAY,UAAStnB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAArH,CAAsH,KAAKwqB,SAAL,GAAe,UAASxqB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE+qB,SAAF,CAAYtqB,CAAZ,CAAP;AAAsB,GAArH,CAAsH,KAAKwnB,MAAL,GAAY,UAASxnB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAArH,CAAsH,KAAKyqB,SAAL,GAAe,UAASzqB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE+qB,SAAF,CAAYtqB,CAAZ,CAAP;AAAsB,GAArH;AAAsH,CAA73F,EAAjB,CAA+4FgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwQ,GAAjB,GAAqB,UAAS1nB,CAAT,EAAW;AAAC,MAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,KAAL,EAAWG,MAAK,UAAhB,EAA9B,CAAN,CAAiE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,CAA3H,CAA4HgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiByQ,SAAjB,GAA2B,UAAS3nB,CAAT,EAAW;AAAC,MAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,WAAL,EAAiBG,MAAK,UAAtB,EAA9B,CAAN,CAAuE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,CAAvI,CAAwIgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwT,eAAjB,GAAiC,IAAIjU,YAAJ,EAAjC,CAAoDO,KAAKf,MAAL,CAAYiB,IAAZ,CAAiByT,oBAAjB,GAAsC,UAASprB,CAAT,EAAW;AAAC,MAAIS,IAAE,IAAIuI,KAAJ,CAAUhJ,CAAV,CAAN,CAAmByX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwT,eAAjB,CAAiChb,SAAjC,CAA2C1P,CAA3C,EAA8C,OAAO8jB,QAAQ9jB,CAAR,CAAP;AAAkB,CAArI,CAAsIgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0T,2BAAjB,GAA6C,UAAS5qB,CAAT,EAAW;AAAC,SAAO,IAAI2I,UAAJ,CAAeqO,KAAKf,MAAL,CAAYiB,IAAZ,CAAiByT,oBAAjB,CAAsC3qB,CAAtC,CAAf,EAAwD,EAAxD,CAAP;AAAmE,CAA5H,CAA6HgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB2T,mBAAjB,GAAqC,UAAS3rB,CAAT,EAAW;AAAC,MAAIO,IAAEP,IAAE,CAAR,CAAU,IAAIc,IAAE,CAACd,IAAEO,CAAH,IAAM,CAAZ,CAAc,IAAIF,IAAE,IAAIgJ,KAAJ,CAAUvI,IAAE,CAAZ,CAAN,CAAqBgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwT,eAAjB,CAAiChb,SAAjC,CAA2CnQ,CAA3C,EAA8CA,EAAE,CAAF,IAAK,CAAG,OAAKE,CAAN,GAAS,GAAV,GAAe,GAAhB,IAAqBF,EAAE,CAAF,CAA1B,CAA+B,OAAOukB,QAAQvkB,CAAR,CAAP;AAAkB,CAA7L,CAA8LyX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB4T,0BAAjB,GAA4C,UAAS9qB,CAAT,EAAW;AAAC,SAAO,IAAI2I,UAAJ,CAAeqO,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB2T,mBAAjB,CAAqC7qB,CAArC,CAAf,EAAuD,EAAvD,CAAP;AAAkE,CAA1H,CAA2HgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB6T,4BAAjB,GAA8C,UAASxrB,CAAT,EAAW;AAAC,MAAIS,IAAET,EAAE4O,SAAF,EAAN,CAAoB,OAAM,CAAN,EAAQ;AAAC,QAAI1O,IAAEuX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB4T,0BAAjB,CAA4C9qB,CAA5C,CAAN,CAAqD,IAAGT,EAAEsM,SAAF,CAAYpM,CAAZ,KAAgB,CAAC,CAApB,EAAsB;AAAC,aAAOA,CAAP;AAAS;AAAC;AAAC,CAA9K,CAA+KuX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB8T,2BAAjB,GAA6C,UAASxrB,CAAT,EAAWD,CAAX,EAAa;AAAC,MAAIE,IAAED,EAAEqM,SAAF,CAAYtM,CAAZ,CAAN,CAAqB,IAAGE,KAAG,CAAN,EAAQ;AAAC,UAAK,6BAAL;AAAmC,OAAGA,KAAG,CAAN,EAAQ;AAAC,WAAOD,CAAP;AAAS,OAAIQ,IAAET,EAAEgU,QAAF,CAAW/T,CAAX,CAAN,CAAoB,IAAIN,IAAE8X,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB6T,4BAAjB,CAA8C/qB,CAA9C,CAAN,CAAuD,OAAOd,EAAEsU,GAAF,CAAMhU,CAAN,CAAP;AAAgB,CAAzO,CAA0OwX,KAAKf,MAAL,CAAYgB,aAAZ,GAA0B,UAASxX,CAAT,EAAW;AAAC,MAAIF,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,IAAId,IAAE,IAAN,CAAW,KAAK+rB,iBAAL,GAAuB,UAASnsB,CAAT,EAAWE,CAAX,EAAa;AAACF,QAAEkY,KAAKf,MAAL,CAAYgB,aAAZ,CAA0BE,mBAA1B,CAA8CrY,CAA9C,CAAF,CAAmD,IAAGA,MAAI,IAAJ,IAAUE,MAAIL,SAAjB,EAA2B;AAACK,UAAEgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC9oB,CAAjC,CAAF;AAAsC,SAAG,mDAAmDoG,OAAnD,CAA2DpG,CAA3D,KAA+D,CAAC,CAAhE,IAAmEE,KAAG,UAAzE,EAAoF;AAAC,UAAG;AAAC,aAAKksB,EAAL,GAAQlU,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0S,yBAAjB,CAA2C9qB,CAA3C,EAA8C+B,MAA9C,EAAR;AAA+D,OAAnE,CAAmE,OAAMrB,CAAN,EAAQ;AAAC,cAAK,6CAA2CV,CAA3C,GAA6C,GAA7C,GAAiDU,CAAtD;AAAwD,YAAK2rB,YAAL,GAAkB,UAASpsB,CAAT,EAAW;AAAC,aAAKmsB,EAAL,CAAQhnB,MAAR,CAAenF,CAAf;AAAkB,OAAhD,CAAiD,KAAKqsB,SAAL,GAAe,UAASrsB,CAAT,EAAW;AAAC,YAAIa,IAAEK,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBpD,CAAvB,CAAN,CAAgC,KAAKmsB,EAAL,CAAQhnB,MAAR,CAAetE,CAAf;AAAkB,OAA7E,CAA8E,KAAKyrB,MAAL,GAAY,YAAU;AAAC,YAAItsB,IAAE,KAAKmsB,EAAL,CAAQ/mB,QAAR,EAAN,CAAyB,OAAOpF,EAAE+B,QAAF,CAAWb,SAAS+B,GAAT,CAAaC,GAAxB,CAAP;AAAoC,OAApF,CAAqF,KAAKooB,YAAL,GAAkB,UAAStrB,CAAT,EAAW;AAAC,aAAKosB,YAAL,CAAkBpsB,CAAlB,EAAqB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAxE,CAAyE,KAAKf,SAAL,GAAe,UAASvrB,CAAT,EAAW;AAAC,aAAKqsB,SAAL,CAAersB,CAAf,EAAkB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAlE;AAAmE,SAAG,WAAWnmB,OAAX,CAAmBpG,CAAnB,KAAuB,CAAC,CAAxB,IAA2BE,KAAG,MAAjC,EAAwC;AAAC,UAAG;AAAC,aAAKksB,EAAL,GAAQ,IAAII,KAAKC,IAAL,CAAUjE,MAAd,EAAR;AAA+B,OAAnC,CAAmC,OAAM9nB,CAAN,EAAQ;AAAC,cAAK,6CAA2CV,CAA3C,GAA6C,GAA7C,GAAiDU,CAAtD;AAAwD,YAAK2rB,YAAL,GAAkB,UAASpsB,CAAT,EAAW;AAAC,aAAKmsB,EAAL,CAAQhnB,MAAR,CAAenF,CAAf;AAAkB,OAAhD,CAAiD,KAAKqsB,SAAL,GAAe,UAASxrB,CAAT,EAAW;AAAC,YAAIb,IAAEusB,KAAKE,KAAL,CAAWpM,GAAX,CAAeqM,MAAf,CAAsB7rB,CAAtB,CAAN,CAA+B,KAAKsrB,EAAL,CAAQhnB,MAAR,CAAenF,CAAf;AAAkB,OAA5E,CAA6E,KAAKssB,MAAL,GAAY,YAAU;AAAC,YAAItsB,IAAE,KAAKmsB,EAAL,CAAQ/mB,QAAR,EAAN,CAAyB,OAAOmnB,KAAKE,KAAL,CAAWpM,GAAX,CAAesM,QAAf,CAAwB3sB,CAAxB,CAAP;AAAkC,OAAlF,CAAmF,KAAKsrB,YAAL,GAAkB,UAAStrB,CAAT,EAAW;AAAC,aAAKosB,YAAL,CAAkBpsB,CAAlB,EAAqB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAxE,CAAyE,KAAKf,SAAL,GAAe,UAASvrB,CAAT,EAAW;AAAC,aAAKqsB,SAAL,CAAersB,CAAf,EAAkB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAlE;AAAmE;AAAC,GAA9rC,CAA+rC,KAAKF,YAAL,GAAkB,UAAS3rB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKmsB,OAA3D,GAAmE,GAAnE,GAAuE,KAAKC,QAAjF;AAA0F,GAAxH,CAAyH,KAAKR,SAAL,GAAe,UAAS5rB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKmsB,OAAxD,GAAgE,GAAhE,GAAoE,KAAKC,QAA9E;AAAuF,GAAlH,CAAmH,KAAKP,MAAL,GAAY,YAAU;AAAC,UAAK,+CAA6C,KAAKM,OAAlD,GAA0D,GAA1D,GAA8D,KAAKC,QAAxE;AAAiF,GAAxG,CAAyG,KAAKvB,YAAL,GAAkB,UAAS7qB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKmsB,OAA3D,GAAmE,GAAnE,GAAuE,KAAKC,QAAjF;AAA0F,GAAxH,CAAyH,KAAKtB,SAAL,GAAe,UAAS9qB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKmsB,OAAxD,GAAgE,GAAhE,GAAoE,KAAKC,QAA9E;AAAuF,GAAlH,CAAmH,IAAGnsB,MAAId,SAAP,EAAiB;AAAC,QAAGc,EAAE2qB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAKgtB,OAAL,GAAalsB,EAAE2qB,GAAf,CAAmB,IAAG3qB,EAAE8qB,IAAF,KAAS5rB,SAAZ,EAAsB;AAAC,aAAKitB,QAAL,GAAc5U,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC,KAAK+D,OAAtC,CAAd;AAA6D,YAAKV,iBAAL,CAAuB,KAAKU,OAA5B,EAAoC,KAAKC,QAAzC;AAAmD;AAAC;AAAC,CAA3gE,CAA4gE5U,KAAKf,MAAL,CAAYgB,aAAZ,CAA0BE,mBAA1B,GAA8C,UAASnX,CAAT,EAAW;AAAC,MAAG,OAAOA,CAAP,KAAW,QAAd,EAAuB;AAACA,QAAEA,EAAEif,WAAF,EAAF,CAAkBjf,IAAEA,EAAEgc,OAAF,CAAU,GAAV,EAAc,EAAd,CAAF;AAAoB,UAAOhc,CAAP;AAAS,CAAjI,CAAkIgX,KAAKf,MAAL,CAAYgB,aAAZ,CAA0BG,aAA1B,GAAwC,UAAS3X,CAAT,EAAW;AAAC,MAAIF,IAAEyX,KAAKf,MAAL,CAAYgB,aAAlB,CAAgC,IAAIjX,IAAET,EAAE4X,mBAAF,CAAsB1X,CAAtB,CAAN,CAA+B,IAAGF,EAAEssB,UAAF,CAAa7rB,CAAb,MAAkBrB,SAArB,EAA+B;AAAC,UAAK,8BAA4Bc,CAAjC;AAAmC,UAAOF,EAAEssB,UAAF,CAAa7rB,CAAb,CAAP;AAAuB,CAA7M,CAA8MgX,KAAKf,MAAL,CAAYgB,aAAZ,CAA0B4U,UAA1B,GAAqC,EAACnE,KAAI,EAAL,EAAQN,MAAK,EAAb,EAAgBC,QAAO,EAAvB,EAA0BC,QAAO,EAAjC,EAAoCC,QAAO,EAA3C,EAA8CC,QAAO,EAArD,EAAwDG,WAAU,EAAlE,EAArC,CAA2G3Q,KAAKf,MAAL,CAAY6V,GAAZ,GAAgB,UAAS5sB,CAAT,EAAW;AAAC,MAAIF,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,IAAIO,IAAE,IAAN,CAAW,IAAIR,IAAE,IAAN,CAAW,IAAID,IAAE,IAAN,CAAW,KAAK0rB,iBAAL,GAAuB,UAASlrB,CAAT,EAAWH,CAAX,EAAa;AAACG,QAAEA,EAAEkf,WAAF,EAAF,CAAkB,IAAGlf,KAAG,IAAN,EAAW;AAACA,UAAE,UAAF;AAAa,SAAEA,EAAEkf,WAAF,EAAF,CAAkB,IAAGlf,EAAEsC,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,YAAK,6CAA2CtC,CAAhD;AAAkD,SAAGH,MAAIjB,SAAP,EAAiB;AAACiB,UAAEoX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC7nB,CAAjC,CAAF;AAAsC,UAAKgsB,OAAL,GAAahsB,IAAE,GAAF,GAAMH,CAAnB,CAAqB,IAAId,IAAEiB,EAAEsC,MAAF,CAAS,CAAT,CAAN,CAAkB,IAAG,mDAAmD6C,OAAnD,CAA2DpG,CAA3D,KAA+D,CAAC,CAAhE,IAAmEc,KAAG,UAAzE,EAAoF;AAAC,UAAG;AAAC,YAAID,IAAEqX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0S,yBAAjB,CAA2C9qB,CAA3C,CAAN,CAAoD,KAAKktB,GAAL,GAAS/rB,SAASuE,IAAT,CAAcD,IAAd,CAAmB1D,MAAnB,CAA0BlB,CAA1B,EAA4B,KAAKssB,IAAjC,CAAT;AAAgD,OAAxG,CAAwG,OAAMltB,CAAN,EAAQ;AAAC,cAAK,iDAA+CD,CAA/C,GAAiD,GAAjD,GAAqDC,CAA1D;AAA4D,YAAKosB,YAAL,GAAkB,UAASrrB,CAAT,EAAW;AAAC,aAAKksB,GAAL,CAAS9nB,MAAT,CAAgBpE,CAAhB;AAAmB,OAAjD,CAAkD,KAAKsrB,SAAL,GAAe,UAAStrB,CAAT,EAAW;AAAC,YAAIiC,IAAE9B,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBrC,CAAvB,CAAN,CAAgC,KAAKksB,GAAL,CAAS9nB,MAAT,CAAgBnC,CAAhB;AAAmB,OAA9E,CAA+E,KAAKmqB,OAAL,GAAa,YAAU;AAAC,YAAIpsB,IAAE,KAAKksB,GAAL,CAAS7nB,QAAT,EAAN,CAA0B,OAAOrE,EAAEgB,QAAF,CAAWb,SAAS+B,GAAT,CAAaC,GAAxB,CAAP;AAAoC,OAAtF,CAAuF,KAAKkqB,aAAL,GAAmB,UAASrsB,CAAT,EAAW;AAAC,aAAKqrB,YAAL,CAAkBrrB,CAAlB,EAAqB,OAAO,KAAKosB,OAAL,EAAP;AAAsB,OAA1E,CAA2E,KAAKE,UAAL,GAAgB,UAAStsB,CAAT,EAAW;AAAC,aAAKsrB,SAAL,CAAetrB,CAAf,EAAkB,OAAO,KAAKosB,OAAL,EAAP;AAAsB,OAApE;AAAqE;AAAC,GAAx3B,CAAy3B,KAAKf,YAAL,GAAkB,UAASrsB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKitB,OAAhE;AAAwE,GAAtG,CAAuG,KAAKX,SAAL,GAAe,UAAStsB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKitB,OAA7D;AAAqE,GAAhG,CAAiG,KAAKG,OAAL,GAAa,YAAU;AAAC,UAAK,+CAA6C,KAAKH,OAAvD;AAA+D,GAAvF,CAAwF,KAAKI,aAAL,GAAmB,UAASrtB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKitB,OAAhE;AAAwE,GAAvG,CAAwG,KAAKK,UAAL,GAAgB,UAASttB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKitB,OAA7D;AAAqE,GAAjG,CAAkG,KAAKM,WAAL,GAAiB,UAASttB,CAAT,EAAW;AAAC,QAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,UAAID,IAAEC,CAAN,CAAQ,IAAGA,EAAEc,MAAF,GAAS,CAAT,IAAY,CAAZ,IAAe,CAACd,EAAEgd,KAAF,CAAQ,gBAAR,CAAnB,EAA6C;AAACjd,YAAEyY,UAAUxY,CAAV,CAAF;AAAe,YAAKktB,IAAL,GAAUhsB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBrD,CAAvB,CAAV,CAAoC;AAAO,SAAG,QAAOC,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC,YAAK,gDAA8CA,CAAnD;AAAqD,SAAID,IAAE,IAAN,CAAW,IAAGC,EAAEqgB,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,UAAGI,EAAEqgB,GAAF,CAAMvf,MAAN,GAAa,CAAb,IAAgB,CAAhB,IAAmB,CAACd,EAAEqgB,GAAF,CAAMrD,KAAN,CAAY,gBAAZ,CAAvB,EAAqD;AAAC,cAAK,8BAA4Bhd,EAAEqgB,GAAnC;AAAuC,WAAErgB,EAAEqgB,GAAJ;AAAQ,SAAGrgB,EAAEutB,IAAF,KAAS3tB,SAAZ,EAAsB;AAACG,UAAEkgB,UAAUjgB,EAAEutB,IAAZ,CAAF;AAAoB,SAAGvtB,EAAEwtB,IAAF,KAAS5tB,SAAZ,EAAsB;AAACG,UAAEyY,UAAUxY,EAAEwtB,IAAZ,CAAF;AAAoB,SAAGxtB,EAAEytB,GAAF,KAAQ7tB,SAAX,EAAqB;AAACG,UAAEsJ,SAASrJ,EAAEytB,GAAX,CAAF;AAAkB,SAAGztB,EAAE0tB,IAAF,KAAS9tB,SAAZ,EAAsB;AAACG,UAAEulB,UAAUtlB,EAAE0tB,IAAZ,CAAF;AAAoB,SAAG3tB,KAAG,IAAN,EAAW;AAAC,YAAK,gDAA8CC,CAAnD;AAAqD,UAAKktB,IAAL,GAAUhsB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBrD,CAAvB,CAAV;AAAoC,GAApoB,CAAqoB,IAAGI,MAAIP,SAAP,EAAiB;AAAC,QAAGO,EAAE+sB,IAAF,KAASttB,SAAZ,EAAsB;AAAC,WAAK0tB,WAAL,CAAiBntB,EAAE+sB,IAAnB;AAAyB,SAAG/sB,EAAEkrB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAKgtB,OAAL,GAAazsB,EAAEkrB,GAAf,CAAmB,IAAGlrB,EAAEqrB,IAAF,KAAS5rB,SAAZ,EAAsB;AAAC,aAAKitB,QAAL,GAAc5U,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC,KAAK+D,OAAtC,CAAd;AAA6D,YAAKV,iBAAL,CAAuB,KAAKU,OAA5B,EAAoC,KAAKC,QAAzC;AAAmD;AAAC;AAAC,CAA/yE,CAAgzE5U,KAAKf,MAAL,CAAYyW,SAAZ,GAAsB,UAASpsB,CAAT,EAAW;AAAC,MAAIgB,IAAE,IAAN,CAAW,IAAIlB,IAAE,IAAN,CAAW,IAAIqB,IAAE,IAAN,CAAW,IAAIhC,IAAE,IAAN,CAAW,IAAIK,IAAE,IAAN,CAAW,IAAIZ,IAAE,IAAN,CAAW,IAAIa,IAAE,IAAN,CAAW,IAAIhB,IAAE,IAAN,CAAW,IAAIsB,IAAE,IAAN,CAAW,IAAIb,IAAE,IAAN,CAAW,IAAID,IAAE,CAAC,CAAP,CAAS,IAAIT,IAAE,IAAN,CAAW,IAAIa,IAAE,IAAN,CAAW,IAAIK,IAAE,IAAN,CAAW,IAAIJ,IAAE,IAAN,CAAW,IAAIZ,IAAE,IAAN,CAAW,KAAK2tB,YAAL,GAAkB,YAAU;AAAC,QAAIprB,IAAE,KAAKoqB,OAAL,CAAa5P,KAAb,CAAmB,gBAAnB,CAAN,CAA2C,IAAGxa,CAAH,EAAK;AAAC,WAAKqrB,SAAL,GAAerrB,EAAE,CAAF,EAAK0d,WAAL,EAAf,CAAkC,KAAK4N,aAAL,GAAmBtrB,EAAE,CAAF,EAAK0d,WAAL,EAAnB;AAAsC;AAAC,GAAvJ,CAAwJ,KAAK6N,uBAAL,GAA6B,UAASxpB,CAAT,EAAWD,CAAX,EAAa;AAAC,QAAIG,IAAE,EAAN,CAAS,IAAInC,IAAEgC,IAAE,CAAF,GAAIC,EAAEzD,MAAZ,CAAmB,KAAI,IAAI4D,IAAE,CAAV,EAAYA,IAAEpC,CAAd,EAAgBoC,GAAhB,EAAoB;AAACD,UAAEA,IAAE,GAAJ;AAAQ,YAAOA,IAAEF,CAAT;AAAW,GAA/G,CAAgH,KAAK2nB,iBAAL,GAAuB,UAASxnB,CAAT,EAAWpC,CAAX,EAAa;AAAC,SAAKsrB,YAAL,GAAoB,IAAGtrB,KAAG,gBAAN,EAAuB;AAAC,YAAK,6BAA2BA,CAAhC;AAAkC,SAAG,mDAAmD6D,OAAnD,CAA2D,KAAK0nB,SAAhE,KAA4E,CAAC,CAAhF,EAAkF;AAAC,UAAG;AAAC,aAAK1B,EAAL,GAAQ,IAAIlU,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,KAAKwC,SAAV,EAA9B,CAAR;AAA4D,OAAhE,CAAgE,OAAMrrB,CAAN,EAAQ;AAAC,cAAK,6CAA2C,KAAKqrB,SAAhD,GAA0D,GAA1D,GAA8DrrB,CAAnE;AAAqE,YAAKd,IAAL,GAAU,UAAS4C,CAAT,EAAWC,CAAX,EAAa;AAAC,YAAI2D,IAAE,IAAN,CAAW,IAAG;AAAC,cAAG3D,MAAI3E,SAAP,EAAiB;AAACsI,gBAAE8lB,QAAQC,MAAR,CAAe3pB,CAAf,CAAF;AAAoB,WAAtC,MAA0C;AAAC4D,gBAAE8lB,QAAQC,MAAR,CAAe3pB,CAAf,EAAiBC,CAAjB,CAAF;AAAsB;AAAC,SAAtE,CAAsE,OAAME,CAAN,EAAQ;AAAC,gBAAK,iBAAeA,CAApB;AAAsB,aAAGyD,EAAE6Q,SAAF,KAAc,IAAjB,EAAsB;AAAC,eAAKmV,MAAL,GAAYhmB,CAAZ,CAAc,KAAKimB,KAAL,GAAW,MAAX;AAAkB,SAAvD,MAA2D;AAAC,cAAGjmB,EAAE4Q,QAAF,KAAa,IAAhB,EAAqB;AAAC,iBAAKsV,MAAL,GAAYlmB,CAAZ,CAAc,KAAKimB,KAAL,GAAW,QAAX;AAAoB,WAAxD,MAA4D;AAAC,kBAAK,kBAAgBjmB,CAArB;AAAuB;AAAC;AAAC,OAA1R,CAA2R,KAAKkkB,YAAL,GAAkB,UAAS3nB,CAAT,EAAW;AAAC,aAAK0nB,EAAL,CAAQC,YAAR,CAAqB3nB,CAArB;AAAwB,OAAtD,CAAuD,KAAK4nB,SAAL,GAAe,UAAS5nB,CAAT,EAAW;AAAC,aAAK0nB,EAAL,CAAQE,SAAR,CAAkB5nB,CAAlB;AAAqB,OAAhD,CAAiD,KAAK4pB,IAAL,GAAU,YAAU;AAAC,aAAKC,QAAL,GAAc,KAAKnC,EAAL,CAAQG,MAAR,EAAd,CAA+B,IAAG,OAAO,KAAKiC,QAAZ,IAAsB,WAAtB,IAAmC,OAAO,KAAKC,WAAZ,IAAyB,WAA/D,EAA2E;AAAC,cAAI/pB,IAAE,IAAIwT,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAM,KAAKqU,WAAZ,EAAtB,CAAN,CAAsD,KAAKE,KAAL,GAAWjqB,EAAEkqB,OAAF,CAAU,KAAKL,QAAf,EAAwB,KAAKC,QAA7B,CAAX;AAAkD,SAApL,MAAwL;AAAC,cAAG,KAAKL,MAAL,YAAuBzV,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,YAAvD,EAAoE;AAAC,iBAAKY,KAAL,GAAW,KAAKR,MAAL,CAAYU,sBAAZ,CAAmC,KAAKN,QAAxC,EAAiD,KAAKT,SAAtD,EAAgE,KAAKgB,UAArE,CAAX;AAA4F,WAAjK,MAAqK;AAAC,gBAAG,KAAKX,MAAL,YAAuBzV,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,KAAvD,EAA6D;AAAC,mBAAKY,KAAL,GAAW,KAAKR,MAAL,CAAYY,mBAAZ,CAAgC,KAAKR,QAArC,EAA8C,KAAKT,SAAnD,CAAX;AAAyE,aAAvI,MAA2I;AAAC,kBAAG,KAAKK,MAAL,YAAuBjW,KAAKf,MAAL,CAAYuX,KAAtC,EAA4C;AAAC,qBAAKC,KAAL,GAAW,KAAKR,MAAL,CAAYY,mBAAZ,CAAgC,KAAKR,QAArC,CAAX;AAA0D,eAAvG,MAA2G;AAAC,oBAAG,KAAKJ,MAAL,YAAuBjW,KAAKf,MAAL,CAAY6X,GAAtC,EAA0C;AAAC,uBAAKL,KAAL,GAAW,KAAKR,MAAL,CAAYY,mBAAZ,CAAgC,KAAKR,QAArC,CAAX;AAA0D,iBAArG,MAAyG;AAAC,wBAAK,6CAA2C,KAAKR,aAArD;AAAmE;AAAC;AAAC;AAAC;AAAC,gBAAO,KAAKY,KAAZ;AAAkB,OAA90B,CAA+0B,KAAKM,UAAL,GAAgB,UAASvqB,CAAT,EAAW;AAAC,aAAK2nB,YAAL,CAAkB3nB,CAAlB,EAAqB,OAAO,KAAK4pB,IAAL,EAAP;AAAmB,OAApE,CAAqE,KAAKM,OAAL,GAAa,UAASlqB,CAAT,EAAW;AAAC,aAAK4nB,SAAL,CAAe5nB,CAAf,EAAkB,OAAO,KAAK4pB,IAAL,EAAP;AAAmB,OAA9D,CAA+D,KAAKY,MAAL,GAAY,UAASxqB,CAAT,EAAW;AAAC,aAAK6pB,QAAL,GAAc,KAAKnC,EAAL,CAAQG,MAAR,EAAd,CAA+B,IAAG,OAAO,KAAK4C,QAAZ,IAAsB,WAAtB,IAAmC,OAAO,KAAKV,WAAZ,IAAyB,WAA/D,EAA2E;AAAC,cAAIlqB,IAAE,IAAI2T,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAM,KAAKqU,WAAZ,EAAtB,CAAN,CAAsD,OAAOlqB,EAAE6qB,SAAF,CAAY,KAAKb,QAAjB,EAA0B7pB,CAA1B,EAA4B,KAAKyqB,QAAjC,CAAP;AAAkD,SAApL,MAAwL;AAAC,cAAG,KAAKd,MAAL,YAAuB3V,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,YAAvD,EAAoE;AAAC,mBAAO,KAAKM,MAAL,CAAYgB,wBAAZ,CAAqC,KAAKd,QAA1C,EAAmD7pB,CAAnD,EAAqD,KAAKopB,SAA1D,EAAoE,KAAKgB,UAAzE,CAAP;AAA4F,WAAjK,MAAqK;AAAC,gBAAG,KAAKT,MAAL,YAAuB3V,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,KAAvD,EAA6D;AAAC,qBAAO,KAAKM,MAAL,CAAYiB,qBAAZ,CAAkC,KAAKf,QAAvC,EAAgD7pB,CAAhD,CAAP;AAA0D,aAAxH,MAA4H;AAAC,kBAAGwT,KAAKf,MAAL,CAAYuX,KAAZ,KAAoB7uB,SAApB,IAA+B,KAAKwuB,MAAL,YAAuBnW,KAAKf,MAAL,CAAYuX,KAArE,EAA2E;AAAC,uBAAO,KAAKL,MAAL,CAAYiB,qBAAZ,CAAkC,KAAKf,QAAvC,EAAgD7pB,CAAhD,CAAP;AAA0D,eAAtI,MAA0I;AAAC,oBAAGwT,KAAKf,MAAL,CAAY6X,GAAZ,KAAkBnvB,SAAlB,IAA6B,KAAKwuB,MAAL,YAAuBnW,KAAKf,MAAL,CAAY6X,GAAnE,EAAuE;AAAC,yBAAO,KAAKX,MAAL,CAAYiB,qBAAZ,CAAkC,KAAKf,QAAvC,EAAgD7pB,CAAhD,CAAP;AAA0D,iBAAlI,MAAsI;AAAC,wBAAK,4CAA0C,KAAKqpB,aAApD;AAAkE;AAAC;AAAC;AAAC;AAAC;AAAC,OAA52B;AAA62B;AAAC,GAAxhF,CAAyhF,KAAKpsB,IAAL,GAAU,UAASc,CAAT,EAAWF,CAAX,EAAa;AAAC,UAAK,qDAAmD,KAAKgtB,WAA7D;AAAyE,GAAjG,CAAkG,KAAKlD,YAAL,GAAkB,UAAS5pB,CAAT,EAAW;AAAC,UAAK,uDAAqD,KAAK8sB,WAA/D;AAA2E,GAAzG,CAA0G,KAAKjD,SAAL,GAAe,UAAS7pB,CAAT,EAAW;AAAC,UAAK,oDAAkD,KAAK8sB,WAA5D;AAAwE,GAAnG,CAAoG,KAAKjB,IAAL,GAAU,YAAU;AAAC,UAAK,4CAA0C,KAAKiB,WAApD;AAAgE,GAArF,CAAsF,KAAKN,UAAL,GAAgB,UAASxsB,CAAT,EAAW;AAAC,UAAK,uDAAqD,KAAK8sB,WAA/D;AAA2E,GAAvG,CAAwG,KAAKX,OAAL,GAAa,UAASnsB,CAAT,EAAW;AAAC,UAAK,oDAAkD,KAAK8sB,WAA5D;AAAwE,GAAjG,CAAkG,KAAKL,MAAL,GAAY,UAASzsB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAK8sB,WAA7D;AAAyE,GAAjG,CAAkG,KAAKC,UAAL,GAAgBhuB,CAAhB,CAAkB,IAAGA,MAAI3B,SAAP,EAAiB;AAAC,QAAG2B,EAAE8pB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAKgtB,OAAL,GAAarrB,EAAE8pB,GAAf,CAAmB,IAAG9pB,EAAEiqB,IAAF,KAAS5rB,SAAZ,EAAsB;AAAC,aAAKitB,QAAL,GAAc5U,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC,KAAK+D,OAAtC,CAAd;AAA6D,OAApF,MAAwF;AAAC,aAAKC,QAAL,GAActrB,EAAEiqB,IAAhB;AAAqB,YAAK8D,WAAL,GAAiB,KAAK1C,OAAL,GAAa,GAAb,GAAiB,KAAKC,QAAvC,CAAgD,KAAKX,iBAAL,CAAuB,KAAKU,OAA5B,EAAoC,KAAKC,QAAzC,EAAmD,KAAKe,YAAL;AAAoB,SAAGrsB,EAAEiuB,UAAF,KAAe5vB,SAAlB,EAA4B;AAAC,WAAKivB,UAAL,GAAgBttB,EAAEiuB,UAAlB;AAA6B,SAAGjuB,EAAEkuB,SAAF,KAAc7vB,SAAjB,EAA2B;AAAC,UAAG2B,EAAEmuB,SAAF,KAAc9vB,SAAjB,EAA2B;AAAC,cAAK,uDAAL;AAA6D,OAAzF,MAA6F;AAAC,YAAG;AAAC,cAAI2C,IAAEyrB,QAAQC,MAAR,CAAe1sB,EAAEkuB,SAAjB,CAAN,CAAkC,KAAK/tB,IAAL,CAAUa,CAAV;AAAa,SAAnD,CAAmD,OAAMS,CAAN,EAAQ;AAAC,gBAAK,0CAAwCA,CAA7C;AAA+C;AAAC;AAAC;AAAC;AAAC,CAAxvI,CAAyvIiV,KAAKf,MAAL,CAAYyY,MAAZ,GAAmB,UAAS1uB,CAAT,EAAW,CAAE,CAAhC,CAAiCgX,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBtW,OAAnB,GAA2B,UAAS5Y,CAAT,EAAWR,CAAX,EAAaE,CAAb,EAAe;AAAC,MAAGF,aAAawY,MAAb,IAAqBxY,EAAE6Y,QAA1B,EAAmC;AAAC,QAAIpY,IAAEuX,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBC,kBAAnB,CAAsC3vB,CAAtC,EAAwCE,CAAxC,CAAN,CAAiD,IAAGO,MAAI,KAAP,EAAa;AAAC,aAAOT,EAAEoZ,OAAF,CAAU5Y,CAAV,CAAP;AAAoB,SAAGC,MAAI,SAAP,EAAiB;AAAC,aAAOT,EAAEqZ,WAAF,CAAc7Y,CAAd,EAAgB,MAAhB,CAAP;AAA+B,SAAID,IAAEE,EAAEsc,KAAF,CAAQ,gBAAR,CAAN,CAAgC,IAAGxc,MAAI,IAAP,EAAY;AAAC,aAAOP,EAAEqZ,WAAF,CAAc7Y,CAAd,EAAgB,QAAMD,EAAE,CAAF,CAAtB,CAAP;AAAmC,WAAK,uDAAqDL,CAA1D;AAA4D,GAApT,MAAwT;AAAC,UAAK,8CAAL;AAAoD;AAAC,CAAzZ,CAA0Z8X,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBE,OAAnB,GAA2B,UAASpvB,CAAT,EAAWR,CAAX,EAAaE,CAAb,EAAe;AAAC,MAAGF,aAAawY,MAAb,IAAqBxY,EAAE8Y,SAA1B,EAAoC;AAAC,QAAIrY,IAAEuX,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBC,kBAAnB,CAAsC3vB,CAAtC,EAAwCE,CAAxC,CAAN,CAAiD,IAAGO,MAAI,KAAP,EAAa;AAAC,aAAOT,EAAE4vB,OAAF,CAAUpvB,CAAV,CAAP;AAAoB,SAAGC,MAAI,SAAP,EAAiB;AAAC,aAAOT,EAAE6vB,WAAF,CAAcrvB,CAAd,EAAgB,MAAhB,CAAP;AAA+B,SAAID,IAAEE,EAAEsc,KAAF,CAAQ,gBAAR,CAAN,CAAgC,IAAGxc,MAAI,IAAP,EAAY;AAAC,aAAOP,EAAE6vB,WAAF,CAAcrvB,CAAd,EAAgB,QAAMD,EAAE,CAAF,CAAtB,CAAP;AAAmC,WAAK,uDAAqDL,CAA1D;AAA4D,GAArT,MAAyT;AAAC,UAAK,8CAAL;AAAoD;AAAC,CAA1Z,CAA2Z8X,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBC,kBAAnB,GAAsC,UAASpvB,CAAT,EAAWS,CAAX,EAAa;AAAC,MAAGT,aAAaiY,MAAhB,EAAuB;AAAC,QAAG,4DAA4DtS,OAA5D,CAAoElF,CAApE,KAAwE,CAAC,CAA5E,EAA8E;AAAC,aAAOA,CAAP;AAAS,SAAGA,MAAI,IAAJ,IAAUA,MAAIrB,SAAjB,EAA2B;AAAC,aAAM,KAAN;AAAY,WAAK,kEAAgEqB,CAArE;AAAuE,SAAK,uDAAqDA,CAA1D;AAA4D,CAA/U,CAAgVgX,KAAKf,MAAL,CAAYsL,GAAZ,GAAgB,IAAI,YAAU;AAAC,OAAKuN,WAAL,GAAiB,EAAC,sBAAqB,eAAtB,EAAsC,kBAAiB,aAAvD,EAAqE,kBAAiB,KAAtF,EAA4F,oBAAmB,WAA/G,EAA2H,cAAa,WAAxI,EAAoJ,cAAa,WAAjK,EAA6K,cAAa,WAA1L,EAAsM,cAAa,WAAnN,EAA+N,cAAa,WAA5O,EAAwP,kBAAiB,aAAzQ,EAAuR,sBAAqB,eAA5S,EAA4T,sBAAqB,eAAjV,EAAjB;AAAoX,CAAnY,EAAhB;AAC/5c,IAAG,OAAO9X,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UAyE3BA,IAzE2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKf,MAAZ,IAAoB,WAApB,IAAiC,CAACe,KAAKf,MAA1C,EAAiD;AAACe,OAAKf,MAAL,GAAY,EAAZ;AAAe,MAAKA,MAAL,CAAYuX,KAAZ,GAAkB,UAASzuB,CAAT,EAAW;AAAC,MAAIS,IAAE,WAAN,CAAkB,IAAIV,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,IAAIP,IAAE,IAAN,CAAW,IAAIgB,IAAE,IAAIyW,YAAJ,EAAN,CAAyB,IAAIvX,IAAE,IAAN,CAAW,KAAKoZ,IAAL,GAAU,IAAV,CAAe,KAAKR,SAAL,GAAe,KAAf,CAAqB,KAAKD,QAAL,GAAc,KAAd,CAAoB,SAASpY,CAAT,CAAW8B,CAAX,EAAajB,CAAb,EAAemB,CAAf,EAAiBrB,CAAjB,EAAmB;AAAC,QAAIT,IAAE8E,KAAKf,GAAL,CAASpD,EAAE6N,SAAF,EAAT,EAAuB/N,EAAE+N,SAAF,EAAvB,CAAN,CAA4C,IAAI9M,IAAEE,EAAEga,KAAF,CAAQ9Z,CAAR,CAAN,CAAiB,IAAIH,IAAEC,EAAE2X,KAAF,CAAQW,WAAR,EAAN,CAA4B,KAAI,IAAIxZ,IAAEV,IAAE,CAAZ,EAAcU,KAAG,CAAjB,EAAmB,EAAEA,CAArB,EAAuB;AAACiB,UAAEA,EAAEka,OAAF,EAAF,CAAcla,EAAEyF,CAAF,GAAI4B,WAAWmD,GAAf,CAAmB,IAAGxL,EAAE+O,OAAF,CAAUhP,CAAV,CAAH,EAAgB;AAAC,YAAGD,EAAEiP,OAAF,CAAUhP,CAAV,CAAH,EAAgB;AAACiB,cAAEA,EAAEia,KAAF,CAAQla,CAAR,CAAF;AAAa,SAA9B,MAAkC;AAACC,cAAEA,EAAEia,KAAF,CAAQha,CAAR,CAAF;AAAa;AAAC,OAAlE,MAAsE;AAAC,YAAGnB,EAAEiP,OAAF,CAAUhP,CAAV,CAAH,EAAgB;AAACiB,cAAEA,EAAEia,KAAF,CAAQ9Z,CAAR,CAAF;AAAa;AAAC;AAAC,YAAOH,CAAP;AAAS,QAAKytB,YAAL,GAAkB,UAASnvB,CAAT,EAAW;AAAC,WAAO,IAAI+I,UAAJ,CAAe/I,EAAEuO,SAAF,EAAf,EAA6BnO,CAA7B,EAAgCqM,GAAhC,CAAoCzM,EAAE2T,QAAF,CAAW5K,WAAWmD,GAAtB,CAApC,EAAgE0H,GAAhE,CAAoE7K,WAAWmD,GAA/E,CAAP;AAA2F,GAAzH,CAA0H,KAAKkjB,aAAL,GAAmB,UAASpvB,CAAT,EAAW;AAAC,SAAKqvB,QAAL,GAAcjY,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BC,SAA1B,CAAoCvvB,CAApC,CAAd,CAAqD,KAAKwvB,SAAL,GAAe,IAAf,CAAoB,KAAKC,SAAL,GAAe,IAAf,CAAoB,KAAKC,SAAL,GAAe1vB,CAAf;AAAiB,GAA7I,CAA8I,KAAK2vB,gBAAL,GAAsB,UAAS3vB,CAAT,EAAW;AAAC,SAAKkY,SAAL,GAAe,IAAf,CAAoB,KAAKsX,SAAL,GAAexvB,CAAf;AAAiB,GAAvE,CAAwE,KAAK4vB,eAAL,GAAqB,UAAS5vB,CAAT,EAAW;AAAC,SAAKiY,QAAL,GAAc,IAAd,CAAmB,KAAKwX,SAAL,GAAezvB,CAAf;AAAiB,GAArE,CAAsE,KAAK6vB,iBAAL,GAAuB,YAAU;AAAC,QAAI1vB,IAAE,KAAKsvB,SAAX,CAAqB,IAAGtvB,EAAEsC,MAAF,CAAS,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,YAAK,mDAAL;AAAyD,SAAI1C,IAAE,KAAKsvB,QAAL,CAAcS,MAAd,GAAqB,CAA3B,CAA6B,IAAG3vB,EAAEF,MAAF,KAAW,IAAEF,IAAE,CAAlB,EAAoB;AAAC,YAAK,iCAAL;AAAuC,SAAIC,IAAE,EAAN,CAASA,EAAE0D,CAAF,GAAIvD,EAAEsC,MAAF,CAAS,CAAT,EAAW1C,CAAX,CAAJ,CAAkBC,EAAEqH,CAAF,GAAIlH,EAAEsC,MAAF,CAAS,IAAE1C,CAAX,CAAJ,CAAkB,OAAOC,CAAP;AAAS,GAAxR,CAAyR,KAAK+vB,sBAAL,GAA4B,YAAU;AAAC,QAAI/vB,IAAE,KAAK0vB,SAAX,CAAqB,IAAG1vB,MAAI,WAAJ,IAAiBA,MAAI,YAArB,IAAmCA,MAAI,OAAvC,IAAgDA,MAAI,YAAvD,EAAoE;AAAC,aAAM,OAAN;AAAc,SAAGA,MAAI,WAAJ,IAAiBA,MAAI,YAArB,IAAmCA,MAAI,OAA1C,EAAkD;AAAC,aAAM,OAAN;AAAc,YAAO,IAAP;AAAY,GAA5N,CAA6N,KAAKgwB,kBAAL,GAAwB,YAAU;AAAC,QAAI7vB,IAAE,KAAKkvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIA,IAAE,KAAK2uB,YAAL,CAAkBhvB,CAAlB,CAAN,CAA2B,IAAID,IAAE,KAAKmvB,QAAL,CAAcppB,CAAd,CAAgBiP,QAAhB,CAAyB1U,CAAzB,CAAN,CAAkC,IAAIkB,IAAExB,EAAEma,IAAF,GAASrB,YAAT,EAAN,CAA8B,IAAItY,IAAER,EAAEoa,IAAF,GAAStB,YAAT,EAAN,CAA8B,IAAIhZ,IAAE,KAAKqvB,QAAL,CAAcS,MAAd,GAAqB,CAA3B,CAA6B,IAAI3tB,IAAE,CAAC,eAAa3B,EAAEU,QAAF,CAAW,EAAX,CAAd,EAA8Bc,KAA9B,CAAoC,CAAChC,CAArC,CAAN,CAA8C,IAAI6B,IAAE,CAAC,eAAaH,EAAER,QAAF,CAAW,EAAX,CAAd,EAA8Bc,KAA9B,CAAoC,CAAChC,CAArC,CAAN,CAA8C,IAAIS,IAAE,CAAC,eAAaC,EAAEQ,QAAF,CAAW,EAAX,CAAd,EAA8Bc,KAA9B,CAAoC,CAAChC,CAArC,CAAN,CAA8C,IAAID,IAAE,OAAK8B,CAAL,GAAOpB,CAAb,CAAe,KAAKkvB,gBAAL,CAAsBxtB,CAAtB,EAAyB,KAAKytB,eAAL,CAAqB7vB,CAArB,EAAwB,OAAM,EAAC2tB,UAASvrB,CAAV,EAAYksB,UAAStuB,CAArB,EAAN;AAA8B,GAAvb,CAAwb,KAAKkuB,mBAAL,GAAyB,UAASjuB,CAAT,EAAW;AAAC,WAAO,KAAK8tB,OAAL,CAAa9tB,CAAb,EAAe,KAAKwvB,SAApB,CAAP;AAAsC,GAA3E,CAA4E,KAAK1B,OAAL,GAAa,UAASptB,CAAT,EAAWX,CAAX,EAAa;AAAC,QAAI0B,IAAE,IAAIsH,UAAJ,CAAehJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIG,IAAE,KAAKmvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIkB,IAAE,IAAIqH,UAAJ,CAAerI,CAAf,EAAiB,EAAjB,CAAN,CAA2B,GAAE;AAAC,UAAIyB,IAAE,KAAKgtB,YAAL,CAAkBjvB,CAAlB,CAAN,CAA2B,IAAI2D,IAAE,KAAKwrB,QAAL,CAAcppB,CAApB,CAAsB,IAAIxF,IAAEoD,EAAEqR,QAAF,CAAW/S,CAAX,CAAN,CAAoB,IAAInC,IAAES,EAAE4Z,IAAF,GAASrB,YAAT,GAAwBvM,GAAxB,CAA4BvM,CAA5B,CAAN;AAAqC,KAA7G,QAAmHF,EAAEiM,SAAF,CAAYlD,WAAW2B,IAAvB,KAA8B,CAAjJ,EAAoJ,IAAI9G,IAAEzB,EAAEkT,UAAF,CAAanV,CAAb,EAAgBgV,QAAhB,CAAyBxT,EAAEkS,GAAF,CAAMnS,EAAEyT,QAAF,CAAWlV,CAAX,CAAN,CAAzB,EAA+CyM,GAA/C,CAAmDvM,CAAnD,CAAN,CAA4D,OAAOkX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBqC,gBAAlB,CAAmCjwB,CAAnC,EAAqC4D,CAArC,CAAP;AAA+C,GAAtW,CAAuW,KAAK4pB,IAAL,GAAU,UAASrrB,CAAT,EAAW0B,CAAX,EAAa;AAAC,QAAInC,IAAEmC,CAAN,CAAQ,IAAI9D,IAAE,KAAKsvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIC,IAAEsI,WAAWmnB,qBAAX,CAAiC/tB,CAAjC,CAAN,CAA0C,GAAE;AAAC,UAAIjC,IAAE,KAAKivB,YAAL,CAAkBpvB,CAAlB,CAAN,CAA2B,IAAI0B,IAAE,KAAK4tB,QAAL,CAAcppB,CAApB,CAAsB,IAAIvF,IAAEe,EAAEyT,QAAF,CAAWhV,CAAX,CAAN,CAAoB,IAAIF,IAAEU,EAAE2Z,IAAF,GAASrB,YAAT,GAAwBvM,GAAxB,CAA4B1M,CAA5B,CAAN;AAAqC,KAA7G,QAAmHC,EAAEiM,SAAF,CAAYlD,WAAW2B,IAAvB,KAA8B,CAAjJ,EAAoJ,IAAI9G,IAAE1D,EAAEmV,UAAF,CAAatV,CAAb,EAAgBmV,QAAhB,CAAyBzU,EAAEmT,GAAF,CAAMlS,EAAEwT,QAAF,CAAWlV,CAAX,CAAN,CAAzB,EAA+CyM,GAA/C,CAAmD1M,CAAnD,CAAN,CAA4D,OAAO,KAAKowB,YAAL,CAAkBnwB,CAAlB,EAAoB4D,CAApB,CAAP;AAA8B,GAA9U,CAA+U,KAAK4qB,qBAAL,GAA2B,UAASzuB,CAAT,EAAWC,CAAX,EAAa;AAAC,WAAO,KAAKsuB,SAAL,CAAevuB,CAAf,EAAiBC,CAAjB,EAAmB,KAAKyvB,SAAxB,CAAP;AAA0C,GAAnF,CAAoF,KAAKnB,SAAL,GAAe,UAASnsB,CAAT,EAAWnC,CAAX,EAAaS,CAAb,EAAe;AAAC,QAAIP,CAAJ,EAAMH,CAAN,CAAQ,IAAIW,IAAE0W,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBwC,WAAlB,CAA8BpwB,CAA9B,CAAN,CAAuCE,IAAEQ,EAAEmB,CAAJ,CAAM9B,IAAEW,EAAEiB,CAAJ,CAAM,IAAIxB,CAAJ,CAAMA,IAAEkZ,UAAUqC,aAAV,CAAwB,KAAK2T,QAAL,CAAc/V,KAAtC,EAA4C7Y,CAA5C,CAAF,CAAiD,IAAID,IAAE,IAAIuI,UAAJ,CAAe5G,CAAf,EAAiB,EAAjB,CAAN,CAA2B,OAAO,KAAKkuB,SAAL,CAAe7vB,CAAf,EAAiBN,CAAjB,EAAmBH,CAAnB,EAAqBI,CAArB,CAAP;AAA+B,GAA3M,CAA4M,KAAKiuB,MAAL,GAAY,UAAS1tB,CAAT,EAAWD,CAAX,EAAaV,CAAb,EAAe;AAAC,QAAIG,CAAJ,EAAMF,CAAN,CAAQ,IAAGswB,QAAQhZ,IAAR,CAAaiZ,OAAb,CAAqB9vB,CAArB,CAAH,EAA2B;AAAC,UAAID,IAAE,KAAKgwB,QAAL,CAAc/vB,CAAd,CAAN,CAAuBP,IAAEM,EAAEqB,CAAJ,CAAM7B,IAAEQ,EAAEmB,CAAJ;AAAM,KAA/D,MAAmE;AAAC,UAAG,qBAAkBlB,CAAlB,yCAAkBA,CAAlB,MAAqBA,EAAEoB,CAAvB,IAA0BpB,EAAEkB,CAA/B,EAAiC;AAACzB,YAAEO,EAAEoB,CAAJ,CAAM7B,IAAES,EAAEkB,CAAJ;AAAM,OAA9C,MAAkD;AAAC,cAAK,6BAAL;AAAmC;AAAC,SAAIxB,CAAJ,CAAM,IAAGJ,aAAasZ,SAAhB,EAA0B;AAAClZ,UAAEJ,CAAF;AAAI,KAA/B,MAAmC;AAAC,UAAGuwB,QAAQhZ,IAAR,CAAaiZ,OAAb,CAAqBxwB,CAArB,CAAH,EAA2B;AAACI,YAAEkZ,UAAUoC,UAAV,CAAqB,KAAK4T,QAAL,CAAc/V,KAAnC,EAAyCvZ,CAAzC,CAAF;AAA8C,OAA1E,MAA8E;AAAC,cAAK,kEAAL;AAAwE;AAAC,SAAIoC,IAAE4G,WAAWmnB,qBAAX,CAAiCxvB,CAAjC,CAAN,CAA0C,OAAO,KAAK2vB,SAAL,CAAeluB,CAAf,EAAiBjC,CAAjB,EAAmBF,CAAnB,EAAqBG,CAArB,CAAP;AAA+B,GAA1c,CAA2c,KAAKkwB,SAAL,GAAe,UAAS3vB,CAAT,EAAWV,CAAX,EAAayD,CAAb,EAAetB,CAAf,EAAiB;AAAC,QAAIjC,IAAE,KAAKmvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIqD,IAAE,KAAKwrB,QAAL,CAAcppB,CAApB,CAAsB,IAAGjG,EAAEiM,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+BlM,EAAEiM,SAAF,CAAY/L,CAAZ,KAAgB,CAAlD,EAAoD;AAAC,aAAO,KAAP;AAAa,SAAGuD,EAAEwI,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+BzI,EAAEwI,SAAF,CAAY/L,CAAZ,KAAgB,CAAlD,EAAoD;AAAC,aAAO,KAAP;AAAa,SAAIO,IAAEgD,EAAE4R,UAAF,CAAanV,CAAb,CAAN,CAAsB,IAAIC,IAAEO,EAAEwU,QAAF,CAAWzU,CAAX,EAAcgM,GAAd,CAAkBvM,CAAlB,CAAN,CAA2B,IAAIH,IAAEC,EAAEkV,QAAF,CAAWzU,CAAX,EAAcgM,GAAd,CAAkBvM,CAAlB,CAAN,CAA2B,IAAIwB,IAAEmC,EAAEqR,QAAF,CAAW/U,CAAX,EAAcyT,GAAd,CAAkBzR,EAAE+S,QAAF,CAAWnV,CAAX,CAAlB,CAAN,CAAuC,IAAI0B,IAAEC,EAAE2Y,IAAF,GAASrB,YAAT,GAAwBvM,GAAxB,CAA4BvM,CAA5B,CAAN,CAAqC,OAAOuB,EAAE+S,MAAF,CAASxU,CAAT,CAAP;AAAmB,GAA5X,CAA6X,KAAKmwB,YAAL,GAAkB,UAAShwB,CAAT,EAAWJ,CAAX,EAAa;AAAC,QAAIG,IAAEC,EAAEswB,iBAAF,EAAN,CAA4B,IAAIzwB,IAAED,EAAE0wB,iBAAF,EAAN,CAA4B,IAAItuB,IAAE,EAAN,CAASA,EAAED,IAAF,CAAO,CAAP,EAAUC,EAAED,IAAF,CAAOhC,EAAED,MAAT,EAAiBkC,IAAEA,EAAEX,MAAF,CAAStB,CAAT,CAAF,CAAciC,EAAED,IAAF,CAAO,CAAP,EAAUC,EAAED,IAAF,CAAOlC,EAAEC,MAAT,EAAiBkC,IAAEA,EAAEX,MAAF,CAASxB,CAAT,CAAF,CAAcmC,EAAEqZ,OAAF,CAAUrZ,EAAElC,MAAZ,EAAoBkC,EAAEqZ,OAAF,CAAU,EAAV,EAAc,OAAOrZ,CAAP;AAAS,GAA9N,CAA+N,KAAKquB,QAAL,GAAc,UAAShwB,CAAT,EAAW;AAAC,QAAI2B,CAAJ,CAAM,IAAG3B,EAAE,CAAF,KAAM,EAAT,EAAY;AAAC,YAAM,IAAInB,KAAJ,CAAU,mCAAV,CAAN;AAAqD,SAAE,CAAF,CAAI,IAAGmB,EAAE2B,CAAF,KAAM,CAAT,EAAW;AAAC,YAAM,IAAI9C,KAAJ,CAAU,iDAAV,CAAN;AAAmE,SAAIa,IAAEM,EAAEwB,KAAF,CAAQG,IAAE,CAAV,EAAYA,IAAE,CAAF,GAAI3B,EAAE2B,IAAE,CAAJ,CAAhB,CAAN,CAA8BA,KAAG,IAAE3B,EAAE2B,IAAE,CAAJ,CAAL,CAAY,IAAG3B,EAAE2B,CAAF,KAAM,CAAT,EAAW;AAAC,YAAM,IAAI9C,KAAJ,CAAU,kDAAV,CAAN;AAAoE,SAAIW,IAAEQ,EAAEwB,KAAF,CAAQG,IAAE,CAAV,EAAYA,IAAE,CAAF,GAAI3B,EAAE2B,IAAE,CAAJ,CAAhB,CAAN,CAA8BA,KAAG,IAAE3B,EAAE2B,IAAE,CAAJ,CAAL,CAAY,IAAIhC,IAAE4I,WAAWmnB,qBAAX,CAAiChwB,CAAjC,CAAN,CAA0C,IAAIH,IAAEgJ,WAAWmnB,qBAAX,CAAiClwB,CAAjC,CAAN,CAA0C,OAAM,EAAC6B,GAAE1B,CAAH,EAAKwB,GAAE5B,CAAP,EAAN;AAAgB,GAA7b,CAA8b,KAAK2wB,eAAL,GAAqB,UAASvuB,CAAT,EAAW;AAAC,QAAGA,EAAElC,MAAF,KAAW,EAAd,EAAiB;AAAC,YAAK,gCAAL;AAAsC,SAAIF,IAAEoC,EAAE,CAAF,IAAK,EAAX,CAAc,IAAGpC,IAAE,CAAF,IAAKA,IAAE,CAAV,EAAY;AAAC,YAAK,wBAAL;AAA8B,SAAIW,IAAE,KAAK2uB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIN,IAAE6I,WAAWmnB,qBAAX,CAAiC/tB,EAAEH,KAAF,CAAQ,CAAR,EAAU,EAAV,CAAjC,EAAgDyK,GAAhD,CAAoD/L,CAApD,CAAN,CAA6D,IAAIP,IAAE4I,WAAWmnB,qBAAX,CAAiC/tB,EAAEH,KAAF,CAAQ,EAAR,EAAW,EAAX,CAAjC,EAAiDyK,GAAjD,CAAqD/L,CAArD,CAAN,CAA8D,OAAM,EAACmB,GAAE3B,CAAH,EAAKyB,GAAExB,CAAP,EAASH,GAAED,CAAX,EAAN;AAAoB,GAAvT,CAAwT,KAAK4wB,kBAAL,GAAwB,UAASzwB,CAAT,EAAW;AAAC,QAAIM,IAAEgiB,OAAN,CAAc,IAAIrgB,IAAEiV,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAInwB,IAAED,EAAE4iB,UAAR,CAAmB,IAAG5iB,EAAEgjB,SAAF,CAAYtjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIF,CAAJ,EAAMG,CAAN,EAAQO,CAAR,CAAU,IAAG;AAACV,UAAES,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBC,IAAEM,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAF,CAAkB,IAAG;AAACQ,YAAED,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,EAAkBuC,MAAlB,CAAyB,CAAzB,CAAF;AAA8B,OAAlC,CAAkC,OAAM1C,CAAN,EAAQ,CAAE;AAAC,KAAvF,CAAuF,OAAMA,CAAN,EAAQ;AAAC,YAAK,0CAAL;AAAgD,UAAK2vB,SAAL,GAAevtB,EAAEnC,CAAF,CAAf,CAAoB,IAAG,KAAK0vB,SAAL,KAAiB3wB,SAApB,EAA8B;AAAC,YAAK,wBAAL;AAA8B,UAAKqwB,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBlvB,CAArB,EAAwB,KAAKivB,gBAAL,CAAsBxvB,CAAtB,EAAyB,KAAK8X,QAAL,GAAc,KAAd;AAAoB,GAA/e,CAAgf,KAAK4Y,kBAAL,GAAwB,UAAS3wB,CAAT,EAAW;AAAC,QAAIwB,IAAE8gB,OAAN,CAAc,IAAIxiB,IAAEoX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAIpwB,IAAEkB,EAAE0hB,UAAR,CAAmB,IAAG1hB,EAAE8hB,SAAF,CAAYtjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIH,CAAJ,EAAMU,CAAN,EAAQ0B,CAAR,EAAUhC,CAAV,CAAY,IAAG;AAACJ,UAAES,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBO,IAAED,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBiC,IAAE3B,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsB,IAAG;AAACC,YAAEK,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,EAAO,CAAP,CAAN,EAAgB,IAAhB,EAAsBuC,MAAtB,CAA6B,CAA7B,CAAF;AAAkC,OAAtC,CAAsC,OAAM/B,CAAN,EAAQ,CAAE;AAAC,KAAnH,CAAmH,OAAMA,CAAN,EAAQ;AAAC,YAAK,wCAAL;AAA8C,UAAKgvB,SAAL,GAAe1vB,EAAES,CAAF,CAAf,CAAoB,IAAG,KAAKivB,SAAL,KAAiB3wB,SAApB,EAA8B;AAAC,YAAK,wBAAL;AAA8B,UAAKqwB,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBzvB,CAArB,EAAwB,KAAKwvB,gBAAL,CAAsBxtB,CAAtB,EAAyB,KAAK8V,QAAL,GAAc,KAAd;AAAoB,GAA3gB,CAA4gB,KAAK6Y,kBAAL,GAAwB,UAAS5wB,CAAT,EAAW;AAAC,QAAIM,IAAEgiB,OAAN,CAAc,IAAIrgB,IAAEiV,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAInwB,IAAED,EAAE4iB,UAAR,CAAmB,IAAG5iB,EAAEgjB,SAAF,CAAYtjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIC,CAAJ,EAAMH,CAAN,EAAQU,CAAR,CAAU,IAAG;AAACP,UAAEM,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBF,IAAES,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBQ,IAAED,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,EAAgBuC,MAAhB,CAAuB,CAAvB,CAAF;AAA4B,KAAxE,CAAwE,OAAM1C,CAAN,EAAQ;AAAC,YAAK,iCAAL;AAAuC,UAAK2vB,SAAL,GAAevtB,EAAEnC,CAAF,CAAf,CAAoB,IAAG,KAAK0vB,SAAL,KAAiB,IAApB,EAAyB;AAAC,YAAK,wBAAL;AAA8B,UAAKN,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBlvB,CAArB;AAAwB,GAAra,CAAsa,KAAKqwB,iBAAL,GAAuB,UAAS5wB,CAAT,EAAWM,CAAX,EAAa;AAAC,QAAGA,MAAI,CAAP,EAAS;AAACA,UAAE,CAAF;AAAI,SAAI0B,IAAEqgB,OAAN,CAAc,IAAItiB,IAAEkX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAIlwB,IAAEyB,EAAEihB,UAAR,CAAmB,IAAGjhB,EAAEqhB,SAAF,CAAYrjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIH,CAAJ,EAAMQ,CAAN,CAAQ,IAAG;AAACR,UAAEU,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAGM,CAAH,EAAK,CAAL,EAAO,CAAP,CAAN,EAAgB,IAAhB,CAAF,CAAwBD,IAAEE,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAGM,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,EAAoBgC,MAApB,CAA2B,CAA3B,CAAF;AAAgC,KAA5D,CAA4D,OAAM1C,CAAN,EAAQ;AAAC,YAAK,4CAAL;AAAkD,UAAK2vB,SAAL,GAAexvB,EAAEF,CAAF,CAAf,CAAoB,IAAG,KAAK0vB,SAAL,KAAiB,IAApB,EAAyB;AAAC,YAAK,wBAAL;AAA8B,UAAKN,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBpvB,CAArB;AAAwB,GAAjb,CAAkb,IAAGrB,MAAIJ,SAAP,EAAiB;AAAC,QAAGI,EAAEma,KAAF,KAAUva,SAAb,EAAuB;AAAC,WAAK2wB,SAAL,GAAevwB,EAAEma,KAAjB;AAAuB;AAAC,OAAG,KAAKoW,SAAL,KAAiB3wB,SAApB,EAA8B;AAAC,SAAK2wB,SAAL,GAAe9vB,CAAf;AAAiB,QAAKwvB,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,IAAGvwB,MAAIJ,SAAP,EAAiB;AAAC,QAAGI,EAAE6xB,GAAF,KAAQjyB,SAAX,EAAqB;AAAC,WAAK4wB,gBAAL,CAAsBxwB,EAAE6xB,GAAxB;AAA6B,SAAG7xB,EAAE8xB,GAAF,KAAQlyB,SAAX,EAAqB;AAAC,WAAK6wB,eAAL,CAAqBzwB,EAAE8xB,GAAvB;AAA4B;AAAC;AAAC,CAAxqN,CAAyqN7Z,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBwC,WAAlB,GAA8B,UAAShwB,CAAT,EAAW;AAAC,MAAIT,IAAEyX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBsD,kBAAlB,CAAqC9wB,CAArC,CAAN,CAA8C,IAAId,IAAE,IAAIyJ,UAAJ,CAAepJ,EAAEkC,CAAjB,EAAmB,EAAnB,CAAN,CAA6B,IAAIhC,IAAE,IAAIkJ,UAAJ,CAAepJ,EAAEgC,CAAjB,EAAmB,EAAnB,CAAN,CAA6B,OAAM,EAACE,GAAEvC,CAAH,EAAKqC,GAAE9B,CAAP,EAAN;AAAgB,CAAlK,CAAmKuX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBsD,kBAAlB,GAAqC,UAAS9xB,CAAT,EAAW;AAAC,MAAIW,IAAEyiB,OAAN,CAAc,IAAIxiB,IAAED,EAAEijB,WAAR,CAAoB,IAAI9jB,IAAEa,EAAE8iB,IAAR,CAAa,IAAGzjB,EAAEqD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,mCAAL;AAAyC,OAAItD,IAAEa,EAAEZ,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGD,EAAEc,MAAF,IAAU,CAAb,EAAe;AAAC,UAAK,wDAAL;AAA8D,OAAIL,IAAET,EAAE,CAAF,CAAN,CAAW,IAAIG,IAAEH,EAAE,CAAF,CAAN,CAAW,IAAGC,EAAEqD,MAAF,CAAS7C,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,uDAAL;AAA6D,OAAGR,EAAEqD,MAAF,CAASnD,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,uDAAL;AAA6D,OAAIO,IAAEX,EAAEE,CAAF,EAAIQ,CAAJ,CAAN,CAAa,IAAID,IAAET,EAAEE,CAAF,EAAIE,CAAJ,CAAN,CAAa,OAAM,EAACuC,GAAEhC,CAAH,EAAK8B,GAAEhC,CAAP,EAAN;AAAgB,CAAte,CAAueyX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBuD,kBAAlB,GAAqC,UAAStxB,CAAT,EAAW;AAAC,MAAIP,IAAE8X,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBsD,kBAAlB,CAAqCrxB,CAArC,CAAN,CAA8C,IAAIF,IAAEL,EAAEuC,CAAR,CAAU,IAAIzB,IAAEd,EAAEqC,CAAR,CAAU,IAAGhC,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAf,IAAsB9C,EAAEM,MAAF,GAAS,EAAV,IAAe,CAAvC,EAAyC;AAACN,QAAEA,EAAE8C,MAAF,CAAS,CAAT,CAAF;AAAc,OAAGrC,EAAEqC,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAf,IAAsBrC,EAAEH,MAAF,GAAS,EAAV,IAAe,CAAvC,EAAyC;AAACG,QAAEA,EAAEqC,MAAF,CAAS,CAAT,CAAF;AAAc,OAAI9C,EAAEM,MAAF,GAAS,EAAV,IAAe,EAAlB,EAAqB;AAACN,QAAE,OAAKA,CAAP;AAAS,OAAIS,EAAEH,MAAF,GAAS,EAAV,IAAe,EAAlB,EAAqB;AAACG,QAAE,OAAKA,CAAP;AAAS,OAAGT,EAAEM,MAAF,GAAS,EAAT,IAAa,CAAhB,EAAkB;AAAC,UAAK,kCAAL;AAAwC,OAAGG,EAAEH,MAAF,GAAS,EAAT,IAAa,CAAhB,EAAkB;AAAC,UAAK,kCAAL;AAAwC,UAAON,IAAES,CAAT;AAAW,CAAla,CAAmagX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBwD,kBAAlB,GAAqC,UAAShxB,CAAT,EAAW;AAAC,MAAMA,EAAEH,MAAF,GAAS,CAAV,GAAa,CAAd,IAAkB,KAAG,CAArB,CAAD,IAA2B,CAA9B,EAAgC;AAAC,UAAK,kDAAL;AAAwD,OAAIJ,IAAEO,EAAEqC,MAAF,CAAS,CAAT,EAAWrC,EAAEH,MAAF,GAAS,CAApB,CAAN,CAA6B,IAAIN,IAAES,EAAEqC,MAAF,CAASrC,EAAEH,MAAF,GAAS,CAAlB,CAAN,CAA2B,OAAOmX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkByD,iBAAlB,CAAoCxxB,CAApC,EAAsCF,CAAtC,CAAP;AAAgD,CAAlP,CAAmPyX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkByD,iBAAlB,GAAoC,UAAS1xB,CAAT,EAAWS,CAAX,EAAa;AAAC,MAAId,IAAE,IAAIyJ,UAAJ,CAAepJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIE,IAAE,IAAIkJ,UAAJ,CAAe3I,CAAf,EAAiB,EAAjB,CAAN,CAA2B,OAAOgX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBqC,gBAAlB,CAAmC3wB,CAAnC,EAAqCO,CAArC,CAAP;AAA+C,CAAvJ,CAAwJuX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBqC,gBAAlB,GAAmC,UAAS7wB,CAAT,EAAWE,CAAX,EAAa;AAAC,MAAIO,IAAEuX,KAAKkF,IAAX,CAAgB,IAAI3c,IAAE,IAAIE,EAAEid,UAAN,CAAiB,EAACmE,QAAO7hB,CAAR,EAAjB,CAAN,CAAmC,IAAIgB,IAAE,IAAIP,EAAEid,UAAN,CAAiB,EAACmE,QAAO3hB,CAAR,EAAjB,CAAN,CAAmC,IAAIM,IAAE,IAAIC,EAAE8d,WAAN,CAAkB,EAACI,OAAM,CAACpe,CAAD,EAAGS,CAAH,CAAP,EAAlB,CAAN,CAAuC,OAAOR,EAAEwe,aAAF,EAAP;AAAyB,CAAvM,CAAwMhH,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAlB,GAA0B,UAASxwB,CAAT,EAAW;AAAC,MAAGA,MAAI,kBAAP,EAA0B;AAAC,WAAM,WAAN;AAAkB,OAAGA,MAAI,YAAP,EAAoB;AAAC,WAAM,WAAN;AAAkB,OAAGA,MAAI,YAAP,EAAoB;AAAC,WAAM,WAAN;AAAkB,OAAG,0CAA0CkF,OAA1C,CAAkDlF,CAAlD,MAAuD,CAAC,CAA3D,EAA6D;AAAC,WAAM,WAAN;AAAkB,OAAG,cAAckF,OAAd,CAAsBlF,CAAtB,MAA2B,CAAC,CAA/B,EAAiC;AAAC,WAAM,WAAN;AAAkB,OAAG,+BAA+BkF,OAA/B,CAAuClF,CAAvC,MAA4C,CAAC,CAAhD,EAAkD;AAAC,WAAM,WAAN;AAAkB,UAAO,IAAP;AAAY,CAAtX;AACt5Q,IAAG,OAAOgX,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UAwE3BA,IAxE2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKf,MAAZ,IAAoB,WAApB,IAAiC,CAACe,KAAKf,MAA1C,EAAiD;AAACe,OAAKf,MAAL,GAAY,EAAZ;AAAe,MAAKA,MAAL,CAAYiZ,aAAZ,GAA0B,IAAI,YAAU;AAAC,MAAI3vB,IAAE,EAAN,CAAS,IAAIE,IAAE,EAAN,CAAS,SAASO,CAAT,CAAWd,CAAX,EAAa;AAAC,WAAO,IAAIyJ,UAAJ,CAAezJ,CAAf,EAAiB,EAAjB,CAAP;AAA4B,QAAKiwB,SAAL,GAAe,UAAS3vB,CAAT,EAAW;AAAC,QAAIN,IAAEM,CAAN,CAAQ,IAAG,OAAOC,EAAEP,CAAF,CAAP,IAAa,WAAhB,EAA4B;AAACA,UAAEO,EAAED,CAAF,CAAF;AAAO,SAAG,OAAOD,EAAEL,CAAF,CAAP,IAAa,WAAhB,EAA4B;AAAC,aAAOK,EAAEL,CAAF,CAAP;AAAY,WAAK,iCAA+BA,CAApC;AAAsC,GAAtJ,CAAuJ,KAAKgyB,MAAL,GAAY,UAASlqB,CAAT,EAAWlH,CAAX,EAAaQ,CAAb,EAAexB,CAAf,EAAiBiD,CAAjB,EAAmBvC,CAAnB,EAAqBG,CAArB,EAAuBX,CAAvB,EAAyBe,CAAzB,EAA2B0D,CAA3B,EAA6BvE,CAA7B,EAA+BoE,CAA/B,EAAiC;AAAC/D,MAAEyH,CAAF,IAAK,EAAL,CAAQ,IAAIzF,IAAEvB,EAAEM,CAAF,CAAN,CAAW,IAAIyG,IAAE/G,EAAElB,CAAF,CAAN,CAAW,IAAImI,IAAEjH,EAAE+B,CAAF,CAAN,CAAW,IAAIV,IAAErB,EAAER,CAAF,CAAN,CAAW,IAAI6D,IAAErD,EAAEL,CAAF,CAAN,CAAW,IAAI8B,IAAE,IAAI2Y,SAAJ,CAAc7Y,CAAd,EAAgBwF,CAAhB,EAAkBE,CAAlB,CAAN,CAA2B,IAAI3F,IAAEG,EAAEuZ,cAAF,CAAiB,OAAKhc,CAAL,GAAOe,CAAxB,CAAN,CAAiCR,EAAEyH,CAAF,EAAK,MAAL,IAAaA,CAAb,CAAezH,EAAEyH,CAAF,EAAK,QAAL,IAAelH,CAAf,CAAiBP,EAAEyH,CAAF,EAAK,OAAL,IAAcvF,CAAd,CAAgBlC,EAAEyH,CAAF,EAAK,GAAL,IAAU1F,CAAV,CAAY/B,EAAEyH,CAAF,EAAK,GAAL,IAAU3F,CAAV,CAAY9B,EAAEyH,CAAF,EAAK,GAAL,IAAU3D,CAAV,CAAY9D,EAAEyH,CAAF,EAAK,KAAL,IAAY9H,CAAZ,CAAcK,EAAEyH,CAAF,EAAK,MAAL,IAAa1D,CAAb,CAAe,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEC,EAAE5D,MAAhB,EAAuB2D,GAAvB,EAA2B;AAAC/D,QAAEgE,EAAED,CAAF,CAAF,IAAQwD,CAAR;AAAU;AAAC,GAAjU;AAAkU,CAApiB,EAA1B,CAA+jBgQ,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kCAAjD,EAAoF,kCAApF,EAAuH,kCAAvH,EAA0J,kCAA1J,EAA6L,GAA7L,EAAiM,kCAAjM,EAAoO,kCAApO,EAAuQ,EAAvQ,EAA0Q,EAA1Q,EAA6Q,mDAA7Q,EAAkUla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,0CAAjD,EAA4F,GAA5F,EAAgG,GAAhG,EAAoG,4CAApG,EAAiJ,GAAjJ,EAAqJ,0CAArJ,EAAgM,0CAAhM,EAA2O,EAA3O,EAA8O,EAA9O,EAAiP,mDAAjP,EAAsSla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,0CAAjD,EAA4F,0CAA5F,EAAuI,0CAAvI,EAAkL,4CAAlL,EAA+N,GAA/N,EAAmO,0CAAnO,EAA8Q,0CAA9Q,EAAyT,EAAzT,EAA4T,EAA5T,EAA+T,mDAA/T,EAAoXla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kDAAjD,EAAoG,GAApG,EAAwG,GAAxG,EAA4G,kDAA5G,EAA+J,GAA/J,EAAmK,kDAAnK,EAAsN,kDAAtN,EAAyQ,EAAzQ,EAA6Qla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kDAAjD,EAAoG,kDAApG,EAAuJ,kDAAvJ,EAA0M,kDAA1M,EAA6P,GAA7P,EAAiQ,kDAAjQ,EAAoT,kDAApT,EAAuW,EAAvW,EAA2Wla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,0DAAjD,EAA4G,0DAA5G,EAAuK,0DAAvK,EAAkO,0DAAlO,EAA6R,GAA7R,EAAiS,0DAAjS,EAA4V,0DAA5V,EAAuZ,EAAvZ,EAA2Zla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kEAAjD,EAAoH,GAApH,EAAwH,GAAxH,EAA4H,kEAA5H,EAA+L,GAA/L,EAAmM,kEAAnM,EAAsQ,kEAAtQ,EAAyU,EAAzU,EAA6Ula,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kEAAjD,EAAoH,kEAApH,EAAuL,kEAAvL,EAA0P,kEAA1P,EAA6T,GAA7T,EAAiU,kEAAjU,EAAoY,kEAApY,EAAuc,CAAC,YAAD,EAAc,OAAd,EAAsB,YAAtB,CAAvc,EAA4ela,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kGAAjD,EAAoJ,kGAApJ,EAAuP,kGAAvP,EAA0V,kGAA1V,EAA6b,GAA7b,EAAic,kGAAjc,EAAoiB,kGAApiB,EAAuoB,CAAC,YAAD,EAAc,OAAd,CAAvoB,EAA+pBla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,qIAAjD,EAAuL,qIAAvL,EAA6T,qIAA7T,EAAmc,qIAAnc,EAAykB,GAAzkB,EAA6kB,oIAA7kB,EAAktB,sIAAltB,EAAy1B,CAAC,YAAD,EAAc,OAAd,CAAz1B;AACnnI,IAAInE,UAAQ,YAAU;AAAC,MAAI7tB,IAAE,SAAFA,CAAE,CAASmB,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOvB,EAAEE,SAASkxB,GAAX,EAAe9wB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAI9B,IAAE,SAAFA,CAAE,CAASa,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOvB,EAAEE,SAASmxB,SAAX,EAAqB/wB,CAArB,EAAuBoB,CAAvB,EAAyBH,CAAzB,CAAP;AAAmC,GAAzD,CAA0D,IAAItB,IAAE,SAAFA,CAAE,CAASK,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOvB,EAAEE,SAASoxB,GAAX,EAAehxB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAIvB,IAAE,SAAFA,CAAE,CAASwB,CAAT,EAAW+B,CAAX,EAAaG,CAAb,EAAenC,CAAf,EAAiB;AAAC,QAAIG,IAAExB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBmB,CAAvB,CAAN,CAAgC,IAAID,IAAEpD,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBsB,CAAvB,CAAN,CAAgC,IAAIpD,IAAEJ,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBb,CAAvB,CAAN,CAAgC,IAAID,IAAE,EAAN,CAASA,EAAEiwB,GAAF,GAAMjuB,CAAN,CAAQhC,EAAEkwB,EAAF,GAAKlxB,CAAL,CAAOgB,EAAEmwB,UAAF,GAAa/vB,CAAb,CAAe,IAAI+B,IAAEjC,EAAEqtB,OAAF,CAAUvtB,CAAV,EAAYgC,CAAZ,EAAc,EAACkuB,IAAGlxB,CAAJ,EAAd,CAAN,CAA4B,OAAOJ,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BqC,CAA3B,CAAP;AAAqC,GAAhO,CAAiO,IAAI1D,IAAE,SAAFA,CAAE,CAASO,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOxC,EAAEmB,SAASkxB,GAAX,EAAe9wB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAIhB,IAAE,SAAFA,CAAE,CAASD,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOxC,EAAEmB,SAASmxB,SAAX,EAAqB/wB,CAArB,EAAuBoB,CAAvB,EAAyBH,CAAzB,CAAP;AAAmC,GAAzD,CAA0D,IAAItC,IAAE,SAAFA,CAAE,CAASqB,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOxC,EAAEmB,SAASoxB,GAAX,EAAehxB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAIxC,IAAE,SAAFA,CAAE,CAASuC,CAAT,EAAW4F,CAAX,EAAazD,CAAb,EAAelC,CAAf,EAAiB;AAAC,QAAIC,IAAEtB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuB8E,CAAvB,CAAN,CAAgC,IAAI3D,IAAErD,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBqB,CAAvB,CAAN,CAAgC,IAAInD,IAAEJ,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBb,CAAvB,CAAN,CAAgC,IAAI+B,IAAEhC,EAAE+W,OAAF,CAAU7W,CAAV,EAAY+B,CAAZ,EAAc,EAACiuB,IAAGlxB,CAAJ,EAAd,CAAN,CAA4B,IAAIoB,IAAExB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBkB,EAAEvC,QAAF,EAAvB,CAAN,CAA2C,IAAI2C,IAAExD,SAAS+B,GAAT,CAAa+C,MAAb,CAAoB5D,SAApB,CAA8BM,CAA9B,CAAN,CAAuC,OAAOgC,CAAP;AAAS,GAA/O,CAAgP,IAAI7D,IAAE,EAAC,eAAc,EAAC6xB,MAAKvyB,CAAN,EAAQwyB,OAAM5xB,CAAd,EAAgB4vB,QAAO,EAAvB,EAA0BiC,OAAM,EAAhC,EAAf,EAAmD,eAAc,EAACF,MAAKvyB,CAAN,EAAQwyB,OAAM5xB,CAAd,EAAgB4vB,QAAO,EAAvB,EAA0BiC,OAAM,EAAhC,EAAjE,EAAqG,eAAc,EAACF,MAAKvyB,CAAN,EAAQwyB,OAAM5xB,CAAd,EAAgB4vB,QAAO,EAAvB,EAA0BiC,OAAM,EAAhC,EAAnH,EAAuJ,gBAAe,EAACF,MAAKjyB,CAAN,EAAQkyB,OAAMpxB,CAAd,EAAgBovB,QAAO,EAAvB,EAA0BiC,OAAM,CAAhC,EAAtK,EAAyM,WAAU,EAACF,MAAKzxB,CAAN,EAAQ0xB,OAAM1yB,CAAd,EAAgB0wB,QAAO,CAAvB,EAAyBiC,OAAM,CAA/B,EAAnN,EAAN,CAA4P,IAAIlyB,IAAE,SAAFA,CAAE,CAASY,CAAT,EAAW;AAAC,WAAOT,EAAES,CAAF,EAAK,MAAL,CAAP;AAAoB,GAAtC,CAAuC,IAAI0B,IAAE,SAAFA,CAAE,CAAS1B,CAAT,EAAW;AAAC,QAAIoB,IAAExB,SAASC,GAAT,CAAac,SAAb,CAAuBa,MAAvB,CAA8BxB,CAA9B,CAAN,CAAuC,IAAIiB,IAAErB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BM,CAA3B,CAAN,CAAoC,OAAOH,CAAP;AAAS,GAAtG,CAAuG,IAAIlB,IAAE,SAAFA,CAAE,CAASoD,CAAT,EAAW;AAAC,QAAIH,IAAE,EAAN,CAAS,IAAI/B,IAAEkC,EAAEuY,KAAF,CAAQ,IAAID,MAAJ,CAAW,kCAAX,EAA8C,GAA9C,CAAR,CAAN,CAAkE,IAAGxa,CAAH,EAAK;AAAC+B,QAAEuuB,MAAF,GAAStwB,EAAE,CAAF,CAAT,CAAc+B,EAAEwuB,MAAF,GAASvwB,EAAE,CAAF,CAAT;AAAc,SAAIjB,IAAEmD,EAAEuY,KAAF,CAAQ,IAAID,MAAJ,CAAW,sCAAX,CAAR,CAAN,CAAkE,IAAGzb,CAAH,EAAK;AAACgD,QAAEiV,IAAF,GAAOjY,EAAE,CAAF,CAAP;AAAY,SAAIoD,IAAE,CAAC,CAAP,CAAS,IAAIH,IAAE,CAAN,CAAQ,IAAGE,EAAE0B,OAAF,CAAU,UAAV,KAAuB,CAAC,CAA3B,EAA6B;AAACzB,UAAED,EAAE0B,OAAF,CAAU,UAAV,CAAF,CAAwB5B,IAAE,CAAF;AAAI,SAAGE,EAAE0B,OAAF,CAAU,MAAV,KAAmB,CAAC,CAAvB,EAAyB;AAACzB,UAAED,EAAE0B,OAAF,CAAU,MAAV,CAAF,CAAoB5B,IAAE,CAAF;AAAI,SAAIjC,IAAEmC,EAAE0B,OAAF,CAAU,UAAV,CAAN,CAA4B,IAAGzB,KAAG,CAAC,CAAJ,IAAOpC,KAAG,CAAC,CAAd,EAAgB;AAAC,UAAII,IAAE+B,EAAE2E,SAAF,CAAY1E,IAAEH,IAAE,CAAhB,EAAkBjC,IAAEiC,CAApB,CAAN,CAA6B7B,IAAEA,EAAEua,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB3Y,EAAEyuB,IAAF,GAAOrwB,CAAP;AAAS,YAAO4B,CAAP;AAAS,GAAnc,CAAoc,IAAI1D,IAAE,SAAFA,CAAE,CAAS2B,CAAT,EAAW2F,CAAX,EAAa5G,CAAb,EAAe;AAAC,QAAImD,IAAEnD,EAAE8H,SAAF,CAAY,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAI9G,IAAEpB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBqB,CAAvB,CAAN,CAAgC,IAAI/B,IAAExB,SAAS+B,GAAT,CAAaU,IAAb,CAAkBP,KAAlB,CAAwB8E,CAAxB,CAAN,CAAiC,IAAIxD,IAAE7D,EAAE0B,CAAF,EAAK,QAAL,IAAe1B,EAAE0B,CAAF,EAAK,OAAL,CAArB,CAAmC,IAAIgC,IAAE,EAAN,CAAS,IAAID,IAAE,IAAN,CAAW,SAAO;AAAC,UAAI9B,IAAEtB,SAASuE,IAAT,CAAcqlB,GAAd,CAAkBhpB,MAAlB,EAAN,CAAiC,IAAGwC,KAAG,IAAN,EAAW;AAAC9B,UAAE2C,MAAF,CAASb,CAAT;AAAY,SAAEa,MAAF,CAASzC,CAAT,EAAYF,EAAE2C,MAAF,CAAS7C,CAAT,EAAYgC,IAAE9B,EAAE4C,QAAF,EAAF,CAAeb,IAAEA,IAAErD,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BkC,CAA3B,CAAJ,CAAkC,IAAGC,EAAEzD,MAAF,IAAU4D,IAAE,CAAf,EAAiB;AAAC;AAAM;AAAC,SAAIsD,IAAE,EAAN,CAASA,EAAEgrB,MAAF,GAASzuB,EAAEjB,MAAF,CAAS,CAAT,EAAWzC,EAAE0B,CAAF,EAAK,QAAL,IAAe,CAA1B,CAAT,CAAsCyF,EAAEirB,KAAF,GAAQ1uB,EAAEjB,MAAF,CAASzC,EAAE0B,CAAF,EAAK,QAAL,IAAe,CAAxB,EAA0B1B,EAAE0B,CAAF,EAAK,OAAL,IAAc,CAAxC,CAAR,CAAmD,OAAOyF,CAAP;AAAS,GAApb,CAAqb,IAAIxH,IAAE,SAAFA,CAAE,CAASc,CAAT,EAAWmD,CAAX,EAAa/B,CAAb,EAAe4B,CAAf,EAAiB;AAAC,QAAI9B,IAAEtB,SAAS+B,GAAT,CAAa+C,MAAb,CAAoB5C,KAApB,CAA0B9B,CAA1B,CAAN,CAAmC,IAAIiB,IAAErB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BI,CAA3B,CAAN,CAAoC,IAAIkC,IAAE7D,EAAE4D,CAAF,EAAK,MAAL,CAAN,CAAmB,IAAInC,IAAEoC,EAAEnC,CAAF,EAAIG,CAAJ,EAAM4B,CAAN,CAAN,CAAe,OAAOhC,CAAP;AAAS,GAA1I,CAA2I,IAAItC,IAAE,SAAFA,CAAE,CAASsB,CAAT,EAAWkB,CAAX,EAAaD,CAAb,EAAemC,CAAf,EAAiB;AAAC,QAAIhC,IAAE7B,EAAE2B,CAAF,EAAK,OAAL,CAAN,CAAoB,IAAIF,IAAEI,EAAEpB,CAAF,EAAIiB,CAAJ,EAAMmC,CAAN,CAAN,CAAe,OAAOpC,CAAP;AAAS,GAApE,CAAqE,OAAM,EAAC4wB,SAAQ,OAAT,EAAiBC,eAAc,uBAAS7xB,CAAT,EAAW;AAAC,aAAOD,EAAEC,CAAF,CAAP;AAAY,KAAvD,EAAwD8xB,sCAAqC,8CAAS7wB,CAAT,EAAWjB,CAAX,EAAaoB,CAAb,EAAe;AAAC,aAAO9B,EAAE2B,CAAF,EAAIjB,CAAJ,EAAMoB,CAAN,CAAP;AAAgB,KAA7H,EAA8H2wB,eAAc,uBAAS/xB,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAeC,CAAf,EAAiB;AAAC,aAAOhC,EAAEc,CAAF,EAAIoB,CAAJ,EAAMH,CAAN,EAAQC,CAAR,CAAP;AAAkB,KAAhL,EAAiL8wB,oBAAmB,4BAASprB,CAAT,EAAW3D,CAAX,EAAa;AAAC,UAAIhC,IAAElB,EAAE6G,CAAF,CAAN,CAAW,IAAI5F,IAAEC,EAAEgX,IAAR,CAAa,IAAI7W,IAAEH,EAAEswB,MAAR,CAAe,IAAIvxB,IAAEiB,EAAEuwB,MAAR,CAAe,IAAItwB,IAAED,EAAEwwB,IAAR,CAAa,IAAIzuB,IAAE1D,EAAE8B,CAAF,EAAI6B,CAAJ,EAAMjD,CAAN,CAAN,CAAe,IAAImD,IAAEH,EAAE0uB,MAAR,CAAe,IAAItuB,IAAElE,EAAEgC,CAAF,EAAIE,CAAJ,EAAM+B,CAAN,EAAQnD,CAAR,CAAN,CAAiB,OAAOoD,CAAP;AAAS,KAA7U,EAA8U6uB,mCAAkC,2CAAShvB,CAAT,EAAW/B,CAAX,EAAayF,CAAb,EAAe3F,CAAf,EAAiBI,CAAjB,EAAmB;AAAC,UAAIpB,IAAE,EAAN,CAAS,IAAG,OAAOgB,CAAP,IAAU,WAAV,IAAuBA,KAAG,IAA7B,EAAkC;AAACA,YAAE,aAAF;AAAgB,WAAG,OAAOzB,EAAEyB,CAAF,CAAP,IAAa,WAAhB,EAA4B;AAAC,cAAK,oCAAkCA,CAAvC;AAAyC,WAAG,OAAOI,CAAP,IAAU,WAAV,IAAuBA,KAAG,IAA7B,EAAkC;AAAC,YAAI+B,IAAE5D,EAAEyB,CAAF,EAAK,OAAL,CAAN,CAAoB,IAAIoC,IAAE1B,EAAEyB,CAAF,CAAN,CAAW/B,IAAEgC,EAAE8uB,WAAF,EAAF;AAAkB,WAAIxrB,IAAEpH,EAAE0B,CAAF,EAAI2F,CAAJ,EAAMvF,CAAN,CAAN,CAAe,IAAIwF,IAAEF,EAAEgrB,MAAR,CAAe,IAAI1uB,IAAEtE,EAAEwC,CAAF,EAAIF,CAAJ,EAAM4F,CAAN,EAAQxF,CAAR,CAAN,CAAiB,IAAIH,IAAE+B,EAAE2Y,OAAF,CAAU,UAAV,EAAqB,QAArB,CAAN,CAAqC,IAAI3b,IAAE,gBAAciD,CAAd,GAAgB,uBAAtB,CAA8CjD,KAAG,4BAAH,CAAgCA,KAAG,eAAagB,CAAb,GAAe,GAAf,GAAmBI,CAAnB,GAAqB,MAAxB,CAA+BpB,KAAG,MAAH,CAAUA,KAAGiB,CAAH,CAAKjB,KAAG,kBAAgBiD,CAAhB,GAAkB,uBAArB,CAA6C,OAAOjD,CAAP;AAAS,KAAh2B,EAAi2BmyB,0BAAyB,kCAASvrB,CAAT,EAAW;AAAC,UAAIE,IAAEib,OAAN,CAAc,IAAIrb,IAAEI,EAAEyb,WAAR,CAAoB,IAAIvf,IAAE8D,EAAEsb,IAAR,CAAa,IAAIphB,IAAE,EAAN,CAAS,IAAII,IAAEsF,EAAEE,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGxF,EAAE5B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,+CAA6C4B,EAAE5B,MAApD;AAA2D,SAAE2xB,UAAF,GAAanuB,EAAE4D,CAAF,EAAIxF,EAAE,CAAF,CAAJ,CAAb,CAAuB,IAAIuF,IAAED,EAAEE,CAAF,EAAIxF,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGuF,EAAEnH,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,iDAA+CmH,EAAEnH,MAAtD;AAA6D,WAAGwD,EAAE4D,CAAF,EAAID,EAAE,CAAF,CAAJ,KAAW,oBAAd,EAAmC;AAAC,cAAK,+BAAL;AAAqC,WAAI3G,IAAE0G,EAAEE,CAAF,EAAID,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGA,EAAEnH,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,mDAAiDQ,EAAER,MAAxD;AAA+D,WAAIyB,IAAEyF,EAAEE,CAAF,EAAI5G,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGiB,EAAEzB,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,qDAAmDyB,EAAEzB,MAA1D;AAAiE,WAAGwD,EAAE4D,CAAF,EAAI3F,EAAE,CAAF,CAAJ,KAAW,kBAAd,EAAiC;AAAC,cAAK,8BAAL;AAAoC,SAAEmxB,mBAAF,GAAsB,WAAtB,CAAkCpxB,EAAEqxB,kBAAF,GAAqBrvB,EAAE4D,CAAF,EAAI3F,EAAE,CAAF,CAAJ,CAArB,CAA+B,IAAIC,IAAEwF,EAAEE,CAAF,EAAI5G,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGkB,EAAE1B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,qDAAmD0B,EAAE1B,MAA1D;AAAiE,WAAGwD,EAAE4D,CAAF,EAAI1F,EAAE,CAAF,CAAJ,KAAW,oBAAd,EAAmC;AAAC,cAAK,gCAAL;AAAsC,WAAI+B,IAAEyD,EAAEE,CAAF,EAAI1F,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAG+B,EAAEzD,MAAF,GAAS,CAAZ,EAAc;AAAC,cAAK,sDAAoDyD,EAAEzD,MAA3D;AAAkE,SAAE8yB,UAAF,GAAatvB,EAAE4D,CAAF,EAAI3D,EAAE,CAAF,CAAJ,CAAb,CAAuB,IAAIG,IAAEJ,EAAE4D,CAAF,EAAI3D,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAG;AAACjC,UAAEuxB,UAAF,GAAaxwB,SAASqB,CAAT,EAAW,EAAX,CAAb;AAA4B,OAAhC,CAAgC,OAAMD,CAAN,EAAQ;AAAC,cAAK,kCAAgCC,CAArC;AAAuC,cAAOpC,CAAP;AAAS,KAAt6D,EAAu6DwxB,0BAAyB,kCAASpvB,CAAT,EAAWpD,CAAX,EAAa;AAAC,UAAIgB,IAAEpB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBsB,EAAEkvB,UAAzB,CAAN,CAA2C,IAAIrxB,IAAEmC,EAAEmvB,UAAR,CAAmB,IAAIrxB,IAAEtB,SAAS6yB,MAAT,CAAgBzyB,CAAhB,EAAkBgB,CAAlB,EAAoB,EAAC0xB,SAAQ,MAAI,EAAb,EAAgBC,YAAW1xB,CAA3B,EAApB,CAAN,CAAyD,IAAIG,IAAExB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BI,CAA3B,CAAN,CAAoC,OAAOE,CAAP;AAAS,KAAlnE,EAAmnEwxB,wCAAuC,gDAAS3vB,CAAT,EAAW2D,CAAX,EAAa;AAAC,UAAIxF,IAAEwjB,SAAS3hB,CAAT,EAAW,uBAAX,CAAN,CAA0C,IAAIjD,IAAE,KAAKmyB,wBAAL,CAA8B/wB,CAA9B,CAAN,CAAuC,IAAIgC,IAAEspB,QAAQ8F,wBAAR,CAAiCxyB,CAAjC,EAAmC4G,CAAnC,CAAN,CAA4C,IAAIzD,IAAE,EAAN,CAASA,EAAEguB,UAAF,GAAavxB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuB9B,EAAEmxB,UAAzB,CAAb,CAAkD,IAAInwB,IAAEpB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBsB,CAAvB,CAAN,CAAgC,IAAIlC,IAAEtB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuB9B,EAAEqyB,kBAAzB,CAAN,CAAmD,IAAIrvB,IAAEpD,SAASmxB,SAAT,CAAmBxC,OAAnB,CAA2BprB,CAA3B,EAA6BnC,CAA7B,EAA+B,EAACkwB,IAAGhwB,CAAJ,EAA/B,CAAN,CAA6C,IAAID,IAAErB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BkC,CAA3B,CAAN,CAAoC,OAAO/B,CAAP;AAAS,KAA7gF,EAA8gF4xB,6BAA4B,qCAAS3xB,CAAT,EAAWD,CAAX,EAAa;AAAC,UAAIjB,IAAE,KAAK4yB,sCAAL,CAA4C1xB,CAA5C,EAA8CD,CAA9C,CAAN,CAAuD,IAAIG,IAAE,KAAK0xB,8BAAL,CAAoC9yB,CAApC,CAAN,CAA6C,OAAOoB,CAAP;AAAS,KAArqF,EAAsqF2xB,2BAA0B,mCAAS7xB,CAAT,EAAW;AAAC,UAAIiC,IAAE4e,OAAN,CAAc,IAAI3e,IAAED,EAAEof,WAAR,CAAoB,IAAIvhB,IAAEmC,EAAEif,IAAR,CAAa,IAAInhB,IAAE,EAAN,CAASA,EAAE+xB,QAAF,GAAW,IAAX,CAAgB,IAAG9xB,EAAEc,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,cAAK,6CAAL;AAAmD,WAAIZ,IAAEgC,EAAElC,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGE,EAAE5B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,6CAAL;AAAmD,WAAG0B,EAAEc,MAAF,CAASZ,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,uCAAL;AAA6C,WAAIpB,IAAEoD,EAAElC,CAAF,EAAIE,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGpB,EAAER,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,uCAAL;AAA6C,WAAG0B,EAAEc,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,uCAAL;AAA6C,SAAEizB,MAAF,GAASjyB,EAAEE,CAAF,EAAIlB,EAAE,CAAF,CAAJ,CAAT,CAAmB,IAAGkB,EAAEc,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAACiB,UAAE+xB,QAAF,GAAWhyB,EAAEE,CAAF,EAAIlB,EAAE,CAAF,CAAJ,CAAX;AAAqB,WAAGkB,EAAEc,MAAF,CAASZ,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,uCAAL;AAA6C,SAAE8xB,MAAF,GAAS/vB,EAAEgf,OAAF,CAAUjhB,CAAV,EAAYE,EAAE,CAAF,CAAZ,CAAT,CAA2B,OAAOH,CAAP;AAAS,KAA3zG,EAA4zGkyB,gCAA+B,wCAASlyB,CAAT,EAAW;AAAC,UAAIjB,IAAE4kB,SAAS3jB,CAAT,EAAW,aAAX,CAAN,CAAgC,IAAIG,IAAE,KAAK0xB,8BAAL,CAAoC9yB,CAApC,CAAN,CAA6C,OAAOoB,CAAP;AAAS,KAA77G,EAA87G0xB,gCAA+B,wCAAS9yB,CAAT,EAAW;AAAC,UAAIiB,IAAE,KAAK8xB,yBAAL,CAA+B/yB,CAA/B,CAAN,CAAwC,IAAIoB,CAAJ,CAAM,IAAGH,EAAEgyB,MAAF,IAAU,oBAAb,EAAkC;AAAC7xB,YAAE,IAAI+V,MAAJ,EAAF;AAAe,OAAlD,MAAsD;AAAC,YAAGlW,EAAEgyB,MAAF,IAAU,gBAAb,EAA8B;AAAC7xB,cAAE,IAAIuV,KAAKf,MAAL,CAAY6X,GAAhB,EAAF;AAAwB,SAAvD,MAA2D;AAAC,cAAGxsB,EAAEgyB,MAAF,IAAU,gBAAb,EAA8B;AAAC7xB,gBAAE,IAAIuV,KAAKf,MAAL,CAAYuX,KAAhB,EAAF;AAA0B,WAAzD,MAA6D;AAAC,kBAAK,mCAAL;AAAyC;AAAC;AAAC,SAAEiD,kBAAF,CAAqBpwB,CAArB,EAAwB,OAAOoB,CAAP;AAAS,KAApxH,EAAqxHgyB,2BAA0B,mCAASnyB,CAAT,EAAW;AAAC,UAAIjB,CAAJ,CAAM,IAAIoB,IAAE2gB,QAAQY,UAAR,CAAmB1hB,CAAnB,EAAqB,CAArB,EAAuB,CAAC,CAAD,EAAG,CAAH,CAAvB,EAA6B,IAA7B,CAAN,CAAyC,IAAGG,MAAI,oBAAP,EAA4B;AAACpB,YAAE,IAAImX,MAAJ,EAAF;AAAe,OAA5C,MAAgD;AAAC,YAAG/V,MAAI,gBAAP,EAAwB;AAACpB,cAAE,IAAI2W,KAAKf,MAAL,CAAY6X,GAAhB,EAAF;AAAwB,SAAjD,MAAqD;AAAC,cAAGrsB,MAAI,gBAAP,EAAwB;AAACpB,gBAAE,IAAI2W,KAAKf,MAAL,CAAYuX,KAAhB,EAAF;AAA0B,WAAnD,MAAuD;AAAC,kBAAK,mCAAL;AAAyC;AAAC;AAAC,SAAEkD,kBAAF,CAAqBpvB,CAArB,EAAwB,OAAOjB,CAAP;AAAS,KAArlI,EAAslIqzB,yBAAwB,iCAASjyB,CAAT,EAAW;AAAC,UAAIgC,IAAE2e,OAAN,CAAc,IAAI/gB,IAAEoC,EAAEmf,WAAR,CAAoB,IAAIrhB,IAAEkC,EAAEgf,IAAR,CAAa,IAAIpiB,IAAE,EAAN,CAAS,IAAGoB,EAAEY,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,cAAK,6BAAL;AAAmC,WAAIf,IAAED,EAAEI,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGH,EAAEzB,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,6BAAL;AAAmC,WAAG4B,EAAEY,MAAF,CAASf,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,6BAAL;AAAmC,SAAElB,CAAF,GAAImB,EAAEE,CAAF,EAAIH,EAAE,CAAF,CAAJ,CAAJ,CAAc,IAAGG,EAAEY,MAAF,CAASf,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,6BAAL;AAAmC,SAAE9B,CAAF,GAAI+B,EAAEE,CAAF,EAAIH,EAAE,CAAF,CAAJ,CAAJ,CAAc,OAAOjB,CAAP;AAAS,KAA98I,EAA+8IszB,qBAAoB,6BAAStyB,CAAT,EAAW;AAAC,UAAImC,IAAE4e,OAAN,CAAc,IAAI3e,IAAED,EAAEof,WAAR,CAAoB,IAAIrhB,IAAEiC,EAAEif,IAAR,CAAa,IAAInhB,IAAE,EAAN,CAASA,EAAE+xB,QAAF,GAAW,IAAX,CAAgB,IAAI5xB,IAAEgC,EAAEpC,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGI,EAAE5B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,8CAA4C4B,EAAE5B,MAAnD;AAA0D,WAAIwD,IAAE5B,EAAE,CAAF,CAAN,CAAW,IAAGJ,EAAEgB,MAAF,CAASgB,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,cAAK,sCAAL;AAA4C,WAAIhD,IAAEoD,EAAEpC,CAAF,EAAIgC,CAAJ,CAAN,CAAa,IAAGhD,EAAER,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,sCAAL;AAA4C,WAAGwB,EAAEgB,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,sCAAL;AAA4C,SAAEizB,MAAF,GAAS/xB,EAAEF,CAAF,EAAIhB,EAAE,CAAF,CAAJ,CAAT,CAAmB,IAAGgB,EAAEgB,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAACiB,UAAE+xB,QAAF,GAAW9xB,EAAEF,CAAF,EAAIhB,EAAE,CAAF,CAAJ,CAAX;AAAqB,OAAhD,MAAoD;AAAC,YAAGgB,EAAEgB,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAACiB,YAAE+xB,QAAF,GAAW,EAAX,CAAc/xB,EAAE+xB,QAAF,CAAWhzB,CAAX,GAAamD,EAAEwf,UAAF,CAAa3hB,CAAb,EAAehB,EAAE,CAAF,CAAf,EAAoB,CAAC,CAAD,CAApB,EAAwB,IAAxB,CAAb,CAA2CiB,EAAE+xB,QAAF,CAAW/xB,CAAX,GAAakC,EAAEwf,UAAF,CAAa3hB,CAAb,EAAehB,EAAE,CAAF,CAAf,EAAoB,CAAC,CAAD,CAApB,EAAwB,IAAxB,CAAb,CAA2CiB,EAAE+xB,QAAF,CAAWv0B,CAAX,GAAa0E,EAAEwf,UAAF,CAAa3hB,CAAb,EAAehB,EAAE,CAAF,CAAf,EAAoB,CAAC,CAAD,CAApB,EAAwB,IAAxB,CAAb;AAA2C;AAAC,WAAGgB,EAAEgB,MAAF,CAASZ,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,sCAAL;AAA4C,SAAE6vB,GAAF,GAAM/vB,EAAEF,CAAF,EAAII,EAAE,CAAF,CAAJ,EAAUY,MAAV,CAAiB,CAAjB,CAAN,CAA0B,OAAOf,CAAP;AAAS,KAA1sK,EAAN;AAAmtK,CAAt8O,EAAZ,CAAq9OyrB,QAAQC,MAAR,GAAe,UAASltB,CAAT,EAAWC,CAAX,EAAaK,CAAb,EAAe;AAAC,MAAIyF,IAAEuc,OAAN;AAAA,MAAchc,IAAEP,EAAE+c,WAAlB;AAAA,MAA8Bpf,IAAEqC,EAAE4c,IAAlC;AAAA,MAAuCvjB,IAAE2G,EAAEmd,UAA3C;AAAA,MAAsDvjB,IAAEuX,KAAKf,MAA7D;AAAA,MAAoErW,IAAEH,EAAE+tB,KAAxE;AAAA,MAA8EnmB,IAAE5H,EAAEquB,GAAlF;AAAA,MAAsFzqB,IAAEmU,MAAxF;AAAA,MAA+FlR,IAAE2e,QAAjG;AAAA,MAA0Grf,IAAEmnB,OAA5G,CAAoH,IAAG,OAAO1pB,CAAP,IAAU,WAAV,IAAuBvD,aAAauD,CAAvC,EAAyC;AAAC,WAAOvD,CAAP;AAAS,OAAG,OAAOF,CAAP,IAAU,WAAV,IAAuBE,aAAaF,CAAvC,EAAyC;AAAC,WAAOE,CAAP;AAAS,OAAG,OAAOuH,CAAP,IAAU,WAAV,IAAuBvH,aAAauH,CAAvC,EAAyC;AAAC,WAAOvH,CAAP;AAAS,OAAGA,EAAEoZ,KAAF,KAAUva,SAAV,IAAqBmB,EAAE8zB,EAAF,KAAOj1B,SAA5B,IAAuCmB,EAAEZ,CAAF,KAAMP,SAAhD,EAA0D;AAAC,WAAO,IAAIiB,CAAJ,CAAM,EAACixB,KAAI/wB,EAAE8zB,EAAP,EAAU1a,OAAMpZ,EAAEoZ,KAAlB,EAAN,CAAP;AAAuC,OAAGpZ,EAAEoZ,KAAF,KAAUva,SAAV,IAAqBmB,EAAEZ,CAAF,KAAMP,SAA9B,EAAwC;AAAC,WAAO,IAAIiB,CAAJ,CAAM,EAACgxB,KAAI9wB,EAAEZ,CAAP,EAASga,OAAMpZ,EAAEoZ,KAAjB,EAAN,CAAP;AAAsC,OAAGpZ,EAAE+zB,GAAF,KAAQl1B,SAAR,IAAmBmB,EAAEM,CAAF,KAAMzB,SAAzB,IAAoCmB,EAAEN,CAAF,KAAMb,SAA1C,IAAqDmB,EAAEZ,CAAF,KAAMP,SAA9D,EAAwE;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEuR,SAAF,CAAYrY,EAAEM,CAAd,EAAgBN,EAAEN,CAAlB,EAAqB,OAAOoH,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQl1B,SAAR,IAAmBmB,EAAEM,CAAF,KAAMzB,SAAzB,IAAoCmB,EAAEN,CAAF,KAAMb,SAA1C,IAAqDmB,EAAEZ,CAAF,KAAMP,SAA3D,IAAsEmB,EAAEO,CAAF,KAAM1B,SAA5E,IAAuFmB,EAAEwB,CAAF,KAAM3C,SAA7F,IAAwGmB,EAAEg0B,EAAF,KAAOn1B,SAA/G,IAA0HmB,EAAEi0B,EAAF,KAAOp1B,SAAjI,IAA4ImB,EAAEk0B,EAAF,KAAOr1B,SAAnJ,IAA8JmB,EAAEm0B,EAAF,KAAOt1B,SAAxK,EAAkL;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEstB,YAAF,CAAep0B,EAAEM,CAAjB,EAAmBN,EAAEN,CAArB,EAAuBM,EAAEZ,CAAzB,EAA2BY,EAAEO,CAA7B,EAA+BP,EAAEwB,CAAjC,EAAmCxB,EAAEg0B,EAArC,EAAwCh0B,EAAEi0B,EAA1C,EAA6Cj0B,EAAEk0B,EAA/C,EAAmD,OAAOptB,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQl1B,SAAR,IAAmBmB,EAAEM,CAAF,KAAMzB,SAAzB,IAAoCmB,EAAEN,CAAF,KAAMb,SAA1C,IAAqDmB,EAAEZ,CAAF,KAAMP,SAA3D,IAAsEmB,EAAEO,CAAF,KAAM1B,SAA/E,EAAyF;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEutB,UAAF,CAAar0B,EAAEM,CAAf,EAAiBN,EAAEN,CAAnB,EAAqBM,EAAEZ,CAAvB,EAA0B,OAAO0H,CAAP;AAAS,OAAG9G,EAAEO,CAAF,KAAM1B,SAAN,IAAiBmB,EAAEwB,CAAF,KAAM3C,SAAvB,IAAkCmB,EAAEhB,CAAF,KAAMH,SAAxC,IAAmDmB,EAAEmH,CAAF,KAAMtI,SAAzD,IAAoEmB,EAAEwD,CAAF,KAAM3E,SAA7E,EAAuF;AAAC,QAAIiI,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEuR,SAAF,CAAYrY,EAAEO,CAAd,EAAgBP,EAAEwB,CAAlB,EAAoBxB,EAAEhB,CAAtB,EAAwBgB,EAAEmH,CAA1B,EAA6B,OAAOL,CAAP;AAAS,OAAG9G,EAAEO,CAAF,KAAM1B,SAAN,IAAiBmB,EAAEwB,CAAF,KAAM3C,SAAvB,IAAkCmB,EAAEhB,CAAF,KAAMH,SAAxC,IAAmDmB,EAAEmH,CAAF,KAAMtI,SAAzD,IAAoEmB,EAAEwD,CAAF,KAAM3E,SAA7E,EAAuF;AAAC,QAAIiI,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEutB,UAAF,CAAar0B,EAAEO,CAAf,EAAiBP,EAAEwB,CAAnB,EAAqBxB,EAAEhB,CAAvB,EAAyBgB,EAAEmH,CAA3B,EAA6BnH,EAAEwD,CAA/B,EAAkC,OAAOsD,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,KAAR,IAAe/zB,EAAEM,CAAF,KAAMzB,SAArB,IAAgCmB,EAAEN,CAAF,KAAMb,SAAtC,IAAiDmB,EAAEZ,CAAF,KAAMP,SAA1D,EAAoE;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEuR,SAAF,CAAYkM,UAAUvkB,EAAEM,CAAZ,CAAZ,EAA2BikB,UAAUvkB,EAAEN,CAAZ,CAA3B,EAA2C,OAAOoH,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,KAAR,IAAe/zB,EAAEM,CAAF,KAAMzB,SAArB,IAAgCmB,EAAEN,CAAF,KAAMb,SAAtC,IAAiDmB,EAAEZ,CAAF,KAAMP,SAAvD,IAAkEmB,EAAEO,CAAF,KAAM1B,SAAxE,IAAmFmB,EAAEwB,CAAF,KAAM3C,SAAzF,IAAoGmB,EAAEg0B,EAAF,KAAOn1B,SAA3G,IAAsHmB,EAAEi0B,EAAF,KAAOp1B,SAA7H,IAAwImB,EAAEm0B,EAAF,KAAOt1B,SAAlJ,EAA4J;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEstB,YAAF,CAAe7P,UAAUvkB,EAAEM,CAAZ,CAAf,EAA8BikB,UAAUvkB,EAAEN,CAAZ,CAA9B,EAA6C6kB,UAAUvkB,EAAEZ,CAAZ,CAA7C,EAA4DmlB,UAAUvkB,EAAEO,CAAZ,CAA5D,EAA2EgkB,UAAUvkB,EAAEwB,CAAZ,CAA3E,EAA0F+iB,UAAUvkB,EAAEg0B,EAAZ,CAA1F,EAA0GzP,UAAUvkB,EAAEi0B,EAAZ,CAA1G,EAA0H1P,UAAUvkB,EAAEm0B,EAAZ,CAA1H,EAA2I,OAAOrtB,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,KAAR,IAAe/zB,EAAEM,CAAF,KAAMzB,SAArB,IAAgCmB,EAAEN,CAAF,KAAMb,SAAtC,IAAiDmB,EAAEZ,CAAF,KAAMP,SAA1D,EAAoE;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEutB,UAAF,CAAa9P,UAAUvkB,EAAEM,CAAZ,CAAb,EAA4BikB,UAAUvkB,EAAEN,CAAZ,CAA5B,EAA2C6kB,UAAUvkB,EAAEZ,CAAZ,CAA3C,EAA2D,OAAO0H,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,IAAR,IAAc/zB,EAAEs0B,GAAF,KAAQz1B,SAAtB,IAAiCmB,EAAEwD,CAAF,KAAM3E,SAAvC,IAAkDmB,EAAEmH,CAAF,KAAMtI,SAAxD,IAAmEmB,EAAEZ,CAAF,KAAMP,SAA5E,EAAsF;AAAC,QAAIgB,IAAE,IAAIC,CAAJ,CAAM,EAACsZ,OAAMpZ,EAAEs0B,GAAT,EAAN,CAAN,CAA2B,IAAI/yB,IAAE1B,EAAEsvB,QAAF,CAAWS,MAAX,GAAkB,CAAxB,CAA0B,IAAIvoB,IAAE,CAAC,eAAakd,UAAUvkB,EAAEwD,CAAZ,CAAd,EAA8B1B,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAI0F,IAAE,CAAC,eAAasd,UAAUvkB,EAAEmH,CAAZ,CAAd,EAA8BrF,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAIoC,IAAE,OAAK0D,CAAL,GAAOJ,CAAb,CAAepH,EAAE6vB,eAAF,CAAkB/rB,CAAlB,EAAqB,OAAO9D,CAAP;AAAS,OAAGG,EAAE+zB,GAAF,KAAQ,IAAR,IAAc/zB,EAAEs0B,GAAF,KAAQz1B,SAAtB,IAAiCmB,EAAEwD,CAAF,KAAM3E,SAAvC,IAAkDmB,EAAEmH,CAAF,KAAMtI,SAAxD,IAAmEmB,EAAEZ,CAAF,KAAMP,SAA5E,EAAsF;AAAC,QAAIgB,IAAE,IAAIC,CAAJ,CAAM,EAACsZ,OAAMpZ,EAAEs0B,GAAT,EAAN,CAAN,CAA2B,IAAI/yB,IAAE1B,EAAEsvB,QAAF,CAAWS,MAAX,GAAkB,CAAxB,CAA0B,IAAIvoB,IAAE,CAAC,eAAakd,UAAUvkB,EAAEwD,CAAZ,CAAd,EAA8B1B,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAI0F,IAAE,CAAC,eAAasd,UAAUvkB,EAAEmH,CAAZ,CAAd,EAA8BrF,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAIoC,IAAE,OAAK0D,CAAL,GAAOJ,CAAb,CAAe,IAAIxH,IAAE,CAAC,eAAa8kB,UAAUvkB,EAAEZ,CAAZ,CAAd,EAA8B0C,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C1B,EAAE6vB,eAAF,CAAkB/rB,CAAlB,EAAqB9D,EAAE4vB,gBAAF,CAAmBhwB,CAAnB,EAAsB,OAAOI,CAAP;AAAS,OAAGS,MAAI,UAAP,EAAkB;AAAC,QAAI4F,IAAElG,CAAN;AAAA,QAAQ+F,IAAEuc,OAAV;AAAA,QAAkB5b,CAAlB;AAAA,QAAoBI,CAApB,CAAsBJ,IAAEJ,EAAEJ,CAAF,EAAI,CAAJ,CAAF,CAAS,IAAGQ,EAAE3G,MAAF,KAAW,CAAd,EAAgB;AAAC+G,UAAE,IAAIvD,CAAJ,EAAF,CAAUuD,EAAE2pB,kBAAF,CAAqBvqB,CAArB;AAAwB,KAAnD,MAAuD;AAAC,UAAGQ,EAAE3G,MAAF,KAAW,CAAd,EAAgB;AAAC+G,YAAE,IAAIS,CAAJ,EAAF,CAAUT,EAAE2pB,kBAAF,CAAqBvqB,CAArB;AAAwB,OAAnD,MAAuD;AAAC,YAAGQ,EAAE3G,MAAF,GAAS,CAAT,IAAYmG,EAAE3D,MAAF,CAASmE,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAAlC,EAAuC;AAACI,cAAE,IAAIhH,CAAJ,EAAF,CAAUgH,EAAE2pB,kBAAF,CAAqBvqB,CAArB;AAAwB,SAA1E,MAA8E;AAAC,gBAAK,sCAAL;AAA4C;AAAC;AAAC,YAAOY,CAAP;AAAS,OAAGxG,MAAI,UAAP,EAAkB;AAAC,QAAIwG,IAAEhB,EAAEutB,8BAAF,CAAiCrzB,CAAjC,CAAN,CAA0C,OAAO8G,CAAP;AAAS,OAAGxG,MAAI,UAAP,EAAkB;AAAC,WAAOwF,EAAE6tB,yBAAF,CAA4B3zB,CAA5B,CAAP;AAAsC,OAAGM,MAAI,SAAP,EAAiB;AAAC,WAAOi0B,KAAKC,uBAAL,CAA6Bx0B,CAA7B,CAAP;AAAuC,OAAGA,EAAEoF,OAAF,CAAU,mBAAV,EAA8B,CAA9B,KAAkC,CAAC,CAAnC,IAAsCpF,EAAEoF,OAAF,CAAU,wBAAV,EAAmC,CAAnC,KAAuC,CAAC,CAA9E,IAAiFpF,EAAEoF,OAAF,CAAU,2BAAV,EAAsC,CAAtC,KAA0C,CAAC,CAA/H,EAAiI;AAAC,WAAOmvB,KAAKE,uBAAL,CAA6Bz0B,CAA7B,CAAP;AAAuC,OAAGA,EAAEoF,OAAF,CAAU,kBAAV,KAA+B,CAAC,CAAnC,EAAqC;AAAC,QAAIwB,IAAEue,SAASnlB,CAAT,EAAW,YAAX,CAAN,CAA+B,OAAO8F,EAAE6tB,yBAAF,CAA4B/sB,CAA5B,CAAP;AAAsC,OAAG5G,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAInD,IAAEuE,EAAExG,CAAF,EAAI,iBAAJ,CAAN,CAA6B,OAAO8F,EAAEonB,MAAF,CAASjrB,CAAT,EAAW,IAAX,EAAgB,UAAhB,CAAP;AAAmC,OAAGjC,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAIa,IAAEO,EAAExG,CAAF,EAAI,iBAAJ,CAAN,CAA6B,IAAI2H,IAAEvI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIwB,IAAErI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIG,IAAEhH,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAItE,IAAEvC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIxE,IAAErC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIa,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEutB,UAAF,CAAa,IAAIxrB,UAAJ,CAAelB,CAAf,EAAiB,EAAjB,CAAb,EAAkC,IAAIkB,UAAJ,CAAepB,CAAf,EAAiB,EAAjB,CAAlC,EAAuD,IAAIoB,UAAJ,CAAezC,CAAf,EAAiB,EAAjB,CAAvD,EAA4E,IAAIyC,UAAJ,CAAelH,CAAf,EAAiB,EAAjB,CAA5E,EAAiG,IAAIkH,UAAJ,CAAepH,CAAf,EAAiB,EAAjB,CAAjG,EAAuH,OAAOqF,CAAP;AAAS,OAAG9G,EAAEoF,OAAF,CAAU,mBAAV,KAAgC,CAAC,CAApC,EAAsC;AAAC,WAAOU,EAAE4tB,8BAAF,CAAiC1zB,CAAjC,CAAP;AAA2C,OAAGA,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAI5E,IAAEsF,EAAEysB,kBAAF,CAAqBvyB,CAArB,EAAuBC,CAAvB,CAAN,CAAgC,IAAI+F,IAAE,IAAI0R,MAAJ,EAAN,CAAmB1R,EAAEyqB,kBAAF,CAAqBjwB,CAArB,EAAwB,OAAOwF,CAAP;AAAS,OAAGhG,EAAEoF,OAAF,CAAU,sBAAV,KAAmC,CAAC,CAApC,IAAuCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAArE,EAAuE;AAAC,QAAIa,IAAEH,EAAEysB,kBAAF,CAAqBvyB,CAArB,EAAuBC,CAAvB,CAAN,CAAgC,IAAI6G,IAAE1H,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAI/G,IAAEE,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAN,CAAwB,IAAIiB,IAAE9H,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,EAAkB1D,MAAlB,CAAyB,CAAzB,CAAN,CAAkC,IAAI7C,IAAE,EAAN,CAAS,IAAGwX,KAAKf,MAAL,CAAYsL,GAAZ,CAAgBuN,WAAhB,CAA4B9vB,CAA5B,MAAiCL,SAApC,EAA8C;AAACa,UAAEwX,KAAKf,MAAL,CAAYsL,GAAZ,CAAgBuN,WAAhB,CAA4B9vB,CAA5B,CAAF;AAAiC,KAAhF,MAAoF;AAAC,YAAK,4CAA0CA,CAA/C;AAAiD,SAAIW,IAAE,IAAIC,CAAJ,CAAM,EAACsZ,OAAM1Z,CAAP,EAAN,CAAN,CAAuBG,EAAE6vB,eAAF,CAAkBxoB,CAAlB,EAAqBrH,EAAE4vB,gBAAF,CAAmB3oB,CAAnB,EAAsBjH,EAAEkY,QAAF,GAAW,KAAX,CAAiB,OAAOlY,CAAP;AAAS,OAAGG,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAIa,IAAEH,EAAEysB,kBAAF,CAAqBvyB,CAArB,EAAuBC,CAAvB,CAAN,CAAgC,IAAI0H,IAAEvI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIwB,IAAErI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIG,IAAEhH,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAItE,IAAEvC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIxE,IAAErC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIa,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEutB,UAAF,CAAa,IAAIxrB,UAAJ,CAAelB,CAAf,EAAiB,EAAjB,CAAb,EAAkC,IAAIkB,UAAJ,CAAepB,CAAf,EAAiB,EAAjB,CAAlC,EAAuD,IAAIoB,UAAJ,CAAezC,CAAf,EAAiB,EAAjB,CAAvD,EAA4E,IAAIyC,UAAJ,CAAelH,CAAf,EAAiB,EAAjB,CAA5E,EAAiG,IAAIkH,UAAJ,CAAepH,CAAf,EAAiB,EAAjB,CAAjG,EAAuH,OAAOqF,CAAP;AAAS,OAAG9G,EAAEoF,OAAF,CAAU,6BAAV,KAA0C,CAAC,CAA9C,EAAgD;AAAC,WAAOU,EAAEstB,2BAAF,CAA8BpzB,CAA9B,EAAgCC,CAAhC,CAAP;AAA0C,SAAK,wBAAL;AAA8B,CAAjxJ,CAAkxJgtB,QAAQyH,eAAR,GAAwB,UAASx0B,CAAT,EAAWP,CAAX,EAAa;AAAC,MAAGO,KAAG,KAAN,EAAY;AAAC,QAAIT,IAAEE,CAAN,CAAQ,IAAIV,IAAE,IAAIyY,MAAJ,EAAN,CAAmBzY,EAAE01B,QAAF,CAAWl1B,CAAX,EAAa,OAAb,EAAsBR,EAAE+Y,SAAF,GAAY,IAAZ,CAAiB/Y,EAAE8Y,QAAF,GAAW,IAAX,CAAgB,IAAI7Y,IAAE,IAAIwY,MAAJ,EAAN,CAAmB,IAAIhY,IAAET,EAAEqB,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAN,CAAuB,IAAIlB,IAAEb,EAAES,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAN,CAAuB9B,EAAEmZ,SAAF,CAAY3Y,CAAZ,EAAcI,CAAd,EAAiBZ,EAAE8Y,SAAF,GAAY,KAAZ,CAAkB9Y,EAAE6Y,QAAF,GAAW,IAAX,CAAgB,IAAI9X,IAAE,EAAN,CAASA,EAAE20B,SAAF,GAAY31B,CAAZ,CAAcgB,EAAE40B,SAAF,GAAY31B,CAAZ,CAAc,OAAOe,CAAP;AAAS,GAAjQ,MAAqQ;AAAC,QAAGC,KAAG,IAAN,EAAW;AAAC,UAAId,IAAEO,CAAN,CAAQ,IAAIX,IAAE,IAAIkY,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAMha,CAAP,EAAtB,CAAN,CAAuC,IAAIS,IAAEb,EAAE8wB,kBAAF,EAAN,CAA6B,IAAI7wB,IAAE,IAAIiY,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAMha,CAAP,EAAtB,CAAN,CAAuCH,EAAEywB,eAAF,CAAkB7vB,EAAEsuB,QAApB,EAA8BlvB,EAAEwwB,gBAAF,CAAmB5vB,EAAE2tB,QAArB,EAA+BvuB,EAAE+Y,SAAF,GAAY,IAAZ,CAAiB/Y,EAAE8Y,QAAF,GAAW,KAAX,CAAiB,IAAI7Y,IAAE,IAAIgY,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAMha,CAAP,EAAtB,CAAN,CAAuCF,EAAEwwB,eAAF,CAAkB7vB,EAAEsuB,QAApB,EAA8BjvB,EAAE8Y,SAAF,GAAY,KAAZ,CAAkB9Y,EAAE6Y,QAAF,GAAW,IAAX,CAAgB,IAAI9X,IAAE,EAAN,CAASA,EAAE20B,SAAF,GAAY31B,CAAZ,CAAcgB,EAAE40B,SAAF,GAAY31B,CAAZ,CAAc,OAAOe,CAAP;AAAS,KAAnX,MAAuX;AAAC,YAAK,wBAAsBC,CAA3B;AAA6B;AAAC;AAAC,CAAnsB,CAAosB+sB,QAAQ6H,MAAR,GAAe,UAASr1B,CAAT,EAAWgI,CAAX,EAAaN,CAAb,EAAelF,CAAf,EAAiBT,CAAjB,EAAmB3B,CAAnB,EAAqB;AAAC,MAAIiG,IAAEoR,IAAN;AAAA,MAAWjX,IAAE6F,EAAEsW,IAAf;AAAA,MAAoBnV,IAAEhH,EAAE+c,mBAAxB;AAAA,MAA4C9d,IAAEe,EAAE2c,UAAhD;AAAA,MAA2D5c,IAAEC,EAAEoc,QAAF,CAAWK,SAAxE;AAAA,MAAkFxc,IAAED,EAAEuhB,IAAtF;AAAA,MAA2Fja,IAAErH,EAAE60B,oBAA/F;AAAA,MAAoHr1B,IAAEoG,EAAEqQ,MAAxH;AAAA,MAA+HxS,IAAEjE,EAAEsuB,GAAnI;AAAA,MAAuIrsB,IAAEjC,EAAEguB,KAA3I;AAAA,MAAiJptB,IAAEoX,MAAnJ,CAA0J,SAASxQ,CAAT,CAAWzF,CAAX,EAAa;AAAC,QAAIsE,IAAE/F,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAAC,OAAM,EAACjU,QAAOtf,EAAEnB,CAAV,EAAP,EAAX,EAAgC,EAAC,OAAMmB,EAAE/B,CAAT,EAAhC,EAA4C,EAAC,OAAM,EAACqhB,QAAOtf,EAAErC,CAAV,EAAP,EAA5C,EAAiE,EAAC,OAAM,EAAC2hB,QAAOtf,EAAElB,CAAV,EAAP,EAAjE,EAAsF,EAAC,OAAM,EAACwgB,QAAOtf,EAAED,CAAV,EAAP,EAAtF,EAA2G,EAAC,OAAM,EAACuf,QAAOtf,EAAEkW,IAAV,EAAP,EAA3G,EAAmI,EAAC,OAAM,EAACoJ,QAAOtf,EAAEmW,IAAV,EAAP,EAAnI,EAA2J,EAAC,OAAM,EAACmJ,QAAOtf,EAAEoW,KAAV,EAAP,EAA3J,CAAL,EAAF,CAAN,CAAoM,OAAO9R,CAAP;AAAS,YAASsB,CAAT,CAAWtB,CAAX,EAAa;AAAC,QAAItE,IAAEzB,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACC,QAAO,EAAC3V,KAAIvZ,EAAEupB,SAAP,EAAR,EAAX,EAAsC,EAACxR,KAAI,CAAC,IAAD,EAAM,IAAN,EAAW,EAAC6D,KAAI,EAACC,MAAK7b,EAAEypB,SAAR,EAAL,EAAX,CAAL,EAAtC,EAAiF,EAAC1R,KAAI,CAAC,IAAD,EAAM,IAAN,EAAW,EAACoX,QAAO,EAAC5V,KAAI,OAAKvZ,EAAEwpB,SAAZ,EAAR,EAAX,CAAL,EAAjF,CAAL,EAAF,CAAN,CAAmJ,OAAO9tB,CAAP;AAAS,YAAS+B,CAAT,CAAW/B,CAAX,EAAa;AAAC,QAAIsE,IAAE/F,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAAC,OAAM,EAACjU,QAAOtf,EAAElB,CAAV,EAAP,EAAX,EAAgC,EAAC,OAAM,EAACwgB,QAAOtf,EAAED,CAAV,EAAP,EAAhC,EAAqD,EAAC,OAAM,EAACuf,QAAOtf,EAAEzC,CAAV,EAAP,EAArD,EAA0E,EAAC,OAAM,EAAC+hB,QAAOtf,EAAE0F,CAAV,EAAP,EAA1E,EAA+F,EAAC,OAAM,EAAC4Z,QAAOtf,EAAE+B,CAAV,EAAP,EAA/F,CAAL,EAAF,CAAN,CAAoI,OAAOuC,CAAP;AAAS,OAAG,CAAEzF,MAAIzB,SAAJ,IAAeY,aAAaa,CAA7B,IAAkCqD,MAAI9E,SAAJ,IAAeY,aAAakE,CAA9D,IAAmEhC,MAAI9C,SAAJ,IAAeY,aAAakC,CAAhG,KAAqGlC,EAAEsY,QAAF,IAAY,IAAjH,KAAwHtQ,MAAI5I,SAAJ,IAAe4I,KAAG,UAA1I,CAAH,EAAyJ;AAAC,QAAIE,IAAE,IAAIJ,CAAJ,CAAM9H,CAAN,CAAN,CAAe,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,OAAOzB,SAASlZ,CAAT,EAAW,YAAX,CAAP;AAAgC,OAAGkE,KAAG,UAAH,IAAenH,MAAIzB,SAAnB,IAA8BY,aAAaa,CAA3C,KAA+C6G,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,KAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAET,EAAEzH,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,OAAOzB,SAASlZ,CAAT,EAAW,iBAAX,CAAP;AAAqC,OAAGkE,KAAG,UAAH,IAAe9F,MAAI9C,SAAnB,IAA8BY,aAAakC,CAA3C,KAA+CwF,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,KAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIlY,IAAE,IAAImH,CAAJ,CAAM,EAAC2a,MAAKniB,EAAE+vB,SAAR,EAAN,CAAN,CAAgC,IAAI9rB,IAAE5D,EAAEoe,aAAF,EAAN,CAAwB,IAAIjf,IAAEoI,EAAE5H,CAAF,CAAN,CAAW,IAAI8B,IAAEtC,EAAEif,aAAF,EAAN,CAAwB,IAAI3d,IAAE,EAAN,CAASA,KAAGkc,SAAS/Y,CAAT,EAAW,eAAX,CAAH,CAA+BnD,KAAGkc,SAASlb,CAAT,EAAW,gBAAX,CAAH,CAAgC,OAAOhB,CAAP;AAAS,OAAGkH,KAAG,UAAH,IAAe9D,MAAI9E,SAAnB,IAA8BY,aAAakE,CAA3C,KAA+CwD,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,KAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAEnE,EAAE/D,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,OAAOzB,SAASlZ,CAAT,EAAW,iBAAX,CAAP;AAAqC,OAAGkE,KAAG,UAAH,IAAenH,MAAIzB,SAAnB,IAA8BY,aAAaa,CAA3C,IAA+C6G,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,IAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAET,EAAEzH,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAGjc,MAAIpD,SAAP,EAAiB;AAACoD,UAAE,cAAF;AAAiB,YAAO,KAAKuwB,iCAAL,CAAuC,KAAvC,EAA6CjvB,CAA7C,EAA+C4D,CAA/C,EAAiDlF,CAAjD,EAAmDpC,CAAnD,CAAP;AAA6D,OAAG4H,KAAG,UAAH,IAAe9F,MAAI9C,SAAnB,IAA8BY,aAAakC,CAA3C,IAA+CwF,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,IAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAEN,EAAE5H,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAGjc,MAAIpD,SAAP,EAAiB;AAACoD,UAAE,cAAF;AAAiB,YAAO,KAAKuwB,iCAAL,CAAuC,IAAvC,EAA4CjvB,CAA5C,EAA8C4D,CAA9C,EAAgDlF,CAAhD,EAAkDpC,CAAlD,CAAP;AAA4D,OAAG4H,KAAG,UAAH,IAAe9D,MAAI9E,SAAnB,IAA8BY,aAAakE,CAA3C,IAA+CwD,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,IAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAEnE,EAAE/D,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAGjc,MAAIpD,SAAP,EAAiB;AAACoD,UAAE,cAAF;AAAiB,YAAO,KAAKuwB,iCAAL,CAAuC,KAAvC,EAA6CjvB,CAA7C,EAA+C4D,CAA/C,EAAiDlF,CAAjD,EAAmDpC,CAAnD,CAAP;AAA6D,OAAIW,IAAE,SAAFA,CAAE,CAASuF,CAAT,EAAWtE,CAAX,EAAa;AAAC,QAAIwE,IAAEtG,EAAEoG,CAAF,EAAItE,CAAJ,CAAN,CAAa,IAAIuE,IAAE,IAAIhG,CAAJ,CAAM,EAACg1B,KAAI,CAAC,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,YAAN,EAAL,EAAD,EAA2B,EAACoT,KAAI,CAAC,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,aAAN,EAAL,EAAD,EAA4B,EAACoT,KAAI,CAAC,EAACC,QAAO,EAAC3V,KAAIrZ,EAAE4sB,UAAP,EAAR,EAAD,EAA6B,EAAC,OAAM5sB,EAAE6sB,UAAT,EAA7B,CAAL,EAA5B,CAAL,EAAD,EAA6F,EAACkC,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,cAAN,EAAL,EAAD,EAA6B,EAACqT,QAAO,EAAC3V,KAAIrZ,EAAE2sB,kBAAP,EAAR,EAA7B,CAAL,EAA7F,CAAL,EAA3B,CAAL,EAAD,EAA+M,EAACqC,QAAO,EAAC3V,KAAIrZ,EAAEyrB,UAAP,EAAR,EAA/M,CAAL,EAAN,CAAN,CAA+P,OAAO1rB,EAAEkY,aAAF,EAAP;AAAyB,GAAzT,CAA0T,IAAIve,IAAE,SAAFA,CAAE,CAAS+G,CAAT,EAAWE,CAAX,EAAa;AAAC,QAAIZ,IAAE,GAAN,CAAU,IAAIQ,IAAErG,SAASC,GAAT,CAAac,SAAb,CAAuBa,MAAvB,CAA8B,CAA9B,CAAN,CAAuC,IAAIuE,IAAE,cAAN,CAAqB,IAAI7E,IAAEtB,SAASC,GAAT,CAAac,SAAb,CAAuBa,MAAvB,CAA8B,CAA9B,CAAN,CAAuC,IAAIkE,IAAE9F,SAAS6yB,MAAT,CAAgBpsB,CAAhB,EAAkBJ,CAAlB,EAAoB,EAACysB,SAAQ,MAAI,EAAb,EAAgBC,YAAWltB,CAA3B,EAApB,CAAN,CAAyD,IAAIE,IAAE/F,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBqE,CAAvB,CAAN,CAAgC,IAAIN,IAAEjG,SAASmxB,SAAT,CAAmBhZ,OAAnB,CAA2BpS,CAA3B,EAA6BD,CAA7B,EAA+B,EAACwrB,IAAGhwB,CAAJ,EAA/B,IAAuC,EAA7C,CAAgD,IAAIsE,IAAE,EAAN,CAASA,EAAE2rB,UAAF,GAAatrB,CAAb,CAAeL,EAAE8sB,UAAF,GAAa1yB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BmF,CAA3B,CAAb,CAA2CT,EAAE+sB,UAAF,GAAa9sB,CAAb,CAAeD,EAAE4sB,mBAAF,GAAsBrsB,CAAtB,CAAwBP,EAAE6sB,kBAAF,GAAqBzyB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BI,CAA3B,CAArB,CAAmD,OAAOsE,CAAP;AAAS,GAAhb,CAAib,IAAG0B,KAAG,UAAH,IAAenH,KAAGzB,SAAlB,IAA6BY,aAAaa,CAA1C,IAA6Cb,EAAEuY,SAAF,IAAa,IAA7D,EAAkE;AAAC,QAAIhZ,IAAEkI,EAAEzH,CAAF,CAAN,CAAW,IAAIL,IAAEJ,EAAEkf,aAAF,EAAN,CAAwB,IAAIvW,IAAE3H,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,eAAN,EAAL,EAAD,EAA8B,EAAC,QAAO,IAAR,EAA9B,CAAL,EAAX,EAA8D,EAACqT,QAAO,EAAC3V,KAAIlgB,CAAL,EAAR,EAA9D,CAAL,EAAF,CAAN,CAA+F,IAAImE,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAG/W,MAAItI,SAAJ,IAAesI,KAAG,IAArB,EAA0B;AAAC,aAAOsV,SAASlZ,CAAT,EAAW,aAAX,CAAP;AAAiC,KAA5D,MAAgE;AAAC,UAAIhC,IAAEf,EAAE+C,CAAF,EAAI4D,CAAJ,CAAN,CAAa,OAAOsV,SAASlb,CAAT,EAAW,uBAAX,CAAP;AAA2C;AAAC,OAAGkG,KAAG,UAAH,IAAe9F,MAAI9C,SAAnB,IAA8BY,aAAakC,CAA3C,IAA8ClC,EAAEuY,SAAF,IAAa,IAA9D,EAAmE;AAAC,QAAIhZ,IAAE,IAAIgB,CAAJ,CAAM,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACC,QAAO,EAAC3V,KAAI7f,EAAE6vB,SAAP,EAAR,EAAX,EAAsC,EAACxR,KAAI,CAAC,IAAD,EAAM,IAAN,EAAW,EAACoX,QAAO,EAAC5V,KAAI,OAAK7f,EAAE8vB,SAAZ,EAAR,EAAX,CAAL,EAAtC,CAAL,EAAN,CAAN,CAA4G,IAAInwB,IAAEJ,EAAEkf,aAAF,EAAN,CAAwB,IAAIvW,IAAE3H,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,aAAN,EAAL,EAAD,EAA4B,EAACD,KAAI,EAACC,MAAKniB,EAAE+vB,SAAR,EAAL,EAA5B,CAAL,EAAX,EAAuE,EAACyF,QAAO,EAAC3V,KAAIlgB,CAAL,EAAR,EAAvE,CAAL,EAAF,CAAN,CAAwG,IAAImE,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAG/W,MAAItI,SAAJ,IAAesI,KAAG,IAArB,EAA0B;AAAC,aAAOsV,SAASlZ,CAAT,EAAW,aAAX,CAAP;AAAiC,KAA5D,MAAgE;AAAC,UAAIhC,IAAEf,EAAE+C,CAAF,EAAI4D,CAAJ,CAAN,CAAa,OAAOsV,SAASlb,CAAT,EAAW,uBAAX,CAAP;AAA2C;AAAC,OAAGkG,KAAG,UAAH,IAAe9D,MAAI9E,SAAnB,IAA8BY,aAAakE,CAA3C,IAA8ClE,EAAEuY,SAAF,IAAa,IAA9D,EAAmE;AAAC,QAAIhZ,IAAE,IAAIE,CAAJ,CAAM,EAAC6hB,QAAOthB,EAAE+D,CAAV,EAAN,CAAN,CAA0B,IAAIpE,IAAEJ,EAAEkf,aAAF,EAAN,CAAwB,IAAIvW,IAAE3H,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,KAAN,EAAL,EAAD,EAAoB,EAACoT,KAAI,CAAC,EAAC,OAAM,EAACjU,QAAOthB,EAAEc,CAAV,EAAP,EAAD,EAAsB,EAAC,OAAM,EAACwgB,QAAOthB,EAAE+B,CAAV,EAAP,EAAtB,EAA2C,EAAC,OAAM,EAACuf,QAAOthB,EAAET,CAAV,EAAP,EAA3C,CAAL,EAApB,CAAL,EAAX,EAA6G,EAACi2B,QAAO,EAAC3V,KAAIlgB,CAAL,EAAR,EAA7G,CAAL,EAAF,CAAN,CAA8I,IAAImE,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAG/W,MAAItI,SAAJ,IAAesI,KAAG,IAArB,EAA0B;AAAC,aAAOsV,SAASlZ,CAAT,EAAW,aAAX,CAAP;AAAiC,KAA5D,MAAgE;AAAC,UAAIhC,IAAEf,EAAE+C,CAAF,EAAI4D,CAAJ,CAAN,CAAa,OAAOsV,SAASlb,CAAT,EAAW,uBAAX,CAAP;AAA2C;AAAC,SAAK,+BAAL;AAAqC,CAAvnI,CAAwnI0rB,QAAQkI,gBAAR,GAAyB,UAAS11B,CAAT,EAAW;AAAC,MAAIS,IAAEilB,SAAS1lB,CAAT,EAAW,qBAAX,CAAN,CAAwC,IAAIE,IAAEstB,QAAQmI,gBAAR,CAAyBl1B,CAAzB,CAAN,CAAkC,OAAOP,CAAP;AAAS,CAAxH,CAAyHstB,QAAQmI,gBAAR,GAAyB,UAASl1B,CAAT,EAAW;AAAC,MAAIP,IAAEstB,QAAQoI,WAAR,CAAoBn1B,CAApB,CAAN,CAA6B,IAAIT,IAAEwtB,QAAQC,MAAR,CAAevtB,EAAE21B,WAAjB,EAA6B,IAA7B,EAAkC,UAAlC,CAAN,CAAoD,OAAO71B,CAAP;AAAS,CAA/H,CAAgIwtB,QAAQoI,WAAR,GAAoB,UAASj2B,CAAT,EAAW;AAAC,MAAIU,IAAEwiB,OAAN,CAAc,IAAIpjB,IAAEY,EAAEgjB,WAAR,CAAoB,IAAInjB,IAAEG,EAAE8iB,MAAR,CAAe,IAAInjB,IAAE,EAAN,CAAS,IAAIT,IAAEI,CAAN,CAAQ,IAAGJ,EAAEuD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,yBAAL;AAA+B,OAAI7C,IAAER,EAAEF,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGU,EAAEK,MAAF,GAAS,CAAZ,EAAc;AAAC,UAAK,yBAAL;AAA+B,OAAGf,EAAEuD,MAAF,CAAS7C,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,UAAK,yBAAL;AAA+B,OAAIQ,IAAEhB,EAAEF,CAAF,EAAIU,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGQ,EAAEH,MAAF,GAAS,CAAZ,EAAc;AAAC,UAAK,yBAAL;AAA+B,KAAEu1B,WAAF,GAAc31B,EAAEX,CAAF,EAAIkB,EAAE,CAAF,CAAJ,CAAd,CAAwB,OAAOT,CAAP;AAAS,CAA7W,CAA8WwtB,QAAQsI,aAAR,GAAsB,UAASn2B,CAAT,EAAW;AAAC,MAAIK,IAAE,EAAN,CAAS,IAAGL,aAAasY,MAAb,IAAqBtY,EAAE4Y,SAA1B,EAAoC;AAACvY,MAAEs0B,GAAF,GAAM,KAAN,CAAYt0B,EAAEa,CAAF,GAAIgkB,UAAUllB,EAAEkB,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEC,CAAF,GAAI4kB,UAAUllB,EAAEM,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEL,CAAF,GAAIklB,UAAUllB,EAAEA,CAAF,CAAI4B,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEc,CAAF,GAAI+jB,UAAUllB,EAAEmB,CAAF,CAAIS,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAE+B,CAAF,GAAI8iB,UAAUllB,EAAEoC,CAAF,CAAIR,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEu0B,EAAF,GAAK1P,UAAUllB,EAAEuY,IAAF,CAAO3W,QAAP,CAAgB,EAAhB,CAAV,CAAL,CAAoCvB,EAAEw0B,EAAF,GAAK3P,UAAUllB,EAAEwY,IAAF,CAAO5W,QAAP,CAAgB,EAAhB,CAAV,CAAL,CAAoCvB,EAAE00B,EAAF,GAAK7P,UAAUllB,EAAEyY,KAAF,CAAQ7W,QAAR,CAAiB,EAAjB,CAAV,CAAL,CAAqC,OAAOvB,CAAP;AAAS,GAAvU,MAA2U;AAAC,QAAGL,aAAasY,MAAb,IAAqBtY,EAAE2Y,QAA1B,EAAmC;AAACtY,QAAEs0B,GAAF,GAAM,KAAN,CAAYt0B,EAAEa,CAAF,GAAIgkB,UAAUllB,EAAEkB,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEC,CAAF,GAAI4kB,UAAUllB,EAAEM,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgC,OAAOvB,CAAP;AAAS,KAAzH,MAA6H;AAAC,UAAGL,aAAa8X,KAAKf,MAAL,CAAYuX,KAAzB,IAAgCtuB,EAAE4Y,SAArC,EAA+C;AAAC,YAAI9X,IAAEd,EAAEywB,sBAAF,EAAN,CAAiC,IAAG3vB,MAAI,OAAJ,IAAaA,MAAI,OAApB,EAA4B;AAAC,gBAAK,qCAAmCA,CAAxC;AAA0C,aAAIP,IAAEP,EAAEuwB,iBAAF,EAAN,CAA4BlwB,EAAEs0B,GAAF,GAAM,IAAN,CAAWt0B,EAAE60B,GAAF,GAAMp0B,CAAN,CAAQT,EAAE+D,CAAF,GAAI8gB,UAAU3kB,EAAE6D,CAAZ,CAAJ,CAAmB/D,EAAE0H,CAAF,GAAImd,UAAU3kB,EAAEwH,CAAZ,CAAJ,CAAmB1H,EAAEL,CAAF,GAAIklB,UAAUllB,EAAEkwB,SAAZ,CAAJ,CAA2B,OAAO7vB,CAAP;AAAS,OAAjR,MAAqR;AAAC,YAAGL,aAAa8X,KAAKf,MAAL,CAAYuX,KAAzB,IAAgCtuB,EAAE2Y,QAArC,EAA8C;AAAC,cAAI7X,IAAEd,EAAEywB,sBAAF,EAAN,CAAiC,IAAG3vB,MAAI,OAAJ,IAAaA,MAAI,OAApB,EAA4B;AAAC,kBAAK,qCAAmCA,CAAxC;AAA0C,eAAIP,IAAEP,EAAEuwB,iBAAF,EAAN,CAA4BlwB,EAAEs0B,GAAF,GAAM,IAAN,CAAWt0B,EAAE60B,GAAF,GAAMp0B,CAAN,CAAQT,EAAE+D,CAAF,GAAI8gB,UAAU3kB,EAAE6D,CAAZ,CAAJ,CAAmB/D,EAAE0H,CAAF,GAAImd,UAAU3kB,EAAEwH,CAAZ,CAAJ,CAAmB,OAAO1H,CAAP;AAAS;AAAC;AAAC;AAAC,SAAK,0BAAL;AAAgC,CAAniC;AAC1ojBiY,OAAO8d,4BAAP,GAAoC,UAASt1B,CAAT,EAAW;AAAC,SAAOoiB,QAAQQ,WAAR,CAAoB5iB,CAApB,EAAsB,CAAtB,CAAP;AAAgC,CAAhF,CAAiFwX,OAAO+d,iCAAP,GAAyC,UAASv2B,CAAT,EAAW;AAAC,MAAIoB,IAAEgiB,OAAN,CAAc,IAAIxiB,IAAEQ,EAAEqiB,IAAR,CAAa,IAAI1iB,IAAEyX,OAAO8d,4BAAP,CAAoCt2B,CAApC,CAAN,CAA6C,IAAIQ,IAAEI,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIJ,IAAEC,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIR,IAAEK,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIN,IAAEG,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIhB,IAAEa,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIjB,IAAEc,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIgC,IAAEnC,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAID,IAAEF,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIb,IAAEU,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIA,IAAE,IAAIwI,KAAJ,EAAN,CAAkBxI,EAAE+B,IAAF,CAAOtC,CAAP,EAASG,CAAT,EAAWJ,CAAX,EAAaE,CAAb,EAAeV,CAAf,EAAiBD,CAAjB,EAAmBiD,CAAnB,EAAqBjC,CAArB,EAAuBZ,CAAvB,EAA0B,OAAOa,CAAP;AAAS,CAAlU,CAAmUyX,OAAOrY,SAAP,CAAiBq2B,2BAAjB,GAA6C,UAASt2B,CAAT,EAAW;AAAC,MAAIO,IAAEwlB,SAAS/lB,CAAT,CAAN,CAAkB,IAAIK,IAAEiY,OAAO+d,iCAAP,CAAyC91B,CAAzC,CAAN,CAAkD,KAAKy0B,YAAL,CAAkB30B,EAAE,CAAF,CAAlB,EAAuBA,EAAE,CAAF,CAAvB,EAA4BA,EAAE,CAAF,CAA5B,EAAiCA,EAAE,CAAF,CAAjC,EAAsCA,EAAE,CAAF,CAAtC,EAA2CA,EAAE,CAAF,CAA3C,EAAgDA,EAAE,CAAF,CAAhD,EAAqDA,EAAE,CAAF,CAArD;AAA2D,CAAxL,CAAyLiY,OAAOrY,SAAP,CAAiBoxB,kBAAjB,GAAoC,UAAS9wB,CAAT,EAAW;AAAC,MAAIF,IAAEiY,OAAO+d,iCAAP,CAAyC91B,CAAzC,CAAN,CAAkD,KAAKy0B,YAAL,CAAkB30B,EAAE,CAAF,CAAlB,EAAuBA,EAAE,CAAF,CAAvB,EAA4BA,EAAE,CAAF,CAA5B,EAAiCA,EAAE,CAAF,CAAjC,EAAsCA,EAAE,CAAF,CAAtC,EAA2CA,EAAE,CAAF,CAA3C,EAAgDA,EAAE,CAAF,CAAhD,EAAqDA,EAAE,CAAF,CAArD;AAA2D,CAA7J,CAA8JiY,OAAOrY,SAAP,CAAiBsxB,kBAAjB,GAAoC,UAASjxB,CAAT,EAAW;AAAC,MAAIC,CAAJ,EAAME,CAAN,EAAQG,CAAR,EAAUP,CAAV,EAAYS,CAAZ,EAAchB,CAAd,EAAgBE,CAAhB,EAAkBa,CAAlB,CAAoB,IAAIgC,IAAEqgB,OAAN,CAAc,IAAItjB,IAAEiD,EAAEihB,UAAR,CAAmB,IAAGjhB,EAAEqhB,SAAF,CAAY5jB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,UAAK,sBAAL;AAA4B,OAAG;AAACC,QAAEX,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBG,IAAEb,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBM,IAAEhB,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBD,IAAET,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBQ,IAAElB,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBR,IAAEF,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBN,IAAEJ,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBO,IAAEjB,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF;AAAsB,GAApL,CAAoL,OAAMI,CAAN,EAAQ;AAAC,UAAK,wCAAL;AAA8C,QAAKs0B,YAAL,CAAkBz0B,CAAlB,EAAoBE,CAApB,EAAsBG,CAAtB,EAAwBP,CAAxB,EAA0BS,CAA1B,EAA4BhB,CAA5B,EAA8BE,CAA9B,EAAgCa,CAAhC;AAAmC,CAA1a,CAA2ayX,OAAOrY,SAAP,CAAiBs2B,kBAAjB,GAAoC,UAASh2B,CAAT,EAAW;AAAC,MAAID,IAAE4iB,OAAN,CAAc,IAAI7iB,IAAEC,EAAEijB,IAAR,CAAa,IAAGjjB,EAAE4jB,SAAF,CAAY3jB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,UAAK,gCAAL;AAAsC,OAAIO,IAAER,EAAEojB,WAAF,CAAcnjB,CAAd,EAAgB,CAAhB,CAAN,CAAyB,IAAGO,EAAEH,MAAF,KAAW,CAAX,IAAcJ,EAAE4C,MAAF,CAASrC,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAAjC,IAAuCP,EAAE4C,MAAF,CAASrC,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAA7D,EAAkE;AAAC,UAAK,iCAAL;AAAuC,OAAIhB,IAAEO,EAAEE,CAAF,EAAIO,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAId,IAAEK,EAAEE,CAAF,EAAIO,EAAE,CAAF,CAAJ,CAAN,CAAgB,KAAKmY,SAAL,CAAenZ,CAAf,EAAiBE,CAAjB;AAAoB,CAAnU,CAAoUsY,OAAOrY,SAAP,CAAiBuxB,kBAAjB,GAAoC,UAASnxB,CAAT,EAAW;AAAC,MAAIE,IAAE2iB,OAAN,CAAc,IAAG3iB,EAAE2jB,SAAF,CAAY7jB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,UAAK,sBAAL;AAA4B,OAAGE,EAAEsjB,YAAF,CAAexjB,CAAf,EAAiB,CAAjB,EAAmB,CAAC,CAAD,EAAG,CAAH,CAAnB,MAA4B,wBAA/B,EAAwD;AAAC,UAAK,0BAAL;AAAgC,OAAIS,IAAEP,EAAEsjB,YAAF,CAAexjB,CAAf,EAAiB,CAAjB,EAAmB,CAAC,CAAD,EAAG,CAAH,CAAnB,CAAN,CAAgC,KAAKk2B,kBAAL,CAAwBz1B,CAAxB;AAA2B,CAAzQ,CAA0QwX,OAAOrY,SAAP,CAAiBwxB,iBAAjB,GAAmC,UAASpxB,CAAT,EAAWL,CAAX,EAAa;AAAC,MAAIc,CAAJ,EAAMP,CAAN,CAAQO,IAAE,IAAIq0B,IAAJ,EAAF,CAAar0B,EAAE01B,WAAF,CAAcn2B,CAAd,EAAiBE,IAAEO,EAAE21B,eAAF,EAAF,CAAsB,KAAKjF,kBAAL,CAAwBjxB,CAAxB;AAA2B,CAAxI;AACpuD,IAAIm2B,iBAAe,IAAI9Z,MAAJ,CAAW,EAAX,CAAnB,CAAkC8Z,eAAeC,OAAf,CAAuB,WAAvB,EAAmC,IAAnC,EAAyC,SAASC,wCAAT,CAAkD52B,CAAlD,EAAoDM,CAApD,EAAsDQ,CAAtD,EAAwD;AAAC,MAAIT,IAAE,SAAFA,CAAE,CAASP,CAAT,EAAW;AAAC,WAAOgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiT,UAAjB,CAA4BnrB,CAA5B,EAA8BgB,CAA9B,CAAP;AAAwC,GAA1D,CAA2D,IAAIP,IAAEF,EAAEL,CAAF,CAAN,CAAW,OAAO8X,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBgT,sBAAjB,CAAwCzqB,CAAxC,EAA0CO,CAA1C,EAA4CR,CAA5C,CAAP;AAAsD,UAASstB,uBAAT,CAAiCttB,CAAjC,EAAmCN,CAAnC,EAAqC;AAAC,MAAIO,IAAE,EAAN,CAAS,IAAIO,IAAEd,IAAE,CAAF,GAAIM,EAAEK,MAAZ,CAAmB,KAAI,IAAIN,IAAE,CAAV,EAAYA,IAAES,CAAd,EAAgBT,GAAhB,EAAoB;AAACE,QAAEA,IAAE,GAAJ;AAAQ,UAAOA,IAAED,CAAT;AAAW,QAAOL,SAAP,CAAiBiuB,IAAjB,GAAsB,UAASluB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIT,IAAE,SAAFA,CAAE,CAASC,CAAT,EAAW;AAAC,WAAOwX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiT,UAAjB,CAA4B3qB,CAA5B,EAA8BQ,CAA9B,CAAP;AAAwC,GAA1D,CAA2D,IAAIP,IAAEF,EAAEL,CAAF,CAAN,CAAW,OAAO,KAAK2uB,mBAAL,CAAyBpuB,CAAzB,EAA2BO,CAA3B,CAAP;AAAqC,CAA/I,CAAgJwX,OAAOrY,SAAP,CAAiB0uB,mBAAjB,GAAqC,UAASruB,CAAT,EAAWC,CAAX,EAAa;AAAC,MAAIT,IAAEgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBgT,sBAAjB,CAAwC1qB,CAAxC,EAA0CC,CAA1C,EAA4C,KAAKW,CAAL,CAAO+N,SAAP,EAA5C,CAAN,CAAsE,IAAI5O,IAAEmX,YAAY1X,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAIE,IAAE,KAAK62B,SAAL,CAAex2B,CAAf,CAAN,CAAwB,IAAIS,IAAEd,EAAE4B,QAAF,CAAW,EAAX,CAAN,CAAqB,OAAOgsB,wBAAwB9sB,CAAxB,EAA0B,KAAKI,CAAL,CAAO+N,SAAP,EAA1B,CAAP;AAAqD,CAAnP,CAAoP,SAAS6nB,YAAT,CAAsBv2B,CAAtB,EAAwBO,CAAxB,EAA0BR,CAA1B,EAA4B;AAAC,MAAID,IAAE,EAAN;AAAA,MAASL,IAAE,CAAX,CAAa,OAAMK,EAAEM,MAAF,GAASG,CAAf,EAAiB;AAACT,SAAG8X,UAAU7X,EAAE+X,UAAU9X,IAAE8C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiC,CAAC,CAACrD,IAAE,UAAH,KAAgB,EAAjB,EAAoB,CAACA,IAAE,QAAH,KAAc,EAAlC,EAAqC,CAACA,IAAE,KAAH,KAAW,CAAhD,EAAkDA,IAAE,GAApD,CAAjC,CAAZ,CAAF,CAAV,CAAH,CAAyHA,KAAG,CAAH;AAAK,UAAOK,CAAP;AAAS,QAAOJ,SAAP,CAAiB82B,OAAjB,GAAyB,UAASz2B,CAAT,EAAWQ,CAAX,EAAad,CAAb,EAAe;AAAC,MAAIO,IAAE,SAAFA,CAAE,CAAST,CAAT,EAAW;AAAC,WAAOgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyBtY,CAAzB,EAA2BgB,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAIT,IAAEE,EAAE8X,UAAU/X,CAAV,CAAF,CAAN,CAAsB,IAAGN,MAAIP,SAAP,EAAiB;AAACO,QAAE,CAAC,CAAH;AAAK,UAAO,KAAKyuB,sBAAL,CAA4BpuB,CAA5B,EAA8BS,CAA9B,EAAgCd,CAAhC,CAAP;AAA0C,CAAxL,CAAyLsY,OAAOrY,SAAP,CAAiBwuB,sBAAjB,GAAwC,UAAS7tB,CAAT,EAAWE,CAAX,EAAaD,CAAb,EAAe;AAAC,MAAIR,IAAE8X,UAAUvX,CAAV,CAAN,CAAmB,IAAIhB,IAAES,EAAEM,MAAR,CAAe,IAAIkC,IAAE,KAAK3B,CAAL,CAAO+N,SAAP,KAAmB,CAAzB,CAA2B,IAAI1O,IAAEgF,KAAK/C,IAAL,CAAUK,IAAE,CAAZ,CAAN,CAAqB,IAAI7C,CAAJ,CAAM,IAAIoB,IAAE,SAAFA,CAAE,CAASV,CAAT,EAAW;AAAC,WAAOoX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyB1X,CAAzB,EAA2BI,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAGD,MAAI,CAAC,CAAL,IAAQA,MAAIpB,SAAf,EAAyB;AAACoB,QAAEjB,CAAF;AAAI,GAA9B,MAAkC;AAAC,QAAGiB,MAAI,CAAC,CAAR,EAAU;AAACA,UAAEN,IAAEX,CAAF,GAAI,CAAN;AAAQ,KAAnB,MAAuB;AAAC,UAAGiB,IAAE,CAAC,CAAN,EAAQ;AAAC,cAAK,qBAAL;AAA2B;AAAC;AAAC,OAAGN,IAAGX,IAAEiB,CAAF,GAAI,CAAV,EAAa;AAAC,UAAK,eAAL;AAAqB,OAAIf,IAAE,EAAN,CAAS,IAAGe,IAAE,CAAL,EAAO;AAACf,QAAE,IAAIuJ,KAAJ,CAAUxI,CAAV,CAAF,CAAe,IAAI0W,YAAJ,GAAmB/G,SAAnB,CAA6B1Q,CAA7B,EAAgCA,IAAEuD,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiCvD,CAAjC,CAAF;AAAsC,OAAIoB,IAAEiX,UAAU/W,EAAEiX,UAAU,qCAAmChY,CAAnC,GAAqCP,CAA/C,CAAF,CAAV,CAAN,CAAsE,IAAIW,IAAE,EAAN,CAAS,KAAIT,IAAE,CAAN,EAAQA,IAAEO,IAAEM,CAAF,GAAIjB,CAAJ,GAAM,CAAhB,EAAkBI,KAAG,CAArB,EAAuB;AAACS,MAAET,CAAF,IAAK,CAAL;AAAO,OAAIM,IAAE+C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiC5C,CAAjC,IAAoC,MAApC,GAA2CX,CAAjD,CAAmD,IAAID,IAAEi3B,aAAa51B,CAAb,EAAeZ,EAAEK,MAAjB,EAAwBS,CAAxB,CAAN,CAAiC,IAAIgB,IAAE,EAAN,CAAS,KAAIpC,IAAE,CAAN,EAAQA,IAAEM,EAAEK,MAAZ,EAAmBX,KAAG,CAAtB,EAAwB;AAACoC,MAAEpC,CAAF,IAAKM,EAAEiD,UAAF,CAAavD,CAAb,IAAgBH,EAAE0D,UAAF,CAAavD,CAAb,CAArB;AAAqC,OAAImB,IAAG,SAAQ,IAAEZ,CAAF,GAAIsC,CAAb,GAAiB,GAAvB,CAA2BT,EAAE,CAAF,KAAM,CAACjB,CAAP,CAAS,KAAInB,IAAE,CAAN,EAAQA,IAAEJ,CAAV,EAAYI,GAAZ,EAAgB;AAACoC,MAAEQ,IAAF,CAAO1B,EAAEqC,UAAF,CAAavD,CAAb,CAAP;AAAwB,KAAE4C,IAAF,CAAO,GAAP,EAAY,OAAOgrB,wBAAwB,KAAKiJ,SAAL,CAAe,IAAIptB,UAAJ,CAAerH,CAAf,CAAf,EAAkCR,QAAlC,CAA2C,EAA3C,CAAxB,EAAuE,KAAKV,CAAL,CAAO+N,SAAP,EAAvE,CAAP;AAAkG,CAAt3B,CAAu3B,SAAS+nB,8BAAT,CAAwCl2B,CAAxC,EAA0Cd,CAA1C,EAA4CO,CAA5C,EAA8C;AAAC,MAAIF,IAAE,IAAIiY,MAAJ,EAAN,CAAmBjY,EAAE4Y,SAAF,CAAYjZ,CAAZ,EAAcO,CAAd,EAAiB,IAAID,IAAED,EAAE0Y,QAAF,CAAWjY,CAAX,CAAN,CAAoB,OAAOR,CAAP;AAAS,UAAS22B,gCAAT,CAA0Cn2B,CAA1C,EAA4CP,CAA5C,EAA8CF,CAA9C,EAAgD;AAAC,MAAIC,IAAE02B,+BAA+Bl2B,CAA/B,EAAiCP,CAAjC,EAAmCF,CAAnC,CAAN,CAA4C,IAAIL,IAAEM,EAAEsB,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,QAAvB,EAAgC,EAAhC,CAAN,CAA0C,OAAO9c,CAAP;AAAS,UAASk3B,4CAAT,CAAsDp3B,CAAtD,EAAwD;AAAC,OAAI,IAAIQ,CAAR,IAAawX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiQ,cAA9B,EAA6C;AAAC,QAAIjoB,IAAE8X,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiQ,cAAjB,CAAgC3nB,CAAhC,CAAN,CAAyC,IAAID,IAAEL,EAAEW,MAAR,CAAe,IAAGb,EAAEmJ,SAAF,CAAY,CAAZ,EAAc5I,CAAd,KAAkBL,CAArB,EAAuB;AAAC,UAAIO,IAAE,CAACD,CAAD,EAAGR,EAAEmJ,SAAF,CAAY5I,CAAZ,CAAH,CAAN,CAAyB,OAAOE,CAAP;AAAS;AAAC,UAAM,EAAN;AAAS,QAAON,SAAP,CAAiB6uB,MAAjB,GAAwB,UAAShvB,CAAT,EAAWW,CAAX,EAAa;AAACA,MAAEA,EAAEqc,OAAF,CAAU4Z,cAAV,EAAyB,EAAzB,CAAF,CAA+Bj2B,IAAEA,EAAEqc,OAAF,CAAU,SAAV,EAAoB,EAApB,CAAF,CAA0B,IAAIzc,IAAEmX,YAAY/W,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAGJ,EAAE4O,SAAF,KAAc,KAAK/N,CAAL,CAAO+N,SAAP,EAAjB,EAAoC;AAAC,WAAO,CAAP;AAAS,OAAIvO,IAAE,KAAKqY,QAAL,CAAc1Y,CAAd,CAAN,CAAuB,IAAIC,IAAEI,EAAEkB,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,QAAvB,EAAgC,EAAhC,CAAN,CAA0C,IAAIld,IAAEs3B,6CAA6C52B,CAA7C,CAAN,CAAsD,IAAGV,EAAEe,MAAF,IAAU,CAAb,EAAe;AAAC,WAAO,KAAP;AAAa,OAAIX,IAAEJ,EAAE,CAAF,CAAN,CAAW,IAAIC,IAAED,EAAE,CAAF,CAAN,CAAW,IAAIkB,IAAE,SAAFA,CAAE,CAASD,CAAT,EAAW;AAAC,WAAOiX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiT,UAAjB,CAA4BpqB,CAA5B,EAA8Bb,CAA9B,CAAP;AAAwC,GAA1D,CAA2D,IAAIO,IAAEO,EAAEhB,CAAF,CAAN,CAAW,OAAOD,KAAGU,CAAV;AAAa,CAAla,CAAma+X,OAAOrY,SAAP,CAAiBivB,qBAAjB,GAAuC,UAAS5uB,CAAT,EAAWQ,CAAX,EAAa;AAACA,MAAEA,EAAEgc,OAAF,CAAU4Z,cAAV,EAAyB,EAAzB,CAAF,CAA+B51B,IAAEA,EAAEgc,OAAF,CAAU,SAAV,EAAoB,EAApB,CAAF,CAA0B,IAAIzc,IAAEmX,YAAY1W,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAGT,EAAE4O,SAAF,KAAc,KAAK/N,CAAL,CAAO+N,SAAP,EAAjB,EAAoC;AAAC,WAAO,CAAP;AAAS,OAAIpP,IAAE,KAAKkZ,QAAL,CAAc1Y,CAAd,CAAN,CAAuB,IAAIT,IAAEC,EAAE+B,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,QAAvB,EAAgC,EAAhC,CAAN,CAA0C,IAAIvc,IAAE22B,6CAA6Ct3B,CAA7C,CAAN,CAAsD,IAAGW,EAAEI,MAAF,IAAU,CAAb,EAAe;AAAC,WAAO,KAAP;AAAa,OAAIX,IAAEO,EAAE,CAAF,CAAN,CAAW,IAAIT,IAAES,EAAE,CAAF,CAAN,CAAW,OAAOT,KAAGQ,CAAV;AAAa,CAA3W,CAA4WgY,OAAOrY,SAAP,CAAiBk3B,SAAjB,GAA2B,UAAS52B,CAAT,EAAWF,CAAX,EAAaS,CAAb,EAAehB,CAAf,EAAiB;AAAC,MAAIQ,IAAE,SAAFA,CAAE,CAASV,CAAT,EAAW;AAAC,WAAOkY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyBxY,CAAzB,EAA2BkB,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAId,IAAEM,EAAE+X,UAAU9X,CAAV,CAAF,CAAN,CAAsB,IAAGT,MAAIL,SAAP,EAAiB;AAACK,QAAE,CAAC,CAAH;AAAK,UAAO,KAAKmvB,wBAAL,CAA8BjvB,CAA9B,EAAgCK,CAAhC,EAAkCS,CAAlC,EAAoChB,CAApC,CAAP;AAA8C,CAAhM,CAAiMwY,OAAOrY,SAAP,CAAiBgvB,wBAAjB,GAA0C,UAASnvB,CAAT,EAAWuC,CAAX,EAAazB,CAAb,EAAeL,CAAf,EAAiB;AAAC,MAAIM,IAAE,IAAI4I,UAAJ,CAAepH,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAGxB,EAAEoO,SAAF,KAAc,KAAK/N,CAAL,CAAO+N,SAAP,EAAjB,EAAoC;AAAC,WAAO,KAAP;AAAa,OAAI1M,IAAE,SAAFA,CAAE,CAAS7B,CAAT,EAAW;AAAC,WAAOoX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyB1X,CAAzB,EAA2BE,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAIH,IAAE0X,UAAUrY,CAAV,CAAN,CAAmB,IAAID,IAAEY,EAAEE,MAAR,CAAe,IAAIf,IAAE,KAAKsB,CAAL,CAAO+N,SAAP,KAAmB,CAAzB,CAA2B,IAAIpM,IAAE0C,KAAK/C,IAAL,CAAU5C,IAAE,CAAZ,CAAN,CAAqB,IAAIwC,CAAJ,CAAM,IAAG7B,MAAI,CAAC,CAAL,IAAQA,MAAId,SAAf,EAAyB;AAACc,QAAEV,CAAF;AAAI,GAA9B,MAAkC;AAAC,QAAGU,MAAI,CAAC,CAAR,EAAU;AAACA,UAAEsC,IAAEhD,CAAF,GAAI,CAAN;AAAQ,KAAnB,MAAuB;AAAC,UAAGU,IAAE,CAAC,CAAN,EAAQ;AAAC,cAAK,qBAAL;AAA2B;AAAC;AAAC,OAAGsC,IAAGhD,IAAEU,CAAF,GAAI,CAAV,EAAa;AAAC,UAAK,eAAL;AAAqB,OAAIO,IAAE,KAAKiY,QAAL,CAAclY,CAAd,EAAiBoU,WAAjB,EAAN,CAAqC,KAAI7S,IAAE,CAAN,EAAQA,IAAEtB,EAAEH,MAAZ,EAAmByB,KAAG,CAAtB,EAAwB;AAACtB,MAAEsB,CAAF,KAAM,GAAN;AAAU,UAAMtB,EAAEH,MAAF,GAASkC,CAAf,EAAiB;AAAC/B,MAAEob,OAAF,CAAU,CAAV;AAAa,OAAGpb,EAAE+B,IAAE,CAAJ,MAAS,GAAZ,EAAgB;AAAC,UAAK,sCAAL;AAA4C,OAAEQ,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiCvC,CAAjC,CAAF,CAAsC,IAAId,IAAEc,EAAEqC,MAAF,CAAS,CAAT,EAAWN,IAAEhD,CAAF,GAAI,CAAf,CAAN,CAAwB,IAAIS,IAAEQ,EAAEqC,MAAF,CAASnD,EAAEW,MAAX,EAAkBd,CAAlB,CAAN,CAA2B,IAAIsB,IAAG,SAAQ,IAAE0B,CAAF,GAAIjD,CAAb,GAAiB,GAAvB,CAA2B,IAAG,CAACI,EAAEuD,UAAF,CAAa,CAAb,IAAgBpC,CAAjB,MAAsB,CAAzB,EAA2B;AAAC,UAAK,8BAAL;AAAoC,OAAID,IAAE41B,aAAax2B,CAAb,EAAeN,EAAEW,MAAjB,EAAwB4B,CAAxB,CAAN,CAAiC,IAAInB,IAAE,EAAN,CAAS,KAAIgB,IAAE,CAAN,EAAQA,IAAEpC,EAAEW,MAAZ,EAAmByB,KAAG,CAAtB,EAAwB;AAAChB,MAAEgB,CAAF,IAAKpC,EAAEuD,UAAF,CAAanB,CAAb,IAAgBlB,EAAEqC,UAAF,CAAanB,CAAb,CAArB;AAAqC,KAAE,CAAF,KAAM,CAACjB,CAAP,CAAS,IAAId,IAAEwC,IAAEhD,CAAF,GAAIU,CAAJ,GAAM,CAAZ,CAAc,KAAI6B,IAAE,CAAN,EAAQA,IAAE/B,CAAV,EAAY+B,KAAG,CAAf,EAAiB;AAAC,QAAGhB,EAAEgB,CAAF,MAAO,CAAV,EAAY;AAAC,YAAK,0BAAL;AAAgC;AAAC,OAAGhB,EAAEf,CAAF,MAAO,CAAV,EAAY;AAAC,UAAK,uBAAL;AAA6B,UAAOC,MAAI6X,UAAU5V,EAAE8V,UAAU,qCAAmC5X,CAAnC,GAAqC4C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiCjC,EAAEsB,KAAF,CAAQ,CAACnC,CAAT,CAAjC,CAA/C,CAAF,CAAV,CAAX;AAAuH,CAArlC,CAAslC+X,OAAO8e,aAAP,GAAqB,CAAC,CAAtB,CAAwB9e,OAAO+e,YAAP,GAAoB,CAAC,CAArB,CAAuB/e,OAAOgf,gBAAP,GAAwB,CAAC,CAAzB;AACzhJ,SAASnC,IAAT,GAAe;AAAC,MAAIt0B,IAAEqiB,OAAN;AAAA,MAAcziB,IAAEI,EAAE6iB,WAAlB;AAAA,MAA8B7jB,IAAEgB,EAAE0iB,IAAlC;AAAA,MAAuCljB,IAAEQ,EAAE2iB,MAA3C;AAAA,MAAkD1jB,IAAEe,EAAEijB,UAAtD;AAAA,MAAiEvjB,IAAEM,EAAEgjB,YAArE;AAAA,MAAkFjkB,IAAEiB,EAAE+iB,YAAtF;AAAA,MAAmG5jB,IAAEa,EAAEyiB,OAAvG;AAAA,MAA+G5iB,IAAEG,EAAEwjB,OAAnH;AAAA,MAA2HvjB,IAAEq0B,IAA7H;AAAA,MAAkI70B,IAAEylB,QAApI,CAA6I,KAAK7F,GAAL,GAAS,IAAT,CAAc,KAAK6S,OAAL,GAAa,CAAb,CAAe,KAAKwE,OAAL,GAAa,CAAb,CAAe,KAAKC,QAAL,GAAc,IAAd,CAAmB,KAAKC,UAAL,GAAgB,YAAU;AAAC,QAAG,KAAKvX,GAAL,KAAW,IAAX,IAAiB,KAAK6S,OAAL,KAAe,CAAnC,EAAqC;AAAC,aAAO,KAAKA,OAAZ;AAAoB,SAAGxyB,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,MAAsB,YAAzB,EAAsC;AAAC,WAAK6S,OAAL,GAAa,CAAb,CAAe,KAAKwE,OAAL,GAAa,CAAC,CAAd,CAAgB,OAAO,CAAP;AAAS,UAAKxE,OAAL,GAAa,CAAb,CAAe,OAAO,CAAP;AAAS,GAA5L,CAA6L,KAAK2E,kBAAL,GAAwB,YAAU;AAAC,WAAO53B,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAAhF,CAAiF,KAAKI,0BAAL,GAAgC,YAAU;AAAC,WAAOj3B,EAAEZ,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,EAAkB,CAAlB,CAAb,EAAkC,IAAlC,CAAF,CAAP;AAAkD,GAA7F,CAA8F,KAAKK,YAAL,GAAkB,YAAU;AAAC,WAAOr3B,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAA1E,CAA2E,KAAKM,eAAL,GAAqB,YAAU;AAAC,WAAO/2B,EAAEg3B,MAAF,CAAS,KAAKF,YAAL,EAAT,CAAP;AAAqC,GAArE,CAAsE,KAAKG,aAAL,GAAmB,YAAU;AAAC,WAAOx3B,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAA3E,CAA4E,KAAKS,gBAAL,GAAsB,YAAU;AAAC,WAAOl3B,EAAEg3B,MAAF,CAAS,KAAKC,aAAL,EAAT,CAAP;AAAsC,GAAvE,CAAwE,KAAKE,YAAL,GAAkB,YAAU;AAAC,QAAIr3B,IAAEd,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,EAAkB,CAAlB,CAAb,CAAN,CAAyC32B,IAAEA,EAAEkc,OAAF,CAAU,OAAV,EAAkB,KAAlB,CAAF,CAA2Blc,IAAE6C,mBAAmB7C,CAAnB,CAAF,CAAwB,OAAOA,CAAP;AAAS,GAAlI,CAAmI,KAAKs3B,WAAL,GAAiB,YAAU;AAAC,QAAIt3B,IAAEd,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,EAAkB,CAAlB,CAAb,CAAN,CAAyC32B,IAAEA,EAAEkc,OAAF,CAAU,OAAV,EAAkB,KAAlB,CAAF,CAA2Blc,IAAE6C,mBAAmB7C,CAAnB,CAAF,CAAwB,OAAOA,CAAP;AAAS,GAAjI,CAAkI,KAAK61B,eAAL,GAAqB,YAAU;AAAC,WAAO51B,EAAEgjB,YAAF,CAAe,KAAK3D,GAApB,EAAwB,CAAxB,EAA0B,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAA1B,EAA6C,IAA7C,CAAP;AAA0D,GAA1F,CAA2F,KAAKY,eAAL,GAAqB,YAAU;AAAC,WAAOv4B,EAAE,KAAKsgB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAA7E,CAA8E,KAAKa,sBAAL,GAA4B,YAAU;AAAC,QAAIx3B,IAAE,KAAKu3B,eAAL,EAAN,CAA6B,OAAOv4B,EAAE,KAAKsgB,GAAP,EAAWtf,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,EAAmB,IAAnB,CAAP;AAAgC,GAApG,CAAqG,KAAKy3B,YAAL,GAAkB,YAAU;AAAC,WAAOxK,QAAQC,MAAR,CAAe,KAAK2I,eAAL,EAAf,EAAsC,IAAtC,EAA2C,UAA3C,CAAP;AAA8D,GAA3F,CAA4F,KAAK6B,yBAAL,GAA+B,YAAU;AAAC,WAAO53B,EAAEZ,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,EAAmB,IAAnB,CAAF,CAAP;AAAmC,GAA7E,CAA8E,KAAKqY,oBAAL,GAA0B,YAAU;AAAC,WAAOz4B,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,CAAb,EAAiB,IAAjB,EAAsB,IAAtB,CAAP;AAAmC,GAAxE,CAAyE,KAAKsY,eAAL,GAAqB,UAASt3B,CAAT,EAAW;AAAC,QAAIE,IAAE,KAAKk3B,yBAAL,EAAN,CAAuC,IAAI13B,IAAE,KAAK23B,oBAAL,EAAN,CAAkC,IAAI11B,IAAEtC,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,CAAb,EAAiB,IAAjB,CAAN,CAA6B,IAAI/e,IAAE,IAAI2W,KAAKf,MAAL,CAAYyW,SAAhB,CAA0B,EAACtC,KAAI9pB,CAAL,EAA1B,CAAN,CAAyCD,EAAEI,IAAF,CAAOL,CAAP,EAAUC,EAAE+qB,SAAF,CAAYrpB,CAAZ,EAAe,OAAO1B,EAAE2tB,MAAF,CAASluB,CAAT,CAAP;AAAmB,GAA5N,CAA6N,KAAK63B,QAAL,GAAc,YAAU;AAAC,QAAG,KAAK1F,OAAL,KAAe,CAAlB,EAAoB;AAAC,aAAO,CAAC,CAAR;AAAU,SAAI5xB,IAAEvB,EAAE,KAAKsgB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAb,EAAqB,IAArB,CAAN,CAAiC,IAAIrd,IAAEpC,EAAE,KAAKyf,GAAP,EAAW/e,CAAX,CAAN,CAAoB,KAAKq2B,QAAL,GAAc,IAAInuB,KAAJ,EAAd,CAA0B,KAAI,IAAInI,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAIkB,IAAE,EAAN,CAASA,EAAEs2B,QAAF,GAAW,KAAX,CAAiB,IAAI93B,IAAEH,EAAE,KAAKyf,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,CAAN,CAAuB,IAAIqB,IAAE,CAAN,CAAQ,IAAG3B,EAAED,MAAF,KAAW,CAAd,EAAgB;AAACyB,UAAEs2B,QAAF,GAAW,IAAX,CAAgBn2B,IAAE,CAAF;AAAI,SAAEggB,GAAF,GAAM1hB,EAAEkjB,WAAF,CAAcjkB,EAAE,KAAKogB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,CAAD,CAAhB,EAAoB,IAApB,CAAd,CAAN,CAA+C,IAAIE,IAAExB,EAAE,KAAKsgB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,IAAEqB,CAAH,CAAhB,CAAN,CAA6BH,EAAEu2B,IAAF,GAAO34B,EAAE,KAAKkgB,GAAP,EAAW9e,CAAX,CAAP,CAAqB,KAAKo2B,QAAL,CAAc50B,IAAd,CAAmBR,CAAnB;AAAsB;AAAC,GAAzX,CAA0X,KAAKw2B,UAAL,GAAgB,UAAS13B,CAAT,EAAW;AAAC,QAAIN,IAAE,KAAK42B,QAAX,CAAoB,IAAIp2B,IAAEF,CAAN,CAAQ,IAAG,CAACA,EAAE2b,KAAF,CAAQ,WAAR,CAAJ,EAAyB;AAACzb,UAAE0W,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmBC,QAAnB,CAA4BphB,CAA5B,CAAF;AAAiC,SAAGE,MAAI,EAAP,EAAU;AAAC,aAAO3B,SAAP;AAAiB,UAAI,IAAIoD,IAAE,CAAV,EAAYA,IAAEjC,EAAED,MAAhB,EAAuBkC,GAAvB,EAA2B;AAAC,UAAGjC,EAAEiC,CAAF,EAAK0f,GAAL,KAAWnhB,CAAd,EAAgB;AAAC,eAAOR,EAAEiC,CAAF,CAAP;AAAY;AAAC,YAAOpD,SAAP;AAAiB,GAA1N,CAA2N,KAAKo5B,sBAAL,GAA4B,YAAU;AAAC,QAAI33B,IAAE,KAAK03B,UAAL,CAAgB,kBAAhB,CAAN,CAA0C,IAAG13B,MAAIzB,SAAP,EAAiB;AAAC,aAAOyB,CAAP;AAAS,SAAIN,IAAEf,EAAE,KAAKqgB,GAAP,EAAWhf,EAAEy3B,IAAb,CAAN,CAAyB,IAAG/3B,MAAI,EAAP,EAAU;AAAC,aAAM,EAAN;AAAS,SAAGA,MAAI,QAAP,EAAgB;AAAC,aAAM,EAACk4B,IAAG,IAAJ,EAAN;AAAgB,SAAGl4B,EAAEuC,MAAF,CAAS,CAAT,EAAW,CAAX,MAAgB,UAAnB,EAA8B;AAAC,UAAI/B,IAAEvB,EAAEe,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAIiC,IAAEK,SAAS9B,CAAT,EAAW,EAAX,CAAN,CAAqB,OAAM,EAAC03B,IAAG,IAAJ,EAASC,SAAQl2B,CAAjB,EAAN;AAA0B,WAAK,8BAAL;AAAoC,GAAzT,CAA0T,KAAKm2B,iBAAL,GAAuB,YAAU;AAAC,QAAI53B,IAAE,KAAKw3B,UAAL,CAAgB,UAAhB,CAAN,CAAkC,IAAGx3B,MAAI3B,SAAP,EAAiB;AAAC,aAAM,EAAN;AAAS,SAAIoD,IAAEhD,EAAE,KAAKqgB,GAAP,EAAW9e,EAAEu3B,IAAb,CAAN,CAAyB,IAAG91B,EAAElC,MAAF,GAAS,CAAT,IAAY,CAAZ,IAAekC,EAAElC,MAAF,IAAU,CAA5B,EAA8B;AAAC,YAAK,2BAAL;AAAiC,SAAIC,IAAEsC,SAASL,EAAEM,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,CAAN,CAA8B,IAAIjC,IAAEgC,SAASL,EAAEM,MAAF,CAAS,CAAT,CAAT,EAAqB,EAArB,EAAyBvB,QAAzB,CAAkC,CAAlC,CAAN,CAA2C,OAAOV,EAAEiC,MAAF,CAAS,CAAT,EAAWjC,EAAEP,MAAF,GAASC,CAApB,CAAP;AAA8B,GAA/R,CAAgS,KAAKq4B,oBAAL,GAA0B,YAAU;AAAC,QAAI/3B,IAAE,KAAK83B,iBAAL,EAAN,CAA+B,IAAIp4B,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,KAAI,IAAIxG,IAAE,CAAV,EAAYA,IAAE3B,EAAEP,MAAhB,EAAuBkC,GAAvB,EAA2B;AAAC,UAAG3B,EAAEiC,MAAF,CAASN,CAAT,EAAW,CAAX,KAAe,GAAlB,EAAsB;AAACjC,UAAEgC,IAAF,CAAOuyB,KAAK+D,aAAL,CAAmBr2B,CAAnB,CAAP;AAA8B;AAAC,YAAOjC,EAAEoC,IAAF,CAAO,GAAP,CAAP;AAAmB,GAA3L,CAA4L,KAAKm2B,0BAAL,GAAgC,YAAU;AAAC,QAAIv4B,IAAE,KAAKg4B,UAAL,CAAgB,sBAAhB,CAAN,CAA8C,IAAGh4B,MAAInB,SAAP,EAAiB;AAAC,aAAOmB,CAAP;AAAS,YAAOf,EAAE,KAAKqgB,GAAP,EAAWtf,EAAE+3B,IAAb,CAAP;AAA0B,GAA9I,CAA+I,KAAKS,4BAAL,GAAkC,YAAU;AAAC,QAAIj4B,IAAE,KAAKy3B,UAAL,CAAgB,wBAAhB,CAAN,CAAgD,IAAGz3B,MAAI1B,SAAP,EAAiB;AAAC,aAAO0B,CAAP;AAAS,SAAIP,IAAE,EAAN,CAAS,IAAIQ,IAAEf,EAAE,KAAK6f,GAAP,EAAW/e,EAAEw3B,IAAb,CAAN,CAAyB,IAAI91B,IAAEpC,EAAEW,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAGE,EAAE+B,MAAF,CAASN,EAAE3B,CAAF,CAAT,EAAc,CAAd,MAAmB,IAAtB,EAA2B;AAACN,UAAEy4B,GAAF,GAAMx5B,EAAEuB,CAAF,EAAIyB,EAAE3B,CAAF,CAAJ,CAAN;AAAgB;AAAC,YAAON,CAAP;AAAS,GAAzP,CAA0P,KAAK04B,qBAAL,GAA2B,YAAU;AAAC,QAAIn4B,IAAE,KAAKy3B,UAAL,CAAgB,aAAhB,CAAN,CAAqC,IAAGz3B,MAAI1B,SAAP,EAAiB;AAAC,aAAO0B,CAAP;AAAS,SAAIP,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,IAAIjI,IAAEf,EAAE,KAAK6f,GAAP,EAAW/e,EAAEw3B,IAAb,CAAN,CAAyB,IAAGv3B,MAAI,EAAP,EAAU;AAAC,aAAOR,CAAP;AAAS,SAAIiC,IAAEpC,EAAEW,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAACN,QAAEgC,IAAF,CAAOlC,EAAEb,EAAEuB,CAAF,EAAIyB,EAAE3B,CAAF,CAAJ,CAAF,CAAP;AAAqB,YAAON,CAAP;AAAS,GAA5O,CAA6O,KAAK24B,oBAAL,GAA0B,YAAU;AAAC,QAAI12B,IAAE,KAAK22B,qBAAL,EAAN,CAAmC,IAAI54B,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,KAAI,IAAInI,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAG2B,EAAE3B,CAAF,EAAK,CAAL,MAAU,KAAb,EAAmB;AAACN,UAAEgC,IAAF,CAAOC,EAAE3B,CAAF,EAAK,CAAL,CAAP;AAAgB;AAAC,YAAON,CAAP;AAAS,GAApK,CAAqK,KAAK44B,qBAAL,GAA2B,YAAU;AAAC,QAAIr4B,CAAJ,EAAMkB,CAAN,EAAQE,CAAR,CAAU,IAAIH,IAAE,KAAKw2B,UAAL,CAAgB,gBAAhB,CAAN,CAAwC,IAAGx2B,MAAI3C,SAAP,EAAiB;AAAC,aAAO2C,CAAP;AAAS,SAAIxB,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,IAAIjI,IAAEf,EAAE,KAAK6f,GAAP,EAAW9d,EAAEu2B,IAAb,CAAN,CAAyB,IAAI91B,IAAEpC,EAAEW,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAACqB,UAAEnB,EAAE+B,MAAF,CAASN,EAAE3B,CAAF,CAAT,EAAc,CAAd,CAAF,CAAmBC,IAAEtB,EAAEuB,CAAF,EAAIyB,EAAE3B,CAAF,CAAJ,CAAF,CAAY,IAAGqB,MAAI,IAAP,EAAY;AAACF,YAAE+hB,UAAUjjB,CAAV,CAAF,CAAeP,EAAEgC,IAAF,CAAO,CAAC,MAAD,EAAQP,CAAR,CAAP;AAAmB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAE+hB,UAAUjjB,CAAV,CAAF,CAAeP,EAAEgC,IAAF,CAAO,CAAC,KAAD,EAAOP,CAAP,CAAP;AAAkB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAE8yB,KAAK2C,MAAL,CAAY32B,CAAZ,EAAc,CAAd,CAAF,CAAmBP,EAAEgC,IAAF,CAAO,CAAC,IAAD,EAAMP,CAAN,CAAP;AAAiB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAE+hB,UAAUjjB,CAAV,CAAF,CAAeP,EAAEgC,IAAF,CAAO,CAAC,KAAD,EAAOP,CAAP,CAAP;AAAkB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAEglB,QAAQlmB,CAAR,CAAF,CAAaP,EAAEgC,IAAF,CAAO,CAAC,IAAD,EAAMP,CAAN,CAAP;AAAiB;AAAC,YAAOzB,CAAP;AAAS,GAAvd,CAAwd,KAAK64B,8BAAL,GAAoC,YAAU;AAAC,QAAIr3B,IAAE,KAAKw2B,UAAL,CAAgB,uBAAhB,CAAN,CAA+C,IAAGx2B,MAAI3C,SAAP,EAAiB;AAAC,aAAO2C,CAAP;AAAS,SAAIxB,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,IAAIxG,IAAEpC,EAAE,KAAKyf,GAAP,EAAW9d,EAAEu2B,IAAb,CAAN,CAAyB,KAAI,IAAIv3B,IAAE,CAAV,EAAYA,IAAEyB,EAAElC,MAAhB,EAAuBS,GAAvB,EAA2B;AAAC,UAAG;AAAC,YAAImB,IAAEzC,EAAE,KAAKogB,GAAP,EAAWrd,EAAEzB,CAAF,CAAX,EAAgB,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAhB,EAAwB,IAAxB,CAAN,CAAoC,IAAID,IAAEijB,UAAU7hB,CAAV,CAAN,CAAmB3B,EAAEgC,IAAF,CAAOzB,CAAP;AAAU,OAArE,CAAqE,OAAMD,CAAN,EAAQ,CAAE;AAAC,YAAON,CAAP;AAAS,GAAzR,CAA0R,KAAK84B,aAAL,GAAmB,YAAU;AAAC,QAAIv4B,IAAE,KAAKy3B,UAAL,CAAgB,qBAAhB,CAAN,CAA6C,IAAGz3B,MAAI1B,SAAP,EAAiB;AAAC,aAAO0B,CAAP;AAAS,SAAIP,IAAE,EAAC+4B,MAAK,EAAN,EAASC,UAAS,EAAlB,EAAN,CAA4B,IAAI/2B,IAAEpC,EAAE,KAAKyf,GAAP,EAAW/e,EAAEw3B,IAAb,CAAN,CAAyB,KAAI,IAAIz3B,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAIkB,IAAEtC,EAAE,KAAKogB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,CAAD,CAAhB,EAAoB,IAApB,CAAN,CAAgC,IAAIE,IAAEtB,EAAE,KAAKogB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,CAAD,CAAhB,EAAoB,IAApB,CAAN,CAAgC,IAAGkB,MAAI,kBAAP,EAA0B;AAACxB,UAAE+4B,IAAF,CAAO/2B,IAAP,CAAYwhB,UAAUhjB,CAAV,CAAZ;AAA0B,WAAGgB,MAAI,kBAAP,EAA0B;AAACxB,UAAEg5B,QAAF,CAAWh3B,IAAX,CAAgBwhB,UAAUhjB,CAAV,CAAhB;AAA8B;AAAC,YAAOR,CAAP;AAAS,GAA/W,CAAgX,KAAKi5B,yBAAL,GAA+B,YAAU;AAAC,QAAIz4B,IAAE,KAAKw3B,UAAL,CAAgB,qBAAhB,CAAN,CAA6C,IAAGx3B,MAAI3B,SAAP,EAAiB;AAAC,aAAO2B,CAAP;AAAS,SAAIR,IAAEP,EAAE,KAAK6f,GAAP,EAAW9e,EAAEu3B,IAAb,CAAN,CAAyB,IAAIp0B,IAAE,EAAN,CAAS,IAAIlC,IAAE5B,EAAEG,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAI2B,IAAE,CAAV,EAAYA,IAAEF,EAAE1B,MAAhB,EAAuB4B,GAAvB,EAA2B;AAAC,UAAIJ,IAAE,EAAN,CAAS,IAAIjB,IAAET,EAAEG,CAAF,EAAIyB,EAAEE,CAAF,CAAJ,CAAN,CAAgBJ,EAAE23B,EAAF,GAAKp5B,EAAEb,EAAEe,CAAF,EAAIM,EAAE,CAAF,CAAJ,CAAF,CAAL,CAAkB,IAAGA,EAAEP,MAAF,KAAW,CAAd,EAAgB;AAAC,YAAIkC,IAAEpC,EAAEG,CAAF,EAAIM,EAAE,CAAF,CAAJ,CAAN,CAAgB,KAAI,IAAIkB,IAAE,CAAV,EAAYA,IAAES,EAAElC,MAAhB,EAAuByB,GAAvB,EAA2B;AAAC,cAAIjB,IAAErB,EAAEc,CAAF,EAAIiC,EAAET,CAAF,CAAJ,EAAS,CAAC,CAAD,CAAT,EAAa,IAAb,CAAN,CAAyB,IAAGjB,MAAI,kBAAP,EAA0B;AAACgB,cAAE43B,GAAF,GAAM3V,UAAUtkB,EAAEc,CAAF,EAAIiC,EAAET,CAAF,CAAJ,EAAS,CAAC,CAAD,CAAT,CAAV,CAAN;AAA+B,WAA1D,MAA8D;AAAC,gBAAGjB,MAAI,kBAAP,EAA0B;AAACgB,gBAAE63B,OAAF,GAAU5V,UAAUtkB,EAAEc,CAAF,EAAIiC,EAAET,CAAF,CAAJ,EAAS,CAAC,CAAD,EAAG,CAAH,CAAT,CAAV,CAAV;AAAqC;AAAC;AAAC;AAAC,SAAEQ,IAAF,CAAOT,CAAP;AAAU,YAAOoC,CAAP;AAAS,GAAnd,CAAod,KAAK01B,WAAL,GAAiB,UAASr5B,CAAT,EAAW;AAAC,SAAK41B,WAAL,CAAiBl2B,EAAEM,CAAF,CAAjB;AAAuB,GAApD,CAAqD,KAAK41B,WAAL,GAAiB,UAAS51B,CAAT,EAAW;AAAC,SAAKsf,GAAL,GAAStf,CAAT,CAAW,KAAK62B,UAAL,GAAkB,IAAG;AAAC73B,QAAE,KAAKsgB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,EAAmB,IAAnB,EAAyB,KAAKuY,QAAL;AAAgB,KAA7C,CAA6C,OAAM51B,CAAN,EAAQ,CAAE;AAAC,GAAlH,CAAmH,KAAKq3B,OAAL,GAAa,YAAU;AAAC,QAAIr3B,IAAEsyB,IAAN,CAAW,IAAIltB,CAAJ,EAAM1D,CAAN,EAAQsD,CAAR,CAAUI,IAAE,gBAAF,CAAmBA,KAAG,sBAAoB,KAAKyvB,kBAAL,EAApB,GAA8C,IAAjD,CAAsDzvB,KAAG,4BAA0B,KAAK0vB,0BAAL,EAA1B,GAA4D,IAA/D,CAAoE1vB,KAAG,eAAa,KAAK4vB,eAAL,EAAb,GAAoC,IAAvC,CAA4C5vB,KAAG,kBAAgB,KAAKgwB,YAAL,EAAhB,GAAoC,IAAvC,CAA4ChwB,KAAG,iBAAe,KAAKiwB,WAAL,EAAf,GAAkC,IAArC,CAA0CjwB,KAAG,gBAAc,KAAK+vB,gBAAL,EAAd,GAAsC,IAAzC,CAA8C/vB,KAAG,+BAAH,CAAmC1D,IAAE,KAAK8zB,YAAL,EAAF,CAAsBpwB,KAAG,wBAAsB1D,EAAE6U,IAAxB,GAA6B,IAAhC,CAAqC,IAAG7U,EAAE6U,IAAF,KAAS,KAAZ,EAAkB;AAACnR,WAAG,WAAS4f,YAAYtjB,EAAErD,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAZ,EAA8BuB,MAA9B,CAAqC,CAArC,EAAuC,EAAvC,CAAT,GAAoD,OAAvD,CAA+D8E,KAAG,WAAS4f,YAAYtjB,EAAEjE,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAZ,CAAT,GAAuC,IAA1C;AAA+C,SAAE,KAAK41B,QAAP,CAAgB,IAAG3vB,MAAIpI,SAAJ,IAAeoI,MAAI,IAAtB,EAA2B;AAACI,WAAG,sBAAH,CAA0B,KAAI,IAAI1F,IAAE,CAAV,EAAYA,IAAEsF,EAAElH,MAAhB,EAAuB4B,GAAvB,EAA2B;AAAC,YAAIrB,IAAE2G,EAAEtF,CAAF,CAAN,CAAW,IAAIuF,IAAEgQ,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmB8B,QAAnB,CAA4BjjB,EAAEqhB,GAA9B,CAAN,CAAyC,IAAGza,MAAI,EAAP,EAAU;AAACA,cAAE5G,EAAEqhB,GAAJ;AAAQ,aAAIne,IAAE,EAAN,CAAS,IAAGlD,EAAEw3B,QAAF,KAAa,IAAhB,EAAqB;AAACt0B,cAAE,UAAF;AAAa,cAAG,OAAK0D,CAAL,GAAO,GAAP,GAAW1D,CAAX,GAAa,KAAhB,CAAsB,IAAG0D,MAAI,kBAAP,EAA0B;AAAC,cAAIxD,IAAE,KAAKu0B,sBAAL,EAAN,CAAoC,IAAGv0B,EAAEw0B,EAAF,KAAOr5B,SAAV,EAAoB;AAACwI,iBAAG,UAAH;AAAc,WAAnC,MAAuC;AAACA,iBAAG,aAAH,CAAiB,IAAG3D,EAAEy0B,OAAF,KAAYt5B,SAAf,EAAyB;AAACwI,mBAAG,eAAa3D,EAAEy0B,OAAlB;AAA0B,kBAAG,IAAH;AAAQ;AAAC,SAArL,MAAyL;AAAC,cAAGjxB,MAAI,UAAP,EAAkB;AAACG,iBAAG,SAAO,KAAKgxB,oBAAL,EAAP,GAAmC,IAAtC;AAA2C,WAA9D,MAAkE;AAAC,gBAAGnxB,MAAI,sBAAP,EAA8B;AAACG,mBAAG,SAAO,KAAKkxB,0BAAL,EAAP,GAAyC,IAA5C;AAAiD,aAAhF,MAAoF;AAAC,kBAAGrxB,MAAI,wBAAP,EAAgC;AAAC,oBAAIlH,IAAE,KAAKw4B,4BAAL,EAAN,CAA0C,IAAGx4B,EAAEy4B,GAAF,KAAQ55B,SAAX,EAAqB;AAACwI,uBAAG,aAAWrH,EAAEy4B,GAAb,GAAiB,IAApB;AAAyB;AAAC,eAA3H,MAA+H;AAAC,oBAAGvxB,MAAI,aAAP,EAAqB;AAAC,sBAAI3D,IAAE,KAAKm1B,qBAAL,EAAN,CAAmCrxB,KAAG,SAAO9D,EAAEnB,IAAF,CAAO,IAAP,CAAP,GAAoB,IAAvB;AAA4B,iBAArF,MAAyF;AAAC,sBAAG8E,MAAI,gBAAP,EAAwB;AAAC,wBAAI3F,IAAE,KAAKq3B,qBAAL,EAAN,CAAmCvxB,KAAG,SAAO9F,CAAP,GAAS,IAAZ;AAAiB,mBAA7E,MAAiF;AAAC,wBAAG2F,MAAI,uBAAP,EAA+B;AAAC,0BAAIC,IAAE,KAAK0xB,8BAAL,EAAN,CAA4CxxB,KAAG,SAAOF,CAAP,GAAS,IAAZ;AAAiB,qBAA7F,MAAiG;AAAC,0BAAGD,MAAI,qBAAP,EAA6B;AAAC,4BAAI3G,IAAE,KAAKu4B,aAAL,EAAN,CAA2B,IAAGv4B,EAAEw4B,IAAF,KAASl6B,SAAZ,EAAsB;AAACwI,+BAAG,eAAa9G,EAAEw4B,IAAF,CAAO32B,IAAP,CAAY,GAAZ,CAAb,GAA8B,IAAjC;AAAsC,6BAAG7B,EAAEy4B,QAAF,KAAan6B,SAAhB,EAA0B;AAACwI,+BAAG,mBAAiB9G,EAAEy4B,QAAF,CAAW52B,IAAX,CAAgB,GAAhB,CAAjB,GAAsC,IAAzC;AAA8C;AAAC,uBAAhM,MAAoM;AAAC,4BAAG8E,MAAI,qBAAP,EAA6B;AAAC,8BAAI1G,IAAE,KAAKy4B,yBAAL,EAAN,CAAuC,KAAI,IAAIz3B,IAAE,CAAV,EAAYA,IAAEhB,EAAET,MAAhB,EAAuByB,GAAvB,EAA2B;AAAC,gCAAGhB,EAAEgB,CAAF,EAAK03B,EAAL,KAAUr6B,SAAb,EAAuB;AAACwI,mCAAG,qBAAmB7G,EAAEgB,CAAF,EAAK03B,EAAxB,GAA2B,IAA9B;AAAmC,iCAAG14B,EAAEgB,CAAF,EAAK23B,GAAL,KAAWt6B,SAAd,EAAwB;AAACwI,mCAAG,cAAY7G,EAAEgB,CAAF,EAAK23B,GAAjB,GAAqB,IAAxB;AAA6B;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC,UAAG,0BAAwB,KAAKzB,yBAAL,EAAxB,GAAyD,IAA5D,CAAiErwB,KAAG,gBAAc,KAAKswB,oBAAL,GAA4Bp1B,MAA5B,CAAmC,CAAnC,EAAqC,EAArC,CAAd,GAAuD,OAA1D,CAAkE,OAAO8E,CAAP;AAAS,GAAnkE;AAAokE,MAAK6vB,MAAL,GAAY,UAASh4B,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAGA,MAAIZ,SAAP,EAAiB;AAACY,QAAE,CAAF;AAAI,OAAGP,EAAEqD,MAAF,CAAS9C,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,UAAK,cAAL;AAAoB,OAAIE,IAAE,IAAI8I,KAAJ,EAAN,CAAkB,IAAIrJ,IAAEkjB,QAAQQ,WAAR,CAAoB5jB,CAApB,EAAsBO,CAAtB,CAAN,CAA+B,KAAI,IAAIC,IAAE,CAAV,EAAYA,IAAEN,EAAEW,MAAhB,EAAuBL,GAAvB,EAA2B;AAACC,MAAEqC,IAAF,CAAOuyB,KAAKgF,OAAL,CAAar6B,CAAb,EAAeE,EAAEM,CAAF,CAAf,CAAP;AAA6B,OAAEC,EAAEwnB,GAAF,CAAM,UAASjnB,CAAT,EAAW;AAAC,WAAOA,EAAEgc,OAAF,CAAU,GAAV,EAAc,KAAd,CAAP;AAA4B,GAA9C,CAAF,CAAkD,OAAM,MAAIvc,EAAEyC,IAAF,CAAO,GAAP,CAAV;AAAsB,CAA/Q,CAAgRmyB,KAAKgF,OAAL,GAAa,UAASr6B,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAGA,MAAIZ,SAAP,EAAiB;AAACY,QAAE,CAAF;AAAI,OAAGP,EAAEqD,MAAF,CAAS9C,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,UAAK,eAAL;AAAqB,OAAIE,IAAE,IAAI8I,KAAJ,EAAN,CAAkB,IAAIrJ,IAAEkjB,QAAQQ,WAAR,CAAoB5jB,CAApB,EAAsBO,CAAtB,CAAN,CAA+B,KAAI,IAAIC,IAAE,CAAV,EAAYA,IAAEN,EAAEW,MAAhB,EAAuBL,GAAvB,EAA2B;AAACC,MAAEqC,IAAF,CAAOuyB,KAAKiF,iBAAL,CAAuBt6B,CAAvB,EAAyBE,EAAEM,CAAF,CAAzB,CAAP;AAAuC,OAAEC,EAAEwnB,GAAF,CAAM,UAASjnB,CAAT,EAAW;AAAC,WAAOA,EAAEgc,OAAF,CAAU,GAAV,EAAc,KAAd,CAAP;AAA4B,GAA9C,CAAF,CAAkD,OAAOvc,EAAEyC,IAAF,CAAO,GAAP,CAAP;AAAmB,CAAxR,CAAyRmyB,KAAKiF,iBAAL,GAAuB,UAASp6B,CAAT,EAAWU,CAAX,EAAa;AAAC,MAAID,IAAEyiB,OAAN,CAAc,IAAIrjB,IAAEY,EAAE8iB,IAAR,CAAa,IAAG7iB,MAAIjB,SAAP,EAAiB;AAACiB,QAAE,CAAF;AAAI,OAAGV,EAAEmD,MAAF,CAASzC,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,UAAK,oCAAL;AAA0C,OAAId,IAAEa,EAAEijB,WAAF,CAAc1jB,CAAd,EAAgBU,CAAhB,CAAN,CAAyB,IAAGd,EAAEe,MAAF,KAAW,CAAX,IAAcX,EAAEmD,MAAF,CAASvD,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAApC,EAAyC;AAAC;AAAqC,OAAIS,IAAER,EAAEG,CAAF,EAAIJ,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIE,IAAEgY,KAAKkF,IAAL,CAAUC,QAAV,CAAmB8B,WAAnB,CAA+B1e,CAA/B,CAAN,CAAwC,IAAIC,IAAEwX,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmBgY,SAAnB,CAA6Bv6B,CAA7B,CAAN,CAAsC,IAAIgB,IAAEjB,EAAEG,CAAF,EAAIJ,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIW,IAAE4X,UAAUrX,CAAV,CAAN,CAAmB,OAAOR,IAAE,GAAF,GAAMC,CAAb;AAAe,CAAjZ,CAAkZ40B,KAAKC,uBAAL,GAA6B,UAAS/0B,CAAT,EAAW;AAAC,MAAIS,IAAE,IAAIq0B,IAAJ,EAAN,CAAiBr0B,EAAE01B,WAAF,CAAcn2B,CAAd,EAAiB,OAAOS,EAAEu3B,YAAF,EAAP;AAAwB,CAAnG,CAAoGlD,KAAKE,uBAAL,GAA6B,UAASh1B,CAAT,EAAW;AAAC,MAAIS,IAAE,IAAIq0B,IAAJ,EAAN,CAAiBr0B,EAAEm5B,WAAF,CAAc55B,CAAd,EAAiB,OAAOS,EAAEu3B,YAAF,EAAP;AAAwB,CAAnG,CAAoGlD,KAAKmF,6BAAL,GAAmC,UAAS/5B,CAAT,EAAW;AAAC,MAAID,IAAE4iB,OAAN,CAAc,IAAItjB,IAAEU,EAAEwjB,UAAR,CAAmB,IAAIzjB,IAAE,EAAN,CAAS,IAAIS,CAAJ,EAAMhB,CAAN,EAAQE,CAAR,CAAUK,EAAE8zB,QAAF,GAAW,IAAX,CAAgBrzB,IAAE,IAAIq0B,IAAJ,EAAF,CAAar0B,EAAEm5B,WAAF,CAAc15B,CAAd,EAAiBT,IAAEgB,EAAE21B,eAAF,EAAF,CAAsBp2B,EAAEwyB,MAAF,GAASjzB,EAAEE,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,EAAgBqD,MAAhB,CAAuB,CAAvB,CAAT,CAAmC9C,EAAE+zB,MAAF,GAASx0B,EAAEE,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAT,CAA2B,IAAGO,EAAE+zB,MAAF,KAAW,gBAAd,EAA+B;AAAC/zB,MAAE8zB,QAAF,GAAWv0B,EAAEE,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAX;AAA6B,UAAOO,CAAP;AAAS,CAA3S,CAA4S80B,KAAK+D,aAAL,GAAmB,CAAC,kBAAD,EAAoB,gBAApB,EAAqC,iBAArC,EAAuD,kBAAvD,EAA0E,cAA1E,EAAyF,aAAzF,EAAuG,SAAvG,EAAiH,cAAjH,EAAgI,cAAhI,CAAnB;AACvqS,IAAG,OAAOphB,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UAmE3BA,IAnE2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKyiB,GAAZ,IAAiB,WAAjB,IAA8B,CAACziB,KAAKyiB,GAAvC,EAA2C;AAACziB,OAAKyiB,GAAL,GAAS,EAAT;AAAY,MAAKA,GAAL,CAASC,GAAT,GAAa,YAAU;AAAC,MAAIn6B,IAAEyX,IAAN;AAAA,MAAWhX,IAAET,EAAEk6B,GAAF,CAAMC,GAAnB;AAAA,MAAuBj6B,IAAEO,EAAE25B,gBAA3B,CAA4C,KAAKC,QAAL,GAAc,UAAS96B,CAAT,EAAWa,CAAX,EAAa;AAAC,QAAI,KAAKk6B,SAAL,KAAiBl7B,SAAlB,KAA+BgB,KAAI,KAAKk6B,SAAL,CAAeC,OAAf,KAAyBn7B,SAA5D,CAAH,EAA2E;AAAC;AAAO,SAAIiB,IAAEd,EAAEid,KAAF,CAAQ,6BAAR,CAAN,CAA6C,IAAGnc,KAAG,IAAN,EAAW;AAAC,YAAK,yDAAL;AAA+D,SAAIG,IAAEH,EAAE,CAAF,CAAN,CAAW,IAAIJ,IAAEI,EAAE,CAAF,CAAN,CAAW,IAAIE,IAAEF,EAAE,CAAF,CAAN,CAAW,IAAIQ,IAAEL,IAAE,GAAF,GAAMP,CAAZ,CAAc,KAAKq6B,SAAL,GAAe,EAAf,CAAkB,KAAKA,SAAL,CAAeE,QAAf,GAAwBh6B,CAAxB,CAA0B,KAAK85B,SAAL,CAAeG,WAAf,GAA2Bx6B,CAA3B,CAA6B,KAAKq6B,SAAL,CAAeI,UAAf,GAA0Bn6B,CAA1B,CAA4B,KAAK+5B,SAAL,CAAeK,EAAf,GAAkB95B,CAAlB,CAAoB,IAAG,CAACT,CAAJ,EAAM;AAAC,UAAIZ,IAAEslB,UAAUvkB,CAAV,CAAN,CAAmB,IAAId,IAAE0X,YAAY3X,CAAZ,EAAc,EAAd,CAAN,CAAwB,KAAK86B,SAAL,CAAeC,OAAf,GAAuB/6B,CAAvB,CAAyB,KAAK86B,SAAL,CAAeM,QAAf,GAAwBn7B,CAAxB;AAA0B,SAAIE,IAAEqlB,WAAWxkB,CAAX,CAAN,CAAoB,IAAIgC,IAAEwiB,WAAW/kB,CAAX,CAAN,CAAoB,KAAKq6B,SAAL,CAAeO,KAAf,GAAqBl7B,CAArB,CAAuB,KAAK26B,SAAL,CAAeQ,QAAf,GAAwBt4B,CAAxB,CAA0B,IAAG,CAACtC,EAAEP,CAAF,EAAI,KAAK26B,SAAT,EAAmB,OAAnB,CAAJ,EAAgC;AAAC,YAAK,yCAAuC36B,CAA5C;AAA8C;AAAC,GAA7pB;AAA8pB,CAAluB,CAAmuB8X,KAAKyiB,GAAL,CAASC,GAAT,CAAatM,IAAb,GAAkB,UAASxtB,CAAT,EAAW4D,CAAX,EAAayD,CAAb,EAAeF,CAAf,EAAiB/G,CAAjB,EAAmB;AAAC,MAAIqD,IAAE2T,IAAN;AAAA,MAAWjV,IAAEsB,EAAEo2B,GAAf;AAAA,MAAmBn4B,IAAES,EAAE23B,GAAvB;AAAA,MAA2B56B,IAAEwC,EAAEg5B,kBAA/B;AAAA,MAAkDj6B,IAAEiB,EAAEq4B,gBAAtD;AAAA,MAAuEz6B,IAAEmE,EAAE4S,MAA3E;AAAA,MAAkFlW,IAAEb,EAAEsuB,KAAtF;AAAA,MAA4FltB,IAAEpB,EAAE4sB,GAAhG;AAAA,MAAoGrsB,IAAEP,EAAEwtB,SAAxG;AAAA,MAAkHrrB,IAAEmiB,IAApH,CAAyH,IAAIjiB,CAAJ,EAAM5B,CAAN,EAAQS,CAAR,CAAU,IAAG,OAAOoD,CAAP,IAAU,QAAV,IAAoB,QAAOA,CAAP,yCAAOA,CAAP,MAAU,QAAjC,EAA0C;AAAC,UAAK,6CAA2CA,CAAhD;AAAkD,OAAG,QAAOA,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC7D,QAAE6D,CAAF,CAAIjC,IAAEF,EAAEF,SAAF,CAAYxB,CAAZ,CAAF;AAAiB,OAAG,OAAO6D,CAAP,IAAU,QAAb,EAAsB;AAACjC,QAAEiC,CAAF,CAAI,IAAG,CAACnD,EAAEkB,CAAF,CAAJ,EAAS;AAAC,YAAK,uCAAqCA,CAA1C;AAA4C,SAAEzC,EAAEyC,CAAF,CAAF;AAAO,OAAE0F,CAAF,CAAI,IAAG,QAAOA,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC7G,QAAEiB,EAAEF,SAAF,CAAY8F,CAAZ,CAAF;AAAiB,OAAG,CAACrH,KAAG,EAAH,IAAOA,KAAG,IAAX,KAAkBD,EAAEyqB,GAAF,KAAQzrB,SAA7B,EAAuC;AAACiB,QAAED,EAAEyqB,GAAJ;AAAQ,OAAIxqB,KAAG,EAAH,IAAOA,KAAG,IAAX,IAAkBD,EAAEyqB,GAAF,KAAQzrB,SAA7B,EAAuC;AAACgB,MAAEyqB,GAAF,GAAMxqB,CAAN,CAAQ2B,IAAEF,EAAEF,SAAF,CAAYxB,CAAZ,CAAF;AAAiB,OAAGC,MAAID,EAAEyqB,GAAT,EAAa;AAAC,UAAK,wCAAsCxqB,CAAtC,GAAwC,IAAxC,GAA6CD,EAAEyqB,GAApD;AAAwD,OAAI3oB,IAAE,IAAN,CAAW,IAAGH,EAAEi5B,aAAF,CAAgB36B,CAAhB,MAAqBjB,SAAxB,EAAkC;AAAC,UAAK,2BAAyBiB,CAA9B;AAAgC,GAAnE,MAAuE;AAAC6B,QAAEH,EAAEi5B,aAAF,CAAgB36B,CAAhB,CAAF;AAAqB,OAAIJ,IAAE8kB,WAAW/iB,CAAX,CAAN,CAAoB,IAAIzB,IAAEwkB,WAAWlkB,CAAX,CAAN,CAAoB,IAAIb,IAAEC,IAAE,GAAF,GAAMM,CAAZ,CAAc,IAAIwD,IAAE,EAAN,CAAS,IAAG7B,EAAEY,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,QAAG0E,MAAIpI,SAAP,EAAiB;AAAC,YAAK,wCAAL;AAA8C,SAAII,IAAE,IAAIuB,CAAJ,CAAM,EAAC8pB,KAAI3oB,CAAL,EAAO8oB,MAAK,UAAZ,EAAuB0B,MAAKllB,CAA5B,EAAN,CAAN,CAA4ChI,EAAEosB,YAAF,CAAe5rB,CAAf,EAAkB+D,IAAEvE,EAAEmtB,OAAF,EAAF;AAAc,GAAtK,MAA0K;AAAC,QAAGzqB,EAAEyD,OAAF,CAAU,WAAV,KAAwB,CAAC,CAA5B,EAA8B;AAAC,UAAIlG,IAAE,IAAIS,CAAJ,CAAM,EAAC2qB,KAAI3oB,CAAL,EAAN,CAAN,CAAqBzC,EAAEyB,IAAF,CAAOsG,CAAP,EAAS/G,CAAT,EAAYhB,EAAEmsB,YAAF,CAAe5rB,CAAf,EAAkBi7B,WAASx7B,EAAEouB,IAAF,EAAT,CAAkB9pB,IAAE0T,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBuD,kBAAlB,CAAqCyJ,QAArC,CAAF;AAAiD,KAArJ,MAAyJ;AAAC,UAAG/4B,KAAG,MAAN,EAAa;AAAC,YAAIzC,IAAE,IAAIS,CAAJ,CAAM,EAAC2qB,KAAI3oB,CAAL,EAAN,CAAN,CAAqBzC,EAAEyB,IAAF,CAAOsG,CAAP,EAAS/G,CAAT,EAAYhB,EAAEmsB,YAAF,CAAe5rB,CAAf,EAAkB+D,IAAEtE,EAAEouB,IAAF,EAAF;AAAW;AAAC;AAAC,OAAI3pB,IAAE2gB,UAAU9gB,CAAV,CAAN,CAAmB,OAAO/D,IAAE,GAAF,GAAMkE,CAAb;AAAe,CAAzsC,CAA0sCuT,KAAKyiB,GAAL,CAASC,GAAT,CAAa1L,MAAb,GAAoB,UAAS3qB,CAAT,EAAW8D,CAAX,EAAa/G,CAAb,EAAe;AAAC,MAAIkD,IAAE0T,IAAN;AAAA,MAAW1V,IAAEgC,EAAEm2B,GAAf;AAAA,MAAmBp4B,IAAEC,EAAEo4B,GAAvB;AAAA,MAA2B95B,IAAEyB,EAAEi5B,kBAA/B;AAAA,MAAkD96B,IAAE8D,EAAE2S,MAAtD;AAAA,MAA6D5V,IAAEb,EAAEguB,KAAjE;AAAA,MAAuEjsB,IAAE/B,EAAEssB,GAA3E;AAAA,MAA+E5sB,IAAEM,EAAEktB,SAAnF;AAAA,MAA6F3qB,CAA7F,CAA+F,IAAG,QAAOyV,MAAP,yCAAOA,MAAP,OAAgB7Y,SAAnB,EAA6B;AAACoD,QAAEyV,MAAF;AAAS,OAAIvQ,IAAE5D,EAAE8a,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAGlX,EAAEpH,MAAF,KAAW,CAAd,EAAgB;AAAC,WAAO,KAAP;AAAa,OAAIb,IAAEiI,EAAE,CAAF,CAAN,CAAW,IAAIxF,IAAEwF,EAAE,CAAF,CAAN,CAAW,IAAIxH,IAAET,IAAE,GAAF,GAAMyC,CAAZ,CAAc,IAAIuF,IAAEqd,UAAUpd,EAAE,CAAF,CAAV,CAAN,CAAsB,IAAInH,IAAEF,EAAE2kB,WAAWtd,EAAE,CAAF,CAAX,CAAF,CAAN,CAA0B,IAAIlH,IAAE,IAAN,CAAW,IAAIgH,IAAE,IAAN,CAAW,IAAGjH,EAAEsqB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,UAAK,mCAAL;AAAyC,GAA/D,MAAmE;AAACoB,QAAED,EAAEsqB,GAAJ,CAAQrjB,IAAEhH,EAAEsC,MAAF,CAAS,CAAT,EAAW,CAAX,CAAF;AAAgB,OAAGjC,KAAG,IAAH,IAASd,OAAOH,SAAP,CAAiB2B,QAAjB,CAA0Ba,IAA1B,CAA+BvB,CAA/B,MAAoC,gBAA7C,IAA+DA,EAAEP,MAAF,GAAS,CAA3E,EAA6E;AAAC,QAAIN,IAAE,MAAIa,EAAE8B,IAAF,CAAO,GAAP,CAAJ,GAAgB,GAAtB,CAA0B,IAAG3C,EAAE2F,OAAF,CAAU,MAAInF,CAAJ,GAAM,GAAhB,KAAsB,CAAC,CAA1B,EAA4B;AAAC,YAAK,gBAAcA,CAAd,GAAgB,4BAArB;AAAkD;AAAC,OAAGA,KAAG,MAAH,IAAWoH,MAAI,IAAlB,EAAuB;AAAC,UAAK,mCAAL;AAAyC,OAAG,OAAOA,CAAP,IAAU,QAAV,IAAoBA,EAAEjC,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAlD,EAAoD;AAACiC,QAAE4lB,QAAQC,MAAR,CAAe7lB,CAAf,CAAF;AAAoB,OAAGJ,KAAG,IAAH,IAASA,KAAG,IAAf,EAAoB;AAAC,QAAG,EAAEI,aAAapF,CAAf,CAAH,EAAqB;AAAC,YAAK,gDAAL;AAAsD;AAAC,OAAGgF,KAAG,IAAN,EAAW;AAAC,QAAG,EAAEI,aAAa9G,CAAf,CAAH,EAAqB;AAAC,YAAK,uCAAL;AAA6C;AAAC,OAAGN,KAAG,MAAN,EAAa,CAAE,KAAI0D,IAAE,IAAN,CAAW,IAAGpC,EAAEk5B,aAAF,CAAgBz6B,EAAEsqB,GAAlB,MAAyBzrB,SAA5B,EAAsC;AAAC,UAAK,2BAAyBoB,CAA9B;AAAgC,GAAvE,MAA2E;AAAC0D,QAAEpC,EAAEk5B,aAAF,CAAgBx6B,CAAhB,CAAF;AAAqB,OAAG0D,KAAG,MAAN,EAAa;AAAC,UAAK,eAAL;AAAqB,GAAnC,MAAuC;AAAC,QAAGA,EAAEpB,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,UAAI/B,IAAE,IAAN,CAAW,IAAG6G,MAAIxI,SAAP,EAAiB;AAAC,cAAK,6CAAL;AAAmD,WAAIgB,IAAE,IAAI4B,CAAJ,CAAM,EAAC6oB,KAAI3mB,CAAL,EAAOwoB,MAAK9kB,CAAZ,EAAN,CAAN,CAA4BxH,EAAEwrB,YAAF,CAAe1rB,CAAf,EAAkBa,IAAEX,EAAEusB,OAAF,EAAF,CAAc,OAAOllB,KAAG1G,CAAV;AAAY,KAAlL,MAAsL;AAAC,UAAGmD,EAAEyB,OAAF,CAAU,WAAV,KAAwB,CAAC,CAA5B,EAA8B;AAAC,YAAInG,IAAE,IAAN,CAAW,IAAG;AAACA,cAAEsB,EAAE2wB,kBAAF,CAAqBhqB,CAArB,CAAF;AAA0B,SAA9B,CAA8B,OAAMxD,CAAN,EAAQ;AAAC,iBAAO,KAAP;AAAa,aAAI1E,IAAE,IAAII,CAAJ,CAAM,EAACkrB,KAAI3mB,CAAL,EAAN,CAAN,CAAqB3E,EAAE2B,IAAF,CAAO0G,CAAP,EAAUrI,EAAEqsB,YAAF,CAAe1rB,CAAf,EAAkB,OAAOX,EAAEkvB,MAAF,CAASjvB,CAAT,CAAP;AAAmB,OAAlK,MAAsK;AAAC,YAAID,IAAE,IAAII,CAAJ,CAAM,EAACkrB,KAAI3mB,CAAL,EAAN,CAAN,CAAqB3E,EAAE2B,IAAF,CAAO0G,CAAP,EAAUrI,EAAEqsB,YAAF,CAAe1rB,CAAf,EAAkB,OAAOX,EAAEkvB,MAAF,CAAShnB,CAAT,CAAP;AAAmB;AAAC;AAAC;AAAC,CAA79C,CAA89CgQ,KAAKyiB,GAAL,CAASC,GAAT,CAAav3B,KAAb,GAAmB,UAASrD,CAAT,EAAW;AAAC,MAAIW,IAAEX,EAAEqf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAI5e,IAAE,EAAN,CAAS,IAAIP,CAAJ,EAAMQ,CAAN,EAAQN,CAAR,CAAU,IAAGO,EAAEI,MAAF,IAAU,CAAV,IAAaJ,EAAEI,MAAF,IAAU,CAA1B,EAA4B;AAAC,UAAK,uDAAL;AAA6D,OAAEJ,EAAE,CAAF,CAAF,CAAOD,IAAEC,EAAE,CAAF,CAAF,CAAO,IAAGA,EAAEI,MAAF,IAAU,CAAb,EAAe;AAACX,QAAEO,EAAE,CAAF,CAAF;AAAO,KAAEg7B,SAAF,GAAYzjB,KAAKyiB,GAAL,CAASC,GAAT,CAAaY,kBAAb,CAAgC/V,WAAWvlB,CAAX,CAAhC,CAAZ,CAA2DO,EAAEm7B,UAAF,GAAa1jB,KAAKyiB,GAAL,CAASC,GAAT,CAAaY,kBAAb,CAAgC/V,WAAW/kB,CAAX,CAAhC,CAAb,CAA4DD,EAAEo7B,QAAF,GAAWnX,KAAKriB,SAAL,CAAe5B,EAAEk7B,SAAjB,EAA2B,IAA3B,EAAgC,IAAhC,CAAX,CAAiD,IAAGl7B,EAAEm7B,UAAF,IAAc,IAAjB,EAAsB;AAACn7B,MAAEq7B,SAAF,GAAYrW,WAAW/kB,CAAX,CAAZ;AAA0B,GAAjD,MAAqD;AAACD,MAAEq7B,SAAF,GAAYpX,KAAKriB,SAAL,CAAe5B,EAAEm7B,UAAjB,EAA4B,IAA5B,EAAiC,IAAjC,CAAZ;AAAmD,OAAGx7B,MAAIP,SAAP,EAAiB;AAACY,MAAEs7B,MAAF,GAASxW,UAAUnlB,CAAV,CAAT;AAAsB,UAAOK,CAAP;AAAS,CAAtgB,CAAugByX,KAAKyiB,GAAL,CAASC,GAAT,CAAaoB,SAAb,GAAuB,UAASt7B,CAAT,EAAWM,CAAX,EAAa2B,CAAb,EAAe;AAAC,MAAIvC,IAAE8X,IAAN;AAAA,MAAWrX,IAAET,EAAEu6B,GAAf;AAAA,MAAmBn5B,IAAEX,EAAE+5B,GAAvB;AAAA,MAA2Bt5B,IAAEE,EAAEg6B,kBAA/B;AAAA,MAAkDj6B,IAAEC,EAAEy6B,OAAtD;AAAA,MAA8D/7B,IAAEsB,EAAE06B,aAAlE,CAAgF,IAAIj7B,IAAEP,EAAE2e,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAI1e,IAAEM,EAAE,CAAF,CAAN,CAAW,IAAIH,IAAEG,EAAE,CAAF,CAAN,CAAW,IAAIuB,IAAE7B,IAAE,GAAF,GAAMG,CAAZ,CAAc,IAAImC,IAAEsiB,UAAUtkB,EAAE,CAAF,CAAV,CAAN,CAAsB,IAAIhB,IAAEqB,EAAEmkB,WAAW9kB,CAAX,CAAF,CAAN,CAAuB,IAAIX,IAAEsB,EAAEmkB,WAAW3kB,CAAX,CAAF,CAAN,CAAuB,IAAGb,EAAEqrB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAO,KAAP;AAAa,OAAG8C,EAAE2oB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,UAAK,oCAAL;AAA0C,OAAG,CAAC0B,EAAEtB,EAAEqrB,GAAJ,EAAQ3oB,EAAE2oB,GAAV,CAAJ,EAAmB;AAAC,WAAO,KAAP;AAAa,OAAGtrB,EAAEm8B,GAAF,KAAQt8B,SAAR,IAAmB,QAAO8C,EAAEw5B,GAAT,MAAe,QAArC,EAA8C;AAAC,QAAG,CAAC56B,EAAEvB,EAAEm8B,GAAJ,EAAQx5B,EAAEw5B,GAAV,CAAJ,EAAmB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGn8B,EAAEo8B,GAAF,KAAQv8B,SAAR,IAAmB,QAAO8C,EAAEy5B,GAAT,MAAe,QAArC,EAA8C;AAAC,QAAG,CAAC76B,EAAEvB,EAAEo8B,GAAJ,EAAQz5B,EAAEy5B,GAAV,CAAJ,EAAmB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGp8B,EAAEq8B,GAAF,KAAQx8B,SAAR,IAAmB,QAAO8C,EAAE05B,GAAT,MAAe,QAArC,EAA8C;AAAC,QAAG,OAAOr8B,EAAEq8B,GAAT,IAAc,QAAjB,EAA0B;AAAC,UAAG,CAAC96B,EAAEvB,EAAEq8B,GAAJ,EAAQ15B,EAAE05B,GAAV,CAAJ,EAAmB;AAAC,eAAO,KAAP;AAAa;AAAC,KAA7D,MAAiE;AAAC,UAAG,QAAOr8B,EAAEq8B,GAAT,KAAc,QAAjB,EAA0B;AAAC,YAAG,CAACn8B,EAAEF,EAAEq8B,GAAJ,EAAQ15B,EAAE05B,GAAV,CAAJ,EAAmB;AAAC,iBAAO,KAAP;AAAa;AAAC;AAAC;AAAC,OAAI57B,IAAEI,EAAEy7B,OAAF,CAAUC,MAAV,EAAN,CAAyB,IAAG55B,EAAE65B,QAAF,KAAa38B,SAAb,IAAwB,OAAO8C,EAAE65B,QAAT,KAAoB,QAA/C,EAAwD;AAAC/7B,QAAEkC,EAAE65B,QAAJ;AAAa,OAAG75B,EAAE85B,WAAF,KAAgB58B,SAAhB,IAA2B,OAAO8C,EAAE85B,WAAT,KAAuB,QAArD,EAA8D;AAAC95B,MAAE85B,WAAF,GAAc,CAAd;AAAgB,OAAGz8B,EAAEoP,GAAF,KAAQvP,SAAR,IAAmB,OAAOG,EAAEoP,GAAT,IAAc,QAApC,EAA6C;AAAC,QAAGpP,EAAEoP,GAAF,GAAMzM,EAAE85B,WAAR,GAAoBh8B,CAAvB,EAAyB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGT,EAAE08B,GAAF,KAAQ78B,SAAR,IAAmB,OAAOG,EAAE08B,GAAT,IAAc,QAApC,EAA6C;AAAC,QAAGj8B,IAAET,EAAE08B,GAAF,GAAM/5B,EAAE85B,WAAb,EAAyB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGz8B,EAAE28B,GAAF,KAAQ98B,SAAR,IAAmB,OAAOG,EAAE28B,GAAT,IAAc,QAApC,EAA6C;AAAC,QAAGl8B,IAAET,EAAE28B,GAAF,GAAMh6B,EAAE85B,WAAb,EAAyB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGz8B,EAAE48B,GAAF,KAAQ/8B,SAAR,IAAmB8C,EAAEi6B,GAAF,KAAQ/8B,SAA9B,EAAwC;AAAC,QAAGG,EAAE48B,GAAF,KAAQj6B,EAAEi6B,GAAb,EAAiB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAG,CAACp7B,EAAE0tB,MAAF,CAASxuB,CAAT,EAAWM,CAAX,EAAa2B,EAAE2oB,GAAf,CAAJ,EAAwB;AAAC,WAAO,KAAP;AAAa,UAAO,IAAP;AAAY,CAAnvC,CAAovCpT,KAAKyiB,GAAL,CAASC,GAAT,CAAasB,aAAb,GAA2B,UAASz7B,CAAT,EAAWS,CAAX,EAAa;AAAC,MAAIP,IAAEuX,KAAKyiB,GAAL,CAASC,GAAT,CAAaqB,OAAnB,CAA2B,IAAGx7B,MAAI,IAAP,EAAY;AAAC,WAAO,KAAP;AAAa,OAAG,QAAOA,CAAP,yCAAOA,CAAP,OAAW,QAAd,EAAuB;AAAC,WAAO,KAAP;AAAa,OAAG,OAAOA,EAAEM,MAAT,KAAkB,QAArB,EAA8B;AAAC,WAAO,KAAP;AAAa,QAAI,IAAIX,IAAE,CAAV,EAAYA,IAAEK,EAAEM,MAAhB,EAAuBX,GAAvB,EAA2B;AAAC,QAAG,CAACO,EAAEF,EAAEL,CAAF,CAAF,EAAOc,CAAP,CAAJ,EAAc;AAAC,aAAO,KAAP;AAAa;AAAC,UAAO,IAAP;AAAY,CAApP,CAAqPgX,KAAKyiB,GAAL,CAASC,GAAT,CAAaqB,OAAb,GAAqB,UAAS77B,CAAT,EAAWK,CAAX,EAAa;AAAC,MAAGA,MAAI,IAAP,EAAY;AAAC,WAAO,KAAP;AAAa,OAAG,QAAOA,CAAP,yCAAOA,CAAP,OAAW,QAAd,EAAuB;AAAC,WAAO,KAAP;AAAa,OAAG,OAAOA,EAAEM,MAAT,KAAkB,QAArB,EAA8B;AAAC,WAAO,KAAP;AAAa,QAAI,IAAIJ,IAAE,CAAV,EAAYA,IAAEF,EAAEM,MAAhB,EAAuBJ,GAAvB,EAA2B;AAAC,QAAGF,EAAEE,CAAF,KAAMP,CAAT,EAAW;AAAC,aAAO,IAAP;AAAY;AAAC,UAAO,KAAP;AAAa,CAAhN,CAAiN8X,KAAKyiB,GAAL,CAASC,GAAT,CAAaa,aAAb,GAA2B,EAACoB,OAAM,YAAP,EAAoBC,OAAM,YAA1B,EAAuCC,OAAM,YAA7C,EAA0DC,OAAM,eAAhE,EAAgFC,OAAM,eAAtF,EAAsGC,OAAM,eAA5G,EAA4HC,OAAM,iBAAlI,EAAoJC,OAAM,iBAA1J,EAA4KC,OAAM,sBAAlL,EAAyMC,OAAM,sBAA/M,EAAsOC,OAAM,sBAA5O,EAAmQC,MAAK,MAAxQ,EAA3B,CAA4StlB,KAAKyiB,GAAL,CAASC,GAAT,CAAaC,gBAAb,GAA8B,UAASl6B,CAAT,EAAWF,CAAX,EAAaL,CAAb,EAAe;AAAC,MAAIM,IAAE,IAAN,CAAW,IAAG;AAACA,QAAEqc,UAAUpc,CAAV,CAAF,CAAe,IAAG,QAAOD,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC,aAAO,CAAP;AAAS,SAAGA,EAAEJ,WAAF,KAAgBmJ,KAAnB,EAAyB;AAAC,aAAO,CAAP;AAAS,SAAGhJ,CAAH,EAAK;AAACA,QAAEL,CAAF,IAAKM,CAAL;AAAO,YAAO,CAAP;AAAS,GAA5G,CAA4G,OAAMQ,CAAN,EAAQ;AAAC,WAAO,CAAP;AAAS;AAAC,CAAxL,CAAyLgX,KAAKyiB,GAAL,CAASC,GAAT,CAAaY,kBAAb,GAAgC,UAAS/6B,CAAT,EAAW;AAAC,MAAIE,IAAE,IAAN,CAAW,IAAG;AAACA,QAAEoc,UAAUtc,CAAV,CAAF,CAAe,IAAG,QAAOE,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC,aAAO,IAAP;AAAY,SAAGA,EAAEL,WAAF,KAAgBmJ,KAAnB,EAAyB;AAAC,aAAO,IAAP;AAAY,YAAO9I,CAAP;AAAS,GAArG,CAAqG,OAAMO,CAAN,EAAQ;AAAC,WAAO,IAAP;AAAY;AAAC,CAAlL,CAAmLgX,KAAKyiB,GAAL,CAASC,GAAT,CAAa6C,+BAAb,GAA6C,UAASh9B,CAAT,EAAW;AAAC,MAAIS,IAAET,EAAEwc,KAAF,CAAQ,yBAAR,CAAN,CAAyC,IAAG/b,KAAG,IAAN,EAAW;AAAC,UAAK,yDAAL;AAA+D,UAAOA,EAAE,CAAF,CAAP;AAAY,CAAzL,CAA0LgX,KAAKyiB,GAAL,CAASC,GAAT,CAAa8C,gBAAb,GAA8B,UAASt9B,CAAT,EAAW;AAAC,MAAGA,EAAE20B,GAAF,KAAQ,KAAR,IAAe30B,EAAE20B,GAAF,KAAQ,IAAvB,IAA6B30B,EAAE20B,GAAF,KAAQ,KAAxC,EAA8C;AAAC,UAAK,yCAAL;AAA+C,OAAI7zB,IAAE,GAAN,CAAU,IAAGd,EAAE20B,GAAF,KAAQ,KAAX,EAAiB;AAAC,QAAG,OAAO30B,EAAEkB,CAAT,IAAY,QAAZ,IAAsB,OAAOlB,EAAEM,CAAT,IAAY,QAArC,EAA8C;AAAC,YAAK,iCAAL;AAAuC,UAAG,UAAQN,EAAEM,CAAV,GAAY,IAAf,CAAoBQ,KAAG,YAAUd,EAAE20B,GAAZ,GAAgB,IAAnB,CAAwB7zB,KAAG,UAAQd,EAAEkB,CAAV,GAAY,IAAf;AAAoB,GAAxK,MAA4K;AAAC,QAAGlB,EAAE20B,GAAF,KAAQ,IAAX,EAAgB;AAAC,UAAG,OAAO30B,EAAEk1B,GAAT,IAAc,QAAd,IAAwB,OAAOl1B,EAAEoE,CAAT,IAAY,QAApC,IAA8C,OAAOpE,EAAE+H,CAAT,IAAY,QAA7D,EAAsE;AAAC,cAAK,qCAAL;AAA2C,YAAG,YAAU/H,EAAEk1B,GAAZ,GAAgB,IAAnB,CAAwBp0B,KAAG,YAAUd,EAAE20B,GAAZ,GAAgB,IAAnB,CAAwB7zB,KAAG,UAAQd,EAAEoE,CAAV,GAAY,IAAf,CAAoBtD,KAAG,UAAQd,EAAE+H,CAAV,GAAY,IAAf;AAAoB,KAA3N,MAA+N;AAAC,UAAG/H,EAAE20B,GAAF,KAAQ,KAAX,EAAiB;AAAC,YAAG,OAAO30B,EAAEa,CAAT,IAAY,QAAf,EAAwB;AAAC,gBAAK,sCAAL;AAA4C,cAAG,YAAUb,EAAE20B,GAAZ,GAAgB,IAAnB,CAAwB7zB,KAAG,UAAQd,EAAEa,CAAV,GAAY,IAAf;AAAoB;AAAC;AAAC,OAAIR,IAAEgY,UAAUvX,CAAV,CAAN,CAAmB,IAAIP,IAAEuX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyB/X,CAAzB,EAA2B,QAA3B,CAAN,CAA2C,IAAIC,IAAE4kB,UAAU3kB,CAAV,CAAN,CAAmB,OAAOD,CAAP;AAAS,CAA9vB,CAA+vBwX,KAAKyiB,GAAL,CAAS2B,OAAT,GAAiB,EAAjB,CAAoBpkB,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBqB,GAAjB,GAAqB,UAASh9B,CAAT,EAAW;AAAC,MAAIF,IAAEyX,KAAKyiB,GAAL,CAAS2B,OAAf;AAAA,MAAuBl8B,IAAEK,EAAE87B,MAA3B;AAAA,MAAkCr7B,IAAET,EAAEm9B,OAAtC,CAA8C,IAAGj9B,KAAG,KAAN,EAAY;AAAC,WAAOP,GAAP;AAAW,GAAxB,MAA4B;AAAC,QAAGO,KAAG,aAAN,EAAoB;AAAC,aAAOP,MAAI,KAAG,EAAd;AAAiB,KAAtC,MAA0C;AAAC,UAAGO,KAAG,YAAN,EAAmB;AAAC,eAAOP,MAAI,KAAG,EAAH,GAAM,EAAjB;AAAoB,OAAxC,MAA4C;AAAC,YAAGO,KAAG,cAAN,EAAqB;AAAC,iBAAOP,MAAI,KAAG,EAAH,GAAM,EAAN,GAAS,EAApB;AAAuB,SAA7C,MAAiD;AAAC,cAAGO,KAAG,aAAN,EAAoB;AAAC,mBAAOP,MAAI,KAAG,EAAH,GAAM,EAAN,GAAS,GAApB;AAAwB,WAA7C,MAAiD;AAAC,gBAAGO,EAAEsc,KAAF,CAAQ,IAAR,CAAH,EAAiB;AAAC,qBAAO/b,EAAEP,CAAF,CAAP;AAAY,aAA9B,MAAkC;AAAC,kBAAGA,EAAEsc,KAAF,CAAQ,UAAR,CAAH,EAAuB;AAAC,uBAAO3Z,SAAS3C,CAAT,CAAP;AAAmB;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC,SAAK,yBAAuBA,CAA5B;AAA8B,CAA1Z,CAA2ZuX,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBsB,OAAjB,GAAyB,UAAS18B,CAAT,EAAW;AAAC,SAAO0lB,UAAU1lB,CAAV,CAAP;AAAoB,CAAzD,CAA0DgX,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBC,MAAjB,GAAwB,YAAU;AAAC,MAAIr7B,IAAE,CAAC,EAAE,IAAI+V,IAAJ,KAAW,IAAb,CAAP,CAA0B,OAAO/V,CAAP;AAAS,CAAtE,CAAuEgX,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBuB,iBAAjB,GAAmC,UAAS38B,CAAT,EAAW;AAAC,MAAIT,IAAE,IAAIwW,IAAJ,CAAS/V,IAAE,IAAX,CAAN,CAAuB,OAAOT,EAAEq9B,WAAF,EAAP;AAAuB,CAA7F,CAA8F5lB,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiByB,YAAjB,GAA8B,UAASr9B,CAAT,EAAW;AAAC,MAAII,IAAE,IAAImW,IAAJ,CAASvW,IAAE,IAAX,CAAN;AAAA,MAAuBT,IAAE,CAAC,SAAOa,EAAEimB,cAAF,EAAR,EAA4BjkB,KAA5B,CAAkC,CAAC,CAAnC,CAAzB;AAAA,MAA+D9C,IAAE,CAAC,QAAMc,EAAEkmB,WAAF,KAAgB,CAAtB,CAAD,EAA2BlkB,KAA3B,CAAiC,CAAC,CAAlC,CAAjE;AAAA,MAAsGrC,IAAE,CAAC,OAAKK,EAAEmmB,UAAF,EAAN,EAAsBnkB,KAAtB,CAA4B,CAAC,CAA7B,CAAxG;AAAA,MAAwI5B,IAAE,CAAC,OAAKJ,EAAEomB,WAAF,EAAN,EAAuBpkB,KAAvB,CAA6B,CAAC,CAA9B,CAA1I;AAAA,MAA2KnC,IAAE,CAAC,OAAKG,EAAEqmB,aAAF,EAAN,EAAyBrkB,KAAzB,CAA+B,CAAC,CAAhC,CAA7K;AAAA,MAAgN5C,IAAE,CAAC,OAAKY,EAAEsmB,aAAF,EAAN,EAAyBtkB,KAAzB,CAA+B,CAAC,CAAhC,CAAlN,CAAqP,OAAO7C,IAAED,CAAF,GAAIS,CAAJ,GAAMS,CAAN,GAAQP,CAAR,GAAUT,CAAV,GAAY,GAAnB;AAAuB,CAAtT;QACt4PyX,Y,GAAAA,Y;QACAX,a,GAAAA,a;QAEAnN,U,GAAAA,U;QACA6O,M,GAAAA,M;IACMslB,I,GAAS9lB,KAAKf,M,CAAd6mB,I;;IACAhP,G,GAAQ9W,KAAKf,M,CAAb6X,G;;IACApB,S,GAAc1V,KAAKf,M,CAAnByW,S;;IACAzV,a,GAAmBD,KAAKf,M,CAAxBgB,a;;IACA6U,G,GAAQ9U,KAAKf,M,CAAb6V,G;;IACA4C,M,GAAY1X,KAAKf,M,CAAjByY,M;;QACN3B,O,GAAAA,O;QACA3K,O,GAAAA,O;QACAiS,I,GAAAA,I;QACAp0B,Q,GAAAA,Q;;AAET;;QACSmI,Q,GAAAA,Q;QACAE,O,GAAAA,O;;AAET;;QACSsb,K,GAAAA,K;QACAC,K,GAAAA,K;QACAC,O,GAAAA,O;QACA5D,M,GAAAA,M;QACA6D,M,GAAAA,M;QACAC,O,GAAAA,O;QACAE,O,GAAAA,O;QACAD,S,GAAAA,S;QACAE,S,GAAAA,S;QACAjc,O,GAAAA,O;QACAkc,S,GAAAA,S;QACAC,S,GAAAA,S;QACAC,U,GAAAA,U;QACAC,U,GAAAA,U;QACAK,S,GAAAA,S;QACAC,S,GAAAA,S;QACA7F,S,GAAAA,S;QACAsE,S,GAAAA,S;QACAjM,S,GAAAA,S;QACAE,S,GAAAA,S;QACAuN,Q,GAAAA,Q;QACAC,U,GAAAA,U;QACAC,U,GAAAA,U;QACAzI,Q,GAAAA,Q;QACA0I,Q,GAAAA,Q;QACAC,gB,GAAAA,gB;QACAI,gB,GAAAA,gB;QACAG,U,GAAAA,U;QACAC,S,GAAAA,S;QACAC,U,GAAAA,U;QACAC,U,GAAAA,U;QACAnB,W,GAAAA,W;QACAE,W,GAAAA,W;QACAyB,S,GAAAA,S;QACAE,S,GAAAA,S;QACAC,O,GAAAA,O;QACAC,O,GAAAA,O;QACA9B,qB,GAAAA,qB;QACA+B,c,GAAAA,c;QACAC,a,GAAAA,a;QACAK,W,GAAAA,W;QACAC,c,GAAAA,c;QACAE,U,GAAAA,U;;AAET;;QACSlQ,I,GAAAA,I;;AACT,IAAM+lB,UAAW/lB,KAAKf,MAAtB;QACoBA,M,GAAX8mB,O;YACe/lB,I;IAATkF,I,SAAAA,I;;aACQlF,I;IAARyiB,G,UAAAA,G;;aACSziB,I;IAATpY,I,UAAAA,I;;;;;;;;;;;;;;AC1Lf,8CAAa;;AAEb,mBAAO,CAAC,oDAAc;;AAEtB,mBAAO,CAAC,8GAA6B;;AAErC,mBAAO,CAAC,4EAA0B;;AAElC;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;AAEA;AACA;;AAEA;AACA;AACA,CAAC,E;;;;;;;;;;;;AC3BD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,gBAAgB;AAChB;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,cAAc;AACd,KAAK;AACL,cAAc;AACd;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,yDAAyD;AACzD;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,YAAY;AACZ;;AAEA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA,WAAW;AACX;AACA,WAAW;AACX;;AAEA;AACA;AACA,wCAAwC,WAAW;AACnD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;;AAEA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA,SAAS;AACT;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA,2BAA2B;AAC3B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,SAAS;AACT;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA,SAAS;AACT;AACA;AACA;AACA;;AAEA;;AAEA,SAAS;AACT;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,oCAAoC,cAAc;AAClD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,KAAK;AACL;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA,iCAAiC,kBAAkB;AACnD;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,iBAAiB;;AAEjB;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,wBAAwB,iBAAiB;AACzC;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,YAAY;AACZ;AACA;;AAEA;AACA,YAAY;AACZ;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;;AAEL;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA,KAAK;;AAEL;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA,8CAA8C,QAAQ;AACtD;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA,aAAa;AACb;AACA;;AAEA,WAAW;AACX;AACA;AACA;;AAEA,WAAW;AACX;AACA;AACA;;AAEA,WAAW;AACX;AACA;AACA;AACA;AACA,KAAK;;AAEL;AACA,8CAA8C,QAAQ;AACtD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA,KAAK;;AAEL;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA,OAAO;AACP;AACA;;AAEA;AACA,KAAK;;AAEL;AACA,8CAA8C,QAAQ;AACtD;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;;AAEL;AACA,8CAA8C,QAAQ;AACtD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;;AAEL;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;;AC/tBY;;AAEZ;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,kCAAkC,SAAS;AAC3C;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;;AAEA;AACA;AACA;AACA;;AAEA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,0CAA0C,UAAU;AACpD;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;;;;;;;;;;;;ACtJA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEY;;AAEZ,aAAa,mBAAO,CAAC,oDAAW;AAChC,cAAc,mBAAO,CAAC,gDAAS;AAC/B,cAAc,mBAAO,CAAC,oEAAS;;AAE/B;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,qBAAqB,mDAAmD;AACxE;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,mBAAmB,UAAU;AAC7B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,YAAY;AAC7B;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,0BAA0B;AAC1B;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA,uCAAuC,SAAS;AAChD;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA,eAAe,iBAAiB;AAChC;AACA;AACA;;AAEA;AACA;AACA,aAAa,iBAAiB;AAC9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,gDAAgD,EAAE;AAClD;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,yCAAyC;AACzC;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;;AAEA;AACA;AACA;AACA,wBAAwB,eAAe;AACvC;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA,GAAG;AACH;AACA,wBAAwB,QAAQ;AAChC;AACA,qBAAqB,eAAe;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,YAAY;AAC7B;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;;AAEA;AACA,SAAS;AACT;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,kBAAkB;AACnC;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,mBAAmB,cAAc;AACjC;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,uDAAuD,OAAO;AAC9D;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA,uDAAuD,OAAO;AAC9D;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,kBAAkB;AAClB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,qBAAqB,QAAQ;AAC7B;AACA;AACA,GAAG;AACH;AACA,eAAe,SAAS;AACxB;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA,mBAAmB,SAAS;AAC5B;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,eAAe,iBAAiB;AAChC;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA,iBAAiB,YAAY;AAC7B;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,KAAK;AACL;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,iBAAiB,gBAAgB;AACjC;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,gBAAgB;AACjC;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,iBAAiB,YAAY;AAC7B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;AC5vDA,iBAAiB;;AAEjB;AACA;AACA;;;;;;;;;;;;ACJA,mBAAO,CAAC,8FAAkC;AAC1C,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C;AACA;AACA;AACA;;;;;;;;;;;;ACHA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;AACA;;;;;;;;;;;;ACJA;AACA,kBAAkB,mBAAO,CAAC,sDAAQ;AAClC;AACA,0CAA0C,mBAAO,CAAC,wDAAS,6BAA6B;AACxF;AACA;AACA;;;;;;;;;;;;;ACNa;AACb,SAAS,mBAAO,CAAC,kEAAc;;AAE/B;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACPA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACJA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;;;;;;;;;;;;;ACJA;AACa;AACb,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;;ACzBA;AACa;AACb,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACdA,YAAY,mBAAO,CAAC,4DAAW;;AAE/B;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACNA;AACA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK,YAAY,eAAe;AAChC;AACA,KAAK;AACL;AACA;;;;;;;;;;;;ACtBA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,wFAAyB;AAC3C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,eAAe;AACzB;AACA;AACA;AACA,wCAAwC;AACxC;AACA,8BAA8B;AAC9B,6BAA6B;AAC7B,+BAA+B;AAC/B,mCAAmC;AACnC,SAAS,iCAAiC;AAC1C;AACA;AACA;AACA;AACA;;;;;;;;;;;;AC3CA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,uBAAuB;AACvB;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,QAAQ,sCAAsC;AAC9C;AACA;AACA;AACA;;;;;;;;;;;;AC3BA,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,gEAAa;AACnC,cAAc,mBAAO,CAAC,sDAAQ;;AAE9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACfA;AACA,yBAAyB,mBAAO,CAAC,kGAA8B;;AAE/D;AACA;AACA;;;;;;;;;;;;;ACLa;AACb,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA;;AAEA;AACA;AACA,2BAA2B,SAAS;AACpC;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACxBA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA,2BAA2B,kBAAkB,EAAE;;AAE/C;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACtBA,iBAAiB;;AAEjB;AACA;AACA;;;;;;;;;;;;;ACJa;AACb,SAAS,mBAAO,CAAC,kEAAc;AAC/B,aAAa,mBAAO,CAAC,0EAAkB;AACvC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,YAAY,mBAAO,CAAC,4DAAW;AAC/B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,WAAW,mBAAO,CAAC,kEAAc;AACjC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,cAAc,mBAAO,CAAC,wDAAS;AAC/B,eAAe,mBAAO,CAAC,sFAAwB;AAC/C;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,uBAAuB,OAAO;AAC9B;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,qBAAqB;AACrB,6BAA6B;AAC7B,0BAA0B;AAC1B,0BAA0B;AAC1B,qBAAqB;AACrB;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,8EAA8E,OAAO;AACrF;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,yCAAyC;AACzC,qBAAqB;AACrB,0BAA0B;AAC1B,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;;AAEL;AACA;AACA;AACA;;;;;;;;;;;;AC/IA;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC,WAAW,mBAAO,CAAC,sFAAwB;AAC3C;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACRa;AACb,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,cAAc,mBAAO,CAAC,wDAAS;AAC/B,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,YAAY,mBAAO,CAAC,4DAAW;AAC/B,wBAAwB,mBAAO,CAAC,0EAAkB;AAClD,WAAW,mBAAO,CAAC,sDAAQ;AAC3B,eAAe,mBAAO,CAAC,sFAAwB;AAC/C;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,qBAAqB;AACrB,qBAAqB;AACrB,0BAA0B;AAC1B;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;;;;;;;;;;;;;ACpFa;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,gEAAa;AACpC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,WAAW,mBAAO,CAAC,wDAAS;AAC5B,YAAY,mBAAO,CAAC,4DAAW;AAC/B,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,eAAe,mBAAO,CAAC,kEAAc;AACrC,YAAY,mBAAO,CAAC,0DAAU;AAC9B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD,wBAAwB,mBAAO,CAAC,sFAAwB;;AAExD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA,OAAO;AACP;AACA,OAAO,mCAAmC,gCAAgC,aAAa;AACvF,8BAA8B,mCAAmC,aAAa;AAC9E;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,qDAAqD;AACrD;AACA,kDAAkD,iBAAiB,EAAE;AACrE;AACA,wDAAwD,aAAa,EAAE,EAAE;AACzE;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA;;AAEA;AACA;;;;;;;;;;;;ACpFA,6BAA6B;AAC7B,uCAAuC;;;;;;;;;;;;;ACD1B;AACb,sBAAsB,mBAAO,CAAC,kEAAc;AAC5C,iBAAiB,mBAAO,CAAC,0EAAkB;;AAE3C;AACA;AACA;AACA;;;;;;;;;;;;ACPA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACnBa;AACb;AACA,YAAY,mBAAO,CAAC,0DAAU;AAC9B;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA,CAAC;AACD;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACzBY;AACb,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C;;AAEA;AACA;AACA;AACA;;;;;;;;;;;;ACRA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACJA;AACA,kBAAkB,mBAAO,CAAC,0DAAU;AACpC,iCAAiC,QAAQ,mBAAmB,UAAU,EAAE,EAAE;AAC1E,CAAC;;;;;;;;;;;;ACHD,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,4DAAW;AAClC;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACNA;AACA;AACA;AACA;;;;;;;;;;;;ACHA;AACA,cAAc,mBAAO,CAAC,sEAAgB;AACtC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,UAAU,mBAAO,CAAC,oEAAe;AACjC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACdA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,WAAW,mBAAO,CAAC,wDAAS;AAC5B,eAAe,mBAAO,CAAC,gEAAa;AACpC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,kFAAkF,uBAAuB;AACzG,iEAAiE;AACjE,+DAA+D;AAC/D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,cAAc;AACd,cAAc;AACd,cAAc;AACd,cAAc;AACd,eAAe;AACf,eAAe;AACf,eAAe;AACf,gBAAgB;AAChB;;;;;;;;;;;;AC1CA,YAAY,mBAAO,CAAC,sDAAQ;AAC5B;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA,KAAK,YAAY;AACjB,GAAG;AACH;;;;;;;;;;;;ACXA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;;;;;;;;;;;;ACNa;AACb,mBAAO,CAAC,4EAAmB;AAC3B,eAAe,mBAAO,CAAC,gEAAa;AACpC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,YAAY,mBAAO,CAAC,0DAAU;AAC9B,cAAc,mBAAO,CAAC,8DAAY;AAClC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,iBAAiB,mBAAO,CAAC,sEAAgB;;AAEzC;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,qBAAqB;AACrB;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;AACA;AACA,yBAAyB,4CAA4C;AACrE;AACA;AACA,CAAC;;AAED;AACA;;AAEA;AACA;AACA;AACA,6BAA6B,UAAU;AACvC;AACA,GAAG;;AAEH;AACA;AACA;AACA;AACA,2BAA2B,mBAAmB,aAAa;AAC3D;AACA;AACA;AACA;AACA,6CAA6C,WAAW;AACxD;AACA;AACA;AACA,GAAG;;AAEH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oBAAoB;AACpB;AACA,kBAAkB;AAClB;AACA,gBAAgB;AAChB;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,gCAAgC,qCAAqC;AACrE;AACA;AACA,2BAA2B,gCAAgC;AAC3D;AACA;AACA;;;;;;;;;;;;;AC/Fa;AACb;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACZa;AACb;AACA,cAAc,mBAAO,CAAC,gEAAa;AACnC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,2BAA2B,mBAAO,CAAC,sDAAQ;;AAE3C;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,OAAO;AACP;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;ACtCA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,WAAW,mBAAO,CAAC,kEAAc;AACjC,kBAAkB,mBAAO,CAAC,0EAAkB;AAC5C,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,8FAA4B;AACpD;AACA;AACA;AACA,uCAAuC,iBAAiB,EAAE;AAC1D;AACA;AACA;AACA;AACA;AACA,mEAAmE,gBAAgB;AACnF;AACA;AACA,GAAG,4CAA4C,gCAAgC;AAC/E;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACxBA,iBAAiB,mBAAO,CAAC,4DAAW;;;;;;;;;;;;ACApC;AACA;AACA;AACA;AACA;AACA,yCAAyC;;;;;;;;;;;;ACLzC,uBAAuB;AACvB;AACA;AACA;;;;;;;;;;;;ACHA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC;AACA,CAAC;AACD;AACA;AACA;;;;;;;;;;;;ACPA,eAAe,mBAAO,CAAC,4DAAW;AAClC;;;;;;;;;;;;ACDA,kBAAkB,mBAAO,CAAC,sEAAgB,MAAM,mBAAO,CAAC,0DAAU;AAClE,+BAA+B,mBAAO,CAAC,oEAAe,gBAAgB,mBAAmB,UAAU,EAAE,EAAE;AACvG,CAAC;;;;;;;;;;;;ACFD,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,kEAAc;AAC3C;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACRA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACfA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;AACA;;;;;;;;;;;;ACLA;AACA,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,eAAe,mBAAO,CAAC,sDAAQ;AAC/B;;AAEA;AACA;AACA;;;;;;;;;;;;ACPA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;;;;;;;;;;;ACJA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;;;;;;;;;;;;ACLA;AACA;AACA;;;;;;;;;;;;ACFA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,YAAY,mBAAO,CAAC,sDAAQ;AAC5B;AACA;AACA;AACA;;;;;;;;;;;;ACPA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACXa;AACb,aAAa,mBAAO,CAAC,0EAAkB;AACvC,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD;;AAEA;AACA,mBAAO,CAAC,wDAAS,qBAAqB,mBAAO,CAAC,sDAAQ,4BAA4B,aAAa,EAAE;;AAEjG;AACA,qDAAqD,4BAA4B;AACjF;AACA;;;;;;;;;;;;;ACZa;AACb,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,gEAAa;AACpC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,eAAe,mBAAO,CAAC,sDAAQ;AAC/B,8CAA8C;AAC9C;AACA;AACA;;AAEA,8BAA8B,aAAa;;AAE3C;AACA;AACA;AACA;AACA;AACA,yCAAyC,oCAAoC;AAC7E,6CAA6C,oCAAoC;AACjF,KAAK,4BAA4B,oCAAoC;AACrE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,gBAAgB,mBAAmB;AACnC;AACA;AACA,kCAAkC,2BAA2B;AAC7D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;;;;;;;;;;;;ACpEA,eAAe,mBAAO,CAAC,sDAAQ;AAC/B;;AAEA;AACA;AACA,iCAAiC,qBAAqB;AACtD;AACA,iCAAiC,SAAS,EAAE;AAC5C,CAAC,YAAY;;AAEb;AACA;AACA;AACA;AACA;AACA;AACA,6BAA6B,SAAS,qBAAqB;AAC3D,iCAAiC,aAAa;AAC9C;AACA,GAAG,YAAY;AACf;AACA;;;;;;;;;;;;ACrBA;AACA,UAAU;AACV;;;;;;;;;;;;ACFA;;;;;;;;;;;;ACAA;;;;;;;;;;;;ACAA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,WAAW,mBAAO,CAAC,kEAAc;AACjC;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACtBA;AACA;AACA;AACA;;;;;;;;;;;;ACHA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACjBA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACJA,WAAW,mBAAO,CAAC,sDAAQ;AAC3B,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,kEAAc;AACpC;AACA;AACA;AACA;AACA,cAAc,mBAAO,CAAC,0DAAU;AAChC,iDAAiD;AACjD,CAAC;AACD;AACA,qBAAqB;AACrB;AACA,SAAS;AACT,GAAG,EAAE;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACpDA,UAAU,mBAAO,CAAC,4DAAW;AAC7B,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,4DAAW;AAChC,iDAAiD,mBAAO,CAAC,sEAAgB;;AAEzE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,0DAA0D,gBAAgB,EAAE;AAC5E;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AClDA,aAAa,mBAAO,CAAC,4DAAW;AAChC,gBAAgB,mBAAO,CAAC,wDAAS;AACjC;AACA;AACA;AACA,aAAa,mBAAO,CAAC,sDAAQ;;AAE7B;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,uCAAuC,sBAAsB,EAAE;AAC/D;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA,gBAAgB;AAChB;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;;;;;;;;;;;;ACpEa;AACb;AACA,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;ACjBa;AACb;AACA,cAAc,mBAAO,CAAC,sEAAgB;AACtC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,UAAU,mBAAO,CAAC,oEAAe;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,8DAAY;AAClC;;AAEA;AACA,6BAA6B,mBAAO,CAAC,0DAAU;AAC/C;AACA;AACA;AACA;AACA;AACA;AACA,oCAAoC,UAAU,EAAE;AAChD,mBAAmB,sCAAsC;AACzD,CAAC,qCAAqC;AACtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH,CAAC;;;;;;;;;;;;ACjCD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,oEAAe;AACjC,kBAAkB,mBAAO,CAAC,0EAAkB;AAC5C,eAAe,mBAAO,CAAC,oEAAe;AACtC,yBAAyB;AACzB;;AAEA;AACA;AACA;AACA,eAAe,mBAAO,CAAC,oEAAe;AACtC;AACA;AACA;AACA;AACA;AACA,EAAE,mBAAO,CAAC,wDAAS;AACnB,6BAA6B;AAC7B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;;;;;;;;;;;;ACxCA,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,4EAAmB;AAChD,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C;;AAEA,YAAY,mBAAO,CAAC,sEAAgB;AACpC;AACA;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf;AACA;AACA;AACA;;;;;;;;;;;;ACfA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,sEAAgB;;AAEtC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACZa;AACb;AACA,iBAAiB,mBAAO,CAAC,8DAAY,MAAM,mBAAO,CAAC,0DAAU;AAC7D;AACA;AACA;AACA,8CAA8C,cAAc;AAC5D,SAAS,mBAAO,CAAC,4DAAW;AAC5B,CAAC;;;;;;;;;;;;ACRD,UAAU,mBAAO,CAAC,oEAAe;AACjC,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,qBAAqB,mBAAO,CAAC,4EAAmB;AAChD;;AAEA,YAAY,mBAAO,CAAC,sEAAgB;AACpC;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf;AACA;;;;;;;;;;;;ACfA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,iBAAiB;;AAEjB;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;AClBA;AACA,YAAY,mBAAO,CAAC,wFAAyB;AAC7C,iBAAiB,mBAAO,CAAC,0EAAkB;;AAE3C;AACA;AACA;;;;;;;;;;;;ACNA;;;;;;;;;;;;ACAA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,oEAAe;AACtC;;AAEA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACZA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,mBAAmB,mBAAO,CAAC,4EAAmB;AAC9C,eAAe,mBAAO,CAAC,oEAAe;;AAEtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AChBA;AACA,YAAY,mBAAO,CAAC,wFAAyB;AAC7C,kBAAkB,mBAAO,CAAC,0EAAkB;;AAE5C;AACA;AACA;;;;;;;;;;;;ACNA,cAAc;;;;;;;;;;;;ACAd;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,YAAY,mBAAO,CAAC,0DAAU;AAC9B;AACA,6BAA6B;AAC7B;AACA;AACA,qDAAqD,OAAO,EAAE;AAC9D;;;;;;;;;;;;ACTA,cAAc,mBAAO,CAAC,sEAAgB;AACtC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,aAAa,mBAAO,CAAC,oEAAe;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;;;;;;;;;;;ACfA;AACA,WAAW,mBAAO,CAAC,sEAAgB;AACnC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,4DAAW;AACjC;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACTA,kBAAkB,mBAAO,CAAC,4DAAW;AACrC,YAAY,mBAAO,CAAC,sEAAgB;;AAEpC,iCAAiC,mBAAO,CAAC,kEAAc;AACvD;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD,gBAAgB,mBAAO,CAAC,4DAAW;AACnC,YAAY,mBAAO,CAAC,sEAAgB;AACpC,SAAS,mBAAO,CAAC,kEAAc;AAC/B;;AAEA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA;AACA,YAAY;AACZ,GAAG;AACH,YAAY;AACZ;AACA;;;;;;;;;;;;ACNA,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,2BAA2B,mBAAO,CAAC,4FAA2B;;AAE9D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACXA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACPA,eAAe,mBAAO,CAAC,gEAAa;AACpC;AACA;AACA;AACA;;;;;;;;;;;;ACJA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,gBAAgB,mBAAO,CAAC,oFAAuB;AAC/C;AACA;;AAEA,mBAAO,CAAC,wDAAS;AACjB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA;AACA,CAAC;AACD;AACA,CAAC;;;;;;;;;;;;;AC9BY;;AAEb,cAAc,mBAAO,CAAC,8DAAY;AAClC;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACpBa;;AAEb,kBAAkB,mBAAO,CAAC,0DAAU;;AAEpC;AACA;AACA;AACA;AACA;;AAEA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA;;AAEA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,mBAAmB,0BAA0B;AAC7C;AACA;AACA,OAAO;AACP;;AAEA;AACA;AACA;;AAEA;;;;;;;;;;;;ACzDA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;;;;;;;;;;;ACPA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACJa;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,YAAY,mBAAO,CAAC,4DAAW;;AAE/B;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA;AACA,GAAG,EAAE;AACL;;;;;;;;;;;;;AC3Ba;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA,GAAG,EAAE;AACL;;;;;;;;;;;;ACXA;AACA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA,kDAAkD;AAClD;AACA;AACA,cAAc,mBAAO,CAAC,sDAAQ,iBAAiB,mBAAO,CAAC,sEAAgB;AACvE;AACA;AACA,OAAO,YAAY,cAAc;AACjC;AACA;AACA;AACA;AACA;AACA;AACA,KAAK,GAAG;AACR;AACA;;;;;;;;;;;;;ACxBa;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,SAAS,mBAAO,CAAC,kEAAc;AAC/B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,cAAc,mBAAO,CAAC,sDAAQ;;AAE9B;AACA;AACA;AACA;AACA,sBAAsB,aAAa;AACnC,GAAG;AACH;;;;;;;;;;;;ACZA,UAAU,mBAAO,CAAC,kEAAc;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;;AAE1B;AACA,oEAAoE,iCAAiC;AACrG;;;;;;;;;;;;ACNA,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;;;;;;;;;;;ACJA,WAAW,mBAAO,CAAC,wDAAS;AAC5B,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA,kDAAkD;;AAElD;AACA,qEAAqE;AACrE,CAAC;AACD;AACA,QAAQ,mBAAO,CAAC,8DAAY;AAC5B;AACA,CAAC;;;;;;;;;;;;ACXD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,cAAc,mBAAO,CAAC,sDAAQ;AAC9B;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACRa;AACb,YAAY,mBAAO,CAAC,0DAAU;;AAE9B;AACA;AACA;AACA,yCAAyC,cAAc;AACvD,GAAG;AACH;;;;;;;;;;;;ACRA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AChBA,sBAAsB;AACtB,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,8DAAY;;AAElC;AACA;AACA;AACA;;;;;;;;;;;;ACPA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0DAAU;AAC9B,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;AACA;AACA;AACA,0FAA0F;AAC1F;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;AClBA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,aAAa,mBAAO,CAAC,0EAAkB;AACvC,cAAc,mBAAO,CAAC,8DAAY;;AAElC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACfa;AACb,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,cAAc,mBAAO,CAAC,8DAAY;;AAElC;AACA;AACA;AACA;AACA;AACA,QAAQ,MAAM;AACd;AACA;;;;;;;;;;;;ACXA,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,8DAAY;AAClC,YAAY,mBAAO,CAAC,0DAAU;AAC9B,aAAa,mBAAO,CAAC,kEAAc;AACnC;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;AC7BA;AACA;;;;;;;;;;;;ACDA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,oEAAe;AACjC,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,MAAM,mBAAO,CAAC,sDAAQ;AACtB;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACnFA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACNA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACTA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACLA;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;;;;;;;;;;;;ACLA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA,2DAA2D;AAC3D;;;;;;;;;;;;ACLA;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;;;;;;;;;;;;ACJA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACXa;AACb,IAAI,mBAAO,CAAC,sEAAgB;AAC5B,gBAAgB,mBAAO,CAAC,8DAAY;AACpC,eAAe,mBAAO,CAAC,4DAAW;AAClC,cAAc,mBAAO,CAAC,0DAAU;AAChC,gBAAgB,mBAAO,CAAC,4DAAW;AACnC,eAAe,mBAAO,CAAC,0DAAU;AACjC,gBAAgB,mBAAO,CAAC,wEAAiB;AACzC,YAAY,mBAAO,CAAC,sDAAQ;AAC5B,mBAAmB,mBAAO,CAAC,sEAAgB;AAC3C,qBAAqB,mBAAO,CAAC,0EAAkB;AAC/C,aAAa,mBAAO,CAAC,wDAAS;AAC9B,oBAAoB,mBAAO,CAAC,wEAAiB;AAC7C,kBAAkB,mBAAO,CAAC,oEAAe;AACzC,iBAAiB,mBAAO,CAAC,kEAAc;AACvC,gBAAgB,mBAAO,CAAC,gEAAa;AACrC,wBAAwB,mBAAO,CAAC,kFAAsB;AACtD,oBAAoB,mBAAO,CAAC,wEAAiB;AAC7C,YAAY,mBAAO,CAAC,sDAAQ;AAC5B,gBAAgB,mBAAO,CAAC,8DAAY;AACpC,iBAAiB,mBAAO,CAAC,kEAAc;AACvC,iBAAiB,mBAAO,CAAC,kEAAc;AACvC,oBAAoB,mBAAO,CAAC,0EAAkB;AAC9C,eAAe,mBAAO,CAAC,0EAAkB;AACzC,uBAAuB,mBAAO,CAAC,oEAAe;AAC9C,aAAa,mBAAO,CAAC,sEAAgB;AACrC,kBAAkB,mBAAO,CAAC,8FAA4B;AACtD,YAAY,mBAAO,CAAC,sDAAQ;AAC5B,YAAY,mBAAO,CAAC,sDAAQ;AAC5B,0BAA0B,mBAAO,CAAC,0EAAkB;AACpD,4BAA4B,mBAAO,CAAC,4EAAmB;AACvD,2BAA2B,mBAAO,CAAC,sFAAwB;AAC3D,uBAAuB,mBAAO,CAAC,kFAAsB;AACrD,kBAAkB,mBAAO,CAAC,kEAAc;AACxC,oBAAoB,mBAAO,CAAC,sEAAgB;AAC5C,mBAAmB,mBAAO,CAAC,sEAAgB;AAC3C,kBAAkB,mBAAO,CAAC,oEAAe;AACzC,wBAAwB,mBAAO,CAAC,kFAAsB;AACtD,YAAY,mBAAO,CAAC,kEAAc;AAClC,cAAc,mBAAO,CAAC,sEAAgB;AACtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,GAAG;;AAEH;AACA;AACA;AACA,GAAG;;AAEH;AACA,4BAA4B;AAC5B,GAAG;;AAEH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,iBAAiB,mBAAmB,0BAA0B,EAAE,EAAE;AAClE;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,yDAAyD,gCAAgC;AACzF;AACA,OAAO;AACP;AACA;AACA,6EAA6E,YAAY;AACzF;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,yDAAyD,6CAA6C,EAAE;;AAExG;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL,mDAAmD;AACnD;AACA,KAAK;AACL;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL,oCAAoC;AACpC;AACA,KAAK;AACL,wEAAwE;AACxE;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL,8DAA8D;AAC9D;AACA,KAAK;AACL,wEAAwE;AACxE;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,GAAG;;AAEH,yBAAyB,sBAAsB,EAAE,EAAE;AACnD;AACA;AACA;AACA;;AAEA,4CAA4C;AAC5C;AACA;AACA;AACA;AACA;AACA,8BAA8B,aAAa;AAC3C;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,sBAAsB,0BAA0B;AAChD,GAAG;;AAEH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA,SAAS;AACT;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA,WAAW;AACX;AACA;AACA;AACA;AACA,SAAS;AACT;AACA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA,OAAO;AACP;AACA;AACA,KAAK;AACL;AACA,KAAK;AACL,yBAAyB;AACzB,KAAK;AACL,uBAAuB;AACvB,2BAA2B;AAC3B,0BAA0B;AAC1B,2BAA2B;AAC3B,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,0BAA0B,aAAa;AACvC,OAAO;AACP;;AAEA;;AAEA;;AAEA;AACA;AACA,KAAK;;AAEL,uDAAuD,6BAA6B,EAAE;AACtF;AACA;AACA,KAAK;;AAEL;;AAEA;;AAEA;;AAEA,uDAAuD,YAAY;;AAEnE;;AAEA;;AAEA;AACA;AACA,KAAK,UAAU,gBAAgB;;AAE/B;AACA;AACA,KAAK;AACL;AACA,KAAK,WAAW,kCAAkC;;AAElD;AACA;AACA;AACA,CAAC,oCAAoC;;;;;;;;;;;;;AC/dxB;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,cAAc,mBAAO,CAAC,8DAAY;AAClC,aAAa,mBAAO,CAAC,0DAAU;AAC/B,WAAW,mBAAO,CAAC,wDAAS;AAC5B,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,YAAY,mBAAO,CAAC,0DAAU;AAC9B,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,gEAAa;AACnC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,SAAS,mBAAO,CAAC,kEAAc;AAC/B,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,QAAQ,WAAW;AACnB;AACA;AACA,QAAQ,UAAU;AAClB;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,QAAQ,WAAW;AACnB;AACA;AACA;AACA,QAAQ,WAAW;AACnB;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,yBAAyB,mBAAmB,uBAAuB,EAAE,EAAE;AACvE;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,iBAAiB,WAAW;AAC5B;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,GAAG;AACH,CAAC;AACD;AACA;AACA,GAAG;AACH,yBAAyB;AACzB,GAAG;AACH,uBAAuB;AACvB,0BAA0B;AAC1B,0BAA0B;AAC1B;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,iDAAiD,iBAAiB;AAClE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACnRA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AC3BA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACJA,aAAa,mBAAO,CAAC,4DAAW;AAChC;;AAEA;;;;;;;;;;;;ACHA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;;;;;;;;;;;;ACJA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,cAAc,mBAAO,CAAC,8DAAY;AAClC,aAAa,mBAAO,CAAC,8DAAY;AACjC,qBAAqB,mBAAO,CAAC,kEAAc;AAC3C;AACA,0DAA0D,sBAAsB;AAChF,kFAAkF,wBAAwB;AAC1G;;;;;;;;;;;;ACRA,YAAY,mBAAO,CAAC,sDAAQ;;;;;;;;;;;;ACA5B,YAAY,mBAAO,CAAC,4DAAW;AAC/B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,aAAa,mBAAO,CAAC,4DAAW;AAChC;;AAEA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;ACVA,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,sDAAQ;AAC/B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,iBAAiB,mBAAO,CAAC,wDAAS;AAClC;AACA;AACA;AACA;;;;;;;;;;;;ACPA;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,UAAU,mBAAO,CAAC,gEAAa,oBAAoB;;AAEnD,8BAA8B,8BAA8B,gBAAgB,EAAE,EAAE;;;;;;;;;;;;ACJhF;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,6BAA6B,aAAa,mBAAO,CAAC,kFAAsB,GAAG;;AAE3E,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACLlB;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,0EAAkB;;AAEvC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,6BAA6B,OAAO,mBAAO,CAAC,oEAAe,GAAG;;AAE9D,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACLlB;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,0EAAkB;;AAExC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0EAAkB;AACtC;AACA;AACA;AACA,0CAA0C,gBAAgB,EAAE;AAC5D;AACA;AACA;AACA;AACA,CAAC;AACD,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACblB;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0EAAkB;AACtC;AACA;AACA;AACA,0CAA0C,gBAAgB,EAAE;AAC5D;AACA;AACA;AACA;AACA,CAAC;AACD,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACblB;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,0EAAkB;AACzC,aAAa,mBAAO,CAAC,0EAAkB;;AAEvC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACVY;AACb,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,WAAW,mBAAO,CAAC,kEAAc;AACjC,kBAAkB,mBAAO,CAAC,0EAAkB;AAC5C,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,8EAAoB;AACjD,gBAAgB,mBAAO,CAAC,8FAA4B;;AAEpD,iCAAiC,mBAAO,CAAC,sEAAgB,mBAAmB,kBAAkB,EAAE;AAChG;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,uDAAuD,gCAAgC;AACvF;AACA;AACA,KAAK;AACL;AACA,kCAAkC,gBAAgB;AAClD;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACpCY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,4EAAmB;AAC1C;AACA;;AAEA,mDAAmD,mBAAO,CAAC,0EAAkB;AAC7E;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACdD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,6BAA6B,UAAU,mBAAO,CAAC,gEAAa,GAAG;;;;;;;;;;;;;ACHlD;AACb,uBAAuB,mBAAO,CAAC,oFAAuB;AACtD,WAAW,mBAAO,CAAC,kEAAc;AACjC,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,gCAAgC;AAChC,cAAc;AACd,iBAAiB;AACjB;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;ACjCa;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;;AAEA;AACA,iCAAiC,mBAAO,CAAC,8DAAY,gBAAgB,mBAAO,CAAC,0EAAkB;AAC/F;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACXY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;;AAEA,mDAAmD,mBAAO,CAAC,0EAAkB;AAC7E;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,WAAW;AACrB;AACA;AACA,CAAC;;;;;;;;;;;;;ACrBY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,0EAAkB;;AAErC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,qBAAqB,mBAAO,CAAC,8EAAoB;;AAEjD;AACA,gCAAgC,mBAAO,CAAC,0DAAU;AAClD,gBAAgB;AAChB;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;AClBY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,wEAAiB;;AAEvC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,wEAAiB;;AAEvC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD,eAAe,mBAAO,CAAC,kEAAc;AACrC;;AAEA;AACA,gCAAgC,mBAAO,CAAC,0DAAU;AAClD;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,UAAU;AACpB;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;AC3BY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0EAAkB;;AAEtC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,YAAY,mBAAO,CAAC,0DAAU;AAC9B;AACA;;AAEA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA,CAAC,MAAM,mBAAO,CAAC,0EAAkB;AACjC;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACtBD,mBAAO,CAAC,sEAAgB;;;;;;;;;;;;ACAxB;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,mBAAmB,6BAA6B,EAAE,EAAE;;;;;;;;;;;;ACHhF;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,kBAAkB,mBAAO,CAAC,oFAAuB;;AAEjD;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACPY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,wEAAiB;;AAE3C,gCAAgC,mBAAO,CAAC,0DAAU;AAClD;AACA,mCAAmC,2BAA2B,UAAU,EAAE,EAAE;AAC5E,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACfD,mBAAmB,mBAAO,CAAC,sDAAQ;AACnC;;AAEA,8BAA8B,mBAAO,CAAC,wDAAS,uBAAuB,mBAAO,CAAC,kFAAsB;;;;;;;;;;;;ACHpG;AACA;AACA;AACA;AACA;AACA;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACXA;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,gCAAgC,OAAO,mBAAO,CAAC,wDAAS,GAAG;;;;;;;;;;;;;ACH9C;AACb,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,mBAAmB,mBAAO,CAAC,sDAAQ;AACnC;AACA;AACA,sCAAsC,mBAAO,CAAC,kEAAc,kCAAkC;AAC9F;AACA;AACA;AACA;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACZH,SAAS,mBAAO,CAAC,kEAAc;AAC/B;AACA;AACA;;AAEA;AACA,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACfY;AACb,aAAa,mBAAO,CAAC,kFAAsB;AAC3C,eAAe,mBAAO,CAAC,sFAAwB;AAC/C;;AAEA;AACA,iBAAiB,mBAAO,CAAC,oEAAe;AACxC,yBAAyB,mEAAmE;AAC5F,CAAC;AACD;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;AClBD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,oEAAe;AACnC;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACjBD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA;AACA;;AAEA;AACA,yEAAyE,eAAe;;;;;;;;;;;;ACTxF;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,kEAAc;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,oEAAe;;AAEpC,iEAAiE,gBAAgB;;;;;;;;;;;;ACJjF;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,SAAS,mBAAO,CAAC,sEAAgB,GAAG;;;;;;;;;;;;ACHhE;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA,yCAAyC;AACzC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA,OAAO;AACP;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACxBD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA,gCAAgC,mBAAO,CAAC,0DAAU;AAClD;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;AChBD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,QAAQ,mBAAO,CAAC,oEAAe,GAAG;;;;;;;;;;;;ACH9D;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,OAAO,mBAAO,CAAC,kEAAc,GAAG;;;;;;;;;;;;ACH5D;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,oEAAe;AACnC;;AAEA;AACA,gCAAgC,mBAAO,CAAC,0DAAU;AAClD;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACdD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,oEAAe;AACnC;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACXD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACPY;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,wBAAwB,mBAAO,CAAC,sFAAwB;AACxD,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,YAAY,mBAAO,CAAC,0DAAU;AAC9B,WAAW,mBAAO,CAAC,sEAAgB;AACnC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,SAAS,mBAAO,CAAC,kEAAc;AAC/B,YAAY,mBAAO,CAAC,sEAAgB;AACpC;AACA;AACA;AACA;AACA;AACA,qBAAqB,mBAAO,CAAC,0EAAkB;AAC/C;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oDAAoD;AACpD,KAAK;AACL;AACA,oCAAoC,cAAc,OAAO;AACzD,qCAAqC,cAAc,OAAO;AAC1D;AACA;AACA,oEAAoE,OAAO;AAC3E;AACA;AACA;AACA;AACA,OAAO;AACP;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,0CAA0C,0BAA0B,EAAE;AACtE;AACA;AACA,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C;AACA;AACA;AACA;AACA;AACA,2BAA2B,iBAAiB;AAC5C;AACA;AACA;AACA;AACA;AACA;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;;;;;;;;;;;;ACpEA;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,8BAA8B,4BAA4B;;;;;;;;;;;;ACH1D;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,4DAAW;;AAEnC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,8BAA8B,YAAY,mBAAO,CAAC,oEAAe,GAAG;;;;;;;;;;;;ACHpE;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;;AAEA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,8BAA8B,qCAAqC;;;;;;;;;;;;ACHnE;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,8BAA8B,sCAAsC;;;;;;;;;;;;ACHpE,cAAc,mBAAO,CAAC,4DAAW;AACjC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C;AACA,+EAA+E,0BAA0B;;;;;;;;;;;;ACHzG,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,kEAAc;AACtC;AACA,2EAA2E,sBAAsB;;;;;;;;;;;;;ACHpF;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,mBAAmB,mBAAO,CAAC,4EAAmB;AAC9C,aAAa,mBAAO,CAAC,0EAAkB;AACvC;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA,MAAM,mBAAO,CAAC,0DAAU;AACxB;AACA,kBAAkB;AAClB,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;;ACjHY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,0DAAU;AAC/B,mBAAmB,mBAAO,CAAC,4EAAmB;AAC9C;;AAEA;AACA;AACA;AACA,CAAC;AACD;AACA,sBAAsB;AACtB,CAAC;AACD;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACjBD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,0CAA0C,SAAS,mBAAO,CAAC,0EAAkB,GAAG;;;;;;;;;;;;ACHhF,cAAc,mBAAO,CAAC,4DAAW;AACjC;AACA,8BAA8B,SAAS,mBAAO,CAAC,0EAAkB,GAAG;;;;;;;;;;;;ACFpE,cAAc,mBAAO,CAAC,4DAAW;AACjC;AACA,iCAAiC,mBAAO,CAAC,sEAAgB,cAAc,mBAAmB,mBAAO,CAAC,oEAAe,GAAG;;;;;;;;;;;;ACFpH,cAAc,mBAAO,CAAC,4DAAW;AACjC;AACA,iCAAiC,mBAAO,CAAC,sEAAgB,cAAc,iBAAiB,mBAAO,CAAC,kEAAc,KAAK;;;;;;;;;;;;ACFnH;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,WAAW,mBAAO,CAAC,wDAAS;;AAE5B,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,gCAAgC,mBAAO,CAAC,sEAAgB;;AAExD,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,mBAAO,CAAC,oEAAe;AACvB,SAAS,mBAAO,CAAC,8EAAoB;AACrC,CAAC;;;;;;;;;;;;ACHD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,oEAAe;;AAE7C,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,eAAe,mBAAO,CAAC,kEAAc;;AAErC,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,eAAe,mBAAO,CAAC,kEAAc;;AAErC,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,eAAe,mBAAO,CAAC,kEAAc;;AAErC,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,8BAA8B,KAAK,mBAAO,CAAC,oEAAe,GAAG;;;;;;;;;;;;ACF7D;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,YAAY,mBAAO,CAAC,sEAAgB;;AAEpC,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,WAAW,mBAAO,CAAC,wDAAS;;AAE5B,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,WAAW,mBAAO,CAAC,wDAAS;;AAE5B,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,8BAA8B,iBAAiB,mBAAO,CAAC,kEAAc,OAAO;;;;;;;;;;;;;ACF/D;AACb;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA,KAAK,mBAAO,CAAC,sDAAQ;AACrB;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;AACA,GAAG;AACH;;;;;;;;;;;;ACTA,cAAc,mBAAO,CAAC,4DAAW;AACjC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C;AACA,8DAA8D,0BAA0B;;;;;;;;;;;;ACHxF,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,kEAAc;AACtC;AACA,0DAA0D,sBAAsB;;;;;;;;;;;;;ACHnE;AACb,cAAc,mBAAO,CAAC,8DAAY;AAClC,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,YAAY,mBAAO,CAAC,4DAAW;AAC/B,yBAAyB,mBAAO,CAAC,sFAAwB;AACzD,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,iCAAiC,mBAAO,CAAC,4FAA2B;AACpE,cAAc,mBAAO,CAAC,8DAAY;AAClC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,qBAAqB,mBAAO,CAAC,8EAAoB;AACjD;AACA;AACA;AACA;AACA;AACA;AACA;AACA,yBAAyB;AACzB;AACA;;AAEA;AACA;AACA;AACA;AACA,+CAA+C,EAAE,mBAAO,CAAC,sDAAQ;AACjE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oCAAoC;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,WAAW;AACX;AACA,WAAW;AACX,SAAS;AACT,OAAO;AACP;AACA;AACA;AACA;AACA,6CAA6C;AAC7C;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT,mBAAmB,kCAAkC;AACrD,SAAS;AACT;AACA;AACA,OAAO;AACP;AACA;AACA,KAAK;AACL;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL,eAAe,uCAAuC;AACtD;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA,uBAAuB,0BAA0B;AACjD;AACA;AACA,SAAS;AACT;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH,kBAAkB,yBAAyB,KAAK;AAChD;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA,iBAAiB;AACjB,wBAAwB;AACxB,gBAAgB;AAChB,oBAAoB;AACpB,wBAAwB;AACxB,gBAAgB;AAChB,oBAAoB;AACpB;AACA,uBAAuB,mBAAO,CAAC,wEAAiB;AAChD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,0DAA0D,oBAAoB;AAC9E,mBAAO,CAAC,kFAAsB;AAC9B,mBAAO,CAAC,sEAAgB;AACxB,UAAU,mBAAO,CAAC,wDAAS;;AAE3B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA,CAAC;AACD,gDAAgD,mBAAO,CAAC,sEAAgB;AACxE;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT,OAAO;AACP;AACA,KAAK;AACL;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;AC7RD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,4DAAW,eAAe;AAChD;AACA;AACA,iCAAiC,mBAAO,CAAC,0DAAU;AACnD,sBAAsB,cAAc;AACpC,CAAC;AACD;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACfD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,0EAAkB;AACvC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,YAAY,mBAAO,CAAC,0DAAU;AAC9B,WAAW,mBAAO,CAAC,wDAAS;AAC5B,kBAAkB,mBAAO,CAAC,4DAAW,eAAe;;AAEpD;AACA;AACA;AACA,gBAAgB;AAChB,mCAAmC,cAAc;AACjD,CAAC;AACD;AACA,0BAA0B,cAAc;AACxC,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;AC9CD;AACA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,wEAAiB;;AAE3C;AACA,gCAAgC,mBAAO,CAAC,0DAAU;AAClD;AACA,gCAAgC,MAAM,WAAW,OAAO,WAAW;AACnE,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACtBD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACVY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA,+BAA+B;AAC/B,cAAc;AACd,0BAA0B;AAC1B;AACA;AACA;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA;AACA,wCAAwC;AACxC,GAAG;AACH,UAAU;AACV,CAAC;;AAED;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACzBD;AACA,WAAW,mBAAO,CAAC,sEAAgB;AACnC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,oEAAe;AACtC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,WAAW,mBAAO,CAAC,sEAAgB;AACnC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,+BAA+B,WAAW;;;;;;;;;;;;ACpB1C;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC;;AAEA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACVD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,+BAA+B,UAAU,mBAAO,CAAC,gEAAa,GAAG;;;;;;;;;;;;ACHjE;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACfD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACdD;AACA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,WAAW,mBAAO,CAAC,sEAAgB;AACnC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,4DAAW;AACjC,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;;AAEA,+BAA+B,WAAW;;;;;;;;;;;;AChC1C,aAAa,mBAAO,CAAC,4DAAW;AAChC,wBAAwB,mBAAO,CAAC,sFAAwB;AACxD,SAAS,mBAAO,CAAC,kEAAc;AAC/B,WAAW,mBAAO,CAAC,sEAAgB;AACnC,eAAe,mBAAO,CAAC,kEAAc;AACrC,aAAa,mBAAO,CAAC,0DAAU;AAC/B;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,IAAI,mBAAO,CAAC,sEAAgB,sBAAsB,mBAAO,CAAC,0DAAU;AACpE,MAAM,mBAAO,CAAC,sDAAQ;AACtB;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,wBAAwB,kBAAkB,EAAE;AAC5C,0BAA0B,gBAAgB;AAC1C,KAAK;AACL;AACA,oCAAoC,iBAAiB;AACrD;AACA;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;;AAEA,mBAAO,CAAC,sEAAgB;;;;;;;;;;;;;AC1CX;AACb,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,mBAAO,CAAC,4DAAW;AACnB;AACA;AACA;AACA,CAAC;AACD;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,IAAI,mBAAO,CAAC,sEAAgB,wBAAwB,mBAAO,CAAC,kEAAc;AAC1E;AACA,OAAO,mBAAO,CAAC,0DAAU;AACzB,CAAC;;;;;;;;;;;;;ACJY;;AAEb,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,yBAAyB,mBAAO,CAAC,wFAAyB;AAC1D,iBAAiB,mBAAO,CAAC,wFAAyB;;AAElD;AACA,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACvCY;;AAEb,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,yBAAyB,mBAAO,CAAC,wFAAyB;AAC1D,iBAAiB,mBAAO,CAAC,wFAAyB;AAClD;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,qBAAqB,oBAAoB;AACzC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,uBAAuB,mBAAmB;AAC1C;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;;ACrHY;;AAEb,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,iBAAiB,mBAAO,CAAC,wFAAyB;;AAElD;AACA,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;AC9BY;;AAEb,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,yBAAyB,mBAAO,CAAC,sFAAwB;AACzD,yBAAyB,mBAAO,CAAC,wFAAyB;AAC1D,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,wFAAyB;AACtD,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,YAAY,mBAAO,CAAC,0DAAU;AAC9B;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,qCAAqC,yBAAyB,EAAE;;AAEhE;AACA,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,mFAAmF;AACnF;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA,yBAAyB,mBAAmB;AAC5C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACrIY;AACb,mBAAO,CAAC,8EAAoB;AAC5B,eAAe,mBAAO,CAAC,kEAAc;AACrC,aAAa,mBAAO,CAAC,0DAAU;AAC/B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C;AACA;;AAEA;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;;AAEA;AACA,IAAI,mBAAO,CAAC,0DAAU,eAAe,wBAAwB,0BAA0B,YAAY,EAAE;AACrG;AACA;AACA;AACA;AACA,GAAG;AACH;AACA,CAAC;AACD;AACA;AACA,GAAG;AACH;;;;;;;;;;;;;ACxBa;AACb,aAAa,mBAAO,CAAC,kFAAsB;AAC3C,eAAe,mBAAO,CAAC,sFAAwB;AAC/C;;AAEA;AACA,iBAAiB,mBAAO,CAAC,oEAAe;AACxC,yBAAyB,mEAAmE;AAC5F,CAAC;AACD;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACbY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,UAAU,mBAAO,CAAC,kEAAc;AAChC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACRD;AACa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,4EAAmB;AACzC;AACA;;AAEA,gCAAgC,mBAAO,CAAC,8EAAoB;AAC5D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACnBY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACND,cAAc,mBAAO,CAAC,4DAAW;AACjC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD;AACA;;AAEA;AACA;AACA;AACA,4CAA4C;AAC5C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;;ACtBD;AACa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,4EAAmB;AACzC;;AAEA,gCAAgC,mBAAO,CAAC,8EAAoB;AAC5D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACXY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb,UAAU,mBAAO,CAAC,kEAAc;;AAEhC;AACA,mBAAO,CAAC,sEAAgB;AACxB,6BAA6B;AAC7B,cAAc;AACd;AACA,CAAC;AACD;AACA;AACA;AACA,iCAAiC;AACjC;AACA;AACA,UAAU;AACV,CAAC;;;;;;;;;;;;;AChBY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACND,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;ACjBD,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA,UAAU,mBAAO,CAAC,0EAAkB;AACpC,CAAC;;;;;;;;;;;;;ACLY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACND;AACa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,4EAAmB;AACzC;AACA;;AAEA,gCAAgC,mBAAO,CAAC,8EAAoB;AAC5D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACjBY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,gEAAa;AACpC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,aAAa,mBAAO,CAAC,0DAAU;AAC/B,aAAa,mBAAO,CAAC,4DAAW;AAChC,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,aAAa,mBAAO,CAAC,8DAAY;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,gEAAa;AACnC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,cAAc,mBAAO,CAAC,0EAAkB;AACxC,cAAc,mBAAO,CAAC,8EAAoB;AAC1C,YAAY,mBAAO,CAAC,sEAAgB;AACpC,UAAU,mBAAO,CAAC,kEAAc;AAChC,YAAY,mBAAO,CAAC,sEAAgB;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,eAAe;AACf;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,sBAAsB;AACtB,sBAAsB,uBAAuB,WAAW,IAAI;AAC5D,GAAG;AACH,CAAC;AACD;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,CAAC;AACD;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,2DAA2D;AAC3D;AACA,KAAK;AACL;AACA,sBAAsB,mCAAmC;AACzD,KAAK;AACL,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,gEAAgE,gCAAgC;AAChG;AACA;AACA;AACA;AACA,GAAG;;AAEH;AACA;AACA,EAAE,mBAAO,CAAC,sEAAgB;AAC1B,EAAE,mBAAO,CAAC,oEAAe;AACzB,EAAE,mBAAO,CAAC,sEAAgB;;AAE1B,sBAAsB,mBAAO,CAAC,8DAAY;AAC1C;AACA;;AAEA;AACA;AACA;AACA;;AAEA,0DAA0D,kBAAkB;;AAE5E;AACA;AACA;AACA,oBAAoB,uBAAuB;;AAE3C,oDAAoD,6BAA6B;;AAEjF;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH,0BAA0B,eAAe,EAAE;AAC3C,0BAA0B,gBAAgB;AAC1C,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA,oDAAoD,OAAO,QAAQ,iCAAiC;AACpG,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA,wEAAwE;AACxE;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA,oCAAoC,mBAAO,CAAC,wDAAS;AACrD;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACzOa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,0DAAU;AAC/B,aAAa,mBAAO,CAAC,wEAAiB;AACtC,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,4DAAW;AACrC,yBAAyB,mBAAO,CAAC,sFAAwB;AACzD;AACA;AACA;AACA;AACA;AACA;;AAEA,6EAA6E,4BAA4B;;AAEzG;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED,4CAA4C,mBAAO,CAAC,0DAAU;AAC9D;AACA,CAAC;AACD;AACA;AACA,6FAA6F;AAC7F;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;AAED,mBAAO,CAAC,sEAAgB;;;;;;;;;;;;AC7CxB,cAAc,mBAAO,CAAC,4DAAW;AACjC,6CAA6C,mBAAO,CAAC,0DAAU;AAC/D,YAAY,mBAAO,CAAC,wEAAiB;AACrC,CAAC;;;;;;;;;;;;ACHD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACJY;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,0EAAkB;AACrC,eAAe,mBAAO,CAAC,gEAAa;AACpC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,aAAa,mBAAO,CAAC,0EAAkB;AACvC,WAAW,mBAAO,CAAC,8EAAoB;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,sFAAwB;AAC/C,sBAAsB,mBAAO,CAAC,sFAAwB;AACtD;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA,gCAAgC,mBAAO,CAAC,oEAAe;;AAEvD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP,KAAK;AACL,GAAG;AACH;;;;;;;;;;;;;AC3Da;AACb,WAAW,mBAAO,CAAC,8EAAoB;AACvC,eAAe,mBAAO,CAAC,sFAAwB;AAC/C;;AAEA;AACA,mBAAO,CAAC,oEAAe;AACvB,6BAA6B,mEAAmE;AAChG,CAAC;AACD;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACbY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,uBAAuB,mBAAO,CAAC,oFAAuB;AACtD,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,yBAAyB,mBAAO,CAAC,wFAAyB;;AAE1D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACrBlB;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,uBAAuB,mBAAO,CAAC,oFAAuB;AACtD,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,yBAAyB,mBAAO,CAAC,wFAAyB;;AAE1D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACpBlB;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,4EAAmB;;AAE3C;AACA;AACA;AACA;AACA,CAAC;;AAED,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;ACX/B;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,sDAAQ;;AAE7B;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACXD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,UAAU,mBAAO,CAAC,sDAAQ;;AAE1B;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,oBAAoB,SAAS,mBAAO,CAAC,4DAAW,GAAG;;;;;;;;;;;;ACHnD;AACA,mBAAO,CAAC,sFAAwB;;;;;;;;;;;;ACDhC;AACA,mBAAO,CAAC,kFAAsB;;;;;;;;;;;;ACD9B;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,uCAAuC,SAAS,mBAAO,CAAC,oFAAuB,UAAU;;;;;;;;;;;;ACHzF;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,6BAA6B;;;;;;;;;;;;ACHzD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,oEAAe;AACnC,aAAa,mBAAO,CAAC,sEAAgB;;AAErC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACVD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACfD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACVD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,6BAA6B;;;;;;;;;;;;ACHzD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,QAAQ,mBAAO,CAAC,oEAAe,GAAG;;;;;;;;;;;;ACH9D;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B;AAC5B;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACNH;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACfY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,sBAAsB,mBAAO,CAAC,kEAAc;;AAE5C;AACA,mBAAO,CAAC,sEAAgB,yBAAyB,mBAAO,CAAC,kFAAsB;AAC/E;AACA,0CAA0C,+DAA+D;AACzG;AACA,CAAC;;;;;;;;;;;;;ACXY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,sBAAsB,mBAAO,CAAC,kEAAc;;AAE5C;AACA,mBAAO,CAAC,sEAAgB,yBAAyB,mBAAO,CAAC,kFAAsB;AAC/E;AACA,0CAA0C,+DAA+D;AACzG;AACA,CAAC;;;;;;;;;;;;ACXD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,8EAAoB;;AAE3C;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,gEAAa;AACnC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,qBAAqB,mBAAO,CAAC,8EAAoB;;AAEjD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACrBY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,+BAA+B,mBAAO,CAAC,sEAAgB;;AAEvD;AACA,mBAAO,CAAC,sEAAgB,yBAAyB,mBAAO,CAAC,kFAAsB;AAC/E;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;;ACjBY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,+BAA+B,mBAAO,CAAC,sEAAgB;;AAEvD;AACA,mBAAO,CAAC,sEAAgB,yBAAyB,mBAAO,CAAC,kFAAsB;AAC/E;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;ACjBD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,8EAAoB;;AAE1C;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACRY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,iBAAiB,mBAAO,CAAC,sDAAQ;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,WAAW,mBAAO,CAAC,wDAAS;AAC5B,YAAY,mBAAO,CAAC,4DAAW;AAC/B;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,4EAA4E,4BAA4B;AACxG;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,GAAG;AACH;;AAEA,uCAAuC;AACvC,uCAAuC,yBAAyB;AAChE,CAAC;;AAED;AACA;AACA;;AAEA,+CAA+C;AAC/C;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,OAAO;AACP;AACA;AACA,KAAK;AACL;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA,SAAS;AACT;AACA;AACA,OAAO;AACP;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,WAAW;AACX;AACA;AACA;AACA,SAAS;AACT;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,aAAa;AACb,WAAW;AACX;AACA;AACA;AACA,WAAW;AACX;AACA,OAAO;AACP,0BAA0B,aAAa;AACvC,KAAK;AACL,GAAG;AACH;AACA,+DAA+D,OAAO;AACtE;AACA;AACA;AACA;AACA,yBAAyB,kBAAkB;AAC3C;AACA;AACA,WAAW;AACX;AACA,OAAO;AACP,0BAA0B,aAAa;AACvC,KAAK;AACL;AACA,CAAC;;AAED,qDAAqD,aAAa,EAAE;;AAEpE,oBAAoB,0BAA0B;;AAE9C,mBAAO,CAAC,sEAAgB;;;;;;;;;;;;;ACtMxB;AACa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,aAAa,mBAAO,CAAC,4DAAW;AAChC,yBAAyB,mBAAO,CAAC,sFAAwB;AACzD,qBAAqB,mBAAO,CAAC,8EAAoB;;AAEjD,2CAA2C;AAC3C;AACA;AACA;AACA;AACA,8DAA8D,UAAU,EAAE;AAC1E,KAAK;AACL;AACA,8DAA8D,SAAS,EAAE;AACzE,KAAK;AACL;AACA,CAAC,EAAE;;;;;;;;;;;;;ACnBU;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,2BAA2B,mBAAO,CAAC,4FAA2B;AAC9D,cAAc,mBAAO,CAAC,8DAAY;;AAElC,+BAA+B;AAC/B;AACA;AACA;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACXH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;;AAEA,cAAc;AACd;AACA,CAAC,EAAE;;;;;;;;;;;;ACPH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;;AAEA,cAAc;AACd;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACdH,UAAU,mBAAO,CAAC,4DAAW;AAC7B,WAAW,mBAAO,CAAC,sFAAwB;AAC3C,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,cAAc;AACd;AACA,CAAC,EAAE;;;;;;;;;;;;AClBH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA,cAAc;AACd;AACA,CAAC,EAAE;;;;;;;;;;;;AChBH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;;AAEA,cAAc;AACd;AACA,CAAC,EAAE;;;;;;;;;;;;ACPH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;;AAEA,cAAc;AACd;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACRH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA,cAAc;AACd;AACA,CAAC,EAAE;;;;;;;;;;;;ACfH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;;AAEA,cAAc;AACd;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACRH,gBAAgB,mBAAO,CAAC,gEAAa;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;;AAEA,eAAe;AACf;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACdH;AACA,mBAAO,CAAC,sFAAwB;;;;;;;;;;;;ACDhC;AACA,mBAAO,CAAC,kFAAsB;;;;;;;;;;;;ACD9B;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,uCAAuC,SAAS,mBAAO,CAAC,oFAAuB,UAAU;;;;;;;;;;;;;ACH5E;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,UAAU,mBAAO,CAAC,kEAAc;;AAEhC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,0DAAU;AACjC;;AAEA;AACA;AACA;AACA;;AAEA,mBAAO,CAAC,sEAAgB;AACxB;AACA,UAAU;AACV,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;AC7BY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,oEAAe;AAClC,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACXY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,oEAAe;AAClC,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACXY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACND,mBAAO,CAAC,oEAAe;;;;;;;;;;;;ACAvB,mBAAO,CAAC,oEAAe;;;;;;;;;;;;ACAvB;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,8BAA8B,SAAS,mBAAO,CAAC,4DAAW,GAAG;;;;;;;;;;;;ACH7D;AACA,mBAAO,CAAC,sFAAwB;;;;;;;;;;;;ACDhC;AACA,mBAAO,CAAC,kFAAsB;;;;;;;;;;;;ACD9B;AACA,mBAAO,CAAC,sFAAwB;;;;;;;;;;;;ACDhC;AACA,mBAAO,CAAC,kFAAsB;;;;;;;;;;;;ACD9B,iBAAiB,mBAAO,CAAC,kFAAsB;AAC/C,cAAc,mBAAO,CAAC,sEAAgB;AACtC,eAAe,mBAAO,CAAC,gEAAa;AACpC,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,oDAAoD,wBAAwB;AAC5E;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACzDA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,wDAAS;AAC7B;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACLD;AACA,aAAa,mBAAO,CAAC,4DAAW;AAChC,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA,sCAAsC;AACtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACnBD,mBAAO,CAAC,0EAAsB;AAC9B,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0GAAsC;AAC9C,mBAAO,CAAC,8GAAwC;AAChD,mBAAO,CAAC,kIAAkD;AAC1D,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,wHAA6C;AACrD,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,gHAAyC;AACjD,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,wGAAqC;AAC7C,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,oGAAmC;AAC3C,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0GAAsC;AAC9C,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,0GAAsC;AAC9C,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,oGAAmC;AAC3C,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,4EAAuB;AAC/B,mBAAO,CAAC,oEAAmB;AAC3B,mBAAO,CAAC,oEAAmB;AAC3B,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,gHAAyC;AACjD,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,oGAAmC;AAC3C,mBAAO,CAAC,oGAAmC;AAC3C,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,oIAAmD;AAC3D,mBAAO,CAAC,8GAAwC;AAChD,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,wGAAqC;AAC7C,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,kHAA0C;AAClD,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,8GAAwC;AAChD,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,wGAAqC;AAC7C,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,oIAAmD;AAC3D,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,0EAAsB;AAC9B,mBAAO,CAAC,0EAAsB;AAC9B,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0EAAsB;AAC9B,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,gHAAyC;AACjD,mBAAO,CAAC,8GAAwC;AAChD,mBAAO,CAAC,wHAA6C;AACrD,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,8GAAwC;AAChD,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,sEAAoB;AAC5B,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,0EAAsB;AAC9B,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,sFAA4B;AACpC,iBAAiB,mBAAO,CAAC,gEAAiB;;;;;;;;;;;;ACrM1C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA,QAAQ,WAAW;;AAEnB;AACA;AACA;AACA,QAAQ,WAAW;;AAEnB;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;;AAEA,QAAQ,WAAW;;AAEnB;AACA;AACA,QAAQ,UAAU;;AAElB;AACA;;;;;;;;;;;;ACnFA;AACA;AACA;AACA;AACA;AACA,eAAe,SAAS;AACxB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;ACvBA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA,iCAAiC;;AAEjC;AACA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;;AAEA;AACA,sBAAsB,QAAQ;AAC9B;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;ACjCA,UAAU,mBAAO,CAAC,yDAAW;AAC7B,kBAAkB,mBAAO,CAAC,iEAAmB;;AAE7C;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;;AAEA;AACA;AACA,oBAAoB,SAAS;AAC7B;AACA;AACA;;AAEA;AACA;;AAEA;;;;;;;;;;;;AC5BA;;AAEA;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;;AAEA;AACA;AACA,4CAA4C;;AAE5C;;;;;;;;;;;;;;;;;;;;AChBA;;AACA;;0JAJA;AACA;;AAKA,IAAMo+B,6CAA6C,EAAnD,C,CAAuD;;IAE1Cl/B,iB,WAAAA,iB;AAET,iCAIQ;AAAA,uFAAJ,EAAI;AAAA,yCAHJm/B,mCAGI;AAAA,YAHJA,mCAGI,yCAHkCD,0CAGlC;AAAA,0CAFJE,wBAEI;AAAA,YAFJA,wBAEI,0CAFuB,IAAIC,YAAJ,CAAU,uBAAV,CAEvB;AAAA,0CADJC,uBACI;AAAA,YADJA,uBACI,0CADsB,IAAID,YAAJ,CAAU,sBAAV,CACtB;;AAAA;;AACJ,aAAKE,oCAAL,GAA4CJ,mCAA5C;;AAEA,aAAKK,oBAAL,GAA4BJ,wBAA5B;AACA,aAAKK,mBAAL,GAA2BH,uBAA3B;AACH;;gCAEDI,I,iBAAKC,S,EAAW;AACZ;AACA,YAAIA,UAAUC,YAAV,IAA0BD,UAAUE,UAAV,KAAyBh/B,SAAvD,EAAkE;AAC9D,gBAAIi/B,WAAWH,UAAUE,UAAzB;AACAngC,qBAAIqgC,KAAJ,CAAU,mEAAV,EAA+ED,QAA/E;;AAEA,gBAAIA,WAAW,CAAf,EAAkB;AACd;AACA,oBAAIE,WAAWF,WAAW,KAAKP,oCAA/B;AACA,oBAAIS,YAAY,CAAhB,EAAkB;AACdA,+BAAW,CAAX;AACH;;AAEDtgC,yBAAIqgC,KAAJ,CAAU,wDAAV,EAAoEC,QAApE;AACA,qBAAKR,oBAAL,CAA0B78B,IAA1B,CAA+Bq9B,QAA/B;AACH,aATD,MAUK;AACDtgC,yBAAIqgC,KAAJ,CAAU,yFAAV;AACA,qBAAKP,oBAAL,CAA0BS,MAA1B;AACH;;AAED;AACA,gBAAIC,UAAUJ,WAAW,CAAzB;AACApgC,qBAAIqgC,KAAJ,CAAU,uDAAV,EAAmEG,OAAnE;AACA,iBAAKT,mBAAL,CAAyB98B,IAAzB,CAA8Bu9B,OAA9B;AACH,SAvBD,MAwBK;AACD,iBAAKV,oBAAL,CAA0BS,MAA1B;AACA,iBAAKR,mBAAL,CAAyBQ,MAAzB;AACH;AACJ,K;;gCAEDE,M,qBAAS;AACLzgC,iBAAIqgC,KAAJ,CAAU,kEAAV;AACA,aAAKP,oBAAL,CAA0BS,MAA1B;AACA,aAAKR,mBAAL,CAAyBQ,MAAzB;AACH,K;;gCAEDG,sB,mCAAuBC,E,EAAI;AACvB,aAAKb,oBAAL,CAA0Bc,UAA1B,CAAqCD,EAArC;AACH,K;;gCACDE,yB,sCAA0BF,E,EAAI;AAC1B,aAAKb,oBAAL,CAA0BgB,aAA1B,CAAwCH,EAAxC;AACH,K;;gCAEDI,qB,kCAAsBJ,E,EAAI;AACtB,aAAKZ,mBAAL,CAAyBa,UAAzB,CAAoCD,EAApC;AACH,K;;gCACDK,wB,qCAAyBL,E,EAAI;AACzB,aAAKZ,mBAAL,CAAyBe,aAAzB,CAAuCH,EAAvC;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACpEL;;0JAHA;AACA;;AAIA,IAAMM,kBAAkB,IAAxB;;IAEavgC,kB,WAAAA,kB;AACT,gCAAYwgC,QAAZ,EAAsBC,SAAtB,EAAiCC,GAAjC,EAAsCC,QAAtC,EAAoE;AAAA,YAApBC,WAAoB,uEAAN,IAAM;;AAAA;;AAChE,aAAKC,SAAL,GAAiBL,QAAjB;AACA,aAAKM,UAAL,GAAkBL,SAAlB;AACA,aAAKM,IAAL,GAAYL,GAAZ;AACA,aAAKM,SAAL,GAAiBL,YAAYJ,eAA7B;AACA,aAAKU,YAAL,GAAoBL,WAApB;;AAEA,YAAIM,MAAMR,IAAI15B,OAAJ,CAAY,GAAZ,EAAiB05B,IAAI15B,OAAJ,CAAY,IAAZ,IAAoB,CAArC,CAAV;AACA,aAAKm6B,aAAL,GAAqBT,IAAIv8B,MAAJ,CAAW,CAAX,EAAc+8B,GAAd,CAArB;;AAEA,aAAKE,MAAL,GAAc7gC,OAAO8gC,QAAP,CAAgBC,aAAhB,CAA8B,QAA9B,CAAd;;AAEA;AACA,aAAKF,MAAL,CAAYG,KAAZ,CAAkBC,UAAlB,GAA+B,QAA/B;AACA,aAAKJ,MAAL,CAAYG,KAAZ,CAAkBE,QAAlB,GAA6B,UAA7B;AACA,aAAKL,MAAL,CAAYG,KAAZ,CAAkBG,OAAlB,GAA4B,MAA5B;AACA,aAAKN,MAAL,CAAYG,KAAZ,CAAkBI,KAAlB,GAA0B,CAA1B;AACA,aAAKP,MAAL,CAAYG,KAAZ,CAAkBK,MAAlB,GAA2B,CAA3B;;AAEA,aAAKR,MAAL,CAAYS,GAAZ,GAAkBnB,GAAlB;AACH;;iCACDpB,I,mBAAO;AAAA;;AACH,eAAO,IAAIwC,OAAJ,CAAY,UAACC,OAAD,EAAa;AAC5B,kBAAKX,MAAL,CAAYY,MAAZ,GAAqB,YAAM;AACvBD;AACH,aAFD;;AAIAxhC,mBAAO8gC,QAAP,CAAgBY,IAAhB,CAAqBC,WAArB,CAAiC,MAAKd,MAAtC;AACA,kBAAKe,kBAAL,GAA0B,MAAKC,QAAL,CAAcC,IAAd,CAAmB,KAAnB,CAA1B;AACA9hC,mBAAO+hC,gBAAP,CAAwB,SAAxB,EAAmC,MAAKH,kBAAxC,EAA4D,KAA5D;AACH,SARM,CAAP;AASH,K;;iCACDC,Q,qBAAS9gC,C,EAAG;AACR,YAAIA,EAAEihC,MAAF,KAAa,KAAKpB,aAAlB,IACA7/B,EAAEkhC,MAAF,KAAa,KAAKpB,MAAL,CAAYqB,aAD7B,EAEE;AACE,gBAAInhC,EAAEsyB,IAAF,KAAW,OAAf,EAAwB;AACpBt0B,yBAAIojC,KAAJ,CAAU,gEAAV;AACA,oBAAI,KAAKzB,YAAT,EAAuB;AACnB,yBAAK0B,IAAL;AACH;AACJ,aALD,MAMK,IAAIrhC,EAAEsyB,IAAF,KAAW,SAAf,EAA0B;AAC3Bt0B,yBAAIqgC,KAAJ,CAAU,kEAAV;AACA,qBAAKgD,IAAL;AACA,qBAAK9B,SAAL;AACH,aAJI,MAKA;AACDvhC,yBAAIqgC,KAAJ,CAAU,yBAAyBr+B,EAAEsyB,IAA3B,GAAkC,uCAA5C;AACH;AACJ;AACJ,K;;iCACDgP,K,kBAAMC,a,EAAe;AAAA;;AACjB,YAAI,KAAKC,cAAL,KAAwBD,aAA5B,EAA2C;AACvCvjC,qBAAIqgC,KAAJ,CAAU,0BAAV;;AAEA,iBAAKgD,IAAL;;AAEA,iBAAKG,cAAL,GAAsBD,aAAtB;;AAEA,gBAAIE,OAAO,SAAPA,IAAO,GAAM;AACb,uBAAK3B,MAAL,CAAYqB,aAAZ,CAA0BO,WAA1B,CAAsC,OAAKlC,UAAL,GAAkB,GAAlB,GAAwB,OAAKgC,cAAnE,EAAmF,OAAK3B,aAAxF;AACH,aAFD;;AAIA;AACA4B;;AAEA;AACA,iBAAKE,MAAL,GAAc1iC,OAAO2iC,WAAP,CAAmBH,IAAnB,EAAyB,KAAK/B,SAA9B,CAAd;AACH;AACJ,K;;iCAED2B,I,mBAAO;AACH,aAAKG,cAAL,GAAsB,IAAtB;;AAEA,YAAI,KAAKG,MAAT,EAAiB;AACb3jC,qBAAIqgC,KAAJ,CAAU,yBAAV;;AAEAp/B,mBAAO4iC,aAAP,CAAqB,KAAKF,MAA1B;AACA,iBAAKA,MAAL,GAAc,IAAd;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;ACtFL;;0JAHA;AACA;;IAIaljC,sB,WAAAA,sB;;;;;qCAETqjC,O,oBAAQC,M,EAAQ;AACZA,eAAOC,mBAAP,GAA6B,YAA7B;AACA,YAAIC,QAAQ,IAAIC,sCAAJ,CAAuBH,MAAvB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBwB,KAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACRL;;0JAHA;AACA;;IAIazjC,qB,WAAAA,qB;;;;;oCAETsjC,O,oBAAQC,M,EAAQ;AACZ,YAAIE,QAAQ,IAAIC,sCAAJ,CAAuBH,MAAvB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBwB,KAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCVL;AACA;;AAEA;;;;AAEA,IAAME,uBAAuB,gCAA7B;AACA,IAAMC,qBAAqB,QAA3B;;IAEaF,kB,WAAAA,kB;AAET,gCAAYH,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI7B,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgB9B,OAAhB;AACA,kBAAK+B,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,aAAKG,QAAL,GAAgBV,OAAOC,mBAAP,IAA8BG,oBAA9C;AACA,aAAKO,MAAL,GAAcX,OAAOY,iBAAP,IAA4BP,kBAA1C;;AAEA,aAAKQ,YAAL,GAAoBb,OAAOc,QAA3B;AACA7kC,iBAAIqgC,KAAJ,CAAU,4CAA4C,KAAKuE,YAA3D;AACH;;iCAEDE,wB,qCAAyBC,e,EAAiB;AACtC,eAAO,CAAC,6BAAD,EAAgC,0CAAhC,EAA4E,iCAA5E,EAA+GC,IAA/G,CAAoH,UAAU9gB,IAAV,EAAgB;AACvI,mBAAO6gB,gBAAgB/hC,cAAhB,CAA+BkhB,IAA/B,CAAP;AACH,SAFM,CAAP;AAGH,K;;iCAED+gB,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AACxB,iBAAK8D,MAAL,CAAY,iBAAZ;AACH,SAFD,MAEO;AACH,gBAAI,CAACjkC,OAAOkkC,OAAZ,EAAqB;AACjB,uBAAO,KAAKD,MAAL,CAAY,sBAAZ,CAAP;AACH;;AAED,gBAAIH,kBAAkB9jC,OAAOkkC,OAAP,CAAeC,OAAf,CAAuB,qBAAvB,EAA8CC,QAApE;AACA,gBAAI,KAAKP,wBAAL,CAA8BC,eAA9B,MAAmD,KAAvD,EAA8D;AAC1D,uBAAO,KAAKG,MAAL,CAAY,+BAAZ,CAAP;AACH;AACD,iBAAKI,MAAL,GAAcH,QAAQI,YAAR,CAAqBC,IAArB,CAA0BzB,OAAO3C,GAAjC,EAAsC,KAAKsD,MAA3C,EAAmD,KAAKD,QAAxD,CAAd;AACA,gBAAI,KAAKa,MAAT,EAAiB;AACbtlC,yBAAIqgC,KAAJ,CAAU,yDAAV;;AAEA,qBAAKoF,kBAAL,GAA0B,KAAKC,aAAL,CAAmB3C,IAAnB,CAAwB,IAAxB,CAA1B;AACA,qBAAK4C,uBAAL,GAA+B,KAAKC,kBAAL,CAAwB7C,IAAxB,CAA6B,IAA7B,CAA/B;;AAEA,qBAAKuC,MAAL,CAAYtC,gBAAZ,CAA6B,MAA7B,EAAqC,KAAKyC,kBAA1C,EAA8D,KAA9D;AACA,qBAAKH,MAAL,CAAYtC,gBAAZ,CAA6B,WAA7B,EAA0C,KAAK2C,uBAA/C,EAAwE,KAAxE;AACH,aARD,MAQO;AACH,qBAAKT,MAAL,CAAY,4BAAZ;AACH;AACJ;AACD,eAAO,KAAKW,OAAZ;AACH,K;;iCAMDD,kB,+BAAmBE,K,EAAO;AACtB,YAAIA,MAAM1E,GAAN,CAAU15B,OAAV,CAAkB,KAAKk9B,YAAvB,MAAyC,CAA7C,EAAgD;AAC5C,iBAAKmB,QAAL,CAAc,EAAE3E,KAAK0E,MAAM1E,GAAb,EAAd;AACH;AACJ,K;;iCACDsE,a,0BAAcM,O,EAAS;AACnB,aAAKd,MAAL,CAAYc,OAAZ;AACH,K;;iCAEDD,Q,qBAASzR,I,EAAM;AACX,aAAK2R,QAAL;;AAEAjmC,iBAAIqgC,KAAJ,CAAU,mEAAV;AACA,aAAKkE,QAAL,CAAcjQ,IAAd;AACH,K;;iCACD4Q,M,mBAAOc,O,EAAS;AACZ,aAAKC,QAAL;;AAEAjmC,iBAAIojC,KAAJ,CAAU4C,OAAV;AACA,aAAKxB,OAAL,CAAa,IAAI/iC,KAAJ,CAAUukC,OAAV,CAAb;AACH,K;;iCAEDE,K,oBAAQ;AACJ,aAAKD,QAAL;AACH,K;;iCAEDA,Q,uBAAW;AACP,YAAI,KAAKX,MAAT,EAAgB;AACZtlC,qBAAIqgC,KAAJ,CAAU,uCAAV;AACA,iBAAKiF,MAAL,CAAYa,mBAAZ,CAAgC,MAAhC,EAAwC,KAAKV,kBAA7C,EAAiE,KAAjE;AACA,iBAAKH,MAAL,CAAYa,mBAAZ,CAAgC,WAAhC,EAA6C,KAAKR,uBAAlD,EAA2E,KAA3E;AACA,iBAAKL,MAAL,CAAYY,KAAZ;AACH;AACD,aAAKZ,MAAL,GAAc,IAAd;AACH,K;;;;4BAtCa;AACV,mBAAO,KAAKjB,QAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;ACxDL;;;;;;+eAHA;AACA;;IAIa+B,a,WAAAA,a;;;AACT,iCACE;AAAA,+FADsE,EACtE;AAAA,oBADWhD,KACX,QADWA,KACX;AAAA,oBADkBiD,iBAClB,QADkBA,iBAClB;AAAA,oBADqCC,SACrC,QADqCA,SACrC;AAAA,oBADgD5W,KAChD,QADgDA,KAChD;AAAA,oBADuD6T,aACvD,QADuDA,aACvD;;AAAA;;AACG,oBAAI,CAACH,KAAL,EAAW;AACRpjC,iCAAIojC,KAAJ,CAAU,kCAAV;AACA,8BAAM,IAAI3hC,KAAJ,CAAU,OAAV,CAAN;AACH;;AAJH,6DAME,kBAAM4kC,qBAAqBjD,KAA3B,CANF;;AAQE,sBAAKlf,IAAL,GAAY,eAAZ;;AAEA,sBAAKkf,KAAL,GAAaA,KAAb;AACA,sBAAKiD,iBAAL,GAAyBA,iBAAzB;AACA,sBAAKC,SAAL,GAAiBA,SAAjB;;AAEA,sBAAK5W,KAAL,GAAaA,KAAb;AACA,sBAAK6T,aAAL,GAAqBA,aAArB;AAfF;AAgBD;;;EAlB8B9hC,K;;;;;;;;;;;;;;;;;;;ACFnC;;0JAHA;AACA;;IAIa8kC,K,WAAAA,K;AAET,mBAAYriB,IAAZ,EAAkB;AAAA;;AACd,aAAKsiB,KAAL,GAAatiB,IAAb;AACA,aAAKuiB,UAAL,GAAkB,EAAlB;AACH;;oBAED7F,U,uBAAWD,E,EAAI;AACX,aAAK8F,UAAL,CAAgBniC,IAAhB,CAAqBq8B,EAArB;AACH,K;;oBAEDG,a,0BAAcH,E,EAAI;AACd,YAAIiB,MAAM,KAAK6E,UAAL,CAAgBC,SAAhB,CAA0B;AAAA,mBAAQC,SAAShG,EAAjB;AAAA,SAA1B,CAAV;AACA,YAAIiB,OAAO,CAAX,EAAc;AACV,iBAAK6E,UAAL,CAAgBngC,MAAhB,CAAuBs7B,GAAvB,EAA4B,CAA5B;AACH;AACJ,K;;oBAEDgF,K,oBAAiB;AACb5mC,iBAAIqgC,KAAJ,CAAU,2BAA2B,KAAKmG,KAA1C;AACA,aAAK,IAAIpkC,IAAI,CAAb,EAAgBA,IAAI,KAAKqkC,UAAL,CAAgBpkC,MAApC,EAA4CD,GAA5C,EAAiD;AAAA;;AAC7C,+BAAKqkC,UAAL,EAAgBrkC,CAAhB;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;;;;AC5BL;AACA;;AAEA,IAAMykC,QAAQ;AACVjD;AAAA;AAAA;AAAA;;AAAA;AAAA;AAAA;;AAAA;AAAA,MAAa,UAAUjD,EAAV,EAAcP,QAAd,EAAwB;AACjC,eAAOwD,YAAYjD,EAAZ,EAAgBP,QAAhB,CAAP;AACH,KAFD,CADU;AAIVyD;AAAA;AAAA;AAAA;;AAAA;AAAA;AAAA;;AAAA;AAAA,MAAe,UAAUiD,MAAV,EAAkB;AAC7B,eAAOjD,cAAciD,MAAd,CAAP;AACH,KAFD;AAJU,CAAd;;AASA,IAAIC,UAAU,KAAd;AACA,IAAIC,UAAU,IAAd;;IAEanmC,M,WAAAA,M;;;;;WAEFomC,Q,uBAAW;AACdF,kBAAU,IAAV;AACH,K;;WAoBMG,iB,8BAAkBC,U,EAAY;AACjCH,kBAAUG,UAAV;AACH,K;;;;4BApBqB;AAClB,gBAAI,CAACJ,OAAL,EAAc;AACV,uBAAOK,QAAP;AACH;AACJ;;;4BAEyB;AACtB,gBAAI,CAACL,OAAD,IAAY,OAAO9lC,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAOomC,YAAP;AACH;AACJ;;;4BAE2B;AACxB,gBAAI,CAACN,OAAD,IAAY,OAAO9lC,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAOqmC,cAAP;AACH;AACJ;;;4BAM2B;AACxB,gBAAI,CAACP,OAAD,IAAY,OAAO9lC,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAO+lC,WAAWO,cAAlB;AACH;AACJ;;;4BAEkB;AACf,gBAAI,CAACR,OAAL,EAAc;AACV,uBAAOF,KAAP;AACH;AACJ;;;;;;;;;;;;;;;;;;;;;;;AClDL;;AACA;;0JAJA;AACA;;IAKaW,e,WAAAA,e;;;;;8BAET1D,O,oBAAQC,M,EAAQ;AACZ,YAAI0D,QAAQ,IAAIC,0BAAJ,CAAiB3D,MAAjB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBgF,KAAhB,CAAP;AACH,K;;8BAEDvG,Q,qBAASE,G,EAAK;AACVphC,iBAAIqgC,KAAJ,CAAU,0BAAV;;AAEA,YAAI;AACAqH,uCAAaC,YAAb,CAA0BvG,GAA1B;AACA,mBAAOoB,QAAQC,OAAR,EAAP;AACH,SAHD,CAIA,OAAOzgC,CAAP,EAAU;AACN,mBAAOwgC,QAAQ8B,MAAR,CAAetiC,CAAf,CAAP;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;qjBCvBL;AACA;;AAEA;;;;AAEA,IAAM4lC,iBAAiB,KAAvB;;IAEaF,Y,WAAAA,Y;AAET,0BAAY3D,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI7B,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgB9B,OAAhB;AACA,kBAAK+B,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,aAAKzB,kBAAL,GAA0B,KAAKC,QAAL,CAAcC,IAAd,CAAmB,IAAnB,CAA1B;AACA9hC,eAAO+hC,gBAAP,CAAwB,SAAxB,EAAmC,KAAKH,kBAAxC,EAA4D,KAA5D;;AAEA,aAAKf,MAAL,GAAc7gC,OAAO8gC,QAAP,CAAgBC,aAAhB,CAA8B,QAA9B,CAAd;;AAEA;AACA,aAAKF,MAAL,CAAYG,KAAZ,CAAkBC,UAAlB,GAA+B,QAA/B;AACA,aAAKJ,MAAL,CAAYG,KAAZ,CAAkBE,QAAlB,GAA6B,UAA7B;AACA,aAAKL,MAAL,CAAYG,KAAZ,CAAkBG,OAAlB,GAA4B,MAA5B;AACA,aAAKN,MAAL,CAAYG,KAAZ,CAAkBI,KAAlB,GAA0B,CAA1B;AACA,aAAKP,MAAL,CAAYG,KAAZ,CAAkBK,MAAlB,GAA2B,CAA3B;;AAEArhC,eAAO8gC,QAAP,CAAgBY,IAAhB,CAAqBC,WAArB,CAAiC,KAAKd,MAAtC;AACH;;2BAEDmD,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AACxB,iBAAK8D,MAAL,CAAY,iBAAZ;AACH,SAFD,MAGK;AACD,gBAAI2C,UAAU9D,OAAO+D,oBAAP,IAA+BF,cAA7C;AACA5nC,qBAAIqgC,KAAJ,CAAU,0CAAV,EAAsDwH,OAAtD;AACA,iBAAKlE,MAAL,GAAc1iC,OAAO8mC,UAAP,CAAkB,KAAKC,QAAL,CAAcjF,IAAd,CAAmB,IAAnB,CAAlB,EAA4C8E,OAA5C,CAAd;AACA,iBAAK/F,MAAL,CAAYS,GAAZ,GAAkBwB,OAAO3C,GAAzB;AACH;;AAED,eAAO,KAAKyE,OAAZ;AACH,K;;2BAMDE,Q,qBAASzR,I,EAAM;AACX,aAAK2R,QAAL;;AAEAjmC,iBAAIqgC,KAAJ,CAAU,qDAAV;AACA,aAAKkE,QAAL,CAAcjQ,IAAd;AACH,K;;2BACD4Q,M,mBAAOc,O,EAAS;AACZ,aAAKC,QAAL;;AAEAjmC,iBAAIojC,KAAJ,CAAU4C,OAAV;AACA,aAAKxB,OAAL,CAAa,IAAI/iC,KAAJ,CAAUukC,OAAV,CAAb;AACH,K;;2BAEDE,K,oBAAQ;AACJ,aAAKD,QAAL;AACH,K;;2BAEDA,Q,uBAAW;AACP,YAAI,KAAKnE,MAAT,EAAiB;AACb9hC,qBAAIqgC,KAAJ,CAAU,uBAAV;;AAEAp/B,mBAAOklC,mBAAP,CAA2B,SAA3B,EAAsC,KAAKtD,kBAA3C,EAA+D,KAA/D;AACA5hC,mBAAOgnC,YAAP,CAAoB,KAAKtE,MAAzB;AACA1iC,mBAAO8gC,QAAP,CAAgBY,IAAhB,CAAqBuF,WAArB,CAAiC,KAAKpG,MAAtC;;AAEA,iBAAK6B,MAAL,GAAc,IAAd;AACA,iBAAK7B,MAAL,GAAc,IAAd;AACA,iBAAKe,kBAAL,GAA0B,IAA1B;AACH;AACJ,K;;2BAEDmF,Q,uBAAW;AACPhoC,iBAAIqgC,KAAJ,CAAU,sBAAV;AACA,aAAK6E,MAAL,CAAY,wBAAZ;AACH,K;;2BAEDpC,Q,qBAAS9gC,C,EAAG;AACRhC,iBAAIqgC,KAAJ,CAAU,sBAAV;;AAEA,YAAI,KAAKsD,MAAL,IACA3hC,EAAEihC,MAAF,KAAa,KAAKkF,OADlB,IAEAnmC,EAAEkhC,MAAF,KAAa,KAAKpB,MAAL,CAAYqB,aAF7B,EAGE;AACE,gBAAI/B,MAAMp/B,EAAEsyB,IAAZ;AACA,gBAAI8M,GAAJ,EAAS;AACL,qBAAK2E,QAAL,CAAc,EAAE3E,KAAKA,GAAP,EAAd;AACH,aAFD,MAGK;AACD,qBAAK8D,MAAL,CAAY,6BAAZ;AACH;AACJ;AACJ,K;;iBAMMyC,Y,yBAAavG,G,EAAK;AACrBphC,iBAAIqgC,KAAJ,CAAU,2BAAV;AACA,YAAIp/B,OAAOmnC,YAAX,EAAyB;AACrBhH,kBAAMA,OAAOngC,OAAOmmC,QAAP,CAAgBiB,IAA7B;AACA,gBAAIjH,GAAJ,EAAS;AACLphC,yBAAIqgC,KAAJ,CAAU,0DAAV;AACAp/B,uBAAOqnC,MAAP,CAAc5E,WAAd,CAA0BtC,GAA1B,EAA+BgG,SAASmB,QAAT,GAAoB,IAApB,GAA2BnB,SAASoB,IAAnE;AACH;AACJ;AACJ,K;;;;4BAtEa;AACV,mBAAO,KAAKnE,QAAZ;AACH;;;4BAuDa;AACV,mBAAO+C,SAASmB,QAAT,GAAoB,IAApB,GAA2BnB,SAASoB,IAA3C;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBCvGL;AACA;;AAEA;;;;IAEapoC,kB,WAAAA,kB;AACT,kCAAa;AAAA;;AACT,aAAKqF,KAAL,GAAa,EAAb;AACH;;iCAEDgjC,O,oBAAQ3U,G,EAAK;AACT9zB,iBAAIqgC,KAAJ,CAAU,4BAAV,EAAwCvM,GAAxC;AACA,eAAO,KAAKruB,KAAL,CAAWquB,GAAX,CAAP;AACH,K;;iCAED4U,O,oBAAQ5U,G,EAAK6U,K,EAAM;AACf3oC,iBAAIqgC,KAAJ,CAAU,4BAAV,EAAwCvM,GAAxC;AACA,aAAKruB,KAAL,CAAWquB,GAAX,IAAkB6U,KAAlB;AACH,K;;iCAEDC,U,uBAAW9U,G,EAAI;AACX9zB,iBAAIqgC,KAAJ,CAAU,+BAAV,EAA2CvM,GAA3C;AACA,eAAO,KAAKruB,KAAL,CAAWquB,GAAX,CAAP;AACH,K;;iCAMDA,G,gBAAI+U,K,EAAO;AACP,eAAO/mC,OAAOgnC,mBAAP,CAA2B,KAAKrjC,KAAhC,EAAuCojC,KAAvC,CAAP;AACH,K;;;;4BANY;AACT,mBAAO/mC,OAAOgnC,mBAAP,CAA2B,KAAKrjC,KAAhC,EAAuCpD,MAA9C;AACH;;;;;;;;;;;;;;;;;;;;;;;AC3BL;;AACA;;;;;;AAEO,IAAM0mC,8BAAW,4BAAY,EAAE9M,mBAAF,EAAO+M,2BAAP,EAAgBnS,qBAAhB,EAAsBpe,yBAAtB,EAA8BmO,+BAA9B,EAAyChc,6BAAzC,EAAmDq+B,iDAAnD,EAAZ,CAAjB,C;;;;;;;;;;;;;;;;;kBCEiBC,W;;AAFxB;;0JAHA;AACA;;AAIe,SAASA,WAAT,OAA8F;AAAA,QAAvEjN,GAAuE,QAAvEA,GAAuE;AAAA,QAAlE+M,OAAkE,QAAlEA,OAAkE;AAAA,QAAzDnS,IAAyD,QAAzDA,IAAyD;AAAA,QAAnDpe,MAAmD,QAAnDA,MAAmD;AAAA,QAA3CmO,SAA2C,QAA3CA,SAA2C;AAAA,QAAhChc,QAAgC,QAAhCA,QAAgC;AAAA,QAAtBq+B,kBAAsB,QAAtBA,kBAAsB;;AACzG;AAAA;AAAA;AAAA;;AAAA,iBAEWE,QAFX,qBAEoBC,GAFpB,EAEyB;AACjBppC,qBAAIqgC,KAAJ,CAAU,mBAAV;AACA,gBAAI;AACA,oBAAIgJ,QAAQpN,IAAIC,GAAJ,CAAQv3B,KAAR,CAAcykC,GAAd,CAAZ;AACA,uBAAO;AACHE,4BAAQD,MAAMpM,SADX;AAEHsM,6BAASF,MAAMnM;AAFZ,iBAAP;AAIH,aAND,CAME,OAAOl7B,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,CAAV;AACH;AACJ,SAbL;;AAAA,iBAeWwnC,WAfX,wBAeuBJ,GAfvB,EAe4BtV,GAf5B,EAeiC2V,MAfjC,EAeyCC,QAfzC,EAemDC,SAfnD,EAe8DC,GAf9D,EAemEC,eAfnE,EAeoF;AAC5E7pC,qBAAIqgC,KAAJ,CAAU,sBAAV;;AAEA,gBAAI;AACA,oBAAIvM,IAAIuC,GAAJ,KAAY,KAAhB,EAAuB;AACnB,wBAAIvC,IAAI9xB,CAAJ,IAAS8xB,IAAIlxB,CAAjB,EAAoB;AAChBkxB,8BAAMkV,QAAQxZ,MAAR,CAAesE,GAAf,CAAN;AACH,qBAFD,MAEO,IAAIA,IAAIgW,GAAJ,IAAWhW,IAAIgW,GAAJ,CAAQznC,MAAvB,EAA+B;AAClC,4BAAIuf,MAAMhX,SAASkpB,IAAIgW,GAAJ,CAAQ,CAAR,CAAT,CAAV;AACAhW,8BAAM+C,KAAKC,uBAAL,CAA6BlV,GAA7B,CAAN;AACH,qBAHM,MAGA;AACH5hB,iCAAIojC,KAAJ,CAAU,oDAAV,EAAgEtP,GAAhE;AACA,+BAAO0O,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,8BAAV,CAAf,CAAP;AACH;AACJ,iBAVD,MAUO,IAAIqyB,IAAIuC,GAAJ,KAAY,IAAhB,EAAsB;AACzB,wBAAIvC,IAAI8C,GAAJ,IAAW9C,IAAIhuB,CAAf,IAAoBguB,IAAIrqB,CAA5B,EAA+B;AAC3BqqB,8BAAMkV,QAAQxZ,MAAR,CAAesE,GAAf,CAAN;AACH,qBAFD,MAEO;AACH9zB,iCAAIojC,KAAJ,CAAU,mDAAV,EAA+DtP,GAA/D;AACA,+BAAO0O,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACJ,iBAPM,MAOA;AACHzB,6BAAIojC,KAAJ,CAAU,4CAAV,EAAwDtP,OAAOA,IAAIuC,GAAnE;AACA,2BAAOmM,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,SAAkCqyB,IAAIuC,GAAhD,CAAf,CAAP;AACH;;AAED,uBAAO0S,SAASgB,YAAT,CAAsBX,GAAtB,EAA2BtV,GAA3B,EAAgC2V,MAAhC,EAAwCC,QAAxC,EAAkDC,SAAlD,EAA6DC,GAA7D,EAAkEC,eAAlE,CAAP;AACH,aAxBD,CAwBE,OAAO7nC,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,KAAKA,EAAEgkC,OAAP,IAAkBhkC,CAA5B;AACA,uBAAOwgC,QAAQ8B,MAAR,CAAe,uBAAf,CAAP;AACH;AACJ,SA9CL;;AAAA,iBAgDW0F,qBAhDX,kCAgDiCZ,GAhDjC,EAgDsCK,MAhDtC,EAgD8CC,QAhD9C,EAgDwDC,SAhDxD,EAgDmEC,GAhDnE,EAgDwEC,eAhDxE,EAgDyF;AACjF,gBAAI,CAACF,SAAL,EAAgB;AACZA,4BAAY,CAAZ;AACH;;AAED,gBAAI,CAACC,GAAL,EAAU;AACNA,sBAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAN;AACH;;AAED,gBAAIL,UAAUR,SAASI,QAAT,CAAkBC,GAAlB,EAAuBG,OAArC;;AAEA,gBAAI,CAACA,QAAQ9L,GAAb,EAAkB;AACdz9B,yBAAIojC,KAAJ,CAAU,gDAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;AACD,gBAAI8nC,QAAQ9L,GAAR,KAAgBgM,MAApB,EAA4B;AACxBzpC,yBAAIojC,KAAJ,CAAU,gDAAV,EAA4DmG,QAAQ9L,GAApE;AACA,uBAAO+E,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,8BAA8B8nC,QAAQ9L,GAAhD,CAAf,CAAP;AACH;;AAED,gBAAI,CAAC8L,QAAQ5L,GAAb,EAAkB;AACd39B,yBAAIojC,KAAJ,CAAU,6CAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,gBAAIwoC,gBAAgBV,QAAQ5L,GAAR,KAAgB+L,QAAhB,IAA6B3+B,MAAM4nB,OAAN,CAAc4W,QAAQ5L,GAAtB,KAA8B4L,QAAQ5L,GAAR,CAAYj2B,OAAZ,CAAoBgiC,QAApB,KAAiC,CAAhH;AACA,gBAAI,CAACO,aAAL,EAAoB;AAChBjqC,yBAAIojC,KAAJ,CAAU,kDAAV,EAA8DmG,QAAQ5L,GAAtE;AACA,uBAAO6E,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gCAAgC8nC,QAAQ5L,GAAlD,CAAf,CAAP;AACH;AACD,gBAAI4L,QAAQW,GAAR,IAAeX,QAAQW,GAAR,KAAgBR,QAAnC,EAA6C;AACzC1pC,yBAAIojC,KAAJ,CAAU,6CAAV,EAAyDmG,QAAQW,GAAjE;AACA,uBAAO1H,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAA2B8nC,QAAQW,GAA7C,CAAf,CAAP;AACH;;AAED,gBAAI,CAACL,eAAL,EAAsB;AAClB,oBAAIM,WAAWP,MAAMD,SAArB;AACA,oBAAIS,WAAWR,MAAMD,SAArB;;AAEA,oBAAI,CAACJ,QAAQtL,GAAb,EAAkB;AACdj+B,6BAAIojC,KAAJ,CAAU,6CAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,oBAAI0oC,WAAWZ,QAAQtL,GAAvB,EAA4B;AACxBj+B,6BAAIojC,KAAJ,CAAU,6CAAV,EAAyDmG,QAAQtL,GAAjE;AACA,2BAAOuE,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAA2B8nC,QAAQtL,GAA7C,CAAf,CAAP;AACH;;AAED,oBAAIsL,QAAQvL,GAAR,IAAemM,WAAWZ,QAAQvL,GAAtC,EAA2C;AACvCh+B,6BAAIojC,KAAJ,CAAU,6CAAV,EAAyDmG,QAAQvL,GAAjE;AACA,2BAAOwE,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAA2B8nC,QAAQvL,GAA7C,CAAf,CAAP;AACH;;AAED,oBAAI,CAACuL,QAAQ74B,GAAb,EAAkB;AACd1Q,6BAAIojC,KAAJ,CAAU,6CAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQ74B,GAAR,GAAc05B,QAAlB,EAA4B;AACxBpqC,6BAAIojC,KAAJ,CAAU,2CAAV,EAAuDmG,QAAQ74B,GAA/D;AACA,2BAAO8xB,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,wBAAwB8nC,QAAQ74B,GAA1C,CAAf,CAAP;AACH;AACJ;;AAED,mBAAO8xB,QAAQC,OAAR,CAAgB8G,OAAhB,CAAP;AACH,SA/GL;;AAAA,iBAiHWQ,YAjHX,yBAiHwBX,GAjHxB,EAiH6BtV,GAjH7B,EAiHkC2V,MAjHlC,EAiH0CC,QAjH1C,EAiHoDC,SAjHpD,EAiH+DC,GAjH/D,EAiHoEC,eAjHpE,EAiHqF;;AAE7E,mBAAOd,SAASiB,qBAAT,CAA+BZ,GAA/B,EAAoCK,MAApC,EAA4CC,QAA5C,EAAsDC,SAAtD,EAAiEC,GAAjE,EAAsEC,eAAtE,EAAuFQ,IAAvF,CAA4F,mBAAW;AAC1G,oBAAI;AACA,wBAAI,CAACpO,IAAIC,GAAJ,CAAQ1L,MAAR,CAAe4Y,GAAf,EAAoBtV,GAApB,EAAyBmV,kBAAzB,CAAL,EAAmD;AAC/CjpC,iCAAIojC,KAAJ,CAAU,oDAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;;AAED,2BAAO8nC,OAAP;AACH,iBAPD,CAOE,OAAOvnC,CAAP,EAAU;AACRhC,6BAAIojC,KAAJ,CAAUphC,KAAKA,EAAEgkC,OAAP,IAAkBhkC,CAA5B;AACA,2BAAOwgC,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACJ,aAZM,CAAP;AAaH,SAhIL;;AAAA,iBAkIWkrB,UAlIX,uBAkIsBgc,KAlItB,EAkI6B/b,GAlI7B,EAkIkC;AAC1B,gBAAI;AACA,uBAAOnU,OAAOiB,IAAP,CAAYiT,UAAZ,CAAuBgc,KAAvB,EAA8B/b,GAA9B,CAAP;AACH,aAFD,CAEE,OAAO5qB,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,CAAV;AACH;AACJ,SAxIL;;AAAA,iBA0IWsoC,cA1IX,2BA0I0B3B,KA1I1B,EA0IiC;AACzB,gBAAI;AACA,uBAAO/hB,UAAU+hB,KAAV,CAAP;AACH,aAFD,CAEE,OAAO3mC,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,CAAV;AACH;AACJ,SAhJL;;AAAA;AAAA;AAkJH;;;;;;;;;;;;;;;;;;;;ACrJD;;AACA;;0JAJA;AACA;;IAKauoC,W,WAAAA,W;AACT,2BAIE;AAAA,YAHEC,sBAGF,uEAH2B,IAG3B;AAAA,YAFEC,kBAEF,uEAFuB5pC,eAAO0mC,cAE9B;AAAA,YADEmD,UACF,uEADe,IACf;;AAAA;;AACE,YAAIF,0BAA0Bz/B,MAAM4nB,OAAN,CAAc6X,sBAAd,CAA9B,EACA;AACI,iBAAKG,aAAL,GAAqBH,uBAAuBpmC,KAAvB,EAArB;AACH,SAHD,MAKA;AACI,iBAAKumC,aAAL,GAAqB,EAArB;AACH;AACD,aAAKA,aAAL,CAAmBrmC,IAAnB,CAAwB,kBAAxB;AACA,YAAIomC,UAAJ,EAAgB;AACZ,iBAAKC,aAAL,CAAmBrmC,IAAnB,CAAwB,iBAAxB;AACH;;AAED,aAAKsmC,eAAL,GAAuBH,kBAAvB;AACA,aAAKI,WAAL,GAAmBH,UAAnB;AACH;;0BAEDI,O,oBAAQ1J,G,EAAKiI,K,EAAO;AAAA;;AAChB,YAAI,CAACjI,GAAL,EAAS;AACLphC,qBAAIojC,KAAJ,CAAU,oCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,4BAAV,EAAwCe,GAAxC;;AAEA,eAAO,IAAIoB,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;;AAEpC,gBAAIyG,MAAM,IAAI,MAAKH,eAAT,EAAV;AACAG,gBAAIvF,IAAJ,CAAS,KAAT,EAAgBpE,GAAhB;;AAEA,gBAAI4J,sBAAsB,MAAKL,aAA/B;AACA,gBAAID,aAAa,MAAKG,WAAtB;;AAEAE,gBAAIrI,MAAJ,GAAa,YAAW;AACpB1iC,yBAAIqgC,KAAJ,CAAU,qDAAV,EAAiE0K,IAAIE,MAArE;;AAEA,oBAAIF,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuB3E,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAIyE,SAAS,iBAAb,EAAgC;AAC5BV,uCAAWK,GAAX,EAAgBV,IAAhB,CAAqB5H,OAArB,EAA8B6B,MAA9B;AACA;AACH;;AAED,4BAAI8G,KAAJ,EAAW;AACP,gCAAI;AACA3I,wCAAQzc,KAAKrhB,KAAL,CAAWomC,IAAIQ,YAAf,CAAR;AACA;AACH,6BAHD,CAIA,OAAOvpC,CAAP,EAAU;AACNhC,yCAAIojC,KAAJ,CAAU,kDAAV,EAA8DphC,EAAEgkC,OAAhE;AACA1B,uCAAOtiC,CAAP;AACA;AACH;AACJ;AACJ;;AAEDsiC,2BAAO7iC,MAAM,oCAAoCypC,WAApC,GAAkD,cAAlD,GAAmE9J,GAAzE,CAAP;AACH,iBA9BD,MA+BK;AACDkD,2BAAO7iC,MAAMspC,IAAIS,UAAJ,GAAiB,IAAjB,GAAwBT,IAAIE,MAA5B,GAAqC,GAA3C,CAAP;AACH;AACJ,aArCD;;AAuCAF,gBAAIU,OAAJ,GAAc,YAAW;AACrBzrC,yBAAIojC,KAAJ,CAAU,oCAAV;AACAkB,uBAAO7iC,MAAM,eAAN,CAAP;AACH,aAHD;;AAKA,gBAAI4nC,KAAJ,EAAW;AACPrpC,yBAAIqgC,KAAJ,CAAU,iEAAV;AACA0K,oBAAIW,gBAAJ,CAAqB,eAArB,EAAsC,YAAYrC,KAAlD;AACH;;AAED0B,gBAAItH,IAAJ;AACH,SA1DM,CAAP;AA2DH,K;;0BAEDkI,Q,qBAASvK,G,EAAKmI,O,EAAS;AAAA;;AACnB,YAAI,CAACnI,GAAL,EAAS;AACLphC,qBAAIojC,KAAJ,CAAU,qCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,6BAAV,EAAyCe,GAAzC;;AAEA,eAAO,IAAIoB,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;;AAEpC,gBAAIyG,MAAM,IAAI,OAAKH,eAAT,EAAV;AACAG,gBAAIvF,IAAJ,CAAS,MAAT,EAAiBpE,GAAjB;;AAEA,gBAAI4J,sBAAsB,OAAKL,aAA/B;;AAEAI,gBAAIrI,MAAJ,GAAa,YAAW;AACpB1iC,yBAAIqgC,KAAJ,CAAU,sDAAV,EAAkE0K,IAAIE,MAAtE;;AAEA,oBAAIF,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuB3E,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAIyE,KAAJ,EAAW;AACP,gCAAI;AACA3I,wCAAQzc,KAAKrhB,KAAL,CAAWomC,IAAIQ,YAAf,CAAR;AACA;AACH,6BAHD,CAIA,OAAOvpC,CAAP,EAAU;AACNhC,yCAAIojC,KAAJ,CAAU,mDAAV,EAA+DphC,EAAEgkC,OAAjE;AACA1B,uCAAOtiC,CAAP;AACA;AACH;AACJ;AACJ;;AAEDsiC,2BAAO7iC,MAAM,oCAAoCypC,WAApC,GAAkD,cAAlD,GAAmE9J,GAAzE,CAAP;AACA;AACH;;AAED,oBAAI2J,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuB3E,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAIyE,KAAJ,EAAW;AACP,gCAAI;AACA,oCAAI7B,UAAUvjB,KAAKrhB,KAAL,CAAWomC,IAAIQ,YAAf,CAAd;AACA,oCAAIhC,WAAWA,QAAQnG,KAAvB,EAA8B;AAC1BpjC,6CAAIojC,KAAJ,CAAU,2CAAV,EAAuDmG,QAAQnG,KAA/D;AACAkB,2CAAO,IAAI7iC,KAAJ,CAAU8nC,QAAQnG,KAAlB,CAAP;AACA;AACH;AACJ,6BAPD,CAQA,OAAOphC,CAAP,EAAU;AACNhC,yCAAIojC,KAAJ,CAAU,mDAAV,EAA+DphC,EAAEgkC,OAAjE;AACA1B,uCAAOtiC,CAAP;AACA;AACH;AACJ;AACJ;AACJ;;AAEDsiC,uBAAO7iC,MAAMspC,IAAIS,UAAJ,GAAiB,IAAjB,GAAwBT,IAAIE,MAA5B,GAAqC,GAA3C,CAAP;AACH,aA7DD;;AA+DAF,gBAAIU,OAAJ,GAAc,YAAW;AACrBzrC,yBAAIojC,KAAJ,CAAU,qCAAV;AACAkB,uBAAO7iC,MAAM,eAAN,CAAP;AACH,aAHD;;AAKA,gBAAIkhC,OAAO,EAAX;AACA,iBAAI,IAAI7O,GAAR,IAAeyV,OAAf,EAAwB;;AAEpB,oBAAIZ,QAAQY,QAAQzV,GAAR,CAAZ;;AAEA,oBAAI6U,KAAJ,EAAW;;AAEP,wBAAIhG,KAAKtgC,MAAL,GAAc,CAAlB,EAAqB;AACjBsgC,gCAAQ,GAAR;AACH;;AAEDA,4BAAQr9B,mBAAmBwuB,GAAnB,CAAR;AACA6O,4BAAQ,GAAR;AACAA,4BAAQr9B,mBAAmBqjC,KAAnB,CAAR;AACH;AACJ;;AAEDoC,gBAAIW,gBAAJ,CAAqB,cAArB,EAAqC,mCAArC;AACAX,gBAAItH,IAAJ,CAASd,IAAT;AACH,SA9FM,CAAP;AA+FH,K;;;;;;;;;;;;;;;;;;;;;;;;;ACzML;AACA;;AAEA,IAAIiJ,YAAY;AACZvL,SADY,mBACL,CAAE,CADG;AAEZwL,QAFY,kBAEN,CAAE,CAFI;AAGZC,QAHY,kBAGN,CAAE,CAHI;AAIZ1I,SAJY,mBAIL,CAAE;AAJG,CAAhB;;AAOA,IAAM2I,OAAO,CAAb;AACA,IAAMC,QAAQ,CAAd;AACA,IAAMC,OAAO,CAAb;AACA,IAAMC,OAAO,CAAb;AACA,IAAMC,QAAQ,CAAd;;AAEA,IAAIC,eAAJ;AACA,IAAIC,cAAJ;;IAEarsC,G,WAAAA,G;;;;;QAOFwF,K,oBAAO;AACV6mC,gBAAQH,IAAR;AACAE,iBAASR,SAAT;AACH,K;;QA+BMvL,K,oBAAc;AACjB,YAAIgM,SAASF,KAAb,EAAmB;AAAA,8CADPG,IACO;AADPA,oBACO;AAAA;;AACfF,mBAAO/L,KAAP,CAAal9B,KAAb,CAAmBipC,MAAnB,EAA2BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA3B;AACH;AACJ,K;;QACMT,I,mBAAa;AAChB,YAAIQ,SAASH,IAAb,EAAkB;AAAA,+CADPI,IACO;AADPA,oBACO;AAAA;;AACdF,mBAAOP,IAAP,CAAY1oC,KAAZ,CAAkBipC,MAAlB,EAA0BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA1B;AACH;AACJ,K;;QACMR,I,mBAAa;AAChB,YAAIO,SAASJ,IAAb,EAAkB;AAAA,+CADPK,IACO;AADPA,oBACO;AAAA;;AACdF,mBAAON,IAAP,CAAY3oC,KAAZ,CAAkBipC,MAAlB,EAA0BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA1B;AACH;AACJ,K;;QACMlJ,K,oBAAc;AACjB,YAAIiJ,SAASL,KAAb,EAAmB;AAAA,+CADPM,IACO;AADPA,oBACO;AAAA;;AACfF,mBAAOhJ,KAAP,CAAajgC,KAAb,CAAmBipC,MAAnB,EAA2BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA3B;AACH;AACJ,K;;;;4BA3DiB;AAAC,mBAAOP,IAAP;AAAY;;;4BACZ;AAAC,mBAAOC,KAAP;AAAa;;;4BACf;AAAC,mBAAOC,IAAP;AAAY;;;4BACb;AAAC,mBAAOC,IAAP;AAAY;;;4BACZ;AAAC,mBAAOC,KAAP;AAAa;;;4BAOf;AACd,mBAAOE,KAAP;AACH,S;0BACgB1D,K,EAAM;AACnB,gBAAIoD,QAAQpD,KAAR,IAAiBA,SAASwD,KAA9B,EAAoC;AAChCE,wBAAQ1D,KAAR;AACH,aAFD,MAGK;AACD,sBAAM,IAAIlnC,KAAJ,CAAU,mBAAV,CAAN;AACH;AACJ;;;4BAEkB;AACf,mBAAO2qC,MAAP;AACH,S;0BACiBzD,K,EAAM;AACpB,gBAAI,CAACA,MAAMtI,KAAP,IAAgBsI,MAAMkD,IAA1B,EAAgC;AAC5B;AACAlD,sBAAMtI,KAAN,GAAcsI,MAAMkD,IAApB;AACH;;AAED,gBAAIlD,MAAMtI,KAAN,IAAesI,MAAMkD,IAArB,IAA6BlD,MAAMmD,IAAnC,IAA2CnD,MAAMvF,KAArD,EAA2D;AACvDgJ,yBAASzD,KAAT;AACH,aAFD,MAGK;AACD,sBAAM,IAAIlnC,KAAJ,CAAU,gBAAV,CAAN;AACH;AACJ;;;;;;AAwBLzB,IAAIwF,KAAJ,G;;;;;;;;;;;;;;;;;;;qjBClFA;AACA;;AAEA;;AACA;;;;AAEA,IAAMgnC,sBAAsB,kCAA5B;;IAEajsC,e,WAAAA,e;AACT,6BAAYksC,QAAZ,EAAqD;AAAA,YAA/BC,eAA+B,uEAAbnC,wBAAa;;AAAA;;AACjD,YAAI,CAACkC,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,wDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,CAAoB,CAAC,0BAAD,CAApB,CAApB;AACH;;8BAsBDG,W,0BAAc;AAAA;;AACV,YAAI,KAAKF,SAAL,CAAetH,QAAnB,EAA6B;AACzBrlC,qBAAIqgC,KAAJ,CAAU,+DAAV;AACA,mBAAOmC,QAAQC,OAAR,CAAgB,KAAKkK,SAAL,CAAetH,QAA/B,CAAP;AACH;;AAED,YAAI,CAAC,KAAKyH,WAAV,EAAuB;AACnB9sC,qBAAIojC,KAAJ,CAAU,iFAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,oDAAV,CAAf,CAAP;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,oDAAV,EAAgE,KAAKyM,WAArE;;AAEA,eAAO,KAAKF,YAAL,CAAkB9B,OAAlB,CAA0B,KAAKgC,WAA/B,EACFzC,IADE,CACG,oBAAY;AACdrqC,qBAAIqgC,KAAJ,CAAU,4CAAV;AACA,kBAAKsM,SAAL,CAAetH,QAAf,GAA0BA,QAA1B;AACA,mBAAOA,QAAP;AACH,SALE,CAAP;AAMH,K;;8BAED0H,S,wBAAY;AACR,eAAO,KAAKC,oBAAL,CAA0B,QAA1B,CAAP;AACH,K;;8BAEDC,wB,uCAA2B;AACvB,eAAO,KAAKD,oBAAL,CAA0B,wBAA1B,CAAP;AACH,K;;8BAEDE,mB,kCAAsB;AAClB,eAAO,KAAKF,oBAAL,CAA0B,mBAA1B,CAAP;AACH,K;;8BAEDG,gB,+BAAgC;AAAA,YAAfC,QAAe,uEAAN,IAAM;;AAC5B,eAAO,KAAKJ,oBAAL,CAA0B,gBAA1B,EAA4CI,QAA5C,CAAP;AACH,K;;8BAEDC,qB,oCAAwB;AACpB,eAAO,KAAKL,oBAAL,CAA0B,sBAA1B,EAAkD,IAAlD,CAAP;AACH,K;;8BAEDM,qB,oCAAwB;AACpB,eAAO,KAAKN,oBAAL,CAA0B,sBAA1B,EAAkD,IAAlD,CAAP;AACH,K;;8BAEDO,qB,oCAAwB;AACpB,eAAO,KAAKP,oBAAL,CAA0B,qBAA1B,EAAiD,IAAjD,CAAP;AACH,K;;8BAEDQ,e,8BAAkB;AACd,eAAO,KAAKR,oBAAL,CAA0B,UAA1B,EAAsC,IAAtC,CAAP;AACH,K;;8BAEDA,oB,iCAAqB9oB,I,EAAsB;AAAA,YAAhBkpB,QAAgB,uEAAP,KAAO;;AACvCptC,iBAAIqgC,KAAJ,CAAU,8CAA8Cnc,IAAxD;;AAEA,eAAO,KAAK2oB,WAAL,GAAmBxC,IAAnB,CAAwB,oBAAY;AACvCrqC,qBAAIqgC,KAAJ,CAAU,wDAAV;;AAEA,gBAAIgF,SAASnhB,IAAT,MAAmB/iB,SAAvB,EAAkC;;AAE9B,oBAAIisC,aAAa,IAAjB,EAAuB;AACnBptC,6BAAI8rC,IAAJ,CAAS,sFAAsF5nB,IAA/F;AACA,2BAAO/iB,SAAP;AACH,iBAHD,MAIK;AACDnB,6BAAIojC,KAAJ,CAAU,6EAA6Elf,IAAvF;AACA,0BAAM,IAAIziB,KAAJ,CAAU,wCAAwCyiB,IAAlD,CAAN;AACH;AACJ;;AAED,mBAAOmhB,SAASnhB,IAAT,CAAP;AACH,SAhBM,CAAP;AAiBH,K;;8BAEDupB,c,6BAAiB;AAAA;;AACb,YAAI,KAAKd,SAAL,CAAee,WAAnB,EAAgC;AAC5B1tC,qBAAIqgC,KAAJ,CAAU,qEAAV;AACA,mBAAOmC,QAAQC,OAAR,CAAgB,KAAKkK,SAAL,CAAee,WAA/B,CAAP;AACH;;AAED,eAAO,KAAKV,oBAAL,CAA0B,UAA1B,EAAsC3C,IAAtC,CAA2C,oBAAY;AAC1DrqC,qBAAIqgC,KAAJ,CAAU,mDAAV,EAA+DsN,QAA/D;;AAEA,mBAAO,OAAKf,YAAL,CAAkB9B,OAAlB,CAA0B6C,QAA1B,EAAoCtD,IAApC,CAAyC,kBAAU;AACtDrqC,yBAAIqgC,KAAJ,CAAU,kDAAV,EAA8DuN,MAA9D;;AAEA,oBAAI,CAACA,OAAO1tB,IAAZ,EAAkB;AACdlgB,6BAAIojC,KAAJ,CAAU,wDAAV;AACA,0BAAM,IAAI3hC,KAAJ,CAAU,wBAAV,CAAN;AACH;;AAED,uBAAKkrC,SAAL,CAAee,WAAf,GAA6BE,OAAO1tB,IAApC;AACA,uBAAO,OAAKysB,SAAL,CAAee,WAAtB;AACH,aAVM,CAAP;AAWH,SAdM,CAAP;AAeH,K;;;;4BApHiB;AACd,gBAAI,CAAC,KAAKG,YAAV,EAAwB;AACpB,oBAAI,KAAKlB,SAAL,CAAeG,WAAnB,EAAgC;AAC5B,yBAAKe,YAAL,GAAoB,KAAKlB,SAAL,CAAeG,WAAnC;AACH,iBAFD,MAGK;AACD,yBAAKe,YAAL,GAAoB,KAAKlB,SAAL,CAAemB,SAAnC;;AAEA,wBAAI,KAAKD,YAAL,IAAqB,KAAKA,YAAL,CAAkBnmC,OAAlB,CAA0B8kC,mBAA1B,IAAiD,CAA1E,EAA6E;AACzE,4BAAI,KAAKqB,YAAL,CAAkB,KAAKA,YAAL,CAAkBxrC,MAAlB,GAA2B,CAA7C,MAAoD,GAAxD,EAA6D;AACzD,iCAAKwrC,YAAL,IAAqB,GAArB;AACH;AACD,6BAAKA,YAAL,IAAqBrB,mBAArB;AACH;AACJ;AACJ;;AAED,mBAAO,KAAKqB,YAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBCrCL;AACA;;AAEA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;IAEa5tC,U,WAAAA,U;AACT,0BAA2B;AAAA,YAAfwsC,QAAe,uEAAJ,EAAI;;AAAA;;AACvB,YAAIA,oBAAoBvsC,sCAAxB,EAA4C;AACxC,iBAAKysC,SAAL,GAAiBF,QAAjB;AACH,SAFD,MAGK;AACD,iBAAKE,SAAL,GAAiB,IAAIzsC,sCAAJ,CAAuBusC,QAAvB,CAAjB;AACH;AACJ;;yBAmBDsB,mB,kCAQE;AAAA;;AAAA,uFAFoH,EAEpH;AAAA,YAPEC,aAOF,QAPEA,aAOF;AAAA,YAPiBC,KAOjB,QAPiBA,KAOjB;AAAA,YAPwBrJ,YAOxB,QAPwBA,YAOxB;AAAA,YAHEtQ,IAGF,QAHEA,IAGF;AAAA,YAHQ5E,KAGR,QAHQA,KAGR;AAAA,YAHewe,MAGf,QAHeA,MAGf;AAAA,YAHuB9L,OAGvB,QAHuBA,OAGvB;AAAA,YAHgC+L,OAGhC,QAHgCA,OAGhC;AAAA,YAHyCC,UAGzC,QAHyCA,UAGzC;AAAA,YAHqDC,aAGrD,QAHqDA,aAGrD;AAAA,YAHoEC,UAGpE,QAHoEA,UAGpE;AAAA,YAHgFC,UAGhF,QAHgFA,UAGhF;AAAA,YAFEC,QAEF,QAFEA,QAEF;AAAA,YAFYxH,OAEZ,QAFYA,OAEZ;AAAA,YAFqByH,WAErB,QAFqBA,WAErB;AAAA,YAFkCC,aAElC,QAFkCA,aAElC;AAAA,YAFiDC,gBAEjD,QAFiDA,gBAEjD;AAAA,YAFmEC,gBAEnE,QAFmEA,gBAEnE;AAAA,YAFqFC,YAErF,QAFqFA,YAErF;AAAA,YAFmGC,YAEnG,QAFmGA,YAEnG;;AAAA,YADEC,UACF;;AACE/uC,iBAAIqgC,KAAJ,CAAU,gCAAV;;AAEA,YAAIc,YAAY,KAAKwL,SAAL,CAAexL,SAA/B;AACA6M,wBAAgBA,iBAAiB,KAAKrB,SAAL,CAAeqB,aAAhD;AACAC,gBAAQA,SAAS,KAAKtB,SAAL,CAAesB,KAAhC;AACArJ,uBAAeA,gBAAgB,KAAK+H,SAAL,CAAe/H,YAA9C;;AAEA;AACAsJ,iBAASA,UAAU,KAAKvB,SAAL,CAAeuB,MAAlC;AACA9L,kBAAUA,WAAW,KAAKuK,SAAL,CAAevK,OAApC;AACA+L,kBAAUA,WAAW,KAAKxB,SAAL,CAAewB,OAApC;AACAC,qBAAaA,cAAc,KAAKzB,SAAL,CAAeyB,UAA1C;AACAG,qBAAaA,cAAc,KAAK5B,SAAL,CAAe4B,UAA1C;AACAC,mBAAWA,YAAY,KAAK7B,SAAL,CAAe6B,QAAtC;AACAE,wBAAgBA,iBAAiB,KAAK/B,SAAL,CAAe+B,aAAhD;AACAC,2BAAmBA,oBAAoB,KAAKhC,SAAL,CAAegC,gBAAtD;AACAC,2BAAmBA,oBAAoB,KAAKjC,SAAL,CAAeiC,gBAAtD;;AAEA,YAAId,YAAY,KAAKnB,SAAL,CAAemB,SAA/B;;AAEA,YAAIkB,6BAAcC,MAAd,CAAqBjB,aAArB,KAAuCA,kBAAkB,MAA7D,EAAqE;AACjE,mBAAOxL,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6CAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsBjC,wBAAtB,GAAiD5C,IAAjD,CAAsD,eAAO;AAChErqC,qBAAIqgC,KAAJ,CAAU,iEAAV,EAA6Ee,GAA7E;;AAEA,gBAAI+N,gBAAgB,IAAIH,4BAAJ,CAAkB;AAClC5N,wBADkC;AAElCD,oCAFkC;AAGlCyD,0CAHkC;AAIlCoJ,4CAJkC;AAKlCC,4BALkC;AAMlC3Z,sBAAMA,QAAQ5E,KANoB;AAOlCoe,oCAPkC;AAQlCI,8BARkC,EAQ1B9L,gBAR0B,EAQjB+L,gBARiB,EAQRC,sBARQ,EAQIC,4BARJ,EAQmBC,sBARnB,EAQ+BC,sBAR/B;AASlCC,kCATkC,EASxBxH,gBATwB,EASfyH,wBATe,EASFE,kCATE,EASgBC,kCAThB,EASkCC,0BATlC,EASgDH,4BAThD;AAUlCU,+BAAe,MAAKzC,SAAL,CAAeyC,aAVI;AAWlCN;AAXkC,aAAlB,CAApB;;AAcA,gBAAIO,cAAcF,cAAczf,KAAhC;AACAqf,yBAAaA,cAAc,MAAKO,WAAhC;;AAEA,mBAAOP,WAAWQ,GAAX,CAAeF,YAAY7T,EAA3B,EAA+B6T,YAAYG,eAAZ,EAA/B,EAA8DnF,IAA9D,CAAmE,YAAM;AAC5E,uBAAO8E,aAAP;AACH,aAFM,CAAP;AAGH,SAvBM,CAAP;AAwBH,K;;yBAEDM,uB,oCAAwBrO,G,EAAK2N,U,EAAiC;AAAA,YAArBW,WAAqB,uEAAP,KAAO;;AAC1D1vC,iBAAIqgC,KAAJ,CAAU,oCAAV;;AAEA,YAAIsP,WAAW,KAAKhD,SAAL,CAAe+B,aAAf,KAAiC,OAAjC,IACV,CAAC,KAAK/B,SAAL,CAAe+B,aAAhB,IAAiCM,6BAAcC,MAAd,CAAqB,KAAKtC,SAAL,CAAeqB,aAApC,CADtC;AAEA,YAAI4B,YAAYD,WAAW,GAAX,GAAiB,GAAjC;;AAEA,YAAIE,WAAW,IAAIC,8BAAJ,CAAmB1O,GAAnB,EAAwBwO,SAAxB,CAAf;;AAEA,YAAI,CAACC,SAASngB,KAAd,EAAqB;AACjB1vB,qBAAIojC,KAAJ,CAAU,0DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAEDstC,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,YAAIS,WAAWL,cAAcX,WAAWiB,MAAX,CAAkBjN,IAAlB,CAAuBgM,UAAvB,CAAd,GAAmDA,WAAW9P,GAAX,CAAe8D,IAAf,CAAoBgM,UAApB,CAAlE;;AAEA,eAAOgB,SAASF,SAASngB,KAAlB,EAAyB2a,IAAzB,CAA8B,6BAAqB;AACtD,gBAAI,CAAC4F,iBAAL,EAAwB;AACpBjwC,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,oCAAV,CAAN;AACH;;AAED,gBAAIiuB,QAAQwgB,yBAAYC,iBAAZ,CAA8BF,iBAA9B,CAAZ;AACA,mBAAO,EAACvgB,YAAD,EAAQmgB,kBAAR,EAAP;AACH,SARM,CAAP;AASH,K;;yBAEDO,qB,kCAAsBhP,G,EAAK2N,U,EAAY;AAAA;;AACnC/uC,iBAAIqgC,KAAJ,CAAU,kCAAV;;AAEA,eAAO,KAAKoP,uBAAL,CAA6BrO,GAA7B,EAAkC2N,UAAlC,EAA8C,IAA9C,EAAoD1E,IAApD,CAAyD,iBAAuB;AAAA,gBAArB3a,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,SAAdA,QAAc;;AACnF7vC,qBAAIqgC,KAAJ,CAAU,oFAAV;AACA,mBAAO,OAAKgQ,UAAL,CAAgBC,sBAAhB,CAAuC5gB,KAAvC,EAA8CmgB,QAA9C,CAAP;AACH,SAHM,CAAP;AAIH,K;;yBAEDU,oB,mCAEE;AAAA;;AAAA,wFAF6G,EAE7G;AAAA,YAFoBlC,aAEpB,SAFoBA,aAEpB;AAAA,YAFmC/Z,IAEnC,SAFmCA,IAEnC;AAAA,YAFyC5E,KAEzC,SAFyCA,KAEzC;AAAA,YAFgD8gB,wBAEhD,SAFgDA,wBAEhD;AAAA,YAF0E7B,gBAE1E,SAF0EA,gBAE1E;AAAA,YAF4FE,YAE5F,SAF4FA,YAE5F;;AAAA,YADEE,UACF;;AACE/uC,iBAAIqgC,KAAJ,CAAU,iCAAV;;AAEAmQ,mCAA2BA,4BAA4B,KAAK7D,SAAL,CAAe6D,wBAAtE;AACA7B,2BAAmBA,oBAAoB,KAAKhC,SAAL,CAAegC,gBAAtD;;AAEA,eAAO,KAAKO,gBAAL,CAAsB5B,qBAAtB,GAA8CjD,IAA9C,CAAmD,eAAO;AAC7D,gBAAI,CAACjJ,GAAL,EAAU;AACNphC,yBAAIojC,KAAJ,CAAU,uEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,yBAAV,CAAN;AACH;;AAEDzB,qBAAIqgC,KAAJ,CAAU,gEAAV,EAA4Ee,GAA5E;;AAEA,gBAAI4F,UAAU,IAAIyJ,8BAAJ,CAAmB;AAC7BrP,wBAD6B;AAE7BiN,4CAF6B;AAG7BmC,kEAH6B;AAI7Blc,sBAAMA,QAAQ5E,KAJe;AAK7Bif,kDAL6B;AAM7BE;AAN6B,aAAnB,CAAd;;AASA,gBAAI6B,eAAe1J,QAAQtX,KAA3B;AACA,gBAAIghB,YAAJ,EAAkB;AACd1wC,yBAAIqgC,KAAJ,CAAU,uEAAV;;AAEA0O,6BAAaA,cAAc,OAAKO,WAAhC;AACAP,2BAAWQ,GAAX,CAAemB,aAAalV,EAA5B,EAAgCkV,aAAalB,eAAb,EAAhC;AACH;;AAED,mBAAOxI,OAAP;AACH,SA1BM,CAAP;AA2BH,K;;yBAED2J,wB,qCAAyBvP,G,EAAK2N,U,EAAiC;AAAA,YAArBW,WAAqB,uEAAP,KAAO;;AAC3D1vC,iBAAIqgC,KAAJ,CAAU,qCAAV;;AAEA,YAAIwP,WAAW,IAAIe,gCAAJ,CAAoBxP,GAApB,CAAf;AACA,YAAI,CAACyO,SAASngB,KAAd,EAAqB;AACjB1vB,qBAAIqgC,KAAJ,CAAU,2DAAV;;AAEA,gBAAIwP,SAASzM,KAAb,EAAoB;AAChBpjC,yBAAI8rC,IAAJ,CAAS,2DAAT,EAAsE+D,SAASzM,KAA/E;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI8B,4BAAJ,CAAkByJ,QAAlB,CAAf,CAAP;AACH;;AAED,mBAAOrN,QAAQC,OAAR,CAAgB,EAACthC,oBAAD,EAAY0uC,kBAAZ,EAAhB,CAAP;AACH;;AAED,YAAIgB,WAAWhB,SAASngB,KAAxB;;AAEAqf,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,YAAIS,WAAWL,cAAcX,WAAWiB,MAAX,CAAkBjN,IAAlB,CAAuBgM,UAAvB,CAAd,GAAmDA,WAAW9P,GAAX,CAAe8D,IAAf,CAAoBgM,UAApB,CAAlE;AACA,eAAOgB,SAASc,QAAT,EAAmBxG,IAAnB,CAAwB,6BAAqB;AAChD,gBAAI,CAAC4F,iBAAL,EAAwB;AACpBjwC,yBAAIojC,KAAJ,CAAU,yEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,oCAAV,CAAN;AACH;;AAED,gBAAIiuB,QAAQohB,aAAMX,iBAAN,CAAwBF,iBAAxB,CAAZ;;AAEA,mBAAO,EAACvgB,YAAD,EAAQmgB,kBAAR,EAAP;AACH,SATM,CAAP;AAUH,K;;yBAEDkB,sB,mCAAuB3P,G,EAAK2N,U,EAAY;AAAA;;AACpC/uC,iBAAIqgC,KAAJ,CAAU,mCAAV;;AAEA,eAAO,KAAKsQ,wBAAL,CAA8BvP,GAA9B,EAAmC2N,UAAnC,EAA+C,IAA/C,EAAqD1E,IAArD,CAA0D,iBAAuB;AAAA,gBAArB3a,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,SAAdA,QAAc;;AACpF,gBAAIngB,KAAJ,EAAW;AACP1vB,yBAAIqgC,KAAJ,CAAU,qFAAV;AACA,uBAAO,OAAKgQ,UAAL,CAAgBW,uBAAhB,CAAwCthB,KAAxC,EAA+CmgB,QAA/C,CAAP;AACH,aAHD,MAIK;AACD7vC,yBAAIqgC,KAAJ,CAAU,wFAAV;AACA,uBAAOwP,QAAP;AACH;AACJ,SATM,CAAP;AAUH,K;;yBAEDoB,e,4BAAgBlC,U,EAAY;AACxB/uC,iBAAIqgC,KAAJ,CAAU,4BAAV;;AAEA0O,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,eAAOwB,aAAMG,eAAN,CAAsBlC,UAAtB,EAAkC,KAAKtC,QAAL,CAAcyE,aAAhD,CAAP;AACH,K;;;;4BA5MiB;AACd,mBAAO,KAAKzE,QAAL,CAAcsC,UAArB;AACH;;;4BACgB;AACb,mBAAO,KAAKtC,QAAL,CAAc0E,SAArB;AACH;;;4BACsB;AACnB,mBAAO,KAAK1E,QAAL,CAAc2E,eAArB;AACH;;;4BAEc;AACX,mBAAO,KAAKzE,SAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKuC,gBAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;;;qjBCtCL;AACA;;AAEA;;AACA;;AACA;;AACA;;;;AAEA,IAAM1C,sBAAsB,kCAA5B;;AAEA,IAAM6E,sBAAsB,UAA5B;AACA,IAAMC,eAAe,QAArB;AACA,IAAMC,uBAAuB,KAAK,EAAlC,C,CAAsC;AACtC,IAAMC,4BAA4B,KAAK,CAAvC;;IAEatxC,kB,WAAAA,kB;AACT,kCAmBQ;AAAA,uFAAJ,EAAI;AAAA,YAjBJ4tC,SAiBI,QAjBJA,SAiBI;AAAA,YAjBOhB,WAiBP,QAjBOA,WAiBP;AAAA,YAjBoBzH,QAiBpB,QAjBoBA,QAiBpB;AAAA,YAjB8BqI,WAiB9B,QAjB8BA,WAiB9B;AAAA,YAfJvM,SAeI,QAfJA,SAeI;AAAA,YAfOiO,aAeP,QAfOA,aAeP;AAAA,sCAfsBpB,aAetB;AAAA,YAfsBA,aAetB,sCAfsCqD,mBAetC;AAAA,8BAf2DpD,KAe3D;AAAA,YAf2DA,KAe3D,8BAfmEqD,YAenE;AAAA,YAdJ1M,YAcI,QAdJA,YAcI;AAAA,YAdU4L,wBAcV,QAdUA,wBAcV;AAAA,YAZJtC,MAYI,QAZJA,MAYI;AAAA,YAZI9L,OAYJ,QAZIA,OAYJ;AAAA,YAZa+L,OAYb,QAZaA,OAYb;AAAA,YAZsBC,UAYtB,QAZsBA,UAYtB;AAAA,YAZkCG,UAYlC,QAZkCA,UAYlC;AAAA,YAZ8CC,QAY9C,QAZ8CA,QAY9C;AAAA,YAZwDE,aAYxD,QAZwDA,aAYxD;AAAA,yCAVJ+C,oBAUI;AAAA,YAVJA,oBAUI,yCAVmB,IAUnB;AAAA,qCAVyBC,YAUzB;AAAA,YAVyBA,YAUzB,qCAVwC,IAUxC;AAAA,sCATJR,aASI;AAAA,YATJA,aASI,sCATYK,oBASZ;AAAA,kCATkC5H,SASlC;AAAA,YATkCA,SASlC,kCAT8C6H,yBAS9C;AAAA,yCARJG,iBAQI;AAAA,YARJA,iBAQI,yCARgB,IAQhB;AAAA,mCANJ5C,UAMI;AAAA,YANJA,UAMI,mCANS,IAAI5uC,0CAAJ,EAMT;AAAA,yCALJyxC,qBAKI;AAAA,YALJA,qBAKI,yCALoBC,oCAKpB;AAAA,yCAJJC,mBAII;AAAA,YAJJA,mBAII,yCAJkBvxC,gCAIlB;AAAA,yCAFJouC,gBAEI;AAAA,YAFJA,gBAEI,yCAFe,EAEf;AAAA,yCADJC,gBACI;AAAA,YADJA,gBACI,yCADe,EACf;;AAAA;;AAEJ,aAAKmD,UAAL,GAAkBjE,SAAlB;AACA,aAAKD,YAAL,GAAoBf,WAApB;AACA,aAAKkF,SAAL,GAAiB3M,QAAjB;AACA,aAAK4M,YAAL,GAAoBvE,WAApB;;AAEA,aAAKlM,UAAL,GAAkBL,SAAlB;AACA,aAAK+Q,cAAL,GAAsB9C,aAAtB;AACA,aAAK+C,cAAL,GAAsBnE,aAAtB;AACA,aAAKoE,MAAL,GAAcnE,KAAd;AACA,aAAKoE,aAAL,GAAqBzN,YAArB;AACA,aAAK0N,yBAAL,GAAiC9B,wBAAjC;;AAEA,aAAK+B,OAAL,GAAerE,MAAf;AACA,aAAKsE,QAAL,GAAgBpQ,OAAhB;AACA,aAAKqQ,QAAL,GAAgBtE,OAAhB;AACA,aAAKuE,WAAL,GAAmBtE,UAAnB;AACA,aAAKuE,WAAL,GAAmBpE,UAAnB;AACA,aAAKqE,SAAL,GAAiBpE,QAAjB;AACA,aAAKqE,cAAL,GAAsBnE,aAAtB;;AAEA,aAAKoE,qBAAL,GAA6B,CAAC,CAACrB,oBAA/B;AACA,aAAKsB,aAAL,GAAqB,CAAC,CAACrB,YAAvB;AACA,aAAKsB,cAAL,GAAsB9B,aAAtB;AACA,aAAK+B,UAAL,GAAkBtJ,SAAlB;AACA,aAAKuJ,kBAAL,GAA0BvB,iBAA1B;;AAEA,aAAKrC,WAAL,GAAmBP,UAAnB;AACA,aAAKsB,UAAL,GAAkB,IAAIuB,qBAAJ,CAA0B,IAA1B,CAAlB;AACA,aAAK1C,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,IAAxB,CAAxB;;AAEA,aAAKqB,iBAAL,GAAyB,QAAOxE,gBAAP,yCAAOA,gBAAP,OAA4B,QAA5B,GAAuCA,gBAAvC,GAA0D,EAAnF;AACA,aAAKyE,iBAAL,GAAyB,QAAOxE,gBAAP,yCAAOA,gBAAP,OAA4B,QAA5B,GAAuCA,gBAAvC,GAA0D,EAAnF;AACH;;AAED;;;;;4BACgB;AACZ,mBAAO,KAAKpN,UAAZ;AACH,S;0BACamH,K,EAAO;AACjB,gBAAI,CAAC,KAAKnH,UAAV,EAAsB;AAClB;AACA,qBAAKA,UAAL,GAAkBmH,KAAlB;AACH,aAHD,MAIK;AACD3oC,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,sCAAV,CAAN;AACH;AACJ;;;4BACmB;AAChB,mBAAO,KAAKywC,cAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;;4BACW;AACR,mBAAO,KAAKC,MAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKC,yBAAZ;AACH;;AAGD;;;;4BACa;AACT,mBAAO,KAAKC,OAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKC,QAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKC,QAAZ;AACH;;;4BACgB;AACb,mBAAO,KAAKC,WAAZ;AACH;;;4BACgB;AACb,mBAAO,KAAKC,WAAZ;AACH;;;4BACc;AACX,mBAAO,KAAKC,SAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;AAGD;;;;4BACgB;AACZ,mBAAO,KAAKd,UAAZ;AACH,S;0BACapJ,K,EAAO;AACjB,gBAAI,CAAC,KAAKoJ,UAAV,EAAsB;AAClB;AACA,qBAAKA,UAAL,GAAkBpJ,KAAlB;AACH,aAHD,MAIK;AACD3oC,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,sCAAV,CAAN;AACH;AACJ;;;4BACiB;AACd,gBAAI,CAAC,KAAKosC,YAAV,EAAwB;AACpB,qBAAKA,YAAL,GAAoB,KAAKC,SAAzB;;AAEA,oBAAI,KAAKD,YAAL,IAAqB,KAAKA,YAAL,CAAkBnmC,OAAlB,CAA0B8kC,mBAA1B,IAAiD,CAA1E,EAA6E;AACzE,wBAAI,KAAKqB,YAAL,CAAkB,KAAKA,YAAL,CAAkBxrC,MAAlB,GAA2B,CAA7C,MAAoD,GAAxD,EAA6D;AACzD,6BAAKwrC,YAAL,IAAqB,GAArB;AACH;AACD,yBAAKA,YAAL,IAAqBrB,mBAArB;AACH;AACJ;;AAED,mBAAO,KAAKqB,YAAZ;AACH;;AAED;;;;4BACe;AACX,mBAAO,KAAKmE,SAAZ;AACH,S;0BACYrJ,K,EAAO;AAChB,iBAAKqJ,SAAL,GAAiBrJ,KAAjB;AACH;;;4BAEiB;AACd,mBAAO,KAAKsJ,YAAZ;AACH,S;0BACetJ,K,EAAO;AACnB,iBAAKsJ,YAAL,GAAoBtJ,KAApB;AACH;;AAED;;;;4BAC2B;AACvB,mBAAO,KAAKmK,qBAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKC,UAAZ;AACH;;;4BACuB;AACpB,mBAAO,KAAKC,kBAAZ;AACH;;;4BAEgB;AACb,mBAAO,KAAK5D,WAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKe,UAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKnB,gBAAZ;AACH;;AAED;;;;4BACuB;AACnB,mBAAO,KAAKiE,iBAAZ;AACH,S;0BACoBxK,K,EAAO;AACxB,gBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA8B;AAC1B,qBAAKwK,iBAAL,GAAyBxK,KAAzB;AACH,aAFD,MAEO;AACH,qBAAKwK,iBAAL,GAAyB,EAAzB;AACH;AACJ;;AAED;;;;4BACuB;AACnB,mBAAO,KAAKC,iBAAZ;AACH,S;0BACoBzK,K,EAAO;AACxB,gBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA8B;AAC1B,qBAAKyK,iBAAL,GAAyBzK,KAAzB;AACH,aAFD,MAEO;AACH,qBAAKyK,iBAAL,GAAyB,EAAzB;AACH;AACJ;;;;;;;;;;;;;;;;;;;;;;;ACxNL;;AACA;;0JAJA;AACA;;IAKaC,c,WAAAA,c;;;;;6BAETvP,O,oBAAQC,M,EAAQ;AACZ,YAAIE,QAAQ,IAAIqP,wBAAJ,CAAgBvP,MAAhB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBwB,KAAhB,CAAP;AACH,K;;6BAED/C,Q,qBAASE,G,EAAKmS,Q,EAAU3D,S,EAAW;AAC/B5vC,iBAAIqgC,KAAJ,CAAU,yBAAV;;AAEA,YAAI;AACAiT,qCAAYE,YAAZ,CAAyBpS,GAAzB,EAA8BmS,QAA9B,EAAwC3D,SAAxC;AACA,mBAAOpN,QAAQC,OAAR,EAAP;AACH,SAHD,CAIA,OAAOzgC,CAAP,EAAU;AACN,mBAAOwgC,QAAQ8B,MAAR,CAAetiC,CAAf,CAAP;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;qjBCvBL;AACA;;AAEA;;AACA;;;;AAEA,IAAMyxC,8BAA8B,GAApC;AACA,IAAMtP,uBAAuB,+DAA7B;AACA;;AAEA,IAAMC,qBAAqB,QAA3B;;IAEakP,W,WAAAA,W;AAET,yBAAYvP,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI7B,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgB9B,OAAhB;AACA,kBAAK+B,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,YAAII,SAASX,OAAOY,iBAAP,IAA4BP,kBAAzC;AACA,YAAIK,WAAWV,OAAOC,mBAAP,IAA8BG,oBAA7C;;AAEA,aAAKmB,MAAL,GAAcrkC,OAAOukC,IAAP,CAAY,EAAZ,EAAgBd,MAAhB,EAAwBD,QAAxB,CAAd;AACA,YAAI,KAAKa,MAAT,EAAiB;AACbtlC,qBAAIqgC,KAAJ,CAAU,8CAAV;AACA,iBAAKqT,yBAAL,GAAiCzyC,OAAO2iC,WAAP,CAAmB,KAAK+P,oBAAL,CAA0B5Q,IAA1B,CAA+B,IAA/B,CAAnB,EAAyD0Q,2BAAzD,CAAjC;AACH;AACJ;;0BAMDxO,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAAC,KAAKuB,MAAV,EAAkB;AACd,iBAAKJ,MAAL,CAAY,kDAAZ;AACH,SAFD,MAGK,IAAI,CAACnB,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AAC7B,iBAAK8D,MAAL,CAAY,uCAAZ;AACA,iBAAKA,MAAL,CAAY,iBAAZ;AACH,SAHI,MAIA;AACDllC,qBAAIqgC,KAAJ,CAAU,4CAAV;;AAEA,iBAAKuT,GAAL,GAAW7P,OAAOvI,EAAlB;AACA,gBAAI,KAAKoY,GAAT,EAAc;AACV3yC,uBAAO,mBAAmB8iC,OAAOvI,EAAjC,IAAuC,KAAK+F,SAAL,CAAewB,IAAf,CAAoB,IAApB,CAAvC;AACH;;AAED,iBAAKuC,MAAL,CAAYuO,KAAZ;AACA,iBAAKvO,MAAL,CAAYrkC,MAAZ,CAAmBmmC,QAAnB,GAA8BrD,OAAO3C,GAArC;AACH;;AAED,eAAO,KAAKyE,OAAZ;AACH,K;;0BAEDE,Q,qBAASzR,I,EAAM;AACXt0B,iBAAIqgC,KAAJ,CAAU,6DAAV;;AAEA,aAAK4F,QAAL;AACA,aAAK1B,QAAL,CAAcjQ,IAAd;AACH,K;;0BACD4Q,M,mBAAOc,O,EAAS;AACZhmC,iBAAIojC,KAAJ,CAAU,qBAAV,EAAiC4C,OAAjC;;AAEA,aAAKC,QAAL;AACA,aAAKzB,OAAL,CAAa,IAAI/iC,KAAJ,CAAUukC,OAAV,CAAb;AACH,K;;0BAEDE,K,oBAAQ;AACJ,aAAKD,QAAL,CAAc,KAAd;AACH,K;;0BAEDA,Q,qBAASsN,Q,EAAU;AACfvzC,iBAAIqgC,KAAJ,CAAU,qBAAV;;AAEAp/B,eAAO4iC,aAAP,CAAqB,KAAK6P,yBAA1B;AACA,aAAKA,yBAAL,GAAiC,IAAjC;;AAEA,eAAOzyC,OAAO,mBAAmB,KAAK2yC,GAA/B,CAAP;;AAEA,YAAI,KAAKtO,MAAL,IAAe,CAACiO,QAApB,EAA8B;AAC1B,iBAAKjO,MAAL,CAAYY,KAAZ;AACH;AACD,aAAKZ,MAAL,GAAc,IAAd;AACH,K;;0BAEDqO,oB,mCAAuB;AACnB,YAAI,CAAC,KAAKrO,MAAN,IAAgB,KAAKA,MAAL,CAAYwO,MAAhC,EAAwC;AACpC,iBAAK5O,MAAL,CAAY,qBAAZ;AACH;AACJ,K;;0BAED3D,S,sBAAUH,G,EAAKmS,Q,EAAU;AACrB,aAAKtN,QAAL,CAAcsN,QAAd;;AAEA,YAAInS,GAAJ,EAAS;AACLphC,qBAAIqgC,KAAJ,CAAU,8BAAV;AACA,iBAAK0F,QAAL,CAAc,EAAE3E,KAAKA,GAAP,EAAd;AACH,SAHD,MAIK;AACDphC,qBAAIqgC,KAAJ,CAAU,mDAAV;AACA,iBAAK6E,MAAL,CAAY,6BAAZ;AACH;AACJ,K;;gBAEMsO,Y,yBAAapS,G,EAAKmS,Q,EAAU3D,S,EAAW;AAC1C,YAAI3uC,OAAO8yC,MAAX,EAAmB;AACf3S,kBAAMA,OAAOngC,OAAOmmC,QAAP,CAAgBiB,IAA7B;AACA,gBAAIjH,GAAJ,EAAS;AACL,oBAAI9M,OAAO0f,uBAAWC,gBAAX,CAA4B7S,GAA5B,EAAiCwO,SAAjC,CAAX;;AAEA,oBAAItb,KAAK5E,KAAT,EAAgB;AACZ,wBAAIxL,OAAO,mBAAmBoQ,KAAK5E,KAAnC;AACA,wBAAIwR,WAAWjgC,OAAO8yC,MAAP,CAAc7vB,IAAd,CAAf;AACA,wBAAIgd,QAAJ,EAAc;AACVlhC,iCAAIqgC,KAAJ,CAAU,yDAAV;AACAa,iCAASE,GAAT,EAAcmS,QAAd;AACH,qBAHD,MAIK;AACDvzC,iCAAI8rC,IAAJ,CAAS,gEAAT;AACH;AACJ,iBAVD,MAWK;AACD9rC,6BAAI8rC,IAAJ,CAAS,0DAAT;AACH;AACJ;AACJ,SApBD,MAqBK;AACD9rC,qBAAI8rC,IAAJ,CAAS,0EAAT;AACH;AACJ,K;;;;4BAtGa;AACV,mBAAO,KAAKzH,QAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBChCL;AACA;;AAEA;;;;IAEa6P,iB,WAAAA,iB;;;;;gCAETpQ,O,sBAAU;AACN,eAAOtB,QAAQC,OAAR,CAAgB,IAAhB,CAAP;AACH,K;;gCAEDwC,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AACxBphC,qBAAIojC,KAAJ,CAAU,6CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iBAAV,CAAf,CAAP;AACH;;AAED,YAAIsiC,OAAOoQ,oBAAX,EAAiC;AAC7BlzC,mBAAOmmC,QAAP,CAAgB5oB,OAAhB,CAAwBulB,OAAO3C,GAA/B;AACH,SAFD,MAGK;AACDngC,mBAAOmmC,QAAP,GAAkBrD,OAAO3C,GAAzB;AACH;;AAED,eAAOoB,QAAQC,OAAR,EAAP;AACH,K;;;;4BAES;AACN,mBAAOxhC,OAAOmmC,QAAP,CAAgBiB,IAAvB;AACH;;;;;;;;;;;;;;;;;;;;;;;;;AC1BL;;AACA;;AACA;;AACA;;AACA;;AACA;;0JARA;AACA;;AASA,IAAM+L,iBAAiB,CAAC,OAAD,EAAU,SAAV,EAAqB,KAArB,EAA4B,KAA5B,EAAmC,KAAnC,EAA0C,KAA1C,EAAiD,KAAjD,EAAwD,QAAxD,CAAvB;;IAEavC,iB,WAAAA,iB;AAET,+BAAYpF,QAAZ,EAImC;AAAA,YAH/BqF,mBAG+B,uEAHTvxC,gCAGS;AAAA,YAF/B8zC,mBAE+B,uEAFTC,gCAES;AAAA,YAD/BC,QAC+B,uEADpBxL,kBACoB;AAAA,YAA/ByL,eAA+B,uEAAbC,wBAAa;;AAAA;;AAC/B,YAAI,CAAChI,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,iEAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKyC,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACA,aAAK+H,gBAAL,GAAwB,IAAIL,mBAAJ,CAAwB,KAAK1H,SAA7B,CAAxB;AACA,aAAKgI,SAAL,GAAiBJ,QAAjB;AACA,aAAKK,YAAL,GAAoB,IAAIJ,eAAJ,CAAoB,KAAK7H,SAAzB,CAApB;AACH;;gCAED2D,sB,mCAAuB5gB,K,EAAOmgB,Q,EAAU;AAAA;;AACpC7vC,iBAAIqgC,KAAJ,CAAU,0CAAV;;AAEA,eAAO,KAAKwU,oBAAL,CAA0BnlB,KAA1B,EAAiCmgB,QAAjC,EAA2CxF,IAA3C,CAAgD,oBAAY;AAC/DrqC,qBAAIqgC,KAAJ,CAAU,2DAAV;AACA,mBAAO,MAAKyU,eAAL,CAAqBplB,KAArB,EAA4BmgB,QAA5B,EAAsCxF,IAAtC,CAA2C,oBAAY;AAC1DrqC,yBAAIqgC,KAAJ,CAAU,4DAAV;AACA,uBAAO,MAAK0U,cAAL,CAAoBrlB,KAApB,EAA2BmgB,QAA3B,EAAqCxF,IAArC,CAA0C,oBAAY;AACzDrqC,6BAAIqgC,KAAJ,CAAU,4DAAV;AACA,2BAAOwP,QAAP;AACH,iBAHM,CAAP;AAIH,aANM,CAAP;AAOH,SATM,CAAP;AAUH,K;;gCAEDmB,uB,oCAAwBthB,K,EAAOmgB,Q,EAAU;AACrC,YAAIngB,MAAM8L,EAAN,KAAaqU,SAASngB,KAA1B,EAAiC;AAC7B1vB,qBAAIojC,KAAJ,CAAU,iEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAED;AACA;AACA;AACAzB,iBAAIqgC,KAAJ,CAAU,4DAAV;AACAwP,iBAASngB,KAAT,GAAiBA,MAAM4E,IAAvB;;AAEA,YAAIub,SAASzM,KAAb,EAAoB;AAChBpjC,qBAAI8rC,IAAJ,CAAS,+DAAT,EAA0E+D,SAASzM,KAAnF;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI8B,4BAAJ,CAAkByJ,QAAlB,CAAf,CAAP;AACH;;AAED,eAAOrN,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAEDgF,oB,iCAAqBnlB,K,EAAOmgB,Q,EAAU;AAClC,YAAIngB,MAAM8L,EAAN,KAAaqU,SAASngB,KAA1B,EAAiC;AAC7B1vB,qBAAIojC,KAAJ,CAAU,8DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMyR,SAAX,EAAsB;AAClBnhC,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,uBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMoe,SAAX,EAAsB;AAClB9tC,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,uBAAV,CAAf,CAAP;AACH;;AAED;AACA,YAAI,CAAC,KAAKkrC,SAAL,CAAemB,SAApB,EAA+B;AAC3B,iBAAKnB,SAAL,CAAemB,SAAf,GAA2Bpe,MAAMoe,SAAjC;AACH;AACD;AAHA,aAIK,IAAI,KAAKnB,SAAL,CAAemB,SAAf,IAA4B,KAAKnB,SAAL,CAAemB,SAAf,KAA6Bpe,MAAMoe,SAAnE,EAA8E;AAC/E9tC,yBAAIojC,KAAJ,CAAU,yFAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iDAAV,CAAf,CAAP;AACH;AACD;AACA,YAAI,CAAC,KAAKkrC,SAAL,CAAexL,SAApB,EAA+B;AAC3B,iBAAKwL,SAAL,CAAexL,SAAf,GAA2BzR,MAAMyR,SAAjC;AACH;AACD;AAHA,aAIK,IAAI,KAAKwL,SAAL,CAAexL,SAAf,IAA4B,KAAKwL,SAAL,CAAexL,SAAf,KAA6BzR,MAAMyR,SAAnE,EAA8E;AAC/EnhC,yBAAIojC,KAAJ,CAAU,yFAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iDAAV,CAAf,CAAP;AACH;;AAED;AACA;AACA;AACAzB,iBAAIqgC,KAAJ,CAAU,yDAAV;AACAwP,iBAASngB,KAAT,GAAiBA,MAAM4E,IAAvB;;AAEA,YAAIub,SAASzM,KAAb,EAAoB;AAChBpjC,qBAAI8rC,IAAJ,CAAS,4DAAT,EAAuE+D,SAASzM,KAAhF;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI8B,4BAAJ,CAAkByJ,QAAlB,CAAf,CAAP;AACH;;AAED,YAAIngB,MAAMslB,KAAN,IAAe,CAACnF,SAASoF,QAA7B,EAAuC;AACnCj1C,qBAAIojC,KAAJ,CAAU,wEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMslB,KAAP,IAAgBnF,SAASoF,QAA7B,EAAuC;AACnCj1C,qBAAIojC,KAAJ,CAAU,4EAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iCAAV,CAAf,CAAP;AACH;;AAED,YAAIiuB,MAAMwlB,aAAN,IAAuB,CAACrF,SAASsF,IAArC,EAA2C;AACvCn1C,qBAAIojC,KAAJ,CAAU,oEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,qBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMwlB,aAAP,IAAwBrF,SAASsF,IAArC,EAA2C;AACvCn1C,qBAAIojC,KAAJ,CAAU,wEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACouC,SAAS5B,KAAd,EAAqB;AACjB;AACA4B,qBAAS5B,KAAT,GAAiBve,MAAMue,KAAvB;AACH;;AAED,eAAOzL,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAEDkF,c,2BAAerlB,K,EAAOmgB,Q,EAAU;AAAA;;AAC5B,YAAIA,SAASuF,eAAb,EAA8B;AAC1Bp1C,qBAAIqgC,KAAJ,CAAU,uEAAV;;AAEAwP,qBAASwF,OAAT,GAAmB,KAAKvC,qBAAL,CAA2BjD,SAASwF,OAApC,CAAnB;;AAEA,gBAAI3lB,MAAMof,YAAN,KAAuB,IAAvB,IAA+B,KAAKnC,SAAL,CAAe+E,YAA9C,IAA8D7B,SAAS3P,YAA3E,EAAyF;AACrFlgC,yBAAIqgC,KAAJ,CAAU,qDAAV;;AAEA,uBAAO,KAAKqU,gBAAL,CAAsBY,SAAtB,CAAgCzF,SAAS3P,YAAzC,EAAuDmK,IAAvD,CAA4D,kBAAU;AACzErqC,6BAAIqgC,KAAJ,CAAU,qFAAV;;AAEA,wBAAIkV,OAAO7X,GAAP,KAAemS,SAASwF,OAAT,CAAiB3X,GAApC,EAAyC;AACrC19B,iCAAIojC,KAAJ,CAAU,kGAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gEAAV,CAAf,CAAP;AACH;;AAEDouC,6BAASwF,OAAT,GAAmB,OAAKG,YAAL,CAAkB3F,SAASwF,OAA3B,EAAoCE,MAApC,CAAnB;AACAv1C,6BAAIqgC,KAAJ,CAAU,+EAAV,EAA2FwP,SAASwF,OAApG;;AAEA,2BAAOxF,QAAP;AACH,iBAZM,CAAP;AAaH,aAhBD,MAiBK;AACD7vC,yBAAIqgC,KAAJ,CAAU,yDAAV;AACH;AACJ,SAzBD,MA0BK;AACDrgC,qBAAIqgC,KAAJ,CAAU,+EAAV;AACH;;AAED,eAAOmC,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAED2F,Y,yBAAaC,O,EAASC,O,EAAS;AAC3B,YAAIC,SAAS7zC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBH,OAAlB,CAAb;;AAEA,aAAK,IAAIvxB,IAAT,IAAiBwxB,OAAjB,EAA0B;AACtB,gBAAIG,SAASH,QAAQxxB,IAAR,CAAb;AACA,gBAAI,CAACnZ,MAAM4nB,OAAN,CAAckjB,MAAd,CAAL,EAA4B;AACxBA,yBAAS,CAACA,MAAD,CAAT;AACH;;AAED,iBAAK,IAAIzzC,IAAI,CAAb,EAAgBA,IAAIyzC,OAAOxzC,MAA3B,EAAmCD,GAAnC,EAAwC;AACpC,oBAAIumC,QAAQkN,OAAOzzC,CAAP,CAAZ;AACA,oBAAI,CAACuzC,OAAOzxB,IAAP,CAAL,EAAmB;AACfyxB,2BAAOzxB,IAAP,IAAeykB,KAAf;AACH,iBAFD,MAGK,IAAI59B,MAAM4nB,OAAN,CAAcgjB,OAAOzxB,IAAP,CAAd,CAAJ,EAAiC;AAClC,wBAAIyxB,OAAOzxB,IAAP,EAAaxc,OAAb,CAAqBihC,KAArB,IAA8B,CAAlC,EAAqC;AACjCgN,+BAAOzxB,IAAP,EAAa5f,IAAb,CAAkBqkC,KAAlB;AACH;AACJ,iBAJI,MAKA,IAAIgN,OAAOzxB,IAAP,MAAiBykB,KAArB,EAA4B;AAC7B,wBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA+B;AAC3BgN,+BAAOzxB,IAAP,IAAe,KAAKsxB,YAAL,CAAkBG,OAAOzxB,IAAP,CAAlB,EAAgCykB,KAAhC,CAAf;AACH,qBAFD,MAGK;AACDgN,+BAAOzxB,IAAP,IAAe,CAACyxB,OAAOzxB,IAAP,CAAD,EAAeykB,KAAf,CAAf;AACH;AACJ;AACJ;AACJ;;AAED,eAAOgN,MAAP;AACH,K;;gCAED7C,qB,kCAAsByC,M,EAAQ;AAC1Bv1C,iBAAIqgC,KAAJ,CAAU,2DAAV,EAAuEkV,MAAvE;;AAEA,YAAII,SAAS7zC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBL,MAAlB,CAAb;;AAEA,YAAI,KAAK5I,SAAL,CAAemG,qBAAnB,EAA0C;AACtCsB,2BAAe0B,OAAf,CAAuB,gBAAQ;AAC3B,uBAAOH,OAAO76B,IAAP,CAAP;AACH,aAFD;;AAIA9a,qBAAIqgC,KAAJ,CAAU,mEAAV,EAA+EsV,MAA/E;AACH,SAND,MAOK;AACD31C,qBAAIqgC,KAAJ,CAAU,uEAAV;AACH;;AAED,eAAOsV,MAAP;AACH,K;;gCAEDb,e,4BAAgBplB,K,EAAOmgB,Q,EAAU;AAC7B,YAAIA,SAASsF,IAAb,EAAmB;AACfn1C,qBAAIqgC,KAAJ,CAAU,oDAAV;AACA,mBAAO,KAAK0V,YAAL,CAAkBrmB,KAAlB,EAAyBmgB,QAAzB,CAAP;AACH;;AAED,YAAIA,SAASoF,QAAb,EAAuB;AACnB,gBAAIpF,SAAS3P,YAAb,EAA2B;AACvBlgC,yBAAIqgC,KAAJ,CAAU,yEAAV;AACA,uBAAO,KAAK2V,8BAAL,CAAoCtmB,KAApC,EAA2CmgB,QAA3C,CAAP;AACH;;AAED7vC,qBAAIqgC,KAAJ,CAAU,wDAAV;AACA,mBAAO,KAAK4V,gBAAL,CAAsBvmB,KAAtB,EAA6BmgB,QAA7B,CAAP;AACH;;AAED7vC,iBAAIqgC,KAAJ,CAAU,+EAAV;AACA,eAAOmC,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAEDkG,Y,yBAAarmB,K,EAAOmgB,Q,EAAU;AAAA;;AAC1B,YAAI7I,UAAU;AACV7F,uBAAWzR,MAAMyR,SADP;AAEViO,2BAAe1f,MAAM0f,aAFX;AAGV+F,kBAAOtF,SAASsF,IAHN;AAIVvQ,0BAAclV,MAAMkV,YAJV;AAKVsQ,2BAAexlB,MAAMwlB;AALX,SAAd;;AAQA,YAAIxlB,MAAMkf,gBAAN,IAA0B,QAAOlf,MAAMkf,gBAAb,MAAmC,QAAjE,EAA2E;AACvE9sC,mBAAO8zC,MAAP,CAAc5O,OAAd,EAAuBtX,MAAMkf,gBAA7B;AACH;;AAED,eAAO,KAAKgG,YAAL,CAAkBsB,YAAlB,CAA+BlP,OAA/B,EAAwCqD,IAAxC,CAA6C,yBAAiB;;AAEjE,iBAAI,IAAIvW,GAAR,IAAeqiB,aAAf,EAA8B;AAC1BtG,yBAAS/b,GAAT,IAAgBqiB,cAAcriB,GAAd,CAAhB;AACH;;AAED,gBAAI+b,SAASoF,QAAb,EAAuB;AACnBj1C,yBAAIqgC,KAAJ,CAAU,gFAAV;AACA,uBAAO,OAAK+V,0BAAL,CAAgC1mB,KAAhC,EAAuCmgB,QAAvC,CAAP;AACH,aAHD,MAIK;AACD7vC,yBAAIqgC,KAAJ,CAAU,+EAAV;AACH;;AAED,mBAAOwP,QAAP;AACH,SAfM,CAAP;AAgBH,K;;gCAEDuG,0B,uCAA2B1mB,K,EAAOmgB,Q,EAAU;AAAA;;AACxC,eAAO,KAAKX,gBAAL,CAAsBnC,SAAtB,GAAkC1C,IAAlC,CAAuC,kBAAU;;AAEpD,gBAAIX,WAAWha,MAAMyR,SAArB;AACA,gBAAIkV,qBAAqB,OAAK1J,SAAL,CAAehD,SAAxC;AACA3pC,qBAAIqgC,KAAJ,CAAU,4GAAV,EAAwHgW,kBAAxH;;AAEA,mBAAO,OAAK1B,SAAL,CAAe3K,qBAAf,CAAqC6F,SAASoF,QAA9C,EAAwDxL,MAAxD,EAAgEC,QAAhE,EAA0E2M,kBAA1E,EAA8FhM,IAA9F,CAAmG,mBAAW;;AAEjH,oBAAI3a,MAAMslB,KAAN,IAAetlB,MAAMslB,KAAN,KAAgBzL,QAAQyL,KAA3C,EAAkD;AAC9Ch1C,6BAAIojC,KAAJ,CAAU,yEAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAAV,CAAf,CAAP;AACH;;AAED,oBAAI,CAAC8nC,QAAQ7L,GAAb,EAAkB;AACd19B,6BAAIojC,KAAJ,CAAU,0EAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDouC,yBAASwF,OAAT,GAAmB9L,OAAnB;AACA,uBAAOsG,QAAP;AACH,aAdM,CAAP;AAeH,SArBM,CAAP;AAsBH,K;;gCAEDmG,8B,2CAA+BtmB,K,EAAOmgB,Q,EAAU;AAAA;;AAC5C,eAAO,KAAKoG,gBAAL,CAAsBvmB,KAAtB,EAA6BmgB,QAA7B,EAAuCxF,IAAvC,CAA4C,oBAAY;AAC3D,mBAAO,OAAKiM,oBAAL,CAA0BzG,QAA1B,CAAP;AACH,SAFM,CAAP;AAGH,K;;gCAEDoG,gB,6BAAiBvmB,K,EAAOmgB,Q,EAAU;AAAA;;AAC9B,YAAI,CAACngB,MAAMslB,KAAX,EAAkB;AACdh1C,qBAAIojC,KAAJ,CAAU,uDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,mBAAV,CAAf,CAAP;AACH;;AAED,YAAI2nC,MAAM,KAAKuL,SAAL,CAAexL,QAAf,CAAwB0G,SAASoF,QAAjC,CAAV;AACA,YAAI,CAAC7L,GAAD,IAAQ,CAACA,IAAIE,MAAb,IAAuB,CAACF,IAAIG,OAAhC,EAAyC;AACrCvpC,qBAAIojC,KAAJ,CAAU,8DAAV,EAA0EgG,GAA1E;AACA,mBAAO5G,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,YAAIiuB,MAAMslB,KAAN,KAAgB5L,IAAIG,OAAJ,CAAYyL,KAAhC,EAAuC;AACnCh1C,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAAV,CAAf,CAAP;AACH;;AAED,YAAIs5B,MAAMqO,IAAIE,MAAJ,CAAWvO,GAArB;;AAEA,eAAO,KAAKmU,gBAAL,CAAsBnC,SAAtB,GAAkC1C,IAAlC,CAAuC,kBAAU;AACpDrqC,qBAAIqgC,KAAJ,CAAU,qDAAV;;AAEA,mBAAO,OAAK6O,gBAAL,CAAsBzB,cAAtB,GAAuCpD,IAAvC,CAA4C,gBAAQ;AACvD,oBAAI,CAACnqB,IAAL,EAAW;AACPlgB,6BAAIojC,KAAJ,CAAU,mEAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,+BAAV,CAAf,CAAP;AACH;;AAEDzB,yBAAIqgC,KAAJ,CAAU,2DAAV;AACA,oBAAIvM,YAAJ;AACA,oBAAI,CAACiH,GAAL,EAAU;AACN7a,2BAAO,OAAKq2B,YAAL,CAAkBr2B,IAAlB,EAAwBkpB,IAAIE,MAAJ,CAAW1c,GAAnC,CAAP;;AAEA,wBAAI1M,KAAK7d,MAAL,GAAc,CAAlB,EAAqB;AACjBrC,iCAAIojC,KAAJ,CAAU,sGAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kEAAV,CAAf,CAAP;AACH,qBAHD,MAIK;AACD;AACA;AACAqyB,8BAAM5T,KAAK,CAAL,CAAN;AACH;AACJ,iBAZD,MAaK;AACD4T,0BAAM5T,KAAKs2B,MAAL,CAAY,eAAO;AACrB,+BAAO1iB,IAAIiH,GAAJ,KAAYA,GAAnB;AACH,qBAFK,EAEH,CAFG,CAAN;AAGH;;AAED,oBAAI,CAACjH,GAAL,EAAU;AACN9zB,6BAAIojC,KAAJ,CAAU,sFAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED,oBAAIioC,WAAWha,MAAMyR,SAArB;;AAEA,oBAAIkV,qBAAqB,OAAK1J,SAAL,CAAehD,SAAxC;AACA3pC,yBAAIqgC,KAAJ,CAAU,uFAAV,EAAmGgW,kBAAnG;;AAEA,uBAAO,OAAK1B,SAAL,CAAenL,WAAf,CAA2BqG,SAASoF,QAApC,EAA8CnhB,GAA9C,EAAmD2V,MAAnD,EAA2DC,QAA3D,EAAqE2M,kBAArE,EAAyFhM,IAAzF,CAA8F,YAAI;AACrGrqC,6BAAIqgC,KAAJ,CAAU,+DAAV;;AAEA,wBAAI,CAAC+I,IAAIG,OAAJ,CAAY7L,GAAjB,EAAsB;AAClB19B,iCAAIojC,KAAJ,CAAU,gEAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDouC,6BAASwF,OAAT,GAAmBjM,IAAIG,OAAvB;;AAEA,2BAAOsG,QAAP;AACH,iBAXM,CAAP;AAYH,aAjDM,CAAP;AAkDH,SArDM,CAAP;AAsDH,K;;gCAED0G,Y,yBAAar2B,I,EAAM0M,G,EAAI;AACnB,YAAIyJ,MAAM,IAAV;AACA,YAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AACtBjV,kBAAM,KAAN;AACH,SAFD,MAGK,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA;AACDr2B,qBAAIqgC,KAAJ,CAAU,qDAAV,EAAiEzT,GAAjE;AACA,mBAAO,EAAP;AACH;;AAED5sB,iBAAIqgC,KAAJ,CAAU,mEAAV,EAA+EhK,GAA/E;;AAEAnW,eAAOA,KAAKs2B,MAAL,CAAY,eAAO;AACtB,mBAAO1iB,IAAIuC,GAAJ,KAAYA,GAAnB;AACH,SAFM,CAAP;;AAIAr2B,iBAAIqgC,KAAJ,CAAU,iEAAV,EAA6EhK,GAA7E,EAAkFnW,KAAK7d,MAAvF;;AAEA,eAAO6d,IAAP;AACH,K;;gCAEDo2B,oB,iCAAqBzG,Q,EAAU;AAC3B,YAAI,CAACA,SAASwF,OAAd,EAAuB;AACnBr1C,qBAAIojC,KAAJ,CAAU,yEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iCAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACouC,SAASwF,OAAT,CAAiBoB,OAAtB,EAA+B;AAC3Bz2C,qBAAIojC,KAAJ,CAAU,gEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,wBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACouC,SAASoF,QAAd,EAAwB;AACpBj1C,qBAAIojC,KAAJ,CAAU,qDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,aAAV,CAAf,CAAP;AACH;;AAED,YAAI2nC,MAAM,KAAKuL,SAAL,CAAexL,QAAf,CAAwB0G,SAASoF,QAAjC,CAAV;AACA,YAAI,CAAC7L,GAAD,IAAQ,CAACA,IAAIE,MAAjB,EAAyB;AACrBtpC,qBAAIojC,KAAJ,CAAU,kEAAV,EAA8EgG,GAA9E;AACA,mBAAO5G,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,YAAIi1C,UAAUtN,IAAIE,MAAJ,CAAW1c,GAAzB;AACA,YAAI,CAAC8pB,OAAD,IAAYA,QAAQr0C,MAAR,KAAmB,CAAnC,EAAsC;AAClCrC,qBAAIojC,KAAJ,CAAU,0DAAV,EAAsEsT,OAAtE;AACA,mBAAOlU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAsBi1C,OAAhC,CAAf,CAAP;AACH;;AAED,YAAIC,WAAWD,QAAQ7xC,MAAR,CAAe,CAAf,EAAkB,CAAlB,CAAf;AACA,YAAI,CAAC8xC,QAAL,EAAe;AACX32C,qBAAIojC,KAAJ,CAAU,0DAAV,EAAsEsT,OAAtE,EAA+EC,QAA/E;AACA,mBAAOnU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAsBi1C,OAAhC,CAAf,CAAP;AACH;;AAEDC,mBAAW/xC,SAAS+xC,QAAT,CAAX;AACA,YAAIA,aAAa,GAAb,IAAoBA,aAAa,GAAjC,IAAwCA,aAAa,GAAzD,EAA8D;AAC1D32C,qBAAIojC,KAAJ,CAAU,0DAAV,EAAsEsT,OAAtE,EAA+EC,QAA/E;AACA,mBAAOnU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAsBi1C,OAAhC,CAAf,CAAP;AACH;;AAED,YAAIE,MAAM,QAAQD,QAAlB;AACA,YAAI5oB,OAAO,KAAK4mB,SAAL,CAAehoB,UAAf,CAA0BkjB,SAAS3P,YAAnC,EAAiD0W,GAAjD,CAAX;AACA,YAAI,CAAC7oB,IAAL,EAAW;AACP/tB,qBAAIojC,KAAJ,CAAU,mEAAV,EAA+EwT,GAA/E;AACA,mBAAOpU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAED,YAAIo1C,OAAO9oB,KAAKlpB,MAAL,CAAY,CAAZ,EAAekpB,KAAK1rB,MAAL,GAAc,CAA7B,CAAX;AACA,YAAIy0C,YAAY,KAAKnC,SAAL,CAAerK,cAAf,CAA8BuM,IAA9B,CAAhB;AACA,YAAIC,cAAcjH,SAASwF,OAAT,CAAiBoB,OAAnC,EAA4C;AACxCz2C,qBAAIojC,KAAJ,CAAU,oEAAV,EAAgF0T,SAAhF,EAA2FjH,SAASwF,OAAT,CAAiBoB,OAA5G;AACA,mBAAOjU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,iDAAV;;AAEA,eAAOmC,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCndL;AACA;;AAEA;;AACA;;AACA;;;;IAEajvC,c,WAAAA,c;AAET,4BAAYm2C,WAAZ,EAA4F;AAAA;;AAAA,YAAnEC,sBAAmE,uEAA1Ct2C,sCAA0C;AAAA,YAAtBmmC,KAAsB,uEAAdhmC,eAAOgmC,KAAO;;AAAA;;AACxF,YAAI,CAACkQ,WAAL,EAAkB;AACd/2C,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,aAAV,CAAN;AACH;;AAED,aAAKw1C,YAAL,GAAoBF,WAApB;AACA,aAAKG,uBAAL,GAA+BF,sBAA/B;AACA,aAAKrT,MAAL,GAAckD,KAAd;;AAEA,aAAKoQ,YAAL,CAAkBE,MAAlB,CAAyBC,aAAzB,CAAuC,KAAKC,MAAL,CAAYtU,IAAZ,CAAiB,IAAjB,CAAvC;AACA,aAAKkU,YAAL,CAAkBE,MAAlB,CAAyBG,eAAzB,CAAyC,KAAKC,KAAL,CAAWxU,IAAX,CAAgB,IAAhB,CAAzC;;AAEA,aAAKkU,YAAL,CAAkBO,OAAlB,GAA4BnN,IAA5B,CAAiC,gBAAQ;AACrC;AACA;AACA,gBAAIoN,IAAJ,EAAU;AACN,sBAAKJ,MAAL,CAAYI,IAAZ;AACH,aAFD,MAGK,IAAI,MAAK9K,SAAL,CAAe+K,uBAAnB,EAA4C;AAC7C,sBAAKT,YAAL,CAAkBU,kBAAlB,GAAuCtN,IAAvC,CAA4C,mBAAW;AACnD,wBAAIuN,UAAU;AACVrU,uCAAgBsU,QAAQtU;AADd,qBAAd;AAGA,wBAAIsU,QAAQna,GAAR,IAAema,QAAQC,GAA3B,EAAgC;AAC5BF,gCAAQvC,OAAR,GAAkB;AACd3X,iCAAKma,QAAQna,GADC;AAEdoa,iCAAKD,QAAQC;AAFC,yBAAlB;AAIH;AACD,0BAAKT,MAAL,CAAYO,OAAZ;AACH,iBAXD,EAYCG,KAZD,CAYO,eAAO;AACV;AACA/3C,6BAAIojC,KAAJ,CAAU,qDAAV,EAAiE4U,IAAIhS,OAArE;AACH,iBAfD;AAgBH;AACJ,SAxBD,EAwBG+R,KAxBH,CAwBS,eAAO;AACZ;AACA/3C,qBAAIojC,KAAJ,CAAU,0CAAV,EAAsD4U,IAAIhS,OAA1D;AACH,SA3BD;AA4BH;;6BAkBDqR,M,mBAAOI,I,EAAM;AAAA;;AACT,YAAIlU,gBAAgBkU,KAAKlU,aAAzB;;AAEA,YAAIA,aAAJ,EAAmB;AACf,gBAAIkU,KAAKpC,OAAT,EAAkB;AACd,qBAAK4C,IAAL,GAAYR,KAAKpC,OAAL,CAAa3X,GAAzB;AACA,qBAAKwa,IAAL,GAAYT,KAAKpC,OAAL,CAAayC,GAAzB;AACA93C,yBAAIqgC,KAAJ,CAAU,uCAAV,EAAmDkD,aAAnD,EAAkE,QAAlE,EAA4E,KAAK0U,IAAjF;AACH,aAJD,MAKK;AACD,qBAAKA,IAAL,GAAY92C,SAAZ;AACA,qBAAK+2C,IAAL,GAAY/2C,SAAZ;AACAnB,yBAAIqgC,KAAJ,CAAU,uCAAV,EAAmDkD,aAAnD,EAAkE,kBAAlE;AACH;;AAED,gBAAI,CAAC,KAAK4U,mBAAV,EAA+B;AAC3B,qBAAKjJ,gBAAL,CAAsB7B,qBAAtB,GAA8ChD,IAA9C,CAAmD,eAAO;AACtD,wBAAIjJ,GAAJ,EAAS;AACLphC,iCAAIqgC,KAAJ,CAAU,0DAAV;;AAEA,4BAAIc,YAAY,OAAKK,UAArB;AACA,4BAAIH,WAAW,OAAK+W,qBAApB;AACA,4BAAI9W,cAAc,OAAK+W,wBAAvB;;AAEA,+BAAKF,mBAAL,GAA2B,IAAI,OAAKjB,uBAAT,CAAiC,OAAK3V,SAAL,CAAewB,IAAf,CAAoB,MAApB,CAAjC,EAA4D5B,SAA5D,EAAuEC,GAAvE,EAA4EC,QAA5E,EAAsFC,WAAtF,CAA3B;AACA,+BAAK6W,mBAAL,CAAyBnY,IAAzB,GAAgCqK,IAAhC,CAAqC,YAAM;AACvC,mCAAK8N,mBAAL,CAAyB7U,KAAzB,CAA+BC,aAA/B;AACH,yBAFD;AAGH,qBAXD,MAYK;AACDvjC,iCAAI8rC,IAAJ,CAAS,sEAAT;AACH;AACJ,iBAhBD,EAgBGiM,KAhBH,CAgBS,eAAO;AACZ;AACA/3C,6BAAIojC,KAAJ,CAAU,0DAAV,EAAsE4U,IAAIhS,OAA1E;AACH,iBAnBD;AAoBH,aArBD,MAsBK;AACD,qBAAKmS,mBAAL,CAAyB7U,KAAzB,CAA+BC,aAA/B;AACH;AACJ;AACJ,K;;6BAEDgU,K,oBAAQ;AAAA;;AACJ,aAAKU,IAAL,GAAY92C,SAAZ;AACA,aAAK+2C,IAAL,GAAY/2C,SAAZ;;AAEA,YAAI,KAAKg3C,mBAAT,EAA8B;AAC1Bn4C,qBAAIqgC,KAAJ,CAAU,sBAAV;AACA,iBAAK8X,mBAAL,CAAyB9U,IAAzB;AACH;;AAED,YAAI,KAAKsJ,SAAL,CAAe+K,uBAAnB,EAA4C;AACxC;AACA,gBAAIY,cAAc,KAAK3U,MAAL,CAAYC,WAAZ,CAAwB,YAAI;AAC1C,uBAAKD,MAAL,CAAYE,aAAZ,CAA0ByU,WAA1B;;AAEA,uBAAKrB,YAAL,CAAkBU,kBAAlB,GAAuCtN,IAAvC,CAA4C,mBAAW;AACnD,wBAAIuN,UAAU;AACVrU,uCAAgBsU,QAAQtU;AADd,qBAAd;AAGA,wBAAIsU,QAAQna,GAAR,IAAema,QAAQC,GAA3B,EAAgC;AAC5BF,gCAAQvC,OAAR,GAAkB;AACd3X,iCAAKma,QAAQna,GADC;AAEdoa,iCAAKD,QAAQC;AAFC,yBAAlB;AAIH;AACD,2BAAKT,MAAL,CAAYO,OAAZ;AACH,iBAXD,EAYCG,KAZD,CAYO,eAAO;AACV;AACA/3C,6BAAIojC,KAAJ,CAAU,gDAAV,EAA4D4U,IAAIhS,OAAhE;AACH,iBAfD;AAiBH,aApBiB,EAoBf,IApBe,CAAlB;AAqBH;AACJ,K;;6BAEDzE,S,wBAAY;AAAA;;AACR,aAAK0V,YAAL,CAAkBU,kBAAlB,GAAuCtN,IAAvC,CAA4C,mBAAW;AACnD,gBAAIkO,aAAa,IAAjB;;AAEA,gBAAIV,OAAJ,EAAa;AACT,oBAAIA,QAAQna,GAAR,KAAgB,OAAKua,IAAzB,EAA+B;AAC3BM,iCAAa,KAAb;AACA,2BAAKJ,mBAAL,CAAyB7U,KAAzB,CAA+BuU,QAAQtU,aAAvC;;AAEA,wBAAIsU,QAAQC,GAAR,KAAgB,OAAKI,IAAzB,EAA+B;AAC3Bl4C,iCAAIqgC,KAAJ,CAAU,2GAAV,EAAuHwX,QAAQtU,aAA/H;AACH,qBAFD,MAGK;AACDvjC,iCAAIqgC,KAAJ,CAAU,sIAAV,EAAkJwX,QAAQtU,aAA1J;AACA,+BAAK0T,YAAL,CAAkBE,MAAlB,CAAyBqB,wBAAzB;AACH;AACJ,iBAXD,MAYK;AACDx4C,6BAAIqgC,KAAJ,CAAU,6DAAV,EAAyEwX,QAAQna,GAAjF;AACH;AACJ,aAhBD,MAiBK;AACD19B,yBAAIqgC,KAAJ,CAAU,4DAAV;AACH;;AAED,gBAAIkY,UAAJ,EAAgB;AACZ,oBAAI,OAAKN,IAAT,EAAe;AACXj4C,6BAAIqgC,KAAJ,CAAU,8EAAV;AACA,2BAAK4W,YAAL,CAAkBE,MAAlB,CAAyBsB,mBAAzB;AACH,iBAHD,MAIK;AACDz4C,6BAAIqgC,KAAJ,CAAU,6EAAV;AACA,2BAAK4W,YAAL,CAAkBE,MAAlB,CAAyBuB,kBAAzB;AACH;AACJ;AACJ,SAlCD,EAkCGX,KAlCH,CAkCS,eAAO;AACZ,gBAAI,OAAKE,IAAT,EAAe;AACXj4C,yBAAIqgC,KAAJ,CAAU,6FAAV,EAAyG2X,IAAIhS,OAA7G;AACA,uBAAKiR,YAAL,CAAkBE,MAAlB,CAAyBsB,mBAAzB;AACH;AACJ,SAvCD;AAwCH,K;;;;4BAvIe;AACZ,mBAAO,KAAKxB,YAAL,CAAkBxK,QAAzB;AACH;;;4BACsB;AACnB,mBAAO,KAAKwK,YAAL,CAAkB7F,eAAzB;AACH;;;4BACgB;AACb,mBAAO,KAAKzE,SAAL,CAAexL,SAAtB;AACH;;;4BAC2B;AACxB,mBAAO,KAAKwL,SAAL,CAAegM,oBAAtB;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKhM,SAAL,CAAeiM,uBAAtB;AACH;;;;;;;;;;;;;;;;;;;;;;;AC/DL;;AACA;;AACA;;0JALA;AACA;;IAMa5J,a,WAAAA,a;AACT,iCAMG;AAAA,YAJC5N,GAID,QAJCA,GAID;AAAA,YAJMD,SAIN,QAJMA,SAIN;AAAA,YAJiByD,YAIjB,QAJiBA,YAIjB;AAAA,YAJ+BoJ,aAI/B,QAJ+BA,aAI/B;AAAA,YAJ8CC,KAI9C,QAJ8CA,KAI9C;AAAA,YAJqDH,SAIrD,QAJqDA,SAIrD;AAAA,YAFCxZ,IAED,QAFCA,IAED;AAAA,YAFO4Z,MAEP,QAFOA,MAEP;AAAA,YAFe9L,OAEf,QAFeA,OAEf;AAAA,YAFwB+L,OAExB,QAFwBA,OAExB;AAAA,YAFiCC,UAEjC,QAFiCA,UAEjC;AAAA,YAF6CC,aAE7C,QAF6CA,aAE7C;AAAA,YAF4DC,UAE5D,QAF4DA,UAE5D;AAAA,YAFwEC,UAExE,QAFwEA,UAExE;AAAA,YAFoFC,QAEpF,QAFoFA,QAEpF;AAAA,YAF8FE,aAE9F,QAF8FA,aAE9F;AAAA,YADC1H,OACD,QADCA,OACD;AAAA,YADUyH,WACV,QADUA,WACV;AAAA,YADuBE,gBACvB,QADuBA,gBACvB;AAAA,YADyCE,YACzC,QADyCA,YACzC;AAAA,YADuDO,aACvD,QADuDA,aACvD;AAAA,YADsER,gBACtE,QADsEA,gBACtE;AAAA,YADwFE,YACxF,QADwFA,YACxF;;AAAA;;AACC,YAAI,CAAC1N,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,mCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;AACD,YAAI,CAAC0/B,SAAL,EAAgB;AACZnhC,qBAAIojC,KAAJ,CAAU,yCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,WAAV,CAAN;AACH;AACD,YAAI,CAACmjC,YAAL,EAAmB;AACf5kC,qBAAIojC,KAAJ,CAAU,4CAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,cAAV,CAAN;AACH;AACD,YAAI,CAACusC,aAAL,EAAoB;AAChBhuC,qBAAIojC,KAAJ,CAAU,6CAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,eAAV,CAAN;AACH;AACD,YAAI,CAACwsC,KAAL,EAAY;AACRjuC,qBAAIojC,KAAJ,CAAU,qCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,OAAV,CAAN;AACH;AACD,YAAI,CAACqsC,SAAL,EAAgB;AACZ9tC,qBAAIojC,KAAJ,CAAU,yCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,WAAV,CAAN;AACH;;AAED,YAAIo3C,OAAO7J,cAAc8J,MAAd,CAAqB9K,aAArB,CAAX;AACA,YAAImH,OAAOnG,cAAcC,MAAd,CAAqBjB,aAArB,CAAX;;AAEA,YAAI,CAACU,aAAL,EAAoB;AAChBA,4BAAgBM,cAAcC,MAAd,CAAqBjB,aAArB,IAAsC,OAAtC,GAAgD,IAAhE;AACH;;AAED,aAAKte,KAAL,GAAa,IAAIwgB,wBAAJ,CAAgB,EAAE8E,OAAO6D,IAAT;AACzBvkB,sBADyB,EACnB6M,oBADmB,EACR2M,oBADQ,EACGlJ,0BADH;AAEzBsQ,2BAAeC,IAFU;AAGzBtG,sCAHyB,EAGXH,4BAHW;AAIzBU,wCAJyB,EAIVnB,YAJU,EAIHW,kCAJG,EAIeE,0BAJf,EAAhB,CAAb;;AAMA1N,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,WAA9B,EAA2CD,SAA3C,CAAN;AACAC,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,cAA9B,EAA8CwD,YAA9C,CAAN;AACAxD,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,eAA9B,EAA+C4M,aAA/C,CAAN;AACA5M,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC6M,KAAvC,CAAN;;AAEA7M,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC,KAAK1R,KAAL,CAAW8L,EAAlD,CAAN;AACA,YAAIqd,IAAJ,EAAU;AACNzX,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC,KAAK1R,KAAL,CAAWslB,KAAlD,CAAN;AACH;AACD,YAAIG,IAAJ,EAAU;AACN/T,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,gBAA9B,EAAgD,KAAK1R,KAAL,CAAWspB,cAA3D,CAAN;AACA5X,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,uBAA9B,EAAuD,MAAvD,CAAN;AACH;;AAED,YAAIgM,WAAW,EAAEc,cAAF,EAAU9L,gBAAV,EAAmB+L,gBAAnB,EAA4BC,sBAA5B,EAAwCC,4BAAxC,EAAuDC,sBAAvD,EAAmEC,sBAAnE,EAA+EC,kBAA/E,EAAyFxH,gBAAzF,EAAkGyH,wBAAlG,EAA+GC,4BAA/G,EAAf;AACA,aAAI,IAAI5a,GAAR,IAAesZ,QAAf,EAAwB;AACpB,gBAAIA,SAAStZ,GAAT,CAAJ,EAAmB;AACfsN,sBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8BtN,GAA9B,EAAmCsZ,SAAStZ,GAAT,CAAnC,CAAN;AACH;AACJ;;AAED,aAAI,IAAIA,IAAR,IAAe6a,gBAAf,EAAgC;AAC5BvN,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8BtN,IAA9B,EAAmC6a,iBAAiB7a,IAAjB,CAAnC,CAAN;AACH;;AAED,aAAKsN,GAAL,GAAWA,GAAX;AACH;;kBAEM0X,M,mBAAO9K,a,EAAe;AACzB,YAAI2H,SAAS3H,cAAcrtB,KAAd,CAAoB,MAApB,EAA4B61B,MAA5B,CAAmC,UAAS7P,IAAT,EAAe;AAC3D,mBAAOA,SAAS,UAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAEgP,OAAO,CAAP,CAAV;AACH,K;;kBAEMsD,O,oBAAQjL,a,EAAe;AAC1B,YAAI2H,SAAS3H,cAAcrtB,KAAd,CAAoB,MAApB,EAA4B61B,MAA5B,CAAmC,UAAS7P,IAAT,EAAe;AAC3D,mBAAOA,SAAS,OAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAEgP,OAAO,CAAP,CAAV;AACH,K;;kBAEM1G,M,mBAAOjB,a,EAAe;AACzB,YAAI2H,SAAS3H,cAAcrtB,KAAd,CAAoB,MAApB,EAA4B61B,MAA5B,CAAmC,UAAS7P,IAAT,EAAe;AAC3D,mBAAOA,SAAS,MAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAEgP,OAAO,CAAP,CAAV;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCpGL;AACA;;AAEA;;;;AAEA,IAAMuD,YAAY,QAAlB;;IAEapJ,c,WAAAA,c;AACT,4BAAY1O,GAAZ,EAAkC;AAAA,YAAjBwO,SAAiB,uEAAL,GAAK;;AAAA;;AAE9B,YAAIiG,SAAS7B,uBAAWC,gBAAX,CAA4B7S,GAA5B,EAAiCwO,SAAjC,CAAb;;AAEA,aAAKxM,KAAL,GAAayS,OAAOzS,KAApB;AACA,aAAKiD,iBAAL,GAAyBwP,OAAOxP,iBAAhC;AACA,aAAKC,SAAL,GAAiBuP,OAAOvP,SAAxB;;AAEA,aAAK6O,IAAL,GAAYU,OAAOV,IAAnB;AACA,aAAKzlB,KAAL,GAAammB,OAAOnmB,KAApB;AACA,aAAKulB,QAAL,GAAgBY,OAAOZ,QAAvB;AACA,aAAK1R,aAAL,GAAqBsS,OAAOtS,aAA5B;AACA,aAAKrD,YAAL,GAAoB2V,OAAO3V,YAA3B;AACA,aAAKiZ,UAAL,GAAkBtD,OAAOsD,UAAzB;AACA,aAAKlL,KAAL,GAAa4H,OAAO5H,KAApB;AACA,aAAKoH,OAAL,GAAel0C,SAAf,CAf8B,CAeJ;;AAE1B,aAAKg/B,UAAL,GAAkB0V,OAAO1V,UAAzB;AACH;;;;4BAEgB;AACb,gBAAI,KAAKiZ,UAAT,EAAqB;AACjB,oBAAIxP,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,uBAAO,KAAKwP,UAAL,GAAkBxP,GAAzB;AACH;AACD,mBAAOzoC,SAAP;AACH,S;0BACcwnC,K,EAAM;AACjB,gBAAIxI,aAAav7B,SAAS+jC,KAAT,CAAjB;AACA,gBAAI,OAAOxI,UAAP,KAAsB,QAAtB,IAAkCA,aAAa,CAAnD,EAAsD;AAClD,oBAAIyJ,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,qBAAKwP,UAAL,GAAkBxP,MAAMzJ,UAAxB;AACH;AACJ;;;4BAEa;AACV,gBAAIA,aAAa,KAAKA,UAAtB;AACA,gBAAIA,eAAeh/B,SAAnB,EAA8B;AAC1B,uBAAOg/B,cAAc,CAArB;AACH;AACD,mBAAOh/B,SAAP;AACH;;;4BAEY;AACT,mBAAO,CAAC,KAAK8sC,KAAL,IAAc,EAAf,EAAmBttB,KAAnB,CAAyB,GAAzB,CAAP;AACH;;;4BAEqB;AAClB,mBAAO,KAAK04B,MAAL,CAAY3xC,OAAZ,CAAoBwxC,SAApB,KAAkC,CAAlC,IAAuC,CAAC,CAAC,KAAKjE,QAArD;AACH;;;;;;;;;;;;;;;;;;;;;;;;;ACtDL;;AACA;;AACA;;AACA;;;;;;;;;;+eANA;AACA;;IAOa/E,W,WAAAA,W;;;AACT,2BAAkJ;AAAA,uFAAJ,EAAI;AAAA,YAArI8E,KAAqI,QAArIA,KAAqI;AAAA,YAA9HlH,SAA8H,QAA9HA,SAA8H;AAAA,YAAnH3M,SAAmH,QAAnHA,SAAmH;AAAA,YAAxGyD,YAAwG,QAAxGA,YAAwG;AAAA,YAA1FsQ,aAA0F,QAA1FA,aAA0F;AAAA,YAA3ExG,aAA2E,QAA3EA,aAA2E;AAAA,YAA5DU,aAA4D,QAA5DA,aAA4D;AAAA,YAA7CnB,KAA6C,QAA7CA,KAA6C;AAAA,YAAtCW,gBAAsC,QAAtCA,gBAAsC;AAAA,YAApBE,YAAoB,QAApBA,YAAoB;;AAAA;;AAAA,qDAC9I,kBAAM1rC,UAAU,CAAV,CAAN,CAD8I;;AAG9I,YAAI4xC,UAAU,IAAd,EAAoB;AAChB,kBAAKsE,MAAL,GAAc,uBAAd;AACH,SAFD,MAGK,IAAItE,KAAJ,EAAW;AACZ,kBAAKsE,MAAL,GAActE,KAAd;AACH;;AAED,YAAIE,kBAAkB,IAAtB,EAA4B;AACxB;AACA,kBAAKqE,cAAL,GAAsB,0BAAW,uBAAX,GAAsB,uBAA5C;AACH,SAHD,MAIK,IAAIrE,aAAJ,EAAmB;AACpB,kBAAKqE,cAAL,GAAsBrE,aAAtB;AACH;;AAED,YAAI,MAAKA,aAAT,EAAwB;AACpB,gBAAInnB,OAAOgb,mBAASpc,UAAT,CAAoB,MAAKuoB,aAAzB,EAAwC,QAAxC,CAAX;AACA,kBAAKsE,eAAL,GAAuBzQ,mBAASuB,cAAT,CAAwBvc,IAAxB,CAAvB;AACH;;AAED,cAAKskB,aAAL,GAAqBzN,YAArB;AACA,cAAKmN,UAAL,GAAkBjE,SAAlB;AACA,cAAKtM,UAAL,GAAkBL,SAAlB;AACA,cAAK0R,cAAL,GAAsBnE,aAAtB;AACA,cAAKwD,cAAL,GAAsB9C,aAAtB;AACA,cAAKgD,MAAL,GAAcnE,KAAd;AACA,cAAKmF,iBAAL,GAAyBxE,gBAAzB;AACA,cAAK6K,aAAL,GAAqB3K,YAArB;AA9B8I;AA+BjJ;;0BAoCDU,e,8BAAkB;AACdxvC,iBAAIqgC,KAAJ,CAAU,6BAAV;AACA,eAAOra,KAAKriB,SAAL,CAAe;AAClB63B,gBAAI,KAAKA,EADS;AAElBlH,kBAAM,KAAKA,IAFO;AAGlBolB,qBAAS,KAAKA,OAHI;AAIlB7K,0BAAc,KAAKA,YAJD;AAKlBmG,mBAAO,KAAKA,KALM;AAMlBE,2BAAe,KAAKA,aANF;AAOlBtQ,0BAAc,KAAKA,YAPD;AAQlBkJ,uBAAW,KAAKA,SARE;AASlB3M,uBAAW,KAAKA,SATE;AAUlBuN,2BAAe,KAAKA,aAVF;AAWlBU,2BAAe,KAAKA,aAXF;AAYlBnB,mBAAO,KAAKA,KAZM;AAalBW,8BAAmB,KAAKA,gBAbN;AAclBE,0BAAc,KAAKA;AAdD,SAAf,CAAP;AAgBH,K;;gBAEMqB,iB,8BAAkBwJ,a,EAAe;AACpC35C,iBAAIqgC,KAAJ,CAAU,+BAAV;AACA,YAAI/L,OAAOtO,KAAKrhB,KAAL,CAAWg1C,aAAX,CAAX;AACA,eAAO,IAAIzJ,WAAJ,CAAgB5b,IAAhB,CAAP;AACH,K;;;;4BA1DW;AACR,mBAAO,KAAKglB,MAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKvH,UAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKvQ,UAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAK6Q,aAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKkH,cAAZ;AACH;;;4BACoB;AACjB,mBAAO,KAAKC,eAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAK3G,cAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKX,cAAZ;AACH;;;4BACW;AACR,mBAAO,KAAKE,MAAZ;AACH;;;4BACsB;AACnB,mBAAO,KAAKgB,iBAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKqG,aAAZ;AACH;;;;EAlE4B3I,a;;;;;;;;;;;;;;;;;;;ACLjC;;AACA;;AACA;;0JALA;AACA;;IAMaL,c,WAAAA,c,GACT,8BAAkG;AAAA,QAArFrP,GAAqF,QAArFA,GAAqF;AAAA,QAAhFiN,aAAgF,QAAhFA,aAAgF;AAAA,QAAjEmC,wBAAiE,QAAjEA,wBAAiE;AAAA,QAAvClc,IAAuC,QAAvCA,IAAuC;AAAA,QAAjCqa,gBAAiC,QAAjCA,gBAAiC;AAAA,QAAfE,YAAe,QAAfA,YAAe;;AAAA;;AAC9F,QAAI,CAACzN,GAAL,EAAU;AACNphC,iBAAIojC,KAAJ,CAAU,oCAAV;AACA,cAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;;AAED,QAAI4sC,aAAJ,EAAmB;AACfjN,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,eAA9B,EAA+CiN,aAA/C,CAAN;AACH;;AAED,QAAImC,wBAAJ,EAA8B;AAC1BpP,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,0BAA9B,EAA0DoP,wBAA1D,CAAN;;AAEA,YAAIlc,IAAJ,EAAU;AACN,iBAAK5E,KAAL,GAAa,IAAIohB,YAAJ,CAAU,EAAExc,UAAF,EAAQua,0BAAR,EAAV,CAAb;;AAEAzN,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC,KAAK1R,KAAL,CAAW8L,EAAlD,CAAN;AACH;AACJ;;AAED,SAAI,IAAI1H,GAAR,IAAe6a,gBAAf,EAAgC;AAC5BvN,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8BtN,GAA9B,EAAmC6a,iBAAiB7a,GAAjB,CAAnC,CAAN;AACH;;AAED,SAAKsN,GAAL,GAAWA,GAAX;AACH,C;;;;;;;;;;;;;;;;;;;AC9BL;;0JAHA;AACA;;IAIawP,e,WAAAA,e,GACT,yBAAYxP,GAAZ,EAAiB;AAAA;;AAEb,YAAIyU,SAAS7B,uBAAWC,gBAAX,CAA4B7S,GAA5B,EAAiC,GAAjC,CAAb;;AAEA,aAAKgC,KAAL,GAAayS,OAAOzS,KAApB;AACA,aAAKiD,iBAAL,GAAyBwP,OAAOxP,iBAAhC;AACA,aAAKC,SAAL,GAAiBuP,OAAOvP,SAAxB;;AAEA,aAAK5W,KAAL,GAAammB,OAAOnmB,KAApB;AACH,C;;;;;;;;;;;;;;;;;;;ACZL;;0JAHA;AACA;;IAIakqB,kB,WAAAA,kB;AAET,gCAAY7C,WAAZ,EAAyB;AAAA;;AACrB,aAAKE,YAAL,GAAoBF,WAApB;AACH;;iCAEDzT,K,oBAAQ;AACJ,YAAI,CAAC,KAAK/B,SAAV,EAAqB;AACjB,iBAAKA,SAAL,GAAiB,KAAKsY,cAAL,CAAoB9W,IAApB,CAAyB,IAAzB,CAAjB;AACA,iBAAKkU,YAAL,CAAkBE,MAAlB,CAAyBzW,sBAAzB,CAAgD,KAAKa,SAArD;;AAEA;AACA,iBAAK0V,YAAL,CAAkBO,OAAlB,GAA4BnN,IAA5B,CAAiC,gBAAM;AACnC;AACH,aAFD,EAEG0N,KAFH,CAES,eAAK;AACV;AACA/3C,yBAAIojC,KAAJ,CAAU,+CAAV,EAA2D4U,IAAIhS,OAA/D;AACH,aALD;AAMH;AACJ,K;;iCAED3C,I,mBAAO;AACH,YAAI,KAAK9B,SAAT,EAAoB;AAChB,iBAAK0V,YAAL,CAAkBE,MAAlB,CAAyBtW,yBAAzB,CAAmD,KAAKU,SAAxD;AACA,mBAAO,KAAKA,SAAZ;AACH;AACJ,K;;iCAEDsY,c,6BAAiB;AAAA;;AACb,aAAK5C,YAAL,CAAkB6C,YAAlB,GAAiCzP,IAAjC,CAAsC,gBAAQ;AAC1CrqC,qBAAIqgC,KAAJ,CAAU,oEAAV;AACH,SAFD,EAEG,eAAO;AACNrgC,qBAAIojC,KAAJ,CAAU,6DAAV,EAAyE4U,IAAIhS,OAA7E;AACA,kBAAKiR,YAAL,CAAkBE,MAAlB,CAAyB4C,sBAAzB,CAAgD/B,GAAhD;AACH,SALD;AAMH,K;;;;;;;;;;;;;;;;;;;;;;qjBCxCL;AACA;;AAEA;;AACA;;;;;;;;IAEalH,K,WAAAA,K;AACT,qBAAoD;AAAA,uFAAJ,EAAI;AAAA,YAAvCtV,EAAuC,QAAvCA,EAAuC;AAAA,YAAnClH,IAAmC,QAAnCA,IAAmC;AAAA,YAA7BolB,OAA6B,QAA7BA,OAA6B;AAAA,YAApB7K,YAAoB,QAApBA,YAAoB;;AAAA;;AAChD,aAAK+E,GAAL,GAAWpY,MAAM,uBAAjB;AACA,aAAK/1B,KAAL,GAAa6uB,IAAb;;AAEA,YAAI,OAAOolB,OAAP,KAAmB,QAAnB,IAA+BA,UAAU,CAA7C,EAAgD;AAC5C,iBAAKM,QAAL,GAAgBN,OAAhB;AACH,SAFD,MAGK;AACD,iBAAKM,QAAL,GAAgBp1C,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAhB;AACH;AACD,aAAKqQ,aAAL,GAAsBpL,YAAtB;AACH;;oBAeDW,e,8BAAkB;AACdxvC,iBAAIqgC,KAAJ,CAAU,uBAAV;AACA,eAAOra,KAAKriB,SAAL,CAAe;AAClB63B,gBAAI,KAAKA,EADS;AAElBlH,kBAAM,KAAKA,IAFO;AAGlBolB,qBAAS,KAAKA,OAHI;AAIlB7K,0BAAc,KAAKA;AAJD,SAAf,CAAP;AAMH,K;;UAEMsB,iB,8BAAkBwJ,a,EAAe;AACpC35C,iBAAIqgC,KAAJ,CAAU,yBAAV;AACA,eAAO,IAAIyQ,KAAJ,CAAU9qB,KAAKrhB,KAAL,CAAWg1C,aAAX,CAAV,CAAP;AACH,K;;UAEM1I,e,4BAAgBiJ,O,EAASC,G,EAAK;;AAEjC,YAAIC,SAAS7hC,KAAKqxB,GAAL,KAAa,IAAb,GAAoBuQ,GAAjC;;AAEA,eAAOD,QAAQG,UAAR,GAAqBhQ,IAArB,CAA0B,gBAAQ;AACrCrqC,qBAAIqgC,KAAJ,CAAU,iCAAV,EAA6CngB,IAA7C;;AAEA,gBAAIo6B,WAAW,EAAf;;AAHqC,uCAI5Bl4C,CAJ4B;AAKjC,oBAAI0xB,MAAM5T,KAAK9d,CAAL,CAAV;AACIS,oBAAIq3C,QAAQjb,GAAR,CAAYnL,GAAZ,EAAiBuW,IAAjB,CAAsB,gBAAQ;AAClC,wBAAI2F,SAAS,KAAb;;AAEA,wBAAIrJ,IAAJ,EAAU;AACN,4BAAI;AACA,gCAAIjX,QAAQohB,MAAMX,iBAAN,CAAwBxJ,IAAxB,CAAZ;;AAEA3mC,qCAAIqgC,KAAJ,CAAU,4CAAV,EAAwDvM,GAAxD,EAA6DpE,MAAMgqB,OAAnE;;AAEA,gCAAIhqB,MAAMgqB,OAAN,IAAiBU,MAArB,EAA6B;AACzBpK,yCAAS,IAAT;AACH;AACJ,yBARD,CASA,OAAOhuC,CAAP,EAAU;AACNhC,qCAAIojC,KAAJ,CAAU,oDAAV,EAAgEtP,GAAhE,EAAqE9xB,EAAEgkC,OAAvE;AACAgK,qCAAS,IAAT;AACH;AACJ,qBAdD,MAeK;AACDhwC,iCAAIqgC,KAAJ,CAAU,qDAAV,EAAiEvM,GAAjE;AACAkc,iCAAS,IAAT;AACH;;AAED,wBAAIA,MAAJ,EAAY;AACRhwC,iCAAIqgC,KAAJ,CAAU,+CAAV,EAA2DvM,GAA3D;AACA,+BAAOomB,QAAQlK,MAAR,CAAelc,GAAf,CAAP;AACH;AACJ,iBA3BO,CANyB;;;AAmCjCwmB,yBAASh2C,IAAT,CAAczB,CAAd;AAnCiC;;AAIrC,iBAAK,IAAIT,IAAI,CAAb,EAAgBA,IAAI8d,KAAK7d,MAAzB,EAAiCD,GAAjC,EAAsC;AAAA,oBAE9BS,CAF8B;;AAAA,sBAA7BT,CAA6B;AAgCrC;;AAEDpC,qBAAIqgC,KAAJ,CAAU,kDAAV,EAA8Dia,SAASj4C,MAAvE;AACA,mBAAOmgC,QAAQ+X,GAAR,CAAYD,QAAZ,CAAP;AACH,SAxCM,CAAP;AAyCH,K;;;;4BAzEQ;AACL,mBAAO,KAAK1G,GAAZ;AACH;;;4BACU;AACP,mBAAO,KAAKnuC,KAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKu0C,QAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;;;AC5BL;;AACA;;AACA;;;;;;+eALA;AACA;;AAMA,IAAMO,gBAAgB,CAAtB,C,CAAyB;;IAEZ7a,K,WAAAA,K;;;AAET,mBAAYzb,IAAZ,EAA6D;AAAA,YAA3C2iB,KAA2C,uEAAnChmC,eAAOgmC,KAA4B;AAAA,YAArB4T,OAAqB,uEAAXt5C,SAAW;;AAAA;;AAAA,qDACzD,kBAAM+iB,IAAN,CADyD;;AAEzD,cAAKyf,MAAL,GAAckD,KAAd;;AAEA,YAAI4T,OAAJ,EAAa;AACT,kBAAKC,QAAL,GAAgBD,OAAhB;AACH,SAFD,MAGK;AACD,kBAAKC,QAAL,GAAgB;AAAA,uBAAMniC,KAAKqxB,GAAL,KAAa,IAAnB;AAAA,aAAhB;AACH;AATwD;AAU5D;;oBAMD3mC,I,iBAAKm9B,Q,EAAU;AACX,YAAIA,YAAY,CAAhB,EAAmB;AACfA,uBAAW,CAAX;AACH;AACDA,mBAAWx7B,SAASw7B,QAAT,CAAX;;AAEA,YAAIua,aAAa,KAAK/Q,GAAL,GAAWxJ,QAA5B;AACA,YAAI,KAAKua,UAAL,KAAoBA,UAApB,IAAkC,KAAKC,YAA3C,EAAyD;AACrD;AACA56C,qBAAIqgC,KAAJ,CAAU,sBAAsB,KAAKmG,KAA3B,GAAmC,oEAA7C,EAAmH,KAAKmU,UAAxH;AACA;AACH;;AAED,aAAKpa,MAAL;;AAEAvgC,iBAAIqgC,KAAJ,CAAU,sBAAsB,KAAKmG,KAA3B,GAAmC,gBAA7C,EAA+DpG,QAA/D;AACA,aAAKya,WAAL,GAAmBF,UAAnB;;AAEA;AACA;AACA;AACA,YAAIG,gBAAgBN,aAApB;AACA,YAAIpa,WAAW0a,aAAf,EAA8B;AAC1BA,4BAAgB1a,QAAhB;AACH;AACD,aAAKwa,YAAL,GAAoB,KAAKjX,MAAL,CAAYC,WAAZ,CAAwB,KAAKrC,SAAL,CAAewB,IAAf,CAAoB,IAApB,CAAxB,EAAmD+X,gBAAgB,IAAnE,CAApB;AACH,K;;oBAMDva,M,qBAAS;AACL,YAAI,KAAKqa,YAAT,EAAuB;AACnB56C,qBAAIqgC,KAAJ,CAAU,gBAAV,EAA4B,KAAKmG,KAAjC;AACA,iBAAK7C,MAAL,CAAYE,aAAZ,CAA0B,KAAK+W,YAA/B;AACA,iBAAKA,YAAL,GAAoB,IAApB;AACH;AACJ,K;;oBAEDrZ,S,wBAAY;AACR,YAAIwZ,OAAO,KAAKF,WAAL,GAAmB,KAAKjR,GAAnC;AACA5pC,iBAAIqgC,KAAJ,CAAU,qBAAqB,KAAKmG,KAA1B,GAAkC,oBAA5C,EAAkEuU,IAAlE;;AAEA,YAAI,KAAKF,WAAL,IAAoB,KAAKjR,GAA7B,EAAkC;AAC9B,iBAAKrJ,MAAL;AACA,6BAAMqG,KAAN;AACH;AACJ,K;;;;4BApDS;AACN,mBAAOhiC,SAAS,KAAK81C,QAAL,EAAT,CAAP;AACH;;;4BA8BgB;AACb,mBAAO,KAAKG,WAAZ;AACH;;;;EAhDsBtU,a;;;;;;;;;;;;;;;;;;;ACN3B;;AACA;;AACA;;0JALA;AACA;;IAMakO,W,WAAAA,W;AACT,yBAAYhI,QAAZ,EAA4F;AAAA,YAAtEC,eAAsE,uEAApDnC,wBAAoD;AAAA,YAAvCuH,mBAAuC,uEAAjBvxC,gCAAiB;;AAAA;;AACxF,YAAI,CAACksC,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,sCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,EAApB;AACA,aAAKwC,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACH;;0BAEDuJ,Y,2BAAwB;AAAA;;AAAA,YAAX5J,IAAW,uEAAJ,EAAI;;AACpBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAK0O,UAAL,GAAkB1O,KAAK0O,UAAL,IAAmB,oBAArC;AACA1O,aAAKnL,SAAL,GAAiBmL,KAAKnL,SAAL,IAAkB,KAAKwL,SAAL,CAAexL,SAAlD;AACAmL,aAAK1H,YAAL,GAAoB0H,KAAK1H,YAAL,IAAqB,KAAK+H,SAAL,CAAe/H,YAAxD;;AAEA,YAAI,CAAC0H,KAAK6I,IAAV,EAAgB;AACZn1C,qBAAIojC,KAAJ,CAAU,0CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,oBAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAK1H,YAAV,EAAwB;AACpB5kC,qBAAIojC,KAAJ,CAAU,kDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAK4I,aAAV,EAAyB;AACrBl1C,qBAAIojC,KAAJ,CAAU,mDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAKnL,SAAV,EAAqB;AACjBnhC,qBAAIojC,KAAJ,CAAU,+CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsB/B,gBAAtB,CAAuC,KAAvC,EAA8C9C,IAA9C,CAAmD,eAAO;AAC7DrqC,qBAAIqgC,KAAJ,CAAU,mDAAV;;AAEA,mBAAO,MAAKuM,YAAL,CAAkBjB,QAAlB,CAA2BvK,GAA3B,EAAgCkL,IAAhC,EAAsCjC,IAAtC,CAA2C,oBAAY;AAC1DrqC,yBAAIqgC,KAAJ,CAAU,6CAAV;AACA,uBAAOwP,QAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;0BAEDoL,oB,mCAAgC;AAAA;;AAAA,YAAX3O,IAAW,uEAAJ,EAAI;;AAC5BA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAK0O,UAAL,GAAkB1O,KAAK0O,UAAL,IAAmB,eAArC;AACA1O,aAAKnL,SAAL,GAAiBmL,KAAKnL,SAAL,IAAkB,KAAKwL,SAAL,CAAexL,SAAlD;AACAmL,aAAK8C,aAAL,GAAqB9C,KAAK8C,aAAL,IAAsB,KAAKzC,SAAL,CAAeyC,aAA1D;;AAEA,YAAI,CAAC9C,KAAK4O,aAAV,EAAyB;AACrBl7C,qBAAIojC,KAAJ,CAAU,2DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAKnL,SAAV,EAAqB;AACjBnhC,qBAAIojC,KAAJ,CAAU,uDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsB/B,gBAAtB,CAAuC,KAAvC,EAA8C9C,IAA9C,CAAmD,eAAO;AAC7DrqC,qBAAIqgC,KAAJ,CAAU,2DAAV;;AAEA,mBAAO,OAAKuM,YAAL,CAAkBjB,QAAlB,CAA2BvK,GAA3B,EAAgCkL,IAAhC,EAAsCjC,IAAtC,CAA2C,oBAAY;AAC1DrqC,yBAAIqgC,KAAJ,CAAU,qDAAV;AACA,uBAAOwP,QAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;;;;;;;;;;;;;;;;;;;;;AC1EL;;AACA;;AACA;;0JALA;AACA;;AAMA,IAAMsL,sBAAsB,cAA5B;AACA,IAAMC,uBAAuB,eAA7B;;IAEaz6C,qB,WAAAA,qB;AACT,mCAAY8rC,QAAZ,EAAyG;AAAA,YAAnFhC,kBAAmF,uEAA9D5pC,eAAO0mC,cAAuD;AAAA,YAAvCuK,mBAAuC,uEAAjBvxC,gCAAiB;;AAAA;;AACrG,YAAI,CAACksC,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,kDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,uBAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAK4O,mBAAL,GAA2B5Q,kBAA3B;AACA,aAAKyE,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACH;;oCAED2O,M,mBAAOjS,K,EAAOkS,Q,EAAiC;AAAA;;AAAA,YAAvBzgC,IAAuB,uEAAhB,cAAgB;;AAC3C,YAAI,CAACuuB,KAAL,EAAY;AACRrpC,qBAAIojC,KAAJ,CAAU,iDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,oBAAV,CAAN;AACH;;AAED,YAAIqZ,SAASqgC,mBAAT,IAAgCrgC,QAAQsgC,oBAA5C,EAAkE;AAC9Dp7C,qBAAIojC,KAAJ,CAAU,kDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,qBAAV,CAAN;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsB3B,qBAAtB,GAA8ClD,IAA9C,CAAmD,eAAO;AAC7D,gBAAI,CAACjJ,GAAL,EAAU;AACN,oBAAIma,QAAJ,EAAc;AACVv7C,6BAAIojC,KAAJ,CAAU,wDAAV;AACA,0BAAM,IAAI3hC,KAAJ,CAAU,0BAAV,CAAN;AACH;;AAED;AACA;AACH;;AAEDzB,qBAAIqgC,KAAJ,CAAU,4CAA4CvlB,IAAtD;AACA,gBAAIqmB,YAAY,MAAKwL,SAAL,CAAexL,SAA/B;AACA,gBAAIiO,gBAAgB,MAAKzC,SAAL,CAAeyC,aAAnC;AACA,mBAAO,MAAKoM,OAAL,CAAapa,GAAb,EAAkBD,SAAlB,EAA6BiO,aAA7B,EAA4C/F,KAA5C,EAAmDvuB,IAAnD,CAAP;AACH,SAfM,CAAP;AAgBH,K;;oCAED0gC,O,oBAAQpa,G,EAAKD,S,EAAWiO,a,EAAe/F,K,EAAOvuB,I,EAAM;AAAA;;AAEhD,eAAO,IAAI0nB,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;;AAEpC,gBAAImX,MAAM,IAAI,OAAKJ,mBAAT,EAAV;AACAI,gBAAIjW,IAAJ,CAAS,MAAT,EAAiBpE,GAAjB;;AAEAqa,gBAAI/Y,MAAJ,GAAa,YAAM;AACf1iC,yBAAIqgC,KAAJ,CAAU,8DAAV,EAA0Eob,IAAIxQ,MAA9E;;AAEA,oBAAIwQ,IAAIxQ,MAAJ,KAAe,GAAnB,EAAwB;AACpBxI;AACH,iBAFD,MAGK;AACD6B,2BAAO7iC,MAAMg6C,IAAIjQ,UAAJ,GAAiB,IAAjB,GAAwBiQ,IAAIxQ,MAA5B,GAAqC,GAA3C,CAAP;AACH;AACJ,aATD;AAUAwQ,gBAAIhQ,OAAJ,GAAc,YAAM;AAChBzrC,yBAAIqgC,KAAJ,CAAU,8CAAV;AACAiE,uBAAO,eAAP;AACH,aAHD;;AAKA,gBAAI3B,OAAO,eAAer9B,mBAAmB67B,SAAnB,CAA1B;AACA,gBAAIiO,aAAJ,EAAmB;AACfzM,wBAAQ,oBAAoBr9B,mBAAmB8pC,aAAnB,CAA5B;AACH;AACDzM,oBAAQ,sBAAsBr9B,mBAAmBwV,IAAnB,CAA9B;AACA6nB,oBAAQ,YAAYr9B,mBAAmB+jC,KAAnB,CAApB;;AAEAoS,gBAAI/P,gBAAJ,CAAqB,cAArB,EAAqC,mCAArC;AACA+P,gBAAIhY,IAAJ,CAASd,IAAT;AACH,SA7BM,CAAP;AA8BH,K;;;;;;;;;;;;;;;;;;;;;;AChFL;;AACA;;0JAJA;AACA;;IAKaqR,U,WAAAA,U;;;;;eACF+E,a,0BAAc3X,G,EAAKld,I,EAAMykB,K,EAAO;AACnC,YAAIvH,IAAI15B,OAAJ,CAAY,GAAZ,IAAmB,CAAvB,EAA0B;AACtB05B,mBAAO,GAAP;AACH;;AAED,YAAIA,IAAIA,IAAI/+B,MAAJ,GAAa,CAAjB,MAAwB,GAA5B,EAAiC;AAC7B++B,mBAAO,GAAP;AACH;;AAEDA,eAAO97B,mBAAmB4e,IAAnB,CAAP;AACAkd,eAAO,GAAP;AACAA,eAAO97B,mBAAmBqjC,KAAnB,CAAP;;AAEA,eAAOvH,GAAP;AACH,K;;eAEM6S,gB,6BAAiBtL,K,EAAyC;AAAA,YAAlCiH,SAAkC,uEAAtB,GAAsB;AAAA,YAAjB8L,MAAiB,uEAAR76C,cAAQ;;AAC7D,YAAI,OAAO8nC,KAAP,KAAiB,QAArB,EAA8B;AAC1BA,oBAAQ+S,OAAOtU,QAAP,CAAgBiB,IAAxB;AACH;;AAED,YAAIzG,MAAM+G,MAAMgT,WAAN,CAAkB/L,SAAlB,CAAV;AACA,YAAIhO,OAAO,CAAX,EAAc;AACV+G,oBAAQA,MAAM9jC,MAAN,CAAa+8B,MAAM,CAAnB,CAAR;AACH;;AAED,YAAIgO,cAAc,GAAlB,EAAuB;AACnB;AACAhO,kBAAM+G,MAAMjhC,OAAN,CAAc,GAAd,CAAN;AACA,gBAAIk6B,OAAO,CAAX,EAAc;AACV+G,wBAAQA,MAAM9jC,MAAN,CAAa,CAAb,EAAgB+8B,GAAhB,CAAR;AACH;AACJ;;AAED,YAAImC,SAAS,EAAb;AAAA,YACI6X,QAAQ,mBADZ;AAAA,YAEIr3C,CAFJ;;AAIA,YAAIs3C,UAAU,CAAd;AACA,eAAOt3C,IAAIq3C,MAAME,IAAN,CAAWnT,KAAX,CAAX,EAA8B;AAC1B5E,mBAAO5+B,mBAAmBZ,EAAE,CAAF,CAAnB,CAAP,IAAmCY,mBAAmBZ,EAAE,CAAF,CAAnB,CAAnC;AACA,gBAAIs3C,YAAY,EAAhB,EAAoB;AAChB77C,yBAAIojC,KAAJ,CAAU,8EAAV,EAA0FuF,KAA1F;AACA,uBAAO;AACHvF,2BAAO;AADJ,iBAAP;AAGH;AACJ;;AAED,aAAK,IAAI2Y,IAAT,IAAiBhY,MAAjB,EAAyB;AACrB,mBAAOA,MAAP;AACH;;AAED,eAAO,EAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBC7DL;AACA;;AAEA;;;;IAEajjC,I,WAAAA,I;AACT,wBAAmH;AAAA,YAAtGm0C,QAAsG,QAAtGA,QAAsG;AAAA,YAA5F1R,aAA4F,QAA5FA,aAA4F;AAAA,YAA7ErD,YAA6E,QAA7EA,YAA6E;AAAA,YAA/Dgb,aAA+D,QAA/DA,aAA+D;AAAA,YAAhD/B,UAAgD,QAAhDA,UAAgD;AAAA,YAApClL,KAAoC,QAApCA,KAAoC;AAAA,YAA7BoH,OAA6B,QAA7BA,OAA6B;AAAA,YAApB+D,UAAoB,QAApBA,UAAoB;AAAA,YAAR1pB,KAAQ,QAARA,KAAQ;;AAAA;;AAC/G,aAAKulB,QAAL,GAAgBA,QAAhB;AACA,aAAK1R,aAAL,GAAqBA,aAArB;AACA,aAAKrD,YAAL,GAAoBA,YAApB;AACA,aAAKgb,aAAL,GAAqBA,aAArB;AACA,aAAK/B,UAAL,GAAkBA,UAAlB;AACA,aAAKlL,KAAL,GAAaA,KAAb;AACA,aAAKoH,OAAL,GAAeA,OAAf;AACA,aAAK+D,UAAL,GAAkBA,UAAlB;AACA,aAAK1pB,KAAL,GAAaA,KAAb;AACH;;mBA6BD8f,e,8BAAkB;AACdxvC,iBAAIqgC,KAAJ,CAAU,sBAAV;AACA,eAAOra,KAAKriB,SAAL,CAAe;AAClBsxC,sBAAU,KAAKA,QADG;AAElB1R,2BAAe,KAAKA,aAFF;AAGlBrD,0BAAc,KAAKA,YAHD;AAIlBgb,2BAAe,KAAKA,aAJF;AAKlB/B,wBAAY,KAAKA,UALC;AAMlBlL,mBAAO,KAAKA,KANM;AAOlBoH,qBAAS,KAAKA,OAPI;AAQlB+D,wBAAY,KAAKA;AARC,SAAf,CAAP;AAUH,K;;SAEMjJ,iB,8BAAkBwJ,a,EAAe;AACpC35C,iBAAIqgC,KAAJ,CAAU,wBAAV;AACA,eAAO,IAAIv/B,IAAJ,CAASklB,KAAKrhB,KAAL,CAAWg1C,aAAX,CAAT,CAAP;AACH,K;;;;4BA5CgB;AACb,gBAAI,KAAKP,UAAT,EAAqB;AACjB,oBAAIxP,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,uBAAO,KAAKwP,UAAL,GAAkBxP,GAAzB;AACH;AACD,mBAAOzoC,SAAP;AACH,S;0BACcwnC,K,EAAO;AAClB,gBAAIxI,aAAav7B,SAAS+jC,KAAT,CAAjB;AACA,gBAAI,OAAOxI,UAAP,KAAsB,QAAtB,IAAkCA,aAAa,CAAnD,EAAsD;AAClD,oBAAIyJ,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,qBAAKwP,UAAL,GAAkBxP,MAAMzJ,UAAxB;AACH;AACJ;;;4BAEa;AACV,gBAAIA,aAAa,KAAKA,UAAtB;AACA,gBAAIA,eAAeh/B,SAAnB,EAA8B;AAC1B,uBAAOg/B,cAAc,CAArB;AACH;AACD,mBAAOh/B,SAAP;AACH;;;4BAEY;AACT,mBAAO,CAAC,KAAK8sC,KAAL,IAAc,EAAf,EAAmBttB,KAAnB,CAAyB,GAAzB,CAAP;AACH;;;;;;;;;;;;;;;;;;;;;;;ACxCL;;AACA;;AACA;;AACA;;0JANA;AACA;;IAOa2zB,e,WAAAA,e;AACT,6BACI7H,QADJ,EAKE;AAAA,YAHEC,eAGF,uEAHoBnC,wBAGpB;AAAA,YAFEuH,mBAEF,uEAFwBvxC,gCAExB;AAAA,YADEg0C,QACF,uEADaxL,kBACb;;AAAA;;AACE,YAAI,CAAC0D,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,0CAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,CAAoBvrC,SAApB,EAA+BA,SAA/B,EAA0C,KAAK66C,iBAAL,CAAuBjZ,IAAvB,CAA4B,IAA5B,CAA1C,CAApB;AACA,aAAKmM,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACA,aAAKgI,SAAL,GAAiBJ,QAAjB;AACH;;8BAEDe,S,sBAAUjM,K,EAAO;AAAA;;AACb,YAAI,CAACA,KAAL,EAAY;AACRrpC,qBAAIojC,KAAJ,CAAU,4CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,qBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsBhC,mBAAtB,GAA4C7C,IAA5C,CAAiD,eAAO;AAC3DrqC,qBAAIqgC,KAAJ,CAAU,kDAAV,EAA8De,GAA9D;;AAEA,mBAAO,MAAKwL,YAAL,CAAkB9B,OAAlB,CAA0B1J,GAA1B,EAA+BiI,KAA/B,EAAsCgB,IAAtC,CAA2C,kBAAU;AACxDrqC,yBAAIqgC,KAAJ,CAAU,4CAAV,EAAwDkV,MAAxD;AACA,uBAAOA,MAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;8BAEDyG,iB,8BAAkBjR,G,EAAK;AAAA;;AACnB,YAAI;AACA,gBAAI3B,MAAM,KAAKuL,SAAL,CAAexL,QAAf,CAAwB4B,IAAIQ,YAA5B,CAAV;AACA,gBAAI,CAACnC,GAAD,IAAQ,CAACA,IAAIE,MAAb,IAAuB,CAACF,IAAIG,OAAhC,EAAyC;AACrCvpC,yBAAIojC,KAAJ,CAAU,wDAAV,EAAoEgG,GAApE;AACA,uBAAO5G,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,gBAAIs5B,MAAMqO,IAAIE,MAAJ,CAAWvO,GAArB;;AAEA,gBAAIkhB,sBAAJ;AACA,oBAAQ,KAAKtP,SAAL,CAAegF,iBAAvB;AACI,qBAAK,IAAL;AACIsK,oCAAgB,KAAK/M,gBAAL,CAAsBnC,SAAtB,EAAhB;AACA;AACJ,qBAAK,KAAL;AACIkP,oCAAgBzZ,QAAQC,OAAR,CAAgB2G,IAAIG,OAAJ,CAAY9L,GAA5B,CAAhB;AACA;AACJ;AACIwe,oCAAgBzZ,QAAQC,OAAR,CAAgB,KAAKkK,SAAL,CAAegF,iBAA/B,CAAhB;AACA;AATR;;AAYA,mBAAOsK,cAAc5R,IAAd,CAAmB,kBAAU;AAChCrqC,yBAAIqgC,KAAJ,CAAU,wDAAwDoJ,MAAlE;;AAEA,uBAAO,OAAKyF,gBAAL,CAAsBzB,cAAtB,GAAuCpD,IAAvC,CAA4C,gBAAQ;AACvD,wBAAI,CAACnqB,IAAL,EAAW;AACPlgB,iCAAIojC,KAAJ,CAAU,kEAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,+BAAV,CAAf,CAAP;AACH;;AAEDzB,6BAAIqgC,KAAJ,CAAU,0DAAV;AACA,wBAAIvM,YAAJ;AACA,wBAAI,CAACiH,GAAL,EAAU;AACN7a,+BAAO,OAAKq2B,YAAL,CAAkBr2B,IAAlB,EAAwBkpB,IAAIE,MAAJ,CAAW1c,GAAnC,CAAP;;AAEA,4BAAI1M,KAAK7d,MAAL,GAAc,CAAlB,EAAqB;AACjBrC,qCAAIojC,KAAJ,CAAU,qGAAV;AACA,mCAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kEAAV,CAAf,CAAP;AACH,yBAHD,MAIK;AACD;AACA;AACAqyB,kCAAM5T,KAAK,CAAL,CAAN;AACH;AACJ,qBAZD,MAaK;AACD4T,8BAAM5T,KAAKs2B,MAAL,CAAY,eAAO;AACrB,mCAAO1iB,IAAIiH,GAAJ,KAAYA,GAAnB;AACH,yBAFK,EAEH,CAFG,CAAN;AAGH;;AAED,wBAAI,CAACjH,GAAL,EAAU;AACN9zB,iCAAIojC,KAAJ,CAAU,qFAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED,wBAAIioC,WAAW,OAAKiD,SAAL,CAAexL,SAA9B;;AAEA,wBAAIkV,qBAAqB,OAAK1J,SAAL,CAAehD,SAAxC;AACA3pC,6BAAIqgC,KAAJ,CAAU,sFAAV,EAAkGgW,kBAAlG;;AAEA,2BAAO,OAAK1B,SAAL,CAAenL,WAAf,CAA2BuB,IAAIQ,YAA/B,EAA6CzX,GAA7C,EAAkD2V,MAAlD,EAA0DC,QAA1D,EAAoE2M,kBAApE,EAAwFl1C,SAAxF,EAAmG,IAAnG,EAAyGkpC,IAAzG,CAA8G,YAAM;AACvHrqC,iCAAIqgC,KAAJ,CAAU,8DAAV;AACA,+BAAO+I,IAAIG,OAAX;AACH,qBAHM,CAAP;AAIH,iBAzCM,CAAP;AA0CH,aA7CM,CAAP;AA8CA;AACH,SArED,CAsEA,OAAOvnC,CAAP,EAAU;AACNhC,qBAAIojC,KAAJ,CAAU,+DAAV,EAA2EphC,EAAEgkC,OAA7E;AACA1B,mBAAOtiC,CAAP;AACA;AACH;AACJ,K;;8BAEDu0C,Y,yBAAar2B,I,EAAM0M,G,EAAK;AACpB,YAAIyJ,MAAM,IAAV;AACA,YAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AACtBjV,kBAAM,KAAN;AACH,SAFD,MAGK,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA;AACDr2B,qBAAIqgC,KAAJ,CAAU,mDAAV,EAA+DzT,GAA/D;AACA,mBAAO,EAAP;AACH;;AAED5sB,iBAAIqgC,KAAJ,CAAU,iEAAV,EAA6EhK,GAA7E;;AAEAnW,eAAOA,KAAKs2B,MAAL,CAAY,eAAO;AACtB,mBAAO1iB,IAAIuC,GAAJ,KAAYA,GAAnB;AACH,SAFM,CAAP;;AAIAr2B,iBAAIqgC,KAAJ,CAAU,+DAAV,EAA2EhK,GAA3E,EAAgFnW,KAAK7d,MAArF;;AAEA,eAAO6d,IAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;;;AC9IL;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;;;+eAZA;AACA;;IAca7f,W,WAAAA,W;;;AACT,2BAME;AAAA,YANUosC,QAMV,uEANqB,EAMrB;AAAA,YALEyP,sBAKF,uEAL2BtC,sCAK3B;AAAA,YAJEuC,kBAIF,uEAJuBv7C,8BAIvB;AAAA,YAHEw7C,yBAGF,uEAH8Bz7C,4CAG9B;AAAA,YAFE6zC,eAEF,uEAFoBC,wBAEpB;AAAA,YADEF,QACF,uEADaxL,kBACb;;AAAA;;AAEE,YAAI,EAAE0D,oBAAoB4P,wCAAtB,CAAJ,EAAgD;AAC5C5P,uBAAW,IAAI4P,wCAAJ,CAAwB5P,QAAxB,CAAX;AACH;;AAJH,qDAKE,uBAAMA,QAAN,CALF;;AAOE,cAAK6P,OAAL,GAAe,IAAIC,oCAAJ,CAAsB9P,QAAtB,CAAf;AACA,cAAK+P,mBAAL,GAA2B,IAAIN,sBAAJ,OAA3B;;AAEA;AACA,YAAI,MAAKzP,QAAL,CAAcgQ,oBAAlB,EAAwC;AACpCz8C,qBAAIqgC,KAAJ,CAAU,+EAAV;AACA,kBAAKqc,gBAAL;AACH;;AAED,YAAI,MAAKjQ,QAAL,CAAckQ,cAAlB,EAAkC;AAC9B38C,qBAAIqgC,KAAJ,CAAU,4EAAV;AACA,kBAAKuc,eAAL,GAAuB,IAAIT,kBAAJ,OAAvB;AACH;;AAED,cAAKU,sBAAL,GAA8B,IAAIT,yBAAJ,CAA8B,MAAKzP,SAAnC,CAA9B;AACA,cAAKiI,YAAL,GAAoB,IAAIJ,eAAJ,CAAoB,MAAK7H,SAAzB,CAApB;AACA,cAAKgI,SAAL,GAAiBJ,QAAjB;AAvBF;AAwBD;;0BAmBDiD,O,sBAAU;AAAA;;AACN,eAAO,KAAKsF,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,gBAAIoN,IAAJ,EAAU;AACNz3C,yBAAI6rC,IAAJ,CAAS,kCAAT;;AAEA,uBAAKyQ,OAAL,CAAatc,IAAb,CAAkByX,IAAlB,EAAwB,KAAxB;;AAEA,uBAAOA,IAAP;AACH,aAND,MAOK;AACDz3C,yBAAI6rC,IAAJ,CAAS,gDAAT;AACA,uBAAO,IAAP;AACH;AACJ,SAZM,CAAP;AAaH,K;;0BAEDkR,U,yBAAa;AAAA;;AACT,eAAO,KAAKC,SAAL,CAAe,IAAf,EAAqB3S,IAArB,CAA0B,YAAM;AACnCrqC,qBAAI6rC,IAAJ,CAAS,mDAAT;AACA,mBAAKyQ,OAAL,CAAa7b,MAAb;AACH,SAHM,CAAP;AAIH,K;;0BAEDwc,c,6BAA0B;AAAA,YAAX3Q,IAAW,uEAAJ,EAAI;;AACtBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIqO,YAAY;AACZ/I,kCAAuB7H,KAAK6H;AADhB,SAAhB;AAGA,eAAO,KAAKgJ,YAAL,CAAkB7Q,IAAlB,EAAwB,KAAK8Q,kBAA7B,EAAiDF,SAAjD,EAA4D7S,IAA5D,CAAiE,YAAI;AACxErqC,qBAAI6rC,IAAJ,CAAS,wCAAT;AACH,SAFM,CAAP;AAGH,K;;0BACDwR,sB,mCAAuBjc,G,EAAK;AACxB,eAAO,KAAKkc,UAAL,CAAgBlc,OAAO,KAAKgc,kBAAL,CAAwBhc,GAA/C,EAAoDiJ,IAApD,CAAyD,gBAAQ;AACpE,gBAAIoN,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,yBAAI6rC,IAAJ,CAAS,iEAAT,EAA4E4L,KAAKpC,OAAL,CAAa3X,GAAzF;AACH,aAFD,MAGK;AACD19B,yBAAI6rC,IAAJ,CAAS,4CAAT;AACH;;AAED,mBAAO4L,IAAP;AACH,SATM,CAAP;AAUH,K;;0BAED8F,W,0BAAuB;AAAA,YAAXjR,IAAW,uEAAJ,EAAI;;AACnBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIzN,MAAMkL,KAAK1H,YAAL,IAAqB,KAAK6H,QAAL,CAAc+Q,kBAAnC,IAAyD,KAAK/Q,QAAL,CAAc7H,YAAjF;AACA,YAAI,CAACxD,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,2EAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED6qC,aAAK1H,YAAL,GAAoBxD,GAApB;AACAkL,aAAKlK,OAAL,GAAe,OAAf;;AAEA,eAAO,KAAKqb,OAAL,CAAanR,IAAb,EAAmB,KAAKoR,eAAxB,EAAyC;AAC5C7Y,sBAAUzD,GADkC;AAE5C4C,iCAAqBsI,KAAKtI,mBAAL,IAA4B,KAAKyI,QAAL,CAAczI,mBAFnB;AAG5CW,+BAAmB2H,KAAK3H,iBAAL,IAA0B,KAAK8H,QAAL,CAAc9H;AAHf,SAAzC,EAIJ0F,IAJI,CAIC,gBAAQ;AACZ,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,kEAAT,EAA6E4L,KAAKpC,OAAL,CAAa3X,GAA1F;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,iCAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAfM,CAAP;AAgBH,K;;0BACDkG,mB,gCAAoBvc,G,EAAK;AACrB,eAAO,KAAKwc,eAAL,CAAqBxc,GAArB,EAA0B,KAAKsc,eAA/B,EAAgDrT,IAAhD,CAAqD,gBAAQ;AAChE,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,8DAAT,EAAyE4L,KAAKpC,OAAL,CAAa3X,GAAtF;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,yCAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAXM,EAWJM,KAXI,CAWE,eAAK;AACV/3C,qBAAIojC,KAAJ,CAAU,SAAmD4U,IAAIhS,OAAjE;AACH,SAbM,CAAP;AAcH,K;;0BAED8T,Y,2BAAwB;AAAA;;AAAA,YAAXxN,IAAW,uEAAJ,EAAI;;AACpBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA;AACA,eAAO,KAAKiO,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,gBAAIoN,QAAQA,KAAKyD,aAAjB,EAAgC;AAC5B5O,qBAAK4O,aAAL,GAAqBzD,KAAKyD,aAA1B;AACA,uBAAO,OAAK2C,gBAAL,CAAsBvR,IAAtB,CAAP;AACH,aAHD,MAIK;AACDA,qBAAK+B,aAAL,GAAqB/B,KAAK+B,aAAL,IAAuB,OAAK5B,QAAL,CAAcqR,2BAAd,IAA6CrG,IAA7C,IAAqDA,KAAKxC,QAAtG;AACA,oBAAIwC,QAAQ,OAAK9K,SAAL,CAAeoR,wBAA3B,EAAqD;AACjD/9C,6BAAIqgC,KAAJ,CAAU,2DAAV,EAAuEoX,KAAKpC,OAAL,CAAa3X,GAApF;AACA4O,yBAAK0R,WAAL,GAAmBvG,KAAKpC,OAAL,CAAa3X,GAAhC;AACH;AACD,uBAAO,OAAKugB,mBAAL,CAAyB3R,IAAzB,CAAP;AACH;AACJ,SAbM,CAAP;AAcH,K;;0BAEDuR,gB,+BAA4B;AAAA;;AAAA,YAAXvR,IAAW,uEAAJ,EAAI;;AACxB,eAAO,KAAKsI,YAAL,CAAkBqG,oBAAlB,CAAuC3O,IAAvC,EAA6CjC,IAA7C,CAAkD,kBAAU;AAC/D,gBAAI,CAACsL,MAAL,EAAa;AACT31C,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,0CAAf,CAAP;AACH;AACD,gBAAI,CAACqR,OAAOzV,YAAZ,EAA0B;AACtBlgC,yBAAIojC,KAAJ,CAAU,4EAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,8CAAf,CAAP;AACH;;AAED,mBAAO,OAAKwY,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,oBAAIoN,IAAJ,EAAU;AACN,wBAAIyG,oBAAoB1b,QAAQC,OAAR,EAAxB;AACA,wBAAIkT,OAAOV,QAAX,EAAqB;AACjBiJ,4CAAoB,OAAKC,qCAAL,CAA2C1G,KAAKpC,OAAhD,EAAyDM,OAAOV,QAAhE,CAApB;AACH;;AAED,2BAAOiJ,kBAAkB7T,IAAlB,CAAuB,YAAM;AAChCrqC,iCAAIqgC,KAAJ,CAAU,8DAAV;AACAoX,6BAAKxC,QAAL,GAAgBU,OAAOV,QAAvB;AACAwC,6BAAKvX,YAAL,GAAoByV,OAAOzV,YAA3B;AACAuX,6BAAKyD,aAAL,GAAqBvF,OAAOuF,aAAP,IAAwBzD,KAAKyD,aAAlD;AACAzD,6BAAKtX,UAAL,GAAkBwV,OAAOxV,UAAzB;;AAEA,+BAAO,OAAK6c,SAAL,CAAevF,IAAf,EAAqBpN,IAArB,CAA0B,YAAI;AACjC,mCAAKiS,OAAL,CAAatc,IAAb,CAAkByX,IAAlB;AACA,mCAAOA,IAAP;AACH,yBAHM,CAAP;AAIH,qBAXM,CAAP;AAYH,iBAlBD,MAmBK;AACD,2BAAO,IAAP;AACH;AACJ,aAvBM,CAAP;AAwBH,SAlCM,CAAP;AAmCH,K;;0BAED0G,qC,kDAAsC9I,O,EAASJ,Q,EAAU;AAAA;;AACrD,eAAO,KAAK/F,gBAAL,CAAsBnC,SAAtB,GAAkC1C,IAAlC,CAAuC,kBAAU;AACpD,mBAAO,OAAKsK,SAAL,CAAe3K,qBAAf,CAAqCiL,QAArC,EAA+CxL,MAA/C,EAAuD,OAAKkD,SAAL,CAAexL,SAAtE,EAAiF,OAAKwL,SAAL,CAAehD,SAAhG,EAA2GU,IAA3G,CAAgH,mBAAW;AAC9H,oBAAI,CAACd,OAAL,EAAc;AACVvpC,6BAAIojC,KAAJ,CAAU,gFAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQ7L,GAAR,KAAgB2X,QAAQ3X,GAA5B,EAAiC;AAC7B19B,6BAAIojC,KAAJ,CAAU,+FAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4CAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQ6U,SAAR,IAAqB7U,QAAQ6U,SAAR,KAAsB/I,QAAQ+I,SAAvD,EAAkE;AAC9Dp+C,6BAAIojC,KAAJ,CAAU,4GAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yDAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQW,GAAR,IAAeX,QAAQW,GAAR,KAAgBmL,QAAQnL,GAA3C,EAAgD;AAC5ClqC,6BAAIojC,KAAJ,CAAU,gGAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6CAAV,CAAf,CAAP;AACH;AACD,oBAAI,CAAC8nC,QAAQW,GAAT,IAAgBmL,QAAQnL,GAA5B,EAAiC;AAC7BlqC,6BAAIojC,KAAJ,CAAU,0GAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,uDAAV,CAAf,CAAP;AACH;AACJ,aArBM,CAAP;AAsBH,SAvBM,CAAP;AAwBH,K;;0BAEDw8C,mB,kCAA+B;AAAA,YAAX3R,IAAW,uEAAJ,EAAI;;AAC3B,YAAIlL,MAAMkL,KAAK1H,YAAL,IAAqB,KAAK6H,QAAL,CAAc4R,mBAAnC,IAA0D,KAAK5R,QAAL,CAAc7H,YAAlF;AACA,YAAI,CAACxD,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,6DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,mCAAV,CAAf,CAAP;AACH;;AAED6qC,aAAK1H,YAAL,GAAoBxD,GAApB;AACAkL,aAAK4B,MAAL,GAAc5B,KAAK4B,MAAL,IAAe,MAA7B;;AAEA,eAAO,KAAKuP,OAAL,CAAanR,IAAb,EAAmB,KAAKgS,gBAAxB,EAA0C;AAC7CzZ,sBAAUzD,GADmC;AAE7C0G,kCAAsBwE,KAAKxE,oBAAL,IAA6B,KAAK2E,QAAL,CAAc3E;AAFpB,SAA1C,EAGJuC,IAHI,CAGC,gBAAQ;AACZ,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,uDAAT,EAAkE4L,KAAKpC,OAAL,CAAa3X,GAA/E;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,kCAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAdM,CAAP;AAeH,K;;0BAED8G,oB,iCAAqBnd,G,EAAK;AACtB,eAAO,KAAKwc,eAAL,CAAqBxc,GAArB,EAA0B,KAAKkd,gBAA/B,EAAiDjU,IAAjD,CAAsD,gBAAQ;AACjE,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,+DAAT,EAA0E4L,KAAKpC,OAAL,CAAa3X,GAAvF;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,0CAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAXM,CAAP;AAYH,K;;0BAED+G,c,2BAAepd,G,EAAK;AAAA;;AAChB,eAAO,KAAKqO,uBAAL,CAA6BrO,GAA7B,EAAkCiJ,IAAlC,CAAuC,gBAAuB;AAAA,gBAArB3a,KAAqB,QAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,QAAdA,QAAc;;AACjE,gBAAIngB,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAKwO,sBAAL,CAA4Bjc,GAA5B,CAAP;AACH;AACD,gBAAI1R,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAK8O,mBAAL,CAAyBvc,GAAzB,CAAP;AACH;AACD,gBAAI1R,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAK0P,oBAAL,CAA0Bnd,GAA1B,CAAP;AACH;AACD,mBAAOoB,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gCAAV,CAAf,CAAP;AACH,SAXM,CAAP;AAYH,K;;0BAEDg9C,e,4BAAgBrd,G,EAAKmS,Q,EAAU;AAAA;;AAC3B,eAAO,KAAK5C,wBAAL,CAA8BvP,GAA9B,EAAmCiJ,IAAnC,CAAwC,iBAAuB;AAAA,gBAArB3a,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,SAAdA,QAAc;;AAClE,gBAAIngB,KAAJ,EAAW;AACP,oBAAIA,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,2BAAO,OAAK6P,uBAAL,CAA6Btd,GAA7B,CAAP;AACH;AACD,oBAAI1R,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,2BAAO,OAAK8P,oBAAL,CAA0Bvd,GAA1B,EAA+BmS,QAA/B,CAAP;AACH;AACD,uBAAO/Q,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gCAAV,CAAf,CAAP;AACH;AACD,mBAAOouC,QAAP;AACH,SAXM,CAAP;AAYH,K;;0BAED8H,kB,iCAA8B;AAAA;;AAAA,YAAXrL,IAAW,uEAAJ,EAAI;;AAC1BA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB,CAH0B,CAGE;AAC5B,YAAIzN,MAAMkL,KAAK1H,YAAL,IAAqB,KAAK6H,QAAL,CAAc4R,mBAAnC,IAA0D,KAAK5R,QAAL,CAAc7H,YAAlF;AACA,YAAI,CAACxD,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,mEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,mCAAV,CAAf,CAAP;AACH;;AAED6qC,aAAK1H,YAAL,GAAoBxD,GAApB;AACAkL,aAAK4B,MAAL,GAAc,MAAd;AACA5B,aAAK0B,aAAL,GAAqB1B,KAAK0B,aAAL,IAAsB,KAAKvB,QAAL,CAAcmS,0BAAzD;AACAtS,aAAK2B,KAAL,GAAa3B,KAAK2B,KAAL,IAAc,QAA3B;AACA3B,aAAKwC,YAAL,GAAoB,IAApB;;AAEA,eAAO,KAAKqO,YAAL,CAAkB7Q,IAAlB,EAAwB,KAAKgS,gBAA7B,EAA+C;AAClDzZ,sBAAUzD,GADwC;AAElD0G,kCAAsBwE,KAAKxE,oBAAL,IAA6B,KAAK2E,QAAL,CAAc3E;AAFf,SAA/C,EAGJuC,IAHI,CAGC,uBAAe;AACnB,mBAAO,OAAK+F,qBAAL,CAA2ByO,YAAYzd,GAAvC,EAA4CiJ,IAA5C,CAAiD,0BAAkB;AACtErqC,yBAAIqgC,KAAJ,CAAU,qDAAV;;AAEA,oBAAIye,eAAevb,aAAf,IAAgCub,eAAezJ,OAAf,CAAuB3X,GAA3D,EAAgE;AAC5D19B,6BAAI6rC,IAAJ,CAAS,sEAAT,EAAkFiT,eAAezJ,OAAf,CAAuB3X,GAAzG;AACA,2BAAO;AACH6F,uCAAeub,eAAevb,aAD3B;AAEH7F,6BAAKohB,eAAezJ,OAAf,CAAuB3X,GAFzB;AAGHoa,6BAAKgH,eAAezJ,OAAf,CAAuByC;AAHzB,qBAAP;AAKH,iBAPD,MAQK;AACD93C,6BAAI6rC,IAAJ,CAAS,uDAAT;AACH;AACJ,aAdM,EAeNkM,KAfM,CAeA,eAAO;AACV,oBAAIC,IAAIzU,aAAJ,IAAqB,OAAKkJ,QAAL,CAAciL,uBAAvC,EAAgE;AAC5D,wBAAIM,IAAIhS,OAAJ,IAAe,gBAAf,IACAgS,IAAIhS,OAAJ,IAAe,kBADf,IAEAgS,IAAIhS,OAAJ,IAAe,sBAFf,IAGAgS,IAAIhS,OAAJ,IAAe,4BAHnB,EAIE;AACEhmC,iCAAI6rC,IAAJ,CAAS,+EAAT;AACA,+BAAO;AACHtI,2CAAeyU,IAAIzU;AADhB,yBAAP;AAGH;AACJ;;AAED,sBAAMyU,GAAN;AACH,aA9BM,CAAP;AA+BH,SAnCM,CAAP;AAoCH,K;;0BAEDyF,O,oBAAQnR,I,EAAMvrC,S,EAAiC;AAAA;;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;AAC3C,eAAO,KAAK5B,YAAL,CAAkB7Q,IAAlB,EAAwBvrC,SAAxB,EAAmCg+C,eAAnC,EAAoD1U,IAApD,CAAyD,uBAAe;AAC3E,mBAAO,QAAKiT,UAAL,CAAgBuB,YAAYzd,GAA5B,EAAiCkL,IAAjC,CAAP;AACH,SAFM,CAAP;AAGH,K;;0BACD6Q,Y,yBAAa7Q,I,EAAMvrC,S,EAAiC;AAAA;;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;;AAEhD,eAAOh+C,UAAU+iC,OAAV,CAAkBib,eAAlB,EAAmC1U,IAAnC,CAAwC,kBAAU;AACrDrqC,qBAAIqgC,KAAJ,CAAU,uDAAV;;AAEA,mBAAO,QAAK0N,mBAAL,CAAyBzB,IAAzB,EAA+BjC,IAA/B,CAAoC,yBAAiB;AACxDrqC,yBAAIqgC,KAAJ,CAAU,8CAAV;;AAEA0e,gCAAgB3d,GAAhB,GAAsB+N,cAAc/N,GAApC;AACA2d,gCAAgBvjB,EAAhB,GAAqB2T,cAAczf,KAAd,CAAoB8L,EAAzC;;AAEA,uBAAOsL,OAAO7B,QAAP,CAAgB8Z,eAAhB,CAAP;AACH,aAPM,EAOJhH,KAPI,CAOE,eAAO;AACZ,oBAAIjR,OAAOZ,KAAX,EAAkB;AACdlmC,6BAAIqgC,KAAJ,CAAU,qFAAV;AACAyG,2BAAOZ,KAAP;AACH;AACD,sBAAM8R,GAAN;AACH,aAbM,CAAP;AAcH,SAjBM,CAAP;AAkBH,K;;0BACDsF,U,uBAAWlc,G,EAAgB;AAAA;;AAAA,YAAXkL,IAAW,uEAAJ,EAAI;;AACvB,eAAO,KAAK8D,qBAAL,CAA2BhP,GAA3B,EAAgCiJ,IAAhC,CAAqC,0BAAkB;AAC1DrqC,qBAAIqgC,KAAJ,CAAU,6CAAV;;AAEA,gBAAIoX,OAAO,IAAI32C,UAAJ,CAASg+C,cAAT,CAAX;;AAEA,gBAAIxS,KAAK0R,WAAT,EAAsB;AAClB,oBAAI1R,KAAK0R,WAAL,KAAqBvG,KAAKpC,OAAL,CAAa3X,GAAtC,EAA2C;AACvC19B,6BAAIqgC,KAAJ,CAAU,kGAAV,EAA8GoX,KAAKpC,OAAL,CAAa3X,GAA3H;AACA,2BAAO8E,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gBAAV,CAAf,CAAP;AACH,iBAHD,MAIK;AACDzB,6BAAIqgC,KAAJ,CAAU,wEAAV;AACH;AACJ;;AAED,mBAAO,QAAK2c,SAAL,CAAevF,IAAf,EAAqBpN,IAArB,CAA0B,YAAM;AACnCrqC,yBAAIqgC,KAAJ,CAAU,qCAAV;;AAEA,wBAAKic,OAAL,CAAatc,IAAb,CAAkByX,IAAlB;;AAEA,uBAAOA,IAAP;AACH,aANM,CAAP;AAOH,SAtBM,CAAP;AAuBH,K;;0BACDmG,e,4BAAgBxc,G,EAAKrgC,S,EAAW;AAC5Bf,iBAAIqgC,KAAJ,CAAU,6BAAV;AACA,eAAOt/B,UAAUmgC,QAAV,CAAmBE,GAAnB,CAAP;AACH,K;;0BAED4d,e,8BAA2B;AAAA,YAAX1S,IAAW,uEAAJ,EAAI;;AACvBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIoQ,wBAAwB3S,KAAKkE,wBAAL,IAAiC,KAAK/D,QAAL,CAAc+D,wBAA3E;AACA,YAAIyO,qBAAJ,EAA0B;AACtB3S,iBAAKkE,wBAAL,GAAgCyO,qBAAhC;AACH;AACD,YAAI/B,YAAY;AACZ/I,kCAAuB7H,KAAK6H;AADhB,SAAhB;AAGA,eAAO,KAAK+K,aAAL,CAAmB5S,IAAnB,EAAyB,KAAK8Q,kBAA9B,EAAkDF,SAAlD,EAA6D7S,IAA7D,CAAkE,YAAI;AACzErqC,qBAAI6rC,IAAJ,CAAS,yCAAT;AACH,SAFM,CAAP;AAGH,K;;0BACD6S,uB,oCAAwBtd,G,EAAK;AACzB,eAAO,KAAK+d,WAAL,CAAiB/d,OAAO,KAAKgc,kBAAL,CAAwBhc,GAAhD,EAAqDiJ,IAArD,CAA0D,oBAAU;AACvErqC,qBAAI6rC,IAAJ,CAAS,iDAAT;AACA,mBAAOgE,QAAP;AACH,SAHM,CAAP;AAIH,K;;0BAEDuP,Y,2BAAwB;AAAA,YAAX9S,IAAW,uEAAJ,EAAI;;AACpBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIzN,MAAMkL,KAAKkE,wBAAL,IAAiC,KAAK/D,QAAL,CAAc4S,8BAA/C,IAAiF,KAAK5S,QAAL,CAAc+D,wBAAzG;AACAlE,aAAKkE,wBAAL,GAAgCpP,GAAhC;AACAkL,aAAKlK,OAAL,GAAe,OAAf;AACA,YAAIkK,KAAKkE,wBAAT,EAAkC;AAC9B;AACA;AACA;AACA;AACA;AACAlE,iBAAK5c,KAAL,GAAa4c,KAAK5c,KAAL,IAAc,EAA3B;AACH;;AAED,eAAO,KAAK4vB,QAAL,CAAchT,IAAd,EAAoB,KAAKoR,eAAzB,EAA0C;AAC7C7Y,sBAAUzD,GADmC;AAE7C4C,iCAAqBsI,KAAKtI,mBAAL,IAA4B,KAAKyI,QAAL,CAAczI,mBAFlB;AAG7CW,+BAAmB2H,KAAK3H,iBAAL,IAA0B,KAAK8H,QAAL,CAAc9H;AAHd,SAA1C,EAIJ0F,IAJI,CAIC,YAAM;AACVrqC,qBAAI6rC,IAAJ,CAAS,sCAAT;AACH,SANM,CAAP;AAOH,K;;0BACD8S,oB,iCAAqBvd,G,EAAKmS,Q,EAAU;AAChC,YAAI,OAAOA,QAAP,KAAqB,WAArB,IAAoC,OAAOnS,GAAP,KAAgB,SAAxD,EAAmE;AAC/DmS,uBAAWnS,GAAX;AACAA,kBAAM,IAAN;AACH;;AAED,YAAIwO,YAAY,GAAhB;AACA,eAAO,KAAK8N,eAAL,CAAqBxc,QAArB,CAA8BE,GAA9B,EAAmCmS,QAAnC,EAA6C3D,SAA7C,EAAwDvF,IAAxD,CAA6D,YAAM;AACtErqC,qBAAI6rC,IAAJ,CAAS,8CAAT;AACH,SAFM,CAAP;AAGH,K;;0BAEDyT,Q,qBAAShT,I,EAAMvrC,S,EAAiC;AAAA;;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;AAC5C,eAAO,KAAKG,aAAL,CAAmB5S,IAAnB,EAAyBvrC,SAAzB,EAAoCg+C,eAApC,EAAqD1U,IAArD,CAA0D,uBAAe;AAC5E,mBAAO,QAAK8U,WAAL,CAAiBN,YAAYzd,GAA7B,CAAP;AACH,SAFM,CAAP;AAGH,K;;0BACD8d,a,4BAA0D;AAAA,YAA5C5S,IAA4C,uEAArC,EAAqC;;AAAA;;AAAA,YAAjCvrC,SAAiC;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;AACtD,eAAOh+C,UAAU+iC,OAAV,CAAkBib,eAAlB,EAAmC1U,IAAnC,CAAwC,kBAAU;AACrDrqC,qBAAIqgC,KAAJ,CAAU,wDAAV;;AAEA,mBAAO,QAAKyc,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjCrqC,yBAAIqgC,KAAJ,CAAU,6DAAV;;AAEA,oBAAIkf,gBAAgB,QAAK5S,SAAL,CAAe6S,0BAAf,GAA4C,QAAKC,eAAL,CAAqBhI,IAArB,CAA5C,GAAyEjV,QAAQC,OAAR,EAA7F;AACA,uBAAO8c,cAAclV,IAAd,CAAmB,YAAM;;AAE5B,wBAAI4K,WAAW3I,KAAK+B,aAAL,IAAsBoJ,QAAQA,KAAKxC,QAAlD;AACA,wBAAIA,QAAJ,EAAc;AACVj1C,iCAAIqgC,KAAJ,CAAU,kEAAV;AACAiM,6BAAK+B,aAAL,GAAqB4G,QAArB;AACH;;AAED,2BAAO,QAAK8H,UAAL,GAAkB1S,IAAlB,CAAuB,YAAM;AAChCrqC,iCAAIqgC,KAAJ,CAAU,mEAAV;;AAEA,+BAAO,QAAKkQ,oBAAL,CAA0BjE,IAA1B,EAAgCjC,IAAhC,CAAqC,0BAAkB;AAC1DrqC,qCAAIqgC,KAAJ,CAAU,gDAAV;;AAEA0e,4CAAgB3d,GAAhB,GAAsBse,eAAete,GAArC;AACA,gCAAIse,eAAehwB,KAAnB,EAA0B;AACtBqvB,gDAAgBvjB,EAAhB,GAAqBkkB,eAAehwB,KAAf,CAAqB8L,EAA1C;AACH;AACD,mCAAOsL,OAAO7B,QAAP,CAAgB8Z,eAAhB,CAAP;AACH,yBARM,CAAP;AASH,qBAZM,CAAP;AAaH,iBArBM,CAAP;AAsBH,aA1BM,EA0BJhH,KA1BI,CA0BE,eAAO;AACZ,oBAAIjR,OAAOZ,KAAX,EAAkB;AACdlmC,6BAAIqgC,KAAJ,CAAU,sFAAV;AACAyG,2BAAOZ,KAAP;AACH;AACD,sBAAM8R,GAAN;AACH,aAhCM,CAAP;AAiCH,SApCM,CAAP;AAqCH,K;;0BACDmH,W,wBAAY/d,G,EAAK;AACb,eAAO,KAAK2P,sBAAL,CAA4B3P,GAA5B,EAAiCiJ,IAAjC,CAAsC,2BAAmB;AAC5DrqC,qBAAIqgC,KAAJ,CAAU,+CAAV;;AAEA,mBAAOsf,eAAP;AACH,SAJM,CAAP;AAKH,K;;0BAEDC,iB,gCAAoB;AAAA;;AAChB,eAAO,KAAK9C,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,mBAAO,QAAKoV,eAAL,CAAqBhI,IAArB,EAA2B,IAA3B,EAAiCpN,IAAjC,CAAsC,mBAAW;AACpD,oBAAIwV,OAAJ,EAAa;AACT7/C,6BAAIqgC,KAAJ,CAAU,mFAAV;;AAEAoX,yBAAKvX,YAAL,GAAoB,IAApB;AACAuX,yBAAKyD,aAAL,GAAqB,IAArB;AACAzD,yBAAK2B,UAAL,GAAkB,IAAlB;AACA3B,yBAAK0B,UAAL,GAAkB,IAAlB;;AAEA,2BAAO,QAAK6D,SAAL,CAAevF,IAAf,EAAqBpN,IAArB,CAA0B,YAAM;AACnCrqC,iCAAIqgC,KAAJ,CAAU,4CAAV;AACA,gCAAKic,OAAL,CAAatc,IAAb,CAAkByX,IAAlB;AACH,qBAHM,CAAP;AAIH;AACJ,aAdM,CAAP;AAeH,SAhBM,EAgBJpN,IAhBI,CAgBC,YAAI;AACRrqC,qBAAI6rC,IAAJ,CAAS,kEAAT;AACH,SAlBM,CAAP;AAmBH,K;;0BAED4T,e,4BAAgBhI,I,EAAM8D,Q,EAAU;AAAA;;AAC5B,YAAI9D,IAAJ,EAAU;AACN,gBAAIvX,eAAeuX,KAAKvX,YAAxB;AACA,gBAAIgb,gBAAgBzD,KAAKyD,aAAzB;;AAEA,mBAAO,KAAK4E,0BAAL,CAAgC5f,YAAhC,EAA8Cqb,QAA9C,EACFlR,IADE,CACG,qBAAa;AACf,uBAAO,QAAK0V,2BAAL,CAAiC7E,aAAjC,EAAgDK,QAAhD,EACFlR,IADE,CACG,qBAAa;AACf,wBAAI,CAAC2V,SAAD,IAAc,CAACC,SAAnB,EAA8B;AAC1BjgD,iCAAIqgC,KAAJ,CAAU,oFAAV;AACH;;AAED,2BAAO2f,aAAaC,SAApB;AACH,iBAPE,CAAP;AAQH,aAVE,CAAP;AAWH;;AAED,eAAOzd,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH,K;;0BAEDqd,0B,uCAA2B5f,Y,EAAcqb,Q,EAAU;AAC/C;AACA,YAAI,CAACrb,YAAD,IAAiBA,aAAax4B,OAAb,CAAqB,GAArB,KAA6B,CAAlD,EAAqD;AACjD,mBAAO86B,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH;;AAED,eAAO,KAAKoa,sBAAL,CAA4BvB,MAA5B,CAAmCpb,YAAnC,EAAiDqb,QAAjD,EAA2DlR,IAA3D,CAAgE;AAAA,mBAAM,IAAN;AAAA,SAAhE,CAAP;AACH,K;;0BAED0V,2B,wCAA4B7E,a,EAAeK,Q,EAAU;AACjD,YAAI,CAACL,aAAL,EAAoB;AAChB,mBAAO1Y,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH;;AAED,eAAO,KAAKoa,sBAAL,CAA4BvB,MAA5B,CAAmCJ,aAAnC,EAAkDK,QAAlD,EAA4D,eAA5D,EAA6ElR,IAA7E,CAAkF;AAAA,mBAAM,IAAN;AAAA,SAAlF,CAAP;AACH,K;;0BAEDqS,gB,+BAAmB;AACf,aAAKF,mBAAL,CAAyBlZ,KAAzB;AACH,K;;0BAED4c,e,8BAAkB;AACd,aAAK1D,mBAAL,CAAyBnZ,IAAzB;AACH,K;;0BAMDyZ,S,wBAAY;AACR,eAAO,KAAKqD,UAAL,CAAgBlhB,GAAhB,CAAoB,KAAKmhB,aAAzB,EAAwC/V,IAAxC,CAA6C,yBAAiB;AACjE,gBAAIsP,aAAJ,EAAmB;AACf35C,yBAAIqgC,KAAJ,CAAU,kDAAV;AACA,uBAAOv/B,WAAKqvC,iBAAL,CAAuBwJ,aAAvB,CAAP;AACH;;AAED35C,qBAAIqgC,KAAJ,CAAU,8CAAV;AACA,mBAAO,IAAP;AACH,SARM,CAAP;AASH,K;;0BAED2c,S,sBAAUvF,I,EAAM;AACZ,YAAIA,IAAJ,EAAU;AACNz3C,qBAAIqgC,KAAJ,CAAU,qCAAV;;AAEA,gBAAIsZ,gBAAgBlC,KAAKjI,eAAL,EAApB;AACA,mBAAO,KAAK2Q,UAAL,CAAgB5Q,GAAhB,CAAoB,KAAK6Q,aAAzB,EAAwCzG,aAAxC,CAAP;AACH,SALD,MAMK;AACD35C,qBAAIqgC,KAAJ,CAAU,oCAAV;AACA,mBAAO,KAAK8f,UAAL,CAAgBnQ,MAAhB,CAAuB,KAAKoQ,aAA5B,CAAP;AACH;AACJ,K;;;;4BAxkBwB;AACrB,mBAAO,KAAK3T,QAAL,CAAc4T,iBAArB;AACH;;;4BACqB;AAClB,mBAAO,KAAK5T,QAAL,CAAc6T,cAArB;AACH;;;4BACsB;AACnB,mBAAO,KAAK7T,QAAL,CAAc8T,eAArB;AACH;;;4BACgB;AACb,mBAAO,KAAK9T,QAAL,CAAc+T,SAArB;AACH;;;4BAEY;AACT,mBAAO,KAAKlE,OAAZ;AACH;;;4BA8hBmB;AAChB,6BAAe,KAAK7P,QAAL,CAAcqB,SAA7B,SAA0C,KAAKrB,QAAL,CAActL,SAAxD;AACH;;;;EAhlB4BlhC,uB;;;;;;;;;;;;;;;;;;;ACZjC;;AACA;;AACA;;;;;;+eALA;AACA;;IAMas8C,iB,WAAAA,iB;;;AAET,+BAAY9P,QAAZ,EAAsB;AAAA;;AAAA,qDAClB,8BAAMA,QAAN,CADkB;;AAElB,cAAKgU,WAAL,GAAmB,IAAIla,YAAJ,CAAU,aAAV,CAAnB;AACA,cAAKma,aAAL,GAAqB,IAAIna,YAAJ,CAAU,eAAV,CAArB;AACA,cAAKoa,iBAAL,GAAyB,IAAIpa,YAAJ,CAAU,oBAAV,CAAzB;AACA,cAAKqa,aAAL,GAAqB,IAAIra,YAAJ,CAAU,gBAAV,CAArB;AACA,cAAKsa,cAAL,GAAsB,IAAIta,YAAJ,CAAU,iBAAV,CAAtB;AACA,cAAKua,mBAAL,GAA2B,IAAIva,YAAJ,CAAU,sBAAV,CAA3B;AAPkB;AAQrB;;gCAEDvG,I,iBAAKyX,I,EAAuB;AAAA,YAAjBc,UAAiB,uEAAN,IAAM;;AACxBv4C,iBAAIqgC,KAAJ,CAAU,wBAAV;AACA,qCAAML,IAAN,YAAWyX,IAAX;AACA,YAAIc,UAAJ,EAAgB;AACZ,iBAAKkI,WAAL,CAAiB7Z,KAAjB,CAAuB6Q,IAAvB;AACH;AACJ,K;;gCACDhX,M,qBAAS;AACLzgC,iBAAIqgC,KAAJ,CAAU,0BAAV;AACA,qCAAMI,MAAN;AACA,aAAKigB,aAAL,CAAmB9Z,KAAnB;AACH,K;;gCAEDwQ,a,0BAAczW,E,EAAI;AACd,aAAK8f,WAAL,CAAiB7f,UAAjB,CAA4BD,EAA5B;AACH,K;;gCACDogB,gB,6BAAiBpgB,E,EAAI;AACjB,aAAK8f,WAAL,CAAiB3f,aAAjB,CAA+BH,EAA/B;AACH,K;;gCAED2W,e,4BAAgB3W,E,EAAI;AAChB,aAAK+f,aAAL,CAAmB9f,UAAnB,CAA8BD,EAA9B;AACH,K;;gCACDqgB,kB,+BAAmBrgB,E,EAAI;AACnB,aAAK+f,aAAL,CAAmB5f,aAAnB,CAAiCH,EAAjC;AACH,K;;gCAEDsgB,mB,gCAAoBtgB,E,EAAI;AACpB,aAAKggB,iBAAL,CAAuB/f,UAAvB,CAAkCD,EAAlC;AACH,K;;gCACDugB,sB,mCAAuBvgB,E,EAAI;AACvB,aAAKggB,iBAAL,CAAuB7f,aAAvB,CAAqCH,EAArC;AACH,K;;gCACDoZ,sB,mCAAuB/3C,C,EAAG;AACtBhC,iBAAIqgC,KAAJ,CAAU,0CAAV,EAAsDr+B,EAAEgkC,OAAxD;AACA,aAAK2a,iBAAL,CAAuB/Z,KAAvB,CAA6B5kC,CAA7B;AACH,K;;gCAEDm/C,e,4BAAgBxgB,E,EAAI;AAChB,aAAKigB,aAAL,CAAmBhgB,UAAnB,CAA8BD,EAA9B;AACH,K;;gCACDygB,kB,+BAAmBzgB,E,EAAI;AACnB,aAAKigB,aAAL,CAAmB9f,aAAnB,CAAiCH,EAAjC;AACH,K;;gCACD+X,kB,iCAAqB;AACjB14C,iBAAIqgC,KAAJ,CAAU,sCAAV;AACA,aAAKugB,aAAL,CAAmBha,KAAnB;AACH,K;;gCAEDya,gB,6BAAiB1gB,E,EAAI;AACjB,aAAKkgB,cAAL,CAAoBjgB,UAApB,CAA+BD,EAA/B;AACH,K;;gCACD2gB,mB,gCAAoB3gB,E,EAAI;AACpB,aAAKkgB,cAAL,CAAoB/f,aAApB,CAAkCH,EAAlC;AACH,K;;gCACD8X,mB,kCAAsB;AAClBz4C,iBAAIqgC,KAAJ,CAAU,uCAAV;AACA,aAAKwgB,cAAL,CAAoBja,KAApB;AACH,K;;gCAED2a,qB,kCAAsB5gB,E,EAAI;AACtB,aAAKmgB,mBAAL,CAAyBlgB,UAAzB,CAAoCD,EAApC;AACH,K;;gCACD6gB,wB,qCAAyB7gB,E,EAAI;AACzB,aAAKmgB,mBAAL,CAAyBhgB,aAAzB,CAAuCH,EAAvC;AACH,K;;gCACD6X,wB,uCAA2B;AACvBx4C,iBAAIqgC,KAAJ,CAAU,4CAAV;AACA,aAAKygB,mBAAL,CAAyBla,KAAzB;AACH,K;;;EAjFkCtmC,qC;;;;;;;;;;;;;;;;;;;;;ACJvC;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;;;+eAVA;AACA;;AAWA,IAAMk/B,6CAA6C,EAAnD;AACA,IAAMiiB,8BAA8B,IAApC;;IAEapF,mB,WAAAA,mB;;;AACT,mCAqBQ;AAAA,uFAAJ,EAAI;AAAA,YApBJmB,kBAoBI,QApBJA,kBAoBI;AAAA,YAnBJ6B,8BAmBI,QAnBJA,8BAmBI;AAAA,YAlBJrb,mBAkBI,QAlBJA,mBAkBI;AAAA,YAjBJW,iBAiBI,QAjBJA,iBAiBI;AAAA,YAhBJ0Z,mBAgBI,QAhBJA,mBAgBI;AAAA,YAfJvW,oBAeI,QAfJA,oBAeI;AAAA,yCAdJ2U,oBAcI;AAAA,YAdJA,oBAcI,yCAdmB,KAcnB;AAAA,yCAbJsB,wBAaI;AAAA,YAbJA,wBAaI,yCAbuB,KAavB;AAAA,yCAZJD,2BAYI;AAAA,YAZJA,2BAYI,yCAZ0B,IAY1B;AAAA,uCAXJnB,cAWI;AAAA,YAXJA,cAWI,uCAXa,IAWb;AAAA,yCAVJjF,uBAUI;AAAA,YAVJA,uBAUI,yCAVsB,KAUtB;AAAA,yCATJiB,oBASI;AAAA,YATJA,oBASI,yCATmB8I,2BASnB;AAAA,yCARJ7I,uBAQI;AAAA,YARJA,uBAQI,yCARsB,IAQtB;AAAA,YAPJgG,0BAOI,QAPJA,0BAOI;AAAA,yCANJY,0BAMI;AAAA,YANJA,0BAMI,yCANyB,KAMzB;AAAA,yCALJ/f,mCAKI;AAAA,YALJA,mCAKI,yCALkCD,0CAKlC;AAAA,yCAJJ6gB,iBAII;AAAA,YAJJA,iBAII,yCAJgB,IAAInM,oCAAJ,EAIhB;AAAA,uCAHJoM,cAGI;AAAA,YAHJA,cAGI,uCAHa,IAAIjN,8BAAJ,EAGb;AAAA,wCAFJkN,eAEI;AAAA,YAFJA,eAEI,wCAFc,IAAI/Y,gCAAJ,EAEd;AAAA,kCADJgZ,SACI;AAAA,YADJA,SACI,kCADQ,IAAIrgD,0CAAJ,CAAyB,EAAEuhD,OAAO7gD,eAAOymC,cAAhB,EAAzB,CACR;;AAAA;;AAAA,qDACJ,+BAAMlkC,UAAU,CAAV,CAAN,CADI;;AAGJ,cAAKu+C,mBAAL,GAA2BnE,kBAA3B;AACA,cAAKoE,+BAAL,GAAuCvC,8BAAvC;AACA,cAAKwC,oBAAL,GAA4B7d,mBAA5B;AACA,cAAK8d,kBAAL,GAA0Bnd,iBAA1B;;AAEA,cAAKod,oBAAL,GAA4B1D,mBAA5B;AACA,cAAK2D,qBAAL,GAA6Bla,oBAA7B;AACA,cAAKma,qBAAL,GAA6BxF,oBAA7B;AACA,cAAKyF,yBAAL,GAAiCnE,wBAAjC;AACA,cAAKoE,4BAAL,GAAoCrE,2BAApC;AACA,cAAKje,oCAAL,GAA4CJ,mCAA5C;;AAEA,cAAK2iB,eAAL,GAAuBzF,cAAvB;AACA,cAAK0F,wBAAL,GAAgC3K,uBAAhC;AACA,cAAKU,qBAAL,GAA6BO,oBAA7B;AACA,cAAKN,wBAAL,GAAgCO,uBAAhC;AACA,YAAIgG,0BAAJ,EAAgC;AAC5B,kBAAK0D,2BAAL,GAAmC1D,0BAAnC;AACH,SAFD,MAGK,IAAIx7C,UAAU,CAAV,KAAgBA,UAAU,CAAV,EAAa4qC,aAAjC,EAAgD;AACjD,kBAAKsU,2BAAL,GAAmCtT,6BAAc8J,MAAd,CAAqB11C,UAAU,CAAV,EAAa4qC,aAAlC,IAAmD,UAAnD,GAAgE,MAAnG;AACH,SAFI,MAGA;AACD,kBAAKsU,2BAAL,GAAmC,UAAnC;AACH;AACD,cAAKC,2BAAL,GAAmC/C,0BAAnC;;AAEA,cAAKpC,kBAAL,GAA0BiD,iBAA1B;AACA,cAAK3C,eAAL,GAAuB4C,cAAvB;AACA,cAAKhC,gBAAL,GAAwBiC,eAAxB;;AAEA,cAAKJ,UAAL,GAAkBK,SAAlB;AAlCI;AAmCP;;;;4BAEwB;AACrB,mBAAO,KAAKmB,mBAAZ;AACH;;;4BACoC;AACjC,mBAAO,KAAKC,+BAAZ;AACH;;;4BACyB;AACtB,mBAAO,KAAKC,oBAAZ;AACH;;;4BACuB;AACpB,mBAAO,KAAKC,kBAAZ;AACH;;;4BAEyB;AACtB,mBAAO,KAAKC,oBAAZ;AACH;;;4BAC2B;AACxB,mBAAO,KAAKC,qBAAZ;AACH;;;4BAC0B;AACvB,mBAAO,KAAKC,qBAAZ;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKC,yBAAZ;AACH;;;4BACiC;AAC9B,mBAAO,KAAKC,4BAAZ;AACH;;;4BACyC;AACtC,mBAAO,KAAKtiB,oCAAZ;AACH;;;4BAEoB;AACjB,mBAAO,KAAKuiB,eAAZ;AACH;;;4BAC6B;AAC1B,mBAAO,KAAKC,wBAAZ;AACH;;;4BAC0B;AACvB,mBAAO,KAAKjK,qBAAZ;AACH;;;4BAC4B;AACzB,mBAAO,KAAKC,wBAAZ;AACH;;;4BAC+B;AAC5B,mBAAO,KAAKiK,2BAAZ;AACH;;;4BACgC;AAC7B,mBAAO,KAAKC,2BAAZ;AACH;;;4BAEuB;AACpB,mBAAO,KAAKnF,kBAAZ;AACH;;;4BACoB;AACjB,mBAAO,KAAKM,eAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKY,gBAAZ;AACH;;;4BAEe;AACZ,mBAAO,KAAK6B,UAAZ;AACH;;;;EA1HoCjgD,uC;;;;;;;;;;;;;;;;;;;ACZzC;;AACA;;0JAJA;AACA;;IAKaC,oB,WAAAA,oB;AACT,oCAAkE;AAAA,uFAAJ,EAAI;AAAA,+BAArDqiD,MAAqD;AAAA,YAArDA,MAAqD,+BAA5C,OAA4C;AAAA,8BAAnCd,KAAmC;AAAA,YAAnCA,KAAmC,8BAA3B7gD,eAAOwmC,YAAoB;;AAAA;;AAC9D,aAAKob,MAAL,GAAcf,KAAd;AACA,aAAKgB,OAAL,GAAeF,MAAf;AACH;;mCAEDjT,G,gBAAIzb,G,EAAK6U,K,EAAO;AACZ3oC,iBAAIqgC,KAAJ,CAAU,0BAAV,EAAsCvM,GAAtC;;AAEAA,cAAM,KAAK4uB,OAAL,GAAe5uB,GAArB;;AAEA,aAAK2uB,MAAL,CAAY/Z,OAAZ,CAAoB5U,GAApB,EAAyB6U,KAAzB;;AAEA,eAAOnG,QAAQC,OAAR,EAAP;AACH,K;;mCAEDxD,G,gBAAInL,G,EAAK;AACL9zB,iBAAIqgC,KAAJ,CAAU,0BAAV,EAAsCvM,GAAtC;;AAEAA,cAAM,KAAK4uB,OAAL,GAAe5uB,GAArB;;AAEA,YAAI6S,OAAO,KAAK8b,MAAL,CAAYha,OAAZ,CAAoB3U,GAApB,CAAX;;AAEA,eAAO0O,QAAQC,OAAR,CAAgBkE,IAAhB,CAAP;AACH,K;;mCAEDqJ,M,mBAAOlc,G,EAAK;AACR9zB,iBAAIqgC,KAAJ,CAAU,6BAAV,EAAyCvM,GAAzC;;AAEAA,cAAM,KAAK4uB,OAAL,GAAe5uB,GAArB;;AAEA,YAAI6S,OAAO,KAAK8b,MAAL,CAAYha,OAAZ,CAAoB3U,GAApB,CAAX;AACA,aAAK2uB,MAAL,CAAY7Z,UAAZ,CAAuB9U,GAAvB;;AAEA,eAAO0O,QAAQC,OAAR,CAAgBkE,IAAhB,CAAP;AACH,K;;mCAED0T,U,yBAAa;AACTr6C,iBAAIqgC,KAAJ,CAAU,iCAAV;;AAEA,YAAIngB,OAAO,EAAX;;AAEA,aAAK,IAAI2oB,QAAQ,CAAjB,EAAoBA,QAAQ,KAAK4Z,MAAL,CAAYpgD,MAAxC,EAAgDwmC,OAAhD,EAAyD;AACrD,gBAAI/U,MAAM,KAAK2uB,MAAL,CAAY3uB,GAAZ,CAAgB+U,KAAhB,CAAV;;AAEA,gBAAI/U,IAAIpsB,OAAJ,CAAY,KAAKg7C,OAAjB,MAA8B,CAAlC,EAAqC;AACjCxiC,qBAAK5b,IAAL,CAAUwvB,IAAIjvB,MAAJ,CAAW,KAAK69C,OAAL,CAAargD,MAAxB,CAAV;AACH;AACJ;;AAED,eAAOmgC,QAAQC,OAAR,CAAgBviB,IAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACzDL;;AAEA,IAAM+oB,qBAAqB,CAAC,OAAD,EAAU,OAAV,EAAmB,OAAnB,EAA4B,OAA5B,EAAqC,OAArC,EAA8C,OAA9C,EAAuD,OAAvD,EAAgE,OAAhE,EAAyE,OAAzE,CAA3B;;QAGIhN,G,GAAAA,c;QACA+M,O,GAAAA,kB;QACAnS,I,GAAAA,e;QACApe,M,GAAAA,iB;QACAmO,S,GAAAA,oB;QACAhc,Q,GAAAA,mB;QACAq+B,kB,GAAAA,kB;;;;;;;;;;;;;;;;;kBCLoB5kC,M;;AANxB;;;;;;AAEA;;;;AAIe,SAASA,MAAT,GAAkB;AAC/B,SAAO,mBAAQma,OAAR,CAAgB,IAAhB,EAAsB,EAAtB,CAAP;AACD;;;;;;;;;;;;;;;;;;ACRD,IAAMze,UAAU,QAAhB,C,QAAkCA,O,GAAAA,O","file":"oidc-client.js","sourcesContent":[" \t// The module cache\n \tvar installedModules = {};\n\n \t// The require function\n \tfunction __webpack_require__(moduleId) {\n\n \t\t// Check if module is in cache\n \t\tif(installedModules[moduleId]) {\n \t\t\treturn installedModules[moduleId].exports;\n \t\t}\n \t\t// Create a new module (and put it into the cache)\n \t\tvar module = installedModules[moduleId] = {\n \t\t\ti: moduleId,\n \t\t\tl: false,\n \t\t\texports: {}\n \t\t};\n\n \t\t// Execute the module function\n \t\tmodules[moduleId].call(module.exports, module, module.exports, __webpack_require__);\n\n \t\t// Flag the module as loaded\n \t\tmodule.l = true;\n\n \t\t// Return the exports of the module\n \t\treturn module.exports;\n \t}\n\n\n \t// expose the modules object (__webpack_modules__)\n \t__webpack_require__.m = modules;\n\n \t// expose the module cache\n \t__webpack_require__.c = installedModules;\n\n \t// define getter function for harmony exports\n \t__webpack_require__.d = function(exports, name, getter) {\n \t\tif(!__webpack_require__.o(exports, name)) {\n \t\t\tObject.defineProperty(exports, name, { enumerable: true, get: getter });\n \t\t}\n \t};\n\n \t// define __esModule on exports\n \t__webpack_require__.r = function(exports) {\n \t\tif(typeof Symbol !== 'undefined' && Symbol.toStringTag) {\n \t\t\tObject.defineProperty(exports, Symbol.toStringTag, { value: 'Module' });\n \t\t}\n \t\tObject.defineProperty(exports, '__esModule', { value: true });\n \t};\n\n \t// create a fake namespace object\n \t// mode & 1: value is a module id, require it\n \t// mode & 2: merge all properties of value into the ns\n \t// mode & 4: return value when already ns object\n \t// mode & 8|1: behave like require\n \t__webpack_require__.t = function(value, mode) {\n \t\tif(mode & 1) value = __webpack_require__(value);\n \t\tif(mode & 8) return value;\n \t\tif((mode & 4) && typeof value === 'object' && value && value.__esModule) return value;\n \t\tvar ns = Object.create(null);\n \t\t__webpack_require__.r(ns);\n \t\tObject.defineProperty(ns, 'default', { enumerable: true, value: value });\n \t\tif(mode & 2 && typeof value != 'string') for(var key in value) __webpack_require__.d(ns, key, function(key) { return value[key]; }.bind(null, key));\n \t\treturn ns;\n \t};\n\n \t// getDefaultExport function for compatibility with non-harmony modules\n \t__webpack_require__.n = function(module) {\n \t\tvar getter = module && module.__esModule ?\n \t\t\tfunction getDefault() { return module['default']; } :\n \t\t\tfunction getModuleExports() { return module; };\n \t\t__webpack_require__.d(getter, 'a', getter);\n \t\treturn getter;\n \t};\n\n \t// Object.prototype.hasOwnProperty.call\n \t__webpack_require__.o = function(object, property) { return Object.prototype.hasOwnProperty.call(object, property); };\n\n \t// __webpack_public_path__\n \t__webpack_require__.p = \"\";\n\n\n \t// Load entry module and return exports\n \treturn __webpack_require__(__webpack_require__.s = 0);\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './src/Log.js';\r\nimport { OidcClient } from './src/OidcClient.js';\r\nimport { OidcClientSettings } from './src/OidcClientSettings.js';\r\nimport { WebStorageStateStore } from './src/WebStorageStateStore.js';\r\nimport { InMemoryWebStorage } from './src/InMemoryWebStorage.js';\r\nimport { UserManager } from './src/UserManager.js';\r\nimport { AccessTokenEvents } from './src/AccessTokenEvents.js';\r\nimport { MetadataService } from './src/MetadataService.js';\r\nimport { CordovaPopupNavigator } from './src/CordovaPopupNavigator.js';\r\nimport { CordovaIFrameNavigator } from './src/CordovaIFrameNavigator.js';\r\nimport { CheckSessionIFrame } from './src/CheckSessionIFrame.js';\r\nimport { TokenRevocationClient } from './src/TokenRevocationClient.js';\r\nimport { SessionMonitor } from './src/SessionMonitor.js';\r\nimport { Global } from './src/Global.js';\r\nimport { User } from './src/User.js';\r\n\r\nimport { Version } from './version.js';\r\n\r\nexport default {\r\n    Version,\r\n    Log,\r\n    OidcClient,\r\n    OidcClientSettings,\r\n    WebStorageStateStore,\r\n    InMemoryWebStorage,\r\n    UserManager,\r\n    AccessTokenEvents,\r\n    MetadataService,\r\n    CordovaPopupNavigator,\r\n    CordovaIFrameNavigator,\r\n    CheckSessionIFrame,\r\n    TokenRevocationClient,\r\n    SessionMonitor,\r\n    Global,\r\n    User\r\n};\r\n","/*\r\n * jsrsasign(all) 8.0.12 (2018-04-22) (c) 2010-2018 Kenji Urushima | kjur.github.com/jsrsasign/license\r\n */\r\n\r\nvar navigator = {};\r\nnavigator.userAgent = false;\r\n\r\nvar window = {};\r\n\n/*!\r\nCopyright (c) 2011, Yahoo! Inc. All rights reserved.\r\nCode licensed under the BSD License:\r\nhttp://developer.yahoo.com/yui/license.html\r\nversion: 2.9.0\r\n*/\r\nif(YAHOO===undefined){var YAHOO={}}YAHOO.lang={extend:function(g,h,f){if(!h||!g){throw new Error(\"YAHOO.lang.extend failed, please check that all dependencies are included.\")}var d=function(){};d.prototype=h.prototype;g.prototype=new d();g.prototype.constructor=g;g.superclass=h.prototype;if(h.prototype.constructor==Object.prototype.constructor){h.prototype.constructor=h}if(f){var b;for(b in f){g.prototype[b]=f[b]}var e=function(){},c=[\"toString\",\"valueOf\"];try{if(/MSIE/.test(navigator.userAgent)){e=function(j,i){for(b=0;b<c.length;b=b+1){var l=c[b],k=i[l];if(typeof k===\"function\"&&k!=Object.prototype[l]){j[l]=k}}}}}catch(a){}e(g.prototype,f)}}};\n/*! CryptoJS v3.1.2 core-fix.js\r\n * code.google.com/p/crypto-js\r\n * (c) 2009-2013 by Jeff Mott. All rights reserved.\r\n * code.google.com/p/crypto-js/wiki/License\r\n * THIS IS FIX of 'core.js' to fix Hmac issue.\r\n * https://code.google.com/p/crypto-js/issues/detail?id=84\r\n * https://crypto-js.googlecode.com/svn-history/r667/branches/3.x/src/core.js\r\n */\r\nvar CryptoJS=CryptoJS||(function(e,g){var a={};var b=a.lib={};var j=b.Base=(function(){function n(){}return{extend:function(p){n.prototype=this;var o=new n();if(p){o.mixIn(p)}if(!o.hasOwnProperty(\"init\")){o.init=function(){o.$super.init.apply(this,arguments)}}o.init.prototype=o;o.$super=this;return o},create:function(){var o=this.extend();o.init.apply(o,arguments);return o},init:function(){},mixIn:function(p){for(var o in p){if(p.hasOwnProperty(o)){this[o]=p[o]}}if(p.hasOwnProperty(\"toString\")){this.toString=p.toString}},clone:function(){return this.init.prototype.extend(this)}}}());var l=b.WordArray=j.extend({init:function(o,n){o=this.words=o||[];if(n!=g){this.sigBytes=n}else{this.sigBytes=o.length*4}},toString:function(n){return(n||h).stringify(this)},concat:function(t){var q=this.words;var p=t.words;var n=this.sigBytes;var s=t.sigBytes;this.clamp();if(n%4){for(var r=0;r<s;r++){var o=(p[r>>>2]>>>(24-(r%4)*8))&255;q[(n+r)>>>2]|=o<<(24-((n+r)%4)*8)}}else{for(var r=0;r<s;r+=4){q[(n+r)>>>2]=p[r>>>2]}}this.sigBytes+=s;return this},clamp:function(){var o=this.words;var n=this.sigBytes;o[n>>>2]&=4294967295<<(32-(n%4)*8);o.length=e.ceil(n/4)},clone:function(){var n=j.clone.call(this);n.words=this.words.slice(0);return n},random:function(p){var o=[];for(var n=0;n<p;n+=4){o.push((e.random()*4294967296)|0)}return new l.init(o,p)}});var m=a.enc={};var h=m.Hex={stringify:function(p){var r=p.words;var o=p.sigBytes;var q=[];for(var n=0;n<o;n++){var s=(r[n>>>2]>>>(24-(n%4)*8))&255;q.push((s>>>4).toString(16));q.push((s&15).toString(16))}return q.join(\"\")},parse:function(p){var n=p.length;var q=[];for(var o=0;o<n;o+=2){q[o>>>3]|=parseInt(p.substr(o,2),16)<<(24-(o%8)*4)}return new l.init(q,n/2)}};var d=m.Latin1={stringify:function(q){var r=q.words;var p=q.sigBytes;var n=[];for(var o=0;o<p;o++){var s=(r[o>>>2]>>>(24-(o%4)*8))&255;n.push(String.fromCharCode(s))}return n.join(\"\")},parse:function(p){var n=p.length;var q=[];for(var o=0;o<n;o++){q[o>>>2]|=(p.charCodeAt(o)&255)<<(24-(o%4)*8)}return new l.init(q,n)}};var c=m.Utf8={stringify:function(n){try{return decodeURIComponent(escape(d.stringify(n)))}catch(o){throw new Error(\"Malformed UTF-8 data\")}},parse:function(n){return d.parse(unescape(encodeURIComponent(n)))}};var i=b.BufferedBlockAlgorithm=j.extend({reset:function(){this._data=new l.init();this._nDataBytes=0},_append:function(n){if(typeof n==\"string\"){n=c.parse(n)}this._data.concat(n);this._nDataBytes+=n.sigBytes},_process:function(w){var q=this._data;var x=q.words;var n=q.sigBytes;var t=this.blockSize;var v=t*4;var u=n/v;if(w){u=e.ceil(u)}else{u=e.max((u|0)-this._minBufferSize,0)}var s=u*t;var r=e.min(s*4,n);if(s){for(var p=0;p<s;p+=t){this._doProcessBlock(x,p)}var o=x.splice(0,s);q.sigBytes-=r}return new l.init(o,r)},clone:function(){var n=j.clone.call(this);n._data=this._data.clone();return n},_minBufferSize:0});var f=b.Hasher=i.extend({cfg:j.extend(),init:function(n){this.cfg=this.cfg.extend(n);this.reset()},reset:function(){i.reset.call(this);this._doReset()},update:function(n){this._append(n);this._process();return this},finalize:function(n){if(n){this._append(n)}var o=this._doFinalize();return o},blockSize:512/32,_createHelper:function(n){return function(p,o){return new n.init(o).finalize(p)}},_createHmacHelper:function(n){return function(p,o){return new k.HMAC.init(n,o).finalize(p)}}});var k=a.algo={};return a}(Math));\n/*\r\nCryptoJS v3.1.2 x64-core-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(g){var a=CryptoJS,f=a.lib,e=f.Base,h=f.WordArray,a=a.x64={};a.Word=e.extend({init:function(b,c){this.high=b;this.low=c}});a.WordArray=e.extend({init:function(b,c){b=this.words=b||[];this.sigBytes=c!=g?c:8*b.length},toX32:function(){for(var b=this.words,c=b.length,a=[],d=0;d<c;d++){var e=b[d];a.push(e.high);a.push(e.low)}return h.create(a,this.sigBytes)},clone:function(){for(var b=e.clone.call(this),c=b.words=this.words.slice(0),a=c.length,d=0;d<a;d++)c[d]=c[d].clone();return b}})})();\r\n\n/*\r\nCryptoJS v3.1.2 enc-base64.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(){var h=CryptoJS,j=h.lib.WordArray;h.enc.Base64={stringify:function(b){var e=b.words,f=b.sigBytes,c=this._map;b.clamp();b=[];for(var a=0;a<f;a+=3)for(var d=(e[a>>>2]>>>24-8*(a%4)&255)<<16|(e[a+1>>>2]>>>24-8*((a+1)%4)&255)<<8|e[a+2>>>2]>>>24-8*((a+2)%4)&255,g=0;4>g&&a+0.75*g<f;g++)b.push(c.charAt(d>>>6*(3-g)&63));if(e=c.charAt(64))for(;b.length%4;)b.push(e);return b.join(\"\")},parse:function(b){var e=b.length,f=this._map,c=f.charAt(64);c&&(c=b.indexOf(c),-1!=c&&(e=c));for(var c=[],a=0,d=0;d<\r\ne;d++)if(d%4){var g=f.indexOf(b.charAt(d-1))<<2*(d%4),h=f.indexOf(b.charAt(d))>>>6-2*(d%4);c[a>>>2]|=(g|h)<<24-8*(a%4);a++}return j.create(c,a)},_map:\"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=\"}})();\r\n\n/*\r\nCryptoJS v3.1.2 sha256-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(k){for(var g=CryptoJS,h=g.lib,v=h.WordArray,j=h.Hasher,h=g.algo,s=[],t=[],u=function(q){return 4294967296*(q-(q|0))|0},l=2,b=0;64>b;){var d;a:{d=l;for(var w=k.sqrt(d),r=2;r<=w;r++)if(!(d%r)){d=!1;break a}d=!0}d&&(8>b&&(s[b]=u(k.pow(l,0.5))),t[b]=u(k.pow(l,1/3)),b++);l++}var n=[],h=h.SHA256=j.extend({_doReset:function(){this._hash=new v.init(s.slice(0))},_doProcessBlock:function(q,h){for(var a=this._hash.words,c=a[0],d=a[1],b=a[2],k=a[3],f=a[4],g=a[5],j=a[6],l=a[7],e=0;64>e;e++){if(16>e)n[e]=\r\nq[h+e]|0;else{var m=n[e-15],p=n[e-2];n[e]=((m<<25|m>>>7)^(m<<14|m>>>18)^m>>>3)+n[e-7]+((p<<15|p>>>17)^(p<<13|p>>>19)^p>>>10)+n[e-16]}m=l+((f<<26|f>>>6)^(f<<21|f>>>11)^(f<<7|f>>>25))+(f&g^~f&j)+t[e]+n[e];p=((c<<30|c>>>2)^(c<<19|c>>>13)^(c<<10|c>>>22))+(c&d^c&b^d&b);l=j;j=g;g=f;f=k+m|0;k=b;b=d;d=c;c=m+p|0}a[0]=a[0]+c|0;a[1]=a[1]+d|0;a[2]=a[2]+b|0;a[3]=a[3]+k|0;a[4]=a[4]+f|0;a[5]=a[5]+g|0;a[6]=a[6]+j|0;a[7]=a[7]+l|0},_doFinalize:function(){var d=this._data,b=d.words,a=8*this._nDataBytes,c=8*d.sigBytes;\r\nb[c>>>5]|=128<<24-c%32;b[(c+64>>>9<<4)+14]=k.floor(a/4294967296);b[(c+64>>>9<<4)+15]=a;d.sigBytes=4*b.length;this._process();return this._hash},clone:function(){var b=j.clone.call(this);b._hash=this._hash.clone();return b}});g.SHA256=j._createHelper(h);g.HmacSHA256=j._createHmacHelper(h)})(Math);\r\n\n/*\r\nCryptoJS v3.1.2 sha512-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(){function a(){return d.create.apply(d,arguments)}for(var n=CryptoJS,r=n.lib.Hasher,e=n.x64,d=e.Word,T=e.WordArray,e=n.algo,ea=[a(1116352408,3609767458),a(1899447441,602891725),a(3049323471,3964484399),a(3921009573,2173295548),a(961987163,4081628472),a(1508970993,3053834265),a(2453635748,2937671579),a(2870763221,3664609560),a(3624381080,2734883394),a(310598401,1164996542),a(607225278,1323610764),a(1426881987,3590304994),a(1925078388,4068182383),a(2162078206,991336113),a(2614888103,633803317),\r\na(3248222580,3479774868),a(3835390401,2666613458),a(4022224774,944711139),a(264347078,2341262773),a(604807628,2007800933),a(770255983,1495990901),a(1249150122,1856431235),a(1555081692,3175218132),a(1996064986,2198950837),a(2554220882,3999719339),a(2821834349,766784016),a(2952996808,2566594879),a(3210313671,3203337956),a(3336571891,1034457026),a(3584528711,2466948901),a(113926993,3758326383),a(338241895,168717936),a(666307205,1188179964),a(773529912,1546045734),a(1294757372,1522805485),a(1396182291,\r\n2643833823),a(1695183700,2343527390),a(1986661051,1014477480),a(2177026350,1206759142),a(2456956037,344077627),a(2730485921,1290863460),a(2820302411,3158454273),a(3259730800,3505952657),a(3345764771,106217008),a(3516065817,3606008344),a(3600352804,1432725776),a(4094571909,1467031594),a(275423344,851169720),a(430227734,3100823752),a(506948616,1363258195),a(659060556,3750685593),a(883997877,3785050280),a(958139571,3318307427),a(1322822218,3812723403),a(1537002063,2003034995),a(1747873779,3602036899),\r\na(1955562222,1575990012),a(2024104815,1125592928),a(2227730452,2716904306),a(2361852424,442776044),a(2428436474,593698344),a(2756734187,3733110249),a(3204031479,2999351573),a(3329325298,3815920427),a(3391569614,3928383900),a(3515267271,566280711),a(3940187606,3454069534),a(4118630271,4000239992),a(116418474,1914138554),a(174292421,2731055270),a(289380356,3203993006),a(460393269,320620315),a(685471733,587496836),a(852142971,1086792851),a(1017036298,365543100),a(1126000580,2618297676),a(1288033470,\r\n3409855158),a(1501505948,4234509866),a(1607167915,987167468),a(1816402316,1246189591)],v=[],w=0;80>w;w++)v[w]=a();e=e.SHA512=r.extend({_doReset:function(){this._hash=new T.init([new d.init(1779033703,4089235720),new d.init(3144134277,2227873595),new d.init(1013904242,4271175723),new d.init(2773480762,1595750129),new d.init(1359893119,2917565137),new d.init(2600822924,725511199),new d.init(528734635,4215389547),new d.init(1541459225,327033209)])},_doProcessBlock:function(a,d){for(var f=this._hash.words,\r\nF=f[0],e=f[1],n=f[2],r=f[3],G=f[4],H=f[5],I=f[6],f=f[7],w=F.high,J=F.low,X=e.high,K=e.low,Y=n.high,L=n.low,Z=r.high,M=r.low,$=G.high,N=G.low,aa=H.high,O=H.low,ba=I.high,P=I.low,ca=f.high,Q=f.low,k=w,g=J,z=X,x=K,A=Y,y=L,U=Z,B=M,l=$,h=N,R=aa,C=O,S=ba,D=P,V=ca,E=Q,m=0;80>m;m++){var s=v[m];if(16>m)var j=s.high=a[d+2*m]|0,b=s.low=a[d+2*m+1]|0;else{var j=v[m-15],b=j.high,p=j.low,j=(b>>>1|p<<31)^(b>>>8|p<<24)^b>>>7,p=(p>>>1|b<<31)^(p>>>8|b<<24)^(p>>>7|b<<25),u=v[m-2],b=u.high,c=u.low,u=(b>>>19|c<<13)^(b<<\r\n3|c>>>29)^b>>>6,c=(c>>>19|b<<13)^(c<<3|b>>>29)^(c>>>6|b<<26),b=v[m-7],W=b.high,t=v[m-16],q=t.high,t=t.low,b=p+b.low,j=j+W+(b>>>0<p>>>0?1:0),b=b+c,j=j+u+(b>>>0<c>>>0?1:0),b=b+t,j=j+q+(b>>>0<t>>>0?1:0);s.high=j;s.low=b}var W=l&R^~l&S,t=h&C^~h&D,s=k&z^k&A^z&A,T=g&x^g&y^x&y,p=(k>>>28|g<<4)^(k<<30|g>>>2)^(k<<25|g>>>7),u=(g>>>28|k<<4)^(g<<30|k>>>2)^(g<<25|k>>>7),c=ea[m],fa=c.high,da=c.low,c=E+((h>>>14|l<<18)^(h>>>18|l<<14)^(h<<23|l>>>9)),q=V+((l>>>14|h<<18)^(l>>>18|h<<14)^(l<<23|h>>>9))+(c>>>0<E>>>0?1:\r\n0),c=c+t,q=q+W+(c>>>0<t>>>0?1:0),c=c+da,q=q+fa+(c>>>0<da>>>0?1:0),c=c+b,q=q+j+(c>>>0<b>>>0?1:0),b=u+T,s=p+s+(b>>>0<u>>>0?1:0),V=S,E=D,S=R,D=C,R=l,C=h,h=B+c|0,l=U+q+(h>>>0<B>>>0?1:0)|0,U=A,B=y,A=z,y=x,z=k,x=g,g=c+b|0,k=q+s+(g>>>0<c>>>0?1:0)|0}J=F.low=J+g;F.high=w+k+(J>>>0<g>>>0?1:0);K=e.low=K+x;e.high=X+z+(K>>>0<x>>>0?1:0);L=n.low=L+y;n.high=Y+A+(L>>>0<y>>>0?1:0);M=r.low=M+B;r.high=Z+U+(M>>>0<B>>>0?1:0);N=G.low=N+h;G.high=$+l+(N>>>0<h>>>0?1:0);O=H.low=O+C;H.high=aa+R+(O>>>0<C>>>0?1:0);P=I.low=P+D;\r\nI.high=ba+S+(P>>>0<D>>>0?1:0);Q=f.low=Q+E;f.high=ca+V+(Q>>>0<E>>>0?1:0)},_doFinalize:function(){var a=this._data,d=a.words,f=8*this._nDataBytes,e=8*a.sigBytes;d[e>>>5]|=128<<24-e%32;d[(e+128>>>10<<5)+30]=Math.floor(f/4294967296);d[(e+128>>>10<<5)+31]=f;a.sigBytes=4*d.length;this._process();return this._hash.toX32()},clone:function(){var a=r.clone.call(this);a._hash=this._hash.clone();return a},blockSize:32});n.SHA512=r._createHelper(e);n.HmacSHA512=r._createHmacHelper(e)})();\r\n\n/*\r\nCryptoJS v3.1.2 sha384-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(){var c=CryptoJS,a=c.x64,b=a.Word,e=a.WordArray,a=c.algo,d=a.SHA512,a=a.SHA384=d.extend({_doReset:function(){this._hash=new e.init([new b.init(3418070365,3238371032),new b.init(1654270250,914150663),new b.init(2438529370,812702999),new b.init(355462360,4144912697),new b.init(1731405415,4290775857),new b.init(2394180231,1750603025),new b.init(3675008525,1694076839),new b.init(1203062813,3204075428)])},_doFinalize:function(){var a=d._doFinalize.call(this);a.sigBytes-=16;return a}});c.SHA384=\r\nd._createHelper(a);c.HmacSHA384=d._createHmacHelper(a)})();\r\n\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nvar b64map=\"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\";var b64pad=\"=\";function hex2b64(d){var b;var e;var a=\"\";for(b=0;b+3<=d.length;b+=3){e=parseInt(d.substring(b,b+3),16);a+=b64map.charAt(e>>6)+b64map.charAt(e&63)}if(b+1==d.length){e=parseInt(d.substring(b,b+1),16);a+=b64map.charAt(e<<2)}else{if(b+2==d.length){e=parseInt(d.substring(b,b+2),16);a+=b64map.charAt(e>>2)+b64map.charAt((e&3)<<4)}}if(b64pad){while((a.length&3)>0){a+=b64pad}}return a}function b64tohex(f){var d=\"\";var e;var b=0;var c;var a;for(e=0;e<f.length;++e){if(f.charAt(e)==b64pad){break}a=b64map.indexOf(f.charAt(e));if(a<0){continue}if(b==0){d+=int2char(a>>2);c=a&3;b=1}else{if(b==1){d+=int2char((c<<2)|(a>>4));c=a&15;b=2}else{if(b==2){d+=int2char(c);d+=int2char(a>>2);c=a&3;b=3}else{d+=int2char((c<<2)|(a>>4));d+=int2char(a&15);b=0}}}}if(b==1){d+=int2char(c<<2)}return d}function b64toBA(e){var d=b64tohex(e);var c;var b=new Array();for(c=0;2*c<d.length;++c){b[c]=parseInt(d.substring(2*c,2*c+2),16)}return b};\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nvar dbits;var canary=244837814094590;var j_lm=((canary&16777215)==15715070);function BigInteger(e,d,f){if(e!=null){if(\"number\"==typeof e){this.fromNumber(e,d,f)}else{if(d==null&&\"string\"!=typeof e){this.fromString(e,256)}else{this.fromString(e,d)}}}}function nbi(){return new BigInteger(null)}function am1(f,a,b,e,h,g){while(--g>=0){var d=a*this[f++]+b[e]+h;h=Math.floor(d/67108864);b[e++]=d&67108863}return h}function am2(f,q,r,e,o,a){var k=q&32767,p=q>>15;while(--a>=0){var d=this[f]&32767;var g=this[f++]>>15;var b=p*d+g*k;d=k*d+((b&32767)<<15)+r[e]+(o&1073741823);o=(d>>>30)+(b>>>15)+p*g+(o>>>30);r[e++]=d&1073741823}return o}function am3(f,q,r,e,o,a){var k=q&16383,p=q>>14;while(--a>=0){var d=this[f]&16383;var g=this[f++]>>14;var b=p*d+g*k;d=k*d+((b&16383)<<14)+r[e]+o;o=(d>>28)+(b>>14)+p*g;r[e++]=d&268435455}return o}if(j_lm&&(navigator.appName==\"Microsoft Internet Explorer\")){BigInteger.prototype.am=am2;dbits=30}else{if(j_lm&&(navigator.appName!=\"Netscape\")){BigInteger.prototype.am=am1;dbits=26}else{BigInteger.prototype.am=am3;dbits=28}}BigInteger.prototype.DB=dbits;BigInteger.prototype.DM=((1<<dbits)-1);BigInteger.prototype.DV=(1<<dbits);var BI_FP=52;BigInteger.prototype.FV=Math.pow(2,BI_FP);BigInteger.prototype.F1=BI_FP-dbits;BigInteger.prototype.F2=2*dbits-BI_FP;var BI_RM=\"0123456789abcdefghijklmnopqrstuvwxyz\";var BI_RC=new Array();var rr,vv;rr=\"0\".charCodeAt(0);for(vv=0;vv<=9;++vv){BI_RC[rr++]=vv}rr=\"a\".charCodeAt(0);for(vv=10;vv<36;++vv){BI_RC[rr++]=vv}rr=\"A\".charCodeAt(0);for(vv=10;vv<36;++vv){BI_RC[rr++]=vv}function int2char(a){return BI_RM.charAt(a)}function intAt(b,a){var d=BI_RC[b.charCodeAt(a)];return(d==null)?-1:d}function bnpCopyTo(b){for(var a=this.t-1;a>=0;--a){b[a]=this[a]}b.t=this.t;b.s=this.s}function bnpFromInt(a){this.t=1;this.s=(a<0)?-1:0;if(a>0){this[0]=a}else{if(a<-1){this[0]=a+this.DV}else{this.t=0}}}function nbv(a){var b=nbi();b.fromInt(a);return b}function bnpFromString(h,c){var e;if(c==16){e=4}else{if(c==8){e=3}else{if(c==256){e=8}else{if(c==2){e=1}else{if(c==32){e=5}else{if(c==4){e=2}else{this.fromRadix(h,c);return}}}}}}this.t=0;this.s=0;var g=h.length,d=false,f=0;while(--g>=0){var a=(e==8)?h[g]&255:intAt(h,g);if(a<0){if(h.charAt(g)==\"-\"){d=true}continue}d=false;if(f==0){this[this.t++]=a}else{if(f+e>this.DB){this[this.t-1]|=(a&((1<<(this.DB-f))-1))<<f;this[this.t++]=(a>>(this.DB-f))}else{this[this.t-1]|=a<<f}}f+=e;if(f>=this.DB){f-=this.DB}}if(e==8&&(h[0]&128)!=0){this.s=-1;if(f>0){this[this.t-1]|=((1<<(this.DB-f))-1)<<f}}this.clamp();if(d){BigInteger.ZERO.subTo(this,this)}}function bnpClamp(){var a=this.s&this.DM;while(this.t>0&&this[this.t-1]==a){--this.t}}function bnToString(c){if(this.s<0){return\"-\"+this.negate().toString(c)}var e;if(c==16){e=4}else{if(c==8){e=3}else{if(c==2){e=1}else{if(c==32){e=5}else{if(c==4){e=2}else{return this.toRadix(c)}}}}}var g=(1<<e)-1,l,a=false,h=\"\",f=this.t;var j=this.DB-(f*this.DB)%e;if(f-->0){if(j<this.DB&&(l=this[f]>>j)>0){a=true;h=int2char(l)}while(f>=0){if(j<e){l=(this[f]&((1<<j)-1))<<(e-j);l|=this[--f]>>(j+=this.DB-e)}else{l=(this[f]>>(j-=e))&g;if(j<=0){j+=this.DB;--f}}if(l>0){a=true}if(a){h+=int2char(l)}}}return a?h:\"0\"}function bnNegate(){var a=nbi();BigInteger.ZERO.subTo(this,a);return a}function bnAbs(){return(this.s<0)?this.negate():this}function bnCompareTo(b){var d=this.s-b.s;if(d!=0){return d}var c=this.t;d=c-b.t;if(d!=0){return(this.s<0)?-d:d}while(--c>=0){if((d=this[c]-b[c])!=0){return d}}return 0}function nbits(a){var c=1,b;if((b=a>>>16)!=0){a=b;c+=16}if((b=a>>8)!=0){a=b;c+=8}if((b=a>>4)!=0){a=b;c+=4}if((b=a>>2)!=0){a=b;c+=2}if((b=a>>1)!=0){a=b;c+=1}return c}function bnBitLength(){if(this.t<=0){return 0}return this.DB*(this.t-1)+nbits(this[this.t-1]^(this.s&this.DM))}function bnpDLShiftTo(c,b){var a;for(a=this.t-1;a>=0;--a){b[a+c]=this[a]}for(a=c-1;a>=0;--a){b[a]=0}b.t=this.t+c;b.s=this.s}function bnpDRShiftTo(c,b){for(var a=c;a<this.t;++a){b[a-c]=this[a]}b.t=Math.max(this.t-c,0);b.s=this.s}function bnpLShiftTo(j,e){var b=j%this.DB;var a=this.DB-b;var g=(1<<a)-1;var f=Math.floor(j/this.DB),h=(this.s<<b)&this.DM,d;for(d=this.t-1;d>=0;--d){e[d+f+1]=(this[d]>>a)|h;h=(this[d]&g)<<b}for(d=f-1;d>=0;--d){e[d]=0}e[f]=h;e.t=this.t+f+1;e.s=this.s;e.clamp()}function bnpRShiftTo(g,d){d.s=this.s;var e=Math.floor(g/this.DB);if(e>=this.t){d.t=0;return}var b=g%this.DB;var a=this.DB-b;var f=(1<<b)-1;d[0]=this[e]>>b;for(var c=e+1;c<this.t;++c){d[c-e-1]|=(this[c]&f)<<a;d[c-e]=this[c]>>b}if(b>0){d[this.t-e-1]|=(this.s&f)<<a}d.t=this.t-e;d.clamp()}function bnpSubTo(d,f){var e=0,g=0,b=Math.min(d.t,this.t);while(e<b){g+=this[e]-d[e];f[e++]=g&this.DM;g>>=this.DB}if(d.t<this.t){g-=d.s;while(e<this.t){g+=this[e];f[e++]=g&this.DM;g>>=this.DB}g+=this.s}else{g+=this.s;while(e<d.t){g-=d[e];f[e++]=g&this.DM;g>>=this.DB}g-=d.s}f.s=(g<0)?-1:0;if(g<-1){f[e++]=this.DV+g}else{if(g>0){f[e++]=g}}f.t=e;f.clamp()}function bnpMultiplyTo(c,e){var b=this.abs(),f=c.abs();var d=b.t;e.t=d+f.t;while(--d>=0){e[d]=0}for(d=0;d<f.t;++d){e[d+b.t]=b.am(0,f[d],e,d,0,b.t)}e.s=0;e.clamp();if(this.s!=c.s){BigInteger.ZERO.subTo(e,e)}}function bnpSquareTo(d){var a=this.abs();var b=d.t=2*a.t;while(--b>=0){d[b]=0}for(b=0;b<a.t-1;++b){var e=a.am(b,a[b],d,2*b,0,1);if((d[b+a.t]+=a.am(b+1,2*a[b],d,2*b+1,e,a.t-b-1))>=a.DV){d[b+a.t]-=a.DV;d[b+a.t+1]=1}}if(d.t>0){d[d.t-1]+=a.am(b,a[b],d,2*b,0,1)}d.s=0;d.clamp()}function bnpDivRemTo(n,h,g){var w=n.abs();if(w.t<=0){return}var k=this.abs();if(k.t<w.t){if(h!=null){h.fromInt(0)}if(g!=null){this.copyTo(g)}return}if(g==null){g=nbi()}var d=nbi(),a=this.s,l=n.s;var v=this.DB-nbits(w[w.t-1]);if(v>0){w.lShiftTo(v,d);k.lShiftTo(v,g)}else{w.copyTo(d);k.copyTo(g)}var p=d.t;var b=d[p-1];if(b==0){return}var o=b*(1<<this.F1)+((p>1)?d[p-2]>>this.F2:0);var A=this.FV/o,z=(1<<this.F1)/o,x=1<<this.F2;var u=g.t,s=u-p,f=(h==null)?nbi():h;d.dlShiftTo(s,f);if(g.compareTo(f)>=0){g[g.t++]=1;g.subTo(f,g)}BigInteger.ONE.dlShiftTo(p,f);f.subTo(d,d);while(d.t<p){d[d.t++]=0}while(--s>=0){var c=(g[--u]==b)?this.DM:Math.floor(g[u]*A+(g[u-1]+x)*z);if((g[u]+=d.am(0,c,g,s,0,p))<c){d.dlShiftTo(s,f);g.subTo(f,g);while(g[u]<--c){g.subTo(f,g)}}}if(h!=null){g.drShiftTo(p,h);if(a!=l){BigInteger.ZERO.subTo(h,h)}}g.t=p;g.clamp();if(v>0){g.rShiftTo(v,g)}if(a<0){BigInteger.ZERO.subTo(g,g)}}function bnMod(b){var c=nbi();this.abs().divRemTo(b,null,c);if(this.s<0&&c.compareTo(BigInteger.ZERO)>0){b.subTo(c,c)}return c}function Classic(a){this.m=a}function cConvert(a){if(a.s<0||a.compareTo(this.m)>=0){return a.mod(this.m)}else{return a}}function cRevert(a){return a}function cReduce(a){a.divRemTo(this.m,null,a)}function cMulTo(a,c,b){a.multiplyTo(c,b);this.reduce(b)}function cSqrTo(a,b){a.squareTo(b);this.reduce(b)}Classic.prototype.convert=cConvert;Classic.prototype.revert=cRevert;Classic.prototype.reduce=cReduce;Classic.prototype.mulTo=cMulTo;Classic.prototype.sqrTo=cSqrTo;function bnpInvDigit(){if(this.t<1){return 0}var a=this[0];if((a&1)==0){return 0}var b=a&3;b=(b*(2-(a&15)*b))&15;b=(b*(2-(a&255)*b))&255;b=(b*(2-(((a&65535)*b)&65535)))&65535;b=(b*(2-a*b%this.DV))%this.DV;return(b>0)?this.DV-b:-b}function Montgomery(a){this.m=a;this.mp=a.invDigit();this.mpl=this.mp&32767;this.mph=this.mp>>15;this.um=(1<<(a.DB-15))-1;this.mt2=2*a.t}function montConvert(a){var b=nbi();a.abs().dlShiftTo(this.m.t,b);b.divRemTo(this.m,null,b);if(a.s<0&&b.compareTo(BigInteger.ZERO)>0){this.m.subTo(b,b)}return b}function montRevert(a){var b=nbi();a.copyTo(b);this.reduce(b);return b}function montReduce(a){while(a.t<=this.mt2){a[a.t++]=0}for(var c=0;c<this.m.t;++c){var b=a[c]&32767;var d=(b*this.mpl+(((b*this.mph+(a[c]>>15)*this.mpl)&this.um)<<15))&a.DM;b=c+this.m.t;a[b]+=this.m.am(0,d,a,c,0,this.m.t);while(a[b]>=a.DV){a[b]-=a.DV;a[++b]++}}a.clamp();a.drShiftTo(this.m.t,a);if(a.compareTo(this.m)>=0){a.subTo(this.m,a)}}function montSqrTo(a,b){a.squareTo(b);this.reduce(b)}function montMulTo(a,c,b){a.multiplyTo(c,b);this.reduce(b)}Montgomery.prototype.convert=montConvert;Montgomery.prototype.revert=montRevert;Montgomery.prototype.reduce=montReduce;Montgomery.prototype.mulTo=montMulTo;Montgomery.prototype.sqrTo=montSqrTo;function bnpIsEven(){return((this.t>0)?(this[0]&1):this.s)==0}function bnpExp(h,j){if(h>4294967295||h<1){return BigInteger.ONE}var f=nbi(),a=nbi(),d=j.convert(this),c=nbits(h)-1;d.copyTo(f);while(--c>=0){j.sqrTo(f,a);if((h&(1<<c))>0){j.mulTo(a,d,f)}else{var b=f;f=a;a=b}}return j.revert(f)}function bnModPowInt(b,a){var c;if(b<256||a.isEven()){c=new Classic(a)}else{c=new Montgomery(a)}return this.exp(b,c)}BigInteger.prototype.copyTo=bnpCopyTo;BigInteger.prototype.fromInt=bnpFromInt;BigInteger.prototype.fromString=bnpFromString;BigInteger.prototype.clamp=bnpClamp;BigInteger.prototype.dlShiftTo=bnpDLShiftTo;BigInteger.prototype.drShiftTo=bnpDRShiftTo;BigInteger.prototype.lShiftTo=bnpLShiftTo;BigInteger.prototype.rShiftTo=bnpRShiftTo;BigInteger.prototype.subTo=bnpSubTo;BigInteger.prototype.multiplyTo=bnpMultiplyTo;BigInteger.prototype.squareTo=bnpSquareTo;BigInteger.prototype.divRemTo=bnpDivRemTo;BigInteger.prototype.invDigit=bnpInvDigit;BigInteger.prototype.isEven=bnpIsEven;BigInteger.prototype.exp=bnpExp;BigInteger.prototype.toString=bnToString;BigInteger.prototype.negate=bnNegate;BigInteger.prototype.abs=bnAbs;BigInteger.prototype.compareTo=bnCompareTo;BigInteger.prototype.bitLength=bnBitLength;BigInteger.prototype.mod=bnMod;BigInteger.prototype.modPowInt=bnModPowInt;BigInteger.ZERO=nbv(0);BigInteger.ONE=nbv(1);\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction bnClone(){var a=nbi();this.copyTo(a);return a}function bnIntValue(){if(this.s<0){if(this.t==1){return this[0]-this.DV}else{if(this.t==0){return -1}}}else{if(this.t==1){return this[0]}else{if(this.t==0){return 0}}}return((this[1]&((1<<(32-this.DB))-1))<<this.DB)|this[0]}function bnByteValue(){return(this.t==0)?this.s:(this[0]<<24)>>24}function bnShortValue(){return(this.t==0)?this.s:(this[0]<<16)>>16}function bnpChunkSize(a){return Math.floor(Math.LN2*this.DB/Math.log(a))}function bnSigNum(){if(this.s<0){return -1}else{if(this.t<=0||(this.t==1&&this[0]<=0)){return 0}else{return 1}}}function bnpToRadix(c){if(c==null){c=10}if(this.signum()==0||c<2||c>36){return\"0\"}var f=this.chunkSize(c);var e=Math.pow(c,f);var i=nbv(e),j=nbi(),h=nbi(),g=\"\";this.divRemTo(i,j,h);while(j.signum()>0){g=(e+h.intValue()).toString(c).substr(1)+g;j.divRemTo(i,j,h)}return h.intValue().toString(c)+g}function bnpFromRadix(m,h){this.fromInt(0);if(h==null){h=10}var f=this.chunkSize(h);var g=Math.pow(h,f),e=false,a=0,l=0;for(var c=0;c<m.length;++c){var k=intAt(m,c);if(k<0){if(m.charAt(c)==\"-\"&&this.signum()==0){e=true}continue}l=h*l+k;if(++a>=f){this.dMultiply(g);this.dAddOffset(l,0);a=0;l=0}}if(a>0){this.dMultiply(Math.pow(h,a));this.dAddOffset(l,0)}if(e){BigInteger.ZERO.subTo(this,this)}}function bnpFromNumber(f,e,h){if(\"number\"==typeof e){if(f<2){this.fromInt(1)}else{this.fromNumber(f,h);if(!this.testBit(f-1)){this.bitwiseTo(BigInteger.ONE.shiftLeft(f-1),op_or,this)}if(this.isEven()){this.dAddOffset(1,0)}while(!this.isProbablePrime(e)){this.dAddOffset(2,0);if(this.bitLength()>f){this.subTo(BigInteger.ONE.shiftLeft(f-1),this)}}}}else{var d=new Array(),g=f&7;d.length=(f>>3)+1;e.nextBytes(d);if(g>0){d[0]&=((1<<g)-1)}else{d[0]=0}this.fromString(d,256)}}function bnToByteArray(){var b=this.t,c=new Array();c[0]=this.s;var e=this.DB-(b*this.DB)%8,f,a=0;if(b-->0){if(e<this.DB&&(f=this[b]>>e)!=(this.s&this.DM)>>e){c[a++]=f|(this.s<<(this.DB-e))}while(b>=0){if(e<8){f=(this[b]&((1<<e)-1))<<(8-e);f|=this[--b]>>(e+=this.DB-8)}else{f=(this[b]>>(e-=8))&255;if(e<=0){e+=this.DB;--b}}if((f&128)!=0){f|=-256}if(a==0&&(this.s&128)!=(f&128)){++a}if(a>0||f!=this.s){c[a++]=f}}}return c}function bnEquals(b){return(this.compareTo(b)==0)}function bnMin(b){return(this.compareTo(b)<0)?this:b}function bnMax(b){return(this.compareTo(b)>0)?this:b}function bnpBitwiseTo(c,h,e){var d,g,b=Math.min(c.t,this.t);for(d=0;d<b;++d){e[d]=h(this[d],c[d])}if(c.t<this.t){g=c.s&this.DM;for(d=b;d<this.t;++d){e[d]=h(this[d],g)}e.t=this.t}else{g=this.s&this.DM;for(d=b;d<c.t;++d){e[d]=h(g,c[d])}e.t=c.t}e.s=h(this.s,c.s);e.clamp()}function op_and(a,b){return a&b}function bnAnd(b){var c=nbi();this.bitwiseTo(b,op_and,c);return c}function op_or(a,b){return a|b}function bnOr(b){var c=nbi();this.bitwiseTo(b,op_or,c);return c}function op_xor(a,b){return a^b}function bnXor(b){var c=nbi();this.bitwiseTo(b,op_xor,c);return c}function op_andnot(a,b){return a&~b}function bnAndNot(b){var c=nbi();this.bitwiseTo(b,op_andnot,c);return c}function bnNot(){var b=nbi();for(var a=0;a<this.t;++a){b[a]=this.DM&~this[a]}b.t=this.t;b.s=~this.s;return b}function bnShiftLeft(b){var a=nbi();if(b<0){this.rShiftTo(-b,a)}else{this.lShiftTo(b,a)}return a}function bnShiftRight(b){var a=nbi();if(b<0){this.lShiftTo(-b,a)}else{this.rShiftTo(b,a)}return a}function lbit(a){if(a==0){return -1}var b=0;if((a&65535)==0){a>>=16;b+=16}if((a&255)==0){a>>=8;b+=8}if((a&15)==0){a>>=4;b+=4}if((a&3)==0){a>>=2;b+=2}if((a&1)==0){++b}return b}function bnGetLowestSetBit(){for(var a=0;a<this.t;++a){if(this[a]!=0){return a*this.DB+lbit(this[a])}}if(this.s<0){return this.t*this.DB}return -1}function cbit(a){var b=0;while(a!=0){a&=a-1;++b}return b}function bnBitCount(){var c=0,a=this.s&this.DM;for(var b=0;b<this.t;++b){c+=cbit(this[b]^a)}return c}function bnTestBit(b){var a=Math.floor(b/this.DB);if(a>=this.t){return(this.s!=0)}return((this[a]&(1<<(b%this.DB)))!=0)}function bnpChangeBit(c,b){var a=BigInteger.ONE.shiftLeft(c);this.bitwiseTo(a,b,a);return a}function bnSetBit(a){return this.changeBit(a,op_or)}function bnClearBit(a){return this.changeBit(a,op_andnot)}function bnFlipBit(a){return this.changeBit(a,op_xor)}function bnpAddTo(d,f){var e=0,g=0,b=Math.min(d.t,this.t);while(e<b){g+=this[e]+d[e];f[e++]=g&this.DM;g>>=this.DB}if(d.t<this.t){g+=d.s;while(e<this.t){g+=this[e];f[e++]=g&this.DM;g>>=this.DB}g+=this.s}else{g+=this.s;while(e<d.t){g+=d[e];f[e++]=g&this.DM;g>>=this.DB}g+=d.s}f.s=(g<0)?-1:0;if(g>0){f[e++]=g}else{if(g<-1){f[e++]=this.DV+g}}f.t=e;f.clamp()}function bnAdd(b){var c=nbi();this.addTo(b,c);return c}function bnSubtract(b){var c=nbi();this.subTo(b,c);return c}function bnMultiply(b){var c=nbi();this.multiplyTo(b,c);return c}function bnSquare(){var a=nbi();this.squareTo(a);return a}function bnDivide(b){var c=nbi();this.divRemTo(b,c,null);return c}function bnRemainder(b){var c=nbi();this.divRemTo(b,null,c);return c}function bnDivideAndRemainder(b){var d=nbi(),c=nbi();this.divRemTo(b,d,c);return new Array(d,c)}function bnpDMultiply(a){this[this.t]=this.am(0,a-1,this,0,0,this.t);++this.t;this.clamp()}function bnpDAddOffset(b,a){if(b==0){return}while(this.t<=a){this[this.t++]=0}this[a]+=b;while(this[a]>=this.DV){this[a]-=this.DV;if(++a>=this.t){this[this.t++]=0}++this[a]}}function NullExp(){}function nNop(a){return a}function nMulTo(a,c,b){a.multiplyTo(c,b)}function nSqrTo(a,b){a.squareTo(b)}NullExp.prototype.convert=nNop;NullExp.prototype.revert=nNop;NullExp.prototype.mulTo=nMulTo;NullExp.prototype.sqrTo=nSqrTo;function bnPow(a){return this.exp(a,new NullExp())}function bnpMultiplyLowerTo(b,f,e){var d=Math.min(this.t+b.t,f);e.s=0;e.t=d;while(d>0){e[--d]=0}var c;for(c=e.t-this.t;d<c;++d){e[d+this.t]=this.am(0,b[d],e,d,0,this.t)}for(c=Math.min(b.t,f);d<c;++d){this.am(0,b[d],e,d,0,f-d)}e.clamp()}function bnpMultiplyUpperTo(b,e,d){--e;var c=d.t=this.t+b.t-e;d.s=0;while(--c>=0){d[c]=0}for(c=Math.max(e-this.t,0);c<b.t;++c){d[this.t+c-e]=this.am(e-c,b[c],d,0,0,this.t+c-e)}d.clamp();d.drShiftTo(1,d)}function Barrett(a){this.r2=nbi();this.q3=nbi();BigInteger.ONE.dlShiftTo(2*a.t,this.r2);this.mu=this.r2.divide(a);this.m=a}function barrettConvert(a){if(a.s<0||a.t>2*this.m.t){return a.mod(this.m)}else{if(a.compareTo(this.m)<0){return a}else{var b=nbi();a.copyTo(b);this.reduce(b);return b}}}function barrettRevert(a){return a}function barrettReduce(a){a.drShiftTo(this.m.t-1,this.r2);if(a.t>this.m.t+1){a.t=this.m.t+1;a.clamp()}this.mu.multiplyUpperTo(this.r2,this.m.t+1,this.q3);this.m.multiplyLowerTo(this.q3,this.m.t+1,this.r2);while(a.compareTo(this.r2)<0){a.dAddOffset(1,this.m.t+1)}a.subTo(this.r2,a);while(a.compareTo(this.m)>=0){a.subTo(this.m,a)}}function barrettSqrTo(a,b){a.squareTo(b);this.reduce(b)}function barrettMulTo(a,c,b){a.multiplyTo(c,b);this.reduce(b)}Barrett.prototype.convert=barrettConvert;Barrett.prototype.revert=barrettRevert;Barrett.prototype.reduce=barrettReduce;Barrett.prototype.mulTo=barrettMulTo;Barrett.prototype.sqrTo=barrettSqrTo;function bnModPow(q,f){var o=q.bitLength(),h,b=nbv(1),v;if(o<=0){return b}else{if(o<18){h=1}else{if(o<48){h=3}else{if(o<144){h=4}else{if(o<768){h=5}else{h=6}}}}}if(o<8){v=new Classic(f)}else{if(f.isEven()){v=new Barrett(f)}else{v=new Montgomery(f)}}var p=new Array(),d=3,s=h-1,a=(1<<h)-1;p[1]=v.convert(this);if(h>1){var A=nbi();v.sqrTo(p[1],A);while(d<=a){p[d]=nbi();v.mulTo(A,p[d-2],p[d]);d+=2}}var l=q.t-1,x,u=true,c=nbi(),y;o=nbits(q[l])-1;while(l>=0){if(o>=s){x=(q[l]>>(o-s))&a}else{x=(q[l]&((1<<(o+1))-1))<<(s-o);if(l>0){x|=q[l-1]>>(this.DB+o-s)}}d=h;while((x&1)==0){x>>=1;--d}if((o-=d)<0){o+=this.DB;--l}if(u){p[x].copyTo(b);u=false}else{while(d>1){v.sqrTo(b,c);v.sqrTo(c,b);d-=2}if(d>0){v.sqrTo(b,c)}else{y=b;b=c;c=y}v.mulTo(c,p[x],b)}while(l>=0&&(q[l]&(1<<o))==0){v.sqrTo(b,c);y=b;b=c;c=y;if(--o<0){o=this.DB-1;--l}}}return v.revert(b)}function bnGCD(c){var b=(this.s<0)?this.negate():this.clone();var h=(c.s<0)?c.negate():c.clone();if(b.compareTo(h)<0){var e=b;b=h;h=e}var d=b.getLowestSetBit(),f=h.getLowestSetBit();if(f<0){return b}if(d<f){f=d}if(f>0){b.rShiftTo(f,b);h.rShiftTo(f,h)}while(b.signum()>0){if((d=b.getLowestSetBit())>0){b.rShiftTo(d,b)}if((d=h.getLowestSetBit())>0){h.rShiftTo(d,h)}if(b.compareTo(h)>=0){b.subTo(h,b);b.rShiftTo(1,b)}else{h.subTo(b,h);h.rShiftTo(1,h)}}if(f>0){h.lShiftTo(f,h)}return h}function bnpModInt(e){if(e<=0){return 0}var c=this.DV%e,b=(this.s<0)?e-1:0;if(this.t>0){if(c==0){b=this[0]%e}else{for(var a=this.t-1;a>=0;--a){b=(c*b+this[a])%e}}}return b}function bnModInverse(f){var j=f.isEven();if((this.isEven()&&j)||f.signum()==0){return BigInteger.ZERO}var i=f.clone(),h=this.clone();var g=nbv(1),e=nbv(0),l=nbv(0),k=nbv(1);while(i.signum()!=0){while(i.isEven()){i.rShiftTo(1,i);if(j){if(!g.isEven()||!e.isEven()){g.addTo(this,g);e.subTo(f,e)}g.rShiftTo(1,g)}else{if(!e.isEven()){e.subTo(f,e)}}e.rShiftTo(1,e)}while(h.isEven()){h.rShiftTo(1,h);if(j){if(!l.isEven()||!k.isEven()){l.addTo(this,l);k.subTo(f,k)}l.rShiftTo(1,l)}else{if(!k.isEven()){k.subTo(f,k)}}k.rShiftTo(1,k)}if(i.compareTo(h)>=0){i.subTo(h,i);if(j){g.subTo(l,g)}e.subTo(k,e)}else{h.subTo(i,h);if(j){l.subTo(g,l)}k.subTo(e,k)}}if(h.compareTo(BigInteger.ONE)!=0){return BigInteger.ZERO}if(k.compareTo(f)>=0){return k.subtract(f)}if(k.signum()<0){k.addTo(f,k)}else{return k}if(k.signum()<0){return k.add(f)}else{return k}}var lowprimes=[2,3,5,7,11,13,17,19,23,29,31,37,41,43,47,53,59,61,67,71,73,79,83,89,97,101,103,107,109,113,127,131,137,139,149,151,157,163,167,173,179,181,191,193,197,199,211,223,227,229,233,239,241,251,257,263,269,271,277,281,283,293,307,311,313,317,331,337,347,349,353,359,367,373,379,383,389,397,401,409,419,421,431,433,439,443,449,457,461,463,467,479,487,491,499,503,509,521,523,541,547,557,563,569,571,577,587,593,599,601,607,613,617,619,631,641,643,647,653,659,661,673,677,683,691,701,709,719,727,733,739,743,751,757,761,769,773,787,797,809,811,821,823,827,829,839,853,857,859,863,877,881,883,887,907,911,919,929,937,941,947,953,967,971,977,983,991,997];var lplim=(1<<26)/lowprimes[lowprimes.length-1];function bnIsProbablePrime(e){var d,b=this.abs();if(b.t==1&&b[0]<=lowprimes[lowprimes.length-1]){for(d=0;d<lowprimes.length;++d){if(b[0]==lowprimes[d]){return true}}return false}if(b.isEven()){return false}d=1;while(d<lowprimes.length){var a=lowprimes[d],c=d+1;while(c<lowprimes.length&&a<lplim){a*=lowprimes[c++]}a=b.modInt(a);while(d<c){if(a%lowprimes[d++]==0){return false}}}return b.millerRabin(e)}function bnpMillerRabin(f){var g=this.subtract(BigInteger.ONE);var c=g.getLowestSetBit();if(c<=0){return false}var h=g.shiftRight(c);f=(f+1)>>1;if(f>lowprimes.length){f=lowprimes.length}var b=nbi();for(var e=0;e<f;++e){b.fromInt(lowprimes[Math.floor(Math.random()*lowprimes.length)]);var l=b.modPow(h,this);if(l.compareTo(BigInteger.ONE)!=0&&l.compareTo(g)!=0){var d=1;while(d++<c&&l.compareTo(g)!=0){l=l.modPowInt(2,this);if(l.compareTo(BigInteger.ONE)==0){return false}}if(l.compareTo(g)!=0){return false}}}return true}BigInteger.prototype.chunkSize=bnpChunkSize;BigInteger.prototype.toRadix=bnpToRadix;BigInteger.prototype.fromRadix=bnpFromRadix;BigInteger.prototype.fromNumber=bnpFromNumber;BigInteger.prototype.bitwiseTo=bnpBitwiseTo;BigInteger.prototype.changeBit=bnpChangeBit;BigInteger.prototype.addTo=bnpAddTo;BigInteger.prototype.dMultiply=bnpDMultiply;BigInteger.prototype.dAddOffset=bnpDAddOffset;BigInteger.prototype.multiplyLowerTo=bnpMultiplyLowerTo;BigInteger.prototype.multiplyUpperTo=bnpMultiplyUpperTo;BigInteger.prototype.modInt=bnpModInt;BigInteger.prototype.millerRabin=bnpMillerRabin;BigInteger.prototype.clone=bnClone;BigInteger.prototype.intValue=bnIntValue;BigInteger.prototype.byteValue=bnByteValue;BigInteger.prototype.shortValue=bnShortValue;BigInteger.prototype.signum=bnSigNum;BigInteger.prototype.toByteArray=bnToByteArray;BigInteger.prototype.equals=bnEquals;BigInteger.prototype.min=bnMin;BigInteger.prototype.max=bnMax;BigInteger.prototype.and=bnAnd;BigInteger.prototype.or=bnOr;BigInteger.prototype.xor=bnXor;BigInteger.prototype.andNot=bnAndNot;BigInteger.prototype.not=bnNot;BigInteger.prototype.shiftLeft=bnShiftLeft;BigInteger.prototype.shiftRight=bnShiftRight;BigInteger.prototype.getLowestSetBit=bnGetLowestSetBit;BigInteger.prototype.bitCount=bnBitCount;BigInteger.prototype.testBit=bnTestBit;BigInteger.prototype.setBit=bnSetBit;BigInteger.prototype.clearBit=bnClearBit;BigInteger.prototype.flipBit=bnFlipBit;BigInteger.prototype.add=bnAdd;BigInteger.prototype.subtract=bnSubtract;BigInteger.prototype.multiply=bnMultiply;BigInteger.prototype.divide=bnDivide;BigInteger.prototype.remainder=bnRemainder;BigInteger.prototype.divideAndRemainder=bnDivideAndRemainder;BigInteger.prototype.modPow=bnModPow;BigInteger.prototype.modInverse=bnModInverse;BigInteger.prototype.pow=bnPow;BigInteger.prototype.gcd=bnGCD;BigInteger.prototype.isProbablePrime=bnIsProbablePrime;BigInteger.prototype.square=bnSquare;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction Arcfour(){this.i=0;this.j=0;this.S=new Array()}function ARC4init(d){var c,a,b;for(c=0;c<256;++c){this.S[c]=c}a=0;for(c=0;c<256;++c){a=(a+this.S[c]+d[c%d.length])&255;b=this.S[c];this.S[c]=this.S[a];this.S[a]=b}this.i=0;this.j=0}function ARC4next(){var a;this.i=(this.i+1)&255;this.j=(this.j+this.S[this.i])&255;a=this.S[this.i];this.S[this.i]=this.S[this.j];this.S[this.j]=a;return this.S[(a+this.S[this.i])&255]}Arcfour.prototype.init=ARC4init;Arcfour.prototype.next=ARC4next;function prng_newstate(){return new Arcfour()}var rng_psize=256;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nvar rng_state;var rng_pool;var rng_pptr;function rng_seed_int(a){rng_pool[rng_pptr++]^=a&255;rng_pool[rng_pptr++]^=(a>>8)&255;rng_pool[rng_pptr++]^=(a>>16)&255;rng_pool[rng_pptr++]^=(a>>24)&255;if(rng_pptr>=rng_psize){rng_pptr-=rng_psize}}function rng_seed_time(){rng_seed_int(new Date().getTime())}if(rng_pool==null){rng_pool=new Array();rng_pptr=0;var t;if(window!==undefined&&(window.crypto!==undefined||window.msCrypto!==undefined)){var crypto=window.crypto||window.msCrypto;if(crypto.getRandomValues){var ua=new Uint8Array(32);crypto.getRandomValues(ua);for(t=0;t<32;++t){rng_pool[rng_pptr++]=ua[t]}}else{if(navigator.appName==\"Netscape\"&&navigator.appVersion<\"5\"){var z=window.crypto.random(32);for(t=0;t<z.length;++t){rng_pool[rng_pptr++]=z.charCodeAt(t)&255}}}}while(rng_pptr<rng_psize){t=Math.floor(65536*Math.random());rng_pool[rng_pptr++]=t>>>8;rng_pool[rng_pptr++]=t&255}rng_pptr=0;rng_seed_time()}function rng_get_byte(){if(rng_state==null){rng_seed_time();rng_state=prng_newstate();rng_state.init(rng_pool);for(rng_pptr=0;rng_pptr<rng_pool.length;++rng_pptr){rng_pool[rng_pptr]=0}rng_pptr=0}return rng_state.next()}function rng_get_bytes(b){var a;for(a=0;a<b.length;++a){b[a]=rng_get_byte()}}function SecureRandom(){}SecureRandom.prototype.nextBytes=rng_get_bytes;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction parseBigInt(b,a){return new BigInteger(b,a)}function linebrk(c,d){var a=\"\";var b=0;while(b+d<c.length){a+=c.substring(b,b+d)+\"\\n\";b+=d}return a+c.substring(b,c.length)}function byte2Hex(a){if(a<16){return\"0\"+a.toString(16)}else{return a.toString(16)}}function pkcs1pad2(e,h){if(h<e.length+11){throw\"Message too long for RSA\";return null}var g=new Array();var d=e.length-1;while(d>=0&&h>0){var f=e.charCodeAt(d--);if(f<128){g[--h]=f}else{if((f>127)&&(f<2048)){g[--h]=(f&63)|128;g[--h]=(f>>6)|192}else{g[--h]=(f&63)|128;g[--h]=((f>>6)&63)|128;g[--h]=(f>>12)|224}}}g[--h]=0;var b=new SecureRandom();var a=new Array();while(h>2){a[0]=0;while(a[0]==0){b.nextBytes(a)}g[--h]=a[0]}g[--h]=2;g[--h]=0;return new BigInteger(g)}function oaep_mgf1_arr(c,a,e){var b=\"\",d=0;while(b.length<a){b+=e(String.fromCharCode.apply(String,c.concat([(d&4278190080)>>24,(d&16711680)>>16,(d&65280)>>8,d&255])));d+=1}return b}function oaep_pad(q,a,f,l){var c=KJUR.crypto.MessageDigest;var o=KJUR.crypto.Util;var b=null;if(!f){f=\"sha1\"}if(typeof f===\"string\"){b=c.getCanonicalAlgName(f);l=c.getHashLength(b);f=function(i){return hextorstr(o.hashHex(rstrtohex(i),b))}}if(q.length+2*l+2>a){throw\"Message too long for RSA\"}var k=\"\",e;for(e=0;e<a-q.length-2*l-2;e+=1){k+=\"\\x00\"}var h=f(\"\")+k+\"\\x01\"+q;var g=new Array(l);new SecureRandom().nextBytes(g);var j=oaep_mgf1_arr(g,h.length,f);var p=[];for(e=0;e<h.length;e+=1){p[e]=h.charCodeAt(e)^j.charCodeAt(e)}var m=oaep_mgf1_arr(p,g.length,f);var d=[0];for(e=0;e<g.length;e+=1){d[e+1]=g[e]^m.charCodeAt(e)}return new BigInteger(d.concat(p))}function RSAKey(){this.n=null;this.e=0;this.d=null;this.p=null;this.q=null;this.dmp1=null;this.dmq1=null;this.coeff=null}function RSASetPublic(b,a){this.isPublic=true;this.isPrivate=false;if(typeof b!==\"string\"){this.n=b;this.e=a}else{if(b!=null&&a!=null&&b.length>0&&a.length>0){this.n=parseBigInt(b,16);this.e=parseInt(a,16)}else{throw\"Invalid RSA public key\"}}}function RSADoPublic(a){return a.modPowInt(this.e,this.n)}function RSAEncrypt(d){var a=pkcs1pad2(d,(this.n.bitLength()+7)>>3);if(a==null){return null}var e=this.doPublic(a);if(e==null){return null}var b=e.toString(16);if((b.length&1)==0){return b}else{return\"0\"+b}}function RSAEncryptOAEP(f,e,b){var a=oaep_pad(f,(this.n.bitLength()+7)>>3,e,b);if(a==null){return null}var g=this.doPublic(a);if(g==null){return null}var d=g.toString(16);if((d.length&1)==0){return d}else{return\"0\"+d}}RSAKey.prototype.doPublic=RSADoPublic;RSAKey.prototype.setPublic=RSASetPublic;RSAKey.prototype.encrypt=RSAEncrypt;RSAKey.prototype.encryptOAEP=RSAEncryptOAEP;RSAKey.prototype.type=\"RSA\";\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction ECFieldElementFp(b,a){this.x=a;this.q=b}function feFpEquals(a){if(a==this){return true}return(this.q.equals(a.q)&&this.x.equals(a.x))}function feFpToBigInteger(){return this.x}function feFpNegate(){return new ECFieldElementFp(this.q,this.x.negate().mod(this.q))}function feFpAdd(a){return new ECFieldElementFp(this.q,this.x.add(a.toBigInteger()).mod(this.q))}function feFpSubtract(a){return new ECFieldElementFp(this.q,this.x.subtract(a.toBigInteger()).mod(this.q))}function feFpMultiply(a){return new ECFieldElementFp(this.q,this.x.multiply(a.toBigInteger()).mod(this.q))}function feFpSquare(){return new ECFieldElementFp(this.q,this.x.square().mod(this.q))}function feFpDivide(a){return new ECFieldElementFp(this.q,this.x.multiply(a.toBigInteger().modInverse(this.q)).mod(this.q))}ECFieldElementFp.prototype.equals=feFpEquals;ECFieldElementFp.prototype.toBigInteger=feFpToBigInteger;ECFieldElementFp.prototype.negate=feFpNegate;ECFieldElementFp.prototype.add=feFpAdd;ECFieldElementFp.prototype.subtract=feFpSubtract;ECFieldElementFp.prototype.multiply=feFpMultiply;ECFieldElementFp.prototype.square=feFpSquare;ECFieldElementFp.prototype.divide=feFpDivide;function ECPointFp(c,a,d,b){this.curve=c;this.x=a;this.y=d;if(b==null){this.z=BigInteger.ONE}else{this.z=b}this.zinv=null}function pointFpGetX(){if(this.zinv==null){this.zinv=this.z.modInverse(this.curve.q)}return this.curve.fromBigInteger(this.x.toBigInteger().multiply(this.zinv).mod(this.curve.q))}function pointFpGetY(){if(this.zinv==null){this.zinv=this.z.modInverse(this.curve.q)}return this.curve.fromBigInteger(this.y.toBigInteger().multiply(this.zinv).mod(this.curve.q))}function pointFpEquals(a){if(a==this){return true}if(this.isInfinity()){return a.isInfinity()}if(a.isInfinity()){return this.isInfinity()}var c,b;c=a.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(a.z)).mod(this.curve.q);if(!c.equals(BigInteger.ZERO)){return false}b=a.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(a.z)).mod(this.curve.q);return b.equals(BigInteger.ZERO)}function pointFpIsInfinity(){if((this.x==null)&&(this.y==null)){return true}return this.z.equals(BigInteger.ZERO)&&!this.y.toBigInteger().equals(BigInteger.ZERO)}function pointFpNegate(){return new ECPointFp(this.curve,this.x,this.y.negate(),this.z)}function pointFpAdd(l){if(this.isInfinity()){return l}if(l.isInfinity()){return this}var p=l.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(l.z)).mod(this.curve.q);var o=l.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(l.z)).mod(this.curve.q);if(BigInteger.ZERO.equals(o)){if(BigInteger.ZERO.equals(p)){return this.twice()}return this.curve.getInfinity()}var j=new BigInteger(\"3\");var e=this.x.toBigInteger();var n=this.y.toBigInteger();var c=l.x.toBigInteger();var k=l.y.toBigInteger();var m=o.square();var i=m.multiply(o);var d=e.multiply(m);var g=p.square().multiply(this.z);var a=g.subtract(d.shiftLeft(1)).multiply(l.z).subtract(i).multiply(o).mod(this.curve.q);var h=d.multiply(j).multiply(p).subtract(n.multiply(i)).subtract(g.multiply(p)).multiply(l.z).add(p.multiply(i)).mod(this.curve.q);var f=i.multiply(this.z).multiply(l.z).mod(this.curve.q);return new ECPointFp(this.curve,this.curve.fromBigInteger(a),this.curve.fromBigInteger(h),f)}function pointFpTwice(){if(this.isInfinity()){return this}if(this.y.toBigInteger().signum()==0){return this.curve.getInfinity()}var g=new BigInteger(\"3\");var c=this.x.toBigInteger();var h=this.y.toBigInteger();var e=h.multiply(this.z);var j=e.multiply(h).mod(this.curve.q);var i=this.curve.a.toBigInteger();var k=c.square().multiply(g);if(!BigInteger.ZERO.equals(i)){k=k.add(this.z.square().multiply(i))}k=k.mod(this.curve.q);var b=k.square().subtract(c.shiftLeft(3).multiply(j)).shiftLeft(1).multiply(e).mod(this.curve.q);var f=k.multiply(g).multiply(c).subtract(j.shiftLeft(1)).shiftLeft(2).multiply(j).subtract(k.square().multiply(k)).mod(this.curve.q);var d=e.square().multiply(e).shiftLeft(3).mod(this.curve.q);return new ECPointFp(this.curve,this.curve.fromBigInteger(b),this.curve.fromBigInteger(f),d)}function pointFpMultiply(b){if(this.isInfinity()){return this}if(b.signum()==0){return this.curve.getInfinity()}var g=b;var f=g.multiply(new BigInteger(\"3\"));var l=this.negate();var d=this;var c;for(c=f.bitLength()-2;c>0;--c){d=d.twice();var a=f.testBit(c);var j=g.testBit(c);if(a!=j){d=d.add(a?this:l)}}return d}function pointFpMultiplyTwo(c,a,b){var d;if(c.bitLength()>b.bitLength()){d=c.bitLength()-1}else{d=b.bitLength()-1}var f=this.curve.getInfinity();var e=this.add(a);while(d>=0){f=f.twice();if(c.testBit(d)){if(b.testBit(d)){f=f.add(e)}else{f=f.add(this)}}else{if(b.testBit(d)){f=f.add(a)}}--d}return f}ECPointFp.prototype.getX=pointFpGetX;ECPointFp.prototype.getY=pointFpGetY;ECPointFp.prototype.equals=pointFpEquals;ECPointFp.prototype.isInfinity=pointFpIsInfinity;ECPointFp.prototype.negate=pointFpNegate;ECPointFp.prototype.add=pointFpAdd;ECPointFp.prototype.twice=pointFpTwice;ECPointFp.prototype.multiply=pointFpMultiply;ECPointFp.prototype.multiplyTwo=pointFpMultiplyTwo;function ECCurveFp(e,d,c){this.q=e;this.a=this.fromBigInteger(d);this.b=this.fromBigInteger(c);this.infinity=new ECPointFp(this,null,null)}function curveFpGetQ(){return this.q}function curveFpGetA(){return this.a}function curveFpGetB(){return this.b}function curveFpEquals(a){if(a==this){return true}return(this.q.equals(a.q)&&this.a.equals(a.a)&&this.b.equals(a.b))}function curveFpGetInfinity(){return this.infinity}function curveFpFromBigInteger(a){return new ECFieldElementFp(this.q,a)}function curveFpDecodePointHex(d){switch(parseInt(d.substr(0,2),16)){case 0:return this.infinity;case 2:case 3:return null;case 4:case 6:case 7:var a=(d.length-2)/2;var c=d.substr(2,a);var b=d.substr(a+2,a);return new ECPointFp(this,this.fromBigInteger(new BigInteger(c,16)),this.fromBigInteger(new BigInteger(b,16)));default:return null}}ECCurveFp.prototype.getQ=curveFpGetQ;ECCurveFp.prototype.getA=curveFpGetA;ECCurveFp.prototype.getB=curveFpGetB;ECCurveFp.prototype.equals=curveFpEquals;ECCurveFp.prototype.getInfinity=curveFpGetInfinity;ECCurveFp.prototype.fromBigInteger=curveFpFromBigInteger;ECCurveFp.prototype.decodePointHex=curveFpDecodePointHex;\n/*! (c) Stefan Thomas | https://github.com/bitcoinjs/bitcoinjs-lib\r\n */\r\nECFieldElementFp.prototype.getByteLength=function(){return Math.floor((this.toBigInteger().bitLength()+7)/8)};ECPointFp.prototype.getEncoded=function(c){var d=function(h,f){var g=h.toByteArrayUnsigned();if(f<g.length){g=g.slice(g.length-f)}else{while(f>g.length){g.unshift(0)}}return g};var a=this.getX().toBigInteger();var e=this.getY().toBigInteger();var b=d(a,32);if(c){if(e.isEven()){b.unshift(2)}else{b.unshift(3)}}else{b.unshift(4);b=b.concat(d(e,32))}return b};ECPointFp.decodeFrom=function(g,c){var f=c[0];var e=c.length-1;var d=c.slice(1,1+e/2);var b=c.slice(1+e/2,1+e);d.unshift(0);b.unshift(0);var a=new BigInteger(d);var h=new BigInteger(b);return new ECPointFp(g,g.fromBigInteger(a),g.fromBigInteger(h))};ECPointFp.decodeFromHex=function(g,c){var f=c.substr(0,2);var e=c.length-2;var d=c.substr(2,e/2);var b=c.substr(2+e/2,e/2);var a=new BigInteger(d,16);var h=new BigInteger(b,16);return new ECPointFp(g,g.fromBigInteger(a),g.fromBigInteger(h))};ECPointFp.prototype.add2D=function(c){if(this.isInfinity()){return c}if(c.isInfinity()){return this}if(this.x.equals(c.x)){if(this.y.equals(c.y)){return this.twice()}return this.curve.getInfinity()}var g=c.x.subtract(this.x);var e=c.y.subtract(this.y);var a=e.divide(g);var d=a.square().subtract(this.x).subtract(c.x);var f=a.multiply(this.x.subtract(d)).subtract(this.y);return new ECPointFp(this.curve,d,f)};ECPointFp.prototype.twice2D=function(){if(this.isInfinity()){return this}if(this.y.toBigInteger().signum()==0){return this.curve.getInfinity()}var b=this.curve.fromBigInteger(BigInteger.valueOf(2));var e=this.curve.fromBigInteger(BigInteger.valueOf(3));var a=this.x.square().multiply(e).add(this.curve.a).divide(this.y.multiply(b));var c=a.square().subtract(this.x.multiply(b));var d=a.multiply(this.x.subtract(c)).subtract(this.y);return new ECPointFp(this.curve,c,d)};ECPointFp.prototype.multiply2D=function(b){if(this.isInfinity()){return this}if(b.signum()==0){return this.curve.getInfinity()}var g=b;var f=g.multiply(new BigInteger(\"3\"));var l=this.negate();var d=this;var c;for(c=f.bitLength()-2;c>0;--c){d=d.twice();var a=f.testBit(c);var j=g.testBit(c);if(a!=j){d=d.add2D(a?this:l)}}return d};ECPointFp.prototype.isOnCurve=function(){var d=this.getX().toBigInteger();var i=this.getY().toBigInteger();var f=this.curve.getA().toBigInteger();var c=this.curve.getB().toBigInteger();var h=this.curve.getQ();var e=i.multiply(i).mod(h);var g=d.multiply(d).multiply(d).add(f.multiply(d)).add(c).mod(h);return e.equals(g)};ECPointFp.prototype.toString=function(){return\"(\"+this.getX().toBigInteger().toString()+\",\"+this.getY().toBigInteger().toString()+\")\"};ECPointFp.prototype.validate=function(){var c=this.curve.getQ();if(this.isInfinity()){throw new Error(\"Point is at infinity.\")}var a=this.getX().toBigInteger();var b=this.getY().toBigInteger();if(a.compareTo(BigInteger.ONE)<0||a.compareTo(c.subtract(BigInteger.ONE))>0){throw new Error(\"x coordinate out of bounds\")}if(b.compareTo(BigInteger.ONE)<0||b.compareTo(c.subtract(BigInteger.ONE))>0){throw new Error(\"y coordinate out of bounds\")}if(!this.isOnCurve()){throw new Error(\"Point is not on the curve.\")}if(this.multiply(c).isInfinity()){throw new Error(\"Point is not a scalar multiple of G.\")}return true};\n/*! Mike Samuel (c) 2009 | code.google.com/p/json-sans-eval\r\n */\r\nvar jsonParse=(function(){var e=\"(?:-?\\\\b(?:0|[1-9][0-9]*)(?:\\\\.[0-9]+)?(?:[eE][+-]?[0-9]+)?\\\\b)\";var j='(?:[^\\\\0-\\\\x08\\\\x0a-\\\\x1f\"\\\\\\\\]|\\\\\\\\(?:[\"/\\\\\\\\bfnrt]|u[0-9A-Fa-f]{4}))';var i='(?:\"'+j+'*\")';var d=new RegExp(\"(?:false|true|null|[\\\\{\\\\}\\\\[\\\\]]|\"+e+\"|\"+i+\")\",\"g\");var k=new RegExp(\"\\\\\\\\(?:([^u])|u(.{4}))\",\"g\");var g={'\"':'\"',\"/\":\"/\",\"\\\\\":\"\\\\\",b:\"\\b\",f:\"\\f\",n:\"\\n\",r:\"\\r\",t:\"\\t\"};function h(l,m,n){return m?g[m]:String.fromCharCode(parseInt(n,16))}var c=new String(\"\");var a=\"\\\\\";var f={\"{\":Object,\"[\":Array};var b=Object.hasOwnProperty;return function(u,q){var p=u.match(d);var x;var v=p[0];var l=false;if(\"{\"===v){x={}}else{if(\"[\"===v){x=[]}else{x=[];l=true}}var t;var r=[x];for(var o=1-l,m=p.length;o<m;++o){v=p[o];var w;switch(v.charCodeAt(0)){default:w=r[0];w[t||w.length]=+(v);t=void 0;break;case 34:v=v.substring(1,v.length-1);if(v.indexOf(a)!==-1){v=v.replace(k,h)}w=r[0];if(!t){if(w instanceof Array){t=w.length}else{t=v||c;break}}w[t]=v;t=void 0;break;case 91:w=r[0];r.unshift(w[t||w.length]=[]);t=void 0;break;case 93:r.shift();break;case 102:w=r[0];w[t||w.length]=false;t=void 0;break;case 110:w=r[0];w[t||w.length]=null;t=void 0;break;case 116:w=r[0];w[t||w.length]=true;t=void 0;break;case 123:w=r[0];r.unshift(w[t||w.length]={});t=void 0;break;case 125:r.shift();break}}if(l){if(r.length!==1){throw new Error()}x=x[0]}else{if(r.length){throw new Error()}}if(q){var s=function(C,B){var D=C[B];if(D&&typeof D===\"object\"){var n=null;for(var z in D){if(b.call(D,z)&&D!==C){var y=s(D,z);if(y!==void 0){D[z]=y}else{if(!n){n=[]}n.push(z)}}}if(n){for(var A=n.length;--A>=0;){delete D[n[A]]}}}return q.call(C,B,D)};x=s({\"\":x},\"\")}return x}})();\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.asn1==\"undefined\"||!KJUR.asn1){KJUR.asn1={}}KJUR.asn1.ASN1Util=new function(){this.integerToByteHex=function(a){var b=a.toString(16);if((b.length%2)==1){b=\"0\"+b}return b};this.bigIntToMinTwosComplementsHex=function(j){var f=j.toString(16);if(f.substr(0,1)!=\"-\"){if(f.length%2==1){f=\"0\"+f}else{if(!f.match(/^[0-7]/)){f=\"00\"+f}}}else{var a=f.substr(1);var e=a.length;if(e%2==1){e+=1}else{if(!f.match(/^[0-7]/)){e+=2}}var g=\"\";for(var d=0;d<e;d++){g+=\"f\"}var c=new BigInteger(g,16);var b=c.xor(j).add(BigInteger.ONE);f=b.toString(16).replace(/^-/,\"\")}return f};this.getPEMStringFromHex=function(a,b){return hextopem(a,b)};this.newObject=function(k){var D=KJUR,n=D.asn1,z=n.DERBoolean,e=n.DERInteger,s=n.DERBitString,h=n.DEROctetString,v=n.DERNull,w=n.DERObjectIdentifier,l=n.DEREnumerated,g=n.DERUTF8String,f=n.DERNumericString,y=n.DERPrintableString,u=n.DERTeletexString,p=n.DERIA5String,C=n.DERUTCTime,j=n.DERGeneralizedTime,m=n.DERSequence,c=n.DERSet,r=n.DERTaggedObject,o=n.ASN1Util.newObject;var t=Object.keys(k);if(t.length!=1){throw\"key of param shall be only one.\"}var F=t[0];if(\":bool:int:bitstr:octstr:null:oid:enum:utf8str:numstr:prnstr:telstr:ia5str:utctime:gentime:seq:set:tag:\".indexOf(\":\"+F+\":\")==-1){throw\"undefined key: \"+F}if(F==\"bool\"){return new z(k[F])}if(F==\"int\"){return new e(k[F])}if(F==\"bitstr\"){return new s(k[F])}if(F==\"octstr\"){return new h(k[F])}if(F==\"null\"){return new v(k[F])}if(F==\"oid\"){return new w(k[F])}if(F==\"enum\"){return new l(k[F])}if(F==\"utf8str\"){return new g(k[F])}if(F==\"numstr\"){return new f(k[F])}if(F==\"prnstr\"){return new y(k[F])}if(F==\"telstr\"){return new u(k[F])}if(F==\"ia5str\"){return new p(k[F])}if(F==\"utctime\"){return new C(k[F])}if(F==\"gentime\"){return new j(k[F])}if(F==\"seq\"){var d=k[F];var E=[];for(var x=0;x<d.length;x++){var B=o(d[x]);E.push(B)}return new m({array:E})}if(F==\"set\"){var d=k[F];var E=[];for(var x=0;x<d.length;x++){var B=o(d[x]);E.push(B)}return new c({array:E})}if(F==\"tag\"){var A=k[F];if(Object.prototype.toString.call(A)===\"[object Array]\"&&A.length==3){var q=o(A[2]);return new r({tag:A[0],explicit:A[1],obj:q})}else{var b={};if(A.explicit!==undefined){b.explicit=A.explicit}if(A.tag!==undefined){b.tag=A.tag}if(A.obj===undefined){throw\"obj shall be specified for 'tag'.\"}b.obj=o(A.obj);return new r(b)}}};this.jsonToASN1HEX=function(b){var a=this.newObject(b);return a.getEncodedHex()}};KJUR.asn1.ASN1Util.oidHexToInt=function(a){var j=\"\";var k=parseInt(a.substr(0,2),16);var d=Math.floor(k/40);var c=k%40;var j=d+\".\"+c;var e=\"\";for(var f=2;f<a.length;f+=2){var g=parseInt(a.substr(f,2),16);var h=(\"00000000\"+g.toString(2)).slice(-8);e=e+h.substr(1,7);if(h.substr(0,1)==\"0\"){var b=new BigInteger(e,2);j=j+\".\"+b.toString(10);e=\"\"}}return j};KJUR.asn1.ASN1Util.oidIntToHex=function(f){var e=function(a){var k=a.toString(16);if(k.length==1){k=\"0\"+k}return k};var d=function(o){var n=\"\";var k=new BigInteger(o,10);var a=k.toString(2);var l=7-a.length%7;if(l==7){l=0}var q=\"\";for(var m=0;m<l;m++){q+=\"0\"}a=q+a;for(var m=0;m<a.length-1;m+=7){var p=a.substr(m,7);if(m!=a.length-7){p=\"1\"+p}n+=e(parseInt(p,2))}return n};if(!f.match(/^[0-9.]+$/)){throw\"malformed oid string: \"+f}var g=\"\";var b=f.split(\".\");var j=parseInt(b[0])*40+parseInt(b[1]);g+=e(j);b.splice(0,2);for(var c=0;c<b.length;c++){g+=d(b[c])}return g};KJUR.asn1.ASN1Object=function(){var c=true;var b=null;var d=\"00\";var e=\"00\";var a=\"\";this.getLengthHexFromValue=function(){if(typeof this.hV==\"undefined\"||this.hV==null){throw\"this.hV is null or undefined.\"}if(this.hV.length%2==1){throw\"value hex must be even length: n=\"+a.length+\",v=\"+this.hV}var i=this.hV.length/2;var h=i.toString(16);if(h.length%2==1){h=\"0\"+h}if(i<128){return h}else{var g=h.length/2;if(g>15){throw\"ASN.1 length too long to represent by 8x: n = \"+i.toString(16)}var f=128+g;return f.toString(16)+h}};this.getEncodedHex=function(){if(this.hTLV==null||this.isModified){this.hV=this.getFreshValueHex();this.hL=this.getLengthHexFromValue();this.hTLV=this.hT+this.hL+this.hV;this.isModified=false}return this.hTLV};this.getValueHex=function(){this.getEncodedHex();return this.hV};this.getFreshValueHex=function(){return\"\"}};KJUR.asn1.DERAbstractString=function(c){KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var b=null;var a=null;this.getString=function(){return this.s};this.setString=function(d){this.hTLV=null;this.isModified=true;this.s=d;this.hV=utf8tohex(this.s).toLowerCase()};this.setStringHex=function(d){this.hTLV=null;this.isModified=true;this.s=null;this.hV=d};this.getFreshValueHex=function(){return this.hV};if(typeof c!=\"undefined\"){if(typeof c==\"string\"){this.setString(c)}else{if(typeof c.str!=\"undefined\"){this.setString(c.str)}else{if(typeof c.hex!=\"undefined\"){this.setStringHex(c.hex)}}}}};YAHOO.lang.extend(KJUR.asn1.DERAbstractString,KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractTime=function(c){KJUR.asn1.DERAbstractTime.superclass.constructor.call(this);var b=null;var a=null;this.localDateToUTC=function(f){utc=f.getTime()+(f.getTimezoneOffset()*60000);var e=new Date(utc);return e};this.formatDate=function(m,o,e){var g=this.zeroPadding;var n=this.localDateToUTC(m);var p=String(n.getFullYear());if(o==\"utc\"){p=p.substr(2,2)}var l=g(String(n.getMonth()+1),2);var q=g(String(n.getDate()),2);var h=g(String(n.getHours()),2);var i=g(String(n.getMinutes()),2);var j=g(String(n.getSeconds()),2);var r=p+l+q+h+i+j;if(e===true){var f=n.getMilliseconds();if(f!=0){var k=g(String(f),3);k=k.replace(/[0]+$/,\"\");r=r+\".\"+k}}return r+\"Z\"};this.zeroPadding=function(e,d){if(e.length>=d){return e}return new Array(d-e.length+1).join(\"0\")+e};this.getString=function(){return this.s};this.setString=function(d){this.hTLV=null;this.isModified=true;this.s=d;this.hV=stohex(d)};this.setByDateValue=function(h,j,e,d,f,g){var i=new Date(Date.UTC(h,j-1,e,d,f,g,0));this.setByDate(i)};this.getFreshValueHex=function(){return this.hV}};YAHOO.lang.extend(KJUR.asn1.DERAbstractTime,KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractStructured=function(b){KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var a=null;this.setByASN1ObjectArray=function(c){this.hTLV=null;this.isModified=true;this.asn1Array=c};this.appendASN1Object=function(c){this.hTLV=null;this.isModified=true;this.asn1Array.push(c)};this.asn1Array=new Array();if(typeof b!=\"undefined\"){if(typeof b.array!=\"undefined\"){this.asn1Array=b.array}}};YAHOO.lang.extend(KJUR.asn1.DERAbstractStructured,KJUR.asn1.ASN1Object);KJUR.asn1.DERBoolean=function(){KJUR.asn1.DERBoolean.superclass.constructor.call(this);this.hT=\"01\";this.hTLV=\"0101ff\"};YAHOO.lang.extend(KJUR.asn1.DERBoolean,KJUR.asn1.ASN1Object);KJUR.asn1.DERInteger=function(a){KJUR.asn1.DERInteger.superclass.constructor.call(this);this.hT=\"02\";this.setByBigInteger=function(b){this.hTLV=null;this.isModified=true;this.hV=KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b)};this.setByInteger=function(c){var b=new BigInteger(String(c),10);this.setByBigInteger(b)};this.setValueHex=function(b){this.hV=b};this.getFreshValueHex=function(){return this.hV};if(typeof a!=\"undefined\"){if(typeof a.bigint!=\"undefined\"){this.setByBigInteger(a.bigint)}else{if(typeof a[\"int\"]!=\"undefined\"){this.setByInteger(a[\"int\"])}else{if(typeof a==\"number\"){this.setByInteger(a)}else{if(typeof a.hex!=\"undefined\"){this.setValueHex(a.hex)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERInteger,KJUR.asn1.ASN1Object);KJUR.asn1.DERBitString=function(b){if(b!==undefined&&typeof b.obj!==\"undefined\"){var a=KJUR.asn1.ASN1Util.newObject(b.obj);b.hex=\"00\"+a.getEncodedHex()}KJUR.asn1.DERBitString.superclass.constructor.call(this);this.hT=\"03\";this.setHexValueIncludingUnusedBits=function(c){this.hTLV=null;this.isModified=true;this.hV=c};this.setUnusedBitsAndHexValue=function(c,e){if(c<0||7<c){throw\"unused bits shall be from 0 to 7: u = \"+c}var d=\"0\"+c;this.hTLV=null;this.isModified=true;this.hV=d+e};this.setByBinaryString=function(e){e=e.replace(/0+$/,\"\");var f=8-e.length%8;if(f==8){f=0}for(var g=0;g<=f;g++){e+=\"0\"}var j=\"\";for(var g=0;g<e.length-1;g+=8){var d=e.substr(g,8);var c=parseInt(d,2).toString(16);if(c.length==1){c=\"0\"+c}j+=c}this.hTLV=null;this.isModified=true;this.hV=\"0\"+f+j};this.setByBooleanArray=function(e){var d=\"\";for(var c=0;c<e.length;c++){if(e[c]==true){d+=\"1\"}else{d+=\"0\"}}this.setByBinaryString(d)};this.newFalseArray=function(e){var c=new Array(e);for(var d=0;d<e;d++){c[d]=false}return c};this.getFreshValueHex=function(){return this.hV};if(typeof b!=\"undefined\"){if(typeof b==\"string\"&&b.toLowerCase().match(/^[0-9a-f]+$/)){this.setHexValueIncludingUnusedBits(b)}else{if(typeof b.hex!=\"undefined\"){this.setHexValueIncludingUnusedBits(b.hex)}else{if(typeof b.bin!=\"undefined\"){this.setByBinaryString(b.bin)}else{if(typeof b.array!=\"undefined\"){this.setByBooleanArray(b.array)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERBitString,KJUR.asn1.ASN1Object);KJUR.asn1.DEROctetString=function(b){if(b!==undefined&&typeof b.obj!==\"undefined\"){var a=KJUR.asn1.ASN1Util.newObject(b.obj);b.hex=a.getEncodedHex()}KJUR.asn1.DEROctetString.superclass.constructor.call(this,b);this.hT=\"04\"};YAHOO.lang.extend(KJUR.asn1.DEROctetString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERNull=function(){KJUR.asn1.DERNull.superclass.constructor.call(this);this.hT=\"05\";this.hTLV=\"0500\"};YAHOO.lang.extend(KJUR.asn1.DERNull,KJUR.asn1.ASN1Object);KJUR.asn1.DERObjectIdentifier=function(c){var b=function(d){var e=d.toString(16);if(e.length==1){e=\"0\"+e}return e};var a=function(k){var j=\"\";var e=new BigInteger(k,10);var d=e.toString(2);var f=7-d.length%7;if(f==7){f=0}var m=\"\";for(var g=0;g<f;g++){m+=\"0\"}d=m+d;for(var g=0;g<d.length-1;g+=7){var l=d.substr(g,7);if(g!=d.length-7){l=\"1\"+l}j+=b(parseInt(l,2))}return j};KJUR.asn1.DERObjectIdentifier.superclass.constructor.call(this);this.hT=\"06\";this.setValueHex=function(d){this.hTLV=null;this.isModified=true;this.s=null;this.hV=d};this.setValueOidString=function(f){if(!f.match(/^[0-9.]+$/)){throw\"malformed oid string: \"+f}var g=\"\";var d=f.split(\".\");var j=parseInt(d[0])*40+parseInt(d[1]);g+=b(j);d.splice(0,2);for(var e=0;e<d.length;e++){g+=a(d[e])}this.hTLV=null;this.isModified=true;this.s=null;this.hV=g};this.setValueName=function(e){var d=KJUR.asn1.x509.OID.name2oid(e);if(d!==\"\"){this.setValueOidString(d)}else{throw\"DERObjectIdentifier oidName undefined: \"+e}};this.getFreshValueHex=function(){return this.hV};if(c!==undefined){if(typeof c===\"string\"){if(c.match(/^[0-2].[0-9.]+$/)){this.setValueOidString(c)}else{this.setValueName(c)}}else{if(c.oid!==undefined){this.setValueOidString(c.oid)}else{if(c.hex!==undefined){this.setValueHex(c.hex)}else{if(c.name!==undefined){this.setValueName(c.name)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERObjectIdentifier,KJUR.asn1.ASN1Object);KJUR.asn1.DEREnumerated=function(a){KJUR.asn1.DEREnumerated.superclass.constructor.call(this);this.hT=\"0a\";this.setByBigInteger=function(b){this.hTLV=null;this.isModified=true;this.hV=KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b)};this.setByInteger=function(c){var b=new BigInteger(String(c),10);this.setByBigInteger(b)};this.setValueHex=function(b){this.hV=b};this.getFreshValueHex=function(){return this.hV};if(typeof a!=\"undefined\"){if(typeof a[\"int\"]!=\"undefined\"){this.setByInteger(a[\"int\"])}else{if(typeof a==\"number\"){this.setByInteger(a)}else{if(typeof a.hex!=\"undefined\"){this.setValueHex(a.hex)}}}}};YAHOO.lang.extend(KJUR.asn1.DEREnumerated,KJUR.asn1.ASN1Object);KJUR.asn1.DERUTF8String=function(a){KJUR.asn1.DERUTF8String.superclass.constructor.call(this,a);this.hT=\"0c\"};YAHOO.lang.extend(KJUR.asn1.DERUTF8String,KJUR.asn1.DERAbstractString);KJUR.asn1.DERNumericString=function(a){KJUR.asn1.DERNumericString.superclass.constructor.call(this,a);this.hT=\"12\"};YAHOO.lang.extend(KJUR.asn1.DERNumericString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERPrintableString=function(a){KJUR.asn1.DERPrintableString.superclass.constructor.call(this,a);this.hT=\"13\"};YAHOO.lang.extend(KJUR.asn1.DERPrintableString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERTeletexString=function(a){KJUR.asn1.DERTeletexString.superclass.constructor.call(this,a);this.hT=\"14\"};YAHOO.lang.extend(KJUR.asn1.DERTeletexString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERIA5String=function(a){KJUR.asn1.DERIA5String.superclass.constructor.call(this,a);this.hT=\"16\"};YAHOO.lang.extend(KJUR.asn1.DERIA5String,KJUR.asn1.DERAbstractString);KJUR.asn1.DERUTCTime=function(a){KJUR.asn1.DERUTCTime.superclass.constructor.call(this,a);this.hT=\"17\";this.setByDate=function(b){this.hTLV=null;this.isModified=true;this.date=b;this.s=this.formatDate(this.date,\"utc\");this.hV=stohex(this.s)};this.getFreshValueHex=function(){if(typeof this.date==\"undefined\"&&typeof this.s==\"undefined\"){this.date=new Date();this.s=this.formatDate(this.date,\"utc\");this.hV=stohex(this.s)}return this.hV};if(a!==undefined){if(a.str!==undefined){this.setString(a.str)}else{if(typeof a==\"string\"&&a.match(/^[0-9]{12}Z$/)){this.setString(a)}else{if(a.hex!==undefined){this.setStringHex(a.hex)}else{if(a.date!==undefined){this.setByDate(a.date)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERUTCTime,KJUR.asn1.DERAbstractTime);KJUR.asn1.DERGeneralizedTime=function(a){KJUR.asn1.DERGeneralizedTime.superclass.constructor.call(this,a);this.hT=\"18\";this.withMillis=false;this.setByDate=function(b){this.hTLV=null;this.isModified=true;this.date=b;this.s=this.formatDate(this.date,\"gen\",this.withMillis);this.hV=stohex(this.s)};this.getFreshValueHex=function(){if(this.date===undefined&&this.s===undefined){this.date=new Date();this.s=this.formatDate(this.date,\"gen\",this.withMillis);this.hV=stohex(this.s)}return this.hV};if(a!==undefined){if(a.str!==undefined){this.setString(a.str)}else{if(typeof a==\"string\"&&a.match(/^[0-9]{14}Z$/)){this.setString(a)}else{if(a.hex!==undefined){this.setStringHex(a.hex)}else{if(a.date!==undefined){this.setByDate(a.date)}}}}if(a.millis===true){this.withMillis=true}}};YAHOO.lang.extend(KJUR.asn1.DERGeneralizedTime,KJUR.asn1.DERAbstractTime);KJUR.asn1.DERSequence=function(a){KJUR.asn1.DERSequence.superclass.constructor.call(this,a);this.hT=\"30\";this.getFreshValueHex=function(){var c=\"\";for(var b=0;b<this.asn1Array.length;b++){var d=this.asn1Array[b];c+=d.getEncodedHex()}this.hV=c;return this.hV}};YAHOO.lang.extend(KJUR.asn1.DERSequence,KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERSet=function(a){KJUR.asn1.DERSet.superclass.constructor.call(this,a);this.hT=\"31\";this.sortFlag=true;this.getFreshValueHex=function(){var b=new Array();for(var c=0;c<this.asn1Array.length;c++){var d=this.asn1Array[c];b.push(d.getEncodedHex())}if(this.sortFlag==true){b.sort()}this.hV=b.join(\"\");return this.hV};if(typeof a!=\"undefined\"){if(typeof a.sortflag!=\"undefined\"&&a.sortflag==false){this.sortFlag=false}}};YAHOO.lang.extend(KJUR.asn1.DERSet,KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERTaggedObject=function(a){KJUR.asn1.DERTaggedObject.superclass.constructor.call(this);this.hT=\"a0\";this.hV=\"\";this.isExplicit=true;this.asn1Object=null;this.setASN1Object=function(b,c,d){this.hT=c;this.isExplicit=b;this.asn1Object=d;if(this.isExplicit){this.hV=this.asn1Object.getEncodedHex();this.hTLV=null;this.isModified=true}else{this.hV=null;this.hTLV=d.getEncodedHex();this.hTLV=this.hTLV.replace(/^../,c);this.isModified=false}};this.getFreshValueHex=function(){return this.hV};if(typeof a!=\"undefined\"){if(typeof a.tag!=\"undefined\"){this.hT=a.tag}if(typeof a.explicit!=\"undefined\"){this.isExplicit=a.explicit}if(typeof a.obj!=\"undefined\"){this.asn1Object=a.obj;this.setASN1Object(this.isExplicit,this.hT,this.asn1Object)}}};YAHOO.lang.extend(KJUR.asn1.DERTaggedObject,KJUR.asn1.ASN1Object);\nvar ASN1HEX=new function(){};ASN1HEX.getLblen=function(c,a){if(c.substr(a+2,1)!=\"8\"){return 1}var b=parseInt(c.substr(a+3,1));if(b==0){return -1}if(0<b&&b<10){return b+1}return -2};ASN1HEX.getL=function(c,b){var a=ASN1HEX.getLblen(c,b);if(a<1){return\"\"}return c.substr(b+2,a*2)};ASN1HEX.getVblen=function(d,a){var c,b;c=ASN1HEX.getL(d,a);if(c==\"\"){return -1}if(c.substr(0,1)===\"8\"){b=new BigInteger(c.substr(2),16)}else{b=new BigInteger(c,16)}return b.intValue()};ASN1HEX.getVidx=function(c,b){var a=ASN1HEX.getLblen(c,b);if(a<0){return a}return b+(a+1)*2};ASN1HEX.getV=function(d,a){var c=ASN1HEX.getVidx(d,a);var b=ASN1HEX.getVblen(d,a);return d.substr(c,b*2)};ASN1HEX.getTLV=function(b,a){return b.substr(a,2)+ASN1HEX.getL(b,a)+ASN1HEX.getV(b,a)};ASN1HEX.getNextSiblingIdx=function(d,a){var c=ASN1HEX.getVidx(d,a);var b=ASN1HEX.getVblen(d,a);return c+b*2};ASN1HEX.getChildIdx=function(e,f){var j=ASN1HEX;var g=new Array();var i=j.getVidx(e,f);if(e.substr(f,2)==\"03\"){g.push(i+2)}else{g.push(i)}var l=j.getVblen(e,f);var c=i;var d=0;while(1){var b=j.getNextSiblingIdx(e,c);if(b==null||(b-i>=(l*2))){break}if(d>=200){break}g.push(b);c=b;d++}return g};ASN1HEX.getNthChildIdx=function(d,b,e){var c=ASN1HEX.getChildIdx(d,b);return c[e]};ASN1HEX.getIdxbyList=function(e,d,c,i){var g=ASN1HEX;var f,b;if(c.length==0){if(i!==undefined){if(e.substr(d,2)!==i){throw\"checking tag doesn't match: \"+e.substr(d,2)+\"!=\"+i}}return d}f=c.shift();b=g.getChildIdx(e,d);return g.getIdxbyList(e,b[f],c,i)};ASN1HEX.getTLVbyList=function(d,c,b,f){var e=ASN1HEX;var a=e.getIdxbyList(d,c,b);if(a===undefined){throw\"can't find nthList object\"}if(f!==undefined){if(d.substr(a,2)!=f){throw\"checking tag doesn't match: \"+d.substr(a,2)+\"!=\"+f}}return e.getTLV(d,a)};ASN1HEX.getVbyList=function(e,c,b,g,i){var f=ASN1HEX;var a,d;a=f.getIdxbyList(e,c,b,g);if(a===undefined){throw\"can't find nthList object\"}d=f.getV(e,a);if(i===true){d=d.substr(2)}return d};ASN1HEX.hextooidstr=function(e){var h=function(b,a){if(b.length>=a){return b}return new Array(a-b.length+1).join(\"0\")+b};var l=[];var o=e.substr(0,2);var f=parseInt(o,16);l[0]=new String(Math.floor(f/40));l[1]=new String(f%40);var m=e.substr(2);var k=[];for(var g=0;g<m.length/2;g++){k.push(parseInt(m.substr(g*2,2),16))}var j=[];var d=\"\";for(var g=0;g<k.length;g++){if(k[g]&128){d=d+h((k[g]&127).toString(2),7)}else{d=d+h((k[g]&127).toString(2),7);j.push(new String(parseInt(d,2)));d=\"\"}}var n=l.join(\".\");if(j.length>0){n=n+\".\"+j.join(\".\")}return n};ASN1HEX.dump=function(t,c,l,g){var p=ASN1HEX;var j=p.getV;var y=p.dump;var w=p.getChildIdx;var e=t;if(t instanceof KJUR.asn1.ASN1Object){e=t.getEncodedHex()}var q=function(A,i){if(A.length<=i*2){return A}else{var v=A.substr(0,i)+\"..(total \"+A.length/2+\"bytes)..\"+A.substr(A.length-i,i);return v}};if(c===undefined){c={ommit_long_octet:32}}if(l===undefined){l=0}if(g===undefined){g=\"\"}var x=c.ommit_long_octet;if(e.substr(l,2)==\"01\"){var h=j(e,l);if(h==\"00\"){return g+\"BOOLEAN FALSE\\n\"}else{return g+\"BOOLEAN TRUE\\n\"}}if(e.substr(l,2)==\"02\"){var h=j(e,l);return g+\"INTEGER \"+q(h,x)+\"\\n\"}if(e.substr(l,2)==\"03\"){var h=j(e,l);return g+\"BITSTRING \"+q(h,x)+\"\\n\"}if(e.substr(l,2)==\"04\"){var h=j(e,l);if(p.isASN1HEX(h)){var k=g+\"OCTETSTRING, encapsulates\\n\";k=k+y(h,c,0,g+\"  \");return k}else{return g+\"OCTETSTRING \"+q(h,x)+\"\\n\"}}if(e.substr(l,2)==\"05\"){return g+\"NULL\\n\"}if(e.substr(l,2)==\"06\"){var m=j(e,l);var a=KJUR.asn1.ASN1Util.oidHexToInt(m);var o=KJUR.asn1.x509.OID.oid2name(a);var b=a.replace(/\\./g,\" \");if(o!=\"\"){return g+\"ObjectIdentifier \"+o+\" (\"+b+\")\\n\"}else{return g+\"ObjectIdentifier (\"+b+\")\\n\"}}if(e.substr(l,2)==\"0c\"){return g+\"UTF8String '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"13\"){return g+\"PrintableString '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"14\"){return g+\"TeletexString '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"16\"){return g+\"IA5String '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"17\"){return g+\"UTCTime \"+hextoutf8(j(e,l))+\"\\n\"}if(e.substr(l,2)==\"18\"){return g+\"GeneralizedTime \"+hextoutf8(j(e,l))+\"\\n\"}if(e.substr(l,2)==\"30\"){if(e.substr(l,4)==\"3000\"){return g+\"SEQUENCE {}\\n\"}var k=g+\"SEQUENCE\\n\";var d=w(e,l);var f=c;if((d.length==2||d.length==3)&&e.substr(d[0],2)==\"06\"&&e.substr(d[d.length-1],2)==\"04\"){var o=p.oidname(j(e,d[0]));var r=JSON.parse(JSON.stringify(c));r.x509ExtName=o;f=r}for(var u=0;u<d.length;u++){k=k+y(e,f,d[u],g+\"  \")}return k}if(e.substr(l,2)==\"31\"){var k=g+\"SET\\n\";var d=w(e,l);for(var u=0;u<d.length;u++){k=k+y(e,c,d[u],g+\"  \")}return k}var z=parseInt(e.substr(l,2),16);if((z&128)!=0){var n=z&31;if((z&32)!=0){var k=g+\"[\"+n+\"]\\n\";var d=w(e,l);for(var u=0;u<d.length;u++){k=k+y(e,c,d[u],g+\"  \")}return k}else{var h=j(e,l);if(h.substr(0,8)==\"68747470\"){h=hextoutf8(h)}if(c.x509ExtName===\"subjectAltName\"&&n==2){h=hextoutf8(h)}var k=g+\"[\"+n+\"] \"+h+\"\\n\";return k}}return g+\"UNKNOWN(\"+e.substr(l,2)+\") \"+j(e,l)+\"\\n\"};ASN1HEX.isASN1HEX=function(e){var d=ASN1HEX;if(e.length%2==1){return false}var c=d.getVblen(e,0);var b=e.substr(0,2);var f=d.getL(e,0);var a=e.length-b.length-f.length;if(a==c*2){return true}return false};ASN1HEX.oidname=function(a){var c=KJUR.asn1;if(KJUR.lang.String.isHex(a)){a=c.ASN1Util.oidHexToInt(a)}var b=c.x509.OID.oid2name(a);if(b===\"\"){b=a}return b};\nvar KJUR;if(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.lang==\"undefined\"||!KJUR.lang){KJUR.lang={}}KJUR.lang.String=function(){};function Base64x(){}function stoBA(d){var b=new Array();for(var c=0;c<d.length;c++){b[c]=d.charCodeAt(c)}return b}function BAtos(b){var d=\"\";for(var c=0;c<b.length;c++){d=d+String.fromCharCode(b[c])}return d}function BAtohex(b){var e=\"\";for(var d=0;d<b.length;d++){var c=b[d].toString(16);if(c.length==1){c=\"0\"+c}e=e+c}return e}function stohex(a){return BAtohex(stoBA(a))}function stob64(a){return hex2b64(stohex(a))}function stob64u(a){return b64tob64u(hex2b64(stohex(a)))}function b64utos(a){return BAtos(b64toBA(b64utob64(a)))}function b64tob64u(a){a=a.replace(/\\=/g,\"\");a=a.replace(/\\+/g,\"-\");a=a.replace(/\\//g,\"_\");return a}function b64utob64(a){if(a.length%4==2){a=a+\"==\"}else{if(a.length%4==3){a=a+\"=\"}}a=a.replace(/-/g,\"+\");a=a.replace(/_/g,\"/\");return a}function hextob64u(a){if(a.length%2==1){a=\"0\"+a}return b64tob64u(hex2b64(a))}function b64utohex(a){return b64tohex(b64utob64(a))}var utf8tob64u,b64utoutf8;if(typeof Buffer===\"function\"){utf8tob64u=function(a){return b64tob64u(new Buffer(a,\"utf8\").toString(\"base64\"))};b64utoutf8=function(a){return new Buffer(b64utob64(a),\"base64\").toString(\"utf8\")}}else{utf8tob64u=function(a){return hextob64u(uricmptohex(encodeURIComponentAll(a)))};b64utoutf8=function(a){return decodeURIComponent(hextouricmp(b64utohex(a)))}}function utf8tob64(a){return hex2b64(uricmptohex(encodeURIComponentAll(a)))}function b64toutf8(a){return decodeURIComponent(hextouricmp(b64tohex(a)))}function utf8tohex(a){return uricmptohex(encodeURIComponentAll(a))}function hextoutf8(a){return decodeURIComponent(hextouricmp(a))}function hextorstr(c){var b=\"\";for(var a=0;a<c.length-1;a+=2){b+=String.fromCharCode(parseInt(c.substr(a,2),16))}return b}function rstrtohex(c){var a=\"\";for(var b=0;b<c.length;b++){a+=(\"0\"+c.charCodeAt(b).toString(16)).slice(-2)}return a}function hextob64(a){return hex2b64(a)}function hextob64nl(b){var a=hextob64(b);var c=a.replace(/(.{64})/g,\"$1\\r\\n\");c=c.replace(/\\r\\n$/,\"\");return c}function b64nltohex(b){var a=b.replace(/[^0-9A-Za-z\\/+=]*/g,\"\");var c=b64tohex(a);return c}function hextopem(a,b){var c=hextob64nl(a);return\"-----BEGIN \"+b+\"-----\\r\\n\"+c+\"\\r\\n-----END \"+b+\"-----\\r\\n\"}function pemtohex(a,b){if(a.indexOf(\"-----BEGIN \")==-1){throw\"can't find PEM header: \"+b}if(b!==undefined){a=a.replace(\"-----BEGIN \"+b+\"-----\",\"\");a=a.replace(\"-----END \"+b+\"-----\",\"\")}else{a=a.replace(/-----BEGIN [^-]+-----/,\"\");a=a.replace(/-----END [^-]+-----/,\"\")}return b64nltohex(a)}function hextoArrayBuffer(d){if(d.length%2!=0){throw\"input is not even length\"}if(d.match(/^[0-9A-Fa-f]+$/)==null){throw\"input is not hexadecimal\"}var b=new ArrayBuffer(d.length/2);var a=new DataView(b);for(var c=0;c<d.length/2;c++){a.setUint8(c,parseInt(d.substr(c*2,2),16))}return b}function ArrayBuffertohex(b){var d=\"\";var a=new DataView(b);for(var c=0;c<b.byteLength;c++){d+=(\"00\"+a.getUint8(c).toString(16)).slice(-2)}return d}function zulutomsec(n){var l,j,m,e,f,i,b,k;var a,h,g,c;c=n.match(/^(\\d{2}|\\d{4})(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(|\\.\\d+)Z$/);if(c){a=c[1];l=parseInt(a);if(a.length===2){if(50<=l&&l<100){l=1900+l}else{if(0<=l&&l<50){l=2000+l}}}j=parseInt(c[2])-1;m=parseInt(c[3]);e=parseInt(c[4]);f=parseInt(c[5]);i=parseInt(c[6]);b=0;h=c[7];if(h!==\"\"){g=(h.substr(1)+\"00\").substr(0,3);b=parseInt(g)}return Date.UTC(l,j,m,e,f,i,b)}throw\"unsupported zulu format: \"+n}function zulutosec(a){var b=zulutomsec(a);return ~~(b/1000)}function zulutodate(a){return new Date(zulutomsec(a))}function datetozulu(g,e,f){var b;var a=g.getUTCFullYear();if(e){if(a<1950||2049<a){throw\"not proper year for UTCTime: \"+a}b=(\"\"+a).slice(-2)}else{b=(\"000\"+a).slice(-4)}b+=(\"0\"+(g.getUTCMonth()+1)).slice(-2);b+=(\"0\"+g.getUTCDate()).slice(-2);b+=(\"0\"+g.getUTCHours()).slice(-2);b+=(\"0\"+g.getUTCMinutes()).slice(-2);b+=(\"0\"+g.getUTCSeconds()).slice(-2);if(f){var c=g.getUTCMilliseconds();if(c!==0){c=(\"00\"+c).slice(-3);c=c.replace(/0+$/g,\"\");b+=\".\"+c}}b+=\"Z\";return b}function uricmptohex(a){return a.replace(/%/g,\"\")}function hextouricmp(a){return a.replace(/(..)/g,\"%$1\")}function ipv6tohex(g){var b=\"malformed IPv6 address\";if(!g.match(/^[0-9A-Fa-f:]+$/)){throw b}g=g.toLowerCase();var d=g.split(\":\").length-1;if(d<2){throw b}var e=\":\".repeat(7-d+2);g=g.replace(\"::\",e);var c=g.split(\":\");if(c.length!=8){throw b}for(var f=0;f<8;f++){c[f]=(\"0000\"+c[f]).slice(-4)}return c.join(\"\")}function hextoipv6(e){if(!e.match(/^[0-9A-Fa-f]{32}$/)){throw\"malformed IPv6 address octet\"}e=e.toLowerCase();var b=e.match(/.{1,4}/g);for(var d=0;d<8;d++){b[d]=b[d].replace(/^0+/,\"\");if(b[d]==\"\"){b[d]=\"0\"}}e=\":\"+b.join(\":\")+\":\";var c=e.match(/:(0:){2,}/g);if(c===null){return e.slice(1,-1)}var f=\"\";for(var d=0;d<c.length;d++){if(c[d].length>f.length){f=c[d]}}e=e.replace(f,\"::\");return e.slice(1,-1)}function hextoip(b){var d=\"malformed hex value\";if(!b.match(/^([0-9A-Fa-f][0-9A-Fa-f]){1,}$/)){throw d}if(b.length==8){var c;try{c=parseInt(b.substr(0,2),16)+\".\"+parseInt(b.substr(2,2),16)+\".\"+parseInt(b.substr(4,2),16)+\".\"+parseInt(b.substr(6,2),16);return c}catch(a){throw d}}else{if(b.length==32){return hextoipv6(b)}else{return b}}}function iptohex(f){var j=\"malformed IP address\";f=f.toLowerCase(f);if(f.match(/^[0-9.]+$/)){var b=f.split(\".\");if(b.length!==4){throw j}var g=\"\";try{for(var e=0;e<4;e++){var h=parseInt(b[e]);g+=(\"0\"+h.toString(16)).slice(-2)}return g}catch(c){throw j}}else{if(f.match(/^[0-9a-f:]+$/)&&f.indexOf(\":\")!==-1){return ipv6tohex(f)}else{throw j}}}function encodeURIComponentAll(a){var d=encodeURIComponent(a);var b=\"\";for(var c=0;c<d.length;c++){if(d[c]==\"%\"){b=b+d.substr(c,3);c=c+2}else{b=b+\"%\"+stohex(d[c])}}return b}function newline_toUnix(a){a=a.replace(/\\r\\n/mg,\"\\n\");return a}function newline_toDos(a){a=a.replace(/\\r\\n/mg,\"\\n\");a=a.replace(/\\n/mg,\"\\r\\n\");return a}KJUR.lang.String.isInteger=function(a){if(a.match(/^[0-9]+$/)){return true}else{if(a.match(/^-[0-9]+$/)){return true}else{return false}}};KJUR.lang.String.isHex=function(a){if(a.length%2==0&&(a.match(/^[0-9a-f]+$/)||a.match(/^[0-9A-F]+$/))){return true}else{return false}};KJUR.lang.String.isBase64=function(a){a=a.replace(/\\s+/g,\"\");if(a.match(/^[0-9A-Za-z+\\/]+={0,3}$/)&&a.length%4==0){return true}else{return false}};KJUR.lang.String.isBase64URL=function(a){if(a.match(/[+/=]/)){return false}a=b64utob64(a);return KJUR.lang.String.isBase64(a)};KJUR.lang.String.isIntegerArray=function(a){a=a.replace(/\\s+/g,\"\");if(a.match(/^\\[[0-9,]+\\]$/)){return true}else{return false}};function hextoposhex(a){if(a.length%2==1){return\"0\"+a}if(a.substr(0,1)>\"7\"){return\"00\"+a}return a}function intarystrtohex(b){b=b.replace(/^\\s*\\[\\s*/,\"\");b=b.replace(/\\s*\\]\\s*$/,\"\");b=b.replace(/\\s*/g,\"\");try{var c=b.split(/,/).map(function(g,e,h){var f=parseInt(g);if(f<0||255<f){throw\"integer not in range 0-255\"}var d=(\"00\"+f.toString(16)).slice(-2);return d}).join(\"\");return c}catch(a){throw\"malformed integer array string: \"+a}}var strdiffidx=function(c,a){var d=c.length;if(c.length>a.length){d=a.length}for(var b=0;b<d;b++){if(c.charCodeAt(b)!=a.charCodeAt(b)){return b}}if(c.length!=a.length){return d}return -1};\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.crypto==\"undefined\"||!KJUR.crypto){KJUR.crypto={}}KJUR.crypto.Util=new function(){this.DIGESTINFOHEAD={sha1:\"3021300906052b0e03021a05000414\",sha224:\"302d300d06096086480165030402040500041c\",sha256:\"3031300d060960864801650304020105000420\",sha384:\"3041300d060960864801650304020205000430\",sha512:\"3051300d060960864801650304020305000440\",md2:\"3020300c06082a864886f70d020205000410\",md5:\"3020300c06082a864886f70d020505000410\",ripemd160:\"3021300906052b2403020105000414\",};this.DEFAULTPROVIDER={md5:\"cryptojs\",sha1:\"cryptojs\",sha224:\"cryptojs\",sha256:\"cryptojs\",sha384:\"cryptojs\",sha512:\"cryptojs\",ripemd160:\"cryptojs\",hmacmd5:\"cryptojs\",hmacsha1:\"cryptojs\",hmacsha224:\"cryptojs\",hmacsha256:\"cryptojs\",hmacsha384:\"cryptojs\",hmacsha512:\"cryptojs\",hmacripemd160:\"cryptojs\",MD5withRSA:\"cryptojs/jsrsa\",SHA1withRSA:\"cryptojs/jsrsa\",SHA224withRSA:\"cryptojs/jsrsa\",SHA256withRSA:\"cryptojs/jsrsa\",SHA384withRSA:\"cryptojs/jsrsa\",SHA512withRSA:\"cryptojs/jsrsa\",RIPEMD160withRSA:\"cryptojs/jsrsa\",MD5withECDSA:\"cryptojs/jsrsa\",SHA1withECDSA:\"cryptojs/jsrsa\",SHA224withECDSA:\"cryptojs/jsrsa\",SHA256withECDSA:\"cryptojs/jsrsa\",SHA384withECDSA:\"cryptojs/jsrsa\",SHA512withECDSA:\"cryptojs/jsrsa\",RIPEMD160withECDSA:\"cryptojs/jsrsa\",SHA1withDSA:\"cryptojs/jsrsa\",SHA224withDSA:\"cryptojs/jsrsa\",SHA256withDSA:\"cryptojs/jsrsa\",MD5withRSAandMGF1:\"cryptojs/jsrsa\",SHA1withRSAandMGF1:\"cryptojs/jsrsa\",SHA224withRSAandMGF1:\"cryptojs/jsrsa\",SHA256withRSAandMGF1:\"cryptojs/jsrsa\",SHA384withRSAandMGF1:\"cryptojs/jsrsa\",SHA512withRSAandMGF1:\"cryptojs/jsrsa\",RIPEMD160withRSAandMGF1:\"cryptojs/jsrsa\",};this.CRYPTOJSMESSAGEDIGESTNAME={md5:CryptoJS.algo.MD5,sha1:CryptoJS.algo.SHA1,sha224:CryptoJS.algo.SHA224,sha256:CryptoJS.algo.SHA256,sha384:CryptoJS.algo.SHA384,sha512:CryptoJS.algo.SHA512,ripemd160:CryptoJS.algo.RIPEMD160};this.getDigestInfoHex=function(a,b){if(typeof this.DIGESTINFOHEAD[b]==\"undefined\"){throw\"alg not supported in Util.DIGESTINFOHEAD: \"+b}return this.DIGESTINFOHEAD[b]+a};this.getPaddedDigestInfoHex=function(h,a,j){var c=this.getDigestInfoHex(h,a);var d=j/4;if(c.length+22>d){throw\"key is too short for SigAlg: keylen=\"+j+\",\"+a}var b=\"0001\";var k=\"00\"+c;var g=\"\";var l=d-b.length-k.length;for(var f=0;f<l;f+=2){g+=\"ff\"}var e=b+g+k;return e};this.hashString=function(a,c){var b=new KJUR.crypto.MessageDigest({alg:c});return b.digestString(a)};this.hashHex=function(b,c){var a=new KJUR.crypto.MessageDigest({alg:c});return a.digestHex(b)};this.sha1=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha1\",prov:\"cryptojs\"});return b.digestString(a)};this.sha256=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha256\",prov:\"cryptojs\"});return b.digestString(a)};this.sha256Hex=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha256\",prov:\"cryptojs\"});return b.digestHex(a)};this.sha512=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha512\",prov:\"cryptojs\"});return b.digestString(a)};this.sha512Hex=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha512\",prov:\"cryptojs\"});return b.digestHex(a)}};KJUR.crypto.Util.md5=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"md5\",prov:\"cryptojs\"});return b.digestString(a)};KJUR.crypto.Util.ripemd160=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"ripemd160\",prov:\"cryptojs\"});return b.digestString(a)};KJUR.crypto.Util.SECURERANDOMGEN=new SecureRandom();KJUR.crypto.Util.getRandomHexOfNbytes=function(b){var a=new Array(b);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(a);return BAtohex(a)};KJUR.crypto.Util.getRandomBigIntegerOfNbytes=function(a){return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbytes(a),16)};KJUR.crypto.Util.getRandomHexOfNbits=function(d){var c=d%8;var a=(d-c)/8;var b=new Array(a+1);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(b);b[0]=(((255<<c)&255)^255)&b[0];return BAtohex(b)};KJUR.crypto.Util.getRandomBigIntegerOfNbits=function(a){return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbits(a),16)};KJUR.crypto.Util.getRandomBigIntegerZeroToMax=function(b){var a=b.bitLength();while(1){var c=KJUR.crypto.Util.getRandomBigIntegerOfNbits(a);if(b.compareTo(c)!=-1){return c}}};KJUR.crypto.Util.getRandomBigIntegerMinToMax=function(e,b){var c=e.compareTo(b);if(c==1){throw\"biMin is greater than biMax\"}if(c==0){return e}var a=b.subtract(e);var d=KJUR.crypto.Util.getRandomBigIntegerZeroToMax(a);return d.add(e)};KJUR.crypto.MessageDigest=function(c){var b=null;var a=null;var d=null;this.setAlgAndProvider=function(g,f){g=KJUR.crypto.MessageDigest.getCanonicalAlgName(g);if(g!==null&&f===undefined){f=KJUR.crypto.Util.DEFAULTPROVIDER[g]}if(\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g)!=-1&&f==\"cryptojs\"){try{this.md=KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g].create()}catch(e){throw\"setAlgAndProvider hash alg set fail alg=\"+g+\"/\"+e}this.updateString=function(h){this.md.update(h)};this.updateHex=function(h){var i=CryptoJS.enc.Hex.parse(h);this.md.update(i)};this.digest=function(){var h=this.md.finalize();return h.toString(CryptoJS.enc.Hex)};this.digestString=function(h){this.updateString(h);return this.digest()};this.digestHex=function(h){this.updateHex(h);return this.digest()}}if(\":sha256:\".indexOf(g)!=-1&&f==\"sjcl\"){try{this.md=new sjcl.hash.sha256()}catch(e){throw\"setAlgAndProvider hash alg set fail alg=\"+g+\"/\"+e}this.updateString=function(h){this.md.update(h)};this.updateHex=function(i){var h=sjcl.codec.hex.toBits(i);this.md.update(h)};this.digest=function(){var h=this.md.finalize();return sjcl.codec.hex.fromBits(h)};this.digestString=function(h){this.updateString(h);return this.digest()};this.digestHex=function(h){this.updateHex(h);return this.digest()}}};this.updateString=function(e){throw\"updateString(str) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.updateHex=function(e){throw\"updateHex(hex) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.digest=function(){throw\"digest() not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.digestString=function(e){throw\"digestString(str) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.digestHex=function(e){throw\"digestHex(hex) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};if(c!==undefined){if(c.alg!==undefined){this.algName=c.alg;if(c.prov===undefined){this.provName=KJUR.crypto.Util.DEFAULTPROVIDER[this.algName]}this.setAlgAndProvider(this.algName,this.provName)}}};KJUR.crypto.MessageDigest.getCanonicalAlgName=function(a){if(typeof a===\"string\"){a=a.toLowerCase();a=a.replace(/-/,\"\")}return a};KJUR.crypto.MessageDigest.getHashLength=function(c){var b=KJUR.crypto.MessageDigest;var a=b.getCanonicalAlgName(c);if(b.HASHLENGTH[a]===undefined){throw\"not supported algorithm: \"+c}return b.HASHLENGTH[a]};KJUR.crypto.MessageDigest.HASHLENGTH={md5:16,sha1:20,sha224:28,sha256:32,sha384:48,sha512:64,ripemd160:20};KJUR.crypto.Mac=function(d){var f=null;var c=null;var a=null;var e=null;var b=null;this.setAlgAndProvider=function(k,i){k=k.toLowerCase();if(k==null){k=\"hmacsha1\"}k=k.toLowerCase();if(k.substr(0,4)!=\"hmac\"){throw\"setAlgAndProvider unsupported HMAC alg: \"+k}if(i===undefined){i=KJUR.crypto.Util.DEFAULTPROVIDER[k]}this.algProv=k+\"/\"+i;var g=k.substr(4);if(\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g)!=-1&&i==\"cryptojs\"){try{var j=KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g];this.mac=CryptoJS.algo.HMAC.create(j,this.pass)}catch(h){throw\"setAlgAndProvider hash alg set fail hashAlg=\"+g+\"/\"+h}this.updateString=function(l){this.mac.update(l)};this.updateHex=function(l){var m=CryptoJS.enc.Hex.parse(l);this.mac.update(m)};this.doFinal=function(){var l=this.mac.finalize();return l.toString(CryptoJS.enc.Hex)};this.doFinalString=function(l){this.updateString(l);return this.doFinal()};this.doFinalHex=function(l){this.updateHex(l);return this.doFinal()}}};this.updateString=function(g){throw\"updateString(str) not supported for this alg/prov: \"+this.algProv};this.updateHex=function(g){throw\"updateHex(hex) not supported for this alg/prov: \"+this.algProv};this.doFinal=function(){throw\"digest() not supported for this alg/prov: \"+this.algProv};this.doFinalString=function(g){throw\"digestString(str) not supported for this alg/prov: \"+this.algProv};this.doFinalHex=function(g){throw\"digestHex(hex) not supported for this alg/prov: \"+this.algProv};this.setPassword=function(h){if(typeof h==\"string\"){var g=h;if(h.length%2==1||!h.match(/^[0-9A-Fa-f]+$/)){g=rstrtohex(h)}this.pass=CryptoJS.enc.Hex.parse(g);return}if(typeof h!=\"object\"){throw\"KJUR.crypto.Mac unsupported password type: \"+h}var g=null;if(h.hex!==undefined){if(h.hex.length%2!=0||!h.hex.match(/^[0-9A-Fa-f]+$/)){throw\"Mac: wrong hex password: \"+h.hex}g=h.hex}if(h.utf8!==undefined){g=utf8tohex(h.utf8)}if(h.rstr!==undefined){g=rstrtohex(h.rstr)}if(h.b64!==undefined){g=b64tohex(h.b64)}if(h.b64u!==undefined){g=b64utohex(h.b64u)}if(g==null){throw\"KJUR.crypto.Mac unsupported password type: \"+h}this.pass=CryptoJS.enc.Hex.parse(g)};if(d!==undefined){if(d.pass!==undefined){this.setPassword(d.pass)}if(d.alg!==undefined){this.algName=d.alg;if(d.prov===undefined){this.provName=KJUR.crypto.Util.DEFAULTPROVIDER[this.algName]}this.setAlgAndProvider(this.algName,this.provName)}}};KJUR.crypto.Signature=function(o){var q=null;var n=null;var r=null;var c=null;var l=null;var d=null;var k=null;var h=null;var p=null;var e=null;var b=-1;var g=null;var j=null;var a=null;var i=null;var f=null;this._setAlgNames=function(){var s=this.algName.match(/^(.+)with(.+)$/);if(s){this.mdAlgName=s[1].toLowerCase();this.pubkeyAlgName=s[2].toLowerCase()}};this._zeroPaddingOfSignature=function(x,w){var v=\"\";var t=w/4-x.length;for(var u=0;u<t;u++){v=v+\"0\"}return v+x};this.setAlgAndProvider=function(u,t){this._setAlgNames();if(t!=\"cryptojs/jsrsa\"){throw\"provider not supported: \"+t}if(\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(this.mdAlgName)!=-1){try{this.md=new KJUR.crypto.MessageDigest({alg:this.mdAlgName})}catch(s){throw\"setAlgAndProvider hash alg set fail alg=\"+this.mdAlgName+\"/\"+s}this.init=function(w,x){var y=null;try{if(x===undefined){y=KEYUTIL.getKey(w)}else{y=KEYUTIL.getKey(w,x)}}catch(v){throw\"init failed:\"+v}if(y.isPrivate===true){this.prvKey=y;this.state=\"SIGN\"}else{if(y.isPublic===true){this.pubKey=y;this.state=\"VERIFY\"}else{throw\"init failed.:\"+y}}};this.updateString=function(v){this.md.updateString(v)};this.updateHex=function(v){this.md.updateHex(v)};this.sign=function(){this.sHashHex=this.md.digest();if(typeof this.ecprvhex!=\"undefined\"&&typeof this.eccurvename!=\"undefined\"){var v=new KJUR.crypto.ECDSA({curve:this.eccurvename});this.hSign=v.signHex(this.sHashHex,this.ecprvhex)}else{if(this.prvKey instanceof RSAKey&&this.pubkeyAlgName===\"rsaandmgf1\"){this.hSign=this.prvKey.signWithMessageHashPSS(this.sHashHex,this.mdAlgName,this.pssSaltLen)}else{if(this.prvKey instanceof RSAKey&&this.pubkeyAlgName===\"rsa\"){this.hSign=this.prvKey.signWithMessageHash(this.sHashHex,this.mdAlgName)}else{if(this.prvKey instanceof KJUR.crypto.ECDSA){this.hSign=this.prvKey.signWithMessageHash(this.sHashHex)}else{if(this.prvKey instanceof KJUR.crypto.DSA){this.hSign=this.prvKey.signWithMessageHash(this.sHashHex)}else{throw\"Signature: unsupported private key alg: \"+this.pubkeyAlgName}}}}}return this.hSign};this.signString=function(v){this.updateString(v);return this.sign()};this.signHex=function(v){this.updateHex(v);return this.sign()};this.verify=function(v){this.sHashHex=this.md.digest();if(typeof this.ecpubhex!=\"undefined\"&&typeof this.eccurvename!=\"undefined\"){var w=new KJUR.crypto.ECDSA({curve:this.eccurvename});return w.verifyHex(this.sHashHex,v,this.ecpubhex)}else{if(this.pubKey instanceof RSAKey&&this.pubkeyAlgName===\"rsaandmgf1\"){return this.pubKey.verifyWithMessageHashPSS(this.sHashHex,v,this.mdAlgName,this.pssSaltLen)}else{if(this.pubKey instanceof RSAKey&&this.pubkeyAlgName===\"rsa\"){return this.pubKey.verifyWithMessageHash(this.sHashHex,v)}else{if(KJUR.crypto.ECDSA!==undefined&&this.pubKey instanceof KJUR.crypto.ECDSA){return this.pubKey.verifyWithMessageHash(this.sHashHex,v)}else{if(KJUR.crypto.DSA!==undefined&&this.pubKey instanceof KJUR.crypto.DSA){return this.pubKey.verifyWithMessageHash(this.sHashHex,v)}else{throw\"Signature: unsupported public key alg: \"+this.pubkeyAlgName}}}}}}}};this.init=function(s,t){throw\"init(key, pass) not supported for this alg:prov=\"+this.algProvName};this.updateString=function(s){throw\"updateString(str) not supported for this alg:prov=\"+this.algProvName};this.updateHex=function(s){throw\"updateHex(hex) not supported for this alg:prov=\"+this.algProvName};this.sign=function(){throw\"sign() not supported for this alg:prov=\"+this.algProvName};this.signString=function(s){throw\"digestString(str) not supported for this alg:prov=\"+this.algProvName};this.signHex=function(s){throw\"digestHex(hex) not supported for this alg:prov=\"+this.algProvName};this.verify=function(s){throw\"verify(hSigVal) not supported for this alg:prov=\"+this.algProvName};this.initParams=o;if(o!==undefined){if(o.alg!==undefined){this.algName=o.alg;if(o.prov===undefined){this.provName=KJUR.crypto.Util.DEFAULTPROVIDER[this.algName]}else{this.provName=o.prov}this.algProvName=this.algName+\":\"+this.provName;this.setAlgAndProvider(this.algName,this.provName);this._setAlgNames()}if(o.psssaltlen!==undefined){this.pssSaltLen=o.psssaltlen}if(o.prvkeypem!==undefined){if(o.prvkeypas!==undefined){throw\"both prvkeypem and prvkeypas parameters not supported\"}else{try{var q=KEYUTIL.getKey(o.prvkeypem);this.init(q)}catch(m){throw\"fatal error to load pem private key: \"+m}}}}};KJUR.crypto.Cipher=function(a){};KJUR.crypto.Cipher.encrypt=function(e,f,d){if(f instanceof RSAKey&&f.isPublic){var c=KJUR.crypto.Cipher.getAlgByKeyAndName(f,d);if(c===\"RSA\"){return f.encrypt(e)}if(c===\"RSAOAEP\"){return f.encryptOAEP(e,\"sha1\")}var b=c.match(/^RSAOAEP(\\d+)$/);if(b!==null){return f.encryptOAEP(e,\"sha\"+b[1])}throw\"Cipher.encrypt: unsupported algorithm for RSAKey: \"+d}else{throw\"Cipher.encrypt: unsupported key or algorithm\"}};KJUR.crypto.Cipher.decrypt=function(e,f,d){if(f instanceof RSAKey&&f.isPrivate){var c=KJUR.crypto.Cipher.getAlgByKeyAndName(f,d);if(c===\"RSA\"){return f.decrypt(e)}if(c===\"RSAOAEP\"){return f.decryptOAEP(e,\"sha1\")}var b=c.match(/^RSAOAEP(\\d+)$/);if(b!==null){return f.decryptOAEP(e,\"sha\"+b[1])}throw\"Cipher.decrypt: unsupported algorithm for RSAKey: \"+d}else{throw\"Cipher.decrypt: unsupported key or algorithm\"}};KJUR.crypto.Cipher.getAlgByKeyAndName=function(b,a){if(b instanceof RSAKey){if(\":RSA:RSAOAEP:RSAOAEP224:RSAOAEP256:RSAOAEP384:RSAOAEP512:\".indexOf(a)!=-1){return a}if(a===null||a===undefined){return\"RSA\"}throw\"getAlgByKeyAndName: not supported algorithm name for RSAKey: \"+a}throw\"getAlgByKeyAndName: not supported algorithm name: \"+a};KJUR.crypto.OID=new function(){this.oidhex2name={\"2a864886f70d010101\":\"rsaEncryption\",\"2a8648ce3d0201\":\"ecPublicKey\",\"2a8648ce380401\":\"dsa\",\"2a8648ce3d030107\":\"secp256r1\",\"2b8104001f\":\"secp192k1\",\"2b81040021\":\"secp224r1\",\"2b8104000a\":\"secp256k1\",\"2b81040023\":\"secp521r1\",\"2b81040022\":\"secp384r1\",\"2a8648ce380403\":\"SHA1withDSA\",\"608648016503040301\":\"SHA224withDSA\",\"608648016503040302\":\"SHA256withDSA\",}};\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.crypto==\"undefined\"||!KJUR.crypto){KJUR.crypto={}}KJUR.crypto.ECDSA=function(h){var e=\"secp256r1\";var g=null;var b=null;var f=null;var a=new SecureRandom();var d=null;this.type=\"EC\";this.isPrivate=false;this.isPublic=false;function c(s,o,r,n){var j=Math.max(o.bitLength(),n.bitLength());var t=s.add2D(r);var q=s.curve.getInfinity();for(var p=j-1;p>=0;--p){q=q.twice2D();q.z=BigInteger.ONE;if(o.testBit(p)){if(n.testBit(p)){q=q.add2D(t)}else{q=q.add2D(s)}}else{if(n.testBit(p)){q=q.add2D(r)}}}return q}this.getBigRandom=function(i){return new BigInteger(i.bitLength(),a).mod(i.subtract(BigInteger.ONE)).add(BigInteger.ONE)};this.setNamedCurve=function(i){this.ecparams=KJUR.crypto.ECParameterDB.getByName(i);this.prvKeyHex=null;this.pubKeyHex=null;this.curveName=i};this.setPrivateKeyHex=function(i){this.isPrivate=true;this.prvKeyHex=i};this.setPublicKeyHex=function(i){this.isPublic=true;this.pubKeyHex=i};this.getPublicKeyXYHex=function(){var k=this.pubKeyHex;if(k.substr(0,2)!==\"04\"){throw\"this method supports uncompressed format(04) only\"}var j=this.ecparams.keylen/4;if(k.length!==2+j*2){throw\"malformed public key hex length\"}var i={};i.x=k.substr(2,j);i.y=k.substr(2+j);return i};this.getShortNISTPCurveName=function(){var i=this.curveName;if(i===\"secp256r1\"||i===\"NIST P-256\"||i===\"P-256\"||i===\"prime256v1\"){return\"P-256\"}if(i===\"secp384r1\"||i===\"NIST P-384\"||i===\"P-384\"){return\"P-384\"}return null};this.generateKeyPairHex=function(){var k=this.ecparams.n;var n=this.getBigRandom(k);var l=this.ecparams.G.multiply(n);var q=l.getX().toBigInteger();var o=l.getY().toBigInteger();var i=this.ecparams.keylen/4;var m=(\"0000000000\"+n.toString(16)).slice(-i);var r=(\"0000000000\"+q.toString(16)).slice(-i);var p=(\"0000000000\"+o.toString(16)).slice(-i);var j=\"04\"+r+p;this.setPrivateKeyHex(m);this.setPublicKeyHex(j);return{ecprvhex:m,ecpubhex:j}};this.signWithMessageHash=function(i){return this.signHex(i,this.prvKeyHex)};this.signHex=function(o,j){var t=new BigInteger(j,16);var l=this.ecparams.n;var q=new BigInteger(o,16);do{var m=this.getBigRandom(l);var u=this.ecparams.G;var p=u.multiply(m);var i=p.getX().toBigInteger().mod(l)}while(i.compareTo(BigInteger.ZERO)<=0);var v=m.modInverse(l).multiply(q.add(t.multiply(i))).mod(l);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(i,v)};this.sign=function(m,u){var q=u;var j=this.ecparams.n;var p=BigInteger.fromByteArrayUnsigned(m);do{var l=this.getBigRandom(j);var t=this.ecparams.G;var o=t.multiply(l);var i=o.getX().toBigInteger().mod(j)}while(i.compareTo(BigInteger.ZERO)<=0);var v=l.modInverse(j).multiply(p.add(q.multiply(i))).mod(j);return this.serializeSig(i,v)};this.verifyWithMessageHash=function(j,i){return this.verifyHex(j,i,this.pubKeyHex)};this.verifyHex=function(m,i,p){var l,j;var o=KJUR.crypto.ECDSA.parseSigHex(i);l=o.r;j=o.s;var k;k=ECPointFp.decodeFromHex(this.ecparams.curve,p);var n=new BigInteger(m,16);return this.verifyRaw(n,l,j,k)};this.verify=function(o,p,j){var l,i;if(Bitcoin.Util.isArray(p)){var n=this.parseSig(p);l=n.r;i=n.s}else{if(\"object\"===typeof p&&p.r&&p.s){l=p.r;i=p.s}else{throw\"Invalid value for signature\"}}var k;if(j instanceof ECPointFp){k=j}else{if(Bitcoin.Util.isArray(j)){k=ECPointFp.decodeFrom(this.ecparams.curve,j)}else{throw\"Invalid format for pubkey value, must be byte array or ECPointFp\"}}var m=BigInteger.fromByteArrayUnsigned(o);return this.verifyRaw(m,l,i,k)};this.verifyRaw=function(o,i,w,m){var l=this.ecparams.n;var u=this.ecparams.G;if(i.compareTo(BigInteger.ONE)<0||i.compareTo(l)>=0){return false}if(w.compareTo(BigInteger.ONE)<0||w.compareTo(l)>=0){return false}var p=w.modInverse(l);var k=o.multiply(p).mod(l);var j=i.multiply(p).mod(l);var q=u.multiply(k).add(m.multiply(j));var t=q.getX().toBigInteger().mod(l);return t.equals(i)};this.serializeSig=function(k,j){var l=k.toByteArraySigned();var i=j.toByteArraySigned();var m=[];m.push(2);m.push(l.length);m=m.concat(l);m.push(2);m.push(i.length);m=m.concat(i);m.unshift(m.length);m.unshift(48);return m};this.parseSig=function(n){var m;if(n[0]!=48){throw new Error(\"Signature not a valid DERSequence\")}m=2;if(n[m]!=2){throw new Error(\"First element in signature must be a DERInteger\")}var l=n.slice(m+2,m+2+n[m+1]);m+=2+n[m+1];if(n[m]!=2){throw new Error(\"Second element in signature must be a DERInteger\")}var i=n.slice(m+2,m+2+n[m+1]);m+=2+n[m+1];var k=BigInteger.fromByteArrayUnsigned(l);var j=BigInteger.fromByteArrayUnsigned(i);return{r:k,s:j}};this.parseSigCompact=function(m){if(m.length!==65){throw\"Signature has the wrong length\"}var j=m[0]-27;if(j<0||j>7){throw\"Invalid signature type\"}var o=this.ecparams.n;var l=BigInteger.fromByteArrayUnsigned(m.slice(1,33)).mod(o);var k=BigInteger.fromByteArrayUnsigned(m.slice(33,65)).mod(o);return{r:l,s:k,i:j}};this.readPKCS5PrvKeyHex=function(l){var n=ASN1HEX;var m=KJUR.crypto.ECDSA.getName;var p=n.getVbyList;if(n.isASN1HEX(l)===false){throw\"not ASN.1 hex string\"}var i,k,o;try{i=p(l,0,[2,0],\"06\");k=p(l,0,[1],\"04\");try{o=p(l,0,[3,0],\"03\").substr(2)}catch(j){}}catch(j){throw\"malformed PKCS#1/5 plain ECC private key\"}this.curveName=m(i);if(this.curveName===undefined){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(o);this.setPrivateKeyHex(k);this.isPublic=false};this.readPKCS8PrvKeyHex=function(l){var q=ASN1HEX;var i=KJUR.crypto.ECDSA.getName;var n=q.getVbyList;if(q.isASN1HEX(l)===false){throw\"not ASN.1 hex string\"}var j,p,m,k;try{j=n(l,0,[1,0],\"06\");p=n(l,0,[1,1],\"06\");m=n(l,0,[2,0,1],\"04\");try{k=n(l,0,[2,0,2,0],\"03\").substr(2)}catch(o){}}catch(o){throw\"malformed PKCS#8 plain ECC private key\"}this.curveName=i(p);if(this.curveName===undefined){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(k);this.setPrivateKeyHex(m);this.isPublic=false};this.readPKCS8PubKeyHex=function(l){var n=ASN1HEX;var m=KJUR.crypto.ECDSA.getName;var p=n.getVbyList;if(n.isASN1HEX(l)===false){throw\"not ASN.1 hex string\"}var k,i,o;try{k=p(l,0,[0,0],\"06\");i=p(l,0,[0,1],\"06\");o=p(l,0,[1],\"03\").substr(2)}catch(j){throw\"malformed PKCS#8 ECC public key\"}this.curveName=m(i);if(this.curveName===null){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(o)};this.readCertPubKeyHex=function(k,p){if(p!==5){p=6}var m=ASN1HEX;var l=KJUR.crypto.ECDSA.getName;var o=m.getVbyList;if(m.isASN1HEX(k)===false){throw\"not ASN.1 hex string\"}var i,n;try{i=o(k,0,[0,p,0,1],\"06\");n=o(k,0,[0,p,1],\"03\").substr(2)}catch(j){throw\"malformed X.509 certificate ECC public key\"}this.curveName=l(i);if(this.curveName===null){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(n)};if(h!==undefined){if(h.curve!==undefined){this.curveName=h.curve}}if(this.curveName===undefined){this.curveName=e}this.setNamedCurve(this.curveName);if(h!==undefined){if(h.prv!==undefined){this.setPrivateKeyHex(h.prv)}if(h.pub!==undefined){this.setPublicKeyHex(h.pub)}}};KJUR.crypto.ECDSA.parseSigHex=function(a){var b=KJUR.crypto.ECDSA.parseSigHexInHexRS(a);var d=new BigInteger(b.r,16);var c=new BigInteger(b.s,16);return{r:d,s:c}};KJUR.crypto.ECDSA.parseSigHexInHexRS=function(f){var j=ASN1HEX;var i=j.getChildIdx;var g=j.getV;if(f.substr(0,2)!=\"30\"){throw\"signature is not a ASN.1 sequence\"}var h=i(f,0);if(h.length!=2){throw\"number of signature ASN.1 sequence elements seem wrong\"}var e=h[0];var d=h[1];if(f.substr(e,2)!=\"02\"){throw\"1st item of sequene of signature is not ASN.1 integer\"}if(f.substr(d,2)!=\"02\"){throw\"2nd item of sequene of signature is not ASN.1 integer\"}var c=g(f,e);var b=g(f,d);return{r:c,s:b}};KJUR.crypto.ECDSA.asn1SigToConcatSig=function(c){var d=KJUR.crypto.ECDSA.parseSigHexInHexRS(c);var b=d.r;var a=d.s;if(b.substr(0,2)==\"00\"&&(b.length%32)==2){b=b.substr(2)}if(a.substr(0,2)==\"00\"&&(a.length%32)==2){a=a.substr(2)}if((b.length%32)==30){b=\"00\"+b}if((a.length%32)==30){a=\"00\"+a}if(b.length%32!=0){throw\"unknown ECDSA sig r length error\"}if(a.length%32!=0){throw\"unknown ECDSA sig s length error\"}return b+a};KJUR.crypto.ECDSA.concatSigToASN1Sig=function(a){if((((a.length/2)*8)%(16*8))!=0){throw\"unknown ECDSA concatinated r-s sig  length error\"}var c=a.substr(0,a.length/2);var b=a.substr(a.length/2);return KJUR.crypto.ECDSA.hexRSSigToASN1Sig(c,b)};KJUR.crypto.ECDSA.hexRSSigToASN1Sig=function(b,a){var d=new BigInteger(b,16);var c=new BigInteger(a,16);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(d,c)};KJUR.crypto.ECDSA.biRSSigToASN1Sig=function(f,d){var c=KJUR.asn1;var b=new c.DERInteger({bigint:f});var a=new c.DERInteger({bigint:d});var e=new c.DERSequence({array:[b,a]});return e.getEncodedHex()};KJUR.crypto.ECDSA.getName=function(a){if(a===\"2a8648ce3d030107\"){return\"secp256r1\"}if(a===\"2b8104000a\"){return\"secp256k1\"}if(a===\"2b81040022\"){return\"secp384r1\"}if(\"|secp256r1|NIST P-256|P-256|prime256v1|\".indexOf(a)!==-1){return\"secp256r1\"}if(\"|secp256k1|\".indexOf(a)!==-1){return\"secp256k1\"}if(\"|secp384r1|NIST P-384|P-384|\".indexOf(a)!==-1){return\"secp384r1\"}return null};\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.crypto==\"undefined\"||!KJUR.crypto){KJUR.crypto={}}KJUR.crypto.ECParameterDB=new function(){var b={};var c={};function a(d){return new BigInteger(d,16)}this.getByName=function(e){var d=e;if(typeof c[d]!=\"undefined\"){d=c[e]}if(typeof b[d]!=\"undefined\"){return b[d]}throw\"unregistered EC curve name: \"+d};this.regist=function(A,l,o,g,m,e,j,f,k,u,d,x){b[A]={};var s=a(o);var z=a(g);var y=a(m);var t=a(e);var w=a(j);var r=new ECCurveFp(s,z,y);var q=r.decodePointHex(\"04\"+f+k);b[A][\"name\"]=A;b[A][\"keylen\"]=l;b[A][\"curve\"]=r;b[A][\"G\"]=q;b[A][\"n\"]=t;b[A][\"h\"]=w;b[A][\"oid\"]=d;b[A][\"info\"]=x;for(var v=0;v<u.length;v++){c[u[v]]=A}}};KJUR.crypto.ECParameterDB.regist(\"secp128r1\",128,\"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF\",\"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFC\",\"E87579C11079F43DD824993C2CEE5ED3\",\"FFFFFFFE0000000075A30D1B9038A115\",\"1\",\"161FF7528B899B2D0C28607CA52C5B86\",\"CF5AC8395BAFEB13C02DA292DDED7A83\",[],\"\",\"secp128r1 : SECG curve over a 128 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160k1\",160,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73\",\"0\",\"7\",\"0100000000000000000001B8FA16DFAB9ACA16B6B3\",\"1\",\"3B4C382CE37AA192A4019E763036F4F5DD4D7EBB\",\"938CF935318FDCED6BC28286531733C3F03C4FEE\",[],\"\",\"secp160k1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160r1\",160,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFC\",\"1C97BEFC54BD7A8B65ACF89F81D4D4ADC565FA45\",\"0100000000000000000001F4C8F927AED3CA752257\",\"1\",\"4A96B5688EF573284664698968C38BB913CBFC82\",\"23A628553168947D59DCC912042351377AC5FB32\",[],\"\",\"secp160r1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp192k1\",192,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFEE37\",\"0\",\"3\",\"FFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D\",\"1\",\"DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D\",\"9B2F2F6D9C5628A7844163D015BE86344082AA88D95E2F9D\",[]);KJUR.crypto.ECParameterDB.regist(\"secp192r1\",192,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC\",\"64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1\",\"FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831\",\"1\",\"188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012\",\"07192B95FFC8DA78631011ED6B24CDD573F977A11E794811\",[]);KJUR.crypto.ECParameterDB.regist(\"secp224r1\",224,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE\",\"B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D\",\"1\",\"B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21\",\"BD376388B5F723FB4C22DFE6CD4375A05A07476444D5819985007E34\",[]);KJUR.crypto.ECParameterDB.regist(\"secp256k1\",256,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F\",\"0\",\"7\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141\",\"1\",\"79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798\",\"483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8\",[]);KJUR.crypto.ECParameterDB.regist(\"secp256r1\",256,\"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF\",\"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFC\",\"5AC635D8AA3A93E7B3EBBD55769886BC651D06B0CC53B0F63BCE3C3E27D2604B\",\"FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551\",\"1\",\"6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296\",\"4FE342E2FE1A7F9B8EE7EB4A7C0F9E162BCE33576B315ECECBB6406837BF51F5\",[\"NIST P-256\",\"P-256\",\"prime256v1\"]);KJUR.crypto.ECParameterDB.regist(\"secp384r1\",384,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFC\",\"B3312FA7E23EE7E4988E056BE3F82D19181D9C6EFE8141120314088F5013875AC656398D8A2ED19D2A85C8EDD3EC2AEF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973\",\"1\",\"AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7\",\"3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5f\",[\"NIST P-384\",\"P-384\"]);KJUR.crypto.ECParameterDB.regist(\"secp521r1\",521,\"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF\",\"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC\",\"051953EB9618E1C9A1F929A21A0B68540EEA2DA725B99B315F3B8B489918EF109E156193951EC7E937B1652C0BD3BB1BF073573DF883D2C34F1EF451FD46B503F00\",\"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA51868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409\",\"1\",\"C6858E06B70404E9CD9E3ECB662395B4429C648139053FB521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66\",\"011839296a789a3bc0045c8a5fb42c7d1bd998f54449579b446817afbd17273e662c97ee72995ef42640c550b9013fad0761353c7086a272c24088be94769fd16650\",[\"NIST P-521\",\"P-521\"]);\nvar KEYUTIL=function(){var d=function(p,r,q){return k(CryptoJS.AES,p,r,q)};var e=function(p,r,q){return k(CryptoJS.TripleDES,p,r,q)};var a=function(p,r,q){return k(CryptoJS.DES,p,r,q)};var k=function(s,x,u,q){var r=CryptoJS.enc.Hex.parse(x);var w=CryptoJS.enc.Hex.parse(u);var p=CryptoJS.enc.Hex.parse(q);var t={};t.key=w;t.iv=p;t.ciphertext=r;var v=s.decrypt(t,w,{iv:p});return CryptoJS.enc.Hex.stringify(v)};var l=function(p,r,q){return g(CryptoJS.AES,p,r,q)};var o=function(p,r,q){return g(CryptoJS.TripleDES,p,r,q)};var f=function(p,r,q){return g(CryptoJS.DES,p,r,q)};var g=function(t,y,v,q){var s=CryptoJS.enc.Hex.parse(y);var x=CryptoJS.enc.Hex.parse(v);var p=CryptoJS.enc.Hex.parse(q);var w=t.encrypt(s,x,{iv:p});var r=CryptoJS.enc.Hex.parse(w.toString());var u=CryptoJS.enc.Base64.stringify(r);return u};var i={\"AES-256-CBC\":{proc:d,eproc:l,keylen:32,ivlen:16},\"AES-192-CBC\":{proc:d,eproc:l,keylen:24,ivlen:16},\"AES-128-CBC\":{proc:d,eproc:l,keylen:16,ivlen:16},\"DES-EDE3-CBC\":{proc:e,eproc:o,keylen:24,ivlen:8},\"DES-CBC\":{proc:a,eproc:f,keylen:8,ivlen:8}};var c=function(p){return i[p][\"proc\"]};var m=function(p){var r=CryptoJS.lib.WordArray.random(p);var q=CryptoJS.enc.Hex.stringify(r);return q};var n=function(v){var w={};var q=v.match(new RegExp(\"DEK-Info: ([^,]+),([0-9A-Fa-f]+)\",\"m\"));if(q){w.cipher=q[1];w.ivsalt=q[2]}var p=v.match(new RegExp(\"-----BEGIN ([A-Z]+) PRIVATE KEY-----\"));if(p){w.type=p[1]}var u=-1;var x=0;if(v.indexOf(\"\\r\\n\\r\\n\")!=-1){u=v.indexOf(\"\\r\\n\\r\\n\");x=2}if(v.indexOf(\"\\n\\n\")!=-1){u=v.indexOf(\"\\n\\n\");x=1}var t=v.indexOf(\"-----END\");if(u!=-1&&t!=-1){var r=v.substring(u+x*2,t-x);r=r.replace(/\\s+/g,\"\");w.data=r}return w};var j=function(q,y,p){var v=p.substring(0,16);var t=CryptoJS.enc.Hex.parse(v);var r=CryptoJS.enc.Utf8.parse(y);var u=i[q][\"keylen\"]+i[q][\"ivlen\"];var x=\"\";var w=null;for(;;){var s=CryptoJS.algo.MD5.create();if(w!=null){s.update(w)}s.update(r);s.update(t);w=s.finalize();x=x+CryptoJS.enc.Hex.stringify(w);if(x.length>=u*2){break}}var z={};z.keyhex=x.substr(0,i[q][\"keylen\"]*2);z.ivhex=x.substr(i[q][\"keylen\"]*2,i[q][\"ivlen\"]*2);return z};var b=function(p,v,r,w){var s=CryptoJS.enc.Base64.parse(p);var q=CryptoJS.enc.Hex.stringify(s);var u=i[v][\"proc\"];var t=u(q,r,w);return t};var h=function(p,s,q,u){var r=i[s][\"eproc\"];var t=r(p,q,u);return t};return{version:\"1.0.0\",parsePKCS5PEM:function(p){return n(p)},getKeyAndUnusedIvByPasscodeAndIvsalt:function(q,p,r){return j(q,p,r)},decryptKeyB64:function(p,r,q,s){return b(p,r,q,s)},getDecryptedKeyHex:function(y,x){var q=n(y);var t=q.type;var r=q.cipher;var p=q.ivsalt;var s=q.data;var w=j(r,x,p);var v=w.keyhex;var u=b(s,r,v,p);return u},getEncryptedPKCS5PEMFromPrvKeyHex:function(x,s,A,t,r){var p=\"\";if(typeof t==\"undefined\"||t==null){t=\"AES-256-CBC\"}if(typeof i[t]==\"undefined\"){throw\"KEYUTIL unsupported algorithm: \"+t}if(typeof r==\"undefined\"||r==null){var v=i[t][\"ivlen\"];var u=m(v);r=u.toUpperCase()}var z=j(t,A,r);var y=z.keyhex;var w=h(s,t,y,r);var q=w.replace(/(.{64})/g,\"$1\\r\\n\");var p=\"-----BEGIN \"+x+\" PRIVATE KEY-----\\r\\n\";p+=\"Proc-Type: 4,ENCRYPTED\\r\\n\";p+=\"DEK-Info: \"+t+\",\"+r+\"\\r\\n\";p+=\"\\r\\n\";p+=q;p+=\"\\r\\n-----END \"+x+\" PRIVATE KEY-----\\r\\n\";return p},parseHexOfEncryptedPKCS8:function(y){var B=ASN1HEX;var z=B.getChildIdx;var w=B.getV;var t={};var r=z(y,0);if(r.length!=2){throw\"malformed format: SEQUENCE(0).items != 2: \"+r.length}t.ciphertext=w(y,r[1]);var A=z(y,r[0]);if(A.length!=2){throw\"malformed format: SEQUENCE(0.0).items != 2: \"+A.length}if(w(y,A[0])!=\"2a864886f70d01050d\"){throw\"this only supports pkcs5PBES2\"}var p=z(y,A[1]);if(A.length!=2){throw\"malformed format: SEQUENCE(0.0.1).items != 2: \"+p.length}var q=z(y,p[1]);if(q.length!=2){throw\"malformed format: SEQUENCE(0.0.1.1).items != 2: \"+q.length}if(w(y,q[0])!=\"2a864886f70d0307\"){throw\"this only supports TripleDES\"}t.encryptionSchemeAlg=\"TripleDES\";t.encryptionSchemeIV=w(y,q[1]);var s=z(y,p[0]);if(s.length!=2){throw\"malformed format: SEQUENCE(0.0.1.0).items != 2: \"+s.length}if(w(y,s[0])!=\"2a864886f70d01050c\"){throw\"this only supports pkcs5PBKDF2\"}var x=z(y,s[1]);if(x.length<2){throw\"malformed format: SEQUENCE(0.0.1.0.1).items < 2: \"+x.length}t.pbkdf2Salt=w(y,x[0]);var u=w(y,x[1]);try{t.pbkdf2Iter=parseInt(u,16)}catch(v){throw\"malformed format pbkdf2Iter: \"+u}return t},getPBKDF2KeyHexFromParam:function(u,p){var t=CryptoJS.enc.Hex.parse(u.pbkdf2Salt);var q=u.pbkdf2Iter;var s=CryptoJS.PBKDF2(p,t,{keySize:192/32,iterations:q});var r=CryptoJS.enc.Hex.stringify(s);return r},_getPlainPKCS8HexFromEncryptedPKCS8PEM:function(x,y){var r=pemtohex(x,\"ENCRYPTED PRIVATE KEY\");var p=this.parseHexOfEncryptedPKCS8(r);var u=KEYUTIL.getPBKDF2KeyHexFromParam(p,y);var v={};v.ciphertext=CryptoJS.enc.Hex.parse(p.ciphertext);var t=CryptoJS.enc.Hex.parse(u);var s=CryptoJS.enc.Hex.parse(p.encryptionSchemeIV);var w=CryptoJS.TripleDES.decrypt(v,t,{iv:s});var q=CryptoJS.enc.Hex.stringify(w);return q},getKeyFromEncryptedPKCS8PEM:function(s,q){var p=this._getPlainPKCS8HexFromEncryptedPKCS8PEM(s,q);var r=this.getKeyFromPlainPrivatePKCS8Hex(p);return r},parsePlainPrivatePKCS8Hex:function(s){var v=ASN1HEX;var u=v.getChildIdx;var t=v.getV;var q={};q.algparam=null;if(s.substr(0,2)!=\"30\"){throw\"malformed plain PKCS8 private key(code:001)\"}var r=u(s,0);if(r.length!=3){throw\"malformed plain PKCS8 private key(code:002)\"}if(s.substr(r[1],2)!=\"30\"){throw\"malformed PKCS8 private key(code:003)\"}var p=u(s,r[1]);if(p.length!=2){throw\"malformed PKCS8 private key(code:004)\"}if(s.substr(p[0],2)!=\"06\"){throw\"malformed PKCS8 private key(code:005)\"}q.algoid=t(s,p[0]);if(s.substr(p[1],2)==\"06\"){q.algparam=t(s,p[1])}if(s.substr(r[2],2)!=\"04\"){throw\"malformed PKCS8 private key(code:006)\"}q.keyidx=v.getVidx(s,r[2]);return q},getKeyFromPlainPrivatePKCS8PEM:function(q){var p=pemtohex(q,\"PRIVATE KEY\");var r=this.getKeyFromPlainPrivatePKCS8Hex(p);return r},getKeyFromPlainPrivatePKCS8Hex:function(p){var q=this.parsePlainPrivatePKCS8Hex(p);var r;if(q.algoid==\"2a864886f70d010101\"){r=new RSAKey()}else{if(q.algoid==\"2a8648ce380401\"){r=new KJUR.crypto.DSA()}else{if(q.algoid==\"2a8648ce3d0201\"){r=new KJUR.crypto.ECDSA()}else{throw\"unsupported private key algorithm\"}}}r.readPKCS8PrvKeyHex(p);return r},_getKeyFromPublicPKCS8Hex:function(q){var p;var r=ASN1HEX.getVbyList(q,0,[0,0],\"06\");if(r===\"2a864886f70d010101\"){p=new RSAKey()}else{if(r===\"2a8648ce380401\"){p=new KJUR.crypto.DSA()}else{if(r===\"2a8648ce3d0201\"){p=new KJUR.crypto.ECDSA()}else{throw\"unsupported PKCS#8 public key hex\"}}}p.readPKCS8PubKeyHex(q);return p},parsePublicRawRSAKeyHex:function(r){var u=ASN1HEX;var t=u.getChildIdx;var s=u.getV;var p={};if(r.substr(0,2)!=\"30\"){throw\"malformed RSA key(code:001)\"}var q=t(r,0);if(q.length!=2){throw\"malformed RSA key(code:002)\"}if(r.substr(q[0],2)!=\"02\"){throw\"malformed RSA key(code:003)\"}p.n=s(r,q[0]);if(r.substr(q[1],2)!=\"02\"){throw\"malformed RSA key(code:004)\"}p.e=s(r,q[1]);return p},parsePublicPKCS8Hex:function(t){var v=ASN1HEX;var u=v.getChildIdx;var s=v.getV;var q={};q.algparam=null;var r=u(t,0);if(r.length!=2){throw\"outer DERSequence shall have 2 elements: \"+r.length}var w=r[0];if(t.substr(w,2)!=\"30\"){throw\"malformed PKCS8 public key(code:001)\"}var p=u(t,w);if(p.length!=2){throw\"malformed PKCS8 public key(code:002)\"}if(t.substr(p[0],2)!=\"06\"){throw\"malformed PKCS8 public key(code:003)\"}q.algoid=s(t,p[0]);if(t.substr(p[1],2)==\"06\"){q.algparam=s(t,p[1])}else{if(t.substr(p[1],2)==\"30\"){q.algparam={};q.algparam.p=v.getVbyList(t,p[1],[0],\"02\");q.algparam.q=v.getVbyList(t,p[1],[1],\"02\");q.algparam.g=v.getVbyList(t,p[1],[2],\"02\")}}if(t.substr(r[1],2)!=\"03\"){throw\"malformed PKCS8 public key(code:004)\"}q.key=s(t,r[1]).substr(2);return q},}}();KEYUTIL.getKey=function(l,k,n){var G=ASN1HEX,L=G.getChildIdx,v=G.getV,d=G.getVbyList,c=KJUR.crypto,i=c.ECDSA,C=c.DSA,w=RSAKey,M=pemtohex,F=KEYUTIL;if(typeof w!=\"undefined\"&&l instanceof w){return l}if(typeof i!=\"undefined\"&&l instanceof i){return l}if(typeof C!=\"undefined\"&&l instanceof C){return l}if(l.curve!==undefined&&l.xy!==undefined&&l.d===undefined){return new i({pub:l.xy,curve:l.curve})}if(l.curve!==undefined&&l.d!==undefined){return new i({prv:l.d,curve:l.curve})}if(l.kty===undefined&&l.n!==undefined&&l.e!==undefined&&l.d===undefined){var P=new w();P.setPublic(l.n,l.e);return P}if(l.kty===undefined&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined&&l.p!==undefined&&l.q!==undefined&&l.dp!==undefined&&l.dq!==undefined&&l.co!==undefined&&l.qi===undefined){var P=new w();P.setPrivateEx(l.n,l.e,l.d,l.p,l.q,l.dp,l.dq,l.co);return P}if(l.kty===undefined&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined&&l.p===undefined){var P=new w();P.setPrivate(l.n,l.e,l.d);return P}if(l.p!==undefined&&l.q!==undefined&&l.g!==undefined&&l.y!==undefined&&l.x===undefined){var P=new C();P.setPublic(l.p,l.q,l.g,l.y);return P}if(l.p!==undefined&&l.q!==undefined&&l.g!==undefined&&l.y!==undefined&&l.x!==undefined){var P=new C();P.setPrivate(l.p,l.q,l.g,l.y,l.x);return P}if(l.kty===\"RSA\"&&l.n!==undefined&&l.e!==undefined&&l.d===undefined){var P=new w();P.setPublic(b64utohex(l.n),b64utohex(l.e));return P}if(l.kty===\"RSA\"&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined&&l.p!==undefined&&l.q!==undefined&&l.dp!==undefined&&l.dq!==undefined&&l.qi!==undefined){var P=new w();P.setPrivateEx(b64utohex(l.n),b64utohex(l.e),b64utohex(l.d),b64utohex(l.p),b64utohex(l.q),b64utohex(l.dp),b64utohex(l.dq),b64utohex(l.qi));return P}if(l.kty===\"RSA\"&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined){var P=new w();P.setPrivate(b64utohex(l.n),b64utohex(l.e),b64utohex(l.d));return P}if(l.kty===\"EC\"&&l.crv!==undefined&&l.x!==undefined&&l.y!==undefined&&l.d===undefined){var j=new i({curve:l.crv});var t=j.ecparams.keylen/4;var B=(\"0000000000\"+b64utohex(l.x)).slice(-t);var z=(\"0000000000\"+b64utohex(l.y)).slice(-t);var u=\"04\"+B+z;j.setPublicKeyHex(u);return j}if(l.kty===\"EC\"&&l.crv!==undefined&&l.x!==undefined&&l.y!==undefined&&l.d!==undefined){var j=new i({curve:l.crv});var t=j.ecparams.keylen/4;var B=(\"0000000000\"+b64utohex(l.x)).slice(-t);var z=(\"0000000000\"+b64utohex(l.y)).slice(-t);var u=\"04\"+B+z;var b=(\"0000000000\"+b64utohex(l.d)).slice(-t);j.setPublicKeyHex(u);j.setPrivateKeyHex(b);return j}if(n===\"pkcs5prv\"){var J=l,G=ASN1HEX,N,P;N=L(J,0);if(N.length===9){P=new w();P.readPKCS5PrvKeyHex(J)}else{if(N.length===6){P=new C();P.readPKCS5PrvKeyHex(J)}else{if(N.length>2&&J.substr(N[1],2)===\"04\"){P=new i();P.readPKCS5PrvKeyHex(J)}else{throw\"unsupported PKCS#1/5 hexadecimal key\"}}}return P}if(n===\"pkcs8prv\"){var P=F.getKeyFromPlainPrivatePKCS8Hex(l);return P}if(n===\"pkcs8pub\"){return F._getKeyFromPublicPKCS8Hex(l)}if(n===\"x509pub\"){return X509.getPublicKeyFromCertHex(l)}if(l.indexOf(\"-END CERTIFICATE-\",0)!=-1||l.indexOf(\"-END X509 CERTIFICATE-\",0)!=-1||l.indexOf(\"-END TRUSTED CERTIFICATE-\",0)!=-1){return X509.getPublicKeyFromCertPEM(l)}if(l.indexOf(\"-END PUBLIC KEY-\")!=-1){var O=pemtohex(l,\"PUBLIC KEY\");return F._getKeyFromPublicPKCS8Hex(O)}if(l.indexOf(\"-END RSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")==-1){var m=M(l,\"RSA PRIVATE KEY\");return F.getKey(m,null,\"pkcs5prv\")}if(l.indexOf(\"-END DSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")==-1){var I=M(l,\"DSA PRIVATE KEY\");var E=d(I,0,[1],\"02\");var D=d(I,0,[2],\"02\");var K=d(I,0,[3],\"02\");var r=d(I,0,[4],\"02\");var s=d(I,0,[5],\"02\");var P=new C();P.setPrivate(new BigInteger(E,16),new BigInteger(D,16),new BigInteger(K,16),new BigInteger(r,16),new BigInteger(s,16));return P}if(l.indexOf(\"-END PRIVATE KEY-\")!=-1){return F.getKeyFromPlainPrivatePKCS8PEM(l)}if(l.indexOf(\"-END RSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")!=-1){var o=F.getDecryptedKeyHex(l,k);var H=new RSAKey();H.readPKCS5PrvKeyHex(o);return H}if(l.indexOf(\"-END EC PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")!=-1){var I=F.getDecryptedKeyHex(l,k);var P=d(I,0,[1],\"04\");var f=d(I,0,[2,0],\"06\");var A=d(I,0,[3,0],\"03\").substr(2);var e=\"\";if(KJUR.crypto.OID.oidhex2name[f]!==undefined){e=KJUR.crypto.OID.oidhex2name[f]}else{throw\"undefined OID(hex) in KJUR.crypto.OID: \"+f}var j=new i({curve:e});j.setPublicKeyHex(A);j.setPrivateKeyHex(P);j.isPublic=false;return j}if(l.indexOf(\"-END DSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")!=-1){var I=F.getDecryptedKeyHex(l,k);var E=d(I,0,[1],\"02\");var D=d(I,0,[2],\"02\");var K=d(I,0,[3],\"02\");var r=d(I,0,[4],\"02\");var s=d(I,0,[5],\"02\");var P=new C();P.setPrivate(new BigInteger(E,16),new BigInteger(D,16),new BigInteger(K,16),new BigInteger(r,16),new BigInteger(s,16));return P}if(l.indexOf(\"-END ENCRYPTED PRIVATE KEY-\")!=-1){return F.getKeyFromEncryptedPKCS8PEM(l,k)}throw\"not supported argument\"};KEYUTIL.generateKeypair=function(a,c){if(a==\"RSA\"){var b=c;var h=new RSAKey();h.generate(b,\"10001\");h.isPrivate=true;h.isPublic=true;var f=new RSAKey();var e=h.n.toString(16);var i=h.e.toString(16);f.setPublic(e,i);f.isPrivate=false;f.isPublic=true;var k={};k.prvKeyObj=h;k.pubKeyObj=f;return k}else{if(a==\"EC\"){var d=c;var g=new KJUR.crypto.ECDSA({curve:d});var j=g.generateKeyPairHex();var h=new KJUR.crypto.ECDSA({curve:d});h.setPublicKeyHex(j.ecpubhex);h.setPrivateKeyHex(j.ecprvhex);h.isPrivate=true;h.isPublic=false;var f=new KJUR.crypto.ECDSA({curve:d});f.setPublicKeyHex(j.ecpubhex);f.isPrivate=false;f.isPublic=true;var k={};k.prvKeyObj=h;k.pubKeyObj=f;return k}else{throw\"unknown algorithm: \"+a}}};KEYUTIL.getPEM=function(b,D,y,m,q,j){var F=KJUR,k=F.asn1,z=k.DERObjectIdentifier,f=k.DERInteger,l=k.ASN1Util.newObject,a=k.x509,C=a.SubjectPublicKeyInfo,e=F.crypto,u=e.DSA,r=e.ECDSA,n=RSAKey;function A(s){var G=l({seq:[{\"int\":0},{\"int\":{bigint:s.n}},{\"int\":s.e},{\"int\":{bigint:s.d}},{\"int\":{bigint:s.p}},{\"int\":{bigint:s.q}},{\"int\":{bigint:s.dmp1}},{\"int\":{bigint:s.dmq1}},{\"int\":{bigint:s.coeff}}]});return G}function B(G){var s=l({seq:[{\"int\":1},{octstr:{hex:G.prvKeyHex}},{tag:[\"a0\",true,{oid:{name:G.curveName}}]},{tag:[\"a1\",true,{bitstr:{hex:\"00\"+G.pubKeyHex}}]}]});return s}function x(s){var G=l({seq:[{\"int\":0},{\"int\":{bigint:s.p}},{\"int\":{bigint:s.q}},{\"int\":{bigint:s.g}},{\"int\":{bigint:s.y}},{\"int\":{bigint:s.x}}]});return G}if(((n!==undefined&&b instanceof n)||(u!==undefined&&b instanceof u)||(r!==undefined&&b instanceof r))&&b.isPublic==true&&(D===undefined||D==\"PKCS8PUB\")){var E=new C(b);var w=E.getEncodedHex();return hextopem(w,\"PUBLIC KEY\")}if(D==\"PKCS1PRV\"&&n!==undefined&&b instanceof n&&(y===undefined||y==null)&&b.isPrivate==true){var E=A(b);var w=E.getEncodedHex();return hextopem(w,\"RSA PRIVATE KEY\")}if(D==\"PKCS1PRV\"&&r!==undefined&&b instanceof r&&(y===undefined||y==null)&&b.isPrivate==true){var i=new z({name:b.curveName});var v=i.getEncodedHex();var h=B(b);var t=h.getEncodedHex();var p=\"\";p+=hextopem(v,\"EC PARAMETERS\");p+=hextopem(t,\"EC PRIVATE KEY\");return p}if(D==\"PKCS1PRV\"&&u!==undefined&&b instanceof u&&(y===undefined||y==null)&&b.isPrivate==true){var E=x(b);var w=E.getEncodedHex();return hextopem(w,\"DSA PRIVATE KEY\")}if(D==\"PKCS5PRV\"&&n!==undefined&&b instanceof n&&(y!==undefined&&y!=null)&&b.isPrivate==true){var E=A(b);var w=E.getEncodedHex();if(m===undefined){m=\"DES-EDE3-CBC\"}return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"RSA\",w,y,m,j)}if(D==\"PKCS5PRV\"&&r!==undefined&&b instanceof r&&(y!==undefined&&y!=null)&&b.isPrivate==true){var E=B(b);var w=E.getEncodedHex();if(m===undefined){m=\"DES-EDE3-CBC\"}return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"EC\",w,y,m,j)}if(D==\"PKCS5PRV\"&&u!==undefined&&b instanceof u&&(y!==undefined&&y!=null)&&b.isPrivate==true){var E=x(b);var w=E.getEncodedHex();if(m===undefined){m=\"DES-EDE3-CBC\"}return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"DSA\",w,y,m,j)}var o=function(G,s){var I=c(G,s);var H=new l({seq:[{seq:[{oid:{name:\"pkcs5PBES2\"}},{seq:[{seq:[{oid:{name:\"pkcs5PBKDF2\"}},{seq:[{octstr:{hex:I.pbkdf2Salt}},{\"int\":I.pbkdf2Iter}]}]},{seq:[{oid:{name:\"des-EDE3-CBC\"}},{octstr:{hex:I.encryptionSchemeIV}}]}]}]},{octstr:{hex:I.ciphertext}}]});return H.getEncodedHex()};var c=function(N,O){var H=100;var M=CryptoJS.lib.WordArray.random(8);var L=\"DES-EDE3-CBC\";var s=CryptoJS.lib.WordArray.random(8);var I=CryptoJS.PBKDF2(O,M,{keySize:192/32,iterations:H});var J=CryptoJS.enc.Hex.parse(N);var K=CryptoJS.TripleDES.encrypt(J,I,{iv:s})+\"\";var G={};G.ciphertext=K;G.pbkdf2Salt=CryptoJS.enc.Hex.stringify(M);G.pbkdf2Iter=H;G.encryptionSchemeAlg=L;G.encryptionSchemeIV=CryptoJS.enc.Hex.stringify(s);return G};if(D==\"PKCS8PRV\"&&n!=undefined&&b instanceof n&&b.isPrivate==true){var g=A(b);var d=g.getEncodedHex();var E=l({seq:[{\"int\":0},{seq:[{oid:{name:\"rsaEncryption\"}},{\"null\":true}]},{octstr:{hex:d}}]});var w=E.getEncodedHex();if(y===undefined||y==null){return hextopem(w,\"PRIVATE KEY\")}else{var t=o(w,y);return hextopem(t,\"ENCRYPTED PRIVATE KEY\")}}if(D==\"PKCS8PRV\"&&r!==undefined&&b instanceof r&&b.isPrivate==true){var g=new l({seq:[{\"int\":1},{octstr:{hex:b.prvKeyHex}},{tag:[\"a1\",true,{bitstr:{hex:\"00\"+b.pubKeyHex}}]}]});var d=g.getEncodedHex();var E=l({seq:[{\"int\":0},{seq:[{oid:{name:\"ecPublicKey\"}},{oid:{name:b.curveName}}]},{octstr:{hex:d}}]});var w=E.getEncodedHex();if(y===undefined||y==null){return hextopem(w,\"PRIVATE KEY\")}else{var t=o(w,y);return hextopem(t,\"ENCRYPTED PRIVATE KEY\")}}if(D==\"PKCS8PRV\"&&u!==undefined&&b instanceof u&&b.isPrivate==true){var g=new f({bigint:b.x});var d=g.getEncodedHex();var E=l({seq:[{\"int\":0},{seq:[{oid:{name:\"dsa\"}},{seq:[{\"int\":{bigint:b.p}},{\"int\":{bigint:b.q}},{\"int\":{bigint:b.g}}]}]},{octstr:{hex:d}}]});var w=E.getEncodedHex();if(y===undefined||y==null){return hextopem(w,\"PRIVATE KEY\")}else{var t=o(w,y);return hextopem(t,\"ENCRYPTED PRIVATE KEY\")}}throw\"unsupported object nor format\"};KEYUTIL.getKeyFromCSRPEM=function(b){var a=pemtohex(b,\"CERTIFICATE REQUEST\");var c=KEYUTIL.getKeyFromCSRHex(a);return c};KEYUTIL.getKeyFromCSRHex=function(a){var c=KEYUTIL.parseCSRHex(a);var b=KEYUTIL.getKey(c.p8pubkeyhex,null,\"pkcs8pub\");return b};KEYUTIL.parseCSRHex=function(d){var i=ASN1HEX;var f=i.getChildIdx;var c=i.getTLV;var b={};var g=d;if(g.substr(0,2)!=\"30\"){throw\"malformed CSR(code:001)\"}var e=f(g,0);if(e.length<1){throw\"malformed CSR(code:002)\"}if(g.substr(e[0],2)!=\"30\"){throw\"malformed CSR(code:003)\"}var a=f(g,e[0]);if(a.length<3){throw\"malformed CSR(code:004)\"}b.p8pubkeyhex=c(g,a[2]);return b};KEYUTIL.getJWKFromKey=function(d){var b={};if(d instanceof RSAKey&&d.isPrivate){b.kty=\"RSA\";b.n=hextob64u(d.n.toString(16));b.e=hextob64u(d.e.toString(16));b.d=hextob64u(d.d.toString(16));b.p=hextob64u(d.p.toString(16));b.q=hextob64u(d.q.toString(16));b.dp=hextob64u(d.dmp1.toString(16));b.dq=hextob64u(d.dmq1.toString(16));b.qi=hextob64u(d.coeff.toString(16));return b}else{if(d instanceof RSAKey&&d.isPublic){b.kty=\"RSA\";b.n=hextob64u(d.n.toString(16));b.e=hextob64u(d.e.toString(16));return b}else{if(d instanceof KJUR.crypto.ECDSA&&d.isPrivate){var a=d.getShortNISTPCurveName();if(a!==\"P-256\"&&a!==\"P-384\"){throw\"unsupported curve name for JWT: \"+a}var c=d.getPublicKeyXYHex();b.kty=\"EC\";b.crv=a;b.x=hextob64u(c.x);b.y=hextob64u(c.y);b.d=hextob64u(d.prvKeyHex);return b}else{if(d instanceof KJUR.crypto.ECDSA&&d.isPublic){var a=d.getShortNISTPCurveName();if(a!==\"P-256\"&&a!==\"P-384\"){throw\"unsupported curve name for JWT: \"+a}var c=d.getPublicKeyXYHex();b.kty=\"EC\";b.crv=a;b.x=hextob64u(c.x);b.y=hextob64u(c.y);return b}}}}throw\"not supported key object\"};\nRSAKey.getPosArrayOfChildrenFromHex=function(a){return ASN1HEX.getChildIdx(a,0)};RSAKey.getHexValueArrayOfChildrenFromHex=function(f){var n=ASN1HEX;var i=n.getV;var k=RSAKey.getPosArrayOfChildrenFromHex(f);var e=i(f,k[0]);var j=i(f,k[1]);var b=i(f,k[2]);var c=i(f,k[3]);var h=i(f,k[4]);var g=i(f,k[5]);var m=i(f,k[6]);var l=i(f,k[7]);var d=i(f,k[8]);var k=new Array();k.push(e,j,b,c,h,g,m,l,d);return k};RSAKey.prototype.readPrivateKeyFromPEMString=function(d){var c=pemtohex(d);var b=RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1],b[2],b[3],b[4],b[5],b[6],b[7],b[8])};RSAKey.prototype.readPKCS5PrvKeyHex=function(c){var b=RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1],b[2],b[3],b[4],b[5],b[6],b[7],b[8])};RSAKey.prototype.readPKCS8PrvKeyHex=function(e){var c,j,l,b,a,f,d,k;var m=ASN1HEX;var g=m.getVbyList;if(m.isASN1HEX(e)===false){throw\"not ASN.1 hex string\"}try{c=g(e,0,[2,0,1],\"02\");j=g(e,0,[2,0,2],\"02\");l=g(e,0,[2,0,3],\"02\");b=g(e,0,[2,0,4],\"02\");a=g(e,0,[2,0,5],\"02\");f=g(e,0,[2,0,6],\"02\");d=g(e,0,[2,0,7],\"02\");k=g(e,0,[2,0,8],\"02\")}catch(i){throw\"malformed PKCS#8 plain RSA private key\"}this.setPrivateEx(c,j,l,b,a,f,d,k)};RSAKey.prototype.readPKCS5PubKeyHex=function(c){var e=ASN1HEX;var b=e.getV;if(e.isASN1HEX(c)===false){throw\"keyHex is not ASN.1 hex string\"}var a=e.getChildIdx(c,0);if(a.length!==2||c.substr(a[0],2)!==\"02\"||c.substr(a[1],2)!==\"02\"){throw\"wrong hex for PKCS#5 public key\"}var f=b(c,a[0]);var d=b(c,a[1]);this.setPublic(f,d)};RSAKey.prototype.readPKCS8PubKeyHex=function(b){var c=ASN1HEX;if(c.isASN1HEX(b)===false){throw\"not ASN.1 hex string\"}if(c.getTLVbyList(b,0,[0,0])!==\"06092a864886f70d010101\"){throw\"not PKCS8 RSA public key\"}var a=c.getTLVbyList(b,0,[1,0]);this.readPKCS5PubKeyHex(a)};RSAKey.prototype.readCertPubKeyHex=function(b,d){var a,c;a=new X509();a.readCertHex(b);c=a.getPublicKeyHex();this.readPKCS8PubKeyHex(c)};\nvar _RE_HEXDECONLY=new RegExp(\"\");_RE_HEXDECONLY.compile(\"[^0-9a-f]\",\"gi\");function _rsasign_getHexPaddedDigestInfoForString(d,e,a){var b=function(f){return KJUR.crypto.Util.hashString(f,a)};var c=b(d);return KJUR.crypto.Util.getPaddedDigestInfoHex(c,a,e)}function _zeroPaddingOfSignature(e,d){var c=\"\";var a=d/4-e.length;for(var b=0;b<a;b++){c=c+\"0\"}return c+e}RSAKey.prototype.sign=function(d,a){var b=function(e){return KJUR.crypto.Util.hashString(e,a)};var c=b(d);return this.signWithMessageHash(c,a)};RSAKey.prototype.signWithMessageHash=function(e,c){var f=KJUR.crypto.Util.getPaddedDigestInfoHex(e,c,this.n.bitLength());var b=parseBigInt(f,16);var d=this.doPrivate(b);var a=d.toString(16);return _zeroPaddingOfSignature(a,this.n.bitLength())};function pss_mgf1_str(c,a,e){var b=\"\",d=0;while(b.length<a){b+=hextorstr(e(rstrtohex(c+String.fromCharCode.apply(String,[(d&4278190080)>>24,(d&16711680)>>16,(d&65280)>>8,d&255]))));d+=1}return b}RSAKey.prototype.signPSS=function(e,a,d){var c=function(f){return KJUR.crypto.Util.hashHex(f,a)};var b=c(rstrtohex(e));if(d===undefined){d=-1}return this.signWithMessageHashPSS(b,a,d)};RSAKey.prototype.signWithMessageHashPSS=function(l,a,k){var b=hextorstr(l);var g=b.length;var m=this.n.bitLength()-1;var c=Math.ceil(m/8);var d;var o=function(i){return KJUR.crypto.Util.hashHex(i,a)};if(k===-1||k===undefined){k=g}else{if(k===-2){k=c-g-2}else{if(k<-2){throw\"invalid salt length\"}}}if(c<(g+k+2)){throw\"data too long\"}var f=\"\";if(k>0){f=new Array(k);new SecureRandom().nextBytes(f);f=String.fromCharCode.apply(String,f)}var n=hextorstr(o(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"+b+f)));var j=[];for(d=0;d<c-k-g-2;d+=1){j[d]=0}var e=String.fromCharCode.apply(String,j)+\"\\x01\"+f;var h=pss_mgf1_str(n,e.length,o);var q=[];for(d=0;d<e.length;d+=1){q[d]=e.charCodeAt(d)^h.charCodeAt(d)}var p=(65280>>(8*c-m))&255;q[0]&=~p;for(d=0;d<g;d++){q.push(n.charCodeAt(d))}q.push(188);return _zeroPaddingOfSignature(this.doPrivate(new BigInteger(q)).toString(16),this.n.bitLength())};function _rsasign_getDecryptSignatureBI(a,d,c){var b=new RSAKey();b.setPublic(d,c);var e=b.doPublic(a);return e}function _rsasign_getHexDigestInfoFromSig(a,c,b){var e=_rsasign_getDecryptSignatureBI(a,c,b);var d=e.toString(16).replace(/^1f+00/,\"\");return d}function _rsasign_getAlgNameAndHashFromHexDisgestInfo(f){for(var e in KJUR.crypto.Util.DIGESTINFOHEAD){var d=KJUR.crypto.Util.DIGESTINFOHEAD[e];var b=d.length;if(f.substring(0,b)==d){var c=[e,f.substring(b)];return c}}return[]}RSAKey.prototype.verify=function(f,j){j=j.replace(_RE_HEXDECONLY,\"\");j=j.replace(/[ \\n]+/g,\"\");var b=parseBigInt(j,16);if(b.bitLength()>this.n.bitLength()){return 0}var i=this.doPublic(b);var e=i.toString(16).replace(/^1f+00/,\"\");var g=_rsasign_getAlgNameAndHashFromHexDisgestInfo(e);if(g.length==0){return false}var d=g[0];var h=g[1];var a=function(k){return KJUR.crypto.Util.hashString(k,d)};var c=a(f);return(h==c)};RSAKey.prototype.verifyWithMessageHash=function(e,a){a=a.replace(_RE_HEXDECONLY,\"\");a=a.replace(/[ \\n]+/g,\"\");var b=parseBigInt(a,16);if(b.bitLength()>this.n.bitLength()){return 0}var h=this.doPublic(b);var g=h.toString(16).replace(/^1f+00/,\"\");var c=_rsasign_getAlgNameAndHashFromHexDisgestInfo(g);if(c.length==0){return false}var d=c[0];var f=c[1];return(f==e)};RSAKey.prototype.verifyPSS=function(c,b,a,f){var e=function(g){return KJUR.crypto.Util.hashHex(g,a)};var d=e(rstrtohex(c));if(f===undefined){f=-1}return this.verifyWithMessageHashPSS(d,b,a,f)};RSAKey.prototype.verifyWithMessageHashPSS=function(f,s,l,c){var k=new BigInteger(s,16);if(k.bitLength()>this.n.bitLength()){return false}var r=function(i){return KJUR.crypto.Util.hashHex(i,l)};var j=hextorstr(f);var h=j.length;var g=this.n.bitLength()-1;var m=Math.ceil(g/8);var q;if(c===-1||c===undefined){c=h}else{if(c===-2){c=m-h-2}else{if(c<-2){throw\"invalid salt length\"}}}if(m<(h+c+2)){throw\"data too long\"}var a=this.doPublic(k).toByteArray();for(q=0;q<a.length;q+=1){a[q]&=255}while(a.length<m){a.unshift(0)}if(a[m-1]!==188){throw\"encoded message does not end in 0xbc\"}a=String.fromCharCode.apply(String,a);var d=a.substr(0,m-h-1);var e=a.substr(d.length,h);var p=(65280>>(8*m-g))&255;if((d.charCodeAt(0)&p)!==0){throw\"bits beyond keysize not zero\"}var n=pss_mgf1_str(e,d.length,r);var o=[];for(q=0;q<d.length;q+=1){o[q]=d.charCodeAt(q)^n.charCodeAt(q)}o[0]&=~p;var b=m-h-c-2;for(q=0;q<b;q+=1){if(o[q]!==0){throw\"leftmost octets not zero\"}}if(o[b]!==1){throw\"0x01 marker not found\"}return e===hextorstr(r(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"+j+String.fromCharCode.apply(String,o.slice(-c)))))};RSAKey.SALT_LEN_HLEN=-1;RSAKey.SALT_LEN_MAX=-2;RSAKey.SALT_LEN_RECOVER=-2;\nfunction X509(){var k=ASN1HEX,j=k.getChildIdx,h=k.getV,b=k.getTLV,f=k.getVbyList,c=k.getTLVbyList,g=k.getIdxbyList,d=k.getVidx,i=k.oidname,a=X509,e=pemtohex;this.hex=null;this.version=0;this.foffset=0;this.aExtInfo=null;this.getVersion=function(){if(this.hex===null||this.version!==0){return this.version}if(c(this.hex,0,[0,0])!==\"a003020102\"){this.version=1;this.foffset=-1;return 1}this.version=3;return 3};this.getSerialNumberHex=function(){return f(this.hex,0,[0,1+this.foffset],\"02\")};this.getSignatureAlgorithmField=function(){return i(f(this.hex,0,[0,2+this.foffset,0],\"06\"))};this.getIssuerHex=function(){return c(this.hex,0,[0,3+this.foffset],\"30\")};this.getIssuerString=function(){return a.hex2dn(this.getIssuerHex())};this.getSubjectHex=function(){return c(this.hex,0,[0,5+this.foffset],\"30\")};this.getSubjectString=function(){return a.hex2dn(this.getSubjectHex())};this.getNotBefore=function(){var l=f(this.hex,0,[0,4+this.foffset,0]);l=l.replace(/(..)/g,\"%$1\");l=decodeURIComponent(l);return l};this.getNotAfter=function(){var l=f(this.hex,0,[0,4+this.foffset,1]);l=l.replace(/(..)/g,\"%$1\");l=decodeURIComponent(l);return l};this.getPublicKeyHex=function(){return k.getTLVbyList(this.hex,0,[0,6+this.foffset],\"30\")};this.getPublicKeyIdx=function(){return g(this.hex,0,[0,6+this.foffset],\"30\")};this.getPublicKeyContentIdx=function(){var l=this.getPublicKeyIdx();return g(this.hex,l,[1,0],\"30\")};this.getPublicKey=function(){return KEYUTIL.getKey(this.getPublicKeyHex(),null,\"pkcs8pub\")};this.getSignatureAlgorithmName=function(){return i(f(this.hex,0,[1,0],\"06\"))};this.getSignatureValueHex=function(){return f(this.hex,0,[2],\"03\",true)};this.verifySignature=function(n){var o=this.getSignatureAlgorithmName();var l=this.getSignatureValueHex();var m=c(this.hex,0,[0],\"30\");var p=new KJUR.crypto.Signature({alg:o});p.init(n);p.updateHex(m);return p.verify(l)};this.parseExt=function(){if(this.version!==3){return -1}var p=g(this.hex,0,[0,7,0],\"30\");var m=j(this.hex,p);this.aExtInfo=new Array();for(var n=0;n<m.length;n++){var q={};q.critical=false;var l=j(this.hex,m[n]);var r=0;if(l.length===3){q.critical=true;r=1}q.oid=k.hextooidstr(f(this.hex,m[n],[0],\"06\"));var o=g(this.hex,m[n],[1+r]);q.vidx=d(this.hex,o);this.aExtInfo.push(q)}};this.getExtInfo=function(n){var l=this.aExtInfo;var o=n;if(!n.match(/^[0-9.]+$/)){o=KJUR.asn1.x509.OID.name2oid(n)}if(o===\"\"){return undefined}for(var m=0;m<l.length;m++){if(l[m].oid===o){return l[m]}}return undefined};this.getExtBasicConstraints=function(){var n=this.getExtInfo(\"basicConstraints\");if(n===undefined){return n}var l=h(this.hex,n.vidx);if(l===\"\"){return{}}if(l===\"0101ff\"){return{cA:true}}if(l.substr(0,8)===\"0101ff02\"){var o=h(l,6);var m=parseInt(o,16);return{cA:true,pathLen:m}}throw\"basicConstraints parse error\"};this.getExtKeyUsageBin=function(){var o=this.getExtInfo(\"keyUsage\");if(o===undefined){return\"\"}var m=h(this.hex,o.vidx);if(m.length%2!=0||m.length<=2){throw\"malformed key usage value\"}var l=parseInt(m.substr(0,2));var n=parseInt(m.substr(2),16).toString(2);return n.substr(0,n.length-l)};this.getExtKeyUsageString=function(){var n=this.getExtKeyUsageBin();var l=new Array();for(var m=0;m<n.length;m++){if(n.substr(m,1)==\"1\"){l.push(X509.KEYUSAGE_NAME[m])}}return l.join(\",\")};this.getExtSubjectKeyIdentifier=function(){var l=this.getExtInfo(\"subjectKeyIdentifier\");if(l===undefined){return l}return h(this.hex,l.vidx)};this.getExtAuthorityKeyIdentifier=function(){var p=this.getExtInfo(\"authorityKeyIdentifier\");if(p===undefined){return p}var l={};var o=b(this.hex,p.vidx);var m=j(o,0);for(var n=0;n<m.length;n++){if(o.substr(m[n],2)===\"80\"){l.kid=h(o,m[n])}}return l};this.getExtExtKeyUsageName=function(){var p=this.getExtInfo(\"extKeyUsage\");if(p===undefined){return p}var l=new Array();var o=b(this.hex,p.vidx);if(o===\"\"){return l}var m=j(o,0);for(var n=0;n<m.length;n++){l.push(i(h(o,m[n])))}return l};this.getExtSubjectAltName=function(){var m=this.getExtSubjectAltName2();var l=new Array();for(var n=0;n<m.length;n++){if(m[n][0]===\"DNS\"){l.push(m[n][1])}}return l};this.getExtSubjectAltName2=function(){var p,s,r;var q=this.getExtInfo(\"subjectAltName\");if(q===undefined){return q}var l=new Array();var o=b(this.hex,q.vidx);var m=j(o,0);for(var n=0;n<m.length;n++){r=o.substr(m[n],2);p=h(o,m[n]);if(r===\"81\"){s=hextoutf8(p);l.push([\"MAIL\",s])}if(r===\"82\"){s=hextoutf8(p);l.push([\"DNS\",s])}if(r===\"84\"){s=X509.hex2dn(p,0);l.push([\"DN\",s])}if(r===\"86\"){s=hextoutf8(p);l.push([\"URI\",s])}if(r===\"87\"){s=hextoip(p);l.push([\"IP\",s])}}return l};this.getExtCRLDistributionPointsURI=function(){var q=this.getExtInfo(\"cRLDistributionPoints\");if(q===undefined){return q}var l=new Array();var m=j(this.hex,q.vidx);for(var o=0;o<m.length;o++){try{var r=f(this.hex,m[o],[0,0,0],\"86\");var p=hextoutf8(r);l.push(p)}catch(n){}}return l};this.getExtAIAInfo=function(){var p=this.getExtInfo(\"authorityInfoAccess\");if(p===undefined){return p}var l={ocsp:[],caissuer:[]};var m=j(this.hex,p.vidx);for(var n=0;n<m.length;n++){var q=f(this.hex,m[n],[0],\"06\");var o=f(this.hex,m[n],[1],\"86\");if(q===\"2b06010505073001\"){l.ocsp.push(hextoutf8(o))}if(q===\"2b06010505073002\"){l.caissuer.push(hextoutf8(o))}}return l};this.getExtCertificatePolicies=function(){var o=this.getExtInfo(\"certificatePolicies\");if(o===undefined){return o}var l=b(this.hex,o.vidx);var u=[];var s=j(l,0);for(var r=0;r<s.length;r++){var t={};var n=j(l,s[r]);t.id=i(h(l,n[0]));if(n.length===2){var m=j(l,n[1]);for(var q=0;q<m.length;q++){var p=f(l,m[q],[0],\"06\");if(p===\"2b06010505070201\"){t.cps=hextoutf8(f(l,m[q],[1]))}else{if(p===\"2b06010505070202\"){t.unotice=hextoutf8(f(l,m[q],[1,0]))}}}}u.push(t)}return u};this.readCertPEM=function(l){this.readCertHex(e(l))};this.readCertHex=function(l){this.hex=l;this.getVersion();try{g(this.hex,0,[0,7],\"a3\");this.parseExt()}catch(m){}};this.getInfo=function(){var m=X509;var B,u,z;B=\"Basic Fields\\n\";B+=\"  serial number: \"+this.getSerialNumberHex()+\"\\n\";B+=\"  signature algorithm: \"+this.getSignatureAlgorithmField()+\"\\n\";B+=\"  issuer: \"+this.getIssuerString()+\"\\n\";B+=\"  notBefore: \"+this.getNotBefore()+\"\\n\";B+=\"  notAfter: \"+this.getNotAfter()+\"\\n\";B+=\"  subject: \"+this.getSubjectString()+\"\\n\";B+=\"  subject public key info: \\n\";u=this.getPublicKey();B+=\"    key algorithm: \"+u.type+\"\\n\";if(u.type===\"RSA\"){B+=\"    n=\"+hextoposhex(u.n.toString(16)).substr(0,16)+\"...\\n\";B+=\"    e=\"+hextoposhex(u.e.toString(16))+\"\\n\"}z=this.aExtInfo;if(z!==undefined&&z!==null){B+=\"X509v3 Extensions:\\n\";for(var r=0;r<z.length;r++){var n=z[r];var A=KJUR.asn1.x509.OID.oid2name(n.oid);if(A===\"\"){A=n.oid}var x=\"\";if(n.critical===true){x=\"CRITICAL\"}B+=\"  \"+A+\" \"+x+\":\\n\";if(A===\"basicConstraints\"){var v=this.getExtBasicConstraints();if(v.cA===undefined){B+=\"    {}\\n\"}else{B+=\"    cA=true\";if(v.pathLen!==undefined){B+=\", pathLen=\"+v.pathLen}B+=\"\\n\"}}else{if(A===\"keyUsage\"){B+=\"    \"+this.getExtKeyUsageString()+\"\\n\"}else{if(A===\"subjectKeyIdentifier\"){B+=\"    \"+this.getExtSubjectKeyIdentifier()+\"\\n\"}else{if(A===\"authorityKeyIdentifier\"){var l=this.getExtAuthorityKeyIdentifier();if(l.kid!==undefined){B+=\"    kid=\"+l.kid+\"\\n\"}}else{if(A===\"extKeyUsage\"){var w=this.getExtExtKeyUsageName();B+=\"    \"+w.join(\", \")+\"\\n\"}else{if(A===\"subjectAltName\"){var t=this.getExtSubjectAltName2();B+=\"    \"+t+\"\\n\"}else{if(A===\"cRLDistributionPoints\"){var y=this.getExtCRLDistributionPointsURI();B+=\"    \"+y+\"\\n\"}else{if(A===\"authorityInfoAccess\"){var p=this.getExtAIAInfo();if(p.ocsp!==undefined){B+=\"    ocsp: \"+p.ocsp.join(\",\")+\"\\n\"}if(p.caissuer!==undefined){B+=\"    caissuer: \"+p.caissuer.join(\",\")+\"\\n\"}}else{if(A===\"certificatePolicies\"){var o=this.getExtCertificatePolicies();for(var q=0;q<o.length;q++){if(o[q].id!==undefined){B+=\"    policy oid: \"+o[q].id+\"\\n\"}if(o[q].cps!==undefined){B+=\"    cps: \"+o[q].cps+\"\\n\"}}}}}}}}}}}}}B+=\"signature algorithm: \"+this.getSignatureAlgorithmName()+\"\\n\";B+=\"signature: \"+this.getSignatureValueHex().substr(0,16)+\"...\\n\";return B}}X509.hex2dn=function(f,b){if(b===undefined){b=0}if(f.substr(b,2)!==\"30\"){throw\"malformed DN\"}var c=new Array();var d=ASN1HEX.getChildIdx(f,b);for(var e=0;e<d.length;e++){c.push(X509.hex2rdn(f,d[e]))}c=c.map(function(a){return a.replace(\"/\",\"\\\\/\")});return\"/\"+c.join(\"/\")};X509.hex2rdn=function(f,b){if(b===undefined){b=0}if(f.substr(b,2)!==\"31\"){throw\"malformed RDN\"}var c=new Array();var d=ASN1HEX.getChildIdx(f,b);for(var e=0;e<d.length;e++){c.push(X509.hex2attrTypeValue(f,d[e]))}c=c.map(function(a){return a.replace(\"+\",\"\\\\+\")});return c.join(\"+\")};X509.hex2attrTypeValue=function(d,i){var j=ASN1HEX;var h=j.getV;if(i===undefined){i=0}if(d.substr(i,2)!==\"30\"){throw\"malformed attribute type and value\"}var g=j.getChildIdx(d,i);if(g.length!==2||d.substr(g[0],2)!==\"06\"){\"malformed attribute type and value\"}var b=h(d,g[0]);var f=KJUR.asn1.ASN1Util.oidHexToInt(b);var e=KJUR.asn1.x509.OID.oid2atype(f);var a=h(d,g[1]);var c=hextorstr(a);return e+\"=\"+c};X509.getPublicKeyFromCertHex=function(b){var a=new X509();a.readCertHex(b);return a.getPublicKey()};X509.getPublicKeyFromCertPEM=function(b){var a=new X509();a.readCertPEM(b);return a.getPublicKey()};X509.getPublicKeyInfoPropOfCertPEM=function(c){var e=ASN1HEX;var g=e.getVbyList;var b={};var a,f,d;b.algparam=null;a=new X509();a.readCertPEM(c);f=a.getPublicKeyHex();b.keyhex=g(f,0,[1],\"03\").substr(2);b.algoid=g(f,0,[0,0],\"06\");if(b.algoid===\"2a8648ce3d0201\"){b.algparam=g(f,0,[0,1],\"06\")}return b};X509.KEYUSAGE_NAME=[\"digitalSignature\",\"nonRepudiation\",\"keyEncipherment\",\"dataEncipherment\",\"keyAgreement\",\"keyCertSign\",\"cRLSign\",\"encipherOnly\",\"decipherOnly\"];\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.jws==\"undefined\"||!KJUR.jws){KJUR.jws={}}KJUR.jws.JWS=function(){var b=KJUR,a=b.jws.JWS,c=a.isSafeJSONString;this.parseJWS=function(g,j){if((this.parsedJWS!==undefined)&&(j||(this.parsedJWS.sigvalH!==undefined))){return}var i=g.match(/^([^.]+)\\.([^.]+)\\.([^.]+)$/);if(i==null){throw\"JWS signature is not a form of 'Head.Payload.SigValue'.\"}var k=i[1];var e=i[2];var l=i[3];var n=k+\".\"+e;this.parsedJWS={};this.parsedJWS.headB64U=k;this.parsedJWS.payloadB64U=e;this.parsedJWS.sigvalB64U=l;this.parsedJWS.si=n;if(!j){var h=b64utohex(l);var f=parseBigInt(h,16);this.parsedJWS.sigvalH=h;this.parsedJWS.sigvalBI=f}var d=b64utoutf8(k);var m=b64utoutf8(e);this.parsedJWS.headS=d;this.parsedJWS.payloadS=m;if(!c(d,this.parsedJWS,\"headP\")){throw\"malformed JSON string for JWS Head: \"+d}}};KJUR.jws.JWS.sign=function(i,v,y,z,a){var w=KJUR,m=w.jws,q=m.JWS,g=q.readSafeJSONString,p=q.isSafeJSONString,d=w.crypto,k=d.ECDSA,o=d.Mac,c=d.Signature,t=JSON;var s,j,n;if(typeof v!=\"string\"&&typeof v!=\"object\"){throw\"spHeader must be JSON string or object: \"+v}if(typeof v==\"object\"){j=v;s=t.stringify(j)}if(typeof v==\"string\"){s=v;if(!p(s)){throw\"JWS Head is not safe JSON string: \"+s}j=g(s)}n=y;if(typeof y==\"object\"){n=t.stringify(y)}if((i==\"\"||i==null)&&j.alg!==undefined){i=j.alg}if((i!=\"\"&&i!=null)&&j.alg===undefined){j.alg=i;s=t.stringify(j)}if(i!==j.alg){throw\"alg and sHeader.alg doesn't match: \"+i+\"!=\"+j.alg}var r=null;if(q.jwsalg2sigalg[i]===undefined){throw\"unsupported alg name: \"+i}else{r=q.jwsalg2sigalg[i]}var e=utf8tob64u(s);var l=utf8tob64u(n);var b=e+\".\"+l;var x=\"\";if(r.substr(0,4)==\"Hmac\"){if(z===undefined){throw\"mac key shall be specified for HS* alg\"}var h=new o({alg:r,prov:\"cryptojs\",pass:z});h.updateString(b);x=h.doFinal()}else{if(r.indexOf(\"withECDSA\")!=-1){var f=new c({alg:r});f.init(z,a);f.updateString(b);hASN1Sig=f.sign();x=KJUR.crypto.ECDSA.asn1SigToConcatSig(hASN1Sig)}else{if(r!=\"none\"){var f=new c({alg:r});f.init(z,a);f.updateString(b);x=f.sign()}}}var u=hextob64u(x);return b+\".\"+u};KJUR.jws.JWS.verify=function(w,B,n){var x=KJUR,q=x.jws,t=q.JWS,i=t.readSafeJSONString,e=x.crypto,p=e.ECDSA,s=e.Mac,d=e.Signature,m;if(typeof RSAKey!==undefined){m=RSAKey}var y=w.split(\".\");if(y.length!==3){return false}var f=y[0];var r=y[1];var c=f+\".\"+r;var A=b64utohex(y[2]);var l=i(b64utoutf8(y[0]));var k=null;var z=null;if(l.alg===undefined){throw\"algorithm not specified in header\"}else{k=l.alg;z=k.substr(0,2)}if(n!=null&&Object.prototype.toString.call(n)===\"[object Array]\"&&n.length>0){var b=\":\"+n.join(\":\")+\":\";if(b.indexOf(\":\"+k+\":\")==-1){throw\"algorithm '\"+k+\"' not accepted in the list\"}}if(k!=\"none\"&&B===null){throw\"key shall be specified to verify.\"}if(typeof B==\"string\"&&B.indexOf(\"-----BEGIN \")!=-1){B=KEYUTIL.getKey(B)}if(z==\"RS\"||z==\"PS\"){if(!(B instanceof m)){throw\"key shall be a RSAKey obj for RS* and PS* algs\"}}if(z==\"ES\"){if(!(B instanceof p)){throw\"key shall be a ECDSA obj for ES* algs\"}}if(k==\"none\"){}var u=null;if(t.jwsalg2sigalg[l.alg]===undefined){throw\"unsupported alg name: \"+k}else{u=t.jwsalg2sigalg[k]}if(u==\"none\"){throw\"not supported\"}else{if(u.substr(0,4)==\"Hmac\"){var o=null;if(B===undefined){throw\"hexadecimal key shall be specified for HMAC\"}var j=new s({alg:u,pass:B});j.updateString(c);o=j.doFinal();return A==o}else{if(u.indexOf(\"withECDSA\")!=-1){var h=null;try{h=p.concatSigToASN1Sig(A)}catch(v){return false}var g=new d({alg:u});g.init(B);g.updateString(c);return g.verify(h)}else{var g=new d({alg:u});g.init(B);g.updateString(c);return g.verify(A)}}}};KJUR.jws.JWS.parse=function(g){var c=g.split(\".\");var b={};var f,e,d;if(c.length!=2&&c.length!=3){throw\"malformed sJWS: wrong number of '.' splitted elements\"}f=c[0];e=c[1];if(c.length==3){d=c[2]}b.headerObj=KJUR.jws.JWS.readSafeJSONString(b64utoutf8(f));b.payloadObj=KJUR.jws.JWS.readSafeJSONString(b64utoutf8(e));b.headerPP=JSON.stringify(b.headerObj,null,\"  \");if(b.payloadObj==null){b.payloadPP=b64utoutf8(e)}else{b.payloadPP=JSON.stringify(b.payloadObj,null,\"  \")}if(d!==undefined){b.sigHex=b64utohex(d)}return b};KJUR.jws.JWS.verifyJWT=function(e,l,r){var d=KJUR,j=d.jws,o=j.JWS,n=o.readSafeJSONString,p=o.inArray,f=o.includedArray;var k=e.split(\".\");var c=k[0];var i=k[1];var q=c+\".\"+i;var m=b64utohex(k[2]);var h=n(b64utoutf8(c));var g=n(b64utoutf8(i));if(h.alg===undefined){return false}if(r.alg===undefined){throw\"acceptField.alg shall be specified\"}if(!p(h.alg,r.alg)){return false}if(g.iss!==undefined&&typeof r.iss===\"object\"){if(!p(g.iss,r.iss)){return false}}if(g.sub!==undefined&&typeof r.sub===\"object\"){if(!p(g.sub,r.sub)){return false}}if(g.aud!==undefined&&typeof r.aud===\"object\"){if(typeof g.aud==\"string\"){if(!p(g.aud,r.aud)){return false}}else{if(typeof g.aud==\"object\"){if(!f(g.aud,r.aud)){return false}}}}var b=j.IntDate.getNow();if(r.verifyAt!==undefined&&typeof r.verifyAt===\"number\"){b=r.verifyAt}if(r.gracePeriod===undefined||typeof r.gracePeriod!==\"number\"){r.gracePeriod=0}if(g.exp!==undefined&&typeof g.exp==\"number\"){if(g.exp+r.gracePeriod<b){return false}}if(g.nbf!==undefined&&typeof g.nbf==\"number\"){if(b<g.nbf-r.gracePeriod){return false}}if(g.iat!==undefined&&typeof g.iat==\"number\"){if(b<g.iat-r.gracePeriod){return false}}if(g.jti!==undefined&&r.jti!==undefined){if(g.jti!==r.jti){return false}}if(!o.verify(e,l,r.alg)){return false}return true};KJUR.jws.JWS.includedArray=function(b,a){var c=KJUR.jws.JWS.inArray;if(b===null){return false}if(typeof b!==\"object\"){return false}if(typeof b.length!==\"number\"){return false}for(var d=0;d<b.length;d++){if(!c(b[d],a)){return false}}return true};KJUR.jws.JWS.inArray=function(d,b){if(b===null){return false}if(typeof b!==\"object\"){return false}if(typeof b.length!==\"number\"){return false}for(var c=0;c<b.length;c++){if(b[c]==d){return true}}return false};KJUR.jws.JWS.jwsalg2sigalg={HS256:\"HmacSHA256\",HS384:\"HmacSHA384\",HS512:\"HmacSHA512\",RS256:\"SHA256withRSA\",RS384:\"SHA384withRSA\",RS512:\"SHA512withRSA\",ES256:\"SHA256withECDSA\",ES384:\"SHA384withECDSA\",PS256:\"SHA256withRSAandMGF1\",PS384:\"SHA384withRSAandMGF1\",PS512:\"SHA512withRSAandMGF1\",none:\"none\",};KJUR.jws.JWS.isSafeJSONString=function(c,b,d){var e=null;try{e=jsonParse(c);if(typeof e!=\"object\"){return 0}if(e.constructor===Array){return 0}if(b){b[d]=e}return 1}catch(a){return 0}};KJUR.jws.JWS.readSafeJSONString=function(b){var c=null;try{c=jsonParse(b);if(typeof c!=\"object\"){return null}if(c.constructor===Array){return null}return c}catch(a){return null}};KJUR.jws.JWS.getEncodedSignatureValueFromJWS=function(b){var a=b.match(/^[^.]+\\.[^.]+\\.([^.]+)$/);if(a==null){throw\"JWS signature is not a form of 'Head.Payload.SigValue'.\"}return a[1]};KJUR.jws.JWS.getJWKthumbprint=function(d){if(d.kty!==\"RSA\"&&d.kty!==\"EC\"&&d.kty!==\"oct\"){throw\"unsupported algorithm for JWK Thumprint\"}var a=\"{\";if(d.kty===\"RSA\"){if(typeof d.n!=\"string\"||typeof d.e!=\"string\"){throw\"wrong n and e value for RSA key\"}a+='\"e\":\"'+d.e+'\",';a+='\"kty\":\"'+d.kty+'\",';a+='\"n\":\"'+d.n+'\"}'}else{if(d.kty===\"EC\"){if(typeof d.crv!=\"string\"||typeof d.x!=\"string\"||typeof d.y!=\"string\"){throw\"wrong crv, x and y value for EC key\"}a+='\"crv\":\"'+d.crv+'\",';a+='\"kty\":\"'+d.kty+'\",';a+='\"x\":\"'+d.x+'\",';a+='\"y\":\"'+d.y+'\"}'}else{if(d.kty===\"oct\"){if(typeof d.k!=\"string\"){throw\"wrong k value for oct(symmetric) key\"}a+='\"kty\":\"'+d.kty+'\",';a+='\"k\":\"'+d.k+'\"}'}}}var b=rstrtohex(a);var c=KJUR.crypto.Util.hashHex(b,\"sha256\");var e=hextob64u(c);return e};KJUR.jws.IntDate={};KJUR.jws.IntDate.get=function(c){var b=KJUR.jws.IntDate,d=b.getNow,a=b.getZulu;if(c==\"now\"){return d()}else{if(c==\"now + 1hour\"){return d()+60*60}else{if(c==\"now + 1day\"){return d()+60*60*24}else{if(c==\"now + 1month\"){return d()+60*60*24*30}else{if(c==\"now + 1year\"){return d()+60*60*24*365}else{if(c.match(/Z$/)){return a(c)}else{if(c.match(/^[0-9]+$/)){return parseInt(c)}}}}}}}throw\"unsupported format: \"+c};KJUR.jws.IntDate.getZulu=function(a){return zulutosec(a)};KJUR.jws.IntDate.getNow=function(){var a=~~(new Date()/1000);return a};KJUR.jws.IntDate.intDate2UTCString=function(a){var b=new Date(a*1000);return b.toUTCString()};KJUR.jws.IntDate.intDate2Zulu=function(e){var i=new Date(e*1000),h=(\"0000\"+i.getUTCFullYear()).slice(-4),g=(\"00\"+(i.getUTCMonth()+1)).slice(-2),b=(\"00\"+i.getUTCDate()).slice(-2),a=(\"00\"+i.getUTCHours()).slice(-2),c=(\"00\"+i.getUTCMinutes()).slice(-2),f=(\"00\"+i.getUTCSeconds()).slice(-2);return h+g+b+a+c+f+\"Z\"};\nexport { SecureRandom };\r\nexport { rng_seed_time };\r\n\r\nexport { BigInteger };\r\nexport { RSAKey };\r\nexport const { EDSA } = KJUR.crypto;\r\nexport const { DSA } = KJUR.crypto;\r\nexport const { Signature } = KJUR.crypto;\r\nexport const { MessageDigest } =  KJUR.crypto;\r\nexport const { Mac } = KJUR.crypto;\r\nexport const { Cipher } =  KJUR.crypto;\r\nexport { KEYUTIL };\r\nexport { ASN1HEX };\r\nexport { X509 };\r\nexport { CryptoJS };\r\n\r\n// ext/base64.js\r\nexport { b64tohex };\r\nexport { b64toBA };\r\n\r\n// base64x.js\r\nexport { stoBA };\r\nexport { BAtos };\r\nexport { BAtohex };\r\nexport { stohex };\r\nexport { stob64 };\r\nexport { stob64u };\r\nexport { b64utos };\r\nexport { b64tob64u };\r\nexport { b64utob64 };\r\nexport { hex2b64 };\r\nexport { hextob64u };\r\nexport { b64utohex };\r\nexport { utf8tob64u };\r\nexport { b64utoutf8 };\r\nexport { utf8tob64 };\r\nexport { b64toutf8 };\r\nexport { utf8tohex };\r\nexport { hextoutf8 };\r\nexport { hextorstr };\r\nexport { rstrtohex };\r\nexport { hextob64 };\r\nexport { hextob64nl };\r\nexport { b64nltohex };\r\nexport { hextopem };\r\nexport { pemtohex };\r\nexport { hextoArrayBuffer };\r\nexport { ArrayBuffertohex };\r\nexport { zulutomsec };\r\nexport { zulutosec };\r\nexport { zulutodate };\r\nexport { datetozulu };\r\nexport { uricmptohex };\r\nexport { hextouricmp };\r\nexport { ipv6tohex };\r\nexport { hextoipv6 };\r\nexport { hextoip };\r\nexport { iptohex };\r\nexport { encodeURIComponentAll };\r\nexport { newline_toUnix };\r\nexport { newline_toDos };\r\nexport { hextoposhex };\r\nexport { intarystrtohex };\r\nexport { strdiffidx };\r\n\r\n// name spaces\r\nexport { KJUR };\r\nconst _crypto =  KJUR.crypto;\r\nexport { _crypto as crypto };\r\nexport const { asn1 } = KJUR;\r\nexport const { jws } = KJUR;\r\nexport const { lang } = KJUR;\r\n\r\n\r\n","\"use strict\";\n\nrequire(\"core-js/shim\");\n\nrequire(\"regenerator-runtime/runtime\");\n\nrequire(\"core-js/fn/regexp/escape\");\n\nif (global._babelPolyfill) {\n  throw new Error(\"only one instance of babel-polyfill is allowed\");\n}\nglobal._babelPolyfill = true;\n\nvar DEFINE_PROPERTY = \"defineProperty\";\nfunction define(O, key, value) {\n  O[key] || Object[DEFINE_PROPERTY](O, key, {\n    writable: true,\n    configurable: true,\n    value: value\n  });\n}\n\ndefine(String.prototype, \"padLeft\", \"\".padStart);\ndefine(String.prototype, \"padRight\", \"\".padEnd);\n\n\"pop,reverse,shift,keys,values,entries,indexOf,every,some,forEach,map,filter,find,findIndex,includes,join,slice,concat,push,splice,unshift,sort,lastIndexOf,reduce,reduceRight,copyWithin,fill\".split(\",\").forEach(function (key) {\n  [][key] && define(Array, key, Function.call.bind([][key]));\n});","/**\n * Copyright (c) 2014, Facebook, Inc.\n * All rights reserved.\n *\n * This source code is licensed under the BSD-style license found in the\n * https://raw.github.com/facebook/regenerator/master/LICENSE file. An\n * additional grant of patent rights can be found in the PATENTS file in\n * the same directory.\n */\n\n!(function(global) {\n  \"use strict\";\n\n  var Op = Object.prototype;\n  var hasOwn = Op.hasOwnProperty;\n  var undefined; // More compressible than void 0.\n  var $Symbol = typeof Symbol === \"function\" ? Symbol : {};\n  var iteratorSymbol = $Symbol.iterator || \"@@iterator\";\n  var asyncIteratorSymbol = $Symbol.asyncIterator || \"@@asyncIterator\";\n  var toStringTagSymbol = $Symbol.toStringTag || \"@@toStringTag\";\n\n  var inModule = typeof module === \"object\";\n  var runtime = global.regeneratorRuntime;\n  if (runtime) {\n    if (inModule) {\n      // If regeneratorRuntime is defined globally and we're in a module,\n      // make the exports object identical to regeneratorRuntime.\n      module.exports = runtime;\n    }\n    // Don't bother evaluating the rest of this file if the runtime was\n    // already defined globally.\n    return;\n  }\n\n  // Define the runtime globally (as expected by generated code) as either\n  // module.exports (if we're in a module) or a new, empty object.\n  runtime = global.regeneratorRuntime = inModule ? module.exports : {};\n\n  function wrap(innerFn, outerFn, self, tryLocsList) {\n    // If outerFn provided and outerFn.prototype is a Generator, then outerFn.prototype instanceof Generator.\n    var protoGenerator = outerFn && outerFn.prototype instanceof Generator ? outerFn : Generator;\n    var generator = Object.create(protoGenerator.prototype);\n    var context = new Context(tryLocsList || []);\n\n    // The ._invoke method unifies the implementations of the .next,\n    // .throw, and .return methods.\n    generator._invoke = makeInvokeMethod(innerFn, self, context);\n\n    return generator;\n  }\n  runtime.wrap = wrap;\n\n  // Try/catch helper to minimize deoptimizations. Returns a completion\n  // record like context.tryEntries[i].completion. This interface could\n  // have been (and was previously) designed to take a closure to be\n  // invoked without arguments, but in all the cases we care about we\n  // already have an existing method we want to call, so there's no need\n  // to create a new function object. We can even get away with assuming\n  // the method takes exactly one argument, since that happens to be true\n  // in every case, so we don't have to touch the arguments object. The\n  // only additional allocation required is the completion record, which\n  // has a stable shape and so hopefully should be cheap to allocate.\n  function tryCatch(fn, obj, arg) {\n    try {\n      return { type: \"normal\", arg: fn.call(obj, arg) };\n    } catch (err) {\n      return { type: \"throw\", arg: err };\n    }\n  }\n\n  var GenStateSuspendedStart = \"suspendedStart\";\n  var GenStateSuspendedYield = \"suspendedYield\";\n  var GenStateExecuting = \"executing\";\n  var GenStateCompleted = \"completed\";\n\n  // Returning this object from the innerFn has the same effect as\n  // breaking out of the dispatch switch statement.\n  var ContinueSentinel = {};\n\n  // Dummy constructor functions that we use as the .constructor and\n  // .constructor.prototype properties for functions that return Generator\n  // objects. For full spec compliance, you may wish to configure your\n  // minifier not to mangle the names of these two functions.\n  function Generator() {}\n  function GeneratorFunction() {}\n  function GeneratorFunctionPrototype() {}\n\n  // This is a polyfill for %IteratorPrototype% for environments that\n  // don't natively support it.\n  var IteratorPrototype = {};\n  IteratorPrototype[iteratorSymbol] = function () {\n    return this;\n  };\n\n  var getProto = Object.getPrototypeOf;\n  var NativeIteratorPrototype = getProto && getProto(getProto(values([])));\n  if (NativeIteratorPrototype &&\n      NativeIteratorPrototype !== Op &&\n      hasOwn.call(NativeIteratorPrototype, iteratorSymbol)) {\n    // This environment has a native %IteratorPrototype%; use it instead\n    // of the polyfill.\n    IteratorPrototype = NativeIteratorPrototype;\n  }\n\n  var Gp = GeneratorFunctionPrototype.prototype =\n    Generator.prototype = Object.create(IteratorPrototype);\n  GeneratorFunction.prototype = Gp.constructor = GeneratorFunctionPrototype;\n  GeneratorFunctionPrototype.constructor = GeneratorFunction;\n  GeneratorFunctionPrototype[toStringTagSymbol] =\n    GeneratorFunction.displayName = \"GeneratorFunction\";\n\n  // Helper for defining the .next, .throw, and .return methods of the\n  // Iterator interface in terms of a single ._invoke method.\n  function defineIteratorMethods(prototype) {\n    [\"next\", \"throw\", \"return\"].forEach(function(method) {\n      prototype[method] = function(arg) {\n        return this._invoke(method, arg);\n      };\n    });\n  }\n\n  runtime.isGeneratorFunction = function(genFun) {\n    var ctor = typeof genFun === \"function\" && genFun.constructor;\n    return ctor\n      ? ctor === GeneratorFunction ||\n        // For the native GeneratorFunction constructor, the best we can\n        // do is to check its .name property.\n        (ctor.displayName || ctor.name) === \"GeneratorFunction\"\n      : false;\n  };\n\n  runtime.mark = function(genFun) {\n    if (Object.setPrototypeOf) {\n      Object.setPrototypeOf(genFun, GeneratorFunctionPrototype);\n    } else {\n      genFun.__proto__ = GeneratorFunctionPrototype;\n      if (!(toStringTagSymbol in genFun)) {\n        genFun[toStringTagSymbol] = \"GeneratorFunction\";\n      }\n    }\n    genFun.prototype = Object.create(Gp);\n    return genFun;\n  };\n\n  // Within the body of any async function, `await x` is transformed to\n  // `yield regeneratorRuntime.awrap(x)`, so that the runtime can test\n  // `hasOwn.call(value, \"__await\")` to determine if the yielded value is\n  // meant to be awaited.\n  runtime.awrap = function(arg) {\n    return { __await: arg };\n  };\n\n  function AsyncIterator(generator) {\n    function invoke(method, arg, resolve, reject) {\n      var record = tryCatch(generator[method], generator, arg);\n      if (record.type === \"throw\") {\n        reject(record.arg);\n      } else {\n        var result = record.arg;\n        var value = result.value;\n        if (value &&\n            typeof value === \"object\" &&\n            hasOwn.call(value, \"__await\")) {\n          return Promise.resolve(value.__await).then(function(value) {\n            invoke(\"next\", value, resolve, reject);\n          }, function(err) {\n            invoke(\"throw\", err, resolve, reject);\n          });\n        }\n\n        return Promise.resolve(value).then(function(unwrapped) {\n          // When a yielded Promise is resolved, its final value becomes\n          // the .value of the Promise<{value,done}> result for the\n          // current iteration. If the Promise is rejected, however, the\n          // result for this iteration will be rejected with the same\n          // reason. Note that rejections of yielded Promises are not\n          // thrown back into the generator function, as is the case\n          // when an awaited Promise is rejected. This difference in\n          // behavior between yield and await is important, because it\n          // allows the consumer to decide what to do with the yielded\n          // rejection (swallow it and continue, manually .throw it back\n          // into the generator, abandon iteration, whatever). With\n          // await, by contrast, there is no opportunity to examine the\n          // rejection reason outside the generator function, so the\n          // only option is to throw it from the await expression, and\n          // let the generator function handle the exception.\n          result.value = unwrapped;\n          resolve(result);\n        }, reject);\n      }\n    }\n\n    if (typeof global.process === \"object\" && global.process.domain) {\n      invoke = global.process.domain.bind(invoke);\n    }\n\n    var previousPromise;\n\n    function enqueue(method, arg) {\n      function callInvokeWithMethodAndArg() {\n        return new Promise(function(resolve, reject) {\n          invoke(method, arg, resolve, reject);\n        });\n      }\n\n      return previousPromise =\n        // If enqueue has been called before, then we want to wait until\n        // all previous Promises have been resolved before calling invoke,\n        // so that results are always delivered in the correct order. If\n        // enqueue has not been called before, then it is important to\n        // call invoke immediately, without waiting on a callback to fire,\n        // so that the async generator function has the opportunity to do\n        // any necessary setup in a predictable way. This predictability\n        // is why the Promise constructor synchronously invokes its\n        // executor callback, and why async functions synchronously\n        // execute code before the first await. Since we implement simple\n        // async functions in terms of async generators, it is especially\n        // important to get this right, even though it requires care.\n        previousPromise ? previousPromise.then(\n          callInvokeWithMethodAndArg,\n          // Avoid propagating failures to Promises returned by later\n          // invocations of the iterator.\n          callInvokeWithMethodAndArg\n        ) : callInvokeWithMethodAndArg();\n    }\n\n    // Define the unified helper method that is used to implement .next,\n    // .throw, and .return (see defineIteratorMethods).\n    this._invoke = enqueue;\n  }\n\n  defineIteratorMethods(AsyncIterator.prototype);\n  AsyncIterator.prototype[asyncIteratorSymbol] = function () {\n    return this;\n  };\n  runtime.AsyncIterator = AsyncIterator;\n\n  // Note that simple async functions are implemented on top of\n  // AsyncIterator objects; they just return a Promise for the value of\n  // the final result produced by the iterator.\n  runtime.async = function(innerFn, outerFn, self, tryLocsList) {\n    var iter = new AsyncIterator(\n      wrap(innerFn, outerFn, self, tryLocsList)\n    );\n\n    return runtime.isGeneratorFunction(outerFn)\n      ? iter // If outerFn is a generator, return the full iterator.\n      : iter.next().then(function(result) {\n          return result.done ? result.value : iter.next();\n        });\n  };\n\n  function makeInvokeMethod(innerFn, self, context) {\n    var state = GenStateSuspendedStart;\n\n    return function invoke(method, arg) {\n      if (state === GenStateExecuting) {\n        throw new Error(\"Generator is already running\");\n      }\n\n      if (state === GenStateCompleted) {\n        if (method === \"throw\") {\n          throw arg;\n        }\n\n        // Be forgiving, per 25.3.3.3.3 of the spec:\n        // https://people.mozilla.org/~jorendorff/es6-draft.html#sec-generatorresume\n        return doneResult();\n      }\n\n      context.method = method;\n      context.arg = arg;\n\n      while (true) {\n        var delegate = context.delegate;\n        if (delegate) {\n          var delegateResult = maybeInvokeDelegate(delegate, context);\n          if (delegateResult) {\n            if (delegateResult === ContinueSentinel) continue;\n            return delegateResult;\n          }\n        }\n\n        if (context.method === \"next\") {\n          // Setting context._sent for legacy support of Babel's\n          // function.sent implementation.\n          context.sent = context._sent = context.arg;\n\n        } else if (context.method === \"throw\") {\n          if (state === GenStateSuspendedStart) {\n            state = GenStateCompleted;\n            throw context.arg;\n          }\n\n          context.dispatchException(context.arg);\n\n        } else if (context.method === \"return\") {\n          context.abrupt(\"return\", context.arg);\n        }\n\n        state = GenStateExecuting;\n\n        var record = tryCatch(innerFn, self, context);\n        if (record.type === \"normal\") {\n          // If an exception is thrown from innerFn, we leave state ===\n          // GenStateExecuting and loop back for another invocation.\n          state = context.done\n            ? GenStateCompleted\n            : GenStateSuspendedYield;\n\n          if (record.arg === ContinueSentinel) {\n            continue;\n          }\n\n          return {\n            value: record.arg,\n            done: context.done\n          };\n\n        } else if (record.type === \"throw\") {\n          state = GenStateCompleted;\n          // Dispatch the exception by looping back around to the\n          // context.dispatchException(context.arg) call above.\n          context.method = \"throw\";\n          context.arg = record.arg;\n        }\n      }\n    };\n  }\n\n  // Call delegate.iterator[context.method](context.arg) and handle the\n  // result, either by returning a { value, done } result from the\n  // delegate iterator, or by modifying context.method and context.arg,\n  // setting context.delegate to null, and returning the ContinueSentinel.\n  function maybeInvokeDelegate(delegate, context) {\n    var method = delegate.iterator[context.method];\n    if (method === undefined) {\n      // A .throw or .return when the delegate iterator has no .throw\n      // method always terminates the yield* loop.\n      context.delegate = null;\n\n      if (context.method === \"throw\") {\n        if (delegate.iterator.return) {\n          // If the delegate iterator has a return method, give it a\n          // chance to clean up.\n          context.method = \"return\";\n          context.arg = undefined;\n          maybeInvokeDelegate(delegate, context);\n\n          if (context.method === \"throw\") {\n            // If maybeInvokeDelegate(context) changed context.method from\n            // \"return\" to \"throw\", let that override the TypeError below.\n            return ContinueSentinel;\n          }\n        }\n\n        context.method = \"throw\";\n        context.arg = new TypeError(\n          \"The iterator does not provide a 'throw' method\");\n      }\n\n      return ContinueSentinel;\n    }\n\n    var record = tryCatch(method, delegate.iterator, context.arg);\n\n    if (record.type === \"throw\") {\n      context.method = \"throw\";\n      context.arg = record.arg;\n      context.delegate = null;\n      return ContinueSentinel;\n    }\n\n    var info = record.arg;\n\n    if (! info) {\n      context.method = \"throw\";\n      context.arg = new TypeError(\"iterator result is not an object\");\n      context.delegate = null;\n      return ContinueSentinel;\n    }\n\n    if (info.done) {\n      // Assign the result of the finished delegate to the temporary\n      // variable specified by delegate.resultName (see delegateYield).\n      context[delegate.resultName] = info.value;\n\n      // Resume execution at the desired location (see delegateYield).\n      context.next = delegate.nextLoc;\n\n      // If context.method was \"throw\" but the delegate handled the\n      // exception, let the outer generator proceed normally. If\n      // context.method was \"next\", forget context.arg since it has been\n      // \"consumed\" by the delegate iterator. If context.method was\n      // \"return\", allow the original .return call to continue in the\n      // outer generator.\n      if (context.method !== \"return\") {\n        context.method = \"next\";\n        context.arg = undefined;\n      }\n\n    } else {\n      // Re-yield the result returned by the delegate method.\n      return info;\n    }\n\n    // The delegate iterator is finished, so forget it and continue with\n    // the outer generator.\n    context.delegate = null;\n    return ContinueSentinel;\n  }\n\n  // Define Generator.prototype.{next,throw,return} in terms of the\n  // unified ._invoke helper method.\n  defineIteratorMethods(Gp);\n\n  Gp[toStringTagSymbol] = \"Generator\";\n\n  // A Generator should always return itself as the iterator object when the\n  // @@iterator function is called on it. Some browsers' implementations of the\n  // iterator prototype chain incorrectly implement this, causing the Generator\n  // object to not be returned from this call. This ensures that doesn't happen.\n  // See https://github.com/facebook/regenerator/issues/274 for more details.\n  Gp[iteratorSymbol] = function() {\n    return this;\n  };\n\n  Gp.toString = function() {\n    return \"[object Generator]\";\n  };\n\n  function pushTryEntry(locs) {\n    var entry = { tryLoc: locs[0] };\n\n    if (1 in locs) {\n      entry.catchLoc = locs[1];\n    }\n\n    if (2 in locs) {\n      entry.finallyLoc = locs[2];\n      entry.afterLoc = locs[3];\n    }\n\n    this.tryEntries.push(entry);\n  }\n\n  function resetTryEntry(entry) {\n    var record = entry.completion || {};\n    record.type = \"normal\";\n    delete record.arg;\n    entry.completion = record;\n  }\n\n  function Context(tryLocsList) {\n    // The root entry object (effectively a try statement without a catch\n    // or a finally block) gives us a place to store values thrown from\n    // locations where there is no enclosing try statement.\n    this.tryEntries = [{ tryLoc: \"root\" }];\n    tryLocsList.forEach(pushTryEntry, this);\n    this.reset(true);\n  }\n\n  runtime.keys = function(object) {\n    var keys = [];\n    for (var key in object) {\n      keys.push(key);\n    }\n    keys.reverse();\n\n    // Rather than returning an object with a next method, we keep\n    // things simple and return the next function itself.\n    return function next() {\n      while (keys.length) {\n        var key = keys.pop();\n        if (key in object) {\n          next.value = key;\n          next.done = false;\n          return next;\n        }\n      }\n\n      // To avoid creating an additional object, we just hang the .value\n      // and .done properties off the next function object itself. This\n      // also ensures that the minifier will not anonymize the function.\n      next.done = true;\n      return next;\n    };\n  };\n\n  function values(iterable) {\n    if (iterable) {\n      var iteratorMethod = iterable[iteratorSymbol];\n      if (iteratorMethod) {\n        return iteratorMethod.call(iterable);\n      }\n\n      if (typeof iterable.next === \"function\") {\n        return iterable;\n      }\n\n      if (!isNaN(iterable.length)) {\n        var i = -1, next = function next() {\n          while (++i < iterable.length) {\n            if (hasOwn.call(iterable, i)) {\n              next.value = iterable[i];\n              next.done = false;\n              return next;\n            }\n          }\n\n          next.value = undefined;\n          next.done = true;\n\n          return next;\n        };\n\n        return next.next = next;\n      }\n    }\n\n    // Return an iterator with no values.\n    return { next: doneResult };\n  }\n  runtime.values = values;\n\n  function doneResult() {\n    return { value: undefined, done: true };\n  }\n\n  Context.prototype = {\n    constructor: Context,\n\n    reset: function(skipTempReset) {\n      this.prev = 0;\n      this.next = 0;\n      // Resetting context._sent for legacy support of Babel's\n      // function.sent implementation.\n      this.sent = this._sent = undefined;\n      this.done = false;\n      this.delegate = null;\n\n      this.method = \"next\";\n      this.arg = undefined;\n\n      this.tryEntries.forEach(resetTryEntry);\n\n      if (!skipTempReset) {\n        for (var name in this) {\n          // Not sure about the optimal order of these conditions:\n          if (name.charAt(0) === \"t\" &&\n              hasOwn.call(this, name) &&\n              !isNaN(+name.slice(1))) {\n            this[name] = undefined;\n          }\n        }\n      }\n    },\n\n    stop: function() {\n      this.done = true;\n\n      var rootEntry = this.tryEntries[0];\n      var rootRecord = rootEntry.completion;\n      if (rootRecord.type === \"throw\") {\n        throw rootRecord.arg;\n      }\n\n      return this.rval;\n    },\n\n    dispatchException: function(exception) {\n      if (this.done) {\n        throw exception;\n      }\n\n      var context = this;\n      function handle(loc, caught) {\n        record.type = \"throw\";\n        record.arg = exception;\n        context.next = loc;\n\n        if (caught) {\n          // If the dispatched exception was caught by a catch block,\n          // then let that catch block handle the exception normally.\n          context.method = \"next\";\n          context.arg = undefined;\n        }\n\n        return !! caught;\n      }\n\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        var record = entry.completion;\n\n        if (entry.tryLoc === \"root\") {\n          // Exception thrown outside of any try block that could handle\n          // it, so set the completion value of the entire function to\n          // throw the exception.\n          return handle(\"end\");\n        }\n\n        if (entry.tryLoc <= this.prev) {\n          var hasCatch = hasOwn.call(entry, \"catchLoc\");\n          var hasFinally = hasOwn.call(entry, \"finallyLoc\");\n\n          if (hasCatch && hasFinally) {\n            if (this.prev < entry.catchLoc) {\n              return handle(entry.catchLoc, true);\n            } else if (this.prev < entry.finallyLoc) {\n              return handle(entry.finallyLoc);\n            }\n\n          } else if (hasCatch) {\n            if (this.prev < entry.catchLoc) {\n              return handle(entry.catchLoc, true);\n            }\n\n          } else if (hasFinally) {\n            if (this.prev < entry.finallyLoc) {\n              return handle(entry.finallyLoc);\n            }\n\n          } else {\n            throw new Error(\"try statement without catch or finally\");\n          }\n        }\n      }\n    },\n\n    abrupt: function(type, arg) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.tryLoc <= this.prev &&\n            hasOwn.call(entry, \"finallyLoc\") &&\n            this.prev < entry.finallyLoc) {\n          var finallyEntry = entry;\n          break;\n        }\n      }\n\n      if (finallyEntry &&\n          (type === \"break\" ||\n           type === \"continue\") &&\n          finallyEntry.tryLoc <= arg &&\n          arg <= finallyEntry.finallyLoc) {\n        // Ignore the finally entry if control is not jumping to a\n        // location outside the try/catch block.\n        finallyEntry = null;\n      }\n\n      var record = finallyEntry ? finallyEntry.completion : {};\n      record.type = type;\n      record.arg = arg;\n\n      if (finallyEntry) {\n        this.method = \"next\";\n        this.next = finallyEntry.finallyLoc;\n        return ContinueSentinel;\n      }\n\n      return this.complete(record);\n    },\n\n    complete: function(record, afterLoc) {\n      if (record.type === \"throw\") {\n        throw record.arg;\n      }\n\n      if (record.type === \"break\" ||\n          record.type === \"continue\") {\n        this.next = record.arg;\n      } else if (record.type === \"return\") {\n        this.rval = this.arg = record.arg;\n        this.method = \"return\";\n        this.next = \"end\";\n      } else if (record.type === \"normal\" && afterLoc) {\n        this.next = afterLoc;\n      }\n\n      return ContinueSentinel;\n    },\n\n    finish: function(finallyLoc) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.finallyLoc === finallyLoc) {\n          this.complete(entry.completion, entry.afterLoc);\n          resetTryEntry(entry);\n          return ContinueSentinel;\n        }\n      }\n    },\n\n    \"catch\": function(tryLoc) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.tryLoc === tryLoc) {\n          var record = entry.completion;\n          if (record.type === \"throw\") {\n            var thrown = record.arg;\n            resetTryEntry(entry);\n          }\n          return thrown;\n        }\n      }\n\n      // The context.catch method must only be called with a location\n      // argument that corresponds to a known catch block.\n      throw new Error(\"illegal catch attempt\");\n    },\n\n    delegateYield: function(iterable, resultName, nextLoc) {\n      this.delegate = {\n        iterator: values(iterable),\n        resultName: resultName,\n        nextLoc: nextLoc\n      };\n\n      if (this.method === \"next\") {\n        // Deliberately forget the last sent value so that we don't\n        // accidentally pass it on to the delegate.\n        this.arg = undefined;\n      }\n\n      return ContinueSentinel;\n    }\n  };\n})(\n  // Among the various tricks for obtaining a reference to the global\n  // object, this seems to be the most reliable technique that does not\n  // use indirect eval (which violates Content Security Policy).\n  typeof global === \"object\" ? global :\n  typeof window === \"object\" ? window :\n  typeof self === \"object\" ? self : this\n);\n","'use strict'\n\nexports.byteLength = byteLength\nexports.toByteArray = toByteArray\nexports.fromByteArray = fromByteArray\n\nvar lookup = []\nvar revLookup = []\nvar Arr = typeof Uint8Array !== 'undefined' ? Uint8Array : Array\n\nvar code = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'\nfor (var i = 0, len = code.length; i < len; ++i) {\n  lookup[i] = code[i]\n  revLookup[code.charCodeAt(i)] = i\n}\n\n// Support decoding URL-safe base64 strings, as Node.js does.\n// See: https://en.wikipedia.org/wiki/Base64#URL_applications\nrevLookup['-'.charCodeAt(0)] = 62\nrevLookup['_'.charCodeAt(0)] = 63\n\nfunction getLens (b64) {\n  var len = b64.length\n\n  if (len % 4 > 0) {\n    throw new Error('Invalid string. Length must be a multiple of 4')\n  }\n\n  // Trim off extra bytes after placeholder bytes are found\n  // See: https://github.com/beatgammit/base64-js/issues/42\n  var validLen = b64.indexOf('=')\n  if (validLen === -1) validLen = len\n\n  var placeHoldersLen = validLen === len\n    ? 0\n    : 4 - (validLen % 4)\n\n  return [validLen, placeHoldersLen]\n}\n\n// base64 is 4/3 + up to two characters of the original data\nfunction byteLength (b64) {\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction _byteLength (b64, validLen, placeHoldersLen) {\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction toByteArray (b64) {\n  var tmp\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n\n  var arr = new Arr(_byteLength(b64, validLen, placeHoldersLen))\n\n  var curByte = 0\n\n  // if there are placeholders, only get up to the last complete 4 chars\n  var len = placeHoldersLen > 0\n    ? validLen - 4\n    : validLen\n\n  for (var i = 0; i < len; i += 4) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 18) |\n      (revLookup[b64.charCodeAt(i + 1)] << 12) |\n      (revLookup[b64.charCodeAt(i + 2)] << 6) |\n      revLookup[b64.charCodeAt(i + 3)]\n    arr[curByte++] = (tmp >> 16) & 0xFF\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 2) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 2) |\n      (revLookup[b64.charCodeAt(i + 1)] >> 4)\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 1) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 10) |\n      (revLookup[b64.charCodeAt(i + 1)] << 4) |\n      (revLookup[b64.charCodeAt(i + 2)] >> 2)\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  return arr\n}\n\nfunction tripletToBase64 (num) {\n  return lookup[num >> 18 & 0x3F] +\n    lookup[num >> 12 & 0x3F] +\n    lookup[num >> 6 & 0x3F] +\n    lookup[num & 0x3F]\n}\n\nfunction encodeChunk (uint8, start, end) {\n  var tmp\n  var output = []\n  for (var i = start; i < end; i += 3) {\n    tmp =\n      ((uint8[i] << 16) & 0xFF0000) +\n      ((uint8[i + 1] << 8) & 0xFF00) +\n      (uint8[i + 2] & 0xFF)\n    output.push(tripletToBase64(tmp))\n  }\n  return output.join('')\n}\n\nfunction fromByteArray (uint8) {\n  var tmp\n  var len = uint8.length\n  var extraBytes = len % 3 // if we have 1 byte left, pad 2 bytes\n  var parts = []\n  var maxChunkLength = 16383 // must be multiple of 3\n\n  // go through the array every three bytes, we'll deal with trailing stuff later\n  for (var i = 0, len2 = len - extraBytes; i < len2; i += maxChunkLength) {\n    parts.push(encodeChunk(\n      uint8, i, (i + maxChunkLength) > len2 ? len2 : (i + maxChunkLength)\n    ))\n  }\n\n  // pad the end with zeros, but make sure to not forget the extra bytes\n  if (extraBytes === 1) {\n    tmp = uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 2] +\n      lookup[(tmp << 4) & 0x3F] +\n      '=='\n    )\n  } else if (extraBytes === 2) {\n    tmp = (uint8[len - 2] << 8) + uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 10] +\n      lookup[(tmp >> 4) & 0x3F] +\n      lookup[(tmp << 2) & 0x3F] +\n      '='\n    )\n  }\n\n  return parts.join('')\n}\n","/*!\n * The buffer module from node.js, for the browser.\n *\n * @author   Feross Aboukhadijeh <feross@feross.org> <http://feross.org>\n * @license  MIT\n */\n/* eslint-disable no-proto */\n\n'use strict'\n\nvar base64 = require('base64-js')\nvar ieee754 = require('ieee754')\nvar isArray = require('isarray')\n\nexports.Buffer = Buffer\nexports.SlowBuffer = SlowBuffer\nexports.INSPECT_MAX_BYTES = 50\n\n/**\n * If `Buffer.TYPED_ARRAY_SUPPORT`:\n *   === true    Use Uint8Array implementation (fastest)\n *   === false   Use Object implementation (most compatible, even IE6)\n *\n * Browsers that support typed arrays are IE 10+, Firefox 4+, Chrome 7+, Safari 5.1+,\n * Opera 11.6+, iOS 4.2+.\n *\n * Due to various browser bugs, sometimes the Object implementation will be used even\n * when the browser supports typed arrays.\n *\n * Note:\n *\n *   - Firefox 4-29 lacks support for adding new properties to `Uint8Array` instances,\n *     See: https://bugzilla.mozilla.org/show_bug.cgi?id=695438.\n *\n *   - Chrome 9-10 is missing the `TypedArray.prototype.subarray` function.\n *\n *   - IE10 has a broken `TypedArray.prototype.subarray` function which returns arrays of\n *     incorrect length in some situations.\n\n * We detect these buggy browsers and set `Buffer.TYPED_ARRAY_SUPPORT` to `false` so they\n * get the Object implementation, which is slower but behaves correctly.\n */\nBuffer.TYPED_ARRAY_SUPPORT = global.TYPED_ARRAY_SUPPORT !== undefined\n  ? global.TYPED_ARRAY_SUPPORT\n  : typedArraySupport()\n\n/*\n * Export kMaxLength after typed array support is determined.\n */\nexports.kMaxLength = kMaxLength()\n\nfunction typedArraySupport () {\n  try {\n    var arr = new Uint8Array(1)\n    arr.__proto__ = {__proto__: Uint8Array.prototype, foo: function () { return 42 }}\n    return arr.foo() === 42 && // typed array instances can be augmented\n        typeof arr.subarray === 'function' && // chrome 9-10 lack `subarray`\n        arr.subarray(1, 1).byteLength === 0 // ie10 has broken `subarray`\n  } catch (e) {\n    return false\n  }\n}\n\nfunction kMaxLength () {\n  return Buffer.TYPED_ARRAY_SUPPORT\n    ? 0x7fffffff\n    : 0x3fffffff\n}\n\nfunction createBuffer (that, length) {\n  if (kMaxLength() < length) {\n    throw new RangeError('Invalid typed array length')\n  }\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = new Uint8Array(length)\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    if (that === null) {\n      that = new Buffer(length)\n    }\n    that.length = length\n  }\n\n  return that\n}\n\n/**\n * The Buffer constructor returns instances of `Uint8Array` that have their\n * prototype changed to `Buffer.prototype`. Furthermore, `Buffer` is a subclass of\n * `Uint8Array`, so the returned instances will have all the node `Buffer` methods\n * and the `Uint8Array` methods. Square bracket notation works as expected -- it\n * returns a single octet.\n *\n * The `Uint8Array` prototype remains unmodified.\n */\n\nfunction Buffer (arg, encodingOrOffset, length) {\n  if (!Buffer.TYPED_ARRAY_SUPPORT && !(this instanceof Buffer)) {\n    return new Buffer(arg, encodingOrOffset, length)\n  }\n\n  // Common case.\n  if (typeof arg === 'number') {\n    if (typeof encodingOrOffset === 'string') {\n      throw new Error(\n        'If encoding is specified then the first argument must be a string'\n      )\n    }\n    return allocUnsafe(this, arg)\n  }\n  return from(this, arg, encodingOrOffset, length)\n}\n\nBuffer.poolSize = 8192 // not used by this implementation\n\n// TODO: Legacy, not needed anymore. Remove in next major version.\nBuffer._augment = function (arr) {\n  arr.__proto__ = Buffer.prototype\n  return arr\n}\n\nfunction from (that, value, encodingOrOffset, length) {\n  if (typeof value === 'number') {\n    throw new TypeError('\"value\" argument must not be a number')\n  }\n\n  if (typeof ArrayBuffer !== 'undefined' && value instanceof ArrayBuffer) {\n    return fromArrayBuffer(that, value, encodingOrOffset, length)\n  }\n\n  if (typeof value === 'string') {\n    return fromString(that, value, encodingOrOffset)\n  }\n\n  return fromObject(that, value)\n}\n\n/**\n * Functionally equivalent to Buffer(arg, encoding) but throws a TypeError\n * if value is a number.\n * Buffer.from(str[, encoding])\n * Buffer.from(array)\n * Buffer.from(buffer)\n * Buffer.from(arrayBuffer[, byteOffset[, length]])\n **/\nBuffer.from = function (value, encodingOrOffset, length) {\n  return from(null, value, encodingOrOffset, length)\n}\n\nif (Buffer.TYPED_ARRAY_SUPPORT) {\n  Buffer.prototype.__proto__ = Uint8Array.prototype\n  Buffer.__proto__ = Uint8Array\n  if (typeof Symbol !== 'undefined' && Symbol.species &&\n      Buffer[Symbol.species] === Buffer) {\n    // Fix subarray() in ES2016. See: https://github.com/feross/buffer/pull/97\n    Object.defineProperty(Buffer, Symbol.species, {\n      value: null,\n      configurable: true\n    })\n  }\n}\n\nfunction assertSize (size) {\n  if (typeof size !== 'number') {\n    throw new TypeError('\"size\" argument must be a number')\n  } else if (size < 0) {\n    throw new RangeError('\"size\" argument must not be negative')\n  }\n}\n\nfunction alloc (that, size, fill, encoding) {\n  assertSize(size)\n  if (size <= 0) {\n    return createBuffer(that, size)\n  }\n  if (fill !== undefined) {\n    // Only pay attention to encoding if it's a string. This\n    // prevents accidentally sending in a number that would\n    // be interpretted as a start offset.\n    return typeof encoding === 'string'\n      ? createBuffer(that, size).fill(fill, encoding)\n      : createBuffer(that, size).fill(fill)\n  }\n  return createBuffer(that, size)\n}\n\n/**\n * Creates a new filled Buffer instance.\n * alloc(size[, fill[, encoding]])\n **/\nBuffer.alloc = function (size, fill, encoding) {\n  return alloc(null, size, fill, encoding)\n}\n\nfunction allocUnsafe (that, size) {\n  assertSize(size)\n  that = createBuffer(that, size < 0 ? 0 : checked(size) | 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) {\n    for (var i = 0; i < size; ++i) {\n      that[i] = 0\n    }\n  }\n  return that\n}\n\n/**\n * Equivalent to Buffer(num), by default creates a non-zero-filled Buffer instance.\n * */\nBuffer.allocUnsafe = function (size) {\n  return allocUnsafe(null, size)\n}\n/**\n * Equivalent to SlowBuffer(num), by default creates a non-zero-filled Buffer instance.\n */\nBuffer.allocUnsafeSlow = function (size) {\n  return allocUnsafe(null, size)\n}\n\nfunction fromString (that, string, encoding) {\n  if (typeof encoding !== 'string' || encoding === '') {\n    encoding = 'utf8'\n  }\n\n  if (!Buffer.isEncoding(encoding)) {\n    throw new TypeError('\"encoding\" must be a valid string encoding')\n  }\n\n  var length = byteLength(string, encoding) | 0\n  that = createBuffer(that, length)\n\n  var actual = that.write(string, encoding)\n\n  if (actual !== length) {\n    // Writing a hex string, for example, that contains invalid characters will\n    // cause everything after the first invalid character to be ignored. (e.g.\n    // 'abxxcd' will be treated as 'ab')\n    that = that.slice(0, actual)\n  }\n\n  return that\n}\n\nfunction fromArrayLike (that, array) {\n  var length = array.length < 0 ? 0 : checked(array.length) | 0\n  that = createBuffer(that, length)\n  for (var i = 0; i < length; i += 1) {\n    that[i] = array[i] & 255\n  }\n  return that\n}\n\nfunction fromArrayBuffer (that, array, byteOffset, length) {\n  array.byteLength // this throws if `array` is not a valid ArrayBuffer\n\n  if (byteOffset < 0 || array.byteLength < byteOffset) {\n    throw new RangeError('\\'offset\\' is out of bounds')\n  }\n\n  if (array.byteLength < byteOffset + (length || 0)) {\n    throw new RangeError('\\'length\\' is out of bounds')\n  }\n\n  if (byteOffset === undefined && length === undefined) {\n    array = new Uint8Array(array)\n  } else if (length === undefined) {\n    array = new Uint8Array(array, byteOffset)\n  } else {\n    array = new Uint8Array(array, byteOffset, length)\n  }\n\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = array\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    that = fromArrayLike(that, array)\n  }\n  return that\n}\n\nfunction fromObject (that, obj) {\n  if (Buffer.isBuffer(obj)) {\n    var len = checked(obj.length) | 0\n    that = createBuffer(that, len)\n\n    if (that.length === 0) {\n      return that\n    }\n\n    obj.copy(that, 0, 0, len)\n    return that\n  }\n\n  if (obj) {\n    if ((typeof ArrayBuffer !== 'undefined' &&\n        obj.buffer instanceof ArrayBuffer) || 'length' in obj) {\n      if (typeof obj.length !== 'number' || isnan(obj.length)) {\n        return createBuffer(that, 0)\n      }\n      return fromArrayLike(that, obj)\n    }\n\n    if (obj.type === 'Buffer' && isArray(obj.data)) {\n      return fromArrayLike(that, obj.data)\n    }\n  }\n\n  throw new TypeError('First argument must be a string, Buffer, ArrayBuffer, Array, or array-like object.')\n}\n\nfunction checked (length) {\n  // Note: cannot use `length < kMaxLength()` here because that fails when\n  // length is NaN (which is otherwise coerced to zero.)\n  if (length >= kMaxLength()) {\n    throw new RangeError('Attempt to allocate Buffer larger than maximum ' +\n                         'size: 0x' + kMaxLength().toString(16) + ' bytes')\n  }\n  return length | 0\n}\n\nfunction SlowBuffer (length) {\n  if (+length != length) { // eslint-disable-line eqeqeq\n    length = 0\n  }\n  return Buffer.alloc(+length)\n}\n\nBuffer.isBuffer = function isBuffer (b) {\n  return !!(b != null && b._isBuffer)\n}\n\nBuffer.compare = function compare (a, b) {\n  if (!Buffer.isBuffer(a) || !Buffer.isBuffer(b)) {\n    throw new TypeError('Arguments must be Buffers')\n  }\n\n  if (a === b) return 0\n\n  var x = a.length\n  var y = b.length\n\n  for (var i = 0, len = Math.min(x, y); i < len; ++i) {\n    if (a[i] !== b[i]) {\n      x = a[i]\n      y = b[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\nBuffer.isEncoding = function isEncoding (encoding) {\n  switch (String(encoding).toLowerCase()) {\n    case 'hex':\n    case 'utf8':\n    case 'utf-8':\n    case 'ascii':\n    case 'latin1':\n    case 'binary':\n    case 'base64':\n    case 'ucs2':\n    case 'ucs-2':\n    case 'utf16le':\n    case 'utf-16le':\n      return true\n    default:\n      return false\n  }\n}\n\nBuffer.concat = function concat (list, length) {\n  if (!isArray(list)) {\n    throw new TypeError('\"list\" argument must be an Array of Buffers')\n  }\n\n  if (list.length === 0) {\n    return Buffer.alloc(0)\n  }\n\n  var i\n  if (length === undefined) {\n    length = 0\n    for (i = 0; i < list.length; ++i) {\n      length += list[i].length\n    }\n  }\n\n  var buffer = Buffer.allocUnsafe(length)\n  var pos = 0\n  for (i = 0; i < list.length; ++i) {\n    var buf = list[i]\n    if (!Buffer.isBuffer(buf)) {\n      throw new TypeError('\"list\" argument must be an Array of Buffers')\n    }\n    buf.copy(buffer, pos)\n    pos += buf.length\n  }\n  return buffer\n}\n\nfunction byteLength (string, encoding) {\n  if (Buffer.isBuffer(string)) {\n    return string.length\n  }\n  if (typeof ArrayBuffer !== 'undefined' && typeof ArrayBuffer.isView === 'function' &&\n      (ArrayBuffer.isView(string) || string instanceof ArrayBuffer)) {\n    return string.byteLength\n  }\n  if (typeof string !== 'string') {\n    string = '' + string\n  }\n\n  var len = string.length\n  if (len === 0) return 0\n\n  // Use a for loop to avoid recursion\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'ascii':\n      case 'latin1':\n      case 'binary':\n        return len\n      case 'utf8':\n      case 'utf-8':\n      case undefined:\n        return utf8ToBytes(string).length\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return len * 2\n      case 'hex':\n        return len >>> 1\n      case 'base64':\n        return base64ToBytes(string).length\n      default:\n        if (loweredCase) return utf8ToBytes(string).length // assume utf8\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\nBuffer.byteLength = byteLength\n\nfunction slowToString (encoding, start, end) {\n  var loweredCase = false\n\n  // No need to verify that \"this.length <= MAX_UINT32\" since it's a read-only\n  // property of a typed array.\n\n  // This behaves neither like String nor Uint8Array in that we set start/end\n  // to their upper/lower bounds if the value passed is out of range.\n  // undefined is handled specially as per ECMA-262 6th Edition,\n  // Section 13.3.3.7 Runtime Semantics: KeyedBindingInitialization.\n  if (start === undefined || start < 0) {\n    start = 0\n  }\n  // Return early if start > this.length. Done here to prevent potential uint32\n  // coercion fail below.\n  if (start > this.length) {\n    return ''\n  }\n\n  if (end === undefined || end > this.length) {\n    end = this.length\n  }\n\n  if (end <= 0) {\n    return ''\n  }\n\n  // Force coersion to uint32. This will also coerce falsey/NaN values to 0.\n  end >>>= 0\n  start >>>= 0\n\n  if (end <= start) {\n    return ''\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  while (true) {\n    switch (encoding) {\n      case 'hex':\n        return hexSlice(this, start, end)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Slice(this, start, end)\n\n      case 'ascii':\n        return asciiSlice(this, start, end)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Slice(this, start, end)\n\n      case 'base64':\n        return base64Slice(this, start, end)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return utf16leSlice(this, start, end)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = (encoding + '').toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\n// The property is used by `Buffer.isBuffer` and `is-buffer` (in Safari 5-7) to detect\n// Buffer instances.\nBuffer.prototype._isBuffer = true\n\nfunction swap (b, n, m) {\n  var i = b[n]\n  b[n] = b[m]\n  b[m] = i\n}\n\nBuffer.prototype.swap16 = function swap16 () {\n  var len = this.length\n  if (len % 2 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 16-bits')\n  }\n  for (var i = 0; i < len; i += 2) {\n    swap(this, i, i + 1)\n  }\n  return this\n}\n\nBuffer.prototype.swap32 = function swap32 () {\n  var len = this.length\n  if (len % 4 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 32-bits')\n  }\n  for (var i = 0; i < len; i += 4) {\n    swap(this, i, i + 3)\n    swap(this, i + 1, i + 2)\n  }\n  return this\n}\n\nBuffer.prototype.swap64 = function swap64 () {\n  var len = this.length\n  if (len % 8 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 64-bits')\n  }\n  for (var i = 0; i < len; i += 8) {\n    swap(this, i, i + 7)\n    swap(this, i + 1, i + 6)\n    swap(this, i + 2, i + 5)\n    swap(this, i + 3, i + 4)\n  }\n  return this\n}\n\nBuffer.prototype.toString = function toString () {\n  var length = this.length | 0\n  if (length === 0) return ''\n  if (arguments.length === 0) return utf8Slice(this, 0, length)\n  return slowToString.apply(this, arguments)\n}\n\nBuffer.prototype.equals = function equals (b) {\n  if (!Buffer.isBuffer(b)) throw new TypeError('Argument must be a Buffer')\n  if (this === b) return true\n  return Buffer.compare(this, b) === 0\n}\n\nBuffer.prototype.inspect = function inspect () {\n  var str = ''\n  var max = exports.INSPECT_MAX_BYTES\n  if (this.length > 0) {\n    str = this.toString('hex', 0, max).match(/.{2}/g).join(' ')\n    if (this.length > max) str += ' ... '\n  }\n  return '<Buffer ' + str + '>'\n}\n\nBuffer.prototype.compare = function compare (target, start, end, thisStart, thisEnd) {\n  if (!Buffer.isBuffer(target)) {\n    throw new TypeError('Argument must be a Buffer')\n  }\n\n  if (start === undefined) {\n    start = 0\n  }\n  if (end === undefined) {\n    end = target ? target.length : 0\n  }\n  if (thisStart === undefined) {\n    thisStart = 0\n  }\n  if (thisEnd === undefined) {\n    thisEnd = this.length\n  }\n\n  if (start < 0 || end > target.length || thisStart < 0 || thisEnd > this.length) {\n    throw new RangeError('out of range index')\n  }\n\n  if (thisStart >= thisEnd && start >= end) {\n    return 0\n  }\n  if (thisStart >= thisEnd) {\n    return -1\n  }\n  if (start >= end) {\n    return 1\n  }\n\n  start >>>= 0\n  end >>>= 0\n  thisStart >>>= 0\n  thisEnd >>>= 0\n\n  if (this === target) return 0\n\n  var x = thisEnd - thisStart\n  var y = end - start\n  var len = Math.min(x, y)\n\n  var thisCopy = this.slice(thisStart, thisEnd)\n  var targetCopy = target.slice(start, end)\n\n  for (var i = 0; i < len; ++i) {\n    if (thisCopy[i] !== targetCopy[i]) {\n      x = thisCopy[i]\n      y = targetCopy[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\n// Finds either the first index of `val` in `buffer` at offset >= `byteOffset`,\n// OR the last index of `val` in `buffer` at offset <= `byteOffset`.\n//\n// Arguments:\n// - buffer - a Buffer to search\n// - val - a string, Buffer, or number\n// - byteOffset - an index into `buffer`; will be clamped to an int32\n// - encoding - an optional encoding, relevant is val is a string\n// - dir - true for indexOf, false for lastIndexOf\nfunction bidirectionalIndexOf (buffer, val, byteOffset, encoding, dir) {\n  // Empty buffer means no match\n  if (buffer.length === 0) return -1\n\n  // Normalize byteOffset\n  if (typeof byteOffset === 'string') {\n    encoding = byteOffset\n    byteOffset = 0\n  } else if (byteOffset > 0x7fffffff) {\n    byteOffset = 0x7fffffff\n  } else if (byteOffset < -0x80000000) {\n    byteOffset = -0x80000000\n  }\n  byteOffset = +byteOffset  // Coerce to Number.\n  if (isNaN(byteOffset)) {\n    // byteOffset: it it's undefined, null, NaN, \"foo\", etc, search whole buffer\n    byteOffset = dir ? 0 : (buffer.length - 1)\n  }\n\n  // Normalize byteOffset: negative offsets start from the end of the buffer\n  if (byteOffset < 0) byteOffset = buffer.length + byteOffset\n  if (byteOffset >= buffer.length) {\n    if (dir) return -1\n    else byteOffset = buffer.length - 1\n  } else if (byteOffset < 0) {\n    if (dir) byteOffset = 0\n    else return -1\n  }\n\n  // Normalize val\n  if (typeof val === 'string') {\n    val = Buffer.from(val, encoding)\n  }\n\n  // Finally, search either indexOf (if dir is true) or lastIndexOf\n  if (Buffer.isBuffer(val)) {\n    // Special case: looking for empty string/buffer always fails\n    if (val.length === 0) {\n      return -1\n    }\n    return arrayIndexOf(buffer, val, byteOffset, encoding, dir)\n  } else if (typeof val === 'number') {\n    val = val & 0xFF // Search for a byte value [0-255]\n    if (Buffer.TYPED_ARRAY_SUPPORT &&\n        typeof Uint8Array.prototype.indexOf === 'function') {\n      if (dir) {\n        return Uint8Array.prototype.indexOf.call(buffer, val, byteOffset)\n      } else {\n        return Uint8Array.prototype.lastIndexOf.call(buffer, val, byteOffset)\n      }\n    }\n    return arrayIndexOf(buffer, [ val ], byteOffset, encoding, dir)\n  }\n\n  throw new TypeError('val must be string, number or Buffer')\n}\n\nfunction arrayIndexOf (arr, val, byteOffset, encoding, dir) {\n  var indexSize = 1\n  var arrLength = arr.length\n  var valLength = val.length\n\n  if (encoding !== undefined) {\n    encoding = String(encoding).toLowerCase()\n    if (encoding === 'ucs2' || encoding === 'ucs-2' ||\n        encoding === 'utf16le' || encoding === 'utf-16le') {\n      if (arr.length < 2 || val.length < 2) {\n        return -1\n      }\n      indexSize = 2\n      arrLength /= 2\n      valLength /= 2\n      byteOffset /= 2\n    }\n  }\n\n  function read (buf, i) {\n    if (indexSize === 1) {\n      return buf[i]\n    } else {\n      return buf.readUInt16BE(i * indexSize)\n    }\n  }\n\n  var i\n  if (dir) {\n    var foundIndex = -1\n    for (i = byteOffset; i < arrLength; i++) {\n      if (read(arr, i) === read(val, foundIndex === -1 ? 0 : i - foundIndex)) {\n        if (foundIndex === -1) foundIndex = i\n        if (i - foundIndex + 1 === valLength) return foundIndex * indexSize\n      } else {\n        if (foundIndex !== -1) i -= i - foundIndex\n        foundIndex = -1\n      }\n    }\n  } else {\n    if (byteOffset + valLength > arrLength) byteOffset = arrLength - valLength\n    for (i = byteOffset; i >= 0; i--) {\n      var found = true\n      for (var j = 0; j < valLength; j++) {\n        if (read(arr, i + j) !== read(val, j)) {\n          found = false\n          break\n        }\n      }\n      if (found) return i\n    }\n  }\n\n  return -1\n}\n\nBuffer.prototype.includes = function includes (val, byteOffset, encoding) {\n  return this.indexOf(val, byteOffset, encoding) !== -1\n}\n\nBuffer.prototype.indexOf = function indexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, true)\n}\n\nBuffer.prototype.lastIndexOf = function lastIndexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, false)\n}\n\nfunction hexWrite (buf, string, offset, length) {\n  offset = Number(offset) || 0\n  var remaining = buf.length - offset\n  if (!length) {\n    length = remaining\n  } else {\n    length = Number(length)\n    if (length > remaining) {\n      length = remaining\n    }\n  }\n\n  // must be an even number of digits\n  var strLen = string.length\n  if (strLen % 2 !== 0) throw new TypeError('Invalid hex string')\n\n  if (length > strLen / 2) {\n    length = strLen / 2\n  }\n  for (var i = 0; i < length; ++i) {\n    var parsed = parseInt(string.substr(i * 2, 2), 16)\n    if (isNaN(parsed)) return i\n    buf[offset + i] = parsed\n  }\n  return i\n}\n\nfunction utf8Write (buf, string, offset, length) {\n  return blitBuffer(utf8ToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nfunction asciiWrite (buf, string, offset, length) {\n  return blitBuffer(asciiToBytes(string), buf, offset, length)\n}\n\nfunction latin1Write (buf, string, offset, length) {\n  return asciiWrite(buf, string, offset, length)\n}\n\nfunction base64Write (buf, string, offset, length) {\n  return blitBuffer(base64ToBytes(string), buf, offset, length)\n}\n\nfunction ucs2Write (buf, string, offset, length) {\n  return blitBuffer(utf16leToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nBuffer.prototype.write = function write (string, offset, length, encoding) {\n  // Buffer#write(string)\n  if (offset === undefined) {\n    encoding = 'utf8'\n    length = this.length\n    offset = 0\n  // Buffer#write(string, encoding)\n  } else if (length === undefined && typeof offset === 'string') {\n    encoding = offset\n    length = this.length\n    offset = 0\n  // Buffer#write(string, offset[, length][, encoding])\n  } else if (isFinite(offset)) {\n    offset = offset | 0\n    if (isFinite(length)) {\n      length = length | 0\n      if (encoding === undefined) encoding = 'utf8'\n    } else {\n      encoding = length\n      length = undefined\n    }\n  // legacy write(string, encoding, offset, length) - remove in v0.13\n  } else {\n    throw new Error(\n      'Buffer.write(string, encoding, offset[, length]) is no longer supported'\n    )\n  }\n\n  var remaining = this.length - offset\n  if (length === undefined || length > remaining) length = remaining\n\n  if ((string.length > 0 && (length < 0 || offset < 0)) || offset > this.length) {\n    throw new RangeError('Attempt to write outside buffer bounds')\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'hex':\n        return hexWrite(this, string, offset, length)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Write(this, string, offset, length)\n\n      case 'ascii':\n        return asciiWrite(this, string, offset, length)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Write(this, string, offset, length)\n\n      case 'base64':\n        // Warning: maxLength not taken into account in base64Write\n        return base64Write(this, string, offset, length)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return ucs2Write(this, string, offset, length)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\nBuffer.prototype.toJSON = function toJSON () {\n  return {\n    type: 'Buffer',\n    data: Array.prototype.slice.call(this._arr || this, 0)\n  }\n}\n\nfunction base64Slice (buf, start, end) {\n  if (start === 0 && end === buf.length) {\n    return base64.fromByteArray(buf)\n  } else {\n    return base64.fromByteArray(buf.slice(start, end))\n  }\n}\n\nfunction utf8Slice (buf, start, end) {\n  end = Math.min(buf.length, end)\n  var res = []\n\n  var i = start\n  while (i < end) {\n    var firstByte = buf[i]\n    var codePoint = null\n    var bytesPerSequence = (firstByte > 0xEF) ? 4\n      : (firstByte > 0xDF) ? 3\n      : (firstByte > 0xBF) ? 2\n      : 1\n\n    if (i + bytesPerSequence <= end) {\n      var secondByte, thirdByte, fourthByte, tempCodePoint\n\n      switch (bytesPerSequence) {\n        case 1:\n          if (firstByte < 0x80) {\n            codePoint = firstByte\n          }\n          break\n        case 2:\n          secondByte = buf[i + 1]\n          if ((secondByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0x1F) << 0x6 | (secondByte & 0x3F)\n            if (tempCodePoint > 0x7F) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 3:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0xC | (secondByte & 0x3F) << 0x6 | (thirdByte & 0x3F)\n            if (tempCodePoint > 0x7FF && (tempCodePoint < 0xD800 || tempCodePoint > 0xDFFF)) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 4:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          fourthByte = buf[i + 3]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80 && (fourthByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0x12 | (secondByte & 0x3F) << 0xC | (thirdByte & 0x3F) << 0x6 | (fourthByte & 0x3F)\n            if (tempCodePoint > 0xFFFF && tempCodePoint < 0x110000) {\n              codePoint = tempCodePoint\n            }\n          }\n      }\n    }\n\n    if (codePoint === null) {\n      // we did not generate a valid codePoint so insert a\n      // replacement char (U+FFFD) and advance only 1 byte\n      codePoint = 0xFFFD\n      bytesPerSequence = 1\n    } else if (codePoint > 0xFFFF) {\n      // encode to utf16 (surrogate pair dance)\n      codePoint -= 0x10000\n      res.push(codePoint >>> 10 & 0x3FF | 0xD800)\n      codePoint = 0xDC00 | codePoint & 0x3FF\n    }\n\n    res.push(codePoint)\n    i += bytesPerSequence\n  }\n\n  return decodeCodePointsArray(res)\n}\n\n// Based on http://stackoverflow.com/a/22747272/680742, the browser with\n// the lowest limit is Chrome, with 0x10000 args.\n// We go 1 magnitude less, for safety\nvar MAX_ARGUMENTS_LENGTH = 0x1000\n\nfunction decodeCodePointsArray (codePoints) {\n  var len = codePoints.length\n  if (len <= MAX_ARGUMENTS_LENGTH) {\n    return String.fromCharCode.apply(String, codePoints) // avoid extra slice()\n  }\n\n  // Decode in chunks to avoid \"call stack size exceeded\".\n  var res = ''\n  var i = 0\n  while (i < len) {\n    res += String.fromCharCode.apply(\n      String,\n      codePoints.slice(i, i += MAX_ARGUMENTS_LENGTH)\n    )\n  }\n  return res\n}\n\nfunction asciiSlice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i] & 0x7F)\n  }\n  return ret\n}\n\nfunction latin1Slice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i])\n  }\n  return ret\n}\n\nfunction hexSlice (buf, start, end) {\n  var len = buf.length\n\n  if (!start || start < 0) start = 0\n  if (!end || end < 0 || end > len) end = len\n\n  var out = ''\n  for (var i = start; i < end; ++i) {\n    out += toHex(buf[i])\n  }\n  return out\n}\n\nfunction utf16leSlice (buf, start, end) {\n  var bytes = buf.slice(start, end)\n  var res = ''\n  for (var i = 0; i < bytes.length; i += 2) {\n    res += String.fromCharCode(bytes[i] + bytes[i + 1] * 256)\n  }\n  return res\n}\n\nBuffer.prototype.slice = function slice (start, end) {\n  var len = this.length\n  start = ~~start\n  end = end === undefined ? len : ~~end\n\n  if (start < 0) {\n    start += len\n    if (start < 0) start = 0\n  } else if (start > len) {\n    start = len\n  }\n\n  if (end < 0) {\n    end += len\n    if (end < 0) end = 0\n  } else if (end > len) {\n    end = len\n  }\n\n  if (end < start) end = start\n\n  var newBuf\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    newBuf = this.subarray(start, end)\n    newBuf.__proto__ = Buffer.prototype\n  } else {\n    var sliceLen = end - start\n    newBuf = new Buffer(sliceLen, undefined)\n    for (var i = 0; i < sliceLen; ++i) {\n      newBuf[i] = this[i + start]\n    }\n  }\n\n  return newBuf\n}\n\n/*\n * Need to make sure that buffer isn't trying to write out of bounds.\n */\nfunction checkOffset (offset, ext, length) {\n  if ((offset % 1) !== 0 || offset < 0) throw new RangeError('offset is not uint')\n  if (offset + ext > length) throw new RangeError('Trying to access beyond buffer length')\n}\n\nBuffer.prototype.readUIntLE = function readUIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUIntBE = function readUIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    checkOffset(offset, byteLength, this.length)\n  }\n\n  var val = this[offset + --byteLength]\n  var mul = 1\n  while (byteLength > 0 && (mul *= 0x100)) {\n    val += this[offset + --byteLength] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUInt8 = function readUInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  return this[offset]\n}\n\nBuffer.prototype.readUInt16LE = function readUInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return this[offset] | (this[offset + 1] << 8)\n}\n\nBuffer.prototype.readUInt16BE = function readUInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return (this[offset] << 8) | this[offset + 1]\n}\n\nBuffer.prototype.readUInt32LE = function readUInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return ((this[offset]) |\n      (this[offset + 1] << 8) |\n      (this[offset + 2] << 16)) +\n      (this[offset + 3] * 0x1000000)\n}\n\nBuffer.prototype.readUInt32BE = function readUInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] * 0x1000000) +\n    ((this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    this[offset + 3])\n}\n\nBuffer.prototype.readIntLE = function readIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readIntBE = function readIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var i = byteLength\n  var mul = 1\n  var val = this[offset + --i]\n  while (i > 0 && (mul *= 0x100)) {\n    val += this[offset + --i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readInt8 = function readInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  if (!(this[offset] & 0x80)) return (this[offset])\n  return ((0xff - this[offset] + 1) * -1)\n}\n\nBuffer.prototype.readInt16LE = function readInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset] | (this[offset + 1] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt16BE = function readInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset + 1] | (this[offset] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt32LE = function readInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset]) |\n    (this[offset + 1] << 8) |\n    (this[offset + 2] << 16) |\n    (this[offset + 3] << 24)\n}\n\nBuffer.prototype.readInt32BE = function readInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] << 24) |\n    (this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    (this[offset + 3])\n}\n\nBuffer.prototype.readFloatLE = function readFloatLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, true, 23, 4)\n}\n\nBuffer.prototype.readFloatBE = function readFloatBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, false, 23, 4)\n}\n\nBuffer.prototype.readDoubleLE = function readDoubleLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, true, 52, 8)\n}\n\nBuffer.prototype.readDoubleBE = function readDoubleBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, false, 52, 8)\n}\n\nfunction checkInt (buf, value, offset, ext, max, min) {\n  if (!Buffer.isBuffer(buf)) throw new TypeError('\"buffer\" argument must be a Buffer instance')\n  if (value > max || value < min) throw new RangeError('\"value\" argument is out of bounds')\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n}\n\nBuffer.prototype.writeUIntLE = function writeUIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var mul = 1\n  var i = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUIntBE = function writeUIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUInt8 = function writeUInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0xff, 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nfunction objectWriteUInt16 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 2); i < j; ++i) {\n    buf[offset + i] = (value & (0xff << (8 * (littleEndian ? i : 1 - i)))) >>>\n      (littleEndian ? i : 1 - i) * 8\n  }\n}\n\nBuffer.prototype.writeUInt16LE = function writeUInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeUInt16BE = function writeUInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nfunction objectWriteUInt32 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffffffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 4); i < j; ++i) {\n    buf[offset + i] = (value >>> (littleEndian ? i : 3 - i) * 8) & 0xff\n  }\n}\n\nBuffer.prototype.writeUInt32LE = function writeUInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset + 3] = (value >>> 24)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 1] = (value >>> 8)\n    this[offset] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeUInt32BE = function writeUInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeIntLE = function writeIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = 0\n  var mul = 1\n  var sub = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i - 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeIntBE = function writeIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  var sub = 0\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i + 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeInt8 = function writeInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0x7f, -0x80)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  if (value < 0) value = 0xff + value + 1\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nBuffer.prototype.writeInt16LE = function writeInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt16BE = function writeInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt32LE = function writeInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 3] = (value >>> 24)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeInt32BE = function writeInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (value < 0) value = 0xffffffff + value + 1\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nfunction checkIEEE754 (buf, value, offset, ext, max, min) {\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n  if (offset < 0) throw new RangeError('Index out of range')\n}\n\nfunction writeFloat (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 4, 3.4028234663852886e+38, -3.4028234663852886e+38)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 23, 4)\n  return offset + 4\n}\n\nBuffer.prototype.writeFloatLE = function writeFloatLE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeFloatBE = function writeFloatBE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, false, noAssert)\n}\n\nfunction writeDouble (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 8, 1.7976931348623157E+308, -1.7976931348623157E+308)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 52, 8)\n  return offset + 8\n}\n\nBuffer.prototype.writeDoubleLE = function writeDoubleLE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeDoubleBE = function writeDoubleBE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, false, noAssert)\n}\n\n// copy(targetBuffer, targetStart=0, sourceStart=0, sourceEnd=buffer.length)\nBuffer.prototype.copy = function copy (target, targetStart, start, end) {\n  if (!start) start = 0\n  if (!end && end !== 0) end = this.length\n  if (targetStart >= target.length) targetStart = target.length\n  if (!targetStart) targetStart = 0\n  if (end > 0 && end < start) end = start\n\n  // Copy 0 bytes; we're done\n  if (end === start) return 0\n  if (target.length === 0 || this.length === 0) return 0\n\n  // Fatal error conditions\n  if (targetStart < 0) {\n    throw new RangeError('targetStart out of bounds')\n  }\n  if (start < 0 || start >= this.length) throw new RangeError('sourceStart out of bounds')\n  if (end < 0) throw new RangeError('sourceEnd out of bounds')\n\n  // Are we oob?\n  if (end > this.length) end = this.length\n  if (target.length - targetStart < end - start) {\n    end = target.length - targetStart + start\n  }\n\n  var len = end - start\n  var i\n\n  if (this === target && start < targetStart && targetStart < end) {\n    // descending copy from end\n    for (i = len - 1; i >= 0; --i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else if (len < 1000 || !Buffer.TYPED_ARRAY_SUPPORT) {\n    // ascending copy from start\n    for (i = 0; i < len; ++i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else {\n    Uint8Array.prototype.set.call(\n      target,\n      this.subarray(start, start + len),\n      targetStart\n    )\n  }\n\n  return len\n}\n\n// Usage:\n//    buffer.fill(number[, offset[, end]])\n//    buffer.fill(buffer[, offset[, end]])\n//    buffer.fill(string[, offset[, end]][, encoding])\nBuffer.prototype.fill = function fill (val, start, end, encoding) {\n  // Handle string cases:\n  if (typeof val === 'string') {\n    if (typeof start === 'string') {\n      encoding = start\n      start = 0\n      end = this.length\n    } else if (typeof end === 'string') {\n      encoding = end\n      end = this.length\n    }\n    if (val.length === 1) {\n      var code = val.charCodeAt(0)\n      if (code < 256) {\n        val = code\n      }\n    }\n    if (encoding !== undefined && typeof encoding !== 'string') {\n      throw new TypeError('encoding must be a string')\n    }\n    if (typeof encoding === 'string' && !Buffer.isEncoding(encoding)) {\n      throw new TypeError('Unknown encoding: ' + encoding)\n    }\n  } else if (typeof val === 'number') {\n    val = val & 255\n  }\n\n  // Invalid ranges are not set to a default, so can range check early.\n  if (start < 0 || this.length < start || this.length < end) {\n    throw new RangeError('Out of range index')\n  }\n\n  if (end <= start) {\n    return this\n  }\n\n  start = start >>> 0\n  end = end === undefined ? this.length : end >>> 0\n\n  if (!val) val = 0\n\n  var i\n  if (typeof val === 'number') {\n    for (i = start; i < end; ++i) {\n      this[i] = val\n    }\n  } else {\n    var bytes = Buffer.isBuffer(val)\n      ? val\n      : utf8ToBytes(new Buffer(val, encoding).toString())\n    var len = bytes.length\n    for (i = 0; i < end - start; ++i) {\n      this[i + start] = bytes[i % len]\n    }\n  }\n\n  return this\n}\n\n// HELPER FUNCTIONS\n// ================\n\nvar INVALID_BASE64_RE = /[^+\\/0-9A-Za-z-_]/g\n\nfunction base64clean (str) {\n  // Node strips out invalid characters like \\n and \\t from the string, base64-js does not\n  str = stringtrim(str).replace(INVALID_BASE64_RE, '')\n  // Node converts strings with length < 2 to ''\n  if (str.length < 2) return ''\n  // Node allows for non-padded base64 strings (missing trailing ===), base64-js does not\n  while (str.length % 4 !== 0) {\n    str = str + '='\n  }\n  return str\n}\n\nfunction stringtrim (str) {\n  if (str.trim) return str.trim()\n  return str.replace(/^\\s+|\\s+$/g, '')\n}\n\nfunction toHex (n) {\n  if (n < 16) return '0' + n.toString(16)\n  return n.toString(16)\n}\n\nfunction utf8ToBytes (string, units) {\n  units = units || Infinity\n  var codePoint\n  var length = string.length\n  var leadSurrogate = null\n  var bytes = []\n\n  for (var i = 0; i < length; ++i) {\n    codePoint = string.charCodeAt(i)\n\n    // is surrogate component\n    if (codePoint > 0xD7FF && codePoint < 0xE000) {\n      // last char was a lead\n      if (!leadSurrogate) {\n        // no lead yet\n        if (codePoint > 0xDBFF) {\n          // unexpected trail\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        } else if (i + 1 === length) {\n          // unpaired lead\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        }\n\n        // valid lead\n        leadSurrogate = codePoint\n\n        continue\n      }\n\n      // 2 leads in a row\n      if (codePoint < 0xDC00) {\n        if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n        leadSurrogate = codePoint\n        continue\n      }\n\n      // valid surrogate pair\n      codePoint = (leadSurrogate - 0xD800 << 10 | codePoint - 0xDC00) + 0x10000\n    } else if (leadSurrogate) {\n      // valid bmp char, but last char was a lead\n      if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n    }\n\n    leadSurrogate = null\n\n    // encode utf8\n    if (codePoint < 0x80) {\n      if ((units -= 1) < 0) break\n      bytes.push(codePoint)\n    } else if (codePoint < 0x800) {\n      if ((units -= 2) < 0) break\n      bytes.push(\n        codePoint >> 0x6 | 0xC0,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x10000) {\n      if ((units -= 3) < 0) break\n      bytes.push(\n        codePoint >> 0xC | 0xE0,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x110000) {\n      if ((units -= 4) < 0) break\n      bytes.push(\n        codePoint >> 0x12 | 0xF0,\n        codePoint >> 0xC & 0x3F | 0x80,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else {\n      throw new Error('Invalid code point')\n    }\n  }\n\n  return bytes\n}\n\nfunction asciiToBytes (str) {\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    // Node's code seems to be doing this and not & 0x7F..\n    byteArray.push(str.charCodeAt(i) & 0xFF)\n  }\n  return byteArray\n}\n\nfunction utf16leToBytes (str, units) {\n  var c, hi, lo\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    if ((units -= 2) < 0) break\n\n    c = str.charCodeAt(i)\n    hi = c >> 8\n    lo = c % 256\n    byteArray.push(lo)\n    byteArray.push(hi)\n  }\n\n  return byteArray\n}\n\nfunction base64ToBytes (str) {\n  return base64.toByteArray(base64clean(str))\n}\n\nfunction blitBuffer (src, dst, offset, length) {\n  for (var i = 0; i < length; ++i) {\n    if ((i + offset >= dst.length) || (i >= src.length)) break\n    dst[i + offset] = src[i]\n  }\n  return i\n}\n\nfunction isnan (val) {\n  return val !== val // eslint-disable-line no-self-compare\n}\n","var toString = {}.toString;\n\nmodule.exports = Array.isArray || function (arr) {\n  return toString.call(arr) == '[object Array]';\n};\n","require('../../modules/core.regexp.escape');\nmodule.exports = require('../../modules/_core').RegExp.escape;\n","module.exports = function (it) {\n  if (typeof it != 'function') throw TypeError(it + ' is not a function!');\n  return it;\n};\n","var cof = require('./_cof');\nmodule.exports = function (it, msg) {\n  if (typeof it != 'number' && cof(it) != 'Number') throw TypeError(msg);\n  return +it;\n};\n","// 22.1.3.31 Array.prototype[@@unscopables]\nvar UNSCOPABLES = require('./_wks')('unscopables');\nvar ArrayProto = Array.prototype;\nif (ArrayProto[UNSCOPABLES] == undefined) require('./_hide')(ArrayProto, UNSCOPABLES, {});\nmodule.exports = function (key) {\n  ArrayProto[UNSCOPABLES][key] = true;\n};\n","'use strict';\nvar at = require('./_string-at')(true);\n\n // `AdvanceStringIndex` abstract operation\n// https://tc39.github.io/ecma262/#sec-advancestringindex\nmodule.exports = function (S, index, unicode) {\n  return index + (unicode ? at(S, index).length : 1);\n};\n","module.exports = function (it, Constructor, name, forbiddenField) {\n  if (!(it instanceof Constructor) || (forbiddenField !== undefined && forbiddenField in it)) {\n    throw TypeError(name + ': incorrect invocation!');\n  } return it;\n};\n","var isObject = require('./_is-object');\nmodule.exports = function (it) {\n  if (!isObject(it)) throw TypeError(it + ' is not an object!');\n  return it;\n};\n","// 22.1.3.3 Array.prototype.copyWithin(target, start, end = this.length)\n'use strict';\nvar toObject = require('./_to-object');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nvar toLength = require('./_to-length');\n\nmodule.exports = [].copyWithin || function copyWithin(target /* = 0 */, start /* = 0, end = @length */) {\n  var O = toObject(this);\n  var len = toLength(O.length);\n  var to = toAbsoluteIndex(target, len);\n  var from = toAbsoluteIndex(start, len);\n  var end = arguments.length > 2 ? arguments[2] : undefined;\n  var count = Math.min((end === undefined ? len : toAbsoluteIndex(end, len)) - from, len - to);\n  var inc = 1;\n  if (from < to && to < from + count) {\n    inc = -1;\n    from += count - 1;\n    to += count - 1;\n  }\n  while (count-- > 0) {\n    if (from in O) O[to] = O[from];\n    else delete O[to];\n    to += inc;\n    from += inc;\n  } return O;\n};\n","// 22.1.3.6 Array.prototype.fill(value, start = 0, end = this.length)\n'use strict';\nvar toObject = require('./_to-object');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nvar toLength = require('./_to-length');\nmodule.exports = function fill(value /* , start = 0, end = @length */) {\n  var O = toObject(this);\n  var length = toLength(O.length);\n  var aLen = arguments.length;\n  var index = toAbsoluteIndex(aLen > 1 ? arguments[1] : undefined, length);\n  var end = aLen > 2 ? arguments[2] : undefined;\n  var endPos = end === undefined ? length : toAbsoluteIndex(end, length);\n  while (endPos > index) O[index++] = value;\n  return O;\n};\n","var forOf = require('./_for-of');\n\nmodule.exports = function (iter, ITERATOR) {\n  var result = [];\n  forOf(iter, false, result.push, result, ITERATOR);\n  return result;\n};\n","// false -> Array#indexOf\n// true  -> Array#includes\nvar toIObject = require('./_to-iobject');\nvar toLength = require('./_to-length');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nmodule.exports = function (IS_INCLUDES) {\n  return function ($this, el, fromIndex) {\n    var O = toIObject($this);\n    var length = toLength(O.length);\n    var index = toAbsoluteIndex(fromIndex, length);\n    var value;\n    // Array#includes uses SameValueZero equality algorithm\n    // eslint-disable-next-line no-self-compare\n    if (IS_INCLUDES && el != el) while (length > index) {\n      value = O[index++];\n      // eslint-disable-next-line no-self-compare\n      if (value != value) return true;\n    // Array#indexOf ignores holes, Array#includes - not\n    } else for (;length > index; index++) if (IS_INCLUDES || index in O) {\n      if (O[index] === el) return IS_INCLUDES || index || 0;\n    } return !IS_INCLUDES && -1;\n  };\n};\n","// 0 -> Array#forEach\n// 1 -> Array#map\n// 2 -> Array#filter\n// 3 -> Array#some\n// 4 -> Array#every\n// 5 -> Array#find\n// 6 -> Array#findIndex\nvar ctx = require('./_ctx');\nvar IObject = require('./_iobject');\nvar toObject = require('./_to-object');\nvar toLength = require('./_to-length');\nvar asc = require('./_array-species-create');\nmodule.exports = function (TYPE, $create) {\n  var IS_MAP = TYPE == 1;\n  var IS_FILTER = TYPE == 2;\n  var IS_SOME = TYPE == 3;\n  var IS_EVERY = TYPE == 4;\n  var IS_FIND_INDEX = TYPE == 6;\n  var NO_HOLES = TYPE == 5 || IS_FIND_INDEX;\n  var create = $create || asc;\n  return function ($this, callbackfn, that) {\n    var O = toObject($this);\n    var self = IObject(O);\n    var f = ctx(callbackfn, that, 3);\n    var length = toLength(self.length);\n    var index = 0;\n    var result = IS_MAP ? create($this, length) : IS_FILTER ? create($this, 0) : undefined;\n    var val, res;\n    for (;length > index; index++) if (NO_HOLES || index in self) {\n      val = self[index];\n      res = f(val, index, O);\n      if (TYPE) {\n        if (IS_MAP) result[index] = res;   // map\n        else if (res) switch (TYPE) {\n          case 3: return true;             // some\n          case 5: return val;              // find\n          case 6: return index;            // findIndex\n          case 2: result.push(val);        // filter\n        } else if (IS_EVERY) return false; // every\n      }\n    }\n    return IS_FIND_INDEX ? -1 : IS_SOME || IS_EVERY ? IS_EVERY : result;\n  };\n};\n","var aFunction = require('./_a-function');\nvar toObject = require('./_to-object');\nvar IObject = require('./_iobject');\nvar toLength = require('./_to-length');\n\nmodule.exports = function (that, callbackfn, aLen, memo, isRight) {\n  aFunction(callbackfn);\n  var O = toObject(that);\n  var self = IObject(O);\n  var length = toLength(O.length);\n  var index = isRight ? length - 1 : 0;\n  var i = isRight ? -1 : 1;\n  if (aLen < 2) for (;;) {\n    if (index in self) {\n      memo = self[index];\n      index += i;\n      break;\n    }\n    index += i;\n    if (isRight ? index < 0 : length <= index) {\n      throw TypeError('Reduce of empty array with no initial value');\n    }\n  }\n  for (;isRight ? index >= 0 : length > index; index += i) if (index in self) {\n    memo = callbackfn(memo, self[index], index, O);\n  }\n  return memo;\n};\n","var isObject = require('./_is-object');\nvar isArray = require('./_is-array');\nvar SPECIES = require('./_wks')('species');\n\nmodule.exports = function (original) {\n  var C;\n  if (isArray(original)) {\n    C = original.constructor;\n    // cross-realm fallback\n    if (typeof C == 'function' && (C === Array || isArray(C.prototype))) C = undefined;\n    if (isObject(C)) {\n      C = C[SPECIES];\n      if (C === null) C = undefined;\n    }\n  } return C === undefined ? Array : C;\n};\n","// 9.4.2.3 ArraySpeciesCreate(originalArray, length)\nvar speciesConstructor = require('./_array-species-constructor');\n\nmodule.exports = function (original, length) {\n  return new (speciesConstructor(original))(length);\n};\n","'use strict';\nvar aFunction = require('./_a-function');\nvar isObject = require('./_is-object');\nvar invoke = require('./_invoke');\nvar arraySlice = [].slice;\nvar factories = {};\n\nvar construct = function (F, len, args) {\n  if (!(len in factories)) {\n    for (var n = [], i = 0; i < len; i++) n[i] = 'a[' + i + ']';\n    // eslint-disable-next-line no-new-func\n    factories[len] = Function('F,a', 'return new F(' + n.join(',') + ')');\n  } return factories[len](F, args);\n};\n\nmodule.exports = Function.bind || function bind(that /* , ...args */) {\n  var fn = aFunction(this);\n  var partArgs = arraySlice.call(arguments, 1);\n  var bound = function (/* args... */) {\n    var args = partArgs.concat(arraySlice.call(arguments));\n    return this instanceof bound ? construct(fn, args.length, args) : invoke(fn, args, that);\n  };\n  if (isObject(fn.prototype)) bound.prototype = fn.prototype;\n  return bound;\n};\n","// getting tag from 19.1.3.6 Object.prototype.toString()\nvar cof = require('./_cof');\nvar TAG = require('./_wks')('toStringTag');\n// ES3 wrong here\nvar ARG = cof(function () { return arguments; }()) == 'Arguments';\n\n// fallback for IE11 Script Access Denied error\nvar tryGet = function (it, key) {\n  try {\n    return it[key];\n  } catch (e) { /* empty */ }\n};\n\nmodule.exports = function (it) {\n  var O, T, B;\n  return it === undefined ? 'Undefined' : it === null ? 'Null'\n    // @@toStringTag case\n    : typeof (T = tryGet(O = Object(it), TAG)) == 'string' ? T\n    // builtinTag case\n    : ARG ? cof(O)\n    // ES3 arguments fallback\n    : (B = cof(O)) == 'Object' && typeof O.callee == 'function' ? 'Arguments' : B;\n};\n","var toString = {}.toString;\n\nmodule.exports = function (it) {\n  return toString.call(it).slice(8, -1);\n};\n","'use strict';\nvar dP = require('./_object-dp').f;\nvar create = require('./_object-create');\nvar redefineAll = require('./_redefine-all');\nvar ctx = require('./_ctx');\nvar anInstance = require('./_an-instance');\nvar forOf = require('./_for-of');\nvar $iterDefine = require('./_iter-define');\nvar step = require('./_iter-step');\nvar setSpecies = require('./_set-species');\nvar DESCRIPTORS = require('./_descriptors');\nvar fastKey = require('./_meta').fastKey;\nvar validate = require('./_validate-collection');\nvar SIZE = DESCRIPTORS ? '_s' : 'size';\n\nvar getEntry = function (that, key) {\n  // fast case\n  var index = fastKey(key);\n  var entry;\n  if (index !== 'F') return that._i[index];\n  // frozen object case\n  for (entry = that._f; entry; entry = entry.n) {\n    if (entry.k == key) return entry;\n  }\n};\n\nmodule.exports = {\n  getConstructor: function (wrapper, NAME, IS_MAP, ADDER) {\n    var C = wrapper(function (that, iterable) {\n      anInstance(that, C, NAME, '_i');\n      that._t = NAME;         // collection type\n      that._i = create(null); // index\n      that._f = undefined;    // first entry\n      that._l = undefined;    // last entry\n      that[SIZE] = 0;         // size\n      if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n    });\n    redefineAll(C.prototype, {\n      // 23.1.3.1 Map.prototype.clear()\n      // 23.2.3.2 Set.prototype.clear()\n      clear: function clear() {\n        for (var that = validate(this, NAME), data = that._i, entry = that._f; entry; entry = entry.n) {\n          entry.r = true;\n          if (entry.p) entry.p = entry.p.n = undefined;\n          delete data[entry.i];\n        }\n        that._f = that._l = undefined;\n        that[SIZE] = 0;\n      },\n      // 23.1.3.3 Map.prototype.delete(key)\n      // 23.2.3.4 Set.prototype.delete(value)\n      'delete': function (key) {\n        var that = validate(this, NAME);\n        var entry = getEntry(that, key);\n        if (entry) {\n          var next = entry.n;\n          var prev = entry.p;\n          delete that._i[entry.i];\n          entry.r = true;\n          if (prev) prev.n = next;\n          if (next) next.p = prev;\n          if (that._f == entry) that._f = next;\n          if (that._l == entry) that._l = prev;\n          that[SIZE]--;\n        } return !!entry;\n      },\n      // 23.2.3.6 Set.prototype.forEach(callbackfn, thisArg = undefined)\n      // 23.1.3.5 Map.prototype.forEach(callbackfn, thisArg = undefined)\n      forEach: function forEach(callbackfn /* , that = undefined */) {\n        validate(this, NAME);\n        var f = ctx(callbackfn, arguments.length > 1 ? arguments[1] : undefined, 3);\n        var entry;\n        while (entry = entry ? entry.n : this._f) {\n          f(entry.v, entry.k, this);\n          // revert to the last existing entry\n          while (entry && entry.r) entry = entry.p;\n        }\n      },\n      // 23.1.3.7 Map.prototype.has(key)\n      // 23.2.3.7 Set.prototype.has(value)\n      has: function has(key) {\n        return !!getEntry(validate(this, NAME), key);\n      }\n    });\n    if (DESCRIPTORS) dP(C.prototype, 'size', {\n      get: function () {\n        return validate(this, NAME)[SIZE];\n      }\n    });\n    return C;\n  },\n  def: function (that, key, value) {\n    var entry = getEntry(that, key);\n    var prev, index;\n    // change existing entry\n    if (entry) {\n      entry.v = value;\n    // create new entry\n    } else {\n      that._l = entry = {\n        i: index = fastKey(key, true), // <- index\n        k: key,                        // <- key\n        v: value,                      // <- value\n        p: prev = that._l,             // <- previous entry\n        n: undefined,                  // <- next entry\n        r: false                       // <- removed\n      };\n      if (!that._f) that._f = entry;\n      if (prev) prev.n = entry;\n      that[SIZE]++;\n      // add to index\n      if (index !== 'F') that._i[index] = entry;\n    } return that;\n  },\n  getEntry: getEntry,\n  setStrong: function (C, NAME, IS_MAP) {\n    // add .keys, .values, .entries, [@@iterator]\n    // 23.1.3.4, 23.1.3.8, 23.1.3.11, 23.1.3.12, 23.2.3.5, 23.2.3.8, 23.2.3.10, 23.2.3.11\n    $iterDefine(C, NAME, function (iterated, kind) {\n      this._t = validate(iterated, NAME); // target\n      this._k = kind;                     // kind\n      this._l = undefined;                // previous\n    }, function () {\n      var that = this;\n      var kind = that._k;\n      var entry = that._l;\n      // revert to the last existing entry\n      while (entry && entry.r) entry = entry.p;\n      // get next entry\n      if (!that._t || !(that._l = entry = entry ? entry.n : that._t._f)) {\n        // or finish the iteration\n        that._t = undefined;\n        return step(1);\n      }\n      // return step by kind\n      if (kind == 'keys') return step(0, entry.k);\n      if (kind == 'values') return step(0, entry.v);\n      return step(0, [entry.k, entry.v]);\n    }, IS_MAP ? 'entries' : 'values', !IS_MAP, true);\n\n    // add [@@species], 23.1.2.2, 23.2.2.2\n    setSpecies(NAME);\n  }\n};\n","// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar classof = require('./_classof');\nvar from = require('./_array-from-iterable');\nmodule.exports = function (NAME) {\n  return function toJSON() {\n    if (classof(this) != NAME) throw TypeError(NAME + \"#toJSON isn't generic\");\n    return from(this);\n  };\n};\n","'use strict';\nvar redefineAll = require('./_redefine-all');\nvar getWeak = require('./_meta').getWeak;\nvar anObject = require('./_an-object');\nvar isObject = require('./_is-object');\nvar anInstance = require('./_an-instance');\nvar forOf = require('./_for-of');\nvar createArrayMethod = require('./_array-methods');\nvar $has = require('./_has');\nvar validate = require('./_validate-collection');\nvar arrayFind = createArrayMethod(5);\nvar arrayFindIndex = createArrayMethod(6);\nvar id = 0;\n\n// fallback for uncaught frozen keys\nvar uncaughtFrozenStore = function (that) {\n  return that._l || (that._l = new UncaughtFrozenStore());\n};\nvar UncaughtFrozenStore = function () {\n  this.a = [];\n};\nvar findUncaughtFrozen = function (store, key) {\n  return arrayFind(store.a, function (it) {\n    return it[0] === key;\n  });\n};\nUncaughtFrozenStore.prototype = {\n  get: function (key) {\n    var entry = findUncaughtFrozen(this, key);\n    if (entry) return entry[1];\n  },\n  has: function (key) {\n    return !!findUncaughtFrozen(this, key);\n  },\n  set: function (key, value) {\n    var entry = findUncaughtFrozen(this, key);\n    if (entry) entry[1] = value;\n    else this.a.push([key, value]);\n  },\n  'delete': function (key) {\n    var index = arrayFindIndex(this.a, function (it) {\n      return it[0] === key;\n    });\n    if (~index) this.a.splice(index, 1);\n    return !!~index;\n  }\n};\n\nmodule.exports = {\n  getConstructor: function (wrapper, NAME, IS_MAP, ADDER) {\n    var C = wrapper(function (that, iterable) {\n      anInstance(that, C, NAME, '_i');\n      that._t = NAME;      // collection type\n      that._i = id++;      // collection id\n      that._l = undefined; // leak store for uncaught frozen objects\n      if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n    });\n    redefineAll(C.prototype, {\n      // 23.3.3.2 WeakMap.prototype.delete(key)\n      // 23.4.3.3 WeakSet.prototype.delete(value)\n      'delete': function (key) {\n        if (!isObject(key)) return false;\n        var data = getWeak(key);\n        if (data === true) return uncaughtFrozenStore(validate(this, NAME))['delete'](key);\n        return data && $has(data, this._i) && delete data[this._i];\n      },\n      // 23.3.3.4 WeakMap.prototype.has(key)\n      // 23.4.3.4 WeakSet.prototype.has(value)\n      has: function has(key) {\n        if (!isObject(key)) return false;\n        var data = getWeak(key);\n        if (data === true) return uncaughtFrozenStore(validate(this, NAME)).has(key);\n        return data && $has(data, this._i);\n      }\n    });\n    return C;\n  },\n  def: function (that, key, value) {\n    var data = getWeak(anObject(key), true);\n    if (data === true) uncaughtFrozenStore(that).set(key, value);\n    else data[that._i] = value;\n    return that;\n  },\n  ufstore: uncaughtFrozenStore\n};\n","'use strict';\nvar global = require('./_global');\nvar $export = require('./_export');\nvar redefine = require('./_redefine');\nvar redefineAll = require('./_redefine-all');\nvar meta = require('./_meta');\nvar forOf = require('./_for-of');\nvar anInstance = require('./_an-instance');\nvar isObject = require('./_is-object');\nvar fails = require('./_fails');\nvar $iterDetect = require('./_iter-detect');\nvar setToStringTag = require('./_set-to-string-tag');\nvar inheritIfRequired = require('./_inherit-if-required');\n\nmodule.exports = function (NAME, wrapper, methods, common, IS_MAP, IS_WEAK) {\n  var Base = global[NAME];\n  var C = Base;\n  var ADDER = IS_MAP ? 'set' : 'add';\n  var proto = C && C.prototype;\n  var O = {};\n  var fixMethod = function (KEY) {\n    var fn = proto[KEY];\n    redefine(proto, KEY,\n      KEY == 'delete' ? function (a) {\n        return IS_WEAK && !isObject(a) ? false : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'has' ? function has(a) {\n        return IS_WEAK && !isObject(a) ? false : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'get' ? function get(a) {\n        return IS_WEAK && !isObject(a) ? undefined : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'add' ? function add(a) { fn.call(this, a === 0 ? 0 : a); return this; }\n        : function set(a, b) { fn.call(this, a === 0 ? 0 : a, b); return this; }\n    );\n  };\n  if (typeof C != 'function' || !(IS_WEAK || proto.forEach && !fails(function () {\n    new C().entries().next();\n  }))) {\n    // create collection constructor\n    C = common.getConstructor(wrapper, NAME, IS_MAP, ADDER);\n    redefineAll(C.prototype, methods);\n    meta.NEED = true;\n  } else {\n    var instance = new C();\n    // early implementations not supports chaining\n    var HASNT_CHAINING = instance[ADDER](IS_WEAK ? {} : -0, 1) != instance;\n    // V8 ~  Chromium 40- weak-collections throws on primitives, but should return false\n    var THROWS_ON_PRIMITIVES = fails(function () { instance.has(1); });\n    // most early implementations doesn't supports iterables, most modern - not close it correctly\n    var ACCEPT_ITERABLES = $iterDetect(function (iter) { new C(iter); }); // eslint-disable-line no-new\n    // for early implementations -0 and +0 not the same\n    var BUGGY_ZERO = !IS_WEAK && fails(function () {\n      // V8 ~ Chromium 42- fails only with 5+ elements\n      var $instance = new C();\n      var index = 5;\n      while (index--) $instance[ADDER](index, index);\n      return !$instance.has(-0);\n    });\n    if (!ACCEPT_ITERABLES) {\n      C = wrapper(function (target, iterable) {\n        anInstance(target, C, NAME);\n        var that = inheritIfRequired(new Base(), target, C);\n        if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n        return that;\n      });\n      C.prototype = proto;\n      proto.constructor = C;\n    }\n    if (THROWS_ON_PRIMITIVES || BUGGY_ZERO) {\n      fixMethod('delete');\n      fixMethod('has');\n      IS_MAP && fixMethod('get');\n    }\n    if (BUGGY_ZERO || HASNT_CHAINING) fixMethod(ADDER);\n    // weak collections should not contains .clear method\n    if (IS_WEAK && proto.clear) delete proto.clear;\n  }\n\n  setToStringTag(C, NAME);\n\n  O[NAME] = C;\n  $export($export.G + $export.W + $export.F * (C != Base), O);\n\n  if (!IS_WEAK) common.setStrong(C, NAME, IS_MAP);\n\n  return C;\n};\n","var core = module.exports = { version: '2.6.4' };\nif (typeof __e == 'number') __e = core; // eslint-disable-line no-undef\n","'use strict';\nvar $defineProperty = require('./_object-dp');\nvar createDesc = require('./_property-desc');\n\nmodule.exports = function (object, index, value) {\n  if (index in object) $defineProperty.f(object, index, createDesc(0, value));\n  else object[index] = value;\n};\n","// optional / simple context binding\nvar aFunction = require('./_a-function');\nmodule.exports = function (fn, that, length) {\n  aFunction(fn);\n  if (that === undefined) return fn;\n  switch (length) {\n    case 1: return function (a) {\n      return fn.call(that, a);\n    };\n    case 2: return function (a, b) {\n      return fn.call(that, a, b);\n    };\n    case 3: return function (a, b, c) {\n      return fn.call(that, a, b, c);\n    };\n  }\n  return function (/* ...args */) {\n    return fn.apply(that, arguments);\n  };\n};\n","'use strict';\n// 20.3.4.36 / 15.9.5.43 Date.prototype.toISOString()\nvar fails = require('./_fails');\nvar getTime = Date.prototype.getTime;\nvar $toISOString = Date.prototype.toISOString;\n\nvar lz = function (num) {\n  return num > 9 ? num : '0' + num;\n};\n\n// PhantomJS / old WebKit has a broken implementations\nmodule.exports = (fails(function () {\n  return $toISOString.call(new Date(-5e13 - 1)) != '0385-07-25T07:06:39.999Z';\n}) || !fails(function () {\n  $toISOString.call(new Date(NaN));\n})) ? function toISOString() {\n  if (!isFinite(getTime.call(this))) throw RangeError('Invalid time value');\n  var d = this;\n  var y = d.getUTCFullYear();\n  var m = d.getUTCMilliseconds();\n  var s = y < 0 ? '-' : y > 9999 ? '+' : '';\n  return s + ('00000' + Math.abs(y)).slice(s ? -6 : -4) +\n    '-' + lz(d.getUTCMonth() + 1) + '-' + lz(d.getUTCDate()) +\n    'T' + lz(d.getUTCHours()) + ':' + lz(d.getUTCMinutes()) +\n    ':' + lz(d.getUTCSeconds()) + '.' + (m > 99 ? m : '0' + lz(m)) + 'Z';\n} : $toISOString;\n","'use strict';\nvar anObject = require('./_an-object');\nvar toPrimitive = require('./_to-primitive');\nvar NUMBER = 'number';\n\nmodule.exports = function (hint) {\n  if (hint !== 'string' && hint !== NUMBER && hint !== 'default') throw TypeError('Incorrect hint');\n  return toPrimitive(anObject(this), hint != NUMBER);\n};\n","// 7.2.1 RequireObjectCoercible(argument)\nmodule.exports = function (it) {\n  if (it == undefined) throw TypeError(\"Can't call method on  \" + it);\n  return it;\n};\n","// Thank's IE8 for his funny defineProperty\nmodule.exports = !require('./_fails')(function () {\n  return Object.defineProperty({}, 'a', { get: function () { return 7; } }).a != 7;\n});\n","var isObject = require('./_is-object');\nvar document = require('./_global').document;\n// typeof document.createElement is 'object' in old IE\nvar is = isObject(document) && isObject(document.createElement);\nmodule.exports = function (it) {\n  return is ? document.createElement(it) : {};\n};\n","// IE 8- don't enum bug keys\nmodule.exports = (\n  'constructor,hasOwnProperty,isPrototypeOf,propertyIsEnumerable,toLocaleString,toString,valueOf'\n).split(',');\n","// all enumerable object keys, includes symbols\nvar getKeys = require('./_object-keys');\nvar gOPS = require('./_object-gops');\nvar pIE = require('./_object-pie');\nmodule.exports = function (it) {\n  var result = getKeys(it);\n  var getSymbols = gOPS.f;\n  if (getSymbols) {\n    var symbols = getSymbols(it);\n    var isEnum = pIE.f;\n    var i = 0;\n    var key;\n    while (symbols.length > i) if (isEnum.call(it, key = symbols[i++])) result.push(key);\n  } return result;\n};\n","var global = require('./_global');\nvar core = require('./_core');\nvar hide = require('./_hide');\nvar redefine = require('./_redefine');\nvar ctx = require('./_ctx');\nvar PROTOTYPE = 'prototype';\n\nvar $export = function (type, name, source) {\n  var IS_FORCED = type & $export.F;\n  var IS_GLOBAL = type & $export.G;\n  var IS_STATIC = type & $export.S;\n  var IS_PROTO = type & $export.P;\n  var IS_BIND = type & $export.B;\n  var target = IS_GLOBAL ? global : IS_STATIC ? global[name] || (global[name] = {}) : (global[name] || {})[PROTOTYPE];\n  var exports = IS_GLOBAL ? core : core[name] || (core[name] = {});\n  var expProto = exports[PROTOTYPE] || (exports[PROTOTYPE] = {});\n  var key, own, out, exp;\n  if (IS_GLOBAL) source = name;\n  for (key in source) {\n    // contains in native\n    own = !IS_FORCED && target && target[key] !== undefined;\n    // export native or passed\n    out = (own ? target : source)[key];\n    // bind timers to global for call from export context\n    exp = IS_BIND && own ? ctx(out, global) : IS_PROTO && typeof out == 'function' ? ctx(Function.call, out) : out;\n    // extend global\n    if (target) redefine(target, key, out, type & $export.U);\n    // export\n    if (exports[key] != out) hide(exports, key, exp);\n    if (IS_PROTO && expProto[key] != out) expProto[key] = out;\n  }\n};\nglobal.core = core;\n// type bitmap\n$export.F = 1;   // forced\n$export.G = 2;   // global\n$export.S = 4;   // static\n$export.P = 8;   // proto\n$export.B = 16;  // bind\n$export.W = 32;  // wrap\n$export.U = 64;  // safe\n$export.R = 128; // real proto method for `library`\nmodule.exports = $export;\n","var MATCH = require('./_wks')('match');\nmodule.exports = function (KEY) {\n  var re = /./;\n  try {\n    '/./'[KEY](re);\n  } catch (e) {\n    try {\n      re[MATCH] = false;\n      return !'/./'[KEY](re);\n    } catch (f) { /* empty */ }\n  } return true;\n};\n","module.exports = function (exec) {\n  try {\n    return !!exec();\n  } catch (e) {\n    return true;\n  }\n};\n","'use strict';\nrequire('./es6.regexp.exec');\nvar redefine = require('./_redefine');\nvar hide = require('./_hide');\nvar fails = require('./_fails');\nvar defined = require('./_defined');\nvar wks = require('./_wks');\nvar regexpExec = require('./_regexp-exec');\n\nvar SPECIES = wks('species');\n\nvar REPLACE_SUPPORTS_NAMED_GROUPS = !fails(function () {\n  // #replace needs built-in support for named groups.\n  // #match works fine because it just return the exec results, even if it has\n  // a \"grops\" property.\n  var re = /./;\n  re.exec = function () {\n    var result = [];\n    result.groups = { a: '7' };\n    return result;\n  };\n  return ''.replace(re, '$<a>') !== '7';\n});\n\nvar SPLIT_WORKS_WITH_OVERWRITTEN_EXEC = (function () {\n  // Chrome 51 has a buggy \"split\" implementation when RegExp#exec !== nativeExec\n  var re = /(?:)/;\n  var originalExec = re.exec;\n  re.exec = function () { return originalExec.apply(this, arguments); };\n  var result = 'ab'.split(re);\n  return result.length === 2 && result[0] === 'a' && result[1] === 'b';\n})();\n\nmodule.exports = function (KEY, length, exec) {\n  var SYMBOL = wks(KEY);\n\n  var DELEGATES_TO_SYMBOL = !fails(function () {\n    // String methods call symbol-named RegEp methods\n    var O = {};\n    O[SYMBOL] = function () { return 7; };\n    return ''[KEY](O) != 7;\n  });\n\n  var DELEGATES_TO_EXEC = DELEGATES_TO_SYMBOL ? !fails(function () {\n    // Symbol-named RegExp methods call .exec\n    var execCalled = false;\n    var re = /a/;\n    re.exec = function () { execCalled = true; return null; };\n    if (KEY === 'split') {\n      // RegExp[@@split] doesn't call the regex's exec method, but first creates\n      // a new one. We need to return the patched regex when creating the new one.\n      re.constructor = {};\n      re.constructor[SPECIES] = function () { return re; };\n    }\n    re[SYMBOL]('');\n    return !execCalled;\n  }) : undefined;\n\n  if (\n    !DELEGATES_TO_SYMBOL ||\n    !DELEGATES_TO_EXEC ||\n    (KEY === 'replace' && !REPLACE_SUPPORTS_NAMED_GROUPS) ||\n    (KEY === 'split' && !SPLIT_WORKS_WITH_OVERWRITTEN_EXEC)\n  ) {\n    var nativeRegExpMethod = /./[SYMBOL];\n    var fns = exec(\n      defined,\n      SYMBOL,\n      ''[KEY],\n      function maybeCallNative(nativeMethod, regexp, str, arg2, forceStringMethod) {\n        if (regexp.exec === regexpExec) {\n          if (DELEGATES_TO_SYMBOL && !forceStringMethod) {\n            // The native String method already delegates to @@method (this\n            // polyfilled function), leasing to infinite recursion.\n            // We avoid it by directly calling the native @@method method.\n            return { done: true, value: nativeRegExpMethod.call(regexp, str, arg2) };\n          }\n          return { done: true, value: nativeMethod.call(str, regexp, arg2) };\n        }\n        return { done: false };\n      }\n    );\n    var strfn = fns[0];\n    var rxfn = fns[1];\n\n    redefine(String.prototype, KEY, strfn);\n    hide(RegExp.prototype, SYMBOL, length == 2\n      // 21.2.5.8 RegExp.prototype[@@replace](string, replaceValue)\n      // 21.2.5.11 RegExp.prototype[@@split](string, limit)\n      ? function (string, arg) { return rxfn.call(string, this, arg); }\n      // 21.2.5.6 RegExp.prototype[@@match](string)\n      // 21.2.5.9 RegExp.prototype[@@search](string)\n      : function (string) { return rxfn.call(string, this); }\n    );\n  }\n};\n","'use strict';\n// 21.2.5.3 get RegExp.prototype.flags\nvar anObject = require('./_an-object');\nmodule.exports = function () {\n  var that = anObject(this);\n  var result = '';\n  if (that.global) result += 'g';\n  if (that.ignoreCase) result += 'i';\n  if (that.multiline) result += 'm';\n  if (that.unicode) result += 'u';\n  if (that.sticky) result += 'y';\n  return result;\n};\n","'use strict';\n// https://tc39.github.io/proposal-flatMap/#sec-FlattenIntoArray\nvar isArray = require('./_is-array');\nvar isObject = require('./_is-object');\nvar toLength = require('./_to-length');\nvar ctx = require('./_ctx');\nvar IS_CONCAT_SPREADABLE = require('./_wks')('isConcatSpreadable');\n\nfunction flattenIntoArray(target, original, source, sourceLen, start, depth, mapper, thisArg) {\n  var targetIndex = start;\n  var sourceIndex = 0;\n  var mapFn = mapper ? ctx(mapper, thisArg, 3) : false;\n  var element, spreadable;\n\n  while (sourceIndex < sourceLen) {\n    if (sourceIndex in source) {\n      element = mapFn ? mapFn(source[sourceIndex], sourceIndex, original) : source[sourceIndex];\n\n      spreadable = false;\n      if (isObject(element)) {\n        spreadable = element[IS_CONCAT_SPREADABLE];\n        spreadable = spreadable !== undefined ? !!spreadable : isArray(element);\n      }\n\n      if (spreadable && depth > 0) {\n        targetIndex = flattenIntoArray(target, original, element, toLength(element.length), targetIndex, depth - 1) - 1;\n      } else {\n        if (targetIndex >= 0x1fffffffffffff) throw TypeError();\n        target[targetIndex] = element;\n      }\n\n      targetIndex++;\n    }\n    sourceIndex++;\n  }\n  return targetIndex;\n}\n\nmodule.exports = flattenIntoArray;\n","var ctx = require('./_ctx');\nvar call = require('./_iter-call');\nvar isArrayIter = require('./_is-array-iter');\nvar anObject = require('./_an-object');\nvar toLength = require('./_to-length');\nvar getIterFn = require('./core.get-iterator-method');\nvar BREAK = {};\nvar RETURN = {};\nvar exports = module.exports = function (iterable, entries, fn, that, ITERATOR) {\n  var iterFn = ITERATOR ? function () { return iterable; } : getIterFn(iterable);\n  var f = ctx(fn, that, entries ? 2 : 1);\n  var index = 0;\n  var length, step, iterator, result;\n  if (typeof iterFn != 'function') throw TypeError(iterable + ' is not iterable!');\n  // fast case for arrays with default iterator\n  if (isArrayIter(iterFn)) for (length = toLength(iterable.length); length > index; index++) {\n    result = entries ? f(anObject(step = iterable[index])[0], step[1]) : f(iterable[index]);\n    if (result === BREAK || result === RETURN) return result;\n  } else for (iterator = iterFn.call(iterable); !(step = iterator.next()).done;) {\n    result = call(iterator, f, step.value, entries);\n    if (result === BREAK || result === RETURN) return result;\n  }\n};\nexports.BREAK = BREAK;\nexports.RETURN = RETURN;\n","module.exports = require('./_shared')('native-function-to-string', Function.toString);\n","// https://github.com/zloirock/core-js/issues/86#issuecomment-115759028\nvar global = module.exports = typeof window != 'undefined' && window.Math == Math\n  ? window : typeof self != 'undefined' && self.Math == Math ? self\n  // eslint-disable-next-line no-new-func\n  : Function('return this')();\nif (typeof __g == 'number') __g = global; // eslint-disable-line no-undef\n","var hasOwnProperty = {}.hasOwnProperty;\nmodule.exports = function (it, key) {\n  return hasOwnProperty.call(it, key);\n};\n","var dP = require('./_object-dp');\nvar createDesc = require('./_property-desc');\nmodule.exports = require('./_descriptors') ? function (object, key, value) {\n  return dP.f(object, key, createDesc(1, value));\n} : function (object, key, value) {\n  object[key] = value;\n  return object;\n};\n","var document = require('./_global').document;\nmodule.exports = document && document.documentElement;\n","module.exports = !require('./_descriptors') && !require('./_fails')(function () {\n  return Object.defineProperty(require('./_dom-create')('div'), 'a', { get: function () { return 7; } }).a != 7;\n});\n","var isObject = require('./_is-object');\nvar setPrototypeOf = require('./_set-proto').set;\nmodule.exports = function (that, target, C) {\n  var S = target.constructor;\n  var P;\n  if (S !== C && typeof S == 'function' && (P = S.prototype) !== C.prototype && isObject(P) && setPrototypeOf) {\n    setPrototypeOf(that, P);\n  } return that;\n};\n","// fast apply, http://jsperf.lnkit.com/fast-apply/5\nmodule.exports = function (fn, args, that) {\n  var un = that === undefined;\n  switch (args.length) {\n    case 0: return un ? fn()\n                      : fn.call(that);\n    case 1: return un ? fn(args[0])\n                      : fn.call(that, args[0]);\n    case 2: return un ? fn(args[0], args[1])\n                      : fn.call(that, args[0], args[1]);\n    case 3: return un ? fn(args[0], args[1], args[2])\n                      : fn.call(that, args[0], args[1], args[2]);\n    case 4: return un ? fn(args[0], args[1], args[2], args[3])\n                      : fn.call(that, args[0], args[1], args[2], args[3]);\n  } return fn.apply(that, args);\n};\n","// fallback for non-array-like ES3 and non-enumerable old V8 strings\nvar cof = require('./_cof');\n// eslint-disable-next-line no-prototype-builtins\nmodule.exports = Object('z').propertyIsEnumerable(0) ? Object : function (it) {\n  return cof(it) == 'String' ? it.split('') : Object(it);\n};\n","// check on default Array iterator\nvar Iterators = require('./_iterators');\nvar ITERATOR = require('./_wks')('iterator');\nvar ArrayProto = Array.prototype;\n\nmodule.exports = function (it) {\n  return it !== undefined && (Iterators.Array === it || ArrayProto[ITERATOR] === it);\n};\n","// 7.2.2 IsArray(argument)\nvar cof = require('./_cof');\nmodule.exports = Array.isArray || function isArray(arg) {\n  return cof(arg) == 'Array';\n};\n","// 20.1.2.3 Number.isInteger(number)\nvar isObject = require('./_is-object');\nvar floor = Math.floor;\nmodule.exports = function isInteger(it) {\n  return !isObject(it) && isFinite(it) && floor(it) === it;\n};\n","module.exports = function (it) {\n  return typeof it === 'object' ? it !== null : typeof it === 'function';\n};\n","// 7.2.8 IsRegExp(argument)\nvar isObject = require('./_is-object');\nvar cof = require('./_cof');\nvar MATCH = require('./_wks')('match');\nmodule.exports = function (it) {\n  var isRegExp;\n  return isObject(it) && ((isRegExp = it[MATCH]) !== undefined ? !!isRegExp : cof(it) == 'RegExp');\n};\n","// call something on iterator step with safe closing on error\nvar anObject = require('./_an-object');\nmodule.exports = function (iterator, fn, value, entries) {\n  try {\n    return entries ? fn(anObject(value)[0], value[1]) : fn(value);\n  // 7.4.6 IteratorClose(iterator, completion)\n  } catch (e) {\n    var ret = iterator['return'];\n    if (ret !== undefined) anObject(ret.call(iterator));\n    throw e;\n  }\n};\n","'use strict';\nvar create = require('./_object-create');\nvar descriptor = require('./_property-desc');\nvar setToStringTag = require('./_set-to-string-tag');\nvar IteratorPrototype = {};\n\n// 25.1.2.1.1 %IteratorPrototype%[@@iterator]()\nrequire('./_hide')(IteratorPrototype, require('./_wks')('iterator'), function () { return this; });\n\nmodule.exports = function (Constructor, NAME, next) {\n  Constructor.prototype = create(IteratorPrototype, { next: descriptor(1, next) });\n  setToStringTag(Constructor, NAME + ' Iterator');\n};\n","'use strict';\nvar LIBRARY = require('./_library');\nvar $export = require('./_export');\nvar redefine = require('./_redefine');\nvar hide = require('./_hide');\nvar Iterators = require('./_iterators');\nvar $iterCreate = require('./_iter-create');\nvar setToStringTag = require('./_set-to-string-tag');\nvar getPrototypeOf = require('./_object-gpo');\nvar ITERATOR = require('./_wks')('iterator');\nvar BUGGY = !([].keys && 'next' in [].keys()); // Safari has buggy iterators w/o `next`\nvar FF_ITERATOR = '@@iterator';\nvar KEYS = 'keys';\nvar VALUES = 'values';\n\nvar returnThis = function () { return this; };\n\nmodule.exports = function (Base, NAME, Constructor, next, DEFAULT, IS_SET, FORCED) {\n  $iterCreate(Constructor, NAME, next);\n  var getMethod = function (kind) {\n    if (!BUGGY && kind in proto) return proto[kind];\n    switch (kind) {\n      case KEYS: return function keys() { return new Constructor(this, kind); };\n      case VALUES: return function values() { return new Constructor(this, kind); };\n    } return function entries() { return new Constructor(this, kind); };\n  };\n  var TAG = NAME + ' Iterator';\n  var DEF_VALUES = DEFAULT == VALUES;\n  var VALUES_BUG = false;\n  var proto = Base.prototype;\n  var $native = proto[ITERATOR] || proto[FF_ITERATOR] || DEFAULT && proto[DEFAULT];\n  var $default = $native || getMethod(DEFAULT);\n  var $entries = DEFAULT ? !DEF_VALUES ? $default : getMethod('entries') : undefined;\n  var $anyNative = NAME == 'Array' ? proto.entries || $native : $native;\n  var methods, key, IteratorPrototype;\n  // Fix native\n  if ($anyNative) {\n    IteratorPrototype = getPrototypeOf($anyNative.call(new Base()));\n    if (IteratorPrototype !== Object.prototype && IteratorPrototype.next) {\n      // Set @@toStringTag to native iterators\n      setToStringTag(IteratorPrototype, TAG, true);\n      // fix for some old engines\n      if (!LIBRARY && typeof IteratorPrototype[ITERATOR] != 'function') hide(IteratorPrototype, ITERATOR, returnThis);\n    }\n  }\n  // fix Array#{values, @@iterator}.name in V8 / FF\n  if (DEF_VALUES && $native && $native.name !== VALUES) {\n    VALUES_BUG = true;\n    $default = function values() { return $native.call(this); };\n  }\n  // Define iterator\n  if ((!LIBRARY || FORCED) && (BUGGY || VALUES_BUG || !proto[ITERATOR])) {\n    hide(proto, ITERATOR, $default);\n  }\n  // Plug for library\n  Iterators[NAME] = $default;\n  Iterators[TAG] = returnThis;\n  if (DEFAULT) {\n    methods = {\n      values: DEF_VALUES ? $default : getMethod(VALUES),\n      keys: IS_SET ? $default : getMethod(KEYS),\n      entries: $entries\n    };\n    if (FORCED) for (key in methods) {\n      if (!(key in proto)) redefine(proto, key, methods[key]);\n    } else $export($export.P + $export.F * (BUGGY || VALUES_BUG), NAME, methods);\n  }\n  return methods;\n};\n","var ITERATOR = require('./_wks')('iterator');\nvar SAFE_CLOSING = false;\n\ntry {\n  var riter = [7][ITERATOR]();\n  riter['return'] = function () { SAFE_CLOSING = true; };\n  // eslint-disable-next-line no-throw-literal\n  Array.from(riter, function () { throw 2; });\n} catch (e) { /* empty */ }\n\nmodule.exports = function (exec, skipClosing) {\n  if (!skipClosing && !SAFE_CLOSING) return false;\n  var safe = false;\n  try {\n    var arr = [7];\n    var iter = arr[ITERATOR]();\n    iter.next = function () { return { done: safe = true }; };\n    arr[ITERATOR] = function () { return iter; };\n    exec(arr);\n  } catch (e) { /* empty */ }\n  return safe;\n};\n","module.exports = function (done, value) {\n  return { value: value, done: !!done };\n};\n","module.exports = {};\n","module.exports = false;\n","// 20.2.2.14 Math.expm1(x)\nvar $expm1 = Math.expm1;\nmodule.exports = (!$expm1\n  // Old FF bug\n  || $expm1(10) > 22025.465794806719 || $expm1(10) < 22025.4657948067165168\n  // Tor Browser bug\n  || $expm1(-2e-17) != -2e-17\n) ? function expm1(x) {\n  return (x = +x) == 0 ? x : x > -1e-6 && x < 1e-6 ? x + x * x / 2 : Math.exp(x) - 1;\n} : $expm1;\n","// 20.2.2.16 Math.fround(x)\nvar sign = require('./_math-sign');\nvar pow = Math.pow;\nvar EPSILON = pow(2, -52);\nvar EPSILON32 = pow(2, -23);\nvar MAX32 = pow(2, 127) * (2 - EPSILON32);\nvar MIN32 = pow(2, -126);\n\nvar roundTiesToEven = function (n) {\n  return n + 1 / EPSILON - 1 / EPSILON;\n};\n\nmodule.exports = Math.fround || function fround(x) {\n  var $abs = Math.abs(x);\n  var $sign = sign(x);\n  var a, result;\n  if ($abs < MIN32) return $sign * roundTiesToEven($abs / MIN32 / EPSILON32) * MIN32 * EPSILON32;\n  a = (1 + EPSILON32 / EPSILON) * $abs;\n  result = a - (a - $abs);\n  // eslint-disable-next-line no-self-compare\n  if (result > MAX32 || result != result) return $sign * Infinity;\n  return $sign * result;\n};\n","// 20.2.2.20 Math.log1p(x)\nmodule.exports = Math.log1p || function log1p(x) {\n  return (x = +x) > -1e-8 && x < 1e-8 ? x - x * x / 2 : Math.log(1 + x);\n};\n","// https://rwaldron.github.io/proposal-math-extensions/\nmodule.exports = Math.scale || function scale(x, inLow, inHigh, outLow, outHigh) {\n  if (\n    arguments.length === 0\n      // eslint-disable-next-line no-self-compare\n      || x != x\n      // eslint-disable-next-line no-self-compare\n      || inLow != inLow\n      // eslint-disable-next-line no-self-compare\n      || inHigh != inHigh\n      // eslint-disable-next-line no-self-compare\n      || outLow != outLow\n      // eslint-disable-next-line no-self-compare\n      || outHigh != outHigh\n  ) return NaN;\n  if (x === Infinity || x === -Infinity) return x;\n  return (x - inLow) * (outHigh - outLow) / (inHigh - inLow) + outLow;\n};\n","// 20.2.2.28 Math.sign(x)\nmodule.exports = Math.sign || function sign(x) {\n  // eslint-disable-next-line no-self-compare\n  return (x = +x) == 0 || x != x ? x : x < 0 ? -1 : 1;\n};\n","var META = require('./_uid')('meta');\nvar isObject = require('./_is-object');\nvar has = require('./_has');\nvar setDesc = require('./_object-dp').f;\nvar id = 0;\nvar isExtensible = Object.isExtensible || function () {\n  return true;\n};\nvar FREEZE = !require('./_fails')(function () {\n  return isExtensible(Object.preventExtensions({}));\n});\nvar setMeta = function (it) {\n  setDesc(it, META, { value: {\n    i: 'O' + ++id, // object ID\n    w: {}          // weak collections IDs\n  } });\n};\nvar fastKey = function (it, create) {\n  // return primitive with prefix\n  if (!isObject(it)) return typeof it == 'symbol' ? it : (typeof it == 'string' ? 'S' : 'P') + it;\n  if (!has(it, META)) {\n    // can't set metadata to uncaught frozen object\n    if (!isExtensible(it)) return 'F';\n    // not necessary to add metadata\n    if (!create) return 'E';\n    // add missing metadata\n    setMeta(it);\n  // return object ID\n  } return it[META].i;\n};\nvar getWeak = function (it, create) {\n  if (!has(it, META)) {\n    // can't set metadata to uncaught frozen object\n    if (!isExtensible(it)) return true;\n    // not necessary to add metadata\n    if (!create) return false;\n    // add missing metadata\n    setMeta(it);\n  // return hash weak collections IDs\n  } return it[META].w;\n};\n// add metadata on freeze-family methods calling\nvar onFreeze = function (it) {\n  if (FREEZE && meta.NEED && isExtensible(it) && !has(it, META)) setMeta(it);\n  return it;\n};\nvar meta = module.exports = {\n  KEY: META,\n  NEED: false,\n  fastKey: fastKey,\n  getWeak: getWeak,\n  onFreeze: onFreeze\n};\n","var Map = require('./es6.map');\nvar $export = require('./_export');\nvar shared = require('./_shared')('metadata');\nvar store = shared.store || (shared.store = new (require('./es6.weak-map'))());\n\nvar getOrCreateMetadataMap = function (target, targetKey, create) {\n  var targetMetadata = store.get(target);\n  if (!targetMetadata) {\n    if (!create) return undefined;\n    store.set(target, targetMetadata = new Map());\n  }\n  var keyMetadata = targetMetadata.get(targetKey);\n  if (!keyMetadata) {\n    if (!create) return undefined;\n    targetMetadata.set(targetKey, keyMetadata = new Map());\n  } return keyMetadata;\n};\nvar ordinaryHasOwnMetadata = function (MetadataKey, O, P) {\n  var metadataMap = getOrCreateMetadataMap(O, P, false);\n  return metadataMap === undefined ? false : metadataMap.has(MetadataKey);\n};\nvar ordinaryGetOwnMetadata = function (MetadataKey, O, P) {\n  var metadataMap = getOrCreateMetadataMap(O, P, false);\n  return metadataMap === undefined ? undefined : metadataMap.get(MetadataKey);\n};\nvar ordinaryDefineOwnMetadata = function (MetadataKey, MetadataValue, O, P) {\n  getOrCreateMetadataMap(O, P, true).set(MetadataKey, MetadataValue);\n};\nvar ordinaryOwnMetadataKeys = function (target, targetKey) {\n  var metadataMap = getOrCreateMetadataMap(target, targetKey, false);\n  var keys = [];\n  if (metadataMap) metadataMap.forEach(function (_, key) { keys.push(key); });\n  return keys;\n};\nvar toMetaKey = function (it) {\n  return it === undefined || typeof it == 'symbol' ? it : String(it);\n};\nvar exp = function (O) {\n  $export($export.S, 'Reflect', O);\n};\n\nmodule.exports = {\n  store: store,\n  map: getOrCreateMetadataMap,\n  has: ordinaryHasOwnMetadata,\n  get: ordinaryGetOwnMetadata,\n  set: ordinaryDefineOwnMetadata,\n  keys: ordinaryOwnMetadataKeys,\n  key: toMetaKey,\n  exp: exp\n};\n","var global = require('./_global');\nvar macrotask = require('./_task').set;\nvar Observer = global.MutationObserver || global.WebKitMutationObserver;\nvar process = global.process;\nvar Promise = global.Promise;\nvar isNode = require('./_cof')(process) == 'process';\n\nmodule.exports = function () {\n  var head, last, notify;\n\n  var flush = function () {\n    var parent, fn;\n    if (isNode && (parent = process.domain)) parent.exit();\n    while (head) {\n      fn = head.fn;\n      head = head.next;\n      try {\n        fn();\n      } catch (e) {\n        if (head) notify();\n        else last = undefined;\n        throw e;\n      }\n    } last = undefined;\n    if (parent) parent.enter();\n  };\n\n  // Node.js\n  if (isNode) {\n    notify = function () {\n      process.nextTick(flush);\n    };\n  // browsers with MutationObserver, except iOS Safari - https://github.com/zloirock/core-js/issues/339\n  } else if (Observer && !(global.navigator && global.navigator.standalone)) {\n    var toggle = true;\n    var node = document.createTextNode('');\n    new Observer(flush).observe(node, { characterData: true }); // eslint-disable-line no-new\n    notify = function () {\n      node.data = toggle = !toggle;\n    };\n  // environments with maybe non-completely correct, but existent Promise\n  } else if (Promise && Promise.resolve) {\n    // Promise.resolve without an argument throws an error in LG WebOS 2\n    var promise = Promise.resolve(undefined);\n    notify = function () {\n      promise.then(flush);\n    };\n  // for other environments - macrotask based on:\n  // - setImmediate\n  // - MessageChannel\n  // - window.postMessag\n  // - onreadystatechange\n  // - setTimeout\n  } else {\n    notify = function () {\n      // strange IE + webpack dev server bug - use .call(global)\n      macrotask.call(global, flush);\n    };\n  }\n\n  return function (fn) {\n    var task = { fn: fn, next: undefined };\n    if (last) last.next = task;\n    if (!head) {\n      head = task;\n      notify();\n    } last = task;\n  };\n};\n","'use strict';\n// 25.4.1.5 NewPromiseCapability(C)\nvar aFunction = require('./_a-function');\n\nfunction PromiseCapability(C) {\n  var resolve, reject;\n  this.promise = new C(function ($$resolve, $$reject) {\n    if (resolve !== undefined || reject !== undefined) throw TypeError('Bad Promise constructor');\n    resolve = $$resolve;\n    reject = $$reject;\n  });\n  this.resolve = aFunction(resolve);\n  this.reject = aFunction(reject);\n}\n\nmodule.exports.f = function (C) {\n  return new PromiseCapability(C);\n};\n","'use strict';\n// 19.1.2.1 Object.assign(target, source, ...)\nvar getKeys = require('./_object-keys');\nvar gOPS = require('./_object-gops');\nvar pIE = require('./_object-pie');\nvar toObject = require('./_to-object');\nvar IObject = require('./_iobject');\nvar $assign = Object.assign;\n\n// should work with symbols and should have deterministic property order (V8 bug)\nmodule.exports = !$assign || require('./_fails')(function () {\n  var A = {};\n  var B = {};\n  // eslint-disable-next-line no-undef\n  var S = Symbol();\n  var K = 'abcdefghijklmnopqrst';\n  A[S] = 7;\n  K.split('').forEach(function (k) { B[k] = k; });\n  return $assign({}, A)[S] != 7 || Object.keys($assign({}, B)).join('') != K;\n}) ? function assign(target, source) { // eslint-disable-line no-unused-vars\n  var T = toObject(target);\n  var aLen = arguments.length;\n  var index = 1;\n  var getSymbols = gOPS.f;\n  var isEnum = pIE.f;\n  while (aLen > index) {\n    var S = IObject(arguments[index++]);\n    var keys = getSymbols ? getKeys(S).concat(getSymbols(S)) : getKeys(S);\n    var length = keys.length;\n    var j = 0;\n    var key;\n    while (length > j) if (isEnum.call(S, key = keys[j++])) T[key] = S[key];\n  } return T;\n} : $assign;\n","// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\nvar anObject = require('./_an-object');\nvar dPs = require('./_object-dps');\nvar enumBugKeys = require('./_enum-bug-keys');\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\nvar Empty = function () { /* empty */ };\nvar PROTOTYPE = 'prototype';\n\n// Create object with fake `null` prototype: use iframe Object with cleared prototype\nvar createDict = function () {\n  // Thrash, waste and sodomy: IE GC bug\n  var iframe = require('./_dom-create')('iframe');\n  var i = enumBugKeys.length;\n  var lt = '<';\n  var gt = '>';\n  var iframeDocument;\n  iframe.style.display = 'none';\n  require('./_html').appendChild(iframe);\n  iframe.src = 'javascript:'; // eslint-disable-line no-script-url\n  // createDict = iframe.contentWindow.Object;\n  // html.removeChild(iframe);\n  iframeDocument = iframe.contentWindow.document;\n  iframeDocument.open();\n  iframeDocument.write(lt + 'script' + gt + 'document.F=Object' + lt + '/script' + gt);\n  iframeDocument.close();\n  createDict = iframeDocument.F;\n  while (i--) delete createDict[PROTOTYPE][enumBugKeys[i]];\n  return createDict();\n};\n\nmodule.exports = Object.create || function create(O, Properties) {\n  var result;\n  if (O !== null) {\n    Empty[PROTOTYPE] = anObject(O);\n    result = new Empty();\n    Empty[PROTOTYPE] = null;\n    // add \"__proto__\" for Object.getPrototypeOf polyfill\n    result[IE_PROTO] = O;\n  } else result = createDict();\n  return Properties === undefined ? result : dPs(result, Properties);\n};\n","var anObject = require('./_an-object');\nvar IE8_DOM_DEFINE = require('./_ie8-dom-define');\nvar toPrimitive = require('./_to-primitive');\nvar dP = Object.defineProperty;\n\nexports.f = require('./_descriptors') ? Object.defineProperty : function defineProperty(O, P, Attributes) {\n  anObject(O);\n  P = toPrimitive(P, true);\n  anObject(Attributes);\n  if (IE8_DOM_DEFINE) try {\n    return dP(O, P, Attributes);\n  } catch (e) { /* empty */ }\n  if ('get' in Attributes || 'set' in Attributes) throw TypeError('Accessors not supported!');\n  if ('value' in Attributes) O[P] = Attributes.value;\n  return O;\n};\n","var dP = require('./_object-dp');\nvar anObject = require('./_an-object');\nvar getKeys = require('./_object-keys');\n\nmodule.exports = require('./_descriptors') ? Object.defineProperties : function defineProperties(O, Properties) {\n  anObject(O);\n  var keys = getKeys(Properties);\n  var length = keys.length;\n  var i = 0;\n  var P;\n  while (length > i) dP.f(O, P = keys[i++], Properties[P]);\n  return O;\n};\n","'use strict';\n// Forced replacement prototype accessors methods\nmodule.exports = require('./_library') || !require('./_fails')(function () {\n  var K = Math.random();\n  // In FF throws only define methods\n  // eslint-disable-next-line no-undef, no-useless-call\n  __defineSetter__.call(null, K, function () { /* empty */ });\n  delete require('./_global')[K];\n});\n","var pIE = require('./_object-pie');\nvar createDesc = require('./_property-desc');\nvar toIObject = require('./_to-iobject');\nvar toPrimitive = require('./_to-primitive');\nvar has = require('./_has');\nvar IE8_DOM_DEFINE = require('./_ie8-dom-define');\nvar gOPD = Object.getOwnPropertyDescriptor;\n\nexports.f = require('./_descriptors') ? gOPD : function getOwnPropertyDescriptor(O, P) {\n  O = toIObject(O);\n  P = toPrimitive(P, true);\n  if (IE8_DOM_DEFINE) try {\n    return gOPD(O, P);\n  } catch (e) { /* empty */ }\n  if (has(O, P)) return createDesc(!pIE.f.call(O, P), O[P]);\n};\n","// fallback for IE11 buggy Object.getOwnPropertyNames with iframe and window\nvar toIObject = require('./_to-iobject');\nvar gOPN = require('./_object-gopn').f;\nvar toString = {}.toString;\n\nvar windowNames = typeof window == 'object' && window && Object.getOwnPropertyNames\n  ? Object.getOwnPropertyNames(window) : [];\n\nvar getWindowNames = function (it) {\n  try {\n    return gOPN(it);\n  } catch (e) {\n    return windowNames.slice();\n  }\n};\n\nmodule.exports.f = function getOwnPropertyNames(it) {\n  return windowNames && toString.call(it) == '[object Window]' ? getWindowNames(it) : gOPN(toIObject(it));\n};\n","// 19.1.2.7 / 15.2.3.4 Object.getOwnPropertyNames(O)\nvar $keys = require('./_object-keys-internal');\nvar hiddenKeys = require('./_enum-bug-keys').concat('length', 'prototype');\n\nexports.f = Object.getOwnPropertyNames || function getOwnPropertyNames(O) {\n  return $keys(O, hiddenKeys);\n};\n","exports.f = Object.getOwnPropertySymbols;\n","// 19.1.2.9 / 15.2.3.2 Object.getPrototypeOf(O)\nvar has = require('./_has');\nvar toObject = require('./_to-object');\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\nvar ObjectProto = Object.prototype;\n\nmodule.exports = Object.getPrototypeOf || function (O) {\n  O = toObject(O);\n  if (has(O, IE_PROTO)) return O[IE_PROTO];\n  if (typeof O.constructor == 'function' && O instanceof O.constructor) {\n    return O.constructor.prototype;\n  } return O instanceof Object ? ObjectProto : null;\n};\n","var has = require('./_has');\nvar toIObject = require('./_to-iobject');\nvar arrayIndexOf = require('./_array-includes')(false);\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\n\nmodule.exports = function (object, names) {\n  var O = toIObject(object);\n  var i = 0;\n  var result = [];\n  var key;\n  for (key in O) if (key != IE_PROTO) has(O, key) && result.push(key);\n  // Don't enum bug & hidden keys\n  while (names.length > i) if (has(O, key = names[i++])) {\n    ~arrayIndexOf(result, key) || result.push(key);\n  }\n  return result;\n};\n","// 19.1.2.14 / 15.2.3.14 Object.keys(O)\nvar $keys = require('./_object-keys-internal');\nvar enumBugKeys = require('./_enum-bug-keys');\n\nmodule.exports = Object.keys || function keys(O) {\n  return $keys(O, enumBugKeys);\n};\n","exports.f = {}.propertyIsEnumerable;\n","// most Object methods by ES6 should accept primitives\nvar $export = require('./_export');\nvar core = require('./_core');\nvar fails = require('./_fails');\nmodule.exports = function (KEY, exec) {\n  var fn = (core.Object || {})[KEY] || Object[KEY];\n  var exp = {};\n  exp[KEY] = exec(fn);\n  $export($export.S + $export.F * fails(function () { fn(1); }), 'Object', exp);\n};\n","var getKeys = require('./_object-keys');\nvar toIObject = require('./_to-iobject');\nvar isEnum = require('./_object-pie').f;\nmodule.exports = function (isEntries) {\n  return function (it) {\n    var O = toIObject(it);\n    var keys = getKeys(O);\n    var length = keys.length;\n    var i = 0;\n    var result = [];\n    var key;\n    while (length > i) if (isEnum.call(O, key = keys[i++])) {\n      result.push(isEntries ? [key, O[key]] : O[key]);\n    } return result;\n  };\n};\n","// all object keys, includes non-enumerable and symbols\nvar gOPN = require('./_object-gopn');\nvar gOPS = require('./_object-gops');\nvar anObject = require('./_an-object');\nvar Reflect = require('./_global').Reflect;\nmodule.exports = Reflect && Reflect.ownKeys || function ownKeys(it) {\n  var keys = gOPN.f(anObject(it));\n  var getSymbols = gOPS.f;\n  return getSymbols ? keys.concat(getSymbols(it)) : keys;\n};\n","var $parseFloat = require('./_global').parseFloat;\nvar $trim = require('./_string-trim').trim;\n\nmodule.exports = 1 / $parseFloat(require('./_string-ws') + '-0') !== -Infinity ? function parseFloat(str) {\n  var string = $trim(String(str), 3);\n  var result = $parseFloat(string);\n  return result === 0 && string.charAt(0) == '-' ? -0 : result;\n} : $parseFloat;\n","var $parseInt = require('./_global').parseInt;\nvar $trim = require('./_string-trim').trim;\nvar ws = require('./_string-ws');\nvar hex = /^[-+]?0[xX]/;\n\nmodule.exports = $parseInt(ws + '08') !== 8 || $parseInt(ws + '0x16') !== 22 ? function parseInt(str, radix) {\n  var string = $trim(String(str), 3);\n  return $parseInt(string, (radix >>> 0) || (hex.test(string) ? 16 : 10));\n} : $parseInt;\n","module.exports = function (exec) {\n  try {\n    return { e: false, v: exec() };\n  } catch (e) {\n    return { e: true, v: e };\n  }\n};\n","var anObject = require('./_an-object');\nvar isObject = require('./_is-object');\nvar newPromiseCapability = require('./_new-promise-capability');\n\nmodule.exports = function (C, x) {\n  anObject(C);\n  if (isObject(x) && x.constructor === C) return x;\n  var promiseCapability = newPromiseCapability.f(C);\n  var resolve = promiseCapability.resolve;\n  resolve(x);\n  return promiseCapability.promise;\n};\n","module.exports = function (bitmap, value) {\n  return {\n    enumerable: !(bitmap & 1),\n    configurable: !(bitmap & 2),\n    writable: !(bitmap & 4),\n    value: value\n  };\n};\n","var redefine = require('./_redefine');\nmodule.exports = function (target, src, safe) {\n  for (var key in src) redefine(target, key, src[key], safe);\n  return target;\n};\n","var global = require('./_global');\nvar hide = require('./_hide');\nvar has = require('./_has');\nvar SRC = require('./_uid')('src');\nvar $toString = require('./_function-to-string');\nvar TO_STRING = 'toString';\nvar TPL = ('' + $toString).split(TO_STRING);\n\nrequire('./_core').inspectSource = function (it) {\n  return $toString.call(it);\n};\n\n(module.exports = function (O, key, val, safe) {\n  var isFunction = typeof val == 'function';\n  if (isFunction) has(val, 'name') || hide(val, 'name', key);\n  if (O[key] === val) return;\n  if (isFunction) has(val, SRC) || hide(val, SRC, O[key] ? '' + O[key] : TPL.join(String(key)));\n  if (O === global) {\n    O[key] = val;\n  } else if (!safe) {\n    delete O[key];\n    hide(O, key, val);\n  } else if (O[key]) {\n    O[key] = val;\n  } else {\n    hide(O, key, val);\n  }\n// add fake Function#toString for correct work wrapped methods / constructors with methods like LoDash isNative\n})(Function.prototype, TO_STRING, function toString() {\n  return typeof this == 'function' && this[SRC] || $toString.call(this);\n});\n","'use strict';\n\nvar classof = require('./_classof');\nvar builtinExec = RegExp.prototype.exec;\n\n // `RegExpExec` abstract operation\n// https://tc39.github.io/ecma262/#sec-regexpexec\nmodule.exports = function (R, S) {\n  var exec = R.exec;\n  if (typeof exec === 'function') {\n    var result = exec.call(R, S);\n    if (typeof result !== 'object') {\n      throw new TypeError('RegExp exec method returned something other than an Object or null');\n    }\n    return result;\n  }\n  if (classof(R) !== 'RegExp') {\n    throw new TypeError('RegExp#exec called on incompatible receiver');\n  }\n  return builtinExec.call(R, S);\n};\n","'use strict';\n\nvar regexpFlags = require('./_flags');\n\nvar nativeExec = RegExp.prototype.exec;\n// This always refers to the native implementation, because the\n// String#replace polyfill uses ./fix-regexp-well-known-symbol-logic.js,\n// which loads this file before patching the method.\nvar nativeReplace = String.prototype.replace;\n\nvar patchedExec = nativeExec;\n\nvar LAST_INDEX = 'lastIndex';\n\nvar UPDATES_LAST_INDEX_WRONG = (function () {\n  var re1 = /a/,\n      re2 = /b*/g;\n  nativeExec.call(re1, 'a');\n  nativeExec.call(re2, 'a');\n  return re1[LAST_INDEX] !== 0 || re2[LAST_INDEX] !== 0;\n})();\n\n// nonparticipating capturing group, copied from es5-shim's String#split patch.\nvar NPCG_INCLUDED = /()??/.exec('')[1] !== undefined;\n\nvar PATCH = UPDATES_LAST_INDEX_WRONG || NPCG_INCLUDED;\n\nif (PATCH) {\n  patchedExec = function exec(str) {\n    var re = this;\n    var lastIndex, reCopy, match, i;\n\n    if (NPCG_INCLUDED) {\n      reCopy = new RegExp('^' + re.source + '$(?!\\\\s)', regexpFlags.call(re));\n    }\n    if (UPDATES_LAST_INDEX_WRONG) lastIndex = re[LAST_INDEX];\n\n    match = nativeExec.call(re, str);\n\n    if (UPDATES_LAST_INDEX_WRONG && match) {\n      re[LAST_INDEX] = re.global ? match.index + match[0].length : lastIndex;\n    }\n    if (NPCG_INCLUDED && match && match.length > 1) {\n      // Fix browsers whose `exec` methods don't consistently return `undefined`\n      // for NPCG, like IE8. NOTE: This doesn' work for /(.?)?/\n      // eslint-disable-next-line no-loop-func\n      nativeReplace.call(match[0], reCopy, function () {\n        for (i = 1; i < arguments.length - 2; i++) {\n          if (arguments[i] === undefined) match[i] = undefined;\n        }\n      });\n    }\n\n    return match;\n  };\n}\n\nmodule.exports = patchedExec;\n","module.exports = function (regExp, replace) {\n  var replacer = replace === Object(replace) ? function (part) {\n    return replace[part];\n  } : replace;\n  return function (it) {\n    return String(it).replace(regExp, replacer);\n  };\n};\n","// 7.2.9 SameValue(x, y)\nmodule.exports = Object.is || function is(x, y) {\n  // eslint-disable-next-line no-self-compare\n  return x === y ? x !== 0 || 1 / x === 1 / y : x != x && y != y;\n};\n","'use strict';\n// https://tc39.github.io/proposal-setmap-offrom/\nvar $export = require('./_export');\nvar aFunction = require('./_a-function');\nvar ctx = require('./_ctx');\nvar forOf = require('./_for-of');\n\nmodule.exports = function (COLLECTION) {\n  $export($export.S, COLLECTION, { from: function from(source /* , mapFn, thisArg */) {\n    var mapFn = arguments[1];\n    var mapping, A, n, cb;\n    aFunction(this);\n    mapping = mapFn !== undefined;\n    if (mapping) aFunction(mapFn);\n    if (source == undefined) return new this();\n    A = [];\n    if (mapping) {\n      n = 0;\n      cb = ctx(mapFn, arguments[2], 2);\n      forOf(source, false, function (nextItem) {\n        A.push(cb(nextItem, n++));\n      });\n    } else {\n      forOf(source, false, A.push, A);\n    }\n    return new this(A);\n  } });\n};\n","'use strict';\n// https://tc39.github.io/proposal-setmap-offrom/\nvar $export = require('./_export');\n\nmodule.exports = function (COLLECTION) {\n  $export($export.S, COLLECTION, { of: function of() {\n    var length = arguments.length;\n    var A = new Array(length);\n    while (length--) A[length] = arguments[length];\n    return new this(A);\n  } });\n};\n","// Works with __proto__ only. Old v8 can't work with null proto objects.\n/* eslint-disable no-proto */\nvar isObject = require('./_is-object');\nvar anObject = require('./_an-object');\nvar check = function (O, proto) {\n  anObject(O);\n  if (!isObject(proto) && proto !== null) throw TypeError(proto + \": can't set as prototype!\");\n};\nmodule.exports = {\n  set: Object.setPrototypeOf || ('__proto__' in {} ? // eslint-disable-line\n    function (test, buggy, set) {\n      try {\n        set = require('./_ctx')(Function.call, require('./_object-gopd').f(Object.prototype, '__proto__').set, 2);\n        set(test, []);\n        buggy = !(test instanceof Array);\n      } catch (e) { buggy = true; }\n      return function setPrototypeOf(O, proto) {\n        check(O, proto);\n        if (buggy) O.__proto__ = proto;\n        else set(O, proto);\n        return O;\n      };\n    }({}, false) : undefined),\n  check: check\n};\n","'use strict';\nvar global = require('./_global');\nvar dP = require('./_object-dp');\nvar DESCRIPTORS = require('./_descriptors');\nvar SPECIES = require('./_wks')('species');\n\nmodule.exports = function (KEY) {\n  var C = global[KEY];\n  if (DESCRIPTORS && C && !C[SPECIES]) dP.f(C, SPECIES, {\n    configurable: true,\n    get: function () { return this; }\n  });\n};\n","var def = require('./_object-dp').f;\nvar has = require('./_has');\nvar TAG = require('./_wks')('toStringTag');\n\nmodule.exports = function (it, tag, stat) {\n  if (it && !has(it = stat ? it : it.prototype, TAG)) def(it, TAG, { configurable: true, value: tag });\n};\n","var shared = require('./_shared')('keys');\nvar uid = require('./_uid');\nmodule.exports = function (key) {\n  return shared[key] || (shared[key] = uid(key));\n};\n","var core = require('./_core');\nvar global = require('./_global');\nvar SHARED = '__core-js_shared__';\nvar store = global[SHARED] || (global[SHARED] = {});\n\n(module.exports = function (key, value) {\n  return store[key] || (store[key] = value !== undefined ? value : {});\n})('versions', []).push({\n  version: core.version,\n  mode: require('./_library') ? 'pure' : 'global',\n  copyright: '© 2019 Denis Pushkarev (zloirock.ru)'\n});\n","// 7.3.20 SpeciesConstructor(O, defaultConstructor)\nvar anObject = require('./_an-object');\nvar aFunction = require('./_a-function');\nvar SPECIES = require('./_wks')('species');\nmodule.exports = function (O, D) {\n  var C = anObject(O).constructor;\n  var S;\n  return C === undefined || (S = anObject(C)[SPECIES]) == undefined ? D : aFunction(S);\n};\n","'use strict';\nvar fails = require('./_fails');\n\nmodule.exports = function (method, arg) {\n  return !!method && fails(function () {\n    // eslint-disable-next-line no-useless-call\n    arg ? method.call(null, function () { /* empty */ }, 1) : method.call(null);\n  });\n};\n","var toInteger = require('./_to-integer');\nvar defined = require('./_defined');\n// true  -> String#at\n// false -> String#codePointAt\nmodule.exports = function (TO_STRING) {\n  return function (that, pos) {\n    var s = String(defined(that));\n    var i = toInteger(pos);\n    var l = s.length;\n    var a, b;\n    if (i < 0 || i >= l) return TO_STRING ? '' : undefined;\n    a = s.charCodeAt(i);\n    return a < 0xd800 || a > 0xdbff || i + 1 === l || (b = s.charCodeAt(i + 1)) < 0xdc00 || b > 0xdfff\n      ? TO_STRING ? s.charAt(i) : a\n      : TO_STRING ? s.slice(i, i + 2) : (a - 0xd800 << 10) + (b - 0xdc00) + 0x10000;\n  };\n};\n","// helper for String#{startsWith, endsWith, includes}\nvar isRegExp = require('./_is-regexp');\nvar defined = require('./_defined');\n\nmodule.exports = function (that, searchString, NAME) {\n  if (isRegExp(searchString)) throw TypeError('String#' + NAME + \" doesn't accept regex!\");\n  return String(defined(that));\n};\n","var $export = require('./_export');\nvar fails = require('./_fails');\nvar defined = require('./_defined');\nvar quot = /\"/g;\n// B.2.3.2.1 CreateHTML(string, tag, attribute, value)\nvar createHTML = function (string, tag, attribute, value) {\n  var S = String(defined(string));\n  var p1 = '<' + tag;\n  if (attribute !== '') p1 += ' ' + attribute + '=\"' + String(value).replace(quot, '&quot;') + '\"';\n  return p1 + '>' + S + '</' + tag + '>';\n};\nmodule.exports = function (NAME, exec) {\n  var O = {};\n  O[NAME] = exec(createHTML);\n  $export($export.P + $export.F * fails(function () {\n    var test = ''[NAME]('\"');\n    return test !== test.toLowerCase() || test.split('\"').length > 3;\n  }), 'String', O);\n};\n","// https://github.com/tc39/proposal-string-pad-start-end\nvar toLength = require('./_to-length');\nvar repeat = require('./_string-repeat');\nvar defined = require('./_defined');\n\nmodule.exports = function (that, maxLength, fillString, left) {\n  var S = String(defined(that));\n  var stringLength = S.length;\n  var fillStr = fillString === undefined ? ' ' : String(fillString);\n  var intMaxLength = toLength(maxLength);\n  if (intMaxLength <= stringLength || fillStr == '') return S;\n  var fillLen = intMaxLength - stringLength;\n  var stringFiller = repeat.call(fillStr, Math.ceil(fillLen / fillStr.length));\n  if (stringFiller.length > fillLen) stringFiller = stringFiller.slice(0, fillLen);\n  return left ? stringFiller + S : S + stringFiller;\n};\n","'use strict';\nvar toInteger = require('./_to-integer');\nvar defined = require('./_defined');\n\nmodule.exports = function repeat(count) {\n  var str = String(defined(this));\n  var res = '';\n  var n = toInteger(count);\n  if (n < 0 || n == Infinity) throw RangeError(\"Count can't be negative\");\n  for (;n > 0; (n >>>= 1) && (str += str)) if (n & 1) res += str;\n  return res;\n};\n","var $export = require('./_export');\nvar defined = require('./_defined');\nvar fails = require('./_fails');\nvar spaces = require('./_string-ws');\nvar space = '[' + spaces + ']';\nvar non = '\\u200b\\u0085';\nvar ltrim = RegExp('^' + space + space + '*');\nvar rtrim = RegExp(space + space + '*$');\n\nvar exporter = function (KEY, exec, ALIAS) {\n  var exp = {};\n  var FORCE = fails(function () {\n    return !!spaces[KEY]() || non[KEY]() != non;\n  });\n  var fn = exp[KEY] = FORCE ? exec(trim) : spaces[KEY];\n  if (ALIAS) exp[ALIAS] = fn;\n  $export($export.P + $export.F * FORCE, 'String', exp);\n};\n\n// 1 -> String#trimLeft\n// 2 -> String#trimRight\n// 3 -> String#trim\nvar trim = exporter.trim = function (string, TYPE) {\n  string = String(defined(string));\n  if (TYPE & 1) string = string.replace(ltrim, '');\n  if (TYPE & 2) string = string.replace(rtrim, '');\n  return string;\n};\n\nmodule.exports = exporter;\n","module.exports = '\\x09\\x0A\\x0B\\x0C\\x0D\\x20\\xA0\\u1680\\u180E\\u2000\\u2001\\u2002\\u2003' +\n  '\\u2004\\u2005\\u2006\\u2007\\u2008\\u2009\\u200A\\u202F\\u205F\\u3000\\u2028\\u2029\\uFEFF';\n","var ctx = require('./_ctx');\nvar invoke = require('./_invoke');\nvar html = require('./_html');\nvar cel = require('./_dom-create');\nvar global = require('./_global');\nvar process = global.process;\nvar setTask = global.setImmediate;\nvar clearTask = global.clearImmediate;\nvar MessageChannel = global.MessageChannel;\nvar Dispatch = global.Dispatch;\nvar counter = 0;\nvar queue = {};\nvar ONREADYSTATECHANGE = 'onreadystatechange';\nvar defer, channel, port;\nvar run = function () {\n  var id = +this;\n  // eslint-disable-next-line no-prototype-builtins\n  if (queue.hasOwnProperty(id)) {\n    var fn = queue[id];\n    delete queue[id];\n    fn();\n  }\n};\nvar listener = function (event) {\n  run.call(event.data);\n};\n// Node.js 0.9+ & IE10+ has setImmediate, otherwise:\nif (!setTask || !clearTask) {\n  setTask = function setImmediate(fn) {\n    var args = [];\n    var i = 1;\n    while (arguments.length > i) args.push(arguments[i++]);\n    queue[++counter] = function () {\n      // eslint-disable-next-line no-new-func\n      invoke(typeof fn == 'function' ? fn : Function(fn), args);\n    };\n    defer(counter);\n    return counter;\n  };\n  clearTask = function clearImmediate(id) {\n    delete queue[id];\n  };\n  // Node.js 0.8-\n  if (require('./_cof')(process) == 'process') {\n    defer = function (id) {\n      process.nextTick(ctx(run, id, 1));\n    };\n  // Sphere (JS game engine) Dispatch API\n  } else if (Dispatch && Dispatch.now) {\n    defer = function (id) {\n      Dispatch.now(ctx(run, id, 1));\n    };\n  // Browsers with MessageChannel, includes WebWorkers\n  } else if (MessageChannel) {\n    channel = new MessageChannel();\n    port = channel.port2;\n    channel.port1.onmessage = listener;\n    defer = ctx(port.postMessage, port, 1);\n  // Browsers with postMessage, skip WebWorkers\n  // IE8 has postMessage, but it's sync & typeof its postMessage is 'object'\n  } else if (global.addEventListener && typeof postMessage == 'function' && !global.importScripts) {\n    defer = function (id) {\n      global.postMessage(id + '', '*');\n    };\n    global.addEventListener('message', listener, false);\n  // IE8-\n  } else if (ONREADYSTATECHANGE in cel('script')) {\n    defer = function (id) {\n      html.appendChild(cel('script'))[ONREADYSTATECHANGE] = function () {\n        html.removeChild(this);\n        run.call(id);\n      };\n    };\n  // Rest old browsers\n  } else {\n    defer = function (id) {\n      setTimeout(ctx(run, id, 1), 0);\n    };\n  }\n}\nmodule.exports = {\n  set: setTask,\n  clear: clearTask\n};\n","var toInteger = require('./_to-integer');\nvar max = Math.max;\nvar min = Math.min;\nmodule.exports = function (index, length) {\n  index = toInteger(index);\n  return index < 0 ? max(index + length, 0) : min(index, length);\n};\n","// https://tc39.github.io/ecma262/#sec-toindex\nvar toInteger = require('./_to-integer');\nvar toLength = require('./_to-length');\nmodule.exports = function (it) {\n  if (it === undefined) return 0;\n  var number = toInteger(it);\n  var length = toLength(number);\n  if (number !== length) throw RangeError('Wrong length!');\n  return length;\n};\n","// 7.1.4 ToInteger\nvar ceil = Math.ceil;\nvar floor = Math.floor;\nmodule.exports = function (it) {\n  return isNaN(it = +it) ? 0 : (it > 0 ? floor : ceil)(it);\n};\n","// to indexed object, toObject with fallback for non-array-like ES3 strings\nvar IObject = require('./_iobject');\nvar defined = require('./_defined');\nmodule.exports = function (it) {\n  return IObject(defined(it));\n};\n","// 7.1.15 ToLength\nvar toInteger = require('./_to-integer');\nvar min = Math.min;\nmodule.exports = function (it) {\n  return it > 0 ? min(toInteger(it), 0x1fffffffffffff) : 0; // pow(2, 53) - 1 == 9007199254740991\n};\n","// 7.1.13 ToObject(argument)\nvar defined = require('./_defined');\nmodule.exports = function (it) {\n  return Object(defined(it));\n};\n","// 7.1.1 ToPrimitive(input [, PreferredType])\nvar isObject = require('./_is-object');\n// instead of the ES6 spec version, we didn't implement @@toPrimitive case\n// and the second argument - flag - preferred type is a string\nmodule.exports = function (it, S) {\n  if (!isObject(it)) return it;\n  var fn, val;\n  if (S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (typeof (fn = it.valueOf) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (!S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  throw TypeError(\"Can't convert object to primitive value\");\n};\n","'use strict';\nif (require('./_descriptors')) {\n  var LIBRARY = require('./_library');\n  var global = require('./_global');\n  var fails = require('./_fails');\n  var $export = require('./_export');\n  var $typed = require('./_typed');\n  var $buffer = require('./_typed-buffer');\n  var ctx = require('./_ctx');\n  var anInstance = require('./_an-instance');\n  var propertyDesc = require('./_property-desc');\n  var hide = require('./_hide');\n  var redefineAll = require('./_redefine-all');\n  var toInteger = require('./_to-integer');\n  var toLength = require('./_to-length');\n  var toIndex = require('./_to-index');\n  var toAbsoluteIndex = require('./_to-absolute-index');\n  var toPrimitive = require('./_to-primitive');\n  var has = require('./_has');\n  var classof = require('./_classof');\n  var isObject = require('./_is-object');\n  var toObject = require('./_to-object');\n  var isArrayIter = require('./_is-array-iter');\n  var create = require('./_object-create');\n  var getPrototypeOf = require('./_object-gpo');\n  var gOPN = require('./_object-gopn').f;\n  var getIterFn = require('./core.get-iterator-method');\n  var uid = require('./_uid');\n  var wks = require('./_wks');\n  var createArrayMethod = require('./_array-methods');\n  var createArrayIncludes = require('./_array-includes');\n  var speciesConstructor = require('./_species-constructor');\n  var ArrayIterators = require('./es6.array.iterator');\n  var Iterators = require('./_iterators');\n  var $iterDetect = require('./_iter-detect');\n  var setSpecies = require('./_set-species');\n  var arrayFill = require('./_array-fill');\n  var arrayCopyWithin = require('./_array-copy-within');\n  var $DP = require('./_object-dp');\n  var $GOPD = require('./_object-gopd');\n  var dP = $DP.f;\n  var gOPD = $GOPD.f;\n  var RangeError = global.RangeError;\n  var TypeError = global.TypeError;\n  var Uint8Array = global.Uint8Array;\n  var ARRAY_BUFFER = 'ArrayBuffer';\n  var SHARED_BUFFER = 'Shared' + ARRAY_BUFFER;\n  var BYTES_PER_ELEMENT = 'BYTES_PER_ELEMENT';\n  var PROTOTYPE = 'prototype';\n  var ArrayProto = Array[PROTOTYPE];\n  var $ArrayBuffer = $buffer.ArrayBuffer;\n  var $DataView = $buffer.DataView;\n  var arrayForEach = createArrayMethod(0);\n  var arrayFilter = createArrayMethod(2);\n  var arraySome = createArrayMethod(3);\n  var arrayEvery = createArrayMethod(4);\n  var arrayFind = createArrayMethod(5);\n  var arrayFindIndex = createArrayMethod(6);\n  var arrayIncludes = createArrayIncludes(true);\n  var arrayIndexOf = createArrayIncludes(false);\n  var arrayValues = ArrayIterators.values;\n  var arrayKeys = ArrayIterators.keys;\n  var arrayEntries = ArrayIterators.entries;\n  var arrayLastIndexOf = ArrayProto.lastIndexOf;\n  var arrayReduce = ArrayProto.reduce;\n  var arrayReduceRight = ArrayProto.reduceRight;\n  var arrayJoin = ArrayProto.join;\n  var arraySort = ArrayProto.sort;\n  var arraySlice = ArrayProto.slice;\n  var arrayToString = ArrayProto.toString;\n  var arrayToLocaleString = ArrayProto.toLocaleString;\n  var ITERATOR = wks('iterator');\n  var TAG = wks('toStringTag');\n  var TYPED_CONSTRUCTOR = uid('typed_constructor');\n  var DEF_CONSTRUCTOR = uid('def_constructor');\n  var ALL_CONSTRUCTORS = $typed.CONSTR;\n  var TYPED_ARRAY = $typed.TYPED;\n  var VIEW = $typed.VIEW;\n  var WRONG_LENGTH = 'Wrong length!';\n\n  var $map = createArrayMethod(1, function (O, length) {\n    return allocate(speciesConstructor(O, O[DEF_CONSTRUCTOR]), length);\n  });\n\n  var LITTLE_ENDIAN = fails(function () {\n    // eslint-disable-next-line no-undef\n    return new Uint8Array(new Uint16Array([1]).buffer)[0] === 1;\n  });\n\n  var FORCED_SET = !!Uint8Array && !!Uint8Array[PROTOTYPE].set && fails(function () {\n    new Uint8Array(1).set({});\n  });\n\n  var toOffset = function (it, BYTES) {\n    var offset = toInteger(it);\n    if (offset < 0 || offset % BYTES) throw RangeError('Wrong offset!');\n    return offset;\n  };\n\n  var validate = function (it) {\n    if (isObject(it) && TYPED_ARRAY in it) return it;\n    throw TypeError(it + ' is not a typed array!');\n  };\n\n  var allocate = function (C, length) {\n    if (!(isObject(C) && TYPED_CONSTRUCTOR in C)) {\n      throw TypeError('It is not a typed array constructor!');\n    } return new C(length);\n  };\n\n  var speciesFromList = function (O, list) {\n    return fromList(speciesConstructor(O, O[DEF_CONSTRUCTOR]), list);\n  };\n\n  var fromList = function (C, list) {\n    var index = 0;\n    var length = list.length;\n    var result = allocate(C, length);\n    while (length > index) result[index] = list[index++];\n    return result;\n  };\n\n  var addGetter = function (it, key, internal) {\n    dP(it, key, { get: function () { return this._d[internal]; } });\n  };\n\n  var $from = function from(source /* , mapfn, thisArg */) {\n    var O = toObject(source);\n    var aLen = arguments.length;\n    var mapfn = aLen > 1 ? arguments[1] : undefined;\n    var mapping = mapfn !== undefined;\n    var iterFn = getIterFn(O);\n    var i, length, values, result, step, iterator;\n    if (iterFn != undefined && !isArrayIter(iterFn)) {\n      for (iterator = iterFn.call(O), values = [], i = 0; !(step = iterator.next()).done; i++) {\n        values.push(step.value);\n      } O = values;\n    }\n    if (mapping && aLen > 2) mapfn = ctx(mapfn, arguments[2], 2);\n    for (i = 0, length = toLength(O.length), result = allocate(this, length); length > i; i++) {\n      result[i] = mapping ? mapfn(O[i], i) : O[i];\n    }\n    return result;\n  };\n\n  var $of = function of(/* ...items */) {\n    var index = 0;\n    var length = arguments.length;\n    var result = allocate(this, length);\n    while (length > index) result[index] = arguments[index++];\n    return result;\n  };\n\n  // iOS Safari 6.x fails here\n  var TO_LOCALE_BUG = !!Uint8Array && fails(function () { arrayToLocaleString.call(new Uint8Array(1)); });\n\n  var $toLocaleString = function toLocaleString() {\n    return arrayToLocaleString.apply(TO_LOCALE_BUG ? arraySlice.call(validate(this)) : validate(this), arguments);\n  };\n\n  var proto = {\n    copyWithin: function copyWithin(target, start /* , end */) {\n      return arrayCopyWithin.call(validate(this), target, start, arguments.length > 2 ? arguments[2] : undefined);\n    },\n    every: function every(callbackfn /* , thisArg */) {\n      return arrayEvery(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    fill: function fill(value /* , start, end */) { // eslint-disable-line no-unused-vars\n      return arrayFill.apply(validate(this), arguments);\n    },\n    filter: function filter(callbackfn /* , thisArg */) {\n      return speciesFromList(this, arrayFilter(validate(this), callbackfn,\n        arguments.length > 1 ? arguments[1] : undefined));\n    },\n    find: function find(predicate /* , thisArg */) {\n      return arrayFind(validate(this), predicate, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    findIndex: function findIndex(predicate /* , thisArg */) {\n      return arrayFindIndex(validate(this), predicate, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    forEach: function forEach(callbackfn /* , thisArg */) {\n      arrayForEach(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    indexOf: function indexOf(searchElement /* , fromIndex */) {\n      return arrayIndexOf(validate(this), searchElement, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    includes: function includes(searchElement /* , fromIndex */) {\n      return arrayIncludes(validate(this), searchElement, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    join: function join(separator) { // eslint-disable-line no-unused-vars\n      return arrayJoin.apply(validate(this), arguments);\n    },\n    lastIndexOf: function lastIndexOf(searchElement /* , fromIndex */) { // eslint-disable-line no-unused-vars\n      return arrayLastIndexOf.apply(validate(this), arguments);\n    },\n    map: function map(mapfn /* , thisArg */) {\n      return $map(validate(this), mapfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    reduce: function reduce(callbackfn /* , initialValue */) { // eslint-disable-line no-unused-vars\n      return arrayReduce.apply(validate(this), arguments);\n    },\n    reduceRight: function reduceRight(callbackfn /* , initialValue */) { // eslint-disable-line no-unused-vars\n      return arrayReduceRight.apply(validate(this), arguments);\n    },\n    reverse: function reverse() {\n      var that = this;\n      var length = validate(that).length;\n      var middle = Math.floor(length / 2);\n      var index = 0;\n      var value;\n      while (index < middle) {\n        value = that[index];\n        that[index++] = that[--length];\n        that[length] = value;\n      } return that;\n    },\n    some: function some(callbackfn /* , thisArg */) {\n      return arraySome(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    sort: function sort(comparefn) {\n      return arraySort.call(validate(this), comparefn);\n    },\n    subarray: function subarray(begin, end) {\n      var O = validate(this);\n      var length = O.length;\n      var $begin = toAbsoluteIndex(begin, length);\n      return new (speciesConstructor(O, O[DEF_CONSTRUCTOR]))(\n        O.buffer,\n        O.byteOffset + $begin * O.BYTES_PER_ELEMENT,\n        toLength((end === undefined ? length : toAbsoluteIndex(end, length)) - $begin)\n      );\n    }\n  };\n\n  var $slice = function slice(start, end) {\n    return speciesFromList(this, arraySlice.call(validate(this), start, end));\n  };\n\n  var $set = function set(arrayLike /* , offset */) {\n    validate(this);\n    var offset = toOffset(arguments[1], 1);\n    var length = this.length;\n    var src = toObject(arrayLike);\n    var len = toLength(src.length);\n    var index = 0;\n    if (len + offset > length) throw RangeError(WRONG_LENGTH);\n    while (index < len) this[offset + index] = src[index++];\n  };\n\n  var $iterators = {\n    entries: function entries() {\n      return arrayEntries.call(validate(this));\n    },\n    keys: function keys() {\n      return arrayKeys.call(validate(this));\n    },\n    values: function values() {\n      return arrayValues.call(validate(this));\n    }\n  };\n\n  var isTAIndex = function (target, key) {\n    return isObject(target)\n      && target[TYPED_ARRAY]\n      && typeof key != 'symbol'\n      && key in target\n      && String(+key) == String(key);\n  };\n  var $getDesc = function getOwnPropertyDescriptor(target, key) {\n    return isTAIndex(target, key = toPrimitive(key, true))\n      ? propertyDesc(2, target[key])\n      : gOPD(target, key);\n  };\n  var $setDesc = function defineProperty(target, key, desc) {\n    if (isTAIndex(target, key = toPrimitive(key, true))\n      && isObject(desc)\n      && has(desc, 'value')\n      && !has(desc, 'get')\n      && !has(desc, 'set')\n      // TODO: add validation descriptor w/o calling accessors\n      && !desc.configurable\n      && (!has(desc, 'writable') || desc.writable)\n      && (!has(desc, 'enumerable') || desc.enumerable)\n    ) {\n      target[key] = desc.value;\n      return target;\n    } return dP(target, key, desc);\n  };\n\n  if (!ALL_CONSTRUCTORS) {\n    $GOPD.f = $getDesc;\n    $DP.f = $setDesc;\n  }\n\n  $export($export.S + $export.F * !ALL_CONSTRUCTORS, 'Object', {\n    getOwnPropertyDescriptor: $getDesc,\n    defineProperty: $setDesc\n  });\n\n  if (fails(function () { arrayToString.call({}); })) {\n    arrayToString = arrayToLocaleString = function toString() {\n      return arrayJoin.call(this);\n    };\n  }\n\n  var $TypedArrayPrototype$ = redefineAll({}, proto);\n  redefineAll($TypedArrayPrototype$, $iterators);\n  hide($TypedArrayPrototype$, ITERATOR, $iterators.values);\n  redefineAll($TypedArrayPrototype$, {\n    slice: $slice,\n    set: $set,\n    constructor: function () { /* noop */ },\n    toString: arrayToString,\n    toLocaleString: $toLocaleString\n  });\n  addGetter($TypedArrayPrototype$, 'buffer', 'b');\n  addGetter($TypedArrayPrototype$, 'byteOffset', 'o');\n  addGetter($TypedArrayPrototype$, 'byteLength', 'l');\n  addGetter($TypedArrayPrototype$, 'length', 'e');\n  dP($TypedArrayPrototype$, TAG, {\n    get: function () { return this[TYPED_ARRAY]; }\n  });\n\n  // eslint-disable-next-line max-statements\n  module.exports = function (KEY, BYTES, wrapper, CLAMPED) {\n    CLAMPED = !!CLAMPED;\n    var NAME = KEY + (CLAMPED ? 'Clamped' : '') + 'Array';\n    var GETTER = 'get' + KEY;\n    var SETTER = 'set' + KEY;\n    var TypedArray = global[NAME];\n    var Base = TypedArray || {};\n    var TAC = TypedArray && getPrototypeOf(TypedArray);\n    var FORCED = !TypedArray || !$typed.ABV;\n    var O = {};\n    var TypedArrayPrototype = TypedArray && TypedArray[PROTOTYPE];\n    var getter = function (that, index) {\n      var data = that._d;\n      return data.v[GETTER](index * BYTES + data.o, LITTLE_ENDIAN);\n    };\n    var setter = function (that, index, value) {\n      var data = that._d;\n      if (CLAMPED) value = (value = Math.round(value)) < 0 ? 0 : value > 0xff ? 0xff : value & 0xff;\n      data.v[SETTER](index * BYTES + data.o, value, LITTLE_ENDIAN);\n    };\n    var addElement = function (that, index) {\n      dP(that, index, {\n        get: function () {\n          return getter(this, index);\n        },\n        set: function (value) {\n          return setter(this, index, value);\n        },\n        enumerable: true\n      });\n    };\n    if (FORCED) {\n      TypedArray = wrapper(function (that, data, $offset, $length) {\n        anInstance(that, TypedArray, NAME, '_d');\n        var index = 0;\n        var offset = 0;\n        var buffer, byteLength, length, klass;\n        if (!isObject(data)) {\n          length = toIndex(data);\n          byteLength = length * BYTES;\n          buffer = new $ArrayBuffer(byteLength);\n        } else if (data instanceof $ArrayBuffer || (klass = classof(data)) == ARRAY_BUFFER || klass == SHARED_BUFFER) {\n          buffer = data;\n          offset = toOffset($offset, BYTES);\n          var $len = data.byteLength;\n          if ($length === undefined) {\n            if ($len % BYTES) throw RangeError(WRONG_LENGTH);\n            byteLength = $len - offset;\n            if (byteLength < 0) throw RangeError(WRONG_LENGTH);\n          } else {\n            byteLength = toLength($length) * BYTES;\n            if (byteLength + offset > $len) throw RangeError(WRONG_LENGTH);\n          }\n          length = byteLength / BYTES;\n        } else if (TYPED_ARRAY in data) {\n          return fromList(TypedArray, data);\n        } else {\n          return $from.call(TypedArray, data);\n        }\n        hide(that, '_d', {\n          b: buffer,\n          o: offset,\n          l: byteLength,\n          e: length,\n          v: new $DataView(buffer)\n        });\n        while (index < length) addElement(that, index++);\n      });\n      TypedArrayPrototype = TypedArray[PROTOTYPE] = create($TypedArrayPrototype$);\n      hide(TypedArrayPrototype, 'constructor', TypedArray);\n    } else if (!fails(function () {\n      TypedArray(1);\n    }) || !fails(function () {\n      new TypedArray(-1); // eslint-disable-line no-new\n    }) || !$iterDetect(function (iter) {\n      new TypedArray(); // eslint-disable-line no-new\n      new TypedArray(null); // eslint-disable-line no-new\n      new TypedArray(1.5); // eslint-disable-line no-new\n      new TypedArray(iter); // eslint-disable-line no-new\n    }, true)) {\n      TypedArray = wrapper(function (that, data, $offset, $length) {\n        anInstance(that, TypedArray, NAME);\n        var klass;\n        // `ws` module bug, temporarily remove validation length for Uint8Array\n        // https://github.com/websockets/ws/pull/645\n        if (!isObject(data)) return new Base(toIndex(data));\n        if (data instanceof $ArrayBuffer || (klass = classof(data)) == ARRAY_BUFFER || klass == SHARED_BUFFER) {\n          return $length !== undefined\n            ? new Base(data, toOffset($offset, BYTES), $length)\n            : $offset !== undefined\n              ? new Base(data, toOffset($offset, BYTES))\n              : new Base(data);\n        }\n        if (TYPED_ARRAY in data) return fromList(TypedArray, data);\n        return $from.call(TypedArray, data);\n      });\n      arrayForEach(TAC !== Function.prototype ? gOPN(Base).concat(gOPN(TAC)) : gOPN(Base), function (key) {\n        if (!(key in TypedArray)) hide(TypedArray, key, Base[key]);\n      });\n      TypedArray[PROTOTYPE] = TypedArrayPrototype;\n      if (!LIBRARY) TypedArrayPrototype.constructor = TypedArray;\n    }\n    var $nativeIterator = TypedArrayPrototype[ITERATOR];\n    var CORRECT_ITER_NAME = !!$nativeIterator\n      && ($nativeIterator.name == 'values' || $nativeIterator.name == undefined);\n    var $iterator = $iterators.values;\n    hide(TypedArray, TYPED_CONSTRUCTOR, true);\n    hide(TypedArrayPrototype, TYPED_ARRAY, NAME);\n    hide(TypedArrayPrototype, VIEW, true);\n    hide(TypedArrayPrototype, DEF_CONSTRUCTOR, TypedArray);\n\n    if (CLAMPED ? new TypedArray(1)[TAG] != NAME : !(TAG in TypedArrayPrototype)) {\n      dP(TypedArrayPrototype, TAG, {\n        get: function () { return NAME; }\n      });\n    }\n\n    O[NAME] = TypedArray;\n\n    $export($export.G + $export.W + $export.F * (TypedArray != Base), O);\n\n    $export($export.S, NAME, {\n      BYTES_PER_ELEMENT: BYTES\n    });\n\n    $export($export.S + $export.F * fails(function () { Base.of.call(TypedArray, 1); }), NAME, {\n      from: $from,\n      of: $of\n    });\n\n    if (!(BYTES_PER_ELEMENT in TypedArrayPrototype)) hide(TypedArrayPrototype, BYTES_PER_ELEMENT, BYTES);\n\n    $export($export.P, NAME, proto);\n\n    setSpecies(NAME);\n\n    $export($export.P + $export.F * FORCED_SET, NAME, { set: $set });\n\n    $export($export.P + $export.F * !CORRECT_ITER_NAME, NAME, $iterators);\n\n    if (!LIBRARY && TypedArrayPrototype.toString != arrayToString) TypedArrayPrototype.toString = arrayToString;\n\n    $export($export.P + $export.F * fails(function () {\n      new TypedArray(1).slice();\n    }), NAME, { slice: $slice });\n\n    $export($export.P + $export.F * (fails(function () {\n      return [1, 2].toLocaleString() != new TypedArray([1, 2]).toLocaleString();\n    }) || !fails(function () {\n      TypedArrayPrototype.toLocaleString.call([1, 2]);\n    })), NAME, { toLocaleString: $toLocaleString });\n\n    Iterators[NAME] = CORRECT_ITER_NAME ? $nativeIterator : $iterator;\n    if (!LIBRARY && !CORRECT_ITER_NAME) hide(TypedArrayPrototype, ITERATOR, $iterator);\n  };\n} else module.exports = function () { /* empty */ };\n","'use strict';\nvar global = require('./_global');\nvar DESCRIPTORS = require('./_descriptors');\nvar LIBRARY = require('./_library');\nvar $typed = require('./_typed');\nvar hide = require('./_hide');\nvar redefineAll = require('./_redefine-all');\nvar fails = require('./_fails');\nvar anInstance = require('./_an-instance');\nvar toInteger = require('./_to-integer');\nvar toLength = require('./_to-length');\nvar toIndex = require('./_to-index');\nvar gOPN = require('./_object-gopn').f;\nvar dP = require('./_object-dp').f;\nvar arrayFill = require('./_array-fill');\nvar setToStringTag = require('./_set-to-string-tag');\nvar ARRAY_BUFFER = 'ArrayBuffer';\nvar DATA_VIEW = 'DataView';\nvar PROTOTYPE = 'prototype';\nvar WRONG_LENGTH = 'Wrong length!';\nvar WRONG_INDEX = 'Wrong index!';\nvar $ArrayBuffer = global[ARRAY_BUFFER];\nvar $DataView = global[DATA_VIEW];\nvar Math = global.Math;\nvar RangeError = global.RangeError;\n// eslint-disable-next-line no-shadow-restricted-names\nvar Infinity = global.Infinity;\nvar BaseBuffer = $ArrayBuffer;\nvar abs = Math.abs;\nvar pow = Math.pow;\nvar floor = Math.floor;\nvar log = Math.log;\nvar LN2 = Math.LN2;\nvar BUFFER = 'buffer';\nvar BYTE_LENGTH = 'byteLength';\nvar BYTE_OFFSET = 'byteOffset';\nvar $BUFFER = DESCRIPTORS ? '_b' : BUFFER;\nvar $LENGTH = DESCRIPTORS ? '_l' : BYTE_LENGTH;\nvar $OFFSET = DESCRIPTORS ? '_o' : BYTE_OFFSET;\n\n// IEEE754 conversions based on https://github.com/feross/ieee754\nfunction packIEEE754(value, mLen, nBytes) {\n  var buffer = new Array(nBytes);\n  var eLen = nBytes * 8 - mLen - 1;\n  var eMax = (1 << eLen) - 1;\n  var eBias = eMax >> 1;\n  var rt = mLen === 23 ? pow(2, -24) - pow(2, -77) : 0;\n  var i = 0;\n  var s = value < 0 || value === 0 && 1 / value < 0 ? 1 : 0;\n  var e, m, c;\n  value = abs(value);\n  // eslint-disable-next-line no-self-compare\n  if (value != value || value === Infinity) {\n    // eslint-disable-next-line no-self-compare\n    m = value != value ? 1 : 0;\n    e = eMax;\n  } else {\n    e = floor(log(value) / LN2);\n    if (value * (c = pow(2, -e)) < 1) {\n      e--;\n      c *= 2;\n    }\n    if (e + eBias >= 1) {\n      value += rt / c;\n    } else {\n      value += rt * pow(2, 1 - eBias);\n    }\n    if (value * c >= 2) {\n      e++;\n      c /= 2;\n    }\n    if (e + eBias >= eMax) {\n      m = 0;\n      e = eMax;\n    } else if (e + eBias >= 1) {\n      m = (value * c - 1) * pow(2, mLen);\n      e = e + eBias;\n    } else {\n      m = value * pow(2, eBias - 1) * pow(2, mLen);\n      e = 0;\n    }\n  }\n  for (; mLen >= 8; buffer[i++] = m & 255, m /= 256, mLen -= 8);\n  e = e << mLen | m;\n  eLen += mLen;\n  for (; eLen > 0; buffer[i++] = e & 255, e /= 256, eLen -= 8);\n  buffer[--i] |= s * 128;\n  return buffer;\n}\nfunction unpackIEEE754(buffer, mLen, nBytes) {\n  var eLen = nBytes * 8 - mLen - 1;\n  var eMax = (1 << eLen) - 1;\n  var eBias = eMax >> 1;\n  var nBits = eLen - 7;\n  var i = nBytes - 1;\n  var s = buffer[i--];\n  var e = s & 127;\n  var m;\n  s >>= 7;\n  for (; nBits > 0; e = e * 256 + buffer[i], i--, nBits -= 8);\n  m = e & (1 << -nBits) - 1;\n  e >>= -nBits;\n  nBits += mLen;\n  for (; nBits > 0; m = m * 256 + buffer[i], i--, nBits -= 8);\n  if (e === 0) {\n    e = 1 - eBias;\n  } else if (e === eMax) {\n    return m ? NaN : s ? -Infinity : Infinity;\n  } else {\n    m = m + pow(2, mLen);\n    e = e - eBias;\n  } return (s ? -1 : 1) * m * pow(2, e - mLen);\n}\n\nfunction unpackI32(bytes) {\n  return bytes[3] << 24 | bytes[2] << 16 | bytes[1] << 8 | bytes[0];\n}\nfunction packI8(it) {\n  return [it & 0xff];\n}\nfunction packI16(it) {\n  return [it & 0xff, it >> 8 & 0xff];\n}\nfunction packI32(it) {\n  return [it & 0xff, it >> 8 & 0xff, it >> 16 & 0xff, it >> 24 & 0xff];\n}\nfunction packF64(it) {\n  return packIEEE754(it, 52, 8);\n}\nfunction packF32(it) {\n  return packIEEE754(it, 23, 4);\n}\n\nfunction addGetter(C, key, internal) {\n  dP(C[PROTOTYPE], key, { get: function () { return this[internal]; } });\n}\n\nfunction get(view, bytes, index, isLittleEndian) {\n  var numIndex = +index;\n  var intIndex = toIndex(numIndex);\n  if (intIndex + bytes > view[$LENGTH]) throw RangeError(WRONG_INDEX);\n  var store = view[$BUFFER]._b;\n  var start = intIndex + view[$OFFSET];\n  var pack = store.slice(start, start + bytes);\n  return isLittleEndian ? pack : pack.reverse();\n}\nfunction set(view, bytes, index, conversion, value, isLittleEndian) {\n  var numIndex = +index;\n  var intIndex = toIndex(numIndex);\n  if (intIndex + bytes > view[$LENGTH]) throw RangeError(WRONG_INDEX);\n  var store = view[$BUFFER]._b;\n  var start = intIndex + view[$OFFSET];\n  var pack = conversion(+value);\n  for (var i = 0; i < bytes; i++) store[start + i] = pack[isLittleEndian ? i : bytes - i - 1];\n}\n\nif (!$typed.ABV) {\n  $ArrayBuffer = function ArrayBuffer(length) {\n    anInstance(this, $ArrayBuffer, ARRAY_BUFFER);\n    var byteLength = toIndex(length);\n    this._b = arrayFill.call(new Array(byteLength), 0);\n    this[$LENGTH] = byteLength;\n  };\n\n  $DataView = function DataView(buffer, byteOffset, byteLength) {\n    anInstance(this, $DataView, DATA_VIEW);\n    anInstance(buffer, $ArrayBuffer, DATA_VIEW);\n    var bufferLength = buffer[$LENGTH];\n    var offset = toInteger(byteOffset);\n    if (offset < 0 || offset > bufferLength) throw RangeError('Wrong offset!');\n    byteLength = byteLength === undefined ? bufferLength - offset : toLength(byteLength);\n    if (offset + byteLength > bufferLength) throw RangeError(WRONG_LENGTH);\n    this[$BUFFER] = buffer;\n    this[$OFFSET] = offset;\n    this[$LENGTH] = byteLength;\n  };\n\n  if (DESCRIPTORS) {\n    addGetter($ArrayBuffer, BYTE_LENGTH, '_l');\n    addGetter($DataView, BUFFER, '_b');\n    addGetter($DataView, BYTE_LENGTH, '_l');\n    addGetter($DataView, BYTE_OFFSET, '_o');\n  }\n\n  redefineAll($DataView[PROTOTYPE], {\n    getInt8: function getInt8(byteOffset) {\n      return get(this, 1, byteOffset)[0] << 24 >> 24;\n    },\n    getUint8: function getUint8(byteOffset) {\n      return get(this, 1, byteOffset)[0];\n    },\n    getInt16: function getInt16(byteOffset /* , littleEndian */) {\n      var bytes = get(this, 2, byteOffset, arguments[1]);\n      return (bytes[1] << 8 | bytes[0]) << 16 >> 16;\n    },\n    getUint16: function getUint16(byteOffset /* , littleEndian */) {\n      var bytes = get(this, 2, byteOffset, arguments[1]);\n      return bytes[1] << 8 | bytes[0];\n    },\n    getInt32: function getInt32(byteOffset /* , littleEndian */) {\n      return unpackI32(get(this, 4, byteOffset, arguments[1]));\n    },\n    getUint32: function getUint32(byteOffset /* , littleEndian */) {\n      return unpackI32(get(this, 4, byteOffset, arguments[1])) >>> 0;\n    },\n    getFloat32: function getFloat32(byteOffset /* , littleEndian */) {\n      return unpackIEEE754(get(this, 4, byteOffset, arguments[1]), 23, 4);\n    },\n    getFloat64: function getFloat64(byteOffset /* , littleEndian */) {\n      return unpackIEEE754(get(this, 8, byteOffset, arguments[1]), 52, 8);\n    },\n    setInt8: function setInt8(byteOffset, value) {\n      set(this, 1, byteOffset, packI8, value);\n    },\n    setUint8: function setUint8(byteOffset, value) {\n      set(this, 1, byteOffset, packI8, value);\n    },\n    setInt16: function setInt16(byteOffset, value /* , littleEndian */) {\n      set(this, 2, byteOffset, packI16, value, arguments[2]);\n    },\n    setUint16: function setUint16(byteOffset, value /* , littleEndian */) {\n      set(this, 2, byteOffset, packI16, value, arguments[2]);\n    },\n    setInt32: function setInt32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packI32, value, arguments[2]);\n    },\n    setUint32: function setUint32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packI32, value, arguments[2]);\n    },\n    setFloat32: function setFloat32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packF32, value, arguments[2]);\n    },\n    setFloat64: function setFloat64(byteOffset, value /* , littleEndian */) {\n      set(this, 8, byteOffset, packF64, value, arguments[2]);\n    }\n  });\n} else {\n  if (!fails(function () {\n    $ArrayBuffer(1);\n  }) || !fails(function () {\n    new $ArrayBuffer(-1); // eslint-disable-line no-new\n  }) || fails(function () {\n    new $ArrayBuffer(); // eslint-disable-line no-new\n    new $ArrayBuffer(1.5); // eslint-disable-line no-new\n    new $ArrayBuffer(NaN); // eslint-disable-line no-new\n    return $ArrayBuffer.name != ARRAY_BUFFER;\n  })) {\n    $ArrayBuffer = function ArrayBuffer(length) {\n      anInstance(this, $ArrayBuffer);\n      return new BaseBuffer(toIndex(length));\n    };\n    var ArrayBufferProto = $ArrayBuffer[PROTOTYPE] = BaseBuffer[PROTOTYPE];\n    for (var keys = gOPN(BaseBuffer), j = 0, key; keys.length > j;) {\n      if (!((key = keys[j++]) in $ArrayBuffer)) hide($ArrayBuffer, key, BaseBuffer[key]);\n    }\n    if (!LIBRARY) ArrayBufferProto.constructor = $ArrayBuffer;\n  }\n  // iOS Safari 7.x bug\n  var view = new $DataView(new $ArrayBuffer(2));\n  var $setInt8 = $DataView[PROTOTYPE].setInt8;\n  view.setInt8(0, 2147483648);\n  view.setInt8(1, 2147483649);\n  if (view.getInt8(0) || !view.getInt8(1)) redefineAll($DataView[PROTOTYPE], {\n    setInt8: function setInt8(byteOffset, value) {\n      $setInt8.call(this, byteOffset, value << 24 >> 24);\n    },\n    setUint8: function setUint8(byteOffset, value) {\n      $setInt8.call(this, byteOffset, value << 24 >> 24);\n    }\n  }, true);\n}\nsetToStringTag($ArrayBuffer, ARRAY_BUFFER);\nsetToStringTag($DataView, DATA_VIEW);\nhide($DataView[PROTOTYPE], $typed.VIEW, true);\nexports[ARRAY_BUFFER] = $ArrayBuffer;\nexports[DATA_VIEW] = $DataView;\n","var global = require('./_global');\nvar hide = require('./_hide');\nvar uid = require('./_uid');\nvar TYPED = uid('typed_array');\nvar VIEW = uid('view');\nvar ABV = !!(global.ArrayBuffer && global.DataView);\nvar CONSTR = ABV;\nvar i = 0;\nvar l = 9;\nvar Typed;\n\nvar TypedArrayConstructors = (\n  'Int8Array,Uint8Array,Uint8ClampedArray,Int16Array,Uint16Array,Int32Array,Uint32Array,Float32Array,Float64Array'\n).split(',');\n\nwhile (i < l) {\n  if (Typed = global[TypedArrayConstructors[i++]]) {\n    hide(Typed.prototype, TYPED, true);\n    hide(Typed.prototype, VIEW, true);\n  } else CONSTR = false;\n}\n\nmodule.exports = {\n  ABV: ABV,\n  CONSTR: CONSTR,\n  TYPED: TYPED,\n  VIEW: VIEW\n};\n","var id = 0;\nvar px = Math.random();\nmodule.exports = function (key) {\n  return 'Symbol('.concat(key === undefined ? '' : key, ')_', (++id + px).toString(36));\n};\n","var global = require('./_global');\nvar navigator = global.navigator;\n\nmodule.exports = navigator && navigator.userAgent || '';\n","var isObject = require('./_is-object');\nmodule.exports = function (it, TYPE) {\n  if (!isObject(it) || it._t !== TYPE) throw TypeError('Incompatible receiver, ' + TYPE + ' required!');\n  return it;\n};\n","var global = require('./_global');\nvar core = require('./_core');\nvar LIBRARY = require('./_library');\nvar wksExt = require('./_wks-ext');\nvar defineProperty = require('./_object-dp').f;\nmodule.exports = function (name) {\n  var $Symbol = core.Symbol || (core.Symbol = LIBRARY ? {} : global.Symbol || {});\n  if (name.charAt(0) != '_' && !(name in $Symbol)) defineProperty($Symbol, name, { value: wksExt.f(name) });\n};\n","exports.f = require('./_wks');\n","var store = require('./_shared')('wks');\nvar uid = require('./_uid');\nvar Symbol = require('./_global').Symbol;\nvar USE_SYMBOL = typeof Symbol == 'function';\n\nvar $exports = module.exports = function (name) {\n  return store[name] || (store[name] =\n    USE_SYMBOL && Symbol[name] || (USE_SYMBOL ? Symbol : uid)('Symbol.' + name));\n};\n\n$exports.store = store;\n","var classof = require('./_classof');\nvar ITERATOR = require('./_wks')('iterator');\nvar Iterators = require('./_iterators');\nmodule.exports = require('./_core').getIteratorMethod = function (it) {\n  if (it != undefined) return it[ITERATOR]\n    || it['@@iterator']\n    || Iterators[classof(it)];\n};\n","// https://github.com/benjamingr/RexExp.escape\nvar $export = require('./_export');\nvar $re = require('./_replacer')(/[\\\\^$*+?.()|[\\]{}]/g, '\\\\$&');\n\n$export($export.S, 'RegExp', { escape: function escape(it) { return $re(it); } });\n","// 22.1.3.3 Array.prototype.copyWithin(target, start, end = this.length)\nvar $export = require('./_export');\n\n$export($export.P, 'Array', { copyWithin: require('./_array-copy-within') });\n\nrequire('./_add-to-unscopables')('copyWithin');\n","'use strict';\nvar $export = require('./_export');\nvar $every = require('./_array-methods')(4);\n\n$export($export.P + $export.F * !require('./_strict-method')([].every, true), 'Array', {\n  // 22.1.3.5 / 15.4.4.16 Array.prototype.every(callbackfn [, thisArg])\n  every: function every(callbackfn /* , thisArg */) {\n    return $every(this, callbackfn, arguments[1]);\n  }\n});\n","// 22.1.3.6 Array.prototype.fill(value, start = 0, end = this.length)\nvar $export = require('./_export');\n\n$export($export.P, 'Array', { fill: require('./_array-fill') });\n\nrequire('./_add-to-unscopables')('fill');\n","'use strict';\nvar $export = require('./_export');\nvar $filter = require('./_array-methods')(2);\n\n$export($export.P + $export.F * !require('./_strict-method')([].filter, true), 'Array', {\n  // 22.1.3.7 / 15.4.4.20 Array.prototype.filter(callbackfn [, thisArg])\n  filter: function filter(callbackfn /* , thisArg */) {\n    return $filter(this, callbackfn, arguments[1]);\n  }\n});\n","'use strict';\n// 22.1.3.9 Array.prototype.findIndex(predicate, thisArg = undefined)\nvar $export = require('./_export');\nvar $find = require('./_array-methods')(6);\nvar KEY = 'findIndex';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  findIndex: function findIndex(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\nrequire('./_add-to-unscopables')(KEY);\n","'use strict';\n// 22.1.3.8 Array.prototype.find(predicate, thisArg = undefined)\nvar $export = require('./_export');\nvar $find = require('./_array-methods')(5);\nvar KEY = 'find';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  find: function find(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\nrequire('./_add-to-unscopables')(KEY);\n","'use strict';\nvar $export = require('./_export');\nvar $forEach = require('./_array-methods')(0);\nvar STRICT = require('./_strict-method')([].forEach, true);\n\n$export($export.P + $export.F * !STRICT, 'Array', {\n  // 22.1.3.10 / 15.4.4.18 Array.prototype.forEach(callbackfn [, thisArg])\n  forEach: function forEach(callbackfn /* , thisArg */) {\n    return $forEach(this, callbackfn, arguments[1]);\n  }\n});\n","'use strict';\nvar ctx = require('./_ctx');\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar call = require('./_iter-call');\nvar isArrayIter = require('./_is-array-iter');\nvar toLength = require('./_to-length');\nvar createProperty = require('./_create-property');\nvar getIterFn = require('./core.get-iterator-method');\n\n$export($export.S + $export.F * !require('./_iter-detect')(function (iter) { Array.from(iter); }), 'Array', {\n  // 22.1.2.1 Array.from(arrayLike, mapfn = undefined, thisArg = undefined)\n  from: function from(arrayLike /* , mapfn = undefined, thisArg = undefined */) {\n    var O = toObject(arrayLike);\n    var C = typeof this == 'function' ? this : Array;\n    var aLen = arguments.length;\n    var mapfn = aLen > 1 ? arguments[1] : undefined;\n    var mapping = mapfn !== undefined;\n    var index = 0;\n    var iterFn = getIterFn(O);\n    var length, result, step, iterator;\n    if (mapping) mapfn = ctx(mapfn, aLen > 2 ? arguments[2] : undefined, 2);\n    // if object isn't iterable or it's array with default iterator - use simple case\n    if (iterFn != undefined && !(C == Array && isArrayIter(iterFn))) {\n      for (iterator = iterFn.call(O), result = new C(); !(step = iterator.next()).done; index++) {\n        createProperty(result, index, mapping ? call(iterator, mapfn, [step.value, index], true) : step.value);\n      }\n    } else {\n      length = toLength(O.length);\n      for (result = new C(length); length > index; index++) {\n        createProperty(result, index, mapping ? mapfn(O[index], index) : O[index]);\n      }\n    }\n    result.length = index;\n    return result;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $indexOf = require('./_array-includes')(false);\nvar $native = [].indexOf;\nvar NEGATIVE_ZERO = !!$native && 1 / [1].indexOf(1, -0) < 0;\n\n$export($export.P + $export.F * (NEGATIVE_ZERO || !require('./_strict-method')($native)), 'Array', {\n  // 22.1.3.11 / 15.4.4.14 Array.prototype.indexOf(searchElement [, fromIndex])\n  indexOf: function indexOf(searchElement /* , fromIndex = 0 */) {\n    return NEGATIVE_ZERO\n      // convert -0 to +0\n      ? $native.apply(this, arguments) || 0\n      : $indexOf(this, searchElement, arguments[1]);\n  }\n});\n","// 22.1.2.2 / 15.4.3.2 Array.isArray(arg)\nvar $export = require('./_export');\n\n$export($export.S, 'Array', { isArray: require('./_is-array') });\n","'use strict';\nvar addToUnscopables = require('./_add-to-unscopables');\nvar step = require('./_iter-step');\nvar Iterators = require('./_iterators');\nvar toIObject = require('./_to-iobject');\n\n// 22.1.3.4 Array.prototype.entries()\n// 22.1.3.13 Array.prototype.keys()\n// 22.1.3.29 Array.prototype.values()\n// 22.1.3.30 Array.prototype[@@iterator]()\nmodule.exports = require('./_iter-define')(Array, 'Array', function (iterated, kind) {\n  this._t = toIObject(iterated); // target\n  this._i = 0;                   // next index\n  this._k = kind;                // kind\n// 22.1.5.2.1 %ArrayIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var kind = this._k;\n  var index = this._i++;\n  if (!O || index >= O.length) {\n    this._t = undefined;\n    return step(1);\n  }\n  if (kind == 'keys') return step(0, index);\n  if (kind == 'values') return step(0, O[index]);\n  return step(0, [index, O[index]]);\n}, 'values');\n\n// argumentsList[@@iterator] is %ArrayProto_values% (9.4.4.6, 9.4.4.7)\nIterators.Arguments = Iterators.Array;\n\naddToUnscopables('keys');\naddToUnscopables('values');\naddToUnscopables('entries');\n","'use strict';\n// 22.1.3.13 Array.prototype.join(separator)\nvar $export = require('./_export');\nvar toIObject = require('./_to-iobject');\nvar arrayJoin = [].join;\n\n// fallback for not array-like strings\n$export($export.P + $export.F * (require('./_iobject') != Object || !require('./_strict-method')(arrayJoin)), 'Array', {\n  join: function join(separator) {\n    return arrayJoin.call(toIObject(this), separator === undefined ? ',' : separator);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar toIObject = require('./_to-iobject');\nvar toInteger = require('./_to-integer');\nvar toLength = require('./_to-length');\nvar $native = [].lastIndexOf;\nvar NEGATIVE_ZERO = !!$native && 1 / [1].lastIndexOf(1, -0) < 0;\n\n$export($export.P + $export.F * (NEGATIVE_ZERO || !require('./_strict-method')($native)), 'Array', {\n  // 22.1.3.14 / 15.4.4.15 Array.prototype.lastIndexOf(searchElement [, fromIndex])\n  lastIndexOf: function lastIndexOf(searchElement /* , fromIndex = @[*-1] */) {\n    // convert -0 to +0\n    if (NEGATIVE_ZERO) return $native.apply(this, arguments) || 0;\n    var O = toIObject(this);\n    var length = toLength(O.length);\n    var index = length - 1;\n    if (arguments.length > 1) index = Math.min(index, toInteger(arguments[1]));\n    if (index < 0) index = length + index;\n    for (;index >= 0; index--) if (index in O) if (O[index] === searchElement) return index || 0;\n    return -1;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $map = require('./_array-methods')(1);\n\n$export($export.P + $export.F * !require('./_strict-method')([].map, true), 'Array', {\n  // 22.1.3.15 / 15.4.4.19 Array.prototype.map(callbackfn [, thisArg])\n  map: function map(callbackfn /* , thisArg */) {\n    return $map(this, callbackfn, arguments[1]);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar createProperty = require('./_create-property');\n\n// WebKit Array.of isn't generic\n$export($export.S + $export.F * require('./_fails')(function () {\n  function F() { /* empty */ }\n  return !(Array.of.call(F) instanceof F);\n}), 'Array', {\n  // 22.1.2.3 Array.of( ...items)\n  of: function of(/* ...args */) {\n    var index = 0;\n    var aLen = arguments.length;\n    var result = new (typeof this == 'function' ? this : Array)(aLen);\n    while (aLen > index) createProperty(result, index, arguments[index++]);\n    result.length = aLen;\n    return result;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $reduce = require('./_array-reduce');\n\n$export($export.P + $export.F * !require('./_strict-method')([].reduceRight, true), 'Array', {\n  // 22.1.3.19 / 15.4.4.22 Array.prototype.reduceRight(callbackfn [, initialValue])\n  reduceRight: function reduceRight(callbackfn /* , initialValue */) {\n    return $reduce(this, callbackfn, arguments.length, arguments[1], true);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $reduce = require('./_array-reduce');\n\n$export($export.P + $export.F * !require('./_strict-method')([].reduce, true), 'Array', {\n  // 22.1.3.18 / 15.4.4.21 Array.prototype.reduce(callbackfn [, initialValue])\n  reduce: function reduce(callbackfn /* , initialValue */) {\n    return $reduce(this, callbackfn, arguments.length, arguments[1], false);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar html = require('./_html');\nvar cof = require('./_cof');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nvar toLength = require('./_to-length');\nvar arraySlice = [].slice;\n\n// fallback for not array-like ES3 strings and DOM objects\n$export($export.P + $export.F * require('./_fails')(function () {\n  if (html) arraySlice.call(html);\n}), 'Array', {\n  slice: function slice(begin, end) {\n    var len = toLength(this.length);\n    var klass = cof(this);\n    end = end === undefined ? len : end;\n    if (klass == 'Array') return arraySlice.call(this, begin, end);\n    var start = toAbsoluteIndex(begin, len);\n    var upTo = toAbsoluteIndex(end, len);\n    var size = toLength(upTo - start);\n    var cloned = new Array(size);\n    var i = 0;\n    for (; i < size; i++) cloned[i] = klass == 'String'\n      ? this.charAt(start + i)\n      : this[start + i];\n    return cloned;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $some = require('./_array-methods')(3);\n\n$export($export.P + $export.F * !require('./_strict-method')([].some, true), 'Array', {\n  // 22.1.3.23 / 15.4.4.17 Array.prototype.some(callbackfn [, thisArg])\n  some: function some(callbackfn /* , thisArg */) {\n    return $some(this, callbackfn, arguments[1]);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar aFunction = require('./_a-function');\nvar toObject = require('./_to-object');\nvar fails = require('./_fails');\nvar $sort = [].sort;\nvar test = [1, 2, 3];\n\n$export($export.P + $export.F * (fails(function () {\n  // IE8-\n  test.sort(undefined);\n}) || !fails(function () {\n  // V8 bug\n  test.sort(null);\n  // Old WebKit\n}) || !require('./_strict-method')($sort)), 'Array', {\n  // 22.1.3.25 Array.prototype.sort(comparefn)\n  sort: function sort(comparefn) {\n    return comparefn === undefined\n      ? $sort.call(toObject(this))\n      : $sort.call(toObject(this), aFunction(comparefn));\n  }\n});\n","require('./_set-species')('Array');\n","// 20.3.3.1 / 15.9.4.4 Date.now()\nvar $export = require('./_export');\n\n$export($export.S, 'Date', { now: function () { return new Date().getTime(); } });\n","// 20.3.4.36 / 15.9.5.43 Date.prototype.toISOString()\nvar $export = require('./_export');\nvar toISOString = require('./_date-to-iso-string');\n\n// PhantomJS / old WebKit has a broken implementations\n$export($export.P + $export.F * (Date.prototype.toISOString !== toISOString), 'Date', {\n  toISOString: toISOString\n});\n","'use strict';\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar toPrimitive = require('./_to-primitive');\n\n$export($export.P + $export.F * require('./_fails')(function () {\n  return new Date(NaN).toJSON() !== null\n    || Date.prototype.toJSON.call({ toISOString: function () { return 1; } }) !== 1;\n}), 'Date', {\n  // eslint-disable-next-line no-unused-vars\n  toJSON: function toJSON(key) {\n    var O = toObject(this);\n    var pv = toPrimitive(O);\n    return typeof pv == 'number' && !isFinite(pv) ? null : O.toISOString();\n  }\n});\n","var TO_PRIMITIVE = require('./_wks')('toPrimitive');\nvar proto = Date.prototype;\n\nif (!(TO_PRIMITIVE in proto)) require('./_hide')(proto, TO_PRIMITIVE, require('./_date-to-primitive'));\n","var DateProto = Date.prototype;\nvar INVALID_DATE = 'Invalid Date';\nvar TO_STRING = 'toString';\nvar $toString = DateProto[TO_STRING];\nvar getTime = DateProto.getTime;\nif (new Date(NaN) + '' != INVALID_DATE) {\n  require('./_redefine')(DateProto, TO_STRING, function toString() {\n    var value = getTime.call(this);\n    // eslint-disable-next-line no-self-compare\n    return value === value ? $toString.call(this) : INVALID_DATE;\n  });\n}\n","// 19.2.3.2 / 15.3.4.5 Function.prototype.bind(thisArg, args...)\nvar $export = require('./_export');\n\n$export($export.P, 'Function', { bind: require('./_bind') });\n","'use strict';\nvar isObject = require('./_is-object');\nvar getPrototypeOf = require('./_object-gpo');\nvar HAS_INSTANCE = require('./_wks')('hasInstance');\nvar FunctionProto = Function.prototype;\n// 19.2.3.6 Function.prototype[@@hasInstance](V)\nif (!(HAS_INSTANCE in FunctionProto)) require('./_object-dp').f(FunctionProto, HAS_INSTANCE, { value: function (O) {\n  if (typeof this != 'function' || !isObject(O)) return false;\n  if (!isObject(this.prototype)) return O instanceof this;\n  // for environment w/o native `@@hasInstance` logic enough `instanceof`, but add this:\n  while (O = getPrototypeOf(O)) if (this.prototype === O) return true;\n  return false;\n} });\n","var dP = require('./_object-dp').f;\nvar FProto = Function.prototype;\nvar nameRE = /^\\s*function ([^ (]*)/;\nvar NAME = 'name';\n\n// 19.2.4.2 name\nNAME in FProto || require('./_descriptors') && dP(FProto, NAME, {\n  configurable: true,\n  get: function () {\n    try {\n      return ('' + this).match(nameRE)[1];\n    } catch (e) {\n      return '';\n    }\n  }\n});\n","'use strict';\nvar strong = require('./_collection-strong');\nvar validate = require('./_validate-collection');\nvar MAP = 'Map';\n\n// 23.1 Map Objects\nmodule.exports = require('./_collection')(MAP, function (get) {\n  return function Map() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.1.3.6 Map.prototype.get(key)\n  get: function get(key) {\n    var entry = strong.getEntry(validate(this, MAP), key);\n    return entry && entry.v;\n  },\n  // 23.1.3.9 Map.prototype.set(key, value)\n  set: function set(key, value) {\n    return strong.def(validate(this, MAP), key === 0 ? 0 : key, value);\n  }\n}, strong, true);\n","// 20.2.2.3 Math.acosh(x)\nvar $export = require('./_export');\nvar log1p = require('./_math-log1p');\nvar sqrt = Math.sqrt;\nvar $acosh = Math.acosh;\n\n$export($export.S + $export.F * !($acosh\n  // V8 bug: https://code.google.com/p/v8/issues/detail?id=3509\n  && Math.floor($acosh(Number.MAX_VALUE)) == 710\n  // Tor Browser bug: Math.acosh(Infinity) -> NaN\n  && $acosh(Infinity) == Infinity\n), 'Math', {\n  acosh: function acosh(x) {\n    return (x = +x) < 1 ? NaN : x > 94906265.62425156\n      ? Math.log(x) + Math.LN2\n      : log1p(x - 1 + sqrt(x - 1) * sqrt(x + 1));\n  }\n});\n","// 20.2.2.5 Math.asinh(x)\nvar $export = require('./_export');\nvar $asinh = Math.asinh;\n\nfunction asinh(x) {\n  return !isFinite(x = +x) || x == 0 ? x : x < 0 ? -asinh(-x) : Math.log(x + Math.sqrt(x * x + 1));\n}\n\n// Tor Browser bug: Math.asinh(0) -> -0\n$export($export.S + $export.F * !($asinh && 1 / $asinh(0) > 0), 'Math', { asinh: asinh });\n","// 20.2.2.7 Math.atanh(x)\nvar $export = require('./_export');\nvar $atanh = Math.atanh;\n\n// Tor Browser bug: Math.atanh(-0) -> 0\n$export($export.S + $export.F * !($atanh && 1 / $atanh(-0) < 0), 'Math', {\n  atanh: function atanh(x) {\n    return (x = +x) == 0 ? x : Math.log((1 + x) / (1 - x)) / 2;\n  }\n});\n","// 20.2.2.9 Math.cbrt(x)\nvar $export = require('./_export');\nvar sign = require('./_math-sign');\n\n$export($export.S, 'Math', {\n  cbrt: function cbrt(x) {\n    return sign(x = +x) * Math.pow(Math.abs(x), 1 / 3);\n  }\n});\n","// 20.2.2.11 Math.clz32(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  clz32: function clz32(x) {\n    return (x >>>= 0) ? 31 - Math.floor(Math.log(x + 0.5) * Math.LOG2E) : 32;\n  }\n});\n","// 20.2.2.12 Math.cosh(x)\nvar $export = require('./_export');\nvar exp = Math.exp;\n\n$export($export.S, 'Math', {\n  cosh: function cosh(x) {\n    return (exp(x = +x) + exp(-x)) / 2;\n  }\n});\n","// 20.2.2.14 Math.expm1(x)\nvar $export = require('./_export');\nvar $expm1 = require('./_math-expm1');\n\n$export($export.S + $export.F * ($expm1 != Math.expm1), 'Math', { expm1: $expm1 });\n","// 20.2.2.16 Math.fround(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { fround: require('./_math-fround') });\n","// 20.2.2.17 Math.hypot([value1[, value2[, … ]]])\nvar $export = require('./_export');\nvar abs = Math.abs;\n\n$export($export.S, 'Math', {\n  hypot: function hypot(value1, value2) { // eslint-disable-line no-unused-vars\n    var sum = 0;\n    var i = 0;\n    var aLen = arguments.length;\n    var larg = 0;\n    var arg, div;\n    while (i < aLen) {\n      arg = abs(arguments[i++]);\n      if (larg < arg) {\n        div = larg / arg;\n        sum = sum * div * div + 1;\n        larg = arg;\n      } else if (arg > 0) {\n        div = arg / larg;\n        sum += div * div;\n      } else sum += arg;\n    }\n    return larg === Infinity ? Infinity : larg * Math.sqrt(sum);\n  }\n});\n","// 20.2.2.18 Math.imul(x, y)\nvar $export = require('./_export');\nvar $imul = Math.imul;\n\n// some WebKit versions fails with big numbers, some has wrong arity\n$export($export.S + $export.F * require('./_fails')(function () {\n  return $imul(0xffffffff, 5) != -5 || $imul.length != 2;\n}), 'Math', {\n  imul: function imul(x, y) {\n    var UINT16 = 0xffff;\n    var xn = +x;\n    var yn = +y;\n    var xl = UINT16 & xn;\n    var yl = UINT16 & yn;\n    return 0 | xl * yl + ((UINT16 & xn >>> 16) * yl + xl * (UINT16 & yn >>> 16) << 16 >>> 0);\n  }\n});\n","// 20.2.2.21 Math.log10(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  log10: function log10(x) {\n    return Math.log(x) * Math.LOG10E;\n  }\n});\n","// 20.2.2.20 Math.log1p(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { log1p: require('./_math-log1p') });\n","// 20.2.2.22 Math.log2(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  log2: function log2(x) {\n    return Math.log(x) / Math.LN2;\n  }\n});\n","// 20.2.2.28 Math.sign(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { sign: require('./_math-sign') });\n","// 20.2.2.30 Math.sinh(x)\nvar $export = require('./_export');\nvar expm1 = require('./_math-expm1');\nvar exp = Math.exp;\n\n// V8 near Chromium 38 has a problem with very small numbers\n$export($export.S + $export.F * require('./_fails')(function () {\n  return !Math.sinh(-2e-17) != -2e-17;\n}), 'Math', {\n  sinh: function sinh(x) {\n    return Math.abs(x = +x) < 1\n      ? (expm1(x) - expm1(-x)) / 2\n      : (exp(x - 1) - exp(-x - 1)) * (Math.E / 2);\n  }\n});\n","// 20.2.2.33 Math.tanh(x)\nvar $export = require('./_export');\nvar expm1 = require('./_math-expm1');\nvar exp = Math.exp;\n\n$export($export.S, 'Math', {\n  tanh: function tanh(x) {\n    var a = expm1(x = +x);\n    var b = expm1(-x);\n    return a == Infinity ? 1 : b == Infinity ? -1 : (a - b) / (exp(x) + exp(-x));\n  }\n});\n","// 20.2.2.34 Math.trunc(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  trunc: function trunc(it) {\n    return (it > 0 ? Math.floor : Math.ceil)(it);\n  }\n});\n","'use strict';\nvar global = require('./_global');\nvar has = require('./_has');\nvar cof = require('./_cof');\nvar inheritIfRequired = require('./_inherit-if-required');\nvar toPrimitive = require('./_to-primitive');\nvar fails = require('./_fails');\nvar gOPN = require('./_object-gopn').f;\nvar gOPD = require('./_object-gopd').f;\nvar dP = require('./_object-dp').f;\nvar $trim = require('./_string-trim').trim;\nvar NUMBER = 'Number';\nvar $Number = global[NUMBER];\nvar Base = $Number;\nvar proto = $Number.prototype;\n// Opera ~12 has broken Object#toString\nvar BROKEN_COF = cof(require('./_object-create')(proto)) == NUMBER;\nvar TRIM = 'trim' in String.prototype;\n\n// 7.1.3 ToNumber(argument)\nvar toNumber = function (argument) {\n  var it = toPrimitive(argument, false);\n  if (typeof it == 'string' && it.length > 2) {\n    it = TRIM ? it.trim() : $trim(it, 3);\n    var first = it.charCodeAt(0);\n    var third, radix, maxCode;\n    if (first === 43 || first === 45) {\n      third = it.charCodeAt(2);\n      if (third === 88 || third === 120) return NaN; // Number('+0x1') should be NaN, old V8 fix\n    } else if (first === 48) {\n      switch (it.charCodeAt(1)) {\n        case 66: case 98: radix = 2; maxCode = 49; break; // fast equal /^0b[01]+$/i\n        case 79: case 111: radix = 8; maxCode = 55; break; // fast equal /^0o[0-7]+$/i\n        default: return +it;\n      }\n      for (var digits = it.slice(2), i = 0, l = digits.length, code; i < l; i++) {\n        code = digits.charCodeAt(i);\n        // parseInt parses a string to a first unavailable symbol\n        // but ToNumber should return NaN if a string contains unavailable symbols\n        if (code < 48 || code > maxCode) return NaN;\n      } return parseInt(digits, radix);\n    }\n  } return +it;\n};\n\nif (!$Number(' 0o1') || !$Number('0b1') || $Number('+0x1')) {\n  $Number = function Number(value) {\n    var it = arguments.length < 1 ? 0 : value;\n    var that = this;\n    return that instanceof $Number\n      // check on 1..constructor(foo) case\n      && (BROKEN_COF ? fails(function () { proto.valueOf.call(that); }) : cof(that) != NUMBER)\n        ? inheritIfRequired(new Base(toNumber(it)), that, $Number) : toNumber(it);\n  };\n  for (var keys = require('./_descriptors') ? gOPN(Base) : (\n    // ES3:\n    'MAX_VALUE,MIN_VALUE,NaN,NEGATIVE_INFINITY,POSITIVE_INFINITY,' +\n    // ES6 (in case, if modules with ES6 Number statics required before):\n    'EPSILON,isFinite,isInteger,isNaN,isSafeInteger,MAX_SAFE_INTEGER,' +\n    'MIN_SAFE_INTEGER,parseFloat,parseInt,isInteger'\n  ).split(','), j = 0, key; keys.length > j; j++) {\n    if (has(Base, key = keys[j]) && !has($Number, key)) {\n      dP($Number, key, gOPD(Base, key));\n    }\n  }\n  $Number.prototype = proto;\n  proto.constructor = $Number;\n  require('./_redefine')(global, NUMBER, $Number);\n}\n","// 20.1.2.1 Number.EPSILON\nvar $export = require('./_export');\n\n$export($export.S, 'Number', { EPSILON: Math.pow(2, -52) });\n","// 20.1.2.2 Number.isFinite(number)\nvar $export = require('./_export');\nvar _isFinite = require('./_global').isFinite;\n\n$export($export.S, 'Number', {\n  isFinite: function isFinite(it) {\n    return typeof it == 'number' && _isFinite(it);\n  }\n});\n","// 20.1.2.3 Number.isInteger(number)\nvar $export = require('./_export');\n\n$export($export.S, 'Number', { isInteger: require('./_is-integer') });\n","// 20.1.2.4 Number.isNaN(number)\nvar $export = require('./_export');\n\n$export($export.S, 'Number', {\n  isNaN: function isNaN(number) {\n    // eslint-disable-next-line no-self-compare\n    return number != number;\n  }\n});\n","// 20.1.2.5 Number.isSafeInteger(number)\nvar $export = require('./_export');\nvar isInteger = require('./_is-integer');\nvar abs = Math.abs;\n\n$export($export.S, 'Number', {\n  isSafeInteger: function isSafeInteger(number) {\n    return isInteger(number) && abs(number) <= 0x1fffffffffffff;\n  }\n});\n","// 20.1.2.6 Number.MAX_SAFE_INTEGER\nvar $export = require('./_export');\n\n$export($export.S, 'Number', { MAX_SAFE_INTEGER: 0x1fffffffffffff });\n","// 20.1.2.10 Number.MIN_SAFE_INTEGER\nvar $export = require('./_export');\n\n$export($export.S, 'Number', { MIN_SAFE_INTEGER: -0x1fffffffffffff });\n","var $export = require('./_export');\nvar $parseFloat = require('./_parse-float');\n// 20.1.2.12 Number.parseFloat(string)\n$export($export.S + $export.F * (Number.parseFloat != $parseFloat), 'Number', { parseFloat: $parseFloat });\n","var $export = require('./_export');\nvar $parseInt = require('./_parse-int');\n// 20.1.2.13 Number.parseInt(string, radix)\n$export($export.S + $export.F * (Number.parseInt != $parseInt), 'Number', { parseInt: $parseInt });\n","'use strict';\nvar $export = require('./_export');\nvar toInteger = require('./_to-integer');\nvar aNumberValue = require('./_a-number-value');\nvar repeat = require('./_string-repeat');\nvar $toFixed = 1.0.toFixed;\nvar floor = Math.floor;\nvar data = [0, 0, 0, 0, 0, 0];\nvar ERROR = 'Number.toFixed: incorrect invocation!';\nvar ZERO = '0';\n\nvar multiply = function (n, c) {\n  var i = -1;\n  var c2 = c;\n  while (++i < 6) {\n    c2 += n * data[i];\n    data[i] = c2 % 1e7;\n    c2 = floor(c2 / 1e7);\n  }\n};\nvar divide = function (n) {\n  var i = 6;\n  var c = 0;\n  while (--i >= 0) {\n    c += data[i];\n    data[i] = floor(c / n);\n    c = (c % n) * 1e7;\n  }\n};\nvar numToString = function () {\n  var i = 6;\n  var s = '';\n  while (--i >= 0) {\n    if (s !== '' || i === 0 || data[i] !== 0) {\n      var t = String(data[i]);\n      s = s === '' ? t : s + repeat.call(ZERO, 7 - t.length) + t;\n    }\n  } return s;\n};\nvar pow = function (x, n, acc) {\n  return n === 0 ? acc : n % 2 === 1 ? pow(x, n - 1, acc * x) : pow(x * x, n / 2, acc);\n};\nvar log = function (x) {\n  var n = 0;\n  var x2 = x;\n  while (x2 >= 4096) {\n    n += 12;\n    x2 /= 4096;\n  }\n  while (x2 >= 2) {\n    n += 1;\n    x2 /= 2;\n  } return n;\n};\n\n$export($export.P + $export.F * (!!$toFixed && (\n  0.00008.toFixed(3) !== '0.000' ||\n  0.9.toFixed(0) !== '1' ||\n  1.255.toFixed(2) !== '1.25' ||\n  1000000000000000128.0.toFixed(0) !== '1000000000000000128'\n) || !require('./_fails')(function () {\n  // V8 ~ Android 4.3-\n  $toFixed.call({});\n})), 'Number', {\n  toFixed: function toFixed(fractionDigits) {\n    var x = aNumberValue(this, ERROR);\n    var f = toInteger(fractionDigits);\n    var s = '';\n    var m = ZERO;\n    var e, z, j, k;\n    if (f < 0 || f > 20) throw RangeError(ERROR);\n    // eslint-disable-next-line no-self-compare\n    if (x != x) return 'NaN';\n    if (x <= -1e21 || x >= 1e21) return String(x);\n    if (x < 0) {\n      s = '-';\n      x = -x;\n    }\n    if (x > 1e-21) {\n      e = log(x * pow(2, 69, 1)) - 69;\n      z = e < 0 ? x * pow(2, -e, 1) : x / pow(2, e, 1);\n      z *= 0x10000000000000;\n      e = 52 - e;\n      if (e > 0) {\n        multiply(0, z);\n        j = f;\n        while (j >= 7) {\n          multiply(1e7, 0);\n          j -= 7;\n        }\n        multiply(pow(10, j, 1), 0);\n        j = e - 1;\n        while (j >= 23) {\n          divide(1 << 23);\n          j -= 23;\n        }\n        divide(1 << j);\n        multiply(1, 1);\n        divide(2);\n        m = numToString();\n      } else {\n        multiply(0, z);\n        multiply(1 << -e, 0);\n        m = numToString() + repeat.call(ZERO, f);\n      }\n    }\n    if (f > 0) {\n      k = m.length;\n      m = s + (k <= f ? '0.' + repeat.call(ZERO, f - k) + m : m.slice(0, k - f) + '.' + m.slice(k - f));\n    } else {\n      m = s + m;\n    } return m;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $fails = require('./_fails');\nvar aNumberValue = require('./_a-number-value');\nvar $toPrecision = 1.0.toPrecision;\n\n$export($export.P + $export.F * ($fails(function () {\n  // IE7-\n  return $toPrecision.call(1, undefined) !== '1';\n}) || !$fails(function () {\n  // V8 ~ Android 4.3-\n  $toPrecision.call({});\n})), 'Number', {\n  toPrecision: function toPrecision(precision) {\n    var that = aNumberValue(this, 'Number#toPrecision: incorrect invocation!');\n    return precision === undefined ? $toPrecision.call(that) : $toPrecision.call(that, precision);\n  }\n});\n","// 19.1.3.1 Object.assign(target, source)\nvar $export = require('./_export');\n\n$export($export.S + $export.F, 'Object', { assign: require('./_object-assign') });\n","var $export = require('./_export');\n// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\n$export($export.S, 'Object', { create: require('./_object-create') });\n","var $export = require('./_export');\n// 19.1.2.3 / 15.2.3.7 Object.defineProperties(O, Properties)\n$export($export.S + $export.F * !require('./_descriptors'), 'Object', { defineProperties: require('./_object-dps') });\n","var $export = require('./_export');\n// 19.1.2.4 / 15.2.3.6 Object.defineProperty(O, P, Attributes)\n$export($export.S + $export.F * !require('./_descriptors'), 'Object', { defineProperty: require('./_object-dp').f });\n","// 19.1.2.5 Object.freeze(O)\nvar isObject = require('./_is-object');\nvar meta = require('./_meta').onFreeze;\n\nrequire('./_object-sap')('freeze', function ($freeze) {\n  return function freeze(it) {\n    return $freeze && isObject(it) ? $freeze(meta(it)) : it;\n  };\n});\n","// 19.1.2.6 Object.getOwnPropertyDescriptor(O, P)\nvar toIObject = require('./_to-iobject');\nvar $getOwnPropertyDescriptor = require('./_object-gopd').f;\n\nrequire('./_object-sap')('getOwnPropertyDescriptor', function () {\n  return function getOwnPropertyDescriptor(it, key) {\n    return $getOwnPropertyDescriptor(toIObject(it), key);\n  };\n});\n","// 19.1.2.7 Object.getOwnPropertyNames(O)\nrequire('./_object-sap')('getOwnPropertyNames', function () {\n  return require('./_object-gopn-ext').f;\n});\n","// 19.1.2.9 Object.getPrototypeOf(O)\nvar toObject = require('./_to-object');\nvar $getPrototypeOf = require('./_object-gpo');\n\nrequire('./_object-sap')('getPrototypeOf', function () {\n  return function getPrototypeOf(it) {\n    return $getPrototypeOf(toObject(it));\n  };\n});\n","// 19.1.2.11 Object.isExtensible(O)\nvar isObject = require('./_is-object');\n\nrequire('./_object-sap')('isExtensible', function ($isExtensible) {\n  return function isExtensible(it) {\n    return isObject(it) ? $isExtensible ? $isExtensible(it) : true : false;\n  };\n});\n","// 19.1.2.12 Object.isFrozen(O)\nvar isObject = require('./_is-object');\n\nrequire('./_object-sap')('isFrozen', function ($isFrozen) {\n  return function isFrozen(it) {\n    return isObject(it) ? $isFrozen ? $isFrozen(it) : false : true;\n  };\n});\n","// 19.1.2.13 Object.isSealed(O)\nvar isObject = require('./_is-object');\n\nrequire('./_object-sap')('isSealed', function ($isSealed) {\n  return function isSealed(it) {\n    return isObject(it) ? $isSealed ? $isSealed(it) : false : true;\n  };\n});\n","// 19.1.3.10 Object.is(value1, value2)\nvar $export = require('./_export');\n$export($export.S, 'Object', { is: require('./_same-value') });\n","// 19.1.2.14 Object.keys(O)\nvar toObject = require('./_to-object');\nvar $keys = require('./_object-keys');\n\nrequire('./_object-sap')('keys', function () {\n  return function keys(it) {\n    return $keys(toObject(it));\n  };\n});\n","// 19.1.2.15 Object.preventExtensions(O)\nvar isObject = require('./_is-object');\nvar meta = require('./_meta').onFreeze;\n\nrequire('./_object-sap')('preventExtensions', function ($preventExtensions) {\n  return function preventExtensions(it) {\n    return $preventExtensions && isObject(it) ? $preventExtensions(meta(it)) : it;\n  };\n});\n","// 19.1.2.17 Object.seal(O)\nvar isObject = require('./_is-object');\nvar meta = require('./_meta').onFreeze;\n\nrequire('./_object-sap')('seal', function ($seal) {\n  return function seal(it) {\n    return $seal && isObject(it) ? $seal(meta(it)) : it;\n  };\n});\n","// 19.1.3.19 Object.setPrototypeOf(O, proto)\nvar $export = require('./_export');\n$export($export.S, 'Object', { setPrototypeOf: require('./_set-proto').set });\n","'use strict';\n// 19.1.3.6 Object.prototype.toString()\nvar classof = require('./_classof');\nvar test = {};\ntest[require('./_wks')('toStringTag')] = 'z';\nif (test + '' != '[object z]') {\n  require('./_redefine')(Object.prototype, 'toString', function toString() {\n    return '[object ' + classof(this) + ']';\n  }, true);\n}\n","var $export = require('./_export');\nvar $parseFloat = require('./_parse-float');\n// 18.2.4 parseFloat(string)\n$export($export.G + $export.F * (parseFloat != $parseFloat), { parseFloat: $parseFloat });\n","var $export = require('./_export');\nvar $parseInt = require('./_parse-int');\n// 18.2.5 parseInt(string, radix)\n$export($export.G + $export.F * (parseInt != $parseInt), { parseInt: $parseInt });\n","'use strict';\nvar LIBRARY = require('./_library');\nvar global = require('./_global');\nvar ctx = require('./_ctx');\nvar classof = require('./_classof');\nvar $export = require('./_export');\nvar isObject = require('./_is-object');\nvar aFunction = require('./_a-function');\nvar anInstance = require('./_an-instance');\nvar forOf = require('./_for-of');\nvar speciesConstructor = require('./_species-constructor');\nvar task = require('./_task').set;\nvar microtask = require('./_microtask')();\nvar newPromiseCapabilityModule = require('./_new-promise-capability');\nvar perform = require('./_perform');\nvar userAgent = require('./_user-agent');\nvar promiseResolve = require('./_promise-resolve');\nvar PROMISE = 'Promise';\nvar TypeError = global.TypeError;\nvar process = global.process;\nvar versions = process && process.versions;\nvar v8 = versions && versions.v8 || '';\nvar $Promise = global[PROMISE];\nvar isNode = classof(process) == 'process';\nvar empty = function () { /* empty */ };\nvar Internal, newGenericPromiseCapability, OwnPromiseCapability, Wrapper;\nvar newPromiseCapability = newGenericPromiseCapability = newPromiseCapabilityModule.f;\n\nvar USE_NATIVE = !!function () {\n  try {\n    // correct subclassing with @@species support\n    var promise = $Promise.resolve(1);\n    var FakePromise = (promise.constructor = {})[require('./_wks')('species')] = function (exec) {\n      exec(empty, empty);\n    };\n    // unhandled rejections tracking support, NodeJS Promise without it fails @@species test\n    return (isNode || typeof PromiseRejectionEvent == 'function')\n      && promise.then(empty) instanceof FakePromise\n      // v8 6.6 (Node 10 and Chrome 66) have a bug with resolving custom thenables\n      // https://bugs.chromium.org/p/chromium/issues/detail?id=830565\n      // we can't detect it synchronously, so just check versions\n      && v8.indexOf('6.6') !== 0\n      && userAgent.indexOf('Chrome/66') === -1;\n  } catch (e) { /* empty */ }\n}();\n\n// helpers\nvar isThenable = function (it) {\n  var then;\n  return isObject(it) && typeof (then = it.then) == 'function' ? then : false;\n};\nvar notify = function (promise, isReject) {\n  if (promise._n) return;\n  promise._n = true;\n  var chain = promise._c;\n  microtask(function () {\n    var value = promise._v;\n    var ok = promise._s == 1;\n    var i = 0;\n    var run = function (reaction) {\n      var handler = ok ? reaction.ok : reaction.fail;\n      var resolve = reaction.resolve;\n      var reject = reaction.reject;\n      var domain = reaction.domain;\n      var result, then, exited;\n      try {\n        if (handler) {\n          if (!ok) {\n            if (promise._h == 2) onHandleUnhandled(promise);\n            promise._h = 1;\n          }\n          if (handler === true) result = value;\n          else {\n            if (domain) domain.enter();\n            result = handler(value); // may throw\n            if (domain) {\n              domain.exit();\n              exited = true;\n            }\n          }\n          if (result === reaction.promise) {\n            reject(TypeError('Promise-chain cycle'));\n          } else if (then = isThenable(result)) {\n            then.call(result, resolve, reject);\n          } else resolve(result);\n        } else reject(value);\n      } catch (e) {\n        if (domain && !exited) domain.exit();\n        reject(e);\n      }\n    };\n    while (chain.length > i) run(chain[i++]); // variable length - can't use forEach\n    promise._c = [];\n    promise._n = false;\n    if (isReject && !promise._h) onUnhandled(promise);\n  });\n};\nvar onUnhandled = function (promise) {\n  task.call(global, function () {\n    var value = promise._v;\n    var unhandled = isUnhandled(promise);\n    var result, handler, console;\n    if (unhandled) {\n      result = perform(function () {\n        if (isNode) {\n          process.emit('unhandledRejection', value, promise);\n        } else if (handler = global.onunhandledrejection) {\n          handler({ promise: promise, reason: value });\n        } else if ((console = global.console) && console.error) {\n          console.error('Unhandled promise rejection', value);\n        }\n      });\n      // Browsers should not trigger `rejectionHandled` event if it was handled here, NodeJS - should\n      promise._h = isNode || isUnhandled(promise) ? 2 : 1;\n    } promise._a = undefined;\n    if (unhandled && result.e) throw result.v;\n  });\n};\nvar isUnhandled = function (promise) {\n  return promise._h !== 1 && (promise._a || promise._c).length === 0;\n};\nvar onHandleUnhandled = function (promise) {\n  task.call(global, function () {\n    var handler;\n    if (isNode) {\n      process.emit('rejectionHandled', promise);\n    } else if (handler = global.onrejectionhandled) {\n      handler({ promise: promise, reason: promise._v });\n    }\n  });\n};\nvar $reject = function (value) {\n  var promise = this;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  promise._v = value;\n  promise._s = 2;\n  if (!promise._a) promise._a = promise._c.slice();\n  notify(promise, true);\n};\nvar $resolve = function (value) {\n  var promise = this;\n  var then;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  try {\n    if (promise === value) throw TypeError(\"Promise can't be resolved itself\");\n    if (then = isThenable(value)) {\n      microtask(function () {\n        var wrapper = { _w: promise, _d: false }; // wrap\n        try {\n          then.call(value, ctx($resolve, wrapper, 1), ctx($reject, wrapper, 1));\n        } catch (e) {\n          $reject.call(wrapper, e);\n        }\n      });\n    } else {\n      promise._v = value;\n      promise._s = 1;\n      notify(promise, false);\n    }\n  } catch (e) {\n    $reject.call({ _w: promise, _d: false }, e); // wrap\n  }\n};\n\n// constructor polyfill\nif (!USE_NATIVE) {\n  // 25.4.3.1 Promise(executor)\n  $Promise = function Promise(executor) {\n    anInstance(this, $Promise, PROMISE, '_h');\n    aFunction(executor);\n    Internal.call(this);\n    try {\n      executor(ctx($resolve, this, 1), ctx($reject, this, 1));\n    } catch (err) {\n      $reject.call(this, err);\n    }\n  };\n  // eslint-disable-next-line no-unused-vars\n  Internal = function Promise(executor) {\n    this._c = [];             // <- awaiting reactions\n    this._a = undefined;      // <- checked in isUnhandled reactions\n    this._s = 0;              // <- state\n    this._d = false;          // <- done\n    this._v = undefined;      // <- value\n    this._h = 0;              // <- rejection state, 0 - default, 1 - handled, 2 - unhandled\n    this._n = false;          // <- notify\n  };\n  Internal.prototype = require('./_redefine-all')($Promise.prototype, {\n    // 25.4.5.3 Promise.prototype.then(onFulfilled, onRejected)\n    then: function then(onFulfilled, onRejected) {\n      var reaction = newPromiseCapability(speciesConstructor(this, $Promise));\n      reaction.ok = typeof onFulfilled == 'function' ? onFulfilled : true;\n      reaction.fail = typeof onRejected == 'function' && onRejected;\n      reaction.domain = isNode ? process.domain : undefined;\n      this._c.push(reaction);\n      if (this._a) this._a.push(reaction);\n      if (this._s) notify(this, false);\n      return reaction.promise;\n    },\n    // 25.4.5.1 Promise.prototype.catch(onRejected)\n    'catch': function (onRejected) {\n      return this.then(undefined, onRejected);\n    }\n  });\n  OwnPromiseCapability = function () {\n    var promise = new Internal();\n    this.promise = promise;\n    this.resolve = ctx($resolve, promise, 1);\n    this.reject = ctx($reject, promise, 1);\n  };\n  newPromiseCapabilityModule.f = newPromiseCapability = function (C) {\n    return C === $Promise || C === Wrapper\n      ? new OwnPromiseCapability(C)\n      : newGenericPromiseCapability(C);\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Promise: $Promise });\nrequire('./_set-to-string-tag')($Promise, PROMISE);\nrequire('./_set-species')(PROMISE);\nWrapper = require('./_core')[PROMISE];\n\n// statics\n$export($export.S + $export.F * !USE_NATIVE, PROMISE, {\n  // 25.4.4.5 Promise.reject(r)\n  reject: function reject(r) {\n    var capability = newPromiseCapability(this);\n    var $$reject = capability.reject;\n    $$reject(r);\n    return capability.promise;\n  }\n});\n$export($export.S + $export.F * (LIBRARY || !USE_NATIVE), PROMISE, {\n  // 25.4.4.6 Promise.resolve(x)\n  resolve: function resolve(x) {\n    return promiseResolve(LIBRARY && this === Wrapper ? $Promise : this, x);\n  }\n});\n$export($export.S + $export.F * !(USE_NATIVE && require('./_iter-detect')(function (iter) {\n  $Promise.all(iter)['catch'](empty);\n})), PROMISE, {\n  // 25.4.4.1 Promise.all(iterable)\n  all: function all(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var resolve = capability.resolve;\n    var reject = capability.reject;\n    var result = perform(function () {\n      var values = [];\n      var index = 0;\n      var remaining = 1;\n      forOf(iterable, false, function (promise) {\n        var $index = index++;\n        var alreadyCalled = false;\n        values.push(undefined);\n        remaining++;\n        C.resolve(promise).then(function (value) {\n          if (alreadyCalled) return;\n          alreadyCalled = true;\n          values[$index] = value;\n          --remaining || resolve(values);\n        }, reject);\n      });\n      --remaining || resolve(values);\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  },\n  // 25.4.4.4 Promise.race(iterable)\n  race: function race(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var reject = capability.reject;\n    var result = perform(function () {\n      forOf(iterable, false, function (promise) {\n        C.resolve(promise).then(capability.resolve, reject);\n      });\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  }\n});\n","// 26.1.1 Reflect.apply(target, thisArgument, argumentsList)\nvar $export = require('./_export');\nvar aFunction = require('./_a-function');\nvar anObject = require('./_an-object');\nvar rApply = (require('./_global').Reflect || {}).apply;\nvar fApply = Function.apply;\n// MS Edge argumentsList argument is optional\n$export($export.S + $export.F * !require('./_fails')(function () {\n  rApply(function () { /* empty */ });\n}), 'Reflect', {\n  apply: function apply(target, thisArgument, argumentsList) {\n    var T = aFunction(target);\n    var L = anObject(argumentsList);\n    return rApply ? rApply(T, thisArgument, L) : fApply.call(T, thisArgument, L);\n  }\n});\n","// 26.1.2 Reflect.construct(target, argumentsList [, newTarget])\nvar $export = require('./_export');\nvar create = require('./_object-create');\nvar aFunction = require('./_a-function');\nvar anObject = require('./_an-object');\nvar isObject = require('./_is-object');\nvar fails = require('./_fails');\nvar bind = require('./_bind');\nvar rConstruct = (require('./_global').Reflect || {}).construct;\n\n// MS Edge supports only 2 arguments and argumentsList argument is optional\n// FF Nightly sets third argument as `new.target`, but does not create `this` from it\nvar NEW_TARGET_BUG = fails(function () {\n  function F() { /* empty */ }\n  return !(rConstruct(function () { /* empty */ }, [], F) instanceof F);\n});\nvar ARGS_BUG = !fails(function () {\n  rConstruct(function () { /* empty */ });\n});\n\n$export($export.S + $export.F * (NEW_TARGET_BUG || ARGS_BUG), 'Reflect', {\n  construct: function construct(Target, args /* , newTarget */) {\n    aFunction(Target);\n    anObject(args);\n    var newTarget = arguments.length < 3 ? Target : aFunction(arguments[2]);\n    if (ARGS_BUG && !NEW_TARGET_BUG) return rConstruct(Target, args, newTarget);\n    if (Target == newTarget) {\n      // w/o altered newTarget, optimization for 0-4 arguments\n      switch (args.length) {\n        case 0: return new Target();\n        case 1: return new Target(args[0]);\n        case 2: return new Target(args[0], args[1]);\n        case 3: return new Target(args[0], args[1], args[2]);\n        case 4: return new Target(args[0], args[1], args[2], args[3]);\n      }\n      // w/o altered newTarget, lot of arguments case\n      var $args = [null];\n      $args.push.apply($args, args);\n      return new (bind.apply(Target, $args))();\n    }\n    // with altered newTarget, not support built-in constructors\n    var proto = newTarget.prototype;\n    var instance = create(isObject(proto) ? proto : Object.prototype);\n    var result = Function.apply.call(Target, instance, args);\n    return isObject(result) ? result : instance;\n  }\n});\n","// 26.1.3 Reflect.defineProperty(target, propertyKey, attributes)\nvar dP = require('./_object-dp');\nvar $export = require('./_export');\nvar anObject = require('./_an-object');\nvar toPrimitive = require('./_to-primitive');\n\n// MS Edge has broken Reflect.defineProperty - throwing instead of returning false\n$export($export.S + $export.F * require('./_fails')(function () {\n  // eslint-disable-next-line no-undef\n  Reflect.defineProperty(dP.f({}, 1, { value: 1 }), 1, { value: 2 });\n}), 'Reflect', {\n  defineProperty: function defineProperty(target, propertyKey, attributes) {\n    anObject(target);\n    propertyKey = toPrimitive(propertyKey, true);\n    anObject(attributes);\n    try {\n      dP.f(target, propertyKey, attributes);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n","// 26.1.4 Reflect.deleteProperty(target, propertyKey)\nvar $export = require('./_export');\nvar gOPD = require('./_object-gopd').f;\nvar anObject = require('./_an-object');\n\n$export($export.S, 'Reflect', {\n  deleteProperty: function deleteProperty(target, propertyKey) {\n    var desc = gOPD(anObject(target), propertyKey);\n    return desc && !desc.configurable ? false : delete target[propertyKey];\n  }\n});\n","'use strict';\n// 26.1.5 Reflect.enumerate(target)\nvar $export = require('./_export');\nvar anObject = require('./_an-object');\nvar Enumerate = function (iterated) {\n  this._t = anObject(iterated); // target\n  this._i = 0;                  // next index\n  var keys = this._k = [];      // keys\n  var key;\n  for (key in iterated) keys.push(key);\n};\nrequire('./_iter-create')(Enumerate, 'Object', function () {\n  var that = this;\n  var keys = that._k;\n  var key;\n  do {\n    if (that._i >= keys.length) return { value: undefined, done: true };\n  } while (!((key = keys[that._i++]) in that._t));\n  return { value: key, done: false };\n});\n\n$export($export.S, 'Reflect', {\n  enumerate: function enumerate(target) {\n    return new Enumerate(target);\n  }\n});\n","// 26.1.7 Reflect.getOwnPropertyDescriptor(target, propertyKey)\nvar gOPD = require('./_object-gopd');\nvar $export = require('./_export');\nvar anObject = require('./_an-object');\n\n$export($export.S, 'Reflect', {\n  getOwnPropertyDescriptor: function getOwnPropertyDescriptor(target, propertyKey) {\n    return gOPD.f(anObject(target), propertyKey);\n  }\n});\n","// 26.1.8 Reflect.getPrototypeOf(target)\nvar $export = require('./_export');\nvar getProto = require('./_object-gpo');\nvar anObject = require('./_an-object');\n\n$export($export.S, 'Reflect', {\n  getPrototypeOf: function getPrototypeOf(target) {\n    return getProto(anObject(target));\n  }\n});\n","// 26.1.6 Reflect.get(target, propertyKey [, receiver])\nvar gOPD = require('./_object-gopd');\nvar getPrototypeOf = require('./_object-gpo');\nvar has = require('./_has');\nvar $export = require('./_export');\nvar isObject = require('./_is-object');\nvar anObject = require('./_an-object');\n\nfunction get(target, propertyKey /* , receiver */) {\n  var receiver = arguments.length < 3 ? target : arguments[2];\n  var desc, proto;\n  if (anObject(target) === receiver) return target[propertyKey];\n  if (desc = gOPD.f(target, propertyKey)) return has(desc, 'value')\n    ? desc.value\n    : desc.get !== undefined\n      ? desc.get.call(receiver)\n      : undefined;\n  if (isObject(proto = getPrototypeOf(target))) return get(proto, propertyKey, receiver);\n}\n\n$export($export.S, 'Reflect', { get: get });\n","// 26.1.9 Reflect.has(target, propertyKey)\nvar $export = require('./_export');\n\n$export($export.S, 'Reflect', {\n  has: function has(target, propertyKey) {\n    return propertyKey in target;\n  }\n});\n","// 26.1.10 Reflect.isExtensible(target)\nvar $export = require('./_export');\nvar anObject = require('./_an-object');\nvar $isExtensible = Object.isExtensible;\n\n$export($export.S, 'Reflect', {\n  isExtensible: function isExtensible(target) {\n    anObject(target);\n    return $isExtensible ? $isExtensible(target) : true;\n  }\n});\n","// 26.1.11 Reflect.ownKeys(target)\nvar $export = require('./_export');\n\n$export($export.S, 'Reflect', { ownKeys: require('./_own-keys') });\n","// 26.1.12 Reflect.preventExtensions(target)\nvar $export = require('./_export');\nvar anObject = require('./_an-object');\nvar $preventExtensions = Object.preventExtensions;\n\n$export($export.S, 'Reflect', {\n  preventExtensions: function preventExtensions(target) {\n    anObject(target);\n    try {\n      if ($preventExtensions) $preventExtensions(target);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n","// 26.1.14 Reflect.setPrototypeOf(target, proto)\nvar $export = require('./_export');\nvar setProto = require('./_set-proto');\n\nif (setProto) $export($export.S, 'Reflect', {\n  setPrototypeOf: function setPrototypeOf(target, proto) {\n    setProto.check(target, proto);\n    try {\n      setProto.set(target, proto);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n","// 26.1.13 Reflect.set(target, propertyKey, V [, receiver])\nvar dP = require('./_object-dp');\nvar gOPD = require('./_object-gopd');\nvar getPrototypeOf = require('./_object-gpo');\nvar has = require('./_has');\nvar $export = require('./_export');\nvar createDesc = require('./_property-desc');\nvar anObject = require('./_an-object');\nvar isObject = require('./_is-object');\n\nfunction set(target, propertyKey, V /* , receiver */) {\n  var receiver = arguments.length < 4 ? target : arguments[3];\n  var ownDesc = gOPD.f(anObject(target), propertyKey);\n  var existingDescriptor, proto;\n  if (!ownDesc) {\n    if (isObject(proto = getPrototypeOf(target))) {\n      return set(proto, propertyKey, V, receiver);\n    }\n    ownDesc = createDesc(0);\n  }\n  if (has(ownDesc, 'value')) {\n    if (ownDesc.writable === false || !isObject(receiver)) return false;\n    if (existingDescriptor = gOPD.f(receiver, propertyKey)) {\n      if (existingDescriptor.get || existingDescriptor.set || existingDescriptor.writable === false) return false;\n      existingDescriptor.value = V;\n      dP.f(receiver, propertyKey, existingDescriptor);\n    } else dP.f(receiver, propertyKey, createDesc(0, V));\n    return true;\n  }\n  return ownDesc.set === undefined ? false : (ownDesc.set.call(receiver, V), true);\n}\n\n$export($export.S, 'Reflect', { set: set });\n","var global = require('./_global');\nvar inheritIfRequired = require('./_inherit-if-required');\nvar dP = require('./_object-dp').f;\nvar gOPN = require('./_object-gopn').f;\nvar isRegExp = require('./_is-regexp');\nvar $flags = require('./_flags');\nvar $RegExp = global.RegExp;\nvar Base = $RegExp;\nvar proto = $RegExp.prototype;\nvar re1 = /a/g;\nvar re2 = /a/g;\n// \"new\" creates a new object, old webkit buggy here\nvar CORRECT_NEW = new $RegExp(re1) !== re1;\n\nif (require('./_descriptors') && (!CORRECT_NEW || require('./_fails')(function () {\n  re2[require('./_wks')('match')] = false;\n  // RegExp constructor can alter flags and IsRegExp works correct with @@match\n  return $RegExp(re1) != re1 || $RegExp(re2) == re2 || $RegExp(re1, 'i') != '/a/i';\n}))) {\n  $RegExp = function RegExp(p, f) {\n    var tiRE = this instanceof $RegExp;\n    var piRE = isRegExp(p);\n    var fiU = f === undefined;\n    return !tiRE && piRE && p.constructor === $RegExp && fiU ? p\n      : inheritIfRequired(CORRECT_NEW\n        ? new Base(piRE && !fiU ? p.source : p, f)\n        : Base((piRE = p instanceof $RegExp) ? p.source : p, piRE && fiU ? $flags.call(p) : f)\n      , tiRE ? this : proto, $RegExp);\n  };\n  var proxy = function (key) {\n    key in $RegExp || dP($RegExp, key, {\n      configurable: true,\n      get: function () { return Base[key]; },\n      set: function (it) { Base[key] = it; }\n    });\n  };\n  for (var keys = gOPN(Base), i = 0; keys.length > i;) proxy(keys[i++]);\n  proto.constructor = $RegExp;\n  $RegExp.prototype = proto;\n  require('./_redefine')(global, 'RegExp', $RegExp);\n}\n\nrequire('./_set-species')('RegExp');\n","'use strict';\nvar regexpExec = require('./_regexp-exec');\nrequire('./_export')({\n  target: 'RegExp',\n  proto: true,\n  forced: regexpExec !== /./.exec\n}, {\n  exec: regexpExec\n});\n","// 21.2.5.3 get RegExp.prototype.flags()\nif (require('./_descriptors') && /./g.flags != 'g') require('./_object-dp').f(RegExp.prototype, 'flags', {\n  configurable: true,\n  get: require('./_flags')\n});\n","'use strict';\n\nvar anObject = require('./_an-object');\nvar toLength = require('./_to-length');\nvar advanceStringIndex = require('./_advance-string-index');\nvar regExpExec = require('./_regexp-exec-abstract');\n\n// @@match logic\nrequire('./_fix-re-wks')('match', 1, function (defined, MATCH, $match, maybeCallNative) {\n  return [\n    // `String.prototype.match` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.match\n    function match(regexp) {\n      var O = defined(this);\n      var fn = regexp == undefined ? undefined : regexp[MATCH];\n      return fn !== undefined ? fn.call(regexp, O) : new RegExp(regexp)[MATCH](String(O));\n    },\n    // `RegExp.prototype[@@match]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@match\n    function (regexp) {\n      var res = maybeCallNative($match, regexp, this);\n      if (res.done) return res.value;\n      var rx = anObject(regexp);\n      var S = String(this);\n      if (!rx.global) return regExpExec(rx, S);\n      var fullUnicode = rx.unicode;\n      rx.lastIndex = 0;\n      var A = [];\n      var n = 0;\n      var result;\n      while ((result = regExpExec(rx, S)) !== null) {\n        var matchStr = String(result[0]);\n        A[n] = matchStr;\n        if (matchStr === '') rx.lastIndex = advanceStringIndex(S, toLength(rx.lastIndex), fullUnicode);\n        n++;\n      }\n      return n === 0 ? null : A;\n    }\n  ];\n});\n","'use strict';\n\nvar anObject = require('./_an-object');\nvar toObject = require('./_to-object');\nvar toLength = require('./_to-length');\nvar toInteger = require('./_to-integer');\nvar advanceStringIndex = require('./_advance-string-index');\nvar regExpExec = require('./_regexp-exec-abstract');\nvar max = Math.max;\nvar min = Math.min;\nvar floor = Math.floor;\nvar SUBSTITUTION_SYMBOLS = /\\$([$&`']|\\d\\d?|<[^>]*>)/g;\nvar SUBSTITUTION_SYMBOLS_NO_NAMED = /\\$([$&`']|\\d\\d?)/g;\n\nvar maybeToString = function (it) {\n  return it === undefined ? it : String(it);\n};\n\n// @@replace logic\nrequire('./_fix-re-wks')('replace', 2, function (defined, REPLACE, $replace, maybeCallNative) {\n  return [\n    // `String.prototype.replace` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.replace\n    function replace(searchValue, replaceValue) {\n      var O = defined(this);\n      var fn = searchValue == undefined ? undefined : searchValue[REPLACE];\n      return fn !== undefined\n        ? fn.call(searchValue, O, replaceValue)\n        : $replace.call(String(O), searchValue, replaceValue);\n    },\n    // `RegExp.prototype[@@replace]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@replace\n    function (regexp, replaceValue) {\n      var res = maybeCallNative($replace, regexp, this, replaceValue);\n      if (res.done) return res.value;\n\n      var rx = anObject(regexp);\n      var S = String(this);\n      var functionalReplace = typeof replaceValue === 'function';\n      if (!functionalReplace) replaceValue = String(replaceValue);\n      var global = rx.global;\n      if (global) {\n        var fullUnicode = rx.unicode;\n        rx.lastIndex = 0;\n      }\n      var results = [];\n      while (true) {\n        var result = regExpExec(rx, S);\n        if (result === null) break;\n        results.push(result);\n        if (!global) break;\n        var matchStr = String(result[0]);\n        if (matchStr === '') rx.lastIndex = advanceStringIndex(S, toLength(rx.lastIndex), fullUnicode);\n      }\n      var accumulatedResult = '';\n      var nextSourcePosition = 0;\n      for (var i = 0; i < results.length; i++) {\n        result = results[i];\n        var matched = String(result[0]);\n        var position = max(min(toInteger(result.index), S.length), 0);\n        var captures = [];\n        // NOTE: This is equivalent to\n        //   captures = result.slice(1).map(maybeToString)\n        // but for some reason `nativeSlice.call(result, 1, result.length)` (called in\n        // the slice polyfill when slicing native arrays) \"doesn't work\" in safari 9 and\n        // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it.\n        for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j]));\n        var namedCaptures = result.groups;\n        if (functionalReplace) {\n          var replacerArgs = [matched].concat(captures, position, S);\n          if (namedCaptures !== undefined) replacerArgs.push(namedCaptures);\n          var replacement = String(replaceValue.apply(undefined, replacerArgs));\n        } else {\n          replacement = getSubstitution(matched, S, position, captures, namedCaptures, replaceValue);\n        }\n        if (position >= nextSourcePosition) {\n          accumulatedResult += S.slice(nextSourcePosition, position) + replacement;\n          nextSourcePosition = position + matched.length;\n        }\n      }\n      return accumulatedResult + S.slice(nextSourcePosition);\n    }\n  ];\n\n    // https://tc39.github.io/ecma262/#sec-getsubstitution\n  function getSubstitution(matched, str, position, captures, namedCaptures, replacement) {\n    var tailPos = position + matched.length;\n    var m = captures.length;\n    var symbols = SUBSTITUTION_SYMBOLS_NO_NAMED;\n    if (namedCaptures !== undefined) {\n      namedCaptures = toObject(namedCaptures);\n      symbols = SUBSTITUTION_SYMBOLS;\n    }\n    return $replace.call(replacement, symbols, function (match, ch) {\n      var capture;\n      switch (ch.charAt(0)) {\n        case '$': return '$';\n        case '&': return matched;\n        case '`': return str.slice(0, position);\n        case \"'\": return str.slice(tailPos);\n        case '<':\n          capture = namedCaptures[ch.slice(1, -1)];\n          break;\n        default: // \\d\\d?\n          var n = +ch;\n          if (n === 0) return match;\n          if (n > m) {\n            var f = floor(n / 10);\n            if (f === 0) return match;\n            if (f <= m) return captures[f - 1] === undefined ? ch.charAt(1) : captures[f - 1] + ch.charAt(1);\n            return match;\n          }\n          capture = captures[n - 1];\n      }\n      return capture === undefined ? '' : capture;\n    });\n  }\n});\n","'use strict';\n\nvar anObject = require('./_an-object');\nvar sameValue = require('./_same-value');\nvar regExpExec = require('./_regexp-exec-abstract');\n\n// @@search logic\nrequire('./_fix-re-wks')('search', 1, function (defined, SEARCH, $search, maybeCallNative) {\n  return [\n    // `String.prototype.search` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.search\n    function search(regexp) {\n      var O = defined(this);\n      var fn = regexp == undefined ? undefined : regexp[SEARCH];\n      return fn !== undefined ? fn.call(regexp, O) : new RegExp(regexp)[SEARCH](String(O));\n    },\n    // `RegExp.prototype[@@search]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@search\n    function (regexp) {\n      var res = maybeCallNative($search, regexp, this);\n      if (res.done) return res.value;\n      var rx = anObject(regexp);\n      var S = String(this);\n      var previousLastIndex = rx.lastIndex;\n      if (!sameValue(previousLastIndex, 0)) rx.lastIndex = 0;\n      var result = regExpExec(rx, S);\n      if (!sameValue(rx.lastIndex, previousLastIndex)) rx.lastIndex = previousLastIndex;\n      return result === null ? -1 : result.index;\n    }\n  ];\n});\n","'use strict';\n\nvar isRegExp = require('./_is-regexp');\nvar anObject = require('./_an-object');\nvar speciesConstructor = require('./_species-constructor');\nvar advanceStringIndex = require('./_advance-string-index');\nvar toLength = require('./_to-length');\nvar callRegExpExec = require('./_regexp-exec-abstract');\nvar regexpExec = require('./_regexp-exec');\nvar fails = require('./_fails');\nvar $min = Math.min;\nvar $push = [].push;\nvar $SPLIT = 'split';\nvar LENGTH = 'length';\nvar LAST_INDEX = 'lastIndex';\nvar MAX_UINT32 = 0xffffffff;\n\n// babel-minify transpiles RegExp('x', 'y') -> /x/y and it causes SyntaxError\nvar SUPPORTS_Y = !fails(function () { RegExp(MAX_UINT32, 'y'); });\n\n// @@split logic\nrequire('./_fix-re-wks')('split', 2, function (defined, SPLIT, $split, maybeCallNative) {\n  var internalSplit;\n  if (\n    'abbc'[$SPLIT](/(b)*/)[1] == 'c' ||\n    'test'[$SPLIT](/(?:)/, -1)[LENGTH] != 4 ||\n    'ab'[$SPLIT](/(?:ab)*/)[LENGTH] != 2 ||\n    '.'[$SPLIT](/(.?)(.?)/)[LENGTH] != 4 ||\n    '.'[$SPLIT](/()()/)[LENGTH] > 1 ||\n    ''[$SPLIT](/.?/)[LENGTH]\n  ) {\n    // based on es5-shim implementation, need to rework it\n    internalSplit = function (separator, limit) {\n      var string = String(this);\n      if (separator === undefined && limit === 0) return [];\n      // If `separator` is not a regex, use native split\n      if (!isRegExp(separator)) return $split.call(string, separator, limit);\n      var output = [];\n      var flags = (separator.ignoreCase ? 'i' : '') +\n                  (separator.multiline ? 'm' : '') +\n                  (separator.unicode ? 'u' : '') +\n                  (separator.sticky ? 'y' : '');\n      var lastLastIndex = 0;\n      var splitLimit = limit === undefined ? MAX_UINT32 : limit >>> 0;\n      // Make `global` and avoid `lastIndex` issues by working with a copy\n      var separatorCopy = new RegExp(separator.source, flags + 'g');\n      var match, lastIndex, lastLength;\n      while (match = regexpExec.call(separatorCopy, string)) {\n        lastIndex = separatorCopy[LAST_INDEX];\n        if (lastIndex > lastLastIndex) {\n          output.push(string.slice(lastLastIndex, match.index));\n          if (match[LENGTH] > 1 && match.index < string[LENGTH]) $push.apply(output, match.slice(1));\n          lastLength = match[0][LENGTH];\n          lastLastIndex = lastIndex;\n          if (output[LENGTH] >= splitLimit) break;\n        }\n        if (separatorCopy[LAST_INDEX] === match.index) separatorCopy[LAST_INDEX]++; // Avoid an infinite loop\n      }\n      if (lastLastIndex === string[LENGTH]) {\n        if (lastLength || !separatorCopy.test('')) output.push('');\n      } else output.push(string.slice(lastLastIndex));\n      return output[LENGTH] > splitLimit ? output.slice(0, splitLimit) : output;\n    };\n  // Chakra, V8\n  } else if ('0'[$SPLIT](undefined, 0)[LENGTH]) {\n    internalSplit = function (separator, limit) {\n      return separator === undefined && limit === 0 ? [] : $split.call(this, separator, limit);\n    };\n  } else {\n    internalSplit = $split;\n  }\n\n  return [\n    // `String.prototype.split` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.split\n    function split(separator, limit) {\n      var O = defined(this);\n      var splitter = separator == undefined ? undefined : separator[SPLIT];\n      return splitter !== undefined\n        ? splitter.call(separator, O, limit)\n        : internalSplit.call(String(O), separator, limit);\n    },\n    // `RegExp.prototype[@@split]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@split\n    //\n    // NOTE: This cannot be properly polyfilled in engines that don't support\n    // the 'y' flag.\n    function (regexp, limit) {\n      var res = maybeCallNative(internalSplit, regexp, this, limit, internalSplit !== $split);\n      if (res.done) return res.value;\n\n      var rx = anObject(regexp);\n      var S = String(this);\n      var C = speciesConstructor(rx, RegExp);\n\n      var unicodeMatching = rx.unicode;\n      var flags = (rx.ignoreCase ? 'i' : '') +\n                  (rx.multiline ? 'm' : '') +\n                  (rx.unicode ? 'u' : '') +\n                  (SUPPORTS_Y ? 'y' : 'g');\n\n      // ^(? + rx + ) is needed, in combination with some S slicing, to\n      // simulate the 'y' flag.\n      var splitter = new C(SUPPORTS_Y ? rx : '^(?:' + rx.source + ')', flags);\n      var lim = limit === undefined ? MAX_UINT32 : limit >>> 0;\n      if (lim === 0) return [];\n      if (S.length === 0) return callRegExpExec(splitter, S) === null ? [S] : [];\n      var p = 0;\n      var q = 0;\n      var A = [];\n      while (q < S.length) {\n        splitter.lastIndex = SUPPORTS_Y ? q : 0;\n        var z = callRegExpExec(splitter, SUPPORTS_Y ? S : S.slice(q));\n        var e;\n        if (\n          z === null ||\n          (e = $min(toLength(splitter.lastIndex + (SUPPORTS_Y ? 0 : q)), S.length)) === p\n        ) {\n          q = advanceStringIndex(S, q, unicodeMatching);\n        } else {\n          A.push(S.slice(p, q));\n          if (A.length === lim) return A;\n          for (var i = 1; i <= z.length - 1; i++) {\n            A.push(z[i]);\n            if (A.length === lim) return A;\n          }\n          q = p = e;\n        }\n      }\n      A.push(S.slice(p));\n      return A;\n    }\n  ];\n});\n","'use strict';\nrequire('./es6.regexp.flags');\nvar anObject = require('./_an-object');\nvar $flags = require('./_flags');\nvar DESCRIPTORS = require('./_descriptors');\nvar TO_STRING = 'toString';\nvar $toString = /./[TO_STRING];\n\nvar define = function (fn) {\n  require('./_redefine')(RegExp.prototype, TO_STRING, fn, true);\n};\n\n// 21.2.5.14 RegExp.prototype.toString()\nif (require('./_fails')(function () { return $toString.call({ source: 'a', flags: 'b' }) != '/a/b'; })) {\n  define(function toString() {\n    var R = anObject(this);\n    return '/'.concat(R.source, '/',\n      'flags' in R ? R.flags : !DESCRIPTORS && R instanceof RegExp ? $flags.call(R) : undefined);\n  });\n// FF44- RegExp#toString has a wrong name\n} else if ($toString.name != TO_STRING) {\n  define(function toString() {\n    return $toString.call(this);\n  });\n}\n","'use strict';\nvar strong = require('./_collection-strong');\nvar validate = require('./_validate-collection');\nvar SET = 'Set';\n\n// 23.2 Set Objects\nmodule.exports = require('./_collection')(SET, function (get) {\n  return function Set() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.2.3.1 Set.prototype.add(value)\n  add: function add(value) {\n    return strong.def(validate(this, SET), value = value === 0 ? 0 : value, value);\n  }\n}, strong);\n","'use strict';\n// B.2.3.2 String.prototype.anchor(name)\nrequire('./_string-html')('anchor', function (createHTML) {\n  return function anchor(name) {\n    return createHTML(this, 'a', 'name', name);\n  };\n});\n","'use strict';\n// B.2.3.3 String.prototype.big()\nrequire('./_string-html')('big', function (createHTML) {\n  return function big() {\n    return createHTML(this, 'big', '', '');\n  };\n});\n","'use strict';\n// B.2.3.4 String.prototype.blink()\nrequire('./_string-html')('blink', function (createHTML) {\n  return function blink() {\n    return createHTML(this, 'blink', '', '');\n  };\n});\n","'use strict';\n// B.2.3.5 String.prototype.bold()\nrequire('./_string-html')('bold', function (createHTML) {\n  return function bold() {\n    return createHTML(this, 'b', '', '');\n  };\n});\n","'use strict';\nvar $export = require('./_export');\nvar $at = require('./_string-at')(false);\n$export($export.P, 'String', {\n  // 21.1.3.3 String.prototype.codePointAt(pos)\n  codePointAt: function codePointAt(pos) {\n    return $at(this, pos);\n  }\n});\n","// 21.1.3.6 String.prototype.endsWith(searchString [, endPosition])\n'use strict';\nvar $export = require('./_export');\nvar toLength = require('./_to-length');\nvar context = require('./_string-context');\nvar ENDS_WITH = 'endsWith';\nvar $endsWith = ''[ENDS_WITH];\n\n$export($export.P + $export.F * require('./_fails-is-regexp')(ENDS_WITH), 'String', {\n  endsWith: function endsWith(searchString /* , endPosition = @length */) {\n    var that = context(this, searchString, ENDS_WITH);\n    var endPosition = arguments.length > 1 ? arguments[1] : undefined;\n    var len = toLength(that.length);\n    var end = endPosition === undefined ? len : Math.min(toLength(endPosition), len);\n    var search = String(searchString);\n    return $endsWith\n      ? $endsWith.call(that, search, end)\n      : that.slice(end - search.length, end) === search;\n  }\n});\n","'use strict';\n// B.2.3.6 String.prototype.fixed()\nrequire('./_string-html')('fixed', function (createHTML) {\n  return function fixed() {\n    return createHTML(this, 'tt', '', '');\n  };\n});\n","'use strict';\n// B.2.3.7 String.prototype.fontcolor(color)\nrequire('./_string-html')('fontcolor', function (createHTML) {\n  return function fontcolor(color) {\n    return createHTML(this, 'font', 'color', color);\n  };\n});\n","'use strict';\n// B.2.3.8 String.prototype.fontsize(size)\nrequire('./_string-html')('fontsize', function (createHTML) {\n  return function fontsize(size) {\n    return createHTML(this, 'font', 'size', size);\n  };\n});\n","var $export = require('./_export');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nvar fromCharCode = String.fromCharCode;\nvar $fromCodePoint = String.fromCodePoint;\n\n// length should be 1, old FF problem\n$export($export.S + $export.F * (!!$fromCodePoint && $fromCodePoint.length != 1), 'String', {\n  // 21.1.2.2 String.fromCodePoint(...codePoints)\n  fromCodePoint: function fromCodePoint(x) { // eslint-disable-line no-unused-vars\n    var res = [];\n    var aLen = arguments.length;\n    var i = 0;\n    var code;\n    while (aLen > i) {\n      code = +arguments[i++];\n      if (toAbsoluteIndex(code, 0x10ffff) !== code) throw RangeError(code + ' is not a valid code point');\n      res.push(code < 0x10000\n        ? fromCharCode(code)\n        : fromCharCode(((code -= 0x10000) >> 10) + 0xd800, code % 0x400 + 0xdc00)\n      );\n    } return res.join('');\n  }\n});\n","// 21.1.3.7 String.prototype.includes(searchString, position = 0)\n'use strict';\nvar $export = require('./_export');\nvar context = require('./_string-context');\nvar INCLUDES = 'includes';\n\n$export($export.P + $export.F * require('./_fails-is-regexp')(INCLUDES), 'String', {\n  includes: function includes(searchString /* , position = 0 */) {\n    return !!~context(this, searchString, INCLUDES)\n      .indexOf(searchString, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n","'use strict';\n// B.2.3.9 String.prototype.italics()\nrequire('./_string-html')('italics', function (createHTML) {\n  return function italics() {\n    return createHTML(this, 'i', '', '');\n  };\n});\n","'use strict';\nvar $at = require('./_string-at')(true);\n\n// 21.1.3.27 String.prototype[@@iterator]()\nrequire('./_iter-define')(String, 'String', function (iterated) {\n  this._t = String(iterated); // target\n  this._i = 0;                // next index\n// 21.1.5.2.1 %StringIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var index = this._i;\n  var point;\n  if (index >= O.length) return { value: undefined, done: true };\n  point = $at(O, index);\n  this._i += point.length;\n  return { value: point, done: false };\n});\n","'use strict';\n// B.2.3.10 String.prototype.link(url)\nrequire('./_string-html')('link', function (createHTML) {\n  return function link(url) {\n    return createHTML(this, 'a', 'href', url);\n  };\n});\n","var $export = require('./_export');\nvar toIObject = require('./_to-iobject');\nvar toLength = require('./_to-length');\n\n$export($export.S, 'String', {\n  // 21.1.2.4 String.raw(callSite, ...substitutions)\n  raw: function raw(callSite) {\n    var tpl = toIObject(callSite.raw);\n    var len = toLength(tpl.length);\n    var aLen = arguments.length;\n    var res = [];\n    var i = 0;\n    while (len > i) {\n      res.push(String(tpl[i++]));\n      if (i < aLen) res.push(String(arguments[i]));\n    } return res.join('');\n  }\n});\n","var $export = require('./_export');\n\n$export($export.P, 'String', {\n  // 21.1.3.13 String.prototype.repeat(count)\n  repeat: require('./_string-repeat')\n});\n","'use strict';\n// B.2.3.11 String.prototype.small()\nrequire('./_string-html')('small', function (createHTML) {\n  return function small() {\n    return createHTML(this, 'small', '', '');\n  };\n});\n","// 21.1.3.18 String.prototype.startsWith(searchString [, position ])\n'use strict';\nvar $export = require('./_export');\nvar toLength = require('./_to-length');\nvar context = require('./_string-context');\nvar STARTS_WITH = 'startsWith';\nvar $startsWith = ''[STARTS_WITH];\n\n$export($export.P + $export.F * require('./_fails-is-regexp')(STARTS_WITH), 'String', {\n  startsWith: function startsWith(searchString /* , position = 0 */) {\n    var that = context(this, searchString, STARTS_WITH);\n    var index = toLength(Math.min(arguments.length > 1 ? arguments[1] : undefined, that.length));\n    var search = String(searchString);\n    return $startsWith\n      ? $startsWith.call(that, search, index)\n      : that.slice(index, index + search.length) === search;\n  }\n});\n","'use strict';\n// B.2.3.12 String.prototype.strike()\nrequire('./_string-html')('strike', function (createHTML) {\n  return function strike() {\n    return createHTML(this, 'strike', '', '');\n  };\n});\n","'use strict';\n// B.2.3.13 String.prototype.sub()\nrequire('./_string-html')('sub', function (createHTML) {\n  return function sub() {\n    return createHTML(this, 'sub', '', '');\n  };\n});\n","'use strict';\n// B.2.3.14 String.prototype.sup()\nrequire('./_string-html')('sup', function (createHTML) {\n  return function sup() {\n    return createHTML(this, 'sup', '', '');\n  };\n});\n","'use strict';\n// 21.1.3.25 String.prototype.trim()\nrequire('./_string-trim')('trim', function ($trim) {\n  return function trim() {\n    return $trim(this, 3);\n  };\n});\n","'use strict';\n// ECMAScript 6 symbols shim\nvar global = require('./_global');\nvar has = require('./_has');\nvar DESCRIPTORS = require('./_descriptors');\nvar $export = require('./_export');\nvar redefine = require('./_redefine');\nvar META = require('./_meta').KEY;\nvar $fails = require('./_fails');\nvar shared = require('./_shared');\nvar setToStringTag = require('./_set-to-string-tag');\nvar uid = require('./_uid');\nvar wks = require('./_wks');\nvar wksExt = require('./_wks-ext');\nvar wksDefine = require('./_wks-define');\nvar enumKeys = require('./_enum-keys');\nvar isArray = require('./_is-array');\nvar anObject = require('./_an-object');\nvar isObject = require('./_is-object');\nvar toIObject = require('./_to-iobject');\nvar toPrimitive = require('./_to-primitive');\nvar createDesc = require('./_property-desc');\nvar _create = require('./_object-create');\nvar gOPNExt = require('./_object-gopn-ext');\nvar $GOPD = require('./_object-gopd');\nvar $DP = require('./_object-dp');\nvar $keys = require('./_object-keys');\nvar gOPD = $GOPD.f;\nvar dP = $DP.f;\nvar gOPN = gOPNExt.f;\nvar $Symbol = global.Symbol;\nvar $JSON = global.JSON;\nvar _stringify = $JSON && $JSON.stringify;\nvar PROTOTYPE = 'prototype';\nvar HIDDEN = wks('_hidden');\nvar TO_PRIMITIVE = wks('toPrimitive');\nvar isEnum = {}.propertyIsEnumerable;\nvar SymbolRegistry = shared('symbol-registry');\nvar AllSymbols = shared('symbols');\nvar OPSymbols = shared('op-symbols');\nvar ObjectProto = Object[PROTOTYPE];\nvar USE_NATIVE = typeof $Symbol == 'function';\nvar QObject = global.QObject;\n// Don't use setters in Qt Script, https://github.com/zloirock/core-js/issues/173\nvar setter = !QObject || !QObject[PROTOTYPE] || !QObject[PROTOTYPE].findChild;\n\n// fallback for old Android, https://code.google.com/p/v8/issues/detail?id=687\nvar setSymbolDesc = DESCRIPTORS && $fails(function () {\n  return _create(dP({}, 'a', {\n    get: function () { return dP(this, 'a', { value: 7 }).a; }\n  })).a != 7;\n}) ? function (it, key, D) {\n  var protoDesc = gOPD(ObjectProto, key);\n  if (protoDesc) delete ObjectProto[key];\n  dP(it, key, D);\n  if (protoDesc && it !== ObjectProto) dP(ObjectProto, key, protoDesc);\n} : dP;\n\nvar wrap = function (tag) {\n  var sym = AllSymbols[tag] = _create($Symbol[PROTOTYPE]);\n  sym._k = tag;\n  return sym;\n};\n\nvar isSymbol = USE_NATIVE && typeof $Symbol.iterator == 'symbol' ? function (it) {\n  return typeof it == 'symbol';\n} : function (it) {\n  return it instanceof $Symbol;\n};\n\nvar $defineProperty = function defineProperty(it, key, D) {\n  if (it === ObjectProto) $defineProperty(OPSymbols, key, D);\n  anObject(it);\n  key = toPrimitive(key, true);\n  anObject(D);\n  if (has(AllSymbols, key)) {\n    if (!D.enumerable) {\n      if (!has(it, HIDDEN)) dP(it, HIDDEN, createDesc(1, {}));\n      it[HIDDEN][key] = true;\n    } else {\n      if (has(it, HIDDEN) && it[HIDDEN][key]) it[HIDDEN][key] = false;\n      D = _create(D, { enumerable: createDesc(0, false) });\n    } return setSymbolDesc(it, key, D);\n  } return dP(it, key, D);\n};\nvar $defineProperties = function defineProperties(it, P) {\n  anObject(it);\n  var keys = enumKeys(P = toIObject(P));\n  var i = 0;\n  var l = keys.length;\n  var key;\n  while (l > i) $defineProperty(it, key = keys[i++], P[key]);\n  return it;\n};\nvar $create = function create(it, P) {\n  return P === undefined ? _create(it) : $defineProperties(_create(it), P);\n};\nvar $propertyIsEnumerable = function propertyIsEnumerable(key) {\n  var E = isEnum.call(this, key = toPrimitive(key, true));\n  if (this === ObjectProto && has(AllSymbols, key) && !has(OPSymbols, key)) return false;\n  return E || !has(this, key) || !has(AllSymbols, key) || has(this, HIDDEN) && this[HIDDEN][key] ? E : true;\n};\nvar $getOwnPropertyDescriptor = function getOwnPropertyDescriptor(it, key) {\n  it = toIObject(it);\n  key = toPrimitive(key, true);\n  if (it === ObjectProto && has(AllSymbols, key) && !has(OPSymbols, key)) return;\n  var D = gOPD(it, key);\n  if (D && has(AllSymbols, key) && !(has(it, HIDDEN) && it[HIDDEN][key])) D.enumerable = true;\n  return D;\n};\nvar $getOwnPropertyNames = function getOwnPropertyNames(it) {\n  var names = gOPN(toIObject(it));\n  var result = [];\n  var i = 0;\n  var key;\n  while (names.length > i) {\n    if (!has(AllSymbols, key = names[i++]) && key != HIDDEN && key != META) result.push(key);\n  } return result;\n};\nvar $getOwnPropertySymbols = function getOwnPropertySymbols(it) {\n  var IS_OP = it === ObjectProto;\n  var names = gOPN(IS_OP ? OPSymbols : toIObject(it));\n  var result = [];\n  var i = 0;\n  var key;\n  while (names.length > i) {\n    if (has(AllSymbols, key = names[i++]) && (IS_OP ? has(ObjectProto, key) : true)) result.push(AllSymbols[key]);\n  } return result;\n};\n\n// 19.4.1.1 Symbol([description])\nif (!USE_NATIVE) {\n  $Symbol = function Symbol() {\n    if (this instanceof $Symbol) throw TypeError('Symbol is not a constructor!');\n    var tag = uid(arguments.length > 0 ? arguments[0] : undefined);\n    var $set = function (value) {\n      if (this === ObjectProto) $set.call(OPSymbols, value);\n      if (has(this, HIDDEN) && has(this[HIDDEN], tag)) this[HIDDEN][tag] = false;\n      setSymbolDesc(this, tag, createDesc(1, value));\n    };\n    if (DESCRIPTORS && setter) setSymbolDesc(ObjectProto, tag, { configurable: true, set: $set });\n    return wrap(tag);\n  };\n  redefine($Symbol[PROTOTYPE], 'toString', function toString() {\n    return this._k;\n  });\n\n  $GOPD.f = $getOwnPropertyDescriptor;\n  $DP.f = $defineProperty;\n  require('./_object-gopn').f = gOPNExt.f = $getOwnPropertyNames;\n  require('./_object-pie').f = $propertyIsEnumerable;\n  require('./_object-gops').f = $getOwnPropertySymbols;\n\n  if (DESCRIPTORS && !require('./_library')) {\n    redefine(ObjectProto, 'propertyIsEnumerable', $propertyIsEnumerable, true);\n  }\n\n  wksExt.f = function (name) {\n    return wrap(wks(name));\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Symbol: $Symbol });\n\nfor (var es6Symbols = (\n  // 19.4.2.2, 19.4.2.3, 19.4.2.4, 19.4.2.6, 19.4.2.8, 19.4.2.9, 19.4.2.10, 19.4.2.11, 19.4.2.12, 19.4.2.13, 19.4.2.14\n  'hasInstance,isConcatSpreadable,iterator,match,replace,search,species,split,toPrimitive,toStringTag,unscopables'\n).split(','), j = 0; es6Symbols.length > j;)wks(es6Symbols[j++]);\n\nfor (var wellKnownSymbols = $keys(wks.store), k = 0; wellKnownSymbols.length > k;) wksDefine(wellKnownSymbols[k++]);\n\n$export($export.S + $export.F * !USE_NATIVE, 'Symbol', {\n  // 19.4.2.1 Symbol.for(key)\n  'for': function (key) {\n    return has(SymbolRegistry, key += '')\n      ? SymbolRegistry[key]\n      : SymbolRegistry[key] = $Symbol(key);\n  },\n  // 19.4.2.5 Symbol.keyFor(sym)\n  keyFor: function keyFor(sym) {\n    if (!isSymbol(sym)) throw TypeError(sym + ' is not a symbol!');\n    for (var key in SymbolRegistry) if (SymbolRegistry[key] === sym) return key;\n  },\n  useSetter: function () { setter = true; },\n  useSimple: function () { setter = false; }\n});\n\n$export($export.S + $export.F * !USE_NATIVE, 'Object', {\n  // 19.1.2.2 Object.create(O [, Properties])\n  create: $create,\n  // 19.1.2.4 Object.defineProperty(O, P, Attributes)\n  defineProperty: $defineProperty,\n  // 19.1.2.3 Object.defineProperties(O, Properties)\n  defineProperties: $defineProperties,\n  // 19.1.2.6 Object.getOwnPropertyDescriptor(O, P)\n  getOwnPropertyDescriptor: $getOwnPropertyDescriptor,\n  // 19.1.2.7 Object.getOwnPropertyNames(O)\n  getOwnPropertyNames: $getOwnPropertyNames,\n  // 19.1.2.8 Object.getOwnPropertySymbols(O)\n  getOwnPropertySymbols: $getOwnPropertySymbols\n});\n\n// 24.3.2 JSON.stringify(value [, replacer [, space]])\n$JSON && $export($export.S + $export.F * (!USE_NATIVE || $fails(function () {\n  var S = $Symbol();\n  // MS Edge converts symbol values to JSON as {}\n  // WebKit converts symbol values to JSON as null\n  // V8 throws on boxed symbols\n  return _stringify([S]) != '[null]' || _stringify({ a: S }) != '{}' || _stringify(Object(S)) != '{}';\n})), 'JSON', {\n  stringify: function stringify(it) {\n    var args = [it];\n    var i = 1;\n    var replacer, $replacer;\n    while (arguments.length > i) args.push(arguments[i++]);\n    $replacer = replacer = args[1];\n    if (!isObject(replacer) && it === undefined || isSymbol(it)) return; // IE8 returns string on undefined\n    if (!isArray(replacer)) replacer = function (key, value) {\n      if (typeof $replacer == 'function') value = $replacer.call(this, key, value);\n      if (!isSymbol(value)) return value;\n    };\n    args[1] = replacer;\n    return _stringify.apply($JSON, args);\n  }\n});\n\n// 19.4.3.4 Symbol.prototype[@@toPrimitive](hint)\n$Symbol[PROTOTYPE][TO_PRIMITIVE] || require('./_hide')($Symbol[PROTOTYPE], TO_PRIMITIVE, $Symbol[PROTOTYPE].valueOf);\n// 19.4.3.5 Symbol.prototype[@@toStringTag]\nsetToStringTag($Symbol, 'Symbol');\n// 20.2.1.9 Math[@@toStringTag]\nsetToStringTag(Math, 'Math', true);\n// 24.3.3 JSON[@@toStringTag]\nsetToStringTag(global.JSON, 'JSON', true);\n","'use strict';\nvar $export = require('./_export');\nvar $typed = require('./_typed');\nvar buffer = require('./_typed-buffer');\nvar anObject = require('./_an-object');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nvar toLength = require('./_to-length');\nvar isObject = require('./_is-object');\nvar ArrayBuffer = require('./_global').ArrayBuffer;\nvar speciesConstructor = require('./_species-constructor');\nvar $ArrayBuffer = buffer.ArrayBuffer;\nvar $DataView = buffer.DataView;\nvar $isView = $typed.ABV && ArrayBuffer.isView;\nvar $slice = $ArrayBuffer.prototype.slice;\nvar VIEW = $typed.VIEW;\nvar ARRAY_BUFFER = 'ArrayBuffer';\n\n$export($export.G + $export.W + $export.F * (ArrayBuffer !== $ArrayBuffer), { ArrayBuffer: $ArrayBuffer });\n\n$export($export.S + $export.F * !$typed.CONSTR, ARRAY_BUFFER, {\n  // 24.1.3.1 ArrayBuffer.isView(arg)\n  isView: function isView(it) {\n    return $isView && $isView(it) || isObject(it) && VIEW in it;\n  }\n});\n\n$export($export.P + $export.U + $export.F * require('./_fails')(function () {\n  return !new $ArrayBuffer(2).slice(1, undefined).byteLength;\n}), ARRAY_BUFFER, {\n  // 24.1.4.3 ArrayBuffer.prototype.slice(start, end)\n  slice: function slice(start, end) {\n    if ($slice !== undefined && end === undefined) return $slice.call(anObject(this), start); // FF fix\n    var len = anObject(this).byteLength;\n    var first = toAbsoluteIndex(start, len);\n    var fin = toAbsoluteIndex(end === undefined ? len : end, len);\n    var result = new (speciesConstructor(this, $ArrayBuffer))(toLength(fin - first));\n    var viewS = new $DataView(this);\n    var viewT = new $DataView(result);\n    var index = 0;\n    while (first < fin) {\n      viewT.setUint8(index++, viewS.getUint8(first++));\n    } return result;\n  }\n});\n\nrequire('./_set-species')(ARRAY_BUFFER);\n","var $export = require('./_export');\n$export($export.G + $export.W + $export.F * !require('./_typed').ABV, {\n  DataView: require('./_typed-buffer').DataView\n});\n","require('./_typed-array')('Float32', 4, function (init) {\n  return function Float32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Float64', 8, function (init) {\n  return function Float64Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Int16', 2, function (init) {\n  return function Int16Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Int32', 4, function (init) {\n  return function Int32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Int8', 1, function (init) {\n  return function Int8Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Uint16', 2, function (init) {\n  return function Uint16Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Uint32', 4, function (init) {\n  return function Uint32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Uint8', 1, function (init) {\n  return function Uint8Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Uint8', 1, function (init) {\n  return function Uint8ClampedArray(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n}, true);\n","'use strict';\nvar global = require('./_global');\nvar each = require('./_array-methods')(0);\nvar redefine = require('./_redefine');\nvar meta = require('./_meta');\nvar assign = require('./_object-assign');\nvar weak = require('./_collection-weak');\nvar isObject = require('./_is-object');\nvar validate = require('./_validate-collection');\nvar NATIVE_WEAK_MAP = require('./_validate-collection');\nvar IS_IE11 = !global.ActiveXObject && 'ActiveXObject' in global;\nvar WEAK_MAP = 'WeakMap';\nvar getWeak = meta.getWeak;\nvar isExtensible = Object.isExtensible;\nvar uncaughtFrozenStore = weak.ufstore;\nvar InternalMap;\n\nvar wrapper = function (get) {\n  return function WeakMap() {\n    return get(this, arguments.length > 0 ? arguments[0] : undefined);\n  };\n};\n\nvar methods = {\n  // 23.3.3.3 WeakMap.prototype.get(key)\n  get: function get(key) {\n    if (isObject(key)) {\n      var data = getWeak(key);\n      if (data === true) return uncaughtFrozenStore(validate(this, WEAK_MAP)).get(key);\n      return data ? data[this._i] : undefined;\n    }\n  },\n  // 23.3.3.5 WeakMap.prototype.set(key, value)\n  set: function set(key, value) {\n    return weak.def(validate(this, WEAK_MAP), key, value);\n  }\n};\n\n// 23.3 WeakMap Objects\nvar $WeakMap = module.exports = require('./_collection')(WEAK_MAP, wrapper, methods, weak, true, true);\n\n// IE11 WeakMap frozen keys fix\nif (NATIVE_WEAK_MAP && IS_IE11) {\n  InternalMap = weak.getConstructor(wrapper, WEAK_MAP);\n  assign(InternalMap.prototype, methods);\n  meta.NEED = true;\n  each(['delete', 'has', 'get', 'set'], function (key) {\n    var proto = $WeakMap.prototype;\n    var method = proto[key];\n    redefine(proto, key, function (a, b) {\n      // store frozen objects on internal weakmap shim\n      if (isObject(a) && !isExtensible(a)) {\n        if (!this._f) this._f = new InternalMap();\n        var result = this._f[key](a, b);\n        return key == 'set' ? this : result;\n      // store all the rest on native weakmap\n      } return method.call(this, a, b);\n    });\n  });\n}\n","'use strict';\nvar weak = require('./_collection-weak');\nvar validate = require('./_validate-collection');\nvar WEAK_SET = 'WeakSet';\n\n// 23.4 WeakSet Objects\nrequire('./_collection')(WEAK_SET, function (get) {\n  return function WeakSet() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.4.3.1 WeakSet.prototype.add(value)\n  add: function add(value) {\n    return weak.def(validate(this, WEAK_SET), value, true);\n  }\n}, weak, false, true);\n","'use strict';\n// https://tc39.github.io/proposal-flatMap/#sec-Array.prototype.flatMap\nvar $export = require('./_export');\nvar flattenIntoArray = require('./_flatten-into-array');\nvar toObject = require('./_to-object');\nvar toLength = require('./_to-length');\nvar aFunction = require('./_a-function');\nvar arraySpeciesCreate = require('./_array-species-create');\n\n$export($export.P, 'Array', {\n  flatMap: function flatMap(callbackfn /* , thisArg */) {\n    var O = toObject(this);\n    var sourceLen, A;\n    aFunction(callbackfn);\n    sourceLen = toLength(O.length);\n    A = arraySpeciesCreate(O, 0);\n    flattenIntoArray(A, O, O, sourceLen, 0, 1, callbackfn, arguments[1]);\n    return A;\n  }\n});\n\nrequire('./_add-to-unscopables')('flatMap');\n","'use strict';\n// https://tc39.github.io/proposal-flatMap/#sec-Array.prototype.flatten\nvar $export = require('./_export');\nvar flattenIntoArray = require('./_flatten-into-array');\nvar toObject = require('./_to-object');\nvar toLength = require('./_to-length');\nvar toInteger = require('./_to-integer');\nvar arraySpeciesCreate = require('./_array-species-create');\n\n$export($export.P, 'Array', {\n  flatten: function flatten(/* depthArg = 1 */) {\n    var depthArg = arguments[0];\n    var O = toObject(this);\n    var sourceLen = toLength(O.length);\n    var A = arraySpeciesCreate(O, 0);\n    flattenIntoArray(A, O, O, sourceLen, 0, depthArg === undefined ? 1 : toInteger(depthArg));\n    return A;\n  }\n});\n\nrequire('./_add-to-unscopables')('flatten');\n","'use strict';\n// https://github.com/tc39/Array.prototype.includes\nvar $export = require('./_export');\nvar $includes = require('./_array-includes')(true);\n\n$export($export.P, 'Array', {\n  includes: function includes(el /* , fromIndex = 0 */) {\n    return $includes(this, el, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n\nrequire('./_add-to-unscopables')('includes');\n","// https://github.com/rwaldron/tc39-notes/blob/master/es6/2014-09/sept-25.md#510-globalasap-for-enqueuing-a-microtask\nvar $export = require('./_export');\nvar microtask = require('./_microtask')();\nvar process = require('./_global').process;\nvar isNode = require('./_cof')(process) == 'process';\n\n$export($export.G, {\n  asap: function asap(fn) {\n    var domain = isNode && process.domain;\n    microtask(domain ? domain.bind(fn) : fn);\n  }\n});\n","// https://github.com/ljharb/proposal-is-error\nvar $export = require('./_export');\nvar cof = require('./_cof');\n\n$export($export.S, 'Error', {\n  isError: function isError(it) {\n    return cof(it) === 'Error';\n  }\n});\n","// https://github.com/tc39/proposal-global\nvar $export = require('./_export');\n\n$export($export.G, { global: require('./_global') });\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-map.from\nrequire('./_set-collection-from')('Map');\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-map.of\nrequire('./_set-collection-of')('Map');\n","// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar $export = require('./_export');\n\n$export($export.P + $export.R, 'Map', { toJSON: require('./_collection-to-json')('Map') });\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  clamp: function clamp(x, lower, upper) {\n    return Math.min(upper, Math.max(lower, x));\n  }\n});\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { DEG_PER_RAD: Math.PI / 180 });\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\nvar RAD_PER_DEG = 180 / Math.PI;\n\n$export($export.S, 'Math', {\n  degrees: function degrees(radians) {\n    return radians * RAD_PER_DEG;\n  }\n});\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\nvar scale = require('./_math-scale');\nvar fround = require('./_math-fround');\n\n$export($export.S, 'Math', {\n  fscale: function fscale(x, inLow, inHigh, outLow, outHigh) {\n    return fround(scale(x, inLow, inHigh, outLow, outHigh));\n  }\n});\n","// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  iaddh: function iaddh(x0, x1, y0, y1) {\n    var $x0 = x0 >>> 0;\n    var $x1 = x1 >>> 0;\n    var $y0 = y0 >>> 0;\n    return $x1 + (y1 >>> 0) + (($x0 & $y0 | ($x0 | $y0) & ~($x0 + $y0 >>> 0)) >>> 31) | 0;\n  }\n});\n","// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  imulh: function imulh(u, v) {\n    var UINT16 = 0xffff;\n    var $u = +u;\n    var $v = +v;\n    var u0 = $u & UINT16;\n    var v0 = $v & UINT16;\n    var u1 = $u >> 16;\n    var v1 = $v >> 16;\n    var t = (u1 * v0 >>> 0) + (u0 * v0 >>> 16);\n    return u1 * v1 + (t >> 16) + ((u0 * v1 >>> 0) + (t & UINT16) >> 16);\n  }\n});\n","// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  isubh: function isubh(x0, x1, y0, y1) {\n    var $x0 = x0 >>> 0;\n    var $x1 = x1 >>> 0;\n    var $y0 = y0 >>> 0;\n    return $x1 - (y1 >>> 0) - ((~$x0 & $y0 | ~($x0 ^ $y0) & $x0 - $y0 >>> 0) >>> 31) | 0;\n  }\n});\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { RAD_PER_DEG: 180 / Math.PI });\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\nvar DEG_PER_RAD = Math.PI / 180;\n\n$export($export.S, 'Math', {\n  radians: function radians(degrees) {\n    return degrees * DEG_PER_RAD;\n  }\n});\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { scale: require('./_math-scale') });\n","// http://jfbastien.github.io/papers/Math.signbit.html\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { signbit: function signbit(x) {\n  // eslint-disable-next-line no-self-compare\n  return (x = +x) != x ? x : x == 0 ? 1 / x == Infinity : x > 0;\n} });\n","// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  umulh: function umulh(u, v) {\n    var UINT16 = 0xffff;\n    var $u = +u;\n    var $v = +v;\n    var u0 = $u & UINT16;\n    var v0 = $v & UINT16;\n    var u1 = $u >>> 16;\n    var v1 = $v >>> 16;\n    var t = (u1 * v0 >>> 0) + (u0 * v0 >>> 16);\n    return u1 * v1 + (t >>> 16) + ((u0 * v1 >>> 0) + (t & UINT16) >>> 16);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar aFunction = require('./_a-function');\nvar $defineProperty = require('./_object-dp');\n\n// B.2.2.2 Object.prototype.__defineGetter__(P, getter)\nrequire('./_descriptors') && $export($export.P + require('./_object-forced-pam'), 'Object', {\n  __defineGetter__: function __defineGetter__(P, getter) {\n    $defineProperty.f(toObject(this), P, { get: aFunction(getter), enumerable: true, configurable: true });\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar aFunction = require('./_a-function');\nvar $defineProperty = require('./_object-dp');\n\n// B.2.2.3 Object.prototype.__defineSetter__(P, setter)\nrequire('./_descriptors') && $export($export.P + require('./_object-forced-pam'), 'Object', {\n  __defineSetter__: function __defineSetter__(P, setter) {\n    $defineProperty.f(toObject(this), P, { set: aFunction(setter), enumerable: true, configurable: true });\n  }\n});\n","// https://github.com/tc39/proposal-object-values-entries\nvar $export = require('./_export');\nvar $entries = require('./_object-to-array')(true);\n\n$export($export.S, 'Object', {\n  entries: function entries(it) {\n    return $entries(it);\n  }\n});\n","// https://github.com/tc39/proposal-object-getownpropertydescriptors\nvar $export = require('./_export');\nvar ownKeys = require('./_own-keys');\nvar toIObject = require('./_to-iobject');\nvar gOPD = require('./_object-gopd');\nvar createProperty = require('./_create-property');\n\n$export($export.S, 'Object', {\n  getOwnPropertyDescriptors: function getOwnPropertyDescriptors(object) {\n    var O = toIObject(object);\n    var getDesc = gOPD.f;\n    var keys = ownKeys(O);\n    var result = {};\n    var i = 0;\n    var key, desc;\n    while (keys.length > i) {\n      desc = getDesc(O, key = keys[i++]);\n      if (desc !== undefined) createProperty(result, key, desc);\n    }\n    return result;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar toPrimitive = require('./_to-primitive');\nvar getPrototypeOf = require('./_object-gpo');\nvar getOwnPropertyDescriptor = require('./_object-gopd').f;\n\n// B.2.2.4 Object.prototype.__lookupGetter__(P)\nrequire('./_descriptors') && $export($export.P + require('./_object-forced-pam'), 'Object', {\n  __lookupGetter__: function __lookupGetter__(P) {\n    var O = toObject(this);\n    var K = toPrimitive(P, true);\n    var D;\n    do {\n      if (D = getOwnPropertyDescriptor(O, K)) return D.get;\n    } while (O = getPrototypeOf(O));\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar toPrimitive = require('./_to-primitive');\nvar getPrototypeOf = require('./_object-gpo');\nvar getOwnPropertyDescriptor = require('./_object-gopd').f;\n\n// B.2.2.5 Object.prototype.__lookupSetter__(P)\nrequire('./_descriptors') && $export($export.P + require('./_object-forced-pam'), 'Object', {\n  __lookupSetter__: function __lookupSetter__(P) {\n    var O = toObject(this);\n    var K = toPrimitive(P, true);\n    var D;\n    do {\n      if (D = getOwnPropertyDescriptor(O, K)) return D.set;\n    } while (O = getPrototypeOf(O));\n  }\n});\n","// https://github.com/tc39/proposal-object-values-entries\nvar $export = require('./_export');\nvar $values = require('./_object-to-array')(false);\n\n$export($export.S, 'Object', {\n  values: function values(it) {\n    return $values(it);\n  }\n});\n","'use strict';\n// https://github.com/zenparsing/es-observable\nvar $export = require('./_export');\nvar global = require('./_global');\nvar core = require('./_core');\nvar microtask = require('./_microtask')();\nvar OBSERVABLE = require('./_wks')('observable');\nvar aFunction = require('./_a-function');\nvar anObject = require('./_an-object');\nvar anInstance = require('./_an-instance');\nvar redefineAll = require('./_redefine-all');\nvar hide = require('./_hide');\nvar forOf = require('./_for-of');\nvar RETURN = forOf.RETURN;\n\nvar getMethod = function (fn) {\n  return fn == null ? undefined : aFunction(fn);\n};\n\nvar cleanupSubscription = function (subscription) {\n  var cleanup = subscription._c;\n  if (cleanup) {\n    subscription._c = undefined;\n    cleanup();\n  }\n};\n\nvar subscriptionClosed = function (subscription) {\n  return subscription._o === undefined;\n};\n\nvar closeSubscription = function (subscription) {\n  if (!subscriptionClosed(subscription)) {\n    subscription._o = undefined;\n    cleanupSubscription(subscription);\n  }\n};\n\nvar Subscription = function (observer, subscriber) {\n  anObject(observer);\n  this._c = undefined;\n  this._o = observer;\n  observer = new SubscriptionObserver(this);\n  try {\n    var cleanup = subscriber(observer);\n    var subscription = cleanup;\n    if (cleanup != null) {\n      if (typeof cleanup.unsubscribe === 'function') cleanup = function () { subscription.unsubscribe(); };\n      else aFunction(cleanup);\n      this._c = cleanup;\n    }\n  } catch (e) {\n    observer.error(e);\n    return;\n  } if (subscriptionClosed(this)) cleanupSubscription(this);\n};\n\nSubscription.prototype = redefineAll({}, {\n  unsubscribe: function unsubscribe() { closeSubscription(this); }\n});\n\nvar SubscriptionObserver = function (subscription) {\n  this._s = subscription;\n};\n\nSubscriptionObserver.prototype = redefineAll({}, {\n  next: function next(value) {\n    var subscription = this._s;\n    if (!subscriptionClosed(subscription)) {\n      var observer = subscription._o;\n      try {\n        var m = getMethod(observer.next);\n        if (m) return m.call(observer, value);\n      } catch (e) {\n        try {\n          closeSubscription(subscription);\n        } finally {\n          throw e;\n        }\n      }\n    }\n  },\n  error: function error(value) {\n    var subscription = this._s;\n    if (subscriptionClosed(subscription)) throw value;\n    var observer = subscription._o;\n    subscription._o = undefined;\n    try {\n      var m = getMethod(observer.error);\n      if (!m) throw value;\n      value = m.call(observer, value);\n    } catch (e) {\n      try {\n        cleanupSubscription(subscription);\n      } finally {\n        throw e;\n      }\n    } cleanupSubscription(subscription);\n    return value;\n  },\n  complete: function complete(value) {\n    var subscription = this._s;\n    if (!subscriptionClosed(subscription)) {\n      var observer = subscription._o;\n      subscription._o = undefined;\n      try {\n        var m = getMethod(observer.complete);\n        value = m ? m.call(observer, value) : undefined;\n      } catch (e) {\n        try {\n          cleanupSubscription(subscription);\n        } finally {\n          throw e;\n        }\n      } cleanupSubscription(subscription);\n      return value;\n    }\n  }\n});\n\nvar $Observable = function Observable(subscriber) {\n  anInstance(this, $Observable, 'Observable', '_f')._f = aFunction(subscriber);\n};\n\nredefineAll($Observable.prototype, {\n  subscribe: function subscribe(observer) {\n    return new Subscription(observer, this._f);\n  },\n  forEach: function forEach(fn) {\n    var that = this;\n    return new (core.Promise || global.Promise)(function (resolve, reject) {\n      aFunction(fn);\n      var subscription = that.subscribe({\n        next: function (value) {\n          try {\n            return fn(value);\n          } catch (e) {\n            reject(e);\n            subscription.unsubscribe();\n          }\n        },\n        error: reject,\n        complete: resolve\n      });\n    });\n  }\n});\n\nredefineAll($Observable, {\n  from: function from(x) {\n    var C = typeof this === 'function' ? this : $Observable;\n    var method = getMethod(anObject(x)[OBSERVABLE]);\n    if (method) {\n      var observable = anObject(method.call(x));\n      return observable.constructor === C ? observable : new C(function (observer) {\n        return observable.subscribe(observer);\n      });\n    }\n    return new C(function (observer) {\n      var done = false;\n      microtask(function () {\n        if (!done) {\n          try {\n            if (forOf(x, false, function (it) {\n              observer.next(it);\n              if (done) return RETURN;\n            }) === RETURN) return;\n          } catch (e) {\n            if (done) throw e;\n            observer.error(e);\n            return;\n          } observer.complete();\n        }\n      });\n      return function () { done = true; };\n    });\n  },\n  of: function of() {\n    for (var i = 0, l = arguments.length, items = new Array(l); i < l;) items[i] = arguments[i++];\n    return new (typeof this === 'function' ? this : $Observable)(function (observer) {\n      var done = false;\n      microtask(function () {\n        if (!done) {\n          for (var j = 0; j < items.length; ++j) {\n            observer.next(items[j]);\n            if (done) return;\n          } observer.complete();\n        }\n      });\n      return function () { done = true; };\n    });\n  }\n});\n\nhide($Observable.prototype, OBSERVABLE, function () { return this; });\n\n$export($export.G, { Observable: $Observable });\n\nrequire('./_set-species')('Observable');\n","// https://github.com/tc39/proposal-promise-finally\n'use strict';\nvar $export = require('./_export');\nvar core = require('./_core');\nvar global = require('./_global');\nvar speciesConstructor = require('./_species-constructor');\nvar promiseResolve = require('./_promise-resolve');\n\n$export($export.P + $export.R, 'Promise', { 'finally': function (onFinally) {\n  var C = speciesConstructor(this, core.Promise || global.Promise);\n  var isFunction = typeof onFinally == 'function';\n  return this.then(\n    isFunction ? function (x) {\n      return promiseResolve(C, onFinally()).then(function () { return x; });\n    } : onFinally,\n    isFunction ? function (e) {\n      return promiseResolve(C, onFinally()).then(function () { throw e; });\n    } : onFinally\n  );\n} });\n","'use strict';\n// https://github.com/tc39/proposal-promise-try\nvar $export = require('./_export');\nvar newPromiseCapability = require('./_new-promise-capability');\nvar perform = require('./_perform');\n\n$export($export.S, 'Promise', { 'try': function (callbackfn) {\n  var promiseCapability = newPromiseCapability.f(this);\n  var result = perform(callbackfn);\n  (result.e ? promiseCapability.reject : promiseCapability.resolve)(result.v);\n  return promiseCapability.promise;\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar toMetaKey = metadata.key;\nvar ordinaryDefineOwnMetadata = metadata.set;\n\nmetadata.exp({ defineMetadata: function defineMetadata(metadataKey, metadataValue, target, targetKey) {\n  ordinaryDefineOwnMetadata(metadataKey, metadataValue, anObject(target), toMetaKey(targetKey));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar toMetaKey = metadata.key;\nvar getOrCreateMetadataMap = metadata.map;\nvar store = metadata.store;\n\nmetadata.exp({ deleteMetadata: function deleteMetadata(metadataKey, target /* , targetKey */) {\n  var targetKey = arguments.length < 3 ? undefined : toMetaKey(arguments[2]);\n  var metadataMap = getOrCreateMetadataMap(anObject(target), targetKey, false);\n  if (metadataMap === undefined || !metadataMap['delete'](metadataKey)) return false;\n  if (metadataMap.size) return true;\n  var targetMetadata = store.get(target);\n  targetMetadata['delete'](targetKey);\n  return !!targetMetadata.size || store['delete'](target);\n} });\n","var Set = require('./es6.set');\nvar from = require('./_array-from-iterable');\nvar metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar getPrototypeOf = require('./_object-gpo');\nvar ordinaryOwnMetadataKeys = metadata.keys;\nvar toMetaKey = metadata.key;\n\nvar ordinaryMetadataKeys = function (O, P) {\n  var oKeys = ordinaryOwnMetadataKeys(O, P);\n  var parent = getPrototypeOf(O);\n  if (parent === null) return oKeys;\n  var pKeys = ordinaryMetadataKeys(parent, P);\n  return pKeys.length ? oKeys.length ? from(new Set(oKeys.concat(pKeys))) : pKeys : oKeys;\n};\n\nmetadata.exp({ getMetadataKeys: function getMetadataKeys(target /* , targetKey */) {\n  return ordinaryMetadataKeys(anObject(target), arguments.length < 2 ? undefined : toMetaKey(arguments[1]));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar getPrototypeOf = require('./_object-gpo');\nvar ordinaryHasOwnMetadata = metadata.has;\nvar ordinaryGetOwnMetadata = metadata.get;\nvar toMetaKey = metadata.key;\n\nvar ordinaryGetMetadata = function (MetadataKey, O, P) {\n  var hasOwn = ordinaryHasOwnMetadata(MetadataKey, O, P);\n  if (hasOwn) return ordinaryGetOwnMetadata(MetadataKey, O, P);\n  var parent = getPrototypeOf(O);\n  return parent !== null ? ordinaryGetMetadata(MetadataKey, parent, P) : undefined;\n};\n\nmetadata.exp({ getMetadata: function getMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryGetMetadata(metadataKey, anObject(target), arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar ordinaryOwnMetadataKeys = metadata.keys;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ getOwnMetadataKeys: function getOwnMetadataKeys(target /* , targetKey */) {\n  return ordinaryOwnMetadataKeys(anObject(target), arguments.length < 2 ? undefined : toMetaKey(arguments[1]));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar ordinaryGetOwnMetadata = metadata.get;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ getOwnMetadata: function getOwnMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryGetOwnMetadata(metadataKey, anObject(target)\n    , arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar getPrototypeOf = require('./_object-gpo');\nvar ordinaryHasOwnMetadata = metadata.has;\nvar toMetaKey = metadata.key;\n\nvar ordinaryHasMetadata = function (MetadataKey, O, P) {\n  var hasOwn = ordinaryHasOwnMetadata(MetadataKey, O, P);\n  if (hasOwn) return true;\n  var parent = getPrototypeOf(O);\n  return parent !== null ? ordinaryHasMetadata(MetadataKey, parent, P) : false;\n};\n\nmetadata.exp({ hasMetadata: function hasMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryHasMetadata(metadataKey, anObject(target), arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar ordinaryHasOwnMetadata = metadata.has;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ hasOwnMetadata: function hasOwnMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryHasOwnMetadata(metadataKey, anObject(target)\n    , arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n","var $metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar aFunction = require('./_a-function');\nvar toMetaKey = $metadata.key;\nvar ordinaryDefineOwnMetadata = $metadata.set;\n\n$metadata.exp({ metadata: function metadata(metadataKey, metadataValue) {\n  return function decorator(target, targetKey) {\n    ordinaryDefineOwnMetadata(\n      metadataKey, metadataValue,\n      (targetKey !== undefined ? anObject : aFunction)(target),\n      toMetaKey(targetKey)\n    );\n  };\n} });\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-set.from\nrequire('./_set-collection-from')('Set');\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-set.of\nrequire('./_set-collection-of')('Set');\n","// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar $export = require('./_export');\n\n$export($export.P + $export.R, 'Set', { toJSON: require('./_collection-to-json')('Set') });\n","'use strict';\n// https://github.com/mathiasbynens/String.prototype.at\nvar $export = require('./_export');\nvar $at = require('./_string-at')(true);\n\n$export($export.P, 'String', {\n  at: function at(pos) {\n    return $at(this, pos);\n  }\n});\n","'use strict';\n// https://tc39.github.io/String.prototype.matchAll/\nvar $export = require('./_export');\nvar defined = require('./_defined');\nvar toLength = require('./_to-length');\nvar isRegExp = require('./_is-regexp');\nvar getFlags = require('./_flags');\nvar RegExpProto = RegExp.prototype;\n\nvar $RegExpStringIterator = function (regexp, string) {\n  this._r = regexp;\n  this._s = string;\n};\n\nrequire('./_iter-create')($RegExpStringIterator, 'RegExp String', function next() {\n  var match = this._r.exec(this._s);\n  return { value: match, done: match === null };\n});\n\n$export($export.P, 'String', {\n  matchAll: function matchAll(regexp) {\n    defined(this);\n    if (!isRegExp(regexp)) throw TypeError(regexp + ' is not a regexp!');\n    var S = String(this);\n    var flags = 'flags' in RegExpProto ? String(regexp.flags) : getFlags.call(regexp);\n    var rx = new RegExp(regexp.source, ~flags.indexOf('g') ? flags : 'g' + flags);\n    rx.lastIndex = toLength(regexp.lastIndex);\n    return new $RegExpStringIterator(rx, S);\n  }\n});\n","'use strict';\n// https://github.com/tc39/proposal-string-pad-start-end\nvar $export = require('./_export');\nvar $pad = require('./_string-pad');\nvar userAgent = require('./_user-agent');\n\n// https://github.com/zloirock/core-js/issues/280\n$export($export.P + $export.F * /Version\\/10\\.\\d+(\\.\\d+)? Safari\\//.test(userAgent), 'String', {\n  padEnd: function padEnd(maxLength /* , fillString = ' ' */) {\n    return $pad(this, maxLength, arguments.length > 1 ? arguments[1] : undefined, false);\n  }\n});\n","'use strict';\n// https://github.com/tc39/proposal-string-pad-start-end\nvar $export = require('./_export');\nvar $pad = require('./_string-pad');\nvar userAgent = require('./_user-agent');\n\n// https://github.com/zloirock/core-js/issues/280\n$export($export.P + $export.F * /Version\\/10\\.\\d+(\\.\\d+)? Safari\\//.test(userAgent), 'String', {\n  padStart: function padStart(maxLength /* , fillString = ' ' */) {\n    return $pad(this, maxLength, arguments.length > 1 ? arguments[1] : undefined, true);\n  }\n});\n","'use strict';\n// https://github.com/sebmarkbage/ecmascript-string-left-right-trim\nrequire('./_string-trim')('trimLeft', function ($trim) {\n  return function trimLeft() {\n    return $trim(this, 1);\n  };\n}, 'trimStart');\n","'use strict';\n// https://github.com/sebmarkbage/ecmascript-string-left-right-trim\nrequire('./_string-trim')('trimRight', function ($trim) {\n  return function trimRight() {\n    return $trim(this, 2);\n  };\n}, 'trimEnd');\n","require('./_wks-define')('asyncIterator');\n","require('./_wks-define')('observable');\n","// https://github.com/tc39/proposal-global\nvar $export = require('./_export');\n\n$export($export.S, 'System', { global: require('./_global') });\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-weakmap.from\nrequire('./_set-collection-from')('WeakMap');\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-weakmap.of\nrequire('./_set-collection-of')('WeakMap');\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-weakset.from\nrequire('./_set-collection-from')('WeakSet');\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-weakset.of\nrequire('./_set-collection-of')('WeakSet');\n","var $iterators = require('./es6.array.iterator');\nvar getKeys = require('./_object-keys');\nvar redefine = require('./_redefine');\nvar global = require('./_global');\nvar hide = require('./_hide');\nvar Iterators = require('./_iterators');\nvar wks = require('./_wks');\nvar ITERATOR = wks('iterator');\nvar TO_STRING_TAG = wks('toStringTag');\nvar ArrayValues = Iterators.Array;\n\nvar DOMIterables = {\n  CSSRuleList: true, // TODO: Not spec compliant, should be false.\n  CSSStyleDeclaration: false,\n  CSSValueList: false,\n  ClientRectList: false,\n  DOMRectList: false,\n  DOMStringList: false,\n  DOMTokenList: true,\n  DataTransferItemList: false,\n  FileList: false,\n  HTMLAllCollection: false,\n  HTMLCollection: false,\n  HTMLFormElement: false,\n  HTMLSelectElement: false,\n  MediaList: true, // TODO: Not spec compliant, should be false.\n  MimeTypeArray: false,\n  NamedNodeMap: false,\n  NodeList: true,\n  PaintRequestList: false,\n  Plugin: false,\n  PluginArray: false,\n  SVGLengthList: false,\n  SVGNumberList: false,\n  SVGPathSegList: false,\n  SVGPointList: false,\n  SVGStringList: false,\n  SVGTransformList: false,\n  SourceBufferList: false,\n  StyleSheetList: true, // TODO: Not spec compliant, should be false.\n  TextTrackCueList: false,\n  TextTrackList: false,\n  TouchList: false\n};\n\nfor (var collections = getKeys(DOMIterables), i = 0; i < collections.length; i++) {\n  var NAME = collections[i];\n  var explicit = DOMIterables[NAME];\n  var Collection = global[NAME];\n  var proto = Collection && Collection.prototype;\n  var key;\n  if (proto) {\n    if (!proto[ITERATOR]) hide(proto, ITERATOR, ArrayValues);\n    if (!proto[TO_STRING_TAG]) hide(proto, TO_STRING_TAG, NAME);\n    Iterators[NAME] = ArrayValues;\n    if (explicit) for (key in $iterators) if (!proto[key]) redefine(proto, key, $iterators[key], true);\n  }\n}\n","var $export = require('./_export');\nvar $task = require('./_task');\n$export($export.G + $export.B, {\n  setImmediate: $task.set,\n  clearImmediate: $task.clear\n});\n","// ie9- setTimeout & setInterval additional parameters fix\nvar global = require('./_global');\nvar $export = require('./_export');\nvar userAgent = require('./_user-agent');\nvar slice = [].slice;\nvar MSIE = /MSIE .\\./.test(userAgent); // <- dirty ie9- check\nvar wrap = function (set) {\n  return function (fn, time /* , ...args */) {\n    var boundArgs = arguments.length > 2;\n    var args = boundArgs ? slice.call(arguments, 2) : false;\n    return set(boundArgs ? function () {\n      // eslint-disable-next-line no-new-func\n      (typeof fn == 'function' ? fn : Function(fn)).apply(this, args);\n    } : fn, time);\n  };\n};\n$export($export.G + $export.B + $export.F * MSIE, {\n  setTimeout: wrap(global.setTimeout),\n  setInterval: wrap(global.setInterval)\n});\n","require('./modules/es6.symbol');\nrequire('./modules/es6.object.create');\nrequire('./modules/es6.object.define-property');\nrequire('./modules/es6.object.define-properties');\nrequire('./modules/es6.object.get-own-property-descriptor');\nrequire('./modules/es6.object.get-prototype-of');\nrequire('./modules/es6.object.keys');\nrequire('./modules/es6.object.get-own-property-names');\nrequire('./modules/es6.object.freeze');\nrequire('./modules/es6.object.seal');\nrequire('./modules/es6.object.prevent-extensions');\nrequire('./modules/es6.object.is-frozen');\nrequire('./modules/es6.object.is-sealed');\nrequire('./modules/es6.object.is-extensible');\nrequire('./modules/es6.object.assign');\nrequire('./modules/es6.object.is');\nrequire('./modules/es6.object.set-prototype-of');\nrequire('./modules/es6.object.to-string');\nrequire('./modules/es6.function.bind');\nrequire('./modules/es6.function.name');\nrequire('./modules/es6.function.has-instance');\nrequire('./modules/es6.parse-int');\nrequire('./modules/es6.parse-float');\nrequire('./modules/es6.number.constructor');\nrequire('./modules/es6.number.to-fixed');\nrequire('./modules/es6.number.to-precision');\nrequire('./modules/es6.number.epsilon');\nrequire('./modules/es6.number.is-finite');\nrequire('./modules/es6.number.is-integer');\nrequire('./modules/es6.number.is-nan');\nrequire('./modules/es6.number.is-safe-integer');\nrequire('./modules/es6.number.max-safe-integer');\nrequire('./modules/es6.number.min-safe-integer');\nrequire('./modules/es6.number.parse-float');\nrequire('./modules/es6.number.parse-int');\nrequire('./modules/es6.math.acosh');\nrequire('./modules/es6.math.asinh');\nrequire('./modules/es6.math.atanh');\nrequire('./modules/es6.math.cbrt');\nrequire('./modules/es6.math.clz32');\nrequire('./modules/es6.math.cosh');\nrequire('./modules/es6.math.expm1');\nrequire('./modules/es6.math.fround');\nrequire('./modules/es6.math.hypot');\nrequire('./modules/es6.math.imul');\nrequire('./modules/es6.math.log10');\nrequire('./modules/es6.math.log1p');\nrequire('./modules/es6.math.log2');\nrequire('./modules/es6.math.sign');\nrequire('./modules/es6.math.sinh');\nrequire('./modules/es6.math.tanh');\nrequire('./modules/es6.math.trunc');\nrequire('./modules/es6.string.from-code-point');\nrequire('./modules/es6.string.raw');\nrequire('./modules/es6.string.trim');\nrequire('./modules/es6.string.iterator');\nrequire('./modules/es6.string.code-point-at');\nrequire('./modules/es6.string.ends-with');\nrequire('./modules/es6.string.includes');\nrequire('./modules/es6.string.repeat');\nrequire('./modules/es6.string.starts-with');\nrequire('./modules/es6.string.anchor');\nrequire('./modules/es6.string.big');\nrequire('./modules/es6.string.blink');\nrequire('./modules/es6.string.bold');\nrequire('./modules/es6.string.fixed');\nrequire('./modules/es6.string.fontcolor');\nrequire('./modules/es6.string.fontsize');\nrequire('./modules/es6.string.italics');\nrequire('./modules/es6.string.link');\nrequire('./modules/es6.string.small');\nrequire('./modules/es6.string.strike');\nrequire('./modules/es6.string.sub');\nrequire('./modules/es6.string.sup');\nrequire('./modules/es6.date.now');\nrequire('./modules/es6.date.to-json');\nrequire('./modules/es6.date.to-iso-string');\nrequire('./modules/es6.date.to-string');\nrequire('./modules/es6.date.to-primitive');\nrequire('./modules/es6.array.is-array');\nrequire('./modules/es6.array.from');\nrequire('./modules/es6.array.of');\nrequire('./modules/es6.array.join');\nrequire('./modules/es6.array.slice');\nrequire('./modules/es6.array.sort');\nrequire('./modules/es6.array.for-each');\nrequire('./modules/es6.array.map');\nrequire('./modules/es6.array.filter');\nrequire('./modules/es6.array.some');\nrequire('./modules/es6.array.every');\nrequire('./modules/es6.array.reduce');\nrequire('./modules/es6.array.reduce-right');\nrequire('./modules/es6.array.index-of');\nrequire('./modules/es6.array.last-index-of');\nrequire('./modules/es6.array.copy-within');\nrequire('./modules/es6.array.fill');\nrequire('./modules/es6.array.find');\nrequire('./modules/es6.array.find-index');\nrequire('./modules/es6.array.species');\nrequire('./modules/es6.array.iterator');\nrequire('./modules/es6.regexp.constructor');\nrequire('./modules/es6.regexp.exec');\nrequire('./modules/es6.regexp.to-string');\nrequire('./modules/es6.regexp.flags');\nrequire('./modules/es6.regexp.match');\nrequire('./modules/es6.regexp.replace');\nrequire('./modules/es6.regexp.search');\nrequire('./modules/es6.regexp.split');\nrequire('./modules/es6.promise');\nrequire('./modules/es6.map');\nrequire('./modules/es6.set');\nrequire('./modules/es6.weak-map');\nrequire('./modules/es6.weak-set');\nrequire('./modules/es6.typed.array-buffer');\nrequire('./modules/es6.typed.data-view');\nrequire('./modules/es6.typed.int8-array');\nrequire('./modules/es6.typed.uint8-array');\nrequire('./modules/es6.typed.uint8-clamped-array');\nrequire('./modules/es6.typed.int16-array');\nrequire('./modules/es6.typed.uint16-array');\nrequire('./modules/es6.typed.int32-array');\nrequire('./modules/es6.typed.uint32-array');\nrequire('./modules/es6.typed.float32-array');\nrequire('./modules/es6.typed.float64-array');\nrequire('./modules/es6.reflect.apply');\nrequire('./modules/es6.reflect.construct');\nrequire('./modules/es6.reflect.define-property');\nrequire('./modules/es6.reflect.delete-property');\nrequire('./modules/es6.reflect.enumerate');\nrequire('./modules/es6.reflect.get');\nrequire('./modules/es6.reflect.get-own-property-descriptor');\nrequire('./modules/es6.reflect.get-prototype-of');\nrequire('./modules/es6.reflect.has');\nrequire('./modules/es6.reflect.is-extensible');\nrequire('./modules/es6.reflect.own-keys');\nrequire('./modules/es6.reflect.prevent-extensions');\nrequire('./modules/es6.reflect.set');\nrequire('./modules/es6.reflect.set-prototype-of');\nrequire('./modules/es7.array.includes');\nrequire('./modules/es7.array.flat-map');\nrequire('./modules/es7.array.flatten');\nrequire('./modules/es7.string.at');\nrequire('./modules/es7.string.pad-start');\nrequire('./modules/es7.string.pad-end');\nrequire('./modules/es7.string.trim-left');\nrequire('./modules/es7.string.trim-right');\nrequire('./modules/es7.string.match-all');\nrequire('./modules/es7.symbol.async-iterator');\nrequire('./modules/es7.symbol.observable');\nrequire('./modules/es7.object.get-own-property-descriptors');\nrequire('./modules/es7.object.values');\nrequire('./modules/es7.object.entries');\nrequire('./modules/es7.object.define-getter');\nrequire('./modules/es7.object.define-setter');\nrequire('./modules/es7.object.lookup-getter');\nrequire('./modules/es7.object.lookup-setter');\nrequire('./modules/es7.map.to-json');\nrequire('./modules/es7.set.to-json');\nrequire('./modules/es7.map.of');\nrequire('./modules/es7.set.of');\nrequire('./modules/es7.weak-map.of');\nrequire('./modules/es7.weak-set.of');\nrequire('./modules/es7.map.from');\nrequire('./modules/es7.set.from');\nrequire('./modules/es7.weak-map.from');\nrequire('./modules/es7.weak-set.from');\nrequire('./modules/es7.global');\nrequire('./modules/es7.system.global');\nrequire('./modules/es7.error.is-error');\nrequire('./modules/es7.math.clamp');\nrequire('./modules/es7.math.deg-per-rad');\nrequire('./modules/es7.math.degrees');\nrequire('./modules/es7.math.fscale');\nrequire('./modules/es7.math.iaddh');\nrequire('./modules/es7.math.isubh');\nrequire('./modules/es7.math.imulh');\nrequire('./modules/es7.math.rad-per-deg');\nrequire('./modules/es7.math.radians');\nrequire('./modules/es7.math.scale');\nrequire('./modules/es7.math.umulh');\nrequire('./modules/es7.math.signbit');\nrequire('./modules/es7.promise.finally');\nrequire('./modules/es7.promise.try');\nrequire('./modules/es7.reflect.define-metadata');\nrequire('./modules/es7.reflect.delete-metadata');\nrequire('./modules/es7.reflect.get-metadata');\nrequire('./modules/es7.reflect.get-metadata-keys');\nrequire('./modules/es7.reflect.get-own-metadata');\nrequire('./modules/es7.reflect.get-own-metadata-keys');\nrequire('./modules/es7.reflect.has-metadata');\nrequire('./modules/es7.reflect.has-own-metadata');\nrequire('./modules/es7.reflect.metadata');\nrequire('./modules/es7.asap');\nrequire('./modules/es7.observable');\nrequire('./modules/web.timers');\nrequire('./modules/web.immediate');\nrequire('./modules/web.dom.iterable');\nmodule.exports = require('./modules/_core');\n","exports.read = function (buffer, offset, isLE, mLen, nBytes) {\n  var e, m\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var nBits = -7\n  var i = isLE ? (nBytes - 1) : 0\n  var d = isLE ? -1 : 1\n  var s = buffer[offset + i]\n\n  i += d\n\n  e = s & ((1 << (-nBits)) - 1)\n  s >>= (-nBits)\n  nBits += eLen\n  for (; nBits > 0; e = (e * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  m = e & ((1 << (-nBits)) - 1)\n  e >>= (-nBits)\n  nBits += mLen\n  for (; nBits > 0; m = (m * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  if (e === 0) {\n    e = 1 - eBias\n  } else if (e === eMax) {\n    return m ? NaN : ((s ? -1 : 1) * Infinity)\n  } else {\n    m = m + Math.pow(2, mLen)\n    e = e - eBias\n  }\n  return (s ? -1 : 1) * m * Math.pow(2, e - mLen)\n}\n\nexports.write = function (buffer, value, offset, isLE, mLen, nBytes) {\n  var e, m, c\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var rt = (mLen === 23 ? Math.pow(2, -24) - Math.pow(2, -77) : 0)\n  var i = isLE ? 0 : (nBytes - 1)\n  var d = isLE ? 1 : -1\n  var s = value < 0 || (value === 0 && 1 / value < 0) ? 1 : 0\n\n  value = Math.abs(value)\n\n  if (isNaN(value) || value === Infinity) {\n    m = isNaN(value) ? 1 : 0\n    e = eMax\n  } else {\n    e = Math.floor(Math.log(value) / Math.LN2)\n    if (value * (c = Math.pow(2, -e)) < 1) {\n      e--\n      c *= 2\n    }\n    if (e + eBias >= 1) {\n      value += rt / c\n    } else {\n      value += rt * Math.pow(2, 1 - eBias)\n    }\n    if (value * c >= 2) {\n      e++\n      c /= 2\n    }\n\n    if (e + eBias >= eMax) {\n      m = 0\n      e = eMax\n    } else if (e + eBias >= 1) {\n      m = ((value * c) - 1) * Math.pow(2, mLen)\n      e = e + eBias\n    } else {\n      m = value * Math.pow(2, eBias - 1) * Math.pow(2, mLen)\n      e = 0\n    }\n  }\n\n  for (; mLen >= 8; buffer[offset + i] = m & 0xff, i += d, m /= 256, mLen -= 8) {}\n\n  e = (e << mLen) | m\n  eLen += mLen\n  for (; eLen > 0; buffer[offset + i] = e & 0xff, i += d, e /= 256, eLen -= 8) {}\n\n  buffer[offset + i - d] |= s * 128\n}\n","/**\n * Convert array of 16 byte values to UUID string format of the form:\n * XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX\n */\nvar byteToHex = [];\nfor (var i = 0; i < 256; ++i) {\n  byteToHex[i] = (i + 0x100).toString(16).substr(1);\n}\n\nfunction bytesToUuid(buf, offset) {\n  var i = offset || 0;\n  var bth = byteToHex;\n  // join used to fix memory issue caused by concatenation: https://bugs.chromium.org/p/v8/issues/detail?id=3175#c4\n  return ([bth[buf[i++]], bth[buf[i++]], \n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]]]).join('');\n}\n\nmodule.exports = bytesToUuid;\n","// Unique ID creation requires a high quality random # generator.  In the\n// browser this is a little complicated due to unknown quality of Math.random()\n// and inconsistent support for the `crypto` API.  We do the best we can via\n// feature-detection\n\n// getRandomValues needs to be invoked in a context where \"this\" is a Crypto\n// implementation. Also, find the complete implementation of crypto on IE11.\nvar getRandomValues = (typeof(crypto) != 'undefined' && crypto.getRandomValues && crypto.getRandomValues.bind(crypto)) ||\n                      (typeof(msCrypto) != 'undefined' && typeof window.msCrypto.getRandomValues == 'function' && msCrypto.getRandomValues.bind(msCrypto));\n\nif (getRandomValues) {\n  // WHATWG crypto RNG - http://wiki.whatwg.org/wiki/Crypto\n  var rnds8 = new Uint8Array(16); // eslint-disable-line no-undef\n\n  module.exports = function whatwgRNG() {\n    getRandomValues(rnds8);\n    return rnds8;\n  };\n} else {\n  // Math.random()-based (RNG)\n  //\n  // If all else fails, use Math.random().  It's fast, but is of unspecified\n  // quality.\n  var rnds = new Array(16);\n\n  module.exports = function mathRNG() {\n    for (var i = 0, r; i < 16; i++) {\n      if ((i & 0x03) === 0) r = Math.random() * 0x100000000;\n      rnds[i] = r >>> ((i & 0x03) << 3) & 0xff;\n    }\n\n    return rnds;\n  };\n}\n","var rng = require('./lib/rng');\nvar bytesToUuid = require('./lib/bytesToUuid');\n\nfunction v4(options, buf, offset) {\n  var i = buf && offset || 0;\n\n  if (typeof(options) == 'string') {\n    buf = options === 'binary' ? new Array(16) : null;\n    options = null;\n  }\n  options = options || {};\n\n  var rnds = options.random || (options.rng || rng)();\n\n  // Per 4.4, set bits for version and `clock_seq_hi_and_reserved`\n  rnds[6] = (rnds[6] & 0x0f) | 0x40;\n  rnds[8] = (rnds[8] & 0x3f) | 0x80;\n\n  // Copy bytes to buffer, if provided\n  if (buf) {\n    for (var ii = 0; ii < 16; ++ii) {\n      buf[i + ii] = rnds[ii];\n    }\n  }\n\n  return buf || bytesToUuid(rnds);\n}\n\nmodule.exports = v4;\n","var g;\n\n// This works in non-strict mode\ng = (function() {\n\treturn this;\n})();\n\ntry {\n\t// This works if eval is allowed (see CSP)\n\tg = g || new Function(\"return this\")();\n} catch (e) {\n\t// This works if the window reference is available\n\tif (typeof window === \"object\") g = window;\n}\n\n// g can still be undefined, but nothing to do about it...\n// We return undefined, instead of nothing here, so it's\n// easier to handle this case. if(!global) { ...}\n\nmodule.exports = g;\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Timer } from './Timer.js';\r\n\r\nconst DefaultAccessTokenExpiringNotificationTime = 60; // seconds\r\n\r\nexport class AccessTokenEvents {\r\n\r\n    constructor({\r\n        accessTokenExpiringNotificationTime = DefaultAccessTokenExpiringNotificationTime,\r\n        accessTokenExpiringTimer = new Timer(\"Access token expiring\"),\r\n        accessTokenExpiredTimer = new Timer(\"Access token expired\")\r\n    } = {}) {\r\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\r\n\r\n        this._accessTokenExpiring = accessTokenExpiringTimer;\r\n        this._accessTokenExpired = accessTokenExpiredTimer;\r\n    }\r\n\r\n    load(container) {\r\n        // only register events if there's an access token and it has an expiration\r\n        if (container.access_token && container.expires_in !== undefined) {\r\n            let duration = container.expires_in;\r\n            Log.debug(\"AccessTokenEvents.load: access token present, remaining duration:\", duration);\r\n\r\n            if (duration > 0) {\r\n                // only register expiring if we still have time\r\n                let expiring = duration - this._accessTokenExpiringNotificationTime;\r\n                if (expiring <= 0){\r\n                    expiring = 1;\r\n                }\r\n                \r\n                Log.debug(\"AccessTokenEvents.load: registering expiring timer in:\", expiring);\r\n                this._accessTokenExpiring.init(expiring);\r\n            }\r\n            else {\r\n                Log.debug(\"AccessTokenEvents.load: canceling existing expiring timer becase we're past expiration.\");\r\n                this._accessTokenExpiring.cancel();\r\n            }\r\n\r\n            // if it's negative, it will still fire\r\n            let expired = duration + 1;\r\n            Log.debug(\"AccessTokenEvents.load: registering expired timer in:\", expired);\r\n            this._accessTokenExpired.init(expired);\r\n        }\r\n        else {\r\n            this._accessTokenExpiring.cancel();\r\n            this._accessTokenExpired.cancel();\r\n        }\r\n    }\r\n\r\n    unload() {\r\n        Log.debug(\"AccessTokenEvents.unload: canceling existing access token timers\");\r\n        this._accessTokenExpiring.cancel();\r\n        this._accessTokenExpired.cancel();\r\n    }\r\n\r\n    addAccessTokenExpiring(cb) {\r\n        this._accessTokenExpiring.addHandler(cb);\r\n    }\r\n    removeAccessTokenExpiring(cb) {\r\n        this._accessTokenExpiring.removeHandler(cb);\r\n    }\r\n\r\n    addAccessTokenExpired(cb) {\r\n        this._accessTokenExpired.addHandler(cb);\r\n    }\r\n    removeAccessTokenExpired(cb) {\r\n        this._accessTokenExpired.removeHandler(cb);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultInterval = 2000;\r\n\r\nexport class CheckSessionIFrame {\r\n    constructor(callback, client_id, url, interval, stopOnError = true) {\r\n        this._callback = callback;\r\n        this._client_id = client_id;\r\n        this._url = url;\r\n        this._interval = interval || DefaultInterval;\r\n        this._stopOnError = stopOnError;\r\n\r\n        var idx = url.indexOf(\"/\", url.indexOf(\"//\") + 2);\r\n        this._frame_origin = url.substr(0, idx);\r\n\r\n        this._frame = window.document.createElement(\"iframe\");\r\n\r\n        // shotgun approach\r\n        this._frame.style.visibility = \"hidden\";\r\n        this._frame.style.position = \"absolute\";\r\n        this._frame.style.display = \"none\";\r\n        this._frame.style.width = 0;\r\n        this._frame.style.height = 0;\r\n\r\n        this._frame.src = url;\r\n    }\r\n    load() {\r\n        return new Promise((resolve) => {\r\n            this._frame.onload = () => {\r\n                resolve();\r\n            }\r\n\r\n            window.document.body.appendChild(this._frame);\r\n            this._boundMessageEvent = this._message.bind(this);\r\n            window.addEventListener(\"message\", this._boundMessageEvent, false);\r\n        });\r\n    }\r\n    _message(e) {\r\n        if (e.origin === this._frame_origin &&\r\n            e.source === this._frame.contentWindow\r\n        ) {\r\n            if (e.data === \"error\") {\r\n                Log.error(\"CheckSessionIFrame: error message from check session op iframe\");\r\n                if (this._stopOnError) {\r\n                    this.stop();\r\n                }\r\n            }\r\n            else if (e.data === \"changed\") {\r\n                Log.debug(\"CheckSessionIFrame: changed message from check session op iframe\");\r\n                this.stop();\r\n                this._callback();\r\n            }\r\n            else {\r\n                Log.debug(\"CheckSessionIFrame: \" + e.data + \" message from check session op iframe\");\r\n            }\r\n        }\r\n    }\r\n    start(session_state) {\r\n        if (this._session_state !== session_state) {\r\n            Log.debug(\"CheckSessionIFrame.start\");\r\n\r\n            this.stop();\r\n\r\n            this._session_state = session_state;\r\n\r\n            let send = () => {\r\n                this._frame.contentWindow.postMessage(this._client_id + \" \" + this._session_state, this._frame_origin);\r\n            };\r\n            \r\n            // trigger now\r\n            send();\r\n\r\n            // and setup timer\r\n            this._timer = window.setInterval(send, this._interval);\r\n        }\r\n    }\r\n\r\n    stop() {\r\n        this._session_state = null;\r\n\r\n        if (this._timer) {\r\n            Log.debug(\"CheckSessionIFrame.stop\");\r\n\r\n            window.clearInterval(this._timer);\r\n            this._timer = null;\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { CordovaPopupWindow } from './CordovaPopupWindow.js';\r\n\r\nexport class CordovaIFrameNavigator {\r\n\r\n    prepare(params) {\r\n        params.popupWindowFeatures = 'hidden=yes';\r\n        let popup = new CordovaPopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { CordovaPopupWindow } from './CordovaPopupWindow.js';\r\n\r\nexport class CordovaPopupNavigator {\r\n\r\n    prepare(params) {\r\n        let popup = new CordovaPopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultPopupFeatures = 'location=no,toolbar=no,zoom=no';\r\nconst DefaultPopupTarget = \"_blank\";\r\n\r\nexport class CordovaPopupWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        this.features = params.popupWindowFeatures || DefaultPopupFeatures;\r\n        this.target = params.popupWindowTarget || DefaultPopupTarget;\r\n        \r\n        this.redirect_uri = params.startUrl;\r\n        Log.debug(\"CordovaPopupWindow.ctor: redirect_uri: \" + this.redirect_uri);\r\n    }\r\n\r\n    _isInAppBrowserInstalled(cordovaMetadata) {\r\n        return [\"cordova-plugin-inappbrowser\", \"cordova-plugin-inappbrowser.inappbrowser\", \"org.apache.cordova.inappbrowser\"].some(function (name) {\r\n            return cordovaMetadata.hasOwnProperty(name)\r\n        })\r\n    }\r\n    \r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            this._error(\"No url provided\");\r\n        } else {\r\n            if (!window.cordova) {\r\n                return this._error(\"cordova is undefined\")\r\n            }\r\n            \r\n            var cordovaMetadata = window.cordova.require(\"cordova/plugin_list\").metadata;\r\n            if (this._isInAppBrowserInstalled(cordovaMetadata) === false) {\r\n                return this._error(\"InAppBrowser plugin not found\")\r\n            }\r\n            this._popup = cordova.InAppBrowser.open(params.url, this.target, this.features);\r\n            if (this._popup) {\r\n                Log.debug(\"CordovaPopupWindow.navigate: popup successfully created\");\r\n                \r\n                this._exitCallbackEvent = this._exitCallback.bind(this); \r\n                this._loadStartCallbackEvent = this._loadStartCallback.bind(this);\r\n                \r\n                this._popup.addEventListener(\"exit\", this._exitCallbackEvent, false);\r\n                this._popup.addEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\r\n            } else {\r\n                this._error(\"Error opening popup window\");\r\n            }\r\n        }\r\n        return this.promise;\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    _loadStartCallback(event) {\r\n        if (event.url.indexOf(this.redirect_uri) === 0) {\r\n            this._success({ url: event.url });\r\n        }    \r\n    }\r\n    _exitCallback(message) {\r\n        this._error(message);    \r\n    }\r\n    \r\n    _success(data) {\r\n        this._cleanup();\r\n\r\n        Log.debug(\"CordovaPopupWindow: Successful response from cordova popup window\");\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        this._cleanup();\r\n\r\n        Log.error(message);\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup();\r\n    }\r\n\r\n    _cleanup() {\r\n        if (this._popup){\r\n            Log.debug(\"CordovaPopupWindow: cleaning up popup\");\r\n            this._popup.removeEventListener(\"exit\", this._exitCallbackEvent, false);\r\n            this._popup.removeEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\r\n            this._popup.close();\r\n        }\r\n        this._popup = null;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class ErrorResponse extends Error {\r\n    constructor({error, error_description, error_uri, state, session_state}={}\r\n    ) {\r\n         if (!error){\r\n            Log.error(\"No error passed to ErrorResponse\");\r\n            throw new Error(\"error\");\r\n        }\r\n\r\n        super(error_description || error);\r\n\r\n        this.name = \"ErrorResponse\";\r\n\r\n        this.error = error;\r\n        this.error_description = error_description;\r\n        this.error_uri = error_uri;\r\n\r\n        this.state = state;\r\n        this.session_state = session_state;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class Event {\r\n\r\n    constructor(name) {\r\n        this._name = name;\r\n        this._callbacks = [];\r\n    }\r\n\r\n    addHandler(cb) {\r\n        this._callbacks.push(cb);\r\n    }\r\n\r\n    removeHandler(cb) {\r\n        var idx = this._callbacks.findIndex(item => item === cb);\r\n        if (idx >= 0) {\r\n            this._callbacks.splice(idx, 1);\r\n        }\r\n    }\r\n\r\n    raise(...params) {\r\n        Log.debug(\"Event: Raising event: \" + this._name);\r\n        for (let i = 0; i < this._callbacks.length; i++) {\r\n            this._callbacks[i](...params);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nconst timer = {\r\n    setInterval: function (cb, duration) {\r\n        return setInterval(cb, duration);\r\n    },\r\n    clearInterval: function (handle) {\r\n        return clearInterval(handle);\r\n    }\r\n};\r\n\r\nlet testing = false;\r\nlet request = null;\r\n\r\nexport class Global {\r\n\r\n    static _testing() {\r\n        testing = true;\r\n    }\r\n\r\n    static get location() {\r\n        if (!testing) {\r\n            return location;\r\n        }\r\n    }\r\n\r\n    static get localStorage() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return localStorage;\r\n        }\r\n    }\r\n\r\n    static get sessionStorage() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return sessionStorage;\r\n        }\r\n    }\r\n\r\n    static setXMLHttpRequest(newRequest) {\r\n        request = newRequest;\r\n    }\r\n\r\n    static get XMLHttpRequest() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return request || XMLHttpRequest;\r\n        }\r\n    }\r\n\r\n    static get timer() {\r\n        if (!testing) {\r\n            return timer;\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { IFrameWindow } from './IFrameWindow.js';\r\n\r\nexport class IFrameNavigator {\r\n\r\n    prepare(params) {\r\n        let frame = new IFrameWindow(params);\r\n        return Promise.resolve(frame);\r\n    }\r\n\r\n    callback(url) {\r\n        Log.debug(\"IFrameNavigator.callback\");\r\n\r\n        try {\r\n            IFrameWindow.notifyParent(url);\r\n            return Promise.resolve();\r\n        }\r\n        catch (e) {\r\n            return Promise.reject(e);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultTimeout = 10000;\r\n\r\nexport class IFrameWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        this._boundMessageEvent = this._message.bind(this);\r\n        window.addEventListener(\"message\", this._boundMessageEvent, false);\r\n\r\n        this._frame = window.document.createElement(\"iframe\");\r\n\r\n        // shotgun approach\r\n        this._frame.style.visibility = \"hidden\";\r\n        this._frame.style.position = \"absolute\";\r\n        this._frame.style.display = \"none\";\r\n        this._frame.style.width = 0;\r\n        this._frame.style.height = 0;\r\n\r\n        window.document.body.appendChild(this._frame);\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            this._error(\"No url provided\");\r\n        }\r\n        else {\r\n            let timeout = params.silentRequestTimeout || DefaultTimeout;\r\n            Log.debug(\"IFrameWindow.navigate: Using timeout of:\", timeout);\r\n            this._timer = window.setTimeout(this._timeout.bind(this), timeout);\r\n            this._frame.src = params.url;\r\n        }\r\n\r\n        return this.promise;\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    _success(data) {\r\n        this._cleanup();\r\n\r\n        Log.debug(\"IFrameWindow: Successful response from frame window\");\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        this._cleanup();\r\n\r\n        Log.error(message);\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup();\r\n    }\r\n\r\n    _cleanup() {\r\n        if (this._frame) {\r\n            Log.debug(\"IFrameWindow: cleanup\");\r\n\r\n            window.removeEventListener(\"message\", this._boundMessageEvent, false);\r\n            window.clearTimeout(this._timer);\r\n            window.document.body.removeChild(this._frame);\r\n\r\n            this._timer = null;\r\n            this._frame = null;\r\n            this._boundMessageEvent = null;\r\n        }\r\n    }\r\n\r\n    _timeout() {\r\n        Log.debug(\"IFrameWindow.timeout\");\r\n        this._error(\"Frame window timed out\");\r\n    }\r\n\r\n    _message(e) {\r\n        Log.debug(\"IFrameWindow.message\");\r\n\r\n        if (this._timer &&\r\n            e.origin === this._origin &&\r\n            e.source === this._frame.contentWindow\r\n        ) {\r\n            let url = e.data;\r\n            if (url) {\r\n                this._success({ url: url });\r\n            }\r\n            else {\r\n                this._error(\"Invalid response from frame\");\r\n            }\r\n        }\r\n    }\r\n\r\n    get _origin() {\r\n        return location.protocol + \"//\" + location.host;\r\n    }\r\n\r\n    static notifyParent(url) {\r\n        Log.debug(\"IFrameWindow.notifyParent\");\r\n        if (window.frameElement) {\r\n            url = url || window.location.href;\r\n            if (url) {\r\n                Log.debug(\"IFrameWindow.notifyParent: posting url message to parent\");\r\n                window.parent.postMessage(url, location.protocol + \"//\" + location.host);\r\n            }\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class InMemoryWebStorage{\r\n    constructor(){\r\n        this._data = {};\r\n    }\r\n\r\n    getItem(key) {\r\n        Log.debug(\"InMemoryWebStorage.getItem\", key);\r\n        return this._data[key];\r\n    }\r\n\r\n    setItem(key, value){\r\n        Log.debug(\"InMemoryWebStorage.setItem\", key);\r\n        this._data[key] = value;\r\n    }\r\n\r\n    removeItem(key){\r\n        Log.debug(\"InMemoryWebStorage.removeItem\", key);\r\n        delete this._data[key];\r\n    }\r\n\r\n    get length() {\r\n        return Object.getOwnPropertyNames(this._data).length;\r\n    }\r\n\r\n    key(index) {\r\n        return Object.getOwnPropertyNames(this._data)[index];\r\n    }\r\n}\r\n","import { jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs } from './crypto/jsrsasign';\r\nimport getJoseUtil from './JoseUtilImpl';\r\n\r\nexport const JoseUtil = getJoseUtil({ jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs });\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport default function getJoseUtil({ jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs }) {\r\n    return class JoseUtil {\r\n\r\n        static parseJwt(jwt) {\r\n            Log.debug(\"JoseUtil.parseJwt\");\r\n            try {\r\n                var token = jws.JWS.parse(jwt);\r\n                return {\r\n                    header: token.headerObj,\r\n                    payload: token.payloadObj\r\n                }\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n\r\n        static validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\r\n            Log.debug(\"JoseUtil.validateJwt\");\r\n\r\n            try {\r\n                if (key.kty === \"RSA\") {\r\n                    if (key.e && key.n) {\r\n                        key = KeyUtil.getKey(key);\r\n                    } else if (key.x5c && key.x5c.length) {\r\n                        var hex = b64tohex(key.x5c[0]);\r\n                        key = X509.getPublicKeyFromCertHex(hex);\r\n                    } else {\r\n                        Log.error(\"JoseUtil.validateJwt: RSA key missing key material\", key);\r\n                        return Promise.reject(new Error(\"RSA key missing key material\"));\r\n                    }\r\n                } else if (key.kty === \"EC\") {\r\n                    if (key.crv && key.x && key.y) {\r\n                        key = KeyUtil.getKey(key);\r\n                    } else {\r\n                        Log.error(\"JoseUtil.validateJwt: EC key missing key material\", key);\r\n                        return Promise.reject(new Error(\"EC key missing key material\"));\r\n                    }\r\n                } else {\r\n                    Log.error(\"JoseUtil.validateJwt: Unsupported key type\", key && key.kty);\r\n                    return Promise.reject(new Error(\"Unsupported key type: \" + key && key.kty));\r\n                }\r\n\r\n                return JoseUtil._validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive);\r\n            } catch (e) {\r\n                Log.error(e && e.message || e);\r\n                return Promise.reject(\"JWT validation failed\");\r\n            }\r\n        }\r\n\r\n        static validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive) {\r\n            if (!clockSkew) {\r\n                clockSkew = 0;\r\n            }\r\n\r\n            if (!now) {\r\n                now = parseInt(Date.now() / 1000);\r\n            }\r\n\r\n            var payload = JoseUtil.parseJwt(jwt).payload;\r\n\r\n            if (!payload.iss) {\r\n                Log.error(\"JoseUtil._validateJwt: issuer was not provided\");\r\n                return Promise.reject(new Error(\"issuer was not provided\"));\r\n            }\r\n            if (payload.iss !== issuer) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid issuer in token\", payload.iss);\r\n                return Promise.reject(new Error(\"Invalid issuer in token: \" + payload.iss));\r\n            }\r\n\r\n            if (!payload.aud) {\r\n                Log.error(\"JoseUtil._validateJwt: aud was not provided\");\r\n                return Promise.reject(new Error(\"aud was not provided\"));\r\n            }\r\n            var validAudience = payload.aud === audience || (Array.isArray(payload.aud) && payload.aud.indexOf(audience) >= 0);\r\n            if (!validAudience) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid audience in token\", payload.aud);\r\n                return Promise.reject(new Error(\"Invalid audience in token: \" + payload.aud));\r\n            }\r\n            if (payload.azp && payload.azp !== audience) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid azp in token\", payload.azp);\r\n                return Promise.reject(new Error(\"Invalid azp in token: \" + payload.azp));\r\n            }\r\n\r\n            if (!timeInsensitive) {\r\n                var lowerNow = now + clockSkew;\r\n                var upperNow = now - clockSkew;\r\n\r\n                if (!payload.iat) {\r\n                    Log.error(\"JoseUtil._validateJwt: iat was not provided\");\r\n                    return Promise.reject(new Error(\"iat was not provided\"));\r\n                }\r\n                if (lowerNow < payload.iat) {\r\n                    Log.error(\"JoseUtil._validateJwt: iat is in the future\", payload.iat);\r\n                    return Promise.reject(new Error(\"iat is in the future: \" + payload.iat));\r\n                }\r\n\r\n                if (payload.nbf && lowerNow < payload.nbf) {\r\n                    Log.error(\"JoseUtil._validateJwt: nbf is in the future\", payload.nbf);\r\n                    return Promise.reject(new Error(\"nbf is in the future: \" + payload.nbf));\r\n                }\r\n\r\n                if (!payload.exp) {\r\n                    Log.error(\"JoseUtil._validateJwt: exp was not provided\");\r\n                    return Promise.reject(new Error(\"exp was not provided\"));\r\n                }\r\n                if (payload.exp < upperNow) {\r\n                    Log.error(\"JoseUtil._validateJwt: exp is in the past\", payload.exp);\r\n                    return Promise.reject(new Error(\"exp is in the past:\" + payload.exp));\r\n                }\r\n            }\r\n\r\n            return Promise.resolve(payload);\r\n        }\r\n\r\n        static _validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\r\n\r\n            return JoseUtil.validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive).then(payload => {\r\n                try {\r\n                    if (!jws.JWS.verify(jwt, key, AllowedSigningAlgs)) {\r\n                        Log.error(\"JoseUtil._validateJwt: signature validation failed\");\r\n                        return Promise.reject(new Error(\"signature validation failed\"));\r\n                    }\r\n\r\n                    return payload;\r\n                } catch (e) {\r\n                    Log.error(e && e.message || e);\r\n                    return Promise.reject(new Error(\"signature validation failed\"));\r\n                }\r\n            });\r\n        }\r\n\r\n        static hashString(value, alg) {\r\n            try {\r\n                return crypto.Util.hashString(value, alg);\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n\r\n        static hexToBase64Url(value) {\r\n            try {\r\n                return hextob64u(value);\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class JsonService {\r\n    constructor(\r\n        additionalContentTypes = null, \r\n        XMLHttpRequestCtor = Global.XMLHttpRequest, \r\n        jwtHandler = null\r\n    ) {\r\n        if (additionalContentTypes && Array.isArray(additionalContentTypes))\r\n        {\r\n            this._contentTypes = additionalContentTypes.slice();\r\n        }\r\n        else\r\n        {\r\n            this._contentTypes = [];\r\n        }\r\n        this._contentTypes.push('application/json');\r\n        if (jwtHandler) {\r\n            this._contentTypes.push('application/jwt');\r\n        }\r\n\r\n        this._XMLHttpRequest = XMLHttpRequestCtor;\r\n        this._jwtHandler = jwtHandler;\r\n    }\r\n\r\n    getJson(url, token) {\r\n        if (!url){\r\n            Log.error(\"JsonService.getJson: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        Log.debug(\"JsonService.getJson, url: \", url);\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var req = new this._XMLHttpRequest();\r\n            req.open('GET', url);\r\n\r\n            var allowedContentTypes = this._contentTypes;\r\n            var jwtHandler = this._jwtHandler;\r\n\r\n            req.onload = function() {\r\n                Log.debug(\"JsonService.getJson: HTTP response received, status\", req.status);\r\n\r\n                if (req.status === 200) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found == \"application/jwt\") {\r\n                            jwtHandler(req).then(resolve, reject);\r\n                            return;\r\n                        }\r\n\r\n                        if (found) {\r\n                            try {\r\n                                resolve(JSON.parse(req.responseText));\r\n                                return;\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.getJson: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n\r\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\r\n                }\r\n                else {\r\n                    reject(Error(req.statusText + \" (\" + req.status + \")\"));\r\n                }\r\n            };\r\n\r\n            req.onerror = function() {\r\n                Log.error(\"JsonService.getJson: network error\");\r\n                reject(Error(\"Network Error\"));\r\n            };\r\n\r\n            if (token) {\r\n                Log.debug(\"JsonService.getJson: token passed, setting Authorization header\");\r\n                req.setRequestHeader(\"Authorization\", \"Bearer \" + token);\r\n            }\r\n\r\n            req.send();\r\n        });\r\n    }\r\n\r\n    postForm(url, payload) {\r\n        if (!url){\r\n            Log.error(\"JsonService.postForm: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        Log.debug(\"JsonService.postForm, url: \", url);\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var req = new this._XMLHttpRequest();\r\n            req.open('POST', url);\r\n\r\n            var allowedContentTypes = this._contentTypes;\r\n\r\n            req.onload = function() {\r\n                Log.debug(\"JsonService.postForm: HTTP response received, status\", req.status);\r\n\r\n                if (req.status === 200) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found) {\r\n                            try {\r\n                                resolve(JSON.parse(req.responseText));\r\n                                return;\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n\r\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\r\n                    return;\r\n                }\r\n\r\n                if (req.status === 400) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found) {\r\n                            try {\r\n                                var payload = JSON.parse(req.responseText);\r\n                                if (payload && payload.error) {\r\n                                    Log.error(\"JsonService.postForm: Error from server: \", payload.error);\r\n                                    reject(new Error(payload.error));\r\n                                    return;\r\n                                }\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n                }\r\n\r\n                reject(Error(req.statusText + \" (\" + req.status + \")\"));\r\n            };\r\n\r\n            req.onerror = function() {\r\n                Log.error(\"JsonService.postForm: network error\");\r\n                reject(Error(\"Network Error\"));\r\n            };\r\n\r\n            let body = \"\";\r\n            for(let key in payload) {\r\n\r\n                let value = payload[key];\r\n\r\n                if (value) {\r\n\r\n                    if (body.length > 0) {\r\n                        body += \"&\";\r\n                    }\r\n\r\n                    body += encodeURIComponent(key);\r\n                    body += \"=\";\r\n                    body += encodeURIComponent(value);\r\n                }\r\n            }\r\n\r\n            req.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\r\n            req.send(body);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nlet nopLogger = {\r\n    debug(){},\r\n    info(){},\r\n    warn(){},\r\n    error(){}\r\n};\r\n\r\nconst NONE = 0;\r\nconst ERROR = 1;\r\nconst WARN = 2;\r\nconst INFO = 3;\r\nconst DEBUG = 4;\r\n\r\nlet logger;\r\nlet level;\r\n\r\nexport class Log {\r\n    static get NONE() {return NONE};\r\n    static get ERROR() {return ERROR};\r\n    static get WARN() {return WARN};\r\n    static get INFO() {return INFO};\r\n    static get DEBUG() {return DEBUG};\r\n    \r\n    static reset(){\r\n        level = INFO;\r\n        logger = nopLogger;\r\n    }\r\n    \r\n    static get level(){\r\n        return level;\r\n    }\r\n    static set level(value){\r\n        if (NONE <= value && value <= DEBUG){\r\n            level = value;\r\n        }\r\n        else {\r\n            throw new Error(\"Invalid log level\");\r\n        }\r\n    }\r\n    \r\n    static get logger(){\r\n        return logger;\r\n    }\r\n    static set logger(value){\r\n        if (!value.debug && value.info) {\r\n            // just to stay backwards compat. can remove in 2.0\r\n            value.debug = value.info;\r\n        }\r\n\r\n        if (value.debug && value.info && value.warn && value.error){\r\n            logger = value;\r\n        }\r\n        else {\r\n            throw new Error(\"Invalid logger\");\r\n        }\r\n    }\r\n    \r\n    static debug(...args){\r\n        if (level >= DEBUG){\r\n            logger.debug.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static info(...args){\r\n        if (level >= INFO){\r\n            logger.info.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static warn(...args){\r\n        if (level >= WARN){\r\n            logger.warn.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static error(...args){\r\n        if (level >= ERROR){\r\n            logger.error.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n}\r\n\r\nLog.reset();\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { JsonService } from './JsonService.js';\r\n\r\nconst OidcMetadataUrlPath = '.well-known/openid-configuration';\r\n\r\nexport class MetadataService {\r\n    constructor(settings, JsonServiceCtor = JsonService) {\r\n        if (!settings) {\r\n            Log.error(\"MetadataService: No settings passed to MetadataService\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor(['application/jwk-set+json']);\r\n    }\r\n\r\n    get metadataUrl() {\r\n        if (!this._metadataUrl) {\r\n            if (this._settings.metadataUrl) {\r\n                this._metadataUrl = this._settings.metadataUrl;\r\n            }\r\n            else {\r\n                this._metadataUrl = this._settings.authority;\r\n\r\n                if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\r\n                    if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\r\n                        this._metadataUrl += '/';\r\n                    }\r\n                    this._metadataUrl += OidcMetadataUrlPath;\r\n                }\r\n            }\r\n        }\r\n\r\n        return this._metadataUrl;\r\n    }\r\n\r\n    getMetadata() {\r\n        if (this._settings.metadata) {\r\n            Log.debug(\"MetadataService.getMetadata: Returning metadata from settings\");\r\n            return Promise.resolve(this._settings.metadata);\r\n        }\r\n\r\n        if (!this.metadataUrl) {\r\n            Log.error(\"MetadataService.getMetadata: No authority or metadataUrl configured on settings\");\r\n            return Promise.reject(new Error(\"No authority or metadataUrl configured on settings\"));\r\n        }\r\n\r\n        Log.debug(\"MetadataService.getMetadata: getting metadata from\", this.metadataUrl);\r\n\r\n        return this._jsonService.getJson(this.metadataUrl)\r\n            .then(metadata => {\r\n                Log.debug(\"MetadataService.getMetadata: json received\");\r\n                this._settings.metadata = metadata;\r\n                return metadata;\r\n            });\r\n    }\r\n\r\n    getIssuer() {\r\n        return this._getMetadataProperty(\"issuer\");\r\n    }\r\n\r\n    getAuthorizationEndpoint() {\r\n        return this._getMetadataProperty(\"authorization_endpoint\");\r\n    }\r\n\r\n    getUserInfoEndpoint() {\r\n        return this._getMetadataProperty(\"userinfo_endpoint\");\r\n    }\r\n\r\n    getTokenEndpoint(optional=true) {\r\n        return this._getMetadataProperty(\"token_endpoint\", optional);\r\n    }\r\n\r\n    getCheckSessionIframe() {\r\n        return this._getMetadataProperty(\"check_session_iframe\", true);\r\n    }\r\n\r\n    getEndSessionEndpoint() {\r\n        return this._getMetadataProperty(\"end_session_endpoint\", true);\r\n    }\r\n\r\n    getRevocationEndpoint() {\r\n        return this._getMetadataProperty(\"revocation_endpoint\", true);\r\n    }\r\n\r\n    getKeysEndpoint() {\r\n        return this._getMetadataProperty(\"jwks_uri\", true);\r\n    }\r\n\r\n    _getMetadataProperty(name, optional=false) {\r\n        Log.debug(\"MetadataService.getMetadataProperty for: \" + name);\r\n\r\n        return this.getMetadata().then(metadata => {\r\n            Log.debug(\"MetadataService.getMetadataProperty: metadata recieved\");\r\n\r\n            if (metadata[name] === undefined) {\r\n\r\n                if (optional === true) {\r\n                    Log.warn(\"MetadataService.getMetadataProperty: Metadata does not contain optional property \" + name);\r\n                    return undefined;\r\n                }\r\n                else {\r\n                    Log.error(\"MetadataService.getMetadataProperty: Metadata does not contain property \" + name);\r\n                    throw new Error(\"Metadata does not contain property \" + name);\r\n                }\r\n            }\r\n\r\n            return metadata[name];\r\n        });\r\n    }\r\n\r\n    getSigningKeys() {\r\n        if (this._settings.signingKeys) {\r\n            Log.debug(\"MetadataService.getSigningKeys: Returning signingKeys from settings\");\r\n            return Promise.resolve(this._settings.signingKeys);\r\n        }\r\n\r\n        return this._getMetadataProperty(\"jwks_uri\").then(jwks_uri => {\r\n            Log.debug(\"MetadataService.getSigningKeys: jwks_uri received\", jwks_uri);\r\n\r\n            return this._jsonService.getJson(jwks_uri).then(keySet => {\r\n                Log.debug(\"MetadataService.getSigningKeys: key set received\", keySet);\r\n\r\n                if (!keySet.keys) {\r\n                    Log.error(\"MetadataService.getSigningKeys: Missing keys on keyset\");\r\n                    throw new Error(\"Missing keys on keyset\");\r\n                }\r\n\r\n                this._settings.signingKeys = keySet.keys;\r\n                return this._settings.signingKeys;\r\n            });\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClientSettings } from './OidcClientSettings.js';\r\nimport { ErrorResponse } from './ErrorResponse.js';\r\nimport { SigninRequest } from './SigninRequest.js';\r\nimport { SigninResponse } from './SigninResponse.js';\r\nimport { SignoutRequest } from './SignoutRequest.js';\r\nimport { SignoutResponse } from './SignoutResponse.js';\r\nimport { SigninState } from './SigninState.js';\r\nimport { State } from './State.js';\r\n\r\nexport class OidcClient {\r\n    constructor(settings = {}) {\r\n        if (settings instanceof OidcClientSettings) {\r\n            this._settings = settings;\r\n        }\r\n        else {\r\n            this._settings = new OidcClientSettings(settings);\r\n        }\r\n    }\r\n\r\n    get _stateStore() {\r\n        return this.settings.stateStore;\r\n    }\r\n    get _validator() {\r\n        return this.settings.validator;\r\n    }\r\n    get _metadataService() {\r\n        return this.settings.metadataService;\r\n    }\r\n\r\n    get settings() {\r\n        return this._settings;\r\n    }\r\n    get metadataService() {\r\n        return this._metadataService;\r\n    }\r\n\r\n    createSigninRequest({\r\n        response_type, scope, redirect_uri,\r\n        // data was meant to be the place a caller could indicate the data to\r\n        // have round tripped, but people were getting confused, so i added state (since that matches the spec)\r\n        // and so now if data is not passed, but state is then state will be used\r\n        data, state, prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values,\r\n        resource, request, request_uri, response_mode, extraQueryParams, extraTokenParams, request_type, skipUserInfo } = {},\r\n        stateStore\r\n    ) {\r\n        Log.debug(\"OidcClient.createSigninRequest\");\r\n\r\n        let client_id = this._settings.client_id;\r\n        response_type = response_type || this._settings.response_type;\r\n        scope = scope || this._settings.scope;\r\n        redirect_uri = redirect_uri || this._settings.redirect_uri;\r\n\r\n        // id_token_hint, login_hint aren't allowed on _settings\r\n        prompt = prompt || this._settings.prompt;\r\n        display = display || this._settings.display;\r\n        max_age = max_age || this._settings.max_age;\r\n        ui_locales = ui_locales || this._settings.ui_locales;\r\n        acr_values = acr_values || this._settings.acr_values;\r\n        resource = resource || this._settings.resource;\r\n        response_mode = response_mode || this._settings.response_mode;\r\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\r\n        extraTokenParams = extraTokenParams || this._settings.extraTokenParams;\r\n\r\n        let authority = this._settings.authority;\r\n\r\n        if (SigninRequest.isCode(response_type) && response_type !== \"code\") {\r\n            return Promise.reject(new Error(\"OpenID Connect hybrid flow is not supported\"));\r\n        }\r\n\r\n        return this._metadataService.getAuthorizationEndpoint().then(url => {\r\n            Log.debug(\"OidcClient.createSigninRequest: Received authorization endpoint\", url);\r\n\r\n            let signinRequest = new SigninRequest({\r\n                url,\r\n                client_id,\r\n                redirect_uri,\r\n                response_type,\r\n                scope,\r\n                data: data || state,\r\n                authority,\r\n                prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values,\r\n                resource, request, request_uri, extraQueryParams, extraTokenParams, request_type, response_mode,\r\n                client_secret: this._settings.client_secret,\r\n                skipUserInfo\r\n            });\r\n\r\n            var signinState = signinRequest.state;\r\n            stateStore = stateStore || this._stateStore;\r\n\r\n            return stateStore.set(signinState.id, signinState.toStorageString()).then(() => {\r\n                return signinRequest;\r\n            });\r\n        });\r\n    }\r\n\r\n    readSigninResponseState(url, stateStore, removeState = false) {\r\n        Log.debug(\"OidcClient.readSigninResponseState\");\r\n\r\n        let useQuery = this._settings.response_mode === \"query\" || \r\n            (!this._settings.response_mode && SigninRequest.isCode(this._settings.response_type));\r\n        let delimiter = useQuery ? \"?\" : \"#\";\r\n\r\n        var response = new SigninResponse(url, delimiter);\r\n\r\n        if (!response.state) {\r\n            Log.error(\"OidcClient.readSigninResponseState: No state in response\");\r\n            return Promise.reject(new Error(\"No state in response\"));\r\n        }\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\r\n\r\n        return stateApi(response.state).then(storedStateString => {\r\n            if (!storedStateString) {\r\n                Log.error(\"OidcClient.readSigninResponseState: No matching state found in storage\");\r\n                throw new Error(\"No matching state found in storage\");\r\n            }\r\n\r\n            let state = SigninState.fromStorageString(storedStateString);\r\n            return {state, response};\r\n        });\r\n    }\r\n\r\n    processSigninResponse(url, stateStore) {\r\n        Log.debug(\"OidcClient.processSigninResponse\");\r\n\r\n        return this.readSigninResponseState(url, stateStore, true).then(({state, response}) => {\r\n            Log.debug(\"OidcClient.processSigninResponse: Received state from storage; validating response\");\r\n            return this._validator.validateSigninResponse(state, response);\r\n        });\r\n    }\r\n\r\n    createSignoutRequest({id_token_hint, data, state, post_logout_redirect_uri, extraQueryParams, request_type } = {},\r\n        stateStore\r\n    ) {\r\n        Log.debug(\"OidcClient.createSignoutRequest\");\r\n\r\n        post_logout_redirect_uri = post_logout_redirect_uri || this._settings.post_logout_redirect_uri;\r\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\r\n\r\n        return this._metadataService.getEndSessionEndpoint().then(url => {\r\n            if (!url) {\r\n                Log.error(\"OidcClient.createSignoutRequest: No end session endpoint url returned\");\r\n                throw new Error(\"no end session endpoint\");\r\n            }\r\n\r\n            Log.debug(\"OidcClient.createSignoutRequest: Received end session endpoint\", url);\r\n\r\n            let request = new SignoutRequest({\r\n                url,\r\n                id_token_hint,\r\n                post_logout_redirect_uri,\r\n                data: data || state,\r\n                extraQueryParams,\r\n                request_type\r\n            });\r\n\r\n            var signoutState = request.state;\r\n            if (signoutState) {\r\n                Log.debug(\"OidcClient.createSignoutRequest: Signout request has state to persist\");\r\n\r\n                stateStore = stateStore || this._stateStore;\r\n                stateStore.set(signoutState.id, signoutState.toStorageString());\r\n            }\r\n\r\n            return request;\r\n        });\r\n    }\r\n\r\n    readSignoutResponseState(url, stateStore, removeState = false) {\r\n        Log.debug(\"OidcClient.readSignoutResponseState\");\r\n\r\n        var response = new SignoutResponse(url);\r\n        if (!response.state) {\r\n            Log.debug(\"OidcClient.readSignoutResponseState: No state in response\");\r\n\r\n            if (response.error) {\r\n                Log.warn(\"OidcClient.readSignoutResponseState: Response was error: \", response.error);\r\n                return Promise.reject(new ErrorResponse(response));\r\n            }\r\n\r\n            return Promise.resolve({undefined, response});\r\n        }\r\n\r\n        var stateKey = response.state;\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\r\n        return stateApi(stateKey).then(storedStateString => {\r\n            if (!storedStateString) {\r\n                Log.error(\"OidcClient.readSignoutResponseState: No matching state found in storage\");\r\n                throw new Error(\"No matching state found in storage\");\r\n            }\r\n\r\n            let state = State.fromStorageString(storedStateString);\r\n\r\n            return {state, response};\r\n        });\r\n    }\r\n\r\n    processSignoutResponse(url, stateStore) {\r\n        Log.debug(\"OidcClient.processSignoutResponse\");\r\n\r\n        return this.readSignoutResponseState(url, stateStore, true).then(({state, response}) => {\r\n            if (state) {\r\n                Log.debug(\"OidcClient.processSignoutResponse: Received state from storage; validating response\");\r\n                return this._validator.validateSignoutResponse(state, response);\r\n            }\r\n            else {\r\n                Log.debug(\"OidcClient.processSignoutResponse: No state from storage; skipping validating response\");\r\n                return response;\r\n            }\r\n        });\r\n    }\r\n\r\n    clearStaleState(stateStore) {\r\n        Log.debug(\"OidcClient.clearStaleState\");\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        return State.clearStaleState(stateStore, this.settings.staleStateAge);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { WebStorageStateStore } from './WebStorageStateStore.js';\r\nimport { ResponseValidator } from './ResponseValidator.js';\r\nimport { MetadataService } from './MetadataService.js';\r\n\r\nconst OidcMetadataUrlPath = '.well-known/openid-configuration';\r\n\r\nconst DefaultResponseType = \"id_token\";\r\nconst DefaultScope = \"openid\";\r\nconst DefaultStaleStateAge = 60 * 15; // seconds\r\nconst DefaultClockSkewInSeconds = 60 * 5;\r\n\r\nexport class OidcClientSettings {\r\n    constructor({\r\n        // metadata related\r\n        authority, metadataUrl, metadata, signingKeys,\r\n        // client related\r\n        client_id, client_secret, response_type = DefaultResponseType, scope = DefaultScope,\r\n        redirect_uri, post_logout_redirect_uri,\r\n        // optional protocol\r\n        prompt, display, max_age, ui_locales, acr_values, resource, response_mode,\r\n        // behavior flags\r\n        filterProtocolClaims = true, loadUserInfo = true,\r\n        staleStateAge = DefaultStaleStateAge, clockSkew = DefaultClockSkewInSeconds,\r\n        userInfoJwtIssuer = 'OP',\r\n        // other behavior\r\n        stateStore = new WebStorageStateStore(),\r\n        ResponseValidatorCtor = ResponseValidator,\r\n        MetadataServiceCtor = MetadataService,\r\n        // extra query params\r\n        extraQueryParams = {},\r\n        extraTokenParams = {}\r\n    } = {}) {\r\n\r\n        this._authority = authority;\r\n        this._metadataUrl = metadataUrl;\r\n        this._metadata = metadata;\r\n        this._signingKeys = signingKeys;\r\n\r\n        this._client_id = client_id;\r\n        this._client_secret = client_secret;\r\n        this._response_type = response_type;\r\n        this._scope = scope;\r\n        this._redirect_uri = redirect_uri;\r\n        this._post_logout_redirect_uri = post_logout_redirect_uri;\r\n\r\n        this._prompt = prompt;\r\n        this._display = display;\r\n        this._max_age = max_age;\r\n        this._ui_locales = ui_locales;\r\n        this._acr_values = acr_values;\r\n        this._resource = resource;\r\n        this._response_mode = response_mode;\r\n\r\n        this._filterProtocolClaims = !!filterProtocolClaims;\r\n        this._loadUserInfo = !!loadUserInfo;\r\n        this._staleStateAge = staleStateAge;\r\n        this._clockSkew = clockSkew;\r\n        this._userInfoJwtIssuer = userInfoJwtIssuer;\r\n\r\n        this._stateStore = stateStore;\r\n        this._validator = new ResponseValidatorCtor(this);\r\n        this._metadataService = new MetadataServiceCtor(this);\r\n\r\n        this._extraQueryParams = typeof extraQueryParams === 'object' ? extraQueryParams : {};\r\n        this._extraTokenParams = typeof extraTokenParams === 'object' ? extraTokenParams : {};\r\n    }\r\n\r\n    // client config\r\n    get client_id() {\r\n        return this._client_id;\r\n    }\r\n    set client_id(value) {\r\n        if (!this._client_id) {\r\n            // one-time set only\r\n            this._client_id = value;\r\n        }\r\n        else {\r\n            Log.error(\"OidcClientSettings.set_client_id: client_id has already been assigned.\")\r\n            throw new Error(\"client_id has already been assigned.\")\r\n        }\r\n    }\r\n    get client_secret() {\r\n        return this._client_secret;\r\n    }\r\n    get response_type() {\r\n        return this._response_type;\r\n    }\r\n    get scope() {\r\n        return this._scope;\r\n    }\r\n    get redirect_uri() {\r\n        return this._redirect_uri;\r\n    }\r\n    get post_logout_redirect_uri() {\r\n        return this._post_logout_redirect_uri;\r\n    }\r\n\r\n\r\n    // optional protocol params\r\n    get prompt() {\r\n        return this._prompt;\r\n    }\r\n    get display() {\r\n        return this._display;\r\n    }\r\n    get max_age() {\r\n        return this._max_age;\r\n    }\r\n    get ui_locales() {\r\n        return this._ui_locales;\r\n    }\r\n    get acr_values() {\r\n        return this._acr_values;\r\n    }\r\n    get resource() {\r\n        return this._resource;\r\n    }\r\n    get response_mode() {\r\n        return this._response_mode;\r\n    }\r\n\r\n\r\n    // metadata\r\n    get authority() {\r\n        return this._authority;\r\n    }\r\n    set authority(value) {\r\n        if (!this._authority) {\r\n            // one-time set only\r\n            this._authority = value;\r\n        }\r\n        else {\r\n            Log.error(\"OidcClientSettings.set_authority: authority has already been assigned.\")\r\n            throw new Error(\"authority has already been assigned.\")\r\n        }\r\n    }\r\n    get metadataUrl() {\r\n        if (!this._metadataUrl) {\r\n            this._metadataUrl = this.authority;\r\n\r\n            if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\r\n                if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\r\n                    this._metadataUrl += '/';\r\n                }\r\n                this._metadataUrl += OidcMetadataUrlPath;\r\n            }\r\n        }\r\n\r\n        return this._metadataUrl;\r\n    }\r\n\r\n    // settable/cachable metadata values\r\n    get metadata() {\r\n        return this._metadata;\r\n    }\r\n    set metadata(value) {\r\n        this._metadata = value;\r\n    }\r\n\r\n    get signingKeys() {\r\n        return this._signingKeys;\r\n    }\r\n    set signingKeys(value) {\r\n        this._signingKeys = value;\r\n    }\r\n\r\n    // behavior flags\r\n    get filterProtocolClaims() {\r\n        return this._filterProtocolClaims;\r\n    }\r\n    get loadUserInfo() {\r\n        return this._loadUserInfo;\r\n    }\r\n    get staleStateAge() {\r\n        return this._staleStateAge;\r\n    }\r\n    get clockSkew() {\r\n        return this._clockSkew;\r\n    }\r\n    get userInfoJwtIssuer() {\r\n        return this._userInfoJwtIssuer;\r\n    }\r\n\r\n    get stateStore() {\r\n        return this._stateStore;\r\n    }\r\n    get validator() {\r\n        return this._validator;\r\n    }\r\n    get metadataService() {\r\n        return this._metadataService;\r\n    }\r\n\r\n    // extra query params\r\n    get extraQueryParams() {\r\n        return this._extraQueryParams;\r\n    }\r\n    set extraQueryParams(value) {\r\n        if (typeof value === 'object'){\r\n            this._extraQueryParams = value;\r\n        } else {\r\n            this._extraQueryParams = {};\r\n        }\r\n    }\r\n\r\n    // extra token params\r\n    get extraTokenParams() {\r\n        return this._extraTokenParams;\r\n    }\r\n    set extraTokenParams(value) {\r\n        if (typeof value === 'object'){\r\n            this._extraTokenParams = value;\r\n        } else {\r\n            this._extraTokenParams = {};\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { PopupWindow } from './PopupWindow.js';\r\n\r\nexport class PopupNavigator {\r\n\r\n    prepare(params) {\r\n        let popup = new PopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n\r\n    callback(url, keepOpen, delimiter) {\r\n        Log.debug(\"PopupNavigator.callback\");\r\n\r\n        try {\r\n            PopupWindow.notifyOpener(url, keepOpen, delimiter);\r\n            return Promise.resolve();\r\n        }\r\n        catch (e) {\r\n            return Promise.reject(e);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nconst CheckForPopupClosedInterval = 500;\r\nconst DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;';\r\n//const DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;resizable=yes';\r\n\r\nconst DefaultPopupTarget = \"_blank\";\r\n\r\nexport class PopupWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        let target = params.popupWindowTarget || DefaultPopupTarget;\r\n        let features = params.popupWindowFeatures || DefaultPopupFeatures;\r\n\r\n        this._popup = window.open('', target, features);\r\n        if (this._popup) {\r\n            Log.debug(\"PopupWindow.ctor: popup successfully created\");\r\n            this._checkForPopupClosedTimer = window.setInterval(this._checkForPopupClosed.bind(this), CheckForPopupClosedInterval);\r\n        }\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!this._popup) {\r\n            this._error(\"PopupWindow.navigate: Error opening popup window\");\r\n        }\r\n        else if (!params || !params.url) {\r\n            this._error(\"PopupWindow.navigate: no url provided\");\r\n            this._error(\"No url provided\");\r\n        }\r\n        else {\r\n            Log.debug(\"PopupWindow.navigate: Setting URL in popup\");\r\n\r\n            this._id = params.id;\r\n            if (this._id) {\r\n                window[\"popupCallback_\" + params.id] = this._callback.bind(this);\r\n            }\r\n\r\n            this._popup.focus();\r\n            this._popup.window.location = params.url;\r\n        }\r\n\r\n        return this.promise;\r\n    }\r\n\r\n    _success(data) {\r\n        Log.debug(\"PopupWindow.callback: Successful response from popup window\");\r\n\r\n        this._cleanup();\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        Log.error(\"PopupWindow.error: \", message);\r\n        \r\n        this._cleanup();\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup(false);\r\n    }\r\n\r\n    _cleanup(keepOpen) {\r\n        Log.debug(\"PopupWindow.cleanup\");\r\n\r\n        window.clearInterval(this._checkForPopupClosedTimer);\r\n        this._checkForPopupClosedTimer = null;\r\n\r\n        delete window[\"popupCallback_\" + this._id];\r\n\r\n        if (this._popup && !keepOpen) {\r\n            this._popup.close();\r\n        }\r\n        this._popup = null;\r\n    }\r\n\r\n    _checkForPopupClosed() {\r\n        if (!this._popup || this._popup.closed) {\r\n            this._error(\"Popup window closed\");\r\n        }\r\n    }\r\n\r\n    _callback(url, keepOpen) {\r\n        this._cleanup(keepOpen);\r\n\r\n        if (url) {\r\n            Log.debug(\"PopupWindow.callback success\");\r\n            this._success({ url: url });\r\n        }\r\n        else {\r\n            Log.debug(\"PopupWindow.callback: Invalid response from popup\");\r\n            this._error(\"Invalid response from popup\");\r\n        }\r\n    }\r\n\r\n    static notifyOpener(url, keepOpen, delimiter) {\r\n        if (window.opener) {\r\n            url = url || window.location.href;\r\n            if (url) {\r\n                var data = UrlUtility.parseUrlFragment(url, delimiter);\r\n\r\n                if (data.state) {\r\n                    var name = \"popupCallback_\" + data.state;\r\n                    var callback = window.opener[name];\r\n                    if (callback) {\r\n                        Log.debug(\"PopupWindow.notifyOpener: passing url message to opener\");\r\n                        callback(url, keepOpen);\r\n                    }\r\n                    else {\r\n                        Log.warn(\"PopupWindow.notifyOpener: no matching callback found on opener\");\r\n                    }\r\n                }\r\n                else {\r\n                    Log.warn(\"PopupWindow.notifyOpener: no state found in response url\");\r\n                }\r\n            }\r\n        }\r\n        else {\r\n            Log.warn(\"PopupWindow.notifyOpener: no window.opener. Can't complete notification.\");\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class RedirectNavigator {\r\n\r\n    prepare() {\r\n        return Promise.resolve(this);\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            Log.error(\"RedirectNavigator.navigate: No url provided\");\r\n            return Promise.reject(new Error(\"No url provided\"));\r\n        }\r\n\r\n        if (params.useReplaceToNavigate) {\r\n            window.location.replace(params.url);\r\n        }\r\n        else {\r\n            window.location = params.url;\r\n        }\r\n\r\n        return Promise.resolve();\r\n    }\r\n\r\n    get url() {\r\n        return window.location.href;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { UserInfoService } from './UserInfoService.js';\r\nimport { TokenClient } from './TokenClient.js';\r\nimport { ErrorResponse } from './ErrorResponse.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\nconst ProtocolClaims = [\"nonce\", \"at_hash\", \"iat\", \"nbf\", \"exp\", \"aud\", \"iss\", \"c_hash\"];\r\n\r\nexport class ResponseValidator {\r\n\r\n    constructor(settings, \r\n        MetadataServiceCtor = MetadataService,\r\n        UserInfoServiceCtor = UserInfoService, \r\n        joseUtil = JoseUtil,\r\n        TokenClientCtor = TokenClient) {\r\n        if (!settings) {\r\n            Log.error(\"ResponseValidator.ctor: No settings passed to ResponseValidator\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n        this._userInfoService = new UserInfoServiceCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n        this._tokenClient = new TokenClientCtor(this._settings);\r\n    }\r\n\r\n    validateSigninResponse(state, response) {\r\n        Log.debug(\"ResponseValidator.validateSigninResponse\");\r\n\r\n        return this._processSigninParams(state, response).then(response => {\r\n            Log.debug(\"ResponseValidator.validateSigninResponse: state processed\");\r\n            return this._validateTokens(state, response).then(response => {\r\n                Log.debug(\"ResponseValidator.validateSigninResponse: tokens validated\");\r\n                return this._processClaims(state, response).then(response => {\r\n                    Log.debug(\"ResponseValidator.validateSigninResponse: claims processed\");\r\n                    return response;\r\n                });\r\n            });\r\n        });\r\n    }\r\n\r\n    validateSignoutResponse(state, response) {\r\n        if (state.id !== response.state) {\r\n            Log.error(\"ResponseValidator.validateSignoutResponse: State does not match\");\r\n            return Promise.reject(new Error(\"State does not match\"));\r\n        }\r\n\r\n        // now that we know the state matches, take the stored data\r\n        // and set it into the response so callers can get their state\r\n        // this is important for both success & error outcomes\r\n        Log.debug(\"ResponseValidator.validateSignoutResponse: state validated\");\r\n        response.state = state.data;\r\n\r\n        if (response.error) {\r\n            Log.warn(\"ResponseValidator.validateSignoutResponse: Response was error\", response.error);\r\n            return Promise.reject(new ErrorResponse(response));\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processSigninParams(state, response) {\r\n        if (state.id !== response.state) {\r\n            Log.error(\"ResponseValidator._processSigninParams: State does not match\");\r\n            return Promise.reject(new Error(\"State does not match\"));\r\n        }\r\n\r\n        if (!state.client_id) {\r\n            Log.error(\"ResponseValidator._processSigninParams: No client_id on state\");\r\n            return Promise.reject(new Error(\"No client_id on state\"));\r\n        }\r\n\r\n        if (!state.authority) {\r\n            Log.error(\"ResponseValidator._processSigninParams: No authority on state\");\r\n            return Promise.reject(new Error(\"No authority on state\"));\r\n        }\r\n\r\n        // this allows the authority to be loaded from the signin state\r\n        if (!this._settings.authority) {\r\n            this._settings.authority = state.authority;\r\n        }\r\n        // ensure we're using the correct authority if the authority is not loaded from signin state\r\n        else if (this._settings.authority && this._settings.authority !== state.authority) {\r\n            Log.error(\"ResponseValidator._processSigninParams: authority mismatch on settings vs. signin state\");\r\n            return Promise.reject(new Error(\"authority mismatch on settings vs. signin state\"));\r\n        }\r\n        // this allows the client_id to be loaded from the signin state\r\n        if (!this._settings.client_id) {\r\n            this._settings.client_id = state.client_id;\r\n        }\r\n        // ensure we're using the correct client_id if the client_id is not loaded from signin state\r\n        else if (this._settings.client_id && this._settings.client_id !== state.client_id) {\r\n            Log.error(\"ResponseValidator._processSigninParams: client_id mismatch on settings vs. signin state\");\r\n            return Promise.reject(new Error(\"client_id mismatch on settings vs. signin state\"));\r\n        }\r\n\r\n        // now that we know the state matches, take the stored data\r\n        // and set it into the response so callers can get their state\r\n        // this is important for both success & error outcomes\r\n        Log.debug(\"ResponseValidator._processSigninParams: state validated\");\r\n        response.state = state.data;\r\n\r\n        if (response.error) {\r\n            Log.warn(\"ResponseValidator._processSigninParams: Response was error\", response.error);\r\n            return Promise.reject(new ErrorResponse(response));\r\n        }\r\n\r\n        if (state.nonce && !response.id_token) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Expecting id_token in response\");\r\n            return Promise.reject(new Error(\"No id_token in response\"));\r\n        }\r\n\r\n        if (!state.nonce && response.id_token) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Not expecting id_token in response\");\r\n            return Promise.reject(new Error(\"Unexpected id_token in response\"));\r\n        }\r\n\r\n        if (state.code_verifier && !response.code) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Expecting code in response\");\r\n            return Promise.reject(new Error(\"No code in response\"));\r\n        }\r\n\r\n        if (!state.code_verifier && response.code) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Not expecting code in response\");\r\n            return Promise.reject(new Error(\"Unexpected code in response\"));\r\n        }\r\n\r\n        if (!response.scope) {\r\n            // if there's no scope on the response, then assume all scopes granted (per-spec) and copy over scopes from original request\r\n            response.scope = state.scope;\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processClaims(state, response) {\r\n        if (response.isOpenIdConnect) {\r\n            Log.debug(\"ResponseValidator._processClaims: response is OIDC, processing claims\");\r\n\r\n            response.profile = this._filterProtocolClaims(response.profile);\r\n\r\n            if (state.skipUserInfo !== true && this._settings.loadUserInfo && response.access_token) {\r\n                Log.debug(\"ResponseValidator._processClaims: loading user info\");\r\n\r\n                return this._userInfoService.getClaims(response.access_token).then(claims => {\r\n                    Log.debug(\"ResponseValidator._processClaims: user info claims received from user info endpoint\");\r\n\r\n                    if (claims.sub !== response.profile.sub) {\r\n                        Log.error(\"ResponseValidator._processClaims: sub from user info endpoint does not match sub in access_token\");\r\n                        return Promise.reject(new Error(\"sub from user info endpoint does not match sub in access_token\"));\r\n                    }\r\n\r\n                    response.profile = this._mergeClaims(response.profile, claims);\r\n                    Log.debug(\"ResponseValidator._processClaims: user info claims received, updated profile:\", response.profile);\r\n\r\n                    return response;\r\n                });\r\n            }\r\n            else {\r\n                Log.debug(\"ResponseValidator._processClaims: not loading user info\");\r\n            }\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._processClaims: response is not OIDC, not processing claims\");\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _mergeClaims(claims1, claims2) {\r\n        var result = Object.assign({}, claims1);\r\n\r\n        for (let name in claims2) {\r\n            var values = claims2[name];\r\n            if (!Array.isArray(values)) {\r\n                values = [values];\r\n            }\r\n\r\n            for (let i = 0; i < values.length; i++) {\r\n                let value = values[i];\r\n                if (!result[name]) {\r\n                    result[name] = value;\r\n                }\r\n                else if (Array.isArray(result[name])) {\r\n                    if (result[name].indexOf(value) < 0) {\r\n                        result[name].push(value);\r\n                    }\r\n                }\r\n                else if (result[name] !== value) {\r\n                    if (typeof value === 'object') {\r\n                        result[name] = this._mergeClaims(result[name], value);\r\n                    } \r\n                    else {\r\n                        result[name] = [result[name], value];\r\n                    }\r\n                }\r\n            }\r\n        }\r\n\r\n        return result;\r\n    }\r\n\r\n    _filterProtocolClaims(claims) {\r\n        Log.debug(\"ResponseValidator._filterProtocolClaims, incoming claims:\", claims);\r\n\r\n        var result = Object.assign({}, claims);\r\n\r\n        if (this._settings._filterProtocolClaims) {\r\n            ProtocolClaims.forEach(type => {\r\n                delete result[type];\r\n            });\r\n\r\n            Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims filtered\", result);\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims not filtered\")\r\n        }\r\n\r\n        return result;\r\n    }\r\n\r\n    _validateTokens(state, response) {\r\n        if (response.code) {\r\n            Log.debug(\"ResponseValidator._validateTokens: Validating code\");\r\n            return this._processCode(state, response);\r\n        }\r\n\r\n        if (response.id_token) {\r\n            if (response.access_token) {\r\n                Log.debug(\"ResponseValidator._validateTokens: Validating id_token and access_token\");\r\n                return this._validateIdTokenAndAccessToken(state, response);\r\n            }\r\n\r\n            Log.debug(\"ResponseValidator._validateTokens: Validating id_token\");\r\n            return this._validateIdToken(state, response);\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._validateTokens: No code to process or id_token to validate\");\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processCode(state, response) {\r\n        var request = {\r\n            client_id: state.client_id,\r\n            client_secret: state.client_secret,\r\n            code : response.code,\r\n            redirect_uri: state.redirect_uri,\r\n            code_verifier: state.code_verifier\r\n        };\r\n\r\n        if (state.extraTokenParams && typeof(state.extraTokenParams) === 'object') {\r\n            Object.assign(request, state.extraTokenParams);\r\n        }\r\n        \r\n        return this._tokenClient.exchangeCode(request).then(tokenResponse => {\r\n            \r\n            for(var key in tokenResponse) {\r\n                response[key] = tokenResponse[key];\r\n            }\r\n\r\n            if (response.id_token) {\r\n                Log.debug(\"ResponseValidator._processCode: token response successful, processing id_token\");\r\n                return this._validateIdTokenAttributes(state, response);\r\n            }\r\n            else {\r\n                Log.debug(\"ResponseValidator._processCode: token response successful, returning response\");\r\n            }\r\n            \r\n            return response;\r\n        });\r\n    }\r\n\r\n    _validateIdTokenAttributes(state, response) {\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n\r\n            let audience = state.client_id;\r\n            let clockSkewInSeconds = this._settings.clockSkew;\r\n            Log.debug(\"ResponseValidator._validateIdTokenAttributes: Validaing JWT attributes; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n            return this._joseUtil.validateJwtAttributes(response.id_token, issuer, audience, clockSkewInSeconds).then(payload => {\r\n            \r\n                if (state.nonce && state.nonce !== payload.nonce) {\r\n                    Log.error(\"ResponseValidator._validateIdTokenAttributes: Invalid nonce in id_token\");\r\n                    return Promise.reject(new Error(\"Invalid nonce in id_token\"));\r\n                }\r\n\r\n                if (!payload.sub) {\r\n                    Log.error(\"ResponseValidator._validateIdTokenAttributes: No sub present in id_token\");\r\n                    return Promise.reject(new Error(\"No sub present in id_token\"));\r\n                }\r\n\r\n                response.profile = payload;\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n\r\n    _validateIdTokenAndAccessToken(state, response) {\r\n        return this._validateIdToken(state, response).then(response => {\r\n            return this._validateAccessToken(response);\r\n        });\r\n    }\r\n\r\n    _validateIdToken(state, response) {\r\n        if (!state.nonce) {\r\n            Log.error(\"ResponseValidator._validateIdToken: No nonce on state\");\r\n            return Promise.reject(new Error(\"No nonce on state\"));\r\n        }\r\n\r\n        let jwt = this._joseUtil.parseJwt(response.id_token);\r\n        if (!jwt || !jwt.header || !jwt.payload) {\r\n            Log.error(\"ResponseValidator._validateIdToken: Failed to parse id_token\", jwt);\r\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n        }\r\n\r\n        if (state.nonce !== jwt.payload.nonce) {\r\n            Log.error(\"ResponseValidator._validateIdToken: Invalid nonce in id_token\");\r\n            return Promise.reject(new Error(\"Invalid nonce in id_token\"));\r\n        }\r\n\r\n        var kid = jwt.header.kid;\r\n\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n            Log.debug(\"ResponseValidator._validateIdToken: Received issuer\");\r\n\r\n            return this._metadataService.getSigningKeys().then(keys => {\r\n                if (!keys) {\r\n                    Log.error(\"ResponseValidator._validateIdToken: No signing keys from metadata\");\r\n                    return Promise.reject(new Error(\"No signing keys from metadata\"));\r\n                }\r\n\r\n                Log.debug(\"ResponseValidator._validateIdToken: Received signing keys\");\r\n                let key;\r\n                if (!kid) {\r\n                    keys = this._filterByAlg(keys, jwt.header.alg);\r\n\r\n                    if (keys.length > 1) {\r\n                        Log.error(\"ResponseValidator._validateIdToken: No kid found in id_token and more than one key found in metadata\");\r\n                        return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\r\n                    }\r\n                    else {\r\n                        // kid is mandatory only when there are multiple keys in the referenced JWK Set document\r\n                        // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\r\n                        key = keys[0];\r\n                    }\r\n                }\r\n                else {\r\n                    key = keys.filter(key => {\r\n                        return key.kid === kid;\r\n                    })[0];\r\n                }\r\n\r\n                if (!key) {\r\n                    Log.error(\"ResponseValidator._validateIdToken: No key matching kid or alg found in signing keys\");\r\n                    return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\r\n                }\r\n\r\n                let audience = state.client_id;\r\n\r\n                let clockSkewInSeconds = this._settings.clockSkew;\r\n                Log.debug(\"ResponseValidator._validateIdToken: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n                return this._joseUtil.validateJwt(response.id_token, key, issuer, audience, clockSkewInSeconds).then(()=>{\r\n                    Log.debug(\"ResponseValidator._validateIdToken: JWT validation successful\");\r\n\r\n                    if (!jwt.payload.sub) {\r\n                        Log.error(\"ResponseValidator._validateIdToken: No sub present in id_token\");\r\n                        return Promise.reject(new Error(\"No sub present in id_token\"));\r\n                    }\r\n\r\n                    response.profile = jwt.payload;\r\n\r\n                    return response;\r\n                });\r\n            });\r\n        });\r\n    }\r\n\r\n    _filterByAlg(keys, alg){\r\n        var kty = null;\r\n        if (alg.startsWith(\"RS\")) {\r\n            kty = \"RSA\";\r\n        }\r\n        else if (alg.startsWith(\"PS\")) {\r\n            kty = \"PS\";\r\n        }\r\n        else if (alg.startsWith(\"ES\")) {\r\n            kty = \"EC\";\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._filterByAlg: alg not supported: \", alg);\r\n            return [];\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._filterByAlg: Looking for keys that match kty: \", kty);\r\n\r\n        keys = keys.filter(key => {\r\n            return key.kty === kty;\r\n        });\r\n\r\n        Log.debug(\"ResponseValidator._filterByAlg: Number of keys that match kty: \", kty, keys.length);\r\n\r\n        return keys;\r\n    }\r\n\r\n    _validateAccessToken(response) {\r\n        if (!response.profile) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No profile loaded from id_token\");\r\n            return Promise.reject(new Error(\"No profile loaded from id_token\"));\r\n        }\r\n\r\n        if (!response.profile.at_hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No at_hash in id_token\");\r\n            return Promise.reject(new Error(\"No at_hash in id_token\"));\r\n        }\r\n\r\n        if (!response.id_token) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No id_token\");\r\n            return Promise.reject(new Error(\"No id_token\"));\r\n        }\r\n\r\n        let jwt = this._joseUtil.parseJwt(response.id_token);\r\n        if (!jwt || !jwt.header) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Failed to parse id_token\", jwt);\r\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n        }\r\n\r\n        var hashAlg = jwt.header.alg;\r\n        if (!hashAlg || hashAlg.length !== 5) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        var hashBits = hashAlg.substr(2, 3);\r\n        if (!hashBits) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        hashBits = parseInt(hashBits);\r\n        if (hashBits !== 256 && hashBits !== 384 && hashBits !== 512) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        let sha = \"sha\" + hashBits;\r\n        var hash = this._joseUtil.hashString(response.access_token, sha);\r\n        if (!hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: access_token hash failed:\", sha);\r\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\r\n        }\r\n\r\n        var left = hash.substr(0, hash.length / 2);\r\n        var left_b64u = this._joseUtil.hexToBase64Url(left);\r\n        if (left_b64u !== response.profile.at_hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Failed to validate at_hash\", left_b64u, response.profile.at_hash);\r\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._validateAccessToken: success\");\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { CheckSessionIFrame } from './CheckSessionIFrame.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class SessionMonitor {\r\n\r\n    constructor(userManager, CheckSessionIFrameCtor = CheckSessionIFrame, timer = Global.timer) {\r\n        if (!userManager) {\r\n            Log.error(\"SessionMonitor.ctor: No user manager passed to SessionMonitor\");\r\n            throw new Error(\"userManager\");\r\n        }\r\n\r\n        this._userManager = userManager;\r\n        this._CheckSessionIFrameCtor = CheckSessionIFrameCtor;\r\n        this._timer = timer;\r\n\r\n        this._userManager.events.addUserLoaded(this._start.bind(this));\r\n        this._userManager.events.addUserUnloaded(this._stop.bind(this));\r\n\r\n        this._userManager.getUser().then(user => {\r\n            // doing this manually here since calling getUser \r\n            // doesn't trigger load event.\r\n            if (user) {\r\n                this._start(user);\r\n            }\r\n            else if (this._settings.monitorAnonymousSession) {\r\n                this._userManager.querySessionStatus().then(session => {\r\n                    let tmpUser = {\r\n                        session_state : session.session_state\r\n                    };\r\n                    if (session.sub && session.sid) {\r\n                        tmpUser.profile = {\r\n                            sub: session.sub,\r\n                            sid: session.sid\r\n                        };\r\n                    }\r\n                    this._start(tmpUser);\r\n                })\r\n                .catch(err => {\r\n                    // catch to suppress errors since we're in a ctor\r\n                    Log.error(\"SessionMonitor ctor: error from querySessionStatus:\", err.message);\r\n                });\r\n            }\r\n        }).catch(err => {\r\n            // catch to suppress errors since we're in a ctor\r\n            Log.error(\"SessionMonitor ctor: error from getUser:\", err.message);\r\n        });\r\n    }\r\n\r\n    get _settings() {\r\n        return this._userManager.settings;\r\n    }\r\n    get _metadataService() {\r\n        return this._userManager.metadataService;\r\n    }\r\n    get _client_id() {\r\n        return this._settings.client_id;\r\n    }\r\n    get _checkSessionInterval() {\r\n        return this._settings.checkSessionInterval;\r\n    }\r\n    get _stopCheckSessionOnError() {\r\n        return this._settings.stopCheckSessionOnError;\r\n    }\r\n\r\n    _start(user) {\r\n        let session_state = user.session_state;\r\n\r\n        if (session_state) {\r\n            if (user.profile) {\r\n                this._sub = user.profile.sub;\r\n                this._sid = user.profile.sid;\r\n                Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", sub:\", this._sub);\r\n            }\r\n            else {\r\n                this._sub = undefined;\r\n                this._sid = undefined;\r\n                Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", anonymous user\");\r\n            }\r\n\r\n            if (!this._checkSessionIFrame) {\r\n                this._metadataService.getCheckSessionIframe().then(url => {\r\n                    if (url) {\r\n                        Log.debug(\"SessionMonitor._start: Initializing check session iframe\")\r\n\r\n                        let client_id = this._client_id;\r\n                        let interval = this._checkSessionInterval;\r\n                        let stopOnError = this._stopCheckSessionOnError;\r\n\r\n                        this._checkSessionIFrame = new this._CheckSessionIFrameCtor(this._callback.bind(this), client_id, url, interval, stopOnError);\r\n                        this._checkSessionIFrame.load().then(() => {\r\n                            this._checkSessionIFrame.start(session_state);\r\n                        });\r\n                    }\r\n                    else {\r\n                        Log.warn(\"SessionMonitor._start: No check session iframe found in the metadata\");\r\n                    }\r\n                }).catch(err => {\r\n                    // catch to suppress errors since we're in non-promise callback\r\n                    Log.error(\"SessionMonitor._start: Error from getCheckSessionIframe:\", err.message);\r\n                });\r\n            }\r\n            else {\r\n                this._checkSessionIFrame.start(session_state);\r\n            }\r\n        }\r\n    }\r\n\r\n    _stop() {\r\n        this._sub = undefined;\r\n        this._sid = undefined;\r\n\r\n        if (this._checkSessionIFrame) {\r\n            Log.debug(\"SessionMonitor._stop\");\r\n            this._checkSessionIFrame.stop();\r\n        }\r\n\r\n        if (this._settings.monitorAnonymousSession) {\r\n            // using a timer to delay re-initialization to avoid race conditions during signout\r\n            let timerHandle = this._timer.setInterval(()=>{\r\n                this._timer.clearInterval(timerHandle);\r\n\r\n                this._userManager.querySessionStatus().then(session => {\r\n                    let tmpUser = {\r\n                        session_state : session.session_state\r\n                    };\r\n                    if (session.sub && session.sid) {\r\n                        tmpUser.profile = {\r\n                            sub: session.sub,\r\n                            sid: session.sid\r\n                        };\r\n                    }\r\n                    this._start(tmpUser);\r\n                })\r\n                .catch(err => {\r\n                    // catch to suppress errors since we're in a callback\r\n                    Log.error(\"SessionMonitor: error from querySessionStatus:\", err.message);\r\n                });\r\n\r\n            }, 1000);\r\n        }\r\n    }\r\n\r\n    _callback() {\r\n        this._userManager.querySessionStatus().then(session => {\r\n            var raiseEvent = true;\r\n\r\n            if (session) {\r\n                if (session.sub === this._sub) {\r\n                    raiseEvent = false;\r\n                    this._checkSessionIFrame.start(session.session_state);\r\n\r\n                    if (session.sid === this._sid) {\r\n                        Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, restarting check session iframe; session_state:\", session.session_state);\r\n                    }\r\n                    else {\r\n                        Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, session state has changed, restarting check session iframe; session_state:\", session.session_state);\r\n                        this._userManager.events._raiseUserSessionChanged();\r\n                    }\r\n                }\r\n                else {\r\n                    Log.debug(\"SessionMonitor._callback: Different subject signed into OP:\", session.sub);\r\n                }\r\n            }\r\n            else {\r\n                Log.debug(\"SessionMonitor._callback: Subject no longer signed into OP\");\r\n            }\r\n\r\n            if (raiseEvent) {\r\n                if (this._sub) {\r\n                    Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed out event\");\r\n                    this._userManager.events._raiseUserSignedOut();\r\n                }\r\n                else {\r\n                    Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed in event\");\r\n                    this._userManager.events._raiseUserSignedIn();\r\n                }\r\n            }\r\n        }).catch(err => {\r\n            if (this._sub) {\r\n                Log.debug(\"SessionMonitor._callback: Error calling queryCurrentSigninSession; raising signed out event\", err.message);\r\n                this._userManager.events._raiseUserSignedOut();\r\n            }\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\nimport { SigninState } from './SigninState.js';\r\n\r\nexport class SigninRequest {\r\n    constructor({\r\n        // mandatory\r\n        url, client_id, redirect_uri, response_type, scope, authority,\r\n        // optional\r\n        data, prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values, resource, response_mode,\r\n        request, request_uri, extraQueryParams, request_type, client_secret, extraTokenParams, skipUserInfo\r\n    }) {\r\n        if (!url) {\r\n            Log.error(\"SigninRequest.ctor: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n        if (!client_id) {\r\n            Log.error(\"SigninRequest.ctor: No client_id passed\");\r\n            throw new Error(\"client_id\");\r\n        }\r\n        if (!redirect_uri) {\r\n            Log.error(\"SigninRequest.ctor: No redirect_uri passed\");\r\n            throw new Error(\"redirect_uri\");\r\n        }\r\n        if (!response_type) {\r\n            Log.error(\"SigninRequest.ctor: No response_type passed\");\r\n            throw new Error(\"response_type\");\r\n        }\r\n        if (!scope) {\r\n            Log.error(\"SigninRequest.ctor: No scope passed\");\r\n            throw new Error(\"scope\");\r\n        }\r\n        if (!authority) {\r\n            Log.error(\"SigninRequest.ctor: No authority passed\");\r\n            throw new Error(\"authority\");\r\n        }\r\n\r\n        let oidc = SigninRequest.isOidc(response_type);\r\n        let code = SigninRequest.isCode(response_type);\r\n\r\n        if (!response_mode) {\r\n            response_mode = SigninRequest.isCode(response_type) ? \"query\" : null;\r\n        }\r\n\r\n        this.state = new SigninState({ nonce: oidc, \r\n            data, client_id, authority, redirect_uri, \r\n            code_verifier: code, \r\n            request_type, response_mode,\r\n            client_secret, scope, extraTokenParams, skipUserInfo });\r\n\r\n        url = UrlUtility.addQueryParam(url, \"client_id\", client_id);\r\n        url = UrlUtility.addQueryParam(url, \"redirect_uri\", redirect_uri);\r\n        url = UrlUtility.addQueryParam(url, \"response_type\", response_type);\r\n        url = UrlUtility.addQueryParam(url, \"scope\", scope);\r\n\r\n        url = UrlUtility.addQueryParam(url, \"state\", this.state.id);\r\n        if (oidc) {\r\n            url = UrlUtility.addQueryParam(url, \"nonce\", this.state.nonce);\r\n        }\r\n        if (code) {\r\n            url = UrlUtility.addQueryParam(url, \"code_challenge\", this.state.code_challenge);\r\n            url = UrlUtility.addQueryParam(url, \"code_challenge_method\", \"S256\");\r\n        }\r\n\r\n        var optional = { prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values, resource, request, request_uri, response_mode };\r\n        for(let key in optional){\r\n            if (optional[key]) {\r\n                url = UrlUtility.addQueryParam(url, key, optional[key]);\r\n            }\r\n        }\r\n\r\n        for(let key in extraQueryParams){\r\n            url = UrlUtility.addQueryParam(url, key, extraQueryParams[key])\r\n        }\r\n\r\n        this.url = url;\r\n    }\r\n\r\n    static isOidc(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"id_token\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n\r\n    static isOAuth(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"token\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n    \r\n    static isCode(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"code\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nconst OidcScope = \"openid\";\r\n\r\nexport class SigninResponse {\r\n    constructor(url, delimiter = \"#\") {\r\n\r\n        var values = UrlUtility.parseUrlFragment(url, delimiter);\r\n\r\n        this.error = values.error;\r\n        this.error_description = values.error_description;\r\n        this.error_uri = values.error_uri;\r\n\r\n        this.code = values.code;\r\n        this.state = values.state;\r\n        this.id_token = values.id_token;\r\n        this.session_state = values.session_state;\r\n        this.access_token = values.access_token;\r\n        this.token_type = values.token_type;\r\n        this.scope = values.scope;\r\n        this.profile = undefined; // will be set from ResponseValidator\r\n\r\n        this.expires_in = values.expires_in;\r\n    }\r\n\r\n    get expires_in() {\r\n        if (this.expires_at) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            return this.expires_at - now;\r\n        }\r\n        return undefined;\r\n    }\r\n    set expires_in(value){\r\n        let expires_in = parseInt(value);\r\n        if (typeof expires_in === 'number' && expires_in > 0) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            this.expires_at = now + expires_in;\r\n        }\r\n    }\r\n\r\n    get expired() {\r\n        let expires_in = this.expires_in;\r\n        if (expires_in !== undefined) {\r\n            return expires_in <= 0;\r\n        }\r\n        return undefined;\r\n    }\r\n\r\n    get scopes() {\r\n        return (this.scope || \"\").split(\" \");\r\n    }\r\n\r\n    get isOpenIdConnect() {\r\n        return this.scopes.indexOf(OidcScope) >= 0 || !!this.id_token;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { State } from './State.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\nimport random from './random.js';\r\n\r\nexport class SigninState extends State {\r\n    constructor({nonce, authority, client_id, redirect_uri, code_verifier, response_mode, client_secret, scope, extraTokenParams, skipUserInfo} = {}) {\r\n        super(arguments[0]);\r\n\r\n        if (nonce === true) {\r\n            this._nonce = random();\r\n        }\r\n        else if (nonce) {\r\n            this._nonce = nonce;\r\n        }\r\n\r\n        if (code_verifier === true) {\r\n            // random() produces 32 length\r\n            this._code_verifier = random() + random() + random();\r\n        }\r\n        else if (code_verifier) {\r\n            this._code_verifier = code_verifier;\r\n        }\r\n        \r\n        if (this.code_verifier) {\r\n            let hash = JoseUtil.hashString(this.code_verifier, \"SHA256\");\r\n            this._code_challenge = JoseUtil.hexToBase64Url(hash);\r\n        }\r\n\r\n        this._redirect_uri = redirect_uri;\r\n        this._authority = authority;\r\n        this._client_id = client_id;\r\n        this._response_mode = response_mode;\r\n        this._client_secret = client_secret;\r\n        this._scope = scope;\r\n        this._extraTokenParams = extraTokenParams;\r\n        this._skipUserInfo = skipUserInfo;\r\n    }\r\n\r\n    get nonce() {\r\n        return this._nonce;\r\n    }\r\n    get authority() {\r\n        return this._authority;\r\n    }\r\n    get client_id() {\r\n        return this._client_id;\r\n    }\r\n    get redirect_uri() {\r\n        return this._redirect_uri;\r\n    }\r\n    get code_verifier() {\r\n        return this._code_verifier;\r\n    }\r\n    get code_challenge() {\r\n        return this._code_challenge;\r\n    }\r\n    get response_mode() {\r\n        return this._response_mode;\r\n    }\r\n    get client_secret() {\r\n        return this._client_secret;\r\n    }\r\n    get scope() {\r\n        return this._scope;\r\n    }\r\n    get extraTokenParams() {\r\n        return this._extraTokenParams;\r\n    }\r\n    get skipUserInfo() {\r\n        return this._skipUserInfo;\r\n    }\r\n    \r\n    toStorageString() {\r\n        Log.debug(\"SigninState.toStorageString\");\r\n        return JSON.stringify({\r\n            id: this.id,\r\n            data: this.data,\r\n            created: this.created,\r\n            request_type: this.request_type,\r\n            nonce: this.nonce,\r\n            code_verifier: this.code_verifier,\r\n            redirect_uri: this.redirect_uri,\r\n            authority: this.authority,\r\n            client_id: this.client_id,\r\n            response_mode: this.response_mode,\r\n            client_secret: this.client_secret,\r\n            scope: this.scope,\r\n            extraTokenParams : this.extraTokenParams,\r\n            skipUserInfo: this.skipUserInfo\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"SigninState.fromStorageString\");\r\n        var data = JSON.parse(storageString);\r\n        return new SigninState(data);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\nimport { State } from './State.js';\r\n\r\nexport class SignoutRequest {\r\n    constructor({url, id_token_hint, post_logout_redirect_uri, data, extraQueryParams, request_type}) {\r\n        if (!url) {\r\n            Log.error(\"SignoutRequest.ctor: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        if (id_token_hint) {\r\n            url = UrlUtility.addQueryParam(url, \"id_token_hint\", id_token_hint);\r\n        }\r\n\r\n        if (post_logout_redirect_uri) {\r\n            url = UrlUtility.addQueryParam(url, \"post_logout_redirect_uri\", post_logout_redirect_uri);\r\n\r\n            if (data) {\r\n                this.state = new State({ data, request_type });\r\n\r\n                url = UrlUtility.addQueryParam(url, \"state\", this.state.id);\r\n            }\r\n        }\r\n\r\n        for(let key in extraQueryParams){\r\n            url = UrlUtility.addQueryParam(url, key, extraQueryParams[key])\r\n        }\r\n\r\n        this.url = url;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nexport class SignoutResponse {\r\n    constructor(url) {\r\n\r\n        var values = UrlUtility.parseUrlFragment(url, \"?\");\r\n\r\n        this.error = values.error;\r\n        this.error_description = values.error_description;\r\n        this.error_uri = values.error_uri;\r\n\r\n        this.state = values.state;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class SilentRenewService {\r\n\r\n    constructor(userManager) {\r\n        this._userManager = userManager;\r\n    }\r\n\r\n    start() {\r\n        if (!this._callback) {\r\n            this._callback = this._tokenExpiring.bind(this);\r\n            this._userManager.events.addAccessTokenExpiring(this._callback);\r\n\r\n            // this will trigger loading of the user so the expiring events can be initialized\r\n            this._userManager.getUser().then(user=>{\r\n                // deliberate nop\r\n            }).catch(err=>{\r\n                // catch to suppress errors since we're in a ctor\r\n                Log.error(\"SilentRenewService.start: Error from getUser:\", err.message);\r\n            });\r\n        }\r\n    }\r\n\r\n    stop() {\r\n        if (this._callback) {\r\n            this._userManager.events.removeAccessTokenExpiring(this._callback);\r\n            delete this._callback;\r\n        }\r\n    }\r\n\r\n    _tokenExpiring() {\r\n        this._userManager.signinSilent().then(user => {\r\n            Log.debug(\"SilentRenewService._tokenExpiring: Silent token renewal successful\");\r\n        }, err => {\r\n            Log.error(\"SilentRenewService._tokenExpiring: Error from signinSilent:\", err.message);\r\n            this._userManager.events._raiseSilentRenewError(err);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport random from './random.js';\r\n\r\nexport class State {\r\n    constructor({id, data, created, request_type} = {}) {\r\n        this._id = id || random();\r\n        this._data = data;\r\n\r\n        if (typeof created === 'number' && created > 0) {\r\n            this._created = created;\r\n        }\r\n        else {\r\n            this._created = parseInt(Date.now() / 1000);\r\n        }\r\n        this._request_type =  request_type;\r\n    }\r\n\r\n    get id() {\r\n        return this._id;\r\n    }\r\n    get data() {\r\n        return this._data;\r\n    }\r\n    get created() {\r\n        return this._created;\r\n    }\r\n    get request_type() {\r\n        return this._request_type;\r\n    }\r\n\r\n    toStorageString() {\r\n        Log.debug(\"State.toStorageString\");\r\n        return JSON.stringify({\r\n            id: this.id,\r\n            data: this.data,\r\n            created: this.created,\r\n            request_type: this.request_type\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"State.fromStorageString\");\r\n        return new State(JSON.parse(storageString));\r\n    }\r\n\r\n    static clearStaleState(storage, age) {\r\n\r\n        var cutoff = Date.now() / 1000 - age;\r\n\r\n        return storage.getAllKeys().then(keys => {\r\n            Log.debug(\"State.clearStaleState: got keys\", keys);\r\n\r\n            var promises = [];\r\n            for (let i = 0; i < keys.length; i++) {\r\n                let key = keys[i];\r\n                var p = storage.get(key).then(item => {\r\n                    let remove = false;\r\n\r\n                    if (item) {\r\n                        try {\r\n                            var state = State.fromStorageString(item)\r\n\r\n                            Log.debug(\"State.clearStaleState: got item from key: \", key, state.created);\r\n\r\n                            if (state.created <= cutoff) {\r\n                                remove = true;\r\n                            }\r\n                        }\r\n                        catch (e) {\r\n                            Log.error(\"State.clearStaleState: Error parsing state for key\", key, e.message);\r\n                            remove = true;\r\n                        }\r\n                    }\r\n                    else {\r\n                        Log.debug(\"State.clearStaleState: no item in storage for key: \", key);\r\n                        remove = true;\r\n                    }\r\n\r\n                    if (remove) {\r\n                        Log.debug(\"State.clearStaleState: removed item for key: \", key);\r\n                        return storage.remove(key);\r\n                    }\r\n                });\r\n\r\n                promises.push(p);\r\n            }\r\n\r\n            Log.debug(\"State.clearStaleState: waiting on promise count:\", promises.length);\r\n            return Promise.all(promises);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\nimport { Event } from './Event.js';\r\n\r\nconst TimerDuration = 5; // seconds\r\n\r\nexport class Timer extends Event {\r\n\r\n    constructor(name, timer = Global.timer, nowFunc = undefined) {\r\n        super(name);\r\n        this._timer = timer;\r\n\r\n        if (nowFunc) {\r\n            this._nowFunc = nowFunc;\r\n        }\r\n        else {\r\n            this._nowFunc = () => Date.now() / 1000;\r\n        }\r\n    }\r\n\r\n    get now() {\r\n        return parseInt(this._nowFunc());\r\n    }\r\n\r\n    init(duration) {\r\n        if (duration <= 0) {\r\n            duration = 1;\r\n        }\r\n        duration = parseInt(duration);\r\n\r\n        var expiration = this.now + duration;\r\n        if (this.expiration === expiration && this._timerHandle) {\r\n            // no need to reinitialize to same expiration, so bail out\r\n            Log.debug(\"Timer.init timer \" + this._name + \" skipping initialization since already initialized for expiration:\", this.expiration);\r\n            return;\r\n        }\r\n\r\n        this.cancel();\r\n\r\n        Log.debug(\"Timer.init timer \" + this._name + \" for duration:\", duration);\r\n        this._expiration = expiration;\r\n\r\n        // we're using a fairly short timer and then checking the expiration in the\r\n        // callback to handle scenarios where the browser device sleeps, and then\r\n        // the timers end up getting delayed.\r\n        var timerDuration = TimerDuration;\r\n        if (duration < timerDuration) {\r\n            timerDuration = duration;\r\n        }\r\n        this._timerHandle = this._timer.setInterval(this._callback.bind(this), timerDuration * 1000);\r\n    }\r\n    \r\n    get expiration() {\r\n        return this._expiration;\r\n    }\r\n\r\n    cancel() {\r\n        if (this._timerHandle) {\r\n            Log.debug(\"Timer.cancel: \", this._name);\r\n            this._timer.clearInterval(this._timerHandle);\r\n            this._timerHandle = null;\r\n        }\r\n    }\r\n\r\n    _callback() {\r\n        var diff = this._expiration - this.now;\r\n        Log.debug(\"Timer.callback; \" + this._name + \" timer expires in:\", diff);\r\n\r\n        if (this._expiration <= this.now) {\r\n            this.cancel();\r\n            super.raise();\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { JsonService } from './JsonService.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Log } from './Log.js';\r\n\r\nexport class TokenClient {\r\n    constructor(settings, JsonServiceCtor = JsonService, MetadataServiceCtor = MetadataService) {\r\n        if (!settings) {\r\n            Log.error(\"TokenClient.ctor: No settings passed\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor();\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n    }\r\n\r\n    exchangeCode(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.grant_type = args.grant_type || \"authorization_code\";\r\n        args.client_id = args.client_id || this._settings.client_id;\r\n        args.redirect_uri = args.redirect_uri || this._settings.redirect_uri;\r\n\r\n        if (!args.code) {\r\n            Log.error(\"TokenClient.exchangeCode: No code passed\");\r\n            return Promise.reject(new Error(\"A code is required\"));\r\n        }\r\n        if (!args.redirect_uri) {\r\n            Log.error(\"TokenClient.exchangeCode: No redirect_uri passed\");\r\n            return Promise.reject(new Error(\"A redirect_uri is required\"));\r\n        }\r\n        if (!args.code_verifier) {\r\n            Log.error(\"TokenClient.exchangeCode: No code_verifier passed\");\r\n            return Promise.reject(new Error(\"A code_verifier is required\"));\r\n        }\r\n        if (!args.client_id) {\r\n            Log.error(\"TokenClient.exchangeCode: No client_id passed\");\r\n            return Promise.reject(new Error(\"A client_id is required\"));\r\n        }\r\n\r\n        return this._metadataService.getTokenEndpoint(false).then(url => {\r\n            Log.debug(\"TokenClient.exchangeCode: Received token endpoint\");\r\n\r\n            return this._jsonService.postForm(url, args).then(response => {\r\n                Log.debug(\"TokenClient.exchangeCode: response received\");\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n\r\n    exchangeRefreshToken(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.grant_type = args.grant_type || \"refresh_token\";\r\n        args.client_id = args.client_id || this._settings.client_id;\r\n        args.client_secret = args.client_secret || this._settings.client_secret;\r\n\r\n        if (!args.refresh_token) {\r\n            Log.error(\"TokenClient.exchangeRefreshToken: No refresh_token passed\");\r\n            return Promise.reject(new Error(\"A refresh_token is required\"));\r\n        }\r\n        if (!args.client_id) {\r\n            Log.error(\"TokenClient.exchangeRefreshToken: No client_id passed\");\r\n            return Promise.reject(new Error(\"A client_id is required\"));\r\n        }\r\n\r\n        return this._metadataService.getTokenEndpoint(false).then(url => {\r\n            Log.debug(\"TokenClient.exchangeRefreshToken: Received token endpoint\");\r\n\r\n            return this._jsonService.postForm(url, args).then(response => {\r\n                Log.debug(\"TokenClient.exchangeRefreshToken: response received\");\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Global } from './Global.js';\r\n\r\nconst AccessTokenTypeHint = \"access_token\";\r\nconst RefreshTokenTypeHint = \"refresh_token\";\r\n\r\nexport class TokenRevocationClient {\r\n    constructor(settings, XMLHttpRequestCtor = Global.XMLHttpRequest, MetadataServiceCtor = MetadataService) {\r\n        if (!settings) {\r\n            Log.error(\"TokenRevocationClient.ctor: No settings provided\");\r\n            throw new Error(\"No settings provided.\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._XMLHttpRequestCtor = XMLHttpRequestCtor;\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n    }\r\n\r\n    revoke(token, required, type = \"access_token\") {\r\n        if (!token) {\r\n            Log.error(\"TokenRevocationClient.revoke: No token provided\");\r\n            throw new Error(\"No token provided.\");\r\n        }\r\n\r\n        if (type !== AccessTokenTypeHint && type != RefreshTokenTypeHint) {\r\n            Log.error(\"TokenRevocationClient.revoke: Invalid token type\");\r\n            throw new Error(\"Invalid token type.\");\r\n        }\r\n\r\n        return this._metadataService.getRevocationEndpoint().then(url => {\r\n            if (!url) {\r\n                if (required) {\r\n                    Log.error(\"TokenRevocationClient.revoke: Revocation not supported\");\r\n                    throw new Error(\"Revocation not supported\");\r\n                }\r\n\r\n                // not required, so don't error and just return\r\n                return;\r\n            }\r\n\r\n            Log.debug(\"TokenRevocationClient.revoke: Revoking \" + type);\r\n            var client_id = this._settings.client_id;\r\n            var client_secret = this._settings.client_secret;\r\n            return this._revoke(url, client_id, client_secret, token, type);\r\n        });\r\n    }\r\n\r\n    _revoke(url, client_id, client_secret, token, type) {\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var xhr = new this._XMLHttpRequestCtor();\r\n            xhr.open(\"POST\", url);\r\n\r\n            xhr.onload = () => {\r\n                Log.debug(\"TokenRevocationClient.revoke: HTTP response received, status\", xhr.status);\r\n\r\n                if (xhr.status === 200) {\r\n                    resolve();\r\n                }\r\n                else {\r\n                    reject(Error(xhr.statusText + \" (\" + xhr.status + \")\"));\r\n                }\r\n            };\r\n            xhr.onerror = () => { \r\n                Log.debug(\"TokenRevocationClient.revoke: Network Error.\")\r\n                reject(\"Network Error\");\r\n            };\r\n\r\n            var body = \"client_id=\" + encodeURIComponent(client_id);\r\n            if (client_secret) {\r\n                body += \"&client_secret=\" + encodeURIComponent(client_secret);\r\n            }\r\n            body += \"&token_type_hint=\" + encodeURIComponent(type);\r\n            body += \"&token=\" + encodeURIComponent(token);\r\n\r\n            xhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\r\n            xhr.send(body);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class UrlUtility {\r\n    static addQueryParam(url, name, value) {\r\n        if (url.indexOf('?') < 0) {\r\n            url += \"?\";\r\n        }\r\n\r\n        if (url[url.length - 1] !== \"?\") {\r\n            url += \"&\";\r\n        }\r\n\r\n        url += encodeURIComponent(name);\r\n        url += \"=\";\r\n        url += encodeURIComponent(value);\r\n\r\n        return url;\r\n    }\r\n\r\n    static parseUrlFragment(value, delimiter = \"#\", global = Global) {\r\n        if (typeof value !== 'string'){\r\n            value = global.location.href;\r\n        }\r\n\r\n        var idx = value.lastIndexOf(delimiter);\r\n        if (idx >= 0) {\r\n            value = value.substr(idx + 1);\r\n        }\r\n\r\n        if (delimiter === \"?\") {\r\n            // if we're doing query, then strip off hash fragment before we parse\r\n            idx = value.indexOf('#');\r\n            if (idx >= 0) {\r\n                value = value.substr(0, idx);\r\n            }\r\n        }\r\n\r\n        var params = {},\r\n            regex = /([^&=]+)=([^&]*)/g,\r\n            m;\r\n\r\n        var counter = 0;\r\n        while (m = regex.exec(value)) {\r\n            params[decodeURIComponent(m[1])] = decodeURIComponent(m[2]);\r\n            if (counter++ > 50) {\r\n                Log.error(\"UrlUtility.parseUrlFragment: response exceeded expected number of parameters\", value);\r\n                return {\r\n                    error: \"Response exceeded expected number of parameters\"\r\n                };\r\n            }\r\n        }\r\n\r\n        for (var prop in params) {\r\n            return params;\r\n        }\r\n\r\n        return {};\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class User {\r\n    constructor({id_token, session_state, access_token, refresh_token, token_type, scope, profile, expires_at, state}) {\r\n        this.id_token = id_token;\r\n        this.session_state = session_state;\r\n        this.access_token = access_token;\r\n        this.refresh_token = refresh_token;\r\n        this.token_type = token_type;\r\n        this.scope = scope;\r\n        this.profile = profile;\r\n        this.expires_at = expires_at;\r\n        this.state = state;\r\n    }\r\n\r\n    get expires_in() {\r\n        if (this.expires_at) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            return this.expires_at - now;\r\n        }\r\n        return undefined;\r\n    }\r\n    set expires_in(value) {\r\n        let expires_in = parseInt(value);\r\n        if (typeof expires_in === 'number' && expires_in > 0) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            this.expires_at = now + expires_in;\r\n        }\r\n    }\r\n\r\n    get expired() {\r\n        let expires_in = this.expires_in;\r\n        if (expires_in !== undefined) {\r\n            return expires_in <= 0;\r\n        }\r\n        return undefined;\r\n    }\r\n\r\n    get scopes() {\r\n        return (this.scope || \"\").split(\" \");\r\n    }\r\n\r\n    toStorageString() {\r\n        Log.debug(\"User.toStorageString\");\r\n        return JSON.stringify({\r\n            id_token: this.id_token,\r\n            session_state: this.session_state,\r\n            access_token: this.access_token,\r\n            refresh_token: this.refresh_token,\r\n            token_type: this.token_type,\r\n            scope: this.scope,\r\n            profile: this.profile,\r\n            expires_at: this.expires_at\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"User.fromStorageString\");\r\n        return new User(JSON.parse(storageString));\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { JsonService } from './JsonService.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Log } from './Log.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\nexport class UserInfoService {\r\n    constructor(\r\n        settings, \r\n        JsonServiceCtor = JsonService, \r\n        MetadataServiceCtor = MetadataService, \r\n        joseUtil = JoseUtil\r\n    ) {\r\n        if (!settings) {\r\n            Log.error(\"UserInfoService.ctor: No settings passed\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor(undefined, undefined, this._getClaimsFromJwt.bind(this));\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n    }\r\n\r\n    getClaims(token) {\r\n        if (!token) {\r\n            Log.error(\"UserInfoService.getClaims: No token passed\");\r\n            return Promise.reject(new Error(\"A token is required\"));\r\n        }\r\n\r\n        return this._metadataService.getUserInfoEndpoint().then(url => {\r\n            Log.debug(\"UserInfoService.getClaims: received userinfo url\", url);\r\n\r\n            return this._jsonService.getJson(url, token).then(claims => {\r\n                Log.debug(\"UserInfoService.getClaims: claims received\", claims);\r\n                return claims;\r\n            });\r\n        });\r\n    }\r\n\r\n    _getClaimsFromJwt(req) {\r\n        try {\r\n            let jwt = this._joseUtil.parseJwt(req.responseText);\r\n            if (!jwt || !jwt.header || !jwt.payload) {\r\n                Log.error(\"UserInfoService._getClaimsFromJwt: Failed to parse JWT\", jwt);\r\n                return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n            }\r\n\r\n            var kid = jwt.header.kid;\r\n\r\n            let issuerPromise;\r\n            switch (this._settings.userInfoJwtIssuer) {\r\n                case 'OP':\r\n                    issuerPromise = this._metadataService.getIssuer();\r\n                    break;\r\n                case 'ANY':\r\n                    issuerPromise = Promise.resolve(jwt.payload.iss);\r\n                    break;\r\n                default:\r\n                    issuerPromise = Promise.resolve(this._settings.userInfoJwtIssuer);\r\n                    break;\r\n            }\r\n\r\n            return issuerPromise.then(issuer => {\r\n                Log.debug(\"UserInfoService._getClaimsFromJwt: Received issuer:\" + issuer);\r\n\r\n                return this._metadataService.getSigningKeys().then(keys => {\r\n                    if (!keys) {\r\n                        Log.error(\"UserInfoService._getClaimsFromJwt: No signing keys from metadata\");\r\n                        return Promise.reject(new Error(\"No signing keys from metadata\"));\r\n                    }\r\n\r\n                    Log.debug(\"UserInfoService._getClaimsFromJwt: Received signing keys\");\r\n                    let key;\r\n                    if (!kid) {\r\n                        keys = this._filterByAlg(keys, jwt.header.alg);\r\n\r\n                        if (keys.length > 1) {\r\n                            Log.error(\"UserInfoService._getClaimsFromJwt: No kid found in id_token and more than one key found in metadata\");\r\n                            return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\r\n                        }\r\n                        else {\r\n                            // kid is mandatory only when there are multiple keys in the referenced JWK Set document\r\n                            // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\r\n                            key = keys[0];\r\n                        }\r\n                    }\r\n                    else {\r\n                        key = keys.filter(key => {\r\n                            return key.kid === kid;\r\n                        })[0];\r\n                    }\r\n\r\n                    if (!key) {\r\n                        Log.error(\"UserInfoService._getClaimsFromJwt: No key matching kid or alg found in signing keys\");\r\n                        return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\r\n                    }\r\n\r\n                    let audience = this._settings.client_id;\r\n\r\n                    let clockSkewInSeconds = this._settings.clockSkew;\r\n                    Log.debug(\"UserInfoService._getClaimsFromJwt: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n                    return this._joseUtil.validateJwt(req.responseText, key, issuer, audience, clockSkewInSeconds, undefined, true).then(() => {\r\n                        Log.debug(\"UserInfoService._getClaimsFromJwt: JWT validation successful\");\r\n                        return jwt.payload;\r\n                    });\r\n                });\r\n            });\r\n            return;\r\n        }\r\n        catch (e) {\r\n            Log.error(\"UserInfoService._getClaimsFromJwt: Error parsing JWT response\", e.message);\r\n            reject(e);\r\n            return;\r\n        }\r\n    }\r\n\r\n    _filterByAlg(keys, alg) {\r\n        var kty = null;\r\n        if (alg.startsWith(\"RS\")) {\r\n            kty = \"RSA\";\r\n        }\r\n        else if (alg.startsWith(\"PS\")) {\r\n            kty = \"PS\";\r\n        }\r\n        else if (alg.startsWith(\"ES\")) {\r\n            kty = \"EC\";\r\n        }\r\n        else {\r\n            Log.debug(\"UserInfoService._filterByAlg: alg not supported: \", alg);\r\n            return [];\r\n        }\r\n\r\n        Log.debug(\"UserInfoService._filterByAlg: Looking for keys that match kty: \", kty);\r\n\r\n        keys = keys.filter(key => {\r\n            return key.kty === kty;\r\n        });\r\n\r\n        Log.debug(\"UserInfoService._filterByAlg: Number of keys that match kty: \", kty, keys.length);\r\n\r\n        return keys;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClient } from './OidcClient.js';\r\nimport { UserManagerSettings } from './UserManagerSettings.js';\r\nimport { User } from './User.js';\r\nimport { UserManagerEvents } from './UserManagerEvents.js';\r\nimport { SilentRenewService } from './SilentRenewService.js';\r\nimport { SessionMonitor } from './SessionMonitor.js';\r\nimport { TokenRevocationClient } from './TokenRevocationClient.js';\r\nimport { TokenClient } from './TokenClient.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\n\r\nexport class UserManager extends OidcClient {\r\n    constructor(settings = {},\r\n        SilentRenewServiceCtor = SilentRenewService,\r\n        SessionMonitorCtor = SessionMonitor,\r\n        TokenRevocationClientCtor = TokenRevocationClient,\r\n        TokenClientCtor = TokenClient,\r\n        joseUtil = JoseUtil\r\n    ) {\r\n\r\n        if (!(settings instanceof UserManagerSettings)) {\r\n            settings = new UserManagerSettings(settings);\r\n        }\r\n        super(settings);\r\n\r\n        this._events = new UserManagerEvents(settings);\r\n        this._silentRenewService = new SilentRenewServiceCtor(this);\r\n\r\n        // order is important for the following properties; these services depend upon the events.\r\n        if (this.settings.automaticSilentRenew) {\r\n            Log.debug(\"UserManager.ctor: automaticSilentRenew is configured, setting up silent renew\");\r\n            this.startSilentRenew();\r\n        }\r\n\r\n        if (this.settings.monitorSession) {\r\n            Log.debug(\"UserManager.ctor: monitorSession is configured, setting up session monitor\");\r\n            this._sessionMonitor = new SessionMonitorCtor(this);\r\n        }\r\n\r\n        this._tokenRevocationClient = new TokenRevocationClientCtor(this._settings);\r\n        this._tokenClient = new TokenClientCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n    }\r\n\r\n    get _redirectNavigator() {\r\n        return this.settings.redirectNavigator;\r\n    }\r\n    get _popupNavigator() {\r\n        return this.settings.popupNavigator;\r\n    }\r\n    get _iframeNavigator() {\r\n        return this.settings.iframeNavigator;\r\n    }\r\n    get _userStore() {\r\n        return this.settings.userStore;\r\n    }\r\n\r\n    get events() {\r\n        return this._events;\r\n    }\r\n\r\n    getUser() {\r\n        return this._loadUser().then(user => {\r\n            if (user) {\r\n                Log.info(\"UserManager.getUser: user loaded\");\r\n\r\n                this._events.load(user, false);\r\n\r\n                return user;\r\n            }\r\n            else {\r\n                Log.info(\"UserManager.getUser: user not found in storage\");\r\n                return null;\r\n            }\r\n        });\r\n    }\r\n\r\n    removeUser() {\r\n        return this.storeUser(null).then(() => {\r\n            Log.info(\"UserManager.removeUser: user removed from storage\");\r\n            this._events.unload();\r\n        });\r\n    }\r\n\r\n    signinRedirect(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:r\";\r\n        let navParams = {\r\n            useReplaceToNavigate : args.useReplaceToNavigate\r\n        };\r\n        return this._signinStart(args, this._redirectNavigator, navParams).then(()=>{\r\n            Log.info(\"UserManager.signinRedirect: successful\");\r\n        });\r\n    }\r\n    signinRedirectCallback(url) {\r\n        return this._signinEnd(url || this._redirectNavigator.url).then(user => {\r\n            if (user.profile && user.profile.sub) {\r\n                Log.info(\"UserManager.signinRedirectCallback: successful, signed in sub: \", user.profile.sub);\r\n            }\r\n            else {\r\n                Log.info(\"UserManager.signinRedirectCallback: no sub\");\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinPopup(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:p\";\r\n        let url = args.redirect_uri || this.settings.popup_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.signinPopup: No popup_redirect_uri or redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No popup_redirect_uri or redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.display = \"popup\";\r\n\r\n        return this._signin(args, this._popupNavigator, {\r\n            startUrl: url,\r\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\r\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\r\n        }).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinPopup: signinPopup successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinPopup: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n    signinPopupCallback(url) {\r\n        return this._signinCallback(url, this._popupNavigator).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinPopupCallback: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinPopupCallback: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        }).catch(err=>{\r\n            Log.error(\"UserManager.signinPopupCallback error: \" + err && err.message);\r\n        });\r\n    }\r\n\r\n    signinSilent(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:s\";\r\n        // first determine if we have a refresh token, or need to use iframe\r\n        return this._loadUser().then(user => {\r\n            if (user && user.refresh_token) {\r\n                args.refresh_token = user.refresh_token;\r\n                return this._useRefreshToken(args);\r\n            }\r\n            else {\r\n                args.id_token_hint = args.id_token_hint || (this.settings.includeIdTokenInSilentRenew && user && user.id_token);\r\n                if (user && this._settings.validateSubOnSilentRenew) {\r\n                    Log.debug(\"UserManager.signinSilent, subject prior to silent renew: \", user.profile.sub);\r\n                    args.current_sub = user.profile.sub;\r\n                }\r\n                return this._signinSilentIframe(args);\r\n            }\r\n        });\r\n    }\r\n\r\n    _useRefreshToken(args = {}) {\r\n        return this._tokenClient.exchangeRefreshToken(args).then(result => {\r\n            if (!result) {\r\n                Log.error(\"UserManager._useRefreshToken: No response returned from token endpoint\");\r\n                return Promise.reject(\"No response returned from token endpoint\");\r\n            }\r\n            if (!result.access_token) {\r\n                Log.error(\"UserManager._useRefreshToken: No access token returned from token endpoint\");\r\n                return Promise.reject(\"No access token returned from token endpoint\");\r\n            }\r\n\r\n            return this._loadUser().then(user => {\r\n                if (user) {\r\n                    let idTokenValidation = Promise.resolve();\r\n                    if (result.id_token) {\r\n                        idTokenValidation = this._validateIdTokenFromTokenRefreshToken(user.profile, result.id_token);\r\n                    }\r\n\r\n                    return idTokenValidation.then(() => {\r\n                        Log.debug(\"UserManager._useRefreshToken: refresh token response success\");\r\n                        user.id_token = result.id_token;\r\n                        user.access_token = result.access_token;\r\n                        user.refresh_token = result.refresh_token || user.refresh_token;\r\n                        user.expires_in = result.expires_in;\r\n\r\n                        return this.storeUser(user).then(()=>{\r\n                            this._events.load(user);\r\n                            return user;\r\n                        });\r\n                    });\r\n                }\r\n                else {\r\n                    return null;\r\n                }\r\n            });\r\n        });\r\n    }\r\n\r\n    _validateIdTokenFromTokenRefreshToken(profile, id_token) {\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n            return this._joseUtil.validateJwtAttributes(id_token, issuer, this._settings.client_id, this._settings.clockSkew).then(payload => {\r\n                if (!payload) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: Failed to validate id_token\");\r\n                    return Promise.reject(new Error(\"Failed to validate id_token\"));\r\n                }\r\n                if (payload.sub !== profile.sub) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: sub in id_token does not match current sub\");\r\n                    return Promise.reject(new Error(\"sub in id_token does not match current sub\"));\r\n                }\r\n                if (payload.auth_time && payload.auth_time !== profile.auth_time) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: auth_time in id_token does not match original auth_time\");\r\n                    return Promise.reject(new Error(\"auth_time in id_token does not match original auth_time\"));\r\n                }\r\n                if (payload.azp && payload.azp !== profile.azp) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp in id_token does not match original azp\");\r\n                    return Promise.reject(new Error(\"azp in id_token does not match original azp\"));\r\n                }\r\n                if (!payload.azp && profile.azp) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp not in id_token, but present in original id_token\");\r\n                    return Promise.reject(new Error(\"azp not in id_token, but present in original id_token\"));\r\n                }\r\n            });\r\n        });\r\n    }\r\n    \r\n    _signinSilentIframe(args = {}) {\r\n        let url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.signinSilent: No silent_redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.prompt = args.prompt || \"none\";\r\n\r\n        return this._signin(args, this._iframeNavigator, {\r\n            startUrl: url,\r\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\r\n        }).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinSilent: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinSilent: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinSilentCallback(url) {\r\n        return this._signinCallback(url, this._iframeNavigator).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinSilentCallback: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinSilentCallback: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinCallback(url) {\r\n        return this.readSigninResponseState(url).then(({state, response}) => {\r\n            if (state.request_type === \"si:r\") {\r\n                return this.signinRedirectCallback(url);\r\n            }\r\n            if (state.request_type === \"si:p\") {\r\n                return this.signinPopupCallback(url);\r\n            }\r\n            if (state.request_type === \"si:s\") {\r\n                return this.signinSilentCallback(url);\r\n            }\r\n            return Promise.reject(new Error(\"invalid response_type in state\"));\r\n        });\r\n    }\r\n\r\n    signoutCallback(url, keepOpen) {\r\n        return this.readSignoutResponseState(url).then(({state, response}) => {\r\n            if (state) {\r\n                if (state.request_type === \"so:r\") {\r\n                    return this.signoutRedirectCallback(url);\r\n                }\r\n                if (state.request_type === \"so:p\") {\r\n                    return this.signoutPopupCallback(url, keepOpen);\r\n                }\r\n                return Promise.reject(new Error(\"invalid response_type in state\"));\r\n            }\r\n            return response;\r\n        });\r\n    }\r\n\r\n    querySessionStatus(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:s\"; // this acts like a signin silent\r\n        let url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.querySessionStatus: No silent_redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.prompt = \"none\";\r\n        args.response_type = args.response_type || this.settings.query_status_response_type;\r\n        args.scope = args.scope || \"openid\";\r\n        args.skipUserInfo = true;\r\n\r\n        return this._signinStart(args, this._iframeNavigator, {\r\n            startUrl: url,\r\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\r\n        }).then(navResponse => {\r\n            return this.processSigninResponse(navResponse.url).then(signinResponse => {\r\n                Log.debug(\"UserManager.querySessionStatus: got signin response\");\r\n\r\n                if (signinResponse.session_state && signinResponse.profile.sub) {\r\n                    Log.info(\"UserManager.querySessionStatus: querySessionStatus success for sub: \",  signinResponse.profile.sub);\r\n                    return {\r\n                        session_state: signinResponse.session_state,\r\n                        sub: signinResponse.profile.sub,\r\n                        sid: signinResponse.profile.sid\r\n                    };\r\n                }\r\n                else {\r\n                    Log.info(\"querySessionStatus successful, user not authenticated\");\r\n                }\r\n            })\r\n            .catch(err => {\r\n                if (err.session_state && this.settings.monitorAnonymousSession) {\r\n                    if (err.message == \"login_required\" || \r\n                        err.message == \"consent_required\" || \r\n                        err.message == \"interaction_required\" || \r\n                        err.message == \"account_selection_required\"\r\n                    ) {\r\n                        Log.info(\"UserManager.querySessionStatus: querySessionStatus success for anonymous user\");\r\n                        return {\r\n                            session_state: err.session_state\r\n                        };\r\n                    }\r\n                }\r\n\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n\r\n    _signin(args, navigator, navigatorParams = {}) {\r\n        return this._signinStart(args, navigator, navigatorParams).then(navResponse => {\r\n            return this._signinEnd(navResponse.url, args);\r\n        });\r\n    }\r\n    _signinStart(args, navigator, navigatorParams = {}) {\r\n\r\n        return navigator.prepare(navigatorParams).then(handle => {\r\n            Log.debug(\"UserManager._signinStart: got navigator window handle\");\r\n\r\n            return this.createSigninRequest(args).then(signinRequest => {\r\n                Log.debug(\"UserManager._signinStart: got signin request\");\r\n\r\n                navigatorParams.url = signinRequest.url;\r\n                navigatorParams.id = signinRequest.state.id;\r\n\r\n                return handle.navigate(navigatorParams);\r\n            }).catch(err => {\r\n                if (handle.close) {\r\n                    Log.debug(\"UserManager._signinStart: Error after preparing navigator, closing navigator window\");\r\n                    handle.close();\r\n                }\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n    _signinEnd(url, args = {}) {\r\n        return this.processSigninResponse(url).then(signinResponse => {\r\n            Log.debug(\"UserManager._signinEnd: got signin response\");\r\n\r\n            let user = new User(signinResponse);\r\n\r\n            if (args.current_sub) {\r\n                if (args.current_sub !== user.profile.sub) {\r\n                    Log.debug(\"UserManager._signinEnd: current user does not match user returned from signin. sub from signin: \", user.profile.sub);\r\n                    return Promise.reject(new Error(\"login_required\"));\r\n                }\r\n                else {\r\n                    Log.debug(\"UserManager._signinEnd: current user matches user returned from signin\");\r\n                }\r\n            }\r\n\r\n            return this.storeUser(user).then(() => {\r\n                Log.debug(\"UserManager._signinEnd: user stored\");\r\n\r\n                this._events.load(user);\r\n\r\n                return user;\r\n            });\r\n        });\r\n    }\r\n    _signinCallback(url, navigator) {\r\n        Log.debug(\"UserManager._signinCallback\");\r\n        return navigator.callback(url);\r\n    }\r\n\r\n    signoutRedirect(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"so:r\";\r\n        let postLogoutRedirectUri = args.post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\r\n        if (postLogoutRedirectUri){\r\n            args.post_logout_redirect_uri = postLogoutRedirectUri;\r\n        }\r\n        let navParams = {\r\n            useReplaceToNavigate : args.useReplaceToNavigate\r\n        };\r\n        return this._signoutStart(args, this._redirectNavigator, navParams).then(()=>{\r\n            Log.info(\"UserManager.signoutRedirect: successful\");\r\n        });\r\n    }\r\n    signoutRedirectCallback(url) {\r\n        return this._signoutEnd(url || this._redirectNavigator.url).then(response=>{\r\n            Log.info(\"UserManager.signoutRedirectCallback: successful\");\r\n            return response;\r\n        });\r\n    }\r\n\r\n    signoutPopup(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"so:p\";\r\n        let url = args.post_logout_redirect_uri || this.settings.popup_post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\r\n        args.post_logout_redirect_uri = url;\r\n        args.display = \"popup\";\r\n        if (args.post_logout_redirect_uri){\r\n            // we're putting a dummy entry in here because we\r\n            // need a unique id from the state for notification\r\n            // to the parent window, which is necessary if we\r\n            // plan to return back to the client after signout\r\n            // and so we can close the popup after signout\r\n            args.state = args.state || {};\r\n        }\r\n\r\n        return this._signout(args, this._popupNavigator, {\r\n            startUrl: url,\r\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\r\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\r\n        }).then(() => {\r\n            Log.info(\"UserManager.signoutPopup: successful\");\r\n        });\r\n    }\r\n    signoutPopupCallback(url, keepOpen) {\r\n        if (typeof(keepOpen) === 'undefined' && typeof(url) === 'boolean') {\r\n            keepOpen = url;\r\n            url = null;\r\n        }\r\n\r\n        let delimiter = '?';\r\n        return this._popupNavigator.callback(url, keepOpen, delimiter).then(() => {\r\n            Log.info(\"UserManager.signoutPopupCallback: successful\");\r\n        });\r\n    }\r\n\r\n    _signout(args, navigator, navigatorParams = {}) {\r\n        return this._signoutStart(args, navigator, navigatorParams).then(navResponse => {\r\n            return this._signoutEnd(navResponse.url);\r\n        });\r\n    }\r\n    _signoutStart(args = {}, navigator, navigatorParams = {}) {\r\n        return navigator.prepare(navigatorParams).then(handle => {\r\n            Log.debug(\"UserManager._signoutStart: got navigator window handle\");\r\n\r\n            return this._loadUser().then(user => {\r\n                Log.debug(\"UserManager._signoutStart: loaded current user from storage\");\r\n\r\n                var revokePromise = this._settings.revokeAccessTokenOnSignout ? this._revokeInternal(user) : Promise.resolve();\r\n                return revokePromise.then(() => {\r\n\r\n                    var id_token = args.id_token_hint || user && user.id_token;\r\n                    if (id_token) {\r\n                        Log.debug(\"UserManager._signoutStart: Setting id_token into signout request\");\r\n                        args.id_token_hint = id_token;\r\n                    }\r\n\r\n                    return this.removeUser().then(() => {\r\n                        Log.debug(\"UserManager._signoutStart: user removed, creating signout request\");\r\n\r\n                        return this.createSignoutRequest(args).then(signoutRequest => {\r\n                            Log.debug(\"UserManager._signoutStart: got signout request\");\r\n\r\n                            navigatorParams.url = signoutRequest.url;\r\n                            if (signoutRequest.state) {\r\n                                navigatorParams.id = signoutRequest.state.id;\r\n                            }\r\n                            return handle.navigate(navigatorParams);\r\n                        });\r\n                    });\r\n                });\r\n            }).catch(err => {\r\n                if (handle.close) {\r\n                    Log.debug(\"UserManager._signoutStart: Error after preparing navigator, closing navigator window\");\r\n                    handle.close();\r\n                }\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n    _signoutEnd(url) {\r\n        return this.processSignoutResponse(url).then(signoutResponse => {\r\n            Log.debug(\"UserManager._signoutEnd: got signout response\");\r\n\r\n            return signoutResponse;\r\n        });\r\n    }\r\n\r\n    revokeAccessToken() {\r\n        return this._loadUser().then(user => {\r\n            return this._revokeInternal(user, true).then(success => {\r\n                if (success) {\r\n                    Log.debug(\"UserManager.revokeAccessToken: removing token properties from user and re-storing\");\r\n\r\n                    user.access_token = null;\r\n                    user.refresh_token = null;\r\n                    user.expires_at = null;\r\n                    user.token_type = null;\r\n\r\n                    return this.storeUser(user).then(() => {\r\n                        Log.debug(\"UserManager.revokeAccessToken: user stored\");\r\n                        this._events.load(user);\r\n                    });\r\n                }\r\n            });\r\n        }).then(()=>{\r\n            Log.info(\"UserManager.revokeAccessToken: access token revoked successfully\");\r\n        });\r\n    }\r\n\r\n    _revokeInternal(user, required) {\r\n        if (user) {\r\n            var access_token = user.access_token;\r\n            var refresh_token = user.refresh_token;\r\n\r\n            return this._revokeAccessTokenInternal(access_token, required)\r\n                .then(atSuccess => {\r\n                    return this._revokeRefreshTokenInternal(refresh_token, required)\r\n                        .then(rtSuccess => {\r\n                            if (!atSuccess && !rtSuccess) {\r\n                                Log.debug(\"UserManager.revokeAccessToken: no need to revoke due to no token(s), or JWT format\");\r\n                            }\r\n                            \r\n                            return atSuccess || rtSuccess;\r\n                        });\r\n                });\r\n        }\r\n\r\n        return Promise.resolve(false);\r\n    }\r\n\r\n    _revokeAccessTokenInternal(access_token, required) {\r\n        // check for JWT vs. reference token\r\n        if (!access_token || access_token.indexOf('.') >= 0) {\r\n            return Promise.resolve(false);\r\n        }\r\n\r\n        return this._tokenRevocationClient.revoke(access_token, required).then(() => true);\r\n    }\r\n\r\n    _revokeRefreshTokenInternal(refresh_token, required) {\r\n        if (!refresh_token) {\r\n            return Promise.resolve(false);\r\n        }\r\n\r\n        return this._tokenRevocationClient.revoke(refresh_token, required, \"refresh_token\").then(() => true);\r\n    }\r\n\r\n    startSilentRenew() {\r\n        this._silentRenewService.start();\r\n    }\r\n\r\n    stopSilentRenew() {\r\n        this._silentRenewService.stop();\r\n    }\r\n\r\n    get _userStoreKey() {\r\n        return `user:${this.settings.authority}:${this.settings.client_id}`;\r\n    }\r\n\r\n    _loadUser() {\r\n        return this._userStore.get(this._userStoreKey).then(storageString => {\r\n            if (storageString) {\r\n                Log.debug(\"UserManager._loadUser: user storageString loaded\");\r\n                return User.fromStorageString(storageString);\r\n            }\r\n\r\n            Log.debug(\"UserManager._loadUser: no user storageString\");\r\n            return null;\r\n        });\r\n    }\r\n\r\n    storeUser(user) {\r\n        if (user) {\r\n            Log.debug(\"UserManager.storeUser: storing user\");\r\n\r\n            var storageString = user.toStorageString();\r\n            return this._userStore.set(this._userStoreKey, storageString);\r\n        }\r\n        else {\r\n            Log.debug(\"storeUser.storeUser: removing user\");\r\n            return this._userStore.remove(this._userStoreKey);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { AccessTokenEvents } from './AccessTokenEvents.js';\r\nimport { Event } from './Event.js';\r\n\r\nexport class UserManagerEvents extends AccessTokenEvents {\r\n\r\n    constructor(settings) {\r\n        super(settings);\r\n        this._userLoaded = new Event(\"User loaded\");\r\n        this._userUnloaded = new Event(\"User unloaded\");\r\n        this._silentRenewError = new Event(\"Silent renew error\");\r\n        this._userSignedIn = new Event(\"User signed in\");\r\n        this._userSignedOut = new Event(\"User signed out\");\r\n        this._userSessionChanged = new Event(\"User session changed\");\r\n    }\r\n\r\n    load(user, raiseEvent=true) {\r\n        Log.debug(\"UserManagerEvents.load\");\r\n        super.load(user);\r\n        if (raiseEvent) {\r\n            this._userLoaded.raise(user);\r\n        }\r\n    }\r\n    unload() {\r\n        Log.debug(\"UserManagerEvents.unload\");\r\n        super.unload();\r\n        this._userUnloaded.raise();\r\n    }\r\n\r\n    addUserLoaded(cb) {\r\n        this._userLoaded.addHandler(cb);\r\n    }\r\n    removeUserLoaded(cb) {\r\n        this._userLoaded.removeHandler(cb);\r\n    }\r\n\r\n    addUserUnloaded(cb) {\r\n        this._userUnloaded.addHandler(cb);\r\n    }\r\n    removeUserUnloaded(cb) {\r\n        this._userUnloaded.removeHandler(cb);\r\n    }\r\n\r\n    addSilentRenewError(cb) {\r\n        this._silentRenewError.addHandler(cb);\r\n    }\r\n    removeSilentRenewError(cb) {\r\n        this._silentRenewError.removeHandler(cb);\r\n    }\r\n    _raiseSilentRenewError(e) {\r\n        Log.debug(\"UserManagerEvents._raiseSilentRenewError\", e.message);\r\n        this._silentRenewError.raise(e);\r\n    }\r\n\r\n    addUserSignedIn(cb) {\r\n        this._userSignedIn.addHandler(cb);\r\n    }\r\n    removeUserSignedIn(cb) {\r\n        this._userSignedIn.removeHandler(cb);\r\n    }\r\n    _raiseUserSignedIn() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSignedIn\");\r\n        this._userSignedIn.raise();\r\n    }\r\n\r\n    addUserSignedOut(cb) {\r\n        this._userSignedOut.addHandler(cb);\r\n    }\r\n    removeUserSignedOut(cb) {\r\n        this._userSignedOut.removeHandler(cb);\r\n    }\r\n    _raiseUserSignedOut() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSignedOut\");\r\n        this._userSignedOut.raise();\r\n    }\r\n\r\n    addUserSessionChanged(cb) {\r\n        this._userSessionChanged.addHandler(cb);\r\n    }\r\n    removeUserSessionChanged(cb) {\r\n        this._userSessionChanged.removeHandler(cb);\r\n    }\r\n    _raiseUserSessionChanged() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSessionChanged\");\r\n        this._userSessionChanged.raise();\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClientSettings } from './OidcClientSettings.js';\r\nimport { RedirectNavigator } from './RedirectNavigator.js';\r\nimport { PopupNavigator } from './PopupNavigator.js';\r\nimport { IFrameNavigator } from './IFrameNavigator.js';\r\nimport { WebStorageStateStore } from './WebStorageStateStore.js';\r\nimport { Global } from './Global.js';\r\nimport { SigninRequest } from './SigninRequest.js';\r\n\r\nconst DefaultAccessTokenExpiringNotificationTime = 60;\r\nconst DefaultCheckSessionInterval = 2000;\r\n\r\nexport class UserManagerSettings extends OidcClientSettings {\r\n    constructor({\r\n        popup_redirect_uri,\r\n        popup_post_logout_redirect_uri,\r\n        popupWindowFeatures,\r\n        popupWindowTarget,\r\n        silent_redirect_uri,\r\n        silentRequestTimeout,\r\n        automaticSilentRenew = false,\r\n        validateSubOnSilentRenew = false,\r\n        includeIdTokenInSilentRenew = true,\r\n        monitorSession = true,\r\n        monitorAnonymousSession = false,\r\n        checkSessionInterval = DefaultCheckSessionInterval,\r\n        stopCheckSessionOnError = true,\r\n        query_status_response_type,\r\n        revokeAccessTokenOnSignout = false,\r\n        accessTokenExpiringNotificationTime = DefaultAccessTokenExpiringNotificationTime,\r\n        redirectNavigator = new RedirectNavigator(),\r\n        popupNavigator = new PopupNavigator(),\r\n        iframeNavigator = new IFrameNavigator(),\r\n        userStore = new WebStorageStateStore({ store: Global.sessionStorage })\r\n    } = {}) {\r\n        super(arguments[0]);\r\n\r\n        this._popup_redirect_uri = popup_redirect_uri;\r\n        this._popup_post_logout_redirect_uri = popup_post_logout_redirect_uri;\r\n        this._popupWindowFeatures = popupWindowFeatures;\r\n        this._popupWindowTarget = popupWindowTarget;\r\n\r\n        this._silent_redirect_uri = silent_redirect_uri;\r\n        this._silentRequestTimeout = silentRequestTimeout;\r\n        this._automaticSilentRenew = automaticSilentRenew;\r\n        this._validateSubOnSilentRenew = validateSubOnSilentRenew;\r\n        this._includeIdTokenInSilentRenew = includeIdTokenInSilentRenew;\r\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\r\n\r\n        this._monitorSession = monitorSession;\r\n        this._monitorAnonymousSession = monitorAnonymousSession;\r\n        this._checkSessionInterval = checkSessionInterval;\r\n        this._stopCheckSessionOnError = stopCheckSessionOnError;\r\n        if (query_status_response_type) {\r\n            this._query_status_response_type = query_status_response_type;\r\n        } \r\n        else if (arguments[0] && arguments[0].response_type) {\r\n            this._query_status_response_type = SigninRequest.isOidc(arguments[0].response_type) ? \"id_token\" : \"code\";\r\n        }\r\n        else {\r\n            this._query_status_response_type = \"id_token\";\r\n        }\r\n        this._revokeAccessTokenOnSignout = revokeAccessTokenOnSignout;\r\n\r\n        this._redirectNavigator = redirectNavigator;\r\n        this._popupNavigator = popupNavigator;\r\n        this._iframeNavigator = iframeNavigator;\r\n\r\n        this._userStore = userStore;\r\n    }\r\n\r\n    get popup_redirect_uri() {\r\n        return this._popup_redirect_uri;\r\n    }\r\n    get popup_post_logout_redirect_uri() {\r\n        return this._popup_post_logout_redirect_uri;\r\n    }\r\n    get popupWindowFeatures() {\r\n        return this._popupWindowFeatures;\r\n    }\r\n    get popupWindowTarget() {\r\n        return this._popupWindowTarget;\r\n    }\r\n\r\n    get silent_redirect_uri() {\r\n        return this._silent_redirect_uri;\r\n    }\r\n     get silentRequestTimeout() {\r\n        return this._silentRequestTimeout;\r\n    }\r\n    get automaticSilentRenew() {\r\n        return this._automaticSilentRenew;\r\n    }\r\n    get validateSubOnSilentRenew() {\r\n        return this._validateSubOnSilentRenew;\r\n    }\r\n    get includeIdTokenInSilentRenew() {\r\n        return this._includeIdTokenInSilentRenew;\r\n    }\r\n    get accessTokenExpiringNotificationTime() {\r\n        return this._accessTokenExpiringNotificationTime;\r\n    }\r\n\r\n    get monitorSession() {\r\n        return this._monitorSession;\r\n    }\r\n    get monitorAnonymousSession() {\r\n        return this._monitorAnonymousSession;\r\n    }\r\n    get checkSessionInterval() {\r\n        return this._checkSessionInterval;\r\n    }\r\n    get stopCheckSessionOnError(){\r\n        return this._stopCheckSessionOnError;\r\n    }\r\n    get query_status_response_type(){\r\n        return this._query_status_response_type;\r\n    }\r\n    get revokeAccessTokenOnSignout() {\r\n        return this._revokeAccessTokenOnSignout;\r\n    }\r\n\r\n    get redirectNavigator() {\r\n        return this._redirectNavigator;\r\n    }\r\n    get popupNavigator() {\r\n        return this._popupNavigator;\r\n    }\r\n    get iframeNavigator() {\r\n        return this._iframeNavigator;\r\n    }\r\n\r\n    get userStore() {\r\n        return this._userStore;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class WebStorageStateStore {\r\n    constructor({prefix = \"oidc.\", store = Global.localStorage} = {}) {\r\n        this._store = store;\r\n        this._prefix = prefix;\r\n    }\r\n\r\n    set(key, value) {\r\n        Log.debug(\"WebStorageStateStore.set\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        this._store.setItem(key, value);\r\n\r\n        return Promise.resolve();\r\n    }\r\n\r\n    get(key) {\r\n        Log.debug(\"WebStorageStateStore.get\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        let item = this._store.getItem(key);\r\n\r\n        return Promise.resolve(item);\r\n    }\r\n\r\n    remove(key) {\r\n        Log.debug(\"WebStorageStateStore.remove\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        let item = this._store.getItem(key);\r\n        this._store.removeItem(key);\r\n\r\n        return Promise.resolve(item);\r\n    }\r\n\r\n    getAllKeys() {\r\n        Log.debug(\"WebStorageStateStore.getAllKeys\");\r\n\r\n        var keys = [];\r\n\r\n        for (let index = 0; index < this._store.length; index++) {\r\n            let key = this._store.key(index);\r\n\r\n            if (key.indexOf(this._prefix) === 0) {\r\n                keys.push(key.substr(this._prefix.length));\r\n            }\r\n        }\r\n\r\n        return Promise.resolve(keys);\r\n    }\r\n}\r\n","import { jws, KEYUTIL as KeyUtil, X509, crypto, hextob64u, b64tohex } from '../../jsrsasign/dist/jsrsasign.js';\r\n\r\nconst AllowedSigningAlgs = ['RS256', 'RS384', 'RS512', 'PS256', 'PS384', 'PS512', 'ES256', 'ES384', 'ES512'];\r\n\r\nexport {\r\n    jws,\r\n    KeyUtil,\r\n    X509,\r\n    crypto,\r\n    hextob64u,\r\n    b64tohex,\r\n    AllowedSigningAlgs\r\n};\r\n","import uuid4 from 'uuid/v4';\r\n\r\n/**\r\n * Generates RFC4122 version 4 guid ()\r\n */\r\n\r\nexport default function random() {\r\n  return uuid4().replace(/-/g, '');\r\n}\r\n","const Version = \"1.10.1\"; export {Version};"],"sourceRoot":""}"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/libs/oidc-client.rsa256.slim.js",
    "content": "var Oidc =\n/******/ (function(modules) { // webpackBootstrap\n/******/ \t// The module cache\n/******/ \tvar installedModules = {};\n/******/\n/******/ \t// The require function\n/******/ \tfunction __webpack_require__(moduleId) {\n/******/\n/******/ \t\t// Check if module is in cache\n/******/ \t\tif(installedModules[moduleId]) {\n/******/ \t\t\treturn installedModules[moduleId].exports;\n/******/ \t\t}\n/******/ \t\t// Create a new module (and put it into the cache)\n/******/ \t\tvar module = installedModules[moduleId] = {\n/******/ \t\t\ti: moduleId,\n/******/ \t\t\tl: false,\n/******/ \t\t\texports: {}\n/******/ \t\t};\n/******/\n/******/ \t\t// Execute the module function\n/******/ \t\tmodules[moduleId].call(module.exports, module, module.exports, __webpack_require__);\n/******/\n/******/ \t\t// Flag the module as loaded\n/******/ \t\tmodule.l = true;\n/******/\n/******/ \t\t// Return the exports of the module\n/******/ \t\treturn module.exports;\n/******/ \t}\n/******/\n/******/\n/******/ \t// expose the modules object (__webpack_modules__)\n/******/ \t__webpack_require__.m = modules;\n/******/\n/******/ \t// expose the module cache\n/******/ \t__webpack_require__.c = installedModules;\n/******/\n/******/ \t// define getter function for harmony exports\n/******/ \t__webpack_require__.d = function(exports, name, getter) {\n/******/ \t\tif(!__webpack_require__.o(exports, name)) {\n/******/ \t\t\tObject.defineProperty(exports, name, { enumerable: true, get: getter });\n/******/ \t\t}\n/******/ \t};\n/******/\n/******/ \t// define __esModule on exports\n/******/ \t__webpack_require__.r = function(exports) {\n/******/ \t\tif(typeof Symbol !== 'undefined' && Symbol.toStringTag) {\n/******/ \t\t\tObject.defineProperty(exports, Symbol.toStringTag, { value: 'Module' });\n/******/ \t\t}\n/******/ \t\tObject.defineProperty(exports, '__esModule', { value: true });\n/******/ \t};\n/******/\n/******/ \t// create a fake namespace object\n/******/ \t// mode & 1: value is a module id, require it\n/******/ \t// mode & 2: merge all properties of value into the ns\n/******/ \t// mode & 4: return value when already ns object\n/******/ \t// mode & 8|1: behave like require\n/******/ \t__webpack_require__.t = function(value, mode) {\n/******/ \t\tif(mode & 1) value = __webpack_require__(value);\n/******/ \t\tif(mode & 8) return value;\n/******/ \t\tif((mode & 4) && typeof value === 'object' && value && value.__esModule) return value;\n/******/ \t\tvar ns = Object.create(null);\n/******/ \t\t__webpack_require__.r(ns);\n/******/ \t\tObject.defineProperty(ns, 'default', { enumerable: true, value: value });\n/******/ \t\tif(mode & 2 && typeof value != 'string') for(var key in value) __webpack_require__.d(ns, key, function(key) { return value[key]; }.bind(null, key));\n/******/ \t\treturn ns;\n/******/ \t};\n/******/\n/******/ \t// getDefaultExport function for compatibility with non-harmony modules\n/******/ \t__webpack_require__.n = function(module) {\n/******/ \t\tvar getter = module && module.__esModule ?\n/******/ \t\t\tfunction getDefault() { return module['default']; } :\n/******/ \t\t\tfunction getModuleExports() { return module; };\n/******/ \t\t__webpack_require__.d(getter, 'a', getter);\n/******/ \t\treturn getter;\n/******/ \t};\n/******/\n/******/ \t// Object.prototype.hasOwnProperty.call\n/******/ \t__webpack_require__.o = function(object, property) { return Object.prototype.hasOwnProperty.call(object, property); };\n/******/\n/******/ \t// __webpack_public_path__\n/******/ \t__webpack_require__.p = \"\";\n/******/\n/******/\n/******/ \t// Load entry module and return exports\n/******/ \treturn __webpack_require__(__webpack_require__.s = 0);\n/******/ })\n/************************************************************************/\n/******/ ({\n\n/***/ \"./index.js\":\n/*!******************!*\\\n  !*** ./index.js ***!\n  \\******************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _Log = __webpack_require__(/*! ./src/Log.js */ \"./src/Log.js\");\n\nvar _OidcClient = __webpack_require__(/*! ./src/OidcClient.js */ \"./src/OidcClient.js\");\n\nvar _OidcClientSettings = __webpack_require__(/*! ./src/OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./src/WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _InMemoryWebStorage = __webpack_require__(/*! ./src/InMemoryWebStorage.js */ \"./src/InMemoryWebStorage.js\");\n\nvar _UserManager = __webpack_require__(/*! ./src/UserManager.js */ \"./src/UserManager.js\");\n\nvar _AccessTokenEvents = __webpack_require__(/*! ./src/AccessTokenEvents.js */ \"./src/AccessTokenEvents.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./src/MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _CordovaPopupNavigator = __webpack_require__(/*! ./src/CordovaPopupNavigator.js */ \"./src/CordovaPopupNavigator.js\");\n\nvar _CordovaIFrameNavigator = __webpack_require__(/*! ./src/CordovaIFrameNavigator.js */ \"./src/CordovaIFrameNavigator.js\");\n\nvar _CheckSessionIFrame = __webpack_require__(/*! ./src/CheckSessionIFrame.js */ \"./src/CheckSessionIFrame.js\");\n\nvar _TokenRevocationClient = __webpack_require__(/*! ./src/TokenRevocationClient.js */ \"./src/TokenRevocationClient.js\");\n\nvar _SessionMonitor = __webpack_require__(/*! ./src/SessionMonitor.js */ \"./src/SessionMonitor.js\");\n\nvar _Global = __webpack_require__(/*! ./src/Global.js */ \"./src/Global.js\");\n\nvar _User = __webpack_require__(/*! ./src/User.js */ \"./src/User.js\");\n\nvar _version = __webpack_require__(/*! ./version.js */ \"./version.js\");\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nexports.default = {\n    Version: _version.Version,\n    Log: _Log.Log,\n    OidcClient: _OidcClient.OidcClient,\n    OidcClientSettings: _OidcClientSettings.OidcClientSettings,\n    WebStorageStateStore: _WebStorageStateStore.WebStorageStateStore,\n    InMemoryWebStorage: _InMemoryWebStorage.InMemoryWebStorage,\n    UserManager: _UserManager.UserManager,\n    AccessTokenEvents: _AccessTokenEvents.AccessTokenEvents,\n    MetadataService: _MetadataService.MetadataService,\n    CordovaPopupNavigator: _CordovaPopupNavigator.CordovaPopupNavigator,\n    CordovaIFrameNavigator: _CordovaIFrameNavigator.CordovaIFrameNavigator,\n    CheckSessionIFrame: _CheckSessionIFrame.CheckSessionIFrame,\n    TokenRevocationClient: _TokenRevocationClient.TokenRevocationClient,\n    SessionMonitor: _SessionMonitor.SessionMonitor,\n    Global: _Global.Global,\n    User: _User.User\n};\nmodule.exports = exports['default'];\n\n/***/ }),\n\n/***/ \"./node_modules/base64-js/index.js\":\n/*!*****************************************!*\\\n  !*** ./node_modules/base64-js/index.js ***!\n  \\*****************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nexports.byteLength = byteLength\nexports.toByteArray = toByteArray\nexports.fromByteArray = fromByteArray\n\nvar lookup = []\nvar revLookup = []\nvar Arr = typeof Uint8Array !== 'undefined' ? Uint8Array : Array\n\nvar code = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'\nfor (var i = 0, len = code.length; i < len; ++i) {\n  lookup[i] = code[i]\n  revLookup[code.charCodeAt(i)] = i\n}\n\n// Support decoding URL-safe base64 strings, as Node.js does.\n// See: https://en.wikipedia.org/wiki/Base64#URL_applications\nrevLookup['-'.charCodeAt(0)] = 62\nrevLookup['_'.charCodeAt(0)] = 63\n\nfunction getLens (b64) {\n  var len = b64.length\n\n  if (len % 4 > 0) {\n    throw new Error('Invalid string. Length must be a multiple of 4')\n  }\n\n  // Trim off extra bytes after placeholder bytes are found\n  // See: https://github.com/beatgammit/base64-js/issues/42\n  var validLen = b64.indexOf('=')\n  if (validLen === -1) validLen = len\n\n  var placeHoldersLen = validLen === len\n    ? 0\n    : 4 - (validLen % 4)\n\n  return [validLen, placeHoldersLen]\n}\n\n// base64 is 4/3 + up to two characters of the original data\nfunction byteLength (b64) {\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction _byteLength (b64, validLen, placeHoldersLen) {\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction toByteArray (b64) {\n  var tmp\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n\n  var arr = new Arr(_byteLength(b64, validLen, placeHoldersLen))\n\n  var curByte = 0\n\n  // if there are placeholders, only get up to the last complete 4 chars\n  var len = placeHoldersLen > 0\n    ? validLen - 4\n    : validLen\n\n  for (var i = 0; i < len; i += 4) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 18) |\n      (revLookup[b64.charCodeAt(i + 1)] << 12) |\n      (revLookup[b64.charCodeAt(i + 2)] << 6) |\n      revLookup[b64.charCodeAt(i + 3)]\n    arr[curByte++] = (tmp >> 16) & 0xFF\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 2) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 2) |\n      (revLookup[b64.charCodeAt(i + 1)] >> 4)\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 1) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 10) |\n      (revLookup[b64.charCodeAt(i + 1)] << 4) |\n      (revLookup[b64.charCodeAt(i + 2)] >> 2)\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  return arr\n}\n\nfunction tripletToBase64 (num) {\n  return lookup[num >> 18 & 0x3F] +\n    lookup[num >> 12 & 0x3F] +\n    lookup[num >> 6 & 0x3F] +\n    lookup[num & 0x3F]\n}\n\nfunction encodeChunk (uint8, start, end) {\n  var tmp\n  var output = []\n  for (var i = start; i < end; i += 3) {\n    tmp =\n      ((uint8[i] << 16) & 0xFF0000) +\n      ((uint8[i + 1] << 8) & 0xFF00) +\n      (uint8[i + 2] & 0xFF)\n    output.push(tripletToBase64(tmp))\n  }\n  return output.join('')\n}\n\nfunction fromByteArray (uint8) {\n  var tmp\n  var len = uint8.length\n  var extraBytes = len % 3 // if we have 1 byte left, pad 2 bytes\n  var parts = []\n  var maxChunkLength = 16383 // must be multiple of 3\n\n  // go through the array every three bytes, we'll deal with trailing stuff later\n  for (var i = 0, len2 = len - extraBytes; i < len2; i += maxChunkLength) {\n    parts.push(encodeChunk(\n      uint8, i, (i + maxChunkLength) > len2 ? len2 : (i + maxChunkLength)\n    ))\n  }\n\n  // pad the end with zeros, but make sure to not forget the extra bytes\n  if (extraBytes === 1) {\n    tmp = uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 2] +\n      lookup[(tmp << 4) & 0x3F] +\n      '=='\n    )\n  } else if (extraBytes === 2) {\n    tmp = (uint8[len - 2] << 8) + uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 10] +\n      lookup[(tmp >> 4) & 0x3F] +\n      lookup[(tmp << 2) & 0x3F] +\n      '='\n    )\n  }\n\n  return parts.join('')\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/es6/promise.js\":\n/*!*********************************************!*\\\n  !*** ./node_modules/core-js/es6/promise.js ***!\n  \\*********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../modules/es6.object.to-string */ \"./node_modules/core-js/modules/es6.object.to-string.js\");\n__webpack_require__(/*! ../modules/es6.string.iterator */ \"./node_modules/core-js/modules/es6.string.iterator.js\");\n__webpack_require__(/*! ../modules/web.dom.iterable */ \"./node_modules/core-js/modules/web.dom.iterable.js\");\n__webpack_require__(/*! ../modules/es6.promise */ \"./node_modules/core-js/modules/es6.promise.js\");\nmodule.exports = __webpack_require__(/*! ../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Promise;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/array/find.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/fn/array/find.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/es6.array.find */ \"./node_modules/core-js/modules/es6.array.find.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Array.find;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/array/is-array.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/fn/array/is-array.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/es6.array.is-array */ \"./node_modules/core-js/modules/es6.array.is-array.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Array.isArray;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/array/some.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/fn/array/some.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/es6.array.some */ \"./node_modules/core-js/modules/es6.array.some.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Array.some;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/array/splice.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/fn/array/splice.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// for a legacy code and future fixes\nmodule.exports = function () {\n  return Function.call.apply(Array.prototype.splice, arguments);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/function/bind.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/fn/function/bind.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/es6.function.bind */ \"./node_modules/core-js/modules/es6.function.bind.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Function.bind;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/object/assign.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/fn/object/assign.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/es6.object.assign */ \"./node_modules/core-js/modules/es6.object.assign.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Object.assign;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_a-function.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_a-function.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it) {\n  if (typeof it != 'function') throw TypeError(it + ' is not a function!');\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_add-to-unscopables.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_add-to-unscopables.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.3.31 Array.prototype[@@unscopables]\nvar UNSCOPABLES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('unscopables');\nvar ArrayProto = Array.prototype;\nif (ArrayProto[UNSCOPABLES] == undefined) __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")(ArrayProto, UNSCOPABLES, {});\nmodule.exports = function (key) {\n  ArrayProto[UNSCOPABLES][key] = true;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_an-instance.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_an-instance.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it, Constructor, name, forbiddenField) {\n  if (!(it instanceof Constructor) || (forbiddenField !== undefined && forbiddenField in it)) {\n    throw TypeError(name + ': incorrect invocation!');\n  } return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_an-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_an-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nmodule.exports = function (it) {\n  if (!isObject(it)) throw TypeError(it + ' is not an object!');\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-includes.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-includes.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// false -> Array#indexOf\n// true  -> Array#includes\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nmodule.exports = function (IS_INCLUDES) {\n  return function ($this, el, fromIndex) {\n    var O = toIObject($this);\n    var length = toLength(O.length);\n    var index = toAbsoluteIndex(fromIndex, length);\n    var value;\n    // Array#includes uses SameValueZero equality algorithm\n    // eslint-disable-next-line no-self-compare\n    if (IS_INCLUDES && el != el) while (length > index) {\n      value = O[index++];\n      // eslint-disable-next-line no-self-compare\n      if (value != value) return true;\n    // Array#indexOf ignores holes, Array#includes - not\n    } else for (;length > index; index++) if (IS_INCLUDES || index in O) {\n      if (O[index] === el) return IS_INCLUDES || index || 0;\n    } return !IS_INCLUDES && -1;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-methods.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-methods.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 0 -> Array#forEach\n// 1 -> Array#map\n// 2 -> Array#filter\n// 3 -> Array#some\n// 4 -> Array#every\n// 5 -> Array#find\n// 6 -> Array#findIndex\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar asc = __webpack_require__(/*! ./_array-species-create */ \"./node_modules/core-js/modules/_array-species-create.js\");\nmodule.exports = function (TYPE, $create) {\n  var IS_MAP = TYPE == 1;\n  var IS_FILTER = TYPE == 2;\n  var IS_SOME = TYPE == 3;\n  var IS_EVERY = TYPE == 4;\n  var IS_FIND_INDEX = TYPE == 6;\n  var NO_HOLES = TYPE == 5 || IS_FIND_INDEX;\n  var create = $create || asc;\n  return function ($this, callbackfn, that) {\n    var O = toObject($this);\n    var self = IObject(O);\n    var f = ctx(callbackfn, that, 3);\n    var length = toLength(self.length);\n    var index = 0;\n    var result = IS_MAP ? create($this, length) : IS_FILTER ? create($this, 0) : undefined;\n    var val, res;\n    for (;length > index; index++) if (NO_HOLES || index in self) {\n      val = self[index];\n      res = f(val, index, O);\n      if (TYPE) {\n        if (IS_MAP) result[index] = res;   // map\n        else if (res) switch (TYPE) {\n          case 3: return true;             // some\n          case 5: return val;              // find\n          case 6: return index;            // findIndex\n          case 2: result.push(val);        // filter\n        } else if (IS_EVERY) return false; // every\n      }\n    }\n    return IS_FIND_INDEX ? -1 : IS_SOME || IS_EVERY ? IS_EVERY : result;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-species-constructor.js\":\n/*!********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-species-constructor.js ***!\n  \\********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar isArray = __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\n\nmodule.exports = function (original) {\n  var C;\n  if (isArray(original)) {\n    C = original.constructor;\n    // cross-realm fallback\n    if (typeof C == 'function' && (C === Array || isArray(C.prototype))) C = undefined;\n    if (isObject(C)) {\n      C = C[SPECIES];\n      if (C === null) C = undefined;\n    }\n  } return C === undefined ? Array : C;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-species-create.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-species-create.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 9.4.2.3 ArraySpeciesCreate(originalArray, length)\nvar speciesConstructor = __webpack_require__(/*! ./_array-species-constructor */ \"./node_modules/core-js/modules/_array-species-constructor.js\");\n\nmodule.exports = function (original, length) {\n  return new (speciesConstructor(original))(length);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_bind.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_bind.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar invoke = __webpack_require__(/*! ./_invoke */ \"./node_modules/core-js/modules/_invoke.js\");\nvar arraySlice = [].slice;\nvar factories = {};\n\nvar construct = function (F, len, args) {\n  if (!(len in factories)) {\n    for (var n = [], i = 0; i < len; i++) n[i] = 'a[' + i + ']';\n    // eslint-disable-next-line no-new-func\n    factories[len] = Function('F,a', 'return new F(' + n.join(',') + ')');\n  } return factories[len](F, args);\n};\n\nmodule.exports = Function.bind || function bind(that /* , ...args */) {\n  var fn = aFunction(this);\n  var partArgs = arraySlice.call(arguments, 1);\n  var bound = function (/* args... */) {\n    var args = partArgs.concat(arraySlice.call(arguments));\n    return this instanceof bound ? construct(fn, args.length, args) : invoke(fn, args, that);\n  };\n  if (isObject(fn.prototype)) bound.prototype = fn.prototype;\n  return bound;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_classof.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_classof.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// getting tag from 19.1.3.6 Object.prototype.toString()\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nvar TAG = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag');\n// ES3 wrong here\nvar ARG = cof(function () { return arguments; }()) == 'Arguments';\n\n// fallback for IE11 Script Access Denied error\nvar tryGet = function (it, key) {\n  try {\n    return it[key];\n  } catch (e) { /* empty */ }\n};\n\nmodule.exports = function (it) {\n  var O, T, B;\n  return it === undefined ? 'Undefined' : it === null ? 'Null'\n    // @@toStringTag case\n    : typeof (T = tryGet(O = Object(it), TAG)) == 'string' ? T\n    // builtinTag case\n    : ARG ? cof(O)\n    // ES3 arguments fallback\n    : (B = cof(O)) == 'Object' && typeof O.callee == 'function' ? 'Arguments' : B;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_cof.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_cof.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar toString = {}.toString;\n\nmodule.exports = function (it) {\n  return toString.call(it).slice(8, -1);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_core.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_core.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar core = module.exports = { version: '2.6.4' };\nif (typeof __e == 'number') __e = core; // eslint-disable-line no-undef\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_ctx.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_ctx.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// optional / simple context binding\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nmodule.exports = function (fn, that, length) {\n  aFunction(fn);\n  if (that === undefined) return fn;\n  switch (length) {\n    case 1: return function (a) {\n      return fn.call(that, a);\n    };\n    case 2: return function (a, b) {\n      return fn.call(that, a, b);\n    };\n    case 3: return function (a, b, c) {\n      return fn.call(that, a, b, c);\n    };\n  }\n  return function (/* ...args */) {\n    return fn.apply(that, arguments);\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_defined.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_defined.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 7.2.1 RequireObjectCoercible(argument)\nmodule.exports = function (it) {\n  if (it == undefined) throw TypeError(\"Can't call method on  \" + it);\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_descriptors.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_descriptors.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// Thank's IE8 for his funny defineProperty\nmodule.exports = !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return Object.defineProperty({}, 'a', { get: function () { return 7; } }).a != 7;\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_dom-create.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_dom-create.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar document = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").document;\n// typeof document.createElement is 'object' in old IE\nvar is = isObject(document) && isObject(document.createElement);\nmodule.exports = function (it) {\n  return is ? document.createElement(it) : {};\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_enum-bug-keys.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_enum-bug-keys.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// IE 8- don't enum bug keys\nmodule.exports = (\n  'constructor,hasOwnProperty,isPrototypeOf,propertyIsEnumerable,toLocaleString,toString,valueOf'\n).split(',');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_export.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_export.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar PROTOTYPE = 'prototype';\n\nvar $export = function (type, name, source) {\n  var IS_FORCED = type & $export.F;\n  var IS_GLOBAL = type & $export.G;\n  var IS_STATIC = type & $export.S;\n  var IS_PROTO = type & $export.P;\n  var IS_BIND = type & $export.B;\n  var target = IS_GLOBAL ? global : IS_STATIC ? global[name] || (global[name] = {}) : (global[name] || {})[PROTOTYPE];\n  var exports = IS_GLOBAL ? core : core[name] || (core[name] = {});\n  var expProto = exports[PROTOTYPE] || (exports[PROTOTYPE] = {});\n  var key, own, out, exp;\n  if (IS_GLOBAL) source = name;\n  for (key in source) {\n    // contains in native\n    own = !IS_FORCED && target && target[key] !== undefined;\n    // export native or passed\n    out = (own ? target : source)[key];\n    // bind timers to global for call from export context\n    exp = IS_BIND && own ? ctx(out, global) : IS_PROTO && typeof out == 'function' ? ctx(Function.call, out) : out;\n    // extend global\n    if (target) redefine(target, key, out, type & $export.U);\n    // export\n    if (exports[key] != out) hide(exports, key, exp);\n    if (IS_PROTO && expProto[key] != out) expProto[key] = out;\n  }\n};\nglobal.core = core;\n// type bitmap\n$export.F = 1;   // forced\n$export.G = 2;   // global\n$export.S = 4;   // static\n$export.P = 8;   // proto\n$export.B = 16;  // bind\n$export.W = 32;  // wrap\n$export.U = 64;  // safe\n$export.R = 128; // real proto method for `library`\nmodule.exports = $export;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_fails.js\":\n/*!************************************************!*\\\n  !*** ./node_modules/core-js/modules/_fails.js ***!\n  \\************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (exec) {\n  try {\n    return !!exec();\n  } catch (e) {\n    return true;\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_for-of.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_for-of.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar call = __webpack_require__(/*! ./_iter-call */ \"./node_modules/core-js/modules/_iter-call.js\");\nvar isArrayIter = __webpack_require__(/*! ./_is-array-iter */ \"./node_modules/core-js/modules/_is-array-iter.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar getIterFn = __webpack_require__(/*! ./core.get-iterator-method */ \"./node_modules/core-js/modules/core.get-iterator-method.js\");\nvar BREAK = {};\nvar RETURN = {};\nvar exports = module.exports = function (iterable, entries, fn, that, ITERATOR) {\n  var iterFn = ITERATOR ? function () { return iterable; } : getIterFn(iterable);\n  var f = ctx(fn, that, entries ? 2 : 1);\n  var index = 0;\n  var length, step, iterator, result;\n  if (typeof iterFn != 'function') throw TypeError(iterable + ' is not iterable!');\n  // fast case for arrays with default iterator\n  if (isArrayIter(iterFn)) for (length = toLength(iterable.length); length > index; index++) {\n    result = entries ? f(anObject(step = iterable[index])[0], step[1]) : f(iterable[index]);\n    if (result === BREAK || result === RETURN) return result;\n  } else for (iterator = iterFn.call(iterable); !(step = iterator.next()).done;) {\n    result = call(iterator, f, step.value, entries);\n    if (result === BREAK || result === RETURN) return result;\n  }\n};\nexports.BREAK = BREAK;\nexports.RETURN = RETURN;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_function-to-string.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_function-to-string.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nmodule.exports = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('native-function-to-string', Function.toString);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_global.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_global.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// https://github.com/zloirock/core-js/issues/86#issuecomment-115759028\nvar global = module.exports = typeof window != 'undefined' && window.Math == Math\n  ? window : typeof self != 'undefined' && self.Math == Math ? self\n  // eslint-disable-next-line no-new-func\n  : Function('return this')();\nif (typeof __g == 'number') __g = global; // eslint-disable-line no-undef\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_has.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_has.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar hasOwnProperty = {}.hasOwnProperty;\nmodule.exports = function (it, key) {\n  return hasOwnProperty.call(it, key);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_hide.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_hide.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nmodule.exports = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? function (object, key, value) {\n  return dP.f(object, key, createDesc(1, value));\n} : function (object, key, value) {\n  object[key] = value;\n  return object;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_html.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_html.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar document = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").document;\nmodule.exports = document && document.documentElement;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_ie8-dom-define.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_ie8-dom-define.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nmodule.exports = !__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return Object.defineProperty(__webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\")('div'), 'a', { get: function () { return 7; } }).a != 7;\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_invoke.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_invoke.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// fast apply, http://jsperf.lnkit.com/fast-apply/5\nmodule.exports = function (fn, args, that) {\n  var un = that === undefined;\n  switch (args.length) {\n    case 0: return un ? fn()\n                      : fn.call(that);\n    case 1: return un ? fn(args[0])\n                      : fn.call(that, args[0]);\n    case 2: return un ? fn(args[0], args[1])\n                      : fn.call(that, args[0], args[1]);\n    case 3: return un ? fn(args[0], args[1], args[2])\n                      : fn.call(that, args[0], args[1], args[2]);\n    case 4: return un ? fn(args[0], args[1], args[2], args[3])\n                      : fn.call(that, args[0], args[1], args[2], args[3]);\n  } return fn.apply(that, args);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iobject.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iobject.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// fallback for non-array-like ES3 and non-enumerable old V8 strings\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\n// eslint-disable-next-line no-prototype-builtins\nmodule.exports = Object('z').propertyIsEnumerable(0) ? Object : function (it) {\n  return cof(it) == 'String' ? it.split('') : Object(it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-array-iter.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-array-iter.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// check on default Array iterator\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar ArrayProto = Array.prototype;\n\nmodule.exports = function (it) {\n  return it !== undefined && (Iterators.Array === it || ArrayProto[ITERATOR] === it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-array.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-array.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.2.2 IsArray(argument)\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nmodule.exports = Array.isArray || function isArray(arg) {\n  return cof(arg) == 'Array';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it) {\n  return typeof it === 'object' ? it !== null : typeof it === 'function';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-call.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-call.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// call something on iterator step with safe closing on error\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nmodule.exports = function (iterator, fn, value, entries) {\n  try {\n    return entries ? fn(anObject(value)[0], value[1]) : fn(value);\n  // 7.4.6 IteratorClose(iterator, completion)\n  } catch (e) {\n    var ret = iterator['return'];\n    if (ret !== undefined) anObject(ret.call(iterator));\n    throw e;\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-create.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-create.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\nvar descriptor = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar IteratorPrototype = {};\n\n// 25.1.2.1.1 %IteratorPrototype%[@@iterator]()\n__webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")(IteratorPrototype, __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator'), function () { return this; });\n\nmodule.exports = function (Constructor, NAME, next) {\n  Constructor.prototype = create(IteratorPrototype, { next: descriptor(1, next) });\n  setToStringTag(Constructor, NAME + ' Iterator');\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-define.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-define.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar $iterCreate = __webpack_require__(/*! ./_iter-create */ \"./node_modules/core-js/modules/_iter-create.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar BUGGY = !([].keys && 'next' in [].keys()); // Safari has buggy iterators w/o `next`\nvar FF_ITERATOR = '@@iterator';\nvar KEYS = 'keys';\nvar VALUES = 'values';\n\nvar returnThis = function () { return this; };\n\nmodule.exports = function (Base, NAME, Constructor, next, DEFAULT, IS_SET, FORCED) {\n  $iterCreate(Constructor, NAME, next);\n  var getMethod = function (kind) {\n    if (!BUGGY && kind in proto) return proto[kind];\n    switch (kind) {\n      case KEYS: return function keys() { return new Constructor(this, kind); };\n      case VALUES: return function values() { return new Constructor(this, kind); };\n    } return function entries() { return new Constructor(this, kind); };\n  };\n  var TAG = NAME + ' Iterator';\n  var DEF_VALUES = DEFAULT == VALUES;\n  var VALUES_BUG = false;\n  var proto = Base.prototype;\n  var $native = proto[ITERATOR] || proto[FF_ITERATOR] || DEFAULT && proto[DEFAULT];\n  var $default = $native || getMethod(DEFAULT);\n  var $entries = DEFAULT ? !DEF_VALUES ? $default : getMethod('entries') : undefined;\n  var $anyNative = NAME == 'Array' ? proto.entries || $native : $native;\n  var methods, key, IteratorPrototype;\n  // Fix native\n  if ($anyNative) {\n    IteratorPrototype = getPrototypeOf($anyNative.call(new Base()));\n    if (IteratorPrototype !== Object.prototype && IteratorPrototype.next) {\n      // Set @@toStringTag to native iterators\n      setToStringTag(IteratorPrototype, TAG, true);\n      // fix for some old engines\n      if (!LIBRARY && typeof IteratorPrototype[ITERATOR] != 'function') hide(IteratorPrototype, ITERATOR, returnThis);\n    }\n  }\n  // fix Array#{values, @@iterator}.name in V8 / FF\n  if (DEF_VALUES && $native && $native.name !== VALUES) {\n    VALUES_BUG = true;\n    $default = function values() { return $native.call(this); };\n  }\n  // Define iterator\n  if ((!LIBRARY || FORCED) && (BUGGY || VALUES_BUG || !proto[ITERATOR])) {\n    hide(proto, ITERATOR, $default);\n  }\n  // Plug for library\n  Iterators[NAME] = $default;\n  Iterators[TAG] = returnThis;\n  if (DEFAULT) {\n    methods = {\n      values: DEF_VALUES ? $default : getMethod(VALUES),\n      keys: IS_SET ? $default : getMethod(KEYS),\n      entries: $entries\n    };\n    if (FORCED) for (key in methods) {\n      if (!(key in proto)) redefine(proto, key, methods[key]);\n    } else $export($export.P + $export.F * (BUGGY || VALUES_BUG), NAME, methods);\n  }\n  return methods;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-detect.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-detect.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar SAFE_CLOSING = false;\n\ntry {\n  var riter = [7][ITERATOR]();\n  riter['return'] = function () { SAFE_CLOSING = true; };\n  // eslint-disable-next-line no-throw-literal\n  Array.from(riter, function () { throw 2; });\n} catch (e) { /* empty */ }\n\nmodule.exports = function (exec, skipClosing) {\n  if (!skipClosing && !SAFE_CLOSING) return false;\n  var safe = false;\n  try {\n    var arr = [7];\n    var iter = arr[ITERATOR]();\n    iter.next = function () { return { done: safe = true }; };\n    arr[ITERATOR] = function () { return iter; };\n    exec(arr);\n  } catch (e) { /* empty */ }\n  return safe;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-step.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-step.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (done, value) {\n  return { value: value, done: !!done };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iterators.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iterators.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = {};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_library.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_library.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = false;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_microtask.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_microtask.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar macrotask = __webpack_require__(/*! ./_task */ \"./node_modules/core-js/modules/_task.js\").set;\nvar Observer = global.MutationObserver || global.WebKitMutationObserver;\nvar process = global.process;\nvar Promise = global.Promise;\nvar isNode = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\")(process) == 'process';\n\nmodule.exports = function () {\n  var head, last, notify;\n\n  var flush = function () {\n    var parent, fn;\n    if (isNode && (parent = process.domain)) parent.exit();\n    while (head) {\n      fn = head.fn;\n      head = head.next;\n      try {\n        fn();\n      } catch (e) {\n        if (head) notify();\n        else last = undefined;\n        throw e;\n      }\n    } last = undefined;\n    if (parent) parent.enter();\n  };\n\n  // Node.js\n  if (isNode) {\n    notify = function () {\n      process.nextTick(flush);\n    };\n  // browsers with MutationObserver, except iOS Safari - https://github.com/zloirock/core-js/issues/339\n  } else if (Observer && !(global.navigator && global.navigator.standalone)) {\n    var toggle = true;\n    var node = document.createTextNode('');\n    new Observer(flush).observe(node, { characterData: true }); // eslint-disable-line no-new\n    notify = function () {\n      node.data = toggle = !toggle;\n    };\n  // environments with maybe non-completely correct, but existent Promise\n  } else if (Promise && Promise.resolve) {\n    // Promise.resolve without an argument throws an error in LG WebOS 2\n    var promise = Promise.resolve(undefined);\n    notify = function () {\n      promise.then(flush);\n    };\n  // for other environments - macrotask based on:\n  // - setImmediate\n  // - MessageChannel\n  // - window.postMessag\n  // - onreadystatechange\n  // - setTimeout\n  } else {\n    notify = function () {\n      // strange IE + webpack dev server bug - use .call(global)\n      macrotask.call(global, flush);\n    };\n  }\n\n  return function (fn) {\n    var task = { fn: fn, next: undefined };\n    if (last) last.next = task;\n    if (!head) {\n      head = task;\n      notify();\n    } last = task;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_new-promise-capability.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_new-promise-capability.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 25.4.1.5 NewPromiseCapability(C)\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\n\nfunction PromiseCapability(C) {\n  var resolve, reject;\n  this.promise = new C(function ($$resolve, $$reject) {\n    if (resolve !== undefined || reject !== undefined) throw TypeError('Bad Promise constructor');\n    resolve = $$resolve;\n    reject = $$reject;\n  });\n  this.resolve = aFunction(resolve);\n  this.reject = aFunction(reject);\n}\n\nmodule.exports.f = function (C) {\n  return new PromiseCapability(C);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-assign.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-assign.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 19.1.2.1 Object.assign(target, source, ...)\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar gOPS = __webpack_require__(/*! ./_object-gops */ \"./node_modules/core-js/modules/_object-gops.js\");\nvar pIE = __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar $assign = Object.assign;\n\n// should work with symbols and should have deterministic property order (V8 bug)\nmodule.exports = !$assign || __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  var A = {};\n  var B = {};\n  // eslint-disable-next-line no-undef\n  var S = Symbol();\n  var K = 'abcdefghijklmnopqrst';\n  A[S] = 7;\n  K.split('').forEach(function (k) { B[k] = k; });\n  return $assign({}, A)[S] != 7 || Object.keys($assign({}, B)).join('') != K;\n}) ? function assign(target, source) { // eslint-disable-line no-unused-vars\n  var T = toObject(target);\n  var aLen = arguments.length;\n  var index = 1;\n  var getSymbols = gOPS.f;\n  var isEnum = pIE.f;\n  while (aLen > index) {\n    var S = IObject(arguments[index++]);\n    var keys = getSymbols ? getKeys(S).concat(getSymbols(S)) : getKeys(S);\n    var length = keys.length;\n    var j = 0;\n    var key;\n    while (length > j) if (isEnum.call(S, key = keys[j++])) T[key] = S[key];\n  } return T;\n} : $assign;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-create.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-create.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar dPs = __webpack_require__(/*! ./_object-dps */ \"./node_modules/core-js/modules/_object-dps.js\");\nvar enumBugKeys = __webpack_require__(/*! ./_enum-bug-keys */ \"./node_modules/core-js/modules/_enum-bug-keys.js\");\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\nvar Empty = function () { /* empty */ };\nvar PROTOTYPE = 'prototype';\n\n// Create object with fake `null` prototype: use iframe Object with cleared prototype\nvar createDict = function () {\n  // Thrash, waste and sodomy: IE GC bug\n  var iframe = __webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\")('iframe');\n  var i = enumBugKeys.length;\n  var lt = '<';\n  var gt = '>';\n  var iframeDocument;\n  iframe.style.display = 'none';\n  __webpack_require__(/*! ./_html */ \"./node_modules/core-js/modules/_html.js\").appendChild(iframe);\n  iframe.src = 'javascript:'; // eslint-disable-line no-script-url\n  // createDict = iframe.contentWindow.Object;\n  // html.removeChild(iframe);\n  iframeDocument = iframe.contentWindow.document;\n  iframeDocument.open();\n  iframeDocument.write(lt + 'script' + gt + 'document.F=Object' + lt + '/script' + gt);\n  iframeDocument.close();\n  createDict = iframeDocument.F;\n  while (i--) delete createDict[PROTOTYPE][enumBugKeys[i]];\n  return createDict();\n};\n\nmodule.exports = Object.create || function create(O, Properties) {\n  var result;\n  if (O !== null) {\n    Empty[PROTOTYPE] = anObject(O);\n    result = new Empty();\n    Empty[PROTOTYPE] = null;\n    // add \"__proto__\" for Object.getPrototypeOf polyfill\n    result[IE_PROTO] = O;\n  } else result = createDict();\n  return Properties === undefined ? result : dPs(result, Properties);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-dp.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-dp.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar IE8_DOM_DEFINE = __webpack_require__(/*! ./_ie8-dom-define */ \"./node_modules/core-js/modules/_ie8-dom-define.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar dP = Object.defineProperty;\n\nexports.f = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? Object.defineProperty : function defineProperty(O, P, Attributes) {\n  anObject(O);\n  P = toPrimitive(P, true);\n  anObject(Attributes);\n  if (IE8_DOM_DEFINE) try {\n    return dP(O, P, Attributes);\n  } catch (e) { /* empty */ }\n  if ('get' in Attributes || 'set' in Attributes) throw TypeError('Accessors not supported!');\n  if ('value' in Attributes) O[P] = Attributes.value;\n  return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-dps.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-dps.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\n\nmodule.exports = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? Object.defineProperties : function defineProperties(O, Properties) {\n  anObject(O);\n  var keys = getKeys(Properties);\n  var length = keys.length;\n  var i = 0;\n  var P;\n  while (length > i) dP.f(O, P = keys[i++], Properties[P]);\n  return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gops.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gops.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.f = Object.getOwnPropertySymbols;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gpo.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gpo.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.9 / 15.2.3.2 Object.getPrototypeOf(O)\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\nvar ObjectProto = Object.prototype;\n\nmodule.exports = Object.getPrototypeOf || function (O) {\n  O = toObject(O);\n  if (has(O, IE_PROTO)) return O[IE_PROTO];\n  if (typeof O.constructor == 'function' && O instanceof O.constructor) {\n    return O.constructor.prototype;\n  } return O instanceof Object ? ObjectProto : null;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-keys-internal.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-keys-internal.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar arrayIndexOf = __webpack_require__(/*! ./_array-includes */ \"./node_modules/core-js/modules/_array-includes.js\")(false);\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\n\nmodule.exports = function (object, names) {\n  var O = toIObject(object);\n  var i = 0;\n  var result = [];\n  var key;\n  for (key in O) if (key != IE_PROTO) has(O, key) && result.push(key);\n  // Don't enum bug & hidden keys\n  while (names.length > i) if (has(O, key = names[i++])) {\n    ~arrayIndexOf(result, key) || result.push(key);\n  }\n  return result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-keys.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-keys.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.14 / 15.2.3.14 Object.keys(O)\nvar $keys = __webpack_require__(/*! ./_object-keys-internal */ \"./node_modules/core-js/modules/_object-keys-internal.js\");\nvar enumBugKeys = __webpack_require__(/*! ./_enum-bug-keys */ \"./node_modules/core-js/modules/_enum-bug-keys.js\");\n\nmodule.exports = Object.keys || function keys(O) {\n  return $keys(O, enumBugKeys);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-pie.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-pie.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.f = {}.propertyIsEnumerable;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_perform.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_perform.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (exec) {\n  try {\n    return { e: false, v: exec() };\n  } catch (e) {\n    return { e: true, v: e };\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_promise-resolve.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_promise-resolve.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar newPromiseCapability = __webpack_require__(/*! ./_new-promise-capability */ \"./node_modules/core-js/modules/_new-promise-capability.js\");\n\nmodule.exports = function (C, x) {\n  anObject(C);\n  if (isObject(x) && x.constructor === C) return x;\n  var promiseCapability = newPromiseCapability.f(C);\n  var resolve = promiseCapability.resolve;\n  resolve(x);\n  return promiseCapability.promise;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_property-desc.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_property-desc.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (bitmap, value) {\n  return {\n    enumerable: !(bitmap & 1),\n    configurable: !(bitmap & 2),\n    writable: !(bitmap & 4),\n    value: value\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_redefine-all.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_redefine-all.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nmodule.exports = function (target, src, safe) {\n  for (var key in src) redefine(target, key, src[key], safe);\n  return target;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_redefine.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_redefine.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar SRC = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\")('src');\nvar $toString = __webpack_require__(/*! ./_function-to-string */ \"./node_modules/core-js/modules/_function-to-string.js\");\nvar TO_STRING = 'toString';\nvar TPL = ('' + $toString).split(TO_STRING);\n\n__webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\").inspectSource = function (it) {\n  return $toString.call(it);\n};\n\n(module.exports = function (O, key, val, safe) {\n  var isFunction = typeof val == 'function';\n  if (isFunction) has(val, 'name') || hide(val, 'name', key);\n  if (O[key] === val) return;\n  if (isFunction) has(val, SRC) || hide(val, SRC, O[key] ? '' + O[key] : TPL.join(String(key)));\n  if (O === global) {\n    O[key] = val;\n  } else if (!safe) {\n    delete O[key];\n    hide(O, key, val);\n  } else if (O[key]) {\n    O[key] = val;\n  } else {\n    hide(O, key, val);\n  }\n// add fake Function#toString for correct work wrapped methods / constructors with methods like LoDash isNative\n})(Function.prototype, TO_STRING, function toString() {\n  return typeof this == 'function' && this[SRC] || $toString.call(this);\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-species.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-species.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\n\nmodule.exports = function (KEY) {\n  var C = global[KEY];\n  if (DESCRIPTORS && C && !C[SPECIES]) dP.f(C, SPECIES, {\n    configurable: true,\n    get: function () { return this; }\n  });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-to-string-tag.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-to-string-tag.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar def = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar TAG = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag');\n\nmodule.exports = function (it, tag, stat) {\n  if (it && !has(it = stat ? it : it.prototype, TAG)) def(it, TAG, { configurable: true, value: tag });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_shared-key.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_shared-key.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar shared = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('keys');\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nmodule.exports = function (key) {\n  return shared[key] || (shared[key] = uid(key));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_shared.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_shared.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar SHARED = '__core-js_shared__';\nvar store = global[SHARED] || (global[SHARED] = {});\n\n(module.exports = function (key, value) {\n  return store[key] || (store[key] = value !== undefined ? value : {});\n})('versions', []).push({\n  version: core.version,\n  mode: __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\") ? 'pure' : 'global',\n  copyright: '© 2019 Denis Pushkarev (zloirock.ru)'\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_species-constructor.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_species-constructor.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.3.20 SpeciesConstructor(O, defaultConstructor)\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\nmodule.exports = function (O, D) {\n  var C = anObject(O).constructor;\n  var S;\n  return C === undefined || (S = anObject(C)[SPECIES]) == undefined ? D : aFunction(S);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_strict-method.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_strict-method.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\n\nmodule.exports = function (method, arg) {\n  return !!method && fails(function () {\n    // eslint-disable-next-line no-useless-call\n    arg ? method.call(null, function () { /* empty */ }, 1) : method.call(null);\n  });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-at.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-at.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\n// true  -> String#at\n// false -> String#codePointAt\nmodule.exports = function (TO_STRING) {\n  return function (that, pos) {\n    var s = String(defined(that));\n    var i = toInteger(pos);\n    var l = s.length;\n    var a, b;\n    if (i < 0 || i >= l) return TO_STRING ? '' : undefined;\n    a = s.charCodeAt(i);\n    return a < 0xd800 || a > 0xdbff || i + 1 === l || (b = s.charCodeAt(i + 1)) < 0xdc00 || b > 0xdfff\n      ? TO_STRING ? s.charAt(i) : a\n      : TO_STRING ? s.slice(i, i + 2) : (a - 0xd800 << 10) + (b - 0xdc00) + 0x10000;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_task.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_task.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar invoke = __webpack_require__(/*! ./_invoke */ \"./node_modules/core-js/modules/_invoke.js\");\nvar html = __webpack_require__(/*! ./_html */ \"./node_modules/core-js/modules/_html.js\");\nvar cel = __webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar process = global.process;\nvar setTask = global.setImmediate;\nvar clearTask = global.clearImmediate;\nvar MessageChannel = global.MessageChannel;\nvar Dispatch = global.Dispatch;\nvar counter = 0;\nvar queue = {};\nvar ONREADYSTATECHANGE = 'onreadystatechange';\nvar defer, channel, port;\nvar run = function () {\n  var id = +this;\n  // eslint-disable-next-line no-prototype-builtins\n  if (queue.hasOwnProperty(id)) {\n    var fn = queue[id];\n    delete queue[id];\n    fn();\n  }\n};\nvar listener = function (event) {\n  run.call(event.data);\n};\n// Node.js 0.9+ & IE10+ has setImmediate, otherwise:\nif (!setTask || !clearTask) {\n  setTask = function setImmediate(fn) {\n    var args = [];\n    var i = 1;\n    while (arguments.length > i) args.push(arguments[i++]);\n    queue[++counter] = function () {\n      // eslint-disable-next-line no-new-func\n      invoke(typeof fn == 'function' ? fn : Function(fn), args);\n    };\n    defer(counter);\n    return counter;\n  };\n  clearTask = function clearImmediate(id) {\n    delete queue[id];\n  };\n  // Node.js 0.8-\n  if (__webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\")(process) == 'process') {\n    defer = function (id) {\n      process.nextTick(ctx(run, id, 1));\n    };\n  // Sphere (JS game engine) Dispatch API\n  } else if (Dispatch && Dispatch.now) {\n    defer = function (id) {\n      Dispatch.now(ctx(run, id, 1));\n    };\n  // Browsers with MessageChannel, includes WebWorkers\n  } else if (MessageChannel) {\n    channel = new MessageChannel();\n    port = channel.port2;\n    channel.port1.onmessage = listener;\n    defer = ctx(port.postMessage, port, 1);\n  // Browsers with postMessage, skip WebWorkers\n  // IE8 has postMessage, but it's sync & typeof its postMessage is 'object'\n  } else if (global.addEventListener && typeof postMessage == 'function' && !global.importScripts) {\n    defer = function (id) {\n      global.postMessage(id + '', '*');\n    };\n    global.addEventListener('message', listener, false);\n  // IE8-\n  } else if (ONREADYSTATECHANGE in cel('script')) {\n    defer = function (id) {\n      html.appendChild(cel('script'))[ONREADYSTATECHANGE] = function () {\n        html.removeChild(this);\n        run.call(id);\n      };\n    };\n  // Rest old browsers\n  } else {\n    defer = function (id) {\n      setTimeout(ctx(run, id, 1), 0);\n    };\n  }\n}\nmodule.exports = {\n  set: setTask,\n  clear: clearTask\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-absolute-index.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-absolute-index.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar max = Math.max;\nvar min = Math.min;\nmodule.exports = function (index, length) {\n  index = toInteger(index);\n  return index < 0 ? max(index + length, 0) : min(index, length);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-integer.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-integer.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 7.1.4 ToInteger\nvar ceil = Math.ceil;\nvar floor = Math.floor;\nmodule.exports = function (it) {\n  return isNaN(it = +it) ? 0 : (it > 0 ? floor : ceil)(it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-iobject.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-iobject.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// to indexed object, toObject with fallback for non-array-like ES3 strings\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nmodule.exports = function (it) {\n  return IObject(defined(it));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-length.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-length.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.15 ToLength\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar min = Math.min;\nmodule.exports = function (it) {\n  return it > 0 ? min(toInteger(it), 0x1fffffffffffff) : 0; // pow(2, 53) - 1 == 9007199254740991\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.13 ToObject(argument)\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nmodule.exports = function (it) {\n  return Object(defined(it));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-primitive.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-primitive.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.1 ToPrimitive(input [, PreferredType])\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n// instead of the ES6 spec version, we didn't implement @@toPrimitive case\n// and the second argument - flag - preferred type is a string\nmodule.exports = function (it, S) {\n  if (!isObject(it)) return it;\n  var fn, val;\n  if (S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (typeof (fn = it.valueOf) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (!S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  throw TypeError(\"Can't convert object to primitive value\");\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_uid.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_uid.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar id = 0;\nvar px = Math.random();\nmodule.exports = function (key) {\n  return 'Symbol('.concat(key === undefined ? '' : key, ')_', (++id + px).toString(36));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_user-agent.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_user-agent.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar navigator = global.navigator;\n\nmodule.exports = navigator && navigator.userAgent || '';\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_wks.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_wks.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar store = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('wks');\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nvar Symbol = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").Symbol;\nvar USE_SYMBOL = typeof Symbol == 'function';\n\nvar $exports = module.exports = function (name) {\n  return store[name] || (store[name] =\n    USE_SYMBOL && Symbol[name] || (USE_SYMBOL ? Symbol : uid)('Symbol.' + name));\n};\n\n$exports.store = store;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/core.get-iterator-method.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/core.get-iterator-method.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nmodule.exports = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\").getIteratorMethod = function (it) {\n  if (it != undefined) return it[ITERATOR]\n    || it['@@iterator']\n    || Iterators[classof(it)];\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.find.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.find.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 22.1.3.8 Array.prototype.find(predicate, thisArg = undefined)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $find = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(5);\nvar KEY = 'find';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  find: function find(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")(KEY);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.is-array.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.is-array.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.2.2 / 15.4.3.2 Array.isArray(arg)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Array', { isArray: __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.iterator.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.iterator.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar addToUnscopables = __webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\");\nvar step = __webpack_require__(/*! ./_iter-step */ \"./node_modules/core-js/modules/_iter-step.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\n\n// 22.1.3.4 Array.prototype.entries()\n// 22.1.3.13 Array.prototype.keys()\n// 22.1.3.29 Array.prototype.values()\n// 22.1.3.30 Array.prototype[@@iterator]()\nmodule.exports = __webpack_require__(/*! ./_iter-define */ \"./node_modules/core-js/modules/_iter-define.js\")(Array, 'Array', function (iterated, kind) {\n  this._t = toIObject(iterated); // target\n  this._i = 0;                   // next index\n  this._k = kind;                // kind\n// 22.1.5.2.1 %ArrayIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var kind = this._k;\n  var index = this._i++;\n  if (!O || index >= O.length) {\n    this._t = undefined;\n    return step(1);\n  }\n  if (kind == 'keys') return step(0, index);\n  if (kind == 'values') return step(0, O[index]);\n  return step(0, [index, O[index]]);\n}, 'values');\n\n// argumentsList[@@iterator] is %ArrayProto_values% (9.4.4.6, 9.4.4.7)\nIterators.Arguments = Iterators.Array;\n\naddToUnscopables('keys');\naddToUnscopables('values');\naddToUnscopables('entries');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.some.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.some.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $some = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(3);\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].some, true), 'Array', {\n  // 22.1.3.23 / 15.4.4.17 Array.prototype.some(callbackfn [, thisArg])\n  some: function some(callbackfn /* , thisArg */) {\n    return $some(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.function.bind.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.function.bind.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.2.3.2 / 15.3.4.5 Function.prototype.bind(thisArg, args...)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P, 'Function', { bind: __webpack_require__(/*! ./_bind */ \"./node_modules/core-js/modules/_bind.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.assign.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.assign.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.3.1 Object.assign(target, source)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S + $export.F, 'Object', { assign: __webpack_require__(/*! ./_object-assign */ \"./node_modules/core-js/modules/_object-assign.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.to-string.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.to-string.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 19.1.3.6 Object.prototype.toString()\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar test = {};\ntest[__webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag')] = 'z';\nif (test + '' != '[object z]') {\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(Object.prototype, 'toString', function toString() {\n    return '[object ' + classof(this) + ']';\n  }, true);\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.promise.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.promise.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\nvar task = __webpack_require__(/*! ./_task */ \"./node_modules/core-js/modules/_task.js\").set;\nvar microtask = __webpack_require__(/*! ./_microtask */ \"./node_modules/core-js/modules/_microtask.js\")();\nvar newPromiseCapabilityModule = __webpack_require__(/*! ./_new-promise-capability */ \"./node_modules/core-js/modules/_new-promise-capability.js\");\nvar perform = __webpack_require__(/*! ./_perform */ \"./node_modules/core-js/modules/_perform.js\");\nvar userAgent = __webpack_require__(/*! ./_user-agent */ \"./node_modules/core-js/modules/_user-agent.js\");\nvar promiseResolve = __webpack_require__(/*! ./_promise-resolve */ \"./node_modules/core-js/modules/_promise-resolve.js\");\nvar PROMISE = 'Promise';\nvar TypeError = global.TypeError;\nvar process = global.process;\nvar versions = process && process.versions;\nvar v8 = versions && versions.v8 || '';\nvar $Promise = global[PROMISE];\nvar isNode = classof(process) == 'process';\nvar empty = function () { /* empty */ };\nvar Internal, newGenericPromiseCapability, OwnPromiseCapability, Wrapper;\nvar newPromiseCapability = newGenericPromiseCapability = newPromiseCapabilityModule.f;\n\nvar USE_NATIVE = !!function () {\n  try {\n    // correct subclassing with @@species support\n    var promise = $Promise.resolve(1);\n    var FakePromise = (promise.constructor = {})[__webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species')] = function (exec) {\n      exec(empty, empty);\n    };\n    // unhandled rejections tracking support, NodeJS Promise without it fails @@species test\n    return (isNode || typeof PromiseRejectionEvent == 'function')\n      && promise.then(empty) instanceof FakePromise\n      // v8 6.6 (Node 10 and Chrome 66) have a bug with resolving custom thenables\n      // https://bugs.chromium.org/p/chromium/issues/detail?id=830565\n      // we can't detect it synchronously, so just check versions\n      && v8.indexOf('6.6') !== 0\n      && userAgent.indexOf('Chrome/66') === -1;\n  } catch (e) { /* empty */ }\n}();\n\n// helpers\nvar isThenable = function (it) {\n  var then;\n  return isObject(it) && typeof (then = it.then) == 'function' ? then : false;\n};\nvar notify = function (promise, isReject) {\n  if (promise._n) return;\n  promise._n = true;\n  var chain = promise._c;\n  microtask(function () {\n    var value = promise._v;\n    var ok = promise._s == 1;\n    var i = 0;\n    var run = function (reaction) {\n      var handler = ok ? reaction.ok : reaction.fail;\n      var resolve = reaction.resolve;\n      var reject = reaction.reject;\n      var domain = reaction.domain;\n      var result, then, exited;\n      try {\n        if (handler) {\n          if (!ok) {\n            if (promise._h == 2) onHandleUnhandled(promise);\n            promise._h = 1;\n          }\n          if (handler === true) result = value;\n          else {\n            if (domain) domain.enter();\n            result = handler(value); // may throw\n            if (domain) {\n              domain.exit();\n              exited = true;\n            }\n          }\n          if (result === reaction.promise) {\n            reject(TypeError('Promise-chain cycle'));\n          } else if (then = isThenable(result)) {\n            then.call(result, resolve, reject);\n          } else resolve(result);\n        } else reject(value);\n      } catch (e) {\n        if (domain && !exited) domain.exit();\n        reject(e);\n      }\n    };\n    while (chain.length > i) run(chain[i++]); // variable length - can't use forEach\n    promise._c = [];\n    promise._n = false;\n    if (isReject && !promise._h) onUnhandled(promise);\n  });\n};\nvar onUnhandled = function (promise) {\n  task.call(global, function () {\n    var value = promise._v;\n    var unhandled = isUnhandled(promise);\n    var result, handler, console;\n    if (unhandled) {\n      result = perform(function () {\n        if (isNode) {\n          process.emit('unhandledRejection', value, promise);\n        } else if (handler = global.onunhandledrejection) {\n          handler({ promise: promise, reason: value });\n        } else if ((console = global.console) && console.error) {\n          console.error('Unhandled promise rejection', value);\n        }\n      });\n      // Browsers should not trigger `rejectionHandled` event if it was handled here, NodeJS - should\n      promise._h = isNode || isUnhandled(promise) ? 2 : 1;\n    } promise._a = undefined;\n    if (unhandled && result.e) throw result.v;\n  });\n};\nvar isUnhandled = function (promise) {\n  return promise._h !== 1 && (promise._a || promise._c).length === 0;\n};\nvar onHandleUnhandled = function (promise) {\n  task.call(global, function () {\n    var handler;\n    if (isNode) {\n      process.emit('rejectionHandled', promise);\n    } else if (handler = global.onrejectionhandled) {\n      handler({ promise: promise, reason: promise._v });\n    }\n  });\n};\nvar $reject = function (value) {\n  var promise = this;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  promise._v = value;\n  promise._s = 2;\n  if (!promise._a) promise._a = promise._c.slice();\n  notify(promise, true);\n};\nvar $resolve = function (value) {\n  var promise = this;\n  var then;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  try {\n    if (promise === value) throw TypeError(\"Promise can't be resolved itself\");\n    if (then = isThenable(value)) {\n      microtask(function () {\n        var wrapper = { _w: promise, _d: false }; // wrap\n        try {\n          then.call(value, ctx($resolve, wrapper, 1), ctx($reject, wrapper, 1));\n        } catch (e) {\n          $reject.call(wrapper, e);\n        }\n      });\n    } else {\n      promise._v = value;\n      promise._s = 1;\n      notify(promise, false);\n    }\n  } catch (e) {\n    $reject.call({ _w: promise, _d: false }, e); // wrap\n  }\n};\n\n// constructor polyfill\nif (!USE_NATIVE) {\n  // 25.4.3.1 Promise(executor)\n  $Promise = function Promise(executor) {\n    anInstance(this, $Promise, PROMISE, '_h');\n    aFunction(executor);\n    Internal.call(this);\n    try {\n      executor(ctx($resolve, this, 1), ctx($reject, this, 1));\n    } catch (err) {\n      $reject.call(this, err);\n    }\n  };\n  // eslint-disable-next-line no-unused-vars\n  Internal = function Promise(executor) {\n    this._c = [];             // <- awaiting reactions\n    this._a = undefined;      // <- checked in isUnhandled reactions\n    this._s = 0;              // <- state\n    this._d = false;          // <- done\n    this._v = undefined;      // <- value\n    this._h = 0;              // <- rejection state, 0 - default, 1 - handled, 2 - unhandled\n    this._n = false;          // <- notify\n  };\n  Internal.prototype = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\")($Promise.prototype, {\n    // 25.4.5.3 Promise.prototype.then(onFulfilled, onRejected)\n    then: function then(onFulfilled, onRejected) {\n      var reaction = newPromiseCapability(speciesConstructor(this, $Promise));\n      reaction.ok = typeof onFulfilled == 'function' ? onFulfilled : true;\n      reaction.fail = typeof onRejected == 'function' && onRejected;\n      reaction.domain = isNode ? process.domain : undefined;\n      this._c.push(reaction);\n      if (this._a) this._a.push(reaction);\n      if (this._s) notify(this, false);\n      return reaction.promise;\n    },\n    // 25.4.5.1 Promise.prototype.catch(onRejected)\n    'catch': function (onRejected) {\n      return this.then(undefined, onRejected);\n    }\n  });\n  OwnPromiseCapability = function () {\n    var promise = new Internal();\n    this.promise = promise;\n    this.resolve = ctx($resolve, promise, 1);\n    this.reject = ctx($reject, promise, 1);\n  };\n  newPromiseCapabilityModule.f = newPromiseCapability = function (C) {\n    return C === $Promise || C === Wrapper\n      ? new OwnPromiseCapability(C)\n      : newGenericPromiseCapability(C);\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Promise: $Promise });\n__webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\")($Promise, PROMISE);\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")(PROMISE);\nWrapper = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\")[PROMISE];\n\n// statics\n$export($export.S + $export.F * !USE_NATIVE, PROMISE, {\n  // 25.4.4.5 Promise.reject(r)\n  reject: function reject(r) {\n    var capability = newPromiseCapability(this);\n    var $$reject = capability.reject;\n    $$reject(r);\n    return capability.promise;\n  }\n});\n$export($export.S + $export.F * (LIBRARY || !USE_NATIVE), PROMISE, {\n  // 25.4.4.6 Promise.resolve(x)\n  resolve: function resolve(x) {\n    return promiseResolve(LIBRARY && this === Wrapper ? $Promise : this, x);\n  }\n});\n$export($export.S + $export.F * !(USE_NATIVE && __webpack_require__(/*! ./_iter-detect */ \"./node_modules/core-js/modules/_iter-detect.js\")(function (iter) {\n  $Promise.all(iter)['catch'](empty);\n})), PROMISE, {\n  // 25.4.4.1 Promise.all(iterable)\n  all: function all(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var resolve = capability.resolve;\n    var reject = capability.reject;\n    var result = perform(function () {\n      var values = [];\n      var index = 0;\n      var remaining = 1;\n      forOf(iterable, false, function (promise) {\n        var $index = index++;\n        var alreadyCalled = false;\n        values.push(undefined);\n        remaining++;\n        C.resolve(promise).then(function (value) {\n          if (alreadyCalled) return;\n          alreadyCalled = true;\n          values[$index] = value;\n          --remaining || resolve(values);\n        }, reject);\n      });\n      --remaining || resolve(values);\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  },\n  // 25.4.4.4 Promise.race(iterable)\n  race: function race(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var reject = capability.reject;\n    var result = perform(function () {\n      forOf(iterable, false, function (promise) {\n        C.resolve(promise).then(capability.resolve, reject);\n      });\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.iterator.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.iterator.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $at = __webpack_require__(/*! ./_string-at */ \"./node_modules/core-js/modules/_string-at.js\")(true);\n\n// 21.1.3.27 String.prototype[@@iterator]()\n__webpack_require__(/*! ./_iter-define */ \"./node_modules/core-js/modules/_iter-define.js\")(String, 'String', function (iterated) {\n  this._t = String(iterated); // target\n  this._i = 0;                // next index\n// 21.1.5.2.1 %StringIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var index = this._i;\n  var point;\n  if (index >= O.length) return { value: undefined, done: true };\n  point = $at(O, index);\n  this._i += point.length;\n  return { value: point, done: false };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/web.dom.iterable.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/web.dom.iterable.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $iterators = __webpack_require__(/*! ./es6.array.iterator */ \"./node_modules/core-js/modules/es6.array.iterator.js\");\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar wks = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\nvar ITERATOR = wks('iterator');\nvar TO_STRING_TAG = wks('toStringTag');\nvar ArrayValues = Iterators.Array;\n\nvar DOMIterables = {\n  CSSRuleList: true, // TODO: Not spec compliant, should be false.\n  CSSStyleDeclaration: false,\n  CSSValueList: false,\n  ClientRectList: false,\n  DOMRectList: false,\n  DOMStringList: false,\n  DOMTokenList: true,\n  DataTransferItemList: false,\n  FileList: false,\n  HTMLAllCollection: false,\n  HTMLCollection: false,\n  HTMLFormElement: false,\n  HTMLSelectElement: false,\n  MediaList: true, // TODO: Not spec compliant, should be false.\n  MimeTypeArray: false,\n  NamedNodeMap: false,\n  NodeList: true,\n  PaintRequestList: false,\n  Plugin: false,\n  PluginArray: false,\n  SVGLengthList: false,\n  SVGNumberList: false,\n  SVGPathSegList: false,\n  SVGPointList: false,\n  SVGStringList: false,\n  SVGTransformList: false,\n  SourceBufferList: false,\n  StyleSheetList: true, // TODO: Not spec compliant, should be false.\n  TextTrackCueList: false,\n  TextTrackList: false,\n  TouchList: false\n};\n\nfor (var collections = getKeys(DOMIterables), i = 0; i < collections.length; i++) {\n  var NAME = collections[i];\n  var explicit = DOMIterables[NAME];\n  var Collection = global[NAME];\n  var proto = Collection && Collection.prototype;\n  var key;\n  if (proto) {\n    if (!proto[ITERATOR]) hide(proto, ITERATOR, ArrayValues);\n    if (!proto[TO_STRING_TAG]) hide(proto, TO_STRING_TAG, NAME);\n    Iterators[NAME] = ArrayValues;\n    if (explicit) for (key in $iterators) if (!proto[key]) redefine(proto, key, $iterators[key], true);\n  }\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/crypto-js/core.js\":\n/*!****************************************!*\\\n  !*** ./node_modules/crypto-js/core.js ***!\n  \\****************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n;(function (root, factory) {\n\tif (true) {\n\t\t// CommonJS\n\t\tmodule.exports = exports = factory();\n\t}\n\telse {}\n}(this, function () {\n\n\t/**\n\t * CryptoJS core components.\n\t */\n\tvar CryptoJS = CryptoJS || (function (Math, undefined) {\n\t    /*\n\t     * Local polyfil of Object.create\n\t     */\n\t    var create = Object.create || (function () {\n\t        function F() {};\n\n\t        return function (obj) {\n\t            var subtype;\n\n\t            F.prototype = obj;\n\n\t            subtype = new F();\n\n\t            F.prototype = null;\n\n\t            return subtype;\n\t        };\n\t    }())\n\n\t    /**\n\t     * CryptoJS namespace.\n\t     */\n\t    var C = {};\n\n\t    /**\n\t     * Library namespace.\n\t     */\n\t    var C_lib = C.lib = {};\n\n\t    /**\n\t     * Base object for prototypal inheritance.\n\t     */\n\t    var Base = C_lib.Base = (function () {\n\n\n\t        return {\n\t            /**\n\t             * Creates a new object that inherits from this object.\n\t             *\n\t             * @param {Object} overrides Properties to copy into the new object.\n\t             *\n\t             * @return {Object} The new object.\n\t             *\n\t             * @static\n\t             *\n\t             * @example\n\t             *\n\t             *     var MyType = CryptoJS.lib.Base.extend({\n\t             *         field: 'value',\n\t             *\n\t             *         method: function () {\n\t             *         }\n\t             *     });\n\t             */\n\t            extend: function (overrides) {\n\t                // Spawn\n\t                var subtype = create(this);\n\n\t                // Augment\n\t                if (overrides) {\n\t                    subtype.mixIn(overrides);\n\t                }\n\n\t                // Create default initializer\n\t                if (!subtype.hasOwnProperty('init') || this.init === subtype.init) {\n\t                    subtype.init = function () {\n\t                        subtype.$super.init.apply(this, arguments);\n\t                    };\n\t                }\n\n\t                // Initializer's prototype is the subtype object\n\t                subtype.init.prototype = subtype;\n\n\t                // Reference supertype\n\t                subtype.$super = this;\n\n\t                return subtype;\n\t            },\n\n\t            /**\n\t             * Extends this object and runs the init method.\n\t             * Arguments to create() will be passed to init().\n\t             *\n\t             * @return {Object} The new object.\n\t             *\n\t             * @static\n\t             *\n\t             * @example\n\t             *\n\t             *     var instance = MyType.create();\n\t             */\n\t            create: function () {\n\t                var instance = this.extend();\n\t                instance.init.apply(instance, arguments);\n\n\t                return instance;\n\t            },\n\n\t            /**\n\t             * Initializes a newly created object.\n\t             * Override this method to add some logic when your objects are created.\n\t             *\n\t             * @example\n\t             *\n\t             *     var MyType = CryptoJS.lib.Base.extend({\n\t             *         init: function () {\n\t             *             // ...\n\t             *         }\n\t             *     });\n\t             */\n\t            init: function () {\n\t            },\n\n\t            /**\n\t             * Copies properties into this object.\n\t             *\n\t             * @param {Object} properties The properties to mix in.\n\t             *\n\t             * @example\n\t             *\n\t             *     MyType.mixIn({\n\t             *         field: 'value'\n\t             *     });\n\t             */\n\t            mixIn: function (properties) {\n\t                for (var propertyName in properties) {\n\t                    if (properties.hasOwnProperty(propertyName)) {\n\t                        this[propertyName] = properties[propertyName];\n\t                    }\n\t                }\n\n\t                // IE won't copy toString using the loop above\n\t                if (properties.hasOwnProperty('toString')) {\n\t                    this.toString = properties.toString;\n\t                }\n\t            },\n\n\t            /**\n\t             * Creates a copy of this object.\n\t             *\n\t             * @return {Object} The clone.\n\t             *\n\t             * @example\n\t             *\n\t             *     var clone = instance.clone();\n\t             */\n\t            clone: function () {\n\t                return this.init.prototype.extend(this);\n\t            }\n\t        };\n\t    }());\n\n\t    /**\n\t     * An array of 32-bit words.\n\t     *\n\t     * @property {Array} words The array of 32-bit words.\n\t     * @property {number} sigBytes The number of significant bytes in this word array.\n\t     */\n\t    var WordArray = C_lib.WordArray = Base.extend({\n\t        /**\n\t         * Initializes a newly created word array.\n\t         *\n\t         * @param {Array} words (Optional) An array of 32-bit words.\n\t         * @param {number} sigBytes (Optional) The number of significant bytes in the words.\n\t         *\n\t         * @example\n\t         *\n\t         *     var wordArray = CryptoJS.lib.WordArray.create();\n\t         *     var wordArray = CryptoJS.lib.WordArray.create([0x00010203, 0x04050607]);\n\t         *     var wordArray = CryptoJS.lib.WordArray.create([0x00010203, 0x04050607], 6);\n\t         */\n\t        init: function (words, sigBytes) {\n\t            words = this.words = words || [];\n\n\t            if (sigBytes != undefined) {\n\t                this.sigBytes = sigBytes;\n\t            } else {\n\t                this.sigBytes = words.length * 4;\n\t            }\n\t        },\n\n\t        /**\n\t         * Converts this word array to a string.\n\t         *\n\t         * @param {Encoder} encoder (Optional) The encoding strategy to use. Default: CryptoJS.enc.Hex\n\t         *\n\t         * @return {string} The stringified word array.\n\t         *\n\t         * @example\n\t         *\n\t         *     var string = wordArray + '';\n\t         *     var string = wordArray.toString();\n\t         *     var string = wordArray.toString(CryptoJS.enc.Utf8);\n\t         */\n\t        toString: function (encoder) {\n\t            return (encoder || Hex).stringify(this);\n\t        },\n\n\t        /**\n\t         * Concatenates a word array to this word array.\n\t         *\n\t         * @param {WordArray} wordArray The word array to append.\n\t         *\n\t         * @return {WordArray} This word array.\n\t         *\n\t         * @example\n\t         *\n\t         *     wordArray1.concat(wordArray2);\n\t         */\n\t        concat: function (wordArray) {\n\t            // Shortcuts\n\t            var thisWords = this.words;\n\t            var thatWords = wordArray.words;\n\t            var thisSigBytes = this.sigBytes;\n\t            var thatSigBytes = wordArray.sigBytes;\n\n\t            // Clamp excess bits\n\t            this.clamp();\n\n\t            // Concat\n\t            if (thisSigBytes % 4) {\n\t                // Copy one byte at a time\n\t                for (var i = 0; i < thatSigBytes; i++) {\n\t                    var thatByte = (thatWords[i >>> 2] >>> (24 - (i % 4) * 8)) & 0xff;\n\t                    thisWords[(thisSigBytes + i) >>> 2] |= thatByte << (24 - ((thisSigBytes + i) % 4) * 8);\n\t                }\n\t            } else {\n\t                // Copy one word at a time\n\t                for (var i = 0; i < thatSigBytes; i += 4) {\n\t                    thisWords[(thisSigBytes + i) >>> 2] = thatWords[i >>> 2];\n\t                }\n\t            }\n\t            this.sigBytes += thatSigBytes;\n\n\t            // Chainable\n\t            return this;\n\t        },\n\n\t        /**\n\t         * Removes insignificant bits.\n\t         *\n\t         * @example\n\t         *\n\t         *     wordArray.clamp();\n\t         */\n\t        clamp: function () {\n\t            // Shortcuts\n\t            var words = this.words;\n\t            var sigBytes = this.sigBytes;\n\n\t            // Clamp\n\t            words[sigBytes >>> 2] &= 0xffffffff << (32 - (sigBytes % 4) * 8);\n\t            words.length = Math.ceil(sigBytes / 4);\n\t        },\n\n\t        /**\n\t         * Creates a copy of this word array.\n\t         *\n\t         * @return {WordArray} The clone.\n\t         *\n\t         * @example\n\t         *\n\t         *     var clone = wordArray.clone();\n\t         */\n\t        clone: function () {\n\t            var clone = Base.clone.call(this);\n\t            clone.words = this.words.slice(0);\n\n\t            return clone;\n\t        },\n\n\t        /**\n\t         * Creates a word array filled with random bytes.\n\t         *\n\t         * @param {number} nBytes The number of random bytes to generate.\n\t         *\n\t         * @return {WordArray} The random word array.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var wordArray = CryptoJS.lib.WordArray.random(16);\n\t         */\n\t        random: function (nBytes) {\n\t            var words = [];\n\n\t            var r = (function (m_w) {\n\t                var m_w = m_w;\n\t                var m_z = 0x3ade68b1;\n\t                var mask = 0xffffffff;\n\n\t                return function () {\n\t                    m_z = (0x9069 * (m_z & 0xFFFF) + (m_z >> 0x10)) & mask;\n\t                    m_w = (0x4650 * (m_w & 0xFFFF) + (m_w >> 0x10)) & mask;\n\t                    var result = ((m_z << 0x10) + m_w) & mask;\n\t                    result /= 0x100000000;\n\t                    result += 0.5;\n\t                    return result * (Math.random() > .5 ? 1 : -1);\n\t                }\n\t            });\n\n\t            for (var i = 0, rcache; i < nBytes; i += 4) {\n\t                var _r = r((rcache || Math.random()) * 0x100000000);\n\n\t                rcache = _r() * 0x3ade67b7;\n\t                words.push((_r() * 0x100000000) | 0);\n\t            }\n\n\t            return new WordArray.init(words, nBytes);\n\t        }\n\t    });\n\n\t    /**\n\t     * Encoder namespace.\n\t     */\n\t    var C_enc = C.enc = {};\n\n\t    /**\n\t     * Hex encoding strategy.\n\t     */\n\t    var Hex = C_enc.Hex = {\n\t        /**\n\t         * Converts a word array to a hex string.\n\t         *\n\t         * @param {WordArray} wordArray The word array.\n\t         *\n\t         * @return {string} The hex string.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var hexString = CryptoJS.enc.Hex.stringify(wordArray);\n\t         */\n\t        stringify: function (wordArray) {\n\t            // Shortcuts\n\t            var words = wordArray.words;\n\t            var sigBytes = wordArray.sigBytes;\n\n\t            // Convert\n\t            var hexChars = [];\n\t            for (var i = 0; i < sigBytes; i++) {\n\t                var bite = (words[i >>> 2] >>> (24 - (i % 4) * 8)) & 0xff;\n\t                hexChars.push((bite >>> 4).toString(16));\n\t                hexChars.push((bite & 0x0f).toString(16));\n\t            }\n\n\t            return hexChars.join('');\n\t        },\n\n\t        /**\n\t         * Converts a hex string to a word array.\n\t         *\n\t         * @param {string} hexStr The hex string.\n\t         *\n\t         * @return {WordArray} The word array.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var wordArray = CryptoJS.enc.Hex.parse(hexString);\n\t         */\n\t        parse: function (hexStr) {\n\t            // Shortcut\n\t            var hexStrLength = hexStr.length;\n\n\t            // Convert\n\t            var words = [];\n\t            for (var i = 0; i < hexStrLength; i += 2) {\n\t                words[i >>> 3] |= parseInt(hexStr.substr(i, 2), 16) << (24 - (i % 8) * 4);\n\t            }\n\n\t            return new WordArray.init(words, hexStrLength / 2);\n\t        }\n\t    };\n\n\t    /**\n\t     * Latin1 encoding strategy.\n\t     */\n\t    var Latin1 = C_enc.Latin1 = {\n\t        /**\n\t         * Converts a word array to a Latin1 string.\n\t         *\n\t         * @param {WordArray} wordArray The word array.\n\t         *\n\t         * @return {string} The Latin1 string.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var latin1String = CryptoJS.enc.Latin1.stringify(wordArray);\n\t         */\n\t        stringify: function (wordArray) {\n\t            // Shortcuts\n\t            var words = wordArray.words;\n\t            var sigBytes = wordArray.sigBytes;\n\n\t            // Convert\n\t            var latin1Chars = [];\n\t            for (var i = 0; i < sigBytes; i++) {\n\t                var bite = (words[i >>> 2] >>> (24 - (i % 4) * 8)) & 0xff;\n\t                latin1Chars.push(String.fromCharCode(bite));\n\t            }\n\n\t            return latin1Chars.join('');\n\t        },\n\n\t        /**\n\t         * Converts a Latin1 string to a word array.\n\t         *\n\t         * @param {string} latin1Str The Latin1 string.\n\t         *\n\t         * @return {WordArray} The word array.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var wordArray = CryptoJS.enc.Latin1.parse(latin1String);\n\t         */\n\t        parse: function (latin1Str) {\n\t            // Shortcut\n\t            var latin1StrLength = latin1Str.length;\n\n\t            // Convert\n\t            var words = [];\n\t            for (var i = 0; i < latin1StrLength; i++) {\n\t                words[i >>> 2] |= (latin1Str.charCodeAt(i) & 0xff) << (24 - (i % 4) * 8);\n\t            }\n\n\t            return new WordArray.init(words, latin1StrLength);\n\t        }\n\t    };\n\n\t    /**\n\t     * UTF-8 encoding strategy.\n\t     */\n\t    var Utf8 = C_enc.Utf8 = {\n\t        /**\n\t         * Converts a word array to a UTF-8 string.\n\t         *\n\t         * @param {WordArray} wordArray The word array.\n\t         *\n\t         * @return {string} The UTF-8 string.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var utf8String = CryptoJS.enc.Utf8.stringify(wordArray);\n\t         */\n\t        stringify: function (wordArray) {\n\t            try {\n\t                return decodeURIComponent(escape(Latin1.stringify(wordArray)));\n\t            } catch (e) {\n\t                throw new Error('Malformed UTF-8 data');\n\t            }\n\t        },\n\n\t        /**\n\t         * Converts a UTF-8 string to a word array.\n\t         *\n\t         * @param {string} utf8Str The UTF-8 string.\n\t         *\n\t         * @return {WordArray} The word array.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var wordArray = CryptoJS.enc.Utf8.parse(utf8String);\n\t         */\n\t        parse: function (utf8Str) {\n\t            return Latin1.parse(unescape(encodeURIComponent(utf8Str)));\n\t        }\n\t    };\n\n\t    /**\n\t     * Abstract buffered block algorithm template.\n\t     *\n\t     * The property blockSize must be implemented in a concrete subtype.\n\t     *\n\t     * @property {number} _minBufferSize The number of blocks that should be kept unprocessed in the buffer. Default: 0\n\t     */\n\t    var BufferedBlockAlgorithm = C_lib.BufferedBlockAlgorithm = Base.extend({\n\t        /**\n\t         * Resets this block algorithm's data buffer to its initial state.\n\t         *\n\t         * @example\n\t         *\n\t         *     bufferedBlockAlgorithm.reset();\n\t         */\n\t        reset: function () {\n\t            // Initial values\n\t            this._data = new WordArray.init();\n\t            this._nDataBytes = 0;\n\t        },\n\n\t        /**\n\t         * Adds new data to this block algorithm's buffer.\n\t         *\n\t         * @param {WordArray|string} data The data to append. Strings are converted to a WordArray using UTF-8.\n\t         *\n\t         * @example\n\t         *\n\t         *     bufferedBlockAlgorithm._append('data');\n\t         *     bufferedBlockAlgorithm._append(wordArray);\n\t         */\n\t        _append: function (data) {\n\t            // Convert string to WordArray, else assume WordArray already\n\t            if (typeof data == 'string') {\n\t                data = Utf8.parse(data);\n\t            }\n\n\t            // Append\n\t            this._data.concat(data);\n\t            this._nDataBytes += data.sigBytes;\n\t        },\n\n\t        /**\n\t         * Processes available data blocks.\n\t         *\n\t         * This method invokes _doProcessBlock(offset), which must be implemented by a concrete subtype.\n\t         *\n\t         * @param {boolean} doFlush Whether all blocks and partial blocks should be processed.\n\t         *\n\t         * @return {WordArray} The processed data.\n\t         *\n\t         * @example\n\t         *\n\t         *     var processedData = bufferedBlockAlgorithm._process();\n\t         *     var processedData = bufferedBlockAlgorithm._process(!!'flush');\n\t         */\n\t        _process: function (doFlush) {\n\t            // Shortcuts\n\t            var data = this._data;\n\t            var dataWords = data.words;\n\t            var dataSigBytes = data.sigBytes;\n\t            var blockSize = this.blockSize;\n\t            var blockSizeBytes = blockSize * 4;\n\n\t            // Count blocks ready\n\t            var nBlocksReady = dataSigBytes / blockSizeBytes;\n\t            if (doFlush) {\n\t                // Round up to include partial blocks\n\t                nBlocksReady = Math.ceil(nBlocksReady);\n\t            } else {\n\t                // Round down to include only full blocks,\n\t                // less the number of blocks that must remain in the buffer\n\t                nBlocksReady = Math.max((nBlocksReady | 0) - this._minBufferSize, 0);\n\t            }\n\n\t            // Count words ready\n\t            var nWordsReady = nBlocksReady * blockSize;\n\n\t            // Count bytes ready\n\t            var nBytesReady = Math.min(nWordsReady * 4, dataSigBytes);\n\n\t            // Process blocks\n\t            if (nWordsReady) {\n\t                for (var offset = 0; offset < nWordsReady; offset += blockSize) {\n\t                    // Perform concrete-algorithm logic\n\t                    this._doProcessBlock(dataWords, offset);\n\t                }\n\n\t                // Remove processed words\n\t                var processedWords = dataWords.splice(0, nWordsReady);\n\t                data.sigBytes -= nBytesReady;\n\t            }\n\n\t            // Return processed words\n\t            return new WordArray.init(processedWords, nBytesReady);\n\t        },\n\n\t        /**\n\t         * Creates a copy of this object.\n\t         *\n\t         * @return {Object} The clone.\n\t         *\n\t         * @example\n\t         *\n\t         *     var clone = bufferedBlockAlgorithm.clone();\n\t         */\n\t        clone: function () {\n\t            var clone = Base.clone.call(this);\n\t            clone._data = this._data.clone();\n\n\t            return clone;\n\t        },\n\n\t        _minBufferSize: 0\n\t    });\n\n\t    /**\n\t     * Abstract hasher template.\n\t     *\n\t     * @property {number} blockSize The number of 32-bit words this hasher operates on. Default: 16 (512 bits)\n\t     */\n\t    var Hasher = C_lib.Hasher = BufferedBlockAlgorithm.extend({\n\t        /**\n\t         * Configuration options.\n\t         */\n\t        cfg: Base.extend(),\n\n\t        /**\n\t         * Initializes a newly created hasher.\n\t         *\n\t         * @param {Object} cfg (Optional) The configuration options to use for this hash computation.\n\t         *\n\t         * @example\n\t         *\n\t         *     var hasher = CryptoJS.algo.SHA256.create();\n\t         */\n\t        init: function (cfg) {\n\t            // Apply config defaults\n\t            this.cfg = this.cfg.extend(cfg);\n\n\t            // Set initial values\n\t            this.reset();\n\t        },\n\n\t        /**\n\t         * Resets this hasher to its initial state.\n\t         *\n\t         * @example\n\t         *\n\t         *     hasher.reset();\n\t         */\n\t        reset: function () {\n\t            // Reset data buffer\n\t            BufferedBlockAlgorithm.reset.call(this);\n\n\t            // Perform concrete-hasher logic\n\t            this._doReset();\n\t        },\n\n\t        /**\n\t         * Updates this hasher with a message.\n\t         *\n\t         * @param {WordArray|string} messageUpdate The message to append.\n\t         *\n\t         * @return {Hasher} This hasher.\n\t         *\n\t         * @example\n\t         *\n\t         *     hasher.update('message');\n\t         *     hasher.update(wordArray);\n\t         */\n\t        update: function (messageUpdate) {\n\t            // Append\n\t            this._append(messageUpdate);\n\n\t            // Update the hash\n\t            this._process();\n\n\t            // Chainable\n\t            return this;\n\t        },\n\n\t        /**\n\t         * Finalizes the hash computation.\n\t         * Note that the finalize operation is effectively a destructive, read-once operation.\n\t         *\n\t         * @param {WordArray|string} messageUpdate (Optional) A final message update.\n\t         *\n\t         * @return {WordArray} The hash.\n\t         *\n\t         * @example\n\t         *\n\t         *     var hash = hasher.finalize();\n\t         *     var hash = hasher.finalize('message');\n\t         *     var hash = hasher.finalize(wordArray);\n\t         */\n\t        finalize: function (messageUpdate) {\n\t            // Final message update\n\t            if (messageUpdate) {\n\t                this._append(messageUpdate);\n\t            }\n\n\t            // Perform concrete-hasher logic\n\t            var hash = this._doFinalize();\n\n\t            return hash;\n\t        },\n\n\t        blockSize: 512/32,\n\n\t        /**\n\t         * Creates a shortcut function to a hasher's object interface.\n\t         *\n\t         * @param {Hasher} hasher The hasher to create a helper for.\n\t         *\n\t         * @return {Function} The shortcut function.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var SHA256 = CryptoJS.lib.Hasher._createHelper(CryptoJS.algo.SHA256);\n\t         */\n\t        _createHelper: function (hasher) {\n\t            return function (message, cfg) {\n\t                return new hasher.init(cfg).finalize(message);\n\t            };\n\t        },\n\n\t        /**\n\t         * Creates a shortcut function to the HMAC's object interface.\n\t         *\n\t         * @param {Hasher} hasher The hasher to use in this HMAC helper.\n\t         *\n\t         * @return {Function} The shortcut function.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var HmacSHA256 = CryptoJS.lib.Hasher._createHmacHelper(CryptoJS.algo.SHA256);\n\t         */\n\t        _createHmacHelper: function (hasher) {\n\t            return function (message, key) {\n\t                return new C_algo.HMAC.init(hasher, key).finalize(message);\n\t            };\n\t        }\n\t    });\n\n\t    /**\n\t     * Algorithm namespace.\n\t     */\n\t    var C_algo = C.algo = {};\n\n\t    return C;\n\t}(Math));\n\n\n\treturn CryptoJS;\n\n}));\n\n/***/ }),\n\n/***/ \"./node_modules/crypto-js/sha256.js\":\n/*!******************************************!*\\\n  !*** ./node_modules/crypto-js/sha256.js ***!\n  \\******************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n;(function (root, factory) {\n\tif (true) {\n\t\t// CommonJS\n\t\tmodule.exports = exports = factory(__webpack_require__(/*! ./core */ \"./node_modules/crypto-js/core.js\"));\n\t}\n\telse {}\n}(this, function (CryptoJS) {\n\n\t(function (Math) {\n\t    // Shortcuts\n\t    var C = CryptoJS;\n\t    var C_lib = C.lib;\n\t    var WordArray = C_lib.WordArray;\n\t    var Hasher = C_lib.Hasher;\n\t    var C_algo = C.algo;\n\n\t    // Initialization and round constants tables\n\t    var H = [];\n\t    var K = [];\n\n\t    // Compute constants\n\t    (function () {\n\t        function isPrime(n) {\n\t            var sqrtN = Math.sqrt(n);\n\t            for (var factor = 2; factor <= sqrtN; factor++) {\n\t                if (!(n % factor)) {\n\t                    return false;\n\t                }\n\t            }\n\n\t            return true;\n\t        }\n\n\t        function getFractionalBits(n) {\n\t            return ((n - (n | 0)) * 0x100000000) | 0;\n\t        }\n\n\t        var n = 2;\n\t        var nPrime = 0;\n\t        while (nPrime < 64) {\n\t            if (isPrime(n)) {\n\t                if (nPrime < 8) {\n\t                    H[nPrime] = getFractionalBits(Math.pow(n, 1 / 2));\n\t                }\n\t                K[nPrime] = getFractionalBits(Math.pow(n, 1 / 3));\n\n\t                nPrime++;\n\t            }\n\n\t            n++;\n\t        }\n\t    }());\n\n\t    // Reusable object\n\t    var W = [];\n\n\t    /**\n\t     * SHA-256 hash algorithm.\n\t     */\n\t    var SHA256 = C_algo.SHA256 = Hasher.extend({\n\t        _doReset: function () {\n\t            this._hash = new WordArray.init(H.slice(0));\n\t        },\n\n\t        _doProcessBlock: function (M, offset) {\n\t            // Shortcut\n\t            var H = this._hash.words;\n\n\t            // Working variables\n\t            var a = H[0];\n\t            var b = H[1];\n\t            var c = H[2];\n\t            var d = H[3];\n\t            var e = H[4];\n\t            var f = H[5];\n\t            var g = H[6];\n\t            var h = H[7];\n\n\t            // Computation\n\t            for (var i = 0; i < 64; i++) {\n\t                if (i < 16) {\n\t                    W[i] = M[offset + i] | 0;\n\t                } else {\n\t                    var gamma0x = W[i - 15];\n\t                    var gamma0  = ((gamma0x << 25) | (gamma0x >>> 7))  ^\n\t                                  ((gamma0x << 14) | (gamma0x >>> 18)) ^\n\t                                   (gamma0x >>> 3);\n\n\t                    var gamma1x = W[i - 2];\n\t                    var gamma1  = ((gamma1x << 15) | (gamma1x >>> 17)) ^\n\t                                  ((gamma1x << 13) | (gamma1x >>> 19)) ^\n\t                                   (gamma1x >>> 10);\n\n\t                    W[i] = gamma0 + W[i - 7] + gamma1 + W[i - 16];\n\t                }\n\n\t                var ch  = (e & f) ^ (~e & g);\n\t                var maj = (a & b) ^ (a & c) ^ (b & c);\n\n\t                var sigma0 = ((a << 30) | (a >>> 2)) ^ ((a << 19) | (a >>> 13)) ^ ((a << 10) | (a >>> 22));\n\t                var sigma1 = ((e << 26) | (e >>> 6)) ^ ((e << 21) | (e >>> 11)) ^ ((e << 7)  | (e >>> 25));\n\n\t                var t1 = h + sigma1 + ch + K[i] + W[i];\n\t                var t2 = sigma0 + maj;\n\n\t                h = g;\n\t                g = f;\n\t                f = e;\n\t                e = (d + t1) | 0;\n\t                d = c;\n\t                c = b;\n\t                b = a;\n\t                a = (t1 + t2) | 0;\n\t            }\n\n\t            // Intermediate hash value\n\t            H[0] = (H[0] + a) | 0;\n\t            H[1] = (H[1] + b) | 0;\n\t            H[2] = (H[2] + c) | 0;\n\t            H[3] = (H[3] + d) | 0;\n\t            H[4] = (H[4] + e) | 0;\n\t            H[5] = (H[5] + f) | 0;\n\t            H[6] = (H[6] + g) | 0;\n\t            H[7] = (H[7] + h) | 0;\n\t        },\n\n\t        _doFinalize: function () {\n\t            // Shortcuts\n\t            var data = this._data;\n\t            var dataWords = data.words;\n\n\t            var nBitsTotal = this._nDataBytes * 8;\n\t            var nBitsLeft = data.sigBytes * 8;\n\n\t            // Add padding\n\t            dataWords[nBitsLeft >>> 5] |= 0x80 << (24 - nBitsLeft % 32);\n\t            dataWords[(((nBitsLeft + 64) >>> 9) << 4) + 14] = Math.floor(nBitsTotal / 0x100000000);\n\t            dataWords[(((nBitsLeft + 64) >>> 9) << 4) + 15] = nBitsTotal;\n\t            data.sigBytes = dataWords.length * 4;\n\n\t            // Hash final blocks\n\t            this._process();\n\n\t            // Return final computed hash\n\t            return this._hash;\n\t        },\n\n\t        clone: function () {\n\t            var clone = Hasher.clone.call(this);\n\t            clone._hash = this._hash.clone();\n\n\t            return clone;\n\t        }\n\t    });\n\n\t    /**\n\t     * Shortcut function to the hasher's object interface.\n\t     *\n\t     * @param {WordArray|string} message The message to hash.\n\t     *\n\t     * @return {WordArray} The hash.\n\t     *\n\t     * @static\n\t     *\n\t     * @example\n\t     *\n\t     *     var hash = CryptoJS.SHA256('message');\n\t     *     var hash = CryptoJS.SHA256(wordArray);\n\t     */\n\t    C.SHA256 = Hasher._createHelper(SHA256);\n\n\t    /**\n\t     * Shortcut function to the HMAC's object interface.\n\t     *\n\t     * @param {WordArray|string} message The message to hash.\n\t     * @param {WordArray|string} key The secret key.\n\t     *\n\t     * @return {WordArray} The HMAC.\n\t     *\n\t     * @static\n\t     *\n\t     * @example\n\t     *\n\t     *     var hmac = CryptoJS.HmacSHA256(message, key);\n\t     */\n\t    C.HmacSHA256 = Hasher._createHmacHelper(SHA256);\n\t}(Math));\n\n\n\treturn CryptoJS.SHA256;\n\n}));\n\n/***/ }),\n\n/***/ \"./node_modules/jsbn/index.js\":\n/*!************************************!*\\\n  !*** ./node_modules/jsbn/index.js ***!\n  \\************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n(function(){\n\n    // Copyright (c) 2005  Tom Wu\n    // All Rights Reserved.\n    // See \"LICENSE\" for details.\n\n    // Basic JavaScript BN library - subset useful for RSA encryption.\n\n    // Bits per digit\n    var dbits;\n\n    // JavaScript engine analysis\n    var canary = 0xdeadbeefcafe;\n    var j_lm = ((canary&0xffffff)==0xefcafe);\n\n    // (public) Constructor\n    function BigInteger(a,b,c) {\n      if(a != null)\n        if(\"number\" == typeof a) this.fromNumber(a,b,c);\n        else if(b == null && \"string\" != typeof a) this.fromString(a,256);\n        else this.fromString(a,b);\n    }\n\n    // return new, unset BigInteger\n    function nbi() { return new BigInteger(null); }\n\n    // am: Compute w_j += (x*this_i), propagate carries,\n    // c is initial carry, returns final carry.\n    // c < 3*dvalue, x < 2*dvalue, this_i < dvalue\n    // We need to select the fastest one that works in this environment.\n\n    // am1: use a single mult and divide to get the high bits,\n    // max digit bits should be 26 because\n    // max internal value = 2*dvalue^2-2*dvalue (< 2^53)\n    function am1(i,x,w,j,c,n) {\n      while(--n >= 0) {\n        var v = x*this[i++]+w[j]+c;\n        c = Math.floor(v/0x4000000);\n        w[j++] = v&0x3ffffff;\n      }\n      return c;\n    }\n    // am2 avoids a big mult-and-extract completely.\n    // Max digit bits should be <= 30 because we do bitwise ops\n    // on values up to 2*hdvalue^2-hdvalue-1 (< 2^31)\n    function am2(i,x,w,j,c,n) {\n      var xl = x&0x7fff, xh = x>>15;\n      while(--n >= 0) {\n        var l = this[i]&0x7fff;\n        var h = this[i++]>>15;\n        var m = xh*l+h*xl;\n        l = xl*l+((m&0x7fff)<<15)+w[j]+(c&0x3fffffff);\n        c = (l>>>30)+(m>>>15)+xh*h+(c>>>30);\n        w[j++] = l&0x3fffffff;\n      }\n      return c;\n    }\n    // Alternately, set max digit bits to 28 since some\n    // browsers slow down when dealing with 32-bit numbers.\n    function am3(i,x,w,j,c,n) {\n      var xl = x&0x3fff, xh = x>>14;\n      while(--n >= 0) {\n        var l = this[i]&0x3fff;\n        var h = this[i++]>>14;\n        var m = xh*l+h*xl;\n        l = xl*l+((m&0x3fff)<<14)+w[j]+c;\n        c = (l>>28)+(m>>14)+xh*h;\n        w[j++] = l&0xfffffff;\n      }\n      return c;\n    }\n    var inBrowser = typeof navigator !== \"undefined\";\n    if(inBrowser && j_lm && (navigator.appName == \"Microsoft Internet Explorer\")) {\n      BigInteger.prototype.am = am2;\n      dbits = 30;\n    }\n    else if(inBrowser && j_lm && (navigator.appName != \"Netscape\")) {\n      BigInteger.prototype.am = am1;\n      dbits = 26;\n    }\n    else { // Mozilla/Netscape seems to prefer am3\n      BigInteger.prototype.am = am3;\n      dbits = 28;\n    }\n\n    BigInteger.prototype.DB = dbits;\n    BigInteger.prototype.DM = ((1<<dbits)-1);\n    BigInteger.prototype.DV = (1<<dbits);\n\n    var BI_FP = 52;\n    BigInteger.prototype.FV = Math.pow(2,BI_FP);\n    BigInteger.prototype.F1 = BI_FP-dbits;\n    BigInteger.prototype.F2 = 2*dbits-BI_FP;\n\n    // Digit conversions\n    var BI_RM = \"0123456789abcdefghijklmnopqrstuvwxyz\";\n    var BI_RC = new Array();\n    var rr,vv;\n    rr = \"0\".charCodeAt(0);\n    for(vv = 0; vv <= 9; ++vv) BI_RC[rr++] = vv;\n    rr = \"a\".charCodeAt(0);\n    for(vv = 10; vv < 36; ++vv) BI_RC[rr++] = vv;\n    rr = \"A\".charCodeAt(0);\n    for(vv = 10; vv < 36; ++vv) BI_RC[rr++] = vv;\n\n    function int2char(n) { return BI_RM.charAt(n); }\n    function intAt(s,i) {\n      var c = BI_RC[s.charCodeAt(i)];\n      return (c==null)?-1:c;\n    }\n\n    // (protected) copy this to r\n    function bnpCopyTo(r) {\n      for(var i = this.t-1; i >= 0; --i) r[i] = this[i];\n      r.t = this.t;\n      r.s = this.s;\n    }\n\n    // (protected) set from integer value x, -DV <= x < DV\n    function bnpFromInt(x) {\n      this.t = 1;\n      this.s = (x<0)?-1:0;\n      if(x > 0) this[0] = x;\n      else if(x < -1) this[0] = x+this.DV;\n      else this.t = 0;\n    }\n\n    // return bigint initialized to value\n    function nbv(i) { var r = nbi(); r.fromInt(i); return r; }\n\n    // (protected) set from string and radix\n    function bnpFromString(s,b) {\n      var k;\n      if(b == 16) k = 4;\n      else if(b == 8) k = 3;\n      else if(b == 256) k = 8; // byte array\n      else if(b == 2) k = 1;\n      else if(b == 32) k = 5;\n      else if(b == 4) k = 2;\n      else { this.fromRadix(s,b); return; }\n      this.t = 0;\n      this.s = 0;\n      var i = s.length, mi = false, sh = 0;\n      while(--i >= 0) {\n        var x = (k==8)?s[i]&0xff:intAt(s,i);\n        if(x < 0) {\n          if(s.charAt(i) == \"-\") mi = true;\n          continue;\n        }\n        mi = false;\n        if(sh == 0)\n          this[this.t++] = x;\n        else if(sh+k > this.DB) {\n          this[this.t-1] |= (x&((1<<(this.DB-sh))-1))<<sh;\n          this[this.t++] = (x>>(this.DB-sh));\n        }\n        else\n          this[this.t-1] |= x<<sh;\n        sh += k;\n        if(sh >= this.DB) sh -= this.DB;\n      }\n      if(k == 8 && (s[0]&0x80) != 0) {\n        this.s = -1;\n        if(sh > 0) this[this.t-1] |= ((1<<(this.DB-sh))-1)<<sh;\n      }\n      this.clamp();\n      if(mi) BigInteger.ZERO.subTo(this,this);\n    }\n\n    // (protected) clamp off excess high words\n    function bnpClamp() {\n      var c = this.s&this.DM;\n      while(this.t > 0 && this[this.t-1] == c) --this.t;\n    }\n\n    // (public) return string representation in given radix\n    function bnToString(b) {\n      if(this.s < 0) return \"-\"+this.negate().toString(b);\n      var k;\n      if(b == 16) k = 4;\n      else if(b == 8) k = 3;\n      else if(b == 2) k = 1;\n      else if(b == 32) k = 5;\n      else if(b == 4) k = 2;\n      else return this.toRadix(b);\n      var km = (1<<k)-1, d, m = false, r = \"\", i = this.t;\n      var p = this.DB-(i*this.DB)%k;\n      if(i-- > 0) {\n        if(p < this.DB && (d = this[i]>>p) > 0) { m = true; r = int2char(d); }\n        while(i >= 0) {\n          if(p < k) {\n            d = (this[i]&((1<<p)-1))<<(k-p);\n            d |= this[--i]>>(p+=this.DB-k);\n          }\n          else {\n            d = (this[i]>>(p-=k))&km;\n            if(p <= 0) { p += this.DB; --i; }\n          }\n          if(d > 0) m = true;\n          if(m) r += int2char(d);\n        }\n      }\n      return m?r:\"0\";\n    }\n\n    // (public) -this\n    function bnNegate() { var r = nbi(); BigInteger.ZERO.subTo(this,r); return r; }\n\n    // (public) |this|\n    function bnAbs() { return (this.s<0)?this.negate():this; }\n\n    // (public) return + if this > a, - if this < a, 0 if equal\n    function bnCompareTo(a) {\n      var r = this.s-a.s;\n      if(r != 0) return r;\n      var i = this.t;\n      r = i-a.t;\n      if(r != 0) return (this.s<0)?-r:r;\n      while(--i >= 0) if((r=this[i]-a[i]) != 0) return r;\n      return 0;\n    }\n\n    // returns bit length of the integer x\n    function nbits(x) {\n      var r = 1, t;\n      if((t=x>>>16) != 0) { x = t; r += 16; }\n      if((t=x>>8) != 0) { x = t; r += 8; }\n      if((t=x>>4) != 0) { x = t; r += 4; }\n      if((t=x>>2) != 0) { x = t; r += 2; }\n      if((t=x>>1) != 0) { x = t; r += 1; }\n      return r;\n    }\n\n    // (public) return the number of bits in \"this\"\n    function bnBitLength() {\n      if(this.t <= 0) return 0;\n      return this.DB*(this.t-1)+nbits(this[this.t-1]^(this.s&this.DM));\n    }\n\n    // (protected) r = this << n*DB\n    function bnpDLShiftTo(n,r) {\n      var i;\n      for(i = this.t-1; i >= 0; --i) r[i+n] = this[i];\n      for(i = n-1; i >= 0; --i) r[i] = 0;\n      r.t = this.t+n;\n      r.s = this.s;\n    }\n\n    // (protected) r = this >> n*DB\n    function bnpDRShiftTo(n,r) {\n      for(var i = n; i < this.t; ++i) r[i-n] = this[i];\n      r.t = Math.max(this.t-n,0);\n      r.s = this.s;\n    }\n\n    // (protected) r = this << n\n    function bnpLShiftTo(n,r) {\n      var bs = n%this.DB;\n      var cbs = this.DB-bs;\n      var bm = (1<<cbs)-1;\n      var ds = Math.floor(n/this.DB), c = (this.s<<bs)&this.DM, i;\n      for(i = this.t-1; i >= 0; --i) {\n        r[i+ds+1] = (this[i]>>cbs)|c;\n        c = (this[i]&bm)<<bs;\n      }\n      for(i = ds-1; i >= 0; --i) r[i] = 0;\n      r[ds] = c;\n      r.t = this.t+ds+1;\n      r.s = this.s;\n      r.clamp();\n    }\n\n    // (protected) r = this >> n\n    function bnpRShiftTo(n,r) {\n      r.s = this.s;\n      var ds = Math.floor(n/this.DB);\n      if(ds >= this.t) { r.t = 0; return; }\n      var bs = n%this.DB;\n      var cbs = this.DB-bs;\n      var bm = (1<<bs)-1;\n      r[0] = this[ds]>>bs;\n      for(var i = ds+1; i < this.t; ++i) {\n        r[i-ds-1] |= (this[i]&bm)<<cbs;\n        r[i-ds] = this[i]>>bs;\n      }\n      if(bs > 0) r[this.t-ds-1] |= (this.s&bm)<<cbs;\n      r.t = this.t-ds;\n      r.clamp();\n    }\n\n    // (protected) r = this - a\n    function bnpSubTo(a,r) {\n      var i = 0, c = 0, m = Math.min(a.t,this.t);\n      while(i < m) {\n        c += this[i]-a[i];\n        r[i++] = c&this.DM;\n        c >>= this.DB;\n      }\n      if(a.t < this.t) {\n        c -= a.s;\n        while(i < this.t) {\n          c += this[i];\n          r[i++] = c&this.DM;\n          c >>= this.DB;\n        }\n        c += this.s;\n      }\n      else {\n        c += this.s;\n        while(i < a.t) {\n          c -= a[i];\n          r[i++] = c&this.DM;\n          c >>= this.DB;\n        }\n        c -= a.s;\n      }\n      r.s = (c<0)?-1:0;\n      if(c < -1) r[i++] = this.DV+c;\n      else if(c > 0) r[i++] = c;\n      r.t = i;\n      r.clamp();\n    }\n\n    // (protected) r = this * a, r != this,a (HAC 14.12)\n    // \"this\" should be the larger one if appropriate.\n    function bnpMultiplyTo(a,r) {\n      var x = this.abs(), y = a.abs();\n      var i = x.t;\n      r.t = i+y.t;\n      while(--i >= 0) r[i] = 0;\n      for(i = 0; i < y.t; ++i) r[i+x.t] = x.am(0,y[i],r,i,0,x.t);\n      r.s = 0;\n      r.clamp();\n      if(this.s != a.s) BigInteger.ZERO.subTo(r,r);\n    }\n\n    // (protected) r = this^2, r != this (HAC 14.16)\n    function bnpSquareTo(r) {\n      var x = this.abs();\n      var i = r.t = 2*x.t;\n      while(--i >= 0) r[i] = 0;\n      for(i = 0; i < x.t-1; ++i) {\n        var c = x.am(i,x[i],r,2*i,0,1);\n        if((r[i+x.t]+=x.am(i+1,2*x[i],r,2*i+1,c,x.t-i-1)) >= x.DV) {\n          r[i+x.t] -= x.DV;\n          r[i+x.t+1] = 1;\n        }\n      }\n      if(r.t > 0) r[r.t-1] += x.am(i,x[i],r,2*i,0,1);\n      r.s = 0;\n      r.clamp();\n    }\n\n    // (protected) divide this by m, quotient and remainder to q, r (HAC 14.20)\n    // r != q, this != m.  q or r may be null.\n    function bnpDivRemTo(m,q,r) {\n      var pm = m.abs();\n      if(pm.t <= 0) return;\n      var pt = this.abs();\n      if(pt.t < pm.t) {\n        if(q != null) q.fromInt(0);\n        if(r != null) this.copyTo(r);\n        return;\n      }\n      if(r == null) r = nbi();\n      var y = nbi(), ts = this.s, ms = m.s;\n      var nsh = this.DB-nbits(pm[pm.t-1]);   // normalize modulus\n      if(nsh > 0) { pm.lShiftTo(nsh,y); pt.lShiftTo(nsh,r); }\n      else { pm.copyTo(y); pt.copyTo(r); }\n      var ys = y.t;\n      var y0 = y[ys-1];\n      if(y0 == 0) return;\n      var yt = y0*(1<<this.F1)+((ys>1)?y[ys-2]>>this.F2:0);\n      var d1 = this.FV/yt, d2 = (1<<this.F1)/yt, e = 1<<this.F2;\n      var i = r.t, j = i-ys, t = (q==null)?nbi():q;\n      y.dlShiftTo(j,t);\n      if(r.compareTo(t) >= 0) {\n        r[r.t++] = 1;\n        r.subTo(t,r);\n      }\n      BigInteger.ONE.dlShiftTo(ys,t);\n      t.subTo(y,y);  // \"negative\" y so we can replace sub with am later\n      while(y.t < ys) y[y.t++] = 0;\n      while(--j >= 0) {\n        // Estimate quotient digit\n        var qd = (r[--i]==y0)?this.DM:Math.floor(r[i]*d1+(r[i-1]+e)*d2);\n        if((r[i]+=y.am(0,qd,r,j,0,ys)) < qd) {   // Try it out\n          y.dlShiftTo(j,t);\n          r.subTo(t,r);\n          while(r[i] < --qd) r.subTo(t,r);\n        }\n      }\n      if(q != null) {\n        r.drShiftTo(ys,q);\n        if(ts != ms) BigInteger.ZERO.subTo(q,q);\n      }\n      r.t = ys;\n      r.clamp();\n      if(nsh > 0) r.rShiftTo(nsh,r); // Denormalize remainder\n      if(ts < 0) BigInteger.ZERO.subTo(r,r);\n    }\n\n    // (public) this mod a\n    function bnMod(a) {\n      var r = nbi();\n      this.abs().divRemTo(a,null,r);\n      if(this.s < 0 && r.compareTo(BigInteger.ZERO) > 0) a.subTo(r,r);\n      return r;\n    }\n\n    // Modular reduction using \"classic\" algorithm\n    function Classic(m) { this.m = m; }\n    function cConvert(x) {\n      if(x.s < 0 || x.compareTo(this.m) >= 0) return x.mod(this.m);\n      else return x;\n    }\n    function cRevert(x) { return x; }\n    function cReduce(x) { x.divRemTo(this.m,null,x); }\n    function cMulTo(x,y,r) { x.multiplyTo(y,r); this.reduce(r); }\n    function cSqrTo(x,r) { x.squareTo(r); this.reduce(r); }\n\n    Classic.prototype.convert = cConvert;\n    Classic.prototype.revert = cRevert;\n    Classic.prototype.reduce = cReduce;\n    Classic.prototype.mulTo = cMulTo;\n    Classic.prototype.sqrTo = cSqrTo;\n\n    // (protected) return \"-1/this % 2^DB\"; useful for Mont. reduction\n    // justification:\n    //         xy == 1 (mod m)\n    //         xy =  1+km\n    //   xy(2-xy) = (1+km)(1-km)\n    // x[y(2-xy)] = 1-k^2m^2\n    // x[y(2-xy)] == 1 (mod m^2)\n    // if y is 1/x mod m, then y(2-xy) is 1/x mod m^2\n    // should reduce x and y(2-xy) by m^2 at each step to keep size bounded.\n    // JS multiply \"overflows\" differently from C/C++, so care is needed here.\n    function bnpInvDigit() {\n      if(this.t < 1) return 0;\n      var x = this[0];\n      if((x&1) == 0) return 0;\n      var y = x&3;       // y == 1/x mod 2^2\n      y = (y*(2-(x&0xf)*y))&0xf; // y == 1/x mod 2^4\n      y = (y*(2-(x&0xff)*y))&0xff;   // y == 1/x mod 2^8\n      y = (y*(2-(((x&0xffff)*y)&0xffff)))&0xffff;    // y == 1/x mod 2^16\n      // last step - calculate inverse mod DV directly;\n      // assumes 16 < DB <= 32 and assumes ability to handle 48-bit ints\n      y = (y*(2-x*y%this.DV))%this.DV;       // y == 1/x mod 2^dbits\n      // we really want the negative inverse, and -DV < y < DV\n      return (y>0)?this.DV-y:-y;\n    }\n\n    // Montgomery reduction\n    function Montgomery(m) {\n      this.m = m;\n      this.mp = m.invDigit();\n      this.mpl = this.mp&0x7fff;\n      this.mph = this.mp>>15;\n      this.um = (1<<(m.DB-15))-1;\n      this.mt2 = 2*m.t;\n    }\n\n    // xR mod m\n    function montConvert(x) {\n      var r = nbi();\n      x.abs().dlShiftTo(this.m.t,r);\n      r.divRemTo(this.m,null,r);\n      if(x.s < 0 && r.compareTo(BigInteger.ZERO) > 0) this.m.subTo(r,r);\n      return r;\n    }\n\n    // x/R mod m\n    function montRevert(x) {\n      var r = nbi();\n      x.copyTo(r);\n      this.reduce(r);\n      return r;\n    }\n\n    // x = x/R mod m (HAC 14.32)\n    function montReduce(x) {\n      while(x.t <= this.mt2) // pad x so am has enough room later\n        x[x.t++] = 0;\n      for(var i = 0; i < this.m.t; ++i) {\n        // faster way of calculating u0 = x[i]*mp mod DV\n        var j = x[i]&0x7fff;\n        var u0 = (j*this.mpl+(((j*this.mph+(x[i]>>15)*this.mpl)&this.um)<<15))&x.DM;\n        // use am to combine the multiply-shift-add into one call\n        j = i+this.m.t;\n        x[j] += this.m.am(0,u0,x,i,0,this.m.t);\n        // propagate carry\n        while(x[j] >= x.DV) { x[j] -= x.DV; x[++j]++; }\n      }\n      x.clamp();\n      x.drShiftTo(this.m.t,x);\n      if(x.compareTo(this.m) >= 0) x.subTo(this.m,x);\n    }\n\n    // r = \"x^2/R mod m\"; x != r\n    function montSqrTo(x,r) { x.squareTo(r); this.reduce(r); }\n\n    // r = \"xy/R mod m\"; x,y != r\n    function montMulTo(x,y,r) { x.multiplyTo(y,r); this.reduce(r); }\n\n    Montgomery.prototype.convert = montConvert;\n    Montgomery.prototype.revert = montRevert;\n    Montgomery.prototype.reduce = montReduce;\n    Montgomery.prototype.mulTo = montMulTo;\n    Montgomery.prototype.sqrTo = montSqrTo;\n\n    // (protected) true iff this is even\n    function bnpIsEven() { return ((this.t>0)?(this[0]&1):this.s) == 0; }\n\n    // (protected) this^e, e < 2^32, doing sqr and mul with \"r\" (HAC 14.79)\n    function bnpExp(e,z) {\n      if(e > 0xffffffff || e < 1) return BigInteger.ONE;\n      var r = nbi(), r2 = nbi(), g = z.convert(this), i = nbits(e)-1;\n      g.copyTo(r);\n      while(--i >= 0) {\n        z.sqrTo(r,r2);\n        if((e&(1<<i)) > 0) z.mulTo(r2,g,r);\n        else { var t = r; r = r2; r2 = t; }\n      }\n      return z.revert(r);\n    }\n\n    // (public) this^e % m, 0 <= e < 2^32\n    function bnModPowInt(e,m) {\n      var z;\n      if(e < 256 || m.isEven()) z = new Classic(m); else z = new Montgomery(m);\n      return this.exp(e,z);\n    }\n\n    // protected\n    BigInteger.prototype.copyTo = bnpCopyTo;\n    BigInteger.prototype.fromInt = bnpFromInt;\n    BigInteger.prototype.fromString = bnpFromString;\n    BigInteger.prototype.clamp = bnpClamp;\n    BigInteger.prototype.dlShiftTo = bnpDLShiftTo;\n    BigInteger.prototype.drShiftTo = bnpDRShiftTo;\n    BigInteger.prototype.lShiftTo = bnpLShiftTo;\n    BigInteger.prototype.rShiftTo = bnpRShiftTo;\n    BigInteger.prototype.subTo = bnpSubTo;\n    BigInteger.prototype.multiplyTo = bnpMultiplyTo;\n    BigInteger.prototype.squareTo = bnpSquareTo;\n    BigInteger.prototype.divRemTo = bnpDivRemTo;\n    BigInteger.prototype.invDigit = bnpInvDigit;\n    BigInteger.prototype.isEven = bnpIsEven;\n    BigInteger.prototype.exp = bnpExp;\n\n    // public\n    BigInteger.prototype.toString = bnToString;\n    BigInteger.prototype.negate = bnNegate;\n    BigInteger.prototype.abs = bnAbs;\n    BigInteger.prototype.compareTo = bnCompareTo;\n    BigInteger.prototype.bitLength = bnBitLength;\n    BigInteger.prototype.mod = bnMod;\n    BigInteger.prototype.modPowInt = bnModPowInt;\n\n    // \"constants\"\n    BigInteger.ZERO = nbv(0);\n    BigInteger.ONE = nbv(1);\n\n    // Copyright (c) 2005-2009  Tom Wu\n    // All Rights Reserved.\n    // See \"LICENSE\" for details.\n\n    // Extended JavaScript BN functions, required for RSA private ops.\n\n    // Version 1.1: new BigInteger(\"0\", 10) returns \"proper\" zero\n    // Version 1.2: square() API, isProbablePrime fix\n\n    // (public)\n    function bnClone() { var r = nbi(); this.copyTo(r); return r; }\n\n    // (public) return value as integer\n    function bnIntValue() {\n      if(this.s < 0) {\n        if(this.t == 1) return this[0]-this.DV;\n        else if(this.t == 0) return -1;\n      }\n      else if(this.t == 1) return this[0];\n      else if(this.t == 0) return 0;\n      // assumes 16 < DB < 32\n      return ((this[1]&((1<<(32-this.DB))-1))<<this.DB)|this[0];\n    }\n\n    // (public) return value as byte\n    function bnByteValue() { return (this.t==0)?this.s:(this[0]<<24)>>24; }\n\n    // (public) return value as short (assumes DB>=16)\n    function bnShortValue() { return (this.t==0)?this.s:(this[0]<<16)>>16; }\n\n    // (protected) return x s.t. r^x < DV\n    function bnpChunkSize(r) { return Math.floor(Math.LN2*this.DB/Math.log(r)); }\n\n    // (public) 0 if this == 0, 1 if this > 0\n    function bnSigNum() {\n      if(this.s < 0) return -1;\n      else if(this.t <= 0 || (this.t == 1 && this[0] <= 0)) return 0;\n      else return 1;\n    }\n\n    // (protected) convert to radix string\n    function bnpToRadix(b) {\n      if(b == null) b = 10;\n      if(this.signum() == 0 || b < 2 || b > 36) return \"0\";\n      var cs = this.chunkSize(b);\n      var a = Math.pow(b,cs);\n      var d = nbv(a), y = nbi(), z = nbi(), r = \"\";\n      this.divRemTo(d,y,z);\n      while(y.signum() > 0) {\n        r = (a+z.intValue()).toString(b).substr(1) + r;\n        y.divRemTo(d,y,z);\n      }\n      return z.intValue().toString(b) + r;\n    }\n\n    // (protected) convert from radix string\n    function bnpFromRadix(s,b) {\n      this.fromInt(0);\n      if(b == null) b = 10;\n      var cs = this.chunkSize(b);\n      var d = Math.pow(b,cs), mi = false, j = 0, w = 0;\n      for(var i = 0; i < s.length; ++i) {\n        var x = intAt(s,i);\n        if(x < 0) {\n          if(s.charAt(i) == \"-\" && this.signum() == 0) mi = true;\n          continue;\n        }\n        w = b*w+x;\n        if(++j >= cs) {\n          this.dMultiply(d);\n          this.dAddOffset(w,0);\n          j = 0;\n          w = 0;\n        }\n      }\n      if(j > 0) {\n        this.dMultiply(Math.pow(b,j));\n        this.dAddOffset(w,0);\n      }\n      if(mi) BigInteger.ZERO.subTo(this,this);\n    }\n\n    // (protected) alternate constructor\n    function bnpFromNumber(a,b,c) {\n      if(\"number\" == typeof b) {\n        // new BigInteger(int,int,RNG)\n        if(a < 2) this.fromInt(1);\n        else {\n          this.fromNumber(a,c);\n          if(!this.testBit(a-1))    // force MSB set\n            this.bitwiseTo(BigInteger.ONE.shiftLeft(a-1),op_or,this);\n          if(this.isEven()) this.dAddOffset(1,0); // force odd\n          while(!this.isProbablePrime(b)) {\n            this.dAddOffset(2,0);\n            if(this.bitLength() > a) this.subTo(BigInteger.ONE.shiftLeft(a-1),this);\n          }\n        }\n      }\n      else {\n        // new BigInteger(int,RNG)\n        var x = new Array(), t = a&7;\n        x.length = (a>>3)+1;\n        b.nextBytes(x);\n        if(t > 0) x[0] &= ((1<<t)-1); else x[0] = 0;\n        this.fromString(x,256);\n      }\n    }\n\n    // (public) convert to bigendian byte array\n    function bnToByteArray() {\n      var i = this.t, r = new Array();\n      r[0] = this.s;\n      var p = this.DB-(i*this.DB)%8, d, k = 0;\n      if(i-- > 0) {\n        if(p < this.DB && (d = this[i]>>p) != (this.s&this.DM)>>p)\n          r[k++] = d|(this.s<<(this.DB-p));\n        while(i >= 0) {\n          if(p < 8) {\n            d = (this[i]&((1<<p)-1))<<(8-p);\n            d |= this[--i]>>(p+=this.DB-8);\n          }\n          else {\n            d = (this[i]>>(p-=8))&0xff;\n            if(p <= 0) { p += this.DB; --i; }\n          }\n          if((d&0x80) != 0) d |= -256;\n          if(k == 0 && (this.s&0x80) != (d&0x80)) ++k;\n          if(k > 0 || d != this.s) r[k++] = d;\n        }\n      }\n      return r;\n    }\n\n    function bnEquals(a) { return(this.compareTo(a)==0); }\n    function bnMin(a) { return(this.compareTo(a)<0)?this:a; }\n    function bnMax(a) { return(this.compareTo(a)>0)?this:a; }\n\n    // (protected) r = this op a (bitwise)\n    function bnpBitwiseTo(a,op,r) {\n      var i, f, m = Math.min(a.t,this.t);\n      for(i = 0; i < m; ++i) r[i] = op(this[i],a[i]);\n      if(a.t < this.t) {\n        f = a.s&this.DM;\n        for(i = m; i < this.t; ++i) r[i] = op(this[i],f);\n        r.t = this.t;\n      }\n      else {\n        f = this.s&this.DM;\n        for(i = m; i < a.t; ++i) r[i] = op(f,a[i]);\n        r.t = a.t;\n      }\n      r.s = op(this.s,a.s);\n      r.clamp();\n    }\n\n    // (public) this & a\n    function op_and(x,y) { return x&y; }\n    function bnAnd(a) { var r = nbi(); this.bitwiseTo(a,op_and,r); return r; }\n\n    // (public) this | a\n    function op_or(x,y) { return x|y; }\n    function bnOr(a) { var r = nbi(); this.bitwiseTo(a,op_or,r); return r; }\n\n    // (public) this ^ a\n    function op_xor(x,y) { return x^y; }\n    function bnXor(a) { var r = nbi(); this.bitwiseTo(a,op_xor,r); return r; }\n\n    // (public) this & ~a\n    function op_andnot(x,y) { return x&~y; }\n    function bnAndNot(a) { var r = nbi(); this.bitwiseTo(a,op_andnot,r); return r; }\n\n    // (public) ~this\n    function bnNot() {\n      var r = nbi();\n      for(var i = 0; i < this.t; ++i) r[i] = this.DM&~this[i];\n      r.t = this.t;\n      r.s = ~this.s;\n      return r;\n    }\n\n    // (public) this << n\n    function bnShiftLeft(n) {\n      var r = nbi();\n      if(n < 0) this.rShiftTo(-n,r); else this.lShiftTo(n,r);\n      return r;\n    }\n\n    // (public) this >> n\n    function bnShiftRight(n) {\n      var r = nbi();\n      if(n < 0) this.lShiftTo(-n,r); else this.rShiftTo(n,r);\n      return r;\n    }\n\n    // return index of lowest 1-bit in x, x < 2^31\n    function lbit(x) {\n      if(x == 0) return -1;\n      var r = 0;\n      if((x&0xffff) == 0) { x >>= 16; r += 16; }\n      if((x&0xff) == 0) { x >>= 8; r += 8; }\n      if((x&0xf) == 0) { x >>= 4; r += 4; }\n      if((x&3) == 0) { x >>= 2; r += 2; }\n      if((x&1) == 0) ++r;\n      return r;\n    }\n\n    // (public) returns index of lowest 1-bit (or -1 if none)\n    function bnGetLowestSetBit() {\n      for(var i = 0; i < this.t; ++i)\n        if(this[i] != 0) return i*this.DB+lbit(this[i]);\n      if(this.s < 0) return this.t*this.DB;\n      return -1;\n    }\n\n    // return number of 1 bits in x\n    function cbit(x) {\n      var r = 0;\n      while(x != 0) { x &= x-1; ++r; }\n      return r;\n    }\n\n    // (public) return number of set bits\n    function bnBitCount() {\n      var r = 0, x = this.s&this.DM;\n      for(var i = 0; i < this.t; ++i) r += cbit(this[i]^x);\n      return r;\n    }\n\n    // (public) true iff nth bit is set\n    function bnTestBit(n) {\n      var j = Math.floor(n/this.DB);\n      if(j >= this.t) return(this.s!=0);\n      return((this[j]&(1<<(n%this.DB)))!=0);\n    }\n\n    // (protected) this op (1<<n)\n    function bnpChangeBit(n,op) {\n      var r = BigInteger.ONE.shiftLeft(n);\n      this.bitwiseTo(r,op,r);\n      return r;\n    }\n\n    // (public) this | (1<<n)\n    function bnSetBit(n) { return this.changeBit(n,op_or); }\n\n    // (public) this & ~(1<<n)\n    function bnClearBit(n) { return this.changeBit(n,op_andnot); }\n\n    // (public) this ^ (1<<n)\n    function bnFlipBit(n) { return this.changeBit(n,op_xor); }\n\n    // (protected) r = this + a\n    function bnpAddTo(a,r) {\n      var i = 0, c = 0, m = Math.min(a.t,this.t);\n      while(i < m) {\n        c += this[i]+a[i];\n        r[i++] = c&this.DM;\n        c >>= this.DB;\n      }\n      if(a.t < this.t) {\n        c += a.s;\n        while(i < this.t) {\n          c += this[i];\n          r[i++] = c&this.DM;\n          c >>= this.DB;\n        }\n        c += this.s;\n      }\n      else {\n        c += this.s;\n        while(i < a.t) {\n          c += a[i];\n          r[i++] = c&this.DM;\n          c >>= this.DB;\n        }\n        c += a.s;\n      }\n      r.s = (c<0)?-1:0;\n      if(c > 0) r[i++] = c;\n      else if(c < -1) r[i++] = this.DV+c;\n      r.t = i;\n      r.clamp();\n    }\n\n    // (public) this + a\n    function bnAdd(a) { var r = nbi(); this.addTo(a,r); return r; }\n\n    // (public) this - a\n    function bnSubtract(a) { var r = nbi(); this.subTo(a,r); return r; }\n\n    // (public) this * a\n    function bnMultiply(a) { var r = nbi(); this.multiplyTo(a,r); return r; }\n\n    // (public) this^2\n    function bnSquare() { var r = nbi(); this.squareTo(r); return r; }\n\n    // (public) this / a\n    function bnDivide(a) { var r = nbi(); this.divRemTo(a,r,null); return r; }\n\n    // (public) this % a\n    function bnRemainder(a) { var r = nbi(); this.divRemTo(a,null,r); return r; }\n\n    // (public) [this/a,this%a]\n    function bnDivideAndRemainder(a) {\n      var q = nbi(), r = nbi();\n      this.divRemTo(a,q,r);\n      return new Array(q,r);\n    }\n\n    // (protected) this *= n, this >= 0, 1 < n < DV\n    function bnpDMultiply(n) {\n      this[this.t] = this.am(0,n-1,this,0,0,this.t);\n      ++this.t;\n      this.clamp();\n    }\n\n    // (protected) this += n << w words, this >= 0\n    function bnpDAddOffset(n,w) {\n      if(n == 0) return;\n      while(this.t <= w) this[this.t++] = 0;\n      this[w] += n;\n      while(this[w] >= this.DV) {\n        this[w] -= this.DV;\n        if(++w >= this.t) this[this.t++] = 0;\n        ++this[w];\n      }\n    }\n\n    // A \"null\" reducer\n    function NullExp() {}\n    function nNop(x) { return x; }\n    function nMulTo(x,y,r) { x.multiplyTo(y,r); }\n    function nSqrTo(x,r) { x.squareTo(r); }\n\n    NullExp.prototype.convert = nNop;\n    NullExp.prototype.revert = nNop;\n    NullExp.prototype.mulTo = nMulTo;\n    NullExp.prototype.sqrTo = nSqrTo;\n\n    // (public) this^e\n    function bnPow(e) { return this.exp(e,new NullExp()); }\n\n    // (protected) r = lower n words of \"this * a\", a.t <= n\n    // \"this\" should be the larger one if appropriate.\n    function bnpMultiplyLowerTo(a,n,r) {\n      var i = Math.min(this.t+a.t,n);\n      r.s = 0; // assumes a,this >= 0\n      r.t = i;\n      while(i > 0) r[--i] = 0;\n      var j;\n      for(j = r.t-this.t; i < j; ++i) r[i+this.t] = this.am(0,a[i],r,i,0,this.t);\n      for(j = Math.min(a.t,n); i < j; ++i) this.am(0,a[i],r,i,0,n-i);\n      r.clamp();\n    }\n\n    // (protected) r = \"this * a\" without lower n words, n > 0\n    // \"this\" should be the larger one if appropriate.\n    function bnpMultiplyUpperTo(a,n,r) {\n      --n;\n      var i = r.t = this.t+a.t-n;\n      r.s = 0; // assumes a,this >= 0\n      while(--i >= 0) r[i] = 0;\n      for(i = Math.max(n-this.t,0); i < a.t; ++i)\n        r[this.t+i-n] = this.am(n-i,a[i],r,0,0,this.t+i-n);\n      r.clamp();\n      r.drShiftTo(1,r);\n    }\n\n    // Barrett modular reduction\n    function Barrett(m) {\n      // setup Barrett\n      this.r2 = nbi();\n      this.q3 = nbi();\n      BigInteger.ONE.dlShiftTo(2*m.t,this.r2);\n      this.mu = this.r2.divide(m);\n      this.m = m;\n    }\n\n    function barrettConvert(x) {\n      if(x.s < 0 || x.t > 2*this.m.t) return x.mod(this.m);\n      else if(x.compareTo(this.m) < 0) return x;\n      else { var r = nbi(); x.copyTo(r); this.reduce(r); return r; }\n    }\n\n    function barrettRevert(x) { return x; }\n\n    // x = x mod m (HAC 14.42)\n    function barrettReduce(x) {\n      x.drShiftTo(this.m.t-1,this.r2);\n      if(x.t > this.m.t+1) { x.t = this.m.t+1; x.clamp(); }\n      this.mu.multiplyUpperTo(this.r2,this.m.t+1,this.q3);\n      this.m.multiplyLowerTo(this.q3,this.m.t+1,this.r2);\n      while(x.compareTo(this.r2) < 0) x.dAddOffset(1,this.m.t+1);\n      x.subTo(this.r2,x);\n      while(x.compareTo(this.m) >= 0) x.subTo(this.m,x);\n    }\n\n    // r = x^2 mod m; x != r\n    function barrettSqrTo(x,r) { x.squareTo(r); this.reduce(r); }\n\n    // r = x*y mod m; x,y != r\n    function barrettMulTo(x,y,r) { x.multiplyTo(y,r); this.reduce(r); }\n\n    Barrett.prototype.convert = barrettConvert;\n    Barrett.prototype.revert = barrettRevert;\n    Barrett.prototype.reduce = barrettReduce;\n    Barrett.prototype.mulTo = barrettMulTo;\n    Barrett.prototype.sqrTo = barrettSqrTo;\n\n    // (public) this^e % m (HAC 14.85)\n    function bnModPow(e,m) {\n      var i = e.bitLength(), k, r = nbv(1), z;\n      if(i <= 0) return r;\n      else if(i < 18) k = 1;\n      else if(i < 48) k = 3;\n      else if(i < 144) k = 4;\n      else if(i < 768) k = 5;\n      else k = 6;\n      if(i < 8)\n        z = new Classic(m);\n      else if(m.isEven())\n        z = new Barrett(m);\n      else\n        z = new Montgomery(m);\n\n      // precomputation\n      var g = new Array(), n = 3, k1 = k-1, km = (1<<k)-1;\n      g[1] = z.convert(this);\n      if(k > 1) {\n        var g2 = nbi();\n        z.sqrTo(g[1],g2);\n        while(n <= km) {\n          g[n] = nbi();\n          z.mulTo(g2,g[n-2],g[n]);\n          n += 2;\n        }\n      }\n\n      var j = e.t-1, w, is1 = true, r2 = nbi(), t;\n      i = nbits(e[j])-1;\n      while(j >= 0) {\n        if(i >= k1) w = (e[j]>>(i-k1))&km;\n        else {\n          w = (e[j]&((1<<(i+1))-1))<<(k1-i);\n          if(j > 0) w |= e[j-1]>>(this.DB+i-k1);\n        }\n\n        n = k;\n        while((w&1) == 0) { w >>= 1; --n; }\n        if((i -= n) < 0) { i += this.DB; --j; }\n        if(is1) {    // ret == 1, don't bother squaring or multiplying it\n          g[w].copyTo(r);\n          is1 = false;\n        }\n        else {\n          while(n > 1) { z.sqrTo(r,r2); z.sqrTo(r2,r); n -= 2; }\n          if(n > 0) z.sqrTo(r,r2); else { t = r; r = r2; r2 = t; }\n          z.mulTo(r2,g[w],r);\n        }\n\n        while(j >= 0 && (e[j]&(1<<i)) == 0) {\n          z.sqrTo(r,r2); t = r; r = r2; r2 = t;\n          if(--i < 0) { i = this.DB-1; --j; }\n        }\n      }\n      return z.revert(r);\n    }\n\n    // (public) gcd(this,a) (HAC 14.54)\n    function bnGCD(a) {\n      var x = (this.s<0)?this.negate():this.clone();\n      var y = (a.s<0)?a.negate():a.clone();\n      if(x.compareTo(y) < 0) { var t = x; x = y; y = t; }\n      var i = x.getLowestSetBit(), g = y.getLowestSetBit();\n      if(g < 0) return x;\n      if(i < g) g = i;\n      if(g > 0) {\n        x.rShiftTo(g,x);\n        y.rShiftTo(g,y);\n      }\n      while(x.signum() > 0) {\n        if((i = x.getLowestSetBit()) > 0) x.rShiftTo(i,x);\n        if((i = y.getLowestSetBit()) > 0) y.rShiftTo(i,y);\n        if(x.compareTo(y) >= 0) {\n          x.subTo(y,x);\n          x.rShiftTo(1,x);\n        }\n        else {\n          y.subTo(x,y);\n          y.rShiftTo(1,y);\n        }\n      }\n      if(g > 0) y.lShiftTo(g,y);\n      return y;\n    }\n\n    // (protected) this % n, n < 2^26\n    function bnpModInt(n) {\n      if(n <= 0) return 0;\n      var d = this.DV%n, r = (this.s<0)?n-1:0;\n      if(this.t > 0)\n        if(d == 0) r = this[0]%n;\n        else for(var i = this.t-1; i >= 0; --i) r = (d*r+this[i])%n;\n      return r;\n    }\n\n    // (public) 1/this % m (HAC 14.61)\n    function bnModInverse(m) {\n      var ac = m.isEven();\n      if((this.isEven() && ac) || m.signum() == 0) return BigInteger.ZERO;\n      var u = m.clone(), v = this.clone();\n      var a = nbv(1), b = nbv(0), c = nbv(0), d = nbv(1);\n      while(u.signum() != 0) {\n        while(u.isEven()) {\n          u.rShiftTo(1,u);\n          if(ac) {\n            if(!a.isEven() || !b.isEven()) { a.addTo(this,a); b.subTo(m,b); }\n            a.rShiftTo(1,a);\n          }\n          else if(!b.isEven()) b.subTo(m,b);\n          b.rShiftTo(1,b);\n        }\n        while(v.isEven()) {\n          v.rShiftTo(1,v);\n          if(ac) {\n            if(!c.isEven() || !d.isEven()) { c.addTo(this,c); d.subTo(m,d); }\n            c.rShiftTo(1,c);\n          }\n          else if(!d.isEven()) d.subTo(m,d);\n          d.rShiftTo(1,d);\n        }\n        if(u.compareTo(v) >= 0) {\n          u.subTo(v,u);\n          if(ac) a.subTo(c,a);\n          b.subTo(d,b);\n        }\n        else {\n          v.subTo(u,v);\n          if(ac) c.subTo(a,c);\n          d.subTo(b,d);\n        }\n      }\n      if(v.compareTo(BigInteger.ONE) != 0) return BigInteger.ZERO;\n      if(d.compareTo(m) >= 0) return d.subtract(m);\n      if(d.signum() < 0) d.addTo(m,d); else return d;\n      if(d.signum() < 0) return d.add(m); else return d;\n    }\n\n    var lowprimes = [2,3,5,7,11,13,17,19,23,29,31,37,41,43,47,53,59,61,67,71,73,79,83,89,97,101,103,107,109,113,127,131,137,139,149,151,157,163,167,173,179,181,191,193,197,199,211,223,227,229,233,239,241,251,257,263,269,271,277,281,283,293,307,311,313,317,331,337,347,349,353,359,367,373,379,383,389,397,401,409,419,421,431,433,439,443,449,457,461,463,467,479,487,491,499,503,509,521,523,541,547,557,563,569,571,577,587,593,599,601,607,613,617,619,631,641,643,647,653,659,661,673,677,683,691,701,709,719,727,733,739,743,751,757,761,769,773,787,797,809,811,821,823,827,829,839,853,857,859,863,877,881,883,887,907,911,919,929,937,941,947,953,967,971,977,983,991,997];\n    var lplim = (1<<26)/lowprimes[lowprimes.length-1];\n\n    // (public) test primality with certainty >= 1-.5^t\n    function bnIsProbablePrime(t) {\n      var i, x = this.abs();\n      if(x.t == 1 && x[0] <= lowprimes[lowprimes.length-1]) {\n        for(i = 0; i < lowprimes.length; ++i)\n          if(x[0] == lowprimes[i]) return true;\n        return false;\n      }\n      if(x.isEven()) return false;\n      i = 1;\n      while(i < lowprimes.length) {\n        var m = lowprimes[i], j = i+1;\n        while(j < lowprimes.length && m < lplim) m *= lowprimes[j++];\n        m = x.modInt(m);\n        while(i < j) if(m%lowprimes[i++] == 0) return false;\n      }\n      return x.millerRabin(t);\n    }\n\n    // (protected) true if probably prime (HAC 4.24, Miller-Rabin)\n    function bnpMillerRabin(t) {\n      var n1 = this.subtract(BigInteger.ONE);\n      var k = n1.getLowestSetBit();\n      if(k <= 0) return false;\n      var r = n1.shiftRight(k);\n      t = (t+1)>>1;\n      if(t > lowprimes.length) t = lowprimes.length;\n      var a = nbi();\n      for(var i = 0; i < t; ++i) {\n        //Pick bases at random, instead of starting at 2\n        a.fromInt(lowprimes[Math.floor(Math.random()*lowprimes.length)]);\n        var y = a.modPow(r,this);\n        if(y.compareTo(BigInteger.ONE) != 0 && y.compareTo(n1) != 0) {\n          var j = 1;\n          while(j++ < k && y.compareTo(n1) != 0) {\n            y = y.modPowInt(2,this);\n            if(y.compareTo(BigInteger.ONE) == 0) return false;\n          }\n          if(y.compareTo(n1) != 0) return false;\n        }\n      }\n      return true;\n    }\n\n    // protected\n    BigInteger.prototype.chunkSize = bnpChunkSize;\n    BigInteger.prototype.toRadix = bnpToRadix;\n    BigInteger.prototype.fromRadix = bnpFromRadix;\n    BigInteger.prototype.fromNumber = bnpFromNumber;\n    BigInteger.prototype.bitwiseTo = bnpBitwiseTo;\n    BigInteger.prototype.changeBit = bnpChangeBit;\n    BigInteger.prototype.addTo = bnpAddTo;\n    BigInteger.prototype.dMultiply = bnpDMultiply;\n    BigInteger.prototype.dAddOffset = bnpDAddOffset;\n    BigInteger.prototype.multiplyLowerTo = bnpMultiplyLowerTo;\n    BigInteger.prototype.multiplyUpperTo = bnpMultiplyUpperTo;\n    BigInteger.prototype.modInt = bnpModInt;\n    BigInteger.prototype.millerRabin = bnpMillerRabin;\n\n    // public\n    BigInteger.prototype.clone = bnClone;\n    BigInteger.prototype.intValue = bnIntValue;\n    BigInteger.prototype.byteValue = bnByteValue;\n    BigInteger.prototype.shortValue = bnShortValue;\n    BigInteger.prototype.signum = bnSigNum;\n    BigInteger.prototype.toByteArray = bnToByteArray;\n    BigInteger.prototype.equals = bnEquals;\n    BigInteger.prototype.min = bnMin;\n    BigInteger.prototype.max = bnMax;\n    BigInteger.prototype.and = bnAnd;\n    BigInteger.prototype.or = bnOr;\n    BigInteger.prototype.xor = bnXor;\n    BigInteger.prototype.andNot = bnAndNot;\n    BigInteger.prototype.not = bnNot;\n    BigInteger.prototype.shiftLeft = bnShiftLeft;\n    BigInteger.prototype.shiftRight = bnShiftRight;\n    BigInteger.prototype.getLowestSetBit = bnGetLowestSetBit;\n    BigInteger.prototype.bitCount = bnBitCount;\n    BigInteger.prototype.testBit = bnTestBit;\n    BigInteger.prototype.setBit = bnSetBit;\n    BigInteger.prototype.clearBit = bnClearBit;\n    BigInteger.prototype.flipBit = bnFlipBit;\n    BigInteger.prototype.add = bnAdd;\n    BigInteger.prototype.subtract = bnSubtract;\n    BigInteger.prototype.multiply = bnMultiply;\n    BigInteger.prototype.divide = bnDivide;\n    BigInteger.prototype.remainder = bnRemainder;\n    BigInteger.prototype.divideAndRemainder = bnDivideAndRemainder;\n    BigInteger.prototype.modPow = bnModPow;\n    BigInteger.prototype.modInverse = bnModInverse;\n    BigInteger.prototype.pow = bnPow;\n    BigInteger.prototype.gcd = bnGCD;\n    BigInteger.prototype.isProbablePrime = bnIsProbablePrime;\n\n    // JSBN-specific extension\n    BigInteger.prototype.square = bnSquare;\n\n    // Expose the Barrett function\n    BigInteger.prototype.Barrett = Barrett\n\n    // BigInteger interfaces not implemented in jsbn:\n\n    // BigInteger(int signum, byte[] magnitude)\n    // double doubleValue()\n    // float floatValue()\n    // int hashCode()\n    // long longValue()\n    // static BigInteger valueOf(long val)\n\n    // Random number generator - requires a PRNG backend, e.g. prng4.js\n\n    // For best results, put code like\n    // <body onClick='rng_seed_time();' onKeyPress='rng_seed_time();'>\n    // in your main HTML document.\n\n    var rng_state;\n    var rng_pool;\n    var rng_pptr;\n\n    // Mix in a 32-bit integer into the pool\n    function rng_seed_int(x) {\n      rng_pool[rng_pptr++] ^= x & 255;\n      rng_pool[rng_pptr++] ^= (x >> 8) & 255;\n      rng_pool[rng_pptr++] ^= (x >> 16) & 255;\n      rng_pool[rng_pptr++] ^= (x >> 24) & 255;\n      if(rng_pptr >= rng_psize) rng_pptr -= rng_psize;\n    }\n\n    // Mix in the current time (w/milliseconds) into the pool\n    function rng_seed_time() {\n      rng_seed_int(new Date().getTime());\n    }\n\n    // Initialize the pool with junk if needed.\n    if(rng_pool == null) {\n      rng_pool = new Array();\n      rng_pptr = 0;\n      var t;\n      if(typeof window !== \"undefined\" && window.crypto) {\n        if (window.crypto.getRandomValues) {\n          // Use webcrypto if available\n          var ua = new Uint8Array(32);\n          window.crypto.getRandomValues(ua);\n          for(t = 0; t < 32; ++t)\n            rng_pool[rng_pptr++] = ua[t];\n        }\n        else if(navigator.appName == \"Netscape\" && navigator.appVersion < \"5\") {\n          // Extract entropy (256 bits) from NS4 RNG if available\n          var z = window.crypto.random(32);\n          for(t = 0; t < z.length; ++t)\n            rng_pool[rng_pptr++] = z.charCodeAt(t) & 255;\n        }\n      }\n      while(rng_pptr < rng_psize) {  // extract some randomness from Math.random()\n        t = Math.floor(65536 * Math.random());\n        rng_pool[rng_pptr++] = t >>> 8;\n        rng_pool[rng_pptr++] = t & 255;\n      }\n      rng_pptr = 0;\n      rng_seed_time();\n      //rng_seed_int(window.screenX);\n      //rng_seed_int(window.screenY);\n    }\n\n    function rng_get_byte() {\n      if(rng_state == null) {\n        rng_seed_time();\n        rng_state = prng_newstate();\n        rng_state.init(rng_pool);\n        for(rng_pptr = 0; rng_pptr < rng_pool.length; ++rng_pptr)\n          rng_pool[rng_pptr] = 0;\n        rng_pptr = 0;\n        //rng_pool = null;\n      }\n      // TODO: allow reseeding after first request\n      return rng_state.next();\n    }\n\n    function rng_get_bytes(ba) {\n      var i;\n      for(i = 0; i < ba.length; ++i) ba[i] = rng_get_byte();\n    }\n\n    function SecureRandom() {}\n\n    SecureRandom.prototype.nextBytes = rng_get_bytes;\n\n    // prng4.js - uses Arcfour as a PRNG\n\n    function Arcfour() {\n      this.i = 0;\n      this.j = 0;\n      this.S = new Array();\n    }\n\n    // Initialize arcfour context from key, an array of ints, each from [0..255]\n    function ARC4init(key) {\n      var i, j, t;\n      for(i = 0; i < 256; ++i)\n        this.S[i] = i;\n      j = 0;\n      for(i = 0; i < 256; ++i) {\n        j = (j + this.S[i] + key[i % key.length]) & 255;\n        t = this.S[i];\n        this.S[i] = this.S[j];\n        this.S[j] = t;\n      }\n      this.i = 0;\n      this.j = 0;\n    }\n\n    function ARC4next() {\n      var t;\n      this.i = (this.i + 1) & 255;\n      this.j = (this.j + this.S[this.i]) & 255;\n      t = this.S[this.i];\n      this.S[this.i] = this.S[this.j];\n      this.S[this.j] = t;\n      return this.S[(t + this.S[this.i]) & 255];\n    }\n\n    Arcfour.prototype.init = ARC4init;\n    Arcfour.prototype.next = ARC4next;\n\n    // Plug in your RNG constructor here\n    function prng_newstate() {\n      return new Arcfour();\n    }\n\n    // Pool size must be a multiple of 4 and greater than 32.\n    // An array of bytes the size of the pool will be passed to init()\n    var rng_psize = 256;\n\n    if (true) {\n        exports = module.exports = {\n            default: BigInteger,\n            BigInteger: BigInteger,\n            SecureRandom: SecureRandom,\n        };\n    } else {}\n\n}).call(this);\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/lib/bytesToUuid.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/uuid/lib/bytesToUuid.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n/**\n * Convert array of 16 byte values to UUID string format of the form:\n * XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX\n */\nvar byteToHex = [];\nfor (var i = 0; i < 256; ++i) {\n  byteToHex[i] = (i + 0x100).toString(16).substr(1);\n}\n\nfunction bytesToUuid(buf, offset) {\n  var i = offset || 0;\n  var bth = byteToHex;\n  // join used to fix memory issue caused by concatenation: https://bugs.chromium.org/p/v8/issues/detail?id=3175#c4\n  return ([bth[buf[i++]], bth[buf[i++]], \n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]]]).join('');\n}\n\nmodule.exports = bytesToUuid;\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/lib/rng-browser.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/uuid/lib/rng-browser.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// Unique ID creation requires a high quality random # generator.  In the\n// browser this is a little complicated due to unknown quality of Math.random()\n// and inconsistent support for the `crypto` API.  We do the best we can via\n// feature-detection\n\n// getRandomValues needs to be invoked in a context where \"this\" is a Crypto\n// implementation. Also, find the complete implementation of crypto on IE11.\nvar getRandomValues = (typeof(crypto) != 'undefined' && crypto.getRandomValues && crypto.getRandomValues.bind(crypto)) ||\n                      (typeof(msCrypto) != 'undefined' && typeof window.msCrypto.getRandomValues == 'function' && msCrypto.getRandomValues.bind(msCrypto));\n\nif (getRandomValues) {\n  // WHATWG crypto RNG - http://wiki.whatwg.org/wiki/Crypto\n  var rnds8 = new Uint8Array(16); // eslint-disable-line no-undef\n\n  module.exports = function whatwgRNG() {\n    getRandomValues(rnds8);\n    return rnds8;\n  };\n} else {\n  // Math.random()-based (RNG)\n  //\n  // If all else fails, use Math.random().  It's fast, but is of unspecified\n  // quality.\n  var rnds = new Array(16);\n\n  module.exports = function mathRNG() {\n    for (var i = 0, r; i < 16; i++) {\n      if ((i & 0x03) === 0) r = Math.random() * 0x100000000;\n      rnds[i] = r >>> ((i & 0x03) << 3) & 0xff;\n    }\n\n    return rnds;\n  };\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/v4.js\":\n/*!*********************************!*\\\n  !*** ./node_modules/uuid/v4.js ***!\n  \\*********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar rng = __webpack_require__(/*! ./lib/rng */ \"./node_modules/uuid/lib/rng-browser.js\");\nvar bytesToUuid = __webpack_require__(/*! ./lib/bytesToUuid */ \"./node_modules/uuid/lib/bytesToUuid.js\");\n\nfunction v4(options, buf, offset) {\n  var i = buf && offset || 0;\n\n  if (typeof(options) == 'string') {\n    buf = options === 'binary' ? new Array(16) : null;\n    options = null;\n  }\n  options = options || {};\n\n  var rnds = options.random || (options.rng || rng)();\n\n  // Per 4.4, set bits for version and `clock_seq_hi_and_reserved`\n  rnds[6] = (rnds[6] & 0x0f) | 0x40;\n  rnds[8] = (rnds[8] & 0x3f) | 0x80;\n\n  // Copy bytes to buffer, if provided\n  if (buf) {\n    for (var ii = 0; ii < 16; ++ii) {\n      buf[i + ii] = rnds[ii];\n    }\n  }\n\n  return buf || bytesToUuid(rnds);\n}\n\nmodule.exports = v4;\n\n\n/***/ }),\n\n/***/ \"./polyfills.js\":\n/*!**********************!*\\\n  !*** ./polyfills.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\n__webpack_require__(/*! core-js/es6/promise */ \"./node_modules/core-js/es6/promise.js\");\n\n__webpack_require__(/*! core-js/fn/function/bind */ \"./node_modules/core-js/fn/function/bind.js\");\n\n__webpack_require__(/*! core-js/fn/object/assign */ \"./node_modules/core-js/fn/object/assign.js\");\n\n__webpack_require__(/*! core-js/fn/array/find */ \"./node_modules/core-js/fn/array/find.js\");\n\n__webpack_require__(/*! core-js/fn/array/some */ \"./node_modules/core-js/fn/array/some.js\");\n\n__webpack_require__(/*! core-js/fn/array/is-array */ \"./node_modules/core-js/fn/array/is-array.js\");\n\n__webpack_require__(/*! core-js/fn/array/splice */ \"./node_modules/core-js/fn/array/splice.js\");\n\n/***/ }),\n\n/***/ \"./src/AccessTokenEvents.js\":\n/*!**********************************!*\\\n  !*** ./src/AccessTokenEvents.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.AccessTokenEvents = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Timer = __webpack_require__(/*! ./Timer.js */ \"./src/Timer.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultAccessTokenExpiringNotificationTime = 60; // seconds\n\nvar AccessTokenEvents = exports.AccessTokenEvents = function () {\n    function AccessTokenEvents() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            _ref$accessTokenExpir = _ref.accessTokenExpiringNotificationTime,\n            accessTokenExpiringNotificationTime = _ref$accessTokenExpir === undefined ? DefaultAccessTokenExpiringNotificationTime : _ref$accessTokenExpir,\n            _ref$accessTokenExpir2 = _ref.accessTokenExpiringTimer,\n            accessTokenExpiringTimer = _ref$accessTokenExpir2 === undefined ? new _Timer.Timer(\"Access token expiring\") : _ref$accessTokenExpir2,\n            _ref$accessTokenExpir3 = _ref.accessTokenExpiredTimer,\n            accessTokenExpiredTimer = _ref$accessTokenExpir3 === undefined ? new _Timer.Timer(\"Access token expired\") : _ref$accessTokenExpir3;\n\n        _classCallCheck(this, AccessTokenEvents);\n\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\n\n        this._accessTokenExpiring = accessTokenExpiringTimer;\n        this._accessTokenExpired = accessTokenExpiredTimer;\n    }\n\n    AccessTokenEvents.prototype.load = function load(container) {\n        // only register events if there's an access token and it has an expiration\n        if (container.access_token && container.expires_in !== undefined) {\n            var duration = container.expires_in;\n            _Log.Log.debug(\"AccessTokenEvents.load: access token present, remaining duration:\", duration);\n\n            if (duration > 0) {\n                // only register expiring if we still have time\n                var expiring = duration - this._accessTokenExpiringNotificationTime;\n                if (expiring <= 0) {\n                    expiring = 1;\n                }\n\n                _Log.Log.debug(\"AccessTokenEvents.load: registering expiring timer in:\", expiring);\n                this._accessTokenExpiring.init(expiring);\n            } else {\n                _Log.Log.debug(\"AccessTokenEvents.load: canceling existing expiring timer becase we're past expiration.\");\n                this._accessTokenExpiring.cancel();\n            }\n\n            // if it's negative, it will still fire\n            var expired = duration + 1;\n            _Log.Log.debug(\"AccessTokenEvents.load: registering expired timer in:\", expired);\n            this._accessTokenExpired.init(expired);\n        } else {\n            this._accessTokenExpiring.cancel();\n            this._accessTokenExpired.cancel();\n        }\n    };\n\n    AccessTokenEvents.prototype.unload = function unload() {\n        _Log.Log.debug(\"AccessTokenEvents.unload: canceling existing access token timers\");\n        this._accessTokenExpiring.cancel();\n        this._accessTokenExpired.cancel();\n    };\n\n    AccessTokenEvents.prototype.addAccessTokenExpiring = function addAccessTokenExpiring(cb) {\n        this._accessTokenExpiring.addHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.removeAccessTokenExpiring = function removeAccessTokenExpiring(cb) {\n        this._accessTokenExpiring.removeHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.addAccessTokenExpired = function addAccessTokenExpired(cb) {\n        this._accessTokenExpired.addHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.removeAccessTokenExpired = function removeAccessTokenExpired(cb) {\n        this._accessTokenExpired.removeHandler(cb);\n    };\n\n    return AccessTokenEvents;\n}();\n\n/***/ }),\n\n/***/ \"./src/CheckSessionIFrame.js\":\n/*!***********************************!*\\\n  !*** ./src/CheckSessionIFrame.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CheckSessionIFrame = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultInterval = 2000;\n\nvar CheckSessionIFrame = exports.CheckSessionIFrame = function () {\n    function CheckSessionIFrame(callback, client_id, url, interval) {\n        var stopOnError = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : true;\n\n        _classCallCheck(this, CheckSessionIFrame);\n\n        this._callback = callback;\n        this._client_id = client_id;\n        this._url = url;\n        this._interval = interval || DefaultInterval;\n        this._stopOnError = stopOnError;\n\n        var idx = url.indexOf(\"/\", url.indexOf(\"//\") + 2);\n        this._frame_origin = url.substr(0, idx);\n\n        this._frame = window.document.createElement(\"iframe\");\n\n        // shotgun approach\n        this._frame.style.visibility = \"hidden\";\n        this._frame.style.position = \"absolute\";\n        this._frame.style.display = \"none\";\n        this._frame.style.width = 0;\n        this._frame.style.height = 0;\n\n        this._frame.src = url;\n    }\n\n    CheckSessionIFrame.prototype.load = function load() {\n        var _this = this;\n\n        return new Promise(function (resolve) {\n            _this._frame.onload = function () {\n                resolve();\n            };\n\n            window.document.body.appendChild(_this._frame);\n            _this._boundMessageEvent = _this._message.bind(_this);\n            window.addEventListener(\"message\", _this._boundMessageEvent, false);\n        });\n    };\n\n    CheckSessionIFrame.prototype._message = function _message(e) {\n        if (e.origin === this._frame_origin && e.source === this._frame.contentWindow) {\n            if (e.data === \"error\") {\n                _Log.Log.error(\"CheckSessionIFrame: error message from check session op iframe\");\n                if (this._stopOnError) {\n                    this.stop();\n                }\n            } else if (e.data === \"changed\") {\n                _Log.Log.debug(\"CheckSessionIFrame: changed message from check session op iframe\");\n                this.stop();\n                this._callback();\n            } else {\n                _Log.Log.debug(\"CheckSessionIFrame: \" + e.data + \" message from check session op iframe\");\n            }\n        }\n    };\n\n    CheckSessionIFrame.prototype.start = function start(session_state) {\n        var _this2 = this;\n\n        if (this._session_state !== session_state) {\n            _Log.Log.debug(\"CheckSessionIFrame.start\");\n\n            this.stop();\n\n            this._session_state = session_state;\n\n            var send = function send() {\n                _this2._frame.contentWindow.postMessage(_this2._client_id + \" \" + _this2._session_state, _this2._frame_origin);\n            };\n\n            // trigger now\n            send();\n\n            // and setup timer\n            this._timer = window.setInterval(send, this._interval);\n        }\n    };\n\n    CheckSessionIFrame.prototype.stop = function stop() {\n        this._session_state = null;\n\n        if (this._timer) {\n            _Log.Log.debug(\"CheckSessionIFrame.stop\");\n\n            window.clearInterval(this._timer);\n            this._timer = null;\n        }\n    };\n\n    return CheckSessionIFrame;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaIFrameNavigator.js\":\n/*!***************************************!*\\\n  !*** ./src/CordovaIFrameNavigator.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaIFrameNavigator = undefined;\n\nvar _CordovaPopupWindow = __webpack_require__(/*! ./CordovaPopupWindow.js */ \"./src/CordovaPopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar CordovaIFrameNavigator = exports.CordovaIFrameNavigator = function () {\n    function CordovaIFrameNavigator() {\n        _classCallCheck(this, CordovaIFrameNavigator);\n    }\n\n    CordovaIFrameNavigator.prototype.prepare = function prepare(params) {\n        params.popupWindowFeatures = 'hidden=yes';\n        var popup = new _CordovaPopupWindow.CordovaPopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    return CordovaIFrameNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaPopupNavigator.js\":\n/*!**************************************!*\\\n  !*** ./src/CordovaPopupNavigator.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaPopupNavigator = undefined;\n\nvar _CordovaPopupWindow = __webpack_require__(/*! ./CordovaPopupWindow.js */ \"./src/CordovaPopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar CordovaPopupNavigator = exports.CordovaPopupNavigator = function () {\n    function CordovaPopupNavigator() {\n        _classCallCheck(this, CordovaPopupNavigator);\n    }\n\n    CordovaPopupNavigator.prototype.prepare = function prepare(params) {\n        var popup = new _CordovaPopupWindow.CordovaPopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    return CordovaPopupNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaPopupWindow.js\":\n/*!***********************************!*\\\n  !*** ./src/CordovaPopupWindow.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaPopupWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar DefaultPopupFeatures = 'location=no,toolbar=no,zoom=no';\nvar DefaultPopupTarget = \"_blank\";\n\nvar CordovaPopupWindow = exports.CordovaPopupWindow = function () {\n    function CordovaPopupWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, CordovaPopupWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        this.features = params.popupWindowFeatures || DefaultPopupFeatures;\n        this.target = params.popupWindowTarget || DefaultPopupTarget;\n\n        this.redirect_uri = params.startUrl;\n        _Log.Log.debug(\"CordovaPopupWindow.ctor: redirect_uri: \" + this.redirect_uri);\n    }\n\n    CordovaPopupWindow.prototype._isInAppBrowserInstalled = function _isInAppBrowserInstalled(cordovaMetadata) {\n        return [\"cordova-plugin-inappbrowser\", \"cordova-plugin-inappbrowser.inappbrowser\", \"org.apache.cordova.inappbrowser\"].some(function (name) {\n            return cordovaMetadata.hasOwnProperty(name);\n        });\n    };\n\n    CordovaPopupWindow.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            this._error(\"No url provided\");\n        } else {\n            if (!window.cordova) {\n                return this._error(\"cordova is undefined\");\n            }\n\n            var cordovaMetadata = window.cordova.require(\"cordova/plugin_list\").metadata;\n            if (this._isInAppBrowserInstalled(cordovaMetadata) === false) {\n                return this._error(\"InAppBrowser plugin not found\");\n            }\n            this._popup = cordova.InAppBrowser.open(params.url, this.target, this.features);\n            if (this._popup) {\n                _Log.Log.debug(\"CordovaPopupWindow.navigate: popup successfully created\");\n\n                this._exitCallbackEvent = this._exitCallback.bind(this);\n                this._loadStartCallbackEvent = this._loadStartCallback.bind(this);\n\n                this._popup.addEventListener(\"exit\", this._exitCallbackEvent, false);\n                this._popup.addEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\n            } else {\n                this._error(\"Error opening popup window\");\n            }\n        }\n        return this.promise;\n    };\n\n    CordovaPopupWindow.prototype._loadStartCallback = function _loadStartCallback(event) {\n        if (event.url.indexOf(this.redirect_uri) === 0) {\n            this._success({ url: event.url });\n        }\n    };\n\n    CordovaPopupWindow.prototype._exitCallback = function _exitCallback(message) {\n        this._error(message);\n    };\n\n    CordovaPopupWindow.prototype._success = function _success(data) {\n        this._cleanup();\n\n        _Log.Log.debug(\"CordovaPopupWindow: Successful response from cordova popup window\");\n        this._resolve(data);\n    };\n\n    CordovaPopupWindow.prototype._error = function _error(message) {\n        this._cleanup();\n\n        _Log.Log.error(message);\n        this._reject(new Error(message));\n    };\n\n    CordovaPopupWindow.prototype.close = function close() {\n        this._cleanup();\n    };\n\n    CordovaPopupWindow.prototype._cleanup = function _cleanup() {\n        if (this._popup) {\n            _Log.Log.debug(\"CordovaPopupWindow: cleaning up popup\");\n            this._popup.removeEventListener(\"exit\", this._exitCallbackEvent, false);\n            this._popup.removeEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\n            this._popup.close();\n        }\n        this._popup = null;\n    };\n\n    _createClass(CordovaPopupWindow, [{\n        key: 'promise',\n        get: function get() {\n            return this._promise;\n        }\n    }]);\n\n    return CordovaPopupWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/ErrorResponse.js\":\n/*!******************************!*\\\n  !*** ./src/ErrorResponse.js ***!\n  \\******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n        value: true\n});\nexports.ErrorResponse = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar ErrorResponse = exports.ErrorResponse = function (_Error) {\n        _inherits(ErrorResponse, _Error);\n\n        function ErrorResponse() {\n                var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n                    error = _ref.error,\n                    error_description = _ref.error_description,\n                    error_uri = _ref.error_uri,\n                    state = _ref.state,\n                    session_state = _ref.session_state;\n\n                _classCallCheck(this, ErrorResponse);\n\n                if (!error) {\n                        _Log.Log.error(\"No error passed to ErrorResponse\");\n                        throw new Error(\"error\");\n                }\n\n                var _this = _possibleConstructorReturn(this, _Error.call(this, error_description || error));\n\n                _this.name = \"ErrorResponse\";\n\n                _this.error = error;\n                _this.error_description = error_description;\n                _this.error_uri = error_uri;\n\n                _this.state = state;\n                _this.session_state = session_state;\n                return _this;\n        }\n\n        return ErrorResponse;\n}(Error);\n\n/***/ }),\n\n/***/ \"./src/Event.js\":\n/*!**********************!*\\\n  !*** ./src/Event.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.Event = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar Event = exports.Event = function () {\n    function Event(name) {\n        _classCallCheck(this, Event);\n\n        this._name = name;\n        this._callbacks = [];\n    }\n\n    Event.prototype.addHandler = function addHandler(cb) {\n        this._callbacks.push(cb);\n    };\n\n    Event.prototype.removeHandler = function removeHandler(cb) {\n        var idx = this._callbacks.findIndex(function (item) {\n            return item === cb;\n        });\n        if (idx >= 0) {\n            this._callbacks.splice(idx, 1);\n        }\n    };\n\n    Event.prototype.raise = function raise() {\n        _Log.Log.debug(\"Event: Raising event: \" + this._name);\n        for (var i = 0; i < this._callbacks.length; i++) {\n            var _callbacks;\n\n            (_callbacks = this._callbacks)[i].apply(_callbacks, arguments);\n        }\n    };\n\n    return Event;\n}();\n\n/***/ }),\n\n/***/ \"./src/Global.js\":\n/*!***********************!*\\\n  !*** ./src/Global.js ***!\n  \\***********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar timer = {\n    setInterval: function (_setInterval) {\n        function setInterval(_x, _x2) {\n            return _setInterval.apply(this, arguments);\n        }\n\n        setInterval.toString = function () {\n            return _setInterval.toString();\n        };\n\n        return setInterval;\n    }(function (cb, duration) {\n        return setInterval(cb, duration);\n    }),\n    clearInterval: function (_clearInterval) {\n        function clearInterval(_x3) {\n            return _clearInterval.apply(this, arguments);\n        }\n\n        clearInterval.toString = function () {\n            return _clearInterval.toString();\n        };\n\n        return clearInterval;\n    }(function (handle) {\n        return clearInterval(handle);\n    })\n};\n\nvar testing = false;\nvar request = null;\n\nvar Global = exports.Global = function () {\n    function Global() {\n        _classCallCheck(this, Global);\n    }\n\n    Global._testing = function _testing() {\n        testing = true;\n    };\n\n    Global.setXMLHttpRequest = function setXMLHttpRequest(newRequest) {\n        request = newRequest;\n    };\n\n    _createClass(Global, null, [{\n        key: 'location',\n        get: function get() {\n            if (!testing) {\n                return location;\n            }\n        }\n    }, {\n        key: 'localStorage',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return localStorage;\n            }\n        }\n    }, {\n        key: 'sessionStorage',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return sessionStorage;\n            }\n        }\n    }, {\n        key: 'XMLHttpRequest',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return request || XMLHttpRequest;\n            }\n        }\n    }, {\n        key: 'timer',\n        get: function get() {\n            if (!testing) {\n                return timer;\n            }\n        }\n    }]);\n\n    return Global;\n}();\n\n/***/ }),\n\n/***/ \"./src/IFrameNavigator.js\":\n/*!********************************!*\\\n  !*** ./src/IFrameNavigator.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.IFrameNavigator = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _IFrameWindow = __webpack_require__(/*! ./IFrameWindow.js */ \"./src/IFrameWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar IFrameNavigator = exports.IFrameNavigator = function () {\n    function IFrameNavigator() {\n        _classCallCheck(this, IFrameNavigator);\n    }\n\n    IFrameNavigator.prototype.prepare = function prepare(params) {\n        var frame = new _IFrameWindow.IFrameWindow(params);\n        return Promise.resolve(frame);\n    };\n\n    IFrameNavigator.prototype.callback = function callback(url) {\n        _Log.Log.debug(\"IFrameNavigator.callback\");\n\n        try {\n            _IFrameWindow.IFrameWindow.notifyParent(url);\n            return Promise.resolve();\n        } catch (e) {\n            return Promise.reject(e);\n        }\n    };\n\n    return IFrameNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/IFrameWindow.js\":\n/*!*****************************!*\\\n  !*** ./src/IFrameWindow.js ***!\n  \\*****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.IFrameWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar DefaultTimeout = 10000;\n\nvar IFrameWindow = exports.IFrameWindow = function () {\n    function IFrameWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, IFrameWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        this._boundMessageEvent = this._message.bind(this);\n        window.addEventListener(\"message\", this._boundMessageEvent, false);\n\n        this._frame = window.document.createElement(\"iframe\");\n\n        // shotgun approach\n        this._frame.style.visibility = \"hidden\";\n        this._frame.style.position = \"absolute\";\n        this._frame.style.display = \"none\";\n        this._frame.style.width = 0;\n        this._frame.style.height = 0;\n\n        window.document.body.appendChild(this._frame);\n    }\n\n    IFrameWindow.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            this._error(\"No url provided\");\n        } else {\n            var timeout = params.silentRequestTimeout || DefaultTimeout;\n            _Log.Log.debug(\"IFrameWindow.navigate: Using timeout of:\", timeout);\n            this._timer = window.setTimeout(this._timeout.bind(this), timeout);\n            this._frame.src = params.url;\n        }\n\n        return this.promise;\n    };\n\n    IFrameWindow.prototype._success = function _success(data) {\n        this._cleanup();\n\n        _Log.Log.debug(\"IFrameWindow: Successful response from frame window\");\n        this._resolve(data);\n    };\n\n    IFrameWindow.prototype._error = function _error(message) {\n        this._cleanup();\n\n        _Log.Log.error(message);\n        this._reject(new Error(message));\n    };\n\n    IFrameWindow.prototype.close = function close() {\n        this._cleanup();\n    };\n\n    IFrameWindow.prototype._cleanup = function _cleanup() {\n        if (this._frame) {\n            _Log.Log.debug(\"IFrameWindow: cleanup\");\n\n            window.removeEventListener(\"message\", this._boundMessageEvent, false);\n            window.clearTimeout(this._timer);\n            window.document.body.removeChild(this._frame);\n\n            this._timer = null;\n            this._frame = null;\n            this._boundMessageEvent = null;\n        }\n    };\n\n    IFrameWindow.prototype._timeout = function _timeout() {\n        _Log.Log.debug(\"IFrameWindow.timeout\");\n        this._error(\"Frame window timed out\");\n    };\n\n    IFrameWindow.prototype._message = function _message(e) {\n        _Log.Log.debug(\"IFrameWindow.message\");\n\n        if (this._timer && e.origin === this._origin && e.source === this._frame.contentWindow) {\n            var url = e.data;\n            if (url) {\n                this._success({ url: url });\n            } else {\n                this._error(\"Invalid response from frame\");\n            }\n        }\n    };\n\n    IFrameWindow.notifyParent = function notifyParent(url) {\n        _Log.Log.debug(\"IFrameWindow.notifyParent\");\n        if (window.frameElement) {\n            url = url || window.location.href;\n            if (url) {\n                _Log.Log.debug(\"IFrameWindow.notifyParent: posting url message to parent\");\n                window.parent.postMessage(url, location.protocol + \"//\" + location.host);\n            }\n        }\n    };\n\n    _createClass(IFrameWindow, [{\n        key: \"promise\",\n        get: function get() {\n            return this._promise;\n        }\n    }, {\n        key: \"_origin\",\n        get: function get() {\n            return location.protocol + \"//\" + location.host;\n        }\n    }]);\n\n    return IFrameWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/InMemoryWebStorage.js\":\n/*!***********************************!*\\\n  !*** ./src/InMemoryWebStorage.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.InMemoryWebStorage = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar InMemoryWebStorage = exports.InMemoryWebStorage = function () {\n    function InMemoryWebStorage() {\n        _classCallCheck(this, InMemoryWebStorage);\n\n        this._data = {};\n    }\n\n    InMemoryWebStorage.prototype.getItem = function getItem(key) {\n        _Log.Log.debug(\"InMemoryWebStorage.getItem\", key);\n        return this._data[key];\n    };\n\n    InMemoryWebStorage.prototype.setItem = function setItem(key, value) {\n        _Log.Log.debug(\"InMemoryWebStorage.setItem\", key);\n        this._data[key] = value;\n    };\n\n    InMemoryWebStorage.prototype.removeItem = function removeItem(key) {\n        _Log.Log.debug(\"InMemoryWebStorage.removeItem\", key);\n        delete this._data[key];\n    };\n\n    InMemoryWebStorage.prototype.key = function key(index) {\n        return Object.getOwnPropertyNames(this._data)[index];\n    };\n\n    _createClass(InMemoryWebStorage, [{\n        key: \"length\",\n        get: function get() {\n            return Object.getOwnPropertyNames(this._data).length;\n        }\n    }]);\n\n    return InMemoryWebStorage;\n}();\n\n/***/ }),\n\n/***/ \"./src/JoseUtilImpl.js\":\n/*!*****************************!*\\\n  !*** ./src/JoseUtilImpl.js ***!\n  \\*****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.default = getJoseUtil;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nfunction getJoseUtil(_ref) {\n    var jws = _ref.jws,\n        KeyUtil = _ref.KeyUtil,\n        X509 = _ref.X509,\n        crypto = _ref.crypto,\n        hextob64u = _ref.hextob64u,\n        b64tohex = _ref.b64tohex,\n        AllowedSigningAlgs = _ref.AllowedSigningAlgs;\n\n    return function () {\n        function JoseUtil() {\n            _classCallCheck(this, JoseUtil);\n        }\n\n        JoseUtil.parseJwt = function parseJwt(jwt) {\n            _Log.Log.debug(\"JoseUtil.parseJwt\");\n            try {\n                var token = jws.JWS.parse(jwt);\n                return {\n                    header: token.headerObj,\n                    payload: token.payloadObj\n                };\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        JoseUtil.validateJwt = function validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\n            _Log.Log.debug(\"JoseUtil.validateJwt\");\n\n            try {\n                if (key.kty === \"RSA\") {\n                    if (key.e && key.n) {\n                        key = KeyUtil.getKey(key);\n                    } else if (key.x5c && key.x5c.length) {\n                        var hex = b64tohex(key.x5c[0]);\n                        key = X509.getPublicKeyFromCertHex(hex);\n                    } else {\n                        _Log.Log.error(\"JoseUtil.validateJwt: RSA key missing key material\", key);\n                        return Promise.reject(new Error(\"RSA key missing key material\"));\n                    }\n                } else if (key.kty === \"EC\") {\n                    if (key.crv && key.x && key.y) {\n                        key = KeyUtil.getKey(key);\n                    } else {\n                        _Log.Log.error(\"JoseUtil.validateJwt: EC key missing key material\", key);\n                        return Promise.reject(new Error(\"EC key missing key material\"));\n                    }\n                } else {\n                    _Log.Log.error(\"JoseUtil.validateJwt: Unsupported key type\", key && key.kty);\n                    return Promise.reject(new Error( true && key.kty));\n                }\n\n                return JoseUtil._validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive);\n            } catch (e) {\n                _Log.Log.error(e && e.message || e);\n                return Promise.reject(\"JWT validation failed\");\n            }\n        };\n\n        JoseUtil.validateJwtAttributes = function validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive) {\n            if (!clockSkew) {\n                clockSkew = 0;\n            }\n\n            if (!now) {\n                now = parseInt(Date.now() / 1000);\n            }\n\n            var payload = JoseUtil.parseJwt(jwt).payload;\n\n            if (!payload.iss) {\n                _Log.Log.error(\"JoseUtil._validateJwt: issuer was not provided\");\n                return Promise.reject(new Error(\"issuer was not provided\"));\n            }\n            if (payload.iss !== issuer) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid issuer in token\", payload.iss);\n                return Promise.reject(new Error(\"Invalid issuer in token: \" + payload.iss));\n            }\n\n            if (!payload.aud) {\n                _Log.Log.error(\"JoseUtil._validateJwt: aud was not provided\");\n                return Promise.reject(new Error(\"aud was not provided\"));\n            }\n            var validAudience = payload.aud === audience || Array.isArray(payload.aud) && payload.aud.indexOf(audience) >= 0;\n            if (!validAudience) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid audience in token\", payload.aud);\n                return Promise.reject(new Error(\"Invalid audience in token: \" + payload.aud));\n            }\n            if (payload.azp && payload.azp !== audience) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid azp in token\", payload.azp);\n                return Promise.reject(new Error(\"Invalid azp in token: \" + payload.azp));\n            }\n\n            if (!timeInsensitive) {\n                var lowerNow = now + clockSkew;\n                var upperNow = now - clockSkew;\n\n                if (!payload.iat) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: iat was not provided\");\n                    return Promise.reject(new Error(\"iat was not provided\"));\n                }\n                if (lowerNow < payload.iat) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: iat is in the future\", payload.iat);\n                    return Promise.reject(new Error(\"iat is in the future: \" + payload.iat));\n                }\n\n                if (payload.nbf && lowerNow < payload.nbf) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: nbf is in the future\", payload.nbf);\n                    return Promise.reject(new Error(\"nbf is in the future: \" + payload.nbf));\n                }\n\n                if (!payload.exp) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: exp was not provided\");\n                    return Promise.reject(new Error(\"exp was not provided\"));\n                }\n                if (payload.exp < upperNow) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: exp is in the past\", payload.exp);\n                    return Promise.reject(new Error(\"exp is in the past:\" + payload.exp));\n                }\n            }\n\n            return Promise.resolve(payload);\n        };\n\n        JoseUtil._validateJwt = function _validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\n\n            return JoseUtil.validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive).then(function (payload) {\n                try {\n                    if (!jws.JWS.verify(jwt, key, AllowedSigningAlgs)) {\n                        _Log.Log.error(\"JoseUtil._validateJwt: signature validation failed\");\n                        return Promise.reject(new Error(\"signature validation failed\"));\n                    }\n\n                    return payload;\n                } catch (e) {\n                    _Log.Log.error(e && e.message || e);\n                    return Promise.reject(new Error(\"signature validation failed\"));\n                }\n            });\n        };\n\n        JoseUtil.hashString = function hashString(value, alg) {\n            try {\n                return crypto.Util.hashString(value, alg);\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        JoseUtil.hexToBase64Url = function hexToBase64Url(value) {\n            try {\n                return hextob64u(value);\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        return JoseUtil;\n    }();\n}\nmodule.exports = exports[\"default\"];\n\n/***/ }),\n\n/***/ \"./src/JoseUtilRsa.js\":\n/*!****************************!*\\\n  !*** ./src/JoseUtilRsa.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nexports.JoseUtil = undefined;\n\nvar _rsa = __webpack_require__(/*! ./crypto/rsa */ \"./src/crypto/rsa.js\");\n\nvar _JoseUtilImpl = __webpack_require__(/*! ./JoseUtilImpl */ \"./src/JoseUtilImpl.js\");\n\nvar _JoseUtilImpl2 = _interopRequireDefault(_JoseUtilImpl);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nvar JoseUtil = exports.JoseUtil = (0, _JoseUtilImpl2.default)({ jws: _rsa.jws, KeyUtil: _rsa.KeyUtil, X509: _rsa.X509, crypto: _rsa.crypto, hextob64u: _rsa.hextob64u, b64tohex: _rsa.b64tohex, AllowedSigningAlgs: _rsa.AllowedSigningAlgs });\n\n/***/ }),\n\n/***/ \"./src/JsonService.js\":\n/*!****************************!*\\\n  !*** ./src/JsonService.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.JsonService = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar JsonService = exports.JsonService = function () {\n    function JsonService() {\n        var additionalContentTypes = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : null;\n        var XMLHttpRequestCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.XMLHttpRequest;\n        var jwtHandler = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : null;\n\n        _classCallCheck(this, JsonService);\n\n        if (additionalContentTypes && Array.isArray(additionalContentTypes)) {\n            this._contentTypes = additionalContentTypes.slice();\n        } else {\n            this._contentTypes = [];\n        }\n        this._contentTypes.push('application/json');\n        if (jwtHandler) {\n            this._contentTypes.push('application/jwt');\n        }\n\n        this._XMLHttpRequest = XMLHttpRequestCtor;\n        this._jwtHandler = jwtHandler;\n    }\n\n    JsonService.prototype.getJson = function getJson(url, token) {\n        var _this = this;\n\n        if (!url) {\n            _Log.Log.error(\"JsonService.getJson: No url passed\");\n            throw new Error(\"url\");\n        }\n\n        _Log.Log.debug(\"JsonService.getJson, url: \", url);\n\n        return new Promise(function (resolve, reject) {\n\n            var req = new _this._XMLHttpRequest();\n            req.open('GET', url);\n\n            var allowedContentTypes = _this._contentTypes;\n            var jwtHandler = _this._jwtHandler;\n\n            req.onload = function () {\n                _Log.Log.debug(\"JsonService.getJson: HTTP response received, status\", req.status);\n\n                if (req.status === 200) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found == \"application/jwt\") {\n                            jwtHandler(req).then(resolve, reject);\n                            return;\n                        }\n\n                        if (found) {\n                            try {\n                                resolve(JSON.parse(req.responseText));\n                                return;\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.getJson: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\n                } else {\n                    reject(Error(req.statusText + \" (\" + req.status + \")\"));\n                }\n            };\n\n            req.onerror = function () {\n                _Log.Log.error(\"JsonService.getJson: network error\");\n                reject(Error(\"Network Error\"));\n            };\n\n            if (token) {\n                _Log.Log.debug(\"JsonService.getJson: token passed, setting Authorization header\");\n                req.setRequestHeader(\"Authorization\", \"Bearer \" + token);\n            }\n\n            req.send();\n        });\n    };\n\n    JsonService.prototype.postForm = function postForm(url, payload) {\n        var _this2 = this;\n\n        if (!url) {\n            _Log.Log.error(\"JsonService.postForm: No url passed\");\n            throw new Error(\"url\");\n        }\n\n        _Log.Log.debug(\"JsonService.postForm, url: \", url);\n\n        return new Promise(function (resolve, reject) {\n\n            var req = new _this2._XMLHttpRequest();\n            req.open('POST', url);\n\n            var allowedContentTypes = _this2._contentTypes;\n\n            req.onload = function () {\n                _Log.Log.debug(\"JsonService.postForm: HTTP response received, status\", req.status);\n\n                if (req.status === 200) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found) {\n                            try {\n                                resolve(JSON.parse(req.responseText));\n                                return;\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\n                    return;\n                }\n\n                if (req.status === 400) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found) {\n                            try {\n                                var payload = JSON.parse(req.responseText);\n                                if (payload && payload.error) {\n                                    _Log.Log.error(\"JsonService.postForm: Error from server: \", payload.error);\n                                    reject(new Error(payload.error));\n                                    return;\n                                }\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n                }\n\n                reject(Error(req.statusText + \" (\" + req.status + \")\"));\n            };\n\n            req.onerror = function () {\n                _Log.Log.error(\"JsonService.postForm: network error\");\n                reject(Error(\"Network Error\"));\n            };\n\n            var body = \"\";\n            for (var key in payload) {\n\n                var value = payload[key];\n\n                if (value) {\n\n                    if (body.length > 0) {\n                        body += \"&\";\n                    }\n\n                    body += encodeURIComponent(key);\n                    body += \"=\";\n                    body += encodeURIComponent(value);\n                }\n            }\n\n            req.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\n            req.send(body);\n        });\n    };\n\n    return JsonService;\n}();\n\n/***/ }),\n\n/***/ \"./src/Log.js\":\n/*!********************!*\\\n  !*** ./src/Log.js ***!\n  \\********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar nopLogger = {\n    debug: function debug() {},\n    info: function info() {},\n    warn: function warn() {},\n    error: function error() {}\n};\n\nvar NONE = 0;\nvar ERROR = 1;\nvar WARN = 2;\nvar INFO = 3;\nvar DEBUG = 4;\n\nvar logger = void 0;\nvar level = void 0;\n\nvar Log = exports.Log = function () {\n    function Log() {\n        _classCallCheck(this, Log);\n    }\n\n    Log.reset = function reset() {\n        level = INFO;\n        logger = nopLogger;\n    };\n\n    Log.debug = function debug() {\n        if (level >= DEBUG) {\n            for (var _len = arguments.length, args = Array(_len), _key = 0; _key < _len; _key++) {\n                args[_key] = arguments[_key];\n            }\n\n            logger.debug.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.info = function info() {\n        if (level >= INFO) {\n            for (var _len2 = arguments.length, args = Array(_len2), _key2 = 0; _key2 < _len2; _key2++) {\n                args[_key2] = arguments[_key2];\n            }\n\n            logger.info.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.warn = function warn() {\n        if (level >= WARN) {\n            for (var _len3 = arguments.length, args = Array(_len3), _key3 = 0; _key3 < _len3; _key3++) {\n                args[_key3] = arguments[_key3];\n            }\n\n            logger.warn.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.error = function error() {\n        if (level >= ERROR) {\n            for (var _len4 = arguments.length, args = Array(_len4), _key4 = 0; _key4 < _len4; _key4++) {\n                args[_key4] = arguments[_key4];\n            }\n\n            logger.error.apply(logger, Array.from(args));\n        }\n    };\n\n    _createClass(Log, null, [{\n        key: \"NONE\",\n        get: function get() {\n            return NONE;\n        }\n    }, {\n        key: \"ERROR\",\n        get: function get() {\n            return ERROR;\n        }\n    }, {\n        key: \"WARN\",\n        get: function get() {\n            return WARN;\n        }\n    }, {\n        key: \"INFO\",\n        get: function get() {\n            return INFO;\n        }\n    }, {\n        key: \"DEBUG\",\n        get: function get() {\n            return DEBUG;\n        }\n    }, {\n        key: \"level\",\n        get: function get() {\n            return level;\n        },\n        set: function set(value) {\n            if (NONE <= value && value <= DEBUG) {\n                level = value;\n            } else {\n                throw new Error(\"Invalid log level\");\n            }\n        }\n    }, {\n        key: \"logger\",\n        get: function get() {\n            return logger;\n        },\n        set: function set(value) {\n            if (!value.debug && value.info) {\n                // just to stay backwards compat. can remove in 2.0\n                value.debug = value.info;\n            }\n\n            if (value.debug && value.info && value.warn && value.error) {\n                logger = value;\n            } else {\n                throw new Error(\"Invalid logger\");\n            }\n        }\n    }]);\n\n    return Log;\n}();\n\nLog.reset();\n\n/***/ }),\n\n/***/ \"./src/MetadataService.js\":\n/*!********************************!*\\\n  !*** ./src/MetadataService.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.MetadataService = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcMetadataUrlPath = '.well-known/openid-configuration';\n\nvar MetadataService = exports.MetadataService = function () {\n    function MetadataService(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n\n        _classCallCheck(this, MetadataService);\n\n        if (!settings) {\n            _Log.Log.error(\"MetadataService: No settings passed to MetadataService\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor(['application/jwk-set+json']);\n    }\n\n    MetadataService.prototype.getMetadata = function getMetadata() {\n        var _this = this;\n\n        if (this._settings.metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadata: Returning metadata from settings\");\n            return Promise.resolve(this._settings.metadata);\n        }\n\n        if (!this.metadataUrl) {\n            _Log.Log.error(\"MetadataService.getMetadata: No authority or metadataUrl configured on settings\");\n            return Promise.reject(new Error(\"No authority or metadataUrl configured on settings\"));\n        }\n\n        _Log.Log.debug(\"MetadataService.getMetadata: getting metadata from\", this.metadataUrl);\n\n        return this._jsonService.getJson(this.metadataUrl).then(function (metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadata: json received\");\n            _this._settings.metadata = metadata;\n            return metadata;\n        });\n    };\n\n    MetadataService.prototype.getIssuer = function getIssuer() {\n        return this._getMetadataProperty(\"issuer\");\n    };\n\n    MetadataService.prototype.getAuthorizationEndpoint = function getAuthorizationEndpoint() {\n        return this._getMetadataProperty(\"authorization_endpoint\");\n    };\n\n    MetadataService.prototype.getUserInfoEndpoint = function getUserInfoEndpoint() {\n        return this._getMetadataProperty(\"userinfo_endpoint\");\n    };\n\n    MetadataService.prototype.getTokenEndpoint = function getTokenEndpoint() {\n        var optional = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : true;\n\n        return this._getMetadataProperty(\"token_endpoint\", optional);\n    };\n\n    MetadataService.prototype.getCheckSessionIframe = function getCheckSessionIframe() {\n        return this._getMetadataProperty(\"check_session_iframe\", true);\n    };\n\n    MetadataService.prototype.getEndSessionEndpoint = function getEndSessionEndpoint() {\n        return this._getMetadataProperty(\"end_session_endpoint\", true);\n    };\n\n    MetadataService.prototype.getRevocationEndpoint = function getRevocationEndpoint() {\n        return this._getMetadataProperty(\"revocation_endpoint\", true);\n    };\n\n    MetadataService.prototype.getKeysEndpoint = function getKeysEndpoint() {\n        return this._getMetadataProperty(\"jwks_uri\", true);\n    };\n\n    MetadataService.prototype._getMetadataProperty = function _getMetadataProperty(name) {\n        var optional = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : false;\n\n        _Log.Log.debug(\"MetadataService.getMetadataProperty for: \" + name);\n\n        return this.getMetadata().then(function (metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadataProperty: metadata recieved\");\n\n            if (metadata[name] === undefined) {\n\n                if (optional === true) {\n                    _Log.Log.warn(\"MetadataService.getMetadataProperty: Metadata does not contain optional property \" + name);\n                    return undefined;\n                } else {\n                    _Log.Log.error(\"MetadataService.getMetadataProperty: Metadata does not contain property \" + name);\n                    throw new Error(\"Metadata does not contain property \" + name);\n                }\n            }\n\n            return metadata[name];\n        });\n    };\n\n    MetadataService.prototype.getSigningKeys = function getSigningKeys() {\n        var _this2 = this;\n\n        if (this._settings.signingKeys) {\n            _Log.Log.debug(\"MetadataService.getSigningKeys: Returning signingKeys from settings\");\n            return Promise.resolve(this._settings.signingKeys);\n        }\n\n        return this._getMetadataProperty(\"jwks_uri\").then(function (jwks_uri) {\n            _Log.Log.debug(\"MetadataService.getSigningKeys: jwks_uri received\", jwks_uri);\n\n            return _this2._jsonService.getJson(jwks_uri).then(function (keySet) {\n                _Log.Log.debug(\"MetadataService.getSigningKeys: key set received\", keySet);\n\n                if (!keySet.keys) {\n                    _Log.Log.error(\"MetadataService.getSigningKeys: Missing keys on keyset\");\n                    throw new Error(\"Missing keys on keyset\");\n                }\n\n                _this2._settings.signingKeys = keySet.keys;\n                return _this2._settings.signingKeys;\n            });\n        });\n    };\n\n    _createClass(MetadataService, [{\n        key: 'metadataUrl',\n        get: function get() {\n            if (!this._metadataUrl) {\n                if (this._settings.metadataUrl) {\n                    this._metadataUrl = this._settings.metadataUrl;\n                } else {\n                    this._metadataUrl = this._settings.authority;\n\n                    if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\n                        if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\n                            this._metadataUrl += '/';\n                        }\n                        this._metadataUrl += OidcMetadataUrlPath;\n                    }\n                }\n            }\n\n            return this._metadataUrl;\n        }\n    }]);\n\n    return MetadataService;\n}();\n\n/***/ }),\n\n/***/ \"./src/OidcClient.js\":\n/*!***************************!*\\\n  !*** ./src/OidcClient.js ***!\n  \\***************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.OidcClient = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClientSettings = __webpack_require__(/*! ./OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _ErrorResponse = __webpack_require__(/*! ./ErrorResponse.js */ \"./src/ErrorResponse.js\");\n\nvar _SigninRequest = __webpack_require__(/*! ./SigninRequest.js */ \"./src/SigninRequest.js\");\n\nvar _SigninResponse = __webpack_require__(/*! ./SigninResponse.js */ \"./src/SigninResponse.js\");\n\nvar _SignoutRequest = __webpack_require__(/*! ./SignoutRequest.js */ \"./src/SignoutRequest.js\");\n\nvar _SignoutResponse = __webpack_require__(/*! ./SignoutResponse.js */ \"./src/SignoutResponse.js\");\n\nvar _SigninState = __webpack_require__(/*! ./SigninState.js */ \"./src/SigninState.js\");\n\nvar _State = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcClient = exports.OidcClient = function () {\n    function OidcClient() {\n        var settings = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        _classCallCheck(this, OidcClient);\n\n        if (settings instanceof _OidcClientSettings.OidcClientSettings) {\n            this._settings = settings;\n        } else {\n            this._settings = new _OidcClientSettings.OidcClientSettings(settings);\n        }\n    }\n\n    OidcClient.prototype.createSigninRequest = function createSigninRequest() {\n        var _this = this;\n\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            response_type = _ref.response_type,\n            scope = _ref.scope,\n            redirect_uri = _ref.redirect_uri,\n            data = _ref.data,\n            state = _ref.state,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            id_token_hint = _ref.id_token_hint,\n            login_hint = _ref.login_hint,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            request = _ref.request,\n            request_uri = _ref.request_uri,\n            response_mode = _ref.response_mode,\n            extraQueryParams = _ref.extraQueryParams,\n            extraTokenParams = _ref.extraTokenParams,\n            request_type = _ref.request_type,\n            skipUserInfo = _ref.skipUserInfo;\n\n        var stateStore = arguments[1];\n\n        _Log.Log.debug(\"OidcClient.createSigninRequest\");\n\n        var client_id = this._settings.client_id;\n        response_type = response_type || this._settings.response_type;\n        scope = scope || this._settings.scope;\n        redirect_uri = redirect_uri || this._settings.redirect_uri;\n\n        // id_token_hint, login_hint aren't allowed on _settings\n        prompt = prompt || this._settings.prompt;\n        display = display || this._settings.display;\n        max_age = max_age || this._settings.max_age;\n        ui_locales = ui_locales || this._settings.ui_locales;\n        acr_values = acr_values || this._settings.acr_values;\n        resource = resource || this._settings.resource;\n        response_mode = response_mode || this._settings.response_mode;\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\n        extraTokenParams = extraTokenParams || this._settings.extraTokenParams;\n\n        var authority = this._settings.authority;\n\n        if (_SigninRequest.SigninRequest.isCode(response_type) && response_type !== \"code\") {\n            return Promise.reject(new Error(\"OpenID Connect hybrid flow is not supported\"));\n        }\n\n        return this._metadataService.getAuthorizationEndpoint().then(function (url) {\n            _Log.Log.debug(\"OidcClient.createSigninRequest: Received authorization endpoint\", url);\n\n            var signinRequest = new _SigninRequest.SigninRequest({\n                url: url,\n                client_id: client_id,\n                redirect_uri: redirect_uri,\n                response_type: response_type,\n                scope: scope,\n                data: data || state,\n                authority: authority,\n                prompt: prompt, display: display, max_age: max_age, ui_locales: ui_locales, id_token_hint: id_token_hint, login_hint: login_hint, acr_values: acr_values,\n                resource: resource, request: request, request_uri: request_uri, extraQueryParams: extraQueryParams, extraTokenParams: extraTokenParams, request_type: request_type, response_mode: response_mode,\n                client_secret: _this._settings.client_secret,\n                skipUserInfo: skipUserInfo\n            });\n\n            var signinState = signinRequest.state;\n            stateStore = stateStore || _this._stateStore;\n\n            return stateStore.set(signinState.id, signinState.toStorageString()).then(function () {\n                return signinRequest;\n            });\n        });\n    };\n\n    OidcClient.prototype.readSigninResponseState = function readSigninResponseState(url, stateStore) {\n        var removeState = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : false;\n\n        _Log.Log.debug(\"OidcClient.readSigninResponseState\");\n\n        var useQuery = this._settings.response_mode === \"query\" || !this._settings.response_mode && _SigninRequest.SigninRequest.isCode(this._settings.response_type);\n        var delimiter = useQuery ? \"?\" : \"#\";\n\n        var response = new _SigninResponse.SigninResponse(url, delimiter);\n\n        if (!response.state) {\n            _Log.Log.error(\"OidcClient.readSigninResponseState: No state in response\");\n            return Promise.reject(new Error(\"No state in response\"));\n        }\n\n        stateStore = stateStore || this._stateStore;\n\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\n\n        return stateApi(response.state).then(function (storedStateString) {\n            if (!storedStateString) {\n                _Log.Log.error(\"OidcClient.readSigninResponseState: No matching state found in storage\");\n                throw new Error(\"No matching state found in storage\");\n            }\n\n            var state = _SigninState.SigninState.fromStorageString(storedStateString);\n            return { state: state, response: response };\n        });\n    };\n\n    OidcClient.prototype.processSigninResponse = function processSigninResponse(url, stateStore) {\n        var _this2 = this;\n\n        _Log.Log.debug(\"OidcClient.processSigninResponse\");\n\n        return this.readSigninResponseState(url, stateStore, true).then(function (_ref2) {\n            var state = _ref2.state,\n                response = _ref2.response;\n\n            _Log.Log.debug(\"OidcClient.processSigninResponse: Received state from storage; validating response\");\n            return _this2._validator.validateSigninResponse(state, response);\n        });\n    };\n\n    OidcClient.prototype.createSignoutRequest = function createSignoutRequest() {\n        var _this3 = this;\n\n        var _ref3 = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            id_token_hint = _ref3.id_token_hint,\n            data = _ref3.data,\n            state = _ref3.state,\n            post_logout_redirect_uri = _ref3.post_logout_redirect_uri,\n            extraQueryParams = _ref3.extraQueryParams,\n            request_type = _ref3.request_type;\n\n        var stateStore = arguments[1];\n\n        _Log.Log.debug(\"OidcClient.createSignoutRequest\");\n\n        post_logout_redirect_uri = post_logout_redirect_uri || this._settings.post_logout_redirect_uri;\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\n\n        return this._metadataService.getEndSessionEndpoint().then(function (url) {\n            if (!url) {\n                _Log.Log.error(\"OidcClient.createSignoutRequest: No end session endpoint url returned\");\n                throw new Error(\"no end session endpoint\");\n            }\n\n            _Log.Log.debug(\"OidcClient.createSignoutRequest: Received end session endpoint\", url);\n\n            var request = new _SignoutRequest.SignoutRequest({\n                url: url,\n                id_token_hint: id_token_hint,\n                post_logout_redirect_uri: post_logout_redirect_uri,\n                data: data || state,\n                extraQueryParams: extraQueryParams,\n                request_type: request_type\n            });\n\n            var signoutState = request.state;\n            if (signoutState) {\n                _Log.Log.debug(\"OidcClient.createSignoutRequest: Signout request has state to persist\");\n\n                stateStore = stateStore || _this3._stateStore;\n                stateStore.set(signoutState.id, signoutState.toStorageString());\n            }\n\n            return request;\n        });\n    };\n\n    OidcClient.prototype.readSignoutResponseState = function readSignoutResponseState(url, stateStore) {\n        var removeState = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : false;\n\n        _Log.Log.debug(\"OidcClient.readSignoutResponseState\");\n\n        var response = new _SignoutResponse.SignoutResponse(url);\n        if (!response.state) {\n            _Log.Log.debug(\"OidcClient.readSignoutResponseState: No state in response\");\n\n            if (response.error) {\n                _Log.Log.warn(\"OidcClient.readSignoutResponseState: Response was error: \", response.error);\n                return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n            }\n\n            return Promise.resolve({ undefined: undefined, response: response });\n        }\n\n        var stateKey = response.state;\n\n        stateStore = stateStore || this._stateStore;\n\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\n        return stateApi(stateKey).then(function (storedStateString) {\n            if (!storedStateString) {\n                _Log.Log.error(\"OidcClient.readSignoutResponseState: No matching state found in storage\");\n                throw new Error(\"No matching state found in storage\");\n            }\n\n            var state = _State.State.fromStorageString(storedStateString);\n\n            return { state: state, response: response };\n        });\n    };\n\n    OidcClient.prototype.processSignoutResponse = function processSignoutResponse(url, stateStore) {\n        var _this4 = this;\n\n        _Log.Log.debug(\"OidcClient.processSignoutResponse\");\n\n        return this.readSignoutResponseState(url, stateStore, true).then(function (_ref4) {\n            var state = _ref4.state,\n                response = _ref4.response;\n\n            if (state) {\n                _Log.Log.debug(\"OidcClient.processSignoutResponse: Received state from storage; validating response\");\n                return _this4._validator.validateSignoutResponse(state, response);\n            } else {\n                _Log.Log.debug(\"OidcClient.processSignoutResponse: No state from storage; skipping validating response\");\n                return response;\n            }\n        });\n    };\n\n    OidcClient.prototype.clearStaleState = function clearStaleState(stateStore) {\n        _Log.Log.debug(\"OidcClient.clearStaleState\");\n\n        stateStore = stateStore || this._stateStore;\n\n        return _State.State.clearStaleState(stateStore, this.settings.staleStateAge);\n    };\n\n    _createClass(OidcClient, [{\n        key: '_stateStore',\n        get: function get() {\n            return this.settings.stateStore;\n        }\n    }, {\n        key: '_validator',\n        get: function get() {\n            return this.settings.validator;\n        }\n    }, {\n        key: '_metadataService',\n        get: function get() {\n            return this.settings.metadataService;\n        }\n    }, {\n        key: 'settings',\n        get: function get() {\n            return this._settings;\n        }\n    }, {\n        key: 'metadataService',\n        get: function get() {\n            return this._metadataService;\n        }\n    }]);\n\n    return OidcClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/OidcClientSettings.js\":\n/*!***********************************!*\\\n  !*** ./src/OidcClientSettings.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.OidcClientSettings = undefined;\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _ResponseValidator = __webpack_require__(/*! ./ResponseValidator.js */ \"./src/ResponseValidator.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcMetadataUrlPath = '.well-known/openid-configuration';\n\nvar DefaultResponseType = \"id_token\";\nvar DefaultScope = \"openid\";\nvar DefaultStaleStateAge = 60 * 15; // seconds\nvar DefaultClockSkewInSeconds = 60 * 5;\n\nvar OidcClientSettings = exports.OidcClientSettings = function () {\n    function OidcClientSettings() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            authority = _ref.authority,\n            metadataUrl = _ref.metadataUrl,\n            metadata = _ref.metadata,\n            signingKeys = _ref.signingKeys,\n            client_id = _ref.client_id,\n            client_secret = _ref.client_secret,\n            _ref$response_type = _ref.response_type,\n            response_type = _ref$response_type === undefined ? DefaultResponseType : _ref$response_type,\n            _ref$scope = _ref.scope,\n            scope = _ref$scope === undefined ? DefaultScope : _ref$scope,\n            redirect_uri = _ref.redirect_uri,\n            post_logout_redirect_uri = _ref.post_logout_redirect_uri,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            response_mode = _ref.response_mode,\n            _ref$filterProtocolCl = _ref.filterProtocolClaims,\n            filterProtocolClaims = _ref$filterProtocolCl === undefined ? true : _ref$filterProtocolCl,\n            _ref$loadUserInfo = _ref.loadUserInfo,\n            loadUserInfo = _ref$loadUserInfo === undefined ? true : _ref$loadUserInfo,\n            _ref$staleStateAge = _ref.staleStateAge,\n            staleStateAge = _ref$staleStateAge === undefined ? DefaultStaleStateAge : _ref$staleStateAge,\n            _ref$clockSkew = _ref.clockSkew,\n            clockSkew = _ref$clockSkew === undefined ? DefaultClockSkewInSeconds : _ref$clockSkew,\n            _ref$userInfoJwtIssue = _ref.userInfoJwtIssuer,\n            userInfoJwtIssuer = _ref$userInfoJwtIssue === undefined ? 'OP' : _ref$userInfoJwtIssue,\n            _ref$stateStore = _ref.stateStore,\n            stateStore = _ref$stateStore === undefined ? new _WebStorageStateStore.WebStorageStateStore() : _ref$stateStore,\n            _ref$ResponseValidato = _ref.ResponseValidatorCtor,\n            ResponseValidatorCtor = _ref$ResponseValidato === undefined ? _ResponseValidator.ResponseValidator : _ref$ResponseValidato,\n            _ref$MetadataServiceC = _ref.MetadataServiceCtor,\n            MetadataServiceCtor = _ref$MetadataServiceC === undefined ? _MetadataService.MetadataService : _ref$MetadataServiceC,\n            _ref$extraQueryParams = _ref.extraQueryParams,\n            extraQueryParams = _ref$extraQueryParams === undefined ? {} : _ref$extraQueryParams,\n            _ref$extraTokenParams = _ref.extraTokenParams,\n            extraTokenParams = _ref$extraTokenParams === undefined ? {} : _ref$extraTokenParams;\n\n        _classCallCheck(this, OidcClientSettings);\n\n        this._authority = authority;\n        this._metadataUrl = metadataUrl;\n        this._metadata = metadata;\n        this._signingKeys = signingKeys;\n\n        this._client_id = client_id;\n        this._client_secret = client_secret;\n        this._response_type = response_type;\n        this._scope = scope;\n        this._redirect_uri = redirect_uri;\n        this._post_logout_redirect_uri = post_logout_redirect_uri;\n\n        this._prompt = prompt;\n        this._display = display;\n        this._max_age = max_age;\n        this._ui_locales = ui_locales;\n        this._acr_values = acr_values;\n        this._resource = resource;\n        this._response_mode = response_mode;\n\n        this._filterProtocolClaims = !!filterProtocolClaims;\n        this._loadUserInfo = !!loadUserInfo;\n        this._staleStateAge = staleStateAge;\n        this._clockSkew = clockSkew;\n        this._userInfoJwtIssuer = userInfoJwtIssuer;\n\n        this._stateStore = stateStore;\n        this._validator = new ResponseValidatorCtor(this);\n        this._metadataService = new MetadataServiceCtor(this);\n\n        this._extraQueryParams = (typeof extraQueryParams === 'undefined' ? 'undefined' : _typeof(extraQueryParams)) === 'object' ? extraQueryParams : {};\n        this._extraTokenParams = (typeof extraTokenParams === 'undefined' ? 'undefined' : _typeof(extraTokenParams)) === 'object' ? extraTokenParams : {};\n    }\n\n    // client config\n\n\n    _createClass(OidcClientSettings, [{\n        key: 'client_id',\n        get: function get() {\n            return this._client_id;\n        },\n        set: function set(value) {\n            if (!this._client_id) {\n                // one-time set only\n                this._client_id = value;\n            } else {\n                _Log.Log.error(\"OidcClientSettings.set_client_id: client_id has already been assigned.\");\n                throw new Error(\"client_id has already been assigned.\");\n            }\n        }\n    }, {\n        key: 'client_secret',\n        get: function get() {\n            return this._client_secret;\n        }\n    }, {\n        key: 'response_type',\n        get: function get() {\n            return this._response_type;\n        }\n    }, {\n        key: 'scope',\n        get: function get() {\n            return this._scope;\n        }\n    }, {\n        key: 'redirect_uri',\n        get: function get() {\n            return this._redirect_uri;\n        }\n    }, {\n        key: 'post_logout_redirect_uri',\n        get: function get() {\n            return this._post_logout_redirect_uri;\n        }\n\n        // optional protocol params\n\n    }, {\n        key: 'prompt',\n        get: function get() {\n            return this._prompt;\n        }\n    }, {\n        key: 'display',\n        get: function get() {\n            return this._display;\n        }\n    }, {\n        key: 'max_age',\n        get: function get() {\n            return this._max_age;\n        }\n    }, {\n        key: 'ui_locales',\n        get: function get() {\n            return this._ui_locales;\n        }\n    }, {\n        key: 'acr_values',\n        get: function get() {\n            return this._acr_values;\n        }\n    }, {\n        key: 'resource',\n        get: function get() {\n            return this._resource;\n        }\n    }, {\n        key: 'response_mode',\n        get: function get() {\n            return this._response_mode;\n        }\n\n        // metadata\n\n    }, {\n        key: 'authority',\n        get: function get() {\n            return this._authority;\n        },\n        set: function set(value) {\n            if (!this._authority) {\n                // one-time set only\n                this._authority = value;\n            } else {\n                _Log.Log.error(\"OidcClientSettings.set_authority: authority has already been assigned.\");\n                throw new Error(\"authority has already been assigned.\");\n            }\n        }\n    }, {\n        key: 'metadataUrl',\n        get: function get() {\n            if (!this._metadataUrl) {\n                this._metadataUrl = this.authority;\n\n                if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\n                    if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\n                        this._metadataUrl += '/';\n                    }\n                    this._metadataUrl += OidcMetadataUrlPath;\n                }\n            }\n\n            return this._metadataUrl;\n        }\n\n        // settable/cachable metadata values\n\n    }, {\n        key: 'metadata',\n        get: function get() {\n            return this._metadata;\n        },\n        set: function set(value) {\n            this._metadata = value;\n        }\n    }, {\n        key: 'signingKeys',\n        get: function get() {\n            return this._signingKeys;\n        },\n        set: function set(value) {\n            this._signingKeys = value;\n        }\n\n        // behavior flags\n\n    }, {\n        key: 'filterProtocolClaims',\n        get: function get() {\n            return this._filterProtocolClaims;\n        }\n    }, {\n        key: 'loadUserInfo',\n        get: function get() {\n            return this._loadUserInfo;\n        }\n    }, {\n        key: 'staleStateAge',\n        get: function get() {\n            return this._staleStateAge;\n        }\n    }, {\n        key: 'clockSkew',\n        get: function get() {\n            return this._clockSkew;\n        }\n    }, {\n        key: 'userInfoJwtIssuer',\n        get: function get() {\n            return this._userInfoJwtIssuer;\n        }\n    }, {\n        key: 'stateStore',\n        get: function get() {\n            return this._stateStore;\n        }\n    }, {\n        key: 'validator',\n        get: function get() {\n            return this._validator;\n        }\n    }, {\n        key: 'metadataService',\n        get: function get() {\n            return this._metadataService;\n        }\n\n        // extra query params\n\n    }, {\n        key: 'extraQueryParams',\n        get: function get() {\n            return this._extraQueryParams;\n        },\n        set: function set(value) {\n            if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                this._extraQueryParams = value;\n            } else {\n                this._extraQueryParams = {};\n            }\n        }\n\n        // extra token params\n\n    }, {\n        key: 'extraTokenParams',\n        get: function get() {\n            return this._extraTokenParams;\n        },\n        set: function set(value) {\n            if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                this._extraTokenParams = value;\n            } else {\n                this._extraTokenParams = {};\n            }\n        }\n    }]);\n\n    return OidcClientSettings;\n}();\n\n/***/ }),\n\n/***/ \"./src/PopupNavigator.js\":\n/*!*******************************!*\\\n  !*** ./src/PopupNavigator.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.PopupNavigator = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _PopupWindow = __webpack_require__(/*! ./PopupWindow.js */ \"./src/PopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar PopupNavigator = exports.PopupNavigator = function () {\n    function PopupNavigator() {\n        _classCallCheck(this, PopupNavigator);\n    }\n\n    PopupNavigator.prototype.prepare = function prepare(params) {\n        var popup = new _PopupWindow.PopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    PopupNavigator.prototype.callback = function callback(url, keepOpen, delimiter) {\n        _Log.Log.debug(\"PopupNavigator.callback\");\n\n        try {\n            _PopupWindow.PopupWindow.notifyOpener(url, keepOpen, delimiter);\n            return Promise.resolve();\n        } catch (e) {\n            return Promise.reject(e);\n        }\n    };\n\n    return PopupNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/PopupWindow.js\":\n/*!****************************!*\\\n  !*** ./src/PopupWindow.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.PopupWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar CheckForPopupClosedInterval = 500;\nvar DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;';\n//const DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;resizable=yes';\n\nvar DefaultPopupTarget = \"_blank\";\n\nvar PopupWindow = exports.PopupWindow = function () {\n    function PopupWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, PopupWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        var target = params.popupWindowTarget || DefaultPopupTarget;\n        var features = params.popupWindowFeatures || DefaultPopupFeatures;\n\n        this._popup = window.open('', target, features);\n        if (this._popup) {\n            _Log.Log.debug(\"PopupWindow.ctor: popup successfully created\");\n            this._checkForPopupClosedTimer = window.setInterval(this._checkForPopupClosed.bind(this), CheckForPopupClosedInterval);\n        }\n    }\n\n    PopupWindow.prototype.navigate = function navigate(params) {\n        if (!this._popup) {\n            this._error(\"PopupWindow.navigate: Error opening popup window\");\n        } else if (!params || !params.url) {\n            this._error(\"PopupWindow.navigate: no url provided\");\n            this._error(\"No url provided\");\n        } else {\n            _Log.Log.debug(\"PopupWindow.navigate: Setting URL in popup\");\n\n            this._id = params.id;\n            if (this._id) {\n                window[\"popupCallback_\" + params.id] = this._callback.bind(this);\n            }\n\n            this._popup.focus();\n            this._popup.window.location = params.url;\n        }\n\n        return this.promise;\n    };\n\n    PopupWindow.prototype._success = function _success(data) {\n        _Log.Log.debug(\"PopupWindow.callback: Successful response from popup window\");\n\n        this._cleanup();\n        this._resolve(data);\n    };\n\n    PopupWindow.prototype._error = function _error(message) {\n        _Log.Log.error(\"PopupWindow.error: \", message);\n\n        this._cleanup();\n        this._reject(new Error(message));\n    };\n\n    PopupWindow.prototype.close = function close() {\n        this._cleanup(false);\n    };\n\n    PopupWindow.prototype._cleanup = function _cleanup(keepOpen) {\n        _Log.Log.debug(\"PopupWindow.cleanup\");\n\n        window.clearInterval(this._checkForPopupClosedTimer);\n        this._checkForPopupClosedTimer = null;\n\n        delete window[\"popupCallback_\" + this._id];\n\n        if (this._popup && !keepOpen) {\n            this._popup.close();\n        }\n        this._popup = null;\n    };\n\n    PopupWindow.prototype._checkForPopupClosed = function _checkForPopupClosed() {\n        if (!this._popup || this._popup.closed) {\n            this._error(\"Popup window closed\");\n        }\n    };\n\n    PopupWindow.prototype._callback = function _callback(url, keepOpen) {\n        this._cleanup(keepOpen);\n\n        if (url) {\n            _Log.Log.debug(\"PopupWindow.callback success\");\n            this._success({ url: url });\n        } else {\n            _Log.Log.debug(\"PopupWindow.callback: Invalid response from popup\");\n            this._error(\"Invalid response from popup\");\n        }\n    };\n\n    PopupWindow.notifyOpener = function notifyOpener(url, keepOpen, delimiter) {\n        if (window.opener) {\n            url = url || window.location.href;\n            if (url) {\n                var data = _UrlUtility.UrlUtility.parseUrlFragment(url, delimiter);\n\n                if (data.state) {\n                    var name = \"popupCallback_\" + data.state;\n                    var callback = window.opener[name];\n                    if (callback) {\n                        _Log.Log.debug(\"PopupWindow.notifyOpener: passing url message to opener\");\n                        callback(url, keepOpen);\n                    } else {\n                        _Log.Log.warn(\"PopupWindow.notifyOpener: no matching callback found on opener\");\n                    }\n                } else {\n                    _Log.Log.warn(\"PopupWindow.notifyOpener: no state found in response url\");\n                }\n            }\n        } else {\n            _Log.Log.warn(\"PopupWindow.notifyOpener: no window.opener. Can't complete notification.\");\n        }\n    };\n\n    _createClass(PopupWindow, [{\n        key: 'promise',\n        get: function get() {\n            return this._promise;\n        }\n    }]);\n\n    return PopupWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/RedirectNavigator.js\":\n/*!**********************************!*\\\n  !*** ./src/RedirectNavigator.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.RedirectNavigator = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar RedirectNavigator = exports.RedirectNavigator = function () {\n    function RedirectNavigator() {\n        _classCallCheck(this, RedirectNavigator);\n    }\n\n    RedirectNavigator.prototype.prepare = function prepare() {\n        return Promise.resolve(this);\n    };\n\n    RedirectNavigator.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            _Log.Log.error(\"RedirectNavigator.navigate: No url provided\");\n            return Promise.reject(new Error(\"No url provided\"));\n        }\n\n        if (params.useReplaceToNavigate) {\n            window.location.replace(params.url);\n        } else {\n            window.location = params.url;\n        }\n\n        return Promise.resolve();\n    };\n\n    _createClass(RedirectNavigator, [{\n        key: \"url\",\n        get: function get() {\n            return window.location.href;\n        }\n    }]);\n\n    return RedirectNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/ResponseValidator.js\":\n/*!**********************************!*\\\n  !*** ./src/ResponseValidator.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.ResponseValidator = undefined;\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _UserInfoService = __webpack_require__(/*! ./UserInfoService.js */ \"./src/UserInfoService.js\");\n\nvar _TokenClient = __webpack_require__(/*! ./TokenClient.js */ \"./src/TokenClient.js\");\n\nvar _ErrorResponse = __webpack_require__(/*! ./ErrorResponse.js */ \"./src/ErrorResponse.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtilRsa.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar ProtocolClaims = [\"nonce\", \"at_hash\", \"iat\", \"nbf\", \"exp\", \"aud\", \"iss\", \"c_hash\"];\n\nvar ResponseValidator = exports.ResponseValidator = function () {\n    function ResponseValidator(settings) {\n        var MetadataServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _MetadataService.MetadataService;\n        var UserInfoServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _UserInfoService.UserInfoService;\n        var joseUtil = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _JoseUtil.JoseUtil;\n        var TokenClientCtor = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : _TokenClient.TokenClient;\n\n        _classCallCheck(this, ResponseValidator);\n\n        if (!settings) {\n            _Log.Log.error(\"ResponseValidator.ctor: No settings passed to ResponseValidator\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._metadataService = new MetadataServiceCtor(this._settings);\n        this._userInfoService = new UserInfoServiceCtor(this._settings);\n        this._joseUtil = joseUtil;\n        this._tokenClient = new TokenClientCtor(this._settings);\n    }\n\n    ResponseValidator.prototype.validateSigninResponse = function validateSigninResponse(state, response) {\n        var _this = this;\n\n        _Log.Log.debug(\"ResponseValidator.validateSigninResponse\");\n\n        return this._processSigninParams(state, response).then(function (response) {\n            _Log.Log.debug(\"ResponseValidator.validateSigninResponse: state processed\");\n            return _this._validateTokens(state, response).then(function (response) {\n                _Log.Log.debug(\"ResponseValidator.validateSigninResponse: tokens validated\");\n                return _this._processClaims(state, response).then(function (response) {\n                    _Log.Log.debug(\"ResponseValidator.validateSigninResponse: claims processed\");\n                    return response;\n                });\n            });\n        });\n    };\n\n    ResponseValidator.prototype.validateSignoutResponse = function validateSignoutResponse(state, response) {\n        if (state.id !== response.state) {\n            _Log.Log.error(\"ResponseValidator.validateSignoutResponse: State does not match\");\n            return Promise.reject(new Error(\"State does not match\"));\n        }\n\n        // now that we know the state matches, take the stored data\n        // and set it into the response so callers can get their state\n        // this is important for both success & error outcomes\n        _Log.Log.debug(\"ResponseValidator.validateSignoutResponse: state validated\");\n        response.state = state.data;\n\n        if (response.error) {\n            _Log.Log.warn(\"ResponseValidator.validateSignoutResponse: Response was error\", response.error);\n            return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processSigninParams = function _processSigninParams(state, response) {\n        if (state.id !== response.state) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: State does not match\");\n            return Promise.reject(new Error(\"State does not match\"));\n        }\n\n        if (!state.client_id) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: No client_id on state\");\n            return Promise.reject(new Error(\"No client_id on state\"));\n        }\n\n        if (!state.authority) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: No authority on state\");\n            return Promise.reject(new Error(\"No authority on state\"));\n        }\n\n        // this allows the authority to be loaded from the signin state\n        if (!this._settings.authority) {\n            this._settings.authority = state.authority;\n        }\n        // ensure we're using the correct authority if the authority is not loaded from signin state\n        else if (this._settings.authority && this._settings.authority !== state.authority) {\n                _Log.Log.error(\"ResponseValidator._processSigninParams: authority mismatch on settings vs. signin state\");\n                return Promise.reject(new Error(\"authority mismatch on settings vs. signin state\"));\n            }\n        // this allows the client_id to be loaded from the signin state\n        if (!this._settings.client_id) {\n            this._settings.client_id = state.client_id;\n        }\n        // ensure we're using the correct client_id if the client_id is not loaded from signin state\n        else if (this._settings.client_id && this._settings.client_id !== state.client_id) {\n                _Log.Log.error(\"ResponseValidator._processSigninParams: client_id mismatch on settings vs. signin state\");\n                return Promise.reject(new Error(\"client_id mismatch on settings vs. signin state\"));\n            }\n\n        // now that we know the state matches, take the stored data\n        // and set it into the response so callers can get their state\n        // this is important for both success & error outcomes\n        _Log.Log.debug(\"ResponseValidator._processSigninParams: state validated\");\n        response.state = state.data;\n\n        if (response.error) {\n            _Log.Log.warn(\"ResponseValidator._processSigninParams: Response was error\", response.error);\n            return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n        }\n\n        if (state.nonce && !response.id_token) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Expecting id_token in response\");\n            return Promise.reject(new Error(\"No id_token in response\"));\n        }\n\n        if (!state.nonce && response.id_token) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Not expecting id_token in response\");\n            return Promise.reject(new Error(\"Unexpected id_token in response\"));\n        }\n\n        if (state.code_verifier && !response.code) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Expecting code in response\");\n            return Promise.reject(new Error(\"No code in response\"));\n        }\n\n        if (!state.code_verifier && response.code) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Not expecting code in response\");\n            return Promise.reject(new Error(\"Unexpected code in response\"));\n        }\n\n        if (!response.scope) {\n            // if there's no scope on the response, then assume all scopes granted (per-spec) and copy over scopes from original request\n            response.scope = state.scope;\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processClaims = function _processClaims(state, response) {\n        var _this2 = this;\n\n        if (response.isOpenIdConnect) {\n            _Log.Log.debug(\"ResponseValidator._processClaims: response is OIDC, processing claims\");\n\n            response.profile = this._filterProtocolClaims(response.profile);\n\n            if (state.skipUserInfo !== true && this._settings.loadUserInfo && response.access_token) {\n                _Log.Log.debug(\"ResponseValidator._processClaims: loading user info\");\n\n                return this._userInfoService.getClaims(response.access_token).then(function (claims) {\n                    _Log.Log.debug(\"ResponseValidator._processClaims: user info claims received from user info endpoint\");\n\n                    if (claims.sub !== response.profile.sub) {\n                        _Log.Log.error(\"ResponseValidator._processClaims: sub from user info endpoint does not match sub in access_token\");\n                        return Promise.reject(new Error(\"sub from user info endpoint does not match sub in access_token\"));\n                    }\n\n                    response.profile = _this2._mergeClaims(response.profile, claims);\n                    _Log.Log.debug(\"ResponseValidator._processClaims: user info claims received, updated profile:\", response.profile);\n\n                    return response;\n                });\n            } else {\n                _Log.Log.debug(\"ResponseValidator._processClaims: not loading user info\");\n            }\n        } else {\n            _Log.Log.debug(\"ResponseValidator._processClaims: response is not OIDC, not processing claims\");\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._mergeClaims = function _mergeClaims(claims1, claims2) {\n        var result = Object.assign({}, claims1);\n\n        for (var name in claims2) {\n            var values = claims2[name];\n            if (!Array.isArray(values)) {\n                values = [values];\n            }\n\n            for (var i = 0; i < values.length; i++) {\n                var value = values[i];\n                if (!result[name]) {\n                    result[name] = value;\n                } else if (Array.isArray(result[name])) {\n                    if (result[name].indexOf(value) < 0) {\n                        result[name].push(value);\n                    }\n                } else if (result[name] !== value) {\n                    if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                        result[name] = this._mergeClaims(result[name], value);\n                    } else {\n                        result[name] = [result[name], value];\n                    }\n                }\n            }\n        }\n\n        return result;\n    };\n\n    ResponseValidator.prototype._filterProtocolClaims = function _filterProtocolClaims(claims) {\n        _Log.Log.debug(\"ResponseValidator._filterProtocolClaims, incoming claims:\", claims);\n\n        var result = Object.assign({}, claims);\n\n        if (this._settings._filterProtocolClaims) {\n            ProtocolClaims.forEach(function (type) {\n                delete result[type];\n            });\n\n            _Log.Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims filtered\", result);\n        } else {\n            _Log.Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims not filtered\");\n        }\n\n        return result;\n    };\n\n    ResponseValidator.prototype._validateTokens = function _validateTokens(state, response) {\n        if (response.code) {\n            _Log.Log.debug(\"ResponseValidator._validateTokens: Validating code\");\n            return this._processCode(state, response);\n        }\n\n        if (response.id_token) {\n            if (response.access_token) {\n                _Log.Log.debug(\"ResponseValidator._validateTokens: Validating id_token and access_token\");\n                return this._validateIdTokenAndAccessToken(state, response);\n            }\n\n            _Log.Log.debug(\"ResponseValidator._validateTokens: Validating id_token\");\n            return this._validateIdToken(state, response);\n        }\n\n        _Log.Log.debug(\"ResponseValidator._validateTokens: No code to process or id_token to validate\");\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processCode = function _processCode(state, response) {\n        var _this3 = this;\n\n        var request = {\n            client_id: state.client_id,\n            client_secret: state.client_secret,\n            code: response.code,\n            redirect_uri: state.redirect_uri,\n            code_verifier: state.code_verifier\n        };\n\n        if (state.extraTokenParams && _typeof(state.extraTokenParams) === 'object') {\n            Object.assign(request, state.extraTokenParams);\n        }\n\n        return this._tokenClient.exchangeCode(request).then(function (tokenResponse) {\n\n            for (var key in tokenResponse) {\n                response[key] = tokenResponse[key];\n            }\n\n            if (response.id_token) {\n                _Log.Log.debug(\"ResponseValidator._processCode: token response successful, processing id_token\");\n                return _this3._validateIdTokenAttributes(state, response);\n            } else {\n                _Log.Log.debug(\"ResponseValidator._processCode: token response successful, returning response\");\n            }\n\n            return response;\n        });\n    };\n\n    ResponseValidator.prototype._validateIdTokenAttributes = function _validateIdTokenAttributes(state, response) {\n        var _this4 = this;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n\n            var audience = state.client_id;\n            var clockSkewInSeconds = _this4._settings.clockSkew;\n            _Log.Log.debug(\"ResponseValidator._validateIdTokenAttributes: Validaing JWT attributes; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n            return _this4._joseUtil.validateJwtAttributes(response.id_token, issuer, audience, clockSkewInSeconds).then(function (payload) {\n\n                if (state.nonce && state.nonce !== payload.nonce) {\n                    _Log.Log.error(\"ResponseValidator._validateIdTokenAttributes: Invalid nonce in id_token\");\n                    return Promise.reject(new Error(\"Invalid nonce in id_token\"));\n                }\n\n                if (!payload.sub) {\n                    _Log.Log.error(\"ResponseValidator._validateIdTokenAttributes: No sub present in id_token\");\n                    return Promise.reject(new Error(\"No sub present in id_token\"));\n                }\n\n                response.profile = payload;\n                return response;\n            });\n        });\n    };\n\n    ResponseValidator.prototype._validateIdTokenAndAccessToken = function _validateIdTokenAndAccessToken(state, response) {\n        var _this5 = this;\n\n        return this._validateIdToken(state, response).then(function (response) {\n            return _this5._validateAccessToken(response);\n        });\n    };\n\n    ResponseValidator.prototype._validateIdToken = function _validateIdToken(state, response) {\n        var _this6 = this;\n\n        if (!state.nonce) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: No nonce on state\");\n            return Promise.reject(new Error(\"No nonce on state\"));\n        }\n\n        var jwt = this._joseUtil.parseJwt(response.id_token);\n        if (!jwt || !jwt.header || !jwt.payload) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: Failed to parse id_token\", jwt);\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\n        }\n\n        if (state.nonce !== jwt.payload.nonce) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: Invalid nonce in id_token\");\n            return Promise.reject(new Error(\"Invalid nonce in id_token\"));\n        }\n\n        var kid = jwt.header.kid;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n            _Log.Log.debug(\"ResponseValidator._validateIdToken: Received issuer\");\n\n            return _this6._metadataService.getSigningKeys().then(function (keys) {\n                if (!keys) {\n                    _Log.Log.error(\"ResponseValidator._validateIdToken: No signing keys from metadata\");\n                    return Promise.reject(new Error(\"No signing keys from metadata\"));\n                }\n\n                _Log.Log.debug(\"ResponseValidator._validateIdToken: Received signing keys\");\n                var key = void 0;\n                if (!kid) {\n                    keys = _this6._filterByAlg(keys, jwt.header.alg);\n\n                    if (keys.length > 1) {\n                        _Log.Log.error(\"ResponseValidator._validateIdToken: No kid found in id_token and more than one key found in metadata\");\n                        return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\n                    } else {\n                        // kid is mandatory only when there are multiple keys in the referenced JWK Set document\n                        // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\n                        key = keys[0];\n                    }\n                } else {\n                    key = keys.filter(function (key) {\n                        return key.kid === kid;\n                    })[0];\n                }\n\n                if (!key) {\n                    _Log.Log.error(\"ResponseValidator._validateIdToken: No key matching kid or alg found in signing keys\");\n                    return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\n                }\n\n                var audience = state.client_id;\n\n                var clockSkewInSeconds = _this6._settings.clockSkew;\n                _Log.Log.debug(\"ResponseValidator._validateIdToken: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n                return _this6._joseUtil.validateJwt(response.id_token, key, issuer, audience, clockSkewInSeconds).then(function () {\n                    _Log.Log.debug(\"ResponseValidator._validateIdToken: JWT validation successful\");\n\n                    if (!jwt.payload.sub) {\n                        _Log.Log.error(\"ResponseValidator._validateIdToken: No sub present in id_token\");\n                        return Promise.reject(new Error(\"No sub present in id_token\"));\n                    }\n\n                    response.profile = jwt.payload;\n\n                    return response;\n                });\n            });\n        });\n    };\n\n    ResponseValidator.prototype._filterByAlg = function _filterByAlg(keys, alg) {\n        var kty = null;\n        if (alg.startsWith(\"RS\")) {\n            kty = \"RSA\";\n        } else if (alg.startsWith(\"PS\")) {\n            kty = \"PS\";\n        } else if (alg.startsWith(\"ES\")) {\n            kty = \"EC\";\n        } else {\n            _Log.Log.debug(\"ResponseValidator._filterByAlg: alg not supported: \", alg);\n            return [];\n        }\n\n        _Log.Log.debug(\"ResponseValidator._filterByAlg: Looking for keys that match kty: \", kty);\n\n        keys = keys.filter(function (key) {\n            return key.kty === kty;\n        });\n\n        _Log.Log.debug(\"ResponseValidator._filterByAlg: Number of keys that match kty: \", kty, keys.length);\n\n        return keys;\n    };\n\n    ResponseValidator.prototype._validateAccessToken = function _validateAccessToken(response) {\n        if (!response.profile) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No profile loaded from id_token\");\n            return Promise.reject(new Error(\"No profile loaded from id_token\"));\n        }\n\n        if (!response.profile.at_hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No at_hash in id_token\");\n            return Promise.reject(new Error(\"No at_hash in id_token\"));\n        }\n\n        if (!response.id_token) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No id_token\");\n            return Promise.reject(new Error(\"No id_token\"));\n        }\n\n        var jwt = this._joseUtil.parseJwt(response.id_token);\n        if (!jwt || !jwt.header) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Failed to parse id_token\", jwt);\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\n        }\n\n        var hashAlg = jwt.header.alg;\n        if (!hashAlg || hashAlg.length !== 5) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        var hashBits = hashAlg.substr(2, 3);\n        if (!hashBits) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        hashBits = parseInt(hashBits);\n        if (hashBits !== 256 && hashBits !== 384 && hashBits !== 512) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        var sha = \"sha\" + hashBits;\n        var hash = this._joseUtil.hashString(response.access_token, sha);\n        if (!hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: access_token hash failed:\", sha);\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\n        }\n\n        var left = hash.substr(0, hash.length / 2);\n        var left_b64u = this._joseUtil.hexToBase64Url(left);\n        if (left_b64u !== response.profile.at_hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Failed to validate at_hash\", left_b64u, response.profile.at_hash);\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\n        }\n\n        _Log.Log.debug(\"ResponseValidator._validateAccessToken: success\");\n\n        return Promise.resolve(response);\n    };\n\n    return ResponseValidator;\n}();\n\n/***/ }),\n\n/***/ \"./src/SessionMonitor.js\":\n/*!*******************************!*\\\n  !*** ./src/SessionMonitor.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SessionMonitor = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _CheckSessionIFrame = __webpack_require__(/*! ./CheckSessionIFrame.js */ \"./src/CheckSessionIFrame.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar SessionMonitor = exports.SessionMonitor = function () {\n    function SessionMonitor(userManager) {\n        var _this = this;\n\n        var CheckSessionIFrameCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _CheckSessionIFrame.CheckSessionIFrame;\n        var timer = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _Global.Global.timer;\n\n        _classCallCheck(this, SessionMonitor);\n\n        if (!userManager) {\n            _Log.Log.error(\"SessionMonitor.ctor: No user manager passed to SessionMonitor\");\n            throw new Error(\"userManager\");\n        }\n\n        this._userManager = userManager;\n        this._CheckSessionIFrameCtor = CheckSessionIFrameCtor;\n        this._timer = timer;\n\n        this._userManager.events.addUserLoaded(this._start.bind(this));\n        this._userManager.events.addUserUnloaded(this._stop.bind(this));\n\n        this._userManager.getUser().then(function (user) {\n            // doing this manually here since calling getUser \n            // doesn't trigger load event.\n            if (user) {\n                _this._start(user);\n            } else if (_this._settings.monitorAnonymousSession) {\n                _this._userManager.querySessionStatus().then(function (session) {\n                    var tmpUser = {\n                        session_state: session.session_state\n                    };\n                    if (session.sub && session.sid) {\n                        tmpUser.profile = {\n                            sub: session.sub,\n                            sid: session.sid\n                        };\n                    }\n                    _this._start(tmpUser);\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in a ctor\n                    _Log.Log.error(\"SessionMonitor ctor: error from querySessionStatus:\", err.message);\n                });\n            }\n        }).catch(function (err) {\n            // catch to suppress errors since we're in a ctor\n            _Log.Log.error(\"SessionMonitor ctor: error from getUser:\", err.message);\n        });\n    }\n\n    SessionMonitor.prototype._start = function _start(user) {\n        var _this2 = this;\n\n        var session_state = user.session_state;\n\n        if (session_state) {\n            if (user.profile) {\n                this._sub = user.profile.sub;\n                this._sid = user.profile.sid;\n                _Log.Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", sub:\", this._sub);\n            } else {\n                this._sub = undefined;\n                this._sid = undefined;\n                _Log.Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", anonymous user\");\n            }\n\n            if (!this._checkSessionIFrame) {\n                this._metadataService.getCheckSessionIframe().then(function (url) {\n                    if (url) {\n                        _Log.Log.debug(\"SessionMonitor._start: Initializing check session iframe\");\n\n                        var client_id = _this2._client_id;\n                        var interval = _this2._checkSessionInterval;\n                        var stopOnError = _this2._stopCheckSessionOnError;\n\n                        _this2._checkSessionIFrame = new _this2._CheckSessionIFrameCtor(_this2._callback.bind(_this2), client_id, url, interval, stopOnError);\n                        _this2._checkSessionIFrame.load().then(function () {\n                            _this2._checkSessionIFrame.start(session_state);\n                        });\n                    } else {\n                        _Log.Log.warn(\"SessionMonitor._start: No check session iframe found in the metadata\");\n                    }\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in non-promise callback\n                    _Log.Log.error(\"SessionMonitor._start: Error from getCheckSessionIframe:\", err.message);\n                });\n            } else {\n                this._checkSessionIFrame.start(session_state);\n            }\n        }\n    };\n\n    SessionMonitor.prototype._stop = function _stop() {\n        var _this3 = this;\n\n        this._sub = undefined;\n        this._sid = undefined;\n\n        if (this._checkSessionIFrame) {\n            _Log.Log.debug(\"SessionMonitor._stop\");\n            this._checkSessionIFrame.stop();\n        }\n\n        if (this._settings.monitorAnonymousSession) {\n            // using a timer to delay re-initialization to avoid race conditions during signout\n            var timerHandle = this._timer.setInterval(function () {\n                _this3._timer.clearInterval(timerHandle);\n\n                _this3._userManager.querySessionStatus().then(function (session) {\n                    var tmpUser = {\n                        session_state: session.session_state\n                    };\n                    if (session.sub && session.sid) {\n                        tmpUser.profile = {\n                            sub: session.sub,\n                            sid: session.sid\n                        };\n                    }\n                    _this3._start(tmpUser);\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in a callback\n                    _Log.Log.error(\"SessionMonitor: error from querySessionStatus:\", err.message);\n                });\n            }, 1000);\n        }\n    };\n\n    SessionMonitor.prototype._callback = function _callback() {\n        var _this4 = this;\n\n        this._userManager.querySessionStatus().then(function (session) {\n            var raiseEvent = true;\n\n            if (session) {\n                if (session.sub === _this4._sub) {\n                    raiseEvent = false;\n                    _this4._checkSessionIFrame.start(session.session_state);\n\n                    if (session.sid === _this4._sid) {\n                        _Log.Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, restarting check session iframe; session_state:\", session.session_state);\n                    } else {\n                        _Log.Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, session state has changed, restarting check session iframe; session_state:\", session.session_state);\n                        _this4._userManager.events._raiseUserSessionChanged();\n                    }\n                } else {\n                    _Log.Log.debug(\"SessionMonitor._callback: Different subject signed into OP:\", session.sub);\n                }\n            } else {\n                _Log.Log.debug(\"SessionMonitor._callback: Subject no longer signed into OP\");\n            }\n\n            if (raiseEvent) {\n                if (_this4._sub) {\n                    _Log.Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed out event\");\n                    _this4._userManager.events._raiseUserSignedOut();\n                } else {\n                    _Log.Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed in event\");\n                    _this4._userManager.events._raiseUserSignedIn();\n                }\n            }\n        }).catch(function (err) {\n            if (_this4._sub) {\n                _Log.Log.debug(\"SessionMonitor._callback: Error calling queryCurrentSigninSession; raising signed out event\", err.message);\n                _this4._userManager.events._raiseUserSignedOut();\n            }\n        });\n    };\n\n    _createClass(SessionMonitor, [{\n        key: '_settings',\n        get: function get() {\n            return this._userManager.settings;\n        }\n    }, {\n        key: '_metadataService',\n        get: function get() {\n            return this._userManager.metadataService;\n        }\n    }, {\n        key: '_client_id',\n        get: function get() {\n            return this._settings.client_id;\n        }\n    }, {\n        key: '_checkSessionInterval',\n        get: function get() {\n            return this._settings.checkSessionInterval;\n        }\n    }, {\n        key: '_stopCheckSessionOnError',\n        get: function get() {\n            return this._settings.stopCheckSessionOnError;\n        }\n    }]);\n\n    return SessionMonitor;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninRequest.js\":\n/*!******************************!*\\\n  !*** ./src/SigninRequest.js ***!\n  \\******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninRequest = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nvar _SigninState = __webpack_require__(/*! ./SigninState.js */ \"./src/SigninState.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SigninRequest = exports.SigninRequest = function () {\n    function SigninRequest(_ref) {\n        var url = _ref.url,\n            client_id = _ref.client_id,\n            redirect_uri = _ref.redirect_uri,\n            response_type = _ref.response_type,\n            scope = _ref.scope,\n            authority = _ref.authority,\n            data = _ref.data,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            id_token_hint = _ref.id_token_hint,\n            login_hint = _ref.login_hint,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            response_mode = _ref.response_mode,\n            request = _ref.request,\n            request_uri = _ref.request_uri,\n            extraQueryParams = _ref.extraQueryParams,\n            request_type = _ref.request_type,\n            client_secret = _ref.client_secret,\n            extraTokenParams = _ref.extraTokenParams,\n            skipUserInfo = _ref.skipUserInfo;\n\n        _classCallCheck(this, SigninRequest);\n\n        if (!url) {\n            _Log.Log.error(\"SigninRequest.ctor: No url passed\");\n            throw new Error(\"url\");\n        }\n        if (!client_id) {\n            _Log.Log.error(\"SigninRequest.ctor: No client_id passed\");\n            throw new Error(\"client_id\");\n        }\n        if (!redirect_uri) {\n            _Log.Log.error(\"SigninRequest.ctor: No redirect_uri passed\");\n            throw new Error(\"redirect_uri\");\n        }\n        if (!response_type) {\n            _Log.Log.error(\"SigninRequest.ctor: No response_type passed\");\n            throw new Error(\"response_type\");\n        }\n        if (!scope) {\n            _Log.Log.error(\"SigninRequest.ctor: No scope passed\");\n            throw new Error(\"scope\");\n        }\n        if (!authority) {\n            _Log.Log.error(\"SigninRequest.ctor: No authority passed\");\n            throw new Error(\"authority\");\n        }\n\n        var oidc = SigninRequest.isOidc(response_type);\n        var code = SigninRequest.isCode(response_type);\n\n        if (!response_mode) {\n            response_mode = SigninRequest.isCode(response_type) ? \"query\" : null;\n        }\n\n        this.state = new _SigninState.SigninState({ nonce: oidc,\n            data: data, client_id: client_id, authority: authority, redirect_uri: redirect_uri,\n            code_verifier: code,\n            request_type: request_type, response_mode: response_mode,\n            client_secret: client_secret, scope: scope, extraTokenParams: extraTokenParams, skipUserInfo: skipUserInfo });\n\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"client_id\", client_id);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"redirect_uri\", redirect_uri);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"response_type\", response_type);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"scope\", scope);\n\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"state\", this.state.id);\n        if (oidc) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"nonce\", this.state.nonce);\n        }\n        if (code) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"code_challenge\", this.state.code_challenge);\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"code_challenge_method\", \"S256\");\n        }\n\n        var optional = { prompt: prompt, display: display, max_age: max_age, ui_locales: ui_locales, id_token_hint: id_token_hint, login_hint: login_hint, acr_values: acr_values, resource: resource, request: request, request_uri: request_uri, response_mode: response_mode };\n        for (var key in optional) {\n            if (optional[key]) {\n                url = _UrlUtility.UrlUtility.addQueryParam(url, key, optional[key]);\n            }\n        }\n\n        for (var _key in extraQueryParams) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, _key, extraQueryParams[_key]);\n        }\n\n        this.url = url;\n    }\n\n    SigninRequest.isOidc = function isOidc(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"id_token\";\n        });\n        return !!result[0];\n    };\n\n    SigninRequest.isOAuth = function isOAuth(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"token\";\n        });\n        return !!result[0];\n    };\n\n    SigninRequest.isCode = function isCode(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"code\";\n        });\n        return !!result[0];\n    };\n\n    return SigninRequest;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninResponse.js\":\n/*!*******************************!*\\\n  !*** ./src/SigninResponse.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninResponse = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcScope = \"openid\";\n\nvar SigninResponse = exports.SigninResponse = function () {\n    function SigninResponse(url) {\n        var delimiter = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : \"#\";\n\n        _classCallCheck(this, SigninResponse);\n\n        var values = _UrlUtility.UrlUtility.parseUrlFragment(url, delimiter);\n\n        this.error = values.error;\n        this.error_description = values.error_description;\n        this.error_uri = values.error_uri;\n\n        this.code = values.code;\n        this.state = values.state;\n        this.id_token = values.id_token;\n        this.session_state = values.session_state;\n        this.access_token = values.access_token;\n        this.token_type = values.token_type;\n        this.scope = values.scope;\n        this.profile = undefined; // will be set from ResponseValidator\n\n        this.expires_in = values.expires_in;\n    }\n\n    _createClass(SigninResponse, [{\n        key: \"expires_in\",\n        get: function get() {\n            if (this.expires_at) {\n                var now = parseInt(Date.now() / 1000);\n                return this.expires_at - now;\n            }\n            return undefined;\n        },\n        set: function set(value) {\n            var expires_in = parseInt(value);\n            if (typeof expires_in === 'number' && expires_in > 0) {\n                var now = parseInt(Date.now() / 1000);\n                this.expires_at = now + expires_in;\n            }\n        }\n    }, {\n        key: \"expired\",\n        get: function get() {\n            var expires_in = this.expires_in;\n            if (expires_in !== undefined) {\n                return expires_in <= 0;\n            }\n            return undefined;\n        }\n    }, {\n        key: \"scopes\",\n        get: function get() {\n            return (this.scope || \"\").split(\" \");\n        }\n    }, {\n        key: \"isOpenIdConnect\",\n        get: function get() {\n            return this.scopes.indexOf(OidcScope) >= 0 || !!this.id_token;\n        }\n    }]);\n\n    return SigninResponse;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninState.js\":\n/*!****************************!*\\\n  !*** ./src/SigninState.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninState = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _State2 = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtilRsa.js\");\n\nvar _random = __webpack_require__(/*! ./random.js */ \"./src/random.js\");\n\nvar _random2 = _interopRequireDefault(_random);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SigninState = exports.SigninState = function (_State) {\n    _inherits(SigninState, _State);\n\n    function SigninState() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            nonce = _ref.nonce,\n            authority = _ref.authority,\n            client_id = _ref.client_id,\n            redirect_uri = _ref.redirect_uri,\n            code_verifier = _ref.code_verifier,\n            response_mode = _ref.response_mode,\n            client_secret = _ref.client_secret,\n            scope = _ref.scope,\n            extraTokenParams = _ref.extraTokenParams,\n            skipUserInfo = _ref.skipUserInfo;\n\n        _classCallCheck(this, SigninState);\n\n        var _this = _possibleConstructorReturn(this, _State.call(this, arguments[0]));\n\n        if (nonce === true) {\n            _this._nonce = (0, _random2.default)();\n        } else if (nonce) {\n            _this._nonce = nonce;\n        }\n\n        if (code_verifier === true) {\n            // random() produces 32 length\n            _this._code_verifier = (0, _random2.default)() + (0, _random2.default)() + (0, _random2.default)();\n        } else if (code_verifier) {\n            _this._code_verifier = code_verifier;\n        }\n\n        if (_this.code_verifier) {\n            var hash = _JoseUtil.JoseUtil.hashString(_this.code_verifier, \"SHA256\");\n            _this._code_challenge = _JoseUtil.JoseUtil.hexToBase64Url(hash);\n        }\n\n        _this._redirect_uri = redirect_uri;\n        _this._authority = authority;\n        _this._client_id = client_id;\n        _this._response_mode = response_mode;\n        _this._client_secret = client_secret;\n        _this._scope = scope;\n        _this._extraTokenParams = extraTokenParams;\n        _this._skipUserInfo = skipUserInfo;\n        return _this;\n    }\n\n    SigninState.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"SigninState.toStorageString\");\n        return JSON.stringify({\n            id: this.id,\n            data: this.data,\n            created: this.created,\n            request_type: this.request_type,\n            nonce: this.nonce,\n            code_verifier: this.code_verifier,\n            redirect_uri: this.redirect_uri,\n            authority: this.authority,\n            client_id: this.client_id,\n            response_mode: this.response_mode,\n            client_secret: this.client_secret,\n            scope: this.scope,\n            extraTokenParams: this.extraTokenParams,\n            skipUserInfo: this.skipUserInfo\n        });\n    };\n\n    SigninState.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"SigninState.fromStorageString\");\n        var data = JSON.parse(storageString);\n        return new SigninState(data);\n    };\n\n    _createClass(SigninState, [{\n        key: 'nonce',\n        get: function get() {\n            return this._nonce;\n        }\n    }, {\n        key: 'authority',\n        get: function get() {\n            return this._authority;\n        }\n    }, {\n        key: 'client_id',\n        get: function get() {\n            return this._client_id;\n        }\n    }, {\n        key: 'redirect_uri',\n        get: function get() {\n            return this._redirect_uri;\n        }\n    }, {\n        key: 'code_verifier',\n        get: function get() {\n            return this._code_verifier;\n        }\n    }, {\n        key: 'code_challenge',\n        get: function get() {\n            return this._code_challenge;\n        }\n    }, {\n        key: 'response_mode',\n        get: function get() {\n            return this._response_mode;\n        }\n    }, {\n        key: 'client_secret',\n        get: function get() {\n            return this._client_secret;\n        }\n    }, {\n        key: 'scope',\n        get: function get() {\n            return this._scope;\n        }\n    }, {\n        key: 'extraTokenParams',\n        get: function get() {\n            return this._extraTokenParams;\n        }\n    }, {\n        key: 'skipUserInfo',\n        get: function get() {\n            return this._skipUserInfo;\n        }\n    }]);\n\n    return SigninState;\n}(_State2.State);\n\n/***/ }),\n\n/***/ \"./src/SignoutRequest.js\":\n/*!*******************************!*\\\n  !*** ./src/SignoutRequest.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SignoutRequest = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nvar _State = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SignoutRequest = exports.SignoutRequest = function SignoutRequest(_ref) {\n    var url = _ref.url,\n        id_token_hint = _ref.id_token_hint,\n        post_logout_redirect_uri = _ref.post_logout_redirect_uri,\n        data = _ref.data,\n        extraQueryParams = _ref.extraQueryParams,\n        request_type = _ref.request_type;\n\n    _classCallCheck(this, SignoutRequest);\n\n    if (!url) {\n        _Log.Log.error(\"SignoutRequest.ctor: No url passed\");\n        throw new Error(\"url\");\n    }\n\n    if (id_token_hint) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"id_token_hint\", id_token_hint);\n    }\n\n    if (post_logout_redirect_uri) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"post_logout_redirect_uri\", post_logout_redirect_uri);\n\n        if (data) {\n            this.state = new _State.State({ data: data, request_type: request_type });\n\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"state\", this.state.id);\n        }\n    }\n\n    for (var key in extraQueryParams) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, key, extraQueryParams[key]);\n    }\n\n    this.url = url;\n};\n\n/***/ }),\n\n/***/ \"./src/SignoutResponse.js\":\n/*!********************************!*\\\n  !*** ./src/SignoutResponse.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n        value: true\n});\nexports.SignoutResponse = undefined;\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SignoutResponse = exports.SignoutResponse = function SignoutResponse(url) {\n        _classCallCheck(this, SignoutResponse);\n\n        var values = _UrlUtility.UrlUtility.parseUrlFragment(url, \"?\");\n\n        this.error = values.error;\n        this.error_description = values.error_description;\n        this.error_uri = values.error_uri;\n\n        this.state = values.state;\n};\n\n/***/ }),\n\n/***/ \"./src/SilentRenewService.js\":\n/*!***********************************!*\\\n  !*** ./src/SilentRenewService.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SilentRenewService = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SilentRenewService = exports.SilentRenewService = function () {\n    function SilentRenewService(userManager) {\n        _classCallCheck(this, SilentRenewService);\n\n        this._userManager = userManager;\n    }\n\n    SilentRenewService.prototype.start = function start() {\n        if (!this._callback) {\n            this._callback = this._tokenExpiring.bind(this);\n            this._userManager.events.addAccessTokenExpiring(this._callback);\n\n            // this will trigger loading of the user so the expiring events can be initialized\n            this._userManager.getUser().then(function (user) {\n                // deliberate nop\n            }).catch(function (err) {\n                // catch to suppress errors since we're in a ctor\n                _Log.Log.error(\"SilentRenewService.start: Error from getUser:\", err.message);\n            });\n        }\n    };\n\n    SilentRenewService.prototype.stop = function stop() {\n        if (this._callback) {\n            this._userManager.events.removeAccessTokenExpiring(this._callback);\n            delete this._callback;\n        }\n    };\n\n    SilentRenewService.prototype._tokenExpiring = function _tokenExpiring() {\n        var _this = this;\n\n        this._userManager.signinSilent().then(function (user) {\n            _Log.Log.debug(\"SilentRenewService._tokenExpiring: Silent token renewal successful\");\n        }, function (err) {\n            _Log.Log.error(\"SilentRenewService._tokenExpiring: Error from signinSilent:\", err.message);\n            _this._userManager.events._raiseSilentRenewError(err);\n        });\n    };\n\n    return SilentRenewService;\n}();\n\n/***/ }),\n\n/***/ \"./src/State.js\":\n/*!**********************!*\\\n  !*** ./src/State.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.State = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _random = __webpack_require__(/*! ./random.js */ \"./src/random.js\");\n\nvar _random2 = _interopRequireDefault(_random);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar State = exports.State = function () {\n    function State() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            id = _ref.id,\n            data = _ref.data,\n            created = _ref.created,\n            request_type = _ref.request_type;\n\n        _classCallCheck(this, State);\n\n        this._id = id || (0, _random2.default)();\n        this._data = data;\n\n        if (typeof created === 'number' && created > 0) {\n            this._created = created;\n        } else {\n            this._created = parseInt(Date.now() / 1000);\n        }\n        this._request_type = request_type;\n    }\n\n    State.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"State.toStorageString\");\n        return JSON.stringify({\n            id: this.id,\n            data: this.data,\n            created: this.created,\n            request_type: this.request_type\n        });\n    };\n\n    State.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"State.fromStorageString\");\n        return new State(JSON.parse(storageString));\n    };\n\n    State.clearStaleState = function clearStaleState(storage, age) {\n\n        var cutoff = Date.now() / 1000 - age;\n\n        return storage.getAllKeys().then(function (keys) {\n            _Log.Log.debug(\"State.clearStaleState: got keys\", keys);\n\n            var promises = [];\n\n            var _loop = function _loop(i) {\n                var key = keys[i];\n                p = storage.get(key).then(function (item) {\n                    var remove = false;\n\n                    if (item) {\n                        try {\n                            var state = State.fromStorageString(item);\n\n                            _Log.Log.debug(\"State.clearStaleState: got item from key: \", key, state.created);\n\n                            if (state.created <= cutoff) {\n                                remove = true;\n                            }\n                        } catch (e) {\n                            _Log.Log.error(\"State.clearStaleState: Error parsing state for key\", key, e.message);\n                            remove = true;\n                        }\n                    } else {\n                        _Log.Log.debug(\"State.clearStaleState: no item in storage for key: \", key);\n                        remove = true;\n                    }\n\n                    if (remove) {\n                        _Log.Log.debug(\"State.clearStaleState: removed item for key: \", key);\n                        return storage.remove(key);\n                    }\n                });\n\n\n                promises.push(p);\n            };\n\n            for (var i = 0; i < keys.length; i++) {\n                var p;\n\n                _loop(i);\n            }\n\n            _Log.Log.debug(\"State.clearStaleState: waiting on promise count:\", promises.length);\n            return Promise.all(promises);\n        });\n    };\n\n    _createClass(State, [{\n        key: 'id',\n        get: function get() {\n            return this._id;\n        }\n    }, {\n        key: 'data',\n        get: function get() {\n            return this._data;\n        }\n    }, {\n        key: 'created',\n        get: function get() {\n            return this._created;\n        }\n    }, {\n        key: 'request_type',\n        get: function get() {\n            return this._request_type;\n        }\n    }]);\n\n    return State;\n}();\n\n/***/ }),\n\n/***/ \"./src/Timer.js\":\n/*!**********************!*\\\n  !*** ./src/Timer.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.Timer = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nvar _Event2 = __webpack_require__(/*! ./Event.js */ \"./src/Event.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar TimerDuration = 5; // seconds\n\nvar Timer = exports.Timer = function (_Event) {\n    _inherits(Timer, _Event);\n\n    function Timer(name) {\n        var timer = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.timer;\n        var nowFunc = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : undefined;\n\n        _classCallCheck(this, Timer);\n\n        var _this = _possibleConstructorReturn(this, _Event.call(this, name));\n\n        _this._timer = timer;\n\n        if (nowFunc) {\n            _this._nowFunc = nowFunc;\n        } else {\n            _this._nowFunc = function () {\n                return Date.now() / 1000;\n            };\n        }\n        return _this;\n    }\n\n    Timer.prototype.init = function init(duration) {\n        if (duration <= 0) {\n            duration = 1;\n        }\n        duration = parseInt(duration);\n\n        var expiration = this.now + duration;\n        if (this.expiration === expiration && this._timerHandle) {\n            // no need to reinitialize to same expiration, so bail out\n            _Log.Log.debug(\"Timer.init timer \" + this._name + \" skipping initialization since already initialized for expiration:\", this.expiration);\n            return;\n        }\n\n        this.cancel();\n\n        _Log.Log.debug(\"Timer.init timer \" + this._name + \" for duration:\", duration);\n        this._expiration = expiration;\n\n        // we're using a fairly short timer and then checking the expiration in the\n        // callback to handle scenarios where the browser device sleeps, and then\n        // the timers end up getting delayed.\n        var timerDuration = TimerDuration;\n        if (duration < timerDuration) {\n            timerDuration = duration;\n        }\n        this._timerHandle = this._timer.setInterval(this._callback.bind(this), timerDuration * 1000);\n    };\n\n    Timer.prototype.cancel = function cancel() {\n        if (this._timerHandle) {\n            _Log.Log.debug(\"Timer.cancel: \", this._name);\n            this._timer.clearInterval(this._timerHandle);\n            this._timerHandle = null;\n        }\n    };\n\n    Timer.prototype._callback = function _callback() {\n        var diff = this._expiration - this.now;\n        _Log.Log.debug(\"Timer.callback; \" + this._name + \" timer expires in:\", diff);\n\n        if (this._expiration <= this.now) {\n            this.cancel();\n            _Event.prototype.raise.call(this);\n        }\n    };\n\n    _createClass(Timer, [{\n        key: 'now',\n        get: function get() {\n            return parseInt(this._nowFunc());\n        }\n    }, {\n        key: 'expiration',\n        get: function get() {\n            return this._expiration;\n        }\n    }]);\n\n    return Timer;\n}(_Event2.Event);\n\n/***/ }),\n\n/***/ \"./src/TokenClient.js\":\n/*!****************************!*\\\n  !*** ./src/TokenClient.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.TokenClient = undefined;\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar TokenClient = exports.TokenClient = function () {\n    function TokenClient(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n\n        _classCallCheck(this, TokenClient);\n\n        if (!settings) {\n            _Log.Log.error(\"TokenClient.ctor: No settings passed\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor();\n        this._metadataService = new MetadataServiceCtor(this._settings);\n    }\n\n    TokenClient.prototype.exchangeCode = function exchangeCode() {\n        var _this = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.grant_type = args.grant_type || \"authorization_code\";\n        args.client_id = args.client_id || this._settings.client_id;\n        args.redirect_uri = args.redirect_uri || this._settings.redirect_uri;\n\n        if (!args.code) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No code passed\");\n            return Promise.reject(new Error(\"A code is required\"));\n        }\n        if (!args.redirect_uri) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No redirect_uri passed\");\n            return Promise.reject(new Error(\"A redirect_uri is required\"));\n        }\n        if (!args.code_verifier) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No code_verifier passed\");\n            return Promise.reject(new Error(\"A code_verifier is required\"));\n        }\n        if (!args.client_id) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No client_id passed\");\n            return Promise.reject(new Error(\"A client_id is required\"));\n        }\n\n        return this._metadataService.getTokenEndpoint(false).then(function (url) {\n            _Log.Log.debug(\"TokenClient.exchangeCode: Received token endpoint\");\n\n            return _this._jsonService.postForm(url, args).then(function (response) {\n                _Log.Log.debug(\"TokenClient.exchangeCode: response received\");\n                return response;\n            });\n        });\n    };\n\n    TokenClient.prototype.exchangeRefreshToken = function exchangeRefreshToken() {\n        var _this2 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.grant_type = args.grant_type || \"refresh_token\";\n        args.client_id = args.client_id || this._settings.client_id;\n        args.client_secret = args.client_secret || this._settings.client_secret;\n\n        if (!args.refresh_token) {\n            _Log.Log.error(\"TokenClient.exchangeRefreshToken: No refresh_token passed\");\n            return Promise.reject(new Error(\"A refresh_token is required\"));\n        }\n        if (!args.client_id) {\n            _Log.Log.error(\"TokenClient.exchangeRefreshToken: No client_id passed\");\n            return Promise.reject(new Error(\"A client_id is required\"));\n        }\n\n        return this._metadataService.getTokenEndpoint(false).then(function (url) {\n            _Log.Log.debug(\"TokenClient.exchangeRefreshToken: Received token endpoint\");\n\n            return _this2._jsonService.postForm(url, args).then(function (response) {\n                _Log.Log.debug(\"TokenClient.exchangeRefreshToken: response received\");\n                return response;\n            });\n        });\n    };\n\n    return TokenClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/TokenRevocationClient.js\":\n/*!**************************************!*\\\n  !*** ./src/TokenRevocationClient.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.TokenRevocationClient = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar AccessTokenTypeHint = \"access_token\";\nvar RefreshTokenTypeHint = \"refresh_token\";\n\nvar TokenRevocationClient = exports.TokenRevocationClient = function () {\n    function TokenRevocationClient(settings) {\n        var XMLHttpRequestCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.XMLHttpRequest;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n\n        _classCallCheck(this, TokenRevocationClient);\n\n        if (!settings) {\n            _Log.Log.error(\"TokenRevocationClient.ctor: No settings provided\");\n            throw new Error(\"No settings provided.\");\n        }\n\n        this._settings = settings;\n        this._XMLHttpRequestCtor = XMLHttpRequestCtor;\n        this._metadataService = new MetadataServiceCtor(this._settings);\n    }\n\n    TokenRevocationClient.prototype.revoke = function revoke(token, required) {\n        var _this = this;\n\n        var type = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : \"access_token\";\n\n        if (!token) {\n            _Log.Log.error(\"TokenRevocationClient.revoke: No token provided\");\n            throw new Error(\"No token provided.\");\n        }\n\n        if (type !== AccessTokenTypeHint && type != RefreshTokenTypeHint) {\n            _Log.Log.error(\"TokenRevocationClient.revoke: Invalid token type\");\n            throw new Error(\"Invalid token type.\");\n        }\n\n        return this._metadataService.getRevocationEndpoint().then(function (url) {\n            if (!url) {\n                if (required) {\n                    _Log.Log.error(\"TokenRevocationClient.revoke: Revocation not supported\");\n                    throw new Error(\"Revocation not supported\");\n                }\n\n                // not required, so don't error and just return\n                return;\n            }\n\n            _Log.Log.debug(\"TokenRevocationClient.revoke: Revoking \" + type);\n            var client_id = _this._settings.client_id;\n            var client_secret = _this._settings.client_secret;\n            return _this._revoke(url, client_id, client_secret, token, type);\n        });\n    };\n\n    TokenRevocationClient.prototype._revoke = function _revoke(url, client_id, client_secret, token, type) {\n        var _this2 = this;\n\n        return new Promise(function (resolve, reject) {\n\n            var xhr = new _this2._XMLHttpRequestCtor();\n            xhr.open(\"POST\", url);\n\n            xhr.onload = function () {\n                _Log.Log.debug(\"TokenRevocationClient.revoke: HTTP response received, status\", xhr.status);\n\n                if (xhr.status === 200) {\n                    resolve();\n                } else {\n                    reject(Error(xhr.statusText + \" (\" + xhr.status + \")\"));\n                }\n            };\n            xhr.onerror = function () {\n                _Log.Log.debug(\"TokenRevocationClient.revoke: Network Error.\");\n                reject(\"Network Error\");\n            };\n\n            var body = \"client_id=\" + encodeURIComponent(client_id);\n            if (client_secret) {\n                body += \"&client_secret=\" + encodeURIComponent(client_secret);\n            }\n            body += \"&token_type_hint=\" + encodeURIComponent(type);\n            body += \"&token=\" + encodeURIComponent(token);\n\n            xhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\n            xhr.send(body);\n        });\n    };\n\n    return TokenRevocationClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/UrlUtility.js\":\n/*!***************************!*\\\n  !*** ./src/UrlUtility.js ***!\n  \\***************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UrlUtility = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UrlUtility = exports.UrlUtility = function () {\n    function UrlUtility() {\n        _classCallCheck(this, UrlUtility);\n    }\n\n    UrlUtility.addQueryParam = function addQueryParam(url, name, value) {\n        if (url.indexOf('?') < 0) {\n            url += \"?\";\n        }\n\n        if (url[url.length - 1] !== \"?\") {\n            url += \"&\";\n        }\n\n        url += encodeURIComponent(name);\n        url += \"=\";\n        url += encodeURIComponent(value);\n\n        return url;\n    };\n\n    UrlUtility.parseUrlFragment = function parseUrlFragment(value) {\n        var delimiter = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : \"#\";\n        var global = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _Global.Global;\n\n        if (typeof value !== 'string') {\n            value = global.location.href;\n        }\n\n        var idx = value.lastIndexOf(delimiter);\n        if (idx >= 0) {\n            value = value.substr(idx + 1);\n        }\n\n        if (delimiter === \"?\") {\n            // if we're doing query, then strip off hash fragment before we parse\n            idx = value.indexOf('#');\n            if (idx >= 0) {\n                value = value.substr(0, idx);\n            }\n        }\n\n        var params = {},\n            regex = /([^&=]+)=([^&]*)/g,\n            m;\n\n        var counter = 0;\n        while (m = regex.exec(value)) {\n            params[decodeURIComponent(m[1])] = decodeURIComponent(m[2]);\n            if (counter++ > 50) {\n                _Log.Log.error(\"UrlUtility.parseUrlFragment: response exceeded expected number of parameters\", value);\n                return {\n                    error: \"Response exceeded expected number of parameters\"\n                };\n            }\n        }\n\n        for (var prop in params) {\n            return params;\n        }\n\n        return {};\n    };\n\n    return UrlUtility;\n}();\n\n/***/ }),\n\n/***/ \"./src/User.js\":\n/*!*********************!*\\\n  !*** ./src/User.js ***!\n  \\*********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.User = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar User = exports.User = function () {\n    function User(_ref) {\n        var id_token = _ref.id_token,\n            session_state = _ref.session_state,\n            access_token = _ref.access_token,\n            refresh_token = _ref.refresh_token,\n            token_type = _ref.token_type,\n            scope = _ref.scope,\n            profile = _ref.profile,\n            expires_at = _ref.expires_at,\n            state = _ref.state;\n\n        _classCallCheck(this, User);\n\n        this.id_token = id_token;\n        this.session_state = session_state;\n        this.access_token = access_token;\n        this.refresh_token = refresh_token;\n        this.token_type = token_type;\n        this.scope = scope;\n        this.profile = profile;\n        this.expires_at = expires_at;\n        this.state = state;\n    }\n\n    User.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"User.toStorageString\");\n        return JSON.stringify({\n            id_token: this.id_token,\n            session_state: this.session_state,\n            access_token: this.access_token,\n            refresh_token: this.refresh_token,\n            token_type: this.token_type,\n            scope: this.scope,\n            profile: this.profile,\n            expires_at: this.expires_at\n        });\n    };\n\n    User.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"User.fromStorageString\");\n        return new User(JSON.parse(storageString));\n    };\n\n    _createClass(User, [{\n        key: 'expires_in',\n        get: function get() {\n            if (this.expires_at) {\n                var now = parseInt(Date.now() / 1000);\n                return this.expires_at - now;\n            }\n            return undefined;\n        },\n        set: function set(value) {\n            var expires_in = parseInt(value);\n            if (typeof expires_in === 'number' && expires_in > 0) {\n                var now = parseInt(Date.now() / 1000);\n                this.expires_at = now + expires_in;\n            }\n        }\n    }, {\n        key: 'expired',\n        get: function get() {\n            var expires_in = this.expires_in;\n            if (expires_in !== undefined) {\n                return expires_in <= 0;\n            }\n            return undefined;\n        }\n    }, {\n        key: 'scopes',\n        get: function get() {\n            return (this.scope || \"\").split(\" \");\n        }\n    }]);\n\n    return User;\n}();\n\n/***/ }),\n\n/***/ \"./src/UserInfoService.js\":\n/*!********************************!*\\\n  !*** ./src/UserInfoService.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserInfoService = undefined;\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtilRsa.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserInfoService = exports.UserInfoService = function () {\n    function UserInfoService(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n        var joseUtil = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _JoseUtil.JoseUtil;\n\n        _classCallCheck(this, UserInfoService);\n\n        if (!settings) {\n            _Log.Log.error(\"UserInfoService.ctor: No settings passed\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor(undefined, undefined, this._getClaimsFromJwt.bind(this));\n        this._metadataService = new MetadataServiceCtor(this._settings);\n        this._joseUtil = joseUtil;\n    }\n\n    UserInfoService.prototype.getClaims = function getClaims(token) {\n        var _this = this;\n\n        if (!token) {\n            _Log.Log.error(\"UserInfoService.getClaims: No token passed\");\n            return Promise.reject(new Error(\"A token is required\"));\n        }\n\n        return this._metadataService.getUserInfoEndpoint().then(function (url) {\n            _Log.Log.debug(\"UserInfoService.getClaims: received userinfo url\", url);\n\n            return _this._jsonService.getJson(url, token).then(function (claims) {\n                _Log.Log.debug(\"UserInfoService.getClaims: claims received\", claims);\n                return claims;\n            });\n        });\n    };\n\n    UserInfoService.prototype._getClaimsFromJwt = function _getClaimsFromJwt(req) {\n        var _this2 = this;\n\n        try {\n            var jwt = this._joseUtil.parseJwt(req.responseText);\n            if (!jwt || !jwt.header || !jwt.payload) {\n                _Log.Log.error(\"UserInfoService._getClaimsFromJwt: Failed to parse JWT\", jwt);\n                return Promise.reject(new Error(\"Failed to parse id_token\"));\n            }\n\n            var kid = jwt.header.kid;\n\n            var issuerPromise = void 0;\n            switch (this._settings.userInfoJwtIssuer) {\n                case 'OP':\n                    issuerPromise = this._metadataService.getIssuer();\n                    break;\n                case 'ANY':\n                    issuerPromise = Promise.resolve(jwt.payload.iss);\n                    break;\n                default:\n                    issuerPromise = Promise.resolve(this._settings.userInfoJwtIssuer);\n                    break;\n            }\n\n            return issuerPromise.then(function (issuer) {\n                _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Received issuer:\" + issuer);\n\n                return _this2._metadataService.getSigningKeys().then(function (keys) {\n                    if (!keys) {\n                        _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No signing keys from metadata\");\n                        return Promise.reject(new Error(\"No signing keys from metadata\"));\n                    }\n\n                    _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Received signing keys\");\n                    var key = void 0;\n                    if (!kid) {\n                        keys = _this2._filterByAlg(keys, jwt.header.alg);\n\n                        if (keys.length > 1) {\n                            _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No kid found in id_token and more than one key found in metadata\");\n                            return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\n                        } else {\n                            // kid is mandatory only when there are multiple keys in the referenced JWK Set document\n                            // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\n                            key = keys[0];\n                        }\n                    } else {\n                        key = keys.filter(function (key) {\n                            return key.kid === kid;\n                        })[0];\n                    }\n\n                    if (!key) {\n                        _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No key matching kid or alg found in signing keys\");\n                        return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\n                    }\n\n                    var audience = _this2._settings.client_id;\n\n                    var clockSkewInSeconds = _this2._settings.clockSkew;\n                    _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n                    return _this2._joseUtil.validateJwt(req.responseText, key, issuer, audience, clockSkewInSeconds, undefined, true).then(function () {\n                        _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: JWT validation successful\");\n                        return jwt.payload;\n                    });\n                });\n            });\n            return;\n        } catch (e) {\n            _Log.Log.error(\"UserInfoService._getClaimsFromJwt: Error parsing JWT response\", e.message);\n            reject(e);\n            return;\n        }\n    };\n\n    UserInfoService.prototype._filterByAlg = function _filterByAlg(keys, alg) {\n        var kty = null;\n        if (alg.startsWith(\"RS\")) {\n            kty = \"RSA\";\n        } else if (alg.startsWith(\"PS\")) {\n            kty = \"PS\";\n        } else if (alg.startsWith(\"ES\")) {\n            kty = \"EC\";\n        } else {\n            _Log.Log.debug(\"UserInfoService._filterByAlg: alg not supported: \", alg);\n            return [];\n        }\n\n        _Log.Log.debug(\"UserInfoService._filterByAlg: Looking for keys that match kty: \", kty);\n\n        keys = keys.filter(function (key) {\n            return key.kty === kty;\n        });\n\n        _Log.Log.debug(\"UserInfoService._filterByAlg: Number of keys that match kty: \", kty, keys.length);\n\n        return keys;\n    };\n\n    return UserInfoService;\n}();\n\n/***/ }),\n\n/***/ \"./src/UserManager.js\":\n/*!****************************!*\\\n  !*** ./src/UserManager.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManager = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClient2 = __webpack_require__(/*! ./OidcClient.js */ \"./src/OidcClient.js\");\n\nvar _UserManagerSettings = __webpack_require__(/*! ./UserManagerSettings.js */ \"./src/UserManagerSettings.js\");\n\nvar _User = __webpack_require__(/*! ./User.js */ \"./src/User.js\");\n\nvar _UserManagerEvents = __webpack_require__(/*! ./UserManagerEvents.js */ \"./src/UserManagerEvents.js\");\n\nvar _SilentRenewService = __webpack_require__(/*! ./SilentRenewService.js */ \"./src/SilentRenewService.js\");\n\nvar _SessionMonitor = __webpack_require__(/*! ./SessionMonitor.js */ \"./src/SessionMonitor.js\");\n\nvar _TokenRevocationClient = __webpack_require__(/*! ./TokenRevocationClient.js */ \"./src/TokenRevocationClient.js\");\n\nvar _TokenClient = __webpack_require__(/*! ./TokenClient.js */ \"./src/TokenClient.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtilRsa.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserManager = exports.UserManager = function (_OidcClient) {\n    _inherits(UserManager, _OidcClient);\n\n    function UserManager() {\n        var settings = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n        var SilentRenewServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _SilentRenewService.SilentRenewService;\n        var SessionMonitorCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _SessionMonitor.SessionMonitor;\n        var TokenRevocationClientCtor = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _TokenRevocationClient.TokenRevocationClient;\n        var TokenClientCtor = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : _TokenClient.TokenClient;\n        var joseUtil = arguments.length > 5 && arguments[5] !== undefined ? arguments[5] : _JoseUtil.JoseUtil;\n\n        _classCallCheck(this, UserManager);\n\n        if (!(settings instanceof _UserManagerSettings.UserManagerSettings)) {\n            settings = new _UserManagerSettings.UserManagerSettings(settings);\n        }\n\n        var _this = _possibleConstructorReturn(this, _OidcClient.call(this, settings));\n\n        _this._events = new _UserManagerEvents.UserManagerEvents(settings);\n        _this._silentRenewService = new SilentRenewServiceCtor(_this);\n\n        // order is important for the following properties; these services depend upon the events.\n        if (_this.settings.automaticSilentRenew) {\n            _Log.Log.debug(\"UserManager.ctor: automaticSilentRenew is configured, setting up silent renew\");\n            _this.startSilentRenew();\n        }\n\n        if (_this.settings.monitorSession) {\n            _Log.Log.debug(\"UserManager.ctor: monitorSession is configured, setting up session monitor\");\n            _this._sessionMonitor = new SessionMonitorCtor(_this);\n        }\n\n        _this._tokenRevocationClient = new TokenRevocationClientCtor(_this._settings);\n        _this._tokenClient = new TokenClientCtor(_this._settings);\n        _this._joseUtil = joseUtil;\n        return _this;\n    }\n\n    UserManager.prototype.getUser = function getUser() {\n        var _this2 = this;\n\n        return this._loadUser().then(function (user) {\n            if (user) {\n                _Log.Log.info(\"UserManager.getUser: user loaded\");\n\n                _this2._events.load(user, false);\n\n                return user;\n            } else {\n                _Log.Log.info(\"UserManager.getUser: user not found in storage\");\n                return null;\n            }\n        });\n    };\n\n    UserManager.prototype.removeUser = function removeUser() {\n        var _this3 = this;\n\n        return this.storeUser(null).then(function () {\n            _Log.Log.info(\"UserManager.removeUser: user removed from storage\");\n            _this3._events.unload();\n        });\n    };\n\n    UserManager.prototype.signinRedirect = function signinRedirect() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:r\";\n        var navParams = {\n            useReplaceToNavigate: args.useReplaceToNavigate\n        };\n        return this._signinStart(args, this._redirectNavigator, navParams).then(function () {\n            _Log.Log.info(\"UserManager.signinRedirect: successful\");\n        });\n    };\n\n    UserManager.prototype.signinRedirectCallback = function signinRedirectCallback(url) {\n        return this._signinEnd(url || this._redirectNavigator.url).then(function (user) {\n            if (user.profile && user.profile.sub) {\n                _Log.Log.info(\"UserManager.signinRedirectCallback: successful, signed in sub: \", user.profile.sub);\n            } else {\n                _Log.Log.info(\"UserManager.signinRedirectCallback: no sub\");\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinPopup = function signinPopup() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:p\";\n        var url = args.redirect_uri || this.settings.popup_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.signinPopup: No popup_redirect_uri or redirect_uri configured\");\n            return Promise.reject(new Error(\"No popup_redirect_uri or redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.display = \"popup\";\n\n        return this._signin(args, this._popupNavigator, {\n            startUrl: url,\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\n        }).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinPopup: signinPopup successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinPopup: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinPopupCallback = function signinPopupCallback(url) {\n        return this._signinCallback(url, this._popupNavigator).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinPopupCallback: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinPopupCallback: no sub\");\n                }\n            }\n\n            return user;\n        }).catch(function (err) {\n            _Log.Log.error( true && err.message);\n        });\n    };\n\n    UserManager.prototype.signinSilent = function signinSilent() {\n        var _this4 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:s\";\n        // first determine if we have a refresh token, or need to use iframe\n        return this._loadUser().then(function (user) {\n            if (user && user.refresh_token) {\n                args.refresh_token = user.refresh_token;\n                return _this4._useRefreshToken(args);\n            } else {\n                args.id_token_hint = args.id_token_hint || _this4.settings.includeIdTokenInSilentRenew && user && user.id_token;\n                if (user && _this4._settings.validateSubOnSilentRenew) {\n                    _Log.Log.debug(\"UserManager.signinSilent, subject prior to silent renew: \", user.profile.sub);\n                    args.current_sub = user.profile.sub;\n                }\n                return _this4._signinSilentIframe(args);\n            }\n        });\n    };\n\n    UserManager.prototype._useRefreshToken = function _useRefreshToken() {\n        var _this5 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        return this._tokenClient.exchangeRefreshToken(args).then(function (result) {\n            if (!result) {\n                _Log.Log.error(\"UserManager._useRefreshToken: No response returned from token endpoint\");\n                return Promise.reject(\"No response returned from token endpoint\");\n            }\n            if (!result.access_token) {\n                _Log.Log.error(\"UserManager._useRefreshToken: No access token returned from token endpoint\");\n                return Promise.reject(\"No access token returned from token endpoint\");\n            }\n\n            return _this5._loadUser().then(function (user) {\n                if (user) {\n                    var idTokenValidation = Promise.resolve();\n                    if (result.id_token) {\n                        idTokenValidation = _this5._validateIdTokenFromTokenRefreshToken(user.profile, result.id_token);\n                    }\n\n                    return idTokenValidation.then(function () {\n                        _Log.Log.debug(\"UserManager._useRefreshToken: refresh token response success\");\n                        user.id_token = result.id_token;\n                        user.access_token = result.access_token;\n                        user.refresh_token = result.refresh_token || user.refresh_token;\n                        user.expires_in = result.expires_in;\n\n                        return _this5.storeUser(user).then(function () {\n                            _this5._events.load(user);\n                            return user;\n                        });\n                    });\n                } else {\n                    return null;\n                }\n            });\n        });\n    };\n\n    UserManager.prototype._validateIdTokenFromTokenRefreshToken = function _validateIdTokenFromTokenRefreshToken(profile, id_token) {\n        var _this6 = this;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n            return _this6._joseUtil.validateJwtAttributes(id_token, issuer, _this6._settings.client_id, _this6._settings.clockSkew).then(function (payload) {\n                if (!payload) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: Failed to validate id_token\");\n                    return Promise.reject(new Error(\"Failed to validate id_token\"));\n                }\n                if (payload.sub !== profile.sub) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: sub in id_token does not match current sub\");\n                    return Promise.reject(new Error(\"sub in id_token does not match current sub\"));\n                }\n                if (payload.auth_time && payload.auth_time !== profile.auth_time) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: auth_time in id_token does not match original auth_time\");\n                    return Promise.reject(new Error(\"auth_time in id_token does not match original auth_time\"));\n                }\n                if (payload.azp && payload.azp !== profile.azp) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp in id_token does not match original azp\");\n                    return Promise.reject(new Error(\"azp in id_token does not match original azp\"));\n                }\n                if (!payload.azp && profile.azp) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp not in id_token, but present in original id_token\");\n                    return Promise.reject(new Error(\"azp not in id_token, but present in original id_token\"));\n                }\n            });\n        });\n    };\n\n    UserManager.prototype._signinSilentIframe = function _signinSilentIframe() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        var url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.signinSilent: No silent_redirect_uri configured\");\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.prompt = args.prompt || \"none\";\n\n        return this._signin(args, this._iframeNavigator, {\n            startUrl: url,\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\n        }).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinSilent: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinSilent: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinSilentCallback = function signinSilentCallback(url) {\n        return this._signinCallback(url, this._iframeNavigator).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinSilentCallback: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinSilentCallback: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinCallback = function signinCallback(url) {\n        var _this7 = this;\n\n        return this.readSigninResponseState(url).then(function (_ref) {\n            var state = _ref.state,\n                response = _ref.response;\n\n            if (state.request_type === \"si:r\") {\n                return _this7.signinRedirectCallback(url);\n            }\n            if (state.request_type === \"si:p\") {\n                return _this7.signinPopupCallback(url);\n            }\n            if (state.request_type === \"si:s\") {\n                return _this7.signinSilentCallback(url);\n            }\n            return Promise.reject(new Error(\"invalid response_type in state\"));\n        });\n    };\n\n    UserManager.prototype.signoutCallback = function signoutCallback(url, keepOpen) {\n        var _this8 = this;\n\n        return this.readSignoutResponseState(url).then(function (_ref2) {\n            var state = _ref2.state,\n                response = _ref2.response;\n\n            if (state) {\n                if (state.request_type === \"so:r\") {\n                    return _this8.signoutRedirectCallback(url);\n                }\n                if (state.request_type === \"so:p\") {\n                    return _this8.signoutPopupCallback(url, keepOpen);\n                }\n                return Promise.reject(new Error(\"invalid response_type in state\"));\n            }\n            return response;\n        });\n    };\n\n    UserManager.prototype.querySessionStatus = function querySessionStatus() {\n        var _this9 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:s\"; // this acts like a signin silent\n        var url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.querySessionStatus: No silent_redirect_uri configured\");\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.prompt = \"none\";\n        args.response_type = args.response_type || this.settings.query_status_response_type;\n        args.scope = args.scope || \"openid\";\n        args.skipUserInfo = true;\n\n        return this._signinStart(args, this._iframeNavigator, {\n            startUrl: url,\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\n        }).then(function (navResponse) {\n            return _this9.processSigninResponse(navResponse.url).then(function (signinResponse) {\n                _Log.Log.debug(\"UserManager.querySessionStatus: got signin response\");\n\n                if (signinResponse.session_state && signinResponse.profile.sub) {\n                    _Log.Log.info(\"UserManager.querySessionStatus: querySessionStatus success for sub: \", signinResponse.profile.sub);\n                    return {\n                        session_state: signinResponse.session_state,\n                        sub: signinResponse.profile.sub,\n                        sid: signinResponse.profile.sid\n                    };\n                } else {\n                    _Log.Log.info(\"querySessionStatus successful, user not authenticated\");\n                }\n            }).catch(function (err) {\n                if (err.session_state && _this9.settings.monitorAnonymousSession) {\n                    if (err.message == \"login_required\" || err.message == \"consent_required\" || err.message == \"interaction_required\" || err.message == \"account_selection_required\") {\n                        _Log.Log.info(\"UserManager.querySessionStatus: querySessionStatus success for anonymous user\");\n                        return {\n                            session_state: err.session_state\n                        };\n                    }\n                }\n\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signin = function _signin(args, navigator) {\n        var _this10 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return this._signinStart(args, navigator, navigatorParams).then(function (navResponse) {\n            return _this10._signinEnd(navResponse.url, args);\n        });\n    };\n\n    UserManager.prototype._signinStart = function _signinStart(args, navigator) {\n        var _this11 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n\n        return navigator.prepare(navigatorParams).then(function (handle) {\n            _Log.Log.debug(\"UserManager._signinStart: got navigator window handle\");\n\n            return _this11.createSigninRequest(args).then(function (signinRequest) {\n                _Log.Log.debug(\"UserManager._signinStart: got signin request\");\n\n                navigatorParams.url = signinRequest.url;\n                navigatorParams.id = signinRequest.state.id;\n\n                return handle.navigate(navigatorParams);\n            }).catch(function (err) {\n                if (handle.close) {\n                    _Log.Log.debug(\"UserManager._signinStart: Error after preparing navigator, closing navigator window\");\n                    handle.close();\n                }\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signinEnd = function _signinEnd(url) {\n        var _this12 = this;\n\n        var args = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {};\n\n        return this.processSigninResponse(url).then(function (signinResponse) {\n            _Log.Log.debug(\"UserManager._signinEnd: got signin response\");\n\n            var user = new _User.User(signinResponse);\n\n            if (args.current_sub) {\n                if (args.current_sub !== user.profile.sub) {\n                    _Log.Log.debug(\"UserManager._signinEnd: current user does not match user returned from signin. sub from signin: \", user.profile.sub);\n                    return Promise.reject(new Error(\"login_required\"));\n                } else {\n                    _Log.Log.debug(\"UserManager._signinEnd: current user matches user returned from signin\");\n                }\n            }\n\n            return _this12.storeUser(user).then(function () {\n                _Log.Log.debug(\"UserManager._signinEnd: user stored\");\n\n                _this12._events.load(user);\n\n                return user;\n            });\n        });\n    };\n\n    UserManager.prototype._signinCallback = function _signinCallback(url, navigator) {\n        _Log.Log.debug(\"UserManager._signinCallback\");\n        return navigator.callback(url);\n    };\n\n    UserManager.prototype.signoutRedirect = function signoutRedirect() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"so:r\";\n        var postLogoutRedirectUri = args.post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\n        if (postLogoutRedirectUri) {\n            args.post_logout_redirect_uri = postLogoutRedirectUri;\n        }\n        var navParams = {\n            useReplaceToNavigate: args.useReplaceToNavigate\n        };\n        return this._signoutStart(args, this._redirectNavigator, navParams).then(function () {\n            _Log.Log.info(\"UserManager.signoutRedirect: successful\");\n        });\n    };\n\n    UserManager.prototype.signoutRedirectCallback = function signoutRedirectCallback(url) {\n        return this._signoutEnd(url || this._redirectNavigator.url).then(function (response) {\n            _Log.Log.info(\"UserManager.signoutRedirectCallback: successful\");\n            return response;\n        });\n    };\n\n    UserManager.prototype.signoutPopup = function signoutPopup() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"so:p\";\n        var url = args.post_logout_redirect_uri || this.settings.popup_post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\n        args.post_logout_redirect_uri = url;\n        args.display = \"popup\";\n        if (args.post_logout_redirect_uri) {\n            // we're putting a dummy entry in here because we\n            // need a unique id from the state for notification\n            // to the parent window, which is necessary if we\n            // plan to return back to the client after signout\n            // and so we can close the popup after signout\n            args.state = args.state || {};\n        }\n\n        return this._signout(args, this._popupNavigator, {\n            startUrl: url,\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\n        }).then(function () {\n            _Log.Log.info(\"UserManager.signoutPopup: successful\");\n        });\n    };\n\n    UserManager.prototype.signoutPopupCallback = function signoutPopupCallback(url, keepOpen) {\n        if (typeof keepOpen === 'undefined' && typeof url === 'boolean') {\n            keepOpen = url;\n            url = null;\n        }\n\n        var delimiter = '?';\n        return this._popupNavigator.callback(url, keepOpen, delimiter).then(function () {\n            _Log.Log.info(\"UserManager.signoutPopupCallback: successful\");\n        });\n    };\n\n    UserManager.prototype._signout = function _signout(args, navigator) {\n        var _this13 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return this._signoutStart(args, navigator, navigatorParams).then(function (navResponse) {\n            return _this13._signoutEnd(navResponse.url);\n        });\n    };\n\n    UserManager.prototype._signoutStart = function _signoutStart() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        var _this14 = this;\n\n        var navigator = arguments[1];\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return navigator.prepare(navigatorParams).then(function (handle) {\n            _Log.Log.debug(\"UserManager._signoutStart: got navigator window handle\");\n\n            return _this14._loadUser().then(function (user) {\n                _Log.Log.debug(\"UserManager._signoutStart: loaded current user from storage\");\n\n                var revokePromise = _this14._settings.revokeAccessTokenOnSignout ? _this14._revokeInternal(user) : Promise.resolve();\n                return revokePromise.then(function () {\n\n                    var id_token = args.id_token_hint || user && user.id_token;\n                    if (id_token) {\n                        _Log.Log.debug(\"UserManager._signoutStart: Setting id_token into signout request\");\n                        args.id_token_hint = id_token;\n                    }\n\n                    return _this14.removeUser().then(function () {\n                        _Log.Log.debug(\"UserManager._signoutStart: user removed, creating signout request\");\n\n                        return _this14.createSignoutRequest(args).then(function (signoutRequest) {\n                            _Log.Log.debug(\"UserManager._signoutStart: got signout request\");\n\n                            navigatorParams.url = signoutRequest.url;\n                            if (signoutRequest.state) {\n                                navigatorParams.id = signoutRequest.state.id;\n                            }\n                            return handle.navigate(navigatorParams);\n                        });\n                    });\n                });\n            }).catch(function (err) {\n                if (handle.close) {\n                    _Log.Log.debug(\"UserManager._signoutStart: Error after preparing navigator, closing navigator window\");\n                    handle.close();\n                }\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signoutEnd = function _signoutEnd(url) {\n        return this.processSignoutResponse(url).then(function (signoutResponse) {\n            _Log.Log.debug(\"UserManager._signoutEnd: got signout response\");\n\n            return signoutResponse;\n        });\n    };\n\n    UserManager.prototype.revokeAccessToken = function revokeAccessToken() {\n        var _this15 = this;\n\n        return this._loadUser().then(function (user) {\n            return _this15._revokeInternal(user, true).then(function (success) {\n                if (success) {\n                    _Log.Log.debug(\"UserManager.revokeAccessToken: removing token properties from user and re-storing\");\n\n                    user.access_token = null;\n                    user.refresh_token = null;\n                    user.expires_at = null;\n                    user.token_type = null;\n\n                    return _this15.storeUser(user).then(function () {\n                        _Log.Log.debug(\"UserManager.revokeAccessToken: user stored\");\n                        _this15._events.load(user);\n                    });\n                }\n            });\n        }).then(function () {\n            _Log.Log.info(\"UserManager.revokeAccessToken: access token revoked successfully\");\n        });\n    };\n\n    UserManager.prototype._revokeInternal = function _revokeInternal(user, required) {\n        var _this16 = this;\n\n        if (user) {\n            var access_token = user.access_token;\n            var refresh_token = user.refresh_token;\n\n            return this._revokeAccessTokenInternal(access_token, required).then(function (atSuccess) {\n                return _this16._revokeRefreshTokenInternal(refresh_token, required).then(function (rtSuccess) {\n                    if (!atSuccess && !rtSuccess) {\n                        _Log.Log.debug(\"UserManager.revokeAccessToken: no need to revoke due to no token(s), or JWT format\");\n                    }\n\n                    return atSuccess || rtSuccess;\n                });\n            });\n        }\n\n        return Promise.resolve(false);\n    };\n\n    UserManager.prototype._revokeAccessTokenInternal = function _revokeAccessTokenInternal(access_token, required) {\n        // check for JWT vs. reference token\n        if (!access_token || access_token.indexOf('.') >= 0) {\n            return Promise.resolve(false);\n        }\n\n        return this._tokenRevocationClient.revoke(access_token, required).then(function () {\n            return true;\n        });\n    };\n\n    UserManager.prototype._revokeRefreshTokenInternal = function _revokeRefreshTokenInternal(refresh_token, required) {\n        if (!refresh_token) {\n            return Promise.resolve(false);\n        }\n\n        return this._tokenRevocationClient.revoke(refresh_token, required, \"refresh_token\").then(function () {\n            return true;\n        });\n    };\n\n    UserManager.prototype.startSilentRenew = function startSilentRenew() {\n        this._silentRenewService.start();\n    };\n\n    UserManager.prototype.stopSilentRenew = function stopSilentRenew() {\n        this._silentRenewService.stop();\n    };\n\n    UserManager.prototype._loadUser = function _loadUser() {\n        return this._userStore.get(this._userStoreKey).then(function (storageString) {\n            if (storageString) {\n                _Log.Log.debug(\"UserManager._loadUser: user storageString loaded\");\n                return _User.User.fromStorageString(storageString);\n            }\n\n            _Log.Log.debug(\"UserManager._loadUser: no user storageString\");\n            return null;\n        });\n    };\n\n    UserManager.prototype.storeUser = function storeUser(user) {\n        if (user) {\n            _Log.Log.debug(\"UserManager.storeUser: storing user\");\n\n            var storageString = user.toStorageString();\n            return this._userStore.set(this._userStoreKey, storageString);\n        } else {\n            _Log.Log.debug(\"storeUser.storeUser: removing user\");\n            return this._userStore.remove(this._userStoreKey);\n        }\n    };\n\n    _createClass(UserManager, [{\n        key: '_redirectNavigator',\n        get: function get() {\n            return this.settings.redirectNavigator;\n        }\n    }, {\n        key: '_popupNavigator',\n        get: function get() {\n            return this.settings.popupNavigator;\n        }\n    }, {\n        key: '_iframeNavigator',\n        get: function get() {\n            return this.settings.iframeNavigator;\n        }\n    }, {\n        key: '_userStore',\n        get: function get() {\n            return this.settings.userStore;\n        }\n    }, {\n        key: 'events',\n        get: function get() {\n            return this._events;\n        }\n    }, {\n        key: '_userStoreKey',\n        get: function get() {\n            return 'user:' + this.settings.authority + ':' + this.settings.client_id;\n        }\n    }]);\n\n    return UserManager;\n}(_OidcClient2.OidcClient);\n\n/***/ }),\n\n/***/ \"./src/UserManagerEvents.js\":\n/*!**********************************!*\\\n  !*** ./src/UserManagerEvents.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManagerEvents = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _AccessTokenEvents2 = __webpack_require__(/*! ./AccessTokenEvents.js */ \"./src/AccessTokenEvents.js\");\n\nvar _Event = __webpack_require__(/*! ./Event.js */ \"./src/Event.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserManagerEvents = exports.UserManagerEvents = function (_AccessTokenEvents) {\n    _inherits(UserManagerEvents, _AccessTokenEvents);\n\n    function UserManagerEvents(settings) {\n        _classCallCheck(this, UserManagerEvents);\n\n        var _this = _possibleConstructorReturn(this, _AccessTokenEvents.call(this, settings));\n\n        _this._userLoaded = new _Event.Event(\"User loaded\");\n        _this._userUnloaded = new _Event.Event(\"User unloaded\");\n        _this._silentRenewError = new _Event.Event(\"Silent renew error\");\n        _this._userSignedIn = new _Event.Event(\"User signed in\");\n        _this._userSignedOut = new _Event.Event(\"User signed out\");\n        _this._userSessionChanged = new _Event.Event(\"User session changed\");\n        return _this;\n    }\n\n    UserManagerEvents.prototype.load = function load(user) {\n        var raiseEvent = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : true;\n\n        _Log.Log.debug(\"UserManagerEvents.load\");\n        _AccessTokenEvents.prototype.load.call(this, user);\n        if (raiseEvent) {\n            this._userLoaded.raise(user);\n        }\n    };\n\n    UserManagerEvents.prototype.unload = function unload() {\n        _Log.Log.debug(\"UserManagerEvents.unload\");\n        _AccessTokenEvents.prototype.unload.call(this);\n        this._userUnloaded.raise();\n    };\n\n    UserManagerEvents.prototype.addUserLoaded = function addUserLoaded(cb) {\n        this._userLoaded.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserLoaded = function removeUserLoaded(cb) {\n        this._userLoaded.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype.addUserUnloaded = function addUserUnloaded(cb) {\n        this._userUnloaded.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserUnloaded = function removeUserUnloaded(cb) {\n        this._userUnloaded.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype.addSilentRenewError = function addSilentRenewError(cb) {\n        this._silentRenewError.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeSilentRenewError = function removeSilentRenewError(cb) {\n        this._silentRenewError.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseSilentRenewError = function _raiseSilentRenewError(e) {\n        _Log.Log.debug(\"UserManagerEvents._raiseSilentRenewError\", e.message);\n        this._silentRenewError.raise(e);\n    };\n\n    UserManagerEvents.prototype.addUserSignedIn = function addUserSignedIn(cb) {\n        this._userSignedIn.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSignedIn = function removeUserSignedIn(cb) {\n        this._userSignedIn.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSignedIn = function _raiseUserSignedIn() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSignedIn\");\n        this._userSignedIn.raise();\n    };\n\n    UserManagerEvents.prototype.addUserSignedOut = function addUserSignedOut(cb) {\n        this._userSignedOut.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSignedOut = function removeUserSignedOut(cb) {\n        this._userSignedOut.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSignedOut = function _raiseUserSignedOut() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSignedOut\");\n        this._userSignedOut.raise();\n    };\n\n    UserManagerEvents.prototype.addUserSessionChanged = function addUserSessionChanged(cb) {\n        this._userSessionChanged.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSessionChanged = function removeUserSessionChanged(cb) {\n        this._userSessionChanged.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSessionChanged = function _raiseUserSessionChanged() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSessionChanged\");\n        this._userSessionChanged.raise();\n    };\n\n    return UserManagerEvents;\n}(_AccessTokenEvents2.AccessTokenEvents);\n\n/***/ }),\n\n/***/ \"./src/UserManagerSettings.js\":\n/*!************************************!*\\\n  !*** ./src/UserManagerSettings.js ***!\n  \\************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManagerSettings = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClientSettings2 = __webpack_require__(/*! ./OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _RedirectNavigator = __webpack_require__(/*! ./RedirectNavigator.js */ \"./src/RedirectNavigator.js\");\n\nvar _PopupNavigator = __webpack_require__(/*! ./PopupNavigator.js */ \"./src/PopupNavigator.js\");\n\nvar _IFrameNavigator = __webpack_require__(/*! ./IFrameNavigator.js */ \"./src/IFrameNavigator.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nvar _SigninRequest = __webpack_require__(/*! ./SigninRequest.js */ \"./src/SigninRequest.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultAccessTokenExpiringNotificationTime = 60;\nvar DefaultCheckSessionInterval = 2000;\n\nvar UserManagerSettings = exports.UserManagerSettings = function (_OidcClientSettings) {\n    _inherits(UserManagerSettings, _OidcClientSettings);\n\n    function UserManagerSettings() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            popup_redirect_uri = _ref.popup_redirect_uri,\n            popup_post_logout_redirect_uri = _ref.popup_post_logout_redirect_uri,\n            popupWindowFeatures = _ref.popupWindowFeatures,\n            popupWindowTarget = _ref.popupWindowTarget,\n            silent_redirect_uri = _ref.silent_redirect_uri,\n            silentRequestTimeout = _ref.silentRequestTimeout,\n            _ref$automaticSilentR = _ref.automaticSilentRenew,\n            automaticSilentRenew = _ref$automaticSilentR === undefined ? false : _ref$automaticSilentR,\n            _ref$validateSubOnSil = _ref.validateSubOnSilentRenew,\n            validateSubOnSilentRenew = _ref$validateSubOnSil === undefined ? false : _ref$validateSubOnSil,\n            _ref$includeIdTokenIn = _ref.includeIdTokenInSilentRenew,\n            includeIdTokenInSilentRenew = _ref$includeIdTokenIn === undefined ? true : _ref$includeIdTokenIn,\n            _ref$monitorSession = _ref.monitorSession,\n            monitorSession = _ref$monitorSession === undefined ? true : _ref$monitorSession,\n            _ref$monitorAnonymous = _ref.monitorAnonymousSession,\n            monitorAnonymousSession = _ref$monitorAnonymous === undefined ? false : _ref$monitorAnonymous,\n            _ref$checkSessionInte = _ref.checkSessionInterval,\n            checkSessionInterval = _ref$checkSessionInte === undefined ? DefaultCheckSessionInterval : _ref$checkSessionInte,\n            _ref$stopCheckSession = _ref.stopCheckSessionOnError,\n            stopCheckSessionOnError = _ref$stopCheckSession === undefined ? true : _ref$stopCheckSession,\n            query_status_response_type = _ref.query_status_response_type,\n            _ref$revokeAccessToke = _ref.revokeAccessTokenOnSignout,\n            revokeAccessTokenOnSignout = _ref$revokeAccessToke === undefined ? false : _ref$revokeAccessToke,\n            _ref$accessTokenExpir = _ref.accessTokenExpiringNotificationTime,\n            accessTokenExpiringNotificationTime = _ref$accessTokenExpir === undefined ? DefaultAccessTokenExpiringNotificationTime : _ref$accessTokenExpir,\n            _ref$redirectNavigato = _ref.redirectNavigator,\n            redirectNavigator = _ref$redirectNavigato === undefined ? new _RedirectNavigator.RedirectNavigator() : _ref$redirectNavigato,\n            _ref$popupNavigator = _ref.popupNavigator,\n            popupNavigator = _ref$popupNavigator === undefined ? new _PopupNavigator.PopupNavigator() : _ref$popupNavigator,\n            _ref$iframeNavigator = _ref.iframeNavigator,\n            iframeNavigator = _ref$iframeNavigator === undefined ? new _IFrameNavigator.IFrameNavigator() : _ref$iframeNavigator,\n            _ref$userStore = _ref.userStore,\n            userStore = _ref$userStore === undefined ? new _WebStorageStateStore.WebStorageStateStore({ store: _Global.Global.sessionStorage }) : _ref$userStore;\n\n        _classCallCheck(this, UserManagerSettings);\n\n        var _this = _possibleConstructorReturn(this, _OidcClientSettings.call(this, arguments[0]));\n\n        _this._popup_redirect_uri = popup_redirect_uri;\n        _this._popup_post_logout_redirect_uri = popup_post_logout_redirect_uri;\n        _this._popupWindowFeatures = popupWindowFeatures;\n        _this._popupWindowTarget = popupWindowTarget;\n\n        _this._silent_redirect_uri = silent_redirect_uri;\n        _this._silentRequestTimeout = silentRequestTimeout;\n        _this._automaticSilentRenew = automaticSilentRenew;\n        _this._validateSubOnSilentRenew = validateSubOnSilentRenew;\n        _this._includeIdTokenInSilentRenew = includeIdTokenInSilentRenew;\n        _this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\n\n        _this._monitorSession = monitorSession;\n        _this._monitorAnonymousSession = monitorAnonymousSession;\n        _this._checkSessionInterval = checkSessionInterval;\n        _this._stopCheckSessionOnError = stopCheckSessionOnError;\n        if (query_status_response_type) {\n            _this._query_status_response_type = query_status_response_type;\n        } else if (arguments[0] && arguments[0].response_type) {\n            _this._query_status_response_type = _SigninRequest.SigninRequest.isOidc(arguments[0].response_type) ? \"id_token\" : \"code\";\n        } else {\n            _this._query_status_response_type = \"id_token\";\n        }\n        _this._revokeAccessTokenOnSignout = revokeAccessTokenOnSignout;\n\n        _this._redirectNavigator = redirectNavigator;\n        _this._popupNavigator = popupNavigator;\n        _this._iframeNavigator = iframeNavigator;\n\n        _this._userStore = userStore;\n        return _this;\n    }\n\n    _createClass(UserManagerSettings, [{\n        key: 'popup_redirect_uri',\n        get: function get() {\n            return this._popup_redirect_uri;\n        }\n    }, {\n        key: 'popup_post_logout_redirect_uri',\n        get: function get() {\n            return this._popup_post_logout_redirect_uri;\n        }\n    }, {\n        key: 'popupWindowFeatures',\n        get: function get() {\n            return this._popupWindowFeatures;\n        }\n    }, {\n        key: 'popupWindowTarget',\n        get: function get() {\n            return this._popupWindowTarget;\n        }\n    }, {\n        key: 'silent_redirect_uri',\n        get: function get() {\n            return this._silent_redirect_uri;\n        }\n    }, {\n        key: 'silentRequestTimeout',\n        get: function get() {\n            return this._silentRequestTimeout;\n        }\n    }, {\n        key: 'automaticSilentRenew',\n        get: function get() {\n            return this._automaticSilentRenew;\n        }\n    }, {\n        key: 'validateSubOnSilentRenew',\n        get: function get() {\n            return this._validateSubOnSilentRenew;\n        }\n    }, {\n        key: 'includeIdTokenInSilentRenew',\n        get: function get() {\n            return this._includeIdTokenInSilentRenew;\n        }\n    }, {\n        key: 'accessTokenExpiringNotificationTime',\n        get: function get() {\n            return this._accessTokenExpiringNotificationTime;\n        }\n    }, {\n        key: 'monitorSession',\n        get: function get() {\n            return this._monitorSession;\n        }\n    }, {\n        key: 'monitorAnonymousSession',\n        get: function get() {\n            return this._monitorAnonymousSession;\n        }\n    }, {\n        key: 'checkSessionInterval',\n        get: function get() {\n            return this._checkSessionInterval;\n        }\n    }, {\n        key: 'stopCheckSessionOnError',\n        get: function get() {\n            return this._stopCheckSessionOnError;\n        }\n    }, {\n        key: 'query_status_response_type',\n        get: function get() {\n            return this._query_status_response_type;\n        }\n    }, {\n        key: 'revokeAccessTokenOnSignout',\n        get: function get() {\n            return this._revokeAccessTokenOnSignout;\n        }\n    }, {\n        key: 'redirectNavigator',\n        get: function get() {\n            return this._redirectNavigator;\n        }\n    }, {\n        key: 'popupNavigator',\n        get: function get() {\n            return this._popupNavigator;\n        }\n    }, {\n        key: 'iframeNavigator',\n        get: function get() {\n            return this._iframeNavigator;\n        }\n    }, {\n        key: 'userStore',\n        get: function get() {\n            return this._userStore;\n        }\n    }]);\n\n    return UserManagerSettings;\n}(_OidcClientSettings2.OidcClientSettings);\n\n/***/ }),\n\n/***/ \"./src/WebStorageStateStore.js\":\n/*!*************************************!*\\\n  !*** ./src/WebStorageStateStore.js ***!\n  \\*************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.WebStorageStateStore = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar WebStorageStateStore = exports.WebStorageStateStore = function () {\n    function WebStorageStateStore() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            _ref$prefix = _ref.prefix,\n            prefix = _ref$prefix === undefined ? \"oidc.\" : _ref$prefix,\n            _ref$store = _ref.store,\n            store = _ref$store === undefined ? _Global.Global.localStorage : _ref$store;\n\n        _classCallCheck(this, WebStorageStateStore);\n\n        this._store = store;\n        this._prefix = prefix;\n    }\n\n    WebStorageStateStore.prototype.set = function set(key, value) {\n        _Log.Log.debug(\"WebStorageStateStore.set\", key);\n\n        key = this._prefix + key;\n\n        this._store.setItem(key, value);\n\n        return Promise.resolve();\n    };\n\n    WebStorageStateStore.prototype.get = function get(key) {\n        _Log.Log.debug(\"WebStorageStateStore.get\", key);\n\n        key = this._prefix + key;\n\n        var item = this._store.getItem(key);\n\n        return Promise.resolve(item);\n    };\n\n    WebStorageStateStore.prototype.remove = function remove(key) {\n        _Log.Log.debug(\"WebStorageStateStore.remove\", key);\n\n        key = this._prefix + key;\n\n        var item = this._store.getItem(key);\n        this._store.removeItem(key);\n\n        return Promise.resolve(item);\n    };\n\n    WebStorageStateStore.prototype.getAllKeys = function getAllKeys() {\n        _Log.Log.debug(\"WebStorageStateStore.getAllKeys\");\n\n        var keys = [];\n\n        for (var index = 0; index < this._store.length; index++) {\n            var key = this._store.key(index);\n\n            if (key.indexOf(this._prefix) === 0) {\n                keys.push(key.substr(this._prefix.length));\n            }\n        }\n\n        return Promise.resolve(keys);\n    };\n\n    return WebStorageStateStore;\n}();\n\n/***/ }),\n\n/***/ \"./src/crypto/rsa.js\":\n/*!***************************!*\\\n  !*** ./src/crypto/rsa.js ***!\n  \\***************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.AllowedSigningAlgs = exports.b64tohex = exports.hextob64u = exports.crypto = exports.X509 = exports.KeyUtil = exports.jws = undefined;\n\nvar _jsbn = __webpack_require__(/*! jsbn */ \"./node_modules/jsbn/index.js\");\n\nvar _jsbn2 = _interopRequireDefault(_jsbn);\n\nvar _sha = __webpack_require__(/*! crypto-js/sha256 */ \"./node_modules/crypto-js/sha256.js\");\n\nvar _sha2 = _interopRequireDefault(_sha);\n\nvar _base64Js = __webpack_require__(/*! base64-js */ \"./node_modules/base64-js/index.js\");\n\nvar _base64Js2 = _interopRequireDefault(_base64Js);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nvar BigInteger = _jsbn2.default.BigInteger;\n\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\n/*\nBased on the work of Auth0\nhttps://github.com/auth0/idtoken-verifier\nhttps://github.com/auth0/idtoken-verifier/blob/master/LICENSE\nWhich is based on the work of Tom Wu\nhttp://www-cs-students.stanford.edu/~tjw/jsbn/\nhttp://www-cs-students.stanford.edu/~tjw/jsbn/LICENSE\n*/\n\n/*\n * To support most basic OpenId use cases (using RSA256), we can get away without\n * requiring the full jrsasign feature set (and resulting massive bundle).\n *\n * - Support RSA 256 algorithm (optionally could support RSA* family)\n * - Parse JWT tokens using the (n) parameter.\n * - Verify signature of id_tokens\n * - Verify at_hash of access_tokens\n * - Perform common base64 encoding/decoding tasks.\n */\n\nvar b64map = \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\";\nvar b64pad = \"=\";\n\nvar Base64 = {\n    b64tohex: function b64tohex(s) {\n        var ret = \"\";\n        var i;\n        var k = 0; // b64 state, 0-3\n        var slop;\n        for (i = 0; i < s.length; ++i) {\n            if (s.charAt(i) === b64pad) break;\n            var v = b64map.indexOf(s.charAt(i));\n            if (v < 0) continue;\n            if (k === 0) {\n                ret += String.fromCharCode(v >> 2);\n                slop = v & 3;\n                k = 1;\n            } else if (k === 1) {\n                ret += String.fromCharCode(slop << 2 | v >> 4);\n                slop = v & 0xf;\n                k = 2;\n            } else if (k === 2) {\n                ret += String.fromCharCode(slop);\n                ret += String.fromCharCode(v >> 2);\n                slop = v & 3;\n                k = 3;\n            } else {\n                ret += String.fromCharCode(slop << 2 | v >> 4);\n                ret += String.fromCharCode(v & 0xf);\n                k = 0;\n            }\n        }\n        if (k === 1) ret += String.fromCharCode(slop << 2);\n        return ret;\n    },\n    hexToBase64: function hexToBase64(h) {\n        var i;\n        var c;\n        var ret = \"\";\n        for (i = 0; i + 3 <= h.length; i += 3) {\n            c = parseInt(h.substring(i, i + 3), 16);\n            ret += b64map.charAt(c >> 6) + b64map.charAt(c & 63);\n        }\n        if (i + 1 === h.length) {\n            c = parseInt(h.substring(i, i + 1), 16);\n            ret += b64map.charAt(c << 2);\n        } else if (i + 2 === h.length) {\n            c = parseInt(h.substring(i, i + 2), 16);\n            ret += b64map.charAt(c >> 2) + b64map.charAt((c & 3) << 4);\n        }\n        if (b64pad) while ((ret.length & 3) > 0) {\n            ret += b64pad;\n        }return ret;\n    },\n    padding: function padding(str) {\n        var mod = str.length % 4;\n        var pad = 4 - mod;\n\n        if (mod === 0) {\n            return str;\n        }\n\n        return str + new Array(1 + pad).join('=');\n    },\n    byteArrayToHex: function byteArrayToHex(raw) {\n        var HEX = '';\n\n        for (var i = 0; i < raw.length; i++) {\n            var _hex = raw[i].toString(16);\n            HEX += _hex.length === 2 ? _hex : '0' + _hex;\n        }\n\n        return HEX;\n    },\n    decodeToHEX: function decodeToHEX(str) {\n        return Base64.byteArrayToHex(_base64Js2.default.toByteArray(Base64.padding(str)));\n    },\n    base64ToBase64Url: function base64ToBase64Url(s) {\n        s = s.replace(/=/g, \"\");\n        s = s.replace(/\\+/g, \"-\");\n        s = s.replace(/\\//g, \"_\");\n        return s;\n    },\n    urlDecode: function urlDecode(str) {\n        str = str.replace(/-/g, '+') // Convert '-' to '+'\n        .replace(/_/g, '/') // Convert '_' to '/'\n        .replace(/\\s/g, ' '); // Convert '\\s' to ' '\n\n        return atob(str);\n    }\n};\n\nvar DigestInfoHead = {\n    sha1: '3021300906052b0e03021a05000414',\n    sha224: '302d300d06096086480165030402040500041c',\n    sha256: '3031300d060960864801650304020105000420',\n    sha384: '3041300d060960864801650304020205000430',\n    sha512: '3051300d060960864801650304020305000440',\n    md2: '3020300c06082a864886f70d020205000410',\n    md5: '3020300c06082a864886f70d020505000410',\n    ripemd160: '3021300906052b2403020105000414'\n};\n\nvar DigestAlgs = {\n    sha256: _sha2.default,\n    SHA256: _sha2.default\n};\n\nfunction RSAVerifier(modulus, exp) {\n    this.n = null;\n    this.e = 0;\n\n    if (modulus != null && exp != null && modulus.length > 0 && exp.length > 0) {\n        this.n = new BigInteger(modulus, 16);\n        this.e = parseInt(exp, 16);\n    } else {\n        throw new Error('Invalid key data');\n    }\n}\n\nfunction getAlgorithmFromDigest(hDigestInfo) {\n    for (var algName in DigestInfoHead) {\n        var head = DigestInfoHead[algName];\n        var len = head.length;\n\n        if (hDigestInfo.substring(0, len) === head) {\n            return {\n                alg: algName,\n                hash: hDigestInfo.substring(len)\n            };\n        }\n    }\n    return [];\n}\n\nRSAVerifier.prototype.verify = function (msg, encsig) {\n    encsig = Base64.decodeToHEX(encsig);\n    encsig = encsig.replace(/[^0-9a-f]|[\\s\\n]]/ig, '');\n\n    var sig = new BigInteger(encsig, 16);\n\n    if (sig.bitLength() > this.n.bitLength()) {\n        throw new Error('Signature does not match with the key modulus.');\n    }\n\n    var decryptedSig = sig.modPowInt(this.e, this.n);\n    var digest = decryptedSig.toString(16).replace(/^1f+00/, '');\n    var digestInfo = getAlgorithmFromDigest(digest);\n\n    if (digestInfo.length === 0) {\n        return false;\n    }\n\n    if (!DigestAlgs.hasOwnProperty(digestInfo.alg)) {\n        throw new Error('Hashing algorithm is not supported.');\n    }\n\n    var msgHash = DigestAlgs[digestInfo.alg](msg).toString();\n    return digestInfo.hash === msgHash;\n};\n\nvar AllowedSigningAlgs = ['RS256'];\n\nvar jws = {\n    JWS: {\n        parse: function parse(token) {\n            var parts = token.split('.');\n            var header;\n            var payload;\n\n            // This diverges from Auth0's implementation, which throws rather than\n            // returning undefined\n            if (parts.length !== 3) {\n                return undefined;\n            }\n\n            try {\n                header = JSON.parse(Base64.urlDecode(parts[0]));\n                payload = JSON.parse(Base64.urlDecode(parts[1]));\n            } catch (e) {\n                return new Error('Token header or payload is not valid JSON');\n            }\n\n            return {\n                headerObj: header,\n                payloadObj: payload\n            };\n        },\n        verify: function verify(jwt, key) {\n            var allowedSigningAlgs = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : [];\n\n            allowedSigningAlgs.forEach(function (alg) {\n                if (AllowedSigningAlgs.indexOf(alg) === -1) {\n                    throw new Error('Invalid signing algorithm: ' + alg);\n                }\n            });\n            var verify = new RSAVerifier(key.n, key.e);\n            var parts = jwt.split('.');\n\n            var headerAndPayload = [parts[0], parts[1]].join('.');\n            return verify.verify(headerAndPayload, parts[2]);\n        }\n    }\n};\n\nvar KeyUtil = {\n    /**\n     * Returns decoded keys in Hex format for use in crypto functions.\n     * Supports modulus/exponent-style keys.\n     *\n     * @param {object} key the security key\n     * @returns\n     */\n    getKey: function getKey(key) {\n        if (key.kty === 'RSA') {\n            return {\n                e: Base64.decodeToHEX(key.e),\n                n: Base64.decodeToHEX(key.n)\n            };\n        }\n\n        return null;\n    }\n};\n\nvar X509 = {\n    getPublicKeyFromCertPEM: function getPublicKeyFromCertPEM() {\n        throw new Error('Not implemented. Use the full oidc-client library if you need support for X509.');\n    }\n};\n\nvar crypto = {\n    Util: {\n        hashString: function hashString(value, alg) {\n            var hashFunc = DigestAlgs[alg];\n            return hashFunc(value).toString();\n        }\n    }\n};\n\nfunction hextob64u(s) {\n    if (s.length % 2 === 1) {\n        s = '0' + s;\n    }\n    return Base64.base64ToBase64Url(Base64.hexToBase64(s));\n}\n\nvar b64tohex = Base64.b64tohex;\nexports.jws = jws;\nexports.KeyUtil = KeyUtil;\nexports.X509 = X509;\nexports.crypto = crypto;\nexports.hextob64u = hextob64u;\nexports.b64tohex = b64tohex;\nexports.AllowedSigningAlgs = AllowedSigningAlgs;\n\n/***/ }),\n\n/***/ \"./src/random.js\":\n/*!***********************!*\\\n  !*** ./src/random.js ***!\n  \\***********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nexports.default = random;\n\nvar _v = __webpack_require__(/*! uuid/v4 */ \"./node_modules/uuid/v4.js\");\n\nvar _v2 = _interopRequireDefault(_v);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\n/**\n * Generates RFC4122 version 4 guid ()\n */\n\nfunction random() {\n  return (0, _v2.default)().replace(/-/g, '');\n}\nmodule.exports = exports['default'];\n\n/***/ }),\n\n/***/ \"./version.js\":\n/*!********************!*\\\n  !*** ./version.js ***!\n  \\********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nvar Version = \"1.10.1\";exports.Version = Version;\n\n/***/ }),\n\n/***/ 0:\n/*!***************************************!*\\\n  !*** multi ./polyfills.js ./index.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./polyfills.js */\"./polyfills.js\");\nmodule.exports = __webpack_require__(/*! ./index.js */\"./index.js\");\n\n\n/***/ })\n\n/******/ });\n//# sourceMappingURL=data:application/json;charset=utf-8;base64,{"version":3,"sources":["webpack://Oidc/webpack/bootstrap","webpack://Oidc/./index.js","webpack://Oidc/./node_modules/base64-js/index.js","webpack://Oidc/./node_modules/core-js/es6/promise.js","webpack://Oidc/./node_modules/core-js/fn/array/find.js","webpack://Oidc/./node_modules/core-js/fn/array/is-array.js","webpack://Oidc/./node_modules/core-js/fn/array/some.js","webpack://Oidc/./node_modules/core-js/fn/array/splice.js","webpack://Oidc/./node_modules/core-js/fn/function/bind.js","webpack://Oidc/./node_modules/core-js/fn/object/assign.js","webpack://Oidc/./node_modules/core-js/modules/_a-function.js","webpack://Oidc/./node_modules/core-js/modules/_add-to-unscopables.js","webpack://Oidc/./node_modules/core-js/modules/_an-instance.js","webpack://Oidc/./node_modules/core-js/modules/_an-object.js","webpack://Oidc/./node_modules/core-js/modules/_array-includes.js","webpack://Oidc/./node_modules/core-js/modules/_array-methods.js","webpack://Oidc/./node_modules/core-js/modules/_array-species-constructor.js","webpack://Oidc/./node_modules/core-js/modules/_array-species-create.js","webpack://Oidc/./node_modules/core-js/modules/_bind.js","webpack://Oidc/./node_modules/core-js/modules/_classof.js","webpack://Oidc/./node_modules/core-js/modules/_cof.js","webpack://Oidc/./node_modules/core-js/modules/_core.js","webpack://Oidc/./node_modules/core-js/modules/_ctx.js","webpack://Oidc/./node_modules/core-js/modules/_defined.js","webpack://Oidc/./node_modules/core-js/modules/_descriptors.js","webpack://Oidc/./node_modules/core-js/modules/_dom-create.js","webpack://Oidc/./node_modules/core-js/modules/_enum-bug-keys.js","webpack://Oidc/./node_modules/core-js/modules/_export.js","webpack://Oidc/./node_modules/core-js/modules/_fails.js","webpack://Oidc/./node_modules/core-js/modules/_for-of.js","webpack://Oidc/./node_modules/core-js/modules/_function-to-string.js","webpack://Oidc/./node_modules/core-js/modules/_global.js","webpack://Oidc/./node_modules/core-js/modules/_has.js","webpack://Oidc/./node_modules/core-js/modules/_hide.js","webpack://Oidc/./node_modules/core-js/modules/_html.js","webpack://Oidc/./node_modules/core-js/modules/_ie8-dom-define.js","webpack://Oidc/./node_modules/core-js/modules/_invoke.js","webpack://Oidc/./node_modules/core-js/modules/_iobject.js","webpack://Oidc/./node_modules/core-js/modules/_is-array-iter.js","webpack://Oidc/./node_modules/core-js/modules/_is-array.js","webpack://Oidc/./node_modules/core-js/modules/_is-object.js","webpack://Oidc/./node_modules/core-js/modules/_iter-call.js","webpack://Oidc/./node_modules/core-js/modules/_iter-create.js","webpack://Oidc/./node_modules/core-js/modules/_iter-define.js","webpack://Oidc/./node_modules/core-js/modules/_iter-detect.js","webpack://Oidc/./node_modules/core-js/modules/_iter-step.js","webpack://Oidc/./node_modules/core-js/modules/_iterators.js","webpack://Oidc/./node_modules/core-js/modules/_library.js","webpack://Oidc/./node_modules/core-js/modules/_microtask.js","webpack://Oidc/./node_modules/core-js/modules/_new-promise-capability.js","webpack://Oidc/./node_modules/core-js/modules/_object-assign.js","webpack://Oidc/./node_modules/core-js/modules/_object-create.js","webpack://Oidc/./node_modules/core-js/modules/_object-dp.js","webpack://Oidc/./node_modules/core-js/modules/_object-dps.js","webpack://Oidc/./node_modules/core-js/modules/_object-gops.js","webpack://Oidc/./node_modules/core-js/modules/_object-gpo.js","webpack://Oidc/./node_modules/core-js/modules/_object-keys-internal.js","webpack://Oidc/./node_modules/core-js/modules/_object-keys.js","webpack://Oidc/./node_modules/core-js/modules/_object-pie.js","webpack://Oidc/./node_modules/core-js/modules/_perform.js","webpack://Oidc/./node_modules/core-js/modules/_promise-resolve.js","webpack://Oidc/./node_modules/core-js/modules/_property-desc.js","webpack://Oidc/./node_modules/core-js/modules/_redefine-all.js","webpack://Oidc/./node_modules/core-js/modules/_redefine.js","webpack://Oidc/./node_modules/core-js/modules/_set-species.js","webpack://Oidc/./node_modules/core-js/modules/_set-to-string-tag.js","webpack://Oidc/./node_modules/core-js/modules/_shared-key.js","webpack://Oidc/./node_modules/core-js/modules/_shared.js","webpack://Oidc/./node_modules/core-js/modules/_species-constructor.js","webpack://Oidc/./node_modules/core-js/modules/_strict-method.js","webpack://Oidc/./node_modules/core-js/modules/_string-at.js","webpack://Oidc/./node_modules/core-js/modules/_task.js","webpack://Oidc/./node_modules/core-js/modules/_to-absolute-index.js","webpack://Oidc/./node_modules/core-js/modules/_to-integer.js","webpack://Oidc/./node_modules/core-js/modules/_to-iobject.js","webpack://Oidc/./node_modules/core-js/modules/_to-length.js","webpack://Oidc/./node_modules/core-js/modules/_to-object.js","webpack://Oidc/./node_modules/core-js/modules/_to-primitive.js","webpack://Oidc/./node_modules/core-js/modules/_uid.js","webpack://Oidc/./node_modules/core-js/modules/_user-agent.js","webpack://Oidc/./node_modules/core-js/modules/_wks.js","webpack://Oidc/./node_modules/core-js/modules/core.get-iterator-method.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.find.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.is-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.iterator.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.some.js","webpack://Oidc/./node_modules/core-js/modules/es6.function.bind.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.assign.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.to-string.js","webpack://Oidc/./node_modules/core-js/modules/es6.promise.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.iterator.js","webpack://Oidc/./node_modules/core-js/modules/web.dom.iterable.js","webpack://Oidc/./node_modules/crypto-js/core.js","webpack://Oidc/./node_modules/crypto-js/sha256.js","webpack://Oidc/./node_modules/jsbn/index.js","webpack://Oidc/./node_modules/uuid/lib/bytesToUuid.js","webpack://Oidc/./node_modules/uuid/lib/rng-browser.js","webpack://Oidc/./node_modules/uuid/v4.js","webpack://Oidc/./polyfills.js","webpack://Oidc/./src/AccessTokenEvents.js","webpack://Oidc/./src/CheckSessionIFrame.js","webpack://Oidc/./src/CordovaIFrameNavigator.js","webpack://Oidc/./src/CordovaPopupNavigator.js","webpack://Oidc/./src/CordovaPopupWindow.js","webpack://Oidc/./src/ErrorResponse.js","webpack://Oidc/./src/Event.js","webpack://Oidc/./src/Global.js","webpack://Oidc/./src/IFrameNavigator.js","webpack://Oidc/./src/IFrameWindow.js","webpack://Oidc/./src/InMemoryWebStorage.js","webpack://Oidc/./src/JoseUtilImpl.js","webpack://Oidc/./src/JoseUtilRsa.js","webpack://Oidc/./src/JsonService.js","webpack://Oidc/./src/Log.js","webpack://Oidc/./src/MetadataService.js","webpack://Oidc/./src/OidcClient.js","webpack://Oidc/./src/OidcClientSettings.js","webpack://Oidc/./src/PopupNavigator.js","webpack://Oidc/./src/PopupWindow.js","webpack://Oidc/./src/RedirectNavigator.js","webpack://Oidc/./src/ResponseValidator.js","webpack://Oidc/./src/SessionMonitor.js","webpack://Oidc/./src/SigninRequest.js","webpack://Oidc/./src/SigninResponse.js","webpack://Oidc/./src/SigninState.js","webpack://Oidc/./src/SignoutRequest.js","webpack://Oidc/./src/SignoutResponse.js","webpack://Oidc/./src/SilentRenewService.js","webpack://Oidc/./src/State.js","webpack://Oidc/./src/Timer.js","webpack://Oidc/./src/TokenClient.js","webpack://Oidc/./src/TokenRevocationClient.js","webpack://Oidc/./src/UrlUtility.js","webpack://Oidc/./src/User.js","webpack://Oidc/./src/UserInfoService.js","webpack://Oidc/./src/UserManager.js","webpack://Oidc/./src/UserManagerEvents.js","webpack://Oidc/./src/UserManagerSettings.js","webpack://Oidc/./src/WebStorageStateStore.js","webpack://Oidc/./src/crypto/rsa.js","webpack://Oidc/./src/random.js","webpack://Oidc/./version.js"],"names":["Version","Log","OidcClient","OidcClientSettings","WebStorageStateStore","InMemoryWebStorage","UserManager","AccessTokenEvents","MetadataService","CordovaPopupNavigator","CordovaIFrameNavigator","CheckSessionIFrame","TokenRevocationClient","SessionMonitor","Global","User","DefaultAccessTokenExpiringNotificationTime","accessTokenExpiringNotificationTime","accessTokenExpiringTimer","Timer","accessTokenExpiredTimer","_accessTokenExpiringNotificationTime","_accessTokenExpiring","_accessTokenExpired","load","container","access_token","expires_in","undefined","duration","debug","expiring","init","cancel","expired","unload","addAccessTokenExpiring","cb","addHandler","removeAccessTokenExpiring","removeHandler","addAccessTokenExpired","removeAccessTokenExpired","DefaultInterval","callback","client_id","url","interval","stopOnError","_callback","_client_id","_url","_interval","_stopOnError","idx","indexOf","_frame_origin","substr","_frame","window","document","createElement","style","visibility","position","display","width","height","src","Promise","resolve","onload","body","appendChild","_boundMessageEvent","_message","bind","addEventListener","e","origin","source","contentWindow","data","error","stop","start","session_state","_session_state","send","postMessage","_timer","setInterval","clearInterval","prepare","params","popupWindowFeatures","popup","CordovaPopupWindow","DefaultPopupFeatures","DefaultPopupTarget","_promise","reject","_resolve","_reject","features","target","popupWindowTarget","redirect_uri","startUrl","_isInAppBrowserInstalled","cordovaMetadata","some","name","hasOwnProperty","navigate","_error","cordova","require","metadata","_popup","InAppBrowser","open","_exitCallbackEvent","_exitCallback","_loadStartCallbackEvent","_loadStartCallback","promise","event","_success","message","_cleanup","Error","close","removeEventListener","ErrorResponse","error_description","error_uri","state","Event","_name","_callbacks","push","findIndex","item","splice","raise","i","length","timer","handle","testing","request","_testing","setXMLHttpRequest","newRequest","location","localStorage","sessionStorage","XMLHttpRequest","IFrameNavigator","frame","IFrameWindow","notifyParent","DefaultTimeout","timeout","silentRequestTimeout","setTimeout","_timeout","clearTimeout","removeChild","_origin","frameElement","href","parent","protocol","host","_data","getItem","key","setItem","value","removeItem","index","Object","getOwnPropertyNames","getJoseUtil","jws","KeyUtil","X509","crypto","hextob64u","b64tohex","AllowedSigningAlgs","parseJwt","jwt","token","JWS","parse","header","headerObj","payload","payloadObj","validateJwt","issuer","audience","clockSkew","now","timeInsensitive","kty","n","getKey","x5c","hex","getPublicKeyFromCertHex","crv","x","y","JoseUtil","_validateJwt","validateJwtAttributes","parseInt","Date","iss","aud","validAudience","Array","isArray","azp","lowerNow","upperNow","iat","nbf","exp","then","verify","hashString","alg","Util","hexToBase64Url","JsonService","additionalContentTypes","XMLHttpRequestCtor","jwtHandler","_contentTypes","slice","_XMLHttpRequest","_jwtHandler","getJson","req","allowedContentTypes","status","contentType","getResponseHeader","found","find","startsWith","JSON","responseText","statusText","onerror","setRequestHeader","postForm","encodeURIComponent","nopLogger","info","warn","NONE","ERROR","WARN","INFO","DEBUG","logger","level","reset","args","apply","from","OidcMetadataUrlPath","settings","JsonServiceCtor","_settings","_jsonService","getMetadata","metadataUrl","getIssuer","_getMetadataProperty","getAuthorizationEndpoint","getUserInfoEndpoint","getTokenEndpoint","optional","getCheckSessionIframe","getEndSessionEndpoint","getRevocationEndpoint","getKeysEndpoint","getSigningKeys","signingKeys","jwks_uri","keySet","keys","_metadataUrl","authority","createSigninRequest","response_type","scope","prompt","max_age","ui_locales","id_token_hint","login_hint","acr_values","resource","request_uri","response_mode","extraQueryParams","extraTokenParams","request_type","skipUserInfo","stateStore","SigninRequest","isCode","_metadataService","signinRequest","client_secret","signinState","_stateStore","set","id","toStorageString","readSigninResponseState","removeState","useQuery","delimiter","response","SigninResponse","stateApi","remove","get","storedStateString","SigninState","fromStorageString","processSigninResponse","_validator","validateSigninResponse","createSignoutRequest","post_logout_redirect_uri","SignoutRequest","signoutState","readSignoutResponseState","SignoutResponse","stateKey","State","processSignoutResponse","validateSignoutResponse","clearStaleState","staleStateAge","validator","metadataService","DefaultResponseType","DefaultScope","DefaultStaleStateAge","DefaultClockSkewInSeconds","filterProtocolClaims","loadUserInfo","userInfoJwtIssuer","ResponseValidatorCtor","ResponseValidator","MetadataServiceCtor","_authority","_metadata","_signingKeys","_client_secret","_response_type","_scope","_redirect_uri","_post_logout_redirect_uri","_prompt","_display","_max_age","_ui_locales","_acr_values","_resource","_response_mode","_filterProtocolClaims","_loadUserInfo","_staleStateAge","_clockSkew","_userInfoJwtIssuer","_extraQueryParams","_extraTokenParams","PopupNavigator","PopupWindow","keepOpen","notifyOpener","CheckForPopupClosedInterval","_checkForPopupClosedTimer","_checkForPopupClosed","_id","focus","closed","opener","UrlUtility","parseUrlFragment","RedirectNavigator","useReplaceToNavigate","replace","ProtocolClaims","UserInfoServiceCtor","UserInfoService","joseUtil","TokenClientCtor","TokenClient","_userInfoService","_joseUtil","_tokenClient","_processSigninParams","_validateTokens","_processClaims","nonce","id_token","code_verifier","code","isOpenIdConnect","profile","getClaims","claims","sub","_mergeClaims","claims1","claims2","result","assign","values","forEach","type","_processCode","_validateIdTokenAndAccessToken","_validateIdToken","exchangeCode","tokenResponse","_validateIdTokenAttributes","clockSkewInSeconds","_validateAccessToken","kid","_filterByAlg","filter","at_hash","hashAlg","hashBits","sha","hash","left","left_b64u","userManager","CheckSessionIFrameCtor","_userManager","_CheckSessionIFrameCtor","events","addUserLoaded","_start","addUserUnloaded","_stop","getUser","user","monitorAnonymousSession","querySessionStatus","tmpUser","session","sid","catch","err","_sub","_sid","_checkSessionIFrame","_checkSessionInterval","_stopCheckSessionOnError","timerHandle","raiseEvent","_raiseUserSessionChanged","_raiseUserSignedOut","_raiseUserSignedIn","checkSessionInterval","stopCheckSessionOnError","oidc","isOidc","addQueryParam","code_challenge","split","isOAuth","OidcScope","token_type","expires_at","scopes","arguments","_nonce","_code_verifier","_code_challenge","_skipUserInfo","stringify","created","storageString","SilentRenewService","_tokenExpiring","signinSilent","_raiseSilentRenewError","_created","_request_type","storage","age","cutoff","getAllKeys","promises","p","all","TimerDuration","nowFunc","_nowFunc","expiration","_timerHandle","_expiration","timerDuration","diff","grant_type","exchangeRefreshToken","refresh_token","AccessTokenTypeHint","RefreshTokenTypeHint","_XMLHttpRequestCtor","revoke","required","_revoke","xhr","global","lastIndexOf","regex","m","counter","exec","decodeURIComponent","prop","_getClaimsFromJwt","issuerPromise","SilentRenewServiceCtor","SessionMonitorCtor","TokenRevocationClientCtor","UserManagerSettings","_events","UserManagerEvents","_silentRenewService","automaticSilentRenew","startSilentRenew","monitorSession","_sessionMonitor","_tokenRevocationClient","_loadUser","removeUser","storeUser","signinRedirect","navParams","_signinStart","_redirectNavigator","signinRedirectCallback","_signinEnd","signinPopup","popup_redirect_uri","_signin","_popupNavigator","signinPopupCallback","_signinCallback","_useRefreshToken","includeIdTokenInSilentRenew","validateSubOnSilentRenew","current_sub","_signinSilentIframe","idTokenValidation","_validateIdTokenFromTokenRefreshToken","auth_time","silent_redirect_uri","_iframeNavigator","signinSilentCallback","signinCallback","signoutCallback","signoutRedirectCallback","signoutPopupCallback","query_status_response_type","navResponse","signinResponse","navigator","navigatorParams","signoutRedirect","postLogoutRedirectUri","_signoutStart","_signoutEnd","signoutPopup","popup_post_logout_redirect_uri","_signout","revokePromise","revokeAccessTokenOnSignout","_revokeInternal","signoutRequest","signoutResponse","revokeAccessToken","success","_revokeAccessTokenInternal","_revokeRefreshTokenInternal","atSuccess","rtSuccess","stopSilentRenew","_userStore","_userStoreKey","redirectNavigator","popupNavigator","iframeNavigator","userStore","_userLoaded","_userUnloaded","_silentRenewError","_userSignedIn","_userSignedOut","_userSessionChanged","removeUserLoaded","removeUserUnloaded","addSilentRenewError","removeSilentRenewError","addUserSignedIn","removeUserSignedIn","addUserSignedOut","removeUserSignedOut","addUserSessionChanged","removeUserSessionChanged","DefaultCheckSessionInterval","store","_popup_redirect_uri","_popup_post_logout_redirect_uri","_popupWindowFeatures","_popupWindowTarget","_silent_redirect_uri","_silentRequestTimeout","_automaticSilentRenew","_validateSubOnSilentRenew","_includeIdTokenInSilentRenew","_monitorSession","_monitorAnonymousSession","_query_status_response_type","_revokeAccessTokenOnSignout","prefix","_store","_prefix","BigInteger","JSBN","b64map","b64pad","Base64","s","ret","k","slop","charAt","v","String","fromCharCode","hexToBase64","h","c","substring","padding","str","mod","pad","join","byteArrayToHex","raw","HEX","_hex","toString","decodeToHEX","base64Js","toByteArray","base64ToBase64Url","urlDecode","atob","DigestInfoHead","sha1","sha224","sha256","sha384","sha512","md2","md5","ripemd160","DigestAlgs","SHA256","RSAVerifier","modulus","getAlgorithmFromDigest","hDigestInfo","algName","head","len","prototype","msg","encsig","sig","bitLength","decryptedSig","modPowInt","digest","digestInfo","msgHash","parts","allowedSigningAlgs","headerAndPayload","getPublicKeyFromCertPEM","hashFunc","random"],"mappings":";;AAAA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;;AAGA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA,kDAA0C,gCAAgC;AAC1E;AACA;;AAEA;AACA;AACA;AACA,gEAAwD,kBAAkB;AAC1E;AACA,yDAAiD,cAAc;AAC/D;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,iDAAyC,iCAAiC;AAC1E,wHAAgH,mBAAmB,EAAE;AACrI;AACA;;AAEA;AACA;AACA;AACA,mCAA2B,0BAA0B,EAAE;AACvD,yCAAiC,eAAe;AAChD;AACA;AACA;;AAEA;AACA,8DAAsD,+DAA+D;;AAErH;AACA;;;AAGA;AACA;;;;;;;;;;;;;;;;;;;AC/EA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AAEA;;AAnBA;AACA;;kBAoBe;AACXA,6BADW;AAEXC,iBAFW;AAGXC,sCAHW;AAIXC,8DAJW;AAKXC,oEALW;AAMXC,8DANW;AAOXC,yCAPW;AAQXC,2DARW;AASXC,qDATW;AAUXC,uEAVW;AAWXC,0EAXW;AAYXC,8DAZW;AAaXC,uEAbW;AAcXC,kDAdW;AAeXC,0BAfW;AAgBXC;AAhBW,C;;;;;;;;;;;;;ACrBH;;AAEZ;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,kCAAkC,SAAS;AAC3C;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;;AAEA;AACA;AACA;AACA;;AAEA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,0CAA0C,UAAU;AACpD;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;;;;;;;;;;;ACtJA,mBAAO,CAAC,+FAAiC;AACzC,mBAAO,CAAC,6FAAgC;AACxC,mBAAO,CAAC,uFAA6B;AACrC,mBAAO,CAAC,6EAAwB;AAChC,iBAAiB,mBAAO,CAAC,iEAAkB;;;;;;;;;;;;ACJ3C,mBAAO,CAAC,sFAA8B;AACtC,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C,mBAAO,CAAC,8FAAkC;AAC1C,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C,mBAAO,CAAC,sFAA8B;AACtC,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C;AACA;AACA;AACA;;;;;;;;;;;;ACHA,mBAAO,CAAC,4FAAiC;AACzC,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C,mBAAO,CAAC,4FAAiC;AACzC,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C;AACA;AACA;AACA;;;;;;;;;;;;ACHA;AACA,kBAAkB,mBAAO,CAAC,sDAAQ;AAClC;AACA,0CAA0C,mBAAO,CAAC,wDAAS,6BAA6B;AACxF;AACA;AACA;;;;;;;;;;;;ACNA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACJA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;;;;;;;;;;;;ACJA;AACA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK,YAAY,eAAe;AAChC;AACA,KAAK;AACL;AACA;;;;;;;;;;;;ACtBA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,wFAAyB;AAC3C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,eAAe;AACzB;AACA;AACA;AACA,wCAAwC;AACxC;AACA,8BAA8B;AAC9B,6BAA6B;AAC7B,+BAA+B;AAC/B,mCAAmC;AACnC,SAAS,iCAAiC;AAC1C;AACA;AACA;AACA;AACA;;;;;;;;;;;;AC3CA,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,gEAAa;AACnC,cAAc,mBAAO,CAAC,sDAAQ;;AAE9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACfA;AACA,yBAAyB,mBAAO,CAAC,kGAA8B;;AAE/D;AACA;AACA;;;;;;;;;;;;;ACLa;AACb,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA;;AAEA;AACA;AACA,2BAA2B,SAAS;AACpC;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACxBA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA,2BAA2B,kBAAkB,EAAE;;AAE/C;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACtBA,iBAAiB;;AAEjB;AACA;AACA;;;;;;;;;;;;ACJA,6BAA6B;AAC7B,uCAAuC;;;;;;;;;;;;ACDvC;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACnBA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACJA;AACA,kBAAkB,mBAAO,CAAC,0DAAU;AACpC,iCAAiC,QAAQ,mBAAmB,UAAU,EAAE,EAAE;AAC1E,CAAC;;;;;;;;;;;;ACHD,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,4DAAW;AAClC;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACNA;AACA;AACA;AACA;;;;;;;;;;;;ACHA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,WAAW,mBAAO,CAAC,wDAAS;AAC5B,eAAe,mBAAO,CAAC,gEAAa;AACpC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,kFAAkF,uBAAuB;AACzG,iEAAiE;AACjE,+DAA+D;AAC/D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,cAAc;AACd,cAAc;AACd,cAAc;AACd,cAAc;AACd,eAAe;AACf,eAAe;AACf,eAAe;AACf,gBAAgB;AAChB;;;;;;;;;;;;AC1CA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;;;;;;;;;;;ACNA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,WAAW,mBAAO,CAAC,kEAAc;AACjC,kBAAkB,mBAAO,CAAC,0EAAkB;AAC5C,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,8FAA4B;AACpD;AACA;AACA;AACA,uCAAuC,iBAAiB,EAAE;AAC1D;AACA;AACA;AACA;AACA;AACA,mEAAmE,gBAAgB;AACnF;AACA;AACA,GAAG,4CAA4C,gCAAgC;AAC/E;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACxBA,iBAAiB,mBAAO,CAAC,4DAAW;;;;;;;;;;;;ACApC;AACA;AACA;AACA;AACA;AACA,yCAAyC;;;;;;;;;;;;ACLzC,uBAAuB;AACvB;AACA;AACA;;;;;;;;;;;;ACHA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC;AACA,CAAC;AACD;AACA;AACA;;;;;;;;;;;;ACPA,eAAe,mBAAO,CAAC,4DAAW;AAClC;;;;;;;;;;;;ACDA,kBAAkB,mBAAO,CAAC,sEAAgB,MAAM,mBAAO,CAAC,0DAAU;AAClE,+BAA+B,mBAAO,CAAC,oEAAe,gBAAgB,mBAAmB,UAAU,EAAE,EAAE;AACvG,CAAC;;;;;;;;;;;;ACFD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACfA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;AACA;;;;;;;;;;;;ACLA;AACA,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,eAAe,mBAAO,CAAC,sDAAQ;AAC/B;;AAEA;AACA;AACA;;;;;;;;;;;;ACPA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;;;;;;;;;;;ACJA;AACA;AACA;;;;;;;;;;;;ACFA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACXa;AACb,aAAa,mBAAO,CAAC,0EAAkB;AACvC,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD;;AAEA;AACA,mBAAO,CAAC,wDAAS,qBAAqB,mBAAO,CAAC,sDAAQ,4BAA4B,aAAa,EAAE;;AAEjG;AACA,qDAAqD,4BAA4B;AACjF;AACA;;;;;;;;;;;;;ACZa;AACb,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,gEAAa;AACpC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,eAAe,mBAAO,CAAC,sDAAQ;AAC/B,8CAA8C;AAC9C;AACA;AACA;;AAEA,8BAA8B,aAAa;;AAE3C;AACA;AACA;AACA;AACA;AACA,yCAAyC,oCAAoC;AAC7E,6CAA6C,oCAAoC;AACjF,KAAK,4BAA4B,oCAAoC;AACrE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,gBAAgB,mBAAmB;AACnC;AACA;AACA,kCAAkC,2BAA2B;AAC7D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;;;;;;;;;;;;ACpEA,eAAe,mBAAO,CAAC,sDAAQ;AAC/B;;AAEA;AACA;AACA,iCAAiC,qBAAqB;AACtD;AACA,iCAAiC,SAAS,EAAE;AAC5C,CAAC,YAAY;;AAEb;AACA;AACA;AACA;AACA;AACA;AACA,6BAA6B,SAAS,qBAAqB;AAC3D,iCAAiC,aAAa;AAC9C;AACA,GAAG,YAAY;AACf;AACA;;;;;;;;;;;;ACrBA;AACA,UAAU;AACV;;;;;;;;;;;;ACFA;;;;;;;;;;;;ACAA;;;;;;;;;;;;ACAA,aAAa,mBAAO,CAAC,4DAAW;AAChC,gBAAgB,mBAAO,CAAC,wDAAS;AACjC;AACA;AACA;AACA,aAAa,mBAAO,CAAC,sDAAQ;;AAE7B;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,uCAAuC,sBAAsB,EAAE;AAC/D;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA,gBAAgB;AAChB;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;;;;;;;;;;;;ACpEa;AACb;AACA,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;ACjBa;AACb;AACA,cAAc,mBAAO,CAAC,sEAAgB;AACtC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,UAAU,mBAAO,CAAC,oEAAe;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,8DAAY;AAClC;;AAEA;AACA,6BAA6B,mBAAO,CAAC,0DAAU;AAC/C;AACA;AACA;AACA;AACA;AACA;AACA,oCAAoC,UAAU,EAAE;AAChD,mBAAmB,sCAAsC;AACzD,CAAC,qCAAqC;AACtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH,CAAC;;;;;;;;;;;;ACjCD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,oEAAe;AACjC,kBAAkB,mBAAO,CAAC,0EAAkB;AAC5C,eAAe,mBAAO,CAAC,oEAAe;AACtC,yBAAyB;AACzB;;AAEA;AACA;AACA;AACA,eAAe,mBAAO,CAAC,oEAAe;AACtC;AACA;AACA;AACA;AACA;AACA,EAAE,mBAAO,CAAC,wDAAS;AACnB,6BAA6B;AAC7B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;;;;;;;;;;;;ACxCA,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,4EAAmB;AAChD,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C;;AAEA,YAAY,mBAAO,CAAC,sEAAgB;AACpC;AACA;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf;AACA;AACA;AACA;;;;;;;;;;;;ACfA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,sEAAgB;;AAEtC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACZA;;;;;;;;;;;;ACAA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,oEAAe;AACtC;;AAEA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACZA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,mBAAmB,mBAAO,CAAC,4EAAmB;AAC9C,eAAe,mBAAO,CAAC,oEAAe;;AAEtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AChBA;AACA,YAAY,mBAAO,CAAC,wFAAyB;AAC7C,kBAAkB,mBAAO,CAAC,0EAAkB;;AAE5C;AACA;AACA;;;;;;;;;;;;ACNA,cAAc;;;;;;;;;;;;ACAd;AACA;AACA,YAAY;AACZ,GAAG;AACH,YAAY;AACZ;AACA;;;;;;;;;;;;ACNA,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,2BAA2B,mBAAO,CAAC,4FAA2B;;AAE9D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACXA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACPA,eAAe,mBAAO,CAAC,gEAAa;AACpC;AACA;AACA;AACA;;;;;;;;;;;;ACJA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,gBAAgB,mBAAO,CAAC,oFAAuB;AAC/C;AACA;;AAEA,mBAAO,CAAC,wDAAS;AACjB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA;AACA,CAAC;AACD;AACA,CAAC;;;;;;;;;;;;;AC9BY;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,SAAS,mBAAO,CAAC,kEAAc;AAC/B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,cAAc,mBAAO,CAAC,sDAAQ;;AAE9B;AACA;AACA;AACA;AACA,sBAAsB,aAAa;AACnC,GAAG;AACH;;;;;;;;;;;;ACZA,UAAU,mBAAO,CAAC,kEAAc;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;;AAE1B;AACA,oEAAoE,iCAAiC;AACrG;;;;;;;;;;;;ACNA,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;;;;;;;;;;;ACJA,WAAW,mBAAO,CAAC,wDAAS;AAC5B,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA,kDAAkD;;AAElD;AACA,qEAAqE;AACrE,CAAC;AACD;AACA,QAAQ,mBAAO,CAAC,8DAAY;AAC5B;AACA,CAAC;;;;;;;;;;;;ACXD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,cAAc,mBAAO,CAAC,sDAAQ;AAC9B;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACRa;AACb,YAAY,mBAAO,CAAC,0DAAU;;AAE9B;AACA;AACA;AACA,yCAAyC,cAAc;AACvD,GAAG;AACH;;;;;;;;;;;;ACRA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AChBA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,oEAAe;AACjC,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,MAAM,mBAAO,CAAC,sDAAQ;AACtB;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACnFA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACNA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACLA;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;;;;;;;;;;;;ACLA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA,2DAA2D;AAC3D;;;;;;;;;;;;ACLA;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;;;;;;;;;;;;ACJA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACXA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACJA,aAAa,mBAAO,CAAC,4DAAW;AAChC;;AAEA;;;;;;;;;;;;ACHA,YAAY,mBAAO,CAAC,4DAAW;AAC/B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,aAAa,mBAAO,CAAC,4DAAW;AAChC;;AAEA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;ACVA,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,sDAAQ;AAC/B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,iBAAiB,mBAAO,CAAC,wDAAS;AAClC;AACA;AACA;AACA;;;;;;;;;;;;;ACPa;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0EAAkB;AACtC;AACA;AACA;AACA,0CAA0C,gBAAgB,EAAE;AAC5D;AACA;AACA;AACA;AACA,CAAC;AACD,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;ACb/B;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,6BAA6B,UAAU,mBAAO,CAAC,gEAAa,GAAG;;;;;;;;;;;;;ACHlD;AACb,uBAAuB,mBAAO,CAAC,oFAAuB;AACtD,WAAW,mBAAO,CAAC,kEAAc;AACjC,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,gCAAgC;AAChC,cAAc;AACd,iBAAiB;AACjB;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;ACjCa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0EAAkB;;AAEtC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,gCAAgC,OAAO,mBAAO,CAAC,wDAAS,GAAG;;;;;;;;;;;;ACH3D;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,0CAA0C,SAAS,mBAAO,CAAC,0EAAkB,GAAG;;;;;;;;;;;;;ACHnE;AACb;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA,KAAK,mBAAO,CAAC,sDAAQ;AACrB;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;AACA,GAAG;AACH;;;;;;;;;;;;;ACTa;AACb,cAAc,mBAAO,CAAC,8DAAY;AAClC,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,YAAY,mBAAO,CAAC,4DAAW;AAC/B,yBAAyB,mBAAO,CAAC,sFAAwB;AACzD,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,iCAAiC,mBAAO,CAAC,4FAA2B;AACpE,cAAc,mBAAO,CAAC,8DAAY;AAClC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,qBAAqB,mBAAO,CAAC,8EAAoB;AACjD;AACA;AACA;AACA;AACA;AACA;AACA;AACA,yBAAyB;AACzB;AACA;;AAEA;AACA;AACA;AACA;AACA,+CAA+C,EAAE,mBAAO,CAAC,sDAAQ;AACjE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oCAAoC;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,WAAW;AACX;AACA,WAAW;AACX,SAAS;AACT,OAAO;AACP;AACA;AACA;AACA;AACA,6CAA6C;AAC7C;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT,mBAAmB,kCAAkC;AACrD,SAAS;AACT;AACA;AACA,OAAO;AACP;AACA;AACA,KAAK;AACL;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL,eAAe,uCAAuC;AACtD;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA,uBAAuB,0BAA0B;AACjD;AACA;AACA,SAAS;AACT;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH,kBAAkB,yBAAyB,KAAK;AAChD;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA,iBAAiB;AACjB,wBAAwB;AACxB,gBAAgB;AAChB,oBAAoB;AACpB,wBAAwB;AACxB,gBAAgB;AAChB,oBAAoB;AACpB;AACA,uBAAuB,mBAAO,CAAC,wEAAiB;AAChD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,0DAA0D,oBAAoB;AAC9E,mBAAO,CAAC,kFAAsB;AAC9B,mBAAO,CAAC,sEAAgB;AACxB,UAAU,mBAAO,CAAC,wDAAS;;AAE3B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA,CAAC;AACD,gDAAgD,mBAAO,CAAC,sEAAgB;AACxE;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT,OAAO;AACP;AACA,KAAK;AACL;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;AC7RY;AACb,UAAU,mBAAO,CAAC,kEAAc;;AAEhC;AACA,mBAAO,CAAC,sEAAgB;AACxB,6BAA6B;AAC7B,cAAc;AACd;AACA,CAAC;AACD;AACA;AACA;AACA,iCAAiC;AACjC;AACA;AACA,UAAU;AACV,CAAC;;;;;;;;;;;;AChBD,iBAAiB,mBAAO,CAAC,kFAAsB;AAC/C,cAAc,mBAAO,CAAC,sEAAgB;AACtC,eAAe,mBAAO,CAAC,gEAAa;AACpC,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,oDAAoD,wBAAwB;AAC5E;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACzDA,CAAC;AACD,KAAK,IAA2B;AAChC;AACA;AACA;AACA,MAAM,EAOJ;AACF,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;;AAEA;;AAEA;AACA;AACA,MAAM;;AAEN;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;;AAGA;AACA;AACA;AACA;AACA,wBAAwB,OAAO;AAC/B;AACA,yBAAyB,OAAO;AAChC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,qBAAqB;AACrB;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA,cAAc;;AAEd;AACA;AACA;AACA;AACA,yBAAyB,OAAO;AAChC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,cAAc;;AAEd;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,qBAAqB;AACrB;AACA;AACA,cAAc;;AAEd;AACA;AACA;AACA,wBAAwB,OAAO;AAC/B;AACA;AACA;AACA;AACA;AACA,qBAAqB;AACrB;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,cAAc;;AAEd;AACA;AACA;AACA,yBAAyB,OAAO;AAChC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,MAAM;;AAEN;AACA;AACA;AACA,mBAAmB,MAAM;AACzB,mBAAmB,OAAO;AAC1B;AACA;AACA;AACA;AACA;AACA,oBAAoB,MAAM;AAC1B,oBAAoB,OAAO;AAC3B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,cAAc;AACd;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA,oBAAoB,QAAQ;AAC5B;AACA,qBAAqB,OAAO;AAC5B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA,oBAAoB,UAAU;AAC9B;AACA,qBAAqB,UAAU;AAC/B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA,gCAAgC,kBAAkB;AAClD;AACA;AACA;AACA,cAAc;AACd;AACA,gCAAgC,kBAAkB;AAClD;AACA;AACA;AACA;;AAEA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA,qBAAqB,UAAU;AAC/B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,UAAU;;AAEV;AACA;AACA;AACA,oBAAoB,OAAO;AAC3B;AACA,qBAAqB,UAAU;AAC/B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,cAAc;;AAEd,oCAAoC,YAAY;AAChD;;AAEA;AACA;AACA;;AAEA;AACA;AACA,MAAM;;AAEN;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oBAAoB,UAAU;AAC9B;AACA,qBAAqB,OAAO;AAC5B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,4BAA4B,cAAc;AAC1C;AACA;AACA;AACA;;AAEA;AACA,UAAU;;AAEV;AACA;AACA;AACA,oBAAoB,OAAO;AAC3B;AACA,qBAAqB,UAAU;AAC/B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,4BAA4B,kBAAkB;AAC9C;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oBAAoB,UAAU;AAC9B;AACA,qBAAqB,OAAO;AAC5B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,4BAA4B,cAAc;AAC1C;AACA;AACA;;AAEA;AACA,UAAU;;AAEV;AACA;AACA;AACA,oBAAoB,OAAO;AAC3B;AACA,qBAAqB,UAAU;AAC/B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,4BAA4B,qBAAqB;AACjD;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oBAAoB,UAAU;AAC9B;AACA,qBAAqB,OAAO;AAC5B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,cAAc;AACd;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA,oBAAoB,OAAO;AAC3B;AACA,qBAAqB,UAAU;AAC/B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,mBAAmB,OAAO;AAC1B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA,oBAAoB,iBAAiB;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA;AACA;AACA,oBAAoB,QAAQ;AAC5B;AACA,qBAAqB,UAAU;AAC/B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,cAAc;AACd;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,qCAAqC,sBAAsB;AAC3D;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA,qBAAqB,OAAO;AAC5B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,UAAU;;AAEV;AACA,MAAM;;AAEN;AACA;AACA;AACA,mBAAmB,OAAO;AAC1B;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,oBAAoB,OAAO;AAC3B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA,oBAAoB,iBAAiB;AACrC;AACA,qBAAqB,OAAO;AAC5B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA;AACA,oBAAoB,iBAAiB;AACrC;AACA,qBAAqB,UAAU;AAC/B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA,UAAU;;AAEV;;AAEA;AACA;AACA;AACA,oBAAoB,OAAO;AAC3B;AACA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA,oBAAoB,OAAO;AAC3B;AACA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,MAAM;;AAEN;AACA;AACA;AACA;;AAEA;AACA,EAAE;;;AAGF;;AAEA,CAAC,G;;;;;;;;;;;ACvvBD,CAAC;AACD,KAAK,IAA2B;AAChC;AACA,qCAAqC,mBAAO,CAAC,gDAAQ;AACrD;AACA,MAAM,EAOJ;AACF,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,iCAAiC,iBAAiB;AAClD;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,MAAM;;AAEN;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU;;AAEV;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,4BAA4B,QAAQ;AACpC;AACA;AACA,kBAAkB;AAClB;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU;;AAEV;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,UAAU;;AAEV;AACA;AACA;;AAEA;AACA;AACA,MAAM;;AAEN;AACA;AACA;AACA,gBAAgB,iBAAiB;AACjC;AACA,iBAAiB,UAAU;AAC3B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,gBAAgB,iBAAiB;AACjC,gBAAgB,iBAAiB;AACjC;AACA,iBAAiB,UAAU;AAC3B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,EAAE;;;AAGF;;AAEA,CAAC,G;;;;;;;;;;;ACtMD;;AAEA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,oBAAoB,6BAA6B;;AAEjD;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU;AACV;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,eAAe,SAAS;AACxB;AACA,gBAAgB,SAAS;AACzB;AACA,gBAAgB,SAAS;;AAEzB,0BAA0B,wBAAwB;AAClD;AACA;AACA;AACA;;AAEA;AACA;AACA,2BAA2B,QAAQ;AACnC;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,qBAAqB,eAAe,cAAc,UAAU;;AAE5D;AACA;AACA;AACA;AACA;AACA,8BAA8B;AAC9B;AACA;AACA;AACA,YAAY,qBAAqB,QAAQ;AACzC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,iDAAiD,UAAU,iBAAiB;AAC5E;AACA;AACA;AACA;AACA;AACA;AACA;AACA,wBAAwB,cAAc,KAAK;AAC3C;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,yBAAyB,eAAe,+BAA+B,UAAU;;AAEjF;AACA,sBAAsB,sCAAsC;;AAE5D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,2BAA2B,OAAO,SAAS;AAC3C,yBAAyB,OAAO,QAAQ;AACxC,yBAAyB,OAAO,QAAQ;AACxC,yBAAyB,OAAO,QAAQ;AACxC,yBAAyB,OAAO,QAAQ;AACxC;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,uBAAuB,QAAQ;AAC/B,kBAAkB,QAAQ;AAC1B;AACA;AACA;;AAEA;AACA;AACA,oBAAoB,YAAY;AAChC;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,uBAAuB,QAAQ;AAC/B;AACA;AACA;AACA,mBAAmB,QAAQ;AAC3B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,wBAAwB,SAAS,QAAQ;AACzC;AACA;AACA;AACA;AACA,uBAAuB,YAAY;AACnC;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,gBAAgB,SAAS;AACzB;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,gBAAgB,WAAW;AAC3B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,0CAA0C;AAC1C,mBAAmB,oBAAoB,oBAAoB;AAC3D,YAAY,cAAc,cAAc;AACxC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,mBAAmB;AACnB;AACA;AACA;AACA;AACA,8CAA8C;AAC9C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oCAAoC;AACpC;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,yBAAyB,YAAY;AACrC;AACA;AACA;AACA;AACA,yBAAyB,UAAU;AACnC,yBAAyB,2BAA2B;AACpD,4BAA4B,mBAAmB,gBAAgB;AAC/D,0BAA0B,eAAe,gBAAgB;;AAEzD;AACA;AACA;AACA;AACA;;AAEA,2CAA2C;AAC3C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,kBAAkB;AAClB,gCAAgC;AAChC,kCAAkC;AAClC,iDAAiD;AACjD;AACA;AACA,sCAAsC;AACtC;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,oBAAoB,cAAc;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,6BAA6B,cAAc,UAAU;AACrD;AACA;AACA;AACA;AACA;;AAEA,yBAAyB;AACzB,6BAA6B,eAAe,gBAAgB;;AAE5D,wBAAwB;AACxB,+BAA+B,mBAAmB,gBAAgB;;AAElE;AACA;AACA;AACA;AACA;;AAEA;AACA,0BAA0B,6CAA6C;;AAEvE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,cAAc,WAAW,QAAQ,QAAQ;AACzC;AACA;AACA;;AAEA;AACA;AACA;AACA,mDAAmD;AACnD;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA;AACA,wBAAwB,eAAe,gBAAgB,UAAU;;AAEjE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,4BAA4B,6CAA6C;;AAEzE;AACA,6BAA6B,6CAA6C;;AAE1E;AACA,8BAA8B,iDAAiD;;AAE/E;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,oBAAoB,cAAc;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,iDAAiD;AACjD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,qCAAqC;AACrC;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,wBAAwB,cAAc,KAAK;AAC3C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,0BAA0B,8BAA8B;AACxD,uBAAuB,oCAAoC;AAC3D,uBAAuB,oCAAoC;;AAE3D;AACA;AACA;AACA,gBAAgB,OAAO;AACvB;AACA;AACA,kBAAkB,YAAY;AAC9B;AACA;AACA;AACA;AACA,kBAAkB,SAAS;AAC3B;AACA;AACA;AACA;AACA;;AAEA;AACA,0BAA0B,YAAY;AACtC,uBAAuB,eAAe,4BAA4B,UAAU;;AAE5E;AACA,yBAAyB,YAAY;AACrC,sBAAsB,eAAe,2BAA2B,UAAU;;AAE1E;AACA,0BAA0B,YAAY;AACtC,uBAAuB,eAAe,4BAA4B,UAAU;;AAE5E;AACA,6BAA6B,aAAa;AAC1C,0BAA0B,eAAe,+BAA+B,UAAU;;AAElF;AACA;AACA;AACA,oBAAoB,YAAY;AAChC;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,oCAAoC;AACpC;AACA;;AAEA;AACA;AACA;AACA,oCAAoC;AACpC;AACA;;AAEA;AACA;AACA;AACA;AACA,2BAA2B,UAAU,SAAS;AAC9C,yBAAyB,SAAS,QAAQ;AAC1C,wBAAwB,SAAS,QAAQ;AACzC,sBAAsB,SAAS,QAAQ;AACvC;AACA;AACA;;AAEA;AACA;AACA,oBAAoB,YAAY;AAChC;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,qBAAqB,UAAU,KAAK;AACpC;AACA;;AAEA;AACA;AACA;AACA,oBAAoB,YAAY;AAChC;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,0BAA0B,gCAAgC;;AAE1D;AACA,4BAA4B,oCAAoC;;AAEhE;AACA,2BAA2B,iCAAiC;;AAE5D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,uBAAuB,eAAe,iBAAiB,UAAU;;AAEjE;AACA,4BAA4B,eAAe,iBAAiB,UAAU;;AAEtE;AACA,4BAA4B,eAAe,sBAAsB,UAAU;;AAE3E;AACA,yBAAyB,eAAe,kBAAkB,UAAU;;AAEpE;AACA,0BAA0B,eAAe,yBAAyB,UAAU;;AAE5E;AACA,6BAA6B,eAAe,yBAAyB,UAAU;;AAE/E;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,sBAAsB,UAAU;AAChC,4BAA4B,mBAAmB;AAC/C,0BAA0B,eAAe;;AAEzC;AACA;AACA;AACA;;AAEA;AACA,uBAAuB,kCAAkC;;AAEzD;AACA;AACA;AACA;AACA,cAAc;AACd;AACA;AACA;AACA,yBAAyB,OAAO;AAChC,8BAA8B,OAAO;AACrC;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,cAAc;AACd;AACA,mCAAmC,SAAS;AAC5C;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,YAAY,eAAe,aAAa,gBAAgB,UAAU;AAClE;;AAEA,+BAA+B,UAAU;;AAEzC;AACA;AACA;AACA,4BAA4B,kBAAkB,WAAW;AACzD;AACA;AACA;AACA;AACA;AACA;;AAEA,qBAAqB;AACrB,gCAAgC,eAAe,gBAAgB;;AAE/D,qBAAqB;AACrB,kCAAkC,mBAAmB,gBAAgB;;AAErE;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,2BAA2B,SAAS,KAAK;AACzC,0BAA0B,cAAc,KAAK;AAC7C,iBAAiB;AACjB;AACA;AACA;AACA;AACA,wBAAwB,eAAe,eAAe,QAAQ;AAC9D,kCAAkC,OAAO,OAAO,QAAQ,QAAQ;AAChE;AACA;;AAEA;AACA,wBAAwB,OAAO,QAAQ;AACvC,uBAAuB,eAAe,KAAK;AAC3C;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,8BAA8B,WAAW,OAAO,OAAO;AACvD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,kCAAkC,QAAQ;AAC1C;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,4CAA4C,iBAAiB,cAAc;AAC3E;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,4CAA4C,iBAAiB,cAAc;AAC3E;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,sCAAsC;AACtC,yCAAyC;AACzC;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA,kBAAkB,sBAAsB;AACxC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oBAAoB,OAAO;AAC3B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA,sCAAsC,8BAA8B;AACpE;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oBAAoB,QAAQ;AAC5B;AACA;AACA;AACA;AACA;AACA,oBAAoB,cAAc;AAClC;AACA;AACA;AACA,mCAAmC;AACnC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,yBAAyB,4BAA4B;AACrD;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,gBAAgB,eAAe;AAC/B;;AAEA;;AAEA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,gBAAgB,SAAS;AACzB;AACA;AACA,gBAAgB,SAAS;AACzB;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA,QAAQ,IAA8B;AACtC;AACA;AACA;AACA;AACA;AACA,KAAK,MAAM,EAKN;;AAEL,CAAC;;;;;;;;;;;;ACh1CD;AACA;AACA;AACA;AACA;AACA,eAAe,SAAS;AACxB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;ACvBA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA,iCAAiC;;AAEjC;AACA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;;AAEA;AACA,sBAAsB,QAAQ;AAC9B;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;ACjCA,UAAU,mBAAO,CAAC,yDAAW;AAC7B,kBAAkB,mBAAO,CAAC,iEAAmB;;AAE7C;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;;AAEA;AACA;AACA,oBAAoB,SAAS;AAC7B;AACA;AACA;;AAEA;AACA;;AAEA;;;;;;;;;;;;;;;ACtBA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA,gG;;;;;;;;;;;;;;;;;;;ACTA;;AACA;;0JAJA;AACA;;AAKA,IAAMC,6CAA6C,EAAnD,C,CAAuD;;IAE1CT,iB,WAAAA,iB;AAET,iCAIQ;AAAA,uFAAJ,EAAI;AAAA,yCAHJU,mCAGI;AAAA,YAHJA,mCAGI,yCAHkCD,0CAGlC;AAAA,0CAFJE,wBAEI;AAAA,YAFJA,wBAEI,0CAFuB,IAAIC,YAAJ,CAAU,uBAAV,CAEvB;AAAA,0CADJC,uBACI;AAAA,YADJA,uBACI,0CADsB,IAAID,YAAJ,CAAU,sBAAV,CACtB;;AAAA;;AACJ,aAAKE,oCAAL,GAA4CJ,mCAA5C;;AAEA,aAAKK,oBAAL,GAA4BJ,wBAA5B;AACA,aAAKK,mBAAL,GAA2BH,uBAA3B;AACH;;gCAEDI,I,iBAAKC,S,EAAW;AACZ;AACA,YAAIA,UAAUC,YAAV,IAA0BD,UAAUE,UAAV,KAAyBC,SAAvD,EAAkE;AAC9D,gBAAIC,WAAWJ,UAAUE,UAAzB;AACA1B,qBAAI6B,KAAJ,CAAU,mEAAV,EAA+ED,QAA/E;;AAEA,gBAAIA,WAAW,CAAf,EAAkB;AACd;AACA,oBAAIE,WAAWF,WAAW,KAAKR,oCAA/B;AACA,oBAAIU,YAAY,CAAhB,EAAkB;AACdA,+BAAW,CAAX;AACH;;AAED9B,yBAAI6B,KAAJ,CAAU,wDAAV,EAAoEC,QAApE;AACA,qBAAKT,oBAAL,CAA0BU,IAA1B,CAA+BD,QAA/B;AACH,aATD,MAUK;AACD9B,yBAAI6B,KAAJ,CAAU,yFAAV;AACA,qBAAKR,oBAAL,CAA0BW,MAA1B;AACH;;AAED;AACA,gBAAIC,UAAUL,WAAW,CAAzB;AACA5B,qBAAI6B,KAAJ,CAAU,uDAAV,EAAmEI,OAAnE;AACA,iBAAKX,mBAAL,CAAyBS,IAAzB,CAA8BE,OAA9B;AACH,SAvBD,MAwBK;AACD,iBAAKZ,oBAAL,CAA0BW,MAA1B;AACA,iBAAKV,mBAAL,CAAyBU,MAAzB;AACH;AACJ,K;;gCAEDE,M,qBAAS;AACLlC,iBAAI6B,KAAJ,CAAU,kEAAV;AACA,aAAKR,oBAAL,CAA0BW,MAA1B;AACA,aAAKV,mBAAL,CAAyBU,MAAzB;AACH,K;;gCAEDG,sB,mCAAuBC,E,EAAI;AACvB,aAAKf,oBAAL,CAA0BgB,UAA1B,CAAqCD,EAArC;AACH,K;;gCACDE,yB,sCAA0BF,E,EAAI;AAC1B,aAAKf,oBAAL,CAA0BkB,aAA1B,CAAwCH,EAAxC;AACH,K;;gCAEDI,qB,kCAAsBJ,E,EAAI;AACtB,aAAKd,mBAAL,CAAyBe,UAAzB,CAAoCD,EAApC;AACH,K;;gCACDK,wB,qCAAyBL,E,EAAI;AACzB,aAAKd,mBAAL,CAAyBiB,aAAzB,CAAuCH,EAAvC;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACpEL;;0JAHA;AACA;;AAIA,IAAMM,kBAAkB,IAAxB;;IAEahC,kB,WAAAA,kB;AACT,gCAAYiC,QAAZ,EAAsBC,SAAtB,EAAiCC,GAAjC,EAAsCC,QAAtC,EAAoE;AAAA,YAApBC,WAAoB,uEAAN,IAAM;;AAAA;;AAChE,aAAKC,SAAL,GAAiBL,QAAjB;AACA,aAAKM,UAAL,GAAkBL,SAAlB;AACA,aAAKM,IAAL,GAAYL,GAAZ;AACA,aAAKM,SAAL,GAAiBL,YAAYJ,eAA7B;AACA,aAAKU,YAAL,GAAoBL,WAApB;;AAEA,YAAIM,MAAMR,IAAIS,OAAJ,CAAY,GAAZ,EAAiBT,IAAIS,OAAJ,CAAY,IAAZ,IAAoB,CAArC,CAAV;AACA,aAAKC,aAAL,GAAqBV,IAAIW,MAAJ,CAAW,CAAX,EAAcH,GAAd,CAArB;;AAEA,aAAKI,MAAL,GAAcC,OAAOC,QAAP,CAAgBC,aAAhB,CAA8B,QAA9B,CAAd;;AAEA;AACA,aAAKH,MAAL,CAAYI,KAAZ,CAAkBC,UAAlB,GAA+B,QAA/B;AACA,aAAKL,MAAL,CAAYI,KAAZ,CAAkBE,QAAlB,GAA6B,UAA7B;AACA,aAAKN,MAAL,CAAYI,KAAZ,CAAkBG,OAAlB,GAA4B,MAA5B;AACA,aAAKP,MAAL,CAAYI,KAAZ,CAAkBI,KAAlB,GAA0B,CAA1B;AACA,aAAKR,MAAL,CAAYI,KAAZ,CAAkBK,MAAlB,GAA2B,CAA3B;;AAEA,aAAKT,MAAL,CAAYU,GAAZ,GAAkBtB,GAAlB;AACH;;iCACDtB,I,mBAAO;AAAA;;AACH,eAAO,IAAI6C,OAAJ,CAAY,UAACC,OAAD,EAAa;AAC5B,kBAAKZ,MAAL,CAAYa,MAAZ,GAAqB,YAAM;AACvBD;AACH,aAFD;;AAIAX,mBAAOC,QAAP,CAAgBY,IAAhB,CAAqBC,WAArB,CAAiC,MAAKf,MAAtC;AACA,kBAAKgB,kBAAL,GAA0B,MAAKC,QAAL,CAAcC,IAAd,CAAmB,KAAnB,CAA1B;AACAjB,mBAAOkB,gBAAP,CAAwB,SAAxB,EAAmC,MAAKH,kBAAxC,EAA4D,KAA5D;AACH,SARM,CAAP;AASH,K;;iCACDC,Q,qBAASG,C,EAAG;AACR,YAAIA,EAAEC,MAAF,KAAa,KAAKvB,aAAlB,IACAsB,EAAEE,MAAF,KAAa,KAAKtB,MAAL,CAAYuB,aAD7B,EAEE;AACE,gBAAIH,EAAEI,IAAF,KAAW,OAAf,EAAwB;AACpBjF,yBAAIkF,KAAJ,CAAU,gEAAV;AACA,oBAAI,KAAK9B,YAAT,EAAuB;AACnB,yBAAK+B,IAAL;AACH;AACJ,aALD,MAMK,IAAIN,EAAEI,IAAF,KAAW,SAAf,EAA0B;AAC3BjF,yBAAI6B,KAAJ,CAAU,kEAAV;AACA,qBAAKsD,IAAL;AACA,qBAAKnC,SAAL;AACH,aAJI,MAKA;AACDhD,yBAAI6B,KAAJ,CAAU,yBAAyBgD,EAAEI,IAA3B,GAAkC,uCAA5C;AACH;AACJ;AACJ,K;;iCACDG,K,kBAAMC,a,EAAe;AAAA;;AACjB,YAAI,KAAKC,cAAL,KAAwBD,aAA5B,EAA2C;AACvCrF,qBAAI6B,KAAJ,CAAU,0BAAV;;AAEA,iBAAKsD,IAAL;;AAEA,iBAAKG,cAAL,GAAsBD,aAAtB;;AAEA,gBAAIE,OAAO,SAAPA,IAAO,GAAM;AACb,uBAAK9B,MAAL,CAAYuB,aAAZ,CAA0BQ,WAA1B,CAAsC,OAAKvC,UAAL,GAAkB,GAAlB,GAAwB,OAAKqC,cAAnE,EAAmF,OAAK/B,aAAxF;AACH,aAFD;;AAIA;AACAgC;;AAEA;AACA,iBAAKE,MAAL,GAAc/B,OAAOgC,WAAP,CAAmBH,IAAnB,EAAyB,KAAKpC,SAA9B,CAAd;AACH;AACJ,K;;iCAEDgC,I,mBAAO;AACH,aAAKG,cAAL,GAAsB,IAAtB;;AAEA,YAAI,KAAKG,MAAT,EAAiB;AACbzF,qBAAI6B,KAAJ,CAAU,yBAAV;;AAEA6B,mBAAOiC,aAAP,CAAqB,KAAKF,MAA1B;AACA,iBAAKA,MAAL,GAAc,IAAd;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;ACtFL;;0JAHA;AACA;;IAIahF,sB,WAAAA,sB;;;;;qCAETmF,O,oBAAQC,M,EAAQ;AACZA,eAAOC,mBAAP,GAA6B,YAA7B;AACA,YAAIC,QAAQ,IAAIC,sCAAJ,CAAuBH,MAAvB,CAAZ;AACA,eAAOzB,QAAQC,OAAR,CAAgB0B,KAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACRL;;0JAHA;AACA;;IAIavF,qB,WAAAA,qB;;;;;oCAEToF,O,oBAAQC,M,EAAQ;AACZ,YAAIE,QAAQ,IAAIC,sCAAJ,CAAuBH,MAAvB,CAAZ;AACA,eAAOzB,QAAQC,OAAR,CAAgB0B,KAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCVL;AACA;;AAEA;;;;AAEA,IAAME,uBAAuB,gCAA7B;AACA,IAAMC,qBAAqB,QAA3B;;IAEaF,kB,WAAAA,kB;AAET,gCAAYH,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI/B,OAAJ,CAAY,UAACC,OAAD,EAAU+B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgBhC,OAAhB;AACA,kBAAKiC,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,aAAKG,QAAL,GAAgBV,OAAOC,mBAAP,IAA8BG,oBAA9C;AACA,aAAKO,MAAL,GAAcX,OAAOY,iBAAP,IAA4BP,kBAA1C;;AAEA,aAAKQ,YAAL,GAAoBb,OAAOc,QAA3B;AACA3G,iBAAI6B,KAAJ,CAAU,4CAA4C,KAAK6E,YAA3D;AACH;;iCAEDE,wB,qCAAyBC,e,EAAiB;AACtC,eAAO,CAAC,6BAAD,EAAgC,0CAAhC,EAA4E,iCAA5E,EAA+GC,IAA/G,CAAoH,UAAUC,IAAV,EAAgB;AACvI,mBAAOF,gBAAgBG,cAAhB,CAA+BD,IAA/B,CAAP;AACH,SAFM,CAAP;AAGH,K;;iCAEDE,Q,qBAASpB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAOhD,GAAvB,EAA4B;AACxB,iBAAKqE,MAAL,CAAY,iBAAZ;AACH,SAFD,MAEO;AACH,gBAAI,CAACxD,OAAOyD,OAAZ,EAAqB;AACjB,uBAAO,KAAKD,MAAL,CAAY,sBAAZ,CAAP;AACH;;AAED,gBAAIL,kBAAkBnD,OAAOyD,OAAP,CAAeC,OAAf,CAAuB,qBAAvB,EAA8CC,QAApE;AACA,gBAAI,KAAKT,wBAAL,CAA8BC,eAA9B,MAAmD,KAAvD,EAA8D;AAC1D,uBAAO,KAAKK,MAAL,CAAY,+BAAZ,CAAP;AACH;AACD,iBAAKI,MAAL,GAAcH,QAAQI,YAAR,CAAqBC,IAArB,CAA0B3B,OAAOhD,GAAjC,EAAsC,KAAK2D,MAA3C,EAAmD,KAAKD,QAAxD,CAAd;AACA,gBAAI,KAAKe,MAAT,EAAiB;AACbtH,yBAAI6B,KAAJ,CAAU,yDAAV;;AAEA,qBAAK4F,kBAAL,GAA0B,KAAKC,aAAL,CAAmB/C,IAAnB,CAAwB,IAAxB,CAA1B;AACA,qBAAKgD,uBAAL,GAA+B,KAAKC,kBAAL,CAAwBjD,IAAxB,CAA6B,IAA7B,CAA/B;;AAEA,qBAAK2C,MAAL,CAAY1C,gBAAZ,CAA6B,MAA7B,EAAqC,KAAK6C,kBAA1C,EAA8D,KAA9D;AACA,qBAAKH,MAAL,CAAY1C,gBAAZ,CAA6B,WAA7B,EAA0C,KAAK+C,uBAA/C,EAAwE,KAAxE;AACH,aARD,MAQO;AACH,qBAAKT,MAAL,CAAY,4BAAZ;AACH;AACJ;AACD,eAAO,KAAKW,OAAZ;AACH,K;;iCAMDD,kB,+BAAmBE,K,EAAO;AACtB,YAAIA,MAAMjF,GAAN,CAAUS,OAAV,CAAkB,KAAKoD,YAAvB,MAAyC,CAA7C,EAAgD;AAC5C,iBAAKqB,QAAL,CAAc,EAAElF,KAAKiF,MAAMjF,GAAb,EAAd;AACH;AACJ,K;;iCACD6E,a,0BAAcM,O,EAAS;AACnB,aAAKd,MAAL,CAAYc,OAAZ;AACH,K;;iCAEDD,Q,qBAAS9C,I,EAAM;AACX,aAAKgD,QAAL;;AAEAjI,iBAAI6B,KAAJ,CAAU,mEAAV;AACA,aAAKwE,QAAL,CAAcpB,IAAd;AACH,K;;iCACDiC,M,mBAAOc,O,EAAS;AACZ,aAAKC,QAAL;;AAEAjI,iBAAIkF,KAAJ,CAAU8C,OAAV;AACA,aAAK1B,OAAL,CAAa,IAAI4B,KAAJ,CAAUF,OAAV,CAAb;AACH,K;;iCAEDG,K,oBAAQ;AACJ,aAAKF,QAAL;AACH,K;;iCAEDA,Q,uBAAW;AACP,YAAI,KAAKX,MAAT,EAAgB;AACZtH,qBAAI6B,KAAJ,CAAU,uCAAV;AACA,iBAAKyF,MAAL,CAAYc,mBAAZ,CAAgC,MAAhC,EAAwC,KAAKX,kBAA7C,EAAiE,KAAjE;AACA,iBAAKH,MAAL,CAAYc,mBAAZ,CAAgC,WAAhC,EAA6C,KAAKT,uBAAlD,EAA2E,KAA3E;AACA,iBAAKL,MAAL,CAAYa,KAAZ;AACH;AACD,aAAKb,MAAL,GAAc,IAAd;AACH,K;;;;4BAtCa;AACV,mBAAO,KAAKnB,QAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;ACxDL;;;;;;+eAHA;AACA;;IAIakC,a,WAAAA,a;;;AACT,iCACE;AAAA,+FADsE,EACtE;AAAA,oBADWnD,KACX,QADWA,KACX;AAAA,oBADkBoD,iBAClB,QADkBA,iBAClB;AAAA,oBADqCC,SACrC,QADqCA,SACrC;AAAA,oBADgDC,KAChD,QADgDA,KAChD;AAAA,oBADuDnD,aACvD,QADuDA,aACvD;;AAAA;;AACG,oBAAI,CAACH,KAAL,EAAW;AACRlF,iCAAIkF,KAAJ,CAAU,kCAAV;AACA,8BAAM,IAAIgD,KAAJ,CAAU,OAAV,CAAN;AACH;;AAJH,6DAME,kBAAMI,qBAAqBpD,KAA3B,CANF;;AAQE,sBAAK6B,IAAL,GAAY,eAAZ;;AAEA,sBAAK7B,KAAL,GAAaA,KAAb;AACA,sBAAKoD,iBAAL,GAAyBA,iBAAzB;AACA,sBAAKC,SAAL,GAAiBA,SAAjB;;AAEA,sBAAKC,KAAL,GAAaA,KAAb;AACA,sBAAKnD,aAAL,GAAqBA,aAArB;AAfF;AAgBD;;;EAlB8B6C,K;;;;;;;;;;;;;;;;;;;ACFnC;;0JAHA;AACA;;IAIaO,K,WAAAA,K;AAET,mBAAY1B,IAAZ,EAAkB;AAAA;;AACd,aAAK2B,KAAL,GAAa3B,IAAb;AACA,aAAK4B,UAAL,GAAkB,EAAlB;AACH;;oBAEDtG,U,uBAAWD,E,EAAI;AACX,aAAKuG,UAAL,CAAgBC,IAAhB,CAAqBxG,EAArB;AACH,K;;oBAEDG,a,0BAAcH,E,EAAI;AACd,YAAIiB,MAAM,KAAKsF,UAAL,CAAgBE,SAAhB,CAA0B;AAAA,mBAAQC,SAAS1G,EAAjB;AAAA,SAA1B,CAAV;AACA,YAAIiB,OAAO,CAAX,EAAc;AACV,iBAAKsF,UAAL,CAAgBI,MAAhB,CAAuB1F,GAAvB,EAA4B,CAA5B;AACH;AACJ,K;;oBAED2F,K,oBAAiB;AACbhJ,iBAAI6B,KAAJ,CAAU,2BAA2B,KAAK6G,KAA1C;AACA,aAAK,IAAIO,IAAI,CAAb,EAAgBA,IAAI,KAAKN,UAAL,CAAgBO,MAApC,EAA4CD,GAA5C,EAAiD;AAAA;;AAC7C,+BAAKN,UAAL,EAAgBM,CAAhB;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;;;;AC5BL;AACA;;AAEA,IAAME,QAAQ;AACVzD;AAAA;AAAA;AAAA;;AAAA;AAAA;AAAA;;AAAA;AAAA,MAAa,UAAUtD,EAAV,EAAcR,QAAd,EAAwB;AACjC,eAAO8D,YAAYtD,EAAZ,EAAgBR,QAAhB,CAAP;AACH,KAFD,CADU;AAIV+D;AAAA;AAAA;AAAA;;AAAA;AAAA;AAAA;;AAAA;AAAA,MAAe,UAAUyD,MAAV,EAAkB;AAC7B,eAAOzD,cAAcyD,MAAd,CAAP;AACH,KAFD;AAJU,CAAd;;AASA,IAAIC,UAAU,KAAd;AACA,IAAIC,UAAU,IAAd;;IAEazI,M,WAAAA,M;;;;;WAEF0I,Q,uBAAW;AACdF,kBAAU,IAAV;AACH,K;;WAoBMG,iB,8BAAkBC,U,EAAY;AACjCH,kBAAUG,UAAV;AACH,K;;;;4BApBqB;AAClB,gBAAI,CAACJ,OAAL,EAAc;AACV,uBAAOK,QAAP;AACH;AACJ;;;4BAEyB;AACtB,gBAAI,CAACL,OAAD,IAAY,OAAO3F,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAOiG,YAAP;AACH;AACJ;;;4BAE2B;AACxB,gBAAI,CAACN,OAAD,IAAY,OAAO3F,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAOkG,cAAP;AACH;AACJ;;;4BAM2B;AACxB,gBAAI,CAACP,OAAD,IAAY,OAAO3F,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAO4F,WAAWO,cAAlB;AACH;AACJ;;;4BAEkB;AACf,gBAAI,CAACR,OAAL,EAAc;AACV,uBAAOF,KAAP;AACH;AACJ;;;;;;;;;;;;;;;;;;;;;;;AClDL;;AACA;;0JAJA;AACA;;IAKaW,e,WAAAA,e;;;;;8BAETlE,O,oBAAQC,M,EAAQ;AACZ,YAAIkE,QAAQ,IAAIC,0BAAJ,CAAiBnE,MAAjB,CAAZ;AACA,eAAOzB,QAAQC,OAAR,CAAgB0F,KAAhB,CAAP;AACH,K;;8BAEDpH,Q,qBAASE,G,EAAK;AACV7C,iBAAI6B,KAAJ,CAAU,0BAAV;;AAEA,YAAI;AACAmI,uCAAaC,YAAb,CAA0BpH,GAA1B;AACA,mBAAOuB,QAAQC,OAAR,EAAP;AACH,SAHD,CAIA,OAAOQ,CAAP,EAAU;AACN,mBAAOT,QAAQgC,MAAR,CAAevB,CAAf,CAAP;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;qjBCvBL;AACA;;AAEA;;;;AAEA,IAAMqF,iBAAiB,KAAvB;;IAEaF,Y,WAAAA,Y;AAET,0BAAYnE,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI/B,OAAJ,CAAY,UAACC,OAAD,EAAU+B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgBhC,OAAhB;AACA,kBAAKiC,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,aAAK3B,kBAAL,GAA0B,KAAKC,QAAL,CAAcC,IAAd,CAAmB,IAAnB,CAA1B;AACAjB,eAAOkB,gBAAP,CAAwB,SAAxB,EAAmC,KAAKH,kBAAxC,EAA4D,KAA5D;;AAEA,aAAKhB,MAAL,GAAcC,OAAOC,QAAP,CAAgBC,aAAhB,CAA8B,QAA9B,CAAd;;AAEA;AACA,aAAKH,MAAL,CAAYI,KAAZ,CAAkBC,UAAlB,GAA+B,QAA/B;AACA,aAAKL,MAAL,CAAYI,KAAZ,CAAkBE,QAAlB,GAA6B,UAA7B;AACA,aAAKN,MAAL,CAAYI,KAAZ,CAAkBG,OAAlB,GAA4B,MAA5B;AACA,aAAKP,MAAL,CAAYI,KAAZ,CAAkBI,KAAlB,GAA0B,CAA1B;AACA,aAAKR,MAAL,CAAYI,KAAZ,CAAkBK,MAAlB,GAA2B,CAA3B;;AAEAR,eAAOC,QAAP,CAAgBY,IAAhB,CAAqBC,WAArB,CAAiC,KAAKf,MAAtC;AACH;;2BAEDwD,Q,qBAASpB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAOhD,GAAvB,EAA4B;AACxB,iBAAKqE,MAAL,CAAY,iBAAZ;AACH,SAFD,MAGK;AACD,gBAAIiD,UAAUtE,OAAOuE,oBAAP,IAA+BF,cAA7C;AACAlK,qBAAI6B,KAAJ,CAAU,0CAAV,EAAsDsI,OAAtD;AACA,iBAAK1E,MAAL,GAAc/B,OAAO2G,UAAP,CAAkB,KAAKC,QAAL,CAAc3F,IAAd,CAAmB,IAAnB,CAAlB,EAA4CwF,OAA5C,CAAd;AACA,iBAAK1G,MAAL,CAAYU,GAAZ,GAAkB0B,OAAOhD,GAAzB;AACH;;AAED,eAAO,KAAKgF,OAAZ;AACH,K;;2BAMDE,Q,qBAAS9C,I,EAAM;AACX,aAAKgD,QAAL;;AAEAjI,iBAAI6B,KAAJ,CAAU,qDAAV;AACA,aAAKwE,QAAL,CAAcpB,IAAd;AACH,K;;2BACDiC,M,mBAAOc,O,EAAS;AACZ,aAAKC,QAAL;;AAEAjI,iBAAIkF,KAAJ,CAAU8C,OAAV;AACA,aAAK1B,OAAL,CAAa,IAAI4B,KAAJ,CAAUF,OAAV,CAAb;AACH,K;;2BAEDG,K,oBAAQ;AACJ,aAAKF,QAAL;AACH,K;;2BAEDA,Q,uBAAW;AACP,YAAI,KAAKxE,MAAT,EAAiB;AACbzD,qBAAI6B,KAAJ,CAAU,uBAAV;;AAEA6B,mBAAO0E,mBAAP,CAA2B,SAA3B,EAAsC,KAAK3D,kBAA3C,EAA+D,KAA/D;AACAf,mBAAO6G,YAAP,CAAoB,KAAK9E,MAAzB;AACA/B,mBAAOC,QAAP,CAAgBY,IAAhB,CAAqBiG,WAArB,CAAiC,KAAK/G,MAAtC;;AAEA,iBAAKgC,MAAL,GAAc,IAAd;AACA,iBAAKhC,MAAL,GAAc,IAAd;AACA,iBAAKgB,kBAAL,GAA0B,IAA1B;AACH;AACJ,K;;2BAED6F,Q,uBAAW;AACPtK,iBAAI6B,KAAJ,CAAU,sBAAV;AACA,aAAKqF,MAAL,CAAY,wBAAZ;AACH,K;;2BAEDxC,Q,qBAASG,C,EAAG;AACR7E,iBAAI6B,KAAJ,CAAU,sBAAV;;AAEA,YAAI,KAAK4D,MAAL,IACAZ,EAAEC,MAAF,KAAa,KAAK2F,OADlB,IAEA5F,EAAEE,MAAF,KAAa,KAAKtB,MAAL,CAAYuB,aAF7B,EAGE;AACE,gBAAInC,MAAMgC,EAAEI,IAAZ;AACA,gBAAIpC,GAAJ,EAAS;AACL,qBAAKkF,QAAL,CAAc,EAAElF,KAAKA,GAAP,EAAd;AACH,aAFD,MAGK;AACD,qBAAKqE,MAAL,CAAY,6BAAZ;AACH;AACJ;AACJ,K;;iBAMM+C,Y,yBAAapH,G,EAAK;AACrB7C,iBAAI6B,KAAJ,CAAU,2BAAV;AACA,YAAI6B,OAAOgH,YAAX,EAAyB;AACrB7H,kBAAMA,OAAOa,OAAOgG,QAAP,CAAgBiB,IAA7B;AACA,gBAAI9H,GAAJ,EAAS;AACL7C,yBAAI6B,KAAJ,CAAU,0DAAV;AACA6B,uBAAOkH,MAAP,CAAcpF,WAAd,CAA0B3C,GAA1B,EAA+B6G,SAASmB,QAAT,GAAoB,IAApB,GAA2BnB,SAASoB,IAAnE;AACH;AACJ;AACJ,K;;;;4BAtEa;AACV,mBAAO,KAAK3E,QAAZ;AACH;;;4BAuDa;AACV,mBAAOuD,SAASmB,QAAT,GAAoB,IAApB,GAA2BnB,SAASoB,IAA3C;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBCvGL;AACA;;AAEA;;;;IAEa1K,kB,WAAAA,kB;AACT,kCAAa;AAAA;;AACT,aAAK2K,KAAL,GAAa,EAAb;AACH;;iCAEDC,O,oBAAQC,G,EAAK;AACTjL,iBAAI6B,KAAJ,CAAU,4BAAV,EAAwCoJ,GAAxC;AACA,eAAO,KAAKF,KAAL,CAAWE,GAAX,CAAP;AACH,K;;iCAEDC,O,oBAAQD,G,EAAKE,K,EAAM;AACfnL,iBAAI6B,KAAJ,CAAU,4BAAV,EAAwCoJ,GAAxC;AACA,aAAKF,KAAL,CAAWE,GAAX,IAAkBE,KAAlB;AACH,K;;iCAEDC,U,uBAAWH,G,EAAI;AACXjL,iBAAI6B,KAAJ,CAAU,+BAAV,EAA2CoJ,GAA3C;AACA,eAAO,KAAKF,KAAL,CAAWE,GAAX,CAAP;AACH,K;;iCAMDA,G,gBAAII,K,EAAO;AACP,eAAOC,OAAOC,mBAAP,CAA2B,KAAKR,KAAhC,EAAuCM,KAAvC,CAAP;AACH,K;;;;4BANY;AACT,mBAAOC,OAAOC,mBAAP,CAA2B,KAAKR,KAAhC,EAAuC7B,MAA9C;AACH;;;;;;;;;;;;;;;;;;;;;kBCtBmBsC,W;;AAFxB;;0JAHA;AACA;;AAIe,SAASA,WAAT,OAA8F;AAAA,QAAvEC,GAAuE,QAAvEA,GAAuE;AAAA,QAAlEC,OAAkE,QAAlEA,OAAkE;AAAA,QAAzDC,IAAyD,QAAzDA,IAAyD;AAAA,QAAnDC,MAAmD,QAAnDA,MAAmD;AAAA,QAA3CC,SAA2C,QAA3CA,SAA2C;AAAA,QAAhCC,QAAgC,QAAhCA,QAAgC;AAAA,QAAtBC,kBAAsB,QAAtBA,kBAAsB;;AACzG;AAAA;AAAA;AAAA;;AAAA,iBAEWC,QAFX,qBAEoBC,GAFpB,EAEyB;AACjBjM,qBAAI6B,KAAJ,CAAU,mBAAV;AACA,gBAAI;AACA,oBAAIqK,QAAQT,IAAIU,GAAJ,CAAQC,KAAR,CAAcH,GAAd,CAAZ;AACA,uBAAO;AACHI,4BAAQH,MAAMI,SADX;AAEHC,6BAASL,MAAMM;AAFZ,iBAAP;AAIH,aAND,CAME,OAAO3H,CAAP,EAAU;AACR7E,yBAAIkF,KAAJ,CAAUL,CAAV;AACH;AACJ,SAbL;;AAAA,iBAeW4H,WAfX,wBAeuBR,GAfvB,EAe4BhB,GAf5B,EAeiCyB,MAfjC,EAeyCC,QAfzC,EAemDC,SAfnD,EAe8DC,GAf9D,EAemEC,eAfnE,EAeoF;AAC5E9M,qBAAI6B,KAAJ,CAAU,sBAAV;;AAEA,gBAAI;AACA,oBAAIoJ,IAAI8B,GAAJ,KAAY,KAAhB,EAAuB;AACnB,wBAAI9B,IAAIpG,CAAJ,IAASoG,IAAI+B,CAAjB,EAAoB;AAChB/B,8BAAMS,QAAQuB,MAAR,CAAehC,GAAf,CAAN;AACH,qBAFD,MAEO,IAAIA,IAAIiC,GAAJ,IAAWjC,IAAIiC,GAAJ,CAAQhE,MAAvB,EAA+B;AAClC,4BAAIiE,MAAMrB,SAASb,IAAIiC,GAAJ,CAAQ,CAAR,CAAT,CAAV;AACAjC,8BAAMU,KAAKyB,uBAAL,CAA6BD,GAA7B,CAAN;AACH,qBAHM,MAGA;AACHnN,iCAAIkF,KAAJ,CAAU,oDAAV,EAAgE+F,GAAhE;AACA,+BAAO7G,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,8BAAV,CAAf,CAAP;AACH;AACJ,iBAVD,MAUO,IAAI+C,IAAI8B,GAAJ,KAAY,IAAhB,EAAsB;AACzB,wBAAI9B,IAAIoC,GAAJ,IAAWpC,IAAIqC,CAAf,IAAoBrC,IAAIsC,CAA5B,EAA+B;AAC3BtC,8BAAMS,QAAQuB,MAAR,CAAehC,GAAf,CAAN;AACH,qBAFD,MAEO;AACHjL,iCAAIkF,KAAJ,CAAU,mDAAV,EAA+D+F,GAA/D;AACA,+BAAO7G,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACJ,iBAPM,MAOA;AACHlI,6BAAIkF,KAAJ,CAAU,4CAAV,EAAwD+F,OAAOA,IAAI8B,GAAnE;AACA,2BAAO3I,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,SAAkC+C,IAAI8B,GAAhD,CAAf,CAAP;AACH;;AAED,uBAAOS,SAASC,YAAT,CAAsBxB,GAAtB,EAA2BhB,GAA3B,EAAgCyB,MAAhC,EAAwCC,QAAxC,EAAkDC,SAAlD,EAA6DC,GAA7D,EAAkEC,eAAlE,CAAP;AACH,aAxBD,CAwBE,OAAOjI,CAAP,EAAU;AACR7E,yBAAIkF,KAAJ,CAAUL,KAAKA,EAAEmD,OAAP,IAAkBnD,CAA5B;AACA,uBAAOT,QAAQgC,MAAR,CAAe,uBAAf,CAAP;AACH;AACJ,SA9CL;;AAAA,iBAgDWsH,qBAhDX,kCAgDiCzB,GAhDjC,EAgDsCS,MAhDtC,EAgD8CC,QAhD9C,EAgDwDC,SAhDxD,EAgDmEC,GAhDnE,EAgDwEC,eAhDxE,EAgDyF;AACjF,gBAAI,CAACF,SAAL,EAAgB;AACZA,4BAAY,CAAZ;AACH;;AAED,gBAAI,CAACC,GAAL,EAAU;AACNA,sBAAMc,SAASC,KAAKf,GAAL,KAAa,IAAtB,CAAN;AACH;;AAED,gBAAIN,UAAUiB,SAASxB,QAAT,CAAkBC,GAAlB,EAAuBM,OAArC;;AAEA,gBAAI,CAACA,QAAQsB,GAAb,EAAkB;AACd7N,yBAAIkF,KAAJ,CAAU,gDAAV;AACA,uBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;AACD,gBAAIqE,QAAQsB,GAAR,KAAgBnB,MAApB,EAA4B;AACxB1M,yBAAIkF,KAAJ,CAAU,gDAAV,EAA4DqH,QAAQsB,GAApE;AACA,uBAAOzJ,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,8BAA8BqE,QAAQsB,GAAhD,CAAf,CAAP;AACH;;AAED,gBAAI,CAACtB,QAAQuB,GAAb,EAAkB;AACd9N,yBAAIkF,KAAJ,CAAU,6CAAV;AACA,uBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,gBAAI6F,gBAAgBxB,QAAQuB,GAAR,KAAgBnB,QAAhB,IAA6BqB,MAAMC,OAAN,CAAc1B,QAAQuB,GAAtB,KAA8BvB,QAAQuB,GAAR,CAAYxK,OAAZ,CAAoBqJ,QAApB,KAAiC,CAAhH;AACA,gBAAI,CAACoB,aAAL,EAAoB;AAChB/N,yBAAIkF,KAAJ,CAAU,kDAAV,EAA8DqH,QAAQuB,GAAtE;AACA,uBAAO1J,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,gCAAgCqE,QAAQuB,GAAlD,CAAf,CAAP;AACH;AACD,gBAAIvB,QAAQ2B,GAAR,IAAe3B,QAAQ2B,GAAR,KAAgBvB,QAAnC,EAA6C;AACzC3M,yBAAIkF,KAAJ,CAAU,6CAAV,EAAyDqH,QAAQ2B,GAAjE;AACA,uBAAO9J,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,2BAA2BqE,QAAQ2B,GAA7C,CAAf,CAAP;AACH;;AAED,gBAAI,CAACpB,eAAL,EAAsB;AAClB,oBAAIqB,WAAWtB,MAAMD,SAArB;AACA,oBAAIwB,WAAWvB,MAAMD,SAArB;;AAEA,oBAAI,CAACL,QAAQ8B,GAAb,EAAkB;AACdrO,6BAAIkF,KAAJ,CAAU,6CAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,oBAAIiG,WAAW5B,QAAQ8B,GAAvB,EAA4B;AACxBrO,6BAAIkF,KAAJ,CAAU,6CAAV,EAAyDqH,QAAQ8B,GAAjE;AACA,2BAAOjK,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,2BAA2BqE,QAAQ8B,GAA7C,CAAf,CAAP;AACH;;AAED,oBAAI9B,QAAQ+B,GAAR,IAAeH,WAAW5B,QAAQ+B,GAAtC,EAA2C;AACvCtO,6BAAIkF,KAAJ,CAAU,6CAAV,EAAyDqH,QAAQ+B,GAAjE;AACA,2BAAOlK,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,2BAA2BqE,QAAQ+B,GAA7C,CAAf,CAAP;AACH;;AAED,oBAAI,CAAC/B,QAAQgC,GAAb,EAAkB;AACdvO,6BAAIkF,KAAJ,CAAU,6CAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,oBAAIqE,QAAQgC,GAAR,GAAcH,QAAlB,EAA4B;AACxBpO,6BAAIkF,KAAJ,CAAU,2CAAV,EAAuDqH,QAAQgC,GAA/D;AACA,2BAAOnK,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,wBAAwBqE,QAAQgC,GAA1C,CAAf,CAAP;AACH;AACJ;;AAED,mBAAOnK,QAAQC,OAAR,CAAgBkI,OAAhB,CAAP;AACH,SA/GL;;AAAA,iBAiHWkB,YAjHX,yBAiHwBxB,GAjHxB,EAiH6BhB,GAjH7B,EAiHkCyB,MAjHlC,EAiH0CC,QAjH1C,EAiHoDC,SAjHpD,EAiH+DC,GAjH/D,EAiHoEC,eAjHpE,EAiHqF;;AAE7E,mBAAOU,SAASE,qBAAT,CAA+BzB,GAA/B,EAAoCS,MAApC,EAA4CC,QAA5C,EAAsDC,SAAtD,EAAiEC,GAAjE,EAAsEC,eAAtE,EAAuF0B,IAAvF,CAA4F,mBAAW;AAC1G,oBAAI;AACA,wBAAI,CAAC/C,IAAIU,GAAJ,CAAQsC,MAAR,CAAexC,GAAf,EAAoBhB,GAApB,EAAyBc,kBAAzB,CAAL,EAAmD;AAC/C/L,iCAAIkF,KAAJ,CAAU,oDAAV;AACA,+BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;;AAED,2BAAOqE,OAAP;AACH,iBAPD,CAOE,OAAO1H,CAAP,EAAU;AACR7E,6BAAIkF,KAAJ,CAAUL,KAAKA,EAAEmD,OAAP,IAAkBnD,CAA5B;AACA,2BAAOT,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACJ,aAZM,CAAP;AAaH,SAhIL;;AAAA,iBAkIWwG,UAlIX,uBAkIsBvD,KAlItB,EAkI6BwD,GAlI7B,EAkIkC;AAC1B,gBAAI;AACA,uBAAO/C,OAAOgD,IAAP,CAAYF,UAAZ,CAAuBvD,KAAvB,EAA8BwD,GAA9B,CAAP;AACH,aAFD,CAEE,OAAO9J,CAAP,EAAU;AACR7E,yBAAIkF,KAAJ,CAAUL,CAAV;AACH;AACJ,SAxIL;;AAAA,iBA0IWgK,cA1IX,2BA0I0B1D,KA1I1B,EA0IiC;AACzB,gBAAI;AACA,uBAAOU,UAAUV,KAAV,CAAP;AACH,aAFD,CAEE,OAAOtG,CAAP,EAAU;AACR7E,yBAAIkF,KAAJ,CAAUL,CAAV;AACH;AACJ,SAhJL;;AAAA;AAAA;AAkJH;;;;;;;;;;;;;;;;;;;;ACxJD;;AACA;;;;;;AAEO,IAAM2I,8BAAW,4BAAY,EAAE/B,aAAF,EAAOC,qBAAP,EAAgBC,eAAhB,EAAsBC,mBAAtB,EAA8BC,yBAA9B,EAAyCC,uBAAzC,EAAmDC,2CAAnD,EAAZ,CAAjB,C;;;;;;;;;;;;;;;;;;;ACAP;;AACA;;0JAJA;AACA;;IAKa+C,W,WAAAA,W;AACT,2BAIE;AAAA,YAHEC,sBAGF,uEAH2B,IAG3B;AAAA,YAFEC,kBAEF,uEAFuBnO,eAAOgJ,cAE9B;AAAA,YADEoF,UACF,uEADe,IACf;;AAAA;;AACE,YAAIF,0BAA0Bf,MAAMC,OAAN,CAAcc,sBAAd,CAA9B,EACA;AACI,iBAAKG,aAAL,GAAqBH,uBAAuBI,KAAvB,EAArB;AACH,SAHD,MAKA;AACI,iBAAKD,aAAL,GAAqB,EAArB;AACH;AACD,aAAKA,aAAL,CAAmBtG,IAAnB,CAAwB,kBAAxB;AACA,YAAIqG,UAAJ,EAAgB;AACZ,iBAAKC,aAAL,CAAmBtG,IAAnB,CAAwB,iBAAxB;AACH;;AAED,aAAKwG,eAAL,GAAuBJ,kBAAvB;AACA,aAAKK,WAAL,GAAmBJ,UAAnB;AACH;;0BAEDK,O,oBAAQzM,G,EAAKqJ,K,EAAO;AAAA;;AAChB,YAAI,CAACrJ,GAAL,EAAS;AACL7C,qBAAIkF,KAAJ,CAAU,oCAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,KAAV,CAAN;AACH;;AAEDlI,iBAAI6B,KAAJ,CAAU,4BAAV,EAAwCgB,GAAxC;;AAEA,eAAO,IAAIuB,OAAJ,CAAY,UAACC,OAAD,EAAU+B,MAAV,EAAqB;;AAEpC,gBAAImJ,MAAM,IAAI,MAAKH,eAAT,EAAV;AACAG,gBAAI/H,IAAJ,CAAS,KAAT,EAAgB3E,GAAhB;;AAEA,gBAAI2M,sBAAsB,MAAKN,aAA/B;AACA,gBAAID,aAAa,MAAKI,WAAtB;;AAEAE,gBAAIjL,MAAJ,GAAa,YAAW;AACpBtE,yBAAI6B,KAAJ,CAAU,qDAAV,EAAiE0N,IAAIE,MAArE;;AAEA,oBAAIF,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuBhH,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAI8G,SAAS,iBAAb,EAAgC;AAC5BX,uCAAWM,GAAX,EAAgBf,IAAhB,CAAqBnK,OAArB,EAA8B+B,MAA9B;AACA;AACH;;AAED,4BAAIwJ,KAAJ,EAAW;AACP,gCAAI;AACAvL,wCAAQ0L,KAAK3D,KAAL,CAAWmD,IAAIS,YAAf,CAAR;AACA;AACH,6BAHD,CAIA,OAAOnL,CAAP,EAAU;AACN7E,yCAAIkF,KAAJ,CAAU,kDAAV,EAA8DL,EAAEmD,OAAhE;AACA5B,uCAAOvB,CAAP;AACA;AACH;AACJ;AACJ;;AAEDuB,2BAAO8B,MAAM,oCAAoCwH,WAApC,GAAkD,cAAlD,GAAmE7M,GAAzE,CAAP;AACH,iBA9BD,MA+BK;AACDuD,2BAAO8B,MAAMqH,IAAIU,UAAJ,GAAiB,IAAjB,GAAwBV,IAAIE,MAA5B,GAAqC,GAA3C,CAAP;AACH;AACJ,aArCD;;AAuCAF,gBAAIW,OAAJ,GAAc,YAAW;AACrBlQ,yBAAIkF,KAAJ,CAAU,oCAAV;AACAkB,uBAAO8B,MAAM,eAAN,CAAP;AACH,aAHD;;AAKA,gBAAIgE,KAAJ,EAAW;AACPlM,yBAAI6B,KAAJ,CAAU,iEAAV;AACA0N,oBAAIY,gBAAJ,CAAqB,eAArB,EAAsC,YAAYjE,KAAlD;AACH;;AAEDqD,gBAAIhK,IAAJ;AACH,SA1DM,CAAP;AA2DH,K;;0BAED6K,Q,qBAASvN,G,EAAK0J,O,EAAS;AAAA;;AACnB,YAAI,CAAC1J,GAAL,EAAS;AACL7C,qBAAIkF,KAAJ,CAAU,qCAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,KAAV,CAAN;AACH;;AAEDlI,iBAAI6B,KAAJ,CAAU,6BAAV,EAAyCgB,GAAzC;;AAEA,eAAO,IAAIuB,OAAJ,CAAY,UAACC,OAAD,EAAU+B,MAAV,EAAqB;;AAEpC,gBAAImJ,MAAM,IAAI,OAAKH,eAAT,EAAV;AACAG,gBAAI/H,IAAJ,CAAS,MAAT,EAAiB3E,GAAjB;;AAEA,gBAAI2M,sBAAsB,OAAKN,aAA/B;;AAEAK,gBAAIjL,MAAJ,GAAa,YAAW;AACpBtE,yBAAI6B,KAAJ,CAAU,sDAAV,EAAkE0N,IAAIE,MAAtE;;AAEA,oBAAIF,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuBhH,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAI8G,KAAJ,EAAW;AACP,gCAAI;AACAvL,wCAAQ0L,KAAK3D,KAAL,CAAWmD,IAAIS,YAAf,CAAR;AACA;AACH,6BAHD,CAIA,OAAOnL,CAAP,EAAU;AACN7E,yCAAIkF,KAAJ,CAAU,mDAAV,EAA+DL,EAAEmD,OAAjE;AACA5B,uCAAOvB,CAAP;AACA;AACH;AACJ;AACJ;;AAEDuB,2BAAO8B,MAAM,oCAAoCwH,WAApC,GAAkD,cAAlD,GAAmE7M,GAAzE,CAAP;AACA;AACH;;AAED,oBAAI0M,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuBhH,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAI8G,KAAJ,EAAW;AACP,gCAAI;AACA,oCAAIrD,UAAUwD,KAAK3D,KAAL,CAAWmD,IAAIS,YAAf,CAAd;AACA,oCAAIzD,WAAWA,QAAQrH,KAAvB,EAA8B;AAC1BlF,6CAAIkF,KAAJ,CAAU,2CAAV,EAAuDqH,QAAQrH,KAA/D;AACAkB,2CAAO,IAAI8B,KAAJ,CAAUqE,QAAQrH,KAAlB,CAAP;AACA;AACH;AACJ,6BAPD,CAQA,OAAOL,CAAP,EAAU;AACN7E,yCAAIkF,KAAJ,CAAU,mDAAV,EAA+DL,EAAEmD,OAAjE;AACA5B,uCAAOvB,CAAP;AACA;AACH;AACJ;AACJ;AACJ;;AAEDuB,uBAAO8B,MAAMqH,IAAIU,UAAJ,GAAiB,IAAjB,GAAwBV,IAAIE,MAA5B,GAAqC,GAA3C,CAAP;AACH,aA7DD;;AA+DAF,gBAAIW,OAAJ,GAAc,YAAW;AACrBlQ,yBAAIkF,KAAJ,CAAU,qCAAV;AACAkB,uBAAO8B,MAAM,eAAN,CAAP;AACH,aAHD;;AAKA,gBAAI3D,OAAO,EAAX;AACA,iBAAI,IAAI0G,GAAR,IAAesB,OAAf,EAAwB;;AAEpB,oBAAIpB,QAAQoB,QAAQtB,GAAR,CAAZ;;AAEA,oBAAIE,KAAJ,EAAW;;AAEP,wBAAI5G,KAAK2E,MAAL,GAAc,CAAlB,EAAqB;AACjB3E,gCAAQ,GAAR;AACH;;AAEDA,4BAAQ8L,mBAAmBpF,GAAnB,CAAR;AACA1G,4BAAQ,GAAR;AACAA,4BAAQ8L,mBAAmBlF,KAAnB,CAAR;AACH;AACJ;;AAEDoE,gBAAIY,gBAAJ,CAAqB,cAArB,EAAqC,mCAArC;AACAZ,gBAAIhK,IAAJ,CAAShB,IAAT;AACH,SA9FM,CAAP;AA+FH,K;;;;;;;;;;;;;;;;;;;;;;;;;ACzML;AACA;;AAEA,IAAI+L,YAAY;AACZzO,SADY,mBACL,CAAE,CADG;AAEZ0O,QAFY,kBAEN,CAAE,CAFI;AAGZC,QAHY,kBAGN,CAAE,CAHI;AAIZtL,SAJY,mBAIL,CAAE;AAJG,CAAhB;;AAOA,IAAMuL,OAAO,CAAb;AACA,IAAMC,QAAQ,CAAd;AACA,IAAMC,OAAO,CAAb;AACA,IAAMC,OAAO,CAAb;AACA,IAAMC,QAAQ,CAAd;;AAEA,IAAIC,eAAJ;AACA,IAAIC,cAAJ;;IAEa/Q,G,WAAAA,G;;;;;QAOFgR,K,oBAAO;AACVD,gBAAQH,IAAR;AACAE,iBAASR,SAAT;AACH,K;;QA+BMzO,K,oBAAc;AACjB,YAAIkP,SAASF,KAAb,EAAmB;AAAA,8CADPI,IACO;AADPA,oBACO;AAAA;;AACfH,mBAAOjP,KAAP,CAAaqP,KAAb,CAAmBJ,MAAnB,EAA2B9C,MAAMmD,IAAN,CAAWF,IAAX,CAA3B;AACH;AACJ,K;;QACMV,I,mBAAa;AAChB,YAAIQ,SAASH,IAAb,EAAkB;AAAA,+CADPK,IACO;AADPA,oBACO;AAAA;;AACdH,mBAAOP,IAAP,CAAYW,KAAZ,CAAkBJ,MAAlB,EAA0B9C,MAAMmD,IAAN,CAAWF,IAAX,CAA1B;AACH;AACJ,K;;QACMT,I,mBAAa;AAChB,YAAIO,SAASJ,IAAb,EAAkB;AAAA,+CADPM,IACO;AADPA,oBACO;AAAA;;AACdH,mBAAON,IAAP,CAAYU,KAAZ,CAAkBJ,MAAlB,EAA0B9C,MAAMmD,IAAN,CAAWF,IAAX,CAA1B;AACH;AACJ,K;;QACM/L,K,oBAAc;AACjB,YAAI6L,SAASL,KAAb,EAAmB;AAAA,+CADPO,IACO;AADPA,oBACO;AAAA;;AACfH,mBAAO5L,KAAP,CAAagM,KAAb,CAAmBJ,MAAnB,EAA2B9C,MAAMmD,IAAN,CAAWF,IAAX,CAA3B;AACH;AACJ,K;;;;4BA3DiB;AAAC,mBAAOR,IAAP;AAAY;;;4BACZ;AAAC,mBAAOC,KAAP;AAAa;;;4BACf;AAAC,mBAAOC,IAAP;AAAY;;;4BACb;AAAC,mBAAOC,IAAP;AAAY;;;4BACZ;AAAC,mBAAOC,KAAP;AAAa;;;4BAOf;AACd,mBAAOE,KAAP;AACH,S;0BACgB5F,K,EAAM;AACnB,gBAAIsF,QAAQtF,KAAR,IAAiBA,SAAS0F,KAA9B,EAAoC;AAChCE,wBAAQ5F,KAAR;AACH,aAFD,MAGK;AACD,sBAAM,IAAIjD,KAAJ,CAAU,mBAAV,CAAN;AACH;AACJ;;;4BAEkB;AACf,mBAAO4I,MAAP;AACH,S;0BACiB3F,K,EAAM;AACpB,gBAAI,CAACA,MAAMtJ,KAAP,IAAgBsJ,MAAMoF,IAA1B,EAAgC;AAC5B;AACApF,sBAAMtJ,KAAN,GAAcsJ,MAAMoF,IAApB;AACH;;AAED,gBAAIpF,MAAMtJ,KAAN,IAAesJ,MAAMoF,IAArB,IAA6BpF,MAAMqF,IAAnC,IAA2CrF,MAAMjG,KAArD,EAA2D;AACvD4L,yBAAS3F,KAAT;AACH,aAFD,MAGK;AACD,sBAAM,IAAIjD,KAAJ,CAAU,gBAAV,CAAN;AACH;AACJ;;;;;;AAwBLlI,IAAIgR,KAAJ,G;;;;;;;;;;;;;;;;;;;qjBClFA;AACA;;AAEA;;AACA;;;;AAEA,IAAMI,sBAAsB,kCAA5B;;IAEa7Q,e,WAAAA,e;AACT,6BAAY8Q,QAAZ,EAAqD;AAAA,YAA/BC,eAA+B,uEAAbxC,wBAAa;;AAAA;;AACjD,YAAI,CAACuC,QAAL,EAAe;AACXrR,qBAAIkF,KAAJ,CAAU,wDAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKqJ,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,CAAoB,CAAC,0BAAD,CAApB,CAApB;AACH;;8BAsBDG,W,0BAAc;AAAA;;AACV,YAAI,KAAKF,SAAL,CAAelK,QAAnB,EAA6B;AACzBrH,qBAAI6B,KAAJ,CAAU,+DAAV;AACA,mBAAOuC,QAAQC,OAAR,CAAgB,KAAKkN,SAAL,CAAelK,QAA/B,CAAP;AACH;;AAED,YAAI,CAAC,KAAKqK,WAAV,EAAuB;AACnB1R,qBAAIkF,KAAJ,CAAU,iFAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,oDAAV,CAAf,CAAP;AACH;;AAEDlI,iBAAI6B,KAAJ,CAAU,oDAAV,EAAgE,KAAK6P,WAArE;;AAEA,eAAO,KAAKF,YAAL,CAAkBlC,OAAlB,CAA0B,KAAKoC,WAA/B,EACFlD,IADE,CACG,oBAAY;AACdxO,qBAAI6B,KAAJ,CAAU,4CAAV;AACA,kBAAK0P,SAAL,CAAelK,QAAf,GAA0BA,QAA1B;AACA,mBAAOA,QAAP;AACH,SALE,CAAP;AAMH,K;;8BAEDsK,S,wBAAY;AACR,eAAO,KAAKC,oBAAL,CAA0B,QAA1B,CAAP;AACH,K;;8BAEDC,wB,uCAA2B;AACvB,eAAO,KAAKD,oBAAL,CAA0B,wBAA1B,CAAP;AACH,K;;8BAEDE,mB,kCAAsB;AAClB,eAAO,KAAKF,oBAAL,CAA0B,mBAA1B,CAAP;AACH,K;;8BAEDG,gB,+BAAgC;AAAA,YAAfC,QAAe,uEAAN,IAAM;;AAC5B,eAAO,KAAKJ,oBAAL,CAA0B,gBAA1B,EAA4CI,QAA5C,CAAP;AACH,K;;8BAEDC,qB,oCAAwB;AACpB,eAAO,KAAKL,oBAAL,CAA0B,sBAA1B,EAAkD,IAAlD,CAAP;AACH,K;;8BAEDM,qB,oCAAwB;AACpB,eAAO,KAAKN,oBAAL,CAA0B,sBAA1B,EAAkD,IAAlD,CAAP;AACH,K;;8BAEDO,qB,oCAAwB;AACpB,eAAO,KAAKP,oBAAL,CAA0B,qBAA1B,EAAiD,IAAjD,CAAP;AACH,K;;8BAEDQ,e,8BAAkB;AACd,eAAO,KAAKR,oBAAL,CAA0B,UAA1B,EAAsC,IAAtC,CAAP;AACH,K;;8BAEDA,oB,iCAAqB7K,I,EAAsB;AAAA,YAAhBiL,QAAgB,uEAAP,KAAO;;AACvChS,iBAAI6B,KAAJ,CAAU,8CAA8CkF,IAAxD;;AAEA,eAAO,KAAK0K,WAAL,GAAmBjD,IAAnB,CAAwB,oBAAY;AACvCxO,qBAAI6B,KAAJ,CAAU,wDAAV;;AAEA,gBAAIwF,SAASN,IAAT,MAAmBpF,SAAvB,EAAkC;;AAE9B,oBAAIqQ,aAAa,IAAjB,EAAuB;AACnBhS,6BAAIwQ,IAAJ,CAAS,sFAAsFzJ,IAA/F;AACA,2BAAOpF,SAAP;AACH,iBAHD,MAIK;AACD3B,6BAAIkF,KAAJ,CAAU,6EAA6E6B,IAAvF;AACA,0BAAM,IAAImB,KAAJ,CAAU,wCAAwCnB,IAAlD,CAAN;AACH;AACJ;;AAED,mBAAOM,SAASN,IAAT,CAAP;AACH,SAhBM,CAAP;AAiBH,K;;8BAEDsL,c,6BAAiB;AAAA;;AACb,YAAI,KAAKd,SAAL,CAAee,WAAnB,EAAgC;AAC5BtS,qBAAI6B,KAAJ,CAAU,qEAAV;AACA,mBAAOuC,QAAQC,OAAR,CAAgB,KAAKkN,SAAL,CAAee,WAA/B,CAAP;AACH;;AAED,eAAO,KAAKV,oBAAL,CAA0B,UAA1B,EAAsCpD,IAAtC,CAA2C,oBAAY;AAC1DxO,qBAAI6B,KAAJ,CAAU,mDAAV,EAA+D0Q,QAA/D;;AAEA,mBAAO,OAAKf,YAAL,CAAkBlC,OAAlB,CAA0BiD,QAA1B,EAAoC/D,IAApC,CAAyC,kBAAU;AACtDxO,yBAAI6B,KAAJ,CAAU,kDAAV,EAA8D2Q,MAA9D;;AAEA,oBAAI,CAACA,OAAOC,IAAZ,EAAkB;AACdzS,6BAAIkF,KAAJ,CAAU,wDAAV;AACA,0BAAM,IAAIgD,KAAJ,CAAU,wBAAV,CAAN;AACH;;AAED,uBAAKqJ,SAAL,CAAee,WAAf,GAA6BE,OAAOC,IAApC;AACA,uBAAO,OAAKlB,SAAL,CAAee,WAAtB;AACH,aAVM,CAAP;AAWH,SAdM,CAAP;AAeH,K;;;;4BApHiB;AACd,gBAAI,CAAC,KAAKI,YAAV,EAAwB;AACpB,oBAAI,KAAKnB,SAAL,CAAeG,WAAnB,EAAgC;AAC5B,yBAAKgB,YAAL,GAAoB,KAAKnB,SAAL,CAAeG,WAAnC;AACH,iBAFD,MAGK;AACD,yBAAKgB,YAAL,GAAoB,KAAKnB,SAAL,CAAeoB,SAAnC;;AAEA,wBAAI,KAAKD,YAAL,IAAqB,KAAKA,YAAL,CAAkBpP,OAAlB,CAA0B8N,mBAA1B,IAAiD,CAA1E,EAA6E;AACzE,4BAAI,KAAKsB,YAAL,CAAkB,KAAKA,YAAL,CAAkBxJ,MAAlB,GAA2B,CAA7C,MAAoD,GAAxD,EAA6D;AACzD,iCAAKwJ,YAAL,IAAqB,GAArB;AACH;AACD,6BAAKA,YAAL,IAAqBtB,mBAArB;AACH;AACJ;AACJ;;AAED,mBAAO,KAAKsB,YAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBCrCL;AACA;;AAEA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;IAEazS,U,WAAAA,U;AACT,0BAA2B;AAAA,YAAfoR,QAAe,uEAAJ,EAAI;;AAAA;;AACvB,YAAIA,oBAAoBnR,sCAAxB,EAA4C;AACxC,iBAAKqR,SAAL,GAAiBF,QAAjB;AACH,SAFD,MAGK;AACD,iBAAKE,SAAL,GAAiB,IAAIrR,sCAAJ,CAAuBmR,QAAvB,CAAjB;AACH;AACJ;;yBAmBDuB,mB,kCAQE;AAAA;;AAAA,uFAFoH,EAEpH;AAAA,YAPEC,aAOF,QAPEA,aAOF;AAAA,YAPiBC,KAOjB,QAPiBA,KAOjB;AAAA,YAPwBpM,YAOxB,QAPwBA,YAOxB;AAAA,YAHEzB,IAGF,QAHEA,IAGF;AAAA,YAHQuD,KAGR,QAHQA,KAGR;AAAA,YAHeuK,MAGf,QAHeA,MAGf;AAAA,YAHuB/O,OAGvB,QAHuBA,OAGvB;AAAA,YAHgCgP,OAGhC,QAHgCA,OAGhC;AAAA,YAHyCC,UAGzC,QAHyCA,UAGzC;AAAA,YAHqDC,aAGrD,QAHqDA,aAGrD;AAAA,YAHoEC,UAGpE,QAHoEA,UAGpE;AAAA,YAHgFC,UAGhF,QAHgFA,UAGhF;AAAA,YAFEC,QAEF,QAFEA,QAEF;AAAA,YAFY/J,OAEZ,QAFYA,OAEZ;AAAA,YAFqBgK,WAErB,QAFqBA,WAErB;AAAA,YAFkCC,aAElC,QAFkCA,aAElC;AAAA,YAFiDC,gBAEjD,QAFiDA,gBAEjD;AAAA,YAFmEC,gBAEnE,QAFmEA,gBAEnE;AAAA,YAFqFC,YAErF,QAFqFA,YAErF;AAAA,YAFmGC,YAEnG,QAFmGA,YAEnG;;AAAA,YADEC,UACF;;AACE5T,iBAAI6B,KAAJ,CAAU,gCAAV;;AAEA,YAAIe,YAAY,KAAK2O,SAAL,CAAe3O,SAA/B;AACAiQ,wBAAgBA,iBAAiB,KAAKtB,SAAL,CAAesB,aAAhD;AACAC,gBAAQA,SAAS,KAAKvB,SAAL,CAAeuB,KAAhC;AACApM,uBAAeA,gBAAgB,KAAK6K,SAAL,CAAe7K,YAA9C;;AAEA;AACAqM,iBAASA,UAAU,KAAKxB,SAAL,CAAewB,MAAlC;AACA/O,kBAAUA,WAAW,KAAKuN,SAAL,CAAevN,OAApC;AACAgP,kBAAUA,WAAW,KAAKzB,SAAL,CAAeyB,OAApC;AACAC,qBAAaA,cAAc,KAAK1B,SAAL,CAAe0B,UAA1C;AACAG,qBAAaA,cAAc,KAAK7B,SAAL,CAAe6B,UAA1C;AACAC,mBAAWA,YAAY,KAAK9B,SAAL,CAAe8B,QAAtC;AACAE,wBAAgBA,iBAAiB,KAAKhC,SAAL,CAAegC,aAAhD;AACAC,2BAAmBA,oBAAoB,KAAKjC,SAAL,CAAeiC,gBAAtD;AACAC,2BAAmBA,oBAAoB,KAAKlC,SAAL,CAAekC,gBAAtD;;AAEA,YAAId,YAAY,KAAKpB,SAAL,CAAeoB,SAA/B;;AAEA,YAAIkB,6BAAcC,MAAd,CAAqBjB,aAArB,KAAuCA,kBAAkB,MAA7D,EAAqE;AACjE,mBAAOzO,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,6CAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAK6L,gBAAL,CAAsBlC,wBAAtB,GAAiDrD,IAAjD,CAAsD,eAAO;AAChExO,qBAAI6B,KAAJ,CAAU,iEAAV,EAA6EgB,GAA7E;;AAEA,gBAAImR,gBAAgB,IAAIH,4BAAJ,CAAkB;AAClChR,wBADkC;AAElCD,oCAFkC;AAGlC8D,0CAHkC;AAIlCmM,4CAJkC;AAKlCC,4BALkC;AAMlC7N,sBAAMA,QAAQuD,KANoB;AAOlCmK,oCAPkC;AAQlCI,8BARkC,EAQ1B/O,gBAR0B,EAQjBgP,gBARiB,EAQRC,sBARQ,EAQIC,4BARJ,EAQmBC,sBARnB,EAQ+BC,sBAR/B;AASlCC,kCATkC,EASxB/J,gBATwB,EASfgK,wBATe,EASFE,kCATE,EASgBC,kCAThB,EASkCC,0BATlC,EASgDH,4BAThD;AAUlCU,+BAAe,MAAK1C,SAAL,CAAe0C,aAVI;AAWlCN;AAXkC,aAAlB,CAApB;;AAcA,gBAAIO,cAAcF,cAAcxL,KAAhC;AACAoL,yBAAaA,cAAc,MAAKO,WAAhC;;AAEA,mBAAOP,WAAWQ,GAAX,CAAeF,YAAYG,EAA3B,EAA+BH,YAAYI,eAAZ,EAA/B,EAA8D9F,IAA9D,CAAmE,YAAM;AAC5E,uBAAOwF,aAAP;AACH,aAFM,CAAP;AAGH,SAvBM,CAAP;AAwBH,K;;yBAEDO,uB,oCAAwB1R,G,EAAK+Q,U,EAAiC;AAAA,YAArBY,WAAqB,uEAAP,KAAO;;AAC1DxU,iBAAI6B,KAAJ,CAAU,oCAAV;;AAEA,YAAI4S,WAAW,KAAKlD,SAAL,CAAegC,aAAf,KAAiC,OAAjC,IACV,CAAC,KAAKhC,SAAL,CAAegC,aAAhB,IAAiCM,6BAAcC,MAAd,CAAqB,KAAKvC,SAAL,CAAesB,aAApC,CADtC;AAEA,YAAI6B,YAAYD,WAAW,GAAX,GAAiB,GAAjC;;AAEA,YAAIE,WAAW,IAAIC,8BAAJ,CAAmB/R,GAAnB,EAAwB6R,SAAxB,CAAf;;AAEA,YAAI,CAACC,SAASnM,KAAd,EAAqB;AACjBxI,qBAAIkF,KAAJ,CAAU,0DAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAED0L,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,YAAIU,WAAWL,cAAcZ,WAAWkB,MAAX,CAAkBnQ,IAAlB,CAAuBiP,UAAvB,CAAd,GAAmDA,WAAWmB,GAAX,CAAepQ,IAAf,CAAoBiP,UAApB,CAAlE;;AAEA,eAAOiB,SAASF,SAASnM,KAAlB,EAAyBgG,IAAzB,CAA8B,6BAAqB;AACtD,gBAAI,CAACwG,iBAAL,EAAwB;AACpBhV,yBAAIkF,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAIgD,KAAJ,CAAU,oCAAV,CAAN;AACH;;AAED,gBAAIM,QAAQyM,yBAAYC,iBAAZ,CAA8BF,iBAA9B,CAAZ;AACA,mBAAO,EAACxM,YAAD,EAAQmM,kBAAR,EAAP;AACH,SARM,CAAP;AASH,K;;yBAEDQ,qB,kCAAsBtS,G,EAAK+Q,U,EAAY;AAAA;;AACnC5T,iBAAI6B,KAAJ,CAAU,kCAAV;;AAEA,eAAO,KAAK0S,uBAAL,CAA6B1R,GAA7B,EAAkC+Q,UAAlC,EAA8C,IAA9C,EAAoDpF,IAApD,CAAyD,iBAAuB;AAAA,gBAArBhG,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmM,QAAc,SAAdA,QAAc;;AACnF3U,qBAAI6B,KAAJ,CAAU,oFAAV;AACA,mBAAO,OAAKuT,UAAL,CAAgBC,sBAAhB,CAAuC7M,KAAvC,EAA8CmM,QAA9C,CAAP;AACH,SAHM,CAAP;AAIH,K;;yBAEDW,oB,mCAEE;AAAA;;AAAA,wFAF6G,EAE7G;AAAA,YAFoBpC,aAEpB,SAFoBA,aAEpB;AAAA,YAFmCjO,IAEnC,SAFmCA,IAEnC;AAAA,YAFyCuD,KAEzC,SAFyCA,KAEzC;AAAA,YAFgD+M,wBAEhD,SAFgDA,wBAEhD;AAAA,YAF0E/B,gBAE1E,SAF0EA,gBAE1E;AAAA,YAF4FE,YAE5F,SAF4FA,YAE5F;;AAAA,YADEE,UACF;;AACE5T,iBAAI6B,KAAJ,CAAU,iCAAV;;AAEA0T,mCAA2BA,4BAA4B,KAAKhE,SAAL,CAAegE,wBAAtE;AACA/B,2BAAmBA,oBAAoB,KAAKjC,SAAL,CAAeiC,gBAAtD;;AAEA,eAAO,KAAKO,gBAAL,CAAsB7B,qBAAtB,GAA8C1D,IAA9C,CAAmD,eAAO;AAC7D,gBAAI,CAAC3L,GAAL,EAAU;AACN7C,yBAAIkF,KAAJ,CAAU,uEAAV;AACA,sBAAM,IAAIgD,KAAJ,CAAU,yBAAV,CAAN;AACH;;AAEDlI,qBAAI6B,KAAJ,CAAU,gEAAV,EAA4EgB,GAA5E;;AAEA,gBAAIyG,UAAU,IAAIkM,8BAAJ,CAAmB;AAC7B3S,wBAD6B;AAE7BqQ,4CAF6B;AAG7BqC,kEAH6B;AAI7BtQ,sBAAMA,QAAQuD,KAJe;AAK7BgL,kDAL6B;AAM7BE;AAN6B,aAAnB,CAAd;;AASA,gBAAI+B,eAAenM,QAAQd,KAA3B;AACA,gBAAIiN,YAAJ,EAAkB;AACdzV,yBAAI6B,KAAJ,CAAU,uEAAV;;AAEA+R,6BAAaA,cAAc,OAAKO,WAAhC;AACAP,2BAAWQ,GAAX,CAAeqB,aAAapB,EAA5B,EAAgCoB,aAAanB,eAAb,EAAhC;AACH;;AAED,mBAAOhL,OAAP;AACH,SA1BM,CAAP;AA2BH,K;;yBAEDoM,wB,qCAAyB7S,G,EAAK+Q,U,EAAiC;AAAA,YAArBY,WAAqB,uEAAP,KAAO;;AAC3DxU,iBAAI6B,KAAJ,CAAU,qCAAV;;AAEA,YAAI8S,WAAW,IAAIgB,gCAAJ,CAAoB9S,GAApB,CAAf;AACA,YAAI,CAAC8R,SAASnM,KAAd,EAAqB;AACjBxI,qBAAI6B,KAAJ,CAAU,2DAAV;;AAEA,gBAAI8S,SAASzP,KAAb,EAAoB;AAChBlF,yBAAIwQ,IAAJ,CAAS,2DAAT,EAAsEmE,SAASzP,KAA/E;AACA,uBAAOd,QAAQgC,MAAR,CAAe,IAAIiC,4BAAJ,CAAkBsM,QAAlB,CAAf,CAAP;AACH;;AAED,mBAAOvQ,QAAQC,OAAR,CAAgB,EAAC1C,oBAAD,EAAYgT,kBAAZ,EAAhB,CAAP;AACH;;AAED,YAAIiB,WAAWjB,SAASnM,KAAxB;;AAEAoL,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,YAAIU,WAAWL,cAAcZ,WAAWkB,MAAX,CAAkBnQ,IAAlB,CAAuBiP,UAAvB,CAAd,GAAmDA,WAAWmB,GAAX,CAAepQ,IAAf,CAAoBiP,UAApB,CAAlE;AACA,eAAOiB,SAASe,QAAT,EAAmBpH,IAAnB,CAAwB,6BAAqB;AAChD,gBAAI,CAACwG,iBAAL,EAAwB;AACpBhV,yBAAIkF,KAAJ,CAAU,yEAAV;AACA,sBAAM,IAAIgD,KAAJ,CAAU,oCAAV,CAAN;AACH;;AAED,gBAAIM,QAAQqN,aAAMX,iBAAN,CAAwBF,iBAAxB,CAAZ;;AAEA,mBAAO,EAACxM,YAAD,EAAQmM,kBAAR,EAAP;AACH,SATM,CAAP;AAUH,K;;yBAEDmB,sB,mCAAuBjT,G,EAAK+Q,U,EAAY;AAAA;;AACpC5T,iBAAI6B,KAAJ,CAAU,mCAAV;;AAEA,eAAO,KAAK6T,wBAAL,CAA8B7S,GAA9B,EAAmC+Q,UAAnC,EAA+C,IAA/C,EAAqDpF,IAArD,CAA0D,iBAAuB;AAAA,gBAArBhG,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmM,QAAc,SAAdA,QAAc;;AACpF,gBAAInM,KAAJ,EAAW;AACPxI,yBAAI6B,KAAJ,CAAU,qFAAV;AACA,uBAAO,OAAKuT,UAAL,CAAgBW,uBAAhB,CAAwCvN,KAAxC,EAA+CmM,QAA/C,CAAP;AACH,aAHD,MAIK;AACD3U,yBAAI6B,KAAJ,CAAU,wFAAV;AACA,uBAAO8S,QAAP;AACH;AACJ,SATM,CAAP;AAUH,K;;yBAEDqB,e,4BAAgBpC,U,EAAY;AACxB5T,iBAAI6B,KAAJ,CAAU,4BAAV;;AAEA+R,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,eAAO0B,aAAMG,eAAN,CAAsBpC,UAAtB,EAAkC,KAAKvC,QAAL,CAAc4E,aAAhD,CAAP;AACH,K;;;;4BA5MiB;AACd,mBAAO,KAAK5E,QAAL,CAAcuC,UAArB;AACH;;;4BACgB;AACb,mBAAO,KAAKvC,QAAL,CAAc6E,SAArB;AACH;;;4BACsB;AACnB,mBAAO,KAAK7E,QAAL,CAAc8E,eAArB;AACH;;;4BAEc;AACX,mBAAO,KAAK5E,SAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKwC,gBAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;;;qjBCtCL;AACA;;AAEA;;AACA;;AACA;;AACA;;;;AAEA,IAAM3C,sBAAsB,kCAA5B;;AAEA,IAAMgF,sBAAsB,UAA5B;AACA,IAAMC,eAAe,QAArB;AACA,IAAMC,uBAAuB,KAAK,EAAlC,C,CAAsC;AACtC,IAAMC,4BAA4B,KAAK,CAAvC;;IAEarW,kB,WAAAA,kB;AACT,kCAmBQ;AAAA,uFAAJ,EAAI;AAAA,YAjBJyS,SAiBI,QAjBJA,SAiBI;AAAA,YAjBOjB,WAiBP,QAjBOA,WAiBP;AAAA,YAjBoBrK,QAiBpB,QAjBoBA,QAiBpB;AAAA,YAjB8BiL,WAiB9B,QAjB8BA,WAiB9B;AAAA,YAfJ1P,SAeI,QAfJA,SAeI;AAAA,YAfOqR,aAeP,QAfOA,aAeP;AAAA,sCAfsBpB,aAetB;AAAA,YAfsBA,aAetB,sCAfsCuD,mBAetC;AAAA,8BAf2DtD,KAe3D;AAAA,YAf2DA,KAe3D,8BAfmEuD,YAenE;AAAA,YAdJ3P,YAcI,QAdJA,YAcI;AAAA,YAdU6O,wBAcV,QAdUA,wBAcV;AAAA,YAZJxC,MAYI,QAZJA,MAYI;AAAA,YAZI/O,OAYJ,QAZIA,OAYJ;AAAA,YAZagP,OAYb,QAZaA,OAYb;AAAA,YAZsBC,UAYtB,QAZsBA,UAYtB;AAAA,YAZkCG,UAYlC,QAZkCA,UAYlC;AAAA,YAZ8CC,QAY9C,QAZ8CA,QAY9C;AAAA,YAZwDE,aAYxD,QAZwDA,aAYxD;AAAA,yCAVJiD,oBAUI;AAAA,YAVJA,oBAUI,yCAVmB,IAUnB;AAAA,qCAVyBC,YAUzB;AAAA,YAVyBA,YAUzB,qCAVwC,IAUxC;AAAA,sCATJR,aASI;AAAA,YATJA,aASI,sCATYK,oBASZ;AAAA,kCATkC1J,SASlC;AAAA,YATkCA,SASlC,kCAT8C2J,yBAS9C;AAAA,yCARJG,iBAQI;AAAA,YARJA,iBAQI,yCARgB,IAQhB;AAAA,mCANJ9C,UAMI;AAAA,YANJA,UAMI,mCANS,IAAIzT,0CAAJ,EAMT;AAAA,yCALJwW,qBAKI;AAAA,YALJA,qBAKI,yCALoBC,oCAKpB;AAAA,yCAJJC,mBAII;AAAA,YAJJA,mBAII,yCAJkBtW,gCAIlB;AAAA,yCAFJiT,gBAEI;AAAA,YAFJA,gBAEI,yCAFe,EAEf;AAAA,yCADJC,gBACI;AAAA,YADJA,gBACI,yCADe,EACf;;AAAA;;AAEJ,aAAKqD,UAAL,GAAkBnE,SAAlB;AACA,aAAKD,YAAL,GAAoBhB,WAApB;AACA,aAAKqF,SAAL,GAAiB1P,QAAjB;AACA,aAAK2P,YAAL,GAAoB1E,WAApB;;AAEA,aAAKrP,UAAL,GAAkBL,SAAlB;AACA,aAAKqU,cAAL,GAAsBhD,aAAtB;AACA,aAAKiD,cAAL,GAAsBrE,aAAtB;AACA,aAAKsE,MAAL,GAAcrE,KAAd;AACA,aAAKsE,aAAL,GAAqB1Q,YAArB;AACA,aAAK2Q,yBAAL,GAAiC9B,wBAAjC;;AAEA,aAAK+B,OAAL,GAAevE,MAAf;AACA,aAAKwE,QAAL,GAAgBvT,OAAhB;AACA,aAAKwT,QAAL,GAAgBxE,OAAhB;AACA,aAAKyE,WAAL,GAAmBxE,UAAnB;AACA,aAAKyE,WAAL,GAAmBtE,UAAnB;AACA,aAAKuE,SAAL,GAAiBtE,QAAjB;AACA,aAAKuE,cAAL,GAAsBrE,aAAtB;;AAEA,aAAKsE,qBAAL,GAA6B,CAAC,CAACrB,oBAA/B;AACA,aAAKsB,aAAL,GAAqB,CAAC,CAACrB,YAAvB;AACA,aAAKsB,cAAL,GAAsB9B,aAAtB;AACA,aAAK+B,UAAL,GAAkBpL,SAAlB;AACA,aAAKqL,kBAAL,GAA0BvB,iBAA1B;;AAEA,aAAKvC,WAAL,GAAmBP,UAAnB;AACA,aAAKwB,UAAL,GAAkB,IAAIuB,qBAAJ,CAA0B,IAA1B,CAAlB;AACA,aAAK5C,gBAAL,GAAwB,IAAI8C,mBAAJ,CAAwB,IAAxB,CAAxB;;AAEA,aAAKqB,iBAAL,GAAyB,QAAO1E,gBAAP,yCAAOA,gBAAP,OAA4B,QAA5B,GAAuCA,gBAAvC,GAA0D,EAAnF;AACA,aAAK2E,iBAAL,GAAyB,QAAO1E,gBAAP,yCAAOA,gBAAP,OAA4B,QAA5B,GAAuCA,gBAAvC,GAA0D,EAAnF;AACH;;AAED;;;;;4BACgB;AACZ,mBAAO,KAAKxQ,UAAZ;AACH,S;0BACakI,K,EAAO;AACjB,gBAAI,CAAC,KAAKlI,UAAV,EAAsB;AAClB;AACA,qBAAKA,UAAL,GAAkBkI,KAAlB;AACH,aAHD,MAIK;AACDnL,yBAAIkF,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAIgD,KAAJ,CAAU,sCAAV,CAAN;AACH;AACJ;;;4BACmB;AAChB,mBAAO,KAAK+O,cAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;;4BACW;AACR,mBAAO,KAAKC,MAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKC,yBAAZ;AACH;;AAGD;;;;4BACa;AACT,mBAAO,KAAKC,OAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKC,QAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKC,QAAZ;AACH;;;4BACgB;AACb,mBAAO,KAAKC,WAAZ;AACH;;;4BACgB;AACb,mBAAO,KAAKC,WAAZ;AACH;;;4BACc;AACX,mBAAO,KAAKC,SAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;AAGD;;;;4BACgB;AACZ,mBAAO,KAAKd,UAAZ;AACH,S;0BACa3L,K,EAAO;AACjB,gBAAI,CAAC,KAAK2L,UAAV,EAAsB;AAClB;AACA,qBAAKA,UAAL,GAAkB3L,KAAlB;AACH,aAHD,MAIK;AACDnL,yBAAIkF,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAIgD,KAAJ,CAAU,sCAAV,CAAN;AACH;AACJ;;;4BACiB;AACd,gBAAI,CAAC,KAAKwK,YAAV,EAAwB;AACpB,qBAAKA,YAAL,GAAoB,KAAKC,SAAzB;;AAEA,oBAAI,KAAKD,YAAL,IAAqB,KAAKA,YAAL,CAAkBpP,OAAlB,CAA0B8N,mBAA1B,IAAiD,CAA1E,EAA6E;AACzE,wBAAI,KAAKsB,YAAL,CAAkB,KAAKA,YAAL,CAAkBxJ,MAAlB,GAA2B,CAA7C,MAAoD,GAAxD,EAA6D;AACzD,6BAAKwJ,YAAL,IAAqB,GAArB;AACH;AACD,yBAAKA,YAAL,IAAqBtB,mBAArB;AACH;AACJ;;AAED,mBAAO,KAAKsB,YAAZ;AACH;;AAED;;;;4BACe;AACX,mBAAO,KAAKqE,SAAZ;AACH,S;0BACY5L,K,EAAO;AAChB,iBAAK4L,SAAL,GAAiB5L,KAAjB;AACH;;;4BAEiB;AACd,mBAAO,KAAK6L,YAAZ;AACH,S;0BACe7L,K,EAAO;AACnB,iBAAK6L,YAAL,GAAoB7L,KAApB;AACH;;AAED;;;;4BAC2B;AACvB,mBAAO,KAAK0M,qBAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKC,UAAZ;AACH;;;4BACuB;AACpB,mBAAO,KAAKC,kBAAZ;AACH;;;4BAEgB;AACb,mBAAO,KAAK9D,WAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKiB,UAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKrB,gBAAZ;AACH;;AAED;;;;4BACuB;AACnB,mBAAO,KAAKmE,iBAAZ;AACH,S;0BACoB/M,K,EAAO;AACxB,gBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA8B;AAC1B,qBAAK+M,iBAAL,GAAyB/M,KAAzB;AACH,aAFD,MAEO;AACH,qBAAK+M,iBAAL,GAAyB,EAAzB;AACH;AACJ;;AAED;;;;4BACuB;AACnB,mBAAO,KAAKC,iBAAZ;AACH,S;0BACoBhN,K,EAAO;AACxB,gBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA8B;AAC1B,qBAAKgN,iBAAL,GAAyBhN,KAAzB;AACH,aAFD,MAEO;AACH,qBAAKgN,iBAAL,GAAyB,EAAzB;AACH;AACJ;;;;;;;;;;;;;;;;;;;;;;;ACxNL;;AACA;;0JAJA;AACA;;IAKaC,c,WAAAA,c;;;;;6BAETxS,O,oBAAQC,M,EAAQ;AACZ,YAAIE,QAAQ,IAAIsS,wBAAJ,CAAgBxS,MAAhB,CAAZ;AACA,eAAOzB,QAAQC,OAAR,CAAgB0B,KAAhB,CAAP;AACH,K;;6BAEDpD,Q,qBAASE,G,EAAKyV,Q,EAAU5D,S,EAAW;AAC/B1U,iBAAI6B,KAAJ,CAAU,yBAAV;;AAEA,YAAI;AACAwW,qCAAYE,YAAZ,CAAyB1V,GAAzB,EAA8ByV,QAA9B,EAAwC5D,SAAxC;AACA,mBAAOtQ,QAAQC,OAAR,EAAP;AACH,SAHD,CAIA,OAAOQ,CAAP,EAAU;AACN,mBAAOT,QAAQgC,MAAR,CAAevB,CAAf,CAAP;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;qjBCvBL;AACA;;AAEA;;AACA;;;;AAEA,IAAM2T,8BAA8B,GAApC;AACA,IAAMvS,uBAAuB,+DAA7B;AACA;;AAEA,IAAMC,qBAAqB,QAA3B;;IAEamS,W,WAAAA,W;AAET,yBAAYxS,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI/B,OAAJ,CAAY,UAACC,OAAD,EAAU+B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgBhC,OAAhB;AACA,kBAAKiC,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,YAAII,SAASX,OAAOY,iBAAP,IAA4BP,kBAAzC;AACA,YAAIK,WAAWV,OAAOC,mBAAP,IAA8BG,oBAA7C;;AAEA,aAAKqB,MAAL,GAAc5D,OAAO8D,IAAP,CAAY,EAAZ,EAAgBhB,MAAhB,EAAwBD,QAAxB,CAAd;AACA,YAAI,KAAKe,MAAT,EAAiB;AACbtH,qBAAI6B,KAAJ,CAAU,8CAAV;AACA,iBAAK4W,yBAAL,GAAiC/U,OAAOgC,WAAP,CAAmB,KAAKgT,oBAAL,CAA0B/T,IAA1B,CAA+B,IAA/B,CAAnB,EAAyD6T,2BAAzD,CAAjC;AACH;AACJ;;0BAMDvR,Q,qBAASpB,M,EAAQ;AACb,YAAI,CAAC,KAAKyB,MAAV,EAAkB;AACd,iBAAKJ,MAAL,CAAY,kDAAZ;AACH,SAFD,MAGK,IAAI,CAACrB,MAAD,IAAW,CAACA,OAAOhD,GAAvB,EAA4B;AAC7B,iBAAKqE,MAAL,CAAY,uCAAZ;AACA,iBAAKA,MAAL,CAAY,iBAAZ;AACH,SAHI,MAIA;AACDlH,qBAAI6B,KAAJ,CAAU,4CAAV;;AAEA,iBAAK8W,GAAL,GAAW9S,OAAOwO,EAAlB;AACA,gBAAI,KAAKsE,GAAT,EAAc;AACVjV,uBAAO,mBAAmBmC,OAAOwO,EAAjC,IAAuC,KAAKrR,SAAL,CAAe2B,IAAf,CAAoB,IAApB,CAAvC;AACH;;AAED,iBAAK2C,MAAL,CAAYsR,KAAZ;AACA,iBAAKtR,MAAL,CAAY5D,MAAZ,CAAmBgG,QAAnB,GAA8B7D,OAAOhD,GAArC;AACH;;AAED,eAAO,KAAKgF,OAAZ;AACH,K;;0BAEDE,Q,qBAAS9C,I,EAAM;AACXjF,iBAAI6B,KAAJ,CAAU,6DAAV;;AAEA,aAAKoG,QAAL;AACA,aAAK5B,QAAL,CAAcpB,IAAd;AACH,K;;0BACDiC,M,mBAAOc,O,EAAS;AACZhI,iBAAIkF,KAAJ,CAAU,qBAAV,EAAiC8C,OAAjC;;AAEA,aAAKC,QAAL;AACA,aAAK3B,OAAL,CAAa,IAAI4B,KAAJ,CAAUF,OAAV,CAAb;AACH,K;;0BAEDG,K,oBAAQ;AACJ,aAAKF,QAAL,CAAc,KAAd;AACH,K;;0BAEDA,Q,qBAASqQ,Q,EAAU;AACftY,iBAAI6B,KAAJ,CAAU,qBAAV;;AAEA6B,eAAOiC,aAAP,CAAqB,KAAK8S,yBAA1B;AACA,aAAKA,yBAAL,GAAiC,IAAjC;;AAEA,eAAO/U,OAAO,mBAAmB,KAAKiV,GAA/B,CAAP;;AAEA,YAAI,KAAKrR,MAAL,IAAe,CAACgR,QAApB,EAA8B;AAC1B,iBAAKhR,MAAL,CAAYa,KAAZ;AACH;AACD,aAAKb,MAAL,GAAc,IAAd;AACH,K;;0BAEDoR,oB,mCAAuB;AACnB,YAAI,CAAC,KAAKpR,MAAN,IAAgB,KAAKA,MAAL,CAAYuR,MAAhC,EAAwC;AACpC,iBAAK3R,MAAL,CAAY,qBAAZ;AACH;AACJ,K;;0BAEDlE,S,sBAAUH,G,EAAKyV,Q,EAAU;AACrB,aAAKrQ,QAAL,CAAcqQ,QAAd;;AAEA,YAAIzV,GAAJ,EAAS;AACL7C,qBAAI6B,KAAJ,CAAU,8BAAV;AACA,iBAAKkG,QAAL,CAAc,EAAElF,KAAKA,GAAP,EAAd;AACH,SAHD,MAIK;AACD7C,qBAAI6B,KAAJ,CAAU,mDAAV;AACA,iBAAKqF,MAAL,CAAY,6BAAZ;AACH;AACJ,K;;gBAEMqR,Y,yBAAa1V,G,EAAKyV,Q,EAAU5D,S,EAAW;AAC1C,YAAIhR,OAAOoV,MAAX,EAAmB;AACfjW,kBAAMA,OAAOa,OAAOgG,QAAP,CAAgBiB,IAA7B;AACA,gBAAI9H,GAAJ,EAAS;AACL,oBAAIoC,OAAO8T,uBAAWC,gBAAX,CAA4BnW,GAA5B,EAAiC6R,SAAjC,CAAX;;AAEA,oBAAIzP,KAAKuD,KAAT,EAAgB;AACZ,wBAAIzB,OAAO,mBAAmB9B,KAAKuD,KAAnC;AACA,wBAAI7F,WAAWe,OAAOoV,MAAP,CAAc/R,IAAd,CAAf;AACA,wBAAIpE,QAAJ,EAAc;AACV3C,iCAAI6B,KAAJ,CAAU,yDAAV;AACAc,iCAASE,GAAT,EAAcyV,QAAd;AACH,qBAHD,MAIK;AACDtY,iCAAIwQ,IAAJ,CAAS,gEAAT;AACH;AACJ,iBAVD,MAWK;AACDxQ,6BAAIwQ,IAAJ,CAAS,0DAAT;AACH;AACJ;AACJ,SApBD,MAqBK;AACDxQ,qBAAIwQ,IAAJ,CAAS,0EAAT;AACH;AACJ,K;;;;4BAtGa;AACV,mBAAO,KAAKrK,QAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBChCL;AACA;;AAEA;;;;IAEa8S,iB,WAAAA,iB;;;;;gCAETrT,O,sBAAU;AACN,eAAOxB,QAAQC,OAAR,CAAgB,IAAhB,CAAP;AACH,K;;gCAED4C,Q,qBAASpB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAOhD,GAAvB,EAA4B;AACxB7C,qBAAIkF,KAAJ,CAAU,6CAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,iBAAV,CAAf,CAAP;AACH;;AAED,YAAIrC,OAAOqT,oBAAX,EAAiC;AAC7BxV,mBAAOgG,QAAP,CAAgByP,OAAhB,CAAwBtT,OAAOhD,GAA/B;AACH,SAFD,MAGK;AACDa,mBAAOgG,QAAP,GAAkB7D,OAAOhD,GAAzB;AACH;;AAED,eAAOuB,QAAQC,OAAR,EAAP;AACH,K;;;;4BAES;AACN,mBAAOX,OAAOgG,QAAP,CAAgBiB,IAAvB;AACH;;;;;;;;;;;;;;;;;;;;;;;;;AC1BL;;AACA;;AACA;;AACA;;AACA;;AACA;;0JARA;AACA;;AASA,IAAMyO,iBAAiB,CAAC,OAAD,EAAU,SAAV,EAAqB,KAArB,EAA4B,KAA5B,EAAmC,KAAnC,EAA0C,KAA1C,EAAiD,KAAjD,EAAwD,QAAxD,CAAvB;;IAEaxC,iB,WAAAA,iB;AAET,+BAAYvF,QAAZ,EAImC;AAAA,YAH/BwF,mBAG+B,uEAHTtW,gCAGS;AAAA,YAF/B8Y,mBAE+B,uEAFTC,gCAES;AAAA,YAD/BC,QAC+B,uEADpB/L,kBACoB;AAAA,YAA/BgM,eAA+B,uEAAbC,wBAAa;;AAAA;;AAC/B,YAAI,CAACpI,QAAL,EAAe;AACXrR,qBAAIkF,KAAJ,CAAU,iEAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKqJ,SAAL,GAAiBF,QAAjB;AACA,aAAK0C,gBAAL,GAAwB,IAAI8C,mBAAJ,CAAwB,KAAKtF,SAA7B,CAAxB;AACA,aAAKmI,gBAAL,GAAwB,IAAIL,mBAAJ,CAAwB,KAAK9H,SAA7B,CAAxB;AACA,aAAKoI,SAAL,GAAiBJ,QAAjB;AACA,aAAKK,YAAL,GAAoB,IAAIJ,eAAJ,CAAoB,KAAKjI,SAAzB,CAApB;AACH;;gCAED8D,sB,mCAAuB7M,K,EAAOmM,Q,EAAU;AAAA;;AACpC3U,iBAAI6B,KAAJ,CAAU,0CAAV;;AAEA,eAAO,KAAKgY,oBAAL,CAA0BrR,KAA1B,EAAiCmM,QAAjC,EAA2CnG,IAA3C,CAAgD,oBAAY;AAC/DxO,qBAAI6B,KAAJ,CAAU,2DAAV;AACA,mBAAO,MAAKiY,eAAL,CAAqBtR,KAArB,EAA4BmM,QAA5B,EAAsCnG,IAAtC,CAA2C,oBAAY;AAC1DxO,yBAAI6B,KAAJ,CAAU,4DAAV;AACA,uBAAO,MAAKkY,cAAL,CAAoBvR,KAApB,EAA2BmM,QAA3B,EAAqCnG,IAArC,CAA0C,oBAAY;AACzDxO,6BAAI6B,KAAJ,CAAU,4DAAV;AACA,2BAAO8S,QAAP;AACH,iBAHM,CAAP;AAIH,aANM,CAAP;AAOH,SATM,CAAP;AAUH,K;;gCAEDoB,uB,oCAAwBvN,K,EAAOmM,Q,EAAU;AACrC,YAAInM,MAAM6L,EAAN,KAAaM,SAASnM,KAA1B,EAAiC;AAC7BxI,qBAAIkF,KAAJ,CAAU,iEAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAED;AACA;AACA;AACAlI,iBAAI6B,KAAJ,CAAU,4DAAV;AACA8S,iBAASnM,KAAT,GAAiBA,MAAMvD,IAAvB;;AAEA,YAAI0P,SAASzP,KAAb,EAAoB;AAChBlF,qBAAIwQ,IAAJ,CAAS,+DAAT,EAA0EmE,SAASzP,KAAnF;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAIiC,4BAAJ,CAAkBsM,QAAlB,CAAf,CAAP;AACH;;AAED,eAAOvQ,QAAQC,OAAR,CAAgBsQ,QAAhB,CAAP;AACH,K;;gCAEDkF,oB,iCAAqBrR,K,EAAOmM,Q,EAAU;AAClC,YAAInM,MAAM6L,EAAN,KAAaM,SAASnM,KAA1B,EAAiC;AAC7BxI,qBAAIkF,KAAJ,CAAU,8DAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACM,MAAM5F,SAAX,EAAsB;AAClB5C,qBAAIkF,KAAJ,CAAU,+DAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,uBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACM,MAAMmK,SAAX,EAAsB;AAClB3S,qBAAIkF,KAAJ,CAAU,+DAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,uBAAV,CAAf,CAAP;AACH;;AAED;AACA,YAAI,CAAC,KAAKqJ,SAAL,CAAeoB,SAApB,EAA+B;AAC3B,iBAAKpB,SAAL,CAAeoB,SAAf,GAA2BnK,MAAMmK,SAAjC;AACH;AACD;AAHA,aAIK,IAAI,KAAKpB,SAAL,CAAeoB,SAAf,IAA4B,KAAKpB,SAAL,CAAeoB,SAAf,KAA6BnK,MAAMmK,SAAnE,EAA8E;AAC/E3S,yBAAIkF,KAAJ,CAAU,yFAAV;AACA,uBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,iDAAV,CAAf,CAAP;AACH;AACD;AACA,YAAI,CAAC,KAAKqJ,SAAL,CAAe3O,SAApB,EAA+B;AAC3B,iBAAK2O,SAAL,CAAe3O,SAAf,GAA2B4F,MAAM5F,SAAjC;AACH;AACD;AAHA,aAIK,IAAI,KAAK2O,SAAL,CAAe3O,SAAf,IAA4B,KAAK2O,SAAL,CAAe3O,SAAf,KAA6B4F,MAAM5F,SAAnE,EAA8E;AAC/E5C,yBAAIkF,KAAJ,CAAU,yFAAV;AACA,uBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,iDAAV,CAAf,CAAP;AACH;;AAED;AACA;AACA;AACAlI,iBAAI6B,KAAJ,CAAU,yDAAV;AACA8S,iBAASnM,KAAT,GAAiBA,MAAMvD,IAAvB;;AAEA,YAAI0P,SAASzP,KAAb,EAAoB;AAChBlF,qBAAIwQ,IAAJ,CAAS,4DAAT,EAAuEmE,SAASzP,KAAhF;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAIiC,4BAAJ,CAAkBsM,QAAlB,CAAf,CAAP;AACH;;AAED,YAAInM,MAAMwR,KAAN,IAAe,CAACrF,SAASsF,QAA7B,EAAuC;AACnCja,qBAAIkF,KAAJ,CAAU,wEAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACM,MAAMwR,KAAP,IAAgBrF,SAASsF,QAA7B,EAAuC;AACnCja,qBAAIkF,KAAJ,CAAU,4EAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,iCAAV,CAAf,CAAP;AACH;;AAED,YAAIM,MAAM0R,aAAN,IAAuB,CAACvF,SAASwF,IAArC,EAA2C;AACvCna,qBAAIkF,KAAJ,CAAU,oEAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,qBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACM,MAAM0R,aAAP,IAAwBvF,SAASwF,IAArC,EAA2C;AACvCna,qBAAIkF,KAAJ,CAAU,wEAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACyM,SAAS7B,KAAd,EAAqB;AACjB;AACA6B,qBAAS7B,KAAT,GAAiBtK,MAAMsK,KAAvB;AACH;;AAED,eAAO1O,QAAQC,OAAR,CAAgBsQ,QAAhB,CAAP;AACH,K;;gCAEDoF,c,2BAAevR,K,EAAOmM,Q,EAAU;AAAA;;AAC5B,YAAIA,SAASyF,eAAb,EAA8B;AAC1Bpa,qBAAI6B,KAAJ,CAAU,uEAAV;;AAEA8S,qBAAS0F,OAAT,GAAmB,KAAKxC,qBAAL,CAA2BlD,SAAS0F,OAApC,CAAnB;;AAEA,gBAAI7R,MAAMmL,YAAN,KAAuB,IAAvB,IAA+B,KAAKpC,SAAL,CAAekF,YAA9C,IAA8D9B,SAASlT,YAA3E,EAAyF;AACrFzB,yBAAI6B,KAAJ,CAAU,qDAAV;;AAEA,uBAAO,KAAK6X,gBAAL,CAAsBY,SAAtB,CAAgC3F,SAASlT,YAAzC,EAAuD+M,IAAvD,CAA4D,kBAAU;AACzExO,6BAAI6B,KAAJ,CAAU,qFAAV;;AAEA,wBAAI0Y,OAAOC,GAAP,KAAe7F,SAAS0F,OAAT,CAAiBG,GAApC,EAAyC;AACrCxa,iCAAIkF,KAAJ,CAAU,kGAAV;AACA,+BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,gEAAV,CAAf,CAAP;AACH;;AAEDyM,6BAAS0F,OAAT,GAAmB,OAAKI,YAAL,CAAkB9F,SAAS0F,OAA3B,EAAoCE,MAApC,CAAnB;AACAva,6BAAI6B,KAAJ,CAAU,+EAAV,EAA2F8S,SAAS0F,OAApG;;AAEA,2BAAO1F,QAAP;AACH,iBAZM,CAAP;AAaH,aAhBD,MAiBK;AACD3U,yBAAI6B,KAAJ,CAAU,yDAAV;AACH;AACJ,SAzBD,MA0BK;AACD7B,qBAAI6B,KAAJ,CAAU,+EAAV;AACH;;AAED,eAAOuC,QAAQC,OAAR,CAAgBsQ,QAAhB,CAAP;AACH,K;;gCAED8F,Y,yBAAaC,O,EAASC,O,EAAS;AAC3B,YAAIC,SAAStP,OAAOuP,MAAP,CAAc,EAAd,EAAkBH,OAAlB,CAAb;;AAEA,aAAK,IAAI3T,IAAT,IAAiB4T,OAAjB,EAA0B;AACtB,gBAAIG,SAASH,QAAQ5T,IAAR,CAAb;AACA,gBAAI,CAACiH,MAAMC,OAAN,CAAc6M,MAAd,CAAL,EAA4B;AACxBA,yBAAS,CAACA,MAAD,CAAT;AACH;;AAED,iBAAK,IAAI7R,IAAI,CAAb,EAAgBA,IAAI6R,OAAO5R,MAA3B,EAAmCD,GAAnC,EAAwC;AACpC,oBAAIkC,QAAQ2P,OAAO7R,CAAP,CAAZ;AACA,oBAAI,CAAC2R,OAAO7T,IAAP,CAAL,EAAmB;AACf6T,2BAAO7T,IAAP,IAAeoE,KAAf;AACH,iBAFD,MAGK,IAAI6C,MAAMC,OAAN,CAAc2M,OAAO7T,IAAP,CAAd,CAAJ,EAAiC;AAClC,wBAAI6T,OAAO7T,IAAP,EAAazD,OAAb,CAAqB6H,KAArB,IAA8B,CAAlC,EAAqC;AACjCyP,+BAAO7T,IAAP,EAAa6B,IAAb,CAAkBuC,KAAlB;AACH;AACJ,iBAJI,MAKA,IAAIyP,OAAO7T,IAAP,MAAiBoE,KAArB,EAA4B;AAC7B,wBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA+B;AAC3ByP,+BAAO7T,IAAP,IAAe,KAAK0T,YAAL,CAAkBG,OAAO7T,IAAP,CAAlB,EAAgCoE,KAAhC,CAAf;AACH,qBAFD,MAGK;AACDyP,+BAAO7T,IAAP,IAAe,CAAC6T,OAAO7T,IAAP,CAAD,EAAeoE,KAAf,CAAf;AACH;AACJ;AACJ;AACJ;;AAED,eAAOyP,MAAP;AACH,K;;gCAED/C,qB,kCAAsB0C,M,EAAQ;AAC1Bva,iBAAI6B,KAAJ,CAAU,2DAAV,EAAuE0Y,MAAvE;;AAEA,YAAIK,SAAStP,OAAOuP,MAAP,CAAc,EAAd,EAAkBN,MAAlB,CAAb;;AAEA,YAAI,KAAKhJ,SAAL,CAAesG,qBAAnB,EAA0C;AACtCuB,2BAAe2B,OAAf,CAAuB,gBAAQ;AAC3B,uBAAOH,OAAOI,IAAP,CAAP;AACH,aAFD;;AAIAhb,qBAAI6B,KAAJ,CAAU,mEAAV,EAA+E+Y,MAA/E;AACH,SAND,MAOK;AACD5a,qBAAI6B,KAAJ,CAAU,uEAAV;AACH;;AAED,eAAO+Y,MAAP;AACH,K;;gCAEDd,e,4BAAgBtR,K,EAAOmM,Q,EAAU;AAC7B,YAAIA,SAASwF,IAAb,EAAmB;AACfna,qBAAI6B,KAAJ,CAAU,oDAAV;AACA,mBAAO,KAAKoZ,YAAL,CAAkBzS,KAAlB,EAAyBmM,QAAzB,CAAP;AACH;;AAED,YAAIA,SAASsF,QAAb,EAAuB;AACnB,gBAAItF,SAASlT,YAAb,EAA2B;AACvBzB,yBAAI6B,KAAJ,CAAU,yEAAV;AACA,uBAAO,KAAKqZ,8BAAL,CAAoC1S,KAApC,EAA2CmM,QAA3C,CAAP;AACH;;AAED3U,qBAAI6B,KAAJ,CAAU,wDAAV;AACA,mBAAO,KAAKsZ,gBAAL,CAAsB3S,KAAtB,EAA6BmM,QAA7B,CAAP;AACH;;AAED3U,iBAAI6B,KAAJ,CAAU,+EAAV;AACA,eAAOuC,QAAQC,OAAR,CAAgBsQ,QAAhB,CAAP;AACH,K;;gCAEDsG,Y,yBAAazS,K,EAAOmM,Q,EAAU;AAAA;;AAC1B,YAAIrL,UAAU;AACV1G,uBAAW4F,MAAM5F,SADP;AAEVqR,2BAAezL,MAAMyL,aAFX;AAGVkG,kBAAOxF,SAASwF,IAHN;AAIVzT,0BAAc8B,MAAM9B,YAJV;AAKVwT,2BAAe1R,MAAM0R;AALX,SAAd;;AAQA,YAAI1R,MAAMiL,gBAAN,IAA0B,QAAOjL,MAAMiL,gBAAb,MAAmC,QAAjE,EAA2E;AACvEnI,mBAAOuP,MAAP,CAAcvR,OAAd,EAAuBd,MAAMiL,gBAA7B;AACH;;AAED,eAAO,KAAKmG,YAAL,CAAkBwB,YAAlB,CAA+B9R,OAA/B,EAAwCkF,IAAxC,CAA6C,yBAAiB;;AAEjE,iBAAI,IAAIvD,GAAR,IAAeoQ,aAAf,EAA8B;AAC1B1G,yBAAS1J,GAAT,IAAgBoQ,cAAcpQ,GAAd,CAAhB;AACH;;AAED,gBAAI0J,SAASsF,QAAb,EAAuB;AACnBja,yBAAI6B,KAAJ,CAAU,gFAAV;AACA,uBAAO,OAAKyZ,0BAAL,CAAgC9S,KAAhC,EAAuCmM,QAAvC,CAAP;AACH,aAHD,MAIK;AACD3U,yBAAI6B,KAAJ,CAAU,+EAAV;AACH;;AAED,mBAAO8S,QAAP;AACH,SAfM,CAAP;AAgBH,K;;gCAED2G,0B,uCAA2B9S,K,EAAOmM,Q,EAAU;AAAA;;AACxC,eAAO,KAAKZ,gBAAL,CAAsBpC,SAAtB,GAAkCnD,IAAlC,CAAuC,kBAAU;;AAEpD,gBAAI7B,WAAWnE,MAAM5F,SAArB;AACA,gBAAI2Y,qBAAqB,OAAKhK,SAAL,CAAe3E,SAAxC;AACA5M,qBAAI6B,KAAJ,CAAU,4GAAV,EAAwH0Z,kBAAxH;;AAEA,mBAAO,OAAK5B,SAAL,CAAejM,qBAAf,CAAqCiH,SAASsF,QAA9C,EAAwDvN,MAAxD,EAAgEC,QAAhE,EAA0E4O,kBAA1E,EAA8F/M,IAA9F,CAAmG,mBAAW;;AAEjH,oBAAIhG,MAAMwR,KAAN,IAAexR,MAAMwR,KAAN,KAAgBzN,QAAQyN,KAA3C,EAAkD;AAC9Cha,6BAAIkF,KAAJ,CAAU,yEAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,2BAAV,CAAf,CAAP;AACH;;AAED,oBAAI,CAACqE,QAAQiO,GAAb,EAAkB;AACdxa,6BAAIkF,KAAJ,CAAU,0EAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDyM,yBAAS0F,OAAT,GAAmB9N,OAAnB;AACA,uBAAOoI,QAAP;AACH,aAdM,CAAP;AAeH,SArBM,CAAP;AAsBH,K;;gCAEDuG,8B,2CAA+B1S,K,EAAOmM,Q,EAAU;AAAA;;AAC5C,eAAO,KAAKwG,gBAAL,CAAsB3S,KAAtB,EAA6BmM,QAA7B,EAAuCnG,IAAvC,CAA4C,oBAAY;AAC3D,mBAAO,OAAKgN,oBAAL,CAA0B7G,QAA1B,CAAP;AACH,SAFM,CAAP;AAGH,K;;gCAEDwG,gB,6BAAiB3S,K,EAAOmM,Q,EAAU;AAAA;;AAC9B,YAAI,CAACnM,MAAMwR,KAAX,EAAkB;AACdha,qBAAIkF,KAAJ,CAAU,uDAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,mBAAV,CAAf,CAAP;AACH;;AAED,YAAI+D,MAAM,KAAK0N,SAAL,CAAe3N,QAAf,CAAwB2I,SAASsF,QAAjC,CAAV;AACA,YAAI,CAAChO,GAAD,IAAQ,CAACA,IAAII,MAAb,IAAuB,CAACJ,IAAIM,OAAhC,EAAyC;AACrCvM,qBAAIkF,KAAJ,CAAU,8DAAV,EAA0E+G,GAA1E;AACA,mBAAO7H,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,YAAIM,MAAMwR,KAAN,KAAgB/N,IAAIM,OAAJ,CAAYyN,KAAhC,EAAuC;AACnCha,qBAAIkF,KAAJ,CAAU,+DAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,2BAAV,CAAf,CAAP;AACH;;AAED,YAAIuT,MAAMxP,IAAII,MAAJ,CAAWoP,GAArB;;AAEA,eAAO,KAAK1H,gBAAL,CAAsBpC,SAAtB,GAAkCnD,IAAlC,CAAuC,kBAAU;AACpDxO,qBAAI6B,KAAJ,CAAU,qDAAV;;AAEA,mBAAO,OAAKkS,gBAAL,CAAsB1B,cAAtB,GAAuC7D,IAAvC,CAA4C,gBAAQ;AACvD,oBAAI,CAACiE,IAAL,EAAW;AACPzS,6BAAIkF,KAAJ,CAAU,mEAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,+BAAV,CAAf,CAAP;AACH;;AAEDlI,yBAAI6B,KAAJ,CAAU,2DAAV;AACA,oBAAIoJ,YAAJ;AACA,oBAAI,CAACwQ,GAAL,EAAU;AACNhJ,2BAAO,OAAKiJ,YAAL,CAAkBjJ,IAAlB,EAAwBxG,IAAII,MAAJ,CAAWsC,GAAnC,CAAP;;AAEA,wBAAI8D,KAAKvJ,MAAL,GAAc,CAAlB,EAAqB;AACjBlJ,iCAAIkF,KAAJ,CAAU,sGAAV;AACA,+BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,kEAAV,CAAf,CAAP;AACH,qBAHD,MAIK;AACD;AACA;AACA+C,8BAAMwH,KAAK,CAAL,CAAN;AACH;AACJ,iBAZD,MAaK;AACDxH,0BAAMwH,KAAKkJ,MAAL,CAAY,eAAO;AACrB,+BAAO1Q,IAAIwQ,GAAJ,KAAYA,GAAnB;AACH,qBAFK,EAEH,CAFG,CAAN;AAGH;;AAED,oBAAI,CAACxQ,GAAL,EAAU;AACNjL,6BAAIkF,KAAJ,CAAU,sFAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED,oBAAIyE,WAAWnE,MAAM5F,SAArB;;AAEA,oBAAI2Y,qBAAqB,OAAKhK,SAAL,CAAe3E,SAAxC;AACA5M,yBAAI6B,KAAJ,CAAU,uFAAV,EAAmG0Z,kBAAnG;;AAEA,uBAAO,OAAK5B,SAAL,CAAelN,WAAf,CAA2BkI,SAASsF,QAApC,EAA8ChP,GAA9C,EAAmDyB,MAAnD,EAA2DC,QAA3D,EAAqE4O,kBAArE,EAAyF/M,IAAzF,CAA8F,YAAI;AACrGxO,6BAAI6B,KAAJ,CAAU,+DAAV;;AAEA,wBAAI,CAACoK,IAAIM,OAAJ,CAAYiO,GAAjB,EAAsB;AAClBxa,iCAAIkF,KAAJ,CAAU,gEAAV;AACA,+BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDyM,6BAAS0F,OAAT,GAAmBpO,IAAIM,OAAvB;;AAEA,2BAAOoI,QAAP;AACH,iBAXM,CAAP;AAYH,aAjDM,CAAP;AAkDH,SArDM,CAAP;AAsDH,K;;gCAED+G,Y,yBAAajJ,I,EAAM9D,G,EAAI;AACnB,YAAI5B,MAAM,IAAV;AACA,YAAI4B,IAAImB,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AACtB/C,kBAAM,KAAN;AACH,SAFD,MAGK,IAAI4B,IAAImB,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3B/C,kBAAM,IAAN;AACH,SAFI,MAGA,IAAI4B,IAAImB,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3B/C,kBAAM,IAAN;AACH,SAFI,MAGA;AACD/M,qBAAI6B,KAAJ,CAAU,qDAAV,EAAiE8M,GAAjE;AACA,mBAAO,EAAP;AACH;;AAED3O,iBAAI6B,KAAJ,CAAU,mEAAV,EAA+EkL,GAA/E;;AAEA0F,eAAOA,KAAKkJ,MAAL,CAAY,eAAO;AACtB,mBAAO1Q,IAAI8B,GAAJ,KAAYA,GAAnB;AACH,SAFM,CAAP;;AAIA/M,iBAAI6B,KAAJ,CAAU,iEAAV,EAA6EkL,GAA7E,EAAkF0F,KAAKvJ,MAAvF;;AAEA,eAAOuJ,IAAP;AACH,K;;gCAED+I,oB,iCAAqB7G,Q,EAAU;AAC3B,YAAI,CAACA,SAAS0F,OAAd,EAAuB;AACnBra,qBAAIkF,KAAJ,CAAU,yEAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,iCAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACyM,SAAS0F,OAAT,CAAiBuB,OAAtB,EAA+B;AAC3B5b,qBAAIkF,KAAJ,CAAU,gEAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,wBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACyM,SAASsF,QAAd,EAAwB;AACpBja,qBAAIkF,KAAJ,CAAU,qDAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,aAAV,CAAf,CAAP;AACH;;AAED,YAAI+D,MAAM,KAAK0N,SAAL,CAAe3N,QAAf,CAAwB2I,SAASsF,QAAjC,CAAV;AACA,YAAI,CAAChO,GAAD,IAAQ,CAACA,IAAII,MAAjB,EAAyB;AACrBrM,qBAAIkF,KAAJ,CAAU,kEAAV,EAA8E+G,GAA9E;AACA,mBAAO7H,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,YAAI2T,UAAU5P,IAAII,MAAJ,CAAWsC,GAAzB;AACA,YAAI,CAACkN,OAAD,IAAYA,QAAQ3S,MAAR,KAAmB,CAAnC,EAAsC;AAClClJ,qBAAIkF,KAAJ,CAAU,0DAAV,EAAsE2W,OAAtE;AACA,mBAAOzX,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,sBAAsB2T,OAAhC,CAAf,CAAP;AACH;;AAED,YAAIC,WAAWD,QAAQrY,MAAR,CAAe,CAAf,EAAkB,CAAlB,CAAf;AACA,YAAI,CAACsY,QAAL,EAAe;AACX9b,qBAAIkF,KAAJ,CAAU,0DAAV,EAAsE2W,OAAtE,EAA+EC,QAA/E;AACA,mBAAO1X,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,sBAAsB2T,OAAhC,CAAf,CAAP;AACH;;AAEDC,mBAAWnO,SAASmO,QAAT,CAAX;AACA,YAAIA,aAAa,GAAb,IAAoBA,aAAa,GAAjC,IAAwCA,aAAa,GAAzD,EAA8D;AAC1D9b,qBAAIkF,KAAJ,CAAU,0DAAV,EAAsE2W,OAAtE,EAA+EC,QAA/E;AACA,mBAAO1X,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,sBAAsB2T,OAAhC,CAAf,CAAP;AACH;;AAED,YAAIE,MAAM,QAAQD,QAAlB;AACA,YAAIE,OAAO,KAAKrC,SAAL,CAAejL,UAAf,CAA0BiG,SAASlT,YAAnC,EAAiDsa,GAAjD,CAAX;AACA,YAAI,CAACC,IAAL,EAAW;AACPhc,qBAAIkF,KAAJ,CAAU,mEAAV,EAA+E6W,GAA/E;AACA,mBAAO3X,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAED,YAAI+T,OAAOD,KAAKxY,MAAL,CAAY,CAAZ,EAAewY,KAAK9S,MAAL,GAAc,CAA7B,CAAX;AACA,YAAIgT,YAAY,KAAKvC,SAAL,CAAe9K,cAAf,CAA8BoN,IAA9B,CAAhB;AACA,YAAIC,cAAcvH,SAAS0F,OAAT,CAAiBuB,OAAnC,EAA4C;AACxC5b,qBAAIkF,KAAJ,CAAU,oEAAV,EAAgFgX,SAAhF,EAA2FvH,SAAS0F,OAAT,CAAiBuB,OAA5G;AACA,mBAAOxX,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDlI,iBAAI6B,KAAJ,CAAU,iDAAV;;AAEA,eAAOuC,QAAQC,OAAR,CAAgBsQ,QAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCndL;AACA;;AAEA;;AACA;;AACA;;;;IAEa/T,c,WAAAA,c;AAET,4BAAYub,WAAZ,EAA4F;AAAA;;AAAA,YAAnEC,sBAAmE,uEAA1C1b,sCAA0C;AAAA,YAAtByI,KAAsB,uEAAdtI,eAAOsI,KAAO;;AAAA;;AACxF,YAAI,CAACgT,WAAL,EAAkB;AACdnc,qBAAIkF,KAAJ,CAAU,+DAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,aAAV,CAAN;AACH;;AAED,aAAKmU,YAAL,GAAoBF,WAApB;AACA,aAAKG,uBAAL,GAA+BF,sBAA/B;AACA,aAAK3W,MAAL,GAAc0D,KAAd;;AAEA,aAAKkT,YAAL,CAAkBE,MAAlB,CAAyBC,aAAzB,CAAuC,KAAKC,MAAL,CAAY9X,IAAZ,CAAiB,IAAjB,CAAvC;AACA,aAAK0X,YAAL,CAAkBE,MAAlB,CAAyBG,eAAzB,CAAyC,KAAKC,KAAL,CAAWhY,IAAX,CAAgB,IAAhB,CAAzC;;AAEA,aAAK0X,YAAL,CAAkBO,OAAlB,GAA4BpO,IAA5B,CAAiC,gBAAQ;AACrC;AACA;AACA,gBAAIqO,IAAJ,EAAU;AACN,sBAAKJ,MAAL,CAAYI,IAAZ;AACH,aAFD,MAGK,IAAI,MAAKtL,SAAL,CAAeuL,uBAAnB,EAA4C;AAC7C,sBAAKT,YAAL,CAAkBU,kBAAlB,GAAuCvO,IAAvC,CAA4C,mBAAW;AACnD,wBAAIwO,UAAU;AACV3X,uCAAgB4X,QAAQ5X;AADd,qBAAd;AAGA,wBAAI4X,QAAQzC,GAAR,IAAeyC,QAAQC,GAA3B,EAAgC;AAC5BF,gCAAQ3C,OAAR,GAAkB;AACdG,iCAAKyC,QAAQzC,GADC;AAEd0C,iCAAKD,QAAQC;AAFC,yBAAlB;AAIH;AACD,0BAAKT,MAAL,CAAYO,OAAZ;AACH,iBAXD,EAYCG,KAZD,CAYO,eAAO;AACV;AACAnd,6BAAIkF,KAAJ,CAAU,qDAAV,EAAiEkY,IAAIpV,OAArE;AACH,iBAfD;AAgBH;AACJ,SAxBD,EAwBGmV,KAxBH,CAwBS,eAAO;AACZ;AACAnd,qBAAIkF,KAAJ,CAAU,0CAAV,EAAsDkY,IAAIpV,OAA1D;AACH,SA3BD;AA4BH;;6BAkBDyU,M,mBAAOI,I,EAAM;AAAA;;AACT,YAAIxX,gBAAgBwX,KAAKxX,aAAzB;;AAEA,YAAIA,aAAJ,EAAmB;AACf,gBAAIwX,KAAKxC,OAAT,EAAkB;AACd,qBAAKgD,IAAL,GAAYR,KAAKxC,OAAL,CAAaG,GAAzB;AACA,qBAAK8C,IAAL,GAAYT,KAAKxC,OAAL,CAAa6C,GAAzB;AACAld,yBAAI6B,KAAJ,CAAU,uCAAV,EAAmDwD,aAAnD,EAAkE,QAAlE,EAA4E,KAAKgY,IAAjF;AACH,aAJD,MAKK;AACD,qBAAKA,IAAL,GAAY1b,SAAZ;AACA,qBAAK2b,IAAL,GAAY3b,SAAZ;AACA3B,yBAAI6B,KAAJ,CAAU,uCAAV,EAAmDwD,aAAnD,EAAkE,kBAAlE;AACH;;AAED,gBAAI,CAAC,KAAKkY,mBAAV,EAA+B;AAC3B,qBAAKxJ,gBAAL,CAAsB9B,qBAAtB,GAA8CzD,IAA9C,CAAmD,eAAO;AACtD,wBAAI3L,GAAJ,EAAS;AACL7C,iCAAI6B,KAAJ,CAAU,0DAAV;;AAEA,4BAAIe,YAAY,OAAKK,UAArB;AACA,4BAAIH,WAAW,OAAK0a,qBAApB;AACA,4BAAIza,cAAc,OAAK0a,wBAAvB;;AAEA,+BAAKF,mBAAL,GAA2B,IAAI,OAAKjB,uBAAT,CAAiC,OAAKtZ,SAAL,CAAe2B,IAAf,CAAoB,MAApB,CAAjC,EAA4D/B,SAA5D,EAAuEC,GAAvE,EAA4EC,QAA5E,EAAsFC,WAAtF,CAA3B;AACA,+BAAKwa,mBAAL,CAAyBhc,IAAzB,GAAgCiN,IAAhC,CAAqC,YAAM;AACvC,mCAAK+O,mBAAL,CAAyBnY,KAAzB,CAA+BC,aAA/B;AACH,yBAFD;AAGH,qBAXD,MAYK;AACDrF,iCAAIwQ,IAAJ,CAAS,sEAAT;AACH;AACJ,iBAhBD,EAgBG2M,KAhBH,CAgBS,eAAO;AACZ;AACAnd,6BAAIkF,KAAJ,CAAU,0DAAV,EAAsEkY,IAAIpV,OAA1E;AACH,iBAnBD;AAoBH,aArBD,MAsBK;AACD,qBAAKuV,mBAAL,CAAyBnY,KAAzB,CAA+BC,aAA/B;AACH;AACJ;AACJ,K;;6BAEDsX,K,oBAAQ;AAAA;;AACJ,aAAKU,IAAL,GAAY1b,SAAZ;AACA,aAAK2b,IAAL,GAAY3b,SAAZ;;AAEA,YAAI,KAAK4b,mBAAT,EAA8B;AAC1Bvd,qBAAI6B,KAAJ,CAAU,sBAAV;AACA,iBAAK0b,mBAAL,CAAyBpY,IAAzB;AACH;;AAED,YAAI,KAAKoM,SAAL,CAAeuL,uBAAnB,EAA4C;AACxC;AACA,gBAAIY,cAAc,KAAKjY,MAAL,CAAYC,WAAZ,CAAwB,YAAI;AAC1C,uBAAKD,MAAL,CAAYE,aAAZ,CAA0B+X,WAA1B;;AAEA,uBAAKrB,YAAL,CAAkBU,kBAAlB,GAAuCvO,IAAvC,CAA4C,mBAAW;AACnD,wBAAIwO,UAAU;AACV3X,uCAAgB4X,QAAQ5X;AADd,qBAAd;AAGA,wBAAI4X,QAAQzC,GAAR,IAAeyC,QAAQC,GAA3B,EAAgC;AAC5BF,gCAAQ3C,OAAR,GAAkB;AACdG,iCAAKyC,QAAQzC,GADC;AAEd0C,iCAAKD,QAAQC;AAFC,yBAAlB;AAIH;AACD,2BAAKT,MAAL,CAAYO,OAAZ;AACH,iBAXD,EAYCG,KAZD,CAYO,eAAO;AACV;AACAnd,6BAAIkF,KAAJ,CAAU,gDAAV,EAA4DkY,IAAIpV,OAAhE;AACH,iBAfD;AAiBH,aApBiB,EAoBf,IApBe,CAAlB;AAqBH;AACJ,K;;6BAEDhF,S,wBAAY;AAAA;;AACR,aAAKqZ,YAAL,CAAkBU,kBAAlB,GAAuCvO,IAAvC,CAA4C,mBAAW;AACnD,gBAAImP,aAAa,IAAjB;;AAEA,gBAAIV,OAAJ,EAAa;AACT,oBAAIA,QAAQzC,GAAR,KAAgB,OAAK6C,IAAzB,EAA+B;AAC3BM,iCAAa,KAAb;AACA,2BAAKJ,mBAAL,CAAyBnY,KAAzB,CAA+B6X,QAAQ5X,aAAvC;;AAEA,wBAAI4X,QAAQC,GAAR,KAAgB,OAAKI,IAAzB,EAA+B;AAC3Btd,iCAAI6B,KAAJ,CAAU,2GAAV,EAAuHob,QAAQ5X,aAA/H;AACH,qBAFD,MAGK;AACDrF,iCAAI6B,KAAJ,CAAU,sIAAV,EAAkJob,QAAQ5X,aAA1J;AACA,+BAAKgX,YAAL,CAAkBE,MAAlB,CAAyBqB,wBAAzB;AACH;AACJ,iBAXD,MAYK;AACD5d,6BAAI6B,KAAJ,CAAU,6DAAV,EAAyEob,QAAQzC,GAAjF;AACH;AACJ,aAhBD,MAiBK;AACDxa,yBAAI6B,KAAJ,CAAU,4DAAV;AACH;;AAED,gBAAI8b,UAAJ,EAAgB;AACZ,oBAAI,OAAKN,IAAT,EAAe;AACXrd,6BAAI6B,KAAJ,CAAU,8EAAV;AACA,2BAAKwa,YAAL,CAAkBE,MAAlB,CAAyBsB,mBAAzB;AACH,iBAHD,MAIK;AACD7d,6BAAI6B,KAAJ,CAAU,6EAAV;AACA,2BAAKwa,YAAL,CAAkBE,MAAlB,CAAyBuB,kBAAzB;AACH;AACJ;AACJ,SAlCD,EAkCGX,KAlCH,CAkCS,eAAO;AACZ,gBAAI,OAAKE,IAAT,EAAe;AACXrd,yBAAI6B,KAAJ,CAAU,6FAAV,EAAyGub,IAAIpV,OAA7G;AACA,uBAAKqU,YAAL,CAAkBE,MAAlB,CAAyBsB,mBAAzB;AACH;AACJ,SAvCD;AAwCH,K;;;;4BAvIe;AACZ,mBAAO,KAAKxB,YAAL,CAAkBhL,QAAzB;AACH;;;4BACsB;AACnB,mBAAO,KAAKgL,YAAL,CAAkBlG,eAAzB;AACH;;;4BACgB;AACb,mBAAO,KAAK5E,SAAL,CAAe3O,SAAtB;AACH;;;4BAC2B;AACxB,mBAAO,KAAK2O,SAAL,CAAewM,oBAAtB;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKxM,SAAL,CAAeyM,uBAAtB;AACH;;;;;;;;;;;;;;;;;;;;;;;AC/DL;;AACA;;AACA;;0JALA;AACA;;IAManK,a,WAAAA,a;AACT,iCAMG;AAAA,YAJChR,GAID,QAJCA,GAID;AAAA,YAJMD,SAIN,QAJMA,SAIN;AAAA,YAJiB8D,YAIjB,QAJiBA,YAIjB;AAAA,YAJ+BmM,aAI/B,QAJ+BA,aAI/B;AAAA,YAJ8CC,KAI9C,QAJ8CA,KAI9C;AAAA,YAJqDH,SAIrD,QAJqDA,SAIrD;AAAA,YAFC1N,IAED,QAFCA,IAED;AAAA,YAFO8N,MAEP,QAFOA,MAEP;AAAA,YAFe/O,OAEf,QAFeA,OAEf;AAAA,YAFwBgP,OAExB,QAFwBA,OAExB;AAAA,YAFiCC,UAEjC,QAFiCA,UAEjC;AAAA,YAF6CC,aAE7C,QAF6CA,aAE7C;AAAA,YAF4DC,UAE5D,QAF4DA,UAE5D;AAAA,YAFwEC,UAExE,QAFwEA,UAExE;AAAA,YAFoFC,QAEpF,QAFoFA,QAEpF;AAAA,YAF8FE,aAE9F,QAF8FA,aAE9F;AAAA,YADCjK,OACD,QADCA,OACD;AAAA,YADUgK,WACV,QADUA,WACV;AAAA,YADuBE,gBACvB,QADuBA,gBACvB;AAAA,YADyCE,YACzC,QADyCA,YACzC;AAAA,YADuDO,aACvD,QADuDA,aACvD;AAAA,YADsER,gBACtE,QADsEA,gBACtE;AAAA,YADwFE,YACxF,QADwFA,YACxF;;AAAA;;AACC,YAAI,CAAC9Q,GAAL,EAAU;AACN7C,qBAAIkF,KAAJ,CAAU,mCAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,KAAV,CAAN;AACH;AACD,YAAI,CAACtF,SAAL,EAAgB;AACZ5C,qBAAIkF,KAAJ,CAAU,yCAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,WAAV,CAAN;AACH;AACD,YAAI,CAACxB,YAAL,EAAmB;AACf1G,qBAAIkF,KAAJ,CAAU,4CAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,cAAV,CAAN;AACH;AACD,YAAI,CAAC2K,aAAL,EAAoB;AAChB7S,qBAAIkF,KAAJ,CAAU,6CAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,eAAV,CAAN;AACH;AACD,YAAI,CAAC4K,KAAL,EAAY;AACR9S,qBAAIkF,KAAJ,CAAU,qCAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,OAAV,CAAN;AACH;AACD,YAAI,CAACyK,SAAL,EAAgB;AACZ3S,qBAAIkF,KAAJ,CAAU,yCAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,WAAV,CAAN;AACH;;AAED,YAAI+V,OAAOpK,cAAcqK,MAAd,CAAqBrL,aAArB,CAAX;AACA,YAAIsH,OAAOtG,cAAcC,MAAd,CAAqBjB,aAArB,CAAX;;AAEA,YAAI,CAACU,aAAL,EAAoB;AAChBA,4BAAgBM,cAAcC,MAAd,CAAqBjB,aAArB,IAAsC,OAAtC,GAAgD,IAAhE;AACH;;AAED,aAAKrK,KAAL,GAAa,IAAIyM,wBAAJ,CAAgB,EAAE+E,OAAOiE,IAAT;AACzBhZ,sBADyB,EACnBrC,oBADmB,EACR+P,oBADQ,EACGjM,0BADH;AAEzBwT,2BAAeC,IAFU;AAGzBzG,sCAHyB,EAGXH,4BAHW;AAIzBU,wCAJyB,EAIVnB,YAJU,EAIHW,kCAJG,EAIeE,0BAJf,EAAhB,CAAb;;AAMA9Q,cAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,WAA9B,EAA2CD,SAA3C,CAAN;AACAC,cAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,cAA9B,EAA8C6D,YAA9C,CAAN;AACA7D,cAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,eAA9B,EAA+CgQ,aAA/C,CAAN;AACAhQ,cAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,OAA9B,EAAuCiQ,KAAvC,CAAN;;AAEAjQ,cAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,OAA9B,EAAuC,KAAK2F,KAAL,CAAW6L,EAAlD,CAAN;AACA,YAAI4J,IAAJ,EAAU;AACNpb,kBAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,OAA9B,EAAuC,KAAK2F,KAAL,CAAWwR,KAAlD,CAAN;AACH;AACD,YAAIG,IAAJ,EAAU;AACNtX,kBAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,gBAA9B,EAAgD,KAAK2F,KAAL,CAAW4V,cAA3D,CAAN;AACAvb,kBAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,uBAA9B,EAAuD,MAAvD,CAAN;AACH;;AAED,YAAImP,WAAW,EAAEe,cAAF,EAAU/O,gBAAV,EAAmBgP,gBAAnB,EAA4BC,sBAA5B,EAAwCC,4BAAxC,EAAuDC,sBAAvD,EAAmEC,sBAAnE,EAA+EC,kBAA/E,EAAyF/J,gBAAzF,EAAkGgK,wBAAlG,EAA+GC,4BAA/G,EAAf;AACA,aAAI,IAAItI,GAAR,IAAe+G,QAAf,EAAwB;AACpB,gBAAIA,SAAS/G,GAAT,CAAJ,EAAmB;AACfpI,sBAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8BoI,GAA9B,EAAmC+G,SAAS/G,GAAT,CAAnC,CAAN;AACH;AACJ;;AAED,aAAI,IAAIA,IAAR,IAAeuI,gBAAf,EAAgC;AAC5B3Q,kBAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8BoI,IAA9B,EAAmCuI,iBAAiBvI,IAAjB,CAAnC,CAAN;AACH;;AAED,aAAKpI,GAAL,GAAWA,GAAX;AACH;;kBAEMqb,M,mBAAOrL,a,EAAe;AACzB,YAAI+H,SAAS/H,cAAcwL,KAAd,CAAoB,MAApB,EAA4B1C,MAA5B,CAAmC,UAAS7S,IAAT,EAAe;AAC3D,mBAAOA,SAAS,UAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAE8R,OAAO,CAAP,CAAV;AACH,K;;kBAEM0D,O,oBAAQzL,a,EAAe;AAC1B,YAAI+H,SAAS/H,cAAcwL,KAAd,CAAoB,MAApB,EAA4B1C,MAA5B,CAAmC,UAAS7S,IAAT,EAAe;AAC3D,mBAAOA,SAAS,OAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAE8R,OAAO,CAAP,CAAV;AACH,K;;kBAEM9G,M,mBAAOjB,a,EAAe;AACzB,YAAI+H,SAAS/H,cAAcwL,KAAd,CAAoB,MAApB,EAA4B1C,MAA5B,CAAmC,UAAS7S,IAAT,EAAe;AAC3D,mBAAOA,SAAS,MAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAE8R,OAAO,CAAP,CAAV;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCpGL;AACA;;AAEA;;;;AAEA,IAAM2D,YAAY,QAAlB;;IAEa3J,c,WAAAA,c;AACT,4BAAY/R,GAAZ,EAAkC;AAAA,YAAjB6R,SAAiB,uEAAL,GAAK;;AAAA;;AAE9B,YAAIoG,SAAS/B,uBAAWC,gBAAX,CAA4BnW,GAA5B,EAAiC6R,SAAjC,CAAb;;AAEA,aAAKxP,KAAL,GAAa4V,OAAO5V,KAApB;AACA,aAAKoD,iBAAL,GAAyBwS,OAAOxS,iBAAhC;AACA,aAAKC,SAAL,GAAiBuS,OAAOvS,SAAxB;;AAEA,aAAK4R,IAAL,GAAYW,OAAOX,IAAnB;AACA,aAAK3R,KAAL,GAAasS,OAAOtS,KAApB;AACA,aAAKyR,QAAL,GAAgBa,OAAOb,QAAvB;AACA,aAAK5U,aAAL,GAAqByV,OAAOzV,aAA5B;AACA,aAAK5D,YAAL,GAAoBqZ,OAAOrZ,YAA3B;AACA,aAAK+c,UAAL,GAAkB1D,OAAO0D,UAAzB;AACA,aAAK1L,KAAL,GAAagI,OAAOhI,KAApB;AACA,aAAKuH,OAAL,GAAe1Y,SAAf,CAf8B,CAeJ;;AAE1B,aAAKD,UAAL,GAAkBoZ,OAAOpZ,UAAzB;AACH;;;;4BAEgB;AACb,gBAAI,KAAK+c,UAAT,EAAqB;AACjB,oBAAI5R,MAAMc,SAASC,KAAKf,GAAL,KAAa,IAAtB,CAAV;AACA,uBAAO,KAAK4R,UAAL,GAAkB5R,GAAzB;AACH;AACD,mBAAOlL,SAAP;AACH,S;0BACcwJ,K,EAAM;AACjB,gBAAIzJ,aAAaiM,SAASxC,KAAT,CAAjB;AACA,gBAAI,OAAOzJ,UAAP,KAAsB,QAAtB,IAAkCA,aAAa,CAAnD,EAAsD;AAClD,oBAAImL,MAAMc,SAASC,KAAKf,GAAL,KAAa,IAAtB,CAAV;AACA,qBAAK4R,UAAL,GAAkB5R,MAAMnL,UAAxB;AACH;AACJ;;;4BAEa;AACV,gBAAIA,aAAa,KAAKA,UAAtB;AACA,gBAAIA,eAAeC,SAAnB,EAA8B;AAC1B,uBAAOD,cAAc,CAArB;AACH;AACD,mBAAOC,SAAP;AACH;;;4BAEY;AACT,mBAAO,CAAC,KAAKmR,KAAL,IAAc,EAAf,EAAmBuL,KAAnB,CAAyB,GAAzB,CAAP;AACH;;;4BAEqB;AAClB,mBAAO,KAAKK,MAAL,CAAYpb,OAAZ,CAAoBib,SAApB,KAAkC,CAAlC,IAAuC,CAAC,CAAC,KAAKtE,QAArD;AACH;;;;;;;;;;;;;;;;;;;;;;;;;ACtDL;;AACA;;AACA;;AACA;;;;;;;;;;+eANA;AACA;;IAOahF,W,WAAAA,W;;;AACT,2BAAkJ;AAAA,uFAAJ,EAAI;AAAA,YAArI+E,KAAqI,QAArIA,KAAqI;AAAA,YAA9HrH,SAA8H,QAA9HA,SAA8H;AAAA,YAAnH/P,SAAmH,QAAnHA,SAAmH;AAAA,YAAxG8D,YAAwG,QAAxGA,YAAwG;AAAA,YAA1FwT,aAA0F,QAA1FA,aAA0F;AAAA,YAA3E3G,aAA2E,QAA3EA,aAA2E;AAAA,YAA5DU,aAA4D,QAA5DA,aAA4D;AAAA,YAA7CnB,KAA6C,QAA7CA,KAA6C;AAAA,YAAtCW,gBAAsC,QAAtCA,gBAAsC;AAAA,YAApBE,YAAoB,QAApBA,YAAoB;;AAAA;;AAAA,qDAC9I,kBAAMgL,UAAU,CAAV,CAAN,CAD8I;;AAG9I,YAAI3E,UAAU,IAAd,EAAoB;AAChB,kBAAK4E,MAAL,GAAc,uBAAd;AACH,SAFD,MAGK,IAAI5E,KAAJ,EAAW;AACZ,kBAAK4E,MAAL,GAAc5E,KAAd;AACH;;AAED,YAAIE,kBAAkB,IAAtB,EAA4B;AACxB;AACA,kBAAK2E,cAAL,GAAsB,0BAAW,uBAAX,GAAsB,uBAA5C;AACH,SAHD,MAIK,IAAI3E,aAAJ,EAAmB;AACpB,kBAAK2E,cAAL,GAAsB3E,aAAtB;AACH;;AAED,YAAI,MAAKA,aAAT,EAAwB;AACpB,gBAAI8B,OAAOxO,mBAASkB,UAAT,CAAoB,MAAKwL,aAAzB,EAAwC,QAAxC,CAAX;AACA,kBAAK4E,eAAL,GAAuBtR,mBAASqB,cAAT,CAAwBmN,IAAxB,CAAvB;AACH;;AAED,cAAK5E,aAAL,GAAqB1Q,YAArB;AACA,cAAKoQ,UAAL,GAAkBnE,SAAlB;AACA,cAAK1P,UAAL,GAAkBL,SAAlB;AACA,cAAKgV,cAAL,GAAsBrE,aAAtB;AACA,cAAK0D,cAAL,GAAsBhD,aAAtB;AACA,cAAKkD,MAAL,GAAcrE,KAAd;AACA,cAAKqF,iBAAL,GAAyB1E,gBAAzB;AACA,cAAKsL,aAAL,GAAqBpL,YAArB;AA9B8I;AA+BjJ;;0BAoCDW,e,8BAAkB;AACdtU,iBAAI6B,KAAJ,CAAU,6BAAV;AACA,eAAOkO,KAAKiP,SAAL,CAAe;AAClB3K,gBAAI,KAAKA,EADS;AAElBpP,kBAAM,KAAKA,IAFO;AAGlBga,qBAAS,KAAKA,OAHI;AAIlBvL,0BAAc,KAAKA,YAJD;AAKlBsG,mBAAO,KAAKA,KALM;AAMlBE,2BAAe,KAAKA,aANF;AAOlBxT,0BAAc,KAAKA,YAPD;AAQlBiM,uBAAW,KAAKA,SARE;AASlB/P,uBAAW,KAAKA,SATE;AAUlB2Q,2BAAe,KAAKA,aAVF;AAWlBU,2BAAe,KAAKA,aAXF;AAYlBnB,mBAAO,KAAKA,KAZM;AAalBW,8BAAmB,KAAKA,gBAbN;AAclBE,0BAAc,KAAKA;AAdD,SAAf,CAAP;AAgBH,K;;gBAEMuB,iB,8BAAkBgK,a,EAAe;AACpClf,iBAAI6B,KAAJ,CAAU,+BAAV;AACA,YAAIoD,OAAO8K,KAAK3D,KAAL,CAAW8S,aAAX,CAAX;AACA,eAAO,IAAIjK,WAAJ,CAAgBhQ,IAAhB,CAAP;AACH,K;;;;4BA1DW;AACR,mBAAO,KAAK2Z,MAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAK9H,UAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAK7T,UAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKmU,aAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKyH,cAAZ;AACH;;;4BACoB;AACjB,mBAAO,KAAKC,eAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKlH,cAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKX,cAAZ;AACH;;;4BACW;AACR,mBAAO,KAAKE,MAAZ;AACH;;;4BACsB;AACnB,mBAAO,KAAKgB,iBAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAK4G,aAAZ;AACH;;;;EAlE4BlJ,a;;;;;;;;;;;;;;;;;;;ACLjC;;AACA;;AACA;;0JALA;AACA;;IAMaL,c,WAAAA,c,GACT,8BAAkG;AAAA,QAArF3S,GAAqF,QAArFA,GAAqF;AAAA,QAAhFqQ,aAAgF,QAAhFA,aAAgF;AAAA,QAAjEqC,wBAAiE,QAAjEA,wBAAiE;AAAA,QAAvCtQ,IAAuC,QAAvCA,IAAuC;AAAA,QAAjCuO,gBAAiC,QAAjCA,gBAAiC;AAAA,QAAfE,YAAe,QAAfA,YAAe;;AAAA;;AAC9F,QAAI,CAAC7Q,GAAL,EAAU;AACN7C,iBAAIkF,KAAJ,CAAU,oCAAV;AACA,cAAM,IAAIgD,KAAJ,CAAU,KAAV,CAAN;AACH;;AAED,QAAIgL,aAAJ,EAAmB;AACfrQ,cAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,eAA9B,EAA+CqQ,aAA/C,CAAN;AACH;;AAED,QAAIqC,wBAAJ,EAA8B;AAC1B1S,cAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,0BAA9B,EAA0D0S,wBAA1D,CAAN;;AAEA,YAAItQ,IAAJ,EAAU;AACN,iBAAKuD,KAAL,GAAa,IAAIqN,YAAJ,CAAU,EAAE5Q,UAAF,EAAQyO,0BAAR,EAAV,CAAb;;AAEA7Q,kBAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8B,OAA9B,EAAuC,KAAK2F,KAAL,CAAW6L,EAAlD,CAAN;AACH;AACJ;;AAED,SAAI,IAAIpJ,GAAR,IAAeuI,gBAAf,EAAgC;AAC5B3Q,cAAMkW,uBAAWoF,aAAX,CAAyBtb,GAAzB,EAA8BoI,GAA9B,EAAmCuI,iBAAiBvI,GAAjB,CAAnC,CAAN;AACH;;AAED,SAAKpI,GAAL,GAAWA,GAAX;AACH,C;;;;;;;;;;;;;;;;;;;AC9BL;;0JAHA;AACA;;IAIa8S,e,WAAAA,e,GACT,yBAAY9S,GAAZ,EAAiB;AAAA;;AAEb,YAAIiY,SAAS/B,uBAAWC,gBAAX,CAA4BnW,GAA5B,EAAiC,GAAjC,CAAb;;AAEA,aAAKqC,KAAL,GAAa4V,OAAO5V,KAApB;AACA,aAAKoD,iBAAL,GAAyBwS,OAAOxS,iBAAhC;AACA,aAAKC,SAAL,GAAiBuS,OAAOvS,SAAxB;;AAEA,aAAKC,KAAL,GAAasS,OAAOtS,KAApB;AACH,C;;;;;;;;;;;;;;;;;;;ACZL;;0JAHA;AACA;;IAIa2W,kB,WAAAA,kB;AAET,gCAAYhD,WAAZ,EAAyB;AAAA;;AACrB,aAAKE,YAAL,GAAoBF,WAApB;AACH;;iCAED/W,K,oBAAQ;AACJ,YAAI,CAAC,KAAKpC,SAAV,EAAqB;AACjB,iBAAKA,SAAL,GAAiB,KAAKoc,cAAL,CAAoBza,IAApB,CAAyB,IAAzB,CAAjB;AACA,iBAAK0X,YAAL,CAAkBE,MAAlB,CAAyBpa,sBAAzB,CAAgD,KAAKa,SAArD;;AAEA;AACA,iBAAKqZ,YAAL,CAAkBO,OAAlB,GAA4BpO,IAA5B,CAAiC,gBAAM;AACnC;AACH,aAFD,EAEG2O,KAFH,CAES,eAAK;AACV;AACAnd,yBAAIkF,KAAJ,CAAU,+CAAV,EAA2DkY,IAAIpV,OAA/D;AACH,aALD;AAMH;AACJ,K;;iCAED7C,I,mBAAO;AACH,YAAI,KAAKnC,SAAT,EAAoB;AAChB,iBAAKqZ,YAAL,CAAkBE,MAAlB,CAAyBja,yBAAzB,CAAmD,KAAKU,SAAxD;AACA,mBAAO,KAAKA,SAAZ;AACH;AACJ,K;;iCAEDoc,c,6BAAiB;AAAA;;AACb,aAAK/C,YAAL,CAAkBgD,YAAlB,GAAiC7Q,IAAjC,CAAsC,gBAAQ;AAC1CxO,qBAAI6B,KAAJ,CAAU,oEAAV;AACH,SAFD,EAEG,eAAO;AACN7B,qBAAIkF,KAAJ,CAAU,6DAAV,EAAyEkY,IAAIpV,OAA7E;AACA,kBAAKqU,YAAL,CAAkBE,MAAlB,CAAyB+C,sBAAzB,CAAgDlC,GAAhD;AACH,SALD;AAMH,K;;;;;;;;;;;;;;;;;;;;;;qjBCxCL;AACA;;AAEA;;AACA;;;;;;;;IAEavH,K,WAAAA,K;AACT,qBAAoD;AAAA,uFAAJ,EAAI;AAAA,YAAvCxB,EAAuC,QAAvCA,EAAuC;AAAA,YAAnCpP,IAAmC,QAAnCA,IAAmC;AAAA,YAA7Bga,OAA6B,QAA7BA,OAA6B;AAAA,YAApBvL,YAAoB,QAApBA,YAAoB;;AAAA;;AAChD,aAAKiF,GAAL,GAAWtE,MAAM,uBAAjB;AACA,aAAKtJ,KAAL,GAAa9F,IAAb;;AAEA,YAAI,OAAOga,OAAP,KAAmB,QAAnB,IAA+BA,UAAU,CAA7C,EAAgD;AAC5C,iBAAKM,QAAL,GAAgBN,OAAhB;AACH,SAFD,MAGK;AACD,iBAAKM,QAAL,GAAgB5R,SAASC,KAAKf,GAAL,KAAa,IAAtB,CAAhB;AACH;AACD,aAAK2S,aAAL,GAAsB9L,YAAtB;AACH;;oBAeDY,e,8BAAkB;AACdtU,iBAAI6B,KAAJ,CAAU,uBAAV;AACA,eAAOkO,KAAKiP,SAAL,CAAe;AAClB3K,gBAAI,KAAKA,EADS;AAElBpP,kBAAM,KAAKA,IAFO;AAGlBga,qBAAS,KAAKA,OAHI;AAIlBvL,0BAAc,KAAKA;AAJD,SAAf,CAAP;AAMH,K;;UAEMwB,iB,8BAAkBgK,a,EAAe;AACpClf,iBAAI6B,KAAJ,CAAU,yBAAV;AACA,eAAO,IAAIgU,KAAJ,CAAU9F,KAAK3D,KAAL,CAAW8S,aAAX,CAAV,CAAP;AACH,K;;UAEMlJ,e,4BAAgByJ,O,EAASC,G,EAAK;;AAEjC,YAAIC,SAAS/R,KAAKf,GAAL,KAAa,IAAb,GAAoB6S,GAAjC;;AAEA,eAAOD,QAAQG,UAAR,GAAqBpR,IAArB,CAA0B,gBAAQ;AACrCxO,qBAAI6B,KAAJ,CAAU,iCAAV,EAA6C4Q,IAA7C;;AAEA,gBAAIoN,WAAW,EAAf;;AAHqC,uCAI5B5W,CAJ4B;AAKjC,oBAAIgC,MAAMwH,KAAKxJ,CAAL,CAAV;AACI6W,oBAAIL,QAAQ1K,GAAR,CAAY9J,GAAZ,EAAiBuD,IAAjB,CAAsB,gBAAQ;AAClC,wBAAIsG,SAAS,KAAb;;AAEA,wBAAIhM,IAAJ,EAAU;AACN,4BAAI;AACA,gCAAIN,QAAQqN,MAAMX,iBAAN,CAAwBpM,IAAxB,CAAZ;;AAEA9I,qCAAI6B,KAAJ,CAAU,4CAAV,EAAwDoJ,GAAxD,EAA6DzC,MAAMyW,OAAnE;;AAEA,gCAAIzW,MAAMyW,OAAN,IAAiBU,MAArB,EAA6B;AACzB7K,yCAAS,IAAT;AACH;AACJ,yBARD,CASA,OAAOjQ,CAAP,EAAU;AACN7E,qCAAIkF,KAAJ,CAAU,oDAAV,EAAgE+F,GAAhE,EAAqEpG,EAAEmD,OAAvE;AACA8M,qCAAS,IAAT;AACH;AACJ,qBAdD,MAeK;AACD9U,iCAAI6B,KAAJ,CAAU,qDAAV,EAAiEoJ,GAAjE;AACA6J,iCAAS,IAAT;AACH;;AAED,wBAAIA,MAAJ,EAAY;AACR9U,iCAAI6B,KAAJ,CAAU,+CAAV,EAA2DoJ,GAA3D;AACA,+BAAOwU,QAAQ3K,MAAR,CAAe7J,GAAf,CAAP;AACH;AACJ,iBA3BO,CANyB;;;AAmCjC4U,yBAASjX,IAAT,CAAckX,CAAd;AAnCiC;;AAIrC,iBAAK,IAAI7W,IAAI,CAAb,EAAgBA,IAAIwJ,KAAKvJ,MAAzB,EAAiCD,GAAjC,EAAsC;AAAA,oBAE9B6W,CAF8B;;AAAA,sBAA7B7W,CAA6B;AAgCrC;;AAEDjJ,qBAAI6B,KAAJ,CAAU,kDAAV,EAA8Dge,SAAS3W,MAAvE;AACA,mBAAO9E,QAAQ2b,GAAR,CAAYF,QAAZ,CAAP;AACH,SAxCM,CAAP;AAyCH,K;;;;4BAzEQ;AACL,mBAAO,KAAKlH,GAAZ;AACH;;;4BACU;AACP,mBAAO,KAAK5N,KAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKwU,QAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;;;AC5BL;;AACA;;AACA;;;;;;+eALA;AACA;;AAMA,IAAMQ,gBAAgB,CAAtB,C,CAAyB;;IAEZ9e,K,WAAAA,K;;;AAET,mBAAY6F,IAAZ,EAA6D;AAAA,YAA3CoC,KAA2C,uEAAnCtI,eAAOsI,KAA4B;AAAA,YAArB8W,OAAqB,uEAAXte,SAAW;;AAAA;;AAAA,qDACzD,kBAAMoF,IAAN,CADyD;;AAEzD,cAAKtB,MAAL,GAAc0D,KAAd;;AAEA,YAAI8W,OAAJ,EAAa;AACT,kBAAKC,QAAL,GAAgBD,OAAhB;AACH,SAFD,MAGK;AACD,kBAAKC,QAAL,GAAgB;AAAA,uBAAMtS,KAAKf,GAAL,KAAa,IAAnB;AAAA,aAAhB;AACH;AATwD;AAU5D;;oBAMD9K,I,iBAAKH,Q,EAAU;AACX,YAAIA,YAAY,CAAhB,EAAmB;AACfA,uBAAW,CAAX;AACH;AACDA,mBAAW+L,SAAS/L,QAAT,CAAX;;AAEA,YAAIue,aAAa,KAAKtT,GAAL,GAAWjL,QAA5B;AACA,YAAI,KAAKue,UAAL,KAAoBA,UAApB,IAAkC,KAAKC,YAA3C,EAAyD;AACrD;AACApgB,qBAAI6B,KAAJ,CAAU,sBAAsB,KAAK6G,KAA3B,GAAmC,oEAA7C,EAAmH,KAAKyX,UAAxH;AACA;AACH;;AAED,aAAKne,MAAL;;AAEAhC,iBAAI6B,KAAJ,CAAU,sBAAsB,KAAK6G,KAA3B,GAAmC,gBAA7C,EAA+D9G,QAA/D;AACA,aAAKye,WAAL,GAAmBF,UAAnB;;AAEA;AACA;AACA;AACA,YAAIG,gBAAgBN,aAApB;AACA,YAAIpe,WAAW0e,aAAf,EAA8B;AAC1BA,4BAAgB1e,QAAhB;AACH;AACD,aAAKwe,YAAL,GAAoB,KAAK3a,MAAL,CAAYC,WAAZ,CAAwB,KAAK1C,SAAL,CAAe2B,IAAf,CAAoB,IAApB,CAAxB,EAAmD2b,gBAAgB,IAAnE,CAApB;AACH,K;;oBAMDte,M,qBAAS;AACL,YAAI,KAAKoe,YAAT,EAAuB;AACnBpgB,qBAAI6B,KAAJ,CAAU,gBAAV,EAA4B,KAAK6G,KAAjC;AACA,iBAAKjD,MAAL,CAAYE,aAAZ,CAA0B,KAAKya,YAA/B;AACA,iBAAKA,YAAL,GAAoB,IAApB;AACH;AACJ,K;;oBAEDpd,S,wBAAY;AACR,YAAIud,OAAO,KAAKF,WAAL,GAAmB,KAAKxT,GAAnC;AACA7M,iBAAI6B,KAAJ,CAAU,qBAAqB,KAAK6G,KAA1B,GAAkC,oBAA5C,EAAkE6X,IAAlE;;AAEA,YAAI,KAAKF,WAAL,IAAoB,KAAKxT,GAA7B,EAAkC;AAC9B,iBAAK7K,MAAL;AACA,6BAAMgH,KAAN;AACH;AACJ,K;;;;4BApDS;AACN,mBAAO2E,SAAS,KAAKuS,QAAL,EAAT,CAAP;AACH;;;4BA8BgB;AACb,mBAAO,KAAKG,WAAZ;AACH;;;;EAhDsB5X,a;;;;;;;;;;;;;;;;;;;ACN3B;;AACA;;AACA;;0JALA;AACA;;IAMagR,W,WAAAA,W;AACT,yBAAYpI,QAAZ,EAA4F;AAAA,YAAtEC,eAAsE,uEAApDxC,wBAAoD;AAAA,YAAvC+H,mBAAuC,uEAAjBtW,gCAAiB;;AAAA;;AACxF,YAAI,CAAC8Q,QAAL,EAAe;AACXrR,qBAAIkF,KAAJ,CAAU,sCAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKqJ,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,EAApB;AACA,aAAKyC,gBAAL,GAAwB,IAAI8C,mBAAJ,CAAwB,KAAKtF,SAA7B,CAAxB;AACH;;0BAED6J,Y,2BAAwB;AAAA;;AAAA,YAAXnK,IAAW,uEAAJ,EAAI;;AACpBA,eAAO3F,OAAOuP,MAAP,CAAc,EAAd,EAAkB5J,IAAlB,CAAP;;AAEAA,aAAKuP,UAAL,GAAkBvP,KAAKuP,UAAL,IAAmB,oBAArC;AACAvP,aAAKrO,SAAL,GAAiBqO,KAAKrO,SAAL,IAAkB,KAAK2O,SAAL,CAAe3O,SAAlD;AACAqO,aAAKvK,YAAL,GAAoBuK,KAAKvK,YAAL,IAAqB,KAAK6K,SAAL,CAAe7K,YAAxD;;AAEA,YAAI,CAACuK,KAAKkJ,IAAV,EAAgB;AACZna,qBAAIkF,KAAJ,CAAU,0CAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,oBAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC+I,KAAKvK,YAAV,EAAwB;AACpB1G,qBAAIkF,KAAJ,CAAU,kDAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC+I,KAAKiJ,aAAV,EAAyB;AACrBla,qBAAIkF,KAAJ,CAAU,mDAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC+I,KAAKrO,SAAV,EAAqB;AACjB5C,qBAAIkF,KAAJ,CAAU,+CAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAK6L,gBAAL,CAAsBhC,gBAAtB,CAAuC,KAAvC,EAA8CvD,IAA9C,CAAmD,eAAO;AAC7DxO,qBAAI6B,KAAJ,CAAU,mDAAV;;AAEA,mBAAO,MAAK2P,YAAL,CAAkBpB,QAAlB,CAA2BvN,GAA3B,EAAgCoO,IAAhC,EAAsCzC,IAAtC,CAA2C,oBAAY;AAC1DxO,yBAAI6B,KAAJ,CAAU,6CAAV;AACA,uBAAO8S,QAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;0BAED8L,oB,mCAAgC;AAAA;;AAAA,YAAXxP,IAAW,uEAAJ,EAAI;;AAC5BA,eAAO3F,OAAOuP,MAAP,CAAc,EAAd,EAAkB5J,IAAlB,CAAP;;AAEAA,aAAKuP,UAAL,GAAkBvP,KAAKuP,UAAL,IAAmB,eAArC;AACAvP,aAAKrO,SAAL,GAAiBqO,KAAKrO,SAAL,IAAkB,KAAK2O,SAAL,CAAe3O,SAAlD;AACAqO,aAAKgD,aAAL,GAAqBhD,KAAKgD,aAAL,IAAsB,KAAK1C,SAAL,CAAe0C,aAA1D;;AAEA,YAAI,CAAChD,KAAKyP,aAAV,EAAyB;AACrB1gB,qBAAIkF,KAAJ,CAAU,2DAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC+I,KAAKrO,SAAV,EAAqB;AACjB5C,qBAAIkF,KAAJ,CAAU,uDAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAK6L,gBAAL,CAAsBhC,gBAAtB,CAAuC,KAAvC,EAA8CvD,IAA9C,CAAmD,eAAO;AAC7DxO,qBAAI6B,KAAJ,CAAU,2DAAV;;AAEA,mBAAO,OAAK2P,YAAL,CAAkBpB,QAAlB,CAA2BvN,GAA3B,EAAgCoO,IAAhC,EAAsCzC,IAAtC,CAA2C,oBAAY;AAC1DxO,yBAAI6B,KAAJ,CAAU,qDAAV;AACA,uBAAO8S,QAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;;;;;;;;;;;;;;;;;;;;;AC1EL;;AACA;;AACA;;0JALA;AACA;;AAMA,IAAMgM,sBAAsB,cAA5B;AACA,IAAMC,uBAAuB,eAA7B;;IAEajgB,qB,WAAAA,qB;AACT,mCAAY0Q,QAAZ,EAAyG;AAAA,YAAnFrC,kBAAmF,uEAA9DnO,eAAOgJ,cAAuD;AAAA,YAAvCgN,mBAAuC,uEAAjBtW,gCAAiB;;AAAA;;AACrG,YAAI,CAAC8Q,QAAL,EAAe;AACXrR,qBAAIkF,KAAJ,CAAU,kDAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,uBAAV,CAAN;AACH;;AAED,aAAKqJ,SAAL,GAAiBF,QAAjB;AACA,aAAKwP,mBAAL,GAA2B7R,kBAA3B;AACA,aAAK+E,gBAAL,GAAwB,IAAI8C,mBAAJ,CAAwB,KAAKtF,SAA7B,CAAxB;AACH;;oCAEDuP,M,mBAAO5U,K,EAAO6U,Q,EAAiC;AAAA;;AAAA,YAAvB/F,IAAuB,uEAAhB,cAAgB;;AAC3C,YAAI,CAAC9O,KAAL,EAAY;AACRlM,qBAAIkF,KAAJ,CAAU,iDAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,oBAAV,CAAN;AACH;;AAED,YAAI8S,SAAS2F,mBAAT,IAAgC3F,QAAQ4F,oBAA5C,EAAkE;AAC9D5gB,qBAAIkF,KAAJ,CAAU,kDAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,qBAAV,CAAN;AACH;;AAED,eAAO,KAAK6L,gBAAL,CAAsB5B,qBAAtB,GAA8C3D,IAA9C,CAAmD,eAAO;AAC7D,gBAAI,CAAC3L,GAAL,EAAU;AACN,oBAAIke,QAAJ,EAAc;AACV/gB,6BAAIkF,KAAJ,CAAU,wDAAV;AACA,0BAAM,IAAIgD,KAAJ,CAAU,0BAAV,CAAN;AACH;;AAED;AACA;AACH;;AAEDlI,qBAAI6B,KAAJ,CAAU,4CAA4CmZ,IAAtD;AACA,gBAAIpY,YAAY,MAAK2O,SAAL,CAAe3O,SAA/B;AACA,gBAAIqR,gBAAgB,MAAK1C,SAAL,CAAe0C,aAAnC;AACA,mBAAO,MAAK+M,OAAL,CAAane,GAAb,EAAkBD,SAAlB,EAA6BqR,aAA7B,EAA4C/H,KAA5C,EAAmD8O,IAAnD,CAAP;AACH,SAfM,CAAP;AAgBH,K;;oCAEDgG,O,oBAAQne,G,EAAKD,S,EAAWqR,a,EAAe/H,K,EAAO8O,I,EAAM;AAAA;;AAEhD,eAAO,IAAI5W,OAAJ,CAAY,UAACC,OAAD,EAAU+B,MAAV,EAAqB;;AAEpC,gBAAI6a,MAAM,IAAI,OAAKJ,mBAAT,EAAV;AACAI,gBAAIzZ,IAAJ,CAAS,MAAT,EAAiB3E,GAAjB;;AAEAoe,gBAAI3c,MAAJ,GAAa,YAAM;AACftE,yBAAI6B,KAAJ,CAAU,8DAAV,EAA0Eof,IAAIxR,MAA9E;;AAEA,oBAAIwR,IAAIxR,MAAJ,KAAe,GAAnB,EAAwB;AACpBpL;AACH,iBAFD,MAGK;AACD+B,2BAAO8B,MAAM+Y,IAAIhR,UAAJ,GAAiB,IAAjB,GAAwBgR,IAAIxR,MAA5B,GAAqC,GAA3C,CAAP;AACH;AACJ,aATD;AAUAwR,gBAAI/Q,OAAJ,GAAc,YAAM;AAChBlQ,yBAAI6B,KAAJ,CAAU,8CAAV;AACAuE,uBAAO,eAAP;AACH,aAHD;;AAKA,gBAAI7B,OAAO,eAAe8L,mBAAmBzN,SAAnB,CAA1B;AACA,gBAAIqR,aAAJ,EAAmB;AACf1P,wBAAQ,oBAAoB8L,mBAAmB4D,aAAnB,CAA5B;AACH;AACD1P,oBAAQ,sBAAsB8L,mBAAmB2K,IAAnB,CAA9B;AACAzW,oBAAQ,YAAY8L,mBAAmBnE,KAAnB,CAApB;;AAEA+U,gBAAI9Q,gBAAJ,CAAqB,cAArB,EAAqC,mCAArC;AACA8Q,gBAAI1b,IAAJ,CAAShB,IAAT;AACH,SA7BM,CAAP;AA8BH,K;;;;;;;;;;;;;;;;;;;;;;AChFL;;AACA;;0JAJA;AACA;;IAKawU,U,WAAAA,U;;;;;eACFoF,a,0BAActb,G,EAAKkE,I,EAAMoE,K,EAAO;AACnC,YAAItI,IAAIS,OAAJ,CAAY,GAAZ,IAAmB,CAAvB,EAA0B;AACtBT,mBAAO,GAAP;AACH;;AAED,YAAIA,IAAIA,IAAIqG,MAAJ,GAAa,CAAjB,MAAwB,GAA5B,EAAiC;AAC7BrG,mBAAO,GAAP;AACH;;AAEDA,eAAOwN,mBAAmBtJ,IAAnB,CAAP;AACAlE,eAAO,GAAP;AACAA,eAAOwN,mBAAmBlF,KAAnB,CAAP;;AAEA,eAAOtI,GAAP;AACH,K;;eAEMmW,gB,6BAAiB7N,K,EAAyC;AAAA,YAAlCuJ,SAAkC,uEAAtB,GAAsB;AAAA,YAAjBwM,MAAiB,uEAARrgB,cAAQ;;AAC7D,YAAI,OAAOsK,KAAP,KAAiB,QAArB,EAA8B;AAC1BA,oBAAQ+V,OAAOxX,QAAP,CAAgBiB,IAAxB;AACH;;AAED,YAAItH,MAAM8H,MAAMgW,WAAN,CAAkBzM,SAAlB,CAAV;AACA,YAAIrR,OAAO,CAAX,EAAc;AACV8H,oBAAQA,MAAM3H,MAAN,CAAaH,MAAM,CAAnB,CAAR;AACH;;AAED,YAAIqR,cAAc,GAAlB,EAAuB;AACnB;AACArR,kBAAM8H,MAAM7H,OAAN,CAAc,GAAd,CAAN;AACA,gBAAID,OAAO,CAAX,EAAc;AACV8H,wBAAQA,MAAM3H,MAAN,CAAa,CAAb,EAAgBH,GAAhB,CAAR;AACH;AACJ;;AAED,YAAIwC,SAAS,EAAb;AAAA,YACIub,QAAQ,mBADZ;AAAA,YAEIC,CAFJ;;AAIA,YAAIC,UAAU,CAAd;AACA,eAAOD,IAAID,MAAMG,IAAN,CAAWpW,KAAX,CAAX,EAA8B;AAC1BtF,mBAAO2b,mBAAmBH,EAAE,CAAF,CAAnB,CAAP,IAAmCG,mBAAmBH,EAAE,CAAF,CAAnB,CAAnC;AACA,gBAAIC,YAAY,EAAhB,EAAoB;AAChBthB,yBAAIkF,KAAJ,CAAU,8EAAV,EAA0FiG,KAA1F;AACA,uBAAO;AACHjG,2BAAO;AADJ,iBAAP;AAGH;AACJ;;AAED,aAAK,IAAIuc,IAAT,IAAiB5b,MAAjB,EAAyB;AACrB,mBAAOA,MAAP;AACH;;AAED,eAAO,EAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBC7DL;AACA;;AAEA;;;;IAEa/E,I,WAAAA,I;AACT,wBAAmH;AAAA,YAAtGmZ,QAAsG,QAAtGA,QAAsG;AAAA,YAA5F5U,aAA4F,QAA5FA,aAA4F;AAAA,YAA7E5D,YAA6E,QAA7EA,YAA6E;AAAA,YAA/Dif,aAA+D,QAA/DA,aAA+D;AAAA,YAAhDlC,UAAgD,QAAhDA,UAAgD;AAAA,YAApC1L,KAAoC,QAApCA,KAAoC;AAAA,YAA7BuH,OAA6B,QAA7BA,OAA6B;AAAA,YAApBoE,UAAoB,QAApBA,UAAoB;AAAA,YAARjW,KAAQ,QAARA,KAAQ;;AAAA;;AAC/G,aAAKyR,QAAL,GAAgBA,QAAhB;AACA,aAAK5U,aAAL,GAAqBA,aAArB;AACA,aAAK5D,YAAL,GAAoBA,YAApB;AACA,aAAKif,aAAL,GAAqBA,aAArB;AACA,aAAKlC,UAAL,GAAkBA,UAAlB;AACA,aAAK1L,KAAL,GAAaA,KAAb;AACA,aAAKuH,OAAL,GAAeA,OAAf;AACA,aAAKoE,UAAL,GAAkBA,UAAlB;AACA,aAAKjW,KAAL,GAAaA,KAAb;AACH;;mBA6BD8L,e,8BAAkB;AACdtU,iBAAI6B,KAAJ,CAAU,sBAAV;AACA,eAAOkO,KAAKiP,SAAL,CAAe;AAClB/E,sBAAU,KAAKA,QADG;AAElB5U,2BAAe,KAAKA,aAFF;AAGlB5D,0BAAc,KAAKA,YAHD;AAIlBif,2BAAe,KAAKA,aAJF;AAKlBlC,wBAAY,KAAKA,UALC;AAMlB1L,mBAAO,KAAKA,KANM;AAOlBuH,qBAAS,KAAKA,OAPI;AAQlBoE,wBAAY,KAAKA;AARC,SAAf,CAAP;AAUH,K;;SAEMvJ,iB,8BAAkBgK,a,EAAe;AACpClf,iBAAI6B,KAAJ,CAAU,wBAAV;AACA,eAAO,IAAIf,IAAJ,CAASiP,KAAK3D,KAAL,CAAW8S,aAAX,CAAT,CAAP;AACH,K;;;;4BA5CgB;AACb,gBAAI,KAAKT,UAAT,EAAqB;AACjB,oBAAI5R,MAAMc,SAASC,KAAKf,GAAL,KAAa,IAAtB,CAAV;AACA,uBAAO,KAAK4R,UAAL,GAAkB5R,GAAzB;AACH;AACD,mBAAOlL,SAAP;AACH,S;0BACcwJ,K,EAAO;AAClB,gBAAIzJ,aAAaiM,SAASxC,KAAT,CAAjB;AACA,gBAAI,OAAOzJ,UAAP,KAAsB,QAAtB,IAAkCA,aAAa,CAAnD,EAAsD;AAClD,oBAAImL,MAAMc,SAASC,KAAKf,GAAL,KAAa,IAAtB,CAAV;AACA,qBAAK4R,UAAL,GAAkB5R,MAAMnL,UAAxB;AACH;AACJ;;;4BAEa;AACV,gBAAIA,aAAa,KAAKA,UAAtB;AACA,gBAAIA,eAAeC,SAAnB,EAA8B;AAC1B,uBAAOD,cAAc,CAArB;AACH;AACD,mBAAOC,SAAP;AACH;;;4BAEY;AACT,mBAAO,CAAC,KAAKmR,KAAL,IAAc,EAAf,EAAmBuL,KAAnB,CAAyB,GAAzB,CAAP;AACH;;;;;;;;;;;;;;;;;;;;;;;ACxCL;;AACA;;AACA;;AACA;;0JANA;AACA;;IAOa/E,e,WAAAA,e;AACT,6BACIjI,QADJ,EAKE;AAAA,YAHEC,eAGF,uEAHoBxC,wBAGpB;AAAA,YAFE+H,mBAEF,uEAFwBtW,gCAExB;AAAA,YADEgZ,QACF,uEADa/L,kBACb;;AAAA;;AACE,YAAI,CAAC6D,QAAL,EAAe;AACXrR,qBAAIkF,KAAJ,CAAU,0CAAV;AACA,kBAAM,IAAIgD,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKqJ,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,CAAoB3P,SAApB,EAA+BA,SAA/B,EAA0C,KAAK+f,iBAAL,CAAuB/c,IAAvB,CAA4B,IAA5B,CAA1C,CAApB;AACA,aAAKoP,gBAAL,GAAwB,IAAI8C,mBAAJ,CAAwB,KAAKtF,SAA7B,CAAxB;AACA,aAAKoI,SAAL,GAAiBJ,QAAjB;AACH;;8BAEDe,S,sBAAUpO,K,EAAO;AAAA;;AACb,YAAI,CAACA,KAAL,EAAY;AACRlM,qBAAIkF,KAAJ,CAAU,4CAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,qBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAK6L,gBAAL,CAAsBjC,mBAAtB,GAA4CtD,IAA5C,CAAiD,eAAO;AAC3DxO,qBAAI6B,KAAJ,CAAU,kDAAV,EAA8DgB,GAA9D;;AAEA,mBAAO,MAAK2O,YAAL,CAAkBlC,OAAlB,CAA0BzM,GAA1B,EAA+BqJ,KAA/B,EAAsCsC,IAAtC,CAA2C,kBAAU;AACxDxO,yBAAI6B,KAAJ,CAAU,4CAAV,EAAwD0Y,MAAxD;AACA,uBAAOA,MAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;8BAEDmH,iB,8BAAkBnS,G,EAAK;AAAA;;AACnB,YAAI;AACA,gBAAItD,MAAM,KAAK0N,SAAL,CAAe3N,QAAf,CAAwBuD,IAAIS,YAA5B,CAAV;AACA,gBAAI,CAAC/D,GAAD,IAAQ,CAACA,IAAII,MAAb,IAAuB,CAACJ,IAAIM,OAAhC,EAAyC;AACrCvM,yBAAIkF,KAAJ,CAAU,wDAAV,EAAoE+G,GAApE;AACA,uBAAO7H,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,gBAAIuT,MAAMxP,IAAII,MAAJ,CAAWoP,GAArB;;AAEA,gBAAIkG,sBAAJ;AACA,oBAAQ,KAAKpQ,SAAL,CAAemF,iBAAvB;AACI,qBAAK,IAAL;AACIiL,oCAAgB,KAAK5N,gBAAL,CAAsBpC,SAAtB,EAAhB;AACA;AACJ,qBAAK,KAAL;AACIgQ,oCAAgBvd,QAAQC,OAAR,CAAgB4H,IAAIM,OAAJ,CAAYsB,GAA5B,CAAhB;AACA;AACJ;AACI8T,oCAAgBvd,QAAQC,OAAR,CAAgB,KAAKkN,SAAL,CAAemF,iBAA/B,CAAhB;AACA;AATR;;AAYA,mBAAOiL,cAAcnT,IAAd,CAAmB,kBAAU;AAChCxO,yBAAI6B,KAAJ,CAAU,wDAAwD6K,MAAlE;;AAEA,uBAAO,OAAKqH,gBAAL,CAAsB1B,cAAtB,GAAuC7D,IAAvC,CAA4C,gBAAQ;AACvD,wBAAI,CAACiE,IAAL,EAAW;AACPzS,iCAAIkF,KAAJ,CAAU,kEAAV;AACA,+BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,+BAAV,CAAf,CAAP;AACH;;AAEDlI,6BAAI6B,KAAJ,CAAU,0DAAV;AACA,wBAAIoJ,YAAJ;AACA,wBAAI,CAACwQ,GAAL,EAAU;AACNhJ,+BAAO,OAAKiJ,YAAL,CAAkBjJ,IAAlB,EAAwBxG,IAAII,MAAJ,CAAWsC,GAAnC,CAAP;;AAEA,4BAAI8D,KAAKvJ,MAAL,GAAc,CAAlB,EAAqB;AACjBlJ,qCAAIkF,KAAJ,CAAU,qGAAV;AACA,mCAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,kEAAV,CAAf,CAAP;AACH,yBAHD,MAIK;AACD;AACA;AACA+C,kCAAMwH,KAAK,CAAL,CAAN;AACH;AACJ,qBAZD,MAaK;AACDxH,8BAAMwH,KAAKkJ,MAAL,CAAY,eAAO;AACrB,mCAAO1Q,IAAIwQ,GAAJ,KAAYA,GAAnB;AACH,yBAFK,EAEH,CAFG,CAAN;AAGH;;AAED,wBAAI,CAACxQ,GAAL,EAAU;AACNjL,iCAAIkF,KAAJ,CAAU,qFAAV;AACA,+BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED,wBAAIyE,WAAW,OAAK4E,SAAL,CAAe3O,SAA9B;;AAEA,wBAAI2Y,qBAAqB,OAAKhK,SAAL,CAAe3E,SAAxC;AACA5M,6BAAI6B,KAAJ,CAAU,sFAAV,EAAkG0Z,kBAAlG;;AAEA,2BAAO,OAAK5B,SAAL,CAAelN,WAAf,CAA2B8C,IAAIS,YAA/B,EAA6C/E,GAA7C,EAAkDyB,MAAlD,EAA0DC,QAA1D,EAAoE4O,kBAApE,EAAwF5Z,SAAxF,EAAmG,IAAnG,EAAyG6M,IAAzG,CAA8G,YAAM;AACvHxO,iCAAI6B,KAAJ,CAAU,8DAAV;AACA,+BAAOoK,IAAIM,OAAX;AACH,qBAHM,CAAP;AAIH,iBAzCM,CAAP;AA0CH,aA7CM,CAAP;AA8CA;AACH,SArED,CAsEA,OAAO1H,CAAP,EAAU;AACN7E,qBAAIkF,KAAJ,CAAU,+DAAV,EAA2EL,EAAEmD,OAA7E;AACA5B,mBAAOvB,CAAP;AACA;AACH;AACJ,K;;8BAED6W,Y,yBAAajJ,I,EAAM9D,G,EAAK;AACpB,YAAI5B,MAAM,IAAV;AACA,YAAI4B,IAAImB,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AACtB/C,kBAAM,KAAN;AACH,SAFD,MAGK,IAAI4B,IAAImB,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3B/C,kBAAM,IAAN;AACH,SAFI,MAGA,IAAI4B,IAAImB,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3B/C,kBAAM,IAAN;AACH,SAFI,MAGA;AACD/M,qBAAI6B,KAAJ,CAAU,mDAAV,EAA+D8M,GAA/D;AACA,mBAAO,EAAP;AACH;;AAED3O,iBAAI6B,KAAJ,CAAU,iEAAV,EAA6EkL,GAA7E;;AAEA0F,eAAOA,KAAKkJ,MAAL,CAAY,eAAO;AACtB,mBAAO1Q,IAAI8B,GAAJ,KAAYA,GAAnB;AACH,SAFM,CAAP;;AAIA/M,iBAAI6B,KAAJ,CAAU,+DAAV,EAA2EkL,GAA3E,EAAgF0F,KAAKvJ,MAArF;;AAEA,eAAOuJ,IAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;;;AC9IL;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;;;+eAZA;AACA;;IAcapS,W,WAAAA,W;;;AACT,2BAME;AAAA,YANUgR,QAMV,uEANqB,EAMrB;AAAA,YALEuQ,sBAKF,uEAL2BzC,sCAK3B;AAAA,YAJE0C,kBAIF,uEAJuBjhB,8BAIvB;AAAA,YAHEkhB,yBAGF,uEAH8BnhB,4CAG9B;AAAA,YAFE6Y,eAEF,uEAFoBC,wBAEpB;AAAA,YADEF,QACF,uEADa/L,kBACb;;AAAA;;AAEE,YAAI,EAAE6D,oBAAoB0Q,wCAAtB,CAAJ,EAAgD;AAC5C1Q,uBAAW,IAAI0Q,wCAAJ,CAAwB1Q,QAAxB,CAAX;AACH;;AAJH,qDAKE,uBAAMA,QAAN,CALF;;AAOE,cAAK2Q,OAAL,GAAe,IAAIC,oCAAJ,CAAsB5Q,QAAtB,CAAf;AACA,cAAK6Q,mBAAL,GAA2B,IAAIN,sBAAJ,OAA3B;;AAEA;AACA,YAAI,MAAKvQ,QAAL,CAAc8Q,oBAAlB,EAAwC;AACpCniB,qBAAI6B,KAAJ,CAAU,+EAAV;AACA,kBAAKugB,gBAAL;AACH;;AAED,YAAI,MAAK/Q,QAAL,CAAcgR,cAAlB,EAAkC;AAC9BriB,qBAAI6B,KAAJ,CAAU,4EAAV;AACA,kBAAKygB,eAAL,GAAuB,IAAIT,kBAAJ,OAAvB;AACH;;AAED,cAAKU,sBAAL,GAA8B,IAAIT,yBAAJ,CAA8B,MAAKvQ,SAAnC,CAA9B;AACA,cAAKqI,YAAL,GAAoB,IAAIJ,eAAJ,CAAoB,MAAKjI,SAAzB,CAApB;AACA,cAAKoI,SAAL,GAAiBJ,QAAjB;AAvBF;AAwBD;;0BAmBDqD,O,sBAAU;AAAA;;AACN,eAAO,KAAK4F,SAAL,GAAiBhU,IAAjB,CAAsB,gBAAQ;AACjC,gBAAIqO,IAAJ,EAAU;AACN7c,yBAAIuQ,IAAJ,CAAS,kCAAT;;AAEA,uBAAKyR,OAAL,CAAazgB,IAAb,CAAkBsb,IAAlB,EAAwB,KAAxB;;AAEA,uBAAOA,IAAP;AACH,aAND,MAOK;AACD7c,yBAAIuQ,IAAJ,CAAS,gDAAT;AACA,uBAAO,IAAP;AACH;AACJ,SAZM,CAAP;AAaH,K;;0BAEDkS,U,yBAAa;AAAA;;AACT,eAAO,KAAKC,SAAL,CAAe,IAAf,EAAqBlU,IAArB,CAA0B,YAAM;AACnCxO,qBAAIuQ,IAAJ,CAAS,mDAAT;AACA,mBAAKyR,OAAL,CAAa9f,MAAb;AACH,SAHM,CAAP;AAIH,K;;0BAEDygB,c,6BAA0B;AAAA,YAAX1R,IAAW,uEAAJ,EAAI;;AACtBA,eAAO3F,OAAOuP,MAAP,CAAc,EAAd,EAAkB5J,IAAlB,CAAP;;AAEAA,aAAKyC,YAAL,GAAoB,MAApB;AACA,YAAIkP,YAAY;AACZ1J,kCAAuBjI,KAAKiI;AADhB,SAAhB;AAGA,eAAO,KAAK2J,YAAL,CAAkB5R,IAAlB,EAAwB,KAAK6R,kBAA7B,EAAiDF,SAAjD,EAA4DpU,IAA5D,CAAiE,YAAI;AACxExO,qBAAIuQ,IAAJ,CAAS,wCAAT;AACH,SAFM,CAAP;AAGH,K;;0BACDwS,sB,mCAAuBlgB,G,EAAK;AACxB,eAAO,KAAKmgB,UAAL,CAAgBngB,OAAO,KAAKigB,kBAAL,CAAwBjgB,GAA/C,EAAoD2L,IAApD,CAAyD,gBAAQ;AACpE,gBAAIqO,KAAKxC,OAAL,IAAgBwC,KAAKxC,OAAL,CAAaG,GAAjC,EAAsC;AAClCxa,yBAAIuQ,IAAJ,CAAS,iEAAT,EAA4EsM,KAAKxC,OAAL,CAAaG,GAAzF;AACH,aAFD,MAGK;AACDxa,yBAAIuQ,IAAJ,CAAS,4CAAT;AACH;;AAED,mBAAOsM,IAAP;AACH,SATM,CAAP;AAUH,K;;0BAEDoG,W,0BAAuB;AAAA,YAAXhS,IAAW,uEAAJ,EAAI;;AACnBA,eAAO3F,OAAOuP,MAAP,CAAc,EAAd,EAAkB5J,IAAlB,CAAP;;AAEAA,aAAKyC,YAAL,GAAoB,MAApB;AACA,YAAI7Q,MAAMoO,KAAKvK,YAAL,IAAqB,KAAK2K,QAAL,CAAc6R,kBAAnC,IAAyD,KAAK7R,QAAL,CAAc3K,YAAjF;AACA,YAAI,CAAC7D,GAAL,EAAU;AACN7C,qBAAIkF,KAAJ,CAAU,2EAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED+I,aAAKvK,YAAL,GAAoB7D,GAApB;AACAoO,aAAKjN,OAAL,GAAe,OAAf;;AAEA,eAAO,KAAKmf,OAAL,CAAalS,IAAb,EAAmB,KAAKmS,eAAxB,EAAyC;AAC5Czc,sBAAU9D,GADkC;AAE5CiD,iCAAqBmL,KAAKnL,mBAAL,IAA4B,KAAKuL,QAAL,CAAcvL,mBAFnB;AAG5CW,+BAAmBwK,KAAKxK,iBAAL,IAA0B,KAAK4K,QAAL,CAAc5K;AAHf,SAAzC,EAIJ+H,IAJI,CAIC,gBAAQ;AACZ,gBAAIqO,IAAJ,EAAU;AACN,oBAAIA,KAAKxC,OAAL,IAAgBwC,KAAKxC,OAAL,CAAaG,GAAjC,EAAsC;AAClCxa,6BAAIuQ,IAAJ,CAAS,kEAAT,EAA6EsM,KAAKxC,OAAL,CAAaG,GAA1F;AACH,iBAFD,MAGK;AACDxa,6BAAIuQ,IAAJ,CAAS,iCAAT;AACH;AACJ;;AAED,mBAAOsM,IAAP;AACH,SAfM,CAAP;AAgBH,K;;0BACDwG,mB,gCAAoBxgB,G,EAAK;AACrB,eAAO,KAAKygB,eAAL,CAAqBzgB,GAArB,EAA0B,KAAKugB,eAA/B,EAAgD5U,IAAhD,CAAqD,gBAAQ;AAChE,gBAAIqO,IAAJ,EAAU;AACN,oBAAIA,KAAKxC,OAAL,IAAgBwC,KAAKxC,OAAL,CAAaG,GAAjC,EAAsC;AAClCxa,6BAAIuQ,IAAJ,CAAS,8DAAT,EAAyEsM,KAAKxC,OAAL,CAAaG,GAAtF;AACH,iBAFD,MAGK;AACDxa,6BAAIuQ,IAAJ,CAAS,yCAAT;AACH;AACJ;;AAED,mBAAOsM,IAAP;AACH,SAXM,EAWJM,KAXI,CAWE,eAAK;AACVnd,qBAAIkF,KAAJ,CAAU,SAAmDkY,IAAIpV,OAAjE;AACH,SAbM,CAAP;AAcH,K;;0BAEDqX,Y,2BAAwB;AAAA;;AAAA,YAAXpO,IAAW,uEAAJ,EAAI;;AACpBA,eAAO3F,OAAOuP,MAAP,CAAc,EAAd,EAAkB5J,IAAlB,CAAP;;AAEAA,aAAKyC,YAAL,GAAoB,MAApB;AACA;AACA,eAAO,KAAK8O,SAAL,GAAiBhU,IAAjB,CAAsB,gBAAQ;AACjC,gBAAIqO,QAAQA,KAAK6D,aAAjB,EAAgC;AAC5BzP,qBAAKyP,aAAL,GAAqB7D,KAAK6D,aAA1B;AACA,uBAAO,OAAK6C,gBAAL,CAAsBtS,IAAtB,CAAP;AACH,aAHD,MAIK;AACDA,qBAAKiC,aAAL,GAAqBjC,KAAKiC,aAAL,IAAuB,OAAK7B,QAAL,CAAcmS,2BAAd,IAA6C3G,IAA7C,IAAqDA,KAAK5C,QAAtG;AACA,oBAAI4C,QAAQ,OAAKtL,SAAL,CAAekS,wBAA3B,EAAqD;AACjDzjB,6BAAI6B,KAAJ,CAAU,2DAAV,EAAuEgb,KAAKxC,OAAL,CAAaG,GAApF;AACAvJ,yBAAKyS,WAAL,GAAmB7G,KAAKxC,OAAL,CAAaG,GAAhC;AACH;AACD,uBAAO,OAAKmJ,mBAAL,CAAyB1S,IAAzB,CAAP;AACH;AACJ,SAbM,CAAP;AAcH,K;;0BAEDsS,gB,+BAA4B;AAAA;;AAAA,YAAXtS,IAAW,uEAAJ,EAAI;;AACxB,eAAO,KAAK2I,YAAL,CAAkB6G,oBAAlB,CAAuCxP,IAAvC,EAA6CzC,IAA7C,CAAkD,kBAAU;AAC/D,gBAAI,CAACoM,MAAL,EAAa;AACT5a,yBAAIkF,KAAJ,CAAU,wEAAV;AACA,uBAAOd,QAAQgC,MAAR,CAAe,0CAAf,CAAP;AACH;AACD,gBAAI,CAACwU,OAAOnZ,YAAZ,EAA0B;AACtBzB,yBAAIkF,KAAJ,CAAU,4EAAV;AACA,uBAAOd,QAAQgC,MAAR,CAAe,8CAAf,CAAP;AACH;;AAED,mBAAO,OAAKoc,SAAL,GAAiBhU,IAAjB,CAAsB,gBAAQ;AACjC,oBAAIqO,IAAJ,EAAU;AACN,wBAAI+G,oBAAoBxf,QAAQC,OAAR,EAAxB;AACA,wBAAIuW,OAAOX,QAAX,EAAqB;AACjB2J,4CAAoB,OAAKC,qCAAL,CAA2ChH,KAAKxC,OAAhD,EAAyDO,OAAOX,QAAhE,CAApB;AACH;;AAED,2BAAO2J,kBAAkBpV,IAAlB,CAAuB,YAAM;AAChCxO,iCAAI6B,KAAJ,CAAU,8DAAV;AACAgb,6BAAK5C,QAAL,GAAgBW,OAAOX,QAAvB;AACA4C,6BAAKpb,YAAL,GAAoBmZ,OAAOnZ,YAA3B;AACAob,6BAAK6D,aAAL,GAAqB9F,OAAO8F,aAAP,IAAwB7D,KAAK6D,aAAlD;AACA7D,6BAAKnb,UAAL,GAAkBkZ,OAAOlZ,UAAzB;;AAEA,+BAAO,OAAKghB,SAAL,CAAe7F,IAAf,EAAqBrO,IAArB,CAA0B,YAAI;AACjC,mCAAKwT,OAAL,CAAazgB,IAAb,CAAkBsb,IAAlB;AACA,mCAAOA,IAAP;AACH,yBAHM,CAAP;AAIH,qBAXM,CAAP;AAYH,iBAlBD,MAmBK;AACD,2BAAO,IAAP;AACH;AACJ,aAvBM,CAAP;AAwBH,SAlCM,CAAP;AAmCH,K;;0BAEDgH,qC,kDAAsCxJ,O,EAASJ,Q,EAAU;AAAA;;AACrD,eAAO,KAAKlG,gBAAL,CAAsBpC,SAAtB,GAAkCnD,IAAlC,CAAuC,kBAAU;AACpD,mBAAO,OAAKmL,SAAL,CAAejM,qBAAf,CAAqCuM,QAArC,EAA+CvN,MAA/C,EAAuD,OAAK6E,SAAL,CAAe3O,SAAtE,EAAiF,OAAK2O,SAAL,CAAe3E,SAAhG,EAA2G4B,IAA3G,CAAgH,mBAAW;AAC9H,oBAAI,CAACjC,OAAL,EAAc;AACVvM,6BAAIkF,KAAJ,CAAU,gFAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,oBAAIqE,QAAQiO,GAAR,KAAgBH,QAAQG,GAA5B,EAAiC;AAC7Bxa,6BAAIkF,KAAJ,CAAU,+FAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,4CAAV,CAAf,CAAP;AACH;AACD,oBAAIqE,QAAQuX,SAAR,IAAqBvX,QAAQuX,SAAR,KAAsBzJ,QAAQyJ,SAAvD,EAAkE;AAC9D9jB,6BAAIkF,KAAJ,CAAU,4GAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,yDAAV,CAAf,CAAP;AACH;AACD,oBAAIqE,QAAQ2B,GAAR,IAAe3B,QAAQ2B,GAAR,KAAgBmM,QAAQnM,GAA3C,EAAgD;AAC5ClO,6BAAIkF,KAAJ,CAAU,gGAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,6CAAV,CAAf,CAAP;AACH;AACD,oBAAI,CAACqE,QAAQ2B,GAAT,IAAgBmM,QAAQnM,GAA5B,EAAiC;AAC7BlO,6BAAIkF,KAAJ,CAAU,0GAAV;AACA,2BAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,uDAAV,CAAf,CAAP;AACH;AACJ,aArBM,CAAP;AAsBH,SAvBM,CAAP;AAwBH,K;;0BAEDyb,mB,kCAA+B;AAAA,YAAX1S,IAAW,uEAAJ,EAAI;;AAC3B,YAAIpO,MAAMoO,KAAKvK,YAAL,IAAqB,KAAK2K,QAAL,CAAc0S,mBAAnC,IAA0D,KAAK1S,QAAL,CAAc3K,YAAlF;AACA,YAAI,CAAC7D,GAAL,EAAU;AACN7C,qBAAIkF,KAAJ,CAAU,6DAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,mCAAV,CAAf,CAAP;AACH;;AAED+I,aAAKvK,YAAL,GAAoB7D,GAApB;AACAoO,aAAK8B,MAAL,GAAc9B,KAAK8B,MAAL,IAAe,MAA7B;;AAEA,eAAO,KAAKoQ,OAAL,CAAalS,IAAb,EAAmB,KAAK+S,gBAAxB,EAA0C;AAC7Crd,sBAAU9D,GADmC;AAE7CuH,kCAAsB6G,KAAK7G,oBAAL,IAA6B,KAAKiH,QAAL,CAAcjH;AAFpB,SAA1C,EAGJoE,IAHI,CAGC,gBAAQ;AACZ,gBAAIqO,IAAJ,EAAU;AACN,oBAAIA,KAAKxC,OAAL,IAAgBwC,KAAKxC,OAAL,CAAaG,GAAjC,EAAsC;AAClCxa,6BAAIuQ,IAAJ,CAAS,uDAAT,EAAkEsM,KAAKxC,OAAL,CAAaG,GAA/E;AACH,iBAFD,MAGK;AACDxa,6BAAIuQ,IAAJ,CAAS,kCAAT;AACH;AACJ;;AAED,mBAAOsM,IAAP;AACH,SAdM,CAAP;AAeH,K;;0BAEDoH,oB,iCAAqBphB,G,EAAK;AACtB,eAAO,KAAKygB,eAAL,CAAqBzgB,GAArB,EAA0B,KAAKmhB,gBAA/B,EAAiDxV,IAAjD,CAAsD,gBAAQ;AACjE,gBAAIqO,IAAJ,EAAU;AACN,oBAAIA,KAAKxC,OAAL,IAAgBwC,KAAKxC,OAAL,CAAaG,GAAjC,EAAsC;AAClCxa,6BAAIuQ,IAAJ,CAAS,+DAAT,EAA0EsM,KAAKxC,OAAL,CAAaG,GAAvF;AACH,iBAFD,MAGK;AACDxa,6BAAIuQ,IAAJ,CAAS,0CAAT;AACH;AACJ;;AAED,mBAAOsM,IAAP;AACH,SAXM,CAAP;AAYH,K;;0BAEDqH,c,2BAAerhB,G,EAAK;AAAA;;AAChB,eAAO,KAAK0R,uBAAL,CAA6B1R,GAA7B,EAAkC2L,IAAlC,CAAuC,gBAAuB;AAAA,gBAArBhG,KAAqB,QAArBA,KAAqB;AAAA,gBAAdmM,QAAc,QAAdA,QAAc;;AACjE,gBAAInM,MAAMkL,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAKqP,sBAAL,CAA4BlgB,GAA5B,CAAP;AACH;AACD,gBAAI2F,MAAMkL,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAK2P,mBAAL,CAAyBxgB,GAAzB,CAAP;AACH;AACD,gBAAI2F,MAAMkL,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAKuQ,oBAAL,CAA0BphB,GAA1B,CAAP;AACH;AACD,mBAAOuB,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,gCAAV,CAAf,CAAP;AACH,SAXM,CAAP;AAYH,K;;0BAEDic,e,4BAAgBthB,G,EAAKyV,Q,EAAU;AAAA;;AAC3B,eAAO,KAAK5C,wBAAL,CAA8B7S,GAA9B,EAAmC2L,IAAnC,CAAwC,iBAAuB;AAAA,gBAArBhG,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmM,QAAc,SAAdA,QAAc;;AAClE,gBAAInM,KAAJ,EAAW;AACP,oBAAIA,MAAMkL,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,2BAAO,OAAK0Q,uBAAL,CAA6BvhB,GAA7B,CAAP;AACH;AACD,oBAAI2F,MAAMkL,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,2BAAO,OAAK2Q,oBAAL,CAA0BxhB,GAA1B,EAA+ByV,QAA/B,CAAP;AACH;AACD,uBAAOlU,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,gCAAV,CAAf,CAAP;AACH;AACD,mBAAOyM,QAAP;AACH,SAXM,CAAP;AAYH,K;;0BAEDoI,kB,iCAA8B;AAAA;;AAAA,YAAX9L,IAAW,uEAAJ,EAAI;;AAC1BA,eAAO3F,OAAOuP,MAAP,CAAc,EAAd,EAAkB5J,IAAlB,CAAP;;AAEAA,aAAKyC,YAAL,GAAoB,MAApB,CAH0B,CAGE;AAC5B,YAAI7Q,MAAMoO,KAAKvK,YAAL,IAAqB,KAAK2K,QAAL,CAAc0S,mBAAnC,IAA0D,KAAK1S,QAAL,CAAc3K,YAAlF;AACA,YAAI,CAAC7D,GAAL,EAAU;AACN7C,qBAAIkF,KAAJ,CAAU,mEAAV;AACA,mBAAOd,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,mCAAV,CAAf,CAAP;AACH;;AAED+I,aAAKvK,YAAL,GAAoB7D,GAApB;AACAoO,aAAK8B,MAAL,GAAc,MAAd;AACA9B,aAAK4B,aAAL,GAAqB5B,KAAK4B,aAAL,IAAsB,KAAKxB,QAAL,CAAciT,0BAAzD;AACArT,aAAK6B,KAAL,GAAa7B,KAAK6B,KAAL,IAAc,QAA3B;AACA7B,aAAK0C,YAAL,GAAoB,IAApB;;AAEA,eAAO,KAAKkP,YAAL,CAAkB5R,IAAlB,EAAwB,KAAK+S,gBAA7B,EAA+C;AAClDrd,sBAAU9D,GADwC;AAElDuH,kCAAsB6G,KAAK7G,oBAAL,IAA6B,KAAKiH,QAAL,CAAcjH;AAFf,SAA/C,EAGJoE,IAHI,CAGC,uBAAe;AACnB,mBAAO,OAAK2G,qBAAL,CAA2BoP,YAAY1hB,GAAvC,EAA4C2L,IAA5C,CAAiD,0BAAkB;AACtExO,yBAAI6B,KAAJ,CAAU,qDAAV;;AAEA,oBAAI2iB,eAAenf,aAAf,IAAgCmf,eAAenK,OAAf,CAAuBG,GAA3D,EAAgE;AAC5Dxa,6BAAIuQ,IAAJ,CAAS,sEAAT,EAAkFiU,eAAenK,OAAf,CAAuBG,GAAzG;AACA,2BAAO;AACHnV,uCAAemf,eAAenf,aAD3B;AAEHmV,6BAAKgK,eAAenK,OAAf,CAAuBG,GAFzB;AAGH0C,6BAAKsH,eAAenK,OAAf,CAAuB6C;AAHzB,qBAAP;AAKH,iBAPD,MAQK;AACDld,6BAAIuQ,IAAJ,CAAS,uDAAT;AACH;AACJ,aAdM,EAeN4M,KAfM,CAeA,eAAO;AACV,oBAAIC,IAAI/X,aAAJ,IAAqB,OAAKgM,QAAL,CAAcyL,uBAAvC,EAAgE;AAC5D,wBAAIM,IAAIpV,OAAJ,IAAe,gBAAf,IACAoV,IAAIpV,OAAJ,IAAe,kBADf,IAEAoV,IAAIpV,OAAJ,IAAe,sBAFf,IAGAoV,IAAIpV,OAAJ,IAAe,4BAHnB,EAIE;AACEhI,iCAAIuQ,IAAJ,CAAS,+EAAT;AACA,+BAAO;AACHlL,2CAAe+X,IAAI/X;AADhB,yBAAP;AAGH;AACJ;;AAED,sBAAM+X,GAAN;AACH,aA9BM,CAAP;AA+BH,SAnCM,CAAP;AAoCH,K;;0BAED+F,O,oBAAQlS,I,EAAMwT,S,EAAiC;AAAA;;AAAA,YAAtBC,eAAsB,uEAAJ,EAAI;;AAC3C,eAAO,KAAK7B,YAAL,CAAkB5R,IAAlB,EAAwBwT,SAAxB,EAAmCC,eAAnC,EAAoDlW,IAApD,CAAyD,uBAAe;AAC3E,mBAAO,QAAKwU,UAAL,CAAgBuB,YAAY1hB,GAA5B,EAAiCoO,IAAjC,CAAP;AACH,SAFM,CAAP;AAGH,K;;0BACD4R,Y,yBAAa5R,I,EAAMwT,S,EAAiC;AAAA;;AAAA,YAAtBC,eAAsB,uEAAJ,EAAI;;;AAEhD,eAAOD,UAAU7e,OAAV,CAAkB8e,eAAlB,EAAmClW,IAAnC,CAAwC,kBAAU;AACrDxO,qBAAI6B,KAAJ,CAAU,uDAAV;;AAEA,mBAAO,QAAK+Q,mBAAL,CAAyB3B,IAAzB,EAA+BzC,IAA/B,CAAoC,yBAAiB;AACxDxO,yBAAI6B,KAAJ,CAAU,8CAAV;;AAEA6iB,gCAAgB7hB,GAAhB,GAAsBmR,cAAcnR,GAApC;AACA6hB,gCAAgBrQ,EAAhB,GAAqBL,cAAcxL,KAAd,CAAoB6L,EAAzC;;AAEA,uBAAOjL,OAAOnC,QAAP,CAAgByd,eAAhB,CAAP;AACH,aAPM,EAOJvH,KAPI,CAOE,eAAO;AACZ,oBAAI/T,OAAOjB,KAAX,EAAkB;AACdnI,6BAAI6B,KAAJ,CAAU,qFAAV;AACAuH,2BAAOjB,KAAP;AACH;AACD,sBAAMiV,GAAN;AACH,aAbM,CAAP;AAcH,SAjBM,CAAP;AAkBH,K;;0BACD4F,U,uBAAWngB,G,EAAgB;AAAA;;AAAA,YAAXoO,IAAW,uEAAJ,EAAI;;AACvB,eAAO,KAAKkE,qBAAL,CAA2BtS,GAA3B,EAAgC2L,IAAhC,CAAqC,0BAAkB;AAC1DxO,qBAAI6B,KAAJ,CAAU,6CAAV;;AAEA,gBAAIgb,OAAO,IAAI/b,UAAJ,CAAS0jB,cAAT,CAAX;;AAEA,gBAAIvT,KAAKyS,WAAT,EAAsB;AAClB,oBAAIzS,KAAKyS,WAAL,KAAqB7G,KAAKxC,OAAL,CAAaG,GAAtC,EAA2C;AACvCxa,6BAAI6B,KAAJ,CAAU,kGAAV,EAA8Ggb,KAAKxC,OAAL,CAAaG,GAA3H;AACA,2BAAOpW,QAAQgC,MAAR,CAAe,IAAI8B,KAAJ,CAAU,gBAAV,CAAf,CAAP;AACH,iBAHD,MAIK;AACDlI,6BAAI6B,KAAJ,CAAU,wEAAV;AACH;AACJ;;AAED,mBAAO,QAAK6gB,SAAL,CAAe7F,IAAf,EAAqBrO,IAArB,CAA0B,YAAM;AACnCxO,yBAAI6B,KAAJ,CAAU,qCAAV;;AAEA,wBAAKmgB,OAAL,CAAazgB,IAAb,CAAkBsb,IAAlB;;AAEA,uBAAOA,IAAP;AACH,aANM,CAAP;AAOH,SAtBM,CAAP;AAuBH,K;;0BACDyG,e,4BAAgBzgB,G,EAAK4hB,S,EAAW;AAC5BzkB,iBAAI6B,KAAJ,CAAU,6BAAV;AACA,eAAO4iB,UAAU9hB,QAAV,CAAmBE,GAAnB,CAAP;AACH,K;;0BAED8hB,e,8BAA2B;AAAA,YAAX1T,IAAW,uEAAJ,EAAI;;AACvBA,eAAO3F,OAAOuP,MAAP,CAAc,EAAd,EAAkB5J,IAAlB,CAAP;;AAEAA,aAAKyC,YAAL,GAAoB,MAApB;AACA,YAAIkR,wBAAwB3T,KAAKsE,wBAAL,IAAiC,KAAKlE,QAAL,CAAckE,wBAA3E;AACA,YAAIqP,qBAAJ,EAA0B;AACtB3T,iBAAKsE,wBAAL,GAAgCqP,qBAAhC;AACH;AACD,YAAIhC,YAAY;AACZ1J,kCAAuBjI,KAAKiI;AADhB,SAAhB;AAGA,eAAO,KAAK2L,aAAL,CAAmB5T,IAAnB,EAAyB,KAAK6R,kBAA9B,EAAkDF,SAAlD,EAA6DpU,IAA7D,CAAkE,YAAI;AACzExO,qBAAIuQ,IAAJ,CAAS,yCAAT;AACH,SAFM,CAAP;AAGH,K;;0BACD6T,uB,oCAAwBvhB,G,EAAK;AACzB,eAAO,KAAKiiB,WAAL,CAAiBjiB,OAAO,KAAKigB,kBAAL,CAAwBjgB,GAAhD,EAAqD2L,IAArD,CAA0D,oBAAU;AACvExO,qBAAIuQ,IAAJ,CAAS,iDAAT;AACA,mBAAOoE,QAAP;AACH,SAHM,CAAP;AAIH,K;;0BAEDoQ,Y,2BAAwB;AAAA,YAAX9T,IAAW,uEAAJ,EAAI;;AACpBA,eAAO3F,OAAOuP,MAAP,CAAc,EAAd,EAAkB5J,IAAlB,CAAP;;AAEAA,aAAKyC,YAAL,GAAoB,MAApB;AACA,YAAI7Q,MAAMoO,KAAKsE,wBAAL,IAAiC,KAAKlE,QAAL,CAAc2T,8BAA/C,IAAiF,KAAK3T,QAAL,CAAckE,wBAAzG;AACAtE,aAAKsE,wBAAL,GAAgC1S,GAAhC;AACAoO,aAAKjN,OAAL,GAAe,OAAf;AACA,YAAIiN,KAAKsE,wBAAT,EAAkC;AAC9B;AACA;AACA;AACA;AACA;AACAtE,iBAAKzI,KAAL,GAAayI,KAAKzI,KAAL,IAAc,EAA3B;AACH;;AAED,eAAO,KAAKyc,QAAL,CAAchU,IAAd,EAAoB,KAAKmS,eAAzB,EAA0C;AAC7Czc,sBAAU9D,GADmC;AAE7CiD,iCAAqBmL,KAAKnL,mBAAL,IAA4B,KAAKuL,QAAL,CAAcvL,mBAFlB;AAG7CW,+BAAmBwK,KAAKxK,iBAAL,IAA0B,KAAK4K,QAAL,CAAc5K;AAHd,SAA1C,EAIJ+H,IAJI,CAIC,YAAM;AACVxO,qBAAIuQ,IAAJ,CAAS,sCAAT;AACH,SANM,CAAP;AAOH,K;;0BACD8T,oB,iCAAqBxhB,G,EAAKyV,Q,EAAU;AAChC,YAAI,OAAOA,QAAP,KAAqB,WAArB,IAAoC,OAAOzV,GAAP,KAAgB,SAAxD,EAAmE;AAC/DyV,uBAAWzV,GAAX;AACAA,kBAAM,IAAN;AACH;;AAED,YAAI6R,YAAY,GAAhB;AACA,eAAO,KAAK0O,eAAL,CAAqBzgB,QAArB,CAA8BE,GAA9B,EAAmCyV,QAAnC,EAA6C5D,SAA7C,EAAwDlG,IAAxD,CAA6D,YAAM;AACtExO,qBAAIuQ,IAAJ,CAAS,8CAAT;AACH,SAFM,CAAP;AAGH,K;;0BAED0U,Q,qBAAShU,I,EAAMwT,S,EAAiC;AAAA;;AAAA,YAAtBC,eAAsB,uEAAJ,EAAI;;AAC5C,eAAO,KAAKG,aAAL,CAAmB5T,IAAnB,EAAyBwT,SAAzB,EAAoCC,eAApC,EAAqDlW,IAArD,CAA0D,uBAAe;AAC5E,mBAAO,QAAKsW,WAAL,CAAiBP,YAAY1hB,GAA7B,CAAP;AACH,SAFM,CAAP;AAGH,K;;0BACDgiB,a,4BAA0D;AAAA,YAA5C5T,IAA4C,uEAArC,EAAqC;;AAAA;;AAAA,YAAjCwT,SAAiC;AAAA,YAAtBC,eAAsB,uEAAJ,EAAI;;AACtD,eAAOD,UAAU7e,OAAV,CAAkB8e,eAAlB,EAAmClW,IAAnC,CAAwC,kBAAU;AACrDxO,qBAAI6B,KAAJ,CAAU,wDAAV;;AAEA,mBAAO,QAAK2gB,SAAL,GAAiBhU,IAAjB,CAAsB,gBAAQ;AACjCxO,yBAAI6B,KAAJ,CAAU,6DAAV;;AAEA,oBAAIqjB,gBAAgB,QAAK3T,SAAL,CAAe4T,0BAAf,GAA4C,QAAKC,eAAL,CAAqBvI,IAArB,CAA5C,GAAyEzY,QAAQC,OAAR,EAA7F;AACA,uBAAO6gB,cAAc1W,IAAd,CAAmB,YAAM;;AAE5B,wBAAIyL,WAAWhJ,KAAKiC,aAAL,IAAsB2J,QAAQA,KAAK5C,QAAlD;AACA,wBAAIA,QAAJ,EAAc;AACVja,iCAAI6B,KAAJ,CAAU,kEAAV;AACAoP,6BAAKiC,aAAL,GAAqB+G,QAArB;AACH;;AAED,2BAAO,QAAKwI,UAAL,GAAkBjU,IAAlB,CAAuB,YAAM;AAChCxO,iCAAI6B,KAAJ,CAAU,mEAAV;;AAEA,+BAAO,QAAKyT,oBAAL,CAA0BrE,IAA1B,EAAgCzC,IAAhC,CAAqC,0BAAkB;AAC1DxO,qCAAI6B,KAAJ,CAAU,gDAAV;;AAEA6iB,4CAAgB7hB,GAAhB,GAAsBwiB,eAAexiB,GAArC;AACA,gCAAIwiB,eAAe7c,KAAnB,EAA0B;AACtBkc,gDAAgBrQ,EAAhB,GAAqBgR,eAAe7c,KAAf,CAAqB6L,EAA1C;AACH;AACD,mCAAOjL,OAAOnC,QAAP,CAAgByd,eAAhB,CAAP;AACH,yBARM,CAAP;AASH,qBAZM,CAAP;AAaH,iBArBM,CAAP;AAsBH,aA1BM,EA0BJvH,KA1BI,CA0BE,eAAO;AACZ,oBAAI/T,OAAOjB,KAAX,EAAkB;AACdnI,6BAAI6B,KAAJ,CAAU,sFAAV;AACAuH,2BAAOjB,KAAP;AACH;AACD,sBAAMiV,GAAN;AACH,aAhCM,CAAP;AAiCH,SApCM,CAAP;AAqCH,K;;0BACD0H,W,wBAAYjiB,G,EAAK;AACb,eAAO,KAAKiT,sBAAL,CAA4BjT,GAA5B,EAAiC2L,IAAjC,CAAsC,2BAAmB;AAC5DxO,qBAAI6B,KAAJ,CAAU,+CAAV;;AAEA,mBAAOyjB,eAAP;AACH,SAJM,CAAP;AAKH,K;;0BAEDC,iB,gCAAoB;AAAA;;AAChB,eAAO,KAAK/C,SAAL,GAAiBhU,IAAjB,CAAsB,gBAAQ;AACjC,mBAAO,QAAK4W,eAAL,CAAqBvI,IAArB,EAA2B,IAA3B,EAAiCrO,IAAjC,CAAsC,mBAAW;AACpD,oBAAIgX,OAAJ,EAAa;AACTxlB,6BAAI6B,KAAJ,CAAU,mFAAV;;AAEAgb,yBAAKpb,YAAL,GAAoB,IAApB;AACAob,yBAAK6D,aAAL,GAAqB,IAArB;AACA7D,yBAAK4B,UAAL,GAAkB,IAAlB;AACA5B,yBAAK2B,UAAL,GAAkB,IAAlB;;AAEA,2BAAO,QAAKkE,SAAL,CAAe7F,IAAf,EAAqBrO,IAArB,CAA0B,YAAM;AACnCxO,iCAAI6B,KAAJ,CAAU,4CAAV;AACA,gCAAKmgB,OAAL,CAAazgB,IAAb,CAAkBsb,IAAlB;AACH,qBAHM,CAAP;AAIH;AACJ,aAdM,CAAP;AAeH,SAhBM,EAgBJrO,IAhBI,CAgBC,YAAI;AACRxO,qBAAIuQ,IAAJ,CAAS,kEAAT;AACH,SAlBM,CAAP;AAmBH,K;;0BAED6U,e,4BAAgBvI,I,EAAMkE,Q,EAAU;AAAA;;AAC5B,YAAIlE,IAAJ,EAAU;AACN,gBAAIpb,eAAeob,KAAKpb,YAAxB;AACA,gBAAIif,gBAAgB7D,KAAK6D,aAAzB;;AAEA,mBAAO,KAAK+E,0BAAL,CAAgChkB,YAAhC,EAA8Csf,QAA9C,EACFvS,IADE,CACG,qBAAa;AACf,uBAAO,QAAKkX,2BAAL,CAAiChF,aAAjC,EAAgDK,QAAhD,EACFvS,IADE,CACG,qBAAa;AACf,wBAAI,CAACmX,SAAD,IAAc,CAACC,SAAnB,EAA8B;AAC1B5lB,iCAAI6B,KAAJ,CAAU,oFAAV;AACH;;AAED,2BAAO8jB,aAAaC,SAApB;AACH,iBAPE,CAAP;AAQH,aAVE,CAAP;AAWH;;AAED,eAAOxhB,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH,K;;0BAEDohB,0B,uCAA2BhkB,Y,EAAcsf,Q,EAAU;AAC/C;AACA,YAAI,CAACtf,YAAD,IAAiBA,aAAa6B,OAAb,CAAqB,GAArB,KAA6B,CAAlD,EAAqD;AACjD,mBAAOc,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH;;AAED,eAAO,KAAKke,sBAAL,CAA4BzB,MAA5B,CAAmCrf,YAAnC,EAAiDsf,QAAjD,EAA2DvS,IAA3D,CAAgE;AAAA,mBAAM,IAAN;AAAA,SAAhE,CAAP;AACH,K;;0BAEDkX,2B,wCAA4BhF,a,EAAeK,Q,EAAU;AACjD,YAAI,CAACL,aAAL,EAAoB;AAChB,mBAAOtc,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH;;AAED,eAAO,KAAKke,sBAAL,CAA4BzB,MAA5B,CAAmCJ,aAAnC,EAAkDK,QAAlD,EAA4D,eAA5D,EAA6EvS,IAA7E,CAAkF;AAAA,mBAAM,IAAN;AAAA,SAAlF,CAAP;AACH,K;;0BAED4T,gB,+BAAmB;AACf,aAAKF,mBAAL,CAAyB9c,KAAzB;AACH,K;;0BAEDygB,e,8BAAkB;AACd,aAAK3D,mBAAL,CAAyB/c,IAAzB;AACH,K;;0BAMDqd,S,wBAAY;AACR,eAAO,KAAKsD,UAAL,CAAgB/Q,GAAhB,CAAoB,KAAKgR,aAAzB,EAAwCvX,IAAxC,CAA6C,yBAAiB;AACjE,gBAAI0Q,aAAJ,EAAmB;AACflf,yBAAI6B,KAAJ,CAAU,kDAAV;AACA,uBAAOf,WAAKoU,iBAAL,CAAuBgK,aAAvB,CAAP;AACH;;AAEDlf,qBAAI6B,KAAJ,CAAU,8CAAV;AACA,mBAAO,IAAP;AACH,SARM,CAAP;AASH,K;;0BAED6gB,S,sBAAU7F,I,EAAM;AACZ,YAAIA,IAAJ,EAAU;AACN7c,qBAAI6B,KAAJ,CAAU,qCAAV;;AAEA,gBAAIqd,gBAAgBrC,KAAKvI,eAAL,EAApB;AACA,mBAAO,KAAKwR,UAAL,CAAgB1R,GAAhB,CAAoB,KAAK2R,aAAzB,EAAwC7G,aAAxC,CAAP;AACH,SALD,MAMK;AACDlf,qBAAI6B,KAAJ,CAAU,oCAAV;AACA,mBAAO,KAAKikB,UAAL,CAAgBhR,MAAhB,CAAuB,KAAKiR,aAA5B,CAAP;AACH;AACJ,K;;;;4BAxkBwB;AACrB,mBAAO,KAAK1U,QAAL,CAAc2U,iBAArB;AACH;;;4BACqB;AAClB,mBAAO,KAAK3U,QAAL,CAAc4U,cAArB;AACH;;;4BACsB;AACnB,mBAAO,KAAK5U,QAAL,CAAc6U,eAArB;AACH;;;4BACgB;AACb,mBAAO,KAAK7U,QAAL,CAAc8U,SAArB;AACH;;;4BAEY;AACT,mBAAO,KAAKnE,OAAZ;AACH;;;4BA8hBmB;AAChB,6BAAe,KAAK3Q,QAAL,CAAcsB,SAA7B,SAA0C,KAAKtB,QAAL,CAAczO,SAAxD;AACH;;;;EAhlB4B3C,uB;;;;;;;;;;;;;;;;;;;ACZjC;;AACA;;AACA;;;;;;+eALA;AACA;;IAMagiB,iB,WAAAA,iB;;;AAET,+BAAY5Q,QAAZ,EAAsB;AAAA;;AAAA,qDAClB,8BAAMA,QAAN,CADkB;;AAElB,cAAK+U,WAAL,GAAmB,IAAI3d,YAAJ,CAAU,aAAV,CAAnB;AACA,cAAK4d,aAAL,GAAqB,IAAI5d,YAAJ,CAAU,eAAV,CAArB;AACA,cAAK6d,iBAAL,GAAyB,IAAI7d,YAAJ,CAAU,oBAAV,CAAzB;AACA,cAAK8d,aAAL,GAAqB,IAAI9d,YAAJ,CAAU,gBAAV,CAArB;AACA,cAAK+d,cAAL,GAAsB,IAAI/d,YAAJ,CAAU,iBAAV,CAAtB;AACA,cAAKge,mBAAL,GAA2B,IAAIhe,YAAJ,CAAU,sBAAV,CAA3B;AAPkB;AAQrB;;gCAEDlH,I,iBAAKsb,I,EAAuB;AAAA,YAAjBc,UAAiB,uEAAN,IAAM;;AACxB3d,iBAAI6B,KAAJ,CAAU,wBAAV;AACA,qCAAMN,IAAN,YAAWsb,IAAX;AACA,YAAIc,UAAJ,EAAgB;AACZ,iBAAKyI,WAAL,CAAiBpd,KAAjB,CAAuB6T,IAAvB;AACH;AACJ,K;;gCACD3a,M,qBAAS;AACLlC,iBAAI6B,KAAJ,CAAU,0BAAV;AACA,qCAAMK,MAAN;AACA,aAAKmkB,aAAL,CAAmBrd,KAAnB;AACH,K;;gCAEDwT,a,0BAAcpa,E,EAAI;AACd,aAAKgkB,WAAL,CAAiB/jB,UAAjB,CAA4BD,EAA5B;AACH,K;;gCACDskB,gB,6BAAiBtkB,E,EAAI;AACjB,aAAKgkB,WAAL,CAAiB7jB,aAAjB,CAA+BH,EAA/B;AACH,K;;gCAEDsa,e,4BAAgBta,E,EAAI;AAChB,aAAKikB,aAAL,CAAmBhkB,UAAnB,CAA8BD,EAA9B;AACH,K;;gCACDukB,kB,+BAAmBvkB,E,EAAI;AACnB,aAAKikB,aAAL,CAAmB9jB,aAAnB,CAAiCH,EAAjC;AACH,K;;gCAEDwkB,mB,gCAAoBxkB,E,EAAI;AACpB,aAAKkkB,iBAAL,CAAuBjkB,UAAvB,CAAkCD,EAAlC;AACH,K;;gCACDykB,sB,mCAAuBzkB,E,EAAI;AACvB,aAAKkkB,iBAAL,CAAuB/jB,aAAvB,CAAqCH,EAArC;AACH,K;;gCACDkd,sB,mCAAuBza,C,EAAG;AACtB7E,iBAAI6B,KAAJ,CAAU,0CAAV,EAAsDgD,EAAEmD,OAAxD;AACA,aAAKse,iBAAL,CAAuBtd,KAAvB,CAA6BnE,CAA7B;AACH,K;;gCAEDiiB,e,4BAAgB1kB,E,EAAI;AAChB,aAAKmkB,aAAL,CAAmBlkB,UAAnB,CAA8BD,EAA9B;AACH,K;;gCACD2kB,kB,+BAAmB3kB,E,EAAI;AACnB,aAAKmkB,aAAL,CAAmBhkB,aAAnB,CAAiCH,EAAjC;AACH,K;;gCACD0b,kB,iCAAqB;AACjB9d,iBAAI6B,KAAJ,CAAU,sCAAV;AACA,aAAK0kB,aAAL,CAAmBvd,KAAnB;AACH,K;;gCAEDge,gB,6BAAiB5kB,E,EAAI;AACjB,aAAKokB,cAAL,CAAoBnkB,UAApB,CAA+BD,EAA/B;AACH,K;;gCACD6kB,mB,gCAAoB7kB,E,EAAI;AACpB,aAAKokB,cAAL,CAAoBjkB,aAApB,CAAkCH,EAAlC;AACH,K;;gCACDyb,mB,kCAAsB;AAClB7d,iBAAI6B,KAAJ,CAAU,uCAAV;AACA,aAAK2kB,cAAL,CAAoBxd,KAApB;AACH,K;;gCAEDke,qB,kCAAsB9kB,E,EAAI;AACtB,aAAKqkB,mBAAL,CAAyBpkB,UAAzB,CAAoCD,EAApC;AACH,K;;gCACD+kB,wB,qCAAyB/kB,E,EAAI;AACzB,aAAKqkB,mBAAL,CAAyBlkB,aAAzB,CAAuCH,EAAvC;AACH,K;;gCACDwb,wB,uCAA2B;AACvB5d,iBAAI6B,KAAJ,CAAU,4CAAV;AACA,aAAK4kB,mBAAL,CAAyBzd,KAAzB;AACH,K;;;EAjFkC1I,qC;;;;;;;;;;;;;;;;;;;;;ACJvC;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;;;+eAVA;AACA;;AAWA,IAAMS,6CAA6C,EAAnD;AACA,IAAMqmB,8BAA8B,IAApC;;IAEarF,mB,WAAAA,mB;;;AACT,mCAqBQ;AAAA,uFAAJ,EAAI;AAAA,YApBJmB,kBAoBI,QApBJA,kBAoBI;AAAA,YAnBJ8B,8BAmBI,QAnBJA,8BAmBI;AAAA,YAlBJlf,mBAkBI,QAlBJA,mBAkBI;AAAA,YAjBJW,iBAiBI,QAjBJA,iBAiBI;AAAA,YAhBJsd,mBAgBI,QAhBJA,mBAgBI;AAAA,YAfJ3Z,oBAeI,QAfJA,oBAeI;AAAA,yCAdJ+X,oBAcI;AAAA,YAdJA,oBAcI,yCAdmB,KAcnB;AAAA,yCAbJsB,wBAaI;AAAA,YAbJA,wBAaI,yCAbuB,KAavB;AAAA,yCAZJD,2BAYI;AAAA,YAZJA,2BAYI,yCAZ0B,IAY1B;AAAA,uCAXJnB,cAWI;AAAA,YAXJA,cAWI,uCAXa,IAWb;AAAA,yCAVJvF,uBAUI;AAAA,YAVJA,uBAUI,yCAVsB,KAUtB;AAAA,yCATJiB,oBASI;AAAA,YATJA,oBASI,yCATmBqJ,2BASnB;AAAA,yCARJpJ,uBAQI;AAAA,YARJA,uBAQI,yCARsB,IAQtB;AAAA,YAPJsG,0BAOI,QAPJA,0BAOI;AAAA,yCANJa,0BAMI;AAAA,YANJA,0BAMI,yCANyB,KAMzB;AAAA,yCALJnkB,mCAKI;AAAA,YALJA,mCAKI,yCALkCD,0CAKlC;AAAA,yCAJJilB,iBAII;AAAA,YAJJA,iBAII,yCAJgB,IAAI/M,oCAAJ,EAIhB;AAAA,uCAHJgN,cAGI;AAAA,YAHJA,cAGI,uCAHa,IAAI7N,8BAAJ,EAGb;AAAA,wCAFJ8N,eAEI;AAAA,YAFJA,eAEI,wCAFc,IAAIpc,gCAAJ,EAEd;AAAA,kCADJqc,SACI;AAAA,YADJA,SACI,kCADQ,IAAIhmB,0CAAJ,CAAyB,EAAEknB,OAAOxmB,eAAO+I,cAAhB,EAAzB,CACR;;AAAA;;AAAA,qDACJ,+BAAM+U,UAAU,CAAV,CAAN,CADI;;AAGJ,cAAK2I,mBAAL,GAA2BpE,kBAA3B;AACA,cAAKqE,+BAAL,GAAuCvC,8BAAvC;AACA,cAAKwC,oBAAL,GAA4B1hB,mBAA5B;AACA,cAAK2hB,kBAAL,GAA0BhhB,iBAA1B;;AAEA,cAAKihB,oBAAL,GAA4B3D,mBAA5B;AACA,cAAK4D,qBAAL,GAA6Bvd,oBAA7B;AACA,cAAKwd,qBAAL,GAA6BzF,oBAA7B;AACA,cAAK0F,yBAAL,GAAiCpE,wBAAjC;AACA,cAAKqE,4BAAL,GAAoCtE,2BAApC;AACA,cAAKpiB,oCAAL,GAA4CJ,mCAA5C;;AAEA,cAAK+mB,eAAL,GAAuB1F,cAAvB;AACA,cAAK2F,wBAAL,GAAgClL,uBAAhC;AACA,cAAKU,qBAAL,GAA6BO,oBAA7B;AACA,cAAKN,wBAAL,GAAgCO,uBAAhC;AACA,YAAIsG,0BAAJ,EAAgC;AAC5B,kBAAK2D,2BAAL,GAAmC3D,0BAAnC;AACH,SAFD,MAGK,IAAI3F,UAAU,CAAV,KAAgBA,UAAU,CAAV,EAAa9L,aAAjC,EAAgD;AACjD,kBAAKoV,2BAAL,GAAmCpU,6BAAcqK,MAAd,CAAqBS,UAAU,CAAV,EAAa9L,aAAlC,IAAmD,UAAnD,GAAgE,MAAnG;AACH,SAFI,MAGA;AACD,kBAAKoV,2BAAL,GAAmC,UAAnC;AACH;AACD,cAAKC,2BAAL,GAAmC/C,0BAAnC;;AAEA,cAAKrC,kBAAL,GAA0BkD,iBAA1B;AACA,cAAK5C,eAAL,GAAuB6C,cAAvB;AACA,cAAKjC,gBAAL,GAAwBkC,eAAxB;;AAEA,cAAKJ,UAAL,GAAkBK,SAAlB;AAlCI;AAmCP;;;;4BAEwB;AACrB,mBAAO,KAAKmB,mBAAZ;AACH;;;4BACoC;AACjC,mBAAO,KAAKC,+BAAZ;AACH;;;4BACyB;AACtB,mBAAO,KAAKC,oBAAZ;AACH;;;4BACuB;AACpB,mBAAO,KAAKC,kBAAZ;AACH;;;4BAEyB;AACtB,mBAAO,KAAKC,oBAAZ;AACH;;;4BAC2B;AACxB,mBAAO,KAAKC,qBAAZ;AACH;;;4BAC0B;AACvB,mBAAO,KAAKC,qBAAZ;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKC,yBAAZ;AACH;;;4BACiC;AAC9B,mBAAO,KAAKC,4BAAZ;AACH;;;4BACyC;AACtC,mBAAO,KAAK1mB,oCAAZ;AACH;;;4BAEoB;AACjB,mBAAO,KAAK2mB,eAAZ;AACH;;;4BAC6B;AAC1B,mBAAO,KAAKC,wBAAZ;AACH;;;4BAC0B;AACvB,mBAAO,KAAKxK,qBAAZ;AACH;;;4BAC4B;AACzB,mBAAO,KAAKC,wBAAZ;AACH;;;4BAC+B;AAC5B,mBAAO,KAAKwK,2BAAZ;AACH;;;4BACgC;AAC7B,mBAAO,KAAKC,2BAAZ;AACH;;;4BAEuB;AACpB,mBAAO,KAAKpF,kBAAZ;AACH;;;4BACoB;AACjB,mBAAO,KAAKM,eAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKY,gBAAZ;AACH;;;4BAEe;AACZ,mBAAO,KAAK8B,UAAZ;AACH;;;;EA1HoC5lB,uC;;;;;;;;;;;;;;;;;;;ACZzC;;AACA;;0JAJA;AACA;;IAKaC,oB,WAAAA,oB;AACT,oCAAkE;AAAA,uFAAJ,EAAI;AAAA,+BAArDgoB,MAAqD;AAAA,YAArDA,MAAqD,+BAA5C,OAA4C;AAAA,8BAAnCd,KAAmC;AAAA,YAAnCA,KAAmC,8BAA3BxmB,eAAO8I,YAAoB;;AAAA;;AAC9D,aAAKye,MAAL,GAAcf,KAAd;AACA,aAAKgB,OAAL,GAAeF,MAAf;AACH;;mCAED/T,G,gBAAInJ,G,EAAKE,K,EAAO;AACZnL,iBAAI6B,KAAJ,CAAU,0BAAV,EAAsCoJ,GAAtC;;AAEAA,cAAM,KAAKod,OAAL,GAAepd,GAArB;;AAEA,aAAKmd,MAAL,CAAYld,OAAZ,CAAoBD,GAApB,EAAyBE,KAAzB;;AAEA,eAAO/G,QAAQC,OAAR,EAAP;AACH,K;;mCAED0Q,G,gBAAI9J,G,EAAK;AACLjL,iBAAI6B,KAAJ,CAAU,0BAAV,EAAsCoJ,GAAtC;;AAEAA,cAAM,KAAKod,OAAL,GAAepd,GAArB;;AAEA,YAAInC,OAAO,KAAKsf,MAAL,CAAYpd,OAAZ,CAAoBC,GAApB,CAAX;;AAEA,eAAO7G,QAAQC,OAAR,CAAgByE,IAAhB,CAAP;AACH,K;;mCAEDgM,M,mBAAO7J,G,EAAK;AACRjL,iBAAI6B,KAAJ,CAAU,6BAAV,EAAyCoJ,GAAzC;;AAEAA,cAAM,KAAKod,OAAL,GAAepd,GAArB;;AAEA,YAAInC,OAAO,KAAKsf,MAAL,CAAYpd,OAAZ,CAAoBC,GAApB,CAAX;AACA,aAAKmd,MAAL,CAAYhd,UAAZ,CAAuBH,GAAvB;;AAEA,eAAO7G,QAAQC,OAAR,CAAgByE,IAAhB,CAAP;AACH,K;;mCAED8W,U,yBAAa;AACT5f,iBAAI6B,KAAJ,CAAU,iCAAV;;AAEA,YAAI4Q,OAAO,EAAX;;AAEA,aAAK,IAAIpH,QAAQ,CAAjB,EAAoBA,QAAQ,KAAK+c,MAAL,CAAYlf,MAAxC,EAAgDmC,OAAhD,EAAyD;AACrD,gBAAIJ,MAAM,KAAKmd,MAAL,CAAYnd,GAAZ,CAAgBI,KAAhB,CAAV;;AAEA,gBAAIJ,IAAI3H,OAAJ,CAAY,KAAK+kB,OAAjB,MAA8B,CAAlC,EAAqC;AACjC5V,qBAAK7J,IAAL,CAAUqC,IAAIzH,MAAJ,CAAW,KAAK6kB,OAAL,CAAanf,MAAxB,CAAV;AACH;AACJ;;AAED,eAAO9E,QAAQC,OAAR,CAAgBoO,IAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACrCL;;;;AACA;;;;AACA;;;;;;AAEA,IAAI6V,aAAaC,eAAKD,UAAtB;;AAEA;;AA1BA;;;;;;;;;AASA;;;;;;;;;;;AAmBA,IAAIE,SAAS,kEAAb;AACA,IAAIC,SAAS,GAAb;;AAEA,IAAMC,SAAS;AACX5c,YADW,oBACF6c,CADE,EACC;AACR,YAAIC,MAAM,EAAV;AACA,YAAI3f,CAAJ;AACA,YAAI4f,IAAI,CAAR,CAHQ,CAGG;AACX,YAAIC,IAAJ;AACA,aAAI7f,IAAI,CAAR,EAAWA,IAAI0f,EAAEzf,MAAjB,EAAyB,EAAED,CAA3B,EAA8B;AAC1B,gBAAG0f,EAAEI,MAAF,CAAS9f,CAAT,MAAgBwf,MAAnB,EAA2B;AAC3B,gBAAIO,IAAIR,OAAOllB,OAAP,CAAeqlB,EAAEI,MAAF,CAAS9f,CAAT,CAAf,CAAR;AACA,gBAAG+f,IAAI,CAAP,EAAU;AACV,gBAAGH,MAAM,CAAT,EAAY;AACRD,uBAAOK,OAAOC,YAAP,CAAoBF,KAAK,CAAzB,CAAP;AACAF,uBAAOE,IAAI,CAAX;AACAH,oBAAI,CAAJ;AACH,aAJD,MAKK,IAAGA,MAAM,CAAT,EAAY;AACbD,uBAAOK,OAAOC,YAAP,CAAqBJ,QAAQ,CAAT,GAAeE,KAAK,CAAxC,CAAP;AACAF,uBAAOE,IAAI,GAAX;AACAH,oBAAI,CAAJ;AACH,aAJI,MAKA,IAAGA,MAAM,CAAT,EAAY;AACbD,uBAAOK,OAAOC,YAAP,CAAoBJ,IAApB,CAAP;AACAF,uBAAOK,OAAOC,YAAP,CAAoBF,KAAK,CAAzB,CAAP;AACAF,uBAAOE,IAAI,CAAX;AACAH,oBAAI,CAAJ;AACH,aALI,MAMA;AACDD,uBAAOK,OAAOC,YAAP,CAAqBJ,QAAQ,CAAT,GAAeE,KAAK,CAAxC,CAAP;AACAJ,uBAAOK,OAAOC,YAAP,CAAoBF,IAAI,GAAxB,CAAP;AACAH,oBAAI,CAAJ;AACH;AACJ;AACD,YAAGA,MAAM,CAAT,EACID,OAAOK,OAAOC,YAAP,CAAoBJ,QAAQ,CAA5B,CAAP;AACJ,eAAOF,GAAP;AACH,KAnCU;AAoCXO,eApCW,uBAoCCC,CApCD,EAoCI;AACX,YAAIngB,CAAJ;AACA,YAAIogB,CAAJ;AACA,YAAIT,MAAM,EAAV;AACA,aAAI3f,IAAI,CAAR,EAAWA,IAAE,CAAF,IAAOmgB,EAAElgB,MAApB,EAA4BD,KAAG,CAA/B,EAAkC;AAC9BogB,gBAAI1b,SAASyb,EAAEE,SAAF,CAAYrgB,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAJ;AACA2f,mBAAOJ,OAAOO,MAAP,CAAcM,KAAK,CAAnB,IAAwBb,OAAOO,MAAP,CAAcM,IAAI,EAAlB,CAA/B;AACH;AACD,YAAGpgB,IAAE,CAAF,KAAQmgB,EAAElgB,MAAb,EAAqB;AACjBmgB,gBAAI1b,SAASyb,EAAEE,SAAF,CAAYrgB,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAJ;AACA2f,mBAAOJ,OAAOO,MAAP,CAAcM,KAAK,CAAnB,CAAP;AACH,SAHD,MAIK,IAAGpgB,IAAE,CAAF,KAAQmgB,EAAElgB,MAAb,EAAqB;AACtBmgB,gBAAI1b,SAASyb,EAAEE,SAAF,CAAYrgB,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAJ;AACA2f,mBAAOJ,OAAOO,MAAP,CAAcM,KAAK,CAAnB,IAAwBb,OAAOO,MAAP,CAAc,CAACM,IAAI,CAAL,KAAW,CAAzB,CAA/B;AACH;AACD,YAAIZ,MAAJ,EAAY,OAAM,CAACG,IAAI1f,MAAJ,GAAa,CAAd,IAAmB,CAAzB;AAA4B0f,mBAAOH,MAAP;AAA5B,SACZ,OAAOG,GAAP;AACH,KAtDU;AAwDXW,WAxDW,mBAwDHC,GAxDG,EAwDE;AACT,YAAIC,MAAOD,IAAItgB,MAAJ,GAAa,CAAxB;AACA,YAAIwgB,MAAM,IAAID,GAAd;;AAEA,YAAIA,QAAQ,CAAZ,EAAe;AACX,mBAAOD,GAAP;AACH;;AAED,eAAOA,MAAO,IAAIxb,KAAJ,CAAU,IAAI0b,GAAd,CAAD,CAAqBC,IAArB,CAA0B,GAA1B,CAAb;AACH,KAjEU;AAmEXC,kBAnEW,0BAmEIC,GAnEJ,EAmES;AAChB,YAAIC,MAAM,EAAV;;AAEA,aAAK,IAAI7gB,IAAI,CAAb,EAAgBA,IAAI4gB,IAAI3gB,MAAxB,EAAgCD,GAAhC,EAAqC;AACjC,gBAAI8gB,OAAOF,IAAI5gB,CAAJ,EAAO+gB,QAAP,CAAgB,EAAhB,CAAX;AACAF,mBAAQC,KAAK7gB,MAAL,KAAgB,CAAhB,GAAoB6gB,IAApB,GAA2B,MAAMA,IAAzC;AACH;;AAED,eAAOD,GAAP;AACH,KA5EU;AA8EXG,eA9EW,uBA8ECT,GA9ED,EA8EM;AACb,eAAOd,OAAOkB,cAAP,CAAsBM,mBAASC,WAAT,CAAqBzB,OAAOa,OAAP,CAAeC,GAAf,CAArB,CAAtB,CAAP;AACH,KAhFU;AAkFXY,qBAlFW,6BAkFOzB,CAlFP,EAkFU;AACjBA,YAAIA,EAAExP,OAAF,CAAU,IAAV,EAAgB,EAAhB,CAAJ;AACAwP,YAAIA,EAAExP,OAAF,CAAU,KAAV,EAAiB,GAAjB,CAAJ;AACAwP,YAAIA,EAAExP,OAAF,CAAU,KAAV,EAAiB,GAAjB,CAAJ;AACA,eAAOwP,CAAP;AACH,KAvFU;AAyFX0B,aAzFW,qBAyFDb,GAzFC,EAyFI;AACXA,cAAMA,IAAIrQ,OAAJ,CAAY,IAAZ,EAAkB,GAAlB,EAAuB;AAAvB,SACDA,OADC,CACO,IADP,EACa,GADb,EACkB;AADlB,SAEDA,OAFC,CAEO,KAFP,EAEc,GAFd,CAAN,CADW,CAGe;;AAE1B,eAAOmR,KAAKd,GAAL,CAAP;AACH;AA/FU,CAAf;;AAmGA,IAAIe,iBAAiB;AACjBC,UAAM,gCADW;AAEjBC,YAAQ,wCAFS;AAGjBC,YAAQ,wCAHS;AAIjBC,YAAQ,wCAJS;AAKjBC,YAAQ,wCALS;AAMjBC,SAAK,sCANY;AAOjBC,SAAK,sCAPY;AAQjBC,eAAW;AARM,CAArB;;AAWA,IAAIC,aAAa;AACbN,YAAQO,aADK;AAEbA,YAAOA;AAFM,CAAjB;;AAKA,SAASC,WAAT,CAAqBC,OAArB,EAA8B5c,GAA9B,EAAmC;AAC/B,SAAKvB,CAAL,GAAS,IAAT;AACA,SAAKnI,CAAL,GAAS,CAAT;;AAEA,QAAIsmB,WAAW,IAAX,IAAmB5c,OAAO,IAA1B,IAAkC4c,QAAQjiB,MAAR,GAAiB,CAAnD,IAAwDqF,IAAIrF,MAAJ,GAAa,CAAzE,EAA4E;AACxE,aAAK8D,CAAL,GAAS,IAAIsb,UAAJ,CAAe6C,OAAf,EAAwB,EAAxB,CAAT;AACA,aAAKtmB,CAAL,GAAS8I,SAASY,GAAT,EAAc,EAAd,CAAT;AACH,KAHD,MAGO;AACH,cAAM,IAAIrG,KAAJ,CAAU,kBAAV,CAAN;AACH;AACJ;;AAED,SAASkjB,sBAAT,CAAgCC,WAAhC,EAA6C;AACzC,SAAK,IAAIC,OAAT,IAAoBf,cAApB,EAAoC;AAChC,YAAIgB,OAAOhB,eAAee,OAAf,CAAX;AACA,YAAIE,MAAMD,KAAKriB,MAAf;;AAEA,YAAImiB,YAAY/B,SAAZ,CAAsB,CAAtB,EAAyBkC,GAAzB,MAAkCD,IAAtC,EAA4C;AACxC,mBAAO;AACH5c,qBAAK2c,OADF;AAEHtP,sBAAMqP,YAAY/B,SAAZ,CAAsBkC,GAAtB;AAFH,aAAP;AAIH;AACJ;AACD,WAAO,EAAP;AACH;;AAGDN,YAAYO,SAAZ,CAAsBhd,MAAtB,GAA+B,UAAUid,GAAV,EAAeC,MAAf,EAAuB;AAClDA,aAASjD,OAAOuB,WAAP,CAAmB0B,MAAnB,CAAT;AACAA,aAASA,OAAOxS,OAAP,CAAe,qBAAf,EAAsC,EAAtC,CAAT;;AAEA,QAAIyS,MAAM,IAAItD,UAAJ,CAAeqD,MAAf,EAAuB,EAAvB,CAAV;;AAEA,QAAIC,IAAIC,SAAJ,KAAkB,KAAK7e,CAAL,CAAO6e,SAAP,EAAtB,EAA0C;AACtC,cAAM,IAAI3jB,KAAJ,CAAU,gDAAV,CAAN;AACH;;AAED,QAAI4jB,eAAeF,IAAIG,SAAJ,CAAc,KAAKlnB,CAAnB,EAAsB,KAAKmI,CAA3B,CAAnB;AACA,QAAIgf,SAASF,aAAa9B,QAAb,CAAsB,EAAtB,EAA0B7Q,OAA1B,CAAkC,QAAlC,EAA4C,EAA5C,CAAb;AACA,QAAI8S,aAAab,uBAAuBY,MAAvB,CAAjB;;AAEA,QAAIC,WAAW/iB,MAAX,KAAsB,CAA1B,EAA6B;AACzB,eAAO,KAAP;AACH;;AAED,QAAI,CAAC8hB,WAAWhkB,cAAX,CAA0BilB,WAAWtd,GAArC,CAAL,EAAgD;AAC5C,cAAM,IAAIzG,KAAJ,CAAU,qCAAV,CAAN;AACH;;AAED,QAAIgkB,UAAUlB,WAAWiB,WAAWtd,GAAtB,EAA2B+c,GAA3B,EAAgC1B,QAAhC,EAAd;AACA,WAAQiC,WAAWjQ,IAAX,KAAoBkQ,OAA5B;AACH,CAxBD;;AA0BA,IAAMngB,qBAAqB,CAAC,OAAD,CAA3B;;AAEA,IAAMN,MAAM;AACRU,SAAK;AACDC,eAAO,eAASF,KAAT,EAAgB;AACnB,gBAAIigB,QAAQjgB,MAAMmS,KAAN,CAAY,GAAZ,CAAZ;AACA,gBAAIhS,MAAJ;AACA,gBAAIE,OAAJ;;AAEA;AACA;AACA,gBAAI4f,MAAMjjB,MAAN,KAAiB,CAArB,EAAwB;AACpB,uBAAOvH,SAAP;AACH;;AAED,gBAAI;AACA0K,yBAAS0D,KAAK3D,KAAL,CAAWsc,OAAO2B,SAAP,CAAiB8B,MAAM,CAAN,CAAjB,CAAX,CAAT;AACA5f,0BAAUwD,KAAK3D,KAAL,CAAWsc,OAAO2B,SAAP,CAAiB8B,MAAM,CAAN,CAAjB,CAAX,CAAV;AACH,aAHD,CAGE,OAAOtnB,CAAP,EAAU;AACR,uBAAO,IAAIqD,KAAJ,CAAU,2CAAV,CAAP;AACH;;AAED,mBAAO;AACHoE,2BAAWD,MADR;AAEHG,4BAAYD;AAFT,aAAP;AAIH,SAvBA;AAwBDkC,gBAAQ,gBAASxC,GAAT,EAAchB,GAAd,EAA4C;AAAA,gBAAzBmhB,kBAAyB,uEAAJ,EAAI;;AAChDA,+BAAmBrR,OAAnB,CAA2B,UAACpM,GAAD,EAAS;AAChC,oBAAI5C,mBAAmBzI,OAAnB,CAA2BqL,GAA3B,MAAoC,CAAC,CAAzC,EAA4C;AACxC,0BAAM,IAAIzG,KAAJ,CAAU,gCAAgCyG,GAA1C,CAAN;AACH;AACJ,aAJD;AAKA,gBAAIF,SAAS,IAAIyc,WAAJ,CAAgBjgB,IAAI+B,CAApB,EAAuB/B,IAAIpG,CAA3B,CAAb;AACA,gBAAIsnB,QAAQlgB,IAAIoS,KAAJ,CAAU,GAAV,CAAZ;;AAEA,gBAAIgO,mBAAmB,CAACF,MAAM,CAAN,CAAD,EAAWA,MAAM,CAAN,CAAX,EAAqBxC,IAArB,CAA0B,GAA1B,CAAvB;AACA,mBAAOlb,OAAOA,MAAP,CAAc4d,gBAAd,EAAgCF,MAAM,CAAN,CAAhC,CAAP;AACH;AAnCA;AADG,CAAZ;;AAwCA,IAAMzgB,UAAU;AACZ;;;;;;;AAOAuB,UARY,kBAQLhC,GARK,EAQA;AACR,YAAIA,IAAI8B,GAAJ,KAAY,KAAhB,EAAuB;AACnB,mBAAO;AACHlI,mBAAG6jB,OAAOuB,WAAP,CAAmBhf,IAAIpG,CAAvB,CADA;AAEHmI,mBAAG0b,OAAOuB,WAAP,CAAmBhf,IAAI+B,CAAvB;AAFA,aAAP;AAIH;;AAED,eAAO,IAAP;AACH;AAjBW,CAAhB;;AAoBA,IAAMrB,OAAO;AACT2gB,6BAAyB,mCAAW;AAChC,cAAM,IAAIpkB,KAAJ,CAAU,iFAAV,CAAN;AACH;AAHQ,CAAb;;AAMA,IAAM0D,SAAS;AACXgD,UAAM;AACFF,oBAAY,oBAASvD,KAAT,EAAgBwD,GAAhB,EAAqB;AAC7B,gBAAI4d,WAAWvB,WAAWrc,GAAX,CAAf;AACA,mBAAO4d,SAASphB,KAAT,EAAgB6e,QAAhB,EAAP;AACH;AAJC;AADK,CAAf;;AASA,SAASne,SAAT,CAAmB8c,CAAnB,EAAsB;AAClB,QAAIA,EAAEzf,MAAF,GAAW,CAAX,KAAiB,CAArB,EAAwB;AACpByf,YAAI,MAAMA,CAAV;AACH;AACD,WAAOD,OAAO0B,iBAAP,CAAyB1B,OAAOS,WAAP,CAAmBR,CAAnB,CAAzB,CAAP;AACH;;IAEM7c,Q,GAAY4c,M,CAAZ5c,Q;QAGHL,G,GAAAA,G;QACAC,O,GAAAA,O;QACAC,I,GAAAA,I;QACAC,M,GAAAA,M;QACAC,S,GAAAA,S;QACAC,Q,GAAAA,Q;QACAC,kB,GAAAA,kB;;;;;;;;;;;;;;;;;kBC/RoBygB,M;;AANxB;;;;;;AAEA;;;;AAIe,SAASA,MAAT,GAAkB;AAC/B,SAAO,mBAAQrT,OAAR,CAAgB,IAAhB,EAAsB,EAAtB,CAAP;AACD;;;;;;;;;;;;;;;;;;ACRD,IAAMpZ,UAAU,QAAhB,C,QAAkCA,O,GAAAA,O","file":"oidc-client.rsa256.slim.js","sourcesContent":[" \t// The module cache\n \tvar installedModules = {};\n\n \t// The require function\n \tfunction __webpack_require__(moduleId) {\n\n \t\t// Check if module is in cache\n \t\tif(installedModules[moduleId]) {\n \t\t\treturn installedModules[moduleId].exports;\n \t\t}\n \t\t// Create a new module (and put it into the cache)\n \t\tvar module = installedModules[moduleId] = {\n \t\t\ti: moduleId,\n \t\t\tl: false,\n \t\t\texports: {}\n \t\t};\n\n \t\t// Execute the module function\n \t\tmodules[moduleId].call(module.exports, module, module.exports, __webpack_require__);\n\n \t\t// Flag the module as loaded\n \t\tmodule.l = true;\n\n \t\t// Return the exports of the module\n \t\treturn module.exports;\n \t}\n\n\n \t// expose the modules object (__webpack_modules__)\n \t__webpack_require__.m = modules;\n\n \t// expose the module cache\n \t__webpack_require__.c = installedModules;\n\n \t// define getter function for harmony exports\n \t__webpack_require__.d = function(exports, name, getter) {\n \t\tif(!__webpack_require__.o(exports, name)) {\n \t\t\tObject.defineProperty(exports, name, { enumerable: true, get: getter });\n \t\t}\n \t};\n\n \t// define __esModule on exports\n \t__webpack_require__.r = function(exports) {\n \t\tif(typeof Symbol !== 'undefined' && Symbol.toStringTag) {\n \t\t\tObject.defineProperty(exports, Symbol.toStringTag, { value: 'Module' });\n \t\t}\n \t\tObject.defineProperty(exports, '__esModule', { value: true });\n \t};\n\n \t// create a fake namespace object\n \t// mode & 1: value is a module id, require it\n \t// mode & 2: merge all properties of value into the ns\n \t// mode & 4: return value when already ns object\n \t// mode & 8|1: behave like require\n \t__webpack_require__.t = function(value, mode) {\n \t\tif(mode & 1) value = __webpack_require__(value);\n \t\tif(mode & 8) return value;\n \t\tif((mode & 4) && typeof value === 'object' && value && value.__esModule) return value;\n \t\tvar ns = Object.create(null);\n \t\t__webpack_require__.r(ns);\n \t\tObject.defineProperty(ns, 'default', { enumerable: true, value: value });\n \t\tif(mode & 2 && typeof value != 'string') for(var key in value) __webpack_require__.d(ns, key, function(key) { return value[key]; }.bind(null, key));\n \t\treturn ns;\n \t};\n\n \t// getDefaultExport function for compatibility with non-harmony modules\n \t__webpack_require__.n = function(module) {\n \t\tvar getter = module && module.__esModule ?\n \t\t\tfunction getDefault() { return module['default']; } :\n \t\t\tfunction getModuleExports() { return module; };\n \t\t__webpack_require__.d(getter, 'a', getter);\n \t\treturn getter;\n \t};\n\n \t// Object.prototype.hasOwnProperty.call\n \t__webpack_require__.o = function(object, property) { return Object.prototype.hasOwnProperty.call(object, property); };\n\n \t// __webpack_public_path__\n \t__webpack_require__.p = \"\";\n\n\n \t// Load entry module and return exports\n \treturn __webpack_require__(__webpack_require__.s = 0);\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './src/Log.js';\r\nimport { OidcClient } from './src/OidcClient.js';\r\nimport { OidcClientSettings } from './src/OidcClientSettings.js';\r\nimport { WebStorageStateStore } from './src/WebStorageStateStore.js';\r\nimport { InMemoryWebStorage } from './src/InMemoryWebStorage.js';\r\nimport { UserManager } from './src/UserManager.js';\r\nimport { AccessTokenEvents } from './src/AccessTokenEvents.js';\r\nimport { MetadataService } from './src/MetadataService.js';\r\nimport { CordovaPopupNavigator } from './src/CordovaPopupNavigator.js';\r\nimport { CordovaIFrameNavigator } from './src/CordovaIFrameNavigator.js';\r\nimport { CheckSessionIFrame } from './src/CheckSessionIFrame.js';\r\nimport { TokenRevocationClient } from './src/TokenRevocationClient.js';\r\nimport { SessionMonitor } from './src/SessionMonitor.js';\r\nimport { Global } from './src/Global.js';\r\nimport { User } from './src/User.js';\r\n\r\nimport { Version } from './version.js';\r\n\r\nexport default {\r\n    Version,\r\n    Log,\r\n    OidcClient,\r\n    OidcClientSettings,\r\n    WebStorageStateStore,\r\n    InMemoryWebStorage,\r\n    UserManager,\r\n    AccessTokenEvents,\r\n    MetadataService,\r\n    CordovaPopupNavigator,\r\n    CordovaIFrameNavigator,\r\n    CheckSessionIFrame,\r\n    TokenRevocationClient,\r\n    SessionMonitor,\r\n    Global,\r\n    User\r\n};\r\n","'use strict'\n\nexports.byteLength = byteLength\nexports.toByteArray = toByteArray\nexports.fromByteArray = fromByteArray\n\nvar lookup = []\nvar revLookup = []\nvar Arr = typeof Uint8Array !== 'undefined' ? Uint8Array : Array\n\nvar code = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'\nfor (var i = 0, len = code.length; i < len; ++i) {\n  lookup[i] = code[i]\n  revLookup[code.charCodeAt(i)] = i\n}\n\n// Support decoding URL-safe base64 strings, as Node.js does.\n// See: https://en.wikipedia.org/wiki/Base64#URL_applications\nrevLookup['-'.charCodeAt(0)] = 62\nrevLookup['_'.charCodeAt(0)] = 63\n\nfunction getLens (b64) {\n  var len = b64.length\n\n  if (len % 4 > 0) {\n    throw new Error('Invalid string. Length must be a multiple of 4')\n  }\n\n  // Trim off extra bytes after placeholder bytes are found\n  // See: https://github.com/beatgammit/base64-js/issues/42\n  var validLen = b64.indexOf('=')\n  if (validLen === -1) validLen = len\n\n  var placeHoldersLen = validLen === len\n    ? 0\n    : 4 - (validLen % 4)\n\n  return [validLen, placeHoldersLen]\n}\n\n// base64 is 4/3 + up to two characters of the original data\nfunction byteLength (b64) {\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction _byteLength (b64, validLen, placeHoldersLen) {\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction toByteArray (b64) {\n  var tmp\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n\n  var arr = new Arr(_byteLength(b64, validLen, placeHoldersLen))\n\n  var curByte = 0\n\n  // if there are placeholders, only get up to the last complete 4 chars\n  var len = placeHoldersLen > 0\n    ? validLen - 4\n    : validLen\n\n  for (var i = 0; i < len; i += 4) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 18) |\n      (revLookup[b64.charCodeAt(i + 1)] << 12) |\n      (revLookup[b64.charCodeAt(i + 2)] << 6) |\n      revLookup[b64.charCodeAt(i + 3)]\n    arr[curByte++] = (tmp >> 16) & 0xFF\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 2) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 2) |\n      (revLookup[b64.charCodeAt(i + 1)] >> 4)\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 1) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 10) |\n      (revLookup[b64.charCodeAt(i + 1)] << 4) |\n      (revLookup[b64.charCodeAt(i + 2)] >> 2)\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  return arr\n}\n\nfunction tripletToBase64 (num) {\n  return lookup[num >> 18 & 0x3F] +\n    lookup[num >> 12 & 0x3F] +\n    lookup[num >> 6 & 0x3F] +\n    lookup[num & 0x3F]\n}\n\nfunction encodeChunk (uint8, start, end) {\n  var tmp\n  var output = []\n  for (var i = start; i < end; i += 3) {\n    tmp =\n      ((uint8[i] << 16) & 0xFF0000) +\n      ((uint8[i + 1] << 8) & 0xFF00) +\n      (uint8[i + 2] & 0xFF)\n    output.push(tripletToBase64(tmp))\n  }\n  return output.join('')\n}\n\nfunction fromByteArray (uint8) {\n  var tmp\n  var len = uint8.length\n  var extraBytes = len % 3 // if we have 1 byte left, pad 2 bytes\n  var parts = []\n  var maxChunkLength = 16383 // must be multiple of 3\n\n  // go through the array every three bytes, we'll deal with trailing stuff later\n  for (var i = 0, len2 = len - extraBytes; i < len2; i += maxChunkLength) {\n    parts.push(encodeChunk(\n      uint8, i, (i + maxChunkLength) > len2 ? len2 : (i + maxChunkLength)\n    ))\n  }\n\n  // pad the end with zeros, but make sure to not forget the extra bytes\n  if (extraBytes === 1) {\n    tmp = uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 2] +\n      lookup[(tmp << 4) & 0x3F] +\n      '=='\n    )\n  } else if (extraBytes === 2) {\n    tmp = (uint8[len - 2] << 8) + uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 10] +\n      lookup[(tmp >> 4) & 0x3F] +\n      lookup[(tmp << 2) & 0x3F] +\n      '='\n    )\n  }\n\n  return parts.join('')\n}\n","require('../modules/es6.object.to-string');\nrequire('../modules/es6.string.iterator');\nrequire('../modules/web.dom.iterable');\nrequire('../modules/es6.promise');\nmodule.exports = require('../modules/_core').Promise;\n","require('../../modules/es6.array.find');\nmodule.exports = require('../../modules/_core').Array.find;\n","require('../../modules/es6.array.is-array');\nmodule.exports = require('../../modules/_core').Array.isArray;\n","require('../../modules/es6.array.some');\nmodule.exports = require('../../modules/_core').Array.some;\n","// for a legacy code and future fixes\nmodule.exports = function () {\n  return Function.call.apply(Array.prototype.splice, arguments);\n};\n","require('../../modules/es6.function.bind');\nmodule.exports = require('../../modules/_core').Function.bind;\n","require('../../modules/es6.object.assign');\nmodule.exports = require('../../modules/_core').Object.assign;\n","module.exports = function (it) {\n  if (typeof it != 'function') throw TypeError(it + ' is not a function!');\n  return it;\n};\n","// 22.1.3.31 Array.prototype[@@unscopables]\nvar UNSCOPABLES = require('./_wks')('unscopables');\nvar ArrayProto = Array.prototype;\nif (ArrayProto[UNSCOPABLES] == undefined) require('./_hide')(ArrayProto, UNSCOPABLES, {});\nmodule.exports = function (key) {\n  ArrayProto[UNSCOPABLES][key] = true;\n};\n","module.exports = function (it, Constructor, name, forbiddenField) {\n  if (!(it instanceof Constructor) || (forbiddenField !== undefined && forbiddenField in it)) {\n    throw TypeError(name + ': incorrect invocation!');\n  } return it;\n};\n","var isObject = require('./_is-object');\nmodule.exports = function (it) {\n  if (!isObject(it)) throw TypeError(it + ' is not an object!');\n  return it;\n};\n","// false -> Array#indexOf\n// true  -> Array#includes\nvar toIObject = require('./_to-iobject');\nvar toLength = require('./_to-length');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nmodule.exports = function (IS_INCLUDES) {\n  return function ($this, el, fromIndex) {\n    var O = toIObject($this);\n    var length = toLength(O.length);\n    var index = toAbsoluteIndex(fromIndex, length);\n    var value;\n    // Array#includes uses SameValueZero equality algorithm\n    // eslint-disable-next-line no-self-compare\n    if (IS_INCLUDES && el != el) while (length > index) {\n      value = O[index++];\n      // eslint-disable-next-line no-self-compare\n      if (value != value) return true;\n    // Array#indexOf ignores holes, Array#includes - not\n    } else for (;length > index; index++) if (IS_INCLUDES || index in O) {\n      if (O[index] === el) return IS_INCLUDES || index || 0;\n    } return !IS_INCLUDES && -1;\n  };\n};\n","// 0 -> Array#forEach\n// 1 -> Array#map\n// 2 -> Array#filter\n// 3 -> Array#some\n// 4 -> Array#every\n// 5 -> Array#find\n// 6 -> Array#findIndex\nvar ctx = require('./_ctx');\nvar IObject = require('./_iobject');\nvar toObject = require('./_to-object');\nvar toLength = require('./_to-length');\nvar asc = require('./_array-species-create');\nmodule.exports = function (TYPE, $create) {\n  var IS_MAP = TYPE == 1;\n  var IS_FILTER = TYPE == 2;\n  var IS_SOME = TYPE == 3;\n  var IS_EVERY = TYPE == 4;\n  var IS_FIND_INDEX = TYPE == 6;\n  var NO_HOLES = TYPE == 5 || IS_FIND_INDEX;\n  var create = $create || asc;\n  return function ($this, callbackfn, that) {\n    var O = toObject($this);\n    var self = IObject(O);\n    var f = ctx(callbackfn, that, 3);\n    var length = toLength(self.length);\n    var index = 0;\n    var result = IS_MAP ? create($this, length) : IS_FILTER ? create($this, 0) : undefined;\n    var val, res;\n    for (;length > index; index++) if (NO_HOLES || index in self) {\n      val = self[index];\n      res = f(val, index, O);\n      if (TYPE) {\n        if (IS_MAP) result[index] = res;   // map\n        else if (res) switch (TYPE) {\n          case 3: return true;             // some\n          case 5: return val;              // find\n          case 6: return index;            // findIndex\n          case 2: result.push(val);        // filter\n        } else if (IS_EVERY) return false; // every\n      }\n    }\n    return IS_FIND_INDEX ? -1 : IS_SOME || IS_EVERY ? IS_EVERY : result;\n  };\n};\n","var isObject = require('./_is-object');\nvar isArray = require('./_is-array');\nvar SPECIES = require('./_wks')('species');\n\nmodule.exports = function (original) {\n  var C;\n  if (isArray(original)) {\n    C = original.constructor;\n    // cross-realm fallback\n    if (typeof C == 'function' && (C === Array || isArray(C.prototype))) C = undefined;\n    if (isObject(C)) {\n      C = C[SPECIES];\n      if (C === null) C = undefined;\n    }\n  } return C === undefined ? Array : C;\n};\n","// 9.4.2.3 ArraySpeciesCreate(originalArray, length)\nvar speciesConstructor = require('./_array-species-constructor');\n\nmodule.exports = function (original, length) {\n  return new (speciesConstructor(original))(length);\n};\n","'use strict';\nvar aFunction = require('./_a-function');\nvar isObject = require('./_is-object');\nvar invoke = require('./_invoke');\nvar arraySlice = [].slice;\nvar factories = {};\n\nvar construct = function (F, len, args) {\n  if (!(len in factories)) {\n    for (var n = [], i = 0; i < len; i++) n[i] = 'a[' + i + ']';\n    // eslint-disable-next-line no-new-func\n    factories[len] = Function('F,a', 'return new F(' + n.join(',') + ')');\n  } return factories[len](F, args);\n};\n\nmodule.exports = Function.bind || function bind(that /* , ...args */) {\n  var fn = aFunction(this);\n  var partArgs = arraySlice.call(arguments, 1);\n  var bound = function (/* args... */) {\n    var args = partArgs.concat(arraySlice.call(arguments));\n    return this instanceof bound ? construct(fn, args.length, args) : invoke(fn, args, that);\n  };\n  if (isObject(fn.prototype)) bound.prototype = fn.prototype;\n  return bound;\n};\n","// getting tag from 19.1.3.6 Object.prototype.toString()\nvar cof = require('./_cof');\nvar TAG = require('./_wks')('toStringTag');\n// ES3 wrong here\nvar ARG = cof(function () { return arguments; }()) == 'Arguments';\n\n// fallback for IE11 Script Access Denied error\nvar tryGet = function (it, key) {\n  try {\n    return it[key];\n  } catch (e) { /* empty */ }\n};\n\nmodule.exports = function (it) {\n  var O, T, B;\n  return it === undefined ? 'Undefined' : it === null ? 'Null'\n    // @@toStringTag case\n    : typeof (T = tryGet(O = Object(it), TAG)) == 'string' ? T\n    // builtinTag case\n    : ARG ? cof(O)\n    // ES3 arguments fallback\n    : (B = cof(O)) == 'Object' && typeof O.callee == 'function' ? 'Arguments' : B;\n};\n","var toString = {}.toString;\n\nmodule.exports = function (it) {\n  return toString.call(it).slice(8, -1);\n};\n","var core = module.exports = { version: '2.6.4' };\nif (typeof __e == 'number') __e = core; // eslint-disable-line no-undef\n","// optional / simple context binding\nvar aFunction = require('./_a-function');\nmodule.exports = function (fn, that, length) {\n  aFunction(fn);\n  if (that === undefined) return fn;\n  switch (length) {\n    case 1: return function (a) {\n      return fn.call(that, a);\n    };\n    case 2: return function (a, b) {\n      return fn.call(that, a, b);\n    };\n    case 3: return function (a, b, c) {\n      return fn.call(that, a, b, c);\n    };\n  }\n  return function (/* ...args */) {\n    return fn.apply(that, arguments);\n  };\n};\n","// 7.2.1 RequireObjectCoercible(argument)\nmodule.exports = function (it) {\n  if (it == undefined) throw TypeError(\"Can't call method on  \" + it);\n  return it;\n};\n","// Thank's IE8 for his funny defineProperty\nmodule.exports = !require('./_fails')(function () {\n  return Object.defineProperty({}, 'a', { get: function () { return 7; } }).a != 7;\n});\n","var isObject = require('./_is-object');\nvar document = require('./_global').document;\n// typeof document.createElement is 'object' in old IE\nvar is = isObject(document) && isObject(document.createElement);\nmodule.exports = function (it) {\n  return is ? document.createElement(it) : {};\n};\n","// IE 8- don't enum bug keys\nmodule.exports = (\n  'constructor,hasOwnProperty,isPrototypeOf,propertyIsEnumerable,toLocaleString,toString,valueOf'\n).split(',');\n","var global = require('./_global');\nvar core = require('./_core');\nvar hide = require('./_hide');\nvar redefine = require('./_redefine');\nvar ctx = require('./_ctx');\nvar PROTOTYPE = 'prototype';\n\nvar $export = function (type, name, source) {\n  var IS_FORCED = type & $export.F;\n  var IS_GLOBAL = type & $export.G;\n  var IS_STATIC = type & $export.S;\n  var IS_PROTO = type & $export.P;\n  var IS_BIND = type & $export.B;\n  var target = IS_GLOBAL ? global : IS_STATIC ? global[name] || (global[name] = {}) : (global[name] || {})[PROTOTYPE];\n  var exports = IS_GLOBAL ? core : core[name] || (core[name] = {});\n  var expProto = exports[PROTOTYPE] || (exports[PROTOTYPE] = {});\n  var key, own, out, exp;\n  if (IS_GLOBAL) source = name;\n  for (key in source) {\n    // contains in native\n    own = !IS_FORCED && target && target[key] !== undefined;\n    // export native or passed\n    out = (own ? target : source)[key];\n    // bind timers to global for call from export context\n    exp = IS_BIND && own ? ctx(out, global) : IS_PROTO && typeof out == 'function' ? ctx(Function.call, out) : out;\n    // extend global\n    if (target) redefine(target, key, out, type & $export.U);\n    // export\n    if (exports[key] != out) hide(exports, key, exp);\n    if (IS_PROTO && expProto[key] != out) expProto[key] = out;\n  }\n};\nglobal.core = core;\n// type bitmap\n$export.F = 1;   // forced\n$export.G = 2;   // global\n$export.S = 4;   // static\n$export.P = 8;   // proto\n$export.B = 16;  // bind\n$export.W = 32;  // wrap\n$export.U = 64;  // safe\n$export.R = 128; // real proto method for `library`\nmodule.exports = $export;\n","module.exports = function (exec) {\n  try {\n    return !!exec();\n  } catch (e) {\n    return true;\n  }\n};\n","var ctx = require('./_ctx');\nvar call = require('./_iter-call');\nvar isArrayIter = require('./_is-array-iter');\nvar anObject = require('./_an-object');\nvar toLength = require('./_to-length');\nvar getIterFn = require('./core.get-iterator-method');\nvar BREAK = {};\nvar RETURN = {};\nvar exports = module.exports = function (iterable, entries, fn, that, ITERATOR) {\n  var iterFn = ITERATOR ? function () { return iterable; } : getIterFn(iterable);\n  var f = ctx(fn, that, entries ? 2 : 1);\n  var index = 0;\n  var length, step, iterator, result;\n  if (typeof iterFn != 'function') throw TypeError(iterable + ' is not iterable!');\n  // fast case for arrays with default iterator\n  if (isArrayIter(iterFn)) for (length = toLength(iterable.length); length > index; index++) {\n    result = entries ? f(anObject(step = iterable[index])[0], step[1]) : f(iterable[index]);\n    if (result === BREAK || result === RETURN) return result;\n  } else for (iterator = iterFn.call(iterable); !(step = iterator.next()).done;) {\n    result = call(iterator, f, step.value, entries);\n    if (result === BREAK || result === RETURN) return result;\n  }\n};\nexports.BREAK = BREAK;\nexports.RETURN = RETURN;\n","module.exports = require('./_shared')('native-function-to-string', Function.toString);\n","// https://github.com/zloirock/core-js/issues/86#issuecomment-115759028\nvar global = module.exports = typeof window != 'undefined' && window.Math == Math\n  ? window : typeof self != 'undefined' && self.Math == Math ? self\n  // eslint-disable-next-line no-new-func\n  : Function('return this')();\nif (typeof __g == 'number') __g = global; // eslint-disable-line no-undef\n","var hasOwnProperty = {}.hasOwnProperty;\nmodule.exports = function (it, key) {\n  return hasOwnProperty.call(it, key);\n};\n","var dP = require('./_object-dp');\nvar createDesc = require('./_property-desc');\nmodule.exports = require('./_descriptors') ? function (object, key, value) {\n  return dP.f(object, key, createDesc(1, value));\n} : function (object, key, value) {\n  object[key] = value;\n  return object;\n};\n","var document = require('./_global').document;\nmodule.exports = document && document.documentElement;\n","module.exports = !require('./_descriptors') && !require('./_fails')(function () {\n  return Object.defineProperty(require('./_dom-create')('div'), 'a', { get: function () { return 7; } }).a != 7;\n});\n","// fast apply, http://jsperf.lnkit.com/fast-apply/5\nmodule.exports = function (fn, args, that) {\n  var un = that === undefined;\n  switch (args.length) {\n    case 0: return un ? fn()\n                      : fn.call(that);\n    case 1: return un ? fn(args[0])\n                      : fn.call(that, args[0]);\n    case 2: return un ? fn(args[0], args[1])\n                      : fn.call(that, args[0], args[1]);\n    case 3: return un ? fn(args[0], args[1], args[2])\n                      : fn.call(that, args[0], args[1], args[2]);\n    case 4: return un ? fn(args[0], args[1], args[2], args[3])\n                      : fn.call(that, args[0], args[1], args[2], args[3]);\n  } return fn.apply(that, args);\n};\n","// fallback for non-array-like ES3 and non-enumerable old V8 strings\nvar cof = require('./_cof');\n// eslint-disable-next-line no-prototype-builtins\nmodule.exports = Object('z').propertyIsEnumerable(0) ? Object : function (it) {\n  return cof(it) == 'String' ? it.split('') : Object(it);\n};\n","// check on default Array iterator\nvar Iterators = require('./_iterators');\nvar ITERATOR = require('./_wks')('iterator');\nvar ArrayProto = Array.prototype;\n\nmodule.exports = function (it) {\n  return it !== undefined && (Iterators.Array === it || ArrayProto[ITERATOR] === it);\n};\n","// 7.2.2 IsArray(argument)\nvar cof = require('./_cof');\nmodule.exports = Array.isArray || function isArray(arg) {\n  return cof(arg) == 'Array';\n};\n","module.exports = function (it) {\n  return typeof it === 'object' ? it !== null : typeof it === 'function';\n};\n","// call something on iterator step with safe closing on error\nvar anObject = require('./_an-object');\nmodule.exports = function (iterator, fn, value, entries) {\n  try {\n    return entries ? fn(anObject(value)[0], value[1]) : fn(value);\n  // 7.4.6 IteratorClose(iterator, completion)\n  } catch (e) {\n    var ret = iterator['return'];\n    if (ret !== undefined) anObject(ret.call(iterator));\n    throw e;\n  }\n};\n","'use strict';\nvar create = require('./_object-create');\nvar descriptor = require('./_property-desc');\nvar setToStringTag = require('./_set-to-string-tag');\nvar IteratorPrototype = {};\n\n// 25.1.2.1.1 %IteratorPrototype%[@@iterator]()\nrequire('./_hide')(IteratorPrototype, require('./_wks')('iterator'), function () { return this; });\n\nmodule.exports = function (Constructor, NAME, next) {\n  Constructor.prototype = create(IteratorPrototype, { next: descriptor(1, next) });\n  setToStringTag(Constructor, NAME + ' Iterator');\n};\n","'use strict';\nvar LIBRARY = require('./_library');\nvar $export = require('./_export');\nvar redefine = require('./_redefine');\nvar hide = require('./_hide');\nvar Iterators = require('./_iterators');\nvar $iterCreate = require('./_iter-create');\nvar setToStringTag = require('./_set-to-string-tag');\nvar getPrototypeOf = require('./_object-gpo');\nvar ITERATOR = require('./_wks')('iterator');\nvar BUGGY = !([].keys && 'next' in [].keys()); // Safari has buggy iterators w/o `next`\nvar FF_ITERATOR = '@@iterator';\nvar KEYS = 'keys';\nvar VALUES = 'values';\n\nvar returnThis = function () { return this; };\n\nmodule.exports = function (Base, NAME, Constructor, next, DEFAULT, IS_SET, FORCED) {\n  $iterCreate(Constructor, NAME, next);\n  var getMethod = function (kind) {\n    if (!BUGGY && kind in proto) return proto[kind];\n    switch (kind) {\n      case KEYS: return function keys() { return new Constructor(this, kind); };\n      case VALUES: return function values() { return new Constructor(this, kind); };\n    } return function entries() { return new Constructor(this, kind); };\n  };\n  var TAG = NAME + ' Iterator';\n  var DEF_VALUES = DEFAULT == VALUES;\n  var VALUES_BUG = false;\n  var proto = Base.prototype;\n  var $native = proto[ITERATOR] || proto[FF_ITERATOR] || DEFAULT && proto[DEFAULT];\n  var $default = $native || getMethod(DEFAULT);\n  var $entries = DEFAULT ? !DEF_VALUES ? $default : getMethod('entries') : undefined;\n  var $anyNative = NAME == 'Array' ? proto.entries || $native : $native;\n  var methods, key, IteratorPrototype;\n  // Fix native\n  if ($anyNative) {\n    IteratorPrototype = getPrototypeOf($anyNative.call(new Base()));\n    if (IteratorPrototype !== Object.prototype && IteratorPrototype.next) {\n      // Set @@toStringTag to native iterators\n      setToStringTag(IteratorPrototype, TAG, true);\n      // fix for some old engines\n      if (!LIBRARY && typeof IteratorPrototype[ITERATOR] != 'function') hide(IteratorPrototype, ITERATOR, returnThis);\n    }\n  }\n  // fix Array#{values, @@iterator}.name in V8 / FF\n  if (DEF_VALUES && $native && $native.name !== VALUES) {\n    VALUES_BUG = true;\n    $default = function values() { return $native.call(this); };\n  }\n  // Define iterator\n  if ((!LIBRARY || FORCED) && (BUGGY || VALUES_BUG || !proto[ITERATOR])) {\n    hide(proto, ITERATOR, $default);\n  }\n  // Plug for library\n  Iterators[NAME] = $default;\n  Iterators[TAG] = returnThis;\n  if (DEFAULT) {\n    methods = {\n      values: DEF_VALUES ? $default : getMethod(VALUES),\n      keys: IS_SET ? $default : getMethod(KEYS),\n      entries: $entries\n    };\n    if (FORCED) for (key in methods) {\n      if (!(key in proto)) redefine(proto, key, methods[key]);\n    } else $export($export.P + $export.F * (BUGGY || VALUES_BUG), NAME, methods);\n  }\n  return methods;\n};\n","var ITERATOR = require('./_wks')('iterator');\nvar SAFE_CLOSING = false;\n\ntry {\n  var riter = [7][ITERATOR]();\n  riter['return'] = function () { SAFE_CLOSING = true; };\n  // eslint-disable-next-line no-throw-literal\n  Array.from(riter, function () { throw 2; });\n} catch (e) { /* empty */ }\n\nmodule.exports = function (exec, skipClosing) {\n  if (!skipClosing && !SAFE_CLOSING) return false;\n  var safe = false;\n  try {\n    var arr = [7];\n    var iter = arr[ITERATOR]();\n    iter.next = function () { return { done: safe = true }; };\n    arr[ITERATOR] = function () { return iter; };\n    exec(arr);\n  } catch (e) { /* empty */ }\n  return safe;\n};\n","module.exports = function (done, value) {\n  return { value: value, done: !!done };\n};\n","module.exports = {};\n","module.exports = false;\n","var global = require('./_global');\nvar macrotask = require('./_task').set;\nvar Observer = global.MutationObserver || global.WebKitMutationObserver;\nvar process = global.process;\nvar Promise = global.Promise;\nvar isNode = require('./_cof')(process) == 'process';\n\nmodule.exports = function () {\n  var head, last, notify;\n\n  var flush = function () {\n    var parent, fn;\n    if (isNode && (parent = process.domain)) parent.exit();\n    while (head) {\n      fn = head.fn;\n      head = head.next;\n      try {\n        fn();\n      } catch (e) {\n        if (head) notify();\n        else last = undefined;\n        throw e;\n      }\n    } last = undefined;\n    if (parent) parent.enter();\n  };\n\n  // Node.js\n  if (isNode) {\n    notify = function () {\n      process.nextTick(flush);\n    };\n  // browsers with MutationObserver, except iOS Safari - https://github.com/zloirock/core-js/issues/339\n  } else if (Observer && !(global.navigator && global.navigator.standalone)) {\n    var toggle = true;\n    var node = document.createTextNode('');\n    new Observer(flush).observe(node, { characterData: true }); // eslint-disable-line no-new\n    notify = function () {\n      node.data = toggle = !toggle;\n    };\n  // environments with maybe non-completely correct, but existent Promise\n  } else if (Promise && Promise.resolve) {\n    // Promise.resolve without an argument throws an error in LG WebOS 2\n    var promise = Promise.resolve(undefined);\n    notify = function () {\n      promise.then(flush);\n    };\n  // for other environments - macrotask based on:\n  // - setImmediate\n  // - MessageChannel\n  // - window.postMessag\n  // - onreadystatechange\n  // - setTimeout\n  } else {\n    notify = function () {\n      // strange IE + webpack dev server bug - use .call(global)\n      macrotask.call(global, flush);\n    };\n  }\n\n  return function (fn) {\n    var task = { fn: fn, next: undefined };\n    if (last) last.next = task;\n    if (!head) {\n      head = task;\n      notify();\n    } last = task;\n  };\n};\n","'use strict';\n// 25.4.1.5 NewPromiseCapability(C)\nvar aFunction = require('./_a-function');\n\nfunction PromiseCapability(C) {\n  var resolve, reject;\n  this.promise = new C(function ($$resolve, $$reject) {\n    if (resolve !== undefined || reject !== undefined) throw TypeError('Bad Promise constructor');\n    resolve = $$resolve;\n    reject = $$reject;\n  });\n  this.resolve = aFunction(resolve);\n  this.reject = aFunction(reject);\n}\n\nmodule.exports.f = function (C) {\n  return new PromiseCapability(C);\n};\n","'use strict';\n// 19.1.2.1 Object.assign(target, source, ...)\nvar getKeys = require('./_object-keys');\nvar gOPS = require('./_object-gops');\nvar pIE = require('./_object-pie');\nvar toObject = require('./_to-object');\nvar IObject = require('./_iobject');\nvar $assign = Object.assign;\n\n// should work with symbols and should have deterministic property order (V8 bug)\nmodule.exports = !$assign || require('./_fails')(function () {\n  var A = {};\n  var B = {};\n  // eslint-disable-next-line no-undef\n  var S = Symbol();\n  var K = 'abcdefghijklmnopqrst';\n  A[S] = 7;\n  K.split('').forEach(function (k) { B[k] = k; });\n  return $assign({}, A)[S] != 7 || Object.keys($assign({}, B)).join('') != K;\n}) ? function assign(target, source) { // eslint-disable-line no-unused-vars\n  var T = toObject(target);\n  var aLen = arguments.length;\n  var index = 1;\n  var getSymbols = gOPS.f;\n  var isEnum = pIE.f;\n  while (aLen > index) {\n    var S = IObject(arguments[index++]);\n    var keys = getSymbols ? getKeys(S).concat(getSymbols(S)) : getKeys(S);\n    var length = keys.length;\n    var j = 0;\n    var key;\n    while (length > j) if (isEnum.call(S, key = keys[j++])) T[key] = S[key];\n  } return T;\n} : $assign;\n","// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\nvar anObject = require('./_an-object');\nvar dPs = require('./_object-dps');\nvar enumBugKeys = require('./_enum-bug-keys');\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\nvar Empty = function () { /* empty */ };\nvar PROTOTYPE = 'prototype';\n\n// Create object with fake `null` prototype: use iframe Object with cleared prototype\nvar createDict = function () {\n  // Thrash, waste and sodomy: IE GC bug\n  var iframe = require('./_dom-create')('iframe');\n  var i = enumBugKeys.length;\n  var lt = '<';\n  var gt = '>';\n  var iframeDocument;\n  iframe.style.display = 'none';\n  require('./_html').appendChild(iframe);\n  iframe.src = 'javascript:'; // eslint-disable-line no-script-url\n  // createDict = iframe.contentWindow.Object;\n  // html.removeChild(iframe);\n  iframeDocument = iframe.contentWindow.document;\n  iframeDocument.open();\n  iframeDocument.write(lt + 'script' + gt + 'document.F=Object' + lt + '/script' + gt);\n  iframeDocument.close();\n  createDict = iframeDocument.F;\n  while (i--) delete createDict[PROTOTYPE][enumBugKeys[i]];\n  return createDict();\n};\n\nmodule.exports = Object.create || function create(O, Properties) {\n  var result;\n  if (O !== null) {\n    Empty[PROTOTYPE] = anObject(O);\n    result = new Empty();\n    Empty[PROTOTYPE] = null;\n    // add \"__proto__\" for Object.getPrototypeOf polyfill\n    result[IE_PROTO] = O;\n  } else result = createDict();\n  return Properties === undefined ? result : dPs(result, Properties);\n};\n","var anObject = require('./_an-object');\nvar IE8_DOM_DEFINE = require('./_ie8-dom-define');\nvar toPrimitive = require('./_to-primitive');\nvar dP = Object.defineProperty;\n\nexports.f = require('./_descriptors') ? Object.defineProperty : function defineProperty(O, P, Attributes) {\n  anObject(O);\n  P = toPrimitive(P, true);\n  anObject(Attributes);\n  if (IE8_DOM_DEFINE) try {\n    return dP(O, P, Attributes);\n  } catch (e) { /* empty */ }\n  if ('get' in Attributes || 'set' in Attributes) throw TypeError('Accessors not supported!');\n  if ('value' in Attributes) O[P] = Attributes.value;\n  return O;\n};\n","var dP = require('./_object-dp');\nvar anObject = require('./_an-object');\nvar getKeys = require('./_object-keys');\n\nmodule.exports = require('./_descriptors') ? Object.defineProperties : function defineProperties(O, Properties) {\n  anObject(O);\n  var keys = getKeys(Properties);\n  var length = keys.length;\n  var i = 0;\n  var P;\n  while (length > i) dP.f(O, P = keys[i++], Properties[P]);\n  return O;\n};\n","exports.f = Object.getOwnPropertySymbols;\n","// 19.1.2.9 / 15.2.3.2 Object.getPrototypeOf(O)\nvar has = require('./_has');\nvar toObject = require('./_to-object');\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\nvar ObjectProto = Object.prototype;\n\nmodule.exports = Object.getPrototypeOf || function (O) {\n  O = toObject(O);\n  if (has(O, IE_PROTO)) return O[IE_PROTO];\n  if (typeof O.constructor == 'function' && O instanceof O.constructor) {\n    return O.constructor.prototype;\n  } return O instanceof Object ? ObjectProto : null;\n};\n","var has = require('./_has');\nvar toIObject = require('./_to-iobject');\nvar arrayIndexOf = require('./_array-includes')(false);\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\n\nmodule.exports = function (object, names) {\n  var O = toIObject(object);\n  var i = 0;\n  var result = [];\n  var key;\n  for (key in O) if (key != IE_PROTO) has(O, key) && result.push(key);\n  // Don't enum bug & hidden keys\n  while (names.length > i) if (has(O, key = names[i++])) {\n    ~arrayIndexOf(result, key) || result.push(key);\n  }\n  return result;\n};\n","// 19.1.2.14 / 15.2.3.14 Object.keys(O)\nvar $keys = require('./_object-keys-internal');\nvar enumBugKeys = require('./_enum-bug-keys');\n\nmodule.exports = Object.keys || function keys(O) {\n  return $keys(O, enumBugKeys);\n};\n","exports.f = {}.propertyIsEnumerable;\n","module.exports = function (exec) {\n  try {\n    return { e: false, v: exec() };\n  } catch (e) {\n    return { e: true, v: e };\n  }\n};\n","var anObject = require('./_an-object');\nvar isObject = require('./_is-object');\nvar newPromiseCapability = require('./_new-promise-capability');\n\nmodule.exports = function (C, x) {\n  anObject(C);\n  if (isObject(x) && x.constructor === C) return x;\n  var promiseCapability = newPromiseCapability.f(C);\n  var resolve = promiseCapability.resolve;\n  resolve(x);\n  return promiseCapability.promise;\n};\n","module.exports = function (bitmap, value) {\n  return {\n    enumerable: !(bitmap & 1),\n    configurable: !(bitmap & 2),\n    writable: !(bitmap & 4),\n    value: value\n  };\n};\n","var redefine = require('./_redefine');\nmodule.exports = function (target, src, safe) {\n  for (var key in src) redefine(target, key, src[key], safe);\n  return target;\n};\n","var global = require('./_global');\nvar hide = require('./_hide');\nvar has = require('./_has');\nvar SRC = require('./_uid')('src');\nvar $toString = require('./_function-to-string');\nvar TO_STRING = 'toString';\nvar TPL = ('' + $toString).split(TO_STRING);\n\nrequire('./_core').inspectSource = function (it) {\n  return $toString.call(it);\n};\n\n(module.exports = function (O, key, val, safe) {\n  var isFunction = typeof val == 'function';\n  if (isFunction) has(val, 'name') || hide(val, 'name', key);\n  if (O[key] === val) return;\n  if (isFunction) has(val, SRC) || hide(val, SRC, O[key] ? '' + O[key] : TPL.join(String(key)));\n  if (O === global) {\n    O[key] = val;\n  } else if (!safe) {\n    delete O[key];\n    hide(O, key, val);\n  } else if (O[key]) {\n    O[key] = val;\n  } else {\n    hide(O, key, val);\n  }\n// add fake Function#toString for correct work wrapped methods / constructors with methods like LoDash isNative\n})(Function.prototype, TO_STRING, function toString() {\n  return typeof this == 'function' && this[SRC] || $toString.call(this);\n});\n","'use strict';\nvar global = require('./_global');\nvar dP = require('./_object-dp');\nvar DESCRIPTORS = require('./_descriptors');\nvar SPECIES = require('./_wks')('species');\n\nmodule.exports = function (KEY) {\n  var C = global[KEY];\n  if (DESCRIPTORS && C && !C[SPECIES]) dP.f(C, SPECIES, {\n    configurable: true,\n    get: function () { return this; }\n  });\n};\n","var def = require('./_object-dp').f;\nvar has = require('./_has');\nvar TAG = require('./_wks')('toStringTag');\n\nmodule.exports = function (it, tag, stat) {\n  if (it && !has(it = stat ? it : it.prototype, TAG)) def(it, TAG, { configurable: true, value: tag });\n};\n","var shared = require('./_shared')('keys');\nvar uid = require('./_uid');\nmodule.exports = function (key) {\n  return shared[key] || (shared[key] = uid(key));\n};\n","var core = require('./_core');\nvar global = require('./_global');\nvar SHARED = '__core-js_shared__';\nvar store = global[SHARED] || (global[SHARED] = {});\n\n(module.exports = function (key, value) {\n  return store[key] || (store[key] = value !== undefined ? value : {});\n})('versions', []).push({\n  version: core.version,\n  mode: require('./_library') ? 'pure' : 'global',\n  copyright: '© 2019 Denis Pushkarev (zloirock.ru)'\n});\n","// 7.3.20 SpeciesConstructor(O, defaultConstructor)\nvar anObject = require('./_an-object');\nvar aFunction = require('./_a-function');\nvar SPECIES = require('./_wks')('species');\nmodule.exports = function (O, D) {\n  var C = anObject(O).constructor;\n  var S;\n  return C === undefined || (S = anObject(C)[SPECIES]) == undefined ? D : aFunction(S);\n};\n","'use strict';\nvar fails = require('./_fails');\n\nmodule.exports = function (method, arg) {\n  return !!method && fails(function () {\n    // eslint-disable-next-line no-useless-call\n    arg ? method.call(null, function () { /* empty */ }, 1) : method.call(null);\n  });\n};\n","var toInteger = require('./_to-integer');\nvar defined = require('./_defined');\n// true  -> String#at\n// false -> String#codePointAt\nmodule.exports = function (TO_STRING) {\n  return function (that, pos) {\n    var s = String(defined(that));\n    var i = toInteger(pos);\n    var l = s.length;\n    var a, b;\n    if (i < 0 || i >= l) return TO_STRING ? '' : undefined;\n    a = s.charCodeAt(i);\n    return a < 0xd800 || a > 0xdbff || i + 1 === l || (b = s.charCodeAt(i + 1)) < 0xdc00 || b > 0xdfff\n      ? TO_STRING ? s.charAt(i) : a\n      : TO_STRING ? s.slice(i, i + 2) : (a - 0xd800 << 10) + (b - 0xdc00) + 0x10000;\n  };\n};\n","var ctx = require('./_ctx');\nvar invoke = require('./_invoke');\nvar html = require('./_html');\nvar cel = require('./_dom-create');\nvar global = require('./_global');\nvar process = global.process;\nvar setTask = global.setImmediate;\nvar clearTask = global.clearImmediate;\nvar MessageChannel = global.MessageChannel;\nvar Dispatch = global.Dispatch;\nvar counter = 0;\nvar queue = {};\nvar ONREADYSTATECHANGE = 'onreadystatechange';\nvar defer, channel, port;\nvar run = function () {\n  var id = +this;\n  // eslint-disable-next-line no-prototype-builtins\n  if (queue.hasOwnProperty(id)) {\n    var fn = queue[id];\n    delete queue[id];\n    fn();\n  }\n};\nvar listener = function (event) {\n  run.call(event.data);\n};\n// Node.js 0.9+ & IE10+ has setImmediate, otherwise:\nif (!setTask || !clearTask) {\n  setTask = function setImmediate(fn) {\n    var args = [];\n    var i = 1;\n    while (arguments.length > i) args.push(arguments[i++]);\n    queue[++counter] = function () {\n      // eslint-disable-next-line no-new-func\n      invoke(typeof fn == 'function' ? fn : Function(fn), args);\n    };\n    defer(counter);\n    return counter;\n  };\n  clearTask = function clearImmediate(id) {\n    delete queue[id];\n  };\n  // Node.js 0.8-\n  if (require('./_cof')(process) == 'process') {\n    defer = function (id) {\n      process.nextTick(ctx(run, id, 1));\n    };\n  // Sphere (JS game engine) Dispatch API\n  } else if (Dispatch && Dispatch.now) {\n    defer = function (id) {\n      Dispatch.now(ctx(run, id, 1));\n    };\n  // Browsers with MessageChannel, includes WebWorkers\n  } else if (MessageChannel) {\n    channel = new MessageChannel();\n    port = channel.port2;\n    channel.port1.onmessage = listener;\n    defer = ctx(port.postMessage, port, 1);\n  // Browsers with postMessage, skip WebWorkers\n  // IE8 has postMessage, but it's sync & typeof its postMessage is 'object'\n  } else if (global.addEventListener && typeof postMessage == 'function' && !global.importScripts) {\n    defer = function (id) {\n      global.postMessage(id + '', '*');\n    };\n    global.addEventListener('message', listener, false);\n  // IE8-\n  } else if (ONREADYSTATECHANGE in cel('script')) {\n    defer = function (id) {\n      html.appendChild(cel('script'))[ONREADYSTATECHANGE] = function () {\n        html.removeChild(this);\n        run.call(id);\n      };\n    };\n  // Rest old browsers\n  } else {\n    defer = function (id) {\n      setTimeout(ctx(run, id, 1), 0);\n    };\n  }\n}\nmodule.exports = {\n  set: setTask,\n  clear: clearTask\n};\n","var toInteger = require('./_to-integer');\nvar max = Math.max;\nvar min = Math.min;\nmodule.exports = function (index, length) {\n  index = toInteger(index);\n  return index < 0 ? max(index + length, 0) : min(index, length);\n};\n","// 7.1.4 ToInteger\nvar ceil = Math.ceil;\nvar floor = Math.floor;\nmodule.exports = function (it) {\n  return isNaN(it = +it) ? 0 : (it > 0 ? floor : ceil)(it);\n};\n","// to indexed object, toObject with fallback for non-array-like ES3 strings\nvar IObject = require('./_iobject');\nvar defined = require('./_defined');\nmodule.exports = function (it) {\n  return IObject(defined(it));\n};\n","// 7.1.15 ToLength\nvar toInteger = require('./_to-integer');\nvar min = Math.min;\nmodule.exports = function (it) {\n  return it > 0 ? min(toInteger(it), 0x1fffffffffffff) : 0; // pow(2, 53) - 1 == 9007199254740991\n};\n","// 7.1.13 ToObject(argument)\nvar defined = require('./_defined');\nmodule.exports = function (it) {\n  return Object(defined(it));\n};\n","// 7.1.1 ToPrimitive(input [, PreferredType])\nvar isObject = require('./_is-object');\n// instead of the ES6 spec version, we didn't implement @@toPrimitive case\n// and the second argument - flag - preferred type is a string\nmodule.exports = function (it, S) {\n  if (!isObject(it)) return it;\n  var fn, val;\n  if (S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (typeof (fn = it.valueOf) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (!S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  throw TypeError(\"Can't convert object to primitive value\");\n};\n","var id = 0;\nvar px = Math.random();\nmodule.exports = function (key) {\n  return 'Symbol('.concat(key === undefined ? '' : key, ')_', (++id + px).toString(36));\n};\n","var global = require('./_global');\nvar navigator = global.navigator;\n\nmodule.exports = navigator && navigator.userAgent || '';\n","var store = require('./_shared')('wks');\nvar uid = require('./_uid');\nvar Symbol = require('./_global').Symbol;\nvar USE_SYMBOL = typeof Symbol == 'function';\n\nvar $exports = module.exports = function (name) {\n  return store[name] || (store[name] =\n    USE_SYMBOL && Symbol[name] || (USE_SYMBOL ? Symbol : uid)('Symbol.' + name));\n};\n\n$exports.store = store;\n","var classof = require('./_classof');\nvar ITERATOR = require('./_wks')('iterator');\nvar Iterators = require('./_iterators');\nmodule.exports = require('./_core').getIteratorMethod = function (it) {\n  if (it != undefined) return it[ITERATOR]\n    || it['@@iterator']\n    || Iterators[classof(it)];\n};\n","'use strict';\n// 22.1.3.8 Array.prototype.find(predicate, thisArg = undefined)\nvar $export = require('./_export');\nvar $find = require('./_array-methods')(5);\nvar KEY = 'find';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  find: function find(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\nrequire('./_add-to-unscopables')(KEY);\n","// 22.1.2.2 / 15.4.3.2 Array.isArray(arg)\nvar $export = require('./_export');\n\n$export($export.S, 'Array', { isArray: require('./_is-array') });\n","'use strict';\nvar addToUnscopables = require('./_add-to-unscopables');\nvar step = require('./_iter-step');\nvar Iterators = require('./_iterators');\nvar toIObject = require('./_to-iobject');\n\n// 22.1.3.4 Array.prototype.entries()\n// 22.1.3.13 Array.prototype.keys()\n// 22.1.3.29 Array.prototype.values()\n// 22.1.3.30 Array.prototype[@@iterator]()\nmodule.exports = require('./_iter-define')(Array, 'Array', function (iterated, kind) {\n  this._t = toIObject(iterated); // target\n  this._i = 0;                   // next index\n  this._k = kind;                // kind\n// 22.1.5.2.1 %ArrayIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var kind = this._k;\n  var index = this._i++;\n  if (!O || index >= O.length) {\n    this._t = undefined;\n    return step(1);\n  }\n  if (kind == 'keys') return step(0, index);\n  if (kind == 'values') return step(0, O[index]);\n  return step(0, [index, O[index]]);\n}, 'values');\n\n// argumentsList[@@iterator] is %ArrayProto_values% (9.4.4.6, 9.4.4.7)\nIterators.Arguments = Iterators.Array;\n\naddToUnscopables('keys');\naddToUnscopables('values');\naddToUnscopables('entries');\n","'use strict';\nvar $export = require('./_export');\nvar $some = require('./_array-methods')(3);\n\n$export($export.P + $export.F * !require('./_strict-method')([].some, true), 'Array', {\n  // 22.1.3.23 / 15.4.4.17 Array.prototype.some(callbackfn [, thisArg])\n  some: function some(callbackfn /* , thisArg */) {\n    return $some(this, callbackfn, arguments[1]);\n  }\n});\n","// 19.2.3.2 / 15.3.4.5 Function.prototype.bind(thisArg, args...)\nvar $export = require('./_export');\n\n$export($export.P, 'Function', { bind: require('./_bind') });\n","// 19.1.3.1 Object.assign(target, source)\nvar $export = require('./_export');\n\n$export($export.S + $export.F, 'Object', { assign: require('./_object-assign') });\n","'use strict';\n// 19.1.3.6 Object.prototype.toString()\nvar classof = require('./_classof');\nvar test = {};\ntest[require('./_wks')('toStringTag')] = 'z';\nif (test + '' != '[object z]') {\n  require('./_redefine')(Object.prototype, 'toString', function toString() {\n    return '[object ' + classof(this) + ']';\n  }, true);\n}\n","'use strict';\nvar LIBRARY = require('./_library');\nvar global = require('./_global');\nvar ctx = require('./_ctx');\nvar classof = require('./_classof');\nvar $export = require('./_export');\nvar isObject = require('./_is-object');\nvar aFunction = require('./_a-function');\nvar anInstance = require('./_an-instance');\nvar forOf = require('./_for-of');\nvar speciesConstructor = require('./_species-constructor');\nvar task = require('./_task').set;\nvar microtask = require('./_microtask')();\nvar newPromiseCapabilityModule = require('./_new-promise-capability');\nvar perform = require('./_perform');\nvar userAgent = require('./_user-agent');\nvar promiseResolve = require('./_promise-resolve');\nvar PROMISE = 'Promise';\nvar TypeError = global.TypeError;\nvar process = global.process;\nvar versions = process && process.versions;\nvar v8 = versions && versions.v8 || '';\nvar $Promise = global[PROMISE];\nvar isNode = classof(process) == 'process';\nvar empty = function () { /* empty */ };\nvar Internal, newGenericPromiseCapability, OwnPromiseCapability, Wrapper;\nvar newPromiseCapability = newGenericPromiseCapability = newPromiseCapabilityModule.f;\n\nvar USE_NATIVE = !!function () {\n  try {\n    // correct subclassing with @@species support\n    var promise = $Promise.resolve(1);\n    var FakePromise = (promise.constructor = {})[require('./_wks')('species')] = function (exec) {\n      exec(empty, empty);\n    };\n    // unhandled rejections tracking support, NodeJS Promise without it fails @@species test\n    return (isNode || typeof PromiseRejectionEvent == 'function')\n      && promise.then(empty) instanceof FakePromise\n      // v8 6.6 (Node 10 and Chrome 66) have a bug with resolving custom thenables\n      // https://bugs.chromium.org/p/chromium/issues/detail?id=830565\n      // we can't detect it synchronously, so just check versions\n      && v8.indexOf('6.6') !== 0\n      && userAgent.indexOf('Chrome/66') === -1;\n  } catch (e) { /* empty */ }\n}();\n\n// helpers\nvar isThenable = function (it) {\n  var then;\n  return isObject(it) && typeof (then = it.then) == 'function' ? then : false;\n};\nvar notify = function (promise, isReject) {\n  if (promise._n) return;\n  promise._n = true;\n  var chain = promise._c;\n  microtask(function () {\n    var value = promise._v;\n    var ok = promise._s == 1;\n    var i = 0;\n    var run = function (reaction) {\n      var handler = ok ? reaction.ok : reaction.fail;\n      var resolve = reaction.resolve;\n      var reject = reaction.reject;\n      var domain = reaction.domain;\n      var result, then, exited;\n      try {\n        if (handler) {\n          if (!ok) {\n            if (promise._h == 2) onHandleUnhandled(promise);\n            promise._h = 1;\n          }\n          if (handler === true) result = value;\n          else {\n            if (domain) domain.enter();\n            result = handler(value); // may throw\n            if (domain) {\n              domain.exit();\n              exited = true;\n            }\n          }\n          if (result === reaction.promise) {\n            reject(TypeError('Promise-chain cycle'));\n          } else if (then = isThenable(result)) {\n            then.call(result, resolve, reject);\n          } else resolve(result);\n        } else reject(value);\n      } catch (e) {\n        if (domain && !exited) domain.exit();\n        reject(e);\n      }\n    };\n    while (chain.length > i) run(chain[i++]); // variable length - can't use forEach\n    promise._c = [];\n    promise._n = false;\n    if (isReject && !promise._h) onUnhandled(promise);\n  });\n};\nvar onUnhandled = function (promise) {\n  task.call(global, function () {\n    var value = promise._v;\n    var unhandled = isUnhandled(promise);\n    var result, handler, console;\n    if (unhandled) {\n      result = perform(function () {\n        if (isNode) {\n          process.emit('unhandledRejection', value, promise);\n        } else if (handler = global.onunhandledrejection) {\n          handler({ promise: promise, reason: value });\n        } else if ((console = global.console) && console.error) {\n          console.error('Unhandled promise rejection', value);\n        }\n      });\n      // Browsers should not trigger `rejectionHandled` event if it was handled here, NodeJS - should\n      promise._h = isNode || isUnhandled(promise) ? 2 : 1;\n    } promise._a = undefined;\n    if (unhandled && result.e) throw result.v;\n  });\n};\nvar isUnhandled = function (promise) {\n  return promise._h !== 1 && (promise._a || promise._c).length === 0;\n};\nvar onHandleUnhandled = function (promise) {\n  task.call(global, function () {\n    var handler;\n    if (isNode) {\n      process.emit('rejectionHandled', promise);\n    } else if (handler = global.onrejectionhandled) {\n      handler({ promise: promise, reason: promise._v });\n    }\n  });\n};\nvar $reject = function (value) {\n  var promise = this;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  promise._v = value;\n  promise._s = 2;\n  if (!promise._a) promise._a = promise._c.slice();\n  notify(promise, true);\n};\nvar $resolve = function (value) {\n  var promise = this;\n  var then;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  try {\n    if (promise === value) throw TypeError(\"Promise can't be resolved itself\");\n    if (then = isThenable(value)) {\n      microtask(function () {\n        var wrapper = { _w: promise, _d: false }; // wrap\n        try {\n          then.call(value, ctx($resolve, wrapper, 1), ctx($reject, wrapper, 1));\n        } catch (e) {\n          $reject.call(wrapper, e);\n        }\n      });\n    } else {\n      promise._v = value;\n      promise._s = 1;\n      notify(promise, false);\n    }\n  } catch (e) {\n    $reject.call({ _w: promise, _d: false }, e); // wrap\n  }\n};\n\n// constructor polyfill\nif (!USE_NATIVE) {\n  // 25.4.3.1 Promise(executor)\n  $Promise = function Promise(executor) {\n    anInstance(this, $Promise, PROMISE, '_h');\n    aFunction(executor);\n    Internal.call(this);\n    try {\n      executor(ctx($resolve, this, 1), ctx($reject, this, 1));\n    } catch (err) {\n      $reject.call(this, err);\n    }\n  };\n  // eslint-disable-next-line no-unused-vars\n  Internal = function Promise(executor) {\n    this._c = [];             // <- awaiting reactions\n    this._a = undefined;      // <- checked in isUnhandled reactions\n    this._s = 0;              // <- state\n    this._d = false;          // <- done\n    this._v = undefined;      // <- value\n    this._h = 0;              // <- rejection state, 0 - default, 1 - handled, 2 - unhandled\n    this._n = false;          // <- notify\n  };\n  Internal.prototype = require('./_redefine-all')($Promise.prototype, {\n    // 25.4.5.3 Promise.prototype.then(onFulfilled, onRejected)\n    then: function then(onFulfilled, onRejected) {\n      var reaction = newPromiseCapability(speciesConstructor(this, $Promise));\n      reaction.ok = typeof onFulfilled == 'function' ? onFulfilled : true;\n      reaction.fail = typeof onRejected == 'function' && onRejected;\n      reaction.domain = isNode ? process.domain : undefined;\n      this._c.push(reaction);\n      if (this._a) this._a.push(reaction);\n      if (this._s) notify(this, false);\n      return reaction.promise;\n    },\n    // 25.4.5.1 Promise.prototype.catch(onRejected)\n    'catch': function (onRejected) {\n      return this.then(undefined, onRejected);\n    }\n  });\n  OwnPromiseCapability = function () {\n    var promise = new Internal();\n    this.promise = promise;\n    this.resolve = ctx($resolve, promise, 1);\n    this.reject = ctx($reject, promise, 1);\n  };\n  newPromiseCapabilityModule.f = newPromiseCapability = function (C) {\n    return C === $Promise || C === Wrapper\n      ? new OwnPromiseCapability(C)\n      : newGenericPromiseCapability(C);\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Promise: $Promise });\nrequire('./_set-to-string-tag')($Promise, PROMISE);\nrequire('./_set-species')(PROMISE);\nWrapper = require('./_core')[PROMISE];\n\n// statics\n$export($export.S + $export.F * !USE_NATIVE, PROMISE, {\n  // 25.4.4.5 Promise.reject(r)\n  reject: function reject(r) {\n    var capability = newPromiseCapability(this);\n    var $$reject = capability.reject;\n    $$reject(r);\n    return capability.promise;\n  }\n});\n$export($export.S + $export.F * (LIBRARY || !USE_NATIVE), PROMISE, {\n  // 25.4.4.6 Promise.resolve(x)\n  resolve: function resolve(x) {\n    return promiseResolve(LIBRARY && this === Wrapper ? $Promise : this, x);\n  }\n});\n$export($export.S + $export.F * !(USE_NATIVE && require('./_iter-detect')(function (iter) {\n  $Promise.all(iter)['catch'](empty);\n})), PROMISE, {\n  // 25.4.4.1 Promise.all(iterable)\n  all: function all(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var resolve = capability.resolve;\n    var reject = capability.reject;\n    var result = perform(function () {\n      var values = [];\n      var index = 0;\n      var remaining = 1;\n      forOf(iterable, false, function (promise) {\n        var $index = index++;\n        var alreadyCalled = false;\n        values.push(undefined);\n        remaining++;\n        C.resolve(promise).then(function (value) {\n          if (alreadyCalled) return;\n          alreadyCalled = true;\n          values[$index] = value;\n          --remaining || resolve(values);\n        }, reject);\n      });\n      --remaining || resolve(values);\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  },\n  // 25.4.4.4 Promise.race(iterable)\n  race: function race(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var reject = capability.reject;\n    var result = perform(function () {\n      forOf(iterable, false, function (promise) {\n        C.resolve(promise).then(capability.resolve, reject);\n      });\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  }\n});\n","'use strict';\nvar $at = require('./_string-at')(true);\n\n// 21.1.3.27 String.prototype[@@iterator]()\nrequire('./_iter-define')(String, 'String', function (iterated) {\n  this._t = String(iterated); // target\n  this._i = 0;                // next index\n// 21.1.5.2.1 %StringIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var index = this._i;\n  var point;\n  if (index >= O.length) return { value: undefined, done: true };\n  point = $at(O, index);\n  this._i += point.length;\n  return { value: point, done: false };\n});\n","var $iterators = require('./es6.array.iterator');\nvar getKeys = require('./_object-keys');\nvar redefine = require('./_redefine');\nvar global = require('./_global');\nvar hide = require('./_hide');\nvar Iterators = require('./_iterators');\nvar wks = require('./_wks');\nvar ITERATOR = wks('iterator');\nvar TO_STRING_TAG = wks('toStringTag');\nvar ArrayValues = Iterators.Array;\n\nvar DOMIterables = {\n  CSSRuleList: true, // TODO: Not spec compliant, should be false.\n  CSSStyleDeclaration: false,\n  CSSValueList: false,\n  ClientRectList: false,\n  DOMRectList: false,\n  DOMStringList: false,\n  DOMTokenList: true,\n  DataTransferItemList: false,\n  FileList: false,\n  HTMLAllCollection: false,\n  HTMLCollection: false,\n  HTMLFormElement: false,\n  HTMLSelectElement: false,\n  MediaList: true, // TODO: Not spec compliant, should be false.\n  MimeTypeArray: false,\n  NamedNodeMap: false,\n  NodeList: true,\n  PaintRequestList: false,\n  Plugin: false,\n  PluginArray: false,\n  SVGLengthList: false,\n  SVGNumberList: false,\n  SVGPathSegList: false,\n  SVGPointList: false,\n  SVGStringList: false,\n  SVGTransformList: false,\n  SourceBufferList: false,\n  StyleSheetList: true, // TODO: Not spec compliant, should be false.\n  TextTrackCueList: false,\n  TextTrackList: false,\n  TouchList: false\n};\n\nfor (var collections = getKeys(DOMIterables), i = 0; i < collections.length; i++) {\n  var NAME = collections[i];\n  var explicit = DOMIterables[NAME];\n  var Collection = global[NAME];\n  var proto = Collection && Collection.prototype;\n  var key;\n  if (proto) {\n    if (!proto[ITERATOR]) hide(proto, ITERATOR, ArrayValues);\n    if (!proto[TO_STRING_TAG]) hide(proto, TO_STRING_TAG, NAME);\n    Iterators[NAME] = ArrayValues;\n    if (explicit) for (key in $iterators) if (!proto[key]) redefine(proto, key, $iterators[key], true);\n  }\n}\n",";(function (root, factory) {\n\tif (typeof exports === \"object\") {\n\t\t// CommonJS\n\t\tmodule.exports = exports = factory();\n\t}\n\telse if (typeof define === \"function\" && define.amd) {\n\t\t// AMD\n\t\tdefine([], factory);\n\t}\n\telse {\n\t\t// Global (browser)\n\t\troot.CryptoJS = factory();\n\t}\n}(this, function () {\n\n\t/**\n\t * CryptoJS core components.\n\t */\n\tvar CryptoJS = CryptoJS || (function (Math, undefined) {\n\t    /*\n\t     * Local polyfil of Object.create\n\t     */\n\t    var create = Object.create || (function () {\n\t        function F() {};\n\n\t        return function (obj) {\n\t            var subtype;\n\n\t            F.prototype = obj;\n\n\t            subtype = new F();\n\n\t            F.prototype = null;\n\n\t            return subtype;\n\t        };\n\t    }())\n\n\t    /**\n\t     * CryptoJS namespace.\n\t     */\n\t    var C = {};\n\n\t    /**\n\t     * Library namespace.\n\t     */\n\t    var C_lib = C.lib = {};\n\n\t    /**\n\t     * Base object for prototypal inheritance.\n\t     */\n\t    var Base = C_lib.Base = (function () {\n\n\n\t        return {\n\t            /**\n\t             * Creates a new object that inherits from this object.\n\t             *\n\t             * @param {Object} overrides Properties to copy into the new object.\n\t             *\n\t             * @return {Object} The new object.\n\t             *\n\t             * @static\n\t             *\n\t             * @example\n\t             *\n\t             *     var MyType = CryptoJS.lib.Base.extend({\n\t             *         field: 'value',\n\t             *\n\t             *         method: function () {\n\t             *         }\n\t             *     });\n\t             */\n\t            extend: function (overrides) {\n\t                // Spawn\n\t                var subtype = create(this);\n\n\t                // Augment\n\t                if (overrides) {\n\t                    subtype.mixIn(overrides);\n\t                }\n\n\t                // Create default initializer\n\t                if (!subtype.hasOwnProperty('init') || this.init === subtype.init) {\n\t                    subtype.init = function () {\n\t                        subtype.$super.init.apply(this, arguments);\n\t                    };\n\t                }\n\n\t                // Initializer's prototype is the subtype object\n\t                subtype.init.prototype = subtype;\n\n\t                // Reference supertype\n\t                subtype.$super = this;\n\n\t                return subtype;\n\t            },\n\n\t            /**\n\t             * Extends this object and runs the init method.\n\t             * Arguments to create() will be passed to init().\n\t             *\n\t             * @return {Object} The new object.\n\t             *\n\t             * @static\n\t             *\n\t             * @example\n\t             *\n\t             *     var instance = MyType.create();\n\t             */\n\t            create: function () {\n\t                var instance = this.extend();\n\t                instance.init.apply(instance, arguments);\n\n\t                return instance;\n\t            },\n\n\t            /**\n\t             * Initializes a newly created object.\n\t             * Override this method to add some logic when your objects are created.\n\t             *\n\t             * @example\n\t             *\n\t             *     var MyType = CryptoJS.lib.Base.extend({\n\t             *         init: function () {\n\t             *             // ...\n\t             *         }\n\t             *     });\n\t             */\n\t            init: function () {\n\t            },\n\n\t            /**\n\t             * Copies properties into this object.\n\t             *\n\t             * @param {Object} properties The properties to mix in.\n\t             *\n\t             * @example\n\t             *\n\t             *     MyType.mixIn({\n\t             *         field: 'value'\n\t             *     });\n\t             */\n\t            mixIn: function (properties) {\n\t                for (var propertyName in properties) {\n\t                    if (properties.hasOwnProperty(propertyName)) {\n\t                        this[propertyName] = properties[propertyName];\n\t                    }\n\t                }\n\n\t                // IE won't copy toString using the loop above\n\t                if (properties.hasOwnProperty('toString')) {\n\t                    this.toString = properties.toString;\n\t                }\n\t            },\n\n\t            /**\n\t             * Creates a copy of this object.\n\t             *\n\t             * @return {Object} The clone.\n\t             *\n\t             * @example\n\t             *\n\t             *     var clone = instance.clone();\n\t             */\n\t            clone: function () {\n\t                return this.init.prototype.extend(this);\n\t            }\n\t        };\n\t    }());\n\n\t    /**\n\t     * An array of 32-bit words.\n\t     *\n\t     * @property {Array} words The array of 32-bit words.\n\t     * @property {number} sigBytes The number of significant bytes in this word array.\n\t     */\n\t    var WordArray = C_lib.WordArray = Base.extend({\n\t        /**\n\t         * Initializes a newly created word array.\n\t         *\n\t         * @param {Array} words (Optional) An array of 32-bit words.\n\t         * @param {number} sigBytes (Optional) The number of significant bytes in the words.\n\t         *\n\t         * @example\n\t         *\n\t         *     var wordArray = CryptoJS.lib.WordArray.create();\n\t         *     var wordArray = CryptoJS.lib.WordArray.create([0x00010203, 0x04050607]);\n\t         *     var wordArray = CryptoJS.lib.WordArray.create([0x00010203, 0x04050607], 6);\n\t         */\n\t        init: function (words, sigBytes) {\n\t            words = this.words = words || [];\n\n\t            if (sigBytes != undefined) {\n\t                this.sigBytes = sigBytes;\n\t            } else {\n\t                this.sigBytes = words.length * 4;\n\t            }\n\t        },\n\n\t        /**\n\t         * Converts this word array to a string.\n\t         *\n\t         * @param {Encoder} encoder (Optional) The encoding strategy to use. Default: CryptoJS.enc.Hex\n\t         *\n\t         * @return {string} The stringified word array.\n\t         *\n\t         * @example\n\t         *\n\t         *     var string = wordArray + '';\n\t         *     var string = wordArray.toString();\n\t         *     var string = wordArray.toString(CryptoJS.enc.Utf8);\n\t         */\n\t        toString: function (encoder) {\n\t            return (encoder || Hex).stringify(this);\n\t        },\n\n\t        /**\n\t         * Concatenates a word array to this word array.\n\t         *\n\t         * @param {WordArray} wordArray The word array to append.\n\t         *\n\t         * @return {WordArray} This word array.\n\t         *\n\t         * @example\n\t         *\n\t         *     wordArray1.concat(wordArray2);\n\t         */\n\t        concat: function (wordArray) {\n\t            // Shortcuts\n\t            var thisWords = this.words;\n\t            var thatWords = wordArray.words;\n\t            var thisSigBytes = this.sigBytes;\n\t            var thatSigBytes = wordArray.sigBytes;\n\n\t            // Clamp excess bits\n\t            this.clamp();\n\n\t            // Concat\n\t            if (thisSigBytes % 4) {\n\t                // Copy one byte at a time\n\t                for (var i = 0; i < thatSigBytes; i++) {\n\t                    var thatByte = (thatWords[i >>> 2] >>> (24 - (i % 4) * 8)) & 0xff;\n\t                    thisWords[(thisSigBytes + i) >>> 2] |= thatByte << (24 - ((thisSigBytes + i) % 4) * 8);\n\t                }\n\t            } else {\n\t                // Copy one word at a time\n\t                for (var i = 0; i < thatSigBytes; i += 4) {\n\t                    thisWords[(thisSigBytes + i) >>> 2] = thatWords[i >>> 2];\n\t                }\n\t            }\n\t            this.sigBytes += thatSigBytes;\n\n\t            // Chainable\n\t            return this;\n\t        },\n\n\t        /**\n\t         * Removes insignificant bits.\n\t         *\n\t         * @example\n\t         *\n\t         *     wordArray.clamp();\n\t         */\n\t        clamp: function () {\n\t            // Shortcuts\n\t            var words = this.words;\n\t            var sigBytes = this.sigBytes;\n\n\t            // Clamp\n\t            words[sigBytes >>> 2] &= 0xffffffff << (32 - (sigBytes % 4) * 8);\n\t            words.length = Math.ceil(sigBytes / 4);\n\t        },\n\n\t        /**\n\t         * Creates a copy of this word array.\n\t         *\n\t         * @return {WordArray} The clone.\n\t         *\n\t         * @example\n\t         *\n\t         *     var clone = wordArray.clone();\n\t         */\n\t        clone: function () {\n\t            var clone = Base.clone.call(this);\n\t            clone.words = this.words.slice(0);\n\n\t            return clone;\n\t        },\n\n\t        /**\n\t         * Creates a word array filled with random bytes.\n\t         *\n\t         * @param {number} nBytes The number of random bytes to generate.\n\t         *\n\t         * @return {WordArray} The random word array.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var wordArray = CryptoJS.lib.WordArray.random(16);\n\t         */\n\t        random: function (nBytes) {\n\t            var words = [];\n\n\t            var r = (function (m_w) {\n\t                var m_w = m_w;\n\t                var m_z = 0x3ade68b1;\n\t                var mask = 0xffffffff;\n\n\t                return function () {\n\t                    m_z = (0x9069 * (m_z & 0xFFFF) + (m_z >> 0x10)) & mask;\n\t                    m_w = (0x4650 * (m_w & 0xFFFF) + (m_w >> 0x10)) & mask;\n\t                    var result = ((m_z << 0x10) + m_w) & mask;\n\t                    result /= 0x100000000;\n\t                    result += 0.5;\n\t                    return result * (Math.random() > .5 ? 1 : -1);\n\t                }\n\t            });\n\n\t            for (var i = 0, rcache; i < nBytes; i += 4) {\n\t                var _r = r((rcache || Math.random()) * 0x100000000);\n\n\t                rcache = _r() * 0x3ade67b7;\n\t                words.push((_r() * 0x100000000) | 0);\n\t            }\n\n\t            return new WordArray.init(words, nBytes);\n\t        }\n\t    });\n\n\t    /**\n\t     * Encoder namespace.\n\t     */\n\t    var C_enc = C.enc = {};\n\n\t    /**\n\t     * Hex encoding strategy.\n\t     */\n\t    var Hex = C_enc.Hex = {\n\t        /**\n\t         * Converts a word array to a hex string.\n\t         *\n\t         * @param {WordArray} wordArray The word array.\n\t         *\n\t         * @return {string} The hex string.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var hexString = CryptoJS.enc.Hex.stringify(wordArray);\n\t         */\n\t        stringify: function (wordArray) {\n\t            // Shortcuts\n\t            var words = wordArray.words;\n\t            var sigBytes = wordArray.sigBytes;\n\n\t            // Convert\n\t            var hexChars = [];\n\t            for (var i = 0; i < sigBytes; i++) {\n\t                var bite = (words[i >>> 2] >>> (24 - (i % 4) * 8)) & 0xff;\n\t                hexChars.push((bite >>> 4).toString(16));\n\t                hexChars.push((bite & 0x0f).toString(16));\n\t            }\n\n\t            return hexChars.join('');\n\t        },\n\n\t        /**\n\t         * Converts a hex string to a word array.\n\t         *\n\t         * @param {string} hexStr The hex string.\n\t         *\n\t         * @return {WordArray} The word array.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var wordArray = CryptoJS.enc.Hex.parse(hexString);\n\t         */\n\t        parse: function (hexStr) {\n\t            // Shortcut\n\t            var hexStrLength = hexStr.length;\n\n\t            // Convert\n\t            var words = [];\n\t            for (var i = 0; i < hexStrLength; i += 2) {\n\t                words[i >>> 3] |= parseInt(hexStr.substr(i, 2), 16) << (24 - (i % 8) * 4);\n\t            }\n\n\t            return new WordArray.init(words, hexStrLength / 2);\n\t        }\n\t    };\n\n\t    /**\n\t     * Latin1 encoding strategy.\n\t     */\n\t    var Latin1 = C_enc.Latin1 = {\n\t        /**\n\t         * Converts a word array to a Latin1 string.\n\t         *\n\t         * @param {WordArray} wordArray The word array.\n\t         *\n\t         * @return {string} The Latin1 string.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var latin1String = CryptoJS.enc.Latin1.stringify(wordArray);\n\t         */\n\t        stringify: function (wordArray) {\n\t            // Shortcuts\n\t            var words = wordArray.words;\n\t            var sigBytes = wordArray.sigBytes;\n\n\t            // Convert\n\t            var latin1Chars = [];\n\t            for (var i = 0; i < sigBytes; i++) {\n\t                var bite = (words[i >>> 2] >>> (24 - (i % 4) * 8)) & 0xff;\n\t                latin1Chars.push(String.fromCharCode(bite));\n\t            }\n\n\t            return latin1Chars.join('');\n\t        },\n\n\t        /**\n\t         * Converts a Latin1 string to a word array.\n\t         *\n\t         * @param {string} latin1Str The Latin1 string.\n\t         *\n\t         * @return {WordArray} The word array.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var wordArray = CryptoJS.enc.Latin1.parse(latin1String);\n\t         */\n\t        parse: function (latin1Str) {\n\t            // Shortcut\n\t            var latin1StrLength = latin1Str.length;\n\n\t            // Convert\n\t            var words = [];\n\t            for (var i = 0; i < latin1StrLength; i++) {\n\t                words[i >>> 2] |= (latin1Str.charCodeAt(i) & 0xff) << (24 - (i % 4) * 8);\n\t            }\n\n\t            return new WordArray.init(words, latin1StrLength);\n\t        }\n\t    };\n\n\t    /**\n\t     * UTF-8 encoding strategy.\n\t     */\n\t    var Utf8 = C_enc.Utf8 = {\n\t        /**\n\t         * Converts a word array to a UTF-8 string.\n\t         *\n\t         * @param {WordArray} wordArray The word array.\n\t         *\n\t         * @return {string} The UTF-8 string.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var utf8String = CryptoJS.enc.Utf8.stringify(wordArray);\n\t         */\n\t        stringify: function (wordArray) {\n\t            try {\n\t                return decodeURIComponent(escape(Latin1.stringify(wordArray)));\n\t            } catch (e) {\n\t                throw new Error('Malformed UTF-8 data');\n\t            }\n\t        },\n\n\t        /**\n\t         * Converts a UTF-8 string to a word array.\n\t         *\n\t         * @param {string} utf8Str The UTF-8 string.\n\t         *\n\t         * @return {WordArray} The word array.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var wordArray = CryptoJS.enc.Utf8.parse(utf8String);\n\t         */\n\t        parse: function (utf8Str) {\n\t            return Latin1.parse(unescape(encodeURIComponent(utf8Str)));\n\t        }\n\t    };\n\n\t    /**\n\t     * Abstract buffered block algorithm template.\n\t     *\n\t     * The property blockSize must be implemented in a concrete subtype.\n\t     *\n\t     * @property {number} _minBufferSize The number of blocks that should be kept unprocessed in the buffer. Default: 0\n\t     */\n\t    var BufferedBlockAlgorithm = C_lib.BufferedBlockAlgorithm = Base.extend({\n\t        /**\n\t         * Resets this block algorithm's data buffer to its initial state.\n\t         *\n\t         * @example\n\t         *\n\t         *     bufferedBlockAlgorithm.reset();\n\t         */\n\t        reset: function () {\n\t            // Initial values\n\t            this._data = new WordArray.init();\n\t            this._nDataBytes = 0;\n\t        },\n\n\t        /**\n\t         * Adds new data to this block algorithm's buffer.\n\t         *\n\t         * @param {WordArray|string} data The data to append. Strings are converted to a WordArray using UTF-8.\n\t         *\n\t         * @example\n\t         *\n\t         *     bufferedBlockAlgorithm._append('data');\n\t         *     bufferedBlockAlgorithm._append(wordArray);\n\t         */\n\t        _append: function (data) {\n\t            // Convert string to WordArray, else assume WordArray already\n\t            if (typeof data == 'string') {\n\t                data = Utf8.parse(data);\n\t            }\n\n\t            // Append\n\t            this._data.concat(data);\n\t            this._nDataBytes += data.sigBytes;\n\t        },\n\n\t        /**\n\t         * Processes available data blocks.\n\t         *\n\t         * This method invokes _doProcessBlock(offset), which must be implemented by a concrete subtype.\n\t         *\n\t         * @param {boolean} doFlush Whether all blocks and partial blocks should be processed.\n\t         *\n\t         * @return {WordArray} The processed data.\n\t         *\n\t         * @example\n\t         *\n\t         *     var processedData = bufferedBlockAlgorithm._process();\n\t         *     var processedData = bufferedBlockAlgorithm._process(!!'flush');\n\t         */\n\t        _process: function (doFlush) {\n\t            // Shortcuts\n\t            var data = this._data;\n\t            var dataWords = data.words;\n\t            var dataSigBytes = data.sigBytes;\n\t            var blockSize = this.blockSize;\n\t            var blockSizeBytes = blockSize * 4;\n\n\t            // Count blocks ready\n\t            var nBlocksReady = dataSigBytes / blockSizeBytes;\n\t            if (doFlush) {\n\t                // Round up to include partial blocks\n\t                nBlocksReady = Math.ceil(nBlocksReady);\n\t            } else {\n\t                // Round down to include only full blocks,\n\t                // less the number of blocks that must remain in the buffer\n\t                nBlocksReady = Math.max((nBlocksReady | 0) - this._minBufferSize, 0);\n\t            }\n\n\t            // Count words ready\n\t            var nWordsReady = nBlocksReady * blockSize;\n\n\t            // Count bytes ready\n\t            var nBytesReady = Math.min(nWordsReady * 4, dataSigBytes);\n\n\t            // Process blocks\n\t            if (nWordsReady) {\n\t                for (var offset = 0; offset < nWordsReady; offset += blockSize) {\n\t                    // Perform concrete-algorithm logic\n\t                    this._doProcessBlock(dataWords, offset);\n\t                }\n\n\t                // Remove processed words\n\t                var processedWords = dataWords.splice(0, nWordsReady);\n\t                data.sigBytes -= nBytesReady;\n\t            }\n\n\t            // Return processed words\n\t            return new WordArray.init(processedWords, nBytesReady);\n\t        },\n\n\t        /**\n\t         * Creates a copy of this object.\n\t         *\n\t         * @return {Object} The clone.\n\t         *\n\t         * @example\n\t         *\n\t         *     var clone = bufferedBlockAlgorithm.clone();\n\t         */\n\t        clone: function () {\n\t            var clone = Base.clone.call(this);\n\t            clone._data = this._data.clone();\n\n\t            return clone;\n\t        },\n\n\t        _minBufferSize: 0\n\t    });\n\n\t    /**\n\t     * Abstract hasher template.\n\t     *\n\t     * @property {number} blockSize The number of 32-bit words this hasher operates on. Default: 16 (512 bits)\n\t     */\n\t    var Hasher = C_lib.Hasher = BufferedBlockAlgorithm.extend({\n\t        /**\n\t         * Configuration options.\n\t         */\n\t        cfg: Base.extend(),\n\n\t        /**\n\t         * Initializes a newly created hasher.\n\t         *\n\t         * @param {Object} cfg (Optional) The configuration options to use for this hash computation.\n\t         *\n\t         * @example\n\t         *\n\t         *     var hasher = CryptoJS.algo.SHA256.create();\n\t         */\n\t        init: function (cfg) {\n\t            // Apply config defaults\n\t            this.cfg = this.cfg.extend(cfg);\n\n\t            // Set initial values\n\t            this.reset();\n\t        },\n\n\t        /**\n\t         * Resets this hasher to its initial state.\n\t         *\n\t         * @example\n\t         *\n\t         *     hasher.reset();\n\t         */\n\t        reset: function () {\n\t            // Reset data buffer\n\t            BufferedBlockAlgorithm.reset.call(this);\n\n\t            // Perform concrete-hasher logic\n\t            this._doReset();\n\t        },\n\n\t        /**\n\t         * Updates this hasher with a message.\n\t         *\n\t         * @param {WordArray|string} messageUpdate The message to append.\n\t         *\n\t         * @return {Hasher} This hasher.\n\t         *\n\t         * @example\n\t         *\n\t         *     hasher.update('message');\n\t         *     hasher.update(wordArray);\n\t         */\n\t        update: function (messageUpdate) {\n\t            // Append\n\t            this._append(messageUpdate);\n\n\t            // Update the hash\n\t            this._process();\n\n\t            // Chainable\n\t            return this;\n\t        },\n\n\t        /**\n\t         * Finalizes the hash computation.\n\t         * Note that the finalize operation is effectively a destructive, read-once operation.\n\t         *\n\t         * @param {WordArray|string} messageUpdate (Optional) A final message update.\n\t         *\n\t         * @return {WordArray} The hash.\n\t         *\n\t         * @example\n\t         *\n\t         *     var hash = hasher.finalize();\n\t         *     var hash = hasher.finalize('message');\n\t         *     var hash = hasher.finalize(wordArray);\n\t         */\n\t        finalize: function (messageUpdate) {\n\t            // Final message update\n\t            if (messageUpdate) {\n\t                this._append(messageUpdate);\n\t            }\n\n\t            // Perform concrete-hasher logic\n\t            var hash = this._doFinalize();\n\n\t            return hash;\n\t        },\n\n\t        blockSize: 512/32,\n\n\t        /**\n\t         * Creates a shortcut function to a hasher's object interface.\n\t         *\n\t         * @param {Hasher} hasher The hasher to create a helper for.\n\t         *\n\t         * @return {Function} The shortcut function.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var SHA256 = CryptoJS.lib.Hasher._createHelper(CryptoJS.algo.SHA256);\n\t         */\n\t        _createHelper: function (hasher) {\n\t            return function (message, cfg) {\n\t                return new hasher.init(cfg).finalize(message);\n\t            };\n\t        },\n\n\t        /**\n\t         * Creates a shortcut function to the HMAC's object interface.\n\t         *\n\t         * @param {Hasher} hasher The hasher to use in this HMAC helper.\n\t         *\n\t         * @return {Function} The shortcut function.\n\t         *\n\t         * @static\n\t         *\n\t         * @example\n\t         *\n\t         *     var HmacSHA256 = CryptoJS.lib.Hasher._createHmacHelper(CryptoJS.algo.SHA256);\n\t         */\n\t        _createHmacHelper: function (hasher) {\n\t            return function (message, key) {\n\t                return new C_algo.HMAC.init(hasher, key).finalize(message);\n\t            };\n\t        }\n\t    });\n\n\t    /**\n\t     * Algorithm namespace.\n\t     */\n\t    var C_algo = C.algo = {};\n\n\t    return C;\n\t}(Math));\n\n\n\treturn CryptoJS;\n\n}));",";(function (root, factory) {\n\tif (typeof exports === \"object\") {\n\t\t// CommonJS\n\t\tmodule.exports = exports = factory(require(\"./core\"));\n\t}\n\telse if (typeof define === \"function\" && define.amd) {\n\t\t// AMD\n\t\tdefine([\"./core\"], factory);\n\t}\n\telse {\n\t\t// Global (browser)\n\t\tfactory(root.CryptoJS);\n\t}\n}(this, function (CryptoJS) {\n\n\t(function (Math) {\n\t    // Shortcuts\n\t    var C = CryptoJS;\n\t    var C_lib = C.lib;\n\t    var WordArray = C_lib.WordArray;\n\t    var Hasher = C_lib.Hasher;\n\t    var C_algo = C.algo;\n\n\t    // Initialization and round constants tables\n\t    var H = [];\n\t    var K = [];\n\n\t    // Compute constants\n\t    (function () {\n\t        function isPrime(n) {\n\t            var sqrtN = Math.sqrt(n);\n\t            for (var factor = 2; factor <= sqrtN; factor++) {\n\t                if (!(n % factor)) {\n\t                    return false;\n\t                }\n\t            }\n\n\t            return true;\n\t        }\n\n\t        function getFractionalBits(n) {\n\t            return ((n - (n | 0)) * 0x100000000) | 0;\n\t        }\n\n\t        var n = 2;\n\t        var nPrime = 0;\n\t        while (nPrime < 64) {\n\t            if (isPrime(n)) {\n\t                if (nPrime < 8) {\n\t                    H[nPrime] = getFractionalBits(Math.pow(n, 1 / 2));\n\t                }\n\t                K[nPrime] = getFractionalBits(Math.pow(n, 1 / 3));\n\n\t                nPrime++;\n\t            }\n\n\t            n++;\n\t        }\n\t    }());\n\n\t    // Reusable object\n\t    var W = [];\n\n\t    /**\n\t     * SHA-256 hash algorithm.\n\t     */\n\t    var SHA256 = C_algo.SHA256 = Hasher.extend({\n\t        _doReset: function () {\n\t            this._hash = new WordArray.init(H.slice(0));\n\t        },\n\n\t        _doProcessBlock: function (M, offset) {\n\t            // Shortcut\n\t            var H = this._hash.words;\n\n\t            // Working variables\n\t            var a = H[0];\n\t            var b = H[1];\n\t            var c = H[2];\n\t            var d = H[3];\n\t            var e = H[4];\n\t            var f = H[5];\n\t            var g = H[6];\n\t            var h = H[7];\n\n\t            // Computation\n\t            for (var i = 0; i < 64; i++) {\n\t                if (i < 16) {\n\t                    W[i] = M[offset + i] | 0;\n\t                } else {\n\t                    var gamma0x = W[i - 15];\n\t                    var gamma0  = ((gamma0x << 25) | (gamma0x >>> 7))  ^\n\t                                  ((gamma0x << 14) | (gamma0x >>> 18)) ^\n\t                                   (gamma0x >>> 3);\n\n\t                    var gamma1x = W[i - 2];\n\t                    var gamma1  = ((gamma1x << 15) | (gamma1x >>> 17)) ^\n\t                                  ((gamma1x << 13) | (gamma1x >>> 19)) ^\n\t                                   (gamma1x >>> 10);\n\n\t                    W[i] = gamma0 + W[i - 7] + gamma1 + W[i - 16];\n\t                }\n\n\t                var ch  = (e & f) ^ (~e & g);\n\t                var maj = (a & b) ^ (a & c) ^ (b & c);\n\n\t                var sigma0 = ((a << 30) | (a >>> 2)) ^ ((a << 19) | (a >>> 13)) ^ ((a << 10) | (a >>> 22));\n\t                var sigma1 = ((e << 26) | (e >>> 6)) ^ ((e << 21) | (e >>> 11)) ^ ((e << 7)  | (e >>> 25));\n\n\t                var t1 = h + sigma1 + ch + K[i] + W[i];\n\t                var t2 = sigma0 + maj;\n\n\t                h = g;\n\t                g = f;\n\t                f = e;\n\t                e = (d + t1) | 0;\n\t                d = c;\n\t                c = b;\n\t                b = a;\n\t                a = (t1 + t2) | 0;\n\t            }\n\n\t            // Intermediate hash value\n\t            H[0] = (H[0] + a) | 0;\n\t            H[1] = (H[1] + b) | 0;\n\t            H[2] = (H[2] + c) | 0;\n\t            H[3] = (H[3] + d) | 0;\n\t            H[4] = (H[4] + e) | 0;\n\t            H[5] = (H[5] + f) | 0;\n\t            H[6] = (H[6] + g) | 0;\n\t            H[7] = (H[7] + h) | 0;\n\t        },\n\n\t        _doFinalize: function () {\n\t            // Shortcuts\n\t            var data = this._data;\n\t            var dataWords = data.words;\n\n\t            var nBitsTotal = this._nDataBytes * 8;\n\t            var nBitsLeft = data.sigBytes * 8;\n\n\t            // Add padding\n\t            dataWords[nBitsLeft >>> 5] |= 0x80 << (24 - nBitsLeft % 32);\n\t            dataWords[(((nBitsLeft + 64) >>> 9) << 4) + 14] = Math.floor(nBitsTotal / 0x100000000);\n\t            dataWords[(((nBitsLeft + 64) >>> 9) << 4) + 15] = nBitsTotal;\n\t            data.sigBytes = dataWords.length * 4;\n\n\t            // Hash final blocks\n\t            this._process();\n\n\t            // Return final computed hash\n\t            return this._hash;\n\t        },\n\n\t        clone: function () {\n\t            var clone = Hasher.clone.call(this);\n\t            clone._hash = this._hash.clone();\n\n\t            return clone;\n\t        }\n\t    });\n\n\t    /**\n\t     * Shortcut function to the hasher's object interface.\n\t     *\n\t     * @param {WordArray|string} message The message to hash.\n\t     *\n\t     * @return {WordArray} The hash.\n\t     *\n\t     * @static\n\t     *\n\t     * @example\n\t     *\n\t     *     var hash = CryptoJS.SHA256('message');\n\t     *     var hash = CryptoJS.SHA256(wordArray);\n\t     */\n\t    C.SHA256 = Hasher._createHelper(SHA256);\n\n\t    /**\n\t     * Shortcut function to the HMAC's object interface.\n\t     *\n\t     * @param {WordArray|string} message The message to hash.\n\t     * @param {WordArray|string} key The secret key.\n\t     *\n\t     * @return {WordArray} The HMAC.\n\t     *\n\t     * @static\n\t     *\n\t     * @example\n\t     *\n\t     *     var hmac = CryptoJS.HmacSHA256(message, key);\n\t     */\n\t    C.HmacSHA256 = Hasher._createHmacHelper(SHA256);\n\t}(Math));\n\n\n\treturn CryptoJS.SHA256;\n\n}));","(function(){\n\n    // Copyright (c) 2005  Tom Wu\n    // All Rights Reserved.\n    // See \"LICENSE\" for details.\n\n    // Basic JavaScript BN library - subset useful for RSA encryption.\n\n    // Bits per digit\n    var dbits;\n\n    // JavaScript engine analysis\n    var canary = 0xdeadbeefcafe;\n    var j_lm = ((canary&0xffffff)==0xefcafe);\n\n    // (public) Constructor\n    function BigInteger(a,b,c) {\n      if(a != null)\n        if(\"number\" == typeof a) this.fromNumber(a,b,c);\n        else if(b == null && \"string\" != typeof a) this.fromString(a,256);\n        else this.fromString(a,b);\n    }\n\n    // return new, unset BigInteger\n    function nbi() { return new BigInteger(null); }\n\n    // am: Compute w_j += (x*this_i), propagate carries,\n    // c is initial carry, returns final carry.\n    // c < 3*dvalue, x < 2*dvalue, this_i < dvalue\n    // We need to select the fastest one that works in this environment.\n\n    // am1: use a single mult and divide to get the high bits,\n    // max digit bits should be 26 because\n    // max internal value = 2*dvalue^2-2*dvalue (< 2^53)\n    function am1(i,x,w,j,c,n) {\n      while(--n >= 0) {\n        var v = x*this[i++]+w[j]+c;\n        c = Math.floor(v/0x4000000);\n        w[j++] = v&0x3ffffff;\n      }\n      return c;\n    }\n    // am2 avoids a big mult-and-extract completely.\n    // Max digit bits should be <= 30 because we do bitwise ops\n    // on values up to 2*hdvalue^2-hdvalue-1 (< 2^31)\n    function am2(i,x,w,j,c,n) {\n      var xl = x&0x7fff, xh = x>>15;\n      while(--n >= 0) {\n        var l = this[i]&0x7fff;\n        var h = this[i++]>>15;\n        var m = xh*l+h*xl;\n        l = xl*l+((m&0x7fff)<<15)+w[j]+(c&0x3fffffff);\n        c = (l>>>30)+(m>>>15)+xh*h+(c>>>30);\n        w[j++] = l&0x3fffffff;\n      }\n      return c;\n    }\n    // Alternately, set max digit bits to 28 since some\n    // browsers slow down when dealing with 32-bit numbers.\n    function am3(i,x,w,j,c,n) {\n      var xl = x&0x3fff, xh = x>>14;\n      while(--n >= 0) {\n        var l = this[i]&0x3fff;\n        var h = this[i++]>>14;\n        var m = xh*l+h*xl;\n        l = xl*l+((m&0x3fff)<<14)+w[j]+c;\n        c = (l>>28)+(m>>14)+xh*h;\n        w[j++] = l&0xfffffff;\n      }\n      return c;\n    }\n    var inBrowser = typeof navigator !== \"undefined\";\n    if(inBrowser && j_lm && (navigator.appName == \"Microsoft Internet Explorer\")) {\n      BigInteger.prototype.am = am2;\n      dbits = 30;\n    }\n    else if(inBrowser && j_lm && (navigator.appName != \"Netscape\")) {\n      BigInteger.prototype.am = am1;\n      dbits = 26;\n    }\n    else { // Mozilla/Netscape seems to prefer am3\n      BigInteger.prototype.am = am3;\n      dbits = 28;\n    }\n\n    BigInteger.prototype.DB = dbits;\n    BigInteger.prototype.DM = ((1<<dbits)-1);\n    BigInteger.prototype.DV = (1<<dbits);\n\n    var BI_FP = 52;\n    BigInteger.prototype.FV = Math.pow(2,BI_FP);\n    BigInteger.prototype.F1 = BI_FP-dbits;\n    BigInteger.prototype.F2 = 2*dbits-BI_FP;\n\n    // Digit conversions\n    var BI_RM = \"0123456789abcdefghijklmnopqrstuvwxyz\";\n    var BI_RC = new Array();\n    var rr,vv;\n    rr = \"0\".charCodeAt(0);\n    for(vv = 0; vv <= 9; ++vv) BI_RC[rr++] = vv;\n    rr = \"a\".charCodeAt(0);\n    for(vv = 10; vv < 36; ++vv) BI_RC[rr++] = vv;\n    rr = \"A\".charCodeAt(0);\n    for(vv = 10; vv < 36; ++vv) BI_RC[rr++] = vv;\n\n    function int2char(n) { return BI_RM.charAt(n); }\n    function intAt(s,i) {\n      var c = BI_RC[s.charCodeAt(i)];\n      return (c==null)?-1:c;\n    }\n\n    // (protected) copy this to r\n    function bnpCopyTo(r) {\n      for(var i = this.t-1; i >= 0; --i) r[i] = this[i];\n      r.t = this.t;\n      r.s = this.s;\n    }\n\n    // (protected) set from integer value x, -DV <= x < DV\n    function bnpFromInt(x) {\n      this.t = 1;\n      this.s = (x<0)?-1:0;\n      if(x > 0) this[0] = x;\n      else if(x < -1) this[0] = x+this.DV;\n      else this.t = 0;\n    }\n\n    // return bigint initialized to value\n    function nbv(i) { var r = nbi(); r.fromInt(i); return r; }\n\n    // (protected) set from string and radix\n    function bnpFromString(s,b) {\n      var k;\n      if(b == 16) k = 4;\n      else if(b == 8) k = 3;\n      else if(b == 256) k = 8; // byte array\n      else if(b == 2) k = 1;\n      else if(b == 32) k = 5;\n      else if(b == 4) k = 2;\n      else { this.fromRadix(s,b); return; }\n      this.t = 0;\n      this.s = 0;\n      var i = s.length, mi = false, sh = 0;\n      while(--i >= 0) {\n        var x = (k==8)?s[i]&0xff:intAt(s,i);\n        if(x < 0) {\n          if(s.charAt(i) == \"-\") mi = true;\n          continue;\n        }\n        mi = false;\n        if(sh == 0)\n          this[this.t++] = x;\n        else if(sh+k > this.DB) {\n          this[this.t-1] |= (x&((1<<(this.DB-sh))-1))<<sh;\n          this[this.t++] = (x>>(this.DB-sh));\n        }\n        else\n          this[this.t-1] |= x<<sh;\n        sh += k;\n        if(sh >= this.DB) sh -= this.DB;\n      }\n      if(k == 8 && (s[0]&0x80) != 0) {\n        this.s = -1;\n        if(sh > 0) this[this.t-1] |= ((1<<(this.DB-sh))-1)<<sh;\n      }\n      this.clamp();\n      if(mi) BigInteger.ZERO.subTo(this,this);\n    }\n\n    // (protected) clamp off excess high words\n    function bnpClamp() {\n      var c = this.s&this.DM;\n      while(this.t > 0 && this[this.t-1] == c) --this.t;\n    }\n\n    // (public) return string representation in given radix\n    function bnToString(b) {\n      if(this.s < 0) return \"-\"+this.negate().toString(b);\n      var k;\n      if(b == 16) k = 4;\n      else if(b == 8) k = 3;\n      else if(b == 2) k = 1;\n      else if(b == 32) k = 5;\n      else if(b == 4) k = 2;\n      else return this.toRadix(b);\n      var km = (1<<k)-1, d, m = false, r = \"\", i = this.t;\n      var p = this.DB-(i*this.DB)%k;\n      if(i-- > 0) {\n        if(p < this.DB && (d = this[i]>>p) > 0) { m = true; r = int2char(d); }\n        while(i >= 0) {\n          if(p < k) {\n            d = (this[i]&((1<<p)-1))<<(k-p);\n            d |= this[--i]>>(p+=this.DB-k);\n          }\n          else {\n            d = (this[i]>>(p-=k))&km;\n            if(p <= 0) { p += this.DB; --i; }\n          }\n          if(d > 0) m = true;\n          if(m) r += int2char(d);\n        }\n      }\n      return m?r:\"0\";\n    }\n\n    // (public) -this\n    function bnNegate() { var r = nbi(); BigInteger.ZERO.subTo(this,r); return r; }\n\n    // (public) |this|\n    function bnAbs() { return (this.s<0)?this.negate():this; }\n\n    // (public) return + if this > a, - if this < a, 0 if equal\n    function bnCompareTo(a) {\n      var r = this.s-a.s;\n      if(r != 0) return r;\n      var i = this.t;\n      r = i-a.t;\n      if(r != 0) return (this.s<0)?-r:r;\n      while(--i >= 0) if((r=this[i]-a[i]) != 0) return r;\n      return 0;\n    }\n\n    // returns bit length of the integer x\n    function nbits(x) {\n      var r = 1, t;\n      if((t=x>>>16) != 0) { x = t; r += 16; }\n      if((t=x>>8) != 0) { x = t; r += 8; }\n      if((t=x>>4) != 0) { x = t; r += 4; }\n      if((t=x>>2) != 0) { x = t; r += 2; }\n      if((t=x>>1) != 0) { x = t; r += 1; }\n      return r;\n    }\n\n    // (public) return the number of bits in \"this\"\n    function bnBitLength() {\n      if(this.t <= 0) return 0;\n      return this.DB*(this.t-1)+nbits(this[this.t-1]^(this.s&this.DM));\n    }\n\n    // (protected) r = this << n*DB\n    function bnpDLShiftTo(n,r) {\n      var i;\n      for(i = this.t-1; i >= 0; --i) r[i+n] = this[i];\n      for(i = n-1; i >= 0; --i) r[i] = 0;\n      r.t = this.t+n;\n      r.s = this.s;\n    }\n\n    // (protected) r = this >> n*DB\n    function bnpDRShiftTo(n,r) {\n      for(var i = n; i < this.t; ++i) r[i-n] = this[i];\n      r.t = Math.max(this.t-n,0);\n      r.s = this.s;\n    }\n\n    // (protected) r = this << n\n    function bnpLShiftTo(n,r) {\n      var bs = n%this.DB;\n      var cbs = this.DB-bs;\n      var bm = (1<<cbs)-1;\n      var ds = Math.floor(n/this.DB), c = (this.s<<bs)&this.DM, i;\n      for(i = this.t-1; i >= 0; --i) {\n        r[i+ds+1] = (this[i]>>cbs)|c;\n        c = (this[i]&bm)<<bs;\n      }\n      for(i = ds-1; i >= 0; --i) r[i] = 0;\n      r[ds] = c;\n      r.t = this.t+ds+1;\n      r.s = this.s;\n      r.clamp();\n    }\n\n    // (protected) r = this >> n\n    function bnpRShiftTo(n,r) {\n      r.s = this.s;\n      var ds = Math.floor(n/this.DB);\n      if(ds >= this.t) { r.t = 0; return; }\n      var bs = n%this.DB;\n      var cbs = this.DB-bs;\n      var bm = (1<<bs)-1;\n      r[0] = this[ds]>>bs;\n      for(var i = ds+1; i < this.t; ++i) {\n        r[i-ds-1] |= (this[i]&bm)<<cbs;\n        r[i-ds] = this[i]>>bs;\n      }\n      if(bs > 0) r[this.t-ds-1] |= (this.s&bm)<<cbs;\n      r.t = this.t-ds;\n      r.clamp();\n    }\n\n    // (protected) r = this - a\n    function bnpSubTo(a,r) {\n      var i = 0, c = 0, m = Math.min(a.t,this.t);\n      while(i < m) {\n        c += this[i]-a[i];\n        r[i++] = c&this.DM;\n        c >>= this.DB;\n      }\n      if(a.t < this.t) {\n        c -= a.s;\n        while(i < this.t) {\n          c += this[i];\n          r[i++] = c&this.DM;\n          c >>= this.DB;\n        }\n        c += this.s;\n      }\n      else {\n        c += this.s;\n        while(i < a.t) {\n          c -= a[i];\n          r[i++] = c&this.DM;\n          c >>= this.DB;\n        }\n        c -= a.s;\n      }\n      r.s = (c<0)?-1:0;\n      if(c < -1) r[i++] = this.DV+c;\n      else if(c > 0) r[i++] = c;\n      r.t = i;\n      r.clamp();\n    }\n\n    // (protected) r = this * a, r != this,a (HAC 14.12)\n    // \"this\" should be the larger one if appropriate.\n    function bnpMultiplyTo(a,r) {\n      var x = this.abs(), y = a.abs();\n      var i = x.t;\n      r.t = i+y.t;\n      while(--i >= 0) r[i] = 0;\n      for(i = 0; i < y.t; ++i) r[i+x.t] = x.am(0,y[i],r,i,0,x.t);\n      r.s = 0;\n      r.clamp();\n      if(this.s != a.s) BigInteger.ZERO.subTo(r,r);\n    }\n\n    // (protected) r = this^2, r != this (HAC 14.16)\n    function bnpSquareTo(r) {\n      var x = this.abs();\n      var i = r.t = 2*x.t;\n      while(--i >= 0) r[i] = 0;\n      for(i = 0; i < x.t-1; ++i) {\n        var c = x.am(i,x[i],r,2*i,0,1);\n        if((r[i+x.t]+=x.am(i+1,2*x[i],r,2*i+1,c,x.t-i-1)) >= x.DV) {\n          r[i+x.t] -= x.DV;\n          r[i+x.t+1] = 1;\n        }\n      }\n      if(r.t > 0) r[r.t-1] += x.am(i,x[i],r,2*i,0,1);\n      r.s = 0;\n      r.clamp();\n    }\n\n    // (protected) divide this by m, quotient and remainder to q, r (HAC 14.20)\n    // r != q, this != m.  q or r may be null.\n    function bnpDivRemTo(m,q,r) {\n      var pm = m.abs();\n      if(pm.t <= 0) return;\n      var pt = this.abs();\n      if(pt.t < pm.t) {\n        if(q != null) q.fromInt(0);\n        if(r != null) this.copyTo(r);\n        return;\n      }\n      if(r == null) r = nbi();\n      var y = nbi(), ts = this.s, ms = m.s;\n      var nsh = this.DB-nbits(pm[pm.t-1]);   // normalize modulus\n      if(nsh > 0) { pm.lShiftTo(nsh,y); pt.lShiftTo(nsh,r); }\n      else { pm.copyTo(y); pt.copyTo(r); }\n      var ys = y.t;\n      var y0 = y[ys-1];\n      if(y0 == 0) return;\n      var yt = y0*(1<<this.F1)+((ys>1)?y[ys-2]>>this.F2:0);\n      var d1 = this.FV/yt, d2 = (1<<this.F1)/yt, e = 1<<this.F2;\n      var i = r.t, j = i-ys, t = (q==null)?nbi():q;\n      y.dlShiftTo(j,t);\n      if(r.compareTo(t) >= 0) {\n        r[r.t++] = 1;\n        r.subTo(t,r);\n      }\n      BigInteger.ONE.dlShiftTo(ys,t);\n      t.subTo(y,y);  // \"negative\" y so we can replace sub with am later\n      while(y.t < ys) y[y.t++] = 0;\n      while(--j >= 0) {\n        // Estimate quotient digit\n        var qd = (r[--i]==y0)?this.DM:Math.floor(r[i]*d1+(r[i-1]+e)*d2);\n        if((r[i]+=y.am(0,qd,r,j,0,ys)) < qd) {   // Try it out\n          y.dlShiftTo(j,t);\n          r.subTo(t,r);\n          while(r[i] < --qd) r.subTo(t,r);\n        }\n      }\n      if(q != null) {\n        r.drShiftTo(ys,q);\n        if(ts != ms) BigInteger.ZERO.subTo(q,q);\n      }\n      r.t = ys;\n      r.clamp();\n      if(nsh > 0) r.rShiftTo(nsh,r); // Denormalize remainder\n      if(ts < 0) BigInteger.ZERO.subTo(r,r);\n    }\n\n    // (public) this mod a\n    function bnMod(a) {\n      var r = nbi();\n      this.abs().divRemTo(a,null,r);\n      if(this.s < 0 && r.compareTo(BigInteger.ZERO) > 0) a.subTo(r,r);\n      return r;\n    }\n\n    // Modular reduction using \"classic\" algorithm\n    function Classic(m) { this.m = m; }\n    function cConvert(x) {\n      if(x.s < 0 || x.compareTo(this.m) >= 0) return x.mod(this.m);\n      else return x;\n    }\n    function cRevert(x) { return x; }\n    function cReduce(x) { x.divRemTo(this.m,null,x); }\n    function cMulTo(x,y,r) { x.multiplyTo(y,r); this.reduce(r); }\n    function cSqrTo(x,r) { x.squareTo(r); this.reduce(r); }\n\n    Classic.prototype.convert = cConvert;\n    Classic.prototype.revert = cRevert;\n    Classic.prototype.reduce = cReduce;\n    Classic.prototype.mulTo = cMulTo;\n    Classic.prototype.sqrTo = cSqrTo;\n\n    // (protected) return \"-1/this % 2^DB\"; useful for Mont. reduction\n    // justification:\n    //         xy == 1 (mod m)\n    //         xy =  1+km\n    //   xy(2-xy) = (1+km)(1-km)\n    // x[y(2-xy)] = 1-k^2m^2\n    // x[y(2-xy)] == 1 (mod m^2)\n    // if y is 1/x mod m, then y(2-xy) is 1/x mod m^2\n    // should reduce x and y(2-xy) by m^2 at each step to keep size bounded.\n    // JS multiply \"overflows\" differently from C/C++, so care is needed here.\n    function bnpInvDigit() {\n      if(this.t < 1) return 0;\n      var x = this[0];\n      if((x&1) == 0) return 0;\n      var y = x&3;       // y == 1/x mod 2^2\n      y = (y*(2-(x&0xf)*y))&0xf; // y == 1/x mod 2^4\n      y = (y*(2-(x&0xff)*y))&0xff;   // y == 1/x mod 2^8\n      y = (y*(2-(((x&0xffff)*y)&0xffff)))&0xffff;    // y == 1/x mod 2^16\n      // last step - calculate inverse mod DV directly;\n      // assumes 16 < DB <= 32 and assumes ability to handle 48-bit ints\n      y = (y*(2-x*y%this.DV))%this.DV;       // y == 1/x mod 2^dbits\n      // we really want the negative inverse, and -DV < y < DV\n      return (y>0)?this.DV-y:-y;\n    }\n\n    // Montgomery reduction\n    function Montgomery(m) {\n      this.m = m;\n      this.mp = m.invDigit();\n      this.mpl = this.mp&0x7fff;\n      this.mph = this.mp>>15;\n      this.um = (1<<(m.DB-15))-1;\n      this.mt2 = 2*m.t;\n    }\n\n    // xR mod m\n    function montConvert(x) {\n      var r = nbi();\n      x.abs().dlShiftTo(this.m.t,r);\n      r.divRemTo(this.m,null,r);\n      if(x.s < 0 && r.compareTo(BigInteger.ZERO) > 0) this.m.subTo(r,r);\n      return r;\n    }\n\n    // x/R mod m\n    function montRevert(x) {\n      var r = nbi();\n      x.copyTo(r);\n      this.reduce(r);\n      return r;\n    }\n\n    // x = x/R mod m (HAC 14.32)\n    function montReduce(x) {\n      while(x.t <= this.mt2) // pad x so am has enough room later\n        x[x.t++] = 0;\n      for(var i = 0; i < this.m.t; ++i) {\n        // faster way of calculating u0 = x[i]*mp mod DV\n        var j = x[i]&0x7fff;\n        var u0 = (j*this.mpl+(((j*this.mph+(x[i]>>15)*this.mpl)&this.um)<<15))&x.DM;\n        // use am to combine the multiply-shift-add into one call\n        j = i+this.m.t;\n        x[j] += this.m.am(0,u0,x,i,0,this.m.t);\n        // propagate carry\n        while(x[j] >= x.DV) { x[j] -= x.DV; x[++j]++; }\n      }\n      x.clamp();\n      x.drShiftTo(this.m.t,x);\n      if(x.compareTo(this.m) >= 0) x.subTo(this.m,x);\n    }\n\n    // r = \"x^2/R mod m\"; x != r\n    function montSqrTo(x,r) { x.squareTo(r); this.reduce(r); }\n\n    // r = \"xy/R mod m\"; x,y != r\n    function montMulTo(x,y,r) { x.multiplyTo(y,r); this.reduce(r); }\n\n    Montgomery.prototype.convert = montConvert;\n    Montgomery.prototype.revert = montRevert;\n    Montgomery.prototype.reduce = montReduce;\n    Montgomery.prototype.mulTo = montMulTo;\n    Montgomery.prototype.sqrTo = montSqrTo;\n\n    // (protected) true iff this is even\n    function bnpIsEven() { return ((this.t>0)?(this[0]&1):this.s) == 0; }\n\n    // (protected) this^e, e < 2^32, doing sqr and mul with \"r\" (HAC 14.79)\n    function bnpExp(e,z) {\n      if(e > 0xffffffff || e < 1) return BigInteger.ONE;\n      var r = nbi(), r2 = nbi(), g = z.convert(this), i = nbits(e)-1;\n      g.copyTo(r);\n      while(--i >= 0) {\n        z.sqrTo(r,r2);\n        if((e&(1<<i)) > 0) z.mulTo(r2,g,r);\n        else { var t = r; r = r2; r2 = t; }\n      }\n      return z.revert(r);\n    }\n\n    // (public) this^e % m, 0 <= e < 2^32\n    function bnModPowInt(e,m) {\n      var z;\n      if(e < 256 || m.isEven()) z = new Classic(m); else z = new Montgomery(m);\n      return this.exp(e,z);\n    }\n\n    // protected\n    BigInteger.prototype.copyTo = bnpCopyTo;\n    BigInteger.prototype.fromInt = bnpFromInt;\n    BigInteger.prototype.fromString = bnpFromString;\n    BigInteger.prototype.clamp = bnpClamp;\n    BigInteger.prototype.dlShiftTo = bnpDLShiftTo;\n    BigInteger.prototype.drShiftTo = bnpDRShiftTo;\n    BigInteger.prototype.lShiftTo = bnpLShiftTo;\n    BigInteger.prototype.rShiftTo = bnpRShiftTo;\n    BigInteger.prototype.subTo = bnpSubTo;\n    BigInteger.prototype.multiplyTo = bnpMultiplyTo;\n    BigInteger.prototype.squareTo = bnpSquareTo;\n    BigInteger.prototype.divRemTo = bnpDivRemTo;\n    BigInteger.prototype.invDigit = bnpInvDigit;\n    BigInteger.prototype.isEven = bnpIsEven;\n    BigInteger.prototype.exp = bnpExp;\n\n    // public\n    BigInteger.prototype.toString = bnToString;\n    BigInteger.prototype.negate = bnNegate;\n    BigInteger.prototype.abs = bnAbs;\n    BigInteger.prototype.compareTo = bnCompareTo;\n    BigInteger.prototype.bitLength = bnBitLength;\n    BigInteger.prototype.mod = bnMod;\n    BigInteger.prototype.modPowInt = bnModPowInt;\n\n    // \"constants\"\n    BigInteger.ZERO = nbv(0);\n    BigInteger.ONE = nbv(1);\n\n    // Copyright (c) 2005-2009  Tom Wu\n    // All Rights Reserved.\n    // See \"LICENSE\" for details.\n\n    // Extended JavaScript BN functions, required for RSA private ops.\n\n    // Version 1.1: new BigInteger(\"0\", 10) returns \"proper\" zero\n    // Version 1.2: square() API, isProbablePrime fix\n\n    // (public)\n    function bnClone() { var r = nbi(); this.copyTo(r); return r; }\n\n    // (public) return value as integer\n    function bnIntValue() {\n      if(this.s < 0) {\n        if(this.t == 1) return this[0]-this.DV;\n        else if(this.t == 0) return -1;\n      }\n      else if(this.t == 1) return this[0];\n      else if(this.t == 0) return 0;\n      // assumes 16 < DB < 32\n      return ((this[1]&((1<<(32-this.DB))-1))<<this.DB)|this[0];\n    }\n\n    // (public) return value as byte\n    function bnByteValue() { return (this.t==0)?this.s:(this[0]<<24)>>24; }\n\n    // (public) return value as short (assumes DB>=16)\n    function bnShortValue() { return (this.t==0)?this.s:(this[0]<<16)>>16; }\n\n    // (protected) return x s.t. r^x < DV\n    function bnpChunkSize(r) { return Math.floor(Math.LN2*this.DB/Math.log(r)); }\n\n    // (public) 0 if this == 0, 1 if this > 0\n    function bnSigNum() {\n      if(this.s < 0) return -1;\n      else if(this.t <= 0 || (this.t == 1 && this[0] <= 0)) return 0;\n      else return 1;\n    }\n\n    // (protected) convert to radix string\n    function bnpToRadix(b) {\n      if(b == null) b = 10;\n      if(this.signum() == 0 || b < 2 || b > 36) return \"0\";\n      var cs = this.chunkSize(b);\n      var a = Math.pow(b,cs);\n      var d = nbv(a), y = nbi(), z = nbi(), r = \"\";\n      this.divRemTo(d,y,z);\n      while(y.signum() > 0) {\n        r = (a+z.intValue()).toString(b).substr(1) + r;\n        y.divRemTo(d,y,z);\n      }\n      return z.intValue().toString(b) + r;\n    }\n\n    // (protected) convert from radix string\n    function bnpFromRadix(s,b) {\n      this.fromInt(0);\n      if(b == null) b = 10;\n      var cs = this.chunkSize(b);\n      var d = Math.pow(b,cs), mi = false, j = 0, w = 0;\n      for(var i = 0; i < s.length; ++i) {\n        var x = intAt(s,i);\n        if(x < 0) {\n          if(s.charAt(i) == \"-\" && this.signum() == 0) mi = true;\n          continue;\n        }\n        w = b*w+x;\n        if(++j >= cs) {\n          this.dMultiply(d);\n          this.dAddOffset(w,0);\n          j = 0;\n          w = 0;\n        }\n      }\n      if(j > 0) {\n        this.dMultiply(Math.pow(b,j));\n        this.dAddOffset(w,0);\n      }\n      if(mi) BigInteger.ZERO.subTo(this,this);\n    }\n\n    // (protected) alternate constructor\n    function bnpFromNumber(a,b,c) {\n      if(\"number\" == typeof b) {\n        // new BigInteger(int,int,RNG)\n        if(a < 2) this.fromInt(1);\n        else {\n          this.fromNumber(a,c);\n          if(!this.testBit(a-1))    // force MSB set\n            this.bitwiseTo(BigInteger.ONE.shiftLeft(a-1),op_or,this);\n          if(this.isEven()) this.dAddOffset(1,0); // force odd\n          while(!this.isProbablePrime(b)) {\n            this.dAddOffset(2,0);\n            if(this.bitLength() > a) this.subTo(BigInteger.ONE.shiftLeft(a-1),this);\n          }\n        }\n      }\n      else {\n        // new BigInteger(int,RNG)\n        var x = new Array(), t = a&7;\n        x.length = (a>>3)+1;\n        b.nextBytes(x);\n        if(t > 0) x[0] &= ((1<<t)-1); else x[0] = 0;\n        this.fromString(x,256);\n      }\n    }\n\n    // (public) convert to bigendian byte array\n    function bnToByteArray() {\n      var i = this.t, r = new Array();\n      r[0] = this.s;\n      var p = this.DB-(i*this.DB)%8, d, k = 0;\n      if(i-- > 0) {\n        if(p < this.DB && (d = this[i]>>p) != (this.s&this.DM)>>p)\n          r[k++] = d|(this.s<<(this.DB-p));\n        while(i >= 0) {\n          if(p < 8) {\n            d = (this[i]&((1<<p)-1))<<(8-p);\n            d |= this[--i]>>(p+=this.DB-8);\n          }\n          else {\n            d = (this[i]>>(p-=8))&0xff;\n            if(p <= 0) { p += this.DB; --i; }\n          }\n          if((d&0x80) != 0) d |= -256;\n          if(k == 0 && (this.s&0x80) != (d&0x80)) ++k;\n          if(k > 0 || d != this.s) r[k++] = d;\n        }\n      }\n      return r;\n    }\n\n    function bnEquals(a) { return(this.compareTo(a)==0); }\n    function bnMin(a) { return(this.compareTo(a)<0)?this:a; }\n    function bnMax(a) { return(this.compareTo(a)>0)?this:a; }\n\n    // (protected) r = this op a (bitwise)\n    function bnpBitwiseTo(a,op,r) {\n      var i, f, m = Math.min(a.t,this.t);\n      for(i = 0; i < m; ++i) r[i] = op(this[i],a[i]);\n      if(a.t < this.t) {\n        f = a.s&this.DM;\n        for(i = m; i < this.t; ++i) r[i] = op(this[i],f);\n        r.t = this.t;\n      }\n      else {\n        f = this.s&this.DM;\n        for(i = m; i < a.t; ++i) r[i] = op(f,a[i]);\n        r.t = a.t;\n      }\n      r.s = op(this.s,a.s);\n      r.clamp();\n    }\n\n    // (public) this & a\n    function op_and(x,y) { return x&y; }\n    function bnAnd(a) { var r = nbi(); this.bitwiseTo(a,op_and,r); return r; }\n\n    // (public) this | a\n    function op_or(x,y) { return x|y; }\n    function bnOr(a) { var r = nbi(); this.bitwiseTo(a,op_or,r); return r; }\n\n    // (public) this ^ a\n    function op_xor(x,y) { return x^y; }\n    function bnXor(a) { var r = nbi(); this.bitwiseTo(a,op_xor,r); return r; }\n\n    // (public) this & ~a\n    function op_andnot(x,y) { return x&~y; }\n    function bnAndNot(a) { var r = nbi(); this.bitwiseTo(a,op_andnot,r); return r; }\n\n    // (public) ~this\n    function bnNot() {\n      var r = nbi();\n      for(var i = 0; i < this.t; ++i) r[i] = this.DM&~this[i];\n      r.t = this.t;\n      r.s = ~this.s;\n      return r;\n    }\n\n    // (public) this << n\n    function bnShiftLeft(n) {\n      var r = nbi();\n      if(n < 0) this.rShiftTo(-n,r); else this.lShiftTo(n,r);\n      return r;\n    }\n\n    // (public) this >> n\n    function bnShiftRight(n) {\n      var r = nbi();\n      if(n < 0) this.lShiftTo(-n,r); else this.rShiftTo(n,r);\n      return r;\n    }\n\n    // return index of lowest 1-bit in x, x < 2^31\n    function lbit(x) {\n      if(x == 0) return -1;\n      var r = 0;\n      if((x&0xffff) == 0) { x >>= 16; r += 16; }\n      if((x&0xff) == 0) { x >>= 8; r += 8; }\n      if((x&0xf) == 0) { x >>= 4; r += 4; }\n      if((x&3) == 0) { x >>= 2; r += 2; }\n      if((x&1) == 0) ++r;\n      return r;\n    }\n\n    // (public) returns index of lowest 1-bit (or -1 if none)\n    function bnGetLowestSetBit() {\n      for(var i = 0; i < this.t; ++i)\n        if(this[i] != 0) return i*this.DB+lbit(this[i]);\n      if(this.s < 0) return this.t*this.DB;\n      return -1;\n    }\n\n    // return number of 1 bits in x\n    function cbit(x) {\n      var r = 0;\n      while(x != 0) { x &= x-1; ++r; }\n      return r;\n    }\n\n    // (public) return number of set bits\n    function bnBitCount() {\n      var r = 0, x = this.s&this.DM;\n      for(var i = 0; i < this.t; ++i) r += cbit(this[i]^x);\n      return r;\n    }\n\n    // (public) true iff nth bit is set\n    function bnTestBit(n) {\n      var j = Math.floor(n/this.DB);\n      if(j >= this.t) return(this.s!=0);\n      return((this[j]&(1<<(n%this.DB)))!=0);\n    }\n\n    // (protected) this op (1<<n)\n    function bnpChangeBit(n,op) {\n      var r = BigInteger.ONE.shiftLeft(n);\n      this.bitwiseTo(r,op,r);\n      return r;\n    }\n\n    // (public) this | (1<<n)\n    function bnSetBit(n) { return this.changeBit(n,op_or); }\n\n    // (public) this & ~(1<<n)\n    function bnClearBit(n) { return this.changeBit(n,op_andnot); }\n\n    // (public) this ^ (1<<n)\n    function bnFlipBit(n) { return this.changeBit(n,op_xor); }\n\n    // (protected) r = this + a\n    function bnpAddTo(a,r) {\n      var i = 0, c = 0, m = Math.min(a.t,this.t);\n      while(i < m) {\n        c += this[i]+a[i];\n        r[i++] = c&this.DM;\n        c >>= this.DB;\n      }\n      if(a.t < this.t) {\n        c += a.s;\n        while(i < this.t) {\n          c += this[i];\n          r[i++] = c&this.DM;\n          c >>= this.DB;\n        }\n        c += this.s;\n      }\n      else {\n        c += this.s;\n        while(i < a.t) {\n          c += a[i];\n          r[i++] = c&this.DM;\n          c >>= this.DB;\n        }\n        c += a.s;\n      }\n      r.s = (c<0)?-1:0;\n      if(c > 0) r[i++] = c;\n      else if(c < -1) r[i++] = this.DV+c;\n      r.t = i;\n      r.clamp();\n    }\n\n    // (public) this + a\n    function bnAdd(a) { var r = nbi(); this.addTo(a,r); return r; }\n\n    // (public) this - a\n    function bnSubtract(a) { var r = nbi(); this.subTo(a,r); return r; }\n\n    // (public) this * a\n    function bnMultiply(a) { var r = nbi(); this.multiplyTo(a,r); return r; }\n\n    // (public) this^2\n    function bnSquare() { var r = nbi(); this.squareTo(r); return r; }\n\n    // (public) this / a\n    function bnDivide(a) { var r = nbi(); this.divRemTo(a,r,null); return r; }\n\n    // (public) this % a\n    function bnRemainder(a) { var r = nbi(); this.divRemTo(a,null,r); return r; }\n\n    // (public) [this/a,this%a]\n    function bnDivideAndRemainder(a) {\n      var q = nbi(), r = nbi();\n      this.divRemTo(a,q,r);\n      return new Array(q,r);\n    }\n\n    // (protected) this *= n, this >= 0, 1 < n < DV\n    function bnpDMultiply(n) {\n      this[this.t] = this.am(0,n-1,this,0,0,this.t);\n      ++this.t;\n      this.clamp();\n    }\n\n    // (protected) this += n << w words, this >= 0\n    function bnpDAddOffset(n,w) {\n      if(n == 0) return;\n      while(this.t <= w) this[this.t++] = 0;\n      this[w] += n;\n      while(this[w] >= this.DV) {\n        this[w] -= this.DV;\n        if(++w >= this.t) this[this.t++] = 0;\n        ++this[w];\n      }\n    }\n\n    // A \"null\" reducer\n    function NullExp() {}\n    function nNop(x) { return x; }\n    function nMulTo(x,y,r) { x.multiplyTo(y,r); }\n    function nSqrTo(x,r) { x.squareTo(r); }\n\n    NullExp.prototype.convert = nNop;\n    NullExp.prototype.revert = nNop;\n    NullExp.prototype.mulTo = nMulTo;\n    NullExp.prototype.sqrTo = nSqrTo;\n\n    // (public) this^e\n    function bnPow(e) { return this.exp(e,new NullExp()); }\n\n    // (protected) r = lower n words of \"this * a\", a.t <= n\n    // \"this\" should be the larger one if appropriate.\n    function bnpMultiplyLowerTo(a,n,r) {\n      var i = Math.min(this.t+a.t,n);\n      r.s = 0; // assumes a,this >= 0\n      r.t = i;\n      while(i > 0) r[--i] = 0;\n      var j;\n      for(j = r.t-this.t; i < j; ++i) r[i+this.t] = this.am(0,a[i],r,i,0,this.t);\n      for(j = Math.min(a.t,n); i < j; ++i) this.am(0,a[i],r,i,0,n-i);\n      r.clamp();\n    }\n\n    // (protected) r = \"this * a\" without lower n words, n > 0\n    // \"this\" should be the larger one if appropriate.\n    function bnpMultiplyUpperTo(a,n,r) {\n      --n;\n      var i = r.t = this.t+a.t-n;\n      r.s = 0; // assumes a,this >= 0\n      while(--i >= 0) r[i] = 0;\n      for(i = Math.max(n-this.t,0); i < a.t; ++i)\n        r[this.t+i-n] = this.am(n-i,a[i],r,0,0,this.t+i-n);\n      r.clamp();\n      r.drShiftTo(1,r);\n    }\n\n    // Barrett modular reduction\n    function Barrett(m) {\n      // setup Barrett\n      this.r2 = nbi();\n      this.q3 = nbi();\n      BigInteger.ONE.dlShiftTo(2*m.t,this.r2);\n      this.mu = this.r2.divide(m);\n      this.m = m;\n    }\n\n    function barrettConvert(x) {\n      if(x.s < 0 || x.t > 2*this.m.t) return x.mod(this.m);\n      else if(x.compareTo(this.m) < 0) return x;\n      else { var r = nbi(); x.copyTo(r); this.reduce(r); return r; }\n    }\n\n    function barrettRevert(x) { return x; }\n\n    // x = x mod m (HAC 14.42)\n    function barrettReduce(x) {\n      x.drShiftTo(this.m.t-1,this.r2);\n      if(x.t > this.m.t+1) { x.t = this.m.t+1; x.clamp(); }\n      this.mu.multiplyUpperTo(this.r2,this.m.t+1,this.q3);\n      this.m.multiplyLowerTo(this.q3,this.m.t+1,this.r2);\n      while(x.compareTo(this.r2) < 0) x.dAddOffset(1,this.m.t+1);\n      x.subTo(this.r2,x);\n      while(x.compareTo(this.m) >= 0) x.subTo(this.m,x);\n    }\n\n    // r = x^2 mod m; x != r\n    function barrettSqrTo(x,r) { x.squareTo(r); this.reduce(r); }\n\n    // r = x*y mod m; x,y != r\n    function barrettMulTo(x,y,r) { x.multiplyTo(y,r); this.reduce(r); }\n\n    Barrett.prototype.convert = barrettConvert;\n    Barrett.prototype.revert = barrettRevert;\n    Barrett.prototype.reduce = barrettReduce;\n    Barrett.prototype.mulTo = barrettMulTo;\n    Barrett.prototype.sqrTo = barrettSqrTo;\n\n    // (public) this^e % m (HAC 14.85)\n    function bnModPow(e,m) {\n      var i = e.bitLength(), k, r = nbv(1), z;\n      if(i <= 0) return r;\n      else if(i < 18) k = 1;\n      else if(i < 48) k = 3;\n      else if(i < 144) k = 4;\n      else if(i < 768) k = 5;\n      else k = 6;\n      if(i < 8)\n        z = new Classic(m);\n      else if(m.isEven())\n        z = new Barrett(m);\n      else\n        z = new Montgomery(m);\n\n      // precomputation\n      var g = new Array(), n = 3, k1 = k-1, km = (1<<k)-1;\n      g[1] = z.convert(this);\n      if(k > 1) {\n        var g2 = nbi();\n        z.sqrTo(g[1],g2);\n        while(n <= km) {\n          g[n] = nbi();\n          z.mulTo(g2,g[n-2],g[n]);\n          n += 2;\n        }\n      }\n\n      var j = e.t-1, w, is1 = true, r2 = nbi(), t;\n      i = nbits(e[j])-1;\n      while(j >= 0) {\n        if(i >= k1) w = (e[j]>>(i-k1))&km;\n        else {\n          w = (e[j]&((1<<(i+1))-1))<<(k1-i);\n          if(j > 0) w |= e[j-1]>>(this.DB+i-k1);\n        }\n\n        n = k;\n        while((w&1) == 0) { w >>= 1; --n; }\n        if((i -= n) < 0) { i += this.DB; --j; }\n        if(is1) {    // ret == 1, don't bother squaring or multiplying it\n          g[w].copyTo(r);\n          is1 = false;\n        }\n        else {\n          while(n > 1) { z.sqrTo(r,r2); z.sqrTo(r2,r); n -= 2; }\n          if(n > 0) z.sqrTo(r,r2); else { t = r; r = r2; r2 = t; }\n          z.mulTo(r2,g[w],r);\n        }\n\n        while(j >= 0 && (e[j]&(1<<i)) == 0) {\n          z.sqrTo(r,r2); t = r; r = r2; r2 = t;\n          if(--i < 0) { i = this.DB-1; --j; }\n        }\n      }\n      return z.revert(r);\n    }\n\n    // (public) gcd(this,a) (HAC 14.54)\n    function bnGCD(a) {\n      var x = (this.s<0)?this.negate():this.clone();\n      var y = (a.s<0)?a.negate():a.clone();\n      if(x.compareTo(y) < 0) { var t = x; x = y; y = t; }\n      var i = x.getLowestSetBit(), g = y.getLowestSetBit();\n      if(g < 0) return x;\n      if(i < g) g = i;\n      if(g > 0) {\n        x.rShiftTo(g,x);\n        y.rShiftTo(g,y);\n      }\n      while(x.signum() > 0) {\n        if((i = x.getLowestSetBit()) > 0) x.rShiftTo(i,x);\n        if((i = y.getLowestSetBit()) > 0) y.rShiftTo(i,y);\n        if(x.compareTo(y) >= 0) {\n          x.subTo(y,x);\n          x.rShiftTo(1,x);\n        }\n        else {\n          y.subTo(x,y);\n          y.rShiftTo(1,y);\n        }\n      }\n      if(g > 0) y.lShiftTo(g,y);\n      return y;\n    }\n\n    // (protected) this % n, n < 2^26\n    function bnpModInt(n) {\n      if(n <= 0) return 0;\n      var d = this.DV%n, r = (this.s<0)?n-1:0;\n      if(this.t > 0)\n        if(d == 0) r = this[0]%n;\n        else for(var i = this.t-1; i >= 0; --i) r = (d*r+this[i])%n;\n      return r;\n    }\n\n    // (public) 1/this % m (HAC 14.61)\n    function bnModInverse(m) {\n      var ac = m.isEven();\n      if((this.isEven() && ac) || m.signum() == 0) return BigInteger.ZERO;\n      var u = m.clone(), v = this.clone();\n      var a = nbv(1), b = nbv(0), c = nbv(0), d = nbv(1);\n      while(u.signum() != 0) {\n        while(u.isEven()) {\n          u.rShiftTo(1,u);\n          if(ac) {\n            if(!a.isEven() || !b.isEven()) { a.addTo(this,a); b.subTo(m,b); }\n            a.rShiftTo(1,a);\n          }\n          else if(!b.isEven()) b.subTo(m,b);\n          b.rShiftTo(1,b);\n        }\n        while(v.isEven()) {\n          v.rShiftTo(1,v);\n          if(ac) {\n            if(!c.isEven() || !d.isEven()) { c.addTo(this,c); d.subTo(m,d); }\n            c.rShiftTo(1,c);\n          }\n          else if(!d.isEven()) d.subTo(m,d);\n          d.rShiftTo(1,d);\n        }\n        if(u.compareTo(v) >= 0) {\n          u.subTo(v,u);\n          if(ac) a.subTo(c,a);\n          b.subTo(d,b);\n        }\n        else {\n          v.subTo(u,v);\n          if(ac) c.subTo(a,c);\n          d.subTo(b,d);\n        }\n      }\n      if(v.compareTo(BigInteger.ONE) != 0) return BigInteger.ZERO;\n      if(d.compareTo(m) >= 0) return d.subtract(m);\n      if(d.signum() < 0) d.addTo(m,d); else return d;\n      if(d.signum() < 0) return d.add(m); else return d;\n    }\n\n    var lowprimes = [2,3,5,7,11,13,17,19,23,29,31,37,41,43,47,53,59,61,67,71,73,79,83,89,97,101,103,107,109,113,127,131,137,139,149,151,157,163,167,173,179,181,191,193,197,199,211,223,227,229,233,239,241,251,257,263,269,271,277,281,283,293,307,311,313,317,331,337,347,349,353,359,367,373,379,383,389,397,401,409,419,421,431,433,439,443,449,457,461,463,467,479,487,491,499,503,509,521,523,541,547,557,563,569,571,577,587,593,599,601,607,613,617,619,631,641,643,647,653,659,661,673,677,683,691,701,709,719,727,733,739,743,751,757,761,769,773,787,797,809,811,821,823,827,829,839,853,857,859,863,877,881,883,887,907,911,919,929,937,941,947,953,967,971,977,983,991,997];\n    var lplim = (1<<26)/lowprimes[lowprimes.length-1];\n\n    // (public) test primality with certainty >= 1-.5^t\n    function bnIsProbablePrime(t) {\n      var i, x = this.abs();\n      if(x.t == 1 && x[0] <= lowprimes[lowprimes.length-1]) {\n        for(i = 0; i < lowprimes.length; ++i)\n          if(x[0] == lowprimes[i]) return true;\n        return false;\n      }\n      if(x.isEven()) return false;\n      i = 1;\n      while(i < lowprimes.length) {\n        var m = lowprimes[i], j = i+1;\n        while(j < lowprimes.length && m < lplim) m *= lowprimes[j++];\n        m = x.modInt(m);\n        while(i < j) if(m%lowprimes[i++] == 0) return false;\n      }\n      return x.millerRabin(t);\n    }\n\n    // (protected) true if probably prime (HAC 4.24, Miller-Rabin)\n    function bnpMillerRabin(t) {\n      var n1 = this.subtract(BigInteger.ONE);\n      var k = n1.getLowestSetBit();\n      if(k <= 0) return false;\n      var r = n1.shiftRight(k);\n      t = (t+1)>>1;\n      if(t > lowprimes.length) t = lowprimes.length;\n      var a = nbi();\n      for(var i = 0; i < t; ++i) {\n        //Pick bases at random, instead of starting at 2\n        a.fromInt(lowprimes[Math.floor(Math.random()*lowprimes.length)]);\n        var y = a.modPow(r,this);\n        if(y.compareTo(BigInteger.ONE) != 0 && y.compareTo(n1) != 0) {\n          var j = 1;\n          while(j++ < k && y.compareTo(n1) != 0) {\n            y = y.modPowInt(2,this);\n            if(y.compareTo(BigInteger.ONE) == 0) return false;\n          }\n          if(y.compareTo(n1) != 0) return false;\n        }\n      }\n      return true;\n    }\n\n    // protected\n    BigInteger.prototype.chunkSize = bnpChunkSize;\n    BigInteger.prototype.toRadix = bnpToRadix;\n    BigInteger.prototype.fromRadix = bnpFromRadix;\n    BigInteger.prototype.fromNumber = bnpFromNumber;\n    BigInteger.prototype.bitwiseTo = bnpBitwiseTo;\n    BigInteger.prototype.changeBit = bnpChangeBit;\n    BigInteger.prototype.addTo = bnpAddTo;\n    BigInteger.prototype.dMultiply = bnpDMultiply;\n    BigInteger.prototype.dAddOffset = bnpDAddOffset;\n    BigInteger.prototype.multiplyLowerTo = bnpMultiplyLowerTo;\n    BigInteger.prototype.multiplyUpperTo = bnpMultiplyUpperTo;\n    BigInteger.prototype.modInt = bnpModInt;\n    BigInteger.prototype.millerRabin = bnpMillerRabin;\n\n    // public\n    BigInteger.prototype.clone = bnClone;\n    BigInteger.prototype.intValue = bnIntValue;\n    BigInteger.prototype.byteValue = bnByteValue;\n    BigInteger.prototype.shortValue = bnShortValue;\n    BigInteger.prototype.signum = bnSigNum;\n    BigInteger.prototype.toByteArray = bnToByteArray;\n    BigInteger.prototype.equals = bnEquals;\n    BigInteger.prototype.min = bnMin;\n    BigInteger.prototype.max = bnMax;\n    BigInteger.prototype.and = bnAnd;\n    BigInteger.prototype.or = bnOr;\n    BigInteger.prototype.xor = bnXor;\n    BigInteger.prototype.andNot = bnAndNot;\n    BigInteger.prototype.not = bnNot;\n    BigInteger.prototype.shiftLeft = bnShiftLeft;\n    BigInteger.prototype.shiftRight = bnShiftRight;\n    BigInteger.prototype.getLowestSetBit = bnGetLowestSetBit;\n    BigInteger.prototype.bitCount = bnBitCount;\n    BigInteger.prototype.testBit = bnTestBit;\n    BigInteger.prototype.setBit = bnSetBit;\n    BigInteger.prototype.clearBit = bnClearBit;\n    BigInteger.prototype.flipBit = bnFlipBit;\n    BigInteger.prototype.add = bnAdd;\n    BigInteger.prototype.subtract = bnSubtract;\n    BigInteger.prototype.multiply = bnMultiply;\n    BigInteger.prototype.divide = bnDivide;\n    BigInteger.prototype.remainder = bnRemainder;\n    BigInteger.prototype.divideAndRemainder = bnDivideAndRemainder;\n    BigInteger.prototype.modPow = bnModPow;\n    BigInteger.prototype.modInverse = bnModInverse;\n    BigInteger.prototype.pow = bnPow;\n    BigInteger.prototype.gcd = bnGCD;\n    BigInteger.prototype.isProbablePrime = bnIsProbablePrime;\n\n    // JSBN-specific extension\n    BigInteger.prototype.square = bnSquare;\n\n    // Expose the Barrett function\n    BigInteger.prototype.Barrett = Barrett\n\n    // BigInteger interfaces not implemented in jsbn:\n\n    // BigInteger(int signum, byte[] magnitude)\n    // double doubleValue()\n    // float floatValue()\n    // int hashCode()\n    // long longValue()\n    // static BigInteger valueOf(long val)\n\n    // Random number generator - requires a PRNG backend, e.g. prng4.js\n\n    // For best results, put code like\n    // <body onClick='rng_seed_time();' onKeyPress='rng_seed_time();'>\n    // in your main HTML document.\n\n    var rng_state;\n    var rng_pool;\n    var rng_pptr;\n\n    // Mix in a 32-bit integer into the pool\n    function rng_seed_int(x) {\n      rng_pool[rng_pptr++] ^= x & 255;\n      rng_pool[rng_pptr++] ^= (x >> 8) & 255;\n      rng_pool[rng_pptr++] ^= (x >> 16) & 255;\n      rng_pool[rng_pptr++] ^= (x >> 24) & 255;\n      if(rng_pptr >= rng_psize) rng_pptr -= rng_psize;\n    }\n\n    // Mix in the current time (w/milliseconds) into the pool\n    function rng_seed_time() {\n      rng_seed_int(new Date().getTime());\n    }\n\n    // Initialize the pool with junk if needed.\n    if(rng_pool == null) {\n      rng_pool = new Array();\n      rng_pptr = 0;\n      var t;\n      if(typeof window !== \"undefined\" && window.crypto) {\n        if (window.crypto.getRandomValues) {\n          // Use webcrypto if available\n          var ua = new Uint8Array(32);\n          window.crypto.getRandomValues(ua);\n          for(t = 0; t < 32; ++t)\n            rng_pool[rng_pptr++] = ua[t];\n        }\n        else if(navigator.appName == \"Netscape\" && navigator.appVersion < \"5\") {\n          // Extract entropy (256 bits) from NS4 RNG if available\n          var z = window.crypto.random(32);\n          for(t = 0; t < z.length; ++t)\n            rng_pool[rng_pptr++] = z.charCodeAt(t) & 255;\n        }\n      }\n      while(rng_pptr < rng_psize) {  // extract some randomness from Math.random()\n        t = Math.floor(65536 * Math.random());\n        rng_pool[rng_pptr++] = t >>> 8;\n        rng_pool[rng_pptr++] = t & 255;\n      }\n      rng_pptr = 0;\n      rng_seed_time();\n      //rng_seed_int(window.screenX);\n      //rng_seed_int(window.screenY);\n    }\n\n    function rng_get_byte() {\n      if(rng_state == null) {\n        rng_seed_time();\n        rng_state = prng_newstate();\n        rng_state.init(rng_pool);\n        for(rng_pptr = 0; rng_pptr < rng_pool.length; ++rng_pptr)\n          rng_pool[rng_pptr] = 0;\n        rng_pptr = 0;\n        //rng_pool = null;\n      }\n      // TODO: allow reseeding after first request\n      return rng_state.next();\n    }\n\n    function rng_get_bytes(ba) {\n      var i;\n      for(i = 0; i < ba.length; ++i) ba[i] = rng_get_byte();\n    }\n\n    function SecureRandom() {}\n\n    SecureRandom.prototype.nextBytes = rng_get_bytes;\n\n    // prng4.js - uses Arcfour as a PRNG\n\n    function Arcfour() {\n      this.i = 0;\n      this.j = 0;\n      this.S = new Array();\n    }\n\n    // Initialize arcfour context from key, an array of ints, each from [0..255]\n    function ARC4init(key) {\n      var i, j, t;\n      for(i = 0; i < 256; ++i)\n        this.S[i] = i;\n      j = 0;\n      for(i = 0; i < 256; ++i) {\n        j = (j + this.S[i] + key[i % key.length]) & 255;\n        t = this.S[i];\n        this.S[i] = this.S[j];\n        this.S[j] = t;\n      }\n      this.i = 0;\n      this.j = 0;\n    }\n\n    function ARC4next() {\n      var t;\n      this.i = (this.i + 1) & 255;\n      this.j = (this.j + this.S[this.i]) & 255;\n      t = this.S[this.i];\n      this.S[this.i] = this.S[this.j];\n      this.S[this.j] = t;\n      return this.S[(t + this.S[this.i]) & 255];\n    }\n\n    Arcfour.prototype.init = ARC4init;\n    Arcfour.prototype.next = ARC4next;\n\n    // Plug in your RNG constructor here\n    function prng_newstate() {\n      return new Arcfour();\n    }\n\n    // Pool size must be a multiple of 4 and greater than 32.\n    // An array of bytes the size of the pool will be passed to init()\n    var rng_psize = 256;\n\n    if (typeof exports !== 'undefined') {\n        exports = module.exports = {\n            default: BigInteger,\n            BigInteger: BigInteger,\n            SecureRandom: SecureRandom,\n        };\n    } else {\n        this.jsbn = {\n          BigInteger: BigInteger,\n          SecureRandom: SecureRandom\n        };\n    }\n\n}).call(this);\n","/**\n * Convert array of 16 byte values to UUID string format of the form:\n * XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX\n */\nvar byteToHex = [];\nfor (var i = 0; i < 256; ++i) {\n  byteToHex[i] = (i + 0x100).toString(16).substr(1);\n}\n\nfunction bytesToUuid(buf, offset) {\n  var i = offset || 0;\n  var bth = byteToHex;\n  // join used to fix memory issue caused by concatenation: https://bugs.chromium.org/p/v8/issues/detail?id=3175#c4\n  return ([bth[buf[i++]], bth[buf[i++]], \n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]]]).join('');\n}\n\nmodule.exports = bytesToUuid;\n","// Unique ID creation requires a high quality random # generator.  In the\n// browser this is a little complicated due to unknown quality of Math.random()\n// and inconsistent support for the `crypto` API.  We do the best we can via\n// feature-detection\n\n// getRandomValues needs to be invoked in a context where \"this\" is a Crypto\n// implementation. Also, find the complete implementation of crypto on IE11.\nvar getRandomValues = (typeof(crypto) != 'undefined' && crypto.getRandomValues && crypto.getRandomValues.bind(crypto)) ||\n                      (typeof(msCrypto) != 'undefined' && typeof window.msCrypto.getRandomValues == 'function' && msCrypto.getRandomValues.bind(msCrypto));\n\nif (getRandomValues) {\n  // WHATWG crypto RNG - http://wiki.whatwg.org/wiki/Crypto\n  var rnds8 = new Uint8Array(16); // eslint-disable-line no-undef\n\n  module.exports = function whatwgRNG() {\n    getRandomValues(rnds8);\n    return rnds8;\n  };\n} else {\n  // Math.random()-based (RNG)\n  //\n  // If all else fails, use Math.random().  It's fast, but is of unspecified\n  // quality.\n  var rnds = new Array(16);\n\n  module.exports = function mathRNG() {\n    for (var i = 0, r; i < 16; i++) {\n      if ((i & 0x03) === 0) r = Math.random() * 0x100000000;\n      rnds[i] = r >>> ((i & 0x03) << 3) & 0xff;\n    }\n\n    return rnds;\n  };\n}\n","var rng = require('./lib/rng');\nvar bytesToUuid = require('./lib/bytesToUuid');\n\nfunction v4(options, buf, offset) {\n  var i = buf && offset || 0;\n\n  if (typeof(options) == 'string') {\n    buf = options === 'binary' ? new Array(16) : null;\n    options = null;\n  }\n  options = options || {};\n\n  var rnds = options.random || (options.rng || rng)();\n\n  // Per 4.4, set bits for version and `clock_seq_hi_and_reserved`\n  rnds[6] = (rnds[6] & 0x0f) | 0x40;\n  rnds[8] = (rnds[8] & 0x3f) | 0x80;\n\n  // Copy bytes to buffer, if provided\n  if (buf) {\n    for (var ii = 0; ii < 16; ++ii) {\n      buf[i + ii] = rnds[ii];\n    }\n  }\n\n  return buf || bytesToUuid(rnds);\n}\n\nmodule.exports = v4;\n","// Declare the ES6 features we're using\r\n\r\n// TODO: Consider using the local function versions of these, so that we\r\n// avoid modifying browser globals (potential for interop bugs with other libraries\r\n// on the page that might be polyfilling ES6 features)\r\n\r\nimport 'core-js/es6/promise';\r\nimport 'core-js/fn/function/bind';\r\nimport 'core-js/fn/object/assign';\r\nimport 'core-js/fn/array/find';\r\nimport 'core-js/fn/array/some';\r\nimport 'core-js/fn/array/is-array';\r\nimport 'core-js/fn/array/splice';\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Timer } from './Timer.js';\r\n\r\nconst DefaultAccessTokenExpiringNotificationTime = 60; // seconds\r\n\r\nexport class AccessTokenEvents {\r\n\r\n    constructor({\r\n        accessTokenExpiringNotificationTime = DefaultAccessTokenExpiringNotificationTime,\r\n        accessTokenExpiringTimer = new Timer(\"Access token expiring\"),\r\n        accessTokenExpiredTimer = new Timer(\"Access token expired\")\r\n    } = {}) {\r\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\r\n\r\n        this._accessTokenExpiring = accessTokenExpiringTimer;\r\n        this._accessTokenExpired = accessTokenExpiredTimer;\r\n    }\r\n\r\n    load(container) {\r\n        // only register events if there's an access token and it has an expiration\r\n        if (container.access_token && container.expires_in !== undefined) {\r\n            let duration = container.expires_in;\r\n            Log.debug(\"AccessTokenEvents.load: access token present, remaining duration:\", duration);\r\n\r\n            if (duration > 0) {\r\n                // only register expiring if we still have time\r\n                let expiring = duration - this._accessTokenExpiringNotificationTime;\r\n                if (expiring <= 0){\r\n                    expiring = 1;\r\n                }\r\n                \r\n                Log.debug(\"AccessTokenEvents.load: registering expiring timer in:\", expiring);\r\n                this._accessTokenExpiring.init(expiring);\r\n            }\r\n            else {\r\n                Log.debug(\"AccessTokenEvents.load: canceling existing expiring timer becase we're past expiration.\");\r\n                this._accessTokenExpiring.cancel();\r\n            }\r\n\r\n            // if it's negative, it will still fire\r\n            let expired = duration + 1;\r\n            Log.debug(\"AccessTokenEvents.load: registering expired timer in:\", expired);\r\n            this._accessTokenExpired.init(expired);\r\n        }\r\n        else {\r\n            this._accessTokenExpiring.cancel();\r\n            this._accessTokenExpired.cancel();\r\n        }\r\n    }\r\n\r\n    unload() {\r\n        Log.debug(\"AccessTokenEvents.unload: canceling existing access token timers\");\r\n        this._accessTokenExpiring.cancel();\r\n        this._accessTokenExpired.cancel();\r\n    }\r\n\r\n    addAccessTokenExpiring(cb) {\r\n        this._accessTokenExpiring.addHandler(cb);\r\n    }\r\n    removeAccessTokenExpiring(cb) {\r\n        this._accessTokenExpiring.removeHandler(cb);\r\n    }\r\n\r\n    addAccessTokenExpired(cb) {\r\n        this._accessTokenExpired.addHandler(cb);\r\n    }\r\n    removeAccessTokenExpired(cb) {\r\n        this._accessTokenExpired.removeHandler(cb);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultInterval = 2000;\r\n\r\nexport class CheckSessionIFrame {\r\n    constructor(callback, client_id, url, interval, stopOnError = true) {\r\n        this._callback = callback;\r\n        this._client_id = client_id;\r\n        this._url = url;\r\n        this._interval = interval || DefaultInterval;\r\n        this._stopOnError = stopOnError;\r\n\r\n        var idx = url.indexOf(\"/\", url.indexOf(\"//\") + 2);\r\n        this._frame_origin = url.substr(0, idx);\r\n\r\n        this._frame = window.document.createElement(\"iframe\");\r\n\r\n        // shotgun approach\r\n        this._frame.style.visibility = \"hidden\";\r\n        this._frame.style.position = \"absolute\";\r\n        this._frame.style.display = \"none\";\r\n        this._frame.style.width = 0;\r\n        this._frame.style.height = 0;\r\n\r\n        this._frame.src = url;\r\n    }\r\n    load() {\r\n        return new Promise((resolve) => {\r\n            this._frame.onload = () => {\r\n                resolve();\r\n            }\r\n\r\n            window.document.body.appendChild(this._frame);\r\n            this._boundMessageEvent = this._message.bind(this);\r\n            window.addEventListener(\"message\", this._boundMessageEvent, false);\r\n        });\r\n    }\r\n    _message(e) {\r\n        if (e.origin === this._frame_origin &&\r\n            e.source === this._frame.contentWindow\r\n        ) {\r\n            if (e.data === \"error\") {\r\n                Log.error(\"CheckSessionIFrame: error message from check session op iframe\");\r\n                if (this._stopOnError) {\r\n                    this.stop();\r\n                }\r\n            }\r\n            else if (e.data === \"changed\") {\r\n                Log.debug(\"CheckSessionIFrame: changed message from check session op iframe\");\r\n                this.stop();\r\n                this._callback();\r\n            }\r\n            else {\r\n                Log.debug(\"CheckSessionIFrame: \" + e.data + \" message from check session op iframe\");\r\n            }\r\n        }\r\n    }\r\n    start(session_state) {\r\n        if (this._session_state !== session_state) {\r\n            Log.debug(\"CheckSessionIFrame.start\");\r\n\r\n            this.stop();\r\n\r\n            this._session_state = session_state;\r\n\r\n            let send = () => {\r\n                this._frame.contentWindow.postMessage(this._client_id + \" \" + this._session_state, this._frame_origin);\r\n            };\r\n            \r\n            // trigger now\r\n            send();\r\n\r\n            // and setup timer\r\n            this._timer = window.setInterval(send, this._interval);\r\n        }\r\n    }\r\n\r\n    stop() {\r\n        this._session_state = null;\r\n\r\n        if (this._timer) {\r\n            Log.debug(\"CheckSessionIFrame.stop\");\r\n\r\n            window.clearInterval(this._timer);\r\n            this._timer = null;\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { CordovaPopupWindow } from './CordovaPopupWindow.js';\r\n\r\nexport class CordovaIFrameNavigator {\r\n\r\n    prepare(params) {\r\n        params.popupWindowFeatures = 'hidden=yes';\r\n        let popup = new CordovaPopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { CordovaPopupWindow } from './CordovaPopupWindow.js';\r\n\r\nexport class CordovaPopupNavigator {\r\n\r\n    prepare(params) {\r\n        let popup = new CordovaPopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultPopupFeatures = 'location=no,toolbar=no,zoom=no';\r\nconst DefaultPopupTarget = \"_blank\";\r\n\r\nexport class CordovaPopupWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        this.features = params.popupWindowFeatures || DefaultPopupFeatures;\r\n        this.target = params.popupWindowTarget || DefaultPopupTarget;\r\n        \r\n        this.redirect_uri = params.startUrl;\r\n        Log.debug(\"CordovaPopupWindow.ctor: redirect_uri: \" + this.redirect_uri);\r\n    }\r\n\r\n    _isInAppBrowserInstalled(cordovaMetadata) {\r\n        return [\"cordova-plugin-inappbrowser\", \"cordova-plugin-inappbrowser.inappbrowser\", \"org.apache.cordova.inappbrowser\"].some(function (name) {\r\n            return cordovaMetadata.hasOwnProperty(name)\r\n        })\r\n    }\r\n    \r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            this._error(\"No url provided\");\r\n        } else {\r\n            if (!window.cordova) {\r\n                return this._error(\"cordova is undefined\")\r\n            }\r\n            \r\n            var cordovaMetadata = window.cordova.require(\"cordova/plugin_list\").metadata;\r\n            if (this._isInAppBrowserInstalled(cordovaMetadata) === false) {\r\n                return this._error(\"InAppBrowser plugin not found\")\r\n            }\r\n            this._popup = cordova.InAppBrowser.open(params.url, this.target, this.features);\r\n            if (this._popup) {\r\n                Log.debug(\"CordovaPopupWindow.navigate: popup successfully created\");\r\n                \r\n                this._exitCallbackEvent = this._exitCallback.bind(this); \r\n                this._loadStartCallbackEvent = this._loadStartCallback.bind(this);\r\n                \r\n                this._popup.addEventListener(\"exit\", this._exitCallbackEvent, false);\r\n                this._popup.addEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\r\n            } else {\r\n                this._error(\"Error opening popup window\");\r\n            }\r\n        }\r\n        return this.promise;\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    _loadStartCallback(event) {\r\n        if (event.url.indexOf(this.redirect_uri) === 0) {\r\n            this._success({ url: event.url });\r\n        }    \r\n    }\r\n    _exitCallback(message) {\r\n        this._error(message);    \r\n    }\r\n    \r\n    _success(data) {\r\n        this._cleanup();\r\n\r\n        Log.debug(\"CordovaPopupWindow: Successful response from cordova popup window\");\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        this._cleanup();\r\n\r\n        Log.error(message);\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup();\r\n    }\r\n\r\n    _cleanup() {\r\n        if (this._popup){\r\n            Log.debug(\"CordovaPopupWindow: cleaning up popup\");\r\n            this._popup.removeEventListener(\"exit\", this._exitCallbackEvent, false);\r\n            this._popup.removeEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\r\n            this._popup.close();\r\n        }\r\n        this._popup = null;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class ErrorResponse extends Error {\r\n    constructor({error, error_description, error_uri, state, session_state}={}\r\n    ) {\r\n         if (!error){\r\n            Log.error(\"No error passed to ErrorResponse\");\r\n            throw new Error(\"error\");\r\n        }\r\n\r\n        super(error_description || error);\r\n\r\n        this.name = \"ErrorResponse\";\r\n\r\n        this.error = error;\r\n        this.error_description = error_description;\r\n        this.error_uri = error_uri;\r\n\r\n        this.state = state;\r\n        this.session_state = session_state;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class Event {\r\n\r\n    constructor(name) {\r\n        this._name = name;\r\n        this._callbacks = [];\r\n    }\r\n\r\n    addHandler(cb) {\r\n        this._callbacks.push(cb);\r\n    }\r\n\r\n    removeHandler(cb) {\r\n        var idx = this._callbacks.findIndex(item => item === cb);\r\n        if (idx >= 0) {\r\n            this._callbacks.splice(idx, 1);\r\n        }\r\n    }\r\n\r\n    raise(...params) {\r\n        Log.debug(\"Event: Raising event: \" + this._name);\r\n        for (let i = 0; i < this._callbacks.length; i++) {\r\n            this._callbacks[i](...params);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nconst timer = {\r\n    setInterval: function (cb, duration) {\r\n        return setInterval(cb, duration);\r\n    },\r\n    clearInterval: function (handle) {\r\n        return clearInterval(handle);\r\n    }\r\n};\r\n\r\nlet testing = false;\r\nlet request = null;\r\n\r\nexport class Global {\r\n\r\n    static _testing() {\r\n        testing = true;\r\n    }\r\n\r\n    static get location() {\r\n        if (!testing) {\r\n            return location;\r\n        }\r\n    }\r\n\r\n    static get localStorage() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return localStorage;\r\n        }\r\n    }\r\n\r\n    static get sessionStorage() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return sessionStorage;\r\n        }\r\n    }\r\n\r\n    static setXMLHttpRequest(newRequest) {\r\n        request = newRequest;\r\n    }\r\n\r\n    static get XMLHttpRequest() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return request || XMLHttpRequest;\r\n        }\r\n    }\r\n\r\n    static get timer() {\r\n        if (!testing) {\r\n            return timer;\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { IFrameWindow } from './IFrameWindow.js';\r\n\r\nexport class IFrameNavigator {\r\n\r\n    prepare(params) {\r\n        let frame = new IFrameWindow(params);\r\n        return Promise.resolve(frame);\r\n    }\r\n\r\n    callback(url) {\r\n        Log.debug(\"IFrameNavigator.callback\");\r\n\r\n        try {\r\n            IFrameWindow.notifyParent(url);\r\n            return Promise.resolve();\r\n        }\r\n        catch (e) {\r\n            return Promise.reject(e);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultTimeout = 10000;\r\n\r\nexport class IFrameWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        this._boundMessageEvent = this._message.bind(this);\r\n        window.addEventListener(\"message\", this._boundMessageEvent, false);\r\n\r\n        this._frame = window.document.createElement(\"iframe\");\r\n\r\n        // shotgun approach\r\n        this._frame.style.visibility = \"hidden\";\r\n        this._frame.style.position = \"absolute\";\r\n        this._frame.style.display = \"none\";\r\n        this._frame.style.width = 0;\r\n        this._frame.style.height = 0;\r\n\r\n        window.document.body.appendChild(this._frame);\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            this._error(\"No url provided\");\r\n        }\r\n        else {\r\n            let timeout = params.silentRequestTimeout || DefaultTimeout;\r\n            Log.debug(\"IFrameWindow.navigate: Using timeout of:\", timeout);\r\n            this._timer = window.setTimeout(this._timeout.bind(this), timeout);\r\n            this._frame.src = params.url;\r\n        }\r\n\r\n        return this.promise;\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    _success(data) {\r\n        this._cleanup();\r\n\r\n        Log.debug(\"IFrameWindow: Successful response from frame window\");\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        this._cleanup();\r\n\r\n        Log.error(message);\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup();\r\n    }\r\n\r\n    _cleanup() {\r\n        if (this._frame) {\r\n            Log.debug(\"IFrameWindow: cleanup\");\r\n\r\n            window.removeEventListener(\"message\", this._boundMessageEvent, false);\r\n            window.clearTimeout(this._timer);\r\n            window.document.body.removeChild(this._frame);\r\n\r\n            this._timer = null;\r\n            this._frame = null;\r\n            this._boundMessageEvent = null;\r\n        }\r\n    }\r\n\r\n    _timeout() {\r\n        Log.debug(\"IFrameWindow.timeout\");\r\n        this._error(\"Frame window timed out\");\r\n    }\r\n\r\n    _message(e) {\r\n        Log.debug(\"IFrameWindow.message\");\r\n\r\n        if (this._timer &&\r\n            e.origin === this._origin &&\r\n            e.source === this._frame.contentWindow\r\n        ) {\r\n            let url = e.data;\r\n            if (url) {\r\n                this._success({ url: url });\r\n            }\r\n            else {\r\n                this._error(\"Invalid response from frame\");\r\n            }\r\n        }\r\n    }\r\n\r\n    get _origin() {\r\n        return location.protocol + \"//\" + location.host;\r\n    }\r\n\r\n    static notifyParent(url) {\r\n        Log.debug(\"IFrameWindow.notifyParent\");\r\n        if (window.frameElement) {\r\n            url = url || window.location.href;\r\n            if (url) {\r\n                Log.debug(\"IFrameWindow.notifyParent: posting url message to parent\");\r\n                window.parent.postMessage(url, location.protocol + \"//\" + location.host);\r\n            }\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class InMemoryWebStorage{\r\n    constructor(){\r\n        this._data = {};\r\n    }\r\n\r\n    getItem(key) {\r\n        Log.debug(\"InMemoryWebStorage.getItem\", key);\r\n        return this._data[key];\r\n    }\r\n\r\n    setItem(key, value){\r\n        Log.debug(\"InMemoryWebStorage.setItem\", key);\r\n        this._data[key] = value;\r\n    }\r\n\r\n    removeItem(key){\r\n        Log.debug(\"InMemoryWebStorage.removeItem\", key);\r\n        delete this._data[key];\r\n    }\r\n\r\n    get length() {\r\n        return Object.getOwnPropertyNames(this._data).length;\r\n    }\r\n\r\n    key(index) {\r\n        return Object.getOwnPropertyNames(this._data)[index];\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport default function getJoseUtil({ jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs }) {\r\n    return class JoseUtil {\r\n\r\n        static parseJwt(jwt) {\r\n            Log.debug(\"JoseUtil.parseJwt\");\r\n            try {\r\n                var token = jws.JWS.parse(jwt);\r\n                return {\r\n                    header: token.headerObj,\r\n                    payload: token.payloadObj\r\n                }\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n\r\n        static validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\r\n            Log.debug(\"JoseUtil.validateJwt\");\r\n\r\n            try {\r\n                if (key.kty === \"RSA\") {\r\n                    if (key.e && key.n) {\r\n                        key = KeyUtil.getKey(key);\r\n                    } else if (key.x5c && key.x5c.length) {\r\n                        var hex = b64tohex(key.x5c[0]);\r\n                        key = X509.getPublicKeyFromCertHex(hex);\r\n                    } else {\r\n                        Log.error(\"JoseUtil.validateJwt: RSA key missing key material\", key);\r\n                        return Promise.reject(new Error(\"RSA key missing key material\"));\r\n                    }\r\n                } else if (key.kty === \"EC\") {\r\n                    if (key.crv && key.x && key.y) {\r\n                        key = KeyUtil.getKey(key);\r\n                    } else {\r\n                        Log.error(\"JoseUtil.validateJwt: EC key missing key material\", key);\r\n                        return Promise.reject(new Error(\"EC key missing key material\"));\r\n                    }\r\n                } else {\r\n                    Log.error(\"JoseUtil.validateJwt: Unsupported key type\", key && key.kty);\r\n                    return Promise.reject(new Error(\"Unsupported key type: \" + key && key.kty));\r\n                }\r\n\r\n                return JoseUtil._validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive);\r\n            } catch (e) {\r\n                Log.error(e && e.message || e);\r\n                return Promise.reject(\"JWT validation failed\");\r\n            }\r\n        }\r\n\r\n        static validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive) {\r\n            if (!clockSkew) {\r\n                clockSkew = 0;\r\n            }\r\n\r\n            if (!now) {\r\n                now = parseInt(Date.now() / 1000);\r\n            }\r\n\r\n            var payload = JoseUtil.parseJwt(jwt).payload;\r\n\r\n            if (!payload.iss) {\r\n                Log.error(\"JoseUtil._validateJwt: issuer was not provided\");\r\n                return Promise.reject(new Error(\"issuer was not provided\"));\r\n            }\r\n            if (payload.iss !== issuer) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid issuer in token\", payload.iss);\r\n                return Promise.reject(new Error(\"Invalid issuer in token: \" + payload.iss));\r\n            }\r\n\r\n            if (!payload.aud) {\r\n                Log.error(\"JoseUtil._validateJwt: aud was not provided\");\r\n                return Promise.reject(new Error(\"aud was not provided\"));\r\n            }\r\n            var validAudience = payload.aud === audience || (Array.isArray(payload.aud) && payload.aud.indexOf(audience) >= 0);\r\n            if (!validAudience) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid audience in token\", payload.aud);\r\n                return Promise.reject(new Error(\"Invalid audience in token: \" + payload.aud));\r\n            }\r\n            if (payload.azp && payload.azp !== audience) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid azp in token\", payload.azp);\r\n                return Promise.reject(new Error(\"Invalid azp in token: \" + payload.azp));\r\n            }\r\n\r\n            if (!timeInsensitive) {\r\n                var lowerNow = now + clockSkew;\r\n                var upperNow = now - clockSkew;\r\n\r\n                if (!payload.iat) {\r\n                    Log.error(\"JoseUtil._validateJwt: iat was not provided\");\r\n                    return Promise.reject(new Error(\"iat was not provided\"));\r\n                }\r\n                if (lowerNow < payload.iat) {\r\n                    Log.error(\"JoseUtil._validateJwt: iat is in the future\", payload.iat);\r\n                    return Promise.reject(new Error(\"iat is in the future: \" + payload.iat));\r\n                }\r\n\r\n                if (payload.nbf && lowerNow < payload.nbf) {\r\n                    Log.error(\"JoseUtil._validateJwt: nbf is in the future\", payload.nbf);\r\n                    return Promise.reject(new Error(\"nbf is in the future: \" + payload.nbf));\r\n                }\r\n\r\n                if (!payload.exp) {\r\n                    Log.error(\"JoseUtil._validateJwt: exp was not provided\");\r\n                    return Promise.reject(new Error(\"exp was not provided\"));\r\n                }\r\n                if (payload.exp < upperNow) {\r\n                    Log.error(\"JoseUtil._validateJwt: exp is in the past\", payload.exp);\r\n                    return Promise.reject(new Error(\"exp is in the past:\" + payload.exp));\r\n                }\r\n            }\r\n\r\n            return Promise.resolve(payload);\r\n        }\r\n\r\n        static _validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\r\n\r\n            return JoseUtil.validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive).then(payload => {\r\n                try {\r\n                    if (!jws.JWS.verify(jwt, key, AllowedSigningAlgs)) {\r\n                        Log.error(\"JoseUtil._validateJwt: signature validation failed\");\r\n                        return Promise.reject(new Error(\"signature validation failed\"));\r\n                    }\r\n\r\n                    return payload;\r\n                } catch (e) {\r\n                    Log.error(e && e.message || e);\r\n                    return Promise.reject(new Error(\"signature validation failed\"));\r\n                }\r\n            });\r\n        }\r\n\r\n        static hashString(value, alg) {\r\n            try {\r\n                return crypto.Util.hashString(value, alg);\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n\r\n        static hexToBase64Url(value) {\r\n            try {\r\n                return hextob64u(value);\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n    }\r\n}\r\n","import { jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs } from './crypto/rsa';\r\nimport getJoseUtil from './JoseUtilImpl';\r\n\r\nexport const JoseUtil = getJoseUtil({ jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs });\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class JsonService {\r\n    constructor(\r\n        additionalContentTypes = null, \r\n        XMLHttpRequestCtor = Global.XMLHttpRequest, \r\n        jwtHandler = null\r\n    ) {\r\n        if (additionalContentTypes && Array.isArray(additionalContentTypes))\r\n        {\r\n            this._contentTypes = additionalContentTypes.slice();\r\n        }\r\n        else\r\n        {\r\n            this._contentTypes = [];\r\n        }\r\n        this._contentTypes.push('application/json');\r\n        if (jwtHandler) {\r\n            this._contentTypes.push('application/jwt');\r\n        }\r\n\r\n        this._XMLHttpRequest = XMLHttpRequestCtor;\r\n        this._jwtHandler = jwtHandler;\r\n    }\r\n\r\n    getJson(url, token) {\r\n        if (!url){\r\n            Log.error(\"JsonService.getJson: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        Log.debug(\"JsonService.getJson, url: \", url);\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var req = new this._XMLHttpRequest();\r\n            req.open('GET', url);\r\n\r\n            var allowedContentTypes = this._contentTypes;\r\n            var jwtHandler = this._jwtHandler;\r\n\r\n            req.onload = function() {\r\n                Log.debug(\"JsonService.getJson: HTTP response received, status\", req.status);\r\n\r\n                if (req.status === 200) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found == \"application/jwt\") {\r\n                            jwtHandler(req).then(resolve, reject);\r\n                            return;\r\n                        }\r\n\r\n                        if (found) {\r\n                            try {\r\n                                resolve(JSON.parse(req.responseText));\r\n                                return;\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.getJson: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n\r\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\r\n                }\r\n                else {\r\n                    reject(Error(req.statusText + \" (\" + req.status + \")\"));\r\n                }\r\n            };\r\n\r\n            req.onerror = function() {\r\n                Log.error(\"JsonService.getJson: network error\");\r\n                reject(Error(\"Network Error\"));\r\n            };\r\n\r\n            if (token) {\r\n                Log.debug(\"JsonService.getJson: token passed, setting Authorization header\");\r\n                req.setRequestHeader(\"Authorization\", \"Bearer \" + token);\r\n            }\r\n\r\n            req.send();\r\n        });\r\n    }\r\n\r\n    postForm(url, payload) {\r\n        if (!url){\r\n            Log.error(\"JsonService.postForm: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        Log.debug(\"JsonService.postForm, url: \", url);\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var req = new this._XMLHttpRequest();\r\n            req.open('POST', url);\r\n\r\n            var allowedContentTypes = this._contentTypes;\r\n\r\n            req.onload = function() {\r\n                Log.debug(\"JsonService.postForm: HTTP response received, status\", req.status);\r\n\r\n                if (req.status === 200) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found) {\r\n                            try {\r\n                                resolve(JSON.parse(req.responseText));\r\n                                return;\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n\r\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\r\n                    return;\r\n                }\r\n\r\n                if (req.status === 400) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found) {\r\n                            try {\r\n                                var payload = JSON.parse(req.responseText);\r\n                                if (payload && payload.error) {\r\n                                    Log.error(\"JsonService.postForm: Error from server: \", payload.error);\r\n                                    reject(new Error(payload.error));\r\n                                    return;\r\n                                }\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n                }\r\n\r\n                reject(Error(req.statusText + \" (\" + req.status + \")\"));\r\n            };\r\n\r\n            req.onerror = function() {\r\n                Log.error(\"JsonService.postForm: network error\");\r\n                reject(Error(\"Network Error\"));\r\n            };\r\n\r\n            let body = \"\";\r\n            for(let key in payload) {\r\n\r\n                let value = payload[key];\r\n\r\n                if (value) {\r\n\r\n                    if (body.length > 0) {\r\n                        body += \"&\";\r\n                    }\r\n\r\n                    body += encodeURIComponent(key);\r\n                    body += \"=\";\r\n                    body += encodeURIComponent(value);\r\n                }\r\n            }\r\n\r\n            req.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\r\n            req.send(body);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nlet nopLogger = {\r\n    debug(){},\r\n    info(){},\r\n    warn(){},\r\n    error(){}\r\n};\r\n\r\nconst NONE = 0;\r\nconst ERROR = 1;\r\nconst WARN = 2;\r\nconst INFO = 3;\r\nconst DEBUG = 4;\r\n\r\nlet logger;\r\nlet level;\r\n\r\nexport class Log {\r\n    static get NONE() {return NONE};\r\n    static get ERROR() {return ERROR};\r\n    static get WARN() {return WARN};\r\n    static get INFO() {return INFO};\r\n    static get DEBUG() {return DEBUG};\r\n    \r\n    static reset(){\r\n        level = INFO;\r\n        logger = nopLogger;\r\n    }\r\n    \r\n    static get level(){\r\n        return level;\r\n    }\r\n    static set level(value){\r\n        if (NONE <= value && value <= DEBUG){\r\n            level = value;\r\n        }\r\n        else {\r\n            throw new Error(\"Invalid log level\");\r\n        }\r\n    }\r\n    \r\n    static get logger(){\r\n        return logger;\r\n    }\r\n    static set logger(value){\r\n        if (!value.debug && value.info) {\r\n            // just to stay backwards compat. can remove in 2.0\r\n            value.debug = value.info;\r\n        }\r\n\r\n        if (value.debug && value.info && value.warn && value.error){\r\n            logger = value;\r\n        }\r\n        else {\r\n            throw new Error(\"Invalid logger\");\r\n        }\r\n    }\r\n    \r\n    static debug(...args){\r\n        if (level >= DEBUG){\r\n            logger.debug.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static info(...args){\r\n        if (level >= INFO){\r\n            logger.info.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static warn(...args){\r\n        if (level >= WARN){\r\n            logger.warn.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static error(...args){\r\n        if (level >= ERROR){\r\n            logger.error.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n}\r\n\r\nLog.reset();\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { JsonService } from './JsonService.js';\r\n\r\nconst OidcMetadataUrlPath = '.well-known/openid-configuration';\r\n\r\nexport class MetadataService {\r\n    constructor(settings, JsonServiceCtor = JsonService) {\r\n        if (!settings) {\r\n            Log.error(\"MetadataService: No settings passed to MetadataService\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor(['application/jwk-set+json']);\r\n    }\r\n\r\n    get metadataUrl() {\r\n        if (!this._metadataUrl) {\r\n            if (this._settings.metadataUrl) {\r\n                this._metadataUrl = this._settings.metadataUrl;\r\n            }\r\n            else {\r\n                this._metadataUrl = this._settings.authority;\r\n\r\n                if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\r\n                    if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\r\n                        this._metadataUrl += '/';\r\n                    }\r\n                    this._metadataUrl += OidcMetadataUrlPath;\r\n                }\r\n            }\r\n        }\r\n\r\n        return this._metadataUrl;\r\n    }\r\n\r\n    getMetadata() {\r\n        if (this._settings.metadata) {\r\n            Log.debug(\"MetadataService.getMetadata: Returning metadata from settings\");\r\n            return Promise.resolve(this._settings.metadata);\r\n        }\r\n\r\n        if (!this.metadataUrl) {\r\n            Log.error(\"MetadataService.getMetadata: No authority or metadataUrl configured on settings\");\r\n            return Promise.reject(new Error(\"No authority or metadataUrl configured on settings\"));\r\n        }\r\n\r\n        Log.debug(\"MetadataService.getMetadata: getting metadata from\", this.metadataUrl);\r\n\r\n        return this._jsonService.getJson(this.metadataUrl)\r\n            .then(metadata => {\r\n                Log.debug(\"MetadataService.getMetadata: json received\");\r\n                this._settings.metadata = metadata;\r\n                return metadata;\r\n            });\r\n    }\r\n\r\n    getIssuer() {\r\n        return this._getMetadataProperty(\"issuer\");\r\n    }\r\n\r\n    getAuthorizationEndpoint() {\r\n        return this._getMetadataProperty(\"authorization_endpoint\");\r\n    }\r\n\r\n    getUserInfoEndpoint() {\r\n        return this._getMetadataProperty(\"userinfo_endpoint\");\r\n    }\r\n\r\n    getTokenEndpoint(optional=true) {\r\n        return this._getMetadataProperty(\"token_endpoint\", optional);\r\n    }\r\n\r\n    getCheckSessionIframe() {\r\n        return this._getMetadataProperty(\"check_session_iframe\", true);\r\n    }\r\n\r\n    getEndSessionEndpoint() {\r\n        return this._getMetadataProperty(\"end_session_endpoint\", true);\r\n    }\r\n\r\n    getRevocationEndpoint() {\r\n        return this._getMetadataProperty(\"revocation_endpoint\", true);\r\n    }\r\n\r\n    getKeysEndpoint() {\r\n        return this._getMetadataProperty(\"jwks_uri\", true);\r\n    }\r\n\r\n    _getMetadataProperty(name, optional=false) {\r\n        Log.debug(\"MetadataService.getMetadataProperty for: \" + name);\r\n\r\n        return this.getMetadata().then(metadata => {\r\n            Log.debug(\"MetadataService.getMetadataProperty: metadata recieved\");\r\n\r\n            if (metadata[name] === undefined) {\r\n\r\n                if (optional === true) {\r\n                    Log.warn(\"MetadataService.getMetadataProperty: Metadata does not contain optional property \" + name);\r\n                    return undefined;\r\n                }\r\n                else {\r\n                    Log.error(\"MetadataService.getMetadataProperty: Metadata does not contain property \" + name);\r\n                    throw new Error(\"Metadata does not contain property \" + name);\r\n                }\r\n            }\r\n\r\n            return metadata[name];\r\n        });\r\n    }\r\n\r\n    getSigningKeys() {\r\n        if (this._settings.signingKeys) {\r\n            Log.debug(\"MetadataService.getSigningKeys: Returning signingKeys from settings\");\r\n            return Promise.resolve(this._settings.signingKeys);\r\n        }\r\n\r\n        return this._getMetadataProperty(\"jwks_uri\").then(jwks_uri => {\r\n            Log.debug(\"MetadataService.getSigningKeys: jwks_uri received\", jwks_uri);\r\n\r\n            return this._jsonService.getJson(jwks_uri).then(keySet => {\r\n                Log.debug(\"MetadataService.getSigningKeys: key set received\", keySet);\r\n\r\n                if (!keySet.keys) {\r\n                    Log.error(\"MetadataService.getSigningKeys: Missing keys on keyset\");\r\n                    throw new Error(\"Missing keys on keyset\");\r\n                }\r\n\r\n                this._settings.signingKeys = keySet.keys;\r\n                return this._settings.signingKeys;\r\n            });\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClientSettings } from './OidcClientSettings.js';\r\nimport { ErrorResponse } from './ErrorResponse.js';\r\nimport { SigninRequest } from './SigninRequest.js';\r\nimport { SigninResponse } from './SigninResponse.js';\r\nimport { SignoutRequest } from './SignoutRequest.js';\r\nimport { SignoutResponse } from './SignoutResponse.js';\r\nimport { SigninState } from './SigninState.js';\r\nimport { State } from './State.js';\r\n\r\nexport class OidcClient {\r\n    constructor(settings = {}) {\r\n        if (settings instanceof OidcClientSettings) {\r\n            this._settings = settings;\r\n        }\r\n        else {\r\n            this._settings = new OidcClientSettings(settings);\r\n        }\r\n    }\r\n\r\n    get _stateStore() {\r\n        return this.settings.stateStore;\r\n    }\r\n    get _validator() {\r\n        return this.settings.validator;\r\n    }\r\n    get _metadataService() {\r\n        return this.settings.metadataService;\r\n    }\r\n\r\n    get settings() {\r\n        return this._settings;\r\n    }\r\n    get metadataService() {\r\n        return this._metadataService;\r\n    }\r\n\r\n    createSigninRequest({\r\n        response_type, scope, redirect_uri,\r\n        // data was meant to be the place a caller could indicate the data to\r\n        // have round tripped, but people were getting confused, so i added state (since that matches the spec)\r\n        // and so now if data is not passed, but state is then state will be used\r\n        data, state, prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values,\r\n        resource, request, request_uri, response_mode, extraQueryParams, extraTokenParams, request_type, skipUserInfo } = {},\r\n        stateStore\r\n    ) {\r\n        Log.debug(\"OidcClient.createSigninRequest\");\r\n\r\n        let client_id = this._settings.client_id;\r\n        response_type = response_type || this._settings.response_type;\r\n        scope = scope || this._settings.scope;\r\n        redirect_uri = redirect_uri || this._settings.redirect_uri;\r\n\r\n        // id_token_hint, login_hint aren't allowed on _settings\r\n        prompt = prompt || this._settings.prompt;\r\n        display = display || this._settings.display;\r\n        max_age = max_age || this._settings.max_age;\r\n        ui_locales = ui_locales || this._settings.ui_locales;\r\n        acr_values = acr_values || this._settings.acr_values;\r\n        resource = resource || this._settings.resource;\r\n        response_mode = response_mode || this._settings.response_mode;\r\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\r\n        extraTokenParams = extraTokenParams || this._settings.extraTokenParams;\r\n\r\n        let authority = this._settings.authority;\r\n\r\n        if (SigninRequest.isCode(response_type) && response_type !== \"code\") {\r\n            return Promise.reject(new Error(\"OpenID Connect hybrid flow is not supported\"));\r\n        }\r\n\r\n        return this._metadataService.getAuthorizationEndpoint().then(url => {\r\n            Log.debug(\"OidcClient.createSigninRequest: Received authorization endpoint\", url);\r\n\r\n            let signinRequest = new SigninRequest({\r\n                url,\r\n                client_id,\r\n                redirect_uri,\r\n                response_type,\r\n                scope,\r\n                data: data || state,\r\n                authority,\r\n                prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values,\r\n                resource, request, request_uri, extraQueryParams, extraTokenParams, request_type, response_mode,\r\n                client_secret: this._settings.client_secret,\r\n                skipUserInfo\r\n            });\r\n\r\n            var signinState = signinRequest.state;\r\n            stateStore = stateStore || this._stateStore;\r\n\r\n            return stateStore.set(signinState.id, signinState.toStorageString()).then(() => {\r\n                return signinRequest;\r\n            });\r\n        });\r\n    }\r\n\r\n    readSigninResponseState(url, stateStore, removeState = false) {\r\n        Log.debug(\"OidcClient.readSigninResponseState\");\r\n\r\n        let useQuery = this._settings.response_mode === \"query\" || \r\n            (!this._settings.response_mode && SigninRequest.isCode(this._settings.response_type));\r\n        let delimiter = useQuery ? \"?\" : \"#\";\r\n\r\n        var response = new SigninResponse(url, delimiter);\r\n\r\n        if (!response.state) {\r\n            Log.error(\"OidcClient.readSigninResponseState: No state in response\");\r\n            return Promise.reject(new Error(\"No state in response\"));\r\n        }\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\r\n\r\n        return stateApi(response.state).then(storedStateString => {\r\n            if (!storedStateString) {\r\n                Log.error(\"OidcClient.readSigninResponseState: No matching state found in storage\");\r\n                throw new Error(\"No matching state found in storage\");\r\n            }\r\n\r\n            let state = SigninState.fromStorageString(storedStateString);\r\n            return {state, response};\r\n        });\r\n    }\r\n\r\n    processSigninResponse(url, stateStore) {\r\n        Log.debug(\"OidcClient.processSigninResponse\");\r\n\r\n        return this.readSigninResponseState(url, stateStore, true).then(({state, response}) => {\r\n            Log.debug(\"OidcClient.processSigninResponse: Received state from storage; validating response\");\r\n            return this._validator.validateSigninResponse(state, response);\r\n        });\r\n    }\r\n\r\n    createSignoutRequest({id_token_hint, data, state, post_logout_redirect_uri, extraQueryParams, request_type } = {},\r\n        stateStore\r\n    ) {\r\n        Log.debug(\"OidcClient.createSignoutRequest\");\r\n\r\n        post_logout_redirect_uri = post_logout_redirect_uri || this._settings.post_logout_redirect_uri;\r\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\r\n\r\n        return this._metadataService.getEndSessionEndpoint().then(url => {\r\n            if (!url) {\r\n                Log.error(\"OidcClient.createSignoutRequest: No end session endpoint url returned\");\r\n                throw new Error(\"no end session endpoint\");\r\n            }\r\n\r\n            Log.debug(\"OidcClient.createSignoutRequest: Received end session endpoint\", url);\r\n\r\n            let request = new SignoutRequest({\r\n                url,\r\n                id_token_hint,\r\n                post_logout_redirect_uri,\r\n                data: data || state,\r\n                extraQueryParams,\r\n                request_type\r\n            });\r\n\r\n            var signoutState = request.state;\r\n            if (signoutState) {\r\n                Log.debug(\"OidcClient.createSignoutRequest: Signout request has state to persist\");\r\n\r\n                stateStore = stateStore || this._stateStore;\r\n                stateStore.set(signoutState.id, signoutState.toStorageString());\r\n            }\r\n\r\n            return request;\r\n        });\r\n    }\r\n\r\n    readSignoutResponseState(url, stateStore, removeState = false) {\r\n        Log.debug(\"OidcClient.readSignoutResponseState\");\r\n\r\n        var response = new SignoutResponse(url);\r\n        if (!response.state) {\r\n            Log.debug(\"OidcClient.readSignoutResponseState: No state in response\");\r\n\r\n            if (response.error) {\r\n                Log.warn(\"OidcClient.readSignoutResponseState: Response was error: \", response.error);\r\n                return Promise.reject(new ErrorResponse(response));\r\n            }\r\n\r\n            return Promise.resolve({undefined, response});\r\n        }\r\n\r\n        var stateKey = response.state;\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\r\n        return stateApi(stateKey).then(storedStateString => {\r\n            if (!storedStateString) {\r\n                Log.error(\"OidcClient.readSignoutResponseState: No matching state found in storage\");\r\n                throw new Error(\"No matching state found in storage\");\r\n            }\r\n\r\n            let state = State.fromStorageString(storedStateString);\r\n\r\n            return {state, response};\r\n        });\r\n    }\r\n\r\n    processSignoutResponse(url, stateStore) {\r\n        Log.debug(\"OidcClient.processSignoutResponse\");\r\n\r\n        return this.readSignoutResponseState(url, stateStore, true).then(({state, response}) => {\r\n            if (state) {\r\n                Log.debug(\"OidcClient.processSignoutResponse: Received state from storage; validating response\");\r\n                return this._validator.validateSignoutResponse(state, response);\r\n            }\r\n            else {\r\n                Log.debug(\"OidcClient.processSignoutResponse: No state from storage; skipping validating response\");\r\n                return response;\r\n            }\r\n        });\r\n    }\r\n\r\n    clearStaleState(stateStore) {\r\n        Log.debug(\"OidcClient.clearStaleState\");\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        return State.clearStaleState(stateStore, this.settings.staleStateAge);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { WebStorageStateStore } from './WebStorageStateStore.js';\r\nimport { ResponseValidator } from './ResponseValidator.js';\r\nimport { MetadataService } from './MetadataService.js';\r\n\r\nconst OidcMetadataUrlPath = '.well-known/openid-configuration';\r\n\r\nconst DefaultResponseType = \"id_token\";\r\nconst DefaultScope = \"openid\";\r\nconst DefaultStaleStateAge = 60 * 15; // seconds\r\nconst DefaultClockSkewInSeconds = 60 * 5;\r\n\r\nexport class OidcClientSettings {\r\n    constructor({\r\n        // metadata related\r\n        authority, metadataUrl, metadata, signingKeys,\r\n        // client related\r\n        client_id, client_secret, response_type = DefaultResponseType, scope = DefaultScope,\r\n        redirect_uri, post_logout_redirect_uri,\r\n        // optional protocol\r\n        prompt, display, max_age, ui_locales, acr_values, resource, response_mode,\r\n        // behavior flags\r\n        filterProtocolClaims = true, loadUserInfo = true,\r\n        staleStateAge = DefaultStaleStateAge, clockSkew = DefaultClockSkewInSeconds,\r\n        userInfoJwtIssuer = 'OP',\r\n        // other behavior\r\n        stateStore = new WebStorageStateStore(),\r\n        ResponseValidatorCtor = ResponseValidator,\r\n        MetadataServiceCtor = MetadataService,\r\n        // extra query params\r\n        extraQueryParams = {},\r\n        extraTokenParams = {}\r\n    } = {}) {\r\n\r\n        this._authority = authority;\r\n        this._metadataUrl = metadataUrl;\r\n        this._metadata = metadata;\r\n        this._signingKeys = signingKeys;\r\n\r\n        this._client_id = client_id;\r\n        this._client_secret = client_secret;\r\n        this._response_type = response_type;\r\n        this._scope = scope;\r\n        this._redirect_uri = redirect_uri;\r\n        this._post_logout_redirect_uri = post_logout_redirect_uri;\r\n\r\n        this._prompt = prompt;\r\n        this._display = display;\r\n        this._max_age = max_age;\r\n        this._ui_locales = ui_locales;\r\n        this._acr_values = acr_values;\r\n        this._resource = resource;\r\n        this._response_mode = response_mode;\r\n\r\n        this._filterProtocolClaims = !!filterProtocolClaims;\r\n        this._loadUserInfo = !!loadUserInfo;\r\n        this._staleStateAge = staleStateAge;\r\n        this._clockSkew = clockSkew;\r\n        this._userInfoJwtIssuer = userInfoJwtIssuer;\r\n\r\n        this._stateStore = stateStore;\r\n        this._validator = new ResponseValidatorCtor(this);\r\n        this._metadataService = new MetadataServiceCtor(this);\r\n\r\n        this._extraQueryParams = typeof extraQueryParams === 'object' ? extraQueryParams : {};\r\n        this._extraTokenParams = typeof extraTokenParams === 'object' ? extraTokenParams : {};\r\n    }\r\n\r\n    // client config\r\n    get client_id() {\r\n        return this._client_id;\r\n    }\r\n    set client_id(value) {\r\n        if (!this._client_id) {\r\n            // one-time set only\r\n            this._client_id = value;\r\n        }\r\n        else {\r\n            Log.error(\"OidcClientSettings.set_client_id: client_id has already been assigned.\")\r\n            throw new Error(\"client_id has already been assigned.\")\r\n        }\r\n    }\r\n    get client_secret() {\r\n        return this._client_secret;\r\n    }\r\n    get response_type() {\r\n        return this._response_type;\r\n    }\r\n    get scope() {\r\n        return this._scope;\r\n    }\r\n    get redirect_uri() {\r\n        return this._redirect_uri;\r\n    }\r\n    get post_logout_redirect_uri() {\r\n        return this._post_logout_redirect_uri;\r\n    }\r\n\r\n\r\n    // optional protocol params\r\n    get prompt() {\r\n        return this._prompt;\r\n    }\r\n    get display() {\r\n        return this._display;\r\n    }\r\n    get max_age() {\r\n        return this._max_age;\r\n    }\r\n    get ui_locales() {\r\n        return this._ui_locales;\r\n    }\r\n    get acr_values() {\r\n        return this._acr_values;\r\n    }\r\n    get resource() {\r\n        return this._resource;\r\n    }\r\n    get response_mode() {\r\n        return this._response_mode;\r\n    }\r\n\r\n\r\n    // metadata\r\n    get authority() {\r\n        return this._authority;\r\n    }\r\n    set authority(value) {\r\n        if (!this._authority) {\r\n            // one-time set only\r\n            this._authority = value;\r\n        }\r\n        else {\r\n            Log.error(\"OidcClientSettings.set_authority: authority has already been assigned.\")\r\n            throw new Error(\"authority has already been assigned.\")\r\n        }\r\n    }\r\n    get metadataUrl() {\r\n        if (!this._metadataUrl) {\r\n            this._metadataUrl = this.authority;\r\n\r\n            if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\r\n                if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\r\n                    this._metadataUrl += '/';\r\n                }\r\n                this._metadataUrl += OidcMetadataUrlPath;\r\n            }\r\n        }\r\n\r\n        return this._metadataUrl;\r\n    }\r\n\r\n    // settable/cachable metadata values\r\n    get metadata() {\r\n        return this._metadata;\r\n    }\r\n    set metadata(value) {\r\n        this._metadata = value;\r\n    }\r\n\r\n    get signingKeys() {\r\n        return this._signingKeys;\r\n    }\r\n    set signingKeys(value) {\r\n        this._signingKeys = value;\r\n    }\r\n\r\n    // behavior flags\r\n    get filterProtocolClaims() {\r\n        return this._filterProtocolClaims;\r\n    }\r\n    get loadUserInfo() {\r\n        return this._loadUserInfo;\r\n    }\r\n    get staleStateAge() {\r\n        return this._staleStateAge;\r\n    }\r\n    get clockSkew() {\r\n        return this._clockSkew;\r\n    }\r\n    get userInfoJwtIssuer() {\r\n        return this._userInfoJwtIssuer;\r\n    }\r\n\r\n    get stateStore() {\r\n        return this._stateStore;\r\n    }\r\n    get validator() {\r\n        return this._validator;\r\n    }\r\n    get metadataService() {\r\n        return this._metadataService;\r\n    }\r\n\r\n    // extra query params\r\n    get extraQueryParams() {\r\n        return this._extraQueryParams;\r\n    }\r\n    set extraQueryParams(value) {\r\n        if (typeof value === 'object'){\r\n            this._extraQueryParams = value;\r\n        } else {\r\n            this._extraQueryParams = {};\r\n        }\r\n    }\r\n\r\n    // extra token params\r\n    get extraTokenParams() {\r\n        return this._extraTokenParams;\r\n    }\r\n    set extraTokenParams(value) {\r\n        if (typeof value === 'object'){\r\n            this._extraTokenParams = value;\r\n        } else {\r\n            this._extraTokenParams = {};\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { PopupWindow } from './PopupWindow.js';\r\n\r\nexport class PopupNavigator {\r\n\r\n    prepare(params) {\r\n        let popup = new PopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n\r\n    callback(url, keepOpen, delimiter) {\r\n        Log.debug(\"PopupNavigator.callback\");\r\n\r\n        try {\r\n            PopupWindow.notifyOpener(url, keepOpen, delimiter);\r\n            return Promise.resolve();\r\n        }\r\n        catch (e) {\r\n            return Promise.reject(e);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nconst CheckForPopupClosedInterval = 500;\r\nconst DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;';\r\n//const DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;resizable=yes';\r\n\r\nconst DefaultPopupTarget = \"_blank\";\r\n\r\nexport class PopupWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        let target = params.popupWindowTarget || DefaultPopupTarget;\r\n        let features = params.popupWindowFeatures || DefaultPopupFeatures;\r\n\r\n        this._popup = window.open('', target, features);\r\n        if (this._popup) {\r\n            Log.debug(\"PopupWindow.ctor: popup successfully created\");\r\n            this._checkForPopupClosedTimer = window.setInterval(this._checkForPopupClosed.bind(this), CheckForPopupClosedInterval);\r\n        }\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!this._popup) {\r\n            this._error(\"PopupWindow.navigate: Error opening popup window\");\r\n        }\r\n        else if (!params || !params.url) {\r\n            this._error(\"PopupWindow.navigate: no url provided\");\r\n            this._error(\"No url provided\");\r\n        }\r\n        else {\r\n            Log.debug(\"PopupWindow.navigate: Setting URL in popup\");\r\n\r\n            this._id = params.id;\r\n            if (this._id) {\r\n                window[\"popupCallback_\" + params.id] = this._callback.bind(this);\r\n            }\r\n\r\n            this._popup.focus();\r\n            this._popup.window.location = params.url;\r\n        }\r\n\r\n        return this.promise;\r\n    }\r\n\r\n    _success(data) {\r\n        Log.debug(\"PopupWindow.callback: Successful response from popup window\");\r\n\r\n        this._cleanup();\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        Log.error(\"PopupWindow.error: \", message);\r\n        \r\n        this._cleanup();\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup(false);\r\n    }\r\n\r\n    _cleanup(keepOpen) {\r\n        Log.debug(\"PopupWindow.cleanup\");\r\n\r\n        window.clearInterval(this._checkForPopupClosedTimer);\r\n        this._checkForPopupClosedTimer = null;\r\n\r\n        delete window[\"popupCallback_\" + this._id];\r\n\r\n        if (this._popup && !keepOpen) {\r\n            this._popup.close();\r\n        }\r\n        this._popup = null;\r\n    }\r\n\r\n    _checkForPopupClosed() {\r\n        if (!this._popup || this._popup.closed) {\r\n            this._error(\"Popup window closed\");\r\n        }\r\n    }\r\n\r\n    _callback(url, keepOpen) {\r\n        this._cleanup(keepOpen);\r\n\r\n        if (url) {\r\n            Log.debug(\"PopupWindow.callback success\");\r\n            this._success({ url: url });\r\n        }\r\n        else {\r\n            Log.debug(\"PopupWindow.callback: Invalid response from popup\");\r\n            this._error(\"Invalid response from popup\");\r\n        }\r\n    }\r\n\r\n    static notifyOpener(url, keepOpen, delimiter) {\r\n        if (window.opener) {\r\n            url = url || window.location.href;\r\n            if (url) {\r\n                var data = UrlUtility.parseUrlFragment(url, delimiter);\r\n\r\n                if (data.state) {\r\n                    var name = \"popupCallback_\" + data.state;\r\n                    var callback = window.opener[name];\r\n                    if (callback) {\r\n                        Log.debug(\"PopupWindow.notifyOpener: passing url message to opener\");\r\n                        callback(url, keepOpen);\r\n                    }\r\n                    else {\r\n                        Log.warn(\"PopupWindow.notifyOpener: no matching callback found on opener\");\r\n                    }\r\n                }\r\n                else {\r\n                    Log.warn(\"PopupWindow.notifyOpener: no state found in response url\");\r\n                }\r\n            }\r\n        }\r\n        else {\r\n            Log.warn(\"PopupWindow.notifyOpener: no window.opener. Can't complete notification.\");\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class RedirectNavigator {\r\n\r\n    prepare() {\r\n        return Promise.resolve(this);\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            Log.error(\"RedirectNavigator.navigate: No url provided\");\r\n            return Promise.reject(new Error(\"No url provided\"));\r\n        }\r\n\r\n        if (params.useReplaceToNavigate) {\r\n            window.location.replace(params.url);\r\n        }\r\n        else {\r\n            window.location = params.url;\r\n        }\r\n\r\n        return Promise.resolve();\r\n    }\r\n\r\n    get url() {\r\n        return window.location.href;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { UserInfoService } from './UserInfoService.js';\r\nimport { TokenClient } from './TokenClient.js';\r\nimport { ErrorResponse } from './ErrorResponse.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\nconst ProtocolClaims = [\"nonce\", \"at_hash\", \"iat\", \"nbf\", \"exp\", \"aud\", \"iss\", \"c_hash\"];\r\n\r\nexport class ResponseValidator {\r\n\r\n    constructor(settings, \r\n        MetadataServiceCtor = MetadataService,\r\n        UserInfoServiceCtor = UserInfoService, \r\n        joseUtil = JoseUtil,\r\n        TokenClientCtor = TokenClient) {\r\n        if (!settings) {\r\n            Log.error(\"ResponseValidator.ctor: No settings passed to ResponseValidator\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n        this._userInfoService = new UserInfoServiceCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n        this._tokenClient = new TokenClientCtor(this._settings);\r\n    }\r\n\r\n    validateSigninResponse(state, response) {\r\n        Log.debug(\"ResponseValidator.validateSigninResponse\");\r\n\r\n        return this._processSigninParams(state, response).then(response => {\r\n            Log.debug(\"ResponseValidator.validateSigninResponse: state processed\");\r\n            return this._validateTokens(state, response).then(response => {\r\n                Log.debug(\"ResponseValidator.validateSigninResponse: tokens validated\");\r\n                return this._processClaims(state, response).then(response => {\r\n                    Log.debug(\"ResponseValidator.validateSigninResponse: claims processed\");\r\n                    return response;\r\n                });\r\n            });\r\n        });\r\n    }\r\n\r\n    validateSignoutResponse(state, response) {\r\n        if (state.id !== response.state) {\r\n            Log.error(\"ResponseValidator.validateSignoutResponse: State does not match\");\r\n            return Promise.reject(new Error(\"State does not match\"));\r\n        }\r\n\r\n        // now that we know the state matches, take the stored data\r\n        // and set it into the response so callers can get their state\r\n        // this is important for both success & error outcomes\r\n        Log.debug(\"ResponseValidator.validateSignoutResponse: state validated\");\r\n        response.state = state.data;\r\n\r\n        if (response.error) {\r\n            Log.warn(\"ResponseValidator.validateSignoutResponse: Response was error\", response.error);\r\n            return Promise.reject(new ErrorResponse(response));\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processSigninParams(state, response) {\r\n        if (state.id !== response.state) {\r\n            Log.error(\"ResponseValidator._processSigninParams: State does not match\");\r\n            return Promise.reject(new Error(\"State does not match\"));\r\n        }\r\n\r\n        if (!state.client_id) {\r\n            Log.error(\"ResponseValidator._processSigninParams: No client_id on state\");\r\n            return Promise.reject(new Error(\"No client_id on state\"));\r\n        }\r\n\r\n        if (!state.authority) {\r\n            Log.error(\"ResponseValidator._processSigninParams: No authority on state\");\r\n            return Promise.reject(new Error(\"No authority on state\"));\r\n        }\r\n\r\n        // this allows the authority to be loaded from the signin state\r\n        if (!this._settings.authority) {\r\n            this._settings.authority = state.authority;\r\n        }\r\n        // ensure we're using the correct authority if the authority is not loaded from signin state\r\n        else if (this._settings.authority && this._settings.authority !== state.authority) {\r\n            Log.error(\"ResponseValidator._processSigninParams: authority mismatch on settings vs. signin state\");\r\n            return Promise.reject(new Error(\"authority mismatch on settings vs. signin state\"));\r\n        }\r\n        // this allows the client_id to be loaded from the signin state\r\n        if (!this._settings.client_id) {\r\n            this._settings.client_id = state.client_id;\r\n        }\r\n        // ensure we're using the correct client_id if the client_id is not loaded from signin state\r\n        else if (this._settings.client_id && this._settings.client_id !== state.client_id) {\r\n            Log.error(\"ResponseValidator._processSigninParams: client_id mismatch on settings vs. signin state\");\r\n            return Promise.reject(new Error(\"client_id mismatch on settings vs. signin state\"));\r\n        }\r\n\r\n        // now that we know the state matches, take the stored data\r\n        // and set it into the response so callers can get their state\r\n        // this is important for both success & error outcomes\r\n        Log.debug(\"ResponseValidator._processSigninParams: state validated\");\r\n        response.state = state.data;\r\n\r\n        if (response.error) {\r\n            Log.warn(\"ResponseValidator._processSigninParams: Response was error\", response.error);\r\n            return Promise.reject(new ErrorResponse(response));\r\n        }\r\n\r\n        if (state.nonce && !response.id_token) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Expecting id_token in response\");\r\n            return Promise.reject(new Error(\"No id_token in response\"));\r\n        }\r\n\r\n        if (!state.nonce && response.id_token) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Not expecting id_token in response\");\r\n            return Promise.reject(new Error(\"Unexpected id_token in response\"));\r\n        }\r\n\r\n        if (state.code_verifier && !response.code) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Expecting code in response\");\r\n            return Promise.reject(new Error(\"No code in response\"));\r\n        }\r\n\r\n        if (!state.code_verifier && response.code) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Not expecting code in response\");\r\n            return Promise.reject(new Error(\"Unexpected code in response\"));\r\n        }\r\n\r\n        if (!response.scope) {\r\n            // if there's no scope on the response, then assume all scopes granted (per-spec) and copy over scopes from original request\r\n            response.scope = state.scope;\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processClaims(state, response) {\r\n        if (response.isOpenIdConnect) {\r\n            Log.debug(\"ResponseValidator._processClaims: response is OIDC, processing claims\");\r\n\r\n            response.profile = this._filterProtocolClaims(response.profile);\r\n\r\n            if (state.skipUserInfo !== true && this._settings.loadUserInfo && response.access_token) {\r\n                Log.debug(\"ResponseValidator._processClaims: loading user info\");\r\n\r\n                return this._userInfoService.getClaims(response.access_token).then(claims => {\r\n                    Log.debug(\"ResponseValidator._processClaims: user info claims received from user info endpoint\");\r\n\r\n                    if (claims.sub !== response.profile.sub) {\r\n                        Log.error(\"ResponseValidator._processClaims: sub from user info endpoint does not match sub in access_token\");\r\n                        return Promise.reject(new Error(\"sub from user info endpoint does not match sub in access_token\"));\r\n                    }\r\n\r\n                    response.profile = this._mergeClaims(response.profile, claims);\r\n                    Log.debug(\"ResponseValidator._processClaims: user info claims received, updated profile:\", response.profile);\r\n\r\n                    return response;\r\n                });\r\n            }\r\n            else {\r\n                Log.debug(\"ResponseValidator._processClaims: not loading user info\");\r\n            }\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._processClaims: response is not OIDC, not processing claims\");\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _mergeClaims(claims1, claims2) {\r\n        var result = Object.assign({}, claims1);\r\n\r\n        for (let name in claims2) {\r\n            var values = claims2[name];\r\n            if (!Array.isArray(values)) {\r\n                values = [values];\r\n            }\r\n\r\n            for (let i = 0; i < values.length; i++) {\r\n                let value = values[i];\r\n                if (!result[name]) {\r\n                    result[name] = value;\r\n                }\r\n                else if (Array.isArray(result[name])) {\r\n                    if (result[name].indexOf(value) < 0) {\r\n                        result[name].push(value);\r\n                    }\r\n                }\r\n                else if (result[name] !== value) {\r\n                    if (typeof value === 'object') {\r\n                        result[name] = this._mergeClaims(result[name], value);\r\n                    } \r\n                    else {\r\n                        result[name] = [result[name], value];\r\n                    }\r\n                }\r\n            }\r\n        }\r\n\r\n        return result;\r\n    }\r\n\r\n    _filterProtocolClaims(claims) {\r\n        Log.debug(\"ResponseValidator._filterProtocolClaims, incoming claims:\", claims);\r\n\r\n        var result = Object.assign({}, claims);\r\n\r\n        if (this._settings._filterProtocolClaims) {\r\n            ProtocolClaims.forEach(type => {\r\n                delete result[type];\r\n            });\r\n\r\n            Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims filtered\", result);\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims not filtered\")\r\n        }\r\n\r\n        return result;\r\n    }\r\n\r\n    _validateTokens(state, response) {\r\n        if (response.code) {\r\n            Log.debug(\"ResponseValidator._validateTokens: Validating code\");\r\n            return this._processCode(state, response);\r\n        }\r\n\r\n        if (response.id_token) {\r\n            if (response.access_token) {\r\n                Log.debug(\"ResponseValidator._validateTokens: Validating id_token and access_token\");\r\n                return this._validateIdTokenAndAccessToken(state, response);\r\n            }\r\n\r\n            Log.debug(\"ResponseValidator._validateTokens: Validating id_token\");\r\n            return this._validateIdToken(state, response);\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._validateTokens: No code to process or id_token to validate\");\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processCode(state, response) {\r\n        var request = {\r\n            client_id: state.client_id,\r\n            client_secret: state.client_secret,\r\n            code : response.code,\r\n            redirect_uri: state.redirect_uri,\r\n            code_verifier: state.code_verifier\r\n        };\r\n\r\n        if (state.extraTokenParams && typeof(state.extraTokenParams) === 'object') {\r\n            Object.assign(request, state.extraTokenParams);\r\n        }\r\n        \r\n        return this._tokenClient.exchangeCode(request).then(tokenResponse => {\r\n            \r\n            for(var key in tokenResponse) {\r\n                response[key] = tokenResponse[key];\r\n            }\r\n\r\n            if (response.id_token) {\r\n                Log.debug(\"ResponseValidator._processCode: token response successful, processing id_token\");\r\n                return this._validateIdTokenAttributes(state, response);\r\n            }\r\n            else {\r\n                Log.debug(\"ResponseValidator._processCode: token response successful, returning response\");\r\n            }\r\n            \r\n            return response;\r\n        });\r\n    }\r\n\r\n    _validateIdTokenAttributes(state, response) {\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n\r\n            let audience = state.client_id;\r\n            let clockSkewInSeconds = this._settings.clockSkew;\r\n            Log.debug(\"ResponseValidator._validateIdTokenAttributes: Validaing JWT attributes; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n            return this._joseUtil.validateJwtAttributes(response.id_token, issuer, audience, clockSkewInSeconds).then(payload => {\r\n            \r\n                if (state.nonce && state.nonce !== payload.nonce) {\r\n                    Log.error(\"ResponseValidator._validateIdTokenAttributes: Invalid nonce in id_token\");\r\n                    return Promise.reject(new Error(\"Invalid nonce in id_token\"));\r\n                }\r\n\r\n                if (!payload.sub) {\r\n                    Log.error(\"ResponseValidator._validateIdTokenAttributes: No sub present in id_token\");\r\n                    return Promise.reject(new Error(\"No sub present in id_token\"));\r\n                }\r\n\r\n                response.profile = payload;\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n\r\n    _validateIdTokenAndAccessToken(state, response) {\r\n        return this._validateIdToken(state, response).then(response => {\r\n            return this._validateAccessToken(response);\r\n        });\r\n    }\r\n\r\n    _validateIdToken(state, response) {\r\n        if (!state.nonce) {\r\n            Log.error(\"ResponseValidator._validateIdToken: No nonce on state\");\r\n            return Promise.reject(new Error(\"No nonce on state\"));\r\n        }\r\n\r\n        let jwt = this._joseUtil.parseJwt(response.id_token);\r\n        if (!jwt || !jwt.header || !jwt.payload) {\r\n            Log.error(\"ResponseValidator._validateIdToken: Failed to parse id_token\", jwt);\r\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n        }\r\n\r\n        if (state.nonce !== jwt.payload.nonce) {\r\n            Log.error(\"ResponseValidator._validateIdToken: Invalid nonce in id_token\");\r\n            return Promise.reject(new Error(\"Invalid nonce in id_token\"));\r\n        }\r\n\r\n        var kid = jwt.header.kid;\r\n\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n            Log.debug(\"ResponseValidator._validateIdToken: Received issuer\");\r\n\r\n            return this._metadataService.getSigningKeys().then(keys => {\r\n                if (!keys) {\r\n                    Log.error(\"ResponseValidator._validateIdToken: No signing keys from metadata\");\r\n                    return Promise.reject(new Error(\"No signing keys from metadata\"));\r\n                }\r\n\r\n                Log.debug(\"ResponseValidator._validateIdToken: Received signing keys\");\r\n                let key;\r\n                if (!kid) {\r\n                    keys = this._filterByAlg(keys, jwt.header.alg);\r\n\r\n                    if (keys.length > 1) {\r\n                        Log.error(\"ResponseValidator._validateIdToken: No kid found in id_token and more than one key found in metadata\");\r\n                        return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\r\n                    }\r\n                    else {\r\n                        // kid is mandatory only when there are multiple keys in the referenced JWK Set document\r\n                        // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\r\n                        key = keys[0];\r\n                    }\r\n                }\r\n                else {\r\n                    key = keys.filter(key => {\r\n                        return key.kid === kid;\r\n                    })[0];\r\n                }\r\n\r\n                if (!key) {\r\n                    Log.error(\"ResponseValidator._validateIdToken: No key matching kid or alg found in signing keys\");\r\n                    return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\r\n                }\r\n\r\n                let audience = state.client_id;\r\n\r\n                let clockSkewInSeconds = this._settings.clockSkew;\r\n                Log.debug(\"ResponseValidator._validateIdToken: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n                return this._joseUtil.validateJwt(response.id_token, key, issuer, audience, clockSkewInSeconds).then(()=>{\r\n                    Log.debug(\"ResponseValidator._validateIdToken: JWT validation successful\");\r\n\r\n                    if (!jwt.payload.sub) {\r\n                        Log.error(\"ResponseValidator._validateIdToken: No sub present in id_token\");\r\n                        return Promise.reject(new Error(\"No sub present in id_token\"));\r\n                    }\r\n\r\n                    response.profile = jwt.payload;\r\n\r\n                    return response;\r\n                });\r\n            });\r\n        });\r\n    }\r\n\r\n    _filterByAlg(keys, alg){\r\n        var kty = null;\r\n        if (alg.startsWith(\"RS\")) {\r\n            kty = \"RSA\";\r\n        }\r\n        else if (alg.startsWith(\"PS\")) {\r\n            kty = \"PS\";\r\n        }\r\n        else if (alg.startsWith(\"ES\")) {\r\n            kty = \"EC\";\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._filterByAlg: alg not supported: \", alg);\r\n            return [];\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._filterByAlg: Looking for keys that match kty: \", kty);\r\n\r\n        keys = keys.filter(key => {\r\n            return key.kty === kty;\r\n        });\r\n\r\n        Log.debug(\"ResponseValidator._filterByAlg: Number of keys that match kty: \", kty, keys.length);\r\n\r\n        return keys;\r\n    }\r\n\r\n    _validateAccessToken(response) {\r\n        if (!response.profile) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No profile loaded from id_token\");\r\n            return Promise.reject(new Error(\"No profile loaded from id_token\"));\r\n        }\r\n\r\n        if (!response.profile.at_hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No at_hash in id_token\");\r\n            return Promise.reject(new Error(\"No at_hash in id_token\"));\r\n        }\r\n\r\n        if (!response.id_token) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No id_token\");\r\n            return Promise.reject(new Error(\"No id_token\"));\r\n        }\r\n\r\n        let jwt = this._joseUtil.parseJwt(response.id_token);\r\n        if (!jwt || !jwt.header) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Failed to parse id_token\", jwt);\r\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n        }\r\n\r\n        var hashAlg = jwt.header.alg;\r\n        if (!hashAlg || hashAlg.length !== 5) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        var hashBits = hashAlg.substr(2, 3);\r\n        if (!hashBits) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        hashBits = parseInt(hashBits);\r\n        if (hashBits !== 256 && hashBits !== 384 && hashBits !== 512) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        let sha = \"sha\" + hashBits;\r\n        var hash = this._joseUtil.hashString(response.access_token, sha);\r\n        if (!hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: access_token hash failed:\", sha);\r\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\r\n        }\r\n\r\n        var left = hash.substr(0, hash.length / 2);\r\n        var left_b64u = this._joseUtil.hexToBase64Url(left);\r\n        if (left_b64u !== response.profile.at_hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Failed to validate at_hash\", left_b64u, response.profile.at_hash);\r\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._validateAccessToken: success\");\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { CheckSessionIFrame } from './CheckSessionIFrame.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class SessionMonitor {\r\n\r\n    constructor(userManager, CheckSessionIFrameCtor = CheckSessionIFrame, timer = Global.timer) {\r\n        if (!userManager) {\r\n            Log.error(\"SessionMonitor.ctor: No user manager passed to SessionMonitor\");\r\n            throw new Error(\"userManager\");\r\n        }\r\n\r\n        this._userManager = userManager;\r\n        this._CheckSessionIFrameCtor = CheckSessionIFrameCtor;\r\n        this._timer = timer;\r\n\r\n        this._userManager.events.addUserLoaded(this._start.bind(this));\r\n        this._userManager.events.addUserUnloaded(this._stop.bind(this));\r\n\r\n        this._userManager.getUser().then(user => {\r\n            // doing this manually here since calling getUser \r\n            // doesn't trigger load event.\r\n            if (user) {\r\n                this._start(user);\r\n            }\r\n            else if (this._settings.monitorAnonymousSession) {\r\n                this._userManager.querySessionStatus().then(session => {\r\n                    let tmpUser = {\r\n                        session_state : session.session_state\r\n                    };\r\n                    if (session.sub && session.sid) {\r\n                        tmpUser.profile = {\r\n                            sub: session.sub,\r\n                            sid: session.sid\r\n                        };\r\n                    }\r\n                    this._start(tmpUser);\r\n                })\r\n                .catch(err => {\r\n                    // catch to suppress errors since we're in a ctor\r\n                    Log.error(\"SessionMonitor ctor: error from querySessionStatus:\", err.message);\r\n                });\r\n            }\r\n        }).catch(err => {\r\n            // catch to suppress errors since we're in a ctor\r\n            Log.error(\"SessionMonitor ctor: error from getUser:\", err.message);\r\n        });\r\n    }\r\n\r\n    get _settings() {\r\n        return this._userManager.settings;\r\n    }\r\n    get _metadataService() {\r\n        return this._userManager.metadataService;\r\n    }\r\n    get _client_id() {\r\n        return this._settings.client_id;\r\n    }\r\n    get _checkSessionInterval() {\r\n        return this._settings.checkSessionInterval;\r\n    }\r\n    get _stopCheckSessionOnError() {\r\n        return this._settings.stopCheckSessionOnError;\r\n    }\r\n\r\n    _start(user) {\r\n        let session_state = user.session_state;\r\n\r\n        if (session_state) {\r\n            if (user.profile) {\r\n                this._sub = user.profile.sub;\r\n                this._sid = user.profile.sid;\r\n                Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", sub:\", this._sub);\r\n            }\r\n            else {\r\n                this._sub = undefined;\r\n                this._sid = undefined;\r\n                Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", anonymous user\");\r\n            }\r\n\r\n            if (!this._checkSessionIFrame) {\r\n                this._metadataService.getCheckSessionIframe().then(url => {\r\n                    if (url) {\r\n                        Log.debug(\"SessionMonitor._start: Initializing check session iframe\")\r\n\r\n                        let client_id = this._client_id;\r\n                        let interval = this._checkSessionInterval;\r\n                        let stopOnError = this._stopCheckSessionOnError;\r\n\r\n                        this._checkSessionIFrame = new this._CheckSessionIFrameCtor(this._callback.bind(this), client_id, url, interval, stopOnError);\r\n                        this._checkSessionIFrame.load().then(() => {\r\n                            this._checkSessionIFrame.start(session_state);\r\n                        });\r\n                    }\r\n                    else {\r\n                        Log.warn(\"SessionMonitor._start: No check session iframe found in the metadata\");\r\n                    }\r\n                }).catch(err => {\r\n                    // catch to suppress errors since we're in non-promise callback\r\n                    Log.error(\"SessionMonitor._start: Error from getCheckSessionIframe:\", err.message);\r\n                });\r\n            }\r\n            else {\r\n                this._checkSessionIFrame.start(session_state);\r\n            }\r\n        }\r\n    }\r\n\r\n    _stop() {\r\n        this._sub = undefined;\r\n        this._sid = undefined;\r\n\r\n        if (this._checkSessionIFrame) {\r\n            Log.debug(\"SessionMonitor._stop\");\r\n            this._checkSessionIFrame.stop();\r\n        }\r\n\r\n        if (this._settings.monitorAnonymousSession) {\r\n            // using a timer to delay re-initialization to avoid race conditions during signout\r\n            let timerHandle = this._timer.setInterval(()=>{\r\n                this._timer.clearInterval(timerHandle);\r\n\r\n                this._userManager.querySessionStatus().then(session => {\r\n                    let tmpUser = {\r\n                        session_state : session.session_state\r\n                    };\r\n                    if (session.sub && session.sid) {\r\n                        tmpUser.profile = {\r\n                            sub: session.sub,\r\n                            sid: session.sid\r\n                        };\r\n                    }\r\n                    this._start(tmpUser);\r\n                })\r\n                .catch(err => {\r\n                    // catch to suppress errors since we're in a callback\r\n                    Log.error(\"SessionMonitor: error from querySessionStatus:\", err.message);\r\n                });\r\n\r\n            }, 1000);\r\n        }\r\n    }\r\n\r\n    _callback() {\r\n        this._userManager.querySessionStatus().then(session => {\r\n            var raiseEvent = true;\r\n\r\n            if (session) {\r\n                if (session.sub === this._sub) {\r\n                    raiseEvent = false;\r\n                    this._checkSessionIFrame.start(session.session_state);\r\n\r\n                    if (session.sid === this._sid) {\r\n                        Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, restarting check session iframe; session_state:\", session.session_state);\r\n                    }\r\n                    else {\r\n                        Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, session state has changed, restarting check session iframe; session_state:\", session.session_state);\r\n                        this._userManager.events._raiseUserSessionChanged();\r\n                    }\r\n                }\r\n                else {\r\n                    Log.debug(\"SessionMonitor._callback: Different subject signed into OP:\", session.sub);\r\n                }\r\n            }\r\n            else {\r\n                Log.debug(\"SessionMonitor._callback: Subject no longer signed into OP\");\r\n            }\r\n\r\n            if (raiseEvent) {\r\n                if (this._sub) {\r\n                    Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed out event\");\r\n                    this._userManager.events._raiseUserSignedOut();\r\n                }\r\n                else {\r\n                    Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed in event\");\r\n                    this._userManager.events._raiseUserSignedIn();\r\n                }\r\n            }\r\n        }).catch(err => {\r\n            if (this._sub) {\r\n                Log.debug(\"SessionMonitor._callback: Error calling queryCurrentSigninSession; raising signed out event\", err.message);\r\n                this._userManager.events._raiseUserSignedOut();\r\n            }\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\nimport { SigninState } from './SigninState.js';\r\n\r\nexport class SigninRequest {\r\n    constructor({\r\n        // mandatory\r\n        url, client_id, redirect_uri, response_type, scope, authority,\r\n        // optional\r\n        data, prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values, resource, response_mode,\r\n        request, request_uri, extraQueryParams, request_type, client_secret, extraTokenParams, skipUserInfo\r\n    }) {\r\n        if (!url) {\r\n            Log.error(\"SigninRequest.ctor: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n        if (!client_id) {\r\n            Log.error(\"SigninRequest.ctor: No client_id passed\");\r\n            throw new Error(\"client_id\");\r\n        }\r\n        if (!redirect_uri) {\r\n            Log.error(\"SigninRequest.ctor: No redirect_uri passed\");\r\n            throw new Error(\"redirect_uri\");\r\n        }\r\n        if (!response_type) {\r\n            Log.error(\"SigninRequest.ctor: No response_type passed\");\r\n            throw new Error(\"response_type\");\r\n        }\r\n        if (!scope) {\r\n            Log.error(\"SigninRequest.ctor: No scope passed\");\r\n            throw new Error(\"scope\");\r\n        }\r\n        if (!authority) {\r\n            Log.error(\"SigninRequest.ctor: No authority passed\");\r\n            throw new Error(\"authority\");\r\n        }\r\n\r\n        let oidc = SigninRequest.isOidc(response_type);\r\n        let code = SigninRequest.isCode(response_type);\r\n\r\n        if (!response_mode) {\r\n            response_mode = SigninRequest.isCode(response_type) ? \"query\" : null;\r\n        }\r\n\r\n        this.state = new SigninState({ nonce: oidc, \r\n            data, client_id, authority, redirect_uri, \r\n            code_verifier: code, \r\n            request_type, response_mode,\r\n            client_secret, scope, extraTokenParams, skipUserInfo });\r\n\r\n        url = UrlUtility.addQueryParam(url, \"client_id\", client_id);\r\n        url = UrlUtility.addQueryParam(url, \"redirect_uri\", redirect_uri);\r\n        url = UrlUtility.addQueryParam(url, \"response_type\", response_type);\r\n        url = UrlUtility.addQueryParam(url, \"scope\", scope);\r\n\r\n        url = UrlUtility.addQueryParam(url, \"state\", this.state.id);\r\n        if (oidc) {\r\n            url = UrlUtility.addQueryParam(url, \"nonce\", this.state.nonce);\r\n        }\r\n        if (code) {\r\n            url = UrlUtility.addQueryParam(url, \"code_challenge\", this.state.code_challenge);\r\n            url = UrlUtility.addQueryParam(url, \"code_challenge_method\", \"S256\");\r\n        }\r\n\r\n        var optional = { prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values, resource, request, request_uri, response_mode };\r\n        for(let key in optional){\r\n            if (optional[key]) {\r\n                url = UrlUtility.addQueryParam(url, key, optional[key]);\r\n            }\r\n        }\r\n\r\n        for(let key in extraQueryParams){\r\n            url = UrlUtility.addQueryParam(url, key, extraQueryParams[key])\r\n        }\r\n\r\n        this.url = url;\r\n    }\r\n\r\n    static isOidc(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"id_token\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n\r\n    static isOAuth(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"token\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n    \r\n    static isCode(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"code\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nconst OidcScope = \"openid\";\r\n\r\nexport class SigninResponse {\r\n    constructor(url, delimiter = \"#\") {\r\n\r\n        var values = UrlUtility.parseUrlFragment(url, delimiter);\r\n\r\n        this.error = values.error;\r\n        this.error_description = values.error_description;\r\n        this.error_uri = values.error_uri;\r\n\r\n        this.code = values.code;\r\n        this.state = values.state;\r\n        this.id_token = values.id_token;\r\n        this.session_state = values.session_state;\r\n        this.access_token = values.access_token;\r\n        this.token_type = values.token_type;\r\n        this.scope = values.scope;\r\n        this.profile = undefined; // will be set from ResponseValidator\r\n\r\n        this.expires_in = values.expires_in;\r\n    }\r\n\r\n    get expires_in() {\r\n        if (this.expires_at) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            return this.expires_at - now;\r\n        }\r\n        return undefined;\r\n    }\r\n    set expires_in(value){\r\n        let expires_in = parseInt(value);\r\n        if (typeof expires_in === 'number' && expires_in > 0) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            this.expires_at = now + expires_in;\r\n        }\r\n    }\r\n\r\n    get expired() {\r\n        let expires_in = this.expires_in;\r\n        if (expires_in !== undefined) {\r\n            return expires_in <= 0;\r\n        }\r\n        return undefined;\r\n    }\r\n\r\n    get scopes() {\r\n        return (this.scope || \"\").split(\" \");\r\n    }\r\n\r\n    get isOpenIdConnect() {\r\n        return this.scopes.indexOf(OidcScope) >= 0 || !!this.id_token;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { State } from './State.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\nimport random from './random.js';\r\n\r\nexport class SigninState extends State {\r\n    constructor({nonce, authority, client_id, redirect_uri, code_verifier, response_mode, client_secret, scope, extraTokenParams, skipUserInfo} = {}) {\r\n        super(arguments[0]);\r\n\r\n        if (nonce === true) {\r\n            this._nonce = random();\r\n        }\r\n        else if (nonce) {\r\n            this._nonce = nonce;\r\n        }\r\n\r\n        if (code_verifier === true) {\r\n            // random() produces 32 length\r\n            this._code_verifier = random() + random() + random();\r\n        }\r\n        else if (code_verifier) {\r\n            this._code_verifier = code_verifier;\r\n        }\r\n        \r\n        if (this.code_verifier) {\r\n            let hash = JoseUtil.hashString(this.code_verifier, \"SHA256\");\r\n            this._code_challenge = JoseUtil.hexToBase64Url(hash);\r\n        }\r\n\r\n        this._redirect_uri = redirect_uri;\r\n        this._authority = authority;\r\n        this._client_id = client_id;\r\n        this._response_mode = response_mode;\r\n        this._client_secret = client_secret;\r\n        this._scope = scope;\r\n        this._extraTokenParams = extraTokenParams;\r\n        this._skipUserInfo = skipUserInfo;\r\n    }\r\n\r\n    get nonce() {\r\n        return this._nonce;\r\n    }\r\n    get authority() {\r\n        return this._authority;\r\n    }\r\n    get client_id() {\r\n        return this._client_id;\r\n    }\r\n    get redirect_uri() {\r\n        return this._redirect_uri;\r\n    }\r\n    get code_verifier() {\r\n        return this._code_verifier;\r\n    }\r\n    get code_challenge() {\r\n        return this._code_challenge;\r\n    }\r\n    get response_mode() {\r\n        return this._response_mode;\r\n    }\r\n    get client_secret() {\r\n        return this._client_secret;\r\n    }\r\n    get scope() {\r\n        return this._scope;\r\n    }\r\n    get extraTokenParams() {\r\n        return this._extraTokenParams;\r\n    }\r\n    get skipUserInfo() {\r\n        return this._skipUserInfo;\r\n    }\r\n    \r\n    toStorageString() {\r\n        Log.debug(\"SigninState.toStorageString\");\r\n        return JSON.stringify({\r\n            id: this.id,\r\n            data: this.data,\r\n            created: this.created,\r\n            request_type: this.request_type,\r\n            nonce: this.nonce,\r\n            code_verifier: this.code_verifier,\r\n            redirect_uri: this.redirect_uri,\r\n            authority: this.authority,\r\n            client_id: this.client_id,\r\n            response_mode: this.response_mode,\r\n            client_secret: this.client_secret,\r\n            scope: this.scope,\r\n            extraTokenParams : this.extraTokenParams,\r\n            skipUserInfo: this.skipUserInfo\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"SigninState.fromStorageString\");\r\n        var data = JSON.parse(storageString);\r\n        return new SigninState(data);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\nimport { State } from './State.js';\r\n\r\nexport class SignoutRequest {\r\n    constructor({url, id_token_hint, post_logout_redirect_uri, data, extraQueryParams, request_type}) {\r\n        if (!url) {\r\n            Log.error(\"SignoutRequest.ctor: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        if (id_token_hint) {\r\n            url = UrlUtility.addQueryParam(url, \"id_token_hint\", id_token_hint);\r\n        }\r\n\r\n        if (post_logout_redirect_uri) {\r\n            url = UrlUtility.addQueryParam(url, \"post_logout_redirect_uri\", post_logout_redirect_uri);\r\n\r\n            if (data) {\r\n                this.state = new State({ data, request_type });\r\n\r\n                url = UrlUtility.addQueryParam(url, \"state\", this.state.id);\r\n            }\r\n        }\r\n\r\n        for(let key in extraQueryParams){\r\n            url = UrlUtility.addQueryParam(url, key, extraQueryParams[key])\r\n        }\r\n\r\n        this.url = url;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nexport class SignoutResponse {\r\n    constructor(url) {\r\n\r\n        var values = UrlUtility.parseUrlFragment(url, \"?\");\r\n\r\n        this.error = values.error;\r\n        this.error_description = values.error_description;\r\n        this.error_uri = values.error_uri;\r\n\r\n        this.state = values.state;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class SilentRenewService {\r\n\r\n    constructor(userManager) {\r\n        this._userManager = userManager;\r\n    }\r\n\r\n    start() {\r\n        if (!this._callback) {\r\n            this._callback = this._tokenExpiring.bind(this);\r\n            this._userManager.events.addAccessTokenExpiring(this._callback);\r\n\r\n            // this will trigger loading of the user so the expiring events can be initialized\r\n            this._userManager.getUser().then(user=>{\r\n                // deliberate nop\r\n            }).catch(err=>{\r\n                // catch to suppress errors since we're in a ctor\r\n                Log.error(\"SilentRenewService.start: Error from getUser:\", err.message);\r\n            });\r\n        }\r\n    }\r\n\r\n    stop() {\r\n        if (this._callback) {\r\n            this._userManager.events.removeAccessTokenExpiring(this._callback);\r\n            delete this._callback;\r\n        }\r\n    }\r\n\r\n    _tokenExpiring() {\r\n        this._userManager.signinSilent().then(user => {\r\n            Log.debug(\"SilentRenewService._tokenExpiring: Silent token renewal successful\");\r\n        }, err => {\r\n            Log.error(\"SilentRenewService._tokenExpiring: Error from signinSilent:\", err.message);\r\n            this._userManager.events._raiseSilentRenewError(err);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport random from './random.js';\r\n\r\nexport class State {\r\n    constructor({id, data, created, request_type} = {}) {\r\n        this._id = id || random();\r\n        this._data = data;\r\n\r\n        if (typeof created === 'number' && created > 0) {\r\n            this._created = created;\r\n        }\r\n        else {\r\n            this._created = parseInt(Date.now() / 1000);\r\n        }\r\n        this._request_type =  request_type;\r\n    }\r\n\r\n    get id() {\r\n        return this._id;\r\n    }\r\n    get data() {\r\n        return this._data;\r\n    }\r\n    get created() {\r\n        return this._created;\r\n    }\r\n    get request_type() {\r\n        return this._request_type;\r\n    }\r\n\r\n    toStorageString() {\r\n        Log.debug(\"State.toStorageString\");\r\n        return JSON.stringify({\r\n            id: this.id,\r\n            data: this.data,\r\n            created: this.created,\r\n            request_type: this.request_type\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"State.fromStorageString\");\r\n        return new State(JSON.parse(storageString));\r\n    }\r\n\r\n    static clearStaleState(storage, age) {\r\n\r\n        var cutoff = Date.now() / 1000 - age;\r\n\r\n        return storage.getAllKeys().then(keys => {\r\n            Log.debug(\"State.clearStaleState: got keys\", keys);\r\n\r\n            var promises = [];\r\n            for (let i = 0; i < keys.length; i++) {\r\n                let key = keys[i];\r\n                var p = storage.get(key).then(item => {\r\n                    let remove = false;\r\n\r\n                    if (item) {\r\n                        try {\r\n                            var state = State.fromStorageString(item)\r\n\r\n                            Log.debug(\"State.clearStaleState: got item from key: \", key, state.created);\r\n\r\n                            if (state.created <= cutoff) {\r\n                                remove = true;\r\n                            }\r\n                        }\r\n                        catch (e) {\r\n                            Log.error(\"State.clearStaleState: Error parsing state for key\", key, e.message);\r\n                            remove = true;\r\n                        }\r\n                    }\r\n                    else {\r\n                        Log.debug(\"State.clearStaleState: no item in storage for key: \", key);\r\n                        remove = true;\r\n                    }\r\n\r\n                    if (remove) {\r\n                        Log.debug(\"State.clearStaleState: removed item for key: \", key);\r\n                        return storage.remove(key);\r\n                    }\r\n                });\r\n\r\n                promises.push(p);\r\n            }\r\n\r\n            Log.debug(\"State.clearStaleState: waiting on promise count:\", promises.length);\r\n            return Promise.all(promises);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\nimport { Event } from './Event.js';\r\n\r\nconst TimerDuration = 5; // seconds\r\n\r\nexport class Timer extends Event {\r\n\r\n    constructor(name, timer = Global.timer, nowFunc = undefined) {\r\n        super(name);\r\n        this._timer = timer;\r\n\r\n        if (nowFunc) {\r\n            this._nowFunc = nowFunc;\r\n        }\r\n        else {\r\n            this._nowFunc = () => Date.now() / 1000;\r\n        }\r\n    }\r\n\r\n    get now() {\r\n        return parseInt(this._nowFunc());\r\n    }\r\n\r\n    init(duration) {\r\n        if (duration <= 0) {\r\n            duration = 1;\r\n        }\r\n        duration = parseInt(duration);\r\n\r\n        var expiration = this.now + duration;\r\n        if (this.expiration === expiration && this._timerHandle) {\r\n            // no need to reinitialize to same expiration, so bail out\r\n            Log.debug(\"Timer.init timer \" + this._name + \" skipping initialization since already initialized for expiration:\", this.expiration);\r\n            return;\r\n        }\r\n\r\n        this.cancel();\r\n\r\n        Log.debug(\"Timer.init timer \" + this._name + \" for duration:\", duration);\r\n        this._expiration = expiration;\r\n\r\n        // we're using a fairly short timer and then checking the expiration in the\r\n        // callback to handle scenarios where the browser device sleeps, and then\r\n        // the timers end up getting delayed.\r\n        var timerDuration = TimerDuration;\r\n        if (duration < timerDuration) {\r\n            timerDuration = duration;\r\n        }\r\n        this._timerHandle = this._timer.setInterval(this._callback.bind(this), timerDuration * 1000);\r\n    }\r\n    \r\n    get expiration() {\r\n        return this._expiration;\r\n    }\r\n\r\n    cancel() {\r\n        if (this._timerHandle) {\r\n            Log.debug(\"Timer.cancel: \", this._name);\r\n            this._timer.clearInterval(this._timerHandle);\r\n            this._timerHandle = null;\r\n        }\r\n    }\r\n\r\n    _callback() {\r\n        var diff = this._expiration - this.now;\r\n        Log.debug(\"Timer.callback; \" + this._name + \" timer expires in:\", diff);\r\n\r\n        if (this._expiration <= this.now) {\r\n            this.cancel();\r\n            super.raise();\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { JsonService } from './JsonService.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Log } from './Log.js';\r\n\r\nexport class TokenClient {\r\n    constructor(settings, JsonServiceCtor = JsonService, MetadataServiceCtor = MetadataService) {\r\n        if (!settings) {\r\n            Log.error(\"TokenClient.ctor: No settings passed\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor();\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n    }\r\n\r\n    exchangeCode(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.grant_type = args.grant_type || \"authorization_code\";\r\n        args.client_id = args.client_id || this._settings.client_id;\r\n        args.redirect_uri = args.redirect_uri || this._settings.redirect_uri;\r\n\r\n        if (!args.code) {\r\n            Log.error(\"TokenClient.exchangeCode: No code passed\");\r\n            return Promise.reject(new Error(\"A code is required\"));\r\n        }\r\n        if (!args.redirect_uri) {\r\n            Log.error(\"TokenClient.exchangeCode: No redirect_uri passed\");\r\n            return Promise.reject(new Error(\"A redirect_uri is required\"));\r\n        }\r\n        if (!args.code_verifier) {\r\n            Log.error(\"TokenClient.exchangeCode: No code_verifier passed\");\r\n            return Promise.reject(new Error(\"A code_verifier is required\"));\r\n        }\r\n        if (!args.client_id) {\r\n            Log.error(\"TokenClient.exchangeCode: No client_id passed\");\r\n            return Promise.reject(new Error(\"A client_id is required\"));\r\n        }\r\n\r\n        return this._metadataService.getTokenEndpoint(false).then(url => {\r\n            Log.debug(\"TokenClient.exchangeCode: Received token endpoint\");\r\n\r\n            return this._jsonService.postForm(url, args).then(response => {\r\n                Log.debug(\"TokenClient.exchangeCode: response received\");\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n\r\n    exchangeRefreshToken(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.grant_type = args.grant_type || \"refresh_token\";\r\n        args.client_id = args.client_id || this._settings.client_id;\r\n        args.client_secret = args.client_secret || this._settings.client_secret;\r\n\r\n        if (!args.refresh_token) {\r\n            Log.error(\"TokenClient.exchangeRefreshToken: No refresh_token passed\");\r\n            return Promise.reject(new Error(\"A refresh_token is required\"));\r\n        }\r\n        if (!args.client_id) {\r\n            Log.error(\"TokenClient.exchangeRefreshToken: No client_id passed\");\r\n            return Promise.reject(new Error(\"A client_id is required\"));\r\n        }\r\n\r\n        return this._metadataService.getTokenEndpoint(false).then(url => {\r\n            Log.debug(\"TokenClient.exchangeRefreshToken: Received token endpoint\");\r\n\r\n            return this._jsonService.postForm(url, args).then(response => {\r\n                Log.debug(\"TokenClient.exchangeRefreshToken: response received\");\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Global } from './Global.js';\r\n\r\nconst AccessTokenTypeHint = \"access_token\";\r\nconst RefreshTokenTypeHint = \"refresh_token\";\r\n\r\nexport class TokenRevocationClient {\r\n    constructor(settings, XMLHttpRequestCtor = Global.XMLHttpRequest, MetadataServiceCtor = MetadataService) {\r\n        if (!settings) {\r\n            Log.error(\"TokenRevocationClient.ctor: No settings provided\");\r\n            throw new Error(\"No settings provided.\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._XMLHttpRequestCtor = XMLHttpRequestCtor;\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n    }\r\n\r\n    revoke(token, required, type = \"access_token\") {\r\n        if (!token) {\r\n            Log.error(\"TokenRevocationClient.revoke: No token provided\");\r\n            throw new Error(\"No token provided.\");\r\n        }\r\n\r\n        if (type !== AccessTokenTypeHint && type != RefreshTokenTypeHint) {\r\n            Log.error(\"TokenRevocationClient.revoke: Invalid token type\");\r\n            throw new Error(\"Invalid token type.\");\r\n        }\r\n\r\n        return this._metadataService.getRevocationEndpoint().then(url => {\r\n            if (!url) {\r\n                if (required) {\r\n                    Log.error(\"TokenRevocationClient.revoke: Revocation not supported\");\r\n                    throw new Error(\"Revocation not supported\");\r\n                }\r\n\r\n                // not required, so don't error and just return\r\n                return;\r\n            }\r\n\r\n            Log.debug(\"TokenRevocationClient.revoke: Revoking \" + type);\r\n            var client_id = this._settings.client_id;\r\n            var client_secret = this._settings.client_secret;\r\n            return this._revoke(url, client_id, client_secret, token, type);\r\n        });\r\n    }\r\n\r\n    _revoke(url, client_id, client_secret, token, type) {\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var xhr = new this._XMLHttpRequestCtor();\r\n            xhr.open(\"POST\", url);\r\n\r\n            xhr.onload = () => {\r\n                Log.debug(\"TokenRevocationClient.revoke: HTTP response received, status\", xhr.status);\r\n\r\n                if (xhr.status === 200) {\r\n                    resolve();\r\n                }\r\n                else {\r\n                    reject(Error(xhr.statusText + \" (\" + xhr.status + \")\"));\r\n                }\r\n            };\r\n            xhr.onerror = () => { \r\n                Log.debug(\"TokenRevocationClient.revoke: Network Error.\")\r\n                reject(\"Network Error\");\r\n            };\r\n\r\n            var body = \"client_id=\" + encodeURIComponent(client_id);\r\n            if (client_secret) {\r\n                body += \"&client_secret=\" + encodeURIComponent(client_secret);\r\n            }\r\n            body += \"&token_type_hint=\" + encodeURIComponent(type);\r\n            body += \"&token=\" + encodeURIComponent(token);\r\n\r\n            xhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\r\n            xhr.send(body);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class UrlUtility {\r\n    static addQueryParam(url, name, value) {\r\n        if (url.indexOf('?') < 0) {\r\n            url += \"?\";\r\n        }\r\n\r\n        if (url[url.length - 1] !== \"?\") {\r\n            url += \"&\";\r\n        }\r\n\r\n        url += encodeURIComponent(name);\r\n        url += \"=\";\r\n        url += encodeURIComponent(value);\r\n\r\n        return url;\r\n    }\r\n\r\n    static parseUrlFragment(value, delimiter = \"#\", global = Global) {\r\n        if (typeof value !== 'string'){\r\n            value = global.location.href;\r\n        }\r\n\r\n        var idx = value.lastIndexOf(delimiter);\r\n        if (idx >= 0) {\r\n            value = value.substr(idx + 1);\r\n        }\r\n\r\n        if (delimiter === \"?\") {\r\n            // if we're doing query, then strip off hash fragment before we parse\r\n            idx = value.indexOf('#');\r\n            if (idx >= 0) {\r\n                value = value.substr(0, idx);\r\n            }\r\n        }\r\n\r\n        var params = {},\r\n            regex = /([^&=]+)=([^&]*)/g,\r\n            m;\r\n\r\n        var counter = 0;\r\n        while (m = regex.exec(value)) {\r\n            params[decodeURIComponent(m[1])] = decodeURIComponent(m[2]);\r\n            if (counter++ > 50) {\r\n                Log.error(\"UrlUtility.parseUrlFragment: response exceeded expected number of parameters\", value);\r\n                return {\r\n                    error: \"Response exceeded expected number of parameters\"\r\n                };\r\n            }\r\n        }\r\n\r\n        for (var prop in params) {\r\n            return params;\r\n        }\r\n\r\n        return {};\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class User {\r\n    constructor({id_token, session_state, access_token, refresh_token, token_type, scope, profile, expires_at, state}) {\r\n        this.id_token = id_token;\r\n        this.session_state = session_state;\r\n        this.access_token = access_token;\r\n        this.refresh_token = refresh_token;\r\n        this.token_type = token_type;\r\n        this.scope = scope;\r\n        this.profile = profile;\r\n        this.expires_at = expires_at;\r\n        this.state = state;\r\n    }\r\n\r\n    get expires_in() {\r\n        if (this.expires_at) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            return this.expires_at - now;\r\n        }\r\n        return undefined;\r\n    }\r\n    set expires_in(value) {\r\n        let expires_in = parseInt(value);\r\n        if (typeof expires_in === 'number' && expires_in > 0) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            this.expires_at = now + expires_in;\r\n        }\r\n    }\r\n\r\n    get expired() {\r\n        let expires_in = this.expires_in;\r\n        if (expires_in !== undefined) {\r\n            return expires_in <= 0;\r\n        }\r\n        return undefined;\r\n    }\r\n\r\n    get scopes() {\r\n        return (this.scope || \"\").split(\" \");\r\n    }\r\n\r\n    toStorageString() {\r\n        Log.debug(\"User.toStorageString\");\r\n        return JSON.stringify({\r\n            id_token: this.id_token,\r\n            session_state: this.session_state,\r\n            access_token: this.access_token,\r\n            refresh_token: this.refresh_token,\r\n            token_type: this.token_type,\r\n            scope: this.scope,\r\n            profile: this.profile,\r\n            expires_at: this.expires_at\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"User.fromStorageString\");\r\n        return new User(JSON.parse(storageString));\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { JsonService } from './JsonService.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Log } from './Log.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\nexport class UserInfoService {\r\n    constructor(\r\n        settings, \r\n        JsonServiceCtor = JsonService, \r\n        MetadataServiceCtor = MetadataService, \r\n        joseUtil = JoseUtil\r\n    ) {\r\n        if (!settings) {\r\n            Log.error(\"UserInfoService.ctor: No settings passed\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor(undefined, undefined, this._getClaimsFromJwt.bind(this));\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n    }\r\n\r\n    getClaims(token) {\r\n        if (!token) {\r\n            Log.error(\"UserInfoService.getClaims: No token passed\");\r\n            return Promise.reject(new Error(\"A token is required\"));\r\n        }\r\n\r\n        return this._metadataService.getUserInfoEndpoint().then(url => {\r\n            Log.debug(\"UserInfoService.getClaims: received userinfo url\", url);\r\n\r\n            return this._jsonService.getJson(url, token).then(claims => {\r\n                Log.debug(\"UserInfoService.getClaims: claims received\", claims);\r\n                return claims;\r\n            });\r\n        });\r\n    }\r\n\r\n    _getClaimsFromJwt(req) {\r\n        try {\r\n            let jwt = this._joseUtil.parseJwt(req.responseText);\r\n            if (!jwt || !jwt.header || !jwt.payload) {\r\n                Log.error(\"UserInfoService._getClaimsFromJwt: Failed to parse JWT\", jwt);\r\n                return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n            }\r\n\r\n            var kid = jwt.header.kid;\r\n\r\n            let issuerPromise;\r\n            switch (this._settings.userInfoJwtIssuer) {\r\n                case 'OP':\r\n                    issuerPromise = this._metadataService.getIssuer();\r\n                    break;\r\n                case 'ANY':\r\n                    issuerPromise = Promise.resolve(jwt.payload.iss);\r\n                    break;\r\n                default:\r\n                    issuerPromise = Promise.resolve(this._settings.userInfoJwtIssuer);\r\n                    break;\r\n            }\r\n\r\n            return issuerPromise.then(issuer => {\r\n                Log.debug(\"UserInfoService._getClaimsFromJwt: Received issuer:\" + issuer);\r\n\r\n                return this._metadataService.getSigningKeys().then(keys => {\r\n                    if (!keys) {\r\n                        Log.error(\"UserInfoService._getClaimsFromJwt: No signing keys from metadata\");\r\n                        return Promise.reject(new Error(\"No signing keys from metadata\"));\r\n                    }\r\n\r\n                    Log.debug(\"UserInfoService._getClaimsFromJwt: Received signing keys\");\r\n                    let key;\r\n                    if (!kid) {\r\n                        keys = this._filterByAlg(keys, jwt.header.alg);\r\n\r\n                        if (keys.length > 1) {\r\n                            Log.error(\"UserInfoService._getClaimsFromJwt: No kid found in id_token and more than one key found in metadata\");\r\n                            return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\r\n                        }\r\n                        else {\r\n                            // kid is mandatory only when there are multiple keys in the referenced JWK Set document\r\n                            // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\r\n                            key = keys[0];\r\n                        }\r\n                    }\r\n                    else {\r\n                        key = keys.filter(key => {\r\n                            return key.kid === kid;\r\n                        })[0];\r\n                    }\r\n\r\n                    if (!key) {\r\n                        Log.error(\"UserInfoService._getClaimsFromJwt: No key matching kid or alg found in signing keys\");\r\n                        return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\r\n                    }\r\n\r\n                    let audience = this._settings.client_id;\r\n\r\n                    let clockSkewInSeconds = this._settings.clockSkew;\r\n                    Log.debug(\"UserInfoService._getClaimsFromJwt: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n                    return this._joseUtil.validateJwt(req.responseText, key, issuer, audience, clockSkewInSeconds, undefined, true).then(() => {\r\n                        Log.debug(\"UserInfoService._getClaimsFromJwt: JWT validation successful\");\r\n                        return jwt.payload;\r\n                    });\r\n                });\r\n            });\r\n            return;\r\n        }\r\n        catch (e) {\r\n            Log.error(\"UserInfoService._getClaimsFromJwt: Error parsing JWT response\", e.message);\r\n            reject(e);\r\n            return;\r\n        }\r\n    }\r\n\r\n    _filterByAlg(keys, alg) {\r\n        var kty = null;\r\n        if (alg.startsWith(\"RS\")) {\r\n            kty = \"RSA\";\r\n        }\r\n        else if (alg.startsWith(\"PS\")) {\r\n            kty = \"PS\";\r\n        }\r\n        else if (alg.startsWith(\"ES\")) {\r\n            kty = \"EC\";\r\n        }\r\n        else {\r\n            Log.debug(\"UserInfoService._filterByAlg: alg not supported: \", alg);\r\n            return [];\r\n        }\r\n\r\n        Log.debug(\"UserInfoService._filterByAlg: Looking for keys that match kty: \", kty);\r\n\r\n        keys = keys.filter(key => {\r\n            return key.kty === kty;\r\n        });\r\n\r\n        Log.debug(\"UserInfoService._filterByAlg: Number of keys that match kty: \", kty, keys.length);\r\n\r\n        return keys;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClient } from './OidcClient.js';\r\nimport { UserManagerSettings } from './UserManagerSettings.js';\r\nimport { User } from './User.js';\r\nimport { UserManagerEvents } from './UserManagerEvents.js';\r\nimport { SilentRenewService } from './SilentRenewService.js';\r\nimport { SessionMonitor } from './SessionMonitor.js';\r\nimport { TokenRevocationClient } from './TokenRevocationClient.js';\r\nimport { TokenClient } from './TokenClient.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\n\r\nexport class UserManager extends OidcClient {\r\n    constructor(settings = {},\r\n        SilentRenewServiceCtor = SilentRenewService,\r\n        SessionMonitorCtor = SessionMonitor,\r\n        TokenRevocationClientCtor = TokenRevocationClient,\r\n        TokenClientCtor = TokenClient,\r\n        joseUtil = JoseUtil\r\n    ) {\r\n\r\n        if (!(settings instanceof UserManagerSettings)) {\r\n            settings = new UserManagerSettings(settings);\r\n        }\r\n        super(settings);\r\n\r\n        this._events = new UserManagerEvents(settings);\r\n        this._silentRenewService = new SilentRenewServiceCtor(this);\r\n\r\n        // order is important for the following properties; these services depend upon the events.\r\n        if (this.settings.automaticSilentRenew) {\r\n            Log.debug(\"UserManager.ctor: automaticSilentRenew is configured, setting up silent renew\");\r\n            this.startSilentRenew();\r\n        }\r\n\r\n        if (this.settings.monitorSession) {\r\n            Log.debug(\"UserManager.ctor: monitorSession is configured, setting up session monitor\");\r\n            this._sessionMonitor = new SessionMonitorCtor(this);\r\n        }\r\n\r\n        this._tokenRevocationClient = new TokenRevocationClientCtor(this._settings);\r\n        this._tokenClient = new TokenClientCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n    }\r\n\r\n    get _redirectNavigator() {\r\n        return this.settings.redirectNavigator;\r\n    }\r\n    get _popupNavigator() {\r\n        return this.settings.popupNavigator;\r\n    }\r\n    get _iframeNavigator() {\r\n        return this.settings.iframeNavigator;\r\n    }\r\n    get _userStore() {\r\n        return this.settings.userStore;\r\n    }\r\n\r\n    get events() {\r\n        return this._events;\r\n    }\r\n\r\n    getUser() {\r\n        return this._loadUser().then(user => {\r\n            if (user) {\r\n                Log.info(\"UserManager.getUser: user loaded\");\r\n\r\n                this._events.load(user, false);\r\n\r\n                return user;\r\n            }\r\n            else {\r\n                Log.info(\"UserManager.getUser: user not found in storage\");\r\n                return null;\r\n            }\r\n        });\r\n    }\r\n\r\n    removeUser() {\r\n        return this.storeUser(null).then(() => {\r\n            Log.info(\"UserManager.removeUser: user removed from storage\");\r\n            this._events.unload();\r\n        });\r\n    }\r\n\r\n    signinRedirect(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:r\";\r\n        let navParams = {\r\n            useReplaceToNavigate : args.useReplaceToNavigate\r\n        };\r\n        return this._signinStart(args, this._redirectNavigator, navParams).then(()=>{\r\n            Log.info(\"UserManager.signinRedirect: successful\");\r\n        });\r\n    }\r\n    signinRedirectCallback(url) {\r\n        return this._signinEnd(url || this._redirectNavigator.url).then(user => {\r\n            if (user.profile && user.profile.sub) {\r\n                Log.info(\"UserManager.signinRedirectCallback: successful, signed in sub: \", user.profile.sub);\r\n            }\r\n            else {\r\n                Log.info(\"UserManager.signinRedirectCallback: no sub\");\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinPopup(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:p\";\r\n        let url = args.redirect_uri || this.settings.popup_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.signinPopup: No popup_redirect_uri or redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No popup_redirect_uri or redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.display = \"popup\";\r\n\r\n        return this._signin(args, this._popupNavigator, {\r\n            startUrl: url,\r\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\r\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\r\n        }).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinPopup: signinPopup successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinPopup: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n    signinPopupCallback(url) {\r\n        return this._signinCallback(url, this._popupNavigator).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinPopupCallback: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinPopupCallback: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        }).catch(err=>{\r\n            Log.error(\"UserManager.signinPopupCallback error: \" + err && err.message);\r\n        });\r\n    }\r\n\r\n    signinSilent(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:s\";\r\n        // first determine if we have a refresh token, or need to use iframe\r\n        return this._loadUser().then(user => {\r\n            if (user && user.refresh_token) {\r\n                args.refresh_token = user.refresh_token;\r\n                return this._useRefreshToken(args);\r\n            }\r\n            else {\r\n                args.id_token_hint = args.id_token_hint || (this.settings.includeIdTokenInSilentRenew && user && user.id_token);\r\n                if (user && this._settings.validateSubOnSilentRenew) {\r\n                    Log.debug(\"UserManager.signinSilent, subject prior to silent renew: \", user.profile.sub);\r\n                    args.current_sub = user.profile.sub;\r\n                }\r\n                return this._signinSilentIframe(args);\r\n            }\r\n        });\r\n    }\r\n\r\n    _useRefreshToken(args = {}) {\r\n        return this._tokenClient.exchangeRefreshToken(args).then(result => {\r\n            if (!result) {\r\n                Log.error(\"UserManager._useRefreshToken: No response returned from token endpoint\");\r\n                return Promise.reject(\"No response returned from token endpoint\");\r\n            }\r\n            if (!result.access_token) {\r\n                Log.error(\"UserManager._useRefreshToken: No access token returned from token endpoint\");\r\n                return Promise.reject(\"No access token returned from token endpoint\");\r\n            }\r\n\r\n            return this._loadUser().then(user => {\r\n                if (user) {\r\n                    let idTokenValidation = Promise.resolve();\r\n                    if (result.id_token) {\r\n                        idTokenValidation = this._validateIdTokenFromTokenRefreshToken(user.profile, result.id_token);\r\n                    }\r\n\r\n                    return idTokenValidation.then(() => {\r\n                        Log.debug(\"UserManager._useRefreshToken: refresh token response success\");\r\n                        user.id_token = result.id_token;\r\n                        user.access_token = result.access_token;\r\n                        user.refresh_token = result.refresh_token || user.refresh_token;\r\n                        user.expires_in = result.expires_in;\r\n\r\n                        return this.storeUser(user).then(()=>{\r\n                            this._events.load(user);\r\n                            return user;\r\n                        });\r\n                    });\r\n                }\r\n                else {\r\n                    return null;\r\n                }\r\n            });\r\n        });\r\n    }\r\n\r\n    _validateIdTokenFromTokenRefreshToken(profile, id_token) {\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n            return this._joseUtil.validateJwtAttributes(id_token, issuer, this._settings.client_id, this._settings.clockSkew).then(payload => {\r\n                if (!payload) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: Failed to validate id_token\");\r\n                    return Promise.reject(new Error(\"Failed to validate id_token\"));\r\n                }\r\n                if (payload.sub !== profile.sub) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: sub in id_token does not match current sub\");\r\n                    return Promise.reject(new Error(\"sub in id_token does not match current sub\"));\r\n                }\r\n                if (payload.auth_time && payload.auth_time !== profile.auth_time) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: auth_time in id_token does not match original auth_time\");\r\n                    return Promise.reject(new Error(\"auth_time in id_token does not match original auth_time\"));\r\n                }\r\n                if (payload.azp && payload.azp !== profile.azp) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp in id_token does not match original azp\");\r\n                    return Promise.reject(new Error(\"azp in id_token does not match original azp\"));\r\n                }\r\n                if (!payload.azp && profile.azp) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp not in id_token, but present in original id_token\");\r\n                    return Promise.reject(new Error(\"azp not in id_token, but present in original id_token\"));\r\n                }\r\n            });\r\n        });\r\n    }\r\n    \r\n    _signinSilentIframe(args = {}) {\r\n        let url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.signinSilent: No silent_redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.prompt = args.prompt || \"none\";\r\n\r\n        return this._signin(args, this._iframeNavigator, {\r\n            startUrl: url,\r\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\r\n        }).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinSilent: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinSilent: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinSilentCallback(url) {\r\n        return this._signinCallback(url, this._iframeNavigator).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinSilentCallback: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinSilentCallback: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinCallback(url) {\r\n        return this.readSigninResponseState(url).then(({state, response}) => {\r\n            if (state.request_type === \"si:r\") {\r\n                return this.signinRedirectCallback(url);\r\n            }\r\n            if (state.request_type === \"si:p\") {\r\n                return this.signinPopupCallback(url);\r\n            }\r\n            if (state.request_type === \"si:s\") {\r\n                return this.signinSilentCallback(url);\r\n            }\r\n            return Promise.reject(new Error(\"invalid response_type in state\"));\r\n        });\r\n    }\r\n\r\n    signoutCallback(url, keepOpen) {\r\n        return this.readSignoutResponseState(url).then(({state, response}) => {\r\n            if (state) {\r\n                if (state.request_type === \"so:r\") {\r\n                    return this.signoutRedirectCallback(url);\r\n                }\r\n                if (state.request_type === \"so:p\") {\r\n                    return this.signoutPopupCallback(url, keepOpen);\r\n                }\r\n                return Promise.reject(new Error(\"invalid response_type in state\"));\r\n            }\r\n            return response;\r\n        });\r\n    }\r\n\r\n    querySessionStatus(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:s\"; // this acts like a signin silent\r\n        let url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.querySessionStatus: No silent_redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.prompt = \"none\";\r\n        args.response_type = args.response_type || this.settings.query_status_response_type;\r\n        args.scope = args.scope || \"openid\";\r\n        args.skipUserInfo = true;\r\n\r\n        return this._signinStart(args, this._iframeNavigator, {\r\n            startUrl: url,\r\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\r\n        }).then(navResponse => {\r\n            return this.processSigninResponse(navResponse.url).then(signinResponse => {\r\n                Log.debug(\"UserManager.querySessionStatus: got signin response\");\r\n\r\n                if (signinResponse.session_state && signinResponse.profile.sub) {\r\n                    Log.info(\"UserManager.querySessionStatus: querySessionStatus success for sub: \",  signinResponse.profile.sub);\r\n                    return {\r\n                        session_state: signinResponse.session_state,\r\n                        sub: signinResponse.profile.sub,\r\n                        sid: signinResponse.profile.sid\r\n                    };\r\n                }\r\n                else {\r\n                    Log.info(\"querySessionStatus successful, user not authenticated\");\r\n                }\r\n            })\r\n            .catch(err => {\r\n                if (err.session_state && this.settings.monitorAnonymousSession) {\r\n                    if (err.message == \"login_required\" || \r\n                        err.message == \"consent_required\" || \r\n                        err.message == \"interaction_required\" || \r\n                        err.message == \"account_selection_required\"\r\n                    ) {\r\n                        Log.info(\"UserManager.querySessionStatus: querySessionStatus success for anonymous user\");\r\n                        return {\r\n                            session_state: err.session_state\r\n                        };\r\n                    }\r\n                }\r\n\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n\r\n    _signin(args, navigator, navigatorParams = {}) {\r\n        return this._signinStart(args, navigator, navigatorParams).then(navResponse => {\r\n            return this._signinEnd(navResponse.url, args);\r\n        });\r\n    }\r\n    _signinStart(args, navigator, navigatorParams = {}) {\r\n\r\n        return navigator.prepare(navigatorParams).then(handle => {\r\n            Log.debug(\"UserManager._signinStart: got navigator window handle\");\r\n\r\n            return this.createSigninRequest(args).then(signinRequest => {\r\n                Log.debug(\"UserManager._signinStart: got signin request\");\r\n\r\n                navigatorParams.url = signinRequest.url;\r\n                navigatorParams.id = signinRequest.state.id;\r\n\r\n                return handle.navigate(navigatorParams);\r\n            }).catch(err => {\r\n                if (handle.close) {\r\n                    Log.debug(\"UserManager._signinStart: Error after preparing navigator, closing navigator window\");\r\n                    handle.close();\r\n                }\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n    _signinEnd(url, args = {}) {\r\n        return this.processSigninResponse(url).then(signinResponse => {\r\n            Log.debug(\"UserManager._signinEnd: got signin response\");\r\n\r\n            let user = new User(signinResponse);\r\n\r\n            if (args.current_sub) {\r\n                if (args.current_sub !== user.profile.sub) {\r\n                    Log.debug(\"UserManager._signinEnd: current user does not match user returned from signin. sub from signin: \", user.profile.sub);\r\n                    return Promise.reject(new Error(\"login_required\"));\r\n                }\r\n                else {\r\n                    Log.debug(\"UserManager._signinEnd: current user matches user returned from signin\");\r\n                }\r\n            }\r\n\r\n            return this.storeUser(user).then(() => {\r\n                Log.debug(\"UserManager._signinEnd: user stored\");\r\n\r\n                this._events.load(user);\r\n\r\n                return user;\r\n            });\r\n        });\r\n    }\r\n    _signinCallback(url, navigator) {\r\n        Log.debug(\"UserManager._signinCallback\");\r\n        return navigator.callback(url);\r\n    }\r\n\r\n    signoutRedirect(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"so:r\";\r\n        let postLogoutRedirectUri = args.post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\r\n        if (postLogoutRedirectUri){\r\n            args.post_logout_redirect_uri = postLogoutRedirectUri;\r\n        }\r\n        let navParams = {\r\n            useReplaceToNavigate : args.useReplaceToNavigate\r\n        };\r\n        return this._signoutStart(args, this._redirectNavigator, navParams).then(()=>{\r\n            Log.info(\"UserManager.signoutRedirect: successful\");\r\n        });\r\n    }\r\n    signoutRedirectCallback(url) {\r\n        return this._signoutEnd(url || this._redirectNavigator.url).then(response=>{\r\n            Log.info(\"UserManager.signoutRedirectCallback: successful\");\r\n            return response;\r\n        });\r\n    }\r\n\r\n    signoutPopup(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"so:p\";\r\n        let url = args.post_logout_redirect_uri || this.settings.popup_post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\r\n        args.post_logout_redirect_uri = url;\r\n        args.display = \"popup\";\r\n        if (args.post_logout_redirect_uri){\r\n            // we're putting a dummy entry in here because we\r\n            // need a unique id from the state for notification\r\n            // to the parent window, which is necessary if we\r\n            // plan to return back to the client after signout\r\n            // and so we can close the popup after signout\r\n            args.state = args.state || {};\r\n        }\r\n\r\n        return this._signout(args, this._popupNavigator, {\r\n            startUrl: url,\r\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\r\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\r\n        }).then(() => {\r\n            Log.info(\"UserManager.signoutPopup: successful\");\r\n        });\r\n    }\r\n    signoutPopupCallback(url, keepOpen) {\r\n        if (typeof(keepOpen) === 'undefined' && typeof(url) === 'boolean') {\r\n            keepOpen = url;\r\n            url = null;\r\n        }\r\n\r\n        let delimiter = '?';\r\n        return this._popupNavigator.callback(url, keepOpen, delimiter).then(() => {\r\n            Log.info(\"UserManager.signoutPopupCallback: successful\");\r\n        });\r\n    }\r\n\r\n    _signout(args, navigator, navigatorParams = {}) {\r\n        return this._signoutStart(args, navigator, navigatorParams).then(navResponse => {\r\n            return this._signoutEnd(navResponse.url);\r\n        });\r\n    }\r\n    _signoutStart(args = {}, navigator, navigatorParams = {}) {\r\n        return navigator.prepare(navigatorParams).then(handle => {\r\n            Log.debug(\"UserManager._signoutStart: got navigator window handle\");\r\n\r\n            return this._loadUser().then(user => {\r\n                Log.debug(\"UserManager._signoutStart: loaded current user from storage\");\r\n\r\n                var revokePromise = this._settings.revokeAccessTokenOnSignout ? this._revokeInternal(user) : Promise.resolve();\r\n                return revokePromise.then(() => {\r\n\r\n                    var id_token = args.id_token_hint || user && user.id_token;\r\n                    if (id_token) {\r\n                        Log.debug(\"UserManager._signoutStart: Setting id_token into signout request\");\r\n                        args.id_token_hint = id_token;\r\n                    }\r\n\r\n                    return this.removeUser().then(() => {\r\n                        Log.debug(\"UserManager._signoutStart: user removed, creating signout request\");\r\n\r\n                        return this.createSignoutRequest(args).then(signoutRequest => {\r\n                            Log.debug(\"UserManager._signoutStart: got signout request\");\r\n\r\n                            navigatorParams.url = signoutRequest.url;\r\n                            if (signoutRequest.state) {\r\n                                navigatorParams.id = signoutRequest.state.id;\r\n                            }\r\n                            return handle.navigate(navigatorParams);\r\n                        });\r\n                    });\r\n                });\r\n            }).catch(err => {\r\n                if (handle.close) {\r\n                    Log.debug(\"UserManager._signoutStart: Error after preparing navigator, closing navigator window\");\r\n                    handle.close();\r\n                }\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n    _signoutEnd(url) {\r\n        return this.processSignoutResponse(url).then(signoutResponse => {\r\n            Log.debug(\"UserManager._signoutEnd: got signout response\");\r\n\r\n            return signoutResponse;\r\n        });\r\n    }\r\n\r\n    revokeAccessToken() {\r\n        return this._loadUser().then(user => {\r\n            return this._revokeInternal(user, true).then(success => {\r\n                if (success) {\r\n                    Log.debug(\"UserManager.revokeAccessToken: removing token properties from user and re-storing\");\r\n\r\n                    user.access_token = null;\r\n                    user.refresh_token = null;\r\n                    user.expires_at = null;\r\n                    user.token_type = null;\r\n\r\n                    return this.storeUser(user).then(() => {\r\n                        Log.debug(\"UserManager.revokeAccessToken: user stored\");\r\n                        this._events.load(user);\r\n                    });\r\n                }\r\n            });\r\n        }).then(()=>{\r\n            Log.info(\"UserManager.revokeAccessToken: access token revoked successfully\");\r\n        });\r\n    }\r\n\r\n    _revokeInternal(user, required) {\r\n        if (user) {\r\n            var access_token = user.access_token;\r\n            var refresh_token = user.refresh_token;\r\n\r\n            return this._revokeAccessTokenInternal(access_token, required)\r\n                .then(atSuccess => {\r\n                    return this._revokeRefreshTokenInternal(refresh_token, required)\r\n                        .then(rtSuccess => {\r\n                            if (!atSuccess && !rtSuccess) {\r\n                                Log.debug(\"UserManager.revokeAccessToken: no need to revoke due to no token(s), or JWT format\");\r\n                            }\r\n                            \r\n                            return atSuccess || rtSuccess;\r\n                        });\r\n                });\r\n        }\r\n\r\n        return Promise.resolve(false);\r\n    }\r\n\r\n    _revokeAccessTokenInternal(access_token, required) {\r\n        // check for JWT vs. reference token\r\n        if (!access_token || access_token.indexOf('.') >= 0) {\r\n            return Promise.resolve(false);\r\n        }\r\n\r\n        return this._tokenRevocationClient.revoke(access_token, required).then(() => true);\r\n    }\r\n\r\n    _revokeRefreshTokenInternal(refresh_token, required) {\r\n        if (!refresh_token) {\r\n            return Promise.resolve(false);\r\n        }\r\n\r\n        return this._tokenRevocationClient.revoke(refresh_token, required, \"refresh_token\").then(() => true);\r\n    }\r\n\r\n    startSilentRenew() {\r\n        this._silentRenewService.start();\r\n    }\r\n\r\n    stopSilentRenew() {\r\n        this._silentRenewService.stop();\r\n    }\r\n\r\n    get _userStoreKey() {\r\n        return `user:${this.settings.authority}:${this.settings.client_id}`;\r\n    }\r\n\r\n    _loadUser() {\r\n        return this._userStore.get(this._userStoreKey).then(storageString => {\r\n            if (storageString) {\r\n                Log.debug(\"UserManager._loadUser: user storageString loaded\");\r\n                return User.fromStorageString(storageString);\r\n            }\r\n\r\n            Log.debug(\"UserManager._loadUser: no user storageString\");\r\n            return null;\r\n        });\r\n    }\r\n\r\n    storeUser(user) {\r\n        if (user) {\r\n            Log.debug(\"UserManager.storeUser: storing user\");\r\n\r\n            var storageString = user.toStorageString();\r\n            return this._userStore.set(this._userStoreKey, storageString);\r\n        }\r\n        else {\r\n            Log.debug(\"storeUser.storeUser: removing user\");\r\n            return this._userStore.remove(this._userStoreKey);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { AccessTokenEvents } from './AccessTokenEvents.js';\r\nimport { Event } from './Event.js';\r\n\r\nexport class UserManagerEvents extends AccessTokenEvents {\r\n\r\n    constructor(settings) {\r\n        super(settings);\r\n        this._userLoaded = new Event(\"User loaded\");\r\n        this._userUnloaded = new Event(\"User unloaded\");\r\n        this._silentRenewError = new Event(\"Silent renew error\");\r\n        this._userSignedIn = new Event(\"User signed in\");\r\n        this._userSignedOut = new Event(\"User signed out\");\r\n        this._userSessionChanged = new Event(\"User session changed\");\r\n    }\r\n\r\n    load(user, raiseEvent=true) {\r\n        Log.debug(\"UserManagerEvents.load\");\r\n        super.load(user);\r\n        if (raiseEvent) {\r\n            this._userLoaded.raise(user);\r\n        }\r\n    }\r\n    unload() {\r\n        Log.debug(\"UserManagerEvents.unload\");\r\n        super.unload();\r\n        this._userUnloaded.raise();\r\n    }\r\n\r\n    addUserLoaded(cb) {\r\n        this._userLoaded.addHandler(cb);\r\n    }\r\n    removeUserLoaded(cb) {\r\n        this._userLoaded.removeHandler(cb);\r\n    }\r\n\r\n    addUserUnloaded(cb) {\r\n        this._userUnloaded.addHandler(cb);\r\n    }\r\n    removeUserUnloaded(cb) {\r\n        this._userUnloaded.removeHandler(cb);\r\n    }\r\n\r\n    addSilentRenewError(cb) {\r\n        this._silentRenewError.addHandler(cb);\r\n    }\r\n    removeSilentRenewError(cb) {\r\n        this._silentRenewError.removeHandler(cb);\r\n    }\r\n    _raiseSilentRenewError(e) {\r\n        Log.debug(\"UserManagerEvents._raiseSilentRenewError\", e.message);\r\n        this._silentRenewError.raise(e);\r\n    }\r\n\r\n    addUserSignedIn(cb) {\r\n        this._userSignedIn.addHandler(cb);\r\n    }\r\n    removeUserSignedIn(cb) {\r\n        this._userSignedIn.removeHandler(cb);\r\n    }\r\n    _raiseUserSignedIn() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSignedIn\");\r\n        this._userSignedIn.raise();\r\n    }\r\n\r\n    addUserSignedOut(cb) {\r\n        this._userSignedOut.addHandler(cb);\r\n    }\r\n    removeUserSignedOut(cb) {\r\n        this._userSignedOut.removeHandler(cb);\r\n    }\r\n    _raiseUserSignedOut() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSignedOut\");\r\n        this._userSignedOut.raise();\r\n    }\r\n\r\n    addUserSessionChanged(cb) {\r\n        this._userSessionChanged.addHandler(cb);\r\n    }\r\n    removeUserSessionChanged(cb) {\r\n        this._userSessionChanged.removeHandler(cb);\r\n    }\r\n    _raiseUserSessionChanged() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSessionChanged\");\r\n        this._userSessionChanged.raise();\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClientSettings } from './OidcClientSettings.js';\r\nimport { RedirectNavigator } from './RedirectNavigator.js';\r\nimport { PopupNavigator } from './PopupNavigator.js';\r\nimport { IFrameNavigator } from './IFrameNavigator.js';\r\nimport { WebStorageStateStore } from './WebStorageStateStore.js';\r\nimport { Global } from './Global.js';\r\nimport { SigninRequest } from './SigninRequest.js';\r\n\r\nconst DefaultAccessTokenExpiringNotificationTime = 60;\r\nconst DefaultCheckSessionInterval = 2000;\r\n\r\nexport class UserManagerSettings extends OidcClientSettings {\r\n    constructor({\r\n        popup_redirect_uri,\r\n        popup_post_logout_redirect_uri,\r\n        popupWindowFeatures,\r\n        popupWindowTarget,\r\n        silent_redirect_uri,\r\n        silentRequestTimeout,\r\n        automaticSilentRenew = false,\r\n        validateSubOnSilentRenew = false,\r\n        includeIdTokenInSilentRenew = true,\r\n        monitorSession = true,\r\n        monitorAnonymousSession = false,\r\n        checkSessionInterval = DefaultCheckSessionInterval,\r\n        stopCheckSessionOnError = true,\r\n        query_status_response_type,\r\n        revokeAccessTokenOnSignout = false,\r\n        accessTokenExpiringNotificationTime = DefaultAccessTokenExpiringNotificationTime,\r\n        redirectNavigator = new RedirectNavigator(),\r\n        popupNavigator = new PopupNavigator(),\r\n        iframeNavigator = new IFrameNavigator(),\r\n        userStore = new WebStorageStateStore({ store: Global.sessionStorage })\r\n    } = {}) {\r\n        super(arguments[0]);\r\n\r\n        this._popup_redirect_uri = popup_redirect_uri;\r\n        this._popup_post_logout_redirect_uri = popup_post_logout_redirect_uri;\r\n        this._popupWindowFeatures = popupWindowFeatures;\r\n        this._popupWindowTarget = popupWindowTarget;\r\n\r\n        this._silent_redirect_uri = silent_redirect_uri;\r\n        this._silentRequestTimeout = silentRequestTimeout;\r\n        this._automaticSilentRenew = automaticSilentRenew;\r\n        this._validateSubOnSilentRenew = validateSubOnSilentRenew;\r\n        this._includeIdTokenInSilentRenew = includeIdTokenInSilentRenew;\r\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\r\n\r\n        this._monitorSession = monitorSession;\r\n        this._monitorAnonymousSession = monitorAnonymousSession;\r\n        this._checkSessionInterval = checkSessionInterval;\r\n        this._stopCheckSessionOnError = stopCheckSessionOnError;\r\n        if (query_status_response_type) {\r\n            this._query_status_response_type = query_status_response_type;\r\n        } \r\n        else if (arguments[0] && arguments[0].response_type) {\r\n            this._query_status_response_type = SigninRequest.isOidc(arguments[0].response_type) ? \"id_token\" : \"code\";\r\n        }\r\n        else {\r\n            this._query_status_response_type = \"id_token\";\r\n        }\r\n        this._revokeAccessTokenOnSignout = revokeAccessTokenOnSignout;\r\n\r\n        this._redirectNavigator = redirectNavigator;\r\n        this._popupNavigator = popupNavigator;\r\n        this._iframeNavigator = iframeNavigator;\r\n\r\n        this._userStore = userStore;\r\n    }\r\n\r\n    get popup_redirect_uri() {\r\n        return this._popup_redirect_uri;\r\n    }\r\n    get popup_post_logout_redirect_uri() {\r\n        return this._popup_post_logout_redirect_uri;\r\n    }\r\n    get popupWindowFeatures() {\r\n        return this._popupWindowFeatures;\r\n    }\r\n    get popupWindowTarget() {\r\n        return this._popupWindowTarget;\r\n    }\r\n\r\n    get silent_redirect_uri() {\r\n        return this._silent_redirect_uri;\r\n    }\r\n     get silentRequestTimeout() {\r\n        return this._silentRequestTimeout;\r\n    }\r\n    get automaticSilentRenew() {\r\n        return this._automaticSilentRenew;\r\n    }\r\n    get validateSubOnSilentRenew() {\r\n        return this._validateSubOnSilentRenew;\r\n    }\r\n    get includeIdTokenInSilentRenew() {\r\n        return this._includeIdTokenInSilentRenew;\r\n    }\r\n    get accessTokenExpiringNotificationTime() {\r\n        return this._accessTokenExpiringNotificationTime;\r\n    }\r\n\r\n    get monitorSession() {\r\n        return this._monitorSession;\r\n    }\r\n    get monitorAnonymousSession() {\r\n        return this._monitorAnonymousSession;\r\n    }\r\n    get checkSessionInterval() {\r\n        return this._checkSessionInterval;\r\n    }\r\n    get stopCheckSessionOnError(){\r\n        return this._stopCheckSessionOnError;\r\n    }\r\n    get query_status_response_type(){\r\n        return this._query_status_response_type;\r\n    }\r\n    get revokeAccessTokenOnSignout() {\r\n        return this._revokeAccessTokenOnSignout;\r\n    }\r\n\r\n    get redirectNavigator() {\r\n        return this._redirectNavigator;\r\n    }\r\n    get popupNavigator() {\r\n        return this._popupNavigator;\r\n    }\r\n    get iframeNavigator() {\r\n        return this._iframeNavigator;\r\n    }\r\n\r\n    get userStore() {\r\n        return this._userStore;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class WebStorageStateStore {\r\n    constructor({prefix = \"oidc.\", store = Global.localStorage} = {}) {\r\n        this._store = store;\r\n        this._prefix = prefix;\r\n    }\r\n\r\n    set(key, value) {\r\n        Log.debug(\"WebStorageStateStore.set\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        this._store.setItem(key, value);\r\n\r\n        return Promise.resolve();\r\n    }\r\n\r\n    get(key) {\r\n        Log.debug(\"WebStorageStateStore.get\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        let item = this._store.getItem(key);\r\n\r\n        return Promise.resolve(item);\r\n    }\r\n\r\n    remove(key) {\r\n        Log.debug(\"WebStorageStateStore.remove\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        let item = this._store.getItem(key);\r\n        this._store.removeItem(key);\r\n\r\n        return Promise.resolve(item);\r\n    }\r\n\r\n    getAllKeys() {\r\n        Log.debug(\"WebStorageStateStore.getAllKeys\");\r\n\r\n        var keys = [];\r\n\r\n        for (let index = 0; index < this._store.length; index++) {\r\n            let key = this._store.key(index);\r\n\r\n            if (key.indexOf(this._prefix) === 0) {\r\n                keys.push(key.substr(this._prefix.length));\r\n            }\r\n        }\r\n\r\n        return Promise.resolve(keys);\r\n    }\r\n}\r\n","/*\r\nBased on the work of Auth0\r\nhttps://github.com/auth0/idtoken-verifier\r\nhttps://github.com/auth0/idtoken-verifier/blob/master/LICENSE\r\nWhich is based on the work of Tom Wu\r\nhttp://www-cs-students.stanford.edu/~tjw/jsbn/\r\nhttp://www-cs-students.stanford.edu/~tjw/jsbn/LICENSE\r\n*/\r\n\r\n/*\r\n * To support most basic OpenId use cases (using RSA256), we can get away without\r\n * requiring the full jrsasign feature set (and resulting massive bundle).\r\n *\r\n * - Support RSA 256 algorithm (optionally could support RSA* family)\r\n * - Parse JWT tokens using the (n) parameter.\r\n * - Verify signature of id_tokens\r\n * - Verify at_hash of access_tokens\r\n * - Perform common base64 encoding/decoding tasks.\r\n */\r\n\r\nimport JSBN from 'jsbn';\r\nimport SHA256 from 'crypto-js/sha256';\r\nimport base64Js from 'base64-js';\r\n\r\nvar BigInteger = JSBN.BigInteger;\r\n\r\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nvar b64map = \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\";\r\nvar b64pad = \"=\";\r\n\r\nconst Base64 = {\r\n    b64tohex(s) {\r\n        var ret = \"\";\r\n        var i;\r\n        var k = 0; // b64 state, 0-3\r\n        var slop;\r\n        for(i = 0; i < s.length; ++i) {\r\n            if(s.charAt(i) === b64pad) break;\r\n            var v = b64map.indexOf(s.charAt(i));\r\n            if(v < 0) continue;\r\n            if(k === 0) {\r\n                ret += String.fromCharCode(v >> 2);\r\n                slop = v & 3;\r\n                k = 1;\r\n            }\r\n            else if(k === 1) {\r\n                ret += String.fromCharCode((slop << 2) | (v >> 4));\r\n                slop = v & 0xf;\r\n                k = 2;\r\n            }\r\n            else if(k === 2) {\r\n                ret += String.fromCharCode(slop);\r\n                ret += String.fromCharCode(v >> 2);\r\n                slop = v & 3;\r\n                k = 3;\r\n            }\r\n            else {\r\n                ret += String.fromCharCode((slop << 2) | (v >> 4));\r\n                ret += String.fromCharCode(v & 0xf);\r\n                k = 0;\r\n            }\r\n        }\r\n        if(k === 1)\r\n            ret += String.fromCharCode(slop << 2);\r\n        return ret;\r\n    },\r\n    hexToBase64(h) {\r\n        var i;\r\n        var c;\r\n        var ret = \"\";\r\n        for(i = 0; i+3 <= h.length; i+=3) {\r\n            c = parseInt(h.substring(i,i+3),16);\r\n            ret += b64map.charAt(c >> 6) + b64map.charAt(c & 63);\r\n        }\r\n        if(i+1 === h.length) {\r\n            c = parseInt(h.substring(i,i+1),16);\r\n            ret += b64map.charAt(c << 2);\r\n        }\r\n        else if(i+2 === h.length) {\r\n            c = parseInt(h.substring(i,i+2),16);\r\n            ret += b64map.charAt(c >> 2) + b64map.charAt((c & 3) << 4);\r\n        }\r\n        if (b64pad) while((ret.length & 3) > 0) ret += b64pad;\r\n        return ret;\r\n    },\r\n\r\n    padding(str) {\r\n        var mod = (str.length % 4);\r\n        var pad = 4 - mod;\r\n\r\n        if (mod === 0) {\r\n            return str;\r\n        }\r\n\r\n        return str + (new Array(1 + pad)).join('=');\r\n    },\r\n\r\n    byteArrayToHex(raw) {\r\n        var HEX = '';\r\n\r\n        for (var i = 0; i < raw.length; i++) {\r\n            var _hex = raw[i].toString(16);\r\n            HEX += (_hex.length === 2 ? _hex : '0' + _hex);\r\n        }\r\n\r\n        return HEX;\r\n    },\r\n\r\n    decodeToHEX(str) {\r\n        return Base64.byteArrayToHex(base64Js.toByteArray(Base64.padding(str)));\r\n    },\r\n\r\n    base64ToBase64Url(s) {\r\n        s = s.replace(/=/g, \"\");\r\n        s = s.replace(/\\+/g, \"-\");\r\n        s = s.replace(/\\//g, \"_\");\r\n        return s;\r\n    },\r\n\r\n    urlDecode(str) {\r\n        str = str.replace(/-/g, '+') // Convert '-' to '+'\r\n            .replace(/_/g, '/') // Convert '_' to '/'\r\n            .replace(/\\s/g, ' '); // Convert '\\s' to ' '\r\n\r\n        return atob(str);\r\n    }\r\n};\r\n\r\n\r\nvar DigestInfoHead = {\r\n    sha1: '3021300906052b0e03021a05000414',\r\n    sha224: '302d300d06096086480165030402040500041c',\r\n    sha256: '3031300d060960864801650304020105000420',\r\n    sha384: '3041300d060960864801650304020205000430',\r\n    sha512: '3051300d060960864801650304020305000440',\r\n    md2: '3020300c06082a864886f70d020205000410',\r\n    md5: '3020300c06082a864886f70d020505000410',\r\n    ripemd160: '3021300906052b2403020105000414'\r\n};\r\n\r\nvar DigestAlgs = {\r\n    sha256: SHA256,\r\n    SHA256:SHA256\r\n};\r\n\r\nfunction RSAVerifier(modulus, exp) {\r\n    this.n = null;\r\n    this.e = 0;\r\n\r\n    if (modulus != null && exp != null && modulus.length > 0 && exp.length > 0) {\r\n        this.n = new BigInteger(modulus, 16);\r\n        this.e = parseInt(exp, 16);\r\n    } else {\r\n        throw new Error('Invalid key data');\r\n    }\r\n}\r\n\r\nfunction getAlgorithmFromDigest(hDigestInfo) {\r\n    for (var algName in DigestInfoHead) {\r\n        var head = DigestInfoHead[algName];\r\n        var len = head.length;\r\n\r\n        if (hDigestInfo.substring(0, len) === head) {\r\n            return {\r\n                alg: algName,\r\n                hash: hDigestInfo.substring(len)\r\n            };\r\n        }\r\n    }\r\n    return [];\r\n}\r\n\r\n\r\nRSAVerifier.prototype.verify = function (msg, encsig) {\r\n    encsig = Base64.decodeToHEX(encsig);\r\n    encsig = encsig.replace(/[^0-9a-f]|[\\s\\n]]/ig, '');\r\n\r\n    var sig = new BigInteger(encsig, 16);\r\n\r\n    if (sig.bitLength() > this.n.bitLength()) {\r\n        throw new Error('Signature does not match with the key modulus.');\r\n    }\r\n\r\n    var decryptedSig = sig.modPowInt(this.e, this.n);\r\n    var digest = decryptedSig.toString(16).replace(/^1f+00/, '');\r\n    var digestInfo = getAlgorithmFromDigest(digest);\r\n\r\n    if (digestInfo.length === 0) {\r\n        return false;\r\n    }\r\n\r\n    if (!DigestAlgs.hasOwnProperty(digestInfo.alg)) {\r\n        throw new Error('Hashing algorithm is not supported.');\r\n    }\r\n\r\n    var msgHash = DigestAlgs[digestInfo.alg](msg).toString();\r\n    return (digestInfo.hash === msgHash);\r\n};\r\n\r\nconst AllowedSigningAlgs = ['RS256'];\r\n\r\nconst jws = {\r\n    JWS: {\r\n        parse: function(token) {\r\n            var parts = token.split('.');\r\n            var header;\r\n            var payload;\r\n\r\n            // This diverges from Auth0's implementation, which throws rather than\r\n            // returning undefined\r\n            if (parts.length !== 3) {\r\n                return undefined;\r\n            }\r\n\r\n            try {\r\n                header = JSON.parse(Base64.urlDecode(parts[0]));\r\n                payload = JSON.parse(Base64.urlDecode(parts[1]));\r\n            } catch (e) {\r\n                return new Error('Token header or payload is not valid JSON');\r\n            }\r\n\r\n            return {\r\n                headerObj: header,\r\n                payloadObj: payload,\r\n            };\r\n        },\r\n        verify: function(jwt, key, allowedSigningAlgs = []) {\r\n            allowedSigningAlgs.forEach((alg) => {\r\n                if (AllowedSigningAlgs.indexOf(alg) === -1) {\r\n                    throw new Error('Invalid signing algorithm: ' + alg);\r\n                }\r\n            });\r\n            var verify = new RSAVerifier(key.n, key.e);\r\n            var parts = jwt.split('.');\r\n\r\n            var headerAndPayload = [parts[0], parts[1]].join('.');\r\n            return verify.verify(headerAndPayload, parts[2]);\r\n        },\r\n    },\r\n};\r\n\r\nconst KeyUtil = {\r\n    /**\r\n     * Returns decoded keys in Hex format for use in crypto functions.\r\n     * Supports modulus/exponent-style keys.\r\n     *\r\n     * @param {object} key the security key\r\n     * @returns\r\n     */\r\n    getKey(key) {\r\n        if (key.kty === 'RSA') {\r\n            return {\r\n                e: Base64.decodeToHEX(key.e),\r\n                n: Base64.decodeToHEX(key.n),\r\n            };\r\n        }\r\n\r\n        return null;\r\n    },\r\n};\r\n\r\nconst X509 = {\r\n    getPublicKeyFromCertPEM: function() {\r\n        throw new Error('Not implemented. Use the full oidc-client library if you need support for X509.');\r\n    },\r\n};\r\n\r\nconst crypto = {\r\n    Util: {\r\n        hashString: function(value, alg) {\r\n            var hashFunc = DigestAlgs[alg];\r\n            return hashFunc(value).toString();\r\n        },\r\n    }\r\n};\r\n\r\nfunction hextob64u(s) {\r\n    if (s.length % 2 === 1) {\r\n        s = '0' + s;\r\n    }\r\n    return Base64.base64ToBase64Url(Base64.hexToBase64(s));\r\n}\r\n\r\nconst {b64tohex} = Base64;\r\n\r\nexport {\r\n    jws,\r\n    KeyUtil,\r\n    X509,\r\n    crypto,\r\n    hextob64u,\r\n    b64tohex,\r\n    AllowedSigningAlgs\r\n};\r\n","import uuid4 from 'uuid/v4';\r\n\r\n/**\r\n * Generates RFC4122 version 4 guid ()\r\n */\r\n\r\nexport default function random() {\r\n  return uuid4().replace(/-/g, '');\r\n}\r\n","const Version = \"1.10.1\"; export {Version};"],"sourceRoot":""}"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/libs/oidc-client.slim.js",
    "content": "var Oidc =\n/******/ (function(modules) { // webpackBootstrap\n/******/ \t// The module cache\n/******/ \tvar installedModules = {};\n/******/\n/******/ \t// The require function\n/******/ \tfunction __webpack_require__(moduleId) {\n/******/\n/******/ \t\t// Check if module is in cache\n/******/ \t\tif(installedModules[moduleId]) {\n/******/ \t\t\treturn installedModules[moduleId].exports;\n/******/ \t\t}\n/******/ \t\t// Create a new module (and put it into the cache)\n/******/ \t\tvar module = installedModules[moduleId] = {\n/******/ \t\t\ti: moduleId,\n/******/ \t\t\tl: false,\n/******/ \t\t\texports: {}\n/******/ \t\t};\n/******/\n/******/ \t\t// Execute the module function\n/******/ \t\tmodules[moduleId].call(module.exports, module, module.exports, __webpack_require__);\n/******/\n/******/ \t\t// Flag the module as loaded\n/******/ \t\tmodule.l = true;\n/******/\n/******/ \t\t// Return the exports of the module\n/******/ \t\treturn module.exports;\n/******/ \t}\n/******/\n/******/\n/******/ \t// expose the modules object (__webpack_modules__)\n/******/ \t__webpack_require__.m = modules;\n/******/\n/******/ \t// expose the module cache\n/******/ \t__webpack_require__.c = installedModules;\n/******/\n/******/ \t// define getter function for harmony exports\n/******/ \t__webpack_require__.d = function(exports, name, getter) {\n/******/ \t\tif(!__webpack_require__.o(exports, name)) {\n/******/ \t\t\tObject.defineProperty(exports, name, { enumerable: true, get: getter });\n/******/ \t\t}\n/******/ \t};\n/******/\n/******/ \t// define __esModule on exports\n/******/ \t__webpack_require__.r = function(exports) {\n/******/ \t\tif(typeof Symbol !== 'undefined' && Symbol.toStringTag) {\n/******/ \t\t\tObject.defineProperty(exports, Symbol.toStringTag, { value: 'Module' });\n/******/ \t\t}\n/******/ \t\tObject.defineProperty(exports, '__esModule', { value: true });\n/******/ \t};\n/******/\n/******/ \t// create a fake namespace object\n/******/ \t// mode & 1: value is a module id, require it\n/******/ \t// mode & 2: merge all properties of value into the ns\n/******/ \t// mode & 4: return value when already ns object\n/******/ \t// mode & 8|1: behave like require\n/******/ \t__webpack_require__.t = function(value, mode) {\n/******/ \t\tif(mode & 1) value = __webpack_require__(value);\n/******/ \t\tif(mode & 8) return value;\n/******/ \t\tif((mode & 4) && typeof value === 'object' && value && value.__esModule) return value;\n/******/ \t\tvar ns = Object.create(null);\n/******/ \t\t__webpack_require__.r(ns);\n/******/ \t\tObject.defineProperty(ns, 'default', { enumerable: true, value: value });\n/******/ \t\tif(mode & 2 && typeof value != 'string') for(var key in value) __webpack_require__.d(ns, key, function(key) { return value[key]; }.bind(null, key));\n/******/ \t\treturn ns;\n/******/ \t};\n/******/\n/******/ \t// getDefaultExport function for compatibility with non-harmony modules\n/******/ \t__webpack_require__.n = function(module) {\n/******/ \t\tvar getter = module && module.__esModule ?\n/******/ \t\t\tfunction getDefault() { return module['default']; } :\n/******/ \t\t\tfunction getModuleExports() { return module; };\n/******/ \t\t__webpack_require__.d(getter, 'a', getter);\n/******/ \t\treturn getter;\n/******/ \t};\n/******/\n/******/ \t// Object.prototype.hasOwnProperty.call\n/******/ \t__webpack_require__.o = function(object, property) { return Object.prototype.hasOwnProperty.call(object, property); };\n/******/\n/******/ \t// __webpack_public_path__\n/******/ \t__webpack_require__.p = \"\";\n/******/\n/******/\n/******/ \t// Load entry module and return exports\n/******/ \treturn __webpack_require__(__webpack_require__.s = 0);\n/******/ })\n/************************************************************************/\n/******/ ({\n\n/***/ \"./index.js\":\n/*!******************!*\\\n  !*** ./index.js ***!\n  \\******************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _Log = __webpack_require__(/*! ./src/Log.js */ \"./src/Log.js\");\n\nvar _OidcClient = __webpack_require__(/*! ./src/OidcClient.js */ \"./src/OidcClient.js\");\n\nvar _OidcClientSettings = __webpack_require__(/*! ./src/OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./src/WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _InMemoryWebStorage = __webpack_require__(/*! ./src/InMemoryWebStorage.js */ \"./src/InMemoryWebStorage.js\");\n\nvar _UserManager = __webpack_require__(/*! ./src/UserManager.js */ \"./src/UserManager.js\");\n\nvar _AccessTokenEvents = __webpack_require__(/*! ./src/AccessTokenEvents.js */ \"./src/AccessTokenEvents.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./src/MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _CordovaPopupNavigator = __webpack_require__(/*! ./src/CordovaPopupNavigator.js */ \"./src/CordovaPopupNavigator.js\");\n\nvar _CordovaIFrameNavigator = __webpack_require__(/*! ./src/CordovaIFrameNavigator.js */ \"./src/CordovaIFrameNavigator.js\");\n\nvar _CheckSessionIFrame = __webpack_require__(/*! ./src/CheckSessionIFrame.js */ \"./src/CheckSessionIFrame.js\");\n\nvar _TokenRevocationClient = __webpack_require__(/*! ./src/TokenRevocationClient.js */ \"./src/TokenRevocationClient.js\");\n\nvar _SessionMonitor = __webpack_require__(/*! ./src/SessionMonitor.js */ \"./src/SessionMonitor.js\");\n\nvar _Global = __webpack_require__(/*! ./src/Global.js */ \"./src/Global.js\");\n\nvar _User = __webpack_require__(/*! ./src/User.js */ \"./src/User.js\");\n\nvar _version = __webpack_require__(/*! ./version.js */ \"./version.js\");\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nexports.default = {\n    Version: _version.Version,\n    Log: _Log.Log,\n    OidcClient: _OidcClient.OidcClient,\n    OidcClientSettings: _OidcClientSettings.OidcClientSettings,\n    WebStorageStateStore: _WebStorageStateStore.WebStorageStateStore,\n    InMemoryWebStorage: _InMemoryWebStorage.InMemoryWebStorage,\n    UserManager: _UserManager.UserManager,\n    AccessTokenEvents: _AccessTokenEvents.AccessTokenEvents,\n    MetadataService: _MetadataService.MetadataService,\n    CordovaPopupNavigator: _CordovaPopupNavigator.CordovaPopupNavigator,\n    CordovaIFrameNavigator: _CordovaIFrameNavigator.CordovaIFrameNavigator,\n    CheckSessionIFrame: _CheckSessionIFrame.CheckSessionIFrame,\n    TokenRevocationClient: _TokenRevocationClient.TokenRevocationClient,\n    SessionMonitor: _SessionMonitor.SessionMonitor,\n    Global: _Global.Global,\n    User: _User.User\n};\nmodule.exports = exports['default'];\n\n/***/ }),\n\n/***/ \"./jsrsasign/dist/jsrsasign.js\":\n/*!*************************************!*\\\n  !*** ./jsrsasign/dist/jsrsasign.js ***!\n  \\*************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n/* WEBPACK VAR INJECTION */(function(Buffer) {\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\n/*\n * jsrsasign(all) 8.0.12 (2018-04-22) (c) 2010-2018 Kenji Urushima | kjur.github.com/jsrsasign/license\n */\n\nvar navigator = {};\nnavigator.userAgent = false;\n\nvar window = {};\n\n/*!\nCopyright (c) 2011, Yahoo! Inc. All rights reserved.\nCode licensed under the BSD License:\nhttp://developer.yahoo.com/yui/license.html\nversion: 2.9.0\n*/\nif (YAHOO === undefined) {\n  var YAHOO = {};\n}YAHOO.lang = { extend: function extend(g, h, f) {\n    if (!h || !g) {\n      throw new Error(\"YAHOO.lang.extend failed, please check that all dependencies are included.\");\n    }var d = function d() {};d.prototype = h.prototype;g.prototype = new d();g.prototype.constructor = g;g.superclass = h.prototype;if (h.prototype.constructor == Object.prototype.constructor) {\n      h.prototype.constructor = h;\n    }if (f) {\n      var b;for (b in f) {\n        g.prototype[b] = f[b];\n      }var e = function e() {},\n          c = [\"toString\", \"valueOf\"];try {\n        if (/MSIE/.test(navigator.userAgent)) {\n          e = function e(j, i) {\n            for (b = 0; b < c.length; b = b + 1) {\n              var l = c[b],\n                  k = i[l];if (typeof k === \"function\" && k != Object.prototype[l]) {\n                j[l] = k;\n              }\n            }\n          };\n        }\n      } catch (a) {}e(g.prototype, f);\n    }\n  } };\n/*! CryptoJS v3.1.2 core-fix.js\n * code.google.com/p/crypto-js\n * (c) 2009-2013 by Jeff Mott. All rights reserved.\n * code.google.com/p/crypto-js/wiki/License\n * THIS IS FIX of 'core.js' to fix Hmac issue.\n * https://code.google.com/p/crypto-js/issues/detail?id=84\n * https://crypto-js.googlecode.com/svn-history/r667/branches/3.x/src/core.js\n */\nvar CryptoJS = CryptoJS || function (e, g) {\n  var a = {};var b = a.lib = {};var j = b.Base = function () {\n    function n() {}return { extend: function extend(p) {\n        n.prototype = this;var o = new n();if (p) {\n          o.mixIn(p);\n        }if (!o.hasOwnProperty(\"init\")) {\n          o.init = function () {\n            o.$super.init.apply(this, arguments);\n          };\n        }o.init.prototype = o;o.$super = this;return o;\n      }, create: function create() {\n        var o = this.extend();o.init.apply(o, arguments);return o;\n      }, init: function init() {}, mixIn: function mixIn(p) {\n        for (var o in p) {\n          if (p.hasOwnProperty(o)) {\n            this[o] = p[o];\n          }\n        }if (p.hasOwnProperty(\"toString\")) {\n          this.toString = p.toString;\n        }\n      }, clone: function clone() {\n        return this.init.prototype.extend(this);\n      } };\n  }();var l = b.WordArray = j.extend({ init: function init(o, n) {\n      o = this.words = o || [];if (n != g) {\n        this.sigBytes = n;\n      } else {\n        this.sigBytes = o.length * 4;\n      }\n    }, toString: function toString(n) {\n      return (n || h).stringify(this);\n    }, concat: function concat(t) {\n      var q = this.words;var p = t.words;var n = this.sigBytes;var s = t.sigBytes;this.clamp();if (n % 4) {\n        for (var r = 0; r < s; r++) {\n          var o = p[r >>> 2] >>> 24 - r % 4 * 8 & 255;q[n + r >>> 2] |= o << 24 - (n + r) % 4 * 8;\n        }\n      } else {\n        for (var r = 0; r < s; r += 4) {\n          q[n + r >>> 2] = p[r >>> 2];\n        }\n      }this.sigBytes += s;return this;\n    }, clamp: function clamp() {\n      var o = this.words;var n = this.sigBytes;o[n >>> 2] &= 4294967295 << 32 - n % 4 * 8;o.length = e.ceil(n / 4);\n    }, clone: function clone() {\n      var n = j.clone.call(this);n.words = this.words.slice(0);return n;\n    }, random: function random(p) {\n      var o = [];for (var n = 0; n < p; n += 4) {\n        o.push(e.random() * 4294967296 | 0);\n      }return new l.init(o, p);\n    } });var m = a.enc = {};var h = m.Hex = { stringify: function stringify(p) {\n      var r = p.words;var o = p.sigBytes;var q = [];for (var n = 0; n < o; n++) {\n        var s = r[n >>> 2] >>> 24 - n % 4 * 8 & 255;q.push((s >>> 4).toString(16));q.push((s & 15).toString(16));\n      }return q.join(\"\");\n    }, parse: function parse(p) {\n      var n = p.length;var q = [];for (var o = 0; o < n; o += 2) {\n        q[o >>> 3] |= parseInt(p.substr(o, 2), 16) << 24 - o % 8 * 4;\n      }return new l.init(q, n / 2);\n    } };var d = m.Latin1 = { stringify: function stringify(q) {\n      var r = q.words;var p = q.sigBytes;var n = [];for (var o = 0; o < p; o++) {\n        var s = r[o >>> 2] >>> 24 - o % 4 * 8 & 255;n.push(String.fromCharCode(s));\n      }return n.join(\"\");\n    }, parse: function parse(p) {\n      var n = p.length;var q = [];for (var o = 0; o < n; o++) {\n        q[o >>> 2] |= (p.charCodeAt(o) & 255) << 24 - o % 4 * 8;\n      }return new l.init(q, n);\n    } };var c = m.Utf8 = { stringify: function stringify(n) {\n      try {\n        return decodeURIComponent(escape(d.stringify(n)));\n      } catch (o) {\n        throw new Error(\"Malformed UTF-8 data\");\n      }\n    }, parse: function parse(n) {\n      return d.parse(unescape(encodeURIComponent(n)));\n    } };var i = b.BufferedBlockAlgorithm = j.extend({ reset: function reset() {\n      this._data = new l.init();this._nDataBytes = 0;\n    }, _append: function _append(n) {\n      if (typeof n == \"string\") {\n        n = c.parse(n);\n      }this._data.concat(n);this._nDataBytes += n.sigBytes;\n    }, _process: function _process(w) {\n      var q = this._data;var x = q.words;var n = q.sigBytes;var t = this.blockSize;var v = t * 4;var u = n / v;if (w) {\n        u = e.ceil(u);\n      } else {\n        u = e.max((u | 0) - this._minBufferSize, 0);\n      }var s = u * t;var r = e.min(s * 4, n);if (s) {\n        for (var p = 0; p < s; p += t) {\n          this._doProcessBlock(x, p);\n        }var o = x.splice(0, s);q.sigBytes -= r;\n      }return new l.init(o, r);\n    }, clone: function clone() {\n      var n = j.clone.call(this);n._data = this._data.clone();return n;\n    }, _minBufferSize: 0 });var f = b.Hasher = i.extend({ cfg: j.extend(), init: function init(n) {\n      this.cfg = this.cfg.extend(n);this.reset();\n    }, reset: function reset() {\n      i.reset.call(this);this._doReset();\n    }, update: function update(n) {\n      this._append(n);this._process();return this;\n    }, finalize: function finalize(n) {\n      if (n) {\n        this._append(n);\n      }var o = this._doFinalize();return o;\n    }, blockSize: 512 / 32, _createHelper: function _createHelper(n) {\n      return function (p, o) {\n        return new n.init(o).finalize(p);\n      };\n    }, _createHmacHelper: function _createHmacHelper(n) {\n      return function (p, o) {\n        return new k.HMAC.init(n, o).finalize(p);\n      };\n    } });var k = a.algo = {};return a;\n}(Math);\n/*\nCryptoJS v3.1.2 x64-core-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function (g) {\n  var a = CryptoJS,\n      f = a.lib,\n      e = f.Base,\n      h = f.WordArray,\n      a = a.x64 = {};a.Word = e.extend({ init: function init(b, c) {\n      this.high = b;this.low = c;\n    } });a.WordArray = e.extend({ init: function init(b, c) {\n      b = this.words = b || [];this.sigBytes = c != g ? c : 8 * b.length;\n    }, toX32: function toX32() {\n      for (var b = this.words, c = b.length, a = [], d = 0; d < c; d++) {\n        var e = b[d];a.push(e.high);a.push(e.low);\n      }return h.create(a, this.sigBytes);\n    }, clone: function clone() {\n      for (var b = e.clone.call(this), c = b.words = this.words.slice(0), a = c.length, d = 0; d < a; d++) {\n        c[d] = c[d].clone();\n      }return b;\n    } });\n})();\n\n/*\nCryptoJS v3.1.2 enc-base64.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function () {\n  var h = CryptoJS,\n      j = h.lib.WordArray;h.enc.Base64 = { stringify: function stringify(b) {\n      var e = b.words,\n          f = b.sigBytes,\n          c = this._map;b.clamp();b = [];for (var a = 0; a < f; a += 3) {\n        for (var d = (e[a >>> 2] >>> 24 - 8 * (a % 4) & 255) << 16 | (e[a + 1 >>> 2] >>> 24 - 8 * ((a + 1) % 4) & 255) << 8 | e[a + 2 >>> 2] >>> 24 - 8 * ((a + 2) % 4) & 255, g = 0; 4 > g && a + 0.75 * g < f; g++) {\n          b.push(c.charAt(d >>> 6 * (3 - g) & 63));\n        }\n      }if (e = c.charAt(64)) for (; b.length % 4;) {\n        b.push(e);\n      }return b.join(\"\");\n    }, parse: function parse(b) {\n      var e = b.length,\n          f = this._map,\n          c = f.charAt(64);c && (c = b.indexOf(c), -1 != c && (e = c));for (var c = [], a = 0, d = 0; d < e; d++) {\n        if (d % 4) {\n          var g = f.indexOf(b.charAt(d - 1)) << 2 * (d % 4),\n              h = f.indexOf(b.charAt(d)) >>> 6 - 2 * (d % 4);c[a >>> 2] |= (g | h) << 24 - 8 * (a % 4);a++;\n        }\n      }return j.create(c, a);\n    }, _map: \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=\" };\n})();\n\n/*\nCryptoJS v3.1.2 sha256-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function (k) {\n  for (var g = CryptoJS, h = g.lib, v = h.WordArray, j = h.Hasher, h = g.algo, s = [], t = [], u = function u(q) {\n    return 4294967296 * (q - (q | 0)) | 0;\n  }, l = 2, b = 0; 64 > b;) {\n    var d;a: {\n      d = l;for (var w = k.sqrt(d), r = 2; r <= w; r++) {\n        if (!(d % r)) {\n          d = !1;break a;\n        }\n      }d = !0;\n    }d && (8 > b && (s[b] = u(k.pow(l, 0.5))), t[b] = u(k.pow(l, 1 / 3)), b++);l++;\n  }var n = [],\n      h = h.SHA256 = j.extend({ _doReset: function _doReset() {\n      this._hash = new v.init(s.slice(0));\n    }, _doProcessBlock: function _doProcessBlock(q, h) {\n      for (var a = this._hash.words, c = a[0], d = a[1], b = a[2], k = a[3], f = a[4], g = a[5], j = a[6], l = a[7], e = 0; 64 > e; e++) {\n        if (16 > e) n[e] = q[h + e] | 0;else {\n          var m = n[e - 15],\n              p = n[e - 2];n[e] = ((m << 25 | m >>> 7) ^ (m << 14 | m >>> 18) ^ m >>> 3) + n[e - 7] + ((p << 15 | p >>> 17) ^ (p << 13 | p >>> 19) ^ p >>> 10) + n[e - 16];\n        }m = l + ((f << 26 | f >>> 6) ^ (f << 21 | f >>> 11) ^ (f << 7 | f >>> 25)) + (f & g ^ ~f & j) + t[e] + n[e];p = ((c << 30 | c >>> 2) ^ (c << 19 | c >>> 13) ^ (c << 10 | c >>> 22)) + (c & d ^ c & b ^ d & b);l = j;j = g;g = f;f = k + m | 0;k = b;b = d;d = c;c = m + p | 0;\n      }a[0] = a[0] + c | 0;a[1] = a[1] + d | 0;a[2] = a[2] + b | 0;a[3] = a[3] + k | 0;a[4] = a[4] + f | 0;a[5] = a[5] + g | 0;a[6] = a[6] + j | 0;a[7] = a[7] + l | 0;\n    }, _doFinalize: function _doFinalize() {\n      var d = this._data,\n          b = d.words,\n          a = 8 * this._nDataBytes,\n          c = 8 * d.sigBytes;\n      b[c >>> 5] |= 128 << 24 - c % 32;b[(c + 64 >>> 9 << 4) + 14] = k.floor(a / 4294967296);b[(c + 64 >>> 9 << 4) + 15] = a;d.sigBytes = 4 * b.length;this._process();return this._hash;\n    }, clone: function clone() {\n      var b = j.clone.call(this);b._hash = this._hash.clone();return b;\n    } });g.SHA256 = j._createHelper(h);g.HmacSHA256 = j._createHmacHelper(h);\n})(Math);\n\n/*\nCryptoJS v3.1.2 sha512-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function () {\n  function a() {\n    return d.create.apply(d, arguments);\n  }for (var n = CryptoJS, r = n.lib.Hasher, e = n.x64, d = e.Word, T = e.WordArray, e = n.algo, ea = [a(1116352408, 3609767458), a(1899447441, 602891725), a(3049323471, 3964484399), a(3921009573, 2173295548), a(961987163, 4081628472), a(1508970993, 3053834265), a(2453635748, 2937671579), a(2870763221, 3664609560), a(3624381080, 2734883394), a(310598401, 1164996542), a(607225278, 1323610764), a(1426881987, 3590304994), a(1925078388, 4068182383), a(2162078206, 991336113), a(2614888103, 633803317), a(3248222580, 3479774868), a(3835390401, 2666613458), a(4022224774, 944711139), a(264347078, 2341262773), a(604807628, 2007800933), a(770255983, 1495990901), a(1249150122, 1856431235), a(1555081692, 3175218132), a(1996064986, 2198950837), a(2554220882, 3999719339), a(2821834349, 766784016), a(2952996808, 2566594879), a(3210313671, 3203337956), a(3336571891, 1034457026), a(3584528711, 2466948901), a(113926993, 3758326383), a(338241895, 168717936), a(666307205, 1188179964), a(773529912, 1546045734), a(1294757372, 1522805485), a(1396182291, 2643833823), a(1695183700, 2343527390), a(1986661051, 1014477480), a(2177026350, 1206759142), a(2456956037, 344077627), a(2730485921, 1290863460), a(2820302411, 3158454273), a(3259730800, 3505952657), a(3345764771, 106217008), a(3516065817, 3606008344), a(3600352804, 1432725776), a(4094571909, 1467031594), a(275423344, 851169720), a(430227734, 3100823752), a(506948616, 1363258195), a(659060556, 3750685593), a(883997877, 3785050280), a(958139571, 3318307427), a(1322822218, 3812723403), a(1537002063, 2003034995), a(1747873779, 3602036899), a(1955562222, 1575990012), a(2024104815, 1125592928), a(2227730452, 2716904306), a(2361852424, 442776044), a(2428436474, 593698344), a(2756734187, 3733110249), a(3204031479, 2999351573), a(3329325298, 3815920427), a(3391569614, 3928383900), a(3515267271, 566280711), a(3940187606, 3454069534), a(4118630271, 4000239992), a(116418474, 1914138554), a(174292421, 2731055270), a(289380356, 3203993006), a(460393269, 320620315), a(685471733, 587496836), a(852142971, 1086792851), a(1017036298, 365543100), a(1126000580, 2618297676), a(1288033470, 3409855158), a(1501505948, 4234509866), a(1607167915, 987167468), a(1816402316, 1246189591)], v = [], w = 0; 80 > w; w++) {\n    v[w] = a();\n  }e = e.SHA512 = r.extend({ _doReset: function _doReset() {\n      this._hash = new T.init([new d.init(1779033703, 4089235720), new d.init(3144134277, 2227873595), new d.init(1013904242, 4271175723), new d.init(2773480762, 1595750129), new d.init(1359893119, 2917565137), new d.init(2600822924, 725511199), new d.init(528734635, 4215389547), new d.init(1541459225, 327033209)]);\n    }, _doProcessBlock: function _doProcessBlock(a, d) {\n      for (var f = this._hash.words, F = f[0], e = f[1], n = f[2], r = f[3], G = f[4], H = f[5], I = f[6], f = f[7], w = F.high, J = F.low, X = e.high, K = e.low, Y = n.high, L = n.low, Z = r.high, M = r.low, $ = G.high, N = G.low, aa = H.high, O = H.low, ba = I.high, P = I.low, ca = f.high, Q = f.low, k = w, g = J, z = X, x = K, A = Y, y = L, U = Z, B = M, l = $, h = N, R = aa, C = O, S = ba, D = P, V = ca, E = Q, m = 0; 80 > m; m++) {\n        var s = v[m];if (16 > m) var j = s.high = a[d + 2 * m] | 0,\n            b = s.low = a[d + 2 * m + 1] | 0;else {\n          var j = v[m - 15],\n              b = j.high,\n              p = j.low,\n              j = (b >>> 1 | p << 31) ^ (b >>> 8 | p << 24) ^ b >>> 7,\n              p = (p >>> 1 | b << 31) ^ (p >>> 8 | b << 24) ^ (p >>> 7 | b << 25),\n              u = v[m - 2],\n              b = u.high,\n              c = u.low,\n              u = (b >>> 19 | c << 13) ^ (b << 3 | c >>> 29) ^ b >>> 6,\n              c = (c >>> 19 | b << 13) ^ (c << 3 | b >>> 29) ^ (c >>> 6 | b << 26),\n              b = v[m - 7],\n              W = b.high,\n              t = v[m - 16],\n              q = t.high,\n              t = t.low,\n              b = p + b.low,\n              j = j + W + (b >>> 0 < p >>> 0 ? 1 : 0),\n              b = b + c,\n              j = j + u + (b >>> 0 < c >>> 0 ? 1 : 0),\n              b = b + t,\n              j = j + q + (b >>> 0 < t >>> 0 ? 1 : 0);s.high = j;s.low = b;\n        }var W = l & R ^ ~l & S,\n            t = h & C ^ ~h & D,\n            s = k & z ^ k & A ^ z & A,\n            T = g & x ^ g & y ^ x & y,\n            p = (k >>> 28 | g << 4) ^ (k << 30 | g >>> 2) ^ (k << 25 | g >>> 7),\n            u = (g >>> 28 | k << 4) ^ (g << 30 | k >>> 2) ^ (g << 25 | k >>> 7),\n            c = ea[m],\n            fa = c.high,\n            da = c.low,\n            c = E + ((h >>> 14 | l << 18) ^ (h >>> 18 | l << 14) ^ (h << 23 | l >>> 9)),\n            q = V + ((l >>> 14 | h << 18) ^ (l >>> 18 | h << 14) ^ (l << 23 | h >>> 9)) + (c >>> 0 < E >>> 0 ? 1 : 0),\n            c = c + t,\n            q = q + W + (c >>> 0 < t >>> 0 ? 1 : 0),\n            c = c + da,\n            q = q + fa + (c >>> 0 < da >>> 0 ? 1 : 0),\n            c = c + b,\n            q = q + j + (c >>> 0 < b >>> 0 ? 1 : 0),\n            b = u + T,\n            s = p + s + (b >>> 0 < u >>> 0 ? 1 : 0),\n            V = S,\n            E = D,\n            S = R,\n            D = C,\n            R = l,\n            C = h,\n            h = B + c | 0,\n            l = U + q + (h >>> 0 < B >>> 0 ? 1 : 0) | 0,\n            U = A,\n            B = y,\n            A = z,\n            y = x,\n            z = k,\n            x = g,\n            g = c + b | 0,\n            k = q + s + (g >>> 0 < c >>> 0 ? 1 : 0) | 0;\n      }J = F.low = J + g;F.high = w + k + (J >>> 0 < g >>> 0 ? 1 : 0);K = e.low = K + x;e.high = X + z + (K >>> 0 < x >>> 0 ? 1 : 0);L = n.low = L + y;n.high = Y + A + (L >>> 0 < y >>> 0 ? 1 : 0);M = r.low = M + B;r.high = Z + U + (M >>> 0 < B >>> 0 ? 1 : 0);N = G.low = N + h;G.high = $ + l + (N >>> 0 < h >>> 0 ? 1 : 0);O = H.low = O + C;H.high = aa + R + (O >>> 0 < C >>> 0 ? 1 : 0);P = I.low = P + D;\n      I.high = ba + S + (P >>> 0 < D >>> 0 ? 1 : 0);Q = f.low = Q + E;f.high = ca + V + (Q >>> 0 < E >>> 0 ? 1 : 0);\n    }, _doFinalize: function _doFinalize() {\n      var a = this._data,\n          d = a.words,\n          f = 8 * this._nDataBytes,\n          e = 8 * a.sigBytes;d[e >>> 5] |= 128 << 24 - e % 32;d[(e + 128 >>> 10 << 5) + 30] = Math.floor(f / 4294967296);d[(e + 128 >>> 10 << 5) + 31] = f;a.sigBytes = 4 * d.length;this._process();return this._hash.toX32();\n    }, clone: function clone() {\n      var a = r.clone.call(this);a._hash = this._hash.clone();return a;\n    }, blockSize: 32 });n.SHA512 = r._createHelper(e);n.HmacSHA512 = r._createHmacHelper(e);\n})();\n\n/*\nCryptoJS v3.1.2 sha384-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function () {\n  var c = CryptoJS,\n      a = c.x64,\n      b = a.Word,\n      e = a.WordArray,\n      a = c.algo,\n      d = a.SHA512,\n      a = a.SHA384 = d.extend({ _doReset: function _doReset() {\n      this._hash = new e.init([new b.init(3418070365, 3238371032), new b.init(1654270250, 914150663), new b.init(2438529370, 812702999), new b.init(355462360, 4144912697), new b.init(1731405415, 4290775857), new b.init(2394180231, 1750603025), new b.init(3675008525, 1694076839), new b.init(1203062813, 3204075428)]);\n    }, _doFinalize: function _doFinalize() {\n      var a = d._doFinalize.call(this);a.sigBytes -= 16;return a;\n    } });c.SHA384 = d._createHelper(a);c.HmacSHA384 = d._createHmacHelper(a);\n})();\n\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nvar b64map = \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\";var b64pad = \"=\";function hex2b64(d) {\n  var b;var e;var a = \"\";for (b = 0; b + 3 <= d.length; b += 3) {\n    e = parseInt(d.substring(b, b + 3), 16);a += b64map.charAt(e >> 6) + b64map.charAt(e & 63);\n  }if (b + 1 == d.length) {\n    e = parseInt(d.substring(b, b + 1), 16);a += b64map.charAt(e << 2);\n  } else {\n    if (b + 2 == d.length) {\n      e = parseInt(d.substring(b, b + 2), 16);a += b64map.charAt(e >> 2) + b64map.charAt((e & 3) << 4);\n    }\n  }if (b64pad) {\n    while ((a.length & 3) > 0) {\n      a += b64pad;\n    }\n  }return a;\n}function b64tohex(f) {\n  var d = \"\";var e;var b = 0;var c;var a;for (e = 0; e < f.length; ++e) {\n    if (f.charAt(e) == b64pad) {\n      break;\n    }a = b64map.indexOf(f.charAt(e));if (a < 0) {\n      continue;\n    }if (b == 0) {\n      d += int2char(a >> 2);c = a & 3;b = 1;\n    } else {\n      if (b == 1) {\n        d += int2char(c << 2 | a >> 4);c = a & 15;b = 2;\n      } else {\n        if (b == 2) {\n          d += int2char(c);d += int2char(a >> 2);c = a & 3;b = 3;\n        } else {\n          d += int2char(c << 2 | a >> 4);d += int2char(a & 15);b = 0;\n        }\n      }\n    }\n  }if (b == 1) {\n    d += int2char(c << 2);\n  }return d;\n}function b64toBA(e) {\n  var d = b64tohex(e);var c;var b = new Array();for (c = 0; 2 * c < d.length; ++c) {\n    b[c] = parseInt(d.substring(2 * c, 2 * c + 2), 16);\n  }return b;\n};\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nvar dbits;var canary = 244837814094590;var j_lm = (canary & 16777215) == 15715070;function BigInteger(e, d, f) {\n  if (e != null) {\n    if (\"number\" == typeof e) {\n      this.fromNumber(e, d, f);\n    } else {\n      if (d == null && \"string\" != typeof e) {\n        this.fromString(e, 256);\n      } else {\n        this.fromString(e, d);\n      }\n    }\n  }\n}function nbi() {\n  return new BigInteger(null);\n}function am1(f, a, b, e, h, g) {\n  while (--g >= 0) {\n    var d = a * this[f++] + b[e] + h;h = Math.floor(d / 67108864);b[e++] = d & 67108863;\n  }return h;\n}function am2(f, q, r, e, o, a) {\n  var k = q & 32767,\n      p = q >> 15;while (--a >= 0) {\n    var d = this[f] & 32767;var g = this[f++] >> 15;var b = p * d + g * k;d = k * d + ((b & 32767) << 15) + r[e] + (o & 1073741823);o = (d >>> 30) + (b >>> 15) + p * g + (o >>> 30);r[e++] = d & 1073741823;\n  }return o;\n}function am3(f, q, r, e, o, a) {\n  var k = q & 16383,\n      p = q >> 14;while (--a >= 0) {\n    var d = this[f] & 16383;var g = this[f++] >> 14;var b = p * d + g * k;d = k * d + ((b & 16383) << 14) + r[e] + o;o = (d >> 28) + (b >> 14) + p * g;r[e++] = d & 268435455;\n  }return o;\n}if (j_lm && navigator.appName == \"Microsoft Internet Explorer\") {\n  BigInteger.prototype.am = am2;dbits = 30;\n} else {\n  if (j_lm && navigator.appName != \"Netscape\") {\n    BigInteger.prototype.am = am1;dbits = 26;\n  } else {\n    BigInteger.prototype.am = am3;dbits = 28;\n  }\n}BigInteger.prototype.DB = dbits;BigInteger.prototype.DM = (1 << dbits) - 1;BigInteger.prototype.DV = 1 << dbits;var BI_FP = 52;BigInteger.prototype.FV = Math.pow(2, BI_FP);BigInteger.prototype.F1 = BI_FP - dbits;BigInteger.prototype.F2 = 2 * dbits - BI_FP;var BI_RM = \"0123456789abcdefghijklmnopqrstuvwxyz\";var BI_RC = new Array();var rr, vv;rr = \"0\".charCodeAt(0);for (vv = 0; vv <= 9; ++vv) {\n  BI_RC[rr++] = vv;\n}rr = \"a\".charCodeAt(0);for (vv = 10; vv < 36; ++vv) {\n  BI_RC[rr++] = vv;\n}rr = \"A\".charCodeAt(0);for (vv = 10; vv < 36; ++vv) {\n  BI_RC[rr++] = vv;\n}function int2char(a) {\n  return BI_RM.charAt(a);\n}function intAt(b, a) {\n  var d = BI_RC[b.charCodeAt(a)];return d == null ? -1 : d;\n}function bnpCopyTo(b) {\n  for (var a = this.t - 1; a >= 0; --a) {\n    b[a] = this[a];\n  }b.t = this.t;b.s = this.s;\n}function bnpFromInt(a) {\n  this.t = 1;this.s = a < 0 ? -1 : 0;if (a > 0) {\n    this[0] = a;\n  } else {\n    if (a < -1) {\n      this[0] = a + this.DV;\n    } else {\n      this.t = 0;\n    }\n  }\n}function nbv(a) {\n  var b = nbi();b.fromInt(a);return b;\n}function bnpFromString(h, c) {\n  var e;if (c == 16) {\n    e = 4;\n  } else {\n    if (c == 8) {\n      e = 3;\n    } else {\n      if (c == 256) {\n        e = 8;\n      } else {\n        if (c == 2) {\n          e = 1;\n        } else {\n          if (c == 32) {\n            e = 5;\n          } else {\n            if (c == 4) {\n              e = 2;\n            } else {\n              this.fromRadix(h, c);return;\n            }\n          }\n        }\n      }\n    }\n  }this.t = 0;this.s = 0;var g = h.length,\n      d = false,\n      f = 0;while (--g >= 0) {\n    var a = e == 8 ? h[g] & 255 : intAt(h, g);if (a < 0) {\n      if (h.charAt(g) == \"-\") {\n        d = true;\n      }continue;\n    }d = false;if (f == 0) {\n      this[this.t++] = a;\n    } else {\n      if (f + e > this.DB) {\n        this[this.t - 1] |= (a & (1 << this.DB - f) - 1) << f;this[this.t++] = a >> this.DB - f;\n      } else {\n        this[this.t - 1] |= a << f;\n      }\n    }f += e;if (f >= this.DB) {\n      f -= this.DB;\n    }\n  }if (e == 8 && (h[0] & 128) != 0) {\n    this.s = -1;if (f > 0) {\n      this[this.t - 1] |= (1 << this.DB - f) - 1 << f;\n    }\n  }this.clamp();if (d) {\n    BigInteger.ZERO.subTo(this, this);\n  }\n}function bnpClamp() {\n  var a = this.s & this.DM;while (this.t > 0 && this[this.t - 1] == a) {\n    --this.t;\n  }\n}function bnToString(c) {\n  if (this.s < 0) {\n    return \"-\" + this.negate().toString(c);\n  }var e;if (c == 16) {\n    e = 4;\n  } else {\n    if (c == 8) {\n      e = 3;\n    } else {\n      if (c == 2) {\n        e = 1;\n      } else {\n        if (c == 32) {\n          e = 5;\n        } else {\n          if (c == 4) {\n            e = 2;\n          } else {\n            return this.toRadix(c);\n          }\n        }\n      }\n    }\n  }var g = (1 << e) - 1,\n      l,\n      a = false,\n      h = \"\",\n      f = this.t;var j = this.DB - f * this.DB % e;if (f-- > 0) {\n    if (j < this.DB && (l = this[f] >> j) > 0) {\n      a = true;h = int2char(l);\n    }while (f >= 0) {\n      if (j < e) {\n        l = (this[f] & (1 << j) - 1) << e - j;l |= this[--f] >> (j += this.DB - e);\n      } else {\n        l = this[f] >> (j -= e) & g;if (j <= 0) {\n          j += this.DB;--f;\n        }\n      }if (l > 0) {\n        a = true;\n      }if (a) {\n        h += int2char(l);\n      }\n    }\n  }return a ? h : \"0\";\n}function bnNegate() {\n  var a = nbi();BigInteger.ZERO.subTo(this, a);return a;\n}function bnAbs() {\n  return this.s < 0 ? this.negate() : this;\n}function bnCompareTo(b) {\n  var d = this.s - b.s;if (d != 0) {\n    return d;\n  }var c = this.t;d = c - b.t;if (d != 0) {\n    return this.s < 0 ? -d : d;\n  }while (--c >= 0) {\n    if ((d = this[c] - b[c]) != 0) {\n      return d;\n    }\n  }return 0;\n}function nbits(a) {\n  var c = 1,\n      b;if ((b = a >>> 16) != 0) {\n    a = b;c += 16;\n  }if ((b = a >> 8) != 0) {\n    a = b;c += 8;\n  }if ((b = a >> 4) != 0) {\n    a = b;c += 4;\n  }if ((b = a >> 2) != 0) {\n    a = b;c += 2;\n  }if ((b = a >> 1) != 0) {\n    a = b;c += 1;\n  }return c;\n}function bnBitLength() {\n  if (this.t <= 0) {\n    return 0;\n  }return this.DB * (this.t - 1) + nbits(this[this.t - 1] ^ this.s & this.DM);\n}function bnpDLShiftTo(c, b) {\n  var a;for (a = this.t - 1; a >= 0; --a) {\n    b[a + c] = this[a];\n  }for (a = c - 1; a >= 0; --a) {\n    b[a] = 0;\n  }b.t = this.t + c;b.s = this.s;\n}function bnpDRShiftTo(c, b) {\n  for (var a = c; a < this.t; ++a) {\n    b[a - c] = this[a];\n  }b.t = Math.max(this.t - c, 0);b.s = this.s;\n}function bnpLShiftTo(j, e) {\n  var b = j % this.DB;var a = this.DB - b;var g = (1 << a) - 1;var f = Math.floor(j / this.DB),\n      h = this.s << b & this.DM,\n      d;for (d = this.t - 1; d >= 0; --d) {\n    e[d + f + 1] = this[d] >> a | h;h = (this[d] & g) << b;\n  }for (d = f - 1; d >= 0; --d) {\n    e[d] = 0;\n  }e[f] = h;e.t = this.t + f + 1;e.s = this.s;e.clamp();\n}function bnpRShiftTo(g, d) {\n  d.s = this.s;var e = Math.floor(g / this.DB);if (e >= this.t) {\n    d.t = 0;return;\n  }var b = g % this.DB;var a = this.DB - b;var f = (1 << b) - 1;d[0] = this[e] >> b;for (var c = e + 1; c < this.t; ++c) {\n    d[c - e - 1] |= (this[c] & f) << a;d[c - e] = this[c] >> b;\n  }if (b > 0) {\n    d[this.t - e - 1] |= (this.s & f) << a;\n  }d.t = this.t - e;d.clamp();\n}function bnpSubTo(d, f) {\n  var e = 0,\n      g = 0,\n      b = Math.min(d.t, this.t);while (e < b) {\n    g += this[e] - d[e];f[e++] = g & this.DM;g >>= this.DB;\n  }if (d.t < this.t) {\n    g -= d.s;while (e < this.t) {\n      g += this[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g += this.s;\n  } else {\n    g += this.s;while (e < d.t) {\n      g -= d[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g -= d.s;\n  }f.s = g < 0 ? -1 : 0;if (g < -1) {\n    f[e++] = this.DV + g;\n  } else {\n    if (g > 0) {\n      f[e++] = g;\n    }\n  }f.t = e;f.clamp();\n}function bnpMultiplyTo(c, e) {\n  var b = this.abs(),\n      f = c.abs();var d = b.t;e.t = d + f.t;while (--d >= 0) {\n    e[d] = 0;\n  }for (d = 0; d < f.t; ++d) {\n    e[d + b.t] = b.am(0, f[d], e, d, 0, b.t);\n  }e.s = 0;e.clamp();if (this.s != c.s) {\n    BigInteger.ZERO.subTo(e, e);\n  }\n}function bnpSquareTo(d) {\n  var a = this.abs();var b = d.t = 2 * a.t;while (--b >= 0) {\n    d[b] = 0;\n  }for (b = 0; b < a.t - 1; ++b) {\n    var e = a.am(b, a[b], d, 2 * b, 0, 1);if ((d[b + a.t] += a.am(b + 1, 2 * a[b], d, 2 * b + 1, e, a.t - b - 1)) >= a.DV) {\n      d[b + a.t] -= a.DV;d[b + a.t + 1] = 1;\n    }\n  }if (d.t > 0) {\n    d[d.t - 1] += a.am(b, a[b], d, 2 * b, 0, 1);\n  }d.s = 0;d.clamp();\n}function bnpDivRemTo(n, h, g) {\n  var w = n.abs();if (w.t <= 0) {\n    return;\n  }var k = this.abs();if (k.t < w.t) {\n    if (h != null) {\n      h.fromInt(0);\n    }if (g != null) {\n      this.copyTo(g);\n    }return;\n  }if (g == null) {\n    g = nbi();\n  }var d = nbi(),\n      a = this.s,\n      l = n.s;var v = this.DB - nbits(w[w.t - 1]);if (v > 0) {\n    w.lShiftTo(v, d);k.lShiftTo(v, g);\n  } else {\n    w.copyTo(d);k.copyTo(g);\n  }var p = d.t;var b = d[p - 1];if (b == 0) {\n    return;\n  }var o = b * (1 << this.F1) + (p > 1 ? d[p - 2] >> this.F2 : 0);var A = this.FV / o,\n      z = (1 << this.F1) / o,\n      x = 1 << this.F2;var u = g.t,\n      s = u - p,\n      f = h == null ? nbi() : h;d.dlShiftTo(s, f);if (g.compareTo(f) >= 0) {\n    g[g.t++] = 1;g.subTo(f, g);\n  }BigInteger.ONE.dlShiftTo(p, f);f.subTo(d, d);while (d.t < p) {\n    d[d.t++] = 0;\n  }while (--s >= 0) {\n    var c = g[--u] == b ? this.DM : Math.floor(g[u] * A + (g[u - 1] + x) * z);if ((g[u] += d.am(0, c, g, s, 0, p)) < c) {\n      d.dlShiftTo(s, f);g.subTo(f, g);while (g[u] < --c) {\n        g.subTo(f, g);\n      }\n    }\n  }if (h != null) {\n    g.drShiftTo(p, h);if (a != l) {\n      BigInteger.ZERO.subTo(h, h);\n    }\n  }g.t = p;g.clamp();if (v > 0) {\n    g.rShiftTo(v, g);\n  }if (a < 0) {\n    BigInteger.ZERO.subTo(g, g);\n  }\n}function bnMod(b) {\n  var c = nbi();this.abs().divRemTo(b, null, c);if (this.s < 0 && c.compareTo(BigInteger.ZERO) > 0) {\n    b.subTo(c, c);\n  }return c;\n}function Classic(a) {\n  this.m = a;\n}function cConvert(a) {\n  if (a.s < 0 || a.compareTo(this.m) >= 0) {\n    return a.mod(this.m);\n  } else {\n    return a;\n  }\n}function cRevert(a) {\n  return a;\n}function cReduce(a) {\n  a.divRemTo(this.m, null, a);\n}function cMulTo(a, c, b) {\n  a.multiplyTo(c, b);this.reduce(b);\n}function cSqrTo(a, b) {\n  a.squareTo(b);this.reduce(b);\n}Classic.prototype.convert = cConvert;Classic.prototype.revert = cRevert;Classic.prototype.reduce = cReduce;Classic.prototype.mulTo = cMulTo;Classic.prototype.sqrTo = cSqrTo;function bnpInvDigit() {\n  if (this.t < 1) {\n    return 0;\n  }var a = this[0];if ((a & 1) == 0) {\n    return 0;\n  }var b = a & 3;b = b * (2 - (a & 15) * b) & 15;b = b * (2 - (a & 255) * b) & 255;b = b * (2 - ((a & 65535) * b & 65535)) & 65535;b = b * (2 - a * b % this.DV) % this.DV;return b > 0 ? this.DV - b : -b;\n}function Montgomery(a) {\n  this.m = a;this.mp = a.invDigit();this.mpl = this.mp & 32767;this.mph = this.mp >> 15;this.um = (1 << a.DB - 15) - 1;this.mt2 = 2 * a.t;\n}function montConvert(a) {\n  var b = nbi();a.abs().dlShiftTo(this.m.t, b);b.divRemTo(this.m, null, b);if (a.s < 0 && b.compareTo(BigInteger.ZERO) > 0) {\n    this.m.subTo(b, b);\n  }return b;\n}function montRevert(a) {\n  var b = nbi();a.copyTo(b);this.reduce(b);return b;\n}function montReduce(a) {\n  while (a.t <= this.mt2) {\n    a[a.t++] = 0;\n  }for (var c = 0; c < this.m.t; ++c) {\n    var b = a[c] & 32767;var d = b * this.mpl + ((b * this.mph + (a[c] >> 15) * this.mpl & this.um) << 15) & a.DM;b = c + this.m.t;a[b] += this.m.am(0, d, a, c, 0, this.m.t);while (a[b] >= a.DV) {\n      a[b] -= a.DV;a[++b]++;\n    }\n  }a.clamp();a.drShiftTo(this.m.t, a);if (a.compareTo(this.m) >= 0) {\n    a.subTo(this.m, a);\n  }\n}function montSqrTo(a, b) {\n  a.squareTo(b);this.reduce(b);\n}function montMulTo(a, c, b) {\n  a.multiplyTo(c, b);this.reduce(b);\n}Montgomery.prototype.convert = montConvert;Montgomery.prototype.revert = montRevert;Montgomery.prototype.reduce = montReduce;Montgomery.prototype.mulTo = montMulTo;Montgomery.prototype.sqrTo = montSqrTo;function bnpIsEven() {\n  return (this.t > 0 ? this[0] & 1 : this.s) == 0;\n}function bnpExp(h, j) {\n  if (h > 4294967295 || h < 1) {\n    return BigInteger.ONE;\n  }var f = nbi(),\n      a = nbi(),\n      d = j.convert(this),\n      c = nbits(h) - 1;d.copyTo(f);while (--c >= 0) {\n    j.sqrTo(f, a);if ((h & 1 << c) > 0) {\n      j.mulTo(a, d, f);\n    } else {\n      var b = f;f = a;a = b;\n    }\n  }return j.revert(f);\n}function bnModPowInt(b, a) {\n  var c;if (b < 256 || a.isEven()) {\n    c = new Classic(a);\n  } else {\n    c = new Montgomery(a);\n  }return this.exp(b, c);\n}BigInteger.prototype.copyTo = bnpCopyTo;BigInteger.prototype.fromInt = bnpFromInt;BigInteger.prototype.fromString = bnpFromString;BigInteger.prototype.clamp = bnpClamp;BigInteger.prototype.dlShiftTo = bnpDLShiftTo;BigInteger.prototype.drShiftTo = bnpDRShiftTo;BigInteger.prototype.lShiftTo = bnpLShiftTo;BigInteger.prototype.rShiftTo = bnpRShiftTo;BigInteger.prototype.subTo = bnpSubTo;BigInteger.prototype.multiplyTo = bnpMultiplyTo;BigInteger.prototype.squareTo = bnpSquareTo;BigInteger.prototype.divRemTo = bnpDivRemTo;BigInteger.prototype.invDigit = bnpInvDigit;BigInteger.prototype.isEven = bnpIsEven;BigInteger.prototype.exp = bnpExp;BigInteger.prototype.toString = bnToString;BigInteger.prototype.negate = bnNegate;BigInteger.prototype.abs = bnAbs;BigInteger.prototype.compareTo = bnCompareTo;BigInteger.prototype.bitLength = bnBitLength;BigInteger.prototype.mod = bnMod;BigInteger.prototype.modPowInt = bnModPowInt;BigInteger.ZERO = nbv(0);BigInteger.ONE = nbv(1);\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction bnClone() {\n  var a = nbi();this.copyTo(a);return a;\n}function bnIntValue() {\n  if (this.s < 0) {\n    if (this.t == 1) {\n      return this[0] - this.DV;\n    } else {\n      if (this.t == 0) {\n        return -1;\n      }\n    }\n  } else {\n    if (this.t == 1) {\n      return this[0];\n    } else {\n      if (this.t == 0) {\n        return 0;\n      }\n    }\n  }return (this[1] & (1 << 32 - this.DB) - 1) << this.DB | this[0];\n}function bnByteValue() {\n  return this.t == 0 ? this.s : this[0] << 24 >> 24;\n}function bnShortValue() {\n  return this.t == 0 ? this.s : this[0] << 16 >> 16;\n}function bnpChunkSize(a) {\n  return Math.floor(Math.LN2 * this.DB / Math.log(a));\n}function bnSigNum() {\n  if (this.s < 0) {\n    return -1;\n  } else {\n    if (this.t <= 0 || this.t == 1 && this[0] <= 0) {\n      return 0;\n    } else {\n      return 1;\n    }\n  }\n}function bnpToRadix(c) {\n  if (c == null) {\n    c = 10;\n  }if (this.signum() == 0 || c < 2 || c > 36) {\n    return \"0\";\n  }var f = this.chunkSize(c);var e = Math.pow(c, f);var i = nbv(e),\n      j = nbi(),\n      h = nbi(),\n      g = \"\";this.divRemTo(i, j, h);while (j.signum() > 0) {\n    g = (e + h.intValue()).toString(c).substr(1) + g;j.divRemTo(i, j, h);\n  }return h.intValue().toString(c) + g;\n}function bnpFromRadix(m, h) {\n  this.fromInt(0);if (h == null) {\n    h = 10;\n  }var f = this.chunkSize(h);var g = Math.pow(h, f),\n      e = false,\n      a = 0,\n      l = 0;for (var c = 0; c < m.length; ++c) {\n    var k = intAt(m, c);if (k < 0) {\n      if (m.charAt(c) == \"-\" && this.signum() == 0) {\n        e = true;\n      }continue;\n    }l = h * l + k;if (++a >= f) {\n      this.dMultiply(g);this.dAddOffset(l, 0);a = 0;l = 0;\n    }\n  }if (a > 0) {\n    this.dMultiply(Math.pow(h, a));this.dAddOffset(l, 0);\n  }if (e) {\n    BigInteger.ZERO.subTo(this, this);\n  }\n}function bnpFromNumber(f, e, h) {\n  if (\"number\" == typeof e) {\n    if (f < 2) {\n      this.fromInt(1);\n    } else {\n      this.fromNumber(f, h);if (!this.testBit(f - 1)) {\n        this.bitwiseTo(BigInteger.ONE.shiftLeft(f - 1), op_or, this);\n      }if (this.isEven()) {\n        this.dAddOffset(1, 0);\n      }while (!this.isProbablePrime(e)) {\n        this.dAddOffset(2, 0);if (this.bitLength() > f) {\n          this.subTo(BigInteger.ONE.shiftLeft(f - 1), this);\n        }\n      }\n    }\n  } else {\n    var d = new Array(),\n        g = f & 7;d.length = (f >> 3) + 1;e.nextBytes(d);if (g > 0) {\n      d[0] &= (1 << g) - 1;\n    } else {\n      d[0] = 0;\n    }this.fromString(d, 256);\n  }\n}function bnToByteArray() {\n  var b = this.t,\n      c = new Array();c[0] = this.s;var e = this.DB - b * this.DB % 8,\n      f,\n      a = 0;if (b-- > 0) {\n    if (e < this.DB && (f = this[b] >> e) != (this.s & this.DM) >> e) {\n      c[a++] = f | this.s << this.DB - e;\n    }while (b >= 0) {\n      if (e < 8) {\n        f = (this[b] & (1 << e) - 1) << 8 - e;f |= this[--b] >> (e += this.DB - 8);\n      } else {\n        f = this[b] >> (e -= 8) & 255;if (e <= 0) {\n          e += this.DB;--b;\n        }\n      }if ((f & 128) != 0) {\n        f |= -256;\n      }if (a == 0 && (this.s & 128) != (f & 128)) {\n        ++a;\n      }if (a > 0 || f != this.s) {\n        c[a++] = f;\n      }\n    }\n  }return c;\n}function bnEquals(b) {\n  return this.compareTo(b) == 0;\n}function bnMin(b) {\n  return this.compareTo(b) < 0 ? this : b;\n}function bnMax(b) {\n  return this.compareTo(b) > 0 ? this : b;\n}function bnpBitwiseTo(c, h, e) {\n  var d,\n      g,\n      b = Math.min(c.t, this.t);for (d = 0; d < b; ++d) {\n    e[d] = h(this[d], c[d]);\n  }if (c.t < this.t) {\n    g = c.s & this.DM;for (d = b; d < this.t; ++d) {\n      e[d] = h(this[d], g);\n    }e.t = this.t;\n  } else {\n    g = this.s & this.DM;for (d = b; d < c.t; ++d) {\n      e[d] = h(g, c[d]);\n    }e.t = c.t;\n  }e.s = h(this.s, c.s);e.clamp();\n}function op_and(a, b) {\n  return a & b;\n}function bnAnd(b) {\n  var c = nbi();this.bitwiseTo(b, op_and, c);return c;\n}function op_or(a, b) {\n  return a | b;\n}function bnOr(b) {\n  var c = nbi();this.bitwiseTo(b, op_or, c);return c;\n}function op_xor(a, b) {\n  return a ^ b;\n}function bnXor(b) {\n  var c = nbi();this.bitwiseTo(b, op_xor, c);return c;\n}function op_andnot(a, b) {\n  return a & ~b;\n}function bnAndNot(b) {\n  var c = nbi();this.bitwiseTo(b, op_andnot, c);return c;\n}function bnNot() {\n  var b = nbi();for (var a = 0; a < this.t; ++a) {\n    b[a] = this.DM & ~this[a];\n  }b.t = this.t;b.s = ~this.s;return b;\n}function bnShiftLeft(b) {\n  var a = nbi();if (b < 0) {\n    this.rShiftTo(-b, a);\n  } else {\n    this.lShiftTo(b, a);\n  }return a;\n}function bnShiftRight(b) {\n  var a = nbi();if (b < 0) {\n    this.lShiftTo(-b, a);\n  } else {\n    this.rShiftTo(b, a);\n  }return a;\n}function lbit(a) {\n  if (a == 0) {\n    return -1;\n  }var b = 0;if ((a & 65535) == 0) {\n    a >>= 16;b += 16;\n  }if ((a & 255) == 0) {\n    a >>= 8;b += 8;\n  }if ((a & 15) == 0) {\n    a >>= 4;b += 4;\n  }if ((a & 3) == 0) {\n    a >>= 2;b += 2;\n  }if ((a & 1) == 0) {\n    ++b;\n  }return b;\n}function bnGetLowestSetBit() {\n  for (var a = 0; a < this.t; ++a) {\n    if (this[a] != 0) {\n      return a * this.DB + lbit(this[a]);\n    }\n  }if (this.s < 0) {\n    return this.t * this.DB;\n  }return -1;\n}function cbit(a) {\n  var b = 0;while (a != 0) {\n    a &= a - 1;++b;\n  }return b;\n}function bnBitCount() {\n  var c = 0,\n      a = this.s & this.DM;for (var b = 0; b < this.t; ++b) {\n    c += cbit(this[b] ^ a);\n  }return c;\n}function bnTestBit(b) {\n  var a = Math.floor(b / this.DB);if (a >= this.t) {\n    return this.s != 0;\n  }return (this[a] & 1 << b % this.DB) != 0;\n}function bnpChangeBit(c, b) {\n  var a = BigInteger.ONE.shiftLeft(c);this.bitwiseTo(a, b, a);return a;\n}function bnSetBit(a) {\n  return this.changeBit(a, op_or);\n}function bnClearBit(a) {\n  return this.changeBit(a, op_andnot);\n}function bnFlipBit(a) {\n  return this.changeBit(a, op_xor);\n}function bnpAddTo(d, f) {\n  var e = 0,\n      g = 0,\n      b = Math.min(d.t, this.t);while (e < b) {\n    g += this[e] + d[e];f[e++] = g & this.DM;g >>= this.DB;\n  }if (d.t < this.t) {\n    g += d.s;while (e < this.t) {\n      g += this[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g += this.s;\n  } else {\n    g += this.s;while (e < d.t) {\n      g += d[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g += d.s;\n  }f.s = g < 0 ? -1 : 0;if (g > 0) {\n    f[e++] = g;\n  } else {\n    if (g < -1) {\n      f[e++] = this.DV + g;\n    }\n  }f.t = e;f.clamp();\n}function bnAdd(b) {\n  var c = nbi();this.addTo(b, c);return c;\n}function bnSubtract(b) {\n  var c = nbi();this.subTo(b, c);return c;\n}function bnMultiply(b) {\n  var c = nbi();this.multiplyTo(b, c);return c;\n}function bnSquare() {\n  var a = nbi();this.squareTo(a);return a;\n}function bnDivide(b) {\n  var c = nbi();this.divRemTo(b, c, null);return c;\n}function bnRemainder(b) {\n  var c = nbi();this.divRemTo(b, null, c);return c;\n}function bnDivideAndRemainder(b) {\n  var d = nbi(),\n      c = nbi();this.divRemTo(b, d, c);return new Array(d, c);\n}function bnpDMultiply(a) {\n  this[this.t] = this.am(0, a - 1, this, 0, 0, this.t);++this.t;this.clamp();\n}function bnpDAddOffset(b, a) {\n  if (b == 0) {\n    return;\n  }while (this.t <= a) {\n    this[this.t++] = 0;\n  }this[a] += b;while (this[a] >= this.DV) {\n    this[a] -= this.DV;if (++a >= this.t) {\n      this[this.t++] = 0;\n    }++this[a];\n  }\n}function NullExp() {}function nNop(a) {\n  return a;\n}function nMulTo(a, c, b) {\n  a.multiplyTo(c, b);\n}function nSqrTo(a, b) {\n  a.squareTo(b);\n}NullExp.prototype.convert = nNop;NullExp.prototype.revert = nNop;NullExp.prototype.mulTo = nMulTo;NullExp.prototype.sqrTo = nSqrTo;function bnPow(a) {\n  return this.exp(a, new NullExp());\n}function bnpMultiplyLowerTo(b, f, e) {\n  var d = Math.min(this.t + b.t, f);e.s = 0;e.t = d;while (d > 0) {\n    e[--d] = 0;\n  }var c;for (c = e.t - this.t; d < c; ++d) {\n    e[d + this.t] = this.am(0, b[d], e, d, 0, this.t);\n  }for (c = Math.min(b.t, f); d < c; ++d) {\n    this.am(0, b[d], e, d, 0, f - d);\n  }e.clamp();\n}function bnpMultiplyUpperTo(b, e, d) {\n  --e;var c = d.t = this.t + b.t - e;d.s = 0;while (--c >= 0) {\n    d[c] = 0;\n  }for (c = Math.max(e - this.t, 0); c < b.t; ++c) {\n    d[this.t + c - e] = this.am(e - c, b[c], d, 0, 0, this.t + c - e);\n  }d.clamp();d.drShiftTo(1, d);\n}function Barrett(a) {\n  this.r2 = nbi();this.q3 = nbi();BigInteger.ONE.dlShiftTo(2 * a.t, this.r2);this.mu = this.r2.divide(a);this.m = a;\n}function barrettConvert(a) {\n  if (a.s < 0 || a.t > 2 * this.m.t) {\n    return a.mod(this.m);\n  } else {\n    if (a.compareTo(this.m) < 0) {\n      return a;\n    } else {\n      var b = nbi();a.copyTo(b);this.reduce(b);return b;\n    }\n  }\n}function barrettRevert(a) {\n  return a;\n}function barrettReduce(a) {\n  a.drShiftTo(this.m.t - 1, this.r2);if (a.t > this.m.t + 1) {\n    a.t = this.m.t + 1;a.clamp();\n  }this.mu.multiplyUpperTo(this.r2, this.m.t + 1, this.q3);this.m.multiplyLowerTo(this.q3, this.m.t + 1, this.r2);while (a.compareTo(this.r2) < 0) {\n    a.dAddOffset(1, this.m.t + 1);\n  }a.subTo(this.r2, a);while (a.compareTo(this.m) >= 0) {\n    a.subTo(this.m, a);\n  }\n}function barrettSqrTo(a, b) {\n  a.squareTo(b);this.reduce(b);\n}function barrettMulTo(a, c, b) {\n  a.multiplyTo(c, b);this.reduce(b);\n}Barrett.prototype.convert = barrettConvert;Barrett.prototype.revert = barrettRevert;Barrett.prototype.reduce = barrettReduce;Barrett.prototype.mulTo = barrettMulTo;Barrett.prototype.sqrTo = barrettSqrTo;function bnModPow(q, f) {\n  var o = q.bitLength(),\n      h,\n      b = nbv(1),\n      v;if (o <= 0) {\n    return b;\n  } else {\n    if (o < 18) {\n      h = 1;\n    } else {\n      if (o < 48) {\n        h = 3;\n      } else {\n        if (o < 144) {\n          h = 4;\n        } else {\n          if (o < 768) {\n            h = 5;\n          } else {\n            h = 6;\n          }\n        }\n      }\n    }\n  }if (o < 8) {\n    v = new Classic(f);\n  } else {\n    if (f.isEven()) {\n      v = new Barrett(f);\n    } else {\n      v = new Montgomery(f);\n    }\n  }var p = new Array(),\n      d = 3,\n      s = h - 1,\n      a = (1 << h) - 1;p[1] = v.convert(this);if (h > 1) {\n    var A = nbi();v.sqrTo(p[1], A);while (d <= a) {\n      p[d] = nbi();v.mulTo(A, p[d - 2], p[d]);d += 2;\n    }\n  }var l = q.t - 1,\n      x,\n      u = true,\n      c = nbi(),\n      y;o = nbits(q[l]) - 1;while (l >= 0) {\n    if (o >= s) {\n      x = q[l] >> o - s & a;\n    } else {\n      x = (q[l] & (1 << o + 1) - 1) << s - o;if (l > 0) {\n        x |= q[l - 1] >> this.DB + o - s;\n      }\n    }d = h;while ((x & 1) == 0) {\n      x >>= 1;--d;\n    }if ((o -= d) < 0) {\n      o += this.DB;--l;\n    }if (u) {\n      p[x].copyTo(b);u = false;\n    } else {\n      while (d > 1) {\n        v.sqrTo(b, c);v.sqrTo(c, b);d -= 2;\n      }if (d > 0) {\n        v.sqrTo(b, c);\n      } else {\n        y = b;b = c;c = y;\n      }v.mulTo(c, p[x], b);\n    }while (l >= 0 && (q[l] & 1 << o) == 0) {\n      v.sqrTo(b, c);y = b;b = c;c = y;if (--o < 0) {\n        o = this.DB - 1;--l;\n      }\n    }\n  }return v.revert(b);\n}function bnGCD(c) {\n  var b = this.s < 0 ? this.negate() : this.clone();var h = c.s < 0 ? c.negate() : c.clone();if (b.compareTo(h) < 0) {\n    var e = b;b = h;h = e;\n  }var d = b.getLowestSetBit(),\n      f = h.getLowestSetBit();if (f < 0) {\n    return b;\n  }if (d < f) {\n    f = d;\n  }if (f > 0) {\n    b.rShiftTo(f, b);h.rShiftTo(f, h);\n  }while (b.signum() > 0) {\n    if ((d = b.getLowestSetBit()) > 0) {\n      b.rShiftTo(d, b);\n    }if ((d = h.getLowestSetBit()) > 0) {\n      h.rShiftTo(d, h);\n    }if (b.compareTo(h) >= 0) {\n      b.subTo(h, b);b.rShiftTo(1, b);\n    } else {\n      h.subTo(b, h);h.rShiftTo(1, h);\n    }\n  }if (f > 0) {\n    h.lShiftTo(f, h);\n  }return h;\n}function bnpModInt(e) {\n  if (e <= 0) {\n    return 0;\n  }var c = this.DV % e,\n      b = this.s < 0 ? e - 1 : 0;if (this.t > 0) {\n    if (c == 0) {\n      b = this[0] % e;\n    } else {\n      for (var a = this.t - 1; a >= 0; --a) {\n        b = (c * b + this[a]) % e;\n      }\n    }\n  }return b;\n}function bnModInverse(f) {\n  var j = f.isEven();if (this.isEven() && j || f.signum() == 0) {\n    return BigInteger.ZERO;\n  }var i = f.clone(),\n      h = this.clone();var g = nbv(1),\n      e = nbv(0),\n      l = nbv(0),\n      k = nbv(1);while (i.signum() != 0) {\n    while (i.isEven()) {\n      i.rShiftTo(1, i);if (j) {\n        if (!g.isEven() || !e.isEven()) {\n          g.addTo(this, g);e.subTo(f, e);\n        }g.rShiftTo(1, g);\n      } else {\n        if (!e.isEven()) {\n          e.subTo(f, e);\n        }\n      }e.rShiftTo(1, e);\n    }while (h.isEven()) {\n      h.rShiftTo(1, h);if (j) {\n        if (!l.isEven() || !k.isEven()) {\n          l.addTo(this, l);k.subTo(f, k);\n        }l.rShiftTo(1, l);\n      } else {\n        if (!k.isEven()) {\n          k.subTo(f, k);\n        }\n      }k.rShiftTo(1, k);\n    }if (i.compareTo(h) >= 0) {\n      i.subTo(h, i);if (j) {\n        g.subTo(l, g);\n      }e.subTo(k, e);\n    } else {\n      h.subTo(i, h);if (j) {\n        l.subTo(g, l);\n      }k.subTo(e, k);\n    }\n  }if (h.compareTo(BigInteger.ONE) != 0) {\n    return BigInteger.ZERO;\n  }if (k.compareTo(f) >= 0) {\n    return k.subtract(f);\n  }if (k.signum() < 0) {\n    k.addTo(f, k);\n  } else {\n    return k;\n  }if (k.signum() < 0) {\n    return k.add(f);\n  } else {\n    return k;\n  }\n}var lowprimes = [2, 3, 5, 7, 11, 13, 17, 19, 23, 29, 31, 37, 41, 43, 47, 53, 59, 61, 67, 71, 73, 79, 83, 89, 97, 101, 103, 107, 109, 113, 127, 131, 137, 139, 149, 151, 157, 163, 167, 173, 179, 181, 191, 193, 197, 199, 211, 223, 227, 229, 233, 239, 241, 251, 257, 263, 269, 271, 277, 281, 283, 293, 307, 311, 313, 317, 331, 337, 347, 349, 353, 359, 367, 373, 379, 383, 389, 397, 401, 409, 419, 421, 431, 433, 439, 443, 449, 457, 461, 463, 467, 479, 487, 491, 499, 503, 509, 521, 523, 541, 547, 557, 563, 569, 571, 577, 587, 593, 599, 601, 607, 613, 617, 619, 631, 641, 643, 647, 653, 659, 661, 673, 677, 683, 691, 701, 709, 719, 727, 733, 739, 743, 751, 757, 761, 769, 773, 787, 797, 809, 811, 821, 823, 827, 829, 839, 853, 857, 859, 863, 877, 881, 883, 887, 907, 911, 919, 929, 937, 941, 947, 953, 967, 971, 977, 983, 991, 997];var lplim = (1 << 26) / lowprimes[lowprimes.length - 1];function bnIsProbablePrime(e) {\n  var d,\n      b = this.abs();if (b.t == 1 && b[0] <= lowprimes[lowprimes.length - 1]) {\n    for (d = 0; d < lowprimes.length; ++d) {\n      if (b[0] == lowprimes[d]) {\n        return true;\n      }\n    }return false;\n  }if (b.isEven()) {\n    return false;\n  }d = 1;while (d < lowprimes.length) {\n    var a = lowprimes[d],\n        c = d + 1;while (c < lowprimes.length && a < lplim) {\n      a *= lowprimes[c++];\n    }a = b.modInt(a);while (d < c) {\n      if (a % lowprimes[d++] == 0) {\n        return false;\n      }\n    }\n  }return b.millerRabin(e);\n}function bnpMillerRabin(f) {\n  var g = this.subtract(BigInteger.ONE);var c = g.getLowestSetBit();if (c <= 0) {\n    return false;\n  }var h = g.shiftRight(c);f = f + 1 >> 1;if (f > lowprimes.length) {\n    f = lowprimes.length;\n  }var b = nbi();for (var e = 0; e < f; ++e) {\n    b.fromInt(lowprimes[Math.floor(Math.random() * lowprimes.length)]);var l = b.modPow(h, this);if (l.compareTo(BigInteger.ONE) != 0 && l.compareTo(g) != 0) {\n      var d = 1;while (d++ < c && l.compareTo(g) != 0) {\n        l = l.modPowInt(2, this);if (l.compareTo(BigInteger.ONE) == 0) {\n          return false;\n        }\n      }if (l.compareTo(g) != 0) {\n        return false;\n      }\n    }\n  }return true;\n}BigInteger.prototype.chunkSize = bnpChunkSize;BigInteger.prototype.toRadix = bnpToRadix;BigInteger.prototype.fromRadix = bnpFromRadix;BigInteger.prototype.fromNumber = bnpFromNumber;BigInteger.prototype.bitwiseTo = bnpBitwiseTo;BigInteger.prototype.changeBit = bnpChangeBit;BigInteger.prototype.addTo = bnpAddTo;BigInteger.prototype.dMultiply = bnpDMultiply;BigInteger.prototype.dAddOffset = bnpDAddOffset;BigInteger.prototype.multiplyLowerTo = bnpMultiplyLowerTo;BigInteger.prototype.multiplyUpperTo = bnpMultiplyUpperTo;BigInteger.prototype.modInt = bnpModInt;BigInteger.prototype.millerRabin = bnpMillerRabin;BigInteger.prototype.clone = bnClone;BigInteger.prototype.intValue = bnIntValue;BigInteger.prototype.byteValue = bnByteValue;BigInteger.prototype.shortValue = bnShortValue;BigInteger.prototype.signum = bnSigNum;BigInteger.prototype.toByteArray = bnToByteArray;BigInteger.prototype.equals = bnEquals;BigInteger.prototype.min = bnMin;BigInteger.prototype.max = bnMax;BigInteger.prototype.and = bnAnd;BigInteger.prototype.or = bnOr;BigInteger.prototype.xor = bnXor;BigInteger.prototype.andNot = bnAndNot;BigInteger.prototype.not = bnNot;BigInteger.prototype.shiftLeft = bnShiftLeft;BigInteger.prototype.shiftRight = bnShiftRight;BigInteger.prototype.getLowestSetBit = bnGetLowestSetBit;BigInteger.prototype.bitCount = bnBitCount;BigInteger.prototype.testBit = bnTestBit;BigInteger.prototype.setBit = bnSetBit;BigInteger.prototype.clearBit = bnClearBit;BigInteger.prototype.flipBit = bnFlipBit;BigInteger.prototype.add = bnAdd;BigInteger.prototype.subtract = bnSubtract;BigInteger.prototype.multiply = bnMultiply;BigInteger.prototype.divide = bnDivide;BigInteger.prototype.remainder = bnRemainder;BigInteger.prototype.divideAndRemainder = bnDivideAndRemainder;BigInteger.prototype.modPow = bnModPow;BigInteger.prototype.modInverse = bnModInverse;BigInteger.prototype.pow = bnPow;BigInteger.prototype.gcd = bnGCD;BigInteger.prototype.isProbablePrime = bnIsProbablePrime;BigInteger.prototype.square = bnSquare;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction Arcfour() {\n  this.i = 0;this.j = 0;this.S = new Array();\n}function ARC4init(d) {\n  var c, a, b;for (c = 0; c < 256; ++c) {\n    this.S[c] = c;\n  }a = 0;for (c = 0; c < 256; ++c) {\n    a = a + this.S[c] + d[c % d.length] & 255;b = this.S[c];this.S[c] = this.S[a];this.S[a] = b;\n  }this.i = 0;this.j = 0;\n}function ARC4next() {\n  var a;this.i = this.i + 1 & 255;this.j = this.j + this.S[this.i] & 255;a = this.S[this.i];this.S[this.i] = this.S[this.j];this.S[this.j] = a;return this.S[a + this.S[this.i] & 255];\n}Arcfour.prototype.init = ARC4init;Arcfour.prototype.next = ARC4next;function prng_newstate() {\n  return new Arcfour();\n}var rng_psize = 256;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nvar rng_state;var rng_pool;var rng_pptr;function rng_seed_int(a) {\n  rng_pool[rng_pptr++] ^= a & 255;rng_pool[rng_pptr++] ^= a >> 8 & 255;rng_pool[rng_pptr++] ^= a >> 16 & 255;rng_pool[rng_pptr++] ^= a >> 24 & 255;if (rng_pptr >= rng_psize) {\n    rng_pptr -= rng_psize;\n  }\n}function rng_seed_time() {\n  rng_seed_int(new Date().getTime());\n}if (rng_pool == null) {\n  rng_pool = new Array();rng_pptr = 0;var t;if (window !== undefined && (window.crypto !== undefined || window.msCrypto !== undefined)) {\n    var crypto = window.crypto || window.msCrypto;if (crypto.getRandomValues) {\n      var ua = new Uint8Array(32);crypto.getRandomValues(ua);for (t = 0; t < 32; ++t) {\n        rng_pool[rng_pptr++] = ua[t];\n      }\n    } else {\n      if (navigator.appName == \"Netscape\" && navigator.appVersion < \"5\") {\n        var z = window.crypto.random(32);for (t = 0; t < z.length; ++t) {\n          rng_pool[rng_pptr++] = z.charCodeAt(t) & 255;\n        }\n      }\n    }\n  }while (rng_pptr < rng_psize) {\n    t = Math.floor(65536 * Math.random());rng_pool[rng_pptr++] = t >>> 8;rng_pool[rng_pptr++] = t & 255;\n  }rng_pptr = 0;rng_seed_time();\n}function rng_get_byte() {\n  if (rng_state == null) {\n    rng_seed_time();rng_state = prng_newstate();rng_state.init(rng_pool);for (rng_pptr = 0; rng_pptr < rng_pool.length; ++rng_pptr) {\n      rng_pool[rng_pptr] = 0;\n    }rng_pptr = 0;\n  }return rng_state.next();\n}function rng_get_bytes(b) {\n  var a;for (a = 0; a < b.length; ++a) {\n    b[a] = rng_get_byte();\n  }\n}function SecureRandom() {}SecureRandom.prototype.nextBytes = rng_get_bytes;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction parseBigInt(b, a) {\n  return new BigInteger(b, a);\n}function linebrk(c, d) {\n  var a = \"\";var b = 0;while (b + d < c.length) {\n    a += c.substring(b, b + d) + \"\\n\";b += d;\n  }return a + c.substring(b, c.length);\n}function byte2Hex(a) {\n  if (a < 16) {\n    return \"0\" + a.toString(16);\n  } else {\n    return a.toString(16);\n  }\n}function pkcs1pad2(e, h) {\n  if (h < e.length + 11) {\n    throw \"Message too long for RSA\";return null;\n  }var g = new Array();var d = e.length - 1;while (d >= 0 && h > 0) {\n    var f = e.charCodeAt(d--);if (f < 128) {\n      g[--h] = f;\n    } else {\n      if (f > 127 && f < 2048) {\n        g[--h] = f & 63 | 128;g[--h] = f >> 6 | 192;\n      } else {\n        g[--h] = f & 63 | 128;g[--h] = f >> 6 & 63 | 128;g[--h] = f >> 12 | 224;\n      }\n    }\n  }g[--h] = 0;var b = new SecureRandom();var a = new Array();while (h > 2) {\n    a[0] = 0;while (a[0] == 0) {\n      b.nextBytes(a);\n    }g[--h] = a[0];\n  }g[--h] = 2;g[--h] = 0;return new BigInteger(g);\n}function oaep_mgf1_arr(c, a, e) {\n  var b = \"\",\n      d = 0;while (b.length < a) {\n    b += e(String.fromCharCode.apply(String, c.concat([(d & 4278190080) >> 24, (d & 16711680) >> 16, (d & 65280) >> 8, d & 255])));d += 1;\n  }return b;\n}function oaep_pad(q, a, f, l) {\n  var c = KJUR.crypto.MessageDigest;var o = KJUR.crypto.Util;var b = null;if (!f) {\n    f = \"sha1\";\n  }if (typeof f === \"string\") {\n    b = c.getCanonicalAlgName(f);l = c.getHashLength(b);f = function f(i) {\n      return hextorstr(o.hashHex(rstrtohex(i), b));\n    };\n  }if (q.length + 2 * l + 2 > a) {\n    throw \"Message too long for RSA\";\n  }var k = \"\",\n      e;for (e = 0; e < a - q.length - 2 * l - 2; e += 1) {\n    k += \"\\x00\";\n  }var h = f(\"\") + k + \"\\x01\" + q;var g = new Array(l);new SecureRandom().nextBytes(g);var j = oaep_mgf1_arr(g, h.length, f);var p = [];for (e = 0; e < h.length; e += 1) {\n    p[e] = h.charCodeAt(e) ^ j.charCodeAt(e);\n  }var m = oaep_mgf1_arr(p, g.length, f);var d = [0];for (e = 0; e < g.length; e += 1) {\n    d[e + 1] = g[e] ^ m.charCodeAt(e);\n  }return new BigInteger(d.concat(p));\n}function RSAKey() {\n  this.n = null;this.e = 0;this.d = null;this.p = null;this.q = null;this.dmp1 = null;this.dmq1 = null;this.coeff = null;\n}function RSASetPublic(b, a) {\n  this.isPublic = true;this.isPrivate = false;if (typeof b !== \"string\") {\n    this.n = b;this.e = a;\n  } else {\n    if (b != null && a != null && b.length > 0 && a.length > 0) {\n      this.n = parseBigInt(b, 16);this.e = parseInt(a, 16);\n    } else {\n      throw \"Invalid RSA public key\";\n    }\n  }\n}function RSADoPublic(a) {\n  return a.modPowInt(this.e, this.n);\n}function RSAEncrypt(d) {\n  var a = pkcs1pad2(d, this.n.bitLength() + 7 >> 3);if (a == null) {\n    return null;\n  }var e = this.doPublic(a);if (e == null) {\n    return null;\n  }var b = e.toString(16);if ((b.length & 1) == 0) {\n    return b;\n  } else {\n    return \"0\" + b;\n  }\n}function RSAEncryptOAEP(f, e, b) {\n  var a = oaep_pad(f, this.n.bitLength() + 7 >> 3, e, b);if (a == null) {\n    return null;\n  }var g = this.doPublic(a);if (g == null) {\n    return null;\n  }var d = g.toString(16);if ((d.length & 1) == 0) {\n    return d;\n  } else {\n    return \"0\" + d;\n  }\n}RSAKey.prototype.doPublic = RSADoPublic;RSAKey.prototype.setPublic = RSASetPublic;RSAKey.prototype.encrypt = RSAEncrypt;RSAKey.prototype.encryptOAEP = RSAEncryptOAEP;RSAKey.prototype.type = \"RSA\";\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction ECFieldElementFp(b, a) {\n  this.x = a;this.q = b;\n}function feFpEquals(a) {\n  if (a == this) {\n    return true;\n  }return this.q.equals(a.q) && this.x.equals(a.x);\n}function feFpToBigInteger() {\n  return this.x;\n}function feFpNegate() {\n  return new ECFieldElementFp(this.q, this.x.negate().mod(this.q));\n}function feFpAdd(a) {\n  return new ECFieldElementFp(this.q, this.x.add(a.toBigInteger()).mod(this.q));\n}function feFpSubtract(a) {\n  return new ECFieldElementFp(this.q, this.x.subtract(a.toBigInteger()).mod(this.q));\n}function feFpMultiply(a) {\n  return new ECFieldElementFp(this.q, this.x.multiply(a.toBigInteger()).mod(this.q));\n}function feFpSquare() {\n  return new ECFieldElementFp(this.q, this.x.square().mod(this.q));\n}function feFpDivide(a) {\n  return new ECFieldElementFp(this.q, this.x.multiply(a.toBigInteger().modInverse(this.q)).mod(this.q));\n}ECFieldElementFp.prototype.equals = feFpEquals;ECFieldElementFp.prototype.toBigInteger = feFpToBigInteger;ECFieldElementFp.prototype.negate = feFpNegate;ECFieldElementFp.prototype.add = feFpAdd;ECFieldElementFp.prototype.subtract = feFpSubtract;ECFieldElementFp.prototype.multiply = feFpMultiply;ECFieldElementFp.prototype.square = feFpSquare;ECFieldElementFp.prototype.divide = feFpDivide;function ECPointFp(c, a, d, b) {\n  this.curve = c;this.x = a;this.y = d;if (b == null) {\n    this.z = BigInteger.ONE;\n  } else {\n    this.z = b;\n  }this.zinv = null;\n}function pointFpGetX() {\n  if (this.zinv == null) {\n    this.zinv = this.z.modInverse(this.curve.q);\n  }return this.curve.fromBigInteger(this.x.toBigInteger().multiply(this.zinv).mod(this.curve.q));\n}function pointFpGetY() {\n  if (this.zinv == null) {\n    this.zinv = this.z.modInverse(this.curve.q);\n  }return this.curve.fromBigInteger(this.y.toBigInteger().multiply(this.zinv).mod(this.curve.q));\n}function pointFpEquals(a) {\n  if (a == this) {\n    return true;\n  }if (this.isInfinity()) {\n    return a.isInfinity();\n  }if (a.isInfinity()) {\n    return this.isInfinity();\n  }var c, b;c = a.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(a.z)).mod(this.curve.q);if (!c.equals(BigInteger.ZERO)) {\n    return false;\n  }b = a.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(a.z)).mod(this.curve.q);return b.equals(BigInteger.ZERO);\n}function pointFpIsInfinity() {\n  if (this.x == null && this.y == null) {\n    return true;\n  }return this.z.equals(BigInteger.ZERO) && !this.y.toBigInteger().equals(BigInteger.ZERO);\n}function pointFpNegate() {\n  return new ECPointFp(this.curve, this.x, this.y.negate(), this.z);\n}function pointFpAdd(l) {\n  if (this.isInfinity()) {\n    return l;\n  }if (l.isInfinity()) {\n    return this;\n  }var p = l.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(l.z)).mod(this.curve.q);var o = l.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(l.z)).mod(this.curve.q);if (BigInteger.ZERO.equals(o)) {\n    if (BigInteger.ZERO.equals(p)) {\n      return this.twice();\n    }return this.curve.getInfinity();\n  }var j = new BigInteger(\"3\");var e = this.x.toBigInteger();var n = this.y.toBigInteger();var c = l.x.toBigInteger();var k = l.y.toBigInteger();var m = o.square();var i = m.multiply(o);var d = e.multiply(m);var g = p.square().multiply(this.z);var a = g.subtract(d.shiftLeft(1)).multiply(l.z).subtract(i).multiply(o).mod(this.curve.q);var h = d.multiply(j).multiply(p).subtract(n.multiply(i)).subtract(g.multiply(p)).multiply(l.z).add(p.multiply(i)).mod(this.curve.q);var f = i.multiply(this.z).multiply(l.z).mod(this.curve.q);return new ECPointFp(this.curve, this.curve.fromBigInteger(a), this.curve.fromBigInteger(h), f);\n}function pointFpTwice() {\n  if (this.isInfinity()) {\n    return this;\n  }if (this.y.toBigInteger().signum() == 0) {\n    return this.curve.getInfinity();\n  }var g = new BigInteger(\"3\");var c = this.x.toBigInteger();var h = this.y.toBigInteger();var e = h.multiply(this.z);var j = e.multiply(h).mod(this.curve.q);var i = this.curve.a.toBigInteger();var k = c.square().multiply(g);if (!BigInteger.ZERO.equals(i)) {\n    k = k.add(this.z.square().multiply(i));\n  }k = k.mod(this.curve.q);var b = k.square().subtract(c.shiftLeft(3).multiply(j)).shiftLeft(1).multiply(e).mod(this.curve.q);var f = k.multiply(g).multiply(c).subtract(j.shiftLeft(1)).shiftLeft(2).multiply(j).subtract(k.square().multiply(k)).mod(this.curve.q);var d = e.square().multiply(e).shiftLeft(3).mod(this.curve.q);return new ECPointFp(this.curve, this.curve.fromBigInteger(b), this.curve.fromBigInteger(f), d);\n}function pointFpMultiply(b) {\n  if (this.isInfinity()) {\n    return this;\n  }if (b.signum() == 0) {\n    return this.curve.getInfinity();\n  }var g = b;var f = g.multiply(new BigInteger(\"3\"));var l = this.negate();var d = this;var c;for (c = f.bitLength() - 2; c > 0; --c) {\n    d = d.twice();var a = f.testBit(c);var j = g.testBit(c);if (a != j) {\n      d = d.add(a ? this : l);\n    }\n  }return d;\n}function pointFpMultiplyTwo(c, a, b) {\n  var d;if (c.bitLength() > b.bitLength()) {\n    d = c.bitLength() - 1;\n  } else {\n    d = b.bitLength() - 1;\n  }var f = this.curve.getInfinity();var e = this.add(a);while (d >= 0) {\n    f = f.twice();if (c.testBit(d)) {\n      if (b.testBit(d)) {\n        f = f.add(e);\n      } else {\n        f = f.add(this);\n      }\n    } else {\n      if (b.testBit(d)) {\n        f = f.add(a);\n      }\n    }--d;\n  }return f;\n}ECPointFp.prototype.getX = pointFpGetX;ECPointFp.prototype.getY = pointFpGetY;ECPointFp.prototype.equals = pointFpEquals;ECPointFp.prototype.isInfinity = pointFpIsInfinity;ECPointFp.prototype.negate = pointFpNegate;ECPointFp.prototype.add = pointFpAdd;ECPointFp.prototype.twice = pointFpTwice;ECPointFp.prototype.multiply = pointFpMultiply;ECPointFp.prototype.multiplyTwo = pointFpMultiplyTwo;function ECCurveFp(e, d, c) {\n  this.q = e;this.a = this.fromBigInteger(d);this.b = this.fromBigInteger(c);this.infinity = new ECPointFp(this, null, null);\n}function curveFpGetQ() {\n  return this.q;\n}function curveFpGetA() {\n  return this.a;\n}function curveFpGetB() {\n  return this.b;\n}function curveFpEquals(a) {\n  if (a == this) {\n    return true;\n  }return this.q.equals(a.q) && this.a.equals(a.a) && this.b.equals(a.b);\n}function curveFpGetInfinity() {\n  return this.infinity;\n}function curveFpFromBigInteger(a) {\n  return new ECFieldElementFp(this.q, a);\n}function curveFpDecodePointHex(d) {\n  switch (parseInt(d.substr(0, 2), 16)) {case 0:\n      return this.infinity;case 2:case 3:\n      return null;case 4:case 6:case 7:\n      var a = (d.length - 2) / 2;var c = d.substr(2, a);var b = d.substr(a + 2, a);return new ECPointFp(this, this.fromBigInteger(new BigInteger(c, 16)), this.fromBigInteger(new BigInteger(b, 16)));default:\n      return null;}\n}ECCurveFp.prototype.getQ = curveFpGetQ;ECCurveFp.prototype.getA = curveFpGetA;ECCurveFp.prototype.getB = curveFpGetB;ECCurveFp.prototype.equals = curveFpEquals;ECCurveFp.prototype.getInfinity = curveFpGetInfinity;ECCurveFp.prototype.fromBigInteger = curveFpFromBigInteger;ECCurveFp.prototype.decodePointHex = curveFpDecodePointHex;\n/*! (c) Stefan Thomas | https://github.com/bitcoinjs/bitcoinjs-lib\n */\nECFieldElementFp.prototype.getByteLength = function () {\n  return Math.floor((this.toBigInteger().bitLength() + 7) / 8);\n};ECPointFp.prototype.getEncoded = function (c) {\n  var d = function d(h, f) {\n    var g = h.toByteArrayUnsigned();if (f < g.length) {\n      g = g.slice(g.length - f);\n    } else {\n      while (f > g.length) {\n        g.unshift(0);\n      }\n    }return g;\n  };var a = this.getX().toBigInteger();var e = this.getY().toBigInteger();var b = d(a, 32);if (c) {\n    if (e.isEven()) {\n      b.unshift(2);\n    } else {\n      b.unshift(3);\n    }\n  } else {\n    b.unshift(4);b = b.concat(d(e, 32));\n  }return b;\n};ECPointFp.decodeFrom = function (g, c) {\n  var f = c[0];var e = c.length - 1;var d = c.slice(1, 1 + e / 2);var b = c.slice(1 + e / 2, 1 + e);d.unshift(0);b.unshift(0);var a = new BigInteger(d);var h = new BigInteger(b);return new ECPointFp(g, g.fromBigInteger(a), g.fromBigInteger(h));\n};ECPointFp.decodeFromHex = function (g, c) {\n  var f = c.substr(0, 2);var e = c.length - 2;var d = c.substr(2, e / 2);var b = c.substr(2 + e / 2, e / 2);var a = new BigInteger(d, 16);var h = new BigInteger(b, 16);return new ECPointFp(g, g.fromBigInteger(a), g.fromBigInteger(h));\n};ECPointFp.prototype.add2D = function (c) {\n  if (this.isInfinity()) {\n    return c;\n  }if (c.isInfinity()) {\n    return this;\n  }if (this.x.equals(c.x)) {\n    if (this.y.equals(c.y)) {\n      return this.twice();\n    }return this.curve.getInfinity();\n  }var g = c.x.subtract(this.x);var e = c.y.subtract(this.y);var a = e.divide(g);var d = a.square().subtract(this.x).subtract(c.x);var f = a.multiply(this.x.subtract(d)).subtract(this.y);return new ECPointFp(this.curve, d, f);\n};ECPointFp.prototype.twice2D = function () {\n  if (this.isInfinity()) {\n    return this;\n  }if (this.y.toBigInteger().signum() == 0) {\n    return this.curve.getInfinity();\n  }var b = this.curve.fromBigInteger(BigInteger.valueOf(2));var e = this.curve.fromBigInteger(BigInteger.valueOf(3));var a = this.x.square().multiply(e).add(this.curve.a).divide(this.y.multiply(b));var c = a.square().subtract(this.x.multiply(b));var d = a.multiply(this.x.subtract(c)).subtract(this.y);return new ECPointFp(this.curve, c, d);\n};ECPointFp.prototype.multiply2D = function (b) {\n  if (this.isInfinity()) {\n    return this;\n  }if (b.signum() == 0) {\n    return this.curve.getInfinity();\n  }var g = b;var f = g.multiply(new BigInteger(\"3\"));var l = this.negate();var d = this;var c;for (c = f.bitLength() - 2; c > 0; --c) {\n    d = d.twice();var a = f.testBit(c);var j = g.testBit(c);if (a != j) {\n      d = d.add2D(a ? this : l);\n    }\n  }return d;\n};ECPointFp.prototype.isOnCurve = function () {\n  var d = this.getX().toBigInteger();var i = this.getY().toBigInteger();var f = this.curve.getA().toBigInteger();var c = this.curve.getB().toBigInteger();var h = this.curve.getQ();var e = i.multiply(i).mod(h);var g = d.multiply(d).multiply(d).add(f.multiply(d)).add(c).mod(h);return e.equals(g);\n};ECPointFp.prototype.toString = function () {\n  return \"(\" + this.getX().toBigInteger().toString() + \",\" + this.getY().toBigInteger().toString() + \")\";\n};ECPointFp.prototype.validate = function () {\n  var c = this.curve.getQ();if (this.isInfinity()) {\n    throw new Error(\"Point is at infinity.\");\n  }var a = this.getX().toBigInteger();var b = this.getY().toBigInteger();if (a.compareTo(BigInteger.ONE) < 0 || a.compareTo(c.subtract(BigInteger.ONE)) > 0) {\n    throw new Error(\"x coordinate out of bounds\");\n  }if (b.compareTo(BigInteger.ONE) < 0 || b.compareTo(c.subtract(BigInteger.ONE)) > 0) {\n    throw new Error(\"y coordinate out of bounds\");\n  }if (!this.isOnCurve()) {\n    throw new Error(\"Point is not on the curve.\");\n  }if (this.multiply(c).isInfinity()) {\n    throw new Error(\"Point is not a scalar multiple of G.\");\n  }return true;\n};\n/*! Mike Samuel (c) 2009 | code.google.com/p/json-sans-eval\n */\nvar jsonParse = function () {\n  var e = \"(?:-?\\\\b(?:0|[1-9][0-9]*)(?:\\\\.[0-9]+)?(?:[eE][+-]?[0-9]+)?\\\\b)\";var j = '(?:[^\\\\0-\\\\x08\\\\x0a-\\\\x1f\"\\\\\\\\]|\\\\\\\\(?:[\"/\\\\\\\\bfnrt]|u[0-9A-Fa-f]{4}))';var i = '(?:\"' + j + '*\")';var d = new RegExp(\"(?:false|true|null|[\\\\{\\\\}\\\\[\\\\]]|\" + e + \"|\" + i + \")\", \"g\");var k = new RegExp(\"\\\\\\\\(?:([^u])|u(.{4}))\", \"g\");var g = { '\"': '\"', \"/\": \"/\", \"\\\\\": \"\\\\\", b: \"\\b\", f: \"\\f\", n: \"\\n\", r: \"\\r\", t: \"\\t\" };function h(l, m, n) {\n    return m ? g[m] : String.fromCharCode(parseInt(n, 16));\n  }var c = new String(\"\");var a = \"\\\\\";var f = { \"{\": Object, \"[\": Array };var b = Object.hasOwnProperty;return function (u, q) {\n    var p = u.match(d);var x;var v = p[0];var l = false;if (\"{\" === v) {\n      x = {};\n    } else {\n      if (\"[\" === v) {\n        x = [];\n      } else {\n        x = [];l = true;\n      }\n    }var t;var r = [x];for (var o = 1 - l, m = p.length; o < m; ++o) {\n      v = p[o];var w;switch (v.charCodeAt(0)) {default:\n          w = r[0];w[t || w.length] = +v;t = void 0;break;case 34:\n          v = v.substring(1, v.length - 1);if (v.indexOf(a) !== -1) {\n            v = v.replace(k, h);\n          }w = r[0];if (!t) {\n            if (w instanceof Array) {\n              t = w.length;\n            } else {\n              t = v || c;break;\n            }\n          }w[t] = v;t = void 0;break;case 91:\n          w = r[0];r.unshift(w[t || w.length] = []);t = void 0;break;case 93:\n          r.shift();break;case 102:\n          w = r[0];w[t || w.length] = false;t = void 0;break;case 110:\n          w = r[0];w[t || w.length] = null;t = void 0;break;case 116:\n          w = r[0];w[t || w.length] = true;t = void 0;break;case 123:\n          w = r[0];r.unshift(w[t || w.length] = {});t = void 0;break;case 125:\n          r.shift();break;}\n    }if (l) {\n      if (r.length !== 1) {\n        throw new Error();\n      }x = x[0];\n    } else {\n      if (r.length) {\n        throw new Error();\n      }\n    }if (q) {\n      var s = function s(C, B) {\n        var D = C[B];if (D && (typeof D === \"undefined\" ? \"undefined\" : _typeof(D)) === \"object\") {\n          var n = null;for (var z in D) {\n            if (b.call(D, z) && D !== C) {\n              var y = s(D, z);if (y !== void 0) {\n                D[z] = y;\n              } else {\n                if (!n) {\n                  n = [];\n                }n.push(z);\n              }\n            }\n          }if (n) {\n            for (var A = n.length; --A >= 0;) {\n              delete D[n[A]];\n            }\n          }\n        }return q.call(C, B, D);\n      };x = s({ \"\": x }, \"\");\n    }return x;\n  };\n}();\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.asn1 == \"undefined\" || !KJUR.asn1) {\n  KJUR.asn1 = {};\n}KJUR.asn1.ASN1Util = new function () {\n  this.integerToByteHex = function (a) {\n    var b = a.toString(16);if (b.length % 2 == 1) {\n      b = \"0\" + b;\n    }return b;\n  };this.bigIntToMinTwosComplementsHex = function (j) {\n    var f = j.toString(16);if (f.substr(0, 1) != \"-\") {\n      if (f.length % 2 == 1) {\n        f = \"0\" + f;\n      } else {\n        if (!f.match(/^[0-7]/)) {\n          f = \"00\" + f;\n        }\n      }\n    } else {\n      var a = f.substr(1);var e = a.length;if (e % 2 == 1) {\n        e += 1;\n      } else {\n        if (!f.match(/^[0-7]/)) {\n          e += 2;\n        }\n      }var g = \"\";for (var d = 0; d < e; d++) {\n        g += \"f\";\n      }var c = new BigInteger(g, 16);var b = c.xor(j).add(BigInteger.ONE);f = b.toString(16).replace(/^-/, \"\");\n    }return f;\n  };this.getPEMStringFromHex = function (a, b) {\n    return hextopem(a, b);\n  };this.newObject = function (k) {\n    var D = KJUR,\n        n = D.asn1,\n        z = n.DERBoolean,\n        e = n.DERInteger,\n        s = n.DERBitString,\n        h = n.DEROctetString,\n        v = n.DERNull,\n        w = n.DERObjectIdentifier,\n        l = n.DEREnumerated,\n        g = n.DERUTF8String,\n        f = n.DERNumericString,\n        y = n.DERPrintableString,\n        u = n.DERTeletexString,\n        p = n.DERIA5String,\n        C = n.DERUTCTime,\n        j = n.DERGeneralizedTime,\n        m = n.DERSequence,\n        c = n.DERSet,\n        r = n.DERTaggedObject,\n        o = n.ASN1Util.newObject;var t = Object.keys(k);if (t.length != 1) {\n      throw \"key of param shall be only one.\";\n    }var F = t[0];if (\":bool:int:bitstr:octstr:null:oid:enum:utf8str:numstr:prnstr:telstr:ia5str:utctime:gentime:seq:set:tag:\".indexOf(\":\" + F + \":\") == -1) {\n      throw \"undefined key: \" + F;\n    }if (F == \"bool\") {\n      return new z(k[F]);\n    }if (F == \"int\") {\n      return new e(k[F]);\n    }if (F == \"bitstr\") {\n      return new s(k[F]);\n    }if (F == \"octstr\") {\n      return new h(k[F]);\n    }if (F == \"null\") {\n      return new v(k[F]);\n    }if (F == \"oid\") {\n      return new w(k[F]);\n    }if (F == \"enum\") {\n      return new l(k[F]);\n    }if (F == \"utf8str\") {\n      return new g(k[F]);\n    }if (F == \"numstr\") {\n      return new f(k[F]);\n    }if (F == \"prnstr\") {\n      return new y(k[F]);\n    }if (F == \"telstr\") {\n      return new u(k[F]);\n    }if (F == \"ia5str\") {\n      return new p(k[F]);\n    }if (F == \"utctime\") {\n      return new C(k[F]);\n    }if (F == \"gentime\") {\n      return new j(k[F]);\n    }if (F == \"seq\") {\n      var d = k[F];var E = [];for (var x = 0; x < d.length; x++) {\n        var B = o(d[x]);E.push(B);\n      }return new m({ array: E });\n    }if (F == \"set\") {\n      var d = k[F];var E = [];for (var x = 0; x < d.length; x++) {\n        var B = o(d[x]);E.push(B);\n      }return new c({ array: E });\n    }if (F == \"tag\") {\n      var A = k[F];if (Object.prototype.toString.call(A) === \"[object Array]\" && A.length == 3) {\n        var q = o(A[2]);return new r({ tag: A[0], explicit: A[1], obj: q });\n      } else {\n        var b = {};if (A.explicit !== undefined) {\n          b.explicit = A.explicit;\n        }if (A.tag !== undefined) {\n          b.tag = A.tag;\n        }if (A.obj === undefined) {\n          throw \"obj shall be specified for 'tag'.\";\n        }b.obj = o(A.obj);return new r(b);\n      }\n    }\n  };this.jsonToASN1HEX = function (b) {\n    var a = this.newObject(b);return a.getEncodedHex();\n  };\n}();KJUR.asn1.ASN1Util.oidHexToInt = function (a) {\n  var j = \"\";var k = parseInt(a.substr(0, 2), 16);var d = Math.floor(k / 40);var c = k % 40;var j = d + \".\" + c;var e = \"\";for (var f = 2; f < a.length; f += 2) {\n    var g = parseInt(a.substr(f, 2), 16);var h = (\"00000000\" + g.toString(2)).slice(-8);e = e + h.substr(1, 7);if (h.substr(0, 1) == \"0\") {\n      var b = new BigInteger(e, 2);j = j + \".\" + b.toString(10);e = \"\";\n    }\n  }return j;\n};KJUR.asn1.ASN1Util.oidIntToHex = function (f) {\n  var e = function e(a) {\n    var k = a.toString(16);if (k.length == 1) {\n      k = \"0\" + k;\n    }return k;\n  };var d = function d(o) {\n    var n = \"\";var k = new BigInteger(o, 10);var a = k.toString(2);var l = 7 - a.length % 7;if (l == 7) {\n      l = 0;\n    }var q = \"\";for (var m = 0; m < l; m++) {\n      q += \"0\";\n    }a = q + a;for (var m = 0; m < a.length - 1; m += 7) {\n      var p = a.substr(m, 7);if (m != a.length - 7) {\n        p = \"1\" + p;\n      }n += e(parseInt(p, 2));\n    }return n;\n  };if (!f.match(/^[0-9.]+$/)) {\n    throw \"malformed oid string: \" + f;\n  }var g = \"\";var b = f.split(\".\");var j = parseInt(b[0]) * 40 + parseInt(b[1]);g += e(j);b.splice(0, 2);for (var c = 0; c < b.length; c++) {\n    g += d(b[c]);\n  }return g;\n};KJUR.asn1.ASN1Object = function () {\n  var c = true;var b = null;var d = \"00\";var e = \"00\";var a = \"\";this.getLengthHexFromValue = function () {\n    if (typeof this.hV == \"undefined\" || this.hV == null) {\n      throw \"this.hV is null or undefined.\";\n    }if (this.hV.length % 2 == 1) {\n      throw \"value hex must be even length: n=\" + a.length + \",v=\" + this.hV;\n    }var i = this.hV.length / 2;var h = i.toString(16);if (h.length % 2 == 1) {\n      h = \"0\" + h;\n    }if (i < 128) {\n      return h;\n    } else {\n      var g = h.length / 2;if (g > 15) {\n        throw \"ASN.1 length too long to represent by 8x: n = \" + i.toString(16);\n      }var f = 128 + g;return f.toString(16) + h;\n    }\n  };this.getEncodedHex = function () {\n    if (this.hTLV == null || this.isModified) {\n      this.hV = this.getFreshValueHex();this.hL = this.getLengthHexFromValue();this.hTLV = this.hT + this.hL + this.hV;this.isModified = false;\n    }return this.hTLV;\n  };this.getValueHex = function () {\n    this.getEncodedHex();return this.hV;\n  };this.getFreshValueHex = function () {\n    return \"\";\n  };\n};KJUR.asn1.DERAbstractString = function (c) {\n  KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var b = null;var a = null;this.getString = function () {\n    return this.s;\n  };this.setString = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = d;this.hV = utf8tohex(this.s).toLowerCase();\n  };this.setStringHex = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = null;this.hV = d;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof c != \"undefined\") {\n    if (typeof c == \"string\") {\n      this.setString(c);\n    } else {\n      if (typeof c.str != \"undefined\") {\n        this.setString(c.str);\n      } else {\n        if (typeof c.hex != \"undefined\") {\n          this.setStringHex(c.hex);\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERAbstractString, KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractTime = function (c) {\n  KJUR.asn1.DERAbstractTime.superclass.constructor.call(this);var b = null;var a = null;this.localDateToUTC = function (f) {\n    utc = f.getTime() + f.getTimezoneOffset() * 60000;var e = new Date(utc);return e;\n  };this.formatDate = function (m, o, e) {\n    var g = this.zeroPadding;var n = this.localDateToUTC(m);var p = String(n.getFullYear());if (o == \"utc\") {\n      p = p.substr(2, 2);\n    }var l = g(String(n.getMonth() + 1), 2);var q = g(String(n.getDate()), 2);var h = g(String(n.getHours()), 2);var i = g(String(n.getMinutes()), 2);var j = g(String(n.getSeconds()), 2);var r = p + l + q + h + i + j;if (e === true) {\n      var f = n.getMilliseconds();if (f != 0) {\n        var k = g(String(f), 3);k = k.replace(/[0]+$/, \"\");r = r + \".\" + k;\n      }\n    }return r + \"Z\";\n  };this.zeroPadding = function (e, d) {\n    if (e.length >= d) {\n      return e;\n    }return new Array(d - e.length + 1).join(\"0\") + e;\n  };this.getString = function () {\n    return this.s;\n  };this.setString = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = d;this.hV = stohex(d);\n  };this.setByDateValue = function (h, j, e, d, f, g) {\n    var i = new Date(Date.UTC(h, j - 1, e, d, f, g, 0));this.setByDate(i);\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };\n};YAHOO.lang.extend(KJUR.asn1.DERAbstractTime, KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractStructured = function (b) {\n  KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var a = null;this.setByASN1ObjectArray = function (c) {\n    this.hTLV = null;this.isModified = true;this.asn1Array = c;\n  };this.appendASN1Object = function (c) {\n    this.hTLV = null;this.isModified = true;this.asn1Array.push(c);\n  };this.asn1Array = new Array();if (typeof b != \"undefined\") {\n    if (typeof b.array != \"undefined\") {\n      this.asn1Array = b.array;\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERAbstractStructured, KJUR.asn1.ASN1Object);KJUR.asn1.DERBoolean = function () {\n  KJUR.asn1.DERBoolean.superclass.constructor.call(this);this.hT = \"01\";this.hTLV = \"0101ff\";\n};YAHOO.lang.extend(KJUR.asn1.DERBoolean, KJUR.asn1.ASN1Object);KJUR.asn1.DERInteger = function (a) {\n  KJUR.asn1.DERInteger.superclass.constructor.call(this);this.hT = \"02\";this.setByBigInteger = function (b) {\n    this.hTLV = null;this.isModified = true;this.hV = KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b);\n  };this.setByInteger = function (c) {\n    var b = new BigInteger(String(c), 10);this.setByBigInteger(b);\n  };this.setValueHex = function (b) {\n    this.hV = b;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a.bigint != \"undefined\") {\n      this.setByBigInteger(a.bigint);\n    } else {\n      if (typeof a[\"int\"] != \"undefined\") {\n        this.setByInteger(a[\"int\"]);\n      } else {\n        if (typeof a == \"number\") {\n          this.setByInteger(a);\n        } else {\n          if (typeof a.hex != \"undefined\") {\n            this.setValueHex(a.hex);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERInteger, KJUR.asn1.ASN1Object);KJUR.asn1.DERBitString = function (b) {\n  if (b !== undefined && typeof b.obj !== \"undefined\") {\n    var a = KJUR.asn1.ASN1Util.newObject(b.obj);b.hex = \"00\" + a.getEncodedHex();\n  }KJUR.asn1.DERBitString.superclass.constructor.call(this);this.hT = \"03\";this.setHexValueIncludingUnusedBits = function (c) {\n    this.hTLV = null;this.isModified = true;this.hV = c;\n  };this.setUnusedBitsAndHexValue = function (c, e) {\n    if (c < 0 || 7 < c) {\n      throw \"unused bits shall be from 0 to 7: u = \" + c;\n    }var d = \"0\" + c;this.hTLV = null;this.isModified = true;this.hV = d + e;\n  };this.setByBinaryString = function (e) {\n    e = e.replace(/0+$/, \"\");var f = 8 - e.length % 8;if (f == 8) {\n      f = 0;\n    }for (var g = 0; g <= f; g++) {\n      e += \"0\";\n    }var j = \"\";for (var g = 0; g < e.length - 1; g += 8) {\n      var d = e.substr(g, 8);var c = parseInt(d, 2).toString(16);if (c.length == 1) {\n        c = \"0\" + c;\n      }j += c;\n    }this.hTLV = null;this.isModified = true;this.hV = \"0\" + f + j;\n  };this.setByBooleanArray = function (e) {\n    var d = \"\";for (var c = 0; c < e.length; c++) {\n      if (e[c] == true) {\n        d += \"1\";\n      } else {\n        d += \"0\";\n      }\n    }this.setByBinaryString(d);\n  };this.newFalseArray = function (e) {\n    var c = new Array(e);for (var d = 0; d < e; d++) {\n      c[d] = false;\n    }return c;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof b != \"undefined\") {\n    if (typeof b == \"string\" && b.toLowerCase().match(/^[0-9a-f]+$/)) {\n      this.setHexValueIncludingUnusedBits(b);\n    } else {\n      if (typeof b.hex != \"undefined\") {\n        this.setHexValueIncludingUnusedBits(b.hex);\n      } else {\n        if (typeof b.bin != \"undefined\") {\n          this.setByBinaryString(b.bin);\n        } else {\n          if (typeof b.array != \"undefined\") {\n            this.setByBooleanArray(b.array);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERBitString, KJUR.asn1.ASN1Object);KJUR.asn1.DEROctetString = function (b) {\n  if (b !== undefined && typeof b.obj !== \"undefined\") {\n    var a = KJUR.asn1.ASN1Util.newObject(b.obj);b.hex = a.getEncodedHex();\n  }KJUR.asn1.DEROctetString.superclass.constructor.call(this, b);this.hT = \"04\";\n};YAHOO.lang.extend(KJUR.asn1.DEROctetString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERNull = function () {\n  KJUR.asn1.DERNull.superclass.constructor.call(this);this.hT = \"05\";this.hTLV = \"0500\";\n};YAHOO.lang.extend(KJUR.asn1.DERNull, KJUR.asn1.ASN1Object);KJUR.asn1.DERObjectIdentifier = function (c) {\n  var b = function b(d) {\n    var e = d.toString(16);if (e.length == 1) {\n      e = \"0\" + e;\n    }return e;\n  };var a = function a(k) {\n    var j = \"\";var e = new BigInteger(k, 10);var d = e.toString(2);var f = 7 - d.length % 7;if (f == 7) {\n      f = 0;\n    }var m = \"\";for (var g = 0; g < f; g++) {\n      m += \"0\";\n    }d = m + d;for (var g = 0; g < d.length - 1; g += 7) {\n      var l = d.substr(g, 7);if (g != d.length - 7) {\n        l = \"1\" + l;\n      }j += b(parseInt(l, 2));\n    }return j;\n  };KJUR.asn1.DERObjectIdentifier.superclass.constructor.call(this);this.hT = \"06\";this.setValueHex = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = null;this.hV = d;\n  };this.setValueOidString = function (f) {\n    if (!f.match(/^[0-9.]+$/)) {\n      throw \"malformed oid string: \" + f;\n    }var g = \"\";var d = f.split(\".\");var j = parseInt(d[0]) * 40 + parseInt(d[1]);g += b(j);d.splice(0, 2);for (var e = 0; e < d.length; e++) {\n      g += a(d[e]);\n    }this.hTLV = null;this.isModified = true;this.s = null;this.hV = g;\n  };this.setValueName = function (e) {\n    var d = KJUR.asn1.x509.OID.name2oid(e);if (d !== \"\") {\n      this.setValueOidString(d);\n    } else {\n      throw \"DERObjectIdentifier oidName undefined: \" + e;\n    }\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (c !== undefined) {\n    if (typeof c === \"string\") {\n      if (c.match(/^[0-2].[0-9.]+$/)) {\n        this.setValueOidString(c);\n      } else {\n        this.setValueName(c);\n      }\n    } else {\n      if (c.oid !== undefined) {\n        this.setValueOidString(c.oid);\n      } else {\n        if (c.hex !== undefined) {\n          this.setValueHex(c.hex);\n        } else {\n          if (c.name !== undefined) {\n            this.setValueName(c.name);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERObjectIdentifier, KJUR.asn1.ASN1Object);KJUR.asn1.DEREnumerated = function (a) {\n  KJUR.asn1.DEREnumerated.superclass.constructor.call(this);this.hT = \"0a\";this.setByBigInteger = function (b) {\n    this.hTLV = null;this.isModified = true;this.hV = KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b);\n  };this.setByInteger = function (c) {\n    var b = new BigInteger(String(c), 10);this.setByBigInteger(b);\n  };this.setValueHex = function (b) {\n    this.hV = b;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a[\"int\"] != \"undefined\") {\n      this.setByInteger(a[\"int\"]);\n    } else {\n      if (typeof a == \"number\") {\n        this.setByInteger(a);\n      } else {\n        if (typeof a.hex != \"undefined\") {\n          this.setValueHex(a.hex);\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DEREnumerated, KJUR.asn1.ASN1Object);KJUR.asn1.DERUTF8String = function (a) {\n  KJUR.asn1.DERUTF8String.superclass.constructor.call(this, a);this.hT = \"0c\";\n};YAHOO.lang.extend(KJUR.asn1.DERUTF8String, KJUR.asn1.DERAbstractString);KJUR.asn1.DERNumericString = function (a) {\n  KJUR.asn1.DERNumericString.superclass.constructor.call(this, a);this.hT = \"12\";\n};YAHOO.lang.extend(KJUR.asn1.DERNumericString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERPrintableString = function (a) {\n  KJUR.asn1.DERPrintableString.superclass.constructor.call(this, a);this.hT = \"13\";\n};YAHOO.lang.extend(KJUR.asn1.DERPrintableString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERTeletexString = function (a) {\n  KJUR.asn1.DERTeletexString.superclass.constructor.call(this, a);this.hT = \"14\";\n};YAHOO.lang.extend(KJUR.asn1.DERTeletexString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERIA5String = function (a) {\n  KJUR.asn1.DERIA5String.superclass.constructor.call(this, a);this.hT = \"16\";\n};YAHOO.lang.extend(KJUR.asn1.DERIA5String, KJUR.asn1.DERAbstractString);KJUR.asn1.DERUTCTime = function (a) {\n  KJUR.asn1.DERUTCTime.superclass.constructor.call(this, a);this.hT = \"17\";this.setByDate = function (b) {\n    this.hTLV = null;this.isModified = true;this.date = b;this.s = this.formatDate(this.date, \"utc\");this.hV = stohex(this.s);\n  };this.getFreshValueHex = function () {\n    if (typeof this.date == \"undefined\" && typeof this.s == \"undefined\") {\n      this.date = new Date();this.s = this.formatDate(this.date, \"utc\");this.hV = stohex(this.s);\n    }return this.hV;\n  };if (a !== undefined) {\n    if (a.str !== undefined) {\n      this.setString(a.str);\n    } else {\n      if (typeof a == \"string\" && a.match(/^[0-9]{12}Z$/)) {\n        this.setString(a);\n      } else {\n        if (a.hex !== undefined) {\n          this.setStringHex(a.hex);\n        } else {\n          if (a.date !== undefined) {\n            this.setByDate(a.date);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERUTCTime, KJUR.asn1.DERAbstractTime);KJUR.asn1.DERGeneralizedTime = function (a) {\n  KJUR.asn1.DERGeneralizedTime.superclass.constructor.call(this, a);this.hT = \"18\";this.withMillis = false;this.setByDate = function (b) {\n    this.hTLV = null;this.isModified = true;this.date = b;this.s = this.formatDate(this.date, \"gen\", this.withMillis);this.hV = stohex(this.s);\n  };this.getFreshValueHex = function () {\n    if (this.date === undefined && this.s === undefined) {\n      this.date = new Date();this.s = this.formatDate(this.date, \"gen\", this.withMillis);this.hV = stohex(this.s);\n    }return this.hV;\n  };if (a !== undefined) {\n    if (a.str !== undefined) {\n      this.setString(a.str);\n    } else {\n      if (typeof a == \"string\" && a.match(/^[0-9]{14}Z$/)) {\n        this.setString(a);\n      } else {\n        if (a.hex !== undefined) {\n          this.setStringHex(a.hex);\n        } else {\n          if (a.date !== undefined) {\n            this.setByDate(a.date);\n          }\n        }\n      }\n    }if (a.millis === true) {\n      this.withMillis = true;\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERGeneralizedTime, KJUR.asn1.DERAbstractTime);KJUR.asn1.DERSequence = function (a) {\n  KJUR.asn1.DERSequence.superclass.constructor.call(this, a);this.hT = \"30\";this.getFreshValueHex = function () {\n    var c = \"\";for (var b = 0; b < this.asn1Array.length; b++) {\n      var d = this.asn1Array[b];c += d.getEncodedHex();\n    }this.hV = c;return this.hV;\n  };\n};YAHOO.lang.extend(KJUR.asn1.DERSequence, KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERSet = function (a) {\n  KJUR.asn1.DERSet.superclass.constructor.call(this, a);this.hT = \"31\";this.sortFlag = true;this.getFreshValueHex = function () {\n    var b = new Array();for (var c = 0; c < this.asn1Array.length; c++) {\n      var d = this.asn1Array[c];b.push(d.getEncodedHex());\n    }if (this.sortFlag == true) {\n      b.sort();\n    }this.hV = b.join(\"\");return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a.sortflag != \"undefined\" && a.sortflag == false) {\n      this.sortFlag = false;\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERSet, KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERTaggedObject = function (a) {\n  KJUR.asn1.DERTaggedObject.superclass.constructor.call(this);this.hT = \"a0\";this.hV = \"\";this.isExplicit = true;this.asn1Object = null;this.setASN1Object = function (b, c, d) {\n    this.hT = c;this.isExplicit = b;this.asn1Object = d;if (this.isExplicit) {\n      this.hV = this.asn1Object.getEncodedHex();this.hTLV = null;this.isModified = true;\n    } else {\n      this.hV = null;this.hTLV = d.getEncodedHex();this.hTLV = this.hTLV.replace(/^../, c);this.isModified = false;\n    }\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a.tag != \"undefined\") {\n      this.hT = a.tag;\n    }if (typeof a.explicit != \"undefined\") {\n      this.isExplicit = a.explicit;\n    }if (typeof a.obj != \"undefined\") {\n      this.asn1Object = a.obj;this.setASN1Object(this.isExplicit, this.hT, this.asn1Object);\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERTaggedObject, KJUR.asn1.ASN1Object);\nvar ASN1HEX = new function () {}();ASN1HEX.getLblen = function (c, a) {\n  if (c.substr(a + 2, 1) != \"8\") {\n    return 1;\n  }var b = parseInt(c.substr(a + 3, 1));if (b == 0) {\n    return -1;\n  }if (0 < b && b < 10) {\n    return b + 1;\n  }return -2;\n};ASN1HEX.getL = function (c, b) {\n  var a = ASN1HEX.getLblen(c, b);if (a < 1) {\n    return \"\";\n  }return c.substr(b + 2, a * 2);\n};ASN1HEX.getVblen = function (d, a) {\n  var c, b;c = ASN1HEX.getL(d, a);if (c == \"\") {\n    return -1;\n  }if (c.substr(0, 1) === \"8\") {\n    b = new BigInteger(c.substr(2), 16);\n  } else {\n    b = new BigInteger(c, 16);\n  }return b.intValue();\n};ASN1HEX.getVidx = function (c, b) {\n  var a = ASN1HEX.getLblen(c, b);if (a < 0) {\n    return a;\n  }return b + (a + 1) * 2;\n};ASN1HEX.getV = function (d, a) {\n  var c = ASN1HEX.getVidx(d, a);var b = ASN1HEX.getVblen(d, a);return d.substr(c, b * 2);\n};ASN1HEX.getTLV = function (b, a) {\n  return b.substr(a, 2) + ASN1HEX.getL(b, a) + ASN1HEX.getV(b, a);\n};ASN1HEX.getNextSiblingIdx = function (d, a) {\n  var c = ASN1HEX.getVidx(d, a);var b = ASN1HEX.getVblen(d, a);return c + b * 2;\n};ASN1HEX.getChildIdx = function (e, f) {\n  var j = ASN1HEX;var g = new Array();var i = j.getVidx(e, f);if (e.substr(f, 2) == \"03\") {\n    g.push(i + 2);\n  } else {\n    g.push(i);\n  }var l = j.getVblen(e, f);var c = i;var d = 0;while (1) {\n    var b = j.getNextSiblingIdx(e, c);if (b == null || b - i >= l * 2) {\n      break;\n    }if (d >= 200) {\n      break;\n    }g.push(b);c = b;d++;\n  }return g;\n};ASN1HEX.getNthChildIdx = function (d, b, e) {\n  var c = ASN1HEX.getChildIdx(d, b);return c[e];\n};ASN1HEX.getIdxbyList = function (e, d, c, i) {\n  var g = ASN1HEX;var f, b;if (c.length == 0) {\n    if (i !== undefined) {\n      if (e.substr(d, 2) !== i) {\n        throw \"checking tag doesn't match: \" + e.substr(d, 2) + \"!=\" + i;\n      }\n    }return d;\n  }f = c.shift();b = g.getChildIdx(e, d);return g.getIdxbyList(e, b[f], c, i);\n};ASN1HEX.getTLVbyList = function (d, c, b, f) {\n  var e = ASN1HEX;var a = e.getIdxbyList(d, c, b);if (a === undefined) {\n    throw \"can't find nthList object\";\n  }if (f !== undefined) {\n    if (d.substr(a, 2) != f) {\n      throw \"checking tag doesn't match: \" + d.substr(a, 2) + \"!=\" + f;\n    }\n  }return e.getTLV(d, a);\n};ASN1HEX.getVbyList = function (e, c, b, g, i) {\n  var f = ASN1HEX;var a, d;a = f.getIdxbyList(e, c, b, g);if (a === undefined) {\n    throw \"can't find nthList object\";\n  }d = f.getV(e, a);if (i === true) {\n    d = d.substr(2);\n  }return d;\n};ASN1HEX.hextooidstr = function (e) {\n  var h = function h(b, a) {\n    if (b.length >= a) {\n      return b;\n    }return new Array(a - b.length + 1).join(\"0\") + b;\n  };var l = [];var o = e.substr(0, 2);var f = parseInt(o, 16);l[0] = new String(Math.floor(f / 40));l[1] = new String(f % 40);var m = e.substr(2);var k = [];for (var g = 0; g < m.length / 2; g++) {\n    k.push(parseInt(m.substr(g * 2, 2), 16));\n  }var j = [];var d = \"\";for (var g = 0; g < k.length; g++) {\n    if (k[g] & 128) {\n      d = d + h((k[g] & 127).toString(2), 7);\n    } else {\n      d = d + h((k[g] & 127).toString(2), 7);j.push(new String(parseInt(d, 2)));d = \"\";\n    }\n  }var n = l.join(\".\");if (j.length > 0) {\n    n = n + \".\" + j.join(\".\");\n  }return n;\n};ASN1HEX.dump = function (t, c, l, g) {\n  var p = ASN1HEX;var j = p.getV;var y = p.dump;var w = p.getChildIdx;var e = t;if (t instanceof KJUR.asn1.ASN1Object) {\n    e = t.getEncodedHex();\n  }var q = function q(A, i) {\n    if (A.length <= i * 2) {\n      return A;\n    } else {\n      var v = A.substr(0, i) + \"..(total \" + A.length / 2 + \"bytes)..\" + A.substr(A.length - i, i);return v;\n    }\n  };if (c === undefined) {\n    c = { ommit_long_octet: 32 };\n  }if (l === undefined) {\n    l = 0;\n  }if (g === undefined) {\n    g = \"\";\n  }var x = c.ommit_long_octet;if (e.substr(l, 2) == \"01\") {\n    var h = j(e, l);if (h == \"00\") {\n      return g + \"BOOLEAN FALSE\\n\";\n    } else {\n      return g + \"BOOLEAN TRUE\\n\";\n    }\n  }if (e.substr(l, 2) == \"02\") {\n    var h = j(e, l);return g + \"INTEGER \" + q(h, x) + \"\\n\";\n  }if (e.substr(l, 2) == \"03\") {\n    var h = j(e, l);return g + \"BITSTRING \" + q(h, x) + \"\\n\";\n  }if (e.substr(l, 2) == \"04\") {\n    var h = j(e, l);if (p.isASN1HEX(h)) {\n      var k = g + \"OCTETSTRING, encapsulates\\n\";k = k + y(h, c, 0, g + \"  \");return k;\n    } else {\n      return g + \"OCTETSTRING \" + q(h, x) + \"\\n\";\n    }\n  }if (e.substr(l, 2) == \"05\") {\n    return g + \"NULL\\n\";\n  }if (e.substr(l, 2) == \"06\") {\n    var m = j(e, l);var a = KJUR.asn1.ASN1Util.oidHexToInt(m);var o = KJUR.asn1.x509.OID.oid2name(a);var b = a.replace(/\\./g, \" \");if (o != \"\") {\n      return g + \"ObjectIdentifier \" + o + \" (\" + b + \")\\n\";\n    } else {\n      return g + \"ObjectIdentifier (\" + b + \")\\n\";\n    }\n  }if (e.substr(l, 2) == \"0c\") {\n    return g + \"UTF8String '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"13\") {\n    return g + \"PrintableString '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"14\") {\n    return g + \"TeletexString '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"16\") {\n    return g + \"IA5String '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"17\") {\n    return g + \"UTCTime \" + hextoutf8(j(e, l)) + \"\\n\";\n  }if (e.substr(l, 2) == \"18\") {\n    return g + \"GeneralizedTime \" + hextoutf8(j(e, l)) + \"\\n\";\n  }if (e.substr(l, 2) == \"30\") {\n    if (e.substr(l, 4) == \"3000\") {\n      return g + \"SEQUENCE {}\\n\";\n    }var k = g + \"SEQUENCE\\n\";var d = w(e, l);var f = c;if ((d.length == 2 || d.length == 3) && e.substr(d[0], 2) == \"06\" && e.substr(d[d.length - 1], 2) == \"04\") {\n      var o = p.oidname(j(e, d[0]));var r = JSON.parse(JSON.stringify(c));r.x509ExtName = o;f = r;\n    }for (var u = 0; u < d.length; u++) {\n      k = k + y(e, f, d[u], g + \"  \");\n    }return k;\n  }if (e.substr(l, 2) == \"31\") {\n    var k = g + \"SET\\n\";var d = w(e, l);for (var u = 0; u < d.length; u++) {\n      k = k + y(e, c, d[u], g + \"  \");\n    }return k;\n  }var z = parseInt(e.substr(l, 2), 16);if ((z & 128) != 0) {\n    var n = z & 31;if ((z & 32) != 0) {\n      var k = g + \"[\" + n + \"]\\n\";var d = w(e, l);for (var u = 0; u < d.length; u++) {\n        k = k + y(e, c, d[u], g + \"  \");\n      }return k;\n    } else {\n      var h = j(e, l);if (h.substr(0, 8) == \"68747470\") {\n        h = hextoutf8(h);\n      }if (c.x509ExtName === \"subjectAltName\" && n == 2) {\n        h = hextoutf8(h);\n      }var k = g + \"[\" + n + \"] \" + h + \"\\n\";return k;\n    }\n  }return g + \"UNKNOWN(\" + e.substr(l, 2) + \") \" + j(e, l) + \"\\n\";\n};ASN1HEX.isASN1HEX = function (e) {\n  var d = ASN1HEX;if (e.length % 2 == 1) {\n    return false;\n  }var c = d.getVblen(e, 0);var b = e.substr(0, 2);var f = d.getL(e, 0);var a = e.length - b.length - f.length;if (a == c * 2) {\n    return true;\n  }return false;\n};ASN1HEX.oidname = function (a) {\n  var c = KJUR.asn1;if (KJUR.lang.String.isHex(a)) {\n    a = c.ASN1Util.oidHexToInt(a);\n  }var b = c.x509.OID.oid2name(a);if (b === \"\") {\n    b = a;\n  }return b;\n};\nvar KJUR;if (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.lang == \"undefined\" || !KJUR.lang) {\n  KJUR.lang = {};\n}KJUR.lang.String = function () {};function Base64x() {}function stoBA(d) {\n  var b = new Array();for (var c = 0; c < d.length; c++) {\n    b[c] = d.charCodeAt(c);\n  }return b;\n}function BAtos(b) {\n  var d = \"\";for (var c = 0; c < b.length; c++) {\n    d = d + String.fromCharCode(b[c]);\n  }return d;\n}function BAtohex(b) {\n  var e = \"\";for (var d = 0; d < b.length; d++) {\n    var c = b[d].toString(16);if (c.length == 1) {\n      c = \"0\" + c;\n    }e = e + c;\n  }return e;\n}function stohex(a) {\n  return BAtohex(stoBA(a));\n}function stob64(a) {\n  return hex2b64(stohex(a));\n}function stob64u(a) {\n  return b64tob64u(hex2b64(stohex(a)));\n}function b64utos(a) {\n  return BAtos(b64toBA(b64utob64(a)));\n}function b64tob64u(a) {\n  a = a.replace(/\\=/g, \"\");a = a.replace(/\\+/g, \"-\");a = a.replace(/\\//g, \"_\");return a;\n}function b64utob64(a) {\n  if (a.length % 4 == 2) {\n    a = a + \"==\";\n  } else {\n    if (a.length % 4 == 3) {\n      a = a + \"=\";\n    }\n  }a = a.replace(/-/g, \"+\");a = a.replace(/_/g, \"/\");return a;\n}function hextob64u(a) {\n  if (a.length % 2 == 1) {\n    a = \"0\" + a;\n  }return b64tob64u(hex2b64(a));\n}function b64utohex(a) {\n  return b64tohex(b64utob64(a));\n}var utf8tob64u, b64utoutf8;if (typeof Buffer === \"function\") {\n  exports.utf8tob64u = utf8tob64u = function utf8tob64u(a) {\n    return b64tob64u(new Buffer(a, \"utf8\").toString(\"base64\"));\n  };exports.b64utoutf8 = b64utoutf8 = function b64utoutf8(a) {\n    return new Buffer(b64utob64(a), \"base64\").toString(\"utf8\");\n  };\n} else {\n  exports.utf8tob64u = utf8tob64u = function utf8tob64u(a) {\n    return hextob64u(uricmptohex(encodeURIComponentAll(a)));\n  };exports.b64utoutf8 = b64utoutf8 = function b64utoutf8(a) {\n    return decodeURIComponent(hextouricmp(b64utohex(a)));\n  };\n}function utf8tob64(a) {\n  return hex2b64(uricmptohex(encodeURIComponentAll(a)));\n}function b64toutf8(a) {\n  return decodeURIComponent(hextouricmp(b64tohex(a)));\n}function utf8tohex(a) {\n  return uricmptohex(encodeURIComponentAll(a));\n}function hextoutf8(a) {\n  return decodeURIComponent(hextouricmp(a));\n}function hextorstr(c) {\n  var b = \"\";for (var a = 0; a < c.length - 1; a += 2) {\n    b += String.fromCharCode(parseInt(c.substr(a, 2), 16));\n  }return b;\n}function rstrtohex(c) {\n  var a = \"\";for (var b = 0; b < c.length; b++) {\n    a += (\"0\" + c.charCodeAt(b).toString(16)).slice(-2);\n  }return a;\n}function hextob64(a) {\n  return hex2b64(a);\n}function hextob64nl(b) {\n  var a = hextob64(b);var c = a.replace(/(.{64})/g, \"$1\\r\\n\");c = c.replace(/\\r\\n$/, \"\");return c;\n}function b64nltohex(b) {\n  var a = b.replace(/[^0-9A-Za-z\\/+=]*/g, \"\");var c = b64tohex(a);return c;\n}function hextopem(a, b) {\n  var c = hextob64nl(a);return \"-----BEGIN \" + b + \"-----\\r\\n\" + c + \"\\r\\n-----END \" + b + \"-----\\r\\n\";\n}function pemtohex(a, b) {\n  if (a.indexOf(\"-----BEGIN \") == -1) {\n    throw \"can't find PEM header: \" + b;\n  }if (b !== undefined) {\n    a = a.replace(\"-----BEGIN \" + b + \"-----\", \"\");a = a.replace(\"-----END \" + b + \"-----\", \"\");\n  } else {\n    a = a.replace(/-----BEGIN [^-]+-----/, \"\");a = a.replace(/-----END [^-]+-----/, \"\");\n  }return b64nltohex(a);\n}function hextoArrayBuffer(d) {\n  if (d.length % 2 != 0) {\n    throw \"input is not even length\";\n  }if (d.match(/^[0-9A-Fa-f]+$/) == null) {\n    throw \"input is not hexadecimal\";\n  }var b = new ArrayBuffer(d.length / 2);var a = new DataView(b);for (var c = 0; c < d.length / 2; c++) {\n    a.setUint8(c, parseInt(d.substr(c * 2, 2), 16));\n  }return b;\n}function ArrayBuffertohex(b) {\n  var d = \"\";var a = new DataView(b);for (var c = 0; c < b.byteLength; c++) {\n    d += (\"00\" + a.getUint8(c).toString(16)).slice(-2);\n  }return d;\n}function zulutomsec(n) {\n  var l, j, m, e, f, i, b, k;var a, h, g, c;c = n.match(/^(\\d{2}|\\d{4})(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(|\\.\\d+)Z$/);if (c) {\n    a = c[1];l = parseInt(a);if (a.length === 2) {\n      if (50 <= l && l < 100) {\n        l = 1900 + l;\n      } else {\n        if (0 <= l && l < 50) {\n          l = 2000 + l;\n        }\n      }\n    }j = parseInt(c[2]) - 1;m = parseInt(c[3]);e = parseInt(c[4]);f = parseInt(c[5]);i = parseInt(c[6]);b = 0;h = c[7];if (h !== \"\") {\n      g = (h.substr(1) + \"00\").substr(0, 3);b = parseInt(g);\n    }return Date.UTC(l, j, m, e, f, i, b);\n  }throw \"unsupported zulu format: \" + n;\n}function zulutosec(a) {\n  var b = zulutomsec(a);return ~~(b / 1000);\n}function zulutodate(a) {\n  return new Date(zulutomsec(a));\n}function datetozulu(g, e, f) {\n  var b;var a = g.getUTCFullYear();if (e) {\n    if (a < 1950 || 2049 < a) {\n      throw \"not proper year for UTCTime: \" + a;\n    }b = (\"\" + a).slice(-2);\n  } else {\n    b = (\"000\" + a).slice(-4);\n  }b += (\"0\" + (g.getUTCMonth() + 1)).slice(-2);b += (\"0\" + g.getUTCDate()).slice(-2);b += (\"0\" + g.getUTCHours()).slice(-2);b += (\"0\" + g.getUTCMinutes()).slice(-2);b += (\"0\" + g.getUTCSeconds()).slice(-2);if (f) {\n    var c = g.getUTCMilliseconds();if (c !== 0) {\n      c = (\"00\" + c).slice(-3);c = c.replace(/0+$/g, \"\");b += \".\" + c;\n    }\n  }b += \"Z\";return b;\n}function uricmptohex(a) {\n  return a.replace(/%/g, \"\");\n}function hextouricmp(a) {\n  return a.replace(/(..)/g, \"%$1\");\n}function ipv6tohex(g) {\n  var b = \"malformed IPv6 address\";if (!g.match(/^[0-9A-Fa-f:]+$/)) {\n    throw b;\n  }g = g.toLowerCase();var d = g.split(\":\").length - 1;if (d < 2) {\n    throw b;\n  }var e = \":\".repeat(7 - d + 2);g = g.replace(\"::\", e);var c = g.split(\":\");if (c.length != 8) {\n    throw b;\n  }for (var f = 0; f < 8; f++) {\n    c[f] = (\"0000\" + c[f]).slice(-4);\n  }return c.join(\"\");\n}function hextoipv6(e) {\n  if (!e.match(/^[0-9A-Fa-f]{32}$/)) {\n    throw \"malformed IPv6 address octet\";\n  }e = e.toLowerCase();var b = e.match(/.{1,4}/g);for (var d = 0; d < 8; d++) {\n    b[d] = b[d].replace(/^0+/, \"\");if (b[d] == \"\") {\n      b[d] = \"0\";\n    }\n  }e = \":\" + b.join(\":\") + \":\";var c = e.match(/:(0:){2,}/g);if (c === null) {\n    return e.slice(1, -1);\n  }var f = \"\";for (var d = 0; d < c.length; d++) {\n    if (c[d].length > f.length) {\n      f = c[d];\n    }\n  }e = e.replace(f, \"::\");return e.slice(1, -1);\n}function hextoip(b) {\n  var d = \"malformed hex value\";if (!b.match(/^([0-9A-Fa-f][0-9A-Fa-f]){1,}$/)) {\n    throw d;\n  }if (b.length == 8) {\n    var c;try {\n      c = parseInt(b.substr(0, 2), 16) + \".\" + parseInt(b.substr(2, 2), 16) + \".\" + parseInt(b.substr(4, 2), 16) + \".\" + parseInt(b.substr(6, 2), 16);return c;\n    } catch (a) {\n      throw d;\n    }\n  } else {\n    if (b.length == 32) {\n      return hextoipv6(b);\n    } else {\n      return b;\n    }\n  }\n}function iptohex(f) {\n  var j = \"malformed IP address\";f = f.toLowerCase(f);if (f.match(/^[0-9.]+$/)) {\n    var b = f.split(\".\");if (b.length !== 4) {\n      throw j;\n    }var g = \"\";try {\n      for (var e = 0; e < 4; e++) {\n        var h = parseInt(b[e]);g += (\"0\" + h.toString(16)).slice(-2);\n      }return g;\n    } catch (c) {\n      throw j;\n    }\n  } else {\n    if (f.match(/^[0-9a-f:]+$/) && f.indexOf(\":\") !== -1) {\n      return ipv6tohex(f);\n    } else {\n      throw j;\n    }\n  }\n}function encodeURIComponentAll(a) {\n  var d = encodeURIComponent(a);var b = \"\";for (var c = 0; c < d.length; c++) {\n    if (d[c] == \"%\") {\n      b = b + d.substr(c, 3);c = c + 2;\n    } else {\n      b = b + \"%\" + stohex(d[c]);\n    }\n  }return b;\n}function newline_toUnix(a) {\n  a = a.replace(/\\r\\n/mg, \"\\n\");return a;\n}function newline_toDos(a) {\n  a = a.replace(/\\r\\n/mg, \"\\n\");a = a.replace(/\\n/mg, \"\\r\\n\");return a;\n}KJUR.lang.String.isInteger = function (a) {\n  if (a.match(/^[0-9]+$/)) {\n    return true;\n  } else {\n    if (a.match(/^-[0-9]+$/)) {\n      return true;\n    } else {\n      return false;\n    }\n  }\n};KJUR.lang.String.isHex = function (a) {\n  if (a.length % 2 == 0 && (a.match(/^[0-9a-f]+$/) || a.match(/^[0-9A-F]+$/))) {\n    return true;\n  } else {\n    return false;\n  }\n};KJUR.lang.String.isBase64 = function (a) {\n  a = a.replace(/\\s+/g, \"\");if (a.match(/^[0-9A-Za-z+\\/]+={0,3}$/) && a.length % 4 == 0) {\n    return true;\n  } else {\n    return false;\n  }\n};KJUR.lang.String.isBase64URL = function (a) {\n  if (a.match(/[+/=]/)) {\n    return false;\n  }a = b64utob64(a);return KJUR.lang.String.isBase64(a);\n};KJUR.lang.String.isIntegerArray = function (a) {\n  a = a.replace(/\\s+/g, \"\");if (a.match(/^\\[[0-9,]+\\]$/)) {\n    return true;\n  } else {\n    return false;\n  }\n};function hextoposhex(a) {\n  if (a.length % 2 == 1) {\n    return \"0\" + a;\n  }if (a.substr(0, 1) > \"7\") {\n    return \"00\" + a;\n  }return a;\n}function intarystrtohex(b) {\n  b = b.replace(/^\\s*\\[\\s*/, \"\");b = b.replace(/\\s*\\]\\s*$/, \"\");b = b.replace(/\\s*/g, \"\");try {\n    var c = b.split(/,/).map(function (g, e, h) {\n      var f = parseInt(g);if (f < 0 || 255 < f) {\n        throw \"integer not in range 0-255\";\n      }var d = (\"00\" + f.toString(16)).slice(-2);return d;\n    }).join(\"\");return c;\n  } catch (a) {\n    throw \"malformed integer array string: \" + a;\n  }\n}var strdiffidx = function strdiffidx(c, a) {\n  var d = c.length;if (c.length > a.length) {\n    d = a.length;\n  }for (var b = 0; b < d; b++) {\n    if (c.charCodeAt(b) != a.charCodeAt(b)) {\n      return b;\n    }\n  }if (c.length != a.length) {\n    return d;\n  }return -1;\n};\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.crypto == \"undefined\" || !KJUR.crypto) {\n  KJUR.crypto = {};\n}KJUR.crypto.Util = new function () {\n  this.DIGESTINFOHEAD = { sha1: \"3021300906052b0e03021a05000414\", sha224: \"302d300d06096086480165030402040500041c\", sha256: \"3031300d060960864801650304020105000420\", sha384: \"3041300d060960864801650304020205000430\", sha512: \"3051300d060960864801650304020305000440\", md2: \"3020300c06082a864886f70d020205000410\", md5: \"3020300c06082a864886f70d020505000410\", ripemd160: \"3021300906052b2403020105000414\" };this.DEFAULTPROVIDER = { md5: \"cryptojs\", sha1: \"cryptojs\", sha224: \"cryptojs\", sha256: \"cryptojs\", sha384: \"cryptojs\", sha512: \"cryptojs\", ripemd160: \"cryptojs\", hmacmd5: \"cryptojs\", hmacsha1: \"cryptojs\", hmacsha224: \"cryptojs\", hmacsha256: \"cryptojs\", hmacsha384: \"cryptojs\", hmacsha512: \"cryptojs\", hmacripemd160: \"cryptojs\", MD5withRSA: \"cryptojs/jsrsa\", SHA1withRSA: \"cryptojs/jsrsa\", SHA224withRSA: \"cryptojs/jsrsa\", SHA256withRSA: \"cryptojs/jsrsa\", SHA384withRSA: \"cryptojs/jsrsa\", SHA512withRSA: \"cryptojs/jsrsa\", RIPEMD160withRSA: \"cryptojs/jsrsa\", MD5withECDSA: \"cryptojs/jsrsa\", SHA1withECDSA: \"cryptojs/jsrsa\", SHA224withECDSA: \"cryptojs/jsrsa\", SHA256withECDSA: \"cryptojs/jsrsa\", SHA384withECDSA: \"cryptojs/jsrsa\", SHA512withECDSA: \"cryptojs/jsrsa\", RIPEMD160withECDSA: \"cryptojs/jsrsa\", SHA1withDSA: \"cryptojs/jsrsa\", SHA224withDSA: \"cryptojs/jsrsa\", SHA256withDSA: \"cryptojs/jsrsa\", MD5withRSAandMGF1: \"cryptojs/jsrsa\", SHA1withRSAandMGF1: \"cryptojs/jsrsa\", SHA224withRSAandMGF1: \"cryptojs/jsrsa\", SHA256withRSAandMGF1: \"cryptojs/jsrsa\", SHA384withRSAandMGF1: \"cryptojs/jsrsa\", SHA512withRSAandMGF1: \"cryptojs/jsrsa\", RIPEMD160withRSAandMGF1: \"cryptojs/jsrsa\" };this.CRYPTOJSMESSAGEDIGESTNAME = { md5: CryptoJS.algo.MD5, sha1: CryptoJS.algo.SHA1, sha224: CryptoJS.algo.SHA224, sha256: CryptoJS.algo.SHA256, sha384: CryptoJS.algo.SHA384, sha512: CryptoJS.algo.SHA512, ripemd160: CryptoJS.algo.RIPEMD160 };this.getDigestInfoHex = function (a, b) {\n    if (typeof this.DIGESTINFOHEAD[b] == \"undefined\") {\n      throw \"alg not supported in Util.DIGESTINFOHEAD: \" + b;\n    }return this.DIGESTINFOHEAD[b] + a;\n  };this.getPaddedDigestInfoHex = function (h, a, j) {\n    var c = this.getDigestInfoHex(h, a);var d = j / 4;if (c.length + 22 > d) {\n      throw \"key is too short for SigAlg: keylen=\" + j + \",\" + a;\n    }var b = \"0001\";var k = \"00\" + c;var g = \"\";var l = d - b.length - k.length;for (var f = 0; f < l; f += 2) {\n      g += \"ff\";\n    }var e = b + g + k;return e;\n  };this.hashString = function (a, c) {\n    var b = new KJUR.crypto.MessageDigest({ alg: c });return b.digestString(a);\n  };this.hashHex = function (b, c) {\n    var a = new KJUR.crypto.MessageDigest({ alg: c });return a.digestHex(b);\n  };this.sha1 = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha1\", prov: \"cryptojs\" });return b.digestString(a);\n  };this.sha256 = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha256\", prov: \"cryptojs\" });return b.digestString(a);\n  };this.sha256Hex = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha256\", prov: \"cryptojs\" });return b.digestHex(a);\n  };this.sha512 = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha512\", prov: \"cryptojs\" });return b.digestString(a);\n  };this.sha512Hex = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha512\", prov: \"cryptojs\" });return b.digestHex(a);\n  };\n}();KJUR.crypto.Util.md5 = function (a) {\n  var b = new KJUR.crypto.MessageDigest({ alg: \"md5\", prov: \"cryptojs\" });return b.digestString(a);\n};KJUR.crypto.Util.ripemd160 = function (a) {\n  var b = new KJUR.crypto.MessageDigest({ alg: \"ripemd160\", prov: \"cryptojs\" });return b.digestString(a);\n};KJUR.crypto.Util.SECURERANDOMGEN = new SecureRandom();KJUR.crypto.Util.getRandomHexOfNbytes = function (b) {\n  var a = new Array(b);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(a);return BAtohex(a);\n};KJUR.crypto.Util.getRandomBigIntegerOfNbytes = function (a) {\n  return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbytes(a), 16);\n};KJUR.crypto.Util.getRandomHexOfNbits = function (d) {\n  var c = d % 8;var a = (d - c) / 8;var b = new Array(a + 1);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(b);b[0] = (255 << c & 255 ^ 255) & b[0];return BAtohex(b);\n};KJUR.crypto.Util.getRandomBigIntegerOfNbits = function (a) {\n  return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbits(a), 16);\n};KJUR.crypto.Util.getRandomBigIntegerZeroToMax = function (b) {\n  var a = b.bitLength();while (1) {\n    var c = KJUR.crypto.Util.getRandomBigIntegerOfNbits(a);if (b.compareTo(c) != -1) {\n      return c;\n    }\n  }\n};KJUR.crypto.Util.getRandomBigIntegerMinToMax = function (e, b) {\n  var c = e.compareTo(b);if (c == 1) {\n    throw \"biMin is greater than biMax\";\n  }if (c == 0) {\n    return e;\n  }var a = b.subtract(e);var d = KJUR.crypto.Util.getRandomBigIntegerZeroToMax(a);return d.add(e);\n};KJUR.crypto.MessageDigest = function (c) {\n  var b = null;var a = null;var d = null;this.setAlgAndProvider = function (g, f) {\n    g = KJUR.crypto.MessageDigest.getCanonicalAlgName(g);if (g !== null && f === undefined) {\n      f = KJUR.crypto.Util.DEFAULTPROVIDER[g];\n    }if (\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g) != -1 && f == \"cryptojs\") {\n      try {\n        this.md = KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g].create();\n      } catch (e) {\n        throw \"setAlgAndProvider hash alg set fail alg=\" + g + \"/\" + e;\n      }this.updateString = function (h) {\n        this.md.update(h);\n      };this.updateHex = function (h) {\n        var i = CryptoJS.enc.Hex.parse(h);this.md.update(i);\n      };this.digest = function () {\n        var h = this.md.finalize();return h.toString(CryptoJS.enc.Hex);\n      };this.digestString = function (h) {\n        this.updateString(h);return this.digest();\n      };this.digestHex = function (h) {\n        this.updateHex(h);return this.digest();\n      };\n    }if (\":sha256:\".indexOf(g) != -1 && f == \"sjcl\") {\n      try {\n        this.md = new sjcl.hash.sha256();\n      } catch (e) {\n        throw \"setAlgAndProvider hash alg set fail alg=\" + g + \"/\" + e;\n      }this.updateString = function (h) {\n        this.md.update(h);\n      };this.updateHex = function (i) {\n        var h = sjcl.codec.hex.toBits(i);this.md.update(h);\n      };this.digest = function () {\n        var h = this.md.finalize();return sjcl.codec.hex.fromBits(h);\n      };this.digestString = function (h) {\n        this.updateString(h);return this.digest();\n      };this.digestHex = function (h) {\n        this.updateHex(h);return this.digest();\n      };\n    }\n  };this.updateString = function (e) {\n    throw \"updateString(str) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.updateHex = function (e) {\n    throw \"updateHex(hex) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.digest = function () {\n    throw \"digest() not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.digestString = function (e) {\n    throw \"digestString(str) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.digestHex = function (e) {\n    throw \"digestHex(hex) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };if (c !== undefined) {\n    if (c.alg !== undefined) {\n      this.algName = c.alg;if (c.prov === undefined) {\n        this.provName = KJUR.crypto.Util.DEFAULTPROVIDER[this.algName];\n      }this.setAlgAndProvider(this.algName, this.provName);\n    }\n  }\n};KJUR.crypto.MessageDigest.getCanonicalAlgName = function (a) {\n  if (typeof a === \"string\") {\n    a = a.toLowerCase();a = a.replace(/-/, \"\");\n  }return a;\n};KJUR.crypto.MessageDigest.getHashLength = function (c) {\n  var b = KJUR.crypto.MessageDigest;var a = b.getCanonicalAlgName(c);if (b.HASHLENGTH[a] === undefined) {\n    throw \"not supported algorithm: \" + c;\n  }return b.HASHLENGTH[a];\n};KJUR.crypto.MessageDigest.HASHLENGTH = { md5: 16, sha1: 20, sha224: 28, sha256: 32, sha384: 48, sha512: 64, ripemd160: 20 };KJUR.crypto.Mac = function (d) {\n  var f = null;var c = null;var a = null;var e = null;var b = null;this.setAlgAndProvider = function (k, i) {\n    k = k.toLowerCase();if (k == null) {\n      k = \"hmacsha1\";\n    }k = k.toLowerCase();if (k.substr(0, 4) != \"hmac\") {\n      throw \"setAlgAndProvider unsupported HMAC alg: \" + k;\n    }if (i === undefined) {\n      i = KJUR.crypto.Util.DEFAULTPROVIDER[k];\n    }this.algProv = k + \"/\" + i;var g = k.substr(4);if (\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g) != -1 && i == \"cryptojs\") {\n      try {\n        var j = KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g];this.mac = CryptoJS.algo.HMAC.create(j, this.pass);\n      } catch (h) {\n        throw \"setAlgAndProvider hash alg set fail hashAlg=\" + g + \"/\" + h;\n      }this.updateString = function (l) {\n        this.mac.update(l);\n      };this.updateHex = function (l) {\n        var m = CryptoJS.enc.Hex.parse(l);this.mac.update(m);\n      };this.doFinal = function () {\n        var l = this.mac.finalize();return l.toString(CryptoJS.enc.Hex);\n      };this.doFinalString = function (l) {\n        this.updateString(l);return this.doFinal();\n      };this.doFinalHex = function (l) {\n        this.updateHex(l);return this.doFinal();\n      };\n    }\n  };this.updateString = function (g) {\n    throw \"updateString(str) not supported for this alg/prov: \" + this.algProv;\n  };this.updateHex = function (g) {\n    throw \"updateHex(hex) not supported for this alg/prov: \" + this.algProv;\n  };this.doFinal = function () {\n    throw \"digest() not supported for this alg/prov: \" + this.algProv;\n  };this.doFinalString = function (g) {\n    throw \"digestString(str) not supported for this alg/prov: \" + this.algProv;\n  };this.doFinalHex = function (g) {\n    throw \"digestHex(hex) not supported for this alg/prov: \" + this.algProv;\n  };this.setPassword = function (h) {\n    if (typeof h == \"string\") {\n      var g = h;if (h.length % 2 == 1 || !h.match(/^[0-9A-Fa-f]+$/)) {\n        g = rstrtohex(h);\n      }this.pass = CryptoJS.enc.Hex.parse(g);return;\n    }if ((typeof h === \"undefined\" ? \"undefined\" : _typeof(h)) != \"object\") {\n      throw \"KJUR.crypto.Mac unsupported password type: \" + h;\n    }var g = null;if (h.hex !== undefined) {\n      if (h.hex.length % 2 != 0 || !h.hex.match(/^[0-9A-Fa-f]+$/)) {\n        throw \"Mac: wrong hex password: \" + h.hex;\n      }g = h.hex;\n    }if (h.utf8 !== undefined) {\n      g = utf8tohex(h.utf8);\n    }if (h.rstr !== undefined) {\n      g = rstrtohex(h.rstr);\n    }if (h.b64 !== undefined) {\n      g = b64tohex(h.b64);\n    }if (h.b64u !== undefined) {\n      g = b64utohex(h.b64u);\n    }if (g == null) {\n      throw \"KJUR.crypto.Mac unsupported password type: \" + h;\n    }this.pass = CryptoJS.enc.Hex.parse(g);\n  };if (d !== undefined) {\n    if (d.pass !== undefined) {\n      this.setPassword(d.pass);\n    }if (d.alg !== undefined) {\n      this.algName = d.alg;if (d.prov === undefined) {\n        this.provName = KJUR.crypto.Util.DEFAULTPROVIDER[this.algName];\n      }this.setAlgAndProvider(this.algName, this.provName);\n    }\n  }\n};KJUR.crypto.Signature = function (o) {\n  var q = null;var n = null;var r = null;var c = null;var l = null;var d = null;var k = null;var h = null;var p = null;var e = null;var b = -1;var g = null;var j = null;var a = null;var i = null;var f = null;this._setAlgNames = function () {\n    var s = this.algName.match(/^(.+)with(.+)$/);if (s) {\n      this.mdAlgName = s[1].toLowerCase();this.pubkeyAlgName = s[2].toLowerCase();\n    }\n  };this._zeroPaddingOfSignature = function (x, w) {\n    var v = \"\";var t = w / 4 - x.length;for (var u = 0; u < t; u++) {\n      v = v + \"0\";\n    }return v + x;\n  };this.setAlgAndProvider = function (u, t) {\n    this._setAlgNames();if (t != \"cryptojs/jsrsa\") {\n      throw \"provider not supported: \" + t;\n    }if (\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(this.mdAlgName) != -1) {\n      try {\n        this.md = new KJUR.crypto.MessageDigest({ alg: this.mdAlgName });\n      } catch (s) {\n        throw \"setAlgAndProvider hash alg set fail alg=\" + this.mdAlgName + \"/\" + s;\n      }this.init = function (w, x) {\n        var y = null;try {\n          if (x === undefined) {\n            y = KEYUTIL.getKey(w);\n          } else {\n            y = KEYUTIL.getKey(w, x);\n          }\n        } catch (v) {\n          throw \"init failed:\" + v;\n        }if (y.isPrivate === true) {\n          this.prvKey = y;this.state = \"SIGN\";\n        } else {\n          if (y.isPublic === true) {\n            this.pubKey = y;this.state = \"VERIFY\";\n          } else {\n            throw \"init failed.:\" + y;\n          }\n        }\n      };this.updateString = function (v) {\n        this.md.updateString(v);\n      };this.updateHex = function (v) {\n        this.md.updateHex(v);\n      };this.sign = function () {\n        this.sHashHex = this.md.digest();if (typeof this.ecprvhex != \"undefined\" && typeof this.eccurvename != \"undefined\") {\n          var v = new KJUR.crypto.ECDSA({ curve: this.eccurvename });this.hSign = v.signHex(this.sHashHex, this.ecprvhex);\n        } else {\n          if (this.prvKey instanceof RSAKey && this.pubkeyAlgName === \"rsaandmgf1\") {\n            this.hSign = this.prvKey.signWithMessageHashPSS(this.sHashHex, this.mdAlgName, this.pssSaltLen);\n          } else {\n            if (this.prvKey instanceof RSAKey && this.pubkeyAlgName === \"rsa\") {\n              this.hSign = this.prvKey.signWithMessageHash(this.sHashHex, this.mdAlgName);\n            } else {\n              if (this.prvKey instanceof KJUR.crypto.ECDSA) {\n                this.hSign = this.prvKey.signWithMessageHash(this.sHashHex);\n              } else {\n                if (this.prvKey instanceof KJUR.crypto.DSA) {\n                  this.hSign = this.prvKey.signWithMessageHash(this.sHashHex);\n                } else {\n                  throw \"Signature: unsupported private key alg: \" + this.pubkeyAlgName;\n                }\n              }\n            }\n          }\n        }return this.hSign;\n      };this.signString = function (v) {\n        this.updateString(v);return this.sign();\n      };this.signHex = function (v) {\n        this.updateHex(v);return this.sign();\n      };this.verify = function (v) {\n        this.sHashHex = this.md.digest();if (typeof this.ecpubhex != \"undefined\" && typeof this.eccurvename != \"undefined\") {\n          var w = new KJUR.crypto.ECDSA({ curve: this.eccurvename });return w.verifyHex(this.sHashHex, v, this.ecpubhex);\n        } else {\n          if (this.pubKey instanceof RSAKey && this.pubkeyAlgName === \"rsaandmgf1\") {\n            return this.pubKey.verifyWithMessageHashPSS(this.sHashHex, v, this.mdAlgName, this.pssSaltLen);\n          } else {\n            if (this.pubKey instanceof RSAKey && this.pubkeyAlgName === \"rsa\") {\n              return this.pubKey.verifyWithMessageHash(this.sHashHex, v);\n            } else {\n              if (KJUR.crypto.ECDSA !== undefined && this.pubKey instanceof KJUR.crypto.ECDSA) {\n                return this.pubKey.verifyWithMessageHash(this.sHashHex, v);\n              } else {\n                if (KJUR.crypto.DSA !== undefined && this.pubKey instanceof KJUR.crypto.DSA) {\n                  return this.pubKey.verifyWithMessageHash(this.sHashHex, v);\n                } else {\n                  throw \"Signature: unsupported public key alg: \" + this.pubkeyAlgName;\n                }\n              }\n            }\n          }\n        }\n      };\n    }\n  };this.init = function (s, t) {\n    throw \"init(key, pass) not supported for this alg:prov=\" + this.algProvName;\n  };this.updateString = function (s) {\n    throw \"updateString(str) not supported for this alg:prov=\" + this.algProvName;\n  };this.updateHex = function (s) {\n    throw \"updateHex(hex) not supported for this alg:prov=\" + this.algProvName;\n  };this.sign = function () {\n    throw \"sign() not supported for this alg:prov=\" + this.algProvName;\n  };this.signString = function (s) {\n    throw \"digestString(str) not supported for this alg:prov=\" + this.algProvName;\n  };this.signHex = function (s) {\n    throw \"digestHex(hex) not supported for this alg:prov=\" + this.algProvName;\n  };this.verify = function (s) {\n    throw \"verify(hSigVal) not supported for this alg:prov=\" + this.algProvName;\n  };this.initParams = o;if (o !== undefined) {\n    if (o.alg !== undefined) {\n      this.algName = o.alg;if (o.prov === undefined) {\n        this.provName = KJUR.crypto.Util.DEFAULTPROVIDER[this.algName];\n      } else {\n        this.provName = o.prov;\n      }this.algProvName = this.algName + \":\" + this.provName;this.setAlgAndProvider(this.algName, this.provName);this._setAlgNames();\n    }if (o.psssaltlen !== undefined) {\n      this.pssSaltLen = o.psssaltlen;\n    }if (o.prvkeypem !== undefined) {\n      if (o.prvkeypas !== undefined) {\n        throw \"both prvkeypem and prvkeypas parameters not supported\";\n      } else {\n        try {\n          var q = KEYUTIL.getKey(o.prvkeypem);this.init(q);\n        } catch (m) {\n          throw \"fatal error to load pem private key: \" + m;\n        }\n      }\n    }\n  }\n};KJUR.crypto.Cipher = function (a) {};KJUR.crypto.Cipher.encrypt = function (e, f, d) {\n  if (f instanceof RSAKey && f.isPublic) {\n    var c = KJUR.crypto.Cipher.getAlgByKeyAndName(f, d);if (c === \"RSA\") {\n      return f.encrypt(e);\n    }if (c === \"RSAOAEP\") {\n      return f.encryptOAEP(e, \"sha1\");\n    }var b = c.match(/^RSAOAEP(\\d+)$/);if (b !== null) {\n      return f.encryptOAEP(e, \"sha\" + b[1]);\n    }throw \"Cipher.encrypt: unsupported algorithm for RSAKey: \" + d;\n  } else {\n    throw \"Cipher.encrypt: unsupported key or algorithm\";\n  }\n};KJUR.crypto.Cipher.decrypt = function (e, f, d) {\n  if (f instanceof RSAKey && f.isPrivate) {\n    var c = KJUR.crypto.Cipher.getAlgByKeyAndName(f, d);if (c === \"RSA\") {\n      return f.decrypt(e);\n    }if (c === \"RSAOAEP\") {\n      return f.decryptOAEP(e, \"sha1\");\n    }var b = c.match(/^RSAOAEP(\\d+)$/);if (b !== null) {\n      return f.decryptOAEP(e, \"sha\" + b[1]);\n    }throw \"Cipher.decrypt: unsupported algorithm for RSAKey: \" + d;\n  } else {\n    throw \"Cipher.decrypt: unsupported key or algorithm\";\n  }\n};KJUR.crypto.Cipher.getAlgByKeyAndName = function (b, a) {\n  if (b instanceof RSAKey) {\n    if (\":RSA:RSAOAEP:RSAOAEP224:RSAOAEP256:RSAOAEP384:RSAOAEP512:\".indexOf(a) != -1) {\n      return a;\n    }if (a === null || a === undefined) {\n      return \"RSA\";\n    }throw \"getAlgByKeyAndName: not supported algorithm name for RSAKey: \" + a;\n  }throw \"getAlgByKeyAndName: not supported algorithm name: \" + a;\n};KJUR.crypto.OID = new function () {\n  this.oidhex2name = { \"2a864886f70d010101\": \"rsaEncryption\", \"2a8648ce3d0201\": \"ecPublicKey\", \"2a8648ce380401\": \"dsa\", \"2a8648ce3d030107\": \"secp256r1\", \"2b8104001f\": \"secp192k1\", \"2b81040021\": \"secp224r1\", \"2b8104000a\": \"secp256k1\", \"2b81040023\": \"secp521r1\", \"2b81040022\": \"secp384r1\", \"2a8648ce380403\": \"SHA1withDSA\", \"608648016503040301\": \"SHA224withDSA\", \"608648016503040302\": \"SHA256withDSA\" };\n}();\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.crypto == \"undefined\" || !KJUR.crypto) {\n  KJUR.crypto = {};\n}KJUR.crypto.ECDSA = function (h) {\n  var e = \"secp256r1\";var g = null;var b = null;var f = null;var a = new SecureRandom();var d = null;this.type = \"EC\";this.isPrivate = false;this.isPublic = false;function c(s, o, r, n) {\n    var j = Math.max(o.bitLength(), n.bitLength());var t = s.add2D(r);var q = s.curve.getInfinity();for (var p = j - 1; p >= 0; --p) {\n      q = q.twice2D();q.z = BigInteger.ONE;if (o.testBit(p)) {\n        if (n.testBit(p)) {\n          q = q.add2D(t);\n        } else {\n          q = q.add2D(s);\n        }\n      } else {\n        if (n.testBit(p)) {\n          q = q.add2D(r);\n        }\n      }\n    }return q;\n  }this.getBigRandom = function (i) {\n    return new BigInteger(i.bitLength(), a).mod(i.subtract(BigInteger.ONE)).add(BigInteger.ONE);\n  };this.setNamedCurve = function (i) {\n    this.ecparams = KJUR.crypto.ECParameterDB.getByName(i);this.prvKeyHex = null;this.pubKeyHex = null;this.curveName = i;\n  };this.setPrivateKeyHex = function (i) {\n    this.isPrivate = true;this.prvKeyHex = i;\n  };this.setPublicKeyHex = function (i) {\n    this.isPublic = true;this.pubKeyHex = i;\n  };this.getPublicKeyXYHex = function () {\n    var k = this.pubKeyHex;if (k.substr(0, 2) !== \"04\") {\n      throw \"this method supports uncompressed format(04) only\";\n    }var j = this.ecparams.keylen / 4;if (k.length !== 2 + j * 2) {\n      throw \"malformed public key hex length\";\n    }var i = {};i.x = k.substr(2, j);i.y = k.substr(2 + j);return i;\n  };this.getShortNISTPCurveName = function () {\n    var i = this.curveName;if (i === \"secp256r1\" || i === \"NIST P-256\" || i === \"P-256\" || i === \"prime256v1\") {\n      return \"P-256\";\n    }if (i === \"secp384r1\" || i === \"NIST P-384\" || i === \"P-384\") {\n      return \"P-384\";\n    }return null;\n  };this.generateKeyPairHex = function () {\n    var k = this.ecparams.n;var n = this.getBigRandom(k);var l = this.ecparams.G.multiply(n);var q = l.getX().toBigInteger();var o = l.getY().toBigInteger();var i = this.ecparams.keylen / 4;var m = (\"0000000000\" + n.toString(16)).slice(-i);var r = (\"0000000000\" + q.toString(16)).slice(-i);var p = (\"0000000000\" + o.toString(16)).slice(-i);var j = \"04\" + r + p;this.setPrivateKeyHex(m);this.setPublicKeyHex(j);return { ecprvhex: m, ecpubhex: j };\n  };this.signWithMessageHash = function (i) {\n    return this.signHex(i, this.prvKeyHex);\n  };this.signHex = function (o, j) {\n    var t = new BigInteger(j, 16);var l = this.ecparams.n;var q = new BigInteger(o, 16);do {\n      var m = this.getBigRandom(l);var u = this.ecparams.G;var p = u.multiply(m);var i = p.getX().toBigInteger().mod(l);\n    } while (i.compareTo(BigInteger.ZERO) <= 0);var v = m.modInverse(l).multiply(q.add(t.multiply(i))).mod(l);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(i, v);\n  };this.sign = function (m, u) {\n    var q = u;var j = this.ecparams.n;var p = BigInteger.fromByteArrayUnsigned(m);do {\n      var l = this.getBigRandom(j);var t = this.ecparams.G;var o = t.multiply(l);var i = o.getX().toBigInteger().mod(j);\n    } while (i.compareTo(BigInteger.ZERO) <= 0);var v = l.modInverse(j).multiply(p.add(q.multiply(i))).mod(j);return this.serializeSig(i, v);\n  };this.verifyWithMessageHash = function (j, i) {\n    return this.verifyHex(j, i, this.pubKeyHex);\n  };this.verifyHex = function (m, i, p) {\n    var l, j;var o = KJUR.crypto.ECDSA.parseSigHex(i);l = o.r;j = o.s;var k;k = ECPointFp.decodeFromHex(this.ecparams.curve, p);var n = new BigInteger(m, 16);return this.verifyRaw(n, l, j, k);\n  };this.verify = function (o, p, j) {\n    var l, i;if (Bitcoin.Util.isArray(p)) {\n      var n = this.parseSig(p);l = n.r;i = n.s;\n    } else {\n      if (\"object\" === (typeof p === \"undefined\" ? \"undefined\" : _typeof(p)) && p.r && p.s) {\n        l = p.r;i = p.s;\n      } else {\n        throw \"Invalid value for signature\";\n      }\n    }var k;if (j instanceof ECPointFp) {\n      k = j;\n    } else {\n      if (Bitcoin.Util.isArray(j)) {\n        k = ECPointFp.decodeFrom(this.ecparams.curve, j);\n      } else {\n        throw \"Invalid format for pubkey value, must be byte array or ECPointFp\";\n      }\n    }var m = BigInteger.fromByteArrayUnsigned(o);return this.verifyRaw(m, l, i, k);\n  };this.verifyRaw = function (o, i, w, m) {\n    var l = this.ecparams.n;var u = this.ecparams.G;if (i.compareTo(BigInteger.ONE) < 0 || i.compareTo(l) >= 0) {\n      return false;\n    }if (w.compareTo(BigInteger.ONE) < 0 || w.compareTo(l) >= 0) {\n      return false;\n    }var p = w.modInverse(l);var k = o.multiply(p).mod(l);var j = i.multiply(p).mod(l);var q = u.multiply(k).add(m.multiply(j));var t = q.getX().toBigInteger().mod(l);return t.equals(i);\n  };this.serializeSig = function (k, j) {\n    var l = k.toByteArraySigned();var i = j.toByteArraySigned();var m = [];m.push(2);m.push(l.length);m = m.concat(l);m.push(2);m.push(i.length);m = m.concat(i);m.unshift(m.length);m.unshift(48);return m;\n  };this.parseSig = function (n) {\n    var m;if (n[0] != 48) {\n      throw new Error(\"Signature not a valid DERSequence\");\n    }m = 2;if (n[m] != 2) {\n      throw new Error(\"First element in signature must be a DERInteger\");\n    }var l = n.slice(m + 2, m + 2 + n[m + 1]);m += 2 + n[m + 1];if (n[m] != 2) {\n      throw new Error(\"Second element in signature must be a DERInteger\");\n    }var i = n.slice(m + 2, m + 2 + n[m + 1]);m += 2 + n[m + 1];var k = BigInteger.fromByteArrayUnsigned(l);var j = BigInteger.fromByteArrayUnsigned(i);return { r: k, s: j };\n  };this.parseSigCompact = function (m) {\n    if (m.length !== 65) {\n      throw \"Signature has the wrong length\";\n    }var j = m[0] - 27;if (j < 0 || j > 7) {\n      throw \"Invalid signature type\";\n    }var o = this.ecparams.n;var l = BigInteger.fromByteArrayUnsigned(m.slice(1, 33)).mod(o);var k = BigInteger.fromByteArrayUnsigned(m.slice(33, 65)).mod(o);return { r: l, s: k, i: j };\n  };this.readPKCS5PrvKeyHex = function (l) {\n    var n = ASN1HEX;var m = KJUR.crypto.ECDSA.getName;var p = n.getVbyList;if (n.isASN1HEX(l) === false) {\n      throw \"not ASN.1 hex string\";\n    }var i, k, o;try {\n      i = p(l, 0, [2, 0], \"06\");k = p(l, 0, [1], \"04\");try {\n        o = p(l, 0, [3, 0], \"03\").substr(2);\n      } catch (j) {}\n    } catch (j) {\n      throw \"malformed PKCS#1/5 plain ECC private key\";\n    }this.curveName = m(i);if (this.curveName === undefined) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(o);this.setPrivateKeyHex(k);this.isPublic = false;\n  };this.readPKCS8PrvKeyHex = function (l) {\n    var q = ASN1HEX;var i = KJUR.crypto.ECDSA.getName;var n = q.getVbyList;if (q.isASN1HEX(l) === false) {\n      throw \"not ASN.1 hex string\";\n    }var j, p, m, k;try {\n      j = n(l, 0, [1, 0], \"06\");p = n(l, 0, [1, 1], \"06\");m = n(l, 0, [2, 0, 1], \"04\");try {\n        k = n(l, 0, [2, 0, 2, 0], \"03\").substr(2);\n      } catch (o) {}\n    } catch (o) {\n      throw \"malformed PKCS#8 plain ECC private key\";\n    }this.curveName = i(p);if (this.curveName === undefined) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(k);this.setPrivateKeyHex(m);this.isPublic = false;\n  };this.readPKCS8PubKeyHex = function (l) {\n    var n = ASN1HEX;var m = KJUR.crypto.ECDSA.getName;var p = n.getVbyList;if (n.isASN1HEX(l) === false) {\n      throw \"not ASN.1 hex string\";\n    }var k, i, o;try {\n      k = p(l, 0, [0, 0], \"06\");i = p(l, 0, [0, 1], \"06\");o = p(l, 0, [1], \"03\").substr(2);\n    } catch (j) {\n      throw \"malformed PKCS#8 ECC public key\";\n    }this.curveName = m(i);if (this.curveName === null) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(o);\n  };this.readCertPubKeyHex = function (k, p) {\n    if (p !== 5) {\n      p = 6;\n    }var m = ASN1HEX;var l = KJUR.crypto.ECDSA.getName;var o = m.getVbyList;if (m.isASN1HEX(k) === false) {\n      throw \"not ASN.1 hex string\";\n    }var i, n;try {\n      i = o(k, 0, [0, p, 0, 1], \"06\");n = o(k, 0, [0, p, 1], \"03\").substr(2);\n    } catch (j) {\n      throw \"malformed X.509 certificate ECC public key\";\n    }this.curveName = l(i);if (this.curveName === null) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(n);\n  };if (h !== undefined) {\n    if (h.curve !== undefined) {\n      this.curveName = h.curve;\n    }\n  }if (this.curveName === undefined) {\n    this.curveName = e;\n  }this.setNamedCurve(this.curveName);if (h !== undefined) {\n    if (h.prv !== undefined) {\n      this.setPrivateKeyHex(h.prv);\n    }if (h.pub !== undefined) {\n      this.setPublicKeyHex(h.pub);\n    }\n  }\n};KJUR.crypto.ECDSA.parseSigHex = function (a) {\n  var b = KJUR.crypto.ECDSA.parseSigHexInHexRS(a);var d = new BigInteger(b.r, 16);var c = new BigInteger(b.s, 16);return { r: d, s: c };\n};KJUR.crypto.ECDSA.parseSigHexInHexRS = function (f) {\n  var j = ASN1HEX;var i = j.getChildIdx;var g = j.getV;if (f.substr(0, 2) != \"30\") {\n    throw \"signature is not a ASN.1 sequence\";\n  }var h = i(f, 0);if (h.length != 2) {\n    throw \"number of signature ASN.1 sequence elements seem wrong\";\n  }var e = h[0];var d = h[1];if (f.substr(e, 2) != \"02\") {\n    throw \"1st item of sequene of signature is not ASN.1 integer\";\n  }if (f.substr(d, 2) != \"02\") {\n    throw \"2nd item of sequene of signature is not ASN.1 integer\";\n  }var c = g(f, e);var b = g(f, d);return { r: c, s: b };\n};KJUR.crypto.ECDSA.asn1SigToConcatSig = function (c) {\n  var d = KJUR.crypto.ECDSA.parseSigHexInHexRS(c);var b = d.r;var a = d.s;if (b.substr(0, 2) == \"00\" && b.length % 32 == 2) {\n    b = b.substr(2);\n  }if (a.substr(0, 2) == \"00\" && a.length % 32 == 2) {\n    a = a.substr(2);\n  }if (b.length % 32 == 30) {\n    b = \"00\" + b;\n  }if (a.length % 32 == 30) {\n    a = \"00\" + a;\n  }if (b.length % 32 != 0) {\n    throw \"unknown ECDSA sig r length error\";\n  }if (a.length % 32 != 0) {\n    throw \"unknown ECDSA sig s length error\";\n  }return b + a;\n};KJUR.crypto.ECDSA.concatSigToASN1Sig = function (a) {\n  if (a.length / 2 * 8 % (16 * 8) != 0) {\n    throw \"unknown ECDSA concatinated r-s sig  length error\";\n  }var c = a.substr(0, a.length / 2);var b = a.substr(a.length / 2);return KJUR.crypto.ECDSA.hexRSSigToASN1Sig(c, b);\n};KJUR.crypto.ECDSA.hexRSSigToASN1Sig = function (b, a) {\n  var d = new BigInteger(b, 16);var c = new BigInteger(a, 16);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(d, c);\n};KJUR.crypto.ECDSA.biRSSigToASN1Sig = function (f, d) {\n  var c = KJUR.asn1;var b = new c.DERInteger({ bigint: f });var a = new c.DERInteger({ bigint: d });var e = new c.DERSequence({ array: [b, a] });return e.getEncodedHex();\n};KJUR.crypto.ECDSA.getName = function (a) {\n  if (a === \"2a8648ce3d030107\") {\n    return \"secp256r1\";\n  }if (a === \"2b8104000a\") {\n    return \"secp256k1\";\n  }if (a === \"2b81040022\") {\n    return \"secp384r1\";\n  }if (\"|secp256r1|NIST P-256|P-256|prime256v1|\".indexOf(a) !== -1) {\n    return \"secp256r1\";\n  }if (\"|secp256k1|\".indexOf(a) !== -1) {\n    return \"secp256k1\";\n  }if (\"|secp384r1|NIST P-384|P-384|\".indexOf(a) !== -1) {\n    return \"secp384r1\";\n  }return null;\n};\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.crypto == \"undefined\" || !KJUR.crypto) {\n  KJUR.crypto = {};\n}KJUR.crypto.ECParameterDB = new function () {\n  var b = {};var c = {};function a(d) {\n    return new BigInteger(d, 16);\n  }this.getByName = function (e) {\n    var d = e;if (typeof c[d] != \"undefined\") {\n      d = c[e];\n    }if (typeof b[d] != \"undefined\") {\n      return b[d];\n    }throw \"unregistered EC curve name: \" + d;\n  };this.regist = function (A, l, o, g, m, e, j, f, k, u, d, x) {\n    b[A] = {};var s = a(o);var z = a(g);var y = a(m);var t = a(e);var w = a(j);var r = new ECCurveFp(s, z, y);var q = r.decodePointHex(\"04\" + f + k);b[A][\"name\"] = A;b[A][\"keylen\"] = l;b[A][\"curve\"] = r;b[A][\"G\"] = q;b[A][\"n\"] = t;b[A][\"h\"] = w;b[A][\"oid\"] = d;b[A][\"info\"] = x;for (var v = 0; v < u.length; v++) {\n      c[u[v]] = A;\n    }\n  };\n}();KJUR.crypto.ECParameterDB.regist(\"secp128r1\", 128, \"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF\", \"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFC\", \"E87579C11079F43DD824993C2CEE5ED3\", \"FFFFFFFE0000000075A30D1B9038A115\", \"1\", \"161FF7528B899B2D0C28607CA52C5B86\", \"CF5AC8395BAFEB13C02DA292DDED7A83\", [], \"\", \"secp128r1 : SECG curve over a 128 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160k1\", 160, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73\", \"0\", \"7\", \"0100000000000000000001B8FA16DFAB9ACA16B6B3\", \"1\", \"3B4C382CE37AA192A4019E763036F4F5DD4D7EBB\", \"938CF935318FDCED6BC28286531733C3F03C4FEE\", [], \"\", \"secp160k1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160r1\", 160, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFC\", \"1C97BEFC54BD7A8B65ACF89F81D4D4ADC565FA45\", \"0100000000000000000001F4C8F927AED3CA752257\", \"1\", \"4A96B5688EF573284664698968C38BB913CBFC82\", \"23A628553168947D59DCC912042351377AC5FB32\", [], \"\", \"secp160r1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp192k1\", 192, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFEE37\", \"0\", \"3\", \"FFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D\", \"1\", \"DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D\", \"9B2F2F6D9C5628A7844163D015BE86344082AA88D95E2F9D\", []);KJUR.crypto.ECParameterDB.regist(\"secp192r1\", 192, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC\", \"64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1\", \"FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831\", \"1\", \"188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012\", \"07192B95FFC8DA78631011ED6B24CDD573F977A11E794811\", []);KJUR.crypto.ECParameterDB.regist(\"secp224r1\", 224, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE\", \"B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D\", \"1\", \"B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21\", \"BD376388B5F723FB4C22DFE6CD4375A05A07476444D5819985007E34\", []);KJUR.crypto.ECParameterDB.regist(\"secp256k1\", 256, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F\", \"0\", \"7\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141\", \"1\", \"79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798\", \"483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8\", []);KJUR.crypto.ECParameterDB.regist(\"secp256r1\", 256, \"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF\", \"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFC\", \"5AC635D8AA3A93E7B3EBBD55769886BC651D06B0CC53B0F63BCE3C3E27D2604B\", \"FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551\", \"1\", \"6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296\", \"4FE342E2FE1A7F9B8EE7EB4A7C0F9E162BCE33576B315ECECBB6406837BF51F5\", [\"NIST P-256\", \"P-256\", \"prime256v1\"]);KJUR.crypto.ECParameterDB.regist(\"secp384r1\", 384, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFC\", \"B3312FA7E23EE7E4988E056BE3F82D19181D9C6EFE8141120314088F5013875AC656398D8A2ED19D2A85C8EDD3EC2AEF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973\", \"1\", \"AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7\", \"3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5f\", [\"NIST P-384\", \"P-384\"]);KJUR.crypto.ECParameterDB.regist(\"secp521r1\", 521, \"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF\", \"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC\", \"051953EB9618E1C9A1F929A21A0B68540EEA2DA725B99B315F3B8B489918EF109E156193951EC7E937B1652C0BD3BB1BF073573DF883D2C34F1EF451FD46B503F00\", \"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA51868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409\", \"1\", \"C6858E06B70404E9CD9E3ECB662395B4429C648139053FB521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66\", \"011839296a789a3bc0045c8a5fb42c7d1bd998f54449579b446817afbd17273e662c97ee72995ef42640c550b9013fad0761353c7086a272c24088be94769fd16650\", [\"NIST P-521\", \"P-521\"]);\nvar KEYUTIL = function () {\n  var d = function d(p, r, q) {\n    return k(CryptoJS.AES, p, r, q);\n  };var e = function e(p, r, q) {\n    return k(CryptoJS.TripleDES, p, r, q);\n  };var a = function a(p, r, q) {\n    return k(CryptoJS.DES, p, r, q);\n  };var k = function k(s, x, u, q) {\n    var r = CryptoJS.enc.Hex.parse(x);var w = CryptoJS.enc.Hex.parse(u);var p = CryptoJS.enc.Hex.parse(q);var t = {};t.key = w;t.iv = p;t.ciphertext = r;var v = s.decrypt(t, w, { iv: p });return CryptoJS.enc.Hex.stringify(v);\n  };var l = function l(p, r, q) {\n    return g(CryptoJS.AES, p, r, q);\n  };var o = function o(p, r, q) {\n    return g(CryptoJS.TripleDES, p, r, q);\n  };var f = function f(p, r, q) {\n    return g(CryptoJS.DES, p, r, q);\n  };var g = function g(t, y, v, q) {\n    var s = CryptoJS.enc.Hex.parse(y);var x = CryptoJS.enc.Hex.parse(v);var p = CryptoJS.enc.Hex.parse(q);var w = t.encrypt(s, x, { iv: p });var r = CryptoJS.enc.Hex.parse(w.toString());var u = CryptoJS.enc.Base64.stringify(r);return u;\n  };var i = { \"AES-256-CBC\": { proc: d, eproc: l, keylen: 32, ivlen: 16 }, \"AES-192-CBC\": { proc: d, eproc: l, keylen: 24, ivlen: 16 }, \"AES-128-CBC\": { proc: d, eproc: l, keylen: 16, ivlen: 16 }, \"DES-EDE3-CBC\": { proc: e, eproc: o, keylen: 24, ivlen: 8 }, \"DES-CBC\": { proc: a, eproc: f, keylen: 8, ivlen: 8 } };var c = function c(p) {\n    return i[p][\"proc\"];\n  };var m = function m(p) {\n    var r = CryptoJS.lib.WordArray.random(p);var q = CryptoJS.enc.Hex.stringify(r);return q;\n  };var n = function n(v) {\n    var w = {};var q = v.match(new RegExp(\"DEK-Info: ([^,]+),([0-9A-Fa-f]+)\", \"m\"));if (q) {\n      w.cipher = q[1];w.ivsalt = q[2];\n    }var p = v.match(new RegExp(\"-----BEGIN ([A-Z]+) PRIVATE KEY-----\"));if (p) {\n      w.type = p[1];\n    }var u = -1;var x = 0;if (v.indexOf(\"\\r\\n\\r\\n\") != -1) {\n      u = v.indexOf(\"\\r\\n\\r\\n\");x = 2;\n    }if (v.indexOf(\"\\n\\n\") != -1) {\n      u = v.indexOf(\"\\n\\n\");x = 1;\n    }var t = v.indexOf(\"-----END\");if (u != -1 && t != -1) {\n      var r = v.substring(u + x * 2, t - x);r = r.replace(/\\s+/g, \"\");w.data = r;\n    }return w;\n  };var j = function j(q, y, p) {\n    var v = p.substring(0, 16);var t = CryptoJS.enc.Hex.parse(v);var r = CryptoJS.enc.Utf8.parse(y);var u = i[q][\"keylen\"] + i[q][\"ivlen\"];var x = \"\";var w = null;for (;;) {\n      var s = CryptoJS.algo.MD5.create();if (w != null) {\n        s.update(w);\n      }s.update(r);s.update(t);w = s.finalize();x = x + CryptoJS.enc.Hex.stringify(w);if (x.length >= u * 2) {\n        break;\n      }\n    }var z = {};z.keyhex = x.substr(0, i[q][\"keylen\"] * 2);z.ivhex = x.substr(i[q][\"keylen\"] * 2, i[q][\"ivlen\"] * 2);return z;\n  };var b = function b(p, v, r, w) {\n    var s = CryptoJS.enc.Base64.parse(p);var q = CryptoJS.enc.Hex.stringify(s);var u = i[v][\"proc\"];var t = u(q, r, w);return t;\n  };var h = function h(p, s, q, u) {\n    var r = i[s][\"eproc\"];var t = r(p, q, u);return t;\n  };return { version: \"1.0.0\", parsePKCS5PEM: function parsePKCS5PEM(p) {\n      return n(p);\n    }, getKeyAndUnusedIvByPasscodeAndIvsalt: function getKeyAndUnusedIvByPasscodeAndIvsalt(q, p, r) {\n      return j(q, p, r);\n    }, decryptKeyB64: function decryptKeyB64(p, r, q, s) {\n      return b(p, r, q, s);\n    }, getDecryptedKeyHex: function getDecryptedKeyHex(y, x) {\n      var q = n(y);var t = q.type;var r = q.cipher;var p = q.ivsalt;var s = q.data;var w = j(r, x, p);var v = w.keyhex;var u = b(s, r, v, p);return u;\n    }, getEncryptedPKCS5PEMFromPrvKeyHex: function getEncryptedPKCS5PEMFromPrvKeyHex(x, s, A, t, r) {\n      var p = \"\";if (typeof t == \"undefined\" || t == null) {\n        t = \"AES-256-CBC\";\n      }if (typeof i[t] == \"undefined\") {\n        throw \"KEYUTIL unsupported algorithm: \" + t;\n      }if (typeof r == \"undefined\" || r == null) {\n        var v = i[t][\"ivlen\"];var u = m(v);r = u.toUpperCase();\n      }var z = j(t, A, r);var y = z.keyhex;var w = h(s, t, y, r);var q = w.replace(/(.{64})/g, \"$1\\r\\n\");var p = \"-----BEGIN \" + x + \" PRIVATE KEY-----\\r\\n\";p += \"Proc-Type: 4,ENCRYPTED\\r\\n\";p += \"DEK-Info: \" + t + \",\" + r + \"\\r\\n\";p += \"\\r\\n\";p += q;p += \"\\r\\n-----END \" + x + \" PRIVATE KEY-----\\r\\n\";return p;\n    }, parseHexOfEncryptedPKCS8: function parseHexOfEncryptedPKCS8(y) {\n      var B = ASN1HEX;var z = B.getChildIdx;var w = B.getV;var t = {};var r = z(y, 0);if (r.length != 2) {\n        throw \"malformed format: SEQUENCE(0).items != 2: \" + r.length;\n      }t.ciphertext = w(y, r[1]);var A = z(y, r[0]);if (A.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0).items != 2: \" + A.length;\n      }if (w(y, A[0]) != \"2a864886f70d01050d\") {\n        throw \"this only supports pkcs5PBES2\";\n      }var p = z(y, A[1]);if (A.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0.1).items != 2: \" + p.length;\n      }var q = z(y, p[1]);if (q.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0.1.1).items != 2: \" + q.length;\n      }if (w(y, q[0]) != \"2a864886f70d0307\") {\n        throw \"this only supports TripleDES\";\n      }t.encryptionSchemeAlg = \"TripleDES\";t.encryptionSchemeIV = w(y, q[1]);var s = z(y, p[0]);if (s.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0.1.0).items != 2: \" + s.length;\n      }if (w(y, s[0]) != \"2a864886f70d01050c\") {\n        throw \"this only supports pkcs5PBKDF2\";\n      }var x = z(y, s[1]);if (x.length < 2) {\n        throw \"malformed format: SEQUENCE(0.0.1.0.1).items < 2: \" + x.length;\n      }t.pbkdf2Salt = w(y, x[0]);var u = w(y, x[1]);try {\n        t.pbkdf2Iter = parseInt(u, 16);\n      } catch (v) {\n        throw \"malformed format pbkdf2Iter: \" + u;\n      }return t;\n    }, getPBKDF2KeyHexFromParam: function getPBKDF2KeyHexFromParam(u, p) {\n      var t = CryptoJS.enc.Hex.parse(u.pbkdf2Salt);var q = u.pbkdf2Iter;var s = CryptoJS.PBKDF2(p, t, { keySize: 192 / 32, iterations: q });var r = CryptoJS.enc.Hex.stringify(s);return r;\n    }, _getPlainPKCS8HexFromEncryptedPKCS8PEM: function _getPlainPKCS8HexFromEncryptedPKCS8PEM(x, y) {\n      var r = pemtohex(x, \"ENCRYPTED PRIVATE KEY\");var p = this.parseHexOfEncryptedPKCS8(r);var u = KEYUTIL.getPBKDF2KeyHexFromParam(p, y);var v = {};v.ciphertext = CryptoJS.enc.Hex.parse(p.ciphertext);var t = CryptoJS.enc.Hex.parse(u);var s = CryptoJS.enc.Hex.parse(p.encryptionSchemeIV);var w = CryptoJS.TripleDES.decrypt(v, t, { iv: s });var q = CryptoJS.enc.Hex.stringify(w);return q;\n    }, getKeyFromEncryptedPKCS8PEM: function getKeyFromEncryptedPKCS8PEM(s, q) {\n      var p = this._getPlainPKCS8HexFromEncryptedPKCS8PEM(s, q);var r = this.getKeyFromPlainPrivatePKCS8Hex(p);return r;\n    }, parsePlainPrivatePKCS8Hex: function parsePlainPrivatePKCS8Hex(s) {\n      var v = ASN1HEX;var u = v.getChildIdx;var t = v.getV;var q = {};q.algparam = null;if (s.substr(0, 2) != \"30\") {\n        throw \"malformed plain PKCS8 private key(code:001)\";\n      }var r = u(s, 0);if (r.length != 3) {\n        throw \"malformed plain PKCS8 private key(code:002)\";\n      }if (s.substr(r[1], 2) != \"30\") {\n        throw \"malformed PKCS8 private key(code:003)\";\n      }var p = u(s, r[1]);if (p.length != 2) {\n        throw \"malformed PKCS8 private key(code:004)\";\n      }if (s.substr(p[0], 2) != \"06\") {\n        throw \"malformed PKCS8 private key(code:005)\";\n      }q.algoid = t(s, p[0]);if (s.substr(p[1], 2) == \"06\") {\n        q.algparam = t(s, p[1]);\n      }if (s.substr(r[2], 2) != \"04\") {\n        throw \"malformed PKCS8 private key(code:006)\";\n      }q.keyidx = v.getVidx(s, r[2]);return q;\n    }, getKeyFromPlainPrivatePKCS8PEM: function getKeyFromPlainPrivatePKCS8PEM(q) {\n      var p = pemtohex(q, \"PRIVATE KEY\");var r = this.getKeyFromPlainPrivatePKCS8Hex(p);return r;\n    }, getKeyFromPlainPrivatePKCS8Hex: function getKeyFromPlainPrivatePKCS8Hex(p) {\n      var q = this.parsePlainPrivatePKCS8Hex(p);var r;if (q.algoid == \"2a864886f70d010101\") {\n        r = new RSAKey();\n      } else {\n        if (q.algoid == \"2a8648ce380401\") {\n          r = new KJUR.crypto.DSA();\n        } else {\n          if (q.algoid == \"2a8648ce3d0201\") {\n            r = new KJUR.crypto.ECDSA();\n          } else {\n            throw \"unsupported private key algorithm\";\n          }\n        }\n      }r.readPKCS8PrvKeyHex(p);return r;\n    }, _getKeyFromPublicPKCS8Hex: function _getKeyFromPublicPKCS8Hex(q) {\n      var p;var r = ASN1HEX.getVbyList(q, 0, [0, 0], \"06\");if (r === \"2a864886f70d010101\") {\n        p = new RSAKey();\n      } else {\n        if (r === \"2a8648ce380401\") {\n          p = new KJUR.crypto.DSA();\n        } else {\n          if (r === \"2a8648ce3d0201\") {\n            p = new KJUR.crypto.ECDSA();\n          } else {\n            throw \"unsupported PKCS#8 public key hex\";\n          }\n        }\n      }p.readPKCS8PubKeyHex(q);return p;\n    }, parsePublicRawRSAKeyHex: function parsePublicRawRSAKeyHex(r) {\n      var u = ASN1HEX;var t = u.getChildIdx;var s = u.getV;var p = {};if (r.substr(0, 2) != \"30\") {\n        throw \"malformed RSA key(code:001)\";\n      }var q = t(r, 0);if (q.length != 2) {\n        throw \"malformed RSA key(code:002)\";\n      }if (r.substr(q[0], 2) != \"02\") {\n        throw \"malformed RSA key(code:003)\";\n      }p.n = s(r, q[0]);if (r.substr(q[1], 2) != \"02\") {\n        throw \"malformed RSA key(code:004)\";\n      }p.e = s(r, q[1]);return p;\n    }, parsePublicPKCS8Hex: function parsePublicPKCS8Hex(t) {\n      var v = ASN1HEX;var u = v.getChildIdx;var s = v.getV;var q = {};q.algparam = null;var r = u(t, 0);if (r.length != 2) {\n        throw \"outer DERSequence shall have 2 elements: \" + r.length;\n      }var w = r[0];if (t.substr(w, 2) != \"30\") {\n        throw \"malformed PKCS8 public key(code:001)\";\n      }var p = u(t, w);if (p.length != 2) {\n        throw \"malformed PKCS8 public key(code:002)\";\n      }if (t.substr(p[0], 2) != \"06\") {\n        throw \"malformed PKCS8 public key(code:003)\";\n      }q.algoid = s(t, p[0]);if (t.substr(p[1], 2) == \"06\") {\n        q.algparam = s(t, p[1]);\n      } else {\n        if (t.substr(p[1], 2) == \"30\") {\n          q.algparam = {};q.algparam.p = v.getVbyList(t, p[1], [0], \"02\");q.algparam.q = v.getVbyList(t, p[1], [1], \"02\");q.algparam.g = v.getVbyList(t, p[1], [2], \"02\");\n        }\n      }if (t.substr(r[1], 2) != \"03\") {\n        throw \"malformed PKCS8 public key(code:004)\";\n      }q.key = s(t, r[1]).substr(2);return q;\n    } };\n}();KEYUTIL.getKey = function (l, k, n) {\n  var G = ASN1HEX,\n      L = G.getChildIdx,\n      v = G.getV,\n      d = G.getVbyList,\n      c = KJUR.crypto,\n      i = c.ECDSA,\n      C = c.DSA,\n      w = RSAKey,\n      M = pemtohex,\n      F = KEYUTIL;if (typeof w != \"undefined\" && l instanceof w) {\n    return l;\n  }if (typeof i != \"undefined\" && l instanceof i) {\n    return l;\n  }if (typeof C != \"undefined\" && l instanceof C) {\n    return l;\n  }if (l.curve !== undefined && l.xy !== undefined && l.d === undefined) {\n    return new i({ pub: l.xy, curve: l.curve });\n  }if (l.curve !== undefined && l.d !== undefined) {\n    return new i({ prv: l.d, curve: l.curve });\n  }if (l.kty === undefined && l.n !== undefined && l.e !== undefined && l.d === undefined) {\n    var P = new w();P.setPublic(l.n, l.e);return P;\n  }if (l.kty === undefined && l.n !== undefined && l.e !== undefined && l.d !== undefined && l.p !== undefined && l.q !== undefined && l.dp !== undefined && l.dq !== undefined && l.co !== undefined && l.qi === undefined) {\n    var P = new w();P.setPrivateEx(l.n, l.e, l.d, l.p, l.q, l.dp, l.dq, l.co);return P;\n  }if (l.kty === undefined && l.n !== undefined && l.e !== undefined && l.d !== undefined && l.p === undefined) {\n    var P = new w();P.setPrivate(l.n, l.e, l.d);return P;\n  }if (l.p !== undefined && l.q !== undefined && l.g !== undefined && l.y !== undefined && l.x === undefined) {\n    var P = new C();P.setPublic(l.p, l.q, l.g, l.y);return P;\n  }if (l.p !== undefined && l.q !== undefined && l.g !== undefined && l.y !== undefined && l.x !== undefined) {\n    var P = new C();P.setPrivate(l.p, l.q, l.g, l.y, l.x);return P;\n  }if (l.kty === \"RSA\" && l.n !== undefined && l.e !== undefined && l.d === undefined) {\n    var P = new w();P.setPublic(b64utohex(l.n), b64utohex(l.e));return P;\n  }if (l.kty === \"RSA\" && l.n !== undefined && l.e !== undefined && l.d !== undefined && l.p !== undefined && l.q !== undefined && l.dp !== undefined && l.dq !== undefined && l.qi !== undefined) {\n    var P = new w();P.setPrivateEx(b64utohex(l.n), b64utohex(l.e), b64utohex(l.d), b64utohex(l.p), b64utohex(l.q), b64utohex(l.dp), b64utohex(l.dq), b64utohex(l.qi));return P;\n  }if (l.kty === \"RSA\" && l.n !== undefined && l.e !== undefined && l.d !== undefined) {\n    var P = new w();P.setPrivate(b64utohex(l.n), b64utohex(l.e), b64utohex(l.d));return P;\n  }if (l.kty === \"EC\" && l.crv !== undefined && l.x !== undefined && l.y !== undefined && l.d === undefined) {\n    var j = new i({ curve: l.crv });var t = j.ecparams.keylen / 4;var B = (\"0000000000\" + b64utohex(l.x)).slice(-t);var z = (\"0000000000\" + b64utohex(l.y)).slice(-t);var u = \"04\" + B + z;j.setPublicKeyHex(u);return j;\n  }if (l.kty === \"EC\" && l.crv !== undefined && l.x !== undefined && l.y !== undefined && l.d !== undefined) {\n    var j = new i({ curve: l.crv });var t = j.ecparams.keylen / 4;var B = (\"0000000000\" + b64utohex(l.x)).slice(-t);var z = (\"0000000000\" + b64utohex(l.y)).slice(-t);var u = \"04\" + B + z;var b = (\"0000000000\" + b64utohex(l.d)).slice(-t);j.setPublicKeyHex(u);j.setPrivateKeyHex(b);return j;\n  }if (n === \"pkcs5prv\") {\n    var J = l,\n        G = ASN1HEX,\n        N,\n        P;N = L(J, 0);if (N.length === 9) {\n      P = new w();P.readPKCS5PrvKeyHex(J);\n    } else {\n      if (N.length === 6) {\n        P = new C();P.readPKCS5PrvKeyHex(J);\n      } else {\n        if (N.length > 2 && J.substr(N[1], 2) === \"04\") {\n          P = new i();P.readPKCS5PrvKeyHex(J);\n        } else {\n          throw \"unsupported PKCS#1/5 hexadecimal key\";\n        }\n      }\n    }return P;\n  }if (n === \"pkcs8prv\") {\n    var P = F.getKeyFromPlainPrivatePKCS8Hex(l);return P;\n  }if (n === \"pkcs8pub\") {\n    return F._getKeyFromPublicPKCS8Hex(l);\n  }if (n === \"x509pub\") {\n    return X509.getPublicKeyFromCertHex(l);\n  }if (l.indexOf(\"-END CERTIFICATE-\", 0) != -1 || l.indexOf(\"-END X509 CERTIFICATE-\", 0) != -1 || l.indexOf(\"-END TRUSTED CERTIFICATE-\", 0) != -1) {\n    return X509.getPublicKeyFromCertPEM(l);\n  }if (l.indexOf(\"-END PUBLIC KEY-\") != -1) {\n    var O = pemtohex(l, \"PUBLIC KEY\");return F._getKeyFromPublicPKCS8Hex(O);\n  }if (l.indexOf(\"-END RSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") == -1) {\n    var m = M(l, \"RSA PRIVATE KEY\");return F.getKey(m, null, \"pkcs5prv\");\n  }if (l.indexOf(\"-END DSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") == -1) {\n    var I = M(l, \"DSA PRIVATE KEY\");var E = d(I, 0, [1], \"02\");var D = d(I, 0, [2], \"02\");var K = d(I, 0, [3], \"02\");var r = d(I, 0, [4], \"02\");var s = d(I, 0, [5], \"02\");var P = new C();P.setPrivate(new BigInteger(E, 16), new BigInteger(D, 16), new BigInteger(K, 16), new BigInteger(r, 16), new BigInteger(s, 16));return P;\n  }if (l.indexOf(\"-END PRIVATE KEY-\") != -1) {\n    return F.getKeyFromPlainPrivatePKCS8PEM(l);\n  }if (l.indexOf(\"-END RSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") != -1) {\n    var o = F.getDecryptedKeyHex(l, k);var H = new RSAKey();H.readPKCS5PrvKeyHex(o);return H;\n  }if (l.indexOf(\"-END EC PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") != -1) {\n    var I = F.getDecryptedKeyHex(l, k);var P = d(I, 0, [1], \"04\");var f = d(I, 0, [2, 0], \"06\");var A = d(I, 0, [3, 0], \"03\").substr(2);var e = \"\";if (KJUR.crypto.OID.oidhex2name[f] !== undefined) {\n      e = KJUR.crypto.OID.oidhex2name[f];\n    } else {\n      throw \"undefined OID(hex) in KJUR.crypto.OID: \" + f;\n    }var j = new i({ curve: e });j.setPublicKeyHex(A);j.setPrivateKeyHex(P);j.isPublic = false;return j;\n  }if (l.indexOf(\"-END DSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") != -1) {\n    var I = F.getDecryptedKeyHex(l, k);var E = d(I, 0, [1], \"02\");var D = d(I, 0, [2], \"02\");var K = d(I, 0, [3], \"02\");var r = d(I, 0, [4], \"02\");var s = d(I, 0, [5], \"02\");var P = new C();P.setPrivate(new BigInteger(E, 16), new BigInteger(D, 16), new BigInteger(K, 16), new BigInteger(r, 16), new BigInteger(s, 16));return P;\n  }if (l.indexOf(\"-END ENCRYPTED PRIVATE KEY-\") != -1) {\n    return F.getKeyFromEncryptedPKCS8PEM(l, k);\n  }throw \"not supported argument\";\n};KEYUTIL.generateKeypair = function (a, c) {\n  if (a == \"RSA\") {\n    var b = c;var h = new RSAKey();h.generate(b, \"10001\");h.isPrivate = true;h.isPublic = true;var f = new RSAKey();var e = h.n.toString(16);var i = h.e.toString(16);f.setPublic(e, i);f.isPrivate = false;f.isPublic = true;var k = {};k.prvKeyObj = h;k.pubKeyObj = f;return k;\n  } else {\n    if (a == \"EC\") {\n      var d = c;var g = new KJUR.crypto.ECDSA({ curve: d });var j = g.generateKeyPairHex();var h = new KJUR.crypto.ECDSA({ curve: d });h.setPublicKeyHex(j.ecpubhex);h.setPrivateKeyHex(j.ecprvhex);h.isPrivate = true;h.isPublic = false;var f = new KJUR.crypto.ECDSA({ curve: d });f.setPublicKeyHex(j.ecpubhex);f.isPrivate = false;f.isPublic = true;var k = {};k.prvKeyObj = h;k.pubKeyObj = f;return k;\n    } else {\n      throw \"unknown algorithm: \" + a;\n    }\n  }\n};KEYUTIL.getPEM = function (b, D, y, m, q, j) {\n  var F = KJUR,\n      k = F.asn1,\n      z = k.DERObjectIdentifier,\n      f = k.DERInteger,\n      l = k.ASN1Util.newObject,\n      a = k.x509,\n      C = a.SubjectPublicKeyInfo,\n      e = F.crypto,\n      u = e.DSA,\n      r = e.ECDSA,\n      n = RSAKey;function A(s) {\n    var G = l({ seq: [{ \"int\": 0 }, { \"int\": { bigint: s.n } }, { \"int\": s.e }, { \"int\": { bigint: s.d } }, { \"int\": { bigint: s.p } }, { \"int\": { bigint: s.q } }, { \"int\": { bigint: s.dmp1 } }, { \"int\": { bigint: s.dmq1 } }, { \"int\": { bigint: s.coeff } }] });return G;\n  }function B(G) {\n    var s = l({ seq: [{ \"int\": 1 }, { octstr: { hex: G.prvKeyHex } }, { tag: [\"a0\", true, { oid: { name: G.curveName } }] }, { tag: [\"a1\", true, { bitstr: { hex: \"00\" + G.pubKeyHex } }] }] });return s;\n  }function x(s) {\n    var G = l({ seq: [{ \"int\": 0 }, { \"int\": { bigint: s.p } }, { \"int\": { bigint: s.q } }, { \"int\": { bigint: s.g } }, { \"int\": { bigint: s.y } }, { \"int\": { bigint: s.x } }] });return G;\n  }if ((n !== undefined && b instanceof n || u !== undefined && b instanceof u || r !== undefined && b instanceof r) && b.isPublic == true && (D === undefined || D == \"PKCS8PUB\")) {\n    var E = new C(b);var w = E.getEncodedHex();return hextopem(w, \"PUBLIC KEY\");\n  }if (D == \"PKCS1PRV\" && n !== undefined && b instanceof n && (y === undefined || y == null) && b.isPrivate == true) {\n    var E = A(b);var w = E.getEncodedHex();return hextopem(w, \"RSA PRIVATE KEY\");\n  }if (D == \"PKCS1PRV\" && r !== undefined && b instanceof r && (y === undefined || y == null) && b.isPrivate == true) {\n    var i = new z({ name: b.curveName });var v = i.getEncodedHex();var h = B(b);var t = h.getEncodedHex();var p = \"\";p += hextopem(v, \"EC PARAMETERS\");p += hextopem(t, \"EC PRIVATE KEY\");return p;\n  }if (D == \"PKCS1PRV\" && u !== undefined && b instanceof u && (y === undefined || y == null) && b.isPrivate == true) {\n    var E = x(b);var w = E.getEncodedHex();return hextopem(w, \"DSA PRIVATE KEY\");\n  }if (D == \"PKCS5PRV\" && n !== undefined && b instanceof n && y !== undefined && y != null && b.isPrivate == true) {\n    var E = A(b);var w = E.getEncodedHex();if (m === undefined) {\n      m = \"DES-EDE3-CBC\";\n    }return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"RSA\", w, y, m, j);\n  }if (D == \"PKCS5PRV\" && r !== undefined && b instanceof r && y !== undefined && y != null && b.isPrivate == true) {\n    var E = B(b);var w = E.getEncodedHex();if (m === undefined) {\n      m = \"DES-EDE3-CBC\";\n    }return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"EC\", w, y, m, j);\n  }if (D == \"PKCS5PRV\" && u !== undefined && b instanceof u && y !== undefined && y != null && b.isPrivate == true) {\n    var E = x(b);var w = E.getEncodedHex();if (m === undefined) {\n      m = \"DES-EDE3-CBC\";\n    }return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"DSA\", w, y, m, j);\n  }var o = function o(G, s) {\n    var I = c(G, s);var H = new l({ seq: [{ seq: [{ oid: { name: \"pkcs5PBES2\" } }, { seq: [{ seq: [{ oid: { name: \"pkcs5PBKDF2\" } }, { seq: [{ octstr: { hex: I.pbkdf2Salt } }, { \"int\": I.pbkdf2Iter }] }] }, { seq: [{ oid: { name: \"des-EDE3-CBC\" } }, { octstr: { hex: I.encryptionSchemeIV } }] }] }] }, { octstr: { hex: I.ciphertext } }] });return H.getEncodedHex();\n  };var c = function c(N, O) {\n    var H = 100;var M = CryptoJS.lib.WordArray.random(8);var L = \"DES-EDE3-CBC\";var s = CryptoJS.lib.WordArray.random(8);var I = CryptoJS.PBKDF2(O, M, { keySize: 192 / 32, iterations: H });var J = CryptoJS.enc.Hex.parse(N);var K = CryptoJS.TripleDES.encrypt(J, I, { iv: s }) + \"\";var G = {};G.ciphertext = K;G.pbkdf2Salt = CryptoJS.enc.Hex.stringify(M);G.pbkdf2Iter = H;G.encryptionSchemeAlg = L;G.encryptionSchemeIV = CryptoJS.enc.Hex.stringify(s);return G;\n  };if (D == \"PKCS8PRV\" && n != undefined && b instanceof n && b.isPrivate == true) {\n    var g = A(b);var d = g.getEncodedHex();var E = l({ seq: [{ \"int\": 0 }, { seq: [{ oid: { name: \"rsaEncryption\" } }, { \"null\": true }] }, { octstr: { hex: d } }] });var w = E.getEncodedHex();if (y === undefined || y == null) {\n      return hextopem(w, \"PRIVATE KEY\");\n    } else {\n      var t = o(w, y);return hextopem(t, \"ENCRYPTED PRIVATE KEY\");\n    }\n  }if (D == \"PKCS8PRV\" && r !== undefined && b instanceof r && b.isPrivate == true) {\n    var g = new l({ seq: [{ \"int\": 1 }, { octstr: { hex: b.prvKeyHex } }, { tag: [\"a1\", true, { bitstr: { hex: \"00\" + b.pubKeyHex } }] }] });var d = g.getEncodedHex();var E = l({ seq: [{ \"int\": 0 }, { seq: [{ oid: { name: \"ecPublicKey\" } }, { oid: { name: b.curveName } }] }, { octstr: { hex: d } }] });var w = E.getEncodedHex();if (y === undefined || y == null) {\n      return hextopem(w, \"PRIVATE KEY\");\n    } else {\n      var t = o(w, y);return hextopem(t, \"ENCRYPTED PRIVATE KEY\");\n    }\n  }if (D == \"PKCS8PRV\" && u !== undefined && b instanceof u && b.isPrivate == true) {\n    var g = new f({ bigint: b.x });var d = g.getEncodedHex();var E = l({ seq: [{ \"int\": 0 }, { seq: [{ oid: { name: \"dsa\" } }, { seq: [{ \"int\": { bigint: b.p } }, { \"int\": { bigint: b.q } }, { \"int\": { bigint: b.g } }] }] }, { octstr: { hex: d } }] });var w = E.getEncodedHex();if (y === undefined || y == null) {\n      return hextopem(w, \"PRIVATE KEY\");\n    } else {\n      var t = o(w, y);return hextopem(t, \"ENCRYPTED PRIVATE KEY\");\n    }\n  }throw \"unsupported object nor format\";\n};KEYUTIL.getKeyFromCSRPEM = function (b) {\n  var a = pemtohex(b, \"CERTIFICATE REQUEST\");var c = KEYUTIL.getKeyFromCSRHex(a);return c;\n};KEYUTIL.getKeyFromCSRHex = function (a) {\n  var c = KEYUTIL.parseCSRHex(a);var b = KEYUTIL.getKey(c.p8pubkeyhex, null, \"pkcs8pub\");return b;\n};KEYUTIL.parseCSRHex = function (d) {\n  var i = ASN1HEX;var f = i.getChildIdx;var c = i.getTLV;var b = {};var g = d;if (g.substr(0, 2) != \"30\") {\n    throw \"malformed CSR(code:001)\";\n  }var e = f(g, 0);if (e.length < 1) {\n    throw \"malformed CSR(code:002)\";\n  }if (g.substr(e[0], 2) != \"30\") {\n    throw \"malformed CSR(code:003)\";\n  }var a = f(g, e[0]);if (a.length < 3) {\n    throw \"malformed CSR(code:004)\";\n  }b.p8pubkeyhex = c(g, a[2]);return b;\n};KEYUTIL.getJWKFromKey = function (d) {\n  var b = {};if (d instanceof RSAKey && d.isPrivate) {\n    b.kty = \"RSA\";b.n = hextob64u(d.n.toString(16));b.e = hextob64u(d.e.toString(16));b.d = hextob64u(d.d.toString(16));b.p = hextob64u(d.p.toString(16));b.q = hextob64u(d.q.toString(16));b.dp = hextob64u(d.dmp1.toString(16));b.dq = hextob64u(d.dmq1.toString(16));b.qi = hextob64u(d.coeff.toString(16));return b;\n  } else {\n    if (d instanceof RSAKey && d.isPublic) {\n      b.kty = \"RSA\";b.n = hextob64u(d.n.toString(16));b.e = hextob64u(d.e.toString(16));return b;\n    } else {\n      if (d instanceof KJUR.crypto.ECDSA && d.isPrivate) {\n        var a = d.getShortNISTPCurveName();if (a !== \"P-256\" && a !== \"P-384\") {\n          throw \"unsupported curve name for JWT: \" + a;\n        }var c = d.getPublicKeyXYHex();b.kty = \"EC\";b.crv = a;b.x = hextob64u(c.x);b.y = hextob64u(c.y);b.d = hextob64u(d.prvKeyHex);return b;\n      } else {\n        if (d instanceof KJUR.crypto.ECDSA && d.isPublic) {\n          var a = d.getShortNISTPCurveName();if (a !== \"P-256\" && a !== \"P-384\") {\n            throw \"unsupported curve name for JWT: \" + a;\n          }var c = d.getPublicKeyXYHex();b.kty = \"EC\";b.crv = a;b.x = hextob64u(c.x);b.y = hextob64u(c.y);return b;\n        }\n      }\n    }\n  }throw \"not supported key object\";\n};\nRSAKey.getPosArrayOfChildrenFromHex = function (a) {\n  return ASN1HEX.getChildIdx(a, 0);\n};RSAKey.getHexValueArrayOfChildrenFromHex = function (f) {\n  var n = ASN1HEX;var i = n.getV;var k = RSAKey.getPosArrayOfChildrenFromHex(f);var e = i(f, k[0]);var j = i(f, k[1]);var b = i(f, k[2]);var c = i(f, k[3]);var h = i(f, k[4]);var g = i(f, k[5]);var m = i(f, k[6]);var l = i(f, k[7]);var d = i(f, k[8]);var k = new Array();k.push(e, j, b, c, h, g, m, l, d);return k;\n};RSAKey.prototype.readPrivateKeyFromPEMString = function (d) {\n  var c = pemtohex(d);var b = RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1], b[2], b[3], b[4], b[5], b[6], b[7], b[8]);\n};RSAKey.prototype.readPKCS5PrvKeyHex = function (c) {\n  var b = RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1], b[2], b[3], b[4], b[5], b[6], b[7], b[8]);\n};RSAKey.prototype.readPKCS8PrvKeyHex = function (e) {\n  var c, j, l, b, a, f, d, k;var m = ASN1HEX;var g = m.getVbyList;if (m.isASN1HEX(e) === false) {\n    throw \"not ASN.1 hex string\";\n  }try {\n    c = g(e, 0, [2, 0, 1], \"02\");j = g(e, 0, [2, 0, 2], \"02\");l = g(e, 0, [2, 0, 3], \"02\");b = g(e, 0, [2, 0, 4], \"02\");a = g(e, 0, [2, 0, 5], \"02\");f = g(e, 0, [2, 0, 6], \"02\");d = g(e, 0, [2, 0, 7], \"02\");k = g(e, 0, [2, 0, 8], \"02\");\n  } catch (i) {\n    throw \"malformed PKCS#8 plain RSA private key\";\n  }this.setPrivateEx(c, j, l, b, a, f, d, k);\n};RSAKey.prototype.readPKCS5PubKeyHex = function (c) {\n  var e = ASN1HEX;var b = e.getV;if (e.isASN1HEX(c) === false) {\n    throw \"keyHex is not ASN.1 hex string\";\n  }var a = e.getChildIdx(c, 0);if (a.length !== 2 || c.substr(a[0], 2) !== \"02\" || c.substr(a[1], 2) !== \"02\") {\n    throw \"wrong hex for PKCS#5 public key\";\n  }var f = b(c, a[0]);var d = b(c, a[1]);this.setPublic(f, d);\n};RSAKey.prototype.readPKCS8PubKeyHex = function (b) {\n  var c = ASN1HEX;if (c.isASN1HEX(b) === false) {\n    throw \"not ASN.1 hex string\";\n  }if (c.getTLVbyList(b, 0, [0, 0]) !== \"06092a864886f70d010101\") {\n    throw \"not PKCS8 RSA public key\";\n  }var a = c.getTLVbyList(b, 0, [1, 0]);this.readPKCS5PubKeyHex(a);\n};RSAKey.prototype.readCertPubKeyHex = function (b, d) {\n  var a, c;a = new X509();a.readCertHex(b);c = a.getPublicKeyHex();this.readPKCS8PubKeyHex(c);\n};\nvar _RE_HEXDECONLY = new RegExp(\"\");_RE_HEXDECONLY.compile(\"[^0-9a-f]\", \"gi\");function _rsasign_getHexPaddedDigestInfoForString(d, e, a) {\n  var b = function b(f) {\n    return KJUR.crypto.Util.hashString(f, a);\n  };var c = b(d);return KJUR.crypto.Util.getPaddedDigestInfoHex(c, a, e);\n}function _zeroPaddingOfSignature(e, d) {\n  var c = \"\";var a = d / 4 - e.length;for (var b = 0; b < a; b++) {\n    c = c + \"0\";\n  }return c + e;\n}RSAKey.prototype.sign = function (d, a) {\n  var b = function b(e) {\n    return KJUR.crypto.Util.hashString(e, a);\n  };var c = b(d);return this.signWithMessageHash(c, a);\n};RSAKey.prototype.signWithMessageHash = function (e, c) {\n  var f = KJUR.crypto.Util.getPaddedDigestInfoHex(e, c, this.n.bitLength());var b = parseBigInt(f, 16);var d = this.doPrivate(b);var a = d.toString(16);return _zeroPaddingOfSignature(a, this.n.bitLength());\n};function pss_mgf1_str(c, a, e) {\n  var b = \"\",\n      d = 0;while (b.length < a) {\n    b += hextorstr(e(rstrtohex(c + String.fromCharCode.apply(String, [(d & 4278190080) >> 24, (d & 16711680) >> 16, (d & 65280) >> 8, d & 255]))));d += 1;\n  }return b;\n}RSAKey.prototype.signPSS = function (e, a, d) {\n  var c = function c(f) {\n    return KJUR.crypto.Util.hashHex(f, a);\n  };var b = c(rstrtohex(e));if (d === undefined) {\n    d = -1;\n  }return this.signWithMessageHashPSS(b, a, d);\n};RSAKey.prototype.signWithMessageHashPSS = function (l, a, k) {\n  var b = hextorstr(l);var g = b.length;var m = this.n.bitLength() - 1;var c = Math.ceil(m / 8);var d;var o = function o(i) {\n    return KJUR.crypto.Util.hashHex(i, a);\n  };if (k === -1 || k === undefined) {\n    k = g;\n  } else {\n    if (k === -2) {\n      k = c - g - 2;\n    } else {\n      if (k < -2) {\n        throw \"invalid salt length\";\n      }\n    }\n  }if (c < g + k + 2) {\n    throw \"data too long\";\n  }var f = \"\";if (k > 0) {\n    f = new Array(k);new SecureRandom().nextBytes(f);f = String.fromCharCode.apply(String, f);\n  }var n = hextorstr(o(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" + b + f)));var j = [];for (d = 0; d < c - k - g - 2; d += 1) {\n    j[d] = 0;\n  }var e = String.fromCharCode.apply(String, j) + \"\\x01\" + f;var h = pss_mgf1_str(n, e.length, o);var q = [];for (d = 0; d < e.length; d += 1) {\n    q[d] = e.charCodeAt(d) ^ h.charCodeAt(d);\n  }var p = 65280 >> 8 * c - m & 255;q[0] &= ~p;for (d = 0; d < g; d++) {\n    q.push(n.charCodeAt(d));\n  }q.push(188);return _zeroPaddingOfSignature(this.doPrivate(new BigInteger(q)).toString(16), this.n.bitLength());\n};function _rsasign_getDecryptSignatureBI(a, d, c) {\n  var b = new RSAKey();b.setPublic(d, c);var e = b.doPublic(a);return e;\n}function _rsasign_getHexDigestInfoFromSig(a, c, b) {\n  var e = _rsasign_getDecryptSignatureBI(a, c, b);var d = e.toString(16).replace(/^1f+00/, \"\");return d;\n}function _rsasign_getAlgNameAndHashFromHexDisgestInfo(f) {\n  for (var e in KJUR.crypto.Util.DIGESTINFOHEAD) {\n    var d = KJUR.crypto.Util.DIGESTINFOHEAD[e];var b = d.length;if (f.substring(0, b) == d) {\n      var c = [e, f.substring(b)];return c;\n    }\n  }return [];\n}RSAKey.prototype.verify = function (f, j) {\n  j = j.replace(_RE_HEXDECONLY, \"\");j = j.replace(/[ \\n]+/g, \"\");var b = parseBigInt(j, 16);if (b.bitLength() > this.n.bitLength()) {\n    return 0;\n  }var i = this.doPublic(b);var e = i.toString(16).replace(/^1f+00/, \"\");var g = _rsasign_getAlgNameAndHashFromHexDisgestInfo(e);if (g.length == 0) {\n    return false;\n  }var d = g[0];var h = g[1];var a = function a(k) {\n    return KJUR.crypto.Util.hashString(k, d);\n  };var c = a(f);return h == c;\n};RSAKey.prototype.verifyWithMessageHash = function (e, a) {\n  a = a.replace(_RE_HEXDECONLY, \"\");a = a.replace(/[ \\n]+/g, \"\");var b = parseBigInt(a, 16);if (b.bitLength() > this.n.bitLength()) {\n    return 0;\n  }var h = this.doPublic(b);var g = h.toString(16).replace(/^1f+00/, \"\");var c = _rsasign_getAlgNameAndHashFromHexDisgestInfo(g);if (c.length == 0) {\n    return false;\n  }var d = c[0];var f = c[1];return f == e;\n};RSAKey.prototype.verifyPSS = function (c, b, a, f) {\n  var e = function e(g) {\n    return KJUR.crypto.Util.hashHex(g, a);\n  };var d = e(rstrtohex(c));if (f === undefined) {\n    f = -1;\n  }return this.verifyWithMessageHashPSS(d, b, a, f);\n};RSAKey.prototype.verifyWithMessageHashPSS = function (f, s, l, c) {\n  var k = new BigInteger(s, 16);if (k.bitLength() > this.n.bitLength()) {\n    return false;\n  }var r = function r(i) {\n    return KJUR.crypto.Util.hashHex(i, l);\n  };var j = hextorstr(f);var h = j.length;var g = this.n.bitLength() - 1;var m = Math.ceil(g / 8);var q;if (c === -1 || c === undefined) {\n    c = h;\n  } else {\n    if (c === -2) {\n      c = m - h - 2;\n    } else {\n      if (c < -2) {\n        throw \"invalid salt length\";\n      }\n    }\n  }if (m < h + c + 2) {\n    throw \"data too long\";\n  }var a = this.doPublic(k).toByteArray();for (q = 0; q < a.length; q += 1) {\n    a[q] &= 255;\n  }while (a.length < m) {\n    a.unshift(0);\n  }if (a[m - 1] !== 188) {\n    throw \"encoded message does not end in 0xbc\";\n  }a = String.fromCharCode.apply(String, a);var d = a.substr(0, m - h - 1);var e = a.substr(d.length, h);var p = 65280 >> 8 * m - g & 255;if ((d.charCodeAt(0) & p) !== 0) {\n    throw \"bits beyond keysize not zero\";\n  }var n = pss_mgf1_str(e, d.length, r);var o = [];for (q = 0; q < d.length; q += 1) {\n    o[q] = d.charCodeAt(q) ^ n.charCodeAt(q);\n  }o[0] &= ~p;var b = m - h - c - 2;for (q = 0; q < b; q += 1) {\n    if (o[q] !== 0) {\n      throw \"leftmost octets not zero\";\n    }\n  }if (o[b] !== 1) {\n    throw \"0x01 marker not found\";\n  }return e === hextorstr(r(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" + j + String.fromCharCode.apply(String, o.slice(-c)))));\n};RSAKey.SALT_LEN_HLEN = -1;RSAKey.SALT_LEN_MAX = -2;RSAKey.SALT_LEN_RECOVER = -2;\nfunction X509() {\n  var k = ASN1HEX,\n      j = k.getChildIdx,\n      h = k.getV,\n      b = k.getTLV,\n      f = k.getVbyList,\n      c = k.getTLVbyList,\n      g = k.getIdxbyList,\n      d = k.getVidx,\n      i = k.oidname,\n      a = X509,\n      e = pemtohex;this.hex = null;this.version = 0;this.foffset = 0;this.aExtInfo = null;this.getVersion = function () {\n    if (this.hex === null || this.version !== 0) {\n      return this.version;\n    }if (c(this.hex, 0, [0, 0]) !== \"a003020102\") {\n      this.version = 1;this.foffset = -1;return 1;\n    }this.version = 3;return 3;\n  };this.getSerialNumberHex = function () {\n    return f(this.hex, 0, [0, 1 + this.foffset], \"02\");\n  };this.getSignatureAlgorithmField = function () {\n    return i(f(this.hex, 0, [0, 2 + this.foffset, 0], \"06\"));\n  };this.getIssuerHex = function () {\n    return c(this.hex, 0, [0, 3 + this.foffset], \"30\");\n  };this.getIssuerString = function () {\n    return a.hex2dn(this.getIssuerHex());\n  };this.getSubjectHex = function () {\n    return c(this.hex, 0, [0, 5 + this.foffset], \"30\");\n  };this.getSubjectString = function () {\n    return a.hex2dn(this.getSubjectHex());\n  };this.getNotBefore = function () {\n    var l = f(this.hex, 0, [0, 4 + this.foffset, 0]);l = l.replace(/(..)/g, \"%$1\");l = decodeURIComponent(l);return l;\n  };this.getNotAfter = function () {\n    var l = f(this.hex, 0, [0, 4 + this.foffset, 1]);l = l.replace(/(..)/g, \"%$1\");l = decodeURIComponent(l);return l;\n  };this.getPublicKeyHex = function () {\n    return k.getTLVbyList(this.hex, 0, [0, 6 + this.foffset], \"30\");\n  };this.getPublicKeyIdx = function () {\n    return g(this.hex, 0, [0, 6 + this.foffset], \"30\");\n  };this.getPublicKeyContentIdx = function () {\n    var l = this.getPublicKeyIdx();return g(this.hex, l, [1, 0], \"30\");\n  };this.getPublicKey = function () {\n    return KEYUTIL.getKey(this.getPublicKeyHex(), null, \"pkcs8pub\");\n  };this.getSignatureAlgorithmName = function () {\n    return i(f(this.hex, 0, [1, 0], \"06\"));\n  };this.getSignatureValueHex = function () {\n    return f(this.hex, 0, [2], \"03\", true);\n  };this.verifySignature = function (n) {\n    var o = this.getSignatureAlgorithmName();var l = this.getSignatureValueHex();var m = c(this.hex, 0, [0], \"30\");var p = new KJUR.crypto.Signature({ alg: o });p.init(n);p.updateHex(m);return p.verify(l);\n  };this.parseExt = function () {\n    if (this.version !== 3) {\n      return -1;\n    }var p = g(this.hex, 0, [0, 7, 0], \"30\");var m = j(this.hex, p);this.aExtInfo = new Array();for (var n = 0; n < m.length; n++) {\n      var q = {};q.critical = false;var l = j(this.hex, m[n]);var r = 0;if (l.length === 3) {\n        q.critical = true;r = 1;\n      }q.oid = k.hextooidstr(f(this.hex, m[n], [0], \"06\"));var o = g(this.hex, m[n], [1 + r]);q.vidx = d(this.hex, o);this.aExtInfo.push(q);\n    }\n  };this.getExtInfo = function (n) {\n    var l = this.aExtInfo;var o = n;if (!n.match(/^[0-9.]+$/)) {\n      o = KJUR.asn1.x509.OID.name2oid(n);\n    }if (o === \"\") {\n      return undefined;\n    }for (var m = 0; m < l.length; m++) {\n      if (l[m].oid === o) {\n        return l[m];\n      }\n    }return undefined;\n  };this.getExtBasicConstraints = function () {\n    var n = this.getExtInfo(\"basicConstraints\");if (n === undefined) {\n      return n;\n    }var l = h(this.hex, n.vidx);if (l === \"\") {\n      return {};\n    }if (l === \"0101ff\") {\n      return { cA: true };\n    }if (l.substr(0, 8) === \"0101ff02\") {\n      var o = h(l, 6);var m = parseInt(o, 16);return { cA: true, pathLen: m };\n    }throw \"basicConstraints parse error\";\n  };this.getExtKeyUsageBin = function () {\n    var o = this.getExtInfo(\"keyUsage\");if (o === undefined) {\n      return \"\";\n    }var m = h(this.hex, o.vidx);if (m.length % 2 != 0 || m.length <= 2) {\n      throw \"malformed key usage value\";\n    }var l = parseInt(m.substr(0, 2));var n = parseInt(m.substr(2), 16).toString(2);return n.substr(0, n.length - l);\n  };this.getExtKeyUsageString = function () {\n    var n = this.getExtKeyUsageBin();var l = new Array();for (var m = 0; m < n.length; m++) {\n      if (n.substr(m, 1) == \"1\") {\n        l.push(X509.KEYUSAGE_NAME[m]);\n      }\n    }return l.join(\",\");\n  };this.getExtSubjectKeyIdentifier = function () {\n    var l = this.getExtInfo(\"subjectKeyIdentifier\");if (l === undefined) {\n      return l;\n    }return h(this.hex, l.vidx);\n  };this.getExtAuthorityKeyIdentifier = function () {\n    var p = this.getExtInfo(\"authorityKeyIdentifier\");if (p === undefined) {\n      return p;\n    }var l = {};var o = b(this.hex, p.vidx);var m = j(o, 0);for (var n = 0; n < m.length; n++) {\n      if (o.substr(m[n], 2) === \"80\") {\n        l.kid = h(o, m[n]);\n      }\n    }return l;\n  };this.getExtExtKeyUsageName = function () {\n    var p = this.getExtInfo(\"extKeyUsage\");if (p === undefined) {\n      return p;\n    }var l = new Array();var o = b(this.hex, p.vidx);if (o === \"\") {\n      return l;\n    }var m = j(o, 0);for (var n = 0; n < m.length; n++) {\n      l.push(i(h(o, m[n])));\n    }return l;\n  };this.getExtSubjectAltName = function () {\n    var m = this.getExtSubjectAltName2();var l = new Array();for (var n = 0; n < m.length; n++) {\n      if (m[n][0] === \"DNS\") {\n        l.push(m[n][1]);\n      }\n    }return l;\n  };this.getExtSubjectAltName2 = function () {\n    var p, s, r;var q = this.getExtInfo(\"subjectAltName\");if (q === undefined) {\n      return q;\n    }var l = new Array();var o = b(this.hex, q.vidx);var m = j(o, 0);for (var n = 0; n < m.length; n++) {\n      r = o.substr(m[n], 2);p = h(o, m[n]);if (r === \"81\") {\n        s = hextoutf8(p);l.push([\"MAIL\", s]);\n      }if (r === \"82\") {\n        s = hextoutf8(p);l.push([\"DNS\", s]);\n      }if (r === \"84\") {\n        s = X509.hex2dn(p, 0);l.push([\"DN\", s]);\n      }if (r === \"86\") {\n        s = hextoutf8(p);l.push([\"URI\", s]);\n      }if (r === \"87\") {\n        s = hextoip(p);l.push([\"IP\", s]);\n      }\n    }return l;\n  };this.getExtCRLDistributionPointsURI = function () {\n    var q = this.getExtInfo(\"cRLDistributionPoints\");if (q === undefined) {\n      return q;\n    }var l = new Array();var m = j(this.hex, q.vidx);for (var o = 0; o < m.length; o++) {\n      try {\n        var r = f(this.hex, m[o], [0, 0, 0], \"86\");var p = hextoutf8(r);l.push(p);\n      } catch (n) {}\n    }return l;\n  };this.getExtAIAInfo = function () {\n    var p = this.getExtInfo(\"authorityInfoAccess\");if (p === undefined) {\n      return p;\n    }var l = { ocsp: [], caissuer: [] };var m = j(this.hex, p.vidx);for (var n = 0; n < m.length; n++) {\n      var q = f(this.hex, m[n], [0], \"06\");var o = f(this.hex, m[n], [1], \"86\");if (q === \"2b06010505073001\") {\n        l.ocsp.push(hextoutf8(o));\n      }if (q === \"2b06010505073002\") {\n        l.caissuer.push(hextoutf8(o));\n      }\n    }return l;\n  };this.getExtCertificatePolicies = function () {\n    var o = this.getExtInfo(\"certificatePolicies\");if (o === undefined) {\n      return o;\n    }var l = b(this.hex, o.vidx);var u = [];var s = j(l, 0);for (var r = 0; r < s.length; r++) {\n      var t = {};var n = j(l, s[r]);t.id = i(h(l, n[0]));if (n.length === 2) {\n        var m = j(l, n[1]);for (var q = 0; q < m.length; q++) {\n          var p = f(l, m[q], [0], \"06\");if (p === \"2b06010505070201\") {\n            t.cps = hextoutf8(f(l, m[q], [1]));\n          } else {\n            if (p === \"2b06010505070202\") {\n              t.unotice = hextoutf8(f(l, m[q], [1, 0]));\n            }\n          }\n        }\n      }u.push(t);\n    }return u;\n  };this.readCertPEM = function (l) {\n    this.readCertHex(e(l));\n  };this.readCertHex = function (l) {\n    this.hex = l;this.getVersion();try {\n      g(this.hex, 0, [0, 7], \"a3\");this.parseExt();\n    } catch (m) {}\n  };this.getInfo = function () {\n    var m = X509;var B, u, z;B = \"Basic Fields\\n\";B += \"  serial number: \" + this.getSerialNumberHex() + \"\\n\";B += \"  signature algorithm: \" + this.getSignatureAlgorithmField() + \"\\n\";B += \"  issuer: \" + this.getIssuerString() + \"\\n\";B += \"  notBefore: \" + this.getNotBefore() + \"\\n\";B += \"  notAfter: \" + this.getNotAfter() + \"\\n\";B += \"  subject: \" + this.getSubjectString() + \"\\n\";B += \"  subject public key info: \\n\";u = this.getPublicKey();B += \"    key algorithm: \" + u.type + \"\\n\";if (u.type === \"RSA\") {\n      B += \"    n=\" + hextoposhex(u.n.toString(16)).substr(0, 16) + \"...\\n\";B += \"    e=\" + hextoposhex(u.e.toString(16)) + \"\\n\";\n    }z = this.aExtInfo;if (z !== undefined && z !== null) {\n      B += \"X509v3 Extensions:\\n\";for (var r = 0; r < z.length; r++) {\n        var n = z[r];var A = KJUR.asn1.x509.OID.oid2name(n.oid);if (A === \"\") {\n          A = n.oid;\n        }var x = \"\";if (n.critical === true) {\n          x = \"CRITICAL\";\n        }B += \"  \" + A + \" \" + x + \":\\n\";if (A === \"basicConstraints\") {\n          var v = this.getExtBasicConstraints();if (v.cA === undefined) {\n            B += \"    {}\\n\";\n          } else {\n            B += \"    cA=true\";if (v.pathLen !== undefined) {\n              B += \", pathLen=\" + v.pathLen;\n            }B += \"\\n\";\n          }\n        } else {\n          if (A === \"keyUsage\") {\n            B += \"    \" + this.getExtKeyUsageString() + \"\\n\";\n          } else {\n            if (A === \"subjectKeyIdentifier\") {\n              B += \"    \" + this.getExtSubjectKeyIdentifier() + \"\\n\";\n            } else {\n              if (A === \"authorityKeyIdentifier\") {\n                var l = this.getExtAuthorityKeyIdentifier();if (l.kid !== undefined) {\n                  B += \"    kid=\" + l.kid + \"\\n\";\n                }\n              } else {\n                if (A === \"extKeyUsage\") {\n                  var w = this.getExtExtKeyUsageName();B += \"    \" + w.join(\", \") + \"\\n\";\n                } else {\n                  if (A === \"subjectAltName\") {\n                    var t = this.getExtSubjectAltName2();B += \"    \" + t + \"\\n\";\n                  } else {\n                    if (A === \"cRLDistributionPoints\") {\n                      var y = this.getExtCRLDistributionPointsURI();B += \"    \" + y + \"\\n\";\n                    } else {\n                      if (A === \"authorityInfoAccess\") {\n                        var p = this.getExtAIAInfo();if (p.ocsp !== undefined) {\n                          B += \"    ocsp: \" + p.ocsp.join(\",\") + \"\\n\";\n                        }if (p.caissuer !== undefined) {\n                          B += \"    caissuer: \" + p.caissuer.join(\",\") + \"\\n\";\n                        }\n                      } else {\n                        if (A === \"certificatePolicies\") {\n                          var o = this.getExtCertificatePolicies();for (var q = 0; q < o.length; q++) {\n                            if (o[q].id !== undefined) {\n                              B += \"    policy oid: \" + o[q].id + \"\\n\";\n                            }if (o[q].cps !== undefined) {\n                              B += \"    cps: \" + o[q].cps + \"\\n\";\n                            }\n                          }\n                        }\n                      }\n                    }\n                  }\n                }\n              }\n            }\n          }\n        }\n      }\n    }B += \"signature algorithm: \" + this.getSignatureAlgorithmName() + \"\\n\";B += \"signature: \" + this.getSignatureValueHex().substr(0, 16) + \"...\\n\";return B;\n  };\n}X509.hex2dn = function (f, b) {\n  if (b === undefined) {\n    b = 0;\n  }if (f.substr(b, 2) !== \"30\") {\n    throw \"malformed DN\";\n  }var c = new Array();var d = ASN1HEX.getChildIdx(f, b);for (var e = 0; e < d.length; e++) {\n    c.push(X509.hex2rdn(f, d[e]));\n  }c = c.map(function (a) {\n    return a.replace(\"/\", \"\\\\/\");\n  });return \"/\" + c.join(\"/\");\n};X509.hex2rdn = function (f, b) {\n  if (b === undefined) {\n    b = 0;\n  }if (f.substr(b, 2) !== \"31\") {\n    throw \"malformed RDN\";\n  }var c = new Array();var d = ASN1HEX.getChildIdx(f, b);for (var e = 0; e < d.length; e++) {\n    c.push(X509.hex2attrTypeValue(f, d[e]));\n  }c = c.map(function (a) {\n    return a.replace(\"+\", \"\\\\+\");\n  });return c.join(\"+\");\n};X509.hex2attrTypeValue = function (d, i) {\n  var j = ASN1HEX;var h = j.getV;if (i === undefined) {\n    i = 0;\n  }if (d.substr(i, 2) !== \"30\") {\n    throw \"malformed attribute type and value\";\n  }var g = j.getChildIdx(d, i);if (g.length !== 2 || d.substr(g[0], 2) !== \"06\") {\n    \"malformed attribute type and value\";\n  }var b = h(d, g[0]);var f = KJUR.asn1.ASN1Util.oidHexToInt(b);var e = KJUR.asn1.x509.OID.oid2atype(f);var a = h(d, g[1]);var c = hextorstr(a);return e + \"=\" + c;\n};X509.getPublicKeyFromCertHex = function (b) {\n  var a = new X509();a.readCertHex(b);return a.getPublicKey();\n};X509.getPublicKeyFromCertPEM = function (b) {\n  var a = new X509();a.readCertPEM(b);return a.getPublicKey();\n};X509.getPublicKeyInfoPropOfCertPEM = function (c) {\n  var e = ASN1HEX;var g = e.getVbyList;var b = {};var a, f, d;b.algparam = null;a = new X509();a.readCertPEM(c);f = a.getPublicKeyHex();b.keyhex = g(f, 0, [1], \"03\").substr(2);b.algoid = g(f, 0, [0, 0], \"06\");if (b.algoid === \"2a8648ce3d0201\") {\n    b.algparam = g(f, 0, [0, 1], \"06\");\n  }return b;\n};X509.KEYUSAGE_NAME = [\"digitalSignature\", \"nonRepudiation\", \"keyEncipherment\", \"dataEncipherment\", \"keyAgreement\", \"keyCertSign\", \"cRLSign\", \"encipherOnly\", \"decipherOnly\"];\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.jws == \"undefined\" || !KJUR.jws) {\n  KJUR.jws = {};\n}KJUR.jws.JWS = function () {\n  var b = KJUR,\n      a = b.jws.JWS,\n      c = a.isSafeJSONString;this.parseJWS = function (g, j) {\n    if (this.parsedJWS !== undefined && (j || this.parsedJWS.sigvalH !== undefined)) {\n      return;\n    }var i = g.match(/^([^.]+)\\.([^.]+)\\.([^.]+)$/);if (i == null) {\n      throw \"JWS signature is not a form of 'Head.Payload.SigValue'.\";\n    }var k = i[1];var e = i[2];var l = i[3];var n = k + \".\" + e;this.parsedJWS = {};this.parsedJWS.headB64U = k;this.parsedJWS.payloadB64U = e;this.parsedJWS.sigvalB64U = l;this.parsedJWS.si = n;if (!j) {\n      var h = b64utohex(l);var f = parseBigInt(h, 16);this.parsedJWS.sigvalH = h;this.parsedJWS.sigvalBI = f;\n    }var d = b64utoutf8(k);var m = b64utoutf8(e);this.parsedJWS.headS = d;this.parsedJWS.payloadS = m;if (!c(d, this.parsedJWS, \"headP\")) {\n      throw \"malformed JSON string for JWS Head: \" + d;\n    }\n  };\n};KJUR.jws.JWS.sign = function (i, v, y, z, a) {\n  var w = KJUR,\n      m = w.jws,\n      q = m.JWS,\n      g = q.readSafeJSONString,\n      p = q.isSafeJSONString,\n      d = w.crypto,\n      k = d.ECDSA,\n      o = d.Mac,\n      c = d.Signature,\n      t = JSON;var s, j, n;if (typeof v != \"string\" && (typeof v === \"undefined\" ? \"undefined\" : _typeof(v)) != \"object\") {\n    throw \"spHeader must be JSON string or object: \" + v;\n  }if ((typeof v === \"undefined\" ? \"undefined\" : _typeof(v)) == \"object\") {\n    j = v;s = t.stringify(j);\n  }if (typeof v == \"string\") {\n    s = v;if (!p(s)) {\n      throw \"JWS Head is not safe JSON string: \" + s;\n    }j = g(s);\n  }n = y;if ((typeof y === \"undefined\" ? \"undefined\" : _typeof(y)) == \"object\") {\n    n = t.stringify(y);\n  }if ((i == \"\" || i == null) && j.alg !== undefined) {\n    i = j.alg;\n  }if (i != \"\" && i != null && j.alg === undefined) {\n    j.alg = i;s = t.stringify(j);\n  }if (i !== j.alg) {\n    throw \"alg and sHeader.alg doesn't match: \" + i + \"!=\" + j.alg;\n  }var r = null;if (q.jwsalg2sigalg[i] === undefined) {\n    throw \"unsupported alg name: \" + i;\n  } else {\n    r = q.jwsalg2sigalg[i];\n  }var e = utf8tob64u(s);var l = utf8tob64u(n);var b = e + \".\" + l;var x = \"\";if (r.substr(0, 4) == \"Hmac\") {\n    if (z === undefined) {\n      throw \"mac key shall be specified for HS* alg\";\n    }var h = new o({ alg: r, prov: \"cryptojs\", pass: z });h.updateString(b);x = h.doFinal();\n  } else {\n    if (r.indexOf(\"withECDSA\") != -1) {\n      var f = new c({ alg: r });f.init(z, a);f.updateString(b);hASN1Sig = f.sign();x = KJUR.crypto.ECDSA.asn1SigToConcatSig(hASN1Sig);\n    } else {\n      if (r != \"none\") {\n        var f = new c({ alg: r });f.init(z, a);f.updateString(b);x = f.sign();\n      }\n    }\n  }var u = hextob64u(x);return b + \".\" + u;\n};KJUR.jws.JWS.verify = function (w, B, n) {\n  var x = KJUR,\n      q = x.jws,\n      t = q.JWS,\n      i = t.readSafeJSONString,\n      e = x.crypto,\n      p = e.ECDSA,\n      s = e.Mac,\n      d = e.Signature,\n      m;if ((typeof RSAKey === \"undefined\" ? \"undefined\" : _typeof(RSAKey)) !== undefined) {\n    m = RSAKey;\n  }var y = w.split(\".\");if (y.length !== 3) {\n    return false;\n  }var f = y[0];var r = y[1];var c = f + \".\" + r;var A = b64utohex(y[2]);var l = i(b64utoutf8(y[0]));var k = null;var z = null;if (l.alg === undefined) {\n    throw \"algorithm not specified in header\";\n  } else {\n    k = l.alg;z = k.substr(0, 2);\n  }if (n != null && Object.prototype.toString.call(n) === \"[object Array]\" && n.length > 0) {\n    var b = \":\" + n.join(\":\") + \":\";if (b.indexOf(\":\" + k + \":\") == -1) {\n      throw \"algorithm '\" + k + \"' not accepted in the list\";\n    }\n  }if (k != \"none\" && B === null) {\n    throw \"key shall be specified to verify.\";\n  }if (typeof B == \"string\" && B.indexOf(\"-----BEGIN \") != -1) {\n    B = KEYUTIL.getKey(B);\n  }if (z == \"RS\" || z == \"PS\") {\n    if (!(B instanceof m)) {\n      throw \"key shall be a RSAKey obj for RS* and PS* algs\";\n    }\n  }if (z == \"ES\") {\n    if (!(B instanceof p)) {\n      throw \"key shall be a ECDSA obj for ES* algs\";\n    }\n  }if (k == \"none\") {}var u = null;if (t.jwsalg2sigalg[l.alg] === undefined) {\n    throw \"unsupported alg name: \" + k;\n  } else {\n    u = t.jwsalg2sigalg[k];\n  }if (u == \"none\") {\n    throw \"not supported\";\n  } else {\n    if (u.substr(0, 4) == \"Hmac\") {\n      var o = null;if (B === undefined) {\n        throw \"hexadecimal key shall be specified for HMAC\";\n      }var j = new s({ alg: u, pass: B });j.updateString(c);o = j.doFinal();return A == o;\n    } else {\n      if (u.indexOf(\"withECDSA\") != -1) {\n        var h = null;try {\n          h = p.concatSigToASN1Sig(A);\n        } catch (v) {\n          return false;\n        }var g = new d({ alg: u });g.init(B);g.updateString(c);return g.verify(h);\n      } else {\n        var g = new d({ alg: u });g.init(B);g.updateString(c);return g.verify(A);\n      }\n    }\n  }\n};KJUR.jws.JWS.parse = function (g) {\n  var c = g.split(\".\");var b = {};var f, e, d;if (c.length != 2 && c.length != 3) {\n    throw \"malformed sJWS: wrong number of '.' splitted elements\";\n  }f = c[0];e = c[1];if (c.length == 3) {\n    d = c[2];\n  }b.headerObj = KJUR.jws.JWS.readSafeJSONString(b64utoutf8(f));b.payloadObj = KJUR.jws.JWS.readSafeJSONString(b64utoutf8(e));b.headerPP = JSON.stringify(b.headerObj, null, \"  \");if (b.payloadObj == null) {\n    b.payloadPP = b64utoutf8(e);\n  } else {\n    b.payloadPP = JSON.stringify(b.payloadObj, null, \"  \");\n  }if (d !== undefined) {\n    b.sigHex = b64utohex(d);\n  }return b;\n};KJUR.jws.JWS.verifyJWT = function (e, l, r) {\n  var d = KJUR,\n      j = d.jws,\n      o = j.JWS,\n      n = o.readSafeJSONString,\n      p = o.inArray,\n      f = o.includedArray;var k = e.split(\".\");var c = k[0];var i = k[1];var q = c + \".\" + i;var m = b64utohex(k[2]);var h = n(b64utoutf8(c));var g = n(b64utoutf8(i));if (h.alg === undefined) {\n    return false;\n  }if (r.alg === undefined) {\n    throw \"acceptField.alg shall be specified\";\n  }if (!p(h.alg, r.alg)) {\n    return false;\n  }if (g.iss !== undefined && _typeof(r.iss) === \"object\") {\n    if (!p(g.iss, r.iss)) {\n      return false;\n    }\n  }if (g.sub !== undefined && _typeof(r.sub) === \"object\") {\n    if (!p(g.sub, r.sub)) {\n      return false;\n    }\n  }if (g.aud !== undefined && _typeof(r.aud) === \"object\") {\n    if (typeof g.aud == \"string\") {\n      if (!p(g.aud, r.aud)) {\n        return false;\n      }\n    } else {\n      if (_typeof(g.aud) == \"object\") {\n        if (!f(g.aud, r.aud)) {\n          return false;\n        }\n      }\n    }\n  }var b = j.IntDate.getNow();if (r.verifyAt !== undefined && typeof r.verifyAt === \"number\") {\n    b = r.verifyAt;\n  }if (r.gracePeriod === undefined || typeof r.gracePeriod !== \"number\") {\n    r.gracePeriod = 0;\n  }if (g.exp !== undefined && typeof g.exp == \"number\") {\n    if (g.exp + r.gracePeriod < b) {\n      return false;\n    }\n  }if (g.nbf !== undefined && typeof g.nbf == \"number\") {\n    if (b < g.nbf - r.gracePeriod) {\n      return false;\n    }\n  }if (g.iat !== undefined && typeof g.iat == \"number\") {\n    if (b < g.iat - r.gracePeriod) {\n      return false;\n    }\n  }if (g.jti !== undefined && r.jti !== undefined) {\n    if (g.jti !== r.jti) {\n      return false;\n    }\n  }if (!o.verify(e, l, r.alg)) {\n    return false;\n  }return true;\n};KJUR.jws.JWS.includedArray = function (b, a) {\n  var c = KJUR.jws.JWS.inArray;if (b === null) {\n    return false;\n  }if ((typeof b === \"undefined\" ? \"undefined\" : _typeof(b)) !== \"object\") {\n    return false;\n  }if (typeof b.length !== \"number\") {\n    return false;\n  }for (var d = 0; d < b.length; d++) {\n    if (!c(b[d], a)) {\n      return false;\n    }\n  }return true;\n};KJUR.jws.JWS.inArray = function (d, b) {\n  if (b === null) {\n    return false;\n  }if ((typeof b === \"undefined\" ? \"undefined\" : _typeof(b)) !== \"object\") {\n    return false;\n  }if (typeof b.length !== \"number\") {\n    return false;\n  }for (var c = 0; c < b.length; c++) {\n    if (b[c] == d) {\n      return true;\n    }\n  }return false;\n};KJUR.jws.JWS.jwsalg2sigalg = { HS256: \"HmacSHA256\", HS384: \"HmacSHA384\", HS512: \"HmacSHA512\", RS256: \"SHA256withRSA\", RS384: \"SHA384withRSA\", RS512: \"SHA512withRSA\", ES256: \"SHA256withECDSA\", ES384: \"SHA384withECDSA\", PS256: \"SHA256withRSAandMGF1\", PS384: \"SHA384withRSAandMGF1\", PS512: \"SHA512withRSAandMGF1\", none: \"none\" };KJUR.jws.JWS.isSafeJSONString = function (c, b, d) {\n  var e = null;try {\n    e = jsonParse(c);if ((typeof e === \"undefined\" ? \"undefined\" : _typeof(e)) != \"object\") {\n      return 0;\n    }if (e.constructor === Array) {\n      return 0;\n    }if (b) {\n      b[d] = e;\n    }return 1;\n  } catch (a) {\n    return 0;\n  }\n};KJUR.jws.JWS.readSafeJSONString = function (b) {\n  var c = null;try {\n    c = jsonParse(b);if ((typeof c === \"undefined\" ? \"undefined\" : _typeof(c)) != \"object\") {\n      return null;\n    }if (c.constructor === Array) {\n      return null;\n    }return c;\n  } catch (a) {\n    return null;\n  }\n};KJUR.jws.JWS.getEncodedSignatureValueFromJWS = function (b) {\n  var a = b.match(/^[^.]+\\.[^.]+\\.([^.]+)$/);if (a == null) {\n    throw \"JWS signature is not a form of 'Head.Payload.SigValue'.\";\n  }return a[1];\n};KJUR.jws.JWS.getJWKthumbprint = function (d) {\n  if (d.kty !== \"RSA\" && d.kty !== \"EC\" && d.kty !== \"oct\") {\n    throw \"unsupported algorithm for JWK Thumprint\";\n  }var a = \"{\";if (d.kty === \"RSA\") {\n    if (typeof d.n != \"string\" || typeof d.e != \"string\") {\n      throw \"wrong n and e value for RSA key\";\n    }a += '\"e\":\"' + d.e + '\",';a += '\"kty\":\"' + d.kty + '\",';a += '\"n\":\"' + d.n + '\"}';\n  } else {\n    if (d.kty === \"EC\") {\n      if (typeof d.crv != \"string\" || typeof d.x != \"string\" || typeof d.y != \"string\") {\n        throw \"wrong crv, x and y value for EC key\";\n      }a += '\"crv\":\"' + d.crv + '\",';a += '\"kty\":\"' + d.kty + '\",';a += '\"x\":\"' + d.x + '\",';a += '\"y\":\"' + d.y + '\"}';\n    } else {\n      if (d.kty === \"oct\") {\n        if (typeof d.k != \"string\") {\n          throw \"wrong k value for oct(symmetric) key\";\n        }a += '\"kty\":\"' + d.kty + '\",';a += '\"k\":\"' + d.k + '\"}';\n      }\n    }\n  }var b = rstrtohex(a);var c = KJUR.crypto.Util.hashHex(b, \"sha256\");var e = hextob64u(c);return e;\n};KJUR.jws.IntDate = {};KJUR.jws.IntDate.get = function (c) {\n  var b = KJUR.jws.IntDate,\n      d = b.getNow,\n      a = b.getZulu;if (c == \"now\") {\n    return d();\n  } else {\n    if (c == \"now + 1hour\") {\n      return d() + 60 * 60;\n    } else {\n      if (c == \"now + 1day\") {\n        return d() + 60 * 60 * 24;\n      } else {\n        if (c == \"now + 1month\") {\n          return d() + 60 * 60 * 24 * 30;\n        } else {\n          if (c == \"now + 1year\") {\n            return d() + 60 * 60 * 24 * 365;\n          } else {\n            if (c.match(/Z$/)) {\n              return a(c);\n            } else {\n              if (c.match(/^[0-9]+$/)) {\n                return parseInt(c);\n              }\n            }\n          }\n        }\n      }\n    }\n  }throw \"unsupported format: \" + c;\n};KJUR.jws.IntDate.getZulu = function (a) {\n  return zulutosec(a);\n};KJUR.jws.IntDate.getNow = function () {\n  var a = ~~(new Date() / 1000);return a;\n};KJUR.jws.IntDate.intDate2UTCString = function (a) {\n  var b = new Date(a * 1000);return b.toUTCString();\n};KJUR.jws.IntDate.intDate2Zulu = function (e) {\n  var i = new Date(e * 1000),\n      h = (\"0000\" + i.getUTCFullYear()).slice(-4),\n      g = (\"00\" + (i.getUTCMonth() + 1)).slice(-2),\n      b = (\"00\" + i.getUTCDate()).slice(-2),\n      a = (\"00\" + i.getUTCHours()).slice(-2),\n      c = (\"00\" + i.getUTCMinutes()).slice(-2),\n      f = (\"00\" + i.getUTCSeconds()).slice(-2);return h + g + b + a + c + f + \"Z\";\n};\nexports.SecureRandom = SecureRandom;\nexports.rng_seed_time = rng_seed_time;\nexports.BigInteger = BigInteger;\nexports.RSAKey = RSAKey;\nvar EDSA = KJUR.crypto.EDSA;\nexports.EDSA = EDSA;\nvar DSA = KJUR.crypto.DSA;\nexports.DSA = DSA;\nvar Signature = KJUR.crypto.Signature;\nexports.Signature = Signature;\nvar MessageDigest = KJUR.crypto.MessageDigest;\nexports.MessageDigest = MessageDigest;\nvar Mac = KJUR.crypto.Mac;\nexports.Mac = Mac;\nvar Cipher = KJUR.crypto.Cipher;\nexports.Cipher = Cipher;\nexports.KEYUTIL = KEYUTIL;\nexports.ASN1HEX = ASN1HEX;\nexports.X509 = X509;\nexports.CryptoJS = CryptoJS;\n\n// ext/base64.js\n\nexports.b64tohex = b64tohex;\nexports.b64toBA = b64toBA;\n\n// base64x.js\n\nexports.stoBA = stoBA;\nexports.BAtos = BAtos;\nexports.BAtohex = BAtohex;\nexports.stohex = stohex;\nexports.stob64 = stob64;\nexports.stob64u = stob64u;\nexports.b64utos = b64utos;\nexports.b64tob64u = b64tob64u;\nexports.b64utob64 = b64utob64;\nexports.hex2b64 = hex2b64;\nexports.hextob64u = hextob64u;\nexports.b64utohex = b64utohex;\nexports.utf8tob64u = utf8tob64u;\nexports.b64utoutf8 = b64utoutf8;\nexports.utf8tob64 = utf8tob64;\nexports.b64toutf8 = b64toutf8;\nexports.utf8tohex = utf8tohex;\nexports.hextoutf8 = hextoutf8;\nexports.hextorstr = hextorstr;\nexports.rstrtohex = rstrtohex;\nexports.hextob64 = hextob64;\nexports.hextob64nl = hextob64nl;\nexports.b64nltohex = b64nltohex;\nexports.hextopem = hextopem;\nexports.pemtohex = pemtohex;\nexports.hextoArrayBuffer = hextoArrayBuffer;\nexports.ArrayBuffertohex = ArrayBuffertohex;\nexports.zulutomsec = zulutomsec;\nexports.zulutosec = zulutosec;\nexports.zulutodate = zulutodate;\nexports.datetozulu = datetozulu;\nexports.uricmptohex = uricmptohex;\nexports.hextouricmp = hextouricmp;\nexports.ipv6tohex = ipv6tohex;\nexports.hextoipv6 = hextoipv6;\nexports.hextoip = hextoip;\nexports.iptohex = iptohex;\nexports.encodeURIComponentAll = encodeURIComponentAll;\nexports.newline_toUnix = newline_toUnix;\nexports.newline_toDos = newline_toDos;\nexports.hextoposhex = hextoposhex;\nexports.intarystrtohex = intarystrtohex;\nexports.strdiffidx = strdiffidx;\n\n// name spaces\n\nexports.KJUR = KJUR;\n\nvar _crypto = KJUR.crypto;\nexports.crypto = _crypto;\nvar _KJUR = KJUR;\nvar asn1 = _KJUR.asn1;\nexports.asn1 = asn1;\nvar _KJUR2 = KJUR;\nvar jws = _KJUR2.jws;\nexports.jws = jws;\nvar _KJUR3 = KJUR;\nvar lang = _KJUR3.lang;\nexports.lang = lang;\n/* WEBPACK VAR INJECTION */}.call(this, __webpack_require__(/*! ./../../node_modules/buffer/index.js */ \"./node_modules/buffer/index.js\").Buffer))\n\n/***/ }),\n\n/***/ \"./node_modules/base64-js/index.js\":\n/*!*****************************************!*\\\n  !*** ./node_modules/base64-js/index.js ***!\n  \\*****************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nexports.byteLength = byteLength\nexports.toByteArray = toByteArray\nexports.fromByteArray = fromByteArray\n\nvar lookup = []\nvar revLookup = []\nvar Arr = typeof Uint8Array !== 'undefined' ? Uint8Array : Array\n\nvar code = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'\nfor (var i = 0, len = code.length; i < len; ++i) {\n  lookup[i] = code[i]\n  revLookup[code.charCodeAt(i)] = i\n}\n\n// Support decoding URL-safe base64 strings, as Node.js does.\n// See: https://en.wikipedia.org/wiki/Base64#URL_applications\nrevLookup['-'.charCodeAt(0)] = 62\nrevLookup['_'.charCodeAt(0)] = 63\n\nfunction getLens (b64) {\n  var len = b64.length\n\n  if (len % 4 > 0) {\n    throw new Error('Invalid string. Length must be a multiple of 4')\n  }\n\n  // Trim off extra bytes after placeholder bytes are found\n  // See: https://github.com/beatgammit/base64-js/issues/42\n  var validLen = b64.indexOf('=')\n  if (validLen === -1) validLen = len\n\n  var placeHoldersLen = validLen === len\n    ? 0\n    : 4 - (validLen % 4)\n\n  return [validLen, placeHoldersLen]\n}\n\n// base64 is 4/3 + up to two characters of the original data\nfunction byteLength (b64) {\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction _byteLength (b64, validLen, placeHoldersLen) {\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction toByteArray (b64) {\n  var tmp\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n\n  var arr = new Arr(_byteLength(b64, validLen, placeHoldersLen))\n\n  var curByte = 0\n\n  // if there are placeholders, only get up to the last complete 4 chars\n  var len = placeHoldersLen > 0\n    ? validLen - 4\n    : validLen\n\n  for (var i = 0; i < len; i += 4) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 18) |\n      (revLookup[b64.charCodeAt(i + 1)] << 12) |\n      (revLookup[b64.charCodeAt(i + 2)] << 6) |\n      revLookup[b64.charCodeAt(i + 3)]\n    arr[curByte++] = (tmp >> 16) & 0xFF\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 2) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 2) |\n      (revLookup[b64.charCodeAt(i + 1)] >> 4)\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 1) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 10) |\n      (revLookup[b64.charCodeAt(i + 1)] << 4) |\n      (revLookup[b64.charCodeAt(i + 2)] >> 2)\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  return arr\n}\n\nfunction tripletToBase64 (num) {\n  return lookup[num >> 18 & 0x3F] +\n    lookup[num >> 12 & 0x3F] +\n    lookup[num >> 6 & 0x3F] +\n    lookup[num & 0x3F]\n}\n\nfunction encodeChunk (uint8, start, end) {\n  var tmp\n  var output = []\n  for (var i = start; i < end; i += 3) {\n    tmp =\n      ((uint8[i] << 16) & 0xFF0000) +\n      ((uint8[i + 1] << 8) & 0xFF00) +\n      (uint8[i + 2] & 0xFF)\n    output.push(tripletToBase64(tmp))\n  }\n  return output.join('')\n}\n\nfunction fromByteArray (uint8) {\n  var tmp\n  var len = uint8.length\n  var extraBytes = len % 3 // if we have 1 byte left, pad 2 bytes\n  var parts = []\n  var maxChunkLength = 16383 // must be multiple of 3\n\n  // go through the array every three bytes, we'll deal with trailing stuff later\n  for (var i = 0, len2 = len - extraBytes; i < len2; i += maxChunkLength) {\n    parts.push(encodeChunk(\n      uint8, i, (i + maxChunkLength) > len2 ? len2 : (i + maxChunkLength)\n    ))\n  }\n\n  // pad the end with zeros, but make sure to not forget the extra bytes\n  if (extraBytes === 1) {\n    tmp = uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 2] +\n      lookup[(tmp << 4) & 0x3F] +\n      '=='\n    )\n  } else if (extraBytes === 2) {\n    tmp = (uint8[len - 2] << 8) + uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 10] +\n      lookup[(tmp >> 4) & 0x3F] +\n      lookup[(tmp << 2) & 0x3F] +\n      '='\n    )\n  }\n\n  return parts.join('')\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/buffer/index.js\":\n/*!**************************************!*\\\n  !*** ./node_modules/buffer/index.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n/* WEBPACK VAR INJECTION */(function(global) {/*!\n * The buffer module from node.js, for the browser.\n *\n * @author   Feross Aboukhadijeh <feross@feross.org> <http://feross.org>\n * @license  MIT\n */\n/* eslint-disable no-proto */\n\n\n\nvar base64 = __webpack_require__(/*! base64-js */ \"./node_modules/base64-js/index.js\")\nvar ieee754 = __webpack_require__(/*! ieee754 */ \"./node_modules/ieee754/index.js\")\nvar isArray = __webpack_require__(/*! isarray */ \"./node_modules/buffer/node_modules/isarray/index.js\")\n\nexports.Buffer = Buffer\nexports.SlowBuffer = SlowBuffer\nexports.INSPECT_MAX_BYTES = 50\n\n/**\n * If `Buffer.TYPED_ARRAY_SUPPORT`:\n *   === true    Use Uint8Array implementation (fastest)\n *   === false   Use Object implementation (most compatible, even IE6)\n *\n * Browsers that support typed arrays are IE 10+, Firefox 4+, Chrome 7+, Safari 5.1+,\n * Opera 11.6+, iOS 4.2+.\n *\n * Due to various browser bugs, sometimes the Object implementation will be used even\n * when the browser supports typed arrays.\n *\n * Note:\n *\n *   - Firefox 4-29 lacks support for adding new properties to `Uint8Array` instances,\n *     See: https://bugzilla.mozilla.org/show_bug.cgi?id=695438.\n *\n *   - Chrome 9-10 is missing the `TypedArray.prototype.subarray` function.\n *\n *   - IE10 has a broken `TypedArray.prototype.subarray` function which returns arrays of\n *     incorrect length in some situations.\n\n * We detect these buggy browsers and set `Buffer.TYPED_ARRAY_SUPPORT` to `false` so they\n * get the Object implementation, which is slower but behaves correctly.\n */\nBuffer.TYPED_ARRAY_SUPPORT = global.TYPED_ARRAY_SUPPORT !== undefined\n  ? global.TYPED_ARRAY_SUPPORT\n  : typedArraySupport()\n\n/*\n * Export kMaxLength after typed array support is determined.\n */\nexports.kMaxLength = kMaxLength()\n\nfunction typedArraySupport () {\n  try {\n    var arr = new Uint8Array(1)\n    arr.__proto__ = {__proto__: Uint8Array.prototype, foo: function () { return 42 }}\n    return arr.foo() === 42 && // typed array instances can be augmented\n        typeof arr.subarray === 'function' && // chrome 9-10 lack `subarray`\n        arr.subarray(1, 1).byteLength === 0 // ie10 has broken `subarray`\n  } catch (e) {\n    return false\n  }\n}\n\nfunction kMaxLength () {\n  return Buffer.TYPED_ARRAY_SUPPORT\n    ? 0x7fffffff\n    : 0x3fffffff\n}\n\nfunction createBuffer (that, length) {\n  if (kMaxLength() < length) {\n    throw new RangeError('Invalid typed array length')\n  }\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = new Uint8Array(length)\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    if (that === null) {\n      that = new Buffer(length)\n    }\n    that.length = length\n  }\n\n  return that\n}\n\n/**\n * The Buffer constructor returns instances of `Uint8Array` that have their\n * prototype changed to `Buffer.prototype`. Furthermore, `Buffer` is a subclass of\n * `Uint8Array`, so the returned instances will have all the node `Buffer` methods\n * and the `Uint8Array` methods. Square bracket notation works as expected -- it\n * returns a single octet.\n *\n * The `Uint8Array` prototype remains unmodified.\n */\n\nfunction Buffer (arg, encodingOrOffset, length) {\n  if (!Buffer.TYPED_ARRAY_SUPPORT && !(this instanceof Buffer)) {\n    return new Buffer(arg, encodingOrOffset, length)\n  }\n\n  // Common case.\n  if (typeof arg === 'number') {\n    if (typeof encodingOrOffset === 'string') {\n      throw new Error(\n        'If encoding is specified then the first argument must be a string'\n      )\n    }\n    return allocUnsafe(this, arg)\n  }\n  return from(this, arg, encodingOrOffset, length)\n}\n\nBuffer.poolSize = 8192 // not used by this implementation\n\n// TODO: Legacy, not needed anymore. Remove in next major version.\nBuffer._augment = function (arr) {\n  arr.__proto__ = Buffer.prototype\n  return arr\n}\n\nfunction from (that, value, encodingOrOffset, length) {\n  if (typeof value === 'number') {\n    throw new TypeError('\"value\" argument must not be a number')\n  }\n\n  if (typeof ArrayBuffer !== 'undefined' && value instanceof ArrayBuffer) {\n    return fromArrayBuffer(that, value, encodingOrOffset, length)\n  }\n\n  if (typeof value === 'string') {\n    return fromString(that, value, encodingOrOffset)\n  }\n\n  return fromObject(that, value)\n}\n\n/**\n * Functionally equivalent to Buffer(arg, encoding) but throws a TypeError\n * if value is a number.\n * Buffer.from(str[, encoding])\n * Buffer.from(array)\n * Buffer.from(buffer)\n * Buffer.from(arrayBuffer[, byteOffset[, length]])\n **/\nBuffer.from = function (value, encodingOrOffset, length) {\n  return from(null, value, encodingOrOffset, length)\n}\n\nif (Buffer.TYPED_ARRAY_SUPPORT) {\n  Buffer.prototype.__proto__ = Uint8Array.prototype\n  Buffer.__proto__ = Uint8Array\n  if (typeof Symbol !== 'undefined' && Symbol.species &&\n      Buffer[Symbol.species] === Buffer) {\n    // Fix subarray() in ES2016. See: https://github.com/feross/buffer/pull/97\n    Object.defineProperty(Buffer, Symbol.species, {\n      value: null,\n      configurable: true\n    })\n  }\n}\n\nfunction assertSize (size) {\n  if (typeof size !== 'number') {\n    throw new TypeError('\"size\" argument must be a number')\n  } else if (size < 0) {\n    throw new RangeError('\"size\" argument must not be negative')\n  }\n}\n\nfunction alloc (that, size, fill, encoding) {\n  assertSize(size)\n  if (size <= 0) {\n    return createBuffer(that, size)\n  }\n  if (fill !== undefined) {\n    // Only pay attention to encoding if it's a string. This\n    // prevents accidentally sending in a number that would\n    // be interpretted as a start offset.\n    return typeof encoding === 'string'\n      ? createBuffer(that, size).fill(fill, encoding)\n      : createBuffer(that, size).fill(fill)\n  }\n  return createBuffer(that, size)\n}\n\n/**\n * Creates a new filled Buffer instance.\n * alloc(size[, fill[, encoding]])\n **/\nBuffer.alloc = function (size, fill, encoding) {\n  return alloc(null, size, fill, encoding)\n}\n\nfunction allocUnsafe (that, size) {\n  assertSize(size)\n  that = createBuffer(that, size < 0 ? 0 : checked(size) | 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) {\n    for (var i = 0; i < size; ++i) {\n      that[i] = 0\n    }\n  }\n  return that\n}\n\n/**\n * Equivalent to Buffer(num), by default creates a non-zero-filled Buffer instance.\n * */\nBuffer.allocUnsafe = function (size) {\n  return allocUnsafe(null, size)\n}\n/**\n * Equivalent to SlowBuffer(num), by default creates a non-zero-filled Buffer instance.\n */\nBuffer.allocUnsafeSlow = function (size) {\n  return allocUnsafe(null, size)\n}\n\nfunction fromString (that, string, encoding) {\n  if (typeof encoding !== 'string' || encoding === '') {\n    encoding = 'utf8'\n  }\n\n  if (!Buffer.isEncoding(encoding)) {\n    throw new TypeError('\"encoding\" must be a valid string encoding')\n  }\n\n  var length = byteLength(string, encoding) | 0\n  that = createBuffer(that, length)\n\n  var actual = that.write(string, encoding)\n\n  if (actual !== length) {\n    // Writing a hex string, for example, that contains invalid characters will\n    // cause everything after the first invalid character to be ignored. (e.g.\n    // 'abxxcd' will be treated as 'ab')\n    that = that.slice(0, actual)\n  }\n\n  return that\n}\n\nfunction fromArrayLike (that, array) {\n  var length = array.length < 0 ? 0 : checked(array.length) | 0\n  that = createBuffer(that, length)\n  for (var i = 0; i < length; i += 1) {\n    that[i] = array[i] & 255\n  }\n  return that\n}\n\nfunction fromArrayBuffer (that, array, byteOffset, length) {\n  array.byteLength // this throws if `array` is not a valid ArrayBuffer\n\n  if (byteOffset < 0 || array.byteLength < byteOffset) {\n    throw new RangeError('\\'offset\\' is out of bounds')\n  }\n\n  if (array.byteLength < byteOffset + (length || 0)) {\n    throw new RangeError('\\'length\\' is out of bounds')\n  }\n\n  if (byteOffset === undefined && length === undefined) {\n    array = new Uint8Array(array)\n  } else if (length === undefined) {\n    array = new Uint8Array(array, byteOffset)\n  } else {\n    array = new Uint8Array(array, byteOffset, length)\n  }\n\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = array\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    that = fromArrayLike(that, array)\n  }\n  return that\n}\n\nfunction fromObject (that, obj) {\n  if (Buffer.isBuffer(obj)) {\n    var len = checked(obj.length) | 0\n    that = createBuffer(that, len)\n\n    if (that.length === 0) {\n      return that\n    }\n\n    obj.copy(that, 0, 0, len)\n    return that\n  }\n\n  if (obj) {\n    if ((typeof ArrayBuffer !== 'undefined' &&\n        obj.buffer instanceof ArrayBuffer) || 'length' in obj) {\n      if (typeof obj.length !== 'number' || isnan(obj.length)) {\n        return createBuffer(that, 0)\n      }\n      return fromArrayLike(that, obj)\n    }\n\n    if (obj.type === 'Buffer' && isArray(obj.data)) {\n      return fromArrayLike(that, obj.data)\n    }\n  }\n\n  throw new TypeError('First argument must be a string, Buffer, ArrayBuffer, Array, or array-like object.')\n}\n\nfunction checked (length) {\n  // Note: cannot use `length < kMaxLength()` here because that fails when\n  // length is NaN (which is otherwise coerced to zero.)\n  if (length >= kMaxLength()) {\n    throw new RangeError('Attempt to allocate Buffer larger than maximum ' +\n                         'size: 0x' + kMaxLength().toString(16) + ' bytes')\n  }\n  return length | 0\n}\n\nfunction SlowBuffer (length) {\n  if (+length != length) { // eslint-disable-line eqeqeq\n    length = 0\n  }\n  return Buffer.alloc(+length)\n}\n\nBuffer.isBuffer = function isBuffer (b) {\n  return !!(b != null && b._isBuffer)\n}\n\nBuffer.compare = function compare (a, b) {\n  if (!Buffer.isBuffer(a) || !Buffer.isBuffer(b)) {\n    throw new TypeError('Arguments must be Buffers')\n  }\n\n  if (a === b) return 0\n\n  var x = a.length\n  var y = b.length\n\n  for (var i = 0, len = Math.min(x, y); i < len; ++i) {\n    if (a[i] !== b[i]) {\n      x = a[i]\n      y = b[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\nBuffer.isEncoding = function isEncoding (encoding) {\n  switch (String(encoding).toLowerCase()) {\n    case 'hex':\n    case 'utf8':\n    case 'utf-8':\n    case 'ascii':\n    case 'latin1':\n    case 'binary':\n    case 'base64':\n    case 'ucs2':\n    case 'ucs-2':\n    case 'utf16le':\n    case 'utf-16le':\n      return true\n    default:\n      return false\n  }\n}\n\nBuffer.concat = function concat (list, length) {\n  if (!isArray(list)) {\n    throw new TypeError('\"list\" argument must be an Array of Buffers')\n  }\n\n  if (list.length === 0) {\n    return Buffer.alloc(0)\n  }\n\n  var i\n  if (length === undefined) {\n    length = 0\n    for (i = 0; i < list.length; ++i) {\n      length += list[i].length\n    }\n  }\n\n  var buffer = Buffer.allocUnsafe(length)\n  var pos = 0\n  for (i = 0; i < list.length; ++i) {\n    var buf = list[i]\n    if (!Buffer.isBuffer(buf)) {\n      throw new TypeError('\"list\" argument must be an Array of Buffers')\n    }\n    buf.copy(buffer, pos)\n    pos += buf.length\n  }\n  return buffer\n}\n\nfunction byteLength (string, encoding) {\n  if (Buffer.isBuffer(string)) {\n    return string.length\n  }\n  if (typeof ArrayBuffer !== 'undefined' && typeof ArrayBuffer.isView === 'function' &&\n      (ArrayBuffer.isView(string) || string instanceof ArrayBuffer)) {\n    return string.byteLength\n  }\n  if (typeof string !== 'string') {\n    string = '' + string\n  }\n\n  var len = string.length\n  if (len === 0) return 0\n\n  // Use a for loop to avoid recursion\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'ascii':\n      case 'latin1':\n      case 'binary':\n        return len\n      case 'utf8':\n      case 'utf-8':\n      case undefined:\n        return utf8ToBytes(string).length\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return len * 2\n      case 'hex':\n        return len >>> 1\n      case 'base64':\n        return base64ToBytes(string).length\n      default:\n        if (loweredCase) return utf8ToBytes(string).length // assume utf8\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\nBuffer.byteLength = byteLength\n\nfunction slowToString (encoding, start, end) {\n  var loweredCase = false\n\n  // No need to verify that \"this.length <= MAX_UINT32\" since it's a read-only\n  // property of a typed array.\n\n  // This behaves neither like String nor Uint8Array in that we set start/end\n  // to their upper/lower bounds if the value passed is out of range.\n  // undefined is handled specially as per ECMA-262 6th Edition,\n  // Section 13.3.3.7 Runtime Semantics: KeyedBindingInitialization.\n  if (start === undefined || start < 0) {\n    start = 0\n  }\n  // Return early if start > this.length. Done here to prevent potential uint32\n  // coercion fail below.\n  if (start > this.length) {\n    return ''\n  }\n\n  if (end === undefined || end > this.length) {\n    end = this.length\n  }\n\n  if (end <= 0) {\n    return ''\n  }\n\n  // Force coersion to uint32. This will also coerce falsey/NaN values to 0.\n  end >>>= 0\n  start >>>= 0\n\n  if (end <= start) {\n    return ''\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  while (true) {\n    switch (encoding) {\n      case 'hex':\n        return hexSlice(this, start, end)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Slice(this, start, end)\n\n      case 'ascii':\n        return asciiSlice(this, start, end)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Slice(this, start, end)\n\n      case 'base64':\n        return base64Slice(this, start, end)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return utf16leSlice(this, start, end)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = (encoding + '').toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\n// The property is used by `Buffer.isBuffer` and `is-buffer` (in Safari 5-7) to detect\n// Buffer instances.\nBuffer.prototype._isBuffer = true\n\nfunction swap (b, n, m) {\n  var i = b[n]\n  b[n] = b[m]\n  b[m] = i\n}\n\nBuffer.prototype.swap16 = function swap16 () {\n  var len = this.length\n  if (len % 2 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 16-bits')\n  }\n  for (var i = 0; i < len; i += 2) {\n    swap(this, i, i + 1)\n  }\n  return this\n}\n\nBuffer.prototype.swap32 = function swap32 () {\n  var len = this.length\n  if (len % 4 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 32-bits')\n  }\n  for (var i = 0; i < len; i += 4) {\n    swap(this, i, i + 3)\n    swap(this, i + 1, i + 2)\n  }\n  return this\n}\n\nBuffer.prototype.swap64 = function swap64 () {\n  var len = this.length\n  if (len % 8 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 64-bits')\n  }\n  for (var i = 0; i < len; i += 8) {\n    swap(this, i, i + 7)\n    swap(this, i + 1, i + 6)\n    swap(this, i + 2, i + 5)\n    swap(this, i + 3, i + 4)\n  }\n  return this\n}\n\nBuffer.prototype.toString = function toString () {\n  var length = this.length | 0\n  if (length === 0) return ''\n  if (arguments.length === 0) return utf8Slice(this, 0, length)\n  return slowToString.apply(this, arguments)\n}\n\nBuffer.prototype.equals = function equals (b) {\n  if (!Buffer.isBuffer(b)) throw new TypeError('Argument must be a Buffer')\n  if (this === b) return true\n  return Buffer.compare(this, b) === 0\n}\n\nBuffer.prototype.inspect = function inspect () {\n  var str = ''\n  var max = exports.INSPECT_MAX_BYTES\n  if (this.length > 0) {\n    str = this.toString('hex', 0, max).match(/.{2}/g).join(' ')\n    if (this.length > max) str += ' ... '\n  }\n  return '<Buffer ' + str + '>'\n}\n\nBuffer.prototype.compare = function compare (target, start, end, thisStart, thisEnd) {\n  if (!Buffer.isBuffer(target)) {\n    throw new TypeError('Argument must be a Buffer')\n  }\n\n  if (start === undefined) {\n    start = 0\n  }\n  if (end === undefined) {\n    end = target ? target.length : 0\n  }\n  if (thisStart === undefined) {\n    thisStart = 0\n  }\n  if (thisEnd === undefined) {\n    thisEnd = this.length\n  }\n\n  if (start < 0 || end > target.length || thisStart < 0 || thisEnd > this.length) {\n    throw new RangeError('out of range index')\n  }\n\n  if (thisStart >= thisEnd && start >= end) {\n    return 0\n  }\n  if (thisStart >= thisEnd) {\n    return -1\n  }\n  if (start >= end) {\n    return 1\n  }\n\n  start >>>= 0\n  end >>>= 0\n  thisStart >>>= 0\n  thisEnd >>>= 0\n\n  if (this === target) return 0\n\n  var x = thisEnd - thisStart\n  var y = end - start\n  var len = Math.min(x, y)\n\n  var thisCopy = this.slice(thisStart, thisEnd)\n  var targetCopy = target.slice(start, end)\n\n  for (var i = 0; i < len; ++i) {\n    if (thisCopy[i] !== targetCopy[i]) {\n      x = thisCopy[i]\n      y = targetCopy[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\n// Finds either the first index of `val` in `buffer` at offset >= `byteOffset`,\n// OR the last index of `val` in `buffer` at offset <= `byteOffset`.\n//\n// Arguments:\n// - buffer - a Buffer to search\n// - val - a string, Buffer, or number\n// - byteOffset - an index into `buffer`; will be clamped to an int32\n// - encoding - an optional encoding, relevant is val is a string\n// - dir - true for indexOf, false for lastIndexOf\nfunction bidirectionalIndexOf (buffer, val, byteOffset, encoding, dir) {\n  // Empty buffer means no match\n  if (buffer.length === 0) return -1\n\n  // Normalize byteOffset\n  if (typeof byteOffset === 'string') {\n    encoding = byteOffset\n    byteOffset = 0\n  } else if (byteOffset > 0x7fffffff) {\n    byteOffset = 0x7fffffff\n  } else if (byteOffset < -0x80000000) {\n    byteOffset = -0x80000000\n  }\n  byteOffset = +byteOffset  // Coerce to Number.\n  if (isNaN(byteOffset)) {\n    // byteOffset: it it's undefined, null, NaN, \"foo\", etc, search whole buffer\n    byteOffset = dir ? 0 : (buffer.length - 1)\n  }\n\n  // Normalize byteOffset: negative offsets start from the end of the buffer\n  if (byteOffset < 0) byteOffset = buffer.length + byteOffset\n  if (byteOffset >= buffer.length) {\n    if (dir) return -1\n    else byteOffset = buffer.length - 1\n  } else if (byteOffset < 0) {\n    if (dir) byteOffset = 0\n    else return -1\n  }\n\n  // Normalize val\n  if (typeof val === 'string') {\n    val = Buffer.from(val, encoding)\n  }\n\n  // Finally, search either indexOf (if dir is true) or lastIndexOf\n  if (Buffer.isBuffer(val)) {\n    // Special case: looking for empty string/buffer always fails\n    if (val.length === 0) {\n      return -1\n    }\n    return arrayIndexOf(buffer, val, byteOffset, encoding, dir)\n  } else if (typeof val === 'number') {\n    val = val & 0xFF // Search for a byte value [0-255]\n    if (Buffer.TYPED_ARRAY_SUPPORT &&\n        typeof Uint8Array.prototype.indexOf === 'function') {\n      if (dir) {\n        return Uint8Array.prototype.indexOf.call(buffer, val, byteOffset)\n      } else {\n        return Uint8Array.prototype.lastIndexOf.call(buffer, val, byteOffset)\n      }\n    }\n    return arrayIndexOf(buffer, [ val ], byteOffset, encoding, dir)\n  }\n\n  throw new TypeError('val must be string, number or Buffer')\n}\n\nfunction arrayIndexOf (arr, val, byteOffset, encoding, dir) {\n  var indexSize = 1\n  var arrLength = arr.length\n  var valLength = val.length\n\n  if (encoding !== undefined) {\n    encoding = String(encoding).toLowerCase()\n    if (encoding === 'ucs2' || encoding === 'ucs-2' ||\n        encoding === 'utf16le' || encoding === 'utf-16le') {\n      if (arr.length < 2 || val.length < 2) {\n        return -1\n      }\n      indexSize = 2\n      arrLength /= 2\n      valLength /= 2\n      byteOffset /= 2\n    }\n  }\n\n  function read (buf, i) {\n    if (indexSize === 1) {\n      return buf[i]\n    } else {\n      return buf.readUInt16BE(i * indexSize)\n    }\n  }\n\n  var i\n  if (dir) {\n    var foundIndex = -1\n    for (i = byteOffset; i < arrLength; i++) {\n      if (read(arr, i) === read(val, foundIndex === -1 ? 0 : i - foundIndex)) {\n        if (foundIndex === -1) foundIndex = i\n        if (i - foundIndex + 1 === valLength) return foundIndex * indexSize\n      } else {\n        if (foundIndex !== -1) i -= i - foundIndex\n        foundIndex = -1\n      }\n    }\n  } else {\n    if (byteOffset + valLength > arrLength) byteOffset = arrLength - valLength\n    for (i = byteOffset; i >= 0; i--) {\n      var found = true\n      for (var j = 0; j < valLength; j++) {\n        if (read(arr, i + j) !== read(val, j)) {\n          found = false\n          break\n        }\n      }\n      if (found) return i\n    }\n  }\n\n  return -1\n}\n\nBuffer.prototype.includes = function includes (val, byteOffset, encoding) {\n  return this.indexOf(val, byteOffset, encoding) !== -1\n}\n\nBuffer.prototype.indexOf = function indexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, true)\n}\n\nBuffer.prototype.lastIndexOf = function lastIndexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, false)\n}\n\nfunction hexWrite (buf, string, offset, length) {\n  offset = Number(offset) || 0\n  var remaining = buf.length - offset\n  if (!length) {\n    length = remaining\n  } else {\n    length = Number(length)\n    if (length > remaining) {\n      length = remaining\n    }\n  }\n\n  // must be an even number of digits\n  var strLen = string.length\n  if (strLen % 2 !== 0) throw new TypeError('Invalid hex string')\n\n  if (length > strLen / 2) {\n    length = strLen / 2\n  }\n  for (var i = 0; i < length; ++i) {\n    var parsed = parseInt(string.substr(i * 2, 2), 16)\n    if (isNaN(parsed)) return i\n    buf[offset + i] = parsed\n  }\n  return i\n}\n\nfunction utf8Write (buf, string, offset, length) {\n  return blitBuffer(utf8ToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nfunction asciiWrite (buf, string, offset, length) {\n  return blitBuffer(asciiToBytes(string), buf, offset, length)\n}\n\nfunction latin1Write (buf, string, offset, length) {\n  return asciiWrite(buf, string, offset, length)\n}\n\nfunction base64Write (buf, string, offset, length) {\n  return blitBuffer(base64ToBytes(string), buf, offset, length)\n}\n\nfunction ucs2Write (buf, string, offset, length) {\n  return blitBuffer(utf16leToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nBuffer.prototype.write = function write (string, offset, length, encoding) {\n  // Buffer#write(string)\n  if (offset === undefined) {\n    encoding = 'utf8'\n    length = this.length\n    offset = 0\n  // Buffer#write(string, encoding)\n  } else if (length === undefined && typeof offset === 'string') {\n    encoding = offset\n    length = this.length\n    offset = 0\n  // Buffer#write(string, offset[, length][, encoding])\n  } else if (isFinite(offset)) {\n    offset = offset | 0\n    if (isFinite(length)) {\n      length = length | 0\n      if (encoding === undefined) encoding = 'utf8'\n    } else {\n      encoding = length\n      length = undefined\n    }\n  // legacy write(string, encoding, offset, length) - remove in v0.13\n  } else {\n    throw new Error(\n      'Buffer.write(string, encoding, offset[, length]) is no longer supported'\n    )\n  }\n\n  var remaining = this.length - offset\n  if (length === undefined || length > remaining) length = remaining\n\n  if ((string.length > 0 && (length < 0 || offset < 0)) || offset > this.length) {\n    throw new RangeError('Attempt to write outside buffer bounds')\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'hex':\n        return hexWrite(this, string, offset, length)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Write(this, string, offset, length)\n\n      case 'ascii':\n        return asciiWrite(this, string, offset, length)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Write(this, string, offset, length)\n\n      case 'base64':\n        // Warning: maxLength not taken into account in base64Write\n        return base64Write(this, string, offset, length)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return ucs2Write(this, string, offset, length)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\nBuffer.prototype.toJSON = function toJSON () {\n  return {\n    type: 'Buffer',\n    data: Array.prototype.slice.call(this._arr || this, 0)\n  }\n}\n\nfunction base64Slice (buf, start, end) {\n  if (start === 0 && end === buf.length) {\n    return base64.fromByteArray(buf)\n  } else {\n    return base64.fromByteArray(buf.slice(start, end))\n  }\n}\n\nfunction utf8Slice (buf, start, end) {\n  end = Math.min(buf.length, end)\n  var res = []\n\n  var i = start\n  while (i < end) {\n    var firstByte = buf[i]\n    var codePoint = null\n    var bytesPerSequence = (firstByte > 0xEF) ? 4\n      : (firstByte > 0xDF) ? 3\n      : (firstByte > 0xBF) ? 2\n      : 1\n\n    if (i + bytesPerSequence <= end) {\n      var secondByte, thirdByte, fourthByte, tempCodePoint\n\n      switch (bytesPerSequence) {\n        case 1:\n          if (firstByte < 0x80) {\n            codePoint = firstByte\n          }\n          break\n        case 2:\n          secondByte = buf[i + 1]\n          if ((secondByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0x1F) << 0x6 | (secondByte & 0x3F)\n            if (tempCodePoint > 0x7F) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 3:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0xC | (secondByte & 0x3F) << 0x6 | (thirdByte & 0x3F)\n            if (tempCodePoint > 0x7FF && (tempCodePoint < 0xD800 || tempCodePoint > 0xDFFF)) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 4:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          fourthByte = buf[i + 3]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80 && (fourthByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0x12 | (secondByte & 0x3F) << 0xC | (thirdByte & 0x3F) << 0x6 | (fourthByte & 0x3F)\n            if (tempCodePoint > 0xFFFF && tempCodePoint < 0x110000) {\n              codePoint = tempCodePoint\n            }\n          }\n      }\n    }\n\n    if (codePoint === null) {\n      // we did not generate a valid codePoint so insert a\n      // replacement char (U+FFFD) and advance only 1 byte\n      codePoint = 0xFFFD\n      bytesPerSequence = 1\n    } else if (codePoint > 0xFFFF) {\n      // encode to utf16 (surrogate pair dance)\n      codePoint -= 0x10000\n      res.push(codePoint >>> 10 & 0x3FF | 0xD800)\n      codePoint = 0xDC00 | codePoint & 0x3FF\n    }\n\n    res.push(codePoint)\n    i += bytesPerSequence\n  }\n\n  return decodeCodePointsArray(res)\n}\n\n// Based on http://stackoverflow.com/a/22747272/680742, the browser with\n// the lowest limit is Chrome, with 0x10000 args.\n// We go 1 magnitude less, for safety\nvar MAX_ARGUMENTS_LENGTH = 0x1000\n\nfunction decodeCodePointsArray (codePoints) {\n  var len = codePoints.length\n  if (len <= MAX_ARGUMENTS_LENGTH) {\n    return String.fromCharCode.apply(String, codePoints) // avoid extra slice()\n  }\n\n  // Decode in chunks to avoid \"call stack size exceeded\".\n  var res = ''\n  var i = 0\n  while (i < len) {\n    res += String.fromCharCode.apply(\n      String,\n      codePoints.slice(i, i += MAX_ARGUMENTS_LENGTH)\n    )\n  }\n  return res\n}\n\nfunction asciiSlice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i] & 0x7F)\n  }\n  return ret\n}\n\nfunction latin1Slice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i])\n  }\n  return ret\n}\n\nfunction hexSlice (buf, start, end) {\n  var len = buf.length\n\n  if (!start || start < 0) start = 0\n  if (!end || end < 0 || end > len) end = len\n\n  var out = ''\n  for (var i = start; i < end; ++i) {\n    out += toHex(buf[i])\n  }\n  return out\n}\n\nfunction utf16leSlice (buf, start, end) {\n  var bytes = buf.slice(start, end)\n  var res = ''\n  for (var i = 0; i < bytes.length; i += 2) {\n    res += String.fromCharCode(bytes[i] + bytes[i + 1] * 256)\n  }\n  return res\n}\n\nBuffer.prototype.slice = function slice (start, end) {\n  var len = this.length\n  start = ~~start\n  end = end === undefined ? len : ~~end\n\n  if (start < 0) {\n    start += len\n    if (start < 0) start = 0\n  } else if (start > len) {\n    start = len\n  }\n\n  if (end < 0) {\n    end += len\n    if (end < 0) end = 0\n  } else if (end > len) {\n    end = len\n  }\n\n  if (end < start) end = start\n\n  var newBuf\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    newBuf = this.subarray(start, end)\n    newBuf.__proto__ = Buffer.prototype\n  } else {\n    var sliceLen = end - start\n    newBuf = new Buffer(sliceLen, undefined)\n    for (var i = 0; i < sliceLen; ++i) {\n      newBuf[i] = this[i + start]\n    }\n  }\n\n  return newBuf\n}\n\n/*\n * Need to make sure that buffer isn't trying to write out of bounds.\n */\nfunction checkOffset (offset, ext, length) {\n  if ((offset % 1) !== 0 || offset < 0) throw new RangeError('offset is not uint')\n  if (offset + ext > length) throw new RangeError('Trying to access beyond buffer length')\n}\n\nBuffer.prototype.readUIntLE = function readUIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUIntBE = function readUIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    checkOffset(offset, byteLength, this.length)\n  }\n\n  var val = this[offset + --byteLength]\n  var mul = 1\n  while (byteLength > 0 && (mul *= 0x100)) {\n    val += this[offset + --byteLength] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUInt8 = function readUInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  return this[offset]\n}\n\nBuffer.prototype.readUInt16LE = function readUInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return this[offset] | (this[offset + 1] << 8)\n}\n\nBuffer.prototype.readUInt16BE = function readUInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return (this[offset] << 8) | this[offset + 1]\n}\n\nBuffer.prototype.readUInt32LE = function readUInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return ((this[offset]) |\n      (this[offset + 1] << 8) |\n      (this[offset + 2] << 16)) +\n      (this[offset + 3] * 0x1000000)\n}\n\nBuffer.prototype.readUInt32BE = function readUInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] * 0x1000000) +\n    ((this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    this[offset + 3])\n}\n\nBuffer.prototype.readIntLE = function readIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readIntBE = function readIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var i = byteLength\n  var mul = 1\n  var val = this[offset + --i]\n  while (i > 0 && (mul *= 0x100)) {\n    val += this[offset + --i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readInt8 = function readInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  if (!(this[offset] & 0x80)) return (this[offset])\n  return ((0xff - this[offset] + 1) * -1)\n}\n\nBuffer.prototype.readInt16LE = function readInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset] | (this[offset + 1] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt16BE = function readInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset + 1] | (this[offset] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt32LE = function readInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset]) |\n    (this[offset + 1] << 8) |\n    (this[offset + 2] << 16) |\n    (this[offset + 3] << 24)\n}\n\nBuffer.prototype.readInt32BE = function readInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] << 24) |\n    (this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    (this[offset + 3])\n}\n\nBuffer.prototype.readFloatLE = function readFloatLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, true, 23, 4)\n}\n\nBuffer.prototype.readFloatBE = function readFloatBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, false, 23, 4)\n}\n\nBuffer.prototype.readDoubleLE = function readDoubleLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, true, 52, 8)\n}\n\nBuffer.prototype.readDoubleBE = function readDoubleBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, false, 52, 8)\n}\n\nfunction checkInt (buf, value, offset, ext, max, min) {\n  if (!Buffer.isBuffer(buf)) throw new TypeError('\"buffer\" argument must be a Buffer instance')\n  if (value > max || value < min) throw new RangeError('\"value\" argument is out of bounds')\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n}\n\nBuffer.prototype.writeUIntLE = function writeUIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var mul = 1\n  var i = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUIntBE = function writeUIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUInt8 = function writeUInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0xff, 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nfunction objectWriteUInt16 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 2); i < j; ++i) {\n    buf[offset + i] = (value & (0xff << (8 * (littleEndian ? i : 1 - i)))) >>>\n      (littleEndian ? i : 1 - i) * 8\n  }\n}\n\nBuffer.prototype.writeUInt16LE = function writeUInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeUInt16BE = function writeUInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nfunction objectWriteUInt32 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffffffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 4); i < j; ++i) {\n    buf[offset + i] = (value >>> (littleEndian ? i : 3 - i) * 8) & 0xff\n  }\n}\n\nBuffer.prototype.writeUInt32LE = function writeUInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset + 3] = (value >>> 24)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 1] = (value >>> 8)\n    this[offset] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeUInt32BE = function writeUInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeIntLE = function writeIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = 0\n  var mul = 1\n  var sub = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i - 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeIntBE = function writeIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  var sub = 0\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i + 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeInt8 = function writeInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0x7f, -0x80)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  if (value < 0) value = 0xff + value + 1\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nBuffer.prototype.writeInt16LE = function writeInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt16BE = function writeInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt32LE = function writeInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 3] = (value >>> 24)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeInt32BE = function writeInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (value < 0) value = 0xffffffff + value + 1\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nfunction checkIEEE754 (buf, value, offset, ext, max, min) {\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n  if (offset < 0) throw new RangeError('Index out of range')\n}\n\nfunction writeFloat (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 4, 3.4028234663852886e+38, -3.4028234663852886e+38)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 23, 4)\n  return offset + 4\n}\n\nBuffer.prototype.writeFloatLE = function writeFloatLE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeFloatBE = function writeFloatBE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, false, noAssert)\n}\n\nfunction writeDouble (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 8, 1.7976931348623157E+308, -1.7976931348623157E+308)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 52, 8)\n  return offset + 8\n}\n\nBuffer.prototype.writeDoubleLE = function writeDoubleLE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeDoubleBE = function writeDoubleBE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, false, noAssert)\n}\n\n// copy(targetBuffer, targetStart=0, sourceStart=0, sourceEnd=buffer.length)\nBuffer.prototype.copy = function copy (target, targetStart, start, end) {\n  if (!start) start = 0\n  if (!end && end !== 0) end = this.length\n  if (targetStart >= target.length) targetStart = target.length\n  if (!targetStart) targetStart = 0\n  if (end > 0 && end < start) end = start\n\n  // Copy 0 bytes; we're done\n  if (end === start) return 0\n  if (target.length === 0 || this.length === 0) return 0\n\n  // Fatal error conditions\n  if (targetStart < 0) {\n    throw new RangeError('targetStart out of bounds')\n  }\n  if (start < 0 || start >= this.length) throw new RangeError('sourceStart out of bounds')\n  if (end < 0) throw new RangeError('sourceEnd out of bounds')\n\n  // Are we oob?\n  if (end > this.length) end = this.length\n  if (target.length - targetStart < end - start) {\n    end = target.length - targetStart + start\n  }\n\n  var len = end - start\n  var i\n\n  if (this === target && start < targetStart && targetStart < end) {\n    // descending copy from end\n    for (i = len - 1; i >= 0; --i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else if (len < 1000 || !Buffer.TYPED_ARRAY_SUPPORT) {\n    // ascending copy from start\n    for (i = 0; i < len; ++i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else {\n    Uint8Array.prototype.set.call(\n      target,\n      this.subarray(start, start + len),\n      targetStart\n    )\n  }\n\n  return len\n}\n\n// Usage:\n//    buffer.fill(number[, offset[, end]])\n//    buffer.fill(buffer[, offset[, end]])\n//    buffer.fill(string[, offset[, end]][, encoding])\nBuffer.prototype.fill = function fill (val, start, end, encoding) {\n  // Handle string cases:\n  if (typeof val === 'string') {\n    if (typeof start === 'string') {\n      encoding = start\n      start = 0\n      end = this.length\n    } else if (typeof end === 'string') {\n      encoding = end\n      end = this.length\n    }\n    if (val.length === 1) {\n      var code = val.charCodeAt(0)\n      if (code < 256) {\n        val = code\n      }\n    }\n    if (encoding !== undefined && typeof encoding !== 'string') {\n      throw new TypeError('encoding must be a string')\n    }\n    if (typeof encoding === 'string' && !Buffer.isEncoding(encoding)) {\n      throw new TypeError('Unknown encoding: ' + encoding)\n    }\n  } else if (typeof val === 'number') {\n    val = val & 255\n  }\n\n  // Invalid ranges are not set to a default, so can range check early.\n  if (start < 0 || this.length < start || this.length < end) {\n    throw new RangeError('Out of range index')\n  }\n\n  if (end <= start) {\n    return this\n  }\n\n  start = start >>> 0\n  end = end === undefined ? this.length : end >>> 0\n\n  if (!val) val = 0\n\n  var i\n  if (typeof val === 'number') {\n    for (i = start; i < end; ++i) {\n      this[i] = val\n    }\n  } else {\n    var bytes = Buffer.isBuffer(val)\n      ? val\n      : utf8ToBytes(new Buffer(val, encoding).toString())\n    var len = bytes.length\n    for (i = 0; i < end - start; ++i) {\n      this[i + start] = bytes[i % len]\n    }\n  }\n\n  return this\n}\n\n// HELPER FUNCTIONS\n// ================\n\nvar INVALID_BASE64_RE = /[^+\\/0-9A-Za-z-_]/g\n\nfunction base64clean (str) {\n  // Node strips out invalid characters like \\n and \\t from the string, base64-js does not\n  str = stringtrim(str).replace(INVALID_BASE64_RE, '')\n  // Node converts strings with length < 2 to ''\n  if (str.length < 2) return ''\n  // Node allows for non-padded base64 strings (missing trailing ===), base64-js does not\n  while (str.length % 4 !== 0) {\n    str = str + '='\n  }\n  return str\n}\n\nfunction stringtrim (str) {\n  if (str.trim) return str.trim()\n  return str.replace(/^\\s+|\\s+$/g, '')\n}\n\nfunction toHex (n) {\n  if (n < 16) return '0' + n.toString(16)\n  return n.toString(16)\n}\n\nfunction utf8ToBytes (string, units) {\n  units = units || Infinity\n  var codePoint\n  var length = string.length\n  var leadSurrogate = null\n  var bytes = []\n\n  for (var i = 0; i < length; ++i) {\n    codePoint = string.charCodeAt(i)\n\n    // is surrogate component\n    if (codePoint > 0xD7FF && codePoint < 0xE000) {\n      // last char was a lead\n      if (!leadSurrogate) {\n        // no lead yet\n        if (codePoint > 0xDBFF) {\n          // unexpected trail\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        } else if (i + 1 === length) {\n          // unpaired lead\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        }\n\n        // valid lead\n        leadSurrogate = codePoint\n\n        continue\n      }\n\n      // 2 leads in a row\n      if (codePoint < 0xDC00) {\n        if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n        leadSurrogate = codePoint\n        continue\n      }\n\n      // valid surrogate pair\n      codePoint = (leadSurrogate - 0xD800 << 10 | codePoint - 0xDC00) + 0x10000\n    } else if (leadSurrogate) {\n      // valid bmp char, but last char was a lead\n      if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n    }\n\n    leadSurrogate = null\n\n    // encode utf8\n    if (codePoint < 0x80) {\n      if ((units -= 1) < 0) break\n      bytes.push(codePoint)\n    } else if (codePoint < 0x800) {\n      if ((units -= 2) < 0) break\n      bytes.push(\n        codePoint >> 0x6 | 0xC0,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x10000) {\n      if ((units -= 3) < 0) break\n      bytes.push(\n        codePoint >> 0xC | 0xE0,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x110000) {\n      if ((units -= 4) < 0) break\n      bytes.push(\n        codePoint >> 0x12 | 0xF0,\n        codePoint >> 0xC & 0x3F | 0x80,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else {\n      throw new Error('Invalid code point')\n    }\n  }\n\n  return bytes\n}\n\nfunction asciiToBytes (str) {\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    // Node's code seems to be doing this and not & 0x7F..\n    byteArray.push(str.charCodeAt(i) & 0xFF)\n  }\n  return byteArray\n}\n\nfunction utf16leToBytes (str, units) {\n  var c, hi, lo\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    if ((units -= 2) < 0) break\n\n    c = str.charCodeAt(i)\n    hi = c >> 8\n    lo = c % 256\n    byteArray.push(lo)\n    byteArray.push(hi)\n  }\n\n  return byteArray\n}\n\nfunction base64ToBytes (str) {\n  return base64.toByteArray(base64clean(str))\n}\n\nfunction blitBuffer (src, dst, offset, length) {\n  for (var i = 0; i < length; ++i) {\n    if ((i + offset >= dst.length) || (i >= src.length)) break\n    dst[i + offset] = src[i]\n  }\n  return i\n}\n\nfunction isnan (val) {\n  return val !== val // eslint-disable-line no-self-compare\n}\n\n/* WEBPACK VAR INJECTION */}.call(this, __webpack_require__(/*! ./../webpack/buildin/global.js */ \"./node_modules/webpack/buildin/global.js\")))\n\n/***/ }),\n\n/***/ \"./node_modules/buffer/node_modules/isarray/index.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/buffer/node_modules/isarray/index.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar toString = {}.toString;\n\nmodule.exports = Array.isArray || function (arr) {\n  return toString.call(arr) == '[object Array]';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/es6/promise.js\":\n/*!*********************************************!*\\\n  !*** ./node_modules/core-js/es6/promise.js ***!\n  \\*********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../modules/es6.object.to-string */ \"./node_modules/core-js/modules/es6.object.to-string.js\");\n__webpack_require__(/*! ../modules/es6.string.iterator */ \"./node_modules/core-js/modules/es6.string.iterator.js\");\n__webpack_require__(/*! ../modules/web.dom.iterable */ \"./node_modules/core-js/modules/web.dom.iterable.js\");\n__webpack_require__(/*! ../modules/es6.promise */ \"./node_modules/core-js/modules/es6.promise.js\");\nmodule.exports = __webpack_require__(/*! ../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Promise;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/array/find.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/fn/array/find.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/es6.array.find */ \"./node_modules/core-js/modules/es6.array.find.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Array.find;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/array/is-array.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/fn/array/is-array.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/es6.array.is-array */ \"./node_modules/core-js/modules/es6.array.is-array.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Array.isArray;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/array/some.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/fn/array/some.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/es6.array.some */ \"./node_modules/core-js/modules/es6.array.some.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Array.some;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/array/splice.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/fn/array/splice.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// for a legacy code and future fixes\nmodule.exports = function () {\n  return Function.call.apply(Array.prototype.splice, arguments);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/function/bind.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/fn/function/bind.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/es6.function.bind */ \"./node_modules/core-js/modules/es6.function.bind.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Function.bind;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/object/assign.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/fn/object/assign.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/es6.object.assign */ \"./node_modules/core-js/modules/es6.object.assign.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").Object.assign;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_a-function.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_a-function.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it) {\n  if (typeof it != 'function') throw TypeError(it + ' is not a function!');\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_add-to-unscopables.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_add-to-unscopables.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.3.31 Array.prototype[@@unscopables]\nvar UNSCOPABLES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('unscopables');\nvar ArrayProto = Array.prototype;\nif (ArrayProto[UNSCOPABLES] == undefined) __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")(ArrayProto, UNSCOPABLES, {});\nmodule.exports = function (key) {\n  ArrayProto[UNSCOPABLES][key] = true;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_an-instance.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_an-instance.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it, Constructor, name, forbiddenField) {\n  if (!(it instanceof Constructor) || (forbiddenField !== undefined && forbiddenField in it)) {\n    throw TypeError(name + ': incorrect invocation!');\n  } return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_an-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_an-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nmodule.exports = function (it) {\n  if (!isObject(it)) throw TypeError(it + ' is not an object!');\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-includes.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-includes.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// false -> Array#indexOf\n// true  -> Array#includes\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nmodule.exports = function (IS_INCLUDES) {\n  return function ($this, el, fromIndex) {\n    var O = toIObject($this);\n    var length = toLength(O.length);\n    var index = toAbsoluteIndex(fromIndex, length);\n    var value;\n    // Array#includes uses SameValueZero equality algorithm\n    // eslint-disable-next-line no-self-compare\n    if (IS_INCLUDES && el != el) while (length > index) {\n      value = O[index++];\n      // eslint-disable-next-line no-self-compare\n      if (value != value) return true;\n    // Array#indexOf ignores holes, Array#includes - not\n    } else for (;length > index; index++) if (IS_INCLUDES || index in O) {\n      if (O[index] === el) return IS_INCLUDES || index || 0;\n    } return !IS_INCLUDES && -1;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-methods.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-methods.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 0 -> Array#forEach\n// 1 -> Array#map\n// 2 -> Array#filter\n// 3 -> Array#some\n// 4 -> Array#every\n// 5 -> Array#find\n// 6 -> Array#findIndex\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar asc = __webpack_require__(/*! ./_array-species-create */ \"./node_modules/core-js/modules/_array-species-create.js\");\nmodule.exports = function (TYPE, $create) {\n  var IS_MAP = TYPE == 1;\n  var IS_FILTER = TYPE == 2;\n  var IS_SOME = TYPE == 3;\n  var IS_EVERY = TYPE == 4;\n  var IS_FIND_INDEX = TYPE == 6;\n  var NO_HOLES = TYPE == 5 || IS_FIND_INDEX;\n  var create = $create || asc;\n  return function ($this, callbackfn, that) {\n    var O = toObject($this);\n    var self = IObject(O);\n    var f = ctx(callbackfn, that, 3);\n    var length = toLength(self.length);\n    var index = 0;\n    var result = IS_MAP ? create($this, length) : IS_FILTER ? create($this, 0) : undefined;\n    var val, res;\n    for (;length > index; index++) if (NO_HOLES || index in self) {\n      val = self[index];\n      res = f(val, index, O);\n      if (TYPE) {\n        if (IS_MAP) result[index] = res;   // map\n        else if (res) switch (TYPE) {\n          case 3: return true;             // some\n          case 5: return val;              // find\n          case 6: return index;            // findIndex\n          case 2: result.push(val);        // filter\n        } else if (IS_EVERY) return false; // every\n      }\n    }\n    return IS_FIND_INDEX ? -1 : IS_SOME || IS_EVERY ? IS_EVERY : result;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-species-constructor.js\":\n/*!********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-species-constructor.js ***!\n  \\********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar isArray = __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\n\nmodule.exports = function (original) {\n  var C;\n  if (isArray(original)) {\n    C = original.constructor;\n    // cross-realm fallback\n    if (typeof C == 'function' && (C === Array || isArray(C.prototype))) C = undefined;\n    if (isObject(C)) {\n      C = C[SPECIES];\n      if (C === null) C = undefined;\n    }\n  } return C === undefined ? Array : C;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-species-create.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-species-create.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 9.4.2.3 ArraySpeciesCreate(originalArray, length)\nvar speciesConstructor = __webpack_require__(/*! ./_array-species-constructor */ \"./node_modules/core-js/modules/_array-species-constructor.js\");\n\nmodule.exports = function (original, length) {\n  return new (speciesConstructor(original))(length);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_bind.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_bind.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar invoke = __webpack_require__(/*! ./_invoke */ \"./node_modules/core-js/modules/_invoke.js\");\nvar arraySlice = [].slice;\nvar factories = {};\n\nvar construct = function (F, len, args) {\n  if (!(len in factories)) {\n    for (var n = [], i = 0; i < len; i++) n[i] = 'a[' + i + ']';\n    // eslint-disable-next-line no-new-func\n    factories[len] = Function('F,a', 'return new F(' + n.join(',') + ')');\n  } return factories[len](F, args);\n};\n\nmodule.exports = Function.bind || function bind(that /* , ...args */) {\n  var fn = aFunction(this);\n  var partArgs = arraySlice.call(arguments, 1);\n  var bound = function (/* args... */) {\n    var args = partArgs.concat(arraySlice.call(arguments));\n    return this instanceof bound ? construct(fn, args.length, args) : invoke(fn, args, that);\n  };\n  if (isObject(fn.prototype)) bound.prototype = fn.prototype;\n  return bound;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_classof.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_classof.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// getting tag from 19.1.3.6 Object.prototype.toString()\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nvar TAG = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag');\n// ES3 wrong here\nvar ARG = cof(function () { return arguments; }()) == 'Arguments';\n\n// fallback for IE11 Script Access Denied error\nvar tryGet = function (it, key) {\n  try {\n    return it[key];\n  } catch (e) { /* empty */ }\n};\n\nmodule.exports = function (it) {\n  var O, T, B;\n  return it === undefined ? 'Undefined' : it === null ? 'Null'\n    // @@toStringTag case\n    : typeof (T = tryGet(O = Object(it), TAG)) == 'string' ? T\n    // builtinTag case\n    : ARG ? cof(O)\n    // ES3 arguments fallback\n    : (B = cof(O)) == 'Object' && typeof O.callee == 'function' ? 'Arguments' : B;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_cof.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_cof.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar toString = {}.toString;\n\nmodule.exports = function (it) {\n  return toString.call(it).slice(8, -1);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_core.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_core.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar core = module.exports = { version: '2.6.4' };\nif (typeof __e == 'number') __e = core; // eslint-disable-line no-undef\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_ctx.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_ctx.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// optional / simple context binding\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nmodule.exports = function (fn, that, length) {\n  aFunction(fn);\n  if (that === undefined) return fn;\n  switch (length) {\n    case 1: return function (a) {\n      return fn.call(that, a);\n    };\n    case 2: return function (a, b) {\n      return fn.call(that, a, b);\n    };\n    case 3: return function (a, b, c) {\n      return fn.call(that, a, b, c);\n    };\n  }\n  return function (/* ...args */) {\n    return fn.apply(that, arguments);\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_defined.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_defined.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 7.2.1 RequireObjectCoercible(argument)\nmodule.exports = function (it) {\n  if (it == undefined) throw TypeError(\"Can't call method on  \" + it);\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_descriptors.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_descriptors.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// Thank's IE8 for his funny defineProperty\nmodule.exports = !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return Object.defineProperty({}, 'a', { get: function () { return 7; } }).a != 7;\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_dom-create.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_dom-create.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar document = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").document;\n// typeof document.createElement is 'object' in old IE\nvar is = isObject(document) && isObject(document.createElement);\nmodule.exports = function (it) {\n  return is ? document.createElement(it) : {};\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_enum-bug-keys.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_enum-bug-keys.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// IE 8- don't enum bug keys\nmodule.exports = (\n  'constructor,hasOwnProperty,isPrototypeOf,propertyIsEnumerable,toLocaleString,toString,valueOf'\n).split(',');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_export.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_export.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar PROTOTYPE = 'prototype';\n\nvar $export = function (type, name, source) {\n  var IS_FORCED = type & $export.F;\n  var IS_GLOBAL = type & $export.G;\n  var IS_STATIC = type & $export.S;\n  var IS_PROTO = type & $export.P;\n  var IS_BIND = type & $export.B;\n  var target = IS_GLOBAL ? global : IS_STATIC ? global[name] || (global[name] = {}) : (global[name] || {})[PROTOTYPE];\n  var exports = IS_GLOBAL ? core : core[name] || (core[name] = {});\n  var expProto = exports[PROTOTYPE] || (exports[PROTOTYPE] = {});\n  var key, own, out, exp;\n  if (IS_GLOBAL) source = name;\n  for (key in source) {\n    // contains in native\n    own = !IS_FORCED && target && target[key] !== undefined;\n    // export native or passed\n    out = (own ? target : source)[key];\n    // bind timers to global for call from export context\n    exp = IS_BIND && own ? ctx(out, global) : IS_PROTO && typeof out == 'function' ? ctx(Function.call, out) : out;\n    // extend global\n    if (target) redefine(target, key, out, type & $export.U);\n    // export\n    if (exports[key] != out) hide(exports, key, exp);\n    if (IS_PROTO && expProto[key] != out) expProto[key] = out;\n  }\n};\nglobal.core = core;\n// type bitmap\n$export.F = 1;   // forced\n$export.G = 2;   // global\n$export.S = 4;   // static\n$export.P = 8;   // proto\n$export.B = 16;  // bind\n$export.W = 32;  // wrap\n$export.U = 64;  // safe\n$export.R = 128; // real proto method for `library`\nmodule.exports = $export;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_fails.js\":\n/*!************************************************!*\\\n  !*** ./node_modules/core-js/modules/_fails.js ***!\n  \\************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (exec) {\n  try {\n    return !!exec();\n  } catch (e) {\n    return true;\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_for-of.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_for-of.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar call = __webpack_require__(/*! ./_iter-call */ \"./node_modules/core-js/modules/_iter-call.js\");\nvar isArrayIter = __webpack_require__(/*! ./_is-array-iter */ \"./node_modules/core-js/modules/_is-array-iter.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar getIterFn = __webpack_require__(/*! ./core.get-iterator-method */ \"./node_modules/core-js/modules/core.get-iterator-method.js\");\nvar BREAK = {};\nvar RETURN = {};\nvar exports = module.exports = function (iterable, entries, fn, that, ITERATOR) {\n  var iterFn = ITERATOR ? function () { return iterable; } : getIterFn(iterable);\n  var f = ctx(fn, that, entries ? 2 : 1);\n  var index = 0;\n  var length, step, iterator, result;\n  if (typeof iterFn != 'function') throw TypeError(iterable + ' is not iterable!');\n  // fast case for arrays with default iterator\n  if (isArrayIter(iterFn)) for (length = toLength(iterable.length); length > index; index++) {\n    result = entries ? f(anObject(step = iterable[index])[0], step[1]) : f(iterable[index]);\n    if (result === BREAK || result === RETURN) return result;\n  } else for (iterator = iterFn.call(iterable); !(step = iterator.next()).done;) {\n    result = call(iterator, f, step.value, entries);\n    if (result === BREAK || result === RETURN) return result;\n  }\n};\nexports.BREAK = BREAK;\nexports.RETURN = RETURN;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_function-to-string.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_function-to-string.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nmodule.exports = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('native-function-to-string', Function.toString);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_global.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_global.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// https://github.com/zloirock/core-js/issues/86#issuecomment-115759028\nvar global = module.exports = typeof window != 'undefined' && window.Math == Math\n  ? window : typeof self != 'undefined' && self.Math == Math ? self\n  // eslint-disable-next-line no-new-func\n  : Function('return this')();\nif (typeof __g == 'number') __g = global; // eslint-disable-line no-undef\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_has.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_has.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar hasOwnProperty = {}.hasOwnProperty;\nmodule.exports = function (it, key) {\n  return hasOwnProperty.call(it, key);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_hide.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_hide.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nmodule.exports = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? function (object, key, value) {\n  return dP.f(object, key, createDesc(1, value));\n} : function (object, key, value) {\n  object[key] = value;\n  return object;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_html.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_html.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar document = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").document;\nmodule.exports = document && document.documentElement;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_ie8-dom-define.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_ie8-dom-define.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nmodule.exports = !__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return Object.defineProperty(__webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\")('div'), 'a', { get: function () { return 7; } }).a != 7;\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_invoke.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_invoke.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// fast apply, http://jsperf.lnkit.com/fast-apply/5\nmodule.exports = function (fn, args, that) {\n  var un = that === undefined;\n  switch (args.length) {\n    case 0: return un ? fn()\n                      : fn.call(that);\n    case 1: return un ? fn(args[0])\n                      : fn.call(that, args[0]);\n    case 2: return un ? fn(args[0], args[1])\n                      : fn.call(that, args[0], args[1]);\n    case 3: return un ? fn(args[0], args[1], args[2])\n                      : fn.call(that, args[0], args[1], args[2]);\n    case 4: return un ? fn(args[0], args[1], args[2], args[3])\n                      : fn.call(that, args[0], args[1], args[2], args[3]);\n  } return fn.apply(that, args);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iobject.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iobject.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// fallback for non-array-like ES3 and non-enumerable old V8 strings\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\n// eslint-disable-next-line no-prototype-builtins\nmodule.exports = Object('z').propertyIsEnumerable(0) ? Object : function (it) {\n  return cof(it) == 'String' ? it.split('') : Object(it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-array-iter.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-array-iter.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// check on default Array iterator\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar ArrayProto = Array.prototype;\n\nmodule.exports = function (it) {\n  return it !== undefined && (Iterators.Array === it || ArrayProto[ITERATOR] === it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-array.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-array.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.2.2 IsArray(argument)\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nmodule.exports = Array.isArray || function isArray(arg) {\n  return cof(arg) == 'Array';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it) {\n  return typeof it === 'object' ? it !== null : typeof it === 'function';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-call.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-call.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// call something on iterator step with safe closing on error\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nmodule.exports = function (iterator, fn, value, entries) {\n  try {\n    return entries ? fn(anObject(value)[0], value[1]) : fn(value);\n  // 7.4.6 IteratorClose(iterator, completion)\n  } catch (e) {\n    var ret = iterator['return'];\n    if (ret !== undefined) anObject(ret.call(iterator));\n    throw e;\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-create.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-create.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\nvar descriptor = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar IteratorPrototype = {};\n\n// 25.1.2.1.1 %IteratorPrototype%[@@iterator]()\n__webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")(IteratorPrototype, __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator'), function () { return this; });\n\nmodule.exports = function (Constructor, NAME, next) {\n  Constructor.prototype = create(IteratorPrototype, { next: descriptor(1, next) });\n  setToStringTag(Constructor, NAME + ' Iterator');\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-define.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-define.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar $iterCreate = __webpack_require__(/*! ./_iter-create */ \"./node_modules/core-js/modules/_iter-create.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar BUGGY = !([].keys && 'next' in [].keys()); // Safari has buggy iterators w/o `next`\nvar FF_ITERATOR = '@@iterator';\nvar KEYS = 'keys';\nvar VALUES = 'values';\n\nvar returnThis = function () { return this; };\n\nmodule.exports = function (Base, NAME, Constructor, next, DEFAULT, IS_SET, FORCED) {\n  $iterCreate(Constructor, NAME, next);\n  var getMethod = function (kind) {\n    if (!BUGGY && kind in proto) return proto[kind];\n    switch (kind) {\n      case KEYS: return function keys() { return new Constructor(this, kind); };\n      case VALUES: return function values() { return new Constructor(this, kind); };\n    } return function entries() { return new Constructor(this, kind); };\n  };\n  var TAG = NAME + ' Iterator';\n  var DEF_VALUES = DEFAULT == VALUES;\n  var VALUES_BUG = false;\n  var proto = Base.prototype;\n  var $native = proto[ITERATOR] || proto[FF_ITERATOR] || DEFAULT && proto[DEFAULT];\n  var $default = $native || getMethod(DEFAULT);\n  var $entries = DEFAULT ? !DEF_VALUES ? $default : getMethod('entries') : undefined;\n  var $anyNative = NAME == 'Array' ? proto.entries || $native : $native;\n  var methods, key, IteratorPrototype;\n  // Fix native\n  if ($anyNative) {\n    IteratorPrototype = getPrototypeOf($anyNative.call(new Base()));\n    if (IteratorPrototype !== Object.prototype && IteratorPrototype.next) {\n      // Set @@toStringTag to native iterators\n      setToStringTag(IteratorPrototype, TAG, true);\n      // fix for some old engines\n      if (!LIBRARY && typeof IteratorPrototype[ITERATOR] != 'function') hide(IteratorPrototype, ITERATOR, returnThis);\n    }\n  }\n  // fix Array#{values, @@iterator}.name in V8 / FF\n  if (DEF_VALUES && $native && $native.name !== VALUES) {\n    VALUES_BUG = true;\n    $default = function values() { return $native.call(this); };\n  }\n  // Define iterator\n  if ((!LIBRARY || FORCED) && (BUGGY || VALUES_BUG || !proto[ITERATOR])) {\n    hide(proto, ITERATOR, $default);\n  }\n  // Plug for library\n  Iterators[NAME] = $default;\n  Iterators[TAG] = returnThis;\n  if (DEFAULT) {\n    methods = {\n      values: DEF_VALUES ? $default : getMethod(VALUES),\n      keys: IS_SET ? $default : getMethod(KEYS),\n      entries: $entries\n    };\n    if (FORCED) for (key in methods) {\n      if (!(key in proto)) redefine(proto, key, methods[key]);\n    } else $export($export.P + $export.F * (BUGGY || VALUES_BUG), NAME, methods);\n  }\n  return methods;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-detect.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-detect.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar SAFE_CLOSING = false;\n\ntry {\n  var riter = [7][ITERATOR]();\n  riter['return'] = function () { SAFE_CLOSING = true; };\n  // eslint-disable-next-line no-throw-literal\n  Array.from(riter, function () { throw 2; });\n} catch (e) { /* empty */ }\n\nmodule.exports = function (exec, skipClosing) {\n  if (!skipClosing && !SAFE_CLOSING) return false;\n  var safe = false;\n  try {\n    var arr = [7];\n    var iter = arr[ITERATOR]();\n    iter.next = function () { return { done: safe = true }; };\n    arr[ITERATOR] = function () { return iter; };\n    exec(arr);\n  } catch (e) { /* empty */ }\n  return safe;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-step.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-step.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (done, value) {\n  return { value: value, done: !!done };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iterators.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iterators.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = {};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_library.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_library.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = false;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_microtask.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_microtask.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar macrotask = __webpack_require__(/*! ./_task */ \"./node_modules/core-js/modules/_task.js\").set;\nvar Observer = global.MutationObserver || global.WebKitMutationObserver;\nvar process = global.process;\nvar Promise = global.Promise;\nvar isNode = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\")(process) == 'process';\n\nmodule.exports = function () {\n  var head, last, notify;\n\n  var flush = function () {\n    var parent, fn;\n    if (isNode && (parent = process.domain)) parent.exit();\n    while (head) {\n      fn = head.fn;\n      head = head.next;\n      try {\n        fn();\n      } catch (e) {\n        if (head) notify();\n        else last = undefined;\n        throw e;\n      }\n    } last = undefined;\n    if (parent) parent.enter();\n  };\n\n  // Node.js\n  if (isNode) {\n    notify = function () {\n      process.nextTick(flush);\n    };\n  // browsers with MutationObserver, except iOS Safari - https://github.com/zloirock/core-js/issues/339\n  } else if (Observer && !(global.navigator && global.navigator.standalone)) {\n    var toggle = true;\n    var node = document.createTextNode('');\n    new Observer(flush).observe(node, { characterData: true }); // eslint-disable-line no-new\n    notify = function () {\n      node.data = toggle = !toggle;\n    };\n  // environments with maybe non-completely correct, but existent Promise\n  } else if (Promise && Promise.resolve) {\n    // Promise.resolve without an argument throws an error in LG WebOS 2\n    var promise = Promise.resolve(undefined);\n    notify = function () {\n      promise.then(flush);\n    };\n  // for other environments - macrotask based on:\n  // - setImmediate\n  // - MessageChannel\n  // - window.postMessag\n  // - onreadystatechange\n  // - setTimeout\n  } else {\n    notify = function () {\n      // strange IE + webpack dev server bug - use .call(global)\n      macrotask.call(global, flush);\n    };\n  }\n\n  return function (fn) {\n    var task = { fn: fn, next: undefined };\n    if (last) last.next = task;\n    if (!head) {\n      head = task;\n      notify();\n    } last = task;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_new-promise-capability.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_new-promise-capability.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 25.4.1.5 NewPromiseCapability(C)\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\n\nfunction PromiseCapability(C) {\n  var resolve, reject;\n  this.promise = new C(function ($$resolve, $$reject) {\n    if (resolve !== undefined || reject !== undefined) throw TypeError('Bad Promise constructor');\n    resolve = $$resolve;\n    reject = $$reject;\n  });\n  this.resolve = aFunction(resolve);\n  this.reject = aFunction(reject);\n}\n\nmodule.exports.f = function (C) {\n  return new PromiseCapability(C);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-assign.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-assign.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 19.1.2.1 Object.assign(target, source, ...)\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar gOPS = __webpack_require__(/*! ./_object-gops */ \"./node_modules/core-js/modules/_object-gops.js\");\nvar pIE = __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar $assign = Object.assign;\n\n// should work with symbols and should have deterministic property order (V8 bug)\nmodule.exports = !$assign || __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  var A = {};\n  var B = {};\n  // eslint-disable-next-line no-undef\n  var S = Symbol();\n  var K = 'abcdefghijklmnopqrst';\n  A[S] = 7;\n  K.split('').forEach(function (k) { B[k] = k; });\n  return $assign({}, A)[S] != 7 || Object.keys($assign({}, B)).join('') != K;\n}) ? function assign(target, source) { // eslint-disable-line no-unused-vars\n  var T = toObject(target);\n  var aLen = arguments.length;\n  var index = 1;\n  var getSymbols = gOPS.f;\n  var isEnum = pIE.f;\n  while (aLen > index) {\n    var S = IObject(arguments[index++]);\n    var keys = getSymbols ? getKeys(S).concat(getSymbols(S)) : getKeys(S);\n    var length = keys.length;\n    var j = 0;\n    var key;\n    while (length > j) if (isEnum.call(S, key = keys[j++])) T[key] = S[key];\n  } return T;\n} : $assign;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-create.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-create.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar dPs = __webpack_require__(/*! ./_object-dps */ \"./node_modules/core-js/modules/_object-dps.js\");\nvar enumBugKeys = __webpack_require__(/*! ./_enum-bug-keys */ \"./node_modules/core-js/modules/_enum-bug-keys.js\");\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\nvar Empty = function () { /* empty */ };\nvar PROTOTYPE = 'prototype';\n\n// Create object with fake `null` prototype: use iframe Object with cleared prototype\nvar createDict = function () {\n  // Thrash, waste and sodomy: IE GC bug\n  var iframe = __webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\")('iframe');\n  var i = enumBugKeys.length;\n  var lt = '<';\n  var gt = '>';\n  var iframeDocument;\n  iframe.style.display = 'none';\n  __webpack_require__(/*! ./_html */ \"./node_modules/core-js/modules/_html.js\").appendChild(iframe);\n  iframe.src = 'javascript:'; // eslint-disable-line no-script-url\n  // createDict = iframe.contentWindow.Object;\n  // html.removeChild(iframe);\n  iframeDocument = iframe.contentWindow.document;\n  iframeDocument.open();\n  iframeDocument.write(lt + 'script' + gt + 'document.F=Object' + lt + '/script' + gt);\n  iframeDocument.close();\n  createDict = iframeDocument.F;\n  while (i--) delete createDict[PROTOTYPE][enumBugKeys[i]];\n  return createDict();\n};\n\nmodule.exports = Object.create || function create(O, Properties) {\n  var result;\n  if (O !== null) {\n    Empty[PROTOTYPE] = anObject(O);\n    result = new Empty();\n    Empty[PROTOTYPE] = null;\n    // add \"__proto__\" for Object.getPrototypeOf polyfill\n    result[IE_PROTO] = O;\n  } else result = createDict();\n  return Properties === undefined ? result : dPs(result, Properties);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-dp.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-dp.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar IE8_DOM_DEFINE = __webpack_require__(/*! ./_ie8-dom-define */ \"./node_modules/core-js/modules/_ie8-dom-define.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar dP = Object.defineProperty;\n\nexports.f = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? Object.defineProperty : function defineProperty(O, P, Attributes) {\n  anObject(O);\n  P = toPrimitive(P, true);\n  anObject(Attributes);\n  if (IE8_DOM_DEFINE) try {\n    return dP(O, P, Attributes);\n  } catch (e) { /* empty */ }\n  if ('get' in Attributes || 'set' in Attributes) throw TypeError('Accessors not supported!');\n  if ('value' in Attributes) O[P] = Attributes.value;\n  return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-dps.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-dps.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\n\nmodule.exports = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? Object.defineProperties : function defineProperties(O, Properties) {\n  anObject(O);\n  var keys = getKeys(Properties);\n  var length = keys.length;\n  var i = 0;\n  var P;\n  while (length > i) dP.f(O, P = keys[i++], Properties[P]);\n  return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gops.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gops.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.f = Object.getOwnPropertySymbols;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gpo.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gpo.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.9 / 15.2.3.2 Object.getPrototypeOf(O)\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\nvar ObjectProto = Object.prototype;\n\nmodule.exports = Object.getPrototypeOf || function (O) {\n  O = toObject(O);\n  if (has(O, IE_PROTO)) return O[IE_PROTO];\n  if (typeof O.constructor == 'function' && O instanceof O.constructor) {\n    return O.constructor.prototype;\n  } return O instanceof Object ? ObjectProto : null;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-keys-internal.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-keys-internal.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar arrayIndexOf = __webpack_require__(/*! ./_array-includes */ \"./node_modules/core-js/modules/_array-includes.js\")(false);\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\n\nmodule.exports = function (object, names) {\n  var O = toIObject(object);\n  var i = 0;\n  var result = [];\n  var key;\n  for (key in O) if (key != IE_PROTO) has(O, key) && result.push(key);\n  // Don't enum bug & hidden keys\n  while (names.length > i) if (has(O, key = names[i++])) {\n    ~arrayIndexOf(result, key) || result.push(key);\n  }\n  return result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-keys.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-keys.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.14 / 15.2.3.14 Object.keys(O)\nvar $keys = __webpack_require__(/*! ./_object-keys-internal */ \"./node_modules/core-js/modules/_object-keys-internal.js\");\nvar enumBugKeys = __webpack_require__(/*! ./_enum-bug-keys */ \"./node_modules/core-js/modules/_enum-bug-keys.js\");\n\nmodule.exports = Object.keys || function keys(O) {\n  return $keys(O, enumBugKeys);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-pie.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-pie.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.f = {}.propertyIsEnumerable;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_perform.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_perform.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (exec) {\n  try {\n    return { e: false, v: exec() };\n  } catch (e) {\n    return { e: true, v: e };\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_promise-resolve.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_promise-resolve.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar newPromiseCapability = __webpack_require__(/*! ./_new-promise-capability */ \"./node_modules/core-js/modules/_new-promise-capability.js\");\n\nmodule.exports = function (C, x) {\n  anObject(C);\n  if (isObject(x) && x.constructor === C) return x;\n  var promiseCapability = newPromiseCapability.f(C);\n  var resolve = promiseCapability.resolve;\n  resolve(x);\n  return promiseCapability.promise;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_property-desc.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_property-desc.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (bitmap, value) {\n  return {\n    enumerable: !(bitmap & 1),\n    configurable: !(bitmap & 2),\n    writable: !(bitmap & 4),\n    value: value\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_redefine-all.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_redefine-all.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nmodule.exports = function (target, src, safe) {\n  for (var key in src) redefine(target, key, src[key], safe);\n  return target;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_redefine.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_redefine.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar SRC = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\")('src');\nvar $toString = __webpack_require__(/*! ./_function-to-string */ \"./node_modules/core-js/modules/_function-to-string.js\");\nvar TO_STRING = 'toString';\nvar TPL = ('' + $toString).split(TO_STRING);\n\n__webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\").inspectSource = function (it) {\n  return $toString.call(it);\n};\n\n(module.exports = function (O, key, val, safe) {\n  var isFunction = typeof val == 'function';\n  if (isFunction) has(val, 'name') || hide(val, 'name', key);\n  if (O[key] === val) return;\n  if (isFunction) has(val, SRC) || hide(val, SRC, O[key] ? '' + O[key] : TPL.join(String(key)));\n  if (O === global) {\n    O[key] = val;\n  } else if (!safe) {\n    delete O[key];\n    hide(O, key, val);\n  } else if (O[key]) {\n    O[key] = val;\n  } else {\n    hide(O, key, val);\n  }\n// add fake Function#toString for correct work wrapped methods / constructors with methods like LoDash isNative\n})(Function.prototype, TO_STRING, function toString() {\n  return typeof this == 'function' && this[SRC] || $toString.call(this);\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-species.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-species.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\n\nmodule.exports = function (KEY) {\n  var C = global[KEY];\n  if (DESCRIPTORS && C && !C[SPECIES]) dP.f(C, SPECIES, {\n    configurable: true,\n    get: function () { return this; }\n  });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-to-string-tag.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-to-string-tag.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar def = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar TAG = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag');\n\nmodule.exports = function (it, tag, stat) {\n  if (it && !has(it = stat ? it : it.prototype, TAG)) def(it, TAG, { configurable: true, value: tag });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_shared-key.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_shared-key.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar shared = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('keys');\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nmodule.exports = function (key) {\n  return shared[key] || (shared[key] = uid(key));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_shared.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_shared.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar SHARED = '__core-js_shared__';\nvar store = global[SHARED] || (global[SHARED] = {});\n\n(module.exports = function (key, value) {\n  return store[key] || (store[key] = value !== undefined ? value : {});\n})('versions', []).push({\n  version: core.version,\n  mode: __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\") ? 'pure' : 'global',\n  copyright: '© 2019 Denis Pushkarev (zloirock.ru)'\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_species-constructor.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_species-constructor.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.3.20 SpeciesConstructor(O, defaultConstructor)\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\nmodule.exports = function (O, D) {\n  var C = anObject(O).constructor;\n  var S;\n  return C === undefined || (S = anObject(C)[SPECIES]) == undefined ? D : aFunction(S);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_strict-method.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_strict-method.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\n\nmodule.exports = function (method, arg) {\n  return !!method && fails(function () {\n    // eslint-disable-next-line no-useless-call\n    arg ? method.call(null, function () { /* empty */ }, 1) : method.call(null);\n  });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-at.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-at.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\n// true  -> String#at\n// false -> String#codePointAt\nmodule.exports = function (TO_STRING) {\n  return function (that, pos) {\n    var s = String(defined(that));\n    var i = toInteger(pos);\n    var l = s.length;\n    var a, b;\n    if (i < 0 || i >= l) return TO_STRING ? '' : undefined;\n    a = s.charCodeAt(i);\n    return a < 0xd800 || a > 0xdbff || i + 1 === l || (b = s.charCodeAt(i + 1)) < 0xdc00 || b > 0xdfff\n      ? TO_STRING ? s.charAt(i) : a\n      : TO_STRING ? s.slice(i, i + 2) : (a - 0xd800 << 10) + (b - 0xdc00) + 0x10000;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_task.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_task.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar invoke = __webpack_require__(/*! ./_invoke */ \"./node_modules/core-js/modules/_invoke.js\");\nvar html = __webpack_require__(/*! ./_html */ \"./node_modules/core-js/modules/_html.js\");\nvar cel = __webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar process = global.process;\nvar setTask = global.setImmediate;\nvar clearTask = global.clearImmediate;\nvar MessageChannel = global.MessageChannel;\nvar Dispatch = global.Dispatch;\nvar counter = 0;\nvar queue = {};\nvar ONREADYSTATECHANGE = 'onreadystatechange';\nvar defer, channel, port;\nvar run = function () {\n  var id = +this;\n  // eslint-disable-next-line no-prototype-builtins\n  if (queue.hasOwnProperty(id)) {\n    var fn = queue[id];\n    delete queue[id];\n    fn();\n  }\n};\nvar listener = function (event) {\n  run.call(event.data);\n};\n// Node.js 0.9+ & IE10+ has setImmediate, otherwise:\nif (!setTask || !clearTask) {\n  setTask = function setImmediate(fn) {\n    var args = [];\n    var i = 1;\n    while (arguments.length > i) args.push(arguments[i++]);\n    queue[++counter] = function () {\n      // eslint-disable-next-line no-new-func\n      invoke(typeof fn == 'function' ? fn : Function(fn), args);\n    };\n    defer(counter);\n    return counter;\n  };\n  clearTask = function clearImmediate(id) {\n    delete queue[id];\n  };\n  // Node.js 0.8-\n  if (__webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\")(process) == 'process') {\n    defer = function (id) {\n      process.nextTick(ctx(run, id, 1));\n    };\n  // Sphere (JS game engine) Dispatch API\n  } else if (Dispatch && Dispatch.now) {\n    defer = function (id) {\n      Dispatch.now(ctx(run, id, 1));\n    };\n  // Browsers with MessageChannel, includes WebWorkers\n  } else if (MessageChannel) {\n    channel = new MessageChannel();\n    port = channel.port2;\n    channel.port1.onmessage = listener;\n    defer = ctx(port.postMessage, port, 1);\n  // Browsers with postMessage, skip WebWorkers\n  // IE8 has postMessage, but it's sync & typeof its postMessage is 'object'\n  } else if (global.addEventListener && typeof postMessage == 'function' && !global.importScripts) {\n    defer = function (id) {\n      global.postMessage(id + '', '*');\n    };\n    global.addEventListener('message', listener, false);\n  // IE8-\n  } else if (ONREADYSTATECHANGE in cel('script')) {\n    defer = function (id) {\n      html.appendChild(cel('script'))[ONREADYSTATECHANGE] = function () {\n        html.removeChild(this);\n        run.call(id);\n      };\n    };\n  // Rest old browsers\n  } else {\n    defer = function (id) {\n      setTimeout(ctx(run, id, 1), 0);\n    };\n  }\n}\nmodule.exports = {\n  set: setTask,\n  clear: clearTask\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-absolute-index.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-absolute-index.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar max = Math.max;\nvar min = Math.min;\nmodule.exports = function (index, length) {\n  index = toInteger(index);\n  return index < 0 ? max(index + length, 0) : min(index, length);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-integer.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-integer.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 7.1.4 ToInteger\nvar ceil = Math.ceil;\nvar floor = Math.floor;\nmodule.exports = function (it) {\n  return isNaN(it = +it) ? 0 : (it > 0 ? floor : ceil)(it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-iobject.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-iobject.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// to indexed object, toObject with fallback for non-array-like ES3 strings\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nmodule.exports = function (it) {\n  return IObject(defined(it));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-length.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-length.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.15 ToLength\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar min = Math.min;\nmodule.exports = function (it) {\n  return it > 0 ? min(toInteger(it), 0x1fffffffffffff) : 0; // pow(2, 53) - 1 == 9007199254740991\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.13 ToObject(argument)\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nmodule.exports = function (it) {\n  return Object(defined(it));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-primitive.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-primitive.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.1 ToPrimitive(input [, PreferredType])\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n// instead of the ES6 spec version, we didn't implement @@toPrimitive case\n// and the second argument - flag - preferred type is a string\nmodule.exports = function (it, S) {\n  if (!isObject(it)) return it;\n  var fn, val;\n  if (S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (typeof (fn = it.valueOf) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (!S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  throw TypeError(\"Can't convert object to primitive value\");\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_uid.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_uid.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar id = 0;\nvar px = Math.random();\nmodule.exports = function (key) {\n  return 'Symbol('.concat(key === undefined ? '' : key, ')_', (++id + px).toString(36));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_user-agent.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_user-agent.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar navigator = global.navigator;\n\nmodule.exports = navigator && navigator.userAgent || '';\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_wks.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_wks.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar store = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('wks');\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nvar Symbol = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").Symbol;\nvar USE_SYMBOL = typeof Symbol == 'function';\n\nvar $exports = module.exports = function (name) {\n  return store[name] || (store[name] =\n    USE_SYMBOL && Symbol[name] || (USE_SYMBOL ? Symbol : uid)('Symbol.' + name));\n};\n\n$exports.store = store;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/core.get-iterator-method.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/core.get-iterator-method.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nmodule.exports = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\").getIteratorMethod = function (it) {\n  if (it != undefined) return it[ITERATOR]\n    || it['@@iterator']\n    || Iterators[classof(it)];\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.find.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.find.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 22.1.3.8 Array.prototype.find(predicate, thisArg = undefined)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $find = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(5);\nvar KEY = 'find';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  find: function find(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")(KEY);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.is-array.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.is-array.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.2.2 / 15.4.3.2 Array.isArray(arg)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Array', { isArray: __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.iterator.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.iterator.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar addToUnscopables = __webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\");\nvar step = __webpack_require__(/*! ./_iter-step */ \"./node_modules/core-js/modules/_iter-step.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\n\n// 22.1.3.4 Array.prototype.entries()\n// 22.1.3.13 Array.prototype.keys()\n// 22.1.3.29 Array.prototype.values()\n// 22.1.3.30 Array.prototype[@@iterator]()\nmodule.exports = __webpack_require__(/*! ./_iter-define */ \"./node_modules/core-js/modules/_iter-define.js\")(Array, 'Array', function (iterated, kind) {\n  this._t = toIObject(iterated); // target\n  this._i = 0;                   // next index\n  this._k = kind;                // kind\n// 22.1.5.2.1 %ArrayIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var kind = this._k;\n  var index = this._i++;\n  if (!O || index >= O.length) {\n    this._t = undefined;\n    return step(1);\n  }\n  if (kind == 'keys') return step(0, index);\n  if (kind == 'values') return step(0, O[index]);\n  return step(0, [index, O[index]]);\n}, 'values');\n\n// argumentsList[@@iterator] is %ArrayProto_values% (9.4.4.6, 9.4.4.7)\nIterators.Arguments = Iterators.Array;\n\naddToUnscopables('keys');\naddToUnscopables('values');\naddToUnscopables('entries');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.some.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.some.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $some = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(3);\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].some, true), 'Array', {\n  // 22.1.3.23 / 15.4.4.17 Array.prototype.some(callbackfn [, thisArg])\n  some: function some(callbackfn /* , thisArg */) {\n    return $some(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.function.bind.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.function.bind.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.2.3.2 / 15.3.4.5 Function.prototype.bind(thisArg, args...)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P, 'Function', { bind: __webpack_require__(/*! ./_bind */ \"./node_modules/core-js/modules/_bind.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.assign.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.assign.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.3.1 Object.assign(target, source)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S + $export.F, 'Object', { assign: __webpack_require__(/*! ./_object-assign */ \"./node_modules/core-js/modules/_object-assign.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.to-string.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.to-string.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 19.1.3.6 Object.prototype.toString()\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar test = {};\ntest[__webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag')] = 'z';\nif (test + '' != '[object z]') {\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(Object.prototype, 'toString', function toString() {\n    return '[object ' + classof(this) + ']';\n  }, true);\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.promise.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.promise.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\nvar task = __webpack_require__(/*! ./_task */ \"./node_modules/core-js/modules/_task.js\").set;\nvar microtask = __webpack_require__(/*! ./_microtask */ \"./node_modules/core-js/modules/_microtask.js\")();\nvar newPromiseCapabilityModule = __webpack_require__(/*! ./_new-promise-capability */ \"./node_modules/core-js/modules/_new-promise-capability.js\");\nvar perform = __webpack_require__(/*! ./_perform */ \"./node_modules/core-js/modules/_perform.js\");\nvar userAgent = __webpack_require__(/*! ./_user-agent */ \"./node_modules/core-js/modules/_user-agent.js\");\nvar promiseResolve = __webpack_require__(/*! ./_promise-resolve */ \"./node_modules/core-js/modules/_promise-resolve.js\");\nvar PROMISE = 'Promise';\nvar TypeError = global.TypeError;\nvar process = global.process;\nvar versions = process && process.versions;\nvar v8 = versions && versions.v8 || '';\nvar $Promise = global[PROMISE];\nvar isNode = classof(process) == 'process';\nvar empty = function () { /* empty */ };\nvar Internal, newGenericPromiseCapability, OwnPromiseCapability, Wrapper;\nvar newPromiseCapability = newGenericPromiseCapability = newPromiseCapabilityModule.f;\n\nvar USE_NATIVE = !!function () {\n  try {\n    // correct subclassing with @@species support\n    var promise = $Promise.resolve(1);\n    var FakePromise = (promise.constructor = {})[__webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species')] = function (exec) {\n      exec(empty, empty);\n    };\n    // unhandled rejections tracking support, NodeJS Promise without it fails @@species test\n    return (isNode || typeof PromiseRejectionEvent == 'function')\n      && promise.then(empty) instanceof FakePromise\n      // v8 6.6 (Node 10 and Chrome 66) have a bug with resolving custom thenables\n      // https://bugs.chromium.org/p/chromium/issues/detail?id=830565\n      // we can't detect it synchronously, so just check versions\n      && v8.indexOf('6.6') !== 0\n      && userAgent.indexOf('Chrome/66') === -1;\n  } catch (e) { /* empty */ }\n}();\n\n// helpers\nvar isThenable = function (it) {\n  var then;\n  return isObject(it) && typeof (then = it.then) == 'function' ? then : false;\n};\nvar notify = function (promise, isReject) {\n  if (promise._n) return;\n  promise._n = true;\n  var chain = promise._c;\n  microtask(function () {\n    var value = promise._v;\n    var ok = promise._s == 1;\n    var i = 0;\n    var run = function (reaction) {\n      var handler = ok ? reaction.ok : reaction.fail;\n      var resolve = reaction.resolve;\n      var reject = reaction.reject;\n      var domain = reaction.domain;\n      var result, then, exited;\n      try {\n        if (handler) {\n          if (!ok) {\n            if (promise._h == 2) onHandleUnhandled(promise);\n            promise._h = 1;\n          }\n          if (handler === true) result = value;\n          else {\n            if (domain) domain.enter();\n            result = handler(value); // may throw\n            if (domain) {\n              domain.exit();\n              exited = true;\n            }\n          }\n          if (result === reaction.promise) {\n            reject(TypeError('Promise-chain cycle'));\n          } else if (then = isThenable(result)) {\n            then.call(result, resolve, reject);\n          } else resolve(result);\n        } else reject(value);\n      } catch (e) {\n        if (domain && !exited) domain.exit();\n        reject(e);\n      }\n    };\n    while (chain.length > i) run(chain[i++]); // variable length - can't use forEach\n    promise._c = [];\n    promise._n = false;\n    if (isReject && !promise._h) onUnhandled(promise);\n  });\n};\nvar onUnhandled = function (promise) {\n  task.call(global, function () {\n    var value = promise._v;\n    var unhandled = isUnhandled(promise);\n    var result, handler, console;\n    if (unhandled) {\n      result = perform(function () {\n        if (isNode) {\n          process.emit('unhandledRejection', value, promise);\n        } else if (handler = global.onunhandledrejection) {\n          handler({ promise: promise, reason: value });\n        } else if ((console = global.console) && console.error) {\n          console.error('Unhandled promise rejection', value);\n        }\n      });\n      // Browsers should not trigger `rejectionHandled` event if it was handled here, NodeJS - should\n      promise._h = isNode || isUnhandled(promise) ? 2 : 1;\n    } promise._a = undefined;\n    if (unhandled && result.e) throw result.v;\n  });\n};\nvar isUnhandled = function (promise) {\n  return promise._h !== 1 && (promise._a || promise._c).length === 0;\n};\nvar onHandleUnhandled = function (promise) {\n  task.call(global, function () {\n    var handler;\n    if (isNode) {\n      process.emit('rejectionHandled', promise);\n    } else if (handler = global.onrejectionhandled) {\n      handler({ promise: promise, reason: promise._v });\n    }\n  });\n};\nvar $reject = function (value) {\n  var promise = this;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  promise._v = value;\n  promise._s = 2;\n  if (!promise._a) promise._a = promise._c.slice();\n  notify(promise, true);\n};\nvar $resolve = function (value) {\n  var promise = this;\n  var then;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  try {\n    if (promise === value) throw TypeError(\"Promise can't be resolved itself\");\n    if (then = isThenable(value)) {\n      microtask(function () {\n        var wrapper = { _w: promise, _d: false }; // wrap\n        try {\n          then.call(value, ctx($resolve, wrapper, 1), ctx($reject, wrapper, 1));\n        } catch (e) {\n          $reject.call(wrapper, e);\n        }\n      });\n    } else {\n      promise._v = value;\n      promise._s = 1;\n      notify(promise, false);\n    }\n  } catch (e) {\n    $reject.call({ _w: promise, _d: false }, e); // wrap\n  }\n};\n\n// constructor polyfill\nif (!USE_NATIVE) {\n  // 25.4.3.1 Promise(executor)\n  $Promise = function Promise(executor) {\n    anInstance(this, $Promise, PROMISE, '_h');\n    aFunction(executor);\n    Internal.call(this);\n    try {\n      executor(ctx($resolve, this, 1), ctx($reject, this, 1));\n    } catch (err) {\n      $reject.call(this, err);\n    }\n  };\n  // eslint-disable-next-line no-unused-vars\n  Internal = function Promise(executor) {\n    this._c = [];             // <- awaiting reactions\n    this._a = undefined;      // <- checked in isUnhandled reactions\n    this._s = 0;              // <- state\n    this._d = false;          // <- done\n    this._v = undefined;      // <- value\n    this._h = 0;              // <- rejection state, 0 - default, 1 - handled, 2 - unhandled\n    this._n = false;          // <- notify\n  };\n  Internal.prototype = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\")($Promise.prototype, {\n    // 25.4.5.3 Promise.prototype.then(onFulfilled, onRejected)\n    then: function then(onFulfilled, onRejected) {\n      var reaction = newPromiseCapability(speciesConstructor(this, $Promise));\n      reaction.ok = typeof onFulfilled == 'function' ? onFulfilled : true;\n      reaction.fail = typeof onRejected == 'function' && onRejected;\n      reaction.domain = isNode ? process.domain : undefined;\n      this._c.push(reaction);\n      if (this._a) this._a.push(reaction);\n      if (this._s) notify(this, false);\n      return reaction.promise;\n    },\n    // 25.4.5.1 Promise.prototype.catch(onRejected)\n    'catch': function (onRejected) {\n      return this.then(undefined, onRejected);\n    }\n  });\n  OwnPromiseCapability = function () {\n    var promise = new Internal();\n    this.promise = promise;\n    this.resolve = ctx($resolve, promise, 1);\n    this.reject = ctx($reject, promise, 1);\n  };\n  newPromiseCapabilityModule.f = newPromiseCapability = function (C) {\n    return C === $Promise || C === Wrapper\n      ? new OwnPromiseCapability(C)\n      : newGenericPromiseCapability(C);\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Promise: $Promise });\n__webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\")($Promise, PROMISE);\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")(PROMISE);\nWrapper = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\")[PROMISE];\n\n// statics\n$export($export.S + $export.F * !USE_NATIVE, PROMISE, {\n  // 25.4.4.5 Promise.reject(r)\n  reject: function reject(r) {\n    var capability = newPromiseCapability(this);\n    var $$reject = capability.reject;\n    $$reject(r);\n    return capability.promise;\n  }\n});\n$export($export.S + $export.F * (LIBRARY || !USE_NATIVE), PROMISE, {\n  // 25.4.4.6 Promise.resolve(x)\n  resolve: function resolve(x) {\n    return promiseResolve(LIBRARY && this === Wrapper ? $Promise : this, x);\n  }\n});\n$export($export.S + $export.F * !(USE_NATIVE && __webpack_require__(/*! ./_iter-detect */ \"./node_modules/core-js/modules/_iter-detect.js\")(function (iter) {\n  $Promise.all(iter)['catch'](empty);\n})), PROMISE, {\n  // 25.4.4.1 Promise.all(iterable)\n  all: function all(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var resolve = capability.resolve;\n    var reject = capability.reject;\n    var result = perform(function () {\n      var values = [];\n      var index = 0;\n      var remaining = 1;\n      forOf(iterable, false, function (promise) {\n        var $index = index++;\n        var alreadyCalled = false;\n        values.push(undefined);\n        remaining++;\n        C.resolve(promise).then(function (value) {\n          if (alreadyCalled) return;\n          alreadyCalled = true;\n          values[$index] = value;\n          --remaining || resolve(values);\n        }, reject);\n      });\n      --remaining || resolve(values);\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  },\n  // 25.4.4.4 Promise.race(iterable)\n  race: function race(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var reject = capability.reject;\n    var result = perform(function () {\n      forOf(iterable, false, function (promise) {\n        C.resolve(promise).then(capability.resolve, reject);\n      });\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.iterator.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.iterator.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $at = __webpack_require__(/*! ./_string-at */ \"./node_modules/core-js/modules/_string-at.js\")(true);\n\n// 21.1.3.27 String.prototype[@@iterator]()\n__webpack_require__(/*! ./_iter-define */ \"./node_modules/core-js/modules/_iter-define.js\")(String, 'String', function (iterated) {\n  this._t = String(iterated); // target\n  this._i = 0;                // next index\n// 21.1.5.2.1 %StringIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var index = this._i;\n  var point;\n  if (index >= O.length) return { value: undefined, done: true };\n  point = $at(O, index);\n  this._i += point.length;\n  return { value: point, done: false };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/web.dom.iterable.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/web.dom.iterable.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $iterators = __webpack_require__(/*! ./es6.array.iterator */ \"./node_modules/core-js/modules/es6.array.iterator.js\");\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar wks = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\nvar ITERATOR = wks('iterator');\nvar TO_STRING_TAG = wks('toStringTag');\nvar ArrayValues = Iterators.Array;\n\nvar DOMIterables = {\n  CSSRuleList: true, // TODO: Not spec compliant, should be false.\n  CSSStyleDeclaration: false,\n  CSSValueList: false,\n  ClientRectList: false,\n  DOMRectList: false,\n  DOMStringList: false,\n  DOMTokenList: true,\n  DataTransferItemList: false,\n  FileList: false,\n  HTMLAllCollection: false,\n  HTMLCollection: false,\n  HTMLFormElement: false,\n  HTMLSelectElement: false,\n  MediaList: true, // TODO: Not spec compliant, should be false.\n  MimeTypeArray: false,\n  NamedNodeMap: false,\n  NodeList: true,\n  PaintRequestList: false,\n  Plugin: false,\n  PluginArray: false,\n  SVGLengthList: false,\n  SVGNumberList: false,\n  SVGPathSegList: false,\n  SVGPointList: false,\n  SVGStringList: false,\n  SVGTransformList: false,\n  SourceBufferList: false,\n  StyleSheetList: true, // TODO: Not spec compliant, should be false.\n  TextTrackCueList: false,\n  TextTrackList: false,\n  TouchList: false\n};\n\nfor (var collections = getKeys(DOMIterables), i = 0; i < collections.length; i++) {\n  var NAME = collections[i];\n  var explicit = DOMIterables[NAME];\n  var Collection = global[NAME];\n  var proto = Collection && Collection.prototype;\n  var key;\n  if (proto) {\n    if (!proto[ITERATOR]) hide(proto, ITERATOR, ArrayValues);\n    if (!proto[TO_STRING_TAG]) hide(proto, TO_STRING_TAG, NAME);\n    Iterators[NAME] = ArrayValues;\n    if (explicit) for (key in $iterators) if (!proto[key]) redefine(proto, key, $iterators[key], true);\n  }\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/ieee754/index.js\":\n/*!***************************************!*\\\n  !*** ./node_modules/ieee754/index.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.read = function (buffer, offset, isLE, mLen, nBytes) {\n  var e, m\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var nBits = -7\n  var i = isLE ? (nBytes - 1) : 0\n  var d = isLE ? -1 : 1\n  var s = buffer[offset + i]\n\n  i += d\n\n  e = s & ((1 << (-nBits)) - 1)\n  s >>= (-nBits)\n  nBits += eLen\n  for (; nBits > 0; e = (e * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  m = e & ((1 << (-nBits)) - 1)\n  e >>= (-nBits)\n  nBits += mLen\n  for (; nBits > 0; m = (m * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  if (e === 0) {\n    e = 1 - eBias\n  } else if (e === eMax) {\n    return m ? NaN : ((s ? -1 : 1) * Infinity)\n  } else {\n    m = m + Math.pow(2, mLen)\n    e = e - eBias\n  }\n  return (s ? -1 : 1) * m * Math.pow(2, e - mLen)\n}\n\nexports.write = function (buffer, value, offset, isLE, mLen, nBytes) {\n  var e, m, c\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var rt = (mLen === 23 ? Math.pow(2, -24) - Math.pow(2, -77) : 0)\n  var i = isLE ? 0 : (nBytes - 1)\n  var d = isLE ? 1 : -1\n  var s = value < 0 || (value === 0 && 1 / value < 0) ? 1 : 0\n\n  value = Math.abs(value)\n\n  if (isNaN(value) || value === Infinity) {\n    m = isNaN(value) ? 1 : 0\n    e = eMax\n  } else {\n    e = Math.floor(Math.log(value) / Math.LN2)\n    if (value * (c = Math.pow(2, -e)) < 1) {\n      e--\n      c *= 2\n    }\n    if (e + eBias >= 1) {\n      value += rt / c\n    } else {\n      value += rt * Math.pow(2, 1 - eBias)\n    }\n    if (value * c >= 2) {\n      e++\n      c /= 2\n    }\n\n    if (e + eBias >= eMax) {\n      m = 0\n      e = eMax\n    } else if (e + eBias >= 1) {\n      m = ((value * c) - 1) * Math.pow(2, mLen)\n      e = e + eBias\n    } else {\n      m = value * Math.pow(2, eBias - 1) * Math.pow(2, mLen)\n      e = 0\n    }\n  }\n\n  for (; mLen >= 8; buffer[offset + i] = m & 0xff, i += d, m /= 256, mLen -= 8) {}\n\n  e = (e << mLen) | m\n  eLen += mLen\n  for (; eLen > 0; buffer[offset + i] = e & 0xff, i += d, e /= 256, eLen -= 8) {}\n\n  buffer[offset + i - d] |= s * 128\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/lib/bytesToUuid.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/uuid/lib/bytesToUuid.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n/**\n * Convert array of 16 byte values to UUID string format of the form:\n * XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX\n */\nvar byteToHex = [];\nfor (var i = 0; i < 256; ++i) {\n  byteToHex[i] = (i + 0x100).toString(16).substr(1);\n}\n\nfunction bytesToUuid(buf, offset) {\n  var i = offset || 0;\n  var bth = byteToHex;\n  // join used to fix memory issue caused by concatenation: https://bugs.chromium.org/p/v8/issues/detail?id=3175#c4\n  return ([bth[buf[i++]], bth[buf[i++]], \n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]]]).join('');\n}\n\nmodule.exports = bytesToUuid;\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/lib/rng-browser.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/uuid/lib/rng-browser.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// Unique ID creation requires a high quality random # generator.  In the\n// browser this is a little complicated due to unknown quality of Math.random()\n// and inconsistent support for the `crypto` API.  We do the best we can via\n// feature-detection\n\n// getRandomValues needs to be invoked in a context where \"this\" is a Crypto\n// implementation. Also, find the complete implementation of crypto on IE11.\nvar getRandomValues = (typeof(crypto) != 'undefined' && crypto.getRandomValues && crypto.getRandomValues.bind(crypto)) ||\n                      (typeof(msCrypto) != 'undefined' && typeof window.msCrypto.getRandomValues == 'function' && msCrypto.getRandomValues.bind(msCrypto));\n\nif (getRandomValues) {\n  // WHATWG crypto RNG - http://wiki.whatwg.org/wiki/Crypto\n  var rnds8 = new Uint8Array(16); // eslint-disable-line no-undef\n\n  module.exports = function whatwgRNG() {\n    getRandomValues(rnds8);\n    return rnds8;\n  };\n} else {\n  // Math.random()-based (RNG)\n  //\n  // If all else fails, use Math.random().  It's fast, but is of unspecified\n  // quality.\n  var rnds = new Array(16);\n\n  module.exports = function mathRNG() {\n    for (var i = 0, r; i < 16; i++) {\n      if ((i & 0x03) === 0) r = Math.random() * 0x100000000;\n      rnds[i] = r >>> ((i & 0x03) << 3) & 0xff;\n    }\n\n    return rnds;\n  };\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/v4.js\":\n/*!*********************************!*\\\n  !*** ./node_modules/uuid/v4.js ***!\n  \\*********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar rng = __webpack_require__(/*! ./lib/rng */ \"./node_modules/uuid/lib/rng-browser.js\");\nvar bytesToUuid = __webpack_require__(/*! ./lib/bytesToUuid */ \"./node_modules/uuid/lib/bytesToUuid.js\");\n\nfunction v4(options, buf, offset) {\n  var i = buf && offset || 0;\n\n  if (typeof(options) == 'string') {\n    buf = options === 'binary' ? new Array(16) : null;\n    options = null;\n  }\n  options = options || {};\n\n  var rnds = options.random || (options.rng || rng)();\n\n  // Per 4.4, set bits for version and `clock_seq_hi_and_reserved`\n  rnds[6] = (rnds[6] & 0x0f) | 0x40;\n  rnds[8] = (rnds[8] & 0x3f) | 0x80;\n\n  // Copy bytes to buffer, if provided\n  if (buf) {\n    for (var ii = 0; ii < 16; ++ii) {\n      buf[i + ii] = rnds[ii];\n    }\n  }\n\n  return buf || bytesToUuid(rnds);\n}\n\nmodule.exports = v4;\n\n\n/***/ }),\n\n/***/ \"./node_modules/webpack/buildin/global.js\":\n/*!***********************************!*\\\n  !*** (webpack)/buildin/global.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar g;\n\n// This works in non-strict mode\ng = (function() {\n\treturn this;\n})();\n\ntry {\n\t// This works if eval is allowed (see CSP)\n\tg = g || new Function(\"return this\")();\n} catch (e) {\n\t// This works if the window reference is available\n\tif (typeof window === \"object\") g = window;\n}\n\n// g can still be undefined, but nothing to do about it...\n// We return undefined, instead of nothing here, so it's\n// easier to handle this case. if(!global) { ...}\n\nmodule.exports = g;\n\n\n/***/ }),\n\n/***/ \"./polyfills.js\":\n/*!**********************!*\\\n  !*** ./polyfills.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\n__webpack_require__(/*! core-js/es6/promise */ \"./node_modules/core-js/es6/promise.js\");\n\n__webpack_require__(/*! core-js/fn/function/bind */ \"./node_modules/core-js/fn/function/bind.js\");\n\n__webpack_require__(/*! core-js/fn/object/assign */ \"./node_modules/core-js/fn/object/assign.js\");\n\n__webpack_require__(/*! core-js/fn/array/find */ \"./node_modules/core-js/fn/array/find.js\");\n\n__webpack_require__(/*! core-js/fn/array/some */ \"./node_modules/core-js/fn/array/some.js\");\n\n__webpack_require__(/*! core-js/fn/array/is-array */ \"./node_modules/core-js/fn/array/is-array.js\");\n\n__webpack_require__(/*! core-js/fn/array/splice */ \"./node_modules/core-js/fn/array/splice.js\");\n\n/***/ }),\n\n/***/ \"./src/AccessTokenEvents.js\":\n/*!**********************************!*\\\n  !*** ./src/AccessTokenEvents.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.AccessTokenEvents = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Timer = __webpack_require__(/*! ./Timer.js */ \"./src/Timer.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultAccessTokenExpiringNotificationTime = 60; // seconds\n\nvar AccessTokenEvents = exports.AccessTokenEvents = function () {\n    function AccessTokenEvents() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            _ref$accessTokenExpir = _ref.accessTokenExpiringNotificationTime,\n            accessTokenExpiringNotificationTime = _ref$accessTokenExpir === undefined ? DefaultAccessTokenExpiringNotificationTime : _ref$accessTokenExpir,\n            _ref$accessTokenExpir2 = _ref.accessTokenExpiringTimer,\n            accessTokenExpiringTimer = _ref$accessTokenExpir2 === undefined ? new _Timer.Timer(\"Access token expiring\") : _ref$accessTokenExpir2,\n            _ref$accessTokenExpir3 = _ref.accessTokenExpiredTimer,\n            accessTokenExpiredTimer = _ref$accessTokenExpir3 === undefined ? new _Timer.Timer(\"Access token expired\") : _ref$accessTokenExpir3;\n\n        _classCallCheck(this, AccessTokenEvents);\n\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\n\n        this._accessTokenExpiring = accessTokenExpiringTimer;\n        this._accessTokenExpired = accessTokenExpiredTimer;\n    }\n\n    AccessTokenEvents.prototype.load = function load(container) {\n        // only register events if there's an access token and it has an expiration\n        if (container.access_token && container.expires_in !== undefined) {\n            var duration = container.expires_in;\n            _Log.Log.debug(\"AccessTokenEvents.load: access token present, remaining duration:\", duration);\n\n            if (duration > 0) {\n                // only register expiring if we still have time\n                var expiring = duration - this._accessTokenExpiringNotificationTime;\n                if (expiring <= 0) {\n                    expiring = 1;\n                }\n\n                _Log.Log.debug(\"AccessTokenEvents.load: registering expiring timer in:\", expiring);\n                this._accessTokenExpiring.init(expiring);\n            } else {\n                _Log.Log.debug(\"AccessTokenEvents.load: canceling existing expiring timer becase we're past expiration.\");\n                this._accessTokenExpiring.cancel();\n            }\n\n            // if it's negative, it will still fire\n            var expired = duration + 1;\n            _Log.Log.debug(\"AccessTokenEvents.load: registering expired timer in:\", expired);\n            this._accessTokenExpired.init(expired);\n        } else {\n            this._accessTokenExpiring.cancel();\n            this._accessTokenExpired.cancel();\n        }\n    };\n\n    AccessTokenEvents.prototype.unload = function unload() {\n        _Log.Log.debug(\"AccessTokenEvents.unload: canceling existing access token timers\");\n        this._accessTokenExpiring.cancel();\n        this._accessTokenExpired.cancel();\n    };\n\n    AccessTokenEvents.prototype.addAccessTokenExpiring = function addAccessTokenExpiring(cb) {\n        this._accessTokenExpiring.addHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.removeAccessTokenExpiring = function removeAccessTokenExpiring(cb) {\n        this._accessTokenExpiring.removeHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.addAccessTokenExpired = function addAccessTokenExpired(cb) {\n        this._accessTokenExpired.addHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.removeAccessTokenExpired = function removeAccessTokenExpired(cb) {\n        this._accessTokenExpired.removeHandler(cb);\n    };\n\n    return AccessTokenEvents;\n}();\n\n/***/ }),\n\n/***/ \"./src/CheckSessionIFrame.js\":\n/*!***********************************!*\\\n  !*** ./src/CheckSessionIFrame.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CheckSessionIFrame = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultInterval = 2000;\n\nvar CheckSessionIFrame = exports.CheckSessionIFrame = function () {\n    function CheckSessionIFrame(callback, client_id, url, interval) {\n        var stopOnError = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : true;\n\n        _classCallCheck(this, CheckSessionIFrame);\n\n        this._callback = callback;\n        this._client_id = client_id;\n        this._url = url;\n        this._interval = interval || DefaultInterval;\n        this._stopOnError = stopOnError;\n\n        var idx = url.indexOf(\"/\", url.indexOf(\"//\") + 2);\n        this._frame_origin = url.substr(0, idx);\n\n        this._frame = window.document.createElement(\"iframe\");\n\n        // shotgun approach\n        this._frame.style.visibility = \"hidden\";\n        this._frame.style.position = \"absolute\";\n        this._frame.style.display = \"none\";\n        this._frame.style.width = 0;\n        this._frame.style.height = 0;\n\n        this._frame.src = url;\n    }\n\n    CheckSessionIFrame.prototype.load = function load() {\n        var _this = this;\n\n        return new Promise(function (resolve) {\n            _this._frame.onload = function () {\n                resolve();\n            };\n\n            window.document.body.appendChild(_this._frame);\n            _this._boundMessageEvent = _this._message.bind(_this);\n            window.addEventListener(\"message\", _this._boundMessageEvent, false);\n        });\n    };\n\n    CheckSessionIFrame.prototype._message = function _message(e) {\n        if (e.origin === this._frame_origin && e.source === this._frame.contentWindow) {\n            if (e.data === \"error\") {\n                _Log.Log.error(\"CheckSessionIFrame: error message from check session op iframe\");\n                if (this._stopOnError) {\n                    this.stop();\n                }\n            } else if (e.data === \"changed\") {\n                _Log.Log.debug(\"CheckSessionIFrame: changed message from check session op iframe\");\n                this.stop();\n                this._callback();\n            } else {\n                _Log.Log.debug(\"CheckSessionIFrame: \" + e.data + \" message from check session op iframe\");\n            }\n        }\n    };\n\n    CheckSessionIFrame.prototype.start = function start(session_state) {\n        var _this2 = this;\n\n        if (this._session_state !== session_state) {\n            _Log.Log.debug(\"CheckSessionIFrame.start\");\n\n            this.stop();\n\n            this._session_state = session_state;\n\n            var send = function send() {\n                _this2._frame.contentWindow.postMessage(_this2._client_id + \" \" + _this2._session_state, _this2._frame_origin);\n            };\n\n            // trigger now\n            send();\n\n            // and setup timer\n            this._timer = window.setInterval(send, this._interval);\n        }\n    };\n\n    CheckSessionIFrame.prototype.stop = function stop() {\n        this._session_state = null;\n\n        if (this._timer) {\n            _Log.Log.debug(\"CheckSessionIFrame.stop\");\n\n            window.clearInterval(this._timer);\n            this._timer = null;\n        }\n    };\n\n    return CheckSessionIFrame;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaIFrameNavigator.js\":\n/*!***************************************!*\\\n  !*** ./src/CordovaIFrameNavigator.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaIFrameNavigator = undefined;\n\nvar _CordovaPopupWindow = __webpack_require__(/*! ./CordovaPopupWindow.js */ \"./src/CordovaPopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar CordovaIFrameNavigator = exports.CordovaIFrameNavigator = function () {\n    function CordovaIFrameNavigator() {\n        _classCallCheck(this, CordovaIFrameNavigator);\n    }\n\n    CordovaIFrameNavigator.prototype.prepare = function prepare(params) {\n        params.popupWindowFeatures = 'hidden=yes';\n        var popup = new _CordovaPopupWindow.CordovaPopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    return CordovaIFrameNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaPopupNavigator.js\":\n/*!**************************************!*\\\n  !*** ./src/CordovaPopupNavigator.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaPopupNavigator = undefined;\n\nvar _CordovaPopupWindow = __webpack_require__(/*! ./CordovaPopupWindow.js */ \"./src/CordovaPopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar CordovaPopupNavigator = exports.CordovaPopupNavigator = function () {\n    function CordovaPopupNavigator() {\n        _classCallCheck(this, CordovaPopupNavigator);\n    }\n\n    CordovaPopupNavigator.prototype.prepare = function prepare(params) {\n        var popup = new _CordovaPopupWindow.CordovaPopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    return CordovaPopupNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaPopupWindow.js\":\n/*!***********************************!*\\\n  !*** ./src/CordovaPopupWindow.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaPopupWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar DefaultPopupFeatures = 'location=no,toolbar=no,zoom=no';\nvar DefaultPopupTarget = \"_blank\";\n\nvar CordovaPopupWindow = exports.CordovaPopupWindow = function () {\n    function CordovaPopupWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, CordovaPopupWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        this.features = params.popupWindowFeatures || DefaultPopupFeatures;\n        this.target = params.popupWindowTarget || DefaultPopupTarget;\n\n        this.redirect_uri = params.startUrl;\n        _Log.Log.debug(\"CordovaPopupWindow.ctor: redirect_uri: \" + this.redirect_uri);\n    }\n\n    CordovaPopupWindow.prototype._isInAppBrowserInstalled = function _isInAppBrowserInstalled(cordovaMetadata) {\n        return [\"cordova-plugin-inappbrowser\", \"cordova-plugin-inappbrowser.inappbrowser\", \"org.apache.cordova.inappbrowser\"].some(function (name) {\n            return cordovaMetadata.hasOwnProperty(name);\n        });\n    };\n\n    CordovaPopupWindow.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            this._error(\"No url provided\");\n        } else {\n            if (!window.cordova) {\n                return this._error(\"cordova is undefined\");\n            }\n\n            var cordovaMetadata = window.cordova.require(\"cordova/plugin_list\").metadata;\n            if (this._isInAppBrowserInstalled(cordovaMetadata) === false) {\n                return this._error(\"InAppBrowser plugin not found\");\n            }\n            this._popup = cordova.InAppBrowser.open(params.url, this.target, this.features);\n            if (this._popup) {\n                _Log.Log.debug(\"CordovaPopupWindow.navigate: popup successfully created\");\n\n                this._exitCallbackEvent = this._exitCallback.bind(this);\n                this._loadStartCallbackEvent = this._loadStartCallback.bind(this);\n\n                this._popup.addEventListener(\"exit\", this._exitCallbackEvent, false);\n                this._popup.addEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\n            } else {\n                this._error(\"Error opening popup window\");\n            }\n        }\n        return this.promise;\n    };\n\n    CordovaPopupWindow.prototype._loadStartCallback = function _loadStartCallback(event) {\n        if (event.url.indexOf(this.redirect_uri) === 0) {\n            this._success({ url: event.url });\n        }\n    };\n\n    CordovaPopupWindow.prototype._exitCallback = function _exitCallback(message) {\n        this._error(message);\n    };\n\n    CordovaPopupWindow.prototype._success = function _success(data) {\n        this._cleanup();\n\n        _Log.Log.debug(\"CordovaPopupWindow: Successful response from cordova popup window\");\n        this._resolve(data);\n    };\n\n    CordovaPopupWindow.prototype._error = function _error(message) {\n        this._cleanup();\n\n        _Log.Log.error(message);\n        this._reject(new Error(message));\n    };\n\n    CordovaPopupWindow.prototype.close = function close() {\n        this._cleanup();\n    };\n\n    CordovaPopupWindow.prototype._cleanup = function _cleanup() {\n        if (this._popup) {\n            _Log.Log.debug(\"CordovaPopupWindow: cleaning up popup\");\n            this._popup.removeEventListener(\"exit\", this._exitCallbackEvent, false);\n            this._popup.removeEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\n            this._popup.close();\n        }\n        this._popup = null;\n    };\n\n    _createClass(CordovaPopupWindow, [{\n        key: 'promise',\n        get: function get() {\n            return this._promise;\n        }\n    }]);\n\n    return CordovaPopupWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/ErrorResponse.js\":\n/*!******************************!*\\\n  !*** ./src/ErrorResponse.js ***!\n  \\******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n        value: true\n});\nexports.ErrorResponse = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar ErrorResponse = exports.ErrorResponse = function (_Error) {\n        _inherits(ErrorResponse, _Error);\n\n        function ErrorResponse() {\n                var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n                    error = _ref.error,\n                    error_description = _ref.error_description,\n                    error_uri = _ref.error_uri,\n                    state = _ref.state,\n                    session_state = _ref.session_state;\n\n                _classCallCheck(this, ErrorResponse);\n\n                if (!error) {\n                        _Log.Log.error(\"No error passed to ErrorResponse\");\n                        throw new Error(\"error\");\n                }\n\n                var _this = _possibleConstructorReturn(this, _Error.call(this, error_description || error));\n\n                _this.name = \"ErrorResponse\";\n\n                _this.error = error;\n                _this.error_description = error_description;\n                _this.error_uri = error_uri;\n\n                _this.state = state;\n                _this.session_state = session_state;\n                return _this;\n        }\n\n        return ErrorResponse;\n}(Error);\n\n/***/ }),\n\n/***/ \"./src/Event.js\":\n/*!**********************!*\\\n  !*** ./src/Event.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.Event = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar Event = exports.Event = function () {\n    function Event(name) {\n        _classCallCheck(this, Event);\n\n        this._name = name;\n        this._callbacks = [];\n    }\n\n    Event.prototype.addHandler = function addHandler(cb) {\n        this._callbacks.push(cb);\n    };\n\n    Event.prototype.removeHandler = function removeHandler(cb) {\n        var idx = this._callbacks.findIndex(function (item) {\n            return item === cb;\n        });\n        if (idx >= 0) {\n            this._callbacks.splice(idx, 1);\n        }\n    };\n\n    Event.prototype.raise = function raise() {\n        _Log.Log.debug(\"Event: Raising event: \" + this._name);\n        for (var i = 0; i < this._callbacks.length; i++) {\n            var _callbacks;\n\n            (_callbacks = this._callbacks)[i].apply(_callbacks, arguments);\n        }\n    };\n\n    return Event;\n}();\n\n/***/ }),\n\n/***/ \"./src/Global.js\":\n/*!***********************!*\\\n  !*** ./src/Global.js ***!\n  \\***********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar timer = {\n    setInterval: function (_setInterval) {\n        function setInterval(_x, _x2) {\n            return _setInterval.apply(this, arguments);\n        }\n\n        setInterval.toString = function () {\n            return _setInterval.toString();\n        };\n\n        return setInterval;\n    }(function (cb, duration) {\n        return setInterval(cb, duration);\n    }),\n    clearInterval: function (_clearInterval) {\n        function clearInterval(_x3) {\n            return _clearInterval.apply(this, arguments);\n        }\n\n        clearInterval.toString = function () {\n            return _clearInterval.toString();\n        };\n\n        return clearInterval;\n    }(function (handle) {\n        return clearInterval(handle);\n    })\n};\n\nvar testing = false;\nvar request = null;\n\nvar Global = exports.Global = function () {\n    function Global() {\n        _classCallCheck(this, Global);\n    }\n\n    Global._testing = function _testing() {\n        testing = true;\n    };\n\n    Global.setXMLHttpRequest = function setXMLHttpRequest(newRequest) {\n        request = newRequest;\n    };\n\n    _createClass(Global, null, [{\n        key: 'location',\n        get: function get() {\n            if (!testing) {\n                return location;\n            }\n        }\n    }, {\n        key: 'localStorage',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return localStorage;\n            }\n        }\n    }, {\n        key: 'sessionStorage',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return sessionStorage;\n            }\n        }\n    }, {\n        key: 'XMLHttpRequest',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return request || XMLHttpRequest;\n            }\n        }\n    }, {\n        key: 'timer',\n        get: function get() {\n            if (!testing) {\n                return timer;\n            }\n        }\n    }]);\n\n    return Global;\n}();\n\n/***/ }),\n\n/***/ \"./src/IFrameNavigator.js\":\n/*!********************************!*\\\n  !*** ./src/IFrameNavigator.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.IFrameNavigator = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _IFrameWindow = __webpack_require__(/*! ./IFrameWindow.js */ \"./src/IFrameWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar IFrameNavigator = exports.IFrameNavigator = function () {\n    function IFrameNavigator() {\n        _classCallCheck(this, IFrameNavigator);\n    }\n\n    IFrameNavigator.prototype.prepare = function prepare(params) {\n        var frame = new _IFrameWindow.IFrameWindow(params);\n        return Promise.resolve(frame);\n    };\n\n    IFrameNavigator.prototype.callback = function callback(url) {\n        _Log.Log.debug(\"IFrameNavigator.callback\");\n\n        try {\n            _IFrameWindow.IFrameWindow.notifyParent(url);\n            return Promise.resolve();\n        } catch (e) {\n            return Promise.reject(e);\n        }\n    };\n\n    return IFrameNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/IFrameWindow.js\":\n/*!*****************************!*\\\n  !*** ./src/IFrameWindow.js ***!\n  \\*****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.IFrameWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar DefaultTimeout = 10000;\n\nvar IFrameWindow = exports.IFrameWindow = function () {\n    function IFrameWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, IFrameWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        this._boundMessageEvent = this._message.bind(this);\n        window.addEventListener(\"message\", this._boundMessageEvent, false);\n\n        this._frame = window.document.createElement(\"iframe\");\n\n        // shotgun approach\n        this._frame.style.visibility = \"hidden\";\n        this._frame.style.position = \"absolute\";\n        this._frame.style.display = \"none\";\n        this._frame.style.width = 0;\n        this._frame.style.height = 0;\n\n        window.document.body.appendChild(this._frame);\n    }\n\n    IFrameWindow.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            this._error(\"No url provided\");\n        } else {\n            var timeout = params.silentRequestTimeout || DefaultTimeout;\n            _Log.Log.debug(\"IFrameWindow.navigate: Using timeout of:\", timeout);\n            this._timer = window.setTimeout(this._timeout.bind(this), timeout);\n            this._frame.src = params.url;\n        }\n\n        return this.promise;\n    };\n\n    IFrameWindow.prototype._success = function _success(data) {\n        this._cleanup();\n\n        _Log.Log.debug(\"IFrameWindow: Successful response from frame window\");\n        this._resolve(data);\n    };\n\n    IFrameWindow.prototype._error = function _error(message) {\n        this._cleanup();\n\n        _Log.Log.error(message);\n        this._reject(new Error(message));\n    };\n\n    IFrameWindow.prototype.close = function close() {\n        this._cleanup();\n    };\n\n    IFrameWindow.prototype._cleanup = function _cleanup() {\n        if (this._frame) {\n            _Log.Log.debug(\"IFrameWindow: cleanup\");\n\n            window.removeEventListener(\"message\", this._boundMessageEvent, false);\n            window.clearTimeout(this._timer);\n            window.document.body.removeChild(this._frame);\n\n            this._timer = null;\n            this._frame = null;\n            this._boundMessageEvent = null;\n        }\n    };\n\n    IFrameWindow.prototype._timeout = function _timeout() {\n        _Log.Log.debug(\"IFrameWindow.timeout\");\n        this._error(\"Frame window timed out\");\n    };\n\n    IFrameWindow.prototype._message = function _message(e) {\n        _Log.Log.debug(\"IFrameWindow.message\");\n\n        if (this._timer && e.origin === this._origin && e.source === this._frame.contentWindow) {\n            var url = e.data;\n            if (url) {\n                this._success({ url: url });\n            } else {\n                this._error(\"Invalid response from frame\");\n            }\n        }\n    };\n\n    IFrameWindow.notifyParent = function notifyParent(url) {\n        _Log.Log.debug(\"IFrameWindow.notifyParent\");\n        if (window.frameElement) {\n            url = url || window.location.href;\n            if (url) {\n                _Log.Log.debug(\"IFrameWindow.notifyParent: posting url message to parent\");\n                window.parent.postMessage(url, location.protocol + \"//\" + location.host);\n            }\n        }\n    };\n\n    _createClass(IFrameWindow, [{\n        key: \"promise\",\n        get: function get() {\n            return this._promise;\n        }\n    }, {\n        key: \"_origin\",\n        get: function get() {\n            return location.protocol + \"//\" + location.host;\n        }\n    }]);\n\n    return IFrameWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/InMemoryWebStorage.js\":\n/*!***********************************!*\\\n  !*** ./src/InMemoryWebStorage.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.InMemoryWebStorage = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar InMemoryWebStorage = exports.InMemoryWebStorage = function () {\n    function InMemoryWebStorage() {\n        _classCallCheck(this, InMemoryWebStorage);\n\n        this._data = {};\n    }\n\n    InMemoryWebStorage.prototype.getItem = function getItem(key) {\n        _Log.Log.debug(\"InMemoryWebStorage.getItem\", key);\n        return this._data[key];\n    };\n\n    InMemoryWebStorage.prototype.setItem = function setItem(key, value) {\n        _Log.Log.debug(\"InMemoryWebStorage.setItem\", key);\n        this._data[key] = value;\n    };\n\n    InMemoryWebStorage.prototype.removeItem = function removeItem(key) {\n        _Log.Log.debug(\"InMemoryWebStorage.removeItem\", key);\n        delete this._data[key];\n    };\n\n    InMemoryWebStorage.prototype.key = function key(index) {\n        return Object.getOwnPropertyNames(this._data)[index];\n    };\n\n    _createClass(InMemoryWebStorage, [{\n        key: \"length\",\n        get: function get() {\n            return Object.getOwnPropertyNames(this._data).length;\n        }\n    }]);\n\n    return InMemoryWebStorage;\n}();\n\n/***/ }),\n\n/***/ \"./src/JoseUtil.js\":\n/*!*************************!*\\\n  !*** ./src/JoseUtil.js ***!\n  \\*************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nexports.JoseUtil = undefined;\n\nvar _jsrsasign = __webpack_require__(/*! ./crypto/jsrsasign */ \"./src/crypto/jsrsasign.js\");\n\nvar _JoseUtilImpl = __webpack_require__(/*! ./JoseUtilImpl */ \"./src/JoseUtilImpl.js\");\n\nvar _JoseUtilImpl2 = _interopRequireDefault(_JoseUtilImpl);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nvar JoseUtil = exports.JoseUtil = (0, _JoseUtilImpl2.default)({ jws: _jsrsasign.jws, KeyUtil: _jsrsasign.KeyUtil, X509: _jsrsasign.X509, crypto: _jsrsasign.crypto, hextob64u: _jsrsasign.hextob64u, b64tohex: _jsrsasign.b64tohex, AllowedSigningAlgs: _jsrsasign.AllowedSigningAlgs });\n\n/***/ }),\n\n/***/ \"./src/JoseUtilImpl.js\":\n/*!*****************************!*\\\n  !*** ./src/JoseUtilImpl.js ***!\n  \\*****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.default = getJoseUtil;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nfunction getJoseUtil(_ref) {\n    var jws = _ref.jws,\n        KeyUtil = _ref.KeyUtil,\n        X509 = _ref.X509,\n        crypto = _ref.crypto,\n        hextob64u = _ref.hextob64u,\n        b64tohex = _ref.b64tohex,\n        AllowedSigningAlgs = _ref.AllowedSigningAlgs;\n\n    return function () {\n        function JoseUtil() {\n            _classCallCheck(this, JoseUtil);\n        }\n\n        JoseUtil.parseJwt = function parseJwt(jwt) {\n            _Log.Log.debug(\"JoseUtil.parseJwt\");\n            try {\n                var token = jws.JWS.parse(jwt);\n                return {\n                    header: token.headerObj,\n                    payload: token.payloadObj\n                };\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        JoseUtil.validateJwt = function validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\n            _Log.Log.debug(\"JoseUtil.validateJwt\");\n\n            try {\n                if (key.kty === \"RSA\") {\n                    if (key.e && key.n) {\n                        key = KeyUtil.getKey(key);\n                    } else if (key.x5c && key.x5c.length) {\n                        var hex = b64tohex(key.x5c[0]);\n                        key = X509.getPublicKeyFromCertHex(hex);\n                    } else {\n                        _Log.Log.error(\"JoseUtil.validateJwt: RSA key missing key material\", key);\n                        return Promise.reject(new Error(\"RSA key missing key material\"));\n                    }\n                } else if (key.kty === \"EC\") {\n                    if (key.crv && key.x && key.y) {\n                        key = KeyUtil.getKey(key);\n                    } else {\n                        _Log.Log.error(\"JoseUtil.validateJwt: EC key missing key material\", key);\n                        return Promise.reject(new Error(\"EC key missing key material\"));\n                    }\n                } else {\n                    _Log.Log.error(\"JoseUtil.validateJwt: Unsupported key type\", key && key.kty);\n                    return Promise.reject(new Error( true && key.kty));\n                }\n\n                return JoseUtil._validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive);\n            } catch (e) {\n                _Log.Log.error(e && e.message || e);\n                return Promise.reject(\"JWT validation failed\");\n            }\n        };\n\n        JoseUtil.validateJwtAttributes = function validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive) {\n            if (!clockSkew) {\n                clockSkew = 0;\n            }\n\n            if (!now) {\n                now = parseInt(Date.now() / 1000);\n            }\n\n            var payload = JoseUtil.parseJwt(jwt).payload;\n\n            if (!payload.iss) {\n                _Log.Log.error(\"JoseUtil._validateJwt: issuer was not provided\");\n                return Promise.reject(new Error(\"issuer was not provided\"));\n            }\n            if (payload.iss !== issuer) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid issuer in token\", payload.iss);\n                return Promise.reject(new Error(\"Invalid issuer in token: \" + payload.iss));\n            }\n\n            if (!payload.aud) {\n                _Log.Log.error(\"JoseUtil._validateJwt: aud was not provided\");\n                return Promise.reject(new Error(\"aud was not provided\"));\n            }\n            var validAudience = payload.aud === audience || Array.isArray(payload.aud) && payload.aud.indexOf(audience) >= 0;\n            if (!validAudience) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid audience in token\", payload.aud);\n                return Promise.reject(new Error(\"Invalid audience in token: \" + payload.aud));\n            }\n            if (payload.azp && payload.azp !== audience) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid azp in token\", payload.azp);\n                return Promise.reject(new Error(\"Invalid azp in token: \" + payload.azp));\n            }\n\n            if (!timeInsensitive) {\n                var lowerNow = now + clockSkew;\n                var upperNow = now - clockSkew;\n\n                if (!payload.iat) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: iat was not provided\");\n                    return Promise.reject(new Error(\"iat was not provided\"));\n                }\n                if (lowerNow < payload.iat) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: iat is in the future\", payload.iat);\n                    return Promise.reject(new Error(\"iat is in the future: \" + payload.iat));\n                }\n\n                if (payload.nbf && lowerNow < payload.nbf) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: nbf is in the future\", payload.nbf);\n                    return Promise.reject(new Error(\"nbf is in the future: \" + payload.nbf));\n                }\n\n                if (!payload.exp) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: exp was not provided\");\n                    return Promise.reject(new Error(\"exp was not provided\"));\n                }\n                if (payload.exp < upperNow) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: exp is in the past\", payload.exp);\n                    return Promise.reject(new Error(\"exp is in the past:\" + payload.exp));\n                }\n            }\n\n            return Promise.resolve(payload);\n        };\n\n        JoseUtil._validateJwt = function _validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\n\n            return JoseUtil.validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive).then(function (payload) {\n                try {\n                    if (!jws.JWS.verify(jwt, key, AllowedSigningAlgs)) {\n                        _Log.Log.error(\"JoseUtil._validateJwt: signature validation failed\");\n                        return Promise.reject(new Error(\"signature validation failed\"));\n                    }\n\n                    return payload;\n                } catch (e) {\n                    _Log.Log.error(e && e.message || e);\n                    return Promise.reject(new Error(\"signature validation failed\"));\n                }\n            });\n        };\n\n        JoseUtil.hashString = function hashString(value, alg) {\n            try {\n                return crypto.Util.hashString(value, alg);\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        JoseUtil.hexToBase64Url = function hexToBase64Url(value) {\n            try {\n                return hextob64u(value);\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        return JoseUtil;\n    }();\n}\nmodule.exports = exports[\"default\"];\n\n/***/ }),\n\n/***/ \"./src/JsonService.js\":\n/*!****************************!*\\\n  !*** ./src/JsonService.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.JsonService = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar JsonService = exports.JsonService = function () {\n    function JsonService() {\n        var additionalContentTypes = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : null;\n        var XMLHttpRequestCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.XMLHttpRequest;\n        var jwtHandler = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : null;\n\n        _classCallCheck(this, JsonService);\n\n        if (additionalContentTypes && Array.isArray(additionalContentTypes)) {\n            this._contentTypes = additionalContentTypes.slice();\n        } else {\n            this._contentTypes = [];\n        }\n        this._contentTypes.push('application/json');\n        if (jwtHandler) {\n            this._contentTypes.push('application/jwt');\n        }\n\n        this._XMLHttpRequest = XMLHttpRequestCtor;\n        this._jwtHandler = jwtHandler;\n    }\n\n    JsonService.prototype.getJson = function getJson(url, token) {\n        var _this = this;\n\n        if (!url) {\n            _Log.Log.error(\"JsonService.getJson: No url passed\");\n            throw new Error(\"url\");\n        }\n\n        _Log.Log.debug(\"JsonService.getJson, url: \", url);\n\n        return new Promise(function (resolve, reject) {\n\n            var req = new _this._XMLHttpRequest();\n            req.open('GET', url);\n\n            var allowedContentTypes = _this._contentTypes;\n            var jwtHandler = _this._jwtHandler;\n\n            req.onload = function () {\n                _Log.Log.debug(\"JsonService.getJson: HTTP response received, status\", req.status);\n\n                if (req.status === 200) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found == \"application/jwt\") {\n                            jwtHandler(req).then(resolve, reject);\n                            return;\n                        }\n\n                        if (found) {\n                            try {\n                                resolve(JSON.parse(req.responseText));\n                                return;\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.getJson: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\n                } else {\n                    reject(Error(req.statusText + \" (\" + req.status + \")\"));\n                }\n            };\n\n            req.onerror = function () {\n                _Log.Log.error(\"JsonService.getJson: network error\");\n                reject(Error(\"Network Error\"));\n            };\n\n            if (token) {\n                _Log.Log.debug(\"JsonService.getJson: token passed, setting Authorization header\");\n                req.setRequestHeader(\"Authorization\", \"Bearer \" + token);\n            }\n\n            req.send();\n        });\n    };\n\n    JsonService.prototype.postForm = function postForm(url, payload) {\n        var _this2 = this;\n\n        if (!url) {\n            _Log.Log.error(\"JsonService.postForm: No url passed\");\n            throw new Error(\"url\");\n        }\n\n        _Log.Log.debug(\"JsonService.postForm, url: \", url);\n\n        return new Promise(function (resolve, reject) {\n\n            var req = new _this2._XMLHttpRequest();\n            req.open('POST', url);\n\n            var allowedContentTypes = _this2._contentTypes;\n\n            req.onload = function () {\n                _Log.Log.debug(\"JsonService.postForm: HTTP response received, status\", req.status);\n\n                if (req.status === 200) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found) {\n                            try {\n                                resolve(JSON.parse(req.responseText));\n                                return;\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\n                    return;\n                }\n\n                if (req.status === 400) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found) {\n                            try {\n                                var payload = JSON.parse(req.responseText);\n                                if (payload && payload.error) {\n                                    _Log.Log.error(\"JsonService.postForm: Error from server: \", payload.error);\n                                    reject(new Error(payload.error));\n                                    return;\n                                }\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n                }\n\n                reject(Error(req.statusText + \" (\" + req.status + \")\"));\n            };\n\n            req.onerror = function () {\n                _Log.Log.error(\"JsonService.postForm: network error\");\n                reject(Error(\"Network Error\"));\n            };\n\n            var body = \"\";\n            for (var key in payload) {\n\n                var value = payload[key];\n\n                if (value) {\n\n                    if (body.length > 0) {\n                        body += \"&\";\n                    }\n\n                    body += encodeURIComponent(key);\n                    body += \"=\";\n                    body += encodeURIComponent(value);\n                }\n            }\n\n            req.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\n            req.send(body);\n        });\n    };\n\n    return JsonService;\n}();\n\n/***/ }),\n\n/***/ \"./src/Log.js\":\n/*!********************!*\\\n  !*** ./src/Log.js ***!\n  \\********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar nopLogger = {\n    debug: function debug() {},\n    info: function info() {},\n    warn: function warn() {},\n    error: function error() {}\n};\n\nvar NONE = 0;\nvar ERROR = 1;\nvar WARN = 2;\nvar INFO = 3;\nvar DEBUG = 4;\n\nvar logger = void 0;\nvar level = void 0;\n\nvar Log = exports.Log = function () {\n    function Log() {\n        _classCallCheck(this, Log);\n    }\n\n    Log.reset = function reset() {\n        level = INFO;\n        logger = nopLogger;\n    };\n\n    Log.debug = function debug() {\n        if (level >= DEBUG) {\n            for (var _len = arguments.length, args = Array(_len), _key = 0; _key < _len; _key++) {\n                args[_key] = arguments[_key];\n            }\n\n            logger.debug.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.info = function info() {\n        if (level >= INFO) {\n            for (var _len2 = arguments.length, args = Array(_len2), _key2 = 0; _key2 < _len2; _key2++) {\n                args[_key2] = arguments[_key2];\n            }\n\n            logger.info.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.warn = function warn() {\n        if (level >= WARN) {\n            for (var _len3 = arguments.length, args = Array(_len3), _key3 = 0; _key3 < _len3; _key3++) {\n                args[_key3] = arguments[_key3];\n            }\n\n            logger.warn.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.error = function error() {\n        if (level >= ERROR) {\n            for (var _len4 = arguments.length, args = Array(_len4), _key4 = 0; _key4 < _len4; _key4++) {\n                args[_key4] = arguments[_key4];\n            }\n\n            logger.error.apply(logger, Array.from(args));\n        }\n    };\n\n    _createClass(Log, null, [{\n        key: \"NONE\",\n        get: function get() {\n            return NONE;\n        }\n    }, {\n        key: \"ERROR\",\n        get: function get() {\n            return ERROR;\n        }\n    }, {\n        key: \"WARN\",\n        get: function get() {\n            return WARN;\n        }\n    }, {\n        key: \"INFO\",\n        get: function get() {\n            return INFO;\n        }\n    }, {\n        key: \"DEBUG\",\n        get: function get() {\n            return DEBUG;\n        }\n    }, {\n        key: \"level\",\n        get: function get() {\n            return level;\n        },\n        set: function set(value) {\n            if (NONE <= value && value <= DEBUG) {\n                level = value;\n            } else {\n                throw new Error(\"Invalid log level\");\n            }\n        }\n    }, {\n        key: \"logger\",\n        get: function get() {\n            return logger;\n        },\n        set: function set(value) {\n            if (!value.debug && value.info) {\n                // just to stay backwards compat. can remove in 2.0\n                value.debug = value.info;\n            }\n\n            if (value.debug && value.info && value.warn && value.error) {\n                logger = value;\n            } else {\n                throw new Error(\"Invalid logger\");\n            }\n        }\n    }]);\n\n    return Log;\n}();\n\nLog.reset();\n\n/***/ }),\n\n/***/ \"./src/MetadataService.js\":\n/*!********************************!*\\\n  !*** ./src/MetadataService.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.MetadataService = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcMetadataUrlPath = '.well-known/openid-configuration';\n\nvar MetadataService = exports.MetadataService = function () {\n    function MetadataService(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n\n        _classCallCheck(this, MetadataService);\n\n        if (!settings) {\n            _Log.Log.error(\"MetadataService: No settings passed to MetadataService\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor(['application/jwk-set+json']);\n    }\n\n    MetadataService.prototype.getMetadata = function getMetadata() {\n        var _this = this;\n\n        if (this._settings.metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadata: Returning metadata from settings\");\n            return Promise.resolve(this._settings.metadata);\n        }\n\n        if (!this.metadataUrl) {\n            _Log.Log.error(\"MetadataService.getMetadata: No authority or metadataUrl configured on settings\");\n            return Promise.reject(new Error(\"No authority or metadataUrl configured on settings\"));\n        }\n\n        _Log.Log.debug(\"MetadataService.getMetadata: getting metadata from\", this.metadataUrl);\n\n        return this._jsonService.getJson(this.metadataUrl).then(function (metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadata: json received\");\n            _this._settings.metadata = metadata;\n            return metadata;\n        });\n    };\n\n    MetadataService.prototype.getIssuer = function getIssuer() {\n        return this._getMetadataProperty(\"issuer\");\n    };\n\n    MetadataService.prototype.getAuthorizationEndpoint = function getAuthorizationEndpoint() {\n        return this._getMetadataProperty(\"authorization_endpoint\");\n    };\n\n    MetadataService.prototype.getUserInfoEndpoint = function getUserInfoEndpoint() {\n        return this._getMetadataProperty(\"userinfo_endpoint\");\n    };\n\n    MetadataService.prototype.getTokenEndpoint = function getTokenEndpoint() {\n        var optional = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : true;\n\n        return this._getMetadataProperty(\"token_endpoint\", optional);\n    };\n\n    MetadataService.prototype.getCheckSessionIframe = function getCheckSessionIframe() {\n        return this._getMetadataProperty(\"check_session_iframe\", true);\n    };\n\n    MetadataService.prototype.getEndSessionEndpoint = function getEndSessionEndpoint() {\n        return this._getMetadataProperty(\"end_session_endpoint\", true);\n    };\n\n    MetadataService.prototype.getRevocationEndpoint = function getRevocationEndpoint() {\n        return this._getMetadataProperty(\"revocation_endpoint\", true);\n    };\n\n    MetadataService.prototype.getKeysEndpoint = function getKeysEndpoint() {\n        return this._getMetadataProperty(\"jwks_uri\", true);\n    };\n\n    MetadataService.prototype._getMetadataProperty = function _getMetadataProperty(name) {\n        var optional = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : false;\n\n        _Log.Log.debug(\"MetadataService.getMetadataProperty for: \" + name);\n\n        return this.getMetadata().then(function (metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadataProperty: metadata recieved\");\n\n            if (metadata[name] === undefined) {\n\n                if (optional === true) {\n                    _Log.Log.warn(\"MetadataService.getMetadataProperty: Metadata does not contain optional property \" + name);\n                    return undefined;\n                } else {\n                    _Log.Log.error(\"MetadataService.getMetadataProperty: Metadata does not contain property \" + name);\n                    throw new Error(\"Metadata does not contain property \" + name);\n                }\n            }\n\n            return metadata[name];\n        });\n    };\n\n    MetadataService.prototype.getSigningKeys = function getSigningKeys() {\n        var _this2 = this;\n\n        if (this._settings.signingKeys) {\n            _Log.Log.debug(\"MetadataService.getSigningKeys: Returning signingKeys from settings\");\n            return Promise.resolve(this._settings.signingKeys);\n        }\n\n        return this._getMetadataProperty(\"jwks_uri\").then(function (jwks_uri) {\n            _Log.Log.debug(\"MetadataService.getSigningKeys: jwks_uri received\", jwks_uri);\n\n            return _this2._jsonService.getJson(jwks_uri).then(function (keySet) {\n                _Log.Log.debug(\"MetadataService.getSigningKeys: key set received\", keySet);\n\n                if (!keySet.keys) {\n                    _Log.Log.error(\"MetadataService.getSigningKeys: Missing keys on keyset\");\n                    throw new Error(\"Missing keys on keyset\");\n                }\n\n                _this2._settings.signingKeys = keySet.keys;\n                return _this2._settings.signingKeys;\n            });\n        });\n    };\n\n    _createClass(MetadataService, [{\n        key: 'metadataUrl',\n        get: function get() {\n            if (!this._metadataUrl) {\n                if (this._settings.metadataUrl) {\n                    this._metadataUrl = this._settings.metadataUrl;\n                } else {\n                    this._metadataUrl = this._settings.authority;\n\n                    if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\n                        if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\n                            this._metadataUrl += '/';\n                        }\n                        this._metadataUrl += OidcMetadataUrlPath;\n                    }\n                }\n            }\n\n            return this._metadataUrl;\n        }\n    }]);\n\n    return MetadataService;\n}();\n\n/***/ }),\n\n/***/ \"./src/OidcClient.js\":\n/*!***************************!*\\\n  !*** ./src/OidcClient.js ***!\n  \\***************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.OidcClient = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClientSettings = __webpack_require__(/*! ./OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _ErrorResponse = __webpack_require__(/*! ./ErrorResponse.js */ \"./src/ErrorResponse.js\");\n\nvar _SigninRequest = __webpack_require__(/*! ./SigninRequest.js */ \"./src/SigninRequest.js\");\n\nvar _SigninResponse = __webpack_require__(/*! ./SigninResponse.js */ \"./src/SigninResponse.js\");\n\nvar _SignoutRequest = __webpack_require__(/*! ./SignoutRequest.js */ \"./src/SignoutRequest.js\");\n\nvar _SignoutResponse = __webpack_require__(/*! ./SignoutResponse.js */ \"./src/SignoutResponse.js\");\n\nvar _SigninState = __webpack_require__(/*! ./SigninState.js */ \"./src/SigninState.js\");\n\nvar _State = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcClient = exports.OidcClient = function () {\n    function OidcClient() {\n        var settings = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        _classCallCheck(this, OidcClient);\n\n        if (settings instanceof _OidcClientSettings.OidcClientSettings) {\n            this._settings = settings;\n        } else {\n            this._settings = new _OidcClientSettings.OidcClientSettings(settings);\n        }\n    }\n\n    OidcClient.prototype.createSigninRequest = function createSigninRequest() {\n        var _this = this;\n\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            response_type = _ref.response_type,\n            scope = _ref.scope,\n            redirect_uri = _ref.redirect_uri,\n            data = _ref.data,\n            state = _ref.state,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            id_token_hint = _ref.id_token_hint,\n            login_hint = _ref.login_hint,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            request = _ref.request,\n            request_uri = _ref.request_uri,\n            response_mode = _ref.response_mode,\n            extraQueryParams = _ref.extraQueryParams,\n            extraTokenParams = _ref.extraTokenParams,\n            request_type = _ref.request_type,\n            skipUserInfo = _ref.skipUserInfo;\n\n        var stateStore = arguments[1];\n\n        _Log.Log.debug(\"OidcClient.createSigninRequest\");\n\n        var client_id = this._settings.client_id;\n        response_type = response_type || this._settings.response_type;\n        scope = scope || this._settings.scope;\n        redirect_uri = redirect_uri || this._settings.redirect_uri;\n\n        // id_token_hint, login_hint aren't allowed on _settings\n        prompt = prompt || this._settings.prompt;\n        display = display || this._settings.display;\n        max_age = max_age || this._settings.max_age;\n        ui_locales = ui_locales || this._settings.ui_locales;\n        acr_values = acr_values || this._settings.acr_values;\n        resource = resource || this._settings.resource;\n        response_mode = response_mode || this._settings.response_mode;\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\n        extraTokenParams = extraTokenParams || this._settings.extraTokenParams;\n\n        var authority = this._settings.authority;\n\n        if (_SigninRequest.SigninRequest.isCode(response_type) && response_type !== \"code\") {\n            return Promise.reject(new Error(\"OpenID Connect hybrid flow is not supported\"));\n        }\n\n        return this._metadataService.getAuthorizationEndpoint().then(function (url) {\n            _Log.Log.debug(\"OidcClient.createSigninRequest: Received authorization endpoint\", url);\n\n            var signinRequest = new _SigninRequest.SigninRequest({\n                url: url,\n                client_id: client_id,\n                redirect_uri: redirect_uri,\n                response_type: response_type,\n                scope: scope,\n                data: data || state,\n                authority: authority,\n                prompt: prompt, display: display, max_age: max_age, ui_locales: ui_locales, id_token_hint: id_token_hint, login_hint: login_hint, acr_values: acr_values,\n                resource: resource, request: request, request_uri: request_uri, extraQueryParams: extraQueryParams, extraTokenParams: extraTokenParams, request_type: request_type, response_mode: response_mode,\n                client_secret: _this._settings.client_secret,\n                skipUserInfo: skipUserInfo\n            });\n\n            var signinState = signinRequest.state;\n            stateStore = stateStore || _this._stateStore;\n\n            return stateStore.set(signinState.id, signinState.toStorageString()).then(function () {\n                return signinRequest;\n            });\n        });\n    };\n\n    OidcClient.prototype.readSigninResponseState = function readSigninResponseState(url, stateStore) {\n        var removeState = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : false;\n\n        _Log.Log.debug(\"OidcClient.readSigninResponseState\");\n\n        var useQuery = this._settings.response_mode === \"query\" || !this._settings.response_mode && _SigninRequest.SigninRequest.isCode(this._settings.response_type);\n        var delimiter = useQuery ? \"?\" : \"#\";\n\n        var response = new _SigninResponse.SigninResponse(url, delimiter);\n\n        if (!response.state) {\n            _Log.Log.error(\"OidcClient.readSigninResponseState: No state in response\");\n            return Promise.reject(new Error(\"No state in response\"));\n        }\n\n        stateStore = stateStore || this._stateStore;\n\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\n\n        return stateApi(response.state).then(function (storedStateString) {\n            if (!storedStateString) {\n                _Log.Log.error(\"OidcClient.readSigninResponseState: No matching state found in storage\");\n                throw new Error(\"No matching state found in storage\");\n            }\n\n            var state = _SigninState.SigninState.fromStorageString(storedStateString);\n            return { state: state, response: response };\n        });\n    };\n\n    OidcClient.prototype.processSigninResponse = function processSigninResponse(url, stateStore) {\n        var _this2 = this;\n\n        _Log.Log.debug(\"OidcClient.processSigninResponse\");\n\n        return this.readSigninResponseState(url, stateStore, true).then(function (_ref2) {\n            var state = _ref2.state,\n                response = _ref2.response;\n\n            _Log.Log.debug(\"OidcClient.processSigninResponse: Received state from storage; validating response\");\n            return _this2._validator.validateSigninResponse(state, response);\n        });\n    };\n\n    OidcClient.prototype.createSignoutRequest = function createSignoutRequest() {\n        var _this3 = this;\n\n        var _ref3 = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            id_token_hint = _ref3.id_token_hint,\n            data = _ref3.data,\n            state = _ref3.state,\n            post_logout_redirect_uri = _ref3.post_logout_redirect_uri,\n            extraQueryParams = _ref3.extraQueryParams,\n            request_type = _ref3.request_type;\n\n        var stateStore = arguments[1];\n\n        _Log.Log.debug(\"OidcClient.createSignoutRequest\");\n\n        post_logout_redirect_uri = post_logout_redirect_uri || this._settings.post_logout_redirect_uri;\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\n\n        return this._metadataService.getEndSessionEndpoint().then(function (url) {\n            if (!url) {\n                _Log.Log.error(\"OidcClient.createSignoutRequest: No end session endpoint url returned\");\n                throw new Error(\"no end session endpoint\");\n            }\n\n            _Log.Log.debug(\"OidcClient.createSignoutRequest: Received end session endpoint\", url);\n\n            var request = new _SignoutRequest.SignoutRequest({\n                url: url,\n                id_token_hint: id_token_hint,\n                post_logout_redirect_uri: post_logout_redirect_uri,\n                data: data || state,\n                extraQueryParams: extraQueryParams,\n                request_type: request_type\n            });\n\n            var signoutState = request.state;\n            if (signoutState) {\n                _Log.Log.debug(\"OidcClient.createSignoutRequest: Signout request has state to persist\");\n\n                stateStore = stateStore || _this3._stateStore;\n                stateStore.set(signoutState.id, signoutState.toStorageString());\n            }\n\n            return request;\n        });\n    };\n\n    OidcClient.prototype.readSignoutResponseState = function readSignoutResponseState(url, stateStore) {\n        var removeState = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : false;\n\n        _Log.Log.debug(\"OidcClient.readSignoutResponseState\");\n\n        var response = new _SignoutResponse.SignoutResponse(url);\n        if (!response.state) {\n            _Log.Log.debug(\"OidcClient.readSignoutResponseState: No state in response\");\n\n            if (response.error) {\n                _Log.Log.warn(\"OidcClient.readSignoutResponseState: Response was error: \", response.error);\n                return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n            }\n\n            return Promise.resolve({ undefined: undefined, response: response });\n        }\n\n        var stateKey = response.state;\n\n        stateStore = stateStore || this._stateStore;\n\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\n        return stateApi(stateKey).then(function (storedStateString) {\n            if (!storedStateString) {\n                _Log.Log.error(\"OidcClient.readSignoutResponseState: No matching state found in storage\");\n                throw new Error(\"No matching state found in storage\");\n            }\n\n            var state = _State.State.fromStorageString(storedStateString);\n\n            return { state: state, response: response };\n        });\n    };\n\n    OidcClient.prototype.processSignoutResponse = function processSignoutResponse(url, stateStore) {\n        var _this4 = this;\n\n        _Log.Log.debug(\"OidcClient.processSignoutResponse\");\n\n        return this.readSignoutResponseState(url, stateStore, true).then(function (_ref4) {\n            var state = _ref4.state,\n                response = _ref4.response;\n\n            if (state) {\n                _Log.Log.debug(\"OidcClient.processSignoutResponse: Received state from storage; validating response\");\n                return _this4._validator.validateSignoutResponse(state, response);\n            } else {\n                _Log.Log.debug(\"OidcClient.processSignoutResponse: No state from storage; skipping validating response\");\n                return response;\n            }\n        });\n    };\n\n    OidcClient.prototype.clearStaleState = function clearStaleState(stateStore) {\n        _Log.Log.debug(\"OidcClient.clearStaleState\");\n\n        stateStore = stateStore || this._stateStore;\n\n        return _State.State.clearStaleState(stateStore, this.settings.staleStateAge);\n    };\n\n    _createClass(OidcClient, [{\n        key: '_stateStore',\n        get: function get() {\n            return this.settings.stateStore;\n        }\n    }, {\n        key: '_validator',\n        get: function get() {\n            return this.settings.validator;\n        }\n    }, {\n        key: '_metadataService',\n        get: function get() {\n            return this.settings.metadataService;\n        }\n    }, {\n        key: 'settings',\n        get: function get() {\n            return this._settings;\n        }\n    }, {\n        key: 'metadataService',\n        get: function get() {\n            return this._metadataService;\n        }\n    }]);\n\n    return OidcClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/OidcClientSettings.js\":\n/*!***********************************!*\\\n  !*** ./src/OidcClientSettings.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.OidcClientSettings = undefined;\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _ResponseValidator = __webpack_require__(/*! ./ResponseValidator.js */ \"./src/ResponseValidator.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcMetadataUrlPath = '.well-known/openid-configuration';\n\nvar DefaultResponseType = \"id_token\";\nvar DefaultScope = \"openid\";\nvar DefaultStaleStateAge = 60 * 15; // seconds\nvar DefaultClockSkewInSeconds = 60 * 5;\n\nvar OidcClientSettings = exports.OidcClientSettings = function () {\n    function OidcClientSettings() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            authority = _ref.authority,\n            metadataUrl = _ref.metadataUrl,\n            metadata = _ref.metadata,\n            signingKeys = _ref.signingKeys,\n            client_id = _ref.client_id,\n            client_secret = _ref.client_secret,\n            _ref$response_type = _ref.response_type,\n            response_type = _ref$response_type === undefined ? DefaultResponseType : _ref$response_type,\n            _ref$scope = _ref.scope,\n            scope = _ref$scope === undefined ? DefaultScope : _ref$scope,\n            redirect_uri = _ref.redirect_uri,\n            post_logout_redirect_uri = _ref.post_logout_redirect_uri,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            response_mode = _ref.response_mode,\n            _ref$filterProtocolCl = _ref.filterProtocolClaims,\n            filterProtocolClaims = _ref$filterProtocolCl === undefined ? true : _ref$filterProtocolCl,\n            _ref$loadUserInfo = _ref.loadUserInfo,\n            loadUserInfo = _ref$loadUserInfo === undefined ? true : _ref$loadUserInfo,\n            _ref$staleStateAge = _ref.staleStateAge,\n            staleStateAge = _ref$staleStateAge === undefined ? DefaultStaleStateAge : _ref$staleStateAge,\n            _ref$clockSkew = _ref.clockSkew,\n            clockSkew = _ref$clockSkew === undefined ? DefaultClockSkewInSeconds : _ref$clockSkew,\n            _ref$userInfoJwtIssue = _ref.userInfoJwtIssuer,\n            userInfoJwtIssuer = _ref$userInfoJwtIssue === undefined ? 'OP' : _ref$userInfoJwtIssue,\n            _ref$stateStore = _ref.stateStore,\n            stateStore = _ref$stateStore === undefined ? new _WebStorageStateStore.WebStorageStateStore() : _ref$stateStore,\n            _ref$ResponseValidato = _ref.ResponseValidatorCtor,\n            ResponseValidatorCtor = _ref$ResponseValidato === undefined ? _ResponseValidator.ResponseValidator : _ref$ResponseValidato,\n            _ref$MetadataServiceC = _ref.MetadataServiceCtor,\n            MetadataServiceCtor = _ref$MetadataServiceC === undefined ? _MetadataService.MetadataService : _ref$MetadataServiceC,\n            _ref$extraQueryParams = _ref.extraQueryParams,\n            extraQueryParams = _ref$extraQueryParams === undefined ? {} : _ref$extraQueryParams,\n            _ref$extraTokenParams = _ref.extraTokenParams,\n            extraTokenParams = _ref$extraTokenParams === undefined ? {} : _ref$extraTokenParams;\n\n        _classCallCheck(this, OidcClientSettings);\n\n        this._authority = authority;\n        this._metadataUrl = metadataUrl;\n        this._metadata = metadata;\n        this._signingKeys = signingKeys;\n\n        this._client_id = client_id;\n        this._client_secret = client_secret;\n        this._response_type = response_type;\n        this._scope = scope;\n        this._redirect_uri = redirect_uri;\n        this._post_logout_redirect_uri = post_logout_redirect_uri;\n\n        this._prompt = prompt;\n        this._display = display;\n        this._max_age = max_age;\n        this._ui_locales = ui_locales;\n        this._acr_values = acr_values;\n        this._resource = resource;\n        this._response_mode = response_mode;\n\n        this._filterProtocolClaims = !!filterProtocolClaims;\n        this._loadUserInfo = !!loadUserInfo;\n        this._staleStateAge = staleStateAge;\n        this._clockSkew = clockSkew;\n        this._userInfoJwtIssuer = userInfoJwtIssuer;\n\n        this._stateStore = stateStore;\n        this._validator = new ResponseValidatorCtor(this);\n        this._metadataService = new MetadataServiceCtor(this);\n\n        this._extraQueryParams = (typeof extraQueryParams === 'undefined' ? 'undefined' : _typeof(extraQueryParams)) === 'object' ? extraQueryParams : {};\n        this._extraTokenParams = (typeof extraTokenParams === 'undefined' ? 'undefined' : _typeof(extraTokenParams)) === 'object' ? extraTokenParams : {};\n    }\n\n    // client config\n\n\n    _createClass(OidcClientSettings, [{\n        key: 'client_id',\n        get: function get() {\n            return this._client_id;\n        },\n        set: function set(value) {\n            if (!this._client_id) {\n                // one-time set only\n                this._client_id = value;\n            } else {\n                _Log.Log.error(\"OidcClientSettings.set_client_id: client_id has already been assigned.\");\n                throw new Error(\"client_id has already been assigned.\");\n            }\n        }\n    }, {\n        key: 'client_secret',\n        get: function get() {\n            return this._client_secret;\n        }\n    }, {\n        key: 'response_type',\n        get: function get() {\n            return this._response_type;\n        }\n    }, {\n        key: 'scope',\n        get: function get() {\n            return this._scope;\n        }\n    }, {\n        key: 'redirect_uri',\n        get: function get() {\n            return this._redirect_uri;\n        }\n    }, {\n        key: 'post_logout_redirect_uri',\n        get: function get() {\n            return this._post_logout_redirect_uri;\n        }\n\n        // optional protocol params\n\n    }, {\n        key: 'prompt',\n        get: function get() {\n            return this._prompt;\n        }\n    }, {\n        key: 'display',\n        get: function get() {\n            return this._display;\n        }\n    }, {\n        key: 'max_age',\n        get: function get() {\n            return this._max_age;\n        }\n    }, {\n        key: 'ui_locales',\n        get: function get() {\n            return this._ui_locales;\n        }\n    }, {\n        key: 'acr_values',\n        get: function get() {\n            return this._acr_values;\n        }\n    }, {\n        key: 'resource',\n        get: function get() {\n            return this._resource;\n        }\n    }, {\n        key: 'response_mode',\n        get: function get() {\n            return this._response_mode;\n        }\n\n        // metadata\n\n    }, {\n        key: 'authority',\n        get: function get() {\n            return this._authority;\n        },\n        set: function set(value) {\n            if (!this._authority) {\n                // one-time set only\n                this._authority = value;\n            } else {\n                _Log.Log.error(\"OidcClientSettings.set_authority: authority has already been assigned.\");\n                throw new Error(\"authority has already been assigned.\");\n            }\n        }\n    }, {\n        key: 'metadataUrl',\n        get: function get() {\n            if (!this._metadataUrl) {\n                this._metadataUrl = this.authority;\n\n                if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\n                    if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\n                        this._metadataUrl += '/';\n                    }\n                    this._metadataUrl += OidcMetadataUrlPath;\n                }\n            }\n\n            return this._metadataUrl;\n        }\n\n        // settable/cachable metadata values\n\n    }, {\n        key: 'metadata',\n        get: function get() {\n            return this._metadata;\n        },\n        set: function set(value) {\n            this._metadata = value;\n        }\n    }, {\n        key: 'signingKeys',\n        get: function get() {\n            return this._signingKeys;\n        },\n        set: function set(value) {\n            this._signingKeys = value;\n        }\n\n        // behavior flags\n\n    }, {\n        key: 'filterProtocolClaims',\n        get: function get() {\n            return this._filterProtocolClaims;\n        }\n    }, {\n        key: 'loadUserInfo',\n        get: function get() {\n            return this._loadUserInfo;\n        }\n    }, {\n        key: 'staleStateAge',\n        get: function get() {\n            return this._staleStateAge;\n        }\n    }, {\n        key: 'clockSkew',\n        get: function get() {\n            return this._clockSkew;\n        }\n    }, {\n        key: 'userInfoJwtIssuer',\n        get: function get() {\n            return this._userInfoJwtIssuer;\n        }\n    }, {\n        key: 'stateStore',\n        get: function get() {\n            return this._stateStore;\n        }\n    }, {\n        key: 'validator',\n        get: function get() {\n            return this._validator;\n        }\n    }, {\n        key: 'metadataService',\n        get: function get() {\n            return this._metadataService;\n        }\n\n        // extra query params\n\n    }, {\n        key: 'extraQueryParams',\n        get: function get() {\n            return this._extraQueryParams;\n        },\n        set: function set(value) {\n            if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                this._extraQueryParams = value;\n            } else {\n                this._extraQueryParams = {};\n            }\n        }\n\n        // extra token params\n\n    }, {\n        key: 'extraTokenParams',\n        get: function get() {\n            return this._extraTokenParams;\n        },\n        set: function set(value) {\n            if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                this._extraTokenParams = value;\n            } else {\n                this._extraTokenParams = {};\n            }\n        }\n    }]);\n\n    return OidcClientSettings;\n}();\n\n/***/ }),\n\n/***/ \"./src/PopupNavigator.js\":\n/*!*******************************!*\\\n  !*** ./src/PopupNavigator.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.PopupNavigator = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _PopupWindow = __webpack_require__(/*! ./PopupWindow.js */ \"./src/PopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar PopupNavigator = exports.PopupNavigator = function () {\n    function PopupNavigator() {\n        _classCallCheck(this, PopupNavigator);\n    }\n\n    PopupNavigator.prototype.prepare = function prepare(params) {\n        var popup = new _PopupWindow.PopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    PopupNavigator.prototype.callback = function callback(url, keepOpen, delimiter) {\n        _Log.Log.debug(\"PopupNavigator.callback\");\n\n        try {\n            _PopupWindow.PopupWindow.notifyOpener(url, keepOpen, delimiter);\n            return Promise.resolve();\n        } catch (e) {\n            return Promise.reject(e);\n        }\n    };\n\n    return PopupNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/PopupWindow.js\":\n/*!****************************!*\\\n  !*** ./src/PopupWindow.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.PopupWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar CheckForPopupClosedInterval = 500;\nvar DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;';\n//const DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;resizable=yes';\n\nvar DefaultPopupTarget = \"_blank\";\n\nvar PopupWindow = exports.PopupWindow = function () {\n    function PopupWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, PopupWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        var target = params.popupWindowTarget || DefaultPopupTarget;\n        var features = params.popupWindowFeatures || DefaultPopupFeatures;\n\n        this._popup = window.open('', target, features);\n        if (this._popup) {\n            _Log.Log.debug(\"PopupWindow.ctor: popup successfully created\");\n            this._checkForPopupClosedTimer = window.setInterval(this._checkForPopupClosed.bind(this), CheckForPopupClosedInterval);\n        }\n    }\n\n    PopupWindow.prototype.navigate = function navigate(params) {\n        if (!this._popup) {\n            this._error(\"PopupWindow.navigate: Error opening popup window\");\n        } else if (!params || !params.url) {\n            this._error(\"PopupWindow.navigate: no url provided\");\n            this._error(\"No url provided\");\n        } else {\n            _Log.Log.debug(\"PopupWindow.navigate: Setting URL in popup\");\n\n            this._id = params.id;\n            if (this._id) {\n                window[\"popupCallback_\" + params.id] = this._callback.bind(this);\n            }\n\n            this._popup.focus();\n            this._popup.window.location = params.url;\n        }\n\n        return this.promise;\n    };\n\n    PopupWindow.prototype._success = function _success(data) {\n        _Log.Log.debug(\"PopupWindow.callback: Successful response from popup window\");\n\n        this._cleanup();\n        this._resolve(data);\n    };\n\n    PopupWindow.prototype._error = function _error(message) {\n        _Log.Log.error(\"PopupWindow.error: \", message);\n\n        this._cleanup();\n        this._reject(new Error(message));\n    };\n\n    PopupWindow.prototype.close = function close() {\n        this._cleanup(false);\n    };\n\n    PopupWindow.prototype._cleanup = function _cleanup(keepOpen) {\n        _Log.Log.debug(\"PopupWindow.cleanup\");\n\n        window.clearInterval(this._checkForPopupClosedTimer);\n        this._checkForPopupClosedTimer = null;\n\n        delete window[\"popupCallback_\" + this._id];\n\n        if (this._popup && !keepOpen) {\n            this._popup.close();\n        }\n        this._popup = null;\n    };\n\n    PopupWindow.prototype._checkForPopupClosed = function _checkForPopupClosed() {\n        if (!this._popup || this._popup.closed) {\n            this._error(\"Popup window closed\");\n        }\n    };\n\n    PopupWindow.prototype._callback = function _callback(url, keepOpen) {\n        this._cleanup(keepOpen);\n\n        if (url) {\n            _Log.Log.debug(\"PopupWindow.callback success\");\n            this._success({ url: url });\n        } else {\n            _Log.Log.debug(\"PopupWindow.callback: Invalid response from popup\");\n            this._error(\"Invalid response from popup\");\n        }\n    };\n\n    PopupWindow.notifyOpener = function notifyOpener(url, keepOpen, delimiter) {\n        if (window.opener) {\n            url = url || window.location.href;\n            if (url) {\n                var data = _UrlUtility.UrlUtility.parseUrlFragment(url, delimiter);\n\n                if (data.state) {\n                    var name = \"popupCallback_\" + data.state;\n                    var callback = window.opener[name];\n                    if (callback) {\n                        _Log.Log.debug(\"PopupWindow.notifyOpener: passing url message to opener\");\n                        callback(url, keepOpen);\n                    } else {\n                        _Log.Log.warn(\"PopupWindow.notifyOpener: no matching callback found on opener\");\n                    }\n                } else {\n                    _Log.Log.warn(\"PopupWindow.notifyOpener: no state found in response url\");\n                }\n            }\n        } else {\n            _Log.Log.warn(\"PopupWindow.notifyOpener: no window.opener. Can't complete notification.\");\n        }\n    };\n\n    _createClass(PopupWindow, [{\n        key: 'promise',\n        get: function get() {\n            return this._promise;\n        }\n    }]);\n\n    return PopupWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/RedirectNavigator.js\":\n/*!**********************************!*\\\n  !*** ./src/RedirectNavigator.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.RedirectNavigator = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar RedirectNavigator = exports.RedirectNavigator = function () {\n    function RedirectNavigator() {\n        _classCallCheck(this, RedirectNavigator);\n    }\n\n    RedirectNavigator.prototype.prepare = function prepare() {\n        return Promise.resolve(this);\n    };\n\n    RedirectNavigator.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            _Log.Log.error(\"RedirectNavigator.navigate: No url provided\");\n            return Promise.reject(new Error(\"No url provided\"));\n        }\n\n        if (params.useReplaceToNavigate) {\n            window.location.replace(params.url);\n        } else {\n            window.location = params.url;\n        }\n\n        return Promise.resolve();\n    };\n\n    _createClass(RedirectNavigator, [{\n        key: \"url\",\n        get: function get() {\n            return window.location.href;\n        }\n    }]);\n\n    return RedirectNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/ResponseValidator.js\":\n/*!**********************************!*\\\n  !*** ./src/ResponseValidator.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.ResponseValidator = undefined;\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _UserInfoService = __webpack_require__(/*! ./UserInfoService.js */ \"./src/UserInfoService.js\");\n\nvar _TokenClient = __webpack_require__(/*! ./TokenClient.js */ \"./src/TokenClient.js\");\n\nvar _ErrorResponse = __webpack_require__(/*! ./ErrorResponse.js */ \"./src/ErrorResponse.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar ProtocolClaims = [\"nonce\", \"at_hash\", \"iat\", \"nbf\", \"exp\", \"aud\", \"iss\", \"c_hash\"];\n\nvar ResponseValidator = exports.ResponseValidator = function () {\n    function ResponseValidator(settings) {\n        var MetadataServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _MetadataService.MetadataService;\n        var UserInfoServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _UserInfoService.UserInfoService;\n        var joseUtil = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _JoseUtil.JoseUtil;\n        var TokenClientCtor = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : _TokenClient.TokenClient;\n\n        _classCallCheck(this, ResponseValidator);\n\n        if (!settings) {\n            _Log.Log.error(\"ResponseValidator.ctor: No settings passed to ResponseValidator\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._metadataService = new MetadataServiceCtor(this._settings);\n        this._userInfoService = new UserInfoServiceCtor(this._settings);\n        this._joseUtil = joseUtil;\n        this._tokenClient = new TokenClientCtor(this._settings);\n    }\n\n    ResponseValidator.prototype.validateSigninResponse = function validateSigninResponse(state, response) {\n        var _this = this;\n\n        _Log.Log.debug(\"ResponseValidator.validateSigninResponse\");\n\n        return this._processSigninParams(state, response).then(function (response) {\n            _Log.Log.debug(\"ResponseValidator.validateSigninResponse: state processed\");\n            return _this._validateTokens(state, response).then(function (response) {\n                _Log.Log.debug(\"ResponseValidator.validateSigninResponse: tokens validated\");\n                return _this._processClaims(state, response).then(function (response) {\n                    _Log.Log.debug(\"ResponseValidator.validateSigninResponse: claims processed\");\n                    return response;\n                });\n            });\n        });\n    };\n\n    ResponseValidator.prototype.validateSignoutResponse = function validateSignoutResponse(state, response) {\n        if (state.id !== response.state) {\n            _Log.Log.error(\"ResponseValidator.validateSignoutResponse: State does not match\");\n            return Promise.reject(new Error(\"State does not match\"));\n        }\n\n        // now that we know the state matches, take the stored data\n        // and set it into the response so callers can get their state\n        // this is important for both success & error outcomes\n        _Log.Log.debug(\"ResponseValidator.validateSignoutResponse: state validated\");\n        response.state = state.data;\n\n        if (response.error) {\n            _Log.Log.warn(\"ResponseValidator.validateSignoutResponse: Response was error\", response.error);\n            return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processSigninParams = function _processSigninParams(state, response) {\n        if (state.id !== response.state) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: State does not match\");\n            return Promise.reject(new Error(\"State does not match\"));\n        }\n\n        if (!state.client_id) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: No client_id on state\");\n            return Promise.reject(new Error(\"No client_id on state\"));\n        }\n\n        if (!state.authority) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: No authority on state\");\n            return Promise.reject(new Error(\"No authority on state\"));\n        }\n\n        // this allows the authority to be loaded from the signin state\n        if (!this._settings.authority) {\n            this._settings.authority = state.authority;\n        }\n        // ensure we're using the correct authority if the authority is not loaded from signin state\n        else if (this._settings.authority && this._settings.authority !== state.authority) {\n                _Log.Log.error(\"ResponseValidator._processSigninParams: authority mismatch on settings vs. signin state\");\n                return Promise.reject(new Error(\"authority mismatch on settings vs. signin state\"));\n            }\n        // this allows the client_id to be loaded from the signin state\n        if (!this._settings.client_id) {\n            this._settings.client_id = state.client_id;\n        }\n        // ensure we're using the correct client_id if the client_id is not loaded from signin state\n        else if (this._settings.client_id && this._settings.client_id !== state.client_id) {\n                _Log.Log.error(\"ResponseValidator._processSigninParams: client_id mismatch on settings vs. signin state\");\n                return Promise.reject(new Error(\"client_id mismatch on settings vs. signin state\"));\n            }\n\n        // now that we know the state matches, take the stored data\n        // and set it into the response so callers can get their state\n        // this is important for both success & error outcomes\n        _Log.Log.debug(\"ResponseValidator._processSigninParams: state validated\");\n        response.state = state.data;\n\n        if (response.error) {\n            _Log.Log.warn(\"ResponseValidator._processSigninParams: Response was error\", response.error);\n            return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n        }\n\n        if (state.nonce && !response.id_token) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Expecting id_token in response\");\n            return Promise.reject(new Error(\"No id_token in response\"));\n        }\n\n        if (!state.nonce && response.id_token) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Not expecting id_token in response\");\n            return Promise.reject(new Error(\"Unexpected id_token in response\"));\n        }\n\n        if (state.code_verifier && !response.code) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Expecting code in response\");\n            return Promise.reject(new Error(\"No code in response\"));\n        }\n\n        if (!state.code_verifier && response.code) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Not expecting code in response\");\n            return Promise.reject(new Error(\"Unexpected code in response\"));\n        }\n\n        if (!response.scope) {\n            // if there's no scope on the response, then assume all scopes granted (per-spec) and copy over scopes from original request\n            response.scope = state.scope;\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processClaims = function _processClaims(state, response) {\n        var _this2 = this;\n\n        if (response.isOpenIdConnect) {\n            _Log.Log.debug(\"ResponseValidator._processClaims: response is OIDC, processing claims\");\n\n            response.profile = this._filterProtocolClaims(response.profile);\n\n            if (state.skipUserInfo !== true && this._settings.loadUserInfo && response.access_token) {\n                _Log.Log.debug(\"ResponseValidator._processClaims: loading user info\");\n\n                return this._userInfoService.getClaims(response.access_token).then(function (claims) {\n                    _Log.Log.debug(\"ResponseValidator._processClaims: user info claims received from user info endpoint\");\n\n                    if (claims.sub !== response.profile.sub) {\n                        _Log.Log.error(\"ResponseValidator._processClaims: sub from user info endpoint does not match sub in access_token\");\n                        return Promise.reject(new Error(\"sub from user info endpoint does not match sub in access_token\"));\n                    }\n\n                    response.profile = _this2._mergeClaims(response.profile, claims);\n                    _Log.Log.debug(\"ResponseValidator._processClaims: user info claims received, updated profile:\", response.profile);\n\n                    return response;\n                });\n            } else {\n                _Log.Log.debug(\"ResponseValidator._processClaims: not loading user info\");\n            }\n        } else {\n            _Log.Log.debug(\"ResponseValidator._processClaims: response is not OIDC, not processing claims\");\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._mergeClaims = function _mergeClaims(claims1, claims2) {\n        var result = Object.assign({}, claims1);\n\n        for (var name in claims2) {\n            var values = claims2[name];\n            if (!Array.isArray(values)) {\n                values = [values];\n            }\n\n            for (var i = 0; i < values.length; i++) {\n                var value = values[i];\n                if (!result[name]) {\n                    result[name] = value;\n                } else if (Array.isArray(result[name])) {\n                    if (result[name].indexOf(value) < 0) {\n                        result[name].push(value);\n                    }\n                } else if (result[name] !== value) {\n                    if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                        result[name] = this._mergeClaims(result[name], value);\n                    } else {\n                        result[name] = [result[name], value];\n                    }\n                }\n            }\n        }\n\n        return result;\n    };\n\n    ResponseValidator.prototype._filterProtocolClaims = function _filterProtocolClaims(claims) {\n        _Log.Log.debug(\"ResponseValidator._filterProtocolClaims, incoming claims:\", claims);\n\n        var result = Object.assign({}, claims);\n\n        if (this._settings._filterProtocolClaims) {\n            ProtocolClaims.forEach(function (type) {\n                delete result[type];\n            });\n\n            _Log.Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims filtered\", result);\n        } else {\n            _Log.Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims not filtered\");\n        }\n\n        return result;\n    };\n\n    ResponseValidator.prototype._validateTokens = function _validateTokens(state, response) {\n        if (response.code) {\n            _Log.Log.debug(\"ResponseValidator._validateTokens: Validating code\");\n            return this._processCode(state, response);\n        }\n\n        if (response.id_token) {\n            if (response.access_token) {\n                _Log.Log.debug(\"ResponseValidator._validateTokens: Validating id_token and access_token\");\n                return this._validateIdTokenAndAccessToken(state, response);\n            }\n\n            _Log.Log.debug(\"ResponseValidator._validateTokens: Validating id_token\");\n            return this._validateIdToken(state, response);\n        }\n\n        _Log.Log.debug(\"ResponseValidator._validateTokens: No code to process or id_token to validate\");\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processCode = function _processCode(state, response) {\n        var _this3 = this;\n\n        var request = {\n            client_id: state.client_id,\n            client_secret: state.client_secret,\n            code: response.code,\n            redirect_uri: state.redirect_uri,\n            code_verifier: state.code_verifier\n        };\n\n        if (state.extraTokenParams && _typeof(state.extraTokenParams) === 'object') {\n            Object.assign(request, state.extraTokenParams);\n        }\n\n        return this._tokenClient.exchangeCode(request).then(function (tokenResponse) {\n\n            for (var key in tokenResponse) {\n                response[key] = tokenResponse[key];\n            }\n\n            if (response.id_token) {\n                _Log.Log.debug(\"ResponseValidator._processCode: token response successful, processing id_token\");\n                return _this3._validateIdTokenAttributes(state, response);\n            } else {\n                _Log.Log.debug(\"ResponseValidator._processCode: token response successful, returning response\");\n            }\n\n            return response;\n        });\n    };\n\n    ResponseValidator.prototype._validateIdTokenAttributes = function _validateIdTokenAttributes(state, response) {\n        var _this4 = this;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n\n            var audience = state.client_id;\n            var clockSkewInSeconds = _this4._settings.clockSkew;\n            _Log.Log.debug(\"ResponseValidator._validateIdTokenAttributes: Validaing JWT attributes; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n            return _this4._joseUtil.validateJwtAttributes(response.id_token, issuer, audience, clockSkewInSeconds).then(function (payload) {\n\n                if (state.nonce && state.nonce !== payload.nonce) {\n                    _Log.Log.error(\"ResponseValidator._validateIdTokenAttributes: Invalid nonce in id_token\");\n                    return Promise.reject(new Error(\"Invalid nonce in id_token\"));\n                }\n\n                if (!payload.sub) {\n                    _Log.Log.error(\"ResponseValidator._validateIdTokenAttributes: No sub present in id_token\");\n                    return Promise.reject(new Error(\"No sub present in id_token\"));\n                }\n\n                response.profile = payload;\n                return response;\n            });\n        });\n    };\n\n    ResponseValidator.prototype._validateIdTokenAndAccessToken = function _validateIdTokenAndAccessToken(state, response) {\n        var _this5 = this;\n\n        return this._validateIdToken(state, response).then(function (response) {\n            return _this5._validateAccessToken(response);\n        });\n    };\n\n    ResponseValidator.prototype._validateIdToken = function _validateIdToken(state, response) {\n        var _this6 = this;\n\n        if (!state.nonce) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: No nonce on state\");\n            return Promise.reject(new Error(\"No nonce on state\"));\n        }\n\n        var jwt = this._joseUtil.parseJwt(response.id_token);\n        if (!jwt || !jwt.header || !jwt.payload) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: Failed to parse id_token\", jwt);\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\n        }\n\n        if (state.nonce !== jwt.payload.nonce) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: Invalid nonce in id_token\");\n            return Promise.reject(new Error(\"Invalid nonce in id_token\"));\n        }\n\n        var kid = jwt.header.kid;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n            _Log.Log.debug(\"ResponseValidator._validateIdToken: Received issuer\");\n\n            return _this6._metadataService.getSigningKeys().then(function (keys) {\n                if (!keys) {\n                    _Log.Log.error(\"ResponseValidator._validateIdToken: No signing keys from metadata\");\n                    return Promise.reject(new Error(\"No signing keys from metadata\"));\n                }\n\n                _Log.Log.debug(\"ResponseValidator._validateIdToken: Received signing keys\");\n                var key = void 0;\n                if (!kid) {\n                    keys = _this6._filterByAlg(keys, jwt.header.alg);\n\n                    if (keys.length > 1) {\n                        _Log.Log.error(\"ResponseValidator._validateIdToken: No kid found in id_token and more than one key found in metadata\");\n                        return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\n                    } else {\n                        // kid is mandatory only when there are multiple keys in the referenced JWK Set document\n                        // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\n                        key = keys[0];\n                    }\n                } else {\n                    key = keys.filter(function (key) {\n                        return key.kid === kid;\n                    })[0];\n                }\n\n                if (!key) {\n                    _Log.Log.error(\"ResponseValidator._validateIdToken: No key matching kid or alg found in signing keys\");\n                    return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\n                }\n\n                var audience = state.client_id;\n\n                var clockSkewInSeconds = _this6._settings.clockSkew;\n                _Log.Log.debug(\"ResponseValidator._validateIdToken: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n                return _this6._joseUtil.validateJwt(response.id_token, key, issuer, audience, clockSkewInSeconds).then(function () {\n                    _Log.Log.debug(\"ResponseValidator._validateIdToken: JWT validation successful\");\n\n                    if (!jwt.payload.sub) {\n                        _Log.Log.error(\"ResponseValidator._validateIdToken: No sub present in id_token\");\n                        return Promise.reject(new Error(\"No sub present in id_token\"));\n                    }\n\n                    response.profile = jwt.payload;\n\n                    return response;\n                });\n            });\n        });\n    };\n\n    ResponseValidator.prototype._filterByAlg = function _filterByAlg(keys, alg) {\n        var kty = null;\n        if (alg.startsWith(\"RS\")) {\n            kty = \"RSA\";\n        } else if (alg.startsWith(\"PS\")) {\n            kty = \"PS\";\n        } else if (alg.startsWith(\"ES\")) {\n            kty = \"EC\";\n        } else {\n            _Log.Log.debug(\"ResponseValidator._filterByAlg: alg not supported: \", alg);\n            return [];\n        }\n\n        _Log.Log.debug(\"ResponseValidator._filterByAlg: Looking for keys that match kty: \", kty);\n\n        keys = keys.filter(function (key) {\n            return key.kty === kty;\n        });\n\n        _Log.Log.debug(\"ResponseValidator._filterByAlg: Number of keys that match kty: \", kty, keys.length);\n\n        return keys;\n    };\n\n    ResponseValidator.prototype._validateAccessToken = function _validateAccessToken(response) {\n        if (!response.profile) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No profile loaded from id_token\");\n            return Promise.reject(new Error(\"No profile loaded from id_token\"));\n        }\n\n        if (!response.profile.at_hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No at_hash in id_token\");\n            return Promise.reject(new Error(\"No at_hash in id_token\"));\n        }\n\n        if (!response.id_token) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No id_token\");\n            return Promise.reject(new Error(\"No id_token\"));\n        }\n\n        var jwt = this._joseUtil.parseJwt(response.id_token);\n        if (!jwt || !jwt.header) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Failed to parse id_token\", jwt);\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\n        }\n\n        var hashAlg = jwt.header.alg;\n        if (!hashAlg || hashAlg.length !== 5) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        var hashBits = hashAlg.substr(2, 3);\n        if (!hashBits) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        hashBits = parseInt(hashBits);\n        if (hashBits !== 256 && hashBits !== 384 && hashBits !== 512) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        var sha = \"sha\" + hashBits;\n        var hash = this._joseUtil.hashString(response.access_token, sha);\n        if (!hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: access_token hash failed:\", sha);\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\n        }\n\n        var left = hash.substr(0, hash.length / 2);\n        var left_b64u = this._joseUtil.hexToBase64Url(left);\n        if (left_b64u !== response.profile.at_hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Failed to validate at_hash\", left_b64u, response.profile.at_hash);\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\n        }\n\n        _Log.Log.debug(\"ResponseValidator._validateAccessToken: success\");\n\n        return Promise.resolve(response);\n    };\n\n    return ResponseValidator;\n}();\n\n/***/ }),\n\n/***/ \"./src/SessionMonitor.js\":\n/*!*******************************!*\\\n  !*** ./src/SessionMonitor.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SessionMonitor = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _CheckSessionIFrame = __webpack_require__(/*! ./CheckSessionIFrame.js */ \"./src/CheckSessionIFrame.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar SessionMonitor = exports.SessionMonitor = function () {\n    function SessionMonitor(userManager) {\n        var _this = this;\n\n        var CheckSessionIFrameCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _CheckSessionIFrame.CheckSessionIFrame;\n        var timer = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _Global.Global.timer;\n\n        _classCallCheck(this, SessionMonitor);\n\n        if (!userManager) {\n            _Log.Log.error(\"SessionMonitor.ctor: No user manager passed to SessionMonitor\");\n            throw new Error(\"userManager\");\n        }\n\n        this._userManager = userManager;\n        this._CheckSessionIFrameCtor = CheckSessionIFrameCtor;\n        this._timer = timer;\n\n        this._userManager.events.addUserLoaded(this._start.bind(this));\n        this._userManager.events.addUserUnloaded(this._stop.bind(this));\n\n        this._userManager.getUser().then(function (user) {\n            // doing this manually here since calling getUser \n            // doesn't trigger load event.\n            if (user) {\n                _this._start(user);\n            } else if (_this._settings.monitorAnonymousSession) {\n                _this._userManager.querySessionStatus().then(function (session) {\n                    var tmpUser = {\n                        session_state: session.session_state\n                    };\n                    if (session.sub && session.sid) {\n                        tmpUser.profile = {\n                            sub: session.sub,\n                            sid: session.sid\n                        };\n                    }\n                    _this._start(tmpUser);\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in a ctor\n                    _Log.Log.error(\"SessionMonitor ctor: error from querySessionStatus:\", err.message);\n                });\n            }\n        }).catch(function (err) {\n            // catch to suppress errors since we're in a ctor\n            _Log.Log.error(\"SessionMonitor ctor: error from getUser:\", err.message);\n        });\n    }\n\n    SessionMonitor.prototype._start = function _start(user) {\n        var _this2 = this;\n\n        var session_state = user.session_state;\n\n        if (session_state) {\n            if (user.profile) {\n                this._sub = user.profile.sub;\n                this._sid = user.profile.sid;\n                _Log.Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", sub:\", this._sub);\n            } else {\n                this._sub = undefined;\n                this._sid = undefined;\n                _Log.Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", anonymous user\");\n            }\n\n            if (!this._checkSessionIFrame) {\n                this._metadataService.getCheckSessionIframe().then(function (url) {\n                    if (url) {\n                        _Log.Log.debug(\"SessionMonitor._start: Initializing check session iframe\");\n\n                        var client_id = _this2._client_id;\n                        var interval = _this2._checkSessionInterval;\n                        var stopOnError = _this2._stopCheckSessionOnError;\n\n                        _this2._checkSessionIFrame = new _this2._CheckSessionIFrameCtor(_this2._callback.bind(_this2), client_id, url, interval, stopOnError);\n                        _this2._checkSessionIFrame.load().then(function () {\n                            _this2._checkSessionIFrame.start(session_state);\n                        });\n                    } else {\n                        _Log.Log.warn(\"SessionMonitor._start: No check session iframe found in the metadata\");\n                    }\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in non-promise callback\n                    _Log.Log.error(\"SessionMonitor._start: Error from getCheckSessionIframe:\", err.message);\n                });\n            } else {\n                this._checkSessionIFrame.start(session_state);\n            }\n        }\n    };\n\n    SessionMonitor.prototype._stop = function _stop() {\n        var _this3 = this;\n\n        this._sub = undefined;\n        this._sid = undefined;\n\n        if (this._checkSessionIFrame) {\n            _Log.Log.debug(\"SessionMonitor._stop\");\n            this._checkSessionIFrame.stop();\n        }\n\n        if (this._settings.monitorAnonymousSession) {\n            // using a timer to delay re-initialization to avoid race conditions during signout\n            var timerHandle = this._timer.setInterval(function () {\n                _this3._timer.clearInterval(timerHandle);\n\n                _this3._userManager.querySessionStatus().then(function (session) {\n                    var tmpUser = {\n                        session_state: session.session_state\n                    };\n                    if (session.sub && session.sid) {\n                        tmpUser.profile = {\n                            sub: session.sub,\n                            sid: session.sid\n                        };\n                    }\n                    _this3._start(tmpUser);\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in a callback\n                    _Log.Log.error(\"SessionMonitor: error from querySessionStatus:\", err.message);\n                });\n            }, 1000);\n        }\n    };\n\n    SessionMonitor.prototype._callback = function _callback() {\n        var _this4 = this;\n\n        this._userManager.querySessionStatus().then(function (session) {\n            var raiseEvent = true;\n\n            if (session) {\n                if (session.sub === _this4._sub) {\n                    raiseEvent = false;\n                    _this4._checkSessionIFrame.start(session.session_state);\n\n                    if (session.sid === _this4._sid) {\n                        _Log.Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, restarting check session iframe; session_state:\", session.session_state);\n                    } else {\n                        _Log.Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, session state has changed, restarting check session iframe; session_state:\", session.session_state);\n                        _this4._userManager.events._raiseUserSessionChanged();\n                    }\n                } else {\n                    _Log.Log.debug(\"SessionMonitor._callback: Different subject signed into OP:\", session.sub);\n                }\n            } else {\n                _Log.Log.debug(\"SessionMonitor._callback: Subject no longer signed into OP\");\n            }\n\n            if (raiseEvent) {\n                if (_this4._sub) {\n                    _Log.Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed out event\");\n                    _this4._userManager.events._raiseUserSignedOut();\n                } else {\n                    _Log.Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed in event\");\n                    _this4._userManager.events._raiseUserSignedIn();\n                }\n            }\n        }).catch(function (err) {\n            if (_this4._sub) {\n                _Log.Log.debug(\"SessionMonitor._callback: Error calling queryCurrentSigninSession; raising signed out event\", err.message);\n                _this4._userManager.events._raiseUserSignedOut();\n            }\n        });\n    };\n\n    _createClass(SessionMonitor, [{\n        key: '_settings',\n        get: function get() {\n            return this._userManager.settings;\n        }\n    }, {\n        key: '_metadataService',\n        get: function get() {\n            return this._userManager.metadataService;\n        }\n    }, {\n        key: '_client_id',\n        get: function get() {\n            return this._settings.client_id;\n        }\n    }, {\n        key: '_checkSessionInterval',\n        get: function get() {\n            return this._settings.checkSessionInterval;\n        }\n    }, {\n        key: '_stopCheckSessionOnError',\n        get: function get() {\n            return this._settings.stopCheckSessionOnError;\n        }\n    }]);\n\n    return SessionMonitor;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninRequest.js\":\n/*!******************************!*\\\n  !*** ./src/SigninRequest.js ***!\n  \\******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninRequest = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nvar _SigninState = __webpack_require__(/*! ./SigninState.js */ \"./src/SigninState.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SigninRequest = exports.SigninRequest = function () {\n    function SigninRequest(_ref) {\n        var url = _ref.url,\n            client_id = _ref.client_id,\n            redirect_uri = _ref.redirect_uri,\n            response_type = _ref.response_type,\n            scope = _ref.scope,\n            authority = _ref.authority,\n            data = _ref.data,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            id_token_hint = _ref.id_token_hint,\n            login_hint = _ref.login_hint,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            response_mode = _ref.response_mode,\n            request = _ref.request,\n            request_uri = _ref.request_uri,\n            extraQueryParams = _ref.extraQueryParams,\n            request_type = _ref.request_type,\n            client_secret = _ref.client_secret,\n            extraTokenParams = _ref.extraTokenParams,\n            skipUserInfo = _ref.skipUserInfo;\n\n        _classCallCheck(this, SigninRequest);\n\n        if (!url) {\n            _Log.Log.error(\"SigninRequest.ctor: No url passed\");\n            throw new Error(\"url\");\n        }\n        if (!client_id) {\n            _Log.Log.error(\"SigninRequest.ctor: No client_id passed\");\n            throw new Error(\"client_id\");\n        }\n        if (!redirect_uri) {\n            _Log.Log.error(\"SigninRequest.ctor: No redirect_uri passed\");\n            throw new Error(\"redirect_uri\");\n        }\n        if (!response_type) {\n            _Log.Log.error(\"SigninRequest.ctor: No response_type passed\");\n            throw new Error(\"response_type\");\n        }\n        if (!scope) {\n            _Log.Log.error(\"SigninRequest.ctor: No scope passed\");\n            throw new Error(\"scope\");\n        }\n        if (!authority) {\n            _Log.Log.error(\"SigninRequest.ctor: No authority passed\");\n            throw new Error(\"authority\");\n        }\n\n        var oidc = SigninRequest.isOidc(response_type);\n        var code = SigninRequest.isCode(response_type);\n\n        if (!response_mode) {\n            response_mode = SigninRequest.isCode(response_type) ? \"query\" : null;\n        }\n\n        this.state = new _SigninState.SigninState({ nonce: oidc,\n            data: data, client_id: client_id, authority: authority, redirect_uri: redirect_uri,\n            code_verifier: code,\n            request_type: request_type, response_mode: response_mode,\n            client_secret: client_secret, scope: scope, extraTokenParams: extraTokenParams, skipUserInfo: skipUserInfo });\n\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"client_id\", client_id);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"redirect_uri\", redirect_uri);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"response_type\", response_type);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"scope\", scope);\n\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"state\", this.state.id);\n        if (oidc) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"nonce\", this.state.nonce);\n        }\n        if (code) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"code_challenge\", this.state.code_challenge);\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"code_challenge_method\", \"S256\");\n        }\n\n        var optional = { prompt: prompt, display: display, max_age: max_age, ui_locales: ui_locales, id_token_hint: id_token_hint, login_hint: login_hint, acr_values: acr_values, resource: resource, request: request, request_uri: request_uri, response_mode: response_mode };\n        for (var key in optional) {\n            if (optional[key]) {\n                url = _UrlUtility.UrlUtility.addQueryParam(url, key, optional[key]);\n            }\n        }\n\n        for (var _key in extraQueryParams) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, _key, extraQueryParams[_key]);\n        }\n\n        this.url = url;\n    }\n\n    SigninRequest.isOidc = function isOidc(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"id_token\";\n        });\n        return !!result[0];\n    };\n\n    SigninRequest.isOAuth = function isOAuth(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"token\";\n        });\n        return !!result[0];\n    };\n\n    SigninRequest.isCode = function isCode(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"code\";\n        });\n        return !!result[0];\n    };\n\n    return SigninRequest;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninResponse.js\":\n/*!*******************************!*\\\n  !*** ./src/SigninResponse.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninResponse = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcScope = \"openid\";\n\nvar SigninResponse = exports.SigninResponse = function () {\n    function SigninResponse(url) {\n        var delimiter = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : \"#\";\n\n        _classCallCheck(this, SigninResponse);\n\n        var values = _UrlUtility.UrlUtility.parseUrlFragment(url, delimiter);\n\n        this.error = values.error;\n        this.error_description = values.error_description;\n        this.error_uri = values.error_uri;\n\n        this.code = values.code;\n        this.state = values.state;\n        this.id_token = values.id_token;\n        this.session_state = values.session_state;\n        this.access_token = values.access_token;\n        this.token_type = values.token_type;\n        this.scope = values.scope;\n        this.profile = undefined; // will be set from ResponseValidator\n\n        this.expires_in = values.expires_in;\n    }\n\n    _createClass(SigninResponse, [{\n        key: \"expires_in\",\n        get: function get() {\n            if (this.expires_at) {\n                var now = parseInt(Date.now() / 1000);\n                return this.expires_at - now;\n            }\n            return undefined;\n        },\n        set: function set(value) {\n            var expires_in = parseInt(value);\n            if (typeof expires_in === 'number' && expires_in > 0) {\n                var now = parseInt(Date.now() / 1000);\n                this.expires_at = now + expires_in;\n            }\n        }\n    }, {\n        key: \"expired\",\n        get: function get() {\n            var expires_in = this.expires_in;\n            if (expires_in !== undefined) {\n                return expires_in <= 0;\n            }\n            return undefined;\n        }\n    }, {\n        key: \"scopes\",\n        get: function get() {\n            return (this.scope || \"\").split(\" \");\n        }\n    }, {\n        key: \"isOpenIdConnect\",\n        get: function get() {\n            return this.scopes.indexOf(OidcScope) >= 0 || !!this.id_token;\n        }\n    }]);\n\n    return SigninResponse;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninState.js\":\n/*!****************************!*\\\n  !*** ./src/SigninState.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninState = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _State2 = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nvar _random = __webpack_require__(/*! ./random.js */ \"./src/random.js\");\n\nvar _random2 = _interopRequireDefault(_random);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SigninState = exports.SigninState = function (_State) {\n    _inherits(SigninState, _State);\n\n    function SigninState() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            nonce = _ref.nonce,\n            authority = _ref.authority,\n            client_id = _ref.client_id,\n            redirect_uri = _ref.redirect_uri,\n            code_verifier = _ref.code_verifier,\n            response_mode = _ref.response_mode,\n            client_secret = _ref.client_secret,\n            scope = _ref.scope,\n            extraTokenParams = _ref.extraTokenParams,\n            skipUserInfo = _ref.skipUserInfo;\n\n        _classCallCheck(this, SigninState);\n\n        var _this = _possibleConstructorReturn(this, _State.call(this, arguments[0]));\n\n        if (nonce === true) {\n            _this._nonce = (0, _random2.default)();\n        } else if (nonce) {\n            _this._nonce = nonce;\n        }\n\n        if (code_verifier === true) {\n            // random() produces 32 length\n            _this._code_verifier = (0, _random2.default)() + (0, _random2.default)() + (0, _random2.default)();\n        } else if (code_verifier) {\n            _this._code_verifier = code_verifier;\n        }\n\n        if (_this.code_verifier) {\n            var hash = _JoseUtil.JoseUtil.hashString(_this.code_verifier, \"SHA256\");\n            _this._code_challenge = _JoseUtil.JoseUtil.hexToBase64Url(hash);\n        }\n\n        _this._redirect_uri = redirect_uri;\n        _this._authority = authority;\n        _this._client_id = client_id;\n        _this._response_mode = response_mode;\n        _this._client_secret = client_secret;\n        _this._scope = scope;\n        _this._extraTokenParams = extraTokenParams;\n        _this._skipUserInfo = skipUserInfo;\n        return _this;\n    }\n\n    SigninState.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"SigninState.toStorageString\");\n        return JSON.stringify({\n            id: this.id,\n            data: this.data,\n            created: this.created,\n            request_type: this.request_type,\n            nonce: this.nonce,\n            code_verifier: this.code_verifier,\n            redirect_uri: this.redirect_uri,\n            authority: this.authority,\n            client_id: this.client_id,\n            response_mode: this.response_mode,\n            client_secret: this.client_secret,\n            scope: this.scope,\n            extraTokenParams: this.extraTokenParams,\n            skipUserInfo: this.skipUserInfo\n        });\n    };\n\n    SigninState.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"SigninState.fromStorageString\");\n        var data = JSON.parse(storageString);\n        return new SigninState(data);\n    };\n\n    _createClass(SigninState, [{\n        key: 'nonce',\n        get: function get() {\n            return this._nonce;\n        }\n    }, {\n        key: 'authority',\n        get: function get() {\n            return this._authority;\n        }\n    }, {\n        key: 'client_id',\n        get: function get() {\n            return this._client_id;\n        }\n    }, {\n        key: 'redirect_uri',\n        get: function get() {\n            return this._redirect_uri;\n        }\n    }, {\n        key: 'code_verifier',\n        get: function get() {\n            return this._code_verifier;\n        }\n    }, {\n        key: 'code_challenge',\n        get: function get() {\n            return this._code_challenge;\n        }\n    }, {\n        key: 'response_mode',\n        get: function get() {\n            return this._response_mode;\n        }\n    }, {\n        key: 'client_secret',\n        get: function get() {\n            return this._client_secret;\n        }\n    }, {\n        key: 'scope',\n        get: function get() {\n            return this._scope;\n        }\n    }, {\n        key: 'extraTokenParams',\n        get: function get() {\n            return this._extraTokenParams;\n        }\n    }, {\n        key: 'skipUserInfo',\n        get: function get() {\n            return this._skipUserInfo;\n        }\n    }]);\n\n    return SigninState;\n}(_State2.State);\n\n/***/ }),\n\n/***/ \"./src/SignoutRequest.js\":\n/*!*******************************!*\\\n  !*** ./src/SignoutRequest.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SignoutRequest = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nvar _State = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SignoutRequest = exports.SignoutRequest = function SignoutRequest(_ref) {\n    var url = _ref.url,\n        id_token_hint = _ref.id_token_hint,\n        post_logout_redirect_uri = _ref.post_logout_redirect_uri,\n        data = _ref.data,\n        extraQueryParams = _ref.extraQueryParams,\n        request_type = _ref.request_type;\n\n    _classCallCheck(this, SignoutRequest);\n\n    if (!url) {\n        _Log.Log.error(\"SignoutRequest.ctor: No url passed\");\n        throw new Error(\"url\");\n    }\n\n    if (id_token_hint) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"id_token_hint\", id_token_hint);\n    }\n\n    if (post_logout_redirect_uri) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"post_logout_redirect_uri\", post_logout_redirect_uri);\n\n        if (data) {\n            this.state = new _State.State({ data: data, request_type: request_type });\n\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"state\", this.state.id);\n        }\n    }\n\n    for (var key in extraQueryParams) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, key, extraQueryParams[key]);\n    }\n\n    this.url = url;\n};\n\n/***/ }),\n\n/***/ \"./src/SignoutResponse.js\":\n/*!********************************!*\\\n  !*** ./src/SignoutResponse.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n        value: true\n});\nexports.SignoutResponse = undefined;\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SignoutResponse = exports.SignoutResponse = function SignoutResponse(url) {\n        _classCallCheck(this, SignoutResponse);\n\n        var values = _UrlUtility.UrlUtility.parseUrlFragment(url, \"?\");\n\n        this.error = values.error;\n        this.error_description = values.error_description;\n        this.error_uri = values.error_uri;\n\n        this.state = values.state;\n};\n\n/***/ }),\n\n/***/ \"./src/SilentRenewService.js\":\n/*!***********************************!*\\\n  !*** ./src/SilentRenewService.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SilentRenewService = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SilentRenewService = exports.SilentRenewService = function () {\n    function SilentRenewService(userManager) {\n        _classCallCheck(this, SilentRenewService);\n\n        this._userManager = userManager;\n    }\n\n    SilentRenewService.prototype.start = function start() {\n        if (!this._callback) {\n            this._callback = this._tokenExpiring.bind(this);\n            this._userManager.events.addAccessTokenExpiring(this._callback);\n\n            // this will trigger loading of the user so the expiring events can be initialized\n            this._userManager.getUser().then(function (user) {\n                // deliberate nop\n            }).catch(function (err) {\n                // catch to suppress errors since we're in a ctor\n                _Log.Log.error(\"SilentRenewService.start: Error from getUser:\", err.message);\n            });\n        }\n    };\n\n    SilentRenewService.prototype.stop = function stop() {\n        if (this._callback) {\n            this._userManager.events.removeAccessTokenExpiring(this._callback);\n            delete this._callback;\n        }\n    };\n\n    SilentRenewService.prototype._tokenExpiring = function _tokenExpiring() {\n        var _this = this;\n\n        this._userManager.signinSilent().then(function (user) {\n            _Log.Log.debug(\"SilentRenewService._tokenExpiring: Silent token renewal successful\");\n        }, function (err) {\n            _Log.Log.error(\"SilentRenewService._tokenExpiring: Error from signinSilent:\", err.message);\n            _this._userManager.events._raiseSilentRenewError(err);\n        });\n    };\n\n    return SilentRenewService;\n}();\n\n/***/ }),\n\n/***/ \"./src/State.js\":\n/*!**********************!*\\\n  !*** ./src/State.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.State = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _random = __webpack_require__(/*! ./random.js */ \"./src/random.js\");\n\nvar _random2 = _interopRequireDefault(_random);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar State = exports.State = function () {\n    function State() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            id = _ref.id,\n            data = _ref.data,\n            created = _ref.created,\n            request_type = _ref.request_type;\n\n        _classCallCheck(this, State);\n\n        this._id = id || (0, _random2.default)();\n        this._data = data;\n\n        if (typeof created === 'number' && created > 0) {\n            this._created = created;\n        } else {\n            this._created = parseInt(Date.now() / 1000);\n        }\n        this._request_type = request_type;\n    }\n\n    State.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"State.toStorageString\");\n        return JSON.stringify({\n            id: this.id,\n            data: this.data,\n            created: this.created,\n            request_type: this.request_type\n        });\n    };\n\n    State.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"State.fromStorageString\");\n        return new State(JSON.parse(storageString));\n    };\n\n    State.clearStaleState = function clearStaleState(storage, age) {\n\n        var cutoff = Date.now() / 1000 - age;\n\n        return storage.getAllKeys().then(function (keys) {\n            _Log.Log.debug(\"State.clearStaleState: got keys\", keys);\n\n            var promises = [];\n\n            var _loop = function _loop(i) {\n                var key = keys[i];\n                p = storage.get(key).then(function (item) {\n                    var remove = false;\n\n                    if (item) {\n                        try {\n                            var state = State.fromStorageString(item);\n\n                            _Log.Log.debug(\"State.clearStaleState: got item from key: \", key, state.created);\n\n                            if (state.created <= cutoff) {\n                                remove = true;\n                            }\n                        } catch (e) {\n                            _Log.Log.error(\"State.clearStaleState: Error parsing state for key\", key, e.message);\n                            remove = true;\n                        }\n                    } else {\n                        _Log.Log.debug(\"State.clearStaleState: no item in storage for key: \", key);\n                        remove = true;\n                    }\n\n                    if (remove) {\n                        _Log.Log.debug(\"State.clearStaleState: removed item for key: \", key);\n                        return storage.remove(key);\n                    }\n                });\n\n\n                promises.push(p);\n            };\n\n            for (var i = 0; i < keys.length; i++) {\n                var p;\n\n                _loop(i);\n            }\n\n            _Log.Log.debug(\"State.clearStaleState: waiting on promise count:\", promises.length);\n            return Promise.all(promises);\n        });\n    };\n\n    _createClass(State, [{\n        key: 'id',\n        get: function get() {\n            return this._id;\n        }\n    }, {\n        key: 'data',\n        get: function get() {\n            return this._data;\n        }\n    }, {\n        key: 'created',\n        get: function get() {\n            return this._created;\n        }\n    }, {\n        key: 'request_type',\n        get: function get() {\n            return this._request_type;\n        }\n    }]);\n\n    return State;\n}();\n\n/***/ }),\n\n/***/ \"./src/Timer.js\":\n/*!**********************!*\\\n  !*** ./src/Timer.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.Timer = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nvar _Event2 = __webpack_require__(/*! ./Event.js */ \"./src/Event.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar TimerDuration = 5; // seconds\n\nvar Timer = exports.Timer = function (_Event) {\n    _inherits(Timer, _Event);\n\n    function Timer(name) {\n        var timer = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.timer;\n        var nowFunc = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : undefined;\n\n        _classCallCheck(this, Timer);\n\n        var _this = _possibleConstructorReturn(this, _Event.call(this, name));\n\n        _this._timer = timer;\n\n        if (nowFunc) {\n            _this._nowFunc = nowFunc;\n        } else {\n            _this._nowFunc = function () {\n                return Date.now() / 1000;\n            };\n        }\n        return _this;\n    }\n\n    Timer.prototype.init = function init(duration) {\n        if (duration <= 0) {\n            duration = 1;\n        }\n        duration = parseInt(duration);\n\n        var expiration = this.now + duration;\n        if (this.expiration === expiration && this._timerHandle) {\n            // no need to reinitialize to same expiration, so bail out\n            _Log.Log.debug(\"Timer.init timer \" + this._name + \" skipping initialization since already initialized for expiration:\", this.expiration);\n            return;\n        }\n\n        this.cancel();\n\n        _Log.Log.debug(\"Timer.init timer \" + this._name + \" for duration:\", duration);\n        this._expiration = expiration;\n\n        // we're using a fairly short timer and then checking the expiration in the\n        // callback to handle scenarios where the browser device sleeps, and then\n        // the timers end up getting delayed.\n        var timerDuration = TimerDuration;\n        if (duration < timerDuration) {\n            timerDuration = duration;\n        }\n        this._timerHandle = this._timer.setInterval(this._callback.bind(this), timerDuration * 1000);\n    };\n\n    Timer.prototype.cancel = function cancel() {\n        if (this._timerHandle) {\n            _Log.Log.debug(\"Timer.cancel: \", this._name);\n            this._timer.clearInterval(this._timerHandle);\n            this._timerHandle = null;\n        }\n    };\n\n    Timer.prototype._callback = function _callback() {\n        var diff = this._expiration - this.now;\n        _Log.Log.debug(\"Timer.callback; \" + this._name + \" timer expires in:\", diff);\n\n        if (this._expiration <= this.now) {\n            this.cancel();\n            _Event.prototype.raise.call(this);\n        }\n    };\n\n    _createClass(Timer, [{\n        key: 'now',\n        get: function get() {\n            return parseInt(this._nowFunc());\n        }\n    }, {\n        key: 'expiration',\n        get: function get() {\n            return this._expiration;\n        }\n    }]);\n\n    return Timer;\n}(_Event2.Event);\n\n/***/ }),\n\n/***/ \"./src/TokenClient.js\":\n/*!****************************!*\\\n  !*** ./src/TokenClient.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.TokenClient = undefined;\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar TokenClient = exports.TokenClient = function () {\n    function TokenClient(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n\n        _classCallCheck(this, TokenClient);\n\n        if (!settings) {\n            _Log.Log.error(\"TokenClient.ctor: No settings passed\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor();\n        this._metadataService = new MetadataServiceCtor(this._settings);\n    }\n\n    TokenClient.prototype.exchangeCode = function exchangeCode() {\n        var _this = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.grant_type = args.grant_type || \"authorization_code\";\n        args.client_id = args.client_id || this._settings.client_id;\n        args.redirect_uri = args.redirect_uri || this._settings.redirect_uri;\n\n        if (!args.code) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No code passed\");\n            return Promise.reject(new Error(\"A code is required\"));\n        }\n        if (!args.redirect_uri) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No redirect_uri passed\");\n            return Promise.reject(new Error(\"A redirect_uri is required\"));\n        }\n        if (!args.code_verifier) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No code_verifier passed\");\n            return Promise.reject(new Error(\"A code_verifier is required\"));\n        }\n        if (!args.client_id) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No client_id passed\");\n            return Promise.reject(new Error(\"A client_id is required\"));\n        }\n\n        return this._metadataService.getTokenEndpoint(false).then(function (url) {\n            _Log.Log.debug(\"TokenClient.exchangeCode: Received token endpoint\");\n\n            return _this._jsonService.postForm(url, args).then(function (response) {\n                _Log.Log.debug(\"TokenClient.exchangeCode: response received\");\n                return response;\n            });\n        });\n    };\n\n    TokenClient.prototype.exchangeRefreshToken = function exchangeRefreshToken() {\n        var _this2 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.grant_type = args.grant_type || \"refresh_token\";\n        args.client_id = args.client_id || this._settings.client_id;\n        args.client_secret = args.client_secret || this._settings.client_secret;\n\n        if (!args.refresh_token) {\n            _Log.Log.error(\"TokenClient.exchangeRefreshToken: No refresh_token passed\");\n            return Promise.reject(new Error(\"A refresh_token is required\"));\n        }\n        if (!args.client_id) {\n            _Log.Log.error(\"TokenClient.exchangeRefreshToken: No client_id passed\");\n            return Promise.reject(new Error(\"A client_id is required\"));\n        }\n\n        return this._metadataService.getTokenEndpoint(false).then(function (url) {\n            _Log.Log.debug(\"TokenClient.exchangeRefreshToken: Received token endpoint\");\n\n            return _this2._jsonService.postForm(url, args).then(function (response) {\n                _Log.Log.debug(\"TokenClient.exchangeRefreshToken: response received\");\n                return response;\n            });\n        });\n    };\n\n    return TokenClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/TokenRevocationClient.js\":\n/*!**************************************!*\\\n  !*** ./src/TokenRevocationClient.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.TokenRevocationClient = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar AccessTokenTypeHint = \"access_token\";\nvar RefreshTokenTypeHint = \"refresh_token\";\n\nvar TokenRevocationClient = exports.TokenRevocationClient = function () {\n    function TokenRevocationClient(settings) {\n        var XMLHttpRequestCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.XMLHttpRequest;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n\n        _classCallCheck(this, TokenRevocationClient);\n\n        if (!settings) {\n            _Log.Log.error(\"TokenRevocationClient.ctor: No settings provided\");\n            throw new Error(\"No settings provided.\");\n        }\n\n        this._settings = settings;\n        this._XMLHttpRequestCtor = XMLHttpRequestCtor;\n        this._metadataService = new MetadataServiceCtor(this._settings);\n    }\n\n    TokenRevocationClient.prototype.revoke = function revoke(token, required) {\n        var _this = this;\n\n        var type = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : \"access_token\";\n\n        if (!token) {\n            _Log.Log.error(\"TokenRevocationClient.revoke: No token provided\");\n            throw new Error(\"No token provided.\");\n        }\n\n        if (type !== AccessTokenTypeHint && type != RefreshTokenTypeHint) {\n            _Log.Log.error(\"TokenRevocationClient.revoke: Invalid token type\");\n            throw new Error(\"Invalid token type.\");\n        }\n\n        return this._metadataService.getRevocationEndpoint().then(function (url) {\n            if (!url) {\n                if (required) {\n                    _Log.Log.error(\"TokenRevocationClient.revoke: Revocation not supported\");\n                    throw new Error(\"Revocation not supported\");\n                }\n\n                // not required, so don't error and just return\n                return;\n            }\n\n            _Log.Log.debug(\"TokenRevocationClient.revoke: Revoking \" + type);\n            var client_id = _this._settings.client_id;\n            var client_secret = _this._settings.client_secret;\n            return _this._revoke(url, client_id, client_secret, token, type);\n        });\n    };\n\n    TokenRevocationClient.prototype._revoke = function _revoke(url, client_id, client_secret, token, type) {\n        var _this2 = this;\n\n        return new Promise(function (resolve, reject) {\n\n            var xhr = new _this2._XMLHttpRequestCtor();\n            xhr.open(\"POST\", url);\n\n            xhr.onload = function () {\n                _Log.Log.debug(\"TokenRevocationClient.revoke: HTTP response received, status\", xhr.status);\n\n                if (xhr.status === 200) {\n                    resolve();\n                } else {\n                    reject(Error(xhr.statusText + \" (\" + xhr.status + \")\"));\n                }\n            };\n            xhr.onerror = function () {\n                _Log.Log.debug(\"TokenRevocationClient.revoke: Network Error.\");\n                reject(\"Network Error\");\n            };\n\n            var body = \"client_id=\" + encodeURIComponent(client_id);\n            if (client_secret) {\n                body += \"&client_secret=\" + encodeURIComponent(client_secret);\n            }\n            body += \"&token_type_hint=\" + encodeURIComponent(type);\n            body += \"&token=\" + encodeURIComponent(token);\n\n            xhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\n            xhr.send(body);\n        });\n    };\n\n    return TokenRevocationClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/UrlUtility.js\":\n/*!***************************!*\\\n  !*** ./src/UrlUtility.js ***!\n  \\***************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UrlUtility = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UrlUtility = exports.UrlUtility = function () {\n    function UrlUtility() {\n        _classCallCheck(this, UrlUtility);\n    }\n\n    UrlUtility.addQueryParam = function addQueryParam(url, name, value) {\n        if (url.indexOf('?') < 0) {\n            url += \"?\";\n        }\n\n        if (url[url.length - 1] !== \"?\") {\n            url += \"&\";\n        }\n\n        url += encodeURIComponent(name);\n        url += \"=\";\n        url += encodeURIComponent(value);\n\n        return url;\n    };\n\n    UrlUtility.parseUrlFragment = function parseUrlFragment(value) {\n        var delimiter = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : \"#\";\n        var global = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _Global.Global;\n\n        if (typeof value !== 'string') {\n            value = global.location.href;\n        }\n\n        var idx = value.lastIndexOf(delimiter);\n        if (idx >= 0) {\n            value = value.substr(idx + 1);\n        }\n\n        if (delimiter === \"?\") {\n            // if we're doing query, then strip off hash fragment before we parse\n            idx = value.indexOf('#');\n            if (idx >= 0) {\n                value = value.substr(0, idx);\n            }\n        }\n\n        var params = {},\n            regex = /([^&=]+)=([^&]*)/g,\n            m;\n\n        var counter = 0;\n        while (m = regex.exec(value)) {\n            params[decodeURIComponent(m[1])] = decodeURIComponent(m[2]);\n            if (counter++ > 50) {\n                _Log.Log.error(\"UrlUtility.parseUrlFragment: response exceeded expected number of parameters\", value);\n                return {\n                    error: \"Response exceeded expected number of parameters\"\n                };\n            }\n        }\n\n        for (var prop in params) {\n            return params;\n        }\n\n        return {};\n    };\n\n    return UrlUtility;\n}();\n\n/***/ }),\n\n/***/ \"./src/User.js\":\n/*!*********************!*\\\n  !*** ./src/User.js ***!\n  \\*********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.User = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar User = exports.User = function () {\n    function User(_ref) {\n        var id_token = _ref.id_token,\n            session_state = _ref.session_state,\n            access_token = _ref.access_token,\n            refresh_token = _ref.refresh_token,\n            token_type = _ref.token_type,\n            scope = _ref.scope,\n            profile = _ref.profile,\n            expires_at = _ref.expires_at,\n            state = _ref.state;\n\n        _classCallCheck(this, User);\n\n        this.id_token = id_token;\n        this.session_state = session_state;\n        this.access_token = access_token;\n        this.refresh_token = refresh_token;\n        this.token_type = token_type;\n        this.scope = scope;\n        this.profile = profile;\n        this.expires_at = expires_at;\n        this.state = state;\n    }\n\n    User.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"User.toStorageString\");\n        return JSON.stringify({\n            id_token: this.id_token,\n            session_state: this.session_state,\n            access_token: this.access_token,\n            refresh_token: this.refresh_token,\n            token_type: this.token_type,\n            scope: this.scope,\n            profile: this.profile,\n            expires_at: this.expires_at\n        });\n    };\n\n    User.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"User.fromStorageString\");\n        return new User(JSON.parse(storageString));\n    };\n\n    _createClass(User, [{\n        key: 'expires_in',\n        get: function get() {\n            if (this.expires_at) {\n                var now = parseInt(Date.now() / 1000);\n                return this.expires_at - now;\n            }\n            return undefined;\n        },\n        set: function set(value) {\n            var expires_in = parseInt(value);\n            if (typeof expires_in === 'number' && expires_in > 0) {\n                var now = parseInt(Date.now() / 1000);\n                this.expires_at = now + expires_in;\n            }\n        }\n    }, {\n        key: 'expired',\n        get: function get() {\n            var expires_in = this.expires_in;\n            if (expires_in !== undefined) {\n                return expires_in <= 0;\n            }\n            return undefined;\n        }\n    }, {\n        key: 'scopes',\n        get: function get() {\n            return (this.scope || \"\").split(\" \");\n        }\n    }]);\n\n    return User;\n}();\n\n/***/ }),\n\n/***/ \"./src/UserInfoService.js\":\n/*!********************************!*\\\n  !*** ./src/UserInfoService.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserInfoService = undefined;\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserInfoService = exports.UserInfoService = function () {\n    function UserInfoService(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n        var joseUtil = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _JoseUtil.JoseUtil;\n\n        _classCallCheck(this, UserInfoService);\n\n        if (!settings) {\n            _Log.Log.error(\"UserInfoService.ctor: No settings passed\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor(undefined, undefined, this._getClaimsFromJwt.bind(this));\n        this._metadataService = new MetadataServiceCtor(this._settings);\n        this._joseUtil = joseUtil;\n    }\n\n    UserInfoService.prototype.getClaims = function getClaims(token) {\n        var _this = this;\n\n        if (!token) {\n            _Log.Log.error(\"UserInfoService.getClaims: No token passed\");\n            return Promise.reject(new Error(\"A token is required\"));\n        }\n\n        return this._metadataService.getUserInfoEndpoint().then(function (url) {\n            _Log.Log.debug(\"UserInfoService.getClaims: received userinfo url\", url);\n\n            return _this._jsonService.getJson(url, token).then(function (claims) {\n                _Log.Log.debug(\"UserInfoService.getClaims: claims received\", claims);\n                return claims;\n            });\n        });\n    };\n\n    UserInfoService.prototype._getClaimsFromJwt = function _getClaimsFromJwt(req) {\n        var _this2 = this;\n\n        try {\n            var jwt = this._joseUtil.parseJwt(req.responseText);\n            if (!jwt || !jwt.header || !jwt.payload) {\n                _Log.Log.error(\"UserInfoService._getClaimsFromJwt: Failed to parse JWT\", jwt);\n                return Promise.reject(new Error(\"Failed to parse id_token\"));\n            }\n\n            var kid = jwt.header.kid;\n\n            var issuerPromise = void 0;\n            switch (this._settings.userInfoJwtIssuer) {\n                case 'OP':\n                    issuerPromise = this._metadataService.getIssuer();\n                    break;\n                case 'ANY':\n                    issuerPromise = Promise.resolve(jwt.payload.iss);\n                    break;\n                default:\n                    issuerPromise = Promise.resolve(this._settings.userInfoJwtIssuer);\n                    break;\n            }\n\n            return issuerPromise.then(function (issuer) {\n                _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Received issuer:\" + issuer);\n\n                return _this2._metadataService.getSigningKeys().then(function (keys) {\n                    if (!keys) {\n                        _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No signing keys from metadata\");\n                        return Promise.reject(new Error(\"No signing keys from metadata\"));\n                    }\n\n                    _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Received signing keys\");\n                    var key = void 0;\n                    if (!kid) {\n                        keys = _this2._filterByAlg(keys, jwt.header.alg);\n\n                        if (keys.length > 1) {\n                            _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No kid found in id_token and more than one key found in metadata\");\n                            return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\n                        } else {\n                            // kid is mandatory only when there are multiple keys in the referenced JWK Set document\n                            // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\n                            key = keys[0];\n                        }\n                    } else {\n                        key = keys.filter(function (key) {\n                            return key.kid === kid;\n                        })[0];\n                    }\n\n                    if (!key) {\n                        _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No key matching kid or alg found in signing keys\");\n                        return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\n                    }\n\n                    var audience = _this2._settings.client_id;\n\n                    var clockSkewInSeconds = _this2._settings.clockSkew;\n                    _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n                    return _this2._joseUtil.validateJwt(req.responseText, key, issuer, audience, clockSkewInSeconds, undefined, true).then(function () {\n                        _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: JWT validation successful\");\n                        return jwt.payload;\n                    });\n                });\n            });\n            return;\n        } catch (e) {\n            _Log.Log.error(\"UserInfoService._getClaimsFromJwt: Error parsing JWT response\", e.message);\n            reject(e);\n            return;\n        }\n    };\n\n    UserInfoService.prototype._filterByAlg = function _filterByAlg(keys, alg) {\n        var kty = null;\n        if (alg.startsWith(\"RS\")) {\n            kty = \"RSA\";\n        } else if (alg.startsWith(\"PS\")) {\n            kty = \"PS\";\n        } else if (alg.startsWith(\"ES\")) {\n            kty = \"EC\";\n        } else {\n            _Log.Log.debug(\"UserInfoService._filterByAlg: alg not supported: \", alg);\n            return [];\n        }\n\n        _Log.Log.debug(\"UserInfoService._filterByAlg: Looking for keys that match kty: \", kty);\n\n        keys = keys.filter(function (key) {\n            return key.kty === kty;\n        });\n\n        _Log.Log.debug(\"UserInfoService._filterByAlg: Number of keys that match kty: \", kty, keys.length);\n\n        return keys;\n    };\n\n    return UserInfoService;\n}();\n\n/***/ }),\n\n/***/ \"./src/UserManager.js\":\n/*!****************************!*\\\n  !*** ./src/UserManager.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManager = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClient2 = __webpack_require__(/*! ./OidcClient.js */ \"./src/OidcClient.js\");\n\nvar _UserManagerSettings = __webpack_require__(/*! ./UserManagerSettings.js */ \"./src/UserManagerSettings.js\");\n\nvar _User = __webpack_require__(/*! ./User.js */ \"./src/User.js\");\n\nvar _UserManagerEvents = __webpack_require__(/*! ./UserManagerEvents.js */ \"./src/UserManagerEvents.js\");\n\nvar _SilentRenewService = __webpack_require__(/*! ./SilentRenewService.js */ \"./src/SilentRenewService.js\");\n\nvar _SessionMonitor = __webpack_require__(/*! ./SessionMonitor.js */ \"./src/SessionMonitor.js\");\n\nvar _TokenRevocationClient = __webpack_require__(/*! ./TokenRevocationClient.js */ \"./src/TokenRevocationClient.js\");\n\nvar _TokenClient = __webpack_require__(/*! ./TokenClient.js */ \"./src/TokenClient.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserManager = exports.UserManager = function (_OidcClient) {\n    _inherits(UserManager, _OidcClient);\n\n    function UserManager() {\n        var settings = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n        var SilentRenewServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _SilentRenewService.SilentRenewService;\n        var SessionMonitorCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _SessionMonitor.SessionMonitor;\n        var TokenRevocationClientCtor = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _TokenRevocationClient.TokenRevocationClient;\n        var TokenClientCtor = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : _TokenClient.TokenClient;\n        var joseUtil = arguments.length > 5 && arguments[5] !== undefined ? arguments[5] : _JoseUtil.JoseUtil;\n\n        _classCallCheck(this, UserManager);\n\n        if (!(settings instanceof _UserManagerSettings.UserManagerSettings)) {\n            settings = new _UserManagerSettings.UserManagerSettings(settings);\n        }\n\n        var _this = _possibleConstructorReturn(this, _OidcClient.call(this, settings));\n\n        _this._events = new _UserManagerEvents.UserManagerEvents(settings);\n        _this._silentRenewService = new SilentRenewServiceCtor(_this);\n\n        // order is important for the following properties; these services depend upon the events.\n        if (_this.settings.automaticSilentRenew) {\n            _Log.Log.debug(\"UserManager.ctor: automaticSilentRenew is configured, setting up silent renew\");\n            _this.startSilentRenew();\n        }\n\n        if (_this.settings.monitorSession) {\n            _Log.Log.debug(\"UserManager.ctor: monitorSession is configured, setting up session monitor\");\n            _this._sessionMonitor = new SessionMonitorCtor(_this);\n        }\n\n        _this._tokenRevocationClient = new TokenRevocationClientCtor(_this._settings);\n        _this._tokenClient = new TokenClientCtor(_this._settings);\n        _this._joseUtil = joseUtil;\n        return _this;\n    }\n\n    UserManager.prototype.getUser = function getUser() {\n        var _this2 = this;\n\n        return this._loadUser().then(function (user) {\n            if (user) {\n                _Log.Log.info(\"UserManager.getUser: user loaded\");\n\n                _this2._events.load(user, false);\n\n                return user;\n            } else {\n                _Log.Log.info(\"UserManager.getUser: user not found in storage\");\n                return null;\n            }\n        });\n    };\n\n    UserManager.prototype.removeUser = function removeUser() {\n        var _this3 = this;\n\n        return this.storeUser(null).then(function () {\n            _Log.Log.info(\"UserManager.removeUser: user removed from storage\");\n            _this3._events.unload();\n        });\n    };\n\n    UserManager.prototype.signinRedirect = function signinRedirect() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:r\";\n        var navParams = {\n            useReplaceToNavigate: args.useReplaceToNavigate\n        };\n        return this._signinStart(args, this._redirectNavigator, navParams).then(function () {\n            _Log.Log.info(\"UserManager.signinRedirect: successful\");\n        });\n    };\n\n    UserManager.prototype.signinRedirectCallback = function signinRedirectCallback(url) {\n        return this._signinEnd(url || this._redirectNavigator.url).then(function (user) {\n            if (user.profile && user.profile.sub) {\n                _Log.Log.info(\"UserManager.signinRedirectCallback: successful, signed in sub: \", user.profile.sub);\n            } else {\n                _Log.Log.info(\"UserManager.signinRedirectCallback: no sub\");\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinPopup = function signinPopup() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:p\";\n        var url = args.redirect_uri || this.settings.popup_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.signinPopup: No popup_redirect_uri or redirect_uri configured\");\n            return Promise.reject(new Error(\"No popup_redirect_uri or redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.display = \"popup\";\n\n        return this._signin(args, this._popupNavigator, {\n            startUrl: url,\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\n        }).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinPopup: signinPopup successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinPopup: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinPopupCallback = function signinPopupCallback(url) {\n        return this._signinCallback(url, this._popupNavigator).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinPopupCallback: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinPopupCallback: no sub\");\n                }\n            }\n\n            return user;\n        }).catch(function (err) {\n            _Log.Log.error( true && err.message);\n        });\n    };\n\n    UserManager.prototype.signinSilent = function signinSilent() {\n        var _this4 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:s\";\n        // first determine if we have a refresh token, or need to use iframe\n        return this._loadUser().then(function (user) {\n            if (user && user.refresh_token) {\n                args.refresh_token = user.refresh_token;\n                return _this4._useRefreshToken(args);\n            } else {\n                args.id_token_hint = args.id_token_hint || _this4.settings.includeIdTokenInSilentRenew && user && user.id_token;\n                if (user && _this4._settings.validateSubOnSilentRenew) {\n                    _Log.Log.debug(\"UserManager.signinSilent, subject prior to silent renew: \", user.profile.sub);\n                    args.current_sub = user.profile.sub;\n                }\n                return _this4._signinSilentIframe(args);\n            }\n        });\n    };\n\n    UserManager.prototype._useRefreshToken = function _useRefreshToken() {\n        var _this5 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        return this._tokenClient.exchangeRefreshToken(args).then(function (result) {\n            if (!result) {\n                _Log.Log.error(\"UserManager._useRefreshToken: No response returned from token endpoint\");\n                return Promise.reject(\"No response returned from token endpoint\");\n            }\n            if (!result.access_token) {\n                _Log.Log.error(\"UserManager._useRefreshToken: No access token returned from token endpoint\");\n                return Promise.reject(\"No access token returned from token endpoint\");\n            }\n\n            return _this5._loadUser().then(function (user) {\n                if (user) {\n                    var idTokenValidation = Promise.resolve();\n                    if (result.id_token) {\n                        idTokenValidation = _this5._validateIdTokenFromTokenRefreshToken(user.profile, result.id_token);\n                    }\n\n                    return idTokenValidation.then(function () {\n                        _Log.Log.debug(\"UserManager._useRefreshToken: refresh token response success\");\n                        user.id_token = result.id_token;\n                        user.access_token = result.access_token;\n                        user.refresh_token = result.refresh_token || user.refresh_token;\n                        user.expires_in = result.expires_in;\n\n                        return _this5.storeUser(user).then(function () {\n                            _this5._events.load(user);\n                            return user;\n                        });\n                    });\n                } else {\n                    return null;\n                }\n            });\n        });\n    };\n\n    UserManager.prototype._validateIdTokenFromTokenRefreshToken = function _validateIdTokenFromTokenRefreshToken(profile, id_token) {\n        var _this6 = this;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n            return _this6._joseUtil.validateJwtAttributes(id_token, issuer, _this6._settings.client_id, _this6._settings.clockSkew).then(function (payload) {\n                if (!payload) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: Failed to validate id_token\");\n                    return Promise.reject(new Error(\"Failed to validate id_token\"));\n                }\n                if (payload.sub !== profile.sub) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: sub in id_token does not match current sub\");\n                    return Promise.reject(new Error(\"sub in id_token does not match current sub\"));\n                }\n                if (payload.auth_time && payload.auth_time !== profile.auth_time) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: auth_time in id_token does not match original auth_time\");\n                    return Promise.reject(new Error(\"auth_time in id_token does not match original auth_time\"));\n                }\n                if (payload.azp && payload.azp !== profile.azp) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp in id_token does not match original azp\");\n                    return Promise.reject(new Error(\"azp in id_token does not match original azp\"));\n                }\n                if (!payload.azp && profile.azp) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp not in id_token, but present in original id_token\");\n                    return Promise.reject(new Error(\"azp not in id_token, but present in original id_token\"));\n                }\n            });\n        });\n    };\n\n    UserManager.prototype._signinSilentIframe = function _signinSilentIframe() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        var url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.signinSilent: No silent_redirect_uri configured\");\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.prompt = args.prompt || \"none\";\n\n        return this._signin(args, this._iframeNavigator, {\n            startUrl: url,\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\n        }).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinSilent: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinSilent: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinSilentCallback = function signinSilentCallback(url) {\n        return this._signinCallback(url, this._iframeNavigator).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinSilentCallback: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinSilentCallback: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinCallback = function signinCallback(url) {\n        var _this7 = this;\n\n        return this.readSigninResponseState(url).then(function (_ref) {\n            var state = _ref.state,\n                response = _ref.response;\n\n            if (state.request_type === \"si:r\") {\n                return _this7.signinRedirectCallback(url);\n            }\n            if (state.request_type === \"si:p\") {\n                return _this7.signinPopupCallback(url);\n            }\n            if (state.request_type === \"si:s\") {\n                return _this7.signinSilentCallback(url);\n            }\n            return Promise.reject(new Error(\"invalid response_type in state\"));\n        });\n    };\n\n    UserManager.prototype.signoutCallback = function signoutCallback(url, keepOpen) {\n        var _this8 = this;\n\n        return this.readSignoutResponseState(url).then(function (_ref2) {\n            var state = _ref2.state,\n                response = _ref2.response;\n\n            if (state) {\n                if (state.request_type === \"so:r\") {\n                    return _this8.signoutRedirectCallback(url);\n                }\n                if (state.request_type === \"so:p\") {\n                    return _this8.signoutPopupCallback(url, keepOpen);\n                }\n                return Promise.reject(new Error(\"invalid response_type in state\"));\n            }\n            return response;\n        });\n    };\n\n    UserManager.prototype.querySessionStatus = function querySessionStatus() {\n        var _this9 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:s\"; // this acts like a signin silent\n        var url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.querySessionStatus: No silent_redirect_uri configured\");\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.prompt = \"none\";\n        args.response_type = args.response_type || this.settings.query_status_response_type;\n        args.scope = args.scope || \"openid\";\n        args.skipUserInfo = true;\n\n        return this._signinStart(args, this._iframeNavigator, {\n            startUrl: url,\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\n        }).then(function (navResponse) {\n            return _this9.processSigninResponse(navResponse.url).then(function (signinResponse) {\n                _Log.Log.debug(\"UserManager.querySessionStatus: got signin response\");\n\n                if (signinResponse.session_state && signinResponse.profile.sub) {\n                    _Log.Log.info(\"UserManager.querySessionStatus: querySessionStatus success for sub: \", signinResponse.profile.sub);\n                    return {\n                        session_state: signinResponse.session_state,\n                        sub: signinResponse.profile.sub,\n                        sid: signinResponse.profile.sid\n                    };\n                } else {\n                    _Log.Log.info(\"querySessionStatus successful, user not authenticated\");\n                }\n            }).catch(function (err) {\n                if (err.session_state && _this9.settings.monitorAnonymousSession) {\n                    if (err.message == \"login_required\" || err.message == \"consent_required\" || err.message == \"interaction_required\" || err.message == \"account_selection_required\") {\n                        _Log.Log.info(\"UserManager.querySessionStatus: querySessionStatus success for anonymous user\");\n                        return {\n                            session_state: err.session_state\n                        };\n                    }\n                }\n\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signin = function _signin(args, navigator) {\n        var _this10 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return this._signinStart(args, navigator, navigatorParams).then(function (navResponse) {\n            return _this10._signinEnd(navResponse.url, args);\n        });\n    };\n\n    UserManager.prototype._signinStart = function _signinStart(args, navigator) {\n        var _this11 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n\n        return navigator.prepare(navigatorParams).then(function (handle) {\n            _Log.Log.debug(\"UserManager._signinStart: got navigator window handle\");\n\n            return _this11.createSigninRequest(args).then(function (signinRequest) {\n                _Log.Log.debug(\"UserManager._signinStart: got signin request\");\n\n                navigatorParams.url = signinRequest.url;\n                navigatorParams.id = signinRequest.state.id;\n\n                return handle.navigate(navigatorParams);\n            }).catch(function (err) {\n                if (handle.close) {\n                    _Log.Log.debug(\"UserManager._signinStart: Error after preparing navigator, closing navigator window\");\n                    handle.close();\n                }\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signinEnd = function _signinEnd(url) {\n        var _this12 = this;\n\n        var args = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {};\n\n        return this.processSigninResponse(url).then(function (signinResponse) {\n            _Log.Log.debug(\"UserManager._signinEnd: got signin response\");\n\n            var user = new _User.User(signinResponse);\n\n            if (args.current_sub) {\n                if (args.current_sub !== user.profile.sub) {\n                    _Log.Log.debug(\"UserManager._signinEnd: current user does not match user returned from signin. sub from signin: \", user.profile.sub);\n                    return Promise.reject(new Error(\"login_required\"));\n                } else {\n                    _Log.Log.debug(\"UserManager._signinEnd: current user matches user returned from signin\");\n                }\n            }\n\n            return _this12.storeUser(user).then(function () {\n                _Log.Log.debug(\"UserManager._signinEnd: user stored\");\n\n                _this12._events.load(user);\n\n                return user;\n            });\n        });\n    };\n\n    UserManager.prototype._signinCallback = function _signinCallback(url, navigator) {\n        _Log.Log.debug(\"UserManager._signinCallback\");\n        return navigator.callback(url);\n    };\n\n    UserManager.prototype.signoutRedirect = function signoutRedirect() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"so:r\";\n        var postLogoutRedirectUri = args.post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\n        if (postLogoutRedirectUri) {\n            args.post_logout_redirect_uri = postLogoutRedirectUri;\n        }\n        var navParams = {\n            useReplaceToNavigate: args.useReplaceToNavigate\n        };\n        return this._signoutStart(args, this._redirectNavigator, navParams).then(function () {\n            _Log.Log.info(\"UserManager.signoutRedirect: successful\");\n        });\n    };\n\n    UserManager.prototype.signoutRedirectCallback = function signoutRedirectCallback(url) {\n        return this._signoutEnd(url || this._redirectNavigator.url).then(function (response) {\n            _Log.Log.info(\"UserManager.signoutRedirectCallback: successful\");\n            return response;\n        });\n    };\n\n    UserManager.prototype.signoutPopup = function signoutPopup() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"so:p\";\n        var url = args.post_logout_redirect_uri || this.settings.popup_post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\n        args.post_logout_redirect_uri = url;\n        args.display = \"popup\";\n        if (args.post_logout_redirect_uri) {\n            // we're putting a dummy entry in here because we\n            // need a unique id from the state for notification\n            // to the parent window, which is necessary if we\n            // plan to return back to the client after signout\n            // and so we can close the popup after signout\n            args.state = args.state || {};\n        }\n\n        return this._signout(args, this._popupNavigator, {\n            startUrl: url,\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\n        }).then(function () {\n            _Log.Log.info(\"UserManager.signoutPopup: successful\");\n        });\n    };\n\n    UserManager.prototype.signoutPopupCallback = function signoutPopupCallback(url, keepOpen) {\n        if (typeof keepOpen === 'undefined' && typeof url === 'boolean') {\n            keepOpen = url;\n            url = null;\n        }\n\n        var delimiter = '?';\n        return this._popupNavigator.callback(url, keepOpen, delimiter).then(function () {\n            _Log.Log.info(\"UserManager.signoutPopupCallback: successful\");\n        });\n    };\n\n    UserManager.prototype._signout = function _signout(args, navigator) {\n        var _this13 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return this._signoutStart(args, navigator, navigatorParams).then(function (navResponse) {\n            return _this13._signoutEnd(navResponse.url);\n        });\n    };\n\n    UserManager.prototype._signoutStart = function _signoutStart() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        var _this14 = this;\n\n        var navigator = arguments[1];\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return navigator.prepare(navigatorParams).then(function (handle) {\n            _Log.Log.debug(\"UserManager._signoutStart: got navigator window handle\");\n\n            return _this14._loadUser().then(function (user) {\n                _Log.Log.debug(\"UserManager._signoutStart: loaded current user from storage\");\n\n                var revokePromise = _this14._settings.revokeAccessTokenOnSignout ? _this14._revokeInternal(user) : Promise.resolve();\n                return revokePromise.then(function () {\n\n                    var id_token = args.id_token_hint || user && user.id_token;\n                    if (id_token) {\n                        _Log.Log.debug(\"UserManager._signoutStart: Setting id_token into signout request\");\n                        args.id_token_hint = id_token;\n                    }\n\n                    return _this14.removeUser().then(function () {\n                        _Log.Log.debug(\"UserManager._signoutStart: user removed, creating signout request\");\n\n                        return _this14.createSignoutRequest(args).then(function (signoutRequest) {\n                            _Log.Log.debug(\"UserManager._signoutStart: got signout request\");\n\n                            navigatorParams.url = signoutRequest.url;\n                            if (signoutRequest.state) {\n                                navigatorParams.id = signoutRequest.state.id;\n                            }\n                            return handle.navigate(navigatorParams);\n                        });\n                    });\n                });\n            }).catch(function (err) {\n                if (handle.close) {\n                    _Log.Log.debug(\"UserManager._signoutStart: Error after preparing navigator, closing navigator window\");\n                    handle.close();\n                }\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signoutEnd = function _signoutEnd(url) {\n        return this.processSignoutResponse(url).then(function (signoutResponse) {\n            _Log.Log.debug(\"UserManager._signoutEnd: got signout response\");\n\n            return signoutResponse;\n        });\n    };\n\n    UserManager.prototype.revokeAccessToken = function revokeAccessToken() {\n        var _this15 = this;\n\n        return this._loadUser().then(function (user) {\n            return _this15._revokeInternal(user, true).then(function (success) {\n                if (success) {\n                    _Log.Log.debug(\"UserManager.revokeAccessToken: removing token properties from user and re-storing\");\n\n                    user.access_token = null;\n                    user.refresh_token = null;\n                    user.expires_at = null;\n                    user.token_type = null;\n\n                    return _this15.storeUser(user).then(function () {\n                        _Log.Log.debug(\"UserManager.revokeAccessToken: user stored\");\n                        _this15._events.load(user);\n                    });\n                }\n            });\n        }).then(function () {\n            _Log.Log.info(\"UserManager.revokeAccessToken: access token revoked successfully\");\n        });\n    };\n\n    UserManager.prototype._revokeInternal = function _revokeInternal(user, required) {\n        var _this16 = this;\n\n        if (user) {\n            var access_token = user.access_token;\n            var refresh_token = user.refresh_token;\n\n            return this._revokeAccessTokenInternal(access_token, required).then(function (atSuccess) {\n                return _this16._revokeRefreshTokenInternal(refresh_token, required).then(function (rtSuccess) {\n                    if (!atSuccess && !rtSuccess) {\n                        _Log.Log.debug(\"UserManager.revokeAccessToken: no need to revoke due to no token(s), or JWT format\");\n                    }\n\n                    return atSuccess || rtSuccess;\n                });\n            });\n        }\n\n        return Promise.resolve(false);\n    };\n\n    UserManager.prototype._revokeAccessTokenInternal = function _revokeAccessTokenInternal(access_token, required) {\n        // check for JWT vs. reference token\n        if (!access_token || access_token.indexOf('.') >= 0) {\n            return Promise.resolve(false);\n        }\n\n        return this._tokenRevocationClient.revoke(access_token, required).then(function () {\n            return true;\n        });\n    };\n\n    UserManager.prototype._revokeRefreshTokenInternal = function _revokeRefreshTokenInternal(refresh_token, required) {\n        if (!refresh_token) {\n            return Promise.resolve(false);\n        }\n\n        return this._tokenRevocationClient.revoke(refresh_token, required, \"refresh_token\").then(function () {\n            return true;\n        });\n    };\n\n    UserManager.prototype.startSilentRenew = function startSilentRenew() {\n        this._silentRenewService.start();\n    };\n\n    UserManager.prototype.stopSilentRenew = function stopSilentRenew() {\n        this._silentRenewService.stop();\n    };\n\n    UserManager.prototype._loadUser = function _loadUser() {\n        return this._userStore.get(this._userStoreKey).then(function (storageString) {\n            if (storageString) {\n                _Log.Log.debug(\"UserManager._loadUser: user storageString loaded\");\n                return _User.User.fromStorageString(storageString);\n            }\n\n            _Log.Log.debug(\"UserManager._loadUser: no user storageString\");\n            return null;\n        });\n    };\n\n    UserManager.prototype.storeUser = function storeUser(user) {\n        if (user) {\n            _Log.Log.debug(\"UserManager.storeUser: storing user\");\n\n            var storageString = user.toStorageString();\n            return this._userStore.set(this._userStoreKey, storageString);\n        } else {\n            _Log.Log.debug(\"storeUser.storeUser: removing user\");\n            return this._userStore.remove(this._userStoreKey);\n        }\n    };\n\n    _createClass(UserManager, [{\n        key: '_redirectNavigator',\n        get: function get() {\n            return this.settings.redirectNavigator;\n        }\n    }, {\n        key: '_popupNavigator',\n        get: function get() {\n            return this.settings.popupNavigator;\n        }\n    }, {\n        key: '_iframeNavigator',\n        get: function get() {\n            return this.settings.iframeNavigator;\n        }\n    }, {\n        key: '_userStore',\n        get: function get() {\n            return this.settings.userStore;\n        }\n    }, {\n        key: 'events',\n        get: function get() {\n            return this._events;\n        }\n    }, {\n        key: '_userStoreKey',\n        get: function get() {\n            return 'user:' + this.settings.authority + ':' + this.settings.client_id;\n        }\n    }]);\n\n    return UserManager;\n}(_OidcClient2.OidcClient);\n\n/***/ }),\n\n/***/ \"./src/UserManagerEvents.js\":\n/*!**********************************!*\\\n  !*** ./src/UserManagerEvents.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManagerEvents = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _AccessTokenEvents2 = __webpack_require__(/*! ./AccessTokenEvents.js */ \"./src/AccessTokenEvents.js\");\n\nvar _Event = __webpack_require__(/*! ./Event.js */ \"./src/Event.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserManagerEvents = exports.UserManagerEvents = function (_AccessTokenEvents) {\n    _inherits(UserManagerEvents, _AccessTokenEvents);\n\n    function UserManagerEvents(settings) {\n        _classCallCheck(this, UserManagerEvents);\n\n        var _this = _possibleConstructorReturn(this, _AccessTokenEvents.call(this, settings));\n\n        _this._userLoaded = new _Event.Event(\"User loaded\");\n        _this._userUnloaded = new _Event.Event(\"User unloaded\");\n        _this._silentRenewError = new _Event.Event(\"Silent renew error\");\n        _this._userSignedIn = new _Event.Event(\"User signed in\");\n        _this._userSignedOut = new _Event.Event(\"User signed out\");\n        _this._userSessionChanged = new _Event.Event(\"User session changed\");\n        return _this;\n    }\n\n    UserManagerEvents.prototype.load = function load(user) {\n        var raiseEvent = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : true;\n\n        _Log.Log.debug(\"UserManagerEvents.load\");\n        _AccessTokenEvents.prototype.load.call(this, user);\n        if (raiseEvent) {\n            this._userLoaded.raise(user);\n        }\n    };\n\n    UserManagerEvents.prototype.unload = function unload() {\n        _Log.Log.debug(\"UserManagerEvents.unload\");\n        _AccessTokenEvents.prototype.unload.call(this);\n        this._userUnloaded.raise();\n    };\n\n    UserManagerEvents.prototype.addUserLoaded = function addUserLoaded(cb) {\n        this._userLoaded.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserLoaded = function removeUserLoaded(cb) {\n        this._userLoaded.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype.addUserUnloaded = function addUserUnloaded(cb) {\n        this._userUnloaded.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserUnloaded = function removeUserUnloaded(cb) {\n        this._userUnloaded.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype.addSilentRenewError = function addSilentRenewError(cb) {\n        this._silentRenewError.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeSilentRenewError = function removeSilentRenewError(cb) {\n        this._silentRenewError.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseSilentRenewError = function _raiseSilentRenewError(e) {\n        _Log.Log.debug(\"UserManagerEvents._raiseSilentRenewError\", e.message);\n        this._silentRenewError.raise(e);\n    };\n\n    UserManagerEvents.prototype.addUserSignedIn = function addUserSignedIn(cb) {\n        this._userSignedIn.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSignedIn = function removeUserSignedIn(cb) {\n        this._userSignedIn.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSignedIn = function _raiseUserSignedIn() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSignedIn\");\n        this._userSignedIn.raise();\n    };\n\n    UserManagerEvents.prototype.addUserSignedOut = function addUserSignedOut(cb) {\n        this._userSignedOut.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSignedOut = function removeUserSignedOut(cb) {\n        this._userSignedOut.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSignedOut = function _raiseUserSignedOut() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSignedOut\");\n        this._userSignedOut.raise();\n    };\n\n    UserManagerEvents.prototype.addUserSessionChanged = function addUserSessionChanged(cb) {\n        this._userSessionChanged.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSessionChanged = function removeUserSessionChanged(cb) {\n        this._userSessionChanged.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSessionChanged = function _raiseUserSessionChanged() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSessionChanged\");\n        this._userSessionChanged.raise();\n    };\n\n    return UserManagerEvents;\n}(_AccessTokenEvents2.AccessTokenEvents);\n\n/***/ }),\n\n/***/ \"./src/UserManagerSettings.js\":\n/*!************************************!*\\\n  !*** ./src/UserManagerSettings.js ***!\n  \\************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManagerSettings = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClientSettings2 = __webpack_require__(/*! ./OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _RedirectNavigator = __webpack_require__(/*! ./RedirectNavigator.js */ \"./src/RedirectNavigator.js\");\n\nvar _PopupNavigator = __webpack_require__(/*! ./PopupNavigator.js */ \"./src/PopupNavigator.js\");\n\nvar _IFrameNavigator = __webpack_require__(/*! ./IFrameNavigator.js */ \"./src/IFrameNavigator.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nvar _SigninRequest = __webpack_require__(/*! ./SigninRequest.js */ \"./src/SigninRequest.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultAccessTokenExpiringNotificationTime = 60;\nvar DefaultCheckSessionInterval = 2000;\n\nvar UserManagerSettings = exports.UserManagerSettings = function (_OidcClientSettings) {\n    _inherits(UserManagerSettings, _OidcClientSettings);\n\n    function UserManagerSettings() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            popup_redirect_uri = _ref.popup_redirect_uri,\n            popup_post_logout_redirect_uri = _ref.popup_post_logout_redirect_uri,\n            popupWindowFeatures = _ref.popupWindowFeatures,\n            popupWindowTarget = _ref.popupWindowTarget,\n            silent_redirect_uri = _ref.silent_redirect_uri,\n            silentRequestTimeout = _ref.silentRequestTimeout,\n            _ref$automaticSilentR = _ref.automaticSilentRenew,\n            automaticSilentRenew = _ref$automaticSilentR === undefined ? false : _ref$automaticSilentR,\n            _ref$validateSubOnSil = _ref.validateSubOnSilentRenew,\n            validateSubOnSilentRenew = _ref$validateSubOnSil === undefined ? false : _ref$validateSubOnSil,\n            _ref$includeIdTokenIn = _ref.includeIdTokenInSilentRenew,\n            includeIdTokenInSilentRenew = _ref$includeIdTokenIn === undefined ? true : _ref$includeIdTokenIn,\n            _ref$monitorSession = _ref.monitorSession,\n            monitorSession = _ref$monitorSession === undefined ? true : _ref$monitorSession,\n            _ref$monitorAnonymous = _ref.monitorAnonymousSession,\n            monitorAnonymousSession = _ref$monitorAnonymous === undefined ? false : _ref$monitorAnonymous,\n            _ref$checkSessionInte = _ref.checkSessionInterval,\n            checkSessionInterval = _ref$checkSessionInte === undefined ? DefaultCheckSessionInterval : _ref$checkSessionInte,\n            _ref$stopCheckSession = _ref.stopCheckSessionOnError,\n            stopCheckSessionOnError = _ref$stopCheckSession === undefined ? true : _ref$stopCheckSession,\n            query_status_response_type = _ref.query_status_response_type,\n            _ref$revokeAccessToke = _ref.revokeAccessTokenOnSignout,\n            revokeAccessTokenOnSignout = _ref$revokeAccessToke === undefined ? false : _ref$revokeAccessToke,\n            _ref$accessTokenExpir = _ref.accessTokenExpiringNotificationTime,\n            accessTokenExpiringNotificationTime = _ref$accessTokenExpir === undefined ? DefaultAccessTokenExpiringNotificationTime : _ref$accessTokenExpir,\n            _ref$redirectNavigato = _ref.redirectNavigator,\n            redirectNavigator = _ref$redirectNavigato === undefined ? new _RedirectNavigator.RedirectNavigator() : _ref$redirectNavigato,\n            _ref$popupNavigator = _ref.popupNavigator,\n            popupNavigator = _ref$popupNavigator === undefined ? new _PopupNavigator.PopupNavigator() : _ref$popupNavigator,\n            _ref$iframeNavigator = _ref.iframeNavigator,\n            iframeNavigator = _ref$iframeNavigator === undefined ? new _IFrameNavigator.IFrameNavigator() : _ref$iframeNavigator,\n            _ref$userStore = _ref.userStore,\n            userStore = _ref$userStore === undefined ? new _WebStorageStateStore.WebStorageStateStore({ store: _Global.Global.sessionStorage }) : _ref$userStore;\n\n        _classCallCheck(this, UserManagerSettings);\n\n        var _this = _possibleConstructorReturn(this, _OidcClientSettings.call(this, arguments[0]));\n\n        _this._popup_redirect_uri = popup_redirect_uri;\n        _this._popup_post_logout_redirect_uri = popup_post_logout_redirect_uri;\n        _this._popupWindowFeatures = popupWindowFeatures;\n        _this._popupWindowTarget = popupWindowTarget;\n\n        _this._silent_redirect_uri = silent_redirect_uri;\n        _this._silentRequestTimeout = silentRequestTimeout;\n        _this._automaticSilentRenew = automaticSilentRenew;\n        _this._validateSubOnSilentRenew = validateSubOnSilentRenew;\n        _this._includeIdTokenInSilentRenew = includeIdTokenInSilentRenew;\n        _this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\n\n        _this._monitorSession = monitorSession;\n        _this._monitorAnonymousSession = monitorAnonymousSession;\n        _this._checkSessionInterval = checkSessionInterval;\n        _this._stopCheckSessionOnError = stopCheckSessionOnError;\n        if (query_status_response_type) {\n            _this._query_status_response_type = query_status_response_type;\n        } else if (arguments[0] && arguments[0].response_type) {\n            _this._query_status_response_type = _SigninRequest.SigninRequest.isOidc(arguments[0].response_type) ? \"id_token\" : \"code\";\n        } else {\n            _this._query_status_response_type = \"id_token\";\n        }\n        _this._revokeAccessTokenOnSignout = revokeAccessTokenOnSignout;\n\n        _this._redirectNavigator = redirectNavigator;\n        _this._popupNavigator = popupNavigator;\n        _this._iframeNavigator = iframeNavigator;\n\n        _this._userStore = userStore;\n        return _this;\n    }\n\n    _createClass(UserManagerSettings, [{\n        key: 'popup_redirect_uri',\n        get: function get() {\n            return this._popup_redirect_uri;\n        }\n    }, {\n        key: 'popup_post_logout_redirect_uri',\n        get: function get() {\n            return this._popup_post_logout_redirect_uri;\n        }\n    }, {\n        key: 'popupWindowFeatures',\n        get: function get() {\n            return this._popupWindowFeatures;\n        }\n    }, {\n        key: 'popupWindowTarget',\n        get: function get() {\n            return this._popupWindowTarget;\n        }\n    }, {\n        key: 'silent_redirect_uri',\n        get: function get() {\n            return this._silent_redirect_uri;\n        }\n    }, {\n        key: 'silentRequestTimeout',\n        get: function get() {\n            return this._silentRequestTimeout;\n        }\n    }, {\n        key: 'automaticSilentRenew',\n        get: function get() {\n            return this._automaticSilentRenew;\n        }\n    }, {\n        key: 'validateSubOnSilentRenew',\n        get: function get() {\n            return this._validateSubOnSilentRenew;\n        }\n    }, {\n        key: 'includeIdTokenInSilentRenew',\n        get: function get() {\n            return this._includeIdTokenInSilentRenew;\n        }\n    }, {\n        key: 'accessTokenExpiringNotificationTime',\n        get: function get() {\n            return this._accessTokenExpiringNotificationTime;\n        }\n    }, {\n        key: 'monitorSession',\n        get: function get() {\n            return this._monitorSession;\n        }\n    }, {\n        key: 'monitorAnonymousSession',\n        get: function get() {\n            return this._monitorAnonymousSession;\n        }\n    }, {\n        key: 'checkSessionInterval',\n        get: function get() {\n            return this._checkSessionInterval;\n        }\n    }, {\n        key: 'stopCheckSessionOnError',\n        get: function get() {\n            return this._stopCheckSessionOnError;\n        }\n    }, {\n        key: 'query_status_response_type',\n        get: function get() {\n            return this._query_status_response_type;\n        }\n    }, {\n        key: 'revokeAccessTokenOnSignout',\n        get: function get() {\n            return this._revokeAccessTokenOnSignout;\n        }\n    }, {\n        key: 'redirectNavigator',\n        get: function get() {\n            return this._redirectNavigator;\n        }\n    }, {\n        key: 'popupNavigator',\n        get: function get() {\n            return this._popupNavigator;\n        }\n    }, {\n        key: 'iframeNavigator',\n        get: function get() {\n            return this._iframeNavigator;\n        }\n    }, {\n        key: 'userStore',\n        get: function get() {\n            return this._userStore;\n        }\n    }]);\n\n    return UserManagerSettings;\n}(_OidcClientSettings2.OidcClientSettings);\n\n/***/ }),\n\n/***/ \"./src/WebStorageStateStore.js\":\n/*!*************************************!*\\\n  !*** ./src/WebStorageStateStore.js ***!\n  \\*************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.WebStorageStateStore = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar WebStorageStateStore = exports.WebStorageStateStore = function () {\n    function WebStorageStateStore() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            _ref$prefix = _ref.prefix,\n            prefix = _ref$prefix === undefined ? \"oidc.\" : _ref$prefix,\n            _ref$store = _ref.store,\n            store = _ref$store === undefined ? _Global.Global.localStorage : _ref$store;\n\n        _classCallCheck(this, WebStorageStateStore);\n\n        this._store = store;\n        this._prefix = prefix;\n    }\n\n    WebStorageStateStore.prototype.set = function set(key, value) {\n        _Log.Log.debug(\"WebStorageStateStore.set\", key);\n\n        key = this._prefix + key;\n\n        this._store.setItem(key, value);\n\n        return Promise.resolve();\n    };\n\n    WebStorageStateStore.prototype.get = function get(key) {\n        _Log.Log.debug(\"WebStorageStateStore.get\", key);\n\n        key = this._prefix + key;\n\n        var item = this._store.getItem(key);\n\n        return Promise.resolve(item);\n    };\n\n    WebStorageStateStore.prototype.remove = function remove(key) {\n        _Log.Log.debug(\"WebStorageStateStore.remove\", key);\n\n        key = this._prefix + key;\n\n        var item = this._store.getItem(key);\n        this._store.removeItem(key);\n\n        return Promise.resolve(item);\n    };\n\n    WebStorageStateStore.prototype.getAllKeys = function getAllKeys() {\n        _Log.Log.debug(\"WebStorageStateStore.getAllKeys\");\n\n        var keys = [];\n\n        for (var index = 0; index < this._store.length; index++) {\n            var key = this._store.key(index);\n\n            if (key.indexOf(this._prefix) === 0) {\n                keys.push(key.substr(this._prefix.length));\n            }\n        }\n\n        return Promise.resolve(keys);\n    };\n\n    return WebStorageStateStore;\n}();\n\n/***/ }),\n\n/***/ \"./src/crypto/jsrsasign.js\":\n/*!*********************************!*\\\n  !*** ./src/crypto/jsrsasign.js ***!\n  \\*********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.AllowedSigningAlgs = exports.b64tohex = exports.hextob64u = exports.crypto = exports.X509 = exports.KeyUtil = exports.jws = undefined;\n\nvar _jsrsasign = __webpack_require__(/*! ../../jsrsasign/dist/jsrsasign.js */ \"./jsrsasign/dist/jsrsasign.js\");\n\nvar AllowedSigningAlgs = ['RS256', 'RS384', 'RS512', 'PS256', 'PS384', 'PS512', 'ES256', 'ES384', 'ES512'];\n\nexports.jws = _jsrsasign.jws;\nexports.KeyUtil = _jsrsasign.KEYUTIL;\nexports.X509 = _jsrsasign.X509;\nexports.crypto = _jsrsasign.crypto;\nexports.hextob64u = _jsrsasign.hextob64u;\nexports.b64tohex = _jsrsasign.b64tohex;\nexports.AllowedSigningAlgs = AllowedSigningAlgs;\n\n/***/ }),\n\n/***/ \"./src/random.js\":\n/*!***********************!*\\\n  !*** ./src/random.js ***!\n  \\***********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nexports.default = random;\n\nvar _v = __webpack_require__(/*! uuid/v4 */ \"./node_modules/uuid/v4.js\");\n\nvar _v2 = _interopRequireDefault(_v);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\n/**\n * Generates RFC4122 version 4 guid ()\n */\n\nfunction random() {\n  return (0, _v2.default)().replace(/-/g, '');\n}\nmodule.exports = exports['default'];\n\n/***/ }),\n\n/***/ \"./version.js\":\n/*!********************!*\\\n  !*** ./version.js ***!\n  \\********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nvar Version = \"1.10.1\";exports.Version = Version;\n\n/***/ }),\n\n/***/ 0:\n/*!***************************************!*\\\n  !*** multi ./polyfills.js ./index.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./polyfills.js */\"./polyfills.js\");\nmodule.exports = __webpack_require__(/*! ./index.js */\"./index.js\");\n\n\n/***/ })\n\n/******/ });\n//# sourceMappingURL=data:application/json;charset=utf-8;base64,{"version":3,"sources":["webpack://Oidc/webpack/bootstrap","webpack://Oidc/./index.js","webpack://Oidc/./jsrsasign/dist/jsrsasign.js","webpack://Oidc/./node_modules/base64-js/index.js","webpack://Oidc/./node_modules/buffer/index.js","webpack://Oidc/./node_modules/buffer/node_modules/isarray/index.js","webpack://Oidc/./node_modules/core-js/es6/promise.js","webpack://Oidc/./node_modules/core-js/fn/array/find.js","webpack://Oidc/./node_modules/core-js/fn/array/is-array.js","webpack://Oidc/./node_modules/core-js/fn/array/some.js","webpack://Oidc/./node_modules/core-js/fn/array/splice.js","webpack://Oidc/./node_modules/core-js/fn/function/bind.js","webpack://Oidc/./node_modules/core-js/fn/object/assign.js","webpack://Oidc/./node_modules/core-js/modules/_a-function.js","webpack://Oidc/./node_modules/core-js/modules/_add-to-unscopables.js","webpack://Oidc/./node_modules/core-js/modules/_an-instance.js","webpack://Oidc/./node_modules/core-js/modules/_an-object.js","webpack://Oidc/./node_modules/core-js/modules/_array-includes.js","webpack://Oidc/./node_modules/core-js/modules/_array-methods.js","webpack://Oidc/./node_modules/core-js/modules/_array-species-constructor.js","webpack://Oidc/./node_modules/core-js/modules/_array-species-create.js","webpack://Oidc/./node_modules/core-js/modules/_bind.js","webpack://Oidc/./node_modules/core-js/modules/_classof.js","webpack://Oidc/./node_modules/core-js/modules/_cof.js","webpack://Oidc/./node_modules/core-js/modules/_core.js","webpack://Oidc/./node_modules/core-js/modules/_ctx.js","webpack://Oidc/./node_modules/core-js/modules/_defined.js","webpack://Oidc/./node_modules/core-js/modules/_descriptors.js","webpack://Oidc/./node_modules/core-js/modules/_dom-create.js","webpack://Oidc/./node_modules/core-js/modules/_enum-bug-keys.js","webpack://Oidc/./node_modules/core-js/modules/_export.js","webpack://Oidc/./node_modules/core-js/modules/_fails.js","webpack://Oidc/./node_modules/core-js/modules/_for-of.js","webpack://Oidc/./node_modules/core-js/modules/_function-to-string.js","webpack://Oidc/./node_modules/core-js/modules/_global.js","webpack://Oidc/./node_modules/core-js/modules/_has.js","webpack://Oidc/./node_modules/core-js/modules/_hide.js","webpack://Oidc/./node_modules/core-js/modules/_html.js","webpack://Oidc/./node_modules/core-js/modules/_ie8-dom-define.js","webpack://Oidc/./node_modules/core-js/modules/_invoke.js","webpack://Oidc/./node_modules/core-js/modules/_iobject.js","webpack://Oidc/./node_modules/core-js/modules/_is-array-iter.js","webpack://Oidc/./node_modules/core-js/modules/_is-array.js","webpack://Oidc/./node_modules/core-js/modules/_is-object.js","webpack://Oidc/./node_modules/core-js/modules/_iter-call.js","webpack://Oidc/./node_modules/core-js/modules/_iter-create.js","webpack://Oidc/./node_modules/core-js/modules/_iter-define.js","webpack://Oidc/./node_modules/core-js/modules/_iter-detect.js","webpack://Oidc/./node_modules/core-js/modules/_iter-step.js","webpack://Oidc/./node_modules/core-js/modules/_iterators.js","webpack://Oidc/./node_modules/core-js/modules/_library.js","webpack://Oidc/./node_modules/core-js/modules/_microtask.js","webpack://Oidc/./node_modules/core-js/modules/_new-promise-capability.js","webpack://Oidc/./node_modules/core-js/modules/_object-assign.js","webpack://Oidc/./node_modules/core-js/modules/_object-create.js","webpack://Oidc/./node_modules/core-js/modules/_object-dp.js","webpack://Oidc/./node_modules/core-js/modules/_object-dps.js","webpack://Oidc/./node_modules/core-js/modules/_object-gops.js","webpack://Oidc/./node_modules/core-js/modules/_object-gpo.js","webpack://Oidc/./node_modules/core-js/modules/_object-keys-internal.js","webpack://Oidc/./node_modules/core-js/modules/_object-keys.js","webpack://Oidc/./node_modules/core-js/modules/_object-pie.js","webpack://Oidc/./node_modules/core-js/modules/_perform.js","webpack://Oidc/./node_modules/core-js/modules/_promise-resolve.js","webpack://Oidc/./node_modules/core-js/modules/_property-desc.js","webpack://Oidc/./node_modules/core-js/modules/_redefine-all.js","webpack://Oidc/./node_modules/core-js/modules/_redefine.js","webpack://Oidc/./node_modules/core-js/modules/_set-species.js","webpack://Oidc/./node_modules/core-js/modules/_set-to-string-tag.js","webpack://Oidc/./node_modules/core-js/modules/_shared-key.js","webpack://Oidc/./node_modules/core-js/modules/_shared.js","webpack://Oidc/./node_modules/core-js/modules/_species-constructor.js","webpack://Oidc/./node_modules/core-js/modules/_strict-method.js","webpack://Oidc/./node_modules/core-js/modules/_string-at.js","webpack://Oidc/./node_modules/core-js/modules/_task.js","webpack://Oidc/./node_modules/core-js/modules/_to-absolute-index.js","webpack://Oidc/./node_modules/core-js/modules/_to-integer.js","webpack://Oidc/./node_modules/core-js/modules/_to-iobject.js","webpack://Oidc/./node_modules/core-js/modules/_to-length.js","webpack://Oidc/./node_modules/core-js/modules/_to-object.js","webpack://Oidc/./node_modules/core-js/modules/_to-primitive.js","webpack://Oidc/./node_modules/core-js/modules/_uid.js","webpack://Oidc/./node_modules/core-js/modules/_user-agent.js","webpack://Oidc/./node_modules/core-js/modules/_wks.js","webpack://Oidc/./node_modules/core-js/modules/core.get-iterator-method.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.find.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.is-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.iterator.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.some.js","webpack://Oidc/./node_modules/core-js/modules/es6.function.bind.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.assign.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.to-string.js","webpack://Oidc/./node_modules/core-js/modules/es6.promise.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.iterator.js","webpack://Oidc/./node_modules/core-js/modules/web.dom.iterable.js","webpack://Oidc/./node_modules/ieee754/index.js","webpack://Oidc/./node_modules/uuid/lib/bytesToUuid.js","webpack://Oidc/./node_modules/uuid/lib/rng-browser.js","webpack://Oidc/./node_modules/uuid/v4.js","webpack://Oidc/(webpack)/buildin/global.js","webpack://Oidc/./polyfills.js","webpack://Oidc/./src/AccessTokenEvents.js","webpack://Oidc/./src/CheckSessionIFrame.js","webpack://Oidc/./src/CordovaIFrameNavigator.js","webpack://Oidc/./src/CordovaPopupNavigator.js","webpack://Oidc/./src/CordovaPopupWindow.js","webpack://Oidc/./src/ErrorResponse.js","webpack://Oidc/./src/Event.js","webpack://Oidc/./src/Global.js","webpack://Oidc/./src/IFrameNavigator.js","webpack://Oidc/./src/IFrameWindow.js","webpack://Oidc/./src/InMemoryWebStorage.js","webpack://Oidc/./src/JoseUtil.js","webpack://Oidc/./src/JoseUtilImpl.js","webpack://Oidc/./src/JsonService.js","webpack://Oidc/./src/Log.js","webpack://Oidc/./src/MetadataService.js","webpack://Oidc/./src/OidcClient.js","webpack://Oidc/./src/OidcClientSettings.js","webpack://Oidc/./src/PopupNavigator.js","webpack://Oidc/./src/PopupWindow.js","webpack://Oidc/./src/RedirectNavigator.js","webpack://Oidc/./src/ResponseValidator.js","webpack://Oidc/./src/SessionMonitor.js","webpack://Oidc/./src/SigninRequest.js","webpack://Oidc/./src/SigninResponse.js","webpack://Oidc/./src/SigninState.js","webpack://Oidc/./src/SignoutRequest.js","webpack://Oidc/./src/SignoutResponse.js","webpack://Oidc/./src/SilentRenewService.js","webpack://Oidc/./src/State.js","webpack://Oidc/./src/Timer.js","webpack://Oidc/./src/TokenClient.js","webpack://Oidc/./src/TokenRevocationClient.js","webpack://Oidc/./src/UrlUtility.js","webpack://Oidc/./src/User.js","webpack://Oidc/./src/UserInfoService.js","webpack://Oidc/./src/UserManager.js","webpack://Oidc/./src/UserManagerEvents.js","webpack://Oidc/./src/UserManagerSettings.js","webpack://Oidc/./src/WebStorageStateStore.js","webpack://Oidc/./src/crypto/jsrsasign.js","webpack://Oidc/./src/random.js","webpack://Oidc/./version.js"],"names":["Version","Log","OidcClient","OidcClientSettings","WebStorageStateStore","InMemoryWebStorage","UserManager","AccessTokenEvents","MetadataService","CordovaPopupNavigator","CordovaIFrameNavigator","CheckSessionIFrame","TokenRevocationClient","SessionMonitor","Global","User","navigator","userAgent","window","YAHOO","undefined","lang","extend","g","h","f","Error","d","prototype","constructor","superclass","Object","b","e","c","test","j","i","length","l","k","a","CryptoJS","lib","Base","n","p","o","mixIn","hasOwnProperty","init","$super","apply","arguments","create","toString","clone","WordArray","words","sigBytes","stringify","concat","t","q","s","clamp","r","ceil","call","slice","random","push","m","enc","Hex","join","parse","parseInt","substr","Latin1","String","fromCharCode","charCodeAt","Utf8","decodeURIComponent","escape","unescape","encodeURIComponent","BufferedBlockAlgorithm","reset","_data","_nDataBytes","_append","_process","w","x","blockSize","v","u","max","_minBufferSize","min","_doProcessBlock","splice","Hasher","cfg","_doReset","update","finalize","_doFinalize","_createHelper","_createHmacHelper","HMAC","algo","Math","x64","Word","high","low","toX32","Base64","_map","charAt","indexOf","sqrt","pow","SHA256","_hash","floor","HmacSHA256","T","ea","SHA512","F","G","H","I","J","X","K","Y","L","Z","M","$","N","aa","O","ba","P","ca","Q","z","A","y","U","B","R","C","S","D","V","E","W","fa","da","HmacSHA512","SHA384","HmacSHA384","b64map","b64pad","hex2b64","substring","b64tohex","int2char","b64toBA","Array","dbits","canary","j_lm","BigInteger","fromNumber","fromString","nbi","am1","am2","am3","appName","am","DB","DM","DV","BI_FP","FV","F1","F2","BI_RM","BI_RC","rr","vv","intAt","bnpCopyTo","bnpFromInt","nbv","fromInt","bnpFromString","fromRadix","ZERO","subTo","bnpClamp","bnToString","negate","toRadix","bnNegate","bnAbs","bnCompareTo","nbits","bnBitLength","bnpDLShiftTo","bnpDRShiftTo","bnpLShiftTo","bnpRShiftTo","bnpSubTo","bnpMultiplyTo","abs","bnpSquareTo","bnpDivRemTo","copyTo","lShiftTo","dlShiftTo","compareTo","ONE","drShiftTo","rShiftTo","bnMod","divRemTo","Classic","cConvert","mod","cRevert","cReduce","cMulTo","multiplyTo","reduce","cSqrTo","squareTo","convert","revert","mulTo","sqrTo","bnpInvDigit","Montgomery","mp","invDigit","mpl","mph","um","mt2","montConvert","montRevert","montReduce","montSqrTo","montMulTo","bnpIsEven","bnpExp","bnModPowInt","isEven","exp","bitLength","modPowInt","bnClone","bnIntValue","bnByteValue","bnShortValue","bnpChunkSize","LN2","log","bnSigNum","bnpToRadix","signum","chunkSize","intValue","bnpFromRadix","dMultiply","dAddOffset","bnpFromNumber","testBit","bitwiseTo","shiftLeft","op_or","isProbablePrime","nextBytes","bnToByteArray","bnEquals","bnMin","bnMax","bnpBitwiseTo","op_and","bnAnd","bnOr","op_xor","bnXor","op_andnot","bnAndNot","bnNot","bnShiftLeft","bnShiftRight","lbit","bnGetLowestSetBit","cbit","bnBitCount","bnTestBit","bnpChangeBit","bnSetBit","changeBit","bnClearBit","bnFlipBit","bnpAddTo","bnAdd","addTo","bnSubtract","bnMultiply","bnSquare","bnDivide","bnRemainder","bnDivideAndRemainder","bnpDMultiply","bnpDAddOffset","NullExp","nNop","nMulTo","nSqrTo","bnPow","bnpMultiplyLowerTo","bnpMultiplyUpperTo","Barrett","r2","q3","mu","divide","barrettConvert","barrettRevert","barrettReduce","multiplyUpperTo","multiplyLowerTo","barrettSqrTo","barrettMulTo","bnModPow","bnGCD","getLowestSetBit","bnpModInt","bnModInverse","subtract","add","lowprimes","lplim","bnIsProbablePrime","modInt","millerRabin","bnpMillerRabin","shiftRight","modPow","byteValue","shortValue","toByteArray","equals","and","or","xor","andNot","not","bitCount","setBit","clearBit","flipBit","multiply","remainder","divideAndRemainder","modInverse","gcd","square","Arcfour","ARC4init","ARC4next","next","prng_newstate","rng_psize","rng_state","rng_pool","rng_pptr","rng_seed_int","rng_seed_time","Date","getTime","crypto","msCrypto","getRandomValues","ua","Uint8Array","appVersion","rng_get_byte","rng_get_bytes","SecureRandom","parseBigInt","linebrk","byte2Hex","pkcs1pad2","oaep_mgf1_arr","oaep_pad","KJUR","MessageDigest","Util","getCanonicalAlgName","getHashLength","hextorstr","hashHex","rstrtohex","RSAKey","dmp1","dmq1","coeff","RSASetPublic","isPublic","isPrivate","RSADoPublic","RSAEncrypt","doPublic","RSAEncryptOAEP","setPublic","encrypt","encryptOAEP","type","ECFieldElementFp","feFpEquals","feFpToBigInteger","feFpNegate","feFpAdd","toBigInteger","feFpSubtract","feFpMultiply","feFpSquare","feFpDivide","ECPointFp","curve","zinv","pointFpGetX","fromBigInteger","pointFpGetY","pointFpEquals","isInfinity","pointFpIsInfinity","pointFpNegate","pointFpAdd","twice","getInfinity","pointFpTwice","pointFpMultiply","pointFpMultiplyTwo","getX","getY","multiplyTwo","ECCurveFp","infinity","curveFpGetQ","curveFpGetA","curveFpGetB","curveFpEquals","curveFpGetInfinity","curveFpFromBigInteger","curveFpDecodePointHex","getQ","getA","getB","decodePointHex","getByteLength","getEncoded","toByteArrayUnsigned","unshift","decodeFrom","decodeFromHex","add2D","twice2D","valueOf","multiply2D","isOnCurve","validate","jsonParse","RegExp","match","replace","shift","asn1","ASN1Util","integerToByteHex","bigIntToMinTwosComplementsHex","getPEMStringFromHex","hextopem","newObject","DERBoolean","DERInteger","DERBitString","DEROctetString","DERNull","DERObjectIdentifier","DEREnumerated","DERUTF8String","DERNumericString","DERPrintableString","DERTeletexString","DERIA5String","DERUTCTime","DERGeneralizedTime","DERSequence","DERSet","DERTaggedObject","keys","array","tag","explicit","obj","jsonToASN1HEX","getEncodedHex","oidHexToInt","oidIntToHex","split","ASN1Object","getLengthHexFromValue","hV","hTLV","isModified","getFreshValueHex","hL","hT","getValueHex","DERAbstractString","getString","setString","utf8tohex","toLowerCase","setStringHex","str","hex","DERAbstractTime","localDateToUTC","utc","getTimezoneOffset","formatDate","zeroPadding","getFullYear","getMonth","getDate","getHours","getMinutes","getSeconds","getMilliseconds","stohex","setByDateValue","UTC","setByDate","DERAbstractStructured","setByASN1ObjectArray","asn1Array","appendASN1Object","setByBigInteger","setByInteger","setValueHex","bigint","setHexValueIncludingUnusedBits","setUnusedBitsAndHexValue","setByBinaryString","setByBooleanArray","newFalseArray","bin","setValueOidString","setValueName","x509","OID","name2oid","oid","name","date","withMillis","millis","sortFlag","sort","sortflag","isExplicit","asn1Object","setASN1Object","ASN1HEX","getLblen","getL","getVblen","getVidx","getV","getTLV","getNextSiblingIdx","getChildIdx","getNthChildIdx","getIdxbyList","getTLVbyList","getVbyList","hextooidstr","dump","ommit_long_octet","isASN1HEX","oid2name","hextoutf8","oidname","JSON","x509ExtName","isHex","Base64x","stoBA","BAtos","BAtohex","stob64","stob64u","b64tob64u","b64utos","b64utob64","hextob64u","b64utohex","utf8tob64u","b64utoutf8","Buffer","uricmptohex","encodeURIComponentAll","hextouricmp","utf8tob64","b64toutf8","hextob64","hextob64nl","b64nltohex","pemtohex","hextoArrayBuffer","ArrayBuffer","DataView","setUint8","ArrayBuffertohex","byteLength","getUint8","zulutomsec","zulutosec","zulutodate","datetozulu","getUTCFullYear","getUTCMonth","getUTCDate","getUTCHours","getUTCMinutes","getUTCSeconds","getUTCMilliseconds","ipv6tohex","repeat","hextoipv6","hextoip","iptohex","newline_toUnix","newline_toDos","isInteger","isBase64","isBase64URL","isIntegerArray","hextoposhex","intarystrtohex","map","strdiffidx","DIGESTINFOHEAD","sha1","sha224","sha256","sha384","sha512","md2","md5","ripemd160","DEFAULTPROVIDER","hmacmd5","hmacsha1","hmacsha224","hmacsha256","hmacsha384","hmacsha512","hmacripemd160","MD5withRSA","SHA1withRSA","SHA224withRSA","SHA256withRSA","SHA384withRSA","SHA512withRSA","RIPEMD160withRSA","MD5withECDSA","SHA1withECDSA","SHA224withECDSA","SHA256withECDSA","SHA384withECDSA","SHA512withECDSA","RIPEMD160withECDSA","SHA1withDSA","SHA224withDSA","SHA256withDSA","MD5withRSAandMGF1","SHA1withRSAandMGF1","SHA224withRSAandMGF1","SHA256withRSAandMGF1","SHA384withRSAandMGF1","SHA512withRSAandMGF1","RIPEMD160withRSAandMGF1","CRYPTOJSMESSAGEDIGESTNAME","MD5","SHA1","SHA224","RIPEMD160","getDigestInfoHex","getPaddedDigestInfoHex","hashString","alg","digestString","digestHex","prov","sha256Hex","sha512Hex","SECURERANDOMGEN","getRandomHexOfNbytes","getRandomBigIntegerOfNbytes","getRandomHexOfNbits","getRandomBigIntegerOfNbits","getRandomBigIntegerZeroToMax","getRandomBigIntegerMinToMax","setAlgAndProvider","md","updateString","updateHex","digest","sjcl","hash","codec","toBits","fromBits","algName","provName","HASHLENGTH","Mac","algProv","mac","pass","doFinal","doFinalString","doFinalHex","setPassword","utf8","rstr","b64","b64u","Signature","_setAlgNames","mdAlgName","pubkeyAlgName","_zeroPaddingOfSignature","KEYUTIL","getKey","prvKey","state","pubKey","sign","sHashHex","ecprvhex","eccurvename","ECDSA","hSign","signHex","signWithMessageHashPSS","pssSaltLen","signWithMessageHash","DSA","signString","verify","ecpubhex","verifyHex","verifyWithMessageHashPSS","verifyWithMessageHash","algProvName","initParams","psssaltlen","prvkeypem","prvkeypas","Cipher","getAlgByKeyAndName","decrypt","decryptOAEP","oidhex2name","getBigRandom","setNamedCurve","ecparams","ECParameterDB","getByName","prvKeyHex","pubKeyHex","curveName","setPrivateKeyHex","setPublicKeyHex","getPublicKeyXYHex","keylen","getShortNISTPCurveName","generateKeyPairHex","biRSSigToASN1Sig","fromByteArrayUnsigned","serializeSig","parseSigHex","verifyRaw","Bitcoin","isArray","parseSig","toByteArraySigned","parseSigCompact","readPKCS5PrvKeyHex","getName","readPKCS8PrvKeyHex","readPKCS8PubKeyHex","readCertPubKeyHex","prv","pub","parseSigHexInHexRS","asn1SigToConcatSig","concatSigToASN1Sig","hexRSSigToASN1Sig","regist","AES","TripleDES","DES","key","iv","ciphertext","proc","eproc","ivlen","cipher","ivsalt","data","keyhex","ivhex","version","parsePKCS5PEM","getKeyAndUnusedIvByPasscodeAndIvsalt","decryptKeyB64","getDecryptedKeyHex","getEncryptedPKCS5PEMFromPrvKeyHex","toUpperCase","parseHexOfEncryptedPKCS8","encryptionSchemeAlg","encryptionSchemeIV","pbkdf2Salt","pbkdf2Iter","getPBKDF2KeyHexFromParam","PBKDF2","keySize","iterations","_getPlainPKCS8HexFromEncryptedPKCS8PEM","getKeyFromEncryptedPKCS8PEM","getKeyFromPlainPrivatePKCS8Hex","parsePlainPrivatePKCS8Hex","algparam","algoid","keyidx","getKeyFromPlainPrivatePKCS8PEM","_getKeyFromPublicPKCS8Hex","parsePublicRawRSAKeyHex","parsePublicPKCS8Hex","xy","kty","dp","dq","co","qi","setPrivateEx","setPrivate","crv","X509","getPublicKeyFromCertHex","getPublicKeyFromCertPEM","generateKeypair","generate","prvKeyObj","pubKeyObj","getPEM","SubjectPublicKeyInfo","seq","octstr","bitstr","getKeyFromCSRPEM","getKeyFromCSRHex","parseCSRHex","p8pubkeyhex","getJWKFromKey","getPosArrayOfChildrenFromHex","getHexValueArrayOfChildrenFromHex","readPrivateKeyFromPEMString","readPKCS5PubKeyHex","readCertHex","getPublicKeyHex","_RE_HEXDECONLY","compile","_rsasign_getHexPaddedDigestInfoForString","doPrivate","pss_mgf1_str","signPSS","_rsasign_getDecryptSignatureBI","_rsasign_getHexDigestInfoFromSig","_rsasign_getAlgNameAndHashFromHexDisgestInfo","verifyPSS","SALT_LEN_HLEN","SALT_LEN_MAX","SALT_LEN_RECOVER","foffset","aExtInfo","getVersion","getSerialNumberHex","getSignatureAlgorithmField","getIssuerHex","getIssuerString","hex2dn","getSubjectHex","getSubjectString","getNotBefore","getNotAfter","getPublicKeyIdx","getPublicKeyContentIdx","getPublicKey","getSignatureAlgorithmName","getSignatureValueHex","verifySignature","parseExt","critical","vidx","getExtInfo","getExtBasicConstraints","cA","pathLen","getExtKeyUsageBin","getExtKeyUsageString","KEYUSAGE_NAME","getExtSubjectKeyIdentifier","getExtAuthorityKeyIdentifier","kid","getExtExtKeyUsageName","getExtSubjectAltName","getExtSubjectAltName2","getExtCRLDistributionPointsURI","getExtAIAInfo","ocsp","caissuer","getExtCertificatePolicies","id","cps","unotice","readCertPEM","getInfo","hex2rdn","hex2attrTypeValue","oid2atype","getPublicKeyInfoPropOfCertPEM","jws","JWS","isSafeJSONString","parseJWS","parsedJWS","sigvalH","headB64U","payloadB64U","sigvalB64U","si","sigvalBI","headS","payloadS","readSafeJSONString","jwsalg2sigalg","hASN1Sig","headerObj","payloadObj","headerPP","payloadPP","sigHex","verifyJWT","inArray","includedArray","iss","sub","aud","IntDate","getNow","verifyAt","gracePeriod","nbf","iat","jti","HS256","HS384","HS512","RS256","RS384","RS512","ES256","ES384","PS256","PS384","PS512","none","getEncodedSignatureValueFromJWS","getJWKthumbprint","get","getZulu","intDate2UTCString","toUTCString","intDate2Zulu","EDSA","_crypto","DefaultAccessTokenExpiringNotificationTime","accessTokenExpiringNotificationTime","accessTokenExpiringTimer","Timer","accessTokenExpiredTimer","_accessTokenExpiringNotificationTime","_accessTokenExpiring","_accessTokenExpired","load","container","access_token","expires_in","duration","debug","expiring","cancel","expired","unload","addAccessTokenExpiring","cb","addHandler","removeAccessTokenExpiring","removeHandler","addAccessTokenExpired","removeAccessTokenExpired","DefaultInterval","callback","client_id","url","interval","stopOnError","_callback","_client_id","_url","_interval","_stopOnError","idx","_frame_origin","_frame","document","createElement","style","visibility","position","display","width","height","src","Promise","resolve","onload","body","appendChild","_boundMessageEvent","_message","bind","addEventListener","origin","source","contentWindow","error","stop","start","session_state","_session_state","send","postMessage","_timer","setInterval","clearInterval","prepare","params","popupWindowFeatures","popup","CordovaPopupWindow","DefaultPopupFeatures","DefaultPopupTarget","_promise","reject","_resolve","_reject","features","target","popupWindowTarget","redirect_uri","startUrl","_isInAppBrowserInstalled","cordovaMetadata","some","navigate","_error","cordova","require","metadata","_popup","InAppBrowser","open","_exitCallbackEvent","_exitCallback","_loadStartCallbackEvent","_loadStartCallback","promise","event","_success","message","_cleanup","close","removeEventListener","ErrorResponse","error_description","error_uri","Event","_name","_callbacks","findIndex","item","raise","timer","handle","testing","request","_testing","setXMLHttpRequest","newRequest","location","localStorage","sessionStorage","XMLHttpRequest","IFrameNavigator","frame","IFrameWindow","notifyParent","DefaultTimeout","timeout","silentRequestTimeout","setTimeout","_timeout","clearTimeout","removeChild","_origin","frameElement","href","parent","protocol","host","getItem","setItem","value","removeItem","index","getOwnPropertyNames","JoseUtil","KeyUtil","AllowedSigningAlgs","getJoseUtil","parseJwt","jwt","token","header","payload","validateJwt","issuer","audience","clockSkew","now","timeInsensitive","x5c","_validateJwt","validateJwtAttributes","validAudience","azp","lowerNow","upperNow","then","hexToBase64Url","JsonService","additionalContentTypes","XMLHttpRequestCtor","jwtHandler","_contentTypes","_XMLHttpRequest","_jwtHandler","getJson","req","allowedContentTypes","status","contentType","getResponseHeader","found","find","startsWith","responseText","statusText","onerror","setRequestHeader","postForm","nopLogger","info","warn","NONE","ERROR","WARN","INFO","DEBUG","logger","level","args","from","OidcMetadataUrlPath","settings","JsonServiceCtor","_settings","_jsonService","getMetadata","metadataUrl","getIssuer","_getMetadataProperty","getAuthorizationEndpoint","getUserInfoEndpoint","getTokenEndpoint","optional","getCheckSessionIframe","getEndSessionEndpoint","getRevocationEndpoint","getKeysEndpoint","getSigningKeys","signingKeys","jwks_uri","keySet","_metadataUrl","authority","createSigninRequest","response_type","scope","prompt","max_age","ui_locales","id_token_hint","login_hint","acr_values","resource","request_uri","response_mode","extraQueryParams","extraTokenParams","request_type","skipUserInfo","stateStore","SigninRequest","isCode","_metadataService","signinRequest","client_secret","signinState","_stateStore","set","toStorageString","readSigninResponseState","removeState","useQuery","delimiter","response","SigninResponse","stateApi","remove","storedStateString","SigninState","fromStorageString","processSigninResponse","_validator","validateSigninResponse","createSignoutRequest","post_logout_redirect_uri","SignoutRequest","signoutState","readSignoutResponseState","SignoutResponse","stateKey","State","processSignoutResponse","validateSignoutResponse","clearStaleState","staleStateAge","validator","metadataService","DefaultResponseType","DefaultScope","DefaultStaleStateAge","DefaultClockSkewInSeconds","filterProtocolClaims","loadUserInfo","userInfoJwtIssuer","ResponseValidatorCtor","ResponseValidator","MetadataServiceCtor","_authority","_metadata","_signingKeys","_client_secret","_response_type","_scope","_redirect_uri","_post_logout_redirect_uri","_prompt","_display","_max_age","_ui_locales","_acr_values","_resource","_response_mode","_filterProtocolClaims","_loadUserInfo","_staleStateAge","_clockSkew","_userInfoJwtIssuer","_extraQueryParams","_extraTokenParams","PopupNavigator","PopupWindow","keepOpen","notifyOpener","CheckForPopupClosedInterval","_checkForPopupClosedTimer","_checkForPopupClosed","_id","focus","closed","opener","UrlUtility","parseUrlFragment","RedirectNavigator","useReplaceToNavigate","ProtocolClaims","UserInfoServiceCtor","UserInfoService","joseUtil","TokenClientCtor","TokenClient","_userInfoService","_joseUtil","_tokenClient","_processSigninParams","_validateTokens","_processClaims","nonce","id_token","code_verifier","code","isOpenIdConnect","profile","getClaims","claims","_mergeClaims","claims1","claims2","result","assign","values","forEach","_processCode","_validateIdTokenAndAccessToken","_validateIdToken","exchangeCode","tokenResponse","_validateIdTokenAttributes","clockSkewInSeconds","_validateAccessToken","_filterByAlg","filter","at_hash","hashAlg","hashBits","sha","left","left_b64u","userManager","CheckSessionIFrameCtor","_userManager","_CheckSessionIFrameCtor","events","addUserLoaded","_start","addUserUnloaded","_stop","getUser","user","monitorAnonymousSession","querySessionStatus","tmpUser","session","sid","catch","err","_sub","_sid","_checkSessionIFrame","_checkSessionInterval","_stopCheckSessionOnError","timerHandle","raiseEvent","_raiseUserSessionChanged","_raiseUserSignedOut","_raiseUserSignedIn","checkSessionInterval","stopCheckSessionOnError","oidc","isOidc","addQueryParam","code_challenge","isOAuth","OidcScope","token_type","expires_at","scopes","_nonce","_code_verifier","_code_challenge","_skipUserInfo","created","storageString","SilentRenewService","_tokenExpiring","signinSilent","_raiseSilentRenewError","_created","_request_type","storage","age","cutoff","getAllKeys","promises","all","TimerDuration","nowFunc","_nowFunc","expiration","_timerHandle","_expiration","timerDuration","diff","grant_type","exchangeRefreshToken","refresh_token","AccessTokenTypeHint","RefreshTokenTypeHint","_XMLHttpRequestCtor","revoke","required","_revoke","xhr","global","lastIndexOf","regex","counter","exec","prop","_getClaimsFromJwt","issuerPromise","SilentRenewServiceCtor","SessionMonitorCtor","TokenRevocationClientCtor","UserManagerSettings","_events","UserManagerEvents","_silentRenewService","automaticSilentRenew","startSilentRenew","monitorSession","_sessionMonitor","_tokenRevocationClient","_loadUser","removeUser","storeUser","signinRedirect","navParams","_signinStart","_redirectNavigator","signinRedirectCallback","_signinEnd","signinPopup","popup_redirect_uri","_signin","_popupNavigator","signinPopupCallback","_signinCallback","_useRefreshToken","includeIdTokenInSilentRenew","validateSubOnSilentRenew","current_sub","_signinSilentIframe","idTokenValidation","_validateIdTokenFromTokenRefreshToken","auth_time","silent_redirect_uri","_iframeNavigator","signinSilentCallback","signinCallback","signoutCallback","signoutRedirectCallback","signoutPopupCallback","query_status_response_type","navResponse","signinResponse","navigatorParams","signoutRedirect","postLogoutRedirectUri","_signoutStart","_signoutEnd","signoutPopup","popup_post_logout_redirect_uri","_signout","revokePromise","revokeAccessTokenOnSignout","_revokeInternal","signoutRequest","signoutResponse","revokeAccessToken","success","_revokeAccessTokenInternal","_revokeRefreshTokenInternal","atSuccess","rtSuccess","stopSilentRenew","_userStore","_userStoreKey","redirectNavigator","popupNavigator","iframeNavigator","userStore","_userLoaded","_userUnloaded","_silentRenewError","_userSignedIn","_userSignedOut","_userSessionChanged","removeUserLoaded","removeUserUnloaded","addSilentRenewError","removeSilentRenewError","addUserSignedIn","removeUserSignedIn","addUserSignedOut","removeUserSignedOut","addUserSessionChanged","removeUserSessionChanged","DefaultCheckSessionInterval","store","_popup_redirect_uri","_popup_post_logout_redirect_uri","_popupWindowFeatures","_popupWindowTarget","_silent_redirect_uri","_silentRequestTimeout","_automaticSilentRenew","_validateSubOnSilentRenew","_includeIdTokenInSilentRenew","_monitorSession","_monitorAnonymousSession","_query_status_response_type","_revokeAccessTokenOnSignout","prefix","_store","_prefix"],"mappings":";;AAAA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;;AAGA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA,kDAA0C,gCAAgC;AAC1E;AACA;;AAEA;AACA;AACA;AACA,gEAAwD,kBAAkB;AAC1E;AACA,yDAAiD,cAAc;AAC/D;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,iDAAyC,iCAAiC;AAC1E,wHAAgH,mBAAmB,EAAE;AACrI;AACA;;AAEA;AACA;AACA;AACA,mCAA2B,0BAA0B,EAAE;AACvD,yCAAiC,eAAe;AAChD;AACA;AACA;;AAEA;AACA,8DAAsD,+DAA+D;;AAErH;AACA;;;AAGA;AACA;;;;;;;;;;;;;;;;;;;AC/EA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AAEA;;AAnBA;AACA;;kBAoBe;AACXA,6BADW;AAEXC,iBAFW;AAGXC,sCAHW;AAIXC,8DAJW;AAKXC,oEALW;AAMXC,8DANW;AAOXC,yCAPW;AAQXC,2DARW;AASXC,qDATW;AAUXC,uEAVW;AAWXC,0EAXW;AAYXC,8DAZW;AAaXC,uEAbW;AAcXC,kDAdW;AAeXC,0BAfW;AAgBXC;AAhBW,C;;;;;;;;;;;;;;;;;;;;;ACrBf;;;;AAIA,IAAIC,YAAY,EAAhB;AACAA,UAAUC,SAAV,GAAsB,KAAtB;;AAEA,IAAIC,SAAS,EAAb;;AAEA;;;;;;AAMA,IAAGC,UAAQC,SAAX,EAAqB;AAAC,MAAID,QAAM,EAAV;AAAa,OAAME,IAAN,GAAW,EAACC,QAAO,gBAASC,CAAT,EAAWC,CAAX,EAAaC,CAAb,EAAe;AAAC,QAAG,CAACD,CAAD,IAAI,CAACD,CAAR,EAAU;AAAC,YAAM,IAAIG,KAAJ,CAAU,4EAAV,CAAN;AAA8F,SAAIC,IAAE,SAAFA,CAAE,GAAU,CAAE,CAAlB,CAAmBA,EAAEC,SAAF,GAAYJ,EAAEI,SAAd,CAAwBL,EAAEK,SAAF,GAAY,IAAID,CAAJ,EAAZ,CAAoBJ,EAAEK,SAAF,CAAYC,WAAZ,GAAwBN,CAAxB,CAA0BA,EAAEO,UAAF,GAAaN,EAAEI,SAAf,CAAyB,IAAGJ,EAAEI,SAAF,CAAYC,WAAZ,IAAyBE,OAAOH,SAAP,CAAiBC,WAA7C,EAAyD;AAACL,QAAEI,SAAF,CAAYC,WAAZ,GAAwBL,CAAxB;AAA0B,SAAGC,CAAH,EAAK;AAAC,UAAIO,CAAJ,CAAM,KAAIA,CAAJ,IAASP,CAAT,EAAW;AAACF,UAAEK,SAAF,CAAYI,CAAZ,IAAeP,EAAEO,CAAF,CAAf;AAAoB,WAAIC,IAAE,aAAU,CAAE,CAAlB;AAAA,UAAmBC,IAAE,CAAC,UAAD,EAAY,SAAZ,CAArB,CAA4C,IAAG;AAAC,YAAG,OAAOC,IAAP,CAAYnB,UAAUC,SAAtB,CAAH,EAAoC;AAACgB,cAAE,WAASG,CAAT,EAAWC,CAAX,EAAa;AAAC,iBAAIL,IAAE,CAAN,EAAQA,IAAEE,EAAEI,MAAZ,EAAmBN,IAAEA,IAAE,CAAvB,EAAyB;AAAC,kBAAIO,IAAEL,EAAEF,CAAF,CAAN;AAAA,kBAAWQ,IAAEH,EAAEE,CAAF,CAAb,CAAkB,IAAG,OAAOC,CAAP,KAAW,UAAX,IAAuBA,KAAGT,OAAOH,SAAP,CAAiBW,CAAjB,CAA7B,EAAiD;AAACH,kBAAEG,CAAF,IAAKC,CAAL;AAAO;AAAC;AAAC,WAAvH;AAAwH;AAAC,OAAlK,CAAkK,OAAMC,CAAN,EAAQ,CAAE,GAAElB,EAAEK,SAAJ,EAAcH,CAAd;AAAiB;AAAC,GAA7lB,EAAX;AACnC;;;;;;;;AAQA,IAAIiB,WAASA,YAAW,UAAST,CAAT,EAAWV,CAAX,EAAa;AAAC,MAAIkB,IAAE,EAAN,CAAS,IAAIT,IAAES,EAAEE,GAAF,GAAM,EAAZ,CAAe,IAAIP,IAAEJ,EAAEY,IAAF,GAAQ,YAAU;AAAC,aAASC,CAAT,GAAY,CAAE,QAAM,EAACvB,QAAO,gBAASwB,CAAT,EAAW;AAACD,UAAEjB,SAAF,GAAY,IAAZ,CAAiB,IAAImB,IAAE,IAAIF,CAAJ,EAAN,CAAc,IAAGC,CAAH,EAAK;AAACC,YAAEC,KAAF,CAAQF,CAAR;AAAW,aAAG,CAACC,EAAEE,cAAF,CAAiB,MAAjB,CAAJ,EAA6B;AAACF,YAAEG,IAAF,GAAO,YAAU;AAACH,cAAEI,MAAF,CAASD,IAAT,CAAcE,KAAd,CAAoB,IAApB,EAAyBC,SAAzB;AAAoC,WAAtD;AAAuD,WAAEH,IAAF,CAAOtB,SAAP,GAAiBmB,CAAjB,CAAmBA,EAAEI,MAAF,GAAS,IAAT,CAAc,OAAOJ,CAAP;AAAS,OAAnM,EAAoMO,QAAO,kBAAU;AAAC,YAAIP,IAAE,KAAKzB,MAAL,EAAN,CAAoByB,EAAEG,IAAF,CAAOE,KAAP,CAAaL,CAAb,EAAeM,SAAf,EAA0B,OAAON,CAAP;AAAS,OAA7Q,EAA8QG,MAAK,gBAAU,CAAE,CAA/R,EAAgSF,OAAM,eAASF,CAAT,EAAW;AAAC,aAAI,IAAIC,CAAR,IAAaD,CAAb,EAAe;AAAC,cAAGA,EAAEG,cAAF,CAAiBF,CAAjB,CAAH,EAAuB;AAAC,iBAAKA,CAAL,IAAQD,EAAEC,CAAF,CAAR;AAAa;AAAC,aAAGD,EAAEG,cAAF,CAAiB,UAAjB,CAAH,EAAgC;AAAC,eAAKM,QAAL,GAAcT,EAAES,QAAhB;AAAyB;AAAC,OAAna,EAAoaC,OAAM,iBAAU;AAAC,eAAO,KAAKN,IAAL,CAAUtB,SAAV,CAAoBN,MAApB,CAA2B,IAA3B,CAAP;AAAwC,OAA7d,EAAN;AAAqe,GAA9f,EAAd,CAAghB,IAAIiB,IAAEP,EAAEyB,SAAF,GAAYrB,EAAEd,MAAF,CAAS,EAAC4B,MAAK,cAASH,CAAT,EAAWF,CAAX,EAAa;AAACE,UAAE,KAAKW,KAAL,GAAWX,KAAG,EAAhB,CAAmB,IAAGF,KAAGtB,CAAN,EAAQ;AAAC,aAAKoC,QAAL,GAAcd,CAAd;AAAgB,OAAzB,MAA6B;AAAC,aAAKc,QAAL,GAAcZ,EAAET,MAAF,GAAS,CAAvB;AAAyB;AAAC,KAA/F,EAAgGiB,UAAS,kBAASV,CAAT,EAAW;AAAC,aAAM,CAACA,KAAGrB,CAAJ,EAAOoC,SAAP,CAAiB,IAAjB,CAAN;AAA6B,KAAlJ,EAAmJC,QAAO,gBAASC,CAAT,EAAW;AAAC,UAAIC,IAAE,KAAKL,KAAX,CAAiB,IAAIZ,IAAEgB,EAAEJ,KAAR,CAAc,IAAIb,IAAE,KAAKc,QAAX,CAAoB,IAAIK,IAAEF,EAAEH,QAAR,CAAiB,KAAKM,KAAL,GAAa,IAAGpB,IAAE,CAAL,EAAO;AAAC,aAAI,IAAIqB,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,GAAhB,EAAoB;AAAC,cAAInB,IAAGD,EAAEoB,MAAI,CAAN,MAAY,KAAIA,IAAE,CAAH,GAAM,CAAtB,GAA0B,GAAhC,CAAoCH,EAAGlB,IAAEqB,CAAH,KAAQ,CAAV,KAAcnB,KAAI,KAAI,CAACF,IAAEqB,CAAH,IAAM,CAAP,GAAU,CAA/B;AAAkC;AAAC,OAApG,MAAwG;AAAC,aAAI,IAAIA,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,KAAG,CAAnB,EAAqB;AAACH,YAAGlB,IAAEqB,CAAH,KAAQ,CAAV,IAAapB,EAAEoB,MAAI,CAAN,CAAb;AAAsB;AAAC,YAAKP,QAAL,IAAeK,CAAf,CAAiB,OAAO,IAAP;AAAY,KAA1a,EAA2aC,OAAM,iBAAU;AAAC,UAAIlB,IAAE,KAAKW,KAAX,CAAiB,IAAIb,IAAE,KAAKc,QAAX,CAAoBZ,EAAEF,MAAI,CAAN,KAAU,cAAa,KAAIA,IAAE,CAAH,GAAM,CAAhC,CAAmCE,EAAET,MAAF,GAASL,EAAEkC,IAAF,CAAOtB,IAAE,CAAT,CAAT;AAAqB,KAAzhB,EAA0hBW,OAAM,iBAAU;AAAC,UAAIX,IAAET,EAAEoB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyBvB,EAAEa,KAAF,GAAQ,KAAKA,KAAL,CAAWW,KAAX,CAAiB,CAAjB,CAAR,CAA4B,OAAOxB,CAAP;AAAS,KAAzmB,EAA0mByB,QAAO,gBAASxB,CAAT,EAAW;AAAC,UAAIC,IAAE,EAAN,CAAS,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAEC,CAAd,EAAgBD,KAAG,CAAnB,EAAqB;AAACE,UAAEwB,IAAF,CAAQtC,EAAEqC,MAAF,KAAW,UAAZ,GAAwB,CAA/B;AAAkC,cAAO,IAAI/B,EAAEW,IAAN,CAAWH,CAAX,EAAaD,CAAb,CAAP;AAAuB,KAArtB,EAAT,CAAlB,CAAmvB,IAAI0B,IAAE/B,EAAEgC,GAAF,GAAM,EAAZ,CAAe,IAAIjD,IAAEgD,EAAEE,GAAF,GAAM,EAACd,WAAU,mBAASd,CAAT,EAAW;AAAC,UAAIoB,IAAEpB,EAAEY,KAAR,CAAc,IAAIX,IAAED,EAAEa,QAAR,CAAiB,IAAII,IAAE,EAAN,CAAS,KAAI,IAAIlB,IAAE,CAAV,EAAYA,IAAEE,CAAd,EAAgBF,GAAhB,EAAoB;AAAC,YAAImB,IAAGE,EAAErB,MAAI,CAAN,MAAY,KAAIA,IAAE,CAAH,GAAM,CAAtB,GAA0B,GAAhC,CAAoCkB,EAAEQ,IAAF,CAAO,CAACP,MAAI,CAAL,EAAQT,QAAR,CAAiB,EAAjB,CAAP,EAA6BQ,EAAEQ,IAAF,CAAO,CAACP,IAAE,EAAH,EAAOT,QAAP,CAAgB,EAAhB,CAAP;AAA4B,cAAOQ,EAAEY,IAAF,CAAO,EAAP,CAAP;AAAkB,KAAnM,EAAoMC,OAAM,eAAS9B,CAAT,EAAW;AAAC,UAAID,IAAEC,EAAER,MAAR,CAAe,IAAIyB,IAAE,EAAN,CAAS,KAAI,IAAIhB,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,KAAG,CAAnB,EAAqB;AAACgB,UAAEhB,MAAI,CAAN,KAAU8B,SAAS/B,EAAEgC,MAAF,CAAS/B,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,KAA6B,KAAIA,IAAE,CAAH,GAAM,CAAhD;AAAmD,cAAO,IAAIR,EAAEW,IAAN,CAAWa,CAAX,EAAalB,IAAE,CAAf,CAAP;AAAyB,KAAhV,EAAZ,CAA8V,IAAIlB,IAAE6C,EAAEO,MAAF,GAAS,EAACnB,WAAU,mBAASG,CAAT,EAAW;AAAC,UAAIG,IAAEH,EAAEL,KAAR,CAAc,IAAIZ,IAAEiB,EAAEJ,QAAR,CAAiB,IAAId,IAAE,EAAN,CAAS,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAED,CAAd,EAAgBC,GAAhB,EAAoB;AAAC,YAAIiB,IAAGE,EAAEnB,MAAI,CAAN,MAAY,KAAIA,IAAE,CAAH,GAAM,CAAtB,GAA0B,GAAhC,CAAoCF,EAAE0B,IAAF,CAAOS,OAAOC,YAAP,CAAoBjB,CAApB,CAAP;AAA+B,cAAOnB,EAAE8B,IAAF,CAAO,EAAP,CAAP;AAAkB,KAAzK,EAA0KC,OAAM,eAAS9B,CAAT,EAAW;AAAC,UAAID,IAAEC,EAAER,MAAR,CAAe,IAAIyB,IAAE,EAAN,CAAS,KAAI,IAAIhB,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,GAAhB,EAAoB;AAACgB,UAAEhB,MAAI,CAAN,KAAU,CAACD,EAAEoC,UAAF,CAAanC,CAAb,IAAgB,GAAjB,KAAwB,KAAIA,IAAE,CAAH,GAAM,CAA3C;AAA8C,cAAO,IAAIR,EAAEW,IAAN,CAAWa,CAAX,EAAalB,CAAb,CAAP;AAAuB,KAA9S,EAAf,CAA+T,IAAIX,IAAEsC,EAAEW,IAAF,GAAO,EAACvB,WAAU,mBAASf,CAAT,EAAW;AAAC,UAAG;AAAC,eAAOuC,mBAAmBC,OAAO1D,EAAEiC,SAAF,CAAYf,CAAZ,CAAP,CAAnB,CAAP;AAAkD,OAAtD,CAAsD,OAAME,CAAN,EAAQ;AAAC,cAAM,IAAIrB,KAAJ,CAAU,sBAAV,CAAN;AAAwC;AAAC,KAA/H,EAAgIkD,OAAM,eAAS/B,CAAT,EAAW;AAAC,aAAOlB,EAAEiD,KAAF,CAAQU,SAASC,mBAAmB1C,CAAnB,CAAT,CAAR,CAAP;AAAgD,KAAlM,EAAb,CAAiN,IAAIR,IAAEL,EAAEwD,sBAAF,GAAyBpD,EAAEd,MAAF,CAAS,EAACmE,OAAM,iBAAU;AAAC,WAAKC,KAAL,GAAW,IAAInD,EAAEW,IAAN,EAAX,CAAwB,KAAKyC,WAAL,GAAiB,CAAjB;AAAmB,KAA7D,EAA8DC,SAAQ,iBAAS/C,CAAT,EAAW;AAAC,UAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAACA,YAAEX,EAAE0C,KAAF,CAAQ/B,CAAR,CAAF;AAAa,YAAK6C,KAAL,CAAW7B,MAAX,CAAkBhB,CAAlB,EAAqB,KAAK8C,WAAL,IAAkB9C,EAAEc,QAApB;AAA6B,KAAxK,EAAyKkC,UAAS,kBAASC,CAAT,EAAW;AAAC,UAAI/B,IAAE,KAAK2B,KAAX,CAAiB,IAAIK,IAAEhC,EAAEL,KAAR,CAAc,IAAIb,IAAEkB,EAAEJ,QAAR,CAAiB,IAAIG,IAAE,KAAKkC,SAAX,CAAqB,IAAIC,IAAEnC,IAAE,CAAR,CAAU,IAAIoC,IAAErD,IAAEoD,CAAR,CAAU,IAAGH,CAAH,EAAK;AAACI,YAAEjE,EAAEkC,IAAF,CAAO+B,CAAP,CAAF;AAAY,OAAlB,MAAsB;AAACA,YAAEjE,EAAEkE,GAAF,CAAM,CAACD,IAAE,CAAH,IAAM,KAAKE,cAAjB,EAAgC,CAAhC,CAAF;AAAqC,WAAIpC,IAAEkC,IAAEpC,CAAR,CAAU,IAAII,IAAEjC,EAAEoE,GAAF,CAAMrC,IAAE,CAAR,EAAUnB,CAAV,CAAN,CAAmB,IAAGmB,CAAH,EAAK;AAAC,aAAI,IAAIlB,IAAE,CAAV,EAAYA,IAAEkB,CAAd,EAAgBlB,KAAGgB,CAAnB,EAAqB;AAAC,eAAKwC,eAAL,CAAqBP,CAArB,EAAuBjD,CAAvB;AAA0B,aAAIC,IAAEgD,EAAEQ,MAAF,CAAS,CAAT,EAAWvC,CAAX,CAAN,CAAoBD,EAAEJ,QAAF,IAAYO,CAAZ;AAAc,cAAO,IAAI3B,EAAEW,IAAN,CAAWH,CAAX,EAAamB,CAAb,CAAP;AAAuB,KAA/d,EAAgeV,OAAM,iBAAU;AAAC,UAAIX,IAAET,EAAEoB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyBvB,EAAE6C,KAAF,GAAQ,KAAKA,KAAL,CAAWlC,KAAX,EAAR,CAA2B,OAAOX,CAAP;AAAS,KAA9iB,EAA+iBuD,gBAAe,CAA9jB,EAAT,CAA/B,CAA0mB,IAAI3E,IAAEO,EAAEwE,MAAF,GAASnE,EAAEf,MAAF,CAAS,EAACmF,KAAIrE,EAAEd,MAAF,EAAL,EAAgB4B,MAAK,cAASL,CAAT,EAAW;AAAC,WAAK4D,GAAL,GAAS,KAAKA,GAAL,CAASnF,MAAT,CAAgBuB,CAAhB,CAAT,CAA4B,KAAK4C,KAAL;AAAa,KAA1E,EAA2EA,OAAM,iBAAU;AAACpD,QAAEoD,KAAF,CAAQrB,IAAR,CAAa,IAAb,EAAmB,KAAKsC,QAAL;AAAgB,KAA/H,EAAgIC,QAAO,gBAAS9D,CAAT,EAAW;AAAC,WAAK+C,OAAL,CAAa/C,CAAb,EAAgB,KAAKgD,QAAL,GAAgB,OAAO,IAAP;AAAY,KAA/L,EAAgMe,UAAS,kBAAS/D,CAAT,EAAW;AAAC,UAAGA,CAAH,EAAK;AAAC,aAAK+C,OAAL,CAAa/C,CAAb;AAAgB,WAAIE,IAAE,KAAK8D,WAAL,EAAN,CAAyB,OAAO9D,CAAP;AAAS,KAA7Q,EAA8QiD,WAAU,MAAI,EAA5R,EAA+Rc,eAAc,uBAASjE,CAAT,EAAW;AAAC,aAAO,UAASC,CAAT,EAAWC,CAAX,EAAa;AAAC,eAAO,IAAIF,EAAEK,IAAN,CAAWH,CAAX,EAAc6D,QAAd,CAAuB9D,CAAvB,CAAP;AAAiC,OAAtD;AAAuD,KAAhX,EAAiXiE,mBAAkB,2BAASlE,CAAT,EAAW;AAAC,aAAO,UAASC,CAAT,EAAWC,CAAX,EAAa;AAAC,eAAO,IAAIP,EAAEwE,IAAF,CAAO9D,IAAX,CAAgBL,CAAhB,EAAkBE,CAAlB,EAAqB6D,QAArB,CAA8B9D,CAA9B,CAAP;AAAwC,OAA7D;AAA8D,KAA7c,EAAT,CAAf,CAAwe,IAAIN,IAAEC,EAAEwE,IAAF,GAAO,EAAb,CAAgB,OAAOxE,CAAP;AAAS,CAAjxG,CAAkxGyE,IAAlxG,CAAxB;AACA;;;;;;AAMA,CAAC,UAAS3F,CAAT,EAAW;AAAC,MAAIkB,IAAEC,QAAN;AAAA,MAAejB,IAAEgB,EAAEE,GAAnB;AAAA,MAAuBV,IAAER,EAAEmB,IAA3B;AAAA,MAAgCpB,IAAEC,EAAEgC,SAApC;AAAA,MAA8ChB,IAAEA,EAAE0E,GAAF,GAAM,EAAtD,CAAyD1E,EAAE2E,IAAF,GAAOnF,EAAEX,MAAF,CAAS,EAAC4B,MAAK,cAASlB,CAAT,EAAWE,CAAX,EAAa;AAAC,WAAKmF,IAAL,GAAUrF,CAAV,CAAY,KAAKsF,GAAL,GAASpF,CAAT;AAAW,KAA3C,EAAT,CAAP,CAA8DO,EAAEgB,SAAF,GAAYxB,EAAEX,MAAF,CAAS,EAAC4B,MAAK,cAASlB,CAAT,EAAWE,CAAX,EAAa;AAACF,UAAE,KAAK0B,KAAL,GAAW1B,KAAG,EAAhB,CAAmB,KAAK2B,QAAL,GAAczB,KAAGX,CAAH,GAAKW,CAAL,GAAO,IAAEF,EAAEM,MAAzB;AAAgC,KAAvE,EAAwEiF,OAAM,iBAAU;AAAC,WAAI,IAAIvF,IAAE,KAAK0B,KAAX,EAAiBxB,IAAEF,EAAEM,MAArB,EAA4BG,IAAE,EAA9B,EAAiCd,IAAE,CAAvC,EAAyCA,IAAEO,CAA3C,EAA6CP,GAA7C,EAAiD;AAAC,YAAIM,IAAED,EAAEL,CAAF,CAAN,CAAWc,EAAE8B,IAAF,CAAOtC,EAAEoF,IAAT,EAAe5E,EAAE8B,IAAF,CAAOtC,EAAEqF,GAAT;AAAc,cAAO9F,EAAE8B,MAAF,CAASb,CAAT,EAAW,KAAKkB,QAAhB,CAAP;AAAiC,KAApN,EAAqNH,OAAM,iBAAU;AAAC,WAAI,IAAIxB,IAAEC,EAAEuB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,EAAyBlC,IAAEF,EAAE0B,KAAF,GAAQ,KAAKA,KAAL,CAAWW,KAAX,CAAiB,CAAjB,CAAnC,EAAuD5B,IAAEP,EAAEI,MAA3D,EAAkEX,IAAE,CAAxE,EAA0EA,IAAEc,CAA5E,EAA8Ed,GAA9E;AAAkFO,UAAEP,CAAF,IAAKO,EAAEP,CAAF,EAAK6B,KAAL,EAAL;AAAlF,OAAoG,OAAOxB,CAAP;AAAS,KAAnV,EAAT,CAAZ;AAA2W,CAA/e;;AAEA;;;;;;AAMA,CAAC,YAAU;AAAC,MAAIR,IAAEkB,QAAN;AAAA,MAAeN,IAAEZ,EAAEmB,GAAF,CAAMc,SAAvB,CAAiCjC,EAAEiD,GAAF,CAAM+C,MAAN,GAAa,EAAC5D,WAAU,mBAAS5B,CAAT,EAAW;AAAC,UAAIC,IAAED,EAAE0B,KAAR;AAAA,UAAcjC,IAAEO,EAAE2B,QAAlB;AAAA,UAA2BzB,IAAE,KAAKuF,IAAlC,CAAuCzF,EAAEiC,KAAF,GAAUjC,IAAE,EAAF,CAAK,KAAI,IAAIS,IAAE,CAAV,EAAYA,IAAEhB,CAAd,EAAgBgB,KAAG,CAAnB;AAAqB,aAAI,IAAId,IAAE,CAACM,EAAEQ,MAAI,CAAN,MAAW,KAAG,KAAGA,IAAE,CAAL,CAAd,GAAsB,GAAvB,KAA6B,EAA7B,GAAgC,CAACR,EAAEQ,IAAE,CAAF,KAAM,CAAR,MAAa,KAAG,KAAG,CAACA,IAAE,CAAH,IAAM,CAAT,CAAhB,GAA4B,GAA7B,KAAmC,CAAnE,GAAqER,EAAEQ,IAAE,CAAF,KAAM,CAAR,MAAa,KAAG,KAAG,CAACA,IAAE,CAAH,IAAM,CAAT,CAAhB,GAA4B,GAAvG,EAA2GlB,IAAE,CAAjH,EAAmH,IAAEA,CAAF,IAAKkB,IAAE,OAAKlB,CAAP,GAASE,CAAjI,EAAmIF,GAAnI;AAAuIS,YAAEuC,IAAF,CAAOrC,EAAEwF,MAAF,CAAS/F,MAAI,KAAG,IAAEJ,CAAL,CAAJ,GAAY,EAArB,CAAP;AAAvI;AAArB,OAA6L,IAAGU,IAAEC,EAAEwF,MAAF,CAAS,EAAT,CAAL,EAAkB,OAAK1F,EAAEM,MAAF,GAAS,CAAd;AAAiBN,UAAEuC,IAAF,CAAOtC,CAAP;AAAjB,OAA2B,OAAOD,EAAE2C,IAAF,CAAO,EAAP,CAAP;AAAkB,KAAzU,EAA0UC,OAAM,eAAS5C,CAAT,EAAW;AAAC,UAAIC,IAAED,EAAEM,MAAR;AAAA,UAAeb,IAAE,KAAKgG,IAAtB;AAAA,UAA2BvF,IAAET,EAAEiG,MAAF,CAAS,EAAT,CAA7B,CAA0CxF,MAAIA,IAAEF,EAAE2F,OAAF,CAAUzF,CAAV,CAAF,EAAe,CAAC,CAAD,IAAIA,CAAJ,KAAQD,IAAEC,CAAV,CAAnB,EAAiC,KAAI,IAAIA,IAAE,EAAN,EAASO,IAAE,CAAX,EAAad,IAAE,CAAnB,EAAqBA,IACtfM,CADie,EAC/dN,GAD+d;AAC3d,YAAGA,IAAE,CAAL,EAAO;AAAC,cAAIJ,IAAEE,EAAEkG,OAAF,CAAU3F,EAAE0F,MAAF,CAAS/F,IAAE,CAAX,CAAV,KAA0B,KAAGA,IAAE,CAAL,CAAhC;AAAA,cAAwCH,IAAEC,EAAEkG,OAAF,CAAU3F,EAAE0F,MAAF,CAAS/F,CAAT,CAAV,MAAyB,IAAE,KAAGA,IAAE,CAAL,CAArE,CAA6EO,EAAEO,MAAI,CAAN,KAAU,CAAClB,IAAEC,CAAH,KAAO,KAAG,KAAGiB,IAAE,CAAL,CAApB,CAA4BA;AAAI;AADsW,OACtW,OAAOL,EAAEkB,MAAF,CAASpB,CAAT,EAAWO,CAAX,CAAP;AAAqB,KADtF,EACuFgF,MAAK,mEAD5F,EAAb;AAC8K,CAD3N;;AAGA;;;;;;AAMA,CAAC,UAASjF,CAAT,EAAW;AAAC,OAAI,IAAIjB,IAAEmB,QAAN,EAAelB,IAAED,EAAEoB,GAAnB,EAAuBsD,IAAEzE,EAAEiC,SAA3B,EAAqCrB,IAAEZ,EAAEgF,MAAzC,EAAgDhF,IAAED,EAAE0F,IAApD,EAAyDjD,IAAE,EAA3D,EAA8DF,IAAE,EAAhE,EAAmEoC,IAAE,SAAFA,CAAE,CAASnC,CAAT,EAAW;AAAC,WAAO,cAAYA,KAAGA,IAAE,CAAL,CAAZ,IAAqB,CAA5B;AAA8B,GAA/G,EAAgHxB,IAAE,CAAlH,EAAoHP,IAAE,CAA1H,EAA4H,KAAGA,CAA/H,GAAkI;AAAC,QAAIL,CAAJ,CAAMc,GAAE;AAACd,UAAEY,CAAF,CAAI,KAAI,IAAIuD,IAAEtD,EAAEoF,IAAF,CAAOjG,CAAP,CAAN,EAAgBuC,IAAE,CAAtB,EAAwBA,KAAG4B,CAA3B,EAA6B5B,GAA7B;AAAiC,YAAG,EAAEvC,IAAEuC,CAAJ,CAAH,EAAU;AAACvC,cAAE,CAAC,CAAH,CAAK,MAAMc,CAAN;AAAQ;AAAzD,OAAyDd,IAAE,CAAC,CAAH;AAAK,WAAI,IAAEK,CAAF,KAAMgC,EAAEhC,CAAF,IAAKkE,EAAE1D,EAAEqF,GAAF,CAAMtF,CAAN,EAAQ,GAAR,CAAF,CAAX,GAA4BuB,EAAE9B,CAAF,IAAKkE,EAAE1D,EAAEqF,GAAF,CAAMtF,CAAN,EAAQ,IAAE,CAAV,CAAF,CAAjC,EAAiDP,GAArD,EAA0DO;AAAI,OAAIM,IAAE,EAAN;AAAA,MAASrB,IAAEA,EAAEsG,MAAF,GAAS1F,EAAEd,MAAF,CAAS,EAACoF,UAAS,oBAAU;AAAC,WAAKqB,KAAL,GAAW,IAAI9B,EAAE/C,IAAN,CAAWc,EAAEK,KAAF,CAAQ,CAAR,CAAX,CAAX;AAAkC,KAAvD,EAAwDiC,iBAAgB,yBAASvC,CAAT,EAAWvC,CAAX,EAAa;AAAC,WAAI,IAAIiB,IAAE,KAAKsF,KAAL,CAAWrE,KAAjB,EAAuBxB,IAAEO,EAAE,CAAF,CAAzB,EAA8Bd,IAAEc,EAAE,CAAF,CAAhC,EAAqCT,IAAES,EAAE,CAAF,CAAvC,EAA4CD,IAAEC,EAAE,CAAF,CAA9C,EAAmDhB,IAAEgB,EAAE,CAAF,CAArD,EAA0DlB,IAAEkB,EAAE,CAAF,CAA5D,EAAiEL,IAAEK,EAAE,CAAF,CAAnE,EAAwEF,IAAEE,EAAE,CAAF,CAA1E,EAA+ER,IAAE,CAArF,EAAuF,KAAGA,CAA1F,EAA4FA,GAA5F,EAAgG;AAAC,YAAG,KAAGA,CAAN,EAAQY,EAAEZ,CAAF,IACrf8B,EAAEvC,IAAES,CAAJ,IAAO,CAD8e,CAAR,KAChe;AAAC,cAAIuC,IAAE3B,EAAEZ,IAAE,EAAJ,CAAN;AAAA,cAAca,IAAED,EAAEZ,IAAE,CAAJ,CAAhB,CAAuBY,EAAEZ,CAAF,IAAK,CAAC,CAACuC,KAAG,EAAH,GAAMA,MAAI,CAAX,KAAeA,KAAG,EAAH,GAAMA,MAAI,EAAzB,IAA6BA,MAAI,CAAlC,IAAqC3B,EAAEZ,IAAE,CAAJ,CAArC,IAA6C,CAACa,KAAG,EAAH,GAAMA,MAAI,EAAX,KAAgBA,KAAG,EAAH,GAAMA,MAAI,EAA1B,IAA8BA,MAAI,EAA/E,IAAmFD,EAAEZ,IAAE,EAAJ,CAAxF;AAAgG,aAAEM,KAAG,CAACd,KAAG,EAAH,GAAMA,MAAI,CAAX,KAAeA,KAAG,EAAH,GAAMA,MAAI,EAAzB,KAA8BA,KAAG,CAAH,GAAKA,MAAI,EAAvC,CAAH,KAAgDA,IAAEF,CAAF,GAAI,CAACE,CAAD,GAAGW,CAAvD,IAA0D0B,EAAE7B,CAAF,CAA1D,GAA+DY,EAAEZ,CAAF,CAAjE,CAAsEa,IAAE,CAAC,CAACZ,KAAG,EAAH,GAAMA,MAAI,CAAX,KAAeA,KAAG,EAAH,GAAMA,MAAI,EAAzB,KAA8BA,KAAG,EAAH,GAAMA,MAAI,EAAxC,CAAD,KAA+CA,IAAEP,CAAF,GAAIO,IAAEF,CAAN,GAAQL,IAAEK,CAAzD,CAAF,CAA8DO,IAAEH,CAAF,CAAIA,IAAEb,CAAF,CAAIA,IAAEE,CAAF,CAAIA,IAAEe,IAAEgC,CAAF,GAAI,CAAN,CAAQhC,IAAER,CAAF,CAAIA,IAAEL,CAAF,CAAIA,IAAEO,CAAF,CAAIA,IAAEsC,IAAE1B,CAAF,GAAI,CAAN;AAAQ,SAAE,CAAF,IAAKL,EAAE,CAAF,IAAKP,CAAL,GAAO,CAAZ,CAAcO,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKd,CAAL,GAAO,CAAZ,CAAcc,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKT,CAAL,GAAO,CAAZ,CAAcS,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKD,CAAL,GAAO,CAAZ,CAAcC,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKhB,CAAL,GAAO,CAAZ,CAAcgB,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKlB,CAAL,GAAO,CAAZ,CAAckB,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKL,CAAL,GAAO,CAAZ,CAAcK,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKF,CAAL,GAAO,CAAZ;AAAc,KAD3G,EAC4GsE,aAAY,uBAAU;AAAC,UAAIlF,IAAE,KAAK+D,KAAX;AAAA,UAAiB1D,IAAEL,EAAE+B,KAArB;AAAA,UAA2BjB,IAAE,IAAE,KAAKkD,WAApC;AAAA,UAAgDzD,IAAE,IAAEP,EAAEgC,QAAtD;AACzb3B,QAAEE,MAAI,CAAN,KAAU,OAAK,KAAGA,IAAE,EAApB,CAAuBF,EAAE,CAACE,IAAE,EAAF,KAAO,CAAP,IAAU,CAAX,IAAc,EAAhB,IAAoBM,EAAEwF,KAAF,CAAQvF,IAAE,UAAV,CAApB,CAA0CT,EAAE,CAACE,IAAE,EAAF,KAAO,CAAP,IAAU,CAAX,IAAc,EAAhB,IAAoBO,CAApB,CAAsBd,EAAEgC,QAAF,GAAW,IAAE3B,EAAEM,MAAf,CAAsB,KAAKuD,QAAL,GAAgB,OAAO,KAAKkC,KAAZ;AAAkB,KAFuK,EAEtKvE,OAAM,iBAAU;AAAC,UAAIxB,IAAEI,EAAEoB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyBpC,EAAE+F,KAAF,GAAQ,KAAKA,KAAL,CAAWvE,KAAX,EAAR,CAA2B,OAAOxB,CAAP;AAAS,KAFwF,EAAT,CAApB,CAExDT,EAAEuG,MAAF,GAAS1F,EAAE0E,aAAF,CAAgBtF,CAAhB,CAAT,CAA4BD,EAAE0G,UAAF,GAAa7F,EAAE2E,iBAAF,CAAoBvF,CAApB,CAAb;AAAoC,CAFjS,EAEmS0F,IAFnS;;AAIA;;;;;;AAMA,CAAC,YAAU;AAAC,WAASzE,CAAT,GAAY;AAAC,WAAOd,EAAE2B,MAAF,CAASF,KAAT,CAAezB,CAAf,EAAiB0B,SAAjB,CAAP;AAAmC,QAAI,IAAIR,IAAEH,QAAN,EAAewB,IAAErB,EAAEF,GAAF,CAAM6D,MAAvB,EAA8BvE,IAAEY,EAAEsE,GAAlC,EAAsCxF,IAAEM,EAAEmF,IAA1C,EAA+Cc,IAAEjG,EAAEwB,SAAnD,EAA6DxB,IAAEY,EAAEoE,IAAjE,EAAsEkB,KAAG,CAAC1F,EAAE,UAAF,EAAa,UAAb,CAAD,EAA0BA,EAAE,UAAF,EAAa,SAAb,CAA1B,EAAkDA,EAAE,UAAF,EAAa,UAAb,CAAlD,EAA2EA,EAAE,UAAF,EAAa,UAAb,CAA3E,EAAoGA,EAAE,SAAF,EAAY,UAAZ,CAApG,EAA4HA,EAAE,UAAF,EAAa,UAAb,CAA5H,EAAqJA,EAAE,UAAF,EAAa,UAAb,CAArJ,EAA8KA,EAAE,UAAF,EAAa,UAAb,CAA9K,EAAuMA,EAAE,UAAF,EAAa,UAAb,CAAvM,EAAgOA,EAAE,SAAF,EAAY,UAAZ,CAAhO,EAAwPA,EAAE,SAAF,EAAY,UAAZ,CAAxP,EAAgRA,EAAE,UAAF,EAAa,UAAb,CAAhR,EAAySA,EAAE,UAAF,EAAa,UAAb,CAAzS,EAAkUA,EAAE,UAAF,EAAa,SAAb,CAAlU,EAA0VA,EAAE,UAAF,EAAa,SAAb,CAA1V,EACzIA,EAAE,UAAF,EAAa,UAAb,CADyI,EAChHA,EAAE,UAAF,EAAa,UAAb,CADgH,EACvFA,EAAE,UAAF,EAAa,SAAb,CADuF,EAC/DA,EAAE,SAAF,EAAY,UAAZ,CAD+D,EACvCA,EAAE,SAAF,EAAY,UAAZ,CADuC,EACfA,EAAE,SAAF,EAAY,UAAZ,CADe,EACSA,EAAE,UAAF,EAAa,UAAb,CADT,EACkCA,EAAE,UAAF,EAAa,UAAb,CADlC,EAC2DA,EAAE,UAAF,EAAa,UAAb,CAD3D,EACoFA,EAAE,UAAF,EAAa,UAAb,CADpF,EAC6GA,EAAE,UAAF,EAAa,SAAb,CAD7G,EACqIA,EAAE,UAAF,EAAa,UAAb,CADrI,EAC8JA,EAAE,UAAF,EAAa,UAAb,CAD9J,EACuLA,EAAE,UAAF,EAAa,UAAb,CADvL,EACgNA,EAAE,UAAF,EAAa,UAAb,CADhN,EACyOA,EAAE,SAAF,EAAY,UAAZ,CADzO,EACiQA,EAAE,SAAF,EAAY,SAAZ,CADjQ,EACwRA,EAAE,SAAF,EAAY,UAAZ,CADxR,EACgTA,EAAE,SAAF,EAAY,UAAZ,CADhT,EACwUA,EAAE,UAAF,EAAa,UAAb,CADxU,EACiWA,EAAE,UAAF,EAC1e,UAD0e,CADjW,EAE7HA,EAAE,UAAF,EAAa,UAAb,CAF6H,EAEpGA,EAAE,UAAF,EAAa,UAAb,CAFoG,EAE3EA,EAAE,UAAF,EAAa,UAAb,CAF2E,EAElDA,EAAE,UAAF,EAAa,SAAb,CAFkD,EAE1BA,EAAE,UAAF,EAAa,UAAb,CAF0B,EAEDA,EAAE,UAAF,EAAa,UAAb,CAFC,EAEwBA,EAAE,UAAF,EAAa,UAAb,CAFxB,EAEiDA,EAAE,UAAF,EAAa,SAAb,CAFjD,EAEyEA,EAAE,UAAF,EAAa,UAAb,CAFzE,EAEkGA,EAAE,UAAF,EAAa,UAAb,CAFlG,EAE2HA,EAAE,UAAF,EAAa,UAAb,CAF3H,EAEoJA,EAAE,SAAF,EAAY,SAAZ,CAFpJ,EAE2KA,EAAE,SAAF,EAAY,UAAZ,CAF3K,EAEmMA,EAAE,SAAF,EAAY,UAAZ,CAFnM,EAE2NA,EAAE,SAAF,EAAY,UAAZ,CAF3N,EAEmPA,EAAE,SAAF,EAAY,UAAZ,CAFnP,EAE2QA,EAAE,SAAF,EAAY,UAAZ,CAF3Q,EAEmSA,EAAE,UAAF,EAAa,UAAb,CAFnS,EAE4TA,EAAE,UAAF,EAAa,UAAb,CAF5T,EAEqVA,EAAE,UAAF,EAAa,UAAb,CAFrV,EAGzIA,EAAE,UAAF,EAAa,UAAb,CAHyI,EAGhHA,EAAE,UAAF,EAAa,UAAb,CAHgH,EAGvFA,EAAE,UAAF,EAAa,UAAb,CAHuF,EAG9DA,EAAE,UAAF,EAAa,SAAb,CAH8D,EAGtCA,EAAE,UAAF,EAAa,SAAb,CAHsC,EAGdA,EAAE,UAAF,EAAa,UAAb,CAHc,EAGWA,EAAE,UAAF,EAAa,UAAb,CAHX,EAGoCA,EAAE,UAAF,EAAa,UAAb,CAHpC,EAG6DA,EAAE,UAAF,EAAa,UAAb,CAH7D,EAGsFA,EAAE,UAAF,EAAa,SAAb,CAHtF,EAG8GA,EAAE,UAAF,EAAa,UAAb,CAH9G,EAGuIA,EAAE,UAAF,EAAa,UAAb,CAHvI,EAGgKA,EAAE,SAAF,EAAY,UAAZ,CAHhK,EAGwLA,EAAE,SAAF,EAAY,UAAZ,CAHxL,EAGgNA,EAAE,SAAF,EAAY,UAAZ,CAHhN,EAGwOA,EAAE,SAAF,EAAY,SAAZ,CAHxO,EAG+PA,EAAE,SAAF,EAAY,SAAZ,CAH/P,EAGsRA,EAAE,SAAF,EAAY,UAAZ,CAHtR,EAG8SA,EAAE,UAAF,EAAa,SAAb,CAH9S,EAGsUA,EAAE,UAAF,EAAa,UAAb,CAHtU,EAG+VA,EAAE,UAAF,EACxe,UADwe,CAH/V,EAI7HA,EAAE,UAAF,EAAa,UAAb,CAJ6H,EAIpGA,EAAE,UAAF,EAAa,SAAb,CAJoG,EAI5EA,EAAE,UAAF,EAAa,UAAb,CAJ4E,CAAzE,EAIuBwD,IAAE,EAJzB,EAI4BH,IAAE,CAJlC,EAIoC,KAAGA,CAJvC,EAIyCA,GAJzC;AAI6CG,MAAEH,CAAF,IAAKrD,GAAL;AAJ7C,GAIsDR,IAAEA,EAAEmG,MAAF,GAASlE,EAAE5C,MAAF,CAAS,EAACoF,UAAS,oBAAU;AAAC,WAAKqB,KAAL,GAAW,IAAIG,EAAEhF,IAAN,CAAW,CAAC,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAD,EAAmC,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAnC,EAAqE,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAArE,EAAuG,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAvG,EAAyI,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAzI,EAA2K,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAA3K,EAA4M,IAAIvB,EAAEuB,IAAN,CAAW,SAAX,EAAqB,UAArB,CAA5M,EAA6O,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAA7O,CAAX,CAAX;AAAsS,KAA3T,EAA4ToD,iBAAgB,yBAAS7D,CAAT,EAAWd,CAAX,EAAa;AAAC,WAAI,IAAIF,IAAE,KAAKsG,KAAL,CAAWrE,KAAjB,EACpe2E,IAAE5G,EAAE,CAAF,CADke,EAC7dQ,IAAER,EAAE,CAAF,CAD2d,EACtdoB,IAAEpB,EAAE,CAAF,CADod,EAC/cyC,IAAEzC,EAAE,CAAF,CAD6c,EACxc6G,IAAE7G,EAAE,CAAF,CADsc,EACjc8G,IAAE9G,EAAE,CAAF,CAD+b,EAC1b+G,IAAE/G,EAAE,CAAF,CADwb,EACnbA,IAAEA,EAAE,CAAF,CADib,EAC5aqE,IAAEuC,EAAEhB,IADwa,EACnaoB,IAAEJ,EAAEf,GAD+Z,EAC3ZoB,IAAEzG,EAAEoF,IADuZ,EAClZsB,IAAE1G,EAAEqF,GAD8Y,EAC1YsB,IAAE/F,EAAEwE,IADsY,EACjYwB,IAAEhG,EAAEyE,GAD6X,EACzXwB,IAAE5E,EAAEmD,IADqX,EAChX0B,IAAE7E,EAAEoD,GAD4W,EACxW0B,IAAEV,EAAEjB,IADoW,EAC/V4B,IAAEX,EAAEhB,GAD2V,EACvV4B,KAAGX,EAAElB,IADkV,EAC7U8B,IAAEZ,EAAEjB,GADyU,EACrU8B,KAAGZ,EAAEnB,IADgU,EAC3TgC,IAAEb,EAAElB,GADuT,EACnTgC,KAAG7H,EAAE4F,IAD8S,EACzSkC,IAAE9H,EAAE6F,GADqS,EACjS9E,IAAEsD,CAD+R,EAC7RvE,IAAEkH,CAD2R,EACzRe,IAAEd,CADuR,EACrR3C,IAAE4C,CADmR,EACjRc,IAAEb,CAD+Q,EAC7Qc,IAAEb,CAD2Q,EACzQc,IAAEb,CADuQ,EACrQc,IAAEb,CADmQ,EACjQxG,IAAEyG,CAD+P,EAC7PxH,IAAEyH,CAD2P,EACzPY,IAAEX,EADuP,EACpPY,IAAEX,CADkP,EAChPY,IAAEX,EAD8O,EAC3OY,IAAEX,CADyO,EACvOY,IAAEX,EADqO,EAClOY,IAAEX,CADgO,EAC9N/E,IAAE,CADwN,EACtN,KAAGA,CADmN,EACjNA,GADiN,EAC7M;AAAC,YAAIR,IAAEiC,EAAEzB,CAAF,CAAN,CAAW,IAAG,KAAGA,CAAN,EAAQ,IAAIpC,IAAE4B,EAAEqD,IAAF,GAAO5E,EAAEd,IAAE,IAAE6C,CAAN,IAAS,CAAtB;AAAA,YAAwBxC,IAAEgC,EAAEsD,GAAF,GAAM7E,EAAEd,IAAE,IAAE6C,CAAJ,GAAM,CAAR,IAAW,CAA3C,CAAR,KAAyD;AAAC,cAAIpC,IAAE6D,EAAEzB,IAAE,EAAJ,CAAN;AAAA,cAAcxC,IAAEI,EAAEiF,IAAlB;AAAA,cAAuBvE,IAAEV,EAAEkF,GAA3B;AAAA,cAA+BlF,IAAE,CAACJ,MAAI,CAAJ,GAAMc,KAAG,EAAV,KAAed,MAAI,CAAJ,GAAMc,KAAG,EAAxB,IAA4Bd,MAAI,CAAjE;AAAA,cAAmEc,IAAE,CAACA,MAAI,CAAJ,GAAMd,KAAG,EAAV,KAAec,MAAI,CAAJ,GAAMd,KAAG,EAAxB,KAA6Bc,MAAI,CAAJ,GAAMd,KAAG,EAAtC,CAArE;AAAA,cAA+GkE,IAAED,EAAEzB,IAAE,CAAJ,CAAjH;AAAA,cAAwHxC,IAAEkE,EAAEmB,IAA5H;AAAA,cAAiInF,IAAEgE,EAAEoB,GAArI;AAAA,cAAyIpB,IAAE,CAAClE,MAAI,EAAJ,GAAOE,KAAG,EAAX,KAAgBF,KACpf,CADof,GAClfE,MAAI,EAD8d,IAC1dF,MAAI,CAD2U;AAAA,cACzUE,IAAE,CAACA,MAAI,EAAJ,GAAOF,KAAG,EAAX,KAAgBE,KAAG,CAAH,GAAKF,MAAI,EAAzB,KAA8BE,MAAI,CAAJ,GAAMF,KAAG,EAAvC,CADuU;AAAA,cAC5RA,IAAEiE,EAAEzB,IAAE,CAAJ,CAD0R;AAAA,cACnR2F,IAAEnI,EAAEqF,IAD+Q;AAAA,cAC1QvD,IAAEmC,EAAEzB,IAAE,EAAJ,CADwQ;AAAA,cAChQT,IAAED,EAAEuD,IAD4P;AAAA,cACvPvD,IAAEA,EAAEwD,GADmP;AAAA,cAC/OtF,IAAEc,IAAEd,EAAEsF,GADyO;AAAA,cACrOlF,IAAEA,IAAE+H,CAAF,IAAKnI,MAAI,CAAJ,GAAMc,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADmO;AAAA,cAC7Md,IAAEA,IAAEE,CADyM;AAAA,cACvME,IAAEA,IAAE8D,CAAF,IAAKlE,MAAI,CAAJ,GAAME,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADqM;AAAA,cAC/KF,IAAEA,IAAE8B,CAD2K;AAAA,cACzK1B,IAAEA,IAAE2B,CAAF,IAAK/B,MAAI,CAAJ,GAAM8B,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADuK,CACjJE,EAAEqD,IAAF,GAAOjF,CAAP,CAAS4B,EAAEsD,GAAF,GAAMtF,CAAN;AAAQ,aAAImI,IAAE5H,IAAEsH,CAAF,GAAI,CAACtH,CAAD,GAAGwH,CAAb;AAAA,YAAejG,IAAEtC,IAAEsI,CAAF,GAAI,CAACtI,CAAD,GAAGwI,CAAxB;AAAA,YAA0BhG,IAAExB,IAAEgH,CAAF,GAAIhH,IAAEiH,CAAN,GAAQD,IAAEC,CAAtC;AAAA,YAAwCvB,IAAE3G,IAAEwE,CAAF,GAAIxE,IAAEmI,CAAN,GAAQ3D,IAAE2D,CAApD;AAAA,YAAsD5G,IAAE,CAACN,MAAI,EAAJ,GAAOjB,KAAG,CAAX,KAAeiB,KAAG,EAAH,GAAMjB,MAAI,CAAzB,KAA6BiB,KAAG,EAAH,GAAMjB,MAAI,CAAvC,CAAxD;AAAA,YAAkG2E,IAAE,CAAC3E,MAAI,EAAJ,GAAOiB,KAAG,CAAX,KAAejB,KAAG,EAAH,GAAMiB,MAAI,CAAzB,KAA6BjB,KAAG,EAAH,GAAMiB,MAAI,CAAvC,CAApG;AAAA,YAA8IN,IAAEiG,GAAG3D,CAAH,CAAhJ;AAAA,YAAsJ4F,KAAGlI,EAAEmF,IAA3J;AAAA,YAAgKgD,KAAGnI,EAAEoF,GAArK;AAAA,YAAyKpF,IAAEgI,KAAG,CAAC1I,MAAI,EAAJ,GAAOe,KAAG,EAAX,KAAgBf,MAAI,EAAJ,GAAOe,KAAG,EAA1B,KAA+Bf,KAAG,EAAH,GAAMe,MAAI,CAAzC,CAAH,CAA3K;AAAA,YAA2NwB,IAAEkG,KAAG,CAAC1H,MAAI,EAAJ,GAAOf,KAAG,EAAX,KAAgBe,MAAI,EAAJ,GAAOf,KAAG,EAA1B,KAA+Be,KAAG,EAAH,GAAMf,MAAI,CAAzC,CAAH,KAAiDU,MAAI,CAAJ,GAAMgI,MAAI,CAAV,GAAY,CAAZ,GACve,CADsb,CAA7N;AAAA,YACtNhI,IAAEA,IAAE4B,CADkN;AAAA,YAChNC,IAAEA,IAAEoG,CAAF,IAAKjI,MAAI,CAAJ,GAAM4B,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAD8M;AAAA,YACxL5B,IAAEA,IAAEmI,EADoL;AAAA,YACjLtG,IAAEA,IAAEqG,EAAF,IAAMlI,MAAI,CAAJ,GAAMmI,OAAK,CAAX,GAAa,CAAb,GAAe,CAArB,CAD+K;AAAA,YACvJnI,IAAEA,IAAEF,CADmJ;AAAA,YACjJ+B,IAAEA,IAAE3B,CAAF,IAAKF,MAAI,CAAJ,GAAMF,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAD+I;AAAA,YACzHA,IAAEkE,IAAEgC,CADqH;AAAA,YACnHlE,IAAElB,IAAEkB,CAAF,IAAKhC,MAAI,CAAJ,GAAMkE,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADiH;AAAA,YAC3F+D,IAAEF,CADyF;AAAA,YACvFG,IAAEF,CADqF;AAAA,YACnFD,IAAEF,CADiF;AAAA,YAC/EG,IAAEF,CAD6E;AAAA,YAC3ED,IAAEtH,CADyE;AAAA,YACvEuH,IAAEtI,CADqE;AAAA,YACnEA,IAAEoI,IAAE1H,CAAF,GAAI,CAD6D;AAAA,YAC3DK,IAAEoH,IAAE5F,CAAF,IAAKvC,MAAI,CAAJ,GAAMoI,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,IAAsB,CADmC;AAAA,YACjCD,IAAEF,CAD+B;AAAA,YAC7BG,IAAEF,CAD2B;AAAA,YACzBD,IAAED,CADuB;AAAA,YACrBE,IAAE3D,CADmB;AAAA,YACjByD,IAAEhH,CADe;AAAA,YACbuD,IAAExE,CADW;AAAA,YACTA,IAAEW,IAAEF,CAAF,GAAI,CADG;AAAA,YACDQ,IAAEuB,IAAEC,CAAF,IAAKzC,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,IAAsB,CADvB;AACyB,WAAEmG,EAAEf,GAAF,GAAMmB,IAAElH,CAAV,CAAY8G,EAAEhB,IAAF,GAAOvB,IAAEtD,CAAF,IAAKiG,MAAI,CAAJ,GAAMlH,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6BoH,IAAE1G,EAAEqF,GAAF,GAAMqB,IAAE5C,CAAV,CAAY9D,EAAEoF,IAAF,GAAOqB,IAAEc,CAAF,IAAKb,MAAI,CAAJ,GAAM5C,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6B8C,IAAEhG,EAAEyE,GAAF,GAAMuB,IAAEa,CAAV,CAAY7G,EAAEwE,IAAF,GAAOuB,IAAEa,CAAF,IAAKZ,MAAI,CAAJ,GAAMa,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6BX,IAAE7E,EAAEoD,GAAF,GAAMyB,IAAEa,CAAV,CAAY1F,EAAEmD,IAAF,GAAOyB,IAAEa,CAAF,IAAKZ,MAAI,CAAJ,GAAMa,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6BX,IAAEX,EAAEhB,GAAF,GAAM2B,IAAEzH,CAAV,CAAY8G,EAAEjB,IAAF,GAAO2B,IAAEzG,CAAF,IAAK0G,MAAI,CAAJ,GAAMzH,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6B2H,IAAEZ,EAAEjB,GAAF,GAAM6B,IAAEW,CAAV,CAAYvB,EAAElB,IAAF,GAAO6B,KAAGW,CAAH,IAAMV,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAApB,CAAP,CAA8BT,IAAEb,EAAElB,GAAF,GAAM+B,IAAEW,CAAV;AACzexB,QAAEnB,IAAF,GAAO+B,KAAGW,CAAH,IAAMV,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAApB,CAAP,CAA8BT,IAAE9H,EAAE6F,GAAF,GAAMiC,IAAEW,CAAV,CAAYzI,EAAE4F,IAAF,GAAOiC,KAAGW,CAAH,IAAMV,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAApB,CAAP;AAA8B,KAJ8D,EAI7DrD,aAAY,uBAAU;AAAC,UAAIpE,IAAE,KAAKiD,KAAX;AAAA,UAAiB/D,IAAEc,EAAEiB,KAArB;AAAA,UAA2BjC,IAAE,IAAE,KAAKkE,WAApC;AAAA,UAAgD1D,IAAE,IAAEQ,EAAEkB,QAAtD,CAA+DhC,EAAEM,MAAI,CAAN,KAAU,OAAK,KAAGA,IAAE,EAApB,CAAuBN,EAAE,CAACM,IAAE,GAAF,KAAQ,EAAR,IAAY,CAAb,IAAgB,EAAlB,IAAsBiF,KAAKc,KAAL,CAAWvG,IAAE,UAAb,CAAtB,CAA+CE,EAAE,CAACM,IAAE,GAAF,KAAQ,EAAR,IAAY,CAAb,IAAgB,EAAlB,IAAsBR,CAAtB,CAAwBgB,EAAEkB,QAAF,GAAW,IAAEhC,EAAEW,MAAf,CAAsB,KAAKuD,QAAL,GAAgB,OAAO,KAAKkC,KAAL,CAAWR,KAAX,EAAP;AAA0B,KAJvL,EAIwL/D,OAAM,iBAAU;AAAC,UAAIf,IAAEyB,EAAEV,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyB3B,EAAEsF,KAAF,GAAQ,KAAKA,KAAL,CAAWvE,KAAX,EAAR,CAA2B,OAAOf,CAAP;AAAS,KAJtQ,EAIuQuD,WAAU,EAJjR,EAAT,CAAX,CAI0SnD,EAAEuF,MAAF,GAASlE,EAAE4C,aAAF,CAAgB7E,CAAhB,CAAT,CAA4BY,EAAEyH,UAAF,GAAapG,EAAE6C,iBAAF,CAAoB9E,CAApB,CAAb;AAAoC,CAR5d;;AAUA;;;;;;AAMA,CAAC,YAAU;AAAC,MAAIC,IAAEQ,QAAN;AAAA,MAAeD,IAAEP,EAAEiF,GAAnB;AAAA,MAAuBnF,IAAES,EAAE2E,IAA3B;AAAA,MAAgCnF,IAAEQ,EAAEgB,SAApC;AAAA,MAA8ChB,IAAEP,EAAE+E,IAAlD;AAAA,MAAuDtF,IAAEc,EAAE2F,MAA3D;AAAA,MAAkE3F,IAAEA,EAAE8H,MAAF,GAAS5I,EAAEL,MAAF,CAAS,EAACoF,UAAS,oBAAU;AAAC,WAAKqB,KAAL,GAAW,IAAI9F,EAAEiB,IAAN,CAAW,CAAC,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAD,EAAmC,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAAnC,EAAoE,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAApE,EAAqG,IAAIlB,EAAEkB,IAAN,CAAW,SAAX,EAAqB,UAArB,CAArG,EAAsI,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAtI,EAAwK,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAxK,EAA0M,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAA1M,EAA4O,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAA5O,CAAX,CAAX;AAAsS,KAA3T,EAA4T2D,aAAY,uBAAU;AAAC,UAAIpE,IAAEd,EAAEkF,WAAF,CAAczC,IAAd,CAAmB,IAAnB,CAAN,CAA+B3B,EAAEkB,QAAF,IAAY,EAAZ,CAAe,OAAOlB,CAAP;AAAS,KAA1Y,EAAT,CAA7E,CAAmeP,EAAEqI,MAAF,GAC/e5I,EAAEmF,aAAF,CAAgBrE,CAAhB,CAD+e,CAC5dP,EAAEsI,UAAF,GAAa7I,EAAEoF,iBAAF,CAAoBtE,CAApB,CAAb;AAAoC,CADvD;;AAGA;;AAEA,IAAIgI,SAAO,kEAAX,CAA8E,IAAIC,SAAO,GAAX,CAAe,SAASC,OAAT,CAAiBhJ,CAAjB,EAAmB;AAAC,MAAIK,CAAJ,CAAM,IAAIC,CAAJ,CAAM,IAAIQ,IAAE,EAAN,CAAS,KAAIT,IAAE,CAAN,EAAQA,IAAE,CAAF,IAAKL,EAAEW,MAAf,EAAsBN,KAAG,CAAzB,EAA2B;AAACC,QAAE4C,SAASlD,EAAEiJ,SAAF,CAAY5I,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAF,CAAkCS,KAAGgI,OAAO/C,MAAP,CAAczF,KAAG,CAAjB,IAAoBwI,OAAO/C,MAAP,CAAczF,IAAE,EAAhB,CAAvB;AAA2C,OAAGD,IAAE,CAAF,IAAKL,EAAEW,MAAV,EAAiB;AAACL,QAAE4C,SAASlD,EAAEiJ,SAAF,CAAY5I,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAF,CAAkCS,KAAGgI,OAAO/C,MAAP,CAAczF,KAAG,CAAjB,CAAH;AAAuB,GAA3E,MAA+E;AAAC,QAAGD,IAAE,CAAF,IAAKL,EAAEW,MAAV,EAAiB;AAACL,UAAE4C,SAASlD,EAAEiJ,SAAF,CAAY5I,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAF,CAAkCS,KAAGgI,OAAO/C,MAAP,CAAczF,KAAG,CAAjB,IAAoBwI,OAAO/C,MAAP,CAAc,CAACzF,IAAE,CAAH,KAAO,CAArB,CAAvB;AAA+C;AAAC,OAAGyI,MAAH,EAAU;AAAC,WAAM,CAACjI,EAAEH,MAAF,GAAS,CAAV,IAAa,CAAnB,EAAqB;AAACG,WAAGiI,MAAH;AAAU;AAAC,UAAOjI,CAAP;AAAS,UAASoI,QAAT,CAAkBpJ,CAAlB,EAAoB;AAAC,MAAIE,IAAE,EAAN,CAAS,IAAIM,CAAJ,CAAM,IAAID,IAAE,CAAN,CAAQ,IAAIE,CAAJ,CAAM,IAAIO,CAAJ,CAAM,KAAIR,IAAE,CAAN,EAAQA,IAAER,EAAEa,MAAZ,EAAmB,EAAEL,CAArB,EAAuB;AAAC,QAAGR,EAAEiG,MAAF,CAASzF,CAAT,KAAayI,MAAhB,EAAuB;AAAC;AAAM,SAAED,OAAO9C,OAAP,CAAelG,EAAEiG,MAAF,CAASzF,CAAT,CAAf,CAAF,CAA8B,IAAGQ,IAAE,CAAL,EAAO;AAAC;AAAS,SAAGT,KAAG,CAAN,EAAQ;AAACL,WAAGmJ,SAASrI,KAAG,CAAZ,CAAH,CAAkBP,IAAEO,IAAE,CAAJ,CAAMT,IAAE,CAAF;AAAI,KAArC,MAAyC;AAAC,UAAGA,KAAG,CAAN,EAAQ;AAACL,aAAGmJ,SAAU5I,KAAG,CAAJ,GAAQO,KAAG,CAApB,CAAH,CAA2BP,IAAEO,IAAE,EAAJ,CAAOT,IAAE,CAAF;AAAI,OAA/C,MAAmD;AAAC,YAAGA,KAAG,CAAN,EAAQ;AAACL,eAAGmJ,SAAS5I,CAAT,CAAH,CAAeP,KAAGmJ,SAASrI,KAAG,CAAZ,CAAH,CAAkBP,IAAEO,IAAE,CAAJ,CAAMT,IAAE,CAAF;AAAI,SAApD,MAAwD;AAACL,eAAGmJ,SAAU5I,KAAG,CAAJ,GAAQO,KAAG,CAApB,CAAH,CAA2Bd,KAAGmJ,SAASrI,IAAE,EAAX,CAAH,CAAkBT,IAAE,CAAF;AAAI;AAAC;AAAC;AAAC,OAAGA,KAAG,CAAN,EAAQ;AAACL,SAAGmJ,SAAS5I,KAAG,CAAZ,CAAH;AAAkB,UAAOP,CAAP;AAAS,UAASoJ,OAAT,CAAiB9I,CAAjB,EAAmB;AAAC,MAAIN,IAAEkJ,SAAS5I,CAAT,CAAN,CAAkB,IAAIC,CAAJ,CAAM,IAAIF,IAAE,IAAIgJ,KAAJ,EAAN,CAAkB,KAAI9I,IAAE,CAAN,EAAQ,IAAEA,CAAF,GAAIP,EAAEW,MAAd,EAAqB,EAAEJ,CAAvB,EAAyB;AAACF,MAAEE,CAAF,IAAK2C,SAASlD,EAAEiJ,SAAF,CAAY,IAAE1I,CAAd,EAAgB,IAAEA,CAAF,GAAI,CAApB,CAAT,EAAgC,EAAhC,CAAL;AAAyC,UAAOF,CAAP;AAAS;AAC9+B;;AAEA,IAAIiJ,KAAJ,CAAU,IAAIC,SAAO,eAAX,CAA2B,IAAIC,OAAM,CAACD,SAAO,QAAR,KAAmB,QAA7B,CAAuC,SAASE,UAAT,CAAoBnJ,CAApB,EAAsBN,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,MAAGQ,KAAG,IAAN,EAAW;AAAC,QAAG,YAAU,OAAOA,CAApB,EAAsB;AAAC,WAAKoJ,UAAL,CAAgBpJ,CAAhB,EAAkBN,CAAlB,EAAoBF,CAApB;AAAuB,KAA9C,MAAkD;AAAC,UAAGE,KAAG,IAAH,IAAS,YAAU,OAAOM,CAA7B,EAA+B;AAAC,aAAKqJ,UAAL,CAAgBrJ,CAAhB,EAAkB,GAAlB;AAAuB,OAAvD,MAA2D;AAAC,aAAKqJ,UAAL,CAAgBrJ,CAAhB,EAAkBN,CAAlB;AAAqB;AAAC;AAAC;AAAC,UAAS4J,GAAT,GAAc;AAAC,SAAO,IAAIH,UAAJ,CAAe,IAAf,CAAP;AAA4B,UAASI,GAAT,CAAa/J,CAAb,EAAegB,CAAf,EAAiBT,CAAjB,EAAmBC,CAAnB,EAAqBT,CAArB,EAAuBD,CAAvB,EAAyB;AAAC,SAAM,EAAEA,CAAF,IAAK,CAAX,EAAa;AAAC,QAAII,IAAEc,IAAE,KAAKhB,GAAL,CAAF,GAAYO,EAAEC,CAAF,CAAZ,GAAiBT,CAAvB,CAAyBA,IAAE0F,KAAKc,KAAL,CAAWrG,IAAE,QAAb,CAAF,CAAyBK,EAAEC,GAAF,IAAON,IAAE,QAAT;AAAkB,UAAOH,CAAP;AAAS,UAASiK,GAAT,CAAahK,CAAb,EAAesC,CAAf,EAAiBG,CAAjB,EAAmBjC,CAAnB,EAAqBc,CAArB,EAAuBN,CAAvB,EAAyB;AAAC,MAAID,IAAEuB,IAAE,KAAR;AAAA,MAAcjB,IAAEiB,KAAG,EAAnB,CAAsB,OAAM,EAAEtB,CAAF,IAAK,CAAX,EAAa;AAAC,QAAId,IAAE,KAAKF,CAAL,IAAQ,KAAd,CAAoB,IAAIF,IAAE,KAAKE,GAAL,KAAW,EAAjB,CAAoB,IAAIO,IAAEc,IAAEnB,CAAF,GAAIJ,IAAEiB,CAAZ,CAAcb,IAAEa,IAAEb,CAAF,IAAK,CAACK,IAAE,KAAH,KAAW,EAAhB,IAAoBkC,EAAEjC,CAAF,CAApB,IAA0Bc,IAAE,UAA5B,CAAF,CAA0CA,IAAE,CAACpB,MAAI,EAAL,KAAUK,MAAI,EAAd,IAAkBc,IAAEvB,CAApB,IAAuBwB,MAAI,EAA3B,CAAF,CAAiCmB,EAAEjC,GAAF,IAAON,IAAE,UAAT;AAAoB,UAAOoB,CAAP;AAAS,UAAS2I,GAAT,CAAajK,CAAb,EAAesC,CAAf,EAAiBG,CAAjB,EAAmBjC,CAAnB,EAAqBc,CAArB,EAAuBN,CAAvB,EAAyB;AAAC,MAAID,IAAEuB,IAAE,KAAR;AAAA,MAAcjB,IAAEiB,KAAG,EAAnB,CAAsB,OAAM,EAAEtB,CAAF,IAAK,CAAX,EAAa;AAAC,QAAId,IAAE,KAAKF,CAAL,IAAQ,KAAd,CAAoB,IAAIF,IAAE,KAAKE,GAAL,KAAW,EAAjB,CAAoB,IAAIO,IAAEc,IAAEnB,CAAF,GAAIJ,IAAEiB,CAAZ,CAAcb,IAAEa,IAAEb,CAAF,IAAK,CAACK,IAAE,KAAH,KAAW,EAAhB,IAAoBkC,EAAEjC,CAAF,CAApB,GAAyBc,CAA3B,CAA6BA,IAAE,CAACpB,KAAG,EAAJ,KAASK,KAAG,EAAZ,IAAgBc,IAAEvB,CAApB,CAAsB2C,EAAEjC,GAAF,IAAON,IAAE,SAAT;AAAmB,UAAOoB,CAAP;AAAS,KAAGoI,QAAOnK,UAAU2K,OAAV,IAAmB,6BAA7B,EAA4D;AAACP,aAAWxJ,SAAX,CAAqBgK,EAArB,GAAwBH,GAAxB,CAA4BR,QAAM,EAAN;AAAS,CAAlG,MAAsG;AAAC,MAAGE,QAAOnK,UAAU2K,OAAV,IAAmB,UAA7B,EAAyC;AAACP,eAAWxJ,SAAX,CAAqBgK,EAArB,GAAwBJ,GAAxB,CAA4BP,QAAM,EAAN;AAAS,GAA/E,MAAmF;AAACG,eAAWxJ,SAAX,CAAqBgK,EAArB,GAAwBF,GAAxB,CAA4BT,QAAM,EAAN;AAAS;AAAC,YAAWrJ,SAAX,CAAqBiK,EAArB,GAAwBZ,KAAxB,CAA8BG,WAAWxJ,SAAX,CAAqBkK,EAArB,GAAyB,CAAC,KAAGb,KAAJ,IAAW,CAApC,CAAuCG,WAAWxJ,SAAX,CAAqBmK,EAArB,GAAyB,KAAGd,KAA5B,CAAmC,IAAIe,QAAM,EAAV,CAAaZ,WAAWxJ,SAAX,CAAqBqK,EAArB,GAAwB/E,KAAKW,GAAL,CAAS,CAAT,EAAWmE,KAAX,CAAxB,CAA0CZ,WAAWxJ,SAAX,CAAqBsK,EAArB,GAAwBF,QAAMf,KAA9B,CAAoCG,WAAWxJ,SAAX,CAAqBuK,EAArB,GAAwB,IAAElB,KAAF,GAAQe,KAAhC,CAAsC,IAAII,QAAM,sCAAV,CAAiD,IAAIC,QAAM,IAAIrB,KAAJ,EAAV,CAAsB,IAAIsB,EAAJ,EAAOC,EAAP,CAAUD,KAAG,IAAIpH,UAAJ,CAAe,CAAf,CAAH,CAAqB,KAAIqH,KAAG,CAAP,EAASA,MAAI,CAAb,EAAe,EAAEA,EAAjB,EAAoB;AAACF,QAAMC,IAAN,IAAYC,EAAZ;AAAe,MAAG,IAAIrH,UAAJ,CAAe,CAAf,CAAH,CAAqB,KAAIqH,KAAG,EAAP,EAAUA,KAAG,EAAb,EAAgB,EAAEA,EAAlB,EAAqB;AAACF,QAAMC,IAAN,IAAYC,EAAZ;AAAe,MAAG,IAAIrH,UAAJ,CAAe,CAAf,CAAH,CAAqB,KAAIqH,KAAG,EAAP,EAAUA,KAAG,EAAb,EAAgB,EAAEA,EAAlB,EAAqB;AAACF,QAAMC,IAAN,IAAYC,EAAZ;AAAe,UAASzB,QAAT,CAAkBrI,CAAlB,EAAoB;AAAC,SAAO2J,MAAM1E,MAAN,CAAajF,CAAb,CAAP;AAAuB,UAAS+J,KAAT,CAAexK,CAAf,EAAiBS,CAAjB,EAAmB;AAAC,MAAId,IAAE0K,MAAMrK,EAAEkD,UAAF,CAAazC,CAAb,CAAN,CAAN,CAA6B,OAAOd,KAAG,IAAJ,GAAU,CAAC,CAAX,GAAaA,CAAnB;AAAqB,UAAS8K,SAAT,CAAmBzK,CAAnB,EAAqB;AAAC,OAAI,IAAIS,IAAE,KAAKqB,CAAL,GAAO,CAAjB,EAAmBrB,KAAG,CAAtB,EAAwB,EAAEA,CAA1B,EAA4B;AAACT,MAAES,CAAF,IAAK,KAAKA,CAAL,CAAL;AAAa,KAAEqB,CAAF,GAAI,KAAKA,CAAT,CAAW9B,EAAEgC,CAAF,GAAI,KAAKA,CAAT;AAAW,UAAS0I,UAAT,CAAoBjK,CAApB,EAAsB;AAAC,OAAKqB,CAAL,GAAO,CAAP,CAAS,KAAKE,CAAL,GAAQvB,IAAE,CAAH,GAAM,CAAC,CAAP,GAAS,CAAhB,CAAkB,IAAGA,IAAE,CAAL,EAAO;AAAC,SAAK,CAAL,IAAQA,CAAR;AAAU,GAAlB,MAAsB;AAAC,QAAGA,IAAE,CAAC,CAAN,EAAQ;AAAC,WAAK,CAAL,IAAQA,IAAE,KAAKsJ,EAAf;AAAkB,KAA3B,MAA+B;AAAC,WAAKjI,CAAL,GAAO,CAAP;AAAS;AAAC;AAAC,UAAS6I,GAAT,CAAalK,CAAb,EAAe;AAAC,MAAIT,IAAEuJ,KAAN,CAAYvJ,EAAE4K,OAAF,CAAUnK,CAAV,EAAa,OAAOT,CAAP;AAAS,UAAS6K,aAAT,CAAuBrL,CAAvB,EAAyBU,CAAzB,EAA2B;AAAC,MAAID,CAAJ,CAAM,IAAGC,KAAG,EAAN,EAAS;AAACD,QAAE,CAAF;AAAI,GAAd,MAAkB;AAAC,QAAGC,KAAG,CAAN,EAAQ;AAACD,UAAE,CAAF;AAAI,KAAb,MAAiB;AAAC,UAAGC,KAAG,GAAN,EAAU;AAACD,YAAE,CAAF;AAAI,OAAf,MAAmB;AAAC,YAAGC,KAAG,CAAN,EAAQ;AAACD,cAAE,CAAF;AAAI,SAAb,MAAiB;AAAC,cAAGC,KAAG,EAAN,EAAS;AAACD,gBAAE,CAAF;AAAI,WAAd,MAAkB;AAAC,gBAAGC,KAAG,CAAN,EAAQ;AAACD,kBAAE,CAAF;AAAI,aAAb,MAAiB;AAAC,mBAAK6K,SAAL,CAAetL,CAAf,EAAiBU,CAAjB,EAAoB;AAAO;AAAC;AAAC;AAAC;AAAC;AAAC,QAAK4B,CAAL,GAAO,CAAP,CAAS,KAAKE,CAAL,GAAO,CAAP,CAAS,IAAIzC,IAAEC,EAAEc,MAAR;AAAA,MAAeX,IAAE,KAAjB;AAAA,MAAuBF,IAAE,CAAzB,CAA2B,OAAM,EAAEF,CAAF,IAAK,CAAX,EAAa;AAAC,QAAIkB,IAAGR,KAAG,CAAJ,GAAOT,EAAED,CAAF,IAAK,GAAZ,GAAgBiL,MAAMhL,CAAN,EAAQD,CAAR,CAAtB,CAAiC,IAAGkB,IAAE,CAAL,EAAO;AAAC,UAAGjB,EAAEkG,MAAF,CAASnG,CAAT,KAAa,GAAhB,EAAoB;AAACI,YAAE,IAAF;AAAO;AAAS,SAAE,KAAF,CAAQ,IAAGF,KAAG,CAAN,EAAQ;AAAC,WAAK,KAAKqC,CAAL,EAAL,IAAerB,CAAf;AAAiB,KAA1B,MAA8B;AAAC,UAAGhB,IAAEQ,CAAF,GAAI,KAAK4J,EAAZ,EAAe;AAAC,aAAK,KAAK/H,CAAL,GAAO,CAAZ,KAAgB,CAACrB,IAAG,CAAC,KAAI,KAAKoJ,EAAL,GAAQpK,CAAb,IAAiB,CAArB,KAA0BA,CAA1C,CAA4C,KAAK,KAAKqC,CAAL,EAAL,IAAgBrB,KAAI,KAAKoJ,EAAL,GAAQpK,CAA5B;AAAgC,OAA5F,MAAgG;AAAC,aAAK,KAAKqC,CAAL,GAAO,CAAZ,KAAgBrB,KAAGhB,CAAnB;AAAqB;AAAC,UAAGQ,CAAH,CAAK,IAAGR,KAAG,KAAKoK,EAAX,EAAc;AAACpK,WAAG,KAAKoK,EAAR;AAAW;AAAC,OAAG5J,KAAG,CAAH,IAAM,CAACT,EAAE,CAAF,IAAK,GAAN,KAAY,CAArB,EAAuB;AAAC,SAAKwC,CAAL,GAAO,CAAC,CAAR,CAAU,IAAGvC,IAAE,CAAL,EAAO;AAAC,WAAK,KAAKqC,CAAL,GAAO,CAAZ,KAAiB,CAAC,KAAI,KAAK+H,EAAL,GAAQpK,CAAb,IAAiB,CAAlB,IAAsBA,CAAtC;AAAwC;AAAC,QAAKwC,KAAL,GAAa,IAAGtC,CAAH,EAAK;AAACyJ,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsB,IAAtB,EAA2B,IAA3B;AAAiC;AAAC,UAASC,QAAT,GAAmB;AAAC,MAAIxK,IAAE,KAAKuB,CAAL,GAAO,KAAK8H,EAAlB,CAAqB,OAAM,KAAKhI,CAAL,GAAO,CAAP,IAAU,KAAK,KAAKA,CAAL,GAAO,CAAZ,KAAgBrB,CAAhC,EAAkC;AAAC,MAAE,KAAKqB,CAAP;AAAS;AAAC,UAASoJ,UAAT,CAAoBhL,CAApB,EAAsB;AAAC,MAAG,KAAK8B,CAAL,GAAO,CAAV,EAAY;AAAC,WAAM,MAAI,KAAKmJ,MAAL,GAAc5J,QAAd,CAAuBrB,CAAvB,CAAV;AAAoC,OAAID,CAAJ,CAAM,IAAGC,KAAG,EAAN,EAAS;AAACD,QAAE,CAAF;AAAI,GAAd,MAAkB;AAAC,QAAGC,KAAG,CAAN,EAAQ;AAACD,UAAE,CAAF;AAAI,KAAb,MAAiB;AAAC,UAAGC,KAAG,CAAN,EAAQ;AAACD,YAAE,CAAF;AAAI,OAAb,MAAiB;AAAC,YAAGC,KAAG,EAAN,EAAS;AAACD,cAAE,CAAF;AAAI,SAAd,MAAkB;AAAC,cAAGC,KAAG,CAAN,EAAQ;AAACD,gBAAE,CAAF;AAAI,WAAb,MAAiB;AAAC,mBAAO,KAAKmL,OAAL,CAAalL,CAAb,CAAP;AAAuB;AAAC;AAAC;AAAC;AAAC,OAAIX,IAAE,CAAC,KAAGU,CAAJ,IAAO,CAAb;AAAA,MAAeM,CAAf;AAAA,MAAiBE,IAAE,KAAnB;AAAA,MAAyBjB,IAAE,EAA3B;AAAA,MAA8BC,IAAE,KAAKqC,CAArC,CAAuC,IAAI1B,IAAE,KAAKyJ,EAAL,GAASpK,IAAE,KAAKoK,EAAR,GAAY5J,CAA1B,CAA4B,IAAGR,MAAI,CAAP,EAAS;AAAC,QAAGW,IAAE,KAAKyJ,EAAP,IAAW,CAACtJ,IAAE,KAAKd,CAAL,KAASW,CAAZ,IAAe,CAA7B,EAA+B;AAACK,UAAE,IAAF,CAAOjB,IAAEsJ,SAASvI,CAAT,CAAF;AAAc,YAAMd,KAAG,CAAT,EAAW;AAAC,UAAGW,IAAEH,CAAL,EAAO;AAACM,YAAE,CAAC,KAAKd,CAAL,IAAS,CAAC,KAAGW,CAAJ,IAAO,CAAjB,KAAuBH,IAAEG,CAA3B,CAA8BG,KAAG,KAAK,EAAEd,CAAP,MAAYW,KAAG,KAAKyJ,EAAL,GAAQ5J,CAAvB,CAAH;AAA6B,OAAnE,MAAuE;AAACM,YAAG,KAAKd,CAAL,MAAUW,KAAGH,CAAb,CAAD,GAAkBV,CAApB,CAAsB,IAAGa,KAAG,CAAN,EAAQ;AAACA,eAAG,KAAKyJ,EAAR,CAAW,EAAEpK,CAAF;AAAI;AAAC,WAAGc,IAAE,CAAL,EAAO;AAACE,YAAE,IAAF;AAAO,WAAGA,CAAH,EAAK;AAACjB,aAAGsJ,SAASvI,CAAT,CAAH;AAAe;AAAC;AAAC,UAAOE,IAAEjB,CAAF,GAAI,GAAX;AAAe,UAAS6L,QAAT,GAAmB;AAAC,MAAI5K,IAAE8I,KAAN,CAAYH,WAAW2B,IAAX,CAAgBC,KAAhB,CAAsB,IAAtB,EAA2BvK,CAA3B,EAA8B,OAAOA,CAAP;AAAS,UAAS6K,KAAT,GAAgB;AAAC,SAAO,KAAKtJ,CAAL,GAAO,CAAR,GAAW,KAAKmJ,MAAL,EAAX,GAAyB,IAA/B;AAAoC,UAASI,WAAT,CAAqBvL,CAArB,EAAuB;AAAC,MAAIL,IAAE,KAAKqC,CAAL,GAAOhC,EAAEgC,CAAf,CAAiB,IAAGrC,KAAG,CAAN,EAAQ;AAAC,WAAOA,CAAP;AAAS,OAAIO,IAAE,KAAK4B,CAAX,CAAanC,IAAEO,IAAEF,EAAE8B,CAAN,CAAQ,IAAGnC,KAAG,CAAN,EAAQ;AAAC,WAAO,KAAKqC,CAAL,GAAO,CAAR,GAAW,CAACrC,CAAZ,GAAcA,CAApB;AAAsB,UAAM,EAAEO,CAAF,IAAK,CAAX,EAAa;AAAC,QAAG,CAACP,IAAE,KAAKO,CAAL,IAAQF,EAAEE,CAAF,CAAX,KAAkB,CAArB,EAAuB;AAAC,aAAOP,CAAP;AAAS;AAAC,UAAO,CAAP;AAAS,UAAS6L,KAAT,CAAe/K,CAAf,EAAiB;AAAC,MAAIP,IAAE,CAAN;AAAA,MAAQF,CAAR,CAAU,IAAG,CAACA,IAAES,MAAI,EAAP,KAAY,CAAf,EAAiB;AAACA,QAAET,CAAF,CAAIE,KAAG,EAAH;AAAM,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,UAAOA,CAAP;AAAS,UAASuL,WAAT,GAAsB;AAAC,MAAG,KAAK3J,CAAL,IAAQ,CAAX,EAAa;AAAC,WAAO,CAAP;AAAS,UAAO,KAAK+H,EAAL,IAAS,KAAK/H,CAAL,GAAO,CAAhB,IAAmB0J,MAAM,KAAK,KAAK1J,CAAL,GAAO,CAAZ,IAAgB,KAAKE,CAAL,GAAO,KAAK8H,EAAlC,CAA1B;AAAiE,UAAS4B,YAAT,CAAsBxL,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,MAAIS,CAAJ,CAAM,KAAIA,IAAE,KAAKqB,CAAL,GAAO,CAAb,EAAerB,KAAG,CAAlB,EAAoB,EAAEA,CAAtB,EAAwB;AAACT,MAAES,IAAEP,CAAJ,IAAO,KAAKO,CAAL,CAAP;AAAe,QAAIA,IAAEP,IAAE,CAAR,EAAUO,KAAG,CAAb,EAAe,EAAEA,CAAjB,EAAmB;AAACT,MAAES,CAAF,IAAK,CAAL;AAAO,KAAEqB,CAAF,GAAI,KAAKA,CAAL,GAAO5B,CAAX,CAAaF,EAAEgC,CAAF,GAAI,KAAKA,CAAT;AAAW,UAAS2J,YAAT,CAAsBzL,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,OAAI,IAAIS,IAAEP,CAAV,EAAYO,IAAE,KAAKqB,CAAnB,EAAqB,EAAErB,CAAvB,EAAyB;AAACT,MAAES,IAAEP,CAAJ,IAAO,KAAKO,CAAL,CAAP;AAAe,KAAEqB,CAAF,GAAIoD,KAAKf,GAAL,CAAS,KAAKrC,CAAL,GAAO5B,CAAhB,EAAkB,CAAlB,CAAJ,CAAyBF,EAAEgC,CAAF,GAAI,KAAKA,CAAT;AAAW,UAAS4J,WAAT,CAAqBxL,CAArB,EAAuBH,CAAvB,EAAyB;AAAC,MAAID,IAAEI,IAAE,KAAKyJ,EAAb,CAAgB,IAAIpJ,IAAE,KAAKoJ,EAAL,GAAQ7J,CAAd,CAAgB,IAAIT,IAAE,CAAC,KAAGkB,CAAJ,IAAO,CAAb,CAAe,IAAIhB,IAAEyF,KAAKc,KAAL,CAAW5F,IAAE,KAAKyJ,EAAlB,CAAN;AAAA,MAA4BrK,IAAG,KAAKwC,CAAL,IAAQhC,CAAT,GAAY,KAAK8J,EAA/C;AAAA,MAAkDnK,CAAlD,CAAoD,KAAIA,IAAE,KAAKmC,CAAL,GAAO,CAAb,EAAenC,KAAG,CAAlB,EAAoB,EAAEA,CAAtB,EAAwB;AAACM,MAAEN,IAAEF,CAAF,GAAI,CAAN,IAAU,KAAKE,CAAL,KAASc,CAAV,GAAajB,CAAtB,CAAwBA,IAAE,CAAC,KAAKG,CAAL,IAAQJ,CAAT,KAAaS,CAAf;AAAiB,QAAIL,IAAEF,IAAE,CAAR,EAAUE,KAAG,CAAb,EAAe,EAAEA,CAAjB,EAAmB;AAACM,MAAEN,CAAF,IAAK,CAAL;AAAO,KAAEF,CAAF,IAAKD,CAAL,CAAOS,EAAE6B,CAAF,GAAI,KAAKA,CAAL,GAAOrC,CAAP,GAAS,CAAb,CAAeQ,EAAE+B,CAAF,GAAI,KAAKA,CAAT,CAAW/B,EAAEgC,KAAF;AAAU,UAAS4J,WAAT,CAAqBtM,CAArB,EAAuBI,CAAvB,EAAyB;AAACA,IAAEqC,CAAF,GAAI,KAAKA,CAAT,CAAW,IAAI/B,IAAEiF,KAAKc,KAAL,CAAWzG,IAAE,KAAKsK,EAAlB,CAAN,CAA4B,IAAG5J,KAAG,KAAK6B,CAAX,EAAa;AAACnC,MAAEmC,CAAF,GAAI,CAAJ,CAAM;AAAO,OAAI9B,IAAET,IAAE,KAAKsK,EAAb,CAAgB,IAAIpJ,IAAE,KAAKoJ,EAAL,GAAQ7J,CAAd,CAAgB,IAAIP,IAAE,CAAC,KAAGO,CAAJ,IAAO,CAAb,CAAeL,EAAE,CAAF,IAAK,KAAKM,CAAL,KAASD,CAAd,CAAgB,KAAI,IAAIE,IAAED,IAAE,CAAZ,EAAcC,IAAE,KAAK4B,CAArB,EAAuB,EAAE5B,CAAzB,EAA2B;AAACP,MAAEO,IAAED,CAAF,GAAI,CAAN,KAAU,CAAC,KAAKC,CAAL,IAAQT,CAAT,KAAagB,CAAvB,CAAyBd,EAAEO,IAAED,CAAJ,IAAO,KAAKC,CAAL,KAASF,CAAhB;AAAkB,OAAGA,IAAE,CAAL,EAAO;AAACL,MAAE,KAAKmC,CAAL,GAAO7B,CAAP,GAAS,CAAX,KAAe,CAAC,KAAK+B,CAAL,GAAOvC,CAAR,KAAYgB,CAA3B;AAA6B,KAAEqB,CAAF,GAAI,KAAKA,CAAL,GAAO7B,CAAX,CAAaN,EAAEsC,KAAF;AAAU,UAAS6J,QAAT,CAAkBnM,CAAlB,EAAoBF,CAApB,EAAsB;AAAC,MAAIQ,IAAE,CAAN;AAAA,MAAQV,IAAE,CAAV;AAAA,MAAYS,IAAEkF,KAAKb,GAAL,CAAS1E,EAAEmC,CAAX,EAAa,KAAKA,CAAlB,CAAd,CAAmC,OAAM7B,IAAED,CAAR,EAAU;AAACT,SAAG,KAAKU,CAAL,IAAQN,EAAEM,CAAF,CAAX,CAAgBR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,OAAGlK,EAAEmC,CAAF,GAAI,KAAKA,CAAZ,EAAc;AAACvC,SAAGI,EAAEqC,CAAL,CAAO,OAAM/B,IAAE,KAAK6B,CAAb,EAAe;AAACvC,WAAG,KAAKU,CAAL,CAAH,CAAWR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAG,KAAK7H,CAAR;AAAU,GAAxF,MAA4F;AAACzC,SAAG,KAAKyC,CAAR,CAAU,OAAM/B,IAAEN,EAAEmC,CAAV,EAAY;AAACvC,WAAGI,EAAEM,CAAF,CAAH,CAAQR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAGlK,EAAEqC,CAAL;AAAO,KAAEA,CAAF,GAAKzC,IAAE,CAAH,GAAM,CAAC,CAAP,GAAS,CAAb,CAAe,IAAGA,IAAE,CAAC,CAAN,EAAQ;AAACE,MAAEQ,GAAF,IAAO,KAAK8J,EAAL,GAAQxK,CAAf;AAAiB,GAA1B,MAA8B;AAAC,QAAGA,IAAE,CAAL,EAAO;AAACE,QAAEQ,GAAF,IAAOV,CAAP;AAAS;AAAC,KAAEuC,CAAF,GAAI7B,CAAJ,CAAMR,EAAEwC,KAAF;AAAU,UAAS8J,aAAT,CAAuB7L,CAAvB,EAAyBD,CAAzB,EAA2B;AAAC,MAAID,IAAE,KAAKgM,GAAL,EAAN;AAAA,MAAiBvM,IAAES,EAAE8L,GAAF,EAAnB,CAA2B,IAAIrM,IAAEK,EAAE8B,CAAR,CAAU7B,EAAE6B,CAAF,GAAInC,IAAEF,EAAEqC,CAAR,CAAU,OAAM,EAAEnC,CAAF,IAAK,CAAX,EAAa;AAACM,MAAEN,CAAF,IAAK,CAAL;AAAO,QAAIA,IAAE,CAAN,EAAQA,IAAEF,EAAEqC,CAAZ,EAAc,EAAEnC,CAAhB,EAAkB;AAACM,MAAEN,IAAEK,EAAE8B,CAAN,IAAS9B,EAAE4J,EAAF,CAAK,CAAL,EAAOnK,EAAEE,CAAF,CAAP,EAAYM,CAAZ,EAAcN,CAAd,EAAgB,CAAhB,EAAkBK,EAAE8B,CAApB,CAAT;AAAgC,KAAEE,CAAF,GAAI,CAAJ,CAAM/B,EAAEgC,KAAF,GAAU,IAAG,KAAKD,CAAL,IAAQ9B,EAAE8B,CAAb,EAAe;AAACoH,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsB/K,CAAtB,EAAwBA,CAAxB;AAA2B;AAAC,UAASgM,WAAT,CAAqBtM,CAArB,EAAuB;AAAC,MAAIc,IAAE,KAAKuL,GAAL,EAAN,CAAiB,IAAIhM,IAAEL,EAAEmC,CAAF,GAAI,IAAErB,EAAEqB,CAAd,CAAgB,OAAM,EAAE9B,CAAF,IAAK,CAAX,EAAa;AAACL,MAAEK,CAAF,IAAK,CAAL;AAAO,QAAIA,IAAE,CAAN,EAAQA,IAAES,EAAEqB,CAAF,GAAI,CAAd,EAAgB,EAAE9B,CAAlB,EAAoB;AAAC,QAAIC,IAAEQ,EAAEmJ,EAAF,CAAK5J,CAAL,EAAOS,EAAET,CAAF,CAAP,EAAYL,CAAZ,EAAc,IAAEK,CAAhB,EAAkB,CAAlB,EAAoB,CAApB,CAAN,CAA6B,IAAG,CAACL,EAAEK,IAAES,EAAEqB,CAAN,KAAUrB,EAAEmJ,EAAF,CAAK5J,IAAE,CAAP,EAAS,IAAES,EAAET,CAAF,CAAX,EAAgBL,CAAhB,EAAkB,IAAEK,CAAF,GAAI,CAAtB,EAAwBC,CAAxB,EAA0BQ,EAAEqB,CAAF,GAAI9B,CAAJ,GAAM,CAAhC,CAAX,KAAgDS,EAAEsJ,EAArD,EAAwD;AAACpK,QAAEK,IAAES,EAAEqB,CAAN,KAAUrB,EAAEsJ,EAAZ,CAAepK,EAAEK,IAAES,EAAEqB,CAAJ,GAAM,CAAR,IAAW,CAAX;AAAa;AAAC,OAAGnC,EAAEmC,CAAF,GAAI,CAAP,EAAS;AAACnC,MAAEA,EAAEmC,CAAF,GAAI,CAAN,KAAUrB,EAAEmJ,EAAF,CAAK5J,CAAL,EAAOS,EAAET,CAAF,CAAP,EAAYL,CAAZ,EAAc,IAAEK,CAAhB,EAAkB,CAAlB,EAAoB,CAApB,CAAV;AAAiC,KAAEgC,CAAF,GAAI,CAAJ,CAAMrC,EAAEsC,KAAF;AAAU,UAASiK,WAAT,CAAqBrL,CAArB,EAAuBrB,CAAvB,EAAyBD,CAAzB,EAA2B;AAAC,MAAIuE,IAAEjD,EAAEmL,GAAF,EAAN,CAAc,IAAGlI,EAAEhC,CAAF,IAAK,CAAR,EAAU;AAAC;AAAO,OAAItB,IAAE,KAAKwL,GAAL,EAAN,CAAiB,IAAGxL,EAAEsB,CAAF,GAAIgC,EAAEhC,CAAT,EAAW;AAAC,QAAGtC,KAAG,IAAN,EAAW;AAACA,QAAEoL,OAAF,CAAU,CAAV;AAAa,SAAGrL,KAAG,IAAN,EAAW;AAAC,WAAK4M,MAAL,CAAY5M,CAAZ;AAAe;AAAO,OAAGA,KAAG,IAAN,EAAW;AAACA,QAAEgK,KAAF;AAAQ,OAAI5J,IAAE4J,KAAN;AAAA,MAAY9I,IAAE,KAAKuB,CAAnB;AAAA,MAAqBzB,IAAEM,EAAEmB,CAAzB,CAA2B,IAAIiC,IAAE,KAAK4F,EAAL,GAAQ2B,MAAM1H,EAAEA,EAAEhC,CAAF,GAAI,CAAN,CAAN,CAAd,CAA8B,IAAGmC,IAAE,CAAL,EAAO;AAACH,MAAEsI,QAAF,CAAWnI,CAAX,EAAatE,CAAb,EAAgBa,EAAE4L,QAAF,CAAWnI,CAAX,EAAa1E,CAAb;AAAgB,GAAxC,MAA4C;AAACuE,MAAEqI,MAAF,CAASxM,CAAT,EAAYa,EAAE2L,MAAF,CAAS5M,CAAT;AAAY,OAAIuB,IAAEnB,EAAEmC,CAAR,CAAU,IAAI9B,IAAEL,EAAEmB,IAAE,CAAJ,CAAN,CAAa,IAAGd,KAAG,CAAN,EAAQ;AAAC;AAAO,OAAIe,IAAEf,KAAG,KAAG,KAAKkK,EAAX,KAAiBpJ,IAAE,CAAH,GAAMnB,EAAEmB,IAAE,CAAJ,KAAQ,KAAKqJ,EAAnB,GAAsB,CAAtC,CAAN,CAA+C,IAAI1C,IAAE,KAAKwC,EAAL,GAAQlJ,CAAd;AAAA,MAAgByG,IAAE,CAAC,KAAG,KAAK0C,EAAT,IAAanJ,CAA/B;AAAA,MAAiCgD,IAAE,KAAG,KAAKoG,EAA3C,CAA8C,IAAIjG,IAAE3E,EAAEuC,CAAR;AAAA,MAAUE,IAAEkC,IAAEpD,CAAd;AAAA,MAAgBrB,IAAGD,KAAG,IAAJ,GAAU+J,KAAV,GAAgB/J,CAAlC,CAAoCG,EAAE0M,SAAF,CAAYrK,CAAZ,EAAcvC,CAAd,EAAiB,IAAGF,EAAE+M,SAAF,CAAY7M,CAAZ,KAAgB,CAAnB,EAAqB;AAACF,MAAEA,EAAEuC,CAAF,EAAF,IAAS,CAAT,CAAWvC,EAAEyL,KAAF,CAAQvL,CAAR,EAAUF,CAAV;AAAa,cAAWgN,GAAX,CAAeF,SAAf,CAAyBvL,CAAzB,EAA2BrB,CAA3B,EAA8BA,EAAEuL,KAAF,CAAQrL,CAAR,EAAUA,CAAV,EAAa,OAAMA,EAAEmC,CAAF,GAAIhB,CAAV,EAAY;AAACnB,MAAEA,EAAEmC,CAAF,EAAF,IAAS,CAAT;AAAW,UAAM,EAAEE,CAAF,IAAK,CAAX,EAAa;AAAC,QAAI9B,IAAGX,EAAE,EAAE2E,CAAJ,KAAQlE,CAAT,GAAY,KAAK8J,EAAjB,GAAoB5E,KAAKc,KAAL,CAAWzG,EAAE2E,CAAF,IAAKuD,CAAL,GAAO,CAAClI,EAAE2E,IAAE,CAAJ,IAAOH,CAAR,IAAWyD,CAA7B,CAA1B,CAA0D,IAAG,CAACjI,EAAE2E,CAAF,KAAMvE,EAAEiK,EAAF,CAAK,CAAL,EAAO1J,CAAP,EAASX,CAAT,EAAWyC,CAAX,EAAa,CAAb,EAAelB,CAAf,CAAP,IAA0BZ,CAA7B,EAA+B;AAACP,QAAE0M,SAAF,CAAYrK,CAAZ,EAAcvC,CAAd,EAAiBF,EAAEyL,KAAF,CAAQvL,CAAR,EAAUF,CAAV,EAAa,OAAMA,EAAE2E,CAAF,IAAK,EAAEhE,CAAb,EAAe;AAACX,UAAEyL,KAAF,CAAQvL,CAAR,EAAUF,CAAV;AAAa;AAAC;AAAC,OAAGC,KAAG,IAAN,EAAW;AAACD,MAAEiN,SAAF,CAAY1L,CAAZ,EAActB,CAAd,EAAiB,IAAGiB,KAAGF,CAAN,EAAQ;AAAC6I,iBAAW2B,IAAX,CAAgBC,KAAhB,CAAsBxL,CAAtB,EAAwBA,CAAxB;AAA2B;AAAC,KAAEsC,CAAF,GAAIhB,CAAJ,CAAMvB,EAAE0C,KAAF,GAAU,IAAGgC,IAAE,CAAL,EAAO;AAAC1E,MAAEkN,QAAF,CAAWxI,CAAX,EAAa1E,CAAb;AAAgB,OAAGkB,IAAE,CAAL,EAAO;AAAC2I,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsBzL,CAAtB,EAAwBA,CAAxB;AAA2B;AAAC,UAASmN,KAAT,CAAe1M,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKyC,GAAL,GAAWW,QAAX,CAAoB3M,CAApB,EAAsB,IAAtB,EAA2BE,CAA3B,EAA8B,IAAG,KAAK8B,CAAL,GAAO,CAAP,IAAU9B,EAAEoM,SAAF,CAAYlD,WAAW2B,IAAvB,IAA6B,CAA1C,EAA4C;AAAC/K,MAAEgL,KAAF,CAAQ9K,CAAR,EAAUA,CAAV;AAAa,UAAOA,CAAP;AAAS,UAAS0M,OAAT,CAAiBnM,CAAjB,EAAmB;AAAC,OAAK+B,CAAL,GAAO/B,CAAP;AAAS,UAASoM,QAAT,CAAkBpM,CAAlB,EAAoB;AAAC,MAAGA,EAAEuB,CAAF,GAAI,CAAJ,IAAOvB,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,KAAqB,CAA/B,EAAiC;AAAC,WAAO/B,EAAEqM,GAAF,CAAM,KAAKtK,CAAX,CAAP;AAAqB,GAAvD,MAA2D;AAAC,WAAO/B,CAAP;AAAS;AAAC,UAASsM,OAAT,CAAiBtM,CAAjB,EAAmB;AAAC,SAAOA,CAAP;AAAS,UAASuM,OAAT,CAAiBvM,CAAjB,EAAmB;AAACA,IAAEkM,QAAF,CAAW,KAAKnK,CAAhB,EAAkB,IAAlB,EAAuB/B,CAAvB;AAA0B,UAASwM,MAAT,CAAgBxM,CAAhB,EAAkBP,CAAlB,EAAoBF,CAApB,EAAsB;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf,EAAkB,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,UAASoN,MAAT,CAAgB3M,CAAhB,EAAkBT,CAAlB,EAAoB;AAACS,IAAE4M,QAAF,CAAWrN,CAAX,EAAc,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,SAAQJ,SAAR,CAAkB0N,OAAlB,GAA0BT,QAA1B,CAAmCD,QAAQhN,SAAR,CAAkB2N,MAAlB,GAAyBR,OAAzB,CAAiCH,QAAQhN,SAAR,CAAkBuN,MAAlB,GAAyBH,OAAzB,CAAiCJ,QAAQhN,SAAR,CAAkB4N,KAAlB,GAAwBP,MAAxB,CAA+BL,QAAQhN,SAAR,CAAkB6N,KAAlB,GAAwBL,MAAxB,CAA+B,SAASM,WAAT,GAAsB;AAAC,MAAG,KAAK5L,CAAL,GAAO,CAAV,EAAY;AAAC,WAAO,CAAP;AAAS,OAAIrB,IAAE,KAAK,CAAL,CAAN,CAAc,IAAG,CAACA,IAAE,CAAH,KAAO,CAAV,EAAY;AAAC,WAAO,CAAP;AAAS,OAAIT,IAAES,IAAE,CAAR,CAAUT,IAAGA,KAAG,IAAE,CAACS,IAAE,EAAH,IAAOT,CAAZ,CAAD,GAAiB,EAAnB,CAAsBA,IAAGA,KAAG,IAAE,CAACS,IAAE,GAAH,IAAQT,CAAb,CAAD,GAAkB,GAApB,CAAwBA,IAAGA,KAAG,KAAI,CAACS,IAAE,KAAH,IAAUT,CAAX,GAAc,KAAjB,CAAH,CAAD,GAA8B,KAAhC,CAAsCA,IAAGA,KAAG,IAAES,IAAET,CAAF,GAAI,KAAK+J,EAAd,CAAD,GAAoB,KAAKA,EAA3B,CAA8B,OAAO/J,IAAE,CAAH,GAAM,KAAK+J,EAAL,GAAQ/J,CAAd,GAAgB,CAACA,CAAvB;AAAyB,UAAS2N,UAAT,CAAoBlN,CAApB,EAAsB;AAAC,OAAK+B,CAAL,GAAO/B,CAAP,CAAS,KAAKmN,EAAL,GAAQnN,EAAEoN,QAAF,EAAR,CAAqB,KAAKC,GAAL,GAAS,KAAKF,EAAL,GAAQ,KAAjB,CAAuB,KAAKG,GAAL,GAAS,KAAKH,EAAL,IAAS,EAAlB,CAAqB,KAAKI,EAAL,GAAQ,CAAC,KAAIvN,EAAEoJ,EAAF,GAAK,EAAV,IAAe,CAAvB,CAAyB,KAAKoE,GAAL,GAAS,IAAExN,EAAEqB,CAAb;AAAe,UAASoM,WAAT,CAAqBzN,CAArB,EAAuB;AAAC,MAAIT,IAAEuJ,KAAN,CAAY9I,EAAEuL,GAAF,GAAQK,SAAR,CAAkB,KAAK7J,CAAL,CAAOV,CAAzB,EAA2B9B,CAA3B,EAA8BA,EAAE2M,QAAF,CAAW,KAAKnK,CAAhB,EAAkB,IAAlB,EAAuBxC,CAAvB,EAA0B,IAAGS,EAAEuB,CAAF,GAAI,CAAJ,IAAOhC,EAAEsM,SAAF,CAAYlD,WAAW2B,IAAvB,IAA6B,CAAvC,EAAyC;AAAC,SAAKvI,CAAL,CAAOwI,KAAP,CAAahL,CAAb,EAAeA,CAAf;AAAkB,UAAOA,CAAP;AAAS,UAASmO,UAAT,CAAoB1N,CAApB,EAAsB;AAAC,MAAIT,IAAEuJ,KAAN,CAAY9I,EAAE0L,MAAF,CAASnM,CAAT,EAAY,KAAKmN,MAAL,CAAYnN,CAAZ,EAAe,OAAOA,CAAP;AAAS,UAASoO,UAAT,CAAoB3N,CAApB,EAAsB;AAAC,SAAMA,EAAEqB,CAAF,IAAK,KAAKmM,GAAhB,EAAoB;AAACxN,MAAEA,EAAEqB,CAAF,EAAF,IAAS,CAAT;AAAW,QAAI,IAAI5B,IAAE,CAAV,EAAYA,IAAE,KAAKsC,CAAL,CAAOV,CAArB,EAAuB,EAAE5B,CAAzB,EAA2B;AAAC,QAAIF,IAAES,EAAEP,CAAF,IAAK,KAAX,CAAiB,IAAIP,IAAGK,IAAE,KAAK8N,GAAP,IAAY,CAAE9N,IAAE,KAAK+N,GAAP,GAAW,CAACtN,EAAEP,CAAF,KAAM,EAAP,IAAW,KAAK4N,GAA5B,GAAiC,KAAKE,EAAvC,KAA4C,EAAxD,CAAD,GAA8DvN,EAAEqJ,EAAtE,CAAyE9J,IAAEE,IAAE,KAAKsC,CAAL,CAAOV,CAAX,CAAarB,EAAET,CAAF,KAAM,KAAKwC,CAAL,CAAOoH,EAAP,CAAU,CAAV,EAAYjK,CAAZ,EAAcc,CAAd,EAAgBP,CAAhB,EAAkB,CAAlB,EAAoB,KAAKsC,CAAL,CAAOV,CAA3B,CAAN,CAAoC,OAAMrB,EAAET,CAAF,KAAMS,EAAEsJ,EAAd,EAAiB;AAACtJ,QAAET,CAAF,KAAMS,EAAEsJ,EAAR,CAAWtJ,EAAE,EAAET,CAAJ;AAAS;AAAC,KAAEiC,KAAF,GAAUxB,EAAE+L,SAAF,CAAY,KAAKhK,CAAL,CAAOV,CAAnB,EAAqBrB,CAArB,EAAwB,IAAGA,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,KAAqB,CAAxB,EAA0B;AAAC/B,MAAEuK,KAAF,CAAQ,KAAKxI,CAAb,EAAe/B,CAAf;AAAkB;AAAC,UAAS4N,SAAT,CAAmB5N,CAAnB,EAAqBT,CAArB,EAAuB;AAACS,IAAE4M,QAAF,CAAWrN,CAAX,EAAc,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,UAASsO,SAAT,CAAmB7N,CAAnB,EAAqBP,CAArB,EAAuBF,CAAvB,EAAyB;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf,EAAkB,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,YAAWJ,SAAX,CAAqB0N,OAArB,GAA6BY,WAA7B,CAAyCP,WAAW/N,SAAX,CAAqB2N,MAArB,GAA4BY,UAA5B,CAAuCR,WAAW/N,SAAX,CAAqBuN,MAArB,GAA4BiB,UAA5B,CAAuCT,WAAW/N,SAAX,CAAqB4N,KAArB,GAA2Bc,SAA3B,CAAqCX,WAAW/N,SAAX,CAAqB6N,KAArB,GAA2BY,SAA3B,CAAqC,SAASE,SAAT,GAAoB;AAAC,SAAM,CAAE,KAAKzM,CAAL,GAAO,CAAR,GAAY,KAAK,CAAL,IAAQ,CAApB,GAAuB,KAAKE,CAA7B,KAAiC,CAAvC;AAAyC,UAASwM,MAAT,CAAgBhP,CAAhB,EAAkBY,CAAlB,EAAoB;AAAC,MAAGZ,IAAE,UAAF,IAAcA,IAAE,CAAnB,EAAqB;AAAC,WAAO4J,WAAWmD,GAAlB;AAAsB,OAAI9M,IAAE8J,KAAN;AAAA,MAAY9I,IAAE8I,KAAd;AAAA,MAAoB5J,IAAES,EAAEkN,OAAF,CAAU,IAAV,CAAtB;AAAA,MAAsCpN,IAAEsL,MAAMhM,CAAN,IAAS,CAAjD,CAAmDG,EAAEwM,MAAF,CAAS1M,CAAT,EAAY,OAAM,EAAES,CAAF,IAAK,CAAX,EAAa;AAACE,MAAEqN,KAAF,CAAQhO,CAAR,EAAUgB,CAAV,EAAa,IAAG,CAACjB,IAAG,KAAGU,CAAP,IAAW,CAAd,EAAgB;AAACE,QAAEoN,KAAF,CAAQ/M,CAAR,EAAUd,CAAV,EAAYF,CAAZ;AAAe,KAAhC,MAAoC;AAAC,UAAIO,IAAEP,CAAN,CAAQA,IAAEgB,CAAF,CAAIA,IAAET,CAAF;AAAI;AAAC,UAAOI,EAAEmN,MAAF,CAAS9N,CAAT,CAAP;AAAmB,UAASgP,WAAT,CAAqBzO,CAArB,EAAuBS,CAAvB,EAAyB;AAAC,MAAIP,CAAJ,CAAM,IAAGF,IAAE,GAAF,IAAOS,EAAEiO,MAAF,EAAV,EAAqB;AAACxO,QAAE,IAAI0M,OAAJ,CAAYnM,CAAZ,CAAF;AAAiB,GAAvC,MAA2C;AAACP,QAAE,IAAIyN,UAAJ,CAAelN,CAAf,CAAF;AAAoB,UAAO,KAAKkO,GAAL,CAAS3O,CAAT,EAAWE,CAAX,CAAP;AAAqB,YAAWN,SAAX,CAAqBuM,MAArB,GAA4B1B,SAA5B,CAAsCrB,WAAWxJ,SAAX,CAAqBgL,OAArB,GAA6BF,UAA7B,CAAwCtB,WAAWxJ,SAAX,CAAqB0J,UAArB,GAAgCuB,aAAhC,CAA8CzB,WAAWxJ,SAAX,CAAqBqC,KAArB,GAA2BgJ,QAA3B,CAAoC7B,WAAWxJ,SAAX,CAAqByM,SAArB,GAA+BX,YAA/B,CAA4CtC,WAAWxJ,SAAX,CAAqB4M,SAArB,GAA+Bb,YAA/B,CAA4CvC,WAAWxJ,SAAX,CAAqBwM,QAArB,GAA8BR,WAA9B,CAA0CxC,WAAWxJ,SAAX,CAAqB6M,QAArB,GAA8BZ,WAA9B,CAA0CzC,WAAWxJ,SAAX,CAAqBoL,KAArB,GAA2Bc,QAA3B,CAAoC1C,WAAWxJ,SAAX,CAAqBsN,UAArB,GAAgCnB,aAAhC,CAA8C3C,WAAWxJ,SAAX,CAAqByN,QAArB,GAA8BpB,WAA9B,CAA0C7C,WAAWxJ,SAAX,CAAqB+M,QAArB,GAA8BT,WAA9B,CAA0C9C,WAAWxJ,SAAX,CAAqBiO,QAArB,GAA8BH,WAA9B,CAA0CtE,WAAWxJ,SAAX,CAAqB8O,MAArB,GAA4BH,SAA5B,CAAsCnF,WAAWxJ,SAAX,CAAqB+O,GAArB,GAAyBH,MAAzB,CAAgCpF,WAAWxJ,SAAX,CAAqB2B,QAArB,GAA8B2J,UAA9B,CAAyC9B,WAAWxJ,SAAX,CAAqBuL,MAArB,GAA4BE,QAA5B,CAAqCjC,WAAWxJ,SAAX,CAAqBoM,GAArB,GAAyBV,KAAzB,CAA+BlC,WAAWxJ,SAAX,CAAqB0M,SAArB,GAA+Bf,WAA/B,CAA2CnC,WAAWxJ,SAAX,CAAqBgP,SAArB,GAA+BnD,WAA/B,CAA2CrC,WAAWxJ,SAAX,CAAqBkN,GAArB,GAAyBJ,KAAzB,CAA+BtD,WAAWxJ,SAAX,CAAqBiP,SAArB,GAA+BJ,WAA/B,CAA2CrF,WAAW2B,IAAX,GAAgBJ,IAAI,CAAJ,CAAhB,CAAuBvB,WAAWmD,GAAX,GAAe5B,IAAI,CAAJ,CAAf;AAClpS;;AAEA,SAASmE,OAAT,GAAkB;AAAC,MAAIrO,IAAE8I,KAAN,CAAY,KAAK4C,MAAL,CAAY1L,CAAZ,EAAe,OAAOA,CAAP;AAAS,UAASsO,UAAT,GAAqB;AAAC,MAAG,KAAK/M,CAAL,GAAO,CAAV,EAAY;AAAC,QAAG,KAAKF,CAAL,IAAQ,CAAX,EAAa;AAAC,aAAO,KAAK,CAAL,IAAQ,KAAKiI,EAApB;AAAuB,KAArC,MAAyC;AAAC,UAAG,KAAKjI,CAAL,IAAQ,CAAX,EAAa;AAAC,eAAO,CAAC,CAAR;AAAU;AAAC;AAAC,GAAjF,MAAqF;AAAC,QAAG,KAAKA,CAAL,IAAQ,CAAX,EAAa;AAAC,aAAO,KAAK,CAAL,CAAP;AAAe,KAA7B,MAAiC;AAAC,UAAG,KAAKA,CAAL,IAAQ,CAAX,EAAa;AAAC,eAAO,CAAP;AAAS;AAAC;AAAC,UAAO,CAAC,KAAK,CAAL,IAAS,CAAC,KAAI,KAAG,KAAK+H,EAAb,IAAkB,CAA5B,KAAiC,KAAKA,EAAvC,GAA2C,KAAK,CAAL,CAAjD;AAAyD,UAASmF,WAAT,GAAsB;AAAC,SAAO,KAAKlN,CAAL,IAAQ,CAAT,GAAY,KAAKE,CAAjB,GAAoB,KAAK,CAAL,KAAS,EAAV,IAAe,EAAxC;AAA2C,UAASiN,YAAT,GAAuB;AAAC,SAAO,KAAKnN,CAAL,IAAQ,CAAT,GAAY,KAAKE,CAAjB,GAAoB,KAAK,CAAL,KAAS,EAAV,IAAe,EAAxC;AAA2C,UAASkN,YAAT,CAAsBzO,CAAtB,EAAwB;AAAC,SAAOyE,KAAKc,KAAL,CAAWd,KAAKiK,GAAL,GAAS,KAAKtF,EAAd,GAAiB3E,KAAKkK,GAAL,CAAS3O,CAAT,CAA5B,CAAP;AAAgD,UAAS4O,QAAT,GAAmB;AAAC,MAAG,KAAKrN,CAAL,GAAO,CAAV,EAAY;AAAC,WAAO,CAAC,CAAR;AAAU,GAAvB,MAA2B;AAAC,QAAG,KAAKF,CAAL,IAAQ,CAAR,IAAY,KAAKA,CAAL,IAAQ,CAAR,IAAW,KAAK,CAAL,KAAS,CAAnC,EAAsC;AAAC,aAAO,CAAP;AAAS,KAAhD,MAAoD;AAAC,aAAO,CAAP;AAAS;AAAC;AAAC,UAASwN,UAAT,CAAoBpP,CAApB,EAAsB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAACA,QAAE,EAAF;AAAK,OAAG,KAAKqP,MAAL,MAAe,CAAf,IAAkBrP,IAAE,CAApB,IAAuBA,IAAE,EAA5B,EAA+B;AAAC,WAAM,GAAN;AAAU,OAAIT,IAAE,KAAK+P,SAAL,CAAetP,CAAf,CAAN,CAAwB,IAAID,IAAEiF,KAAKW,GAAL,CAAS3F,CAAT,EAAWT,CAAX,CAAN,CAAoB,IAAIY,IAAEsK,IAAI1K,CAAJ,CAAN;AAAA,MAAaG,IAAEmJ,KAAf;AAAA,MAAqB/J,IAAE+J,KAAvB;AAAA,MAA6BhK,IAAE,EAA/B,CAAkC,KAAKoN,QAAL,CAActM,CAAd,EAAgBD,CAAhB,EAAkBZ,CAAlB,EAAqB,OAAMY,EAAEmP,MAAF,KAAW,CAAjB,EAAmB;AAAChQ,QAAE,CAACU,IAAET,EAAEiQ,QAAF,EAAH,EAAiBlO,QAAjB,CAA0BrB,CAA1B,EAA6B4C,MAA7B,CAAoC,CAApC,IAAuCvD,CAAzC,CAA2Ca,EAAEuM,QAAF,CAAWtM,CAAX,EAAaD,CAAb,EAAeZ,CAAf;AAAkB,UAAOA,EAAEiQ,QAAF,GAAalO,QAAb,CAAsBrB,CAAtB,IAAyBX,CAAhC;AAAkC,UAASmQ,YAAT,CAAsBlN,CAAtB,EAAwBhD,CAAxB,EAA0B;AAAC,OAAKoL,OAAL,CAAa,CAAb,EAAgB,IAAGpL,KAAG,IAAN,EAAW;AAACA,QAAE,EAAF;AAAK,OAAIC,IAAE,KAAK+P,SAAL,CAAehQ,CAAf,CAAN,CAAwB,IAAID,IAAE2F,KAAKW,GAAL,CAASrG,CAAT,EAAWC,CAAX,CAAN;AAAA,MAAoBQ,IAAE,KAAtB;AAAA,MAA4BQ,IAAE,CAA9B;AAAA,MAAgCF,IAAE,CAAlC,CAAoC,KAAI,IAAIL,IAAE,CAAV,EAAYA,IAAEsC,EAAElC,MAAhB,EAAuB,EAAEJ,CAAzB,EAA2B;AAAC,QAAIM,IAAEgK,MAAMhI,CAAN,EAAQtC,CAAR,CAAN,CAAiB,IAAGM,IAAE,CAAL,EAAO;AAAC,UAAGgC,EAAEkD,MAAF,CAASxF,CAAT,KAAa,GAAb,IAAkB,KAAKqP,MAAL,MAAe,CAApC,EAAsC;AAACtP,YAAE,IAAF;AAAO;AAAS,SAAET,IAAEe,CAAF,GAAIC,CAAN,CAAQ,IAAG,EAAEC,CAAF,IAAKhB,CAAR,EAAU;AAAC,WAAKkQ,SAAL,CAAepQ,CAAf,EAAkB,KAAKqQ,UAAL,CAAgBrP,CAAhB,EAAkB,CAAlB,EAAqBE,IAAE,CAAF,CAAIF,IAAE,CAAF;AAAI;AAAC,OAAGE,IAAE,CAAL,EAAO;AAAC,SAAKkP,SAAL,CAAezK,KAAKW,GAAL,CAASrG,CAAT,EAAWiB,CAAX,CAAf,EAA8B,KAAKmP,UAAL,CAAgBrP,CAAhB,EAAkB,CAAlB;AAAqB,OAAGN,CAAH,EAAK;AAACmJ,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsB,IAAtB,EAA2B,IAA3B;AAAiC;AAAC,UAAS6E,aAAT,CAAuBpQ,CAAvB,EAAyBQ,CAAzB,EAA2BT,CAA3B,EAA6B;AAAC,MAAG,YAAU,OAAOS,CAApB,EAAsB;AAAC,QAAGR,IAAE,CAAL,EAAO;AAAC,WAAKmL,OAAL,CAAa,CAAb;AAAgB,KAAxB,MAA4B;AAAC,WAAKvB,UAAL,CAAgB5J,CAAhB,EAAkBD,CAAlB,EAAqB,IAAG,CAAC,KAAKsQ,OAAL,CAAarQ,IAAE,CAAf,CAAJ,EAAsB;AAAC,aAAKsQ,SAAL,CAAe3G,WAAWmD,GAAX,CAAeyD,SAAf,CAAyBvQ,IAAE,CAA3B,CAAf,EAA6CwQ,KAA7C,EAAmD,IAAnD;AAAyD,WAAG,KAAKvB,MAAL,EAAH,EAAiB;AAAC,aAAKkB,UAAL,CAAgB,CAAhB,EAAkB,CAAlB;AAAqB,cAAM,CAAC,KAAKM,eAAL,CAAqBjQ,CAArB,CAAP,EAA+B;AAAC,aAAK2P,UAAL,CAAgB,CAAhB,EAAkB,CAAlB,EAAqB,IAAG,KAAKhB,SAAL,KAAiBnP,CAApB,EAAsB;AAAC,eAAKuL,KAAL,CAAW5B,WAAWmD,GAAX,CAAeyD,SAAf,CAAyBvQ,IAAE,CAA3B,CAAX,EAAyC,IAAzC;AAA+C;AAAC;AAAC;AAAC,GAA9T,MAAkU;AAAC,QAAIE,IAAE,IAAIqJ,KAAJ,EAAN;AAAA,QAAkBzJ,IAAEE,IAAE,CAAtB,CAAwBE,EAAEW,MAAF,GAAS,CAACb,KAAG,CAAJ,IAAO,CAAhB,CAAkBQ,EAAEkQ,SAAF,CAAYxQ,CAAZ,EAAe,IAAGJ,IAAE,CAAL,EAAO;AAACI,QAAE,CAAF,KAAO,CAAC,KAAGJ,CAAJ,IAAO,CAAd;AAAiB,KAAzB,MAA6B;AAACI,QAAE,CAAF,IAAK,CAAL;AAAO,UAAK2J,UAAL,CAAgB3J,CAAhB,EAAkB,GAAlB;AAAuB;AAAC,UAASyQ,aAAT,GAAwB;AAAC,MAAIpQ,IAAE,KAAK8B,CAAX;AAAA,MAAa5B,IAAE,IAAI8I,KAAJ,EAAf,CAA2B9I,EAAE,CAAF,IAAK,KAAK8B,CAAV,CAAY,IAAI/B,IAAE,KAAK4J,EAAL,GAAS7J,IAAE,KAAK6J,EAAR,GAAY,CAA1B;AAAA,MAA4BpK,CAA5B;AAAA,MAA8BgB,IAAE,CAAhC,CAAkC,IAAGT,MAAI,CAAP,EAAS;AAAC,QAAGC,IAAE,KAAK4J,EAAP,IAAW,CAACpK,IAAE,KAAKO,CAAL,KAASC,CAAZ,KAAgB,CAAC,KAAK+B,CAAL,GAAO,KAAK8H,EAAb,KAAkB7J,CAAhD,EAAkD;AAACC,QAAEO,GAAF,IAAOhB,IAAG,KAAKuC,CAAL,IAAS,KAAK6H,EAAL,GAAQ5J,CAA3B;AAA+B,YAAMD,KAAG,CAAT,EAAW;AAAC,UAAGC,IAAE,CAAL,EAAO;AAACR,YAAE,CAAC,KAAKO,CAAL,IAAS,CAAC,KAAGC,CAAJ,IAAO,CAAjB,KAAuB,IAAEA,CAA3B,CAA8BR,KAAG,KAAK,EAAEO,CAAP,MAAYC,KAAG,KAAK4J,EAAL,GAAQ,CAAvB,CAAH;AAA6B,OAAnE,MAAuE;AAACpK,YAAG,KAAKO,CAAL,MAAUC,KAAG,CAAb,CAAD,GAAkB,GAApB,CAAwB,IAAGA,KAAG,CAAN,EAAQ;AAACA,eAAG,KAAK4J,EAAR,CAAW,EAAE7J,CAAF;AAAI;AAAC,WAAG,CAACP,IAAE,GAAH,KAAS,CAAZ,EAAc;AAACA,aAAG,CAAC,GAAJ;AAAQ,WAAGgB,KAAG,CAAH,IAAM,CAAC,KAAKuB,CAAL,GAAO,GAAR,MAAevC,IAAE,GAAjB,CAAT,EAA+B;AAAC,UAAEgB,CAAF;AAAI,WAAGA,IAAE,CAAF,IAAKhB,KAAG,KAAKuC,CAAhB,EAAkB;AAAC9B,UAAEO,GAAF,IAAOhB,CAAP;AAAS;AAAC;AAAC,UAAOS,CAAP;AAAS,UAASmQ,QAAT,CAAkBrQ,CAAlB,EAAoB;AAAC,SAAO,KAAKsM,SAAL,CAAetM,CAAf,KAAmB,CAA1B;AAA6B,UAASsQ,KAAT,CAAetQ,CAAf,EAAiB;AAAC,SAAO,KAAKsM,SAAL,CAAetM,CAAf,IAAkB,CAAnB,GAAsB,IAAtB,GAA2BA,CAAjC;AAAmC,UAASuQ,KAAT,CAAevQ,CAAf,EAAiB;AAAC,SAAO,KAAKsM,SAAL,CAAetM,CAAf,IAAkB,CAAnB,GAAsB,IAAtB,GAA2BA,CAAjC;AAAmC,UAASwQ,YAAT,CAAsBtQ,CAAtB,EAAwBV,CAAxB,EAA0BS,CAA1B,EAA4B;AAAC,MAAIN,CAAJ;AAAA,MAAMJ,CAAN;AAAA,MAAQS,IAAEkF,KAAKb,GAAL,CAASnE,EAAE4B,CAAX,EAAa,KAAKA,CAAlB,CAAV,CAA+B,KAAInC,IAAE,CAAN,EAAQA,IAAEK,CAAV,EAAY,EAAEL,CAAd,EAAgB;AAACM,MAAEN,CAAF,IAAKH,EAAE,KAAKG,CAAL,CAAF,EAAUO,EAAEP,CAAF,CAAV,CAAL;AAAqB,OAAGO,EAAE4B,CAAF,GAAI,KAAKA,CAAZ,EAAc;AAACvC,QAAEW,EAAE8B,CAAF,GAAI,KAAK8H,EAAX,CAAc,KAAInK,IAAEK,CAAN,EAAQL,IAAE,KAAKmC,CAAf,EAAiB,EAAEnC,CAAnB,EAAqB;AAACM,QAAEN,CAAF,IAAKH,EAAE,KAAKG,CAAL,CAAF,EAAUJ,CAAV,CAAL;AAAkB,OAAEuC,CAAF,GAAI,KAAKA,CAAT;AAAW,GAAhF,MAAoF;AAACvC,QAAE,KAAKyC,CAAL,GAAO,KAAK8H,EAAd,CAAiB,KAAInK,IAAEK,CAAN,EAAQL,IAAEO,EAAE4B,CAAZ,EAAc,EAAEnC,CAAhB,EAAkB;AAACM,QAAEN,CAAF,IAAKH,EAAED,CAAF,EAAIW,EAAEP,CAAF,CAAJ,CAAL;AAAe,OAAEmC,CAAF,GAAI5B,EAAE4B,CAAN;AAAQ,KAAEE,CAAF,GAAIxC,EAAE,KAAKwC,CAAP,EAAS9B,EAAE8B,CAAX,CAAJ,CAAkB/B,EAAEgC,KAAF;AAAU,UAASwO,MAAT,CAAgBhQ,CAAhB,EAAkBT,CAAlB,EAAoB;AAAC,SAAOS,IAAET,CAAT;AAAW,UAAS0Q,KAAT,CAAe1Q,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiByQ,MAAjB,EAAwBvQ,CAAxB,EAA2B,OAAOA,CAAP;AAAS,UAAS+P,KAAT,CAAexP,CAAf,EAAiBT,CAAjB,EAAmB;AAAC,SAAOS,IAAET,CAAT;AAAW,UAAS2Q,IAAT,CAAc3Q,CAAd,EAAgB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiBiQ,KAAjB,EAAuB/P,CAAvB,EAA0B,OAAOA,CAAP;AAAS,UAAS0Q,MAAT,CAAgBnQ,CAAhB,EAAkBT,CAAlB,EAAoB;AAAC,SAAOS,IAAET,CAAT;AAAW,UAAS6Q,KAAT,CAAe7Q,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiB4Q,MAAjB,EAAwB1Q,CAAxB,EAA2B,OAAOA,CAAP;AAAS,UAAS4Q,SAAT,CAAmBrQ,CAAnB,EAAqBT,CAArB,EAAuB;AAAC,SAAOS,IAAE,CAACT,CAAV;AAAY,UAAS+Q,QAAT,CAAkB/Q,CAAlB,EAAoB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiB8Q,SAAjB,EAA2B5Q,CAA3B,EAA8B,OAAOA,CAAP;AAAS,UAAS8Q,KAAT,GAAgB;AAAC,MAAIhR,IAAEuJ,KAAN,CAAY,KAAI,IAAI9I,IAAE,CAAV,EAAYA,IAAE,KAAKqB,CAAnB,EAAqB,EAAErB,CAAvB,EAAyB;AAACT,MAAES,CAAF,IAAK,KAAKqJ,EAAL,GAAQ,CAAC,KAAKrJ,CAAL,CAAd;AAAsB,KAAEqB,CAAF,GAAI,KAAKA,CAAT,CAAW9B,EAAEgC,CAAF,GAAI,CAAC,KAAKA,CAAV,CAAY,OAAOhC,CAAP;AAAS,UAASiR,WAAT,CAAqBjR,CAArB,EAAuB;AAAC,MAAIS,IAAE8I,KAAN,CAAY,IAAGvJ,IAAE,CAAL,EAAO;AAAC,SAAKyM,QAAL,CAAc,CAACzM,CAAf,EAAiBS,CAAjB;AAAoB,GAA5B,MAAgC;AAAC,SAAK2L,QAAL,CAAcpM,CAAd,EAAgBS,CAAhB;AAAmB,UAAOA,CAAP;AAAS,UAASyQ,YAAT,CAAsBlR,CAAtB,EAAwB;AAAC,MAAIS,IAAE8I,KAAN,CAAY,IAAGvJ,IAAE,CAAL,EAAO;AAAC,SAAKoM,QAAL,CAAc,CAACpM,CAAf,EAAiBS,CAAjB;AAAoB,GAA5B,MAAgC;AAAC,SAAKgM,QAAL,CAAczM,CAAd,EAAgBS,CAAhB;AAAmB,UAAOA,CAAP;AAAS,UAAS0Q,IAAT,CAAc1Q,CAAd,EAAgB;AAAC,MAAGA,KAAG,CAAN,EAAQ;AAAC,WAAO,CAAC,CAAR;AAAU,OAAIT,IAAE,CAAN,CAAQ,IAAG,CAACS,IAAE,KAAH,KAAW,CAAd,EAAgB;AAACA,UAAI,EAAJ,CAAOT,KAAG,EAAH;AAAM,OAAG,CAACS,IAAE,GAAH,KAAS,CAAZ,EAAc;AAACA,UAAI,CAAJ,CAAMT,KAAG,CAAH;AAAK,OAAG,CAACS,IAAE,EAAH,KAAQ,CAAX,EAAa;AAACA,UAAI,CAAJ,CAAMT,KAAG,CAAH;AAAK,OAAG,CAACS,IAAE,CAAH,KAAO,CAAV,EAAY;AAACA,UAAI,CAAJ,CAAMT,KAAG,CAAH;AAAK,OAAG,CAACS,IAAE,CAAH,KAAO,CAAV,EAAY;AAAC,MAAET,CAAF;AAAI,UAAOA,CAAP;AAAS,UAASoR,iBAAT,GAA4B;AAAC,OAAI,IAAI3Q,IAAE,CAAV,EAAYA,IAAE,KAAKqB,CAAnB,EAAqB,EAAErB,CAAvB,EAAyB;AAAC,QAAG,KAAKA,CAAL,KAAS,CAAZ,EAAc;AAAC,aAAOA,IAAE,KAAKoJ,EAAP,GAAUsH,KAAK,KAAK1Q,CAAL,CAAL,CAAjB;AAA+B;AAAC,OAAG,KAAKuB,CAAL,GAAO,CAAV,EAAY;AAAC,WAAO,KAAKF,CAAL,GAAO,KAAK+H,EAAnB;AAAsB,UAAO,CAAC,CAAR;AAAU,UAASwH,IAAT,CAAc5Q,CAAd,EAAgB;AAAC,MAAIT,IAAE,CAAN,CAAQ,OAAMS,KAAG,CAAT,EAAW;AAACA,SAAGA,IAAE,CAAL,CAAO,EAAET,CAAF;AAAI,UAAOA,CAAP;AAAS,UAASsR,UAAT,GAAqB;AAAC,MAAIpR,IAAE,CAAN;AAAA,MAAQO,IAAE,KAAKuB,CAAL,GAAO,KAAK8H,EAAtB,CAAyB,KAAI,IAAI9J,IAAE,CAAV,EAAYA,IAAE,KAAK8B,CAAnB,EAAqB,EAAE9B,CAAvB,EAAyB;AAACE,SAAGmR,KAAK,KAAKrR,CAAL,IAAQS,CAAb,CAAH;AAAmB,UAAOP,CAAP;AAAS,UAASqR,SAAT,CAAmBvR,CAAnB,EAAqB;AAAC,MAAIS,IAAEyE,KAAKc,KAAL,CAAWhG,IAAE,KAAK6J,EAAlB,CAAN,CAA4B,IAAGpJ,KAAG,KAAKqB,CAAX,EAAa;AAAC,WAAO,KAAKE,CAAL,IAAQ,CAAf;AAAkB,UAAO,CAAC,KAAKvB,CAAL,IAAS,KAAIT,IAAE,KAAK6J,EAArB,KAA4B,CAAnC;AAAsC,UAAS2H,YAAT,CAAsBtR,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,MAAIS,IAAE2I,WAAWmD,GAAX,CAAeyD,SAAf,CAAyB9P,CAAzB,CAAN,CAAkC,KAAK6P,SAAL,CAAetP,CAAf,EAAiBT,CAAjB,EAAmBS,CAAnB,EAAsB,OAAOA,CAAP;AAAS,UAASgR,QAAT,CAAkBhR,CAAlB,EAAoB;AAAC,SAAO,KAAKiR,SAAL,CAAejR,CAAf,EAAiBwP,KAAjB,CAAP;AAA+B,UAAS0B,UAAT,CAAoBlR,CAApB,EAAsB;AAAC,SAAO,KAAKiR,SAAL,CAAejR,CAAf,EAAiBqQ,SAAjB,CAAP;AAAmC,UAASc,SAAT,CAAmBnR,CAAnB,EAAqB;AAAC,SAAO,KAAKiR,SAAL,CAAejR,CAAf,EAAiBmQ,MAAjB,CAAP;AAAgC,UAASiB,QAAT,CAAkBlS,CAAlB,EAAoBF,CAApB,EAAsB;AAAC,MAAIQ,IAAE,CAAN;AAAA,MAAQV,IAAE,CAAV;AAAA,MAAYS,IAAEkF,KAAKb,GAAL,CAAS1E,EAAEmC,CAAX,EAAa,KAAKA,CAAlB,CAAd,CAAmC,OAAM7B,IAAED,CAAR,EAAU;AAACT,SAAG,KAAKU,CAAL,IAAQN,EAAEM,CAAF,CAAX,CAAgBR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,OAAGlK,EAAEmC,CAAF,GAAI,KAAKA,CAAZ,EAAc;AAACvC,SAAGI,EAAEqC,CAAL,CAAO,OAAM/B,IAAE,KAAK6B,CAAb,EAAe;AAACvC,WAAG,KAAKU,CAAL,CAAH,CAAWR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAG,KAAK7H,CAAR;AAAU,GAAxF,MAA4F;AAACzC,SAAG,KAAKyC,CAAR,CAAU,OAAM/B,IAAEN,EAAEmC,CAAV,EAAY;AAACvC,WAAGI,EAAEM,CAAF,CAAH,CAAQR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAGlK,EAAEqC,CAAL;AAAO,KAAEA,CAAF,GAAKzC,IAAE,CAAH,GAAM,CAAC,CAAP,GAAS,CAAb,CAAe,IAAGA,IAAE,CAAL,EAAO;AAACE,MAAEQ,GAAF,IAAOV,CAAP;AAAS,GAAjB,MAAqB;AAAC,QAAGA,IAAE,CAAC,CAAN,EAAQ;AAACE,QAAEQ,GAAF,IAAO,KAAK8J,EAAL,GAAQxK,CAAf;AAAiB;AAAC,KAAEuC,CAAF,GAAI7B,CAAJ,CAAMR,EAAEwC,KAAF;AAAU,UAAS6P,KAAT,CAAe9R,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwI,KAAL,CAAW/R,CAAX,EAAaE,CAAb,EAAgB,OAAOA,CAAP;AAAS,UAAS8R,UAAT,CAAoBhS,CAApB,EAAsB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKyB,KAAL,CAAWhL,CAAX,EAAaE,CAAb,EAAgB,OAAOA,CAAP;AAAS,UAAS+R,UAAT,CAAoBjS,CAApB,EAAsB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAK2D,UAAL,CAAgBlN,CAAhB,EAAkBE,CAAlB,EAAqB,OAAOA,CAAP;AAAS,UAASgS,QAAT,GAAmB;AAAC,MAAIzR,IAAE8I,KAAN,CAAY,KAAK8D,QAAL,CAAc5M,CAAd,EAAiB,OAAOA,CAAP;AAAS,UAAS0R,QAAT,CAAkBnS,CAAlB,EAAoB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKoD,QAAL,CAAc3M,CAAd,EAAgBE,CAAhB,EAAkB,IAAlB,EAAwB,OAAOA,CAAP;AAAS,UAASkS,WAAT,CAAqBpS,CAArB,EAAuB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKoD,QAAL,CAAc3M,CAAd,EAAgB,IAAhB,EAAqBE,CAArB,EAAwB,OAAOA,CAAP;AAAS,UAASmS,oBAAT,CAA8BrS,CAA9B,EAAgC;AAAC,MAAIL,IAAE4J,KAAN;AAAA,MAAYrJ,IAAEqJ,KAAd,CAAoB,KAAKoD,QAAL,CAAc3M,CAAd,EAAgBL,CAAhB,EAAkBO,CAAlB,EAAqB,OAAO,IAAI8I,KAAJ,CAAUrJ,CAAV,EAAYO,CAAZ,CAAP;AAAsB,UAASoS,YAAT,CAAsB7R,CAAtB,EAAwB;AAAC,OAAK,KAAKqB,CAAV,IAAa,KAAK8H,EAAL,CAAQ,CAAR,EAAUnJ,IAAE,CAAZ,EAAc,IAAd,EAAmB,CAAnB,EAAqB,CAArB,EAAuB,KAAKqB,CAA5B,CAAb,CAA4C,EAAE,KAAKA,CAAP,CAAS,KAAKG,KAAL;AAAa,UAASsQ,aAAT,CAAuBvS,CAAvB,EAAyBS,CAAzB,EAA2B;AAAC,MAAGT,KAAG,CAAN,EAAQ;AAAC;AAAO,UAAM,KAAK8B,CAAL,IAAQrB,CAAd,EAAgB;AAAC,SAAK,KAAKqB,CAAL,EAAL,IAAe,CAAf;AAAiB,QAAKrB,CAAL,KAAST,CAAT,CAAW,OAAM,KAAKS,CAAL,KAAS,KAAKsJ,EAApB,EAAuB;AAAC,SAAKtJ,CAAL,KAAS,KAAKsJ,EAAd,CAAiB,IAAG,EAAEtJ,CAAF,IAAK,KAAKqB,CAAb,EAAe;AAAC,WAAK,KAAKA,CAAL,EAAL,IAAe,CAAf;AAAiB,OAAE,KAAKrB,CAAL,CAAF;AAAU;AAAC,UAAS+R,OAAT,GAAkB,CAAE,UAASC,IAAT,CAAchS,CAAd,EAAgB;AAAC,SAAOA,CAAP;AAAS,UAASiS,MAAT,CAAgBjS,CAAhB,EAAkBP,CAAlB,EAAoBF,CAApB,EAAsB;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf;AAAkB,UAAS2S,MAAT,CAAgBlS,CAAhB,EAAkBT,CAAlB,EAAoB;AAACS,IAAE4M,QAAF,CAAWrN,CAAX;AAAc,SAAQJ,SAAR,CAAkB0N,OAAlB,GAA0BmF,IAA1B,CAA+BD,QAAQ5S,SAAR,CAAkB2N,MAAlB,GAAyBkF,IAAzB,CAA8BD,QAAQ5S,SAAR,CAAkB4N,KAAlB,GAAwBkF,MAAxB,CAA+BF,QAAQ5S,SAAR,CAAkB6N,KAAlB,GAAwBkF,MAAxB,CAA+B,SAASC,KAAT,CAAenS,CAAf,EAAiB;AAAC,SAAO,KAAKkO,GAAL,CAASlO,CAAT,EAAW,IAAI+R,OAAJ,EAAX,CAAP;AAAiC,UAASK,kBAAT,CAA4B7S,CAA5B,EAA8BP,CAA9B,EAAgCQ,CAAhC,EAAkC;AAAC,MAAIN,IAAEuF,KAAKb,GAAL,CAAS,KAAKvC,CAAL,GAAO9B,EAAE8B,CAAlB,EAAoBrC,CAApB,CAAN,CAA6BQ,EAAE+B,CAAF,GAAI,CAAJ,CAAM/B,EAAE6B,CAAF,GAAInC,CAAJ,CAAM,OAAMA,IAAE,CAAR,EAAU;AAACM,MAAE,EAAEN,CAAJ,IAAO,CAAP;AAAS,OAAIO,CAAJ,CAAM,KAAIA,IAAED,EAAE6B,CAAF,GAAI,KAAKA,CAAf,EAAiBnC,IAAEO,CAAnB,EAAqB,EAAEP,CAAvB,EAAyB;AAACM,MAAEN,IAAE,KAAKmC,CAAT,IAAY,KAAK8H,EAAL,CAAQ,CAAR,EAAU5J,EAAEL,CAAF,CAAV,EAAeM,CAAf,EAAiBN,CAAjB,EAAmB,CAAnB,EAAqB,KAAKmC,CAA1B,CAAZ;AAAyC,QAAI5B,IAAEgF,KAAKb,GAAL,CAASrE,EAAE8B,CAAX,EAAarC,CAAb,CAAN,EAAsBE,IAAEO,CAAxB,EAA0B,EAAEP,CAA5B,EAA8B;AAAC,SAAKiK,EAAL,CAAQ,CAAR,EAAU5J,EAAEL,CAAF,CAAV,EAAeM,CAAf,EAAiBN,CAAjB,EAAmB,CAAnB,EAAqBF,IAAEE,CAAvB;AAA0B,KAAEsC,KAAF;AAAU,UAAS6Q,kBAAT,CAA4B9S,CAA5B,EAA8BC,CAA9B,EAAgCN,CAAhC,EAAkC;AAAC,IAAEM,CAAF,CAAI,IAAIC,IAAEP,EAAEmC,CAAF,GAAI,KAAKA,CAAL,GAAO9B,EAAE8B,CAAT,GAAW7B,CAArB,CAAuBN,EAAEqC,CAAF,GAAI,CAAJ,CAAM,OAAM,EAAE9B,CAAF,IAAK,CAAX,EAAa;AAACP,MAAEO,CAAF,IAAK,CAAL;AAAO,QAAIA,IAAEgF,KAAKf,GAAL,CAASlE,IAAE,KAAK6B,CAAhB,EAAkB,CAAlB,CAAN,EAA2B5B,IAAEF,EAAE8B,CAA/B,EAAiC,EAAE5B,CAAnC,EAAqC;AAACP,MAAE,KAAKmC,CAAL,GAAO5B,CAAP,GAASD,CAAX,IAAc,KAAK2J,EAAL,CAAQ3J,IAAEC,CAAV,EAAYF,EAAEE,CAAF,CAAZ,EAAiBP,CAAjB,EAAmB,CAAnB,EAAqB,CAArB,EAAuB,KAAKmC,CAAL,GAAO5B,CAAP,GAASD,CAAhC,CAAd;AAAiD,KAAEgC,KAAF,GAAUtC,EAAE6M,SAAF,CAAY,CAAZ,EAAc7M,CAAd;AAAiB,UAASoT,OAAT,CAAiBtS,CAAjB,EAAmB;AAAC,OAAKuS,EAAL,GAAQzJ,KAAR,CAAc,KAAK0J,EAAL,GAAQ1J,KAAR,CAAcH,WAAWmD,GAAX,CAAeF,SAAf,CAAyB,IAAE5L,EAAEqB,CAA7B,EAA+B,KAAKkR,EAApC,EAAwC,KAAKE,EAAL,GAAQ,KAAKF,EAAL,CAAQG,MAAR,CAAe1S,CAAf,CAAR,CAA0B,KAAK+B,CAAL,GAAO/B,CAAP;AAAS,UAAS2S,cAAT,CAAwB3S,CAAxB,EAA0B;AAAC,MAAGA,EAAEuB,CAAF,GAAI,CAAJ,IAAOvB,EAAEqB,CAAF,GAAI,IAAE,KAAKU,CAAL,CAAOV,CAAvB,EAAyB;AAAC,WAAOrB,EAAEqM,GAAF,CAAM,KAAKtK,CAAX,CAAP;AAAqB,GAA/C,MAAmD;AAAC,QAAG/B,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,IAAoB,CAAvB,EAAyB;AAAC,aAAO/B,CAAP;AAAS,KAAnC,MAAuC;AAAC,UAAIT,IAAEuJ,KAAN,CAAY9I,EAAE0L,MAAF,CAASnM,CAAT,EAAY,KAAKmN,MAAL,CAAYnN,CAAZ,EAAe,OAAOA,CAAP;AAAS;AAAC;AAAC,UAASqT,aAAT,CAAuB5S,CAAvB,EAAyB;AAAC,SAAOA,CAAP;AAAS,UAAS6S,aAAT,CAAuB7S,CAAvB,EAAyB;AAACA,IAAE+L,SAAF,CAAY,KAAKhK,CAAL,CAAOV,CAAP,GAAS,CAArB,EAAuB,KAAKkR,EAA5B,EAAgC,IAAGvS,EAAEqB,CAAF,GAAI,KAAKU,CAAL,CAAOV,CAAP,GAAS,CAAhB,EAAkB;AAACrB,MAAEqB,CAAF,GAAI,KAAKU,CAAL,CAAOV,CAAP,GAAS,CAAb,CAAerB,EAAEwB,KAAF;AAAU,QAAKiR,EAAL,CAAQK,eAAR,CAAwB,KAAKP,EAA7B,EAAgC,KAAKxQ,CAAL,CAAOV,CAAP,GAAS,CAAzC,EAA2C,KAAKmR,EAAhD,EAAoD,KAAKzQ,CAAL,CAAOgR,eAAP,CAAuB,KAAKP,EAA5B,EAA+B,KAAKzQ,CAAL,CAAOV,CAAP,GAAS,CAAxC,EAA0C,KAAKkR,EAA/C,EAAmD,OAAMvS,EAAE6L,SAAF,CAAY,KAAK0G,EAAjB,IAAqB,CAA3B,EAA6B;AAACvS,MAAEmP,UAAF,CAAa,CAAb,EAAe,KAAKpN,CAAL,CAAOV,CAAP,GAAS,CAAxB;AAA2B,KAAEkJ,KAAF,CAAQ,KAAKgI,EAAb,EAAgBvS,CAAhB,EAAmB,OAAMA,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,KAAqB,CAA3B,EAA6B;AAAC/B,MAAEuK,KAAF,CAAQ,KAAKxI,CAAb,EAAe/B,CAAf;AAAkB;AAAC,UAASgT,YAAT,CAAsBhT,CAAtB,EAAwBT,CAAxB,EAA0B;AAACS,IAAE4M,QAAF,CAAWrN,CAAX,EAAc,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,UAAS0T,YAAT,CAAsBjT,CAAtB,EAAwBP,CAAxB,EAA0BF,CAA1B,EAA4B;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf,EAAkB,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,SAAQJ,SAAR,CAAkB0N,OAAlB,GAA0B8F,cAA1B,CAAyCL,QAAQnT,SAAR,CAAkB2N,MAAlB,GAAyB8F,aAAzB,CAAuCN,QAAQnT,SAAR,CAAkBuN,MAAlB,GAAyBmG,aAAzB,CAAuCP,QAAQnT,SAAR,CAAkB4N,KAAlB,GAAwBkG,YAAxB,CAAqCX,QAAQnT,SAAR,CAAkB6N,KAAlB,GAAwBgG,YAAxB,CAAqC,SAASE,QAAT,CAAkB5R,CAAlB,EAAoBtC,CAApB,EAAsB;AAAC,MAAIsB,IAAEgB,EAAE6M,SAAF,EAAN;AAAA,MAAoBpP,CAApB;AAAA,MAAsBQ,IAAE2K,IAAI,CAAJ,CAAxB;AAAA,MAA+B1G,CAA/B,CAAiC,IAAGlD,KAAG,CAAN,EAAQ;AAAC,WAAOf,CAAP;AAAS,GAAlB,MAAsB;AAAC,QAAGe,IAAE,EAAL,EAAQ;AAACvB,UAAE,CAAF;AAAI,KAAb,MAAiB;AAAC,UAAGuB,IAAE,EAAL,EAAQ;AAACvB,YAAE,CAAF;AAAI,OAAb,MAAiB;AAAC,YAAGuB,IAAE,GAAL,EAAS;AAACvB,cAAE,CAAF;AAAI,SAAd,MAAkB;AAAC,cAAGuB,IAAE,GAAL,EAAS;AAACvB,gBAAE,CAAF;AAAI,WAAd,MAAkB;AAACA,gBAAE,CAAF;AAAI;AAAC;AAAC;AAAC;AAAC,OAAGuB,IAAE,CAAL,EAAO;AAACkD,QAAE,IAAI2I,OAAJ,CAAYnN,CAAZ,CAAF;AAAiB,GAAzB,MAA6B;AAAC,QAAGA,EAAEiP,MAAF,EAAH,EAAc;AAACzK,UAAE,IAAI8O,OAAJ,CAAYtT,CAAZ,CAAF;AAAiB,KAAhC,MAAoC;AAACwE,UAAE,IAAI0J,UAAJ,CAAelO,CAAf,CAAF;AAAoB;AAAC,OAAIqB,IAAE,IAAIkI,KAAJ,EAAN;AAAA,MAAkBrJ,IAAE,CAApB;AAAA,MAAsBqC,IAAExC,IAAE,CAA1B;AAAA,MAA4BiB,IAAE,CAAC,KAAGjB,CAAJ,IAAO,CAArC,CAAuCsB,EAAE,CAAF,IAAKmD,EAAEqJ,OAAF,CAAU,IAAV,CAAL,CAAqB,IAAG9N,IAAE,CAAL,EAAO;AAAC,QAAIiI,IAAE8B,KAAN,CAAYtF,EAAEwJ,KAAF,CAAQ3M,EAAE,CAAF,CAAR,EAAa2G,CAAb,EAAgB,OAAM9H,KAAGc,CAAT,EAAW;AAACK,QAAEnB,CAAF,IAAK4J,KAAL,CAAWtF,EAAEuJ,KAAF,CAAQ/F,CAAR,EAAU3G,EAAEnB,IAAE,CAAJ,CAAV,EAAiBmB,EAAEnB,CAAF,CAAjB,EAAuBA,KAAG,CAAH;AAAK;AAAC,OAAIY,IAAEwB,EAAED,CAAF,GAAI,CAAV;AAAA,MAAYiC,CAAZ;AAAA,MAAcG,IAAE,IAAhB;AAAA,MAAqBhE,IAAEqJ,KAAvB;AAAA,MAA6B7B,CAA7B,CAA+B3G,IAAEyK,MAAMzJ,EAAExB,CAAF,CAAN,IAAY,CAAd,CAAgB,OAAMA,KAAG,CAAT,EAAW;AAAC,QAAGQ,KAAGiB,CAAN,EAAQ;AAAC+B,UAAGhC,EAAExB,CAAF,KAAOQ,IAAEiB,CAAV,GAAcvB,CAAhB;AAAkB,KAA3B,MAA+B;AAACsD,UAAE,CAAChC,EAAExB,CAAF,IAAM,CAAC,KAAIQ,IAAE,CAAP,IAAW,CAAlB,KAAwBiB,IAAEjB,CAA5B,CAA+B,IAAGR,IAAE,CAAL,EAAO;AAACwD,aAAGhC,EAAExB,IAAE,CAAJ,KAAS,KAAKsJ,EAAL,GAAQ9I,CAAR,GAAUiB,CAAtB;AAAyB;AAAC,SAAExC,CAAF,CAAI,OAAM,CAACuE,IAAE,CAAH,KAAO,CAAb,EAAe;AAACA,YAAI,CAAJ,CAAM,EAAEpE,CAAF;AAAI,SAAG,CAACoB,KAAGpB,CAAJ,IAAO,CAAV,EAAY;AAACoB,WAAG,KAAK8I,EAAR,CAAW,EAAEtJ,CAAF;AAAI,SAAG2D,CAAH,EAAK;AAACpD,QAAEiD,CAAF,EAAKoI,MAAL,CAAYnM,CAAZ,EAAekE,IAAE,KAAF;AAAQ,KAA7B,MAAiC;AAAC,aAAMvE,IAAE,CAAR,EAAU;AAACsE,UAAEwJ,KAAF,CAAQzN,CAAR,EAAUE,CAAV,EAAa+D,EAAEwJ,KAAF,CAAQvN,CAAR,EAAUF,CAAV,EAAaL,KAAG,CAAH;AAAK,WAAGA,IAAE,CAAL,EAAO;AAACsE,UAAEwJ,KAAF,CAAQzN,CAAR,EAAUE,CAAV;AAAa,OAArB,MAAyB;AAACwH,YAAE1H,CAAF,CAAIA,IAAEE,CAAF,CAAIA,IAAEwH,CAAF;AAAI,SAAE8F,KAAF,CAAQtN,CAAR,EAAUY,EAAEiD,CAAF,CAAV,EAAe/D,CAAf;AAAkB,YAAMO,KAAG,CAAH,IAAM,CAACwB,EAAExB,CAAF,IAAM,KAAGQ,CAAV,KAAe,CAA3B,EAA6B;AAACkD,QAAEwJ,KAAF,CAAQzN,CAAR,EAAUE,CAAV,EAAawH,IAAE1H,CAAF,CAAIA,IAAEE,CAAF,CAAIA,IAAEwH,CAAF,CAAI,IAAG,EAAE3G,CAAF,GAAI,CAAP,EAAS;AAACA,YAAE,KAAK8I,EAAL,GAAQ,CAAV,CAAY,EAAEtJ,CAAF;AAAI;AAAC;AAAC,UAAO0D,EAAEsJ,MAAF,CAASvN,CAAT,CAAP;AAAmB,UAAS4T,KAAT,CAAe1T,CAAf,EAAiB;AAAC,MAAIF,IAAG,KAAKgC,CAAL,GAAO,CAAR,GAAW,KAAKmJ,MAAL,EAAX,GAAyB,KAAK3J,KAAL,EAA/B,CAA4C,IAAIhC,IAAGU,EAAE8B,CAAF,GAAI,CAAL,GAAQ9B,EAAEiL,MAAF,EAAR,GAAmBjL,EAAEsB,KAAF,EAAzB,CAAmC,IAAGxB,EAAEsM,SAAF,CAAY9M,CAAZ,IAAe,CAAlB,EAAoB;AAAC,QAAIS,IAAED,CAAN,CAAQA,IAAER,CAAF,CAAIA,IAAES,CAAF;AAAI,OAAIN,IAAEK,EAAE6T,eAAF,EAAN;AAAA,MAA0BpU,IAAED,EAAEqU,eAAF,EAA5B,CAAgD,IAAGpU,IAAE,CAAL,EAAO;AAAC,WAAOO,CAAP;AAAS,OAAGL,IAAEF,CAAL,EAAO;AAACA,QAAEE,CAAF;AAAI,OAAGF,IAAE,CAAL,EAAO;AAACO,MAAEyM,QAAF,CAAWhN,CAAX,EAAaO,CAAb,EAAgBR,EAAEiN,QAAF,CAAWhN,CAAX,EAAaD,CAAb;AAAgB,UAAMQ,EAAEuP,MAAF,KAAW,CAAjB,EAAmB;AAAC,QAAG,CAAC5P,IAAEK,EAAE6T,eAAF,EAAH,IAAwB,CAA3B,EAA6B;AAAC7T,QAAEyM,QAAF,CAAW9M,CAAX,EAAaK,CAAb;AAAgB,SAAG,CAACL,IAAEH,EAAEqU,eAAF,EAAH,IAAwB,CAA3B,EAA6B;AAACrU,QAAEiN,QAAF,CAAW9M,CAAX,EAAaH,CAAb;AAAgB,SAAGQ,EAAEsM,SAAF,CAAY9M,CAAZ,KAAgB,CAAnB,EAAqB;AAACQ,QAAEgL,KAAF,CAAQxL,CAAR,EAAUQ,CAAV,EAAaA,EAAEyM,QAAF,CAAW,CAAX,EAAazM,CAAb;AAAgB,KAAnD,MAAuD;AAACR,QAAEwL,KAAF,CAAQhL,CAAR,EAAUR,CAAV,EAAaA,EAAEiN,QAAF,CAAW,CAAX,EAAajN,CAAb;AAAgB;AAAC,OAAGC,IAAE,CAAL,EAAO;AAACD,MAAE4M,QAAF,CAAW3M,CAAX,EAAaD,CAAb;AAAgB,UAAOA,CAAP;AAAS,UAASsU,SAAT,CAAmB7T,CAAnB,EAAqB;AAAC,MAAGA,KAAG,CAAN,EAAQ;AAAC,WAAO,CAAP;AAAS,OAAIC,IAAE,KAAK6J,EAAL,GAAQ9J,CAAd;AAAA,MAAgBD,IAAG,KAAKgC,CAAL,GAAO,CAAR,GAAW/B,IAAE,CAAb,GAAe,CAAjC,CAAmC,IAAG,KAAK6B,CAAL,GAAO,CAAV,EAAY;AAAC,QAAG5B,KAAG,CAAN,EAAQ;AAACF,UAAE,KAAK,CAAL,IAAQC,CAAV;AAAY,KAArB,MAAyB;AAAC,WAAI,IAAIQ,IAAE,KAAKqB,CAAL,GAAO,CAAjB,EAAmBrB,KAAG,CAAtB,EAAwB,EAAEA,CAA1B,EAA4B;AAACT,YAAE,CAACE,IAAEF,CAAF,GAAI,KAAKS,CAAL,CAAL,IAAcR,CAAhB;AAAkB;AAAC;AAAC,UAAOD,CAAP;AAAS,UAAS+T,YAAT,CAAsBtU,CAAtB,EAAwB;AAAC,MAAIW,IAAEX,EAAEiP,MAAF,EAAN,CAAiB,IAAI,KAAKA,MAAL,MAAetO,CAAhB,IAAoBX,EAAE8P,MAAF,MAAY,CAAnC,EAAqC;AAAC,WAAOnG,WAAW2B,IAAlB;AAAuB,OAAI1K,IAAEZ,EAAE+B,KAAF,EAAN;AAAA,MAAgBhC,IAAE,KAAKgC,KAAL,EAAlB,CAA+B,IAAIjC,IAAEoL,IAAI,CAAJ,CAAN;AAAA,MAAa1K,IAAE0K,IAAI,CAAJ,CAAf;AAAA,MAAsBpK,IAAEoK,IAAI,CAAJ,CAAxB;AAAA,MAA+BnK,IAAEmK,IAAI,CAAJ,CAAjC,CAAwC,OAAMtK,EAAEkP,MAAF,MAAY,CAAlB,EAAoB;AAAC,WAAMlP,EAAEqO,MAAF,EAAN,EAAiB;AAACrO,QAAEoM,QAAF,CAAW,CAAX,EAAapM,CAAb,EAAgB,IAAGD,CAAH,EAAK;AAAC,YAAG,CAACb,EAAEmP,MAAF,EAAD,IAAa,CAACzO,EAAEyO,MAAF,EAAjB,EAA4B;AAACnP,YAAEwS,KAAF,CAAQ,IAAR,EAAaxS,CAAb,EAAgBU,EAAE+K,KAAF,CAAQvL,CAAR,EAAUQ,CAAV;AAAa,WAAEwM,QAAF,CAAW,CAAX,EAAalN,CAAb;AAAgB,OAAhF,MAAoF;AAAC,YAAG,CAACU,EAAEyO,MAAF,EAAJ,EAAe;AAACzO,YAAE+K,KAAF,CAAQvL,CAAR,EAAUQ,CAAV;AAAa;AAAC,SAAEwM,QAAF,CAAW,CAAX,EAAaxM,CAAb;AAAgB,YAAMT,EAAEkP,MAAF,EAAN,EAAiB;AAAClP,QAAEiN,QAAF,CAAW,CAAX,EAAajN,CAAb,EAAgB,IAAGY,CAAH,EAAK;AAAC,YAAG,CAACG,EAAEmO,MAAF,EAAD,IAAa,CAAClO,EAAEkO,MAAF,EAAjB,EAA4B;AAACnO,YAAEwR,KAAF,CAAQ,IAAR,EAAaxR,CAAb,EAAgBC,EAAEwK,KAAF,CAAQvL,CAAR,EAAUe,CAAV;AAAa,WAAEiM,QAAF,CAAW,CAAX,EAAalM,CAAb;AAAgB,OAAhF,MAAoF;AAAC,YAAG,CAACC,EAAEkO,MAAF,EAAJ,EAAe;AAAClO,YAAEwK,KAAF,CAAQvL,CAAR,EAAUe,CAAV;AAAa;AAAC,SAAEiM,QAAF,CAAW,CAAX,EAAajM,CAAb;AAAgB,SAAGH,EAAEiM,SAAF,CAAY9M,CAAZ,KAAgB,CAAnB,EAAqB;AAACa,QAAE2K,KAAF,CAAQxL,CAAR,EAAUa,CAAV,EAAa,IAAGD,CAAH,EAAK;AAACb,UAAEyL,KAAF,CAAQzK,CAAR,EAAUhB,CAAV;AAAa,SAAEyL,KAAF,CAAQxK,CAAR,EAAUP,CAAV;AAAa,KAAnE,MAAuE;AAACT,QAAEwL,KAAF,CAAQ3K,CAAR,EAAUb,CAAV,EAAa,IAAGY,CAAH,EAAK;AAACG,UAAEyK,KAAF,CAAQzL,CAAR,EAAUgB,CAAV;AAAa,SAAEyK,KAAF,CAAQ/K,CAAR,EAAUO,CAAV;AAAa;AAAC,OAAGhB,EAAE8M,SAAF,CAAYlD,WAAWmD,GAAvB,KAA6B,CAAhC,EAAkC;AAAC,WAAOnD,WAAW2B,IAAlB;AAAuB,OAAGvK,EAAE8L,SAAF,CAAY7M,CAAZ,KAAgB,CAAnB,EAAqB;AAAC,WAAOe,EAAEwT,QAAF,CAAWvU,CAAX,CAAP;AAAqB,OAAGe,EAAE+O,MAAF,KAAW,CAAd,EAAgB;AAAC/O,MAAEuR,KAAF,CAAQtS,CAAR,EAAUe,CAAV;AAAa,GAA9B,MAAkC;AAAC,WAAOA,CAAP;AAAS,OAAGA,EAAE+O,MAAF,KAAW,CAAd,EAAgB;AAAC,WAAO/O,EAAEyT,GAAF,CAAMxU,CAAN,CAAP;AAAgB,GAAjC,MAAqC;AAAC,WAAOe,CAAP;AAAS;AAAC,KAAI0T,YAAU,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,EAAO,CAAP,EAAS,EAAT,EAAY,EAAZ,EAAe,EAAf,EAAkB,EAAlB,EAAqB,EAArB,EAAwB,EAAxB,EAA2B,EAA3B,EAA8B,EAA9B,EAAiC,EAAjC,EAAoC,EAApC,EAAuC,EAAvC,EAA0C,EAA1C,EAA6C,EAA7C,EAAgD,EAAhD,EAAmD,EAAnD,EAAsD,EAAtD,EAAyD,EAAzD,EAA4D,EAA5D,EAA+D,EAA/D,EAAkE,EAAlE,EAAqE,EAArE,EAAwE,GAAxE,EAA4E,GAA5E,EAAgF,GAAhF,EAAoF,GAApF,EAAwF,GAAxF,EAA4F,GAA5F,EAAgG,GAAhG,EAAoG,GAApG,EAAwG,GAAxG,EAA4G,GAA5G,EAAgH,GAAhH,EAAoH,GAApH,EAAwH,GAAxH,EAA4H,GAA5H,EAAgI,GAAhI,EAAoI,GAApI,EAAwI,GAAxI,EAA4I,GAA5I,EAAgJ,GAAhJ,EAAoJ,GAApJ,EAAwJ,GAAxJ,EAA4J,GAA5J,EAAgK,GAAhK,EAAoK,GAApK,EAAwK,GAAxK,EAA4K,GAA5K,EAAgL,GAAhL,EAAoL,GAApL,EAAwL,GAAxL,EAA4L,GAA5L,EAAgM,GAAhM,EAAoM,GAApM,EAAwM,GAAxM,EAA4M,GAA5M,EAAgN,GAAhN,EAAoN,GAApN,EAAwN,GAAxN,EAA4N,GAA5N,EAAgO,GAAhO,EAAoO,GAApO,EAAwO,GAAxO,EAA4O,GAA5O,EAAgP,GAAhP,EAAoP,GAApP,EAAwP,GAAxP,EAA4P,GAA5P,EAAgQ,GAAhQ,EAAoQ,GAApQ,EAAwQ,GAAxQ,EAA4Q,GAA5Q,EAAgR,GAAhR,EAAoR,GAApR,EAAwR,GAAxR,EAA4R,GAA5R,EAAgS,GAAhS,EAAoS,GAApS,EAAwS,GAAxS,EAA4S,GAA5S,EAAgT,GAAhT,EAAoT,GAApT,EAAwT,GAAxT,EAA4T,GAA5T,EAAgU,GAAhU,EAAoU,GAApU,EAAwU,GAAxU,EAA4U,GAA5U,EAAgV,GAAhV,EAAoV,GAApV,EAAwV,GAAxV,EAA4V,GAA5V,EAAgW,GAAhW,EAAoW,GAApW,EAAwW,GAAxW,EAA4W,GAA5W,EAAgX,GAAhX,EAAoX,GAApX,EAAwX,GAAxX,EAA4X,GAA5X,EAAgY,GAAhY,EAAoY,GAApY,EAAwY,GAAxY,EAA4Y,GAA5Y,EAAgZ,GAAhZ,EAAoZ,GAApZ,EAAwZ,GAAxZ,EAA4Z,GAA5Z,EAAga,GAAha,EAAoa,GAApa,EAAwa,GAAxa,EAA4a,GAA5a,EAAgb,GAAhb,EAAob,GAApb,EAAwb,GAAxb,EAA4b,GAA5b,EAAgc,GAAhc,EAAoc,GAApc,EAAwc,GAAxc,EAA4c,GAA5c,EAAgd,GAAhd,EAAod,GAApd,EAAwd,GAAxd,EAA4d,GAA5d,EAAge,GAAhe,EAAoe,GAApe,EAAwe,GAAxe,EAA4e,GAA5e,EAAgf,GAAhf,EAAof,GAApf,EAAwf,GAAxf,EAA4f,GAA5f,EAAggB,GAAhgB,EAAogB,GAApgB,EAAwgB,GAAxgB,EAA4gB,GAA5gB,EAAghB,GAAhhB,EAAohB,GAAphB,EAAwhB,GAAxhB,EAA4hB,GAA5hB,EAAgiB,GAAhiB,EAAoiB,GAApiB,EAAwiB,GAAxiB,EAA4iB,GAA5iB,EAAgjB,GAAhjB,EAAojB,GAApjB,EAAwjB,GAAxjB,EAA4jB,GAA5jB,EAAgkB,GAAhkB,EAAokB,GAApkB,EAAwkB,GAAxkB,EAA4kB,GAA5kB,EAAglB,GAAhlB,EAAolB,GAAplB,EAAwlB,GAAxlB,EAA4lB,GAA5lB,EAAgmB,GAAhmB,EAAomB,GAApmB,EAAwmB,GAAxmB,EAA4mB,GAA5mB,EAAgnB,GAAhnB,EAAonB,GAApnB,EAAwnB,GAAxnB,EAA4nB,GAA5nB,EAAgoB,GAAhoB,CAAd,CAAmpB,IAAIC,QAAM,CAAC,KAAG,EAAJ,IAAQD,UAAUA,UAAU5T,MAAV,GAAiB,CAA3B,CAAlB,CAAgD,SAAS8T,iBAAT,CAA2BnU,CAA3B,EAA6B;AAAC,MAAIN,CAAJ;AAAA,MAAMK,IAAE,KAAKgM,GAAL,EAAR,CAAmB,IAAGhM,EAAE8B,CAAF,IAAK,CAAL,IAAQ9B,EAAE,CAAF,KAAMkU,UAAUA,UAAU5T,MAAV,GAAiB,CAA3B,CAAjB,EAA+C;AAAC,SAAIX,IAAE,CAAN,EAAQA,IAAEuU,UAAU5T,MAApB,EAA2B,EAAEX,CAA7B,EAA+B;AAAC,UAAGK,EAAE,CAAF,KAAMkU,UAAUvU,CAAV,CAAT,EAAsB;AAAC,eAAO,IAAP;AAAY;AAAC,YAAO,KAAP;AAAa,OAAGK,EAAE0O,MAAF,EAAH,EAAc;AAAC,WAAO,KAAP;AAAa,OAAE,CAAF,CAAI,OAAM/O,IAAEuU,UAAU5T,MAAlB,EAAyB;AAAC,QAAIG,IAAEyT,UAAUvU,CAAV,CAAN;AAAA,QAAmBO,IAAEP,IAAE,CAAvB,CAAyB,OAAMO,IAAEgU,UAAU5T,MAAZ,IAAoBG,IAAE0T,KAA5B,EAAkC;AAAC1T,WAAGyT,UAAUhU,GAAV,CAAH;AAAkB,SAAEF,EAAEqU,MAAF,CAAS5T,CAAT,CAAF,CAAc,OAAMd,IAAEO,CAAR,EAAU;AAAC,UAAGO,IAAEyT,UAAUvU,GAAV,CAAF,IAAkB,CAArB,EAAuB;AAAC,eAAO,KAAP;AAAa;AAAC;AAAC,UAAOK,EAAEsU,WAAF,CAAcrU,CAAd,CAAP;AAAwB,UAASsU,cAAT,CAAwB9U,CAAxB,EAA0B;AAAC,MAAIF,IAAE,KAAKyU,QAAL,CAAc5K,WAAWmD,GAAzB,CAAN,CAAoC,IAAIrM,IAAEX,EAAEsU,eAAF,EAAN,CAA0B,IAAG3T,KAAG,CAAN,EAAQ;AAAC,WAAO,KAAP;AAAa,OAAIV,IAAED,EAAEiV,UAAF,CAAatU,CAAb,CAAN,CAAsBT,IAAGA,IAAE,CAAH,IAAO,CAAT,CAAW,IAAGA,IAAEyU,UAAU5T,MAAf,EAAsB;AAACb,QAAEyU,UAAU5T,MAAZ;AAAmB,OAAIN,IAAEuJ,KAAN,CAAY,KAAI,IAAItJ,IAAE,CAAV,EAAYA,IAAER,CAAd,EAAgB,EAAEQ,CAAlB,EAAoB;AAACD,MAAE4K,OAAF,CAAUsJ,UAAUhP,KAAKc,KAAL,CAAWd,KAAK5C,MAAL,KAAc4R,UAAU5T,MAAnC,CAAV,CAAV,EAAiE,IAAIC,IAAEP,EAAEyU,MAAF,CAASjV,CAAT,EAAW,IAAX,CAAN,CAAuB,IAAGe,EAAE+L,SAAF,CAAYlD,WAAWmD,GAAvB,KAA6B,CAA7B,IAAgChM,EAAE+L,SAAF,CAAY/M,CAAZ,KAAgB,CAAnD,EAAqD;AAAC,UAAII,IAAE,CAAN,CAAQ,OAAMA,MAAIO,CAAJ,IAAOK,EAAE+L,SAAF,CAAY/M,CAAZ,KAAgB,CAA7B,EAA+B;AAACgB,YAAEA,EAAEsO,SAAF,CAAY,CAAZ,EAAc,IAAd,CAAF,CAAsB,IAAGtO,EAAE+L,SAAF,CAAYlD,WAAWmD,GAAvB,KAA6B,CAAhC,EAAkC;AAAC,iBAAO,KAAP;AAAa;AAAC,WAAGhM,EAAE+L,SAAF,CAAY/M,CAAZ,KAAgB,CAAnB,EAAqB;AAAC,eAAO,KAAP;AAAa;AAAC;AAAC,UAAO,IAAP;AAAY,YAAWK,SAAX,CAAqB4P,SAArB,GAA+BN,YAA/B,CAA4C9F,WAAWxJ,SAAX,CAAqBwL,OAArB,GAA6BkE,UAA7B,CAAwClG,WAAWxJ,SAAX,CAAqBkL,SAArB,GAA+B4E,YAA/B,CAA4CtG,WAAWxJ,SAAX,CAAqByJ,UAArB,GAAgCwG,aAAhC,CAA8CzG,WAAWxJ,SAAX,CAAqBmQ,SAArB,GAA+BS,YAA/B,CAA4CpH,WAAWxJ,SAAX,CAAqB8R,SAArB,GAA+BF,YAA/B,CAA4CpI,WAAWxJ,SAAX,CAAqBmS,KAArB,GAA2BF,QAA3B,CAAoCzI,WAAWxJ,SAAX,CAAqB+P,SAArB,GAA+B2C,YAA/B,CAA4ClJ,WAAWxJ,SAAX,CAAqBgQ,UAArB,GAAgC2C,aAAhC,CAA8CnJ,WAAWxJ,SAAX,CAAqB4T,eAArB,GAAqCX,kBAArC,CAAwDzJ,WAAWxJ,SAAX,CAAqB2T,eAArB,GAAqCT,kBAArC,CAAwD1J,WAAWxJ,SAAX,CAAqByU,MAArB,GAA4BP,SAA5B,CAAsC1K,WAAWxJ,SAAX,CAAqB0U,WAArB,GAAiCC,cAAjC,CAAgDnL,WAAWxJ,SAAX,CAAqB4B,KAArB,GAA2BsN,OAA3B,CAAmC1F,WAAWxJ,SAAX,CAAqB6P,QAArB,GAA8BV,UAA9B,CAAyC3F,WAAWxJ,SAAX,CAAqB8U,SAArB,GAA+B1F,WAA/B,CAA2C5F,WAAWxJ,SAAX,CAAqB+U,UAArB,GAAgC1F,YAAhC,CAA6C7F,WAAWxJ,SAAX,CAAqB2P,MAArB,GAA4BF,QAA5B,CAAqCjG,WAAWxJ,SAAX,CAAqBgV,WAArB,GAAiCxE,aAAjC,CAA+ChH,WAAWxJ,SAAX,CAAqBiV,MAArB,GAA4BxE,QAA5B,CAAqCjH,WAAWxJ,SAAX,CAAqByE,GAArB,GAAyBiM,KAAzB,CAA+BlH,WAAWxJ,SAAX,CAAqBuE,GAArB,GAAyBoM,KAAzB,CAA+BnH,WAAWxJ,SAAX,CAAqBkV,GAArB,GAAyBpE,KAAzB,CAA+BtH,WAAWxJ,SAAX,CAAqBmV,EAArB,GAAwBpE,IAAxB,CAA6BvH,WAAWxJ,SAAX,CAAqBoV,GAArB,GAAyBnE,KAAzB,CAA+BzH,WAAWxJ,SAAX,CAAqBqV,MAArB,GAA4BlE,QAA5B,CAAqC3H,WAAWxJ,SAAX,CAAqBsV,GAArB,GAAyBlE,KAAzB,CAA+B5H,WAAWxJ,SAAX,CAAqBoQ,SAArB,GAA+BiB,WAA/B,CAA2C7H,WAAWxJ,SAAX,CAAqB4U,UAArB,GAAgCtD,YAAhC,CAA6C9H,WAAWxJ,SAAX,CAAqBiU,eAArB,GAAqCzC,iBAArC,CAAuDhI,WAAWxJ,SAAX,CAAqBuV,QAArB,GAA8B7D,UAA9B,CAAyClI,WAAWxJ,SAAX,CAAqBkQ,OAArB,GAA6ByB,SAA7B,CAAuCnI,WAAWxJ,SAAX,CAAqBwV,MAArB,GAA4B3D,QAA5B,CAAqCrI,WAAWxJ,SAAX,CAAqByV,QAArB,GAA8B1D,UAA9B,CAAyCvI,WAAWxJ,SAAX,CAAqB0V,OAArB,GAA6B1D,SAA7B,CAAuCxI,WAAWxJ,SAAX,CAAqBqU,GAArB,GAAyBnC,KAAzB,CAA+B1I,WAAWxJ,SAAX,CAAqBoU,QAArB,GAA8BhC,UAA9B,CAAyC5I,WAAWxJ,SAAX,CAAqB2V,QAArB,GAA8BtD,UAA9B,CAAyC7I,WAAWxJ,SAAX,CAAqBuT,MAArB,GAA4BhB,QAA5B,CAAqC/I,WAAWxJ,SAAX,CAAqB4V,SAArB,GAA+BpD,WAA/B,CAA2ChJ,WAAWxJ,SAAX,CAAqB6V,kBAArB,GAAwCpD,oBAAxC,CAA6DjJ,WAAWxJ,SAAX,CAAqB6U,MAArB,GAA4Bd,QAA5B,CAAqCvK,WAAWxJ,SAAX,CAAqB8V,UAArB,GAAgC3B,YAAhC,CAA6C3K,WAAWxJ,SAAX,CAAqBiG,GAArB,GAAyB+M,KAAzB,CAA+BxJ,WAAWxJ,SAAX,CAAqB+V,GAArB,GAAyB/B,KAAzB,CAA+BxK,WAAWxJ,SAAX,CAAqBsQ,eAArB,GAAqCkE,iBAArC,CAAuDhL,WAAWxJ,SAAX,CAAqBgW,MAArB,GAA4B1D,QAA5B;AACrgZ;;AAEA,SAAS2D,OAAT,GAAkB;AAAC,OAAKxV,CAAL,GAAO,CAAP,CAAS,KAAKD,CAAL,GAAO,CAAP,CAAS,KAAK2H,CAAL,GAAO,IAAIiB,KAAJ,EAAP;AAAmB,UAAS8M,QAAT,CAAkBnW,CAAlB,EAAoB;AAAC,MAAIO,CAAJ,EAAMO,CAAN,EAAQT,CAAR,CAAU,KAAIE,IAAE,CAAN,EAAQA,IAAE,GAAV,EAAc,EAAEA,CAAhB,EAAkB;AAAC,SAAK6H,CAAL,CAAO7H,CAAP,IAAUA,CAAV;AAAY,OAAE,CAAF,CAAI,KAAIA,IAAE,CAAN,EAAQA,IAAE,GAAV,EAAc,EAAEA,CAAhB,EAAkB;AAACO,QAAGA,IAAE,KAAKsH,CAAL,CAAO7H,CAAP,CAAF,GAAYP,EAAEO,IAAEP,EAAEW,MAAN,CAAb,GAA4B,GAA9B,CAAkCN,IAAE,KAAK+H,CAAL,CAAO7H,CAAP,CAAF,CAAY,KAAK6H,CAAL,CAAO7H,CAAP,IAAU,KAAK6H,CAAL,CAAOtH,CAAP,CAAV,CAAoB,KAAKsH,CAAL,CAAOtH,CAAP,IAAUT,CAAV;AAAY,QAAKK,CAAL,GAAO,CAAP,CAAS,KAAKD,CAAL,GAAO,CAAP;AAAS,UAAS2V,QAAT,GAAmB;AAAC,MAAItV,CAAJ,CAAM,KAAKJ,CAAL,GAAQ,KAAKA,CAAL,GAAO,CAAR,GAAW,GAAlB,CAAsB,KAAKD,CAAL,GAAQ,KAAKA,CAAL,GAAO,KAAK2H,CAAL,CAAO,KAAK1H,CAAZ,CAAR,GAAwB,GAA/B,CAAmCI,IAAE,KAAKsH,CAAL,CAAO,KAAK1H,CAAZ,CAAF,CAAiB,KAAK0H,CAAL,CAAO,KAAK1H,CAAZ,IAAe,KAAK0H,CAAL,CAAO,KAAK3H,CAAZ,CAAf,CAA8B,KAAK2H,CAAL,CAAO,KAAK3H,CAAZ,IAAeK,CAAf,CAAiB,OAAO,KAAKsH,CAAL,CAAQtH,IAAE,KAAKsH,CAAL,CAAO,KAAK1H,CAAZ,CAAH,GAAmB,GAA1B,CAAP;AAAsC,SAAQT,SAAR,CAAkBsB,IAAlB,GAAuB4U,QAAvB,CAAgCD,QAAQjW,SAAR,CAAkBoW,IAAlB,GAAuBD,QAAvB,CAAgC,SAASE,aAAT,GAAwB;AAAC,SAAO,IAAIJ,OAAJ,EAAP;AAAqB,KAAIK,YAAU,GAAd;AACphB;;AAEA,IAAIC,SAAJ,CAAc,IAAIC,QAAJ,CAAa,IAAIC,QAAJ,CAAa,SAASC,YAAT,CAAsB7V,CAAtB,EAAwB;AAAC2V,WAASC,UAAT,KAAsB5V,IAAE,GAAxB,CAA4B2V,SAASC,UAAT,KAAuB5V,KAAG,CAAJ,GAAO,GAA7B,CAAiC2V,SAASC,UAAT,KAAuB5V,KAAG,EAAJ,GAAQ,GAA9B,CAAkC2V,SAASC,UAAT,KAAuB5V,KAAG,EAAJ,GAAQ,GAA9B,CAAkC,IAAG4V,YAAUH,SAAb,EAAuB;AAACG,gBAAUH,SAAV;AAAoB;AAAC,UAASK,aAAT,GAAwB;AAACD,eAAa,IAAIE,IAAJ,GAAWC,OAAX,EAAb;AAAmC,KAAGL,YAAU,IAAb,EAAkB;AAACA,aAAS,IAAIpN,KAAJ,EAAT,CAAqBqN,WAAS,CAAT,CAAW,IAAIvU,CAAJ,CAAM,IAAG5C,WAASE,SAAT,KAAqBF,OAAOwX,MAAP,KAAgBtX,SAAhB,IAA2BF,OAAOyX,QAAP,KAAkBvX,SAAlE,CAAH,EAAgF;AAAC,QAAIsX,SAAOxX,OAAOwX,MAAP,IAAexX,OAAOyX,QAAjC,CAA0C,IAAGD,OAAOE,eAAV,EAA0B;AAAC,UAAIC,KAAG,IAAIC,UAAJ,CAAe,EAAf,CAAP,CAA0BJ,OAAOE,eAAP,CAAuBC,EAAvB,EAA2B,KAAI/U,IAAE,CAAN,EAAQA,IAAE,EAAV,EAAa,EAAEA,CAAf,EAAiB;AAACsU,iBAASC,UAAT,IAAqBQ,GAAG/U,CAAH,CAArB;AAA2B;AAAC,KAA9H,MAAkI;AAAC,UAAG9C,UAAU2K,OAAV,IAAmB,UAAnB,IAA+B3K,UAAU+X,UAAV,GAAqB,GAAvD,EAA2D;AAAC,YAAIvP,IAAEtI,OAAOwX,MAAP,CAAcpU,MAAd,CAAqB,EAArB,CAAN,CAA+B,KAAIR,IAAE,CAAN,EAAQA,IAAE0F,EAAElH,MAAZ,EAAmB,EAAEwB,CAArB,EAAuB;AAACsU,mBAASC,UAAT,IAAqB7O,EAAEtE,UAAF,CAAapB,CAAb,IAAgB,GAArC;AAAyC;AAAC;AAAC;AAAC,UAAMuU,WAASH,SAAf,EAAyB;AAACpU,QAAEoD,KAAKc,KAAL,CAAW,QAAMd,KAAK5C,MAAL,EAAjB,CAAF,CAAkC8T,SAASC,UAAT,IAAqBvU,MAAI,CAAzB,CAA2BsU,SAASC,UAAT,IAAqBvU,IAAE,GAAvB;AAA2B,cAAS,CAAT,CAAWyU;AAAgB,UAASS,YAAT,GAAuB;AAAC,MAAGb,aAAW,IAAd,EAAmB;AAACI,oBAAgBJ,YAAUF,eAAV,CAA0BE,UAAUjV,IAAV,CAAekV,QAAf,EAAyB,KAAIC,WAAS,CAAb,EAAeA,WAASD,SAAS9V,MAAjC,EAAwC,EAAE+V,QAA1C,EAAmD;AAACD,eAASC,QAAT,IAAmB,CAAnB;AAAqB,gBAAS,CAAT;AAAW,UAAOF,UAAUH,IAAV,EAAP;AAAwB,UAASiB,aAAT,CAAuBjX,CAAvB,EAAyB;AAAC,MAAIS,CAAJ,CAAM,KAAIA,IAAE,CAAN,EAAQA,IAAET,EAAEM,MAAZ,EAAmB,EAAEG,CAArB,EAAuB;AAACT,MAAES,CAAF,IAAKuW,cAAL;AAAoB;AAAC,UAASE,YAAT,GAAuB,CAAE,cAAatX,SAAb,CAAuBuQ,SAAvB,GAAiC8G,aAAjC;AAC/sC;;AAEA,SAASE,WAAT,CAAqBnX,CAArB,EAAuBS,CAAvB,EAAyB;AAAC,SAAO,IAAI2I,UAAJ,CAAepJ,CAAf,EAAiBS,CAAjB,CAAP;AAA2B,UAAS2W,OAAT,CAAiBlX,CAAjB,EAAmBP,CAAnB,EAAqB;AAAC,MAAIc,IAAE,EAAN,CAAS,IAAIT,IAAE,CAAN,CAAQ,OAAMA,IAAEL,CAAF,GAAIO,EAAEI,MAAZ,EAAmB;AAACG,SAAGP,EAAE0I,SAAF,CAAY5I,CAAZ,EAAcA,IAAEL,CAAhB,IAAmB,IAAtB,CAA2BK,KAAGL,CAAH;AAAK,UAAOc,IAAEP,EAAE0I,SAAF,CAAY5I,CAAZ,EAAcE,EAAEI,MAAhB,CAAT;AAAiC,UAAS+W,QAAT,CAAkB5W,CAAlB,EAAoB;AAAC,MAAGA,IAAE,EAAL,EAAQ;AAAC,WAAM,MAAIA,EAAEc,QAAF,CAAW,EAAX,CAAV;AAAyB,GAAlC,MAAsC;AAAC,WAAOd,EAAEc,QAAF,CAAW,EAAX,CAAP;AAAsB;AAAC,UAAS+V,SAAT,CAAmBrX,CAAnB,EAAqBT,CAArB,EAAuB;AAAC,MAAGA,IAAES,EAAEK,MAAF,GAAS,EAAd,EAAiB;AAAC,UAAK,0BAAL,CAAgC,OAAO,IAAP;AAAY,OAAIf,IAAE,IAAIyJ,KAAJ,EAAN,CAAkB,IAAIrJ,IAAEM,EAAEK,MAAF,GAAS,CAAf,CAAiB,OAAMX,KAAG,CAAH,IAAMH,IAAE,CAAd,EAAgB;AAAC,QAAIC,IAAEQ,EAAEiD,UAAF,CAAavD,GAAb,CAAN,CAAwB,IAAGF,IAAE,GAAL,EAAS;AAACF,QAAE,EAAEC,CAAJ,IAAOC,CAAP;AAAS,KAAnB,MAAuB;AAAC,UAAIA,IAAE,GAAH,IAAUA,IAAE,IAAf,EAAqB;AAACF,UAAE,EAAEC,CAAJ,IAAQC,IAAE,EAAH,GAAO,GAAd,CAAkBF,EAAE,EAAEC,CAAJ,IAAQC,KAAG,CAAJ,GAAO,GAAd;AAAkB,OAA1D,MAA8D;AAACF,UAAE,EAAEC,CAAJ,IAAQC,IAAE,EAAH,GAAO,GAAd,CAAkBF,EAAE,EAAEC,CAAJ,IAASC,KAAG,CAAJ,GAAO,EAAR,GAAY,GAAnB,CAAuBF,EAAE,EAAEC,CAAJ,IAAQC,KAAG,EAAJ,GAAQ,GAAf;AAAmB;AAAC;AAAC,KAAE,EAAED,CAAJ,IAAO,CAAP,CAAS,IAAIQ,IAAE,IAAIkX,YAAJ,EAAN,CAAyB,IAAIzW,IAAE,IAAIuI,KAAJ,EAAN,CAAkB,OAAMxJ,IAAE,CAAR,EAAU;AAACiB,MAAE,CAAF,IAAK,CAAL,CAAO,OAAMA,EAAE,CAAF,KAAM,CAAZ,EAAc;AAACT,QAAEmQ,SAAF,CAAY1P,CAAZ;AAAe,OAAE,EAAEjB,CAAJ,IAAOiB,EAAE,CAAF,CAAP;AAAY,KAAE,EAAEjB,CAAJ,IAAO,CAAP,CAASD,EAAE,EAAEC,CAAJ,IAAO,CAAP,CAAS,OAAO,IAAI4J,UAAJ,CAAe7J,CAAf,CAAP;AAAyB,UAASgY,aAAT,CAAuBrX,CAAvB,EAAyBO,CAAzB,EAA2BR,CAA3B,EAA6B;AAAC,MAAID,IAAE,EAAN;AAAA,MAASL,IAAE,CAAX,CAAa,OAAMK,EAAEM,MAAF,GAASG,CAAf,EAAiB;AAACT,SAAGC,EAAE+C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiC9C,EAAE2B,MAAF,CAAS,CAAC,CAAClC,IAAE,UAAH,KAAgB,EAAjB,EAAoB,CAACA,IAAE,QAAH,KAAc,EAAlC,EAAqC,CAACA,IAAE,KAAH,KAAW,CAAhD,EAAkDA,IAAE,GAApD,CAAT,CAAjC,CAAF,CAAH,CAA2GA,KAAG,CAAH;AAAK,UAAOK,CAAP;AAAS,UAASwX,QAAT,CAAkBzV,CAAlB,EAAoBtB,CAApB,EAAsBhB,CAAtB,EAAwBc,CAAxB,EAA0B;AAAC,MAAIL,IAAEuX,KAAKf,MAAL,CAAYgB,aAAlB,CAAgC,IAAI3W,IAAE0W,KAAKf,MAAL,CAAYiB,IAAlB,CAAuB,IAAI3X,IAAE,IAAN,CAAW,IAAG,CAACP,CAAJ,EAAM;AAACA,QAAE,MAAF;AAAS,OAAG,OAAOA,CAAP,KAAW,QAAd,EAAuB;AAACO,QAAEE,EAAE0X,mBAAF,CAAsBnY,CAAtB,CAAF,CAA2Bc,IAAEL,EAAE2X,aAAF,CAAgB7X,CAAhB,CAAF,CAAqBP,IAAE,WAASY,CAAT,EAAW;AAAC,aAAOyX,UAAU/W,EAAEgX,OAAF,CAAUC,UAAU3X,CAAV,CAAV,EAAuBL,CAAvB,CAAV,CAAP;AAA4C,KAA1D;AAA2D,OAAG+B,EAAEzB,MAAF,GAAS,IAAEC,CAAX,GAAa,CAAb,GAAeE,CAAlB,EAAoB;AAAC,UAAK,0BAAL;AAAgC,OAAID,IAAE,EAAN;AAAA,MAASP,CAAT,CAAW,KAAIA,IAAE,CAAN,EAAQA,IAAEQ,IAAEsB,EAAEzB,MAAJ,GAAW,IAAEC,CAAb,GAAe,CAAzB,EAA2BN,KAAG,CAA9B,EAAgC;AAACO,SAAG,MAAH;AAAU,OAAIhB,IAAEC,EAAE,EAAF,IAAMe,CAAN,GAAQ,MAAR,GAAeuB,CAArB,CAAuB,IAAIxC,IAAE,IAAIyJ,KAAJ,CAAUzI,CAAV,CAAN,CAAmB,IAAI2W,YAAJ,GAAmB/G,SAAnB,CAA6B5Q,CAA7B,EAAgC,IAAIa,IAAEmX,cAAchY,CAAd,EAAgBC,EAAEc,MAAlB,EAAyBb,CAAzB,CAAN,CAAkC,IAAIqB,IAAE,EAAN,CAAS,KAAIb,IAAE,CAAN,EAAQA,IAAET,EAAEc,MAAZ,EAAmBL,KAAG,CAAtB,EAAwB;AAACa,MAAEb,CAAF,IAAKT,EAAE0D,UAAF,CAAajD,CAAb,IAAgBG,EAAE8C,UAAF,CAAajD,CAAb,CAArB;AAAqC,OAAIuC,IAAE+U,cAAczW,CAAd,EAAgBvB,EAAEe,MAAlB,EAAyBb,CAAzB,CAAN,CAAkC,IAAIE,IAAE,CAAC,CAAD,CAAN,CAAU,KAAIM,IAAE,CAAN,EAAQA,IAAEV,EAAEe,MAAZ,EAAmBL,KAAG,CAAtB,EAAwB;AAACN,MAAEM,IAAE,CAAJ,IAAOV,EAAEU,CAAF,IAAKuC,EAAEU,UAAF,CAAajD,CAAb,CAAZ;AAA4B,UAAO,IAAImJ,UAAJ,CAAezJ,EAAEkC,MAAF,CAASf,CAAT,CAAf,CAAP;AAAmC,UAASmX,MAAT,GAAiB;AAAC,OAAKpX,CAAL,GAAO,IAAP,CAAY,KAAKZ,CAAL,GAAO,CAAP,CAAS,KAAKN,CAAL,GAAO,IAAP,CAAY,KAAKmB,CAAL,GAAO,IAAP,CAAY,KAAKiB,CAAL,GAAO,IAAP,CAAY,KAAKmW,IAAL,GAAU,IAAV,CAAe,KAAKC,IAAL,GAAU,IAAV,CAAe,KAAKC,KAAL,GAAW,IAAX;AAAgB,UAASC,YAAT,CAAsBrY,CAAtB,EAAwBS,CAAxB,EAA0B;AAAC,OAAK6X,QAAL,GAAc,IAAd,CAAmB,KAAKC,SAAL,GAAe,KAAf,CAAqB,IAAG,OAAOvY,CAAP,KAAW,QAAd,EAAuB;AAAC,SAAKa,CAAL,GAAOb,CAAP,CAAS,KAAKC,CAAL,GAAOQ,CAAP;AAAS,GAA1C,MAA8C;AAAC,QAAGT,KAAG,IAAH,IAASS,KAAG,IAAZ,IAAkBT,EAAEM,MAAF,GAAS,CAA3B,IAA8BG,EAAEH,MAAF,GAAS,CAA1C,EAA4C;AAAC,WAAKO,CAAL,GAAOsW,YAAYnX,CAAZ,EAAc,EAAd,CAAP,CAAyB,KAAKC,CAAL,GAAO4C,SAASpC,CAAT,EAAW,EAAX,CAAP;AAAsB,KAA5F,MAAgG;AAAC,YAAK,wBAAL;AAA8B;AAAC;AAAC,UAAS+X,WAAT,CAAqB/X,CAArB,EAAuB;AAAC,SAAOA,EAAEoO,SAAF,CAAY,KAAK5O,CAAjB,EAAmB,KAAKY,CAAxB,CAAP;AAAkC,UAAS4X,UAAT,CAAoB9Y,CAApB,EAAsB;AAAC,MAAIc,IAAE6W,UAAU3X,CAAV,EAAa,KAAKkB,CAAL,CAAO+N,SAAP,KAAmB,CAApB,IAAwB,CAApC,CAAN,CAA6C,IAAGnO,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAIR,IAAE,KAAKyY,QAAL,CAAcjY,CAAd,CAAN,CAAuB,IAAGR,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAID,IAAEC,EAAEsB,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG,CAACvB,EAAEM,MAAF,GAAS,CAAV,KAAc,CAAjB,EAAmB;AAAC,WAAON,CAAP;AAAS,GAA7B,MAAiC;AAAC,WAAM,MAAIA,CAAV;AAAY;AAAC,UAAS2Y,cAAT,CAAwBlZ,CAAxB,EAA0BQ,CAA1B,EAA4BD,CAA5B,EAA8B;AAAC,MAAIS,IAAE+W,SAAS/X,CAAT,EAAY,KAAKoB,CAAL,CAAO+N,SAAP,KAAmB,CAApB,IAAwB,CAAnC,EAAqC3O,CAArC,EAAuCD,CAAvC,CAAN,CAAgD,IAAGS,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAIlB,IAAE,KAAKmZ,QAAL,CAAcjY,CAAd,CAAN,CAAuB,IAAGlB,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAII,IAAEJ,EAAEgC,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG,CAAC5B,EAAEW,MAAF,GAAS,CAAV,KAAc,CAAjB,EAAmB;AAAC,WAAOX,CAAP;AAAS,GAA7B,MAAiC;AAAC,WAAM,MAAIA,CAAV;AAAY;AAAC,QAAOC,SAAP,CAAiB8Y,QAAjB,GAA0BF,WAA1B,CAAsCP,OAAOrY,SAAP,CAAiBgZ,SAAjB,GAA2BP,YAA3B,CAAwCJ,OAAOrY,SAAP,CAAiBiZ,OAAjB,GAAyBJ,UAAzB,CAAoCR,OAAOrY,SAAP,CAAiBkZ,WAAjB,GAA6BH,cAA7B,CAA4CV,OAAOrY,SAAP,CAAiBmZ,IAAjB,GAAsB,KAAtB;AAC3gF;;AAEA,SAASC,gBAAT,CAA0BhZ,CAA1B,EAA4BS,CAA5B,EAA8B;AAAC,OAAKsD,CAAL,GAAOtD,CAAP,CAAS,KAAKsB,CAAL,GAAO/B,CAAP;AAAS,UAASiZ,UAAT,CAAoBxY,CAApB,EAAsB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,UAAO,KAAKsB,CAAL,CAAO8S,MAAP,CAAcpU,EAAEsB,CAAhB,KAAoB,KAAKgC,CAAL,CAAO8Q,MAAP,CAAcpU,EAAEsD,CAAhB,CAA3B;AAA+C,UAASmV,gBAAT,GAA2B;AAAC,SAAO,KAAKnV,CAAZ;AAAc,UAASoV,UAAT,GAAqB;AAAC,SAAO,IAAIH,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOoH,MAAP,GAAgB2B,GAAhB,CAAoB,KAAK/K,CAAzB,CAA5B,CAAP;AAAgE,UAASqX,OAAT,CAAiB3Y,CAAjB,EAAmB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOkQ,GAAP,CAAWxT,EAAE4Y,YAAF,EAAX,EAA6BvM,GAA7B,CAAiC,KAAK/K,CAAtC,CAA5B,CAAP;AAA6E,UAASuX,YAAT,CAAsB7Y,CAAtB,EAAwB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOiQ,QAAP,CAAgBvT,EAAE4Y,YAAF,EAAhB,EAAkCvM,GAAlC,CAAsC,KAAK/K,CAA3C,CAA5B,CAAP;AAAkF,UAASwX,YAAT,CAAsB9Y,CAAtB,EAAwB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOwR,QAAP,CAAgB9U,EAAE4Y,YAAF,EAAhB,EAAkCvM,GAAlC,CAAsC,KAAK/K,CAA3C,CAA5B,CAAP;AAAkF,UAASyX,UAAT,GAAqB;AAAC,SAAO,IAAIR,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAO6R,MAAP,GAAgB9I,GAAhB,CAAoB,KAAK/K,CAAzB,CAA5B,CAAP;AAAgE,UAAS0X,UAAT,CAAoBhZ,CAApB,EAAsB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOwR,QAAP,CAAgB9U,EAAE4Y,YAAF,GAAiB3D,UAAjB,CAA4B,KAAK3T,CAAjC,CAAhB,EAAqD+K,GAArD,CAAyD,KAAK/K,CAA9D,CAA5B,CAAP;AAAqG,kBAAiBnC,SAAjB,CAA2BiV,MAA3B,GAAkCoE,UAAlC,CAA6CD,iBAAiBpZ,SAAjB,CAA2ByZ,YAA3B,GAAwCH,gBAAxC,CAAyDF,iBAAiBpZ,SAAjB,CAA2BuL,MAA3B,GAAkCgO,UAAlC,CAA6CH,iBAAiBpZ,SAAjB,CAA2BqU,GAA3B,GAA+BmF,OAA/B,CAAuCJ,iBAAiBpZ,SAAjB,CAA2BoU,QAA3B,GAAoCsF,YAApC,CAAiDN,iBAAiBpZ,SAAjB,CAA2B2V,QAA3B,GAAoCgE,YAApC,CAAiDP,iBAAiBpZ,SAAjB,CAA2BgW,MAA3B,GAAkC4D,UAAlC,CAA6CR,iBAAiBpZ,SAAjB,CAA2BuT,MAA3B,GAAkCsG,UAAlC,CAA6C,SAASC,SAAT,CAAmBxZ,CAAnB,EAAqBO,CAArB,EAAuBd,CAAvB,EAAyBK,CAAzB,EAA2B;AAAC,OAAK2Z,KAAL,GAAWzZ,CAAX,CAAa,KAAK6D,CAAL,GAAOtD,CAAP,CAAS,KAAKiH,CAAL,GAAO/H,CAAP,CAAS,IAAGK,KAAG,IAAN,EAAW;AAAC,SAAKwH,CAAL,GAAO4B,WAAWmD,GAAlB;AAAsB,GAAlC,MAAsC;AAAC,SAAK/E,CAAL,GAAOxH,CAAP;AAAS,QAAK4Z,IAAL,GAAU,IAAV;AAAe,UAASC,WAAT,GAAsB;AAAC,MAAG,KAAKD,IAAL,IAAW,IAAd,EAAmB;AAAC,SAAKA,IAAL,GAAU,KAAKpS,CAAL,CAAOkO,UAAP,CAAkB,KAAKiE,KAAL,CAAW5X,CAA7B,CAAV;AAA0C,UAAO,KAAK4X,KAAL,CAAWG,cAAX,CAA0B,KAAK/V,CAAL,CAAOsV,YAAP,GAAsB9D,QAAtB,CAA+B,KAAKqE,IAApC,EAA0C9M,GAA1C,CAA8C,KAAK6M,KAAL,CAAW5X,CAAzD,CAA1B,CAAP;AAA8F,UAASgY,WAAT,GAAsB;AAAC,MAAG,KAAKH,IAAL,IAAW,IAAd,EAAmB;AAAC,SAAKA,IAAL,GAAU,KAAKpS,CAAL,CAAOkO,UAAP,CAAkB,KAAKiE,KAAL,CAAW5X,CAA7B,CAAV;AAA0C,UAAO,KAAK4X,KAAL,CAAWG,cAAX,CAA0B,KAAKpS,CAAL,CAAO2R,YAAP,GAAsB9D,QAAtB,CAA+B,KAAKqE,IAApC,EAA0C9M,GAA1C,CAA8C,KAAK6M,KAAL,CAAW5X,CAAzD,CAA1B,CAAP;AAA8F,UAASiY,aAAT,CAAuBvZ,CAAvB,EAAyB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKwZ,UAAL,EAAH,EAAqB;AAAC,WAAOxZ,EAAEwZ,UAAF,EAAP;AAAsB,OAAGxZ,EAAEwZ,UAAF,EAAH,EAAkB;AAAC,WAAO,KAAKA,UAAL,EAAP;AAAyB,OAAI/Z,CAAJ,EAAMF,CAAN,CAAQE,IAAEO,EAAEiH,CAAF,CAAI2R,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKtM,CAAL,CAAO2R,YAAP,GAAsB9D,QAAtB,CAA+B9U,EAAE+G,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAF,CAAsG,IAAG,CAAC7B,EAAE2U,MAAF,CAASzL,WAAW2B,IAApB,CAAJ,EAA8B;AAAC,WAAO,KAAP;AAAa,OAAEtK,EAAEsD,CAAF,CAAIsV,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKjQ,CAAL,CAAOsV,YAAP,GAAsB9D,QAAtB,CAA+B9U,EAAE+G,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAF,CAAsG,OAAO/B,EAAE6U,MAAF,CAASzL,WAAW2B,IAApB,CAAP;AAAiC,UAASmP,iBAAT,GAA4B;AAAC,MAAI,KAAKnW,CAAL,IAAQ,IAAT,IAAiB,KAAK2D,CAAL,IAAQ,IAA5B,EAAkC;AAAC,WAAO,IAAP;AAAY,UAAO,KAAKF,CAAL,CAAOqN,MAAP,CAAczL,WAAW2B,IAAzB,KAAgC,CAAC,KAAKrD,CAAL,CAAO2R,YAAP,GAAsBxE,MAAtB,CAA6BzL,WAAW2B,IAAxC,CAAxC;AAAsF,UAASoP,aAAT,GAAwB;AAAC,SAAO,IAAIT,SAAJ,CAAc,KAAKC,KAAnB,EAAyB,KAAK5V,CAA9B,EAAgC,KAAK2D,CAAL,CAAOyD,MAAP,EAAhC,EAAgD,KAAK3D,CAArD,CAAP;AAA+D,UAAS4S,UAAT,CAAoB7Z,CAApB,EAAsB;AAAC,MAAG,KAAK0Z,UAAL,EAAH,EAAqB;AAAC,WAAO1Z,CAAP;AAAS,OAAGA,EAAE0Z,UAAF,EAAH,EAAkB;AAAC,WAAO,IAAP;AAAY,OAAInZ,IAAEP,EAAEmH,CAAF,CAAI2R,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKtM,CAAL,CAAO2R,YAAP,GAAsB9D,QAAtB,CAA+BhV,EAAEiH,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAN,CAA0G,IAAIhB,IAAER,EAAEwD,CAAF,CAAIsV,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKjQ,CAAL,CAAOsV,YAAP,GAAsB9D,QAAtB,CAA+BhV,EAAEiH,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAN,CAA0G,IAAGqH,WAAW2B,IAAX,CAAgB8J,MAAhB,CAAuB9T,CAAvB,CAAH,EAA6B;AAAC,QAAGqI,WAAW2B,IAAX,CAAgB8J,MAAhB,CAAuB/T,CAAvB,CAAH,EAA6B;AAAC,aAAO,KAAKuZ,KAAL,EAAP;AAAoB,YAAO,KAAKV,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAIla,IAAE,IAAIgJ,UAAJ,CAAe,GAAf,CAAN,CAA0B,IAAInJ,IAAE,KAAK8D,CAAL,CAAOsV,YAAP,EAAN,CAA4B,IAAIxY,IAAE,KAAK6G,CAAL,CAAO2R,YAAP,EAAN,CAA4B,IAAInZ,IAAEK,EAAEwD,CAAF,CAAIsV,YAAJ,EAAN,CAAyB,IAAI7Y,IAAED,EAAEmH,CAAF,CAAI2R,YAAJ,EAAN,CAAyB,IAAI7W,IAAEzB,EAAE6U,MAAF,EAAN,CAAiB,IAAIvV,IAAEmC,EAAE+S,QAAF,CAAWxU,CAAX,CAAN,CAAoB,IAAIpB,IAAEM,EAAEsV,QAAF,CAAW/S,CAAX,CAAN,CAAoB,IAAIjD,IAAEuB,EAAE8U,MAAF,GAAWL,QAAX,CAAoB,KAAK/N,CAAzB,CAAN,CAAkC,IAAI/G,IAAElB,EAAEyU,QAAF,CAAWrU,EAAEqQ,SAAF,CAAY,CAAZ,CAAX,EAA2BuF,QAA3B,CAAoChV,EAAEiH,CAAtC,EAAyCwM,QAAzC,CAAkD3T,CAAlD,EAAqDkV,QAArD,CAA8DxU,CAA9D,EAAiE+L,GAAjE,CAAqE,KAAK6M,KAAL,CAAW5X,CAAhF,CAAN,CAAyF,IAAIvC,IAAEG,EAAE4V,QAAF,CAAWnV,CAAX,EAAcmV,QAAd,CAAuBzU,CAAvB,EAA0BkT,QAA1B,CAAmCnT,EAAE0U,QAAF,CAAWlV,CAAX,CAAnC,EAAkD2T,QAAlD,CAA2DzU,EAAEgW,QAAF,CAAWzU,CAAX,CAA3D,EAA0EyU,QAA1E,CAAmFhV,EAAEiH,CAArF,EAAwFyM,GAAxF,CAA4FnT,EAAEyU,QAAF,CAAWlV,CAAX,CAA5F,EAA2GyM,GAA3G,CAA+G,KAAK6M,KAAL,CAAW5X,CAA1H,CAAN,CAAmI,IAAItC,IAAEY,EAAEkV,QAAF,CAAW,KAAK/N,CAAhB,EAAmB+N,QAAnB,CAA4BhV,EAAEiH,CAA9B,EAAiCsF,GAAjC,CAAqC,KAAK6M,KAAL,CAAW5X,CAAhD,CAAN,CAAyD,OAAO,IAAI2X,SAAJ,CAAc,KAAKC,KAAnB,EAAyB,KAAKA,KAAL,CAAWG,cAAX,CAA0BrZ,CAA1B,CAAzB,EAAsD,KAAKkZ,KAAL,CAAWG,cAAX,CAA0Bta,CAA1B,CAAtD,EAAmFC,CAAnF,CAAP;AAA6F,UAAS8a,YAAT,GAAuB;AAAC,MAAG,KAAKN,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKvS,CAAL,CAAO2R,YAAP,GAAsB9J,MAAtB,MAAgC,CAAnC,EAAqC;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAE,IAAI6J,UAAJ,CAAe,GAAf,CAAN,CAA0B,IAAIlJ,IAAE,KAAK6D,CAAL,CAAOsV,YAAP,EAAN,CAA4B,IAAI7Z,IAAE,KAAKkI,CAAL,CAAO2R,YAAP,EAAN,CAA4B,IAAIpZ,IAAET,EAAE+V,QAAF,CAAW,KAAK/N,CAAhB,CAAN,CAAyB,IAAIpH,IAAEH,EAAEsV,QAAF,CAAW/V,CAAX,EAAcsN,GAAd,CAAkB,KAAK6M,KAAL,CAAW5X,CAA7B,CAAN,CAAsC,IAAI1B,IAAE,KAAKsZ,KAAL,CAAWlZ,CAAX,CAAa4Y,YAAb,EAAN,CAAkC,IAAI7Y,IAAEN,EAAE0V,MAAF,GAAWL,QAAX,CAAoBhW,CAApB,CAAN,CAA6B,IAAG,CAAC6J,WAAW2B,IAAX,CAAgB8J,MAAhB,CAAuBxU,CAAvB,CAAJ,EAA8B;AAACG,QAAEA,EAAEyT,GAAF,CAAM,KAAKzM,CAAL,CAAOoO,MAAP,GAAgBL,QAAhB,CAAyBlV,CAAzB,CAAN,CAAF;AAAqC,OAAEG,EAAEsM,GAAF,CAAM,KAAK6M,KAAL,CAAW5X,CAAjB,CAAF,CAAsB,IAAI/B,IAAEQ,EAAEoV,MAAF,GAAW5B,QAAX,CAAoB9T,EAAE8P,SAAF,CAAY,CAAZ,EAAeuF,QAAf,CAAwBnV,CAAxB,CAApB,EAAgD4P,SAAhD,CAA0D,CAA1D,EAA6DuF,QAA7D,CAAsEtV,CAAtE,EAAyE6M,GAAzE,CAA6E,KAAK6M,KAAL,CAAW5X,CAAxF,CAAN,CAAiG,IAAItC,IAAEe,EAAE+U,QAAF,CAAWhW,CAAX,EAAcgW,QAAd,CAAuBrV,CAAvB,EAA0B8T,QAA1B,CAAmC5T,EAAE4P,SAAF,CAAY,CAAZ,CAAnC,EAAmDA,SAAnD,CAA6D,CAA7D,EAAgEuF,QAAhE,CAAyEnV,CAAzE,EAA4E4T,QAA5E,CAAqFxT,EAAEoV,MAAF,GAAWL,QAAX,CAAoB/U,CAApB,CAArF,EAA6GsM,GAA7G,CAAiH,KAAK6M,KAAL,CAAW5X,CAA5H,CAAN,CAAqI,IAAIpC,IAAEM,EAAE2V,MAAF,GAAWL,QAAX,CAAoBtV,CAApB,EAAuB+P,SAAvB,CAAiC,CAAjC,EAAoClD,GAApC,CAAwC,KAAK6M,KAAL,CAAW5X,CAAnD,CAAN,CAA4D,OAAO,IAAI2X,SAAJ,CAAc,KAAKC,KAAnB,EAAyB,KAAKA,KAAL,CAAWG,cAAX,CAA0B9Z,CAA1B,CAAzB,EAAsD,KAAK2Z,KAAL,CAAWG,cAAX,CAA0Bra,CAA1B,CAAtD,EAAmFE,CAAnF,CAAP;AAA6F,UAAS6a,eAAT,CAAyBxa,CAAzB,EAA2B;AAAC,MAAG,KAAKia,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAGja,EAAEuP,MAAF,MAAY,CAAf,EAAiB;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAES,CAAN,CAAQ,IAAIP,IAAEF,EAAEgW,QAAF,CAAW,IAAInM,UAAJ,CAAe,GAAf,CAAX,CAAN,CAAsC,IAAI7I,IAAE,KAAK4K,MAAL,EAAN,CAAoB,IAAIxL,IAAE,IAAN,CAAW,IAAIO,CAAJ,CAAM,KAAIA,IAAET,EAAEmP,SAAF,KAAc,CAApB,EAAsB1O,IAAE,CAAxB,EAA0B,EAAEA,CAA5B,EAA8B;AAACP,QAAEA,EAAE0a,KAAF,EAAF,CAAY,IAAI5Z,IAAEhB,EAAEqQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAIE,IAAEb,EAAEuQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAGO,KAAGL,CAAN,EAAQ;AAACT,UAAEA,EAAEsU,GAAF,CAAMxT,IAAE,IAAF,GAAOF,CAAb,CAAF;AAAkB;AAAC,UAAOZ,CAAP;AAAS,UAAS8a,kBAAT,CAA4Bva,CAA5B,EAA8BO,CAA9B,EAAgCT,CAAhC,EAAkC;AAAC,MAAIL,CAAJ,CAAM,IAAGO,EAAE0O,SAAF,KAAc5O,EAAE4O,SAAF,EAAjB,EAA+B;AAACjP,QAAEO,EAAE0O,SAAF,KAAc,CAAhB;AAAkB,GAAlD,MAAsD;AAACjP,QAAEK,EAAE4O,SAAF,KAAc,CAAhB;AAAkB,OAAInP,IAAE,KAAKka,KAAL,CAAWW,WAAX,EAAN,CAA+B,IAAIra,IAAE,KAAKgU,GAAL,CAASxT,CAAT,CAAN,CAAkB,OAAMd,KAAG,CAAT,EAAW;AAACF,QAAEA,EAAE4a,KAAF,EAAF,CAAY,IAAGna,EAAE4P,OAAF,CAAUnQ,CAAV,CAAH,EAAgB;AAAC,UAAGK,EAAE8P,OAAF,CAAUnQ,CAAV,CAAH,EAAgB;AAACF,YAAEA,EAAEwU,GAAF,CAAMhU,CAAN,CAAF;AAAW,OAA5B,MAAgC;AAACR,YAAEA,EAAEwU,GAAF,CAAM,IAAN,CAAF;AAAc;AAAC,KAAjE,MAAqE;AAAC,UAAGjU,EAAE8P,OAAF,CAAUnQ,CAAV,CAAH,EAAgB;AAACF,YAAEA,EAAEwU,GAAF,CAAMxT,CAAN,CAAF;AAAW;AAAC,OAAEd,CAAF;AAAI,UAAOF,CAAP;AAAS,WAAUG,SAAV,CAAoB8a,IAApB,GAAyBb,WAAzB,CAAqCH,UAAU9Z,SAAV,CAAoB+a,IAApB,GAAyBZ,WAAzB,CAAqCL,UAAU9Z,SAAV,CAAoBiV,MAApB,GAA2BmF,aAA3B,CAAyCN,UAAU9Z,SAAV,CAAoBqa,UAApB,GAA+BC,iBAA/B,CAAiDR,UAAU9Z,SAAV,CAAoBuL,MAApB,GAA2BgP,aAA3B,CAAyCT,UAAU9Z,SAAV,CAAoBqU,GAApB,GAAwBmG,UAAxB,CAAmCV,UAAU9Z,SAAV,CAAoBya,KAApB,GAA0BE,YAA1B,CAAuCb,UAAU9Z,SAAV,CAAoB2V,QAApB,GAA6BiF,eAA7B,CAA6Cd,UAAU9Z,SAAV,CAAoBgb,WAApB,GAAgCH,kBAAhC,CAAmD,SAASI,SAAT,CAAmB5a,CAAnB,EAAqBN,CAArB,EAAuBO,CAAvB,EAAyB;AAAC,OAAK6B,CAAL,GAAO9B,CAAP,CAAS,KAAKQ,CAAL,GAAO,KAAKqZ,cAAL,CAAoBna,CAApB,CAAP,CAA8B,KAAKK,CAAL,GAAO,KAAK8Z,cAAL,CAAoB5Z,CAApB,CAAP,CAA8B,KAAK4a,QAAL,GAAc,IAAIpB,SAAJ,CAAc,IAAd,EAAmB,IAAnB,EAAwB,IAAxB,CAAd;AAA4C,UAASqB,WAAT,GAAsB;AAAC,SAAO,KAAKhZ,CAAZ;AAAc,UAASiZ,WAAT,GAAsB;AAAC,SAAO,KAAKva,CAAZ;AAAc,UAASwa,WAAT,GAAsB;AAAC,SAAO,KAAKjb,CAAZ;AAAc,UAASkb,aAAT,CAAuBza,CAAvB,EAAyB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,UAAO,KAAKsB,CAAL,CAAO8S,MAAP,CAAcpU,EAAEsB,CAAhB,KAAoB,KAAKtB,CAAL,CAAOoU,MAAP,CAAcpU,EAAEA,CAAhB,CAApB,IAAwC,KAAKT,CAAL,CAAO6U,MAAP,CAAcpU,EAAET,CAAhB,CAA/C;AAAmE,UAASmb,kBAAT,GAA6B;AAAC,SAAO,KAAKL,QAAZ;AAAqB,UAASM,qBAAT,CAA+B3a,CAA/B,EAAiC;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4BtB,CAA5B,CAAP;AAAsC,UAAS4a,qBAAT,CAA+B1b,CAA/B,EAAiC;AAAC,UAAOkD,SAASlD,EAAEmD,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAP,GAAmC,KAAK,CAAL;AAAO,aAAO,KAAKgY,QAAZ,CAAqB,KAAK,CAAL,CAAO,KAAK,CAAL;AAAO,aAAO,IAAP,CAAY,KAAK,CAAL,CAAO,KAAK,CAAL,CAAO,KAAK,CAAL;AAAO,UAAIra,IAAE,CAACd,EAAEW,MAAF,GAAS,CAAV,IAAa,CAAnB,CAAqB,IAAIJ,IAAEP,EAAEmD,MAAF,CAAS,CAAT,EAAWrC,CAAX,CAAN,CAAoB,IAAIT,IAAEL,EAAEmD,MAAF,CAASrC,IAAE,CAAX,EAAaA,CAAb,CAAN,CAAsB,OAAO,IAAIiZ,SAAJ,CAAc,IAAd,EAAmB,KAAKI,cAAL,CAAoB,IAAI1Q,UAAJ,CAAelJ,CAAf,EAAiB,EAAjB,CAApB,CAAnB,EAA6D,KAAK4Z,cAAL,CAAoB,IAAI1Q,UAAJ,CAAepJ,CAAf,EAAiB,EAAjB,CAApB,CAA7D,CAAP,CAA+G;AAAQ,aAAO,IAAP,CAApS;AAAiT,WAAUJ,SAAV,CAAoB0b,IAApB,GAAyBP,WAAzB,CAAqCF,UAAUjb,SAAV,CAAoB2b,IAApB,GAAyBP,WAAzB,CAAqCH,UAAUjb,SAAV,CAAoB4b,IAApB,GAAyBP,WAAzB,CAAqCJ,UAAUjb,SAAV,CAAoBiV,MAApB,GAA2BqG,aAA3B,CAAyCL,UAAUjb,SAAV,CAAoB0a,WAApB,GAAgCa,kBAAhC,CAAmDN,UAAUjb,SAAV,CAAoBka,cAApB,GAAmCsB,qBAAnC,CAAyDP,UAAUjb,SAAV,CAAoB6b,cAApB,GAAmCJ,qBAAnC;AAClkM;;AAEArC,iBAAiBpZ,SAAjB,CAA2B8b,aAA3B,GAAyC,YAAU;AAAC,SAAOxW,KAAKc,KAAL,CAAW,CAAC,KAAKqT,YAAL,GAAoBzK,SAApB,KAAgC,CAAjC,IAAoC,CAA/C,CAAP;AAAyD,CAA7G,CAA8G8K,UAAU9Z,SAAV,CAAoB+b,UAApB,GAA+B,UAASzb,CAAT,EAAW;AAAC,MAAIP,IAAE,SAAFA,CAAE,CAASH,CAAT,EAAWC,CAAX,EAAa;AAAC,QAAIF,IAAEC,EAAEoc,mBAAF,EAAN,CAA8B,IAAGnc,IAAEF,EAAEe,MAAP,EAAc;AAACf,UAAEA,EAAE8C,KAAF,CAAQ9C,EAAEe,MAAF,GAASb,CAAjB,CAAF;AAAsB,KAArC,MAAyC;AAAC,aAAMA,IAAEF,EAAEe,MAAV,EAAiB;AAACf,UAAEsc,OAAF,CAAU,CAAV;AAAa;AAAC,YAAOtc,CAAP;AAAS,GAArI,CAAsI,IAAIkB,IAAE,KAAKia,IAAL,GAAYrB,YAAZ,EAAN,CAAiC,IAAIpZ,IAAE,KAAK0a,IAAL,GAAYtB,YAAZ,EAAN,CAAiC,IAAIrZ,IAAEL,EAAEc,CAAF,EAAI,EAAJ,CAAN,CAAc,IAAGP,CAAH,EAAK;AAAC,QAAGD,EAAEyO,MAAF,EAAH,EAAc;AAAC1O,QAAE6b,OAAF,CAAU,CAAV;AAAa,KAA5B,MAAgC;AAAC7b,QAAE6b,OAAF,CAAU,CAAV;AAAa;AAAC,GAArD,MAAyD;AAAC7b,MAAE6b,OAAF,CAAU,CAAV,EAAa7b,IAAEA,EAAE6B,MAAF,CAASlC,EAAEM,CAAF,EAAI,EAAJ,CAAT,CAAF;AAAoB,UAAOD,CAAP;AAAS,CAArW,CAAsW0Z,UAAUoC,UAAV,GAAqB,UAASvc,CAAT,EAAWW,CAAX,EAAa;AAAC,MAAIT,IAAES,EAAE,CAAF,CAAN,CAAW,IAAID,IAAEC,EAAEI,MAAF,GAAS,CAAf,CAAiB,IAAIX,IAAEO,EAAEmC,KAAF,CAAQ,CAAR,EAAU,IAAEpC,IAAE,CAAd,CAAN,CAAuB,IAAID,IAAEE,EAAEmC,KAAF,CAAQ,IAAEpC,IAAE,CAAZ,EAAc,IAAEA,CAAhB,CAAN,CAAyBN,EAAEkc,OAAF,CAAU,CAAV,EAAa7b,EAAE6b,OAAF,CAAU,CAAV,EAAa,IAAIpb,IAAE,IAAI2I,UAAJ,CAAezJ,CAAf,CAAN,CAAwB,IAAIH,IAAE,IAAI4J,UAAJ,CAAepJ,CAAf,CAAN,CAAwB,OAAO,IAAI0Z,SAAJ,CAAcna,CAAd,EAAgBA,EAAEua,cAAF,CAAiBrZ,CAAjB,CAAhB,EAAoClB,EAAEua,cAAF,CAAiBta,CAAjB,CAApC,CAAP;AAAgE,CAAzP,CAA0Pka,UAAUqC,aAAV,GAAwB,UAASxc,CAAT,EAAWW,CAAX,EAAa;AAAC,MAAIT,IAAES,EAAE4C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAI7C,IAAEC,EAAEI,MAAF,GAAS,CAAf,CAAiB,IAAIX,IAAEO,EAAE4C,MAAF,CAAS,CAAT,EAAW7C,IAAE,CAAb,CAAN,CAAsB,IAAID,IAAEE,EAAE4C,MAAF,CAAS,IAAE7C,IAAE,CAAb,EAAeA,IAAE,CAAjB,CAAN,CAA0B,IAAIQ,IAAE,IAAI2I,UAAJ,CAAezJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIH,IAAE,IAAI4J,UAAJ,CAAepJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,OAAO,IAAI0Z,SAAJ,CAAcna,CAAd,EAAgBA,EAAEua,cAAF,CAAiBrZ,CAAjB,CAAhB,EAAoClB,EAAEua,cAAF,CAAiBta,CAAjB,CAApC,CAAP;AAAgE,CAAjP,CAAkPka,UAAU9Z,SAAV,CAAoBoc,KAApB,GAA0B,UAAS9b,CAAT,EAAW;AAAC,MAAG,KAAK+Z,UAAL,EAAH,EAAqB;AAAC,WAAO/Z,CAAP;AAAS,OAAGA,EAAE+Z,UAAF,EAAH,EAAkB;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKlW,CAAL,CAAO8Q,MAAP,CAAc3U,EAAE6D,CAAhB,CAAH,EAAsB;AAAC,QAAG,KAAK2D,CAAL,CAAOmN,MAAP,CAAc3U,EAAEwH,CAAhB,CAAH,EAAsB;AAAC,aAAO,KAAK2S,KAAL,EAAP;AAAoB,YAAO,KAAKV,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAEW,EAAE6D,CAAF,CAAIiQ,QAAJ,CAAa,KAAKjQ,CAAlB,CAAN,CAA2B,IAAI9D,IAAEC,EAAEwH,CAAF,CAAIsM,QAAJ,CAAa,KAAKtM,CAAlB,CAAN,CAA2B,IAAIjH,IAAER,EAAEkT,MAAF,CAAS5T,CAAT,CAAN,CAAkB,IAAII,IAAEc,EAAEmV,MAAF,GAAW5B,QAAX,CAAoB,KAAKjQ,CAAzB,EAA4BiQ,QAA5B,CAAqC9T,EAAE6D,CAAvC,CAAN,CAAgD,IAAItE,IAAEgB,EAAE8U,QAAF,CAAW,KAAKxR,CAAL,CAAOiQ,QAAP,CAAgBrU,CAAhB,CAAX,EAA+BqU,QAA/B,CAAwC,KAAKtM,CAA7C,CAAN,CAAsD,OAAO,IAAIgS,SAAJ,CAAc,KAAKC,KAAnB,EAAyBha,CAAzB,EAA2BF,CAA3B,CAAP;AAAqC,CAAzZ,CAA0Zia,UAAU9Z,SAAV,CAAoBqc,OAApB,GAA4B,YAAU;AAAC,MAAG,KAAKhC,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKvS,CAAL,CAAO2R,YAAP,GAAsB9J,MAAtB,MAAgC,CAAnC,EAAqC;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAIta,IAAE,KAAK2Z,KAAL,CAAWG,cAAX,CAA0B1Q,WAAW8S,OAAX,CAAmB,CAAnB,CAA1B,CAAN,CAAuD,IAAIjc,IAAE,KAAK0Z,KAAL,CAAWG,cAAX,CAA0B1Q,WAAW8S,OAAX,CAAmB,CAAnB,CAA1B,CAAN,CAAuD,IAAIzb,IAAE,KAAKsD,CAAL,CAAO6R,MAAP,GAAgBL,QAAhB,CAAyBtV,CAAzB,EAA4BgU,GAA5B,CAAgC,KAAK0F,KAAL,CAAWlZ,CAA3C,EAA8C0S,MAA9C,CAAqD,KAAKzL,CAAL,CAAO6N,QAAP,CAAgBvV,CAAhB,CAArD,CAAN,CAA+E,IAAIE,IAAEO,EAAEmV,MAAF,GAAW5B,QAAX,CAAoB,KAAKjQ,CAAL,CAAOwR,QAAP,CAAgBvV,CAAhB,CAApB,CAAN,CAA8C,IAAIL,IAAEc,EAAE8U,QAAF,CAAW,KAAKxR,CAAL,CAAOiQ,QAAP,CAAgB9T,CAAhB,CAAX,EAA+B8T,QAA/B,CAAwC,KAAKtM,CAA7C,CAAN,CAAsD,OAAO,IAAIgS,SAAJ,CAAc,KAAKC,KAAnB,EAAyBzZ,CAAzB,EAA2BP,CAA3B,CAAP;AAAqC,CAArd,CAAsd+Z,UAAU9Z,SAAV,CAAoBuc,UAApB,GAA+B,UAASnc,CAAT,EAAW;AAAC,MAAG,KAAKia,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAGja,EAAEuP,MAAF,MAAY,CAAf,EAAiB;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAES,CAAN,CAAQ,IAAIP,IAAEF,EAAEgW,QAAF,CAAW,IAAInM,UAAJ,CAAe,GAAf,CAAX,CAAN,CAAsC,IAAI7I,IAAE,KAAK4K,MAAL,EAAN,CAAoB,IAAIxL,IAAE,IAAN,CAAW,IAAIO,CAAJ,CAAM,KAAIA,IAAET,EAAEmP,SAAF,KAAc,CAApB,EAAsB1O,IAAE,CAAxB,EAA0B,EAAEA,CAA5B,EAA8B;AAACP,QAAEA,EAAE0a,KAAF,EAAF,CAAY,IAAI5Z,IAAEhB,EAAEqQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAIE,IAAEb,EAAEuQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAGO,KAAGL,CAAN,EAAQ;AAACT,UAAEA,EAAEqc,KAAF,CAAQvb,IAAE,IAAF,GAAOF,CAAf,CAAF;AAAoB;AAAC,UAAOZ,CAAP;AAAS,CAA1U,CAA2U+Z,UAAU9Z,SAAV,CAAoBwc,SAApB,GAA8B,YAAU;AAAC,MAAIzc,IAAE,KAAK+a,IAAL,GAAYrB,YAAZ,EAAN,CAAiC,IAAIhZ,IAAE,KAAKsa,IAAL,GAAYtB,YAAZ,EAAN,CAAiC,IAAI5Z,IAAE,KAAKka,KAAL,CAAW4B,IAAX,GAAkBlC,YAAlB,EAAN,CAAuC,IAAInZ,IAAE,KAAKyZ,KAAL,CAAW6B,IAAX,GAAkBnC,YAAlB,EAAN,CAAuC,IAAI7Z,IAAE,KAAKma,KAAL,CAAW2B,IAAX,EAAN,CAAwB,IAAIrb,IAAEI,EAAEkV,QAAF,CAAWlV,CAAX,EAAcyM,GAAd,CAAkBtN,CAAlB,CAAN,CAA2B,IAAID,IAAEI,EAAE4V,QAAF,CAAW5V,CAAX,EAAc4V,QAAd,CAAuB5V,CAAvB,EAA0BsU,GAA1B,CAA8BxU,EAAE8V,QAAF,CAAW5V,CAAX,CAA9B,EAA6CsU,GAA7C,CAAiD/T,CAAjD,EAAoD4M,GAApD,CAAwDtN,CAAxD,CAAN,CAAiE,OAAOS,EAAE4U,MAAF,CAAStV,CAAT,CAAP;AAAmB,CAAhU,CAAiUma,UAAU9Z,SAAV,CAAoB2B,QAApB,GAA6B,YAAU;AAAC,SAAM,MAAI,KAAKmZ,IAAL,GAAYrB,YAAZ,GAA2B9X,QAA3B,EAAJ,GAA0C,GAA1C,GAA8C,KAAKoZ,IAAL,GAAYtB,YAAZ,GAA2B9X,QAA3B,EAA9C,GAAoF,GAA1F;AAA8F,CAAtI,CAAuImY,UAAU9Z,SAAV,CAAoByc,QAApB,GAA6B,YAAU;AAAC,MAAInc,IAAE,KAAKyZ,KAAL,CAAW2B,IAAX,EAAN,CAAwB,IAAG,KAAKrB,UAAL,EAAH,EAAqB;AAAC,UAAM,IAAIva,KAAJ,CAAU,uBAAV,CAAN;AAAyC,OAAIe,IAAE,KAAKia,IAAL,GAAYrB,YAAZ,EAAN,CAAiC,IAAIrZ,IAAE,KAAK2a,IAAL,GAAYtB,YAAZ,EAAN,CAAiC,IAAG5Y,EAAE6L,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+B9L,EAAE6L,SAAF,CAAYpM,EAAE8T,QAAF,CAAW5K,WAAWmD,GAAtB,CAAZ,IAAwC,CAA1E,EAA4E;AAAC,UAAM,IAAI7M,KAAJ,CAAU,4BAAV,CAAN;AAA8C,OAAGM,EAAEsM,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+BvM,EAAEsM,SAAF,CAAYpM,EAAE8T,QAAF,CAAW5K,WAAWmD,GAAtB,CAAZ,IAAwC,CAA1E,EAA4E;AAAC,UAAM,IAAI7M,KAAJ,CAAU,4BAAV,CAAN;AAA8C,OAAG,CAAC,KAAK0c,SAAL,EAAJ,EAAqB;AAAC,UAAM,IAAI1c,KAAJ,CAAU,4BAAV,CAAN;AAA8C,OAAG,KAAK6V,QAAL,CAAcrV,CAAd,EAAiB+Z,UAAjB,EAAH,EAAiC;AAAC,UAAM,IAAIva,KAAJ,CAAU,sCAAV,CAAN;AAAwD,UAAO,IAAP;AAAY,CAAjmB;AACnkF;;AAEA,IAAI4c,YAAW,YAAU;AAAC,MAAIrc,IAAE,iEAAN,CAAwE,IAAIG,IAAE,wEAAN,CAA+E,IAAIC,IAAE,SAAOD,CAAP,GAAS,KAAf,CAAqB,IAAIT,IAAE,IAAI4c,MAAJ,CAAW,uCAAqCtc,CAArC,GAAuC,GAAvC,GAA2CI,CAA3C,GAA6C,GAAxD,EAA4D,GAA5D,CAAN,CAAuE,IAAIG,IAAE,IAAI+b,MAAJ,CAAW,wBAAX,EAAoC,GAApC,CAAN,CAA+C,IAAIhd,IAAE,EAAC,KAAI,GAAL,EAAS,KAAI,GAAb,EAAiB,MAAK,IAAtB,EAA2BS,GAAE,IAA7B,EAAkCP,GAAE,IAApC,EAAyCoB,GAAE,IAA3C,EAAgDqB,GAAE,IAAlD,EAAuDJ,GAAE,IAAzD,EAAN,CAAqE,SAAStC,CAAT,CAAWe,CAAX,EAAaiC,CAAb,EAAe3B,CAAf,EAAiB;AAAC,WAAO2B,IAAEjD,EAAEiD,CAAF,CAAF,GAAOQ,OAAOC,YAAP,CAAoBJ,SAAShC,CAAT,EAAW,EAAX,CAApB,CAAd;AAAkD,OAAIX,IAAE,IAAI8C,MAAJ,CAAW,EAAX,CAAN,CAAqB,IAAIvC,IAAE,IAAN,CAAW,IAAIhB,IAAE,EAAC,KAAIM,MAAL,EAAY,KAAIiJ,KAAhB,EAAN,CAA6B,IAAIhJ,IAAED,OAAOkB,cAAb,CAA4B,OAAO,UAASiD,CAAT,EAAWnC,CAAX,EAAa;AAAC,QAAIjB,IAAEoD,EAAEsY,KAAF,CAAQ7c,CAAR,CAAN,CAAiB,IAAIoE,CAAJ,CAAM,IAAIE,IAAEnD,EAAE,CAAF,CAAN,CAAW,IAAIP,IAAE,KAAN,CAAY,IAAG,QAAM0D,CAAT,EAAW;AAACF,UAAE,EAAF;AAAK,KAAjB,MAAqB;AAAC,UAAG,QAAME,CAAT,EAAW;AAACF,YAAE,EAAF;AAAK,OAAjB,MAAqB;AAACA,YAAE,EAAF,CAAKxD,IAAE,IAAF;AAAO;AAAC,SAAIuB,CAAJ,CAAM,IAAII,IAAE,CAAC6B,CAAD,CAAN,CAAU,KAAI,IAAIhD,IAAE,IAAER,CAAR,EAAUiC,IAAE1B,EAAER,MAAlB,EAAyBS,IAAEyB,CAA3B,EAA6B,EAAEzB,CAA/B,EAAiC;AAACkD,UAAEnD,EAAEC,CAAF,CAAF,CAAO,IAAI+C,CAAJ,CAAM,QAAOG,EAAEf,UAAF,CAAa,CAAb,CAAP,GAAwB;AAAQY,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,CAAE2D,CAAjB,CAAoBnC,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,EAAL;AAAQmC,cAAEA,EAAE2E,SAAF,CAAY,CAAZ,EAAc3E,EAAE3D,MAAF,GAAS,CAAvB,CAAF,CAA4B,IAAG2D,EAAE0B,OAAF,CAAUlF,CAAV,MAAe,CAAC,CAAnB,EAAqB;AAACwD,gBAAEA,EAAEwY,OAAF,CAAUjc,CAAV,EAAYhB,CAAZ,CAAF;AAAiB,eAAE0C,EAAE,CAAF,CAAF,CAAO,IAAG,CAACJ,CAAJ,EAAM;AAAC,gBAAGgC,aAAakF,KAAhB,EAAsB;AAAClH,kBAAEgC,EAAExD,MAAJ;AAAW,aAAlC,MAAsC;AAACwB,kBAAEmC,KAAG/D,CAAL,CAAO;AAAM;AAAC,aAAE4B,CAAF,IAAKmC,CAAL,CAAOnC,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,EAAL;AAAQgC,cAAE5B,EAAE,CAAF,CAAF,CAAOA,EAAE2Z,OAAF,CAAU/X,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,EAAzB,EAA6BwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,EAAL;AAAQI,YAAEwa,KAAF,GAAU,MAAM,KAAK,GAAL;AAAS5Y,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,KAAf,CAAqBwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASgC,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,IAAf,CAAoBwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASgC,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,IAAf,CAAoBwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASgC,cAAE5B,EAAE,CAAF,CAAF,CAAOA,EAAE2Z,OAAF,CAAU/X,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,EAAzB,EAA6BwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASI,YAAEwa,KAAF,GAAU,MAA1iB;AAAijB,SAAGnc,CAAH,EAAK;AAAC,UAAG2B,EAAE5B,MAAF,KAAW,CAAd,EAAgB;AAAC,cAAM,IAAIZ,KAAJ,EAAN;AAAkB,WAAEqE,EAAE,CAAF,CAAF;AAAO,KAAhD,MAAoD;AAAC,UAAG7B,EAAE5B,MAAL,EAAY;AAAC,cAAM,IAAIZ,KAAJ,EAAN;AAAkB;AAAC,SAAGqC,CAAH,EAAK;AAAC,UAAIC,IAAE,SAAFA,CAAE,CAAS8F,CAAT,EAAWF,CAAX,EAAa;AAAC,YAAII,IAAEF,EAAEF,CAAF,CAAN,CAAW,IAAGI,KAAG,QAAOA,CAAP,yCAAOA,CAAP,OAAW,QAAjB,EAA0B;AAAC,cAAInH,IAAE,IAAN,CAAW,KAAI,IAAI2G,CAAR,IAAaQ,CAAb,EAAe;AAAC,gBAAGhI,EAAEoC,IAAF,CAAO4F,CAAP,EAASR,CAAT,KAAaQ,MAAIF,CAApB,EAAsB;AAAC,kBAAIJ,IAAE1F,EAAEgG,CAAF,EAAIR,CAAJ,CAAN,CAAa,IAAGE,MAAI,KAAK,CAAZ,EAAc;AAACM,kBAAER,CAAF,IAAKE,CAAL;AAAO,eAAtB,MAA0B;AAAC,oBAAG,CAAC7G,CAAJ,EAAM;AAACA,sBAAE,EAAF;AAAK,mBAAE0B,IAAF,CAAOiF,CAAP;AAAU;AAAC;AAAC,eAAG3G,CAAH,EAAK;AAAC,iBAAI,IAAI4G,IAAE5G,EAAEP,MAAZ,EAAmB,EAAEmH,CAAF,IAAK,CAAxB,GAA2B;AAAC,qBAAOO,EAAEnH,EAAE4G,CAAF,CAAF,CAAP;AAAe;AAAC;AAAC,gBAAO1F,EAAEK,IAAF,CAAO0F,CAAP,EAASF,CAAT,EAAWI,CAAX,CAAP;AAAqB,OAApP,CAAqPjE,IAAE/B,EAAE,EAAC,IAAG+B,CAAJ,EAAF,EAAS,EAAT,CAAF;AAAe,YAAOA,CAAP;AAAS,GAAplC;AAAqlC,CAArmD,EAAd;AACA,IAAG,OAAO0T,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UA6E3BA,IA7E2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKkF,IAAZ,IAAkB,WAAlB,IAA+B,CAAClF,KAAKkF,IAAxC,EAA6C;AAAClF,OAAKkF,IAAL,GAAU,EAAV;AAAa,MAAKA,IAAL,CAAUC,QAAV,GAAmB,IAAI,YAAU;AAAC,OAAKC,gBAAL,GAAsB,UAASpc,CAAT,EAAW;AAAC,QAAIT,IAAES,EAAEc,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAIvB,EAAEM,MAAF,GAAS,CAAV,IAAc,CAAjB,EAAmB;AAACN,UAAE,MAAIA,CAAN;AAAQ,YAAOA,CAAP;AAAS,GAA5F,CAA6F,KAAK8c,6BAAL,GAAmC,UAAS1c,CAAT,EAAW;AAAC,QAAIX,IAAEW,EAAEmB,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG9B,EAAEqD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,GAAlB,EAAsB;AAAC,UAAGrD,EAAEa,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACb,YAAE,MAAIA,CAAN;AAAQ,OAA1B,MAA8B;AAAC,YAAG,CAACA,EAAE+c,KAAF,CAAQ,QAAR,CAAJ,EAAsB;AAAC/c,cAAE,OAAKA,CAAP;AAAS;AAAC;AAAC,KAAxF,MAA4F;AAAC,UAAIgB,IAAEhB,EAAEqD,MAAF,CAAS,CAAT,CAAN,CAAkB,IAAI7C,IAAEQ,EAAEH,MAAR,CAAe,IAAGL,IAAE,CAAF,IAAK,CAAR,EAAU;AAACA,aAAG,CAAH;AAAK,OAAhB,MAAoB;AAAC,YAAG,CAACR,EAAE+c,KAAF,CAAQ,QAAR,CAAJ,EAAsB;AAACvc,eAAG,CAAH;AAAK;AAAC,WAAIV,IAAE,EAAN,CAAS,KAAI,IAAII,IAAE,CAAV,EAAYA,IAAEM,CAAd,EAAgBN,GAAhB,EAAoB;AAACJ,aAAG,GAAH;AAAO,WAAIW,IAAE,IAAIkJ,UAAJ,CAAe7J,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIS,IAAEE,EAAE8U,GAAF,CAAM5U,CAAN,EAAS6T,GAAT,CAAa7K,WAAWmD,GAAxB,CAAN,CAAmC9M,IAAEO,EAAEuB,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,IAAvB,EAA4B,EAA5B,CAAF;AAAkC,YAAOhd,CAAP;AAAS,GAAlY,CAAmY,KAAKsd,mBAAL,GAAyB,UAAStc,CAAT,EAAWT,CAAX,EAAa;AAAC,WAAOgd,SAASvc,CAAT,EAAWT,CAAX,CAAP;AAAqB,GAA5D,CAA6D,KAAKid,SAAL,GAAe,UAASzc,CAAT,EAAW;AAAC,QAAIwH,IAAEyP,IAAN;AAAA,QAAW5W,IAAEmH,EAAE2U,IAAf;AAAA,QAAoBnV,IAAE3G,EAAEqc,UAAxB;AAAA,QAAmCjd,IAAEY,EAAEsc,UAAvC;AAAA,QAAkDnb,IAAEnB,EAAEuc,YAAtD;AAAA,QAAmE5d,IAAEqB,EAAEwc,cAAvE;AAAA,QAAsFpZ,IAAEpD,EAAEyc,OAA1F;AAAA,QAAkGxZ,IAAEjD,EAAE0c,mBAAtG;AAAA,QAA0Hhd,IAAEM,EAAE2c,aAA9H;AAAA,QAA4Ije,IAAEsB,EAAE4c,aAAhJ;AAAA,QAA8Jhe,IAAEoB,EAAE6c,gBAAlK;AAAA,QAAmLhW,IAAE7G,EAAE8c,kBAAvL;AAAA,QAA0MzZ,IAAErD,EAAE+c,gBAA9M;AAAA,QAA+N9c,IAAED,EAAEgd,YAAnO;AAAA,QAAgP/V,IAAEjH,EAAEid,UAApP;AAAA,QAA+P1d,IAAES,EAAEkd,kBAAnQ;AAAA,QAAsRvb,IAAE3B,EAAEmd,WAA1R;AAAA,QAAsS9d,IAAEW,EAAEod,MAA1S;AAAA,QAAiT/b,IAAErB,EAAEqd,eAArT;AAAA,QAAqUnd,IAAEF,EAAE+b,QAAF,CAAWK,SAAlV,CAA4V,IAAInb,IAAE/B,OAAOoe,IAAP,CAAY3d,CAAZ,CAAN,CAAqB,IAAGsB,EAAExB,MAAF,IAAU,CAAb,EAAe;AAAC,YAAK,iCAAL;AAAuC,SAAI+F,IAAEvE,EAAE,CAAF,CAAN,CAAW,IAAG,yGAAyG6D,OAAzG,CAAiH,MAAIU,CAAJ,GAAM,GAAvH,KAA6H,CAAC,CAAjI,EAAmI;AAAC,YAAK,oBAAkBA,CAAvB;AAAyB,SAAGA,KAAG,MAAN,EAAa;AAAC,aAAO,IAAImB,CAAJ,CAAMhH,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,KAAN,EAAY;AAAC,aAAO,IAAIpG,CAAJ,CAAMO,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAIrE,CAAJ,CAAMxB,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAI7G,CAAJ,CAAMgB,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,MAAN,EAAa;AAAC,aAAO,IAAIpC,CAAJ,CAAMzD,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,KAAN,EAAY;AAAC,aAAO,IAAIvC,CAAJ,CAAMtD,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,MAAN,EAAa;AAAC,aAAO,IAAI9F,CAAJ,CAAMC,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,SAAN,EAAgB;AAAC,aAAO,IAAI9G,CAAJ,CAAMiB,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAI5G,CAAJ,CAAMe,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAIqB,CAAJ,CAAMlH,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAInC,CAAJ,CAAM1D,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAIvF,CAAJ,CAAMN,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,SAAN,EAAgB;AAAC,aAAO,IAAIyB,CAAJ,CAAMtH,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,SAAN,EAAgB;AAAC,aAAO,IAAIjG,CAAJ,CAAMI,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,KAAN,EAAY;AAAC,UAAI1G,IAAEa,EAAE6F,CAAF,CAAN,CAAW,IAAI6B,IAAE,EAAN,CAAS,KAAI,IAAInE,IAAE,CAAV,EAAYA,IAAEpE,EAAEW,MAAhB,EAAuByD,GAAvB,EAA2B;AAAC,YAAI6D,IAAE7G,EAAEpB,EAAEoE,CAAF,CAAF,CAAN,CAAcmE,EAAE3F,IAAF,CAAOqF,CAAP;AAAU,cAAO,IAAIpF,CAAJ,CAAM,EAAC4b,OAAMlW,CAAP,EAAN,CAAP;AAAwB,SAAG7B,KAAG,KAAN,EAAY;AAAC,UAAI1G,IAAEa,EAAE6F,CAAF,CAAN,CAAW,IAAI6B,IAAE,EAAN,CAAS,KAAI,IAAInE,IAAE,CAAV,EAAYA,IAAEpE,EAAEW,MAAhB,EAAuByD,GAAvB,EAA2B;AAAC,YAAI6D,IAAE7G,EAAEpB,EAAEoE,CAAF,CAAF,CAAN,CAAcmE,EAAE3F,IAAF,CAAOqF,CAAP;AAAU,cAAO,IAAI1H,CAAJ,CAAM,EAACke,OAAMlW,CAAP,EAAN,CAAP;AAAwB,SAAG7B,KAAG,KAAN,EAAY;AAAC,UAAIoB,IAAEjH,EAAE6F,CAAF,CAAN,CAAW,IAAGtG,OAAOH,SAAP,CAAiB2B,QAAjB,CAA0Ba,IAA1B,CAA+BqF,CAA/B,MAAoC,gBAApC,IAAsDA,EAAEnH,MAAF,IAAU,CAAnE,EAAqE;AAAC,YAAIyB,IAAEhB,EAAE0G,EAAE,CAAF,CAAF,CAAN,CAAc,OAAO,IAAIvF,CAAJ,CAAM,EAACmc,KAAI5W,EAAE,CAAF,CAAL,EAAU6W,UAAS7W,EAAE,CAAF,CAAnB,EAAwB8W,KAAIxc,CAA5B,EAAN,CAAP;AAA6C,OAAjI,MAAqI;AAAC,YAAI/B,IAAE,EAAN,CAAS,IAAGyH,EAAE6W,QAAF,KAAalf,SAAhB,EAA0B;AAACY,YAAEse,QAAF,GAAW7W,EAAE6W,QAAb;AAAsB,aAAG7W,EAAE4W,GAAF,KAAQjf,SAAX,EAAqB;AAACY,YAAEqe,GAAF,GAAM5W,EAAE4W,GAAR;AAAY,aAAG5W,EAAE8W,GAAF,KAAQnf,SAAX,EAAqB;AAAC,gBAAK,mCAAL;AAAyC,WAAEmf,GAAF,GAAMxd,EAAE0G,EAAE8W,GAAJ,CAAN,CAAe,OAAO,IAAIrc,CAAJ,CAAMlC,CAAN,CAAP;AAAgB;AAAC;AAAC,GAAhoD,CAAioD,KAAKwe,aAAL,GAAmB,UAASxe,CAAT,EAAW;AAAC,QAAIS,IAAE,KAAKwc,SAAL,CAAejd,CAAf,CAAN,CAAwB,OAAOS,EAAEge,aAAF,EAAP;AAAyB,GAAhF;AAAiF,CAA9vE,EAAnB,CAAkxEhH,KAAKkF,IAAL,CAAUC,QAAV,CAAmB8B,WAAnB,GAA+B,UAASje,CAAT,EAAW;AAAC,MAAIL,IAAE,EAAN,CAAS,IAAII,IAAEqC,SAASpC,EAAEqC,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAN,CAAiC,IAAInD,IAAEuF,KAAKc,KAAL,CAAWxF,IAAE,EAAb,CAAN,CAAuB,IAAIN,IAAEM,IAAE,EAAR,CAAW,IAAIJ,IAAET,IAAE,GAAF,GAAMO,CAAZ,CAAc,IAAID,IAAE,EAAN,CAAS,KAAI,IAAIR,IAAE,CAAV,EAAYA,IAAEgB,EAAEH,MAAhB,EAAuBb,KAAG,CAA1B,EAA4B;AAAC,QAAIF,IAAEsD,SAASpC,EAAEqC,MAAF,CAASrD,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAN,CAAiC,IAAID,IAAE,CAAC,aAAWD,EAAEgC,QAAF,CAAW,CAAX,CAAZ,EAA2Bc,KAA3B,CAAiC,CAAC,CAAlC,CAAN,CAA2CpC,IAAEA,IAAET,EAAEsD,MAAF,CAAS,CAAT,EAAW,CAAX,CAAJ,CAAkB,IAAGtD,EAAEsD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,GAAlB,EAAsB;AAAC,UAAI9C,IAAE,IAAIoJ,UAAJ,CAAenJ,CAAf,EAAiB,CAAjB,CAAN,CAA0BG,IAAEA,IAAE,GAAF,GAAMJ,EAAEuB,QAAF,CAAW,EAAX,CAAR,CAAuBtB,IAAE,EAAF;AAAK;AAAC,UAAOG,CAAP;AAAS,CAAhW,CAAiWqX,KAAKkF,IAAL,CAAUC,QAAV,CAAmB+B,WAAnB,GAA+B,UAASlf,CAAT,EAAW;AAAC,MAAIQ,IAAE,SAAFA,CAAE,CAASQ,CAAT,EAAW;AAAC,QAAID,IAAEC,EAAEc,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAGf,EAAEF,MAAF,IAAU,CAAb,EAAe;AAACE,UAAE,MAAIA,CAAN;AAAQ,YAAOA,CAAP;AAAS,GAAxE,CAAyE,IAAIb,IAAE,SAAFA,CAAE,CAASoB,CAAT,EAAW;AAAC,QAAIF,IAAE,EAAN,CAAS,IAAIL,IAAE,IAAI4I,UAAJ,CAAerI,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIN,IAAED,EAAEe,QAAF,CAAW,CAAX,CAAN,CAAoB,IAAIhB,IAAE,IAAEE,EAAEH,MAAF,GAAS,CAAjB,CAAmB,IAAGC,KAAG,CAAN,EAAQ;AAACA,UAAE,CAAF;AAAI,SAAIwB,IAAE,EAAN,CAAS,KAAI,IAAIS,IAAE,CAAV,EAAYA,IAAEjC,CAAd,EAAgBiC,GAAhB,EAAoB;AAACT,WAAG,GAAH;AAAO,SAAEA,IAAEtB,CAAJ,CAAM,KAAI,IAAI+B,IAAE,CAAV,EAAYA,IAAE/B,EAAEH,MAAF,GAAS,CAAvB,EAAyBkC,KAAG,CAA5B,EAA8B;AAAC,UAAI1B,IAAEL,EAAEqC,MAAF,CAASN,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAGA,KAAG/B,EAAEH,MAAF,GAAS,CAAf,EAAiB;AAACQ,YAAE,MAAIA,CAAN;AAAQ,YAAGb,EAAE4C,SAAS/B,CAAT,EAAW,CAAX,CAAF,CAAH;AAAoB,YAAOD,CAAP;AAAS,GAA/P,CAAgQ,IAAG,CAACpB,EAAE+c,KAAF,CAAQ,WAAR,CAAJ,EAAyB;AAAC,UAAK,2BAAyB/c,CAA9B;AAAgC,OAAIF,IAAE,EAAN,CAAS,IAAIS,IAAEP,EAAEmf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAIxe,IAAEyC,SAAS7C,EAAE,CAAF,CAAT,IAAe,EAAf,GAAkB6C,SAAS7C,EAAE,CAAF,CAAT,CAAxB,CAAuCT,KAAGU,EAAEG,CAAF,CAAH,CAAQJ,EAAEuE,MAAF,CAAS,CAAT,EAAW,CAAX,EAAc,KAAI,IAAIrE,IAAE,CAAV,EAAYA,IAAEF,EAAEM,MAAhB,EAAuBJ,GAAvB,EAA2B;AAACX,SAAGI,EAAEK,EAAEE,CAAF,CAAF,CAAH;AAAW,UAAOX,CAAP;AAAS,CAAvjB,CAAwjBkY,KAAKkF,IAAL,CAAUkC,UAAV,GAAqB,YAAU;AAAC,MAAI3e,IAAE,IAAN,CAAW,IAAIF,IAAE,IAAN,CAAW,IAAIL,IAAE,IAAN,CAAW,IAAIM,IAAE,IAAN,CAAW,IAAIQ,IAAE,EAAN,CAAS,KAAKqe,qBAAL,GAA2B,YAAU;AAAC,QAAG,OAAO,KAAKC,EAAZ,IAAgB,WAAhB,IAA6B,KAAKA,EAAL,IAAS,IAAzC,EAA8C;AAAC,YAAK,+BAAL;AAAqC,SAAG,KAAKA,EAAL,CAAQze,MAAR,GAAe,CAAf,IAAkB,CAArB,EAAuB;AAAC,YAAK,sCAAoCG,EAAEH,MAAtC,GAA6C,KAA7C,GAAmD,KAAKye,EAA7D;AAAgE,SAAI1e,IAAE,KAAK0e,EAAL,CAAQze,MAAR,GAAe,CAArB,CAAuB,IAAId,IAAEa,EAAEkB,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG/B,EAAEc,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACd,UAAE,MAAIA,CAAN;AAAQ,SAAGa,IAAE,GAAL,EAAS;AAAC,aAAOb,CAAP;AAAS,KAAnB,MAAuB;AAAC,UAAID,IAAEC,EAAEc,MAAF,GAAS,CAAf,CAAiB,IAAGf,IAAE,EAAL,EAAQ;AAAC,cAAK,mDAAiDc,EAAEkB,QAAF,CAAW,EAAX,CAAtD;AAAqE,WAAI9B,IAAE,MAAIF,CAAV,CAAY,OAAOE,EAAE8B,QAAF,CAAW,EAAX,IAAe/B,CAAtB;AAAwB;AAAC,GAApb,CAAqb,KAAKif,aAAL,GAAmB,YAAU;AAAC,QAAG,KAAKO,IAAL,IAAW,IAAX,IAAiB,KAAKC,UAAzB,EAAoC;AAAC,WAAKF,EAAL,GAAQ,KAAKG,gBAAL,EAAR,CAAgC,KAAKC,EAAL,GAAQ,KAAKL,qBAAL,EAAR,CAAqC,KAAKE,IAAL,GAAU,KAAKI,EAAL,GAAQ,KAAKD,EAAb,GAAgB,KAAKJ,EAA/B,CAAkC,KAAKE,UAAL,GAAgB,KAAhB;AAAsB,YAAO,KAAKD,IAAZ;AAAiB,GAAjN,CAAkN,KAAKK,WAAL,GAAiB,YAAU;AAAC,SAAKZ,aAAL,GAAqB,OAAO,KAAKM,EAAZ;AAAe,GAAhE,CAAiE,KAAKG,gBAAL,GAAsB,YAAU;AAAC,WAAM,EAAN;AAAS,GAA1C;AAA2C,CAAx0B,CAAy0BzH,KAAKkF,IAAL,CAAU2C,iBAAV,GAA4B,UAASpf,CAAT,EAAW;AAACuX,OAAKkF,IAAL,CAAU2C,iBAAV,CAA4Bxf,UAA5B,CAAuCD,WAAvC,CAAmDuC,IAAnD,CAAwD,IAAxD,EAA8D,IAAIpC,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,KAAK8e,SAAL,GAAe,YAAU;AAAC,WAAO,KAAKvd,CAAZ;AAAc,GAAxC,CAAyC,KAAKwd,SAAL,GAAe,UAAS7f,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAOrC,CAAP,CAAS,KAAKof,EAAL,GAAQU,UAAU,KAAKzd,CAAf,EAAkB0d,WAAlB,EAAR;AAAwC,GAAhH,CAAiH,KAAKC,YAAL,GAAkB,UAAShgB,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAO,IAAP,CAAY,KAAK+c,EAAL,GAAQpf,CAAR;AAAU,GAAxF,CAAyF,KAAKuf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAO7e,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,WAAKsf,SAAL,CAAetf,CAAf;AAAkB,KAAzC,MAA6C;AAAC,UAAG,OAAOA,EAAE0f,GAAT,IAAc,WAAjB,EAA6B;AAAC,aAAKJ,SAAL,CAAetf,EAAE0f,GAAjB;AAAsB,OAApD,MAAwD;AAAC,YAAG,OAAO1f,EAAE2f,GAAT,IAAc,WAAjB,EAA6B;AAAC,eAAKF,YAAL,CAAkBzf,EAAE2f,GAApB;AAAyB;AAAC;AAAC;AAAC;AAAC,CAA5lB,CAA6lB1gB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAU2C,iBAA5B,EAA8C7H,KAAKkF,IAAL,CAAUkC,UAAxD,EAAoEpH,KAAKkF,IAAL,CAAUmD,eAAV,GAA0B,UAAS5f,CAAT,EAAW;AAACuX,OAAKkF,IAAL,CAAUmD,eAAV,CAA0BhgB,UAA1B,CAAqCD,WAArC,CAAiDuC,IAAjD,CAAsD,IAAtD,EAA4D,IAAIpC,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,KAAKsf,cAAL,GAAoB,UAAStgB,CAAT,EAAW;AAACugB,UAAIvgB,EAAEgX,OAAF,KAAahX,EAAEwgB,iBAAF,KAAsB,KAAvC,CAA8C,IAAIhgB,IAAE,IAAIuW,IAAJ,CAASwJ,GAAT,CAAN,CAAoB,OAAO/f,CAAP;AAAS,GAA3G,CAA4G,KAAKigB,UAAL,GAAgB,UAAS1d,CAAT,EAAWzB,CAAX,EAAad,CAAb,EAAe;AAAC,QAAIV,IAAE,KAAK4gB,WAAX,CAAuB,IAAItf,IAAE,KAAKkf,cAAL,CAAoBvd,CAApB,CAAN,CAA6B,IAAI1B,IAAEkC,OAAOnC,EAAEuf,WAAF,EAAP,CAAN,CAA8B,IAAGrf,KAAG,KAAN,EAAY;AAACD,UAAEA,EAAEgC,MAAF,CAAS,CAAT,EAAW,CAAX,CAAF;AAAgB,SAAIvC,IAAEhB,EAAEyD,OAAOnC,EAAEwf,QAAF,KAAa,CAApB,CAAF,EAAyB,CAAzB,CAAN,CAAkC,IAAIte,IAAExC,EAAEyD,OAAOnC,EAAEyf,OAAF,EAAP,CAAF,EAAsB,CAAtB,CAAN,CAA+B,IAAI9gB,IAAED,EAAEyD,OAAOnC,EAAE0f,QAAF,EAAP,CAAF,EAAuB,CAAvB,CAAN,CAAgC,IAAIlgB,IAAEd,EAAEyD,OAAOnC,EAAE2f,UAAF,EAAP,CAAF,EAAyB,CAAzB,CAAN,CAAkC,IAAIpgB,IAAEb,EAAEyD,OAAOnC,EAAE4f,UAAF,EAAP,CAAF,EAAyB,CAAzB,CAAN,CAAkC,IAAIve,IAAEpB,IAAEP,CAAF,GAAIwB,CAAJ,GAAMvC,CAAN,GAAQa,CAAR,GAAUD,CAAhB,CAAkB,IAAGH,MAAI,IAAP,EAAY;AAAC,UAAIR,IAAEoB,EAAE6f,eAAF,EAAN,CAA0B,IAAGjhB,KAAG,CAAN,EAAQ;AAAC,YAAIe,IAAEjB,EAAEyD,OAAOvD,CAAP,CAAF,EAAY,CAAZ,CAAN,CAAqBe,IAAEA,EAAEic,OAAF,CAAU,OAAV,EAAkB,EAAlB,CAAF,CAAwBva,IAAEA,IAAE,GAAF,GAAM1B,CAAR;AAAU;AAAC,YAAO0B,IAAE,GAAT;AAAa,GAA3b,CAA4b,KAAKie,WAAL,GAAiB,UAASlgB,CAAT,EAAWN,CAAX,EAAa;AAAC,QAAGM,EAAEK,MAAF,IAAUX,CAAb,EAAe;AAAC,aAAOM,CAAP;AAAS,YAAO,IAAI+I,KAAJ,CAAUrJ,IAAEM,EAAEK,MAAJ,GAAW,CAArB,EAAwBqC,IAAxB,CAA6B,GAA7B,IAAkC1C,CAAzC;AAA2C,GAAnG,CAAoG,KAAKsf,SAAL,GAAe,YAAU;AAAC,WAAO,KAAKvd,CAAZ;AAAc,GAAxC,CAAyC,KAAKwd,SAAL,GAAe,UAAS7f,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAOrC,CAAP,CAAS,KAAKof,EAAL,GAAQ4B,OAAOhhB,CAAP,CAAR;AAAkB,GAA1F,CAA2F,KAAKihB,cAAL,GAAoB,UAASphB,CAAT,EAAWY,CAAX,EAAaH,CAAb,EAAeN,CAAf,EAAiBF,CAAjB,EAAmBF,CAAnB,EAAqB;AAAC,QAAIc,IAAE,IAAImW,IAAJ,CAASA,KAAKqK,GAAL,CAASrhB,CAAT,EAAWY,IAAE,CAAb,EAAeH,CAAf,EAAiBN,CAAjB,EAAmBF,CAAnB,EAAqBF,CAArB,EAAuB,CAAvB,CAAT,CAAN,CAA0C,KAAKuhB,SAAL,CAAezgB,CAAf;AAAkB,GAAtG,CAAuG,KAAK6e,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD;AAAiD,CAAhiC,CAAiiC5f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUmD,eAA5B,EAA4CrI,KAAKkF,IAAL,CAAUkC,UAAtD,EAAkEpH,KAAKkF,IAAL,CAAUoE,qBAAV,GAAgC,UAAS/gB,CAAT,EAAW;AAACyX,OAAKkF,IAAL,CAAU2C,iBAAV,CAA4Bxf,UAA5B,CAAuCD,WAAvC,CAAmDuC,IAAnD,CAAwD,IAAxD,EAA8D,IAAI3B,IAAE,IAAN,CAAW,KAAKugB,oBAAL,GAA0B,UAAS9gB,CAAT,EAAW;AAAC,SAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKgC,SAAL,GAAe/gB,CAAf;AAAiB,GAA3F,CAA4F,KAAKghB,gBAAL,GAAsB,UAAShhB,CAAT,EAAW;AAAC,SAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKgC,SAAL,CAAe1e,IAAf,CAAoBrC,CAApB;AAAuB,GAA7F,CAA8F,KAAK+gB,SAAL,GAAe,IAAIjY,KAAJ,EAAf,CAA2B,IAAG,OAAOhJ,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAEoe,KAAT,IAAgB,WAAnB,EAA+B;AAAC,WAAK6C,SAAL,GAAejhB,EAAEoe,KAAjB;AAAuB;AAAC;AAAC,CAA7Z,CAA8Zjf,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUoE,qBAA5B,EAAkDtJ,KAAKkF,IAAL,CAAUkC,UAA5D,EAAwEpH,KAAKkF,IAAL,CAAUO,UAAV,GAAqB,YAAU;AAACzF,OAAKkF,IAAL,CAAUO,UAAV,CAAqBpd,UAArB,CAAgCD,WAAhC,CAA4CuC,IAA5C,CAAiD,IAAjD,EAAuD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKJ,IAAL,GAAU,QAAV;AAAmB,CAAvH,CAAwH7f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUO,UAA5B,EAAuCzF,KAAKkF,IAAL,CAAUkC,UAAjD,EAA6DpH,KAAKkF,IAAL,CAAUQ,UAAV,GAAqB,UAAS1c,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUQ,UAAV,CAAqBrd,UAArB,CAAgCD,WAAhC,CAA4CuC,IAA5C,CAAiD,IAAjD,EAAuD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAK+B,eAAL,GAAqB,UAASnhB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQtH,KAAKkF,IAAL,CAAUC,QAAV,CAAmBE,6BAAnB,CAAiD9c,CAAjD,CAAR;AAA4D,GAAjI,CAAkI,KAAKohB,YAAL,GAAkB,UAASlhB,CAAT,EAAW;AAAC,QAAIF,IAAE,IAAIoJ,UAAJ,CAAepG,OAAO9C,CAAP,CAAf,EAAyB,EAAzB,CAAN,CAAmC,KAAKihB,eAAL,CAAqBnhB,CAArB;AAAwB,GAAzF,CAA0F,KAAKqhB,WAAL,GAAiB,UAASrhB,CAAT,EAAW;AAAC,SAAK+e,EAAL,GAAQ/e,CAAR;AAAU,GAAvC,CAAwC,KAAKkf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAE6gB,MAAT,IAAiB,WAApB,EAAgC;AAAC,WAAKH,eAAL,CAAqB1gB,EAAE6gB,MAAvB;AAA+B,KAAhE,MAAoE;AAAC,UAAG,OAAO7gB,EAAE,KAAF,CAAP,IAAiB,WAApB,EAAgC;AAAC,aAAK2gB,YAAL,CAAkB3gB,EAAE,KAAF,CAAlB;AAA4B,OAA7D,MAAiE;AAAC,YAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,eAAK2gB,YAAL,CAAkB3gB,CAAlB;AAAqB,SAA5C,MAAgD;AAAC,cAAG,OAAOA,EAAEof,GAAT,IAAc,WAAjB,EAA6B;AAAC,iBAAKwB,WAAL,CAAiB5gB,EAAEof,GAAnB;AAAwB;AAAC;AAAC;AAAC;AAAC;AAAC,CAAvqB,CAAwqB1gB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUQ,UAA5B,EAAuC1F,KAAKkF,IAAL,CAAUkC,UAAjD,EAA6DpH,KAAKkF,IAAL,CAAUS,YAAV,GAAuB,UAASpd,CAAT,EAAW;AAAC,MAAGA,MAAIZ,SAAJ,IAAe,OAAOY,EAAEue,GAAT,KAAe,WAAjC,EAA6C;AAAC,QAAI9d,IAAEgX,KAAKkF,IAAL,CAAUC,QAAV,CAAmBK,SAAnB,CAA6Bjd,EAAEue,GAA/B,CAAN,CAA0Cve,EAAE6f,GAAF,GAAM,OAAKpf,EAAEge,aAAF,EAAX;AAA6B,QAAK9B,IAAL,CAAUS,YAAV,CAAuBtd,UAAvB,CAAkCD,WAAlC,CAA8CuC,IAA9C,CAAmD,IAAnD,EAAyD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKmC,8BAAL,GAAoC,UAASrhB,CAAT,EAAW;AAAC,SAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQ7e,CAAR;AAAU,GAA9F,CAA+F,KAAKshB,wBAAL,GAA8B,UAASthB,CAAT,EAAWD,CAAX,EAAa;AAAC,QAAGC,IAAE,CAAF,IAAK,IAAEA,CAAV,EAAY;AAAC,YAAK,2CAAyCA,CAA9C;AAAgD,SAAIP,IAAE,MAAIO,CAAV,CAAY,KAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQpf,IAAEM,CAAV;AAAY,GAArK,CAAsK,KAAKwhB,iBAAL,GAAuB,UAASxhB,CAAT,EAAW;AAACA,QAAEA,EAAEwc,OAAF,CAAU,KAAV,EAAgB,EAAhB,CAAF,CAAsB,IAAIhd,IAAE,IAAEQ,EAAEK,MAAF,GAAS,CAAjB,CAAmB,IAAGb,KAAG,CAAN,EAAQ;AAACA,UAAE,CAAF;AAAI,UAAI,IAAIF,IAAE,CAAV,EAAYA,KAAGE,CAAf,EAAiBF,GAAjB,EAAqB;AAACU,WAAG,GAAH;AAAO,SAAIG,IAAE,EAAN,CAAS,KAAI,IAAIb,IAAE,CAAV,EAAYA,IAAEU,EAAEK,MAAF,GAAS,CAAvB,EAAyBf,KAAG,CAA5B,EAA8B;AAAC,UAAII,IAAEM,EAAE6C,MAAF,CAASvD,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAIW,IAAE2C,SAASlD,CAAT,EAAW,CAAX,EAAc4B,QAAd,CAAuB,EAAvB,CAAN,CAAiC,IAAGrB,EAAEI,MAAF,IAAU,CAAb,EAAe;AAACJ,YAAE,MAAIA,CAAN;AAAQ,YAAGA,CAAH;AAAK,UAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQ,MAAItf,CAAJ,GAAMW,CAAd;AAAgB,GAApS,CAAqS,KAAKshB,iBAAL,GAAuB,UAASzhB,CAAT,EAAW;AAAC,QAAIN,IAAE,EAAN,CAAS,KAAI,IAAIO,IAAE,CAAV,EAAYA,IAAED,EAAEK,MAAhB,EAAuBJ,GAAvB,EAA2B;AAAC,UAAGD,EAAEC,CAAF,KAAM,IAAT,EAAc;AAACP,aAAG,GAAH;AAAO,OAAtB,MAA0B;AAACA,aAAG,GAAH;AAAO;AAAC,UAAK8hB,iBAAL,CAAuB9hB,CAAvB;AAA0B,GAArI,CAAsI,KAAKgiB,aAAL,GAAmB,UAAS1hB,CAAT,EAAW;AAAC,QAAIC,IAAE,IAAI8I,KAAJ,CAAU/I,CAAV,CAAN,CAAmB,KAAI,IAAIN,IAAE,CAAV,EAAYA,IAAEM,CAAd,EAAgBN,GAAhB,EAAoB;AAACO,QAAEP,CAAF,IAAK,KAAL;AAAW,YAAOO,CAAP;AAAS,GAA3F,CAA4F,KAAKgf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAO/e,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,CAAP,IAAU,QAAV,IAAoBA,EAAE0f,WAAF,GAAgBlD,KAAhB,CAAsB,aAAtB,CAAvB,EAA4D;AAAC,WAAK+E,8BAAL,CAAoCvhB,CAApC;AAAuC,KAApG,MAAwG;AAAC,UAAG,OAAOA,EAAE6f,GAAT,IAAc,WAAjB,EAA6B;AAAC,aAAK0B,8BAAL,CAAoCvhB,EAAE6f,GAAtC;AAA2C,OAAzE,MAA6E;AAAC,YAAG,OAAO7f,EAAE4hB,GAAT,IAAc,WAAjB,EAA6B;AAAC,eAAKH,iBAAL,CAAuBzhB,EAAE4hB,GAAzB;AAA8B,SAA5D,MAAgE;AAAC,cAAG,OAAO5hB,EAAEoe,KAAT,IAAgB,WAAnB,EAA+B;AAAC,iBAAKsD,iBAAL,CAAuB1hB,EAAEoe,KAAzB;AAAgC;AAAC;AAAC;AAAC;AAAC;AAAC,CAAl3C,CAAm3Cjf,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUS,YAA5B,EAAyC3F,KAAKkF,IAAL,CAAUkC,UAAnD,EAA+DpH,KAAKkF,IAAL,CAAUU,cAAV,GAAyB,UAASrd,CAAT,EAAW;AAAC,MAAGA,MAAIZ,SAAJ,IAAe,OAAOY,EAAEue,GAAT,KAAe,WAAjC,EAA6C;AAAC,QAAI9d,IAAEgX,KAAKkF,IAAL,CAAUC,QAAV,CAAmBK,SAAnB,CAA6Bjd,EAAEue,GAA/B,CAAN,CAA0Cve,EAAE6f,GAAF,GAAMpf,EAAEge,aAAF,EAAN;AAAwB,QAAK9B,IAAL,CAAUU,cAAV,CAAyBvd,UAAzB,CAAoCD,WAApC,CAAgDuC,IAAhD,CAAqD,IAArD,EAA0DpC,CAA1D,EAA6D,KAAKof,EAAL,GAAQ,IAAR;AAAa,CAA/N,CAAgOjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUU,cAA5B,EAA2C5F,KAAKkF,IAAL,CAAU2C,iBAArD,EAAwE7H,KAAKkF,IAAL,CAAUW,OAAV,GAAkB,YAAU;AAAC7F,OAAKkF,IAAL,CAAUW,OAAV,CAAkBxd,UAAlB,CAA6BD,WAA7B,CAAyCuC,IAAzC,CAA8C,IAA9C,EAAoD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKJ,IAAL,GAAU,MAAV;AAAiB,CAA/G,CAAgH7f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUW,OAA5B,EAAoC7F,KAAKkF,IAAL,CAAUkC,UAA9C,EAA0DpH,KAAKkF,IAAL,CAAUY,mBAAV,GAA8B,UAASrd,CAAT,EAAW;AAAC,MAAIF,IAAE,SAAFA,CAAE,CAASL,CAAT,EAAW;AAAC,QAAIM,IAAEN,EAAE4B,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAGtB,EAAEK,MAAF,IAAU,CAAb,EAAe;AAACL,UAAE,MAAIA,CAAN;AAAQ,YAAOA,CAAP;AAAS,GAAxE,CAAyE,IAAIQ,IAAE,SAAFA,CAAE,CAASD,CAAT,EAAW;AAAC,QAAIJ,IAAE,EAAN,CAAS,IAAIH,IAAE,IAAImJ,UAAJ,CAAe5I,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIb,IAAEM,EAAEsB,QAAF,CAAW,CAAX,CAAN,CAAoB,IAAI9B,IAAE,IAAEE,EAAEW,MAAF,GAAS,CAAjB,CAAmB,IAAGb,KAAG,CAAN,EAAQ;AAACA,UAAE,CAAF;AAAI,SAAI+C,IAAE,EAAN,CAAS,KAAI,IAAIjD,IAAE,CAAV,EAAYA,IAAEE,CAAd,EAAgBF,GAAhB,EAAoB;AAACiD,WAAG,GAAH;AAAO,SAAEA,IAAE7C,CAAJ,CAAM,KAAI,IAAIJ,IAAE,CAAV,EAAYA,IAAEI,EAAEW,MAAF,GAAS,CAAvB,EAAyBf,KAAG,CAA5B,EAA8B;AAAC,UAAIgB,IAAEZ,EAAEmD,MAAF,CAASvD,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAGA,KAAGI,EAAEW,MAAF,GAAS,CAAf,EAAiB;AAACC,YAAE,MAAIA,CAAN;AAAQ,YAAGP,EAAE6C,SAAStC,CAAT,EAAW,CAAX,CAAF,CAAH;AAAoB,YAAOH,CAAP;AAAS,GAA/P,CAAgQqX,KAAKkF,IAAL,CAAUY,mBAAV,CAA8Bzd,UAA9B,CAAyCD,WAAzC,CAAqDuC,IAArD,CAA0D,IAA1D,EAAgE,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKiC,WAAL,GAAiB,UAAS1hB,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAO,IAAP,CAAY,KAAK+c,EAAL,GAAQpf,CAAR;AAAU,GAAvF,CAAwF,KAAKkiB,iBAAL,GAAuB,UAASpiB,CAAT,EAAW;AAAC,QAAG,CAACA,EAAE+c,KAAF,CAAQ,WAAR,CAAJ,EAAyB;AAAC,YAAK,2BAAyB/c,CAA9B;AAAgC,SAAIF,IAAE,EAAN,CAAS,IAAII,IAAEF,EAAEmf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAIxe,IAAEyC,SAASlD,EAAE,CAAF,CAAT,IAAe,EAAf,GAAkBkD,SAASlD,EAAE,CAAF,CAAT,CAAxB,CAAuCJ,KAAGS,EAAEI,CAAF,CAAH,CAAQT,EAAE4E,MAAF,CAAS,CAAT,EAAW,CAAX,EAAc,KAAI,IAAItE,IAAE,CAAV,EAAYA,IAAEN,EAAEW,MAAhB,EAAuBL,GAAvB,EAA2B;AAACV,WAAGkB,EAAEd,EAAEM,CAAF,CAAF,CAAH;AAAW,UAAK+e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAO,IAAP,CAAY,KAAK+c,EAAL,GAAQxf,CAAR;AAAU,GAAvR,CAAwR,KAAKuiB,YAAL,GAAkB,UAAS7hB,CAAT,EAAW;AAAC,QAAIN,IAAE8X,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmBC,QAAnB,CAA4BhiB,CAA5B,CAAN,CAAqC,IAAGN,MAAI,EAAP,EAAU;AAAC,WAAKkiB,iBAAL,CAAuBliB,CAAvB;AAA0B,KAArC,MAAyC;AAAC,YAAK,4CAA0CM,CAA/C;AAAiD;AAAC,GAA/J,CAAgK,KAAKif,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG7e,MAAId,SAAP,EAAiB;AAAC,QAAG,OAAOc,CAAP,KAAW,QAAd,EAAuB;AAAC,UAAGA,EAAEsc,KAAF,CAAQ,iBAAR,CAAH,EAA8B;AAAC,aAAKqF,iBAAL,CAAuB3hB,CAAvB;AAA0B,OAAzD,MAA6D;AAAC,aAAK4hB,YAAL,CAAkB5hB,CAAlB;AAAqB;AAAC,KAA5G,MAAgH;AAAC,UAAGA,EAAEgiB,GAAF,KAAQ9iB,SAAX,EAAqB;AAAC,aAAKyiB,iBAAL,CAAuB3hB,EAAEgiB,GAAzB;AAA8B,OAApD,MAAwD;AAAC,YAAGhiB,EAAE2f,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,eAAKiiB,WAAL,CAAiBnhB,EAAE2f,GAAnB;AAAwB,SAA9C,MAAkD;AAAC,cAAG3f,EAAEiiB,IAAF,KAAS/iB,SAAZ,EAAsB;AAAC,iBAAK0iB,YAAL,CAAkB5hB,EAAEiiB,IAApB;AAA0B;AAAC;AAAC;AAAC;AAAC;AAAC,CAAtyC,CAAuyChjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUY,mBAA5B,EAAgD9F,KAAKkF,IAAL,CAAUkC,UAA1D,EAAsEpH,KAAKkF,IAAL,CAAUa,aAAV,GAAwB,UAAS/c,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUa,aAAV,CAAwB1d,UAAxB,CAAmCD,WAAnC,CAA+CuC,IAA/C,CAAoD,IAApD,EAA0D,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAK+B,eAAL,GAAqB,UAASnhB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQtH,KAAKkF,IAAL,CAAUC,QAAV,CAAmBE,6BAAnB,CAAiD9c,CAAjD,CAAR;AAA4D,GAAjI,CAAkI,KAAKohB,YAAL,GAAkB,UAASlhB,CAAT,EAAW;AAAC,QAAIF,IAAE,IAAIoJ,UAAJ,CAAepG,OAAO9C,CAAP,CAAf,EAAyB,EAAzB,CAAN,CAAmC,KAAKihB,eAAL,CAAqBnhB,CAArB;AAAwB,GAAzF,CAA0F,KAAKqhB,WAAL,GAAiB,UAASrhB,CAAT,EAAW;AAAC,SAAK+e,EAAL,GAAQ/e,CAAR;AAAU,GAAvC,CAAwC,KAAKkf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAE,KAAF,CAAP,IAAiB,WAApB,EAAgC;AAAC,WAAK2gB,YAAL,CAAkB3gB,EAAE,KAAF,CAAlB;AAA4B,KAA7D,MAAiE;AAAC,UAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,aAAK2gB,YAAL,CAAkB3gB,CAAlB;AAAqB,OAA5C,MAAgD;AAAC,YAAG,OAAOA,EAAEof,GAAT,IAAc,WAAjB,EAA6B;AAAC,eAAKwB,WAAL,CAAiB5gB,EAAEof,GAAnB;AAAwB;AAAC;AAAC;AAAC;AAAC,CAAvmB,CAAwmB1gB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUa,aAA5B,EAA0C/F,KAAKkF,IAAL,CAAUkC,UAApD,EAAgEpH,KAAKkF,IAAL,CAAUc,aAAV,GAAwB,UAAShd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUc,aAAV,CAAwB3d,UAAxB,CAAmCD,WAAnC,CAA+CuC,IAA/C,CAAoD,IAApD,EAAyD3B,CAAzD,EAA4D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAA7G,CAA8GjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUc,aAA5B,EAA0ChG,KAAKkF,IAAL,CAAU2C,iBAApD,EAAuE7H,KAAKkF,IAAL,CAAUe,gBAAV,GAA2B,UAASjd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUe,gBAAV,CAA2B5d,UAA3B,CAAsCD,WAAtC,CAAkDuC,IAAlD,CAAuD,IAAvD,EAA4D3B,CAA5D,EAA+D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAAnH,CAAoHjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUe,gBAA5B,EAA6CjG,KAAKkF,IAAL,CAAU2C,iBAAvD,EAA0E7H,KAAKkF,IAAL,CAAUgB,kBAAV,GAA6B,UAASld,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUgB,kBAAV,CAA6B7d,UAA7B,CAAwCD,WAAxC,CAAoDuC,IAApD,CAAyD,IAAzD,EAA8D3B,CAA9D,EAAiE,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAAvH,CAAwHjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUgB,kBAA5B,EAA+ClG,KAAKkF,IAAL,CAAU2C,iBAAzD,EAA4E7H,KAAKkF,IAAL,CAAUiB,gBAAV,GAA2B,UAASnd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUiB,gBAAV,CAA2B9d,UAA3B,CAAsCD,WAAtC,CAAkDuC,IAAlD,CAAuD,IAAvD,EAA4D3B,CAA5D,EAA+D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAAnH,CAAoHjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUiB,gBAA5B,EAA6CnG,KAAKkF,IAAL,CAAU2C,iBAAvD,EAA0E7H,KAAKkF,IAAL,CAAUkB,YAAV,GAAuB,UAASpd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUkB,YAAV,CAAuB/d,UAAvB,CAAkCD,WAAlC,CAA8CuC,IAA9C,CAAmD,IAAnD,EAAwD3B,CAAxD,EAA2D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAA3G,CAA4GjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUkB,YAA5B,EAAyCpG,KAAKkF,IAAL,CAAU2C,iBAAnD,EAAsE7H,KAAKkF,IAAL,CAAUmB,UAAV,GAAqB,UAASrd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUmB,UAAV,CAAqBhe,UAArB,CAAgCD,WAAhC,CAA4CuC,IAA5C,CAAiD,IAAjD,EAAsD3B,CAAtD,EAAyD,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAK0B,SAAL,GAAe,UAAS9gB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKmD,IAAL,GAAUpiB,CAAV,CAAY,KAAKgC,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,CAAP,CAAwC,KAAKrD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,GAA1I,CAA2I,KAAKkd,gBAAL,GAAsB,YAAU;AAAC,QAAG,OAAO,KAAKkD,IAAZ,IAAkB,WAAlB,IAA+B,OAAO,KAAKpgB,CAAZ,IAAe,WAAjD,EAA6D;AAAC,WAAKogB,IAAL,GAAU,IAAI5L,IAAJ,EAAV,CAAqB,KAAKxU,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,CAAP,CAAwC,KAAKrD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,YAAO,KAAK+c,EAAZ;AAAe,GAAlM,CAAmM,IAAGte,MAAIrB,SAAP,EAAiB;AAAC,QAAGqB,EAAEmf,GAAF,KAAQxgB,SAAX,EAAqB;AAAC,WAAKogB,SAAL,CAAe/e,EAAEmf,GAAjB;AAAsB,KAA5C,MAAgD;AAAC,UAAG,OAAOnf,CAAP,IAAU,QAAV,IAAoBA,EAAE+b,KAAF,CAAQ,cAAR,CAAvB,EAA+C;AAAC,aAAKgD,SAAL,CAAe/e,CAAf;AAAkB,OAAlE,MAAsE;AAAC,YAAGA,EAAEof,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,eAAKugB,YAAL,CAAkBlf,EAAEof,GAApB;AAAyB,SAA/C,MAAmD;AAAC,cAAGpf,EAAE2hB,IAAF,KAAShjB,SAAZ,EAAsB;AAAC,iBAAK0hB,SAAL,CAAergB,EAAE2hB,IAAjB;AAAuB;AAAC;AAAC;AAAC;AAAC;AAAC,CAAtqB,CAAuqBjjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUmB,UAA5B,EAAuCrG,KAAKkF,IAAL,CAAUmD,eAAjD,EAAkErI,KAAKkF,IAAL,CAAUoB,kBAAV,GAA6B,UAAStd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUoB,kBAAV,CAA6Bje,UAA7B,CAAwCD,WAAxC,CAAoDuC,IAApD,CAAyD,IAAzD,EAA8D3B,CAA9D,EAAiE,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAKiD,UAAL,GAAgB,KAAhB,CAAsB,KAAKvB,SAAL,GAAe,UAAS9gB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKmD,IAAL,GAAUpiB,CAAV,CAAY,KAAKgC,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,EAAgC,KAAKC,UAArC,CAAP,CAAwD,KAAKtD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,GAA1J,CAA2J,KAAKkd,gBAAL,GAAsB,YAAU;AAAC,QAAG,KAAKkD,IAAL,KAAYhjB,SAAZ,IAAuB,KAAK4C,CAAL,KAAS5C,SAAnC,EAA6C;AAAC,WAAKgjB,IAAL,GAAU,IAAI5L,IAAJ,EAAV,CAAqB,KAAKxU,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,EAAgC,KAAKC,UAArC,CAAP,CAAwD,KAAKtD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,YAAO,KAAK+c,EAAZ;AAAe,GAAlM,CAAmM,IAAGte,MAAIrB,SAAP,EAAiB;AAAC,QAAGqB,EAAEmf,GAAF,KAAQxgB,SAAX,EAAqB;AAAC,WAAKogB,SAAL,CAAe/e,EAAEmf,GAAjB;AAAsB,KAA5C,MAAgD;AAAC,UAAG,OAAOnf,CAAP,IAAU,QAAV,IAAoBA,EAAE+b,KAAF,CAAQ,cAAR,CAAvB,EAA+C;AAAC,aAAKgD,SAAL,CAAe/e,CAAf;AAAkB,OAAlE,MAAsE;AAAC,YAAGA,EAAEof,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,eAAKugB,YAAL,CAAkBlf,EAAEof,GAApB;AAAyB,SAA/C,MAAmD;AAAC,cAAGpf,EAAE2hB,IAAF,KAAShjB,SAAZ,EAAsB;AAAC,iBAAK0hB,SAAL,CAAergB,EAAE2hB,IAAjB;AAAuB;AAAC;AAAC;AAAC,SAAG3hB,EAAE6hB,MAAF,KAAW,IAAd,EAAmB;AAAC,WAAKD,UAAL,GAAgB,IAAhB;AAAqB;AAAC;AAAC,CAArwB,CAAswBljB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUoB,kBAA5B,EAA+CtG,KAAKkF,IAAL,CAAUmD,eAAzD,EAA0ErI,KAAKkF,IAAL,CAAUqB,WAAV,GAAsB,UAASvd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUqB,WAAV,CAAsBle,UAAtB,CAAiCD,WAAjC,CAA6CuC,IAA7C,CAAkD,IAAlD,EAAuD3B,CAAvD,EAA0D,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAKF,gBAAL,GAAsB,YAAU;AAAC,QAAIhf,IAAE,EAAN,CAAS,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE,KAAKihB,SAAL,CAAe3gB,MAA7B,EAAoCN,GAApC,EAAwC;AAAC,UAAIL,IAAE,KAAKshB,SAAL,CAAejhB,CAAf,CAAN,CAAwBE,KAAGP,EAAE8e,aAAF,EAAH;AAAqB,UAAKM,EAAL,GAAQ7e,CAAR,CAAU,OAAO,KAAK6e,EAAZ;AAAe,GAAzJ;AAA0J,CAAnQ,CAAoQ5f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUqB,WAA5B,EAAwCvG,KAAKkF,IAAL,CAAUoE,qBAAlD,EAAyEtJ,KAAKkF,IAAL,CAAUsB,MAAV,GAAiB,UAASxd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUsB,MAAV,CAAiBne,UAAjB,CAA4BD,WAA5B,CAAwCuC,IAAxC,CAA6C,IAA7C,EAAkD3B,CAAlD,EAAqD,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAKmD,QAAL,GAAc,IAAd,CAAmB,KAAKrD,gBAAL,GAAsB,YAAU;AAAC,QAAIlf,IAAE,IAAIgJ,KAAJ,EAAN,CAAkB,KAAI,IAAI9I,IAAE,CAAV,EAAYA,IAAE,KAAK+gB,SAAL,CAAe3gB,MAA7B,EAAoCJ,GAApC,EAAwC;AAAC,UAAIP,IAAE,KAAKshB,SAAL,CAAe/gB,CAAf,CAAN,CAAwBF,EAAEuC,IAAF,CAAO5C,EAAE8e,aAAF,EAAP;AAA0B,SAAG,KAAK8D,QAAL,IAAe,IAAlB,EAAuB;AAACviB,QAAEwiB,IAAF;AAAS,UAAKzD,EAAL,GAAQ/e,EAAE2C,IAAF,CAAO,EAAP,CAAR,CAAmB,OAAO,KAAKoc,EAAZ;AAAe,GAAjN,CAAkN,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAEgiB,QAAT,IAAmB,WAAnB,IAAgChiB,EAAEgiB,QAAF,IAAY,KAA/C,EAAqD;AAAC,WAAKF,QAAL,GAAc,KAAd;AAAoB;AAAC;AAAC,CAA1a,CAA2apjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUsB,MAA5B,EAAmCxG,KAAKkF,IAAL,CAAUoE,qBAA7C,EAAoEtJ,KAAKkF,IAAL,CAAUuB,eAAV,GAA0B,UAASzd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUuB,eAAV,CAA0Bpe,UAA1B,CAAqCD,WAArC,CAAiDuC,IAAjD,CAAsD,IAAtD,EAA4D,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKL,EAAL,GAAQ,EAAR,CAAW,KAAK2D,UAAL,GAAgB,IAAhB,CAAqB,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKC,aAAL,GAAmB,UAAS5iB,CAAT,EAAWE,CAAX,EAAaP,CAAb,EAAe;AAAC,SAAKyf,EAAL,GAAQlf,CAAR,CAAU,KAAKwiB,UAAL,GAAgB1iB,CAAhB,CAAkB,KAAK2iB,UAAL,GAAgBhjB,CAAhB,CAAkB,IAAG,KAAK+iB,UAAR,EAAmB;AAAC,WAAK3D,EAAL,GAAQ,KAAK4D,UAAL,CAAgBlE,aAAhB,EAAR,CAAwC,KAAKO,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB;AAAqB,KAAhG,MAAoG;AAAC,WAAKF,EAAL,GAAQ,IAAR,CAAa,KAAKC,IAAL,GAAUrf,EAAE8e,aAAF,EAAV,CAA4B,KAAKO,IAAL,GAAU,KAAKA,IAAL,CAAUvC,OAAV,CAAkB,KAAlB,EAAwBvc,CAAxB,CAAV,CAAqC,KAAK+e,UAAL,GAAgB,KAAhB;AAAsB;AAAC,GAA3R,CAA4R,KAAKC,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAE4d,GAAT,IAAc,WAAjB,EAA6B;AAAC,WAAKe,EAAL,GAAQ3e,EAAE4d,GAAV;AAAc,SAAG,OAAO5d,EAAE6d,QAAT,IAAmB,WAAtB,EAAkC;AAAC,WAAKoE,UAAL,GAAgBjiB,EAAE6d,QAAlB;AAA2B,SAAG,OAAO7d,EAAE8d,GAAT,IAAc,WAAjB,EAA6B;AAAC,WAAKoE,UAAL,GAAgBliB,EAAE8d,GAAlB,CAAsB,KAAKqE,aAAL,CAAmB,KAAKF,UAAxB,EAAmC,KAAKtD,EAAxC,EAA2C,KAAKuD,UAAhD;AAA4D;AAAC;AAAC,CAAvuB,CAAwuBxjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUuB,eAA5B,EAA4CzG,KAAKkF,IAAL,CAAUkC,UAAtD;AAC5ne,IAAIgE,UAAQ,IAAI,YAAU,CAAE,CAAhB,EAAZ,CAA6BA,QAAQC,QAAR,GAAiB,UAAS5iB,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAGP,EAAE4C,MAAF,CAASrC,IAAE,CAAX,EAAa,CAAb,KAAiB,GAApB,EAAwB;AAAC,WAAO,CAAP;AAAS,OAAIT,IAAE6C,SAAS3C,EAAE4C,MAAF,CAASrC,IAAE,CAAX,EAAa,CAAb,CAAT,CAAN,CAAgC,IAAGT,KAAG,CAAN,EAAQ;AAAC,WAAO,CAAC,CAAR;AAAU,OAAG,IAAEA,CAAF,IAAKA,IAAE,EAAV,EAAa;AAAC,WAAOA,IAAE,CAAT;AAAW,UAAO,CAAC,CAAR;AAAU,CAAvJ,CAAwJ6iB,QAAQE,IAAR,GAAa,UAAS7iB,CAAT,EAAWF,CAAX,EAAa;AAAC,MAAIS,IAAEoiB,QAAQC,QAAR,CAAiB5iB,CAAjB,EAAmBF,CAAnB,CAAN,CAA4B,IAAGS,IAAE,CAAL,EAAO;AAAC,WAAM,EAAN;AAAS,UAAOP,EAAE4C,MAAF,CAAS9C,IAAE,CAAX,EAAaS,IAAE,CAAf,CAAP;AAAyB,CAAjG,CAAkGoiB,QAAQG,QAAR,GAAiB,UAASrjB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIP,CAAJ,EAAMF,CAAN,CAAQE,IAAE2iB,QAAQE,IAAR,CAAapjB,CAAb,EAAec,CAAf,CAAF,CAAoB,IAAGP,KAAG,EAAN,EAAS;AAAC,WAAO,CAAC,CAAR;AAAU,OAAGA,EAAE4C,MAAF,CAAS,CAAT,EAAW,CAAX,MAAgB,GAAnB,EAAuB;AAAC9C,QAAE,IAAIoJ,UAAJ,CAAelJ,EAAE4C,MAAF,CAAS,CAAT,CAAf,EAA2B,EAA3B,CAAF;AAAiC,GAAzD,MAA6D;AAAC9C,QAAE,IAAIoJ,UAAJ,CAAelJ,CAAf,EAAiB,EAAjB,CAAF;AAAuB,UAAOF,EAAEyP,QAAF,EAAP;AAAoB,CAAxL,CAAyLoT,QAAQI,OAAR,GAAgB,UAAS/iB,CAAT,EAAWF,CAAX,EAAa;AAAC,MAAIS,IAAEoiB,QAAQC,QAAR,CAAiB5iB,CAAjB,EAAmBF,CAAnB,CAAN,CAA4B,IAAGS,IAAE,CAAL,EAAO;AAAC,WAAOA,CAAP;AAAS,UAAOT,IAAE,CAACS,IAAE,CAAH,IAAM,CAAf;AAAiB,CAA5F,CAA6FoiB,QAAQK,IAAR,GAAa,UAASvjB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIP,IAAE2iB,QAAQI,OAAR,CAAgBtjB,CAAhB,EAAkBc,CAAlB,CAAN,CAA2B,IAAIT,IAAE6iB,QAAQG,QAAR,CAAiBrjB,CAAjB,EAAmBc,CAAnB,CAAN,CAA4B,OAAOd,EAAEmD,MAAF,CAAS5C,CAAT,EAAWF,IAAE,CAAb,CAAP;AAAuB,CAAzG,CAA0G6iB,QAAQM,MAAR,GAAe,UAASnjB,CAAT,EAAWS,CAAX,EAAa;AAAC,SAAOT,EAAE8C,MAAF,CAASrC,CAAT,EAAW,CAAX,IAAcoiB,QAAQE,IAAR,CAAa/iB,CAAb,EAAeS,CAAf,CAAd,GAAgCoiB,QAAQK,IAAR,CAAaljB,CAAb,EAAeS,CAAf,CAAvC;AAAyD,CAAtF,CAAuFoiB,QAAQO,iBAAR,GAA0B,UAASzjB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIP,IAAE2iB,QAAQI,OAAR,CAAgBtjB,CAAhB,EAAkBc,CAAlB,CAAN,CAA2B,IAAIT,IAAE6iB,QAAQG,QAAR,CAAiBrjB,CAAjB,EAAmBc,CAAnB,CAAN,CAA4B,OAAOP,IAAEF,IAAE,CAAX;AAAa,CAA5G,CAA6G6iB,QAAQQ,WAAR,GAAoB,UAASpjB,CAAT,EAAWR,CAAX,EAAa;AAAC,MAAIW,IAAEyiB,OAAN,CAAc,IAAItjB,IAAE,IAAIyJ,KAAJ,EAAN,CAAkB,IAAI3I,IAAED,EAAE6iB,OAAF,CAAUhjB,CAAV,EAAYR,CAAZ,CAAN,CAAqB,IAAGQ,EAAE6C,MAAF,CAASrD,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAACF,MAAEgD,IAAF,CAAOlC,IAAE,CAAT;AAAY,GAApC,MAAwC;AAACd,MAAEgD,IAAF,CAAOlC,CAAP;AAAU,OAAIE,IAAEH,EAAE4iB,QAAF,CAAW/iB,CAAX,EAAaR,CAAb,CAAN,CAAsB,IAAIS,IAAEG,CAAN,CAAQ,IAAIV,IAAE,CAAN,CAAQ,OAAM,CAAN,EAAQ;AAAC,QAAIK,IAAEI,EAAEgjB,iBAAF,CAAoBnjB,CAApB,EAAsBC,CAAtB,CAAN,CAA+B,IAAGF,KAAG,IAAH,IAAUA,IAAEK,CAAF,IAAME,IAAE,CAArB,EAAyB;AAAC;AAAM,SAAGZ,KAAG,GAAN,EAAU;AAAC;AAAM,OAAE4C,IAAF,CAAOvC,CAAP,EAAUE,IAAEF,CAAF,CAAIL;AAAI,UAAOJ,CAAP;AAAS,CAApS,CAAqSsjB,QAAQS,cAAR,GAAuB,UAAS3jB,CAAT,EAAWK,CAAX,EAAaC,CAAb,EAAe;AAAC,MAAIC,IAAE2iB,QAAQQ,WAAR,CAAoB1jB,CAApB,EAAsBK,CAAtB,CAAN,CAA+B,OAAOE,EAAED,CAAF,CAAP;AAAY,CAAlF,CAAmF4iB,QAAQU,YAAR,GAAqB,UAAStjB,CAAT,EAAWN,CAAX,EAAaO,CAAb,EAAeG,CAAf,EAAiB;AAAC,MAAId,IAAEsjB,OAAN,CAAc,IAAIpjB,CAAJ,EAAMO,CAAN,CAAQ,IAAGE,EAAEI,MAAF,IAAU,CAAb,EAAe;AAAC,QAAGD,MAAIjB,SAAP,EAAiB;AAAC,UAAGa,EAAE6C,MAAF,CAASnD,CAAT,EAAW,CAAX,MAAgBU,CAAnB,EAAqB;AAAC,cAAK,iCAA+BJ,EAAE6C,MAAF,CAASnD,CAAT,EAAW,CAAX,CAA/B,GAA6C,IAA7C,GAAkDU,CAAvD;AAAyD;AAAC,YAAOV,CAAP;AAAS,OAAEO,EAAEwc,KAAF,EAAF,CAAY1c,IAAET,EAAE8jB,WAAF,CAAcpjB,CAAd,EAAgBN,CAAhB,CAAF,CAAqB,OAAOJ,EAAEgkB,YAAF,CAAetjB,CAAf,EAAiBD,EAAEP,CAAF,CAAjB,EAAsBS,CAAtB,EAAwBG,CAAxB,CAAP;AAAkC,CAA3P,CAA4PwiB,QAAQW,YAAR,GAAqB,UAAS7jB,CAAT,EAAWO,CAAX,EAAaF,CAAb,EAAeP,CAAf,EAAiB;AAAC,MAAIQ,IAAE4iB,OAAN,CAAc,IAAIpiB,IAAER,EAAEsjB,YAAF,CAAe5jB,CAAf,EAAiBO,CAAjB,EAAmBF,CAAnB,CAAN,CAA4B,IAAGS,MAAIrB,SAAP,EAAiB;AAAC,UAAK,2BAAL;AAAiC,OAAGK,MAAIL,SAAP,EAAiB;AAAC,QAAGO,EAAEmD,MAAF,CAASrC,CAAT,EAAW,CAAX,KAAehB,CAAlB,EAAoB;AAAC,YAAK,iCAA+BE,EAAEmD,MAAF,CAASrC,CAAT,EAAW,CAAX,CAA/B,GAA6C,IAA7C,GAAkDhB,CAAvD;AAAyD;AAAC,UAAOQ,EAAEkjB,MAAF,CAASxjB,CAAT,EAAWc,CAAX,CAAP;AAAqB,CAA1P,CAA2PoiB,QAAQY,UAAR,GAAmB,UAASxjB,CAAT,EAAWC,CAAX,EAAaF,CAAb,EAAeT,CAAf,EAAiBc,CAAjB,EAAmB;AAAC,MAAIZ,IAAEojB,OAAN,CAAc,IAAIpiB,CAAJ,EAAMd,CAAN,CAAQc,IAAEhB,EAAE8jB,YAAF,CAAetjB,CAAf,EAAiBC,CAAjB,EAAmBF,CAAnB,EAAqBT,CAArB,CAAF,CAA0B,IAAGkB,MAAIrB,SAAP,EAAiB;AAAC,UAAK,2BAAL;AAAiC,OAAEK,EAAEyjB,IAAF,CAAOjjB,CAAP,EAASQ,CAAT,CAAF,CAAc,IAAGJ,MAAI,IAAP,EAAY;AAACV,QAAEA,EAAEmD,MAAF,CAAS,CAAT,CAAF;AAAc,UAAOnD,CAAP;AAAS,CAA5L,CAA6LkjB,QAAQa,WAAR,GAAoB,UAASzjB,CAAT,EAAW;AAAC,MAAIT,IAAE,SAAFA,CAAE,CAASQ,CAAT,EAAWS,CAAX,EAAa;AAAC,QAAGT,EAAEM,MAAF,IAAUG,CAAb,EAAe;AAAC,aAAOT,CAAP;AAAS,YAAO,IAAIgJ,KAAJ,CAAUvI,IAAET,EAAEM,MAAJ,GAAW,CAArB,EAAwBqC,IAAxB,CAA6B,GAA7B,IAAkC3C,CAAzC;AAA2C,GAAxF,CAAyF,IAAIO,IAAE,EAAN,CAAS,IAAIQ,IAAEd,EAAE6C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAIrD,IAAEoD,SAAS9B,CAAT,EAAW,EAAX,CAAN,CAAqBR,EAAE,CAAF,IAAK,IAAIyC,MAAJ,CAAWkC,KAAKc,KAAL,CAAWvG,IAAE,EAAb,CAAX,CAAL,CAAkCc,EAAE,CAAF,IAAK,IAAIyC,MAAJ,CAAWvD,IAAE,EAAb,CAAL,CAAsB,IAAI+C,IAAEvC,EAAE6C,MAAF,CAAS,CAAT,CAAN,CAAkB,IAAItC,IAAE,EAAN,CAAS,KAAI,IAAIjB,IAAE,CAAV,EAAYA,IAAEiD,EAAElC,MAAF,GAAS,CAAvB,EAAyBf,GAAzB,EAA6B;AAACiB,MAAE+B,IAAF,CAAOM,SAASL,EAAEM,MAAF,CAASvD,IAAE,CAAX,EAAa,CAAb,CAAT,EAAyB,EAAzB,CAAP;AAAqC,OAAIa,IAAE,EAAN,CAAS,IAAIT,IAAE,EAAN,CAAS,KAAI,IAAIJ,IAAE,CAAV,EAAYA,IAAEiB,EAAEF,MAAhB,EAAuBf,GAAvB,EAA2B;AAAC,QAAGiB,EAAEjB,CAAF,IAAK,GAAR,EAAY;AAACI,UAAEA,IAAEH,EAAE,CAACgB,EAAEjB,CAAF,IAAK,GAAN,EAAWgC,QAAX,CAAoB,CAApB,CAAF,EAAyB,CAAzB,CAAJ;AAAgC,KAA7C,MAAiD;AAAC5B,UAAEA,IAAEH,EAAE,CAACgB,EAAEjB,CAAF,IAAK,GAAN,EAAWgC,QAAX,CAAoB,CAApB,CAAF,EAAyB,CAAzB,CAAJ,CAAgCnB,EAAEmC,IAAF,CAAO,IAAIS,MAAJ,CAAWH,SAASlD,CAAT,EAAW,CAAX,CAAX,CAAP,EAAkCA,IAAE,EAAF;AAAK;AAAC,OAAIkB,IAAEN,EAAEoC,IAAF,CAAO,GAAP,CAAN,CAAkB,IAAGvC,EAAEE,MAAF,GAAS,CAAZ,EAAc;AAACO,QAAEA,IAAE,GAAF,GAAMT,EAAEuC,IAAF,CAAO,GAAP,CAAR;AAAoB,UAAO9B,CAAP;AAAS,CAAviB,CAAwiBgiB,QAAQc,IAAR,GAAa,UAAS7hB,CAAT,EAAW5B,CAAX,EAAaK,CAAb,EAAehB,CAAf,EAAiB;AAAC,MAAIuB,IAAE+hB,OAAN,CAAc,IAAIziB,IAAEU,EAAEoiB,IAAR,CAAa,IAAIxb,IAAE5G,EAAE6iB,IAAR,CAAa,IAAI7f,IAAEhD,EAAEuiB,WAAR,CAAoB,IAAIpjB,IAAE6B,CAAN,CAAQ,IAAGA,aAAa2V,KAAKkF,IAAL,CAAUkC,UAA1B,EAAqC;AAAC5e,QAAE6B,EAAE2c,aAAF,EAAF;AAAoB,OAAI1c,IAAE,SAAFA,CAAE,CAAS0F,CAAT,EAAWpH,CAAX,EAAa;AAAC,QAAGoH,EAAEnH,MAAF,IAAUD,IAAE,CAAf,EAAiB;AAAC,aAAOoH,CAAP;AAAS,KAA3B,MAA+B;AAAC,UAAIxD,IAAEwD,EAAE3E,MAAF,CAAS,CAAT,EAAWzC,CAAX,IAAc,WAAd,GAA0BoH,EAAEnH,MAAF,GAAS,CAAnC,GAAqC,UAArC,GAAgDmH,EAAE3E,MAAF,CAAS2E,EAAEnH,MAAF,GAASD,CAAlB,EAAoBA,CAApB,CAAtD,CAA6E,OAAO4D,CAAP;AAAS;AAAC,GAA3I,CAA4I,IAAG/D,MAAId,SAAP,EAAiB;AAACc,QAAE,EAAC0jB,kBAAiB,EAAlB,EAAF;AAAwB,OAAGrjB,MAAInB,SAAP,EAAiB;AAACmB,QAAE,CAAF;AAAI,OAAGhB,MAAIH,SAAP,EAAiB;AAACG,QAAE,EAAF;AAAK,OAAIwE,IAAE7D,EAAE0jB,gBAAR,CAAyB,IAAG3jB,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAGf,KAAG,IAAN,EAAW;AAAC,aAAOD,IAAE,iBAAT;AAA2B,KAAvC,MAA2C;AAAC,aAAOA,IAAE,gBAAT;AAA0B;AAAC,OAAGU,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,OAAOhB,IAAE,UAAF,GAAawC,EAAEvC,CAAF,EAAIuE,CAAJ,CAAb,GAAoB,IAA3B;AAAgC,OAAG9D,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,OAAOhB,IAAE,YAAF,GAAewC,EAAEvC,CAAF,EAAIuE,CAAJ,CAAf,GAAsB,IAA7B;AAAkC,OAAG9D,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAGO,EAAE+iB,SAAF,CAAYrkB,CAAZ,CAAH,EAAkB;AAAC,UAAIgB,IAAEjB,IAAE,6BAAR,CAAsCiB,IAAEA,IAAEkH,EAAElI,CAAF,EAAIU,CAAJ,EAAM,CAAN,EAAQX,IAAE,IAAV,CAAJ,CAAoB,OAAOiB,CAAP;AAAS,KAAtF,MAA0F;AAAC,aAAOjB,IAAE,cAAF,GAAiBwC,EAAEvC,CAAF,EAAIuE,CAAJ,CAAjB,GAAwB,IAA/B;AAAoC;AAAC,OAAG9D,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,QAAT;AAAkB,OAAGU,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIiC,IAAEpC,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAIE,IAAEgX,KAAKkF,IAAL,CAAUC,QAAV,CAAmB8B,WAAnB,CAA+Blc,CAA/B,CAAN,CAAwC,IAAIzB,IAAE0W,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmB8B,QAAnB,CAA4BrjB,CAA5B,CAAN,CAAqC,IAAIT,IAAES,EAAEgc,OAAF,CAAU,KAAV,EAAgB,GAAhB,CAAN,CAA2B,IAAG1b,KAAG,EAAN,EAAS;AAAC,aAAOxB,IAAE,mBAAF,GAAsBwB,CAAtB,GAAwB,IAAxB,GAA6Bf,CAA7B,GAA+B,KAAtC;AAA4C,KAAtD,MAA0D;AAAC,aAAOT,IAAE,oBAAF,GAAuBS,CAAvB,GAAyB,KAAhC;AAAsC;AAAC,OAAGC,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,cAAF,GAAiBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAjB,GAAmC,KAA1C;AAAgD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,mBAAF,GAAsBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAtB,GAAwC,KAA/C;AAAqD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,iBAAF,GAAoBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAApB,GAAsC,KAA7C;AAAmD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,aAAF,GAAgBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAhB,GAAkC,KAAzC;AAA+C,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,UAAF,GAAawkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAb,GAA+B,IAAtC;AAA2C,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,kBAAF,GAAqBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAArB,GAAuC,IAA9C;AAAmD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,aAAOhB,IAAE,eAAT;AAAyB,SAAIiB,IAAEjB,IAAE,YAAR,CAAqB,IAAII,IAAEmE,EAAE7D,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAId,IAAES,CAAN,CAAQ,IAAG,CAACP,EAAEW,MAAF,IAAU,CAAV,IAAaX,EAAEW,MAAF,IAAU,CAAxB,KAA4BL,EAAE6C,MAAF,CAASnD,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAA9C,IAAoDM,EAAE6C,MAAF,CAASnD,EAAEA,EAAEW,MAAF,GAAS,CAAX,CAAT,EAAuB,CAAvB,KAA2B,IAAlF,EAAuF;AAAC,UAAIS,IAAED,EAAEkjB,OAAF,CAAU5jB,EAAEH,CAAF,EAAIN,EAAE,CAAF,CAAJ,CAAV,CAAN,CAA2B,IAAIuC,IAAE+hB,KAAKrhB,KAAL,CAAWqhB,KAAKriB,SAAL,CAAe1B,CAAf,CAAX,CAAN,CAAoCgC,EAAEgiB,WAAF,GAAcnjB,CAAd,CAAgBtB,IAAEyC,CAAF;AAAI,UAAI,IAAIgC,IAAE,CAAV,EAAYA,IAAEvE,EAAEW,MAAhB,EAAuB4D,GAAvB,EAA2B;AAAC1D,UAAEA,IAAEkH,EAAEzH,CAAF,EAAIR,CAAJ,EAAME,EAAEuE,CAAF,CAAN,EAAW3E,IAAE,IAAb,CAAJ;AAAuB,YAAOiB,CAAP;AAAS,OAAGP,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIC,IAAEjB,IAAE,OAAR,CAAgB,IAAII,IAAEmE,EAAE7D,CAAF,EAAIM,CAAJ,CAAN,CAAa,KAAI,IAAI2D,IAAE,CAAV,EAAYA,IAAEvE,EAAEW,MAAhB,EAAuB4D,GAAvB,EAA2B;AAAC1D,UAAEA,IAAEkH,EAAEzH,CAAF,EAAIC,CAAJ,EAAMP,EAAEuE,CAAF,CAAN,EAAW3E,IAAE,IAAb,CAAJ;AAAuB,YAAOiB,CAAP;AAAS,OAAIgH,IAAE3E,SAAS5C,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAN,CAAiC,IAAG,CAACiH,IAAE,GAAH,KAAS,CAAZ,EAAc;AAAC,QAAI3G,IAAE2G,IAAE,EAAR,CAAW,IAAG,CAACA,IAAE,EAAH,KAAQ,CAAX,EAAa;AAAC,UAAIhH,IAAEjB,IAAE,GAAF,GAAMsB,CAAN,GAAQ,KAAd,CAAoB,IAAIlB,IAAEmE,EAAE7D,CAAF,EAAIM,CAAJ,CAAN,CAAa,KAAI,IAAI2D,IAAE,CAAV,EAAYA,IAAEvE,EAAEW,MAAhB,EAAuB4D,GAAvB,EAA2B;AAAC1D,YAAEA,IAAEkH,EAAEzH,CAAF,EAAIC,CAAJ,EAAMP,EAAEuE,CAAF,CAAN,EAAW3E,IAAE,IAAb,CAAJ;AAAuB,cAAOiB,CAAP;AAAS,KAA3G,MAA+G;AAAC,UAAIhB,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAGf,EAAEsD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,UAAlB,EAA6B;AAACtD,YAAEukB,UAAUvkB,CAAV,CAAF;AAAe,WAAGU,EAAEgkB,WAAF,KAAgB,gBAAhB,IAAkCrjB,KAAG,CAAxC,EAA0C;AAACrB,YAAEukB,UAAUvkB,CAAV,CAAF;AAAe,WAAIgB,IAAEjB,IAAE,GAAF,GAAMsB,CAAN,GAAQ,IAAR,GAAarB,CAAb,GAAe,IAArB,CAA0B,OAAOgB,CAAP;AAAS;AAAC,UAAOjB,IAAE,UAAF,GAAaU,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,CAAb,GAA2B,IAA3B,GAAgCH,EAAEH,CAAF,EAAIM,CAAJ,CAAhC,GAAuC,IAA9C;AAAmD,CAAv0E,CAAw0EsiB,QAAQgB,SAAR,GAAkB,UAAS5jB,CAAT,EAAW;AAAC,MAAIN,IAAEkjB,OAAN,CAAc,IAAG5iB,EAAEK,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAAC,WAAO,KAAP;AAAa,OAAIJ,IAAEP,EAAEqjB,QAAF,CAAW/iB,CAAX,EAAa,CAAb,CAAN,CAAsB,IAAID,IAAEC,EAAE6C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAIrD,IAAEE,EAAEojB,IAAF,CAAO9iB,CAAP,EAAS,CAAT,CAAN,CAAkB,IAAIQ,IAAER,EAAEK,MAAF,GAASN,EAAEM,MAAX,GAAkBb,EAAEa,MAA1B,CAAiC,IAAGG,KAAGP,IAAE,CAAR,EAAU;AAAC,WAAO,IAAP;AAAY,UAAO,KAAP;AAAa,CAA5M,CAA6M2iB,QAAQmB,OAAR,GAAgB,UAASvjB,CAAT,EAAW;AAAC,MAAIP,IAAEuX,KAAKkF,IAAX,CAAgB,IAAGlF,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBmhB,KAAjB,CAAuB1jB,CAAvB,CAAH,EAA6B;AAACA,QAAEP,EAAE0c,QAAF,CAAW8B,WAAX,CAAuBje,CAAvB,CAAF;AAA4B,OAAIT,IAAEE,EAAE6hB,IAAF,CAAOC,GAAP,CAAW8B,QAAX,CAAoBrjB,CAApB,CAAN,CAA6B,IAAGT,MAAI,EAAP,EAAU;AAACA,QAAES,CAAF;AAAI,UAAOT,CAAP;AAAS,CAA3J;AACp8J,IAAIyX,IAAJ,CAAS,IAAG,OAAOA,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UA2EpCA,IA3EoC,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKpY,IAAZ,IAAkB,WAAlB,IAA+B,CAACoY,KAAKpY,IAAxC,EAA6C;AAACoY,OAAKpY,IAAL,GAAU,EAAV;AAAa,MAAKA,IAAL,CAAU2D,MAAV,GAAiB,YAAU,CAAE,CAA7B,CAA8B,SAASohB,OAAT,GAAkB,CAAE,UAASC,KAAT,CAAe1kB,CAAf,EAAiB;AAAC,MAAIK,IAAE,IAAIgJ,KAAJ,EAAN,CAAkB,KAAI,IAAI9I,IAAE,CAAV,EAAYA,IAAEP,EAAEW,MAAhB,EAAuBJ,GAAvB,EAA2B;AAACF,MAAEE,CAAF,IAAKP,EAAEuD,UAAF,CAAahD,CAAb,CAAL;AAAqB,UAAOF,CAAP;AAAS,UAASskB,KAAT,CAAetkB,CAAf,EAAiB;AAAC,MAAIL,IAAE,EAAN,CAAS,KAAI,IAAIO,IAAE,CAAV,EAAYA,IAAEF,EAAEM,MAAhB,EAAuBJ,GAAvB,EAA2B;AAACP,QAAEA,IAAEqD,OAAOC,YAAP,CAAoBjD,EAAEE,CAAF,CAApB,CAAJ;AAA8B,UAAOP,CAAP;AAAS,UAAS4kB,OAAT,CAAiBvkB,CAAjB,EAAmB;AAAC,MAAIC,IAAE,EAAN,CAAS,KAAI,IAAIN,IAAE,CAAV,EAAYA,IAAEK,EAAEM,MAAhB,EAAuBX,GAAvB,EAA2B;AAAC,QAAIO,IAAEF,EAAEL,CAAF,EAAK4B,QAAL,CAAc,EAAd,CAAN,CAAwB,IAAGrB,EAAEI,MAAF,IAAU,CAAb,EAAe;AAACJ,UAAE,MAAIA,CAAN;AAAQ,SAAED,IAAEC,CAAJ;AAAM,UAAOD,CAAP;AAAS,UAAS0gB,MAAT,CAAgBlgB,CAAhB,EAAkB;AAAC,SAAO8jB,QAAQF,MAAM5jB,CAAN,CAAR,CAAP;AAAyB,UAAS+jB,MAAT,CAAgB/jB,CAAhB,EAAkB;AAAC,SAAOkI,QAAQgY,OAAOlgB,CAAP,CAAR,CAAP;AAA0B,UAASgkB,OAAT,CAAiBhkB,CAAjB,EAAmB;AAAC,SAAOikB,UAAU/b,QAAQgY,OAAOlgB,CAAP,CAAR,CAAV,CAAP;AAAqC,UAASkkB,OAAT,CAAiBlkB,CAAjB,EAAmB;AAAC,SAAO6jB,MAAMvb,QAAQ6b,UAAUnkB,CAAV,CAAR,CAAN,CAAP;AAAoC,UAASikB,SAAT,CAAmBjkB,CAAnB,EAAqB;AAACA,MAAEA,EAAEgc,OAAF,CAAU,KAAV,EAAgB,EAAhB,CAAF,CAAsBhc,IAAEA,EAAEgc,OAAF,CAAU,KAAV,EAAgB,GAAhB,CAAF,CAAuBhc,IAAEA,EAAEgc,OAAF,CAAU,KAAV,EAAgB,GAAhB,CAAF,CAAuB,OAAOhc,CAAP;AAAS,UAASmkB,SAAT,CAAmBnkB,CAAnB,EAAqB;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACG,QAAEA,IAAE,IAAJ;AAAS,GAA3B,MAA+B;AAAC,QAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACG,UAAEA,IAAE,GAAJ;AAAQ;AAAC,OAAEA,EAAEgc,OAAF,CAAU,IAAV,EAAe,GAAf,CAAF,CAAsBhc,IAAEA,EAAEgc,OAAF,CAAU,IAAV,EAAe,GAAf,CAAF,CAAsB,OAAOhc,CAAP;AAAS,UAASokB,SAAT,CAAmBpkB,CAAnB,EAAqB;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACG,QAAE,MAAIA,CAAN;AAAQ,UAAOikB,UAAU/b,QAAQlI,CAAR,CAAV,CAAP;AAA6B,UAASqkB,SAAT,CAAmBrkB,CAAnB,EAAqB;AAAC,SAAOoI,SAAS+b,UAAUnkB,CAAV,CAAT,CAAP;AAA8B,KAAIskB,UAAJ,EAAeC,UAAf,CAA0B,IAAG,OAAOC,MAAP,KAAgB,UAAnB,EAA8B;AAAC,UA0C1jCF,UA1C0jC,gBAAW,oBAAStkB,CAAT,EAAW;AAAC,WAAOikB,UAAU,IAAIO,MAAJ,CAAWxkB,CAAX,EAAa,MAAb,EAAqBc,QAArB,CAA8B,QAA9B,CAAV,CAAP;AAA0D,GAAjF,CAAkF,QA2C5oCyjB,UA3C4oC,gBAAW,oBAASvkB,CAAT,EAAW;AAAC,WAAO,IAAIwkB,MAAJ,CAAWL,UAAUnkB,CAAV,CAAX,EAAwB,QAAxB,EAAkCc,QAAlC,CAA2C,MAA3C,CAAP;AAA0D,GAAjF;AAAkF,CAAnM,MAAuM;AAAC,UA0CnuCwjB,UA1CmuC,gBAAW,oBAAStkB,CAAT,EAAW;AAAC,WAAOokB,UAAUK,YAAYC,sBAAsB1kB,CAAtB,CAAZ,CAAV,CAAP;AAAwD,GAA/E,CAAgF,QA2CnzCukB,UA3CmzC,gBAAW,oBAASvkB,CAAT,EAAW;AAAC,WAAO2C,mBAAmBgiB,YAAYN,UAAUrkB,CAAV,CAAZ,CAAnB,CAAP;AAAqD,GAA5E;AAA6E,UAAS4kB,SAAT,CAAmB5kB,CAAnB,EAAqB;AAAC,SAAOkI,QAAQuc,YAAYC,sBAAsB1kB,CAAtB,CAAZ,CAAR,CAAP;AAAsD,UAAS6kB,SAAT,CAAmB7kB,CAAnB,EAAqB;AAAC,SAAO2C,mBAAmBgiB,YAAYvc,SAASpI,CAAT,CAAZ,CAAnB,CAAP;AAAoD,UAASgf,SAAT,CAAmBhf,CAAnB,EAAqB;AAAC,SAAOykB,YAAYC,sBAAsB1kB,CAAtB,CAAZ,CAAP;AAA6C,UAASsjB,SAAT,CAAmBtjB,CAAnB,EAAqB;AAAC,SAAO2C,mBAAmBgiB,YAAY3kB,CAAZ,CAAnB,CAAP;AAA0C,UAASqX,SAAT,CAAmB5X,CAAnB,EAAqB;AAAC,MAAIF,IAAE,EAAN,CAAS,KAAI,IAAIS,IAAE,CAAV,EAAYA,IAAEP,EAAEI,MAAF,GAAS,CAAvB,EAAyBG,KAAG,CAA5B,EAA8B;AAACT,SAAGgD,OAAOC,YAAP,CAAoBJ,SAAS3C,EAAE4C,MAAF,CAASrC,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAApB,CAAH;AAAmD,UAAOT,CAAP;AAAS,UAASgY,SAAT,CAAmB9X,CAAnB,EAAqB;AAAC,MAAIO,IAAE,EAAN,CAAS,KAAI,IAAIT,IAAE,CAAV,EAAYA,IAAEE,EAAEI,MAAhB,EAAuBN,GAAvB,EAA2B;AAACS,SAAG,CAAC,MAAIP,EAAEgD,UAAF,CAAalD,CAAb,EAAgBuB,QAAhB,CAAyB,EAAzB,CAAL,EAAmCc,KAAnC,CAAyC,CAAC,CAA1C,CAAH;AAAgD,UAAO5B,CAAP;AAAS,UAAS8kB,QAAT,CAAkB9kB,CAAlB,EAAoB;AAAC,SAAOkI,QAAQlI,CAAR,CAAP;AAAkB,UAAS+kB,UAAT,CAAoBxlB,CAApB,EAAsB;AAAC,MAAIS,IAAE8kB,SAASvlB,CAAT,CAAN,CAAkB,IAAIE,IAAEO,EAAEgc,OAAF,CAAU,UAAV,EAAqB,QAArB,CAAN,CAAqCvc,IAAEA,EAAEuc,OAAF,CAAU,OAAV,EAAkB,EAAlB,CAAF,CAAwB,OAAOvc,CAAP;AAAS,UAASulB,UAAT,CAAoBzlB,CAApB,EAAsB;AAAC,MAAIS,IAAET,EAAEyc,OAAF,CAAU,oBAAV,EAA+B,EAA/B,CAAN,CAAyC,IAAIvc,IAAE2I,SAASpI,CAAT,CAAN,CAAkB,OAAOP,CAAP;AAAS,UAAS8c,QAAT,CAAkBvc,CAAlB,EAAoBT,CAApB,EAAsB;AAAC,MAAIE,IAAEslB,WAAW/kB,CAAX,CAAN,CAAoB,OAAM,gBAAcT,CAAd,GAAgB,WAAhB,GAA4BE,CAA5B,GAA8B,eAA9B,GAA8CF,CAA9C,GAAgD,WAAtD;AAAkE,UAAS0lB,QAAT,CAAkBjlB,CAAlB,EAAoBT,CAApB,EAAsB;AAAC,MAAGS,EAAEkF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAA9B,EAAgC;AAAC,UAAK,4BAA0B3F,CAA/B;AAAiC,OAAGA,MAAIZ,SAAP,EAAiB;AAACqB,QAAEA,EAAEgc,OAAF,CAAU,gBAAczc,CAAd,GAAgB,OAA1B,EAAkC,EAAlC,CAAF,CAAwCS,IAAEA,EAAEgc,OAAF,CAAU,cAAYzc,CAAZ,GAAc,OAAxB,EAAgC,EAAhC,CAAF;AAAsC,GAAhG,MAAoG;AAACS,QAAEA,EAAEgc,OAAF,CAAU,uBAAV,EAAkC,EAAlC,CAAF,CAAwChc,IAAEA,EAAEgc,OAAF,CAAU,qBAAV,EAAgC,EAAhC,CAAF;AAAsC,UAAOgJ,WAAWhlB,CAAX,CAAP;AAAqB,UAASklB,gBAAT,CAA0BhmB,CAA1B,EAA4B;AAAC,MAAGA,EAAEW,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAAC,UAAK,0BAAL;AAAgC,OAAGX,EAAE6c,KAAF,CAAQ,gBAAR,KAA2B,IAA9B,EAAmC;AAAC,UAAK,0BAAL;AAAgC,OAAIxc,IAAE,IAAI4lB,WAAJ,CAAgBjmB,EAAEW,MAAF,GAAS,CAAzB,CAAN,CAAkC,IAAIG,IAAE,IAAIolB,QAAJ,CAAa7lB,CAAb,CAAN,CAAsB,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEP,EAAEW,MAAF,GAAS,CAAvB,EAAyBJ,GAAzB,EAA6B;AAACO,MAAEqlB,QAAF,CAAW5lB,CAAX,EAAa2C,SAASlD,EAAEmD,MAAF,CAAS5C,IAAE,CAAX,EAAa,CAAb,CAAT,EAAyB,EAAzB,CAAb;AAA2C,UAAOF,CAAP;AAAS,UAAS+lB,gBAAT,CAA0B/lB,CAA1B,EAA4B;AAAC,MAAIL,IAAE,EAAN,CAAS,IAAIc,IAAE,IAAIolB,QAAJ,CAAa7lB,CAAb,CAAN,CAAsB,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEF,EAAEgmB,UAAhB,EAA2B9lB,GAA3B,EAA+B;AAACP,SAAG,CAAC,OAAKc,EAAEwlB,QAAF,CAAW/lB,CAAX,EAAcqB,QAAd,CAAuB,EAAvB,CAAN,EAAkCc,KAAlC,CAAwC,CAAC,CAAzC,CAAH;AAA+C,UAAO1C,CAAP;AAAS,UAASumB,UAAT,CAAoBrlB,CAApB,EAAsB;AAAC,MAAIN,CAAJ,EAAMH,CAAN,EAAQoC,CAAR,EAAUvC,CAAV,EAAYR,CAAZ,EAAcY,CAAd,EAAgBL,CAAhB,EAAkBQ,CAAlB,CAAoB,IAAIC,CAAJ,EAAMjB,CAAN,EAAQD,CAAR,EAAUW,CAAV,CAAYA,IAAEW,EAAE2b,KAAF,CAAQ,wDAAR,CAAF,CAAoE,IAAGtc,CAAH,EAAK;AAACO,QAAEP,EAAE,CAAF,CAAF,CAAOK,IAAEsC,SAASpC,CAAT,CAAF,CAAc,IAAGA,EAAEH,MAAF,KAAW,CAAd,EAAgB;AAAC,UAAG,MAAIC,CAAJ,IAAOA,IAAE,GAAZ,EAAgB;AAACA,YAAE,OAAKA,CAAP;AAAS,OAA1B,MAA8B;AAAC,YAAG,KAAGA,CAAH,IAAMA,IAAE,EAAX,EAAc;AAACA,cAAE,OAAKA,CAAP;AAAS;AAAC;AAAC,SAAEsC,SAAS3C,EAAE,CAAF,CAAT,IAAe,CAAjB,CAAmBsC,IAAEK,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBD,IAAE4C,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBT,IAAEoD,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBG,IAAEwC,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBF,IAAE,CAAF,CAAIR,IAAEU,EAAE,CAAF,CAAF,CAAO,IAAGV,MAAI,EAAP,EAAU;AAACD,UAAE,CAACC,EAAEsD,MAAF,CAAS,CAAT,IAAY,IAAb,EAAmBA,MAAnB,CAA0B,CAA1B,EAA4B,CAA5B,CAAF,CAAiC9C,IAAE6C,SAAStD,CAAT,CAAF;AAAc,YAAOiX,KAAKqK,GAAL,CAAStgB,CAAT,EAAWH,CAAX,EAAaoC,CAAb,EAAevC,CAAf,EAAiBR,CAAjB,EAAmBY,CAAnB,EAAqBL,CAArB,CAAP;AAA+B,SAAK,8BAA4Ba,CAAjC;AAAmC,UAASslB,SAAT,CAAmB1lB,CAAnB,EAAqB;AAAC,MAAIT,IAAEkmB,WAAWzlB,CAAX,CAAN,CAAoB,OAAO,CAAC,EAAET,IAAE,IAAJ,CAAR;AAAkB,UAASomB,UAAT,CAAoB3lB,CAApB,EAAsB;AAAC,SAAO,IAAI+V,IAAJ,CAAS0P,WAAWzlB,CAAX,CAAT,CAAP;AAA+B,UAAS4lB,UAAT,CAAoB9mB,CAApB,EAAsBU,CAAtB,EAAwBR,CAAxB,EAA0B;AAAC,MAAIO,CAAJ,CAAM,IAAIS,IAAElB,EAAE+mB,cAAF,EAAN,CAAyB,IAAGrmB,CAAH,EAAK;AAAC,QAAGQ,IAAE,IAAF,IAAQ,OAAKA,CAAhB,EAAkB;AAAC,YAAK,kCAAgCA,CAArC;AAAuC,SAAE,CAAC,KAAGA,CAAJ,EAAO4B,KAAP,CAAa,CAAC,CAAd,CAAF;AAAmB,GAAnF,MAAuF;AAACrC,QAAE,CAAC,QAAMS,CAAP,EAAU4B,KAAV,CAAgB,CAAC,CAAjB,CAAF;AAAsB,QAAG,CAAC,OAAK9C,EAAEgnB,WAAF,KAAgB,CAArB,CAAD,EAA0BlkB,KAA1B,CAAgC,CAAC,CAAjC,CAAH,CAAuCrC,KAAG,CAAC,MAAIT,EAAEinB,UAAF,EAAL,EAAqBnkB,KAArB,CAA2B,CAAC,CAA5B,CAAH,CAAkCrC,KAAG,CAAC,MAAIT,EAAEknB,WAAF,EAAL,EAAsBpkB,KAAtB,CAA4B,CAAC,CAA7B,CAAH,CAAmCrC,KAAG,CAAC,MAAIT,EAAEmnB,aAAF,EAAL,EAAwBrkB,KAAxB,CAA8B,CAAC,CAA/B,CAAH,CAAqCrC,KAAG,CAAC,MAAIT,EAAEonB,aAAF,EAAL,EAAwBtkB,KAAxB,CAA8B,CAAC,CAA/B,CAAH,CAAqC,IAAG5C,CAAH,EAAK;AAAC,QAAIS,IAAEX,EAAEqnB,kBAAF,EAAN,CAA6B,IAAG1mB,MAAI,CAAP,EAAS;AAACA,UAAE,CAAC,OAAKA,CAAN,EAASmC,KAAT,CAAe,CAAC,CAAhB,CAAF,CAAqBnC,IAAEA,EAAEuc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuBzc,KAAG,MAAIE,CAAP;AAAS;AAAC,QAAG,GAAH,CAAO,OAAOF,CAAP;AAAS,UAASklB,WAAT,CAAqBzkB,CAArB,EAAuB;AAAC,SAAOA,EAAEgc,OAAF,CAAU,IAAV,EAAe,EAAf,CAAP;AAA0B,UAAS2I,WAAT,CAAqB3kB,CAArB,EAAuB;AAAC,SAAOA,EAAEgc,OAAF,CAAU,OAAV,EAAkB,KAAlB,CAAP;AAAgC,UAASoK,SAAT,CAAmBtnB,CAAnB,EAAqB;AAAC,MAAIS,IAAE,wBAAN,CAA+B,IAAG,CAACT,EAAEid,KAAF,CAAQ,iBAAR,CAAJ,EAA+B;AAAC,UAAMxc,CAAN;AAAQ,OAAET,EAAEmgB,WAAF,EAAF,CAAkB,IAAI/f,IAAEJ,EAAEqf,KAAF,CAAQ,GAAR,EAAate,MAAb,GAAoB,CAA1B,CAA4B,IAAGX,IAAE,CAAL,EAAO;AAAC,UAAMK,CAAN;AAAQ,OAAIC,IAAE,IAAI6mB,MAAJ,CAAW,IAAEnnB,CAAF,GAAI,CAAf,CAAN,CAAwBJ,IAAEA,EAAEkd,OAAF,CAAU,IAAV,EAAexc,CAAf,CAAF,CAAoB,IAAIC,IAAEX,EAAEqf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAG1e,EAAEI,MAAF,IAAU,CAAb,EAAe;AAAC,UAAMN,CAAN;AAAQ,QAAI,IAAIP,IAAE,CAAV,EAAYA,IAAE,CAAd,EAAgBA,GAAhB,EAAoB;AAACS,MAAET,CAAF,IAAK,CAAC,SAAOS,EAAET,CAAF,CAAR,EAAc4C,KAAd,CAAoB,CAAC,CAArB,CAAL;AAA6B,UAAOnC,EAAEyC,IAAF,CAAO,EAAP,CAAP;AAAkB,UAASokB,SAAT,CAAmB9mB,CAAnB,EAAqB;AAAC,MAAG,CAACA,EAAEuc,KAAF,CAAQ,mBAAR,CAAJ,EAAiC;AAAC,UAAK,8BAAL;AAAoC,OAAEvc,EAAEyf,WAAF,EAAF,CAAkB,IAAI1f,IAAEC,EAAEuc,KAAF,CAAQ,SAAR,CAAN,CAAyB,KAAI,IAAI7c,IAAE,CAAV,EAAYA,IAAE,CAAd,EAAgBA,GAAhB,EAAoB;AAACK,MAAEL,CAAF,IAAKK,EAAEL,CAAF,EAAK8c,OAAL,CAAa,KAAb,EAAmB,EAAnB,CAAL,CAA4B,IAAGzc,EAAEL,CAAF,KAAM,EAAT,EAAY;AAACK,QAAEL,CAAF,IAAK,GAAL;AAAS;AAAC,OAAE,MAAIK,EAAE2C,IAAF,CAAO,GAAP,CAAJ,GAAgB,GAAlB,CAAsB,IAAIzC,IAAED,EAAEuc,KAAF,CAAQ,YAAR,CAAN,CAA4B,IAAGtc,MAAI,IAAP,EAAY;AAAC,WAAOD,EAAEoC,KAAF,CAAQ,CAAR,EAAU,CAAC,CAAX,CAAP;AAAqB,OAAI5C,IAAE,EAAN,CAAS,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEO,EAAEI,MAAhB,EAAuBX,GAAvB,EAA2B;AAAC,QAAGO,EAAEP,CAAF,EAAKW,MAAL,GAAYb,EAAEa,MAAjB,EAAwB;AAACb,UAAES,EAAEP,CAAF,CAAF;AAAO;AAAC,OAAEM,EAAEwc,OAAF,CAAUhd,CAAV,EAAY,IAAZ,CAAF,CAAoB,OAAOQ,EAAEoC,KAAF,CAAQ,CAAR,EAAU,CAAC,CAAX,CAAP;AAAqB,UAAS2kB,OAAT,CAAiBhnB,CAAjB,EAAmB;AAAC,MAAIL,IAAE,qBAAN,CAA4B,IAAG,CAACK,EAAEwc,KAAF,CAAQ,gCAAR,CAAJ,EAA8C;AAAC,UAAM7c,CAAN;AAAQ,OAAGK,EAAEM,MAAF,IAAU,CAAb,EAAe;AAAC,QAAIJ,CAAJ,CAAM,IAAG;AAACA,UAAE2C,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,IAA2B,GAA3B,GAA+BD,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAA/B,GAA0D,GAA1D,GAA8DD,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAA9D,GAAyF,GAAzF,GAA6FD,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAA/F,CAA0H,OAAO5C,CAAP;AAAS,KAAvI,CAAuI,OAAMO,CAAN,EAAQ;AAAC,YAAMd,CAAN;AAAQ;AAAC,GAA/K,MAAmL;AAAC,QAAGK,EAAEM,MAAF,IAAU,EAAb,EAAgB;AAAC,aAAOymB,UAAU/mB,CAAV,CAAP;AAAoB,KAArC,MAAyC;AAAC,aAAOA,CAAP;AAAS;AAAC;AAAC,UAASinB,OAAT,CAAiBxnB,CAAjB,EAAmB;AAAC,MAAIW,IAAE,sBAAN,CAA6BX,IAAEA,EAAEigB,WAAF,CAAcjgB,CAAd,CAAF,CAAmB,IAAGA,EAAE+c,KAAF,CAAQ,WAAR,CAAH,EAAwB;AAAC,QAAIxc,IAAEP,EAAEmf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAG5e,EAAEM,MAAF,KAAW,CAAd,EAAgB;AAAC,YAAMF,CAAN;AAAQ,SAAIb,IAAE,EAAN,CAAS,IAAG;AAAC,WAAI,IAAIU,IAAE,CAAV,EAAYA,IAAE,CAAd,EAAgBA,GAAhB,EAAoB;AAAC,YAAIT,IAAEqD,SAAS7C,EAAEC,CAAF,CAAT,CAAN,CAAqBV,KAAG,CAAC,MAAIC,EAAE+B,QAAF,CAAW,EAAX,CAAL,EAAqBc,KAArB,CAA2B,CAAC,CAA5B,CAAH;AAAkC,cAAO9C,CAAP;AAAS,KAAzF,CAAyF,OAAMW,CAAN,EAAQ;AAAC,YAAME,CAAN;AAAQ;AAAC,GAAzL,MAA6L;AAAC,QAAGX,EAAE+c,KAAF,CAAQ,cAAR,KAAyB/c,EAAEkG,OAAF,CAAU,GAAV,MAAiB,CAAC,CAA9C,EAAgD;AAAC,aAAOkhB,UAAUpnB,CAAV,CAAP;AAAoB,KAArE,MAAyE;AAAC,YAAMW,CAAN;AAAQ;AAAC;AAAC,UAAS+kB,qBAAT,CAA+B1kB,CAA/B,EAAiC;AAAC,MAAId,IAAE4D,mBAAmB9C,CAAnB,CAAN,CAA4B,IAAIT,IAAE,EAAN,CAAS,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEP,EAAEW,MAAhB,EAAuBJ,GAAvB,EAA2B;AAAC,QAAGP,EAAEO,CAAF,KAAM,GAAT,EAAa;AAACF,UAAEA,IAAEL,EAAEmD,MAAF,CAAS5C,CAAT,EAAW,CAAX,CAAJ,CAAkBA,IAAEA,IAAE,CAAJ;AAAM,KAAtC,MAA0C;AAACF,UAAEA,IAAE,GAAF,GAAM2gB,OAAOhhB,EAAEO,CAAF,CAAP,CAAR;AAAqB;AAAC,UAAOF,CAAP;AAAS,UAASknB,cAAT,CAAwBzmB,CAAxB,EAA0B;AAACA,MAAEA,EAAEgc,OAAF,CAAU,QAAV,EAAmB,IAAnB,CAAF,CAA2B,OAAOhc,CAAP;AAAS,UAAS0mB,aAAT,CAAuB1mB,CAAvB,EAAyB;AAACA,MAAEA,EAAEgc,OAAF,CAAU,QAAV,EAAmB,IAAnB,CAAF,CAA2Bhc,IAAEA,EAAEgc,OAAF,CAAU,MAAV,EAAiB,MAAjB,CAAF,CAA2B,OAAOhc,CAAP;AAAS,MAAKpB,IAAL,CAAU2D,MAAV,CAAiBokB,SAAjB,GAA2B,UAAS3mB,CAAT,EAAW;AAAC,MAAGA,EAAE+b,KAAF,CAAQ,UAAR,CAAH,EAAuB;AAAC,WAAO,IAAP;AAAY,GAApC,MAAwC;AAAC,QAAG/b,EAAE+b,KAAF,CAAQ,WAAR,CAAH,EAAwB;AAAC,aAAO,IAAP;AAAY,KAArC,MAAyC;AAAC,aAAO,KAAP;AAAa;AAAC;AAAC,CAAzI,CAA0I/E,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBmhB,KAAjB,GAAuB,UAAS1jB,CAAT,EAAW;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAZ,KAAgBG,EAAE+b,KAAF,CAAQ,aAAR,KAAwB/b,EAAE+b,KAAF,CAAQ,aAAR,CAAxC,CAAH,EAAmE;AAAC,WAAO,IAAP;AAAY,GAAhF,MAAoF;AAAC,WAAO,KAAP;AAAa;AAAC,CAAtI,CAAuI/E,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBqkB,QAAjB,GAA0B,UAAS5mB,CAAT,EAAW;AAACA,MAAEA,EAAEgc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB,IAAGhc,EAAE+b,KAAF,CAAQ,yBAAR,KAAoC/b,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAnD,EAAqD;AAAC,WAAO,IAAP;AAAY,GAAlE,MAAsE;AAAC,WAAO,KAAP;AAAa;AAAC,CAAlJ,CAAmJmX,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBskB,WAAjB,GAA6B,UAAS7mB,CAAT,EAAW;AAAC,MAAGA,EAAE+b,KAAF,CAAQ,OAAR,CAAH,EAAoB;AAAC,WAAO,KAAP;AAAa,OAAEoI,UAAUnkB,CAAV,CAAF,CAAe,OAAOgX,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBqkB,QAAjB,CAA0B5mB,CAA1B,CAAP;AAAoC,CAA9H,CAA+HgX,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBukB,cAAjB,GAAgC,UAAS9mB,CAAT,EAAW;AAACA,MAAEA,EAAEgc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB,IAAGhc,EAAE+b,KAAF,CAAQ,eAAR,CAAH,EAA4B;AAAC,WAAO,IAAP;AAAY,GAAzC,MAA6C;AAAC,WAAO,KAAP;AAAa;AAAC,CAA/H,CAAgI,SAASgL,WAAT,CAAqB/mB,CAArB,EAAuB;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAAC,WAAM,MAAIG,CAAV;AAAY,OAAGA,EAAEqC,MAAF,CAAS,CAAT,EAAW,CAAX,IAAc,GAAjB,EAAqB;AAAC,WAAM,OAAKrC,CAAX;AAAa,UAAOA,CAAP;AAAS,UAASgnB,cAAT,CAAwBznB,CAAxB,EAA0B;AAACA,MAAEA,EAAEyc,OAAF,CAAU,WAAV,EAAsB,EAAtB,CAAF,CAA4Bzc,IAAEA,EAAEyc,OAAF,CAAU,WAAV,EAAsB,EAAtB,CAAF,CAA4Bzc,IAAEA,EAAEyc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB,IAAG;AAAC,QAAIvc,IAAEF,EAAE4e,KAAF,CAAQ,GAAR,EAAa8I,GAAb,CAAiB,UAASnoB,CAAT,EAAWU,CAAX,EAAaT,CAAb,EAAe;AAAC,UAAIC,IAAEoD,SAAStD,CAAT,CAAN,CAAkB,IAAGE,IAAE,CAAF,IAAK,MAAIA,CAAZ,EAAc;AAAC,cAAK,4BAAL;AAAkC,WAAIE,IAAE,CAAC,OAAKF,EAAE8B,QAAF,CAAW,EAAX,CAAN,EAAsBc,KAAtB,CAA4B,CAAC,CAA7B,CAAN,CAAsC,OAAO1C,CAAP;AAAS,KAAnJ,EAAqJgD,IAArJ,CAA0J,EAA1J,CAAN,CAAoK,OAAOzC,CAAP;AAAS,GAAjL,CAAiL,OAAMO,CAAN,EAAQ;AAAC,UAAK,qCAAmCA,CAAxC;AAA0C;AAAC,KAAIknB,aAAW,SAAXA,UAAW,CAASznB,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAId,IAAEO,EAAEI,MAAR,CAAe,IAAGJ,EAAEI,MAAF,GAASG,EAAEH,MAAd,EAAqB;AAACX,QAAEc,EAAEH,MAAJ;AAAW,QAAI,IAAIN,IAAE,CAAV,EAAYA,IAAEL,CAAd,EAAgBK,GAAhB,EAAoB;AAAC,QAAGE,EAAEgD,UAAF,CAAalD,CAAb,KAAiBS,EAAEyC,UAAF,CAAalD,CAAb,CAApB,EAAoC;AAAC,aAAOA,CAAP;AAAS;AAAC,OAAGE,EAAEI,MAAF,IAAUG,EAAEH,MAAf,EAAsB;AAAC,WAAOX,CAAP;AAAS,UAAO,CAAC,CAAR;AAAU,CAA3L;AAClzN,IAAG,OAAO8X,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UA0E3BA,IA1E2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKf,MAAZ,IAAoB,WAApB,IAAiC,CAACe,KAAKf,MAA1C,EAAiD;AAACe,OAAKf,MAAL,GAAY,EAAZ;AAAe,MAAKA,MAAL,CAAYiB,IAAZ,GAAiB,IAAI,YAAU;AAAC,OAAKiQ,cAAL,GAAoB,EAACC,MAAK,gCAAN,EAAuCC,QAAO,wCAA9C,EAAuFC,QAAO,wCAA9F,EAAuIC,QAAO,wCAA9I,EAAuLC,QAAO,wCAA9L,EAAuOC,KAAI,sCAA3O,EAAkRC,KAAI,sCAAtR,EAA6TC,WAAU,gCAAvU,EAApB,CAA8X,KAAKC,eAAL,GAAqB,EAACF,KAAI,UAAL,EAAgBN,MAAK,UAArB,EAAgCC,QAAO,UAAvC,EAAkDC,QAAO,UAAzD,EAAoEC,QAAO,UAA3E,EAAsFC,QAAO,UAA7F,EAAwGG,WAAU,UAAlH,EAA6HE,SAAQ,UAArI,EAAgJC,UAAS,UAAzJ,EAAoKC,YAAW,UAA/K,EAA0LC,YAAW,UAArM,EAAgNC,YAAW,UAA3N,EAAsOC,YAAW,UAAjP,EAA4PC,eAAc,UAA1Q,EAAqRC,YAAW,gBAAhS,EAAiTC,aAAY,gBAA7T,EAA8UC,eAAc,gBAA5V,EAA6WC,eAAc,gBAA3X,EAA4YC,eAAc,gBAA1Z,EAA2aC,eAAc,gBAAzb,EAA0cC,kBAAiB,gBAA3d,EAA4eC,cAAa,gBAAzf,EAA0gBC,eAAc,gBAAxhB,EAAyiBC,iBAAgB,gBAAzjB,EAA0kBC,iBAAgB,gBAA1lB,EAA2mBC,iBAAgB,gBAA3nB,EAA4oBC,iBAAgB,gBAA5pB,EAA6qBC,oBAAmB,gBAAhsB,EAAitBC,aAAY,gBAA7tB,EAA8uBC,eAAc,gBAA5vB,EAA6wBC,eAAc,gBAA3xB,EAA4yBC,mBAAkB,gBAA9zB,EAA+0BC,oBAAmB,gBAAl2B,EAAm3BC,sBAAqB,gBAAx4B,EAAy5BC,sBAAqB,gBAA96B,EAA+7BC,sBAAqB,gBAAp9B,EAAq+BC,sBAAqB,gBAA1/B,EAA2gCC,yBAAwB,gBAAniC,EAArB,CAA2kC,KAAKC,yBAAL,GAA+B,EAAClC,KAAIznB,SAASuE,IAAT,CAAcqlB,GAAnB,EAAuBzC,MAAKnnB,SAASuE,IAAT,CAAcslB,IAA1C,EAA+CzC,QAAOpnB,SAASuE,IAAT,CAAculB,MAApE,EAA2EzC,QAAOrnB,SAASuE,IAAT,CAAca,MAAhG,EAAuGkiB,QAAOtnB,SAASuE,IAAT,CAAcsD,MAA5H,EAAmI0f,QAAOvnB,SAASuE,IAAT,CAAcmB,MAAxJ,EAA+JgiB,WAAU1nB,SAASuE,IAAT,CAAcwlB,SAAvL,EAA/B,CAAiO,KAAKC,gBAAL,GAAsB,UAASjqB,CAAT,EAAWT,CAAX,EAAa;AAAC,QAAG,OAAO,KAAK4nB,cAAL,CAAoB5nB,CAApB,CAAP,IAA+B,WAAlC,EAA8C;AAAC,YAAK,+CAA6CA,CAAlD;AAAoD,YAAO,KAAK4nB,cAAL,CAAoB5nB,CAApB,IAAuBS,CAA9B;AAAgC,GAAvK,CAAwK,KAAKkqB,sBAAL,GAA4B,UAASnrB,CAAT,EAAWiB,CAAX,EAAaL,CAAb,EAAe;AAAC,QAAIF,IAAE,KAAKwqB,gBAAL,CAAsBlrB,CAAtB,EAAwBiB,CAAxB,CAAN,CAAiC,IAAId,IAAES,IAAE,CAAR,CAAU,IAAGF,EAAEI,MAAF,GAAS,EAAT,GAAYX,CAAf,EAAiB;AAAC,YAAK,yCAAuCS,CAAvC,GAAyC,GAAzC,GAA6CK,CAAlD;AAAoD,SAAIT,IAAE,MAAN,CAAa,IAAIQ,IAAE,OAAKN,CAAX,CAAa,IAAIX,IAAE,EAAN,CAAS,IAAIgB,IAAEZ,IAAEK,EAAEM,MAAJ,GAAWE,EAAEF,MAAnB,CAA0B,KAAI,IAAIb,IAAE,CAAV,EAAYA,IAAEc,CAAd,EAAgBd,KAAG,CAAnB,EAAqB;AAACF,WAAG,IAAH;AAAQ,SAAIU,IAAED,IAAET,CAAF,GAAIiB,CAAV,CAAY,OAAOP,CAAP;AAAS,GAA7Q,CAA8Q,KAAK2qB,UAAL,GAAgB,UAASnqB,CAAT,EAAWP,CAAX,EAAa;AAAC,QAAIF,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI3qB,CAAL,EAA9B,CAAN,CAA6C,OAAOF,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAApG,CAAqG,KAAKsX,OAAL,GAAa,UAAS/X,CAAT,EAAWE,CAAX,EAAa;AAAC,QAAIO,IAAE,IAAIgX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI3qB,CAAL,EAA9B,CAAN,CAA6C,OAAOO,EAAEsqB,SAAF,CAAY/qB,CAAZ,CAAP;AAAsB,GAA9F,CAA+F,KAAK6nB,IAAL,GAAU,UAASpnB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,MAAL,EAAYG,MAAK,UAAjB,EAA9B,CAAN,CAAkE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAAjH,CAAkH,KAAKsnB,MAAL,GAAY,UAAStnB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAArH,CAAsH,KAAKwqB,SAAL,GAAe,UAASxqB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE+qB,SAAF,CAAYtqB,CAAZ,CAAP;AAAsB,GAArH,CAAsH,KAAKwnB,MAAL,GAAY,UAASxnB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAArH,CAAsH,KAAKyqB,SAAL,GAAe,UAASzqB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE+qB,SAAF,CAAYtqB,CAAZ,CAAP;AAAsB,GAArH;AAAsH,CAA73F,EAAjB,CAA+4FgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwQ,GAAjB,GAAqB,UAAS1nB,CAAT,EAAW;AAAC,MAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,KAAL,EAAWG,MAAK,UAAhB,EAA9B,CAAN,CAAiE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,CAA3H,CAA4HgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiByQ,SAAjB,GAA2B,UAAS3nB,CAAT,EAAW;AAAC,MAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,WAAL,EAAiBG,MAAK,UAAtB,EAA9B,CAAN,CAAuE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,CAAvI,CAAwIgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwT,eAAjB,GAAiC,IAAIjU,YAAJ,EAAjC,CAAoDO,KAAKf,MAAL,CAAYiB,IAAZ,CAAiByT,oBAAjB,GAAsC,UAASprB,CAAT,EAAW;AAAC,MAAIS,IAAE,IAAIuI,KAAJ,CAAUhJ,CAAV,CAAN,CAAmByX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwT,eAAjB,CAAiChb,SAAjC,CAA2C1P,CAA3C,EAA8C,OAAO8jB,QAAQ9jB,CAAR,CAAP;AAAkB,CAArI,CAAsIgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0T,2BAAjB,GAA6C,UAAS5qB,CAAT,EAAW;AAAC,SAAO,IAAI2I,UAAJ,CAAeqO,KAAKf,MAAL,CAAYiB,IAAZ,CAAiByT,oBAAjB,CAAsC3qB,CAAtC,CAAf,EAAwD,EAAxD,CAAP;AAAmE,CAA5H,CAA6HgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB2T,mBAAjB,GAAqC,UAAS3rB,CAAT,EAAW;AAAC,MAAIO,IAAEP,IAAE,CAAR,CAAU,IAAIc,IAAE,CAACd,IAAEO,CAAH,IAAM,CAAZ,CAAc,IAAIF,IAAE,IAAIgJ,KAAJ,CAAUvI,IAAE,CAAZ,CAAN,CAAqBgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwT,eAAjB,CAAiChb,SAAjC,CAA2CnQ,CAA3C,EAA8CA,EAAE,CAAF,IAAK,CAAG,OAAKE,CAAN,GAAS,GAAV,GAAe,GAAhB,IAAqBF,EAAE,CAAF,CAA1B,CAA+B,OAAOukB,QAAQvkB,CAAR,CAAP;AAAkB,CAA7L,CAA8LyX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB4T,0BAAjB,GAA4C,UAAS9qB,CAAT,EAAW;AAAC,SAAO,IAAI2I,UAAJ,CAAeqO,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB2T,mBAAjB,CAAqC7qB,CAArC,CAAf,EAAuD,EAAvD,CAAP;AAAkE,CAA1H,CAA2HgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB6T,4BAAjB,GAA8C,UAASxrB,CAAT,EAAW;AAAC,MAAIS,IAAET,EAAE4O,SAAF,EAAN,CAAoB,OAAM,CAAN,EAAQ;AAAC,QAAI1O,IAAEuX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB4T,0BAAjB,CAA4C9qB,CAA5C,CAAN,CAAqD,IAAGT,EAAEsM,SAAF,CAAYpM,CAAZ,KAAgB,CAAC,CAApB,EAAsB;AAAC,aAAOA,CAAP;AAAS;AAAC;AAAC,CAA9K,CAA+KuX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB8T,2BAAjB,GAA6C,UAASxrB,CAAT,EAAWD,CAAX,EAAa;AAAC,MAAIE,IAAED,EAAEqM,SAAF,CAAYtM,CAAZ,CAAN,CAAqB,IAAGE,KAAG,CAAN,EAAQ;AAAC,UAAK,6BAAL;AAAmC,OAAGA,KAAG,CAAN,EAAQ;AAAC,WAAOD,CAAP;AAAS,OAAIQ,IAAET,EAAEgU,QAAF,CAAW/T,CAAX,CAAN,CAAoB,IAAIN,IAAE8X,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB6T,4BAAjB,CAA8C/qB,CAA9C,CAAN,CAAuD,OAAOd,EAAEsU,GAAF,CAAMhU,CAAN,CAAP;AAAgB,CAAzO,CAA0OwX,KAAKf,MAAL,CAAYgB,aAAZ,GAA0B,UAASxX,CAAT,EAAW;AAAC,MAAIF,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,IAAId,IAAE,IAAN,CAAW,KAAK+rB,iBAAL,GAAuB,UAASnsB,CAAT,EAAWE,CAAX,EAAa;AAACF,QAAEkY,KAAKf,MAAL,CAAYgB,aAAZ,CAA0BE,mBAA1B,CAA8CrY,CAA9C,CAAF,CAAmD,IAAGA,MAAI,IAAJ,IAAUE,MAAIL,SAAjB,EAA2B;AAACK,UAAEgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC9oB,CAAjC,CAAF;AAAsC,SAAG,mDAAmDoG,OAAnD,CAA2DpG,CAA3D,KAA+D,CAAC,CAAhE,IAAmEE,KAAG,UAAzE,EAAoF;AAAC,UAAG;AAAC,aAAKksB,EAAL,GAAQlU,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0S,yBAAjB,CAA2C9qB,CAA3C,EAA8C+B,MAA9C,EAAR;AAA+D,OAAnE,CAAmE,OAAMrB,CAAN,EAAQ;AAAC,cAAK,6CAA2CV,CAA3C,GAA6C,GAA7C,GAAiDU,CAAtD;AAAwD,YAAK2rB,YAAL,GAAkB,UAASpsB,CAAT,EAAW;AAAC,aAAKmsB,EAAL,CAAQhnB,MAAR,CAAenF,CAAf;AAAkB,OAAhD,CAAiD,KAAKqsB,SAAL,GAAe,UAASrsB,CAAT,EAAW;AAAC,YAAIa,IAAEK,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBpD,CAAvB,CAAN,CAAgC,KAAKmsB,EAAL,CAAQhnB,MAAR,CAAetE,CAAf;AAAkB,OAA7E,CAA8E,KAAKyrB,MAAL,GAAY,YAAU;AAAC,YAAItsB,IAAE,KAAKmsB,EAAL,CAAQ/mB,QAAR,EAAN,CAAyB,OAAOpF,EAAE+B,QAAF,CAAWb,SAAS+B,GAAT,CAAaC,GAAxB,CAAP;AAAoC,OAApF,CAAqF,KAAKooB,YAAL,GAAkB,UAAStrB,CAAT,EAAW;AAAC,aAAKosB,YAAL,CAAkBpsB,CAAlB,EAAqB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAxE,CAAyE,KAAKf,SAAL,GAAe,UAASvrB,CAAT,EAAW;AAAC,aAAKqsB,SAAL,CAAersB,CAAf,EAAkB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAlE;AAAmE,SAAG,WAAWnmB,OAAX,CAAmBpG,CAAnB,KAAuB,CAAC,CAAxB,IAA2BE,KAAG,MAAjC,EAAwC;AAAC,UAAG;AAAC,aAAKksB,EAAL,GAAQ,IAAII,KAAKC,IAAL,CAAUjE,MAAd,EAAR;AAA+B,OAAnC,CAAmC,OAAM9nB,CAAN,EAAQ;AAAC,cAAK,6CAA2CV,CAA3C,GAA6C,GAA7C,GAAiDU,CAAtD;AAAwD,YAAK2rB,YAAL,GAAkB,UAASpsB,CAAT,EAAW;AAAC,aAAKmsB,EAAL,CAAQhnB,MAAR,CAAenF,CAAf;AAAkB,OAAhD,CAAiD,KAAKqsB,SAAL,GAAe,UAASxrB,CAAT,EAAW;AAAC,YAAIb,IAAEusB,KAAKE,KAAL,CAAWpM,GAAX,CAAeqM,MAAf,CAAsB7rB,CAAtB,CAAN,CAA+B,KAAKsrB,EAAL,CAAQhnB,MAAR,CAAenF,CAAf;AAAkB,OAA5E,CAA6E,KAAKssB,MAAL,GAAY,YAAU;AAAC,YAAItsB,IAAE,KAAKmsB,EAAL,CAAQ/mB,QAAR,EAAN,CAAyB,OAAOmnB,KAAKE,KAAL,CAAWpM,GAAX,CAAesM,QAAf,CAAwB3sB,CAAxB,CAAP;AAAkC,OAAlF,CAAmF,KAAKsrB,YAAL,GAAkB,UAAStrB,CAAT,EAAW;AAAC,aAAKosB,YAAL,CAAkBpsB,CAAlB,EAAqB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAxE,CAAyE,KAAKf,SAAL,GAAe,UAASvrB,CAAT,EAAW;AAAC,aAAKqsB,SAAL,CAAersB,CAAf,EAAkB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAlE;AAAmE;AAAC,GAA9rC,CAA+rC,KAAKF,YAAL,GAAkB,UAAS3rB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKmsB,OAA3D,GAAmE,GAAnE,GAAuE,KAAKC,QAAjF;AAA0F,GAAxH,CAAyH,KAAKR,SAAL,GAAe,UAAS5rB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKmsB,OAAxD,GAAgE,GAAhE,GAAoE,KAAKC,QAA9E;AAAuF,GAAlH,CAAmH,KAAKP,MAAL,GAAY,YAAU;AAAC,UAAK,+CAA6C,KAAKM,OAAlD,GAA0D,GAA1D,GAA8D,KAAKC,QAAxE;AAAiF,GAAxG,CAAyG,KAAKvB,YAAL,GAAkB,UAAS7qB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKmsB,OAA3D,GAAmE,GAAnE,GAAuE,KAAKC,QAAjF;AAA0F,GAAxH,CAAyH,KAAKtB,SAAL,GAAe,UAAS9qB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKmsB,OAAxD,GAAgE,GAAhE,GAAoE,KAAKC,QAA9E;AAAuF,GAAlH,CAAmH,IAAGnsB,MAAId,SAAP,EAAiB;AAAC,QAAGc,EAAE2qB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAKgtB,OAAL,GAAalsB,EAAE2qB,GAAf,CAAmB,IAAG3qB,EAAE8qB,IAAF,KAAS5rB,SAAZ,EAAsB;AAAC,aAAKitB,QAAL,GAAc5U,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC,KAAK+D,OAAtC,CAAd;AAA6D,YAAKV,iBAAL,CAAuB,KAAKU,OAA5B,EAAoC,KAAKC,QAAzC;AAAmD;AAAC;AAAC,CAA3gE,CAA4gE5U,KAAKf,MAAL,CAAYgB,aAAZ,CAA0BE,mBAA1B,GAA8C,UAASnX,CAAT,EAAW;AAAC,MAAG,OAAOA,CAAP,KAAW,QAAd,EAAuB;AAACA,QAAEA,EAAEif,WAAF,EAAF,CAAkBjf,IAAEA,EAAEgc,OAAF,CAAU,GAAV,EAAc,EAAd,CAAF;AAAoB,UAAOhc,CAAP;AAAS,CAAjI,CAAkIgX,KAAKf,MAAL,CAAYgB,aAAZ,CAA0BG,aAA1B,GAAwC,UAAS3X,CAAT,EAAW;AAAC,MAAIF,IAAEyX,KAAKf,MAAL,CAAYgB,aAAlB,CAAgC,IAAIjX,IAAET,EAAE4X,mBAAF,CAAsB1X,CAAtB,CAAN,CAA+B,IAAGF,EAAEssB,UAAF,CAAa7rB,CAAb,MAAkBrB,SAArB,EAA+B;AAAC,UAAK,8BAA4Bc,CAAjC;AAAmC,UAAOF,EAAEssB,UAAF,CAAa7rB,CAAb,CAAP;AAAuB,CAA7M,CAA8MgX,KAAKf,MAAL,CAAYgB,aAAZ,CAA0B4U,UAA1B,GAAqC,EAACnE,KAAI,EAAL,EAAQN,MAAK,EAAb,EAAgBC,QAAO,EAAvB,EAA0BC,QAAO,EAAjC,EAAoCC,QAAO,EAA3C,EAA8CC,QAAO,EAArD,EAAwDG,WAAU,EAAlE,EAArC,CAA2G3Q,KAAKf,MAAL,CAAY6V,GAAZ,GAAgB,UAAS5sB,CAAT,EAAW;AAAC,MAAIF,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,IAAIO,IAAE,IAAN,CAAW,IAAIR,IAAE,IAAN,CAAW,IAAID,IAAE,IAAN,CAAW,KAAK0rB,iBAAL,GAAuB,UAASlrB,CAAT,EAAWH,CAAX,EAAa;AAACG,QAAEA,EAAEkf,WAAF,EAAF,CAAkB,IAAGlf,KAAG,IAAN,EAAW;AAACA,UAAE,UAAF;AAAa,SAAEA,EAAEkf,WAAF,EAAF,CAAkB,IAAGlf,EAAEsC,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,YAAK,6CAA2CtC,CAAhD;AAAkD,SAAGH,MAAIjB,SAAP,EAAiB;AAACiB,UAAEoX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC7nB,CAAjC,CAAF;AAAsC,UAAKgsB,OAAL,GAAahsB,IAAE,GAAF,GAAMH,CAAnB,CAAqB,IAAId,IAAEiB,EAAEsC,MAAF,CAAS,CAAT,CAAN,CAAkB,IAAG,mDAAmD6C,OAAnD,CAA2DpG,CAA3D,KAA+D,CAAC,CAAhE,IAAmEc,KAAG,UAAzE,EAAoF;AAAC,UAAG;AAAC,YAAID,IAAEqX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0S,yBAAjB,CAA2C9qB,CAA3C,CAAN,CAAoD,KAAKktB,GAAL,GAAS/rB,SAASuE,IAAT,CAAcD,IAAd,CAAmB1D,MAAnB,CAA0BlB,CAA1B,EAA4B,KAAKssB,IAAjC,CAAT;AAAgD,OAAxG,CAAwG,OAAMltB,CAAN,EAAQ;AAAC,cAAK,iDAA+CD,CAA/C,GAAiD,GAAjD,GAAqDC,CAA1D;AAA4D,YAAKosB,YAAL,GAAkB,UAASrrB,CAAT,EAAW;AAAC,aAAKksB,GAAL,CAAS9nB,MAAT,CAAgBpE,CAAhB;AAAmB,OAAjD,CAAkD,KAAKsrB,SAAL,GAAe,UAAStrB,CAAT,EAAW;AAAC,YAAIiC,IAAE9B,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBrC,CAAvB,CAAN,CAAgC,KAAKksB,GAAL,CAAS9nB,MAAT,CAAgBnC,CAAhB;AAAmB,OAA9E,CAA+E,KAAKmqB,OAAL,GAAa,YAAU;AAAC,YAAIpsB,IAAE,KAAKksB,GAAL,CAAS7nB,QAAT,EAAN,CAA0B,OAAOrE,EAAEgB,QAAF,CAAWb,SAAS+B,GAAT,CAAaC,GAAxB,CAAP;AAAoC,OAAtF,CAAuF,KAAKkqB,aAAL,GAAmB,UAASrsB,CAAT,EAAW;AAAC,aAAKqrB,YAAL,CAAkBrrB,CAAlB,EAAqB,OAAO,KAAKosB,OAAL,EAAP;AAAsB,OAA1E,CAA2E,KAAKE,UAAL,GAAgB,UAAStsB,CAAT,EAAW;AAAC,aAAKsrB,SAAL,CAAetrB,CAAf,EAAkB,OAAO,KAAKosB,OAAL,EAAP;AAAsB,OAApE;AAAqE;AAAC,GAAx3B,CAAy3B,KAAKf,YAAL,GAAkB,UAASrsB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKitB,OAAhE;AAAwE,GAAtG,CAAuG,KAAKX,SAAL,GAAe,UAAStsB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKitB,OAA7D;AAAqE,GAAhG,CAAiG,KAAKG,OAAL,GAAa,YAAU;AAAC,UAAK,+CAA6C,KAAKH,OAAvD;AAA+D,GAAvF,CAAwF,KAAKI,aAAL,GAAmB,UAASrtB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKitB,OAAhE;AAAwE,GAAvG,CAAwG,KAAKK,UAAL,GAAgB,UAASttB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKitB,OAA7D;AAAqE,GAAjG,CAAkG,KAAKM,WAAL,GAAiB,UAASttB,CAAT,EAAW;AAAC,QAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,UAAID,IAAEC,CAAN,CAAQ,IAAGA,EAAEc,MAAF,GAAS,CAAT,IAAY,CAAZ,IAAe,CAACd,EAAEgd,KAAF,CAAQ,gBAAR,CAAnB,EAA6C;AAACjd,YAAEyY,UAAUxY,CAAV,CAAF;AAAe,YAAKktB,IAAL,GAAUhsB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBrD,CAAvB,CAAV,CAAoC;AAAO,SAAG,QAAOC,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC,YAAK,gDAA8CA,CAAnD;AAAqD,SAAID,IAAE,IAAN,CAAW,IAAGC,EAAEqgB,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,UAAGI,EAAEqgB,GAAF,CAAMvf,MAAN,GAAa,CAAb,IAAgB,CAAhB,IAAmB,CAACd,EAAEqgB,GAAF,CAAMrD,KAAN,CAAY,gBAAZ,CAAvB,EAAqD;AAAC,cAAK,8BAA4Bhd,EAAEqgB,GAAnC;AAAuC,WAAErgB,EAAEqgB,GAAJ;AAAQ,SAAGrgB,EAAEutB,IAAF,KAAS3tB,SAAZ,EAAsB;AAACG,UAAEkgB,UAAUjgB,EAAEutB,IAAZ,CAAF;AAAoB,SAAGvtB,EAAEwtB,IAAF,KAAS5tB,SAAZ,EAAsB;AAACG,UAAEyY,UAAUxY,EAAEwtB,IAAZ,CAAF;AAAoB,SAAGxtB,EAAEytB,GAAF,KAAQ7tB,SAAX,EAAqB;AAACG,UAAEsJ,SAASrJ,EAAEytB,GAAX,CAAF;AAAkB,SAAGztB,EAAE0tB,IAAF,KAAS9tB,SAAZ,EAAsB;AAACG,UAAEulB,UAAUtlB,EAAE0tB,IAAZ,CAAF;AAAoB,SAAG3tB,KAAG,IAAN,EAAW;AAAC,YAAK,gDAA8CC,CAAnD;AAAqD,UAAKktB,IAAL,GAAUhsB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBrD,CAAvB,CAAV;AAAoC,GAApoB,CAAqoB,IAAGI,MAAIP,SAAP,EAAiB;AAAC,QAAGO,EAAE+sB,IAAF,KAASttB,SAAZ,EAAsB;AAAC,WAAK0tB,WAAL,CAAiBntB,EAAE+sB,IAAnB;AAAyB,SAAG/sB,EAAEkrB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAKgtB,OAAL,GAAazsB,EAAEkrB,GAAf,CAAmB,IAAGlrB,EAAEqrB,IAAF,KAAS5rB,SAAZ,EAAsB;AAAC,aAAKitB,QAAL,GAAc5U,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC,KAAK+D,OAAtC,CAAd;AAA6D,YAAKV,iBAAL,CAAuB,KAAKU,OAA5B,EAAoC,KAAKC,QAAzC;AAAmD;AAAC;AAAC,CAA/yE,CAAgzE5U,KAAKf,MAAL,CAAYyW,SAAZ,GAAsB,UAASpsB,CAAT,EAAW;AAAC,MAAIgB,IAAE,IAAN,CAAW,IAAIlB,IAAE,IAAN,CAAW,IAAIqB,IAAE,IAAN,CAAW,IAAIhC,IAAE,IAAN,CAAW,IAAIK,IAAE,IAAN,CAAW,IAAIZ,IAAE,IAAN,CAAW,IAAIa,IAAE,IAAN,CAAW,IAAIhB,IAAE,IAAN,CAAW,IAAIsB,IAAE,IAAN,CAAW,IAAIb,IAAE,IAAN,CAAW,IAAID,IAAE,CAAC,CAAP,CAAS,IAAIT,IAAE,IAAN,CAAW,IAAIa,IAAE,IAAN,CAAW,IAAIK,IAAE,IAAN,CAAW,IAAIJ,IAAE,IAAN,CAAW,IAAIZ,IAAE,IAAN,CAAW,KAAK2tB,YAAL,GAAkB,YAAU;AAAC,QAAIprB,IAAE,KAAKoqB,OAAL,CAAa5P,KAAb,CAAmB,gBAAnB,CAAN,CAA2C,IAAGxa,CAAH,EAAK;AAAC,WAAKqrB,SAAL,GAAerrB,EAAE,CAAF,EAAK0d,WAAL,EAAf,CAAkC,KAAK4N,aAAL,GAAmBtrB,EAAE,CAAF,EAAK0d,WAAL,EAAnB;AAAsC;AAAC,GAAvJ,CAAwJ,KAAK6N,uBAAL,GAA6B,UAASxpB,CAAT,EAAWD,CAAX,EAAa;AAAC,QAAIG,IAAE,EAAN,CAAS,IAAInC,IAAEgC,IAAE,CAAF,GAAIC,EAAEzD,MAAZ,CAAmB,KAAI,IAAI4D,IAAE,CAAV,EAAYA,IAAEpC,CAAd,EAAgBoC,GAAhB,EAAoB;AAACD,UAAEA,IAAE,GAAJ;AAAQ,YAAOA,IAAEF,CAAT;AAAW,GAA/G,CAAgH,KAAK2nB,iBAAL,GAAuB,UAASxnB,CAAT,EAAWpC,CAAX,EAAa;AAAC,SAAKsrB,YAAL,GAAoB,IAAGtrB,KAAG,gBAAN,EAAuB;AAAC,YAAK,6BAA2BA,CAAhC;AAAkC,SAAG,mDAAmD6D,OAAnD,CAA2D,KAAK0nB,SAAhE,KAA4E,CAAC,CAAhF,EAAkF;AAAC,UAAG;AAAC,aAAK1B,EAAL,GAAQ,IAAIlU,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,KAAKwC,SAAV,EAA9B,CAAR;AAA4D,OAAhE,CAAgE,OAAMrrB,CAAN,EAAQ;AAAC,cAAK,6CAA2C,KAAKqrB,SAAhD,GAA0D,GAA1D,GAA8DrrB,CAAnE;AAAqE,YAAKd,IAAL,GAAU,UAAS4C,CAAT,EAAWC,CAAX,EAAa;AAAC,YAAI2D,IAAE,IAAN,CAAW,IAAG;AAAC,cAAG3D,MAAI3E,SAAP,EAAiB;AAACsI,gBAAE8lB,QAAQC,MAAR,CAAe3pB,CAAf,CAAF;AAAoB,WAAtC,MAA0C;AAAC4D,gBAAE8lB,QAAQC,MAAR,CAAe3pB,CAAf,EAAiBC,CAAjB,CAAF;AAAsB;AAAC,SAAtE,CAAsE,OAAME,CAAN,EAAQ;AAAC,gBAAK,iBAAeA,CAApB;AAAsB,aAAGyD,EAAE6Q,SAAF,KAAc,IAAjB,EAAsB;AAAC,eAAKmV,MAAL,GAAYhmB,CAAZ,CAAc,KAAKimB,KAAL,GAAW,MAAX;AAAkB,SAAvD,MAA2D;AAAC,cAAGjmB,EAAE4Q,QAAF,KAAa,IAAhB,EAAqB;AAAC,iBAAKsV,MAAL,GAAYlmB,CAAZ,CAAc,KAAKimB,KAAL,GAAW,QAAX;AAAoB,WAAxD,MAA4D;AAAC,kBAAK,kBAAgBjmB,CAArB;AAAuB;AAAC;AAAC,OAA1R,CAA2R,KAAKkkB,YAAL,GAAkB,UAAS3nB,CAAT,EAAW;AAAC,aAAK0nB,EAAL,CAAQC,YAAR,CAAqB3nB,CAArB;AAAwB,OAAtD,CAAuD,KAAK4nB,SAAL,GAAe,UAAS5nB,CAAT,EAAW;AAAC,aAAK0nB,EAAL,CAAQE,SAAR,CAAkB5nB,CAAlB;AAAqB,OAAhD,CAAiD,KAAK4pB,IAAL,GAAU,YAAU;AAAC,aAAKC,QAAL,GAAc,KAAKnC,EAAL,CAAQG,MAAR,EAAd,CAA+B,IAAG,OAAO,KAAKiC,QAAZ,IAAsB,WAAtB,IAAmC,OAAO,KAAKC,WAAZ,IAAyB,WAA/D,EAA2E;AAAC,cAAI/pB,IAAE,IAAIwT,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAM,KAAKqU,WAAZ,EAAtB,CAAN,CAAsD,KAAKE,KAAL,GAAWjqB,EAAEkqB,OAAF,CAAU,KAAKL,QAAf,EAAwB,KAAKC,QAA7B,CAAX;AAAkD,SAApL,MAAwL;AAAC,cAAG,KAAKL,MAAL,YAAuBzV,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,YAAvD,EAAoE;AAAC,iBAAKY,KAAL,GAAW,KAAKR,MAAL,CAAYU,sBAAZ,CAAmC,KAAKN,QAAxC,EAAiD,KAAKT,SAAtD,EAAgE,KAAKgB,UAArE,CAAX;AAA4F,WAAjK,MAAqK;AAAC,gBAAG,KAAKX,MAAL,YAAuBzV,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,KAAvD,EAA6D;AAAC,mBAAKY,KAAL,GAAW,KAAKR,MAAL,CAAYY,mBAAZ,CAAgC,KAAKR,QAArC,EAA8C,KAAKT,SAAnD,CAAX;AAAyE,aAAvI,MAA2I;AAAC,kBAAG,KAAKK,MAAL,YAAuBjW,KAAKf,MAAL,CAAYuX,KAAtC,EAA4C;AAAC,qBAAKC,KAAL,GAAW,KAAKR,MAAL,CAAYY,mBAAZ,CAAgC,KAAKR,QAArC,CAAX;AAA0D,eAAvG,MAA2G;AAAC,oBAAG,KAAKJ,MAAL,YAAuBjW,KAAKf,MAAL,CAAY6X,GAAtC,EAA0C;AAAC,uBAAKL,KAAL,GAAW,KAAKR,MAAL,CAAYY,mBAAZ,CAAgC,KAAKR,QAArC,CAAX;AAA0D,iBAArG,MAAyG;AAAC,wBAAK,6CAA2C,KAAKR,aAArD;AAAmE;AAAC;AAAC;AAAC;AAAC,gBAAO,KAAKY,KAAZ;AAAkB,OAA90B,CAA+0B,KAAKM,UAAL,GAAgB,UAASvqB,CAAT,EAAW;AAAC,aAAK2nB,YAAL,CAAkB3nB,CAAlB,EAAqB,OAAO,KAAK4pB,IAAL,EAAP;AAAmB,OAApE,CAAqE,KAAKM,OAAL,GAAa,UAASlqB,CAAT,EAAW;AAAC,aAAK4nB,SAAL,CAAe5nB,CAAf,EAAkB,OAAO,KAAK4pB,IAAL,EAAP;AAAmB,OAA9D,CAA+D,KAAKY,MAAL,GAAY,UAASxqB,CAAT,EAAW;AAAC,aAAK6pB,QAAL,GAAc,KAAKnC,EAAL,CAAQG,MAAR,EAAd,CAA+B,IAAG,OAAO,KAAK4C,QAAZ,IAAsB,WAAtB,IAAmC,OAAO,KAAKV,WAAZ,IAAyB,WAA/D,EAA2E;AAAC,cAAIlqB,IAAE,IAAI2T,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAM,KAAKqU,WAAZ,EAAtB,CAAN,CAAsD,OAAOlqB,EAAE6qB,SAAF,CAAY,KAAKb,QAAjB,EAA0B7pB,CAA1B,EAA4B,KAAKyqB,QAAjC,CAAP;AAAkD,SAApL,MAAwL;AAAC,cAAG,KAAKd,MAAL,YAAuB3V,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,YAAvD,EAAoE;AAAC,mBAAO,KAAKM,MAAL,CAAYgB,wBAAZ,CAAqC,KAAKd,QAA1C,EAAmD7pB,CAAnD,EAAqD,KAAKopB,SAA1D,EAAoE,KAAKgB,UAAzE,CAAP;AAA4F,WAAjK,MAAqK;AAAC,gBAAG,KAAKT,MAAL,YAAuB3V,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,KAAvD,EAA6D;AAAC,qBAAO,KAAKM,MAAL,CAAYiB,qBAAZ,CAAkC,KAAKf,QAAvC,EAAgD7pB,CAAhD,CAAP;AAA0D,aAAxH,MAA4H;AAAC,kBAAGwT,KAAKf,MAAL,CAAYuX,KAAZ,KAAoB7uB,SAApB,IAA+B,KAAKwuB,MAAL,YAAuBnW,KAAKf,MAAL,CAAYuX,KAArE,EAA2E;AAAC,uBAAO,KAAKL,MAAL,CAAYiB,qBAAZ,CAAkC,KAAKf,QAAvC,EAAgD7pB,CAAhD,CAAP;AAA0D,eAAtI,MAA0I;AAAC,oBAAGwT,KAAKf,MAAL,CAAY6X,GAAZ,KAAkBnvB,SAAlB,IAA6B,KAAKwuB,MAAL,YAAuBnW,KAAKf,MAAL,CAAY6X,GAAnE,EAAuE;AAAC,yBAAO,KAAKX,MAAL,CAAYiB,qBAAZ,CAAkC,KAAKf,QAAvC,EAAgD7pB,CAAhD,CAAP;AAA0D,iBAAlI,MAAsI;AAAC,wBAAK,4CAA0C,KAAKqpB,aAApD;AAAkE;AAAC;AAAC;AAAC;AAAC;AAAC,OAA52B;AAA62B;AAAC,GAAxhF,CAAyhF,KAAKpsB,IAAL,GAAU,UAASc,CAAT,EAAWF,CAAX,EAAa;AAAC,UAAK,qDAAmD,KAAKgtB,WAA7D;AAAyE,GAAjG,CAAkG,KAAKlD,YAAL,GAAkB,UAAS5pB,CAAT,EAAW;AAAC,UAAK,uDAAqD,KAAK8sB,WAA/D;AAA2E,GAAzG,CAA0G,KAAKjD,SAAL,GAAe,UAAS7pB,CAAT,EAAW;AAAC,UAAK,oDAAkD,KAAK8sB,WAA5D;AAAwE,GAAnG,CAAoG,KAAKjB,IAAL,GAAU,YAAU;AAAC,UAAK,4CAA0C,KAAKiB,WAApD;AAAgE,GAArF,CAAsF,KAAKN,UAAL,GAAgB,UAASxsB,CAAT,EAAW;AAAC,UAAK,uDAAqD,KAAK8sB,WAA/D;AAA2E,GAAvG,CAAwG,KAAKX,OAAL,GAAa,UAASnsB,CAAT,EAAW;AAAC,UAAK,oDAAkD,KAAK8sB,WAA5D;AAAwE,GAAjG,CAAkG,KAAKL,MAAL,GAAY,UAASzsB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAK8sB,WAA7D;AAAyE,GAAjG,CAAkG,KAAKC,UAAL,GAAgBhuB,CAAhB,CAAkB,IAAGA,MAAI3B,SAAP,EAAiB;AAAC,QAAG2B,EAAE8pB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAKgtB,OAAL,GAAarrB,EAAE8pB,GAAf,CAAmB,IAAG9pB,EAAEiqB,IAAF,KAAS5rB,SAAZ,EAAsB;AAAC,aAAKitB,QAAL,GAAc5U,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC,KAAK+D,OAAtC,CAAd;AAA6D,OAApF,MAAwF;AAAC,aAAKC,QAAL,GAActrB,EAAEiqB,IAAhB;AAAqB,YAAK8D,WAAL,GAAiB,KAAK1C,OAAL,GAAa,GAAb,GAAiB,KAAKC,QAAvC,CAAgD,KAAKX,iBAAL,CAAuB,KAAKU,OAA5B,EAAoC,KAAKC,QAAzC,EAAmD,KAAKe,YAAL;AAAoB,SAAGrsB,EAAEiuB,UAAF,KAAe5vB,SAAlB,EAA4B;AAAC,WAAKivB,UAAL,GAAgBttB,EAAEiuB,UAAlB;AAA6B,SAAGjuB,EAAEkuB,SAAF,KAAc7vB,SAAjB,EAA2B;AAAC,UAAG2B,EAAEmuB,SAAF,KAAc9vB,SAAjB,EAA2B;AAAC,cAAK,uDAAL;AAA6D,OAAzF,MAA6F;AAAC,YAAG;AAAC,cAAI2C,IAAEyrB,QAAQC,MAAR,CAAe1sB,EAAEkuB,SAAjB,CAAN,CAAkC,KAAK/tB,IAAL,CAAUa,CAAV;AAAa,SAAnD,CAAmD,OAAMS,CAAN,EAAQ;AAAC,gBAAK,0CAAwCA,CAA7C;AAA+C;AAAC;AAAC;AAAC;AAAC,CAAxvI,CAAyvIiV,KAAKf,MAAL,CAAYyY,MAAZ,GAAmB,UAAS1uB,CAAT,EAAW,CAAE,CAAhC,CAAiCgX,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBtW,OAAnB,GAA2B,UAAS5Y,CAAT,EAAWR,CAAX,EAAaE,CAAb,EAAe;AAAC,MAAGF,aAAawY,MAAb,IAAqBxY,EAAE6Y,QAA1B,EAAmC;AAAC,QAAIpY,IAAEuX,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBC,kBAAnB,CAAsC3vB,CAAtC,EAAwCE,CAAxC,CAAN,CAAiD,IAAGO,MAAI,KAAP,EAAa;AAAC,aAAOT,EAAEoZ,OAAF,CAAU5Y,CAAV,CAAP;AAAoB,SAAGC,MAAI,SAAP,EAAiB;AAAC,aAAOT,EAAEqZ,WAAF,CAAc7Y,CAAd,EAAgB,MAAhB,CAAP;AAA+B,SAAID,IAAEE,EAAEsc,KAAF,CAAQ,gBAAR,CAAN,CAAgC,IAAGxc,MAAI,IAAP,EAAY;AAAC,aAAOP,EAAEqZ,WAAF,CAAc7Y,CAAd,EAAgB,QAAMD,EAAE,CAAF,CAAtB,CAAP;AAAmC,WAAK,uDAAqDL,CAA1D;AAA4D,GAApT,MAAwT;AAAC,UAAK,8CAAL;AAAoD;AAAC,CAAzZ,CAA0Z8X,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBE,OAAnB,GAA2B,UAASpvB,CAAT,EAAWR,CAAX,EAAaE,CAAb,EAAe;AAAC,MAAGF,aAAawY,MAAb,IAAqBxY,EAAE8Y,SAA1B,EAAoC;AAAC,QAAIrY,IAAEuX,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBC,kBAAnB,CAAsC3vB,CAAtC,EAAwCE,CAAxC,CAAN,CAAiD,IAAGO,MAAI,KAAP,EAAa;AAAC,aAAOT,EAAE4vB,OAAF,CAAUpvB,CAAV,CAAP;AAAoB,SAAGC,MAAI,SAAP,EAAiB;AAAC,aAAOT,EAAE6vB,WAAF,CAAcrvB,CAAd,EAAgB,MAAhB,CAAP;AAA+B,SAAID,IAAEE,EAAEsc,KAAF,CAAQ,gBAAR,CAAN,CAAgC,IAAGxc,MAAI,IAAP,EAAY;AAAC,aAAOP,EAAE6vB,WAAF,CAAcrvB,CAAd,EAAgB,QAAMD,EAAE,CAAF,CAAtB,CAAP;AAAmC,WAAK,uDAAqDL,CAA1D;AAA4D,GAArT,MAAyT;AAAC,UAAK,8CAAL;AAAoD;AAAC,CAA1Z,CAA2Z8X,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBC,kBAAnB,GAAsC,UAASpvB,CAAT,EAAWS,CAAX,EAAa;AAAC,MAAGT,aAAaiY,MAAhB,EAAuB;AAAC,QAAG,4DAA4DtS,OAA5D,CAAoElF,CAApE,KAAwE,CAAC,CAA5E,EAA8E;AAAC,aAAOA,CAAP;AAAS,SAAGA,MAAI,IAAJ,IAAUA,MAAIrB,SAAjB,EAA2B;AAAC,aAAM,KAAN;AAAY,WAAK,kEAAgEqB,CAArE;AAAuE,SAAK,uDAAqDA,CAA1D;AAA4D,CAA/U,CAAgVgX,KAAKf,MAAL,CAAYsL,GAAZ,GAAgB,IAAI,YAAU;AAAC,OAAKuN,WAAL,GAAiB,EAAC,sBAAqB,eAAtB,EAAsC,kBAAiB,aAAvD,EAAqE,kBAAiB,KAAtF,EAA4F,oBAAmB,WAA/G,EAA2H,cAAa,WAAxI,EAAoJ,cAAa,WAAjK,EAA6K,cAAa,WAA1L,EAAsM,cAAa,WAAnN,EAA+N,cAAa,WAA5O,EAAwP,kBAAiB,aAAzQ,EAAuR,sBAAqB,eAA5S,EAA4T,sBAAqB,eAAjV,EAAjB;AAAoX,CAAnY,EAAhB;AAC/5c,IAAG,OAAO9X,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UAyE3BA,IAzE2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKf,MAAZ,IAAoB,WAApB,IAAiC,CAACe,KAAKf,MAA1C,EAAiD;AAACe,OAAKf,MAAL,GAAY,EAAZ;AAAe,MAAKA,MAAL,CAAYuX,KAAZ,GAAkB,UAASzuB,CAAT,EAAW;AAAC,MAAIS,IAAE,WAAN,CAAkB,IAAIV,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,IAAIP,IAAE,IAAN,CAAW,IAAIgB,IAAE,IAAIyW,YAAJ,EAAN,CAAyB,IAAIvX,IAAE,IAAN,CAAW,KAAKoZ,IAAL,GAAU,IAAV,CAAe,KAAKR,SAAL,GAAe,KAAf,CAAqB,KAAKD,QAAL,GAAc,KAAd,CAAoB,SAASpY,CAAT,CAAW8B,CAAX,EAAajB,CAAb,EAAemB,CAAf,EAAiBrB,CAAjB,EAAmB;AAAC,QAAIT,IAAE8E,KAAKf,GAAL,CAASpD,EAAE6N,SAAF,EAAT,EAAuB/N,EAAE+N,SAAF,EAAvB,CAAN,CAA4C,IAAI9M,IAAEE,EAAEga,KAAF,CAAQ9Z,CAAR,CAAN,CAAiB,IAAIH,IAAEC,EAAE2X,KAAF,CAAQW,WAAR,EAAN,CAA4B,KAAI,IAAIxZ,IAAEV,IAAE,CAAZ,EAAcU,KAAG,CAAjB,EAAmB,EAAEA,CAArB,EAAuB;AAACiB,UAAEA,EAAEka,OAAF,EAAF,CAAcla,EAAEyF,CAAF,GAAI4B,WAAWmD,GAAf,CAAmB,IAAGxL,EAAE+O,OAAF,CAAUhP,CAAV,CAAH,EAAgB;AAAC,YAAGD,EAAEiP,OAAF,CAAUhP,CAAV,CAAH,EAAgB;AAACiB,cAAEA,EAAEia,KAAF,CAAQla,CAAR,CAAF;AAAa,SAA9B,MAAkC;AAACC,cAAEA,EAAEia,KAAF,CAAQha,CAAR,CAAF;AAAa;AAAC,OAAlE,MAAsE;AAAC,YAAGnB,EAAEiP,OAAF,CAAUhP,CAAV,CAAH,EAAgB;AAACiB,cAAEA,EAAEia,KAAF,CAAQ9Z,CAAR,CAAF;AAAa;AAAC;AAAC,YAAOH,CAAP;AAAS,QAAKytB,YAAL,GAAkB,UAASnvB,CAAT,EAAW;AAAC,WAAO,IAAI+I,UAAJ,CAAe/I,EAAEuO,SAAF,EAAf,EAA6BnO,CAA7B,EAAgCqM,GAAhC,CAAoCzM,EAAE2T,QAAF,CAAW5K,WAAWmD,GAAtB,CAApC,EAAgE0H,GAAhE,CAAoE7K,WAAWmD,GAA/E,CAAP;AAA2F,GAAzH,CAA0H,KAAKkjB,aAAL,GAAmB,UAASpvB,CAAT,EAAW;AAAC,SAAKqvB,QAAL,GAAcjY,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BC,SAA1B,CAAoCvvB,CAApC,CAAd,CAAqD,KAAKwvB,SAAL,GAAe,IAAf,CAAoB,KAAKC,SAAL,GAAe,IAAf,CAAoB,KAAKC,SAAL,GAAe1vB,CAAf;AAAiB,GAA7I,CAA8I,KAAK2vB,gBAAL,GAAsB,UAAS3vB,CAAT,EAAW;AAAC,SAAKkY,SAAL,GAAe,IAAf,CAAoB,KAAKsX,SAAL,GAAexvB,CAAf;AAAiB,GAAvE,CAAwE,KAAK4vB,eAAL,GAAqB,UAAS5vB,CAAT,EAAW;AAAC,SAAKiY,QAAL,GAAc,IAAd,CAAmB,KAAKwX,SAAL,GAAezvB,CAAf;AAAiB,GAArE,CAAsE,KAAK6vB,iBAAL,GAAuB,YAAU;AAAC,QAAI1vB,IAAE,KAAKsvB,SAAX,CAAqB,IAAGtvB,EAAEsC,MAAF,CAAS,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,YAAK,mDAAL;AAAyD,SAAI1C,IAAE,KAAKsvB,QAAL,CAAcS,MAAd,GAAqB,CAA3B,CAA6B,IAAG3vB,EAAEF,MAAF,KAAW,IAAEF,IAAE,CAAlB,EAAoB;AAAC,YAAK,iCAAL;AAAuC,SAAIC,IAAE,EAAN,CAASA,EAAE0D,CAAF,GAAIvD,EAAEsC,MAAF,CAAS,CAAT,EAAW1C,CAAX,CAAJ,CAAkBC,EAAEqH,CAAF,GAAIlH,EAAEsC,MAAF,CAAS,IAAE1C,CAAX,CAAJ,CAAkB,OAAOC,CAAP;AAAS,GAAxR,CAAyR,KAAK+vB,sBAAL,GAA4B,YAAU;AAAC,QAAI/vB,IAAE,KAAK0vB,SAAX,CAAqB,IAAG1vB,MAAI,WAAJ,IAAiBA,MAAI,YAArB,IAAmCA,MAAI,OAAvC,IAAgDA,MAAI,YAAvD,EAAoE;AAAC,aAAM,OAAN;AAAc,SAAGA,MAAI,WAAJ,IAAiBA,MAAI,YAArB,IAAmCA,MAAI,OAA1C,EAAkD;AAAC,aAAM,OAAN;AAAc,YAAO,IAAP;AAAY,GAA5N,CAA6N,KAAKgwB,kBAAL,GAAwB,YAAU;AAAC,QAAI7vB,IAAE,KAAKkvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIA,IAAE,KAAK2uB,YAAL,CAAkBhvB,CAAlB,CAAN,CAA2B,IAAID,IAAE,KAAKmvB,QAAL,CAAcppB,CAAd,CAAgBiP,QAAhB,CAAyB1U,CAAzB,CAAN,CAAkC,IAAIkB,IAAExB,EAAEma,IAAF,GAASrB,YAAT,EAAN,CAA8B,IAAItY,IAAER,EAAEoa,IAAF,GAAStB,YAAT,EAAN,CAA8B,IAAIhZ,IAAE,KAAKqvB,QAAL,CAAcS,MAAd,GAAqB,CAA3B,CAA6B,IAAI3tB,IAAE,CAAC,eAAa3B,EAAEU,QAAF,CAAW,EAAX,CAAd,EAA8Bc,KAA9B,CAAoC,CAAChC,CAArC,CAAN,CAA8C,IAAI6B,IAAE,CAAC,eAAaH,EAAER,QAAF,CAAW,EAAX,CAAd,EAA8Bc,KAA9B,CAAoC,CAAChC,CAArC,CAAN,CAA8C,IAAIS,IAAE,CAAC,eAAaC,EAAEQ,QAAF,CAAW,EAAX,CAAd,EAA8Bc,KAA9B,CAAoC,CAAChC,CAArC,CAAN,CAA8C,IAAID,IAAE,OAAK8B,CAAL,GAAOpB,CAAb,CAAe,KAAKkvB,gBAAL,CAAsBxtB,CAAtB,EAAyB,KAAKytB,eAAL,CAAqB7vB,CAArB,EAAwB,OAAM,EAAC2tB,UAASvrB,CAAV,EAAYksB,UAAStuB,CAArB,EAAN;AAA8B,GAAvb,CAAwb,KAAKkuB,mBAAL,GAAyB,UAASjuB,CAAT,EAAW;AAAC,WAAO,KAAK8tB,OAAL,CAAa9tB,CAAb,EAAe,KAAKwvB,SAApB,CAAP;AAAsC,GAA3E,CAA4E,KAAK1B,OAAL,GAAa,UAASptB,CAAT,EAAWX,CAAX,EAAa;AAAC,QAAI0B,IAAE,IAAIsH,UAAJ,CAAehJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIG,IAAE,KAAKmvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIkB,IAAE,IAAIqH,UAAJ,CAAerI,CAAf,EAAiB,EAAjB,CAAN,CAA2B,GAAE;AAAC,UAAIyB,IAAE,KAAKgtB,YAAL,CAAkBjvB,CAAlB,CAAN,CAA2B,IAAI2D,IAAE,KAAKwrB,QAAL,CAAcppB,CAApB,CAAsB,IAAIxF,IAAEoD,EAAEqR,QAAF,CAAW/S,CAAX,CAAN,CAAoB,IAAInC,IAAES,EAAE4Z,IAAF,GAASrB,YAAT,GAAwBvM,GAAxB,CAA4BvM,CAA5B,CAAN;AAAqC,KAA7G,QAAmHF,EAAEiM,SAAF,CAAYlD,WAAW2B,IAAvB,KAA8B,CAAjJ,EAAoJ,IAAI9G,IAAEzB,EAAEkT,UAAF,CAAanV,CAAb,EAAgBgV,QAAhB,CAAyBxT,EAAEkS,GAAF,CAAMnS,EAAEyT,QAAF,CAAWlV,CAAX,CAAN,CAAzB,EAA+CyM,GAA/C,CAAmDvM,CAAnD,CAAN,CAA4D,OAAOkX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBqC,gBAAlB,CAAmCjwB,CAAnC,EAAqC4D,CAArC,CAAP;AAA+C,GAAtW,CAAuW,KAAK4pB,IAAL,GAAU,UAASrrB,CAAT,EAAW0B,CAAX,EAAa;AAAC,QAAInC,IAAEmC,CAAN,CAAQ,IAAI9D,IAAE,KAAKsvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIC,IAAEsI,WAAWmnB,qBAAX,CAAiC/tB,CAAjC,CAAN,CAA0C,GAAE;AAAC,UAAIjC,IAAE,KAAKivB,YAAL,CAAkBpvB,CAAlB,CAAN,CAA2B,IAAI0B,IAAE,KAAK4tB,QAAL,CAAcppB,CAApB,CAAsB,IAAIvF,IAAEe,EAAEyT,QAAF,CAAWhV,CAAX,CAAN,CAAoB,IAAIF,IAAEU,EAAE2Z,IAAF,GAASrB,YAAT,GAAwBvM,GAAxB,CAA4B1M,CAA5B,CAAN;AAAqC,KAA7G,QAAmHC,EAAEiM,SAAF,CAAYlD,WAAW2B,IAAvB,KAA8B,CAAjJ,EAAoJ,IAAI9G,IAAE1D,EAAEmV,UAAF,CAAatV,CAAb,EAAgBmV,QAAhB,CAAyBzU,EAAEmT,GAAF,CAAMlS,EAAEwT,QAAF,CAAWlV,CAAX,CAAN,CAAzB,EAA+CyM,GAA/C,CAAmD1M,CAAnD,CAAN,CAA4D,OAAO,KAAKowB,YAAL,CAAkBnwB,CAAlB,EAAoB4D,CAApB,CAAP;AAA8B,GAA9U,CAA+U,KAAK4qB,qBAAL,GAA2B,UAASzuB,CAAT,EAAWC,CAAX,EAAa;AAAC,WAAO,KAAKsuB,SAAL,CAAevuB,CAAf,EAAiBC,CAAjB,EAAmB,KAAKyvB,SAAxB,CAAP;AAA0C,GAAnF,CAAoF,KAAKnB,SAAL,GAAe,UAASnsB,CAAT,EAAWnC,CAAX,EAAaS,CAAb,EAAe;AAAC,QAAIP,CAAJ,EAAMH,CAAN,CAAQ,IAAIW,IAAE0W,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBwC,WAAlB,CAA8BpwB,CAA9B,CAAN,CAAuCE,IAAEQ,EAAEmB,CAAJ,CAAM9B,IAAEW,EAAEiB,CAAJ,CAAM,IAAIxB,CAAJ,CAAMA,IAAEkZ,UAAUqC,aAAV,CAAwB,KAAK2T,QAAL,CAAc/V,KAAtC,EAA4C7Y,CAA5C,CAAF,CAAiD,IAAID,IAAE,IAAIuI,UAAJ,CAAe5G,CAAf,EAAiB,EAAjB,CAAN,CAA2B,OAAO,KAAKkuB,SAAL,CAAe7vB,CAAf,EAAiBN,CAAjB,EAAmBH,CAAnB,EAAqBI,CAArB,CAAP;AAA+B,GAA3M,CAA4M,KAAKiuB,MAAL,GAAY,UAAS1tB,CAAT,EAAWD,CAAX,EAAaV,CAAb,EAAe;AAAC,QAAIG,CAAJ,EAAMF,CAAN,CAAQ,IAAGswB,QAAQhZ,IAAR,CAAaiZ,OAAb,CAAqB9vB,CAArB,CAAH,EAA2B;AAAC,UAAID,IAAE,KAAKgwB,QAAL,CAAc/vB,CAAd,CAAN,CAAuBP,IAAEM,EAAEqB,CAAJ,CAAM7B,IAAEQ,EAAEmB,CAAJ;AAAM,KAA/D,MAAmE;AAAC,UAAG,qBAAkBlB,CAAlB,yCAAkBA,CAAlB,MAAqBA,EAAEoB,CAAvB,IAA0BpB,EAAEkB,CAA/B,EAAiC;AAACzB,YAAEO,EAAEoB,CAAJ,CAAM7B,IAAES,EAAEkB,CAAJ;AAAM,OAA9C,MAAkD;AAAC,cAAK,6BAAL;AAAmC;AAAC,SAAIxB,CAAJ,CAAM,IAAGJ,aAAasZ,SAAhB,EAA0B;AAAClZ,UAAEJ,CAAF;AAAI,KAA/B,MAAmC;AAAC,UAAGuwB,QAAQhZ,IAAR,CAAaiZ,OAAb,CAAqBxwB,CAArB,CAAH,EAA2B;AAACI,YAAEkZ,UAAUoC,UAAV,CAAqB,KAAK4T,QAAL,CAAc/V,KAAnC,EAAyCvZ,CAAzC,CAAF;AAA8C,OAA1E,MAA8E;AAAC,cAAK,kEAAL;AAAwE;AAAC,SAAIoC,IAAE4G,WAAWmnB,qBAAX,CAAiCxvB,CAAjC,CAAN,CAA0C,OAAO,KAAK2vB,SAAL,CAAeluB,CAAf,EAAiBjC,CAAjB,EAAmBF,CAAnB,EAAqBG,CAArB,CAAP;AAA+B,GAA1c,CAA2c,KAAKkwB,SAAL,GAAe,UAAS3vB,CAAT,EAAWV,CAAX,EAAayD,CAAb,EAAetB,CAAf,EAAiB;AAAC,QAAIjC,IAAE,KAAKmvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIqD,IAAE,KAAKwrB,QAAL,CAAcppB,CAApB,CAAsB,IAAGjG,EAAEiM,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+BlM,EAAEiM,SAAF,CAAY/L,CAAZ,KAAgB,CAAlD,EAAoD;AAAC,aAAO,KAAP;AAAa,SAAGuD,EAAEwI,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+BzI,EAAEwI,SAAF,CAAY/L,CAAZ,KAAgB,CAAlD,EAAoD;AAAC,aAAO,KAAP;AAAa,SAAIO,IAAEgD,EAAE4R,UAAF,CAAanV,CAAb,CAAN,CAAsB,IAAIC,IAAEO,EAAEwU,QAAF,CAAWzU,CAAX,EAAcgM,GAAd,CAAkBvM,CAAlB,CAAN,CAA2B,IAAIH,IAAEC,EAAEkV,QAAF,CAAWzU,CAAX,EAAcgM,GAAd,CAAkBvM,CAAlB,CAAN,CAA2B,IAAIwB,IAAEmC,EAAEqR,QAAF,CAAW/U,CAAX,EAAcyT,GAAd,CAAkBzR,EAAE+S,QAAF,CAAWnV,CAAX,CAAlB,CAAN,CAAuC,IAAI0B,IAAEC,EAAE2Y,IAAF,GAASrB,YAAT,GAAwBvM,GAAxB,CAA4BvM,CAA5B,CAAN,CAAqC,OAAOuB,EAAE+S,MAAF,CAASxU,CAAT,CAAP;AAAmB,GAA5X,CAA6X,KAAKmwB,YAAL,GAAkB,UAAShwB,CAAT,EAAWJ,CAAX,EAAa;AAAC,QAAIG,IAAEC,EAAEswB,iBAAF,EAAN,CAA4B,IAAIzwB,IAAED,EAAE0wB,iBAAF,EAAN,CAA4B,IAAItuB,IAAE,EAAN,CAASA,EAAED,IAAF,CAAO,CAAP,EAAUC,EAAED,IAAF,CAAOhC,EAAED,MAAT,EAAiBkC,IAAEA,EAAEX,MAAF,CAAStB,CAAT,CAAF,CAAciC,EAAED,IAAF,CAAO,CAAP,EAAUC,EAAED,IAAF,CAAOlC,EAAEC,MAAT,EAAiBkC,IAAEA,EAAEX,MAAF,CAASxB,CAAT,CAAF,CAAcmC,EAAEqZ,OAAF,CAAUrZ,EAAElC,MAAZ,EAAoBkC,EAAEqZ,OAAF,CAAU,EAAV,EAAc,OAAOrZ,CAAP;AAAS,GAA9N,CAA+N,KAAKquB,QAAL,GAAc,UAAShwB,CAAT,EAAW;AAAC,QAAI2B,CAAJ,CAAM,IAAG3B,EAAE,CAAF,KAAM,EAAT,EAAY;AAAC,YAAM,IAAInB,KAAJ,CAAU,mCAAV,CAAN;AAAqD,SAAE,CAAF,CAAI,IAAGmB,EAAE2B,CAAF,KAAM,CAAT,EAAW;AAAC,YAAM,IAAI9C,KAAJ,CAAU,iDAAV,CAAN;AAAmE,SAAIa,IAAEM,EAAEwB,KAAF,CAAQG,IAAE,CAAV,EAAYA,IAAE,CAAF,GAAI3B,EAAE2B,IAAE,CAAJ,CAAhB,CAAN,CAA8BA,KAAG,IAAE3B,EAAE2B,IAAE,CAAJ,CAAL,CAAY,IAAG3B,EAAE2B,CAAF,KAAM,CAAT,EAAW;AAAC,YAAM,IAAI9C,KAAJ,CAAU,kDAAV,CAAN;AAAoE,SAAIW,IAAEQ,EAAEwB,KAAF,CAAQG,IAAE,CAAV,EAAYA,IAAE,CAAF,GAAI3B,EAAE2B,IAAE,CAAJ,CAAhB,CAAN,CAA8BA,KAAG,IAAE3B,EAAE2B,IAAE,CAAJ,CAAL,CAAY,IAAIhC,IAAE4I,WAAWmnB,qBAAX,CAAiChwB,CAAjC,CAAN,CAA0C,IAAIH,IAAEgJ,WAAWmnB,qBAAX,CAAiClwB,CAAjC,CAAN,CAA0C,OAAM,EAAC6B,GAAE1B,CAAH,EAAKwB,GAAE5B,CAAP,EAAN;AAAgB,GAA7b,CAA8b,KAAK2wB,eAAL,GAAqB,UAASvuB,CAAT,EAAW;AAAC,QAAGA,EAAElC,MAAF,KAAW,EAAd,EAAiB;AAAC,YAAK,gCAAL;AAAsC,SAAIF,IAAEoC,EAAE,CAAF,IAAK,EAAX,CAAc,IAAGpC,IAAE,CAAF,IAAKA,IAAE,CAAV,EAAY;AAAC,YAAK,wBAAL;AAA8B,SAAIW,IAAE,KAAK2uB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIN,IAAE6I,WAAWmnB,qBAAX,CAAiC/tB,EAAEH,KAAF,CAAQ,CAAR,EAAU,EAAV,CAAjC,EAAgDyK,GAAhD,CAAoD/L,CAApD,CAAN,CAA6D,IAAIP,IAAE4I,WAAWmnB,qBAAX,CAAiC/tB,EAAEH,KAAF,CAAQ,EAAR,EAAW,EAAX,CAAjC,EAAiDyK,GAAjD,CAAqD/L,CAArD,CAAN,CAA8D,OAAM,EAACmB,GAAE3B,CAAH,EAAKyB,GAAExB,CAAP,EAASH,GAAED,CAAX,EAAN;AAAoB,GAAvT,CAAwT,KAAK4wB,kBAAL,GAAwB,UAASzwB,CAAT,EAAW;AAAC,QAAIM,IAAEgiB,OAAN,CAAc,IAAIrgB,IAAEiV,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAInwB,IAAED,EAAE4iB,UAAR,CAAmB,IAAG5iB,EAAEgjB,SAAF,CAAYtjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIF,CAAJ,EAAMG,CAAN,EAAQO,CAAR,CAAU,IAAG;AAACV,UAAES,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBC,IAAEM,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAF,CAAkB,IAAG;AAACQ,YAAED,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,EAAkBuC,MAAlB,CAAyB,CAAzB,CAAF;AAA8B,OAAlC,CAAkC,OAAM1C,CAAN,EAAQ,CAAE;AAAC,KAAvF,CAAuF,OAAMA,CAAN,EAAQ;AAAC,YAAK,0CAAL;AAAgD,UAAK2vB,SAAL,GAAevtB,EAAEnC,CAAF,CAAf,CAAoB,IAAG,KAAK0vB,SAAL,KAAiB3wB,SAApB,EAA8B;AAAC,YAAK,wBAAL;AAA8B,UAAKqwB,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBlvB,CAArB,EAAwB,KAAKivB,gBAAL,CAAsBxvB,CAAtB,EAAyB,KAAK8X,QAAL,GAAc,KAAd;AAAoB,GAA/e,CAAgf,KAAK4Y,kBAAL,GAAwB,UAAS3wB,CAAT,EAAW;AAAC,QAAIwB,IAAE8gB,OAAN,CAAc,IAAIxiB,IAAEoX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAIpwB,IAAEkB,EAAE0hB,UAAR,CAAmB,IAAG1hB,EAAE8hB,SAAF,CAAYtjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIH,CAAJ,EAAMU,CAAN,EAAQ0B,CAAR,EAAUhC,CAAV,CAAY,IAAG;AAACJ,UAAES,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBO,IAAED,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBiC,IAAE3B,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsB,IAAG;AAACC,YAAEK,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,EAAO,CAAP,CAAN,EAAgB,IAAhB,EAAsBuC,MAAtB,CAA6B,CAA7B,CAAF;AAAkC,OAAtC,CAAsC,OAAM/B,CAAN,EAAQ,CAAE;AAAC,KAAnH,CAAmH,OAAMA,CAAN,EAAQ;AAAC,YAAK,wCAAL;AAA8C,UAAKgvB,SAAL,GAAe1vB,EAAES,CAAF,CAAf,CAAoB,IAAG,KAAKivB,SAAL,KAAiB3wB,SAApB,EAA8B;AAAC,YAAK,wBAAL;AAA8B,UAAKqwB,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBzvB,CAArB,EAAwB,KAAKwvB,gBAAL,CAAsBxtB,CAAtB,EAAyB,KAAK8V,QAAL,GAAc,KAAd;AAAoB,GAA3gB,CAA4gB,KAAK6Y,kBAAL,GAAwB,UAAS5wB,CAAT,EAAW;AAAC,QAAIM,IAAEgiB,OAAN,CAAc,IAAIrgB,IAAEiV,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAInwB,IAAED,EAAE4iB,UAAR,CAAmB,IAAG5iB,EAAEgjB,SAAF,CAAYtjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIC,CAAJ,EAAMH,CAAN,EAAQU,CAAR,CAAU,IAAG;AAACP,UAAEM,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBF,IAAES,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBQ,IAAED,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,EAAgBuC,MAAhB,CAAuB,CAAvB,CAAF;AAA4B,KAAxE,CAAwE,OAAM1C,CAAN,EAAQ;AAAC,YAAK,iCAAL;AAAuC,UAAK2vB,SAAL,GAAevtB,EAAEnC,CAAF,CAAf,CAAoB,IAAG,KAAK0vB,SAAL,KAAiB,IAApB,EAAyB;AAAC,YAAK,wBAAL;AAA8B,UAAKN,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBlvB,CAArB;AAAwB,GAAra,CAAsa,KAAKqwB,iBAAL,GAAuB,UAAS5wB,CAAT,EAAWM,CAAX,EAAa;AAAC,QAAGA,MAAI,CAAP,EAAS;AAACA,UAAE,CAAF;AAAI,SAAI0B,IAAEqgB,OAAN,CAAc,IAAItiB,IAAEkX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAIlwB,IAAEyB,EAAEihB,UAAR,CAAmB,IAAGjhB,EAAEqhB,SAAF,CAAYrjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIH,CAAJ,EAAMQ,CAAN,CAAQ,IAAG;AAACR,UAAEU,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAGM,CAAH,EAAK,CAAL,EAAO,CAAP,CAAN,EAAgB,IAAhB,CAAF,CAAwBD,IAAEE,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAGM,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,EAAoBgC,MAApB,CAA2B,CAA3B,CAAF;AAAgC,KAA5D,CAA4D,OAAM1C,CAAN,EAAQ;AAAC,YAAK,4CAAL;AAAkD,UAAK2vB,SAAL,GAAexvB,EAAEF,CAAF,CAAf,CAAoB,IAAG,KAAK0vB,SAAL,KAAiB,IAApB,EAAyB;AAAC,YAAK,wBAAL;AAA8B,UAAKN,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBpvB,CAArB;AAAwB,GAAjb,CAAkb,IAAGrB,MAAIJ,SAAP,EAAiB;AAAC,QAAGI,EAAEma,KAAF,KAAUva,SAAb,EAAuB;AAAC,WAAK2wB,SAAL,GAAevwB,EAAEma,KAAjB;AAAuB;AAAC,OAAG,KAAKoW,SAAL,KAAiB3wB,SAApB,EAA8B;AAAC,SAAK2wB,SAAL,GAAe9vB,CAAf;AAAiB,QAAKwvB,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,IAAGvwB,MAAIJ,SAAP,EAAiB;AAAC,QAAGI,EAAE6xB,GAAF,KAAQjyB,SAAX,EAAqB;AAAC,WAAK4wB,gBAAL,CAAsBxwB,EAAE6xB,GAAxB;AAA6B,SAAG7xB,EAAE8xB,GAAF,KAAQlyB,SAAX,EAAqB;AAAC,WAAK6wB,eAAL,CAAqBzwB,EAAE8xB,GAAvB;AAA4B;AAAC;AAAC,CAAxqN,CAAyqN7Z,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBwC,WAAlB,GAA8B,UAAShwB,CAAT,EAAW;AAAC,MAAIT,IAAEyX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBsD,kBAAlB,CAAqC9wB,CAArC,CAAN,CAA8C,IAAId,IAAE,IAAIyJ,UAAJ,CAAepJ,EAAEkC,CAAjB,EAAmB,EAAnB,CAAN,CAA6B,IAAIhC,IAAE,IAAIkJ,UAAJ,CAAepJ,EAAEgC,CAAjB,EAAmB,EAAnB,CAAN,CAA6B,OAAM,EAACE,GAAEvC,CAAH,EAAKqC,GAAE9B,CAAP,EAAN;AAAgB,CAAlK,CAAmKuX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBsD,kBAAlB,GAAqC,UAAS9xB,CAAT,EAAW;AAAC,MAAIW,IAAEyiB,OAAN,CAAc,IAAIxiB,IAAED,EAAEijB,WAAR,CAAoB,IAAI9jB,IAAEa,EAAE8iB,IAAR,CAAa,IAAGzjB,EAAEqD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,mCAAL;AAAyC,OAAItD,IAAEa,EAAEZ,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGD,EAAEc,MAAF,IAAU,CAAb,EAAe;AAAC,UAAK,wDAAL;AAA8D,OAAIL,IAAET,EAAE,CAAF,CAAN,CAAW,IAAIG,IAAEH,EAAE,CAAF,CAAN,CAAW,IAAGC,EAAEqD,MAAF,CAAS7C,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,uDAAL;AAA6D,OAAGR,EAAEqD,MAAF,CAASnD,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,uDAAL;AAA6D,OAAIO,IAAEX,EAAEE,CAAF,EAAIQ,CAAJ,CAAN,CAAa,IAAID,IAAET,EAAEE,CAAF,EAAIE,CAAJ,CAAN,CAAa,OAAM,EAACuC,GAAEhC,CAAH,EAAK8B,GAAEhC,CAAP,EAAN;AAAgB,CAAte,CAAueyX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBuD,kBAAlB,GAAqC,UAAStxB,CAAT,EAAW;AAAC,MAAIP,IAAE8X,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBsD,kBAAlB,CAAqCrxB,CAArC,CAAN,CAA8C,IAAIF,IAAEL,EAAEuC,CAAR,CAAU,IAAIzB,IAAEd,EAAEqC,CAAR,CAAU,IAAGhC,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAf,IAAsB9C,EAAEM,MAAF,GAAS,EAAV,IAAe,CAAvC,EAAyC;AAACN,QAAEA,EAAE8C,MAAF,CAAS,CAAT,CAAF;AAAc,OAAGrC,EAAEqC,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAf,IAAsBrC,EAAEH,MAAF,GAAS,EAAV,IAAe,CAAvC,EAAyC;AAACG,QAAEA,EAAEqC,MAAF,CAAS,CAAT,CAAF;AAAc,OAAI9C,EAAEM,MAAF,GAAS,EAAV,IAAe,EAAlB,EAAqB;AAACN,QAAE,OAAKA,CAAP;AAAS,OAAIS,EAAEH,MAAF,GAAS,EAAV,IAAe,EAAlB,EAAqB;AAACG,QAAE,OAAKA,CAAP;AAAS,OAAGT,EAAEM,MAAF,GAAS,EAAT,IAAa,CAAhB,EAAkB;AAAC,UAAK,kCAAL;AAAwC,OAAGG,EAAEH,MAAF,GAAS,EAAT,IAAa,CAAhB,EAAkB;AAAC,UAAK,kCAAL;AAAwC,UAAON,IAAES,CAAT;AAAW,CAAla,CAAmagX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBwD,kBAAlB,GAAqC,UAAShxB,CAAT,EAAW;AAAC,MAAMA,EAAEH,MAAF,GAAS,CAAV,GAAa,CAAd,IAAkB,KAAG,CAArB,CAAD,IAA2B,CAA9B,EAAgC;AAAC,UAAK,kDAAL;AAAwD,OAAIJ,IAAEO,EAAEqC,MAAF,CAAS,CAAT,EAAWrC,EAAEH,MAAF,GAAS,CAApB,CAAN,CAA6B,IAAIN,IAAES,EAAEqC,MAAF,CAASrC,EAAEH,MAAF,GAAS,CAAlB,CAAN,CAA2B,OAAOmX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkByD,iBAAlB,CAAoCxxB,CAApC,EAAsCF,CAAtC,CAAP;AAAgD,CAAlP,CAAmPyX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkByD,iBAAlB,GAAoC,UAAS1xB,CAAT,EAAWS,CAAX,EAAa;AAAC,MAAId,IAAE,IAAIyJ,UAAJ,CAAepJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIE,IAAE,IAAIkJ,UAAJ,CAAe3I,CAAf,EAAiB,EAAjB,CAAN,CAA2B,OAAOgX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBqC,gBAAlB,CAAmC3wB,CAAnC,EAAqCO,CAArC,CAAP;AAA+C,CAAvJ,CAAwJuX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBqC,gBAAlB,GAAmC,UAAS7wB,CAAT,EAAWE,CAAX,EAAa;AAAC,MAAIO,IAAEuX,KAAKkF,IAAX,CAAgB,IAAI3c,IAAE,IAAIE,EAAEid,UAAN,CAAiB,EAACmE,QAAO7hB,CAAR,EAAjB,CAAN,CAAmC,IAAIgB,IAAE,IAAIP,EAAEid,UAAN,CAAiB,EAACmE,QAAO3hB,CAAR,EAAjB,CAAN,CAAmC,IAAIM,IAAE,IAAIC,EAAE8d,WAAN,CAAkB,EAACI,OAAM,CAACpe,CAAD,EAAGS,CAAH,CAAP,EAAlB,CAAN,CAAuC,OAAOR,EAAEwe,aAAF,EAAP;AAAyB,CAAvM,CAAwMhH,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAlB,GAA0B,UAASxwB,CAAT,EAAW;AAAC,MAAGA,MAAI,kBAAP,EAA0B;AAAC,WAAM,WAAN;AAAkB,OAAGA,MAAI,YAAP,EAAoB;AAAC,WAAM,WAAN;AAAkB,OAAGA,MAAI,YAAP,EAAoB;AAAC,WAAM,WAAN;AAAkB,OAAG,0CAA0CkF,OAA1C,CAAkDlF,CAAlD,MAAuD,CAAC,CAA3D,EAA6D;AAAC,WAAM,WAAN;AAAkB,OAAG,cAAckF,OAAd,CAAsBlF,CAAtB,MAA2B,CAAC,CAA/B,EAAiC;AAAC,WAAM,WAAN;AAAkB,OAAG,+BAA+BkF,OAA/B,CAAuClF,CAAvC,MAA4C,CAAC,CAAhD,EAAkD;AAAC,WAAM,WAAN;AAAkB,UAAO,IAAP;AAAY,CAAtX;AACt5Q,IAAG,OAAOgX,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UAwE3BA,IAxE2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKf,MAAZ,IAAoB,WAApB,IAAiC,CAACe,KAAKf,MAA1C,EAAiD;AAACe,OAAKf,MAAL,GAAY,EAAZ;AAAe,MAAKA,MAAL,CAAYiZ,aAAZ,GAA0B,IAAI,YAAU;AAAC,MAAI3vB,IAAE,EAAN,CAAS,IAAIE,IAAE,EAAN,CAAS,SAASO,CAAT,CAAWd,CAAX,EAAa;AAAC,WAAO,IAAIyJ,UAAJ,CAAezJ,CAAf,EAAiB,EAAjB,CAAP;AAA4B,QAAKiwB,SAAL,GAAe,UAAS3vB,CAAT,EAAW;AAAC,QAAIN,IAAEM,CAAN,CAAQ,IAAG,OAAOC,EAAEP,CAAF,CAAP,IAAa,WAAhB,EAA4B;AAACA,UAAEO,EAAED,CAAF,CAAF;AAAO,SAAG,OAAOD,EAAEL,CAAF,CAAP,IAAa,WAAhB,EAA4B;AAAC,aAAOK,EAAEL,CAAF,CAAP;AAAY,WAAK,iCAA+BA,CAApC;AAAsC,GAAtJ,CAAuJ,KAAKgyB,MAAL,GAAY,UAASlqB,CAAT,EAAWlH,CAAX,EAAaQ,CAAb,EAAexB,CAAf,EAAiBiD,CAAjB,EAAmBvC,CAAnB,EAAqBG,CAArB,EAAuBX,CAAvB,EAAyBe,CAAzB,EAA2B0D,CAA3B,EAA6BvE,CAA7B,EAA+BoE,CAA/B,EAAiC;AAAC/D,MAAEyH,CAAF,IAAK,EAAL,CAAQ,IAAIzF,IAAEvB,EAAEM,CAAF,CAAN,CAAW,IAAIyG,IAAE/G,EAAElB,CAAF,CAAN,CAAW,IAAImI,IAAEjH,EAAE+B,CAAF,CAAN,CAAW,IAAIV,IAAErB,EAAER,CAAF,CAAN,CAAW,IAAI6D,IAAErD,EAAEL,CAAF,CAAN,CAAW,IAAI8B,IAAE,IAAI2Y,SAAJ,CAAc7Y,CAAd,EAAgBwF,CAAhB,EAAkBE,CAAlB,CAAN,CAA2B,IAAI3F,IAAEG,EAAEuZ,cAAF,CAAiB,OAAKhc,CAAL,GAAOe,CAAxB,CAAN,CAAiCR,EAAEyH,CAAF,EAAK,MAAL,IAAaA,CAAb,CAAezH,EAAEyH,CAAF,EAAK,QAAL,IAAelH,CAAf,CAAiBP,EAAEyH,CAAF,EAAK,OAAL,IAAcvF,CAAd,CAAgBlC,EAAEyH,CAAF,EAAK,GAAL,IAAU1F,CAAV,CAAY/B,EAAEyH,CAAF,EAAK,GAAL,IAAU3F,CAAV,CAAY9B,EAAEyH,CAAF,EAAK,GAAL,IAAU3D,CAAV,CAAY9D,EAAEyH,CAAF,EAAK,KAAL,IAAY9H,CAAZ,CAAcK,EAAEyH,CAAF,EAAK,MAAL,IAAa1D,CAAb,CAAe,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEC,EAAE5D,MAAhB,EAAuB2D,GAAvB,EAA2B;AAAC/D,QAAEgE,EAAED,CAAF,CAAF,IAAQwD,CAAR;AAAU;AAAC,GAAjU;AAAkU,CAApiB,EAA1B,CAA+jBgQ,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kCAAjD,EAAoF,kCAApF,EAAuH,kCAAvH,EAA0J,kCAA1J,EAA6L,GAA7L,EAAiM,kCAAjM,EAAoO,kCAApO,EAAuQ,EAAvQ,EAA0Q,EAA1Q,EAA6Q,mDAA7Q,EAAkUla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,0CAAjD,EAA4F,GAA5F,EAAgG,GAAhG,EAAoG,4CAApG,EAAiJ,GAAjJ,EAAqJ,0CAArJ,EAAgM,0CAAhM,EAA2O,EAA3O,EAA8O,EAA9O,EAAiP,mDAAjP,EAAsSla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,0CAAjD,EAA4F,0CAA5F,EAAuI,0CAAvI,EAAkL,4CAAlL,EAA+N,GAA/N,EAAmO,0CAAnO,EAA8Q,0CAA9Q,EAAyT,EAAzT,EAA4T,EAA5T,EAA+T,mDAA/T,EAAoXla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kDAAjD,EAAoG,GAApG,EAAwG,GAAxG,EAA4G,kDAA5G,EAA+J,GAA/J,EAAmK,kDAAnK,EAAsN,kDAAtN,EAAyQ,EAAzQ,EAA6Qla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kDAAjD,EAAoG,kDAApG,EAAuJ,kDAAvJ,EAA0M,kDAA1M,EAA6P,GAA7P,EAAiQ,kDAAjQ,EAAoT,kDAApT,EAAuW,EAAvW,EAA2Wla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,0DAAjD,EAA4G,0DAA5G,EAAuK,0DAAvK,EAAkO,0DAAlO,EAA6R,GAA7R,EAAiS,0DAAjS,EAA4V,0DAA5V,EAAuZ,EAAvZ,EAA2Zla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kEAAjD,EAAoH,GAApH,EAAwH,GAAxH,EAA4H,kEAA5H,EAA+L,GAA/L,EAAmM,kEAAnM,EAAsQ,kEAAtQ,EAAyU,EAAzU,EAA6Ula,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kEAAjD,EAAoH,kEAApH,EAAuL,kEAAvL,EAA0P,kEAA1P,EAA6T,GAA7T,EAAiU,kEAAjU,EAAoY,kEAApY,EAAuc,CAAC,YAAD,EAAc,OAAd,EAAsB,YAAtB,CAAvc,EAA4ela,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kGAAjD,EAAoJ,kGAApJ,EAAuP,kGAAvP,EAA0V,kGAA1V,EAA6b,GAA7b,EAAic,kGAAjc,EAAoiB,kGAApiB,EAAuoB,CAAC,YAAD,EAAc,OAAd,CAAvoB,EAA+pBla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,qIAAjD,EAAuL,qIAAvL,EAA6T,qIAA7T,EAAmc,qIAAnc,EAAykB,GAAzkB,EAA6kB,oIAA7kB,EAAktB,sIAAltB,EAAy1B,CAAC,YAAD,EAAc,OAAd,CAAz1B;AACnnI,IAAInE,UAAQ,YAAU;AAAC,MAAI7tB,IAAE,SAAFA,CAAE,CAASmB,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOvB,EAAEE,SAASkxB,GAAX,EAAe9wB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAI9B,IAAE,SAAFA,CAAE,CAASa,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOvB,EAAEE,SAASmxB,SAAX,EAAqB/wB,CAArB,EAAuBoB,CAAvB,EAAyBH,CAAzB,CAAP;AAAmC,GAAzD,CAA0D,IAAItB,IAAE,SAAFA,CAAE,CAASK,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOvB,EAAEE,SAASoxB,GAAX,EAAehxB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAIvB,IAAE,SAAFA,CAAE,CAASwB,CAAT,EAAW+B,CAAX,EAAaG,CAAb,EAAenC,CAAf,EAAiB;AAAC,QAAIG,IAAExB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBmB,CAAvB,CAAN,CAAgC,IAAID,IAAEpD,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBsB,CAAvB,CAAN,CAAgC,IAAIpD,IAAEJ,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBb,CAAvB,CAAN,CAAgC,IAAID,IAAE,EAAN,CAASA,EAAEiwB,GAAF,GAAMjuB,CAAN,CAAQhC,EAAEkwB,EAAF,GAAKlxB,CAAL,CAAOgB,EAAEmwB,UAAF,GAAa/vB,CAAb,CAAe,IAAI+B,IAAEjC,EAAEqtB,OAAF,CAAUvtB,CAAV,EAAYgC,CAAZ,EAAc,EAACkuB,IAAGlxB,CAAJ,EAAd,CAAN,CAA4B,OAAOJ,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BqC,CAA3B,CAAP;AAAqC,GAAhO,CAAiO,IAAI1D,IAAE,SAAFA,CAAE,CAASO,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOxC,EAAEmB,SAASkxB,GAAX,EAAe9wB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAIhB,IAAE,SAAFA,CAAE,CAASD,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOxC,EAAEmB,SAASmxB,SAAX,EAAqB/wB,CAArB,EAAuBoB,CAAvB,EAAyBH,CAAzB,CAAP;AAAmC,GAAzD,CAA0D,IAAItC,IAAE,SAAFA,CAAE,CAASqB,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOxC,EAAEmB,SAASoxB,GAAX,EAAehxB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAIxC,IAAE,SAAFA,CAAE,CAASuC,CAAT,EAAW4F,CAAX,EAAazD,CAAb,EAAelC,CAAf,EAAiB;AAAC,QAAIC,IAAEtB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuB8E,CAAvB,CAAN,CAAgC,IAAI3D,IAAErD,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBqB,CAAvB,CAAN,CAAgC,IAAInD,IAAEJ,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBb,CAAvB,CAAN,CAAgC,IAAI+B,IAAEhC,EAAE+W,OAAF,CAAU7W,CAAV,EAAY+B,CAAZ,EAAc,EAACiuB,IAAGlxB,CAAJ,EAAd,CAAN,CAA4B,IAAIoB,IAAExB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBkB,EAAEvC,QAAF,EAAvB,CAAN,CAA2C,IAAI2C,IAAExD,SAAS+B,GAAT,CAAa+C,MAAb,CAAoB5D,SAApB,CAA8BM,CAA9B,CAAN,CAAuC,OAAOgC,CAAP;AAAS,GAA/O,CAAgP,IAAI7D,IAAE,EAAC,eAAc,EAAC6xB,MAAKvyB,CAAN,EAAQwyB,OAAM5xB,CAAd,EAAgB4vB,QAAO,EAAvB,EAA0BiC,OAAM,EAAhC,EAAf,EAAmD,eAAc,EAACF,MAAKvyB,CAAN,EAAQwyB,OAAM5xB,CAAd,EAAgB4vB,QAAO,EAAvB,EAA0BiC,OAAM,EAAhC,EAAjE,EAAqG,eAAc,EAACF,MAAKvyB,CAAN,EAAQwyB,OAAM5xB,CAAd,EAAgB4vB,QAAO,EAAvB,EAA0BiC,OAAM,EAAhC,EAAnH,EAAuJ,gBAAe,EAACF,MAAKjyB,CAAN,EAAQkyB,OAAMpxB,CAAd,EAAgBovB,QAAO,EAAvB,EAA0BiC,OAAM,CAAhC,EAAtK,EAAyM,WAAU,EAACF,MAAKzxB,CAAN,EAAQ0xB,OAAM1yB,CAAd,EAAgB0wB,QAAO,CAAvB,EAAyBiC,OAAM,CAA/B,EAAnN,EAAN,CAA4P,IAAIlyB,IAAE,SAAFA,CAAE,CAASY,CAAT,EAAW;AAAC,WAAOT,EAAES,CAAF,EAAK,MAAL,CAAP;AAAoB,GAAtC,CAAuC,IAAI0B,IAAE,SAAFA,CAAE,CAAS1B,CAAT,EAAW;AAAC,QAAIoB,IAAExB,SAASC,GAAT,CAAac,SAAb,CAAuBa,MAAvB,CAA8BxB,CAA9B,CAAN,CAAuC,IAAIiB,IAAErB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BM,CAA3B,CAAN,CAAoC,OAAOH,CAAP;AAAS,GAAtG,CAAuG,IAAIlB,IAAE,SAAFA,CAAE,CAASoD,CAAT,EAAW;AAAC,QAAIH,IAAE,EAAN,CAAS,IAAI/B,IAAEkC,EAAEuY,KAAF,CAAQ,IAAID,MAAJ,CAAW,kCAAX,EAA8C,GAA9C,CAAR,CAAN,CAAkE,IAAGxa,CAAH,EAAK;AAAC+B,QAAEuuB,MAAF,GAAStwB,EAAE,CAAF,CAAT,CAAc+B,EAAEwuB,MAAF,GAASvwB,EAAE,CAAF,CAAT;AAAc,SAAIjB,IAAEmD,EAAEuY,KAAF,CAAQ,IAAID,MAAJ,CAAW,sCAAX,CAAR,CAAN,CAAkE,IAAGzb,CAAH,EAAK;AAACgD,QAAEiV,IAAF,GAAOjY,EAAE,CAAF,CAAP;AAAY,SAAIoD,IAAE,CAAC,CAAP,CAAS,IAAIH,IAAE,CAAN,CAAQ,IAAGE,EAAE0B,OAAF,CAAU,UAAV,KAAuB,CAAC,CAA3B,EAA6B;AAACzB,UAAED,EAAE0B,OAAF,CAAU,UAAV,CAAF,CAAwB5B,IAAE,CAAF;AAAI,SAAGE,EAAE0B,OAAF,CAAU,MAAV,KAAmB,CAAC,CAAvB,EAAyB;AAACzB,UAAED,EAAE0B,OAAF,CAAU,MAAV,CAAF,CAAoB5B,IAAE,CAAF;AAAI,SAAIjC,IAAEmC,EAAE0B,OAAF,CAAU,UAAV,CAAN,CAA4B,IAAGzB,KAAG,CAAC,CAAJ,IAAOpC,KAAG,CAAC,CAAd,EAAgB;AAAC,UAAII,IAAE+B,EAAE2E,SAAF,CAAY1E,IAAEH,IAAE,CAAhB,EAAkBjC,IAAEiC,CAApB,CAAN,CAA6B7B,IAAEA,EAAEua,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB3Y,EAAEyuB,IAAF,GAAOrwB,CAAP;AAAS,YAAO4B,CAAP;AAAS,GAAnc,CAAoc,IAAI1D,IAAE,SAAFA,CAAE,CAAS2B,CAAT,EAAW2F,CAAX,EAAa5G,CAAb,EAAe;AAAC,QAAImD,IAAEnD,EAAE8H,SAAF,CAAY,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAI9G,IAAEpB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBqB,CAAvB,CAAN,CAAgC,IAAI/B,IAAExB,SAAS+B,GAAT,CAAaU,IAAb,CAAkBP,KAAlB,CAAwB8E,CAAxB,CAAN,CAAiC,IAAIxD,IAAE7D,EAAE0B,CAAF,EAAK,QAAL,IAAe1B,EAAE0B,CAAF,EAAK,OAAL,CAArB,CAAmC,IAAIgC,IAAE,EAAN,CAAS,IAAID,IAAE,IAAN,CAAW,SAAO;AAAC,UAAI9B,IAAEtB,SAASuE,IAAT,CAAcqlB,GAAd,CAAkBhpB,MAAlB,EAAN,CAAiC,IAAGwC,KAAG,IAAN,EAAW;AAAC9B,UAAE2C,MAAF,CAASb,CAAT;AAAY,SAAEa,MAAF,CAASzC,CAAT,EAAYF,EAAE2C,MAAF,CAAS7C,CAAT,EAAYgC,IAAE9B,EAAE4C,QAAF,EAAF,CAAeb,IAAEA,IAAErD,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BkC,CAA3B,CAAJ,CAAkC,IAAGC,EAAEzD,MAAF,IAAU4D,IAAE,CAAf,EAAiB;AAAC;AAAM;AAAC,SAAIsD,IAAE,EAAN,CAASA,EAAEgrB,MAAF,GAASzuB,EAAEjB,MAAF,CAAS,CAAT,EAAWzC,EAAE0B,CAAF,EAAK,QAAL,IAAe,CAA1B,CAAT,CAAsCyF,EAAEirB,KAAF,GAAQ1uB,EAAEjB,MAAF,CAASzC,EAAE0B,CAAF,EAAK,QAAL,IAAe,CAAxB,EAA0B1B,EAAE0B,CAAF,EAAK,OAAL,IAAc,CAAxC,CAAR,CAAmD,OAAOyF,CAAP;AAAS,GAApb,CAAqb,IAAIxH,IAAE,SAAFA,CAAE,CAASc,CAAT,EAAWmD,CAAX,EAAa/B,CAAb,EAAe4B,CAAf,EAAiB;AAAC,QAAI9B,IAAEtB,SAAS+B,GAAT,CAAa+C,MAAb,CAAoB5C,KAApB,CAA0B9B,CAA1B,CAAN,CAAmC,IAAIiB,IAAErB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BI,CAA3B,CAAN,CAAoC,IAAIkC,IAAE7D,EAAE4D,CAAF,EAAK,MAAL,CAAN,CAAmB,IAAInC,IAAEoC,EAAEnC,CAAF,EAAIG,CAAJ,EAAM4B,CAAN,CAAN,CAAe,OAAOhC,CAAP;AAAS,GAA1I,CAA2I,IAAItC,IAAE,SAAFA,CAAE,CAASsB,CAAT,EAAWkB,CAAX,EAAaD,CAAb,EAAemC,CAAf,EAAiB;AAAC,QAAIhC,IAAE7B,EAAE2B,CAAF,EAAK,OAAL,CAAN,CAAoB,IAAIF,IAAEI,EAAEpB,CAAF,EAAIiB,CAAJ,EAAMmC,CAAN,CAAN,CAAe,OAAOpC,CAAP;AAAS,GAApE,CAAqE,OAAM,EAAC4wB,SAAQ,OAAT,EAAiBC,eAAc,uBAAS7xB,CAAT,EAAW;AAAC,aAAOD,EAAEC,CAAF,CAAP;AAAY,KAAvD,EAAwD8xB,sCAAqC,8CAAS7wB,CAAT,EAAWjB,CAAX,EAAaoB,CAAb,EAAe;AAAC,aAAO9B,EAAE2B,CAAF,EAAIjB,CAAJ,EAAMoB,CAAN,CAAP;AAAgB,KAA7H,EAA8H2wB,eAAc,uBAAS/xB,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAeC,CAAf,EAAiB;AAAC,aAAOhC,EAAEc,CAAF,EAAIoB,CAAJ,EAAMH,CAAN,EAAQC,CAAR,CAAP;AAAkB,KAAhL,EAAiL8wB,oBAAmB,4BAASprB,CAAT,EAAW3D,CAAX,EAAa;AAAC,UAAIhC,IAAElB,EAAE6G,CAAF,CAAN,CAAW,IAAI5F,IAAEC,EAAEgX,IAAR,CAAa,IAAI7W,IAAEH,EAAEswB,MAAR,CAAe,IAAIvxB,IAAEiB,EAAEuwB,MAAR,CAAe,IAAItwB,IAAED,EAAEwwB,IAAR,CAAa,IAAIzuB,IAAE1D,EAAE8B,CAAF,EAAI6B,CAAJ,EAAMjD,CAAN,CAAN,CAAe,IAAImD,IAAEH,EAAE0uB,MAAR,CAAe,IAAItuB,IAAElE,EAAEgC,CAAF,EAAIE,CAAJ,EAAM+B,CAAN,EAAQnD,CAAR,CAAN,CAAiB,OAAOoD,CAAP;AAAS,KAA7U,EAA8U6uB,mCAAkC,2CAAShvB,CAAT,EAAW/B,CAAX,EAAayF,CAAb,EAAe3F,CAAf,EAAiBI,CAAjB,EAAmB;AAAC,UAAIpB,IAAE,EAAN,CAAS,IAAG,OAAOgB,CAAP,IAAU,WAAV,IAAuBA,KAAG,IAA7B,EAAkC;AAACA,YAAE,aAAF;AAAgB,WAAG,OAAOzB,EAAEyB,CAAF,CAAP,IAAa,WAAhB,EAA4B;AAAC,cAAK,oCAAkCA,CAAvC;AAAyC,WAAG,OAAOI,CAAP,IAAU,WAAV,IAAuBA,KAAG,IAA7B,EAAkC;AAAC,YAAI+B,IAAE5D,EAAEyB,CAAF,EAAK,OAAL,CAAN,CAAoB,IAAIoC,IAAE1B,EAAEyB,CAAF,CAAN,CAAW/B,IAAEgC,EAAE8uB,WAAF,EAAF;AAAkB,WAAIxrB,IAAEpH,EAAE0B,CAAF,EAAI2F,CAAJ,EAAMvF,CAAN,CAAN,CAAe,IAAIwF,IAAEF,EAAEgrB,MAAR,CAAe,IAAI1uB,IAAEtE,EAAEwC,CAAF,EAAIF,CAAJ,EAAM4F,CAAN,EAAQxF,CAAR,CAAN,CAAiB,IAAIH,IAAE+B,EAAE2Y,OAAF,CAAU,UAAV,EAAqB,QAArB,CAAN,CAAqC,IAAI3b,IAAE,gBAAciD,CAAd,GAAgB,uBAAtB,CAA8CjD,KAAG,4BAAH,CAAgCA,KAAG,eAAagB,CAAb,GAAe,GAAf,GAAmBI,CAAnB,GAAqB,MAAxB,CAA+BpB,KAAG,MAAH,CAAUA,KAAGiB,CAAH,CAAKjB,KAAG,kBAAgBiD,CAAhB,GAAkB,uBAArB,CAA6C,OAAOjD,CAAP;AAAS,KAAh2B,EAAi2BmyB,0BAAyB,kCAASvrB,CAAT,EAAW;AAAC,UAAIE,IAAEib,OAAN,CAAc,IAAIrb,IAAEI,EAAEyb,WAAR,CAAoB,IAAIvf,IAAE8D,EAAEsb,IAAR,CAAa,IAAIphB,IAAE,EAAN,CAAS,IAAII,IAAEsF,EAAEE,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGxF,EAAE5B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,+CAA6C4B,EAAE5B,MAApD;AAA2D,SAAE2xB,UAAF,GAAanuB,EAAE4D,CAAF,EAAIxF,EAAE,CAAF,CAAJ,CAAb,CAAuB,IAAIuF,IAAED,EAAEE,CAAF,EAAIxF,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGuF,EAAEnH,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,iDAA+CmH,EAAEnH,MAAtD;AAA6D,WAAGwD,EAAE4D,CAAF,EAAID,EAAE,CAAF,CAAJ,KAAW,oBAAd,EAAmC;AAAC,cAAK,+BAAL;AAAqC,WAAI3G,IAAE0G,EAAEE,CAAF,EAAID,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGA,EAAEnH,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,mDAAiDQ,EAAER,MAAxD;AAA+D,WAAIyB,IAAEyF,EAAEE,CAAF,EAAI5G,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGiB,EAAEzB,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,qDAAmDyB,EAAEzB,MAA1D;AAAiE,WAAGwD,EAAE4D,CAAF,EAAI3F,EAAE,CAAF,CAAJ,KAAW,kBAAd,EAAiC;AAAC,cAAK,8BAAL;AAAoC,SAAEmxB,mBAAF,GAAsB,WAAtB,CAAkCpxB,EAAEqxB,kBAAF,GAAqBrvB,EAAE4D,CAAF,EAAI3F,EAAE,CAAF,CAAJ,CAArB,CAA+B,IAAIC,IAAEwF,EAAEE,CAAF,EAAI5G,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGkB,EAAE1B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,qDAAmD0B,EAAE1B,MAA1D;AAAiE,WAAGwD,EAAE4D,CAAF,EAAI1F,EAAE,CAAF,CAAJ,KAAW,oBAAd,EAAmC;AAAC,cAAK,gCAAL;AAAsC,WAAI+B,IAAEyD,EAAEE,CAAF,EAAI1F,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAG+B,EAAEzD,MAAF,GAAS,CAAZ,EAAc;AAAC,cAAK,sDAAoDyD,EAAEzD,MAA3D;AAAkE,SAAE8yB,UAAF,GAAatvB,EAAE4D,CAAF,EAAI3D,EAAE,CAAF,CAAJ,CAAb,CAAuB,IAAIG,IAAEJ,EAAE4D,CAAF,EAAI3D,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAG;AAACjC,UAAEuxB,UAAF,GAAaxwB,SAASqB,CAAT,EAAW,EAAX,CAAb;AAA4B,OAAhC,CAAgC,OAAMD,CAAN,EAAQ;AAAC,cAAK,kCAAgCC,CAArC;AAAuC,cAAOpC,CAAP;AAAS,KAAt6D,EAAu6DwxB,0BAAyB,kCAASpvB,CAAT,EAAWpD,CAAX,EAAa;AAAC,UAAIgB,IAAEpB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBsB,EAAEkvB,UAAzB,CAAN,CAA2C,IAAIrxB,IAAEmC,EAAEmvB,UAAR,CAAmB,IAAIrxB,IAAEtB,SAAS6yB,MAAT,CAAgBzyB,CAAhB,EAAkBgB,CAAlB,EAAoB,EAAC0xB,SAAQ,MAAI,EAAb,EAAgBC,YAAW1xB,CAA3B,EAApB,CAAN,CAAyD,IAAIG,IAAExB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BI,CAA3B,CAAN,CAAoC,OAAOE,CAAP;AAAS,KAAlnE,EAAmnEwxB,wCAAuC,gDAAS3vB,CAAT,EAAW2D,CAAX,EAAa;AAAC,UAAIxF,IAAEwjB,SAAS3hB,CAAT,EAAW,uBAAX,CAAN,CAA0C,IAAIjD,IAAE,KAAKmyB,wBAAL,CAA8B/wB,CAA9B,CAAN,CAAuC,IAAIgC,IAAEspB,QAAQ8F,wBAAR,CAAiCxyB,CAAjC,EAAmC4G,CAAnC,CAAN,CAA4C,IAAIzD,IAAE,EAAN,CAASA,EAAEguB,UAAF,GAAavxB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuB9B,EAAEmxB,UAAzB,CAAb,CAAkD,IAAInwB,IAAEpB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBsB,CAAvB,CAAN,CAAgC,IAAIlC,IAAEtB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuB9B,EAAEqyB,kBAAzB,CAAN,CAAmD,IAAIrvB,IAAEpD,SAASmxB,SAAT,CAAmBxC,OAAnB,CAA2BprB,CAA3B,EAA6BnC,CAA7B,EAA+B,EAACkwB,IAAGhwB,CAAJ,EAA/B,CAAN,CAA6C,IAAID,IAAErB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BkC,CAA3B,CAAN,CAAoC,OAAO/B,CAAP;AAAS,KAA7gF,EAA8gF4xB,6BAA4B,qCAAS3xB,CAAT,EAAWD,CAAX,EAAa;AAAC,UAAIjB,IAAE,KAAK4yB,sCAAL,CAA4C1xB,CAA5C,EAA8CD,CAA9C,CAAN,CAAuD,IAAIG,IAAE,KAAK0xB,8BAAL,CAAoC9yB,CAApC,CAAN,CAA6C,OAAOoB,CAAP;AAAS,KAArqF,EAAsqF2xB,2BAA0B,mCAAS7xB,CAAT,EAAW;AAAC,UAAIiC,IAAE4e,OAAN,CAAc,IAAI3e,IAAED,EAAEof,WAAR,CAAoB,IAAIvhB,IAAEmC,EAAEif,IAAR,CAAa,IAAInhB,IAAE,EAAN,CAASA,EAAE+xB,QAAF,GAAW,IAAX,CAAgB,IAAG9xB,EAAEc,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,cAAK,6CAAL;AAAmD,WAAIZ,IAAEgC,EAAElC,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGE,EAAE5B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,6CAAL;AAAmD,WAAG0B,EAAEc,MAAF,CAASZ,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,uCAAL;AAA6C,WAAIpB,IAAEoD,EAAElC,CAAF,EAAIE,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGpB,EAAER,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,uCAAL;AAA6C,WAAG0B,EAAEc,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,uCAAL;AAA6C,SAAEizB,MAAF,GAASjyB,EAAEE,CAAF,EAAIlB,EAAE,CAAF,CAAJ,CAAT,CAAmB,IAAGkB,EAAEc,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAACiB,UAAE+xB,QAAF,GAAWhyB,EAAEE,CAAF,EAAIlB,EAAE,CAAF,CAAJ,CAAX;AAAqB,WAAGkB,EAAEc,MAAF,CAASZ,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,uCAAL;AAA6C,SAAE8xB,MAAF,GAAS/vB,EAAEgf,OAAF,CAAUjhB,CAAV,EAAYE,EAAE,CAAF,CAAZ,CAAT,CAA2B,OAAOH,CAAP;AAAS,KAA3zG,EAA4zGkyB,gCAA+B,wCAASlyB,CAAT,EAAW;AAAC,UAAIjB,IAAE4kB,SAAS3jB,CAAT,EAAW,aAAX,CAAN,CAAgC,IAAIG,IAAE,KAAK0xB,8BAAL,CAAoC9yB,CAApC,CAAN,CAA6C,OAAOoB,CAAP;AAAS,KAA77G,EAA87G0xB,gCAA+B,wCAAS9yB,CAAT,EAAW;AAAC,UAAIiB,IAAE,KAAK8xB,yBAAL,CAA+B/yB,CAA/B,CAAN,CAAwC,IAAIoB,CAAJ,CAAM,IAAGH,EAAEgyB,MAAF,IAAU,oBAAb,EAAkC;AAAC7xB,YAAE,IAAI+V,MAAJ,EAAF;AAAe,OAAlD,MAAsD;AAAC,YAAGlW,EAAEgyB,MAAF,IAAU,gBAAb,EAA8B;AAAC7xB,cAAE,IAAIuV,KAAKf,MAAL,CAAY6X,GAAhB,EAAF;AAAwB,SAAvD,MAA2D;AAAC,cAAGxsB,EAAEgyB,MAAF,IAAU,gBAAb,EAA8B;AAAC7xB,gBAAE,IAAIuV,KAAKf,MAAL,CAAYuX,KAAhB,EAAF;AAA0B,WAAzD,MAA6D;AAAC,kBAAK,mCAAL;AAAyC;AAAC;AAAC,SAAEiD,kBAAF,CAAqBpwB,CAArB,EAAwB,OAAOoB,CAAP;AAAS,KAApxH,EAAqxHgyB,2BAA0B,mCAASnyB,CAAT,EAAW;AAAC,UAAIjB,CAAJ,CAAM,IAAIoB,IAAE2gB,QAAQY,UAAR,CAAmB1hB,CAAnB,EAAqB,CAArB,EAAuB,CAAC,CAAD,EAAG,CAAH,CAAvB,EAA6B,IAA7B,CAAN,CAAyC,IAAGG,MAAI,oBAAP,EAA4B;AAACpB,YAAE,IAAImX,MAAJ,EAAF;AAAe,OAA5C,MAAgD;AAAC,YAAG/V,MAAI,gBAAP,EAAwB;AAACpB,cAAE,IAAI2W,KAAKf,MAAL,CAAY6X,GAAhB,EAAF;AAAwB,SAAjD,MAAqD;AAAC,cAAGrsB,MAAI,gBAAP,EAAwB;AAACpB,gBAAE,IAAI2W,KAAKf,MAAL,CAAYuX,KAAhB,EAAF;AAA0B,WAAnD,MAAuD;AAAC,kBAAK,mCAAL;AAAyC;AAAC;AAAC,SAAEkD,kBAAF,CAAqBpvB,CAArB,EAAwB,OAAOjB,CAAP;AAAS,KAArlI,EAAslIqzB,yBAAwB,iCAASjyB,CAAT,EAAW;AAAC,UAAIgC,IAAE2e,OAAN,CAAc,IAAI/gB,IAAEoC,EAAEmf,WAAR,CAAoB,IAAIrhB,IAAEkC,EAAEgf,IAAR,CAAa,IAAIpiB,IAAE,EAAN,CAAS,IAAGoB,EAAEY,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,cAAK,6BAAL;AAAmC,WAAIf,IAAED,EAAEI,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGH,EAAEzB,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,6BAAL;AAAmC,WAAG4B,EAAEY,MAAF,CAASf,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,6BAAL;AAAmC,SAAElB,CAAF,GAAImB,EAAEE,CAAF,EAAIH,EAAE,CAAF,CAAJ,CAAJ,CAAc,IAAGG,EAAEY,MAAF,CAASf,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,6BAAL;AAAmC,SAAE9B,CAAF,GAAI+B,EAAEE,CAAF,EAAIH,EAAE,CAAF,CAAJ,CAAJ,CAAc,OAAOjB,CAAP;AAAS,KAA98I,EAA+8IszB,qBAAoB,6BAAStyB,CAAT,EAAW;AAAC,UAAImC,IAAE4e,OAAN,CAAc,IAAI3e,IAAED,EAAEof,WAAR,CAAoB,IAAIrhB,IAAEiC,EAAEif,IAAR,CAAa,IAAInhB,IAAE,EAAN,CAASA,EAAE+xB,QAAF,GAAW,IAAX,CAAgB,IAAI5xB,IAAEgC,EAAEpC,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGI,EAAE5B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,8CAA4C4B,EAAE5B,MAAnD;AAA0D,WAAIwD,IAAE5B,EAAE,CAAF,CAAN,CAAW,IAAGJ,EAAEgB,MAAF,CAASgB,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,cAAK,sCAAL;AAA4C,WAAIhD,IAAEoD,EAAEpC,CAAF,EAAIgC,CAAJ,CAAN,CAAa,IAAGhD,EAAER,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,sCAAL;AAA4C,WAAGwB,EAAEgB,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,sCAAL;AAA4C,SAAEizB,MAAF,GAAS/xB,EAAEF,CAAF,EAAIhB,EAAE,CAAF,CAAJ,CAAT,CAAmB,IAAGgB,EAAEgB,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAACiB,UAAE+xB,QAAF,GAAW9xB,EAAEF,CAAF,EAAIhB,EAAE,CAAF,CAAJ,CAAX;AAAqB,OAAhD,MAAoD;AAAC,YAAGgB,EAAEgB,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAACiB,YAAE+xB,QAAF,GAAW,EAAX,CAAc/xB,EAAE+xB,QAAF,CAAWhzB,CAAX,GAAamD,EAAEwf,UAAF,CAAa3hB,CAAb,EAAehB,EAAE,CAAF,CAAf,EAAoB,CAAC,CAAD,CAApB,EAAwB,IAAxB,CAAb,CAA2CiB,EAAE+xB,QAAF,CAAW/xB,CAAX,GAAakC,EAAEwf,UAAF,CAAa3hB,CAAb,EAAehB,EAAE,CAAF,CAAf,EAAoB,CAAC,CAAD,CAApB,EAAwB,IAAxB,CAAb,CAA2CiB,EAAE+xB,QAAF,CAAWv0B,CAAX,GAAa0E,EAAEwf,UAAF,CAAa3hB,CAAb,EAAehB,EAAE,CAAF,CAAf,EAAoB,CAAC,CAAD,CAApB,EAAwB,IAAxB,CAAb;AAA2C;AAAC,WAAGgB,EAAEgB,MAAF,CAASZ,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,sCAAL;AAA4C,SAAE6vB,GAAF,GAAM/vB,EAAEF,CAAF,EAAII,EAAE,CAAF,CAAJ,EAAUY,MAAV,CAAiB,CAAjB,CAAN,CAA0B,OAAOf,CAAP;AAAS,KAA1sK,EAAN;AAAmtK,CAAt8O,EAAZ,CAAq9OyrB,QAAQC,MAAR,GAAe,UAASltB,CAAT,EAAWC,CAAX,EAAaK,CAAb,EAAe;AAAC,MAAIyF,IAAEuc,OAAN;AAAA,MAAchc,IAAEP,EAAE+c,WAAlB;AAAA,MAA8Bpf,IAAEqC,EAAE4c,IAAlC;AAAA,MAAuCvjB,IAAE2G,EAAEmd,UAA3C;AAAA,MAAsDvjB,IAAEuX,KAAKf,MAA7D;AAAA,MAAoErW,IAAEH,EAAE+tB,KAAxE;AAAA,MAA8EnmB,IAAE5H,EAAEquB,GAAlF;AAAA,MAAsFzqB,IAAEmU,MAAxF;AAAA,MAA+FlR,IAAE2e,QAAjG;AAAA,MAA0Grf,IAAEmnB,OAA5G,CAAoH,IAAG,OAAO1pB,CAAP,IAAU,WAAV,IAAuBvD,aAAauD,CAAvC,EAAyC;AAAC,WAAOvD,CAAP;AAAS,OAAG,OAAOF,CAAP,IAAU,WAAV,IAAuBE,aAAaF,CAAvC,EAAyC;AAAC,WAAOE,CAAP;AAAS,OAAG,OAAOuH,CAAP,IAAU,WAAV,IAAuBvH,aAAauH,CAAvC,EAAyC;AAAC,WAAOvH,CAAP;AAAS,OAAGA,EAAEoZ,KAAF,KAAUva,SAAV,IAAqBmB,EAAE8zB,EAAF,KAAOj1B,SAA5B,IAAuCmB,EAAEZ,CAAF,KAAMP,SAAhD,EAA0D;AAAC,WAAO,IAAIiB,CAAJ,CAAM,EAACixB,KAAI/wB,EAAE8zB,EAAP,EAAU1a,OAAMpZ,EAAEoZ,KAAlB,EAAN,CAAP;AAAuC,OAAGpZ,EAAEoZ,KAAF,KAAUva,SAAV,IAAqBmB,EAAEZ,CAAF,KAAMP,SAA9B,EAAwC;AAAC,WAAO,IAAIiB,CAAJ,CAAM,EAACgxB,KAAI9wB,EAAEZ,CAAP,EAASga,OAAMpZ,EAAEoZ,KAAjB,EAAN,CAAP;AAAsC,OAAGpZ,EAAE+zB,GAAF,KAAQl1B,SAAR,IAAmBmB,EAAEM,CAAF,KAAMzB,SAAzB,IAAoCmB,EAAEN,CAAF,KAAMb,SAA1C,IAAqDmB,EAAEZ,CAAF,KAAMP,SAA9D,EAAwE;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEuR,SAAF,CAAYrY,EAAEM,CAAd,EAAgBN,EAAEN,CAAlB,EAAqB,OAAOoH,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQl1B,SAAR,IAAmBmB,EAAEM,CAAF,KAAMzB,SAAzB,IAAoCmB,EAAEN,CAAF,KAAMb,SAA1C,IAAqDmB,EAAEZ,CAAF,KAAMP,SAA3D,IAAsEmB,EAAEO,CAAF,KAAM1B,SAA5E,IAAuFmB,EAAEwB,CAAF,KAAM3C,SAA7F,IAAwGmB,EAAEg0B,EAAF,KAAOn1B,SAA/G,IAA0HmB,EAAEi0B,EAAF,KAAOp1B,SAAjI,IAA4ImB,EAAEk0B,EAAF,KAAOr1B,SAAnJ,IAA8JmB,EAAEm0B,EAAF,KAAOt1B,SAAxK,EAAkL;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEstB,YAAF,CAAep0B,EAAEM,CAAjB,EAAmBN,EAAEN,CAArB,EAAuBM,EAAEZ,CAAzB,EAA2BY,EAAEO,CAA7B,EAA+BP,EAAEwB,CAAjC,EAAmCxB,EAAEg0B,EAArC,EAAwCh0B,EAAEi0B,EAA1C,EAA6Cj0B,EAAEk0B,EAA/C,EAAmD,OAAOptB,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQl1B,SAAR,IAAmBmB,EAAEM,CAAF,KAAMzB,SAAzB,IAAoCmB,EAAEN,CAAF,KAAMb,SAA1C,IAAqDmB,EAAEZ,CAAF,KAAMP,SAA3D,IAAsEmB,EAAEO,CAAF,KAAM1B,SAA/E,EAAyF;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEutB,UAAF,CAAar0B,EAAEM,CAAf,EAAiBN,EAAEN,CAAnB,EAAqBM,EAAEZ,CAAvB,EAA0B,OAAO0H,CAAP;AAAS,OAAG9G,EAAEO,CAAF,KAAM1B,SAAN,IAAiBmB,EAAEwB,CAAF,KAAM3C,SAAvB,IAAkCmB,EAAEhB,CAAF,KAAMH,SAAxC,IAAmDmB,EAAEmH,CAAF,KAAMtI,SAAzD,IAAoEmB,EAAEwD,CAAF,KAAM3E,SAA7E,EAAuF;AAAC,QAAIiI,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEuR,SAAF,CAAYrY,EAAEO,CAAd,EAAgBP,EAAEwB,CAAlB,EAAoBxB,EAAEhB,CAAtB,EAAwBgB,EAAEmH,CAA1B,EAA6B,OAAOL,CAAP;AAAS,OAAG9G,EAAEO,CAAF,KAAM1B,SAAN,IAAiBmB,EAAEwB,CAAF,KAAM3C,SAAvB,IAAkCmB,EAAEhB,CAAF,KAAMH,SAAxC,IAAmDmB,EAAEmH,CAAF,KAAMtI,SAAzD,IAAoEmB,EAAEwD,CAAF,KAAM3E,SAA7E,EAAuF;AAAC,QAAIiI,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEutB,UAAF,CAAar0B,EAAEO,CAAf,EAAiBP,EAAEwB,CAAnB,EAAqBxB,EAAEhB,CAAvB,EAAyBgB,EAAEmH,CAA3B,EAA6BnH,EAAEwD,CAA/B,EAAkC,OAAOsD,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,KAAR,IAAe/zB,EAAEM,CAAF,KAAMzB,SAArB,IAAgCmB,EAAEN,CAAF,KAAMb,SAAtC,IAAiDmB,EAAEZ,CAAF,KAAMP,SAA1D,EAAoE;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEuR,SAAF,CAAYkM,UAAUvkB,EAAEM,CAAZ,CAAZ,EAA2BikB,UAAUvkB,EAAEN,CAAZ,CAA3B,EAA2C,OAAOoH,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,KAAR,IAAe/zB,EAAEM,CAAF,KAAMzB,SAArB,IAAgCmB,EAAEN,CAAF,KAAMb,SAAtC,IAAiDmB,EAAEZ,CAAF,KAAMP,SAAvD,IAAkEmB,EAAEO,CAAF,KAAM1B,SAAxE,IAAmFmB,EAAEwB,CAAF,KAAM3C,SAAzF,IAAoGmB,EAAEg0B,EAAF,KAAOn1B,SAA3G,IAAsHmB,EAAEi0B,EAAF,KAAOp1B,SAA7H,IAAwImB,EAAEm0B,EAAF,KAAOt1B,SAAlJ,EAA4J;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEstB,YAAF,CAAe7P,UAAUvkB,EAAEM,CAAZ,CAAf,EAA8BikB,UAAUvkB,EAAEN,CAAZ,CAA9B,EAA6C6kB,UAAUvkB,EAAEZ,CAAZ,CAA7C,EAA4DmlB,UAAUvkB,EAAEO,CAAZ,CAA5D,EAA2EgkB,UAAUvkB,EAAEwB,CAAZ,CAA3E,EAA0F+iB,UAAUvkB,EAAEg0B,EAAZ,CAA1F,EAA0GzP,UAAUvkB,EAAEi0B,EAAZ,CAA1G,EAA0H1P,UAAUvkB,EAAEm0B,EAAZ,CAA1H,EAA2I,OAAOrtB,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,KAAR,IAAe/zB,EAAEM,CAAF,KAAMzB,SAArB,IAAgCmB,EAAEN,CAAF,KAAMb,SAAtC,IAAiDmB,EAAEZ,CAAF,KAAMP,SAA1D,EAAoE;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEutB,UAAF,CAAa9P,UAAUvkB,EAAEM,CAAZ,CAAb,EAA4BikB,UAAUvkB,EAAEN,CAAZ,CAA5B,EAA2C6kB,UAAUvkB,EAAEZ,CAAZ,CAA3C,EAA2D,OAAO0H,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,IAAR,IAAc/zB,EAAEs0B,GAAF,KAAQz1B,SAAtB,IAAiCmB,EAAEwD,CAAF,KAAM3E,SAAvC,IAAkDmB,EAAEmH,CAAF,KAAMtI,SAAxD,IAAmEmB,EAAEZ,CAAF,KAAMP,SAA5E,EAAsF;AAAC,QAAIgB,IAAE,IAAIC,CAAJ,CAAM,EAACsZ,OAAMpZ,EAAEs0B,GAAT,EAAN,CAAN,CAA2B,IAAI/yB,IAAE1B,EAAEsvB,QAAF,CAAWS,MAAX,GAAkB,CAAxB,CAA0B,IAAIvoB,IAAE,CAAC,eAAakd,UAAUvkB,EAAEwD,CAAZ,CAAd,EAA8B1B,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAI0F,IAAE,CAAC,eAAasd,UAAUvkB,EAAEmH,CAAZ,CAAd,EAA8BrF,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAIoC,IAAE,OAAK0D,CAAL,GAAOJ,CAAb,CAAepH,EAAE6vB,eAAF,CAAkB/rB,CAAlB,EAAqB,OAAO9D,CAAP;AAAS,OAAGG,EAAE+zB,GAAF,KAAQ,IAAR,IAAc/zB,EAAEs0B,GAAF,KAAQz1B,SAAtB,IAAiCmB,EAAEwD,CAAF,KAAM3E,SAAvC,IAAkDmB,EAAEmH,CAAF,KAAMtI,SAAxD,IAAmEmB,EAAEZ,CAAF,KAAMP,SAA5E,EAAsF;AAAC,QAAIgB,IAAE,IAAIC,CAAJ,CAAM,EAACsZ,OAAMpZ,EAAEs0B,GAAT,EAAN,CAAN,CAA2B,IAAI/yB,IAAE1B,EAAEsvB,QAAF,CAAWS,MAAX,GAAkB,CAAxB,CAA0B,IAAIvoB,IAAE,CAAC,eAAakd,UAAUvkB,EAAEwD,CAAZ,CAAd,EAA8B1B,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAI0F,IAAE,CAAC,eAAasd,UAAUvkB,EAAEmH,CAAZ,CAAd,EAA8BrF,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAIoC,IAAE,OAAK0D,CAAL,GAAOJ,CAAb,CAAe,IAAIxH,IAAE,CAAC,eAAa8kB,UAAUvkB,EAAEZ,CAAZ,CAAd,EAA8B0C,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C1B,EAAE6vB,eAAF,CAAkB/rB,CAAlB,EAAqB9D,EAAE4vB,gBAAF,CAAmBhwB,CAAnB,EAAsB,OAAOI,CAAP;AAAS,OAAGS,MAAI,UAAP,EAAkB;AAAC,QAAI4F,IAAElG,CAAN;AAAA,QAAQ+F,IAAEuc,OAAV;AAAA,QAAkB5b,CAAlB;AAAA,QAAoBI,CAApB,CAAsBJ,IAAEJ,EAAEJ,CAAF,EAAI,CAAJ,CAAF,CAAS,IAAGQ,EAAE3G,MAAF,KAAW,CAAd,EAAgB;AAAC+G,UAAE,IAAIvD,CAAJ,EAAF,CAAUuD,EAAE2pB,kBAAF,CAAqBvqB,CAArB;AAAwB,KAAnD,MAAuD;AAAC,UAAGQ,EAAE3G,MAAF,KAAW,CAAd,EAAgB;AAAC+G,YAAE,IAAIS,CAAJ,EAAF,CAAUT,EAAE2pB,kBAAF,CAAqBvqB,CAArB;AAAwB,OAAnD,MAAuD;AAAC,YAAGQ,EAAE3G,MAAF,GAAS,CAAT,IAAYmG,EAAE3D,MAAF,CAASmE,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAAlC,EAAuC;AAACI,cAAE,IAAIhH,CAAJ,EAAF,CAAUgH,EAAE2pB,kBAAF,CAAqBvqB,CAArB;AAAwB,SAA1E,MAA8E;AAAC,gBAAK,sCAAL;AAA4C;AAAC;AAAC,YAAOY,CAAP;AAAS,OAAGxG,MAAI,UAAP,EAAkB;AAAC,QAAIwG,IAAEhB,EAAEutB,8BAAF,CAAiCrzB,CAAjC,CAAN,CAA0C,OAAO8G,CAAP;AAAS,OAAGxG,MAAI,UAAP,EAAkB;AAAC,WAAOwF,EAAE6tB,yBAAF,CAA4B3zB,CAA5B,CAAP;AAAsC,OAAGM,MAAI,SAAP,EAAiB;AAAC,WAAOi0B,KAAKC,uBAAL,CAA6Bx0B,CAA7B,CAAP;AAAuC,OAAGA,EAAEoF,OAAF,CAAU,mBAAV,EAA8B,CAA9B,KAAkC,CAAC,CAAnC,IAAsCpF,EAAEoF,OAAF,CAAU,wBAAV,EAAmC,CAAnC,KAAuC,CAAC,CAA9E,IAAiFpF,EAAEoF,OAAF,CAAU,2BAAV,EAAsC,CAAtC,KAA0C,CAAC,CAA/H,EAAiI;AAAC,WAAOmvB,KAAKE,uBAAL,CAA6Bz0B,CAA7B,CAAP;AAAuC,OAAGA,EAAEoF,OAAF,CAAU,kBAAV,KAA+B,CAAC,CAAnC,EAAqC;AAAC,QAAIwB,IAAEue,SAASnlB,CAAT,EAAW,YAAX,CAAN,CAA+B,OAAO8F,EAAE6tB,yBAAF,CAA4B/sB,CAA5B,CAAP;AAAsC,OAAG5G,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAInD,IAAEuE,EAAExG,CAAF,EAAI,iBAAJ,CAAN,CAA6B,OAAO8F,EAAEonB,MAAF,CAASjrB,CAAT,EAAW,IAAX,EAAgB,UAAhB,CAAP;AAAmC,OAAGjC,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAIa,IAAEO,EAAExG,CAAF,EAAI,iBAAJ,CAAN,CAA6B,IAAI2H,IAAEvI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIwB,IAAErI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIG,IAAEhH,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAItE,IAAEvC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIxE,IAAErC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIa,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEutB,UAAF,CAAa,IAAIxrB,UAAJ,CAAelB,CAAf,EAAiB,EAAjB,CAAb,EAAkC,IAAIkB,UAAJ,CAAepB,CAAf,EAAiB,EAAjB,CAAlC,EAAuD,IAAIoB,UAAJ,CAAezC,CAAf,EAAiB,EAAjB,CAAvD,EAA4E,IAAIyC,UAAJ,CAAelH,CAAf,EAAiB,EAAjB,CAA5E,EAAiG,IAAIkH,UAAJ,CAAepH,CAAf,EAAiB,EAAjB,CAAjG,EAAuH,OAAOqF,CAAP;AAAS,OAAG9G,EAAEoF,OAAF,CAAU,mBAAV,KAAgC,CAAC,CAApC,EAAsC;AAAC,WAAOU,EAAE4tB,8BAAF,CAAiC1zB,CAAjC,CAAP;AAA2C,OAAGA,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAI5E,IAAEsF,EAAEysB,kBAAF,CAAqBvyB,CAArB,EAAuBC,CAAvB,CAAN,CAAgC,IAAI+F,IAAE,IAAI0R,MAAJ,EAAN,CAAmB1R,EAAEyqB,kBAAF,CAAqBjwB,CAArB,EAAwB,OAAOwF,CAAP;AAAS,OAAGhG,EAAEoF,OAAF,CAAU,sBAAV,KAAmC,CAAC,CAApC,IAAuCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAArE,EAAuE;AAAC,QAAIa,IAAEH,EAAEysB,kBAAF,CAAqBvyB,CAArB,EAAuBC,CAAvB,CAAN,CAAgC,IAAI6G,IAAE1H,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAI/G,IAAEE,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAN,CAAwB,IAAIiB,IAAE9H,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,EAAkB1D,MAAlB,CAAyB,CAAzB,CAAN,CAAkC,IAAI7C,IAAE,EAAN,CAAS,IAAGwX,KAAKf,MAAL,CAAYsL,GAAZ,CAAgBuN,WAAhB,CAA4B9vB,CAA5B,MAAiCL,SAApC,EAA8C;AAACa,UAAEwX,KAAKf,MAAL,CAAYsL,GAAZ,CAAgBuN,WAAhB,CAA4B9vB,CAA5B,CAAF;AAAiC,KAAhF,MAAoF;AAAC,YAAK,4CAA0CA,CAA/C;AAAiD,SAAIW,IAAE,IAAIC,CAAJ,CAAM,EAACsZ,OAAM1Z,CAAP,EAAN,CAAN,CAAuBG,EAAE6vB,eAAF,CAAkBxoB,CAAlB,EAAqBrH,EAAE4vB,gBAAF,CAAmB3oB,CAAnB,EAAsBjH,EAAEkY,QAAF,GAAW,KAAX,CAAiB,OAAOlY,CAAP;AAAS,OAAGG,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAIa,IAAEH,EAAEysB,kBAAF,CAAqBvyB,CAArB,EAAuBC,CAAvB,CAAN,CAAgC,IAAI0H,IAAEvI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIwB,IAAErI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIG,IAAEhH,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAItE,IAAEvC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIxE,IAAErC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIa,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEutB,UAAF,CAAa,IAAIxrB,UAAJ,CAAelB,CAAf,EAAiB,EAAjB,CAAb,EAAkC,IAAIkB,UAAJ,CAAepB,CAAf,EAAiB,EAAjB,CAAlC,EAAuD,IAAIoB,UAAJ,CAAezC,CAAf,EAAiB,EAAjB,CAAvD,EAA4E,IAAIyC,UAAJ,CAAelH,CAAf,EAAiB,EAAjB,CAA5E,EAAiG,IAAIkH,UAAJ,CAAepH,CAAf,EAAiB,EAAjB,CAAjG,EAAuH,OAAOqF,CAAP;AAAS,OAAG9G,EAAEoF,OAAF,CAAU,6BAAV,KAA0C,CAAC,CAA9C,EAAgD;AAAC,WAAOU,EAAEstB,2BAAF,CAA8BpzB,CAA9B,EAAgCC,CAAhC,CAAP;AAA0C,SAAK,wBAAL;AAA8B,CAAjxJ,CAAkxJgtB,QAAQyH,eAAR,GAAwB,UAASx0B,CAAT,EAAWP,CAAX,EAAa;AAAC,MAAGO,KAAG,KAAN,EAAY;AAAC,QAAIT,IAAEE,CAAN,CAAQ,IAAIV,IAAE,IAAIyY,MAAJ,EAAN,CAAmBzY,EAAE01B,QAAF,CAAWl1B,CAAX,EAAa,OAAb,EAAsBR,EAAE+Y,SAAF,GAAY,IAAZ,CAAiB/Y,EAAE8Y,QAAF,GAAW,IAAX,CAAgB,IAAI7Y,IAAE,IAAIwY,MAAJ,EAAN,CAAmB,IAAIhY,IAAET,EAAEqB,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAN,CAAuB,IAAIlB,IAAEb,EAAES,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAN,CAAuB9B,EAAEmZ,SAAF,CAAY3Y,CAAZ,EAAcI,CAAd,EAAiBZ,EAAE8Y,SAAF,GAAY,KAAZ,CAAkB9Y,EAAE6Y,QAAF,GAAW,IAAX,CAAgB,IAAI9X,IAAE,EAAN,CAASA,EAAE20B,SAAF,GAAY31B,CAAZ,CAAcgB,EAAE40B,SAAF,GAAY31B,CAAZ,CAAc,OAAOe,CAAP;AAAS,GAAjQ,MAAqQ;AAAC,QAAGC,KAAG,IAAN,EAAW;AAAC,UAAId,IAAEO,CAAN,CAAQ,IAAIX,IAAE,IAAIkY,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAMha,CAAP,EAAtB,CAAN,CAAuC,IAAIS,IAAEb,EAAE8wB,kBAAF,EAAN,CAA6B,IAAI7wB,IAAE,IAAIiY,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAMha,CAAP,EAAtB,CAAN,CAAuCH,EAAEywB,eAAF,CAAkB7vB,EAAEsuB,QAApB,EAA8BlvB,EAAEwwB,gBAAF,CAAmB5vB,EAAE2tB,QAArB,EAA+BvuB,EAAE+Y,SAAF,GAAY,IAAZ,CAAiB/Y,EAAE8Y,QAAF,GAAW,KAAX,CAAiB,IAAI7Y,IAAE,IAAIgY,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAMha,CAAP,EAAtB,CAAN,CAAuCF,EAAEwwB,eAAF,CAAkB7vB,EAAEsuB,QAApB,EAA8BjvB,EAAE8Y,SAAF,GAAY,KAAZ,CAAkB9Y,EAAE6Y,QAAF,GAAW,IAAX,CAAgB,IAAI9X,IAAE,EAAN,CAASA,EAAE20B,SAAF,GAAY31B,CAAZ,CAAcgB,EAAE40B,SAAF,GAAY31B,CAAZ,CAAc,OAAOe,CAAP;AAAS,KAAnX,MAAuX;AAAC,YAAK,wBAAsBC,CAA3B;AAA6B;AAAC;AAAC,CAAnsB,CAAosB+sB,QAAQ6H,MAAR,GAAe,UAASr1B,CAAT,EAAWgI,CAAX,EAAaN,CAAb,EAAelF,CAAf,EAAiBT,CAAjB,EAAmB3B,CAAnB,EAAqB;AAAC,MAAIiG,IAAEoR,IAAN;AAAA,MAAWjX,IAAE6F,EAAEsW,IAAf;AAAA,MAAoBnV,IAAEhH,EAAE+c,mBAAxB;AAAA,MAA4C9d,IAAEe,EAAE2c,UAAhD;AAAA,MAA2D5c,IAAEC,EAAEoc,QAAF,CAAWK,SAAxE;AAAA,MAAkFxc,IAAED,EAAEuhB,IAAtF;AAAA,MAA2Fja,IAAErH,EAAE60B,oBAA/F;AAAA,MAAoHr1B,IAAEoG,EAAEqQ,MAAxH;AAAA,MAA+HxS,IAAEjE,EAAEsuB,GAAnI;AAAA,MAAuIrsB,IAAEjC,EAAEguB,KAA3I;AAAA,MAAiJptB,IAAEoX,MAAnJ,CAA0J,SAASxQ,CAAT,CAAWzF,CAAX,EAAa;AAAC,QAAIsE,IAAE/F,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAAC,OAAM,EAACjU,QAAOtf,EAAEnB,CAAV,EAAP,EAAX,EAAgC,EAAC,OAAMmB,EAAE/B,CAAT,EAAhC,EAA4C,EAAC,OAAM,EAACqhB,QAAOtf,EAAErC,CAAV,EAAP,EAA5C,EAAiE,EAAC,OAAM,EAAC2hB,QAAOtf,EAAElB,CAAV,EAAP,EAAjE,EAAsF,EAAC,OAAM,EAACwgB,QAAOtf,EAAED,CAAV,EAAP,EAAtF,EAA2G,EAAC,OAAM,EAACuf,QAAOtf,EAAEkW,IAAV,EAAP,EAA3G,EAAmI,EAAC,OAAM,EAACoJ,QAAOtf,EAAEmW,IAAV,EAAP,EAAnI,EAA2J,EAAC,OAAM,EAACmJ,QAAOtf,EAAEoW,KAAV,EAAP,EAA3J,CAAL,EAAF,CAAN,CAAoM,OAAO9R,CAAP;AAAS,YAASsB,CAAT,CAAWtB,CAAX,EAAa;AAAC,QAAItE,IAAEzB,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACC,QAAO,EAAC3V,KAAIvZ,EAAEupB,SAAP,EAAR,EAAX,EAAsC,EAACxR,KAAI,CAAC,IAAD,EAAM,IAAN,EAAW,EAAC6D,KAAI,EAACC,MAAK7b,EAAEypB,SAAR,EAAL,EAAX,CAAL,EAAtC,EAAiF,EAAC1R,KAAI,CAAC,IAAD,EAAM,IAAN,EAAW,EAACoX,QAAO,EAAC5V,KAAI,OAAKvZ,EAAEwpB,SAAZ,EAAR,EAAX,CAAL,EAAjF,CAAL,EAAF,CAAN,CAAmJ,OAAO9tB,CAAP;AAAS,YAAS+B,CAAT,CAAW/B,CAAX,EAAa;AAAC,QAAIsE,IAAE/F,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAAC,OAAM,EAACjU,QAAOtf,EAAElB,CAAV,EAAP,EAAX,EAAgC,EAAC,OAAM,EAACwgB,QAAOtf,EAAED,CAAV,EAAP,EAAhC,EAAqD,EAAC,OAAM,EAACuf,QAAOtf,EAAEzC,CAAV,EAAP,EAArD,EAA0E,EAAC,OAAM,EAAC+hB,QAAOtf,EAAE0F,CAAV,EAAP,EAA1E,EAA+F,EAAC,OAAM,EAAC4Z,QAAOtf,EAAE+B,CAAV,EAAP,EAA/F,CAAL,EAAF,CAAN,CAAoI,OAAOuC,CAAP;AAAS,OAAG,CAAEzF,MAAIzB,SAAJ,IAAeY,aAAaa,CAA7B,IAAkCqD,MAAI9E,SAAJ,IAAeY,aAAakE,CAA9D,IAAmEhC,MAAI9C,SAAJ,IAAeY,aAAakC,CAAhG,KAAqGlC,EAAEsY,QAAF,IAAY,IAAjH,KAAwHtQ,MAAI5I,SAAJ,IAAe4I,KAAG,UAA1I,CAAH,EAAyJ;AAAC,QAAIE,IAAE,IAAIJ,CAAJ,CAAM9H,CAAN,CAAN,CAAe,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,OAAOzB,SAASlZ,CAAT,EAAW,YAAX,CAAP;AAAgC,OAAGkE,KAAG,UAAH,IAAenH,MAAIzB,SAAnB,IAA8BY,aAAaa,CAA3C,KAA+C6G,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,KAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAET,EAAEzH,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,OAAOzB,SAASlZ,CAAT,EAAW,iBAAX,CAAP;AAAqC,OAAGkE,KAAG,UAAH,IAAe9F,MAAI9C,SAAnB,IAA8BY,aAAakC,CAA3C,KAA+CwF,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,KAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIlY,IAAE,IAAImH,CAAJ,CAAM,EAAC2a,MAAKniB,EAAE+vB,SAAR,EAAN,CAAN,CAAgC,IAAI9rB,IAAE5D,EAAEoe,aAAF,EAAN,CAAwB,IAAIjf,IAAEoI,EAAE5H,CAAF,CAAN,CAAW,IAAI8B,IAAEtC,EAAEif,aAAF,EAAN,CAAwB,IAAI3d,IAAE,EAAN,CAASA,KAAGkc,SAAS/Y,CAAT,EAAW,eAAX,CAAH,CAA+BnD,KAAGkc,SAASlb,CAAT,EAAW,gBAAX,CAAH,CAAgC,OAAOhB,CAAP;AAAS,OAAGkH,KAAG,UAAH,IAAe9D,MAAI9E,SAAnB,IAA8BY,aAAakE,CAA3C,KAA+CwD,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,KAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAEnE,EAAE/D,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,OAAOzB,SAASlZ,CAAT,EAAW,iBAAX,CAAP;AAAqC,OAAGkE,KAAG,UAAH,IAAenH,MAAIzB,SAAnB,IAA8BY,aAAaa,CAA3C,IAA+C6G,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,IAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAET,EAAEzH,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAGjc,MAAIpD,SAAP,EAAiB;AAACoD,UAAE,cAAF;AAAiB,YAAO,KAAKuwB,iCAAL,CAAuC,KAAvC,EAA6CjvB,CAA7C,EAA+C4D,CAA/C,EAAiDlF,CAAjD,EAAmDpC,CAAnD,CAAP;AAA6D,OAAG4H,KAAG,UAAH,IAAe9F,MAAI9C,SAAnB,IAA8BY,aAAakC,CAA3C,IAA+CwF,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,IAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAEN,EAAE5H,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAGjc,MAAIpD,SAAP,EAAiB;AAACoD,UAAE,cAAF;AAAiB,YAAO,KAAKuwB,iCAAL,CAAuC,IAAvC,EAA4CjvB,CAA5C,EAA8C4D,CAA9C,EAAgDlF,CAAhD,EAAkDpC,CAAlD,CAAP;AAA4D,OAAG4H,KAAG,UAAH,IAAe9D,MAAI9E,SAAnB,IAA8BY,aAAakE,CAA3C,IAA+CwD,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,IAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAEnE,EAAE/D,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAGjc,MAAIpD,SAAP,EAAiB;AAACoD,UAAE,cAAF;AAAiB,YAAO,KAAKuwB,iCAAL,CAAuC,KAAvC,EAA6CjvB,CAA7C,EAA+C4D,CAA/C,EAAiDlF,CAAjD,EAAmDpC,CAAnD,CAAP;AAA6D,OAAIW,IAAE,SAAFA,CAAE,CAASuF,CAAT,EAAWtE,CAAX,EAAa;AAAC,QAAIwE,IAAEtG,EAAEoG,CAAF,EAAItE,CAAJ,CAAN,CAAa,IAAIuE,IAAE,IAAIhG,CAAJ,CAAM,EAACg1B,KAAI,CAAC,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,YAAN,EAAL,EAAD,EAA2B,EAACoT,KAAI,CAAC,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,aAAN,EAAL,EAAD,EAA4B,EAACoT,KAAI,CAAC,EAACC,QAAO,EAAC3V,KAAIrZ,EAAE4sB,UAAP,EAAR,EAAD,EAA6B,EAAC,OAAM5sB,EAAE6sB,UAAT,EAA7B,CAAL,EAA5B,CAAL,EAAD,EAA6F,EAACkC,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,cAAN,EAAL,EAAD,EAA6B,EAACqT,QAAO,EAAC3V,KAAIrZ,EAAE2sB,kBAAP,EAAR,EAA7B,CAAL,EAA7F,CAAL,EAA3B,CAAL,EAAD,EAA+M,EAACqC,QAAO,EAAC3V,KAAIrZ,EAAEyrB,UAAP,EAAR,EAA/M,CAAL,EAAN,CAAN,CAA+P,OAAO1rB,EAAEkY,aAAF,EAAP;AAAyB,GAAzT,CAA0T,IAAIve,IAAE,SAAFA,CAAE,CAAS+G,CAAT,EAAWE,CAAX,EAAa;AAAC,QAAIZ,IAAE,GAAN,CAAU,IAAIQ,IAAErG,SAASC,GAAT,CAAac,SAAb,CAAuBa,MAAvB,CAA8B,CAA9B,CAAN,CAAuC,IAAIuE,IAAE,cAAN,CAAqB,IAAI7E,IAAEtB,SAASC,GAAT,CAAac,SAAb,CAAuBa,MAAvB,CAA8B,CAA9B,CAAN,CAAuC,IAAIkE,IAAE9F,SAAS6yB,MAAT,CAAgBpsB,CAAhB,EAAkBJ,CAAlB,EAAoB,EAACysB,SAAQ,MAAI,EAAb,EAAgBC,YAAWltB,CAA3B,EAApB,CAAN,CAAyD,IAAIE,IAAE/F,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBqE,CAAvB,CAAN,CAAgC,IAAIN,IAAEjG,SAASmxB,SAAT,CAAmBhZ,OAAnB,CAA2BpS,CAA3B,EAA6BD,CAA7B,EAA+B,EAACwrB,IAAGhwB,CAAJ,EAA/B,IAAuC,EAA7C,CAAgD,IAAIsE,IAAE,EAAN,CAASA,EAAE2rB,UAAF,GAAatrB,CAAb,CAAeL,EAAE8sB,UAAF,GAAa1yB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BmF,CAA3B,CAAb,CAA2CT,EAAE+sB,UAAF,GAAa9sB,CAAb,CAAeD,EAAE4sB,mBAAF,GAAsBrsB,CAAtB,CAAwBP,EAAE6sB,kBAAF,GAAqBzyB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BI,CAA3B,CAArB,CAAmD,OAAOsE,CAAP;AAAS,GAAhb,CAAib,IAAG0B,KAAG,UAAH,IAAenH,KAAGzB,SAAlB,IAA6BY,aAAaa,CAA1C,IAA6Cb,EAAEuY,SAAF,IAAa,IAA7D,EAAkE;AAAC,QAAIhZ,IAAEkI,EAAEzH,CAAF,CAAN,CAAW,IAAIL,IAAEJ,EAAEkf,aAAF,EAAN,CAAwB,IAAIvW,IAAE3H,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,eAAN,EAAL,EAAD,EAA8B,EAAC,QAAO,IAAR,EAA9B,CAAL,EAAX,EAA8D,EAACqT,QAAO,EAAC3V,KAAIlgB,CAAL,EAAR,EAA9D,CAAL,EAAF,CAAN,CAA+F,IAAImE,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAG/W,MAAItI,SAAJ,IAAesI,KAAG,IAArB,EAA0B;AAAC,aAAOsV,SAASlZ,CAAT,EAAW,aAAX,CAAP;AAAiC,KAA5D,MAAgE;AAAC,UAAIhC,IAAEf,EAAE+C,CAAF,EAAI4D,CAAJ,CAAN,CAAa,OAAOsV,SAASlb,CAAT,EAAW,uBAAX,CAAP;AAA2C;AAAC,OAAGkG,KAAG,UAAH,IAAe9F,MAAI9C,SAAnB,IAA8BY,aAAakC,CAA3C,IAA8ClC,EAAEuY,SAAF,IAAa,IAA9D,EAAmE;AAAC,QAAIhZ,IAAE,IAAIgB,CAAJ,CAAM,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACC,QAAO,EAAC3V,KAAI7f,EAAE6vB,SAAP,EAAR,EAAX,EAAsC,EAACxR,KAAI,CAAC,IAAD,EAAM,IAAN,EAAW,EAACoX,QAAO,EAAC5V,KAAI,OAAK7f,EAAE8vB,SAAZ,EAAR,EAAX,CAAL,EAAtC,CAAL,EAAN,CAAN,CAA4G,IAAInwB,IAAEJ,EAAEkf,aAAF,EAAN,CAAwB,IAAIvW,IAAE3H,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,aAAN,EAAL,EAAD,EAA4B,EAACD,KAAI,EAACC,MAAKniB,EAAE+vB,SAAR,EAAL,EAA5B,CAAL,EAAX,EAAuE,EAACyF,QAAO,EAAC3V,KAAIlgB,CAAL,EAAR,EAAvE,CAAL,EAAF,CAAN,CAAwG,IAAImE,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAG/W,MAAItI,SAAJ,IAAesI,KAAG,IAArB,EAA0B;AAAC,aAAOsV,SAASlZ,CAAT,EAAW,aAAX,CAAP;AAAiC,KAA5D,MAAgE;AAAC,UAAIhC,IAAEf,EAAE+C,CAAF,EAAI4D,CAAJ,CAAN,CAAa,OAAOsV,SAASlb,CAAT,EAAW,uBAAX,CAAP;AAA2C;AAAC,OAAGkG,KAAG,UAAH,IAAe9D,MAAI9E,SAAnB,IAA8BY,aAAakE,CAA3C,IAA8ClE,EAAEuY,SAAF,IAAa,IAA9D,EAAmE;AAAC,QAAIhZ,IAAE,IAAIE,CAAJ,CAAM,EAAC6hB,QAAOthB,EAAE+D,CAAV,EAAN,CAAN,CAA0B,IAAIpE,IAAEJ,EAAEkf,aAAF,EAAN,CAAwB,IAAIvW,IAAE3H,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,KAAN,EAAL,EAAD,EAAoB,EAACoT,KAAI,CAAC,EAAC,OAAM,EAACjU,QAAOthB,EAAEc,CAAV,EAAP,EAAD,EAAsB,EAAC,OAAM,EAACwgB,QAAOthB,EAAE+B,CAAV,EAAP,EAAtB,EAA2C,EAAC,OAAM,EAACuf,QAAOthB,EAAET,CAAV,EAAP,EAA3C,CAAL,EAApB,CAAL,EAAX,EAA6G,EAACi2B,QAAO,EAAC3V,KAAIlgB,CAAL,EAAR,EAA7G,CAAL,EAAF,CAAN,CAA8I,IAAImE,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAG/W,MAAItI,SAAJ,IAAesI,KAAG,IAArB,EAA0B;AAAC,aAAOsV,SAASlZ,CAAT,EAAW,aAAX,CAAP;AAAiC,KAA5D,MAAgE;AAAC,UAAIhC,IAAEf,EAAE+C,CAAF,EAAI4D,CAAJ,CAAN,CAAa,OAAOsV,SAASlb,CAAT,EAAW,uBAAX,CAAP;AAA2C;AAAC,SAAK,+BAAL;AAAqC,CAAvnI,CAAwnI0rB,QAAQkI,gBAAR,GAAyB,UAAS11B,CAAT,EAAW;AAAC,MAAIS,IAAEilB,SAAS1lB,CAAT,EAAW,qBAAX,CAAN,CAAwC,IAAIE,IAAEstB,QAAQmI,gBAAR,CAAyBl1B,CAAzB,CAAN,CAAkC,OAAOP,CAAP;AAAS,CAAxH,CAAyHstB,QAAQmI,gBAAR,GAAyB,UAASl1B,CAAT,EAAW;AAAC,MAAIP,IAAEstB,QAAQoI,WAAR,CAAoBn1B,CAApB,CAAN,CAA6B,IAAIT,IAAEwtB,QAAQC,MAAR,CAAevtB,EAAE21B,WAAjB,EAA6B,IAA7B,EAAkC,UAAlC,CAAN,CAAoD,OAAO71B,CAAP;AAAS,CAA/H,CAAgIwtB,QAAQoI,WAAR,GAAoB,UAASj2B,CAAT,EAAW;AAAC,MAAIU,IAAEwiB,OAAN,CAAc,IAAIpjB,IAAEY,EAAEgjB,WAAR,CAAoB,IAAInjB,IAAEG,EAAE8iB,MAAR,CAAe,IAAInjB,IAAE,EAAN,CAAS,IAAIT,IAAEI,CAAN,CAAQ,IAAGJ,EAAEuD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,yBAAL;AAA+B,OAAI7C,IAAER,EAAEF,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGU,EAAEK,MAAF,GAAS,CAAZ,EAAc;AAAC,UAAK,yBAAL;AAA+B,OAAGf,EAAEuD,MAAF,CAAS7C,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,UAAK,yBAAL;AAA+B,OAAIQ,IAAEhB,EAAEF,CAAF,EAAIU,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGQ,EAAEH,MAAF,GAAS,CAAZ,EAAc;AAAC,UAAK,yBAAL;AAA+B,KAAEu1B,WAAF,GAAc31B,EAAEX,CAAF,EAAIkB,EAAE,CAAF,CAAJ,CAAd,CAAwB,OAAOT,CAAP;AAAS,CAA7W,CAA8WwtB,QAAQsI,aAAR,GAAsB,UAASn2B,CAAT,EAAW;AAAC,MAAIK,IAAE,EAAN,CAAS,IAAGL,aAAasY,MAAb,IAAqBtY,EAAE4Y,SAA1B,EAAoC;AAACvY,MAAEs0B,GAAF,GAAM,KAAN,CAAYt0B,EAAEa,CAAF,GAAIgkB,UAAUllB,EAAEkB,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEC,CAAF,GAAI4kB,UAAUllB,EAAEM,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEL,CAAF,GAAIklB,UAAUllB,EAAEA,CAAF,CAAI4B,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEc,CAAF,GAAI+jB,UAAUllB,EAAEmB,CAAF,CAAIS,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAE+B,CAAF,GAAI8iB,UAAUllB,EAAEoC,CAAF,CAAIR,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEu0B,EAAF,GAAK1P,UAAUllB,EAAEuY,IAAF,CAAO3W,QAAP,CAAgB,EAAhB,CAAV,CAAL,CAAoCvB,EAAEw0B,EAAF,GAAK3P,UAAUllB,EAAEwY,IAAF,CAAO5W,QAAP,CAAgB,EAAhB,CAAV,CAAL,CAAoCvB,EAAE00B,EAAF,GAAK7P,UAAUllB,EAAEyY,KAAF,CAAQ7W,QAAR,CAAiB,EAAjB,CAAV,CAAL,CAAqC,OAAOvB,CAAP;AAAS,GAAvU,MAA2U;AAAC,QAAGL,aAAasY,MAAb,IAAqBtY,EAAE2Y,QAA1B,EAAmC;AAACtY,QAAEs0B,GAAF,GAAM,KAAN,CAAYt0B,EAAEa,CAAF,GAAIgkB,UAAUllB,EAAEkB,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEC,CAAF,GAAI4kB,UAAUllB,EAAEM,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgC,OAAOvB,CAAP;AAAS,KAAzH,MAA6H;AAAC,UAAGL,aAAa8X,KAAKf,MAAL,CAAYuX,KAAzB,IAAgCtuB,EAAE4Y,SAArC,EAA+C;AAAC,YAAI9X,IAAEd,EAAEywB,sBAAF,EAAN,CAAiC,IAAG3vB,MAAI,OAAJ,IAAaA,MAAI,OAApB,EAA4B;AAAC,gBAAK,qCAAmCA,CAAxC;AAA0C,aAAIP,IAAEP,EAAEuwB,iBAAF,EAAN,CAA4BlwB,EAAEs0B,GAAF,GAAM,IAAN,CAAWt0B,EAAE60B,GAAF,GAAMp0B,CAAN,CAAQT,EAAE+D,CAAF,GAAI8gB,UAAU3kB,EAAE6D,CAAZ,CAAJ,CAAmB/D,EAAE0H,CAAF,GAAImd,UAAU3kB,EAAEwH,CAAZ,CAAJ,CAAmB1H,EAAEL,CAAF,GAAIklB,UAAUllB,EAAEkwB,SAAZ,CAAJ,CAA2B,OAAO7vB,CAAP;AAAS,OAAjR,MAAqR;AAAC,YAAGL,aAAa8X,KAAKf,MAAL,CAAYuX,KAAzB,IAAgCtuB,EAAE2Y,QAArC,EAA8C;AAAC,cAAI7X,IAAEd,EAAEywB,sBAAF,EAAN,CAAiC,IAAG3vB,MAAI,OAAJ,IAAaA,MAAI,OAApB,EAA4B;AAAC,kBAAK,qCAAmCA,CAAxC;AAA0C,eAAIP,IAAEP,EAAEuwB,iBAAF,EAAN,CAA4BlwB,EAAEs0B,GAAF,GAAM,IAAN,CAAWt0B,EAAE60B,GAAF,GAAMp0B,CAAN,CAAQT,EAAE+D,CAAF,GAAI8gB,UAAU3kB,EAAE6D,CAAZ,CAAJ,CAAmB/D,EAAE0H,CAAF,GAAImd,UAAU3kB,EAAEwH,CAAZ,CAAJ,CAAmB,OAAO1H,CAAP;AAAS;AAAC;AAAC;AAAC,SAAK,0BAAL;AAAgC,CAAniC;AAC1ojBiY,OAAO8d,4BAAP,GAAoC,UAASt1B,CAAT,EAAW;AAAC,SAAOoiB,QAAQQ,WAAR,CAAoB5iB,CAApB,EAAsB,CAAtB,CAAP;AAAgC,CAAhF,CAAiFwX,OAAO+d,iCAAP,GAAyC,UAASv2B,CAAT,EAAW;AAAC,MAAIoB,IAAEgiB,OAAN,CAAc,IAAIxiB,IAAEQ,EAAEqiB,IAAR,CAAa,IAAI1iB,IAAEyX,OAAO8d,4BAAP,CAAoCt2B,CAApC,CAAN,CAA6C,IAAIQ,IAAEI,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIJ,IAAEC,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIR,IAAEK,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIN,IAAEG,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIhB,IAAEa,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIjB,IAAEc,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIgC,IAAEnC,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAID,IAAEF,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIb,IAAEU,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIA,IAAE,IAAIwI,KAAJ,EAAN,CAAkBxI,EAAE+B,IAAF,CAAOtC,CAAP,EAASG,CAAT,EAAWJ,CAAX,EAAaE,CAAb,EAAeV,CAAf,EAAiBD,CAAjB,EAAmBiD,CAAnB,EAAqBjC,CAArB,EAAuBZ,CAAvB,EAA0B,OAAOa,CAAP;AAAS,CAAlU,CAAmUyX,OAAOrY,SAAP,CAAiBq2B,2BAAjB,GAA6C,UAASt2B,CAAT,EAAW;AAAC,MAAIO,IAAEwlB,SAAS/lB,CAAT,CAAN,CAAkB,IAAIK,IAAEiY,OAAO+d,iCAAP,CAAyC91B,CAAzC,CAAN,CAAkD,KAAKy0B,YAAL,CAAkB30B,EAAE,CAAF,CAAlB,EAAuBA,EAAE,CAAF,CAAvB,EAA4BA,EAAE,CAAF,CAA5B,EAAiCA,EAAE,CAAF,CAAjC,EAAsCA,EAAE,CAAF,CAAtC,EAA2CA,EAAE,CAAF,CAA3C,EAAgDA,EAAE,CAAF,CAAhD,EAAqDA,EAAE,CAAF,CAArD;AAA2D,CAAxL,CAAyLiY,OAAOrY,SAAP,CAAiBoxB,kBAAjB,GAAoC,UAAS9wB,CAAT,EAAW;AAAC,MAAIF,IAAEiY,OAAO+d,iCAAP,CAAyC91B,CAAzC,CAAN,CAAkD,KAAKy0B,YAAL,CAAkB30B,EAAE,CAAF,CAAlB,EAAuBA,EAAE,CAAF,CAAvB,EAA4BA,EAAE,CAAF,CAA5B,EAAiCA,EAAE,CAAF,CAAjC,EAAsCA,EAAE,CAAF,CAAtC,EAA2CA,EAAE,CAAF,CAA3C,EAAgDA,EAAE,CAAF,CAAhD,EAAqDA,EAAE,CAAF,CAArD;AAA2D,CAA7J,CAA8JiY,OAAOrY,SAAP,CAAiBsxB,kBAAjB,GAAoC,UAASjxB,CAAT,EAAW;AAAC,MAAIC,CAAJ,EAAME,CAAN,EAAQG,CAAR,EAAUP,CAAV,EAAYS,CAAZ,EAAchB,CAAd,EAAgBE,CAAhB,EAAkBa,CAAlB,CAAoB,IAAIgC,IAAEqgB,OAAN,CAAc,IAAItjB,IAAEiD,EAAEihB,UAAR,CAAmB,IAAGjhB,EAAEqhB,SAAF,CAAY5jB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,UAAK,sBAAL;AAA4B,OAAG;AAACC,QAAEX,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBG,IAAEb,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBM,IAAEhB,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBD,IAAET,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBQ,IAAElB,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBR,IAAEF,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBN,IAAEJ,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBO,IAAEjB,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF;AAAsB,GAApL,CAAoL,OAAMI,CAAN,EAAQ;AAAC,UAAK,wCAAL;AAA8C,QAAKs0B,YAAL,CAAkBz0B,CAAlB,EAAoBE,CAApB,EAAsBG,CAAtB,EAAwBP,CAAxB,EAA0BS,CAA1B,EAA4BhB,CAA5B,EAA8BE,CAA9B,EAAgCa,CAAhC;AAAmC,CAA1a,CAA2ayX,OAAOrY,SAAP,CAAiBs2B,kBAAjB,GAAoC,UAASh2B,CAAT,EAAW;AAAC,MAAID,IAAE4iB,OAAN,CAAc,IAAI7iB,IAAEC,EAAEijB,IAAR,CAAa,IAAGjjB,EAAE4jB,SAAF,CAAY3jB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,UAAK,gCAAL;AAAsC,OAAIO,IAAER,EAAEojB,WAAF,CAAcnjB,CAAd,EAAgB,CAAhB,CAAN,CAAyB,IAAGO,EAAEH,MAAF,KAAW,CAAX,IAAcJ,EAAE4C,MAAF,CAASrC,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAAjC,IAAuCP,EAAE4C,MAAF,CAASrC,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAA7D,EAAkE;AAAC,UAAK,iCAAL;AAAuC,OAAIhB,IAAEO,EAAEE,CAAF,EAAIO,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAId,IAAEK,EAAEE,CAAF,EAAIO,EAAE,CAAF,CAAJ,CAAN,CAAgB,KAAKmY,SAAL,CAAenZ,CAAf,EAAiBE,CAAjB;AAAoB,CAAnU,CAAoUsY,OAAOrY,SAAP,CAAiBuxB,kBAAjB,GAAoC,UAASnxB,CAAT,EAAW;AAAC,MAAIE,IAAE2iB,OAAN,CAAc,IAAG3iB,EAAE2jB,SAAF,CAAY7jB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,UAAK,sBAAL;AAA4B,OAAGE,EAAEsjB,YAAF,CAAexjB,CAAf,EAAiB,CAAjB,EAAmB,CAAC,CAAD,EAAG,CAAH,CAAnB,MAA4B,wBAA/B,EAAwD;AAAC,UAAK,0BAAL;AAAgC,OAAIS,IAAEP,EAAEsjB,YAAF,CAAexjB,CAAf,EAAiB,CAAjB,EAAmB,CAAC,CAAD,EAAG,CAAH,CAAnB,CAAN,CAAgC,KAAKk2B,kBAAL,CAAwBz1B,CAAxB;AAA2B,CAAzQ,CAA0QwX,OAAOrY,SAAP,CAAiBwxB,iBAAjB,GAAmC,UAASpxB,CAAT,EAAWL,CAAX,EAAa;AAAC,MAAIc,CAAJ,EAAMP,CAAN,CAAQO,IAAE,IAAIq0B,IAAJ,EAAF,CAAar0B,EAAE01B,WAAF,CAAcn2B,CAAd,EAAiBE,IAAEO,EAAE21B,eAAF,EAAF,CAAsB,KAAKjF,kBAAL,CAAwBjxB,CAAxB;AAA2B,CAAxI;AACpuD,IAAIm2B,iBAAe,IAAI9Z,MAAJ,CAAW,EAAX,CAAnB,CAAkC8Z,eAAeC,OAAf,CAAuB,WAAvB,EAAmC,IAAnC,EAAyC,SAASC,wCAAT,CAAkD52B,CAAlD,EAAoDM,CAApD,EAAsDQ,CAAtD,EAAwD;AAAC,MAAIT,IAAE,SAAFA,CAAE,CAASP,CAAT,EAAW;AAAC,WAAOgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiT,UAAjB,CAA4BnrB,CAA5B,EAA8BgB,CAA9B,CAAP;AAAwC,GAA1D,CAA2D,IAAIP,IAAEF,EAAEL,CAAF,CAAN,CAAW,OAAO8X,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBgT,sBAAjB,CAAwCzqB,CAAxC,EAA0CO,CAA1C,EAA4CR,CAA5C,CAAP;AAAsD,UAASstB,uBAAT,CAAiCttB,CAAjC,EAAmCN,CAAnC,EAAqC;AAAC,MAAIO,IAAE,EAAN,CAAS,IAAIO,IAAEd,IAAE,CAAF,GAAIM,EAAEK,MAAZ,CAAmB,KAAI,IAAIN,IAAE,CAAV,EAAYA,IAAES,CAAd,EAAgBT,GAAhB,EAAoB;AAACE,QAAEA,IAAE,GAAJ;AAAQ,UAAOA,IAAED,CAAT;AAAW,QAAOL,SAAP,CAAiBiuB,IAAjB,GAAsB,UAASluB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIT,IAAE,SAAFA,CAAE,CAASC,CAAT,EAAW;AAAC,WAAOwX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiT,UAAjB,CAA4B3qB,CAA5B,EAA8BQ,CAA9B,CAAP;AAAwC,GAA1D,CAA2D,IAAIP,IAAEF,EAAEL,CAAF,CAAN,CAAW,OAAO,KAAK2uB,mBAAL,CAAyBpuB,CAAzB,EAA2BO,CAA3B,CAAP;AAAqC,CAA/I,CAAgJwX,OAAOrY,SAAP,CAAiB0uB,mBAAjB,GAAqC,UAASruB,CAAT,EAAWC,CAAX,EAAa;AAAC,MAAIT,IAAEgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBgT,sBAAjB,CAAwC1qB,CAAxC,EAA0CC,CAA1C,EAA4C,KAAKW,CAAL,CAAO+N,SAAP,EAA5C,CAAN,CAAsE,IAAI5O,IAAEmX,YAAY1X,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAIE,IAAE,KAAK62B,SAAL,CAAex2B,CAAf,CAAN,CAAwB,IAAIS,IAAEd,EAAE4B,QAAF,CAAW,EAAX,CAAN,CAAqB,OAAOgsB,wBAAwB9sB,CAAxB,EAA0B,KAAKI,CAAL,CAAO+N,SAAP,EAA1B,CAAP;AAAqD,CAAnP,CAAoP,SAAS6nB,YAAT,CAAsBv2B,CAAtB,EAAwBO,CAAxB,EAA0BR,CAA1B,EAA4B;AAAC,MAAID,IAAE,EAAN;AAAA,MAASL,IAAE,CAAX,CAAa,OAAMK,EAAEM,MAAF,GAASG,CAAf,EAAiB;AAACT,SAAG8X,UAAU7X,EAAE+X,UAAU9X,IAAE8C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiC,CAAC,CAACrD,IAAE,UAAH,KAAgB,EAAjB,EAAoB,CAACA,IAAE,QAAH,KAAc,EAAlC,EAAqC,CAACA,IAAE,KAAH,KAAW,CAAhD,EAAkDA,IAAE,GAApD,CAAjC,CAAZ,CAAF,CAAV,CAAH,CAAyHA,KAAG,CAAH;AAAK,UAAOK,CAAP;AAAS,QAAOJ,SAAP,CAAiB82B,OAAjB,GAAyB,UAASz2B,CAAT,EAAWQ,CAAX,EAAad,CAAb,EAAe;AAAC,MAAIO,IAAE,SAAFA,CAAE,CAAST,CAAT,EAAW;AAAC,WAAOgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyBtY,CAAzB,EAA2BgB,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAIT,IAAEE,EAAE8X,UAAU/X,CAAV,CAAF,CAAN,CAAsB,IAAGN,MAAIP,SAAP,EAAiB;AAACO,QAAE,CAAC,CAAH;AAAK,UAAO,KAAKyuB,sBAAL,CAA4BpuB,CAA5B,EAA8BS,CAA9B,EAAgCd,CAAhC,CAAP;AAA0C,CAAxL,CAAyLsY,OAAOrY,SAAP,CAAiBwuB,sBAAjB,GAAwC,UAAS7tB,CAAT,EAAWE,CAAX,EAAaD,CAAb,EAAe;AAAC,MAAIR,IAAE8X,UAAUvX,CAAV,CAAN,CAAmB,IAAIhB,IAAES,EAAEM,MAAR,CAAe,IAAIkC,IAAE,KAAK3B,CAAL,CAAO+N,SAAP,KAAmB,CAAzB,CAA2B,IAAI1O,IAAEgF,KAAK/C,IAAL,CAAUK,IAAE,CAAZ,CAAN,CAAqB,IAAI7C,CAAJ,CAAM,IAAIoB,IAAE,SAAFA,CAAE,CAASV,CAAT,EAAW;AAAC,WAAOoX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyB1X,CAAzB,EAA2BI,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAGD,MAAI,CAAC,CAAL,IAAQA,MAAIpB,SAAf,EAAyB;AAACoB,QAAEjB,CAAF;AAAI,GAA9B,MAAkC;AAAC,QAAGiB,MAAI,CAAC,CAAR,EAAU;AAACA,UAAEN,IAAEX,CAAF,GAAI,CAAN;AAAQ,KAAnB,MAAuB;AAAC,UAAGiB,IAAE,CAAC,CAAN,EAAQ;AAAC,cAAK,qBAAL;AAA2B;AAAC;AAAC,OAAGN,IAAGX,IAAEiB,CAAF,GAAI,CAAV,EAAa;AAAC,UAAK,eAAL;AAAqB,OAAIf,IAAE,EAAN,CAAS,IAAGe,IAAE,CAAL,EAAO;AAACf,QAAE,IAAIuJ,KAAJ,CAAUxI,CAAV,CAAF,CAAe,IAAI0W,YAAJ,GAAmB/G,SAAnB,CAA6B1Q,CAA7B,EAAgCA,IAAEuD,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiCvD,CAAjC,CAAF;AAAsC,OAAIoB,IAAEiX,UAAU/W,EAAEiX,UAAU,qCAAmChY,CAAnC,GAAqCP,CAA/C,CAAF,CAAV,CAAN,CAAsE,IAAIW,IAAE,EAAN,CAAS,KAAIT,IAAE,CAAN,EAAQA,IAAEO,IAAEM,CAAF,GAAIjB,CAAJ,GAAM,CAAhB,EAAkBI,KAAG,CAArB,EAAuB;AAACS,MAAET,CAAF,IAAK,CAAL;AAAO,OAAIM,IAAE+C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiC5C,CAAjC,IAAoC,MAApC,GAA2CX,CAAjD,CAAmD,IAAID,IAAEi3B,aAAa51B,CAAb,EAAeZ,EAAEK,MAAjB,EAAwBS,CAAxB,CAAN,CAAiC,IAAIgB,IAAE,EAAN,CAAS,KAAIpC,IAAE,CAAN,EAAQA,IAAEM,EAAEK,MAAZ,EAAmBX,KAAG,CAAtB,EAAwB;AAACoC,MAAEpC,CAAF,IAAKM,EAAEiD,UAAF,CAAavD,CAAb,IAAgBH,EAAE0D,UAAF,CAAavD,CAAb,CAArB;AAAqC,OAAImB,IAAG,SAAQ,IAAEZ,CAAF,GAAIsC,CAAb,GAAiB,GAAvB,CAA2BT,EAAE,CAAF,KAAM,CAACjB,CAAP,CAAS,KAAInB,IAAE,CAAN,EAAQA,IAAEJ,CAAV,EAAYI,GAAZ,EAAgB;AAACoC,MAAEQ,IAAF,CAAO1B,EAAEqC,UAAF,CAAavD,CAAb,CAAP;AAAwB,KAAE4C,IAAF,CAAO,GAAP,EAAY,OAAOgrB,wBAAwB,KAAKiJ,SAAL,CAAe,IAAIptB,UAAJ,CAAerH,CAAf,CAAf,EAAkCR,QAAlC,CAA2C,EAA3C,CAAxB,EAAuE,KAAKV,CAAL,CAAO+N,SAAP,EAAvE,CAAP;AAAkG,CAAt3B,CAAu3B,SAAS+nB,8BAAT,CAAwCl2B,CAAxC,EAA0Cd,CAA1C,EAA4CO,CAA5C,EAA8C;AAAC,MAAIF,IAAE,IAAIiY,MAAJ,EAAN,CAAmBjY,EAAE4Y,SAAF,CAAYjZ,CAAZ,EAAcO,CAAd,EAAiB,IAAID,IAAED,EAAE0Y,QAAF,CAAWjY,CAAX,CAAN,CAAoB,OAAOR,CAAP;AAAS,UAAS22B,gCAAT,CAA0Cn2B,CAA1C,EAA4CP,CAA5C,EAA8CF,CAA9C,EAAgD;AAAC,MAAIC,IAAE02B,+BAA+Bl2B,CAA/B,EAAiCP,CAAjC,EAAmCF,CAAnC,CAAN,CAA4C,IAAIL,IAAEM,EAAEsB,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,QAAvB,EAAgC,EAAhC,CAAN,CAA0C,OAAO9c,CAAP;AAAS,UAASk3B,4CAAT,CAAsDp3B,CAAtD,EAAwD;AAAC,OAAI,IAAIQ,CAAR,IAAawX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiQ,cAA9B,EAA6C;AAAC,QAAIjoB,IAAE8X,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiQ,cAAjB,CAAgC3nB,CAAhC,CAAN,CAAyC,IAAID,IAAEL,EAAEW,MAAR,CAAe,IAAGb,EAAEmJ,SAAF,CAAY,CAAZ,EAAc5I,CAAd,KAAkBL,CAArB,EAAuB;AAAC,UAAIO,IAAE,CAACD,CAAD,EAAGR,EAAEmJ,SAAF,CAAY5I,CAAZ,CAAH,CAAN,CAAyB,OAAOE,CAAP;AAAS;AAAC,UAAM,EAAN;AAAS,QAAON,SAAP,CAAiB6uB,MAAjB,GAAwB,UAAShvB,CAAT,EAAWW,CAAX,EAAa;AAACA,MAAEA,EAAEqc,OAAF,CAAU4Z,cAAV,EAAyB,EAAzB,CAAF,CAA+Bj2B,IAAEA,EAAEqc,OAAF,CAAU,SAAV,EAAoB,EAApB,CAAF,CAA0B,IAAIzc,IAAEmX,YAAY/W,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAGJ,EAAE4O,SAAF,KAAc,KAAK/N,CAAL,CAAO+N,SAAP,EAAjB,EAAoC;AAAC,WAAO,CAAP;AAAS,OAAIvO,IAAE,KAAKqY,QAAL,CAAc1Y,CAAd,CAAN,CAAuB,IAAIC,IAAEI,EAAEkB,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,QAAvB,EAAgC,EAAhC,CAAN,CAA0C,IAAIld,IAAEs3B,6CAA6C52B,CAA7C,CAAN,CAAsD,IAAGV,EAAEe,MAAF,IAAU,CAAb,EAAe;AAAC,WAAO,KAAP;AAAa,OAAIX,IAAEJ,EAAE,CAAF,CAAN,CAAW,IAAIC,IAAED,EAAE,CAAF,CAAN,CAAW,IAAIkB,IAAE,SAAFA,CAAE,CAASD,CAAT,EAAW;AAAC,WAAOiX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiT,UAAjB,CAA4BpqB,CAA5B,EAA8Bb,CAA9B,CAAP;AAAwC,GAA1D,CAA2D,IAAIO,IAAEO,EAAEhB,CAAF,CAAN,CAAW,OAAOD,KAAGU,CAAV;AAAa,CAAla,CAAma+X,OAAOrY,SAAP,CAAiBivB,qBAAjB,GAAuC,UAAS5uB,CAAT,EAAWQ,CAAX,EAAa;AAACA,MAAEA,EAAEgc,OAAF,CAAU4Z,cAAV,EAAyB,EAAzB,CAAF,CAA+B51B,IAAEA,EAAEgc,OAAF,CAAU,SAAV,EAAoB,EAApB,CAAF,CAA0B,IAAIzc,IAAEmX,YAAY1W,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAGT,EAAE4O,SAAF,KAAc,KAAK/N,CAAL,CAAO+N,SAAP,EAAjB,EAAoC;AAAC,WAAO,CAAP;AAAS,OAAIpP,IAAE,KAAKkZ,QAAL,CAAc1Y,CAAd,CAAN,CAAuB,IAAIT,IAAEC,EAAE+B,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,QAAvB,EAAgC,EAAhC,CAAN,CAA0C,IAAIvc,IAAE22B,6CAA6Ct3B,CAA7C,CAAN,CAAsD,IAAGW,EAAEI,MAAF,IAAU,CAAb,EAAe;AAAC,WAAO,KAAP;AAAa,OAAIX,IAAEO,EAAE,CAAF,CAAN,CAAW,IAAIT,IAAES,EAAE,CAAF,CAAN,CAAW,OAAOT,KAAGQ,CAAV;AAAa,CAA3W,CAA4WgY,OAAOrY,SAAP,CAAiBk3B,SAAjB,GAA2B,UAAS52B,CAAT,EAAWF,CAAX,EAAaS,CAAb,EAAehB,CAAf,EAAiB;AAAC,MAAIQ,IAAE,SAAFA,CAAE,CAASV,CAAT,EAAW;AAAC,WAAOkY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyBxY,CAAzB,EAA2BkB,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAId,IAAEM,EAAE+X,UAAU9X,CAAV,CAAF,CAAN,CAAsB,IAAGT,MAAIL,SAAP,EAAiB;AAACK,QAAE,CAAC,CAAH;AAAK,UAAO,KAAKmvB,wBAAL,CAA8BjvB,CAA9B,EAAgCK,CAAhC,EAAkCS,CAAlC,EAAoChB,CAApC,CAAP;AAA8C,CAAhM,CAAiMwY,OAAOrY,SAAP,CAAiBgvB,wBAAjB,GAA0C,UAASnvB,CAAT,EAAWuC,CAAX,EAAazB,CAAb,EAAeL,CAAf,EAAiB;AAAC,MAAIM,IAAE,IAAI4I,UAAJ,CAAepH,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAGxB,EAAEoO,SAAF,KAAc,KAAK/N,CAAL,CAAO+N,SAAP,EAAjB,EAAoC;AAAC,WAAO,KAAP;AAAa,OAAI1M,IAAE,SAAFA,CAAE,CAAS7B,CAAT,EAAW;AAAC,WAAOoX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyB1X,CAAzB,EAA2BE,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAIH,IAAE0X,UAAUrY,CAAV,CAAN,CAAmB,IAAID,IAAEY,EAAEE,MAAR,CAAe,IAAIf,IAAE,KAAKsB,CAAL,CAAO+N,SAAP,KAAmB,CAAzB,CAA2B,IAAIpM,IAAE0C,KAAK/C,IAAL,CAAU5C,IAAE,CAAZ,CAAN,CAAqB,IAAIwC,CAAJ,CAAM,IAAG7B,MAAI,CAAC,CAAL,IAAQA,MAAId,SAAf,EAAyB;AAACc,QAAEV,CAAF;AAAI,GAA9B,MAAkC;AAAC,QAAGU,MAAI,CAAC,CAAR,EAAU;AAACA,UAAEsC,IAAEhD,CAAF,GAAI,CAAN;AAAQ,KAAnB,MAAuB;AAAC,UAAGU,IAAE,CAAC,CAAN,EAAQ;AAAC,cAAK,qBAAL;AAA2B;AAAC;AAAC,OAAGsC,IAAGhD,IAAEU,CAAF,GAAI,CAAV,EAAa;AAAC,UAAK,eAAL;AAAqB,OAAIO,IAAE,KAAKiY,QAAL,CAAclY,CAAd,EAAiBoU,WAAjB,EAAN,CAAqC,KAAI7S,IAAE,CAAN,EAAQA,IAAEtB,EAAEH,MAAZ,EAAmByB,KAAG,CAAtB,EAAwB;AAACtB,MAAEsB,CAAF,KAAM,GAAN;AAAU,UAAMtB,EAAEH,MAAF,GAASkC,CAAf,EAAiB;AAAC/B,MAAEob,OAAF,CAAU,CAAV;AAAa,OAAGpb,EAAE+B,IAAE,CAAJ,MAAS,GAAZ,EAAgB;AAAC,UAAK,sCAAL;AAA4C,OAAEQ,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiCvC,CAAjC,CAAF,CAAsC,IAAId,IAAEc,EAAEqC,MAAF,CAAS,CAAT,EAAWN,IAAEhD,CAAF,GAAI,CAAf,CAAN,CAAwB,IAAIS,IAAEQ,EAAEqC,MAAF,CAASnD,EAAEW,MAAX,EAAkBd,CAAlB,CAAN,CAA2B,IAAIsB,IAAG,SAAQ,IAAE0B,CAAF,GAAIjD,CAAb,GAAiB,GAAvB,CAA2B,IAAG,CAACI,EAAEuD,UAAF,CAAa,CAAb,IAAgBpC,CAAjB,MAAsB,CAAzB,EAA2B;AAAC,UAAK,8BAAL;AAAoC,OAAID,IAAE41B,aAAax2B,CAAb,EAAeN,EAAEW,MAAjB,EAAwB4B,CAAxB,CAAN,CAAiC,IAAInB,IAAE,EAAN,CAAS,KAAIgB,IAAE,CAAN,EAAQA,IAAEpC,EAAEW,MAAZ,EAAmByB,KAAG,CAAtB,EAAwB;AAAChB,MAAEgB,CAAF,IAAKpC,EAAEuD,UAAF,CAAanB,CAAb,IAAgBlB,EAAEqC,UAAF,CAAanB,CAAb,CAArB;AAAqC,KAAE,CAAF,KAAM,CAACjB,CAAP,CAAS,IAAId,IAAEwC,IAAEhD,CAAF,GAAIU,CAAJ,GAAM,CAAZ,CAAc,KAAI6B,IAAE,CAAN,EAAQA,IAAE/B,CAAV,EAAY+B,KAAG,CAAf,EAAiB;AAAC,QAAGhB,EAAEgB,CAAF,MAAO,CAAV,EAAY;AAAC,YAAK,0BAAL;AAAgC;AAAC,OAAGhB,EAAEf,CAAF,MAAO,CAAV,EAAY;AAAC,UAAK,uBAAL;AAA6B,UAAOC,MAAI6X,UAAU5V,EAAE8V,UAAU,qCAAmC5X,CAAnC,GAAqC4C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiCjC,EAAEsB,KAAF,CAAQ,CAACnC,CAAT,CAAjC,CAA/C,CAAF,CAAV,CAAX;AAAuH,CAArlC,CAAslC+X,OAAO8e,aAAP,GAAqB,CAAC,CAAtB,CAAwB9e,OAAO+e,YAAP,GAAoB,CAAC,CAArB,CAAuB/e,OAAOgf,gBAAP,GAAwB,CAAC,CAAzB;AACzhJ,SAASnC,IAAT,GAAe;AAAC,MAAIt0B,IAAEqiB,OAAN;AAAA,MAAcziB,IAAEI,EAAE6iB,WAAlB;AAAA,MAA8B7jB,IAAEgB,EAAE0iB,IAAlC;AAAA,MAAuCljB,IAAEQ,EAAE2iB,MAA3C;AAAA,MAAkD1jB,IAAEe,EAAEijB,UAAtD;AAAA,MAAiEvjB,IAAEM,EAAEgjB,YAArE;AAAA,MAAkFjkB,IAAEiB,EAAE+iB,YAAtF;AAAA,MAAmG5jB,IAAEa,EAAEyiB,OAAvG;AAAA,MAA+G5iB,IAAEG,EAAEwjB,OAAnH;AAAA,MAA2HvjB,IAAEq0B,IAA7H;AAAA,MAAkI70B,IAAEylB,QAApI,CAA6I,KAAK7F,GAAL,GAAS,IAAT,CAAc,KAAK6S,OAAL,GAAa,CAAb,CAAe,KAAKwE,OAAL,GAAa,CAAb,CAAe,KAAKC,QAAL,GAAc,IAAd,CAAmB,KAAKC,UAAL,GAAgB,YAAU;AAAC,QAAG,KAAKvX,GAAL,KAAW,IAAX,IAAiB,KAAK6S,OAAL,KAAe,CAAnC,EAAqC;AAAC,aAAO,KAAKA,OAAZ;AAAoB,SAAGxyB,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,MAAsB,YAAzB,EAAsC;AAAC,WAAK6S,OAAL,GAAa,CAAb,CAAe,KAAKwE,OAAL,GAAa,CAAC,CAAd,CAAgB,OAAO,CAAP;AAAS,UAAKxE,OAAL,GAAa,CAAb,CAAe,OAAO,CAAP;AAAS,GAA5L,CAA6L,KAAK2E,kBAAL,GAAwB,YAAU;AAAC,WAAO53B,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAAhF,CAAiF,KAAKI,0BAAL,GAAgC,YAAU;AAAC,WAAOj3B,EAAEZ,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,EAAkB,CAAlB,CAAb,EAAkC,IAAlC,CAAF,CAAP;AAAkD,GAA7F,CAA8F,KAAKK,YAAL,GAAkB,YAAU;AAAC,WAAOr3B,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAA1E,CAA2E,KAAKM,eAAL,GAAqB,YAAU;AAAC,WAAO/2B,EAAEg3B,MAAF,CAAS,KAAKF,YAAL,EAAT,CAAP;AAAqC,GAArE,CAAsE,KAAKG,aAAL,GAAmB,YAAU;AAAC,WAAOx3B,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAA3E,CAA4E,KAAKS,gBAAL,GAAsB,YAAU;AAAC,WAAOl3B,EAAEg3B,MAAF,CAAS,KAAKC,aAAL,EAAT,CAAP;AAAsC,GAAvE,CAAwE,KAAKE,YAAL,GAAkB,YAAU;AAAC,QAAIr3B,IAAEd,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,EAAkB,CAAlB,CAAb,CAAN,CAAyC32B,IAAEA,EAAEkc,OAAF,CAAU,OAAV,EAAkB,KAAlB,CAAF,CAA2Blc,IAAE6C,mBAAmB7C,CAAnB,CAAF,CAAwB,OAAOA,CAAP;AAAS,GAAlI,CAAmI,KAAKs3B,WAAL,GAAiB,YAAU;AAAC,QAAIt3B,IAAEd,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,EAAkB,CAAlB,CAAb,CAAN,CAAyC32B,IAAEA,EAAEkc,OAAF,CAAU,OAAV,EAAkB,KAAlB,CAAF,CAA2Blc,IAAE6C,mBAAmB7C,CAAnB,CAAF,CAAwB,OAAOA,CAAP;AAAS,GAAjI,CAAkI,KAAK61B,eAAL,GAAqB,YAAU;AAAC,WAAO51B,EAAEgjB,YAAF,CAAe,KAAK3D,GAApB,EAAwB,CAAxB,EAA0B,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAA1B,EAA6C,IAA7C,CAAP;AAA0D,GAA1F,CAA2F,KAAKY,eAAL,GAAqB,YAAU;AAAC,WAAOv4B,EAAE,KAAKsgB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAA7E,CAA8E,KAAKa,sBAAL,GAA4B,YAAU;AAAC,QAAIx3B,IAAE,KAAKu3B,eAAL,EAAN,CAA6B,OAAOv4B,EAAE,KAAKsgB,GAAP,EAAWtf,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,EAAmB,IAAnB,CAAP;AAAgC,GAApG,CAAqG,KAAKy3B,YAAL,GAAkB,YAAU;AAAC,WAAOxK,QAAQC,MAAR,CAAe,KAAK2I,eAAL,EAAf,EAAsC,IAAtC,EAA2C,UAA3C,CAAP;AAA8D,GAA3F,CAA4F,KAAK6B,yBAAL,GAA+B,YAAU;AAAC,WAAO53B,EAAEZ,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,EAAmB,IAAnB,CAAF,CAAP;AAAmC,GAA7E,CAA8E,KAAKqY,oBAAL,GAA0B,YAAU;AAAC,WAAOz4B,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,CAAb,EAAiB,IAAjB,EAAsB,IAAtB,CAAP;AAAmC,GAAxE,CAAyE,KAAKsY,eAAL,GAAqB,UAASt3B,CAAT,EAAW;AAAC,QAAIE,IAAE,KAAKk3B,yBAAL,EAAN,CAAuC,IAAI13B,IAAE,KAAK23B,oBAAL,EAAN,CAAkC,IAAI11B,IAAEtC,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,CAAb,EAAiB,IAAjB,CAAN,CAA6B,IAAI/e,IAAE,IAAI2W,KAAKf,MAAL,CAAYyW,SAAhB,CAA0B,EAACtC,KAAI9pB,CAAL,EAA1B,CAAN,CAAyCD,EAAEI,IAAF,CAAOL,CAAP,EAAUC,EAAE+qB,SAAF,CAAYrpB,CAAZ,EAAe,OAAO1B,EAAE2tB,MAAF,CAASluB,CAAT,CAAP;AAAmB,GAA5N,CAA6N,KAAK63B,QAAL,GAAc,YAAU;AAAC,QAAG,KAAK1F,OAAL,KAAe,CAAlB,EAAoB;AAAC,aAAO,CAAC,CAAR;AAAU,SAAI5xB,IAAEvB,EAAE,KAAKsgB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAb,EAAqB,IAArB,CAAN,CAAiC,IAAIrd,IAAEpC,EAAE,KAAKyf,GAAP,EAAW/e,CAAX,CAAN,CAAoB,KAAKq2B,QAAL,GAAc,IAAInuB,KAAJ,EAAd,CAA0B,KAAI,IAAInI,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAIkB,IAAE,EAAN,CAASA,EAAEs2B,QAAF,GAAW,KAAX,CAAiB,IAAI93B,IAAEH,EAAE,KAAKyf,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,CAAN,CAAuB,IAAIqB,IAAE,CAAN,CAAQ,IAAG3B,EAAED,MAAF,KAAW,CAAd,EAAgB;AAACyB,UAAEs2B,QAAF,GAAW,IAAX,CAAgBn2B,IAAE,CAAF;AAAI,SAAEggB,GAAF,GAAM1hB,EAAEkjB,WAAF,CAAcjkB,EAAE,KAAKogB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,CAAD,CAAhB,EAAoB,IAApB,CAAd,CAAN,CAA+C,IAAIE,IAAExB,EAAE,KAAKsgB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,IAAEqB,CAAH,CAAhB,CAAN,CAA6BH,EAAEu2B,IAAF,GAAO34B,EAAE,KAAKkgB,GAAP,EAAW9e,CAAX,CAAP,CAAqB,KAAKo2B,QAAL,CAAc50B,IAAd,CAAmBR,CAAnB;AAAsB;AAAC,GAAzX,CAA0X,KAAKw2B,UAAL,GAAgB,UAAS13B,CAAT,EAAW;AAAC,QAAIN,IAAE,KAAK42B,QAAX,CAAoB,IAAIp2B,IAAEF,CAAN,CAAQ,IAAG,CAACA,EAAE2b,KAAF,CAAQ,WAAR,CAAJ,EAAyB;AAACzb,UAAE0W,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmBC,QAAnB,CAA4BphB,CAA5B,CAAF;AAAiC,SAAGE,MAAI,EAAP,EAAU;AAAC,aAAO3B,SAAP;AAAiB,UAAI,IAAIoD,IAAE,CAAV,EAAYA,IAAEjC,EAAED,MAAhB,EAAuBkC,GAAvB,EAA2B;AAAC,UAAGjC,EAAEiC,CAAF,EAAK0f,GAAL,KAAWnhB,CAAd,EAAgB;AAAC,eAAOR,EAAEiC,CAAF,CAAP;AAAY;AAAC,YAAOpD,SAAP;AAAiB,GAA1N,CAA2N,KAAKo5B,sBAAL,GAA4B,YAAU;AAAC,QAAI33B,IAAE,KAAK03B,UAAL,CAAgB,kBAAhB,CAAN,CAA0C,IAAG13B,MAAIzB,SAAP,EAAiB;AAAC,aAAOyB,CAAP;AAAS,SAAIN,IAAEf,EAAE,KAAKqgB,GAAP,EAAWhf,EAAEy3B,IAAb,CAAN,CAAyB,IAAG/3B,MAAI,EAAP,EAAU;AAAC,aAAM,EAAN;AAAS,SAAGA,MAAI,QAAP,EAAgB;AAAC,aAAM,EAACk4B,IAAG,IAAJ,EAAN;AAAgB,SAAGl4B,EAAEuC,MAAF,CAAS,CAAT,EAAW,CAAX,MAAgB,UAAnB,EAA8B;AAAC,UAAI/B,IAAEvB,EAAEe,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAIiC,IAAEK,SAAS9B,CAAT,EAAW,EAAX,CAAN,CAAqB,OAAM,EAAC03B,IAAG,IAAJ,EAASC,SAAQl2B,CAAjB,EAAN;AAA0B,WAAK,8BAAL;AAAoC,GAAzT,CAA0T,KAAKm2B,iBAAL,GAAuB,YAAU;AAAC,QAAI53B,IAAE,KAAKw3B,UAAL,CAAgB,UAAhB,CAAN,CAAkC,IAAGx3B,MAAI3B,SAAP,EAAiB;AAAC,aAAM,EAAN;AAAS,SAAIoD,IAAEhD,EAAE,KAAKqgB,GAAP,EAAW9e,EAAEu3B,IAAb,CAAN,CAAyB,IAAG91B,EAAElC,MAAF,GAAS,CAAT,IAAY,CAAZ,IAAekC,EAAElC,MAAF,IAAU,CAA5B,EAA8B;AAAC,YAAK,2BAAL;AAAiC,SAAIC,IAAEsC,SAASL,EAAEM,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,CAAN,CAA8B,IAAIjC,IAAEgC,SAASL,EAAEM,MAAF,CAAS,CAAT,CAAT,EAAqB,EAArB,EAAyBvB,QAAzB,CAAkC,CAAlC,CAAN,CAA2C,OAAOV,EAAEiC,MAAF,CAAS,CAAT,EAAWjC,EAAEP,MAAF,GAASC,CAApB,CAAP;AAA8B,GAA/R,CAAgS,KAAKq4B,oBAAL,GAA0B,YAAU;AAAC,QAAI/3B,IAAE,KAAK83B,iBAAL,EAAN,CAA+B,IAAIp4B,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,KAAI,IAAIxG,IAAE,CAAV,EAAYA,IAAE3B,EAAEP,MAAhB,EAAuBkC,GAAvB,EAA2B;AAAC,UAAG3B,EAAEiC,MAAF,CAASN,CAAT,EAAW,CAAX,KAAe,GAAlB,EAAsB;AAACjC,UAAEgC,IAAF,CAAOuyB,KAAK+D,aAAL,CAAmBr2B,CAAnB,CAAP;AAA8B;AAAC,YAAOjC,EAAEoC,IAAF,CAAO,GAAP,CAAP;AAAmB,GAA3L,CAA4L,KAAKm2B,0BAAL,GAAgC,YAAU;AAAC,QAAIv4B,IAAE,KAAKg4B,UAAL,CAAgB,sBAAhB,CAAN,CAA8C,IAAGh4B,MAAInB,SAAP,EAAiB;AAAC,aAAOmB,CAAP;AAAS,YAAOf,EAAE,KAAKqgB,GAAP,EAAWtf,EAAE+3B,IAAb,CAAP;AAA0B,GAA9I,CAA+I,KAAKS,4BAAL,GAAkC,YAAU;AAAC,QAAIj4B,IAAE,KAAKy3B,UAAL,CAAgB,wBAAhB,CAAN,CAAgD,IAAGz3B,MAAI1B,SAAP,EAAiB;AAAC,aAAO0B,CAAP;AAAS,SAAIP,IAAE,EAAN,CAAS,IAAIQ,IAAEf,EAAE,KAAK6f,GAAP,EAAW/e,EAAEw3B,IAAb,CAAN,CAAyB,IAAI91B,IAAEpC,EAAEW,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAGE,EAAE+B,MAAF,CAASN,EAAE3B,CAAF,CAAT,EAAc,CAAd,MAAmB,IAAtB,EAA2B;AAACN,UAAEy4B,GAAF,GAAMx5B,EAAEuB,CAAF,EAAIyB,EAAE3B,CAAF,CAAJ,CAAN;AAAgB;AAAC,YAAON,CAAP;AAAS,GAAzP,CAA0P,KAAK04B,qBAAL,GAA2B,YAAU;AAAC,QAAIn4B,IAAE,KAAKy3B,UAAL,CAAgB,aAAhB,CAAN,CAAqC,IAAGz3B,MAAI1B,SAAP,EAAiB;AAAC,aAAO0B,CAAP;AAAS,SAAIP,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,IAAIjI,IAAEf,EAAE,KAAK6f,GAAP,EAAW/e,EAAEw3B,IAAb,CAAN,CAAyB,IAAGv3B,MAAI,EAAP,EAAU;AAAC,aAAOR,CAAP;AAAS,SAAIiC,IAAEpC,EAAEW,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAACN,QAAEgC,IAAF,CAAOlC,EAAEb,EAAEuB,CAAF,EAAIyB,EAAE3B,CAAF,CAAJ,CAAF,CAAP;AAAqB,YAAON,CAAP;AAAS,GAA5O,CAA6O,KAAK24B,oBAAL,GAA0B,YAAU;AAAC,QAAI12B,IAAE,KAAK22B,qBAAL,EAAN,CAAmC,IAAI54B,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,KAAI,IAAInI,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAG2B,EAAE3B,CAAF,EAAK,CAAL,MAAU,KAAb,EAAmB;AAACN,UAAEgC,IAAF,CAAOC,EAAE3B,CAAF,EAAK,CAAL,CAAP;AAAgB;AAAC,YAAON,CAAP;AAAS,GAApK,CAAqK,KAAK44B,qBAAL,GAA2B,YAAU;AAAC,QAAIr4B,CAAJ,EAAMkB,CAAN,EAAQE,CAAR,CAAU,IAAIH,IAAE,KAAKw2B,UAAL,CAAgB,gBAAhB,CAAN,CAAwC,IAAGx2B,MAAI3C,SAAP,EAAiB;AAAC,aAAO2C,CAAP;AAAS,SAAIxB,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,IAAIjI,IAAEf,EAAE,KAAK6f,GAAP,EAAW9d,EAAEu2B,IAAb,CAAN,CAAyB,IAAI91B,IAAEpC,EAAEW,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAACqB,UAAEnB,EAAE+B,MAAF,CAASN,EAAE3B,CAAF,CAAT,EAAc,CAAd,CAAF,CAAmBC,IAAEtB,EAAEuB,CAAF,EAAIyB,EAAE3B,CAAF,CAAJ,CAAF,CAAY,IAAGqB,MAAI,IAAP,EAAY;AAACF,YAAE+hB,UAAUjjB,CAAV,CAAF,CAAeP,EAAEgC,IAAF,CAAO,CAAC,MAAD,EAAQP,CAAR,CAAP;AAAmB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAE+hB,UAAUjjB,CAAV,CAAF,CAAeP,EAAEgC,IAAF,CAAO,CAAC,KAAD,EAAOP,CAAP,CAAP;AAAkB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAE8yB,KAAK2C,MAAL,CAAY32B,CAAZ,EAAc,CAAd,CAAF,CAAmBP,EAAEgC,IAAF,CAAO,CAAC,IAAD,EAAMP,CAAN,CAAP;AAAiB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAE+hB,UAAUjjB,CAAV,CAAF,CAAeP,EAAEgC,IAAF,CAAO,CAAC,KAAD,EAAOP,CAAP,CAAP;AAAkB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAEglB,QAAQlmB,CAAR,CAAF,CAAaP,EAAEgC,IAAF,CAAO,CAAC,IAAD,EAAMP,CAAN,CAAP;AAAiB;AAAC,YAAOzB,CAAP;AAAS,GAAvd,CAAwd,KAAK64B,8BAAL,GAAoC,YAAU;AAAC,QAAIr3B,IAAE,KAAKw2B,UAAL,CAAgB,uBAAhB,CAAN,CAA+C,IAAGx2B,MAAI3C,SAAP,EAAiB;AAAC,aAAO2C,CAAP;AAAS,SAAIxB,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,IAAIxG,IAAEpC,EAAE,KAAKyf,GAAP,EAAW9d,EAAEu2B,IAAb,CAAN,CAAyB,KAAI,IAAIv3B,IAAE,CAAV,EAAYA,IAAEyB,EAAElC,MAAhB,EAAuBS,GAAvB,EAA2B;AAAC,UAAG;AAAC,YAAImB,IAAEzC,EAAE,KAAKogB,GAAP,EAAWrd,EAAEzB,CAAF,CAAX,EAAgB,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAhB,EAAwB,IAAxB,CAAN,CAAoC,IAAID,IAAEijB,UAAU7hB,CAAV,CAAN,CAAmB3B,EAAEgC,IAAF,CAAOzB,CAAP;AAAU,OAArE,CAAqE,OAAMD,CAAN,EAAQ,CAAE;AAAC,YAAON,CAAP;AAAS,GAAzR,CAA0R,KAAK84B,aAAL,GAAmB,YAAU;AAAC,QAAIv4B,IAAE,KAAKy3B,UAAL,CAAgB,qBAAhB,CAAN,CAA6C,IAAGz3B,MAAI1B,SAAP,EAAiB;AAAC,aAAO0B,CAAP;AAAS,SAAIP,IAAE,EAAC+4B,MAAK,EAAN,EAASC,UAAS,EAAlB,EAAN,CAA4B,IAAI/2B,IAAEpC,EAAE,KAAKyf,GAAP,EAAW/e,EAAEw3B,IAAb,CAAN,CAAyB,KAAI,IAAIz3B,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAIkB,IAAEtC,EAAE,KAAKogB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,CAAD,CAAhB,EAAoB,IAApB,CAAN,CAAgC,IAAIE,IAAEtB,EAAE,KAAKogB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,CAAD,CAAhB,EAAoB,IAApB,CAAN,CAAgC,IAAGkB,MAAI,kBAAP,EAA0B;AAACxB,UAAE+4B,IAAF,CAAO/2B,IAAP,CAAYwhB,UAAUhjB,CAAV,CAAZ;AAA0B,WAAGgB,MAAI,kBAAP,EAA0B;AAACxB,UAAEg5B,QAAF,CAAWh3B,IAAX,CAAgBwhB,UAAUhjB,CAAV,CAAhB;AAA8B;AAAC,YAAOR,CAAP;AAAS,GAA/W,CAAgX,KAAKi5B,yBAAL,GAA+B,YAAU;AAAC,QAAIz4B,IAAE,KAAKw3B,UAAL,CAAgB,qBAAhB,CAAN,CAA6C,IAAGx3B,MAAI3B,SAAP,EAAiB;AAAC,aAAO2B,CAAP;AAAS,SAAIR,IAAEP,EAAE,KAAK6f,GAAP,EAAW9e,EAAEu3B,IAAb,CAAN,CAAyB,IAAIp0B,IAAE,EAAN,CAAS,IAAIlC,IAAE5B,EAAEG,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAI2B,IAAE,CAAV,EAAYA,IAAEF,EAAE1B,MAAhB,EAAuB4B,GAAvB,EAA2B;AAAC,UAAIJ,IAAE,EAAN,CAAS,IAAIjB,IAAET,EAAEG,CAAF,EAAIyB,EAAEE,CAAF,CAAJ,CAAN,CAAgBJ,EAAE23B,EAAF,GAAKp5B,EAAEb,EAAEe,CAAF,EAAIM,EAAE,CAAF,CAAJ,CAAF,CAAL,CAAkB,IAAGA,EAAEP,MAAF,KAAW,CAAd,EAAgB;AAAC,YAAIkC,IAAEpC,EAAEG,CAAF,EAAIM,EAAE,CAAF,CAAJ,CAAN,CAAgB,KAAI,IAAIkB,IAAE,CAAV,EAAYA,IAAES,EAAElC,MAAhB,EAAuByB,GAAvB,EAA2B;AAAC,cAAIjB,IAAErB,EAAEc,CAAF,EAAIiC,EAAET,CAAF,CAAJ,EAAS,CAAC,CAAD,CAAT,EAAa,IAAb,CAAN,CAAyB,IAAGjB,MAAI,kBAAP,EAA0B;AAACgB,cAAE43B,GAAF,GAAM3V,UAAUtkB,EAAEc,CAAF,EAAIiC,EAAET,CAAF,CAAJ,EAAS,CAAC,CAAD,CAAT,CAAV,CAAN;AAA+B,WAA1D,MAA8D;AAAC,gBAAGjB,MAAI,kBAAP,EAA0B;AAACgB,gBAAE63B,OAAF,GAAU5V,UAAUtkB,EAAEc,CAAF,EAAIiC,EAAET,CAAF,CAAJ,EAAS,CAAC,CAAD,EAAG,CAAH,CAAT,CAAV,CAAV;AAAqC;AAAC;AAAC;AAAC,SAAEQ,IAAF,CAAOT,CAAP;AAAU,YAAOoC,CAAP;AAAS,GAAnd,CAAod,KAAK01B,WAAL,GAAiB,UAASr5B,CAAT,EAAW;AAAC,SAAK41B,WAAL,CAAiBl2B,EAAEM,CAAF,CAAjB;AAAuB,GAApD,CAAqD,KAAK41B,WAAL,GAAiB,UAAS51B,CAAT,EAAW;AAAC,SAAKsf,GAAL,GAAStf,CAAT,CAAW,KAAK62B,UAAL,GAAkB,IAAG;AAAC73B,QAAE,KAAKsgB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,EAAmB,IAAnB,EAAyB,KAAKuY,QAAL;AAAgB,KAA7C,CAA6C,OAAM51B,CAAN,EAAQ,CAAE;AAAC,GAAlH,CAAmH,KAAKq3B,OAAL,GAAa,YAAU;AAAC,QAAIr3B,IAAEsyB,IAAN,CAAW,IAAIltB,CAAJ,EAAM1D,CAAN,EAAQsD,CAAR,CAAUI,IAAE,gBAAF,CAAmBA,KAAG,sBAAoB,KAAKyvB,kBAAL,EAApB,GAA8C,IAAjD,CAAsDzvB,KAAG,4BAA0B,KAAK0vB,0BAAL,EAA1B,GAA4D,IAA/D,CAAoE1vB,KAAG,eAAa,KAAK4vB,eAAL,EAAb,GAAoC,IAAvC,CAA4C5vB,KAAG,kBAAgB,KAAKgwB,YAAL,EAAhB,GAAoC,IAAvC,CAA4ChwB,KAAG,iBAAe,KAAKiwB,WAAL,EAAf,GAAkC,IAArC,CAA0CjwB,KAAG,gBAAc,KAAK+vB,gBAAL,EAAd,GAAsC,IAAzC,CAA8C/vB,KAAG,+BAAH,CAAmC1D,IAAE,KAAK8zB,YAAL,EAAF,CAAsBpwB,KAAG,wBAAsB1D,EAAE6U,IAAxB,GAA6B,IAAhC,CAAqC,IAAG7U,EAAE6U,IAAF,KAAS,KAAZ,EAAkB;AAACnR,WAAG,WAAS4f,YAAYtjB,EAAErD,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAZ,EAA8BuB,MAA9B,CAAqC,CAArC,EAAuC,EAAvC,CAAT,GAAoD,OAAvD,CAA+D8E,KAAG,WAAS4f,YAAYtjB,EAAEjE,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAZ,CAAT,GAAuC,IAA1C;AAA+C,SAAE,KAAK41B,QAAP,CAAgB,IAAG3vB,MAAIpI,SAAJ,IAAeoI,MAAI,IAAtB,EAA2B;AAACI,WAAG,sBAAH,CAA0B,KAAI,IAAI1F,IAAE,CAAV,EAAYA,IAAEsF,EAAElH,MAAhB,EAAuB4B,GAAvB,EAA2B;AAAC,YAAIrB,IAAE2G,EAAEtF,CAAF,CAAN,CAAW,IAAIuF,IAAEgQ,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmB8B,QAAnB,CAA4BjjB,EAAEqhB,GAA9B,CAAN,CAAyC,IAAGza,MAAI,EAAP,EAAU;AAACA,cAAE5G,EAAEqhB,GAAJ;AAAQ,aAAIne,IAAE,EAAN,CAAS,IAAGlD,EAAEw3B,QAAF,KAAa,IAAhB,EAAqB;AAACt0B,cAAE,UAAF;AAAa,cAAG,OAAK0D,CAAL,GAAO,GAAP,GAAW1D,CAAX,GAAa,KAAhB,CAAsB,IAAG0D,MAAI,kBAAP,EAA0B;AAAC,cAAIxD,IAAE,KAAKu0B,sBAAL,EAAN,CAAoC,IAAGv0B,EAAEw0B,EAAF,KAAOr5B,SAAV,EAAoB;AAACwI,iBAAG,UAAH;AAAc,WAAnC,MAAuC;AAACA,iBAAG,aAAH,CAAiB,IAAG3D,EAAEy0B,OAAF,KAAYt5B,SAAf,EAAyB;AAACwI,mBAAG,eAAa3D,EAAEy0B,OAAlB;AAA0B,kBAAG,IAAH;AAAQ;AAAC,SAArL,MAAyL;AAAC,cAAGjxB,MAAI,UAAP,EAAkB;AAACG,iBAAG,SAAO,KAAKgxB,oBAAL,EAAP,GAAmC,IAAtC;AAA2C,WAA9D,MAAkE;AAAC,gBAAGnxB,MAAI,sBAAP,EAA8B;AAACG,mBAAG,SAAO,KAAKkxB,0BAAL,EAAP,GAAyC,IAA5C;AAAiD,aAAhF,MAAoF;AAAC,kBAAGrxB,MAAI,wBAAP,EAAgC;AAAC,oBAAIlH,IAAE,KAAKw4B,4BAAL,EAAN,CAA0C,IAAGx4B,EAAEy4B,GAAF,KAAQ55B,SAAX,EAAqB;AAACwI,uBAAG,aAAWrH,EAAEy4B,GAAb,GAAiB,IAApB;AAAyB;AAAC,eAA3H,MAA+H;AAAC,oBAAGvxB,MAAI,aAAP,EAAqB;AAAC,sBAAI3D,IAAE,KAAKm1B,qBAAL,EAAN,CAAmCrxB,KAAG,SAAO9D,EAAEnB,IAAF,CAAO,IAAP,CAAP,GAAoB,IAAvB;AAA4B,iBAArF,MAAyF;AAAC,sBAAG8E,MAAI,gBAAP,EAAwB;AAAC,wBAAI3F,IAAE,KAAKq3B,qBAAL,EAAN,CAAmCvxB,KAAG,SAAO9F,CAAP,GAAS,IAAZ;AAAiB,mBAA7E,MAAiF;AAAC,wBAAG2F,MAAI,uBAAP,EAA+B;AAAC,0BAAIC,IAAE,KAAK0xB,8BAAL,EAAN,CAA4CxxB,KAAG,SAAOF,CAAP,GAAS,IAAZ;AAAiB,qBAA7F,MAAiG;AAAC,0BAAGD,MAAI,qBAAP,EAA6B;AAAC,4BAAI3G,IAAE,KAAKu4B,aAAL,EAAN,CAA2B,IAAGv4B,EAAEw4B,IAAF,KAASl6B,SAAZ,EAAsB;AAACwI,+BAAG,eAAa9G,EAAEw4B,IAAF,CAAO32B,IAAP,CAAY,GAAZ,CAAb,GAA8B,IAAjC;AAAsC,6BAAG7B,EAAEy4B,QAAF,KAAan6B,SAAhB,EAA0B;AAACwI,+BAAG,mBAAiB9G,EAAEy4B,QAAF,CAAW52B,IAAX,CAAgB,GAAhB,CAAjB,GAAsC,IAAzC;AAA8C;AAAC,uBAAhM,MAAoM;AAAC,4BAAG8E,MAAI,qBAAP,EAA6B;AAAC,8BAAI1G,IAAE,KAAKy4B,yBAAL,EAAN,CAAuC,KAAI,IAAIz3B,IAAE,CAAV,EAAYA,IAAEhB,EAAET,MAAhB,EAAuByB,GAAvB,EAA2B;AAAC,gCAAGhB,EAAEgB,CAAF,EAAK03B,EAAL,KAAUr6B,SAAb,EAAuB;AAACwI,mCAAG,qBAAmB7G,EAAEgB,CAAF,EAAK03B,EAAxB,GAA2B,IAA9B;AAAmC,iCAAG14B,EAAEgB,CAAF,EAAK23B,GAAL,KAAWt6B,SAAd,EAAwB;AAACwI,mCAAG,cAAY7G,EAAEgB,CAAF,EAAK23B,GAAjB,GAAqB,IAAxB;AAA6B;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC,UAAG,0BAAwB,KAAKzB,yBAAL,EAAxB,GAAyD,IAA5D,CAAiErwB,KAAG,gBAAc,KAAKswB,oBAAL,GAA4Bp1B,MAA5B,CAAmC,CAAnC,EAAqC,EAArC,CAAd,GAAuD,OAA1D,CAAkE,OAAO8E,CAAP;AAAS,GAAnkE;AAAokE,MAAK6vB,MAAL,GAAY,UAASh4B,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAGA,MAAIZ,SAAP,EAAiB;AAACY,QAAE,CAAF;AAAI,OAAGP,EAAEqD,MAAF,CAAS9C,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,UAAK,cAAL;AAAoB,OAAIE,IAAE,IAAI8I,KAAJ,EAAN,CAAkB,IAAIrJ,IAAEkjB,QAAQQ,WAAR,CAAoB5jB,CAApB,EAAsBO,CAAtB,CAAN,CAA+B,KAAI,IAAIC,IAAE,CAAV,EAAYA,IAAEN,EAAEW,MAAhB,EAAuBL,GAAvB,EAA2B;AAACC,MAAEqC,IAAF,CAAOuyB,KAAKgF,OAAL,CAAar6B,CAAb,EAAeE,EAAEM,CAAF,CAAf,CAAP;AAA6B,OAAEC,EAAEwnB,GAAF,CAAM,UAASjnB,CAAT,EAAW;AAAC,WAAOA,EAAEgc,OAAF,CAAU,GAAV,EAAc,KAAd,CAAP;AAA4B,GAA9C,CAAF,CAAkD,OAAM,MAAIvc,EAAEyC,IAAF,CAAO,GAAP,CAAV;AAAsB,CAA/Q,CAAgRmyB,KAAKgF,OAAL,GAAa,UAASr6B,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAGA,MAAIZ,SAAP,EAAiB;AAACY,QAAE,CAAF;AAAI,OAAGP,EAAEqD,MAAF,CAAS9C,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,UAAK,eAAL;AAAqB,OAAIE,IAAE,IAAI8I,KAAJ,EAAN,CAAkB,IAAIrJ,IAAEkjB,QAAQQ,WAAR,CAAoB5jB,CAApB,EAAsBO,CAAtB,CAAN,CAA+B,KAAI,IAAIC,IAAE,CAAV,EAAYA,IAAEN,EAAEW,MAAhB,EAAuBL,GAAvB,EAA2B;AAACC,MAAEqC,IAAF,CAAOuyB,KAAKiF,iBAAL,CAAuBt6B,CAAvB,EAAyBE,EAAEM,CAAF,CAAzB,CAAP;AAAuC,OAAEC,EAAEwnB,GAAF,CAAM,UAASjnB,CAAT,EAAW;AAAC,WAAOA,EAAEgc,OAAF,CAAU,GAAV,EAAc,KAAd,CAAP;AAA4B,GAA9C,CAAF,CAAkD,OAAOvc,EAAEyC,IAAF,CAAO,GAAP,CAAP;AAAmB,CAAxR,CAAyRmyB,KAAKiF,iBAAL,GAAuB,UAASp6B,CAAT,EAAWU,CAAX,EAAa;AAAC,MAAID,IAAEyiB,OAAN,CAAc,IAAIrjB,IAAEY,EAAE8iB,IAAR,CAAa,IAAG7iB,MAAIjB,SAAP,EAAiB;AAACiB,QAAE,CAAF;AAAI,OAAGV,EAAEmD,MAAF,CAASzC,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,UAAK,oCAAL;AAA0C,OAAId,IAAEa,EAAEijB,WAAF,CAAc1jB,CAAd,EAAgBU,CAAhB,CAAN,CAAyB,IAAGd,EAAEe,MAAF,KAAW,CAAX,IAAcX,EAAEmD,MAAF,CAASvD,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAApC,EAAyC;AAAC;AAAqC,OAAIS,IAAER,EAAEG,CAAF,EAAIJ,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIE,IAAEgY,KAAKkF,IAAL,CAAUC,QAAV,CAAmB8B,WAAnB,CAA+B1e,CAA/B,CAAN,CAAwC,IAAIC,IAAEwX,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmBgY,SAAnB,CAA6Bv6B,CAA7B,CAAN,CAAsC,IAAIgB,IAAEjB,EAAEG,CAAF,EAAIJ,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIW,IAAE4X,UAAUrX,CAAV,CAAN,CAAmB,OAAOR,IAAE,GAAF,GAAMC,CAAb;AAAe,CAAjZ,CAAkZ40B,KAAKC,uBAAL,GAA6B,UAAS/0B,CAAT,EAAW;AAAC,MAAIS,IAAE,IAAIq0B,IAAJ,EAAN,CAAiBr0B,EAAE01B,WAAF,CAAcn2B,CAAd,EAAiB,OAAOS,EAAEu3B,YAAF,EAAP;AAAwB,CAAnG,CAAoGlD,KAAKE,uBAAL,GAA6B,UAASh1B,CAAT,EAAW;AAAC,MAAIS,IAAE,IAAIq0B,IAAJ,EAAN,CAAiBr0B,EAAEm5B,WAAF,CAAc55B,CAAd,EAAiB,OAAOS,EAAEu3B,YAAF,EAAP;AAAwB,CAAnG,CAAoGlD,KAAKmF,6BAAL,GAAmC,UAAS/5B,CAAT,EAAW;AAAC,MAAID,IAAE4iB,OAAN,CAAc,IAAItjB,IAAEU,EAAEwjB,UAAR,CAAmB,IAAIzjB,IAAE,EAAN,CAAS,IAAIS,CAAJ,EAAMhB,CAAN,EAAQE,CAAR,CAAUK,EAAE8zB,QAAF,GAAW,IAAX,CAAgBrzB,IAAE,IAAIq0B,IAAJ,EAAF,CAAar0B,EAAEm5B,WAAF,CAAc15B,CAAd,EAAiBT,IAAEgB,EAAE21B,eAAF,EAAF,CAAsBp2B,EAAEwyB,MAAF,GAASjzB,EAAEE,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,EAAgBqD,MAAhB,CAAuB,CAAvB,CAAT,CAAmC9C,EAAE+zB,MAAF,GAASx0B,EAAEE,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAT,CAA2B,IAAGO,EAAE+zB,MAAF,KAAW,gBAAd,EAA+B;AAAC/zB,MAAE8zB,QAAF,GAAWv0B,EAAEE,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAX;AAA6B,UAAOO,CAAP;AAAS,CAA3S,CAA4S80B,KAAK+D,aAAL,GAAmB,CAAC,kBAAD,EAAoB,gBAApB,EAAqC,iBAArC,EAAuD,kBAAvD,EAA0E,cAA1E,EAAyF,aAAzF,EAAuG,SAAvG,EAAiH,cAAjH,EAAgI,cAAhI,CAAnB;AACvqS,IAAG,OAAOphB,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UAmE3BA,IAnE2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKyiB,GAAZ,IAAiB,WAAjB,IAA8B,CAACziB,KAAKyiB,GAAvC,EAA2C;AAACziB,OAAKyiB,GAAL,GAAS,EAAT;AAAY,MAAKA,GAAL,CAASC,GAAT,GAAa,YAAU;AAAC,MAAIn6B,IAAEyX,IAAN;AAAA,MAAWhX,IAAET,EAAEk6B,GAAF,CAAMC,GAAnB;AAAA,MAAuBj6B,IAAEO,EAAE25B,gBAA3B,CAA4C,KAAKC,QAAL,GAAc,UAAS96B,CAAT,EAAWa,CAAX,EAAa;AAAC,QAAI,KAAKk6B,SAAL,KAAiBl7B,SAAlB,KAA+BgB,KAAI,KAAKk6B,SAAL,CAAeC,OAAf,KAAyBn7B,SAA5D,CAAH,EAA2E;AAAC;AAAO,SAAIiB,IAAEd,EAAEid,KAAF,CAAQ,6BAAR,CAAN,CAA6C,IAAGnc,KAAG,IAAN,EAAW;AAAC,YAAK,yDAAL;AAA+D,SAAIG,IAAEH,EAAE,CAAF,CAAN,CAAW,IAAIJ,IAAEI,EAAE,CAAF,CAAN,CAAW,IAAIE,IAAEF,EAAE,CAAF,CAAN,CAAW,IAAIQ,IAAEL,IAAE,GAAF,GAAMP,CAAZ,CAAc,KAAKq6B,SAAL,GAAe,EAAf,CAAkB,KAAKA,SAAL,CAAeE,QAAf,GAAwBh6B,CAAxB,CAA0B,KAAK85B,SAAL,CAAeG,WAAf,GAA2Bx6B,CAA3B,CAA6B,KAAKq6B,SAAL,CAAeI,UAAf,GAA0Bn6B,CAA1B,CAA4B,KAAK+5B,SAAL,CAAeK,EAAf,GAAkB95B,CAAlB,CAAoB,IAAG,CAACT,CAAJ,EAAM;AAAC,UAAIZ,IAAEslB,UAAUvkB,CAAV,CAAN,CAAmB,IAAId,IAAE0X,YAAY3X,CAAZ,EAAc,EAAd,CAAN,CAAwB,KAAK86B,SAAL,CAAeC,OAAf,GAAuB/6B,CAAvB,CAAyB,KAAK86B,SAAL,CAAeM,QAAf,GAAwBn7B,CAAxB;AAA0B,SAAIE,IAAEqlB,WAAWxkB,CAAX,CAAN,CAAoB,IAAIgC,IAAEwiB,WAAW/kB,CAAX,CAAN,CAAoB,KAAKq6B,SAAL,CAAeO,KAAf,GAAqBl7B,CAArB,CAAuB,KAAK26B,SAAL,CAAeQ,QAAf,GAAwBt4B,CAAxB,CAA0B,IAAG,CAACtC,EAAEP,CAAF,EAAI,KAAK26B,SAAT,EAAmB,OAAnB,CAAJ,EAAgC;AAAC,YAAK,yCAAuC36B,CAA5C;AAA8C;AAAC,GAA7pB;AAA8pB,CAAluB,CAAmuB8X,KAAKyiB,GAAL,CAASC,GAAT,CAAatM,IAAb,GAAkB,UAASxtB,CAAT,EAAW4D,CAAX,EAAayD,CAAb,EAAeF,CAAf,EAAiB/G,CAAjB,EAAmB;AAAC,MAAIqD,IAAE2T,IAAN;AAAA,MAAWjV,IAAEsB,EAAEo2B,GAAf;AAAA,MAAmBn4B,IAAES,EAAE23B,GAAvB;AAAA,MAA2B56B,IAAEwC,EAAEg5B,kBAA/B;AAAA,MAAkDj6B,IAAEiB,EAAEq4B,gBAAtD;AAAA,MAAuEz6B,IAAEmE,EAAE4S,MAA3E;AAAA,MAAkFlW,IAAEb,EAAEsuB,KAAtF;AAAA,MAA4FltB,IAAEpB,EAAE4sB,GAAhG;AAAA,MAAoGrsB,IAAEP,EAAEwtB,SAAxG;AAAA,MAAkHrrB,IAAEmiB,IAApH,CAAyH,IAAIjiB,CAAJ,EAAM5B,CAAN,EAAQS,CAAR,CAAU,IAAG,OAAOoD,CAAP,IAAU,QAAV,IAAoB,QAAOA,CAAP,yCAAOA,CAAP,MAAU,QAAjC,EAA0C;AAAC,UAAK,6CAA2CA,CAAhD;AAAkD,OAAG,QAAOA,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC7D,QAAE6D,CAAF,CAAIjC,IAAEF,EAAEF,SAAF,CAAYxB,CAAZ,CAAF;AAAiB,OAAG,OAAO6D,CAAP,IAAU,QAAb,EAAsB;AAACjC,QAAEiC,CAAF,CAAI,IAAG,CAACnD,EAAEkB,CAAF,CAAJ,EAAS;AAAC,YAAK,uCAAqCA,CAA1C;AAA4C,SAAEzC,EAAEyC,CAAF,CAAF;AAAO,OAAE0F,CAAF,CAAI,IAAG,QAAOA,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC7G,QAAEiB,EAAEF,SAAF,CAAY8F,CAAZ,CAAF;AAAiB,OAAG,CAACrH,KAAG,EAAH,IAAOA,KAAG,IAAX,KAAkBD,EAAEyqB,GAAF,KAAQzrB,SAA7B,EAAuC;AAACiB,QAAED,EAAEyqB,GAAJ;AAAQ,OAAIxqB,KAAG,EAAH,IAAOA,KAAG,IAAX,IAAkBD,EAAEyqB,GAAF,KAAQzrB,SAA7B,EAAuC;AAACgB,MAAEyqB,GAAF,GAAMxqB,CAAN,CAAQ2B,IAAEF,EAAEF,SAAF,CAAYxB,CAAZ,CAAF;AAAiB,OAAGC,MAAID,EAAEyqB,GAAT,EAAa;AAAC,UAAK,wCAAsCxqB,CAAtC,GAAwC,IAAxC,GAA6CD,EAAEyqB,GAApD;AAAwD,OAAI3oB,IAAE,IAAN,CAAW,IAAGH,EAAEi5B,aAAF,CAAgB36B,CAAhB,MAAqBjB,SAAxB,EAAkC;AAAC,UAAK,2BAAyBiB,CAA9B;AAAgC,GAAnE,MAAuE;AAAC6B,QAAEH,EAAEi5B,aAAF,CAAgB36B,CAAhB,CAAF;AAAqB,OAAIJ,IAAE8kB,WAAW/iB,CAAX,CAAN,CAAoB,IAAIzB,IAAEwkB,WAAWlkB,CAAX,CAAN,CAAoB,IAAIb,IAAEC,IAAE,GAAF,GAAMM,CAAZ,CAAc,IAAIwD,IAAE,EAAN,CAAS,IAAG7B,EAAEY,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,QAAG0E,MAAIpI,SAAP,EAAiB;AAAC,YAAK,wCAAL;AAA8C,SAAII,IAAE,IAAIuB,CAAJ,CAAM,EAAC8pB,KAAI3oB,CAAL,EAAO8oB,MAAK,UAAZ,EAAuB0B,MAAKllB,CAA5B,EAAN,CAAN,CAA4ChI,EAAEosB,YAAF,CAAe5rB,CAAf,EAAkB+D,IAAEvE,EAAEmtB,OAAF,EAAF;AAAc,GAAtK,MAA0K;AAAC,QAAGzqB,EAAEyD,OAAF,CAAU,WAAV,KAAwB,CAAC,CAA5B,EAA8B;AAAC,UAAIlG,IAAE,IAAIS,CAAJ,CAAM,EAAC2qB,KAAI3oB,CAAL,EAAN,CAAN,CAAqBzC,EAAEyB,IAAF,CAAOsG,CAAP,EAAS/G,CAAT,EAAYhB,EAAEmsB,YAAF,CAAe5rB,CAAf,EAAkBi7B,WAASx7B,EAAEouB,IAAF,EAAT,CAAkB9pB,IAAE0T,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBuD,kBAAlB,CAAqCyJ,QAArC,CAAF;AAAiD,KAArJ,MAAyJ;AAAC,UAAG/4B,KAAG,MAAN,EAAa;AAAC,YAAIzC,IAAE,IAAIS,CAAJ,CAAM,EAAC2qB,KAAI3oB,CAAL,EAAN,CAAN,CAAqBzC,EAAEyB,IAAF,CAAOsG,CAAP,EAAS/G,CAAT,EAAYhB,EAAEmsB,YAAF,CAAe5rB,CAAf,EAAkB+D,IAAEtE,EAAEouB,IAAF,EAAF;AAAW;AAAC;AAAC,OAAI3pB,IAAE2gB,UAAU9gB,CAAV,CAAN,CAAmB,OAAO/D,IAAE,GAAF,GAAMkE,CAAb;AAAe,CAAzsC,CAA0sCuT,KAAKyiB,GAAL,CAASC,GAAT,CAAa1L,MAAb,GAAoB,UAAS3qB,CAAT,EAAW8D,CAAX,EAAa/G,CAAb,EAAe;AAAC,MAAIkD,IAAE0T,IAAN;AAAA,MAAW1V,IAAEgC,EAAEm2B,GAAf;AAAA,MAAmBp4B,IAAEC,EAAEo4B,GAAvB;AAAA,MAA2B95B,IAAEyB,EAAEi5B,kBAA/B;AAAA,MAAkD96B,IAAE8D,EAAE2S,MAAtD;AAAA,MAA6D5V,IAAEb,EAAEguB,KAAjE;AAAA,MAAuEjsB,IAAE/B,EAAEssB,GAA3E;AAAA,MAA+E5sB,IAAEM,EAAEktB,SAAnF;AAAA,MAA6F3qB,CAA7F,CAA+F,IAAG,QAAOyV,MAAP,yCAAOA,MAAP,OAAgB7Y,SAAnB,EAA6B;AAACoD,QAAEyV,MAAF;AAAS,OAAIvQ,IAAE5D,EAAE8a,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAGlX,EAAEpH,MAAF,KAAW,CAAd,EAAgB;AAAC,WAAO,KAAP;AAAa,OAAIb,IAAEiI,EAAE,CAAF,CAAN,CAAW,IAAIxF,IAAEwF,EAAE,CAAF,CAAN,CAAW,IAAIxH,IAAET,IAAE,GAAF,GAAMyC,CAAZ,CAAc,IAAIuF,IAAEqd,UAAUpd,EAAE,CAAF,CAAV,CAAN,CAAsB,IAAInH,IAAEF,EAAE2kB,WAAWtd,EAAE,CAAF,CAAX,CAAF,CAAN,CAA0B,IAAIlH,IAAE,IAAN,CAAW,IAAIgH,IAAE,IAAN,CAAW,IAAGjH,EAAEsqB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,UAAK,mCAAL;AAAyC,GAA/D,MAAmE;AAACoB,QAAED,EAAEsqB,GAAJ,CAAQrjB,IAAEhH,EAAEsC,MAAF,CAAS,CAAT,EAAW,CAAX,CAAF;AAAgB,OAAGjC,KAAG,IAAH,IAASd,OAAOH,SAAP,CAAiB2B,QAAjB,CAA0Ba,IAA1B,CAA+BvB,CAA/B,MAAoC,gBAA7C,IAA+DA,EAAEP,MAAF,GAAS,CAA3E,EAA6E;AAAC,QAAIN,IAAE,MAAIa,EAAE8B,IAAF,CAAO,GAAP,CAAJ,GAAgB,GAAtB,CAA0B,IAAG3C,EAAE2F,OAAF,CAAU,MAAInF,CAAJ,GAAM,GAAhB,KAAsB,CAAC,CAA1B,EAA4B;AAAC,YAAK,gBAAcA,CAAd,GAAgB,4BAArB;AAAkD;AAAC,OAAGA,KAAG,MAAH,IAAWoH,MAAI,IAAlB,EAAuB;AAAC,UAAK,mCAAL;AAAyC,OAAG,OAAOA,CAAP,IAAU,QAAV,IAAoBA,EAAEjC,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAlD,EAAoD;AAACiC,QAAE4lB,QAAQC,MAAR,CAAe7lB,CAAf,CAAF;AAAoB,OAAGJ,KAAG,IAAH,IAASA,KAAG,IAAf,EAAoB;AAAC,QAAG,EAAEI,aAAapF,CAAf,CAAH,EAAqB;AAAC,YAAK,gDAAL;AAAsD;AAAC,OAAGgF,KAAG,IAAN,EAAW;AAAC,QAAG,EAAEI,aAAa9G,CAAf,CAAH,EAAqB;AAAC,YAAK,uCAAL;AAA6C;AAAC,OAAGN,KAAG,MAAN,EAAa,CAAE,KAAI0D,IAAE,IAAN,CAAW,IAAGpC,EAAEk5B,aAAF,CAAgBz6B,EAAEsqB,GAAlB,MAAyBzrB,SAA5B,EAAsC;AAAC,UAAK,2BAAyBoB,CAA9B;AAAgC,GAAvE,MAA2E;AAAC0D,QAAEpC,EAAEk5B,aAAF,CAAgBx6B,CAAhB,CAAF;AAAqB,OAAG0D,KAAG,MAAN,EAAa;AAAC,UAAK,eAAL;AAAqB,GAAnC,MAAuC;AAAC,QAAGA,EAAEpB,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,UAAI/B,IAAE,IAAN,CAAW,IAAG6G,MAAIxI,SAAP,EAAiB;AAAC,cAAK,6CAAL;AAAmD,WAAIgB,IAAE,IAAI4B,CAAJ,CAAM,EAAC6oB,KAAI3mB,CAAL,EAAOwoB,MAAK9kB,CAAZ,EAAN,CAAN,CAA4BxH,EAAEwrB,YAAF,CAAe1rB,CAAf,EAAkBa,IAAEX,EAAEusB,OAAF,EAAF,CAAc,OAAOllB,KAAG1G,CAAV;AAAY,KAAlL,MAAsL;AAAC,UAAGmD,EAAEyB,OAAF,CAAU,WAAV,KAAwB,CAAC,CAA5B,EAA8B;AAAC,YAAInG,IAAE,IAAN,CAAW,IAAG;AAACA,cAAEsB,EAAE2wB,kBAAF,CAAqBhqB,CAArB,CAAF;AAA0B,SAA9B,CAA8B,OAAMxD,CAAN,EAAQ;AAAC,iBAAO,KAAP;AAAa,aAAI1E,IAAE,IAAII,CAAJ,CAAM,EAACkrB,KAAI3mB,CAAL,EAAN,CAAN,CAAqB3E,EAAE2B,IAAF,CAAO0G,CAAP,EAAUrI,EAAEqsB,YAAF,CAAe1rB,CAAf,EAAkB,OAAOX,EAAEkvB,MAAF,CAASjvB,CAAT,CAAP;AAAmB,OAAlK,MAAsK;AAAC,YAAID,IAAE,IAAII,CAAJ,CAAM,EAACkrB,KAAI3mB,CAAL,EAAN,CAAN,CAAqB3E,EAAE2B,IAAF,CAAO0G,CAAP,EAAUrI,EAAEqsB,YAAF,CAAe1rB,CAAf,EAAkB,OAAOX,EAAEkvB,MAAF,CAAShnB,CAAT,CAAP;AAAmB;AAAC;AAAC;AAAC,CAA79C,CAA89CgQ,KAAKyiB,GAAL,CAASC,GAAT,CAAav3B,KAAb,GAAmB,UAASrD,CAAT,EAAW;AAAC,MAAIW,IAAEX,EAAEqf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAI5e,IAAE,EAAN,CAAS,IAAIP,CAAJ,EAAMQ,CAAN,EAAQN,CAAR,CAAU,IAAGO,EAAEI,MAAF,IAAU,CAAV,IAAaJ,EAAEI,MAAF,IAAU,CAA1B,EAA4B;AAAC,UAAK,uDAAL;AAA6D,OAAEJ,EAAE,CAAF,CAAF,CAAOD,IAAEC,EAAE,CAAF,CAAF,CAAO,IAAGA,EAAEI,MAAF,IAAU,CAAb,EAAe;AAACX,QAAEO,EAAE,CAAF,CAAF;AAAO,KAAEg7B,SAAF,GAAYzjB,KAAKyiB,GAAL,CAASC,GAAT,CAAaY,kBAAb,CAAgC/V,WAAWvlB,CAAX,CAAhC,CAAZ,CAA2DO,EAAEm7B,UAAF,GAAa1jB,KAAKyiB,GAAL,CAASC,GAAT,CAAaY,kBAAb,CAAgC/V,WAAW/kB,CAAX,CAAhC,CAAb,CAA4DD,EAAEo7B,QAAF,GAAWnX,KAAKriB,SAAL,CAAe5B,EAAEk7B,SAAjB,EAA2B,IAA3B,EAAgC,IAAhC,CAAX,CAAiD,IAAGl7B,EAAEm7B,UAAF,IAAc,IAAjB,EAAsB;AAACn7B,MAAEq7B,SAAF,GAAYrW,WAAW/kB,CAAX,CAAZ;AAA0B,GAAjD,MAAqD;AAACD,MAAEq7B,SAAF,GAAYpX,KAAKriB,SAAL,CAAe5B,EAAEm7B,UAAjB,EAA4B,IAA5B,EAAiC,IAAjC,CAAZ;AAAmD,OAAGx7B,MAAIP,SAAP,EAAiB;AAACY,MAAEs7B,MAAF,GAASxW,UAAUnlB,CAAV,CAAT;AAAsB,UAAOK,CAAP;AAAS,CAAtgB,CAAugByX,KAAKyiB,GAAL,CAASC,GAAT,CAAaoB,SAAb,GAAuB,UAASt7B,CAAT,EAAWM,CAAX,EAAa2B,CAAb,EAAe;AAAC,MAAIvC,IAAE8X,IAAN;AAAA,MAAWrX,IAAET,EAAEu6B,GAAf;AAAA,MAAmBn5B,IAAEX,EAAE+5B,GAAvB;AAAA,MAA2Bt5B,IAAEE,EAAEg6B,kBAA/B;AAAA,MAAkDj6B,IAAEC,EAAEy6B,OAAtD;AAAA,MAA8D/7B,IAAEsB,EAAE06B,aAAlE,CAAgF,IAAIj7B,IAAEP,EAAE2e,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAI1e,IAAEM,EAAE,CAAF,CAAN,CAAW,IAAIH,IAAEG,EAAE,CAAF,CAAN,CAAW,IAAIuB,IAAE7B,IAAE,GAAF,GAAMG,CAAZ,CAAc,IAAImC,IAAEsiB,UAAUtkB,EAAE,CAAF,CAAV,CAAN,CAAsB,IAAIhB,IAAEqB,EAAEmkB,WAAW9kB,CAAX,CAAF,CAAN,CAAuB,IAAIX,IAAEsB,EAAEmkB,WAAW3kB,CAAX,CAAF,CAAN,CAAuB,IAAGb,EAAEqrB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAO,KAAP;AAAa,OAAG8C,EAAE2oB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,UAAK,oCAAL;AAA0C,OAAG,CAAC0B,EAAEtB,EAAEqrB,GAAJ,EAAQ3oB,EAAE2oB,GAAV,CAAJ,EAAmB;AAAC,WAAO,KAAP;AAAa,OAAGtrB,EAAEm8B,GAAF,KAAQt8B,SAAR,IAAmB,QAAO8C,EAAEw5B,GAAT,MAAe,QAArC,EAA8C;AAAC,QAAG,CAAC56B,EAAEvB,EAAEm8B,GAAJ,EAAQx5B,EAAEw5B,GAAV,CAAJ,EAAmB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGn8B,EAAEo8B,GAAF,KAAQv8B,SAAR,IAAmB,QAAO8C,EAAEy5B,GAAT,MAAe,QAArC,EAA8C;AAAC,QAAG,CAAC76B,EAAEvB,EAAEo8B,GAAJ,EAAQz5B,EAAEy5B,GAAV,CAAJ,EAAmB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGp8B,EAAEq8B,GAAF,KAAQx8B,SAAR,IAAmB,QAAO8C,EAAE05B,GAAT,MAAe,QAArC,EAA8C;AAAC,QAAG,OAAOr8B,EAAEq8B,GAAT,IAAc,QAAjB,EAA0B;AAAC,UAAG,CAAC96B,EAAEvB,EAAEq8B,GAAJ,EAAQ15B,EAAE05B,GAAV,CAAJ,EAAmB;AAAC,eAAO,KAAP;AAAa;AAAC,KAA7D,MAAiE;AAAC,UAAG,QAAOr8B,EAAEq8B,GAAT,KAAc,QAAjB,EAA0B;AAAC,YAAG,CAACn8B,EAAEF,EAAEq8B,GAAJ,EAAQ15B,EAAE05B,GAAV,CAAJ,EAAmB;AAAC,iBAAO,KAAP;AAAa;AAAC;AAAC;AAAC,OAAI57B,IAAEI,EAAEy7B,OAAF,CAAUC,MAAV,EAAN,CAAyB,IAAG55B,EAAE65B,QAAF,KAAa38B,SAAb,IAAwB,OAAO8C,EAAE65B,QAAT,KAAoB,QAA/C,EAAwD;AAAC/7B,QAAEkC,EAAE65B,QAAJ;AAAa,OAAG75B,EAAE85B,WAAF,KAAgB58B,SAAhB,IAA2B,OAAO8C,EAAE85B,WAAT,KAAuB,QAArD,EAA8D;AAAC95B,MAAE85B,WAAF,GAAc,CAAd;AAAgB,OAAGz8B,EAAEoP,GAAF,KAAQvP,SAAR,IAAmB,OAAOG,EAAEoP,GAAT,IAAc,QAApC,EAA6C;AAAC,QAAGpP,EAAEoP,GAAF,GAAMzM,EAAE85B,WAAR,GAAoBh8B,CAAvB,EAAyB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGT,EAAE08B,GAAF,KAAQ78B,SAAR,IAAmB,OAAOG,EAAE08B,GAAT,IAAc,QAApC,EAA6C;AAAC,QAAGj8B,IAAET,EAAE08B,GAAF,GAAM/5B,EAAE85B,WAAb,EAAyB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGz8B,EAAE28B,GAAF,KAAQ98B,SAAR,IAAmB,OAAOG,EAAE28B,GAAT,IAAc,QAApC,EAA6C;AAAC,QAAGl8B,IAAET,EAAE28B,GAAF,GAAMh6B,EAAE85B,WAAb,EAAyB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGz8B,EAAE48B,GAAF,KAAQ/8B,SAAR,IAAmB8C,EAAEi6B,GAAF,KAAQ/8B,SAA9B,EAAwC;AAAC,QAAGG,EAAE48B,GAAF,KAAQj6B,EAAEi6B,GAAb,EAAiB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAG,CAACp7B,EAAE0tB,MAAF,CAASxuB,CAAT,EAAWM,CAAX,EAAa2B,EAAE2oB,GAAf,CAAJ,EAAwB;AAAC,WAAO,KAAP;AAAa,UAAO,IAAP;AAAY,CAAnvC,CAAovCpT,KAAKyiB,GAAL,CAASC,GAAT,CAAasB,aAAb,GAA2B,UAASz7B,CAAT,EAAWS,CAAX,EAAa;AAAC,MAAIP,IAAEuX,KAAKyiB,GAAL,CAASC,GAAT,CAAaqB,OAAnB,CAA2B,IAAGx7B,MAAI,IAAP,EAAY;AAAC,WAAO,KAAP;AAAa,OAAG,QAAOA,CAAP,yCAAOA,CAAP,OAAW,QAAd,EAAuB;AAAC,WAAO,KAAP;AAAa,OAAG,OAAOA,EAAEM,MAAT,KAAkB,QAArB,EAA8B;AAAC,WAAO,KAAP;AAAa,QAAI,IAAIX,IAAE,CAAV,EAAYA,IAAEK,EAAEM,MAAhB,EAAuBX,GAAvB,EAA2B;AAAC,QAAG,CAACO,EAAEF,EAAEL,CAAF,CAAF,EAAOc,CAAP,CAAJ,EAAc;AAAC,aAAO,KAAP;AAAa;AAAC,UAAO,IAAP;AAAY,CAApP,CAAqPgX,KAAKyiB,GAAL,CAASC,GAAT,CAAaqB,OAAb,GAAqB,UAAS77B,CAAT,EAAWK,CAAX,EAAa;AAAC,MAAGA,MAAI,IAAP,EAAY;AAAC,WAAO,KAAP;AAAa,OAAG,QAAOA,CAAP,yCAAOA,CAAP,OAAW,QAAd,EAAuB;AAAC,WAAO,KAAP;AAAa,OAAG,OAAOA,EAAEM,MAAT,KAAkB,QAArB,EAA8B;AAAC,WAAO,KAAP;AAAa,QAAI,IAAIJ,IAAE,CAAV,EAAYA,IAAEF,EAAEM,MAAhB,EAAuBJ,GAAvB,EAA2B;AAAC,QAAGF,EAAEE,CAAF,KAAMP,CAAT,EAAW;AAAC,aAAO,IAAP;AAAY;AAAC,UAAO,KAAP;AAAa,CAAhN,CAAiN8X,KAAKyiB,GAAL,CAASC,GAAT,CAAaa,aAAb,GAA2B,EAACoB,OAAM,YAAP,EAAoBC,OAAM,YAA1B,EAAuCC,OAAM,YAA7C,EAA0DC,OAAM,eAAhE,EAAgFC,OAAM,eAAtF,EAAsGC,OAAM,eAA5G,EAA4HC,OAAM,iBAAlI,EAAoJC,OAAM,iBAA1J,EAA4KC,OAAM,sBAAlL,EAAyMC,OAAM,sBAA/M,EAAsOC,OAAM,sBAA5O,EAAmQC,MAAK,MAAxQ,EAA3B,CAA4StlB,KAAKyiB,GAAL,CAASC,GAAT,CAAaC,gBAAb,GAA8B,UAASl6B,CAAT,EAAWF,CAAX,EAAaL,CAAb,EAAe;AAAC,MAAIM,IAAE,IAAN,CAAW,IAAG;AAACA,QAAEqc,UAAUpc,CAAV,CAAF,CAAe,IAAG,QAAOD,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC,aAAO,CAAP;AAAS,SAAGA,EAAEJ,WAAF,KAAgBmJ,KAAnB,EAAyB;AAAC,aAAO,CAAP;AAAS,SAAGhJ,CAAH,EAAK;AAACA,QAAEL,CAAF,IAAKM,CAAL;AAAO,YAAO,CAAP;AAAS,GAA5G,CAA4G,OAAMQ,CAAN,EAAQ;AAAC,WAAO,CAAP;AAAS;AAAC,CAAxL,CAAyLgX,KAAKyiB,GAAL,CAASC,GAAT,CAAaY,kBAAb,GAAgC,UAAS/6B,CAAT,EAAW;AAAC,MAAIE,IAAE,IAAN,CAAW,IAAG;AAACA,QAAEoc,UAAUtc,CAAV,CAAF,CAAe,IAAG,QAAOE,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC,aAAO,IAAP;AAAY,SAAGA,EAAEL,WAAF,KAAgBmJ,KAAnB,EAAyB;AAAC,aAAO,IAAP;AAAY,YAAO9I,CAAP;AAAS,GAArG,CAAqG,OAAMO,CAAN,EAAQ;AAAC,WAAO,IAAP;AAAY;AAAC,CAAlL,CAAmLgX,KAAKyiB,GAAL,CAASC,GAAT,CAAa6C,+BAAb,GAA6C,UAASh9B,CAAT,EAAW;AAAC,MAAIS,IAAET,EAAEwc,KAAF,CAAQ,yBAAR,CAAN,CAAyC,IAAG/b,KAAG,IAAN,EAAW;AAAC,UAAK,yDAAL;AAA+D,UAAOA,EAAE,CAAF,CAAP;AAAY,CAAzL,CAA0LgX,KAAKyiB,GAAL,CAASC,GAAT,CAAa8C,gBAAb,GAA8B,UAASt9B,CAAT,EAAW;AAAC,MAAGA,EAAE20B,GAAF,KAAQ,KAAR,IAAe30B,EAAE20B,GAAF,KAAQ,IAAvB,IAA6B30B,EAAE20B,GAAF,KAAQ,KAAxC,EAA8C;AAAC,UAAK,yCAAL;AAA+C,OAAI7zB,IAAE,GAAN,CAAU,IAAGd,EAAE20B,GAAF,KAAQ,KAAX,EAAiB;AAAC,QAAG,OAAO30B,EAAEkB,CAAT,IAAY,QAAZ,IAAsB,OAAOlB,EAAEM,CAAT,IAAY,QAArC,EAA8C;AAAC,YAAK,iCAAL;AAAuC,UAAG,UAAQN,EAAEM,CAAV,GAAY,IAAf,CAAoBQ,KAAG,YAAUd,EAAE20B,GAAZ,GAAgB,IAAnB,CAAwB7zB,KAAG,UAAQd,EAAEkB,CAAV,GAAY,IAAf;AAAoB,GAAxK,MAA4K;AAAC,QAAGlB,EAAE20B,GAAF,KAAQ,IAAX,EAAgB;AAAC,UAAG,OAAO30B,EAAEk1B,GAAT,IAAc,QAAd,IAAwB,OAAOl1B,EAAEoE,CAAT,IAAY,QAApC,IAA8C,OAAOpE,EAAE+H,CAAT,IAAY,QAA7D,EAAsE;AAAC,cAAK,qCAAL;AAA2C,YAAG,YAAU/H,EAAEk1B,GAAZ,GAAgB,IAAnB,CAAwBp0B,KAAG,YAAUd,EAAE20B,GAAZ,GAAgB,IAAnB,CAAwB7zB,KAAG,UAAQd,EAAEoE,CAAV,GAAY,IAAf,CAAoBtD,KAAG,UAAQd,EAAE+H,CAAV,GAAY,IAAf;AAAoB,KAA3N,MAA+N;AAAC,UAAG/H,EAAE20B,GAAF,KAAQ,KAAX,EAAiB;AAAC,YAAG,OAAO30B,EAAEa,CAAT,IAAY,QAAf,EAAwB;AAAC,gBAAK,sCAAL;AAA4C,cAAG,YAAUb,EAAE20B,GAAZ,GAAgB,IAAnB,CAAwB7zB,KAAG,UAAQd,EAAEa,CAAV,GAAY,IAAf;AAAoB;AAAC;AAAC,OAAIR,IAAEgY,UAAUvX,CAAV,CAAN,CAAmB,IAAIP,IAAEuX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyB/X,CAAzB,EAA2B,QAA3B,CAAN,CAA2C,IAAIC,IAAE4kB,UAAU3kB,CAAV,CAAN,CAAmB,OAAOD,CAAP;AAAS,CAA9vB,CAA+vBwX,KAAKyiB,GAAL,CAAS2B,OAAT,GAAiB,EAAjB,CAAoBpkB,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBqB,GAAjB,GAAqB,UAASh9B,CAAT,EAAW;AAAC,MAAIF,IAAEyX,KAAKyiB,GAAL,CAAS2B,OAAf;AAAA,MAAuBl8B,IAAEK,EAAE87B,MAA3B;AAAA,MAAkCr7B,IAAET,EAAEm9B,OAAtC,CAA8C,IAAGj9B,KAAG,KAAN,EAAY;AAAC,WAAOP,GAAP;AAAW,GAAxB,MAA4B;AAAC,QAAGO,KAAG,aAAN,EAAoB;AAAC,aAAOP,MAAI,KAAG,EAAd;AAAiB,KAAtC,MAA0C;AAAC,UAAGO,KAAG,YAAN,EAAmB;AAAC,eAAOP,MAAI,KAAG,EAAH,GAAM,EAAjB;AAAoB,OAAxC,MAA4C;AAAC,YAAGO,KAAG,cAAN,EAAqB;AAAC,iBAAOP,MAAI,KAAG,EAAH,GAAM,EAAN,GAAS,EAApB;AAAuB,SAA7C,MAAiD;AAAC,cAAGO,KAAG,aAAN,EAAoB;AAAC,mBAAOP,MAAI,KAAG,EAAH,GAAM,EAAN,GAAS,GAApB;AAAwB,WAA7C,MAAiD;AAAC,gBAAGO,EAAEsc,KAAF,CAAQ,IAAR,CAAH,EAAiB;AAAC,qBAAO/b,EAAEP,CAAF,CAAP;AAAY,aAA9B,MAAkC;AAAC,kBAAGA,EAAEsc,KAAF,CAAQ,UAAR,CAAH,EAAuB;AAAC,uBAAO3Z,SAAS3C,CAAT,CAAP;AAAmB;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC,SAAK,yBAAuBA,CAA5B;AAA8B,CAA1Z,CAA2ZuX,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBsB,OAAjB,GAAyB,UAAS18B,CAAT,EAAW;AAAC,SAAO0lB,UAAU1lB,CAAV,CAAP;AAAoB,CAAzD,CAA0DgX,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBC,MAAjB,GAAwB,YAAU;AAAC,MAAIr7B,IAAE,CAAC,EAAE,IAAI+V,IAAJ,KAAW,IAAb,CAAP,CAA0B,OAAO/V,CAAP;AAAS,CAAtE,CAAuEgX,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBuB,iBAAjB,GAAmC,UAAS38B,CAAT,EAAW;AAAC,MAAIT,IAAE,IAAIwW,IAAJ,CAAS/V,IAAE,IAAX,CAAN,CAAuB,OAAOT,EAAEq9B,WAAF,EAAP;AAAuB,CAA7F,CAA8F5lB,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiByB,YAAjB,GAA8B,UAASr9B,CAAT,EAAW;AAAC,MAAII,IAAE,IAAImW,IAAJ,CAASvW,IAAE,IAAX,CAAN;AAAA,MAAuBT,IAAE,CAAC,SAAOa,EAAEimB,cAAF,EAAR,EAA4BjkB,KAA5B,CAAkC,CAAC,CAAnC,CAAzB;AAAA,MAA+D9C,IAAE,CAAC,QAAMc,EAAEkmB,WAAF,KAAgB,CAAtB,CAAD,EAA2BlkB,KAA3B,CAAiC,CAAC,CAAlC,CAAjE;AAAA,MAAsGrC,IAAE,CAAC,OAAKK,EAAEmmB,UAAF,EAAN,EAAsBnkB,KAAtB,CAA4B,CAAC,CAA7B,CAAxG;AAAA,MAAwI5B,IAAE,CAAC,OAAKJ,EAAEomB,WAAF,EAAN,EAAuBpkB,KAAvB,CAA6B,CAAC,CAA9B,CAA1I;AAAA,MAA2KnC,IAAE,CAAC,OAAKG,EAAEqmB,aAAF,EAAN,EAAyBrkB,KAAzB,CAA+B,CAAC,CAAhC,CAA7K;AAAA,MAAgN5C,IAAE,CAAC,OAAKY,EAAEsmB,aAAF,EAAN,EAAyBtkB,KAAzB,CAA+B,CAAC,CAAhC,CAAlN,CAAqP,OAAO7C,IAAED,CAAF,GAAIS,CAAJ,GAAMS,CAAN,GAAQP,CAAR,GAAUT,CAAV,GAAY,GAAnB;AAAuB,CAAtT;QACt4PyX,Y,GAAAA,Y;QACAX,a,GAAAA,a;QAEAnN,U,GAAAA,U;QACA6O,M,GAAAA,M;IACMslB,I,GAAS9lB,KAAKf,M,CAAd6mB,I;;IACAhP,G,GAAQ9W,KAAKf,M,CAAb6X,G;;IACApB,S,GAAc1V,KAAKf,M,CAAnByW,S;;IACAzV,a,GAAmBD,KAAKf,M,CAAxBgB,a;;IACA6U,G,GAAQ9U,KAAKf,M,CAAb6V,G;;IACA4C,M,GAAY1X,KAAKf,M,CAAjByY,M;;QACN3B,O,GAAAA,O;QACA3K,O,GAAAA,O;QACAiS,I,GAAAA,I;QACAp0B,Q,GAAAA,Q;;AAET;;QACSmI,Q,GAAAA,Q;QACAE,O,GAAAA,O;;AAET;;QACSsb,K,GAAAA,K;QACAC,K,GAAAA,K;QACAC,O,GAAAA,O;QACA5D,M,GAAAA,M;QACA6D,M,GAAAA,M;QACAC,O,GAAAA,O;QACAE,O,GAAAA,O;QACAD,S,GAAAA,S;QACAE,S,GAAAA,S;QACAjc,O,GAAAA,O;QACAkc,S,GAAAA,S;QACAC,S,GAAAA,S;QACAC,U,GAAAA,U;QACAC,U,GAAAA,U;QACAK,S,GAAAA,S;QACAC,S,GAAAA,S;QACA7F,S,GAAAA,S;QACAsE,S,GAAAA,S;QACAjM,S,GAAAA,S;QACAE,S,GAAAA,S;QACAuN,Q,GAAAA,Q;QACAC,U,GAAAA,U;QACAC,U,GAAAA,U;QACAzI,Q,GAAAA,Q;QACA0I,Q,GAAAA,Q;QACAC,gB,GAAAA,gB;QACAI,gB,GAAAA,gB;QACAG,U,GAAAA,U;QACAC,S,GAAAA,S;QACAC,U,GAAAA,U;QACAC,U,GAAAA,U;QACAnB,W,GAAAA,W;QACAE,W,GAAAA,W;QACAyB,S,GAAAA,S;QACAE,S,GAAAA,S;QACAC,O,GAAAA,O;QACAC,O,GAAAA,O;QACA9B,qB,GAAAA,qB;QACA+B,c,GAAAA,c;QACAC,a,GAAAA,a;QACAK,W,GAAAA,W;QACAC,c,GAAAA,c;QACAE,U,GAAAA,U;;AAET;;QACSlQ,I,GAAAA,I;;AACT,IAAM+lB,UAAW/lB,KAAKf,MAAtB;QACoBA,M,GAAX8mB,O;YACe/lB,I;IAATkF,I,SAAAA,I;;aACQlF,I;IAARyiB,G,UAAAA,G;;aACSziB,I;IAATpY,I,UAAAA,I;;;;;;;;;;;;;;AC1LH;;AAEZ;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,kCAAkC,SAAS;AAC3C;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;;AAEA;AACA;AACA;AACA;;AAEA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,0CAA0C,UAAU;AACpD;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;;;;;;;;;;;;ACtJA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEY;;AAEZ,aAAa,mBAAO,CAAC,oDAAW;AAChC,cAAc,mBAAO,CAAC,gDAAS;AAC/B,cAAc,mBAAO,CAAC,oEAAS;;AAE/B;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,qBAAqB,mDAAmD;AACxE;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,mBAAmB,UAAU;AAC7B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,YAAY;AAC7B;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,0BAA0B;AAC1B;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA,uCAAuC,SAAS;AAChD;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA,eAAe,iBAAiB;AAChC;AACA;AACA;;AAEA;AACA;AACA,aAAa,iBAAiB;AAC9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,gDAAgD,EAAE;AAClD;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,yCAAyC;AACzC;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;;AAEA;AACA;AACA;AACA,wBAAwB,eAAe;AACvC;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA,GAAG;AACH;AACA,wBAAwB,QAAQ;AAChC;AACA,qBAAqB,eAAe;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,YAAY;AAC7B;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;;AAEA;AACA,SAAS;AACT;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,kBAAkB;AACnC;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,mBAAmB,cAAc;AACjC;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,uDAAuD,OAAO;AAC9D;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA,uDAAuD,OAAO;AAC9D;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,kBAAkB;AAClB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,qBAAqB,QAAQ;AAC7B;AACA;AACA,GAAG;AACH;AACA,eAAe,SAAS;AACxB;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA,mBAAmB,SAAS;AAC5B;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,eAAe,iBAAiB;AAChC;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA,iBAAiB,YAAY;AAC7B;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,KAAK;AACL;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,iBAAiB,gBAAgB;AACjC;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,gBAAgB;AACjC;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,iBAAiB,YAAY;AAC7B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;AC5vDA,iBAAiB;;AAEjB;AACA;AACA;;;;;;;;;;;;ACJA,mBAAO,CAAC,+FAAiC;AACzC,mBAAO,CAAC,6FAAgC;AACxC,mBAAO,CAAC,uFAA6B;AACrC,mBAAO,CAAC,6EAAwB;AAChC,iBAAiB,mBAAO,CAAC,iEAAkB;;;;;;;;;;;;ACJ3C,mBAAO,CAAC,sFAA8B;AACtC,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C,mBAAO,CAAC,8FAAkC;AAC1C,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C,mBAAO,CAAC,sFAA8B;AACtC,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C;AACA;AACA;AACA;;;;;;;;;;;;ACHA,mBAAO,CAAC,4FAAiC;AACzC,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C,mBAAO,CAAC,4FAAiC;AACzC,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C;AACA;AACA;AACA;;;;;;;;;;;;ACHA;AACA,kBAAkB,mBAAO,CAAC,sDAAQ;AAClC;AACA,0CAA0C,mBAAO,CAAC,wDAAS,6BAA6B;AACxF;AACA;AACA;;;;;;;;;;;;ACNA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACJA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;;;;;;;;;;;;ACJA;AACA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK,YAAY,eAAe;AAChC;AACA,KAAK;AACL;AACA;;;;;;;;;;;;ACtBA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,wFAAyB;AAC3C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,eAAe;AACzB;AACA;AACA;AACA,wCAAwC;AACxC;AACA,8BAA8B;AAC9B,6BAA6B;AAC7B,+BAA+B;AAC/B,mCAAmC;AACnC,SAAS,iCAAiC;AAC1C;AACA;AACA;AACA;AACA;;;;;;;;;;;;AC3CA,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,gEAAa;AACnC,cAAc,mBAAO,CAAC,sDAAQ;;AAE9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACfA;AACA,yBAAyB,mBAAO,CAAC,kGAA8B;;AAE/D;AACA;AACA;;;;;;;;;;;;;ACLa;AACb,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA;;AAEA;AACA;AACA,2BAA2B,SAAS;AACpC;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACxBA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA,2BAA2B,kBAAkB,EAAE;;AAE/C;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACtBA,iBAAiB;;AAEjB;AACA;AACA;;;;;;;;;;;;ACJA,6BAA6B;AAC7B,uCAAuC;;;;;;;;;;;;ACDvC;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACnBA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACJA;AACA,kBAAkB,mBAAO,CAAC,0DAAU;AACpC,iCAAiC,QAAQ,mBAAmB,UAAU,EAAE,EAAE;AAC1E,CAAC;;;;;;;;;;;;ACHD,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,4DAAW;AAClC;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACNA;AACA;AACA;AACA;;;;;;;;;;;;ACHA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,WAAW,mBAAO,CAAC,wDAAS;AAC5B,eAAe,mBAAO,CAAC,gEAAa;AACpC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,kFAAkF,uBAAuB;AACzG,iEAAiE;AACjE,+DAA+D;AAC/D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,cAAc;AACd,cAAc;AACd,cAAc;AACd,cAAc;AACd,eAAe;AACf,eAAe;AACf,eAAe;AACf,gBAAgB;AAChB;;;;;;;;;;;;AC1CA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;;;;;;;;;;;ACNA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,WAAW,mBAAO,CAAC,kEAAc;AACjC,kBAAkB,mBAAO,CAAC,0EAAkB;AAC5C,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,8FAA4B;AACpD;AACA;AACA;AACA,uCAAuC,iBAAiB,EAAE;AAC1D;AACA;AACA;AACA;AACA;AACA,mEAAmE,gBAAgB;AACnF;AACA;AACA,GAAG,4CAA4C,gCAAgC;AAC/E;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACxBA,iBAAiB,mBAAO,CAAC,4DAAW;;;;;;;;;;;;ACApC;AACA;AACA;AACA;AACA;AACA,yCAAyC;;;;;;;;;;;;ACLzC,uBAAuB;AACvB;AACA;AACA;;;;;;;;;;;;ACHA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC;AACA,CAAC;AACD;AACA;AACA;;;;;;;;;;;;ACPA,eAAe,mBAAO,CAAC,4DAAW;AAClC;;;;;;;;;;;;ACDA,kBAAkB,mBAAO,CAAC,sEAAgB,MAAM,mBAAO,CAAC,0DAAU;AAClE,+BAA+B,mBAAO,CAAC,oEAAe,gBAAgB,mBAAmB,UAAU,EAAE,EAAE;AACvG,CAAC;;;;;;;;;;;;ACFD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACfA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;AACA;;;;;;;;;;;;ACLA;AACA,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,eAAe,mBAAO,CAAC,sDAAQ;AAC/B;;AAEA;AACA;AACA;;;;;;;;;;;;ACPA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;;;;;;;;;;;ACJA;AACA;AACA;;;;;;;;;;;;ACFA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACXa;AACb,aAAa,mBAAO,CAAC,0EAAkB;AACvC,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD;;AAEA;AACA,mBAAO,CAAC,wDAAS,qBAAqB,mBAAO,CAAC,sDAAQ,4BAA4B,aAAa,EAAE;;AAEjG;AACA,qDAAqD,4BAA4B;AACjF;AACA;;;;;;;;;;;;;ACZa;AACb,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,gEAAa;AACpC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,eAAe,mBAAO,CAAC,sDAAQ;AAC/B,8CAA8C;AAC9C;AACA;AACA;;AAEA,8BAA8B,aAAa;;AAE3C;AACA;AACA;AACA;AACA;AACA,yCAAyC,oCAAoC;AAC7E,6CAA6C,oCAAoC;AACjF,KAAK,4BAA4B,oCAAoC;AACrE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,gBAAgB,mBAAmB;AACnC;AACA;AACA,kCAAkC,2BAA2B;AAC7D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;;;;;;;;;;;;ACpEA,eAAe,mBAAO,CAAC,sDAAQ;AAC/B;;AAEA;AACA;AACA,iCAAiC,qBAAqB;AACtD;AACA,iCAAiC,SAAS,EAAE;AAC5C,CAAC,YAAY;;AAEb;AACA;AACA;AACA;AACA;AACA;AACA,6BAA6B,SAAS,qBAAqB;AAC3D,iCAAiC,aAAa;AAC9C;AACA,GAAG,YAAY;AACf;AACA;;;;;;;;;;;;ACrBA;AACA,UAAU;AACV;;;;;;;;;;;;ACFA;;;;;;;;;;;;ACAA;;;;;;;;;;;;ACAA,aAAa,mBAAO,CAAC,4DAAW;AAChC,gBAAgB,mBAAO,CAAC,wDAAS;AACjC;AACA;AACA;AACA,aAAa,mBAAO,CAAC,sDAAQ;;AAE7B;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,uCAAuC,sBAAsB,EAAE;AAC/D;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA,gBAAgB;AAChB;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;;;;;;;;;;;;ACpEa;AACb;AACA,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;ACjBa;AACb;AACA,cAAc,mBAAO,CAAC,sEAAgB;AACtC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,UAAU,mBAAO,CAAC,oEAAe;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,8DAAY;AAClC;;AAEA;AACA,6BAA6B,mBAAO,CAAC,0DAAU;AAC/C;AACA;AACA;AACA;AACA;AACA;AACA,oCAAoC,UAAU,EAAE;AAChD,mBAAmB,sCAAsC;AACzD,CAAC,qCAAqC;AACtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH,CAAC;;;;;;;;;;;;ACjCD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,oEAAe;AACjC,kBAAkB,mBAAO,CAAC,0EAAkB;AAC5C,eAAe,mBAAO,CAAC,oEAAe;AACtC,yBAAyB;AACzB;;AAEA;AACA;AACA;AACA,eAAe,mBAAO,CAAC,oEAAe;AACtC;AACA;AACA;AACA;AACA;AACA,EAAE,mBAAO,CAAC,wDAAS;AACnB,6BAA6B;AAC7B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;;;;;;;;;;;;ACxCA,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,4EAAmB;AAChD,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C;;AAEA,YAAY,mBAAO,CAAC,sEAAgB;AACpC;AACA;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf;AACA;AACA;AACA;;;;;;;;;;;;ACfA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,sEAAgB;;AAEtC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACZA;;;;;;;;;;;;ACAA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,oEAAe;AACtC;;AAEA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACZA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,mBAAmB,mBAAO,CAAC,4EAAmB;AAC9C,eAAe,mBAAO,CAAC,oEAAe;;AAEtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AChBA;AACA,YAAY,mBAAO,CAAC,wFAAyB;AAC7C,kBAAkB,mBAAO,CAAC,0EAAkB;;AAE5C;AACA;AACA;;;;;;;;;;;;ACNA,cAAc;;;;;;;;;;;;ACAd;AACA;AACA,YAAY;AACZ,GAAG;AACH,YAAY;AACZ;AACA;;;;;;;;;;;;ACNA,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,2BAA2B,mBAAO,CAAC,4FAA2B;;AAE9D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACXA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACPA,eAAe,mBAAO,CAAC,gEAAa;AACpC;AACA;AACA;AACA;;;;;;;;;;;;ACJA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,gBAAgB,mBAAO,CAAC,oFAAuB;AAC/C;AACA;;AAEA,mBAAO,CAAC,wDAAS;AACjB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA;AACA,CAAC;AACD;AACA,CAAC;;;;;;;;;;;;;AC9BY;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,SAAS,mBAAO,CAAC,kEAAc;AAC/B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,cAAc,mBAAO,CAAC,sDAAQ;;AAE9B;AACA;AACA;AACA;AACA,sBAAsB,aAAa;AACnC,GAAG;AACH;;;;;;;;;;;;ACZA,UAAU,mBAAO,CAAC,kEAAc;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;;AAE1B;AACA,oEAAoE,iCAAiC;AACrG;;;;;;;;;;;;ACNA,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;;;;;;;;;;;ACJA,WAAW,mBAAO,CAAC,wDAAS;AAC5B,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA,kDAAkD;;AAElD;AACA,qEAAqE;AACrE,CAAC;AACD;AACA,QAAQ,mBAAO,CAAC,8DAAY;AAC5B;AACA,CAAC;;;;;;;;;;;;ACXD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,cAAc,mBAAO,CAAC,sDAAQ;AAC9B;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACRa;AACb,YAAY,mBAAO,CAAC,0DAAU;;AAE9B;AACA;AACA;AACA,yCAAyC,cAAc;AACvD,GAAG;AACH;;;;;;;;;;;;ACRA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AChBA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,oEAAe;AACjC,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,MAAM,mBAAO,CAAC,sDAAQ;AACtB;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACnFA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACNA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACLA;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;;;;;;;;;;;;ACLA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA,2DAA2D;AAC3D;;;;;;;;;;;;ACLA;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;;;;;;;;;;;;ACJA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACXA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACJA,aAAa,mBAAO,CAAC,4DAAW;AAChC;;AAEA;;;;;;;;;;;;ACHA,YAAY,mBAAO,CAAC,4DAAW;AAC/B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,aAAa,mBAAO,CAAC,4DAAW;AAChC;;AAEA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;ACVA,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,sDAAQ;AAC/B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,iBAAiB,mBAAO,CAAC,wDAAS;AAClC;AACA;AACA;AACA;;;;;;;;;;;;;ACPa;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0EAAkB;AACtC;AACA;AACA;AACA,0CAA0C,gBAAgB,EAAE;AAC5D;AACA;AACA;AACA;AACA,CAAC;AACD,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;ACb/B;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,6BAA6B,UAAU,mBAAO,CAAC,gEAAa,GAAG;;;;;;;;;;;;;ACHlD;AACb,uBAAuB,mBAAO,CAAC,oFAAuB;AACtD,WAAW,mBAAO,CAAC,kEAAc;AACjC,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,gCAAgC;AAChC,cAAc;AACd,iBAAiB;AACjB;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;ACjCa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0EAAkB;;AAEtC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,gCAAgC,OAAO,mBAAO,CAAC,wDAAS,GAAG;;;;;;;;;;;;ACH3D;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,0CAA0C,SAAS,mBAAO,CAAC,0EAAkB,GAAG;;;;;;;;;;;;;ACHnE;AACb;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA,KAAK,mBAAO,CAAC,sDAAQ;AACrB;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;AACA,GAAG;AACH;;;;;;;;;;;;;ACTa;AACb,cAAc,mBAAO,CAAC,8DAAY;AAClC,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,YAAY,mBAAO,CAAC,4DAAW;AAC/B,yBAAyB,mBAAO,CAAC,sFAAwB;AACzD,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,iCAAiC,mBAAO,CAAC,4FAA2B;AACpE,cAAc,mBAAO,CAAC,8DAAY;AAClC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,qBAAqB,mBAAO,CAAC,8EAAoB;AACjD;AACA;AACA;AACA;AACA;AACA;AACA;AACA,yBAAyB;AACzB;AACA;;AAEA;AACA;AACA;AACA;AACA,+CAA+C,EAAE,mBAAO,CAAC,sDAAQ;AACjE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oCAAoC;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,WAAW;AACX;AACA,WAAW;AACX,SAAS;AACT,OAAO;AACP;AACA;AACA;AACA;AACA,6CAA6C;AAC7C;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT,mBAAmB,kCAAkC;AACrD,SAAS;AACT;AACA;AACA,OAAO;AACP;AACA;AACA,KAAK;AACL;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL,eAAe,uCAAuC;AACtD;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA,uBAAuB,0BAA0B;AACjD;AACA;AACA,SAAS;AACT;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH,kBAAkB,yBAAyB,KAAK;AAChD;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA,iBAAiB;AACjB,wBAAwB;AACxB,gBAAgB;AAChB,oBAAoB;AACpB,wBAAwB;AACxB,gBAAgB;AAChB,oBAAoB;AACpB;AACA,uBAAuB,mBAAO,CAAC,wEAAiB;AAChD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,0DAA0D,oBAAoB;AAC9E,mBAAO,CAAC,kFAAsB;AAC9B,mBAAO,CAAC,sEAAgB;AACxB,UAAU,mBAAO,CAAC,wDAAS;;AAE3B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA,CAAC;AACD,gDAAgD,mBAAO,CAAC,sEAAgB;AACxE;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT,OAAO;AACP;AACA,KAAK;AACL;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;AC7RY;AACb,UAAU,mBAAO,CAAC,kEAAc;;AAEhC;AACA,mBAAO,CAAC,sEAAgB;AACxB,6BAA6B;AAC7B,cAAc;AACd;AACA,CAAC;AACD;AACA;AACA;AACA,iCAAiC;AACjC;AACA;AACA,UAAU;AACV,CAAC;;;;;;;;;;;;AChBD,iBAAiB,mBAAO,CAAC,kFAAsB;AAC/C,cAAc,mBAAO,CAAC,sEAAgB;AACtC,eAAe,mBAAO,CAAC,gEAAa;AACpC,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,oDAAoD,wBAAwB;AAC5E;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACzDA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA,QAAQ,WAAW;;AAEnB;AACA;AACA;AACA,QAAQ,WAAW;;AAEnB;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;;AAEA,QAAQ,WAAW;;AAEnB;AACA;AACA,QAAQ,UAAU;;AAElB;AACA;;;;;;;;;;;;ACnFA;AACA;AACA;AACA;AACA;AACA,eAAe,SAAS;AACxB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;ACvBA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA,iCAAiC;;AAEjC;AACA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;;AAEA;AACA,sBAAsB,QAAQ;AAC9B;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;ACjCA,UAAU,mBAAO,CAAC,yDAAW;AAC7B,kBAAkB,mBAAO,CAAC,iEAAmB;;AAE7C;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;;AAEA;AACA;AACA,oBAAoB,SAAS;AAC7B;AACA;AACA;;AAEA;AACA;;AAEA;;;;;;;;;;;;AC5BA;;AAEA;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;;AAEA;AACA;AACA,4CAA4C;;AAE5C;;;;;;;;;;;;;;;ACbA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA,gG;;;;;;;;;;;;;;;;;;;ACTA;;AACA;;0JAJA;AACA;;AAKA,IAAMo+B,6CAA6C,EAAnD,C,CAAuD;;IAE1Cl/B,iB,WAAAA,iB;AAET,iCAIQ;AAAA,uFAAJ,EAAI;AAAA,yCAHJm/B,mCAGI;AAAA,YAHJA,mCAGI,yCAHkCD,0CAGlC;AAAA,0CAFJE,wBAEI;AAAA,YAFJA,wBAEI,0CAFuB,IAAIC,YAAJ,CAAU,uBAAV,CAEvB;AAAA,0CADJC,uBACI;AAAA,YADJA,uBACI,0CADsB,IAAID,YAAJ,CAAU,sBAAV,CACtB;;AAAA;;AACJ,aAAKE,oCAAL,GAA4CJ,mCAA5C;;AAEA,aAAKK,oBAAL,GAA4BJ,wBAA5B;AACA,aAAKK,mBAAL,GAA2BH,uBAA3B;AACH;;gCAEDI,I,iBAAKC,S,EAAW;AACZ;AACA,YAAIA,UAAUC,YAAV,IAA0BD,UAAUE,UAAV,KAAyBh/B,SAAvD,EAAkE;AAC9D,gBAAIi/B,WAAWH,UAAUE,UAAzB;AACAngC,qBAAIqgC,KAAJ,CAAU,mEAAV,EAA+ED,QAA/E;;AAEA,gBAAIA,WAAW,CAAf,EAAkB;AACd;AACA,oBAAIE,WAAWF,WAAW,KAAKP,oCAA/B;AACA,oBAAIS,YAAY,CAAhB,EAAkB;AACdA,+BAAW,CAAX;AACH;;AAEDtgC,yBAAIqgC,KAAJ,CAAU,wDAAV,EAAoEC,QAApE;AACA,qBAAKR,oBAAL,CAA0B78B,IAA1B,CAA+Bq9B,QAA/B;AACH,aATD,MAUK;AACDtgC,yBAAIqgC,KAAJ,CAAU,yFAAV;AACA,qBAAKP,oBAAL,CAA0BS,MAA1B;AACH;;AAED;AACA,gBAAIC,UAAUJ,WAAW,CAAzB;AACApgC,qBAAIqgC,KAAJ,CAAU,uDAAV,EAAmEG,OAAnE;AACA,iBAAKT,mBAAL,CAAyB98B,IAAzB,CAA8Bu9B,OAA9B;AACH,SAvBD,MAwBK;AACD,iBAAKV,oBAAL,CAA0BS,MAA1B;AACA,iBAAKR,mBAAL,CAAyBQ,MAAzB;AACH;AACJ,K;;gCAEDE,M,qBAAS;AACLzgC,iBAAIqgC,KAAJ,CAAU,kEAAV;AACA,aAAKP,oBAAL,CAA0BS,MAA1B;AACA,aAAKR,mBAAL,CAAyBQ,MAAzB;AACH,K;;gCAEDG,sB,mCAAuBC,E,EAAI;AACvB,aAAKb,oBAAL,CAA0Bc,UAA1B,CAAqCD,EAArC;AACH,K;;gCACDE,yB,sCAA0BF,E,EAAI;AAC1B,aAAKb,oBAAL,CAA0BgB,aAA1B,CAAwCH,EAAxC;AACH,K;;gCAEDI,qB,kCAAsBJ,E,EAAI;AACtB,aAAKZ,mBAAL,CAAyBa,UAAzB,CAAoCD,EAApC;AACH,K;;gCACDK,wB,qCAAyBL,E,EAAI;AACzB,aAAKZ,mBAAL,CAAyBe,aAAzB,CAAuCH,EAAvC;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACpEL;;0JAHA;AACA;;AAIA,IAAMM,kBAAkB,IAAxB;;IAEavgC,kB,WAAAA,kB;AACT,gCAAYwgC,QAAZ,EAAsBC,SAAtB,EAAiCC,GAAjC,EAAsCC,QAAtC,EAAoE;AAAA,YAApBC,WAAoB,uEAAN,IAAM;;AAAA;;AAChE,aAAKC,SAAL,GAAiBL,QAAjB;AACA,aAAKM,UAAL,GAAkBL,SAAlB;AACA,aAAKM,IAAL,GAAYL,GAAZ;AACA,aAAKM,SAAL,GAAiBL,YAAYJ,eAA7B;AACA,aAAKU,YAAL,GAAoBL,WAApB;;AAEA,YAAIM,MAAMR,IAAI15B,OAAJ,CAAY,GAAZ,EAAiB05B,IAAI15B,OAAJ,CAAY,IAAZ,IAAoB,CAArC,CAAV;AACA,aAAKm6B,aAAL,GAAqBT,IAAIv8B,MAAJ,CAAW,CAAX,EAAc+8B,GAAd,CAArB;;AAEA,aAAKE,MAAL,GAAc7gC,OAAO8gC,QAAP,CAAgBC,aAAhB,CAA8B,QAA9B,CAAd;;AAEA;AACA,aAAKF,MAAL,CAAYG,KAAZ,CAAkBC,UAAlB,GAA+B,QAA/B;AACA,aAAKJ,MAAL,CAAYG,KAAZ,CAAkBE,QAAlB,GAA6B,UAA7B;AACA,aAAKL,MAAL,CAAYG,KAAZ,CAAkBG,OAAlB,GAA4B,MAA5B;AACA,aAAKN,MAAL,CAAYG,KAAZ,CAAkBI,KAAlB,GAA0B,CAA1B;AACA,aAAKP,MAAL,CAAYG,KAAZ,CAAkBK,MAAlB,GAA2B,CAA3B;;AAEA,aAAKR,MAAL,CAAYS,GAAZ,GAAkBnB,GAAlB;AACH;;iCACDpB,I,mBAAO;AAAA;;AACH,eAAO,IAAIwC,OAAJ,CAAY,UAACC,OAAD,EAAa;AAC5B,kBAAKX,MAAL,CAAYY,MAAZ,GAAqB,YAAM;AACvBD;AACH,aAFD;;AAIAxhC,mBAAO8gC,QAAP,CAAgBY,IAAhB,CAAqBC,WAArB,CAAiC,MAAKd,MAAtC;AACA,kBAAKe,kBAAL,GAA0B,MAAKC,QAAL,CAAcC,IAAd,CAAmB,KAAnB,CAA1B;AACA9hC,mBAAO+hC,gBAAP,CAAwB,SAAxB,EAAmC,MAAKH,kBAAxC,EAA4D,KAA5D;AACH,SARM,CAAP;AASH,K;;iCACDC,Q,qBAAS9gC,C,EAAG;AACR,YAAIA,EAAEihC,MAAF,KAAa,KAAKpB,aAAlB,IACA7/B,EAAEkhC,MAAF,KAAa,KAAKpB,MAAL,CAAYqB,aAD7B,EAEE;AACE,gBAAInhC,EAAEsyB,IAAF,KAAW,OAAf,EAAwB;AACpBt0B,yBAAIojC,KAAJ,CAAU,gEAAV;AACA,oBAAI,KAAKzB,YAAT,EAAuB;AACnB,yBAAK0B,IAAL;AACH;AACJ,aALD,MAMK,IAAIrhC,EAAEsyB,IAAF,KAAW,SAAf,EAA0B;AAC3Bt0B,yBAAIqgC,KAAJ,CAAU,kEAAV;AACA,qBAAKgD,IAAL;AACA,qBAAK9B,SAAL;AACH,aAJI,MAKA;AACDvhC,yBAAIqgC,KAAJ,CAAU,yBAAyBr+B,EAAEsyB,IAA3B,GAAkC,uCAA5C;AACH;AACJ;AACJ,K;;iCACDgP,K,kBAAMC,a,EAAe;AAAA;;AACjB,YAAI,KAAKC,cAAL,KAAwBD,aAA5B,EAA2C;AACvCvjC,qBAAIqgC,KAAJ,CAAU,0BAAV;;AAEA,iBAAKgD,IAAL;;AAEA,iBAAKG,cAAL,GAAsBD,aAAtB;;AAEA,gBAAIE,OAAO,SAAPA,IAAO,GAAM;AACb,uBAAK3B,MAAL,CAAYqB,aAAZ,CAA0BO,WAA1B,CAAsC,OAAKlC,UAAL,GAAkB,GAAlB,GAAwB,OAAKgC,cAAnE,EAAmF,OAAK3B,aAAxF;AACH,aAFD;;AAIA;AACA4B;;AAEA;AACA,iBAAKE,MAAL,GAAc1iC,OAAO2iC,WAAP,CAAmBH,IAAnB,EAAyB,KAAK/B,SAA9B,CAAd;AACH;AACJ,K;;iCAED2B,I,mBAAO;AACH,aAAKG,cAAL,GAAsB,IAAtB;;AAEA,YAAI,KAAKG,MAAT,EAAiB;AACb3jC,qBAAIqgC,KAAJ,CAAU,yBAAV;;AAEAp/B,mBAAO4iC,aAAP,CAAqB,KAAKF,MAA1B;AACA,iBAAKA,MAAL,GAAc,IAAd;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;ACtFL;;0JAHA;AACA;;IAIaljC,sB,WAAAA,sB;;;;;qCAETqjC,O,oBAAQC,M,EAAQ;AACZA,eAAOC,mBAAP,GAA6B,YAA7B;AACA,YAAIC,QAAQ,IAAIC,sCAAJ,CAAuBH,MAAvB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBwB,KAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACRL;;0JAHA;AACA;;IAIazjC,qB,WAAAA,qB;;;;;oCAETsjC,O,oBAAQC,M,EAAQ;AACZ,YAAIE,QAAQ,IAAIC,sCAAJ,CAAuBH,MAAvB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBwB,KAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCVL;AACA;;AAEA;;;;AAEA,IAAME,uBAAuB,gCAA7B;AACA,IAAMC,qBAAqB,QAA3B;;IAEaF,kB,WAAAA,kB;AAET,gCAAYH,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI7B,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgB9B,OAAhB;AACA,kBAAK+B,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,aAAKG,QAAL,GAAgBV,OAAOC,mBAAP,IAA8BG,oBAA9C;AACA,aAAKO,MAAL,GAAcX,OAAOY,iBAAP,IAA4BP,kBAA1C;;AAEA,aAAKQ,YAAL,GAAoBb,OAAOc,QAA3B;AACA7kC,iBAAIqgC,KAAJ,CAAU,4CAA4C,KAAKuE,YAA3D;AACH;;iCAEDE,wB,qCAAyBC,e,EAAiB;AACtC,eAAO,CAAC,6BAAD,EAAgC,0CAAhC,EAA4E,iCAA5E,EAA+GC,IAA/G,CAAoH,UAAU9gB,IAAV,EAAgB;AACvI,mBAAO6gB,gBAAgB/hC,cAAhB,CAA+BkhB,IAA/B,CAAP;AACH,SAFM,CAAP;AAGH,K;;iCAED+gB,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AACxB,iBAAK8D,MAAL,CAAY,iBAAZ;AACH,SAFD,MAEO;AACH,gBAAI,CAACjkC,OAAOkkC,OAAZ,EAAqB;AACjB,uBAAO,KAAKD,MAAL,CAAY,sBAAZ,CAAP;AACH;;AAED,gBAAIH,kBAAkB9jC,OAAOkkC,OAAP,CAAeC,OAAf,CAAuB,qBAAvB,EAA8CC,QAApE;AACA,gBAAI,KAAKP,wBAAL,CAA8BC,eAA9B,MAAmD,KAAvD,EAA8D;AAC1D,uBAAO,KAAKG,MAAL,CAAY,+BAAZ,CAAP;AACH;AACD,iBAAKI,MAAL,GAAcH,QAAQI,YAAR,CAAqBC,IAArB,CAA0BzB,OAAO3C,GAAjC,EAAsC,KAAKsD,MAA3C,EAAmD,KAAKD,QAAxD,CAAd;AACA,gBAAI,KAAKa,MAAT,EAAiB;AACbtlC,yBAAIqgC,KAAJ,CAAU,yDAAV;;AAEA,qBAAKoF,kBAAL,GAA0B,KAAKC,aAAL,CAAmB3C,IAAnB,CAAwB,IAAxB,CAA1B;AACA,qBAAK4C,uBAAL,GAA+B,KAAKC,kBAAL,CAAwB7C,IAAxB,CAA6B,IAA7B,CAA/B;;AAEA,qBAAKuC,MAAL,CAAYtC,gBAAZ,CAA6B,MAA7B,EAAqC,KAAKyC,kBAA1C,EAA8D,KAA9D;AACA,qBAAKH,MAAL,CAAYtC,gBAAZ,CAA6B,WAA7B,EAA0C,KAAK2C,uBAA/C,EAAwE,KAAxE;AACH,aARD,MAQO;AACH,qBAAKT,MAAL,CAAY,4BAAZ;AACH;AACJ;AACD,eAAO,KAAKW,OAAZ;AACH,K;;iCAMDD,kB,+BAAmBE,K,EAAO;AACtB,YAAIA,MAAM1E,GAAN,CAAU15B,OAAV,CAAkB,KAAKk9B,YAAvB,MAAyC,CAA7C,EAAgD;AAC5C,iBAAKmB,QAAL,CAAc,EAAE3E,KAAK0E,MAAM1E,GAAb,EAAd;AACH;AACJ,K;;iCACDsE,a,0BAAcM,O,EAAS;AACnB,aAAKd,MAAL,CAAYc,OAAZ;AACH,K;;iCAEDD,Q,qBAASzR,I,EAAM;AACX,aAAK2R,QAAL;;AAEAjmC,iBAAIqgC,KAAJ,CAAU,mEAAV;AACA,aAAKkE,QAAL,CAAcjQ,IAAd;AACH,K;;iCACD4Q,M,mBAAOc,O,EAAS;AACZ,aAAKC,QAAL;;AAEAjmC,iBAAIojC,KAAJ,CAAU4C,OAAV;AACA,aAAKxB,OAAL,CAAa,IAAI/iC,KAAJ,CAAUukC,OAAV,CAAb;AACH,K;;iCAEDE,K,oBAAQ;AACJ,aAAKD,QAAL;AACH,K;;iCAEDA,Q,uBAAW;AACP,YAAI,KAAKX,MAAT,EAAgB;AACZtlC,qBAAIqgC,KAAJ,CAAU,uCAAV;AACA,iBAAKiF,MAAL,CAAYa,mBAAZ,CAAgC,MAAhC,EAAwC,KAAKV,kBAA7C,EAAiE,KAAjE;AACA,iBAAKH,MAAL,CAAYa,mBAAZ,CAAgC,WAAhC,EAA6C,KAAKR,uBAAlD,EAA2E,KAA3E;AACA,iBAAKL,MAAL,CAAYY,KAAZ;AACH;AACD,aAAKZ,MAAL,GAAc,IAAd;AACH,K;;;;4BAtCa;AACV,mBAAO,KAAKjB,QAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;ACxDL;;;;;;+eAHA;AACA;;IAIa+B,a,WAAAA,a;;;AACT,iCACE;AAAA,+FADsE,EACtE;AAAA,oBADWhD,KACX,QADWA,KACX;AAAA,oBADkBiD,iBAClB,QADkBA,iBAClB;AAAA,oBADqCC,SACrC,QADqCA,SACrC;AAAA,oBADgD5W,KAChD,QADgDA,KAChD;AAAA,oBADuD6T,aACvD,QADuDA,aACvD;;AAAA;;AACG,oBAAI,CAACH,KAAL,EAAW;AACRpjC,iCAAIojC,KAAJ,CAAU,kCAAV;AACA,8BAAM,IAAI3hC,KAAJ,CAAU,OAAV,CAAN;AACH;;AAJH,6DAME,kBAAM4kC,qBAAqBjD,KAA3B,CANF;;AAQE,sBAAKlf,IAAL,GAAY,eAAZ;;AAEA,sBAAKkf,KAAL,GAAaA,KAAb;AACA,sBAAKiD,iBAAL,GAAyBA,iBAAzB;AACA,sBAAKC,SAAL,GAAiBA,SAAjB;;AAEA,sBAAK5W,KAAL,GAAaA,KAAb;AACA,sBAAK6T,aAAL,GAAqBA,aAArB;AAfF;AAgBD;;;EAlB8B9hC,K;;;;;;;;;;;;;;;;;;;ACFnC;;0JAHA;AACA;;IAIa8kC,K,WAAAA,K;AAET,mBAAYriB,IAAZ,EAAkB;AAAA;;AACd,aAAKsiB,KAAL,GAAatiB,IAAb;AACA,aAAKuiB,UAAL,GAAkB,EAAlB;AACH;;oBAED7F,U,uBAAWD,E,EAAI;AACX,aAAK8F,UAAL,CAAgBniC,IAAhB,CAAqBq8B,EAArB;AACH,K;;oBAEDG,a,0BAAcH,E,EAAI;AACd,YAAIiB,MAAM,KAAK6E,UAAL,CAAgBC,SAAhB,CAA0B;AAAA,mBAAQC,SAAShG,EAAjB;AAAA,SAA1B,CAAV;AACA,YAAIiB,OAAO,CAAX,EAAc;AACV,iBAAK6E,UAAL,CAAgBngC,MAAhB,CAAuBs7B,GAAvB,EAA4B,CAA5B;AACH;AACJ,K;;oBAEDgF,K,oBAAiB;AACb5mC,iBAAIqgC,KAAJ,CAAU,2BAA2B,KAAKmG,KAA1C;AACA,aAAK,IAAIpkC,IAAI,CAAb,EAAgBA,IAAI,KAAKqkC,UAAL,CAAgBpkC,MAApC,EAA4CD,GAA5C,EAAiD;AAAA;;AAC7C,+BAAKqkC,UAAL,EAAgBrkC,CAAhB;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;;;;AC5BL;AACA;;AAEA,IAAMykC,QAAQ;AACVjD;AAAA;AAAA;AAAA;;AAAA;AAAA;AAAA;;AAAA;AAAA,MAAa,UAAUjD,EAAV,EAAcP,QAAd,EAAwB;AACjC,eAAOwD,YAAYjD,EAAZ,EAAgBP,QAAhB,CAAP;AACH,KAFD,CADU;AAIVyD;AAAA;AAAA;AAAA;;AAAA;AAAA;AAAA;;AAAA;AAAA,MAAe,UAAUiD,MAAV,EAAkB;AAC7B,eAAOjD,cAAciD,MAAd,CAAP;AACH,KAFD;AAJU,CAAd;;AASA,IAAIC,UAAU,KAAd;AACA,IAAIC,UAAU,IAAd;;IAEanmC,M,WAAAA,M;;;;;WAEFomC,Q,uBAAW;AACdF,kBAAU,IAAV;AACH,K;;WAoBMG,iB,8BAAkBC,U,EAAY;AACjCH,kBAAUG,UAAV;AACH,K;;;;4BApBqB;AAClB,gBAAI,CAACJ,OAAL,EAAc;AACV,uBAAOK,QAAP;AACH;AACJ;;;4BAEyB;AACtB,gBAAI,CAACL,OAAD,IAAY,OAAO9lC,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAOomC,YAAP;AACH;AACJ;;;4BAE2B;AACxB,gBAAI,CAACN,OAAD,IAAY,OAAO9lC,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAOqmC,cAAP;AACH;AACJ;;;4BAM2B;AACxB,gBAAI,CAACP,OAAD,IAAY,OAAO9lC,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAO+lC,WAAWO,cAAlB;AACH;AACJ;;;4BAEkB;AACf,gBAAI,CAACR,OAAL,EAAc;AACV,uBAAOF,KAAP;AACH;AACJ;;;;;;;;;;;;;;;;;;;;;;;AClDL;;AACA;;0JAJA;AACA;;IAKaW,e,WAAAA,e;;;;;8BAET1D,O,oBAAQC,M,EAAQ;AACZ,YAAI0D,QAAQ,IAAIC,0BAAJ,CAAiB3D,MAAjB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBgF,KAAhB,CAAP;AACH,K;;8BAEDvG,Q,qBAASE,G,EAAK;AACVphC,iBAAIqgC,KAAJ,CAAU,0BAAV;;AAEA,YAAI;AACAqH,uCAAaC,YAAb,CAA0BvG,GAA1B;AACA,mBAAOoB,QAAQC,OAAR,EAAP;AACH,SAHD,CAIA,OAAOzgC,CAAP,EAAU;AACN,mBAAOwgC,QAAQ8B,MAAR,CAAetiC,CAAf,CAAP;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;qjBCvBL;AACA;;AAEA;;;;AAEA,IAAM4lC,iBAAiB,KAAvB;;IAEaF,Y,WAAAA,Y;AAET,0BAAY3D,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI7B,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgB9B,OAAhB;AACA,kBAAK+B,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,aAAKzB,kBAAL,GAA0B,KAAKC,QAAL,CAAcC,IAAd,CAAmB,IAAnB,CAA1B;AACA9hC,eAAO+hC,gBAAP,CAAwB,SAAxB,EAAmC,KAAKH,kBAAxC,EAA4D,KAA5D;;AAEA,aAAKf,MAAL,GAAc7gC,OAAO8gC,QAAP,CAAgBC,aAAhB,CAA8B,QAA9B,CAAd;;AAEA;AACA,aAAKF,MAAL,CAAYG,KAAZ,CAAkBC,UAAlB,GAA+B,QAA/B;AACA,aAAKJ,MAAL,CAAYG,KAAZ,CAAkBE,QAAlB,GAA6B,UAA7B;AACA,aAAKL,MAAL,CAAYG,KAAZ,CAAkBG,OAAlB,GAA4B,MAA5B;AACA,aAAKN,MAAL,CAAYG,KAAZ,CAAkBI,KAAlB,GAA0B,CAA1B;AACA,aAAKP,MAAL,CAAYG,KAAZ,CAAkBK,MAAlB,GAA2B,CAA3B;;AAEArhC,eAAO8gC,QAAP,CAAgBY,IAAhB,CAAqBC,WAArB,CAAiC,KAAKd,MAAtC;AACH;;2BAEDmD,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AACxB,iBAAK8D,MAAL,CAAY,iBAAZ;AACH,SAFD,MAGK;AACD,gBAAI2C,UAAU9D,OAAO+D,oBAAP,IAA+BF,cAA7C;AACA5nC,qBAAIqgC,KAAJ,CAAU,0CAAV,EAAsDwH,OAAtD;AACA,iBAAKlE,MAAL,GAAc1iC,OAAO8mC,UAAP,CAAkB,KAAKC,QAAL,CAAcjF,IAAd,CAAmB,IAAnB,CAAlB,EAA4C8E,OAA5C,CAAd;AACA,iBAAK/F,MAAL,CAAYS,GAAZ,GAAkBwB,OAAO3C,GAAzB;AACH;;AAED,eAAO,KAAKyE,OAAZ;AACH,K;;2BAMDE,Q,qBAASzR,I,EAAM;AACX,aAAK2R,QAAL;;AAEAjmC,iBAAIqgC,KAAJ,CAAU,qDAAV;AACA,aAAKkE,QAAL,CAAcjQ,IAAd;AACH,K;;2BACD4Q,M,mBAAOc,O,EAAS;AACZ,aAAKC,QAAL;;AAEAjmC,iBAAIojC,KAAJ,CAAU4C,OAAV;AACA,aAAKxB,OAAL,CAAa,IAAI/iC,KAAJ,CAAUukC,OAAV,CAAb;AACH,K;;2BAEDE,K,oBAAQ;AACJ,aAAKD,QAAL;AACH,K;;2BAEDA,Q,uBAAW;AACP,YAAI,KAAKnE,MAAT,EAAiB;AACb9hC,qBAAIqgC,KAAJ,CAAU,uBAAV;;AAEAp/B,mBAAOklC,mBAAP,CAA2B,SAA3B,EAAsC,KAAKtD,kBAA3C,EAA+D,KAA/D;AACA5hC,mBAAOgnC,YAAP,CAAoB,KAAKtE,MAAzB;AACA1iC,mBAAO8gC,QAAP,CAAgBY,IAAhB,CAAqBuF,WAArB,CAAiC,KAAKpG,MAAtC;;AAEA,iBAAK6B,MAAL,GAAc,IAAd;AACA,iBAAK7B,MAAL,GAAc,IAAd;AACA,iBAAKe,kBAAL,GAA0B,IAA1B;AACH;AACJ,K;;2BAEDmF,Q,uBAAW;AACPhoC,iBAAIqgC,KAAJ,CAAU,sBAAV;AACA,aAAK6E,MAAL,CAAY,wBAAZ;AACH,K;;2BAEDpC,Q,qBAAS9gC,C,EAAG;AACRhC,iBAAIqgC,KAAJ,CAAU,sBAAV;;AAEA,YAAI,KAAKsD,MAAL,IACA3hC,EAAEihC,MAAF,KAAa,KAAKkF,OADlB,IAEAnmC,EAAEkhC,MAAF,KAAa,KAAKpB,MAAL,CAAYqB,aAF7B,EAGE;AACE,gBAAI/B,MAAMp/B,EAAEsyB,IAAZ;AACA,gBAAI8M,GAAJ,EAAS;AACL,qBAAK2E,QAAL,CAAc,EAAE3E,KAAKA,GAAP,EAAd;AACH,aAFD,MAGK;AACD,qBAAK8D,MAAL,CAAY,6BAAZ;AACH;AACJ;AACJ,K;;iBAMMyC,Y,yBAAavG,G,EAAK;AACrBphC,iBAAIqgC,KAAJ,CAAU,2BAAV;AACA,YAAIp/B,OAAOmnC,YAAX,EAAyB;AACrBhH,kBAAMA,OAAOngC,OAAOmmC,QAAP,CAAgBiB,IAA7B;AACA,gBAAIjH,GAAJ,EAAS;AACLphC,yBAAIqgC,KAAJ,CAAU,0DAAV;AACAp/B,uBAAOqnC,MAAP,CAAc5E,WAAd,CAA0BtC,GAA1B,EAA+BgG,SAASmB,QAAT,GAAoB,IAApB,GAA2BnB,SAASoB,IAAnE;AACH;AACJ;AACJ,K;;;;4BAtEa;AACV,mBAAO,KAAKnE,QAAZ;AACH;;;4BAuDa;AACV,mBAAO+C,SAASmB,QAAT,GAAoB,IAApB,GAA2BnB,SAASoB,IAA3C;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBCvGL;AACA;;AAEA;;;;IAEapoC,kB,WAAAA,kB;AACT,kCAAa;AAAA;;AACT,aAAKqF,KAAL,GAAa,EAAb;AACH;;iCAEDgjC,O,oBAAQ3U,G,EAAK;AACT9zB,iBAAIqgC,KAAJ,CAAU,4BAAV,EAAwCvM,GAAxC;AACA,eAAO,KAAKruB,KAAL,CAAWquB,GAAX,CAAP;AACH,K;;iCAED4U,O,oBAAQ5U,G,EAAK6U,K,EAAM;AACf3oC,iBAAIqgC,KAAJ,CAAU,4BAAV,EAAwCvM,GAAxC;AACA,aAAKruB,KAAL,CAAWquB,GAAX,IAAkB6U,KAAlB;AACH,K;;iCAEDC,U,uBAAW9U,G,EAAI;AACX9zB,iBAAIqgC,KAAJ,CAAU,+BAAV,EAA2CvM,GAA3C;AACA,eAAO,KAAKruB,KAAL,CAAWquB,GAAX,CAAP;AACH,K;;iCAMDA,G,gBAAI+U,K,EAAO;AACP,eAAO/mC,OAAOgnC,mBAAP,CAA2B,KAAKrjC,KAAhC,EAAuCojC,KAAvC,CAAP;AACH,K;;;;4BANY;AACT,mBAAO/mC,OAAOgnC,mBAAP,CAA2B,KAAKrjC,KAAhC,EAAuCpD,MAA9C;AACH;;;;;;;;;;;;;;;;;;;;;;;AC3BL;;AACA;;;;;;AAEO,IAAM0mC,8BAAW,4BAAY,EAAE9M,mBAAF,EAAO+M,2BAAP,EAAgBnS,qBAAhB,EAAsBpe,yBAAtB,EAA8BmO,+BAA9B,EAAyChc,6BAAzC,EAAmDq+B,iDAAnD,EAAZ,CAAjB,C;;;;;;;;;;;;;;;;;kBCEiBC,W;;AAFxB;;0JAHA;AACA;;AAIe,SAASA,WAAT,OAA8F;AAAA,QAAvEjN,GAAuE,QAAvEA,GAAuE;AAAA,QAAlE+M,OAAkE,QAAlEA,OAAkE;AAAA,QAAzDnS,IAAyD,QAAzDA,IAAyD;AAAA,QAAnDpe,MAAmD,QAAnDA,MAAmD;AAAA,QAA3CmO,SAA2C,QAA3CA,SAA2C;AAAA,QAAhChc,QAAgC,QAAhCA,QAAgC;AAAA,QAAtBq+B,kBAAsB,QAAtBA,kBAAsB;;AACzG;AAAA;AAAA;AAAA;;AAAA,iBAEWE,QAFX,qBAEoBC,GAFpB,EAEyB;AACjBppC,qBAAIqgC,KAAJ,CAAU,mBAAV;AACA,gBAAI;AACA,oBAAIgJ,QAAQpN,IAAIC,GAAJ,CAAQv3B,KAAR,CAAcykC,GAAd,CAAZ;AACA,uBAAO;AACHE,4BAAQD,MAAMpM,SADX;AAEHsM,6BAASF,MAAMnM;AAFZ,iBAAP;AAIH,aAND,CAME,OAAOl7B,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,CAAV;AACH;AACJ,SAbL;;AAAA,iBAeWwnC,WAfX,wBAeuBJ,GAfvB,EAe4BtV,GAf5B,EAeiC2V,MAfjC,EAeyCC,QAfzC,EAemDC,SAfnD,EAe8DC,GAf9D,EAemEC,eAfnE,EAeoF;AAC5E7pC,qBAAIqgC,KAAJ,CAAU,sBAAV;;AAEA,gBAAI;AACA,oBAAIvM,IAAIuC,GAAJ,KAAY,KAAhB,EAAuB;AACnB,wBAAIvC,IAAI9xB,CAAJ,IAAS8xB,IAAIlxB,CAAjB,EAAoB;AAChBkxB,8BAAMkV,QAAQxZ,MAAR,CAAesE,GAAf,CAAN;AACH,qBAFD,MAEO,IAAIA,IAAIgW,GAAJ,IAAWhW,IAAIgW,GAAJ,CAAQznC,MAAvB,EAA+B;AAClC,4BAAIuf,MAAMhX,SAASkpB,IAAIgW,GAAJ,CAAQ,CAAR,CAAT,CAAV;AACAhW,8BAAM+C,KAAKC,uBAAL,CAA6BlV,GAA7B,CAAN;AACH,qBAHM,MAGA;AACH5hB,iCAAIojC,KAAJ,CAAU,oDAAV,EAAgEtP,GAAhE;AACA,+BAAO0O,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,8BAAV,CAAf,CAAP;AACH;AACJ,iBAVD,MAUO,IAAIqyB,IAAIuC,GAAJ,KAAY,IAAhB,EAAsB;AACzB,wBAAIvC,IAAI8C,GAAJ,IAAW9C,IAAIhuB,CAAf,IAAoBguB,IAAIrqB,CAA5B,EAA+B;AAC3BqqB,8BAAMkV,QAAQxZ,MAAR,CAAesE,GAAf,CAAN;AACH,qBAFD,MAEO;AACH9zB,iCAAIojC,KAAJ,CAAU,mDAAV,EAA+DtP,GAA/D;AACA,+BAAO0O,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACJ,iBAPM,MAOA;AACHzB,6BAAIojC,KAAJ,CAAU,4CAAV,EAAwDtP,OAAOA,IAAIuC,GAAnE;AACA,2BAAOmM,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,SAAkCqyB,IAAIuC,GAAhD,CAAf,CAAP;AACH;;AAED,uBAAO0S,SAASgB,YAAT,CAAsBX,GAAtB,EAA2BtV,GAA3B,EAAgC2V,MAAhC,EAAwCC,QAAxC,EAAkDC,SAAlD,EAA6DC,GAA7D,EAAkEC,eAAlE,CAAP;AACH,aAxBD,CAwBE,OAAO7nC,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,KAAKA,EAAEgkC,OAAP,IAAkBhkC,CAA5B;AACA,uBAAOwgC,QAAQ8B,MAAR,CAAe,uBAAf,CAAP;AACH;AACJ,SA9CL;;AAAA,iBAgDW0F,qBAhDX,kCAgDiCZ,GAhDjC,EAgDsCK,MAhDtC,EAgD8CC,QAhD9C,EAgDwDC,SAhDxD,EAgDmEC,GAhDnE,EAgDwEC,eAhDxE,EAgDyF;AACjF,gBAAI,CAACF,SAAL,EAAgB;AACZA,4BAAY,CAAZ;AACH;;AAED,gBAAI,CAACC,GAAL,EAAU;AACNA,sBAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAN;AACH;;AAED,gBAAIL,UAAUR,SAASI,QAAT,CAAkBC,GAAlB,EAAuBG,OAArC;;AAEA,gBAAI,CAACA,QAAQ9L,GAAb,EAAkB;AACdz9B,yBAAIojC,KAAJ,CAAU,gDAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;AACD,gBAAI8nC,QAAQ9L,GAAR,KAAgBgM,MAApB,EAA4B;AACxBzpC,yBAAIojC,KAAJ,CAAU,gDAAV,EAA4DmG,QAAQ9L,GAApE;AACA,uBAAO+E,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,8BAA8B8nC,QAAQ9L,GAAhD,CAAf,CAAP;AACH;;AAED,gBAAI,CAAC8L,QAAQ5L,GAAb,EAAkB;AACd39B,yBAAIojC,KAAJ,CAAU,6CAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,gBAAIwoC,gBAAgBV,QAAQ5L,GAAR,KAAgB+L,QAAhB,IAA6B3+B,MAAM4nB,OAAN,CAAc4W,QAAQ5L,GAAtB,KAA8B4L,QAAQ5L,GAAR,CAAYj2B,OAAZ,CAAoBgiC,QAApB,KAAiC,CAAhH;AACA,gBAAI,CAACO,aAAL,EAAoB;AAChBjqC,yBAAIojC,KAAJ,CAAU,kDAAV,EAA8DmG,QAAQ5L,GAAtE;AACA,uBAAO6E,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gCAAgC8nC,QAAQ5L,GAAlD,CAAf,CAAP;AACH;AACD,gBAAI4L,QAAQW,GAAR,IAAeX,QAAQW,GAAR,KAAgBR,QAAnC,EAA6C;AACzC1pC,yBAAIojC,KAAJ,CAAU,6CAAV,EAAyDmG,QAAQW,GAAjE;AACA,uBAAO1H,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAA2B8nC,QAAQW,GAA7C,CAAf,CAAP;AACH;;AAED,gBAAI,CAACL,eAAL,EAAsB;AAClB,oBAAIM,WAAWP,MAAMD,SAArB;AACA,oBAAIS,WAAWR,MAAMD,SAArB;;AAEA,oBAAI,CAACJ,QAAQtL,GAAb,EAAkB;AACdj+B,6BAAIojC,KAAJ,CAAU,6CAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,oBAAI0oC,WAAWZ,QAAQtL,GAAvB,EAA4B;AACxBj+B,6BAAIojC,KAAJ,CAAU,6CAAV,EAAyDmG,QAAQtL,GAAjE;AACA,2BAAOuE,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAA2B8nC,QAAQtL,GAA7C,CAAf,CAAP;AACH;;AAED,oBAAIsL,QAAQvL,GAAR,IAAemM,WAAWZ,QAAQvL,GAAtC,EAA2C;AACvCh+B,6BAAIojC,KAAJ,CAAU,6CAAV,EAAyDmG,QAAQvL,GAAjE;AACA,2BAAOwE,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAA2B8nC,QAAQvL,GAA7C,CAAf,CAAP;AACH;;AAED,oBAAI,CAACuL,QAAQ74B,GAAb,EAAkB;AACd1Q,6BAAIojC,KAAJ,CAAU,6CAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQ74B,GAAR,GAAc05B,QAAlB,EAA4B;AACxBpqC,6BAAIojC,KAAJ,CAAU,2CAAV,EAAuDmG,QAAQ74B,GAA/D;AACA,2BAAO8xB,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,wBAAwB8nC,QAAQ74B,GAA1C,CAAf,CAAP;AACH;AACJ;;AAED,mBAAO8xB,QAAQC,OAAR,CAAgB8G,OAAhB,CAAP;AACH,SA/GL;;AAAA,iBAiHWQ,YAjHX,yBAiHwBX,GAjHxB,EAiH6BtV,GAjH7B,EAiHkC2V,MAjHlC,EAiH0CC,QAjH1C,EAiHoDC,SAjHpD,EAiH+DC,GAjH/D,EAiHoEC,eAjHpE,EAiHqF;;AAE7E,mBAAOd,SAASiB,qBAAT,CAA+BZ,GAA/B,EAAoCK,MAApC,EAA4CC,QAA5C,EAAsDC,SAAtD,EAAiEC,GAAjE,EAAsEC,eAAtE,EAAuFQ,IAAvF,CAA4F,mBAAW;AAC1G,oBAAI;AACA,wBAAI,CAACpO,IAAIC,GAAJ,CAAQ1L,MAAR,CAAe4Y,GAAf,EAAoBtV,GAApB,EAAyBmV,kBAAzB,CAAL,EAAmD;AAC/CjpC,iCAAIojC,KAAJ,CAAU,oDAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;;AAED,2BAAO8nC,OAAP;AACH,iBAPD,CAOE,OAAOvnC,CAAP,EAAU;AACRhC,6BAAIojC,KAAJ,CAAUphC,KAAKA,EAAEgkC,OAAP,IAAkBhkC,CAA5B;AACA,2BAAOwgC,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACJ,aAZM,CAAP;AAaH,SAhIL;;AAAA,iBAkIWkrB,UAlIX,uBAkIsBgc,KAlItB,EAkI6B/b,GAlI7B,EAkIkC;AAC1B,gBAAI;AACA,uBAAOnU,OAAOiB,IAAP,CAAYiT,UAAZ,CAAuBgc,KAAvB,EAA8B/b,GAA9B,CAAP;AACH,aAFD,CAEE,OAAO5qB,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,CAAV;AACH;AACJ,SAxIL;;AAAA,iBA0IWsoC,cA1IX,2BA0I0B3B,KA1I1B,EA0IiC;AACzB,gBAAI;AACA,uBAAO/hB,UAAU+hB,KAAV,CAAP;AACH,aAFD,CAEE,OAAO3mC,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,CAAV;AACH;AACJ,SAhJL;;AAAA;AAAA;AAkJH;;;;;;;;;;;;;;;;;;;;ACrJD;;AACA;;0JAJA;AACA;;IAKauoC,W,WAAAA,W;AACT,2BAIE;AAAA,YAHEC,sBAGF,uEAH2B,IAG3B;AAAA,YAFEC,kBAEF,uEAFuB5pC,eAAO0mC,cAE9B;AAAA,YADEmD,UACF,uEADe,IACf;;AAAA;;AACE,YAAIF,0BAA0Bz/B,MAAM4nB,OAAN,CAAc6X,sBAAd,CAA9B,EACA;AACI,iBAAKG,aAAL,GAAqBH,uBAAuBpmC,KAAvB,EAArB;AACH,SAHD,MAKA;AACI,iBAAKumC,aAAL,GAAqB,EAArB;AACH;AACD,aAAKA,aAAL,CAAmBrmC,IAAnB,CAAwB,kBAAxB;AACA,YAAIomC,UAAJ,EAAgB;AACZ,iBAAKC,aAAL,CAAmBrmC,IAAnB,CAAwB,iBAAxB;AACH;;AAED,aAAKsmC,eAAL,GAAuBH,kBAAvB;AACA,aAAKI,WAAL,GAAmBH,UAAnB;AACH;;0BAEDI,O,oBAAQ1J,G,EAAKiI,K,EAAO;AAAA;;AAChB,YAAI,CAACjI,GAAL,EAAS;AACLphC,qBAAIojC,KAAJ,CAAU,oCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,4BAAV,EAAwCe,GAAxC;;AAEA,eAAO,IAAIoB,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;;AAEpC,gBAAIyG,MAAM,IAAI,MAAKH,eAAT,EAAV;AACAG,gBAAIvF,IAAJ,CAAS,KAAT,EAAgBpE,GAAhB;;AAEA,gBAAI4J,sBAAsB,MAAKL,aAA/B;AACA,gBAAID,aAAa,MAAKG,WAAtB;;AAEAE,gBAAIrI,MAAJ,GAAa,YAAW;AACpB1iC,yBAAIqgC,KAAJ,CAAU,qDAAV,EAAiE0K,IAAIE,MAArE;;AAEA,oBAAIF,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuB3E,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAIyE,SAAS,iBAAb,EAAgC;AAC5BV,uCAAWK,GAAX,EAAgBV,IAAhB,CAAqB5H,OAArB,EAA8B6B,MAA9B;AACA;AACH;;AAED,4BAAI8G,KAAJ,EAAW;AACP,gCAAI;AACA3I,wCAAQzc,KAAKrhB,KAAL,CAAWomC,IAAIQ,YAAf,CAAR;AACA;AACH,6BAHD,CAIA,OAAOvpC,CAAP,EAAU;AACNhC,yCAAIojC,KAAJ,CAAU,kDAAV,EAA8DphC,EAAEgkC,OAAhE;AACA1B,uCAAOtiC,CAAP;AACA;AACH;AACJ;AACJ;;AAEDsiC,2BAAO7iC,MAAM,oCAAoCypC,WAApC,GAAkD,cAAlD,GAAmE9J,GAAzE,CAAP;AACH,iBA9BD,MA+BK;AACDkD,2BAAO7iC,MAAMspC,IAAIS,UAAJ,GAAiB,IAAjB,GAAwBT,IAAIE,MAA5B,GAAqC,GAA3C,CAAP;AACH;AACJ,aArCD;;AAuCAF,gBAAIU,OAAJ,GAAc,YAAW;AACrBzrC,yBAAIojC,KAAJ,CAAU,oCAAV;AACAkB,uBAAO7iC,MAAM,eAAN,CAAP;AACH,aAHD;;AAKA,gBAAI4nC,KAAJ,EAAW;AACPrpC,yBAAIqgC,KAAJ,CAAU,iEAAV;AACA0K,oBAAIW,gBAAJ,CAAqB,eAArB,EAAsC,YAAYrC,KAAlD;AACH;;AAED0B,gBAAItH,IAAJ;AACH,SA1DM,CAAP;AA2DH,K;;0BAEDkI,Q,qBAASvK,G,EAAKmI,O,EAAS;AAAA;;AACnB,YAAI,CAACnI,GAAL,EAAS;AACLphC,qBAAIojC,KAAJ,CAAU,qCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,6BAAV,EAAyCe,GAAzC;;AAEA,eAAO,IAAIoB,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;;AAEpC,gBAAIyG,MAAM,IAAI,OAAKH,eAAT,EAAV;AACAG,gBAAIvF,IAAJ,CAAS,MAAT,EAAiBpE,GAAjB;;AAEA,gBAAI4J,sBAAsB,OAAKL,aAA/B;;AAEAI,gBAAIrI,MAAJ,GAAa,YAAW;AACpB1iC,yBAAIqgC,KAAJ,CAAU,sDAAV,EAAkE0K,IAAIE,MAAtE;;AAEA,oBAAIF,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuB3E,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAIyE,KAAJ,EAAW;AACP,gCAAI;AACA3I,wCAAQzc,KAAKrhB,KAAL,CAAWomC,IAAIQ,YAAf,CAAR;AACA;AACH,6BAHD,CAIA,OAAOvpC,CAAP,EAAU;AACNhC,yCAAIojC,KAAJ,CAAU,mDAAV,EAA+DphC,EAAEgkC,OAAjE;AACA1B,uCAAOtiC,CAAP;AACA;AACH;AACJ;AACJ;;AAEDsiC,2BAAO7iC,MAAM,oCAAoCypC,WAApC,GAAkD,cAAlD,GAAmE9J,GAAzE,CAAP;AACA;AACH;;AAED,oBAAI2J,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuB3E,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAIyE,KAAJ,EAAW;AACP,gCAAI;AACA,oCAAI7B,UAAUvjB,KAAKrhB,KAAL,CAAWomC,IAAIQ,YAAf,CAAd;AACA,oCAAIhC,WAAWA,QAAQnG,KAAvB,EAA8B;AAC1BpjC,6CAAIojC,KAAJ,CAAU,2CAAV,EAAuDmG,QAAQnG,KAA/D;AACAkB,2CAAO,IAAI7iC,KAAJ,CAAU8nC,QAAQnG,KAAlB,CAAP;AACA;AACH;AACJ,6BAPD,CAQA,OAAOphC,CAAP,EAAU;AACNhC,yCAAIojC,KAAJ,CAAU,mDAAV,EAA+DphC,EAAEgkC,OAAjE;AACA1B,uCAAOtiC,CAAP;AACA;AACH;AACJ;AACJ;AACJ;;AAEDsiC,uBAAO7iC,MAAMspC,IAAIS,UAAJ,GAAiB,IAAjB,GAAwBT,IAAIE,MAA5B,GAAqC,GAA3C,CAAP;AACH,aA7DD;;AA+DAF,gBAAIU,OAAJ,GAAc,YAAW;AACrBzrC,yBAAIojC,KAAJ,CAAU,qCAAV;AACAkB,uBAAO7iC,MAAM,eAAN,CAAP;AACH,aAHD;;AAKA,gBAAIkhC,OAAO,EAAX;AACA,iBAAI,IAAI7O,GAAR,IAAeyV,OAAf,EAAwB;;AAEpB,oBAAIZ,QAAQY,QAAQzV,GAAR,CAAZ;;AAEA,oBAAI6U,KAAJ,EAAW;;AAEP,wBAAIhG,KAAKtgC,MAAL,GAAc,CAAlB,EAAqB;AACjBsgC,gCAAQ,GAAR;AACH;;AAEDA,4BAAQr9B,mBAAmBwuB,GAAnB,CAAR;AACA6O,4BAAQ,GAAR;AACAA,4BAAQr9B,mBAAmBqjC,KAAnB,CAAR;AACH;AACJ;;AAEDoC,gBAAIW,gBAAJ,CAAqB,cAArB,EAAqC,mCAArC;AACAX,gBAAItH,IAAJ,CAASd,IAAT;AACH,SA9FM,CAAP;AA+FH,K;;;;;;;;;;;;;;;;;;;;;;;;;ACzML;AACA;;AAEA,IAAIiJ,YAAY;AACZvL,SADY,mBACL,CAAE,CADG;AAEZwL,QAFY,kBAEN,CAAE,CAFI;AAGZC,QAHY,kBAGN,CAAE,CAHI;AAIZ1I,SAJY,mBAIL,CAAE;AAJG,CAAhB;;AAOA,IAAM2I,OAAO,CAAb;AACA,IAAMC,QAAQ,CAAd;AACA,IAAMC,OAAO,CAAb;AACA,IAAMC,OAAO,CAAb;AACA,IAAMC,QAAQ,CAAd;;AAEA,IAAIC,eAAJ;AACA,IAAIC,cAAJ;;IAEarsC,G,WAAAA,G;;;;;QAOFwF,K,oBAAO;AACV6mC,gBAAQH,IAAR;AACAE,iBAASR,SAAT;AACH,K;;QA+BMvL,K,oBAAc;AACjB,YAAIgM,SAASF,KAAb,EAAmB;AAAA,8CADPG,IACO;AADPA,oBACO;AAAA;;AACfF,mBAAO/L,KAAP,CAAal9B,KAAb,CAAmBipC,MAAnB,EAA2BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA3B;AACH;AACJ,K;;QACMT,I,mBAAa;AAChB,YAAIQ,SAASH,IAAb,EAAkB;AAAA,+CADPI,IACO;AADPA,oBACO;AAAA;;AACdF,mBAAOP,IAAP,CAAY1oC,KAAZ,CAAkBipC,MAAlB,EAA0BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA1B;AACH;AACJ,K;;QACMR,I,mBAAa;AAChB,YAAIO,SAASJ,IAAb,EAAkB;AAAA,+CADPK,IACO;AADPA,oBACO;AAAA;;AACdF,mBAAON,IAAP,CAAY3oC,KAAZ,CAAkBipC,MAAlB,EAA0BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA1B;AACH;AACJ,K;;QACMlJ,K,oBAAc;AACjB,YAAIiJ,SAASL,KAAb,EAAmB;AAAA,+CADPM,IACO;AADPA,oBACO;AAAA;;AACfF,mBAAOhJ,KAAP,CAAajgC,KAAb,CAAmBipC,MAAnB,EAA2BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA3B;AACH;AACJ,K;;;;4BA3DiB;AAAC,mBAAOP,IAAP;AAAY;;;4BACZ;AAAC,mBAAOC,KAAP;AAAa;;;4BACf;AAAC,mBAAOC,IAAP;AAAY;;;4BACb;AAAC,mBAAOC,IAAP;AAAY;;;4BACZ;AAAC,mBAAOC,KAAP;AAAa;;;4BAOf;AACd,mBAAOE,KAAP;AACH,S;0BACgB1D,K,EAAM;AACnB,gBAAIoD,QAAQpD,KAAR,IAAiBA,SAASwD,KAA9B,EAAoC;AAChCE,wBAAQ1D,KAAR;AACH,aAFD,MAGK;AACD,sBAAM,IAAIlnC,KAAJ,CAAU,mBAAV,CAAN;AACH;AACJ;;;4BAEkB;AACf,mBAAO2qC,MAAP;AACH,S;0BACiBzD,K,EAAM;AACpB,gBAAI,CAACA,MAAMtI,KAAP,IAAgBsI,MAAMkD,IAA1B,EAAgC;AAC5B;AACAlD,sBAAMtI,KAAN,GAAcsI,MAAMkD,IAApB;AACH;;AAED,gBAAIlD,MAAMtI,KAAN,IAAesI,MAAMkD,IAArB,IAA6BlD,MAAMmD,IAAnC,IAA2CnD,MAAMvF,KAArD,EAA2D;AACvDgJ,yBAASzD,KAAT;AACH,aAFD,MAGK;AACD,sBAAM,IAAIlnC,KAAJ,CAAU,gBAAV,CAAN;AACH;AACJ;;;;;;AAwBLzB,IAAIwF,KAAJ,G;;;;;;;;;;;;;;;;;;;qjBClFA;AACA;;AAEA;;AACA;;;;AAEA,IAAMgnC,sBAAsB,kCAA5B;;IAEajsC,e,WAAAA,e;AACT,6BAAYksC,QAAZ,EAAqD;AAAA,YAA/BC,eAA+B,uEAAbnC,wBAAa;;AAAA;;AACjD,YAAI,CAACkC,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,wDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,CAAoB,CAAC,0BAAD,CAApB,CAApB;AACH;;8BAsBDG,W,0BAAc;AAAA;;AACV,YAAI,KAAKF,SAAL,CAAetH,QAAnB,EAA6B;AACzBrlC,qBAAIqgC,KAAJ,CAAU,+DAAV;AACA,mBAAOmC,QAAQC,OAAR,CAAgB,KAAKkK,SAAL,CAAetH,QAA/B,CAAP;AACH;;AAED,YAAI,CAAC,KAAKyH,WAAV,EAAuB;AACnB9sC,qBAAIojC,KAAJ,CAAU,iFAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,oDAAV,CAAf,CAAP;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,oDAAV,EAAgE,KAAKyM,WAArE;;AAEA,eAAO,KAAKF,YAAL,CAAkB9B,OAAlB,CAA0B,KAAKgC,WAA/B,EACFzC,IADE,CACG,oBAAY;AACdrqC,qBAAIqgC,KAAJ,CAAU,4CAAV;AACA,kBAAKsM,SAAL,CAAetH,QAAf,GAA0BA,QAA1B;AACA,mBAAOA,QAAP;AACH,SALE,CAAP;AAMH,K;;8BAED0H,S,wBAAY;AACR,eAAO,KAAKC,oBAAL,CAA0B,QAA1B,CAAP;AACH,K;;8BAEDC,wB,uCAA2B;AACvB,eAAO,KAAKD,oBAAL,CAA0B,wBAA1B,CAAP;AACH,K;;8BAEDE,mB,kCAAsB;AAClB,eAAO,KAAKF,oBAAL,CAA0B,mBAA1B,CAAP;AACH,K;;8BAEDG,gB,+BAAgC;AAAA,YAAfC,QAAe,uEAAN,IAAM;;AAC5B,eAAO,KAAKJ,oBAAL,CAA0B,gBAA1B,EAA4CI,QAA5C,CAAP;AACH,K;;8BAEDC,qB,oCAAwB;AACpB,eAAO,KAAKL,oBAAL,CAA0B,sBAA1B,EAAkD,IAAlD,CAAP;AACH,K;;8BAEDM,qB,oCAAwB;AACpB,eAAO,KAAKN,oBAAL,CAA0B,sBAA1B,EAAkD,IAAlD,CAAP;AACH,K;;8BAEDO,qB,oCAAwB;AACpB,eAAO,KAAKP,oBAAL,CAA0B,qBAA1B,EAAiD,IAAjD,CAAP;AACH,K;;8BAEDQ,e,8BAAkB;AACd,eAAO,KAAKR,oBAAL,CAA0B,UAA1B,EAAsC,IAAtC,CAAP;AACH,K;;8BAEDA,oB,iCAAqB9oB,I,EAAsB;AAAA,YAAhBkpB,QAAgB,uEAAP,KAAO;;AACvCptC,iBAAIqgC,KAAJ,CAAU,8CAA8Cnc,IAAxD;;AAEA,eAAO,KAAK2oB,WAAL,GAAmBxC,IAAnB,CAAwB,oBAAY;AACvCrqC,qBAAIqgC,KAAJ,CAAU,wDAAV;;AAEA,gBAAIgF,SAASnhB,IAAT,MAAmB/iB,SAAvB,EAAkC;;AAE9B,oBAAIisC,aAAa,IAAjB,EAAuB;AACnBptC,6BAAI8rC,IAAJ,CAAS,sFAAsF5nB,IAA/F;AACA,2BAAO/iB,SAAP;AACH,iBAHD,MAIK;AACDnB,6BAAIojC,KAAJ,CAAU,6EAA6Elf,IAAvF;AACA,0BAAM,IAAIziB,KAAJ,CAAU,wCAAwCyiB,IAAlD,CAAN;AACH;AACJ;;AAED,mBAAOmhB,SAASnhB,IAAT,CAAP;AACH,SAhBM,CAAP;AAiBH,K;;8BAEDupB,c,6BAAiB;AAAA;;AACb,YAAI,KAAKd,SAAL,CAAee,WAAnB,EAAgC;AAC5B1tC,qBAAIqgC,KAAJ,CAAU,qEAAV;AACA,mBAAOmC,QAAQC,OAAR,CAAgB,KAAKkK,SAAL,CAAee,WAA/B,CAAP;AACH;;AAED,eAAO,KAAKV,oBAAL,CAA0B,UAA1B,EAAsC3C,IAAtC,CAA2C,oBAAY;AAC1DrqC,qBAAIqgC,KAAJ,CAAU,mDAAV,EAA+DsN,QAA/D;;AAEA,mBAAO,OAAKf,YAAL,CAAkB9B,OAAlB,CAA0B6C,QAA1B,EAAoCtD,IAApC,CAAyC,kBAAU;AACtDrqC,yBAAIqgC,KAAJ,CAAU,kDAAV,EAA8DuN,MAA9D;;AAEA,oBAAI,CAACA,OAAO1tB,IAAZ,EAAkB;AACdlgB,6BAAIojC,KAAJ,CAAU,wDAAV;AACA,0BAAM,IAAI3hC,KAAJ,CAAU,wBAAV,CAAN;AACH;;AAED,uBAAKkrC,SAAL,CAAee,WAAf,GAA6BE,OAAO1tB,IAApC;AACA,uBAAO,OAAKysB,SAAL,CAAee,WAAtB;AACH,aAVM,CAAP;AAWH,SAdM,CAAP;AAeH,K;;;;4BApHiB;AACd,gBAAI,CAAC,KAAKG,YAAV,EAAwB;AACpB,oBAAI,KAAKlB,SAAL,CAAeG,WAAnB,EAAgC;AAC5B,yBAAKe,YAAL,GAAoB,KAAKlB,SAAL,CAAeG,WAAnC;AACH,iBAFD,MAGK;AACD,yBAAKe,YAAL,GAAoB,KAAKlB,SAAL,CAAemB,SAAnC;;AAEA,wBAAI,KAAKD,YAAL,IAAqB,KAAKA,YAAL,CAAkBnmC,OAAlB,CAA0B8kC,mBAA1B,IAAiD,CAA1E,EAA6E;AACzE,4BAAI,KAAKqB,YAAL,CAAkB,KAAKA,YAAL,CAAkBxrC,MAAlB,GAA2B,CAA7C,MAAoD,GAAxD,EAA6D;AACzD,iCAAKwrC,YAAL,IAAqB,GAArB;AACH;AACD,6BAAKA,YAAL,IAAqBrB,mBAArB;AACH;AACJ;AACJ;;AAED,mBAAO,KAAKqB,YAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBCrCL;AACA;;AAEA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;IAEa5tC,U,WAAAA,U;AACT,0BAA2B;AAAA,YAAfwsC,QAAe,uEAAJ,EAAI;;AAAA;;AACvB,YAAIA,oBAAoBvsC,sCAAxB,EAA4C;AACxC,iBAAKysC,SAAL,GAAiBF,QAAjB;AACH,SAFD,MAGK;AACD,iBAAKE,SAAL,GAAiB,IAAIzsC,sCAAJ,CAAuBusC,QAAvB,CAAjB;AACH;AACJ;;yBAmBDsB,mB,kCAQE;AAAA;;AAAA,uFAFoH,EAEpH;AAAA,YAPEC,aAOF,QAPEA,aAOF;AAAA,YAPiBC,KAOjB,QAPiBA,KAOjB;AAAA,YAPwBrJ,YAOxB,QAPwBA,YAOxB;AAAA,YAHEtQ,IAGF,QAHEA,IAGF;AAAA,YAHQ5E,KAGR,QAHQA,KAGR;AAAA,YAHewe,MAGf,QAHeA,MAGf;AAAA,YAHuB9L,OAGvB,QAHuBA,OAGvB;AAAA,YAHgC+L,OAGhC,QAHgCA,OAGhC;AAAA,YAHyCC,UAGzC,QAHyCA,UAGzC;AAAA,YAHqDC,aAGrD,QAHqDA,aAGrD;AAAA,YAHoEC,UAGpE,QAHoEA,UAGpE;AAAA,YAHgFC,UAGhF,QAHgFA,UAGhF;AAAA,YAFEC,QAEF,QAFEA,QAEF;AAAA,YAFYxH,OAEZ,QAFYA,OAEZ;AAAA,YAFqByH,WAErB,QAFqBA,WAErB;AAAA,YAFkCC,aAElC,QAFkCA,aAElC;AAAA,YAFiDC,gBAEjD,QAFiDA,gBAEjD;AAAA,YAFmEC,gBAEnE,QAFmEA,gBAEnE;AAAA,YAFqFC,YAErF,QAFqFA,YAErF;AAAA,YAFmGC,YAEnG,QAFmGA,YAEnG;;AAAA,YADEC,UACF;;AACE/uC,iBAAIqgC,KAAJ,CAAU,gCAAV;;AAEA,YAAIc,YAAY,KAAKwL,SAAL,CAAexL,SAA/B;AACA6M,wBAAgBA,iBAAiB,KAAKrB,SAAL,CAAeqB,aAAhD;AACAC,gBAAQA,SAAS,KAAKtB,SAAL,CAAesB,KAAhC;AACArJ,uBAAeA,gBAAgB,KAAK+H,SAAL,CAAe/H,YAA9C;;AAEA;AACAsJ,iBAASA,UAAU,KAAKvB,SAAL,CAAeuB,MAAlC;AACA9L,kBAAUA,WAAW,KAAKuK,SAAL,CAAevK,OAApC;AACA+L,kBAAUA,WAAW,KAAKxB,SAAL,CAAewB,OAApC;AACAC,qBAAaA,cAAc,KAAKzB,SAAL,CAAeyB,UAA1C;AACAG,qBAAaA,cAAc,KAAK5B,SAAL,CAAe4B,UAA1C;AACAC,mBAAWA,YAAY,KAAK7B,SAAL,CAAe6B,QAAtC;AACAE,wBAAgBA,iBAAiB,KAAK/B,SAAL,CAAe+B,aAAhD;AACAC,2BAAmBA,oBAAoB,KAAKhC,SAAL,CAAegC,gBAAtD;AACAC,2BAAmBA,oBAAoB,KAAKjC,SAAL,CAAeiC,gBAAtD;;AAEA,YAAId,YAAY,KAAKnB,SAAL,CAAemB,SAA/B;;AAEA,YAAIkB,6BAAcC,MAAd,CAAqBjB,aAArB,KAAuCA,kBAAkB,MAA7D,EAAqE;AACjE,mBAAOxL,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6CAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsBjC,wBAAtB,GAAiD5C,IAAjD,CAAsD,eAAO;AAChErqC,qBAAIqgC,KAAJ,CAAU,iEAAV,EAA6Ee,GAA7E;;AAEA,gBAAI+N,gBAAgB,IAAIH,4BAAJ,CAAkB;AAClC5N,wBADkC;AAElCD,oCAFkC;AAGlCyD,0CAHkC;AAIlCoJ,4CAJkC;AAKlCC,4BALkC;AAMlC3Z,sBAAMA,QAAQ5E,KANoB;AAOlCoe,oCAPkC;AAQlCI,8BARkC,EAQ1B9L,gBAR0B,EAQjB+L,gBARiB,EAQRC,sBARQ,EAQIC,4BARJ,EAQmBC,sBARnB,EAQ+BC,sBAR/B;AASlCC,kCATkC,EASxBxH,gBATwB,EASfyH,wBATe,EASFE,kCATE,EASgBC,kCAThB,EASkCC,0BATlC,EASgDH,4BAThD;AAUlCU,+BAAe,MAAKzC,SAAL,CAAeyC,aAVI;AAWlCN;AAXkC,aAAlB,CAApB;;AAcA,gBAAIO,cAAcF,cAAczf,KAAhC;AACAqf,yBAAaA,cAAc,MAAKO,WAAhC;;AAEA,mBAAOP,WAAWQ,GAAX,CAAeF,YAAY7T,EAA3B,EAA+B6T,YAAYG,eAAZ,EAA/B,EAA8DnF,IAA9D,CAAmE,YAAM;AAC5E,uBAAO8E,aAAP;AACH,aAFM,CAAP;AAGH,SAvBM,CAAP;AAwBH,K;;yBAEDM,uB,oCAAwBrO,G,EAAK2N,U,EAAiC;AAAA,YAArBW,WAAqB,uEAAP,KAAO;;AAC1D1vC,iBAAIqgC,KAAJ,CAAU,oCAAV;;AAEA,YAAIsP,WAAW,KAAKhD,SAAL,CAAe+B,aAAf,KAAiC,OAAjC,IACV,CAAC,KAAK/B,SAAL,CAAe+B,aAAhB,IAAiCM,6BAAcC,MAAd,CAAqB,KAAKtC,SAAL,CAAeqB,aAApC,CADtC;AAEA,YAAI4B,YAAYD,WAAW,GAAX,GAAiB,GAAjC;;AAEA,YAAIE,WAAW,IAAIC,8BAAJ,CAAmB1O,GAAnB,EAAwBwO,SAAxB,CAAf;;AAEA,YAAI,CAACC,SAASngB,KAAd,EAAqB;AACjB1vB,qBAAIojC,KAAJ,CAAU,0DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAEDstC,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,YAAIS,WAAWL,cAAcX,WAAWiB,MAAX,CAAkBjN,IAAlB,CAAuBgM,UAAvB,CAAd,GAAmDA,WAAW9P,GAAX,CAAe8D,IAAf,CAAoBgM,UAApB,CAAlE;;AAEA,eAAOgB,SAASF,SAASngB,KAAlB,EAAyB2a,IAAzB,CAA8B,6BAAqB;AACtD,gBAAI,CAAC4F,iBAAL,EAAwB;AACpBjwC,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,oCAAV,CAAN;AACH;;AAED,gBAAIiuB,QAAQwgB,yBAAYC,iBAAZ,CAA8BF,iBAA9B,CAAZ;AACA,mBAAO,EAACvgB,YAAD,EAAQmgB,kBAAR,EAAP;AACH,SARM,CAAP;AASH,K;;yBAEDO,qB,kCAAsBhP,G,EAAK2N,U,EAAY;AAAA;;AACnC/uC,iBAAIqgC,KAAJ,CAAU,kCAAV;;AAEA,eAAO,KAAKoP,uBAAL,CAA6BrO,GAA7B,EAAkC2N,UAAlC,EAA8C,IAA9C,EAAoD1E,IAApD,CAAyD,iBAAuB;AAAA,gBAArB3a,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,SAAdA,QAAc;;AACnF7vC,qBAAIqgC,KAAJ,CAAU,oFAAV;AACA,mBAAO,OAAKgQ,UAAL,CAAgBC,sBAAhB,CAAuC5gB,KAAvC,EAA8CmgB,QAA9C,CAAP;AACH,SAHM,CAAP;AAIH,K;;yBAEDU,oB,mCAEE;AAAA;;AAAA,wFAF6G,EAE7G;AAAA,YAFoBlC,aAEpB,SAFoBA,aAEpB;AAAA,YAFmC/Z,IAEnC,SAFmCA,IAEnC;AAAA,YAFyC5E,KAEzC,SAFyCA,KAEzC;AAAA,YAFgD8gB,wBAEhD,SAFgDA,wBAEhD;AAAA,YAF0E7B,gBAE1E,SAF0EA,gBAE1E;AAAA,YAF4FE,YAE5F,SAF4FA,YAE5F;;AAAA,YADEE,UACF;;AACE/uC,iBAAIqgC,KAAJ,CAAU,iCAAV;;AAEAmQ,mCAA2BA,4BAA4B,KAAK7D,SAAL,CAAe6D,wBAAtE;AACA7B,2BAAmBA,oBAAoB,KAAKhC,SAAL,CAAegC,gBAAtD;;AAEA,eAAO,KAAKO,gBAAL,CAAsB5B,qBAAtB,GAA8CjD,IAA9C,CAAmD,eAAO;AAC7D,gBAAI,CAACjJ,GAAL,EAAU;AACNphC,yBAAIojC,KAAJ,CAAU,uEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,yBAAV,CAAN;AACH;;AAEDzB,qBAAIqgC,KAAJ,CAAU,gEAAV,EAA4Ee,GAA5E;;AAEA,gBAAI4F,UAAU,IAAIyJ,8BAAJ,CAAmB;AAC7BrP,wBAD6B;AAE7BiN,4CAF6B;AAG7BmC,kEAH6B;AAI7Blc,sBAAMA,QAAQ5E,KAJe;AAK7Bif,kDAL6B;AAM7BE;AAN6B,aAAnB,CAAd;;AASA,gBAAI6B,eAAe1J,QAAQtX,KAA3B;AACA,gBAAIghB,YAAJ,EAAkB;AACd1wC,yBAAIqgC,KAAJ,CAAU,uEAAV;;AAEA0O,6BAAaA,cAAc,OAAKO,WAAhC;AACAP,2BAAWQ,GAAX,CAAemB,aAAalV,EAA5B,EAAgCkV,aAAalB,eAAb,EAAhC;AACH;;AAED,mBAAOxI,OAAP;AACH,SA1BM,CAAP;AA2BH,K;;yBAED2J,wB,qCAAyBvP,G,EAAK2N,U,EAAiC;AAAA,YAArBW,WAAqB,uEAAP,KAAO;;AAC3D1vC,iBAAIqgC,KAAJ,CAAU,qCAAV;;AAEA,YAAIwP,WAAW,IAAIe,gCAAJ,CAAoBxP,GAApB,CAAf;AACA,YAAI,CAACyO,SAASngB,KAAd,EAAqB;AACjB1vB,qBAAIqgC,KAAJ,CAAU,2DAAV;;AAEA,gBAAIwP,SAASzM,KAAb,EAAoB;AAChBpjC,yBAAI8rC,IAAJ,CAAS,2DAAT,EAAsE+D,SAASzM,KAA/E;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI8B,4BAAJ,CAAkByJ,QAAlB,CAAf,CAAP;AACH;;AAED,mBAAOrN,QAAQC,OAAR,CAAgB,EAACthC,oBAAD,EAAY0uC,kBAAZ,EAAhB,CAAP;AACH;;AAED,YAAIgB,WAAWhB,SAASngB,KAAxB;;AAEAqf,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,YAAIS,WAAWL,cAAcX,WAAWiB,MAAX,CAAkBjN,IAAlB,CAAuBgM,UAAvB,CAAd,GAAmDA,WAAW9P,GAAX,CAAe8D,IAAf,CAAoBgM,UAApB,CAAlE;AACA,eAAOgB,SAASc,QAAT,EAAmBxG,IAAnB,CAAwB,6BAAqB;AAChD,gBAAI,CAAC4F,iBAAL,EAAwB;AACpBjwC,yBAAIojC,KAAJ,CAAU,yEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,oCAAV,CAAN;AACH;;AAED,gBAAIiuB,QAAQohB,aAAMX,iBAAN,CAAwBF,iBAAxB,CAAZ;;AAEA,mBAAO,EAACvgB,YAAD,EAAQmgB,kBAAR,EAAP;AACH,SATM,CAAP;AAUH,K;;yBAEDkB,sB,mCAAuB3P,G,EAAK2N,U,EAAY;AAAA;;AACpC/uC,iBAAIqgC,KAAJ,CAAU,mCAAV;;AAEA,eAAO,KAAKsQ,wBAAL,CAA8BvP,GAA9B,EAAmC2N,UAAnC,EAA+C,IAA/C,EAAqD1E,IAArD,CAA0D,iBAAuB;AAAA,gBAArB3a,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,SAAdA,QAAc;;AACpF,gBAAIngB,KAAJ,EAAW;AACP1vB,yBAAIqgC,KAAJ,CAAU,qFAAV;AACA,uBAAO,OAAKgQ,UAAL,CAAgBW,uBAAhB,CAAwCthB,KAAxC,EAA+CmgB,QAA/C,CAAP;AACH,aAHD,MAIK;AACD7vC,yBAAIqgC,KAAJ,CAAU,wFAAV;AACA,uBAAOwP,QAAP;AACH;AACJ,SATM,CAAP;AAUH,K;;yBAEDoB,e,4BAAgBlC,U,EAAY;AACxB/uC,iBAAIqgC,KAAJ,CAAU,4BAAV;;AAEA0O,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,eAAOwB,aAAMG,eAAN,CAAsBlC,UAAtB,EAAkC,KAAKtC,QAAL,CAAcyE,aAAhD,CAAP;AACH,K;;;;4BA5MiB;AACd,mBAAO,KAAKzE,QAAL,CAAcsC,UAArB;AACH;;;4BACgB;AACb,mBAAO,KAAKtC,QAAL,CAAc0E,SAArB;AACH;;;4BACsB;AACnB,mBAAO,KAAK1E,QAAL,CAAc2E,eAArB;AACH;;;4BAEc;AACX,mBAAO,KAAKzE,SAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKuC,gBAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;;;qjBCtCL;AACA;;AAEA;;AACA;;AACA;;AACA;;;;AAEA,IAAM1C,sBAAsB,kCAA5B;;AAEA,IAAM6E,sBAAsB,UAA5B;AACA,IAAMC,eAAe,QAArB;AACA,IAAMC,uBAAuB,KAAK,EAAlC,C,CAAsC;AACtC,IAAMC,4BAA4B,KAAK,CAAvC;;IAEatxC,kB,WAAAA,kB;AACT,kCAmBQ;AAAA,uFAAJ,EAAI;AAAA,YAjBJ4tC,SAiBI,QAjBJA,SAiBI;AAAA,YAjBOhB,WAiBP,QAjBOA,WAiBP;AAAA,YAjBoBzH,QAiBpB,QAjBoBA,QAiBpB;AAAA,YAjB8BqI,WAiB9B,QAjB8BA,WAiB9B;AAAA,YAfJvM,SAeI,QAfJA,SAeI;AAAA,YAfOiO,aAeP,QAfOA,aAeP;AAAA,sCAfsBpB,aAetB;AAAA,YAfsBA,aAetB,sCAfsCqD,mBAetC;AAAA,8BAf2DpD,KAe3D;AAAA,YAf2DA,KAe3D,8BAfmEqD,YAenE;AAAA,YAdJ1M,YAcI,QAdJA,YAcI;AAAA,YAdU4L,wBAcV,QAdUA,wBAcV;AAAA,YAZJtC,MAYI,QAZJA,MAYI;AAAA,YAZI9L,OAYJ,QAZIA,OAYJ;AAAA,YAZa+L,OAYb,QAZaA,OAYb;AAAA,YAZsBC,UAYtB,QAZsBA,UAYtB;AAAA,YAZkCG,UAYlC,QAZkCA,UAYlC;AAAA,YAZ8CC,QAY9C,QAZ8CA,QAY9C;AAAA,YAZwDE,aAYxD,QAZwDA,aAYxD;AAAA,yCAVJ+C,oBAUI;AAAA,YAVJA,oBAUI,yCAVmB,IAUnB;AAAA,qCAVyBC,YAUzB;AAAA,YAVyBA,YAUzB,qCAVwC,IAUxC;AAAA,sCATJR,aASI;AAAA,YATJA,aASI,sCATYK,oBASZ;AAAA,kCATkC5H,SASlC;AAAA,YATkCA,SASlC,kCAT8C6H,yBAS9C;AAAA,yCARJG,iBAQI;AAAA,YARJA,iBAQI,yCARgB,IAQhB;AAAA,mCANJ5C,UAMI;AAAA,YANJA,UAMI,mCANS,IAAI5uC,0CAAJ,EAMT;AAAA,yCALJyxC,qBAKI;AAAA,YALJA,qBAKI,yCALoBC,oCAKpB;AAAA,yCAJJC,mBAII;AAAA,YAJJA,mBAII,yCAJkBvxC,gCAIlB;AAAA,yCAFJouC,gBAEI;AAAA,YAFJA,gBAEI,yCAFe,EAEf;AAAA,yCADJC,gBACI;AAAA,YADJA,gBACI,yCADe,EACf;;AAAA;;AAEJ,aAAKmD,UAAL,GAAkBjE,SAAlB;AACA,aAAKD,YAAL,GAAoBf,WAApB;AACA,aAAKkF,SAAL,GAAiB3M,QAAjB;AACA,aAAK4M,YAAL,GAAoBvE,WAApB;;AAEA,aAAKlM,UAAL,GAAkBL,SAAlB;AACA,aAAK+Q,cAAL,GAAsB9C,aAAtB;AACA,aAAK+C,cAAL,GAAsBnE,aAAtB;AACA,aAAKoE,MAAL,GAAcnE,KAAd;AACA,aAAKoE,aAAL,GAAqBzN,YAArB;AACA,aAAK0N,yBAAL,GAAiC9B,wBAAjC;;AAEA,aAAK+B,OAAL,GAAerE,MAAf;AACA,aAAKsE,QAAL,GAAgBpQ,OAAhB;AACA,aAAKqQ,QAAL,GAAgBtE,OAAhB;AACA,aAAKuE,WAAL,GAAmBtE,UAAnB;AACA,aAAKuE,WAAL,GAAmBpE,UAAnB;AACA,aAAKqE,SAAL,GAAiBpE,QAAjB;AACA,aAAKqE,cAAL,GAAsBnE,aAAtB;;AAEA,aAAKoE,qBAAL,GAA6B,CAAC,CAACrB,oBAA/B;AACA,aAAKsB,aAAL,GAAqB,CAAC,CAACrB,YAAvB;AACA,aAAKsB,cAAL,GAAsB9B,aAAtB;AACA,aAAK+B,UAAL,GAAkBtJ,SAAlB;AACA,aAAKuJ,kBAAL,GAA0BvB,iBAA1B;;AAEA,aAAKrC,WAAL,GAAmBP,UAAnB;AACA,aAAKsB,UAAL,GAAkB,IAAIuB,qBAAJ,CAA0B,IAA1B,CAAlB;AACA,aAAK1C,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,IAAxB,CAAxB;;AAEA,aAAKqB,iBAAL,GAAyB,QAAOxE,gBAAP,yCAAOA,gBAAP,OAA4B,QAA5B,GAAuCA,gBAAvC,GAA0D,EAAnF;AACA,aAAKyE,iBAAL,GAAyB,QAAOxE,gBAAP,yCAAOA,gBAAP,OAA4B,QAA5B,GAAuCA,gBAAvC,GAA0D,EAAnF;AACH;;AAED;;;;;4BACgB;AACZ,mBAAO,KAAKpN,UAAZ;AACH,S;0BACamH,K,EAAO;AACjB,gBAAI,CAAC,KAAKnH,UAAV,EAAsB;AAClB;AACA,qBAAKA,UAAL,GAAkBmH,KAAlB;AACH,aAHD,MAIK;AACD3oC,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,sCAAV,CAAN;AACH;AACJ;;;4BACmB;AAChB,mBAAO,KAAKywC,cAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;;4BACW;AACR,mBAAO,KAAKC,MAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKC,yBAAZ;AACH;;AAGD;;;;4BACa;AACT,mBAAO,KAAKC,OAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKC,QAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKC,QAAZ;AACH;;;4BACgB;AACb,mBAAO,KAAKC,WAAZ;AACH;;;4BACgB;AACb,mBAAO,KAAKC,WAAZ;AACH;;;4BACc;AACX,mBAAO,KAAKC,SAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;AAGD;;;;4BACgB;AACZ,mBAAO,KAAKd,UAAZ;AACH,S;0BACapJ,K,EAAO;AACjB,gBAAI,CAAC,KAAKoJ,UAAV,EAAsB;AAClB;AACA,qBAAKA,UAAL,GAAkBpJ,KAAlB;AACH,aAHD,MAIK;AACD3oC,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,sCAAV,CAAN;AACH;AACJ;;;4BACiB;AACd,gBAAI,CAAC,KAAKosC,YAAV,EAAwB;AACpB,qBAAKA,YAAL,GAAoB,KAAKC,SAAzB;;AAEA,oBAAI,KAAKD,YAAL,IAAqB,KAAKA,YAAL,CAAkBnmC,OAAlB,CAA0B8kC,mBAA1B,IAAiD,CAA1E,EAA6E;AACzE,wBAAI,KAAKqB,YAAL,CAAkB,KAAKA,YAAL,CAAkBxrC,MAAlB,GAA2B,CAA7C,MAAoD,GAAxD,EAA6D;AACzD,6BAAKwrC,YAAL,IAAqB,GAArB;AACH;AACD,yBAAKA,YAAL,IAAqBrB,mBAArB;AACH;AACJ;;AAED,mBAAO,KAAKqB,YAAZ;AACH;;AAED;;;;4BACe;AACX,mBAAO,KAAKmE,SAAZ;AACH,S;0BACYrJ,K,EAAO;AAChB,iBAAKqJ,SAAL,GAAiBrJ,KAAjB;AACH;;;4BAEiB;AACd,mBAAO,KAAKsJ,YAAZ;AACH,S;0BACetJ,K,EAAO;AACnB,iBAAKsJ,YAAL,GAAoBtJ,KAApB;AACH;;AAED;;;;4BAC2B;AACvB,mBAAO,KAAKmK,qBAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKC,UAAZ;AACH;;;4BACuB;AACpB,mBAAO,KAAKC,kBAAZ;AACH;;;4BAEgB;AACb,mBAAO,KAAK5D,WAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKe,UAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKnB,gBAAZ;AACH;;AAED;;;;4BACuB;AACnB,mBAAO,KAAKiE,iBAAZ;AACH,S;0BACoBxK,K,EAAO;AACxB,gBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA8B;AAC1B,qBAAKwK,iBAAL,GAAyBxK,KAAzB;AACH,aAFD,MAEO;AACH,qBAAKwK,iBAAL,GAAyB,EAAzB;AACH;AACJ;;AAED;;;;4BACuB;AACnB,mBAAO,KAAKC,iBAAZ;AACH,S;0BACoBzK,K,EAAO;AACxB,gBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA8B;AAC1B,qBAAKyK,iBAAL,GAAyBzK,KAAzB;AACH,aAFD,MAEO;AACH,qBAAKyK,iBAAL,GAAyB,EAAzB;AACH;AACJ;;;;;;;;;;;;;;;;;;;;;;;ACxNL;;AACA;;0JAJA;AACA;;IAKaC,c,WAAAA,c;;;;;6BAETvP,O,oBAAQC,M,EAAQ;AACZ,YAAIE,QAAQ,IAAIqP,wBAAJ,CAAgBvP,MAAhB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBwB,KAAhB,CAAP;AACH,K;;6BAED/C,Q,qBAASE,G,EAAKmS,Q,EAAU3D,S,EAAW;AAC/B5vC,iBAAIqgC,KAAJ,CAAU,yBAAV;;AAEA,YAAI;AACAiT,qCAAYE,YAAZ,CAAyBpS,GAAzB,EAA8BmS,QAA9B,EAAwC3D,SAAxC;AACA,mBAAOpN,QAAQC,OAAR,EAAP;AACH,SAHD,CAIA,OAAOzgC,CAAP,EAAU;AACN,mBAAOwgC,QAAQ8B,MAAR,CAAetiC,CAAf,CAAP;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;qjBCvBL;AACA;;AAEA;;AACA;;;;AAEA,IAAMyxC,8BAA8B,GAApC;AACA,IAAMtP,uBAAuB,+DAA7B;AACA;;AAEA,IAAMC,qBAAqB,QAA3B;;IAEakP,W,WAAAA,W;AAET,yBAAYvP,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI7B,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgB9B,OAAhB;AACA,kBAAK+B,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,YAAII,SAASX,OAAOY,iBAAP,IAA4BP,kBAAzC;AACA,YAAIK,WAAWV,OAAOC,mBAAP,IAA8BG,oBAA7C;;AAEA,aAAKmB,MAAL,GAAcrkC,OAAOukC,IAAP,CAAY,EAAZ,EAAgBd,MAAhB,EAAwBD,QAAxB,CAAd;AACA,YAAI,KAAKa,MAAT,EAAiB;AACbtlC,qBAAIqgC,KAAJ,CAAU,8CAAV;AACA,iBAAKqT,yBAAL,GAAiCzyC,OAAO2iC,WAAP,CAAmB,KAAK+P,oBAAL,CAA0B5Q,IAA1B,CAA+B,IAA/B,CAAnB,EAAyD0Q,2BAAzD,CAAjC;AACH;AACJ;;0BAMDxO,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAAC,KAAKuB,MAAV,EAAkB;AACd,iBAAKJ,MAAL,CAAY,kDAAZ;AACH,SAFD,MAGK,IAAI,CAACnB,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AAC7B,iBAAK8D,MAAL,CAAY,uCAAZ;AACA,iBAAKA,MAAL,CAAY,iBAAZ;AACH,SAHI,MAIA;AACDllC,qBAAIqgC,KAAJ,CAAU,4CAAV;;AAEA,iBAAKuT,GAAL,GAAW7P,OAAOvI,EAAlB;AACA,gBAAI,KAAKoY,GAAT,EAAc;AACV3yC,uBAAO,mBAAmB8iC,OAAOvI,EAAjC,IAAuC,KAAK+F,SAAL,CAAewB,IAAf,CAAoB,IAApB,CAAvC;AACH;;AAED,iBAAKuC,MAAL,CAAYuO,KAAZ;AACA,iBAAKvO,MAAL,CAAYrkC,MAAZ,CAAmBmmC,QAAnB,GAA8BrD,OAAO3C,GAArC;AACH;;AAED,eAAO,KAAKyE,OAAZ;AACH,K;;0BAEDE,Q,qBAASzR,I,EAAM;AACXt0B,iBAAIqgC,KAAJ,CAAU,6DAAV;;AAEA,aAAK4F,QAAL;AACA,aAAK1B,QAAL,CAAcjQ,IAAd;AACH,K;;0BACD4Q,M,mBAAOc,O,EAAS;AACZhmC,iBAAIojC,KAAJ,CAAU,qBAAV,EAAiC4C,OAAjC;;AAEA,aAAKC,QAAL;AACA,aAAKzB,OAAL,CAAa,IAAI/iC,KAAJ,CAAUukC,OAAV,CAAb;AACH,K;;0BAEDE,K,oBAAQ;AACJ,aAAKD,QAAL,CAAc,KAAd;AACH,K;;0BAEDA,Q,qBAASsN,Q,EAAU;AACfvzC,iBAAIqgC,KAAJ,CAAU,qBAAV;;AAEAp/B,eAAO4iC,aAAP,CAAqB,KAAK6P,yBAA1B;AACA,aAAKA,yBAAL,GAAiC,IAAjC;;AAEA,eAAOzyC,OAAO,mBAAmB,KAAK2yC,GAA/B,CAAP;;AAEA,YAAI,KAAKtO,MAAL,IAAe,CAACiO,QAApB,EAA8B;AAC1B,iBAAKjO,MAAL,CAAYY,KAAZ;AACH;AACD,aAAKZ,MAAL,GAAc,IAAd;AACH,K;;0BAEDqO,oB,mCAAuB;AACnB,YAAI,CAAC,KAAKrO,MAAN,IAAgB,KAAKA,MAAL,CAAYwO,MAAhC,EAAwC;AACpC,iBAAK5O,MAAL,CAAY,qBAAZ;AACH;AACJ,K;;0BAED3D,S,sBAAUH,G,EAAKmS,Q,EAAU;AACrB,aAAKtN,QAAL,CAAcsN,QAAd;;AAEA,YAAInS,GAAJ,EAAS;AACLphC,qBAAIqgC,KAAJ,CAAU,8BAAV;AACA,iBAAK0F,QAAL,CAAc,EAAE3E,KAAKA,GAAP,EAAd;AACH,SAHD,MAIK;AACDphC,qBAAIqgC,KAAJ,CAAU,mDAAV;AACA,iBAAK6E,MAAL,CAAY,6BAAZ;AACH;AACJ,K;;gBAEMsO,Y,yBAAapS,G,EAAKmS,Q,EAAU3D,S,EAAW;AAC1C,YAAI3uC,OAAO8yC,MAAX,EAAmB;AACf3S,kBAAMA,OAAOngC,OAAOmmC,QAAP,CAAgBiB,IAA7B;AACA,gBAAIjH,GAAJ,EAAS;AACL,oBAAI9M,OAAO0f,uBAAWC,gBAAX,CAA4B7S,GAA5B,EAAiCwO,SAAjC,CAAX;;AAEA,oBAAItb,KAAK5E,KAAT,EAAgB;AACZ,wBAAIxL,OAAO,mBAAmBoQ,KAAK5E,KAAnC;AACA,wBAAIwR,WAAWjgC,OAAO8yC,MAAP,CAAc7vB,IAAd,CAAf;AACA,wBAAIgd,QAAJ,EAAc;AACVlhC,iCAAIqgC,KAAJ,CAAU,yDAAV;AACAa,iCAASE,GAAT,EAAcmS,QAAd;AACH,qBAHD,MAIK;AACDvzC,iCAAI8rC,IAAJ,CAAS,gEAAT;AACH;AACJ,iBAVD,MAWK;AACD9rC,6BAAI8rC,IAAJ,CAAS,0DAAT;AACH;AACJ;AACJ,SApBD,MAqBK;AACD9rC,qBAAI8rC,IAAJ,CAAS,0EAAT;AACH;AACJ,K;;;;4BAtGa;AACV,mBAAO,KAAKzH,QAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBChCL;AACA;;AAEA;;;;IAEa6P,iB,WAAAA,iB;;;;;gCAETpQ,O,sBAAU;AACN,eAAOtB,QAAQC,OAAR,CAAgB,IAAhB,CAAP;AACH,K;;gCAEDwC,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AACxBphC,qBAAIojC,KAAJ,CAAU,6CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iBAAV,CAAf,CAAP;AACH;;AAED,YAAIsiC,OAAOoQ,oBAAX,EAAiC;AAC7BlzC,mBAAOmmC,QAAP,CAAgB5oB,OAAhB,CAAwBulB,OAAO3C,GAA/B;AACH,SAFD,MAGK;AACDngC,mBAAOmmC,QAAP,GAAkBrD,OAAO3C,GAAzB;AACH;;AAED,eAAOoB,QAAQC,OAAR,EAAP;AACH,K;;;;4BAES;AACN,mBAAOxhC,OAAOmmC,QAAP,CAAgBiB,IAAvB;AACH;;;;;;;;;;;;;;;;;;;;;;;;;AC1BL;;AACA;;AACA;;AACA;;AACA;;AACA;;0JARA;AACA;;AASA,IAAM+L,iBAAiB,CAAC,OAAD,EAAU,SAAV,EAAqB,KAArB,EAA4B,KAA5B,EAAmC,KAAnC,EAA0C,KAA1C,EAAiD,KAAjD,EAAwD,QAAxD,CAAvB;;IAEavC,iB,WAAAA,iB;AAET,+BAAYpF,QAAZ,EAImC;AAAA,YAH/BqF,mBAG+B,uEAHTvxC,gCAGS;AAAA,YAF/B8zC,mBAE+B,uEAFTC,gCAES;AAAA,YAD/BC,QAC+B,uEADpBxL,kBACoB;AAAA,YAA/ByL,eAA+B,uEAAbC,wBAAa;;AAAA;;AAC/B,YAAI,CAAChI,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,iEAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKyC,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACA,aAAK+H,gBAAL,GAAwB,IAAIL,mBAAJ,CAAwB,KAAK1H,SAA7B,CAAxB;AACA,aAAKgI,SAAL,GAAiBJ,QAAjB;AACA,aAAKK,YAAL,GAAoB,IAAIJ,eAAJ,CAAoB,KAAK7H,SAAzB,CAApB;AACH;;gCAED2D,sB,mCAAuB5gB,K,EAAOmgB,Q,EAAU;AAAA;;AACpC7vC,iBAAIqgC,KAAJ,CAAU,0CAAV;;AAEA,eAAO,KAAKwU,oBAAL,CAA0BnlB,KAA1B,EAAiCmgB,QAAjC,EAA2CxF,IAA3C,CAAgD,oBAAY;AAC/DrqC,qBAAIqgC,KAAJ,CAAU,2DAAV;AACA,mBAAO,MAAKyU,eAAL,CAAqBplB,KAArB,EAA4BmgB,QAA5B,EAAsCxF,IAAtC,CAA2C,oBAAY;AAC1DrqC,yBAAIqgC,KAAJ,CAAU,4DAAV;AACA,uBAAO,MAAK0U,cAAL,CAAoBrlB,KAApB,EAA2BmgB,QAA3B,EAAqCxF,IAArC,CAA0C,oBAAY;AACzDrqC,6BAAIqgC,KAAJ,CAAU,4DAAV;AACA,2BAAOwP,QAAP;AACH,iBAHM,CAAP;AAIH,aANM,CAAP;AAOH,SATM,CAAP;AAUH,K;;gCAEDmB,uB,oCAAwBthB,K,EAAOmgB,Q,EAAU;AACrC,YAAIngB,MAAM8L,EAAN,KAAaqU,SAASngB,KAA1B,EAAiC;AAC7B1vB,qBAAIojC,KAAJ,CAAU,iEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAED;AACA;AACA;AACAzB,iBAAIqgC,KAAJ,CAAU,4DAAV;AACAwP,iBAASngB,KAAT,GAAiBA,MAAM4E,IAAvB;;AAEA,YAAIub,SAASzM,KAAb,EAAoB;AAChBpjC,qBAAI8rC,IAAJ,CAAS,+DAAT,EAA0E+D,SAASzM,KAAnF;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI8B,4BAAJ,CAAkByJ,QAAlB,CAAf,CAAP;AACH;;AAED,eAAOrN,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAEDgF,oB,iCAAqBnlB,K,EAAOmgB,Q,EAAU;AAClC,YAAIngB,MAAM8L,EAAN,KAAaqU,SAASngB,KAA1B,EAAiC;AAC7B1vB,qBAAIojC,KAAJ,CAAU,8DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMyR,SAAX,EAAsB;AAClBnhC,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,uBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMoe,SAAX,EAAsB;AAClB9tC,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,uBAAV,CAAf,CAAP;AACH;;AAED;AACA,YAAI,CAAC,KAAKkrC,SAAL,CAAemB,SAApB,EAA+B;AAC3B,iBAAKnB,SAAL,CAAemB,SAAf,GAA2Bpe,MAAMoe,SAAjC;AACH;AACD;AAHA,aAIK,IAAI,KAAKnB,SAAL,CAAemB,SAAf,IAA4B,KAAKnB,SAAL,CAAemB,SAAf,KAA6Bpe,MAAMoe,SAAnE,EAA8E;AAC/E9tC,yBAAIojC,KAAJ,CAAU,yFAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iDAAV,CAAf,CAAP;AACH;AACD;AACA,YAAI,CAAC,KAAKkrC,SAAL,CAAexL,SAApB,EAA+B;AAC3B,iBAAKwL,SAAL,CAAexL,SAAf,GAA2BzR,MAAMyR,SAAjC;AACH;AACD;AAHA,aAIK,IAAI,KAAKwL,SAAL,CAAexL,SAAf,IAA4B,KAAKwL,SAAL,CAAexL,SAAf,KAA6BzR,MAAMyR,SAAnE,EAA8E;AAC/EnhC,yBAAIojC,KAAJ,CAAU,yFAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iDAAV,CAAf,CAAP;AACH;;AAED;AACA;AACA;AACAzB,iBAAIqgC,KAAJ,CAAU,yDAAV;AACAwP,iBAASngB,KAAT,GAAiBA,MAAM4E,IAAvB;;AAEA,YAAIub,SAASzM,KAAb,EAAoB;AAChBpjC,qBAAI8rC,IAAJ,CAAS,4DAAT,EAAuE+D,SAASzM,KAAhF;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI8B,4BAAJ,CAAkByJ,QAAlB,CAAf,CAAP;AACH;;AAED,YAAIngB,MAAMslB,KAAN,IAAe,CAACnF,SAASoF,QAA7B,EAAuC;AACnCj1C,qBAAIojC,KAAJ,CAAU,wEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMslB,KAAP,IAAgBnF,SAASoF,QAA7B,EAAuC;AACnCj1C,qBAAIojC,KAAJ,CAAU,4EAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iCAAV,CAAf,CAAP;AACH;;AAED,YAAIiuB,MAAMwlB,aAAN,IAAuB,CAACrF,SAASsF,IAArC,EAA2C;AACvCn1C,qBAAIojC,KAAJ,CAAU,oEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,qBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMwlB,aAAP,IAAwBrF,SAASsF,IAArC,EAA2C;AACvCn1C,qBAAIojC,KAAJ,CAAU,wEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACouC,SAAS5B,KAAd,EAAqB;AACjB;AACA4B,qBAAS5B,KAAT,GAAiBve,MAAMue,KAAvB;AACH;;AAED,eAAOzL,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAEDkF,c,2BAAerlB,K,EAAOmgB,Q,EAAU;AAAA;;AAC5B,YAAIA,SAASuF,eAAb,EAA8B;AAC1Bp1C,qBAAIqgC,KAAJ,CAAU,uEAAV;;AAEAwP,qBAASwF,OAAT,GAAmB,KAAKvC,qBAAL,CAA2BjD,SAASwF,OAApC,CAAnB;;AAEA,gBAAI3lB,MAAMof,YAAN,KAAuB,IAAvB,IAA+B,KAAKnC,SAAL,CAAe+E,YAA9C,IAA8D7B,SAAS3P,YAA3E,EAAyF;AACrFlgC,yBAAIqgC,KAAJ,CAAU,qDAAV;;AAEA,uBAAO,KAAKqU,gBAAL,CAAsBY,SAAtB,CAAgCzF,SAAS3P,YAAzC,EAAuDmK,IAAvD,CAA4D,kBAAU;AACzErqC,6BAAIqgC,KAAJ,CAAU,qFAAV;;AAEA,wBAAIkV,OAAO7X,GAAP,KAAemS,SAASwF,OAAT,CAAiB3X,GAApC,EAAyC;AACrC19B,iCAAIojC,KAAJ,CAAU,kGAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gEAAV,CAAf,CAAP;AACH;;AAEDouC,6BAASwF,OAAT,GAAmB,OAAKG,YAAL,CAAkB3F,SAASwF,OAA3B,EAAoCE,MAApC,CAAnB;AACAv1C,6BAAIqgC,KAAJ,CAAU,+EAAV,EAA2FwP,SAASwF,OAApG;;AAEA,2BAAOxF,QAAP;AACH,iBAZM,CAAP;AAaH,aAhBD,MAiBK;AACD7vC,yBAAIqgC,KAAJ,CAAU,yDAAV;AACH;AACJ,SAzBD,MA0BK;AACDrgC,qBAAIqgC,KAAJ,CAAU,+EAAV;AACH;;AAED,eAAOmC,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAED2F,Y,yBAAaC,O,EAASC,O,EAAS;AAC3B,YAAIC,SAAS7zC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBH,OAAlB,CAAb;;AAEA,aAAK,IAAIvxB,IAAT,IAAiBwxB,OAAjB,EAA0B;AACtB,gBAAIG,SAASH,QAAQxxB,IAAR,CAAb;AACA,gBAAI,CAACnZ,MAAM4nB,OAAN,CAAckjB,MAAd,CAAL,EAA4B;AACxBA,yBAAS,CAACA,MAAD,CAAT;AACH;;AAED,iBAAK,IAAIzzC,IAAI,CAAb,EAAgBA,IAAIyzC,OAAOxzC,MAA3B,EAAmCD,GAAnC,EAAwC;AACpC,oBAAIumC,QAAQkN,OAAOzzC,CAAP,CAAZ;AACA,oBAAI,CAACuzC,OAAOzxB,IAAP,CAAL,EAAmB;AACfyxB,2BAAOzxB,IAAP,IAAeykB,KAAf;AACH,iBAFD,MAGK,IAAI59B,MAAM4nB,OAAN,CAAcgjB,OAAOzxB,IAAP,CAAd,CAAJ,EAAiC;AAClC,wBAAIyxB,OAAOzxB,IAAP,EAAaxc,OAAb,CAAqBihC,KAArB,IAA8B,CAAlC,EAAqC;AACjCgN,+BAAOzxB,IAAP,EAAa5f,IAAb,CAAkBqkC,KAAlB;AACH;AACJ,iBAJI,MAKA,IAAIgN,OAAOzxB,IAAP,MAAiBykB,KAArB,EAA4B;AAC7B,wBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA+B;AAC3BgN,+BAAOzxB,IAAP,IAAe,KAAKsxB,YAAL,CAAkBG,OAAOzxB,IAAP,CAAlB,EAAgCykB,KAAhC,CAAf;AACH,qBAFD,MAGK;AACDgN,+BAAOzxB,IAAP,IAAe,CAACyxB,OAAOzxB,IAAP,CAAD,EAAeykB,KAAf,CAAf;AACH;AACJ;AACJ;AACJ;;AAED,eAAOgN,MAAP;AACH,K;;gCAED7C,qB,kCAAsByC,M,EAAQ;AAC1Bv1C,iBAAIqgC,KAAJ,CAAU,2DAAV,EAAuEkV,MAAvE;;AAEA,YAAII,SAAS7zC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBL,MAAlB,CAAb;;AAEA,YAAI,KAAK5I,SAAL,CAAemG,qBAAnB,EAA0C;AACtCsB,2BAAe0B,OAAf,CAAuB,gBAAQ;AAC3B,uBAAOH,OAAO76B,IAAP,CAAP;AACH,aAFD;;AAIA9a,qBAAIqgC,KAAJ,CAAU,mEAAV,EAA+EsV,MAA/E;AACH,SAND,MAOK;AACD31C,qBAAIqgC,KAAJ,CAAU,uEAAV;AACH;;AAED,eAAOsV,MAAP;AACH,K;;gCAEDb,e,4BAAgBplB,K,EAAOmgB,Q,EAAU;AAC7B,YAAIA,SAASsF,IAAb,EAAmB;AACfn1C,qBAAIqgC,KAAJ,CAAU,oDAAV;AACA,mBAAO,KAAK0V,YAAL,CAAkBrmB,KAAlB,EAAyBmgB,QAAzB,CAAP;AACH;;AAED,YAAIA,SAASoF,QAAb,EAAuB;AACnB,gBAAIpF,SAAS3P,YAAb,EAA2B;AACvBlgC,yBAAIqgC,KAAJ,CAAU,yEAAV;AACA,uBAAO,KAAK2V,8BAAL,CAAoCtmB,KAApC,EAA2CmgB,QAA3C,CAAP;AACH;;AAED7vC,qBAAIqgC,KAAJ,CAAU,wDAAV;AACA,mBAAO,KAAK4V,gBAAL,CAAsBvmB,KAAtB,EAA6BmgB,QAA7B,CAAP;AACH;;AAED7vC,iBAAIqgC,KAAJ,CAAU,+EAAV;AACA,eAAOmC,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAEDkG,Y,yBAAarmB,K,EAAOmgB,Q,EAAU;AAAA;;AAC1B,YAAI7I,UAAU;AACV7F,uBAAWzR,MAAMyR,SADP;AAEViO,2BAAe1f,MAAM0f,aAFX;AAGV+F,kBAAOtF,SAASsF,IAHN;AAIVvQ,0BAAclV,MAAMkV,YAJV;AAKVsQ,2BAAexlB,MAAMwlB;AALX,SAAd;;AAQA,YAAIxlB,MAAMkf,gBAAN,IAA0B,QAAOlf,MAAMkf,gBAAb,MAAmC,QAAjE,EAA2E;AACvE9sC,mBAAO8zC,MAAP,CAAc5O,OAAd,EAAuBtX,MAAMkf,gBAA7B;AACH;;AAED,eAAO,KAAKgG,YAAL,CAAkBsB,YAAlB,CAA+BlP,OAA/B,EAAwCqD,IAAxC,CAA6C,yBAAiB;;AAEjE,iBAAI,IAAIvW,GAAR,IAAeqiB,aAAf,EAA8B;AAC1BtG,yBAAS/b,GAAT,IAAgBqiB,cAAcriB,GAAd,CAAhB;AACH;;AAED,gBAAI+b,SAASoF,QAAb,EAAuB;AACnBj1C,yBAAIqgC,KAAJ,CAAU,gFAAV;AACA,uBAAO,OAAK+V,0BAAL,CAAgC1mB,KAAhC,EAAuCmgB,QAAvC,CAAP;AACH,aAHD,MAIK;AACD7vC,yBAAIqgC,KAAJ,CAAU,+EAAV;AACH;;AAED,mBAAOwP,QAAP;AACH,SAfM,CAAP;AAgBH,K;;gCAEDuG,0B,uCAA2B1mB,K,EAAOmgB,Q,EAAU;AAAA;;AACxC,eAAO,KAAKX,gBAAL,CAAsBnC,SAAtB,GAAkC1C,IAAlC,CAAuC,kBAAU;;AAEpD,gBAAIX,WAAWha,MAAMyR,SAArB;AACA,gBAAIkV,qBAAqB,OAAK1J,SAAL,CAAehD,SAAxC;AACA3pC,qBAAIqgC,KAAJ,CAAU,4GAAV,EAAwHgW,kBAAxH;;AAEA,mBAAO,OAAK1B,SAAL,CAAe3K,qBAAf,CAAqC6F,SAASoF,QAA9C,EAAwDxL,MAAxD,EAAgEC,QAAhE,EAA0E2M,kBAA1E,EAA8FhM,IAA9F,CAAmG,mBAAW;;AAEjH,oBAAI3a,MAAMslB,KAAN,IAAetlB,MAAMslB,KAAN,KAAgBzL,QAAQyL,KAA3C,EAAkD;AAC9Ch1C,6BAAIojC,KAAJ,CAAU,yEAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAAV,CAAf,CAAP;AACH;;AAED,oBAAI,CAAC8nC,QAAQ7L,GAAb,EAAkB;AACd19B,6BAAIojC,KAAJ,CAAU,0EAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDouC,yBAASwF,OAAT,GAAmB9L,OAAnB;AACA,uBAAOsG,QAAP;AACH,aAdM,CAAP;AAeH,SArBM,CAAP;AAsBH,K;;gCAEDmG,8B,2CAA+BtmB,K,EAAOmgB,Q,EAAU;AAAA;;AAC5C,eAAO,KAAKoG,gBAAL,CAAsBvmB,KAAtB,EAA6BmgB,QAA7B,EAAuCxF,IAAvC,CAA4C,oBAAY;AAC3D,mBAAO,OAAKiM,oBAAL,CAA0BzG,QAA1B,CAAP;AACH,SAFM,CAAP;AAGH,K;;gCAEDoG,gB,6BAAiBvmB,K,EAAOmgB,Q,EAAU;AAAA;;AAC9B,YAAI,CAACngB,MAAMslB,KAAX,EAAkB;AACdh1C,qBAAIojC,KAAJ,CAAU,uDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,mBAAV,CAAf,CAAP;AACH;;AAED,YAAI2nC,MAAM,KAAKuL,SAAL,CAAexL,QAAf,CAAwB0G,SAASoF,QAAjC,CAAV;AACA,YAAI,CAAC7L,GAAD,IAAQ,CAACA,IAAIE,MAAb,IAAuB,CAACF,IAAIG,OAAhC,EAAyC;AACrCvpC,qBAAIojC,KAAJ,CAAU,8DAAV,EAA0EgG,GAA1E;AACA,mBAAO5G,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,YAAIiuB,MAAMslB,KAAN,KAAgB5L,IAAIG,OAAJ,CAAYyL,KAAhC,EAAuC;AACnCh1C,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAAV,CAAf,CAAP;AACH;;AAED,YAAIs5B,MAAMqO,IAAIE,MAAJ,CAAWvO,GAArB;;AAEA,eAAO,KAAKmU,gBAAL,CAAsBnC,SAAtB,GAAkC1C,IAAlC,CAAuC,kBAAU;AACpDrqC,qBAAIqgC,KAAJ,CAAU,qDAAV;;AAEA,mBAAO,OAAK6O,gBAAL,CAAsBzB,cAAtB,GAAuCpD,IAAvC,CAA4C,gBAAQ;AACvD,oBAAI,CAACnqB,IAAL,EAAW;AACPlgB,6BAAIojC,KAAJ,CAAU,mEAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,+BAAV,CAAf,CAAP;AACH;;AAEDzB,yBAAIqgC,KAAJ,CAAU,2DAAV;AACA,oBAAIvM,YAAJ;AACA,oBAAI,CAACiH,GAAL,EAAU;AACN7a,2BAAO,OAAKq2B,YAAL,CAAkBr2B,IAAlB,EAAwBkpB,IAAIE,MAAJ,CAAW1c,GAAnC,CAAP;;AAEA,wBAAI1M,KAAK7d,MAAL,GAAc,CAAlB,EAAqB;AACjBrC,iCAAIojC,KAAJ,CAAU,sGAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kEAAV,CAAf,CAAP;AACH,qBAHD,MAIK;AACD;AACA;AACAqyB,8BAAM5T,KAAK,CAAL,CAAN;AACH;AACJ,iBAZD,MAaK;AACD4T,0BAAM5T,KAAKs2B,MAAL,CAAY,eAAO;AACrB,+BAAO1iB,IAAIiH,GAAJ,KAAYA,GAAnB;AACH,qBAFK,EAEH,CAFG,CAAN;AAGH;;AAED,oBAAI,CAACjH,GAAL,EAAU;AACN9zB,6BAAIojC,KAAJ,CAAU,sFAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED,oBAAIioC,WAAWha,MAAMyR,SAArB;;AAEA,oBAAIkV,qBAAqB,OAAK1J,SAAL,CAAehD,SAAxC;AACA3pC,yBAAIqgC,KAAJ,CAAU,uFAAV,EAAmGgW,kBAAnG;;AAEA,uBAAO,OAAK1B,SAAL,CAAenL,WAAf,CAA2BqG,SAASoF,QAApC,EAA8CnhB,GAA9C,EAAmD2V,MAAnD,EAA2DC,QAA3D,EAAqE2M,kBAArE,EAAyFhM,IAAzF,CAA8F,YAAI;AACrGrqC,6BAAIqgC,KAAJ,CAAU,+DAAV;;AAEA,wBAAI,CAAC+I,IAAIG,OAAJ,CAAY7L,GAAjB,EAAsB;AAClB19B,iCAAIojC,KAAJ,CAAU,gEAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDouC,6BAASwF,OAAT,GAAmBjM,IAAIG,OAAvB;;AAEA,2BAAOsG,QAAP;AACH,iBAXM,CAAP;AAYH,aAjDM,CAAP;AAkDH,SArDM,CAAP;AAsDH,K;;gCAED0G,Y,yBAAar2B,I,EAAM0M,G,EAAI;AACnB,YAAIyJ,MAAM,IAAV;AACA,YAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AACtBjV,kBAAM,KAAN;AACH,SAFD,MAGK,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA;AACDr2B,qBAAIqgC,KAAJ,CAAU,qDAAV,EAAiEzT,GAAjE;AACA,mBAAO,EAAP;AACH;;AAED5sB,iBAAIqgC,KAAJ,CAAU,mEAAV,EAA+EhK,GAA/E;;AAEAnW,eAAOA,KAAKs2B,MAAL,CAAY,eAAO;AACtB,mBAAO1iB,IAAIuC,GAAJ,KAAYA,GAAnB;AACH,SAFM,CAAP;;AAIAr2B,iBAAIqgC,KAAJ,CAAU,iEAAV,EAA6EhK,GAA7E,EAAkFnW,KAAK7d,MAAvF;;AAEA,eAAO6d,IAAP;AACH,K;;gCAEDo2B,oB,iCAAqBzG,Q,EAAU;AAC3B,YAAI,CAACA,SAASwF,OAAd,EAAuB;AACnBr1C,qBAAIojC,KAAJ,CAAU,yEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iCAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACouC,SAASwF,OAAT,CAAiBoB,OAAtB,EAA+B;AAC3Bz2C,qBAAIojC,KAAJ,CAAU,gEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,wBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACouC,SAASoF,QAAd,EAAwB;AACpBj1C,qBAAIojC,KAAJ,CAAU,qDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,aAAV,CAAf,CAAP;AACH;;AAED,YAAI2nC,MAAM,KAAKuL,SAAL,CAAexL,QAAf,CAAwB0G,SAASoF,QAAjC,CAAV;AACA,YAAI,CAAC7L,GAAD,IAAQ,CAACA,IAAIE,MAAjB,EAAyB;AACrBtpC,qBAAIojC,KAAJ,CAAU,kEAAV,EAA8EgG,GAA9E;AACA,mBAAO5G,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,YAAIi1C,UAAUtN,IAAIE,MAAJ,CAAW1c,GAAzB;AACA,YAAI,CAAC8pB,OAAD,IAAYA,QAAQr0C,MAAR,KAAmB,CAAnC,EAAsC;AAClCrC,qBAAIojC,KAAJ,CAAU,0DAAV,EAAsEsT,OAAtE;AACA,mBAAOlU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAsBi1C,OAAhC,CAAf,CAAP;AACH;;AAED,YAAIC,WAAWD,QAAQ7xC,MAAR,CAAe,CAAf,EAAkB,CAAlB,CAAf;AACA,YAAI,CAAC8xC,QAAL,EAAe;AACX32C,qBAAIojC,KAAJ,CAAU,0DAAV,EAAsEsT,OAAtE,EAA+EC,QAA/E;AACA,mBAAOnU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAsBi1C,OAAhC,CAAf,CAAP;AACH;;AAEDC,mBAAW/xC,SAAS+xC,QAAT,CAAX;AACA,YAAIA,aAAa,GAAb,IAAoBA,aAAa,GAAjC,IAAwCA,aAAa,GAAzD,EAA8D;AAC1D32C,qBAAIojC,KAAJ,CAAU,0DAAV,EAAsEsT,OAAtE,EAA+EC,QAA/E;AACA,mBAAOnU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAsBi1C,OAAhC,CAAf,CAAP;AACH;;AAED,YAAIE,MAAM,QAAQD,QAAlB;AACA,YAAI5oB,OAAO,KAAK4mB,SAAL,CAAehoB,UAAf,CAA0BkjB,SAAS3P,YAAnC,EAAiD0W,GAAjD,CAAX;AACA,YAAI,CAAC7oB,IAAL,EAAW;AACP/tB,qBAAIojC,KAAJ,CAAU,mEAAV,EAA+EwT,GAA/E;AACA,mBAAOpU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAED,YAAIo1C,OAAO9oB,KAAKlpB,MAAL,CAAY,CAAZ,EAAekpB,KAAK1rB,MAAL,GAAc,CAA7B,CAAX;AACA,YAAIy0C,YAAY,KAAKnC,SAAL,CAAerK,cAAf,CAA8BuM,IAA9B,CAAhB;AACA,YAAIC,cAAcjH,SAASwF,OAAT,CAAiBoB,OAAnC,EAA4C;AACxCz2C,qBAAIojC,KAAJ,CAAU,oEAAV,EAAgF0T,SAAhF,EAA2FjH,SAASwF,OAAT,CAAiBoB,OAA5G;AACA,mBAAOjU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,iDAAV;;AAEA,eAAOmC,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCndL;AACA;;AAEA;;AACA;;AACA;;;;IAEajvC,c,WAAAA,c;AAET,4BAAYm2C,WAAZ,EAA4F;AAAA;;AAAA,YAAnEC,sBAAmE,uEAA1Ct2C,sCAA0C;AAAA,YAAtBmmC,KAAsB,uEAAdhmC,eAAOgmC,KAAO;;AAAA;;AACxF,YAAI,CAACkQ,WAAL,EAAkB;AACd/2C,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,aAAV,CAAN;AACH;;AAED,aAAKw1C,YAAL,GAAoBF,WAApB;AACA,aAAKG,uBAAL,GAA+BF,sBAA/B;AACA,aAAKrT,MAAL,GAAckD,KAAd;;AAEA,aAAKoQ,YAAL,CAAkBE,MAAlB,CAAyBC,aAAzB,CAAuC,KAAKC,MAAL,CAAYtU,IAAZ,CAAiB,IAAjB,CAAvC;AACA,aAAKkU,YAAL,CAAkBE,MAAlB,CAAyBG,eAAzB,CAAyC,KAAKC,KAAL,CAAWxU,IAAX,CAAgB,IAAhB,CAAzC;;AAEA,aAAKkU,YAAL,CAAkBO,OAAlB,GAA4BnN,IAA5B,CAAiC,gBAAQ;AACrC;AACA;AACA,gBAAIoN,IAAJ,EAAU;AACN,sBAAKJ,MAAL,CAAYI,IAAZ;AACH,aAFD,MAGK,IAAI,MAAK9K,SAAL,CAAe+K,uBAAnB,EAA4C;AAC7C,sBAAKT,YAAL,CAAkBU,kBAAlB,GAAuCtN,IAAvC,CAA4C,mBAAW;AACnD,wBAAIuN,UAAU;AACVrU,uCAAgBsU,QAAQtU;AADd,qBAAd;AAGA,wBAAIsU,QAAQna,GAAR,IAAema,QAAQC,GAA3B,EAAgC;AAC5BF,gCAAQvC,OAAR,GAAkB;AACd3X,iCAAKma,QAAQna,GADC;AAEdoa,iCAAKD,QAAQC;AAFC,yBAAlB;AAIH;AACD,0BAAKT,MAAL,CAAYO,OAAZ;AACH,iBAXD,EAYCG,KAZD,CAYO,eAAO;AACV;AACA/3C,6BAAIojC,KAAJ,CAAU,qDAAV,EAAiE4U,IAAIhS,OAArE;AACH,iBAfD;AAgBH;AACJ,SAxBD,EAwBG+R,KAxBH,CAwBS,eAAO;AACZ;AACA/3C,qBAAIojC,KAAJ,CAAU,0CAAV,EAAsD4U,IAAIhS,OAA1D;AACH,SA3BD;AA4BH;;6BAkBDqR,M,mBAAOI,I,EAAM;AAAA;;AACT,YAAIlU,gBAAgBkU,KAAKlU,aAAzB;;AAEA,YAAIA,aAAJ,EAAmB;AACf,gBAAIkU,KAAKpC,OAAT,EAAkB;AACd,qBAAK4C,IAAL,GAAYR,KAAKpC,OAAL,CAAa3X,GAAzB;AACA,qBAAKwa,IAAL,GAAYT,KAAKpC,OAAL,CAAayC,GAAzB;AACA93C,yBAAIqgC,KAAJ,CAAU,uCAAV,EAAmDkD,aAAnD,EAAkE,QAAlE,EAA4E,KAAK0U,IAAjF;AACH,aAJD,MAKK;AACD,qBAAKA,IAAL,GAAY92C,SAAZ;AACA,qBAAK+2C,IAAL,GAAY/2C,SAAZ;AACAnB,yBAAIqgC,KAAJ,CAAU,uCAAV,EAAmDkD,aAAnD,EAAkE,kBAAlE;AACH;;AAED,gBAAI,CAAC,KAAK4U,mBAAV,EAA+B;AAC3B,qBAAKjJ,gBAAL,CAAsB7B,qBAAtB,GAA8ChD,IAA9C,CAAmD,eAAO;AACtD,wBAAIjJ,GAAJ,EAAS;AACLphC,iCAAIqgC,KAAJ,CAAU,0DAAV;;AAEA,4BAAIc,YAAY,OAAKK,UAArB;AACA,4BAAIH,WAAW,OAAK+W,qBAApB;AACA,4BAAI9W,cAAc,OAAK+W,wBAAvB;;AAEA,+BAAKF,mBAAL,GAA2B,IAAI,OAAKjB,uBAAT,CAAiC,OAAK3V,SAAL,CAAewB,IAAf,CAAoB,MAApB,CAAjC,EAA4D5B,SAA5D,EAAuEC,GAAvE,EAA4EC,QAA5E,EAAsFC,WAAtF,CAA3B;AACA,+BAAK6W,mBAAL,CAAyBnY,IAAzB,GAAgCqK,IAAhC,CAAqC,YAAM;AACvC,mCAAK8N,mBAAL,CAAyB7U,KAAzB,CAA+BC,aAA/B;AACH,yBAFD;AAGH,qBAXD,MAYK;AACDvjC,iCAAI8rC,IAAJ,CAAS,sEAAT;AACH;AACJ,iBAhBD,EAgBGiM,KAhBH,CAgBS,eAAO;AACZ;AACA/3C,6BAAIojC,KAAJ,CAAU,0DAAV,EAAsE4U,IAAIhS,OAA1E;AACH,iBAnBD;AAoBH,aArBD,MAsBK;AACD,qBAAKmS,mBAAL,CAAyB7U,KAAzB,CAA+BC,aAA/B;AACH;AACJ;AACJ,K;;6BAEDgU,K,oBAAQ;AAAA;;AACJ,aAAKU,IAAL,GAAY92C,SAAZ;AACA,aAAK+2C,IAAL,GAAY/2C,SAAZ;;AAEA,YAAI,KAAKg3C,mBAAT,EAA8B;AAC1Bn4C,qBAAIqgC,KAAJ,CAAU,sBAAV;AACA,iBAAK8X,mBAAL,CAAyB9U,IAAzB;AACH;;AAED,YAAI,KAAKsJ,SAAL,CAAe+K,uBAAnB,EAA4C;AACxC;AACA,gBAAIY,cAAc,KAAK3U,MAAL,CAAYC,WAAZ,CAAwB,YAAI;AAC1C,uBAAKD,MAAL,CAAYE,aAAZ,CAA0ByU,WAA1B;;AAEA,uBAAKrB,YAAL,CAAkBU,kBAAlB,GAAuCtN,IAAvC,CAA4C,mBAAW;AACnD,wBAAIuN,UAAU;AACVrU,uCAAgBsU,QAAQtU;AADd,qBAAd;AAGA,wBAAIsU,QAAQna,GAAR,IAAema,QAAQC,GAA3B,EAAgC;AAC5BF,gCAAQvC,OAAR,GAAkB;AACd3X,iCAAKma,QAAQna,GADC;AAEdoa,iCAAKD,QAAQC;AAFC,yBAAlB;AAIH;AACD,2BAAKT,MAAL,CAAYO,OAAZ;AACH,iBAXD,EAYCG,KAZD,CAYO,eAAO;AACV;AACA/3C,6BAAIojC,KAAJ,CAAU,gDAAV,EAA4D4U,IAAIhS,OAAhE;AACH,iBAfD;AAiBH,aApBiB,EAoBf,IApBe,CAAlB;AAqBH;AACJ,K;;6BAEDzE,S,wBAAY;AAAA;;AACR,aAAK0V,YAAL,CAAkBU,kBAAlB,GAAuCtN,IAAvC,CAA4C,mBAAW;AACnD,gBAAIkO,aAAa,IAAjB;;AAEA,gBAAIV,OAAJ,EAAa;AACT,oBAAIA,QAAQna,GAAR,KAAgB,OAAKua,IAAzB,EAA+B;AAC3BM,iCAAa,KAAb;AACA,2BAAKJ,mBAAL,CAAyB7U,KAAzB,CAA+BuU,QAAQtU,aAAvC;;AAEA,wBAAIsU,QAAQC,GAAR,KAAgB,OAAKI,IAAzB,EAA+B;AAC3Bl4C,iCAAIqgC,KAAJ,CAAU,2GAAV,EAAuHwX,QAAQtU,aAA/H;AACH,qBAFD,MAGK;AACDvjC,iCAAIqgC,KAAJ,CAAU,sIAAV,EAAkJwX,QAAQtU,aAA1J;AACA,+BAAK0T,YAAL,CAAkBE,MAAlB,CAAyBqB,wBAAzB;AACH;AACJ,iBAXD,MAYK;AACDx4C,6BAAIqgC,KAAJ,CAAU,6DAAV,EAAyEwX,QAAQna,GAAjF;AACH;AACJ,aAhBD,MAiBK;AACD19B,yBAAIqgC,KAAJ,CAAU,4DAAV;AACH;;AAED,gBAAIkY,UAAJ,EAAgB;AACZ,oBAAI,OAAKN,IAAT,EAAe;AACXj4C,6BAAIqgC,KAAJ,CAAU,8EAAV;AACA,2BAAK4W,YAAL,CAAkBE,MAAlB,CAAyBsB,mBAAzB;AACH,iBAHD,MAIK;AACDz4C,6BAAIqgC,KAAJ,CAAU,6EAAV;AACA,2BAAK4W,YAAL,CAAkBE,MAAlB,CAAyBuB,kBAAzB;AACH;AACJ;AACJ,SAlCD,EAkCGX,KAlCH,CAkCS,eAAO;AACZ,gBAAI,OAAKE,IAAT,EAAe;AACXj4C,yBAAIqgC,KAAJ,CAAU,6FAAV,EAAyG2X,IAAIhS,OAA7G;AACA,uBAAKiR,YAAL,CAAkBE,MAAlB,CAAyBsB,mBAAzB;AACH;AACJ,SAvCD;AAwCH,K;;;;4BAvIe;AACZ,mBAAO,KAAKxB,YAAL,CAAkBxK,QAAzB;AACH;;;4BACsB;AACnB,mBAAO,KAAKwK,YAAL,CAAkB7F,eAAzB;AACH;;;4BACgB;AACb,mBAAO,KAAKzE,SAAL,CAAexL,SAAtB;AACH;;;4BAC2B;AACxB,mBAAO,KAAKwL,SAAL,CAAegM,oBAAtB;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKhM,SAAL,CAAeiM,uBAAtB;AACH;;;;;;;;;;;;;;;;;;;;;;;AC/DL;;AACA;;AACA;;0JALA;AACA;;IAMa5J,a,WAAAA,a;AACT,iCAMG;AAAA,YAJC5N,GAID,QAJCA,GAID;AAAA,YAJMD,SAIN,QAJMA,SAIN;AAAA,YAJiByD,YAIjB,QAJiBA,YAIjB;AAAA,YAJ+BoJ,aAI/B,QAJ+BA,aAI/B;AAAA,YAJ8CC,KAI9C,QAJ8CA,KAI9C;AAAA,YAJqDH,SAIrD,QAJqDA,SAIrD;AAAA,YAFCxZ,IAED,QAFCA,IAED;AAAA,YAFO4Z,MAEP,QAFOA,MAEP;AAAA,YAFe9L,OAEf,QAFeA,OAEf;AAAA,YAFwB+L,OAExB,QAFwBA,OAExB;AAAA,YAFiCC,UAEjC,QAFiCA,UAEjC;AAAA,YAF6CC,aAE7C,QAF6CA,aAE7C;AAAA,YAF4DC,UAE5D,QAF4DA,UAE5D;AAAA,YAFwEC,UAExE,QAFwEA,UAExE;AAAA,YAFoFC,QAEpF,QAFoFA,QAEpF;AAAA,YAF8FE,aAE9F,QAF8FA,aAE9F;AAAA,YADC1H,OACD,QADCA,OACD;AAAA,YADUyH,WACV,QADUA,WACV;AAAA,YADuBE,gBACvB,QADuBA,gBACvB;AAAA,YADyCE,YACzC,QADyCA,YACzC;AAAA,YADuDO,aACvD,QADuDA,aACvD;AAAA,YADsER,gBACtE,QADsEA,gBACtE;AAAA,YADwFE,YACxF,QADwFA,YACxF;;AAAA;;AACC,YAAI,CAAC1N,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,mCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;AACD,YAAI,CAAC0/B,SAAL,EAAgB;AACZnhC,qBAAIojC,KAAJ,CAAU,yCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,WAAV,CAAN;AACH;AACD,YAAI,CAACmjC,YAAL,EAAmB;AACf5kC,qBAAIojC,KAAJ,CAAU,4CAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,cAAV,CAAN;AACH;AACD,YAAI,CAACusC,aAAL,EAAoB;AAChBhuC,qBAAIojC,KAAJ,CAAU,6CAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,eAAV,CAAN;AACH;AACD,YAAI,CAACwsC,KAAL,EAAY;AACRjuC,qBAAIojC,KAAJ,CAAU,qCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,OAAV,CAAN;AACH;AACD,YAAI,CAACqsC,SAAL,EAAgB;AACZ9tC,qBAAIojC,KAAJ,CAAU,yCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,WAAV,CAAN;AACH;;AAED,YAAIo3C,OAAO7J,cAAc8J,MAAd,CAAqB9K,aAArB,CAAX;AACA,YAAImH,OAAOnG,cAAcC,MAAd,CAAqBjB,aAArB,CAAX;;AAEA,YAAI,CAACU,aAAL,EAAoB;AAChBA,4BAAgBM,cAAcC,MAAd,CAAqBjB,aAArB,IAAsC,OAAtC,GAAgD,IAAhE;AACH;;AAED,aAAKte,KAAL,GAAa,IAAIwgB,wBAAJ,CAAgB,EAAE8E,OAAO6D,IAAT;AACzBvkB,sBADyB,EACnB6M,oBADmB,EACR2M,oBADQ,EACGlJ,0BADH;AAEzBsQ,2BAAeC,IAFU;AAGzBtG,sCAHyB,EAGXH,4BAHW;AAIzBU,wCAJyB,EAIVnB,YAJU,EAIHW,kCAJG,EAIeE,0BAJf,EAAhB,CAAb;;AAMA1N,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,WAA9B,EAA2CD,SAA3C,CAAN;AACAC,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,cAA9B,EAA8CwD,YAA9C,CAAN;AACAxD,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,eAA9B,EAA+C4M,aAA/C,CAAN;AACA5M,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC6M,KAAvC,CAAN;;AAEA7M,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC,KAAK1R,KAAL,CAAW8L,EAAlD,CAAN;AACA,YAAIqd,IAAJ,EAAU;AACNzX,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC,KAAK1R,KAAL,CAAWslB,KAAlD,CAAN;AACH;AACD,YAAIG,IAAJ,EAAU;AACN/T,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,gBAA9B,EAAgD,KAAK1R,KAAL,CAAWspB,cAA3D,CAAN;AACA5X,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,uBAA9B,EAAuD,MAAvD,CAAN;AACH;;AAED,YAAIgM,WAAW,EAAEc,cAAF,EAAU9L,gBAAV,EAAmB+L,gBAAnB,EAA4BC,sBAA5B,EAAwCC,4BAAxC,EAAuDC,sBAAvD,EAAmEC,sBAAnE,EAA+EC,kBAA/E,EAAyFxH,gBAAzF,EAAkGyH,wBAAlG,EAA+GC,4BAA/G,EAAf;AACA,aAAI,IAAI5a,GAAR,IAAesZ,QAAf,EAAwB;AACpB,gBAAIA,SAAStZ,GAAT,CAAJ,EAAmB;AACfsN,sBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8BtN,GAA9B,EAAmCsZ,SAAStZ,GAAT,CAAnC,CAAN;AACH;AACJ;;AAED,aAAI,IAAIA,IAAR,IAAe6a,gBAAf,EAAgC;AAC5BvN,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8BtN,IAA9B,EAAmC6a,iBAAiB7a,IAAjB,CAAnC,CAAN;AACH;;AAED,aAAKsN,GAAL,GAAWA,GAAX;AACH;;kBAEM0X,M,mBAAO9K,a,EAAe;AACzB,YAAI2H,SAAS3H,cAAcrtB,KAAd,CAAoB,MAApB,EAA4B61B,MAA5B,CAAmC,UAAS7P,IAAT,EAAe;AAC3D,mBAAOA,SAAS,UAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAEgP,OAAO,CAAP,CAAV;AACH,K;;kBAEMsD,O,oBAAQjL,a,EAAe;AAC1B,YAAI2H,SAAS3H,cAAcrtB,KAAd,CAAoB,MAApB,EAA4B61B,MAA5B,CAAmC,UAAS7P,IAAT,EAAe;AAC3D,mBAAOA,SAAS,OAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAEgP,OAAO,CAAP,CAAV;AACH,K;;kBAEM1G,M,mBAAOjB,a,EAAe;AACzB,YAAI2H,SAAS3H,cAAcrtB,KAAd,CAAoB,MAApB,EAA4B61B,MAA5B,CAAmC,UAAS7P,IAAT,EAAe;AAC3D,mBAAOA,SAAS,MAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAEgP,OAAO,CAAP,CAAV;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCpGL;AACA;;AAEA;;;;AAEA,IAAMuD,YAAY,QAAlB;;IAEapJ,c,WAAAA,c;AACT,4BAAY1O,GAAZ,EAAkC;AAAA,YAAjBwO,SAAiB,uEAAL,GAAK;;AAAA;;AAE9B,YAAIiG,SAAS7B,uBAAWC,gBAAX,CAA4B7S,GAA5B,EAAiCwO,SAAjC,CAAb;;AAEA,aAAKxM,KAAL,GAAayS,OAAOzS,KAApB;AACA,aAAKiD,iBAAL,GAAyBwP,OAAOxP,iBAAhC;AACA,aAAKC,SAAL,GAAiBuP,OAAOvP,SAAxB;;AAEA,aAAK6O,IAAL,GAAYU,OAAOV,IAAnB;AACA,aAAKzlB,KAAL,GAAammB,OAAOnmB,KAApB;AACA,aAAKulB,QAAL,GAAgBY,OAAOZ,QAAvB;AACA,aAAK1R,aAAL,GAAqBsS,OAAOtS,aAA5B;AACA,aAAKrD,YAAL,GAAoB2V,OAAO3V,YAA3B;AACA,aAAKiZ,UAAL,GAAkBtD,OAAOsD,UAAzB;AACA,aAAKlL,KAAL,GAAa4H,OAAO5H,KAApB;AACA,aAAKoH,OAAL,GAAel0C,SAAf,CAf8B,CAeJ;;AAE1B,aAAKg/B,UAAL,GAAkB0V,OAAO1V,UAAzB;AACH;;;;4BAEgB;AACb,gBAAI,KAAKiZ,UAAT,EAAqB;AACjB,oBAAIxP,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,uBAAO,KAAKwP,UAAL,GAAkBxP,GAAzB;AACH;AACD,mBAAOzoC,SAAP;AACH,S;0BACcwnC,K,EAAM;AACjB,gBAAIxI,aAAav7B,SAAS+jC,KAAT,CAAjB;AACA,gBAAI,OAAOxI,UAAP,KAAsB,QAAtB,IAAkCA,aAAa,CAAnD,EAAsD;AAClD,oBAAIyJ,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,qBAAKwP,UAAL,GAAkBxP,MAAMzJ,UAAxB;AACH;AACJ;;;4BAEa;AACV,gBAAIA,aAAa,KAAKA,UAAtB;AACA,gBAAIA,eAAeh/B,SAAnB,EAA8B;AAC1B,uBAAOg/B,cAAc,CAArB;AACH;AACD,mBAAOh/B,SAAP;AACH;;;4BAEY;AACT,mBAAO,CAAC,KAAK8sC,KAAL,IAAc,EAAf,EAAmBttB,KAAnB,CAAyB,GAAzB,CAAP;AACH;;;4BAEqB;AAClB,mBAAO,KAAK04B,MAAL,CAAY3xC,OAAZ,CAAoBwxC,SAApB,KAAkC,CAAlC,IAAuC,CAAC,CAAC,KAAKjE,QAArD;AACH;;;;;;;;;;;;;;;;;;;;;;;;;ACtDL;;AACA;;AACA;;AACA;;;;;;;;;;+eANA;AACA;;IAOa/E,W,WAAAA,W;;;AACT,2BAAkJ;AAAA,uFAAJ,EAAI;AAAA,YAArI8E,KAAqI,QAArIA,KAAqI;AAAA,YAA9HlH,SAA8H,QAA9HA,SAA8H;AAAA,YAAnH3M,SAAmH,QAAnHA,SAAmH;AAAA,YAAxGyD,YAAwG,QAAxGA,YAAwG;AAAA,YAA1FsQ,aAA0F,QAA1FA,aAA0F;AAAA,YAA3ExG,aAA2E,QAA3EA,aAA2E;AAAA,YAA5DU,aAA4D,QAA5DA,aAA4D;AAAA,YAA7CnB,KAA6C,QAA7CA,KAA6C;AAAA,YAAtCW,gBAAsC,QAAtCA,gBAAsC;AAAA,YAApBE,YAAoB,QAApBA,YAAoB;;AAAA;;AAAA,qDAC9I,kBAAM1rC,UAAU,CAAV,CAAN,CAD8I;;AAG9I,YAAI4xC,UAAU,IAAd,EAAoB;AAChB,kBAAKsE,MAAL,GAAc,uBAAd;AACH,SAFD,MAGK,IAAItE,KAAJ,EAAW;AACZ,kBAAKsE,MAAL,GAActE,KAAd;AACH;;AAED,YAAIE,kBAAkB,IAAtB,EAA4B;AACxB;AACA,kBAAKqE,cAAL,GAAsB,0BAAW,uBAAX,GAAsB,uBAA5C;AACH,SAHD,MAIK,IAAIrE,aAAJ,EAAmB;AACpB,kBAAKqE,cAAL,GAAsBrE,aAAtB;AACH;;AAED,YAAI,MAAKA,aAAT,EAAwB;AACpB,gBAAInnB,OAAOgb,mBAASpc,UAAT,CAAoB,MAAKuoB,aAAzB,EAAwC,QAAxC,CAAX;AACA,kBAAKsE,eAAL,GAAuBzQ,mBAASuB,cAAT,CAAwBvc,IAAxB,CAAvB;AACH;;AAED,cAAKskB,aAAL,GAAqBzN,YAArB;AACA,cAAKmN,UAAL,GAAkBjE,SAAlB;AACA,cAAKtM,UAAL,GAAkBL,SAAlB;AACA,cAAK0R,cAAL,GAAsBnE,aAAtB;AACA,cAAKwD,cAAL,GAAsB9C,aAAtB;AACA,cAAKgD,MAAL,GAAcnE,KAAd;AACA,cAAKmF,iBAAL,GAAyBxE,gBAAzB;AACA,cAAK6K,aAAL,GAAqB3K,YAArB;AA9B8I;AA+BjJ;;0BAoCDU,e,8BAAkB;AACdxvC,iBAAIqgC,KAAJ,CAAU,6BAAV;AACA,eAAOra,KAAKriB,SAAL,CAAe;AAClB63B,gBAAI,KAAKA,EADS;AAElBlH,kBAAM,KAAKA,IAFO;AAGlBolB,qBAAS,KAAKA,OAHI;AAIlB7K,0BAAc,KAAKA,YAJD;AAKlBmG,mBAAO,KAAKA,KALM;AAMlBE,2BAAe,KAAKA,aANF;AAOlBtQ,0BAAc,KAAKA,YAPD;AAQlBkJ,uBAAW,KAAKA,SARE;AASlB3M,uBAAW,KAAKA,SATE;AAUlBuN,2BAAe,KAAKA,aAVF;AAWlBU,2BAAe,KAAKA,aAXF;AAYlBnB,mBAAO,KAAKA,KAZM;AAalBW,8BAAmB,KAAKA,gBAbN;AAclBE,0BAAc,KAAKA;AAdD,SAAf,CAAP;AAgBH,K;;gBAEMqB,iB,8BAAkBwJ,a,EAAe;AACpC35C,iBAAIqgC,KAAJ,CAAU,+BAAV;AACA,YAAI/L,OAAOtO,KAAKrhB,KAAL,CAAWg1C,aAAX,CAAX;AACA,eAAO,IAAIzJ,WAAJ,CAAgB5b,IAAhB,CAAP;AACH,K;;;;4BA1DW;AACR,mBAAO,KAAKglB,MAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKvH,UAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKvQ,UAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAK6Q,aAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKkH,cAAZ;AACH;;;4BACoB;AACjB,mBAAO,KAAKC,eAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAK3G,cAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKX,cAAZ;AACH;;;4BACW;AACR,mBAAO,KAAKE,MAAZ;AACH;;;4BACsB;AACnB,mBAAO,KAAKgB,iBAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKqG,aAAZ;AACH;;;;EAlE4B3I,a;;;;;;;;;;;;;;;;;;;ACLjC;;AACA;;AACA;;0JALA;AACA;;IAMaL,c,WAAAA,c,GACT,8BAAkG;AAAA,QAArFrP,GAAqF,QAArFA,GAAqF;AAAA,QAAhFiN,aAAgF,QAAhFA,aAAgF;AAAA,QAAjEmC,wBAAiE,QAAjEA,wBAAiE;AAAA,QAAvClc,IAAuC,QAAvCA,IAAuC;AAAA,QAAjCqa,gBAAiC,QAAjCA,gBAAiC;AAAA,QAAfE,YAAe,QAAfA,YAAe;;AAAA;;AAC9F,QAAI,CAACzN,GAAL,EAAU;AACNphC,iBAAIojC,KAAJ,CAAU,oCAAV;AACA,cAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;;AAED,QAAI4sC,aAAJ,EAAmB;AACfjN,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,eAA9B,EAA+CiN,aAA/C,CAAN;AACH;;AAED,QAAImC,wBAAJ,EAA8B;AAC1BpP,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,0BAA9B,EAA0DoP,wBAA1D,CAAN;;AAEA,YAAIlc,IAAJ,EAAU;AACN,iBAAK5E,KAAL,GAAa,IAAIohB,YAAJ,CAAU,EAAExc,UAAF,EAAQua,0BAAR,EAAV,CAAb;;AAEAzN,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC,KAAK1R,KAAL,CAAW8L,EAAlD,CAAN;AACH;AACJ;;AAED,SAAI,IAAI1H,GAAR,IAAe6a,gBAAf,EAAgC;AAC5BvN,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8BtN,GAA9B,EAAmC6a,iBAAiB7a,GAAjB,CAAnC,CAAN;AACH;;AAED,SAAKsN,GAAL,GAAWA,GAAX;AACH,C;;;;;;;;;;;;;;;;;;;AC9BL;;0JAHA;AACA;;IAIawP,e,WAAAA,e,GACT,yBAAYxP,GAAZ,EAAiB;AAAA;;AAEb,YAAIyU,SAAS7B,uBAAWC,gBAAX,CAA4B7S,GAA5B,EAAiC,GAAjC,CAAb;;AAEA,aAAKgC,KAAL,GAAayS,OAAOzS,KAApB;AACA,aAAKiD,iBAAL,GAAyBwP,OAAOxP,iBAAhC;AACA,aAAKC,SAAL,GAAiBuP,OAAOvP,SAAxB;;AAEA,aAAK5W,KAAL,GAAammB,OAAOnmB,KAApB;AACH,C;;;;;;;;;;;;;;;;;;;ACZL;;0JAHA;AACA;;IAIakqB,kB,WAAAA,kB;AAET,gCAAY7C,WAAZ,EAAyB;AAAA;;AACrB,aAAKE,YAAL,GAAoBF,WAApB;AACH;;iCAEDzT,K,oBAAQ;AACJ,YAAI,CAAC,KAAK/B,SAAV,EAAqB;AACjB,iBAAKA,SAAL,GAAiB,KAAKsY,cAAL,CAAoB9W,IAApB,CAAyB,IAAzB,CAAjB;AACA,iBAAKkU,YAAL,CAAkBE,MAAlB,CAAyBzW,sBAAzB,CAAgD,KAAKa,SAArD;;AAEA;AACA,iBAAK0V,YAAL,CAAkBO,OAAlB,GAA4BnN,IAA5B,CAAiC,gBAAM;AACnC;AACH,aAFD,EAEG0N,KAFH,CAES,eAAK;AACV;AACA/3C,yBAAIojC,KAAJ,CAAU,+CAAV,EAA2D4U,IAAIhS,OAA/D;AACH,aALD;AAMH;AACJ,K;;iCAED3C,I,mBAAO;AACH,YAAI,KAAK9B,SAAT,EAAoB;AAChB,iBAAK0V,YAAL,CAAkBE,MAAlB,CAAyBtW,yBAAzB,CAAmD,KAAKU,SAAxD;AACA,mBAAO,KAAKA,SAAZ;AACH;AACJ,K;;iCAEDsY,c,6BAAiB;AAAA;;AACb,aAAK5C,YAAL,CAAkB6C,YAAlB,GAAiCzP,IAAjC,CAAsC,gBAAQ;AAC1CrqC,qBAAIqgC,KAAJ,CAAU,oEAAV;AACH,SAFD,EAEG,eAAO;AACNrgC,qBAAIojC,KAAJ,CAAU,6DAAV,EAAyE4U,IAAIhS,OAA7E;AACA,kBAAKiR,YAAL,CAAkBE,MAAlB,CAAyB4C,sBAAzB,CAAgD/B,GAAhD;AACH,SALD;AAMH,K;;;;;;;;;;;;;;;;;;;;;;qjBCxCL;AACA;;AAEA;;AACA;;;;;;;;IAEalH,K,WAAAA,K;AACT,qBAAoD;AAAA,uFAAJ,EAAI;AAAA,YAAvCtV,EAAuC,QAAvCA,EAAuC;AAAA,YAAnClH,IAAmC,QAAnCA,IAAmC;AAAA,YAA7BolB,OAA6B,QAA7BA,OAA6B;AAAA,YAApB7K,YAAoB,QAApBA,YAAoB;;AAAA;;AAChD,aAAK+E,GAAL,GAAWpY,MAAM,uBAAjB;AACA,aAAK/1B,KAAL,GAAa6uB,IAAb;;AAEA,YAAI,OAAOolB,OAAP,KAAmB,QAAnB,IAA+BA,UAAU,CAA7C,EAAgD;AAC5C,iBAAKM,QAAL,GAAgBN,OAAhB;AACH,SAFD,MAGK;AACD,iBAAKM,QAAL,GAAgBp1C,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAhB;AACH;AACD,aAAKqQ,aAAL,GAAsBpL,YAAtB;AACH;;oBAeDW,e,8BAAkB;AACdxvC,iBAAIqgC,KAAJ,CAAU,uBAAV;AACA,eAAOra,KAAKriB,SAAL,CAAe;AAClB63B,gBAAI,KAAKA,EADS;AAElBlH,kBAAM,KAAKA,IAFO;AAGlBolB,qBAAS,KAAKA,OAHI;AAIlB7K,0BAAc,KAAKA;AAJD,SAAf,CAAP;AAMH,K;;UAEMsB,iB,8BAAkBwJ,a,EAAe;AACpC35C,iBAAIqgC,KAAJ,CAAU,yBAAV;AACA,eAAO,IAAIyQ,KAAJ,CAAU9qB,KAAKrhB,KAAL,CAAWg1C,aAAX,CAAV,CAAP;AACH,K;;UAEM1I,e,4BAAgBiJ,O,EAASC,G,EAAK;;AAEjC,YAAIC,SAAS7hC,KAAKqxB,GAAL,KAAa,IAAb,GAAoBuQ,GAAjC;;AAEA,eAAOD,QAAQG,UAAR,GAAqBhQ,IAArB,CAA0B,gBAAQ;AACrCrqC,qBAAIqgC,KAAJ,CAAU,iCAAV,EAA6CngB,IAA7C;;AAEA,gBAAIo6B,WAAW,EAAf;;AAHqC,uCAI5Bl4C,CAJ4B;AAKjC,oBAAI0xB,MAAM5T,KAAK9d,CAAL,CAAV;AACIS,oBAAIq3C,QAAQjb,GAAR,CAAYnL,GAAZ,EAAiBuW,IAAjB,CAAsB,gBAAQ;AAClC,wBAAI2F,SAAS,KAAb;;AAEA,wBAAIrJ,IAAJ,EAAU;AACN,4BAAI;AACA,gCAAIjX,QAAQohB,MAAMX,iBAAN,CAAwBxJ,IAAxB,CAAZ;;AAEA3mC,qCAAIqgC,KAAJ,CAAU,4CAAV,EAAwDvM,GAAxD,EAA6DpE,MAAMgqB,OAAnE;;AAEA,gCAAIhqB,MAAMgqB,OAAN,IAAiBU,MAArB,EAA6B;AACzBpK,yCAAS,IAAT;AACH;AACJ,yBARD,CASA,OAAOhuC,CAAP,EAAU;AACNhC,qCAAIojC,KAAJ,CAAU,oDAAV,EAAgEtP,GAAhE,EAAqE9xB,EAAEgkC,OAAvE;AACAgK,qCAAS,IAAT;AACH;AACJ,qBAdD,MAeK;AACDhwC,iCAAIqgC,KAAJ,CAAU,qDAAV,EAAiEvM,GAAjE;AACAkc,iCAAS,IAAT;AACH;;AAED,wBAAIA,MAAJ,EAAY;AACRhwC,iCAAIqgC,KAAJ,CAAU,+CAAV,EAA2DvM,GAA3D;AACA,+BAAOomB,QAAQlK,MAAR,CAAelc,GAAf,CAAP;AACH;AACJ,iBA3BO,CANyB;;;AAmCjCwmB,yBAASh2C,IAAT,CAAczB,CAAd;AAnCiC;;AAIrC,iBAAK,IAAIT,IAAI,CAAb,EAAgBA,IAAI8d,KAAK7d,MAAzB,EAAiCD,GAAjC,EAAsC;AAAA,oBAE9BS,CAF8B;;AAAA,sBAA7BT,CAA6B;AAgCrC;;AAEDpC,qBAAIqgC,KAAJ,CAAU,kDAAV,EAA8Dia,SAASj4C,MAAvE;AACA,mBAAOmgC,QAAQ+X,GAAR,CAAYD,QAAZ,CAAP;AACH,SAxCM,CAAP;AAyCH,K;;;;4BAzEQ;AACL,mBAAO,KAAK1G,GAAZ;AACH;;;4BACU;AACP,mBAAO,KAAKnuC,KAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKu0C,QAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;;;AC5BL;;AACA;;AACA;;;;;;+eALA;AACA;;AAMA,IAAMO,gBAAgB,CAAtB,C,CAAyB;;IAEZ7a,K,WAAAA,K;;;AAET,mBAAYzb,IAAZ,EAA6D;AAAA,YAA3C2iB,KAA2C,uEAAnChmC,eAAOgmC,KAA4B;AAAA,YAArB4T,OAAqB,uEAAXt5C,SAAW;;AAAA;;AAAA,qDACzD,kBAAM+iB,IAAN,CADyD;;AAEzD,cAAKyf,MAAL,GAAckD,KAAd;;AAEA,YAAI4T,OAAJ,EAAa;AACT,kBAAKC,QAAL,GAAgBD,OAAhB;AACH,SAFD,MAGK;AACD,kBAAKC,QAAL,GAAgB;AAAA,uBAAMniC,KAAKqxB,GAAL,KAAa,IAAnB;AAAA,aAAhB;AACH;AATwD;AAU5D;;oBAMD3mC,I,iBAAKm9B,Q,EAAU;AACX,YAAIA,YAAY,CAAhB,EAAmB;AACfA,uBAAW,CAAX;AACH;AACDA,mBAAWx7B,SAASw7B,QAAT,CAAX;;AAEA,YAAIua,aAAa,KAAK/Q,GAAL,GAAWxJ,QAA5B;AACA,YAAI,KAAKua,UAAL,KAAoBA,UAApB,IAAkC,KAAKC,YAA3C,EAAyD;AACrD;AACA56C,qBAAIqgC,KAAJ,CAAU,sBAAsB,KAAKmG,KAA3B,GAAmC,oEAA7C,EAAmH,KAAKmU,UAAxH;AACA;AACH;;AAED,aAAKpa,MAAL;;AAEAvgC,iBAAIqgC,KAAJ,CAAU,sBAAsB,KAAKmG,KAA3B,GAAmC,gBAA7C,EAA+DpG,QAA/D;AACA,aAAKya,WAAL,GAAmBF,UAAnB;;AAEA;AACA;AACA;AACA,YAAIG,gBAAgBN,aAApB;AACA,YAAIpa,WAAW0a,aAAf,EAA8B;AAC1BA,4BAAgB1a,QAAhB;AACH;AACD,aAAKwa,YAAL,GAAoB,KAAKjX,MAAL,CAAYC,WAAZ,CAAwB,KAAKrC,SAAL,CAAewB,IAAf,CAAoB,IAApB,CAAxB,EAAmD+X,gBAAgB,IAAnE,CAApB;AACH,K;;oBAMDva,M,qBAAS;AACL,YAAI,KAAKqa,YAAT,EAAuB;AACnB56C,qBAAIqgC,KAAJ,CAAU,gBAAV,EAA4B,KAAKmG,KAAjC;AACA,iBAAK7C,MAAL,CAAYE,aAAZ,CAA0B,KAAK+W,YAA/B;AACA,iBAAKA,YAAL,GAAoB,IAApB;AACH;AACJ,K;;oBAEDrZ,S,wBAAY;AACR,YAAIwZ,OAAO,KAAKF,WAAL,GAAmB,KAAKjR,GAAnC;AACA5pC,iBAAIqgC,KAAJ,CAAU,qBAAqB,KAAKmG,KAA1B,GAAkC,oBAA5C,EAAkEuU,IAAlE;;AAEA,YAAI,KAAKF,WAAL,IAAoB,KAAKjR,GAA7B,EAAkC;AAC9B,iBAAKrJ,MAAL;AACA,6BAAMqG,KAAN;AACH;AACJ,K;;;;4BApDS;AACN,mBAAOhiC,SAAS,KAAK81C,QAAL,EAAT,CAAP;AACH;;;4BA8BgB;AACb,mBAAO,KAAKG,WAAZ;AACH;;;;EAhDsBtU,a;;;;;;;;;;;;;;;;;;;ACN3B;;AACA;;AACA;;0JALA;AACA;;IAMakO,W,WAAAA,W;AACT,yBAAYhI,QAAZ,EAA4F;AAAA,YAAtEC,eAAsE,uEAApDnC,wBAAoD;AAAA,YAAvCuH,mBAAuC,uEAAjBvxC,gCAAiB;;AAAA;;AACxF,YAAI,CAACksC,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,sCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,EAApB;AACA,aAAKwC,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACH;;0BAEDuJ,Y,2BAAwB;AAAA;;AAAA,YAAX5J,IAAW,uEAAJ,EAAI;;AACpBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAK0O,UAAL,GAAkB1O,KAAK0O,UAAL,IAAmB,oBAArC;AACA1O,aAAKnL,SAAL,GAAiBmL,KAAKnL,SAAL,IAAkB,KAAKwL,SAAL,CAAexL,SAAlD;AACAmL,aAAK1H,YAAL,GAAoB0H,KAAK1H,YAAL,IAAqB,KAAK+H,SAAL,CAAe/H,YAAxD;;AAEA,YAAI,CAAC0H,KAAK6I,IAAV,EAAgB;AACZn1C,qBAAIojC,KAAJ,CAAU,0CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,oBAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAK1H,YAAV,EAAwB;AACpB5kC,qBAAIojC,KAAJ,CAAU,kDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAK4I,aAAV,EAAyB;AACrBl1C,qBAAIojC,KAAJ,CAAU,mDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAKnL,SAAV,EAAqB;AACjBnhC,qBAAIojC,KAAJ,CAAU,+CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsB/B,gBAAtB,CAAuC,KAAvC,EAA8C9C,IAA9C,CAAmD,eAAO;AAC7DrqC,qBAAIqgC,KAAJ,CAAU,mDAAV;;AAEA,mBAAO,MAAKuM,YAAL,CAAkBjB,QAAlB,CAA2BvK,GAA3B,EAAgCkL,IAAhC,EAAsCjC,IAAtC,CAA2C,oBAAY;AAC1DrqC,yBAAIqgC,KAAJ,CAAU,6CAAV;AACA,uBAAOwP,QAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;0BAEDoL,oB,mCAAgC;AAAA;;AAAA,YAAX3O,IAAW,uEAAJ,EAAI;;AAC5BA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAK0O,UAAL,GAAkB1O,KAAK0O,UAAL,IAAmB,eAArC;AACA1O,aAAKnL,SAAL,GAAiBmL,KAAKnL,SAAL,IAAkB,KAAKwL,SAAL,CAAexL,SAAlD;AACAmL,aAAK8C,aAAL,GAAqB9C,KAAK8C,aAAL,IAAsB,KAAKzC,SAAL,CAAeyC,aAA1D;;AAEA,YAAI,CAAC9C,KAAK4O,aAAV,EAAyB;AACrBl7C,qBAAIojC,KAAJ,CAAU,2DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAKnL,SAAV,EAAqB;AACjBnhC,qBAAIojC,KAAJ,CAAU,uDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsB/B,gBAAtB,CAAuC,KAAvC,EAA8C9C,IAA9C,CAAmD,eAAO;AAC7DrqC,qBAAIqgC,KAAJ,CAAU,2DAAV;;AAEA,mBAAO,OAAKuM,YAAL,CAAkBjB,QAAlB,CAA2BvK,GAA3B,EAAgCkL,IAAhC,EAAsCjC,IAAtC,CAA2C,oBAAY;AAC1DrqC,yBAAIqgC,KAAJ,CAAU,qDAAV;AACA,uBAAOwP,QAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;;;;;;;;;;;;;;;;;;;;;AC1EL;;AACA;;AACA;;0JALA;AACA;;AAMA,IAAMsL,sBAAsB,cAA5B;AACA,IAAMC,uBAAuB,eAA7B;;IAEaz6C,qB,WAAAA,qB;AACT,mCAAY8rC,QAAZ,EAAyG;AAAA,YAAnFhC,kBAAmF,uEAA9D5pC,eAAO0mC,cAAuD;AAAA,YAAvCuK,mBAAuC,uEAAjBvxC,gCAAiB;;AAAA;;AACrG,YAAI,CAACksC,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,kDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,uBAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAK4O,mBAAL,GAA2B5Q,kBAA3B;AACA,aAAKyE,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACH;;oCAED2O,M,mBAAOjS,K,EAAOkS,Q,EAAiC;AAAA;;AAAA,YAAvBzgC,IAAuB,uEAAhB,cAAgB;;AAC3C,YAAI,CAACuuB,KAAL,EAAY;AACRrpC,qBAAIojC,KAAJ,CAAU,iDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,oBAAV,CAAN;AACH;;AAED,YAAIqZ,SAASqgC,mBAAT,IAAgCrgC,QAAQsgC,oBAA5C,EAAkE;AAC9Dp7C,qBAAIojC,KAAJ,CAAU,kDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,qBAAV,CAAN;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsB3B,qBAAtB,GAA8ClD,IAA9C,CAAmD,eAAO;AAC7D,gBAAI,CAACjJ,GAAL,EAAU;AACN,oBAAIma,QAAJ,EAAc;AACVv7C,6BAAIojC,KAAJ,CAAU,wDAAV;AACA,0BAAM,IAAI3hC,KAAJ,CAAU,0BAAV,CAAN;AACH;;AAED;AACA;AACH;;AAEDzB,qBAAIqgC,KAAJ,CAAU,4CAA4CvlB,IAAtD;AACA,gBAAIqmB,YAAY,MAAKwL,SAAL,CAAexL,SAA/B;AACA,gBAAIiO,gBAAgB,MAAKzC,SAAL,CAAeyC,aAAnC;AACA,mBAAO,MAAKoM,OAAL,CAAapa,GAAb,EAAkBD,SAAlB,EAA6BiO,aAA7B,EAA4C/F,KAA5C,EAAmDvuB,IAAnD,CAAP;AACH,SAfM,CAAP;AAgBH,K;;oCAED0gC,O,oBAAQpa,G,EAAKD,S,EAAWiO,a,EAAe/F,K,EAAOvuB,I,EAAM;AAAA;;AAEhD,eAAO,IAAI0nB,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;;AAEpC,gBAAImX,MAAM,IAAI,OAAKJ,mBAAT,EAAV;AACAI,gBAAIjW,IAAJ,CAAS,MAAT,EAAiBpE,GAAjB;;AAEAqa,gBAAI/Y,MAAJ,GAAa,YAAM;AACf1iC,yBAAIqgC,KAAJ,CAAU,8DAAV,EAA0Eob,IAAIxQ,MAA9E;;AAEA,oBAAIwQ,IAAIxQ,MAAJ,KAAe,GAAnB,EAAwB;AACpBxI;AACH,iBAFD,MAGK;AACD6B,2BAAO7iC,MAAMg6C,IAAIjQ,UAAJ,GAAiB,IAAjB,GAAwBiQ,IAAIxQ,MAA5B,GAAqC,GAA3C,CAAP;AACH;AACJ,aATD;AAUAwQ,gBAAIhQ,OAAJ,GAAc,YAAM;AAChBzrC,yBAAIqgC,KAAJ,CAAU,8CAAV;AACAiE,uBAAO,eAAP;AACH,aAHD;;AAKA,gBAAI3B,OAAO,eAAer9B,mBAAmB67B,SAAnB,CAA1B;AACA,gBAAIiO,aAAJ,EAAmB;AACfzM,wBAAQ,oBAAoBr9B,mBAAmB8pC,aAAnB,CAA5B;AACH;AACDzM,oBAAQ,sBAAsBr9B,mBAAmBwV,IAAnB,CAA9B;AACA6nB,oBAAQ,YAAYr9B,mBAAmB+jC,KAAnB,CAApB;;AAEAoS,gBAAI/P,gBAAJ,CAAqB,cAArB,EAAqC,mCAArC;AACA+P,gBAAIhY,IAAJ,CAASd,IAAT;AACH,SA7BM,CAAP;AA8BH,K;;;;;;;;;;;;;;;;;;;;;;AChFL;;AACA;;0JAJA;AACA;;IAKaqR,U,WAAAA,U;;;;;eACF+E,a,0BAAc3X,G,EAAKld,I,EAAMykB,K,EAAO;AACnC,YAAIvH,IAAI15B,OAAJ,CAAY,GAAZ,IAAmB,CAAvB,EAA0B;AACtB05B,mBAAO,GAAP;AACH;;AAED,YAAIA,IAAIA,IAAI/+B,MAAJ,GAAa,CAAjB,MAAwB,GAA5B,EAAiC;AAC7B++B,mBAAO,GAAP;AACH;;AAEDA,eAAO97B,mBAAmB4e,IAAnB,CAAP;AACAkd,eAAO,GAAP;AACAA,eAAO97B,mBAAmBqjC,KAAnB,CAAP;;AAEA,eAAOvH,GAAP;AACH,K;;eAEM6S,gB,6BAAiBtL,K,EAAyC;AAAA,YAAlCiH,SAAkC,uEAAtB,GAAsB;AAAA,YAAjB8L,MAAiB,uEAAR76C,cAAQ;;AAC7D,YAAI,OAAO8nC,KAAP,KAAiB,QAArB,EAA8B;AAC1BA,oBAAQ+S,OAAOtU,QAAP,CAAgBiB,IAAxB;AACH;;AAED,YAAIzG,MAAM+G,MAAMgT,WAAN,CAAkB/L,SAAlB,CAAV;AACA,YAAIhO,OAAO,CAAX,EAAc;AACV+G,oBAAQA,MAAM9jC,MAAN,CAAa+8B,MAAM,CAAnB,CAAR;AACH;;AAED,YAAIgO,cAAc,GAAlB,EAAuB;AACnB;AACAhO,kBAAM+G,MAAMjhC,OAAN,CAAc,GAAd,CAAN;AACA,gBAAIk6B,OAAO,CAAX,EAAc;AACV+G,wBAAQA,MAAM9jC,MAAN,CAAa,CAAb,EAAgB+8B,GAAhB,CAAR;AACH;AACJ;;AAED,YAAImC,SAAS,EAAb;AAAA,YACI6X,QAAQ,mBADZ;AAAA,YAEIr3C,CAFJ;;AAIA,YAAIs3C,UAAU,CAAd;AACA,eAAOt3C,IAAIq3C,MAAME,IAAN,CAAWnT,KAAX,CAAX,EAA8B;AAC1B5E,mBAAO5+B,mBAAmBZ,EAAE,CAAF,CAAnB,CAAP,IAAmCY,mBAAmBZ,EAAE,CAAF,CAAnB,CAAnC;AACA,gBAAIs3C,YAAY,EAAhB,EAAoB;AAChB77C,yBAAIojC,KAAJ,CAAU,8EAAV,EAA0FuF,KAA1F;AACA,uBAAO;AACHvF,2BAAO;AADJ,iBAAP;AAGH;AACJ;;AAED,aAAK,IAAI2Y,IAAT,IAAiBhY,MAAjB,EAAyB;AACrB,mBAAOA,MAAP;AACH;;AAED,eAAO,EAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBC7DL;AACA;;AAEA;;;;IAEajjC,I,WAAAA,I;AACT,wBAAmH;AAAA,YAAtGm0C,QAAsG,QAAtGA,QAAsG;AAAA,YAA5F1R,aAA4F,QAA5FA,aAA4F;AAAA,YAA7ErD,YAA6E,QAA7EA,YAA6E;AAAA,YAA/Dgb,aAA+D,QAA/DA,aAA+D;AAAA,YAAhD/B,UAAgD,QAAhDA,UAAgD;AAAA,YAApClL,KAAoC,QAApCA,KAAoC;AAAA,YAA7BoH,OAA6B,QAA7BA,OAA6B;AAAA,YAApB+D,UAAoB,QAApBA,UAAoB;AAAA,YAAR1pB,KAAQ,QAARA,KAAQ;;AAAA;;AAC/G,aAAKulB,QAAL,GAAgBA,QAAhB;AACA,aAAK1R,aAAL,GAAqBA,aAArB;AACA,aAAKrD,YAAL,GAAoBA,YAApB;AACA,aAAKgb,aAAL,GAAqBA,aAArB;AACA,aAAK/B,UAAL,GAAkBA,UAAlB;AACA,aAAKlL,KAAL,GAAaA,KAAb;AACA,aAAKoH,OAAL,GAAeA,OAAf;AACA,aAAK+D,UAAL,GAAkBA,UAAlB;AACA,aAAK1pB,KAAL,GAAaA,KAAb;AACH;;mBA6BD8f,e,8BAAkB;AACdxvC,iBAAIqgC,KAAJ,CAAU,sBAAV;AACA,eAAOra,KAAKriB,SAAL,CAAe;AAClBsxC,sBAAU,KAAKA,QADG;AAElB1R,2BAAe,KAAKA,aAFF;AAGlBrD,0BAAc,KAAKA,YAHD;AAIlBgb,2BAAe,KAAKA,aAJF;AAKlB/B,wBAAY,KAAKA,UALC;AAMlBlL,mBAAO,KAAKA,KANM;AAOlBoH,qBAAS,KAAKA,OAPI;AAQlB+D,wBAAY,KAAKA;AARC,SAAf,CAAP;AAUH,K;;SAEMjJ,iB,8BAAkBwJ,a,EAAe;AACpC35C,iBAAIqgC,KAAJ,CAAU,wBAAV;AACA,eAAO,IAAIv/B,IAAJ,CAASklB,KAAKrhB,KAAL,CAAWg1C,aAAX,CAAT,CAAP;AACH,K;;;;4BA5CgB;AACb,gBAAI,KAAKP,UAAT,EAAqB;AACjB,oBAAIxP,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,uBAAO,KAAKwP,UAAL,GAAkBxP,GAAzB;AACH;AACD,mBAAOzoC,SAAP;AACH,S;0BACcwnC,K,EAAO;AAClB,gBAAIxI,aAAav7B,SAAS+jC,KAAT,CAAjB;AACA,gBAAI,OAAOxI,UAAP,KAAsB,QAAtB,IAAkCA,aAAa,CAAnD,EAAsD;AAClD,oBAAIyJ,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,qBAAKwP,UAAL,GAAkBxP,MAAMzJ,UAAxB;AACH;AACJ;;;4BAEa;AACV,gBAAIA,aAAa,KAAKA,UAAtB;AACA,gBAAIA,eAAeh/B,SAAnB,EAA8B;AAC1B,uBAAOg/B,cAAc,CAArB;AACH;AACD,mBAAOh/B,SAAP;AACH;;;4BAEY;AACT,mBAAO,CAAC,KAAK8sC,KAAL,IAAc,EAAf,EAAmBttB,KAAnB,CAAyB,GAAzB,CAAP;AACH;;;;;;;;;;;;;;;;;;;;;;;ACxCL;;AACA;;AACA;;AACA;;0JANA;AACA;;IAOa2zB,e,WAAAA,e;AACT,6BACI7H,QADJ,EAKE;AAAA,YAHEC,eAGF,uEAHoBnC,wBAGpB;AAAA,YAFEuH,mBAEF,uEAFwBvxC,gCAExB;AAAA,YADEg0C,QACF,uEADaxL,kBACb;;AAAA;;AACE,YAAI,CAAC0D,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,0CAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,CAAoBvrC,SAApB,EAA+BA,SAA/B,EAA0C,KAAK66C,iBAAL,CAAuBjZ,IAAvB,CAA4B,IAA5B,CAA1C,CAApB;AACA,aAAKmM,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACA,aAAKgI,SAAL,GAAiBJ,QAAjB;AACH;;8BAEDe,S,sBAAUjM,K,EAAO;AAAA;;AACb,YAAI,CAACA,KAAL,EAAY;AACRrpC,qBAAIojC,KAAJ,CAAU,4CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,qBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsBhC,mBAAtB,GAA4C7C,IAA5C,CAAiD,eAAO;AAC3DrqC,qBAAIqgC,KAAJ,CAAU,kDAAV,EAA8De,GAA9D;;AAEA,mBAAO,MAAKwL,YAAL,CAAkB9B,OAAlB,CAA0B1J,GAA1B,EAA+BiI,KAA/B,EAAsCgB,IAAtC,CAA2C,kBAAU;AACxDrqC,yBAAIqgC,KAAJ,CAAU,4CAAV,EAAwDkV,MAAxD;AACA,uBAAOA,MAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;8BAEDyG,iB,8BAAkBjR,G,EAAK;AAAA;;AACnB,YAAI;AACA,gBAAI3B,MAAM,KAAKuL,SAAL,CAAexL,QAAf,CAAwB4B,IAAIQ,YAA5B,CAAV;AACA,gBAAI,CAACnC,GAAD,IAAQ,CAACA,IAAIE,MAAb,IAAuB,CAACF,IAAIG,OAAhC,EAAyC;AACrCvpC,yBAAIojC,KAAJ,CAAU,wDAAV,EAAoEgG,GAApE;AACA,uBAAO5G,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,gBAAIs5B,MAAMqO,IAAIE,MAAJ,CAAWvO,GAArB;;AAEA,gBAAIkhB,sBAAJ;AACA,oBAAQ,KAAKtP,SAAL,CAAegF,iBAAvB;AACI,qBAAK,IAAL;AACIsK,oCAAgB,KAAK/M,gBAAL,CAAsBnC,SAAtB,EAAhB;AACA;AACJ,qBAAK,KAAL;AACIkP,oCAAgBzZ,QAAQC,OAAR,CAAgB2G,IAAIG,OAAJ,CAAY9L,GAA5B,CAAhB;AACA;AACJ;AACIwe,oCAAgBzZ,QAAQC,OAAR,CAAgB,KAAKkK,SAAL,CAAegF,iBAA/B,CAAhB;AACA;AATR;;AAYA,mBAAOsK,cAAc5R,IAAd,CAAmB,kBAAU;AAChCrqC,yBAAIqgC,KAAJ,CAAU,wDAAwDoJ,MAAlE;;AAEA,uBAAO,OAAKyF,gBAAL,CAAsBzB,cAAtB,GAAuCpD,IAAvC,CAA4C,gBAAQ;AACvD,wBAAI,CAACnqB,IAAL,EAAW;AACPlgB,iCAAIojC,KAAJ,CAAU,kEAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,+BAAV,CAAf,CAAP;AACH;;AAEDzB,6BAAIqgC,KAAJ,CAAU,0DAAV;AACA,wBAAIvM,YAAJ;AACA,wBAAI,CAACiH,GAAL,EAAU;AACN7a,+BAAO,OAAKq2B,YAAL,CAAkBr2B,IAAlB,EAAwBkpB,IAAIE,MAAJ,CAAW1c,GAAnC,CAAP;;AAEA,4BAAI1M,KAAK7d,MAAL,GAAc,CAAlB,EAAqB;AACjBrC,qCAAIojC,KAAJ,CAAU,qGAAV;AACA,mCAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kEAAV,CAAf,CAAP;AACH,yBAHD,MAIK;AACD;AACA;AACAqyB,kCAAM5T,KAAK,CAAL,CAAN;AACH;AACJ,qBAZD,MAaK;AACD4T,8BAAM5T,KAAKs2B,MAAL,CAAY,eAAO;AACrB,mCAAO1iB,IAAIiH,GAAJ,KAAYA,GAAnB;AACH,yBAFK,EAEH,CAFG,CAAN;AAGH;;AAED,wBAAI,CAACjH,GAAL,EAAU;AACN9zB,iCAAIojC,KAAJ,CAAU,qFAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED,wBAAIioC,WAAW,OAAKiD,SAAL,CAAexL,SAA9B;;AAEA,wBAAIkV,qBAAqB,OAAK1J,SAAL,CAAehD,SAAxC;AACA3pC,6BAAIqgC,KAAJ,CAAU,sFAAV,EAAkGgW,kBAAlG;;AAEA,2BAAO,OAAK1B,SAAL,CAAenL,WAAf,CAA2BuB,IAAIQ,YAA/B,EAA6CzX,GAA7C,EAAkD2V,MAAlD,EAA0DC,QAA1D,EAAoE2M,kBAApE,EAAwFl1C,SAAxF,EAAmG,IAAnG,EAAyGkpC,IAAzG,CAA8G,YAAM;AACvHrqC,iCAAIqgC,KAAJ,CAAU,8DAAV;AACA,+BAAO+I,IAAIG,OAAX;AACH,qBAHM,CAAP;AAIH,iBAzCM,CAAP;AA0CH,aA7CM,CAAP;AA8CA;AACH,SArED,CAsEA,OAAOvnC,CAAP,EAAU;AACNhC,qBAAIojC,KAAJ,CAAU,+DAAV,EAA2EphC,EAAEgkC,OAA7E;AACA1B,mBAAOtiC,CAAP;AACA;AACH;AACJ,K;;8BAEDu0C,Y,yBAAar2B,I,EAAM0M,G,EAAK;AACpB,YAAIyJ,MAAM,IAAV;AACA,YAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AACtBjV,kBAAM,KAAN;AACH,SAFD,MAGK,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA;AACDr2B,qBAAIqgC,KAAJ,CAAU,mDAAV,EAA+DzT,GAA/D;AACA,mBAAO,EAAP;AACH;;AAED5sB,iBAAIqgC,KAAJ,CAAU,iEAAV,EAA6EhK,GAA7E;;AAEAnW,eAAOA,KAAKs2B,MAAL,CAAY,eAAO;AACtB,mBAAO1iB,IAAIuC,GAAJ,KAAYA,GAAnB;AACH,SAFM,CAAP;;AAIAr2B,iBAAIqgC,KAAJ,CAAU,+DAAV,EAA2EhK,GAA3E,EAAgFnW,KAAK7d,MAArF;;AAEA,eAAO6d,IAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;;;AC9IL;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;;;+eAZA;AACA;;IAca7f,W,WAAAA,W;;;AACT,2BAME;AAAA,YANUosC,QAMV,uEANqB,EAMrB;AAAA,YALEyP,sBAKF,uEAL2BtC,sCAK3B;AAAA,YAJEuC,kBAIF,uEAJuBv7C,8BAIvB;AAAA,YAHEw7C,yBAGF,uEAH8Bz7C,4CAG9B;AAAA,YAFE6zC,eAEF,uEAFoBC,wBAEpB;AAAA,YADEF,QACF,uEADaxL,kBACb;;AAAA;;AAEE,YAAI,EAAE0D,oBAAoB4P,wCAAtB,CAAJ,EAAgD;AAC5C5P,uBAAW,IAAI4P,wCAAJ,CAAwB5P,QAAxB,CAAX;AACH;;AAJH,qDAKE,uBAAMA,QAAN,CALF;;AAOE,cAAK6P,OAAL,GAAe,IAAIC,oCAAJ,CAAsB9P,QAAtB,CAAf;AACA,cAAK+P,mBAAL,GAA2B,IAAIN,sBAAJ,OAA3B;;AAEA;AACA,YAAI,MAAKzP,QAAL,CAAcgQ,oBAAlB,EAAwC;AACpCz8C,qBAAIqgC,KAAJ,CAAU,+EAAV;AACA,kBAAKqc,gBAAL;AACH;;AAED,YAAI,MAAKjQ,QAAL,CAAckQ,cAAlB,EAAkC;AAC9B38C,qBAAIqgC,KAAJ,CAAU,4EAAV;AACA,kBAAKuc,eAAL,GAAuB,IAAIT,kBAAJ,OAAvB;AACH;;AAED,cAAKU,sBAAL,GAA8B,IAAIT,yBAAJ,CAA8B,MAAKzP,SAAnC,CAA9B;AACA,cAAKiI,YAAL,GAAoB,IAAIJ,eAAJ,CAAoB,MAAK7H,SAAzB,CAApB;AACA,cAAKgI,SAAL,GAAiBJ,QAAjB;AAvBF;AAwBD;;0BAmBDiD,O,sBAAU;AAAA;;AACN,eAAO,KAAKsF,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,gBAAIoN,IAAJ,EAAU;AACNz3C,yBAAI6rC,IAAJ,CAAS,kCAAT;;AAEA,uBAAKyQ,OAAL,CAAatc,IAAb,CAAkByX,IAAlB,EAAwB,KAAxB;;AAEA,uBAAOA,IAAP;AACH,aAND,MAOK;AACDz3C,yBAAI6rC,IAAJ,CAAS,gDAAT;AACA,uBAAO,IAAP;AACH;AACJ,SAZM,CAAP;AAaH,K;;0BAEDkR,U,yBAAa;AAAA;;AACT,eAAO,KAAKC,SAAL,CAAe,IAAf,EAAqB3S,IAArB,CAA0B,YAAM;AACnCrqC,qBAAI6rC,IAAJ,CAAS,mDAAT;AACA,mBAAKyQ,OAAL,CAAa7b,MAAb;AACH,SAHM,CAAP;AAIH,K;;0BAEDwc,c,6BAA0B;AAAA,YAAX3Q,IAAW,uEAAJ,EAAI;;AACtBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIqO,YAAY;AACZ/I,kCAAuB7H,KAAK6H;AADhB,SAAhB;AAGA,eAAO,KAAKgJ,YAAL,CAAkB7Q,IAAlB,EAAwB,KAAK8Q,kBAA7B,EAAiDF,SAAjD,EAA4D7S,IAA5D,CAAiE,YAAI;AACxErqC,qBAAI6rC,IAAJ,CAAS,wCAAT;AACH,SAFM,CAAP;AAGH,K;;0BACDwR,sB,mCAAuBjc,G,EAAK;AACxB,eAAO,KAAKkc,UAAL,CAAgBlc,OAAO,KAAKgc,kBAAL,CAAwBhc,GAA/C,EAAoDiJ,IAApD,CAAyD,gBAAQ;AACpE,gBAAIoN,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,yBAAI6rC,IAAJ,CAAS,iEAAT,EAA4E4L,KAAKpC,OAAL,CAAa3X,GAAzF;AACH,aAFD,MAGK;AACD19B,yBAAI6rC,IAAJ,CAAS,4CAAT;AACH;;AAED,mBAAO4L,IAAP;AACH,SATM,CAAP;AAUH,K;;0BAED8F,W,0BAAuB;AAAA,YAAXjR,IAAW,uEAAJ,EAAI;;AACnBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIzN,MAAMkL,KAAK1H,YAAL,IAAqB,KAAK6H,QAAL,CAAc+Q,kBAAnC,IAAyD,KAAK/Q,QAAL,CAAc7H,YAAjF;AACA,YAAI,CAACxD,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,2EAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED6qC,aAAK1H,YAAL,GAAoBxD,GAApB;AACAkL,aAAKlK,OAAL,GAAe,OAAf;;AAEA,eAAO,KAAKqb,OAAL,CAAanR,IAAb,EAAmB,KAAKoR,eAAxB,EAAyC;AAC5C7Y,sBAAUzD,GADkC;AAE5C4C,iCAAqBsI,KAAKtI,mBAAL,IAA4B,KAAKyI,QAAL,CAAczI,mBAFnB;AAG5CW,+BAAmB2H,KAAK3H,iBAAL,IAA0B,KAAK8H,QAAL,CAAc9H;AAHf,SAAzC,EAIJ0F,IAJI,CAIC,gBAAQ;AACZ,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,kEAAT,EAA6E4L,KAAKpC,OAAL,CAAa3X,GAA1F;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,iCAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAfM,CAAP;AAgBH,K;;0BACDkG,mB,gCAAoBvc,G,EAAK;AACrB,eAAO,KAAKwc,eAAL,CAAqBxc,GAArB,EAA0B,KAAKsc,eAA/B,EAAgDrT,IAAhD,CAAqD,gBAAQ;AAChE,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,8DAAT,EAAyE4L,KAAKpC,OAAL,CAAa3X,GAAtF;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,yCAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAXM,EAWJM,KAXI,CAWE,eAAK;AACV/3C,qBAAIojC,KAAJ,CAAU,SAAmD4U,IAAIhS,OAAjE;AACH,SAbM,CAAP;AAcH,K;;0BAED8T,Y,2BAAwB;AAAA;;AAAA,YAAXxN,IAAW,uEAAJ,EAAI;;AACpBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA;AACA,eAAO,KAAKiO,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,gBAAIoN,QAAQA,KAAKyD,aAAjB,EAAgC;AAC5B5O,qBAAK4O,aAAL,GAAqBzD,KAAKyD,aAA1B;AACA,uBAAO,OAAK2C,gBAAL,CAAsBvR,IAAtB,CAAP;AACH,aAHD,MAIK;AACDA,qBAAK+B,aAAL,GAAqB/B,KAAK+B,aAAL,IAAuB,OAAK5B,QAAL,CAAcqR,2BAAd,IAA6CrG,IAA7C,IAAqDA,KAAKxC,QAAtG;AACA,oBAAIwC,QAAQ,OAAK9K,SAAL,CAAeoR,wBAA3B,EAAqD;AACjD/9C,6BAAIqgC,KAAJ,CAAU,2DAAV,EAAuEoX,KAAKpC,OAAL,CAAa3X,GAApF;AACA4O,yBAAK0R,WAAL,GAAmBvG,KAAKpC,OAAL,CAAa3X,GAAhC;AACH;AACD,uBAAO,OAAKugB,mBAAL,CAAyB3R,IAAzB,CAAP;AACH;AACJ,SAbM,CAAP;AAcH,K;;0BAEDuR,gB,+BAA4B;AAAA;;AAAA,YAAXvR,IAAW,uEAAJ,EAAI;;AACxB,eAAO,KAAKsI,YAAL,CAAkBqG,oBAAlB,CAAuC3O,IAAvC,EAA6CjC,IAA7C,CAAkD,kBAAU;AAC/D,gBAAI,CAACsL,MAAL,EAAa;AACT31C,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,0CAAf,CAAP;AACH;AACD,gBAAI,CAACqR,OAAOzV,YAAZ,EAA0B;AACtBlgC,yBAAIojC,KAAJ,CAAU,4EAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,8CAAf,CAAP;AACH;;AAED,mBAAO,OAAKwY,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,oBAAIoN,IAAJ,EAAU;AACN,wBAAIyG,oBAAoB1b,QAAQC,OAAR,EAAxB;AACA,wBAAIkT,OAAOV,QAAX,EAAqB;AACjBiJ,4CAAoB,OAAKC,qCAAL,CAA2C1G,KAAKpC,OAAhD,EAAyDM,OAAOV,QAAhE,CAApB;AACH;;AAED,2BAAOiJ,kBAAkB7T,IAAlB,CAAuB,YAAM;AAChCrqC,iCAAIqgC,KAAJ,CAAU,8DAAV;AACAoX,6BAAKxC,QAAL,GAAgBU,OAAOV,QAAvB;AACAwC,6BAAKvX,YAAL,GAAoByV,OAAOzV,YAA3B;AACAuX,6BAAKyD,aAAL,GAAqBvF,OAAOuF,aAAP,IAAwBzD,KAAKyD,aAAlD;AACAzD,6BAAKtX,UAAL,GAAkBwV,OAAOxV,UAAzB;;AAEA,+BAAO,OAAK6c,SAAL,CAAevF,IAAf,EAAqBpN,IAArB,CAA0B,YAAI;AACjC,mCAAKiS,OAAL,CAAatc,IAAb,CAAkByX,IAAlB;AACA,mCAAOA,IAAP;AACH,yBAHM,CAAP;AAIH,qBAXM,CAAP;AAYH,iBAlBD,MAmBK;AACD,2BAAO,IAAP;AACH;AACJ,aAvBM,CAAP;AAwBH,SAlCM,CAAP;AAmCH,K;;0BAED0G,qC,kDAAsC9I,O,EAASJ,Q,EAAU;AAAA;;AACrD,eAAO,KAAK/F,gBAAL,CAAsBnC,SAAtB,GAAkC1C,IAAlC,CAAuC,kBAAU;AACpD,mBAAO,OAAKsK,SAAL,CAAe3K,qBAAf,CAAqCiL,QAArC,EAA+CxL,MAA/C,EAAuD,OAAKkD,SAAL,CAAexL,SAAtE,EAAiF,OAAKwL,SAAL,CAAehD,SAAhG,EAA2GU,IAA3G,CAAgH,mBAAW;AAC9H,oBAAI,CAACd,OAAL,EAAc;AACVvpC,6BAAIojC,KAAJ,CAAU,gFAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQ7L,GAAR,KAAgB2X,QAAQ3X,GAA5B,EAAiC;AAC7B19B,6BAAIojC,KAAJ,CAAU,+FAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4CAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQ6U,SAAR,IAAqB7U,QAAQ6U,SAAR,KAAsB/I,QAAQ+I,SAAvD,EAAkE;AAC9Dp+C,6BAAIojC,KAAJ,CAAU,4GAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yDAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQW,GAAR,IAAeX,QAAQW,GAAR,KAAgBmL,QAAQnL,GAA3C,EAAgD;AAC5ClqC,6BAAIojC,KAAJ,CAAU,gGAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6CAAV,CAAf,CAAP;AACH;AACD,oBAAI,CAAC8nC,QAAQW,GAAT,IAAgBmL,QAAQnL,GAA5B,EAAiC;AAC7BlqC,6BAAIojC,KAAJ,CAAU,0GAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,uDAAV,CAAf,CAAP;AACH;AACJ,aArBM,CAAP;AAsBH,SAvBM,CAAP;AAwBH,K;;0BAEDw8C,mB,kCAA+B;AAAA,YAAX3R,IAAW,uEAAJ,EAAI;;AAC3B,YAAIlL,MAAMkL,KAAK1H,YAAL,IAAqB,KAAK6H,QAAL,CAAc4R,mBAAnC,IAA0D,KAAK5R,QAAL,CAAc7H,YAAlF;AACA,YAAI,CAACxD,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,6DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,mCAAV,CAAf,CAAP;AACH;;AAED6qC,aAAK1H,YAAL,GAAoBxD,GAApB;AACAkL,aAAK4B,MAAL,GAAc5B,KAAK4B,MAAL,IAAe,MAA7B;;AAEA,eAAO,KAAKuP,OAAL,CAAanR,IAAb,EAAmB,KAAKgS,gBAAxB,EAA0C;AAC7CzZ,sBAAUzD,GADmC;AAE7C0G,kCAAsBwE,KAAKxE,oBAAL,IAA6B,KAAK2E,QAAL,CAAc3E;AAFpB,SAA1C,EAGJuC,IAHI,CAGC,gBAAQ;AACZ,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,uDAAT,EAAkE4L,KAAKpC,OAAL,CAAa3X,GAA/E;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,kCAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAdM,CAAP;AAeH,K;;0BAED8G,oB,iCAAqBnd,G,EAAK;AACtB,eAAO,KAAKwc,eAAL,CAAqBxc,GAArB,EAA0B,KAAKkd,gBAA/B,EAAiDjU,IAAjD,CAAsD,gBAAQ;AACjE,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,+DAAT,EAA0E4L,KAAKpC,OAAL,CAAa3X,GAAvF;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,0CAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAXM,CAAP;AAYH,K;;0BAED+G,c,2BAAepd,G,EAAK;AAAA;;AAChB,eAAO,KAAKqO,uBAAL,CAA6BrO,GAA7B,EAAkCiJ,IAAlC,CAAuC,gBAAuB;AAAA,gBAArB3a,KAAqB,QAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,QAAdA,QAAc;;AACjE,gBAAIngB,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAKwO,sBAAL,CAA4Bjc,GAA5B,CAAP;AACH;AACD,gBAAI1R,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAK8O,mBAAL,CAAyBvc,GAAzB,CAAP;AACH;AACD,gBAAI1R,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAK0P,oBAAL,CAA0Bnd,GAA1B,CAAP;AACH;AACD,mBAAOoB,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gCAAV,CAAf,CAAP;AACH,SAXM,CAAP;AAYH,K;;0BAEDg9C,e,4BAAgBrd,G,EAAKmS,Q,EAAU;AAAA;;AAC3B,eAAO,KAAK5C,wBAAL,CAA8BvP,GAA9B,EAAmCiJ,IAAnC,CAAwC,iBAAuB;AAAA,gBAArB3a,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,SAAdA,QAAc;;AAClE,gBAAIngB,KAAJ,EAAW;AACP,oBAAIA,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,2BAAO,OAAK6P,uBAAL,CAA6Btd,GAA7B,CAAP;AACH;AACD,oBAAI1R,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,2BAAO,OAAK8P,oBAAL,CAA0Bvd,GAA1B,EAA+BmS,QAA/B,CAAP;AACH;AACD,uBAAO/Q,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gCAAV,CAAf,CAAP;AACH;AACD,mBAAOouC,QAAP;AACH,SAXM,CAAP;AAYH,K;;0BAED8H,kB,iCAA8B;AAAA;;AAAA,YAAXrL,IAAW,uEAAJ,EAAI;;AAC1BA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB,CAH0B,CAGE;AAC5B,YAAIzN,MAAMkL,KAAK1H,YAAL,IAAqB,KAAK6H,QAAL,CAAc4R,mBAAnC,IAA0D,KAAK5R,QAAL,CAAc7H,YAAlF;AACA,YAAI,CAACxD,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,mEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,mCAAV,CAAf,CAAP;AACH;;AAED6qC,aAAK1H,YAAL,GAAoBxD,GAApB;AACAkL,aAAK4B,MAAL,GAAc,MAAd;AACA5B,aAAK0B,aAAL,GAAqB1B,KAAK0B,aAAL,IAAsB,KAAKvB,QAAL,CAAcmS,0BAAzD;AACAtS,aAAK2B,KAAL,GAAa3B,KAAK2B,KAAL,IAAc,QAA3B;AACA3B,aAAKwC,YAAL,GAAoB,IAApB;;AAEA,eAAO,KAAKqO,YAAL,CAAkB7Q,IAAlB,EAAwB,KAAKgS,gBAA7B,EAA+C;AAClDzZ,sBAAUzD,GADwC;AAElD0G,kCAAsBwE,KAAKxE,oBAAL,IAA6B,KAAK2E,QAAL,CAAc3E;AAFf,SAA/C,EAGJuC,IAHI,CAGC,uBAAe;AACnB,mBAAO,OAAK+F,qBAAL,CAA2ByO,YAAYzd,GAAvC,EAA4CiJ,IAA5C,CAAiD,0BAAkB;AACtErqC,yBAAIqgC,KAAJ,CAAU,qDAAV;;AAEA,oBAAIye,eAAevb,aAAf,IAAgCub,eAAezJ,OAAf,CAAuB3X,GAA3D,EAAgE;AAC5D19B,6BAAI6rC,IAAJ,CAAS,sEAAT,EAAkFiT,eAAezJ,OAAf,CAAuB3X,GAAzG;AACA,2BAAO;AACH6F,uCAAeub,eAAevb,aAD3B;AAEH7F,6BAAKohB,eAAezJ,OAAf,CAAuB3X,GAFzB;AAGHoa,6BAAKgH,eAAezJ,OAAf,CAAuByC;AAHzB,qBAAP;AAKH,iBAPD,MAQK;AACD93C,6BAAI6rC,IAAJ,CAAS,uDAAT;AACH;AACJ,aAdM,EAeNkM,KAfM,CAeA,eAAO;AACV,oBAAIC,IAAIzU,aAAJ,IAAqB,OAAKkJ,QAAL,CAAciL,uBAAvC,EAAgE;AAC5D,wBAAIM,IAAIhS,OAAJ,IAAe,gBAAf,IACAgS,IAAIhS,OAAJ,IAAe,kBADf,IAEAgS,IAAIhS,OAAJ,IAAe,sBAFf,IAGAgS,IAAIhS,OAAJ,IAAe,4BAHnB,EAIE;AACEhmC,iCAAI6rC,IAAJ,CAAS,+EAAT;AACA,+BAAO;AACHtI,2CAAeyU,IAAIzU;AADhB,yBAAP;AAGH;AACJ;;AAED,sBAAMyU,GAAN;AACH,aA9BM,CAAP;AA+BH,SAnCM,CAAP;AAoCH,K;;0BAEDyF,O,oBAAQnR,I,EAAMvrC,S,EAAiC;AAAA;;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;AAC3C,eAAO,KAAK5B,YAAL,CAAkB7Q,IAAlB,EAAwBvrC,SAAxB,EAAmCg+C,eAAnC,EAAoD1U,IAApD,CAAyD,uBAAe;AAC3E,mBAAO,QAAKiT,UAAL,CAAgBuB,YAAYzd,GAA5B,EAAiCkL,IAAjC,CAAP;AACH,SAFM,CAAP;AAGH,K;;0BACD6Q,Y,yBAAa7Q,I,EAAMvrC,S,EAAiC;AAAA;;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;;AAEhD,eAAOh+C,UAAU+iC,OAAV,CAAkBib,eAAlB,EAAmC1U,IAAnC,CAAwC,kBAAU;AACrDrqC,qBAAIqgC,KAAJ,CAAU,uDAAV;;AAEA,mBAAO,QAAK0N,mBAAL,CAAyBzB,IAAzB,EAA+BjC,IAA/B,CAAoC,yBAAiB;AACxDrqC,yBAAIqgC,KAAJ,CAAU,8CAAV;;AAEA0e,gCAAgB3d,GAAhB,GAAsB+N,cAAc/N,GAApC;AACA2d,gCAAgBvjB,EAAhB,GAAqB2T,cAAczf,KAAd,CAAoB8L,EAAzC;;AAEA,uBAAOsL,OAAO7B,QAAP,CAAgB8Z,eAAhB,CAAP;AACH,aAPM,EAOJhH,KAPI,CAOE,eAAO;AACZ,oBAAIjR,OAAOZ,KAAX,EAAkB;AACdlmC,6BAAIqgC,KAAJ,CAAU,qFAAV;AACAyG,2BAAOZ,KAAP;AACH;AACD,sBAAM8R,GAAN;AACH,aAbM,CAAP;AAcH,SAjBM,CAAP;AAkBH,K;;0BACDsF,U,uBAAWlc,G,EAAgB;AAAA;;AAAA,YAAXkL,IAAW,uEAAJ,EAAI;;AACvB,eAAO,KAAK8D,qBAAL,CAA2BhP,GAA3B,EAAgCiJ,IAAhC,CAAqC,0BAAkB;AAC1DrqC,qBAAIqgC,KAAJ,CAAU,6CAAV;;AAEA,gBAAIoX,OAAO,IAAI32C,UAAJ,CAASg+C,cAAT,CAAX;;AAEA,gBAAIxS,KAAK0R,WAAT,EAAsB;AAClB,oBAAI1R,KAAK0R,WAAL,KAAqBvG,KAAKpC,OAAL,CAAa3X,GAAtC,EAA2C;AACvC19B,6BAAIqgC,KAAJ,CAAU,kGAAV,EAA8GoX,KAAKpC,OAAL,CAAa3X,GAA3H;AACA,2BAAO8E,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gBAAV,CAAf,CAAP;AACH,iBAHD,MAIK;AACDzB,6BAAIqgC,KAAJ,CAAU,wEAAV;AACH;AACJ;;AAED,mBAAO,QAAK2c,SAAL,CAAevF,IAAf,EAAqBpN,IAArB,CAA0B,YAAM;AACnCrqC,yBAAIqgC,KAAJ,CAAU,qCAAV;;AAEA,wBAAKic,OAAL,CAAatc,IAAb,CAAkByX,IAAlB;;AAEA,uBAAOA,IAAP;AACH,aANM,CAAP;AAOH,SAtBM,CAAP;AAuBH,K;;0BACDmG,e,4BAAgBxc,G,EAAKrgC,S,EAAW;AAC5Bf,iBAAIqgC,KAAJ,CAAU,6BAAV;AACA,eAAOt/B,UAAUmgC,QAAV,CAAmBE,GAAnB,CAAP;AACH,K;;0BAED4d,e,8BAA2B;AAAA,YAAX1S,IAAW,uEAAJ,EAAI;;AACvBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIoQ,wBAAwB3S,KAAKkE,wBAAL,IAAiC,KAAK/D,QAAL,CAAc+D,wBAA3E;AACA,YAAIyO,qBAAJ,EAA0B;AACtB3S,iBAAKkE,wBAAL,GAAgCyO,qBAAhC;AACH;AACD,YAAI/B,YAAY;AACZ/I,kCAAuB7H,KAAK6H;AADhB,SAAhB;AAGA,eAAO,KAAK+K,aAAL,CAAmB5S,IAAnB,EAAyB,KAAK8Q,kBAA9B,EAAkDF,SAAlD,EAA6D7S,IAA7D,CAAkE,YAAI;AACzErqC,qBAAI6rC,IAAJ,CAAS,yCAAT;AACH,SAFM,CAAP;AAGH,K;;0BACD6S,uB,oCAAwBtd,G,EAAK;AACzB,eAAO,KAAK+d,WAAL,CAAiB/d,OAAO,KAAKgc,kBAAL,CAAwBhc,GAAhD,EAAqDiJ,IAArD,CAA0D,oBAAU;AACvErqC,qBAAI6rC,IAAJ,CAAS,iDAAT;AACA,mBAAOgE,QAAP;AACH,SAHM,CAAP;AAIH,K;;0BAEDuP,Y,2BAAwB;AAAA,YAAX9S,IAAW,uEAAJ,EAAI;;AACpBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIzN,MAAMkL,KAAKkE,wBAAL,IAAiC,KAAK/D,QAAL,CAAc4S,8BAA/C,IAAiF,KAAK5S,QAAL,CAAc+D,wBAAzG;AACAlE,aAAKkE,wBAAL,GAAgCpP,GAAhC;AACAkL,aAAKlK,OAAL,GAAe,OAAf;AACA,YAAIkK,KAAKkE,wBAAT,EAAkC;AAC9B;AACA;AACA;AACA;AACA;AACAlE,iBAAK5c,KAAL,GAAa4c,KAAK5c,KAAL,IAAc,EAA3B;AACH;;AAED,eAAO,KAAK4vB,QAAL,CAAchT,IAAd,EAAoB,KAAKoR,eAAzB,EAA0C;AAC7C7Y,sBAAUzD,GADmC;AAE7C4C,iCAAqBsI,KAAKtI,mBAAL,IAA4B,KAAKyI,QAAL,CAAczI,mBAFlB;AAG7CW,+BAAmB2H,KAAK3H,iBAAL,IAA0B,KAAK8H,QAAL,CAAc9H;AAHd,SAA1C,EAIJ0F,IAJI,CAIC,YAAM;AACVrqC,qBAAI6rC,IAAJ,CAAS,sCAAT;AACH,SANM,CAAP;AAOH,K;;0BACD8S,oB,iCAAqBvd,G,EAAKmS,Q,EAAU;AAChC,YAAI,OAAOA,QAAP,KAAqB,WAArB,IAAoC,OAAOnS,GAAP,KAAgB,SAAxD,EAAmE;AAC/DmS,uBAAWnS,GAAX;AACAA,kBAAM,IAAN;AACH;;AAED,YAAIwO,YAAY,GAAhB;AACA,eAAO,KAAK8N,eAAL,CAAqBxc,QAArB,CAA8BE,GAA9B,EAAmCmS,QAAnC,EAA6C3D,SAA7C,EAAwDvF,IAAxD,CAA6D,YAAM;AACtErqC,qBAAI6rC,IAAJ,CAAS,8CAAT;AACH,SAFM,CAAP;AAGH,K;;0BAEDyT,Q,qBAAShT,I,EAAMvrC,S,EAAiC;AAAA;;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;AAC5C,eAAO,KAAKG,aAAL,CAAmB5S,IAAnB,EAAyBvrC,SAAzB,EAAoCg+C,eAApC,EAAqD1U,IAArD,CAA0D,uBAAe;AAC5E,mBAAO,QAAK8U,WAAL,CAAiBN,YAAYzd,GAA7B,CAAP;AACH,SAFM,CAAP;AAGH,K;;0BACD8d,a,4BAA0D;AAAA,YAA5C5S,IAA4C,uEAArC,EAAqC;;AAAA;;AAAA,YAAjCvrC,SAAiC;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;AACtD,eAAOh+C,UAAU+iC,OAAV,CAAkBib,eAAlB,EAAmC1U,IAAnC,CAAwC,kBAAU;AACrDrqC,qBAAIqgC,KAAJ,CAAU,wDAAV;;AAEA,mBAAO,QAAKyc,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjCrqC,yBAAIqgC,KAAJ,CAAU,6DAAV;;AAEA,oBAAIkf,gBAAgB,QAAK5S,SAAL,CAAe6S,0BAAf,GAA4C,QAAKC,eAAL,CAAqBhI,IAArB,CAA5C,GAAyEjV,QAAQC,OAAR,EAA7F;AACA,uBAAO8c,cAAclV,IAAd,CAAmB,YAAM;;AAE5B,wBAAI4K,WAAW3I,KAAK+B,aAAL,IAAsBoJ,QAAQA,KAAKxC,QAAlD;AACA,wBAAIA,QAAJ,EAAc;AACVj1C,iCAAIqgC,KAAJ,CAAU,kEAAV;AACAiM,6BAAK+B,aAAL,GAAqB4G,QAArB;AACH;;AAED,2BAAO,QAAK8H,UAAL,GAAkB1S,IAAlB,CAAuB,YAAM;AAChCrqC,iCAAIqgC,KAAJ,CAAU,mEAAV;;AAEA,+BAAO,QAAKkQ,oBAAL,CAA0BjE,IAA1B,EAAgCjC,IAAhC,CAAqC,0BAAkB;AAC1DrqC,qCAAIqgC,KAAJ,CAAU,gDAAV;;AAEA0e,4CAAgB3d,GAAhB,GAAsBse,eAAete,GAArC;AACA,gCAAIse,eAAehwB,KAAnB,EAA0B;AACtBqvB,gDAAgBvjB,EAAhB,GAAqBkkB,eAAehwB,KAAf,CAAqB8L,EAA1C;AACH;AACD,mCAAOsL,OAAO7B,QAAP,CAAgB8Z,eAAhB,CAAP;AACH,yBARM,CAAP;AASH,qBAZM,CAAP;AAaH,iBArBM,CAAP;AAsBH,aA1BM,EA0BJhH,KA1BI,CA0BE,eAAO;AACZ,oBAAIjR,OAAOZ,KAAX,EAAkB;AACdlmC,6BAAIqgC,KAAJ,CAAU,sFAAV;AACAyG,2BAAOZ,KAAP;AACH;AACD,sBAAM8R,GAAN;AACH,aAhCM,CAAP;AAiCH,SApCM,CAAP;AAqCH,K;;0BACDmH,W,wBAAY/d,G,EAAK;AACb,eAAO,KAAK2P,sBAAL,CAA4B3P,GAA5B,EAAiCiJ,IAAjC,CAAsC,2BAAmB;AAC5DrqC,qBAAIqgC,KAAJ,CAAU,+CAAV;;AAEA,mBAAOsf,eAAP;AACH,SAJM,CAAP;AAKH,K;;0BAEDC,iB,gCAAoB;AAAA;;AAChB,eAAO,KAAK9C,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,mBAAO,QAAKoV,eAAL,CAAqBhI,IAArB,EAA2B,IAA3B,EAAiCpN,IAAjC,CAAsC,mBAAW;AACpD,oBAAIwV,OAAJ,EAAa;AACT7/C,6BAAIqgC,KAAJ,CAAU,mFAAV;;AAEAoX,yBAAKvX,YAAL,GAAoB,IAApB;AACAuX,yBAAKyD,aAAL,GAAqB,IAArB;AACAzD,yBAAK2B,UAAL,GAAkB,IAAlB;AACA3B,yBAAK0B,UAAL,GAAkB,IAAlB;;AAEA,2BAAO,QAAK6D,SAAL,CAAevF,IAAf,EAAqBpN,IAArB,CAA0B,YAAM;AACnCrqC,iCAAIqgC,KAAJ,CAAU,4CAAV;AACA,gCAAKic,OAAL,CAAatc,IAAb,CAAkByX,IAAlB;AACH,qBAHM,CAAP;AAIH;AACJ,aAdM,CAAP;AAeH,SAhBM,EAgBJpN,IAhBI,CAgBC,YAAI;AACRrqC,qBAAI6rC,IAAJ,CAAS,kEAAT;AACH,SAlBM,CAAP;AAmBH,K;;0BAED4T,e,4BAAgBhI,I,EAAM8D,Q,EAAU;AAAA;;AAC5B,YAAI9D,IAAJ,EAAU;AACN,gBAAIvX,eAAeuX,KAAKvX,YAAxB;AACA,gBAAIgb,gBAAgBzD,KAAKyD,aAAzB;;AAEA,mBAAO,KAAK4E,0BAAL,CAAgC5f,YAAhC,EAA8Cqb,QAA9C,EACFlR,IADE,CACG,qBAAa;AACf,uBAAO,QAAK0V,2BAAL,CAAiC7E,aAAjC,EAAgDK,QAAhD,EACFlR,IADE,CACG,qBAAa;AACf,wBAAI,CAAC2V,SAAD,IAAc,CAACC,SAAnB,EAA8B;AAC1BjgD,iCAAIqgC,KAAJ,CAAU,oFAAV;AACH;;AAED,2BAAO2f,aAAaC,SAApB;AACH,iBAPE,CAAP;AAQH,aAVE,CAAP;AAWH;;AAED,eAAOzd,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH,K;;0BAEDqd,0B,uCAA2B5f,Y,EAAcqb,Q,EAAU;AAC/C;AACA,YAAI,CAACrb,YAAD,IAAiBA,aAAax4B,OAAb,CAAqB,GAArB,KAA6B,CAAlD,EAAqD;AACjD,mBAAO86B,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH;;AAED,eAAO,KAAKoa,sBAAL,CAA4BvB,MAA5B,CAAmCpb,YAAnC,EAAiDqb,QAAjD,EAA2DlR,IAA3D,CAAgE;AAAA,mBAAM,IAAN;AAAA,SAAhE,CAAP;AACH,K;;0BAED0V,2B,wCAA4B7E,a,EAAeK,Q,EAAU;AACjD,YAAI,CAACL,aAAL,EAAoB;AAChB,mBAAO1Y,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH;;AAED,eAAO,KAAKoa,sBAAL,CAA4BvB,MAA5B,CAAmCJ,aAAnC,EAAkDK,QAAlD,EAA4D,eAA5D,EAA6ElR,IAA7E,CAAkF;AAAA,mBAAM,IAAN;AAAA,SAAlF,CAAP;AACH,K;;0BAEDqS,gB,+BAAmB;AACf,aAAKF,mBAAL,CAAyBlZ,KAAzB;AACH,K;;0BAED4c,e,8BAAkB;AACd,aAAK1D,mBAAL,CAAyBnZ,IAAzB;AACH,K;;0BAMDyZ,S,wBAAY;AACR,eAAO,KAAKqD,UAAL,CAAgBlhB,GAAhB,CAAoB,KAAKmhB,aAAzB,EAAwC/V,IAAxC,CAA6C,yBAAiB;AACjE,gBAAIsP,aAAJ,EAAmB;AACf35C,yBAAIqgC,KAAJ,CAAU,kDAAV;AACA,uBAAOv/B,WAAKqvC,iBAAL,CAAuBwJ,aAAvB,CAAP;AACH;;AAED35C,qBAAIqgC,KAAJ,CAAU,8CAAV;AACA,mBAAO,IAAP;AACH,SARM,CAAP;AASH,K;;0BAED2c,S,sBAAUvF,I,EAAM;AACZ,YAAIA,IAAJ,EAAU;AACNz3C,qBAAIqgC,KAAJ,CAAU,qCAAV;;AAEA,gBAAIsZ,gBAAgBlC,KAAKjI,eAAL,EAApB;AACA,mBAAO,KAAK2Q,UAAL,CAAgB5Q,GAAhB,CAAoB,KAAK6Q,aAAzB,EAAwCzG,aAAxC,CAAP;AACH,SALD,MAMK;AACD35C,qBAAIqgC,KAAJ,CAAU,oCAAV;AACA,mBAAO,KAAK8f,UAAL,CAAgBnQ,MAAhB,CAAuB,KAAKoQ,aAA5B,CAAP;AACH;AACJ,K;;;;4BAxkBwB;AACrB,mBAAO,KAAK3T,QAAL,CAAc4T,iBAArB;AACH;;;4BACqB;AAClB,mBAAO,KAAK5T,QAAL,CAAc6T,cAArB;AACH;;;4BACsB;AACnB,mBAAO,KAAK7T,QAAL,CAAc8T,eAArB;AACH;;;4BACgB;AACb,mBAAO,KAAK9T,QAAL,CAAc+T,SAArB;AACH;;;4BAEY;AACT,mBAAO,KAAKlE,OAAZ;AACH;;;4BA8hBmB;AAChB,6BAAe,KAAK7P,QAAL,CAAcqB,SAA7B,SAA0C,KAAKrB,QAAL,CAActL,SAAxD;AACH;;;;EAhlB4BlhC,uB;;;;;;;;;;;;;;;;;;;ACZjC;;AACA;;AACA;;;;;;+eALA;AACA;;IAMas8C,iB,WAAAA,iB;;;AAET,+BAAY9P,QAAZ,EAAsB;AAAA;;AAAA,qDAClB,8BAAMA,QAAN,CADkB;;AAElB,cAAKgU,WAAL,GAAmB,IAAIla,YAAJ,CAAU,aAAV,CAAnB;AACA,cAAKma,aAAL,GAAqB,IAAIna,YAAJ,CAAU,eAAV,CAArB;AACA,cAAKoa,iBAAL,GAAyB,IAAIpa,YAAJ,CAAU,oBAAV,CAAzB;AACA,cAAKqa,aAAL,GAAqB,IAAIra,YAAJ,CAAU,gBAAV,CAArB;AACA,cAAKsa,cAAL,GAAsB,IAAIta,YAAJ,CAAU,iBAAV,CAAtB;AACA,cAAKua,mBAAL,GAA2B,IAAIva,YAAJ,CAAU,sBAAV,CAA3B;AAPkB;AAQrB;;gCAEDvG,I,iBAAKyX,I,EAAuB;AAAA,YAAjBc,UAAiB,uEAAN,IAAM;;AACxBv4C,iBAAIqgC,KAAJ,CAAU,wBAAV;AACA,qCAAML,IAAN,YAAWyX,IAAX;AACA,YAAIc,UAAJ,EAAgB;AACZ,iBAAKkI,WAAL,CAAiB7Z,KAAjB,CAAuB6Q,IAAvB;AACH;AACJ,K;;gCACDhX,M,qBAAS;AACLzgC,iBAAIqgC,KAAJ,CAAU,0BAAV;AACA,qCAAMI,MAAN;AACA,aAAKigB,aAAL,CAAmB9Z,KAAnB;AACH,K;;gCAEDwQ,a,0BAAczW,E,EAAI;AACd,aAAK8f,WAAL,CAAiB7f,UAAjB,CAA4BD,EAA5B;AACH,K;;gCACDogB,gB,6BAAiBpgB,E,EAAI;AACjB,aAAK8f,WAAL,CAAiB3f,aAAjB,CAA+BH,EAA/B;AACH,K;;gCAED2W,e,4BAAgB3W,E,EAAI;AAChB,aAAK+f,aAAL,CAAmB9f,UAAnB,CAA8BD,EAA9B;AACH,K;;gCACDqgB,kB,+BAAmBrgB,E,EAAI;AACnB,aAAK+f,aAAL,CAAmB5f,aAAnB,CAAiCH,EAAjC;AACH,K;;gCAEDsgB,mB,gCAAoBtgB,E,EAAI;AACpB,aAAKggB,iBAAL,CAAuB/f,UAAvB,CAAkCD,EAAlC;AACH,K;;gCACDugB,sB,mCAAuBvgB,E,EAAI;AACvB,aAAKggB,iBAAL,CAAuB7f,aAAvB,CAAqCH,EAArC;AACH,K;;gCACDoZ,sB,mCAAuB/3C,C,EAAG;AACtBhC,iBAAIqgC,KAAJ,CAAU,0CAAV,EAAsDr+B,EAAEgkC,OAAxD;AACA,aAAK2a,iBAAL,CAAuB/Z,KAAvB,CAA6B5kC,CAA7B;AACH,K;;gCAEDm/C,e,4BAAgBxgB,E,EAAI;AAChB,aAAKigB,aAAL,CAAmBhgB,UAAnB,CAA8BD,EAA9B;AACH,K;;gCACDygB,kB,+BAAmBzgB,E,EAAI;AACnB,aAAKigB,aAAL,CAAmB9f,aAAnB,CAAiCH,EAAjC;AACH,K;;gCACD+X,kB,iCAAqB;AACjB14C,iBAAIqgC,KAAJ,CAAU,sCAAV;AACA,aAAKugB,aAAL,CAAmBha,KAAnB;AACH,K;;gCAEDya,gB,6BAAiB1gB,E,EAAI;AACjB,aAAKkgB,cAAL,CAAoBjgB,UAApB,CAA+BD,EAA/B;AACH,K;;gCACD2gB,mB,gCAAoB3gB,E,EAAI;AACpB,aAAKkgB,cAAL,CAAoB/f,aAApB,CAAkCH,EAAlC;AACH,K;;gCACD8X,mB,kCAAsB;AAClBz4C,iBAAIqgC,KAAJ,CAAU,uCAAV;AACA,aAAKwgB,cAAL,CAAoBja,KAApB;AACH,K;;gCAED2a,qB,kCAAsB5gB,E,EAAI;AACtB,aAAKmgB,mBAAL,CAAyBlgB,UAAzB,CAAoCD,EAApC;AACH,K;;gCACD6gB,wB,qCAAyB7gB,E,EAAI;AACzB,aAAKmgB,mBAAL,CAAyBhgB,aAAzB,CAAuCH,EAAvC;AACH,K;;gCACD6X,wB,uCAA2B;AACvBx4C,iBAAIqgC,KAAJ,CAAU,4CAAV;AACA,aAAKygB,mBAAL,CAAyBla,KAAzB;AACH,K;;;EAjFkCtmC,qC;;;;;;;;;;;;;;;;;;;;;ACJvC;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;;;+eAVA;AACA;;AAWA,IAAMk/B,6CAA6C,EAAnD;AACA,IAAMiiB,8BAA8B,IAApC;;IAEapF,mB,WAAAA,mB;;;AACT,mCAqBQ;AAAA,uFAAJ,EAAI;AAAA,YApBJmB,kBAoBI,QApBJA,kBAoBI;AAAA,YAnBJ6B,8BAmBI,QAnBJA,8BAmBI;AAAA,YAlBJrb,mBAkBI,QAlBJA,mBAkBI;AAAA,YAjBJW,iBAiBI,QAjBJA,iBAiBI;AAAA,YAhBJ0Z,mBAgBI,QAhBJA,mBAgBI;AAAA,YAfJvW,oBAeI,QAfJA,oBAeI;AAAA,yCAdJ2U,oBAcI;AAAA,YAdJA,oBAcI,yCAdmB,KAcnB;AAAA,yCAbJsB,wBAaI;AAAA,YAbJA,wBAaI,yCAbuB,KAavB;AAAA,yCAZJD,2BAYI;AAAA,YAZJA,2BAYI,yCAZ0B,IAY1B;AAAA,uCAXJnB,cAWI;AAAA,YAXJA,cAWI,uCAXa,IAWb;AAAA,yCAVJjF,uBAUI;AAAA,YAVJA,uBAUI,yCAVsB,KAUtB;AAAA,yCATJiB,oBASI;AAAA,YATJA,oBASI,yCATmB8I,2BASnB;AAAA,yCARJ7I,uBAQI;AAAA,YARJA,uBAQI,yCARsB,IAQtB;AAAA,YAPJgG,0BAOI,QAPJA,0BAOI;AAAA,yCANJY,0BAMI;AAAA,YANJA,0BAMI,yCANyB,KAMzB;AAAA,yCALJ/f,mCAKI;AAAA,YALJA,mCAKI,yCALkCD,0CAKlC;AAAA,yCAJJ6gB,iBAII;AAAA,YAJJA,iBAII,yCAJgB,IAAInM,oCAAJ,EAIhB;AAAA,uCAHJoM,cAGI;AAAA,YAHJA,cAGI,uCAHa,IAAIjN,8BAAJ,EAGb;AAAA,wCAFJkN,eAEI;AAAA,YAFJA,eAEI,wCAFc,IAAI/Y,gCAAJ,EAEd;AAAA,kCADJgZ,SACI;AAAA,YADJA,SACI,kCADQ,IAAIrgD,0CAAJ,CAAyB,EAAEuhD,OAAO7gD,eAAOymC,cAAhB,EAAzB,CACR;;AAAA;;AAAA,qDACJ,+BAAMlkC,UAAU,CAAV,CAAN,CADI;;AAGJ,cAAKu+C,mBAAL,GAA2BnE,kBAA3B;AACA,cAAKoE,+BAAL,GAAuCvC,8BAAvC;AACA,cAAKwC,oBAAL,GAA4B7d,mBAA5B;AACA,cAAK8d,kBAAL,GAA0Bnd,iBAA1B;;AAEA,cAAKod,oBAAL,GAA4B1D,mBAA5B;AACA,cAAK2D,qBAAL,GAA6Bla,oBAA7B;AACA,cAAKma,qBAAL,GAA6BxF,oBAA7B;AACA,cAAKyF,yBAAL,GAAiCnE,wBAAjC;AACA,cAAKoE,4BAAL,GAAoCrE,2BAApC;AACA,cAAKje,oCAAL,GAA4CJ,mCAA5C;;AAEA,cAAK2iB,eAAL,GAAuBzF,cAAvB;AACA,cAAK0F,wBAAL,GAAgC3K,uBAAhC;AACA,cAAKU,qBAAL,GAA6BO,oBAA7B;AACA,cAAKN,wBAAL,GAAgCO,uBAAhC;AACA,YAAIgG,0BAAJ,EAAgC;AAC5B,kBAAK0D,2BAAL,GAAmC1D,0BAAnC;AACH,SAFD,MAGK,IAAIx7C,UAAU,CAAV,KAAgBA,UAAU,CAAV,EAAa4qC,aAAjC,EAAgD;AACjD,kBAAKsU,2BAAL,GAAmCtT,6BAAc8J,MAAd,CAAqB11C,UAAU,CAAV,EAAa4qC,aAAlC,IAAmD,UAAnD,GAAgE,MAAnG;AACH,SAFI,MAGA;AACD,kBAAKsU,2BAAL,GAAmC,UAAnC;AACH;AACD,cAAKC,2BAAL,GAAmC/C,0BAAnC;;AAEA,cAAKpC,kBAAL,GAA0BiD,iBAA1B;AACA,cAAK3C,eAAL,GAAuB4C,cAAvB;AACA,cAAKhC,gBAAL,GAAwBiC,eAAxB;;AAEA,cAAKJ,UAAL,GAAkBK,SAAlB;AAlCI;AAmCP;;;;4BAEwB;AACrB,mBAAO,KAAKmB,mBAAZ;AACH;;;4BACoC;AACjC,mBAAO,KAAKC,+BAAZ;AACH;;;4BACyB;AACtB,mBAAO,KAAKC,oBAAZ;AACH;;;4BACuB;AACpB,mBAAO,KAAKC,kBAAZ;AACH;;;4BAEyB;AACtB,mBAAO,KAAKC,oBAAZ;AACH;;;4BAC2B;AACxB,mBAAO,KAAKC,qBAAZ;AACH;;;4BAC0B;AACvB,mBAAO,KAAKC,qBAAZ;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKC,yBAAZ;AACH;;;4BACiC;AAC9B,mBAAO,KAAKC,4BAAZ;AACH;;;4BACyC;AACtC,mBAAO,KAAKtiB,oCAAZ;AACH;;;4BAEoB;AACjB,mBAAO,KAAKuiB,eAAZ;AACH;;;4BAC6B;AAC1B,mBAAO,KAAKC,wBAAZ;AACH;;;4BAC0B;AACvB,mBAAO,KAAKjK,qBAAZ;AACH;;;4BAC4B;AACzB,mBAAO,KAAKC,wBAAZ;AACH;;;4BAC+B;AAC5B,mBAAO,KAAKiK,2BAAZ;AACH;;;4BACgC;AAC7B,mBAAO,KAAKC,2BAAZ;AACH;;;4BAEuB;AACpB,mBAAO,KAAKnF,kBAAZ;AACH;;;4BACoB;AACjB,mBAAO,KAAKM,eAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKY,gBAAZ;AACH;;;4BAEe;AACZ,mBAAO,KAAK6B,UAAZ;AACH;;;;EA1HoCjgD,uC;;;;;;;;;;;;;;;;;;;ACZzC;;AACA;;0JAJA;AACA;;IAKaC,oB,WAAAA,oB;AACT,oCAAkE;AAAA,uFAAJ,EAAI;AAAA,+BAArDqiD,MAAqD;AAAA,YAArDA,MAAqD,+BAA5C,OAA4C;AAAA,8BAAnCd,KAAmC;AAAA,YAAnCA,KAAmC,8BAA3B7gD,eAAOwmC,YAAoB;;AAAA;;AAC9D,aAAKob,MAAL,GAAcf,KAAd;AACA,aAAKgB,OAAL,GAAeF,MAAf;AACH;;mCAEDjT,G,gBAAIzb,G,EAAK6U,K,EAAO;AACZ3oC,iBAAIqgC,KAAJ,CAAU,0BAAV,EAAsCvM,GAAtC;;AAEAA,cAAM,KAAK4uB,OAAL,GAAe5uB,GAArB;;AAEA,aAAK2uB,MAAL,CAAY/Z,OAAZ,CAAoB5U,GAApB,EAAyB6U,KAAzB;;AAEA,eAAOnG,QAAQC,OAAR,EAAP;AACH,K;;mCAEDxD,G,gBAAInL,G,EAAK;AACL9zB,iBAAIqgC,KAAJ,CAAU,0BAAV,EAAsCvM,GAAtC;;AAEAA,cAAM,KAAK4uB,OAAL,GAAe5uB,GAArB;;AAEA,YAAI6S,OAAO,KAAK8b,MAAL,CAAYha,OAAZ,CAAoB3U,GAApB,CAAX;;AAEA,eAAO0O,QAAQC,OAAR,CAAgBkE,IAAhB,CAAP;AACH,K;;mCAEDqJ,M,mBAAOlc,G,EAAK;AACR9zB,iBAAIqgC,KAAJ,CAAU,6BAAV,EAAyCvM,GAAzC;;AAEAA,cAAM,KAAK4uB,OAAL,GAAe5uB,GAArB;;AAEA,YAAI6S,OAAO,KAAK8b,MAAL,CAAYha,OAAZ,CAAoB3U,GAApB,CAAX;AACA,aAAK2uB,MAAL,CAAY7Z,UAAZ,CAAuB9U,GAAvB;;AAEA,eAAO0O,QAAQC,OAAR,CAAgBkE,IAAhB,CAAP;AACH,K;;mCAED0T,U,yBAAa;AACTr6C,iBAAIqgC,KAAJ,CAAU,iCAAV;;AAEA,YAAIngB,OAAO,EAAX;;AAEA,aAAK,IAAI2oB,QAAQ,CAAjB,EAAoBA,QAAQ,KAAK4Z,MAAL,CAAYpgD,MAAxC,EAAgDwmC,OAAhD,EAAyD;AACrD,gBAAI/U,MAAM,KAAK2uB,MAAL,CAAY3uB,GAAZ,CAAgB+U,KAAhB,CAAV;;AAEA,gBAAI/U,IAAIpsB,OAAJ,CAAY,KAAKg7C,OAAjB,MAA8B,CAAlC,EAAqC;AACjCxiC,qBAAK5b,IAAL,CAAUwvB,IAAIjvB,MAAJ,CAAW,KAAK69C,OAAL,CAAargD,MAAxB,CAAV;AACH;AACJ;;AAED,eAAOmgC,QAAQC,OAAR,CAAgBviB,IAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACzDL;;AAEA,IAAM+oB,qBAAqB,CAAC,OAAD,EAAU,OAAV,EAAmB,OAAnB,EAA4B,OAA5B,EAAqC,OAArC,EAA8C,OAA9C,EAAuD,OAAvD,EAAgE,OAAhE,EAAyE,OAAzE,CAA3B;;QAGIhN,G,GAAAA,c;QACA+M,O,GAAAA,kB;QACAnS,I,GAAAA,e;QACApe,M,GAAAA,iB;QACAmO,S,GAAAA,oB;QACAhc,Q,GAAAA,mB;QACAq+B,kB,GAAAA,kB;;;;;;;;;;;;;;;;;kBCLoB5kC,M;;AANxB;;;;;;AAEA;;;;AAIe,SAASA,MAAT,GAAkB;AAC/B,SAAO,mBAAQma,OAAR,CAAgB,IAAhB,EAAsB,EAAtB,CAAP;AACD;;;;;;;;;;;;;;;;;;ACRD,IAAMze,UAAU,QAAhB,C,QAAkCA,O,GAAAA,O","file":"oidc-client.slim.js","sourcesContent":[" \t// The module cache\n \tvar installedModules = {};\n\n \t// The require function\n \tfunction __webpack_require__(moduleId) {\n\n \t\t// Check if module is in cache\n \t\tif(installedModules[moduleId]) {\n \t\t\treturn installedModules[moduleId].exports;\n \t\t}\n \t\t// Create a new module (and put it into the cache)\n \t\tvar module = installedModules[moduleId] = {\n \t\t\ti: moduleId,\n \t\t\tl: false,\n \t\t\texports: {}\n \t\t};\n\n \t\t// Execute the module function\n \t\tmodules[moduleId].call(module.exports, module, module.exports, __webpack_require__);\n\n \t\t// Flag the module as loaded\n \t\tmodule.l = true;\n\n \t\t// Return the exports of the module\n \t\treturn module.exports;\n \t}\n\n\n \t// expose the modules object (__webpack_modules__)\n \t__webpack_require__.m = modules;\n\n \t// expose the module cache\n \t__webpack_require__.c = installedModules;\n\n \t// define getter function for harmony exports\n \t__webpack_require__.d = function(exports, name, getter) {\n \t\tif(!__webpack_require__.o(exports, name)) {\n \t\t\tObject.defineProperty(exports, name, { enumerable: true, get: getter });\n \t\t}\n \t};\n\n \t// define __esModule on exports\n \t__webpack_require__.r = function(exports) {\n \t\tif(typeof Symbol !== 'undefined' && Symbol.toStringTag) {\n \t\t\tObject.defineProperty(exports, Symbol.toStringTag, { value: 'Module' });\n \t\t}\n \t\tObject.defineProperty(exports, '__esModule', { value: true });\n \t};\n\n \t// create a fake namespace object\n \t// mode & 1: value is a module id, require it\n \t// mode & 2: merge all properties of value into the ns\n \t// mode & 4: return value when already ns object\n \t// mode & 8|1: behave like require\n \t__webpack_require__.t = function(value, mode) {\n \t\tif(mode & 1) value = __webpack_require__(value);\n \t\tif(mode & 8) return value;\n \t\tif((mode & 4) && typeof value === 'object' && value && value.__esModule) return value;\n \t\tvar ns = Object.create(null);\n \t\t__webpack_require__.r(ns);\n \t\tObject.defineProperty(ns, 'default', { enumerable: true, value: value });\n \t\tif(mode & 2 && typeof value != 'string') for(var key in value) __webpack_require__.d(ns, key, function(key) { return value[key]; }.bind(null, key));\n \t\treturn ns;\n \t};\n\n \t// getDefaultExport function for compatibility with non-harmony modules\n \t__webpack_require__.n = function(module) {\n \t\tvar getter = module && module.__esModule ?\n \t\t\tfunction getDefault() { return module['default']; } :\n \t\t\tfunction getModuleExports() { return module; };\n \t\t__webpack_require__.d(getter, 'a', getter);\n \t\treturn getter;\n \t};\n\n \t// Object.prototype.hasOwnProperty.call\n \t__webpack_require__.o = function(object, property) { return Object.prototype.hasOwnProperty.call(object, property); };\n\n \t// __webpack_public_path__\n \t__webpack_require__.p = \"\";\n\n\n \t// Load entry module and return exports\n \treturn __webpack_require__(__webpack_require__.s = 0);\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './src/Log.js';\r\nimport { OidcClient } from './src/OidcClient.js';\r\nimport { OidcClientSettings } from './src/OidcClientSettings.js';\r\nimport { WebStorageStateStore } from './src/WebStorageStateStore.js';\r\nimport { InMemoryWebStorage } from './src/InMemoryWebStorage.js';\r\nimport { UserManager } from './src/UserManager.js';\r\nimport { AccessTokenEvents } from './src/AccessTokenEvents.js';\r\nimport { MetadataService } from './src/MetadataService.js';\r\nimport { CordovaPopupNavigator } from './src/CordovaPopupNavigator.js';\r\nimport { CordovaIFrameNavigator } from './src/CordovaIFrameNavigator.js';\r\nimport { CheckSessionIFrame } from './src/CheckSessionIFrame.js';\r\nimport { TokenRevocationClient } from './src/TokenRevocationClient.js';\r\nimport { SessionMonitor } from './src/SessionMonitor.js';\r\nimport { Global } from './src/Global.js';\r\nimport { User } from './src/User.js';\r\n\r\nimport { Version } from './version.js';\r\n\r\nexport default {\r\n    Version,\r\n    Log,\r\n    OidcClient,\r\n    OidcClientSettings,\r\n    WebStorageStateStore,\r\n    InMemoryWebStorage,\r\n    UserManager,\r\n    AccessTokenEvents,\r\n    MetadataService,\r\n    CordovaPopupNavigator,\r\n    CordovaIFrameNavigator,\r\n    CheckSessionIFrame,\r\n    TokenRevocationClient,\r\n    SessionMonitor,\r\n    Global,\r\n    User\r\n};\r\n","/*\r\n * jsrsasign(all) 8.0.12 (2018-04-22) (c) 2010-2018 Kenji Urushima | kjur.github.com/jsrsasign/license\r\n */\r\n\r\nvar navigator = {};\r\nnavigator.userAgent = false;\r\n\r\nvar window = {};\r\n\n/*!\r\nCopyright (c) 2011, Yahoo! Inc. All rights reserved.\r\nCode licensed under the BSD License:\r\nhttp://developer.yahoo.com/yui/license.html\r\nversion: 2.9.0\r\n*/\r\nif(YAHOO===undefined){var YAHOO={}}YAHOO.lang={extend:function(g,h,f){if(!h||!g){throw new Error(\"YAHOO.lang.extend failed, please check that all dependencies are included.\")}var d=function(){};d.prototype=h.prototype;g.prototype=new d();g.prototype.constructor=g;g.superclass=h.prototype;if(h.prototype.constructor==Object.prototype.constructor){h.prototype.constructor=h}if(f){var b;for(b in f){g.prototype[b]=f[b]}var e=function(){},c=[\"toString\",\"valueOf\"];try{if(/MSIE/.test(navigator.userAgent)){e=function(j,i){for(b=0;b<c.length;b=b+1){var l=c[b],k=i[l];if(typeof k===\"function\"&&k!=Object.prototype[l]){j[l]=k}}}}}catch(a){}e(g.prototype,f)}}};\n/*! CryptoJS v3.1.2 core-fix.js\r\n * code.google.com/p/crypto-js\r\n * (c) 2009-2013 by Jeff Mott. All rights reserved.\r\n * code.google.com/p/crypto-js/wiki/License\r\n * THIS IS FIX of 'core.js' to fix Hmac issue.\r\n * https://code.google.com/p/crypto-js/issues/detail?id=84\r\n * https://crypto-js.googlecode.com/svn-history/r667/branches/3.x/src/core.js\r\n */\r\nvar CryptoJS=CryptoJS||(function(e,g){var a={};var b=a.lib={};var j=b.Base=(function(){function n(){}return{extend:function(p){n.prototype=this;var o=new n();if(p){o.mixIn(p)}if(!o.hasOwnProperty(\"init\")){o.init=function(){o.$super.init.apply(this,arguments)}}o.init.prototype=o;o.$super=this;return o},create:function(){var o=this.extend();o.init.apply(o,arguments);return o},init:function(){},mixIn:function(p){for(var o in p){if(p.hasOwnProperty(o)){this[o]=p[o]}}if(p.hasOwnProperty(\"toString\")){this.toString=p.toString}},clone:function(){return this.init.prototype.extend(this)}}}());var l=b.WordArray=j.extend({init:function(o,n){o=this.words=o||[];if(n!=g){this.sigBytes=n}else{this.sigBytes=o.length*4}},toString:function(n){return(n||h).stringify(this)},concat:function(t){var q=this.words;var p=t.words;var n=this.sigBytes;var s=t.sigBytes;this.clamp();if(n%4){for(var r=0;r<s;r++){var o=(p[r>>>2]>>>(24-(r%4)*8))&255;q[(n+r)>>>2]|=o<<(24-((n+r)%4)*8)}}else{for(var r=0;r<s;r+=4){q[(n+r)>>>2]=p[r>>>2]}}this.sigBytes+=s;return this},clamp:function(){var o=this.words;var n=this.sigBytes;o[n>>>2]&=4294967295<<(32-(n%4)*8);o.length=e.ceil(n/4)},clone:function(){var n=j.clone.call(this);n.words=this.words.slice(0);return n},random:function(p){var o=[];for(var n=0;n<p;n+=4){o.push((e.random()*4294967296)|0)}return new l.init(o,p)}});var m=a.enc={};var h=m.Hex={stringify:function(p){var r=p.words;var o=p.sigBytes;var q=[];for(var n=0;n<o;n++){var s=(r[n>>>2]>>>(24-(n%4)*8))&255;q.push((s>>>4).toString(16));q.push((s&15).toString(16))}return q.join(\"\")},parse:function(p){var n=p.length;var q=[];for(var o=0;o<n;o+=2){q[o>>>3]|=parseInt(p.substr(o,2),16)<<(24-(o%8)*4)}return new l.init(q,n/2)}};var d=m.Latin1={stringify:function(q){var r=q.words;var p=q.sigBytes;var n=[];for(var o=0;o<p;o++){var s=(r[o>>>2]>>>(24-(o%4)*8))&255;n.push(String.fromCharCode(s))}return n.join(\"\")},parse:function(p){var n=p.length;var q=[];for(var o=0;o<n;o++){q[o>>>2]|=(p.charCodeAt(o)&255)<<(24-(o%4)*8)}return new l.init(q,n)}};var c=m.Utf8={stringify:function(n){try{return decodeURIComponent(escape(d.stringify(n)))}catch(o){throw new Error(\"Malformed UTF-8 data\")}},parse:function(n){return d.parse(unescape(encodeURIComponent(n)))}};var i=b.BufferedBlockAlgorithm=j.extend({reset:function(){this._data=new l.init();this._nDataBytes=0},_append:function(n){if(typeof n==\"string\"){n=c.parse(n)}this._data.concat(n);this._nDataBytes+=n.sigBytes},_process:function(w){var q=this._data;var x=q.words;var n=q.sigBytes;var t=this.blockSize;var v=t*4;var u=n/v;if(w){u=e.ceil(u)}else{u=e.max((u|0)-this._minBufferSize,0)}var s=u*t;var r=e.min(s*4,n);if(s){for(var p=0;p<s;p+=t){this._doProcessBlock(x,p)}var o=x.splice(0,s);q.sigBytes-=r}return new l.init(o,r)},clone:function(){var n=j.clone.call(this);n._data=this._data.clone();return n},_minBufferSize:0});var f=b.Hasher=i.extend({cfg:j.extend(),init:function(n){this.cfg=this.cfg.extend(n);this.reset()},reset:function(){i.reset.call(this);this._doReset()},update:function(n){this._append(n);this._process();return this},finalize:function(n){if(n){this._append(n)}var o=this._doFinalize();return o},blockSize:512/32,_createHelper:function(n){return function(p,o){return new n.init(o).finalize(p)}},_createHmacHelper:function(n){return function(p,o){return new k.HMAC.init(n,o).finalize(p)}}});var k=a.algo={};return a}(Math));\n/*\r\nCryptoJS v3.1.2 x64-core-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(g){var a=CryptoJS,f=a.lib,e=f.Base,h=f.WordArray,a=a.x64={};a.Word=e.extend({init:function(b,c){this.high=b;this.low=c}});a.WordArray=e.extend({init:function(b,c){b=this.words=b||[];this.sigBytes=c!=g?c:8*b.length},toX32:function(){for(var b=this.words,c=b.length,a=[],d=0;d<c;d++){var e=b[d];a.push(e.high);a.push(e.low)}return h.create(a,this.sigBytes)},clone:function(){for(var b=e.clone.call(this),c=b.words=this.words.slice(0),a=c.length,d=0;d<a;d++)c[d]=c[d].clone();return b}})})();\r\n\n/*\r\nCryptoJS v3.1.2 enc-base64.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(){var h=CryptoJS,j=h.lib.WordArray;h.enc.Base64={stringify:function(b){var e=b.words,f=b.sigBytes,c=this._map;b.clamp();b=[];for(var a=0;a<f;a+=3)for(var d=(e[a>>>2]>>>24-8*(a%4)&255)<<16|(e[a+1>>>2]>>>24-8*((a+1)%4)&255)<<8|e[a+2>>>2]>>>24-8*((a+2)%4)&255,g=0;4>g&&a+0.75*g<f;g++)b.push(c.charAt(d>>>6*(3-g)&63));if(e=c.charAt(64))for(;b.length%4;)b.push(e);return b.join(\"\")},parse:function(b){var e=b.length,f=this._map,c=f.charAt(64);c&&(c=b.indexOf(c),-1!=c&&(e=c));for(var c=[],a=0,d=0;d<\r\ne;d++)if(d%4){var g=f.indexOf(b.charAt(d-1))<<2*(d%4),h=f.indexOf(b.charAt(d))>>>6-2*(d%4);c[a>>>2]|=(g|h)<<24-8*(a%4);a++}return j.create(c,a)},_map:\"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=\"}})();\r\n\n/*\r\nCryptoJS v3.1.2 sha256-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(k){for(var g=CryptoJS,h=g.lib,v=h.WordArray,j=h.Hasher,h=g.algo,s=[],t=[],u=function(q){return 4294967296*(q-(q|0))|0},l=2,b=0;64>b;){var d;a:{d=l;for(var w=k.sqrt(d),r=2;r<=w;r++)if(!(d%r)){d=!1;break a}d=!0}d&&(8>b&&(s[b]=u(k.pow(l,0.5))),t[b]=u(k.pow(l,1/3)),b++);l++}var n=[],h=h.SHA256=j.extend({_doReset:function(){this._hash=new v.init(s.slice(0))},_doProcessBlock:function(q,h){for(var a=this._hash.words,c=a[0],d=a[1],b=a[2],k=a[3],f=a[4],g=a[5],j=a[6],l=a[7],e=0;64>e;e++){if(16>e)n[e]=\r\nq[h+e]|0;else{var m=n[e-15],p=n[e-2];n[e]=((m<<25|m>>>7)^(m<<14|m>>>18)^m>>>3)+n[e-7]+((p<<15|p>>>17)^(p<<13|p>>>19)^p>>>10)+n[e-16]}m=l+((f<<26|f>>>6)^(f<<21|f>>>11)^(f<<7|f>>>25))+(f&g^~f&j)+t[e]+n[e];p=((c<<30|c>>>2)^(c<<19|c>>>13)^(c<<10|c>>>22))+(c&d^c&b^d&b);l=j;j=g;g=f;f=k+m|0;k=b;b=d;d=c;c=m+p|0}a[0]=a[0]+c|0;a[1]=a[1]+d|0;a[2]=a[2]+b|0;a[3]=a[3]+k|0;a[4]=a[4]+f|0;a[5]=a[5]+g|0;a[6]=a[6]+j|0;a[7]=a[7]+l|0},_doFinalize:function(){var d=this._data,b=d.words,a=8*this._nDataBytes,c=8*d.sigBytes;\r\nb[c>>>5]|=128<<24-c%32;b[(c+64>>>9<<4)+14]=k.floor(a/4294967296);b[(c+64>>>9<<4)+15]=a;d.sigBytes=4*b.length;this._process();return this._hash},clone:function(){var b=j.clone.call(this);b._hash=this._hash.clone();return b}});g.SHA256=j._createHelper(h);g.HmacSHA256=j._createHmacHelper(h)})(Math);\r\n\n/*\r\nCryptoJS v3.1.2 sha512-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(){function a(){return d.create.apply(d,arguments)}for(var n=CryptoJS,r=n.lib.Hasher,e=n.x64,d=e.Word,T=e.WordArray,e=n.algo,ea=[a(1116352408,3609767458),a(1899447441,602891725),a(3049323471,3964484399),a(3921009573,2173295548),a(961987163,4081628472),a(1508970993,3053834265),a(2453635748,2937671579),a(2870763221,3664609560),a(3624381080,2734883394),a(310598401,1164996542),a(607225278,1323610764),a(1426881987,3590304994),a(1925078388,4068182383),a(2162078206,991336113),a(2614888103,633803317),\r\na(3248222580,3479774868),a(3835390401,2666613458),a(4022224774,944711139),a(264347078,2341262773),a(604807628,2007800933),a(770255983,1495990901),a(1249150122,1856431235),a(1555081692,3175218132),a(1996064986,2198950837),a(2554220882,3999719339),a(2821834349,766784016),a(2952996808,2566594879),a(3210313671,3203337956),a(3336571891,1034457026),a(3584528711,2466948901),a(113926993,3758326383),a(338241895,168717936),a(666307205,1188179964),a(773529912,1546045734),a(1294757372,1522805485),a(1396182291,\r\n2643833823),a(1695183700,2343527390),a(1986661051,1014477480),a(2177026350,1206759142),a(2456956037,344077627),a(2730485921,1290863460),a(2820302411,3158454273),a(3259730800,3505952657),a(3345764771,106217008),a(3516065817,3606008344),a(3600352804,1432725776),a(4094571909,1467031594),a(275423344,851169720),a(430227734,3100823752),a(506948616,1363258195),a(659060556,3750685593),a(883997877,3785050280),a(958139571,3318307427),a(1322822218,3812723403),a(1537002063,2003034995),a(1747873779,3602036899),\r\na(1955562222,1575990012),a(2024104815,1125592928),a(2227730452,2716904306),a(2361852424,442776044),a(2428436474,593698344),a(2756734187,3733110249),a(3204031479,2999351573),a(3329325298,3815920427),a(3391569614,3928383900),a(3515267271,566280711),a(3940187606,3454069534),a(4118630271,4000239992),a(116418474,1914138554),a(174292421,2731055270),a(289380356,3203993006),a(460393269,320620315),a(685471733,587496836),a(852142971,1086792851),a(1017036298,365543100),a(1126000580,2618297676),a(1288033470,\r\n3409855158),a(1501505948,4234509866),a(1607167915,987167468),a(1816402316,1246189591)],v=[],w=0;80>w;w++)v[w]=a();e=e.SHA512=r.extend({_doReset:function(){this._hash=new T.init([new d.init(1779033703,4089235720),new d.init(3144134277,2227873595),new d.init(1013904242,4271175723),new d.init(2773480762,1595750129),new d.init(1359893119,2917565137),new d.init(2600822924,725511199),new d.init(528734635,4215389547),new d.init(1541459225,327033209)])},_doProcessBlock:function(a,d){for(var f=this._hash.words,\r\nF=f[0],e=f[1],n=f[2],r=f[3],G=f[4],H=f[5],I=f[6],f=f[7],w=F.high,J=F.low,X=e.high,K=e.low,Y=n.high,L=n.low,Z=r.high,M=r.low,$=G.high,N=G.low,aa=H.high,O=H.low,ba=I.high,P=I.low,ca=f.high,Q=f.low,k=w,g=J,z=X,x=K,A=Y,y=L,U=Z,B=M,l=$,h=N,R=aa,C=O,S=ba,D=P,V=ca,E=Q,m=0;80>m;m++){var s=v[m];if(16>m)var j=s.high=a[d+2*m]|0,b=s.low=a[d+2*m+1]|0;else{var j=v[m-15],b=j.high,p=j.low,j=(b>>>1|p<<31)^(b>>>8|p<<24)^b>>>7,p=(p>>>1|b<<31)^(p>>>8|b<<24)^(p>>>7|b<<25),u=v[m-2],b=u.high,c=u.low,u=(b>>>19|c<<13)^(b<<\r\n3|c>>>29)^b>>>6,c=(c>>>19|b<<13)^(c<<3|b>>>29)^(c>>>6|b<<26),b=v[m-7],W=b.high,t=v[m-16],q=t.high,t=t.low,b=p+b.low,j=j+W+(b>>>0<p>>>0?1:0),b=b+c,j=j+u+(b>>>0<c>>>0?1:0),b=b+t,j=j+q+(b>>>0<t>>>0?1:0);s.high=j;s.low=b}var W=l&R^~l&S,t=h&C^~h&D,s=k&z^k&A^z&A,T=g&x^g&y^x&y,p=(k>>>28|g<<4)^(k<<30|g>>>2)^(k<<25|g>>>7),u=(g>>>28|k<<4)^(g<<30|k>>>2)^(g<<25|k>>>7),c=ea[m],fa=c.high,da=c.low,c=E+((h>>>14|l<<18)^(h>>>18|l<<14)^(h<<23|l>>>9)),q=V+((l>>>14|h<<18)^(l>>>18|h<<14)^(l<<23|h>>>9))+(c>>>0<E>>>0?1:\r\n0),c=c+t,q=q+W+(c>>>0<t>>>0?1:0),c=c+da,q=q+fa+(c>>>0<da>>>0?1:0),c=c+b,q=q+j+(c>>>0<b>>>0?1:0),b=u+T,s=p+s+(b>>>0<u>>>0?1:0),V=S,E=D,S=R,D=C,R=l,C=h,h=B+c|0,l=U+q+(h>>>0<B>>>0?1:0)|0,U=A,B=y,A=z,y=x,z=k,x=g,g=c+b|0,k=q+s+(g>>>0<c>>>0?1:0)|0}J=F.low=J+g;F.high=w+k+(J>>>0<g>>>0?1:0);K=e.low=K+x;e.high=X+z+(K>>>0<x>>>0?1:0);L=n.low=L+y;n.high=Y+A+(L>>>0<y>>>0?1:0);M=r.low=M+B;r.high=Z+U+(M>>>0<B>>>0?1:0);N=G.low=N+h;G.high=$+l+(N>>>0<h>>>0?1:0);O=H.low=O+C;H.high=aa+R+(O>>>0<C>>>0?1:0);P=I.low=P+D;\r\nI.high=ba+S+(P>>>0<D>>>0?1:0);Q=f.low=Q+E;f.high=ca+V+(Q>>>0<E>>>0?1:0)},_doFinalize:function(){var a=this._data,d=a.words,f=8*this._nDataBytes,e=8*a.sigBytes;d[e>>>5]|=128<<24-e%32;d[(e+128>>>10<<5)+30]=Math.floor(f/4294967296);d[(e+128>>>10<<5)+31]=f;a.sigBytes=4*d.length;this._process();return this._hash.toX32()},clone:function(){var a=r.clone.call(this);a._hash=this._hash.clone();return a},blockSize:32});n.SHA512=r._createHelper(e);n.HmacSHA512=r._createHmacHelper(e)})();\r\n\n/*\r\nCryptoJS v3.1.2 sha384-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(){var c=CryptoJS,a=c.x64,b=a.Word,e=a.WordArray,a=c.algo,d=a.SHA512,a=a.SHA384=d.extend({_doReset:function(){this._hash=new e.init([new b.init(3418070365,3238371032),new b.init(1654270250,914150663),new b.init(2438529370,812702999),new b.init(355462360,4144912697),new b.init(1731405415,4290775857),new b.init(2394180231,1750603025),new b.init(3675008525,1694076839),new b.init(1203062813,3204075428)])},_doFinalize:function(){var a=d._doFinalize.call(this);a.sigBytes-=16;return a}});c.SHA384=\r\nd._createHelper(a);c.HmacSHA384=d._createHmacHelper(a)})();\r\n\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nvar b64map=\"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\";var b64pad=\"=\";function hex2b64(d){var b;var e;var a=\"\";for(b=0;b+3<=d.length;b+=3){e=parseInt(d.substring(b,b+3),16);a+=b64map.charAt(e>>6)+b64map.charAt(e&63)}if(b+1==d.length){e=parseInt(d.substring(b,b+1),16);a+=b64map.charAt(e<<2)}else{if(b+2==d.length){e=parseInt(d.substring(b,b+2),16);a+=b64map.charAt(e>>2)+b64map.charAt((e&3)<<4)}}if(b64pad){while((a.length&3)>0){a+=b64pad}}return a}function b64tohex(f){var d=\"\";var e;var b=0;var c;var a;for(e=0;e<f.length;++e){if(f.charAt(e)==b64pad){break}a=b64map.indexOf(f.charAt(e));if(a<0){continue}if(b==0){d+=int2char(a>>2);c=a&3;b=1}else{if(b==1){d+=int2char((c<<2)|(a>>4));c=a&15;b=2}else{if(b==2){d+=int2char(c);d+=int2char(a>>2);c=a&3;b=3}else{d+=int2char((c<<2)|(a>>4));d+=int2char(a&15);b=0}}}}if(b==1){d+=int2char(c<<2)}return d}function b64toBA(e){var d=b64tohex(e);var c;var b=new Array();for(c=0;2*c<d.length;++c){b[c]=parseInt(d.substring(2*c,2*c+2),16)}return b};\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nvar dbits;var canary=244837814094590;var j_lm=((canary&16777215)==15715070);function BigInteger(e,d,f){if(e!=null){if(\"number\"==typeof e){this.fromNumber(e,d,f)}else{if(d==null&&\"string\"!=typeof e){this.fromString(e,256)}else{this.fromString(e,d)}}}}function nbi(){return new BigInteger(null)}function am1(f,a,b,e,h,g){while(--g>=0){var d=a*this[f++]+b[e]+h;h=Math.floor(d/67108864);b[e++]=d&67108863}return h}function am2(f,q,r,e,o,a){var k=q&32767,p=q>>15;while(--a>=0){var d=this[f]&32767;var g=this[f++]>>15;var b=p*d+g*k;d=k*d+((b&32767)<<15)+r[e]+(o&1073741823);o=(d>>>30)+(b>>>15)+p*g+(o>>>30);r[e++]=d&1073741823}return o}function am3(f,q,r,e,o,a){var k=q&16383,p=q>>14;while(--a>=0){var d=this[f]&16383;var g=this[f++]>>14;var b=p*d+g*k;d=k*d+((b&16383)<<14)+r[e]+o;o=(d>>28)+(b>>14)+p*g;r[e++]=d&268435455}return o}if(j_lm&&(navigator.appName==\"Microsoft Internet Explorer\")){BigInteger.prototype.am=am2;dbits=30}else{if(j_lm&&(navigator.appName!=\"Netscape\")){BigInteger.prototype.am=am1;dbits=26}else{BigInteger.prototype.am=am3;dbits=28}}BigInteger.prototype.DB=dbits;BigInteger.prototype.DM=((1<<dbits)-1);BigInteger.prototype.DV=(1<<dbits);var BI_FP=52;BigInteger.prototype.FV=Math.pow(2,BI_FP);BigInteger.prototype.F1=BI_FP-dbits;BigInteger.prototype.F2=2*dbits-BI_FP;var BI_RM=\"0123456789abcdefghijklmnopqrstuvwxyz\";var BI_RC=new Array();var rr,vv;rr=\"0\".charCodeAt(0);for(vv=0;vv<=9;++vv){BI_RC[rr++]=vv}rr=\"a\".charCodeAt(0);for(vv=10;vv<36;++vv){BI_RC[rr++]=vv}rr=\"A\".charCodeAt(0);for(vv=10;vv<36;++vv){BI_RC[rr++]=vv}function int2char(a){return BI_RM.charAt(a)}function intAt(b,a){var d=BI_RC[b.charCodeAt(a)];return(d==null)?-1:d}function bnpCopyTo(b){for(var a=this.t-1;a>=0;--a){b[a]=this[a]}b.t=this.t;b.s=this.s}function bnpFromInt(a){this.t=1;this.s=(a<0)?-1:0;if(a>0){this[0]=a}else{if(a<-1){this[0]=a+this.DV}else{this.t=0}}}function nbv(a){var b=nbi();b.fromInt(a);return b}function bnpFromString(h,c){var e;if(c==16){e=4}else{if(c==8){e=3}else{if(c==256){e=8}else{if(c==2){e=1}else{if(c==32){e=5}else{if(c==4){e=2}else{this.fromRadix(h,c);return}}}}}}this.t=0;this.s=0;var g=h.length,d=false,f=0;while(--g>=0){var a=(e==8)?h[g]&255:intAt(h,g);if(a<0){if(h.charAt(g)==\"-\"){d=true}continue}d=false;if(f==0){this[this.t++]=a}else{if(f+e>this.DB){this[this.t-1]|=(a&((1<<(this.DB-f))-1))<<f;this[this.t++]=(a>>(this.DB-f))}else{this[this.t-1]|=a<<f}}f+=e;if(f>=this.DB){f-=this.DB}}if(e==8&&(h[0]&128)!=0){this.s=-1;if(f>0){this[this.t-1]|=((1<<(this.DB-f))-1)<<f}}this.clamp();if(d){BigInteger.ZERO.subTo(this,this)}}function bnpClamp(){var a=this.s&this.DM;while(this.t>0&&this[this.t-1]==a){--this.t}}function bnToString(c){if(this.s<0){return\"-\"+this.negate().toString(c)}var e;if(c==16){e=4}else{if(c==8){e=3}else{if(c==2){e=1}else{if(c==32){e=5}else{if(c==4){e=2}else{return this.toRadix(c)}}}}}var g=(1<<e)-1,l,a=false,h=\"\",f=this.t;var j=this.DB-(f*this.DB)%e;if(f-->0){if(j<this.DB&&(l=this[f]>>j)>0){a=true;h=int2char(l)}while(f>=0){if(j<e){l=(this[f]&((1<<j)-1))<<(e-j);l|=this[--f]>>(j+=this.DB-e)}else{l=(this[f]>>(j-=e))&g;if(j<=0){j+=this.DB;--f}}if(l>0){a=true}if(a){h+=int2char(l)}}}return a?h:\"0\"}function bnNegate(){var a=nbi();BigInteger.ZERO.subTo(this,a);return a}function bnAbs(){return(this.s<0)?this.negate():this}function bnCompareTo(b){var d=this.s-b.s;if(d!=0){return d}var c=this.t;d=c-b.t;if(d!=0){return(this.s<0)?-d:d}while(--c>=0){if((d=this[c]-b[c])!=0){return d}}return 0}function nbits(a){var c=1,b;if((b=a>>>16)!=0){a=b;c+=16}if((b=a>>8)!=0){a=b;c+=8}if((b=a>>4)!=0){a=b;c+=4}if((b=a>>2)!=0){a=b;c+=2}if((b=a>>1)!=0){a=b;c+=1}return c}function bnBitLength(){if(this.t<=0){return 0}return this.DB*(this.t-1)+nbits(this[this.t-1]^(this.s&this.DM))}function bnpDLShiftTo(c,b){var a;for(a=this.t-1;a>=0;--a){b[a+c]=this[a]}for(a=c-1;a>=0;--a){b[a]=0}b.t=this.t+c;b.s=this.s}function bnpDRShiftTo(c,b){for(var a=c;a<this.t;++a){b[a-c]=this[a]}b.t=Math.max(this.t-c,0);b.s=this.s}function bnpLShiftTo(j,e){var b=j%this.DB;var a=this.DB-b;var g=(1<<a)-1;var f=Math.floor(j/this.DB),h=(this.s<<b)&this.DM,d;for(d=this.t-1;d>=0;--d){e[d+f+1]=(this[d]>>a)|h;h=(this[d]&g)<<b}for(d=f-1;d>=0;--d){e[d]=0}e[f]=h;e.t=this.t+f+1;e.s=this.s;e.clamp()}function bnpRShiftTo(g,d){d.s=this.s;var e=Math.floor(g/this.DB);if(e>=this.t){d.t=0;return}var b=g%this.DB;var a=this.DB-b;var f=(1<<b)-1;d[0]=this[e]>>b;for(var c=e+1;c<this.t;++c){d[c-e-1]|=(this[c]&f)<<a;d[c-e]=this[c]>>b}if(b>0){d[this.t-e-1]|=(this.s&f)<<a}d.t=this.t-e;d.clamp()}function bnpSubTo(d,f){var e=0,g=0,b=Math.min(d.t,this.t);while(e<b){g+=this[e]-d[e];f[e++]=g&this.DM;g>>=this.DB}if(d.t<this.t){g-=d.s;while(e<this.t){g+=this[e];f[e++]=g&this.DM;g>>=this.DB}g+=this.s}else{g+=this.s;while(e<d.t){g-=d[e];f[e++]=g&this.DM;g>>=this.DB}g-=d.s}f.s=(g<0)?-1:0;if(g<-1){f[e++]=this.DV+g}else{if(g>0){f[e++]=g}}f.t=e;f.clamp()}function bnpMultiplyTo(c,e){var b=this.abs(),f=c.abs();var d=b.t;e.t=d+f.t;while(--d>=0){e[d]=0}for(d=0;d<f.t;++d){e[d+b.t]=b.am(0,f[d],e,d,0,b.t)}e.s=0;e.clamp();if(this.s!=c.s){BigInteger.ZERO.subTo(e,e)}}function bnpSquareTo(d){var a=this.abs();var b=d.t=2*a.t;while(--b>=0){d[b]=0}for(b=0;b<a.t-1;++b){var e=a.am(b,a[b],d,2*b,0,1);if((d[b+a.t]+=a.am(b+1,2*a[b],d,2*b+1,e,a.t-b-1))>=a.DV){d[b+a.t]-=a.DV;d[b+a.t+1]=1}}if(d.t>0){d[d.t-1]+=a.am(b,a[b],d,2*b,0,1)}d.s=0;d.clamp()}function bnpDivRemTo(n,h,g){var w=n.abs();if(w.t<=0){return}var k=this.abs();if(k.t<w.t){if(h!=null){h.fromInt(0)}if(g!=null){this.copyTo(g)}return}if(g==null){g=nbi()}var d=nbi(),a=this.s,l=n.s;var v=this.DB-nbits(w[w.t-1]);if(v>0){w.lShiftTo(v,d);k.lShiftTo(v,g)}else{w.copyTo(d);k.copyTo(g)}var p=d.t;var b=d[p-1];if(b==0){return}var o=b*(1<<this.F1)+((p>1)?d[p-2]>>this.F2:0);var A=this.FV/o,z=(1<<this.F1)/o,x=1<<this.F2;var u=g.t,s=u-p,f=(h==null)?nbi():h;d.dlShiftTo(s,f);if(g.compareTo(f)>=0){g[g.t++]=1;g.subTo(f,g)}BigInteger.ONE.dlShiftTo(p,f);f.subTo(d,d);while(d.t<p){d[d.t++]=0}while(--s>=0){var c=(g[--u]==b)?this.DM:Math.floor(g[u]*A+(g[u-1]+x)*z);if((g[u]+=d.am(0,c,g,s,0,p))<c){d.dlShiftTo(s,f);g.subTo(f,g);while(g[u]<--c){g.subTo(f,g)}}}if(h!=null){g.drShiftTo(p,h);if(a!=l){BigInteger.ZERO.subTo(h,h)}}g.t=p;g.clamp();if(v>0){g.rShiftTo(v,g)}if(a<0){BigInteger.ZERO.subTo(g,g)}}function bnMod(b){var c=nbi();this.abs().divRemTo(b,null,c);if(this.s<0&&c.compareTo(BigInteger.ZERO)>0){b.subTo(c,c)}return c}function Classic(a){this.m=a}function cConvert(a){if(a.s<0||a.compareTo(this.m)>=0){return a.mod(this.m)}else{return a}}function cRevert(a){return a}function cReduce(a){a.divRemTo(this.m,null,a)}function cMulTo(a,c,b){a.multiplyTo(c,b);this.reduce(b)}function cSqrTo(a,b){a.squareTo(b);this.reduce(b)}Classic.prototype.convert=cConvert;Classic.prototype.revert=cRevert;Classic.prototype.reduce=cReduce;Classic.prototype.mulTo=cMulTo;Classic.prototype.sqrTo=cSqrTo;function bnpInvDigit(){if(this.t<1){return 0}var a=this[0];if((a&1)==0){return 0}var b=a&3;b=(b*(2-(a&15)*b))&15;b=(b*(2-(a&255)*b))&255;b=(b*(2-(((a&65535)*b)&65535)))&65535;b=(b*(2-a*b%this.DV))%this.DV;return(b>0)?this.DV-b:-b}function Montgomery(a){this.m=a;this.mp=a.invDigit();this.mpl=this.mp&32767;this.mph=this.mp>>15;this.um=(1<<(a.DB-15))-1;this.mt2=2*a.t}function montConvert(a){var b=nbi();a.abs().dlShiftTo(this.m.t,b);b.divRemTo(this.m,null,b);if(a.s<0&&b.compareTo(BigInteger.ZERO)>0){this.m.subTo(b,b)}return b}function montRevert(a){var b=nbi();a.copyTo(b);this.reduce(b);return b}function montReduce(a){while(a.t<=this.mt2){a[a.t++]=0}for(var c=0;c<this.m.t;++c){var b=a[c]&32767;var d=(b*this.mpl+(((b*this.mph+(a[c]>>15)*this.mpl)&this.um)<<15))&a.DM;b=c+this.m.t;a[b]+=this.m.am(0,d,a,c,0,this.m.t);while(a[b]>=a.DV){a[b]-=a.DV;a[++b]++}}a.clamp();a.drShiftTo(this.m.t,a);if(a.compareTo(this.m)>=0){a.subTo(this.m,a)}}function montSqrTo(a,b){a.squareTo(b);this.reduce(b)}function montMulTo(a,c,b){a.multiplyTo(c,b);this.reduce(b)}Montgomery.prototype.convert=montConvert;Montgomery.prototype.revert=montRevert;Montgomery.prototype.reduce=montReduce;Montgomery.prototype.mulTo=montMulTo;Montgomery.prototype.sqrTo=montSqrTo;function bnpIsEven(){return((this.t>0)?(this[0]&1):this.s)==0}function bnpExp(h,j){if(h>4294967295||h<1){return BigInteger.ONE}var f=nbi(),a=nbi(),d=j.convert(this),c=nbits(h)-1;d.copyTo(f);while(--c>=0){j.sqrTo(f,a);if((h&(1<<c))>0){j.mulTo(a,d,f)}else{var b=f;f=a;a=b}}return j.revert(f)}function bnModPowInt(b,a){var c;if(b<256||a.isEven()){c=new Classic(a)}else{c=new Montgomery(a)}return this.exp(b,c)}BigInteger.prototype.copyTo=bnpCopyTo;BigInteger.prototype.fromInt=bnpFromInt;BigInteger.prototype.fromString=bnpFromString;BigInteger.prototype.clamp=bnpClamp;BigInteger.prototype.dlShiftTo=bnpDLShiftTo;BigInteger.prototype.drShiftTo=bnpDRShiftTo;BigInteger.prototype.lShiftTo=bnpLShiftTo;BigInteger.prototype.rShiftTo=bnpRShiftTo;BigInteger.prototype.subTo=bnpSubTo;BigInteger.prototype.multiplyTo=bnpMultiplyTo;BigInteger.prototype.squareTo=bnpSquareTo;BigInteger.prototype.divRemTo=bnpDivRemTo;BigInteger.prototype.invDigit=bnpInvDigit;BigInteger.prototype.isEven=bnpIsEven;BigInteger.prototype.exp=bnpExp;BigInteger.prototype.toString=bnToString;BigInteger.prototype.negate=bnNegate;BigInteger.prototype.abs=bnAbs;BigInteger.prototype.compareTo=bnCompareTo;BigInteger.prototype.bitLength=bnBitLength;BigInteger.prototype.mod=bnMod;BigInteger.prototype.modPowInt=bnModPowInt;BigInteger.ZERO=nbv(0);BigInteger.ONE=nbv(1);\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction bnClone(){var a=nbi();this.copyTo(a);return a}function bnIntValue(){if(this.s<0){if(this.t==1){return this[0]-this.DV}else{if(this.t==0){return -1}}}else{if(this.t==1){return this[0]}else{if(this.t==0){return 0}}}return((this[1]&((1<<(32-this.DB))-1))<<this.DB)|this[0]}function bnByteValue(){return(this.t==0)?this.s:(this[0]<<24)>>24}function bnShortValue(){return(this.t==0)?this.s:(this[0]<<16)>>16}function bnpChunkSize(a){return Math.floor(Math.LN2*this.DB/Math.log(a))}function bnSigNum(){if(this.s<0){return -1}else{if(this.t<=0||(this.t==1&&this[0]<=0)){return 0}else{return 1}}}function bnpToRadix(c){if(c==null){c=10}if(this.signum()==0||c<2||c>36){return\"0\"}var f=this.chunkSize(c);var e=Math.pow(c,f);var i=nbv(e),j=nbi(),h=nbi(),g=\"\";this.divRemTo(i,j,h);while(j.signum()>0){g=(e+h.intValue()).toString(c).substr(1)+g;j.divRemTo(i,j,h)}return h.intValue().toString(c)+g}function bnpFromRadix(m,h){this.fromInt(0);if(h==null){h=10}var f=this.chunkSize(h);var g=Math.pow(h,f),e=false,a=0,l=0;for(var c=0;c<m.length;++c){var k=intAt(m,c);if(k<0){if(m.charAt(c)==\"-\"&&this.signum()==0){e=true}continue}l=h*l+k;if(++a>=f){this.dMultiply(g);this.dAddOffset(l,0);a=0;l=0}}if(a>0){this.dMultiply(Math.pow(h,a));this.dAddOffset(l,0)}if(e){BigInteger.ZERO.subTo(this,this)}}function bnpFromNumber(f,e,h){if(\"number\"==typeof e){if(f<2){this.fromInt(1)}else{this.fromNumber(f,h);if(!this.testBit(f-1)){this.bitwiseTo(BigInteger.ONE.shiftLeft(f-1),op_or,this)}if(this.isEven()){this.dAddOffset(1,0)}while(!this.isProbablePrime(e)){this.dAddOffset(2,0);if(this.bitLength()>f){this.subTo(BigInteger.ONE.shiftLeft(f-1),this)}}}}else{var d=new Array(),g=f&7;d.length=(f>>3)+1;e.nextBytes(d);if(g>0){d[0]&=((1<<g)-1)}else{d[0]=0}this.fromString(d,256)}}function bnToByteArray(){var b=this.t,c=new Array();c[0]=this.s;var e=this.DB-(b*this.DB)%8,f,a=0;if(b-->0){if(e<this.DB&&(f=this[b]>>e)!=(this.s&this.DM)>>e){c[a++]=f|(this.s<<(this.DB-e))}while(b>=0){if(e<8){f=(this[b]&((1<<e)-1))<<(8-e);f|=this[--b]>>(e+=this.DB-8)}else{f=(this[b]>>(e-=8))&255;if(e<=0){e+=this.DB;--b}}if((f&128)!=0){f|=-256}if(a==0&&(this.s&128)!=(f&128)){++a}if(a>0||f!=this.s){c[a++]=f}}}return c}function bnEquals(b){return(this.compareTo(b)==0)}function bnMin(b){return(this.compareTo(b)<0)?this:b}function bnMax(b){return(this.compareTo(b)>0)?this:b}function bnpBitwiseTo(c,h,e){var d,g,b=Math.min(c.t,this.t);for(d=0;d<b;++d){e[d]=h(this[d],c[d])}if(c.t<this.t){g=c.s&this.DM;for(d=b;d<this.t;++d){e[d]=h(this[d],g)}e.t=this.t}else{g=this.s&this.DM;for(d=b;d<c.t;++d){e[d]=h(g,c[d])}e.t=c.t}e.s=h(this.s,c.s);e.clamp()}function op_and(a,b){return a&b}function bnAnd(b){var c=nbi();this.bitwiseTo(b,op_and,c);return c}function op_or(a,b){return a|b}function bnOr(b){var c=nbi();this.bitwiseTo(b,op_or,c);return c}function op_xor(a,b){return a^b}function bnXor(b){var c=nbi();this.bitwiseTo(b,op_xor,c);return c}function op_andnot(a,b){return a&~b}function bnAndNot(b){var c=nbi();this.bitwiseTo(b,op_andnot,c);return c}function bnNot(){var b=nbi();for(var a=0;a<this.t;++a){b[a]=this.DM&~this[a]}b.t=this.t;b.s=~this.s;return b}function bnShiftLeft(b){var a=nbi();if(b<0){this.rShiftTo(-b,a)}else{this.lShiftTo(b,a)}return a}function bnShiftRight(b){var a=nbi();if(b<0){this.lShiftTo(-b,a)}else{this.rShiftTo(b,a)}return a}function lbit(a){if(a==0){return -1}var b=0;if((a&65535)==0){a>>=16;b+=16}if((a&255)==0){a>>=8;b+=8}if((a&15)==0){a>>=4;b+=4}if((a&3)==0){a>>=2;b+=2}if((a&1)==0){++b}return b}function bnGetLowestSetBit(){for(var a=0;a<this.t;++a){if(this[a]!=0){return a*this.DB+lbit(this[a])}}if(this.s<0){return this.t*this.DB}return -1}function cbit(a){var b=0;while(a!=0){a&=a-1;++b}return b}function bnBitCount(){var c=0,a=this.s&this.DM;for(var b=0;b<this.t;++b){c+=cbit(this[b]^a)}return c}function bnTestBit(b){var a=Math.floor(b/this.DB);if(a>=this.t){return(this.s!=0)}return((this[a]&(1<<(b%this.DB)))!=0)}function bnpChangeBit(c,b){var a=BigInteger.ONE.shiftLeft(c);this.bitwiseTo(a,b,a);return a}function bnSetBit(a){return this.changeBit(a,op_or)}function bnClearBit(a){return this.changeBit(a,op_andnot)}function bnFlipBit(a){return this.changeBit(a,op_xor)}function bnpAddTo(d,f){var e=0,g=0,b=Math.min(d.t,this.t);while(e<b){g+=this[e]+d[e];f[e++]=g&this.DM;g>>=this.DB}if(d.t<this.t){g+=d.s;while(e<this.t){g+=this[e];f[e++]=g&this.DM;g>>=this.DB}g+=this.s}else{g+=this.s;while(e<d.t){g+=d[e];f[e++]=g&this.DM;g>>=this.DB}g+=d.s}f.s=(g<0)?-1:0;if(g>0){f[e++]=g}else{if(g<-1){f[e++]=this.DV+g}}f.t=e;f.clamp()}function bnAdd(b){var c=nbi();this.addTo(b,c);return c}function bnSubtract(b){var c=nbi();this.subTo(b,c);return c}function bnMultiply(b){var c=nbi();this.multiplyTo(b,c);return c}function bnSquare(){var a=nbi();this.squareTo(a);return a}function bnDivide(b){var c=nbi();this.divRemTo(b,c,null);return c}function bnRemainder(b){var c=nbi();this.divRemTo(b,null,c);return c}function bnDivideAndRemainder(b){var d=nbi(),c=nbi();this.divRemTo(b,d,c);return new Array(d,c)}function bnpDMultiply(a){this[this.t]=this.am(0,a-1,this,0,0,this.t);++this.t;this.clamp()}function bnpDAddOffset(b,a){if(b==0){return}while(this.t<=a){this[this.t++]=0}this[a]+=b;while(this[a]>=this.DV){this[a]-=this.DV;if(++a>=this.t){this[this.t++]=0}++this[a]}}function NullExp(){}function nNop(a){return a}function nMulTo(a,c,b){a.multiplyTo(c,b)}function nSqrTo(a,b){a.squareTo(b)}NullExp.prototype.convert=nNop;NullExp.prototype.revert=nNop;NullExp.prototype.mulTo=nMulTo;NullExp.prototype.sqrTo=nSqrTo;function bnPow(a){return this.exp(a,new NullExp())}function bnpMultiplyLowerTo(b,f,e){var d=Math.min(this.t+b.t,f);e.s=0;e.t=d;while(d>0){e[--d]=0}var c;for(c=e.t-this.t;d<c;++d){e[d+this.t]=this.am(0,b[d],e,d,0,this.t)}for(c=Math.min(b.t,f);d<c;++d){this.am(0,b[d],e,d,0,f-d)}e.clamp()}function bnpMultiplyUpperTo(b,e,d){--e;var c=d.t=this.t+b.t-e;d.s=0;while(--c>=0){d[c]=0}for(c=Math.max(e-this.t,0);c<b.t;++c){d[this.t+c-e]=this.am(e-c,b[c],d,0,0,this.t+c-e)}d.clamp();d.drShiftTo(1,d)}function Barrett(a){this.r2=nbi();this.q3=nbi();BigInteger.ONE.dlShiftTo(2*a.t,this.r2);this.mu=this.r2.divide(a);this.m=a}function barrettConvert(a){if(a.s<0||a.t>2*this.m.t){return a.mod(this.m)}else{if(a.compareTo(this.m)<0){return a}else{var b=nbi();a.copyTo(b);this.reduce(b);return b}}}function barrettRevert(a){return a}function barrettReduce(a){a.drShiftTo(this.m.t-1,this.r2);if(a.t>this.m.t+1){a.t=this.m.t+1;a.clamp()}this.mu.multiplyUpperTo(this.r2,this.m.t+1,this.q3);this.m.multiplyLowerTo(this.q3,this.m.t+1,this.r2);while(a.compareTo(this.r2)<0){a.dAddOffset(1,this.m.t+1)}a.subTo(this.r2,a);while(a.compareTo(this.m)>=0){a.subTo(this.m,a)}}function barrettSqrTo(a,b){a.squareTo(b);this.reduce(b)}function barrettMulTo(a,c,b){a.multiplyTo(c,b);this.reduce(b)}Barrett.prototype.convert=barrettConvert;Barrett.prototype.revert=barrettRevert;Barrett.prototype.reduce=barrettReduce;Barrett.prototype.mulTo=barrettMulTo;Barrett.prototype.sqrTo=barrettSqrTo;function bnModPow(q,f){var o=q.bitLength(),h,b=nbv(1),v;if(o<=0){return b}else{if(o<18){h=1}else{if(o<48){h=3}else{if(o<144){h=4}else{if(o<768){h=5}else{h=6}}}}}if(o<8){v=new Classic(f)}else{if(f.isEven()){v=new Barrett(f)}else{v=new Montgomery(f)}}var p=new Array(),d=3,s=h-1,a=(1<<h)-1;p[1]=v.convert(this);if(h>1){var A=nbi();v.sqrTo(p[1],A);while(d<=a){p[d]=nbi();v.mulTo(A,p[d-2],p[d]);d+=2}}var l=q.t-1,x,u=true,c=nbi(),y;o=nbits(q[l])-1;while(l>=0){if(o>=s){x=(q[l]>>(o-s))&a}else{x=(q[l]&((1<<(o+1))-1))<<(s-o);if(l>0){x|=q[l-1]>>(this.DB+o-s)}}d=h;while((x&1)==0){x>>=1;--d}if((o-=d)<0){o+=this.DB;--l}if(u){p[x].copyTo(b);u=false}else{while(d>1){v.sqrTo(b,c);v.sqrTo(c,b);d-=2}if(d>0){v.sqrTo(b,c)}else{y=b;b=c;c=y}v.mulTo(c,p[x],b)}while(l>=0&&(q[l]&(1<<o))==0){v.sqrTo(b,c);y=b;b=c;c=y;if(--o<0){o=this.DB-1;--l}}}return v.revert(b)}function bnGCD(c){var b=(this.s<0)?this.negate():this.clone();var h=(c.s<0)?c.negate():c.clone();if(b.compareTo(h)<0){var e=b;b=h;h=e}var d=b.getLowestSetBit(),f=h.getLowestSetBit();if(f<0){return b}if(d<f){f=d}if(f>0){b.rShiftTo(f,b);h.rShiftTo(f,h)}while(b.signum()>0){if((d=b.getLowestSetBit())>0){b.rShiftTo(d,b)}if((d=h.getLowestSetBit())>0){h.rShiftTo(d,h)}if(b.compareTo(h)>=0){b.subTo(h,b);b.rShiftTo(1,b)}else{h.subTo(b,h);h.rShiftTo(1,h)}}if(f>0){h.lShiftTo(f,h)}return h}function bnpModInt(e){if(e<=0){return 0}var c=this.DV%e,b=(this.s<0)?e-1:0;if(this.t>0){if(c==0){b=this[0]%e}else{for(var a=this.t-1;a>=0;--a){b=(c*b+this[a])%e}}}return b}function bnModInverse(f){var j=f.isEven();if((this.isEven()&&j)||f.signum()==0){return BigInteger.ZERO}var i=f.clone(),h=this.clone();var g=nbv(1),e=nbv(0),l=nbv(0),k=nbv(1);while(i.signum()!=0){while(i.isEven()){i.rShiftTo(1,i);if(j){if(!g.isEven()||!e.isEven()){g.addTo(this,g);e.subTo(f,e)}g.rShiftTo(1,g)}else{if(!e.isEven()){e.subTo(f,e)}}e.rShiftTo(1,e)}while(h.isEven()){h.rShiftTo(1,h);if(j){if(!l.isEven()||!k.isEven()){l.addTo(this,l);k.subTo(f,k)}l.rShiftTo(1,l)}else{if(!k.isEven()){k.subTo(f,k)}}k.rShiftTo(1,k)}if(i.compareTo(h)>=0){i.subTo(h,i);if(j){g.subTo(l,g)}e.subTo(k,e)}else{h.subTo(i,h);if(j){l.subTo(g,l)}k.subTo(e,k)}}if(h.compareTo(BigInteger.ONE)!=0){return BigInteger.ZERO}if(k.compareTo(f)>=0){return k.subtract(f)}if(k.signum()<0){k.addTo(f,k)}else{return k}if(k.signum()<0){return k.add(f)}else{return k}}var lowprimes=[2,3,5,7,11,13,17,19,23,29,31,37,41,43,47,53,59,61,67,71,73,79,83,89,97,101,103,107,109,113,127,131,137,139,149,151,157,163,167,173,179,181,191,193,197,199,211,223,227,229,233,239,241,251,257,263,269,271,277,281,283,293,307,311,313,317,331,337,347,349,353,359,367,373,379,383,389,397,401,409,419,421,431,433,439,443,449,457,461,463,467,479,487,491,499,503,509,521,523,541,547,557,563,569,571,577,587,593,599,601,607,613,617,619,631,641,643,647,653,659,661,673,677,683,691,701,709,719,727,733,739,743,751,757,761,769,773,787,797,809,811,821,823,827,829,839,853,857,859,863,877,881,883,887,907,911,919,929,937,941,947,953,967,971,977,983,991,997];var lplim=(1<<26)/lowprimes[lowprimes.length-1];function bnIsProbablePrime(e){var d,b=this.abs();if(b.t==1&&b[0]<=lowprimes[lowprimes.length-1]){for(d=0;d<lowprimes.length;++d){if(b[0]==lowprimes[d]){return true}}return false}if(b.isEven()){return false}d=1;while(d<lowprimes.length){var a=lowprimes[d],c=d+1;while(c<lowprimes.length&&a<lplim){a*=lowprimes[c++]}a=b.modInt(a);while(d<c){if(a%lowprimes[d++]==0){return false}}}return b.millerRabin(e)}function bnpMillerRabin(f){var g=this.subtract(BigInteger.ONE);var c=g.getLowestSetBit();if(c<=0){return false}var h=g.shiftRight(c);f=(f+1)>>1;if(f>lowprimes.length){f=lowprimes.length}var b=nbi();for(var e=0;e<f;++e){b.fromInt(lowprimes[Math.floor(Math.random()*lowprimes.length)]);var l=b.modPow(h,this);if(l.compareTo(BigInteger.ONE)!=0&&l.compareTo(g)!=0){var d=1;while(d++<c&&l.compareTo(g)!=0){l=l.modPowInt(2,this);if(l.compareTo(BigInteger.ONE)==0){return false}}if(l.compareTo(g)!=0){return false}}}return true}BigInteger.prototype.chunkSize=bnpChunkSize;BigInteger.prototype.toRadix=bnpToRadix;BigInteger.prototype.fromRadix=bnpFromRadix;BigInteger.prototype.fromNumber=bnpFromNumber;BigInteger.prototype.bitwiseTo=bnpBitwiseTo;BigInteger.prototype.changeBit=bnpChangeBit;BigInteger.prototype.addTo=bnpAddTo;BigInteger.prototype.dMultiply=bnpDMultiply;BigInteger.prototype.dAddOffset=bnpDAddOffset;BigInteger.prototype.multiplyLowerTo=bnpMultiplyLowerTo;BigInteger.prototype.multiplyUpperTo=bnpMultiplyUpperTo;BigInteger.prototype.modInt=bnpModInt;BigInteger.prototype.millerRabin=bnpMillerRabin;BigInteger.prototype.clone=bnClone;BigInteger.prototype.intValue=bnIntValue;BigInteger.prototype.byteValue=bnByteValue;BigInteger.prototype.shortValue=bnShortValue;BigInteger.prototype.signum=bnSigNum;BigInteger.prototype.toByteArray=bnToByteArray;BigInteger.prototype.equals=bnEquals;BigInteger.prototype.min=bnMin;BigInteger.prototype.max=bnMax;BigInteger.prototype.and=bnAnd;BigInteger.prototype.or=bnOr;BigInteger.prototype.xor=bnXor;BigInteger.prototype.andNot=bnAndNot;BigInteger.prototype.not=bnNot;BigInteger.prototype.shiftLeft=bnShiftLeft;BigInteger.prototype.shiftRight=bnShiftRight;BigInteger.prototype.getLowestSetBit=bnGetLowestSetBit;BigInteger.prototype.bitCount=bnBitCount;BigInteger.prototype.testBit=bnTestBit;BigInteger.prototype.setBit=bnSetBit;BigInteger.prototype.clearBit=bnClearBit;BigInteger.prototype.flipBit=bnFlipBit;BigInteger.prototype.add=bnAdd;BigInteger.prototype.subtract=bnSubtract;BigInteger.prototype.multiply=bnMultiply;BigInteger.prototype.divide=bnDivide;BigInteger.prototype.remainder=bnRemainder;BigInteger.prototype.divideAndRemainder=bnDivideAndRemainder;BigInteger.prototype.modPow=bnModPow;BigInteger.prototype.modInverse=bnModInverse;BigInteger.prototype.pow=bnPow;BigInteger.prototype.gcd=bnGCD;BigInteger.prototype.isProbablePrime=bnIsProbablePrime;BigInteger.prototype.square=bnSquare;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction Arcfour(){this.i=0;this.j=0;this.S=new Array()}function ARC4init(d){var c,a,b;for(c=0;c<256;++c){this.S[c]=c}a=0;for(c=0;c<256;++c){a=(a+this.S[c]+d[c%d.length])&255;b=this.S[c];this.S[c]=this.S[a];this.S[a]=b}this.i=0;this.j=0}function ARC4next(){var a;this.i=(this.i+1)&255;this.j=(this.j+this.S[this.i])&255;a=this.S[this.i];this.S[this.i]=this.S[this.j];this.S[this.j]=a;return this.S[(a+this.S[this.i])&255]}Arcfour.prototype.init=ARC4init;Arcfour.prototype.next=ARC4next;function prng_newstate(){return new Arcfour()}var rng_psize=256;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nvar rng_state;var rng_pool;var rng_pptr;function rng_seed_int(a){rng_pool[rng_pptr++]^=a&255;rng_pool[rng_pptr++]^=(a>>8)&255;rng_pool[rng_pptr++]^=(a>>16)&255;rng_pool[rng_pptr++]^=(a>>24)&255;if(rng_pptr>=rng_psize){rng_pptr-=rng_psize}}function rng_seed_time(){rng_seed_int(new Date().getTime())}if(rng_pool==null){rng_pool=new Array();rng_pptr=0;var t;if(window!==undefined&&(window.crypto!==undefined||window.msCrypto!==undefined)){var crypto=window.crypto||window.msCrypto;if(crypto.getRandomValues){var ua=new Uint8Array(32);crypto.getRandomValues(ua);for(t=0;t<32;++t){rng_pool[rng_pptr++]=ua[t]}}else{if(navigator.appName==\"Netscape\"&&navigator.appVersion<\"5\"){var z=window.crypto.random(32);for(t=0;t<z.length;++t){rng_pool[rng_pptr++]=z.charCodeAt(t)&255}}}}while(rng_pptr<rng_psize){t=Math.floor(65536*Math.random());rng_pool[rng_pptr++]=t>>>8;rng_pool[rng_pptr++]=t&255}rng_pptr=0;rng_seed_time()}function rng_get_byte(){if(rng_state==null){rng_seed_time();rng_state=prng_newstate();rng_state.init(rng_pool);for(rng_pptr=0;rng_pptr<rng_pool.length;++rng_pptr){rng_pool[rng_pptr]=0}rng_pptr=0}return rng_state.next()}function rng_get_bytes(b){var a;for(a=0;a<b.length;++a){b[a]=rng_get_byte()}}function SecureRandom(){}SecureRandom.prototype.nextBytes=rng_get_bytes;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction parseBigInt(b,a){return new BigInteger(b,a)}function linebrk(c,d){var a=\"\";var b=0;while(b+d<c.length){a+=c.substring(b,b+d)+\"\\n\";b+=d}return a+c.substring(b,c.length)}function byte2Hex(a){if(a<16){return\"0\"+a.toString(16)}else{return a.toString(16)}}function pkcs1pad2(e,h){if(h<e.length+11){throw\"Message too long for RSA\";return null}var g=new Array();var d=e.length-1;while(d>=0&&h>0){var f=e.charCodeAt(d--);if(f<128){g[--h]=f}else{if((f>127)&&(f<2048)){g[--h]=(f&63)|128;g[--h]=(f>>6)|192}else{g[--h]=(f&63)|128;g[--h]=((f>>6)&63)|128;g[--h]=(f>>12)|224}}}g[--h]=0;var b=new SecureRandom();var a=new Array();while(h>2){a[0]=0;while(a[0]==0){b.nextBytes(a)}g[--h]=a[0]}g[--h]=2;g[--h]=0;return new BigInteger(g)}function oaep_mgf1_arr(c,a,e){var b=\"\",d=0;while(b.length<a){b+=e(String.fromCharCode.apply(String,c.concat([(d&4278190080)>>24,(d&16711680)>>16,(d&65280)>>8,d&255])));d+=1}return b}function oaep_pad(q,a,f,l){var c=KJUR.crypto.MessageDigest;var o=KJUR.crypto.Util;var b=null;if(!f){f=\"sha1\"}if(typeof f===\"string\"){b=c.getCanonicalAlgName(f);l=c.getHashLength(b);f=function(i){return hextorstr(o.hashHex(rstrtohex(i),b))}}if(q.length+2*l+2>a){throw\"Message too long for RSA\"}var k=\"\",e;for(e=0;e<a-q.length-2*l-2;e+=1){k+=\"\\x00\"}var h=f(\"\")+k+\"\\x01\"+q;var g=new Array(l);new SecureRandom().nextBytes(g);var j=oaep_mgf1_arr(g,h.length,f);var p=[];for(e=0;e<h.length;e+=1){p[e]=h.charCodeAt(e)^j.charCodeAt(e)}var m=oaep_mgf1_arr(p,g.length,f);var d=[0];for(e=0;e<g.length;e+=1){d[e+1]=g[e]^m.charCodeAt(e)}return new BigInteger(d.concat(p))}function RSAKey(){this.n=null;this.e=0;this.d=null;this.p=null;this.q=null;this.dmp1=null;this.dmq1=null;this.coeff=null}function RSASetPublic(b,a){this.isPublic=true;this.isPrivate=false;if(typeof b!==\"string\"){this.n=b;this.e=a}else{if(b!=null&&a!=null&&b.length>0&&a.length>0){this.n=parseBigInt(b,16);this.e=parseInt(a,16)}else{throw\"Invalid RSA public key\"}}}function RSADoPublic(a){return a.modPowInt(this.e,this.n)}function RSAEncrypt(d){var a=pkcs1pad2(d,(this.n.bitLength()+7)>>3);if(a==null){return null}var e=this.doPublic(a);if(e==null){return null}var b=e.toString(16);if((b.length&1)==0){return b}else{return\"0\"+b}}function RSAEncryptOAEP(f,e,b){var a=oaep_pad(f,(this.n.bitLength()+7)>>3,e,b);if(a==null){return null}var g=this.doPublic(a);if(g==null){return null}var d=g.toString(16);if((d.length&1)==0){return d}else{return\"0\"+d}}RSAKey.prototype.doPublic=RSADoPublic;RSAKey.prototype.setPublic=RSASetPublic;RSAKey.prototype.encrypt=RSAEncrypt;RSAKey.prototype.encryptOAEP=RSAEncryptOAEP;RSAKey.prototype.type=\"RSA\";\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction ECFieldElementFp(b,a){this.x=a;this.q=b}function feFpEquals(a){if(a==this){return true}return(this.q.equals(a.q)&&this.x.equals(a.x))}function feFpToBigInteger(){return this.x}function feFpNegate(){return new ECFieldElementFp(this.q,this.x.negate().mod(this.q))}function feFpAdd(a){return new ECFieldElementFp(this.q,this.x.add(a.toBigInteger()).mod(this.q))}function feFpSubtract(a){return new ECFieldElementFp(this.q,this.x.subtract(a.toBigInteger()).mod(this.q))}function feFpMultiply(a){return new ECFieldElementFp(this.q,this.x.multiply(a.toBigInteger()).mod(this.q))}function feFpSquare(){return new ECFieldElementFp(this.q,this.x.square().mod(this.q))}function feFpDivide(a){return new ECFieldElementFp(this.q,this.x.multiply(a.toBigInteger().modInverse(this.q)).mod(this.q))}ECFieldElementFp.prototype.equals=feFpEquals;ECFieldElementFp.prototype.toBigInteger=feFpToBigInteger;ECFieldElementFp.prototype.negate=feFpNegate;ECFieldElementFp.prototype.add=feFpAdd;ECFieldElementFp.prototype.subtract=feFpSubtract;ECFieldElementFp.prototype.multiply=feFpMultiply;ECFieldElementFp.prototype.square=feFpSquare;ECFieldElementFp.prototype.divide=feFpDivide;function ECPointFp(c,a,d,b){this.curve=c;this.x=a;this.y=d;if(b==null){this.z=BigInteger.ONE}else{this.z=b}this.zinv=null}function pointFpGetX(){if(this.zinv==null){this.zinv=this.z.modInverse(this.curve.q)}return this.curve.fromBigInteger(this.x.toBigInteger().multiply(this.zinv).mod(this.curve.q))}function pointFpGetY(){if(this.zinv==null){this.zinv=this.z.modInverse(this.curve.q)}return this.curve.fromBigInteger(this.y.toBigInteger().multiply(this.zinv).mod(this.curve.q))}function pointFpEquals(a){if(a==this){return true}if(this.isInfinity()){return a.isInfinity()}if(a.isInfinity()){return this.isInfinity()}var c,b;c=a.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(a.z)).mod(this.curve.q);if(!c.equals(BigInteger.ZERO)){return false}b=a.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(a.z)).mod(this.curve.q);return b.equals(BigInteger.ZERO)}function pointFpIsInfinity(){if((this.x==null)&&(this.y==null)){return true}return this.z.equals(BigInteger.ZERO)&&!this.y.toBigInteger().equals(BigInteger.ZERO)}function pointFpNegate(){return new ECPointFp(this.curve,this.x,this.y.negate(),this.z)}function pointFpAdd(l){if(this.isInfinity()){return l}if(l.isInfinity()){return this}var p=l.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(l.z)).mod(this.curve.q);var o=l.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(l.z)).mod(this.curve.q);if(BigInteger.ZERO.equals(o)){if(BigInteger.ZERO.equals(p)){return this.twice()}return this.curve.getInfinity()}var j=new BigInteger(\"3\");var e=this.x.toBigInteger();var n=this.y.toBigInteger();var c=l.x.toBigInteger();var k=l.y.toBigInteger();var m=o.square();var i=m.multiply(o);var d=e.multiply(m);var g=p.square().multiply(this.z);var a=g.subtract(d.shiftLeft(1)).multiply(l.z).subtract(i).multiply(o).mod(this.curve.q);var h=d.multiply(j).multiply(p).subtract(n.multiply(i)).subtract(g.multiply(p)).multiply(l.z).add(p.multiply(i)).mod(this.curve.q);var f=i.multiply(this.z).multiply(l.z).mod(this.curve.q);return new ECPointFp(this.curve,this.curve.fromBigInteger(a),this.curve.fromBigInteger(h),f)}function pointFpTwice(){if(this.isInfinity()){return this}if(this.y.toBigInteger().signum()==0){return this.curve.getInfinity()}var g=new BigInteger(\"3\");var c=this.x.toBigInteger();var h=this.y.toBigInteger();var e=h.multiply(this.z);var j=e.multiply(h).mod(this.curve.q);var i=this.curve.a.toBigInteger();var k=c.square().multiply(g);if(!BigInteger.ZERO.equals(i)){k=k.add(this.z.square().multiply(i))}k=k.mod(this.curve.q);var b=k.square().subtract(c.shiftLeft(3).multiply(j)).shiftLeft(1).multiply(e).mod(this.curve.q);var f=k.multiply(g).multiply(c).subtract(j.shiftLeft(1)).shiftLeft(2).multiply(j).subtract(k.square().multiply(k)).mod(this.curve.q);var d=e.square().multiply(e).shiftLeft(3).mod(this.curve.q);return new ECPointFp(this.curve,this.curve.fromBigInteger(b),this.curve.fromBigInteger(f),d)}function pointFpMultiply(b){if(this.isInfinity()){return this}if(b.signum()==0){return this.curve.getInfinity()}var g=b;var f=g.multiply(new BigInteger(\"3\"));var l=this.negate();var d=this;var c;for(c=f.bitLength()-2;c>0;--c){d=d.twice();var a=f.testBit(c);var j=g.testBit(c);if(a!=j){d=d.add(a?this:l)}}return d}function pointFpMultiplyTwo(c,a,b){var d;if(c.bitLength()>b.bitLength()){d=c.bitLength()-1}else{d=b.bitLength()-1}var f=this.curve.getInfinity();var e=this.add(a);while(d>=0){f=f.twice();if(c.testBit(d)){if(b.testBit(d)){f=f.add(e)}else{f=f.add(this)}}else{if(b.testBit(d)){f=f.add(a)}}--d}return f}ECPointFp.prototype.getX=pointFpGetX;ECPointFp.prototype.getY=pointFpGetY;ECPointFp.prototype.equals=pointFpEquals;ECPointFp.prototype.isInfinity=pointFpIsInfinity;ECPointFp.prototype.negate=pointFpNegate;ECPointFp.prototype.add=pointFpAdd;ECPointFp.prototype.twice=pointFpTwice;ECPointFp.prototype.multiply=pointFpMultiply;ECPointFp.prototype.multiplyTwo=pointFpMultiplyTwo;function ECCurveFp(e,d,c){this.q=e;this.a=this.fromBigInteger(d);this.b=this.fromBigInteger(c);this.infinity=new ECPointFp(this,null,null)}function curveFpGetQ(){return this.q}function curveFpGetA(){return this.a}function curveFpGetB(){return this.b}function curveFpEquals(a){if(a==this){return true}return(this.q.equals(a.q)&&this.a.equals(a.a)&&this.b.equals(a.b))}function curveFpGetInfinity(){return this.infinity}function curveFpFromBigInteger(a){return new ECFieldElementFp(this.q,a)}function curveFpDecodePointHex(d){switch(parseInt(d.substr(0,2),16)){case 0:return this.infinity;case 2:case 3:return null;case 4:case 6:case 7:var a=(d.length-2)/2;var c=d.substr(2,a);var b=d.substr(a+2,a);return new ECPointFp(this,this.fromBigInteger(new BigInteger(c,16)),this.fromBigInteger(new BigInteger(b,16)));default:return null}}ECCurveFp.prototype.getQ=curveFpGetQ;ECCurveFp.prototype.getA=curveFpGetA;ECCurveFp.prototype.getB=curveFpGetB;ECCurveFp.prototype.equals=curveFpEquals;ECCurveFp.prototype.getInfinity=curveFpGetInfinity;ECCurveFp.prototype.fromBigInteger=curveFpFromBigInteger;ECCurveFp.prototype.decodePointHex=curveFpDecodePointHex;\n/*! (c) Stefan Thomas | https://github.com/bitcoinjs/bitcoinjs-lib\r\n */\r\nECFieldElementFp.prototype.getByteLength=function(){return Math.floor((this.toBigInteger().bitLength()+7)/8)};ECPointFp.prototype.getEncoded=function(c){var d=function(h,f){var g=h.toByteArrayUnsigned();if(f<g.length){g=g.slice(g.length-f)}else{while(f>g.length){g.unshift(0)}}return g};var a=this.getX().toBigInteger();var e=this.getY().toBigInteger();var b=d(a,32);if(c){if(e.isEven()){b.unshift(2)}else{b.unshift(3)}}else{b.unshift(4);b=b.concat(d(e,32))}return b};ECPointFp.decodeFrom=function(g,c){var f=c[0];var e=c.length-1;var d=c.slice(1,1+e/2);var b=c.slice(1+e/2,1+e);d.unshift(0);b.unshift(0);var a=new BigInteger(d);var h=new BigInteger(b);return new ECPointFp(g,g.fromBigInteger(a),g.fromBigInteger(h))};ECPointFp.decodeFromHex=function(g,c){var f=c.substr(0,2);var e=c.length-2;var d=c.substr(2,e/2);var b=c.substr(2+e/2,e/2);var a=new BigInteger(d,16);var h=new BigInteger(b,16);return new ECPointFp(g,g.fromBigInteger(a),g.fromBigInteger(h))};ECPointFp.prototype.add2D=function(c){if(this.isInfinity()){return c}if(c.isInfinity()){return this}if(this.x.equals(c.x)){if(this.y.equals(c.y)){return this.twice()}return this.curve.getInfinity()}var g=c.x.subtract(this.x);var e=c.y.subtract(this.y);var a=e.divide(g);var d=a.square().subtract(this.x).subtract(c.x);var f=a.multiply(this.x.subtract(d)).subtract(this.y);return new ECPointFp(this.curve,d,f)};ECPointFp.prototype.twice2D=function(){if(this.isInfinity()){return this}if(this.y.toBigInteger().signum()==0){return this.curve.getInfinity()}var b=this.curve.fromBigInteger(BigInteger.valueOf(2));var e=this.curve.fromBigInteger(BigInteger.valueOf(3));var a=this.x.square().multiply(e).add(this.curve.a).divide(this.y.multiply(b));var c=a.square().subtract(this.x.multiply(b));var d=a.multiply(this.x.subtract(c)).subtract(this.y);return new ECPointFp(this.curve,c,d)};ECPointFp.prototype.multiply2D=function(b){if(this.isInfinity()){return this}if(b.signum()==0){return this.curve.getInfinity()}var g=b;var f=g.multiply(new BigInteger(\"3\"));var l=this.negate();var d=this;var c;for(c=f.bitLength()-2;c>0;--c){d=d.twice();var a=f.testBit(c);var j=g.testBit(c);if(a!=j){d=d.add2D(a?this:l)}}return d};ECPointFp.prototype.isOnCurve=function(){var d=this.getX().toBigInteger();var i=this.getY().toBigInteger();var f=this.curve.getA().toBigInteger();var c=this.curve.getB().toBigInteger();var h=this.curve.getQ();var e=i.multiply(i).mod(h);var g=d.multiply(d).multiply(d).add(f.multiply(d)).add(c).mod(h);return e.equals(g)};ECPointFp.prototype.toString=function(){return\"(\"+this.getX().toBigInteger().toString()+\",\"+this.getY().toBigInteger().toString()+\")\"};ECPointFp.prototype.validate=function(){var c=this.curve.getQ();if(this.isInfinity()){throw new Error(\"Point is at infinity.\")}var a=this.getX().toBigInteger();var b=this.getY().toBigInteger();if(a.compareTo(BigInteger.ONE)<0||a.compareTo(c.subtract(BigInteger.ONE))>0){throw new Error(\"x coordinate out of bounds\")}if(b.compareTo(BigInteger.ONE)<0||b.compareTo(c.subtract(BigInteger.ONE))>0){throw new Error(\"y coordinate out of bounds\")}if(!this.isOnCurve()){throw new Error(\"Point is not on the curve.\")}if(this.multiply(c).isInfinity()){throw new Error(\"Point is not a scalar multiple of G.\")}return true};\n/*! Mike Samuel (c) 2009 | code.google.com/p/json-sans-eval\r\n */\r\nvar jsonParse=(function(){var e=\"(?:-?\\\\b(?:0|[1-9][0-9]*)(?:\\\\.[0-9]+)?(?:[eE][+-]?[0-9]+)?\\\\b)\";var j='(?:[^\\\\0-\\\\x08\\\\x0a-\\\\x1f\"\\\\\\\\]|\\\\\\\\(?:[\"/\\\\\\\\bfnrt]|u[0-9A-Fa-f]{4}))';var i='(?:\"'+j+'*\")';var d=new RegExp(\"(?:false|true|null|[\\\\{\\\\}\\\\[\\\\]]|\"+e+\"|\"+i+\")\",\"g\");var k=new RegExp(\"\\\\\\\\(?:([^u])|u(.{4}))\",\"g\");var g={'\"':'\"',\"/\":\"/\",\"\\\\\":\"\\\\\",b:\"\\b\",f:\"\\f\",n:\"\\n\",r:\"\\r\",t:\"\\t\"};function h(l,m,n){return m?g[m]:String.fromCharCode(parseInt(n,16))}var c=new String(\"\");var a=\"\\\\\";var f={\"{\":Object,\"[\":Array};var b=Object.hasOwnProperty;return function(u,q){var p=u.match(d);var x;var v=p[0];var l=false;if(\"{\"===v){x={}}else{if(\"[\"===v){x=[]}else{x=[];l=true}}var t;var r=[x];for(var o=1-l,m=p.length;o<m;++o){v=p[o];var w;switch(v.charCodeAt(0)){default:w=r[0];w[t||w.length]=+(v);t=void 0;break;case 34:v=v.substring(1,v.length-1);if(v.indexOf(a)!==-1){v=v.replace(k,h)}w=r[0];if(!t){if(w instanceof Array){t=w.length}else{t=v||c;break}}w[t]=v;t=void 0;break;case 91:w=r[0];r.unshift(w[t||w.length]=[]);t=void 0;break;case 93:r.shift();break;case 102:w=r[0];w[t||w.length]=false;t=void 0;break;case 110:w=r[0];w[t||w.length]=null;t=void 0;break;case 116:w=r[0];w[t||w.length]=true;t=void 0;break;case 123:w=r[0];r.unshift(w[t||w.length]={});t=void 0;break;case 125:r.shift();break}}if(l){if(r.length!==1){throw new Error()}x=x[0]}else{if(r.length){throw new Error()}}if(q){var s=function(C,B){var D=C[B];if(D&&typeof D===\"object\"){var n=null;for(var z in D){if(b.call(D,z)&&D!==C){var y=s(D,z);if(y!==void 0){D[z]=y}else{if(!n){n=[]}n.push(z)}}}if(n){for(var A=n.length;--A>=0;){delete D[n[A]]}}}return q.call(C,B,D)};x=s({\"\":x},\"\")}return x}})();\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.asn1==\"undefined\"||!KJUR.asn1){KJUR.asn1={}}KJUR.asn1.ASN1Util=new function(){this.integerToByteHex=function(a){var b=a.toString(16);if((b.length%2)==1){b=\"0\"+b}return b};this.bigIntToMinTwosComplementsHex=function(j){var f=j.toString(16);if(f.substr(0,1)!=\"-\"){if(f.length%2==1){f=\"0\"+f}else{if(!f.match(/^[0-7]/)){f=\"00\"+f}}}else{var a=f.substr(1);var e=a.length;if(e%2==1){e+=1}else{if(!f.match(/^[0-7]/)){e+=2}}var g=\"\";for(var d=0;d<e;d++){g+=\"f\"}var c=new BigInteger(g,16);var b=c.xor(j).add(BigInteger.ONE);f=b.toString(16).replace(/^-/,\"\")}return f};this.getPEMStringFromHex=function(a,b){return hextopem(a,b)};this.newObject=function(k){var D=KJUR,n=D.asn1,z=n.DERBoolean,e=n.DERInteger,s=n.DERBitString,h=n.DEROctetString,v=n.DERNull,w=n.DERObjectIdentifier,l=n.DEREnumerated,g=n.DERUTF8String,f=n.DERNumericString,y=n.DERPrintableString,u=n.DERTeletexString,p=n.DERIA5String,C=n.DERUTCTime,j=n.DERGeneralizedTime,m=n.DERSequence,c=n.DERSet,r=n.DERTaggedObject,o=n.ASN1Util.newObject;var t=Object.keys(k);if(t.length!=1){throw\"key of param shall be only one.\"}var F=t[0];if(\":bool:int:bitstr:octstr:null:oid:enum:utf8str:numstr:prnstr:telstr:ia5str:utctime:gentime:seq:set:tag:\".indexOf(\":\"+F+\":\")==-1){throw\"undefined key: \"+F}if(F==\"bool\"){return new z(k[F])}if(F==\"int\"){return new e(k[F])}if(F==\"bitstr\"){return new s(k[F])}if(F==\"octstr\"){return new h(k[F])}if(F==\"null\"){return new v(k[F])}if(F==\"oid\"){return new w(k[F])}if(F==\"enum\"){return new l(k[F])}if(F==\"utf8str\"){return new g(k[F])}if(F==\"numstr\"){return new f(k[F])}if(F==\"prnstr\"){return new y(k[F])}if(F==\"telstr\"){return new u(k[F])}if(F==\"ia5str\"){return new p(k[F])}if(F==\"utctime\"){return new C(k[F])}if(F==\"gentime\"){return new j(k[F])}if(F==\"seq\"){var d=k[F];var E=[];for(var x=0;x<d.length;x++){var B=o(d[x]);E.push(B)}return new m({array:E})}if(F==\"set\"){var d=k[F];var E=[];for(var x=0;x<d.length;x++){var B=o(d[x]);E.push(B)}return new c({array:E})}if(F==\"tag\"){var A=k[F];if(Object.prototype.toString.call(A)===\"[object Array]\"&&A.length==3){var q=o(A[2]);return new r({tag:A[0],explicit:A[1],obj:q})}else{var b={};if(A.explicit!==undefined){b.explicit=A.explicit}if(A.tag!==undefined){b.tag=A.tag}if(A.obj===undefined){throw\"obj shall be specified for 'tag'.\"}b.obj=o(A.obj);return new r(b)}}};this.jsonToASN1HEX=function(b){var a=this.newObject(b);return a.getEncodedHex()}};KJUR.asn1.ASN1Util.oidHexToInt=function(a){var j=\"\";var k=parseInt(a.substr(0,2),16);var d=Math.floor(k/40);var c=k%40;var j=d+\".\"+c;var e=\"\";for(var f=2;f<a.length;f+=2){var g=parseInt(a.substr(f,2),16);var h=(\"00000000\"+g.toString(2)).slice(-8);e=e+h.substr(1,7);if(h.substr(0,1)==\"0\"){var b=new BigInteger(e,2);j=j+\".\"+b.toString(10);e=\"\"}}return j};KJUR.asn1.ASN1Util.oidIntToHex=function(f){var e=function(a){var k=a.toString(16);if(k.length==1){k=\"0\"+k}return k};var d=function(o){var n=\"\";var k=new BigInteger(o,10);var a=k.toString(2);var l=7-a.length%7;if(l==7){l=0}var q=\"\";for(var m=0;m<l;m++){q+=\"0\"}a=q+a;for(var m=0;m<a.length-1;m+=7){var p=a.substr(m,7);if(m!=a.length-7){p=\"1\"+p}n+=e(parseInt(p,2))}return n};if(!f.match(/^[0-9.]+$/)){throw\"malformed oid string: \"+f}var g=\"\";var b=f.split(\".\");var j=parseInt(b[0])*40+parseInt(b[1]);g+=e(j);b.splice(0,2);for(var c=0;c<b.length;c++){g+=d(b[c])}return g};KJUR.asn1.ASN1Object=function(){var c=true;var b=null;var d=\"00\";var e=\"00\";var a=\"\";this.getLengthHexFromValue=function(){if(typeof this.hV==\"undefined\"||this.hV==null){throw\"this.hV is null or undefined.\"}if(this.hV.length%2==1){throw\"value hex must be even length: n=\"+a.length+\",v=\"+this.hV}var i=this.hV.length/2;var h=i.toString(16);if(h.length%2==1){h=\"0\"+h}if(i<128){return h}else{var g=h.length/2;if(g>15){throw\"ASN.1 length too long to represent by 8x: n = \"+i.toString(16)}var f=128+g;return f.toString(16)+h}};this.getEncodedHex=function(){if(this.hTLV==null||this.isModified){this.hV=this.getFreshValueHex();this.hL=this.getLengthHexFromValue();this.hTLV=this.hT+this.hL+this.hV;this.isModified=false}return this.hTLV};this.getValueHex=function(){this.getEncodedHex();return this.hV};this.getFreshValueHex=function(){return\"\"}};KJUR.asn1.DERAbstractString=function(c){KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var b=null;var a=null;this.getString=function(){return this.s};this.setString=function(d){this.hTLV=null;this.isModified=true;this.s=d;this.hV=utf8tohex(this.s).toLowerCase()};this.setStringHex=function(d){this.hTLV=null;this.isModified=true;this.s=null;this.hV=d};this.getFreshValueHex=function(){return this.hV};if(typeof c!=\"undefined\"){if(typeof c==\"string\"){this.setString(c)}else{if(typeof c.str!=\"undefined\"){this.setString(c.str)}else{if(typeof c.hex!=\"undefined\"){this.setStringHex(c.hex)}}}}};YAHOO.lang.extend(KJUR.asn1.DERAbstractString,KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractTime=function(c){KJUR.asn1.DERAbstractTime.superclass.constructor.call(this);var b=null;var a=null;this.localDateToUTC=function(f){utc=f.getTime()+(f.getTimezoneOffset()*60000);var e=new Date(utc);return e};this.formatDate=function(m,o,e){var g=this.zeroPadding;var n=this.localDateToUTC(m);var p=String(n.getFullYear());if(o==\"utc\"){p=p.substr(2,2)}var l=g(String(n.getMonth()+1),2);var q=g(String(n.getDate()),2);var h=g(String(n.getHours()),2);var i=g(String(n.getMinutes()),2);var j=g(String(n.getSeconds()),2);var r=p+l+q+h+i+j;if(e===true){var f=n.getMilliseconds();if(f!=0){var k=g(String(f),3);k=k.replace(/[0]+$/,\"\");r=r+\".\"+k}}return r+\"Z\"};this.zeroPadding=function(e,d){if(e.length>=d){return e}return new Array(d-e.length+1).join(\"0\")+e};this.getString=function(){return this.s};this.setString=function(d){this.hTLV=null;this.isModified=true;this.s=d;this.hV=stohex(d)};this.setByDateValue=function(h,j,e,d,f,g){var i=new Date(Date.UTC(h,j-1,e,d,f,g,0));this.setByDate(i)};this.getFreshValueHex=function(){return this.hV}};YAHOO.lang.extend(KJUR.asn1.DERAbstractTime,KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractStructured=function(b){KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var a=null;this.setByASN1ObjectArray=function(c){this.hTLV=null;this.isModified=true;this.asn1Array=c};this.appendASN1Object=function(c){this.hTLV=null;this.isModified=true;this.asn1Array.push(c)};this.asn1Array=new Array();if(typeof b!=\"undefined\"){if(typeof b.array!=\"undefined\"){this.asn1Array=b.array}}};YAHOO.lang.extend(KJUR.asn1.DERAbstractStructured,KJUR.asn1.ASN1Object);KJUR.asn1.DERBoolean=function(){KJUR.asn1.DERBoolean.superclass.constructor.call(this);this.hT=\"01\";this.hTLV=\"0101ff\"};YAHOO.lang.extend(KJUR.asn1.DERBoolean,KJUR.asn1.ASN1Object);KJUR.asn1.DERInteger=function(a){KJUR.asn1.DERInteger.superclass.constructor.call(this);this.hT=\"02\";this.setByBigInteger=function(b){this.hTLV=null;this.isModified=true;this.hV=KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b)};this.setByInteger=function(c){var b=new BigInteger(String(c),10);this.setByBigInteger(b)};this.setValueHex=function(b){this.hV=b};this.getFreshValueHex=function(){return this.hV};if(typeof a!=\"undefined\"){if(typeof a.bigint!=\"undefined\"){this.setByBigInteger(a.bigint)}else{if(typeof a[\"int\"]!=\"undefined\"){this.setByInteger(a[\"int\"])}else{if(typeof a==\"number\"){this.setByInteger(a)}else{if(typeof a.hex!=\"undefined\"){this.setValueHex(a.hex)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERInteger,KJUR.asn1.ASN1Object);KJUR.asn1.DERBitString=function(b){if(b!==undefined&&typeof b.obj!==\"undefined\"){var a=KJUR.asn1.ASN1Util.newObject(b.obj);b.hex=\"00\"+a.getEncodedHex()}KJUR.asn1.DERBitString.superclass.constructor.call(this);this.hT=\"03\";this.setHexValueIncludingUnusedBits=function(c){this.hTLV=null;this.isModified=true;this.hV=c};this.setUnusedBitsAndHexValue=function(c,e){if(c<0||7<c){throw\"unused bits shall be from 0 to 7: u = \"+c}var d=\"0\"+c;this.hTLV=null;this.isModified=true;this.hV=d+e};this.setByBinaryString=function(e){e=e.replace(/0+$/,\"\");var f=8-e.length%8;if(f==8){f=0}for(var g=0;g<=f;g++){e+=\"0\"}var j=\"\";for(var g=0;g<e.length-1;g+=8){var d=e.substr(g,8);var c=parseInt(d,2).toString(16);if(c.length==1){c=\"0\"+c}j+=c}this.hTLV=null;this.isModified=true;this.hV=\"0\"+f+j};this.setByBooleanArray=function(e){var d=\"\";for(var c=0;c<e.length;c++){if(e[c]==true){d+=\"1\"}else{d+=\"0\"}}this.setByBinaryString(d)};this.newFalseArray=function(e){var c=new Array(e);for(var d=0;d<e;d++){c[d]=false}return c};this.getFreshValueHex=function(){return this.hV};if(typeof b!=\"undefined\"){if(typeof b==\"string\"&&b.toLowerCase().match(/^[0-9a-f]+$/)){this.setHexValueIncludingUnusedBits(b)}else{if(typeof b.hex!=\"undefined\"){this.setHexValueIncludingUnusedBits(b.hex)}else{if(typeof b.bin!=\"undefined\"){this.setByBinaryString(b.bin)}else{if(typeof b.array!=\"undefined\"){this.setByBooleanArray(b.array)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERBitString,KJUR.asn1.ASN1Object);KJUR.asn1.DEROctetString=function(b){if(b!==undefined&&typeof b.obj!==\"undefined\"){var a=KJUR.asn1.ASN1Util.newObject(b.obj);b.hex=a.getEncodedHex()}KJUR.asn1.DEROctetString.superclass.constructor.call(this,b);this.hT=\"04\"};YAHOO.lang.extend(KJUR.asn1.DEROctetString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERNull=function(){KJUR.asn1.DERNull.superclass.constructor.call(this);this.hT=\"05\";this.hTLV=\"0500\"};YAHOO.lang.extend(KJUR.asn1.DERNull,KJUR.asn1.ASN1Object);KJUR.asn1.DERObjectIdentifier=function(c){var b=function(d){var e=d.toString(16);if(e.length==1){e=\"0\"+e}return e};var a=function(k){var j=\"\";var e=new BigInteger(k,10);var d=e.toString(2);var f=7-d.length%7;if(f==7){f=0}var m=\"\";for(var g=0;g<f;g++){m+=\"0\"}d=m+d;for(var g=0;g<d.length-1;g+=7){var l=d.substr(g,7);if(g!=d.length-7){l=\"1\"+l}j+=b(parseInt(l,2))}return j};KJUR.asn1.DERObjectIdentifier.superclass.constructor.call(this);this.hT=\"06\";this.setValueHex=function(d){this.hTLV=null;this.isModified=true;this.s=null;this.hV=d};this.setValueOidString=function(f){if(!f.match(/^[0-9.]+$/)){throw\"malformed oid string: \"+f}var g=\"\";var d=f.split(\".\");var j=parseInt(d[0])*40+parseInt(d[1]);g+=b(j);d.splice(0,2);for(var e=0;e<d.length;e++){g+=a(d[e])}this.hTLV=null;this.isModified=true;this.s=null;this.hV=g};this.setValueName=function(e){var d=KJUR.asn1.x509.OID.name2oid(e);if(d!==\"\"){this.setValueOidString(d)}else{throw\"DERObjectIdentifier oidName undefined: \"+e}};this.getFreshValueHex=function(){return this.hV};if(c!==undefined){if(typeof c===\"string\"){if(c.match(/^[0-2].[0-9.]+$/)){this.setValueOidString(c)}else{this.setValueName(c)}}else{if(c.oid!==undefined){this.setValueOidString(c.oid)}else{if(c.hex!==undefined){this.setValueHex(c.hex)}else{if(c.name!==undefined){this.setValueName(c.name)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERObjectIdentifier,KJUR.asn1.ASN1Object);KJUR.asn1.DEREnumerated=function(a){KJUR.asn1.DEREnumerated.superclass.constructor.call(this);this.hT=\"0a\";this.setByBigInteger=function(b){this.hTLV=null;this.isModified=true;this.hV=KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b)};this.setByInteger=function(c){var b=new BigInteger(String(c),10);this.setByBigInteger(b)};this.setValueHex=function(b){this.hV=b};this.getFreshValueHex=function(){return this.hV};if(typeof a!=\"undefined\"){if(typeof a[\"int\"]!=\"undefined\"){this.setByInteger(a[\"int\"])}else{if(typeof a==\"number\"){this.setByInteger(a)}else{if(typeof a.hex!=\"undefined\"){this.setValueHex(a.hex)}}}}};YAHOO.lang.extend(KJUR.asn1.DEREnumerated,KJUR.asn1.ASN1Object);KJUR.asn1.DERUTF8String=function(a){KJUR.asn1.DERUTF8String.superclass.constructor.call(this,a);this.hT=\"0c\"};YAHOO.lang.extend(KJUR.asn1.DERUTF8String,KJUR.asn1.DERAbstractString);KJUR.asn1.DERNumericString=function(a){KJUR.asn1.DERNumericString.superclass.constructor.call(this,a);this.hT=\"12\"};YAHOO.lang.extend(KJUR.asn1.DERNumericString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERPrintableString=function(a){KJUR.asn1.DERPrintableString.superclass.constructor.call(this,a);this.hT=\"13\"};YAHOO.lang.extend(KJUR.asn1.DERPrintableString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERTeletexString=function(a){KJUR.asn1.DERTeletexString.superclass.constructor.call(this,a);this.hT=\"14\"};YAHOO.lang.extend(KJUR.asn1.DERTeletexString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERIA5String=function(a){KJUR.asn1.DERIA5String.superclass.constructor.call(this,a);this.hT=\"16\"};YAHOO.lang.extend(KJUR.asn1.DERIA5String,KJUR.asn1.DERAbstractString);KJUR.asn1.DERUTCTime=function(a){KJUR.asn1.DERUTCTime.superclass.constructor.call(this,a);this.hT=\"17\";this.setByDate=function(b){this.hTLV=null;this.isModified=true;this.date=b;this.s=this.formatDate(this.date,\"utc\");this.hV=stohex(this.s)};this.getFreshValueHex=function(){if(typeof this.date==\"undefined\"&&typeof this.s==\"undefined\"){this.date=new Date();this.s=this.formatDate(this.date,\"utc\");this.hV=stohex(this.s)}return this.hV};if(a!==undefined){if(a.str!==undefined){this.setString(a.str)}else{if(typeof a==\"string\"&&a.match(/^[0-9]{12}Z$/)){this.setString(a)}else{if(a.hex!==undefined){this.setStringHex(a.hex)}else{if(a.date!==undefined){this.setByDate(a.date)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERUTCTime,KJUR.asn1.DERAbstractTime);KJUR.asn1.DERGeneralizedTime=function(a){KJUR.asn1.DERGeneralizedTime.superclass.constructor.call(this,a);this.hT=\"18\";this.withMillis=false;this.setByDate=function(b){this.hTLV=null;this.isModified=true;this.date=b;this.s=this.formatDate(this.date,\"gen\",this.withMillis);this.hV=stohex(this.s)};this.getFreshValueHex=function(){if(this.date===undefined&&this.s===undefined){this.date=new Date();this.s=this.formatDate(this.date,\"gen\",this.withMillis);this.hV=stohex(this.s)}return this.hV};if(a!==undefined){if(a.str!==undefined){this.setString(a.str)}else{if(typeof a==\"string\"&&a.match(/^[0-9]{14}Z$/)){this.setString(a)}else{if(a.hex!==undefined){this.setStringHex(a.hex)}else{if(a.date!==undefined){this.setByDate(a.date)}}}}if(a.millis===true){this.withMillis=true}}};YAHOO.lang.extend(KJUR.asn1.DERGeneralizedTime,KJUR.asn1.DERAbstractTime);KJUR.asn1.DERSequence=function(a){KJUR.asn1.DERSequence.superclass.constructor.call(this,a);this.hT=\"30\";this.getFreshValueHex=function(){var c=\"\";for(var b=0;b<this.asn1Array.length;b++){var d=this.asn1Array[b];c+=d.getEncodedHex()}this.hV=c;return this.hV}};YAHOO.lang.extend(KJUR.asn1.DERSequence,KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERSet=function(a){KJUR.asn1.DERSet.superclass.constructor.call(this,a);this.hT=\"31\";this.sortFlag=true;this.getFreshValueHex=function(){var b=new Array();for(var c=0;c<this.asn1Array.length;c++){var d=this.asn1Array[c];b.push(d.getEncodedHex())}if(this.sortFlag==true){b.sort()}this.hV=b.join(\"\");return this.hV};if(typeof a!=\"undefined\"){if(typeof a.sortflag!=\"undefined\"&&a.sortflag==false){this.sortFlag=false}}};YAHOO.lang.extend(KJUR.asn1.DERSet,KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERTaggedObject=function(a){KJUR.asn1.DERTaggedObject.superclass.constructor.call(this);this.hT=\"a0\";this.hV=\"\";this.isExplicit=true;this.asn1Object=null;this.setASN1Object=function(b,c,d){this.hT=c;this.isExplicit=b;this.asn1Object=d;if(this.isExplicit){this.hV=this.asn1Object.getEncodedHex();this.hTLV=null;this.isModified=true}else{this.hV=null;this.hTLV=d.getEncodedHex();this.hTLV=this.hTLV.replace(/^../,c);this.isModified=false}};this.getFreshValueHex=function(){return this.hV};if(typeof a!=\"undefined\"){if(typeof a.tag!=\"undefined\"){this.hT=a.tag}if(typeof a.explicit!=\"undefined\"){this.isExplicit=a.explicit}if(typeof a.obj!=\"undefined\"){this.asn1Object=a.obj;this.setASN1Object(this.isExplicit,this.hT,this.asn1Object)}}};YAHOO.lang.extend(KJUR.asn1.DERTaggedObject,KJUR.asn1.ASN1Object);\nvar ASN1HEX=new function(){};ASN1HEX.getLblen=function(c,a){if(c.substr(a+2,1)!=\"8\"){return 1}var b=parseInt(c.substr(a+3,1));if(b==0){return -1}if(0<b&&b<10){return b+1}return -2};ASN1HEX.getL=function(c,b){var a=ASN1HEX.getLblen(c,b);if(a<1){return\"\"}return c.substr(b+2,a*2)};ASN1HEX.getVblen=function(d,a){var c,b;c=ASN1HEX.getL(d,a);if(c==\"\"){return -1}if(c.substr(0,1)===\"8\"){b=new BigInteger(c.substr(2),16)}else{b=new BigInteger(c,16)}return b.intValue()};ASN1HEX.getVidx=function(c,b){var a=ASN1HEX.getLblen(c,b);if(a<0){return a}return b+(a+1)*2};ASN1HEX.getV=function(d,a){var c=ASN1HEX.getVidx(d,a);var b=ASN1HEX.getVblen(d,a);return d.substr(c,b*2)};ASN1HEX.getTLV=function(b,a){return b.substr(a,2)+ASN1HEX.getL(b,a)+ASN1HEX.getV(b,a)};ASN1HEX.getNextSiblingIdx=function(d,a){var c=ASN1HEX.getVidx(d,a);var b=ASN1HEX.getVblen(d,a);return c+b*2};ASN1HEX.getChildIdx=function(e,f){var j=ASN1HEX;var g=new Array();var i=j.getVidx(e,f);if(e.substr(f,2)==\"03\"){g.push(i+2)}else{g.push(i)}var l=j.getVblen(e,f);var c=i;var d=0;while(1){var b=j.getNextSiblingIdx(e,c);if(b==null||(b-i>=(l*2))){break}if(d>=200){break}g.push(b);c=b;d++}return g};ASN1HEX.getNthChildIdx=function(d,b,e){var c=ASN1HEX.getChildIdx(d,b);return c[e]};ASN1HEX.getIdxbyList=function(e,d,c,i){var g=ASN1HEX;var f,b;if(c.length==0){if(i!==undefined){if(e.substr(d,2)!==i){throw\"checking tag doesn't match: \"+e.substr(d,2)+\"!=\"+i}}return d}f=c.shift();b=g.getChildIdx(e,d);return g.getIdxbyList(e,b[f],c,i)};ASN1HEX.getTLVbyList=function(d,c,b,f){var e=ASN1HEX;var a=e.getIdxbyList(d,c,b);if(a===undefined){throw\"can't find nthList object\"}if(f!==undefined){if(d.substr(a,2)!=f){throw\"checking tag doesn't match: \"+d.substr(a,2)+\"!=\"+f}}return e.getTLV(d,a)};ASN1HEX.getVbyList=function(e,c,b,g,i){var f=ASN1HEX;var a,d;a=f.getIdxbyList(e,c,b,g);if(a===undefined){throw\"can't find nthList object\"}d=f.getV(e,a);if(i===true){d=d.substr(2)}return d};ASN1HEX.hextooidstr=function(e){var h=function(b,a){if(b.length>=a){return b}return new Array(a-b.length+1).join(\"0\")+b};var l=[];var o=e.substr(0,2);var f=parseInt(o,16);l[0]=new String(Math.floor(f/40));l[1]=new String(f%40);var m=e.substr(2);var k=[];for(var g=0;g<m.length/2;g++){k.push(parseInt(m.substr(g*2,2),16))}var j=[];var d=\"\";for(var g=0;g<k.length;g++){if(k[g]&128){d=d+h((k[g]&127).toString(2),7)}else{d=d+h((k[g]&127).toString(2),7);j.push(new String(parseInt(d,2)));d=\"\"}}var n=l.join(\".\");if(j.length>0){n=n+\".\"+j.join(\".\")}return n};ASN1HEX.dump=function(t,c,l,g){var p=ASN1HEX;var j=p.getV;var y=p.dump;var w=p.getChildIdx;var e=t;if(t instanceof KJUR.asn1.ASN1Object){e=t.getEncodedHex()}var q=function(A,i){if(A.length<=i*2){return A}else{var v=A.substr(0,i)+\"..(total \"+A.length/2+\"bytes)..\"+A.substr(A.length-i,i);return v}};if(c===undefined){c={ommit_long_octet:32}}if(l===undefined){l=0}if(g===undefined){g=\"\"}var x=c.ommit_long_octet;if(e.substr(l,2)==\"01\"){var h=j(e,l);if(h==\"00\"){return g+\"BOOLEAN FALSE\\n\"}else{return g+\"BOOLEAN TRUE\\n\"}}if(e.substr(l,2)==\"02\"){var h=j(e,l);return g+\"INTEGER \"+q(h,x)+\"\\n\"}if(e.substr(l,2)==\"03\"){var h=j(e,l);return g+\"BITSTRING \"+q(h,x)+\"\\n\"}if(e.substr(l,2)==\"04\"){var h=j(e,l);if(p.isASN1HEX(h)){var k=g+\"OCTETSTRING, encapsulates\\n\";k=k+y(h,c,0,g+\"  \");return k}else{return g+\"OCTETSTRING \"+q(h,x)+\"\\n\"}}if(e.substr(l,2)==\"05\"){return g+\"NULL\\n\"}if(e.substr(l,2)==\"06\"){var m=j(e,l);var a=KJUR.asn1.ASN1Util.oidHexToInt(m);var o=KJUR.asn1.x509.OID.oid2name(a);var b=a.replace(/\\./g,\" \");if(o!=\"\"){return g+\"ObjectIdentifier \"+o+\" (\"+b+\")\\n\"}else{return g+\"ObjectIdentifier (\"+b+\")\\n\"}}if(e.substr(l,2)==\"0c\"){return g+\"UTF8String '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"13\"){return g+\"PrintableString '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"14\"){return g+\"TeletexString '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"16\"){return g+\"IA5String '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"17\"){return g+\"UTCTime \"+hextoutf8(j(e,l))+\"\\n\"}if(e.substr(l,2)==\"18\"){return g+\"GeneralizedTime \"+hextoutf8(j(e,l))+\"\\n\"}if(e.substr(l,2)==\"30\"){if(e.substr(l,4)==\"3000\"){return g+\"SEQUENCE {}\\n\"}var k=g+\"SEQUENCE\\n\";var d=w(e,l);var f=c;if((d.length==2||d.length==3)&&e.substr(d[0],2)==\"06\"&&e.substr(d[d.length-1],2)==\"04\"){var o=p.oidname(j(e,d[0]));var r=JSON.parse(JSON.stringify(c));r.x509ExtName=o;f=r}for(var u=0;u<d.length;u++){k=k+y(e,f,d[u],g+\"  \")}return k}if(e.substr(l,2)==\"31\"){var k=g+\"SET\\n\";var d=w(e,l);for(var u=0;u<d.length;u++){k=k+y(e,c,d[u],g+\"  \")}return k}var z=parseInt(e.substr(l,2),16);if((z&128)!=0){var n=z&31;if((z&32)!=0){var k=g+\"[\"+n+\"]\\n\";var d=w(e,l);for(var u=0;u<d.length;u++){k=k+y(e,c,d[u],g+\"  \")}return k}else{var h=j(e,l);if(h.substr(0,8)==\"68747470\"){h=hextoutf8(h)}if(c.x509ExtName===\"subjectAltName\"&&n==2){h=hextoutf8(h)}var k=g+\"[\"+n+\"] \"+h+\"\\n\";return k}}return g+\"UNKNOWN(\"+e.substr(l,2)+\") \"+j(e,l)+\"\\n\"};ASN1HEX.isASN1HEX=function(e){var d=ASN1HEX;if(e.length%2==1){return false}var c=d.getVblen(e,0);var b=e.substr(0,2);var f=d.getL(e,0);var a=e.length-b.length-f.length;if(a==c*2){return true}return false};ASN1HEX.oidname=function(a){var c=KJUR.asn1;if(KJUR.lang.String.isHex(a)){a=c.ASN1Util.oidHexToInt(a)}var b=c.x509.OID.oid2name(a);if(b===\"\"){b=a}return b};\nvar KJUR;if(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.lang==\"undefined\"||!KJUR.lang){KJUR.lang={}}KJUR.lang.String=function(){};function Base64x(){}function stoBA(d){var b=new Array();for(var c=0;c<d.length;c++){b[c]=d.charCodeAt(c)}return b}function BAtos(b){var d=\"\";for(var c=0;c<b.length;c++){d=d+String.fromCharCode(b[c])}return d}function BAtohex(b){var e=\"\";for(var d=0;d<b.length;d++){var c=b[d].toString(16);if(c.length==1){c=\"0\"+c}e=e+c}return e}function stohex(a){return BAtohex(stoBA(a))}function stob64(a){return hex2b64(stohex(a))}function stob64u(a){return b64tob64u(hex2b64(stohex(a)))}function b64utos(a){return BAtos(b64toBA(b64utob64(a)))}function b64tob64u(a){a=a.replace(/\\=/g,\"\");a=a.replace(/\\+/g,\"-\");a=a.replace(/\\//g,\"_\");return a}function b64utob64(a){if(a.length%4==2){a=a+\"==\"}else{if(a.length%4==3){a=a+\"=\"}}a=a.replace(/-/g,\"+\");a=a.replace(/_/g,\"/\");return a}function hextob64u(a){if(a.length%2==1){a=\"0\"+a}return b64tob64u(hex2b64(a))}function b64utohex(a){return b64tohex(b64utob64(a))}var utf8tob64u,b64utoutf8;if(typeof Buffer===\"function\"){utf8tob64u=function(a){return b64tob64u(new Buffer(a,\"utf8\").toString(\"base64\"))};b64utoutf8=function(a){return new Buffer(b64utob64(a),\"base64\").toString(\"utf8\")}}else{utf8tob64u=function(a){return hextob64u(uricmptohex(encodeURIComponentAll(a)))};b64utoutf8=function(a){return decodeURIComponent(hextouricmp(b64utohex(a)))}}function utf8tob64(a){return hex2b64(uricmptohex(encodeURIComponentAll(a)))}function b64toutf8(a){return decodeURIComponent(hextouricmp(b64tohex(a)))}function utf8tohex(a){return uricmptohex(encodeURIComponentAll(a))}function hextoutf8(a){return decodeURIComponent(hextouricmp(a))}function hextorstr(c){var b=\"\";for(var a=0;a<c.length-1;a+=2){b+=String.fromCharCode(parseInt(c.substr(a,2),16))}return b}function rstrtohex(c){var a=\"\";for(var b=0;b<c.length;b++){a+=(\"0\"+c.charCodeAt(b).toString(16)).slice(-2)}return a}function hextob64(a){return hex2b64(a)}function hextob64nl(b){var a=hextob64(b);var c=a.replace(/(.{64})/g,\"$1\\r\\n\");c=c.replace(/\\r\\n$/,\"\");return c}function b64nltohex(b){var a=b.replace(/[^0-9A-Za-z\\/+=]*/g,\"\");var c=b64tohex(a);return c}function hextopem(a,b){var c=hextob64nl(a);return\"-----BEGIN \"+b+\"-----\\r\\n\"+c+\"\\r\\n-----END \"+b+\"-----\\r\\n\"}function pemtohex(a,b){if(a.indexOf(\"-----BEGIN \")==-1){throw\"can't find PEM header: \"+b}if(b!==undefined){a=a.replace(\"-----BEGIN \"+b+\"-----\",\"\");a=a.replace(\"-----END \"+b+\"-----\",\"\")}else{a=a.replace(/-----BEGIN [^-]+-----/,\"\");a=a.replace(/-----END [^-]+-----/,\"\")}return b64nltohex(a)}function hextoArrayBuffer(d){if(d.length%2!=0){throw\"input is not even length\"}if(d.match(/^[0-9A-Fa-f]+$/)==null){throw\"input is not hexadecimal\"}var b=new ArrayBuffer(d.length/2);var a=new DataView(b);for(var c=0;c<d.length/2;c++){a.setUint8(c,parseInt(d.substr(c*2,2),16))}return b}function ArrayBuffertohex(b){var d=\"\";var a=new DataView(b);for(var c=0;c<b.byteLength;c++){d+=(\"00\"+a.getUint8(c).toString(16)).slice(-2)}return d}function zulutomsec(n){var l,j,m,e,f,i,b,k;var a,h,g,c;c=n.match(/^(\\d{2}|\\d{4})(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(|\\.\\d+)Z$/);if(c){a=c[1];l=parseInt(a);if(a.length===2){if(50<=l&&l<100){l=1900+l}else{if(0<=l&&l<50){l=2000+l}}}j=parseInt(c[2])-1;m=parseInt(c[3]);e=parseInt(c[4]);f=parseInt(c[5]);i=parseInt(c[6]);b=0;h=c[7];if(h!==\"\"){g=(h.substr(1)+\"00\").substr(0,3);b=parseInt(g)}return Date.UTC(l,j,m,e,f,i,b)}throw\"unsupported zulu format: \"+n}function zulutosec(a){var b=zulutomsec(a);return ~~(b/1000)}function zulutodate(a){return new Date(zulutomsec(a))}function datetozulu(g,e,f){var b;var a=g.getUTCFullYear();if(e){if(a<1950||2049<a){throw\"not proper year for UTCTime: \"+a}b=(\"\"+a).slice(-2)}else{b=(\"000\"+a).slice(-4)}b+=(\"0\"+(g.getUTCMonth()+1)).slice(-2);b+=(\"0\"+g.getUTCDate()).slice(-2);b+=(\"0\"+g.getUTCHours()).slice(-2);b+=(\"0\"+g.getUTCMinutes()).slice(-2);b+=(\"0\"+g.getUTCSeconds()).slice(-2);if(f){var c=g.getUTCMilliseconds();if(c!==0){c=(\"00\"+c).slice(-3);c=c.replace(/0+$/g,\"\");b+=\".\"+c}}b+=\"Z\";return b}function uricmptohex(a){return a.replace(/%/g,\"\")}function hextouricmp(a){return a.replace(/(..)/g,\"%$1\")}function ipv6tohex(g){var b=\"malformed IPv6 address\";if(!g.match(/^[0-9A-Fa-f:]+$/)){throw b}g=g.toLowerCase();var d=g.split(\":\").length-1;if(d<2){throw b}var e=\":\".repeat(7-d+2);g=g.replace(\"::\",e);var c=g.split(\":\");if(c.length!=8){throw b}for(var f=0;f<8;f++){c[f]=(\"0000\"+c[f]).slice(-4)}return c.join(\"\")}function hextoipv6(e){if(!e.match(/^[0-9A-Fa-f]{32}$/)){throw\"malformed IPv6 address octet\"}e=e.toLowerCase();var b=e.match(/.{1,4}/g);for(var d=0;d<8;d++){b[d]=b[d].replace(/^0+/,\"\");if(b[d]==\"\"){b[d]=\"0\"}}e=\":\"+b.join(\":\")+\":\";var c=e.match(/:(0:){2,}/g);if(c===null){return e.slice(1,-1)}var f=\"\";for(var d=0;d<c.length;d++){if(c[d].length>f.length){f=c[d]}}e=e.replace(f,\"::\");return e.slice(1,-1)}function hextoip(b){var d=\"malformed hex value\";if(!b.match(/^([0-9A-Fa-f][0-9A-Fa-f]){1,}$/)){throw d}if(b.length==8){var c;try{c=parseInt(b.substr(0,2),16)+\".\"+parseInt(b.substr(2,2),16)+\".\"+parseInt(b.substr(4,2),16)+\".\"+parseInt(b.substr(6,2),16);return c}catch(a){throw d}}else{if(b.length==32){return hextoipv6(b)}else{return b}}}function iptohex(f){var j=\"malformed IP address\";f=f.toLowerCase(f);if(f.match(/^[0-9.]+$/)){var b=f.split(\".\");if(b.length!==4){throw j}var g=\"\";try{for(var e=0;e<4;e++){var h=parseInt(b[e]);g+=(\"0\"+h.toString(16)).slice(-2)}return g}catch(c){throw j}}else{if(f.match(/^[0-9a-f:]+$/)&&f.indexOf(\":\")!==-1){return ipv6tohex(f)}else{throw j}}}function encodeURIComponentAll(a){var d=encodeURIComponent(a);var b=\"\";for(var c=0;c<d.length;c++){if(d[c]==\"%\"){b=b+d.substr(c,3);c=c+2}else{b=b+\"%\"+stohex(d[c])}}return b}function newline_toUnix(a){a=a.replace(/\\r\\n/mg,\"\\n\");return a}function newline_toDos(a){a=a.replace(/\\r\\n/mg,\"\\n\");a=a.replace(/\\n/mg,\"\\r\\n\");return a}KJUR.lang.String.isInteger=function(a){if(a.match(/^[0-9]+$/)){return true}else{if(a.match(/^-[0-9]+$/)){return true}else{return false}}};KJUR.lang.String.isHex=function(a){if(a.length%2==0&&(a.match(/^[0-9a-f]+$/)||a.match(/^[0-9A-F]+$/))){return true}else{return false}};KJUR.lang.String.isBase64=function(a){a=a.replace(/\\s+/g,\"\");if(a.match(/^[0-9A-Za-z+\\/]+={0,3}$/)&&a.length%4==0){return true}else{return false}};KJUR.lang.String.isBase64URL=function(a){if(a.match(/[+/=]/)){return false}a=b64utob64(a);return KJUR.lang.String.isBase64(a)};KJUR.lang.String.isIntegerArray=function(a){a=a.replace(/\\s+/g,\"\");if(a.match(/^\\[[0-9,]+\\]$/)){return true}else{return false}};function hextoposhex(a){if(a.length%2==1){return\"0\"+a}if(a.substr(0,1)>\"7\"){return\"00\"+a}return a}function intarystrtohex(b){b=b.replace(/^\\s*\\[\\s*/,\"\");b=b.replace(/\\s*\\]\\s*$/,\"\");b=b.replace(/\\s*/g,\"\");try{var c=b.split(/,/).map(function(g,e,h){var f=parseInt(g);if(f<0||255<f){throw\"integer not in range 0-255\"}var d=(\"00\"+f.toString(16)).slice(-2);return d}).join(\"\");return c}catch(a){throw\"malformed integer array string: \"+a}}var strdiffidx=function(c,a){var d=c.length;if(c.length>a.length){d=a.length}for(var b=0;b<d;b++){if(c.charCodeAt(b)!=a.charCodeAt(b)){return b}}if(c.length!=a.length){return d}return -1};\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.crypto==\"undefined\"||!KJUR.crypto){KJUR.crypto={}}KJUR.crypto.Util=new function(){this.DIGESTINFOHEAD={sha1:\"3021300906052b0e03021a05000414\",sha224:\"302d300d06096086480165030402040500041c\",sha256:\"3031300d060960864801650304020105000420\",sha384:\"3041300d060960864801650304020205000430\",sha512:\"3051300d060960864801650304020305000440\",md2:\"3020300c06082a864886f70d020205000410\",md5:\"3020300c06082a864886f70d020505000410\",ripemd160:\"3021300906052b2403020105000414\",};this.DEFAULTPROVIDER={md5:\"cryptojs\",sha1:\"cryptojs\",sha224:\"cryptojs\",sha256:\"cryptojs\",sha384:\"cryptojs\",sha512:\"cryptojs\",ripemd160:\"cryptojs\",hmacmd5:\"cryptojs\",hmacsha1:\"cryptojs\",hmacsha224:\"cryptojs\",hmacsha256:\"cryptojs\",hmacsha384:\"cryptojs\",hmacsha512:\"cryptojs\",hmacripemd160:\"cryptojs\",MD5withRSA:\"cryptojs/jsrsa\",SHA1withRSA:\"cryptojs/jsrsa\",SHA224withRSA:\"cryptojs/jsrsa\",SHA256withRSA:\"cryptojs/jsrsa\",SHA384withRSA:\"cryptojs/jsrsa\",SHA512withRSA:\"cryptojs/jsrsa\",RIPEMD160withRSA:\"cryptojs/jsrsa\",MD5withECDSA:\"cryptojs/jsrsa\",SHA1withECDSA:\"cryptojs/jsrsa\",SHA224withECDSA:\"cryptojs/jsrsa\",SHA256withECDSA:\"cryptojs/jsrsa\",SHA384withECDSA:\"cryptojs/jsrsa\",SHA512withECDSA:\"cryptojs/jsrsa\",RIPEMD160withECDSA:\"cryptojs/jsrsa\",SHA1withDSA:\"cryptojs/jsrsa\",SHA224withDSA:\"cryptojs/jsrsa\",SHA256withDSA:\"cryptojs/jsrsa\",MD5withRSAandMGF1:\"cryptojs/jsrsa\",SHA1withRSAandMGF1:\"cryptojs/jsrsa\",SHA224withRSAandMGF1:\"cryptojs/jsrsa\",SHA256withRSAandMGF1:\"cryptojs/jsrsa\",SHA384withRSAandMGF1:\"cryptojs/jsrsa\",SHA512withRSAandMGF1:\"cryptojs/jsrsa\",RIPEMD160withRSAandMGF1:\"cryptojs/jsrsa\",};this.CRYPTOJSMESSAGEDIGESTNAME={md5:CryptoJS.algo.MD5,sha1:CryptoJS.algo.SHA1,sha224:CryptoJS.algo.SHA224,sha256:CryptoJS.algo.SHA256,sha384:CryptoJS.algo.SHA384,sha512:CryptoJS.algo.SHA512,ripemd160:CryptoJS.algo.RIPEMD160};this.getDigestInfoHex=function(a,b){if(typeof this.DIGESTINFOHEAD[b]==\"undefined\"){throw\"alg not supported in Util.DIGESTINFOHEAD: \"+b}return this.DIGESTINFOHEAD[b]+a};this.getPaddedDigestInfoHex=function(h,a,j){var c=this.getDigestInfoHex(h,a);var d=j/4;if(c.length+22>d){throw\"key is too short for SigAlg: keylen=\"+j+\",\"+a}var b=\"0001\";var k=\"00\"+c;var g=\"\";var l=d-b.length-k.length;for(var f=0;f<l;f+=2){g+=\"ff\"}var e=b+g+k;return e};this.hashString=function(a,c){var b=new KJUR.crypto.MessageDigest({alg:c});return b.digestString(a)};this.hashHex=function(b,c){var a=new KJUR.crypto.MessageDigest({alg:c});return a.digestHex(b)};this.sha1=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha1\",prov:\"cryptojs\"});return b.digestString(a)};this.sha256=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha256\",prov:\"cryptojs\"});return b.digestString(a)};this.sha256Hex=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha256\",prov:\"cryptojs\"});return b.digestHex(a)};this.sha512=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha512\",prov:\"cryptojs\"});return b.digestString(a)};this.sha512Hex=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha512\",prov:\"cryptojs\"});return b.digestHex(a)}};KJUR.crypto.Util.md5=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"md5\",prov:\"cryptojs\"});return b.digestString(a)};KJUR.crypto.Util.ripemd160=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"ripemd160\",prov:\"cryptojs\"});return b.digestString(a)};KJUR.crypto.Util.SECURERANDOMGEN=new SecureRandom();KJUR.crypto.Util.getRandomHexOfNbytes=function(b){var a=new Array(b);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(a);return BAtohex(a)};KJUR.crypto.Util.getRandomBigIntegerOfNbytes=function(a){return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbytes(a),16)};KJUR.crypto.Util.getRandomHexOfNbits=function(d){var c=d%8;var a=(d-c)/8;var b=new Array(a+1);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(b);b[0]=(((255<<c)&255)^255)&b[0];return BAtohex(b)};KJUR.crypto.Util.getRandomBigIntegerOfNbits=function(a){return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbits(a),16)};KJUR.crypto.Util.getRandomBigIntegerZeroToMax=function(b){var a=b.bitLength();while(1){var c=KJUR.crypto.Util.getRandomBigIntegerOfNbits(a);if(b.compareTo(c)!=-1){return c}}};KJUR.crypto.Util.getRandomBigIntegerMinToMax=function(e,b){var c=e.compareTo(b);if(c==1){throw\"biMin is greater than biMax\"}if(c==0){return e}var a=b.subtract(e);var d=KJUR.crypto.Util.getRandomBigIntegerZeroToMax(a);return d.add(e)};KJUR.crypto.MessageDigest=function(c){var b=null;var a=null;var d=null;this.setAlgAndProvider=function(g,f){g=KJUR.crypto.MessageDigest.getCanonicalAlgName(g);if(g!==null&&f===undefined){f=KJUR.crypto.Util.DEFAULTPROVIDER[g]}if(\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g)!=-1&&f==\"cryptojs\"){try{this.md=KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g].create()}catch(e){throw\"setAlgAndProvider hash alg set fail alg=\"+g+\"/\"+e}this.updateString=function(h){this.md.update(h)};this.updateHex=function(h){var i=CryptoJS.enc.Hex.parse(h);this.md.update(i)};this.digest=function(){var h=this.md.finalize();return h.toString(CryptoJS.enc.Hex)};this.digestString=function(h){this.updateString(h);return this.digest()};this.digestHex=function(h){this.updateHex(h);return this.digest()}}if(\":sha256:\".indexOf(g)!=-1&&f==\"sjcl\"){try{this.md=new sjcl.hash.sha256()}catch(e){throw\"setAlgAndProvider hash alg set fail alg=\"+g+\"/\"+e}this.updateString=function(h){this.md.update(h)};this.updateHex=function(i){var h=sjcl.codec.hex.toBits(i);this.md.update(h)};this.digest=function(){var h=this.md.finalize();return sjcl.codec.hex.fromBits(h)};this.digestString=function(h){this.updateString(h);return this.digest()};this.digestHex=function(h){this.updateHex(h);return this.digest()}}};this.updateString=function(e){throw\"updateString(str) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.updateHex=function(e){throw\"updateHex(hex) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.digest=function(){throw\"digest() not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.digestString=function(e){throw\"digestString(str) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.digestHex=function(e){throw\"digestHex(hex) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};if(c!==undefined){if(c.alg!==undefined){this.algName=c.alg;if(c.prov===undefined){this.provName=KJUR.crypto.Util.DEFAULTPROVIDER[this.algName]}this.setAlgAndProvider(this.algName,this.provName)}}};KJUR.crypto.MessageDigest.getCanonicalAlgName=function(a){if(typeof a===\"string\"){a=a.toLowerCase();a=a.replace(/-/,\"\")}return a};KJUR.crypto.MessageDigest.getHashLength=function(c){var b=KJUR.crypto.MessageDigest;var a=b.getCanonicalAlgName(c);if(b.HASHLENGTH[a]===undefined){throw\"not supported algorithm: \"+c}return b.HASHLENGTH[a]};KJUR.crypto.MessageDigest.HASHLENGTH={md5:16,sha1:20,sha224:28,sha256:32,sha384:48,sha512:64,ripemd160:20};KJUR.crypto.Mac=function(d){var f=null;var c=null;var a=null;var e=null;var b=null;this.setAlgAndProvider=function(k,i){k=k.toLowerCase();if(k==null){k=\"hmacsha1\"}k=k.toLowerCase();if(k.substr(0,4)!=\"hmac\"){throw\"setAlgAndProvider unsupported HMAC alg: \"+k}if(i===undefined){i=KJUR.crypto.Util.DEFAULTPROVIDER[k]}this.algProv=k+\"/\"+i;var g=k.substr(4);if(\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g)!=-1&&i==\"cryptojs\"){try{var j=KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g];this.mac=CryptoJS.algo.HMAC.create(j,this.pass)}catch(h){throw\"setAlgAndProvider hash alg set fail hashAlg=\"+g+\"/\"+h}this.updateString=function(l){this.mac.update(l)};this.updateHex=function(l){var m=CryptoJS.enc.Hex.parse(l);this.mac.update(m)};this.doFinal=function(){var l=this.mac.finalize();return l.toString(CryptoJS.enc.Hex)};this.doFinalString=function(l){this.updateString(l);return this.doFinal()};this.doFinalHex=function(l){this.updateHex(l);return this.doFinal()}}};this.updateString=function(g){throw\"updateString(str) not supported for this alg/prov: \"+this.algProv};this.updateHex=function(g){throw\"updateHex(hex) not supported for this alg/prov: \"+this.algProv};this.doFinal=function(){throw\"digest() not supported for this alg/prov: \"+this.algProv};this.doFinalString=function(g){throw\"digestString(str) not supported for this alg/prov: \"+this.algProv};this.doFinalHex=function(g){throw\"digestHex(hex) not supported for this alg/prov: \"+this.algProv};this.setPassword=function(h){if(typeof h==\"string\"){var g=h;if(h.length%2==1||!h.match(/^[0-9A-Fa-f]+$/)){g=rstrtohex(h)}this.pass=CryptoJS.enc.Hex.parse(g);return}if(typeof h!=\"object\"){throw\"KJUR.crypto.Mac unsupported password type: \"+h}var g=null;if(h.hex!==undefined){if(h.hex.length%2!=0||!h.hex.match(/^[0-9A-Fa-f]+$/)){throw\"Mac: wrong hex password: \"+h.hex}g=h.hex}if(h.utf8!==undefined){g=utf8tohex(h.utf8)}if(h.rstr!==undefined){g=rstrtohex(h.rstr)}if(h.b64!==undefined){g=b64tohex(h.b64)}if(h.b64u!==undefined){g=b64utohex(h.b64u)}if(g==null){throw\"KJUR.crypto.Mac unsupported password type: \"+h}this.pass=CryptoJS.enc.Hex.parse(g)};if(d!==undefined){if(d.pass!==undefined){this.setPassword(d.pass)}if(d.alg!==undefined){this.algName=d.alg;if(d.prov===undefined){this.provName=KJUR.crypto.Util.DEFAULTPROVIDER[this.algName]}this.setAlgAndProvider(this.algName,this.provName)}}};KJUR.crypto.Signature=function(o){var q=null;var n=null;var r=null;var c=null;var l=null;var d=null;var k=null;var h=null;var p=null;var e=null;var b=-1;var g=null;var j=null;var a=null;var i=null;var f=null;this._setAlgNames=function(){var s=this.algName.match(/^(.+)with(.+)$/);if(s){this.mdAlgName=s[1].toLowerCase();this.pubkeyAlgName=s[2].toLowerCase()}};this._zeroPaddingOfSignature=function(x,w){var v=\"\";var t=w/4-x.length;for(var u=0;u<t;u++){v=v+\"0\"}return v+x};this.setAlgAndProvider=function(u,t){this._setAlgNames();if(t!=\"cryptojs/jsrsa\"){throw\"provider not supported: \"+t}if(\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(this.mdAlgName)!=-1){try{this.md=new KJUR.crypto.MessageDigest({alg:this.mdAlgName})}catch(s){throw\"setAlgAndProvider hash alg set fail alg=\"+this.mdAlgName+\"/\"+s}this.init=function(w,x){var y=null;try{if(x===undefined){y=KEYUTIL.getKey(w)}else{y=KEYUTIL.getKey(w,x)}}catch(v){throw\"init failed:\"+v}if(y.isPrivate===true){this.prvKey=y;this.state=\"SIGN\"}else{if(y.isPublic===true){this.pubKey=y;this.state=\"VERIFY\"}else{throw\"init failed.:\"+y}}};this.updateString=function(v){this.md.updateString(v)};this.updateHex=function(v){this.md.updateHex(v)};this.sign=function(){this.sHashHex=this.md.digest();if(typeof this.ecprvhex!=\"undefined\"&&typeof this.eccurvename!=\"undefined\"){var v=new KJUR.crypto.ECDSA({curve:this.eccurvename});this.hSign=v.signHex(this.sHashHex,this.ecprvhex)}else{if(this.prvKey instanceof RSAKey&&this.pubkeyAlgName===\"rsaandmgf1\"){this.hSign=this.prvKey.signWithMessageHashPSS(this.sHashHex,this.mdAlgName,this.pssSaltLen)}else{if(this.prvKey instanceof RSAKey&&this.pubkeyAlgName===\"rsa\"){this.hSign=this.prvKey.signWithMessageHash(this.sHashHex,this.mdAlgName)}else{if(this.prvKey instanceof KJUR.crypto.ECDSA){this.hSign=this.prvKey.signWithMessageHash(this.sHashHex)}else{if(this.prvKey instanceof KJUR.crypto.DSA){this.hSign=this.prvKey.signWithMessageHash(this.sHashHex)}else{throw\"Signature: unsupported private key alg: \"+this.pubkeyAlgName}}}}}return this.hSign};this.signString=function(v){this.updateString(v);return this.sign()};this.signHex=function(v){this.updateHex(v);return this.sign()};this.verify=function(v){this.sHashHex=this.md.digest();if(typeof this.ecpubhex!=\"undefined\"&&typeof this.eccurvename!=\"undefined\"){var w=new KJUR.crypto.ECDSA({curve:this.eccurvename});return w.verifyHex(this.sHashHex,v,this.ecpubhex)}else{if(this.pubKey instanceof RSAKey&&this.pubkeyAlgName===\"rsaandmgf1\"){return this.pubKey.verifyWithMessageHashPSS(this.sHashHex,v,this.mdAlgName,this.pssSaltLen)}else{if(this.pubKey instanceof RSAKey&&this.pubkeyAlgName===\"rsa\"){return this.pubKey.verifyWithMessageHash(this.sHashHex,v)}else{if(KJUR.crypto.ECDSA!==undefined&&this.pubKey instanceof KJUR.crypto.ECDSA){return this.pubKey.verifyWithMessageHash(this.sHashHex,v)}else{if(KJUR.crypto.DSA!==undefined&&this.pubKey instanceof KJUR.crypto.DSA){return this.pubKey.verifyWithMessageHash(this.sHashHex,v)}else{throw\"Signature: unsupported public key alg: \"+this.pubkeyAlgName}}}}}}}};this.init=function(s,t){throw\"init(key, pass) not supported for this alg:prov=\"+this.algProvName};this.updateString=function(s){throw\"updateString(str) not supported for this alg:prov=\"+this.algProvName};this.updateHex=function(s){throw\"updateHex(hex) not supported for this alg:prov=\"+this.algProvName};this.sign=function(){throw\"sign() not supported for this alg:prov=\"+this.algProvName};this.signString=function(s){throw\"digestString(str) not supported for this alg:prov=\"+this.algProvName};this.signHex=function(s){throw\"digestHex(hex) not supported for this alg:prov=\"+this.algProvName};this.verify=function(s){throw\"verify(hSigVal) not supported for this alg:prov=\"+this.algProvName};this.initParams=o;if(o!==undefined){if(o.alg!==undefined){this.algName=o.alg;if(o.prov===undefined){this.provName=KJUR.crypto.Util.DEFAULTPROVIDER[this.algName]}else{this.provName=o.prov}this.algProvName=this.algName+\":\"+this.provName;this.setAlgAndProvider(this.algName,this.provName);this._setAlgNames()}if(o.psssaltlen!==undefined){this.pssSaltLen=o.psssaltlen}if(o.prvkeypem!==undefined){if(o.prvkeypas!==undefined){throw\"both prvkeypem and prvkeypas parameters not supported\"}else{try{var q=KEYUTIL.getKey(o.prvkeypem);this.init(q)}catch(m){throw\"fatal error to load pem private key: \"+m}}}}};KJUR.crypto.Cipher=function(a){};KJUR.crypto.Cipher.encrypt=function(e,f,d){if(f instanceof RSAKey&&f.isPublic){var c=KJUR.crypto.Cipher.getAlgByKeyAndName(f,d);if(c===\"RSA\"){return f.encrypt(e)}if(c===\"RSAOAEP\"){return f.encryptOAEP(e,\"sha1\")}var b=c.match(/^RSAOAEP(\\d+)$/);if(b!==null){return f.encryptOAEP(e,\"sha\"+b[1])}throw\"Cipher.encrypt: unsupported algorithm for RSAKey: \"+d}else{throw\"Cipher.encrypt: unsupported key or algorithm\"}};KJUR.crypto.Cipher.decrypt=function(e,f,d){if(f instanceof RSAKey&&f.isPrivate){var c=KJUR.crypto.Cipher.getAlgByKeyAndName(f,d);if(c===\"RSA\"){return f.decrypt(e)}if(c===\"RSAOAEP\"){return f.decryptOAEP(e,\"sha1\")}var b=c.match(/^RSAOAEP(\\d+)$/);if(b!==null){return f.decryptOAEP(e,\"sha\"+b[1])}throw\"Cipher.decrypt: unsupported algorithm for RSAKey: \"+d}else{throw\"Cipher.decrypt: unsupported key or algorithm\"}};KJUR.crypto.Cipher.getAlgByKeyAndName=function(b,a){if(b instanceof RSAKey){if(\":RSA:RSAOAEP:RSAOAEP224:RSAOAEP256:RSAOAEP384:RSAOAEP512:\".indexOf(a)!=-1){return a}if(a===null||a===undefined){return\"RSA\"}throw\"getAlgByKeyAndName: not supported algorithm name for RSAKey: \"+a}throw\"getAlgByKeyAndName: not supported algorithm name: \"+a};KJUR.crypto.OID=new function(){this.oidhex2name={\"2a864886f70d010101\":\"rsaEncryption\",\"2a8648ce3d0201\":\"ecPublicKey\",\"2a8648ce380401\":\"dsa\",\"2a8648ce3d030107\":\"secp256r1\",\"2b8104001f\":\"secp192k1\",\"2b81040021\":\"secp224r1\",\"2b8104000a\":\"secp256k1\",\"2b81040023\":\"secp521r1\",\"2b81040022\":\"secp384r1\",\"2a8648ce380403\":\"SHA1withDSA\",\"608648016503040301\":\"SHA224withDSA\",\"608648016503040302\":\"SHA256withDSA\",}};\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.crypto==\"undefined\"||!KJUR.crypto){KJUR.crypto={}}KJUR.crypto.ECDSA=function(h){var e=\"secp256r1\";var g=null;var b=null;var f=null;var a=new SecureRandom();var d=null;this.type=\"EC\";this.isPrivate=false;this.isPublic=false;function c(s,o,r,n){var j=Math.max(o.bitLength(),n.bitLength());var t=s.add2D(r);var q=s.curve.getInfinity();for(var p=j-1;p>=0;--p){q=q.twice2D();q.z=BigInteger.ONE;if(o.testBit(p)){if(n.testBit(p)){q=q.add2D(t)}else{q=q.add2D(s)}}else{if(n.testBit(p)){q=q.add2D(r)}}}return q}this.getBigRandom=function(i){return new BigInteger(i.bitLength(),a).mod(i.subtract(BigInteger.ONE)).add(BigInteger.ONE)};this.setNamedCurve=function(i){this.ecparams=KJUR.crypto.ECParameterDB.getByName(i);this.prvKeyHex=null;this.pubKeyHex=null;this.curveName=i};this.setPrivateKeyHex=function(i){this.isPrivate=true;this.prvKeyHex=i};this.setPublicKeyHex=function(i){this.isPublic=true;this.pubKeyHex=i};this.getPublicKeyXYHex=function(){var k=this.pubKeyHex;if(k.substr(0,2)!==\"04\"){throw\"this method supports uncompressed format(04) only\"}var j=this.ecparams.keylen/4;if(k.length!==2+j*2){throw\"malformed public key hex length\"}var i={};i.x=k.substr(2,j);i.y=k.substr(2+j);return i};this.getShortNISTPCurveName=function(){var i=this.curveName;if(i===\"secp256r1\"||i===\"NIST P-256\"||i===\"P-256\"||i===\"prime256v1\"){return\"P-256\"}if(i===\"secp384r1\"||i===\"NIST P-384\"||i===\"P-384\"){return\"P-384\"}return null};this.generateKeyPairHex=function(){var k=this.ecparams.n;var n=this.getBigRandom(k);var l=this.ecparams.G.multiply(n);var q=l.getX().toBigInteger();var o=l.getY().toBigInteger();var i=this.ecparams.keylen/4;var m=(\"0000000000\"+n.toString(16)).slice(-i);var r=(\"0000000000\"+q.toString(16)).slice(-i);var p=(\"0000000000\"+o.toString(16)).slice(-i);var j=\"04\"+r+p;this.setPrivateKeyHex(m);this.setPublicKeyHex(j);return{ecprvhex:m,ecpubhex:j}};this.signWithMessageHash=function(i){return this.signHex(i,this.prvKeyHex)};this.signHex=function(o,j){var t=new BigInteger(j,16);var l=this.ecparams.n;var q=new BigInteger(o,16);do{var m=this.getBigRandom(l);var u=this.ecparams.G;var p=u.multiply(m);var i=p.getX().toBigInteger().mod(l)}while(i.compareTo(BigInteger.ZERO)<=0);var v=m.modInverse(l).multiply(q.add(t.multiply(i))).mod(l);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(i,v)};this.sign=function(m,u){var q=u;var j=this.ecparams.n;var p=BigInteger.fromByteArrayUnsigned(m);do{var l=this.getBigRandom(j);var t=this.ecparams.G;var o=t.multiply(l);var i=o.getX().toBigInteger().mod(j)}while(i.compareTo(BigInteger.ZERO)<=0);var v=l.modInverse(j).multiply(p.add(q.multiply(i))).mod(j);return this.serializeSig(i,v)};this.verifyWithMessageHash=function(j,i){return this.verifyHex(j,i,this.pubKeyHex)};this.verifyHex=function(m,i,p){var l,j;var o=KJUR.crypto.ECDSA.parseSigHex(i);l=o.r;j=o.s;var k;k=ECPointFp.decodeFromHex(this.ecparams.curve,p);var n=new BigInteger(m,16);return this.verifyRaw(n,l,j,k)};this.verify=function(o,p,j){var l,i;if(Bitcoin.Util.isArray(p)){var n=this.parseSig(p);l=n.r;i=n.s}else{if(\"object\"===typeof p&&p.r&&p.s){l=p.r;i=p.s}else{throw\"Invalid value for signature\"}}var k;if(j instanceof ECPointFp){k=j}else{if(Bitcoin.Util.isArray(j)){k=ECPointFp.decodeFrom(this.ecparams.curve,j)}else{throw\"Invalid format for pubkey value, must be byte array or ECPointFp\"}}var m=BigInteger.fromByteArrayUnsigned(o);return this.verifyRaw(m,l,i,k)};this.verifyRaw=function(o,i,w,m){var l=this.ecparams.n;var u=this.ecparams.G;if(i.compareTo(BigInteger.ONE)<0||i.compareTo(l)>=0){return false}if(w.compareTo(BigInteger.ONE)<0||w.compareTo(l)>=0){return false}var p=w.modInverse(l);var k=o.multiply(p).mod(l);var j=i.multiply(p).mod(l);var q=u.multiply(k).add(m.multiply(j));var t=q.getX().toBigInteger().mod(l);return t.equals(i)};this.serializeSig=function(k,j){var l=k.toByteArraySigned();var i=j.toByteArraySigned();var m=[];m.push(2);m.push(l.length);m=m.concat(l);m.push(2);m.push(i.length);m=m.concat(i);m.unshift(m.length);m.unshift(48);return m};this.parseSig=function(n){var m;if(n[0]!=48){throw new Error(\"Signature not a valid DERSequence\")}m=2;if(n[m]!=2){throw new Error(\"First element in signature must be a DERInteger\")}var l=n.slice(m+2,m+2+n[m+1]);m+=2+n[m+1];if(n[m]!=2){throw new Error(\"Second element in signature must be a DERInteger\")}var i=n.slice(m+2,m+2+n[m+1]);m+=2+n[m+1];var k=BigInteger.fromByteArrayUnsigned(l);var j=BigInteger.fromByteArrayUnsigned(i);return{r:k,s:j}};this.parseSigCompact=function(m){if(m.length!==65){throw\"Signature has the wrong length\"}var j=m[0]-27;if(j<0||j>7){throw\"Invalid signature type\"}var o=this.ecparams.n;var l=BigInteger.fromByteArrayUnsigned(m.slice(1,33)).mod(o);var k=BigInteger.fromByteArrayUnsigned(m.slice(33,65)).mod(o);return{r:l,s:k,i:j}};this.readPKCS5PrvKeyHex=function(l){var n=ASN1HEX;var m=KJUR.crypto.ECDSA.getName;var p=n.getVbyList;if(n.isASN1HEX(l)===false){throw\"not ASN.1 hex string\"}var i,k,o;try{i=p(l,0,[2,0],\"06\");k=p(l,0,[1],\"04\");try{o=p(l,0,[3,0],\"03\").substr(2)}catch(j){}}catch(j){throw\"malformed PKCS#1/5 plain ECC private key\"}this.curveName=m(i);if(this.curveName===undefined){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(o);this.setPrivateKeyHex(k);this.isPublic=false};this.readPKCS8PrvKeyHex=function(l){var q=ASN1HEX;var i=KJUR.crypto.ECDSA.getName;var n=q.getVbyList;if(q.isASN1HEX(l)===false){throw\"not ASN.1 hex string\"}var j,p,m,k;try{j=n(l,0,[1,0],\"06\");p=n(l,0,[1,1],\"06\");m=n(l,0,[2,0,1],\"04\");try{k=n(l,0,[2,0,2,0],\"03\").substr(2)}catch(o){}}catch(o){throw\"malformed PKCS#8 plain ECC private key\"}this.curveName=i(p);if(this.curveName===undefined){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(k);this.setPrivateKeyHex(m);this.isPublic=false};this.readPKCS8PubKeyHex=function(l){var n=ASN1HEX;var m=KJUR.crypto.ECDSA.getName;var p=n.getVbyList;if(n.isASN1HEX(l)===false){throw\"not ASN.1 hex string\"}var k,i,o;try{k=p(l,0,[0,0],\"06\");i=p(l,0,[0,1],\"06\");o=p(l,0,[1],\"03\").substr(2)}catch(j){throw\"malformed PKCS#8 ECC public key\"}this.curveName=m(i);if(this.curveName===null){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(o)};this.readCertPubKeyHex=function(k,p){if(p!==5){p=6}var m=ASN1HEX;var l=KJUR.crypto.ECDSA.getName;var o=m.getVbyList;if(m.isASN1HEX(k)===false){throw\"not ASN.1 hex string\"}var i,n;try{i=o(k,0,[0,p,0,1],\"06\");n=o(k,0,[0,p,1],\"03\").substr(2)}catch(j){throw\"malformed X.509 certificate ECC public key\"}this.curveName=l(i);if(this.curveName===null){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(n)};if(h!==undefined){if(h.curve!==undefined){this.curveName=h.curve}}if(this.curveName===undefined){this.curveName=e}this.setNamedCurve(this.curveName);if(h!==undefined){if(h.prv!==undefined){this.setPrivateKeyHex(h.prv)}if(h.pub!==undefined){this.setPublicKeyHex(h.pub)}}};KJUR.crypto.ECDSA.parseSigHex=function(a){var b=KJUR.crypto.ECDSA.parseSigHexInHexRS(a);var d=new BigInteger(b.r,16);var c=new BigInteger(b.s,16);return{r:d,s:c}};KJUR.crypto.ECDSA.parseSigHexInHexRS=function(f){var j=ASN1HEX;var i=j.getChildIdx;var g=j.getV;if(f.substr(0,2)!=\"30\"){throw\"signature is not a ASN.1 sequence\"}var h=i(f,0);if(h.length!=2){throw\"number of signature ASN.1 sequence elements seem wrong\"}var e=h[0];var d=h[1];if(f.substr(e,2)!=\"02\"){throw\"1st item of sequene of signature is not ASN.1 integer\"}if(f.substr(d,2)!=\"02\"){throw\"2nd item of sequene of signature is not ASN.1 integer\"}var c=g(f,e);var b=g(f,d);return{r:c,s:b}};KJUR.crypto.ECDSA.asn1SigToConcatSig=function(c){var d=KJUR.crypto.ECDSA.parseSigHexInHexRS(c);var b=d.r;var a=d.s;if(b.substr(0,2)==\"00\"&&(b.length%32)==2){b=b.substr(2)}if(a.substr(0,2)==\"00\"&&(a.length%32)==2){a=a.substr(2)}if((b.length%32)==30){b=\"00\"+b}if((a.length%32)==30){a=\"00\"+a}if(b.length%32!=0){throw\"unknown ECDSA sig r length error\"}if(a.length%32!=0){throw\"unknown ECDSA sig s length error\"}return b+a};KJUR.crypto.ECDSA.concatSigToASN1Sig=function(a){if((((a.length/2)*8)%(16*8))!=0){throw\"unknown ECDSA concatinated r-s sig  length error\"}var c=a.substr(0,a.length/2);var b=a.substr(a.length/2);return KJUR.crypto.ECDSA.hexRSSigToASN1Sig(c,b)};KJUR.crypto.ECDSA.hexRSSigToASN1Sig=function(b,a){var d=new BigInteger(b,16);var c=new BigInteger(a,16);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(d,c)};KJUR.crypto.ECDSA.biRSSigToASN1Sig=function(f,d){var c=KJUR.asn1;var b=new c.DERInteger({bigint:f});var a=new c.DERInteger({bigint:d});var e=new c.DERSequence({array:[b,a]});return e.getEncodedHex()};KJUR.crypto.ECDSA.getName=function(a){if(a===\"2a8648ce3d030107\"){return\"secp256r1\"}if(a===\"2b8104000a\"){return\"secp256k1\"}if(a===\"2b81040022\"){return\"secp384r1\"}if(\"|secp256r1|NIST P-256|P-256|prime256v1|\".indexOf(a)!==-1){return\"secp256r1\"}if(\"|secp256k1|\".indexOf(a)!==-1){return\"secp256k1\"}if(\"|secp384r1|NIST P-384|P-384|\".indexOf(a)!==-1){return\"secp384r1\"}return null};\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.crypto==\"undefined\"||!KJUR.crypto){KJUR.crypto={}}KJUR.crypto.ECParameterDB=new function(){var b={};var c={};function a(d){return new BigInteger(d,16)}this.getByName=function(e){var d=e;if(typeof c[d]!=\"undefined\"){d=c[e]}if(typeof b[d]!=\"undefined\"){return b[d]}throw\"unregistered EC curve name: \"+d};this.regist=function(A,l,o,g,m,e,j,f,k,u,d,x){b[A]={};var s=a(o);var z=a(g);var y=a(m);var t=a(e);var w=a(j);var r=new ECCurveFp(s,z,y);var q=r.decodePointHex(\"04\"+f+k);b[A][\"name\"]=A;b[A][\"keylen\"]=l;b[A][\"curve\"]=r;b[A][\"G\"]=q;b[A][\"n\"]=t;b[A][\"h\"]=w;b[A][\"oid\"]=d;b[A][\"info\"]=x;for(var v=0;v<u.length;v++){c[u[v]]=A}}};KJUR.crypto.ECParameterDB.regist(\"secp128r1\",128,\"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF\",\"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFC\",\"E87579C11079F43DD824993C2CEE5ED3\",\"FFFFFFFE0000000075A30D1B9038A115\",\"1\",\"161FF7528B899B2D0C28607CA52C5B86\",\"CF5AC8395BAFEB13C02DA292DDED7A83\",[],\"\",\"secp128r1 : SECG curve over a 128 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160k1\",160,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73\",\"0\",\"7\",\"0100000000000000000001B8FA16DFAB9ACA16B6B3\",\"1\",\"3B4C382CE37AA192A4019E763036F4F5DD4D7EBB\",\"938CF935318FDCED6BC28286531733C3F03C4FEE\",[],\"\",\"secp160k1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160r1\",160,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFC\",\"1C97BEFC54BD7A8B65ACF89F81D4D4ADC565FA45\",\"0100000000000000000001F4C8F927AED3CA752257\",\"1\",\"4A96B5688EF573284664698968C38BB913CBFC82\",\"23A628553168947D59DCC912042351377AC5FB32\",[],\"\",\"secp160r1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp192k1\",192,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFEE37\",\"0\",\"3\",\"FFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D\",\"1\",\"DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D\",\"9B2F2F6D9C5628A7844163D015BE86344082AA88D95E2F9D\",[]);KJUR.crypto.ECParameterDB.regist(\"secp192r1\",192,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC\",\"64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1\",\"FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831\",\"1\",\"188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012\",\"07192B95FFC8DA78631011ED6B24CDD573F977A11E794811\",[]);KJUR.crypto.ECParameterDB.regist(\"secp224r1\",224,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE\",\"B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D\",\"1\",\"B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21\",\"BD376388B5F723FB4C22DFE6CD4375A05A07476444D5819985007E34\",[]);KJUR.crypto.ECParameterDB.regist(\"secp256k1\",256,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F\",\"0\",\"7\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141\",\"1\",\"79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798\",\"483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8\",[]);KJUR.crypto.ECParameterDB.regist(\"secp256r1\",256,\"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF\",\"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFC\",\"5AC635D8AA3A93E7B3EBBD55769886BC651D06B0CC53B0F63BCE3C3E27D2604B\",\"FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551\",\"1\",\"6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296\",\"4FE342E2FE1A7F9B8EE7EB4A7C0F9E162BCE33576B315ECECBB6406837BF51F5\",[\"NIST P-256\",\"P-256\",\"prime256v1\"]);KJUR.crypto.ECParameterDB.regist(\"secp384r1\",384,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFC\",\"B3312FA7E23EE7E4988E056BE3F82D19181D9C6EFE8141120314088F5013875AC656398D8A2ED19D2A85C8EDD3EC2AEF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973\",\"1\",\"AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7\",\"3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5f\",[\"NIST P-384\",\"P-384\"]);KJUR.crypto.ECParameterDB.regist(\"secp521r1\",521,\"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF\",\"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC\",\"051953EB9618E1C9A1F929A21A0B68540EEA2DA725B99B315F3B8B489918EF109E156193951EC7E937B1652C0BD3BB1BF073573DF883D2C34F1EF451FD46B503F00\",\"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA51868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409\",\"1\",\"C6858E06B70404E9CD9E3ECB662395B4429C648139053FB521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66\",\"011839296a789a3bc0045c8a5fb42c7d1bd998f54449579b446817afbd17273e662c97ee72995ef42640c550b9013fad0761353c7086a272c24088be94769fd16650\",[\"NIST P-521\",\"P-521\"]);\nvar KEYUTIL=function(){var d=function(p,r,q){return k(CryptoJS.AES,p,r,q)};var e=function(p,r,q){return k(CryptoJS.TripleDES,p,r,q)};var a=function(p,r,q){return k(CryptoJS.DES,p,r,q)};var k=function(s,x,u,q){var r=CryptoJS.enc.Hex.parse(x);var w=CryptoJS.enc.Hex.parse(u);var p=CryptoJS.enc.Hex.parse(q);var t={};t.key=w;t.iv=p;t.ciphertext=r;var v=s.decrypt(t,w,{iv:p});return CryptoJS.enc.Hex.stringify(v)};var l=function(p,r,q){return g(CryptoJS.AES,p,r,q)};var o=function(p,r,q){return g(CryptoJS.TripleDES,p,r,q)};var f=function(p,r,q){return g(CryptoJS.DES,p,r,q)};var g=function(t,y,v,q){var s=CryptoJS.enc.Hex.parse(y);var x=CryptoJS.enc.Hex.parse(v);var p=CryptoJS.enc.Hex.parse(q);var w=t.encrypt(s,x,{iv:p});var r=CryptoJS.enc.Hex.parse(w.toString());var u=CryptoJS.enc.Base64.stringify(r);return u};var i={\"AES-256-CBC\":{proc:d,eproc:l,keylen:32,ivlen:16},\"AES-192-CBC\":{proc:d,eproc:l,keylen:24,ivlen:16},\"AES-128-CBC\":{proc:d,eproc:l,keylen:16,ivlen:16},\"DES-EDE3-CBC\":{proc:e,eproc:o,keylen:24,ivlen:8},\"DES-CBC\":{proc:a,eproc:f,keylen:8,ivlen:8}};var c=function(p){return i[p][\"proc\"]};var m=function(p){var r=CryptoJS.lib.WordArray.random(p);var q=CryptoJS.enc.Hex.stringify(r);return q};var n=function(v){var w={};var q=v.match(new RegExp(\"DEK-Info: ([^,]+),([0-9A-Fa-f]+)\",\"m\"));if(q){w.cipher=q[1];w.ivsalt=q[2]}var p=v.match(new RegExp(\"-----BEGIN ([A-Z]+) PRIVATE KEY-----\"));if(p){w.type=p[1]}var u=-1;var x=0;if(v.indexOf(\"\\r\\n\\r\\n\")!=-1){u=v.indexOf(\"\\r\\n\\r\\n\");x=2}if(v.indexOf(\"\\n\\n\")!=-1){u=v.indexOf(\"\\n\\n\");x=1}var t=v.indexOf(\"-----END\");if(u!=-1&&t!=-1){var r=v.substring(u+x*2,t-x);r=r.replace(/\\s+/g,\"\");w.data=r}return w};var j=function(q,y,p){var v=p.substring(0,16);var t=CryptoJS.enc.Hex.parse(v);var r=CryptoJS.enc.Utf8.parse(y);var u=i[q][\"keylen\"]+i[q][\"ivlen\"];var x=\"\";var w=null;for(;;){var s=CryptoJS.algo.MD5.create();if(w!=null){s.update(w)}s.update(r);s.update(t);w=s.finalize();x=x+CryptoJS.enc.Hex.stringify(w);if(x.length>=u*2){break}}var z={};z.keyhex=x.substr(0,i[q][\"keylen\"]*2);z.ivhex=x.substr(i[q][\"keylen\"]*2,i[q][\"ivlen\"]*2);return z};var b=function(p,v,r,w){var s=CryptoJS.enc.Base64.parse(p);var q=CryptoJS.enc.Hex.stringify(s);var u=i[v][\"proc\"];var t=u(q,r,w);return t};var h=function(p,s,q,u){var r=i[s][\"eproc\"];var t=r(p,q,u);return t};return{version:\"1.0.0\",parsePKCS5PEM:function(p){return n(p)},getKeyAndUnusedIvByPasscodeAndIvsalt:function(q,p,r){return j(q,p,r)},decryptKeyB64:function(p,r,q,s){return b(p,r,q,s)},getDecryptedKeyHex:function(y,x){var q=n(y);var t=q.type;var r=q.cipher;var p=q.ivsalt;var s=q.data;var w=j(r,x,p);var v=w.keyhex;var u=b(s,r,v,p);return u},getEncryptedPKCS5PEMFromPrvKeyHex:function(x,s,A,t,r){var p=\"\";if(typeof t==\"undefined\"||t==null){t=\"AES-256-CBC\"}if(typeof i[t]==\"undefined\"){throw\"KEYUTIL unsupported algorithm: \"+t}if(typeof r==\"undefined\"||r==null){var v=i[t][\"ivlen\"];var u=m(v);r=u.toUpperCase()}var z=j(t,A,r);var y=z.keyhex;var w=h(s,t,y,r);var q=w.replace(/(.{64})/g,\"$1\\r\\n\");var p=\"-----BEGIN \"+x+\" PRIVATE KEY-----\\r\\n\";p+=\"Proc-Type: 4,ENCRYPTED\\r\\n\";p+=\"DEK-Info: \"+t+\",\"+r+\"\\r\\n\";p+=\"\\r\\n\";p+=q;p+=\"\\r\\n-----END \"+x+\" PRIVATE KEY-----\\r\\n\";return p},parseHexOfEncryptedPKCS8:function(y){var B=ASN1HEX;var z=B.getChildIdx;var w=B.getV;var t={};var r=z(y,0);if(r.length!=2){throw\"malformed format: SEQUENCE(0).items != 2: \"+r.length}t.ciphertext=w(y,r[1]);var A=z(y,r[0]);if(A.length!=2){throw\"malformed format: SEQUENCE(0.0).items != 2: \"+A.length}if(w(y,A[0])!=\"2a864886f70d01050d\"){throw\"this only supports pkcs5PBES2\"}var p=z(y,A[1]);if(A.length!=2){throw\"malformed format: SEQUENCE(0.0.1).items != 2: \"+p.length}var q=z(y,p[1]);if(q.length!=2){throw\"malformed format: SEQUENCE(0.0.1.1).items != 2: \"+q.length}if(w(y,q[0])!=\"2a864886f70d0307\"){throw\"this only supports TripleDES\"}t.encryptionSchemeAlg=\"TripleDES\";t.encryptionSchemeIV=w(y,q[1]);var s=z(y,p[0]);if(s.length!=2){throw\"malformed format: SEQUENCE(0.0.1.0).items != 2: \"+s.length}if(w(y,s[0])!=\"2a864886f70d01050c\"){throw\"this only supports pkcs5PBKDF2\"}var x=z(y,s[1]);if(x.length<2){throw\"malformed format: SEQUENCE(0.0.1.0.1).items < 2: \"+x.length}t.pbkdf2Salt=w(y,x[0]);var u=w(y,x[1]);try{t.pbkdf2Iter=parseInt(u,16)}catch(v){throw\"malformed format pbkdf2Iter: \"+u}return t},getPBKDF2KeyHexFromParam:function(u,p){var t=CryptoJS.enc.Hex.parse(u.pbkdf2Salt);var q=u.pbkdf2Iter;var s=CryptoJS.PBKDF2(p,t,{keySize:192/32,iterations:q});var r=CryptoJS.enc.Hex.stringify(s);return r},_getPlainPKCS8HexFromEncryptedPKCS8PEM:function(x,y){var r=pemtohex(x,\"ENCRYPTED PRIVATE KEY\");var p=this.parseHexOfEncryptedPKCS8(r);var u=KEYUTIL.getPBKDF2KeyHexFromParam(p,y);var v={};v.ciphertext=CryptoJS.enc.Hex.parse(p.ciphertext);var t=CryptoJS.enc.Hex.parse(u);var s=CryptoJS.enc.Hex.parse(p.encryptionSchemeIV);var w=CryptoJS.TripleDES.decrypt(v,t,{iv:s});var q=CryptoJS.enc.Hex.stringify(w);return q},getKeyFromEncryptedPKCS8PEM:function(s,q){var p=this._getPlainPKCS8HexFromEncryptedPKCS8PEM(s,q);var r=this.getKeyFromPlainPrivatePKCS8Hex(p);return r},parsePlainPrivatePKCS8Hex:function(s){var v=ASN1HEX;var u=v.getChildIdx;var t=v.getV;var q={};q.algparam=null;if(s.substr(0,2)!=\"30\"){throw\"malformed plain PKCS8 private key(code:001)\"}var r=u(s,0);if(r.length!=3){throw\"malformed plain PKCS8 private key(code:002)\"}if(s.substr(r[1],2)!=\"30\"){throw\"malformed PKCS8 private key(code:003)\"}var p=u(s,r[1]);if(p.length!=2){throw\"malformed PKCS8 private key(code:004)\"}if(s.substr(p[0],2)!=\"06\"){throw\"malformed PKCS8 private key(code:005)\"}q.algoid=t(s,p[0]);if(s.substr(p[1],2)==\"06\"){q.algparam=t(s,p[1])}if(s.substr(r[2],2)!=\"04\"){throw\"malformed PKCS8 private key(code:006)\"}q.keyidx=v.getVidx(s,r[2]);return q},getKeyFromPlainPrivatePKCS8PEM:function(q){var p=pemtohex(q,\"PRIVATE KEY\");var r=this.getKeyFromPlainPrivatePKCS8Hex(p);return r},getKeyFromPlainPrivatePKCS8Hex:function(p){var q=this.parsePlainPrivatePKCS8Hex(p);var r;if(q.algoid==\"2a864886f70d010101\"){r=new RSAKey()}else{if(q.algoid==\"2a8648ce380401\"){r=new KJUR.crypto.DSA()}else{if(q.algoid==\"2a8648ce3d0201\"){r=new KJUR.crypto.ECDSA()}else{throw\"unsupported private key algorithm\"}}}r.readPKCS8PrvKeyHex(p);return r},_getKeyFromPublicPKCS8Hex:function(q){var p;var r=ASN1HEX.getVbyList(q,0,[0,0],\"06\");if(r===\"2a864886f70d010101\"){p=new RSAKey()}else{if(r===\"2a8648ce380401\"){p=new KJUR.crypto.DSA()}else{if(r===\"2a8648ce3d0201\"){p=new KJUR.crypto.ECDSA()}else{throw\"unsupported PKCS#8 public key hex\"}}}p.readPKCS8PubKeyHex(q);return p},parsePublicRawRSAKeyHex:function(r){var u=ASN1HEX;var t=u.getChildIdx;var s=u.getV;var p={};if(r.substr(0,2)!=\"30\"){throw\"malformed RSA key(code:001)\"}var q=t(r,0);if(q.length!=2){throw\"malformed RSA key(code:002)\"}if(r.substr(q[0],2)!=\"02\"){throw\"malformed RSA key(code:003)\"}p.n=s(r,q[0]);if(r.substr(q[1],2)!=\"02\"){throw\"malformed RSA key(code:004)\"}p.e=s(r,q[1]);return p},parsePublicPKCS8Hex:function(t){var v=ASN1HEX;var u=v.getChildIdx;var s=v.getV;var q={};q.algparam=null;var r=u(t,0);if(r.length!=2){throw\"outer DERSequence shall have 2 elements: \"+r.length}var w=r[0];if(t.substr(w,2)!=\"30\"){throw\"malformed PKCS8 public key(code:001)\"}var p=u(t,w);if(p.length!=2){throw\"malformed PKCS8 public key(code:002)\"}if(t.substr(p[0],2)!=\"06\"){throw\"malformed PKCS8 public key(code:003)\"}q.algoid=s(t,p[0]);if(t.substr(p[1],2)==\"06\"){q.algparam=s(t,p[1])}else{if(t.substr(p[1],2)==\"30\"){q.algparam={};q.algparam.p=v.getVbyList(t,p[1],[0],\"02\");q.algparam.q=v.getVbyList(t,p[1],[1],\"02\");q.algparam.g=v.getVbyList(t,p[1],[2],\"02\")}}if(t.substr(r[1],2)!=\"03\"){throw\"malformed PKCS8 public key(code:004)\"}q.key=s(t,r[1]).substr(2);return q},}}();KEYUTIL.getKey=function(l,k,n){var G=ASN1HEX,L=G.getChildIdx,v=G.getV,d=G.getVbyList,c=KJUR.crypto,i=c.ECDSA,C=c.DSA,w=RSAKey,M=pemtohex,F=KEYUTIL;if(typeof w!=\"undefined\"&&l instanceof w){return l}if(typeof i!=\"undefined\"&&l instanceof i){return l}if(typeof C!=\"undefined\"&&l instanceof C){return l}if(l.curve!==undefined&&l.xy!==undefined&&l.d===undefined){return new i({pub:l.xy,curve:l.curve})}if(l.curve!==undefined&&l.d!==undefined){return new i({prv:l.d,curve:l.curve})}if(l.kty===undefined&&l.n!==undefined&&l.e!==undefined&&l.d===undefined){var P=new w();P.setPublic(l.n,l.e);return P}if(l.kty===undefined&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined&&l.p!==undefined&&l.q!==undefined&&l.dp!==undefined&&l.dq!==undefined&&l.co!==undefined&&l.qi===undefined){var P=new w();P.setPrivateEx(l.n,l.e,l.d,l.p,l.q,l.dp,l.dq,l.co);return P}if(l.kty===undefined&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined&&l.p===undefined){var P=new w();P.setPrivate(l.n,l.e,l.d);return P}if(l.p!==undefined&&l.q!==undefined&&l.g!==undefined&&l.y!==undefined&&l.x===undefined){var P=new C();P.setPublic(l.p,l.q,l.g,l.y);return P}if(l.p!==undefined&&l.q!==undefined&&l.g!==undefined&&l.y!==undefined&&l.x!==undefined){var P=new C();P.setPrivate(l.p,l.q,l.g,l.y,l.x);return P}if(l.kty===\"RSA\"&&l.n!==undefined&&l.e!==undefined&&l.d===undefined){var P=new w();P.setPublic(b64utohex(l.n),b64utohex(l.e));return P}if(l.kty===\"RSA\"&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined&&l.p!==undefined&&l.q!==undefined&&l.dp!==undefined&&l.dq!==undefined&&l.qi!==undefined){var P=new w();P.setPrivateEx(b64utohex(l.n),b64utohex(l.e),b64utohex(l.d),b64utohex(l.p),b64utohex(l.q),b64utohex(l.dp),b64utohex(l.dq),b64utohex(l.qi));return P}if(l.kty===\"RSA\"&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined){var P=new w();P.setPrivate(b64utohex(l.n),b64utohex(l.e),b64utohex(l.d));return P}if(l.kty===\"EC\"&&l.crv!==undefined&&l.x!==undefined&&l.y!==undefined&&l.d===undefined){var j=new i({curve:l.crv});var t=j.ecparams.keylen/4;var B=(\"0000000000\"+b64utohex(l.x)).slice(-t);var z=(\"0000000000\"+b64utohex(l.y)).slice(-t);var u=\"04\"+B+z;j.setPublicKeyHex(u);return j}if(l.kty===\"EC\"&&l.crv!==undefined&&l.x!==undefined&&l.y!==undefined&&l.d!==undefined){var j=new i({curve:l.crv});var t=j.ecparams.keylen/4;var B=(\"0000000000\"+b64utohex(l.x)).slice(-t);var z=(\"0000000000\"+b64utohex(l.y)).slice(-t);var u=\"04\"+B+z;var b=(\"0000000000\"+b64utohex(l.d)).slice(-t);j.setPublicKeyHex(u);j.setPrivateKeyHex(b);return j}if(n===\"pkcs5prv\"){var J=l,G=ASN1HEX,N,P;N=L(J,0);if(N.length===9){P=new w();P.readPKCS5PrvKeyHex(J)}else{if(N.length===6){P=new C();P.readPKCS5PrvKeyHex(J)}else{if(N.length>2&&J.substr(N[1],2)===\"04\"){P=new i();P.readPKCS5PrvKeyHex(J)}else{throw\"unsupported PKCS#1/5 hexadecimal key\"}}}return P}if(n===\"pkcs8prv\"){var P=F.getKeyFromPlainPrivatePKCS8Hex(l);return P}if(n===\"pkcs8pub\"){return F._getKeyFromPublicPKCS8Hex(l)}if(n===\"x509pub\"){return X509.getPublicKeyFromCertHex(l)}if(l.indexOf(\"-END CERTIFICATE-\",0)!=-1||l.indexOf(\"-END X509 CERTIFICATE-\",0)!=-1||l.indexOf(\"-END TRUSTED CERTIFICATE-\",0)!=-1){return X509.getPublicKeyFromCertPEM(l)}if(l.indexOf(\"-END PUBLIC KEY-\")!=-1){var O=pemtohex(l,\"PUBLIC KEY\");return F._getKeyFromPublicPKCS8Hex(O)}if(l.indexOf(\"-END RSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")==-1){var m=M(l,\"RSA PRIVATE KEY\");return F.getKey(m,null,\"pkcs5prv\")}if(l.indexOf(\"-END DSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")==-1){var I=M(l,\"DSA PRIVATE KEY\");var E=d(I,0,[1],\"02\");var D=d(I,0,[2],\"02\");var K=d(I,0,[3],\"02\");var r=d(I,0,[4],\"02\");var s=d(I,0,[5],\"02\");var P=new C();P.setPrivate(new BigInteger(E,16),new BigInteger(D,16),new BigInteger(K,16),new BigInteger(r,16),new BigInteger(s,16));return P}if(l.indexOf(\"-END PRIVATE KEY-\")!=-1){return F.getKeyFromPlainPrivatePKCS8PEM(l)}if(l.indexOf(\"-END RSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")!=-1){var o=F.getDecryptedKeyHex(l,k);var H=new RSAKey();H.readPKCS5PrvKeyHex(o);return H}if(l.indexOf(\"-END EC PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")!=-1){var I=F.getDecryptedKeyHex(l,k);var P=d(I,0,[1],\"04\");var f=d(I,0,[2,0],\"06\");var A=d(I,0,[3,0],\"03\").substr(2);var e=\"\";if(KJUR.crypto.OID.oidhex2name[f]!==undefined){e=KJUR.crypto.OID.oidhex2name[f]}else{throw\"undefined OID(hex) in KJUR.crypto.OID: \"+f}var j=new i({curve:e});j.setPublicKeyHex(A);j.setPrivateKeyHex(P);j.isPublic=false;return j}if(l.indexOf(\"-END DSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")!=-1){var I=F.getDecryptedKeyHex(l,k);var E=d(I,0,[1],\"02\");var D=d(I,0,[2],\"02\");var K=d(I,0,[3],\"02\");var r=d(I,0,[4],\"02\");var s=d(I,0,[5],\"02\");var P=new C();P.setPrivate(new BigInteger(E,16),new BigInteger(D,16),new BigInteger(K,16),new BigInteger(r,16),new BigInteger(s,16));return P}if(l.indexOf(\"-END ENCRYPTED PRIVATE KEY-\")!=-1){return F.getKeyFromEncryptedPKCS8PEM(l,k)}throw\"not supported argument\"};KEYUTIL.generateKeypair=function(a,c){if(a==\"RSA\"){var b=c;var h=new RSAKey();h.generate(b,\"10001\");h.isPrivate=true;h.isPublic=true;var f=new RSAKey();var e=h.n.toString(16);var i=h.e.toString(16);f.setPublic(e,i);f.isPrivate=false;f.isPublic=true;var k={};k.prvKeyObj=h;k.pubKeyObj=f;return k}else{if(a==\"EC\"){var d=c;var g=new KJUR.crypto.ECDSA({curve:d});var j=g.generateKeyPairHex();var h=new KJUR.crypto.ECDSA({curve:d});h.setPublicKeyHex(j.ecpubhex);h.setPrivateKeyHex(j.ecprvhex);h.isPrivate=true;h.isPublic=false;var f=new KJUR.crypto.ECDSA({curve:d});f.setPublicKeyHex(j.ecpubhex);f.isPrivate=false;f.isPublic=true;var k={};k.prvKeyObj=h;k.pubKeyObj=f;return k}else{throw\"unknown algorithm: \"+a}}};KEYUTIL.getPEM=function(b,D,y,m,q,j){var F=KJUR,k=F.asn1,z=k.DERObjectIdentifier,f=k.DERInteger,l=k.ASN1Util.newObject,a=k.x509,C=a.SubjectPublicKeyInfo,e=F.crypto,u=e.DSA,r=e.ECDSA,n=RSAKey;function A(s){var G=l({seq:[{\"int\":0},{\"int\":{bigint:s.n}},{\"int\":s.e},{\"int\":{bigint:s.d}},{\"int\":{bigint:s.p}},{\"int\":{bigint:s.q}},{\"int\":{bigint:s.dmp1}},{\"int\":{bigint:s.dmq1}},{\"int\":{bigint:s.coeff}}]});return G}function B(G){var s=l({seq:[{\"int\":1},{octstr:{hex:G.prvKeyHex}},{tag:[\"a0\",true,{oid:{name:G.curveName}}]},{tag:[\"a1\",true,{bitstr:{hex:\"00\"+G.pubKeyHex}}]}]});return s}function x(s){var G=l({seq:[{\"int\":0},{\"int\":{bigint:s.p}},{\"int\":{bigint:s.q}},{\"int\":{bigint:s.g}},{\"int\":{bigint:s.y}},{\"int\":{bigint:s.x}}]});return G}if(((n!==undefined&&b instanceof n)||(u!==undefined&&b instanceof u)||(r!==undefined&&b instanceof r))&&b.isPublic==true&&(D===undefined||D==\"PKCS8PUB\")){var E=new C(b);var w=E.getEncodedHex();return hextopem(w,\"PUBLIC KEY\")}if(D==\"PKCS1PRV\"&&n!==undefined&&b instanceof n&&(y===undefined||y==null)&&b.isPrivate==true){var E=A(b);var w=E.getEncodedHex();return hextopem(w,\"RSA PRIVATE KEY\")}if(D==\"PKCS1PRV\"&&r!==undefined&&b instanceof r&&(y===undefined||y==null)&&b.isPrivate==true){var i=new z({name:b.curveName});var v=i.getEncodedHex();var h=B(b);var t=h.getEncodedHex();var p=\"\";p+=hextopem(v,\"EC PARAMETERS\");p+=hextopem(t,\"EC PRIVATE KEY\");return p}if(D==\"PKCS1PRV\"&&u!==undefined&&b instanceof u&&(y===undefined||y==null)&&b.isPrivate==true){var E=x(b);var w=E.getEncodedHex();return hextopem(w,\"DSA PRIVATE KEY\")}if(D==\"PKCS5PRV\"&&n!==undefined&&b instanceof n&&(y!==undefined&&y!=null)&&b.isPrivate==true){var E=A(b);var w=E.getEncodedHex();if(m===undefined){m=\"DES-EDE3-CBC\"}return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"RSA\",w,y,m,j)}if(D==\"PKCS5PRV\"&&r!==undefined&&b instanceof r&&(y!==undefined&&y!=null)&&b.isPrivate==true){var E=B(b);var w=E.getEncodedHex();if(m===undefined){m=\"DES-EDE3-CBC\"}return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"EC\",w,y,m,j)}if(D==\"PKCS5PRV\"&&u!==undefined&&b instanceof u&&(y!==undefined&&y!=null)&&b.isPrivate==true){var E=x(b);var w=E.getEncodedHex();if(m===undefined){m=\"DES-EDE3-CBC\"}return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"DSA\",w,y,m,j)}var o=function(G,s){var I=c(G,s);var H=new l({seq:[{seq:[{oid:{name:\"pkcs5PBES2\"}},{seq:[{seq:[{oid:{name:\"pkcs5PBKDF2\"}},{seq:[{octstr:{hex:I.pbkdf2Salt}},{\"int\":I.pbkdf2Iter}]}]},{seq:[{oid:{name:\"des-EDE3-CBC\"}},{octstr:{hex:I.encryptionSchemeIV}}]}]}]},{octstr:{hex:I.ciphertext}}]});return H.getEncodedHex()};var c=function(N,O){var H=100;var M=CryptoJS.lib.WordArray.random(8);var L=\"DES-EDE3-CBC\";var s=CryptoJS.lib.WordArray.random(8);var I=CryptoJS.PBKDF2(O,M,{keySize:192/32,iterations:H});var J=CryptoJS.enc.Hex.parse(N);var K=CryptoJS.TripleDES.encrypt(J,I,{iv:s})+\"\";var G={};G.ciphertext=K;G.pbkdf2Salt=CryptoJS.enc.Hex.stringify(M);G.pbkdf2Iter=H;G.encryptionSchemeAlg=L;G.encryptionSchemeIV=CryptoJS.enc.Hex.stringify(s);return G};if(D==\"PKCS8PRV\"&&n!=undefined&&b instanceof n&&b.isPrivate==true){var g=A(b);var d=g.getEncodedHex();var E=l({seq:[{\"int\":0},{seq:[{oid:{name:\"rsaEncryption\"}},{\"null\":true}]},{octstr:{hex:d}}]});var w=E.getEncodedHex();if(y===undefined||y==null){return hextopem(w,\"PRIVATE KEY\")}else{var t=o(w,y);return hextopem(t,\"ENCRYPTED PRIVATE KEY\")}}if(D==\"PKCS8PRV\"&&r!==undefined&&b instanceof r&&b.isPrivate==true){var g=new l({seq:[{\"int\":1},{octstr:{hex:b.prvKeyHex}},{tag:[\"a1\",true,{bitstr:{hex:\"00\"+b.pubKeyHex}}]}]});var d=g.getEncodedHex();var E=l({seq:[{\"int\":0},{seq:[{oid:{name:\"ecPublicKey\"}},{oid:{name:b.curveName}}]},{octstr:{hex:d}}]});var w=E.getEncodedHex();if(y===undefined||y==null){return hextopem(w,\"PRIVATE KEY\")}else{var t=o(w,y);return hextopem(t,\"ENCRYPTED PRIVATE KEY\")}}if(D==\"PKCS8PRV\"&&u!==undefined&&b instanceof u&&b.isPrivate==true){var g=new f({bigint:b.x});var d=g.getEncodedHex();var E=l({seq:[{\"int\":0},{seq:[{oid:{name:\"dsa\"}},{seq:[{\"int\":{bigint:b.p}},{\"int\":{bigint:b.q}},{\"int\":{bigint:b.g}}]}]},{octstr:{hex:d}}]});var w=E.getEncodedHex();if(y===undefined||y==null){return hextopem(w,\"PRIVATE KEY\")}else{var t=o(w,y);return hextopem(t,\"ENCRYPTED PRIVATE KEY\")}}throw\"unsupported object nor format\"};KEYUTIL.getKeyFromCSRPEM=function(b){var a=pemtohex(b,\"CERTIFICATE REQUEST\");var c=KEYUTIL.getKeyFromCSRHex(a);return c};KEYUTIL.getKeyFromCSRHex=function(a){var c=KEYUTIL.parseCSRHex(a);var b=KEYUTIL.getKey(c.p8pubkeyhex,null,\"pkcs8pub\");return b};KEYUTIL.parseCSRHex=function(d){var i=ASN1HEX;var f=i.getChildIdx;var c=i.getTLV;var b={};var g=d;if(g.substr(0,2)!=\"30\"){throw\"malformed CSR(code:001)\"}var e=f(g,0);if(e.length<1){throw\"malformed CSR(code:002)\"}if(g.substr(e[0],2)!=\"30\"){throw\"malformed CSR(code:003)\"}var a=f(g,e[0]);if(a.length<3){throw\"malformed CSR(code:004)\"}b.p8pubkeyhex=c(g,a[2]);return b};KEYUTIL.getJWKFromKey=function(d){var b={};if(d instanceof RSAKey&&d.isPrivate){b.kty=\"RSA\";b.n=hextob64u(d.n.toString(16));b.e=hextob64u(d.e.toString(16));b.d=hextob64u(d.d.toString(16));b.p=hextob64u(d.p.toString(16));b.q=hextob64u(d.q.toString(16));b.dp=hextob64u(d.dmp1.toString(16));b.dq=hextob64u(d.dmq1.toString(16));b.qi=hextob64u(d.coeff.toString(16));return b}else{if(d instanceof RSAKey&&d.isPublic){b.kty=\"RSA\";b.n=hextob64u(d.n.toString(16));b.e=hextob64u(d.e.toString(16));return b}else{if(d instanceof KJUR.crypto.ECDSA&&d.isPrivate){var a=d.getShortNISTPCurveName();if(a!==\"P-256\"&&a!==\"P-384\"){throw\"unsupported curve name for JWT: \"+a}var c=d.getPublicKeyXYHex();b.kty=\"EC\";b.crv=a;b.x=hextob64u(c.x);b.y=hextob64u(c.y);b.d=hextob64u(d.prvKeyHex);return b}else{if(d instanceof KJUR.crypto.ECDSA&&d.isPublic){var a=d.getShortNISTPCurveName();if(a!==\"P-256\"&&a!==\"P-384\"){throw\"unsupported curve name for JWT: \"+a}var c=d.getPublicKeyXYHex();b.kty=\"EC\";b.crv=a;b.x=hextob64u(c.x);b.y=hextob64u(c.y);return b}}}}throw\"not supported key object\"};\nRSAKey.getPosArrayOfChildrenFromHex=function(a){return ASN1HEX.getChildIdx(a,0)};RSAKey.getHexValueArrayOfChildrenFromHex=function(f){var n=ASN1HEX;var i=n.getV;var k=RSAKey.getPosArrayOfChildrenFromHex(f);var e=i(f,k[0]);var j=i(f,k[1]);var b=i(f,k[2]);var c=i(f,k[3]);var h=i(f,k[4]);var g=i(f,k[5]);var m=i(f,k[6]);var l=i(f,k[7]);var d=i(f,k[8]);var k=new Array();k.push(e,j,b,c,h,g,m,l,d);return k};RSAKey.prototype.readPrivateKeyFromPEMString=function(d){var c=pemtohex(d);var b=RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1],b[2],b[3],b[4],b[5],b[6],b[7],b[8])};RSAKey.prototype.readPKCS5PrvKeyHex=function(c){var b=RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1],b[2],b[3],b[4],b[5],b[6],b[7],b[8])};RSAKey.prototype.readPKCS8PrvKeyHex=function(e){var c,j,l,b,a,f,d,k;var m=ASN1HEX;var g=m.getVbyList;if(m.isASN1HEX(e)===false){throw\"not ASN.1 hex string\"}try{c=g(e,0,[2,0,1],\"02\");j=g(e,0,[2,0,2],\"02\");l=g(e,0,[2,0,3],\"02\");b=g(e,0,[2,0,4],\"02\");a=g(e,0,[2,0,5],\"02\");f=g(e,0,[2,0,6],\"02\");d=g(e,0,[2,0,7],\"02\");k=g(e,0,[2,0,8],\"02\")}catch(i){throw\"malformed PKCS#8 plain RSA private key\"}this.setPrivateEx(c,j,l,b,a,f,d,k)};RSAKey.prototype.readPKCS5PubKeyHex=function(c){var e=ASN1HEX;var b=e.getV;if(e.isASN1HEX(c)===false){throw\"keyHex is not ASN.1 hex string\"}var a=e.getChildIdx(c,0);if(a.length!==2||c.substr(a[0],2)!==\"02\"||c.substr(a[1],2)!==\"02\"){throw\"wrong hex for PKCS#5 public key\"}var f=b(c,a[0]);var d=b(c,a[1]);this.setPublic(f,d)};RSAKey.prototype.readPKCS8PubKeyHex=function(b){var c=ASN1HEX;if(c.isASN1HEX(b)===false){throw\"not ASN.1 hex string\"}if(c.getTLVbyList(b,0,[0,0])!==\"06092a864886f70d010101\"){throw\"not PKCS8 RSA public key\"}var a=c.getTLVbyList(b,0,[1,0]);this.readPKCS5PubKeyHex(a)};RSAKey.prototype.readCertPubKeyHex=function(b,d){var a,c;a=new X509();a.readCertHex(b);c=a.getPublicKeyHex();this.readPKCS8PubKeyHex(c)};\nvar _RE_HEXDECONLY=new RegExp(\"\");_RE_HEXDECONLY.compile(\"[^0-9a-f]\",\"gi\");function _rsasign_getHexPaddedDigestInfoForString(d,e,a){var b=function(f){return KJUR.crypto.Util.hashString(f,a)};var c=b(d);return KJUR.crypto.Util.getPaddedDigestInfoHex(c,a,e)}function _zeroPaddingOfSignature(e,d){var c=\"\";var a=d/4-e.length;for(var b=0;b<a;b++){c=c+\"0\"}return c+e}RSAKey.prototype.sign=function(d,a){var b=function(e){return KJUR.crypto.Util.hashString(e,a)};var c=b(d);return this.signWithMessageHash(c,a)};RSAKey.prototype.signWithMessageHash=function(e,c){var f=KJUR.crypto.Util.getPaddedDigestInfoHex(e,c,this.n.bitLength());var b=parseBigInt(f,16);var d=this.doPrivate(b);var a=d.toString(16);return _zeroPaddingOfSignature(a,this.n.bitLength())};function pss_mgf1_str(c,a,e){var b=\"\",d=0;while(b.length<a){b+=hextorstr(e(rstrtohex(c+String.fromCharCode.apply(String,[(d&4278190080)>>24,(d&16711680)>>16,(d&65280)>>8,d&255]))));d+=1}return b}RSAKey.prototype.signPSS=function(e,a,d){var c=function(f){return KJUR.crypto.Util.hashHex(f,a)};var b=c(rstrtohex(e));if(d===undefined){d=-1}return this.signWithMessageHashPSS(b,a,d)};RSAKey.prototype.signWithMessageHashPSS=function(l,a,k){var b=hextorstr(l);var g=b.length;var m=this.n.bitLength()-1;var c=Math.ceil(m/8);var d;var o=function(i){return KJUR.crypto.Util.hashHex(i,a)};if(k===-1||k===undefined){k=g}else{if(k===-2){k=c-g-2}else{if(k<-2){throw\"invalid salt length\"}}}if(c<(g+k+2)){throw\"data too long\"}var f=\"\";if(k>0){f=new Array(k);new SecureRandom().nextBytes(f);f=String.fromCharCode.apply(String,f)}var n=hextorstr(o(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"+b+f)));var j=[];for(d=0;d<c-k-g-2;d+=1){j[d]=0}var e=String.fromCharCode.apply(String,j)+\"\\x01\"+f;var h=pss_mgf1_str(n,e.length,o);var q=[];for(d=0;d<e.length;d+=1){q[d]=e.charCodeAt(d)^h.charCodeAt(d)}var p=(65280>>(8*c-m))&255;q[0]&=~p;for(d=0;d<g;d++){q.push(n.charCodeAt(d))}q.push(188);return _zeroPaddingOfSignature(this.doPrivate(new BigInteger(q)).toString(16),this.n.bitLength())};function _rsasign_getDecryptSignatureBI(a,d,c){var b=new RSAKey();b.setPublic(d,c);var e=b.doPublic(a);return e}function _rsasign_getHexDigestInfoFromSig(a,c,b){var e=_rsasign_getDecryptSignatureBI(a,c,b);var d=e.toString(16).replace(/^1f+00/,\"\");return d}function _rsasign_getAlgNameAndHashFromHexDisgestInfo(f){for(var e in KJUR.crypto.Util.DIGESTINFOHEAD){var d=KJUR.crypto.Util.DIGESTINFOHEAD[e];var b=d.length;if(f.substring(0,b)==d){var c=[e,f.substring(b)];return c}}return[]}RSAKey.prototype.verify=function(f,j){j=j.replace(_RE_HEXDECONLY,\"\");j=j.replace(/[ \\n]+/g,\"\");var b=parseBigInt(j,16);if(b.bitLength()>this.n.bitLength()){return 0}var i=this.doPublic(b);var e=i.toString(16).replace(/^1f+00/,\"\");var g=_rsasign_getAlgNameAndHashFromHexDisgestInfo(e);if(g.length==0){return false}var d=g[0];var h=g[1];var a=function(k){return KJUR.crypto.Util.hashString(k,d)};var c=a(f);return(h==c)};RSAKey.prototype.verifyWithMessageHash=function(e,a){a=a.replace(_RE_HEXDECONLY,\"\");a=a.replace(/[ \\n]+/g,\"\");var b=parseBigInt(a,16);if(b.bitLength()>this.n.bitLength()){return 0}var h=this.doPublic(b);var g=h.toString(16).replace(/^1f+00/,\"\");var c=_rsasign_getAlgNameAndHashFromHexDisgestInfo(g);if(c.length==0){return false}var d=c[0];var f=c[1];return(f==e)};RSAKey.prototype.verifyPSS=function(c,b,a,f){var e=function(g){return KJUR.crypto.Util.hashHex(g,a)};var d=e(rstrtohex(c));if(f===undefined){f=-1}return this.verifyWithMessageHashPSS(d,b,a,f)};RSAKey.prototype.verifyWithMessageHashPSS=function(f,s,l,c){var k=new BigInteger(s,16);if(k.bitLength()>this.n.bitLength()){return false}var r=function(i){return KJUR.crypto.Util.hashHex(i,l)};var j=hextorstr(f);var h=j.length;var g=this.n.bitLength()-1;var m=Math.ceil(g/8);var q;if(c===-1||c===undefined){c=h}else{if(c===-2){c=m-h-2}else{if(c<-2){throw\"invalid salt length\"}}}if(m<(h+c+2)){throw\"data too long\"}var a=this.doPublic(k).toByteArray();for(q=0;q<a.length;q+=1){a[q]&=255}while(a.length<m){a.unshift(0)}if(a[m-1]!==188){throw\"encoded message does not end in 0xbc\"}a=String.fromCharCode.apply(String,a);var d=a.substr(0,m-h-1);var e=a.substr(d.length,h);var p=(65280>>(8*m-g))&255;if((d.charCodeAt(0)&p)!==0){throw\"bits beyond keysize not zero\"}var n=pss_mgf1_str(e,d.length,r);var o=[];for(q=0;q<d.length;q+=1){o[q]=d.charCodeAt(q)^n.charCodeAt(q)}o[0]&=~p;var b=m-h-c-2;for(q=0;q<b;q+=1){if(o[q]!==0){throw\"leftmost octets not zero\"}}if(o[b]!==1){throw\"0x01 marker not found\"}return e===hextorstr(r(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"+j+String.fromCharCode.apply(String,o.slice(-c)))))};RSAKey.SALT_LEN_HLEN=-1;RSAKey.SALT_LEN_MAX=-2;RSAKey.SALT_LEN_RECOVER=-2;\nfunction X509(){var k=ASN1HEX,j=k.getChildIdx,h=k.getV,b=k.getTLV,f=k.getVbyList,c=k.getTLVbyList,g=k.getIdxbyList,d=k.getVidx,i=k.oidname,a=X509,e=pemtohex;this.hex=null;this.version=0;this.foffset=0;this.aExtInfo=null;this.getVersion=function(){if(this.hex===null||this.version!==0){return this.version}if(c(this.hex,0,[0,0])!==\"a003020102\"){this.version=1;this.foffset=-1;return 1}this.version=3;return 3};this.getSerialNumberHex=function(){return f(this.hex,0,[0,1+this.foffset],\"02\")};this.getSignatureAlgorithmField=function(){return i(f(this.hex,0,[0,2+this.foffset,0],\"06\"))};this.getIssuerHex=function(){return c(this.hex,0,[0,3+this.foffset],\"30\")};this.getIssuerString=function(){return a.hex2dn(this.getIssuerHex())};this.getSubjectHex=function(){return c(this.hex,0,[0,5+this.foffset],\"30\")};this.getSubjectString=function(){return a.hex2dn(this.getSubjectHex())};this.getNotBefore=function(){var l=f(this.hex,0,[0,4+this.foffset,0]);l=l.replace(/(..)/g,\"%$1\");l=decodeURIComponent(l);return l};this.getNotAfter=function(){var l=f(this.hex,0,[0,4+this.foffset,1]);l=l.replace(/(..)/g,\"%$1\");l=decodeURIComponent(l);return l};this.getPublicKeyHex=function(){return k.getTLVbyList(this.hex,0,[0,6+this.foffset],\"30\")};this.getPublicKeyIdx=function(){return g(this.hex,0,[0,6+this.foffset],\"30\")};this.getPublicKeyContentIdx=function(){var l=this.getPublicKeyIdx();return g(this.hex,l,[1,0],\"30\")};this.getPublicKey=function(){return KEYUTIL.getKey(this.getPublicKeyHex(),null,\"pkcs8pub\")};this.getSignatureAlgorithmName=function(){return i(f(this.hex,0,[1,0],\"06\"))};this.getSignatureValueHex=function(){return f(this.hex,0,[2],\"03\",true)};this.verifySignature=function(n){var o=this.getSignatureAlgorithmName();var l=this.getSignatureValueHex();var m=c(this.hex,0,[0],\"30\");var p=new KJUR.crypto.Signature({alg:o});p.init(n);p.updateHex(m);return p.verify(l)};this.parseExt=function(){if(this.version!==3){return -1}var p=g(this.hex,0,[0,7,0],\"30\");var m=j(this.hex,p);this.aExtInfo=new Array();for(var n=0;n<m.length;n++){var q={};q.critical=false;var l=j(this.hex,m[n]);var r=0;if(l.length===3){q.critical=true;r=1}q.oid=k.hextooidstr(f(this.hex,m[n],[0],\"06\"));var o=g(this.hex,m[n],[1+r]);q.vidx=d(this.hex,o);this.aExtInfo.push(q)}};this.getExtInfo=function(n){var l=this.aExtInfo;var o=n;if(!n.match(/^[0-9.]+$/)){o=KJUR.asn1.x509.OID.name2oid(n)}if(o===\"\"){return undefined}for(var m=0;m<l.length;m++){if(l[m].oid===o){return l[m]}}return undefined};this.getExtBasicConstraints=function(){var n=this.getExtInfo(\"basicConstraints\");if(n===undefined){return n}var l=h(this.hex,n.vidx);if(l===\"\"){return{}}if(l===\"0101ff\"){return{cA:true}}if(l.substr(0,8)===\"0101ff02\"){var o=h(l,6);var m=parseInt(o,16);return{cA:true,pathLen:m}}throw\"basicConstraints parse error\"};this.getExtKeyUsageBin=function(){var o=this.getExtInfo(\"keyUsage\");if(o===undefined){return\"\"}var m=h(this.hex,o.vidx);if(m.length%2!=0||m.length<=2){throw\"malformed key usage value\"}var l=parseInt(m.substr(0,2));var n=parseInt(m.substr(2),16).toString(2);return n.substr(0,n.length-l)};this.getExtKeyUsageString=function(){var n=this.getExtKeyUsageBin();var l=new Array();for(var m=0;m<n.length;m++){if(n.substr(m,1)==\"1\"){l.push(X509.KEYUSAGE_NAME[m])}}return l.join(\",\")};this.getExtSubjectKeyIdentifier=function(){var l=this.getExtInfo(\"subjectKeyIdentifier\");if(l===undefined){return l}return h(this.hex,l.vidx)};this.getExtAuthorityKeyIdentifier=function(){var p=this.getExtInfo(\"authorityKeyIdentifier\");if(p===undefined){return p}var l={};var o=b(this.hex,p.vidx);var m=j(o,0);for(var n=0;n<m.length;n++){if(o.substr(m[n],2)===\"80\"){l.kid=h(o,m[n])}}return l};this.getExtExtKeyUsageName=function(){var p=this.getExtInfo(\"extKeyUsage\");if(p===undefined){return p}var l=new Array();var o=b(this.hex,p.vidx);if(o===\"\"){return l}var m=j(o,0);for(var n=0;n<m.length;n++){l.push(i(h(o,m[n])))}return l};this.getExtSubjectAltName=function(){var m=this.getExtSubjectAltName2();var l=new Array();for(var n=0;n<m.length;n++){if(m[n][0]===\"DNS\"){l.push(m[n][1])}}return l};this.getExtSubjectAltName2=function(){var p,s,r;var q=this.getExtInfo(\"subjectAltName\");if(q===undefined){return q}var l=new Array();var o=b(this.hex,q.vidx);var m=j(o,0);for(var n=0;n<m.length;n++){r=o.substr(m[n],2);p=h(o,m[n]);if(r===\"81\"){s=hextoutf8(p);l.push([\"MAIL\",s])}if(r===\"82\"){s=hextoutf8(p);l.push([\"DNS\",s])}if(r===\"84\"){s=X509.hex2dn(p,0);l.push([\"DN\",s])}if(r===\"86\"){s=hextoutf8(p);l.push([\"URI\",s])}if(r===\"87\"){s=hextoip(p);l.push([\"IP\",s])}}return l};this.getExtCRLDistributionPointsURI=function(){var q=this.getExtInfo(\"cRLDistributionPoints\");if(q===undefined){return q}var l=new Array();var m=j(this.hex,q.vidx);for(var o=0;o<m.length;o++){try{var r=f(this.hex,m[o],[0,0,0],\"86\");var p=hextoutf8(r);l.push(p)}catch(n){}}return l};this.getExtAIAInfo=function(){var p=this.getExtInfo(\"authorityInfoAccess\");if(p===undefined){return p}var l={ocsp:[],caissuer:[]};var m=j(this.hex,p.vidx);for(var n=0;n<m.length;n++){var q=f(this.hex,m[n],[0],\"06\");var o=f(this.hex,m[n],[1],\"86\");if(q===\"2b06010505073001\"){l.ocsp.push(hextoutf8(o))}if(q===\"2b06010505073002\"){l.caissuer.push(hextoutf8(o))}}return l};this.getExtCertificatePolicies=function(){var o=this.getExtInfo(\"certificatePolicies\");if(o===undefined){return o}var l=b(this.hex,o.vidx);var u=[];var s=j(l,0);for(var r=0;r<s.length;r++){var t={};var n=j(l,s[r]);t.id=i(h(l,n[0]));if(n.length===2){var m=j(l,n[1]);for(var q=0;q<m.length;q++){var p=f(l,m[q],[0],\"06\");if(p===\"2b06010505070201\"){t.cps=hextoutf8(f(l,m[q],[1]))}else{if(p===\"2b06010505070202\"){t.unotice=hextoutf8(f(l,m[q],[1,0]))}}}}u.push(t)}return u};this.readCertPEM=function(l){this.readCertHex(e(l))};this.readCertHex=function(l){this.hex=l;this.getVersion();try{g(this.hex,0,[0,7],\"a3\");this.parseExt()}catch(m){}};this.getInfo=function(){var m=X509;var B,u,z;B=\"Basic Fields\\n\";B+=\"  serial number: \"+this.getSerialNumberHex()+\"\\n\";B+=\"  signature algorithm: \"+this.getSignatureAlgorithmField()+\"\\n\";B+=\"  issuer: \"+this.getIssuerString()+\"\\n\";B+=\"  notBefore: \"+this.getNotBefore()+\"\\n\";B+=\"  notAfter: \"+this.getNotAfter()+\"\\n\";B+=\"  subject: \"+this.getSubjectString()+\"\\n\";B+=\"  subject public key info: \\n\";u=this.getPublicKey();B+=\"    key algorithm: \"+u.type+\"\\n\";if(u.type===\"RSA\"){B+=\"    n=\"+hextoposhex(u.n.toString(16)).substr(0,16)+\"...\\n\";B+=\"    e=\"+hextoposhex(u.e.toString(16))+\"\\n\"}z=this.aExtInfo;if(z!==undefined&&z!==null){B+=\"X509v3 Extensions:\\n\";for(var r=0;r<z.length;r++){var n=z[r];var A=KJUR.asn1.x509.OID.oid2name(n.oid);if(A===\"\"){A=n.oid}var x=\"\";if(n.critical===true){x=\"CRITICAL\"}B+=\"  \"+A+\" \"+x+\":\\n\";if(A===\"basicConstraints\"){var v=this.getExtBasicConstraints();if(v.cA===undefined){B+=\"    {}\\n\"}else{B+=\"    cA=true\";if(v.pathLen!==undefined){B+=\", pathLen=\"+v.pathLen}B+=\"\\n\"}}else{if(A===\"keyUsage\"){B+=\"    \"+this.getExtKeyUsageString()+\"\\n\"}else{if(A===\"subjectKeyIdentifier\"){B+=\"    \"+this.getExtSubjectKeyIdentifier()+\"\\n\"}else{if(A===\"authorityKeyIdentifier\"){var l=this.getExtAuthorityKeyIdentifier();if(l.kid!==undefined){B+=\"    kid=\"+l.kid+\"\\n\"}}else{if(A===\"extKeyUsage\"){var w=this.getExtExtKeyUsageName();B+=\"    \"+w.join(\", \")+\"\\n\"}else{if(A===\"subjectAltName\"){var t=this.getExtSubjectAltName2();B+=\"    \"+t+\"\\n\"}else{if(A===\"cRLDistributionPoints\"){var y=this.getExtCRLDistributionPointsURI();B+=\"    \"+y+\"\\n\"}else{if(A===\"authorityInfoAccess\"){var p=this.getExtAIAInfo();if(p.ocsp!==undefined){B+=\"    ocsp: \"+p.ocsp.join(\",\")+\"\\n\"}if(p.caissuer!==undefined){B+=\"    caissuer: \"+p.caissuer.join(\",\")+\"\\n\"}}else{if(A===\"certificatePolicies\"){var o=this.getExtCertificatePolicies();for(var q=0;q<o.length;q++){if(o[q].id!==undefined){B+=\"    policy oid: \"+o[q].id+\"\\n\"}if(o[q].cps!==undefined){B+=\"    cps: \"+o[q].cps+\"\\n\"}}}}}}}}}}}}}B+=\"signature algorithm: \"+this.getSignatureAlgorithmName()+\"\\n\";B+=\"signature: \"+this.getSignatureValueHex().substr(0,16)+\"...\\n\";return B}}X509.hex2dn=function(f,b){if(b===undefined){b=0}if(f.substr(b,2)!==\"30\"){throw\"malformed DN\"}var c=new Array();var d=ASN1HEX.getChildIdx(f,b);for(var e=0;e<d.length;e++){c.push(X509.hex2rdn(f,d[e]))}c=c.map(function(a){return a.replace(\"/\",\"\\\\/\")});return\"/\"+c.join(\"/\")};X509.hex2rdn=function(f,b){if(b===undefined){b=0}if(f.substr(b,2)!==\"31\"){throw\"malformed RDN\"}var c=new Array();var d=ASN1HEX.getChildIdx(f,b);for(var e=0;e<d.length;e++){c.push(X509.hex2attrTypeValue(f,d[e]))}c=c.map(function(a){return a.replace(\"+\",\"\\\\+\")});return c.join(\"+\")};X509.hex2attrTypeValue=function(d,i){var j=ASN1HEX;var h=j.getV;if(i===undefined){i=0}if(d.substr(i,2)!==\"30\"){throw\"malformed attribute type and value\"}var g=j.getChildIdx(d,i);if(g.length!==2||d.substr(g[0],2)!==\"06\"){\"malformed attribute type and value\"}var b=h(d,g[0]);var f=KJUR.asn1.ASN1Util.oidHexToInt(b);var e=KJUR.asn1.x509.OID.oid2atype(f);var a=h(d,g[1]);var c=hextorstr(a);return e+\"=\"+c};X509.getPublicKeyFromCertHex=function(b){var a=new X509();a.readCertHex(b);return a.getPublicKey()};X509.getPublicKeyFromCertPEM=function(b){var a=new X509();a.readCertPEM(b);return a.getPublicKey()};X509.getPublicKeyInfoPropOfCertPEM=function(c){var e=ASN1HEX;var g=e.getVbyList;var b={};var a,f,d;b.algparam=null;a=new X509();a.readCertPEM(c);f=a.getPublicKeyHex();b.keyhex=g(f,0,[1],\"03\").substr(2);b.algoid=g(f,0,[0,0],\"06\");if(b.algoid===\"2a8648ce3d0201\"){b.algparam=g(f,0,[0,1],\"06\")}return b};X509.KEYUSAGE_NAME=[\"digitalSignature\",\"nonRepudiation\",\"keyEncipherment\",\"dataEncipherment\",\"keyAgreement\",\"keyCertSign\",\"cRLSign\",\"encipherOnly\",\"decipherOnly\"];\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.jws==\"undefined\"||!KJUR.jws){KJUR.jws={}}KJUR.jws.JWS=function(){var b=KJUR,a=b.jws.JWS,c=a.isSafeJSONString;this.parseJWS=function(g,j){if((this.parsedJWS!==undefined)&&(j||(this.parsedJWS.sigvalH!==undefined))){return}var i=g.match(/^([^.]+)\\.([^.]+)\\.([^.]+)$/);if(i==null){throw\"JWS signature is not a form of 'Head.Payload.SigValue'.\"}var k=i[1];var e=i[2];var l=i[3];var n=k+\".\"+e;this.parsedJWS={};this.parsedJWS.headB64U=k;this.parsedJWS.payloadB64U=e;this.parsedJWS.sigvalB64U=l;this.parsedJWS.si=n;if(!j){var h=b64utohex(l);var f=parseBigInt(h,16);this.parsedJWS.sigvalH=h;this.parsedJWS.sigvalBI=f}var d=b64utoutf8(k);var m=b64utoutf8(e);this.parsedJWS.headS=d;this.parsedJWS.payloadS=m;if(!c(d,this.parsedJWS,\"headP\")){throw\"malformed JSON string for JWS Head: \"+d}}};KJUR.jws.JWS.sign=function(i,v,y,z,a){var w=KJUR,m=w.jws,q=m.JWS,g=q.readSafeJSONString,p=q.isSafeJSONString,d=w.crypto,k=d.ECDSA,o=d.Mac,c=d.Signature,t=JSON;var s,j,n;if(typeof v!=\"string\"&&typeof v!=\"object\"){throw\"spHeader must be JSON string or object: \"+v}if(typeof v==\"object\"){j=v;s=t.stringify(j)}if(typeof v==\"string\"){s=v;if(!p(s)){throw\"JWS Head is not safe JSON string: \"+s}j=g(s)}n=y;if(typeof y==\"object\"){n=t.stringify(y)}if((i==\"\"||i==null)&&j.alg!==undefined){i=j.alg}if((i!=\"\"&&i!=null)&&j.alg===undefined){j.alg=i;s=t.stringify(j)}if(i!==j.alg){throw\"alg and sHeader.alg doesn't match: \"+i+\"!=\"+j.alg}var r=null;if(q.jwsalg2sigalg[i]===undefined){throw\"unsupported alg name: \"+i}else{r=q.jwsalg2sigalg[i]}var e=utf8tob64u(s);var l=utf8tob64u(n);var b=e+\".\"+l;var x=\"\";if(r.substr(0,4)==\"Hmac\"){if(z===undefined){throw\"mac key shall be specified for HS* alg\"}var h=new o({alg:r,prov:\"cryptojs\",pass:z});h.updateString(b);x=h.doFinal()}else{if(r.indexOf(\"withECDSA\")!=-1){var f=new c({alg:r});f.init(z,a);f.updateString(b);hASN1Sig=f.sign();x=KJUR.crypto.ECDSA.asn1SigToConcatSig(hASN1Sig)}else{if(r!=\"none\"){var f=new c({alg:r});f.init(z,a);f.updateString(b);x=f.sign()}}}var u=hextob64u(x);return b+\".\"+u};KJUR.jws.JWS.verify=function(w,B,n){var x=KJUR,q=x.jws,t=q.JWS,i=t.readSafeJSONString,e=x.crypto,p=e.ECDSA,s=e.Mac,d=e.Signature,m;if(typeof RSAKey!==undefined){m=RSAKey}var y=w.split(\".\");if(y.length!==3){return false}var f=y[0];var r=y[1];var c=f+\".\"+r;var A=b64utohex(y[2]);var l=i(b64utoutf8(y[0]));var k=null;var z=null;if(l.alg===undefined){throw\"algorithm not specified in header\"}else{k=l.alg;z=k.substr(0,2)}if(n!=null&&Object.prototype.toString.call(n)===\"[object Array]\"&&n.length>0){var b=\":\"+n.join(\":\")+\":\";if(b.indexOf(\":\"+k+\":\")==-1){throw\"algorithm '\"+k+\"' not accepted in the list\"}}if(k!=\"none\"&&B===null){throw\"key shall be specified to verify.\"}if(typeof B==\"string\"&&B.indexOf(\"-----BEGIN \")!=-1){B=KEYUTIL.getKey(B)}if(z==\"RS\"||z==\"PS\"){if(!(B instanceof m)){throw\"key shall be a RSAKey obj for RS* and PS* algs\"}}if(z==\"ES\"){if(!(B instanceof p)){throw\"key shall be a ECDSA obj for ES* algs\"}}if(k==\"none\"){}var u=null;if(t.jwsalg2sigalg[l.alg]===undefined){throw\"unsupported alg name: \"+k}else{u=t.jwsalg2sigalg[k]}if(u==\"none\"){throw\"not supported\"}else{if(u.substr(0,4)==\"Hmac\"){var o=null;if(B===undefined){throw\"hexadecimal key shall be specified for HMAC\"}var j=new s({alg:u,pass:B});j.updateString(c);o=j.doFinal();return A==o}else{if(u.indexOf(\"withECDSA\")!=-1){var h=null;try{h=p.concatSigToASN1Sig(A)}catch(v){return false}var g=new d({alg:u});g.init(B);g.updateString(c);return g.verify(h)}else{var g=new d({alg:u});g.init(B);g.updateString(c);return g.verify(A)}}}};KJUR.jws.JWS.parse=function(g){var c=g.split(\".\");var b={};var f,e,d;if(c.length!=2&&c.length!=3){throw\"malformed sJWS: wrong number of '.' splitted elements\"}f=c[0];e=c[1];if(c.length==3){d=c[2]}b.headerObj=KJUR.jws.JWS.readSafeJSONString(b64utoutf8(f));b.payloadObj=KJUR.jws.JWS.readSafeJSONString(b64utoutf8(e));b.headerPP=JSON.stringify(b.headerObj,null,\"  \");if(b.payloadObj==null){b.payloadPP=b64utoutf8(e)}else{b.payloadPP=JSON.stringify(b.payloadObj,null,\"  \")}if(d!==undefined){b.sigHex=b64utohex(d)}return b};KJUR.jws.JWS.verifyJWT=function(e,l,r){var d=KJUR,j=d.jws,o=j.JWS,n=o.readSafeJSONString,p=o.inArray,f=o.includedArray;var k=e.split(\".\");var c=k[0];var i=k[1];var q=c+\".\"+i;var m=b64utohex(k[2]);var h=n(b64utoutf8(c));var g=n(b64utoutf8(i));if(h.alg===undefined){return false}if(r.alg===undefined){throw\"acceptField.alg shall be specified\"}if(!p(h.alg,r.alg)){return false}if(g.iss!==undefined&&typeof r.iss===\"object\"){if(!p(g.iss,r.iss)){return false}}if(g.sub!==undefined&&typeof r.sub===\"object\"){if(!p(g.sub,r.sub)){return false}}if(g.aud!==undefined&&typeof r.aud===\"object\"){if(typeof g.aud==\"string\"){if(!p(g.aud,r.aud)){return false}}else{if(typeof g.aud==\"object\"){if(!f(g.aud,r.aud)){return false}}}}var b=j.IntDate.getNow();if(r.verifyAt!==undefined&&typeof r.verifyAt===\"number\"){b=r.verifyAt}if(r.gracePeriod===undefined||typeof r.gracePeriod!==\"number\"){r.gracePeriod=0}if(g.exp!==undefined&&typeof g.exp==\"number\"){if(g.exp+r.gracePeriod<b){return false}}if(g.nbf!==undefined&&typeof g.nbf==\"number\"){if(b<g.nbf-r.gracePeriod){return false}}if(g.iat!==undefined&&typeof g.iat==\"number\"){if(b<g.iat-r.gracePeriod){return false}}if(g.jti!==undefined&&r.jti!==undefined){if(g.jti!==r.jti){return false}}if(!o.verify(e,l,r.alg)){return false}return true};KJUR.jws.JWS.includedArray=function(b,a){var c=KJUR.jws.JWS.inArray;if(b===null){return false}if(typeof b!==\"object\"){return false}if(typeof b.length!==\"number\"){return false}for(var d=0;d<b.length;d++){if(!c(b[d],a)){return false}}return true};KJUR.jws.JWS.inArray=function(d,b){if(b===null){return false}if(typeof b!==\"object\"){return false}if(typeof b.length!==\"number\"){return false}for(var c=0;c<b.length;c++){if(b[c]==d){return true}}return false};KJUR.jws.JWS.jwsalg2sigalg={HS256:\"HmacSHA256\",HS384:\"HmacSHA384\",HS512:\"HmacSHA512\",RS256:\"SHA256withRSA\",RS384:\"SHA384withRSA\",RS512:\"SHA512withRSA\",ES256:\"SHA256withECDSA\",ES384:\"SHA384withECDSA\",PS256:\"SHA256withRSAandMGF1\",PS384:\"SHA384withRSAandMGF1\",PS512:\"SHA512withRSAandMGF1\",none:\"none\",};KJUR.jws.JWS.isSafeJSONString=function(c,b,d){var e=null;try{e=jsonParse(c);if(typeof e!=\"object\"){return 0}if(e.constructor===Array){return 0}if(b){b[d]=e}return 1}catch(a){return 0}};KJUR.jws.JWS.readSafeJSONString=function(b){var c=null;try{c=jsonParse(b);if(typeof c!=\"object\"){return null}if(c.constructor===Array){return null}return c}catch(a){return null}};KJUR.jws.JWS.getEncodedSignatureValueFromJWS=function(b){var a=b.match(/^[^.]+\\.[^.]+\\.([^.]+)$/);if(a==null){throw\"JWS signature is not a form of 'Head.Payload.SigValue'.\"}return a[1]};KJUR.jws.JWS.getJWKthumbprint=function(d){if(d.kty!==\"RSA\"&&d.kty!==\"EC\"&&d.kty!==\"oct\"){throw\"unsupported algorithm for JWK Thumprint\"}var a=\"{\";if(d.kty===\"RSA\"){if(typeof d.n!=\"string\"||typeof d.e!=\"string\"){throw\"wrong n and e value for RSA key\"}a+='\"e\":\"'+d.e+'\",';a+='\"kty\":\"'+d.kty+'\",';a+='\"n\":\"'+d.n+'\"}'}else{if(d.kty===\"EC\"){if(typeof d.crv!=\"string\"||typeof d.x!=\"string\"||typeof d.y!=\"string\"){throw\"wrong crv, x and y value for EC key\"}a+='\"crv\":\"'+d.crv+'\",';a+='\"kty\":\"'+d.kty+'\",';a+='\"x\":\"'+d.x+'\",';a+='\"y\":\"'+d.y+'\"}'}else{if(d.kty===\"oct\"){if(typeof d.k!=\"string\"){throw\"wrong k value for oct(symmetric) key\"}a+='\"kty\":\"'+d.kty+'\",';a+='\"k\":\"'+d.k+'\"}'}}}var b=rstrtohex(a);var c=KJUR.crypto.Util.hashHex(b,\"sha256\");var e=hextob64u(c);return e};KJUR.jws.IntDate={};KJUR.jws.IntDate.get=function(c){var b=KJUR.jws.IntDate,d=b.getNow,a=b.getZulu;if(c==\"now\"){return d()}else{if(c==\"now + 1hour\"){return d()+60*60}else{if(c==\"now + 1day\"){return d()+60*60*24}else{if(c==\"now + 1month\"){return d()+60*60*24*30}else{if(c==\"now + 1year\"){return d()+60*60*24*365}else{if(c.match(/Z$/)){return a(c)}else{if(c.match(/^[0-9]+$/)){return parseInt(c)}}}}}}}throw\"unsupported format: \"+c};KJUR.jws.IntDate.getZulu=function(a){return zulutosec(a)};KJUR.jws.IntDate.getNow=function(){var a=~~(new Date()/1000);return a};KJUR.jws.IntDate.intDate2UTCString=function(a){var b=new Date(a*1000);return b.toUTCString()};KJUR.jws.IntDate.intDate2Zulu=function(e){var i=new Date(e*1000),h=(\"0000\"+i.getUTCFullYear()).slice(-4),g=(\"00\"+(i.getUTCMonth()+1)).slice(-2),b=(\"00\"+i.getUTCDate()).slice(-2),a=(\"00\"+i.getUTCHours()).slice(-2),c=(\"00\"+i.getUTCMinutes()).slice(-2),f=(\"00\"+i.getUTCSeconds()).slice(-2);return h+g+b+a+c+f+\"Z\"};\nexport { SecureRandom };\r\nexport { rng_seed_time };\r\n\r\nexport { BigInteger };\r\nexport { RSAKey };\r\nexport const { EDSA } = KJUR.crypto;\r\nexport const { DSA } = KJUR.crypto;\r\nexport const { Signature } = KJUR.crypto;\r\nexport const { MessageDigest } =  KJUR.crypto;\r\nexport const { Mac } = KJUR.crypto;\r\nexport const { Cipher } =  KJUR.crypto;\r\nexport { KEYUTIL };\r\nexport { ASN1HEX };\r\nexport { X509 };\r\nexport { CryptoJS };\r\n\r\n// ext/base64.js\r\nexport { b64tohex };\r\nexport { b64toBA };\r\n\r\n// base64x.js\r\nexport { stoBA };\r\nexport { BAtos };\r\nexport { BAtohex };\r\nexport { stohex };\r\nexport { stob64 };\r\nexport { stob64u };\r\nexport { b64utos };\r\nexport { b64tob64u };\r\nexport { b64utob64 };\r\nexport { hex2b64 };\r\nexport { hextob64u };\r\nexport { b64utohex };\r\nexport { utf8tob64u };\r\nexport { b64utoutf8 };\r\nexport { utf8tob64 };\r\nexport { b64toutf8 };\r\nexport { utf8tohex };\r\nexport { hextoutf8 };\r\nexport { hextorstr };\r\nexport { rstrtohex };\r\nexport { hextob64 };\r\nexport { hextob64nl };\r\nexport { b64nltohex };\r\nexport { hextopem };\r\nexport { pemtohex };\r\nexport { hextoArrayBuffer };\r\nexport { ArrayBuffertohex };\r\nexport { zulutomsec };\r\nexport { zulutosec };\r\nexport { zulutodate };\r\nexport { datetozulu };\r\nexport { uricmptohex };\r\nexport { hextouricmp };\r\nexport { ipv6tohex };\r\nexport { hextoipv6 };\r\nexport { hextoip };\r\nexport { iptohex };\r\nexport { encodeURIComponentAll };\r\nexport { newline_toUnix };\r\nexport { newline_toDos };\r\nexport { hextoposhex };\r\nexport { intarystrtohex };\r\nexport { strdiffidx };\r\n\r\n// name spaces\r\nexport { KJUR };\r\nconst _crypto =  KJUR.crypto;\r\nexport { _crypto as crypto };\r\nexport const { asn1 } = KJUR;\r\nexport const { jws } = KJUR;\r\nexport const { lang } = KJUR;\r\n\r\n\r\n","'use strict'\n\nexports.byteLength = byteLength\nexports.toByteArray = toByteArray\nexports.fromByteArray = fromByteArray\n\nvar lookup = []\nvar revLookup = []\nvar Arr = typeof Uint8Array !== 'undefined' ? Uint8Array : Array\n\nvar code = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'\nfor (var i = 0, len = code.length; i < len; ++i) {\n  lookup[i] = code[i]\n  revLookup[code.charCodeAt(i)] = i\n}\n\n// Support decoding URL-safe base64 strings, as Node.js does.\n// See: https://en.wikipedia.org/wiki/Base64#URL_applications\nrevLookup['-'.charCodeAt(0)] = 62\nrevLookup['_'.charCodeAt(0)] = 63\n\nfunction getLens (b64) {\n  var len = b64.length\n\n  if (len % 4 > 0) {\n    throw new Error('Invalid string. Length must be a multiple of 4')\n  }\n\n  // Trim off extra bytes after placeholder bytes are found\n  // See: https://github.com/beatgammit/base64-js/issues/42\n  var validLen = b64.indexOf('=')\n  if (validLen === -1) validLen = len\n\n  var placeHoldersLen = validLen === len\n    ? 0\n    : 4 - (validLen % 4)\n\n  return [validLen, placeHoldersLen]\n}\n\n// base64 is 4/3 + up to two characters of the original data\nfunction byteLength (b64) {\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction _byteLength (b64, validLen, placeHoldersLen) {\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction toByteArray (b64) {\n  var tmp\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n\n  var arr = new Arr(_byteLength(b64, validLen, placeHoldersLen))\n\n  var curByte = 0\n\n  // if there are placeholders, only get up to the last complete 4 chars\n  var len = placeHoldersLen > 0\n    ? validLen - 4\n    : validLen\n\n  for (var i = 0; i < len; i += 4) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 18) |\n      (revLookup[b64.charCodeAt(i + 1)] << 12) |\n      (revLookup[b64.charCodeAt(i + 2)] << 6) |\n      revLookup[b64.charCodeAt(i + 3)]\n    arr[curByte++] = (tmp >> 16) & 0xFF\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 2) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 2) |\n      (revLookup[b64.charCodeAt(i + 1)] >> 4)\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 1) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 10) |\n      (revLookup[b64.charCodeAt(i + 1)] << 4) |\n      (revLookup[b64.charCodeAt(i + 2)] >> 2)\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  return arr\n}\n\nfunction tripletToBase64 (num) {\n  return lookup[num >> 18 & 0x3F] +\n    lookup[num >> 12 & 0x3F] +\n    lookup[num >> 6 & 0x3F] +\n    lookup[num & 0x3F]\n}\n\nfunction encodeChunk (uint8, start, end) {\n  var tmp\n  var output = []\n  for (var i = start; i < end; i += 3) {\n    tmp =\n      ((uint8[i] << 16) & 0xFF0000) +\n      ((uint8[i + 1] << 8) & 0xFF00) +\n      (uint8[i + 2] & 0xFF)\n    output.push(tripletToBase64(tmp))\n  }\n  return output.join('')\n}\n\nfunction fromByteArray (uint8) {\n  var tmp\n  var len = uint8.length\n  var extraBytes = len % 3 // if we have 1 byte left, pad 2 bytes\n  var parts = []\n  var maxChunkLength = 16383 // must be multiple of 3\n\n  // go through the array every three bytes, we'll deal with trailing stuff later\n  for (var i = 0, len2 = len - extraBytes; i < len2; i += maxChunkLength) {\n    parts.push(encodeChunk(\n      uint8, i, (i + maxChunkLength) > len2 ? len2 : (i + maxChunkLength)\n    ))\n  }\n\n  // pad the end with zeros, but make sure to not forget the extra bytes\n  if (extraBytes === 1) {\n    tmp = uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 2] +\n      lookup[(tmp << 4) & 0x3F] +\n      '=='\n    )\n  } else if (extraBytes === 2) {\n    tmp = (uint8[len - 2] << 8) + uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 10] +\n      lookup[(tmp >> 4) & 0x3F] +\n      lookup[(tmp << 2) & 0x3F] +\n      '='\n    )\n  }\n\n  return parts.join('')\n}\n","/*!\n * The buffer module from node.js, for the browser.\n *\n * @author   Feross Aboukhadijeh <feross@feross.org> <http://feross.org>\n * @license  MIT\n */\n/* eslint-disable no-proto */\n\n'use strict'\n\nvar base64 = require('base64-js')\nvar ieee754 = require('ieee754')\nvar isArray = require('isarray')\n\nexports.Buffer = Buffer\nexports.SlowBuffer = SlowBuffer\nexports.INSPECT_MAX_BYTES = 50\n\n/**\n * If `Buffer.TYPED_ARRAY_SUPPORT`:\n *   === true    Use Uint8Array implementation (fastest)\n *   === false   Use Object implementation (most compatible, even IE6)\n *\n * Browsers that support typed arrays are IE 10+, Firefox 4+, Chrome 7+, Safari 5.1+,\n * Opera 11.6+, iOS 4.2+.\n *\n * Due to various browser bugs, sometimes the Object implementation will be used even\n * when the browser supports typed arrays.\n *\n * Note:\n *\n *   - Firefox 4-29 lacks support for adding new properties to `Uint8Array` instances,\n *     See: https://bugzilla.mozilla.org/show_bug.cgi?id=695438.\n *\n *   - Chrome 9-10 is missing the `TypedArray.prototype.subarray` function.\n *\n *   - IE10 has a broken `TypedArray.prototype.subarray` function which returns arrays of\n *     incorrect length in some situations.\n\n * We detect these buggy browsers and set `Buffer.TYPED_ARRAY_SUPPORT` to `false` so they\n * get the Object implementation, which is slower but behaves correctly.\n */\nBuffer.TYPED_ARRAY_SUPPORT = global.TYPED_ARRAY_SUPPORT !== undefined\n  ? global.TYPED_ARRAY_SUPPORT\n  : typedArraySupport()\n\n/*\n * Export kMaxLength after typed array support is determined.\n */\nexports.kMaxLength = kMaxLength()\n\nfunction typedArraySupport () {\n  try {\n    var arr = new Uint8Array(1)\n    arr.__proto__ = {__proto__: Uint8Array.prototype, foo: function () { return 42 }}\n    return arr.foo() === 42 && // typed array instances can be augmented\n        typeof arr.subarray === 'function' && // chrome 9-10 lack `subarray`\n        arr.subarray(1, 1).byteLength === 0 // ie10 has broken `subarray`\n  } catch (e) {\n    return false\n  }\n}\n\nfunction kMaxLength () {\n  return Buffer.TYPED_ARRAY_SUPPORT\n    ? 0x7fffffff\n    : 0x3fffffff\n}\n\nfunction createBuffer (that, length) {\n  if (kMaxLength() < length) {\n    throw new RangeError('Invalid typed array length')\n  }\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = new Uint8Array(length)\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    if (that === null) {\n      that = new Buffer(length)\n    }\n    that.length = length\n  }\n\n  return that\n}\n\n/**\n * The Buffer constructor returns instances of `Uint8Array` that have their\n * prototype changed to `Buffer.prototype`. Furthermore, `Buffer` is a subclass of\n * `Uint8Array`, so the returned instances will have all the node `Buffer` methods\n * and the `Uint8Array` methods. Square bracket notation works as expected -- it\n * returns a single octet.\n *\n * The `Uint8Array` prototype remains unmodified.\n */\n\nfunction Buffer (arg, encodingOrOffset, length) {\n  if (!Buffer.TYPED_ARRAY_SUPPORT && !(this instanceof Buffer)) {\n    return new Buffer(arg, encodingOrOffset, length)\n  }\n\n  // Common case.\n  if (typeof arg === 'number') {\n    if (typeof encodingOrOffset === 'string') {\n      throw new Error(\n        'If encoding is specified then the first argument must be a string'\n      )\n    }\n    return allocUnsafe(this, arg)\n  }\n  return from(this, arg, encodingOrOffset, length)\n}\n\nBuffer.poolSize = 8192 // not used by this implementation\n\n// TODO: Legacy, not needed anymore. Remove in next major version.\nBuffer._augment = function (arr) {\n  arr.__proto__ = Buffer.prototype\n  return arr\n}\n\nfunction from (that, value, encodingOrOffset, length) {\n  if (typeof value === 'number') {\n    throw new TypeError('\"value\" argument must not be a number')\n  }\n\n  if (typeof ArrayBuffer !== 'undefined' && value instanceof ArrayBuffer) {\n    return fromArrayBuffer(that, value, encodingOrOffset, length)\n  }\n\n  if (typeof value === 'string') {\n    return fromString(that, value, encodingOrOffset)\n  }\n\n  return fromObject(that, value)\n}\n\n/**\n * Functionally equivalent to Buffer(arg, encoding) but throws a TypeError\n * if value is a number.\n * Buffer.from(str[, encoding])\n * Buffer.from(array)\n * Buffer.from(buffer)\n * Buffer.from(arrayBuffer[, byteOffset[, length]])\n **/\nBuffer.from = function (value, encodingOrOffset, length) {\n  return from(null, value, encodingOrOffset, length)\n}\n\nif (Buffer.TYPED_ARRAY_SUPPORT) {\n  Buffer.prototype.__proto__ = Uint8Array.prototype\n  Buffer.__proto__ = Uint8Array\n  if (typeof Symbol !== 'undefined' && Symbol.species &&\n      Buffer[Symbol.species] === Buffer) {\n    // Fix subarray() in ES2016. See: https://github.com/feross/buffer/pull/97\n    Object.defineProperty(Buffer, Symbol.species, {\n      value: null,\n      configurable: true\n    })\n  }\n}\n\nfunction assertSize (size) {\n  if (typeof size !== 'number') {\n    throw new TypeError('\"size\" argument must be a number')\n  } else if (size < 0) {\n    throw new RangeError('\"size\" argument must not be negative')\n  }\n}\n\nfunction alloc (that, size, fill, encoding) {\n  assertSize(size)\n  if (size <= 0) {\n    return createBuffer(that, size)\n  }\n  if (fill !== undefined) {\n    // Only pay attention to encoding if it's a string. This\n    // prevents accidentally sending in a number that would\n    // be interpretted as a start offset.\n    return typeof encoding === 'string'\n      ? createBuffer(that, size).fill(fill, encoding)\n      : createBuffer(that, size).fill(fill)\n  }\n  return createBuffer(that, size)\n}\n\n/**\n * Creates a new filled Buffer instance.\n * alloc(size[, fill[, encoding]])\n **/\nBuffer.alloc = function (size, fill, encoding) {\n  return alloc(null, size, fill, encoding)\n}\n\nfunction allocUnsafe (that, size) {\n  assertSize(size)\n  that = createBuffer(that, size < 0 ? 0 : checked(size) | 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) {\n    for (var i = 0; i < size; ++i) {\n      that[i] = 0\n    }\n  }\n  return that\n}\n\n/**\n * Equivalent to Buffer(num), by default creates a non-zero-filled Buffer instance.\n * */\nBuffer.allocUnsafe = function (size) {\n  return allocUnsafe(null, size)\n}\n/**\n * Equivalent to SlowBuffer(num), by default creates a non-zero-filled Buffer instance.\n */\nBuffer.allocUnsafeSlow = function (size) {\n  return allocUnsafe(null, size)\n}\n\nfunction fromString (that, string, encoding) {\n  if (typeof encoding !== 'string' || encoding === '') {\n    encoding = 'utf8'\n  }\n\n  if (!Buffer.isEncoding(encoding)) {\n    throw new TypeError('\"encoding\" must be a valid string encoding')\n  }\n\n  var length = byteLength(string, encoding) | 0\n  that = createBuffer(that, length)\n\n  var actual = that.write(string, encoding)\n\n  if (actual !== length) {\n    // Writing a hex string, for example, that contains invalid characters will\n    // cause everything after the first invalid character to be ignored. (e.g.\n    // 'abxxcd' will be treated as 'ab')\n    that = that.slice(0, actual)\n  }\n\n  return that\n}\n\nfunction fromArrayLike (that, array) {\n  var length = array.length < 0 ? 0 : checked(array.length) | 0\n  that = createBuffer(that, length)\n  for (var i = 0; i < length; i += 1) {\n    that[i] = array[i] & 255\n  }\n  return that\n}\n\nfunction fromArrayBuffer (that, array, byteOffset, length) {\n  array.byteLength // this throws if `array` is not a valid ArrayBuffer\n\n  if (byteOffset < 0 || array.byteLength < byteOffset) {\n    throw new RangeError('\\'offset\\' is out of bounds')\n  }\n\n  if (array.byteLength < byteOffset + (length || 0)) {\n    throw new RangeError('\\'length\\' is out of bounds')\n  }\n\n  if (byteOffset === undefined && length === undefined) {\n    array = new Uint8Array(array)\n  } else if (length === undefined) {\n    array = new Uint8Array(array, byteOffset)\n  } else {\n    array = new Uint8Array(array, byteOffset, length)\n  }\n\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = array\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    that = fromArrayLike(that, array)\n  }\n  return that\n}\n\nfunction fromObject (that, obj) {\n  if (Buffer.isBuffer(obj)) {\n    var len = checked(obj.length) | 0\n    that = createBuffer(that, len)\n\n    if (that.length === 0) {\n      return that\n    }\n\n    obj.copy(that, 0, 0, len)\n    return that\n  }\n\n  if (obj) {\n    if ((typeof ArrayBuffer !== 'undefined' &&\n        obj.buffer instanceof ArrayBuffer) || 'length' in obj) {\n      if (typeof obj.length !== 'number' || isnan(obj.length)) {\n        return createBuffer(that, 0)\n      }\n      return fromArrayLike(that, obj)\n    }\n\n    if (obj.type === 'Buffer' && isArray(obj.data)) {\n      return fromArrayLike(that, obj.data)\n    }\n  }\n\n  throw new TypeError('First argument must be a string, Buffer, ArrayBuffer, Array, or array-like object.')\n}\n\nfunction checked (length) {\n  // Note: cannot use `length < kMaxLength()` here because that fails when\n  // length is NaN (which is otherwise coerced to zero.)\n  if (length >= kMaxLength()) {\n    throw new RangeError('Attempt to allocate Buffer larger than maximum ' +\n                         'size: 0x' + kMaxLength().toString(16) + ' bytes')\n  }\n  return length | 0\n}\n\nfunction SlowBuffer (length) {\n  if (+length != length) { // eslint-disable-line eqeqeq\n    length = 0\n  }\n  return Buffer.alloc(+length)\n}\n\nBuffer.isBuffer = function isBuffer (b) {\n  return !!(b != null && b._isBuffer)\n}\n\nBuffer.compare = function compare (a, b) {\n  if (!Buffer.isBuffer(a) || !Buffer.isBuffer(b)) {\n    throw new TypeError('Arguments must be Buffers')\n  }\n\n  if (a === b) return 0\n\n  var x = a.length\n  var y = b.length\n\n  for (var i = 0, len = Math.min(x, y); i < len; ++i) {\n    if (a[i] !== b[i]) {\n      x = a[i]\n      y = b[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\nBuffer.isEncoding = function isEncoding (encoding) {\n  switch (String(encoding).toLowerCase()) {\n    case 'hex':\n    case 'utf8':\n    case 'utf-8':\n    case 'ascii':\n    case 'latin1':\n    case 'binary':\n    case 'base64':\n    case 'ucs2':\n    case 'ucs-2':\n    case 'utf16le':\n    case 'utf-16le':\n      return true\n    default:\n      return false\n  }\n}\n\nBuffer.concat = function concat (list, length) {\n  if (!isArray(list)) {\n    throw new TypeError('\"list\" argument must be an Array of Buffers')\n  }\n\n  if (list.length === 0) {\n    return Buffer.alloc(0)\n  }\n\n  var i\n  if (length === undefined) {\n    length = 0\n    for (i = 0; i < list.length; ++i) {\n      length += list[i].length\n    }\n  }\n\n  var buffer = Buffer.allocUnsafe(length)\n  var pos = 0\n  for (i = 0; i < list.length; ++i) {\n    var buf = list[i]\n    if (!Buffer.isBuffer(buf)) {\n      throw new TypeError('\"list\" argument must be an Array of Buffers')\n    }\n    buf.copy(buffer, pos)\n    pos += buf.length\n  }\n  return buffer\n}\n\nfunction byteLength (string, encoding) {\n  if (Buffer.isBuffer(string)) {\n    return string.length\n  }\n  if (typeof ArrayBuffer !== 'undefined' && typeof ArrayBuffer.isView === 'function' &&\n      (ArrayBuffer.isView(string) || string instanceof ArrayBuffer)) {\n    return string.byteLength\n  }\n  if (typeof string !== 'string') {\n    string = '' + string\n  }\n\n  var len = string.length\n  if (len === 0) return 0\n\n  // Use a for loop to avoid recursion\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'ascii':\n      case 'latin1':\n      case 'binary':\n        return len\n      case 'utf8':\n      case 'utf-8':\n      case undefined:\n        return utf8ToBytes(string).length\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return len * 2\n      case 'hex':\n        return len >>> 1\n      case 'base64':\n        return base64ToBytes(string).length\n      default:\n        if (loweredCase) return utf8ToBytes(string).length // assume utf8\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\nBuffer.byteLength = byteLength\n\nfunction slowToString (encoding, start, end) {\n  var loweredCase = false\n\n  // No need to verify that \"this.length <= MAX_UINT32\" since it's a read-only\n  // property of a typed array.\n\n  // This behaves neither like String nor Uint8Array in that we set start/end\n  // to their upper/lower bounds if the value passed is out of range.\n  // undefined is handled specially as per ECMA-262 6th Edition,\n  // Section 13.3.3.7 Runtime Semantics: KeyedBindingInitialization.\n  if (start === undefined || start < 0) {\n    start = 0\n  }\n  // Return early if start > this.length. Done here to prevent potential uint32\n  // coercion fail below.\n  if (start > this.length) {\n    return ''\n  }\n\n  if (end === undefined || end > this.length) {\n    end = this.length\n  }\n\n  if (end <= 0) {\n    return ''\n  }\n\n  // Force coersion to uint32. This will also coerce falsey/NaN values to 0.\n  end >>>= 0\n  start >>>= 0\n\n  if (end <= start) {\n    return ''\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  while (true) {\n    switch (encoding) {\n      case 'hex':\n        return hexSlice(this, start, end)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Slice(this, start, end)\n\n      case 'ascii':\n        return asciiSlice(this, start, end)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Slice(this, start, end)\n\n      case 'base64':\n        return base64Slice(this, start, end)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return utf16leSlice(this, start, end)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = (encoding + '').toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\n// The property is used by `Buffer.isBuffer` and `is-buffer` (in Safari 5-7) to detect\n// Buffer instances.\nBuffer.prototype._isBuffer = true\n\nfunction swap (b, n, m) {\n  var i = b[n]\n  b[n] = b[m]\n  b[m] = i\n}\n\nBuffer.prototype.swap16 = function swap16 () {\n  var len = this.length\n  if (len % 2 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 16-bits')\n  }\n  for (var i = 0; i < len; i += 2) {\n    swap(this, i, i + 1)\n  }\n  return this\n}\n\nBuffer.prototype.swap32 = function swap32 () {\n  var len = this.length\n  if (len % 4 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 32-bits')\n  }\n  for (var i = 0; i < len; i += 4) {\n    swap(this, i, i + 3)\n    swap(this, i + 1, i + 2)\n  }\n  return this\n}\n\nBuffer.prototype.swap64 = function swap64 () {\n  var len = this.length\n  if (len % 8 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 64-bits')\n  }\n  for (var i = 0; i < len; i += 8) {\n    swap(this, i, i + 7)\n    swap(this, i + 1, i + 6)\n    swap(this, i + 2, i + 5)\n    swap(this, i + 3, i + 4)\n  }\n  return this\n}\n\nBuffer.prototype.toString = function toString () {\n  var length = this.length | 0\n  if (length === 0) return ''\n  if (arguments.length === 0) return utf8Slice(this, 0, length)\n  return slowToString.apply(this, arguments)\n}\n\nBuffer.prototype.equals = function equals (b) {\n  if (!Buffer.isBuffer(b)) throw new TypeError('Argument must be a Buffer')\n  if (this === b) return true\n  return Buffer.compare(this, b) === 0\n}\n\nBuffer.prototype.inspect = function inspect () {\n  var str = ''\n  var max = exports.INSPECT_MAX_BYTES\n  if (this.length > 0) {\n    str = this.toString('hex', 0, max).match(/.{2}/g).join(' ')\n    if (this.length > max) str += ' ... '\n  }\n  return '<Buffer ' + str + '>'\n}\n\nBuffer.prototype.compare = function compare (target, start, end, thisStart, thisEnd) {\n  if (!Buffer.isBuffer(target)) {\n    throw new TypeError('Argument must be a Buffer')\n  }\n\n  if (start === undefined) {\n    start = 0\n  }\n  if (end === undefined) {\n    end = target ? target.length : 0\n  }\n  if (thisStart === undefined) {\n    thisStart = 0\n  }\n  if (thisEnd === undefined) {\n    thisEnd = this.length\n  }\n\n  if (start < 0 || end > target.length || thisStart < 0 || thisEnd > this.length) {\n    throw new RangeError('out of range index')\n  }\n\n  if (thisStart >= thisEnd && start >= end) {\n    return 0\n  }\n  if (thisStart >= thisEnd) {\n    return -1\n  }\n  if (start >= end) {\n    return 1\n  }\n\n  start >>>= 0\n  end >>>= 0\n  thisStart >>>= 0\n  thisEnd >>>= 0\n\n  if (this === target) return 0\n\n  var x = thisEnd - thisStart\n  var y = end - start\n  var len = Math.min(x, y)\n\n  var thisCopy = this.slice(thisStart, thisEnd)\n  var targetCopy = target.slice(start, end)\n\n  for (var i = 0; i < len; ++i) {\n    if (thisCopy[i] !== targetCopy[i]) {\n      x = thisCopy[i]\n      y = targetCopy[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\n// Finds either the first index of `val` in `buffer` at offset >= `byteOffset`,\n// OR the last index of `val` in `buffer` at offset <= `byteOffset`.\n//\n// Arguments:\n// - buffer - a Buffer to search\n// - val - a string, Buffer, or number\n// - byteOffset - an index into `buffer`; will be clamped to an int32\n// - encoding - an optional encoding, relevant is val is a string\n// - dir - true for indexOf, false for lastIndexOf\nfunction bidirectionalIndexOf (buffer, val, byteOffset, encoding, dir) {\n  // Empty buffer means no match\n  if (buffer.length === 0) return -1\n\n  // Normalize byteOffset\n  if (typeof byteOffset === 'string') {\n    encoding = byteOffset\n    byteOffset = 0\n  } else if (byteOffset > 0x7fffffff) {\n    byteOffset = 0x7fffffff\n  } else if (byteOffset < -0x80000000) {\n    byteOffset = -0x80000000\n  }\n  byteOffset = +byteOffset  // Coerce to Number.\n  if (isNaN(byteOffset)) {\n    // byteOffset: it it's undefined, null, NaN, \"foo\", etc, search whole buffer\n    byteOffset = dir ? 0 : (buffer.length - 1)\n  }\n\n  // Normalize byteOffset: negative offsets start from the end of the buffer\n  if (byteOffset < 0) byteOffset = buffer.length + byteOffset\n  if (byteOffset >= buffer.length) {\n    if (dir) return -1\n    else byteOffset = buffer.length - 1\n  } else if (byteOffset < 0) {\n    if (dir) byteOffset = 0\n    else return -1\n  }\n\n  // Normalize val\n  if (typeof val === 'string') {\n    val = Buffer.from(val, encoding)\n  }\n\n  // Finally, search either indexOf (if dir is true) or lastIndexOf\n  if (Buffer.isBuffer(val)) {\n    // Special case: looking for empty string/buffer always fails\n    if (val.length === 0) {\n      return -1\n    }\n    return arrayIndexOf(buffer, val, byteOffset, encoding, dir)\n  } else if (typeof val === 'number') {\n    val = val & 0xFF // Search for a byte value [0-255]\n    if (Buffer.TYPED_ARRAY_SUPPORT &&\n        typeof Uint8Array.prototype.indexOf === 'function') {\n      if (dir) {\n        return Uint8Array.prototype.indexOf.call(buffer, val, byteOffset)\n      } else {\n        return Uint8Array.prototype.lastIndexOf.call(buffer, val, byteOffset)\n      }\n    }\n    return arrayIndexOf(buffer, [ val ], byteOffset, encoding, dir)\n  }\n\n  throw new TypeError('val must be string, number or Buffer')\n}\n\nfunction arrayIndexOf (arr, val, byteOffset, encoding, dir) {\n  var indexSize = 1\n  var arrLength = arr.length\n  var valLength = val.length\n\n  if (encoding !== undefined) {\n    encoding = String(encoding).toLowerCase()\n    if (encoding === 'ucs2' || encoding === 'ucs-2' ||\n        encoding === 'utf16le' || encoding === 'utf-16le') {\n      if (arr.length < 2 || val.length < 2) {\n        return -1\n      }\n      indexSize = 2\n      arrLength /= 2\n      valLength /= 2\n      byteOffset /= 2\n    }\n  }\n\n  function read (buf, i) {\n    if (indexSize === 1) {\n      return buf[i]\n    } else {\n      return buf.readUInt16BE(i * indexSize)\n    }\n  }\n\n  var i\n  if (dir) {\n    var foundIndex = -1\n    for (i = byteOffset; i < arrLength; i++) {\n      if (read(arr, i) === read(val, foundIndex === -1 ? 0 : i - foundIndex)) {\n        if (foundIndex === -1) foundIndex = i\n        if (i - foundIndex + 1 === valLength) return foundIndex * indexSize\n      } else {\n        if (foundIndex !== -1) i -= i - foundIndex\n        foundIndex = -1\n      }\n    }\n  } else {\n    if (byteOffset + valLength > arrLength) byteOffset = arrLength - valLength\n    for (i = byteOffset; i >= 0; i--) {\n      var found = true\n      for (var j = 0; j < valLength; j++) {\n        if (read(arr, i + j) !== read(val, j)) {\n          found = false\n          break\n        }\n      }\n      if (found) return i\n    }\n  }\n\n  return -1\n}\n\nBuffer.prototype.includes = function includes (val, byteOffset, encoding) {\n  return this.indexOf(val, byteOffset, encoding) !== -1\n}\n\nBuffer.prototype.indexOf = function indexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, true)\n}\n\nBuffer.prototype.lastIndexOf = function lastIndexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, false)\n}\n\nfunction hexWrite (buf, string, offset, length) {\n  offset = Number(offset) || 0\n  var remaining = buf.length - offset\n  if (!length) {\n    length = remaining\n  } else {\n    length = Number(length)\n    if (length > remaining) {\n      length = remaining\n    }\n  }\n\n  // must be an even number of digits\n  var strLen = string.length\n  if (strLen % 2 !== 0) throw new TypeError('Invalid hex string')\n\n  if (length > strLen / 2) {\n    length = strLen / 2\n  }\n  for (var i = 0; i < length; ++i) {\n    var parsed = parseInt(string.substr(i * 2, 2), 16)\n    if (isNaN(parsed)) return i\n    buf[offset + i] = parsed\n  }\n  return i\n}\n\nfunction utf8Write (buf, string, offset, length) {\n  return blitBuffer(utf8ToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nfunction asciiWrite (buf, string, offset, length) {\n  return blitBuffer(asciiToBytes(string), buf, offset, length)\n}\n\nfunction latin1Write (buf, string, offset, length) {\n  return asciiWrite(buf, string, offset, length)\n}\n\nfunction base64Write (buf, string, offset, length) {\n  return blitBuffer(base64ToBytes(string), buf, offset, length)\n}\n\nfunction ucs2Write (buf, string, offset, length) {\n  return blitBuffer(utf16leToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nBuffer.prototype.write = function write (string, offset, length, encoding) {\n  // Buffer#write(string)\n  if (offset === undefined) {\n    encoding = 'utf8'\n    length = this.length\n    offset = 0\n  // Buffer#write(string, encoding)\n  } else if (length === undefined && typeof offset === 'string') {\n    encoding = offset\n    length = this.length\n    offset = 0\n  // Buffer#write(string, offset[, length][, encoding])\n  } else if (isFinite(offset)) {\n    offset = offset | 0\n    if (isFinite(length)) {\n      length = length | 0\n      if (encoding === undefined) encoding = 'utf8'\n    } else {\n      encoding = length\n      length = undefined\n    }\n  // legacy write(string, encoding, offset, length) - remove in v0.13\n  } else {\n    throw new Error(\n      'Buffer.write(string, encoding, offset[, length]) is no longer supported'\n    )\n  }\n\n  var remaining = this.length - offset\n  if (length === undefined || length > remaining) length = remaining\n\n  if ((string.length > 0 && (length < 0 || offset < 0)) || offset > this.length) {\n    throw new RangeError('Attempt to write outside buffer bounds')\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'hex':\n        return hexWrite(this, string, offset, length)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Write(this, string, offset, length)\n\n      case 'ascii':\n        return asciiWrite(this, string, offset, length)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Write(this, string, offset, length)\n\n      case 'base64':\n        // Warning: maxLength not taken into account in base64Write\n        return base64Write(this, string, offset, length)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return ucs2Write(this, string, offset, length)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\nBuffer.prototype.toJSON = function toJSON () {\n  return {\n    type: 'Buffer',\n    data: Array.prototype.slice.call(this._arr || this, 0)\n  }\n}\n\nfunction base64Slice (buf, start, end) {\n  if (start === 0 && end === buf.length) {\n    return base64.fromByteArray(buf)\n  } else {\n    return base64.fromByteArray(buf.slice(start, end))\n  }\n}\n\nfunction utf8Slice (buf, start, end) {\n  end = Math.min(buf.length, end)\n  var res = []\n\n  var i = start\n  while (i < end) {\n    var firstByte = buf[i]\n    var codePoint = null\n    var bytesPerSequence = (firstByte > 0xEF) ? 4\n      : (firstByte > 0xDF) ? 3\n      : (firstByte > 0xBF) ? 2\n      : 1\n\n    if (i + bytesPerSequence <= end) {\n      var secondByte, thirdByte, fourthByte, tempCodePoint\n\n      switch (bytesPerSequence) {\n        case 1:\n          if (firstByte < 0x80) {\n            codePoint = firstByte\n          }\n          break\n        case 2:\n          secondByte = buf[i + 1]\n          if ((secondByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0x1F) << 0x6 | (secondByte & 0x3F)\n            if (tempCodePoint > 0x7F) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 3:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0xC | (secondByte & 0x3F) << 0x6 | (thirdByte & 0x3F)\n            if (tempCodePoint > 0x7FF && (tempCodePoint < 0xD800 || tempCodePoint > 0xDFFF)) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 4:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          fourthByte = buf[i + 3]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80 && (fourthByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0x12 | (secondByte & 0x3F) << 0xC | (thirdByte & 0x3F) << 0x6 | (fourthByte & 0x3F)\n            if (tempCodePoint > 0xFFFF && tempCodePoint < 0x110000) {\n              codePoint = tempCodePoint\n            }\n          }\n      }\n    }\n\n    if (codePoint === null) {\n      // we did not generate a valid codePoint so insert a\n      // replacement char (U+FFFD) and advance only 1 byte\n      codePoint = 0xFFFD\n      bytesPerSequence = 1\n    } else if (codePoint > 0xFFFF) {\n      // encode to utf16 (surrogate pair dance)\n      codePoint -= 0x10000\n      res.push(codePoint >>> 10 & 0x3FF | 0xD800)\n      codePoint = 0xDC00 | codePoint & 0x3FF\n    }\n\n    res.push(codePoint)\n    i += bytesPerSequence\n  }\n\n  return decodeCodePointsArray(res)\n}\n\n// Based on http://stackoverflow.com/a/22747272/680742, the browser with\n// the lowest limit is Chrome, with 0x10000 args.\n// We go 1 magnitude less, for safety\nvar MAX_ARGUMENTS_LENGTH = 0x1000\n\nfunction decodeCodePointsArray (codePoints) {\n  var len = codePoints.length\n  if (len <= MAX_ARGUMENTS_LENGTH) {\n    return String.fromCharCode.apply(String, codePoints) // avoid extra slice()\n  }\n\n  // Decode in chunks to avoid \"call stack size exceeded\".\n  var res = ''\n  var i = 0\n  while (i < len) {\n    res += String.fromCharCode.apply(\n      String,\n      codePoints.slice(i, i += MAX_ARGUMENTS_LENGTH)\n    )\n  }\n  return res\n}\n\nfunction asciiSlice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i] & 0x7F)\n  }\n  return ret\n}\n\nfunction latin1Slice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i])\n  }\n  return ret\n}\n\nfunction hexSlice (buf, start, end) {\n  var len = buf.length\n\n  if (!start || start < 0) start = 0\n  if (!end || end < 0 || end > len) end = len\n\n  var out = ''\n  for (var i = start; i < end; ++i) {\n    out += toHex(buf[i])\n  }\n  return out\n}\n\nfunction utf16leSlice (buf, start, end) {\n  var bytes = buf.slice(start, end)\n  var res = ''\n  for (var i = 0; i < bytes.length; i += 2) {\n    res += String.fromCharCode(bytes[i] + bytes[i + 1] * 256)\n  }\n  return res\n}\n\nBuffer.prototype.slice = function slice (start, end) {\n  var len = this.length\n  start = ~~start\n  end = end === undefined ? len : ~~end\n\n  if (start < 0) {\n    start += len\n    if (start < 0) start = 0\n  } else if (start > len) {\n    start = len\n  }\n\n  if (end < 0) {\n    end += len\n    if (end < 0) end = 0\n  } else if (end > len) {\n    end = len\n  }\n\n  if (end < start) end = start\n\n  var newBuf\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    newBuf = this.subarray(start, end)\n    newBuf.__proto__ = Buffer.prototype\n  } else {\n    var sliceLen = end - start\n    newBuf = new Buffer(sliceLen, undefined)\n    for (var i = 0; i < sliceLen; ++i) {\n      newBuf[i] = this[i + start]\n    }\n  }\n\n  return newBuf\n}\n\n/*\n * Need to make sure that buffer isn't trying to write out of bounds.\n */\nfunction checkOffset (offset, ext, length) {\n  if ((offset % 1) !== 0 || offset < 0) throw new RangeError('offset is not uint')\n  if (offset + ext > length) throw new RangeError('Trying to access beyond buffer length')\n}\n\nBuffer.prototype.readUIntLE = function readUIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUIntBE = function readUIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    checkOffset(offset, byteLength, this.length)\n  }\n\n  var val = this[offset + --byteLength]\n  var mul = 1\n  while (byteLength > 0 && (mul *= 0x100)) {\n    val += this[offset + --byteLength] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUInt8 = function readUInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  return this[offset]\n}\n\nBuffer.prototype.readUInt16LE = function readUInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return this[offset] | (this[offset + 1] << 8)\n}\n\nBuffer.prototype.readUInt16BE = function readUInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return (this[offset] << 8) | this[offset + 1]\n}\n\nBuffer.prototype.readUInt32LE = function readUInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return ((this[offset]) |\n      (this[offset + 1] << 8) |\n      (this[offset + 2] << 16)) +\n      (this[offset + 3] * 0x1000000)\n}\n\nBuffer.prototype.readUInt32BE = function readUInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] * 0x1000000) +\n    ((this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    this[offset + 3])\n}\n\nBuffer.prototype.readIntLE = function readIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readIntBE = function readIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var i = byteLength\n  var mul = 1\n  var val = this[offset + --i]\n  while (i > 0 && (mul *= 0x100)) {\n    val += this[offset + --i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readInt8 = function readInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  if (!(this[offset] & 0x80)) return (this[offset])\n  return ((0xff - this[offset] + 1) * -1)\n}\n\nBuffer.prototype.readInt16LE = function readInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset] | (this[offset + 1] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt16BE = function readInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset + 1] | (this[offset] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt32LE = function readInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset]) |\n    (this[offset + 1] << 8) |\n    (this[offset + 2] << 16) |\n    (this[offset + 3] << 24)\n}\n\nBuffer.prototype.readInt32BE = function readInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] << 24) |\n    (this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    (this[offset + 3])\n}\n\nBuffer.prototype.readFloatLE = function readFloatLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, true, 23, 4)\n}\n\nBuffer.prototype.readFloatBE = function readFloatBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, false, 23, 4)\n}\n\nBuffer.prototype.readDoubleLE = function readDoubleLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, true, 52, 8)\n}\n\nBuffer.prototype.readDoubleBE = function readDoubleBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, false, 52, 8)\n}\n\nfunction checkInt (buf, value, offset, ext, max, min) {\n  if (!Buffer.isBuffer(buf)) throw new TypeError('\"buffer\" argument must be a Buffer instance')\n  if (value > max || value < min) throw new RangeError('\"value\" argument is out of bounds')\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n}\n\nBuffer.prototype.writeUIntLE = function writeUIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var mul = 1\n  var i = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUIntBE = function writeUIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUInt8 = function writeUInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0xff, 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nfunction objectWriteUInt16 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 2); i < j; ++i) {\n    buf[offset + i] = (value & (0xff << (8 * (littleEndian ? i : 1 - i)))) >>>\n      (littleEndian ? i : 1 - i) * 8\n  }\n}\n\nBuffer.prototype.writeUInt16LE = function writeUInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeUInt16BE = function writeUInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nfunction objectWriteUInt32 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffffffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 4); i < j; ++i) {\n    buf[offset + i] = (value >>> (littleEndian ? i : 3 - i) * 8) & 0xff\n  }\n}\n\nBuffer.prototype.writeUInt32LE = function writeUInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset + 3] = (value >>> 24)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 1] = (value >>> 8)\n    this[offset] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeUInt32BE = function writeUInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeIntLE = function writeIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = 0\n  var mul = 1\n  var sub = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i - 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeIntBE = function writeIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  var sub = 0\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i + 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeInt8 = function writeInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0x7f, -0x80)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  if (value < 0) value = 0xff + value + 1\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nBuffer.prototype.writeInt16LE = function writeInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt16BE = function writeInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt32LE = function writeInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 3] = (value >>> 24)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeInt32BE = function writeInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (value < 0) value = 0xffffffff + value + 1\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nfunction checkIEEE754 (buf, value, offset, ext, max, min) {\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n  if (offset < 0) throw new RangeError('Index out of range')\n}\n\nfunction writeFloat (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 4, 3.4028234663852886e+38, -3.4028234663852886e+38)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 23, 4)\n  return offset + 4\n}\n\nBuffer.prototype.writeFloatLE = function writeFloatLE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeFloatBE = function writeFloatBE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, false, noAssert)\n}\n\nfunction writeDouble (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 8, 1.7976931348623157E+308, -1.7976931348623157E+308)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 52, 8)\n  return offset + 8\n}\n\nBuffer.prototype.writeDoubleLE = function writeDoubleLE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeDoubleBE = function writeDoubleBE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, false, noAssert)\n}\n\n// copy(targetBuffer, targetStart=0, sourceStart=0, sourceEnd=buffer.length)\nBuffer.prototype.copy = function copy (target, targetStart, start, end) {\n  if (!start) start = 0\n  if (!end && end !== 0) end = this.length\n  if (targetStart >= target.length) targetStart = target.length\n  if (!targetStart) targetStart = 0\n  if (end > 0 && end < start) end = start\n\n  // Copy 0 bytes; we're done\n  if (end === start) return 0\n  if (target.length === 0 || this.length === 0) return 0\n\n  // Fatal error conditions\n  if (targetStart < 0) {\n    throw new RangeError('targetStart out of bounds')\n  }\n  if (start < 0 || start >= this.length) throw new RangeError('sourceStart out of bounds')\n  if (end < 0) throw new RangeError('sourceEnd out of bounds')\n\n  // Are we oob?\n  if (end > this.length) end = this.length\n  if (target.length - targetStart < end - start) {\n    end = target.length - targetStart + start\n  }\n\n  var len = end - start\n  var i\n\n  if (this === target && start < targetStart && targetStart < end) {\n    // descending copy from end\n    for (i = len - 1; i >= 0; --i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else if (len < 1000 || !Buffer.TYPED_ARRAY_SUPPORT) {\n    // ascending copy from start\n    for (i = 0; i < len; ++i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else {\n    Uint8Array.prototype.set.call(\n      target,\n      this.subarray(start, start + len),\n      targetStart\n    )\n  }\n\n  return len\n}\n\n// Usage:\n//    buffer.fill(number[, offset[, end]])\n//    buffer.fill(buffer[, offset[, end]])\n//    buffer.fill(string[, offset[, end]][, encoding])\nBuffer.prototype.fill = function fill (val, start, end, encoding) {\n  // Handle string cases:\n  if (typeof val === 'string') {\n    if (typeof start === 'string') {\n      encoding = start\n      start = 0\n      end = this.length\n    } else if (typeof end === 'string') {\n      encoding = end\n      end = this.length\n    }\n    if (val.length === 1) {\n      var code = val.charCodeAt(0)\n      if (code < 256) {\n        val = code\n      }\n    }\n    if (encoding !== undefined && typeof encoding !== 'string') {\n      throw new TypeError('encoding must be a string')\n    }\n    if (typeof encoding === 'string' && !Buffer.isEncoding(encoding)) {\n      throw new TypeError('Unknown encoding: ' + encoding)\n    }\n  } else if (typeof val === 'number') {\n    val = val & 255\n  }\n\n  // Invalid ranges are not set to a default, so can range check early.\n  if (start < 0 || this.length < start || this.length < end) {\n    throw new RangeError('Out of range index')\n  }\n\n  if (end <= start) {\n    return this\n  }\n\n  start = start >>> 0\n  end = end === undefined ? this.length : end >>> 0\n\n  if (!val) val = 0\n\n  var i\n  if (typeof val === 'number') {\n    for (i = start; i < end; ++i) {\n      this[i] = val\n    }\n  } else {\n    var bytes = Buffer.isBuffer(val)\n      ? val\n      : utf8ToBytes(new Buffer(val, encoding).toString())\n    var len = bytes.length\n    for (i = 0; i < end - start; ++i) {\n      this[i + start] = bytes[i % len]\n    }\n  }\n\n  return this\n}\n\n// HELPER FUNCTIONS\n// ================\n\nvar INVALID_BASE64_RE = /[^+\\/0-9A-Za-z-_]/g\n\nfunction base64clean (str) {\n  // Node strips out invalid characters like \\n and \\t from the string, base64-js does not\n  str = stringtrim(str).replace(INVALID_BASE64_RE, '')\n  // Node converts strings with length < 2 to ''\n  if (str.length < 2) return ''\n  // Node allows for non-padded base64 strings (missing trailing ===), base64-js does not\n  while (str.length % 4 !== 0) {\n    str = str + '='\n  }\n  return str\n}\n\nfunction stringtrim (str) {\n  if (str.trim) return str.trim()\n  return str.replace(/^\\s+|\\s+$/g, '')\n}\n\nfunction toHex (n) {\n  if (n < 16) return '0' + n.toString(16)\n  return n.toString(16)\n}\n\nfunction utf8ToBytes (string, units) {\n  units = units || Infinity\n  var codePoint\n  var length = string.length\n  var leadSurrogate = null\n  var bytes = []\n\n  for (var i = 0; i < length; ++i) {\n    codePoint = string.charCodeAt(i)\n\n    // is surrogate component\n    if (codePoint > 0xD7FF && codePoint < 0xE000) {\n      // last char was a lead\n      if (!leadSurrogate) {\n        // no lead yet\n        if (codePoint > 0xDBFF) {\n          // unexpected trail\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        } else if (i + 1 === length) {\n          // unpaired lead\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        }\n\n        // valid lead\n        leadSurrogate = codePoint\n\n        continue\n      }\n\n      // 2 leads in a row\n      if (codePoint < 0xDC00) {\n        if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n        leadSurrogate = codePoint\n        continue\n      }\n\n      // valid surrogate pair\n      codePoint = (leadSurrogate - 0xD800 << 10 | codePoint - 0xDC00) + 0x10000\n    } else if (leadSurrogate) {\n      // valid bmp char, but last char was a lead\n      if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n    }\n\n    leadSurrogate = null\n\n    // encode utf8\n    if (codePoint < 0x80) {\n      if ((units -= 1) < 0) break\n      bytes.push(codePoint)\n    } else if (codePoint < 0x800) {\n      if ((units -= 2) < 0) break\n      bytes.push(\n        codePoint >> 0x6 | 0xC0,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x10000) {\n      if ((units -= 3) < 0) break\n      bytes.push(\n        codePoint >> 0xC | 0xE0,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x110000) {\n      if ((units -= 4) < 0) break\n      bytes.push(\n        codePoint >> 0x12 | 0xF0,\n        codePoint >> 0xC & 0x3F | 0x80,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else {\n      throw new Error('Invalid code point')\n    }\n  }\n\n  return bytes\n}\n\nfunction asciiToBytes (str) {\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    // Node's code seems to be doing this and not & 0x7F..\n    byteArray.push(str.charCodeAt(i) & 0xFF)\n  }\n  return byteArray\n}\n\nfunction utf16leToBytes (str, units) {\n  var c, hi, lo\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    if ((units -= 2) < 0) break\n\n    c = str.charCodeAt(i)\n    hi = c >> 8\n    lo = c % 256\n    byteArray.push(lo)\n    byteArray.push(hi)\n  }\n\n  return byteArray\n}\n\nfunction base64ToBytes (str) {\n  return base64.toByteArray(base64clean(str))\n}\n\nfunction blitBuffer (src, dst, offset, length) {\n  for (var i = 0; i < length; ++i) {\n    if ((i + offset >= dst.length) || (i >= src.length)) break\n    dst[i + offset] = src[i]\n  }\n  return i\n}\n\nfunction isnan (val) {\n  return val !== val // eslint-disable-line no-self-compare\n}\n","var toString = {}.toString;\n\nmodule.exports = Array.isArray || function (arr) {\n  return toString.call(arr) == '[object Array]';\n};\n","require('../modules/es6.object.to-string');\nrequire('../modules/es6.string.iterator');\nrequire('../modules/web.dom.iterable');\nrequire('../modules/es6.promise');\nmodule.exports = require('../modules/_core').Promise;\n","require('../../modules/es6.array.find');\nmodule.exports = require('../../modules/_core').Array.find;\n","require('../../modules/es6.array.is-array');\nmodule.exports = require('../../modules/_core').Array.isArray;\n","require('../../modules/es6.array.some');\nmodule.exports = require('../../modules/_core').Array.some;\n","// for a legacy code and future fixes\nmodule.exports = function () {\n  return Function.call.apply(Array.prototype.splice, arguments);\n};\n","require('../../modules/es6.function.bind');\nmodule.exports = require('../../modules/_core').Function.bind;\n","require('../../modules/es6.object.assign');\nmodule.exports = require('../../modules/_core').Object.assign;\n","module.exports = function (it) {\n  if (typeof it != 'function') throw TypeError(it + ' is not a function!');\n  return it;\n};\n","// 22.1.3.31 Array.prototype[@@unscopables]\nvar UNSCOPABLES = require('./_wks')('unscopables');\nvar ArrayProto = Array.prototype;\nif (ArrayProto[UNSCOPABLES] == undefined) require('./_hide')(ArrayProto, UNSCOPABLES, {});\nmodule.exports = function (key) {\n  ArrayProto[UNSCOPABLES][key] = true;\n};\n","module.exports = function (it, Constructor, name, forbiddenField) {\n  if (!(it instanceof Constructor) || (forbiddenField !== undefined && forbiddenField in it)) {\n    throw TypeError(name + ': incorrect invocation!');\n  } return it;\n};\n","var isObject = require('./_is-object');\nmodule.exports = function (it) {\n  if (!isObject(it)) throw TypeError(it + ' is not an object!');\n  return it;\n};\n","// false -> Array#indexOf\n// true  -> Array#includes\nvar toIObject = require('./_to-iobject');\nvar toLength = require('./_to-length');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nmodule.exports = function (IS_INCLUDES) {\n  return function ($this, el, fromIndex) {\n    var O = toIObject($this);\n    var length = toLength(O.length);\n    var index = toAbsoluteIndex(fromIndex, length);\n    var value;\n    // Array#includes uses SameValueZero equality algorithm\n    // eslint-disable-next-line no-self-compare\n    if (IS_INCLUDES && el != el) while (length > index) {\n      value = O[index++];\n      // eslint-disable-next-line no-self-compare\n      if (value != value) return true;\n    // Array#indexOf ignores holes, Array#includes - not\n    } else for (;length > index; index++) if (IS_INCLUDES || index in O) {\n      if (O[index] === el) return IS_INCLUDES || index || 0;\n    } return !IS_INCLUDES && -1;\n  };\n};\n","// 0 -> Array#forEach\n// 1 -> Array#map\n// 2 -> Array#filter\n// 3 -> Array#some\n// 4 -> Array#every\n// 5 -> Array#find\n// 6 -> Array#findIndex\nvar ctx = require('./_ctx');\nvar IObject = require('./_iobject');\nvar toObject = require('./_to-object');\nvar toLength = require('./_to-length');\nvar asc = require('./_array-species-create');\nmodule.exports = function (TYPE, $create) {\n  var IS_MAP = TYPE == 1;\n  var IS_FILTER = TYPE == 2;\n  var IS_SOME = TYPE == 3;\n  var IS_EVERY = TYPE == 4;\n  var IS_FIND_INDEX = TYPE == 6;\n  var NO_HOLES = TYPE == 5 || IS_FIND_INDEX;\n  var create = $create || asc;\n  return function ($this, callbackfn, that) {\n    var O = toObject($this);\n    var self = IObject(O);\n    var f = ctx(callbackfn, that, 3);\n    var length = toLength(self.length);\n    var index = 0;\n    var result = IS_MAP ? create($this, length) : IS_FILTER ? create($this, 0) : undefined;\n    var val, res;\n    for (;length > index; index++) if (NO_HOLES || index in self) {\n      val = self[index];\n      res = f(val, index, O);\n      if (TYPE) {\n        if (IS_MAP) result[index] = res;   // map\n        else if (res) switch (TYPE) {\n          case 3: return true;             // some\n          case 5: return val;              // find\n          case 6: return index;            // findIndex\n          case 2: result.push(val);        // filter\n        } else if (IS_EVERY) return false; // every\n      }\n    }\n    return IS_FIND_INDEX ? -1 : IS_SOME || IS_EVERY ? IS_EVERY : result;\n  };\n};\n","var isObject = require('./_is-object');\nvar isArray = require('./_is-array');\nvar SPECIES = require('./_wks')('species');\n\nmodule.exports = function (original) {\n  var C;\n  if (isArray(original)) {\n    C = original.constructor;\n    // cross-realm fallback\n    if (typeof C == 'function' && (C === Array || isArray(C.prototype))) C = undefined;\n    if (isObject(C)) {\n      C = C[SPECIES];\n      if (C === null) C = undefined;\n    }\n  } return C === undefined ? Array : C;\n};\n","// 9.4.2.3 ArraySpeciesCreate(originalArray, length)\nvar speciesConstructor = require('./_array-species-constructor');\n\nmodule.exports = function (original, length) {\n  return new (speciesConstructor(original))(length);\n};\n","'use strict';\nvar aFunction = require('./_a-function');\nvar isObject = require('./_is-object');\nvar invoke = require('./_invoke');\nvar arraySlice = [].slice;\nvar factories = {};\n\nvar construct = function (F, len, args) {\n  if (!(len in factories)) {\n    for (var n = [], i = 0; i < len; i++) n[i] = 'a[' + i + ']';\n    // eslint-disable-next-line no-new-func\n    factories[len] = Function('F,a', 'return new F(' + n.join(',') + ')');\n  } return factories[len](F, args);\n};\n\nmodule.exports = Function.bind || function bind(that /* , ...args */) {\n  var fn = aFunction(this);\n  var partArgs = arraySlice.call(arguments, 1);\n  var bound = function (/* args... */) {\n    var args = partArgs.concat(arraySlice.call(arguments));\n    return this instanceof bound ? construct(fn, args.length, args) : invoke(fn, args, that);\n  };\n  if (isObject(fn.prototype)) bound.prototype = fn.prototype;\n  return bound;\n};\n","// getting tag from 19.1.3.6 Object.prototype.toString()\nvar cof = require('./_cof');\nvar TAG = require('./_wks')('toStringTag');\n// ES3 wrong here\nvar ARG = cof(function () { return arguments; }()) == 'Arguments';\n\n// fallback for IE11 Script Access Denied error\nvar tryGet = function (it, key) {\n  try {\n    return it[key];\n  } catch (e) { /* empty */ }\n};\n\nmodule.exports = function (it) {\n  var O, T, B;\n  return it === undefined ? 'Undefined' : it === null ? 'Null'\n    // @@toStringTag case\n    : typeof (T = tryGet(O = Object(it), TAG)) == 'string' ? T\n    // builtinTag case\n    : ARG ? cof(O)\n    // ES3 arguments fallback\n    : (B = cof(O)) == 'Object' && typeof O.callee == 'function' ? 'Arguments' : B;\n};\n","var toString = {}.toString;\n\nmodule.exports = function (it) {\n  return toString.call(it).slice(8, -1);\n};\n","var core = module.exports = { version: '2.6.4' };\nif (typeof __e == 'number') __e = core; // eslint-disable-line no-undef\n","// optional / simple context binding\nvar aFunction = require('./_a-function');\nmodule.exports = function (fn, that, length) {\n  aFunction(fn);\n  if (that === undefined) return fn;\n  switch (length) {\n    case 1: return function (a) {\n      return fn.call(that, a);\n    };\n    case 2: return function (a, b) {\n      return fn.call(that, a, b);\n    };\n    case 3: return function (a, b, c) {\n      return fn.call(that, a, b, c);\n    };\n  }\n  return function (/* ...args */) {\n    return fn.apply(that, arguments);\n  };\n};\n","// 7.2.1 RequireObjectCoercible(argument)\nmodule.exports = function (it) {\n  if (it == undefined) throw TypeError(\"Can't call method on  \" + it);\n  return it;\n};\n","// Thank's IE8 for his funny defineProperty\nmodule.exports = !require('./_fails')(function () {\n  return Object.defineProperty({}, 'a', { get: function () { return 7; } }).a != 7;\n});\n","var isObject = require('./_is-object');\nvar document = require('./_global').document;\n// typeof document.createElement is 'object' in old IE\nvar is = isObject(document) && isObject(document.createElement);\nmodule.exports = function (it) {\n  return is ? document.createElement(it) : {};\n};\n","// IE 8- don't enum bug keys\nmodule.exports = (\n  'constructor,hasOwnProperty,isPrototypeOf,propertyIsEnumerable,toLocaleString,toString,valueOf'\n).split(',');\n","var global = require('./_global');\nvar core = require('./_core');\nvar hide = require('./_hide');\nvar redefine = require('./_redefine');\nvar ctx = require('./_ctx');\nvar PROTOTYPE = 'prototype';\n\nvar $export = function (type, name, source) {\n  var IS_FORCED = type & $export.F;\n  var IS_GLOBAL = type & $export.G;\n  var IS_STATIC = type & $export.S;\n  var IS_PROTO = type & $export.P;\n  var IS_BIND = type & $export.B;\n  var target = IS_GLOBAL ? global : IS_STATIC ? global[name] || (global[name] = {}) : (global[name] || {})[PROTOTYPE];\n  var exports = IS_GLOBAL ? core : core[name] || (core[name] = {});\n  var expProto = exports[PROTOTYPE] || (exports[PROTOTYPE] = {});\n  var key, own, out, exp;\n  if (IS_GLOBAL) source = name;\n  for (key in source) {\n    // contains in native\n    own = !IS_FORCED && target && target[key] !== undefined;\n    // export native or passed\n    out = (own ? target : source)[key];\n    // bind timers to global for call from export context\n    exp = IS_BIND && own ? ctx(out, global) : IS_PROTO && typeof out == 'function' ? ctx(Function.call, out) : out;\n    // extend global\n    if (target) redefine(target, key, out, type & $export.U);\n    // export\n    if (exports[key] != out) hide(exports, key, exp);\n    if (IS_PROTO && expProto[key] != out) expProto[key] = out;\n  }\n};\nglobal.core = core;\n// type bitmap\n$export.F = 1;   // forced\n$export.G = 2;   // global\n$export.S = 4;   // static\n$export.P = 8;   // proto\n$export.B = 16;  // bind\n$export.W = 32;  // wrap\n$export.U = 64;  // safe\n$export.R = 128; // real proto method for `library`\nmodule.exports = $export;\n","module.exports = function (exec) {\n  try {\n    return !!exec();\n  } catch (e) {\n    return true;\n  }\n};\n","var ctx = require('./_ctx');\nvar call = require('./_iter-call');\nvar isArrayIter = require('./_is-array-iter');\nvar anObject = require('./_an-object');\nvar toLength = require('./_to-length');\nvar getIterFn = require('./core.get-iterator-method');\nvar BREAK = {};\nvar RETURN = {};\nvar exports = module.exports = function (iterable, entries, fn, that, ITERATOR) {\n  var iterFn = ITERATOR ? function () { return iterable; } : getIterFn(iterable);\n  var f = ctx(fn, that, entries ? 2 : 1);\n  var index = 0;\n  var length, step, iterator, result;\n  if (typeof iterFn != 'function') throw TypeError(iterable + ' is not iterable!');\n  // fast case for arrays with default iterator\n  if (isArrayIter(iterFn)) for (length = toLength(iterable.length); length > index; index++) {\n    result = entries ? f(anObject(step = iterable[index])[0], step[1]) : f(iterable[index]);\n    if (result === BREAK || result === RETURN) return result;\n  } else for (iterator = iterFn.call(iterable); !(step = iterator.next()).done;) {\n    result = call(iterator, f, step.value, entries);\n    if (result === BREAK || result === RETURN) return result;\n  }\n};\nexports.BREAK = BREAK;\nexports.RETURN = RETURN;\n","module.exports = require('./_shared')('native-function-to-string', Function.toString);\n","// https://github.com/zloirock/core-js/issues/86#issuecomment-115759028\nvar global = module.exports = typeof window != 'undefined' && window.Math == Math\n  ? window : typeof self != 'undefined' && self.Math == Math ? self\n  // eslint-disable-next-line no-new-func\n  : Function('return this')();\nif (typeof __g == 'number') __g = global; // eslint-disable-line no-undef\n","var hasOwnProperty = {}.hasOwnProperty;\nmodule.exports = function (it, key) {\n  return hasOwnProperty.call(it, key);\n};\n","var dP = require('./_object-dp');\nvar createDesc = require('./_property-desc');\nmodule.exports = require('./_descriptors') ? function (object, key, value) {\n  return dP.f(object, key, createDesc(1, value));\n} : function (object, key, value) {\n  object[key] = value;\n  return object;\n};\n","var document = require('./_global').document;\nmodule.exports = document && document.documentElement;\n","module.exports = !require('./_descriptors') && !require('./_fails')(function () {\n  return Object.defineProperty(require('./_dom-create')('div'), 'a', { get: function () { return 7; } }).a != 7;\n});\n","// fast apply, http://jsperf.lnkit.com/fast-apply/5\nmodule.exports = function (fn, args, that) {\n  var un = that === undefined;\n  switch (args.length) {\n    case 0: return un ? fn()\n                      : fn.call(that);\n    case 1: return un ? fn(args[0])\n                      : fn.call(that, args[0]);\n    case 2: return un ? fn(args[0], args[1])\n                      : fn.call(that, args[0], args[1]);\n    case 3: return un ? fn(args[0], args[1], args[2])\n                      : fn.call(that, args[0], args[1], args[2]);\n    case 4: return un ? fn(args[0], args[1], args[2], args[3])\n                      : fn.call(that, args[0], args[1], args[2], args[3]);\n  } return fn.apply(that, args);\n};\n","// fallback for non-array-like ES3 and non-enumerable old V8 strings\nvar cof = require('./_cof');\n// eslint-disable-next-line no-prototype-builtins\nmodule.exports = Object('z').propertyIsEnumerable(0) ? Object : function (it) {\n  return cof(it) == 'String' ? it.split('') : Object(it);\n};\n","// check on default Array iterator\nvar Iterators = require('./_iterators');\nvar ITERATOR = require('./_wks')('iterator');\nvar ArrayProto = Array.prototype;\n\nmodule.exports = function (it) {\n  return it !== undefined && (Iterators.Array === it || ArrayProto[ITERATOR] === it);\n};\n","// 7.2.2 IsArray(argument)\nvar cof = require('./_cof');\nmodule.exports = Array.isArray || function isArray(arg) {\n  return cof(arg) == 'Array';\n};\n","module.exports = function (it) {\n  return typeof it === 'object' ? it !== null : typeof it === 'function';\n};\n","// call something on iterator step with safe closing on error\nvar anObject = require('./_an-object');\nmodule.exports = function (iterator, fn, value, entries) {\n  try {\n    return entries ? fn(anObject(value)[0], value[1]) : fn(value);\n  // 7.4.6 IteratorClose(iterator, completion)\n  } catch (e) {\n    var ret = iterator['return'];\n    if (ret !== undefined) anObject(ret.call(iterator));\n    throw e;\n  }\n};\n","'use strict';\nvar create = require('./_object-create');\nvar descriptor = require('./_property-desc');\nvar setToStringTag = require('./_set-to-string-tag');\nvar IteratorPrototype = {};\n\n// 25.1.2.1.1 %IteratorPrototype%[@@iterator]()\nrequire('./_hide')(IteratorPrototype, require('./_wks')('iterator'), function () { return this; });\n\nmodule.exports = function (Constructor, NAME, next) {\n  Constructor.prototype = create(IteratorPrototype, { next: descriptor(1, next) });\n  setToStringTag(Constructor, NAME + ' Iterator');\n};\n","'use strict';\nvar LIBRARY = require('./_library');\nvar $export = require('./_export');\nvar redefine = require('./_redefine');\nvar hide = require('./_hide');\nvar Iterators = require('./_iterators');\nvar $iterCreate = require('./_iter-create');\nvar setToStringTag = require('./_set-to-string-tag');\nvar getPrototypeOf = require('./_object-gpo');\nvar ITERATOR = require('./_wks')('iterator');\nvar BUGGY = !([].keys && 'next' in [].keys()); // Safari has buggy iterators w/o `next`\nvar FF_ITERATOR = '@@iterator';\nvar KEYS = 'keys';\nvar VALUES = 'values';\n\nvar returnThis = function () { return this; };\n\nmodule.exports = function (Base, NAME, Constructor, next, DEFAULT, IS_SET, FORCED) {\n  $iterCreate(Constructor, NAME, next);\n  var getMethod = function (kind) {\n    if (!BUGGY && kind in proto) return proto[kind];\n    switch (kind) {\n      case KEYS: return function keys() { return new Constructor(this, kind); };\n      case VALUES: return function values() { return new Constructor(this, kind); };\n    } return function entries() { return new Constructor(this, kind); };\n  };\n  var TAG = NAME + ' Iterator';\n  var DEF_VALUES = DEFAULT == VALUES;\n  var VALUES_BUG = false;\n  var proto = Base.prototype;\n  var $native = proto[ITERATOR] || proto[FF_ITERATOR] || DEFAULT && proto[DEFAULT];\n  var $default = $native || getMethod(DEFAULT);\n  var $entries = DEFAULT ? !DEF_VALUES ? $default : getMethod('entries') : undefined;\n  var $anyNative = NAME == 'Array' ? proto.entries || $native : $native;\n  var methods, key, IteratorPrototype;\n  // Fix native\n  if ($anyNative) {\n    IteratorPrototype = getPrototypeOf($anyNative.call(new Base()));\n    if (IteratorPrototype !== Object.prototype && IteratorPrototype.next) {\n      // Set @@toStringTag to native iterators\n      setToStringTag(IteratorPrototype, TAG, true);\n      // fix for some old engines\n      if (!LIBRARY && typeof IteratorPrototype[ITERATOR] != 'function') hide(IteratorPrototype, ITERATOR, returnThis);\n    }\n  }\n  // fix Array#{values, @@iterator}.name in V8 / FF\n  if (DEF_VALUES && $native && $native.name !== VALUES) {\n    VALUES_BUG = true;\n    $default = function values() { return $native.call(this); };\n  }\n  // Define iterator\n  if ((!LIBRARY || FORCED) && (BUGGY || VALUES_BUG || !proto[ITERATOR])) {\n    hide(proto, ITERATOR, $default);\n  }\n  // Plug for library\n  Iterators[NAME] = $default;\n  Iterators[TAG] = returnThis;\n  if (DEFAULT) {\n    methods = {\n      values: DEF_VALUES ? $default : getMethod(VALUES),\n      keys: IS_SET ? $default : getMethod(KEYS),\n      entries: $entries\n    };\n    if (FORCED) for (key in methods) {\n      if (!(key in proto)) redefine(proto, key, methods[key]);\n    } else $export($export.P + $export.F * (BUGGY || VALUES_BUG), NAME, methods);\n  }\n  return methods;\n};\n","var ITERATOR = require('./_wks')('iterator');\nvar SAFE_CLOSING = false;\n\ntry {\n  var riter = [7][ITERATOR]();\n  riter['return'] = function () { SAFE_CLOSING = true; };\n  // eslint-disable-next-line no-throw-literal\n  Array.from(riter, function () { throw 2; });\n} catch (e) { /* empty */ }\n\nmodule.exports = function (exec, skipClosing) {\n  if (!skipClosing && !SAFE_CLOSING) return false;\n  var safe = false;\n  try {\n    var arr = [7];\n    var iter = arr[ITERATOR]();\n    iter.next = function () { return { done: safe = true }; };\n    arr[ITERATOR] = function () { return iter; };\n    exec(arr);\n  } catch (e) { /* empty */ }\n  return safe;\n};\n","module.exports = function (done, value) {\n  return { value: value, done: !!done };\n};\n","module.exports = {};\n","module.exports = false;\n","var global = require('./_global');\nvar macrotask = require('./_task').set;\nvar Observer = global.MutationObserver || global.WebKitMutationObserver;\nvar process = global.process;\nvar Promise = global.Promise;\nvar isNode = require('./_cof')(process) == 'process';\n\nmodule.exports = function () {\n  var head, last, notify;\n\n  var flush = function () {\n    var parent, fn;\n    if (isNode && (parent = process.domain)) parent.exit();\n    while (head) {\n      fn = head.fn;\n      head = head.next;\n      try {\n        fn();\n      } catch (e) {\n        if (head) notify();\n        else last = undefined;\n        throw e;\n      }\n    } last = undefined;\n    if (parent) parent.enter();\n  };\n\n  // Node.js\n  if (isNode) {\n    notify = function () {\n      process.nextTick(flush);\n    };\n  // browsers with MutationObserver, except iOS Safari - https://github.com/zloirock/core-js/issues/339\n  } else if (Observer && !(global.navigator && global.navigator.standalone)) {\n    var toggle = true;\n    var node = document.createTextNode('');\n    new Observer(flush).observe(node, { characterData: true }); // eslint-disable-line no-new\n    notify = function () {\n      node.data = toggle = !toggle;\n    };\n  // environments with maybe non-completely correct, but existent Promise\n  } else if (Promise && Promise.resolve) {\n    // Promise.resolve without an argument throws an error in LG WebOS 2\n    var promise = Promise.resolve(undefined);\n    notify = function () {\n      promise.then(flush);\n    };\n  // for other environments - macrotask based on:\n  // - setImmediate\n  // - MessageChannel\n  // - window.postMessag\n  // - onreadystatechange\n  // - setTimeout\n  } else {\n    notify = function () {\n      // strange IE + webpack dev server bug - use .call(global)\n      macrotask.call(global, flush);\n    };\n  }\n\n  return function (fn) {\n    var task = { fn: fn, next: undefined };\n    if (last) last.next = task;\n    if (!head) {\n      head = task;\n      notify();\n    } last = task;\n  };\n};\n","'use strict';\n// 25.4.1.5 NewPromiseCapability(C)\nvar aFunction = require('./_a-function');\n\nfunction PromiseCapability(C) {\n  var resolve, reject;\n  this.promise = new C(function ($$resolve, $$reject) {\n    if (resolve !== undefined || reject !== undefined) throw TypeError('Bad Promise constructor');\n    resolve = $$resolve;\n    reject = $$reject;\n  });\n  this.resolve = aFunction(resolve);\n  this.reject = aFunction(reject);\n}\n\nmodule.exports.f = function (C) {\n  return new PromiseCapability(C);\n};\n","'use strict';\n// 19.1.2.1 Object.assign(target, source, ...)\nvar getKeys = require('./_object-keys');\nvar gOPS = require('./_object-gops');\nvar pIE = require('./_object-pie');\nvar toObject = require('./_to-object');\nvar IObject = require('./_iobject');\nvar $assign = Object.assign;\n\n// should work with symbols and should have deterministic property order (V8 bug)\nmodule.exports = !$assign || require('./_fails')(function () {\n  var A = {};\n  var B = {};\n  // eslint-disable-next-line no-undef\n  var S = Symbol();\n  var K = 'abcdefghijklmnopqrst';\n  A[S] = 7;\n  K.split('').forEach(function (k) { B[k] = k; });\n  return $assign({}, A)[S] != 7 || Object.keys($assign({}, B)).join('') != K;\n}) ? function assign(target, source) { // eslint-disable-line no-unused-vars\n  var T = toObject(target);\n  var aLen = arguments.length;\n  var index = 1;\n  var getSymbols = gOPS.f;\n  var isEnum = pIE.f;\n  while (aLen > index) {\n    var S = IObject(arguments[index++]);\n    var keys = getSymbols ? getKeys(S).concat(getSymbols(S)) : getKeys(S);\n    var length = keys.length;\n    var j = 0;\n    var key;\n    while (length > j) if (isEnum.call(S, key = keys[j++])) T[key] = S[key];\n  } return T;\n} : $assign;\n","// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\nvar anObject = require('./_an-object');\nvar dPs = require('./_object-dps');\nvar enumBugKeys = require('./_enum-bug-keys');\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\nvar Empty = function () { /* empty */ };\nvar PROTOTYPE = 'prototype';\n\n// Create object with fake `null` prototype: use iframe Object with cleared prototype\nvar createDict = function () {\n  // Thrash, waste and sodomy: IE GC bug\n  var iframe = require('./_dom-create')('iframe');\n  var i = enumBugKeys.length;\n  var lt = '<';\n  var gt = '>';\n  var iframeDocument;\n  iframe.style.display = 'none';\n  require('./_html').appendChild(iframe);\n  iframe.src = 'javascript:'; // eslint-disable-line no-script-url\n  // createDict = iframe.contentWindow.Object;\n  // html.removeChild(iframe);\n  iframeDocument = iframe.contentWindow.document;\n  iframeDocument.open();\n  iframeDocument.write(lt + 'script' + gt + 'document.F=Object' + lt + '/script' + gt);\n  iframeDocument.close();\n  createDict = iframeDocument.F;\n  while (i--) delete createDict[PROTOTYPE][enumBugKeys[i]];\n  return createDict();\n};\n\nmodule.exports = Object.create || function create(O, Properties) {\n  var result;\n  if (O !== null) {\n    Empty[PROTOTYPE] = anObject(O);\n    result = new Empty();\n    Empty[PROTOTYPE] = null;\n    // add \"__proto__\" for Object.getPrototypeOf polyfill\n    result[IE_PROTO] = O;\n  } else result = createDict();\n  return Properties === undefined ? result : dPs(result, Properties);\n};\n","var anObject = require('./_an-object');\nvar IE8_DOM_DEFINE = require('./_ie8-dom-define');\nvar toPrimitive = require('./_to-primitive');\nvar dP = Object.defineProperty;\n\nexports.f = require('./_descriptors') ? Object.defineProperty : function defineProperty(O, P, Attributes) {\n  anObject(O);\n  P = toPrimitive(P, true);\n  anObject(Attributes);\n  if (IE8_DOM_DEFINE) try {\n    return dP(O, P, Attributes);\n  } catch (e) { /* empty */ }\n  if ('get' in Attributes || 'set' in Attributes) throw TypeError('Accessors not supported!');\n  if ('value' in Attributes) O[P] = Attributes.value;\n  return O;\n};\n","var dP = require('./_object-dp');\nvar anObject = require('./_an-object');\nvar getKeys = require('./_object-keys');\n\nmodule.exports = require('./_descriptors') ? Object.defineProperties : function defineProperties(O, Properties) {\n  anObject(O);\n  var keys = getKeys(Properties);\n  var length = keys.length;\n  var i = 0;\n  var P;\n  while (length > i) dP.f(O, P = keys[i++], Properties[P]);\n  return O;\n};\n","exports.f = Object.getOwnPropertySymbols;\n","// 19.1.2.9 / 15.2.3.2 Object.getPrototypeOf(O)\nvar has = require('./_has');\nvar toObject = require('./_to-object');\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\nvar ObjectProto = Object.prototype;\n\nmodule.exports = Object.getPrototypeOf || function (O) {\n  O = toObject(O);\n  if (has(O, IE_PROTO)) return O[IE_PROTO];\n  if (typeof O.constructor == 'function' && O instanceof O.constructor) {\n    return O.constructor.prototype;\n  } return O instanceof Object ? ObjectProto : null;\n};\n","var has = require('./_has');\nvar toIObject = require('./_to-iobject');\nvar arrayIndexOf = require('./_array-includes')(false);\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\n\nmodule.exports = function (object, names) {\n  var O = toIObject(object);\n  var i = 0;\n  var result = [];\n  var key;\n  for (key in O) if (key != IE_PROTO) has(O, key) && result.push(key);\n  // Don't enum bug & hidden keys\n  while (names.length > i) if (has(O, key = names[i++])) {\n    ~arrayIndexOf(result, key) || result.push(key);\n  }\n  return result;\n};\n","// 19.1.2.14 / 15.2.3.14 Object.keys(O)\nvar $keys = require('./_object-keys-internal');\nvar enumBugKeys = require('./_enum-bug-keys');\n\nmodule.exports = Object.keys || function keys(O) {\n  return $keys(O, enumBugKeys);\n};\n","exports.f = {}.propertyIsEnumerable;\n","module.exports = function (exec) {\n  try {\n    return { e: false, v: exec() };\n  } catch (e) {\n    return { e: true, v: e };\n  }\n};\n","var anObject = require('./_an-object');\nvar isObject = require('./_is-object');\nvar newPromiseCapability = require('./_new-promise-capability');\n\nmodule.exports = function (C, x) {\n  anObject(C);\n  if (isObject(x) && x.constructor === C) return x;\n  var promiseCapability = newPromiseCapability.f(C);\n  var resolve = promiseCapability.resolve;\n  resolve(x);\n  return promiseCapability.promise;\n};\n","module.exports = function (bitmap, value) {\n  return {\n    enumerable: !(bitmap & 1),\n    configurable: !(bitmap & 2),\n    writable: !(bitmap & 4),\n    value: value\n  };\n};\n","var redefine = require('./_redefine');\nmodule.exports = function (target, src, safe) {\n  for (var key in src) redefine(target, key, src[key], safe);\n  return target;\n};\n","var global = require('./_global');\nvar hide = require('./_hide');\nvar has = require('./_has');\nvar SRC = require('./_uid')('src');\nvar $toString = require('./_function-to-string');\nvar TO_STRING = 'toString';\nvar TPL = ('' + $toString).split(TO_STRING);\n\nrequire('./_core').inspectSource = function (it) {\n  return $toString.call(it);\n};\n\n(module.exports = function (O, key, val, safe) {\n  var isFunction = typeof val == 'function';\n  if (isFunction) has(val, 'name') || hide(val, 'name', key);\n  if (O[key] === val) return;\n  if (isFunction) has(val, SRC) || hide(val, SRC, O[key] ? '' + O[key] : TPL.join(String(key)));\n  if (O === global) {\n    O[key] = val;\n  } else if (!safe) {\n    delete O[key];\n    hide(O, key, val);\n  } else if (O[key]) {\n    O[key] = val;\n  } else {\n    hide(O, key, val);\n  }\n// add fake Function#toString for correct work wrapped methods / constructors with methods like LoDash isNative\n})(Function.prototype, TO_STRING, function toString() {\n  return typeof this == 'function' && this[SRC] || $toString.call(this);\n});\n","'use strict';\nvar global = require('./_global');\nvar dP = require('./_object-dp');\nvar DESCRIPTORS = require('./_descriptors');\nvar SPECIES = require('./_wks')('species');\n\nmodule.exports = function (KEY) {\n  var C = global[KEY];\n  if (DESCRIPTORS && C && !C[SPECIES]) dP.f(C, SPECIES, {\n    configurable: true,\n    get: function () { return this; }\n  });\n};\n","var def = require('./_object-dp').f;\nvar has = require('./_has');\nvar TAG = require('./_wks')('toStringTag');\n\nmodule.exports = function (it, tag, stat) {\n  if (it && !has(it = stat ? it : it.prototype, TAG)) def(it, TAG, { configurable: true, value: tag });\n};\n","var shared = require('./_shared')('keys');\nvar uid = require('./_uid');\nmodule.exports = function (key) {\n  return shared[key] || (shared[key] = uid(key));\n};\n","var core = require('./_core');\nvar global = require('./_global');\nvar SHARED = '__core-js_shared__';\nvar store = global[SHARED] || (global[SHARED] = {});\n\n(module.exports = function (key, value) {\n  return store[key] || (store[key] = value !== undefined ? value : {});\n})('versions', []).push({\n  version: core.version,\n  mode: require('./_library') ? 'pure' : 'global',\n  copyright: '© 2019 Denis Pushkarev (zloirock.ru)'\n});\n","// 7.3.20 SpeciesConstructor(O, defaultConstructor)\nvar anObject = require('./_an-object');\nvar aFunction = require('./_a-function');\nvar SPECIES = require('./_wks')('species');\nmodule.exports = function (O, D) {\n  var C = anObject(O).constructor;\n  var S;\n  return C === undefined || (S = anObject(C)[SPECIES]) == undefined ? D : aFunction(S);\n};\n","'use strict';\nvar fails = require('./_fails');\n\nmodule.exports = function (method, arg) {\n  return !!method && fails(function () {\n    // eslint-disable-next-line no-useless-call\n    arg ? method.call(null, function () { /* empty */ }, 1) : method.call(null);\n  });\n};\n","var toInteger = require('./_to-integer');\nvar defined = require('./_defined');\n// true  -> String#at\n// false -> String#codePointAt\nmodule.exports = function (TO_STRING) {\n  return function (that, pos) {\n    var s = String(defined(that));\n    var i = toInteger(pos);\n    var l = s.length;\n    var a, b;\n    if (i < 0 || i >= l) return TO_STRING ? '' : undefined;\n    a = s.charCodeAt(i);\n    return a < 0xd800 || a > 0xdbff || i + 1 === l || (b = s.charCodeAt(i + 1)) < 0xdc00 || b > 0xdfff\n      ? TO_STRING ? s.charAt(i) : a\n      : TO_STRING ? s.slice(i, i + 2) : (a - 0xd800 << 10) + (b - 0xdc00) + 0x10000;\n  };\n};\n","var ctx = require('./_ctx');\nvar invoke = require('./_invoke');\nvar html = require('./_html');\nvar cel = require('./_dom-create');\nvar global = require('./_global');\nvar process = global.process;\nvar setTask = global.setImmediate;\nvar clearTask = global.clearImmediate;\nvar MessageChannel = global.MessageChannel;\nvar Dispatch = global.Dispatch;\nvar counter = 0;\nvar queue = {};\nvar ONREADYSTATECHANGE = 'onreadystatechange';\nvar defer, channel, port;\nvar run = function () {\n  var id = +this;\n  // eslint-disable-next-line no-prototype-builtins\n  if (queue.hasOwnProperty(id)) {\n    var fn = queue[id];\n    delete queue[id];\n    fn();\n  }\n};\nvar listener = function (event) {\n  run.call(event.data);\n};\n// Node.js 0.9+ & IE10+ has setImmediate, otherwise:\nif (!setTask || !clearTask) {\n  setTask = function setImmediate(fn) {\n    var args = [];\n    var i = 1;\n    while (arguments.length > i) args.push(arguments[i++]);\n    queue[++counter] = function () {\n      // eslint-disable-next-line no-new-func\n      invoke(typeof fn == 'function' ? fn : Function(fn), args);\n    };\n    defer(counter);\n    return counter;\n  };\n  clearTask = function clearImmediate(id) {\n    delete queue[id];\n  };\n  // Node.js 0.8-\n  if (require('./_cof')(process) == 'process') {\n    defer = function (id) {\n      process.nextTick(ctx(run, id, 1));\n    };\n  // Sphere (JS game engine) Dispatch API\n  } else if (Dispatch && Dispatch.now) {\n    defer = function (id) {\n      Dispatch.now(ctx(run, id, 1));\n    };\n  // Browsers with MessageChannel, includes WebWorkers\n  } else if (MessageChannel) {\n    channel = new MessageChannel();\n    port = channel.port2;\n    channel.port1.onmessage = listener;\n    defer = ctx(port.postMessage, port, 1);\n  // Browsers with postMessage, skip WebWorkers\n  // IE8 has postMessage, but it's sync & typeof its postMessage is 'object'\n  } else if (global.addEventListener && typeof postMessage == 'function' && !global.importScripts) {\n    defer = function (id) {\n      global.postMessage(id + '', '*');\n    };\n    global.addEventListener('message', listener, false);\n  // IE8-\n  } else if (ONREADYSTATECHANGE in cel('script')) {\n    defer = function (id) {\n      html.appendChild(cel('script'))[ONREADYSTATECHANGE] = function () {\n        html.removeChild(this);\n        run.call(id);\n      };\n    };\n  // Rest old browsers\n  } else {\n    defer = function (id) {\n      setTimeout(ctx(run, id, 1), 0);\n    };\n  }\n}\nmodule.exports = {\n  set: setTask,\n  clear: clearTask\n};\n","var toInteger = require('./_to-integer');\nvar max = Math.max;\nvar min = Math.min;\nmodule.exports = function (index, length) {\n  index = toInteger(index);\n  return index < 0 ? max(index + length, 0) : min(index, length);\n};\n","// 7.1.4 ToInteger\nvar ceil = Math.ceil;\nvar floor = Math.floor;\nmodule.exports = function (it) {\n  return isNaN(it = +it) ? 0 : (it > 0 ? floor : ceil)(it);\n};\n","// to indexed object, toObject with fallback for non-array-like ES3 strings\nvar IObject = require('./_iobject');\nvar defined = require('./_defined');\nmodule.exports = function (it) {\n  return IObject(defined(it));\n};\n","// 7.1.15 ToLength\nvar toInteger = require('./_to-integer');\nvar min = Math.min;\nmodule.exports = function (it) {\n  return it > 0 ? min(toInteger(it), 0x1fffffffffffff) : 0; // pow(2, 53) - 1 == 9007199254740991\n};\n","// 7.1.13 ToObject(argument)\nvar defined = require('./_defined');\nmodule.exports = function (it) {\n  return Object(defined(it));\n};\n","// 7.1.1 ToPrimitive(input [, PreferredType])\nvar isObject = require('./_is-object');\n// instead of the ES6 spec version, we didn't implement @@toPrimitive case\n// and the second argument - flag - preferred type is a string\nmodule.exports = function (it, S) {\n  if (!isObject(it)) return it;\n  var fn, val;\n  if (S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (typeof (fn = it.valueOf) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (!S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  throw TypeError(\"Can't convert object to primitive value\");\n};\n","var id = 0;\nvar px = Math.random();\nmodule.exports = function (key) {\n  return 'Symbol('.concat(key === undefined ? '' : key, ')_', (++id + px).toString(36));\n};\n","var global = require('./_global');\nvar navigator = global.navigator;\n\nmodule.exports = navigator && navigator.userAgent || '';\n","var store = require('./_shared')('wks');\nvar uid = require('./_uid');\nvar Symbol = require('./_global').Symbol;\nvar USE_SYMBOL = typeof Symbol == 'function';\n\nvar $exports = module.exports = function (name) {\n  return store[name] || (store[name] =\n    USE_SYMBOL && Symbol[name] || (USE_SYMBOL ? Symbol : uid)('Symbol.' + name));\n};\n\n$exports.store = store;\n","var classof = require('./_classof');\nvar ITERATOR = require('./_wks')('iterator');\nvar Iterators = require('./_iterators');\nmodule.exports = require('./_core').getIteratorMethod = function (it) {\n  if (it != undefined) return it[ITERATOR]\n    || it['@@iterator']\n    || Iterators[classof(it)];\n};\n","'use strict';\n// 22.1.3.8 Array.prototype.find(predicate, thisArg = undefined)\nvar $export = require('./_export');\nvar $find = require('./_array-methods')(5);\nvar KEY = 'find';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  find: function find(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\nrequire('./_add-to-unscopables')(KEY);\n","// 22.1.2.2 / 15.4.3.2 Array.isArray(arg)\nvar $export = require('./_export');\n\n$export($export.S, 'Array', { isArray: require('./_is-array') });\n","'use strict';\nvar addToUnscopables = require('./_add-to-unscopables');\nvar step = require('./_iter-step');\nvar Iterators = require('./_iterators');\nvar toIObject = require('./_to-iobject');\n\n// 22.1.3.4 Array.prototype.entries()\n// 22.1.3.13 Array.prototype.keys()\n// 22.1.3.29 Array.prototype.values()\n// 22.1.3.30 Array.prototype[@@iterator]()\nmodule.exports = require('./_iter-define')(Array, 'Array', function (iterated, kind) {\n  this._t = toIObject(iterated); // target\n  this._i = 0;                   // next index\n  this._k = kind;                // kind\n// 22.1.5.2.1 %ArrayIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var kind = this._k;\n  var index = this._i++;\n  if (!O || index >= O.length) {\n    this._t = undefined;\n    return step(1);\n  }\n  if (kind == 'keys') return step(0, index);\n  if (kind == 'values') return step(0, O[index]);\n  return step(0, [index, O[index]]);\n}, 'values');\n\n// argumentsList[@@iterator] is %ArrayProto_values% (9.4.4.6, 9.4.4.7)\nIterators.Arguments = Iterators.Array;\n\naddToUnscopables('keys');\naddToUnscopables('values');\naddToUnscopables('entries');\n","'use strict';\nvar $export = require('./_export');\nvar $some = require('./_array-methods')(3);\n\n$export($export.P + $export.F * !require('./_strict-method')([].some, true), 'Array', {\n  // 22.1.3.23 / 15.4.4.17 Array.prototype.some(callbackfn [, thisArg])\n  some: function some(callbackfn /* , thisArg */) {\n    return $some(this, callbackfn, arguments[1]);\n  }\n});\n","// 19.2.3.2 / 15.3.4.5 Function.prototype.bind(thisArg, args...)\nvar $export = require('./_export');\n\n$export($export.P, 'Function', { bind: require('./_bind') });\n","// 19.1.3.1 Object.assign(target, source)\nvar $export = require('./_export');\n\n$export($export.S + $export.F, 'Object', { assign: require('./_object-assign') });\n","'use strict';\n// 19.1.3.6 Object.prototype.toString()\nvar classof = require('./_classof');\nvar test = {};\ntest[require('./_wks')('toStringTag')] = 'z';\nif (test + '' != '[object z]') {\n  require('./_redefine')(Object.prototype, 'toString', function toString() {\n    return '[object ' + classof(this) + ']';\n  }, true);\n}\n","'use strict';\nvar LIBRARY = require('./_library');\nvar global = require('./_global');\nvar ctx = require('./_ctx');\nvar classof = require('./_classof');\nvar $export = require('./_export');\nvar isObject = require('./_is-object');\nvar aFunction = require('./_a-function');\nvar anInstance = require('./_an-instance');\nvar forOf = require('./_for-of');\nvar speciesConstructor = require('./_species-constructor');\nvar task = require('./_task').set;\nvar microtask = require('./_microtask')();\nvar newPromiseCapabilityModule = require('./_new-promise-capability');\nvar perform = require('./_perform');\nvar userAgent = require('./_user-agent');\nvar promiseResolve = require('./_promise-resolve');\nvar PROMISE = 'Promise';\nvar TypeError = global.TypeError;\nvar process = global.process;\nvar versions = process && process.versions;\nvar v8 = versions && versions.v8 || '';\nvar $Promise = global[PROMISE];\nvar isNode = classof(process) == 'process';\nvar empty = function () { /* empty */ };\nvar Internal, newGenericPromiseCapability, OwnPromiseCapability, Wrapper;\nvar newPromiseCapability = newGenericPromiseCapability = newPromiseCapabilityModule.f;\n\nvar USE_NATIVE = !!function () {\n  try {\n    // correct subclassing with @@species support\n    var promise = $Promise.resolve(1);\n    var FakePromise = (promise.constructor = {})[require('./_wks')('species')] = function (exec) {\n      exec(empty, empty);\n    };\n    // unhandled rejections tracking support, NodeJS Promise without it fails @@species test\n    return (isNode || typeof PromiseRejectionEvent == 'function')\n      && promise.then(empty) instanceof FakePromise\n      // v8 6.6 (Node 10 and Chrome 66) have a bug with resolving custom thenables\n      // https://bugs.chromium.org/p/chromium/issues/detail?id=830565\n      // we can't detect it synchronously, so just check versions\n      && v8.indexOf('6.6') !== 0\n      && userAgent.indexOf('Chrome/66') === -1;\n  } catch (e) { /* empty */ }\n}();\n\n// helpers\nvar isThenable = function (it) {\n  var then;\n  return isObject(it) && typeof (then = it.then) == 'function' ? then : false;\n};\nvar notify = function (promise, isReject) {\n  if (promise._n) return;\n  promise._n = true;\n  var chain = promise._c;\n  microtask(function () {\n    var value = promise._v;\n    var ok = promise._s == 1;\n    var i = 0;\n    var run = function (reaction) {\n      var handler = ok ? reaction.ok : reaction.fail;\n      var resolve = reaction.resolve;\n      var reject = reaction.reject;\n      var domain = reaction.domain;\n      var result, then, exited;\n      try {\n        if (handler) {\n          if (!ok) {\n            if (promise._h == 2) onHandleUnhandled(promise);\n            promise._h = 1;\n          }\n          if (handler === true) result = value;\n          else {\n            if (domain) domain.enter();\n            result = handler(value); // may throw\n            if (domain) {\n              domain.exit();\n              exited = true;\n            }\n          }\n          if (result === reaction.promise) {\n            reject(TypeError('Promise-chain cycle'));\n          } else if (then = isThenable(result)) {\n            then.call(result, resolve, reject);\n          } else resolve(result);\n        } else reject(value);\n      } catch (e) {\n        if (domain && !exited) domain.exit();\n        reject(e);\n      }\n    };\n    while (chain.length > i) run(chain[i++]); // variable length - can't use forEach\n    promise._c = [];\n    promise._n = false;\n    if (isReject && !promise._h) onUnhandled(promise);\n  });\n};\nvar onUnhandled = function (promise) {\n  task.call(global, function () {\n    var value = promise._v;\n    var unhandled = isUnhandled(promise);\n    var result, handler, console;\n    if (unhandled) {\n      result = perform(function () {\n        if (isNode) {\n          process.emit('unhandledRejection', value, promise);\n        } else if (handler = global.onunhandledrejection) {\n          handler({ promise: promise, reason: value });\n        } else if ((console = global.console) && console.error) {\n          console.error('Unhandled promise rejection', value);\n        }\n      });\n      // Browsers should not trigger `rejectionHandled` event if it was handled here, NodeJS - should\n      promise._h = isNode || isUnhandled(promise) ? 2 : 1;\n    } promise._a = undefined;\n    if (unhandled && result.e) throw result.v;\n  });\n};\nvar isUnhandled = function (promise) {\n  return promise._h !== 1 && (promise._a || promise._c).length === 0;\n};\nvar onHandleUnhandled = function (promise) {\n  task.call(global, function () {\n    var handler;\n    if (isNode) {\n      process.emit('rejectionHandled', promise);\n    } else if (handler = global.onrejectionhandled) {\n      handler({ promise: promise, reason: promise._v });\n    }\n  });\n};\nvar $reject = function (value) {\n  var promise = this;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  promise._v = value;\n  promise._s = 2;\n  if (!promise._a) promise._a = promise._c.slice();\n  notify(promise, true);\n};\nvar $resolve = function (value) {\n  var promise = this;\n  var then;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  try {\n    if (promise === value) throw TypeError(\"Promise can't be resolved itself\");\n    if (then = isThenable(value)) {\n      microtask(function () {\n        var wrapper = { _w: promise, _d: false }; // wrap\n        try {\n          then.call(value, ctx($resolve, wrapper, 1), ctx($reject, wrapper, 1));\n        } catch (e) {\n          $reject.call(wrapper, e);\n        }\n      });\n    } else {\n      promise._v = value;\n      promise._s = 1;\n      notify(promise, false);\n    }\n  } catch (e) {\n    $reject.call({ _w: promise, _d: false }, e); // wrap\n  }\n};\n\n// constructor polyfill\nif (!USE_NATIVE) {\n  // 25.4.3.1 Promise(executor)\n  $Promise = function Promise(executor) {\n    anInstance(this, $Promise, PROMISE, '_h');\n    aFunction(executor);\n    Internal.call(this);\n    try {\n      executor(ctx($resolve, this, 1), ctx($reject, this, 1));\n    } catch (err) {\n      $reject.call(this, err);\n    }\n  };\n  // eslint-disable-next-line no-unused-vars\n  Internal = function Promise(executor) {\n    this._c = [];             // <- awaiting reactions\n    this._a = undefined;      // <- checked in isUnhandled reactions\n    this._s = 0;              // <- state\n    this._d = false;          // <- done\n    this._v = undefined;      // <- value\n    this._h = 0;              // <- rejection state, 0 - default, 1 - handled, 2 - unhandled\n    this._n = false;          // <- notify\n  };\n  Internal.prototype = require('./_redefine-all')($Promise.prototype, {\n    // 25.4.5.3 Promise.prototype.then(onFulfilled, onRejected)\n    then: function then(onFulfilled, onRejected) {\n      var reaction = newPromiseCapability(speciesConstructor(this, $Promise));\n      reaction.ok = typeof onFulfilled == 'function' ? onFulfilled : true;\n      reaction.fail = typeof onRejected == 'function' && onRejected;\n      reaction.domain = isNode ? process.domain : undefined;\n      this._c.push(reaction);\n      if (this._a) this._a.push(reaction);\n      if (this._s) notify(this, false);\n      return reaction.promise;\n    },\n    // 25.4.5.1 Promise.prototype.catch(onRejected)\n    'catch': function (onRejected) {\n      return this.then(undefined, onRejected);\n    }\n  });\n  OwnPromiseCapability = function () {\n    var promise = new Internal();\n    this.promise = promise;\n    this.resolve = ctx($resolve, promise, 1);\n    this.reject = ctx($reject, promise, 1);\n  };\n  newPromiseCapabilityModule.f = newPromiseCapability = function (C) {\n    return C === $Promise || C === Wrapper\n      ? new OwnPromiseCapability(C)\n      : newGenericPromiseCapability(C);\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Promise: $Promise });\nrequire('./_set-to-string-tag')($Promise, PROMISE);\nrequire('./_set-species')(PROMISE);\nWrapper = require('./_core')[PROMISE];\n\n// statics\n$export($export.S + $export.F * !USE_NATIVE, PROMISE, {\n  // 25.4.4.5 Promise.reject(r)\n  reject: function reject(r) {\n    var capability = newPromiseCapability(this);\n    var $$reject = capability.reject;\n    $$reject(r);\n    return capability.promise;\n  }\n});\n$export($export.S + $export.F * (LIBRARY || !USE_NATIVE), PROMISE, {\n  // 25.4.4.6 Promise.resolve(x)\n  resolve: function resolve(x) {\n    return promiseResolve(LIBRARY && this === Wrapper ? $Promise : this, x);\n  }\n});\n$export($export.S + $export.F * !(USE_NATIVE && require('./_iter-detect')(function (iter) {\n  $Promise.all(iter)['catch'](empty);\n})), PROMISE, {\n  // 25.4.4.1 Promise.all(iterable)\n  all: function all(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var resolve = capability.resolve;\n    var reject = capability.reject;\n    var result = perform(function () {\n      var values = [];\n      var index = 0;\n      var remaining = 1;\n      forOf(iterable, false, function (promise) {\n        var $index = index++;\n        var alreadyCalled = false;\n        values.push(undefined);\n        remaining++;\n        C.resolve(promise).then(function (value) {\n          if (alreadyCalled) return;\n          alreadyCalled = true;\n          values[$index] = value;\n          --remaining || resolve(values);\n        }, reject);\n      });\n      --remaining || resolve(values);\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  },\n  // 25.4.4.4 Promise.race(iterable)\n  race: function race(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var reject = capability.reject;\n    var result = perform(function () {\n      forOf(iterable, false, function (promise) {\n        C.resolve(promise).then(capability.resolve, reject);\n      });\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  }\n});\n","'use strict';\nvar $at = require('./_string-at')(true);\n\n// 21.1.3.27 String.prototype[@@iterator]()\nrequire('./_iter-define')(String, 'String', function (iterated) {\n  this._t = String(iterated); // target\n  this._i = 0;                // next index\n// 21.1.5.2.1 %StringIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var index = this._i;\n  var point;\n  if (index >= O.length) return { value: undefined, done: true };\n  point = $at(O, index);\n  this._i += point.length;\n  return { value: point, done: false };\n});\n","var $iterators = require('./es6.array.iterator');\nvar getKeys = require('./_object-keys');\nvar redefine = require('./_redefine');\nvar global = require('./_global');\nvar hide = require('./_hide');\nvar Iterators = require('./_iterators');\nvar wks = require('./_wks');\nvar ITERATOR = wks('iterator');\nvar TO_STRING_TAG = wks('toStringTag');\nvar ArrayValues = Iterators.Array;\n\nvar DOMIterables = {\n  CSSRuleList: true, // TODO: Not spec compliant, should be false.\n  CSSStyleDeclaration: false,\n  CSSValueList: false,\n  ClientRectList: false,\n  DOMRectList: false,\n  DOMStringList: false,\n  DOMTokenList: true,\n  DataTransferItemList: false,\n  FileList: false,\n  HTMLAllCollection: false,\n  HTMLCollection: false,\n  HTMLFormElement: false,\n  HTMLSelectElement: false,\n  MediaList: true, // TODO: Not spec compliant, should be false.\n  MimeTypeArray: false,\n  NamedNodeMap: false,\n  NodeList: true,\n  PaintRequestList: false,\n  Plugin: false,\n  PluginArray: false,\n  SVGLengthList: false,\n  SVGNumberList: false,\n  SVGPathSegList: false,\n  SVGPointList: false,\n  SVGStringList: false,\n  SVGTransformList: false,\n  SourceBufferList: false,\n  StyleSheetList: true, // TODO: Not spec compliant, should be false.\n  TextTrackCueList: false,\n  TextTrackList: false,\n  TouchList: false\n};\n\nfor (var collections = getKeys(DOMIterables), i = 0; i < collections.length; i++) {\n  var NAME = collections[i];\n  var explicit = DOMIterables[NAME];\n  var Collection = global[NAME];\n  var proto = Collection && Collection.prototype;\n  var key;\n  if (proto) {\n    if (!proto[ITERATOR]) hide(proto, ITERATOR, ArrayValues);\n    if (!proto[TO_STRING_TAG]) hide(proto, TO_STRING_TAG, NAME);\n    Iterators[NAME] = ArrayValues;\n    if (explicit) for (key in $iterators) if (!proto[key]) redefine(proto, key, $iterators[key], true);\n  }\n}\n","exports.read = function (buffer, offset, isLE, mLen, nBytes) {\n  var e, m\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var nBits = -7\n  var i = isLE ? (nBytes - 1) : 0\n  var d = isLE ? -1 : 1\n  var s = buffer[offset + i]\n\n  i += d\n\n  e = s & ((1 << (-nBits)) - 1)\n  s >>= (-nBits)\n  nBits += eLen\n  for (; nBits > 0; e = (e * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  m = e & ((1 << (-nBits)) - 1)\n  e >>= (-nBits)\n  nBits += mLen\n  for (; nBits > 0; m = (m * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  if (e === 0) {\n    e = 1 - eBias\n  } else if (e === eMax) {\n    return m ? NaN : ((s ? -1 : 1) * Infinity)\n  } else {\n    m = m + Math.pow(2, mLen)\n    e = e - eBias\n  }\n  return (s ? -1 : 1) * m * Math.pow(2, e - mLen)\n}\n\nexports.write = function (buffer, value, offset, isLE, mLen, nBytes) {\n  var e, m, c\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var rt = (mLen === 23 ? Math.pow(2, -24) - Math.pow(2, -77) : 0)\n  var i = isLE ? 0 : (nBytes - 1)\n  var d = isLE ? 1 : -1\n  var s = value < 0 || (value === 0 && 1 / value < 0) ? 1 : 0\n\n  value = Math.abs(value)\n\n  if (isNaN(value) || value === Infinity) {\n    m = isNaN(value) ? 1 : 0\n    e = eMax\n  } else {\n    e = Math.floor(Math.log(value) / Math.LN2)\n    if (value * (c = Math.pow(2, -e)) < 1) {\n      e--\n      c *= 2\n    }\n    if (e + eBias >= 1) {\n      value += rt / c\n    } else {\n      value += rt * Math.pow(2, 1 - eBias)\n    }\n    if (value * c >= 2) {\n      e++\n      c /= 2\n    }\n\n    if (e + eBias >= eMax) {\n      m = 0\n      e = eMax\n    } else if (e + eBias >= 1) {\n      m = ((value * c) - 1) * Math.pow(2, mLen)\n      e = e + eBias\n    } else {\n      m = value * Math.pow(2, eBias - 1) * Math.pow(2, mLen)\n      e = 0\n    }\n  }\n\n  for (; mLen >= 8; buffer[offset + i] = m & 0xff, i += d, m /= 256, mLen -= 8) {}\n\n  e = (e << mLen) | m\n  eLen += mLen\n  for (; eLen > 0; buffer[offset + i] = e & 0xff, i += d, e /= 256, eLen -= 8) {}\n\n  buffer[offset + i - d] |= s * 128\n}\n","/**\n * Convert array of 16 byte values to UUID string format of the form:\n * XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX\n */\nvar byteToHex = [];\nfor (var i = 0; i < 256; ++i) {\n  byteToHex[i] = (i + 0x100).toString(16).substr(1);\n}\n\nfunction bytesToUuid(buf, offset) {\n  var i = offset || 0;\n  var bth = byteToHex;\n  // join used to fix memory issue caused by concatenation: https://bugs.chromium.org/p/v8/issues/detail?id=3175#c4\n  return ([bth[buf[i++]], bth[buf[i++]], \n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]]]).join('');\n}\n\nmodule.exports = bytesToUuid;\n","// Unique ID creation requires a high quality random # generator.  In the\n// browser this is a little complicated due to unknown quality of Math.random()\n// and inconsistent support for the `crypto` API.  We do the best we can via\n// feature-detection\n\n// getRandomValues needs to be invoked in a context where \"this\" is a Crypto\n// implementation. Also, find the complete implementation of crypto on IE11.\nvar getRandomValues = (typeof(crypto) != 'undefined' && crypto.getRandomValues && crypto.getRandomValues.bind(crypto)) ||\n                      (typeof(msCrypto) != 'undefined' && typeof window.msCrypto.getRandomValues == 'function' && msCrypto.getRandomValues.bind(msCrypto));\n\nif (getRandomValues) {\n  // WHATWG crypto RNG - http://wiki.whatwg.org/wiki/Crypto\n  var rnds8 = new Uint8Array(16); // eslint-disable-line no-undef\n\n  module.exports = function whatwgRNG() {\n    getRandomValues(rnds8);\n    return rnds8;\n  };\n} else {\n  // Math.random()-based (RNG)\n  //\n  // If all else fails, use Math.random().  It's fast, but is of unspecified\n  // quality.\n  var rnds = new Array(16);\n\n  module.exports = function mathRNG() {\n    for (var i = 0, r; i < 16; i++) {\n      if ((i & 0x03) === 0) r = Math.random() * 0x100000000;\n      rnds[i] = r >>> ((i & 0x03) << 3) & 0xff;\n    }\n\n    return rnds;\n  };\n}\n","var rng = require('./lib/rng');\nvar bytesToUuid = require('./lib/bytesToUuid');\n\nfunction v4(options, buf, offset) {\n  var i = buf && offset || 0;\n\n  if (typeof(options) == 'string') {\n    buf = options === 'binary' ? new Array(16) : null;\n    options = null;\n  }\n  options = options || {};\n\n  var rnds = options.random || (options.rng || rng)();\n\n  // Per 4.4, set bits for version and `clock_seq_hi_and_reserved`\n  rnds[6] = (rnds[6] & 0x0f) | 0x40;\n  rnds[8] = (rnds[8] & 0x3f) | 0x80;\n\n  // Copy bytes to buffer, if provided\n  if (buf) {\n    for (var ii = 0; ii < 16; ++ii) {\n      buf[i + ii] = rnds[ii];\n    }\n  }\n\n  return buf || bytesToUuid(rnds);\n}\n\nmodule.exports = v4;\n","var g;\n\n// This works in non-strict mode\ng = (function() {\n\treturn this;\n})();\n\ntry {\n\t// This works if eval is allowed (see CSP)\n\tg = g || new Function(\"return this\")();\n} catch (e) {\n\t// This works if the window reference is available\n\tif (typeof window === \"object\") g = window;\n}\n\n// g can still be undefined, but nothing to do about it...\n// We return undefined, instead of nothing here, so it's\n// easier to handle this case. if(!global) { ...}\n\nmodule.exports = g;\n","// Declare the ES6 features we're using\r\n\r\n// TODO: Consider using the local function versions of these, so that we\r\n// avoid modifying browser globals (potential for interop bugs with other libraries\r\n// on the page that might be polyfilling ES6 features)\r\n\r\nimport 'core-js/es6/promise';\r\nimport 'core-js/fn/function/bind';\r\nimport 'core-js/fn/object/assign';\r\nimport 'core-js/fn/array/find';\r\nimport 'core-js/fn/array/some';\r\nimport 'core-js/fn/array/is-array';\r\nimport 'core-js/fn/array/splice';\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Timer } from './Timer.js';\r\n\r\nconst DefaultAccessTokenExpiringNotificationTime = 60; // seconds\r\n\r\nexport class AccessTokenEvents {\r\n\r\n    constructor({\r\n        accessTokenExpiringNotificationTime = DefaultAccessTokenExpiringNotificationTime,\r\n        accessTokenExpiringTimer = new Timer(\"Access token expiring\"),\r\n        accessTokenExpiredTimer = new Timer(\"Access token expired\")\r\n    } = {}) {\r\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\r\n\r\n        this._accessTokenExpiring = accessTokenExpiringTimer;\r\n        this._accessTokenExpired = accessTokenExpiredTimer;\r\n    }\r\n\r\n    load(container) {\r\n        // only register events if there's an access token and it has an expiration\r\n        if (container.access_token && container.expires_in !== undefined) {\r\n            let duration = container.expires_in;\r\n            Log.debug(\"AccessTokenEvents.load: access token present, remaining duration:\", duration);\r\n\r\n            if (duration > 0) {\r\n                // only register expiring if we still have time\r\n                let expiring = duration - this._accessTokenExpiringNotificationTime;\r\n                if (expiring <= 0){\r\n                    expiring = 1;\r\n                }\r\n                \r\n                Log.debug(\"AccessTokenEvents.load: registering expiring timer in:\", expiring);\r\n                this._accessTokenExpiring.init(expiring);\r\n            }\r\n            else {\r\n                Log.debug(\"AccessTokenEvents.load: canceling existing expiring timer becase we're past expiration.\");\r\n                this._accessTokenExpiring.cancel();\r\n            }\r\n\r\n            // if it's negative, it will still fire\r\n            let expired = duration + 1;\r\n            Log.debug(\"AccessTokenEvents.load: registering expired timer in:\", expired);\r\n            this._accessTokenExpired.init(expired);\r\n        }\r\n        else {\r\n            this._accessTokenExpiring.cancel();\r\n            this._accessTokenExpired.cancel();\r\n        }\r\n    }\r\n\r\n    unload() {\r\n        Log.debug(\"AccessTokenEvents.unload: canceling existing access token timers\");\r\n        this._accessTokenExpiring.cancel();\r\n        this._accessTokenExpired.cancel();\r\n    }\r\n\r\n    addAccessTokenExpiring(cb) {\r\n        this._accessTokenExpiring.addHandler(cb);\r\n    }\r\n    removeAccessTokenExpiring(cb) {\r\n        this._accessTokenExpiring.removeHandler(cb);\r\n    }\r\n\r\n    addAccessTokenExpired(cb) {\r\n        this._accessTokenExpired.addHandler(cb);\r\n    }\r\n    removeAccessTokenExpired(cb) {\r\n        this._accessTokenExpired.removeHandler(cb);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultInterval = 2000;\r\n\r\nexport class CheckSessionIFrame {\r\n    constructor(callback, client_id, url, interval, stopOnError = true) {\r\n        this._callback = callback;\r\n        this._client_id = client_id;\r\n        this._url = url;\r\n        this._interval = interval || DefaultInterval;\r\n        this._stopOnError = stopOnError;\r\n\r\n        var idx = url.indexOf(\"/\", url.indexOf(\"//\") + 2);\r\n        this._frame_origin = url.substr(0, idx);\r\n\r\n        this._frame = window.document.createElement(\"iframe\");\r\n\r\n        // shotgun approach\r\n        this._frame.style.visibility = \"hidden\";\r\n        this._frame.style.position = \"absolute\";\r\n        this._frame.style.display = \"none\";\r\n        this._frame.style.width = 0;\r\n        this._frame.style.height = 0;\r\n\r\n        this._frame.src = url;\r\n    }\r\n    load() {\r\n        return new Promise((resolve) => {\r\n            this._frame.onload = () => {\r\n                resolve();\r\n            }\r\n\r\n            window.document.body.appendChild(this._frame);\r\n            this._boundMessageEvent = this._message.bind(this);\r\n            window.addEventListener(\"message\", this._boundMessageEvent, false);\r\n        });\r\n    }\r\n    _message(e) {\r\n        if (e.origin === this._frame_origin &&\r\n            e.source === this._frame.contentWindow\r\n        ) {\r\n            if (e.data === \"error\") {\r\n                Log.error(\"CheckSessionIFrame: error message from check session op iframe\");\r\n                if (this._stopOnError) {\r\n                    this.stop();\r\n                }\r\n            }\r\n            else if (e.data === \"changed\") {\r\n                Log.debug(\"CheckSessionIFrame: changed message from check session op iframe\");\r\n                this.stop();\r\n                this._callback();\r\n            }\r\n            else {\r\n                Log.debug(\"CheckSessionIFrame: \" + e.data + \" message from check session op iframe\");\r\n            }\r\n        }\r\n    }\r\n    start(session_state) {\r\n        if (this._session_state !== session_state) {\r\n            Log.debug(\"CheckSessionIFrame.start\");\r\n\r\n            this.stop();\r\n\r\n            this._session_state = session_state;\r\n\r\n            let send = () => {\r\n                this._frame.contentWindow.postMessage(this._client_id + \" \" + this._session_state, this._frame_origin);\r\n            };\r\n            \r\n            // trigger now\r\n            send();\r\n\r\n            // and setup timer\r\n            this._timer = window.setInterval(send, this._interval);\r\n        }\r\n    }\r\n\r\n    stop() {\r\n        this._session_state = null;\r\n\r\n        if (this._timer) {\r\n            Log.debug(\"CheckSessionIFrame.stop\");\r\n\r\n            window.clearInterval(this._timer);\r\n            this._timer = null;\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { CordovaPopupWindow } from './CordovaPopupWindow.js';\r\n\r\nexport class CordovaIFrameNavigator {\r\n\r\n    prepare(params) {\r\n        params.popupWindowFeatures = 'hidden=yes';\r\n        let popup = new CordovaPopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { CordovaPopupWindow } from './CordovaPopupWindow.js';\r\n\r\nexport class CordovaPopupNavigator {\r\n\r\n    prepare(params) {\r\n        let popup = new CordovaPopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultPopupFeatures = 'location=no,toolbar=no,zoom=no';\r\nconst DefaultPopupTarget = \"_blank\";\r\n\r\nexport class CordovaPopupWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        this.features = params.popupWindowFeatures || DefaultPopupFeatures;\r\n        this.target = params.popupWindowTarget || DefaultPopupTarget;\r\n        \r\n        this.redirect_uri = params.startUrl;\r\n        Log.debug(\"CordovaPopupWindow.ctor: redirect_uri: \" + this.redirect_uri);\r\n    }\r\n\r\n    _isInAppBrowserInstalled(cordovaMetadata) {\r\n        return [\"cordova-plugin-inappbrowser\", \"cordova-plugin-inappbrowser.inappbrowser\", \"org.apache.cordova.inappbrowser\"].some(function (name) {\r\n            return cordovaMetadata.hasOwnProperty(name)\r\n        })\r\n    }\r\n    \r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            this._error(\"No url provided\");\r\n        } else {\r\n            if (!window.cordova) {\r\n                return this._error(\"cordova is undefined\")\r\n            }\r\n            \r\n            var cordovaMetadata = window.cordova.require(\"cordova/plugin_list\").metadata;\r\n            if (this._isInAppBrowserInstalled(cordovaMetadata) === false) {\r\n                return this._error(\"InAppBrowser plugin not found\")\r\n            }\r\n            this._popup = cordova.InAppBrowser.open(params.url, this.target, this.features);\r\n            if (this._popup) {\r\n                Log.debug(\"CordovaPopupWindow.navigate: popup successfully created\");\r\n                \r\n                this._exitCallbackEvent = this._exitCallback.bind(this); \r\n                this._loadStartCallbackEvent = this._loadStartCallback.bind(this);\r\n                \r\n                this._popup.addEventListener(\"exit\", this._exitCallbackEvent, false);\r\n                this._popup.addEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\r\n            } else {\r\n                this._error(\"Error opening popup window\");\r\n            }\r\n        }\r\n        return this.promise;\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    _loadStartCallback(event) {\r\n        if (event.url.indexOf(this.redirect_uri) === 0) {\r\n            this._success({ url: event.url });\r\n        }    \r\n    }\r\n    _exitCallback(message) {\r\n        this._error(message);    \r\n    }\r\n    \r\n    _success(data) {\r\n        this._cleanup();\r\n\r\n        Log.debug(\"CordovaPopupWindow: Successful response from cordova popup window\");\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        this._cleanup();\r\n\r\n        Log.error(message);\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup();\r\n    }\r\n\r\n    _cleanup() {\r\n        if (this._popup){\r\n            Log.debug(\"CordovaPopupWindow: cleaning up popup\");\r\n            this._popup.removeEventListener(\"exit\", this._exitCallbackEvent, false);\r\n            this._popup.removeEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\r\n            this._popup.close();\r\n        }\r\n        this._popup = null;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class ErrorResponse extends Error {\r\n    constructor({error, error_description, error_uri, state, session_state}={}\r\n    ) {\r\n         if (!error){\r\n            Log.error(\"No error passed to ErrorResponse\");\r\n            throw new Error(\"error\");\r\n        }\r\n\r\n        super(error_description || error);\r\n\r\n        this.name = \"ErrorResponse\";\r\n\r\n        this.error = error;\r\n        this.error_description = error_description;\r\n        this.error_uri = error_uri;\r\n\r\n        this.state = state;\r\n        this.session_state = session_state;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class Event {\r\n\r\n    constructor(name) {\r\n        this._name = name;\r\n        this._callbacks = [];\r\n    }\r\n\r\n    addHandler(cb) {\r\n        this._callbacks.push(cb);\r\n    }\r\n\r\n    removeHandler(cb) {\r\n        var idx = this._callbacks.findIndex(item => item === cb);\r\n        if (idx >= 0) {\r\n            this._callbacks.splice(idx, 1);\r\n        }\r\n    }\r\n\r\n    raise(...params) {\r\n        Log.debug(\"Event: Raising event: \" + this._name);\r\n        for (let i = 0; i < this._callbacks.length; i++) {\r\n            this._callbacks[i](...params);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nconst timer = {\r\n    setInterval: function (cb, duration) {\r\n        return setInterval(cb, duration);\r\n    },\r\n    clearInterval: function (handle) {\r\n        return clearInterval(handle);\r\n    }\r\n};\r\n\r\nlet testing = false;\r\nlet request = null;\r\n\r\nexport class Global {\r\n\r\n    static _testing() {\r\n        testing = true;\r\n    }\r\n\r\n    static get location() {\r\n        if (!testing) {\r\n            return location;\r\n        }\r\n    }\r\n\r\n    static get localStorage() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return localStorage;\r\n        }\r\n    }\r\n\r\n    static get sessionStorage() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return sessionStorage;\r\n        }\r\n    }\r\n\r\n    static setXMLHttpRequest(newRequest) {\r\n        request = newRequest;\r\n    }\r\n\r\n    static get XMLHttpRequest() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return request || XMLHttpRequest;\r\n        }\r\n    }\r\n\r\n    static get timer() {\r\n        if (!testing) {\r\n            return timer;\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { IFrameWindow } from './IFrameWindow.js';\r\n\r\nexport class IFrameNavigator {\r\n\r\n    prepare(params) {\r\n        let frame = new IFrameWindow(params);\r\n        return Promise.resolve(frame);\r\n    }\r\n\r\n    callback(url) {\r\n        Log.debug(\"IFrameNavigator.callback\");\r\n\r\n        try {\r\n            IFrameWindow.notifyParent(url);\r\n            return Promise.resolve();\r\n        }\r\n        catch (e) {\r\n            return Promise.reject(e);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultTimeout = 10000;\r\n\r\nexport class IFrameWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        this._boundMessageEvent = this._message.bind(this);\r\n        window.addEventListener(\"message\", this._boundMessageEvent, false);\r\n\r\n        this._frame = window.document.createElement(\"iframe\");\r\n\r\n        // shotgun approach\r\n        this._frame.style.visibility = \"hidden\";\r\n        this._frame.style.position = \"absolute\";\r\n        this._frame.style.display = \"none\";\r\n        this._frame.style.width = 0;\r\n        this._frame.style.height = 0;\r\n\r\n        window.document.body.appendChild(this._frame);\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            this._error(\"No url provided\");\r\n        }\r\n        else {\r\n            let timeout = params.silentRequestTimeout || DefaultTimeout;\r\n            Log.debug(\"IFrameWindow.navigate: Using timeout of:\", timeout);\r\n            this._timer = window.setTimeout(this._timeout.bind(this), timeout);\r\n            this._frame.src = params.url;\r\n        }\r\n\r\n        return this.promise;\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    _success(data) {\r\n        this._cleanup();\r\n\r\n        Log.debug(\"IFrameWindow: Successful response from frame window\");\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        this._cleanup();\r\n\r\n        Log.error(message);\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup();\r\n    }\r\n\r\n    _cleanup() {\r\n        if (this._frame) {\r\n            Log.debug(\"IFrameWindow: cleanup\");\r\n\r\n            window.removeEventListener(\"message\", this._boundMessageEvent, false);\r\n            window.clearTimeout(this._timer);\r\n            window.document.body.removeChild(this._frame);\r\n\r\n            this._timer = null;\r\n            this._frame = null;\r\n            this._boundMessageEvent = null;\r\n        }\r\n    }\r\n\r\n    _timeout() {\r\n        Log.debug(\"IFrameWindow.timeout\");\r\n        this._error(\"Frame window timed out\");\r\n    }\r\n\r\n    _message(e) {\r\n        Log.debug(\"IFrameWindow.message\");\r\n\r\n        if (this._timer &&\r\n            e.origin === this._origin &&\r\n            e.source === this._frame.contentWindow\r\n        ) {\r\n            let url = e.data;\r\n            if (url) {\r\n                this._success({ url: url });\r\n            }\r\n            else {\r\n                this._error(\"Invalid response from frame\");\r\n            }\r\n        }\r\n    }\r\n\r\n    get _origin() {\r\n        return location.protocol + \"//\" + location.host;\r\n    }\r\n\r\n    static notifyParent(url) {\r\n        Log.debug(\"IFrameWindow.notifyParent\");\r\n        if (window.frameElement) {\r\n            url = url || window.location.href;\r\n            if (url) {\r\n                Log.debug(\"IFrameWindow.notifyParent: posting url message to parent\");\r\n                window.parent.postMessage(url, location.protocol + \"//\" + location.host);\r\n            }\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class InMemoryWebStorage{\r\n    constructor(){\r\n        this._data = {};\r\n    }\r\n\r\n    getItem(key) {\r\n        Log.debug(\"InMemoryWebStorage.getItem\", key);\r\n        return this._data[key];\r\n    }\r\n\r\n    setItem(key, value){\r\n        Log.debug(\"InMemoryWebStorage.setItem\", key);\r\n        this._data[key] = value;\r\n    }\r\n\r\n    removeItem(key){\r\n        Log.debug(\"InMemoryWebStorage.removeItem\", key);\r\n        delete this._data[key];\r\n    }\r\n\r\n    get length() {\r\n        return Object.getOwnPropertyNames(this._data).length;\r\n    }\r\n\r\n    key(index) {\r\n        return Object.getOwnPropertyNames(this._data)[index];\r\n    }\r\n}\r\n","import { jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs } from './crypto/jsrsasign';\r\nimport getJoseUtil from './JoseUtilImpl';\r\n\r\nexport const JoseUtil = getJoseUtil({ jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs });\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport default function getJoseUtil({ jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs }) {\r\n    return class JoseUtil {\r\n\r\n        static parseJwt(jwt) {\r\n            Log.debug(\"JoseUtil.parseJwt\");\r\n            try {\r\n                var token = jws.JWS.parse(jwt);\r\n                return {\r\n                    header: token.headerObj,\r\n                    payload: token.payloadObj\r\n                }\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n\r\n        static validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\r\n            Log.debug(\"JoseUtil.validateJwt\");\r\n\r\n            try {\r\n                if (key.kty === \"RSA\") {\r\n                    if (key.e && key.n) {\r\n                        key = KeyUtil.getKey(key);\r\n                    } else if (key.x5c && key.x5c.length) {\r\n                        var hex = b64tohex(key.x5c[0]);\r\n                        key = X509.getPublicKeyFromCertHex(hex);\r\n                    } else {\r\n                        Log.error(\"JoseUtil.validateJwt: RSA key missing key material\", key);\r\n                        return Promise.reject(new Error(\"RSA key missing key material\"));\r\n                    }\r\n                } else if (key.kty === \"EC\") {\r\n                    if (key.crv && key.x && key.y) {\r\n                        key = KeyUtil.getKey(key);\r\n                    } else {\r\n                        Log.error(\"JoseUtil.validateJwt: EC key missing key material\", key);\r\n                        return Promise.reject(new Error(\"EC key missing key material\"));\r\n                    }\r\n                } else {\r\n                    Log.error(\"JoseUtil.validateJwt: Unsupported key type\", key && key.kty);\r\n                    return Promise.reject(new Error(\"Unsupported key type: \" + key && key.kty));\r\n                }\r\n\r\n                return JoseUtil._validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive);\r\n            } catch (e) {\r\n                Log.error(e && e.message || e);\r\n                return Promise.reject(\"JWT validation failed\");\r\n            }\r\n        }\r\n\r\n        static validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive) {\r\n            if (!clockSkew) {\r\n                clockSkew = 0;\r\n            }\r\n\r\n            if (!now) {\r\n                now = parseInt(Date.now() / 1000);\r\n            }\r\n\r\n            var payload = JoseUtil.parseJwt(jwt).payload;\r\n\r\n            if (!payload.iss) {\r\n                Log.error(\"JoseUtil._validateJwt: issuer was not provided\");\r\n                return Promise.reject(new Error(\"issuer was not provided\"));\r\n            }\r\n            if (payload.iss !== issuer) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid issuer in token\", payload.iss);\r\n                return Promise.reject(new Error(\"Invalid issuer in token: \" + payload.iss));\r\n            }\r\n\r\n            if (!payload.aud) {\r\n                Log.error(\"JoseUtil._validateJwt: aud was not provided\");\r\n                return Promise.reject(new Error(\"aud was not provided\"));\r\n            }\r\n            var validAudience = payload.aud === audience || (Array.isArray(payload.aud) && payload.aud.indexOf(audience) >= 0);\r\n            if (!validAudience) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid audience in token\", payload.aud);\r\n                return Promise.reject(new Error(\"Invalid audience in token: \" + payload.aud));\r\n            }\r\n            if (payload.azp && payload.azp !== audience) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid azp in token\", payload.azp);\r\n                return Promise.reject(new Error(\"Invalid azp in token: \" + payload.azp));\r\n            }\r\n\r\n            if (!timeInsensitive) {\r\n                var lowerNow = now + clockSkew;\r\n                var upperNow = now - clockSkew;\r\n\r\n                if (!payload.iat) {\r\n                    Log.error(\"JoseUtil._validateJwt: iat was not provided\");\r\n                    return Promise.reject(new Error(\"iat was not provided\"));\r\n                }\r\n                if (lowerNow < payload.iat) {\r\n                    Log.error(\"JoseUtil._validateJwt: iat is in the future\", payload.iat);\r\n                    return Promise.reject(new Error(\"iat is in the future: \" + payload.iat));\r\n                }\r\n\r\n                if (payload.nbf && lowerNow < payload.nbf) {\r\n                    Log.error(\"JoseUtil._validateJwt: nbf is in the future\", payload.nbf);\r\n                    return Promise.reject(new Error(\"nbf is in the future: \" + payload.nbf));\r\n                }\r\n\r\n                if (!payload.exp) {\r\n                    Log.error(\"JoseUtil._validateJwt: exp was not provided\");\r\n                    return Promise.reject(new Error(\"exp was not provided\"));\r\n                }\r\n                if (payload.exp < upperNow) {\r\n                    Log.error(\"JoseUtil._validateJwt: exp is in the past\", payload.exp);\r\n                    return Promise.reject(new Error(\"exp is in the past:\" + payload.exp));\r\n                }\r\n            }\r\n\r\n            return Promise.resolve(payload);\r\n        }\r\n\r\n        static _validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\r\n\r\n            return JoseUtil.validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive).then(payload => {\r\n                try {\r\n                    if (!jws.JWS.verify(jwt, key, AllowedSigningAlgs)) {\r\n                        Log.error(\"JoseUtil._validateJwt: signature validation failed\");\r\n                        return Promise.reject(new Error(\"signature validation failed\"));\r\n                    }\r\n\r\n                    return payload;\r\n                } catch (e) {\r\n                    Log.error(e && e.message || e);\r\n                    return Promise.reject(new Error(\"signature validation failed\"));\r\n                }\r\n            });\r\n        }\r\n\r\n        static hashString(value, alg) {\r\n            try {\r\n                return crypto.Util.hashString(value, alg);\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n\r\n        static hexToBase64Url(value) {\r\n            try {\r\n                return hextob64u(value);\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class JsonService {\r\n    constructor(\r\n        additionalContentTypes = null, \r\n        XMLHttpRequestCtor = Global.XMLHttpRequest, \r\n        jwtHandler = null\r\n    ) {\r\n        if (additionalContentTypes && Array.isArray(additionalContentTypes))\r\n        {\r\n            this._contentTypes = additionalContentTypes.slice();\r\n        }\r\n        else\r\n        {\r\n            this._contentTypes = [];\r\n        }\r\n        this._contentTypes.push('application/json');\r\n        if (jwtHandler) {\r\n            this._contentTypes.push('application/jwt');\r\n        }\r\n\r\n        this._XMLHttpRequest = XMLHttpRequestCtor;\r\n        this._jwtHandler = jwtHandler;\r\n    }\r\n\r\n    getJson(url, token) {\r\n        if (!url){\r\n            Log.error(\"JsonService.getJson: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        Log.debug(\"JsonService.getJson, url: \", url);\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var req = new this._XMLHttpRequest();\r\n            req.open('GET', url);\r\n\r\n            var allowedContentTypes = this._contentTypes;\r\n            var jwtHandler = this._jwtHandler;\r\n\r\n            req.onload = function() {\r\n                Log.debug(\"JsonService.getJson: HTTP response received, status\", req.status);\r\n\r\n                if (req.status === 200) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found == \"application/jwt\") {\r\n                            jwtHandler(req).then(resolve, reject);\r\n                            return;\r\n                        }\r\n\r\n                        if (found) {\r\n                            try {\r\n                                resolve(JSON.parse(req.responseText));\r\n                                return;\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.getJson: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n\r\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\r\n                }\r\n                else {\r\n                    reject(Error(req.statusText + \" (\" + req.status + \")\"));\r\n                }\r\n            };\r\n\r\n            req.onerror = function() {\r\n                Log.error(\"JsonService.getJson: network error\");\r\n                reject(Error(\"Network Error\"));\r\n            };\r\n\r\n            if (token) {\r\n                Log.debug(\"JsonService.getJson: token passed, setting Authorization header\");\r\n                req.setRequestHeader(\"Authorization\", \"Bearer \" + token);\r\n            }\r\n\r\n            req.send();\r\n        });\r\n    }\r\n\r\n    postForm(url, payload) {\r\n        if (!url){\r\n            Log.error(\"JsonService.postForm: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        Log.debug(\"JsonService.postForm, url: \", url);\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var req = new this._XMLHttpRequest();\r\n            req.open('POST', url);\r\n\r\n            var allowedContentTypes = this._contentTypes;\r\n\r\n            req.onload = function() {\r\n                Log.debug(\"JsonService.postForm: HTTP response received, status\", req.status);\r\n\r\n                if (req.status === 200) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found) {\r\n                            try {\r\n                                resolve(JSON.parse(req.responseText));\r\n                                return;\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n\r\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\r\n                    return;\r\n                }\r\n\r\n                if (req.status === 400) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found) {\r\n                            try {\r\n                                var payload = JSON.parse(req.responseText);\r\n                                if (payload && payload.error) {\r\n                                    Log.error(\"JsonService.postForm: Error from server: \", payload.error);\r\n                                    reject(new Error(payload.error));\r\n                                    return;\r\n                                }\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n                }\r\n\r\n                reject(Error(req.statusText + \" (\" + req.status + \")\"));\r\n            };\r\n\r\n            req.onerror = function() {\r\n                Log.error(\"JsonService.postForm: network error\");\r\n                reject(Error(\"Network Error\"));\r\n            };\r\n\r\n            let body = \"\";\r\n            for(let key in payload) {\r\n\r\n                let value = payload[key];\r\n\r\n                if (value) {\r\n\r\n                    if (body.length > 0) {\r\n                        body += \"&\";\r\n                    }\r\n\r\n                    body += encodeURIComponent(key);\r\n                    body += \"=\";\r\n                    body += encodeURIComponent(value);\r\n                }\r\n            }\r\n\r\n            req.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\r\n            req.send(body);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nlet nopLogger = {\r\n    debug(){},\r\n    info(){},\r\n    warn(){},\r\n    error(){}\r\n};\r\n\r\nconst NONE = 0;\r\nconst ERROR = 1;\r\nconst WARN = 2;\r\nconst INFO = 3;\r\nconst DEBUG = 4;\r\n\r\nlet logger;\r\nlet level;\r\n\r\nexport class Log {\r\n    static get NONE() {return NONE};\r\n    static get ERROR() {return ERROR};\r\n    static get WARN() {return WARN};\r\n    static get INFO() {return INFO};\r\n    static get DEBUG() {return DEBUG};\r\n    \r\n    static reset(){\r\n        level = INFO;\r\n        logger = nopLogger;\r\n    }\r\n    \r\n    static get level(){\r\n        return level;\r\n    }\r\n    static set level(value){\r\n        if (NONE <= value && value <= DEBUG){\r\n            level = value;\r\n        }\r\n        else {\r\n            throw new Error(\"Invalid log level\");\r\n        }\r\n    }\r\n    \r\n    static get logger(){\r\n        return logger;\r\n    }\r\n    static set logger(value){\r\n        if (!value.debug && value.info) {\r\n            // just to stay backwards compat. can remove in 2.0\r\n            value.debug = value.info;\r\n        }\r\n\r\n        if (value.debug && value.info && value.warn && value.error){\r\n            logger = value;\r\n        }\r\n        else {\r\n            throw new Error(\"Invalid logger\");\r\n        }\r\n    }\r\n    \r\n    static debug(...args){\r\n        if (level >= DEBUG){\r\n            logger.debug.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static info(...args){\r\n        if (level >= INFO){\r\n            logger.info.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static warn(...args){\r\n        if (level >= WARN){\r\n            logger.warn.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static error(...args){\r\n        if (level >= ERROR){\r\n            logger.error.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n}\r\n\r\nLog.reset();\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { JsonService } from './JsonService.js';\r\n\r\nconst OidcMetadataUrlPath = '.well-known/openid-configuration';\r\n\r\nexport class MetadataService {\r\n    constructor(settings, JsonServiceCtor = JsonService) {\r\n        if (!settings) {\r\n            Log.error(\"MetadataService: No settings passed to MetadataService\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor(['application/jwk-set+json']);\r\n    }\r\n\r\n    get metadataUrl() {\r\n        if (!this._metadataUrl) {\r\n            if (this._settings.metadataUrl) {\r\n                this._metadataUrl = this._settings.metadataUrl;\r\n            }\r\n            else {\r\n                this._metadataUrl = this._settings.authority;\r\n\r\n                if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\r\n                    if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\r\n                        this._metadataUrl += '/';\r\n                    }\r\n                    this._metadataUrl += OidcMetadataUrlPath;\r\n                }\r\n            }\r\n        }\r\n\r\n        return this._metadataUrl;\r\n    }\r\n\r\n    getMetadata() {\r\n        if (this._settings.metadata) {\r\n            Log.debug(\"MetadataService.getMetadata: Returning metadata from settings\");\r\n            return Promise.resolve(this._settings.metadata);\r\n        }\r\n\r\n        if (!this.metadataUrl) {\r\n            Log.error(\"MetadataService.getMetadata: No authority or metadataUrl configured on settings\");\r\n            return Promise.reject(new Error(\"No authority or metadataUrl configured on settings\"));\r\n        }\r\n\r\n        Log.debug(\"MetadataService.getMetadata: getting metadata from\", this.metadataUrl);\r\n\r\n        return this._jsonService.getJson(this.metadataUrl)\r\n            .then(metadata => {\r\n                Log.debug(\"MetadataService.getMetadata: json received\");\r\n                this._settings.metadata = metadata;\r\n                return metadata;\r\n            });\r\n    }\r\n\r\n    getIssuer() {\r\n        return this._getMetadataProperty(\"issuer\");\r\n    }\r\n\r\n    getAuthorizationEndpoint() {\r\n        return this._getMetadataProperty(\"authorization_endpoint\");\r\n    }\r\n\r\n    getUserInfoEndpoint() {\r\n        return this._getMetadataProperty(\"userinfo_endpoint\");\r\n    }\r\n\r\n    getTokenEndpoint(optional=true) {\r\n        return this._getMetadataProperty(\"token_endpoint\", optional);\r\n    }\r\n\r\n    getCheckSessionIframe() {\r\n        return this._getMetadataProperty(\"check_session_iframe\", true);\r\n    }\r\n\r\n    getEndSessionEndpoint() {\r\n        return this._getMetadataProperty(\"end_session_endpoint\", true);\r\n    }\r\n\r\n    getRevocationEndpoint() {\r\n        return this._getMetadataProperty(\"revocation_endpoint\", true);\r\n    }\r\n\r\n    getKeysEndpoint() {\r\n        return this._getMetadataProperty(\"jwks_uri\", true);\r\n    }\r\n\r\n    _getMetadataProperty(name, optional=false) {\r\n        Log.debug(\"MetadataService.getMetadataProperty for: \" + name);\r\n\r\n        return this.getMetadata().then(metadata => {\r\n            Log.debug(\"MetadataService.getMetadataProperty: metadata recieved\");\r\n\r\n            if (metadata[name] === undefined) {\r\n\r\n                if (optional === true) {\r\n                    Log.warn(\"MetadataService.getMetadataProperty: Metadata does not contain optional property \" + name);\r\n                    return undefined;\r\n                }\r\n                else {\r\n                    Log.error(\"MetadataService.getMetadataProperty: Metadata does not contain property \" + name);\r\n                    throw new Error(\"Metadata does not contain property \" + name);\r\n                }\r\n            }\r\n\r\n            return metadata[name];\r\n        });\r\n    }\r\n\r\n    getSigningKeys() {\r\n        if (this._settings.signingKeys) {\r\n            Log.debug(\"MetadataService.getSigningKeys: Returning signingKeys from settings\");\r\n            return Promise.resolve(this._settings.signingKeys);\r\n        }\r\n\r\n        return this._getMetadataProperty(\"jwks_uri\").then(jwks_uri => {\r\n            Log.debug(\"MetadataService.getSigningKeys: jwks_uri received\", jwks_uri);\r\n\r\n            return this._jsonService.getJson(jwks_uri).then(keySet => {\r\n                Log.debug(\"MetadataService.getSigningKeys: key set received\", keySet);\r\n\r\n                if (!keySet.keys) {\r\n                    Log.error(\"MetadataService.getSigningKeys: Missing keys on keyset\");\r\n                    throw new Error(\"Missing keys on keyset\");\r\n                }\r\n\r\n                this._settings.signingKeys = keySet.keys;\r\n                return this._settings.signingKeys;\r\n            });\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClientSettings } from './OidcClientSettings.js';\r\nimport { ErrorResponse } from './ErrorResponse.js';\r\nimport { SigninRequest } from './SigninRequest.js';\r\nimport { SigninResponse } from './SigninResponse.js';\r\nimport { SignoutRequest } from './SignoutRequest.js';\r\nimport { SignoutResponse } from './SignoutResponse.js';\r\nimport { SigninState } from './SigninState.js';\r\nimport { State } from './State.js';\r\n\r\nexport class OidcClient {\r\n    constructor(settings = {}) {\r\n        if (settings instanceof OidcClientSettings) {\r\n            this._settings = settings;\r\n        }\r\n        else {\r\n            this._settings = new OidcClientSettings(settings);\r\n        }\r\n    }\r\n\r\n    get _stateStore() {\r\n        return this.settings.stateStore;\r\n    }\r\n    get _validator() {\r\n        return this.settings.validator;\r\n    }\r\n    get _metadataService() {\r\n        return this.settings.metadataService;\r\n    }\r\n\r\n    get settings() {\r\n        return this._settings;\r\n    }\r\n    get metadataService() {\r\n        return this._metadataService;\r\n    }\r\n\r\n    createSigninRequest({\r\n        response_type, scope, redirect_uri,\r\n        // data was meant to be the place a caller could indicate the data to\r\n        // have round tripped, but people were getting confused, so i added state (since that matches the spec)\r\n        // and so now if data is not passed, but state is then state will be used\r\n        data, state, prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values,\r\n        resource, request, request_uri, response_mode, extraQueryParams, extraTokenParams, request_type, skipUserInfo } = {},\r\n        stateStore\r\n    ) {\r\n        Log.debug(\"OidcClient.createSigninRequest\");\r\n\r\n        let client_id = this._settings.client_id;\r\n        response_type = response_type || this._settings.response_type;\r\n        scope = scope || this._settings.scope;\r\n        redirect_uri = redirect_uri || this._settings.redirect_uri;\r\n\r\n        // id_token_hint, login_hint aren't allowed on _settings\r\n        prompt = prompt || this._settings.prompt;\r\n        display = display || this._settings.display;\r\n        max_age = max_age || this._settings.max_age;\r\n        ui_locales = ui_locales || this._settings.ui_locales;\r\n        acr_values = acr_values || this._settings.acr_values;\r\n        resource = resource || this._settings.resource;\r\n        response_mode = response_mode || this._settings.response_mode;\r\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\r\n        extraTokenParams = extraTokenParams || this._settings.extraTokenParams;\r\n\r\n        let authority = this._settings.authority;\r\n\r\n        if (SigninRequest.isCode(response_type) && response_type !== \"code\") {\r\n            return Promise.reject(new Error(\"OpenID Connect hybrid flow is not supported\"));\r\n        }\r\n\r\n        return this._metadataService.getAuthorizationEndpoint().then(url => {\r\n            Log.debug(\"OidcClient.createSigninRequest: Received authorization endpoint\", url);\r\n\r\n            let signinRequest = new SigninRequest({\r\n                url,\r\n                client_id,\r\n                redirect_uri,\r\n                response_type,\r\n                scope,\r\n                data: data || state,\r\n                authority,\r\n                prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values,\r\n                resource, request, request_uri, extraQueryParams, extraTokenParams, request_type, response_mode,\r\n                client_secret: this._settings.client_secret,\r\n                skipUserInfo\r\n            });\r\n\r\n            var signinState = signinRequest.state;\r\n            stateStore = stateStore || this._stateStore;\r\n\r\n            return stateStore.set(signinState.id, signinState.toStorageString()).then(() => {\r\n                return signinRequest;\r\n            });\r\n        });\r\n    }\r\n\r\n    readSigninResponseState(url, stateStore, removeState = false) {\r\n        Log.debug(\"OidcClient.readSigninResponseState\");\r\n\r\n        let useQuery = this._settings.response_mode === \"query\" || \r\n            (!this._settings.response_mode && SigninRequest.isCode(this._settings.response_type));\r\n        let delimiter = useQuery ? \"?\" : \"#\";\r\n\r\n        var response = new SigninResponse(url, delimiter);\r\n\r\n        if (!response.state) {\r\n            Log.error(\"OidcClient.readSigninResponseState: No state in response\");\r\n            return Promise.reject(new Error(\"No state in response\"));\r\n        }\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\r\n\r\n        return stateApi(response.state).then(storedStateString => {\r\n            if (!storedStateString) {\r\n                Log.error(\"OidcClient.readSigninResponseState: No matching state found in storage\");\r\n                throw new Error(\"No matching state found in storage\");\r\n            }\r\n\r\n            let state = SigninState.fromStorageString(storedStateString);\r\n            return {state, response};\r\n        });\r\n    }\r\n\r\n    processSigninResponse(url, stateStore) {\r\n        Log.debug(\"OidcClient.processSigninResponse\");\r\n\r\n        return this.readSigninResponseState(url, stateStore, true).then(({state, response}) => {\r\n            Log.debug(\"OidcClient.processSigninResponse: Received state from storage; validating response\");\r\n            return this._validator.validateSigninResponse(state, response);\r\n        });\r\n    }\r\n\r\n    createSignoutRequest({id_token_hint, data, state, post_logout_redirect_uri, extraQueryParams, request_type } = {},\r\n        stateStore\r\n    ) {\r\n        Log.debug(\"OidcClient.createSignoutRequest\");\r\n\r\n        post_logout_redirect_uri = post_logout_redirect_uri || this._settings.post_logout_redirect_uri;\r\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\r\n\r\n        return this._metadataService.getEndSessionEndpoint().then(url => {\r\n            if (!url) {\r\n                Log.error(\"OidcClient.createSignoutRequest: No end session endpoint url returned\");\r\n                throw new Error(\"no end session endpoint\");\r\n            }\r\n\r\n            Log.debug(\"OidcClient.createSignoutRequest: Received end session endpoint\", url);\r\n\r\n            let request = new SignoutRequest({\r\n                url,\r\n                id_token_hint,\r\n                post_logout_redirect_uri,\r\n                data: data || state,\r\n                extraQueryParams,\r\n                request_type\r\n            });\r\n\r\n            var signoutState = request.state;\r\n            if (signoutState) {\r\n                Log.debug(\"OidcClient.createSignoutRequest: Signout request has state to persist\");\r\n\r\n                stateStore = stateStore || this._stateStore;\r\n                stateStore.set(signoutState.id, signoutState.toStorageString());\r\n            }\r\n\r\n            return request;\r\n        });\r\n    }\r\n\r\n    readSignoutResponseState(url, stateStore, removeState = false) {\r\n        Log.debug(\"OidcClient.readSignoutResponseState\");\r\n\r\n        var response = new SignoutResponse(url);\r\n        if (!response.state) {\r\n            Log.debug(\"OidcClient.readSignoutResponseState: No state in response\");\r\n\r\n            if (response.error) {\r\n                Log.warn(\"OidcClient.readSignoutResponseState: Response was error: \", response.error);\r\n                return Promise.reject(new ErrorResponse(response));\r\n            }\r\n\r\n            return Promise.resolve({undefined, response});\r\n        }\r\n\r\n        var stateKey = response.state;\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\r\n        return stateApi(stateKey).then(storedStateString => {\r\n            if (!storedStateString) {\r\n                Log.error(\"OidcClient.readSignoutResponseState: No matching state found in storage\");\r\n                throw new Error(\"No matching state found in storage\");\r\n            }\r\n\r\n            let state = State.fromStorageString(storedStateString);\r\n\r\n            return {state, response};\r\n        });\r\n    }\r\n\r\n    processSignoutResponse(url, stateStore) {\r\n        Log.debug(\"OidcClient.processSignoutResponse\");\r\n\r\n        return this.readSignoutResponseState(url, stateStore, true).then(({state, response}) => {\r\n            if (state) {\r\n                Log.debug(\"OidcClient.processSignoutResponse: Received state from storage; validating response\");\r\n                return this._validator.validateSignoutResponse(state, response);\r\n            }\r\n            else {\r\n                Log.debug(\"OidcClient.processSignoutResponse: No state from storage; skipping validating response\");\r\n                return response;\r\n            }\r\n        });\r\n    }\r\n\r\n    clearStaleState(stateStore) {\r\n        Log.debug(\"OidcClient.clearStaleState\");\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        return State.clearStaleState(stateStore, this.settings.staleStateAge);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { WebStorageStateStore } from './WebStorageStateStore.js';\r\nimport { ResponseValidator } from './ResponseValidator.js';\r\nimport { MetadataService } from './MetadataService.js';\r\n\r\nconst OidcMetadataUrlPath = '.well-known/openid-configuration';\r\n\r\nconst DefaultResponseType = \"id_token\";\r\nconst DefaultScope = \"openid\";\r\nconst DefaultStaleStateAge = 60 * 15; // seconds\r\nconst DefaultClockSkewInSeconds = 60 * 5;\r\n\r\nexport class OidcClientSettings {\r\n    constructor({\r\n        // metadata related\r\n        authority, metadataUrl, metadata, signingKeys,\r\n        // client related\r\n        client_id, client_secret, response_type = DefaultResponseType, scope = DefaultScope,\r\n        redirect_uri, post_logout_redirect_uri,\r\n        // optional protocol\r\n        prompt, display, max_age, ui_locales, acr_values, resource, response_mode,\r\n        // behavior flags\r\n        filterProtocolClaims = true, loadUserInfo = true,\r\n        staleStateAge = DefaultStaleStateAge, clockSkew = DefaultClockSkewInSeconds,\r\n        userInfoJwtIssuer = 'OP',\r\n        // other behavior\r\n        stateStore = new WebStorageStateStore(),\r\n        ResponseValidatorCtor = ResponseValidator,\r\n        MetadataServiceCtor = MetadataService,\r\n        // extra query params\r\n        extraQueryParams = {},\r\n        extraTokenParams = {}\r\n    } = {}) {\r\n\r\n        this._authority = authority;\r\n        this._metadataUrl = metadataUrl;\r\n        this._metadata = metadata;\r\n        this._signingKeys = signingKeys;\r\n\r\n        this._client_id = client_id;\r\n        this._client_secret = client_secret;\r\n        this._response_type = response_type;\r\n        this._scope = scope;\r\n        this._redirect_uri = redirect_uri;\r\n        this._post_logout_redirect_uri = post_logout_redirect_uri;\r\n\r\n        this._prompt = prompt;\r\n        this._display = display;\r\n        this._max_age = max_age;\r\n        this._ui_locales = ui_locales;\r\n        this._acr_values = acr_values;\r\n        this._resource = resource;\r\n        this._response_mode = response_mode;\r\n\r\n        this._filterProtocolClaims = !!filterProtocolClaims;\r\n        this._loadUserInfo = !!loadUserInfo;\r\n        this._staleStateAge = staleStateAge;\r\n        this._clockSkew = clockSkew;\r\n        this._userInfoJwtIssuer = userInfoJwtIssuer;\r\n\r\n        this._stateStore = stateStore;\r\n        this._validator = new ResponseValidatorCtor(this);\r\n        this._metadataService = new MetadataServiceCtor(this);\r\n\r\n        this._extraQueryParams = typeof extraQueryParams === 'object' ? extraQueryParams : {};\r\n        this._extraTokenParams = typeof extraTokenParams === 'object' ? extraTokenParams : {};\r\n    }\r\n\r\n    // client config\r\n    get client_id() {\r\n        return this._client_id;\r\n    }\r\n    set client_id(value) {\r\n        if (!this._client_id) {\r\n            // one-time set only\r\n            this._client_id = value;\r\n        }\r\n        else {\r\n            Log.error(\"OidcClientSettings.set_client_id: client_id has already been assigned.\")\r\n            throw new Error(\"client_id has already been assigned.\")\r\n        }\r\n    }\r\n    get client_secret() {\r\n        return this._client_secret;\r\n    }\r\n    get response_type() {\r\n        return this._response_type;\r\n    }\r\n    get scope() {\r\n        return this._scope;\r\n    }\r\n    get redirect_uri() {\r\n        return this._redirect_uri;\r\n    }\r\n    get post_logout_redirect_uri() {\r\n        return this._post_logout_redirect_uri;\r\n    }\r\n\r\n\r\n    // optional protocol params\r\n    get prompt() {\r\n        return this._prompt;\r\n    }\r\n    get display() {\r\n        return this._display;\r\n    }\r\n    get max_age() {\r\n        return this._max_age;\r\n    }\r\n    get ui_locales() {\r\n        return this._ui_locales;\r\n    }\r\n    get acr_values() {\r\n        return this._acr_values;\r\n    }\r\n    get resource() {\r\n        return this._resource;\r\n    }\r\n    get response_mode() {\r\n        return this._response_mode;\r\n    }\r\n\r\n\r\n    // metadata\r\n    get authority() {\r\n        return this._authority;\r\n    }\r\n    set authority(value) {\r\n        if (!this._authority) {\r\n            // one-time set only\r\n            this._authority = value;\r\n        }\r\n        else {\r\n            Log.error(\"OidcClientSettings.set_authority: authority has already been assigned.\")\r\n            throw new Error(\"authority has already been assigned.\")\r\n        }\r\n    }\r\n    get metadataUrl() {\r\n        if (!this._metadataUrl) {\r\n            this._metadataUrl = this.authority;\r\n\r\n            if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\r\n                if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\r\n                    this._metadataUrl += '/';\r\n                }\r\n                this._metadataUrl += OidcMetadataUrlPath;\r\n            }\r\n        }\r\n\r\n        return this._metadataUrl;\r\n    }\r\n\r\n    // settable/cachable metadata values\r\n    get metadata() {\r\n        return this._metadata;\r\n    }\r\n    set metadata(value) {\r\n        this._metadata = value;\r\n    }\r\n\r\n    get signingKeys() {\r\n        return this._signingKeys;\r\n    }\r\n    set signingKeys(value) {\r\n        this._signingKeys = value;\r\n    }\r\n\r\n    // behavior flags\r\n    get filterProtocolClaims() {\r\n        return this._filterProtocolClaims;\r\n    }\r\n    get loadUserInfo() {\r\n        return this._loadUserInfo;\r\n    }\r\n    get staleStateAge() {\r\n        return this._staleStateAge;\r\n    }\r\n    get clockSkew() {\r\n        return this._clockSkew;\r\n    }\r\n    get userInfoJwtIssuer() {\r\n        return this._userInfoJwtIssuer;\r\n    }\r\n\r\n    get stateStore() {\r\n        return this._stateStore;\r\n    }\r\n    get validator() {\r\n        return this._validator;\r\n    }\r\n    get metadataService() {\r\n        return this._metadataService;\r\n    }\r\n\r\n    // extra query params\r\n    get extraQueryParams() {\r\n        return this._extraQueryParams;\r\n    }\r\n    set extraQueryParams(value) {\r\n        if (typeof value === 'object'){\r\n            this._extraQueryParams = value;\r\n        } else {\r\n            this._extraQueryParams = {};\r\n        }\r\n    }\r\n\r\n    // extra token params\r\n    get extraTokenParams() {\r\n        return this._extraTokenParams;\r\n    }\r\n    set extraTokenParams(value) {\r\n        if (typeof value === 'object'){\r\n            this._extraTokenParams = value;\r\n        } else {\r\n            this._extraTokenParams = {};\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { PopupWindow } from './PopupWindow.js';\r\n\r\nexport class PopupNavigator {\r\n\r\n    prepare(params) {\r\n        let popup = new PopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n\r\n    callback(url, keepOpen, delimiter) {\r\n        Log.debug(\"PopupNavigator.callback\");\r\n\r\n        try {\r\n            PopupWindow.notifyOpener(url, keepOpen, delimiter);\r\n            return Promise.resolve();\r\n        }\r\n        catch (e) {\r\n            return Promise.reject(e);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nconst CheckForPopupClosedInterval = 500;\r\nconst DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;';\r\n//const DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;resizable=yes';\r\n\r\nconst DefaultPopupTarget = \"_blank\";\r\n\r\nexport class PopupWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        let target = params.popupWindowTarget || DefaultPopupTarget;\r\n        let features = params.popupWindowFeatures || DefaultPopupFeatures;\r\n\r\n        this._popup = window.open('', target, features);\r\n        if (this._popup) {\r\n            Log.debug(\"PopupWindow.ctor: popup successfully created\");\r\n            this._checkForPopupClosedTimer = window.setInterval(this._checkForPopupClosed.bind(this), CheckForPopupClosedInterval);\r\n        }\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!this._popup) {\r\n            this._error(\"PopupWindow.navigate: Error opening popup window\");\r\n        }\r\n        else if (!params || !params.url) {\r\n            this._error(\"PopupWindow.navigate: no url provided\");\r\n            this._error(\"No url provided\");\r\n        }\r\n        else {\r\n            Log.debug(\"PopupWindow.navigate: Setting URL in popup\");\r\n\r\n            this._id = params.id;\r\n            if (this._id) {\r\n                window[\"popupCallback_\" + params.id] = this._callback.bind(this);\r\n            }\r\n\r\n            this._popup.focus();\r\n            this._popup.window.location = params.url;\r\n        }\r\n\r\n        return this.promise;\r\n    }\r\n\r\n    _success(data) {\r\n        Log.debug(\"PopupWindow.callback: Successful response from popup window\");\r\n\r\n        this._cleanup();\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        Log.error(\"PopupWindow.error: \", message);\r\n        \r\n        this._cleanup();\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup(false);\r\n    }\r\n\r\n    _cleanup(keepOpen) {\r\n        Log.debug(\"PopupWindow.cleanup\");\r\n\r\n        window.clearInterval(this._checkForPopupClosedTimer);\r\n        this._checkForPopupClosedTimer = null;\r\n\r\n        delete window[\"popupCallback_\" + this._id];\r\n\r\n        if (this._popup && !keepOpen) {\r\n            this._popup.close();\r\n        }\r\n        this._popup = null;\r\n    }\r\n\r\n    _checkForPopupClosed() {\r\n        if (!this._popup || this._popup.closed) {\r\n            this._error(\"Popup window closed\");\r\n        }\r\n    }\r\n\r\n    _callback(url, keepOpen) {\r\n        this._cleanup(keepOpen);\r\n\r\n        if (url) {\r\n            Log.debug(\"PopupWindow.callback success\");\r\n            this._success({ url: url });\r\n        }\r\n        else {\r\n            Log.debug(\"PopupWindow.callback: Invalid response from popup\");\r\n            this._error(\"Invalid response from popup\");\r\n        }\r\n    }\r\n\r\n    static notifyOpener(url, keepOpen, delimiter) {\r\n        if (window.opener) {\r\n            url = url || window.location.href;\r\n            if (url) {\r\n                var data = UrlUtility.parseUrlFragment(url, delimiter);\r\n\r\n                if (data.state) {\r\n                    var name = \"popupCallback_\" + data.state;\r\n                    var callback = window.opener[name];\r\n                    if (callback) {\r\n                        Log.debug(\"PopupWindow.notifyOpener: passing url message to opener\");\r\n                        callback(url, keepOpen);\r\n                    }\r\n                    else {\r\n                        Log.warn(\"PopupWindow.notifyOpener: no matching callback found on opener\");\r\n                    }\r\n                }\r\n                else {\r\n                    Log.warn(\"PopupWindow.notifyOpener: no state found in response url\");\r\n                }\r\n            }\r\n        }\r\n        else {\r\n            Log.warn(\"PopupWindow.notifyOpener: no window.opener. Can't complete notification.\");\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class RedirectNavigator {\r\n\r\n    prepare() {\r\n        return Promise.resolve(this);\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            Log.error(\"RedirectNavigator.navigate: No url provided\");\r\n            return Promise.reject(new Error(\"No url provided\"));\r\n        }\r\n\r\n        if (params.useReplaceToNavigate) {\r\n            window.location.replace(params.url);\r\n        }\r\n        else {\r\n            window.location = params.url;\r\n        }\r\n\r\n        return Promise.resolve();\r\n    }\r\n\r\n    get url() {\r\n        return window.location.href;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { UserInfoService } from './UserInfoService.js';\r\nimport { TokenClient } from './TokenClient.js';\r\nimport { ErrorResponse } from './ErrorResponse.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\nconst ProtocolClaims = [\"nonce\", \"at_hash\", \"iat\", \"nbf\", \"exp\", \"aud\", \"iss\", \"c_hash\"];\r\n\r\nexport class ResponseValidator {\r\n\r\n    constructor(settings, \r\n        MetadataServiceCtor = MetadataService,\r\n        UserInfoServiceCtor = UserInfoService, \r\n        joseUtil = JoseUtil,\r\n        TokenClientCtor = TokenClient) {\r\n        if (!settings) {\r\n            Log.error(\"ResponseValidator.ctor: No settings passed to ResponseValidator\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n        this._userInfoService = new UserInfoServiceCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n        this._tokenClient = new TokenClientCtor(this._settings);\r\n    }\r\n\r\n    validateSigninResponse(state, response) {\r\n        Log.debug(\"ResponseValidator.validateSigninResponse\");\r\n\r\n        return this._processSigninParams(state, response).then(response => {\r\n            Log.debug(\"ResponseValidator.validateSigninResponse: state processed\");\r\n            return this._validateTokens(state, response).then(response => {\r\n                Log.debug(\"ResponseValidator.validateSigninResponse: tokens validated\");\r\n                return this._processClaims(state, response).then(response => {\r\n                    Log.debug(\"ResponseValidator.validateSigninResponse: claims processed\");\r\n                    return response;\r\n                });\r\n            });\r\n        });\r\n    }\r\n\r\n    validateSignoutResponse(state, response) {\r\n        if (state.id !== response.state) {\r\n            Log.error(\"ResponseValidator.validateSignoutResponse: State does not match\");\r\n            return Promise.reject(new Error(\"State does not match\"));\r\n        }\r\n\r\n        // now that we know the state matches, take the stored data\r\n        // and set it into the response so callers can get their state\r\n        // this is important for both success & error outcomes\r\n        Log.debug(\"ResponseValidator.validateSignoutResponse: state validated\");\r\n        response.state = state.data;\r\n\r\n        if (response.error) {\r\n            Log.warn(\"ResponseValidator.validateSignoutResponse: Response was error\", response.error);\r\n            return Promise.reject(new ErrorResponse(response));\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processSigninParams(state, response) {\r\n        if (state.id !== response.state) {\r\n            Log.error(\"ResponseValidator._processSigninParams: State does not match\");\r\n            return Promise.reject(new Error(\"State does not match\"));\r\n        }\r\n\r\n        if (!state.client_id) {\r\n            Log.error(\"ResponseValidator._processSigninParams: No client_id on state\");\r\n            return Promise.reject(new Error(\"No client_id on state\"));\r\n        }\r\n\r\n        if (!state.authority) {\r\n            Log.error(\"ResponseValidator._processSigninParams: No authority on state\");\r\n            return Promise.reject(new Error(\"No authority on state\"));\r\n        }\r\n\r\n        // this allows the authority to be loaded from the signin state\r\n        if (!this._settings.authority) {\r\n            this._settings.authority = state.authority;\r\n        }\r\n        // ensure we're using the correct authority if the authority is not loaded from signin state\r\n        else if (this._settings.authority && this._settings.authority !== state.authority) {\r\n            Log.error(\"ResponseValidator._processSigninParams: authority mismatch on settings vs. signin state\");\r\n            return Promise.reject(new Error(\"authority mismatch on settings vs. signin state\"));\r\n        }\r\n        // this allows the client_id to be loaded from the signin state\r\n        if (!this._settings.client_id) {\r\n            this._settings.client_id = state.client_id;\r\n        }\r\n        // ensure we're using the correct client_id if the client_id is not loaded from signin state\r\n        else if (this._settings.client_id && this._settings.client_id !== state.client_id) {\r\n            Log.error(\"ResponseValidator._processSigninParams: client_id mismatch on settings vs. signin state\");\r\n            return Promise.reject(new Error(\"client_id mismatch on settings vs. signin state\"));\r\n        }\r\n\r\n        // now that we know the state matches, take the stored data\r\n        // and set it into the response so callers can get their state\r\n        // this is important for both success & error outcomes\r\n        Log.debug(\"ResponseValidator._processSigninParams: state validated\");\r\n        response.state = state.data;\r\n\r\n        if (response.error) {\r\n            Log.warn(\"ResponseValidator._processSigninParams: Response was error\", response.error);\r\n            return Promise.reject(new ErrorResponse(response));\r\n        }\r\n\r\n        if (state.nonce && !response.id_token) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Expecting id_token in response\");\r\n            return Promise.reject(new Error(\"No id_token in response\"));\r\n        }\r\n\r\n        if (!state.nonce && response.id_token) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Not expecting id_token in response\");\r\n            return Promise.reject(new Error(\"Unexpected id_token in response\"));\r\n        }\r\n\r\n        if (state.code_verifier && !response.code) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Expecting code in response\");\r\n            return Promise.reject(new Error(\"No code in response\"));\r\n        }\r\n\r\n        if (!state.code_verifier && response.code) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Not expecting code in response\");\r\n            return Promise.reject(new Error(\"Unexpected code in response\"));\r\n        }\r\n\r\n        if (!response.scope) {\r\n            // if there's no scope on the response, then assume all scopes granted (per-spec) and copy over scopes from original request\r\n            response.scope = state.scope;\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processClaims(state, response) {\r\n        if (response.isOpenIdConnect) {\r\n            Log.debug(\"ResponseValidator._processClaims: response is OIDC, processing claims\");\r\n\r\n            response.profile = this._filterProtocolClaims(response.profile);\r\n\r\n            if (state.skipUserInfo !== true && this._settings.loadUserInfo && response.access_token) {\r\n                Log.debug(\"ResponseValidator._processClaims: loading user info\");\r\n\r\n                return this._userInfoService.getClaims(response.access_token).then(claims => {\r\n                    Log.debug(\"ResponseValidator._processClaims: user info claims received from user info endpoint\");\r\n\r\n                    if (claims.sub !== response.profile.sub) {\r\n                        Log.error(\"ResponseValidator._processClaims: sub from user info endpoint does not match sub in access_token\");\r\n                        return Promise.reject(new Error(\"sub from user info endpoint does not match sub in access_token\"));\r\n                    }\r\n\r\n                    response.profile = this._mergeClaims(response.profile, claims);\r\n                    Log.debug(\"ResponseValidator._processClaims: user info claims received, updated profile:\", response.profile);\r\n\r\n                    return response;\r\n                });\r\n            }\r\n            else {\r\n                Log.debug(\"ResponseValidator._processClaims: not loading user info\");\r\n            }\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._processClaims: response is not OIDC, not processing claims\");\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _mergeClaims(claims1, claims2) {\r\n        var result = Object.assign({}, claims1);\r\n\r\n        for (let name in claims2) {\r\n            var values = claims2[name];\r\n            if (!Array.isArray(values)) {\r\n                values = [values];\r\n            }\r\n\r\n            for (let i = 0; i < values.length; i++) {\r\n                let value = values[i];\r\n                if (!result[name]) {\r\n                    result[name] = value;\r\n                }\r\n                else if (Array.isArray(result[name])) {\r\n                    if (result[name].indexOf(value) < 0) {\r\n                        result[name].push(value);\r\n                    }\r\n                }\r\n                else if (result[name] !== value) {\r\n                    if (typeof value === 'object') {\r\n                        result[name] = this._mergeClaims(result[name], value);\r\n                    } \r\n                    else {\r\n                        result[name] = [result[name], value];\r\n                    }\r\n                }\r\n            }\r\n        }\r\n\r\n        return result;\r\n    }\r\n\r\n    _filterProtocolClaims(claims) {\r\n        Log.debug(\"ResponseValidator._filterProtocolClaims, incoming claims:\", claims);\r\n\r\n        var result = Object.assign({}, claims);\r\n\r\n        if (this._settings._filterProtocolClaims) {\r\n            ProtocolClaims.forEach(type => {\r\n                delete result[type];\r\n            });\r\n\r\n            Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims filtered\", result);\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims not filtered\")\r\n        }\r\n\r\n        return result;\r\n    }\r\n\r\n    _validateTokens(state, response) {\r\n        if (response.code) {\r\n            Log.debug(\"ResponseValidator._validateTokens: Validating code\");\r\n            return this._processCode(state, response);\r\n        }\r\n\r\n        if (response.id_token) {\r\n            if (response.access_token) {\r\n                Log.debug(\"ResponseValidator._validateTokens: Validating id_token and access_token\");\r\n                return this._validateIdTokenAndAccessToken(state, response);\r\n            }\r\n\r\n            Log.debug(\"ResponseValidator._validateTokens: Validating id_token\");\r\n            return this._validateIdToken(state, response);\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._validateTokens: No code to process or id_token to validate\");\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processCode(state, response) {\r\n        var request = {\r\n            client_id: state.client_id,\r\n            client_secret: state.client_secret,\r\n            code : response.code,\r\n            redirect_uri: state.redirect_uri,\r\n            code_verifier: state.code_verifier\r\n        };\r\n\r\n        if (state.extraTokenParams && typeof(state.extraTokenParams) === 'object') {\r\n            Object.assign(request, state.extraTokenParams);\r\n        }\r\n        \r\n        return this._tokenClient.exchangeCode(request).then(tokenResponse => {\r\n            \r\n            for(var key in tokenResponse) {\r\n                response[key] = tokenResponse[key];\r\n            }\r\n\r\n            if (response.id_token) {\r\n                Log.debug(\"ResponseValidator._processCode: token response successful, processing id_token\");\r\n                return this._validateIdTokenAttributes(state, response);\r\n            }\r\n            else {\r\n                Log.debug(\"ResponseValidator._processCode: token response successful, returning response\");\r\n            }\r\n            \r\n            return response;\r\n        });\r\n    }\r\n\r\n    _validateIdTokenAttributes(state, response) {\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n\r\n            let audience = state.client_id;\r\n            let clockSkewInSeconds = this._settings.clockSkew;\r\n            Log.debug(\"ResponseValidator._validateIdTokenAttributes: Validaing JWT attributes; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n            return this._joseUtil.validateJwtAttributes(response.id_token, issuer, audience, clockSkewInSeconds).then(payload => {\r\n            \r\n                if (state.nonce && state.nonce !== payload.nonce) {\r\n                    Log.error(\"ResponseValidator._validateIdTokenAttributes: Invalid nonce in id_token\");\r\n                    return Promise.reject(new Error(\"Invalid nonce in id_token\"));\r\n                }\r\n\r\n                if (!payload.sub) {\r\n                    Log.error(\"ResponseValidator._validateIdTokenAttributes: No sub present in id_token\");\r\n                    return Promise.reject(new Error(\"No sub present in id_token\"));\r\n                }\r\n\r\n                response.profile = payload;\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n\r\n    _validateIdTokenAndAccessToken(state, response) {\r\n        return this._validateIdToken(state, response).then(response => {\r\n            return this._validateAccessToken(response);\r\n        });\r\n    }\r\n\r\n    _validateIdToken(state, response) {\r\n        if (!state.nonce) {\r\n            Log.error(\"ResponseValidator._validateIdToken: No nonce on state\");\r\n            return Promise.reject(new Error(\"No nonce on state\"));\r\n        }\r\n\r\n        let jwt = this._joseUtil.parseJwt(response.id_token);\r\n        if (!jwt || !jwt.header || !jwt.payload) {\r\n            Log.error(\"ResponseValidator._validateIdToken: Failed to parse id_token\", jwt);\r\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n        }\r\n\r\n        if (state.nonce !== jwt.payload.nonce) {\r\n            Log.error(\"ResponseValidator._validateIdToken: Invalid nonce in id_token\");\r\n            return Promise.reject(new Error(\"Invalid nonce in id_token\"));\r\n        }\r\n\r\n        var kid = jwt.header.kid;\r\n\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n            Log.debug(\"ResponseValidator._validateIdToken: Received issuer\");\r\n\r\n            return this._metadataService.getSigningKeys().then(keys => {\r\n                if (!keys) {\r\n                    Log.error(\"ResponseValidator._validateIdToken: No signing keys from metadata\");\r\n                    return Promise.reject(new Error(\"No signing keys from metadata\"));\r\n                }\r\n\r\n                Log.debug(\"ResponseValidator._validateIdToken: Received signing keys\");\r\n                let key;\r\n                if (!kid) {\r\n                    keys = this._filterByAlg(keys, jwt.header.alg);\r\n\r\n                    if (keys.length > 1) {\r\n                        Log.error(\"ResponseValidator._validateIdToken: No kid found in id_token and more than one key found in metadata\");\r\n                        return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\r\n                    }\r\n                    else {\r\n                        // kid is mandatory only when there are multiple keys in the referenced JWK Set document\r\n                        // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\r\n                        key = keys[0];\r\n                    }\r\n                }\r\n                else {\r\n                    key = keys.filter(key => {\r\n                        return key.kid === kid;\r\n                    })[0];\r\n                }\r\n\r\n                if (!key) {\r\n                    Log.error(\"ResponseValidator._validateIdToken: No key matching kid or alg found in signing keys\");\r\n                    return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\r\n                }\r\n\r\n                let audience = state.client_id;\r\n\r\n                let clockSkewInSeconds = this._settings.clockSkew;\r\n                Log.debug(\"ResponseValidator._validateIdToken: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n                return this._joseUtil.validateJwt(response.id_token, key, issuer, audience, clockSkewInSeconds).then(()=>{\r\n                    Log.debug(\"ResponseValidator._validateIdToken: JWT validation successful\");\r\n\r\n                    if (!jwt.payload.sub) {\r\n                        Log.error(\"ResponseValidator._validateIdToken: No sub present in id_token\");\r\n                        return Promise.reject(new Error(\"No sub present in id_token\"));\r\n                    }\r\n\r\n                    response.profile = jwt.payload;\r\n\r\n                    return response;\r\n                });\r\n            });\r\n        });\r\n    }\r\n\r\n    _filterByAlg(keys, alg){\r\n        var kty = null;\r\n        if (alg.startsWith(\"RS\")) {\r\n            kty = \"RSA\";\r\n        }\r\n        else if (alg.startsWith(\"PS\")) {\r\n            kty = \"PS\";\r\n        }\r\n        else if (alg.startsWith(\"ES\")) {\r\n            kty = \"EC\";\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._filterByAlg: alg not supported: \", alg);\r\n            return [];\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._filterByAlg: Looking for keys that match kty: \", kty);\r\n\r\n        keys = keys.filter(key => {\r\n            return key.kty === kty;\r\n        });\r\n\r\n        Log.debug(\"ResponseValidator._filterByAlg: Number of keys that match kty: \", kty, keys.length);\r\n\r\n        return keys;\r\n    }\r\n\r\n    _validateAccessToken(response) {\r\n        if (!response.profile) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No profile loaded from id_token\");\r\n            return Promise.reject(new Error(\"No profile loaded from id_token\"));\r\n        }\r\n\r\n        if (!response.profile.at_hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No at_hash in id_token\");\r\n            return Promise.reject(new Error(\"No at_hash in id_token\"));\r\n        }\r\n\r\n        if (!response.id_token) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No id_token\");\r\n            return Promise.reject(new Error(\"No id_token\"));\r\n        }\r\n\r\n        let jwt = this._joseUtil.parseJwt(response.id_token);\r\n        if (!jwt || !jwt.header) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Failed to parse id_token\", jwt);\r\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n        }\r\n\r\n        var hashAlg = jwt.header.alg;\r\n        if (!hashAlg || hashAlg.length !== 5) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        var hashBits = hashAlg.substr(2, 3);\r\n        if (!hashBits) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        hashBits = parseInt(hashBits);\r\n        if (hashBits !== 256 && hashBits !== 384 && hashBits !== 512) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        let sha = \"sha\" + hashBits;\r\n        var hash = this._joseUtil.hashString(response.access_token, sha);\r\n        if (!hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: access_token hash failed:\", sha);\r\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\r\n        }\r\n\r\n        var left = hash.substr(0, hash.length / 2);\r\n        var left_b64u = this._joseUtil.hexToBase64Url(left);\r\n        if (left_b64u !== response.profile.at_hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Failed to validate at_hash\", left_b64u, response.profile.at_hash);\r\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._validateAccessToken: success\");\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { CheckSessionIFrame } from './CheckSessionIFrame.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class SessionMonitor {\r\n\r\n    constructor(userManager, CheckSessionIFrameCtor = CheckSessionIFrame, timer = Global.timer) {\r\n        if (!userManager) {\r\n            Log.error(\"SessionMonitor.ctor: No user manager passed to SessionMonitor\");\r\n            throw new Error(\"userManager\");\r\n        }\r\n\r\n        this._userManager = userManager;\r\n        this._CheckSessionIFrameCtor = CheckSessionIFrameCtor;\r\n        this._timer = timer;\r\n\r\n        this._userManager.events.addUserLoaded(this._start.bind(this));\r\n        this._userManager.events.addUserUnloaded(this._stop.bind(this));\r\n\r\n        this._userManager.getUser().then(user => {\r\n            // doing this manually here since calling getUser \r\n            // doesn't trigger load event.\r\n            if (user) {\r\n                this._start(user);\r\n            }\r\n            else if (this._settings.monitorAnonymousSession) {\r\n                this._userManager.querySessionStatus().then(session => {\r\n                    let tmpUser = {\r\n                        session_state : session.session_state\r\n                    };\r\n                    if (session.sub && session.sid) {\r\n                        tmpUser.profile = {\r\n                            sub: session.sub,\r\n                            sid: session.sid\r\n                        };\r\n                    }\r\n                    this._start(tmpUser);\r\n                })\r\n                .catch(err => {\r\n                    // catch to suppress errors since we're in a ctor\r\n                    Log.error(\"SessionMonitor ctor: error from querySessionStatus:\", err.message);\r\n                });\r\n            }\r\n        }).catch(err => {\r\n            // catch to suppress errors since we're in a ctor\r\n            Log.error(\"SessionMonitor ctor: error from getUser:\", err.message);\r\n        });\r\n    }\r\n\r\n    get _settings() {\r\n        return this._userManager.settings;\r\n    }\r\n    get _metadataService() {\r\n        return this._userManager.metadataService;\r\n    }\r\n    get _client_id() {\r\n        return this._settings.client_id;\r\n    }\r\n    get _checkSessionInterval() {\r\n        return this._settings.checkSessionInterval;\r\n    }\r\n    get _stopCheckSessionOnError() {\r\n        return this._settings.stopCheckSessionOnError;\r\n    }\r\n\r\n    _start(user) {\r\n        let session_state = user.session_state;\r\n\r\n        if (session_state) {\r\n            if (user.profile) {\r\n                this._sub = user.profile.sub;\r\n                this._sid = user.profile.sid;\r\n                Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", sub:\", this._sub);\r\n            }\r\n            else {\r\n                this._sub = undefined;\r\n                this._sid = undefined;\r\n                Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", anonymous user\");\r\n            }\r\n\r\n            if (!this._checkSessionIFrame) {\r\n                this._metadataService.getCheckSessionIframe().then(url => {\r\n                    if (url) {\r\n                        Log.debug(\"SessionMonitor._start: Initializing check session iframe\")\r\n\r\n                        let client_id = this._client_id;\r\n                        let interval = this._checkSessionInterval;\r\n                        let stopOnError = this._stopCheckSessionOnError;\r\n\r\n                        this._checkSessionIFrame = new this._CheckSessionIFrameCtor(this._callback.bind(this), client_id, url, interval, stopOnError);\r\n                        this._checkSessionIFrame.load().then(() => {\r\n                            this._checkSessionIFrame.start(session_state);\r\n                        });\r\n                    }\r\n                    else {\r\n                        Log.warn(\"SessionMonitor._start: No check session iframe found in the metadata\");\r\n                    }\r\n                }).catch(err => {\r\n                    // catch to suppress errors since we're in non-promise callback\r\n                    Log.error(\"SessionMonitor._start: Error from getCheckSessionIframe:\", err.message);\r\n                });\r\n            }\r\n            else {\r\n                this._checkSessionIFrame.start(session_state);\r\n            }\r\n        }\r\n    }\r\n\r\n    _stop() {\r\n        this._sub = undefined;\r\n        this._sid = undefined;\r\n\r\n        if (this._checkSessionIFrame) {\r\n            Log.debug(\"SessionMonitor._stop\");\r\n            this._checkSessionIFrame.stop();\r\n        }\r\n\r\n        if (this._settings.monitorAnonymousSession) {\r\n            // using a timer to delay re-initialization to avoid race conditions during signout\r\n            let timerHandle = this._timer.setInterval(()=>{\r\n                this._timer.clearInterval(timerHandle);\r\n\r\n                this._userManager.querySessionStatus().then(session => {\r\n                    let tmpUser = {\r\n                        session_state : session.session_state\r\n                    };\r\n                    if (session.sub && session.sid) {\r\n                        tmpUser.profile = {\r\n                            sub: session.sub,\r\n                            sid: session.sid\r\n                        };\r\n                    }\r\n                    this._start(tmpUser);\r\n                })\r\n                .catch(err => {\r\n                    // catch to suppress errors since we're in a callback\r\n                    Log.error(\"SessionMonitor: error from querySessionStatus:\", err.message);\r\n                });\r\n\r\n            }, 1000);\r\n        }\r\n    }\r\n\r\n    _callback() {\r\n        this._userManager.querySessionStatus().then(session => {\r\n            var raiseEvent = true;\r\n\r\n            if (session) {\r\n                if (session.sub === this._sub) {\r\n                    raiseEvent = false;\r\n                    this._checkSessionIFrame.start(session.session_state);\r\n\r\n                    if (session.sid === this._sid) {\r\n                        Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, restarting check session iframe; session_state:\", session.session_state);\r\n                    }\r\n                    else {\r\n                        Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, session state has changed, restarting check session iframe; session_state:\", session.session_state);\r\n                        this._userManager.events._raiseUserSessionChanged();\r\n                    }\r\n                }\r\n                else {\r\n                    Log.debug(\"SessionMonitor._callback: Different subject signed into OP:\", session.sub);\r\n                }\r\n            }\r\n            else {\r\n                Log.debug(\"SessionMonitor._callback: Subject no longer signed into OP\");\r\n            }\r\n\r\n            if (raiseEvent) {\r\n                if (this._sub) {\r\n                    Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed out event\");\r\n                    this._userManager.events._raiseUserSignedOut();\r\n                }\r\n                else {\r\n                    Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed in event\");\r\n                    this._userManager.events._raiseUserSignedIn();\r\n                }\r\n            }\r\n        }).catch(err => {\r\n            if (this._sub) {\r\n                Log.debug(\"SessionMonitor._callback: Error calling queryCurrentSigninSession; raising signed out event\", err.message);\r\n                this._userManager.events._raiseUserSignedOut();\r\n            }\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\nimport { SigninState } from './SigninState.js';\r\n\r\nexport class SigninRequest {\r\n    constructor({\r\n        // mandatory\r\n        url, client_id, redirect_uri, response_type, scope, authority,\r\n        // optional\r\n        data, prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values, resource, response_mode,\r\n        request, request_uri, extraQueryParams, request_type, client_secret, extraTokenParams, skipUserInfo\r\n    }) {\r\n        if (!url) {\r\n            Log.error(\"SigninRequest.ctor: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n        if (!client_id) {\r\n            Log.error(\"SigninRequest.ctor: No client_id passed\");\r\n            throw new Error(\"client_id\");\r\n        }\r\n        if (!redirect_uri) {\r\n            Log.error(\"SigninRequest.ctor: No redirect_uri passed\");\r\n            throw new Error(\"redirect_uri\");\r\n        }\r\n        if (!response_type) {\r\n            Log.error(\"SigninRequest.ctor: No response_type passed\");\r\n            throw new Error(\"response_type\");\r\n        }\r\n        if (!scope) {\r\n            Log.error(\"SigninRequest.ctor: No scope passed\");\r\n            throw new Error(\"scope\");\r\n        }\r\n        if (!authority) {\r\n            Log.error(\"SigninRequest.ctor: No authority passed\");\r\n            throw new Error(\"authority\");\r\n        }\r\n\r\n        let oidc = SigninRequest.isOidc(response_type);\r\n        let code = SigninRequest.isCode(response_type);\r\n\r\n        if (!response_mode) {\r\n            response_mode = SigninRequest.isCode(response_type) ? \"query\" : null;\r\n        }\r\n\r\n        this.state = new SigninState({ nonce: oidc, \r\n            data, client_id, authority, redirect_uri, \r\n            code_verifier: code, \r\n            request_type, response_mode,\r\n            client_secret, scope, extraTokenParams, skipUserInfo });\r\n\r\n        url = UrlUtility.addQueryParam(url, \"client_id\", client_id);\r\n        url = UrlUtility.addQueryParam(url, \"redirect_uri\", redirect_uri);\r\n        url = UrlUtility.addQueryParam(url, \"response_type\", response_type);\r\n        url = UrlUtility.addQueryParam(url, \"scope\", scope);\r\n\r\n        url = UrlUtility.addQueryParam(url, \"state\", this.state.id);\r\n        if (oidc) {\r\n            url = UrlUtility.addQueryParam(url, \"nonce\", this.state.nonce);\r\n        }\r\n        if (code) {\r\n            url = UrlUtility.addQueryParam(url, \"code_challenge\", this.state.code_challenge);\r\n            url = UrlUtility.addQueryParam(url, \"code_challenge_method\", \"S256\");\r\n        }\r\n\r\n        var optional = { prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values, resource, request, request_uri, response_mode };\r\n        for(let key in optional){\r\n            if (optional[key]) {\r\n                url = UrlUtility.addQueryParam(url, key, optional[key]);\r\n            }\r\n        }\r\n\r\n        for(let key in extraQueryParams){\r\n            url = UrlUtility.addQueryParam(url, key, extraQueryParams[key])\r\n        }\r\n\r\n        this.url = url;\r\n    }\r\n\r\n    static isOidc(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"id_token\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n\r\n    static isOAuth(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"token\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n    \r\n    static isCode(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"code\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nconst OidcScope = \"openid\";\r\n\r\nexport class SigninResponse {\r\n    constructor(url, delimiter = \"#\") {\r\n\r\n        var values = UrlUtility.parseUrlFragment(url, delimiter);\r\n\r\n        this.error = values.error;\r\n        this.error_description = values.error_description;\r\n        this.error_uri = values.error_uri;\r\n\r\n        this.code = values.code;\r\n        this.state = values.state;\r\n        this.id_token = values.id_token;\r\n        this.session_state = values.session_state;\r\n        this.access_token = values.access_token;\r\n        this.token_type = values.token_type;\r\n        this.scope = values.scope;\r\n        this.profile = undefined; // will be set from ResponseValidator\r\n\r\n        this.expires_in = values.expires_in;\r\n    }\r\n\r\n    get expires_in() {\r\n        if (this.expires_at) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            return this.expires_at - now;\r\n        }\r\n        return undefined;\r\n    }\r\n    set expires_in(value){\r\n        let expires_in = parseInt(value);\r\n        if (typeof expires_in === 'number' && expires_in > 0) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            this.expires_at = now + expires_in;\r\n        }\r\n    }\r\n\r\n    get expired() {\r\n        let expires_in = this.expires_in;\r\n        if (expires_in !== undefined) {\r\n            return expires_in <= 0;\r\n        }\r\n        return undefined;\r\n    }\r\n\r\n    get scopes() {\r\n        return (this.scope || \"\").split(\" \");\r\n    }\r\n\r\n    get isOpenIdConnect() {\r\n        return this.scopes.indexOf(OidcScope) >= 0 || !!this.id_token;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { State } from './State.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\nimport random from './random.js';\r\n\r\nexport class SigninState extends State {\r\n    constructor({nonce, authority, client_id, redirect_uri, code_verifier, response_mode, client_secret, scope, extraTokenParams, skipUserInfo} = {}) {\r\n        super(arguments[0]);\r\n\r\n        if (nonce === true) {\r\n            this._nonce = random();\r\n        }\r\n        else if (nonce) {\r\n            this._nonce = nonce;\r\n        }\r\n\r\n        if (code_verifier === true) {\r\n            // random() produces 32 length\r\n            this._code_verifier = random() + random() + random();\r\n        }\r\n        else if (code_verifier) {\r\n            this._code_verifier = code_verifier;\r\n        }\r\n        \r\n        if (this.code_verifier) {\r\n            let hash = JoseUtil.hashString(this.code_verifier, \"SHA256\");\r\n            this._code_challenge = JoseUtil.hexToBase64Url(hash);\r\n        }\r\n\r\n        this._redirect_uri = redirect_uri;\r\n        this._authority = authority;\r\n        this._client_id = client_id;\r\n        this._response_mode = response_mode;\r\n        this._client_secret = client_secret;\r\n        this._scope = scope;\r\n        this._extraTokenParams = extraTokenParams;\r\n        this._skipUserInfo = skipUserInfo;\r\n    }\r\n\r\n    get nonce() {\r\n        return this._nonce;\r\n    }\r\n    get authority() {\r\n        return this._authority;\r\n    }\r\n    get client_id() {\r\n        return this._client_id;\r\n    }\r\n    get redirect_uri() {\r\n        return this._redirect_uri;\r\n    }\r\n    get code_verifier() {\r\n        return this._code_verifier;\r\n    }\r\n    get code_challenge() {\r\n        return this._code_challenge;\r\n    }\r\n    get response_mode() {\r\n        return this._response_mode;\r\n    }\r\n    get client_secret() {\r\n        return this._client_secret;\r\n    }\r\n    get scope() {\r\n        return this._scope;\r\n    }\r\n    get extraTokenParams() {\r\n        return this._extraTokenParams;\r\n    }\r\n    get skipUserInfo() {\r\n        return this._skipUserInfo;\r\n    }\r\n    \r\n    toStorageString() {\r\n        Log.debug(\"SigninState.toStorageString\");\r\n        return JSON.stringify({\r\n            id: this.id,\r\n            data: this.data,\r\n            created: this.created,\r\n            request_type: this.request_type,\r\n            nonce: this.nonce,\r\n            code_verifier: this.code_verifier,\r\n            redirect_uri: this.redirect_uri,\r\n            authority: this.authority,\r\n            client_id: this.client_id,\r\n            response_mode: this.response_mode,\r\n            client_secret: this.client_secret,\r\n            scope: this.scope,\r\n            extraTokenParams : this.extraTokenParams,\r\n            skipUserInfo: this.skipUserInfo\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"SigninState.fromStorageString\");\r\n        var data = JSON.parse(storageString);\r\n        return new SigninState(data);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\nimport { State } from './State.js';\r\n\r\nexport class SignoutRequest {\r\n    constructor({url, id_token_hint, post_logout_redirect_uri, data, extraQueryParams, request_type}) {\r\n        if (!url) {\r\n            Log.error(\"SignoutRequest.ctor: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        if (id_token_hint) {\r\n            url = UrlUtility.addQueryParam(url, \"id_token_hint\", id_token_hint);\r\n        }\r\n\r\n        if (post_logout_redirect_uri) {\r\n            url = UrlUtility.addQueryParam(url, \"post_logout_redirect_uri\", post_logout_redirect_uri);\r\n\r\n            if (data) {\r\n                this.state = new State({ data, request_type });\r\n\r\n                url = UrlUtility.addQueryParam(url, \"state\", this.state.id);\r\n            }\r\n        }\r\n\r\n        for(let key in extraQueryParams){\r\n            url = UrlUtility.addQueryParam(url, key, extraQueryParams[key])\r\n        }\r\n\r\n        this.url = url;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nexport class SignoutResponse {\r\n    constructor(url) {\r\n\r\n        var values = UrlUtility.parseUrlFragment(url, \"?\");\r\n\r\n        this.error = values.error;\r\n        this.error_description = values.error_description;\r\n        this.error_uri = values.error_uri;\r\n\r\n        this.state = values.state;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class SilentRenewService {\r\n\r\n    constructor(userManager) {\r\n        this._userManager = userManager;\r\n    }\r\n\r\n    start() {\r\n        if (!this._callback) {\r\n            this._callback = this._tokenExpiring.bind(this);\r\n            this._userManager.events.addAccessTokenExpiring(this._callback);\r\n\r\n            // this will trigger loading of the user so the expiring events can be initialized\r\n            this._userManager.getUser().then(user=>{\r\n                // deliberate nop\r\n            }).catch(err=>{\r\n                // catch to suppress errors since we're in a ctor\r\n                Log.error(\"SilentRenewService.start: Error from getUser:\", err.message);\r\n            });\r\n        }\r\n    }\r\n\r\n    stop() {\r\n        if (this._callback) {\r\n            this._userManager.events.removeAccessTokenExpiring(this._callback);\r\n            delete this._callback;\r\n        }\r\n    }\r\n\r\n    _tokenExpiring() {\r\n        this._userManager.signinSilent().then(user => {\r\n            Log.debug(\"SilentRenewService._tokenExpiring: Silent token renewal successful\");\r\n        }, err => {\r\n            Log.error(\"SilentRenewService._tokenExpiring: Error from signinSilent:\", err.message);\r\n            this._userManager.events._raiseSilentRenewError(err);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport random from './random.js';\r\n\r\nexport class State {\r\n    constructor({id, data, created, request_type} = {}) {\r\n        this._id = id || random();\r\n        this._data = data;\r\n\r\n        if (typeof created === 'number' && created > 0) {\r\n            this._created = created;\r\n        }\r\n        else {\r\n            this._created = parseInt(Date.now() / 1000);\r\n        }\r\n        this._request_type =  request_type;\r\n    }\r\n\r\n    get id() {\r\n        return this._id;\r\n    }\r\n    get data() {\r\n        return this._data;\r\n    }\r\n    get created() {\r\n        return this._created;\r\n    }\r\n    get request_type() {\r\n        return this._request_type;\r\n    }\r\n\r\n    toStorageString() {\r\n        Log.debug(\"State.toStorageString\");\r\n        return JSON.stringify({\r\n            id: this.id,\r\n            data: this.data,\r\n            created: this.created,\r\n            request_type: this.request_type\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"State.fromStorageString\");\r\n        return new State(JSON.parse(storageString));\r\n    }\r\n\r\n    static clearStaleState(storage, age) {\r\n\r\n        var cutoff = Date.now() / 1000 - age;\r\n\r\n        return storage.getAllKeys().then(keys => {\r\n            Log.debug(\"State.clearStaleState: got keys\", keys);\r\n\r\n            var promises = [];\r\n            for (let i = 0; i < keys.length; i++) {\r\n                let key = keys[i];\r\n                var p = storage.get(key).then(item => {\r\n                    let remove = false;\r\n\r\n                    if (item) {\r\n                        try {\r\n                            var state = State.fromStorageString(item)\r\n\r\n                            Log.debug(\"State.clearStaleState: got item from key: \", key, state.created);\r\n\r\n                            if (state.created <= cutoff) {\r\n                                remove = true;\r\n                            }\r\n                        }\r\n                        catch (e) {\r\n                            Log.error(\"State.clearStaleState: Error parsing state for key\", key, e.message);\r\n                            remove = true;\r\n                        }\r\n                    }\r\n                    else {\r\n                        Log.debug(\"State.clearStaleState: no item in storage for key: \", key);\r\n                        remove = true;\r\n                    }\r\n\r\n                    if (remove) {\r\n                        Log.debug(\"State.clearStaleState: removed item for key: \", key);\r\n                        return storage.remove(key);\r\n                    }\r\n                });\r\n\r\n                promises.push(p);\r\n            }\r\n\r\n            Log.debug(\"State.clearStaleState: waiting on promise count:\", promises.length);\r\n            return Promise.all(promises);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\nimport { Event } from './Event.js';\r\n\r\nconst TimerDuration = 5; // seconds\r\n\r\nexport class Timer extends Event {\r\n\r\n    constructor(name, timer = Global.timer, nowFunc = undefined) {\r\n        super(name);\r\n        this._timer = timer;\r\n\r\n        if (nowFunc) {\r\n            this._nowFunc = nowFunc;\r\n        }\r\n        else {\r\n            this._nowFunc = () => Date.now() / 1000;\r\n        }\r\n    }\r\n\r\n    get now() {\r\n        return parseInt(this._nowFunc());\r\n    }\r\n\r\n    init(duration) {\r\n        if (duration <= 0) {\r\n            duration = 1;\r\n        }\r\n        duration = parseInt(duration);\r\n\r\n        var expiration = this.now + duration;\r\n        if (this.expiration === expiration && this._timerHandle) {\r\n            // no need to reinitialize to same expiration, so bail out\r\n            Log.debug(\"Timer.init timer \" + this._name + \" skipping initialization since already initialized for expiration:\", this.expiration);\r\n            return;\r\n        }\r\n\r\n        this.cancel();\r\n\r\n        Log.debug(\"Timer.init timer \" + this._name + \" for duration:\", duration);\r\n        this._expiration = expiration;\r\n\r\n        // we're using a fairly short timer and then checking the expiration in the\r\n        // callback to handle scenarios where the browser device sleeps, and then\r\n        // the timers end up getting delayed.\r\n        var timerDuration = TimerDuration;\r\n        if (duration < timerDuration) {\r\n            timerDuration = duration;\r\n        }\r\n        this._timerHandle = this._timer.setInterval(this._callback.bind(this), timerDuration * 1000);\r\n    }\r\n    \r\n    get expiration() {\r\n        return this._expiration;\r\n    }\r\n\r\n    cancel() {\r\n        if (this._timerHandle) {\r\n            Log.debug(\"Timer.cancel: \", this._name);\r\n            this._timer.clearInterval(this._timerHandle);\r\n            this._timerHandle = null;\r\n        }\r\n    }\r\n\r\n    _callback() {\r\n        var diff = this._expiration - this.now;\r\n        Log.debug(\"Timer.callback; \" + this._name + \" timer expires in:\", diff);\r\n\r\n        if (this._expiration <= this.now) {\r\n            this.cancel();\r\n            super.raise();\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { JsonService } from './JsonService.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Log } from './Log.js';\r\n\r\nexport class TokenClient {\r\n    constructor(settings, JsonServiceCtor = JsonService, MetadataServiceCtor = MetadataService) {\r\n        if (!settings) {\r\n            Log.error(\"TokenClient.ctor: No settings passed\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor();\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n    }\r\n\r\n    exchangeCode(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.grant_type = args.grant_type || \"authorization_code\";\r\n        args.client_id = args.client_id || this._settings.client_id;\r\n        args.redirect_uri = args.redirect_uri || this._settings.redirect_uri;\r\n\r\n        if (!args.code) {\r\n            Log.error(\"TokenClient.exchangeCode: No code passed\");\r\n            return Promise.reject(new Error(\"A code is required\"));\r\n        }\r\n        if (!args.redirect_uri) {\r\n            Log.error(\"TokenClient.exchangeCode: No redirect_uri passed\");\r\n            return Promise.reject(new Error(\"A redirect_uri is required\"));\r\n        }\r\n        if (!args.code_verifier) {\r\n            Log.error(\"TokenClient.exchangeCode: No code_verifier passed\");\r\n            return Promise.reject(new Error(\"A code_verifier is required\"));\r\n        }\r\n        if (!args.client_id) {\r\n            Log.error(\"TokenClient.exchangeCode: No client_id passed\");\r\n            return Promise.reject(new Error(\"A client_id is required\"));\r\n        }\r\n\r\n        return this._metadataService.getTokenEndpoint(false).then(url => {\r\n            Log.debug(\"TokenClient.exchangeCode: Received token endpoint\");\r\n\r\n            return this._jsonService.postForm(url, args).then(response => {\r\n                Log.debug(\"TokenClient.exchangeCode: response received\");\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n\r\n    exchangeRefreshToken(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.grant_type = args.grant_type || \"refresh_token\";\r\n        args.client_id = args.client_id || this._settings.client_id;\r\n        args.client_secret = args.client_secret || this._settings.client_secret;\r\n\r\n        if (!args.refresh_token) {\r\n            Log.error(\"TokenClient.exchangeRefreshToken: No refresh_token passed\");\r\n            return Promise.reject(new Error(\"A refresh_token is required\"));\r\n        }\r\n        if (!args.client_id) {\r\n            Log.error(\"TokenClient.exchangeRefreshToken: No client_id passed\");\r\n            return Promise.reject(new Error(\"A client_id is required\"));\r\n        }\r\n\r\n        return this._metadataService.getTokenEndpoint(false).then(url => {\r\n            Log.debug(\"TokenClient.exchangeRefreshToken: Received token endpoint\");\r\n\r\n            return this._jsonService.postForm(url, args).then(response => {\r\n                Log.debug(\"TokenClient.exchangeRefreshToken: response received\");\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Global } from './Global.js';\r\n\r\nconst AccessTokenTypeHint = \"access_token\";\r\nconst RefreshTokenTypeHint = \"refresh_token\";\r\n\r\nexport class TokenRevocationClient {\r\n    constructor(settings, XMLHttpRequestCtor = Global.XMLHttpRequest, MetadataServiceCtor = MetadataService) {\r\n        if (!settings) {\r\n            Log.error(\"TokenRevocationClient.ctor: No settings provided\");\r\n            throw new Error(\"No settings provided.\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._XMLHttpRequestCtor = XMLHttpRequestCtor;\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n    }\r\n\r\n    revoke(token, required, type = \"access_token\") {\r\n        if (!token) {\r\n            Log.error(\"TokenRevocationClient.revoke: No token provided\");\r\n            throw new Error(\"No token provided.\");\r\n        }\r\n\r\n        if (type !== AccessTokenTypeHint && type != RefreshTokenTypeHint) {\r\n            Log.error(\"TokenRevocationClient.revoke: Invalid token type\");\r\n            throw new Error(\"Invalid token type.\");\r\n        }\r\n\r\n        return this._metadataService.getRevocationEndpoint().then(url => {\r\n            if (!url) {\r\n                if (required) {\r\n                    Log.error(\"TokenRevocationClient.revoke: Revocation not supported\");\r\n                    throw new Error(\"Revocation not supported\");\r\n                }\r\n\r\n                // not required, so don't error and just return\r\n                return;\r\n            }\r\n\r\n            Log.debug(\"TokenRevocationClient.revoke: Revoking \" + type);\r\n            var client_id = this._settings.client_id;\r\n            var client_secret = this._settings.client_secret;\r\n            return this._revoke(url, client_id, client_secret, token, type);\r\n        });\r\n    }\r\n\r\n    _revoke(url, client_id, client_secret, token, type) {\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var xhr = new this._XMLHttpRequestCtor();\r\n            xhr.open(\"POST\", url);\r\n\r\n            xhr.onload = () => {\r\n                Log.debug(\"TokenRevocationClient.revoke: HTTP response received, status\", xhr.status);\r\n\r\n                if (xhr.status === 200) {\r\n                    resolve();\r\n                }\r\n                else {\r\n                    reject(Error(xhr.statusText + \" (\" + xhr.status + \")\"));\r\n                }\r\n            };\r\n            xhr.onerror = () => { \r\n                Log.debug(\"TokenRevocationClient.revoke: Network Error.\")\r\n                reject(\"Network Error\");\r\n            };\r\n\r\n            var body = \"client_id=\" + encodeURIComponent(client_id);\r\n            if (client_secret) {\r\n                body += \"&client_secret=\" + encodeURIComponent(client_secret);\r\n            }\r\n            body += \"&token_type_hint=\" + encodeURIComponent(type);\r\n            body += \"&token=\" + encodeURIComponent(token);\r\n\r\n            xhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\r\n            xhr.send(body);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class UrlUtility {\r\n    static addQueryParam(url, name, value) {\r\n        if (url.indexOf('?') < 0) {\r\n            url += \"?\";\r\n        }\r\n\r\n        if (url[url.length - 1] !== \"?\") {\r\n            url += \"&\";\r\n        }\r\n\r\n        url += encodeURIComponent(name);\r\n        url += \"=\";\r\n        url += encodeURIComponent(value);\r\n\r\n        return url;\r\n    }\r\n\r\n    static parseUrlFragment(value, delimiter = \"#\", global = Global) {\r\n        if (typeof value !== 'string'){\r\n            value = global.location.href;\r\n        }\r\n\r\n        var idx = value.lastIndexOf(delimiter);\r\n        if (idx >= 0) {\r\n            value = value.substr(idx + 1);\r\n        }\r\n\r\n        if (delimiter === \"?\") {\r\n            // if we're doing query, then strip off hash fragment before we parse\r\n            idx = value.indexOf('#');\r\n            if (idx >= 0) {\r\n                value = value.substr(0, idx);\r\n            }\r\n        }\r\n\r\n        var params = {},\r\n            regex = /([^&=]+)=([^&]*)/g,\r\n            m;\r\n\r\n        var counter = 0;\r\n        while (m = regex.exec(value)) {\r\n            params[decodeURIComponent(m[1])] = decodeURIComponent(m[2]);\r\n            if (counter++ > 50) {\r\n                Log.error(\"UrlUtility.parseUrlFragment: response exceeded expected number of parameters\", value);\r\n                return {\r\n                    error: \"Response exceeded expected number of parameters\"\r\n                };\r\n            }\r\n        }\r\n\r\n        for (var prop in params) {\r\n            return params;\r\n        }\r\n\r\n        return {};\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class User {\r\n    constructor({id_token, session_state, access_token, refresh_token, token_type, scope, profile, expires_at, state}) {\r\n        this.id_token = id_token;\r\n        this.session_state = session_state;\r\n        this.access_token = access_token;\r\n        this.refresh_token = refresh_token;\r\n        this.token_type = token_type;\r\n        this.scope = scope;\r\n        this.profile = profile;\r\n        this.expires_at = expires_at;\r\n        this.state = state;\r\n    }\r\n\r\n    get expires_in() {\r\n        if (this.expires_at) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            return this.expires_at - now;\r\n        }\r\n        return undefined;\r\n    }\r\n    set expires_in(value) {\r\n        let expires_in = parseInt(value);\r\n        if (typeof expires_in === 'number' && expires_in > 0) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            this.expires_at = now + expires_in;\r\n        }\r\n    }\r\n\r\n    get expired() {\r\n        let expires_in = this.expires_in;\r\n        if (expires_in !== undefined) {\r\n            return expires_in <= 0;\r\n        }\r\n        return undefined;\r\n    }\r\n\r\n    get scopes() {\r\n        return (this.scope || \"\").split(\" \");\r\n    }\r\n\r\n    toStorageString() {\r\n        Log.debug(\"User.toStorageString\");\r\n        return JSON.stringify({\r\n            id_token: this.id_token,\r\n            session_state: this.session_state,\r\n            access_token: this.access_token,\r\n            refresh_token: this.refresh_token,\r\n            token_type: this.token_type,\r\n            scope: this.scope,\r\n            profile: this.profile,\r\n            expires_at: this.expires_at\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"User.fromStorageString\");\r\n        return new User(JSON.parse(storageString));\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { JsonService } from './JsonService.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Log } from './Log.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\nexport class UserInfoService {\r\n    constructor(\r\n        settings, \r\n        JsonServiceCtor = JsonService, \r\n        MetadataServiceCtor = MetadataService, \r\n        joseUtil = JoseUtil\r\n    ) {\r\n        if (!settings) {\r\n            Log.error(\"UserInfoService.ctor: No settings passed\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor(undefined, undefined, this._getClaimsFromJwt.bind(this));\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n    }\r\n\r\n    getClaims(token) {\r\n        if (!token) {\r\n            Log.error(\"UserInfoService.getClaims: No token passed\");\r\n            return Promise.reject(new Error(\"A token is required\"));\r\n        }\r\n\r\n        return this._metadataService.getUserInfoEndpoint().then(url => {\r\n            Log.debug(\"UserInfoService.getClaims: received userinfo url\", url);\r\n\r\n            return this._jsonService.getJson(url, token).then(claims => {\r\n                Log.debug(\"UserInfoService.getClaims: claims received\", claims);\r\n                return claims;\r\n            });\r\n        });\r\n    }\r\n\r\n    _getClaimsFromJwt(req) {\r\n        try {\r\n            let jwt = this._joseUtil.parseJwt(req.responseText);\r\n            if (!jwt || !jwt.header || !jwt.payload) {\r\n                Log.error(\"UserInfoService._getClaimsFromJwt: Failed to parse JWT\", jwt);\r\n                return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n            }\r\n\r\n            var kid = jwt.header.kid;\r\n\r\n            let issuerPromise;\r\n            switch (this._settings.userInfoJwtIssuer) {\r\n                case 'OP':\r\n                    issuerPromise = this._metadataService.getIssuer();\r\n                    break;\r\n                case 'ANY':\r\n                    issuerPromise = Promise.resolve(jwt.payload.iss);\r\n                    break;\r\n                default:\r\n                    issuerPromise = Promise.resolve(this._settings.userInfoJwtIssuer);\r\n                    break;\r\n            }\r\n\r\n            return issuerPromise.then(issuer => {\r\n                Log.debug(\"UserInfoService._getClaimsFromJwt: Received issuer:\" + issuer);\r\n\r\n                return this._metadataService.getSigningKeys().then(keys => {\r\n                    if (!keys) {\r\n                        Log.error(\"UserInfoService._getClaimsFromJwt: No signing keys from metadata\");\r\n                        return Promise.reject(new Error(\"No signing keys from metadata\"));\r\n                    }\r\n\r\n                    Log.debug(\"UserInfoService._getClaimsFromJwt: Received signing keys\");\r\n                    let key;\r\n                    if (!kid) {\r\n                        keys = this._filterByAlg(keys, jwt.header.alg);\r\n\r\n                        if (keys.length > 1) {\r\n                            Log.error(\"UserInfoService._getClaimsFromJwt: No kid found in id_token and more than one key found in metadata\");\r\n                            return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\r\n                        }\r\n                        else {\r\n                            // kid is mandatory only when there are multiple keys in the referenced JWK Set document\r\n                            // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\r\n                            key = keys[0];\r\n                        }\r\n                    }\r\n                    else {\r\n                        key = keys.filter(key => {\r\n                            return key.kid === kid;\r\n                        })[0];\r\n                    }\r\n\r\n                    if (!key) {\r\n                        Log.error(\"UserInfoService._getClaimsFromJwt: No key matching kid or alg found in signing keys\");\r\n                        return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\r\n                    }\r\n\r\n                    let audience = this._settings.client_id;\r\n\r\n                    let clockSkewInSeconds = this._settings.clockSkew;\r\n                    Log.debug(\"UserInfoService._getClaimsFromJwt: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n                    return this._joseUtil.validateJwt(req.responseText, key, issuer, audience, clockSkewInSeconds, undefined, true).then(() => {\r\n                        Log.debug(\"UserInfoService._getClaimsFromJwt: JWT validation successful\");\r\n                        return jwt.payload;\r\n                    });\r\n                });\r\n            });\r\n            return;\r\n        }\r\n        catch (e) {\r\n            Log.error(\"UserInfoService._getClaimsFromJwt: Error parsing JWT response\", e.message);\r\n            reject(e);\r\n            return;\r\n        }\r\n    }\r\n\r\n    _filterByAlg(keys, alg) {\r\n        var kty = null;\r\n        if (alg.startsWith(\"RS\")) {\r\n            kty = \"RSA\";\r\n        }\r\n        else if (alg.startsWith(\"PS\")) {\r\n            kty = \"PS\";\r\n        }\r\n        else if (alg.startsWith(\"ES\")) {\r\n            kty = \"EC\";\r\n        }\r\n        else {\r\n            Log.debug(\"UserInfoService._filterByAlg: alg not supported: \", alg);\r\n            return [];\r\n        }\r\n\r\n        Log.debug(\"UserInfoService._filterByAlg: Looking for keys that match kty: \", kty);\r\n\r\n        keys = keys.filter(key => {\r\n            return key.kty === kty;\r\n        });\r\n\r\n        Log.debug(\"UserInfoService._filterByAlg: Number of keys that match kty: \", kty, keys.length);\r\n\r\n        return keys;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClient } from './OidcClient.js';\r\nimport { UserManagerSettings } from './UserManagerSettings.js';\r\nimport { User } from './User.js';\r\nimport { UserManagerEvents } from './UserManagerEvents.js';\r\nimport { SilentRenewService } from './SilentRenewService.js';\r\nimport { SessionMonitor } from './SessionMonitor.js';\r\nimport { TokenRevocationClient } from './TokenRevocationClient.js';\r\nimport { TokenClient } from './TokenClient.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\n\r\nexport class UserManager extends OidcClient {\r\n    constructor(settings = {},\r\n        SilentRenewServiceCtor = SilentRenewService,\r\n        SessionMonitorCtor = SessionMonitor,\r\n        TokenRevocationClientCtor = TokenRevocationClient,\r\n        TokenClientCtor = TokenClient,\r\n        joseUtil = JoseUtil\r\n    ) {\r\n\r\n        if (!(settings instanceof UserManagerSettings)) {\r\n            settings = new UserManagerSettings(settings);\r\n        }\r\n        super(settings);\r\n\r\n        this._events = new UserManagerEvents(settings);\r\n        this._silentRenewService = new SilentRenewServiceCtor(this);\r\n\r\n        // order is important for the following properties; these services depend upon the events.\r\n        if (this.settings.automaticSilentRenew) {\r\n            Log.debug(\"UserManager.ctor: automaticSilentRenew is configured, setting up silent renew\");\r\n            this.startSilentRenew();\r\n        }\r\n\r\n        if (this.settings.monitorSession) {\r\n            Log.debug(\"UserManager.ctor: monitorSession is configured, setting up session monitor\");\r\n            this._sessionMonitor = new SessionMonitorCtor(this);\r\n        }\r\n\r\n        this._tokenRevocationClient = new TokenRevocationClientCtor(this._settings);\r\n        this._tokenClient = new TokenClientCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n    }\r\n\r\n    get _redirectNavigator() {\r\n        return this.settings.redirectNavigator;\r\n    }\r\n    get _popupNavigator() {\r\n        return this.settings.popupNavigator;\r\n    }\r\n    get _iframeNavigator() {\r\n        return this.settings.iframeNavigator;\r\n    }\r\n    get _userStore() {\r\n        return this.settings.userStore;\r\n    }\r\n\r\n    get events() {\r\n        return this._events;\r\n    }\r\n\r\n    getUser() {\r\n        return this._loadUser().then(user => {\r\n            if (user) {\r\n                Log.info(\"UserManager.getUser: user loaded\");\r\n\r\n                this._events.load(user, false);\r\n\r\n                return user;\r\n            }\r\n            else {\r\n                Log.info(\"UserManager.getUser: user not found in storage\");\r\n                return null;\r\n            }\r\n        });\r\n    }\r\n\r\n    removeUser() {\r\n        return this.storeUser(null).then(() => {\r\n            Log.info(\"UserManager.removeUser: user removed from storage\");\r\n            this._events.unload();\r\n        });\r\n    }\r\n\r\n    signinRedirect(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:r\";\r\n        let navParams = {\r\n            useReplaceToNavigate : args.useReplaceToNavigate\r\n        };\r\n        return this._signinStart(args, this._redirectNavigator, navParams).then(()=>{\r\n            Log.info(\"UserManager.signinRedirect: successful\");\r\n        });\r\n    }\r\n    signinRedirectCallback(url) {\r\n        return this._signinEnd(url || this._redirectNavigator.url).then(user => {\r\n            if (user.profile && user.profile.sub) {\r\n                Log.info(\"UserManager.signinRedirectCallback: successful, signed in sub: \", user.profile.sub);\r\n            }\r\n            else {\r\n                Log.info(\"UserManager.signinRedirectCallback: no sub\");\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinPopup(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:p\";\r\n        let url = args.redirect_uri || this.settings.popup_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.signinPopup: No popup_redirect_uri or redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No popup_redirect_uri or redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.display = \"popup\";\r\n\r\n        return this._signin(args, this._popupNavigator, {\r\n            startUrl: url,\r\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\r\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\r\n        }).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinPopup: signinPopup successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinPopup: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n    signinPopupCallback(url) {\r\n        return this._signinCallback(url, this._popupNavigator).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinPopupCallback: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinPopupCallback: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        }).catch(err=>{\r\n            Log.error(\"UserManager.signinPopupCallback error: \" + err && err.message);\r\n        });\r\n    }\r\n\r\n    signinSilent(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:s\";\r\n        // first determine if we have a refresh token, or need to use iframe\r\n        return this._loadUser().then(user => {\r\n            if (user && user.refresh_token) {\r\n                args.refresh_token = user.refresh_token;\r\n                return this._useRefreshToken(args);\r\n            }\r\n            else {\r\n                args.id_token_hint = args.id_token_hint || (this.settings.includeIdTokenInSilentRenew && user && user.id_token);\r\n                if (user && this._settings.validateSubOnSilentRenew) {\r\n                    Log.debug(\"UserManager.signinSilent, subject prior to silent renew: \", user.profile.sub);\r\n                    args.current_sub = user.profile.sub;\r\n                }\r\n                return this._signinSilentIframe(args);\r\n            }\r\n        });\r\n    }\r\n\r\n    _useRefreshToken(args = {}) {\r\n        return this._tokenClient.exchangeRefreshToken(args).then(result => {\r\n            if (!result) {\r\n                Log.error(\"UserManager._useRefreshToken: No response returned from token endpoint\");\r\n                return Promise.reject(\"No response returned from token endpoint\");\r\n            }\r\n            if (!result.access_token) {\r\n                Log.error(\"UserManager._useRefreshToken: No access token returned from token endpoint\");\r\n                return Promise.reject(\"No access token returned from token endpoint\");\r\n            }\r\n\r\n            return this._loadUser().then(user => {\r\n                if (user) {\r\n                    let idTokenValidation = Promise.resolve();\r\n                    if (result.id_token) {\r\n                        idTokenValidation = this._validateIdTokenFromTokenRefreshToken(user.profile, result.id_token);\r\n                    }\r\n\r\n                    return idTokenValidation.then(() => {\r\n                        Log.debug(\"UserManager._useRefreshToken: refresh token response success\");\r\n                        user.id_token = result.id_token;\r\n                        user.access_token = result.access_token;\r\n                        user.refresh_token = result.refresh_token || user.refresh_token;\r\n                        user.expires_in = result.expires_in;\r\n\r\n                        return this.storeUser(user).then(()=>{\r\n                            this._events.load(user);\r\n                            return user;\r\n                        });\r\n                    });\r\n                }\r\n                else {\r\n                    return null;\r\n                }\r\n            });\r\n        });\r\n    }\r\n\r\n    _validateIdTokenFromTokenRefreshToken(profile, id_token) {\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n            return this._joseUtil.validateJwtAttributes(id_token, issuer, this._settings.client_id, this._settings.clockSkew).then(payload => {\r\n                if (!payload) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: Failed to validate id_token\");\r\n                    return Promise.reject(new Error(\"Failed to validate id_token\"));\r\n                }\r\n                if (payload.sub !== profile.sub) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: sub in id_token does not match current sub\");\r\n                    return Promise.reject(new Error(\"sub in id_token does not match current sub\"));\r\n                }\r\n                if (payload.auth_time && payload.auth_time !== profile.auth_time) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: auth_time in id_token does not match original auth_time\");\r\n                    return Promise.reject(new Error(\"auth_time in id_token does not match original auth_time\"));\r\n                }\r\n                if (payload.azp && payload.azp !== profile.azp) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp in id_token does not match original azp\");\r\n                    return Promise.reject(new Error(\"azp in id_token does not match original azp\"));\r\n                }\r\n                if (!payload.azp && profile.azp) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp not in id_token, but present in original id_token\");\r\n                    return Promise.reject(new Error(\"azp not in id_token, but present in original id_token\"));\r\n                }\r\n            });\r\n        });\r\n    }\r\n    \r\n    _signinSilentIframe(args = {}) {\r\n        let url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.signinSilent: No silent_redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.prompt = args.prompt || \"none\";\r\n\r\n        return this._signin(args, this._iframeNavigator, {\r\n            startUrl: url,\r\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\r\n        }).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinSilent: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinSilent: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinSilentCallback(url) {\r\n        return this._signinCallback(url, this._iframeNavigator).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinSilentCallback: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinSilentCallback: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinCallback(url) {\r\n        return this.readSigninResponseState(url).then(({state, response}) => {\r\n            if (state.request_type === \"si:r\") {\r\n                return this.signinRedirectCallback(url);\r\n            }\r\n            if (state.request_type === \"si:p\") {\r\n                return this.signinPopupCallback(url);\r\n            }\r\n            if (state.request_type === \"si:s\") {\r\n                return this.signinSilentCallback(url);\r\n            }\r\n            return Promise.reject(new Error(\"invalid response_type in state\"));\r\n        });\r\n    }\r\n\r\n    signoutCallback(url, keepOpen) {\r\n        return this.readSignoutResponseState(url).then(({state, response}) => {\r\n            if (state) {\r\n                if (state.request_type === \"so:r\") {\r\n                    return this.signoutRedirectCallback(url);\r\n                }\r\n                if (state.request_type === \"so:p\") {\r\n                    return this.signoutPopupCallback(url, keepOpen);\r\n                }\r\n                return Promise.reject(new Error(\"invalid response_type in state\"));\r\n            }\r\n            return response;\r\n        });\r\n    }\r\n\r\n    querySessionStatus(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:s\"; // this acts like a signin silent\r\n        let url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.querySessionStatus: No silent_redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.prompt = \"none\";\r\n        args.response_type = args.response_type || this.settings.query_status_response_type;\r\n        args.scope = args.scope || \"openid\";\r\n        args.skipUserInfo = true;\r\n\r\n        return this._signinStart(args, this._iframeNavigator, {\r\n            startUrl: url,\r\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\r\n        }).then(navResponse => {\r\n            return this.processSigninResponse(navResponse.url).then(signinResponse => {\r\n                Log.debug(\"UserManager.querySessionStatus: got signin response\");\r\n\r\n                if (signinResponse.session_state && signinResponse.profile.sub) {\r\n                    Log.info(\"UserManager.querySessionStatus: querySessionStatus success for sub: \",  signinResponse.profile.sub);\r\n                    return {\r\n                        session_state: signinResponse.session_state,\r\n                        sub: signinResponse.profile.sub,\r\n                        sid: signinResponse.profile.sid\r\n                    };\r\n                }\r\n                else {\r\n                    Log.info(\"querySessionStatus successful, user not authenticated\");\r\n                }\r\n            })\r\n            .catch(err => {\r\n                if (err.session_state && this.settings.monitorAnonymousSession) {\r\n                    if (err.message == \"login_required\" || \r\n                        err.message == \"consent_required\" || \r\n                        err.message == \"interaction_required\" || \r\n                        err.message == \"account_selection_required\"\r\n                    ) {\r\n                        Log.info(\"UserManager.querySessionStatus: querySessionStatus success for anonymous user\");\r\n                        return {\r\n                            session_state: err.session_state\r\n                        };\r\n                    }\r\n                }\r\n\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n\r\n    _signin(args, navigator, navigatorParams = {}) {\r\n        return this._signinStart(args, navigator, navigatorParams).then(navResponse => {\r\n            return this._signinEnd(navResponse.url, args);\r\n        });\r\n    }\r\n    _signinStart(args, navigator, navigatorParams = {}) {\r\n\r\n        return navigator.prepare(navigatorParams).then(handle => {\r\n            Log.debug(\"UserManager._signinStart: got navigator window handle\");\r\n\r\n            return this.createSigninRequest(args).then(signinRequest => {\r\n                Log.debug(\"UserManager._signinStart: got signin request\");\r\n\r\n                navigatorParams.url = signinRequest.url;\r\n                navigatorParams.id = signinRequest.state.id;\r\n\r\n                return handle.navigate(navigatorParams);\r\n            }).catch(err => {\r\n                if (handle.close) {\r\n                    Log.debug(\"UserManager._signinStart: Error after preparing navigator, closing navigator window\");\r\n                    handle.close();\r\n                }\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n    _signinEnd(url, args = {}) {\r\n        return this.processSigninResponse(url).then(signinResponse => {\r\n            Log.debug(\"UserManager._signinEnd: got signin response\");\r\n\r\n            let user = new User(signinResponse);\r\n\r\n            if (args.current_sub) {\r\n                if (args.current_sub !== user.profile.sub) {\r\n                    Log.debug(\"UserManager._signinEnd: current user does not match user returned from signin. sub from signin: \", user.profile.sub);\r\n                    return Promise.reject(new Error(\"login_required\"));\r\n                }\r\n                else {\r\n                    Log.debug(\"UserManager._signinEnd: current user matches user returned from signin\");\r\n                }\r\n            }\r\n\r\n            return this.storeUser(user).then(() => {\r\n                Log.debug(\"UserManager._signinEnd: user stored\");\r\n\r\n                this._events.load(user);\r\n\r\n                return user;\r\n            });\r\n        });\r\n    }\r\n    _signinCallback(url, navigator) {\r\n        Log.debug(\"UserManager._signinCallback\");\r\n        return navigator.callback(url);\r\n    }\r\n\r\n    signoutRedirect(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"so:r\";\r\n        let postLogoutRedirectUri = args.post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\r\n        if (postLogoutRedirectUri){\r\n            args.post_logout_redirect_uri = postLogoutRedirectUri;\r\n        }\r\n        let navParams = {\r\n            useReplaceToNavigate : args.useReplaceToNavigate\r\n        };\r\n        return this._signoutStart(args, this._redirectNavigator, navParams).then(()=>{\r\n            Log.info(\"UserManager.signoutRedirect: successful\");\r\n        });\r\n    }\r\n    signoutRedirectCallback(url) {\r\n        return this._signoutEnd(url || this._redirectNavigator.url).then(response=>{\r\n            Log.info(\"UserManager.signoutRedirectCallback: successful\");\r\n            return response;\r\n        });\r\n    }\r\n\r\n    signoutPopup(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"so:p\";\r\n        let url = args.post_logout_redirect_uri || this.settings.popup_post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\r\n        args.post_logout_redirect_uri = url;\r\n        args.display = \"popup\";\r\n        if (args.post_logout_redirect_uri){\r\n            // we're putting a dummy entry in here because we\r\n            // need a unique id from the state for notification\r\n            // to the parent window, which is necessary if we\r\n            // plan to return back to the client after signout\r\n            // and so we can close the popup after signout\r\n            args.state = args.state || {};\r\n        }\r\n\r\n        return this._signout(args, this._popupNavigator, {\r\n            startUrl: url,\r\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\r\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\r\n        }).then(() => {\r\n            Log.info(\"UserManager.signoutPopup: successful\");\r\n        });\r\n    }\r\n    signoutPopupCallback(url, keepOpen) {\r\n        if (typeof(keepOpen) === 'undefined' && typeof(url) === 'boolean') {\r\n            keepOpen = url;\r\n            url = null;\r\n        }\r\n\r\n        let delimiter = '?';\r\n        return this._popupNavigator.callback(url, keepOpen, delimiter).then(() => {\r\n            Log.info(\"UserManager.signoutPopupCallback: successful\");\r\n        });\r\n    }\r\n\r\n    _signout(args, navigator, navigatorParams = {}) {\r\n        return this._signoutStart(args, navigator, navigatorParams).then(navResponse => {\r\n            return this._signoutEnd(navResponse.url);\r\n        });\r\n    }\r\n    _signoutStart(args = {}, navigator, navigatorParams = {}) {\r\n        return navigator.prepare(navigatorParams).then(handle => {\r\n            Log.debug(\"UserManager._signoutStart: got navigator window handle\");\r\n\r\n            return this._loadUser().then(user => {\r\n                Log.debug(\"UserManager._signoutStart: loaded current user from storage\");\r\n\r\n                var revokePromise = this._settings.revokeAccessTokenOnSignout ? this._revokeInternal(user) : Promise.resolve();\r\n                return revokePromise.then(() => {\r\n\r\n                    var id_token = args.id_token_hint || user && user.id_token;\r\n                    if (id_token) {\r\n                        Log.debug(\"UserManager._signoutStart: Setting id_token into signout request\");\r\n                        args.id_token_hint = id_token;\r\n                    }\r\n\r\n                    return this.removeUser().then(() => {\r\n                        Log.debug(\"UserManager._signoutStart: user removed, creating signout request\");\r\n\r\n                        return this.createSignoutRequest(args).then(signoutRequest => {\r\n                            Log.debug(\"UserManager._signoutStart: got signout request\");\r\n\r\n                            navigatorParams.url = signoutRequest.url;\r\n                            if (signoutRequest.state) {\r\n                                navigatorParams.id = signoutRequest.state.id;\r\n                            }\r\n                            return handle.navigate(navigatorParams);\r\n                        });\r\n                    });\r\n                });\r\n            }).catch(err => {\r\n                if (handle.close) {\r\n                    Log.debug(\"UserManager._signoutStart: Error after preparing navigator, closing navigator window\");\r\n                    handle.close();\r\n                }\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n    _signoutEnd(url) {\r\n        return this.processSignoutResponse(url).then(signoutResponse => {\r\n            Log.debug(\"UserManager._signoutEnd: got signout response\");\r\n\r\n            return signoutResponse;\r\n        });\r\n    }\r\n\r\n    revokeAccessToken() {\r\n        return this._loadUser().then(user => {\r\n            return this._revokeInternal(user, true).then(success => {\r\n                if (success) {\r\n                    Log.debug(\"UserManager.revokeAccessToken: removing token properties from user and re-storing\");\r\n\r\n                    user.access_token = null;\r\n                    user.refresh_token = null;\r\n                    user.expires_at = null;\r\n                    user.token_type = null;\r\n\r\n                    return this.storeUser(user).then(() => {\r\n                        Log.debug(\"UserManager.revokeAccessToken: user stored\");\r\n                        this._events.load(user);\r\n                    });\r\n                }\r\n            });\r\n        }).then(()=>{\r\n            Log.info(\"UserManager.revokeAccessToken: access token revoked successfully\");\r\n        });\r\n    }\r\n\r\n    _revokeInternal(user, required) {\r\n        if (user) {\r\n            var access_token = user.access_token;\r\n            var refresh_token = user.refresh_token;\r\n\r\n            return this._revokeAccessTokenInternal(access_token, required)\r\n                .then(atSuccess => {\r\n                    return this._revokeRefreshTokenInternal(refresh_token, required)\r\n                        .then(rtSuccess => {\r\n                            if (!atSuccess && !rtSuccess) {\r\n                                Log.debug(\"UserManager.revokeAccessToken: no need to revoke due to no token(s), or JWT format\");\r\n                            }\r\n                            \r\n                            return atSuccess || rtSuccess;\r\n                        });\r\n                });\r\n        }\r\n\r\n        return Promise.resolve(false);\r\n    }\r\n\r\n    _revokeAccessTokenInternal(access_token, required) {\r\n        // check for JWT vs. reference token\r\n        if (!access_token || access_token.indexOf('.') >= 0) {\r\n            return Promise.resolve(false);\r\n        }\r\n\r\n        return this._tokenRevocationClient.revoke(access_token, required).then(() => true);\r\n    }\r\n\r\n    _revokeRefreshTokenInternal(refresh_token, required) {\r\n        if (!refresh_token) {\r\n            return Promise.resolve(false);\r\n        }\r\n\r\n        return this._tokenRevocationClient.revoke(refresh_token, required, \"refresh_token\").then(() => true);\r\n    }\r\n\r\n    startSilentRenew() {\r\n        this._silentRenewService.start();\r\n    }\r\n\r\n    stopSilentRenew() {\r\n        this._silentRenewService.stop();\r\n    }\r\n\r\n    get _userStoreKey() {\r\n        return `user:${this.settings.authority}:${this.settings.client_id}`;\r\n    }\r\n\r\n    _loadUser() {\r\n        return this._userStore.get(this._userStoreKey).then(storageString => {\r\n            if (storageString) {\r\n                Log.debug(\"UserManager._loadUser: user storageString loaded\");\r\n                return User.fromStorageString(storageString);\r\n            }\r\n\r\n            Log.debug(\"UserManager._loadUser: no user storageString\");\r\n            return null;\r\n        });\r\n    }\r\n\r\n    storeUser(user) {\r\n        if (user) {\r\n            Log.debug(\"UserManager.storeUser: storing user\");\r\n\r\n            var storageString = user.toStorageString();\r\n            return this._userStore.set(this._userStoreKey, storageString);\r\n        }\r\n        else {\r\n            Log.debug(\"storeUser.storeUser: removing user\");\r\n            return this._userStore.remove(this._userStoreKey);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { AccessTokenEvents } from './AccessTokenEvents.js';\r\nimport { Event } from './Event.js';\r\n\r\nexport class UserManagerEvents extends AccessTokenEvents {\r\n\r\n    constructor(settings) {\r\n        super(settings);\r\n        this._userLoaded = new Event(\"User loaded\");\r\n        this._userUnloaded = new Event(\"User unloaded\");\r\n        this._silentRenewError = new Event(\"Silent renew error\");\r\n        this._userSignedIn = new Event(\"User signed in\");\r\n        this._userSignedOut = new Event(\"User signed out\");\r\n        this._userSessionChanged = new Event(\"User session changed\");\r\n    }\r\n\r\n    load(user, raiseEvent=true) {\r\n        Log.debug(\"UserManagerEvents.load\");\r\n        super.load(user);\r\n        if (raiseEvent) {\r\n            this._userLoaded.raise(user);\r\n        }\r\n    }\r\n    unload() {\r\n        Log.debug(\"UserManagerEvents.unload\");\r\n        super.unload();\r\n        this._userUnloaded.raise();\r\n    }\r\n\r\n    addUserLoaded(cb) {\r\n        this._userLoaded.addHandler(cb);\r\n    }\r\n    removeUserLoaded(cb) {\r\n        this._userLoaded.removeHandler(cb);\r\n    }\r\n\r\n    addUserUnloaded(cb) {\r\n        this._userUnloaded.addHandler(cb);\r\n    }\r\n    removeUserUnloaded(cb) {\r\n        this._userUnloaded.removeHandler(cb);\r\n    }\r\n\r\n    addSilentRenewError(cb) {\r\n        this._silentRenewError.addHandler(cb);\r\n    }\r\n    removeSilentRenewError(cb) {\r\n        this._silentRenewError.removeHandler(cb);\r\n    }\r\n    _raiseSilentRenewError(e) {\r\n        Log.debug(\"UserManagerEvents._raiseSilentRenewError\", e.message);\r\n        this._silentRenewError.raise(e);\r\n    }\r\n\r\n    addUserSignedIn(cb) {\r\n        this._userSignedIn.addHandler(cb);\r\n    }\r\n    removeUserSignedIn(cb) {\r\n        this._userSignedIn.removeHandler(cb);\r\n    }\r\n    _raiseUserSignedIn() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSignedIn\");\r\n        this._userSignedIn.raise();\r\n    }\r\n\r\n    addUserSignedOut(cb) {\r\n        this._userSignedOut.addHandler(cb);\r\n    }\r\n    removeUserSignedOut(cb) {\r\n        this._userSignedOut.removeHandler(cb);\r\n    }\r\n    _raiseUserSignedOut() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSignedOut\");\r\n        this._userSignedOut.raise();\r\n    }\r\n\r\n    addUserSessionChanged(cb) {\r\n        this._userSessionChanged.addHandler(cb);\r\n    }\r\n    removeUserSessionChanged(cb) {\r\n        this._userSessionChanged.removeHandler(cb);\r\n    }\r\n    _raiseUserSessionChanged() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSessionChanged\");\r\n        this._userSessionChanged.raise();\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClientSettings } from './OidcClientSettings.js';\r\nimport { RedirectNavigator } from './RedirectNavigator.js';\r\nimport { PopupNavigator } from './PopupNavigator.js';\r\nimport { IFrameNavigator } from './IFrameNavigator.js';\r\nimport { WebStorageStateStore } from './WebStorageStateStore.js';\r\nimport { Global } from './Global.js';\r\nimport { SigninRequest } from './SigninRequest.js';\r\n\r\nconst DefaultAccessTokenExpiringNotificationTime = 60;\r\nconst DefaultCheckSessionInterval = 2000;\r\n\r\nexport class UserManagerSettings extends OidcClientSettings {\r\n    constructor({\r\n        popup_redirect_uri,\r\n        popup_post_logout_redirect_uri,\r\n        popupWindowFeatures,\r\n        popupWindowTarget,\r\n        silent_redirect_uri,\r\n        silentRequestTimeout,\r\n        automaticSilentRenew = false,\r\n        validateSubOnSilentRenew = false,\r\n        includeIdTokenInSilentRenew = true,\r\n        monitorSession = true,\r\n        monitorAnonymousSession = false,\r\n        checkSessionInterval = DefaultCheckSessionInterval,\r\n        stopCheckSessionOnError = true,\r\n        query_status_response_type,\r\n        revokeAccessTokenOnSignout = false,\r\n        accessTokenExpiringNotificationTime = DefaultAccessTokenExpiringNotificationTime,\r\n        redirectNavigator = new RedirectNavigator(),\r\n        popupNavigator = new PopupNavigator(),\r\n        iframeNavigator = new IFrameNavigator(),\r\n        userStore = new WebStorageStateStore({ store: Global.sessionStorage })\r\n    } = {}) {\r\n        super(arguments[0]);\r\n\r\n        this._popup_redirect_uri = popup_redirect_uri;\r\n        this._popup_post_logout_redirect_uri = popup_post_logout_redirect_uri;\r\n        this._popupWindowFeatures = popupWindowFeatures;\r\n        this._popupWindowTarget = popupWindowTarget;\r\n\r\n        this._silent_redirect_uri = silent_redirect_uri;\r\n        this._silentRequestTimeout = silentRequestTimeout;\r\n        this._automaticSilentRenew = automaticSilentRenew;\r\n        this._validateSubOnSilentRenew = validateSubOnSilentRenew;\r\n        this._includeIdTokenInSilentRenew = includeIdTokenInSilentRenew;\r\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\r\n\r\n        this._monitorSession = monitorSession;\r\n        this._monitorAnonymousSession = monitorAnonymousSession;\r\n        this._checkSessionInterval = checkSessionInterval;\r\n        this._stopCheckSessionOnError = stopCheckSessionOnError;\r\n        if (query_status_response_type) {\r\n            this._query_status_response_type = query_status_response_type;\r\n        } \r\n        else if (arguments[0] && arguments[0].response_type) {\r\n            this._query_status_response_type = SigninRequest.isOidc(arguments[0].response_type) ? \"id_token\" : \"code\";\r\n        }\r\n        else {\r\n            this._query_status_response_type = \"id_token\";\r\n        }\r\n        this._revokeAccessTokenOnSignout = revokeAccessTokenOnSignout;\r\n\r\n        this._redirectNavigator = redirectNavigator;\r\n        this._popupNavigator = popupNavigator;\r\n        this._iframeNavigator = iframeNavigator;\r\n\r\n        this._userStore = userStore;\r\n    }\r\n\r\n    get popup_redirect_uri() {\r\n        return this._popup_redirect_uri;\r\n    }\r\n    get popup_post_logout_redirect_uri() {\r\n        return this._popup_post_logout_redirect_uri;\r\n    }\r\n    get popupWindowFeatures() {\r\n        return this._popupWindowFeatures;\r\n    }\r\n    get popupWindowTarget() {\r\n        return this._popupWindowTarget;\r\n    }\r\n\r\n    get silent_redirect_uri() {\r\n        return this._silent_redirect_uri;\r\n    }\r\n     get silentRequestTimeout() {\r\n        return this._silentRequestTimeout;\r\n    }\r\n    get automaticSilentRenew() {\r\n        return this._automaticSilentRenew;\r\n    }\r\n    get validateSubOnSilentRenew() {\r\n        return this._validateSubOnSilentRenew;\r\n    }\r\n    get includeIdTokenInSilentRenew() {\r\n        return this._includeIdTokenInSilentRenew;\r\n    }\r\n    get accessTokenExpiringNotificationTime() {\r\n        return this._accessTokenExpiringNotificationTime;\r\n    }\r\n\r\n    get monitorSession() {\r\n        return this._monitorSession;\r\n    }\r\n    get monitorAnonymousSession() {\r\n        return this._monitorAnonymousSession;\r\n    }\r\n    get checkSessionInterval() {\r\n        return this._checkSessionInterval;\r\n    }\r\n    get stopCheckSessionOnError(){\r\n        return this._stopCheckSessionOnError;\r\n    }\r\n    get query_status_response_type(){\r\n        return this._query_status_response_type;\r\n    }\r\n    get revokeAccessTokenOnSignout() {\r\n        return this._revokeAccessTokenOnSignout;\r\n    }\r\n\r\n    get redirectNavigator() {\r\n        return this._redirectNavigator;\r\n    }\r\n    get popupNavigator() {\r\n        return this._popupNavigator;\r\n    }\r\n    get iframeNavigator() {\r\n        return this._iframeNavigator;\r\n    }\r\n\r\n    get userStore() {\r\n        return this._userStore;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class WebStorageStateStore {\r\n    constructor({prefix = \"oidc.\", store = Global.localStorage} = {}) {\r\n        this._store = store;\r\n        this._prefix = prefix;\r\n    }\r\n\r\n    set(key, value) {\r\n        Log.debug(\"WebStorageStateStore.set\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        this._store.setItem(key, value);\r\n\r\n        return Promise.resolve();\r\n    }\r\n\r\n    get(key) {\r\n        Log.debug(\"WebStorageStateStore.get\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        let item = this._store.getItem(key);\r\n\r\n        return Promise.resolve(item);\r\n    }\r\n\r\n    remove(key) {\r\n        Log.debug(\"WebStorageStateStore.remove\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        let item = this._store.getItem(key);\r\n        this._store.removeItem(key);\r\n\r\n        return Promise.resolve(item);\r\n    }\r\n\r\n    getAllKeys() {\r\n        Log.debug(\"WebStorageStateStore.getAllKeys\");\r\n\r\n        var keys = [];\r\n\r\n        for (let index = 0; index < this._store.length; index++) {\r\n            let key = this._store.key(index);\r\n\r\n            if (key.indexOf(this._prefix) === 0) {\r\n                keys.push(key.substr(this._prefix.length));\r\n            }\r\n        }\r\n\r\n        return Promise.resolve(keys);\r\n    }\r\n}\r\n","import { jws, KEYUTIL as KeyUtil, X509, crypto, hextob64u, b64tohex } from '../../jsrsasign/dist/jsrsasign.js';\r\n\r\nconst AllowedSigningAlgs = ['RS256', 'RS384', 'RS512', 'PS256', 'PS384', 'PS512', 'ES256', 'ES384', 'ES512'];\r\n\r\nexport {\r\n    jws,\r\n    KeyUtil,\r\n    X509,\r\n    crypto,\r\n    hextob64u,\r\n    b64tohex,\r\n    AllowedSigningAlgs\r\n};\r\n","import uuid4 from 'uuid/v4';\r\n\r\n/**\r\n * Generates RFC4122 version 4 guid ()\r\n */\r\n\r\nexport default function random() {\r\n  return uuid4().replace(/-/g, '');\r\n}\r\n","const Version = \"1.10.1\"; export {Version};"],"sourceRoot":""}"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/popup.html",
    "content": "﻿<!DOCTYPE html>\n<html>\n<head>\n    <title></title>\n</head>\n<body>\n   \n    <script src=\"libs/oidc-client.js\"></script>\n    <script src=\"popup.js\"></script>\n</body>\n</html>\n\n"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/popup.js",
    "content": "﻿var mgr = new Oidc.UserManager();\nmgr.signinPopupCallback();\n"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/silent.html",
    "content": "﻿<!DOCTYPE html>\n<html xmlns=\"http://www.w3.org/1999/xhtml\">\n<head>\n    <title></title>\n</head>\n<body>\n    <script src=\"libs/oidc-client.js\"></script>\n    <script src=\"silent.js\"></script>\n</body>\n</html>\n"
  },
  {
    "path": "samples/Clients/src/JsOidc/wwwroot/silent.js",
    "content": "﻿var mgr = new Oidc.UserManager();\nmgr.signinSilentCallback();\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly IHttpClientFactory _httpClientFactory;\n\n    public HomeController(IHttpClientFactory httpClientFactory)\n    {\n        _httpClientFactory = httpClientFactory;\n    }\n\n    [AllowAnonymous]\n    public IActionResult Index() => View();\n\n    public IActionResult Secure() => View();\n\n    public IActionResult Logout() => SignOut(\"oidc\");\n\n    public async Task<IActionResult> CallApi()\n    {\n        var client = _httpClientFactory.CreateClient(\"client\");\n\n        var response = await client.GetStringAsync(\"identity\");\n        ViewBag.Json = JsonSerializer.Deserialize<JsonElement>(response).ToString();\n\n        return View();\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Clients;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/MvcAutomaticTokenManagement.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConfigureLogger();\n\ntry\n{\n    Log.Information(\"Starting host...\");\n    JwtSecurityTokenHandler.DefaultMapInboundClaims = false;\n\n    var builder = WebApplication.CreateBuilder(args);\n    builder.Host.UseSerilog();\n    var services = builder.Services;\n\n\n    // add MVC\n    services.AddControllersWithViews();\n\n    // add cookie-based session management with OpenID Connect authentication\n    services.AddAuthentication(options =>\n    {\n        options.DefaultScheme = \"cookie\";\n        options.DefaultChallengeScheme = \"oidc\";\n    })\n        .AddCookie(\"cookie\", options =>\n        {\n            options.Cookie.Name = \"mvcclient\";\n\n            options.ExpireTimeSpan = TimeSpan.FromHours(8);\n            options.SlidingExpiration = false;\n\n            // could be used to automatically trigger re-authentication (if you want to do that at the pipeline level)\n            //options.Events.OnValidatePrincipal = async e =>\n            //{\n            //    var currentToken = await e.HttpContext.GetAccessTokenAsync();\n\n            //    if (string.IsNullOrWhiteSpace(currentToken))\n            //    {\n            //        e.RejectPrincipal();\n            //    }\n            //};\n\n            options.Events.OnSigningOut = async e =>\n            {\n                // automatically revoke refresh token at signout time\n                await e.HttpContext.RevokeUserRefreshTokenAsync();\n            };\n        })\n        .AddOpenIdConnect(\"oidc\", options =>\n        {\n            options.Authority = Constants.Authority;\n            options.RequireHttpsMetadata = false;\n\n            options.ClientId = \"mvc.tokenmanagement\";\n            options.ClientSecret = \"secret\";\n\n            // code flow + PKCE (PKCE is turned on by default)\n            options.ResponseType = \"code\";\n            options.UsePkce = true;\n\n            options.Scope.Clear();\n            options.Scope.Add(\"openid\");\n            options.Scope.Add(\"profile\");\n            options.Scope.Add(\"resource1.scope1\");\n            options.Scope.Add(\"offline_access\");\n\n            // keeps id_token smaller\n            options.GetClaimsFromUserInfoEndpoint = true;\n            options.SaveTokens = true;\n\n            options.TokenValidationParameters = new TokenValidationParameters\n            {\n                NameClaimType = \"name\",\n                RoleClaimType = \"role\"\n            };\n        });\n\n    // add automatic token management\n    services.AddAccessTokenManagement();\n\n    // add HTTP client to call protected API\n    services.AddUserAccessTokenHttpClient(\"client\", configureClient: client =>\n    {\n        client.BaseAddress = new Uri(Constants.SampleApi);\n    });\n\n    using (var app = builder.Build())\n    {\n        app\n            .UseSerilogRequestLogging()\n            .UseDeveloperExceptionPage()\n            .UseHttpsRedirection()\n            .UseStaticFiles()\n            .UseRouting()\n            .UseAuthentication()\n            .UseAuthorization();\n\n        app.MapDefaultControllerRoute().RequireAuthorization();\n\n        await app.RunAsync();\n        return 0;\n    }\n}\ncatch (Exception ex)\n{\n    Log.Fatal(ex, \"Host terminated unexpectedly.\");\n    return 1;\n}\nfinally\n{\n    Log.CloseAndFlush();\n}\n\nSerilog.ILogger ConfigureLogger() =>\n    Log.Logger = new LoggerConfiguration()\n    .MinimumLevel.Warning()\n    .MinimumLevel.Override(\"IdentityModel\", LogEventLevel.Debug)\n    .MinimumLevel.Override(\"System.Net.Http\", LogEventLevel.Information)\n    .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n    .Enrich.FromLogContext()\n    .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\")\n    .CreateLogger();"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"Host\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:44301/\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/Views/Home/CallApi.cshtml",
    "content": "﻿<h1>API Response</h1>\n\n<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/Views/Home/Index.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Home Page\";\n}\n\n<div class=\"text-center\">\n    <h1 class=\"display-4\">Welcome</h1>\n    <p>Learn about <a href=\"https://docs.microsoft.com/aspnet/core\">building Web apps with ASP.NET Core</a>.</p>\n</div>\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/Views/Home/Secure.cshtml",
    "content": "﻿@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/Views/Shared/_Layout.cshtml",
    "content": "﻿<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MVC Client</title>\n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <header>\n        <nav class=\"navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3\">\n            <div class=\"container\">\n                <a class=\"navbar-brand\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">MvcCode</a>\n                <button class=\"navbar-toggler\" type=\"button\" data-toggle=\"collapse\" data-target=\".navbar-collapse\" aria-controls=\"navbarSupportedContent\"\n                        aria-expanded=\"false\" aria-label=\"Toggle navigation\">\n                    <span class=\"navbar-toggler-icon\"></span>\n                </button>\n                <div class=\"navbar-collapse collapse d-sm-inline-flex flex-sm-row-reverse\">\n                    <ul class=\"navbar-nav flex-grow-1\">\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">Home</a>\n                        </li>\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Secure\">Secure</a>\n                        </li>\n\n                        @if (User.Identity.IsAuthenticated)\n                        {\n                            <li class=\"nav-item\">\n                                <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"CallApi\">Call API</a>\n                            </li>\n                            <li class=\"nav-item\">\n                                <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Logout\">Logout</a>\n                            </li>\n                        }\n                    </ul>\n                </div>\n            </div>\n        </nav>\n    </header>\n    <div class=\"container\">\n        <main role=\"main\" class=\"pb-3\">\n            @RenderBody()\n        </main>\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n    <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    @RenderSection(\"Scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/Views/Shared/_ValidationScriptsPartial.cshtml",
    "content": "﻿<script src=\"~/lib/jquery-validation/dist/jquery.validate.min.js\"></script>\n<script src=\"~/lib/jquery-validation-unobtrusive/jquery.validate.unobtrusive.min.js\"></script>\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/appsettings.Development.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Debug\",\n      \"System\": \"Information\",\n      \"Microsoft\": \"Information\"\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/appsettings.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Information\",\n      \"Microsoft\": \"Warning\",\n      \"Microsoft.Hosting.Lifetime\": \"Information\"\n    }\n  },\n  \"AllowedHosts\": \"*\"\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/wwwroot/css/site.css",
    "content": "﻿/* Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\nfor details on configuring this project to bundle and minify static web assets. */\n\na.navbar-brand {\n  white-space: normal;\n  text-align: center;\n  word-break: break-all;\n}\n\n/* Provide sufficient contrast against white background */\na {\n  color: #0366d6;\n}\n\n.btn-primary {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n.nav-pills .nav-link.active, .nav-pills .show > .nav-link {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  font-size: 14px;\n}\n@media (min-width: 768px) {\n  html {\n    font-size: 16px;\n  }\n}\n\n.border-top {\n  border-top: 1px solid #e5e5e5;\n}\n.border-bottom {\n  border-bottom: 1px solid #e5e5e5;\n}\n\n.box-shadow {\n  box-shadow: 0 .25rem .75rem rgba(0, 0, 0, .05);\n}\n\nbutton.accept-policy {\n  font-size: 1rem;\n  line-height: inherit;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  position: relative;\n  min-height: 100%;\n}\n\nbody {\n  /* Margin bottom by footer height */\n  margin-bottom: 60px;\n}\n.footer {\n  position: absolute;\n  bottom: 0;\n  width: 100%;\n  white-space: nowrap;\n  line-height: 60px; /* Vertically center the text there */\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcAutomaticTokenManagement/wwwroot/js/site.js",
    "content": "﻿// Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\n// for details on configuring this project to bundle and minify static web assets.\n\n// Write your JavaScript code.\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly IHttpClientFactory _httpClientFactory;\n    private readonly IDiscoveryCache _discoveryCache;\n\n    public HomeController(IHttpClientFactory httpClientFactory, IDiscoveryCache discoveryCache)\n    {\n        _httpClientFactory = httpClientFactory;\n        _discoveryCache = discoveryCache;\n    }\n\n    [AllowAnonymous]\n    public IActionResult Index() => View();\n\n    public IActionResult Secure() => View();\n\n    public IActionResult Logout() => SignOut(\"oidc\");\n\n    public async Task<IActionResult> CallApi()\n    {\n        var token = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = _httpClientFactory.CreateClient();\n        client.SetBearerToken(token);\n\n        var response = await client.GetStringAsync(Constants.SampleApi + \"identity\");\n        ViewBag.Json = JsonSerializer.Deserialize<JsonElement>(response).ToString();\n\n        return View();\n    }\n\n    public async Task<IActionResult> RenewTokens()\n    {\n        var disco = await _discoveryCache.GetAsync();\n        if (disco.IsError) throw new Exception(disco.Error);\n\n        var rt = await HttpContext.GetTokenAsync(\"refresh_token\");\n        var tokenClient = _httpClientFactory.CreateClient();\n\n        var tokenResult = await tokenClient.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = disco.TokenEndpoint,\n\n            ClientId = \"mvc.code\",\n            ClientSecret = \"secret\",\n            RefreshToken = rt\n        });\n\n        if (!tokenResult.IsError)\n        {\n            var oldIdToken = await HttpContext.GetTokenAsync(\"id_token\");\n            var newAccessToken = tokenResult.AccessToken;\n            var newRefreshToken = tokenResult.RefreshToken;\n            var expiresAt = DateTime.UtcNow + TimeSpan.FromSeconds(tokenResult.ExpiresIn);\n\n            var info = await HttpContext.AuthenticateAsync(\"Cookies\");\n\n            info.Properties.UpdateTokenValue(\"refresh_token\", newRefreshToken);\n            info.Properties.UpdateTokenValue(\"access_token\", newAccessToken);\n            info.Properties.UpdateTokenValue(\"expires_at\", expiresAt.ToString(\"o\", CultureInfo.InvariantCulture));\n\n            await HttpContext.SignInAsync(\"Cookies\", info.Principal, info.Properties);\n            return Redirect(\"~/Home/Secure\");\n        }\n\n        ViewData[\"Error\"] = tokenResult.Error;\n        return View(\"Error\");\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Clients;\nglobal using IdentityModel;\nglobal using IdentityModel.Client;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authentication.Cookies;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using System.Globalization;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/MvcCode.csproj",
    "content": "﻿<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n</Project>\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nJwtSecurityTokenHandler.DefaultMapInboundClaims = false;\n\nvar builder = WebApplication.CreateBuilder(args);\n\nvar services = builder.Services;\n\nservices.AddControllersWithViews();\n\nservices\n.AddHttpClient()\n.AddSingleton<IDiscoveryCache>(r =>\n{\n    var factory = r.GetRequiredService<IHttpClientFactory>();\n    return new DiscoveryCache(Constants.Authority, () => factory.CreateClient());\n}\n)\n.AddAuthentication(options =>\n{\n    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;\n    options.DefaultChallengeScheme = \"oidc\";\n})\n.AddCookie(options =>\n{\n    options.Cookie.Name = \"mvccode\";\n})\n.AddOpenIdConnect(\"oidc\", options =>\n{\n    options.Authority = Constants.Authority;\n    options.RequireHttpsMetadata = false;\n\n    options.ClientId = \"mvc.code\";\n    options.ClientSecret = \"secret\";\n\n    // code flow + PKCE (PKCE is turned on by default)\n    options.ResponseType = \"code\";\n    options.UsePkce = true;\n\n    options.Scope.Clear();\n    options.Scope.Add(\"openid\");\n    options.Scope.Add(\"profile\");\n    options.Scope.Add(\"email\");\n    options.Scope.Add(\"resource1.scope1\");\n    options.Scope.Add(\"transaction:123\");\n    //options.Scope.Add(\"transaction\");\n    options.Scope.Add(\"offline_access\");\n\n    // not mapped by default\n    options.ClaimActions.MapJsonKey(\"website\", \"website\");\n\n    // keeps id_token smaller\n    options.GetClaimsFromUserInfoEndpoint = true;\n    options.SaveTokens = true;\n\n    options.TokenValidationParameters = new TokenValidationParameters\n    {\n        NameClaimType = JwtClaimTypes.Name,\n        RoleClaimType = JwtClaimTypes.Role,\n    };\n});\n\nvar app = builder.Build();\n\napp.UseSerilogRequestLogging()\n.UseDeveloperExceptionPage()\n.UseHttpsRedirection()\n.UseStaticFiles()\n.UseRouting()\n.UseAuthentication()\n.UseAuthorization();\n\napp.MapDefaultControllerRoute().RequireAuthorization();\n\nawait app.RunAsync();\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/Properties/launchSettings.json",
    "content": "﻿{\n  \"profiles\": {\n    \"Host\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"applicationUrl\": \"https://localhost:44302\",\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      }\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/Views/Home/CallApi.cshtml",
    "content": "﻿<h1>API Response</h1>\n\n<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Clients/src/MvcCode/Views/Home/Index.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Home Page\";\n}\n\n<div class=\"text-center\">\n    <h1 class=\"display-4\">Welcome</h1>\n    <p>Learn about <a href=\"https://docs.microsoft.com/aspnet/core\">building Web apps with ASP.NET Core</a>.</p>\n</div>\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/Views/Home/Secure.cshtml",
    "content": "﻿@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<div class=\"panel\">\n    <a class=\"btn btn-primary\" href=\"~/home/callapi\">Call API</a>\n    <a class=\"btn btn-primary\" href=\"~/home/renewtokens\">Renew Tokens</a>\n</div>\n\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Clients/src/MvcCode/Views/Shared/Error.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n\n<h3>Development Mode</h3>\n<p>\n    Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.\n</p>\n<p>\n    <strong>Development environment should not be enabled in deployed applications</strong>, as it can result in sensitive information from exceptions being displayed to end users. For local debugging, development environment can be enabled by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>, and restarting the application.\n</p>\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/Views/Shared/_Layout.cshtml",
    "content": "﻿<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcCode</title>\n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <header>\n        <nav class=\"navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3\">\n            <div class=\"container\">\n                <a class=\"navbar-brand\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">MvcCode</a>\n                <button class=\"navbar-toggler\" type=\"button\" data-toggle=\"collapse\" data-target=\".navbar-collapse\" aria-controls=\"navbarSupportedContent\"\n                        aria-expanded=\"false\" aria-label=\"Toggle navigation\">\n                    <span class=\"navbar-toggler-icon\"></span>\n                </button>\n                <div class=\"navbar-collapse collapse d-sm-inline-flex flex-sm-row-reverse\">\n                    <ul class=\"navbar-nav flex-grow-1\">\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">Home</a>\n                        </li>\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Secure\">Secure</a>\n                        </li>\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Logout\">Logout</a>\n                        </li>\n                    </ul>\n                </div>\n            </div>\n        </nav>\n    </header>\n    <div class=\"container\">\n        <main role=\"main\" class=\"pb-3\">\n            @RenderBody()\n        </main>\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n    <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    @RenderSection(\"Scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/Views/Shared/_ValidationScriptsPartial.cshtml",
    "content": "﻿<script src=\"~/lib/jquery-validation/dist/jquery.validate.min.js\"></script>\n<script src=\"~/lib/jquery-validation-unobtrusive/jquery.validate.unobtrusive.min.js\"></script>\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Clients/src/MvcCode/wwwroot/css/site.css",
    "content": "﻿/* Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\nfor details on configuring this project to bundle and minify static web assets. */\n\na.navbar-brand {\n  white-space: normal;\n  text-align: center;\n  word-break: break-all;\n}\n\n/* Provide sufficient contrast against white background */\na {\n  color: #0366d6;\n}\n\n.btn-primary {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n.nav-pills .nav-link.active, .nav-pills .show > .nav-link {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  font-size: 14px;\n}\n@media (min-width: 768px) {\n  html {\n    font-size: 16px;\n  }\n}\n\n.border-top {\n  border-top: 1px solid #e5e5e5;\n}\n.border-bottom {\n  border-bottom: 1px solid #e5e5e5;\n}\n\n.box-shadow {\n  box-shadow: 0 .25rem .75rem rgba(0, 0, 0, .05);\n}\n\nbutton.accept-policy {\n  font-size: 1rem;\n  line-height: inherit;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  position: relative;\n  min-height: 100%;\n}\n\nbody {\n  /* Margin bottom by footer height */\n  margin-bottom: 60px;\n}\n.footer {\n  position: absolute;\n  bottom: 0;\n  width: 100%;\n  white-space: nowrap;\n  line-height: 60px; /* Vertically center the text there */\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcCode/wwwroot/js/site.js",
    "content": "﻿// Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\n// for details on configuring this project to bundle and minify static web assets.\n\n// Write your JavaScript code.\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly IHttpClientFactory _httpClientFactory;\n    private readonly IDiscoveryCache _discoveryCache;\n\n    public HomeController(IHttpClientFactory httpClientFactory, IDiscoveryCache discoveryCache)\n    {\n        _httpClientFactory = httpClientFactory;\n        _discoveryCache = discoveryCache;\n    }\n\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    [Authorize]\n    public IActionResult Secure()\n    {\n        return View();\n    }\n\n    [Authorize]\n    public async Task<IActionResult> CallApi()\n    {\n        var token = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = _httpClientFactory.CreateClient();\n        client.SetBearerToken(token);\n\n        var response = await client.GetStringAsync(Constants.SampleApi + \"identity\");\n        ViewBag.Json = JsonSerializer.Deserialize<JsonElement>(response).ToString();\n\n        return View();\n    }\n\n    public async Task<IActionResult> RenewTokens()\n    {\n        var disco = await _discoveryCache.GetAsync();\n        if (disco.IsError) throw new Exception(disco.Error);\n\n        var rt = await HttpContext.GetTokenAsync(\"refresh_token\");\n        var tokenClient = _httpClientFactory.CreateClient();\n\n        var tokenResult = await tokenClient.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = disco.TokenEndpoint,\n\n            ClientId = \"mvc.hybrid.backchannel\",\n            ClientSecret = \"secret\",\n            RefreshToken = rt\n        });\n\n        if (!tokenResult.IsError)\n        {\n            var old_id_token = await HttpContext.GetTokenAsync(\"id_token\");\n            var new_access_token = tokenResult.AccessToken;\n            var new_refresh_token = tokenResult.RefreshToken;\n            var expiresAt = DateTime.UtcNow + TimeSpan.FromSeconds(tokenResult.ExpiresIn);\n\n            var info = await HttpContext.AuthenticateAsync(\"Cookies\");\n\n            info.Properties.UpdateTokenValue(\"refresh_token\", new_refresh_token);\n            info.Properties.UpdateTokenValue(\"access_token\", new_access_token);\n            info.Properties.UpdateTokenValue(\"expires_at\", expiresAt.ToString(\"o\", CultureInfo.InvariantCulture));\n\n            await HttpContext.SignInAsync(\"Cookies\", info.Principal, info.Properties);\n            return Redirect(\"~/Home/Secure\");\n        }\n\n        ViewData[\"Error\"] = tokenResult.Error;\n        return View(\"Error\");\n    }\n\n    public IActionResult Logout()\n    {\n        return new SignOutResult(new[] { \"Cookies\", \"oidc\" });\n    }\n\n    public IActionResult Error()\n    {\n        return View();\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Controllers/LogoutController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class LogoutController : Controller\n{\n    public LogoutSessionManager LogoutSessions { get; }\n\n    public LogoutController(LogoutSessionManager logoutSessions)\n    {\n        LogoutSessions = logoutSessions;\n    }\n\n    [HttpPost]\n    [AllowAnonymous]\n    public async Task<IActionResult> Index(string logout_token)\n    {\n        Response.Headers.Append(\"Cache-Control\", \"no-cache, no-store\");\n        Response.Headers.Append(\"Pragma\", \"no-cache\");\n\n        try\n        {\n            var user = await ValidateLogoutToken(logout_token);\n\n            // these are the sub & sid to signout\n            var sub = user.FindFirst(\"sub\")?.Value;\n            var sid = user.FindFirst(\"sid\")?.Value;\n\n            LogoutSessions.Add(sub, sid);\n\n            return Ok();\n        }\n        catch { }\n\n        return BadRequest();\n    }\n\n    private async Task<ClaimsPrincipal> ValidateLogoutToken(string logoutToken)\n    {\n        var claims = await ValidateJwt(logoutToken);\n\n        if (claims.FindFirst(\"sub\") == null && claims.FindFirst(\"sid\") == null) throw new Exception(\"Invalid logout token\");\n\n        var nonce = claims.FindFirstValue(\"nonce\");\n        if (!String.IsNullOrWhiteSpace(nonce)) throw new Exception(\"Invalid logout token\");\n\n        var eventsJson = claims.FindFirst(\"events\")?.Value;\n        if (String.IsNullOrWhiteSpace(eventsJson)) throw new Exception(\"Invalid logout token\");\n\n        var events =JsonSerializer.Deserialize<JsonElement>(eventsJson);\n        var logoutEvent = events.TryGetValue(\"http://schemas.openid.net/event/backchannel-logout\");\n        if (logoutEvent.ValueKind == JsonValueKind.Null) throw new Exception(\"Invalid logout token\");\n\n        return claims;\n    }\n\n    private static async Task<ClaimsPrincipal> ValidateJwt(string jwt)\n    {\n        // read discovery document to find issuer and key material\n        var client = new HttpClient();\n        var disco = await client.GetDiscoveryDocumentAsync(Constants.Authority);\n\n        var keys = new List<SecurityKey>();\n        foreach (var webKey in disco.KeySet.Keys)\n        {\n            var key = new JsonWebKey()\n            {\n                Kty = webKey.Kty,\n                Alg = webKey.Alg,\n                Kid = webKey.Kid,\n                X = webKey.X,\n                Y = webKey.Y,\n                Crv = webKey.Crv,\n                E = webKey.E,\n                N = webKey.N,\n            };\n            keys.Add(key);\n        }\n\n        var parameters = new TokenValidationParameters\n        {\n            ValidIssuer = disco.Issuer,\n            ValidAudience = \"mvc.hybrid.backchannel\",\n            IssuerSigningKeys = keys,\n\n            NameClaimType = JwtClaimTypes.Name,\n            RoleClaimType = JwtClaimTypes.Role\n        };\n\n        var handler = new JwtSecurityTokenHandler();\n        handler.InboundClaimTypeMap.Clear();\n\n        var user = handler.ValidateToken(jwt, parameters, out var _);\n        return user;\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/CookieEventHandler.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class CookieEventHandler : CookieAuthenticationEvents\n{\n    public CookieEventHandler(LogoutSessionManager logoutSessions)\n    {\n        LogoutSessions = logoutSessions;\n    }\n\n    public LogoutSessionManager LogoutSessions { get; }\n\n    public override async Task ValidatePrincipal(CookieValidatePrincipalContext context)\n    {\n        if (context.Principal.Identity.IsAuthenticated)\n        {\n            var sub = context.Principal.FindFirst(\"sub\")?.Value;\n            var sid = context.Principal.FindFirst(\"sid\")?.Value;\n\n            if (LogoutSessions.IsLoggedOut(sub, sid))\n            {\n                context.RejectPrincipal();\n                await context.HttpContext.SignOutAsync();\n\n                // todo: if we have a refresh token, it should be revoked here.\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Clients;\nglobal using IdentityModel;\nglobal using IdentityModel.Client;\nglobal using Microsoft.AspNetCore;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authentication.Cookies;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using System.Globalization;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Security.Claims;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/LogoutSessionManager.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class LogoutSessionManager\n{\n    // yes - that needs to be thread-safe, distributed etc (it's a sample)\n    List<Session> _sessions = new List<Session>();\n\n    public void Add(string sub, string sid)\n    {\n        _sessions.Add(new Session { Sub = sub, Sid = sid }); \n    }\n\n    public bool IsLoggedOut(string sub, string sid)\n    {\n        var matches = _sessions.Any(s => s.IsMatch(sub, sid));\n        return matches;\n    }\n\n    private class Session\n    {\n        public string Sub { get; set; }\n        public string Sid { get; set; }\n\n        public bool IsMatch(string sub, string sid)\n        {\n            return (Sid == sid && Sub == sub) ||\n                   (Sid == sid && Sub == null) ||\n                   (Sid == null && Sub == sub);\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/MvcHybridBackChannel.csproj",
    "content": "﻿<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nJwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();\n\nvar builder= WebApplication.CreateBuilder(args);\n\nvar services = builder.Services;\n\nservices.AddControllersWithViews();\n\nservices\n.AddHttpClient()\n.AddSingleton<IDiscoveryCache>(r =>\n{\n    var factory = r.GetRequiredService<IHttpClientFactory>();\n    return new DiscoveryCache(Constants.Authority, () => factory.CreateClient());\n})\n.AddTransient<CookieEventHandler>()\n.AddSingleton<LogoutSessionManager>()\n.AddAuthentication(options =>\n{\n    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;\n    options.DefaultChallengeScheme = \"oidc\";\n})\n.AddCookie(options =>\n{\n    options.ExpireTimeSpan = TimeSpan.FromMinutes(60);\n    options.Cookie.Name = \"mvchybridbc\";\n\n    options.EventsType = typeof(CookieEventHandler);\n})\n.AddOpenIdConnect(\"oidc\", options =>\n{\n    options.Authority = Constants.Authority;\n    options.RequireHttpsMetadata = false;\n\n    options.ClientSecret = \"secret\";\n    options.ClientId = \"mvc.hybrid.backchannel\";\n\n    options.ResponseType = \"code id_token\";\n\n    options.Scope.Clear();\n    options.Scope.Add(\"openid\");\n    options.Scope.Add(\"profile\");\n    options.Scope.Add(\"email\");\n    options.Scope.Add(\"resource1.scope1\");\n    options.Scope.Add(\"offline_access\");\n\n    options.ClaimActions.MapAllExcept(\"iss\", \"nbf\", \"exp\", \"aud\", \"nonce\", \"iat\", \"c_hash\");\n\n    options.GetClaimsFromUserInfoEndpoint = true;\n    options.SaveTokens = true;\n\n    options.TokenValidationParameters = new TokenValidationParameters\n    {\n        NameClaimType = JwtClaimTypes.Name,\n        RoleClaimType = JwtClaimTypes.Role,\n    };\n});\n\n\n\nusing (var app = builder.Build())\n{\n    await app.RunAsync();\n}"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"Host\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:44303\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Views/Home/CallApi.cshtml",
    "content": "﻿<h1>API Response</h1>\n\n<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Views/Home/Index.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Home Page\";\n}\n\n@if(User.Identity.IsAuthenticated)\n{\n    <h1>Logged in as: @User.Identity.Name</h1>\n}\nelse\n{\n    <h1>Not Logged In</h1>\n}"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Views/Home/Secure.cshtml",
    "content": "﻿@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<div class=\"panel\">\n    <a class=\"btn btn-primary\" href=\"~/home/callapi\">Call API</a>\n    <a class=\"btn btn-primary\" href=\"~/home/renewtokens\">Renew Tokens</a>\n</div>\n\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Views/Shared/Error.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n\n<h3>Development Mode</h3>\n<p>\n    Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.\n</p>\n<p>\n    <strong>Development environment should not be enabled in deployed applications</strong>, as it can result in sensitive information from exceptions being displayed to end users. For local debugging, development environment can be enabled by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>, and restarting the application.\n</p>\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Views/Shared/_Layout.cshtml",
    "content": "﻿<!DOCTYPE html>\n<html>\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcHybrid</title>\n\n    <environment names=\"Development\">\n        <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.css\" />\n        <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n    </environment>\n    <environment names=\"Staging,Production\">\n        <link rel=\"stylesheet\" href=\"https://ajax.aspnetcdn.com/ajax/bootstrap/3.3.6/css/bootstrap.min.css\"\n              asp-fallback-href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\"\n              asp-fallback-test-class=\"sr-only\" asp-fallback-test-property=\"position\" asp-fallback-test-value=\"absolute\" />\n        <link rel=\"stylesheet\" href=\"~/css/site.min.css\" asp-append-version=\"true\" />\n    </environment>\n</head>\n<body>\n    <div class=\"navbar navbar-inverse navbar-fixed-top\">\n        <div class=\"container\">\n            <div class=\"navbar-header\">\n                <button type=\"button\" class=\"navbar-toggle\" data-toggle=\"collapse\" data-target=\".navbar-collapse\">\n                    <span class=\"sr-only\">Toggle navigation</span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                    <span class=\"icon-bar\"></span>\n                </button>\n                <a asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\" class=\"navbar-brand\">MvcHybrid</a>\n            </div>\n            <div class=\"navbar-collapse collapse\">\n                <ul class=\"nav navbar-nav\">\n                    <li><a asp-controller=\"Home\" asp-action=\"Secure\">Secure</a></li>\n                    <li><a asp-controller=\"Home\" asp-action=\"Logout\">Logout</a></li>\n                </ul>\n            </div>\n        </div>\n    </div>\n    <div class=\"container body-content\">\n        @RenderBody()\n        <hr />\n        <footer>\n            <p>&copy; 2016 - MvcHybrid</p>\n        </footer>\n    </div>\n\n    <environment names=\"Development\">\n        <script src=\"~/lib/jquery/dist/jquery.js\"></script>\n        <script src=\"~/lib/bootstrap/dist/js/bootstrap.js\"></script>\n        <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    </environment>\n    <environment names=\"Staging,Production\">\n        <script src=\"https://ajax.aspnetcdn.com/ajax/jquery/jquery-2.2.0.min.js\"\n                asp-fallback-src=\"~/lib/jquery/dist/jquery.min.js\"\n                asp-fallback-test=\"window.jQuery\">\n        </script>\n        <script src=\"https://ajax.aspnetcdn.com/ajax/bootstrap/3.3.6/bootstrap.min.js\"\n                asp-fallback-src=\"~/lib/bootstrap/dist/js/bootstrap.min.js\"\n                asp-fallback-test=\"window.jQuery && window.jQuery.fn && window.jQuery.fn.modal\">\n        </script>\n        <script src=\"~/js/site.min.js\" asp-append-version=\"true\"></script>\n    </environment>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/wwwroot/_references.js",
    "content": "﻿/// <autosync enabled=\"true\" />\n/// <reference path=\"js/site.js\" />\n/// <reference path=\"lib/bootstrap/dist/js/bootstrap.js\" />\n/// <reference path=\"lib/jquery/dist/jquery.js\" />\n/// <reference path=\"lib/jquery-validation/dist/jquery.validate.js\" />\n/// <reference path=\"lib/jquery-validation-unobtrusive/jquery.validate.unobtrusive.js\" />\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/wwwroot/css/site.css",
    "content": "﻿body {\n    padding-top: 50px;\n    padding-bottom: 20px;\n}\n\n/* Wrapping element */\n/* Set some basic padding to keep content from hitting the edges */\n.body-content {\n    padding-left: 15px;\n    padding-right: 15px;\n}\n\n/* Set widths on the form inputs since otherwise they're 100% wide */\ninput,\nselect,\ntextarea {\n    max-width: 280px;\n}\n\n/* Carousel */\n.carousel-caption p {\n    font-size: 20px;\n    line-height: 1.4;\n}\n\n/* Make .svg files in the carousel display properly in older browsers */\n.carousel-inner .item img[src$=\".svg\"]\n{\n    width: 100%;\n}\n\n/* Hide/rearrange for smaller screens */\n@media screen and (max-width: 767px) {\n  /* Hide captions */\n  .carousel-caption {\n    display: none\n  }\n}\n"
  },
  {
    "path": "samples/Clients/src/MvcHybridBackChannel/wwwroot/js/site.js",
    "content": "﻿// Write your Javascript code.\n"
  },
  {
    "path": "samples/Clients/src/WindowsConsoleSystemBrowser/CallbackManager.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.IO.Pipes;\n\nclass CallbackManager\n{\n    private readonly string _name;\n\n    public CallbackManager(string name)\n    {\n        _name = name ?? throw new ArgumentNullException(nameof(name));\n    }\n\n    public int ClientConnectTimeoutSeconds { get; set; } = 1;\n\n    public async Task RunClient(string args)\n    {\n        using (var client = new NamedPipeClientStream(\".\", _name, PipeDirection.Out))\n        {\n            await client.ConnectAsync(ClientConnectTimeoutSeconds * 1000);\n\n            using (var sw = new StreamWriter(client) { AutoFlush = true })\n            {\n                await sw.WriteAsync(args);\n            }\n        }\n    }\n\n    public async Task<string> RunServer(CancellationToken? token = null)\n    {\n        token = CancellationToken.None;\n\n        using (var server = new NamedPipeServerStream(_name, PipeDirection.In))\n        {\n            await server.WaitForConnectionAsync(token.Value);\n\n            using (var sr = new StreamReader(server))\n            {\n                var msg = await sr.ReadToEndAsync();\n                return msg;\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/WindowsConsoleSystemBrowser/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Logging;\n\nIdentityModelEventSource.ShowPII = true;\n\nif (args.Any())\n{\n    await ProcessCallback(args[0]);\n}\nelse\n{\n    await Run();\n}\n\nasync Task ProcessCallback(string args)\n{\n    var response = new AuthorizeResponse(args);\n    if (!String.IsNullOrWhiteSpace(response.State))\n    {\n        Console.WriteLine($\"Found state: {response.State}\");\n        var callbackManager = new CallbackManager(response.State);\n        await callbackManager.RunClient(args);\n    }\n    else\n    {\n        Console.WriteLine(\"Error: no state on response\");\n    }\n}\n\nconst string CustomUriScheme = \"sample-windows-client\";\n\n[SupportedOSPlatform(\"windows\")]\nasync Task Run()\n{\n    new RegistryConfig(CustomUriScheme).Configure();\n\n    Console.WriteLine(\"+-----------------------+\");\n    Console.WriteLine(\"|  Sign in with OIDC    |\");\n    Console.WriteLine(\"+-----------------------+\");\n    Console.WriteLine(\"\");\n    Console.WriteLine(\"Press any key to sign in...\");\n    Console.ReadKey();\n\n    await SignIn();\n\n    Console.ReadKey();\n}\n\nasync Task SignIn()\n{\n    // create a redirect URI using the custom redirect uri\n    string redirectUri = string.Format(CustomUriScheme + \"://callback\");\n    Console.WriteLine(\"redirect URI: \" + redirectUri);\n\n    var options = new OidcClientOptions\n    {\n        Authority = Constants.Authority,\n        ClientId = \"winconsole\",\n        Scope = \"openid profile scope1\",\n        RedirectUri = redirectUri,\n    };\n\n    var serilog = new LoggerConfiguration()\n          .MinimumLevel.Verbose()\n          .Enrich.FromLogContext()\n          .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message}{NewLine}{Exception}{NewLine}\")\n          .CreateLogger();\n\n    options.LoggerFactory.AddSerilog(serilog);\n\n    var client = new OidcClient(options);\n    var state = await client.PrepareLoginAsync();\n\n    Console.WriteLine($\"Start URL: {state.StartUrl}\");\n\n    var callbackManager = new CallbackManager(state.State);\n\n    // open system browser to start authentication\n    Process.Start(state.StartUrl);\n\n    Console.WriteLine(\"Running callback manager\");\n    var response = await callbackManager.RunServer();\n\n    Console.WriteLine($\"Response from authorize endpoint: {response}\");\n\n    // Brings the Console to Focus.\n    BringConsoleToFront();\n\n    var result = await client.ProcessResponseAsync(response, state);\n\n    BringConsoleToFront();\n\n    if (result.IsError)\n    {\n        Console.WriteLine(\"\\n\\nError:\\n{0}\", result.Error);\n    }\n    else\n    {\n        Console.WriteLine(\"\\n\\nClaims:\");\n        foreach (var claim in result.User.Claims)\n        {\n            Console.WriteLine(\"{0}: {1}\", claim.Type, claim.Value);\n        }\n\n        Console.WriteLine();\n\n        if (!string.IsNullOrEmpty(result.IdentityToken))\n        {\n            Console.WriteLine(\"Identity token:\\n{0}\", result.IdentityToken);\n        }\n\n        if (!string.IsNullOrEmpty(result.AccessToken))\n        {\n            Console.WriteLine(\"Access token:\\n{0}\", result.AccessToken);\n        }\n\n        if (!string.IsNullOrWhiteSpace(result.RefreshToken))\n        {\n            Console.WriteLine(\"Refresh token:\\n{0}\", result.RefreshToken);\n        }\n    }\n}\n\n// Hack to bring the Console window to front.\n// ref: http://stackoverflow.com/a/12066376\n[DllImport(\"kernel32.dll\", ExactSpelling = true)]\nstatic extern IntPtr GetConsoleWindow();\n\n[DllImport(\"user32.dll\")]\n[return: MarshalAs(UnmanagedType.Bool)]\nstatic extern bool SetForegroundWindow(IntPtr hWnd);\n\nvoid BringConsoleToFront()\n{\n    SetForegroundWindow(GetConsoleWindow());\n}\n\nstatic string GetRequestPostData(HttpListenerRequest request)\n{\n    if (!request.HasEntityBody)\n    {\n        return null;\n    }\n\n    using (var body = request.InputStream)\n    {\n        using (var reader = new System.IO.StreamReader(body, request.ContentEncoding))\n        {\n            return reader.ReadToEnd();\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/WindowsConsoleSystemBrowser/RegistryConfig.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.Win32;\nusing System.Reflection;\n\nclass RegistryConfig\n{\n    public RegistryConfig(string uriScheme)\n    {\n        CustomUriScheme = uriScheme;\n    }\n\n\n    [SupportedOSPlatform(\"windows\")]\n    public void Configure()\n    {\n        if (NeedToAddKeys()) AddRegKeys();\n    }\n\n    string CustomUriScheme { get; }\n\n    string CustomUriSchemeKeyPath => RootKeyPath + @\"\\\" + CustomUriScheme;\n    string CustomUriSchemeKeyValueValue => \"URL:\" + CustomUriScheme;\n    string CommandKeyPath => CustomUriSchemeKeyPath + @\"\\shell\\open\\command\";\n\n    const string RootKeyPath = @\"Software\\Classes\";\n\n    const string CustomUriSchemeKeyValueName = \"\";\n\n    const string ShellKeyName = \"shell\";\n    const string OpenKeyName = \"open\";\n    const string CommandKeyName = \"command\";\n\n    const string CommandKeyValueName = \"\";\n    const string CommandKeyValueFormat = \"\\\"{0}\\\" \\\"%1\\\"\";\n    static string CommandKeyValueValue => String.Format(CommandKeyValueFormat, Assembly.GetExecutingAssembly().Location);\n\n    const string UrlProtocolValueName = \"URL Protocol\";\n    const string UrlProtocolValueValue = \"\";\n\n    [SupportedOSPlatform(\"windows\")]\n    bool NeedToAddKeys()\n    {\n        var addKeys = false;\n\n        using (var commandKey = Registry.CurrentUser.OpenSubKey(CommandKeyPath))\n        {\n            var commandValue = commandKey?.GetValue(CommandKeyValueName);\n            addKeys |= !CommandKeyValueValue.Equals(commandValue);\n        }\n\n        using (var customUriSchemeKey = Registry.CurrentUser.OpenSubKey(CustomUriSchemeKeyPath))\n        {\n            var uriValue = customUriSchemeKey?.GetValue(CustomUriSchemeKeyValueName);\n            var protocolValue = customUriSchemeKey?.GetValue(UrlProtocolValueName);\n\n            addKeys |= !CustomUriSchemeKeyValueValue.Equals(uriValue);\n            addKeys |= !UrlProtocolValueValue.Equals(protocolValue);\n        }\n\n        return addKeys;\n    }\n\n    [SupportedOSPlatform(\"windows\")]\n    void AddRegKeys()\n    {\n        using (var classesKey = Registry.CurrentUser.OpenSubKey(RootKeyPath, true))\n        {\n            using (var root = classesKey.OpenSubKey(CustomUriScheme, true) ??\n                classesKey.CreateSubKey(CustomUriScheme, true))\n            {\n                root.SetValue(CustomUriSchemeKeyValueName, CustomUriSchemeKeyValueValue);\n                root.SetValue(UrlProtocolValueName, UrlProtocolValueValue);\n\n                using (var shell = root.OpenSubKey(ShellKeyName, true) ??\n                        root.CreateSubKey(ShellKeyName, true))\n                {\n                    using (var open = shell.OpenSubKey(OpenKeyName, true) ??\n                            shell.CreateSubKey(OpenKeyName, true))\n                    {\n                        using (var command = open.OpenSubKey(CommandKeyName, true) ??\n                                open.CreateSubKey(CommandKeyName, true))\n                        {\n                            command.SetValue(CommandKeyValueName, CommandKeyValueValue);\n                        }\n                    }\n                }\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Clients/src/WindowsConsoleSystemBrowser/WindowsConsoleSystemBrowser.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n    <PropertyGroup>\n        <OutputType>Exe</OutputType>\n    </PropertyGroup>\n</Project>"
  },
  {
    "path": "samples/Directory.Build.props",
    "content": "<Project>\n  <PropertyGroup>\n\t<IdentityServerVersion>8.0.4-alpha.2</IdentityServerVersion>\n  </PropertyGroup>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n  <ItemGroup>  \n\t<None Remove=\"$(SolutionDir)../icon.jpg\"/>\n\t<None Remove=\"$(SolutionDir)../LICENSE\" />\n\t<None Remove=\"$(SolutionDir)../README.md\" />\n  </ItemGroup>\n  <PropertyGroup>\n\t<SignAssembly>false</SignAssembly>\n  </PropertyGroup>\n  <ItemGroup>\n    <PackageVersion Include=\"HigginsSoft.IdentityServer8\" Version=\"$(IdentityServerVersion)\" />\n\t<PackageVersion Include=\"HigginsSoft.IdentityServer8.Security\" Version=\"$(IdentityServerVersion)\" />\n\t<PackageVersion Include=\"HigginsSoft.IdentityServer8.AspNetIdentity\" Version=\"$(IdentityServerVersion)\" />\n    <PackageVersion Include=\"HigginsSoft.IdentityServer8.EntityFramework\" Version=\"$(IdentityServerVersion)\" />\n  </ItemGroup> \n  <ItemGroup>\n    <PackageReference Include=\"IdentityModel.OidcClient\" />\n    <PackageReference Include=\"IdentityModel.AspNetCore\" />\n    <PackageReference Include=\"IdentityModel.AspNetCore.AccessTokenValidation\" />\n    <PackageReference Include=\"IdentityModel.AspNetCore.OAuth2Introspection\"  />\n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.JwtBearer\" />\n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.OpenIdConnect\" />\n    <PackageReference Include=\"Microsoft.AspNetCore.Server.Kestrel\" />\n    <PackageReference Include=\"Microsoft.IdentityModel.Protocols.OpenIdConnect\" />\n\t<PackageReference Include=\"Microsoft.Extensions.DependencyInjection\" />\n    <PackageReference Include=\"SeriLog\" />\n    <PackageReference Include=\"Serilog.AspNetCore\" />\n    <PackageReference Include=\"Serilog.Extensions.Logging\" />\n    <PackageReference Include=\"Serilog.Sinks.Console\" />\n    <PackageReference Include=\"System.IdentityModel.Tokens.Jwt\" />\n    <Compile Include=\"$(SolutionDir)..\\..\\SamplesGlobalUsings.cs\" Link=\"SamplesGlobalUsings.cs\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/KeyManagement/Directory.Build.props",
    "content": "<Project>\n    <ImportGroup>\n        <Import Project=\"../Directory.Build.props\" />\n    </ImportGroup>\n  <ItemGroup>\n    <PackageReference Include=\"IdentityServer4.KeyManagement\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.SqlServer\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.Design\" >\n\t   <PrivateAssets>all</PrivateAssets>\n\t   <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n    </PackageReference>\n    <Compile Include=\"$(SolutionDir)..\\KeyManagementGlobalUsings.cs\" Link=\"KeyManagementGlobalUsings\" />\n  </ItemGroup>\t\n</Project>"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/Directory.Build.props",
    "content": "<Project>\n    <ImportGroup>\n        <Import Project=\"../Directory.Build.props\" />\n    </ImportGroup>\n</Project>"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/FileSystem/Config.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic static class Config\n{\n    public static IEnumerable<IdentityResource> GetIdentityResources()\n    {\n        return new IdentityResource[]\n        {\n            new IdentityResources.OpenId()\n        };\n    }\n\n    public static IEnumerable<ApiResource> GetApis()\n    {\n        return new ApiResource[] { };\n    }\n\n    public static IEnumerable<Client> GetClients()\n    {\n        return new Client[] { };\n    }\n}\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/FileSystem/FileSystemSample.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <Folder Include=\"dataprotectionkeys\\\" />\n    <Folder Include=\"signingkeys\\\" />\n  </ItemGroup>\n \n</Project>\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/FileSystem/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConsole.Title = \"IdentityServer8\";\n\nvar app = CreateWebHostBuilder(args);\nawait app.RunAsync();\n\n\nWebApplication CreateWebHostBuilder(string[] args)\n{\n    var builder = WebApplication.CreateBuilder(args);\n    builder.Host.UseSerilog((context, configuration) =>\n    {\n        configuration\n            .MinimumLevel.Debug()\n            .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n            .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n            .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n            .Enrich.FromLogContext()\n            .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Literate);\n    });\n\n    var services = builder.Services;\n    var name = \"CN=test.dataprotection\";\n    var cert = X509.LocalMachine.My.SubjectDistinguishedName.Find(name, false).FirstOrDefault();\n\n    var Environment = builder.Environment;\n    services.AddDataProtection()\n        .PersistKeysToFileSystem(new DirectoryInfo(Path.Combine(Environment.ContentRootPath, \"dataprotectionkeys\")));\n    //.ProtectKeysWithCertificate(cert);\n\n    services.AddIdentityServer()\n       .AddInMemoryIdentityResources(Config.GetIdentityResources())\n       .AddInMemoryApiResources(Config.GetApis())\n       .AddInMemoryClients(Config.GetClients())\n       .AddSigningKeyManagement(\n           options => // configuring options is optional :)\n           {\n               options.DeleteRetiredKeys = true;\n               options.KeyType = IdentityServer4.KeyManagement.KeyType.RSA;\n\n               // all of these values in here are changed for local testing\n               options.InitializationDuration = TimeSpan.FromSeconds(5);\n               options.InitializationSynchronizationDelay = TimeSpan.FromSeconds(1);\n\n               options.KeyActivationDelay = TimeSpan.FromSeconds(10);\n               options.KeyExpiration = options.KeyActivationDelay * 2;\n               options.KeyRetirement = options.KeyActivationDelay * 3;\n\n               // You can get your own license from:\n               // https://www.identityserver8.com/products/KeyManagement\n               options.Licensee = \"your licensee\";\n               options.License = \"your license key\";\n           })\n           //.EnableInMemoryCaching()\n           .PersistKeysToFileSystem(Path.Combine(Environment.ContentRootPath, @\"signingkeys\"))\n           .ProtectKeysWithDataProtection();\n\n    // .PersistKeysWith<TYourStore>() // use this when you implement your own ISigningKeyStore\n    //.EnableInMemoryCaching() // caching disabled unless explicitly enabled\n    // run \"..\\cert\\cert.ps1\" from a powershell prompt to create new cert/pfx\n    // put the pfx created in the local machine store\n    //.ProtectKeysWithX509Certificate(\"CN=SigningKeysMasterKey\")\n    ;\n\n\n    var app = builder.Build();\n\n    if (Environment.IsDevelopment())\n    {\n        app.UseDeveloperExceptionPage();\n    }\n\n    app.UseIdentityServer();\n\n    return app;\n\n\n\n}\n\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/FileSystem/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:5000\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"host\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"launchUrl\": \"http://localhost:5000/.well-known/openid-configuration/jwks\",\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"http://localhost:5000\"\n    }\n  }\n}"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/FileSystem/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\npublic class Startup\n{\n    public IWebHostEnvironment Environment { get; }\n\n    public Startup(IConfiguration config, IWebHostEnvironment environment)\n    {\n        Environment = environment;\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        var name = \"CN=test.dataprotection\";\n        var cert = X509.LocalMachine.My.SubjectDistinguishedName.Find(name, false).FirstOrDefault();\n\n        services.AddDataProtection()\n            .PersistKeysToFileSystem(new DirectoryInfo(Path.Combine(Environment.ContentRootPath, \"dataprotectionkeys\")));\n            //.ProtectKeysWithCertificate(cert);\n\n        var builder = services.AddIdentityServer()\n            .AddInMemoryIdentityResources(Config.GetIdentityResources())\n            .AddInMemoryApiResources(Config.GetApis())\n            .AddInMemoryClients(Config.GetClients())\n            .AddSigningKeyManagement(\n                options => // configuring options is optional :)\n                {\n                    options.DeleteRetiredKeys = true;\n                    options.KeyType = IdentityServer4.KeyManagement.KeyType.RSA;\n\n                    // all of these values in here are changed for local testing\n                    options.InitializationDuration = TimeSpan.FromSeconds(5);\n                    options.InitializationSynchronizationDelay = TimeSpan.FromSeconds(1);\n\n                    options.KeyActivationDelay = TimeSpan.FromSeconds(10);\n                    options.KeyExpiration = options.KeyActivationDelay * 2;\n                    options.KeyRetirement = options.KeyActivationDelay * 3;\n\n                    // You can get your own license from:\n                    // https://www.identityserver8.com/products/KeyManagement\n                    options.Licensee = \"your licensee\";\n                    options.License = \"your license key\";\n                })\n                //.EnableInMemoryCaching()\n                .PersistKeysToFileSystem(Path.Combine(Environment.ContentRootPath, @\"signingkeys\"))\n                .ProtectKeysWithDataProtection();\n\n                // .PersistKeysWith<TYourStore>() // use this when you implement your own ISigningKeyStore\n                //.EnableInMemoryCaching() // caching disabled unless explicitly enabled\n                // run \"..\\cert\\cert.ps1\" from a powershell prompt to create new cert/pfx\n                // put the pfx created in the local machine store\n                //.ProtectKeysWithX509Certificate(\"CN=SigningKeysMasterKey\")\n            ;\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n        if (Environment.IsDevelopment())\n        {\n            app.UseDeveloperExceptionPage();\n        }\n\n        app.UseIdentityServer();\n    }\n}\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/FileSystem/appsettings.json",
    "content": "{\n  \"ConnectionStrings\": {\n    \"db\": \"server=(localdb)\\\\mssqllocaldb;database=IdentityServer8.KeyManagement;trusted_connection=yes;\"\n  }\n}"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/KeyManagement.sln",
    "content": "﻿\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 10.0.40219.1\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"filesystem\", \"filesystem\", \"{66069BF5-F9C7-446A-8AD6-C4FA556F99CD}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"database\", \"database\", \"{5460F146-2FAA-4D3B-B3FF-6E0222824293}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"FileSystemSample\", \"FileSystem\\FileSystemSample.csproj\", \"{59A7BDFE-02E5-4FA5-9B7F-A5888C8CACCB}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"EfSample\", \"database\\EF\\EfSample.csproj\", \"{7B9531E7-47A4-4C36-95B9-ADAA4FADF732}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"migrations\", \"database\\migrations\\migrations.csproj\", \"{1979B108-6006-4CFC-81F1-6397659580AB}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Solution Files\", \"Solution Files\", \"{0287EA18-2EE5-4878-A2D7-B8FBA31DCE44}\"\n\tProjectSection(SolutionItems) = preProject\n\t\tDirectory.Build.props = Directory.Build.props\n\t\tKeyManagement.sln.licenseheader = KeyManagement.sln.licenseheader\n\tEndProjectSection\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tRelease|Any CPU = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{59A7BDFE-02E5-4FA5-9B7F-A5888C8CACCB}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{59A7BDFE-02E5-4FA5-9B7F-A5888C8CACCB}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{59A7BDFE-02E5-4FA5-9B7F-A5888C8CACCB}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{59A7BDFE-02E5-4FA5-9B7F-A5888C8CACCB}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{7B9531E7-47A4-4C36-95B9-ADAA4FADF732}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{7B9531E7-47A4-4C36-95B9-ADAA4FADF732}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{7B9531E7-47A4-4C36-95B9-ADAA4FADF732}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{7B9531E7-47A4-4C36-95B9-ADAA4FADF732}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{1979B108-6006-4CFC-81F1-6397659580AB}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{1979B108-6006-4CFC-81F1-6397659580AB}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{1979B108-6006-4CFC-81F1-6397659580AB}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{1979B108-6006-4CFC-81F1-6397659580AB}.Release|Any CPU.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{59A7BDFE-02E5-4FA5-9B7F-A5888C8CACCB} = {66069BF5-F9C7-446A-8AD6-C4FA556F99CD}\n\t\t{7B9531E7-47A4-4C36-95B9-ADAA4FADF732} = {5460F146-2FAA-4D3B-B3FF-6E0222824293}\n\t\t{1979B108-6006-4CFC-81F1-6397659580AB} = {5460F146-2FAA-4D3B-B3FF-6E0222824293}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {34FB2185-9C34-4130-ADA6-2AF52DFBF5DA}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/KeyManagement.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft\n Written by Alexander Higgins https://github.com/alexhiggins732/ \n \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code for this software can be found at https://github.com/alexhiggins732/IdentityServer8\n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n\n*/\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/EF/Config.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic static class Config\n{\n    public static IEnumerable<IdentityResource> GetIdentityResources()\n    {\n        return new IdentityResource[]\n        {\n                new IdentityResources.OpenId()\n        };\n    }\n\n    public static IEnumerable<ApiResource> GetApis()\n    {\n        return new ApiResource[] { };\n    }\n\n    public static IEnumerable<Client> GetClients()\n    {\n        return new Client[] { };\n    }\n}\n\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/EF/EfSample.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n</Project>\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/EF/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConsole.Title = \"IdentityServer8\";\n\nvar builder = WebApplication.CreateBuilder(args);\nbuilder.Host.UseSerilog((context, configuration) =>\n{\n    configuration\n        .MinimumLevel.Debug()\n        .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n        .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n        .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n        .Enrich.FromLogContext()\n        .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Literate);\n});\nvar services = builder.Services;\n\n//var name = \"CN=test.dataprotection\";\n//var cert = X509.LocalMachine.My.SubjectDistinguishedName.Find(name, false).FirstOrDefault();\n\nvar cn = builder.Configuration.GetConnectionString(\"db\");\nvar Environment = builder.Environment;\nservices.AddDataProtection()\n    .PersistKeysToFileSystem(new DirectoryInfo(Path.Combine(Environment.ContentRootPath, \"dataprotectionkeys\")));\n//.PersistKeysToDatabase(new DatabaseKeyManagementOptions\n//{\n//    ConfigureDbContext = b => b.UseSqlServer(cn),\n//    LoggerFactory = LoggerFactory,\n//});\n//.ProtectKeysWithCertificate(cert);\n\nservices.AddIdentityServer()\n     .AddInMemoryIdentityResources(Config.GetIdentityResources())\n     .AddInMemoryApiResources(Config.GetApis())\n     .AddInMemoryClients(Config.GetClients())\n     .AddSigningKeyManagement(\n         options => // configuring options is optional :)\n         {\n             options.DeleteRetiredKeys = true;\n             options.KeyType = IdentityServer4.KeyManagement.KeyType.RSA;\n\n             // all of these values in here are changed for local testing\n             options.InitializationDuration = TimeSpan.FromSeconds(5);\n             options.InitializationSynchronizationDelay = TimeSpan.FromSeconds(1);\n\n             options.KeyActivationDelay = TimeSpan.FromSeconds(10);\n             options.KeyExpiration = options.KeyActivationDelay * 2;\n             options.KeyRetirement = options.KeyActivationDelay * 3;\n\n             // You can get your own license from:\n             // https://www.identityserver8.com/products/KeyManagement\n             options.Licensee = \"your licensee\";\n             options.License = \"your license key\";\n         })\n         .PersistKeysToFileSystem(new DirectoryInfo(Path.Combine(Environment.ContentRootPath, \"signingkeys\")).FullName)\n         //.PersistKeysToDatabase(new DatabaseKeyManagementOptions {\n         //    ConfigureDbContext = b => b.UseSqlServer(cn),\n         //})\n         .ProtectKeysWithDataProtection()\n     //.EnableInMemoryCaching() // caching disabled unless explicitly enabled\n     ;\nvar app = builder.Build();\n\nif (Environment.IsDevelopment())\n{\n    app.UseDeveloperExceptionPage();\n}\n\napp.UseIdentityServer();\n\nawait app.RunAsync();\n\n\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/EF/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:5000\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"host\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"launchUrl\": \"http://localhost:5000/.well-known/openid-configuration/jwks\",\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"http://localhost:5000\"\n    }\n  }\n}"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/EF/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n\npublic class Startup\n{\n    public IConfiguration Configuration { get; }\n    public IWebHostEnvironment Environment { get; }\n    public ILoggerFactory LoggerFactory { get; set; }\n\n    public Startup(IConfiguration config, IWebHostEnvironment environment, ILoggerFactory loggerFactory)\n    {\n        Configuration = config;\n        Environment = environment;\n        LoggerFactory = loggerFactory;\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        //var name = \"CN=test.dataprotection\";\n        //var cert = X509.LocalMachine.My.SubjectDistinguishedName.Find(name, false).FirstOrDefault();\n\n        var cn = Configuration.GetConnectionString(\"db\");\n\n        services.AddDataProtection()\n            .PersistKeysToFileSystem(new DirectoryInfo(Path.Combine(Environment.ContentRootPath, \"dataprotectionkeys\")));\n        //.PersistKeysToDatabase(new DatabaseKeyManagementOptions\n        //{\n        //    ConfigureDbContext = b => b.UseSqlServer(cn),\n        //    LoggerFactory = LoggerFactory,\n        //});\n        //.ProtectKeysWithCertificate(cert);\n\n        var builder = services.AddIdentityServer()\n            .AddInMemoryIdentityResources(Config.GetIdentityResources())\n            .AddInMemoryApiResources(Config.GetApis())\n            .AddInMemoryClients(Config.GetClients())\n            .AddSigningKeyManagement(\n                options => // configuring options is optional :)\n                {\n                    options.DeleteRetiredKeys = true;\n                    options.KeyType = IdentityServer4.KeyManagement.KeyType.RSA;\n\n                    // all of these values in here are changed for local testing\n                    options.InitializationDuration = TimeSpan.FromSeconds(5);\n                    options.InitializationSynchronizationDelay = TimeSpan.FromSeconds(1);\n\n                    options.KeyActivationDelay = TimeSpan.FromSeconds(10);\n                    options.KeyExpiration = options.KeyActivationDelay * 2;\n                    options.KeyRetirement = options.KeyActivationDelay * 3;\n\n                    // You can get your own license from:\n                    // https://www.identityserver8.com/products/KeyManagement\n                    options.Licensee = \"your licensee\";\n                    options.License = \"your license key\";\n                })\n                .PersistKeysToFileSystem(new DirectoryInfo(Path.Combine(Environment.ContentRootPath, \"signingkeys\")).FullName)\n                //.PersistKeysToDatabase(new DatabaseKeyManagementOptions {\n                //    ConfigureDbContext = b => b.UseSqlServer(cn),\n                //})\n                .ProtectKeysWithDataProtection()\n            //.EnableInMemoryCaching() // caching disabled unless explicitly enabled\n            ;\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n        if (Environment.IsDevelopment())\n        {\n            app.UseDeveloperExceptionPage();\n        }\n\n        app.UseIdentityServer();\n    }\n}\n\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/EF/appsettings.json",
    "content": "{\n  \"ConnectionStrings\": {\n    \"db\": \"server=(localdb)\\\\mssqllocaldb;database=IdentityServer8.KeyManagement;trusted_connection=yes;\"\n  }\n}"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/migrations/Migrations/KeyManagement/20200327143521_KeyManagement.Designer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\n\nusing Microsoft.EntityFrameworkCore;\nusing Microsoft.EntityFrameworkCore.Metadata;\nusing Microsoft.EntityFrameworkCore.Migrations;\n\n//[DbContext(typeof(KeyManagementDbContext))]\n[Migration(\"20200327143521_KeyManagement\")]\npartial class KeyManagement\n{\n    protected override void BuildTargetModel(ModelBuilder modelBuilder)\n    {\n#pragma warning disable 612, 618\n        modelBuilder\n            .HasAnnotation(\"ProductVersion\", \"3.1.3\")\n            .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n            .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n        modelBuilder.Entity(\"IdentityServer8.KeyManagement.EntityFramework.DataProtectionKey\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<DateTime>(\"Created\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Name\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"Name\")\n                    .IsUnique()\n                    .HasFilter(\"[Name] IS NOT NULL\");\n\n                b.ToTable(\"DataProtectionKeys\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.KeyManagement.EntityFramework.SigningKey\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<DateTime>(\"Created\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Name\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"Name\")\n                    .IsUnique()\n                    .HasFilter(\"[Name] IS NOT NULL\");\n\n                b.ToTable(\"SigningKeys\");\n            });\n#pragma warning restore 612, 618\n    }\n}\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/migrations/Migrations/KeyManagement/20200327143521_KeyManagement.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic partial class KeyManagement : Migration\n{\n    protected override void Up(MigrationBuilder migrationBuilder)\n    {\n        migrationBuilder.CreateTable(\n            name: \"DataProtectionKeys\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Created = table.Column<DateTime>(nullable: false),\n                Name = table.Column<string>(maxLength: 200, nullable: true),\n                Value = table.Column<string>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_DataProtectionKeys\", x => x.Id);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"SigningKeys\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Created = table.Column<DateTime>(nullable: false),\n                Name = table.Column<string>(maxLength: 200, nullable: true),\n                Value = table.Column<string>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_SigningKeys\", x => x.Id);\n            });\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_DataProtectionKeys_Name\",\n            table: \"DataProtectionKeys\",\n            column: \"Name\",\n            unique: true,\n            filter: \"[Name] IS NOT NULL\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_SigningKeys_Name\",\n            table: \"SigningKeys\",\n            column: \"Name\",\n            unique: true,\n            filter: \"[Name] IS NOT NULL\");\n    }\n\n    protected override void Down(MigrationBuilder migrationBuilder)\n    {\n        migrationBuilder.DropTable(\n            name: \"DataProtectionKeys\");\n\n        migrationBuilder.DropTable(\n            name: \"SigningKeys\");\n    }\n}\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/migrations/Migrations/KeyManagement/KeyManagementDbContextModelSnapshot.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\n\n// [DbContext(typeof(KeyManagementDbContext))]\npartial class KeyManagementDbContextModelSnapshot : ModelSnapshot\n{\n    protected override void BuildModel(ModelBuilder modelBuilder)\n    {\n#pragma warning disable 612, 618\n        modelBuilder\n            .HasAnnotation(\"ProductVersion\", \"3.1.3\")\n            .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n            .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n        modelBuilder.Entity(\"IdentityServer8.KeyManagement.EntityFramework.DataProtectionKey\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<DateTime>(\"Created\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Name\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"Name\")\n                    .IsUnique()\n                    .HasFilter(\"[Name] IS NOT NULL\");\n\n                b.ToTable(\"DataProtectionKeys\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.KeyManagement.EntityFramework.SigningKey\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<DateTime>(\"Created\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Name\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"Name\")\n                    .IsUnique()\n                    .HasFilter(\"[Name] IS NOT NULL\");\n\n                b.ToTable(\"SigningKeys\");\n            });\n#pragma warning restore 612, 618\n    }\n}\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/migrations/Migrations/KeyManagement.sql",
    "content": "﻿IF OBJECT_ID(N'[__EFMigrationsHistory]') IS NULL\nBEGIN\n    CREATE TABLE [__EFMigrationsHistory] (\n        [MigrationId] nvarchar(150) NOT NULL,\n        [ProductVersion] nvarchar(32) NOT NULL,\n        CONSTRAINT [PK___EFMigrationsHistory] PRIMARY KEY ([MigrationId])\n    );\nEND;\n\nGO\n\nCREATE TABLE [DataProtectionKeys] (\n    [Id] int NOT NULL IDENTITY,\n    [Created] datetime2 NOT NULL,\n    [Name] nvarchar(200) NULL,\n    [Value] nvarchar(max) NOT NULL,\n    CONSTRAINT [PK_DataProtectionKeys] PRIMARY KEY ([Id])\n);\n\nGO\n\nCREATE TABLE [SigningKeys] (\n    [Id] int NOT NULL IDENTITY,\n    [Created] datetime2 NOT NULL,\n    [Name] nvarchar(200) NULL,\n    [Value] nvarchar(max) NOT NULL,\n    CONSTRAINT [PK_SigningKeys] PRIMARY KEY ([Id])\n);\n\nGO\n\nCREATE UNIQUE INDEX [IX_DataProtectionKeys_Name] ON [DataProtectionKeys] ([Name]) WHERE [Name] IS NOT NULL;\n\nGO\n\nCREATE UNIQUE INDEX [IX_SigningKeys_Name] ON [SigningKeys] ([Name]) WHERE [Name] IS NOT NULL;\n\nGO\n\nINSERT INTO [__EFMigrationsHistory] ([MigrationId], [ProductVersion])\nVALUES (N'20200327143521_KeyManagement', N'3.1.3');\n\nGO\n\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/migrations/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nIWebHostBuilder CreateWebHostBuilder(string[] args) =>\n    WebHost.CreateDefaultBuilder(args)\n        .UseStartup<Startup>();\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/migrations/Properties/launchSettings.json",
    "content": "﻿{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false, \n    \"anonymousAuthentication\": true, \n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:60249\",\n      \"sslPort\": 44348\n    }\n  },\n  \"profiles\": {\n    \"IIS Express\": {\n      \"commandName\": \"IISExpress\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      }\n    },\n    \"migrations\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"applicationUrl\": \"https://localhost:5001;http://localhost:5000\",\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      }\n    }\n  }\n}"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/migrations/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class Startup\n{\n    public IConfiguration Configuration { get; }\n\n    public Startup(IConfiguration config)\n    {\n        Configuration = config;\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        var cn = Configuration.GetConnectionString(\"db\");\n\n        //services.AddKeyManagementDbContext(new DatabaseKeyManagementOptions {\n        //    ConfigureDbContext = b =>\n        //         b.UseSqlServer(cn, dbOpts => dbOpts.MigrationsAssembly(typeof(Startup).Assembly.FullName))\n        //});\n    }\n\n    public void Configure(IApplicationBuilder app, IHostingEnvironment env)\n    {\n    }\n}\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/migrations/appsettings.json",
    "content": "{\n  \"ConnectionStrings\": {\n    \"db\": \"server=(localdb)\\\\mssqllocaldb;database=IdentityServer8.KeyManagement;trusted_connection=yes;\"\n  }\n}"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/migrations/builddb.bat",
    "content": "dotnet ef database drop -c KeyManagementDbContext\n\nrmdir /S /Q Migrations\n\ndotnet ef migrations add KeyManagement -c KeyManagementDbContext -o Migrations/KeyManagement\ndotnet ef migrations script -c KeyManagementDbContext -o Migrations/KeyManagement.sql\ndotnet ef database update -c KeyManagementDbContext\n"
  },
  {
    "path": "samples/KeyManagement/FileSystemKeys/database/migrations/migrations.csproj",
    "content": "﻿<Project Sdk=\"Microsoft.NET.Sdk.Web\" />\n"
  },
  {
    "path": "samples/KeyManagement/KeyManagementGlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityServer4.Models;\nglobal using Microsoft.AspNetCore;\nglobal using IHostingEnvironment = Microsoft.Extensions.Hosting.IHostingEnvironment;\nglobal using Microsoft.EntityFrameworkCore.Migrations;\nglobal using Microsoft.EntityFrameworkCore;\nglobal using Microsoft.EntityFrameworkCore.Infrastructure;\nglobal using Microsoft.EntityFrameworkCore.Metadata;\n"
  },
  {
    "path": "samples/Quickstarts/1_ClientCredentials/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "samples/Quickstarts/1_ClientCredentials/Quickstart.sln",
    "content": "﻿\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 15.0.26124.0\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{BD8BA25C-A91D-419D-99B6-B575ADD6D061}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer\", \"src\\IdentityServer\\IdentityServer.csproj\", \"{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Api\", \"..\\Shared\\src\\Api\\Api.csproj\", \"{085FFBFE-436E-4622-A4E0-4828CC357F9B}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Client\", \"..\\Shared\\src\\Client\\Client.csproj\", \"{E6DBD7EC-D769-4226-A58C-17121F6E144B}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tDebug|x64 = Debug|x64\n\t\tDebug|x86 = Debug|x86\n\t\tRelease|Any CPU = Release|Any CPU\n\t\tRelease|x64 = Release|x64\n\t\tRelease|x86 = Release|x86\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x64.Build.0 = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x86.Build.0 = Release|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Release|x64.Build.0 = Release|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{085FFBFE-436E-4622-A4E0-4828CC357F9B}.Release|x86.Build.0 = Release|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Release|x64.Build.0 = Release|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{E6DBD7EC-D769-4226-A58C-17121F6E144B}.Release|x86.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {84D5AF06-1243-46F1-9D58-70ED572832C3}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "samples/Quickstarts/1_ClientCredentials/Quickstart.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft\n Written by Alexander Higgins https://github.com/alexhiggins732/ \n \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code for this software can be found at https://github.com/alexhiggins732/IdentityServer8\n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n\n*/\n"
  },
  {
    "path": "samples/Quickstarts/1_ClientCredentials/src/IdentityServer/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityServer8.Models;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\n"
  },
  {
    "path": "samples/Quickstarts/1_ClientCredentials/src/IdentityServer/IdentityServer.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"HigginsSoft.IdentityServer8\" />\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n</Project>\n"
  },
  {
    "path": "samples/Quickstarts/1_ClientCredentials/src/IdentityServer/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Secret = IdentityServer8.Models.Secret;\n\nConfigureLogger();\n\ntry\n{\n    Log.Information(\"Starting host...\");\n\n    var builder = WebApplication.CreateBuilder(args);\n\n    var services = builder.Services;\n\n    // uncomment, if you want to add an MVC-based UI\n    //services.AddControllersWithViews();\n\n    services\n        .AddIdentityServer()\n        .AddInMemoryApiScopes(new ApiScope[] { new(\"api1\", \"My API\") })\n        .AddDeveloperSigningCredential()\n        .AddInMemoryClients(new Client[] { new()\n            {\n                    ClientId = \"client\",\n\n                    // no interactive user, use the clientid/secret for authentication\n                    AllowedGrantTypes = GrantTypes.ClientCredentials,\n\n                    // secret for authentication\n                    ClientSecrets = new Secret[] {new (\"secret\".Sha256()) },\n\n                    // scopes that client has access to\n                    AllowedScopes = { \"api1\" }\n            }\n        });\n\n\n    using (var app = builder.Build())\n    {\n        if (app.Environment.IsDevelopment())\n            app.UseDeveloperExceptionPage();\n\n        // uncomment if you want to add MVC\n        //app.UseStaticFiles();\n        //app.UseRouting();\n\n        app.UseIdentityServer();\n\n        // uncomment, if you want to add MVC-based\n        //app.UseAuthorization();\n        //app.UseEndpoints(endpoints =>\n        //{\n        //    endpoints.MapDefaultControllerRoute();\n        //});\n\n        await app.RunAsync();\n    }\n\n    return 0;\n}\ncatch (Exception ex)\n{\n    Log.Fatal(ex, \"Host terminated unexpectedly.\");\n    return 1;\n}\nfinally\n{\n    Log.CloseAndFlush();\n}\n\n\nvoid ConfigureLogger() => Log.Logger = new LoggerConfiguration()\n    .MinimumLevel.Debug()\n    .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n    .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n    .Enrich.FromLogContext()\n    // uncomment to write to Azure diagnostics stream\n    //.WriteTo.File(\n    //    @\"D:\\home\\LogFiles\\Application\\identityserver.txt\",\n    //    fileSizeLimitBytes: 1_000_000,\n    //    rollOnFileSizeLimit: true,\n    //    shared: true,\n    //    flushToDiskInterval: TimeSpan.FromSeconds(1))\n    .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n    .CreateLogger();\n"
  },
  {
    "path": "samples/Quickstarts/1_ClientCredentials/src/IdentityServer/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"SelfHost\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/1_ClientCredentials/src/IdentityServer/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/Quickstart.sln",
    "content": "﻿\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 15.0.26124.0\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{BD8BA25C-A91D-419D-99B6-B575ADD6D061}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer\", \"src\\IdentityServer\\IdentityServer.csproj\", \"{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcClient\", \"src\\MvcClient\\MvcClient.csproj\", \"{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Api\", \"..\\Shared\\src\\Api\\Api.csproj\", \"{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Client\", \"..\\Shared\\src\\Client\\Client.csproj\", \"{225A262C-3B2D-4064-9C6C-5A3136046237}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tDebug|x64 = Debug|x64\n\t\tDebug|x86 = Debug|x86\n\t\tRelease|Any CPU = Release|Any CPU\n\t\tRelease|x64 = Release|x64\n\t\tRelease|x86 = Release|x86\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x64.Build.0 = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x86.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x64.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x86.Build.0 = Release|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Release|x64.Build.0 = Release|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{6E3FD384-F4EA-420B-A0F4-E9BF08127F68}.Release|x86.Build.0 = Release|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Release|x64.Build.0 = Release|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{225A262C-3B2D-4064-9C6C-5A3136046237}.Release|x86.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {84D5AF06-1243-46F1-9D58-70ED572832C3}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/Quickstart.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft\n Written by Alexander Higgins https://github.com/alexhiggins732/ \n \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code for this software can be found at https://github.com/alexhiggins732/IdentityServer8\n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n\n*/\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Config.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Secret = IdentityServer8.Models.Secret;\n\npublic static class Config\n{\n    public static IEnumerable<IdentityResource> IdentityResources =>\n        new List<IdentityResource>\n        {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n        };\n\n\n    public static IEnumerable<ApiScope> ApiScopes =>\n        new List<ApiScope>\n        {\n            new ApiScope(\"api1\", \"My API\")\n        };\n\n    public static IEnumerable<Client> Clients =>\n        new List<Client>\n        {\n            // machine to machine client\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                // scopes that client has access to\n                AllowedScopes = { \"api1\" }\n            },\n            \n            // interactive ASP.NET Core MVC client\n            new Client\n            {\n                ClientId = \"mvc\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.Code,\n                \n                // where to redirect to after login\n                RedirectUris = { \"https://localhost:5002/signin-oidc\" },\n\n                // where to redirect to after logout\n                PostLogoutRedirectUris = { \"https://localhost:5002/signout-callback-oidc\" },\n\n                AllowedScopes = new List<string>\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    \"api1\"\n                }\n            }\n        };\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.Configuration;\nglobal using IdentityServer8.Events;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Test;\nglobal using IdentityServer8.Validation;\nglobal using IdentityServerHost.Quickstart.UI;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Hosting;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.AspNetCore.Mvc.Filters;\nglobal using Microsoft.Extensions.Hosting;\nglobal using Microsoft.Extensions.Options;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\nglobal using System;\nglobal using System.ComponentModel.DataAnnotations;\nglobal using System.Security.Claims;\nglobal using System.Text;\nglobal using System.Text.Json;\nglobal using static IdentityModel.JwtClaimTypes;\nglobal using IdentityServerClaimValueTypes = IdentityServer8.IdentityServerConstants.ClaimValueTypes;\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/IdentityServer.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"HigginsSoft.IdentityServer8\" />\n    <PackageReference Include=\"HigginsSoft.IdentityServer8.Security\" />\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.Google\" />\n  </ItemGroup>\n</Project>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConfigureLogger();\n\ntry\n{\n    Log.Information(\"Starting host...\");\n\n    var builder = WebApplication.CreateBuilder(args);\n\n    var services = builder.Services;\n\n    services.AddControllersWithViews();\n\n    services\n        .AddIdentityServer()\n        .AddInMemoryIdentityResources(Config.IdentityResources)\n        .AddInMemoryApiScopes(Config.ApiScopes)\n        .AddInMemoryClients(Config.Clients)\n        .AddTestUsers(TestUsers.Users)\n        .AddDeveloperSigningCredential();\n\n    services.AddAuthentication()\n        .AddGoogle(\"Google\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n            options.ClientId = \"<insert here>\";\n            options.ClientSecret = \"<insert here>\";\n        })\n        .AddOpenIdConnect(\"oidc\", \"Demo IdentityServer\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n            options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n            options.SaveTokens = true;\n\n            options.Authority = \"https://demo.identityserver8.io/\";\n            options.ClientId = \"interactive.confidential\";\n            options.ClientSecret = \"secret\";\n            options.ResponseType = \"code\";\n\n            options.TokenValidationParameters = new()\n            {\n                NameClaimType = \"name\",\n                RoleClaimType = \"role\"\n            };\n        });\n\n\n    using (var app = builder.Build())\n    {\n        if (app.Environment.IsDevelopment())\n            app.UseDeveloperExceptionPage();\n\n        app.UseStaticFiles()\n            .UseRouting()\n            .UseIdentityServer()\n            .UseAuthorization();\n\n        app.MapDefaultControllerRoute();\n\n        await app.RunAsync();\n    }\n\n    return 0;\n}\ncatch (Exception ex)\n{\n    Log.Fatal(ex, \"Host terminated unexpectedly.\");\n    return 1;\n}\nfinally\n{\n    Log.CloseAndFlush();\n}\n\n\nvoid ConfigureLogger() => Log.Logger = new LoggerConfiguration()\n    .MinimumLevel.Debug()\n    .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n    .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n    .Enrich.FromLogContext()\n    // uncomment to write to Azure diagnostics stream\n    //.WriteTo.File(\n    //    @\"D:\\home\\LogFiles\\Application\\identityserver.txt\",\n    //    fileSizeLimitBytes: 1_000_000,\n    //    rollOnFileSizeLimit: true,\n    //    shared: true,\n    //    flushToDiskInterval: TimeSpan.FromSeconds(1))\n    .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n    .CreateLogger();\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"SelfHost\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Account/AccountController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller implements a typical login/logout/provision workflow for local and external accounts.\n/// The login service encapsulates the interactions with the user data store. This data store is in-memory only and cannot be used for production!\n/// The interaction service provides a way for the UI to communicate with identityserver for validation and context retrieval\n/// </summary>\n[SecurityHeaders]\n[AllowAnonymous]\npublic class AccountController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly IAuthenticationSchemeProvider _schemeProvider;\n    private readonly IEventService _events;\n\n    public AccountController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IAuthenticationSchemeProvider schemeProvider,\n        IEventService events,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _schemeProvider = schemeProvider;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Entry point into the login workflow\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Login(string returnUrl)\n    {\n        // build a model so we know what to show on the login page\n        var vm = await BuildLoginViewModelAsync(returnUrl);\n\n        if (vm.IsExternalLoginOnly)\n        {\n            // we only have one option for logging in and it's an external provider\n            return returnUrl.IsAllowedRedirect() ? RedirectToAction(\"Challenge\", \"External\", new { scheme = vm.ExternalLoginScheme, returnUrl = returnUrl.SanitizeForRedirect() }) : Forbid();\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Login(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (ModelState.IsValid)\n        {\n            // validate username/password against in-memory store\n            if (_users.ValidateCredentials(model.Username, model.Password))\n            {\n                var user = _users.FindByUsername(model.Username);\n                await _events.RaiseAsync(new UserLoginSuccessEvent(user.Username, user.SubjectId, user.Username, clientId: context?.Client.ClientId));\n\n                // only set explicit expiration here if user chooses \"remember me\". \n                // otherwise we rely upon expiration configured in cookie middleware.\n                AuthenticationProperties props = null;\n                if (AccountOptions.AllowRememberLogin && model.RememberLogin)\n                {\n                    props = new AuthenticationProperties\n                    {\n                        IsPersistent = true,\n                        ExpiresUtc = DateTimeOffset.UtcNow.Add(AccountOptions.RememberMeLoginDuration)\n                    };\n                };\n\n                // issue authentication cookie with subject ID and username\n                var isuser = new IdentityServerUser(user.SubjectId)\n                {\n                    DisplayName = user.Username\n                };\n\n                await HttpContext.SignInAsync(isuser, props);\n\n                if (context != null)\n                {\n                    if (context.IsNativeClient())\n                    {\n                        // The client is native, so this change in how to\n                        // return the response is for better UX for the end user.\n                        return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                    }\n\n                    // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n\n                // request for a local page\n                if (Url.IsLocalUrl(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n                else if (string.IsNullOrEmpty(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n                }\n                else\n                {\n                    // user might have clicked on a malicious link - should be logged\n                    throw new Exception(\"invalid return URL\");\n                }\n            }\n\n            await _events.RaiseAsync(new UserLoginFailureEvent(model.Username, \"invalid credentials\", clientId: context?.Client.ClientId));\n            ModelState.AddModelError(string.Empty, AccountOptions.InvalidCredentialsErrorMessage);\n        }\n\n        // something went wrong, show form with error\n        var vm = await BuildLoginViewModelAsync(model);\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> LoginCancel(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (context != null)\n        {\n            // if the user cancels, send a result back into IdentityServer as if they \n            // denied the consent (even if this client does not require consent).\n            // this will send back an access denied OIDC error response to the client.\n            await _interaction.DenyAuthorizationAsync(context, AuthorizationError.AccessDenied);\n\n            // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n            }\n\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n        }\n        else\n        {\n            // since we don't have a valid context, then we just go back to the home page\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n        }\n\n    }\n\n    /// <summary>\n    /// Show logout page\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Logout(string logoutId)\n    {\n        // build a model so the logout page knows what to display\n        var vm = await BuildLogoutViewModelAsync(logoutId);\n\n        if (vm.ShowLogoutPrompt == false)\n        {\n            // if the request for logout was properly authenticated from IdentityServer, then\n            // we don't need to show the prompt and can just log the user out directly.\n            return await Logout(vm);\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle logout page postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Logout(LogoutInputModel model)\n    {\n        // build a model so the logged out page knows what to display\n        var vm = await BuildLoggedOutViewModelAsync(model.LogoutId);\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            // delete local authentication cookie\n            await HttpContext.SignOutAsync();\n\n            // raise the logout event\n            await _events.RaiseAsync(new UserLogoutSuccessEvent(User.GetSubjectId(), User.GetDisplayName()));\n        }\n\n        // check if we need to trigger sign-out at an upstream identity provider\n        if (vm.TriggerExternalSignout)\n        {\n            // build a return URL so the upstream provider will redirect back\n            // to us after the user has logged out. this allows us to then\n            // complete our single sign-out processing.\n            string url = Url.Action(\"Logout\", new { logoutId = vm.LogoutId });\n\n            // this triggers a redirect to the external provider for sign-out\n            return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);\n        }\n\n        return View(\"LoggedOut\", vm);\n    }\n\n    [HttpGet]\n    public IActionResult AccessDenied()\n    {\n        return View();\n    }\n\n\n    /*****************************************/\n    /* helper APIs for the AccountController */\n    /*****************************************/\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(string returnUrl)\n    {\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (context?.IdP != null && await _schemeProvider.GetSchemeAsync(context.IdP) != null)\n        {\n            var local = context.IdP == IdentityServer8.IdentityServerConstants.LocalIdentityProvider;\n\n            // this is meant to short circuit the UI and only trigger the one external IdP\n            var vm = new LoginViewModel\n            {\n                EnableLocalLogin = local,\n                ReturnUrl = returnUrl,\n                Username = context?.LoginHint,\n            };\n\n            if (!local)\n            {\n                vm.ExternalProviders = new[] { new ExternalProvider { AuthenticationScheme = context.IdP } };\n            }\n\n            return vm;\n        }\n\n        var schemes = await _schemeProvider.GetAllSchemesAsync();\n\n        var providers = schemes\n            .Where(x => x.DisplayName != null)\n            .Select(x => new ExternalProvider\n            {\n                DisplayName = x.DisplayName ?? x.Name,\n                AuthenticationScheme = x.Name\n            }).ToList();\n\n        var allowLocal = true;\n        if (context?.Client.ClientId != null)\n        {\n            var client = await _clientStore.FindEnabledClientByIdAsync(context.Client.ClientId);\n            if (client != null)\n            {\n                allowLocal = client.EnableLocalLogin;\n\n                if (client.IdentityProviderRestrictions != null && client.IdentityProviderRestrictions.Any())\n                {\n                    providers = providers.Where(provider => client.IdentityProviderRestrictions.Contains(provider.AuthenticationScheme)).ToList();\n                }\n            }\n        }\n\n        return new LoginViewModel\n        {\n            AllowRememberLogin = AccountOptions.AllowRememberLogin,\n            EnableLocalLogin = allowLocal && AccountOptions.AllowLocalLogin,\n            ReturnUrl = returnUrl,\n            Username = context?.LoginHint,\n            ExternalProviders = providers.ToArray()\n        };\n    }\n\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(LoginInputModel model)\n    {\n        var vm = await BuildLoginViewModelAsync(model.ReturnUrl);\n        vm.Username = model.Username;\n        vm.RememberLogin = model.RememberLogin;\n        return vm;\n    }\n\n    private async Task<LogoutViewModel> BuildLogoutViewModelAsync(string logoutId)\n    {\n        var vm = new LogoutViewModel { LogoutId = logoutId, ShowLogoutPrompt = AccountOptions.ShowLogoutPrompt };\n\n        if (User?.Identity.IsAuthenticated != true)\n        {\n            // if the user is not authenticated, then just show logged out page\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        var context = await _interaction.GetLogoutContextAsync(logoutId);\n        if (context?.ShowSignoutPrompt == false)\n        {\n            // it's safe to automatically sign-out\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        // show the logout prompt. this prevents attacks where the user\n        // is automatically signed out by another malicious web page.\n        return vm;\n    }\n\n    private async Task<LoggedOutViewModel> BuildLoggedOutViewModelAsync(string logoutId)\n    {\n        // get context information (client name, post logout redirect URI and iframe for federated signout)\n        var logout = await _interaction.GetLogoutContextAsync(logoutId);\n\n        var vm = new LoggedOutViewModel\n        {\n            AutomaticRedirectAfterSignOut = AccountOptions.AutomaticRedirectAfterSignOut,\n            PostLogoutRedirectUri = logout?.PostLogoutRedirectUri,\n            ClientName = string.IsNullOrEmpty(logout?.ClientName) ? logout?.ClientId : logout?.ClientName,\n            SignOutIframeUrl = logout?.SignOutIFrameUrl,\n            LogoutId = logoutId\n        };\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            var idp = User.FindFirst(JwtClaimTypes.IdentityProvider)?.Value;\n            if (idp != null && idp != IdentityServer8.IdentityServerConstants.LocalIdentityProvider)\n            {\n                var providerSupportsSignout = await HttpContext.GetSchemeSupportsSignOutAsync(idp);\n                if (providerSupportsSignout)\n                {\n                    if (vm.LogoutId == null)\n                    {\n                        // if there's no current logout context, we need to create one\n                        // this captures necessary info from the current logged in user\n                        // before we signout and redirect away to the external IdP for signout\n                        vm.LogoutId = await _interaction.CreateLogoutContextAsync();\n                    }\n\n                    vm.ExternalAuthenticationScheme = idp;\n                }\n            }\n        }\n\n        return vm;\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Account/AccountOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI\n{\n    public class AccountOptions\n    {\n        public static bool AllowLocalLogin = true;\n        public static bool AllowRememberLogin = true;\n        public static TimeSpan RememberMeLoginDuration = TimeSpan.FromDays(30);\n\n        public static bool ShowLogoutPrompt = true;\n        public static bool AutomaticRedirectAfterSignOut = false;\n\n        public static string InvalidCredentialsErrorMessage = \"Invalid username or password\";\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Account/ExternalController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class ExternalController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly ILogger<ExternalController> _logger;\n    private readonly IEventService _events;\n\n    public ExternalController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IEventService events,\n        ILogger<ExternalController> logger,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _logger = logger;\n        _events = events;\n    }\n\n    /// <summary>\n    /// initiate roundtrip to external authentication provider\n    /// </summary>\n    [HttpGet]\n    public IActionResult Challenge(string scheme, string returnUrl)\n    {\n        if (string.IsNullOrEmpty(returnUrl)) returnUrl = \"~/\";\n\n        // validate returnUrl - either it is a valid OIDC URL or back to a local page\n        if (Url.IsLocalUrl(returnUrl) == false && _interaction.IsValidReturnUrl(returnUrl) == false)\n        {\n            // user might have clicked on a malicious link - should be logged\n            throw new Exception(\"invalid return URL\");\n        }\n        \n        // start challenge and roundtrip the return URL and scheme \n        var props = new AuthenticationProperties\n        {\n            RedirectUri = Url.Action(nameof(Callback)), \n            Items =\n            {\n                { \"returnUrl\", returnUrl }, \n                { \"scheme\", scheme },\n            }\n        };\n\n        return Challenge(props, scheme);\n        \n    }\n\n    /// <summary>\n    /// Post processing of external authentication\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Callback()\n    {\n        // read external identity from the temporary cookie\n        var result = await HttpContext.AuthenticateAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n        if (result?.Succeeded != true)\n        {\n            throw new Exception(\"External authentication error\");\n        }\n\n        if (_logger.IsEnabled(LogLevel.Debug))\n        {\n            var externalClaims = result.Principal.Claims.Select(c => $\"{c.Type}: {c.Value}\");\n            _logger.LogDebug(\"External claims: {@claims}\", externalClaims);\n        }\n\n        // lookup our user and external provider info\n        var (user, provider, providerUserId, claims) = FindUserFromExternalProvider(result);\n        if (user == null)\n        {\n            // this might be where you might initiate a custom workflow for user registration\n            // in this sample we don't show how that would be done, as our sample implementation\n            // simply auto-provisions new external user\n            user = AutoProvisionUser(provider, providerUserId, claims);\n        }\n\n        // this allows us to collect any additional claims or properties\n        // for the specific protocols used and store them in the local auth cookie.\n        // this is typically used to store data needed for signout from those protocols.\n        var additionalLocalClaims = new List<Claim>();\n        var localSignInProps = new AuthenticationProperties();\n        ProcessLoginCallback(result, additionalLocalClaims, localSignInProps);\n        \n        // issue authentication cookie for user\n        var isuser = new IdentityServerUser(user.SubjectId)\n        {\n            DisplayName = user.Username,\n            IdentityProvider = provider,\n            AdditionalClaims = additionalLocalClaims\n        };\n\n        await HttpContext.SignInAsync(isuser, localSignInProps);\n\n        // delete temporary cookie used during external authentication\n        await HttpContext.SignOutAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n        // retrieve return URL\n        var returnUrl = result.Properties.Items[\"returnUrl\"] ?? \"~/\";\n\n        // check if external login is in the context of an OIDC request\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        await _events.RaiseAsync(new UserLoginSuccessEvent(provider, providerUserId, user.SubjectId, user.Username, true, context?.Client.ClientId));\n\n        if (context != null)\n        {\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", returnUrl);\n            }\n        }\n\n        return Redirect(returnUrl);\n    }\n\n    private (TestUser user, string provider, string providerUserId, IEnumerable<Claim> claims) FindUserFromExternalProvider(AuthenticateResult result)\n    {\n        var externalUser = result.Principal;\n\n        // try to determine the unique id of the external user (issued by the provider)\n        // the most common claim type for that are the sub claim and the NameIdentifier\n        // depending on the external provider, some other claim type might be used\n        var userIdClaim = externalUser.FindFirst(JwtClaimTypes.Subject) ??\n                          externalUser.FindFirst(ClaimTypes.NameIdentifier) ??\n                          throw new Exception(\"Unknown userid\");\n\n        // remove the user id claim so we don't include it as an extra claim if/when we provision the user\n        var claims = externalUser.Claims.ToList();\n        claims.Remove(userIdClaim);\n\n        var provider = result.Properties.Items[\"scheme\"];\n        var providerUserId = userIdClaim.Value;\n\n        // find external user\n        var user = _users.FindByExternalProvider(provider, providerUserId);\n\n        return (user, provider, providerUserId, claims);\n    }\n\n    private TestUser AutoProvisionUser(string provider, string providerUserId, IEnumerable<Claim> claims)\n    {\n        var user = _users.AutoProvisionUser(provider, providerUserId, claims.ToList());\n        return user;\n    }\n\n    // if the external login is OIDC-based, there are certain things we need to preserve to make logout work\n    // this will be different for WS-Fed, SAML2p or other protocols\n    private void ProcessLoginCallback(AuthenticateResult externalResult, List<Claim> localClaims, AuthenticationProperties localSignInProps)\n    {\n        // if the external system sent a session id claim, copy it over\n        // so we can use it for single sign-out\n        var sid = externalResult.Principal.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.SessionId);\n        if (sid != null)\n        {\n            localClaims.Add(new Claim(JwtClaimTypes.SessionId, sid.Value));\n        }\n\n        // if the external provider issued an id_token, we'll keep it for signout\n        var idToken = externalResult.Properties.GetTokenValue(\"id_token\");\n        if (idToken != null)\n        {\n            localSignInProps.StoreTokens(new[] { new AuthenticationToken { Name = \"id_token\", Value = idToken } });\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Account/ExternalProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ExternalProvider\n{\n    public string DisplayName { get; set; }\n    public string AuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Account/LoggedOutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoggedOutViewModel\n{\n    public string PostLogoutRedirectUri { get; set; }\n    public string ClientName { get; set; }\n    public string SignOutIframeUrl { get; set; }\n\n    public bool AutomaticRedirectAfterSignOut { get; set; }\n\n    public string LogoutId { get; set; }\n    public bool TriggerExternalSignout => ExternalAuthenticationScheme != null;\n    public string ExternalAuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Account/LoginInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginInputModel\n{\n    [Required]\n    public string Username { get; set; }\n    [Required]\n    public string Password { get; set; }\n    public bool RememberLogin { get; set; }\n    public string ReturnUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Account/LoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginViewModel : LoginInputModel\n{\n    public bool AllowRememberLogin { get; set; } = true;\n    public bool EnableLocalLogin { get; set; } = true;\n\n    public IEnumerable<ExternalProvider> ExternalProviders { get; set; } = Enumerable.Empty<ExternalProvider>();\n    public IEnumerable<ExternalProvider> VisibleExternalProviders => ExternalProviders.Where(x => !String.IsNullOrWhiteSpace(x.DisplayName));\n\n    public bool IsExternalLoginOnly => EnableLocalLogin == false && ExternalProviders?.Count() == 1;\n    public string ExternalLoginScheme => IsExternalLoginOnly ? ExternalProviders?.SingleOrDefault()?.AuthenticationScheme : null;\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Account/LogoutInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutInputModel\n{\n    public string LogoutId { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Account/LogoutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutViewModel : LogoutInputModel\n{\n    public bool ShowLogoutPrompt { get; set; } = true;\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Account/RedirectViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class RedirectViewModel\n{\n    public string RedirectUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Consent/ConsentController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This controller processes the consent UI\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class ConsentController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly ILogger<ConsentController> _logger;\n\n    public ConsentController(\n        IIdentityServerInteractionService interaction,\n        IEventService events,\n        ILogger<ConsentController> logger)\n    {\n        _interaction = interaction;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Shows the consent screen\n    /// </summary>\n    /// <param name=\"returnUrl\"></param>\n    /// <returns></returns>\n    [HttpGet]\n    public async Task<IActionResult> Index(string returnUrl)\n    {\n        var vm = await BuildViewModelAsync(returnUrl);\n        if (vm != null)\n        {\n            return View(\"Index\", vm);\n        }\n\n        return View(\"Error\");\n    }\n\n    /// <summary>\n    /// Handles the consent screen postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Index(ConsentInputModel model)\n    {\n        var result = await ProcessConsent(model);\n\n        if (result.IsRedirect)\n        {\n            var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n            if (context?.IsNativeClient() == true)\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", result.RedirectUri);\n            }\n            return result.RedirectUri.IsAllowedRedirect() ? Redirect(result.RedirectUri.SanitizeForRedirect()) : Forbid();\n        }\n\n        if (result.HasValidationError)\n        {\n            ModelState.AddModelError(string.Empty, result.ValidationError);\n        }\n\n        if (result.ShowView)\n        {\n            return View(\"Index\", result.ViewModel);\n        }\n\n        return View(\"Error\");\n    }\n\n    /*****************************************/\n    /* helper APIs for the ConsentController */\n    /*****************************************/\n    private async Task<ProcessConsentResult> ProcessConsent(ConsentInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        // validate return url is still valid\n        var request = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model?.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model?.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.GrantConsentAsync(request, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.ReturnUrl, model);\n        }\n\n        return result;\n    }\n\n    private async Task<ConsentViewModel> BuildViewModelAsync(string returnUrl, ConsentInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (request != null)\n        {\n            return CreateConsentViewModel(model, returnUrl, request);\n        }\n        else\n        {\n            _logger.LogError(\"No consent request matching request: {0}\", returnUrl.SanitizeForLog());\n        }\n\n        return null;\n    }\n\n    private ConsentViewModel CreateConsentViewModel(\n        ConsentInputModel model, string returnUrl,\n        AuthorizationRequest request)\n    {\n        var vm = new ConsentViewModel\n        {\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n            Description = model?.Description,\n\n            ReturnUrl = returnUrl,\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach(var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        var displayName = apiScope.DisplayName ?? apiScope.Name;\n        if (!String.IsNullOrWhiteSpace(parsedScopeValue.ParsedParameter))\n        {\n            displayName += \":\" + parsedScopeValue.ParsedParameter;\n        }\n\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            DisplayName = displayName,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Consent/ConsentInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentInputModel\n{\n    public string Button { get; set; }\n    public IEnumerable<string> ScopesConsented { get; set; }\n    public bool RememberConsent { get; set; }\n    public string ReturnUrl { get; set; }\n    public string Description { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Consent/ConsentOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentOptions\n{\n    public static bool EnableOfflineAccess = true;\n    public static string OfflineAccessDisplayName = \"Offline Access\";\n    public static string OfflineAccessDescription = \"Access to your applications and resources, even when you are offline\";\n\n    public static readonly string MustChooseOneErrorMessage = \"You must pick at least one permission\";\n    public static readonly string InvalidSelectionErrorMessage = \"Invalid selection\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Consent/ConsentViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentViewModel : ConsentInputModel\n{\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public bool AllowRememberConsent { get; set; }\n\n    public IEnumerable<ScopeViewModel> IdentityScopes { get; set; }\n    public IEnumerable<ScopeViewModel> ApiScopes { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Consent/ProcessConsentResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ProcessConsentResult\n{\n    public bool IsRedirect => RedirectUri != null;\n    public string RedirectUri { get; set; }\n    public Client Client { get; set; }\n\n    public bool ShowView => ViewModel != null;\n    public ConsentViewModel ViewModel { get; set; }\n\n    public bool HasValidationError => ValidationError != null;\n    public string ValidationError { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Consent/ScopeViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ScopeViewModel\n{\n    public string Value { get; set; }\n    public string DisplayName { get; set; }\n    public string Description { get; set; }\n    public bool Emphasize { get; set; }\n    public bool Required { get; set; }\n    public bool Checked { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Device/DeviceAuthorizationInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationInputModel : ConsentInputModel\n{\n    public string UserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Device/DeviceAuthorizationViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationViewModel : ConsentViewModel\n{\n    public string UserCode { get; set; }\n    public bool ConfirmUserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Device/DeviceController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[Authorize]\n[SecurityHeaders]\npublic class DeviceController : Controller\n{\n    private readonly IDeviceFlowInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly IOptions<IdentityServerOptions> _options;\n    private readonly ILogger<DeviceController> _logger;\n\n    public DeviceController(\n        IDeviceFlowInteractionService interaction,\n        IEventService eventService,\n        IOptions<IdentityServerOptions> options,\n        ILogger<DeviceController> logger)\n    {\n        _interaction = interaction;\n        _events = eventService;\n        _options = options;\n        _logger = logger;\n    }\n\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        string userCodeParamName = _options.Value.UserInteraction.DeviceVerificationUserCodeParameter;\n        string userCode = Request.Query[userCodeParamName];\n        if (string.IsNullOrWhiteSpace(userCode)) return View(\"UserCodeCapture\");\n\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        vm.ConfirmUserCode = true;\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> UserCodeCapture(string userCode)\n    {\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Callback(DeviceAuthorizationInputModel model)\n    {\n        if (model == null) throw new ArgumentNullException(nameof(model));\n\n        var result = await ProcessConsent(model);\n        if (result.HasValidationError) return View(\"Error\");\n\n        return View(\"Success\");\n    }\n\n    private async Task<ProcessConsentResult> ProcessConsent(DeviceAuthorizationInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        var request = await _interaction.GetAuthorizationContextAsync(model.UserCode);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.HandleRequestAsync(model.UserCode, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.UserCode, model);\n        }\n\n        return result;\n    }\n\n    private async Task<DeviceAuthorizationViewModel> BuildViewModelAsync(string userCode, DeviceAuthorizationInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(userCode);\n        if (request != null)\n        {\n            return CreateConsentViewModel(userCode, model, request);\n        }\n\n        return null;\n    }\n\n    private DeviceAuthorizationViewModel CreateConsentViewModel(string userCode, DeviceAuthorizationInputModel model, DeviceFlowAuthorizationRequest request)\n    {\n        var vm = new DeviceAuthorizationViewModel\n        {\n            UserCode = userCode,\n            Description = model?.Description,\n\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach (var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            // todo: use the parsed scope value in the display?\n            DisplayName = apiScope.DisplayName ?? apiScope.Name,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Diagnostics/DiagnosticsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[Authorize]\npublic class DiagnosticsController : Controller\n{\n    public async Task<IActionResult> Index()\n    {\n        var localAddresses = new string[] { \"127.0.0.1\", \"::1\", HttpContext.Connection.LocalIpAddress.ToString() };\n        if (!localAddresses.Contains(HttpContext.Connection.RemoteIpAddress.ToString()))\n        {\n            return NotFound();\n        }\n\n        var model = new DiagnosticsViewModel(await HttpContext.AuthenticateAsync());\n        return View(model);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Diagnostics/DiagnosticsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DiagnosticsViewModel\n{\n    public DiagnosticsViewModel(AuthenticateResult result)\n    {\n        AuthenticateResult = result;\n\n        if (result.Properties.Items.ContainsKey(\"client_list\"))\n        {\n            var encoded = result.Properties.Items[\"client_list\"];\n            var bytes = Base64Url.Decode(encoded);\n            var value = Encoding.UTF8.GetString(bytes);\n\n            Clients = JsonSerializer.Deserialize<string[]>(value);\n        }\n    }\n\n    public AuthenticateResult AuthenticateResult { get; }\n    public IEnumerable<string> Clients { get; } = new List<string>();\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Extensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic static class Extensions\n{\n    /// <summary>\n    /// Checks if the redirect URI is for a native client.\n    /// </summary>\n    /// <returns></returns>\n    public static bool IsNativeClient(this AuthorizationRequest context)\n    {\n        return !context.RedirectUri.StartsWith(\"https\", StringComparison.Ordinal)\n           && !context.RedirectUri.StartsWith(\"http\", StringComparison.Ordinal);\n    }\n\n    public static IActionResult LoadingPage(this Controller controller, string viewName, string redirectUri)\n    {\n        controller.HttpContext.Response.StatusCode = 200;\n        controller.HttpContext.Response.Headers[\"Location\"] = \"\";\n        \n        return controller.View(viewName, new RedirectViewModel { RedirectUrl = redirectUri });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Grants/GrantsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller allows a user to revoke grants given to clients\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class GrantsController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clients;\n    private readonly IResourceStore _resources;\n    private readonly IEventService _events;\n\n    public GrantsController(IIdentityServerInteractionService interaction,\n        IClientStore clients,\n        IResourceStore resources,\n        IEventService events)\n    {\n        _interaction = interaction;\n        _clients = clients;\n        _resources = resources;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Show list of grants\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        return View(\"Index\", await BuildViewModelAsync());\n    }\n\n    /// <summary>\n    /// Handle postback to revoke a client\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Revoke(string clientId)\n    {\n        await _interaction.RevokeUserConsentAsync(clientId);\n        await _events.RaiseAsync(new GrantsRevokedEvent(User.GetSubjectId(), clientId));\n\n        return RedirectToAction(\"Index\");\n    }\n\n    private async Task<GrantsViewModel> BuildViewModelAsync()\n    {\n        var grants = await _interaction.GetAllUserGrantsAsync();\n\n        var list = new List<GrantViewModel>();\n        foreach(var grant in grants)\n        {\n            var client = await _clients.FindClientByIdAsync(grant.ClientId);\n            if (client != null)\n            {\n                var resources = await _resources.FindResourcesByScopeAsync(grant.Scopes);\n\n                var item = new GrantViewModel()\n                {\n                    ClientId = client.ClientId,\n                    ClientName = client.ClientName ?? client.ClientId,\n                    ClientLogoUrl = client.LogoUri,\n                    ClientUrl = client.ClientUri,\n                    Description = grant.Description,\n                    Created = grant.CreationTime,\n                    Expires = grant.Expiration,\n                    IdentityGrantNames = resources.IdentityResources.Select(x => x.DisplayName ?? x.Name).ToArray(),\n                    ApiGrantNames = resources.ApiScopes.Select(x => x.DisplayName ?? x.Name).ToArray()\n                };\n\n                list.Add(item);\n            }\n        }\n\n        return new GrantsViewModel\n        {\n            Grants = list\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Grants/GrantsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class GrantsViewModel\n{\n    public IEnumerable<GrantViewModel> Grants { get; set; }\n}\n\npublic class GrantViewModel\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public string Description { get; set; }\n    public DateTime Created { get; set; }\n    public DateTime? Expires { get; set; }\n    public IEnumerable<string> IdentityGrantNames { get; set; }\n    public IEnumerable<string> ApiGrantNames { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Home/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ErrorViewModel\n{\n    public ErrorViewModel()\n    {\n    }\n\n    public ErrorViewModel(string error)\n    {\n        Error = new ErrorMessage { Error = error };\n    }\n\n    public ErrorMessage Error { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/Home/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class HomeController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IWebHostEnvironment _environment;\n    private readonly ILogger _logger;\n\n    public HomeController(IIdentityServerInteractionService interaction, IWebHostEnvironment environment, ILogger<HomeController> logger)\n    {\n        _interaction = interaction;\n        _environment = environment;\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        if (_environment.IsDevelopment())\n        {\n            // only show in development\n            return View();\n        }\n\n        _logger.LogInformation(\"Homepage is disabled in production. Returning 404.\");\n        return NotFound();\n    }\n\n    /// <summary>\n    /// Shows the error page\n    /// </summary>\n    public async Task<IActionResult> Error(string errorId)\n    {\n        var vm = new ErrorViewModel();\n\n        // retrieve error details from identityserver\n        var message = await _interaction.GetErrorContextAsync(errorId);\n        if (message != null)\n        {\n            vm.Error = message;\n\n            if (!_environment.IsDevelopment())\n            {\n                // only show in development\n                message.ErrorDescription = null;\n            }\n        }\n\n        return View(\"Error\", vm);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/SecurityHeadersAttribute.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class SecurityHeadersAttribute : ActionFilterAttribute\n{\n    public override void OnResultExecuting(ResultExecutingContext context)\n    {\n        var result = context.Result;\n        if (result is ViewResult)\n        {\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Type-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Type-Options\", \"nosniff\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Frame-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Frame-Options\", \"SAMEORIGIN\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy\n            var csp = \"default-src 'self'; object-src 'none'; frame-ancestors 'none'; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self';\";\n            // also consider adding upgrade-insecure-requests once you have HTTPS in place for production\n            //csp += \"upgrade-insecure-requests;\";\n            // also an example if you need client images to be displayed from twitter\n            // csp += \"img-src 'self' https://pbs.twimg.com;\";\n\n            // once for standards compliant browsers\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Content-Security-Policy\", csp);\n            }\n            // and once again for IE\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Security-Policy\", csp);\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy\n            var referrer_policy = \"no-referrer\";\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Referrer-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Referrer-Policy\", referrer_policy);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Quickstart/TestUsers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class TestUsers\n{\n\n    static readonly object UserAddress = new\n    {\n        street_address = \"One Hacker Way\",\n        locality = \"Heidelberg\",\n        postal_code = 69118,\n        country = \"Germany\"\n    };\n\n    public static List<TestUser> Users => new List<TestUser>\n    {\n        new()\n        {\n            SubjectId = \"818727\",\n            Username = \"alice\",\n            Password = \"alice\",\n            Claims =\n            {\n                new (Name, \"Alice Smith\"),\n                new (GivenName, \"Alice\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"AliceSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://alice.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        },\n        new()\n        {\n            SubjectId = \"88421113\",\n            Username = \"bob\",\n            Password = \"bob\",\n            Claims =\n            {\n                new (Name, \"Bob Smith\"),\n                new (GivenName, \"Bob\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"BobSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://bob.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        }\n    };\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Account/AccessDenied.cshtml",
    "content": "﻿\n<div class=\"container\">\n    <div class=\"lead\">\n        <h1>Access Denied</h1>\n        <p>You do not have access to that resource.</p>\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Account/LoggedOut.cshtml",
    "content": "﻿@model LoggedOutViewModel\n\n@{ \n    // set this so the layout rendering sees an anonymous user\n    ViewData[\"signed-out\"] = true;\n}\n\n<div class=\"logged-out-page\">\n    <h1>\n        Logout\n        <small>You are now logged out</small>\n    </h1>\n\n    @if (Model.PostLogoutRedirectUri != null)\n    {\n        <div>\n            Click <a class=\"PostLogoutRedirectUri\" href=\"@Model.PostLogoutRedirectUri\">here</a> to return to the\n            <span>@Model.ClientName</span> application.\n        </div>\n    }\n\n    @if (Model.SignOutIframeUrl != null)\n    {\n        <iframe width=\"0\" height=\"0\" class=\"signout\" src=\"@Model.SignOutIframeUrl\"></iframe>\n    }\n</div>\n\n@section scripts\n{\n    @if (Model.AutomaticRedirectAfterSignOut)\n    {\n        <script src=\"~/js/signout-redirect.js\"></script>\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Account/Login.cshtml",
    "content": "@model LoginViewModel\n\n<div class=\"login-page\">\n    <div class=\"lead\">\n        <h1>Login</h1>\n        <p>Choose how to login</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n\n        @if (Model.EnableLocalLogin)\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>Local Account</h2>\n                    </div>\n\n                    <div class=\"card-body\">\n                        <form asp-route=\"Login\">\n                            <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n\n                            <div class=\"form-group\">\n                                <label asp-for=\"Username\"></label>\n                                <input class=\"form-control\" placeholder=\"Username\" asp-for=\"Username\" autofocus>\n                            </div>\n                            <div class=\"form-group\">\n                                <label asp-for=\"Password\"></label>\n                                <input type=\"password\" class=\"form-control\" placeholder=\"Password\" asp-for=\"Password\" autocomplete=\"off\">\n                            </div>\n                            @if (Model.AllowRememberLogin)\n                            {\n                                <div class=\"form-group\">\n                                    <div class=\"form-check\">\n                                        <input class=\"form-check-input\" asp-for=\"RememberLogin\">\n                                        <label class=\"form-check-label\" asp-for=\"RememberLogin\">\n                                            Remember My Login\n                                        </label>\n                                    </div>\n                                </div>\n                            }\n                            <button class=\"btn btn-primary\" name=\"button\" value=\"login\">Login</button>\n                            <button class=\"btn btn-secondary\" name=\"button\" value=\"cancel\" formaction=\"/Account/LoginCancel\">Cancel</button>\n                        </form>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>External Account</h2>\n                    </div>\n                    <div class=\"card-body\">\n                        <ul class=\"list-inline\">\n                            @foreach (var provider in Model.VisibleExternalProviders)\n                            {\n                                <li class=\"list-inline-item\">\n                                    <a class=\"btn btn-secondary\"\n                                       asp-controller=\"External\"\n                                       asp-action=\"Challenge\"\n                                       asp-route-scheme=\"@provider.AuthenticationScheme\"\n                                       asp-route-returnUrl=\"@Model.ReturnUrl\">\n                                        @provider.DisplayName\n                                    </a>\n                                </li>\n                            }\n                        </ul>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (!Model.EnableLocalLogin && !Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"alert alert-warning\">\n                <strong>Invalid login request</strong>\n                There are no login schemes configured for this request.\n            </div>\n        }\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Account/Logout.cshtml",
    "content": "﻿@model LogoutViewModel\n\n<div class=\"logout-page\">\n    <div class=\"lead\">\n        <h1>Logout</h1>\n        <p>Would you like to logout of IdentityServer?</p>\n    </div>\n\n    <form asp-action=\"Logout\">\n        <input type=\"hidden\" name=\"logoutId\" value=\"@Model.LogoutId\"  />\n        <div class=\"form-group\">\n            <button class=\"btn btn-primary\">Yes</button>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Consent/Index.cshtml",
    "content": "@model ConsentViewModel\n\n<div class=\"page-consent\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Index\">\n        <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Device/Success.cshtml",
    "content": "\n<div class=\"page-device-success\">\n    <div class=\"lead\">\n        <h1>Success</h1>\n        <p>You have successfully authorized the device</p>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Device/UserCodeCapture.cshtml",
    "content": "@model string\n\n<div class=\"page-device-code\">\n    <div class=\"lead\">\n        <h1>User Code</h1>\n        <p>Please enter the code displayed on your device.</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <form asp-action=\"UserCodeCapture\">\n                <div class=\"form-group\">\n                    <label for=\"userCode\">User Code:</label>\n                    <input class=\"form-control\" for=\"userCode\" name=\"userCode\" autofocus />\n                </div>\n\n                <button class=\"btn btn-primary\" name=\"button\">Submit</button>\n            </form>\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Device/UserCodeConfirmation.cshtml",
    "content": "@model DeviceAuthorizationViewModel\n\n<div class=\"page-device-confirmation\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        @if (Model.ConfirmUserCode)\n        {\n            <p>Please confirm that the authorization request quotes the code: <strong>@Model.UserCode</strong>.</p>\n        }\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Callback\">\n        <input asp-for=\"UserCode\" type=\"hidden\" value=\"@Model.UserCode\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Diagnostics/Index.cshtml",
    "content": "@model DiagnosticsViewModel\n\n<div class=\"diagnostics-page\">\n    <div class=\"lead\">\n        <h1>Authentication Cookie</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Claims</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var claim in Model.AuthenticateResult.Principal.Claims)\n                        {\n                            <dt>@claim.Type</dt>\n                            <dd>@claim.Value</dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n        \n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Properties</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var prop in Model.AuthenticateResult.Properties.Items)\n                        {\n                            <dt>@prop.Key</dt>\n                            <dd>@prop.Value</dd>\n                        }\n                        @if (Model.Clients.Any())\n                        {\n                            <dt>Clients</dt>\n                            <dd>\n                            @{\n                                var clients = Model.Clients.ToArray();\n                                for(var i = 0; i < clients.Length; i++)\n                                {\n                                    <text>@clients[i]</text>\n                                    if (i < clients.Length - 1)\n                                    {\n                                        <text>, </text>\n                                    }\n                                }\n                            }\n                            </dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n    </div>\n</div>\n\n\n\n\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Grants/Index.cshtml",
    "content": "﻿@model GrantsViewModel\n\n<div class=\"grants-page\">\n    <div class=\"lead\">\n        <h1>Client Application Permissions</h1>\n        <p>Below is the list of applications you have given permission to and the resources they have access to.</p>\n    </div>\n\n    @if (Model.Grants.Any() == false)\n    {\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                <div class=\"alert alert-info\">\n                    You have not given access to any applications\n                </div>\n            </div>\n        </div>\n    }\n    else\n    {\n        foreach (var grant in Model.Grants)\n        {\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <div class=\"row\">\n                        <div class=\"col-sm-8 card-title\">\n                            @if (grant.ClientLogoUrl != null)\n                            {\n                                <img src=\"@grant.ClientLogoUrl\">\n                            }\n                            <strong>@grant.ClientName</strong>\n                        </div>\n\n                        <div class=\"col-sm-2\">\n                            <form asp-action=\"Revoke\">\n                                <input type=\"hidden\" name=\"clientId\" value=\"@grant.ClientId\">\n                                <button class=\"btn btn-danger\">Revoke Access</button>\n                            </form>\n                        </div>\n                    </div>\n                </div>\n                \n                <ul class=\"list-group list-group-flush\">\n                    @if (grant.Description != null)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Description:</label> @grant.Description\n                        </li>   \n                    }\n                    <li class=\"list-group-item\">\n                        <label>Created:</label> @grant.Created.ToString(\"yyyy-MM-dd\")\n                    </li>\n                    @if (grant.Expires.HasValue)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Expires:</label> @grant.Expires.Value.ToString(\"yyyy-MM-dd\")\n                        </li>\n                    }\n                    @if (grant.IdentityGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Identity Grants</label>\n                            <ul>\n                                @foreach (var name in grant.IdentityGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                    @if (grant.ApiGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>API Grants</label>\n                            <ul>\n                                @foreach (var name in grant.ApiGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                </ul>\n            </div>\n        }\n    }\n</div>"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Home/Index.cshtml",
    "content": "@using System.Diagnostics\n\n@{\n    var version = FileVersionInfo.GetVersionInfo(typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.Location).ProductVersion.Split('+').First();\n}\n\n<div class=\"welcome-page\">\n    <h1>\n        <img src=\"~/icon.jpg\">\n        Welcome to IdentityServer8\n        <small class=\"text-muted\">(version @version)</small>\n    </h1>\n\n    <ul>\n        <li>\n            IdentityServer publishes a\n            <a href=\"~/.well-known/openid-configuration\">discovery document</a>\n            where you can find metadata and links to all the endpoints, key material, etc.\n        </li>\n        <li>\n            Click <a href=\"~/diagnostics\">here</a> to see the claims for your current session.\n        </li>\n        <li>\n            Click <a href=\"~/grants\">here</a> to manage your stored grants.\n        </li>\n        <li>\n            Here are links to the\n            <a href=\"https://github.com/alexhiggins732/IdentityServer8\">source code repository</a>,\n            and <a href=\"https://github.com/alexhiggins732/IdentityServer8/tree/main/samples\">ready to use samples</a>.\n        </li>\n    </ul>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Shared/Error.cshtml",
    "content": "@model ErrorViewModel\n\n@{\n    var error = Model?.Error?.Error;\n    var errorDescription = Model?.Error?.ErrorDescription;\n    var request_id = Model?.Error?.RequestId;\n}\n\n<div class=\"error-page\">\n    <div class=\"lead\">\n        <h1>Error</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <div class=\"alert alert-danger\">\n                Sorry, there was an error\n\n                @if (error != null)\n                {\n                    <strong>\n                        <em>\n                            : @error\n                        </em>\n                    </strong>\n\n                    if (errorDescription != null)\n                    {\n                        <div>@errorDescription</div>\n                    }\n                }\n            </div>\n\n            @if (request_id != null)\n            {\n                <div class=\"request-id\">Request Id: @request_id</div>\n            }\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Shared/Redirect.cshtml",
    "content": "@model RedirectViewModel\n@using Microsoft.Extensions.DependencyInjection;\n<div class=\"redirect-page\">\n    <div class=\"lead\">\n        <h1>You are now being returned to the application</h1>\n        <p>Once complete, you may close this tab.</p>\n    </div>\n</div>\n\n<meta http-equiv=\"refresh\" content=\"0;url=@Model.RedirectUrl\" data-url=\"@Model.RedirectUrl\">\n<script>\n    var url = '@Ioc.Sanitizer.Url.Sanitize(Model.RedirectUrl)';\n    window.location.href = url;\n</script>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0, shrink-to-fit=no\" />\n\n    <title>IdentityServer8</title>\n    \n    <link rel=\"icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    <link rel=\"shortcut icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    \n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <partial name=\"_Nav\" />\n   \n    <div class=\"container body-container\">\n        @RenderBody()\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.slim.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Shared/_Nav.cshtml",
    "content": "@using IdentityServer8.Extensions\n\n@{\n    string name = null;\n    if (!true.Equals(ViewData[\"signed-out\"]))\n    {\n        name = Context.User?.GetDisplayName();\n    }\n}\n\n<div class=\"nav-page\">\n    <nav class=\"navbar navbar-expand-lg navbar-dark bg-dark\">\n\n        <a href=\"~/\" class=\"navbar-brand\">\n            <img src=\"~/icon.png\" class=\"icon-banner\">\n            IdentityServer8\n        </a>\n\n        @if (!string.IsNullOrWhiteSpace(name))\n        {\n            <ul class=\"navbar-nav mr-auto\">\n                <li class=\"nav-item dropdown\">\n                    <a href=\"#\" class=\"nav-link dropdown-toggle\" data-toggle=\"dropdown\">@name <b class=\"caret\"></b></a>\n                    \n                    <div class=\"dropdown-menu\">\n                        <a class=\"dropdown-item\" asp-action=\"Logout\" asp-controller=\"Account\">Logout</a>\n                    </div>\n              </li>\n            </ul>\n        }\n    \n    </nav>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Shared/_ScopeListItem.cshtml",
    "content": "﻿@model ScopeViewModel\n\n<li class=\"list-group-item\">\n    <label>\n        <input class=\"consent-scopecheck\"\n               type=\"checkbox\"\n               name=\"ScopesConsented\"\n               id=\"scopes_@Model.Value\"\n               value=\"@Model.Value\"\n               checked=\"@Model.Checked\"\n               disabled=\"@Model.Required\" />\n        @if (Model.Required)\n        {\n            <input type=\"hidden\"\n                   name=\"ScopesConsented\"\n                   value=\"@Model.Value\" />\n        }\n        <strong>@Model.DisplayName</strong>\n        @if (Model.Emphasize)\n        {\n            <span class=\"glyphicon glyphicon-exclamation-sign\"></span>\n        }\n    </label>\n    @if (Model.Required)\n    {\n        <span><em>(required)</em></span>\n    }\n    @if (Model.Description != null)\n    {\n        <div class=\"consent-description\">\n            <label for=\"scopes_@Model.Value\">@Model.Description</label>\n        </div>\n    }\n</li>"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/Shared/_ValidationSummary.cshtml",
    "content": "﻿@if (ViewContext.ModelState.IsValid == false)\n{\n    <div class=\"alert alert-danger\">\n        <strong>Error</strong>\n        <div asp-validation-summary=\"All\" class=\"danger\"></div>\n    </div>\n}"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/_ViewImports.cshtml",
    "content": "﻿@using IdentityServerHost.Quickstart.UI\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/wwwroot/css/site.css",
    "content": "﻿.body-container {\n  margin-top: 60px;\n  padding-bottom: 40px; }\n\n.welcome-page li {\n  list-style: none;\n  padding: 4px; }\n\n.logged-out-page iframe {\n  display: none;\n  width: 0;\n  height: 0; }\n\n.grants-page .card {\n  margin-top: 20px;\n  border-bottom: 1px solid lightgray; }\n  .grants-page .card .card-title {\n    font-size: 120%;\n    font-weight: bold; }\n    .grants-page .card .card-title img {\n      width: 100px;\n      height: 100px; }\n  .grants-page .card label {\n    font-weight: bold; }\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/wwwroot/css/site.scss",
    "content": "﻿.body-container {\n    margin-top: 60px;\n    padding-bottom:40px;\n}\n\n.welcome-page {\n    li {\n        list-style: none;\n        padding: 4px;\n    }\n}\n\n.logged-out-page {\n    iframe {\n        display: none;\n        width: 0;\n        height: 0;\n    }\n}\n\n.grants-page {\n    .card {\n        margin-top: 20px;\n        border-bottom: 1px solid lightgray;\n\n        .card-title {\n            img {\n                width: 100px;\n                height: 100px;\n            }\n\n            font-size: 120%;\n            font-weight: bold;\n        }\n\n        label {\n            font-weight: bold;\n        }\n    }\n}\n\n\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/wwwroot/js/signin-redirect.js",
    "content": "//window.location.href = document.querySelector(\"meta[http-equiv=refresh]\").getAttribute(\"data-url\");\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/IdentityServer/wwwroot/js/signout-redirect.js",
    "content": "﻿window.addEventListener(\"load\", function () {\n    var a = document.querySelector(\"a.PostLogoutRedirectUri\");\n    if (a) {\n        window.location = a.href;\n    }\n});\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly ILogger<HomeController> _logger;\n\n    public HomeController(ILogger<HomeController> logger)\n    {\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    public async Task<IActionResult> CallApi()\n    {\n        var accessToken = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = new HttpClient();\n        client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue(\"Bearer\", accessToken);\n        var content = await client.GetStringAsync(\"https://localhost:6001/identity\");\n\n        var obj = JsonSerializer.Deserialize<JsonElement>(content);\n        ViewBag.Json = obj.ToString();\n        return View(\"json\");\n    }\n\n    public IActionResult Logout()\n    {\n        return SignOut(\"Cookies\", \"oidc\");\n    }\n\n    [ResponseCache(Duration = 0, Location = ResponseCacheLocation.None, NoStore = true)]\n    public IActionResult Error()\n    {\n        return View(new ErrorViewModel { RequestId = Activity.Current?.Id ?? HttpContext.TraceIdentifier });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using System.Diagnostics;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Net.Http.Headers;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Models/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class ErrorViewModel\n{\n    public string RequestId { get; set; }\n\n    public bool ShowRequestId => !string.IsNullOrEmpty(RequestId);\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/MvcClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <Content Update=\"Views\\Shared\\Json.cshtml\">\n      <ExcludeFromSingleFile>true</ExcludeFromSingleFile>\n      <CopyToPublishDirectory>PreserveNewest</CopyToPublishDirectory>\n    </Content>\n  </ItemGroup>\n\n</Project>"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nJwtSecurityTokenHandler.DefaultMapInboundClaims = false;\n\n\nvar builder = WebApplication.CreateBuilder(args);\n\nbuilder.Services.AddControllersWithViews();\nbuilder.Services\n    .AddAuthentication(options =>\n    {\n        options.DefaultScheme = \"Cookies\";\n        options.DefaultChallengeScheme = \"oidc\";\n    })\n    .AddCookie(\"Cookies\")\n    .AddOpenIdConnect(\"oidc\", options =>\n    {\n        options.Authority = \"https://localhost:5001\";\n\n        options.ClientId = \"mvc\";\n        options.ClientSecret = \"secret\";\n        options.ResponseType = \"code\";\n\n        options.Scope.Add(\"api1\");\n\n        options.SaveTokens = true;\n    });\n\n\nusing (var app = builder.Build())\n{\n    if (app.Environment.IsDevelopment())\n        app.UseDeveloperExceptionPage();\n    else\n        app.UseExceptionHandler(\"/Home/Error\");\n\n    app.UseStaticFiles();\n    app.UseRouting();\n    app.UseAuthentication();\n    app.UseAuthorization();\n    app.MapDefaultControllerRoute().RequireAuthorization();\n\n    await app.RunAsync();\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"MvcClient\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5002\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Views/Home/Index.cshtml",
    "content": "@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Views/Home/Privacy.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Privacy Policy\";\n}\n<h1>@ViewData[\"Title\"]</h1>\n\n<p>Use this page to detail your site's privacy policy.</p>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Views/Shared/Error.cshtml",
    "content": "﻿@model ErrorViewModel\n@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n\n@if (Model.ShowRequestId)\n{\n    <p>\n        <strong>Request ID:</strong> <code>@Model.RequestId</code>\n    </p>\n}\n\n<h3>Development Mode</h3>\n<p>\n    Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.\n</p>\n<p>\n    <strong>The Development environment shouldn't be enabled for deployed applications.</strong>\n    It can result in displaying sensitive information from exceptions to end users.\n    For local debugging, enable the <strong>Development</strong> environment by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>\n    and restarting the app.\n</p>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcClient</title>\n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <header>\n        <nav class=\"navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3\">\n            <div class=\"container\">\n                <a class=\"navbar-brand\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">MvcClient</a>\n                <button class=\"navbar-toggler\" type=\"button\" data-toggle=\"collapse\" data-target=\".navbar-collapse\" aria-controls=\"navbarSupportedContent\"\n                        aria-expanded=\"false\" aria-label=\"Toggle navigation\">\n                    <span class=\"navbar-toggler-icon\"></span>\n                </button>\n                <div class=\"navbar-collapse collapse d-sm-inline-flex flex-sm-row-reverse\">\n                    <ul class=\"navbar-nav flex-grow-1\">\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">Home</a>\n                        </li>\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Logout\">Logout</a>\n                        </li>\n                    </ul>\n                </div>\n            </div>\n        </nav>\n    </header>\n    <div class=\"container\">\n        <main role=\"main\" class=\"pb-3\">\n            @RenderBody()\n        </main>\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n    <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    @RenderSection(\"Scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Views/Shared/_ValidationScriptsPartial.cshtml",
    "content": "﻿<script src=\"~/lib/jquery-validation/dist/jquery.validate.min.js\"></script>\n<script src=\"~/lib/jquery-validation-unobtrusive/jquery.validate.unobtrusive.min.js\"></script>\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Views/Shared/json.cshtml",
    "content": "<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/appsettings.Development.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Debug\",\n      \"System\": \"Information\",\n      \"Microsoft\": \"Information\"\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/appsettings.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Information\",\n      \"Microsoft\": \"Warning\",\n      \"Microsoft.Hosting.Lifetime\": \"Information\"\n    }\n  },\n  \"AllowedHosts\": \"*\"\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/wwwroot/css/site.css",
    "content": "﻿/* Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\nfor details on configuring this project to bundle and minify static web assets. */\n\na.navbar-brand {\n  white-space: normal;\n  text-align: center;\n  word-break: break-all;\n}\n\n/* Provide sufficient contrast against white background */\na {\n  color: #0366d6;\n}\n\n.btn-primary {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n.nav-pills .nav-link.active, .nav-pills .show > .nav-link {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  font-size: 14px;\n}\n@media (min-width: 768px) {\n  html {\n    font-size: 16px;\n  }\n}\n\n.border-top {\n  border-top: 1px solid #e5e5e5;\n}\n.border-bottom {\n  border-bottom: 1px solid #e5e5e5;\n}\n\n.box-shadow {\n  box-shadow: 0 .25rem .75rem rgba(0, 0, 0, .05);\n}\n\nbutton.accept-policy {\n  font-size: 1rem;\n  line-height: inherit;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  position: relative;\n  min-height: 100%;\n}\n\nbody {\n  /* Margin bottom by footer height */\n  margin-bottom: 60px;\n}\n.footer {\n  position: absolute;\n  bottom: 0;\n  width: 100%;\n  white-space: nowrap;\n  line-height: 60px; /* Vertically center the text there */\n}\n"
  },
  {
    "path": "samples/Quickstarts/2_InteractiveAspNetCore/src/MvcClient/wwwroot/js/site.js",
    "content": "﻿// Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\n// for details on configuring this project to bundle and minify static web assets.\n\n// Write your JavaScript code.\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/Quickstart.sln",
    "content": "﻿\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 15.0.26124.0\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{BD8BA25C-A91D-419D-99B6-B575ADD6D061}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer\", \"src\\IdentityServer\\IdentityServer.csproj\", \"{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcClient\", \"src\\MvcClient\\MvcClient.csproj\", \"{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Api\", \"..\\Shared\\src\\Api\\Api.csproj\", \"{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Client\", \"..\\Shared\\src\\Client\\Client.csproj\", \"{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tDebug|x64 = Debug|x64\n\t\tDebug|x86 = Debug|x86\n\t\tRelease|Any CPU = Release|Any CPU\n\t\tRelease|x64 = Release|x64\n\t\tRelease|x86 = Release|x86\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x64.Build.0 = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x86.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x64.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x86.Build.0 = Release|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Release|x64.Build.0 = Release|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{FB7DDF43-1EB6-4FBF-B83D-6E19F723D7E4}.Release|x86.Build.0 = Release|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Release|x64.Build.0 = Release|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{78C0AEF8-E8B7-4F62-948C-FEFBF0ED881B}.Release|x86.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {84D5AF06-1243-46F1-9D58-70ED572832C3}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/Quickstart.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft\n Written by Alexander Higgins https://github.com/alexhiggins732/ \n \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code for this software can be found at https://github.com/alexhiggins732/IdentityServer8\n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n\n*/\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Config.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Secret = IdentityServer8.Models.Secret;\n\npublic static class Config\n{\n    public static IEnumerable<IdentityResource> IdentityResources =>\n        new List<IdentityResource>\n        {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n        };\n\n\n    public static IEnumerable<ApiScope> ApiScopes =>\n        new List<ApiScope>\n        {\n            new ApiScope(\"api1\", \"My API\")\n        };\n\n    public static IEnumerable<Client> Clients =>\n        new List<Client>\n        {\n            // machine to machine client\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                // scopes that client has access to\n                AllowedScopes = { \"api1\" }\n            },\n            \n            // interactive ASP.NET Core MVC client\n            new Client\n            {\n                ClientId = \"mvc\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.Code,\n                \n                // where to redirect to after login\n                RedirectUris = { \"https://localhost:5002/signin-oidc\" },\n\n                // where to redirect to after logout\n                PostLogoutRedirectUris = { \"https://localhost:5002/signout-callback-oidc\" },\n\n                AllowedScopes = new List<string>\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    \"api1\"\n                }\n            }\n        };\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.Configuration;\nglobal using IdentityServer8.Events;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Test;\nglobal using IdentityServer8.Validation;\nglobal using IdentityServerHost.Quickstart.UI;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Hosting;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.AspNetCore.Mvc.Filters;\nglobal using Microsoft.Extensions.Hosting;\nglobal using Microsoft.Extensions.Options;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\nglobal using System;\nglobal using System.ComponentModel.DataAnnotations;\nglobal using System.Security.Claims;\nglobal using System.Text;\nglobal using System.Text.Json;\nglobal using static IdentityModel.JwtClaimTypes;\nglobal using IdentityServerClaimValueTypes = IdentityServer8.IdentityServerConstants.ClaimValueTypes;\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/IdentityServer.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"HigginsSoft.IdentityServer8\" />\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n\n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.Google\" />\n  </ItemGroup>\n</Project>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConfigureLogger();\n\ntry\n{\n    Log.Information(\"Starting host...\");\n\n    var builder = WebApplication.CreateBuilder(args);\n\n    var services = builder.Services;\n\n    services.AddControllersWithViews();\n\n    services\n        .AddIdentityServer()\n        .AddInMemoryIdentityResources(Config.IdentityResources)\n        .AddInMemoryApiScopes(Config.ApiScopes)\n        .AddInMemoryClients(Config.Clients)\n        .AddTestUsers(TestUsers.Users)\n        .AddDeveloperSigningCredential();\n\n    services.AddAuthentication()\n        .AddGoogle(\"Google\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n            options.ClientId = \"<insert here>\";\n            options.ClientSecret = \"<insert here>\";\n        })\n        .AddOpenIdConnect(\"oidc\", \"Demo IdentityServer\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n            options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n            options.SaveTokens = true;\n\n            options.Authority = \"https://demo.identityserver8.io/\";\n            options.ClientId = \"interactive.confidential\";\n            options.ClientSecret = \"secret\";\n            options.ResponseType = \"code\";\n\n            options.TokenValidationParameters = new()\n            {\n                NameClaimType = \"name\",\n                RoleClaimType = \"role\"\n            };\n        });\n\n\n    using (var app = builder.Build())\n    {\n        if (app.Environment.IsDevelopment())\n            app.UseDeveloperExceptionPage();\n\n        app.UseStaticFiles()\n            .UseRouting()\n            .UseIdentityServer()\n            .UseAuthorization();\n\n        app.MapDefaultControllerRoute();\n\n        await app.RunAsync();\n    }\n\n    return 0;\n}\ncatch (Exception ex)\n{\n    Log.Fatal(ex, \"Host terminated unexpectedly.\");\n    return 1;\n}\nfinally\n{\n    Log.CloseAndFlush();\n}\n\n\nvoid ConfigureLogger() => Log.Logger = new LoggerConfiguration()\n    .MinimumLevel.Debug()\n    .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n    .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n    .Enrich.FromLogContext()\n    // uncomment to write to Azure diagnostics stream\n    //.WriteTo.File(\n    //    @\"D:\\home\\LogFiles\\Application\\identityserver.txt\",\n    //    fileSizeLimitBytes: 1_000_000,\n    //    rollOnFileSizeLimit: true,\n    //    shared: true,\n    //    flushToDiskInterval: TimeSpan.FromSeconds(1))\n    .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n    .CreateLogger();\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"SelfHost\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Account/AccountController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller implements a typical login/logout/provision workflow for local and external accounts.\n/// The login service encapsulates the interactions with the user data store. This data store is in-memory only and cannot be used for production!\n/// The interaction service provides a way for the UI to communicate with identityserver for validation and context retrieval\n/// </summary>\n[SecurityHeaders]\n[AllowAnonymous]\npublic class AccountController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly IAuthenticationSchemeProvider _schemeProvider;\n    private readonly IEventService _events;\n\n    public AccountController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IAuthenticationSchemeProvider schemeProvider,\n        IEventService events,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _schemeProvider = schemeProvider;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Entry point into the login workflow\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Login(string returnUrl)\n    {\n        // build a model so we know what to show on the login page\n        var vm = await BuildLoginViewModelAsync(returnUrl);\n\n        if (vm.IsExternalLoginOnly)\n        {\n            // we only have one option for logging in and it's an external provider\n            return returnUrl.IsAllowedRedirect() ? RedirectToAction(\"Challenge\", \"External\", new { scheme = vm.ExternalLoginScheme, returnUrl = returnUrl.SanitizeForRedirect() }) : Forbid();\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Login(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (ModelState.IsValid)\n        {\n            // validate username/password against in-memory store\n            if (_users.ValidateCredentials(model.Username, model.Password))\n            {\n                var user = _users.FindByUsername(model.Username);\n                await _events.RaiseAsync(new UserLoginSuccessEvent(user.Username, user.SubjectId, user.Username, clientId: context?.Client.ClientId));\n\n                // only set explicit expiration here if user chooses \"remember me\". \n                // otherwise we rely upon expiration configured in cookie middleware.\n                AuthenticationProperties props = null;\n                if (AccountOptions.AllowRememberLogin && model.RememberLogin)\n                {\n                    props = new AuthenticationProperties\n                    {\n                        IsPersistent = true,\n                        ExpiresUtc = DateTimeOffset.UtcNow.Add(AccountOptions.RememberMeLoginDuration)\n                    };\n                };\n\n                // issue authentication cookie with subject ID and username\n                var isuser = new IdentityServerUser(user.SubjectId)\n                {\n                    DisplayName = user.Username\n                };\n\n                await HttpContext.SignInAsync(isuser, props);\n\n                if (context != null)\n                {\n                    if (context.IsNativeClient())\n                    {\n                        // The client is native, so this change in how to\n                        // return the response is for better UX for the end user.\n                        return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                    }\n\n                    // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n\n                // request for a local page\n                if (Url.IsLocalUrl(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n                else if (string.IsNullOrEmpty(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n                }\n                else\n                {\n                    // user might have clicked on a malicious link - should be logged\n                    throw new Exception(\"invalid return URL\");\n                }\n            }\n\n            await _events.RaiseAsync(new UserLoginFailureEvent(model.Username, \"invalid credentials\", clientId: context?.Client.ClientId));\n            ModelState.AddModelError(string.Empty, AccountOptions.InvalidCredentialsErrorMessage);\n        }\n\n        // something went wrong, show form with error\n        var vm = await BuildLoginViewModelAsync(model);\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> LoginCancel(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (context != null)\n        {\n            // if the user cancels, send a result back into IdentityServer as if they \n            // denied the consent (even if this client does not require consent).\n            // this will send back an access denied OIDC error response to the client.\n            await _interaction.DenyAuthorizationAsync(context, AuthorizationError.AccessDenied);\n\n            // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n            }\n\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n        }\n        else\n        {\n            // since we don't have a valid context, then we just go back to the home page\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n        }\n\n    }\n\n    /// <summary>\n    /// Show logout page\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Logout(string logoutId)\n    {\n        // build a model so the logout page knows what to display\n        var vm = await BuildLogoutViewModelAsync(logoutId);\n\n        if (vm.ShowLogoutPrompt == false)\n        {\n            // if the request for logout was properly authenticated from IdentityServer, then\n            // we don't need to show the prompt and can just log the user out directly.\n            return await Logout(vm);\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle logout page postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Logout(LogoutInputModel model)\n    {\n        // build a model so the logged out page knows what to display\n        var vm = await BuildLoggedOutViewModelAsync(model.LogoutId);\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            // delete local authentication cookie\n            await HttpContext.SignOutAsync();\n\n            // raise the logout event\n            await _events.RaiseAsync(new UserLogoutSuccessEvent(User.GetSubjectId(), User.GetDisplayName()));\n        }\n\n        // check if we need to trigger sign-out at an upstream identity provider\n        if (vm.TriggerExternalSignout)\n        {\n            // build a return URL so the upstream provider will redirect back\n            // to us after the user has logged out. this allows us to then\n            // complete our single sign-out processing.\n            string url = Url.Action(\"Logout\", new { logoutId = vm.LogoutId });\n\n            // this triggers a redirect to the external provider for sign-out\n            return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);\n        }\n\n        return View(\"LoggedOut\", vm);\n    }\n\n    [HttpGet]\n    public IActionResult AccessDenied()\n    {\n        return View();\n    }\n\n\n    /*****************************************/\n    /* helper APIs for the AccountController */\n    /*****************************************/\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(string returnUrl)\n    {\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (context?.IdP != null && await _schemeProvider.GetSchemeAsync(context.IdP) != null)\n        {\n            var local = context.IdP == IdentityServer8.IdentityServerConstants.LocalIdentityProvider;\n\n            // this is meant to short circuit the UI and only trigger the one external IdP\n            var vm = new LoginViewModel\n            {\n                EnableLocalLogin = local,\n                ReturnUrl = returnUrl,\n                Username = context?.LoginHint,\n            };\n\n            if (!local)\n            {\n                vm.ExternalProviders = new[] { new ExternalProvider { AuthenticationScheme = context.IdP } };\n            }\n\n            return vm;\n        }\n\n        var schemes = await _schemeProvider.GetAllSchemesAsync();\n\n        var providers = schemes\n            .Where(x => x.DisplayName != null)\n            .Select(x => new ExternalProvider\n            {\n                DisplayName = x.DisplayName ?? x.Name,\n                AuthenticationScheme = x.Name\n            }).ToList();\n\n        var allowLocal = true;\n        if (context?.Client.ClientId != null)\n        {\n            var client = await _clientStore.FindEnabledClientByIdAsync(context.Client.ClientId);\n            if (client != null)\n            {\n                allowLocal = client.EnableLocalLogin;\n\n                if (client.IdentityProviderRestrictions != null && client.IdentityProviderRestrictions.Any())\n                {\n                    providers = providers.Where(provider => client.IdentityProviderRestrictions.Contains(provider.AuthenticationScheme)).ToList();\n                }\n            }\n        }\n\n        return new LoginViewModel\n        {\n            AllowRememberLogin = AccountOptions.AllowRememberLogin,\n            EnableLocalLogin = allowLocal && AccountOptions.AllowLocalLogin,\n            ReturnUrl = returnUrl,\n            Username = context?.LoginHint,\n            ExternalProviders = providers.ToArray()\n        };\n    }\n\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(LoginInputModel model)\n    {\n        var vm = await BuildLoginViewModelAsync(model.ReturnUrl);\n        vm.Username = model.Username;\n        vm.RememberLogin = model.RememberLogin;\n        return vm;\n    }\n\n    private async Task<LogoutViewModel> BuildLogoutViewModelAsync(string logoutId)\n    {\n        var vm = new LogoutViewModel { LogoutId = logoutId, ShowLogoutPrompt = AccountOptions.ShowLogoutPrompt };\n\n        if (User?.Identity.IsAuthenticated != true)\n        {\n            // if the user is not authenticated, then just show logged out page\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        var context = await _interaction.GetLogoutContextAsync(logoutId);\n        if (context?.ShowSignoutPrompt == false)\n        {\n            // it's safe to automatically sign-out\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        // show the logout prompt. this prevents attacks where the user\n        // is automatically signed out by another malicious web page.\n        return vm;\n    }\n\n    private async Task<LoggedOutViewModel> BuildLoggedOutViewModelAsync(string logoutId)\n    {\n        // get context information (client name, post logout redirect URI and iframe for federated signout)\n        var logout = await _interaction.GetLogoutContextAsync(logoutId);\n\n        var vm = new LoggedOutViewModel\n        {\n            AutomaticRedirectAfterSignOut = AccountOptions.AutomaticRedirectAfterSignOut,\n            PostLogoutRedirectUri = logout?.PostLogoutRedirectUri,\n            ClientName = string.IsNullOrEmpty(logout?.ClientName) ? logout?.ClientId : logout?.ClientName,\n            SignOutIframeUrl = logout?.SignOutIFrameUrl,\n            LogoutId = logoutId\n        };\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            var idp = User.FindFirst(JwtClaimTypes.IdentityProvider)?.Value;\n            if (idp != null && idp != IdentityServer8.IdentityServerConstants.LocalIdentityProvider)\n            {\n                var providerSupportsSignout = await HttpContext.GetSchemeSupportsSignOutAsync(idp);\n                if (providerSupportsSignout)\n                {\n                    if (vm.LogoutId == null)\n                    {\n                        // if there's no current logout context, we need to create one\n                        // this captures necessary info from the current logged in user\n                        // before we signout and redirect away to the external IdP for signout\n                        vm.LogoutId = await _interaction.CreateLogoutContextAsync();\n                    }\n\n                    vm.ExternalAuthenticationScheme = idp;\n                }\n            }\n        }\n\n        return vm;\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Account/AccountOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI\n{\n    public class AccountOptions\n    {\n        public static bool AllowLocalLogin = true;\n        public static bool AllowRememberLogin = true;\n        public static TimeSpan RememberMeLoginDuration = TimeSpan.FromDays(30);\n\n        public static bool ShowLogoutPrompt = true;\n        public static bool AutomaticRedirectAfterSignOut = false;\n\n        public static string InvalidCredentialsErrorMessage = \"Invalid username or password\";\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Account/ExternalController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class ExternalController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly ILogger<ExternalController> _logger;\n    private readonly IEventService _events;\n\n    public ExternalController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IEventService events,\n        ILogger<ExternalController> logger,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _logger = logger;\n        _events = events;\n    }\n\n    /// <summary>\n    /// initiate roundtrip to external authentication provider\n    /// </summary>\n    [HttpGet]\n    public IActionResult Challenge(string scheme, string returnUrl)\n    {\n        if (string.IsNullOrEmpty(returnUrl)) returnUrl = \"~/\";\n\n        // validate returnUrl - either it is a valid OIDC URL or back to a local page\n        if (Url.IsLocalUrl(returnUrl) == false && _interaction.IsValidReturnUrl(returnUrl) == false)\n        {\n            // user might have clicked on a malicious link - should be logged\n            throw new Exception(\"invalid return URL\");\n        }\n        \n        // start challenge and roundtrip the return URL and scheme \n        var props = new AuthenticationProperties\n        {\n            RedirectUri = Url.Action(nameof(Callback)), \n            Items =\n            {\n                { \"returnUrl\", returnUrl }, \n                { \"scheme\", scheme },\n            }\n        };\n\n        return Challenge(props, scheme);\n        \n    }\n\n    /// <summary>\n    /// Post processing of external authentication\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Callback()\n    {\n        // read external identity from the temporary cookie\n        var result = await HttpContext.AuthenticateAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n        if (result?.Succeeded != true)\n        {\n            throw new Exception(\"External authentication error\");\n        }\n\n        if (_logger.IsEnabled(LogLevel.Debug))\n        {\n            var externalClaims = result.Principal.Claims.Select(c => $\"{c.Type}: {c.Value}\");\n            _logger.LogDebug(\"External claims: {@claims}\", externalClaims);\n        }\n\n        // lookup our user and external provider info\n        var (user, provider, providerUserId, claims) = FindUserFromExternalProvider(result);\n        if (user == null)\n        {\n            // this might be where you might initiate a custom workflow for user registration\n            // in this sample we don't show how that would be done, as our sample implementation\n            // simply auto-provisions new external user\n            user = AutoProvisionUser(provider, providerUserId, claims);\n        }\n\n        // this allows us to collect any additional claims or properties\n        // for the specific protocols used and store them in the local auth cookie.\n        // this is typically used to store data needed for signout from those protocols.\n        var additionalLocalClaims = new List<Claim>();\n        var localSignInProps = new AuthenticationProperties();\n        ProcessLoginCallback(result, additionalLocalClaims, localSignInProps);\n        \n        // issue authentication cookie for user\n        var isuser = new IdentityServerUser(user.SubjectId)\n        {\n            DisplayName = user.Username,\n            IdentityProvider = provider,\n            AdditionalClaims = additionalLocalClaims\n        };\n\n        await HttpContext.SignInAsync(isuser, localSignInProps);\n\n        // delete temporary cookie used during external authentication\n        await HttpContext.SignOutAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n        // retrieve return URL\n        var returnUrl = result.Properties.Items[\"returnUrl\"] ?? \"~/\";\n\n        // check if external login is in the context of an OIDC request\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        await _events.RaiseAsync(new UserLoginSuccessEvent(provider, providerUserId, user.SubjectId, user.Username, true, context?.Client.ClientId));\n\n        if (context != null)\n        {\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", returnUrl);\n            }\n        }\n\n        return Redirect(returnUrl);\n    }\n\n    private (TestUser user, string provider, string providerUserId, IEnumerable<Claim> claims) FindUserFromExternalProvider(AuthenticateResult result)\n    {\n        var externalUser = result.Principal;\n\n        // try to determine the unique id of the external user (issued by the provider)\n        // the most common claim type for that are the sub claim and the NameIdentifier\n        // depending on the external provider, some other claim type might be used\n        var userIdClaim = externalUser.FindFirst(JwtClaimTypes.Subject) ??\n                          externalUser.FindFirst(ClaimTypes.NameIdentifier) ??\n                          throw new Exception(\"Unknown userid\");\n\n        // remove the user id claim so we don't include it as an extra claim if/when we provision the user\n        var claims = externalUser.Claims.ToList();\n        claims.Remove(userIdClaim);\n\n        var provider = result.Properties.Items[\"scheme\"];\n        var providerUserId = userIdClaim.Value;\n\n        // find external user\n        var user = _users.FindByExternalProvider(provider, providerUserId);\n\n        return (user, provider, providerUserId, claims);\n    }\n\n    private TestUser AutoProvisionUser(string provider, string providerUserId, IEnumerable<Claim> claims)\n    {\n        var user = _users.AutoProvisionUser(provider, providerUserId, claims.ToList());\n        return user;\n    }\n\n    // if the external login is OIDC-based, there are certain things we need to preserve to make logout work\n    // this will be different for WS-Fed, SAML2p or other protocols\n    private void ProcessLoginCallback(AuthenticateResult externalResult, List<Claim> localClaims, AuthenticationProperties localSignInProps)\n    {\n        // if the external system sent a session id claim, copy it over\n        // so we can use it for single sign-out\n        var sid = externalResult.Principal.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.SessionId);\n        if (sid != null)\n        {\n            localClaims.Add(new Claim(JwtClaimTypes.SessionId, sid.Value));\n        }\n\n        // if the external provider issued an id_token, we'll keep it for signout\n        var idToken = externalResult.Properties.GetTokenValue(\"id_token\");\n        if (idToken != null)\n        {\n            localSignInProps.StoreTokens(new[] { new AuthenticationToken { Name = \"id_token\", Value = idToken } });\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Account/ExternalProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ExternalProvider\n{\n    public string DisplayName { get; set; }\n    public string AuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Account/LoggedOutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoggedOutViewModel\n{\n    public string PostLogoutRedirectUri { get; set; }\n    public string ClientName { get; set; }\n    public string SignOutIframeUrl { get; set; }\n\n    public bool AutomaticRedirectAfterSignOut { get; set; }\n\n    public string LogoutId { get; set; }\n    public bool TriggerExternalSignout => ExternalAuthenticationScheme != null;\n    public string ExternalAuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Account/LoginInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginInputModel\n{\n    [Required]\n    public string Username { get; set; }\n    [Required]\n    public string Password { get; set; }\n    public bool RememberLogin { get; set; }\n    public string ReturnUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Account/LoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginViewModel : LoginInputModel\n{\n    public bool AllowRememberLogin { get; set; } = true;\n    public bool EnableLocalLogin { get; set; } = true;\n\n    public IEnumerable<ExternalProvider> ExternalProviders { get; set; } = Enumerable.Empty<ExternalProvider>();\n    public IEnumerable<ExternalProvider> VisibleExternalProviders => ExternalProviders.Where(x => !String.IsNullOrWhiteSpace(x.DisplayName));\n\n    public bool IsExternalLoginOnly => EnableLocalLogin == false && ExternalProviders?.Count() == 1;\n    public string ExternalLoginScheme => IsExternalLoginOnly ? ExternalProviders?.SingleOrDefault()?.AuthenticationScheme : null;\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Account/LogoutInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutInputModel\n{\n    public string LogoutId { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Account/LogoutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutViewModel : LogoutInputModel\n{\n    public bool ShowLogoutPrompt { get; set; } = true;\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Account/RedirectViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class RedirectViewModel\n{\n    public string RedirectUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Consent/ConsentController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This controller processes the consent UI\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class ConsentController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly ILogger<ConsentController> _logger;\n\n    public ConsentController(\n        IIdentityServerInteractionService interaction,\n        IEventService events,\n        ILogger<ConsentController> logger)\n    {\n        _interaction = interaction;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Shows the consent screen\n    /// </summary>\n    /// <param name=\"returnUrl\"></param>\n    /// <returns></returns>\n    [HttpGet]\n    public async Task<IActionResult> Index(string returnUrl)\n    {\n        var vm = await BuildViewModelAsync(returnUrl);\n        if (vm != null)\n        {\n            return View(\"Index\", vm);\n        }\n\n        return View(\"Error\");\n    }\n\n    /// <summary>\n    /// Handles the consent screen postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Index(ConsentInputModel model)\n    {\n        var result = await ProcessConsent(model);\n\n        if (result.IsRedirect)\n        {\n            var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n            if (context?.IsNativeClient() == true)\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", result.RedirectUri);\n            }\n            return result.RedirectUri.IsAllowedRedirect() ? Redirect(result.RedirectUri.SanitizeForRedirect()) : Forbid();\n        }\n\n        if (result.HasValidationError)\n        {\n            ModelState.AddModelError(string.Empty, result.ValidationError);\n        }\n\n        if (result.ShowView)\n        {\n            return View(\"Index\", result.ViewModel);\n        }\n\n        return View(\"Error\");\n    }\n\n    /*****************************************/\n    /* helper APIs for the ConsentController */\n    /*****************************************/\n    private async Task<ProcessConsentResult> ProcessConsent(ConsentInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        // validate return url is still valid\n        var request = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model?.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model?.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.GrantConsentAsync(request, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.ReturnUrl, model);\n        }\n\n        return result;\n    }\n\n    private async Task<ConsentViewModel> BuildViewModelAsync(string returnUrl, ConsentInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (request != null)\n        {\n            return CreateConsentViewModel(model, returnUrl, request);\n        }\n        else\n        {\n            _logger.LogError(\"No consent request matching request: {0}\", returnUrl.SanitizeForLog());\n        }\n\n        return null;\n    }\n\n    private ConsentViewModel CreateConsentViewModel(\n        ConsentInputModel model, string returnUrl,\n        AuthorizationRequest request)\n    {\n        var vm = new ConsentViewModel\n        {\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n            Description = model?.Description,\n\n            ReturnUrl = returnUrl,\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach(var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        var displayName = apiScope.DisplayName ?? apiScope.Name;\n        if (!String.IsNullOrWhiteSpace(parsedScopeValue.ParsedParameter))\n        {\n            displayName += \":\" + parsedScopeValue.ParsedParameter;\n        }\n\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            DisplayName = displayName,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Consent/ConsentInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentInputModel\n{\n    public string Button { get; set; }\n    public IEnumerable<string> ScopesConsented { get; set; }\n    public bool RememberConsent { get; set; }\n    public string ReturnUrl { get; set; }\n    public string Description { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Consent/ConsentOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentOptions\n{\n    public static bool EnableOfflineAccess = true;\n    public static string OfflineAccessDisplayName = \"Offline Access\";\n    public static string OfflineAccessDescription = \"Access to your applications and resources, even when you are offline\";\n\n    public static readonly string MustChooseOneErrorMessage = \"You must pick at least one permission\";\n    public static readonly string InvalidSelectionErrorMessage = \"Invalid selection\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Consent/ConsentViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentViewModel : ConsentInputModel\n{\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public bool AllowRememberConsent { get; set; }\n\n    public IEnumerable<ScopeViewModel> IdentityScopes { get; set; }\n    public IEnumerable<ScopeViewModel> ApiScopes { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Consent/ProcessConsentResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ProcessConsentResult\n{\n    public bool IsRedirect => RedirectUri != null;\n    public string RedirectUri { get; set; }\n    public Client Client { get; set; }\n\n    public bool ShowView => ViewModel != null;\n    public ConsentViewModel ViewModel { get; set; }\n\n    public bool HasValidationError => ValidationError != null;\n    public string ValidationError { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Consent/ScopeViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ScopeViewModel\n{\n    public string Value { get; set; }\n    public string DisplayName { get; set; }\n    public string Description { get; set; }\n    public bool Emphasize { get; set; }\n    public bool Required { get; set; }\n    public bool Checked { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Device/DeviceAuthorizationInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationInputModel : ConsentInputModel\n{\n    public string UserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Device/DeviceAuthorizationViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationViewModel : ConsentViewModel\n{\n    public string UserCode { get; set; }\n    public bool ConfirmUserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Device/DeviceController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[Authorize]\n[SecurityHeaders]\npublic class DeviceController : Controller\n{\n    private readonly IDeviceFlowInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly IOptions<IdentityServerOptions> _options;\n    private readonly ILogger<DeviceController> _logger;\n\n    public DeviceController(\n        IDeviceFlowInteractionService interaction,\n        IEventService eventService,\n        IOptions<IdentityServerOptions> options,\n        ILogger<DeviceController> logger)\n    {\n        _interaction = interaction;\n        _events = eventService;\n        _options = options;\n        _logger = logger;\n    }\n\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        string userCodeParamName = _options.Value.UserInteraction.DeviceVerificationUserCodeParameter;\n        string userCode = Request.Query[userCodeParamName];\n        if (string.IsNullOrWhiteSpace(userCode)) return View(\"UserCodeCapture\");\n\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        vm.ConfirmUserCode = true;\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> UserCodeCapture(string userCode)\n    {\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Callback(DeviceAuthorizationInputModel model)\n    {\n        if (model == null) throw new ArgumentNullException(nameof(model));\n\n        var result = await ProcessConsent(model);\n        if (result.HasValidationError) return View(\"Error\");\n\n        return View(\"Success\");\n    }\n\n    private async Task<ProcessConsentResult> ProcessConsent(DeviceAuthorizationInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        var request = await _interaction.GetAuthorizationContextAsync(model.UserCode);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.HandleRequestAsync(model.UserCode, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.UserCode, model);\n        }\n\n        return result;\n    }\n\n    private async Task<DeviceAuthorizationViewModel> BuildViewModelAsync(string userCode, DeviceAuthorizationInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(userCode);\n        if (request != null)\n        {\n            return CreateConsentViewModel(userCode, model, request);\n        }\n\n        return null;\n    }\n\n    private DeviceAuthorizationViewModel CreateConsentViewModel(string userCode, DeviceAuthorizationInputModel model, DeviceFlowAuthorizationRequest request)\n    {\n        var vm = new DeviceAuthorizationViewModel\n        {\n            UserCode = userCode,\n            Description = model?.Description,\n\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach (var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            // todo: use the parsed scope value in the display?\n            DisplayName = apiScope.DisplayName ?? apiScope.Name,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Diagnostics/DiagnosticsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[Authorize]\npublic class DiagnosticsController : Controller\n{\n    public async Task<IActionResult> Index()\n    {\n        var localAddresses = new string[] { \"127.0.0.1\", \"::1\", HttpContext.Connection.LocalIpAddress.ToString() };\n        if (!localAddresses.Contains(HttpContext.Connection.RemoteIpAddress.ToString()))\n        {\n            return NotFound();\n        }\n\n        var model = new DiagnosticsViewModel(await HttpContext.AuthenticateAsync());\n        return View(model);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Diagnostics/DiagnosticsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DiagnosticsViewModel\n{\n    public DiagnosticsViewModel(AuthenticateResult result)\n    {\n        AuthenticateResult = result;\n\n        if (result.Properties.Items.ContainsKey(\"client_list\"))\n        {\n            var encoded = result.Properties.Items[\"client_list\"];\n            var bytes = Base64Url.Decode(encoded);\n            var value = Encoding.UTF8.GetString(bytes);\n\n            Clients = JsonSerializer.Deserialize<string[]>(value);\n        }\n    }\n\n    public AuthenticateResult AuthenticateResult { get; }\n    public IEnumerable<string> Clients { get; } = new List<string>();\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Extensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic static class Extensions\n{\n    /// <summary>\n    /// Checks if the redirect URI is for a native client.\n    /// </summary>\n    /// <returns></returns>\n    public static bool IsNativeClient(this AuthorizationRequest context)\n    {\n        return !context.RedirectUri.StartsWith(\"https\", StringComparison.Ordinal)\n           && !context.RedirectUri.StartsWith(\"http\", StringComparison.Ordinal);\n    }\n\n    public static IActionResult LoadingPage(this Controller controller, string viewName, string redirectUri)\n    {\n        controller.HttpContext.Response.StatusCode = 200;\n        controller.HttpContext.Response.Headers[\"Location\"] = \"\";\n        \n        return controller.View(viewName, new RedirectViewModel { RedirectUrl = redirectUri });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Grants/GrantsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller allows a user to revoke grants given to clients\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class GrantsController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clients;\n    private readonly IResourceStore _resources;\n    private readonly IEventService _events;\n\n    public GrantsController(IIdentityServerInteractionService interaction,\n        IClientStore clients,\n        IResourceStore resources,\n        IEventService events)\n    {\n        _interaction = interaction;\n        _clients = clients;\n        _resources = resources;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Show list of grants\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        return View(\"Index\", await BuildViewModelAsync());\n    }\n\n    /// <summary>\n    /// Handle postback to revoke a client\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Revoke(string clientId)\n    {\n        await _interaction.RevokeUserConsentAsync(clientId);\n        await _events.RaiseAsync(new GrantsRevokedEvent(User.GetSubjectId(), clientId));\n\n        return RedirectToAction(\"Index\");\n    }\n\n    private async Task<GrantsViewModel> BuildViewModelAsync()\n    {\n        var grants = await _interaction.GetAllUserGrantsAsync();\n\n        var list = new List<GrantViewModel>();\n        foreach(var grant in grants)\n        {\n            var client = await _clients.FindClientByIdAsync(grant.ClientId);\n            if (client != null)\n            {\n                var resources = await _resources.FindResourcesByScopeAsync(grant.Scopes);\n\n                var item = new GrantViewModel()\n                {\n                    ClientId = client.ClientId,\n                    ClientName = client.ClientName ?? client.ClientId,\n                    ClientLogoUrl = client.LogoUri,\n                    ClientUrl = client.ClientUri,\n                    Description = grant.Description,\n                    Created = grant.CreationTime,\n                    Expires = grant.Expiration,\n                    IdentityGrantNames = resources.IdentityResources.Select(x => x.DisplayName ?? x.Name).ToArray(),\n                    ApiGrantNames = resources.ApiScopes.Select(x => x.DisplayName ?? x.Name).ToArray()\n                };\n\n                list.Add(item);\n            }\n        }\n\n        return new GrantsViewModel\n        {\n            Grants = list\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Grants/GrantsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class GrantsViewModel\n{\n    public IEnumerable<GrantViewModel> Grants { get; set; }\n}\n\npublic class GrantViewModel\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public string Description { get; set; }\n    public DateTime Created { get; set; }\n    public DateTime? Expires { get; set; }\n    public IEnumerable<string> IdentityGrantNames { get; set; }\n    public IEnumerable<string> ApiGrantNames { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Home/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ErrorViewModel\n{\n    public ErrorViewModel()\n    {\n    }\n\n    public ErrorViewModel(string error)\n    {\n        Error = new ErrorMessage { Error = error };\n    }\n\n    public ErrorMessage Error { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/Home/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class HomeController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IWebHostEnvironment _environment;\n    private readonly ILogger _logger;\n\n    public HomeController(IIdentityServerInteractionService interaction, IWebHostEnvironment environment, ILogger<HomeController> logger)\n    {\n        _interaction = interaction;\n        _environment = environment;\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        if (_environment.IsDevelopment())\n        {\n            // only show in development\n            return View();\n        }\n\n        _logger.LogInformation(\"Homepage is disabled in production. Returning 404.\");\n        return NotFound();\n    }\n\n    /// <summary>\n    /// Shows the error page\n    /// </summary>\n    public async Task<IActionResult> Error(string errorId)\n    {\n        var vm = new ErrorViewModel();\n\n        // retrieve error details from identityserver\n        var message = await _interaction.GetErrorContextAsync(errorId);\n        if (message != null)\n        {\n            vm.Error = message;\n\n            if (!_environment.IsDevelopment())\n            {\n                // only show in development\n                message.ErrorDescription = null;\n            }\n        }\n\n        return View(\"Error\", vm);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/SecurityHeadersAttribute.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class SecurityHeadersAttribute : ActionFilterAttribute\n{\n    public override void OnResultExecuting(ResultExecutingContext context)\n    {\n        var result = context.Result;\n        if (result is ViewResult)\n        {\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Type-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Type-Options\", \"nosniff\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Frame-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Frame-Options\", \"SAMEORIGIN\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy\n            var csp = \"default-src 'self'; object-src 'none'; frame-ancestors 'none'; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self';\";\n            // also consider adding upgrade-insecure-requests once you have HTTPS in place for production\n            //csp += \"upgrade-insecure-requests;\";\n            // also an example if you need client images to be displayed from twitter\n            // csp += \"img-src 'self' https://pbs.twimg.com;\";\n\n            // once for standards compliant browsers\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Content-Security-Policy\", csp);\n            }\n            // and once again for IE\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Security-Policy\", csp);\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy\n            var referrer_policy = \"no-referrer\";\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Referrer-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Referrer-Policy\", referrer_policy);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Quickstart/TestUsers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class TestUsers\n{\n\n    static readonly object UserAddress = new\n    {\n        street_address = \"One Hacker Way\",\n        locality = \"Heidelberg\",\n        postal_code = 69118,\n        country = \"Germany\"\n    };\n\n    public static List<TestUser> Users => new List<TestUser>\n    {\n        new()\n        {\n            SubjectId = \"818727\",\n            Username = \"alice\",\n            Password = \"alice\",\n            Claims =\n            {\n                new (Name, \"Alice Smith\"),\n                new (GivenName, \"Alice\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"AliceSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://alice.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        },\n        new()\n        {\n            SubjectId = \"88421113\",\n            Username = \"bob\",\n            Password = \"bob\",\n            Claims =\n            {\n                new (Name, \"Bob Smith\"),\n                new (GivenName, \"Bob\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"BobSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://bob.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        }\n    };\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Account/AccessDenied.cshtml",
    "content": "﻿\n<div class=\"container\">\n    <div class=\"lead\">\n        <h1>Access Denied</h1>\n        <p>You do not have access to that resource.</p>\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Account/LoggedOut.cshtml",
    "content": "﻿@model LoggedOutViewModel\n\n@{ \n    // set this so the layout rendering sees an anonymous user\n    ViewData[\"signed-out\"] = true;\n}\n\n<div class=\"logged-out-page\">\n    <h1>\n        Logout\n        <small>You are now logged out</small>\n    </h1>\n\n    @if (Model.PostLogoutRedirectUri != null)\n    {\n        <div>\n            Click <a class=\"PostLogoutRedirectUri\" href=\"@Model.PostLogoutRedirectUri\">here</a> to return to the\n            <span>@Model.ClientName</span> application.\n        </div>\n    }\n\n    @if (Model.SignOutIframeUrl != null)\n    {\n        <iframe width=\"0\" height=\"0\" class=\"signout\" src=\"@Model.SignOutIframeUrl\"></iframe>\n    }\n</div>\n\n@section scripts\n{\n    @if (Model.AutomaticRedirectAfterSignOut)\n    {\n        <script src=\"~/js/signout-redirect.js\"></script>\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Account/Login.cshtml",
    "content": "@model LoginViewModel\n\n<div class=\"login-page\">\n    <div class=\"lead\">\n        <h1>Login</h1>\n        <p>Choose how to login</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n\n        @if (Model.EnableLocalLogin)\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>Local Account</h2>\n                    </div>\n\n                    <div class=\"card-body\">\n                        <form asp-route=\"Login\">\n                            <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n\n                            <div class=\"form-group\">\n                                <label asp-for=\"Username\"></label>\n                                <input class=\"form-control\" placeholder=\"Username\" asp-for=\"Username\" autofocus>\n                            </div>\n                            <div class=\"form-group\">\n                                <label asp-for=\"Password\"></label>\n                                <input type=\"password\" class=\"form-control\" placeholder=\"Password\" asp-for=\"Password\" autocomplete=\"off\">\n                            </div>\n                            @if (Model.AllowRememberLogin)\n                            {\n                                <div class=\"form-group\">\n                                    <div class=\"form-check\">\n                                        <input class=\"form-check-input\" asp-for=\"RememberLogin\">\n                                        <label class=\"form-check-label\" asp-for=\"RememberLogin\">\n                                            Remember My Login\n                                        </label>\n                                    </div>\n                                </div>\n                            }\n                            <button class=\"btn btn-primary\" name=\"button\" value=\"login\">Login</button>\n                            <button class=\"btn btn-secondary\" name=\"button\" value=\"cancel\" formaction=\"/Account/LoginCancel\">Cancel</button>\n                        </form>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>External Account</h2>\n                    </div>\n                    <div class=\"card-body\">\n                        <ul class=\"list-inline\">\n                            @foreach (var provider in Model.VisibleExternalProviders)\n                            {\n                                <li class=\"list-inline-item\">\n                                    <a class=\"btn btn-secondary\"\n                                       asp-controller=\"External\"\n                                       asp-action=\"Challenge\"\n                                       asp-route-scheme=\"@provider.AuthenticationScheme\"\n                                       asp-route-returnUrl=\"@Model.ReturnUrl\">\n                                        @provider.DisplayName\n                                    </a>\n                                </li>\n                            }\n                        </ul>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (!Model.EnableLocalLogin && !Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"alert alert-warning\">\n                <strong>Invalid login request</strong>\n                There are no login schemes configured for this request.\n            </div>\n        }\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Account/Logout.cshtml",
    "content": "﻿@model LogoutViewModel\n\n<div class=\"logout-page\">\n    <div class=\"lead\">\n        <h1>Logout</h1>\n        <p>Would you like to logout of IdentityServer?</p>\n    </div>\n\n    <form asp-action=\"Logout\">\n        <input type=\"hidden\" name=\"logoutId\" value=\"@Model.LogoutId\"  />\n        <div class=\"form-group\">\n            <button class=\"btn btn-primary\">Yes</button>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Consent/Index.cshtml",
    "content": "@model ConsentViewModel\n\n<div class=\"page-consent\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Index\">\n        <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Device/Success.cshtml",
    "content": "\n<div class=\"page-device-success\">\n    <div class=\"lead\">\n        <h1>Success</h1>\n        <p>You have successfully authorized the device</p>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Device/UserCodeCapture.cshtml",
    "content": "@model string\n\n<div class=\"page-device-code\">\n    <div class=\"lead\">\n        <h1>User Code</h1>\n        <p>Please enter the code displayed on your device.</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <form asp-action=\"UserCodeCapture\">\n                <div class=\"form-group\">\n                    <label for=\"userCode\">User Code:</label>\n                    <input class=\"form-control\" for=\"userCode\" name=\"userCode\" autofocus />\n                </div>\n\n                <button class=\"btn btn-primary\" name=\"button\">Submit</button>\n            </form>\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Device/UserCodeConfirmation.cshtml",
    "content": "@model DeviceAuthorizationViewModel\n\n<div class=\"page-device-confirmation\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        @if (Model.ConfirmUserCode)\n        {\n            <p>Please confirm that the authorization request quotes the code: <strong>@Model.UserCode</strong>.</p>\n        }\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Callback\">\n        <input asp-for=\"UserCode\" type=\"hidden\" value=\"@Model.UserCode\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Diagnostics/Index.cshtml",
    "content": "@model DiagnosticsViewModel\n\n<div class=\"diagnostics-page\">\n    <div class=\"lead\">\n        <h1>Authentication Cookie</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Claims</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var claim in Model.AuthenticateResult.Principal.Claims)\n                        {\n                            <dt>@claim.Type</dt>\n                            <dd>@claim.Value</dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n        \n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Properties</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var prop in Model.AuthenticateResult.Properties.Items)\n                        {\n                            <dt>@prop.Key</dt>\n                            <dd>@prop.Value</dd>\n                        }\n                        @if (Model.Clients.Any())\n                        {\n                            <dt>Clients</dt>\n                            <dd>\n                            @{\n                                var clients = Model.Clients.ToArray();\n                                for(var i = 0; i < clients.Length; i++)\n                                {\n                                    <text>@clients[i]</text>\n                                    if (i < clients.Length - 1)\n                                    {\n                                        <text>, </text>\n                                    }\n                                }\n                            }\n                            </dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n    </div>\n</div>\n\n\n\n\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Grants/Index.cshtml",
    "content": "﻿@model GrantsViewModel\n\n<div class=\"grants-page\">\n    <div class=\"lead\">\n        <h1>Client Application Permissions</h1>\n        <p>Below is the list of applications you have given permission to and the resources they have access to.</p>\n    </div>\n\n    @if (Model.Grants.Any() == false)\n    {\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                <div class=\"alert alert-info\">\n                    You have not given access to any applications\n                </div>\n            </div>\n        </div>\n    }\n    else\n    {\n        foreach (var grant in Model.Grants)\n        {\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <div class=\"row\">\n                        <div class=\"col-sm-8 card-title\">\n                            @if (grant.ClientLogoUrl != null)\n                            {\n                                <img src=\"@grant.ClientLogoUrl\">\n                            }\n                            <strong>@grant.ClientName</strong>\n                        </div>\n\n                        <div class=\"col-sm-2\">\n                            <form asp-action=\"Revoke\">\n                                <input type=\"hidden\" name=\"clientId\" value=\"@grant.ClientId\">\n                                <button class=\"btn btn-danger\">Revoke Access</button>\n                            </form>\n                        </div>\n                    </div>\n                </div>\n                \n                <ul class=\"list-group list-group-flush\">\n                    @if (grant.Description != null)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Description:</label> @grant.Description\n                        </li>   \n                    }\n                    <li class=\"list-group-item\">\n                        <label>Created:</label> @grant.Created.ToString(\"yyyy-MM-dd\")\n                    </li>\n                    @if (grant.Expires.HasValue)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Expires:</label> @grant.Expires.Value.ToString(\"yyyy-MM-dd\")\n                        </li>\n                    }\n                    @if (grant.IdentityGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Identity Grants</label>\n                            <ul>\n                                @foreach (var name in grant.IdentityGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                    @if (grant.ApiGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>API Grants</label>\n                            <ul>\n                                @foreach (var name in grant.ApiGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                </ul>\n            </div>\n        }\n    }\n</div>"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Home/Index.cshtml",
    "content": "@using System.Diagnostics\n\n@{\n    var version = FileVersionInfo.GetVersionInfo(typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.Location).ProductVersion.Split('+').First();\n}\n\n<div class=\"welcome-page\">\n    <h1>\n        <img src=\"~/icon.jpg\">\n        Welcome to IdentityServer8\n        <small class=\"text-muted\">(version @version)</small>\n    </h1>\n\n    <ul>\n        <li>\n            IdentityServer publishes a\n            <a href=\"~/.well-known/openid-configuration\">discovery document</a>\n            where you can find metadata and links to all the endpoints, key material, etc.\n        </li>\n        <li>\n            Click <a href=\"~/diagnostics\">here</a> to see the claims for your current session.\n        </li>\n        <li>\n            Click <a href=\"~/grants\">here</a> to manage your stored grants.\n        </li>\n        <li>\n            Here are links to the\n            <a href=\"https://github.com/alexhiggins732/IdentityServer8\">source code repository</a>,\n            and <a href=\"https://github.com/alexhiggins732/IdentityServer8/tree/main/samples\">ready to use samples</a>.\n        </li>\n    </ul>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Shared/Error.cshtml",
    "content": "@model ErrorViewModel\n\n@{\n    var error = Model?.Error?.Error;\n    var errorDescription = Model?.Error?.ErrorDescription;\n    var request_id = Model?.Error?.RequestId;\n}\n\n<div class=\"error-page\">\n    <div class=\"lead\">\n        <h1>Error</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <div class=\"alert alert-danger\">\n                Sorry, there was an error\n\n                @if (error != null)\n                {\n                    <strong>\n                        <em>\n                            : @error\n                        </em>\n                    </strong>\n\n                    if (errorDescription != null)\n                    {\n                        <div>@errorDescription</div>\n                    }\n                }\n            </div>\n\n            @if (request_id != null)\n            {\n                <div class=\"request-id\">Request Id: @request_id</div>\n            }\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Shared/Redirect.cshtml",
    "content": "@model RedirectViewModel\n@using Microsoft.Extensions.DependencyInjection;\n<div class=\"redirect-page\">\n    <div class=\"lead\">\n        <h1>You are now being returned to the application</h1>\n        <p>Once complete, you may close this tab.</p>\n    </div>\n</div>\n\n<meta http-equiv=\"refresh\" content=\"0;url=@Model.RedirectUrl\" data-url=\"@Model.RedirectUrl\">\n<script>\n    var url = '@Ioc.Sanitizer.Url.Sanitize(Model.RedirectUrl)';\n    window.location.href = url;\n</script>\n\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0, shrink-to-fit=no\" />\n\n    <title>IdentityServer8</title>\n    \n    <link rel=\"icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    <link rel=\"shortcut icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    \n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <partial name=\"_Nav\" />\n   \n    <div class=\"container body-container\">\n        @RenderBody()\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.slim.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Shared/_Nav.cshtml",
    "content": "@using IdentityServer8.Extensions\n\n@{\n    string name = null;\n    if (!true.Equals(ViewData[\"signed-out\"]))\n    {\n        name = Context.User?.GetDisplayName();\n    }\n}\n\n<div class=\"nav-page\">\n    <nav class=\"navbar navbar-expand-lg navbar-dark bg-dark\">\n\n        <a href=\"~/\" class=\"navbar-brand\">\n            <img src=\"~/icon.png\" class=\"icon-banner\">\n            IdentityServer8\n        </a>\n\n        @if (!string.IsNullOrWhiteSpace(name))\n        {\n            <ul class=\"navbar-nav mr-auto\">\n                <li class=\"nav-item dropdown\">\n                    <a href=\"#\" class=\"nav-link dropdown-toggle\" data-toggle=\"dropdown\">@name <b class=\"caret\"></b></a>\n                    \n                    <div class=\"dropdown-menu\">\n                        <a class=\"dropdown-item\" asp-action=\"Logout\" asp-controller=\"Account\">Logout</a>\n                    </div>\n              </li>\n            </ul>\n        }\n    \n    </nav>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Shared/_ScopeListItem.cshtml",
    "content": "﻿@model ScopeViewModel\n\n<li class=\"list-group-item\">\n    <label>\n        <input class=\"consent-scopecheck\"\n               type=\"checkbox\"\n               name=\"ScopesConsented\"\n               id=\"scopes_@Model.Value\"\n               value=\"@Model.Value\"\n               checked=\"@Model.Checked\"\n               disabled=\"@Model.Required\" />\n        @if (Model.Required)\n        {\n            <input type=\"hidden\"\n                   name=\"ScopesConsented\"\n                   value=\"@Model.Value\" />\n        }\n        <strong>@Model.DisplayName</strong>\n        @if (Model.Emphasize)\n        {\n            <span class=\"glyphicon glyphicon-exclamation-sign\"></span>\n        }\n    </label>\n    @if (Model.Required)\n    {\n        <span><em>(required)</em></span>\n    }\n    @if (Model.Description != null)\n    {\n        <div class=\"consent-description\">\n            <label for=\"scopes_@Model.Value\">@Model.Description</label>\n        </div>\n    }\n</li>"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/Shared/_ValidationSummary.cshtml",
    "content": "﻿@if (ViewContext.ModelState.IsValid == false)\n{\n    <div class=\"alert alert-danger\">\n        <strong>Error</strong>\n        <div asp-validation-summary=\"All\" class=\"danger\"></div>\n    </div>\n}"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/_ViewImports.cshtml",
    "content": "﻿@using IdentityServerHost.Quickstart.UI\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/wwwroot/css/site.css",
    "content": "﻿.body-container {\n  margin-top: 60px;\n  padding-bottom: 40px; }\n\n.welcome-page li {\n  list-style: none;\n  padding: 4px; }\n\n.logged-out-page iframe {\n  display: none;\n  width: 0;\n  height: 0; }\n\n.grants-page .card {\n  margin-top: 20px;\n  border-bottom: 1px solid lightgray; }\n  .grants-page .card .card-title {\n    font-size: 120%;\n    font-weight: bold; }\n    .grants-page .card .card-title img {\n      width: 100px;\n      height: 100px; }\n  .grants-page .card label {\n    font-weight: bold; }\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/wwwroot/css/site.scss",
    "content": "﻿.body-container {\n    margin-top: 60px;\n    padding-bottom:40px;\n}\n\n.welcome-page {\n    li {\n        list-style: none;\n        padding: 4px;\n    }\n}\n\n.logged-out-page {\n    iframe {\n        display: none;\n        width: 0;\n        height: 0;\n    }\n}\n\n.grants-page {\n    .card {\n        margin-top: 20px;\n        border-bottom: 1px solid lightgray;\n\n        .card-title {\n            img {\n                width: 100px;\n                height: 100px;\n            }\n\n            font-size: 120%;\n            font-weight: bold;\n        }\n\n        label {\n            font-weight: bold;\n        }\n    }\n}\n\n\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/wwwroot/js/signin-redirect.js",
    "content": "//window.location.href = document.querySelector(\"meta[http-equiv=refresh]\").getAttribute(\"data-url\");\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/IdentityServer/wwwroot/js/signout-redirect.js",
    "content": "﻿window.addEventListener(\"load\", function () {\n    var a = document.querySelector(\"a.PostLogoutRedirectUri\");\n    if (a) {\n        window.location = a.href;\n    }\n});\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly ILogger<HomeController> _logger;\n\n    public HomeController(ILogger<HomeController> logger)\n    {\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    public async Task<IActionResult> CallApi()\n    {\n        var accessToken = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = new HttpClient();\n        client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue(\"Bearer\", accessToken);\n        var content = await client.GetStringAsync(\"https://localhost:6001/identity\");\n\n        var obj = JsonSerializer.Deserialize<JsonElement>(content);\n        ViewBag.Json = obj.ToString();\n        return View(\"json\");\n    }\n\n    public IActionResult Logout()\n    {\n        return SignOut(\"Cookies\", \"oidc\");\n    }\n\n    [ResponseCache(Duration = 0, Location = ResponseCacheLocation.None, NoStore = true)]\n    public IActionResult Error()\n    {\n        return View(new ErrorViewModel { RequestId = Activity.Current?.Id ?? HttpContext.TraceIdentifier });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using System.Diagnostics;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Net.Http.Headers;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Models/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class ErrorViewModel\n{\n    public string RequestId { get; set; }\n\n    public bool ShowRequestId => !string.IsNullOrEmpty(RequestId);\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/MvcClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <Content Update=\"Views\\Shared\\Json.cshtml\">\n      <ExcludeFromSingleFile>true</ExcludeFromSingleFile>\n      <CopyToPublishDirectory>PreserveNewest</CopyToPublishDirectory>\n    </Content>\n  </ItemGroup>\n\n</Project>"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nJwtSecurityTokenHandler.DefaultMapInboundClaims = false;\n\n\nvar builder = WebApplication.CreateBuilder(args);\n\nbuilder.Services.AddControllersWithViews();\nbuilder.Services\n    .AddAuthentication(options =>\n    {\n        options.DefaultScheme = \"Cookies\";\n        options.DefaultChallengeScheme = \"oidc\";\n    })\n    .AddCookie(\"Cookies\")\n    .AddOpenIdConnect(\"oidc\", options =>\n    {\n        options.Authority = \"https://localhost:5001\";\n\n        options.ClientId = \"mvc\";\n        options.ClientSecret = \"secret\";\n        options.ResponseType = \"code\";\n\n        options.Scope.Add(\"api1\");\n\n        options.SaveTokens = true;\n    });\n\n\nusing (var app = builder.Build())\n{\n    if (app.Environment.IsDevelopment())\n        app.UseDeveloperExceptionPage();\n    else\n        app.UseExceptionHandler(\"/Home/Error\");\n\n    app.UseStaticFiles();\n    app.UseRouting();\n    app.UseAuthentication();\n    app.UseAuthorization();\n    app.MapDefaultControllerRoute().RequireAuthorization();\n\n    await app.RunAsync();\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"MvcClient\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5002\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Views/Home/Index.cshtml",
    "content": "@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Views/Home/Privacy.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Privacy Policy\";\n}\n<h1>@ViewData[\"Title\"]</h1>\n\n<p>Use this page to detail your site's privacy policy.</p>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Views/Shared/Error.cshtml",
    "content": "﻿@model ErrorViewModel\n@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n\n@if (Model.ShowRequestId)\n{\n    <p>\n        <strong>Request ID:</strong> <code>@Model.RequestId</code>\n    </p>\n}\n\n<h3>Development Mode</h3>\n<p>\n    Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.\n</p>\n<p>\n    <strong>The Development environment shouldn't be enabled for deployed applications.</strong>\n    It can result in displaying sensitive information from exceptions to end users.\n    For local debugging, enable the <strong>Development</strong> environment by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>\n    and restarting the app.\n</p>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcClient</title>\n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <header>\n        <nav class=\"navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3\">\n            <div class=\"container\">\n                <a class=\"navbar-brand\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">MvcClient</a>\n                <button class=\"navbar-toggler\" type=\"button\" data-toggle=\"collapse\" data-target=\".navbar-collapse\" aria-controls=\"navbarSupportedContent\"\n                        aria-expanded=\"false\" aria-label=\"Toggle navigation\">\n                    <span class=\"navbar-toggler-icon\"></span>\n                </button>\n                <div class=\"navbar-collapse collapse d-sm-inline-flex flex-sm-row-reverse\">\n                    <ul class=\"navbar-nav flex-grow-1\">\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">Home</a>\n                        </li>\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Logout\">Logout</a>\n                        </li>\n                    </ul>\n                </div>\n            </div>\n        </nav>\n    </header>\n    <div class=\"container\">\n        <main role=\"main\" class=\"pb-3\">\n            @RenderBody()\n        </main>\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n    <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    @RenderSection(\"Scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Views/Shared/_ValidationScriptsPartial.cshtml",
    "content": "﻿<script src=\"~/lib/jquery-validation/dist/jquery.validate.min.js\"></script>\n<script src=\"~/lib/jquery-validation-unobtrusive/jquery.validate.unobtrusive.min.js\"></script>\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Views/Shared/json.cshtml",
    "content": "<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/appsettings.Development.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Debug\",\n      \"System\": \"Information\",\n      \"Microsoft\": \"Information\"\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/appsettings.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Information\",\n      \"Microsoft\": \"Warning\",\n      \"Microsoft.Hosting.Lifetime\": \"Information\"\n    }\n  },\n  \"AllowedHosts\": \"*\"\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/wwwroot/css/site.css",
    "content": "﻿/* Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\nfor details on configuring this project to bundle and minify static web assets. */\n\na.navbar-brand {\n  white-space: normal;\n  text-align: center;\n  word-break: break-all;\n}\n\n/* Provide sufficient contrast against white background */\na {\n  color: #0366d6;\n}\n\n.btn-primary {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n.nav-pills .nav-link.active, .nav-pills .show > .nav-link {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  font-size: 14px;\n}\n@media (min-width: 768px) {\n  html {\n    font-size: 16px;\n  }\n}\n\n.border-top {\n  border-top: 1px solid #e5e5e5;\n}\n.border-bottom {\n  border-bottom: 1px solid #e5e5e5;\n}\n\n.box-shadow {\n  box-shadow: 0 .25rem .75rem rgba(0, 0, 0, .05);\n}\n\nbutton.accept-policy {\n  font-size: 1rem;\n  line-height: inherit;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  position: relative;\n  min-height: 100%;\n}\n\nbody {\n  /* Margin bottom by footer height */\n  margin-bottom: 60px;\n}\n.footer {\n  position: absolute;\n  bottom: 0;\n  width: 100%;\n  white-space: nowrap;\n  line-height: 60px; /* Vertically center the text there */\n}\n"
  },
  {
    "path": "samples/Quickstarts/3_AspNetCoreAndApis/src/MvcClient/wwwroot/js/site.js",
    "content": "﻿// Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\n// for details on configuring this project to bundle and minify static web assets.\n\n// Write your JavaScript code.\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/Quickstart.sln",
    "content": "﻿\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 15.0.26124.0\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{BD8BA25C-A91D-419D-99B6-B575ADD6D061}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer\", \"src\\IdentityServer\\IdentityServer.csproj\", \"{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcClient\", \"src\\MvcClient\\MvcClient.csproj\", \"{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"JavaScriptClient\", \"src\\JavaScriptClient\\JavaScriptClient.csproj\", \"{DD8D4022-0073-40EE-84F0-8E4833522BB9}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Api\", \"..\\Shared\\src\\Api\\Api.csproj\", \"{8D0EA8BB-7B55-4F60-8011-EF220103BADB}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Client\", \"..\\Shared\\src\\Client\\Client.csproj\", \"{8FC8CFB9-740B-4D13-B396-99283AA758AC}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tDebug|x64 = Debug|x64\n\t\tDebug|x86 = Debug|x86\n\t\tRelease|Any CPU = Release|Any CPU\n\t\tRelease|x64 = Release|x64\n\t\tRelease|x86 = Release|x86\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x64.Build.0 = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x86.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x64.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x86.Build.0 = Release|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Release|x64.Build.0 = Release|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9}.Release|x86.Build.0 = Release|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Release|x64.Build.0 = Release|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{8D0EA8BB-7B55-4F60-8011-EF220103BADB}.Release|x86.Build.0 = Release|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Release|x64.Build.0 = Release|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{8FC8CFB9-740B-4D13-B396-99283AA758AC}.Release|x86.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\t\t{DD8D4022-0073-40EE-84F0-8E4833522BB9} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {84D5AF06-1243-46F1-9D58-70ED572832C3}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/Quickstart.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft\n Written by Alexander Higgins https://github.com/alexhiggins732/ \n \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code for this software can be found at https://github.com/alexhiggins732/IdentityServer8\n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n\n*/\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Config.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Secret = IdentityServer8.Models.Secret;\n\npublic static class Config\n{\n    public static IEnumerable<IdentityResource> IdentityResources =>\n        new List<IdentityResource>\n        {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n        };\n\n\n    public static IEnumerable<ApiScope> ApiScopes =>\n        new List<ApiScope>\n        {\n            new ApiScope(\"api1\", \"My API\")\n        };\n\n    public static IEnumerable<Client> Clients =>\n        new List<Client>\n        {\n            // machine to machine client\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                // scopes that client has access to\n                AllowedScopes = { \"api1\" }\n            },\n            \n            // interactive ASP.NET Core MVC client\n            new Client\n            {\n                ClientId = \"mvc\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.Code,\n                \n                // where to redirect to after login\n                RedirectUris = { \"https://localhost:5002/signin-oidc\" },\n\n                // where to redirect to after logout\n                PostLogoutRedirectUris = { \"https://localhost:5002/signout-callback-oidc\" },\n\n                AllowedScopes = new List<string>\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    \"api1\"\n                }\n            }\n        };\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.Configuration;\nglobal using IdentityServer8.Events;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Test;\nglobal using IdentityServer8.Validation;\nglobal using IdentityServerHost.Quickstart.UI;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Hosting;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.AspNetCore.Mvc.Filters;\nglobal using Microsoft.Extensions.Hosting;\nglobal using Microsoft.Extensions.Options;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\nglobal using System;\nglobal using System.ComponentModel.DataAnnotations;\nglobal using System.Security.Claims;\nglobal using System.Text;\nglobal using System.Text.Json;\nglobal using static IdentityModel.JwtClaimTypes;\nglobal using IdentityServerClaimValueTypes = IdentityServer8.IdentityServerConstants.ClaimValueTypes;"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/IdentityServer.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"HigginsSoft.IdentityServer8\" />\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />  \n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.Google\" />\n  </ItemGroup>\n</Project>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConfigureLogger();\n\ntry\n{\n    Log.Information(\"Starting host...\");\n\n    var builder = WebApplication.CreateBuilder(args);\n\n    var services = builder.Services;\n\n    services.AddControllersWithViews();\n\n    services\n        .AddIdentityServer()\n        .AddInMemoryIdentityResources(Config.IdentityResources)\n        .AddInMemoryApiScopes(Config.ApiScopes)\n        .AddInMemoryClients(Config.Clients)\n        .AddTestUsers(TestUsers.Users)\n        .AddDeveloperSigningCredential();\n\n    services.AddAuthentication()\n        .AddGoogle(\"Google\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n            options.ClientId = \"<insert here>\";\n            options.ClientSecret = \"<insert here>\";\n        })\n        .AddOpenIdConnect(\"oidc\", \"Demo IdentityServer\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n            options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n            options.SaveTokens = true;\n\n            options.Authority = \"https://demo.identityserver8.io/\";\n            options.ClientId = \"interactive.confidential\";\n            options.ClientSecret = \"secret\";\n            options.ResponseType = \"code\";\n\n            options.TokenValidationParameters = new()\n            {\n                NameClaimType = \"name\",\n                RoleClaimType = \"role\"\n            };\n        });\n\n\n    using (var app = builder.Build())\n    {\n        if (app.Environment.IsDevelopment())\n            app.UseDeveloperExceptionPage();\n\n        app.UseStaticFiles()\n            .UseRouting()\n            .UseIdentityServer()\n            .UseAuthorization();\n\n        app.MapDefaultControllerRoute();\n\n        await app.RunAsync();\n    }\n\n    return 0;\n}\ncatch (Exception ex)\n{\n    Log.Fatal(ex, \"Host terminated unexpectedly.\");\n    return 1;\n}\nfinally\n{\n    Log.CloseAndFlush();\n}\n\n\nvoid ConfigureLogger() => Log.Logger = new LoggerConfiguration()\n    .MinimumLevel.Debug()\n    .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n    .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n    .Enrich.FromLogContext()\n    // uncomment to write to Azure diagnostics stream\n    //.WriteTo.File(\n    //    @\"D:\\home\\LogFiles\\Application\\identityserver.txt\",\n    //    fileSizeLimitBytes: 1_000_000,\n    //    rollOnFileSizeLimit: true,\n    //    shared: true,\n    //    flushToDiskInterval: TimeSpan.FromSeconds(1))\n    .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n    .CreateLogger();\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"SelfHost\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Account/AccountController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller implements a typical login/logout/provision workflow for local and external accounts.\n/// The login service encapsulates the interactions with the user data store. This data store is in-memory only and cannot be used for production!\n/// The interaction service provides a way for the UI to communicate with identityserver for validation and context retrieval\n/// </summary>\n[SecurityHeaders]\n[AllowAnonymous]\npublic class AccountController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly IAuthenticationSchemeProvider _schemeProvider;\n    private readonly IEventService _events;\n\n    public AccountController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IAuthenticationSchemeProvider schemeProvider,\n        IEventService events,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _schemeProvider = schemeProvider;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Entry point into the login workflow\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Login(string returnUrl)\n    {\n        // build a model so we know what to show on the login page\n        var vm = await BuildLoginViewModelAsync(returnUrl);\n\n        if (vm.IsExternalLoginOnly)\n        {\n            // we only have one option for logging in and it's an external provider\n            return returnUrl.IsAllowedRedirect() ? RedirectToAction(\"Challenge\", \"External\", new { scheme = vm.ExternalLoginScheme, returnUrl = returnUrl.SanitizeForRedirect() }) : Forbid();\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Login(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (ModelState.IsValid)\n        {\n            // validate username/password against in-memory store\n            if (_users.ValidateCredentials(model.Username, model.Password))\n            {\n                var user = _users.FindByUsername(model.Username);\n                await _events.RaiseAsync(new UserLoginSuccessEvent(user.Username, user.SubjectId, user.Username, clientId: context?.Client.ClientId));\n\n                // only set explicit expiration here if user chooses \"remember me\". \n                // otherwise we rely upon expiration configured in cookie middleware.\n                AuthenticationProperties props = null;\n                if (AccountOptions.AllowRememberLogin && model.RememberLogin)\n                {\n                    props = new AuthenticationProperties\n                    {\n                        IsPersistent = true,\n                        ExpiresUtc = DateTimeOffset.UtcNow.Add(AccountOptions.RememberMeLoginDuration)\n                    };\n                };\n\n                // issue authentication cookie with subject ID and username\n                var isuser = new IdentityServerUser(user.SubjectId)\n                {\n                    DisplayName = user.Username\n                };\n\n                await HttpContext.SignInAsync(isuser, props);\n\n                if (context != null)\n                {\n                    if (context.IsNativeClient())\n                    {\n                        // The client is native, so this change in how to\n                        // return the response is for better UX for the end user.\n                        return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                    }\n\n                    // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n\n                // request for a local page\n                if (Url.IsLocalUrl(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n                else if (string.IsNullOrEmpty(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n                }\n                else\n                {\n                    // user might have clicked on a malicious link - should be logged\n                    throw new Exception(\"invalid return URL\");\n                }\n            }\n\n            await _events.RaiseAsync(new UserLoginFailureEvent(model.Username, \"invalid credentials\", clientId: context?.Client.ClientId));\n            ModelState.AddModelError(string.Empty, AccountOptions.InvalidCredentialsErrorMessage);\n        }\n\n        // something went wrong, show form with error\n        var vm = await BuildLoginViewModelAsync(model);\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> LoginCancel(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (context != null)\n        {\n            // if the user cancels, send a result back into IdentityServer as if they \n            // denied the consent (even if this client does not require consent).\n            // this will send back an access denied OIDC error response to the client.\n            await _interaction.DenyAuthorizationAsync(context, AuthorizationError.AccessDenied);\n\n            // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n            }\n\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n        }\n        else\n        {\n            // since we don't have a valid context, then we just go back to the home page\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n        }\n\n    }\n\n    /// <summary>\n    /// Show logout page\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Logout(string logoutId)\n    {\n        // build a model so the logout page knows what to display\n        var vm = await BuildLogoutViewModelAsync(logoutId);\n\n        if (vm.ShowLogoutPrompt == false)\n        {\n            // if the request for logout was properly authenticated from IdentityServer, then\n            // we don't need to show the prompt and can just log the user out directly.\n            return await Logout(vm);\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle logout page postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Logout(LogoutInputModel model)\n    {\n        // build a model so the logged out page knows what to display\n        var vm = await BuildLoggedOutViewModelAsync(model.LogoutId);\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            // delete local authentication cookie\n            await HttpContext.SignOutAsync();\n\n            // raise the logout event\n            await _events.RaiseAsync(new UserLogoutSuccessEvent(User.GetSubjectId(), User.GetDisplayName()));\n        }\n\n        // check if we need to trigger sign-out at an upstream identity provider\n        if (vm.TriggerExternalSignout)\n        {\n            // build a return URL so the upstream provider will redirect back\n            // to us after the user has logged out. this allows us to then\n            // complete our single sign-out processing.\n            string url = Url.Action(\"Logout\", new { logoutId = vm.LogoutId });\n\n            // this triggers a redirect to the external provider for sign-out\n            return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);\n        }\n\n        return View(\"LoggedOut\", vm);\n    }\n\n    [HttpGet]\n    public IActionResult AccessDenied()\n    {\n        return View();\n    }\n\n\n    /*****************************************/\n    /* helper APIs for the AccountController */\n    /*****************************************/\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(string returnUrl)\n    {\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (context?.IdP != null && await _schemeProvider.GetSchemeAsync(context.IdP) != null)\n        {\n            var local = context.IdP == IdentityServer8.IdentityServerConstants.LocalIdentityProvider;\n\n            // this is meant to short circuit the UI and only trigger the one external IdP\n            var vm = new LoginViewModel\n            {\n                EnableLocalLogin = local,\n                ReturnUrl = returnUrl,\n                Username = context?.LoginHint,\n            };\n\n            if (!local)\n            {\n                vm.ExternalProviders = new[] { new ExternalProvider { AuthenticationScheme = context.IdP } };\n            }\n\n            return vm;\n        }\n\n        var schemes = await _schemeProvider.GetAllSchemesAsync();\n\n        var providers = schemes\n            .Where(x => x.DisplayName != null)\n            .Select(x => new ExternalProvider\n            {\n                DisplayName = x.DisplayName ?? x.Name,\n                AuthenticationScheme = x.Name\n            }).ToList();\n\n        var allowLocal = true;\n        if (context?.Client.ClientId != null)\n        {\n            var client = await _clientStore.FindEnabledClientByIdAsync(context.Client.ClientId);\n            if (client != null)\n            {\n                allowLocal = client.EnableLocalLogin;\n\n                if (client.IdentityProviderRestrictions != null && client.IdentityProviderRestrictions.Any())\n                {\n                    providers = providers.Where(provider => client.IdentityProviderRestrictions.Contains(provider.AuthenticationScheme)).ToList();\n                }\n            }\n        }\n\n        return new LoginViewModel\n        {\n            AllowRememberLogin = AccountOptions.AllowRememberLogin,\n            EnableLocalLogin = allowLocal && AccountOptions.AllowLocalLogin,\n            ReturnUrl = returnUrl,\n            Username = context?.LoginHint,\n            ExternalProviders = providers.ToArray()\n        };\n    }\n\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(LoginInputModel model)\n    {\n        var vm = await BuildLoginViewModelAsync(model.ReturnUrl);\n        vm.Username = model.Username;\n        vm.RememberLogin = model.RememberLogin;\n        return vm;\n    }\n\n    private async Task<LogoutViewModel> BuildLogoutViewModelAsync(string logoutId)\n    {\n        var vm = new LogoutViewModel { LogoutId = logoutId, ShowLogoutPrompt = AccountOptions.ShowLogoutPrompt };\n\n        if (User?.Identity.IsAuthenticated != true)\n        {\n            // if the user is not authenticated, then just show logged out page\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        var context = await _interaction.GetLogoutContextAsync(logoutId);\n        if (context?.ShowSignoutPrompt == false)\n        {\n            // it's safe to automatically sign-out\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        // show the logout prompt. this prevents attacks where the user\n        // is automatically signed out by another malicious web page.\n        return vm;\n    }\n\n    private async Task<LoggedOutViewModel> BuildLoggedOutViewModelAsync(string logoutId)\n    {\n        // get context information (client name, post logout redirect URI and iframe for federated signout)\n        var logout = await _interaction.GetLogoutContextAsync(logoutId);\n\n        var vm = new LoggedOutViewModel\n        {\n            AutomaticRedirectAfterSignOut = AccountOptions.AutomaticRedirectAfterSignOut,\n            PostLogoutRedirectUri = logout?.PostLogoutRedirectUri,\n            ClientName = string.IsNullOrEmpty(logout?.ClientName) ? logout?.ClientId : logout?.ClientName,\n            SignOutIframeUrl = logout?.SignOutIFrameUrl,\n            LogoutId = logoutId\n        };\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            var idp = User.FindFirst(JwtClaimTypes.IdentityProvider)?.Value;\n            if (idp != null && idp != IdentityServer8.IdentityServerConstants.LocalIdentityProvider)\n            {\n                var providerSupportsSignout = await HttpContext.GetSchemeSupportsSignOutAsync(idp);\n                if (providerSupportsSignout)\n                {\n                    if (vm.LogoutId == null)\n                    {\n                        // if there's no current logout context, we need to create one\n                        // this captures necessary info from the current logged in user\n                        // before we signout and redirect away to the external IdP for signout\n                        vm.LogoutId = await _interaction.CreateLogoutContextAsync();\n                    }\n\n                    vm.ExternalAuthenticationScheme = idp;\n                }\n            }\n        }\n\n        return vm;\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Account/AccountOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI\n{\n    public class AccountOptions\n    {\n        public static bool AllowLocalLogin = true;\n        public static bool AllowRememberLogin = true;\n        public static TimeSpan RememberMeLoginDuration = TimeSpan.FromDays(30);\n\n        public static bool ShowLogoutPrompt = true;\n        public static bool AutomaticRedirectAfterSignOut = false;\n\n        public static string InvalidCredentialsErrorMessage = \"Invalid username or password\";\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Account/ExternalController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class ExternalController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly ILogger<ExternalController> _logger;\n    private readonly IEventService _events;\n\n    public ExternalController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IEventService events,\n        ILogger<ExternalController> logger,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _logger = logger;\n        _events = events;\n    }\n\n    /// <summary>\n    /// initiate roundtrip to external authentication provider\n    /// </summary>\n    [HttpGet]\n    public IActionResult Challenge(string scheme, string returnUrl)\n    {\n        if (string.IsNullOrEmpty(returnUrl)) returnUrl = \"~/\";\n\n        // validate returnUrl - either it is a valid OIDC URL or back to a local page\n        if (Url.IsLocalUrl(returnUrl) == false && _interaction.IsValidReturnUrl(returnUrl) == false)\n        {\n            // user might have clicked on a malicious link - should be logged\n            throw new Exception(\"invalid return URL\");\n        }\n        \n        // start challenge and roundtrip the return URL and scheme \n        var props = new AuthenticationProperties\n        {\n            RedirectUri = Url.Action(nameof(Callback)), \n            Items =\n            {\n                { \"returnUrl\", returnUrl }, \n                { \"scheme\", scheme },\n            }\n        };\n\n        return Challenge(props, scheme);\n        \n    }\n\n    /// <summary>\n    /// Post processing of external authentication\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Callback()\n    {\n        // read external identity from the temporary cookie\n        var result = await HttpContext.AuthenticateAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n        if (result?.Succeeded != true)\n        {\n            throw new Exception(\"External authentication error\");\n        }\n\n        if (_logger.IsEnabled(LogLevel.Debug))\n        {\n            var externalClaims = result.Principal.Claims.Select(c => $\"{c.Type}: {c.Value}\");\n            _logger.LogDebug(\"External claims: {@claims}\", externalClaims);\n        }\n\n        // lookup our user and external provider info\n        var (user, provider, providerUserId, claims) = FindUserFromExternalProvider(result);\n        if (user == null)\n        {\n            // this might be where you might initiate a custom workflow for user registration\n            // in this sample we don't show how that would be done, as our sample implementation\n            // simply auto-provisions new external user\n            user = AutoProvisionUser(provider, providerUserId, claims);\n        }\n\n        // this allows us to collect any additional claims or properties\n        // for the specific protocols used and store them in the local auth cookie.\n        // this is typically used to store data needed for signout from those protocols.\n        var additionalLocalClaims = new List<Claim>();\n        var localSignInProps = new AuthenticationProperties();\n        ProcessLoginCallback(result, additionalLocalClaims, localSignInProps);\n        \n        // issue authentication cookie for user\n        var isuser = new IdentityServerUser(user.SubjectId)\n        {\n            DisplayName = user.Username,\n            IdentityProvider = provider,\n            AdditionalClaims = additionalLocalClaims\n        };\n\n        await HttpContext.SignInAsync(isuser, localSignInProps);\n\n        // delete temporary cookie used during external authentication\n        await HttpContext.SignOutAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n        // retrieve return URL\n        var returnUrl = result.Properties.Items[\"returnUrl\"] ?? \"~/\";\n\n        // check if external login is in the context of an OIDC request\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        await _events.RaiseAsync(new UserLoginSuccessEvent(provider, providerUserId, user.SubjectId, user.Username, true, context?.Client.ClientId));\n\n        if (context != null)\n        {\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", returnUrl);\n            }\n        }\n\n        return Redirect(returnUrl);\n    }\n\n    private (TestUser user, string provider, string providerUserId, IEnumerable<Claim> claims) FindUserFromExternalProvider(AuthenticateResult result)\n    {\n        var externalUser = result.Principal;\n\n        // try to determine the unique id of the external user (issued by the provider)\n        // the most common claim type for that are the sub claim and the NameIdentifier\n        // depending on the external provider, some other claim type might be used\n        var userIdClaim = externalUser.FindFirst(JwtClaimTypes.Subject) ??\n                          externalUser.FindFirst(ClaimTypes.NameIdentifier) ??\n                          throw new Exception(\"Unknown userid\");\n\n        // remove the user id claim so we don't include it as an extra claim if/when we provision the user\n        var claims = externalUser.Claims.ToList();\n        claims.Remove(userIdClaim);\n\n        var provider = result.Properties.Items[\"scheme\"];\n        var providerUserId = userIdClaim.Value;\n\n        // find external user\n        var user = _users.FindByExternalProvider(provider, providerUserId);\n\n        return (user, provider, providerUserId, claims);\n    }\n\n    private TestUser AutoProvisionUser(string provider, string providerUserId, IEnumerable<Claim> claims)\n    {\n        var user = _users.AutoProvisionUser(provider, providerUserId, claims.ToList());\n        return user;\n    }\n\n    // if the external login is OIDC-based, there are certain things we need to preserve to make logout work\n    // this will be different for WS-Fed, SAML2p or other protocols\n    private void ProcessLoginCallback(AuthenticateResult externalResult, List<Claim> localClaims, AuthenticationProperties localSignInProps)\n    {\n        // if the external system sent a session id claim, copy it over\n        // so we can use it for single sign-out\n        var sid = externalResult.Principal.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.SessionId);\n        if (sid != null)\n        {\n            localClaims.Add(new Claim(JwtClaimTypes.SessionId, sid.Value));\n        }\n\n        // if the external provider issued an id_token, we'll keep it for signout\n        var idToken = externalResult.Properties.GetTokenValue(\"id_token\");\n        if (idToken != null)\n        {\n            localSignInProps.StoreTokens(new[] { new AuthenticationToken { Name = \"id_token\", Value = idToken } });\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Account/ExternalProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ExternalProvider\n{\n    public string DisplayName { get; set; }\n    public string AuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Account/LoggedOutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoggedOutViewModel\n{\n    public string PostLogoutRedirectUri { get; set; }\n    public string ClientName { get; set; }\n    public string SignOutIframeUrl { get; set; }\n\n    public bool AutomaticRedirectAfterSignOut { get; set; }\n\n    public string LogoutId { get; set; }\n    public bool TriggerExternalSignout => ExternalAuthenticationScheme != null;\n    public string ExternalAuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Account/LoginInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginInputModel\n{\n    [Required]\n    public string Username { get; set; }\n    [Required]\n    public string Password { get; set; }\n    public bool RememberLogin { get; set; }\n    public string ReturnUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Account/LoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginViewModel : LoginInputModel\n{\n    public bool AllowRememberLogin { get; set; } = true;\n    public bool EnableLocalLogin { get; set; } = true;\n\n    public IEnumerable<ExternalProvider> ExternalProviders { get; set; } = Enumerable.Empty<ExternalProvider>();\n    public IEnumerable<ExternalProvider> VisibleExternalProviders => ExternalProviders.Where(x => !String.IsNullOrWhiteSpace(x.DisplayName));\n\n    public bool IsExternalLoginOnly => EnableLocalLogin == false && ExternalProviders?.Count() == 1;\n    public string ExternalLoginScheme => IsExternalLoginOnly ? ExternalProviders?.SingleOrDefault()?.AuthenticationScheme : null;\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Account/LogoutInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutInputModel\n{\n    public string LogoutId { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Account/LogoutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutViewModel : LogoutInputModel\n{\n    public bool ShowLogoutPrompt { get; set; } = true;\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Account/RedirectViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class RedirectViewModel\n{\n    public string RedirectUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Consent/ConsentController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This controller processes the consent UI\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class ConsentController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly ILogger<ConsentController> _logger;\n\n    public ConsentController(\n        IIdentityServerInteractionService interaction,\n        IEventService events,\n        ILogger<ConsentController> logger)\n    {\n        _interaction = interaction;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Shows the consent screen\n    /// </summary>\n    /// <param name=\"returnUrl\"></param>\n    /// <returns></returns>\n    [HttpGet]\n    public async Task<IActionResult> Index(string returnUrl)\n    {\n        var vm = await BuildViewModelAsync(returnUrl);\n        if (vm != null)\n        {\n            return View(\"Index\", vm);\n        }\n\n        return View(\"Error\");\n    }\n\n    /// <summary>\n    /// Handles the consent screen postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Index(ConsentInputModel model)\n    {\n        var result = await ProcessConsent(model);\n\n        if (result.IsRedirect)\n        {\n            var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n            if (context?.IsNativeClient() == true)\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", result.RedirectUri);\n            }\n            return result.RedirectUri.IsAllowedRedirect() ? Redirect(result.RedirectUri.SanitizeForRedirect()) : Forbid();\n        }\n\n        if (result.HasValidationError)\n        {\n            ModelState.AddModelError(string.Empty, result.ValidationError);\n        }\n\n        if (result.ShowView)\n        {\n            return View(\"Index\", result.ViewModel);\n        }\n\n        return View(\"Error\");\n    }\n\n    /*****************************************/\n    /* helper APIs for the ConsentController */\n    /*****************************************/\n    private async Task<ProcessConsentResult> ProcessConsent(ConsentInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        // validate return url is still valid\n        var request = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model?.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model?.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.GrantConsentAsync(request, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.ReturnUrl, model);\n        }\n\n        return result;\n    }\n\n    private async Task<ConsentViewModel> BuildViewModelAsync(string returnUrl, ConsentInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (request != null)\n        {\n            return CreateConsentViewModel(model, returnUrl, request);\n        }\n        else\n        {\n            _logger.LogError(\"No consent request matching request: {0}\", returnUrl.SanitizeForLog());\n        }\n\n        return null;\n    }\n\n    private ConsentViewModel CreateConsentViewModel(\n        ConsentInputModel model, string returnUrl,\n        AuthorizationRequest request)\n    {\n        var vm = new ConsentViewModel\n        {\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n            Description = model?.Description,\n\n            ReturnUrl = returnUrl,\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach(var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        var displayName = apiScope.DisplayName ?? apiScope.Name;\n        if (!String.IsNullOrWhiteSpace(parsedScopeValue.ParsedParameter))\n        {\n            displayName += \":\" + parsedScopeValue.ParsedParameter;\n        }\n\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            DisplayName = displayName,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Consent/ConsentInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentInputModel\n{\n    public string Button { get; set; }\n    public IEnumerable<string> ScopesConsented { get; set; }\n    public bool RememberConsent { get; set; }\n    public string ReturnUrl { get; set; }\n    public string Description { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Consent/ConsentOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentOptions\n{\n    public static bool EnableOfflineAccess = true;\n    public static string OfflineAccessDisplayName = \"Offline Access\";\n    public static string OfflineAccessDescription = \"Access to your applications and resources, even when you are offline\";\n\n    public static readonly string MustChooseOneErrorMessage = \"You must pick at least one permission\";\n    public static readonly string InvalidSelectionErrorMessage = \"Invalid selection\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Consent/ConsentViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentViewModel : ConsentInputModel\n{\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public bool AllowRememberConsent { get; set; }\n\n    public IEnumerable<ScopeViewModel> IdentityScopes { get; set; }\n    public IEnumerable<ScopeViewModel> ApiScopes { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Consent/ProcessConsentResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ProcessConsentResult\n{\n    public bool IsRedirect => RedirectUri != null;\n    public string RedirectUri { get; set; }\n    public Client Client { get; set; }\n\n    public bool ShowView => ViewModel != null;\n    public ConsentViewModel ViewModel { get; set; }\n\n    public bool HasValidationError => ValidationError != null;\n    public string ValidationError { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Consent/ScopeViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ScopeViewModel\n{\n    public string Value { get; set; }\n    public string DisplayName { get; set; }\n    public string Description { get; set; }\n    public bool Emphasize { get; set; }\n    public bool Required { get; set; }\n    public bool Checked { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Device/DeviceAuthorizationInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationInputModel : ConsentInputModel\n{\n    public string UserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Device/DeviceAuthorizationViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationViewModel : ConsentViewModel\n{\n    public string UserCode { get; set; }\n    public bool ConfirmUserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Device/DeviceController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[Authorize]\n[SecurityHeaders]\npublic class DeviceController : Controller\n{\n    private readonly IDeviceFlowInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly IOptions<IdentityServerOptions> _options;\n    private readonly ILogger<DeviceController> _logger;\n\n    public DeviceController(\n        IDeviceFlowInteractionService interaction,\n        IEventService eventService,\n        IOptions<IdentityServerOptions> options,\n        ILogger<DeviceController> logger)\n    {\n        _interaction = interaction;\n        _events = eventService;\n        _options = options;\n        _logger = logger;\n    }\n\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        string userCodeParamName = _options.Value.UserInteraction.DeviceVerificationUserCodeParameter;\n        string userCode = Request.Query[userCodeParamName];\n        if (string.IsNullOrWhiteSpace(userCode)) return View(\"UserCodeCapture\");\n\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        vm.ConfirmUserCode = true;\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> UserCodeCapture(string userCode)\n    {\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Callback(DeviceAuthorizationInputModel model)\n    {\n        if (model == null) throw new ArgumentNullException(nameof(model));\n\n        var result = await ProcessConsent(model);\n        if (result.HasValidationError) return View(\"Error\");\n\n        return View(\"Success\");\n    }\n\n    private async Task<ProcessConsentResult> ProcessConsent(DeviceAuthorizationInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        var request = await _interaction.GetAuthorizationContextAsync(model.UserCode);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.HandleRequestAsync(model.UserCode, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.UserCode, model);\n        }\n\n        return result;\n    }\n\n    private async Task<DeviceAuthorizationViewModel> BuildViewModelAsync(string userCode, DeviceAuthorizationInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(userCode);\n        if (request != null)\n        {\n            return CreateConsentViewModel(userCode, model, request);\n        }\n\n        return null;\n    }\n\n    private DeviceAuthorizationViewModel CreateConsentViewModel(string userCode, DeviceAuthorizationInputModel model, DeviceFlowAuthorizationRequest request)\n    {\n        var vm = new DeviceAuthorizationViewModel\n        {\n            UserCode = userCode,\n            Description = model?.Description,\n\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach (var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            // todo: use the parsed scope value in the display?\n            DisplayName = apiScope.DisplayName ?? apiScope.Name,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Diagnostics/DiagnosticsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[Authorize]\npublic class DiagnosticsController : Controller\n{\n    public async Task<IActionResult> Index()\n    {\n        var localAddresses = new string[] { \"127.0.0.1\", \"::1\", HttpContext.Connection.LocalIpAddress.ToString() };\n        if (!localAddresses.Contains(HttpContext.Connection.RemoteIpAddress.ToString()))\n        {\n            return NotFound();\n        }\n\n        var model = new DiagnosticsViewModel(await HttpContext.AuthenticateAsync());\n        return View(model);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Diagnostics/DiagnosticsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DiagnosticsViewModel\n{\n    public DiagnosticsViewModel(AuthenticateResult result)\n    {\n        AuthenticateResult = result;\n\n        if (result.Properties.Items.ContainsKey(\"client_list\"))\n        {\n            var encoded = result.Properties.Items[\"client_list\"];\n            var bytes = Base64Url.Decode(encoded);\n            var value = Encoding.UTF8.GetString(bytes);\n\n            Clients = JsonSerializer.Deserialize<string[]>(value);\n        }\n    }\n\n    public AuthenticateResult AuthenticateResult { get; }\n    public IEnumerable<string> Clients { get; } = new List<string>();\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Extensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic static class Extensions\n{\n    /// <summary>\n    /// Checks if the redirect URI is for a native client.\n    /// </summary>\n    /// <returns></returns>\n    public static bool IsNativeClient(this AuthorizationRequest context)\n    {\n        return !context.RedirectUri.StartsWith(\"https\", StringComparison.Ordinal)\n           && !context.RedirectUri.StartsWith(\"http\", StringComparison.Ordinal);\n    }\n\n    public static IActionResult LoadingPage(this Controller controller, string viewName, string redirectUri)\n    {\n        controller.HttpContext.Response.StatusCode = 200;\n        controller.HttpContext.Response.Headers[\"Location\"] = \"\";\n        \n        return controller.View(viewName, new RedirectViewModel { RedirectUrl = redirectUri });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Grants/GrantsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller allows a user to revoke grants given to clients\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class GrantsController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clients;\n    private readonly IResourceStore _resources;\n    private readonly IEventService _events;\n\n    public GrantsController(IIdentityServerInteractionService interaction,\n        IClientStore clients,\n        IResourceStore resources,\n        IEventService events)\n    {\n        _interaction = interaction;\n        _clients = clients;\n        _resources = resources;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Show list of grants\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        return View(\"Index\", await BuildViewModelAsync());\n    }\n\n    /// <summary>\n    /// Handle postback to revoke a client\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Revoke(string clientId)\n    {\n        await _interaction.RevokeUserConsentAsync(clientId);\n        await _events.RaiseAsync(new GrantsRevokedEvent(User.GetSubjectId(), clientId));\n\n        return RedirectToAction(\"Index\");\n    }\n\n    private async Task<GrantsViewModel> BuildViewModelAsync()\n    {\n        var grants = await _interaction.GetAllUserGrantsAsync();\n\n        var list = new List<GrantViewModel>();\n        foreach(var grant in grants)\n        {\n            var client = await _clients.FindClientByIdAsync(grant.ClientId);\n            if (client != null)\n            {\n                var resources = await _resources.FindResourcesByScopeAsync(grant.Scopes);\n\n                var item = new GrantViewModel()\n                {\n                    ClientId = client.ClientId,\n                    ClientName = client.ClientName ?? client.ClientId,\n                    ClientLogoUrl = client.LogoUri,\n                    ClientUrl = client.ClientUri,\n                    Description = grant.Description,\n                    Created = grant.CreationTime,\n                    Expires = grant.Expiration,\n                    IdentityGrantNames = resources.IdentityResources.Select(x => x.DisplayName ?? x.Name).ToArray(),\n                    ApiGrantNames = resources.ApiScopes.Select(x => x.DisplayName ?? x.Name).ToArray()\n                };\n\n                list.Add(item);\n            }\n        }\n\n        return new GrantsViewModel\n        {\n            Grants = list\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Grants/GrantsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class GrantsViewModel\n{\n    public IEnumerable<GrantViewModel> Grants { get; set; }\n}\n\npublic class GrantViewModel\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public string Description { get; set; }\n    public DateTime Created { get; set; }\n    public DateTime? Expires { get; set; }\n    public IEnumerable<string> IdentityGrantNames { get; set; }\n    public IEnumerable<string> ApiGrantNames { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Home/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ErrorViewModel\n{\n    public ErrorViewModel()\n    {\n    }\n\n    public ErrorViewModel(string error)\n    {\n        Error = new ErrorMessage { Error = error };\n    }\n\n    public ErrorMessage Error { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/Home/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class HomeController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IWebHostEnvironment _environment;\n    private readonly ILogger _logger;\n\n    public HomeController(IIdentityServerInteractionService interaction, IWebHostEnvironment environment, ILogger<HomeController> logger)\n    {\n        _interaction = interaction;\n        _environment = environment;\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        if (_environment.IsDevelopment())\n        {\n            // only show in development\n            return View();\n        }\n\n        _logger.LogInformation(\"Homepage is disabled in production. Returning 404.\");\n        return NotFound();\n    }\n\n    /// <summary>\n    /// Shows the error page\n    /// </summary>\n    public async Task<IActionResult> Error(string errorId)\n    {\n        var vm = new ErrorViewModel();\n\n        // retrieve error details from identityserver\n        var message = await _interaction.GetErrorContextAsync(errorId);\n        if (message != null)\n        {\n            vm.Error = message;\n\n            if (!_environment.IsDevelopment())\n            {\n                // only show in development\n                message.ErrorDescription = null;\n            }\n        }\n\n        return View(\"Error\", vm);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/SecurityHeadersAttribute.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class SecurityHeadersAttribute : ActionFilterAttribute\n{\n    public override void OnResultExecuting(ResultExecutingContext context)\n    {\n        var result = context.Result;\n        if (result is ViewResult)\n        {\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Type-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Type-Options\", \"nosniff\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Frame-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Frame-Options\", \"SAMEORIGIN\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy\n            var csp = \"default-src 'self'; object-src 'none'; frame-ancestors 'none'; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self';\";\n            // also consider adding upgrade-insecure-requests once you have HTTPS in place for production\n            //csp += \"upgrade-insecure-requests;\";\n            // also an example if you need client images to be displayed from twitter\n            // csp += \"img-src 'self' https://pbs.twimg.com;\";\n\n            // once for standards compliant browsers\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Content-Security-Policy\", csp);\n            }\n            // and once again for IE\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Security-Policy\", csp);\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy\n            var referrer_policy = \"no-referrer\";\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Referrer-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Referrer-Policy\", referrer_policy);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Quickstart/TestUsers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class TestUsers\n{\n\n    static readonly object UserAddress = new\n    {\n        street_address = \"One Hacker Way\",\n        locality = \"Heidelberg\",\n        postal_code = 69118,\n        country = \"Germany\"\n    };\n\n    public static List<TestUser> Users => new List<TestUser>\n    {\n        new()\n        {\n            SubjectId = \"818727\",\n            Username = \"alice\",\n            Password = \"alice\",\n            Claims =\n            {\n                new (Name, \"Alice Smith\"),\n                new (GivenName, \"Alice\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"AliceSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://alice.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        },\n        new()\n        {\n            SubjectId = \"88421113\",\n            Username = \"bob\",\n            Password = \"bob\",\n            Claims =\n            {\n                new (Name, \"Bob Smith\"),\n                new (GivenName, \"Bob\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"BobSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://bob.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        }\n    };\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8;\nusing IdentityServerHost.Quickstart.UI;\nusing Microsoft.AspNetCore.Builder;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.Extensions.DependencyInjection;\nusing Microsoft.Extensions.Hosting;\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer\n{\n    public class Startup\n    {\n        public void ConfigureServices(IServiceCollection services)\n        {\n            services.AddControllersWithViews();\n\n            var builder = services.AddIdentityServer()\n                .AddInMemoryIdentityResources(Config.IdentityResources)\n                .AddInMemoryApiScopes(Config.ApiScopes)\n                .AddInMemoryClients(Config.Clients)\n                .AddTestUsers(TestUsers.Users);\n\n            builder.AddDeveloperSigningCredential();\n\n            services.AddAuthentication()\n                .AddGoogle(\"Google\", options =>\n                {\n                    options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n                    options.ClientId = \"<insert here>\";\n                    options.ClientSecret = \"<insert here>\";\n                })\n                .AddOpenIdConnect(\"oidc\", \"Demo IdentityServer\", options =>\n                {\n                    options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n                    options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n                    options.SaveTokens = true;\n\n                    options.Authority = \"https://demo.identityserver8.io/\";\n                    options.ClientId = \"interactive.confidential\";\n                    options.ClientSecret = \"secret\";\n                    options.ResponseType = \"code\";\n\n                    options.TokenValidationParameters = new TokenValidationParameters\n                    {\n                        NameClaimType = \"name\",\n                        RoleClaimType = \"role\"\n                    };\n                });\n        }\n\n        public void Configure(IApplicationBuilder app, IWebHostEnvironment env)\n        {\n            if (env.IsDevelopment())\n            {\n                app.UseDeveloperExceptionPage();\n            }\n\n            app.UseStaticFiles();\n            app.UseRouting();\n\n            app.UseIdentityServer();\n            app.UseAuthorization();\n\n            app.UseEndpoints(endpoints =>\n            {\n                endpoints.MapDefaultControllerRoute();\n            });\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Account/AccessDenied.cshtml",
    "content": "﻿\n<div class=\"container\">\n    <div class=\"lead\">\n        <h1>Access Denied</h1>\n        <p>You do not have access to that resource.</p>\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Account/LoggedOut.cshtml",
    "content": "﻿@model LoggedOutViewModel\n\n@{ \n    // set this so the layout rendering sees an anonymous user\n    ViewData[\"signed-out\"] = true;\n}\n\n<div class=\"logged-out-page\">\n    <h1>\n        Logout\n        <small>You are now logged out</small>\n    </h1>\n\n    @if (Model.PostLogoutRedirectUri != null)\n    {\n        <div>\n            Click <a class=\"PostLogoutRedirectUri\" href=\"@Model.PostLogoutRedirectUri\">here</a> to return to the\n            <span>@Model.ClientName</span> application.\n        </div>\n    }\n\n    @if (Model.SignOutIframeUrl != null)\n    {\n        <iframe width=\"0\" height=\"0\" class=\"signout\" src=\"@Model.SignOutIframeUrl\"></iframe>\n    }\n</div>\n\n@section scripts\n{\n    @if (Model.AutomaticRedirectAfterSignOut)\n    {\n        <script src=\"~/js/signout-redirect.js\"></script>\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Account/Login.cshtml",
    "content": "@model LoginViewModel\n\n<div class=\"login-page\">\n    <div class=\"lead\">\n        <h1>Login</h1>\n        <p>Choose how to login</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n\n        @if (Model.EnableLocalLogin)\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>Local Account</h2>\n                    </div>\n\n                    <div class=\"card-body\">\n                        <form asp-route=\"Login\">\n                            <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n\n                            <div class=\"form-group\">\n                                <label asp-for=\"Username\"></label>\n                                <input class=\"form-control\" placeholder=\"Username\" asp-for=\"Username\" autofocus>\n                            </div>\n                            <div class=\"form-group\">\n                                <label asp-for=\"Password\"></label>\n                                <input type=\"password\" class=\"form-control\" placeholder=\"Password\" asp-for=\"Password\" autocomplete=\"off\">\n                            </div>\n                            @if (Model.AllowRememberLogin)\n                            {\n                                <div class=\"form-group\">\n                                    <div class=\"form-check\">\n                                        <input class=\"form-check-input\" asp-for=\"RememberLogin\">\n                                        <label class=\"form-check-label\" asp-for=\"RememberLogin\">\n                                            Remember My Login\n                                        </label>\n                                    </div>\n                                </div>\n                            }\n                            <button class=\"btn btn-primary\" name=\"button\" value=\"login\">Login</button>\n                            <button class=\"btn btn-secondary\" name=\"button\" value=\"cancel\" formaction=\"/Account/LoginCancel\">Cancel</button>\n                        </form>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>External Account</h2>\n                    </div>\n                    <div class=\"card-body\">\n                        <ul class=\"list-inline\">\n                            @foreach (var provider in Model.VisibleExternalProviders)\n                            {\n                                <li class=\"list-inline-item\">\n                                    <a class=\"btn btn-secondary\"\n                                       asp-controller=\"External\"\n                                       asp-action=\"Challenge\"\n                                       asp-route-scheme=\"@provider.AuthenticationScheme\"\n                                       asp-route-returnUrl=\"@Model.ReturnUrl\">\n                                        @provider.DisplayName\n                                    </a>\n                                </li>\n                            }\n                        </ul>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (!Model.EnableLocalLogin && !Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"alert alert-warning\">\n                <strong>Invalid login request</strong>\n                There are no login schemes configured for this request.\n            </div>\n        }\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Account/Logout.cshtml",
    "content": "﻿@model LogoutViewModel\n\n<div class=\"logout-page\">\n    <div class=\"lead\">\n        <h1>Logout</h1>\n        <p>Would you like to logout of IdentityServer?</p>\n    </div>\n\n    <form asp-action=\"Logout\">\n        <input type=\"hidden\" name=\"logoutId\" value=\"@Model.LogoutId\"  />\n        <div class=\"form-group\">\n            <button class=\"btn btn-primary\">Yes</button>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Consent/Index.cshtml",
    "content": "@model ConsentViewModel\n\n<div class=\"page-consent\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Index\">\n        <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Device/Success.cshtml",
    "content": "\n<div class=\"page-device-success\">\n    <div class=\"lead\">\n        <h1>Success</h1>\n        <p>You have successfully authorized the device</p>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Device/UserCodeCapture.cshtml",
    "content": "@model string\n\n<div class=\"page-device-code\">\n    <div class=\"lead\">\n        <h1>User Code</h1>\n        <p>Please enter the code displayed on your device.</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <form asp-action=\"UserCodeCapture\">\n                <div class=\"form-group\">\n                    <label for=\"userCode\">User Code:</label>\n                    <input class=\"form-control\" for=\"userCode\" name=\"userCode\" autofocus />\n                </div>\n\n                <button class=\"btn btn-primary\" name=\"button\">Submit</button>\n            </form>\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Device/UserCodeConfirmation.cshtml",
    "content": "@model DeviceAuthorizationViewModel\n\n<div class=\"page-device-confirmation\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        @if (Model.ConfirmUserCode)\n        {\n            <p>Please confirm that the authorization request quotes the code: <strong>@Model.UserCode</strong>.</p>\n        }\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Callback\">\n        <input asp-for=\"UserCode\" type=\"hidden\" value=\"@Model.UserCode\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Diagnostics/Index.cshtml",
    "content": "@model DiagnosticsViewModel\n\n<div class=\"diagnostics-page\">\n    <div class=\"lead\">\n        <h1>Authentication Cookie</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Claims</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var claim in Model.AuthenticateResult.Principal.Claims)\n                        {\n                            <dt>@claim.Type</dt>\n                            <dd>@claim.Value</dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n        \n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Properties</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var prop in Model.AuthenticateResult.Properties.Items)\n                        {\n                            <dt>@prop.Key</dt>\n                            <dd>@prop.Value</dd>\n                        }\n                        @if (Model.Clients.Any())\n                        {\n                            <dt>Clients</dt>\n                            <dd>\n                            @{\n                                var clients = Model.Clients.ToArray();\n                                for(var i = 0; i < clients.Length; i++)\n                                {\n                                    <text>@clients[i]</text>\n                                    if (i < clients.Length - 1)\n                                    {\n                                        <text>, </text>\n                                    }\n                                }\n                            }\n                            </dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n    </div>\n</div>\n\n\n\n\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Grants/Index.cshtml",
    "content": "﻿@model GrantsViewModel\n\n<div class=\"grants-page\">\n    <div class=\"lead\">\n        <h1>Client Application Permissions</h1>\n        <p>Below is the list of applications you have given permission to and the resources they have access to.</p>\n    </div>\n\n    @if (Model.Grants.Any() == false)\n    {\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                <div class=\"alert alert-info\">\n                    You have not given access to any applications\n                </div>\n            </div>\n        </div>\n    }\n    else\n    {\n        foreach (var grant in Model.Grants)\n        {\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <div class=\"row\">\n                        <div class=\"col-sm-8 card-title\">\n                            @if (grant.ClientLogoUrl != null)\n                            {\n                                <img src=\"@grant.ClientLogoUrl\">\n                            }\n                            <strong>@grant.ClientName</strong>\n                        </div>\n\n                        <div class=\"col-sm-2\">\n                            <form asp-action=\"Revoke\">\n                                <input type=\"hidden\" name=\"clientId\" value=\"@grant.ClientId\">\n                                <button class=\"btn btn-danger\">Revoke Access</button>\n                            </form>\n                        </div>\n                    </div>\n                </div>\n                \n                <ul class=\"list-group list-group-flush\">\n                    @if (grant.Description != null)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Description:</label> @grant.Description\n                        </li>   \n                    }\n                    <li class=\"list-group-item\">\n                        <label>Created:</label> @grant.Created.ToString(\"yyyy-MM-dd\")\n                    </li>\n                    @if (grant.Expires.HasValue)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Expires:</label> @grant.Expires.Value.ToString(\"yyyy-MM-dd\")\n                        </li>\n                    }\n                    @if (grant.IdentityGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Identity Grants</label>\n                            <ul>\n                                @foreach (var name in grant.IdentityGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                    @if (grant.ApiGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>API Grants</label>\n                            <ul>\n                                @foreach (var name in grant.ApiGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                </ul>\n            </div>\n        }\n    }\n</div>"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Home/Index.cshtml",
    "content": "@using System.Diagnostics\n\n@{\n    var version = FileVersionInfo.GetVersionInfo(typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.Location).ProductVersion.Split('+').First();\n}\n\n<div class=\"welcome-page\">\n    <h1>\n        <img src=\"~/icon.jpg\">\n        Welcome to IdentityServer8\n        <small class=\"text-muted\">(version @version)</small>\n    </h1>\n\n    <ul>\n        <li>\n            IdentityServer publishes a\n            <a href=\"~/.well-known/openid-configuration\">discovery document</a>\n            where you can find metadata and links to all the endpoints, key material, etc.\n        </li>\n        <li>\n            Click <a href=\"~/diagnostics\">here</a> to see the claims for your current session.\n        </li>\n        <li>\n            Click <a href=\"~/grants\">here</a> to manage your stored grants.\n        </li>\n        <li>\n            Here are links to the\n            <a href=\"https://github.com/alexhiggins732/IdentityServer8\">source code repository</a>,\n            and <a href=\"https://github.com/alexhiggins732/IdentityServer8/tree/main/samples\">ready to use samples</a>.\n        </li>\n    </ul>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Shared/Error.cshtml",
    "content": "@model ErrorViewModel\n\n@{\n    var error = Model?.Error?.Error;\n    var errorDescription = Model?.Error?.ErrorDescription;\n    var request_id = Model?.Error?.RequestId;\n}\n\n<div class=\"error-page\">\n    <div class=\"lead\">\n        <h1>Error</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <div class=\"alert alert-danger\">\n                Sorry, there was an error\n\n                @if (error != null)\n                {\n                    <strong>\n                        <em>\n                            : @error\n                        </em>\n                    </strong>\n\n                    if (errorDescription != null)\n                    {\n                        <div>@errorDescription</div>\n                    }\n                }\n            </div>\n\n            @if (request_id != null)\n            {\n                <div class=\"request-id\">Request Id: @request_id</div>\n            }\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Shared/Redirect.cshtml",
    "content": "@model RedirectViewModel\n@using Microsoft.Extensions.DependencyInjection;\n<div class=\"redirect-page\">\n    <div class=\"lead\">\n        <h1>You are now being returned to the application</h1>\n        <p>Once complete, you may close this tab.</p>\n    </div>\n</div>\n\n<meta http-equiv=\"refresh\" content=\"0;url=@Model.RedirectUrl\" data-url=\"@Model.RedirectUrl\">\n<script>\n    var url = '@Ioc.Sanitizer.Url.Sanitize(Model.RedirectUrl)';\n    window.location.href = url;\n</script>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0, shrink-to-fit=no\" />\n\n    <title>IdentityServer8</title>\n    \n    <link rel=\"icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    <link rel=\"shortcut icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    \n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <partial name=\"_Nav\" />\n   \n    <div class=\"container body-container\">\n        @RenderBody()\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.slim.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Shared/_Nav.cshtml",
    "content": "@using IdentityServer8.Extensions\n\n@{\n    string name = null;\n    if (!true.Equals(ViewData[\"signed-out\"]))\n    {\n        name = Context.User?.GetDisplayName();\n    }\n}\n\n<div class=\"nav-page\">\n    <nav class=\"navbar navbar-expand-lg navbar-dark bg-dark\">\n\n        <a href=\"~/\" class=\"navbar-brand\">\n            <img src=\"~/icon.png\" class=\"icon-banner\">\n            IdentityServer8\n        </a>\n\n        @if (!string.IsNullOrWhiteSpace(name))\n        {\n            <ul class=\"navbar-nav mr-auto\">\n                <li class=\"nav-item dropdown\">\n                    <a href=\"#\" class=\"nav-link dropdown-toggle\" data-toggle=\"dropdown\">@name <b class=\"caret\"></b></a>\n                    \n                    <div class=\"dropdown-menu\">\n                        <a class=\"dropdown-item\" asp-action=\"Logout\" asp-controller=\"Account\">Logout</a>\n                    </div>\n              </li>\n            </ul>\n        }\n    \n    </nav>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Shared/_ScopeListItem.cshtml",
    "content": "﻿@model ScopeViewModel\n\n<li class=\"list-group-item\">\n    <label>\n        <input class=\"consent-scopecheck\"\n               type=\"checkbox\"\n               name=\"ScopesConsented\"\n               id=\"scopes_@Model.Value\"\n               value=\"@Model.Value\"\n               checked=\"@Model.Checked\"\n               disabled=\"@Model.Required\" />\n        @if (Model.Required)\n        {\n            <input type=\"hidden\"\n                   name=\"ScopesConsented\"\n                   value=\"@Model.Value\" />\n        }\n        <strong>@Model.DisplayName</strong>\n        @if (Model.Emphasize)\n        {\n            <span class=\"glyphicon glyphicon-exclamation-sign\"></span>\n        }\n    </label>\n    @if (Model.Required)\n    {\n        <span><em>(required)</em></span>\n    }\n    @if (Model.Description != null)\n    {\n        <div class=\"consent-description\">\n            <label for=\"scopes_@Model.Value\">@Model.Description</label>\n        </div>\n    }\n</li>"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/Shared/_ValidationSummary.cshtml",
    "content": "﻿@if (ViewContext.ModelState.IsValid == false)\n{\n    <div class=\"alert alert-danger\">\n        <strong>Error</strong>\n        <div asp-validation-summary=\"All\" class=\"danger\"></div>\n    </div>\n}"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/_ViewImports.cshtml",
    "content": "﻿@using IdentityServerHost.Quickstart.UI\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/wwwroot/css/site.css",
    "content": "﻿.body-container {\n  margin-top: 60px;\n  padding-bottom: 40px; }\n\n.welcome-page li {\n  list-style: none;\n  padding: 4px; }\n\n.logged-out-page iframe {\n  display: none;\n  width: 0;\n  height: 0; }\n\n.grants-page .card {\n  margin-top: 20px;\n  border-bottom: 1px solid lightgray; }\n  .grants-page .card .card-title {\n    font-size: 120%;\n    font-weight: bold; }\n    .grants-page .card .card-title img {\n      width: 100px;\n      height: 100px; }\n  .grants-page .card label {\n    font-weight: bold; }\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/wwwroot/css/site.scss",
    "content": "﻿.body-container {\n    margin-top: 60px;\n    padding-bottom:40px;\n}\n\n.welcome-page {\n    li {\n        list-style: none;\n        padding: 4px;\n    }\n}\n\n.logged-out-page {\n    iframe {\n        display: none;\n        width: 0;\n        height: 0;\n    }\n}\n\n.grants-page {\n    .card {\n        margin-top: 20px;\n        border-bottom: 1px solid lightgray;\n\n        .card-title {\n            img {\n                width: 100px;\n                height: 100px;\n            }\n\n            font-size: 120%;\n            font-weight: bold;\n        }\n\n        label {\n            font-weight: bold;\n        }\n    }\n}\n\n\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/wwwroot/js/signin-redirect.js",
    "content": "// window.location.href = document.querySelector(\"meta[http-equiv=refresh]\").getAttribute(\"data-url\");\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/IdentityServer/wwwroot/js/signout-redirect.js",
    "content": "﻿window.addEventListener(\"load\", function () {\n    var a = document.querySelector(\"a.PostLogoutRedirectUri\");\n    if (a) {\n        window.location = a.href;\n    }\n});\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/JavaScriptClient/JavaScriptClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n</Project>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/JavaScriptClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nvar app = WebApplication.Create(args);\napp.UseDefaultFiles();\napp.UseStaticFiles();\nawait app.RunAsync();\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/JavaScriptClient/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:5003\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"JavaScriptClient\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5003\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/JavaScriptClient/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore.Builder;\n\nnamespace JavaScriptClient\n{\n    public class Startup\n    {\n        public void Configure(IApplicationBuilder app)\n        {\n            app.UseDefaultFiles();\n            app.UseStaticFiles();\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/JavaScriptClient/appsettings.Development.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Debug\",\n      \"System\": \"Information\",\n      \"Microsoft\": \"Information\"\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/JavaScriptClient/appsettings.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Warning\"\n    }\n  },\n  \"AllowedHosts\": \"*\"\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/JavaScriptClient/wwwroot/app.js",
    "content": "/// <reference path=\"oidc-client.js\" />\n\nfunction log() {\n    document.getElementById('results').innerText = '';\n\n    Array.prototype.forEach.call(arguments, function (msg) {\n        if (msg instanceof Error) {\n            msg = \"Error: \" + msg.message;\n        }\n        else if (typeof msg !== 'string') {\n            msg = JSON.stringify(msg, null, 2);\n        }\n        document.getElementById('results').innerText += msg + '\\r\\n';\n    });\n}\n\ndocument.getElementById(\"login\").addEventListener(\"click\", login, false);\ndocument.getElementById(\"api\").addEventListener(\"click\", api, false);\ndocument.getElementById(\"logout\").addEventListener(\"click\", logout, false);\n\nvar config = {\n    authority: \"https://localhost:5001\",\n    client_id: \"js\",\n    redirect_uri: \"https://localhost:5003/callback.html\",\n    response_type: \"code\",\n    scope:\"openid profile api1\",\n    post_logout_redirect_uri : \"https://localhost:5003/index.html\",\n};\nvar mgr = new Oidc.UserManager(config);\n\nmgr.getUser().then(function (user) {\n    if (user) {\n        log(\"User logged in\", user.profile);\n    }\n    else {\n        log(\"User not logged in\");\n    }\n});\n\nfunction login() {\n    mgr.signinRedirect();\n}\n\nfunction api() {\n    mgr.getUser().then(function (user) {\n        var url = \"https://localhost:6001/identity\";\n\n        var xhr = new XMLHttpRequest();\n        xhr.open(\"GET\", url);\n        xhr.onload = function () {\n            log(xhr.status, JSON.parse(xhr.responseText));\n        }\n        xhr.setRequestHeader(\"Authorization\", \"Bearer \" + user.access_token);\n        xhr.send();\n    });\n}\n\nfunction logout() {\n    mgr.signoutRedirect();\n}"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/JavaScriptClient/wwwroot/callback.html",
    "content": "<!DOCTYPE html>\n<html>\n<head>\n    <meta charset=\"utf-8\" />\n    <title></title>\n</head>\n<body>\n    <script src=\"oidc-client.js\"></script>\n    <script>\n        new Oidc.UserManager({ response_mode: \"query\" }).signinRedirectCallback().then(function () {\n            window.location = \"index.html\";\n        }).catch(function (e) {\n            console.error(e);\n        });\n    </script>\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/JavaScriptClient/wwwroot/index.html",
    "content": "<!DOCTYPE html>\n<html>\n<head>\n    <meta charset=\"utf-8\" />\n    <title></title>\n</head>\n<body>\n    <button id=\"login\">Login</button>\n    <button id=\"api\">Call API</button>\n    <button id=\"logout\">Logout</button>\n\n    <pre id=\"results\"></pre>\n\n    <script src=\"oidc-client.js\"></script>\n    <script src=\"app.js\"></script>\n</body>\n</html>"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/JavaScriptClient/wwwroot/oidc-client.js",
    "content": "var Oidc =\n/******/ (function(modules) { // webpackBootstrap\n/******/ \t// The module cache\n/******/ \tvar installedModules = {};\n/******/\n/******/ \t// The require function\n/******/ \tfunction __webpack_require__(moduleId) {\n/******/\n/******/ \t\t// Check if module is in cache\n/******/ \t\tif(installedModules[moduleId]) {\n/******/ \t\t\treturn installedModules[moduleId].exports;\n/******/ \t\t}\n/******/ \t\t// Create a new module (and put it into the cache)\n/******/ \t\tvar module = installedModules[moduleId] = {\n/******/ \t\t\ti: moduleId,\n/******/ \t\t\tl: false,\n/******/ \t\t\texports: {}\n/******/ \t\t};\n/******/\n/******/ \t\t// Execute the module function\n/******/ \t\tmodules[moduleId].call(module.exports, module, module.exports, __webpack_require__);\n/******/\n/******/ \t\t// Flag the module as loaded\n/******/ \t\tmodule.l = true;\n/******/\n/******/ \t\t// Return the exports of the module\n/******/ \t\treturn module.exports;\n/******/ \t}\n/******/\n/******/\n/******/ \t// expose the modules object (__webpack_modules__)\n/******/ \t__webpack_require__.m = modules;\n/******/\n/******/ \t// expose the module cache\n/******/ \t__webpack_require__.c = installedModules;\n/******/\n/******/ \t// define getter function for harmony exports\n/******/ \t__webpack_require__.d = function(exports, name, getter) {\n/******/ \t\tif(!__webpack_require__.o(exports, name)) {\n/******/ \t\t\tObject.defineProperty(exports, name, { enumerable: true, get: getter });\n/******/ \t\t}\n/******/ \t};\n/******/\n/******/ \t// define __esModule on exports\n/******/ \t__webpack_require__.r = function(exports) {\n/******/ \t\tif(typeof Symbol !== 'undefined' && Symbol.toStringTag) {\n/******/ \t\t\tObject.defineProperty(exports, Symbol.toStringTag, { value: 'Module' });\n/******/ \t\t}\n/******/ \t\tObject.defineProperty(exports, '__esModule', { value: true });\n/******/ \t};\n/******/\n/******/ \t// create a fake namespace object\n/******/ \t// mode & 1: value is a module id, require it\n/******/ \t// mode & 2: merge all properties of value into the ns\n/******/ \t// mode & 4: return value when already ns object\n/******/ \t// mode & 8|1: behave like require\n/******/ \t__webpack_require__.t = function(value, mode) {\n/******/ \t\tif(mode & 1) value = __webpack_require__(value);\n/******/ \t\tif(mode & 8) return value;\n/******/ \t\tif((mode & 4) && typeof value === 'object' && value && value.__esModule) return value;\n/******/ \t\tvar ns = Object.create(null);\n/******/ \t\t__webpack_require__.r(ns);\n/******/ \t\tObject.defineProperty(ns, 'default', { enumerable: true, value: value });\n/******/ \t\tif(mode & 2 && typeof value != 'string') for(var key in value) __webpack_require__.d(ns, key, function(key) { return value[key]; }.bind(null, key));\n/******/ \t\treturn ns;\n/******/ \t};\n/******/\n/******/ \t// getDefaultExport function for compatibility with non-harmony modules\n/******/ \t__webpack_require__.n = function(module) {\n/******/ \t\tvar getter = module && module.__esModule ?\n/******/ \t\t\tfunction getDefault() { return module['default']; } :\n/******/ \t\t\tfunction getModuleExports() { return module; };\n/******/ \t\t__webpack_require__.d(getter, 'a', getter);\n/******/ \t\treturn getter;\n/******/ \t};\n/******/\n/******/ \t// Object.prototype.hasOwnProperty.call\n/******/ \t__webpack_require__.o = function(object, property) { return Object.prototype.hasOwnProperty.call(object, property); };\n/******/\n/******/ \t// __webpack_public_path__\n/******/ \t__webpack_require__.p = \"\";\n/******/\n/******/\n/******/ \t// Load entry module and return exports\n/******/ \treturn __webpack_require__(__webpack_require__.s = 0);\n/******/ })\n/************************************************************************/\n/******/ ({\n\n/***/ \"./index.js\":\n/*!******************!*\\\n  !*** ./index.js ***!\n  \\******************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _Log = __webpack_require__(/*! ./src/Log.js */ \"./src/Log.js\");\n\nvar _OidcClient = __webpack_require__(/*! ./src/OidcClient.js */ \"./src/OidcClient.js\");\n\nvar _OidcClientSettings = __webpack_require__(/*! ./src/OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./src/WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _InMemoryWebStorage = __webpack_require__(/*! ./src/InMemoryWebStorage.js */ \"./src/InMemoryWebStorage.js\");\n\nvar _UserManager = __webpack_require__(/*! ./src/UserManager.js */ \"./src/UserManager.js\");\n\nvar _AccessTokenEvents = __webpack_require__(/*! ./src/AccessTokenEvents.js */ \"./src/AccessTokenEvents.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./src/MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _CordovaPopupNavigator = __webpack_require__(/*! ./src/CordovaPopupNavigator.js */ \"./src/CordovaPopupNavigator.js\");\n\nvar _CordovaIFrameNavigator = __webpack_require__(/*! ./src/CordovaIFrameNavigator.js */ \"./src/CordovaIFrameNavigator.js\");\n\nvar _CheckSessionIFrame = __webpack_require__(/*! ./src/CheckSessionIFrame.js */ \"./src/CheckSessionIFrame.js\");\n\nvar _TokenRevocationClient = __webpack_require__(/*! ./src/TokenRevocationClient.js */ \"./src/TokenRevocationClient.js\");\n\nvar _SessionMonitor = __webpack_require__(/*! ./src/SessionMonitor.js */ \"./src/SessionMonitor.js\");\n\nvar _Global = __webpack_require__(/*! ./src/Global.js */ \"./src/Global.js\");\n\nvar _User = __webpack_require__(/*! ./src/User.js */ \"./src/User.js\");\n\nvar _version = __webpack_require__(/*! ./version.js */ \"./version.js\");\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nexports.default = {\n    Version: _version.Version,\n    Log: _Log.Log,\n    OidcClient: _OidcClient.OidcClient,\n    OidcClientSettings: _OidcClientSettings.OidcClientSettings,\n    WebStorageStateStore: _WebStorageStateStore.WebStorageStateStore,\n    InMemoryWebStorage: _InMemoryWebStorage.InMemoryWebStorage,\n    UserManager: _UserManager.UserManager,\n    AccessTokenEvents: _AccessTokenEvents.AccessTokenEvents,\n    MetadataService: _MetadataService.MetadataService,\n    CordovaPopupNavigator: _CordovaPopupNavigator.CordovaPopupNavigator,\n    CordovaIFrameNavigator: _CordovaIFrameNavigator.CordovaIFrameNavigator,\n    CheckSessionIFrame: _CheckSessionIFrame.CheckSessionIFrame,\n    TokenRevocationClient: _TokenRevocationClient.TokenRevocationClient,\n    SessionMonitor: _SessionMonitor.SessionMonitor,\n    Global: _Global.Global,\n    User: _User.User\n};\nmodule.exports = exports['default'];\n\n/***/ }),\n\n/***/ \"./jsrsasign/dist/jsrsasign.js\":\n/*!*************************************!*\\\n  !*** ./jsrsasign/dist/jsrsasign.js ***!\n  \\*************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n/* WEBPACK VAR INJECTION */(function(Buffer) {\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\n/*\n * jsrsasign(all) 8.0.12 (2018-04-22) (c) 2010-2018 Kenji Urushima | kjur.github.com/jsrsasign/license\n */\n\nvar navigator = {};\nnavigator.userAgent = false;\n\nvar window = {};\n\n/*!\nCopyright (c) 2011, Yahoo! Inc. All rights reserved.\nCode licensed under the BSD License:\nhttp://developer.yahoo.com/yui/license.html\nversion: 2.9.0\n*/\nif (YAHOO === undefined) {\n  var YAHOO = {};\n}YAHOO.lang = { extend: function extend(g, h, f) {\n    if (!h || !g) {\n      throw new Error(\"YAHOO.lang.extend failed, please check that all dependencies are included.\");\n    }var d = function d() {};d.prototype = h.prototype;g.prototype = new d();g.prototype.constructor = g;g.superclass = h.prototype;if (h.prototype.constructor == Object.prototype.constructor) {\n      h.prototype.constructor = h;\n    }if (f) {\n      var b;for (b in f) {\n        g.prototype[b] = f[b];\n      }var e = function e() {},\n          c = [\"toString\", \"valueOf\"];try {\n        if (/MSIE/.test(navigator.userAgent)) {\n          e = function e(j, i) {\n            for (b = 0; b < c.length; b = b + 1) {\n              var l = c[b],\n                  k = i[l];if (typeof k === \"function\" && k != Object.prototype[l]) {\n                j[l] = k;\n              }\n            }\n          };\n        }\n      } catch (a) {}e(g.prototype, f);\n    }\n  } };\n/*! CryptoJS v3.1.2 core-fix.js\n * code.google.com/p/crypto-js\n * (c) 2009-2013 by Jeff Mott. All rights reserved.\n * code.google.com/p/crypto-js/wiki/License\n * THIS IS FIX of 'core.js' to fix Hmac issue.\n * https://code.google.com/p/crypto-js/issues/detail?id=84\n * https://crypto-js.googlecode.com/svn-history/r667/branches/3.x/src/core.js\n */\nvar CryptoJS = CryptoJS || function (e, g) {\n  var a = {};var b = a.lib = {};var j = b.Base = function () {\n    function n() {}return { extend: function extend(p) {\n        n.prototype = this;var o = new n();if (p) {\n          o.mixIn(p);\n        }if (!o.hasOwnProperty(\"init\")) {\n          o.init = function () {\n            o.$super.init.apply(this, arguments);\n          };\n        }o.init.prototype = o;o.$super = this;return o;\n      }, create: function create() {\n        var o = this.extend();o.init.apply(o, arguments);return o;\n      }, init: function init() {}, mixIn: function mixIn(p) {\n        for (var o in p) {\n          if (p.hasOwnProperty(o)) {\n            this[o] = p[o];\n          }\n        }if (p.hasOwnProperty(\"toString\")) {\n          this.toString = p.toString;\n        }\n      }, clone: function clone() {\n        return this.init.prototype.extend(this);\n      } };\n  }();var l = b.WordArray = j.extend({ init: function init(o, n) {\n      o = this.words = o || [];if (n != g) {\n        this.sigBytes = n;\n      } else {\n        this.sigBytes = o.length * 4;\n      }\n    }, toString: function toString(n) {\n      return (n || h).stringify(this);\n    }, concat: function concat(t) {\n      var q = this.words;var p = t.words;var n = this.sigBytes;var s = t.sigBytes;this.clamp();if (n % 4) {\n        for (var r = 0; r < s; r++) {\n          var o = p[r >>> 2] >>> 24 - r % 4 * 8 & 255;q[n + r >>> 2] |= o << 24 - (n + r) % 4 * 8;\n        }\n      } else {\n        for (var r = 0; r < s; r += 4) {\n          q[n + r >>> 2] = p[r >>> 2];\n        }\n      }this.sigBytes += s;return this;\n    }, clamp: function clamp() {\n      var o = this.words;var n = this.sigBytes;o[n >>> 2] &= 4294967295 << 32 - n % 4 * 8;o.length = e.ceil(n / 4);\n    }, clone: function clone() {\n      var n = j.clone.call(this);n.words = this.words.slice(0);return n;\n    }, random: function random(p) {\n      var o = [];for (var n = 0; n < p; n += 4) {\n        o.push(e.random() * 4294967296 | 0);\n      }return new l.init(o, p);\n    } });var m = a.enc = {};var h = m.Hex = { stringify: function stringify(p) {\n      var r = p.words;var o = p.sigBytes;var q = [];for (var n = 0; n < o; n++) {\n        var s = r[n >>> 2] >>> 24 - n % 4 * 8 & 255;q.push((s >>> 4).toString(16));q.push((s & 15).toString(16));\n      }return q.join(\"\");\n    }, parse: function parse(p) {\n      var n = p.length;var q = [];for (var o = 0; o < n; o += 2) {\n        q[o >>> 3] |= parseInt(p.substr(o, 2), 16) << 24 - o % 8 * 4;\n      }return new l.init(q, n / 2);\n    } };var d = m.Latin1 = { stringify: function stringify(q) {\n      var r = q.words;var p = q.sigBytes;var n = [];for (var o = 0; o < p; o++) {\n        var s = r[o >>> 2] >>> 24 - o % 4 * 8 & 255;n.push(String.fromCharCode(s));\n      }return n.join(\"\");\n    }, parse: function parse(p) {\n      var n = p.length;var q = [];for (var o = 0; o < n; o++) {\n        q[o >>> 2] |= (p.charCodeAt(o) & 255) << 24 - o % 4 * 8;\n      }return new l.init(q, n);\n    } };var c = m.Utf8 = { stringify: function stringify(n) {\n      try {\n        return decodeURIComponent(escape(d.stringify(n)));\n      } catch (o) {\n        throw new Error(\"Malformed UTF-8 data\");\n      }\n    }, parse: function parse(n) {\n      return d.parse(unescape(encodeURIComponent(n)));\n    } };var i = b.BufferedBlockAlgorithm = j.extend({ reset: function reset() {\n      this._data = new l.init();this._nDataBytes = 0;\n    }, _append: function _append(n) {\n      if (typeof n == \"string\") {\n        n = c.parse(n);\n      }this._data.concat(n);this._nDataBytes += n.sigBytes;\n    }, _process: function _process(w) {\n      var q = this._data;var x = q.words;var n = q.sigBytes;var t = this.blockSize;var v = t * 4;var u = n / v;if (w) {\n        u = e.ceil(u);\n      } else {\n        u = e.max((u | 0) - this._minBufferSize, 0);\n      }var s = u * t;var r = e.min(s * 4, n);if (s) {\n        for (var p = 0; p < s; p += t) {\n          this._doProcessBlock(x, p);\n        }var o = x.splice(0, s);q.sigBytes -= r;\n      }return new l.init(o, r);\n    }, clone: function clone() {\n      var n = j.clone.call(this);n._data = this._data.clone();return n;\n    }, _minBufferSize: 0 });var f = b.Hasher = i.extend({ cfg: j.extend(), init: function init(n) {\n      this.cfg = this.cfg.extend(n);this.reset();\n    }, reset: function reset() {\n      i.reset.call(this);this._doReset();\n    }, update: function update(n) {\n      this._append(n);this._process();return this;\n    }, finalize: function finalize(n) {\n      if (n) {\n        this._append(n);\n      }var o = this._doFinalize();return o;\n    }, blockSize: 512 / 32, _createHelper: function _createHelper(n) {\n      return function (p, o) {\n        return new n.init(o).finalize(p);\n      };\n    }, _createHmacHelper: function _createHmacHelper(n) {\n      return function (p, o) {\n        return new k.HMAC.init(n, o).finalize(p);\n      };\n    } });var k = a.algo = {};return a;\n}(Math);\n/*\nCryptoJS v3.1.2 x64-core-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function (g) {\n  var a = CryptoJS,\n      f = a.lib,\n      e = f.Base,\n      h = f.WordArray,\n      a = a.x64 = {};a.Word = e.extend({ init: function init(b, c) {\n      this.high = b;this.low = c;\n    } });a.WordArray = e.extend({ init: function init(b, c) {\n      b = this.words = b || [];this.sigBytes = c != g ? c : 8 * b.length;\n    }, toX32: function toX32() {\n      for (var b = this.words, c = b.length, a = [], d = 0; d < c; d++) {\n        var e = b[d];a.push(e.high);a.push(e.low);\n      }return h.create(a, this.sigBytes);\n    }, clone: function clone() {\n      for (var b = e.clone.call(this), c = b.words = this.words.slice(0), a = c.length, d = 0; d < a; d++) {\n        c[d] = c[d].clone();\n      }return b;\n    } });\n})();\n\n/*\nCryptoJS v3.1.2 enc-base64.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function () {\n  var h = CryptoJS,\n      j = h.lib.WordArray;h.enc.Base64 = { stringify: function stringify(b) {\n      var e = b.words,\n          f = b.sigBytes,\n          c = this._map;b.clamp();b = [];for (var a = 0; a < f; a += 3) {\n        for (var d = (e[a >>> 2] >>> 24 - 8 * (a % 4) & 255) << 16 | (e[a + 1 >>> 2] >>> 24 - 8 * ((a + 1) % 4) & 255) << 8 | e[a + 2 >>> 2] >>> 24 - 8 * ((a + 2) % 4) & 255, g = 0; 4 > g && a + 0.75 * g < f; g++) {\n          b.push(c.charAt(d >>> 6 * (3 - g) & 63));\n        }\n      }if (e = c.charAt(64)) for (; b.length % 4;) {\n        b.push(e);\n      }return b.join(\"\");\n    }, parse: function parse(b) {\n      var e = b.length,\n          f = this._map,\n          c = f.charAt(64);c && (c = b.indexOf(c), -1 != c && (e = c));for (var c = [], a = 0, d = 0; d < e; d++) {\n        if (d % 4) {\n          var g = f.indexOf(b.charAt(d - 1)) << 2 * (d % 4),\n              h = f.indexOf(b.charAt(d)) >>> 6 - 2 * (d % 4);c[a >>> 2] |= (g | h) << 24 - 8 * (a % 4);a++;\n        }\n      }return j.create(c, a);\n    }, _map: \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=\" };\n})();\n\n/*\nCryptoJS v3.1.2 sha256-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function (k) {\n  for (var g = CryptoJS, h = g.lib, v = h.WordArray, j = h.Hasher, h = g.algo, s = [], t = [], u = function u(q) {\n    return 4294967296 * (q - (q | 0)) | 0;\n  }, l = 2, b = 0; 64 > b;) {\n    var d;a: {\n      d = l;for (var w = k.sqrt(d), r = 2; r <= w; r++) {\n        if (!(d % r)) {\n          d = !1;break a;\n        }\n      }d = !0;\n    }d && (8 > b && (s[b] = u(k.pow(l, 0.5))), t[b] = u(k.pow(l, 1 / 3)), b++);l++;\n  }var n = [],\n      h = h.SHA256 = j.extend({ _doReset: function _doReset() {\n      this._hash = new v.init(s.slice(0));\n    }, _doProcessBlock: function _doProcessBlock(q, h) {\n      for (var a = this._hash.words, c = a[0], d = a[1], b = a[2], k = a[3], f = a[4], g = a[5], j = a[6], l = a[7], e = 0; 64 > e; e++) {\n        if (16 > e) n[e] = q[h + e] | 0;else {\n          var m = n[e - 15],\n              p = n[e - 2];n[e] = ((m << 25 | m >>> 7) ^ (m << 14 | m >>> 18) ^ m >>> 3) + n[e - 7] + ((p << 15 | p >>> 17) ^ (p << 13 | p >>> 19) ^ p >>> 10) + n[e - 16];\n        }m = l + ((f << 26 | f >>> 6) ^ (f << 21 | f >>> 11) ^ (f << 7 | f >>> 25)) + (f & g ^ ~f & j) + t[e] + n[e];p = ((c << 30 | c >>> 2) ^ (c << 19 | c >>> 13) ^ (c << 10 | c >>> 22)) + (c & d ^ c & b ^ d & b);l = j;j = g;g = f;f = k + m | 0;k = b;b = d;d = c;c = m + p | 0;\n      }a[0] = a[0] + c | 0;a[1] = a[1] + d | 0;a[2] = a[2] + b | 0;a[3] = a[3] + k | 0;a[4] = a[4] + f | 0;a[5] = a[5] + g | 0;a[6] = a[6] + j | 0;a[7] = a[7] + l | 0;\n    }, _doFinalize: function _doFinalize() {\n      var d = this._data,\n          b = d.words,\n          a = 8 * this._nDataBytes,\n          c = 8 * d.sigBytes;\n      b[c >>> 5] |= 128 << 24 - c % 32;b[(c + 64 >>> 9 << 4) + 14] = k.floor(a / 4294967296);b[(c + 64 >>> 9 << 4) + 15] = a;d.sigBytes = 4 * b.length;this._process();return this._hash;\n    }, clone: function clone() {\n      var b = j.clone.call(this);b._hash = this._hash.clone();return b;\n    } });g.SHA256 = j._createHelper(h);g.HmacSHA256 = j._createHmacHelper(h);\n})(Math);\n\n/*\nCryptoJS v3.1.2 sha512-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function () {\n  function a() {\n    return d.create.apply(d, arguments);\n  }for (var n = CryptoJS, r = n.lib.Hasher, e = n.x64, d = e.Word, T = e.WordArray, e = n.algo, ea = [a(1116352408, 3609767458), a(1899447441, 602891725), a(3049323471, 3964484399), a(3921009573, 2173295548), a(961987163, 4081628472), a(1508970993, 3053834265), a(2453635748, 2937671579), a(2870763221, 3664609560), a(3624381080, 2734883394), a(310598401, 1164996542), a(607225278, 1323610764), a(1426881987, 3590304994), a(1925078388, 4068182383), a(2162078206, 991336113), a(2614888103, 633803317), a(3248222580, 3479774868), a(3835390401, 2666613458), a(4022224774, 944711139), a(264347078, 2341262773), a(604807628, 2007800933), a(770255983, 1495990901), a(1249150122, 1856431235), a(1555081692, 3175218132), a(1996064986, 2198950837), a(2554220882, 3999719339), a(2821834349, 766784016), a(2952996808, 2566594879), a(3210313671, 3203337956), a(3336571891, 1034457026), a(3584528711, 2466948901), a(113926993, 3758326383), a(338241895, 168717936), a(666307205, 1188179964), a(773529912, 1546045734), a(1294757372, 1522805485), a(1396182291, 2643833823), a(1695183700, 2343527390), a(1986661051, 1014477480), a(2177026350, 1206759142), a(2456956037, 344077627), a(2730485921, 1290863460), a(2820302411, 3158454273), a(3259730800, 3505952657), a(3345764771, 106217008), a(3516065817, 3606008344), a(3600352804, 1432725776), a(4094571909, 1467031594), a(275423344, 851169720), a(430227734, 3100823752), a(506948616, 1363258195), a(659060556, 3750685593), a(883997877, 3785050280), a(958139571, 3318307427), a(1322822218, 3812723403), a(1537002063, 2003034995), a(1747873779, 3602036899), a(1955562222, 1575990012), a(2024104815, 1125592928), a(2227730452, 2716904306), a(2361852424, 442776044), a(2428436474, 593698344), a(2756734187, 3733110249), a(3204031479, 2999351573), a(3329325298, 3815920427), a(3391569614, 3928383900), a(3515267271, 566280711), a(3940187606, 3454069534), a(4118630271, 4000239992), a(116418474, 1914138554), a(174292421, 2731055270), a(289380356, 3203993006), a(460393269, 320620315), a(685471733, 587496836), a(852142971, 1086792851), a(1017036298, 365543100), a(1126000580, 2618297676), a(1288033470, 3409855158), a(1501505948, 4234509866), a(1607167915, 987167468), a(1816402316, 1246189591)], v = [], w = 0; 80 > w; w++) {\n    v[w] = a();\n  }e = e.SHA512 = r.extend({ _doReset: function _doReset() {\n      this._hash = new T.init([new d.init(1779033703, 4089235720), new d.init(3144134277, 2227873595), new d.init(1013904242, 4271175723), new d.init(2773480762, 1595750129), new d.init(1359893119, 2917565137), new d.init(2600822924, 725511199), new d.init(528734635, 4215389547), new d.init(1541459225, 327033209)]);\n    }, _doProcessBlock: function _doProcessBlock(a, d) {\n      for (var f = this._hash.words, F = f[0], e = f[1], n = f[2], r = f[3], G = f[4], H = f[5], I = f[6], f = f[7], w = F.high, J = F.low, X = e.high, K = e.low, Y = n.high, L = n.low, Z = r.high, M = r.low, $ = G.high, N = G.low, aa = H.high, O = H.low, ba = I.high, P = I.low, ca = f.high, Q = f.low, k = w, g = J, z = X, x = K, A = Y, y = L, U = Z, B = M, l = $, h = N, R = aa, C = O, S = ba, D = P, V = ca, E = Q, m = 0; 80 > m; m++) {\n        var s = v[m];if (16 > m) var j = s.high = a[d + 2 * m] | 0,\n            b = s.low = a[d + 2 * m + 1] | 0;else {\n          var j = v[m - 15],\n              b = j.high,\n              p = j.low,\n              j = (b >>> 1 | p << 31) ^ (b >>> 8 | p << 24) ^ b >>> 7,\n              p = (p >>> 1 | b << 31) ^ (p >>> 8 | b << 24) ^ (p >>> 7 | b << 25),\n              u = v[m - 2],\n              b = u.high,\n              c = u.low,\n              u = (b >>> 19 | c << 13) ^ (b << 3 | c >>> 29) ^ b >>> 6,\n              c = (c >>> 19 | b << 13) ^ (c << 3 | b >>> 29) ^ (c >>> 6 | b << 26),\n              b = v[m - 7],\n              W = b.high,\n              t = v[m - 16],\n              q = t.high,\n              t = t.low,\n              b = p + b.low,\n              j = j + W + (b >>> 0 < p >>> 0 ? 1 : 0),\n              b = b + c,\n              j = j + u + (b >>> 0 < c >>> 0 ? 1 : 0),\n              b = b + t,\n              j = j + q + (b >>> 0 < t >>> 0 ? 1 : 0);s.high = j;s.low = b;\n        }var W = l & R ^ ~l & S,\n            t = h & C ^ ~h & D,\n            s = k & z ^ k & A ^ z & A,\n            T = g & x ^ g & y ^ x & y,\n            p = (k >>> 28 | g << 4) ^ (k << 30 | g >>> 2) ^ (k << 25 | g >>> 7),\n            u = (g >>> 28 | k << 4) ^ (g << 30 | k >>> 2) ^ (g << 25 | k >>> 7),\n            c = ea[m],\n            fa = c.high,\n            da = c.low,\n            c = E + ((h >>> 14 | l << 18) ^ (h >>> 18 | l << 14) ^ (h << 23 | l >>> 9)),\n            q = V + ((l >>> 14 | h << 18) ^ (l >>> 18 | h << 14) ^ (l << 23 | h >>> 9)) + (c >>> 0 < E >>> 0 ? 1 : 0),\n            c = c + t,\n            q = q + W + (c >>> 0 < t >>> 0 ? 1 : 0),\n            c = c + da,\n            q = q + fa + (c >>> 0 < da >>> 0 ? 1 : 0),\n            c = c + b,\n            q = q + j + (c >>> 0 < b >>> 0 ? 1 : 0),\n            b = u + T,\n            s = p + s + (b >>> 0 < u >>> 0 ? 1 : 0),\n            V = S,\n            E = D,\n            S = R,\n            D = C,\n            R = l,\n            C = h,\n            h = B + c | 0,\n            l = U + q + (h >>> 0 < B >>> 0 ? 1 : 0) | 0,\n            U = A,\n            B = y,\n            A = z,\n            y = x,\n            z = k,\n            x = g,\n            g = c + b | 0,\n            k = q + s + (g >>> 0 < c >>> 0 ? 1 : 0) | 0;\n      }J = F.low = J + g;F.high = w + k + (J >>> 0 < g >>> 0 ? 1 : 0);K = e.low = K + x;e.high = X + z + (K >>> 0 < x >>> 0 ? 1 : 0);L = n.low = L + y;n.high = Y + A + (L >>> 0 < y >>> 0 ? 1 : 0);M = r.low = M + B;r.high = Z + U + (M >>> 0 < B >>> 0 ? 1 : 0);N = G.low = N + h;G.high = $ + l + (N >>> 0 < h >>> 0 ? 1 : 0);O = H.low = O + C;H.high = aa + R + (O >>> 0 < C >>> 0 ? 1 : 0);P = I.low = P + D;\n      I.high = ba + S + (P >>> 0 < D >>> 0 ? 1 : 0);Q = f.low = Q + E;f.high = ca + V + (Q >>> 0 < E >>> 0 ? 1 : 0);\n    }, _doFinalize: function _doFinalize() {\n      var a = this._data,\n          d = a.words,\n          f = 8 * this._nDataBytes,\n          e = 8 * a.sigBytes;d[e >>> 5] |= 128 << 24 - e % 32;d[(e + 128 >>> 10 << 5) + 30] = Math.floor(f / 4294967296);d[(e + 128 >>> 10 << 5) + 31] = f;a.sigBytes = 4 * d.length;this._process();return this._hash.toX32();\n    }, clone: function clone() {\n      var a = r.clone.call(this);a._hash = this._hash.clone();return a;\n    }, blockSize: 32 });n.SHA512 = r._createHelper(e);n.HmacSHA512 = r._createHmacHelper(e);\n})();\n\n/*\nCryptoJS v3.1.2 sha384-min.js\ncode.google.com/p/crypto-js\n(c) 2009-2013 by Jeff Mott. All rights reserved.\ncode.google.com/p/crypto-js/wiki/License\n*/\n(function () {\n  var c = CryptoJS,\n      a = c.x64,\n      b = a.Word,\n      e = a.WordArray,\n      a = c.algo,\n      d = a.SHA512,\n      a = a.SHA384 = d.extend({ _doReset: function _doReset() {\n      this._hash = new e.init([new b.init(3418070365, 3238371032), new b.init(1654270250, 914150663), new b.init(2438529370, 812702999), new b.init(355462360, 4144912697), new b.init(1731405415, 4290775857), new b.init(2394180231, 1750603025), new b.init(3675008525, 1694076839), new b.init(1203062813, 3204075428)]);\n    }, _doFinalize: function _doFinalize() {\n      var a = d._doFinalize.call(this);a.sigBytes -= 16;return a;\n    } });c.SHA384 = d._createHelper(a);c.HmacSHA384 = d._createHmacHelper(a);\n})();\n\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nvar b64map = \"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\";var b64pad = \"=\";function hex2b64(d) {\n  var b;var e;var a = \"\";for (b = 0; b + 3 <= d.length; b += 3) {\n    e = parseInt(d.substring(b, b + 3), 16);a += b64map.charAt(e >> 6) + b64map.charAt(e & 63);\n  }if (b + 1 == d.length) {\n    e = parseInt(d.substring(b, b + 1), 16);a += b64map.charAt(e << 2);\n  } else {\n    if (b + 2 == d.length) {\n      e = parseInt(d.substring(b, b + 2), 16);a += b64map.charAt(e >> 2) + b64map.charAt((e & 3) << 4);\n    }\n  }if (b64pad) {\n    while ((a.length & 3) > 0) {\n      a += b64pad;\n    }\n  }return a;\n}function b64tohex(f) {\n  var d = \"\";var e;var b = 0;var c;var a;for (e = 0; e < f.length; ++e) {\n    if (f.charAt(e) == b64pad) {\n      break;\n    }a = b64map.indexOf(f.charAt(e));if (a < 0) {\n      continue;\n    }if (b == 0) {\n      d += int2char(a >> 2);c = a & 3;b = 1;\n    } else {\n      if (b == 1) {\n        d += int2char(c << 2 | a >> 4);c = a & 15;b = 2;\n      } else {\n        if (b == 2) {\n          d += int2char(c);d += int2char(a >> 2);c = a & 3;b = 3;\n        } else {\n          d += int2char(c << 2 | a >> 4);d += int2char(a & 15);b = 0;\n        }\n      }\n    }\n  }if (b == 1) {\n    d += int2char(c << 2);\n  }return d;\n}function b64toBA(e) {\n  var d = b64tohex(e);var c;var b = new Array();for (c = 0; 2 * c < d.length; ++c) {\n    b[c] = parseInt(d.substring(2 * c, 2 * c + 2), 16);\n  }return b;\n};\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nvar dbits;var canary = 244837814094590;var j_lm = (canary & 16777215) == 15715070;function BigInteger(e, d, f) {\n  if (e != null) {\n    if (\"number\" == typeof e) {\n      this.fromNumber(e, d, f);\n    } else {\n      if (d == null && \"string\" != typeof e) {\n        this.fromString(e, 256);\n      } else {\n        this.fromString(e, d);\n      }\n    }\n  }\n}function nbi() {\n  return new BigInteger(null);\n}function am1(f, a, b, e, h, g) {\n  while (--g >= 0) {\n    var d = a * this[f++] + b[e] + h;h = Math.floor(d / 67108864);b[e++] = d & 67108863;\n  }return h;\n}function am2(f, q, r, e, o, a) {\n  var k = q & 32767,\n      p = q >> 15;while (--a >= 0) {\n    var d = this[f] & 32767;var g = this[f++] >> 15;var b = p * d + g * k;d = k * d + ((b & 32767) << 15) + r[e] + (o & 1073741823);o = (d >>> 30) + (b >>> 15) + p * g + (o >>> 30);r[e++] = d & 1073741823;\n  }return o;\n}function am3(f, q, r, e, o, a) {\n  var k = q & 16383,\n      p = q >> 14;while (--a >= 0) {\n    var d = this[f] & 16383;var g = this[f++] >> 14;var b = p * d + g * k;d = k * d + ((b & 16383) << 14) + r[e] + o;o = (d >> 28) + (b >> 14) + p * g;r[e++] = d & 268435455;\n  }return o;\n}if (j_lm && navigator.appName == \"Microsoft Internet Explorer\") {\n  BigInteger.prototype.am = am2;dbits = 30;\n} else {\n  if (j_lm && navigator.appName != \"Netscape\") {\n    BigInteger.prototype.am = am1;dbits = 26;\n  } else {\n    BigInteger.prototype.am = am3;dbits = 28;\n  }\n}BigInteger.prototype.DB = dbits;BigInteger.prototype.DM = (1 << dbits) - 1;BigInteger.prototype.DV = 1 << dbits;var BI_FP = 52;BigInteger.prototype.FV = Math.pow(2, BI_FP);BigInteger.prototype.F1 = BI_FP - dbits;BigInteger.prototype.F2 = 2 * dbits - BI_FP;var BI_RM = \"0123456789abcdefghijklmnopqrstuvwxyz\";var BI_RC = new Array();var rr, vv;rr = \"0\".charCodeAt(0);for (vv = 0; vv <= 9; ++vv) {\n  BI_RC[rr++] = vv;\n}rr = \"a\".charCodeAt(0);for (vv = 10; vv < 36; ++vv) {\n  BI_RC[rr++] = vv;\n}rr = \"A\".charCodeAt(0);for (vv = 10; vv < 36; ++vv) {\n  BI_RC[rr++] = vv;\n}function int2char(a) {\n  return BI_RM.charAt(a);\n}function intAt(b, a) {\n  var d = BI_RC[b.charCodeAt(a)];return d == null ? -1 : d;\n}function bnpCopyTo(b) {\n  for (var a = this.t - 1; a >= 0; --a) {\n    b[a] = this[a];\n  }b.t = this.t;b.s = this.s;\n}function bnpFromInt(a) {\n  this.t = 1;this.s = a < 0 ? -1 : 0;if (a > 0) {\n    this[0] = a;\n  } else {\n    if (a < -1) {\n      this[0] = a + this.DV;\n    } else {\n      this.t = 0;\n    }\n  }\n}function nbv(a) {\n  var b = nbi();b.fromInt(a);return b;\n}function bnpFromString(h, c) {\n  var e;if (c == 16) {\n    e = 4;\n  } else {\n    if (c == 8) {\n      e = 3;\n    } else {\n      if (c == 256) {\n        e = 8;\n      } else {\n        if (c == 2) {\n          e = 1;\n        } else {\n          if (c == 32) {\n            e = 5;\n          } else {\n            if (c == 4) {\n              e = 2;\n            } else {\n              this.fromRadix(h, c);return;\n            }\n          }\n        }\n      }\n    }\n  }this.t = 0;this.s = 0;var g = h.length,\n      d = false,\n      f = 0;while (--g >= 0) {\n    var a = e == 8 ? h[g] & 255 : intAt(h, g);if (a < 0) {\n      if (h.charAt(g) == \"-\") {\n        d = true;\n      }continue;\n    }d = false;if (f == 0) {\n      this[this.t++] = a;\n    } else {\n      if (f + e > this.DB) {\n        this[this.t - 1] |= (a & (1 << this.DB - f) - 1) << f;this[this.t++] = a >> this.DB - f;\n      } else {\n        this[this.t - 1] |= a << f;\n      }\n    }f += e;if (f >= this.DB) {\n      f -= this.DB;\n    }\n  }if (e == 8 && (h[0] & 128) != 0) {\n    this.s = -1;if (f > 0) {\n      this[this.t - 1] |= (1 << this.DB - f) - 1 << f;\n    }\n  }this.clamp();if (d) {\n    BigInteger.ZERO.subTo(this, this);\n  }\n}function bnpClamp() {\n  var a = this.s & this.DM;while (this.t > 0 && this[this.t - 1] == a) {\n    --this.t;\n  }\n}function bnToString(c) {\n  if (this.s < 0) {\n    return \"-\" + this.negate().toString(c);\n  }var e;if (c == 16) {\n    e = 4;\n  } else {\n    if (c == 8) {\n      e = 3;\n    } else {\n      if (c == 2) {\n        e = 1;\n      } else {\n        if (c == 32) {\n          e = 5;\n        } else {\n          if (c == 4) {\n            e = 2;\n          } else {\n            return this.toRadix(c);\n          }\n        }\n      }\n    }\n  }var g = (1 << e) - 1,\n      l,\n      a = false,\n      h = \"\",\n      f = this.t;var j = this.DB - f * this.DB % e;if (f-- > 0) {\n    if (j < this.DB && (l = this[f] >> j) > 0) {\n      a = true;h = int2char(l);\n    }while (f >= 0) {\n      if (j < e) {\n        l = (this[f] & (1 << j) - 1) << e - j;l |= this[--f] >> (j += this.DB - e);\n      } else {\n        l = this[f] >> (j -= e) & g;if (j <= 0) {\n          j += this.DB;--f;\n        }\n      }if (l > 0) {\n        a = true;\n      }if (a) {\n        h += int2char(l);\n      }\n    }\n  }return a ? h : \"0\";\n}function bnNegate() {\n  var a = nbi();BigInteger.ZERO.subTo(this, a);return a;\n}function bnAbs() {\n  return this.s < 0 ? this.negate() : this;\n}function bnCompareTo(b) {\n  var d = this.s - b.s;if (d != 0) {\n    return d;\n  }var c = this.t;d = c - b.t;if (d != 0) {\n    return this.s < 0 ? -d : d;\n  }while (--c >= 0) {\n    if ((d = this[c] - b[c]) != 0) {\n      return d;\n    }\n  }return 0;\n}function nbits(a) {\n  var c = 1,\n      b;if ((b = a >>> 16) != 0) {\n    a = b;c += 16;\n  }if ((b = a >> 8) != 0) {\n    a = b;c += 8;\n  }if ((b = a >> 4) != 0) {\n    a = b;c += 4;\n  }if ((b = a >> 2) != 0) {\n    a = b;c += 2;\n  }if ((b = a >> 1) != 0) {\n    a = b;c += 1;\n  }return c;\n}function bnBitLength() {\n  if (this.t <= 0) {\n    return 0;\n  }return this.DB * (this.t - 1) + nbits(this[this.t - 1] ^ this.s & this.DM);\n}function bnpDLShiftTo(c, b) {\n  var a;for (a = this.t - 1; a >= 0; --a) {\n    b[a + c] = this[a];\n  }for (a = c - 1; a >= 0; --a) {\n    b[a] = 0;\n  }b.t = this.t + c;b.s = this.s;\n}function bnpDRShiftTo(c, b) {\n  for (var a = c; a < this.t; ++a) {\n    b[a - c] = this[a];\n  }b.t = Math.max(this.t - c, 0);b.s = this.s;\n}function bnpLShiftTo(j, e) {\n  var b = j % this.DB;var a = this.DB - b;var g = (1 << a) - 1;var f = Math.floor(j / this.DB),\n      h = this.s << b & this.DM,\n      d;for (d = this.t - 1; d >= 0; --d) {\n    e[d + f + 1] = this[d] >> a | h;h = (this[d] & g) << b;\n  }for (d = f - 1; d >= 0; --d) {\n    e[d] = 0;\n  }e[f] = h;e.t = this.t + f + 1;e.s = this.s;e.clamp();\n}function bnpRShiftTo(g, d) {\n  d.s = this.s;var e = Math.floor(g / this.DB);if (e >= this.t) {\n    d.t = 0;return;\n  }var b = g % this.DB;var a = this.DB - b;var f = (1 << b) - 1;d[0] = this[e] >> b;for (var c = e + 1; c < this.t; ++c) {\n    d[c - e - 1] |= (this[c] & f) << a;d[c - e] = this[c] >> b;\n  }if (b > 0) {\n    d[this.t - e - 1] |= (this.s & f) << a;\n  }d.t = this.t - e;d.clamp();\n}function bnpSubTo(d, f) {\n  var e = 0,\n      g = 0,\n      b = Math.min(d.t, this.t);while (e < b) {\n    g += this[e] - d[e];f[e++] = g & this.DM;g >>= this.DB;\n  }if (d.t < this.t) {\n    g -= d.s;while (e < this.t) {\n      g += this[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g += this.s;\n  } else {\n    g += this.s;while (e < d.t) {\n      g -= d[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g -= d.s;\n  }f.s = g < 0 ? -1 : 0;if (g < -1) {\n    f[e++] = this.DV + g;\n  } else {\n    if (g > 0) {\n      f[e++] = g;\n    }\n  }f.t = e;f.clamp();\n}function bnpMultiplyTo(c, e) {\n  var b = this.abs(),\n      f = c.abs();var d = b.t;e.t = d + f.t;while (--d >= 0) {\n    e[d] = 0;\n  }for (d = 0; d < f.t; ++d) {\n    e[d + b.t] = b.am(0, f[d], e, d, 0, b.t);\n  }e.s = 0;e.clamp();if (this.s != c.s) {\n    BigInteger.ZERO.subTo(e, e);\n  }\n}function bnpSquareTo(d) {\n  var a = this.abs();var b = d.t = 2 * a.t;while (--b >= 0) {\n    d[b] = 0;\n  }for (b = 0; b < a.t - 1; ++b) {\n    var e = a.am(b, a[b], d, 2 * b, 0, 1);if ((d[b + a.t] += a.am(b + 1, 2 * a[b], d, 2 * b + 1, e, a.t - b - 1)) >= a.DV) {\n      d[b + a.t] -= a.DV;d[b + a.t + 1] = 1;\n    }\n  }if (d.t > 0) {\n    d[d.t - 1] += a.am(b, a[b], d, 2 * b, 0, 1);\n  }d.s = 0;d.clamp();\n}function bnpDivRemTo(n, h, g) {\n  var w = n.abs();if (w.t <= 0) {\n    return;\n  }var k = this.abs();if (k.t < w.t) {\n    if (h != null) {\n      h.fromInt(0);\n    }if (g != null) {\n      this.copyTo(g);\n    }return;\n  }if (g == null) {\n    g = nbi();\n  }var d = nbi(),\n      a = this.s,\n      l = n.s;var v = this.DB - nbits(w[w.t - 1]);if (v > 0) {\n    w.lShiftTo(v, d);k.lShiftTo(v, g);\n  } else {\n    w.copyTo(d);k.copyTo(g);\n  }var p = d.t;var b = d[p - 1];if (b == 0) {\n    return;\n  }var o = b * (1 << this.F1) + (p > 1 ? d[p - 2] >> this.F2 : 0);var A = this.FV / o,\n      z = (1 << this.F1) / o,\n      x = 1 << this.F2;var u = g.t,\n      s = u - p,\n      f = h == null ? nbi() : h;d.dlShiftTo(s, f);if (g.compareTo(f) >= 0) {\n    g[g.t++] = 1;g.subTo(f, g);\n  }BigInteger.ONE.dlShiftTo(p, f);f.subTo(d, d);while (d.t < p) {\n    d[d.t++] = 0;\n  }while (--s >= 0) {\n    var c = g[--u] == b ? this.DM : Math.floor(g[u] * A + (g[u - 1] + x) * z);if ((g[u] += d.am(0, c, g, s, 0, p)) < c) {\n      d.dlShiftTo(s, f);g.subTo(f, g);while (g[u] < --c) {\n        g.subTo(f, g);\n      }\n    }\n  }if (h != null) {\n    g.drShiftTo(p, h);if (a != l) {\n      BigInteger.ZERO.subTo(h, h);\n    }\n  }g.t = p;g.clamp();if (v > 0) {\n    g.rShiftTo(v, g);\n  }if (a < 0) {\n    BigInteger.ZERO.subTo(g, g);\n  }\n}function bnMod(b) {\n  var c = nbi();this.abs().divRemTo(b, null, c);if (this.s < 0 && c.compareTo(BigInteger.ZERO) > 0) {\n    b.subTo(c, c);\n  }return c;\n}function Classic(a) {\n  this.m = a;\n}function cConvert(a) {\n  if (a.s < 0 || a.compareTo(this.m) >= 0) {\n    return a.mod(this.m);\n  } else {\n    return a;\n  }\n}function cRevert(a) {\n  return a;\n}function cReduce(a) {\n  a.divRemTo(this.m, null, a);\n}function cMulTo(a, c, b) {\n  a.multiplyTo(c, b);this.reduce(b);\n}function cSqrTo(a, b) {\n  a.squareTo(b);this.reduce(b);\n}Classic.prototype.convert = cConvert;Classic.prototype.revert = cRevert;Classic.prototype.reduce = cReduce;Classic.prototype.mulTo = cMulTo;Classic.prototype.sqrTo = cSqrTo;function bnpInvDigit() {\n  if (this.t < 1) {\n    return 0;\n  }var a = this[0];if ((a & 1) == 0) {\n    return 0;\n  }var b = a & 3;b = b * (2 - (a & 15) * b) & 15;b = b * (2 - (a & 255) * b) & 255;b = b * (2 - ((a & 65535) * b & 65535)) & 65535;b = b * (2 - a * b % this.DV) % this.DV;return b > 0 ? this.DV - b : -b;\n}function Montgomery(a) {\n  this.m = a;this.mp = a.invDigit();this.mpl = this.mp & 32767;this.mph = this.mp >> 15;this.um = (1 << a.DB - 15) - 1;this.mt2 = 2 * a.t;\n}function montConvert(a) {\n  var b = nbi();a.abs().dlShiftTo(this.m.t, b);b.divRemTo(this.m, null, b);if (a.s < 0 && b.compareTo(BigInteger.ZERO) > 0) {\n    this.m.subTo(b, b);\n  }return b;\n}function montRevert(a) {\n  var b = nbi();a.copyTo(b);this.reduce(b);return b;\n}function montReduce(a) {\n  while (a.t <= this.mt2) {\n    a[a.t++] = 0;\n  }for (var c = 0; c < this.m.t; ++c) {\n    var b = a[c] & 32767;var d = b * this.mpl + ((b * this.mph + (a[c] >> 15) * this.mpl & this.um) << 15) & a.DM;b = c + this.m.t;a[b] += this.m.am(0, d, a, c, 0, this.m.t);while (a[b] >= a.DV) {\n      a[b] -= a.DV;a[++b]++;\n    }\n  }a.clamp();a.drShiftTo(this.m.t, a);if (a.compareTo(this.m) >= 0) {\n    a.subTo(this.m, a);\n  }\n}function montSqrTo(a, b) {\n  a.squareTo(b);this.reduce(b);\n}function montMulTo(a, c, b) {\n  a.multiplyTo(c, b);this.reduce(b);\n}Montgomery.prototype.convert = montConvert;Montgomery.prototype.revert = montRevert;Montgomery.prototype.reduce = montReduce;Montgomery.prototype.mulTo = montMulTo;Montgomery.prototype.sqrTo = montSqrTo;function bnpIsEven() {\n  return (this.t > 0 ? this[0] & 1 : this.s) == 0;\n}function bnpExp(h, j) {\n  if (h > 4294967295 || h < 1) {\n    return BigInteger.ONE;\n  }var f = nbi(),\n      a = nbi(),\n      d = j.convert(this),\n      c = nbits(h) - 1;d.copyTo(f);while (--c >= 0) {\n    j.sqrTo(f, a);if ((h & 1 << c) > 0) {\n      j.mulTo(a, d, f);\n    } else {\n      var b = f;f = a;a = b;\n    }\n  }return j.revert(f);\n}function bnModPowInt(b, a) {\n  var c;if (b < 256 || a.isEven()) {\n    c = new Classic(a);\n  } else {\n    c = new Montgomery(a);\n  }return this.exp(b, c);\n}BigInteger.prototype.copyTo = bnpCopyTo;BigInteger.prototype.fromInt = bnpFromInt;BigInteger.prototype.fromString = bnpFromString;BigInteger.prototype.clamp = bnpClamp;BigInteger.prototype.dlShiftTo = bnpDLShiftTo;BigInteger.prototype.drShiftTo = bnpDRShiftTo;BigInteger.prototype.lShiftTo = bnpLShiftTo;BigInteger.prototype.rShiftTo = bnpRShiftTo;BigInteger.prototype.subTo = bnpSubTo;BigInteger.prototype.multiplyTo = bnpMultiplyTo;BigInteger.prototype.squareTo = bnpSquareTo;BigInteger.prototype.divRemTo = bnpDivRemTo;BigInteger.prototype.invDigit = bnpInvDigit;BigInteger.prototype.isEven = bnpIsEven;BigInteger.prototype.exp = bnpExp;BigInteger.prototype.toString = bnToString;BigInteger.prototype.negate = bnNegate;BigInteger.prototype.abs = bnAbs;BigInteger.prototype.compareTo = bnCompareTo;BigInteger.prototype.bitLength = bnBitLength;BigInteger.prototype.mod = bnMod;BigInteger.prototype.modPowInt = bnModPowInt;BigInteger.ZERO = nbv(0);BigInteger.ONE = nbv(1);\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction bnClone() {\n  var a = nbi();this.copyTo(a);return a;\n}function bnIntValue() {\n  if (this.s < 0) {\n    if (this.t == 1) {\n      return this[0] - this.DV;\n    } else {\n      if (this.t == 0) {\n        return -1;\n      }\n    }\n  } else {\n    if (this.t == 1) {\n      return this[0];\n    } else {\n      if (this.t == 0) {\n        return 0;\n      }\n    }\n  }return (this[1] & (1 << 32 - this.DB) - 1) << this.DB | this[0];\n}function bnByteValue() {\n  return this.t == 0 ? this.s : this[0] << 24 >> 24;\n}function bnShortValue() {\n  return this.t == 0 ? this.s : this[0] << 16 >> 16;\n}function bnpChunkSize(a) {\n  return Math.floor(Math.LN2 * this.DB / Math.log(a));\n}function bnSigNum() {\n  if (this.s < 0) {\n    return -1;\n  } else {\n    if (this.t <= 0 || this.t == 1 && this[0] <= 0) {\n      return 0;\n    } else {\n      return 1;\n    }\n  }\n}function bnpToRadix(c) {\n  if (c == null) {\n    c = 10;\n  }if (this.signum() == 0 || c < 2 || c > 36) {\n    return \"0\";\n  }var f = this.chunkSize(c);var e = Math.pow(c, f);var i = nbv(e),\n      j = nbi(),\n      h = nbi(),\n      g = \"\";this.divRemTo(i, j, h);while (j.signum() > 0) {\n    g = (e + h.intValue()).toString(c).substr(1) + g;j.divRemTo(i, j, h);\n  }return h.intValue().toString(c) + g;\n}function bnpFromRadix(m, h) {\n  this.fromInt(0);if (h == null) {\n    h = 10;\n  }var f = this.chunkSize(h);var g = Math.pow(h, f),\n      e = false,\n      a = 0,\n      l = 0;for (var c = 0; c < m.length; ++c) {\n    var k = intAt(m, c);if (k < 0) {\n      if (m.charAt(c) == \"-\" && this.signum() == 0) {\n        e = true;\n      }continue;\n    }l = h * l + k;if (++a >= f) {\n      this.dMultiply(g);this.dAddOffset(l, 0);a = 0;l = 0;\n    }\n  }if (a > 0) {\n    this.dMultiply(Math.pow(h, a));this.dAddOffset(l, 0);\n  }if (e) {\n    BigInteger.ZERO.subTo(this, this);\n  }\n}function bnpFromNumber(f, e, h) {\n  if (\"number\" == typeof e) {\n    if (f < 2) {\n      this.fromInt(1);\n    } else {\n      this.fromNumber(f, h);if (!this.testBit(f - 1)) {\n        this.bitwiseTo(BigInteger.ONE.shiftLeft(f - 1), op_or, this);\n      }if (this.isEven()) {\n        this.dAddOffset(1, 0);\n      }while (!this.isProbablePrime(e)) {\n        this.dAddOffset(2, 0);if (this.bitLength() > f) {\n          this.subTo(BigInteger.ONE.shiftLeft(f - 1), this);\n        }\n      }\n    }\n  } else {\n    var d = new Array(),\n        g = f & 7;d.length = (f >> 3) + 1;e.nextBytes(d);if (g > 0) {\n      d[0] &= (1 << g) - 1;\n    } else {\n      d[0] = 0;\n    }this.fromString(d, 256);\n  }\n}function bnToByteArray() {\n  var b = this.t,\n      c = new Array();c[0] = this.s;var e = this.DB - b * this.DB % 8,\n      f,\n      a = 0;if (b-- > 0) {\n    if (e < this.DB && (f = this[b] >> e) != (this.s & this.DM) >> e) {\n      c[a++] = f | this.s << this.DB - e;\n    }while (b >= 0) {\n      if (e < 8) {\n        f = (this[b] & (1 << e) - 1) << 8 - e;f |= this[--b] >> (e += this.DB - 8);\n      } else {\n        f = this[b] >> (e -= 8) & 255;if (e <= 0) {\n          e += this.DB;--b;\n        }\n      }if ((f & 128) != 0) {\n        f |= -256;\n      }if (a == 0 && (this.s & 128) != (f & 128)) {\n        ++a;\n      }if (a > 0 || f != this.s) {\n        c[a++] = f;\n      }\n    }\n  }return c;\n}function bnEquals(b) {\n  return this.compareTo(b) == 0;\n}function bnMin(b) {\n  return this.compareTo(b) < 0 ? this : b;\n}function bnMax(b) {\n  return this.compareTo(b) > 0 ? this : b;\n}function bnpBitwiseTo(c, h, e) {\n  var d,\n      g,\n      b = Math.min(c.t, this.t);for (d = 0; d < b; ++d) {\n    e[d] = h(this[d], c[d]);\n  }if (c.t < this.t) {\n    g = c.s & this.DM;for (d = b; d < this.t; ++d) {\n      e[d] = h(this[d], g);\n    }e.t = this.t;\n  } else {\n    g = this.s & this.DM;for (d = b; d < c.t; ++d) {\n      e[d] = h(g, c[d]);\n    }e.t = c.t;\n  }e.s = h(this.s, c.s);e.clamp();\n}function op_and(a, b) {\n  return a & b;\n}function bnAnd(b) {\n  var c = nbi();this.bitwiseTo(b, op_and, c);return c;\n}function op_or(a, b) {\n  return a | b;\n}function bnOr(b) {\n  var c = nbi();this.bitwiseTo(b, op_or, c);return c;\n}function op_xor(a, b) {\n  return a ^ b;\n}function bnXor(b) {\n  var c = nbi();this.bitwiseTo(b, op_xor, c);return c;\n}function op_andnot(a, b) {\n  return a & ~b;\n}function bnAndNot(b) {\n  var c = nbi();this.bitwiseTo(b, op_andnot, c);return c;\n}function bnNot() {\n  var b = nbi();for (var a = 0; a < this.t; ++a) {\n    b[a] = this.DM & ~this[a];\n  }b.t = this.t;b.s = ~this.s;return b;\n}function bnShiftLeft(b) {\n  var a = nbi();if (b < 0) {\n    this.rShiftTo(-b, a);\n  } else {\n    this.lShiftTo(b, a);\n  }return a;\n}function bnShiftRight(b) {\n  var a = nbi();if (b < 0) {\n    this.lShiftTo(-b, a);\n  } else {\n    this.rShiftTo(b, a);\n  }return a;\n}function lbit(a) {\n  if (a == 0) {\n    return -1;\n  }var b = 0;if ((a & 65535) == 0) {\n    a >>= 16;b += 16;\n  }if ((a & 255) == 0) {\n    a >>= 8;b += 8;\n  }if ((a & 15) == 0) {\n    a >>= 4;b += 4;\n  }if ((a & 3) == 0) {\n    a >>= 2;b += 2;\n  }if ((a & 1) == 0) {\n    ++b;\n  }return b;\n}function bnGetLowestSetBit() {\n  for (var a = 0; a < this.t; ++a) {\n    if (this[a] != 0) {\n      return a * this.DB + lbit(this[a]);\n    }\n  }if (this.s < 0) {\n    return this.t * this.DB;\n  }return -1;\n}function cbit(a) {\n  var b = 0;while (a != 0) {\n    a &= a - 1;++b;\n  }return b;\n}function bnBitCount() {\n  var c = 0,\n      a = this.s & this.DM;for (var b = 0; b < this.t; ++b) {\n    c += cbit(this[b] ^ a);\n  }return c;\n}function bnTestBit(b) {\n  var a = Math.floor(b / this.DB);if (a >= this.t) {\n    return this.s != 0;\n  }return (this[a] & 1 << b % this.DB) != 0;\n}function bnpChangeBit(c, b) {\n  var a = BigInteger.ONE.shiftLeft(c);this.bitwiseTo(a, b, a);return a;\n}function bnSetBit(a) {\n  return this.changeBit(a, op_or);\n}function bnClearBit(a) {\n  return this.changeBit(a, op_andnot);\n}function bnFlipBit(a) {\n  return this.changeBit(a, op_xor);\n}function bnpAddTo(d, f) {\n  var e = 0,\n      g = 0,\n      b = Math.min(d.t, this.t);while (e < b) {\n    g += this[e] + d[e];f[e++] = g & this.DM;g >>= this.DB;\n  }if (d.t < this.t) {\n    g += d.s;while (e < this.t) {\n      g += this[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g += this.s;\n  } else {\n    g += this.s;while (e < d.t) {\n      g += d[e];f[e++] = g & this.DM;g >>= this.DB;\n    }g += d.s;\n  }f.s = g < 0 ? -1 : 0;if (g > 0) {\n    f[e++] = g;\n  } else {\n    if (g < -1) {\n      f[e++] = this.DV + g;\n    }\n  }f.t = e;f.clamp();\n}function bnAdd(b) {\n  var c = nbi();this.addTo(b, c);return c;\n}function bnSubtract(b) {\n  var c = nbi();this.subTo(b, c);return c;\n}function bnMultiply(b) {\n  var c = nbi();this.multiplyTo(b, c);return c;\n}function bnSquare() {\n  var a = nbi();this.squareTo(a);return a;\n}function bnDivide(b) {\n  var c = nbi();this.divRemTo(b, c, null);return c;\n}function bnRemainder(b) {\n  var c = nbi();this.divRemTo(b, null, c);return c;\n}function bnDivideAndRemainder(b) {\n  var d = nbi(),\n      c = nbi();this.divRemTo(b, d, c);return new Array(d, c);\n}function bnpDMultiply(a) {\n  this[this.t] = this.am(0, a - 1, this, 0, 0, this.t);++this.t;this.clamp();\n}function bnpDAddOffset(b, a) {\n  if (b == 0) {\n    return;\n  }while (this.t <= a) {\n    this[this.t++] = 0;\n  }this[a] += b;while (this[a] >= this.DV) {\n    this[a] -= this.DV;if (++a >= this.t) {\n      this[this.t++] = 0;\n    }++this[a];\n  }\n}function NullExp() {}function nNop(a) {\n  return a;\n}function nMulTo(a, c, b) {\n  a.multiplyTo(c, b);\n}function nSqrTo(a, b) {\n  a.squareTo(b);\n}NullExp.prototype.convert = nNop;NullExp.prototype.revert = nNop;NullExp.prototype.mulTo = nMulTo;NullExp.prototype.sqrTo = nSqrTo;function bnPow(a) {\n  return this.exp(a, new NullExp());\n}function bnpMultiplyLowerTo(b, f, e) {\n  var d = Math.min(this.t + b.t, f);e.s = 0;e.t = d;while (d > 0) {\n    e[--d] = 0;\n  }var c;for (c = e.t - this.t; d < c; ++d) {\n    e[d + this.t] = this.am(0, b[d], e, d, 0, this.t);\n  }for (c = Math.min(b.t, f); d < c; ++d) {\n    this.am(0, b[d], e, d, 0, f - d);\n  }e.clamp();\n}function bnpMultiplyUpperTo(b, e, d) {\n  --e;var c = d.t = this.t + b.t - e;d.s = 0;while (--c >= 0) {\n    d[c] = 0;\n  }for (c = Math.max(e - this.t, 0); c < b.t; ++c) {\n    d[this.t + c - e] = this.am(e - c, b[c], d, 0, 0, this.t + c - e);\n  }d.clamp();d.drShiftTo(1, d);\n}function Barrett(a) {\n  this.r2 = nbi();this.q3 = nbi();BigInteger.ONE.dlShiftTo(2 * a.t, this.r2);this.mu = this.r2.divide(a);this.m = a;\n}function barrettConvert(a) {\n  if (a.s < 0 || a.t > 2 * this.m.t) {\n    return a.mod(this.m);\n  } else {\n    if (a.compareTo(this.m) < 0) {\n      return a;\n    } else {\n      var b = nbi();a.copyTo(b);this.reduce(b);return b;\n    }\n  }\n}function barrettRevert(a) {\n  return a;\n}function barrettReduce(a) {\n  a.drShiftTo(this.m.t - 1, this.r2);if (a.t > this.m.t + 1) {\n    a.t = this.m.t + 1;a.clamp();\n  }this.mu.multiplyUpperTo(this.r2, this.m.t + 1, this.q3);this.m.multiplyLowerTo(this.q3, this.m.t + 1, this.r2);while (a.compareTo(this.r2) < 0) {\n    a.dAddOffset(1, this.m.t + 1);\n  }a.subTo(this.r2, a);while (a.compareTo(this.m) >= 0) {\n    a.subTo(this.m, a);\n  }\n}function barrettSqrTo(a, b) {\n  a.squareTo(b);this.reduce(b);\n}function barrettMulTo(a, c, b) {\n  a.multiplyTo(c, b);this.reduce(b);\n}Barrett.prototype.convert = barrettConvert;Barrett.prototype.revert = barrettRevert;Barrett.prototype.reduce = barrettReduce;Barrett.prototype.mulTo = barrettMulTo;Barrett.prototype.sqrTo = barrettSqrTo;function bnModPow(q, f) {\n  var o = q.bitLength(),\n      h,\n      b = nbv(1),\n      v;if (o <= 0) {\n    return b;\n  } else {\n    if (o < 18) {\n      h = 1;\n    } else {\n      if (o < 48) {\n        h = 3;\n      } else {\n        if (o < 144) {\n          h = 4;\n        } else {\n          if (o < 768) {\n            h = 5;\n          } else {\n            h = 6;\n          }\n        }\n      }\n    }\n  }if (o < 8) {\n    v = new Classic(f);\n  } else {\n    if (f.isEven()) {\n      v = new Barrett(f);\n    } else {\n      v = new Montgomery(f);\n    }\n  }var p = new Array(),\n      d = 3,\n      s = h - 1,\n      a = (1 << h) - 1;p[1] = v.convert(this);if (h > 1) {\n    var A = nbi();v.sqrTo(p[1], A);while (d <= a) {\n      p[d] = nbi();v.mulTo(A, p[d - 2], p[d]);d += 2;\n    }\n  }var l = q.t - 1,\n      x,\n      u = true,\n      c = nbi(),\n      y;o = nbits(q[l]) - 1;while (l >= 0) {\n    if (o >= s) {\n      x = q[l] >> o - s & a;\n    } else {\n      x = (q[l] & (1 << o + 1) - 1) << s - o;if (l > 0) {\n        x |= q[l - 1] >> this.DB + o - s;\n      }\n    }d = h;while ((x & 1) == 0) {\n      x >>= 1;--d;\n    }if ((o -= d) < 0) {\n      o += this.DB;--l;\n    }if (u) {\n      p[x].copyTo(b);u = false;\n    } else {\n      while (d > 1) {\n        v.sqrTo(b, c);v.sqrTo(c, b);d -= 2;\n      }if (d > 0) {\n        v.sqrTo(b, c);\n      } else {\n        y = b;b = c;c = y;\n      }v.mulTo(c, p[x], b);\n    }while (l >= 0 && (q[l] & 1 << o) == 0) {\n      v.sqrTo(b, c);y = b;b = c;c = y;if (--o < 0) {\n        o = this.DB - 1;--l;\n      }\n    }\n  }return v.revert(b);\n}function bnGCD(c) {\n  var b = this.s < 0 ? this.negate() : this.clone();var h = c.s < 0 ? c.negate() : c.clone();if (b.compareTo(h) < 0) {\n    var e = b;b = h;h = e;\n  }var d = b.getLowestSetBit(),\n      f = h.getLowestSetBit();if (f < 0) {\n    return b;\n  }if (d < f) {\n    f = d;\n  }if (f > 0) {\n    b.rShiftTo(f, b);h.rShiftTo(f, h);\n  }while (b.signum() > 0) {\n    if ((d = b.getLowestSetBit()) > 0) {\n      b.rShiftTo(d, b);\n    }if ((d = h.getLowestSetBit()) > 0) {\n      h.rShiftTo(d, h);\n    }if (b.compareTo(h) >= 0) {\n      b.subTo(h, b);b.rShiftTo(1, b);\n    } else {\n      h.subTo(b, h);h.rShiftTo(1, h);\n    }\n  }if (f > 0) {\n    h.lShiftTo(f, h);\n  }return h;\n}function bnpModInt(e) {\n  if (e <= 0) {\n    return 0;\n  }var c = this.DV % e,\n      b = this.s < 0 ? e - 1 : 0;if (this.t > 0) {\n    if (c == 0) {\n      b = this[0] % e;\n    } else {\n      for (var a = this.t - 1; a >= 0; --a) {\n        b = (c * b + this[a]) % e;\n      }\n    }\n  }return b;\n}function bnModInverse(f) {\n  var j = f.isEven();if (this.isEven() && j || f.signum() == 0) {\n    return BigInteger.ZERO;\n  }var i = f.clone(),\n      h = this.clone();var g = nbv(1),\n      e = nbv(0),\n      l = nbv(0),\n      k = nbv(1);while (i.signum() != 0) {\n    while (i.isEven()) {\n      i.rShiftTo(1, i);if (j) {\n        if (!g.isEven() || !e.isEven()) {\n          g.addTo(this, g);e.subTo(f, e);\n        }g.rShiftTo(1, g);\n      } else {\n        if (!e.isEven()) {\n          e.subTo(f, e);\n        }\n      }e.rShiftTo(1, e);\n    }while (h.isEven()) {\n      h.rShiftTo(1, h);if (j) {\n        if (!l.isEven() || !k.isEven()) {\n          l.addTo(this, l);k.subTo(f, k);\n        }l.rShiftTo(1, l);\n      } else {\n        if (!k.isEven()) {\n          k.subTo(f, k);\n        }\n      }k.rShiftTo(1, k);\n    }if (i.compareTo(h) >= 0) {\n      i.subTo(h, i);if (j) {\n        g.subTo(l, g);\n      }e.subTo(k, e);\n    } else {\n      h.subTo(i, h);if (j) {\n        l.subTo(g, l);\n      }k.subTo(e, k);\n    }\n  }if (h.compareTo(BigInteger.ONE) != 0) {\n    return BigInteger.ZERO;\n  }if (k.compareTo(f) >= 0) {\n    return k.subtract(f);\n  }if (k.signum() < 0) {\n    k.addTo(f, k);\n  } else {\n    return k;\n  }if (k.signum() < 0) {\n    return k.add(f);\n  } else {\n    return k;\n  }\n}var lowprimes = [2, 3, 5, 7, 11, 13, 17, 19, 23, 29, 31, 37, 41, 43, 47, 53, 59, 61, 67, 71, 73, 79, 83, 89, 97, 101, 103, 107, 109, 113, 127, 131, 137, 139, 149, 151, 157, 163, 167, 173, 179, 181, 191, 193, 197, 199, 211, 223, 227, 229, 233, 239, 241, 251, 257, 263, 269, 271, 277, 281, 283, 293, 307, 311, 313, 317, 331, 337, 347, 349, 353, 359, 367, 373, 379, 383, 389, 397, 401, 409, 419, 421, 431, 433, 439, 443, 449, 457, 461, 463, 467, 479, 487, 491, 499, 503, 509, 521, 523, 541, 547, 557, 563, 569, 571, 577, 587, 593, 599, 601, 607, 613, 617, 619, 631, 641, 643, 647, 653, 659, 661, 673, 677, 683, 691, 701, 709, 719, 727, 733, 739, 743, 751, 757, 761, 769, 773, 787, 797, 809, 811, 821, 823, 827, 829, 839, 853, 857, 859, 863, 877, 881, 883, 887, 907, 911, 919, 929, 937, 941, 947, 953, 967, 971, 977, 983, 991, 997];var lplim = (1 << 26) / lowprimes[lowprimes.length - 1];function bnIsProbablePrime(e) {\n  var d,\n      b = this.abs();if (b.t == 1 && b[0] <= lowprimes[lowprimes.length - 1]) {\n    for (d = 0; d < lowprimes.length; ++d) {\n      if (b[0] == lowprimes[d]) {\n        return true;\n      }\n    }return false;\n  }if (b.isEven()) {\n    return false;\n  }d = 1;while (d < lowprimes.length) {\n    var a = lowprimes[d],\n        c = d + 1;while (c < lowprimes.length && a < lplim) {\n      a *= lowprimes[c++];\n    }a = b.modInt(a);while (d < c) {\n      if (a % lowprimes[d++] == 0) {\n        return false;\n      }\n    }\n  }return b.millerRabin(e);\n}function bnpMillerRabin(f) {\n  var g = this.subtract(BigInteger.ONE);var c = g.getLowestSetBit();if (c <= 0) {\n    return false;\n  }var h = g.shiftRight(c);f = f + 1 >> 1;if (f > lowprimes.length) {\n    f = lowprimes.length;\n  }var b = nbi();for (var e = 0; e < f; ++e) {\n    b.fromInt(lowprimes[Math.floor(Math.random() * lowprimes.length)]);var l = b.modPow(h, this);if (l.compareTo(BigInteger.ONE) != 0 && l.compareTo(g) != 0) {\n      var d = 1;while (d++ < c && l.compareTo(g) != 0) {\n        l = l.modPowInt(2, this);if (l.compareTo(BigInteger.ONE) == 0) {\n          return false;\n        }\n      }if (l.compareTo(g) != 0) {\n        return false;\n      }\n    }\n  }return true;\n}BigInteger.prototype.chunkSize = bnpChunkSize;BigInteger.prototype.toRadix = bnpToRadix;BigInteger.prototype.fromRadix = bnpFromRadix;BigInteger.prototype.fromNumber = bnpFromNumber;BigInteger.prototype.bitwiseTo = bnpBitwiseTo;BigInteger.prototype.changeBit = bnpChangeBit;BigInteger.prototype.addTo = bnpAddTo;BigInteger.prototype.dMultiply = bnpDMultiply;BigInteger.prototype.dAddOffset = bnpDAddOffset;BigInteger.prototype.multiplyLowerTo = bnpMultiplyLowerTo;BigInteger.prototype.multiplyUpperTo = bnpMultiplyUpperTo;BigInteger.prototype.modInt = bnpModInt;BigInteger.prototype.millerRabin = bnpMillerRabin;BigInteger.prototype.clone = bnClone;BigInteger.prototype.intValue = bnIntValue;BigInteger.prototype.byteValue = bnByteValue;BigInteger.prototype.shortValue = bnShortValue;BigInteger.prototype.signum = bnSigNum;BigInteger.prototype.toByteArray = bnToByteArray;BigInteger.prototype.equals = bnEquals;BigInteger.prototype.min = bnMin;BigInteger.prototype.max = bnMax;BigInteger.prototype.and = bnAnd;BigInteger.prototype.or = bnOr;BigInteger.prototype.xor = bnXor;BigInteger.prototype.andNot = bnAndNot;BigInteger.prototype.not = bnNot;BigInteger.prototype.shiftLeft = bnShiftLeft;BigInteger.prototype.shiftRight = bnShiftRight;BigInteger.prototype.getLowestSetBit = bnGetLowestSetBit;BigInteger.prototype.bitCount = bnBitCount;BigInteger.prototype.testBit = bnTestBit;BigInteger.prototype.setBit = bnSetBit;BigInteger.prototype.clearBit = bnClearBit;BigInteger.prototype.flipBit = bnFlipBit;BigInteger.prototype.add = bnAdd;BigInteger.prototype.subtract = bnSubtract;BigInteger.prototype.multiply = bnMultiply;BigInteger.prototype.divide = bnDivide;BigInteger.prototype.remainder = bnRemainder;BigInteger.prototype.divideAndRemainder = bnDivideAndRemainder;BigInteger.prototype.modPow = bnModPow;BigInteger.prototype.modInverse = bnModInverse;BigInteger.prototype.pow = bnPow;BigInteger.prototype.gcd = bnGCD;BigInteger.prototype.isProbablePrime = bnIsProbablePrime;BigInteger.prototype.square = bnSquare;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction Arcfour() {\n  this.i = 0;this.j = 0;this.S = new Array();\n}function ARC4init(d) {\n  var c, a, b;for (c = 0; c < 256; ++c) {\n    this.S[c] = c;\n  }a = 0;for (c = 0; c < 256; ++c) {\n    a = a + this.S[c] + d[c % d.length] & 255;b = this.S[c];this.S[c] = this.S[a];this.S[a] = b;\n  }this.i = 0;this.j = 0;\n}function ARC4next() {\n  var a;this.i = this.i + 1 & 255;this.j = this.j + this.S[this.i] & 255;a = this.S[this.i];this.S[this.i] = this.S[this.j];this.S[this.j] = a;return this.S[a + this.S[this.i] & 255];\n}Arcfour.prototype.init = ARC4init;Arcfour.prototype.next = ARC4next;function prng_newstate() {\n  return new Arcfour();\n}var rng_psize = 256;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nvar rng_state;var rng_pool;var rng_pptr;function rng_seed_int(a) {\n  rng_pool[rng_pptr++] ^= a & 255;rng_pool[rng_pptr++] ^= a >> 8 & 255;rng_pool[rng_pptr++] ^= a >> 16 & 255;rng_pool[rng_pptr++] ^= a >> 24 & 255;if (rng_pptr >= rng_psize) {\n    rng_pptr -= rng_psize;\n  }\n}function rng_seed_time() {\n  rng_seed_int(new Date().getTime());\n}if (rng_pool == null) {\n  rng_pool = new Array();rng_pptr = 0;var t;if (window !== undefined && (window.crypto !== undefined || window.msCrypto !== undefined)) {\n    var crypto = window.crypto || window.msCrypto;if (crypto.getRandomValues) {\n      var ua = new Uint8Array(32);crypto.getRandomValues(ua);for (t = 0; t < 32; ++t) {\n        rng_pool[rng_pptr++] = ua[t];\n      }\n    } else {\n      if (navigator.appName == \"Netscape\" && navigator.appVersion < \"5\") {\n        var z = window.crypto.random(32);for (t = 0; t < z.length; ++t) {\n          rng_pool[rng_pptr++] = z.charCodeAt(t) & 255;\n        }\n      }\n    }\n  }while (rng_pptr < rng_psize) {\n    t = Math.floor(65536 * Math.random());rng_pool[rng_pptr++] = t >>> 8;rng_pool[rng_pptr++] = t & 255;\n  }rng_pptr = 0;rng_seed_time();\n}function rng_get_byte() {\n  if (rng_state == null) {\n    rng_seed_time();rng_state = prng_newstate();rng_state.init(rng_pool);for (rng_pptr = 0; rng_pptr < rng_pool.length; ++rng_pptr) {\n      rng_pool[rng_pptr] = 0;\n    }rng_pptr = 0;\n  }return rng_state.next();\n}function rng_get_bytes(b) {\n  var a;for (a = 0; a < b.length; ++a) {\n    b[a] = rng_get_byte();\n  }\n}function SecureRandom() {}SecureRandom.prototype.nextBytes = rng_get_bytes;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction parseBigInt(b, a) {\n  return new BigInteger(b, a);\n}function linebrk(c, d) {\n  var a = \"\";var b = 0;while (b + d < c.length) {\n    a += c.substring(b, b + d) + \"\\n\";b += d;\n  }return a + c.substring(b, c.length);\n}function byte2Hex(a) {\n  if (a < 16) {\n    return \"0\" + a.toString(16);\n  } else {\n    return a.toString(16);\n  }\n}function pkcs1pad2(e, h) {\n  if (h < e.length + 11) {\n    throw \"Message too long for RSA\";return null;\n  }var g = new Array();var d = e.length - 1;while (d >= 0 && h > 0) {\n    var f = e.charCodeAt(d--);if (f < 128) {\n      g[--h] = f;\n    } else {\n      if (f > 127 && f < 2048) {\n        g[--h] = f & 63 | 128;g[--h] = f >> 6 | 192;\n      } else {\n        g[--h] = f & 63 | 128;g[--h] = f >> 6 & 63 | 128;g[--h] = f >> 12 | 224;\n      }\n    }\n  }g[--h] = 0;var b = new SecureRandom();var a = new Array();while (h > 2) {\n    a[0] = 0;while (a[0] == 0) {\n      b.nextBytes(a);\n    }g[--h] = a[0];\n  }g[--h] = 2;g[--h] = 0;return new BigInteger(g);\n}function oaep_mgf1_arr(c, a, e) {\n  var b = \"\",\n      d = 0;while (b.length < a) {\n    b += e(String.fromCharCode.apply(String, c.concat([(d & 4278190080) >> 24, (d & 16711680) >> 16, (d & 65280) >> 8, d & 255])));d += 1;\n  }return b;\n}function oaep_pad(q, a, f, l) {\n  var c = KJUR.crypto.MessageDigest;var o = KJUR.crypto.Util;var b = null;if (!f) {\n    f = \"sha1\";\n  }if (typeof f === \"string\") {\n    b = c.getCanonicalAlgName(f);l = c.getHashLength(b);f = function f(i) {\n      return hextorstr(o.hashHex(rstrtohex(i), b));\n    };\n  }if (q.length + 2 * l + 2 > a) {\n    throw \"Message too long for RSA\";\n  }var k = \"\",\n      e;for (e = 0; e < a - q.length - 2 * l - 2; e += 1) {\n    k += \"\\x00\";\n  }var h = f(\"\") + k + \"\\x01\" + q;var g = new Array(l);new SecureRandom().nextBytes(g);var j = oaep_mgf1_arr(g, h.length, f);var p = [];for (e = 0; e < h.length; e += 1) {\n    p[e] = h.charCodeAt(e) ^ j.charCodeAt(e);\n  }var m = oaep_mgf1_arr(p, g.length, f);var d = [0];for (e = 0; e < g.length; e += 1) {\n    d[e + 1] = g[e] ^ m.charCodeAt(e);\n  }return new BigInteger(d.concat(p));\n}function RSAKey() {\n  this.n = null;this.e = 0;this.d = null;this.p = null;this.q = null;this.dmp1 = null;this.dmq1 = null;this.coeff = null;\n}function RSASetPublic(b, a) {\n  this.isPublic = true;this.isPrivate = false;if (typeof b !== \"string\") {\n    this.n = b;this.e = a;\n  } else {\n    if (b != null && a != null && b.length > 0 && a.length > 0) {\n      this.n = parseBigInt(b, 16);this.e = parseInt(a, 16);\n    } else {\n      throw \"Invalid RSA public key\";\n    }\n  }\n}function RSADoPublic(a) {\n  return a.modPowInt(this.e, this.n);\n}function RSAEncrypt(d) {\n  var a = pkcs1pad2(d, this.n.bitLength() + 7 >> 3);if (a == null) {\n    return null;\n  }var e = this.doPublic(a);if (e == null) {\n    return null;\n  }var b = e.toString(16);if ((b.length & 1) == 0) {\n    return b;\n  } else {\n    return \"0\" + b;\n  }\n}function RSAEncryptOAEP(f, e, b) {\n  var a = oaep_pad(f, this.n.bitLength() + 7 >> 3, e, b);if (a == null) {\n    return null;\n  }var g = this.doPublic(a);if (g == null) {\n    return null;\n  }var d = g.toString(16);if ((d.length & 1) == 0) {\n    return d;\n  } else {\n    return \"0\" + d;\n  }\n}RSAKey.prototype.doPublic = RSADoPublic;RSAKey.prototype.setPublic = RSASetPublic;RSAKey.prototype.encrypt = RSAEncrypt;RSAKey.prototype.encryptOAEP = RSAEncryptOAEP;RSAKey.prototype.type = \"RSA\";\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\n */\nfunction ECFieldElementFp(b, a) {\n  this.x = a;this.q = b;\n}function feFpEquals(a) {\n  if (a == this) {\n    return true;\n  }return this.q.equals(a.q) && this.x.equals(a.x);\n}function feFpToBigInteger() {\n  return this.x;\n}function feFpNegate() {\n  return new ECFieldElementFp(this.q, this.x.negate().mod(this.q));\n}function feFpAdd(a) {\n  return new ECFieldElementFp(this.q, this.x.add(a.toBigInteger()).mod(this.q));\n}function feFpSubtract(a) {\n  return new ECFieldElementFp(this.q, this.x.subtract(a.toBigInteger()).mod(this.q));\n}function feFpMultiply(a) {\n  return new ECFieldElementFp(this.q, this.x.multiply(a.toBigInteger()).mod(this.q));\n}function feFpSquare() {\n  return new ECFieldElementFp(this.q, this.x.square().mod(this.q));\n}function feFpDivide(a) {\n  return new ECFieldElementFp(this.q, this.x.multiply(a.toBigInteger().modInverse(this.q)).mod(this.q));\n}ECFieldElementFp.prototype.equals = feFpEquals;ECFieldElementFp.prototype.toBigInteger = feFpToBigInteger;ECFieldElementFp.prototype.negate = feFpNegate;ECFieldElementFp.prototype.add = feFpAdd;ECFieldElementFp.prototype.subtract = feFpSubtract;ECFieldElementFp.prototype.multiply = feFpMultiply;ECFieldElementFp.prototype.square = feFpSquare;ECFieldElementFp.prototype.divide = feFpDivide;function ECPointFp(c, a, d, b) {\n  this.curve = c;this.x = a;this.y = d;if (b == null) {\n    this.z = BigInteger.ONE;\n  } else {\n    this.z = b;\n  }this.zinv = null;\n}function pointFpGetX() {\n  if (this.zinv == null) {\n    this.zinv = this.z.modInverse(this.curve.q);\n  }return this.curve.fromBigInteger(this.x.toBigInteger().multiply(this.zinv).mod(this.curve.q));\n}function pointFpGetY() {\n  if (this.zinv == null) {\n    this.zinv = this.z.modInverse(this.curve.q);\n  }return this.curve.fromBigInteger(this.y.toBigInteger().multiply(this.zinv).mod(this.curve.q));\n}function pointFpEquals(a) {\n  if (a == this) {\n    return true;\n  }if (this.isInfinity()) {\n    return a.isInfinity();\n  }if (a.isInfinity()) {\n    return this.isInfinity();\n  }var c, b;c = a.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(a.z)).mod(this.curve.q);if (!c.equals(BigInteger.ZERO)) {\n    return false;\n  }b = a.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(a.z)).mod(this.curve.q);return b.equals(BigInteger.ZERO);\n}function pointFpIsInfinity() {\n  if (this.x == null && this.y == null) {\n    return true;\n  }return this.z.equals(BigInteger.ZERO) && !this.y.toBigInteger().equals(BigInteger.ZERO);\n}function pointFpNegate() {\n  return new ECPointFp(this.curve, this.x, this.y.negate(), this.z);\n}function pointFpAdd(l) {\n  if (this.isInfinity()) {\n    return l;\n  }if (l.isInfinity()) {\n    return this;\n  }var p = l.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(l.z)).mod(this.curve.q);var o = l.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(l.z)).mod(this.curve.q);if (BigInteger.ZERO.equals(o)) {\n    if (BigInteger.ZERO.equals(p)) {\n      return this.twice();\n    }return this.curve.getInfinity();\n  }var j = new BigInteger(\"3\");var e = this.x.toBigInteger();var n = this.y.toBigInteger();var c = l.x.toBigInteger();var k = l.y.toBigInteger();var m = o.square();var i = m.multiply(o);var d = e.multiply(m);var g = p.square().multiply(this.z);var a = g.subtract(d.shiftLeft(1)).multiply(l.z).subtract(i).multiply(o).mod(this.curve.q);var h = d.multiply(j).multiply(p).subtract(n.multiply(i)).subtract(g.multiply(p)).multiply(l.z).add(p.multiply(i)).mod(this.curve.q);var f = i.multiply(this.z).multiply(l.z).mod(this.curve.q);return new ECPointFp(this.curve, this.curve.fromBigInteger(a), this.curve.fromBigInteger(h), f);\n}function pointFpTwice() {\n  if (this.isInfinity()) {\n    return this;\n  }if (this.y.toBigInteger().signum() == 0) {\n    return this.curve.getInfinity();\n  }var g = new BigInteger(\"3\");var c = this.x.toBigInteger();var h = this.y.toBigInteger();var e = h.multiply(this.z);var j = e.multiply(h).mod(this.curve.q);var i = this.curve.a.toBigInteger();var k = c.square().multiply(g);if (!BigInteger.ZERO.equals(i)) {\n    k = k.add(this.z.square().multiply(i));\n  }k = k.mod(this.curve.q);var b = k.square().subtract(c.shiftLeft(3).multiply(j)).shiftLeft(1).multiply(e).mod(this.curve.q);var f = k.multiply(g).multiply(c).subtract(j.shiftLeft(1)).shiftLeft(2).multiply(j).subtract(k.square().multiply(k)).mod(this.curve.q);var d = e.square().multiply(e).shiftLeft(3).mod(this.curve.q);return new ECPointFp(this.curve, this.curve.fromBigInteger(b), this.curve.fromBigInteger(f), d);\n}function pointFpMultiply(b) {\n  if (this.isInfinity()) {\n    return this;\n  }if (b.signum() == 0) {\n    return this.curve.getInfinity();\n  }var g = b;var f = g.multiply(new BigInteger(\"3\"));var l = this.negate();var d = this;var c;for (c = f.bitLength() - 2; c > 0; --c) {\n    d = d.twice();var a = f.testBit(c);var j = g.testBit(c);if (a != j) {\n      d = d.add(a ? this : l);\n    }\n  }return d;\n}function pointFpMultiplyTwo(c, a, b) {\n  var d;if (c.bitLength() > b.bitLength()) {\n    d = c.bitLength() - 1;\n  } else {\n    d = b.bitLength() - 1;\n  }var f = this.curve.getInfinity();var e = this.add(a);while (d >= 0) {\n    f = f.twice();if (c.testBit(d)) {\n      if (b.testBit(d)) {\n        f = f.add(e);\n      } else {\n        f = f.add(this);\n      }\n    } else {\n      if (b.testBit(d)) {\n        f = f.add(a);\n      }\n    }--d;\n  }return f;\n}ECPointFp.prototype.getX = pointFpGetX;ECPointFp.prototype.getY = pointFpGetY;ECPointFp.prototype.equals = pointFpEquals;ECPointFp.prototype.isInfinity = pointFpIsInfinity;ECPointFp.prototype.negate = pointFpNegate;ECPointFp.prototype.add = pointFpAdd;ECPointFp.prototype.twice = pointFpTwice;ECPointFp.prototype.multiply = pointFpMultiply;ECPointFp.prototype.multiplyTwo = pointFpMultiplyTwo;function ECCurveFp(e, d, c) {\n  this.q = e;this.a = this.fromBigInteger(d);this.b = this.fromBigInteger(c);this.infinity = new ECPointFp(this, null, null);\n}function curveFpGetQ() {\n  return this.q;\n}function curveFpGetA() {\n  return this.a;\n}function curveFpGetB() {\n  return this.b;\n}function curveFpEquals(a) {\n  if (a == this) {\n    return true;\n  }return this.q.equals(a.q) && this.a.equals(a.a) && this.b.equals(a.b);\n}function curveFpGetInfinity() {\n  return this.infinity;\n}function curveFpFromBigInteger(a) {\n  return new ECFieldElementFp(this.q, a);\n}function curveFpDecodePointHex(d) {\n  switch (parseInt(d.substr(0, 2), 16)) {case 0:\n      return this.infinity;case 2:case 3:\n      return null;case 4:case 6:case 7:\n      var a = (d.length - 2) / 2;var c = d.substr(2, a);var b = d.substr(a + 2, a);return new ECPointFp(this, this.fromBigInteger(new BigInteger(c, 16)), this.fromBigInteger(new BigInteger(b, 16)));default:\n      return null;}\n}ECCurveFp.prototype.getQ = curveFpGetQ;ECCurveFp.prototype.getA = curveFpGetA;ECCurveFp.prototype.getB = curveFpGetB;ECCurveFp.prototype.equals = curveFpEquals;ECCurveFp.prototype.getInfinity = curveFpGetInfinity;ECCurveFp.prototype.fromBigInteger = curveFpFromBigInteger;ECCurveFp.prototype.decodePointHex = curveFpDecodePointHex;\n/*! (c) Stefan Thomas | https://github.com/bitcoinjs/bitcoinjs-lib\n */\nECFieldElementFp.prototype.getByteLength = function () {\n  return Math.floor((this.toBigInteger().bitLength() + 7) / 8);\n};ECPointFp.prototype.getEncoded = function (c) {\n  var d = function d(h, f) {\n    var g = h.toByteArrayUnsigned();if (f < g.length) {\n      g = g.slice(g.length - f);\n    } else {\n      while (f > g.length) {\n        g.unshift(0);\n      }\n    }return g;\n  };var a = this.getX().toBigInteger();var e = this.getY().toBigInteger();var b = d(a, 32);if (c) {\n    if (e.isEven()) {\n      b.unshift(2);\n    } else {\n      b.unshift(3);\n    }\n  } else {\n    b.unshift(4);b = b.concat(d(e, 32));\n  }return b;\n};ECPointFp.decodeFrom = function (g, c) {\n  var f = c[0];var e = c.length - 1;var d = c.slice(1, 1 + e / 2);var b = c.slice(1 + e / 2, 1 + e);d.unshift(0);b.unshift(0);var a = new BigInteger(d);var h = new BigInteger(b);return new ECPointFp(g, g.fromBigInteger(a), g.fromBigInteger(h));\n};ECPointFp.decodeFromHex = function (g, c) {\n  var f = c.substr(0, 2);var e = c.length - 2;var d = c.substr(2, e / 2);var b = c.substr(2 + e / 2, e / 2);var a = new BigInteger(d, 16);var h = new BigInteger(b, 16);return new ECPointFp(g, g.fromBigInteger(a), g.fromBigInteger(h));\n};ECPointFp.prototype.add2D = function (c) {\n  if (this.isInfinity()) {\n    return c;\n  }if (c.isInfinity()) {\n    return this;\n  }if (this.x.equals(c.x)) {\n    if (this.y.equals(c.y)) {\n      return this.twice();\n    }return this.curve.getInfinity();\n  }var g = c.x.subtract(this.x);var e = c.y.subtract(this.y);var a = e.divide(g);var d = a.square().subtract(this.x).subtract(c.x);var f = a.multiply(this.x.subtract(d)).subtract(this.y);return new ECPointFp(this.curve, d, f);\n};ECPointFp.prototype.twice2D = function () {\n  if (this.isInfinity()) {\n    return this;\n  }if (this.y.toBigInteger().signum() == 0) {\n    return this.curve.getInfinity();\n  }var b = this.curve.fromBigInteger(BigInteger.valueOf(2));var e = this.curve.fromBigInteger(BigInteger.valueOf(3));var a = this.x.square().multiply(e).add(this.curve.a).divide(this.y.multiply(b));var c = a.square().subtract(this.x.multiply(b));var d = a.multiply(this.x.subtract(c)).subtract(this.y);return new ECPointFp(this.curve, c, d);\n};ECPointFp.prototype.multiply2D = function (b) {\n  if (this.isInfinity()) {\n    return this;\n  }if (b.signum() == 0) {\n    return this.curve.getInfinity();\n  }var g = b;var f = g.multiply(new BigInteger(\"3\"));var l = this.negate();var d = this;var c;for (c = f.bitLength() - 2; c > 0; --c) {\n    d = d.twice();var a = f.testBit(c);var j = g.testBit(c);if (a != j) {\n      d = d.add2D(a ? this : l);\n    }\n  }return d;\n};ECPointFp.prototype.isOnCurve = function () {\n  var d = this.getX().toBigInteger();var i = this.getY().toBigInteger();var f = this.curve.getA().toBigInteger();var c = this.curve.getB().toBigInteger();var h = this.curve.getQ();var e = i.multiply(i).mod(h);var g = d.multiply(d).multiply(d).add(f.multiply(d)).add(c).mod(h);return e.equals(g);\n};ECPointFp.prototype.toString = function () {\n  return \"(\" + this.getX().toBigInteger().toString() + \",\" + this.getY().toBigInteger().toString() + \")\";\n};ECPointFp.prototype.validate = function () {\n  var c = this.curve.getQ();if (this.isInfinity()) {\n    throw new Error(\"Point is at infinity.\");\n  }var a = this.getX().toBigInteger();var b = this.getY().toBigInteger();if (a.compareTo(BigInteger.ONE) < 0 || a.compareTo(c.subtract(BigInteger.ONE)) > 0) {\n    throw new Error(\"x coordinate out of bounds\");\n  }if (b.compareTo(BigInteger.ONE) < 0 || b.compareTo(c.subtract(BigInteger.ONE)) > 0) {\n    throw new Error(\"y coordinate out of bounds\");\n  }if (!this.isOnCurve()) {\n    throw new Error(\"Point is not on the curve.\");\n  }if (this.multiply(c).isInfinity()) {\n    throw new Error(\"Point is not a scalar multiple of G.\");\n  }return true;\n};\n/*! Mike Samuel (c) 2009 | code.google.com/p/json-sans-eval\n */\nvar jsonParse = function () {\n  var e = \"(?:-?\\\\b(?:0|[1-9][0-9]*)(?:\\\\.[0-9]+)?(?:[eE][+-]?[0-9]+)?\\\\b)\";var j = '(?:[^\\\\0-\\\\x08\\\\x0a-\\\\x1f\"\\\\\\\\]|\\\\\\\\(?:[\"/\\\\\\\\bfnrt]|u[0-9A-Fa-f]{4}))';var i = '(?:\"' + j + '*\")';var d = new RegExp(\"(?:false|true|null|[\\\\{\\\\}\\\\[\\\\]]|\" + e + \"|\" + i + \")\", \"g\");var k = new RegExp(\"\\\\\\\\(?:([^u])|u(.{4}))\", \"g\");var g = { '\"': '\"', \"/\": \"/\", \"\\\\\": \"\\\\\", b: \"\\b\", f: \"\\f\", n: \"\\n\", r: \"\\r\", t: \"\\t\" };function h(l, m, n) {\n    return m ? g[m] : String.fromCharCode(parseInt(n, 16));\n  }var c = new String(\"\");var a = \"\\\\\";var f = { \"{\": Object, \"[\": Array };var b = Object.hasOwnProperty;return function (u, q) {\n    var p = u.match(d);var x;var v = p[0];var l = false;if (\"{\" === v) {\n      x = {};\n    } else {\n      if (\"[\" === v) {\n        x = [];\n      } else {\n        x = [];l = true;\n      }\n    }var t;var r = [x];for (var o = 1 - l, m = p.length; o < m; ++o) {\n      v = p[o];var w;switch (v.charCodeAt(0)) {default:\n          w = r[0];w[t || w.length] = +v;t = void 0;break;case 34:\n          v = v.substring(1, v.length - 1);if (v.indexOf(a) !== -1) {\n            v = v.replace(k, h);\n          }w = r[0];if (!t) {\n            if (w instanceof Array) {\n              t = w.length;\n            } else {\n              t = v || c;break;\n            }\n          }w[t] = v;t = void 0;break;case 91:\n          w = r[0];r.unshift(w[t || w.length] = []);t = void 0;break;case 93:\n          r.shift();break;case 102:\n          w = r[0];w[t || w.length] = false;t = void 0;break;case 110:\n          w = r[0];w[t || w.length] = null;t = void 0;break;case 116:\n          w = r[0];w[t || w.length] = true;t = void 0;break;case 123:\n          w = r[0];r.unshift(w[t || w.length] = {});t = void 0;break;case 125:\n          r.shift();break;}\n    }if (l) {\n      if (r.length !== 1) {\n        throw new Error();\n      }x = x[0];\n    } else {\n      if (r.length) {\n        throw new Error();\n      }\n    }if (q) {\n      var s = function s(C, B) {\n        var D = C[B];if (D && (typeof D === \"undefined\" ? \"undefined\" : _typeof(D)) === \"object\") {\n          var n = null;for (var z in D) {\n            if (b.call(D, z) && D !== C) {\n              var y = s(D, z);if (y !== void 0) {\n                D[z] = y;\n              } else {\n                if (!n) {\n                  n = [];\n                }n.push(z);\n              }\n            }\n          }if (n) {\n            for (var A = n.length; --A >= 0;) {\n              delete D[n[A]];\n            }\n          }\n        }return q.call(C, B, D);\n      };x = s({ \"\": x }, \"\");\n    }return x;\n  };\n}();\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.asn1 == \"undefined\" || !KJUR.asn1) {\n  KJUR.asn1 = {};\n}KJUR.asn1.ASN1Util = new function () {\n  this.integerToByteHex = function (a) {\n    var b = a.toString(16);if (b.length % 2 == 1) {\n      b = \"0\" + b;\n    }return b;\n  };this.bigIntToMinTwosComplementsHex = function (j) {\n    var f = j.toString(16);if (f.substr(0, 1) != \"-\") {\n      if (f.length % 2 == 1) {\n        f = \"0\" + f;\n      } else {\n        if (!f.match(/^[0-7]/)) {\n          f = \"00\" + f;\n        }\n      }\n    } else {\n      var a = f.substr(1);var e = a.length;if (e % 2 == 1) {\n        e += 1;\n      } else {\n        if (!f.match(/^[0-7]/)) {\n          e += 2;\n        }\n      }var g = \"\";for (var d = 0; d < e; d++) {\n        g += \"f\";\n      }var c = new BigInteger(g, 16);var b = c.xor(j).add(BigInteger.ONE);f = b.toString(16).replace(/^-/, \"\");\n    }return f;\n  };this.getPEMStringFromHex = function (a, b) {\n    return hextopem(a, b);\n  };this.newObject = function (k) {\n    var D = KJUR,\n        n = D.asn1,\n        z = n.DERBoolean,\n        e = n.DERInteger,\n        s = n.DERBitString,\n        h = n.DEROctetString,\n        v = n.DERNull,\n        w = n.DERObjectIdentifier,\n        l = n.DEREnumerated,\n        g = n.DERUTF8String,\n        f = n.DERNumericString,\n        y = n.DERPrintableString,\n        u = n.DERTeletexString,\n        p = n.DERIA5String,\n        C = n.DERUTCTime,\n        j = n.DERGeneralizedTime,\n        m = n.DERSequence,\n        c = n.DERSet,\n        r = n.DERTaggedObject,\n        o = n.ASN1Util.newObject;var t = Object.keys(k);if (t.length != 1) {\n      throw \"key of param shall be only one.\";\n    }var F = t[0];if (\":bool:int:bitstr:octstr:null:oid:enum:utf8str:numstr:prnstr:telstr:ia5str:utctime:gentime:seq:set:tag:\".indexOf(\":\" + F + \":\") == -1) {\n      throw \"undefined key: \" + F;\n    }if (F == \"bool\") {\n      return new z(k[F]);\n    }if (F == \"int\") {\n      return new e(k[F]);\n    }if (F == \"bitstr\") {\n      return new s(k[F]);\n    }if (F == \"octstr\") {\n      return new h(k[F]);\n    }if (F == \"null\") {\n      return new v(k[F]);\n    }if (F == \"oid\") {\n      return new w(k[F]);\n    }if (F == \"enum\") {\n      return new l(k[F]);\n    }if (F == \"utf8str\") {\n      return new g(k[F]);\n    }if (F == \"numstr\") {\n      return new f(k[F]);\n    }if (F == \"prnstr\") {\n      return new y(k[F]);\n    }if (F == \"telstr\") {\n      return new u(k[F]);\n    }if (F == \"ia5str\") {\n      return new p(k[F]);\n    }if (F == \"utctime\") {\n      return new C(k[F]);\n    }if (F == \"gentime\") {\n      return new j(k[F]);\n    }if (F == \"seq\") {\n      var d = k[F];var E = [];for (var x = 0; x < d.length; x++) {\n        var B = o(d[x]);E.push(B);\n      }return new m({ array: E });\n    }if (F == \"set\") {\n      var d = k[F];var E = [];for (var x = 0; x < d.length; x++) {\n        var B = o(d[x]);E.push(B);\n      }return new c({ array: E });\n    }if (F == \"tag\") {\n      var A = k[F];if (Object.prototype.toString.call(A) === \"[object Array]\" && A.length == 3) {\n        var q = o(A[2]);return new r({ tag: A[0], explicit: A[1], obj: q });\n      } else {\n        var b = {};if (A.explicit !== undefined) {\n          b.explicit = A.explicit;\n        }if (A.tag !== undefined) {\n          b.tag = A.tag;\n        }if (A.obj === undefined) {\n          throw \"obj shall be specified for 'tag'.\";\n        }b.obj = o(A.obj);return new r(b);\n      }\n    }\n  };this.jsonToASN1HEX = function (b) {\n    var a = this.newObject(b);return a.getEncodedHex();\n  };\n}();KJUR.asn1.ASN1Util.oidHexToInt = function (a) {\n  var j = \"\";var k = parseInt(a.substr(0, 2), 16);var d = Math.floor(k / 40);var c = k % 40;var j = d + \".\" + c;var e = \"\";for (var f = 2; f < a.length; f += 2) {\n    var g = parseInt(a.substr(f, 2), 16);var h = (\"00000000\" + g.toString(2)).slice(-8);e = e + h.substr(1, 7);if (h.substr(0, 1) == \"0\") {\n      var b = new BigInteger(e, 2);j = j + \".\" + b.toString(10);e = \"\";\n    }\n  }return j;\n};KJUR.asn1.ASN1Util.oidIntToHex = function (f) {\n  var e = function e(a) {\n    var k = a.toString(16);if (k.length == 1) {\n      k = \"0\" + k;\n    }return k;\n  };var d = function d(o) {\n    var n = \"\";var k = new BigInteger(o, 10);var a = k.toString(2);var l = 7 - a.length % 7;if (l == 7) {\n      l = 0;\n    }var q = \"\";for (var m = 0; m < l; m++) {\n      q += \"0\";\n    }a = q + a;for (var m = 0; m < a.length - 1; m += 7) {\n      var p = a.substr(m, 7);if (m != a.length - 7) {\n        p = \"1\" + p;\n      }n += e(parseInt(p, 2));\n    }return n;\n  };if (!f.match(/^[0-9.]+$/)) {\n    throw \"malformed oid string: \" + f;\n  }var g = \"\";var b = f.split(\".\");var j = parseInt(b[0]) * 40 + parseInt(b[1]);g += e(j);b.splice(0, 2);for (var c = 0; c < b.length; c++) {\n    g += d(b[c]);\n  }return g;\n};KJUR.asn1.ASN1Object = function () {\n  var c = true;var b = null;var d = \"00\";var e = \"00\";var a = \"\";this.getLengthHexFromValue = function () {\n    if (typeof this.hV == \"undefined\" || this.hV == null) {\n      throw \"this.hV is null or undefined.\";\n    }if (this.hV.length % 2 == 1) {\n      throw \"value hex must be even length: n=\" + a.length + \",v=\" + this.hV;\n    }var i = this.hV.length / 2;var h = i.toString(16);if (h.length % 2 == 1) {\n      h = \"0\" + h;\n    }if (i < 128) {\n      return h;\n    } else {\n      var g = h.length / 2;if (g > 15) {\n        throw \"ASN.1 length too long to represent by 8x: n = \" + i.toString(16);\n      }var f = 128 + g;return f.toString(16) + h;\n    }\n  };this.getEncodedHex = function () {\n    if (this.hTLV == null || this.isModified) {\n      this.hV = this.getFreshValueHex();this.hL = this.getLengthHexFromValue();this.hTLV = this.hT + this.hL + this.hV;this.isModified = false;\n    }return this.hTLV;\n  };this.getValueHex = function () {\n    this.getEncodedHex();return this.hV;\n  };this.getFreshValueHex = function () {\n    return \"\";\n  };\n};KJUR.asn1.DERAbstractString = function (c) {\n  KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var b = null;var a = null;this.getString = function () {\n    return this.s;\n  };this.setString = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = d;this.hV = utf8tohex(this.s).toLowerCase();\n  };this.setStringHex = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = null;this.hV = d;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof c != \"undefined\") {\n    if (typeof c == \"string\") {\n      this.setString(c);\n    } else {\n      if (typeof c.str != \"undefined\") {\n        this.setString(c.str);\n      } else {\n        if (typeof c.hex != \"undefined\") {\n          this.setStringHex(c.hex);\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERAbstractString, KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractTime = function (c) {\n  KJUR.asn1.DERAbstractTime.superclass.constructor.call(this);var b = null;var a = null;this.localDateToUTC = function (f) {\n    utc = f.getTime() + f.getTimezoneOffset() * 60000;var e = new Date(utc);return e;\n  };this.formatDate = function (m, o, e) {\n    var g = this.zeroPadding;var n = this.localDateToUTC(m);var p = String(n.getFullYear());if (o == \"utc\") {\n      p = p.substr(2, 2);\n    }var l = g(String(n.getMonth() + 1), 2);var q = g(String(n.getDate()), 2);var h = g(String(n.getHours()), 2);var i = g(String(n.getMinutes()), 2);var j = g(String(n.getSeconds()), 2);var r = p + l + q + h + i + j;if (e === true) {\n      var f = n.getMilliseconds();if (f != 0) {\n        var k = g(String(f), 3);k = k.replace(/[0]+$/, \"\");r = r + \".\" + k;\n      }\n    }return r + \"Z\";\n  };this.zeroPadding = function (e, d) {\n    if (e.length >= d) {\n      return e;\n    }return new Array(d - e.length + 1).join(\"0\") + e;\n  };this.getString = function () {\n    return this.s;\n  };this.setString = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = d;this.hV = stohex(d);\n  };this.setByDateValue = function (h, j, e, d, f, g) {\n    var i = new Date(Date.UTC(h, j - 1, e, d, f, g, 0));this.setByDate(i);\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };\n};YAHOO.lang.extend(KJUR.asn1.DERAbstractTime, KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractStructured = function (b) {\n  KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var a = null;this.setByASN1ObjectArray = function (c) {\n    this.hTLV = null;this.isModified = true;this.asn1Array = c;\n  };this.appendASN1Object = function (c) {\n    this.hTLV = null;this.isModified = true;this.asn1Array.push(c);\n  };this.asn1Array = new Array();if (typeof b != \"undefined\") {\n    if (typeof b.array != \"undefined\") {\n      this.asn1Array = b.array;\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERAbstractStructured, KJUR.asn1.ASN1Object);KJUR.asn1.DERBoolean = function () {\n  KJUR.asn1.DERBoolean.superclass.constructor.call(this);this.hT = \"01\";this.hTLV = \"0101ff\";\n};YAHOO.lang.extend(KJUR.asn1.DERBoolean, KJUR.asn1.ASN1Object);KJUR.asn1.DERInteger = function (a) {\n  KJUR.asn1.DERInteger.superclass.constructor.call(this);this.hT = \"02\";this.setByBigInteger = function (b) {\n    this.hTLV = null;this.isModified = true;this.hV = KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b);\n  };this.setByInteger = function (c) {\n    var b = new BigInteger(String(c), 10);this.setByBigInteger(b);\n  };this.setValueHex = function (b) {\n    this.hV = b;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a.bigint != \"undefined\") {\n      this.setByBigInteger(a.bigint);\n    } else {\n      if (typeof a[\"int\"] != \"undefined\") {\n        this.setByInteger(a[\"int\"]);\n      } else {\n        if (typeof a == \"number\") {\n          this.setByInteger(a);\n        } else {\n          if (typeof a.hex != \"undefined\") {\n            this.setValueHex(a.hex);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERInteger, KJUR.asn1.ASN1Object);KJUR.asn1.DERBitString = function (b) {\n  if (b !== undefined && typeof b.obj !== \"undefined\") {\n    var a = KJUR.asn1.ASN1Util.newObject(b.obj);b.hex = \"00\" + a.getEncodedHex();\n  }KJUR.asn1.DERBitString.superclass.constructor.call(this);this.hT = \"03\";this.setHexValueIncludingUnusedBits = function (c) {\n    this.hTLV = null;this.isModified = true;this.hV = c;\n  };this.setUnusedBitsAndHexValue = function (c, e) {\n    if (c < 0 || 7 < c) {\n      throw \"unused bits shall be from 0 to 7: u = \" + c;\n    }var d = \"0\" + c;this.hTLV = null;this.isModified = true;this.hV = d + e;\n  };this.setByBinaryString = function (e) {\n    e = e.replace(/0+$/, \"\");var f = 8 - e.length % 8;if (f == 8) {\n      f = 0;\n    }for (var g = 0; g <= f; g++) {\n      e += \"0\";\n    }var j = \"\";for (var g = 0; g < e.length - 1; g += 8) {\n      var d = e.substr(g, 8);var c = parseInt(d, 2).toString(16);if (c.length == 1) {\n        c = \"0\" + c;\n      }j += c;\n    }this.hTLV = null;this.isModified = true;this.hV = \"0\" + f + j;\n  };this.setByBooleanArray = function (e) {\n    var d = \"\";for (var c = 0; c < e.length; c++) {\n      if (e[c] == true) {\n        d += \"1\";\n      } else {\n        d += \"0\";\n      }\n    }this.setByBinaryString(d);\n  };this.newFalseArray = function (e) {\n    var c = new Array(e);for (var d = 0; d < e; d++) {\n      c[d] = false;\n    }return c;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof b != \"undefined\") {\n    if (typeof b == \"string\" && b.toLowerCase().match(/^[0-9a-f]+$/)) {\n      this.setHexValueIncludingUnusedBits(b);\n    } else {\n      if (typeof b.hex != \"undefined\") {\n        this.setHexValueIncludingUnusedBits(b.hex);\n      } else {\n        if (typeof b.bin != \"undefined\") {\n          this.setByBinaryString(b.bin);\n        } else {\n          if (typeof b.array != \"undefined\") {\n            this.setByBooleanArray(b.array);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERBitString, KJUR.asn1.ASN1Object);KJUR.asn1.DEROctetString = function (b) {\n  if (b !== undefined && typeof b.obj !== \"undefined\") {\n    var a = KJUR.asn1.ASN1Util.newObject(b.obj);b.hex = a.getEncodedHex();\n  }KJUR.asn1.DEROctetString.superclass.constructor.call(this, b);this.hT = \"04\";\n};YAHOO.lang.extend(KJUR.asn1.DEROctetString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERNull = function () {\n  KJUR.asn1.DERNull.superclass.constructor.call(this);this.hT = \"05\";this.hTLV = \"0500\";\n};YAHOO.lang.extend(KJUR.asn1.DERNull, KJUR.asn1.ASN1Object);KJUR.asn1.DERObjectIdentifier = function (c) {\n  var b = function b(d) {\n    var e = d.toString(16);if (e.length == 1) {\n      e = \"0\" + e;\n    }return e;\n  };var a = function a(k) {\n    var j = \"\";var e = new BigInteger(k, 10);var d = e.toString(2);var f = 7 - d.length % 7;if (f == 7) {\n      f = 0;\n    }var m = \"\";for (var g = 0; g < f; g++) {\n      m += \"0\";\n    }d = m + d;for (var g = 0; g < d.length - 1; g += 7) {\n      var l = d.substr(g, 7);if (g != d.length - 7) {\n        l = \"1\" + l;\n      }j += b(parseInt(l, 2));\n    }return j;\n  };KJUR.asn1.DERObjectIdentifier.superclass.constructor.call(this);this.hT = \"06\";this.setValueHex = function (d) {\n    this.hTLV = null;this.isModified = true;this.s = null;this.hV = d;\n  };this.setValueOidString = function (f) {\n    if (!f.match(/^[0-9.]+$/)) {\n      throw \"malformed oid string: \" + f;\n    }var g = \"\";var d = f.split(\".\");var j = parseInt(d[0]) * 40 + parseInt(d[1]);g += b(j);d.splice(0, 2);for (var e = 0; e < d.length; e++) {\n      g += a(d[e]);\n    }this.hTLV = null;this.isModified = true;this.s = null;this.hV = g;\n  };this.setValueName = function (e) {\n    var d = KJUR.asn1.x509.OID.name2oid(e);if (d !== \"\") {\n      this.setValueOidString(d);\n    } else {\n      throw \"DERObjectIdentifier oidName undefined: \" + e;\n    }\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (c !== undefined) {\n    if (typeof c === \"string\") {\n      if (c.match(/^[0-2].[0-9.]+$/)) {\n        this.setValueOidString(c);\n      } else {\n        this.setValueName(c);\n      }\n    } else {\n      if (c.oid !== undefined) {\n        this.setValueOidString(c.oid);\n      } else {\n        if (c.hex !== undefined) {\n          this.setValueHex(c.hex);\n        } else {\n          if (c.name !== undefined) {\n            this.setValueName(c.name);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERObjectIdentifier, KJUR.asn1.ASN1Object);KJUR.asn1.DEREnumerated = function (a) {\n  KJUR.asn1.DEREnumerated.superclass.constructor.call(this);this.hT = \"0a\";this.setByBigInteger = function (b) {\n    this.hTLV = null;this.isModified = true;this.hV = KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b);\n  };this.setByInteger = function (c) {\n    var b = new BigInteger(String(c), 10);this.setByBigInteger(b);\n  };this.setValueHex = function (b) {\n    this.hV = b;\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a[\"int\"] != \"undefined\") {\n      this.setByInteger(a[\"int\"]);\n    } else {\n      if (typeof a == \"number\") {\n        this.setByInteger(a);\n      } else {\n        if (typeof a.hex != \"undefined\") {\n          this.setValueHex(a.hex);\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DEREnumerated, KJUR.asn1.ASN1Object);KJUR.asn1.DERUTF8String = function (a) {\n  KJUR.asn1.DERUTF8String.superclass.constructor.call(this, a);this.hT = \"0c\";\n};YAHOO.lang.extend(KJUR.asn1.DERUTF8String, KJUR.asn1.DERAbstractString);KJUR.asn1.DERNumericString = function (a) {\n  KJUR.asn1.DERNumericString.superclass.constructor.call(this, a);this.hT = \"12\";\n};YAHOO.lang.extend(KJUR.asn1.DERNumericString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERPrintableString = function (a) {\n  KJUR.asn1.DERPrintableString.superclass.constructor.call(this, a);this.hT = \"13\";\n};YAHOO.lang.extend(KJUR.asn1.DERPrintableString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERTeletexString = function (a) {\n  KJUR.asn1.DERTeletexString.superclass.constructor.call(this, a);this.hT = \"14\";\n};YAHOO.lang.extend(KJUR.asn1.DERTeletexString, KJUR.asn1.DERAbstractString);KJUR.asn1.DERIA5String = function (a) {\n  KJUR.asn1.DERIA5String.superclass.constructor.call(this, a);this.hT = \"16\";\n};YAHOO.lang.extend(KJUR.asn1.DERIA5String, KJUR.asn1.DERAbstractString);KJUR.asn1.DERUTCTime = function (a) {\n  KJUR.asn1.DERUTCTime.superclass.constructor.call(this, a);this.hT = \"17\";this.setByDate = function (b) {\n    this.hTLV = null;this.isModified = true;this.date = b;this.s = this.formatDate(this.date, \"utc\");this.hV = stohex(this.s);\n  };this.getFreshValueHex = function () {\n    if (typeof this.date == \"undefined\" && typeof this.s == \"undefined\") {\n      this.date = new Date();this.s = this.formatDate(this.date, \"utc\");this.hV = stohex(this.s);\n    }return this.hV;\n  };if (a !== undefined) {\n    if (a.str !== undefined) {\n      this.setString(a.str);\n    } else {\n      if (typeof a == \"string\" && a.match(/^[0-9]{12}Z$/)) {\n        this.setString(a);\n      } else {\n        if (a.hex !== undefined) {\n          this.setStringHex(a.hex);\n        } else {\n          if (a.date !== undefined) {\n            this.setByDate(a.date);\n          }\n        }\n      }\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERUTCTime, KJUR.asn1.DERAbstractTime);KJUR.asn1.DERGeneralizedTime = function (a) {\n  KJUR.asn1.DERGeneralizedTime.superclass.constructor.call(this, a);this.hT = \"18\";this.withMillis = false;this.setByDate = function (b) {\n    this.hTLV = null;this.isModified = true;this.date = b;this.s = this.formatDate(this.date, \"gen\", this.withMillis);this.hV = stohex(this.s);\n  };this.getFreshValueHex = function () {\n    if (this.date === undefined && this.s === undefined) {\n      this.date = new Date();this.s = this.formatDate(this.date, \"gen\", this.withMillis);this.hV = stohex(this.s);\n    }return this.hV;\n  };if (a !== undefined) {\n    if (a.str !== undefined) {\n      this.setString(a.str);\n    } else {\n      if (typeof a == \"string\" && a.match(/^[0-9]{14}Z$/)) {\n        this.setString(a);\n      } else {\n        if (a.hex !== undefined) {\n          this.setStringHex(a.hex);\n        } else {\n          if (a.date !== undefined) {\n            this.setByDate(a.date);\n          }\n        }\n      }\n    }if (a.millis === true) {\n      this.withMillis = true;\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERGeneralizedTime, KJUR.asn1.DERAbstractTime);KJUR.asn1.DERSequence = function (a) {\n  KJUR.asn1.DERSequence.superclass.constructor.call(this, a);this.hT = \"30\";this.getFreshValueHex = function () {\n    var c = \"\";for (var b = 0; b < this.asn1Array.length; b++) {\n      var d = this.asn1Array[b];c += d.getEncodedHex();\n    }this.hV = c;return this.hV;\n  };\n};YAHOO.lang.extend(KJUR.asn1.DERSequence, KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERSet = function (a) {\n  KJUR.asn1.DERSet.superclass.constructor.call(this, a);this.hT = \"31\";this.sortFlag = true;this.getFreshValueHex = function () {\n    var b = new Array();for (var c = 0; c < this.asn1Array.length; c++) {\n      var d = this.asn1Array[c];b.push(d.getEncodedHex());\n    }if (this.sortFlag == true) {\n      b.sort();\n    }this.hV = b.join(\"\");return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a.sortflag != \"undefined\" && a.sortflag == false) {\n      this.sortFlag = false;\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERSet, KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERTaggedObject = function (a) {\n  KJUR.asn1.DERTaggedObject.superclass.constructor.call(this);this.hT = \"a0\";this.hV = \"\";this.isExplicit = true;this.asn1Object = null;this.setASN1Object = function (b, c, d) {\n    this.hT = c;this.isExplicit = b;this.asn1Object = d;if (this.isExplicit) {\n      this.hV = this.asn1Object.getEncodedHex();this.hTLV = null;this.isModified = true;\n    } else {\n      this.hV = null;this.hTLV = d.getEncodedHex();this.hTLV = this.hTLV.replace(/^../, c);this.isModified = false;\n    }\n  };this.getFreshValueHex = function () {\n    return this.hV;\n  };if (typeof a != \"undefined\") {\n    if (typeof a.tag != \"undefined\") {\n      this.hT = a.tag;\n    }if (typeof a.explicit != \"undefined\") {\n      this.isExplicit = a.explicit;\n    }if (typeof a.obj != \"undefined\") {\n      this.asn1Object = a.obj;this.setASN1Object(this.isExplicit, this.hT, this.asn1Object);\n    }\n  }\n};YAHOO.lang.extend(KJUR.asn1.DERTaggedObject, KJUR.asn1.ASN1Object);\nvar ASN1HEX = new function () {}();ASN1HEX.getLblen = function (c, a) {\n  if (c.substr(a + 2, 1) != \"8\") {\n    return 1;\n  }var b = parseInt(c.substr(a + 3, 1));if (b == 0) {\n    return -1;\n  }if (0 < b && b < 10) {\n    return b + 1;\n  }return -2;\n};ASN1HEX.getL = function (c, b) {\n  var a = ASN1HEX.getLblen(c, b);if (a < 1) {\n    return \"\";\n  }return c.substr(b + 2, a * 2);\n};ASN1HEX.getVblen = function (d, a) {\n  var c, b;c = ASN1HEX.getL(d, a);if (c == \"\") {\n    return -1;\n  }if (c.substr(0, 1) === \"8\") {\n    b = new BigInteger(c.substr(2), 16);\n  } else {\n    b = new BigInteger(c, 16);\n  }return b.intValue();\n};ASN1HEX.getVidx = function (c, b) {\n  var a = ASN1HEX.getLblen(c, b);if (a < 0) {\n    return a;\n  }return b + (a + 1) * 2;\n};ASN1HEX.getV = function (d, a) {\n  var c = ASN1HEX.getVidx(d, a);var b = ASN1HEX.getVblen(d, a);return d.substr(c, b * 2);\n};ASN1HEX.getTLV = function (b, a) {\n  return b.substr(a, 2) + ASN1HEX.getL(b, a) + ASN1HEX.getV(b, a);\n};ASN1HEX.getNextSiblingIdx = function (d, a) {\n  var c = ASN1HEX.getVidx(d, a);var b = ASN1HEX.getVblen(d, a);return c + b * 2;\n};ASN1HEX.getChildIdx = function (e, f) {\n  var j = ASN1HEX;var g = new Array();var i = j.getVidx(e, f);if (e.substr(f, 2) == \"03\") {\n    g.push(i + 2);\n  } else {\n    g.push(i);\n  }var l = j.getVblen(e, f);var c = i;var d = 0;while (1) {\n    var b = j.getNextSiblingIdx(e, c);if (b == null || b - i >= l * 2) {\n      break;\n    }if (d >= 200) {\n      break;\n    }g.push(b);c = b;d++;\n  }return g;\n};ASN1HEX.getNthChildIdx = function (d, b, e) {\n  var c = ASN1HEX.getChildIdx(d, b);return c[e];\n};ASN1HEX.getIdxbyList = function (e, d, c, i) {\n  var g = ASN1HEX;var f, b;if (c.length == 0) {\n    if (i !== undefined) {\n      if (e.substr(d, 2) !== i) {\n        throw \"checking tag doesn't match: \" + e.substr(d, 2) + \"!=\" + i;\n      }\n    }return d;\n  }f = c.shift();b = g.getChildIdx(e, d);return g.getIdxbyList(e, b[f], c, i);\n};ASN1HEX.getTLVbyList = function (d, c, b, f) {\n  var e = ASN1HEX;var a = e.getIdxbyList(d, c, b);if (a === undefined) {\n    throw \"can't find nthList object\";\n  }if (f !== undefined) {\n    if (d.substr(a, 2) != f) {\n      throw \"checking tag doesn't match: \" + d.substr(a, 2) + \"!=\" + f;\n    }\n  }return e.getTLV(d, a);\n};ASN1HEX.getVbyList = function (e, c, b, g, i) {\n  var f = ASN1HEX;var a, d;a = f.getIdxbyList(e, c, b, g);if (a === undefined) {\n    throw \"can't find nthList object\";\n  }d = f.getV(e, a);if (i === true) {\n    d = d.substr(2);\n  }return d;\n};ASN1HEX.hextooidstr = function (e) {\n  var h = function h(b, a) {\n    if (b.length >= a) {\n      return b;\n    }return new Array(a - b.length + 1).join(\"0\") + b;\n  };var l = [];var o = e.substr(0, 2);var f = parseInt(o, 16);l[0] = new String(Math.floor(f / 40));l[1] = new String(f % 40);var m = e.substr(2);var k = [];for (var g = 0; g < m.length / 2; g++) {\n    k.push(parseInt(m.substr(g * 2, 2), 16));\n  }var j = [];var d = \"\";for (var g = 0; g < k.length; g++) {\n    if (k[g] & 128) {\n      d = d + h((k[g] & 127).toString(2), 7);\n    } else {\n      d = d + h((k[g] & 127).toString(2), 7);j.push(new String(parseInt(d, 2)));d = \"\";\n    }\n  }var n = l.join(\".\");if (j.length > 0) {\n    n = n + \".\" + j.join(\".\");\n  }return n;\n};ASN1HEX.dump = function (t, c, l, g) {\n  var p = ASN1HEX;var j = p.getV;var y = p.dump;var w = p.getChildIdx;var e = t;if (t instanceof KJUR.asn1.ASN1Object) {\n    e = t.getEncodedHex();\n  }var q = function q(A, i) {\n    if (A.length <= i * 2) {\n      return A;\n    } else {\n      var v = A.substr(0, i) + \"..(total \" + A.length / 2 + \"bytes)..\" + A.substr(A.length - i, i);return v;\n    }\n  };if (c === undefined) {\n    c = { ommit_long_octet: 32 };\n  }if (l === undefined) {\n    l = 0;\n  }if (g === undefined) {\n    g = \"\";\n  }var x = c.ommit_long_octet;if (e.substr(l, 2) == \"01\") {\n    var h = j(e, l);if (h == \"00\") {\n      return g + \"BOOLEAN FALSE\\n\";\n    } else {\n      return g + \"BOOLEAN TRUE\\n\";\n    }\n  }if (e.substr(l, 2) == \"02\") {\n    var h = j(e, l);return g + \"INTEGER \" + q(h, x) + \"\\n\";\n  }if (e.substr(l, 2) == \"03\") {\n    var h = j(e, l);return g + \"BITSTRING \" + q(h, x) + \"\\n\";\n  }if (e.substr(l, 2) == \"04\") {\n    var h = j(e, l);if (p.isASN1HEX(h)) {\n      var k = g + \"OCTETSTRING, encapsulates\\n\";k = k + y(h, c, 0, g + \"  \");return k;\n    } else {\n      return g + \"OCTETSTRING \" + q(h, x) + \"\\n\";\n    }\n  }if (e.substr(l, 2) == \"05\") {\n    return g + \"NULL\\n\";\n  }if (e.substr(l, 2) == \"06\") {\n    var m = j(e, l);var a = KJUR.asn1.ASN1Util.oidHexToInt(m);var o = KJUR.asn1.x509.OID.oid2name(a);var b = a.replace(/\\./g, \" \");if (o != \"\") {\n      return g + \"ObjectIdentifier \" + o + \" (\" + b + \")\\n\";\n    } else {\n      return g + \"ObjectIdentifier (\" + b + \")\\n\";\n    }\n  }if (e.substr(l, 2) == \"0c\") {\n    return g + \"UTF8String '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"13\") {\n    return g + \"PrintableString '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"14\") {\n    return g + \"TeletexString '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"16\") {\n    return g + \"IA5String '\" + hextoutf8(j(e, l)) + \"'\\n\";\n  }if (e.substr(l, 2) == \"17\") {\n    return g + \"UTCTime \" + hextoutf8(j(e, l)) + \"\\n\";\n  }if (e.substr(l, 2) == \"18\") {\n    return g + \"GeneralizedTime \" + hextoutf8(j(e, l)) + \"\\n\";\n  }if (e.substr(l, 2) == \"30\") {\n    if (e.substr(l, 4) == \"3000\") {\n      return g + \"SEQUENCE {}\\n\";\n    }var k = g + \"SEQUENCE\\n\";var d = w(e, l);var f = c;if ((d.length == 2 || d.length == 3) && e.substr(d[0], 2) == \"06\" && e.substr(d[d.length - 1], 2) == \"04\") {\n      var o = p.oidname(j(e, d[0]));var r = JSON.parse(JSON.stringify(c));r.x509ExtName = o;f = r;\n    }for (var u = 0; u < d.length; u++) {\n      k = k + y(e, f, d[u], g + \"  \");\n    }return k;\n  }if (e.substr(l, 2) == \"31\") {\n    var k = g + \"SET\\n\";var d = w(e, l);for (var u = 0; u < d.length; u++) {\n      k = k + y(e, c, d[u], g + \"  \");\n    }return k;\n  }var z = parseInt(e.substr(l, 2), 16);if ((z & 128) != 0) {\n    var n = z & 31;if ((z & 32) != 0) {\n      var k = g + \"[\" + n + \"]\\n\";var d = w(e, l);for (var u = 0; u < d.length; u++) {\n        k = k + y(e, c, d[u], g + \"  \");\n      }return k;\n    } else {\n      var h = j(e, l);if (h.substr(0, 8) == \"68747470\") {\n        h = hextoutf8(h);\n      }if (c.x509ExtName === \"subjectAltName\" && n == 2) {\n        h = hextoutf8(h);\n      }var k = g + \"[\" + n + \"] \" + h + \"\\n\";return k;\n    }\n  }return g + \"UNKNOWN(\" + e.substr(l, 2) + \") \" + j(e, l) + \"\\n\";\n};ASN1HEX.isASN1HEX = function (e) {\n  var d = ASN1HEX;if (e.length % 2 == 1) {\n    return false;\n  }var c = d.getVblen(e, 0);var b = e.substr(0, 2);var f = d.getL(e, 0);var a = e.length - b.length - f.length;if (a == c * 2) {\n    return true;\n  }return false;\n};ASN1HEX.oidname = function (a) {\n  var c = KJUR.asn1;if (KJUR.lang.String.isHex(a)) {\n    a = c.ASN1Util.oidHexToInt(a);\n  }var b = c.x509.OID.oid2name(a);if (b === \"\") {\n    b = a;\n  }return b;\n};\nvar KJUR;if (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.lang == \"undefined\" || !KJUR.lang) {\n  KJUR.lang = {};\n}KJUR.lang.String = function () {};function Base64x() {}function stoBA(d) {\n  var b = new Array();for (var c = 0; c < d.length; c++) {\n    b[c] = d.charCodeAt(c);\n  }return b;\n}function BAtos(b) {\n  var d = \"\";for (var c = 0; c < b.length; c++) {\n    d = d + String.fromCharCode(b[c]);\n  }return d;\n}function BAtohex(b) {\n  var e = \"\";for (var d = 0; d < b.length; d++) {\n    var c = b[d].toString(16);if (c.length == 1) {\n      c = \"0\" + c;\n    }e = e + c;\n  }return e;\n}function stohex(a) {\n  return BAtohex(stoBA(a));\n}function stob64(a) {\n  return hex2b64(stohex(a));\n}function stob64u(a) {\n  return b64tob64u(hex2b64(stohex(a)));\n}function b64utos(a) {\n  return BAtos(b64toBA(b64utob64(a)));\n}function b64tob64u(a) {\n  a = a.replace(/\\=/g, \"\");a = a.replace(/\\+/g, \"-\");a = a.replace(/\\//g, \"_\");return a;\n}function b64utob64(a) {\n  if (a.length % 4 == 2) {\n    a = a + \"==\";\n  } else {\n    if (a.length % 4 == 3) {\n      a = a + \"=\";\n    }\n  }a = a.replace(/-/g, \"+\");a = a.replace(/_/g, \"/\");return a;\n}function hextob64u(a) {\n  if (a.length % 2 == 1) {\n    a = \"0\" + a;\n  }return b64tob64u(hex2b64(a));\n}function b64utohex(a) {\n  return b64tohex(b64utob64(a));\n}var utf8tob64u, b64utoutf8;if (typeof Buffer === \"function\") {\n  exports.utf8tob64u = utf8tob64u = function utf8tob64u(a) {\n    return b64tob64u(new Buffer(a, \"utf8\").toString(\"base64\"));\n  };exports.b64utoutf8 = b64utoutf8 = function b64utoutf8(a) {\n    return new Buffer(b64utob64(a), \"base64\").toString(\"utf8\");\n  };\n} else {\n  exports.utf8tob64u = utf8tob64u = function utf8tob64u(a) {\n    return hextob64u(uricmptohex(encodeURIComponentAll(a)));\n  };exports.b64utoutf8 = b64utoutf8 = function b64utoutf8(a) {\n    return decodeURIComponent(hextouricmp(b64utohex(a)));\n  };\n}function utf8tob64(a) {\n  return hex2b64(uricmptohex(encodeURIComponentAll(a)));\n}function b64toutf8(a) {\n  return decodeURIComponent(hextouricmp(b64tohex(a)));\n}function utf8tohex(a) {\n  return uricmptohex(encodeURIComponentAll(a));\n}function hextoutf8(a) {\n  return decodeURIComponent(hextouricmp(a));\n}function hextorstr(c) {\n  var b = \"\";for (var a = 0; a < c.length - 1; a += 2) {\n    b += String.fromCharCode(parseInt(c.substr(a, 2), 16));\n  }return b;\n}function rstrtohex(c) {\n  var a = \"\";for (var b = 0; b < c.length; b++) {\n    a += (\"0\" + c.charCodeAt(b).toString(16)).slice(-2);\n  }return a;\n}function hextob64(a) {\n  return hex2b64(a);\n}function hextob64nl(b) {\n  var a = hextob64(b);var c = a.replace(/(.{64})/g, \"$1\\r\\n\");c = c.replace(/\\r\\n$/, \"\");return c;\n}function b64nltohex(b) {\n  var a = b.replace(/[^0-9A-Za-z\\/+=]*/g, \"\");var c = b64tohex(a);return c;\n}function hextopem(a, b) {\n  var c = hextob64nl(a);return \"-----BEGIN \" + b + \"-----\\r\\n\" + c + \"\\r\\n-----END \" + b + \"-----\\r\\n\";\n}function pemtohex(a, b) {\n  if (a.indexOf(\"-----BEGIN \") == -1) {\n    throw \"can't find PEM header: \" + b;\n  }if (b !== undefined) {\n    a = a.replace(\"-----BEGIN \" + b + \"-----\", \"\");a = a.replace(\"-----END \" + b + \"-----\", \"\");\n  } else {\n    a = a.replace(/-----BEGIN [^-]+-----/, \"\");a = a.replace(/-----END [^-]+-----/, \"\");\n  }return b64nltohex(a);\n}function hextoArrayBuffer(d) {\n  if (d.length % 2 != 0) {\n    throw \"input is not even length\";\n  }if (d.match(/^[0-9A-Fa-f]+$/) == null) {\n    throw \"input is not hexadecimal\";\n  }var b = new ArrayBuffer(d.length / 2);var a = new DataView(b);for (var c = 0; c < d.length / 2; c++) {\n    a.setUint8(c, parseInt(d.substr(c * 2, 2), 16));\n  }return b;\n}function ArrayBuffertohex(b) {\n  var d = \"\";var a = new DataView(b);for (var c = 0; c < b.byteLength; c++) {\n    d += (\"00\" + a.getUint8(c).toString(16)).slice(-2);\n  }return d;\n}function zulutomsec(n) {\n  var l, j, m, e, f, i, b, k;var a, h, g, c;c = n.match(/^(\\d{2}|\\d{4})(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(|\\.\\d+)Z$/);if (c) {\n    a = c[1];l = parseInt(a);if (a.length === 2) {\n      if (50 <= l && l < 100) {\n        l = 1900 + l;\n      } else {\n        if (0 <= l && l < 50) {\n          l = 2000 + l;\n        }\n      }\n    }j = parseInt(c[2]) - 1;m = parseInt(c[3]);e = parseInt(c[4]);f = parseInt(c[5]);i = parseInt(c[6]);b = 0;h = c[7];if (h !== \"\") {\n      g = (h.substr(1) + \"00\").substr(0, 3);b = parseInt(g);\n    }return Date.UTC(l, j, m, e, f, i, b);\n  }throw \"unsupported zulu format: \" + n;\n}function zulutosec(a) {\n  var b = zulutomsec(a);return ~~(b / 1000);\n}function zulutodate(a) {\n  return new Date(zulutomsec(a));\n}function datetozulu(g, e, f) {\n  var b;var a = g.getUTCFullYear();if (e) {\n    if (a < 1950 || 2049 < a) {\n      throw \"not proper year for UTCTime: \" + a;\n    }b = (\"\" + a).slice(-2);\n  } else {\n    b = (\"000\" + a).slice(-4);\n  }b += (\"0\" + (g.getUTCMonth() + 1)).slice(-2);b += (\"0\" + g.getUTCDate()).slice(-2);b += (\"0\" + g.getUTCHours()).slice(-2);b += (\"0\" + g.getUTCMinutes()).slice(-2);b += (\"0\" + g.getUTCSeconds()).slice(-2);if (f) {\n    var c = g.getUTCMilliseconds();if (c !== 0) {\n      c = (\"00\" + c).slice(-3);c = c.replace(/0+$/g, \"\");b += \".\" + c;\n    }\n  }b += \"Z\";return b;\n}function uricmptohex(a) {\n  return a.replace(/%/g, \"\");\n}function hextouricmp(a) {\n  return a.replace(/(..)/g, \"%$1\");\n}function ipv6tohex(g) {\n  var b = \"malformed IPv6 address\";if (!g.match(/^[0-9A-Fa-f:]+$/)) {\n    throw b;\n  }g = g.toLowerCase();var d = g.split(\":\").length - 1;if (d < 2) {\n    throw b;\n  }var e = \":\".repeat(7 - d + 2);g = g.replace(\"::\", e);var c = g.split(\":\");if (c.length != 8) {\n    throw b;\n  }for (var f = 0; f < 8; f++) {\n    c[f] = (\"0000\" + c[f]).slice(-4);\n  }return c.join(\"\");\n}function hextoipv6(e) {\n  if (!e.match(/^[0-9A-Fa-f]{32}$/)) {\n    throw \"malformed IPv6 address octet\";\n  }e = e.toLowerCase();var b = e.match(/.{1,4}/g);for (var d = 0; d < 8; d++) {\n    b[d] = b[d].replace(/^0+/, \"\");if (b[d] == \"\") {\n      b[d] = \"0\";\n    }\n  }e = \":\" + b.join(\":\") + \":\";var c = e.match(/:(0:){2,}/g);if (c === null) {\n    return e.slice(1, -1);\n  }var f = \"\";for (var d = 0; d < c.length; d++) {\n    if (c[d].length > f.length) {\n      f = c[d];\n    }\n  }e = e.replace(f, \"::\");return e.slice(1, -1);\n}function hextoip(b) {\n  var d = \"malformed hex value\";if (!b.match(/^([0-9A-Fa-f][0-9A-Fa-f]){1,}$/)) {\n    throw d;\n  }if (b.length == 8) {\n    var c;try {\n      c = parseInt(b.substr(0, 2), 16) + \".\" + parseInt(b.substr(2, 2), 16) + \".\" + parseInt(b.substr(4, 2), 16) + \".\" + parseInt(b.substr(6, 2), 16);return c;\n    } catch (a) {\n      throw d;\n    }\n  } else {\n    if (b.length == 32) {\n      return hextoipv6(b);\n    } else {\n      return b;\n    }\n  }\n}function iptohex(f) {\n  var j = \"malformed IP address\";f = f.toLowerCase(f);if (f.match(/^[0-9.]+$/)) {\n    var b = f.split(\".\");if (b.length !== 4) {\n      throw j;\n    }var g = \"\";try {\n      for (var e = 0; e < 4; e++) {\n        var h = parseInt(b[e]);g += (\"0\" + h.toString(16)).slice(-2);\n      }return g;\n    } catch (c) {\n      throw j;\n    }\n  } else {\n    if (f.match(/^[0-9a-f:]+$/) && f.indexOf(\":\") !== -1) {\n      return ipv6tohex(f);\n    } else {\n      throw j;\n    }\n  }\n}function encodeURIComponentAll(a) {\n  var d = encodeURIComponent(a);var b = \"\";for (var c = 0; c < d.length; c++) {\n    if (d[c] == \"%\") {\n      b = b + d.substr(c, 3);c = c + 2;\n    } else {\n      b = b + \"%\" + stohex(d[c]);\n    }\n  }return b;\n}function newline_toUnix(a) {\n  a = a.replace(/\\r\\n/mg, \"\\n\");return a;\n}function newline_toDos(a) {\n  a = a.replace(/\\r\\n/mg, \"\\n\");a = a.replace(/\\n/mg, \"\\r\\n\");return a;\n}KJUR.lang.String.isInteger = function (a) {\n  if (a.match(/^[0-9]+$/)) {\n    return true;\n  } else {\n    if (a.match(/^-[0-9]+$/)) {\n      return true;\n    } else {\n      return false;\n    }\n  }\n};KJUR.lang.String.isHex = function (a) {\n  if (a.length % 2 == 0 && (a.match(/^[0-9a-f]+$/) || a.match(/^[0-9A-F]+$/))) {\n    return true;\n  } else {\n    return false;\n  }\n};KJUR.lang.String.isBase64 = function (a) {\n  a = a.replace(/\\s+/g, \"\");if (a.match(/^[0-9A-Za-z+\\/]+={0,3}$/) && a.length % 4 == 0) {\n    return true;\n  } else {\n    return false;\n  }\n};KJUR.lang.String.isBase64URL = function (a) {\n  if (a.match(/[+/=]/)) {\n    return false;\n  }a = b64utob64(a);return KJUR.lang.String.isBase64(a);\n};KJUR.lang.String.isIntegerArray = function (a) {\n  a = a.replace(/\\s+/g, \"\");if (a.match(/^\\[[0-9,]+\\]$/)) {\n    return true;\n  } else {\n    return false;\n  }\n};function hextoposhex(a) {\n  if (a.length % 2 == 1) {\n    return \"0\" + a;\n  }if (a.substr(0, 1) > \"7\") {\n    return \"00\" + a;\n  }return a;\n}function intarystrtohex(b) {\n  b = b.replace(/^\\s*\\[\\s*/, \"\");b = b.replace(/\\s*\\]\\s*$/, \"\");b = b.replace(/\\s*/g, \"\");try {\n    var c = b.split(/,/).map(function (g, e, h) {\n      var f = parseInt(g);if (f < 0 || 255 < f) {\n        throw \"integer not in range 0-255\";\n      }var d = (\"00\" + f.toString(16)).slice(-2);return d;\n    }).join(\"\");return c;\n  } catch (a) {\n    throw \"malformed integer array string: \" + a;\n  }\n}var strdiffidx = function strdiffidx(c, a) {\n  var d = c.length;if (c.length > a.length) {\n    d = a.length;\n  }for (var b = 0; b < d; b++) {\n    if (c.charCodeAt(b) != a.charCodeAt(b)) {\n      return b;\n    }\n  }if (c.length != a.length) {\n    return d;\n  }return -1;\n};\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.crypto == \"undefined\" || !KJUR.crypto) {\n  KJUR.crypto = {};\n}KJUR.crypto.Util = new function () {\n  this.DIGESTINFOHEAD = { sha1: \"3021300906052b0e03021a05000414\", sha224: \"302d300d06096086480165030402040500041c\", sha256: \"3031300d060960864801650304020105000420\", sha384: \"3041300d060960864801650304020205000430\", sha512: \"3051300d060960864801650304020305000440\", md2: \"3020300c06082a864886f70d020205000410\", md5: \"3020300c06082a864886f70d020505000410\", ripemd160: \"3021300906052b2403020105000414\" };this.DEFAULTPROVIDER = { md5: \"cryptojs\", sha1: \"cryptojs\", sha224: \"cryptojs\", sha256: \"cryptojs\", sha384: \"cryptojs\", sha512: \"cryptojs\", ripemd160: \"cryptojs\", hmacmd5: \"cryptojs\", hmacsha1: \"cryptojs\", hmacsha224: \"cryptojs\", hmacsha256: \"cryptojs\", hmacsha384: \"cryptojs\", hmacsha512: \"cryptojs\", hmacripemd160: \"cryptojs\", MD5withRSA: \"cryptojs/jsrsa\", SHA1withRSA: \"cryptojs/jsrsa\", SHA224withRSA: \"cryptojs/jsrsa\", SHA256withRSA: \"cryptojs/jsrsa\", SHA384withRSA: \"cryptojs/jsrsa\", SHA512withRSA: \"cryptojs/jsrsa\", RIPEMD160withRSA: \"cryptojs/jsrsa\", MD5withECDSA: \"cryptojs/jsrsa\", SHA1withECDSA: \"cryptojs/jsrsa\", SHA224withECDSA: \"cryptojs/jsrsa\", SHA256withECDSA: \"cryptojs/jsrsa\", SHA384withECDSA: \"cryptojs/jsrsa\", SHA512withECDSA: \"cryptojs/jsrsa\", RIPEMD160withECDSA: \"cryptojs/jsrsa\", SHA1withDSA: \"cryptojs/jsrsa\", SHA224withDSA: \"cryptojs/jsrsa\", SHA256withDSA: \"cryptojs/jsrsa\", MD5withRSAandMGF1: \"cryptojs/jsrsa\", SHA1withRSAandMGF1: \"cryptojs/jsrsa\", SHA224withRSAandMGF1: \"cryptojs/jsrsa\", SHA256withRSAandMGF1: \"cryptojs/jsrsa\", SHA384withRSAandMGF1: \"cryptojs/jsrsa\", SHA512withRSAandMGF1: \"cryptojs/jsrsa\", RIPEMD160withRSAandMGF1: \"cryptojs/jsrsa\" };this.CRYPTOJSMESSAGEDIGESTNAME = { md5: CryptoJS.algo.MD5, sha1: CryptoJS.algo.SHA1, sha224: CryptoJS.algo.SHA224, sha256: CryptoJS.algo.SHA256, sha384: CryptoJS.algo.SHA384, sha512: CryptoJS.algo.SHA512, ripemd160: CryptoJS.algo.RIPEMD160 };this.getDigestInfoHex = function (a, b) {\n    if (typeof this.DIGESTINFOHEAD[b] == \"undefined\") {\n      throw \"alg not supported in Util.DIGESTINFOHEAD: \" + b;\n    }return this.DIGESTINFOHEAD[b] + a;\n  };this.getPaddedDigestInfoHex = function (h, a, j) {\n    var c = this.getDigestInfoHex(h, a);var d = j / 4;if (c.length + 22 > d) {\n      throw \"key is too short for SigAlg: keylen=\" + j + \",\" + a;\n    }var b = \"0001\";var k = \"00\" + c;var g = \"\";var l = d - b.length - k.length;for (var f = 0; f < l; f += 2) {\n      g += \"ff\";\n    }var e = b + g + k;return e;\n  };this.hashString = function (a, c) {\n    var b = new KJUR.crypto.MessageDigest({ alg: c });return b.digestString(a);\n  };this.hashHex = function (b, c) {\n    var a = new KJUR.crypto.MessageDigest({ alg: c });return a.digestHex(b);\n  };this.sha1 = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha1\", prov: \"cryptojs\" });return b.digestString(a);\n  };this.sha256 = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha256\", prov: \"cryptojs\" });return b.digestString(a);\n  };this.sha256Hex = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha256\", prov: \"cryptojs\" });return b.digestHex(a);\n  };this.sha512 = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha512\", prov: \"cryptojs\" });return b.digestString(a);\n  };this.sha512Hex = function (a) {\n    var b = new KJUR.crypto.MessageDigest({ alg: \"sha512\", prov: \"cryptojs\" });return b.digestHex(a);\n  };\n}();KJUR.crypto.Util.md5 = function (a) {\n  var b = new KJUR.crypto.MessageDigest({ alg: \"md5\", prov: \"cryptojs\" });return b.digestString(a);\n};KJUR.crypto.Util.ripemd160 = function (a) {\n  var b = new KJUR.crypto.MessageDigest({ alg: \"ripemd160\", prov: \"cryptojs\" });return b.digestString(a);\n};KJUR.crypto.Util.SECURERANDOMGEN = new SecureRandom();KJUR.crypto.Util.getRandomHexOfNbytes = function (b) {\n  var a = new Array(b);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(a);return BAtohex(a);\n};KJUR.crypto.Util.getRandomBigIntegerOfNbytes = function (a) {\n  return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbytes(a), 16);\n};KJUR.crypto.Util.getRandomHexOfNbits = function (d) {\n  var c = d % 8;var a = (d - c) / 8;var b = new Array(a + 1);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(b);b[0] = (255 << c & 255 ^ 255) & b[0];return BAtohex(b);\n};KJUR.crypto.Util.getRandomBigIntegerOfNbits = function (a) {\n  return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbits(a), 16);\n};KJUR.crypto.Util.getRandomBigIntegerZeroToMax = function (b) {\n  var a = b.bitLength();while (1) {\n    var c = KJUR.crypto.Util.getRandomBigIntegerOfNbits(a);if (b.compareTo(c) != -1) {\n      return c;\n    }\n  }\n};KJUR.crypto.Util.getRandomBigIntegerMinToMax = function (e, b) {\n  var c = e.compareTo(b);if (c == 1) {\n    throw \"biMin is greater than biMax\";\n  }if (c == 0) {\n    return e;\n  }var a = b.subtract(e);var d = KJUR.crypto.Util.getRandomBigIntegerZeroToMax(a);return d.add(e);\n};KJUR.crypto.MessageDigest = function (c) {\n  var b = null;var a = null;var d = null;this.setAlgAndProvider = function (g, f) {\n    g = KJUR.crypto.MessageDigest.getCanonicalAlgName(g);if (g !== null && f === undefined) {\n      f = KJUR.crypto.Util.DEFAULTPROVIDER[g];\n    }if (\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g) != -1 && f == \"cryptojs\") {\n      try {\n        this.md = KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g].create();\n      } catch (e) {\n        throw \"setAlgAndProvider hash alg set fail alg=\" + g + \"/\" + e;\n      }this.updateString = function (h) {\n        this.md.update(h);\n      };this.updateHex = function (h) {\n        var i = CryptoJS.enc.Hex.parse(h);this.md.update(i);\n      };this.digest = function () {\n        var h = this.md.finalize();return h.toString(CryptoJS.enc.Hex);\n      };this.digestString = function (h) {\n        this.updateString(h);return this.digest();\n      };this.digestHex = function (h) {\n        this.updateHex(h);return this.digest();\n      };\n    }if (\":sha256:\".indexOf(g) != -1 && f == \"sjcl\") {\n      try {\n        this.md = new sjcl.hash.sha256();\n      } catch (e) {\n        throw \"setAlgAndProvider hash alg set fail alg=\" + g + \"/\" + e;\n      }this.updateString = function (h) {\n        this.md.update(h);\n      };this.updateHex = function (i) {\n        var h = sjcl.codec.hex.toBits(i);this.md.update(h);\n      };this.digest = function () {\n        var h = this.md.finalize();return sjcl.codec.hex.fromBits(h);\n      };this.digestString = function (h) {\n        this.updateString(h);return this.digest();\n      };this.digestHex = function (h) {\n        this.updateHex(h);return this.digest();\n      };\n    }\n  };this.updateString = function (e) {\n    throw \"updateString(str) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.updateHex = function (e) {\n    throw \"updateHex(hex) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.digest = function () {\n    throw \"digest() not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.digestString = function (e) {\n    throw \"digestString(str) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };this.digestHex = function (e) {\n    throw \"digestHex(hex) not supported for this alg/prov: \" + this.algName + \"/\" + this.provName;\n  };if (c !== undefined) {\n    if (c.alg !== undefined) {\n      this.algName = c.alg;if (c.prov === undefined) {\n        this.provName = KJUR.crypto.Util.DEFAULTPROVIDER[this.algName];\n      }this.setAlgAndProvider(this.algName, this.provName);\n    }\n  }\n};KJUR.crypto.MessageDigest.getCanonicalAlgName = function (a) {\n  if (typeof a === \"string\") {\n    a = a.toLowerCase();a = a.replace(/-/, \"\");\n  }return a;\n};KJUR.crypto.MessageDigest.getHashLength = function (c) {\n  var b = KJUR.crypto.MessageDigest;var a = b.getCanonicalAlgName(c);if (b.HASHLENGTH[a] === undefined) {\n    throw \"not supported algorithm: \" + c;\n  }return b.HASHLENGTH[a];\n};KJUR.crypto.MessageDigest.HASHLENGTH = { md5: 16, sha1: 20, sha224: 28, sha256: 32, sha384: 48, sha512: 64, ripemd160: 20 };KJUR.crypto.Mac = function (d) {\n  var f = null;var c = null;var a = null;var e = null;var b = null;this.setAlgAndProvider = function (k, i) {\n    k = k.toLowerCase();if (k == null) {\n      k = \"hmacsha1\";\n    }k = k.toLowerCase();if (k.substr(0, 4) != \"hmac\") {\n      throw \"setAlgAndProvider unsupported HMAC alg: \" + k;\n    }if (i === undefined) {\n      i = KJUR.crypto.Util.DEFAULTPROVIDER[k];\n    }this.algProv = k + \"/\" + i;var g = k.substr(4);if (\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g) != -1 && i == \"cryptojs\") {\n      try {\n        var j = KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g];this.mac = CryptoJS.algo.HMAC.create(j, this.pass);\n      } catch (h) {\n        throw \"setAlgAndProvider hash alg set fail hashAlg=\" + g + \"/\" + h;\n      }this.updateString = function (l) {\n        this.mac.update(l);\n      };this.updateHex = function (l) {\n        var m = CryptoJS.enc.Hex.parse(l);this.mac.update(m);\n      };this.doFinal = function () {\n        var l = this.mac.finalize();return l.toString(CryptoJS.enc.Hex);\n      };this.doFinalString = function (l) {\n        this.updateString(l);return this.doFinal();\n      };this.doFinalHex = function (l) {\n        this.updateHex(l);return this.doFinal();\n      };\n    }\n  };this.updateString = function (g) {\n    throw \"updateString(str) not supported for this alg/prov: \" + this.algProv;\n  };this.updateHex = function (g) {\n    throw \"updateHex(hex) not supported for this alg/prov: \" + this.algProv;\n  };this.doFinal = function () {\n    throw \"digest() not supported for this alg/prov: \" + this.algProv;\n  };this.doFinalString = function (g) {\n    throw \"digestString(str) not supported for this alg/prov: \" + this.algProv;\n  };this.doFinalHex = function (g) {\n    throw \"digestHex(hex) not supported for this alg/prov: \" + this.algProv;\n  };this.setPassword = function (h) {\n    if (typeof h == \"string\") {\n      var g = h;if (h.length % 2 == 1 || !h.match(/^[0-9A-Fa-f]+$/)) {\n        g = rstrtohex(h);\n      }this.pass = CryptoJS.enc.Hex.parse(g);return;\n    }if ((typeof h === \"undefined\" ? \"undefined\" : _typeof(h)) != \"object\") {\n      throw \"KJUR.crypto.Mac unsupported password type: \" + h;\n    }var g = null;if (h.hex !== undefined) {\n      if (h.hex.length % 2 != 0 || !h.hex.match(/^[0-9A-Fa-f]+$/)) {\n        throw \"Mac: wrong hex password: \" + h.hex;\n      }g = h.hex;\n    }if (h.utf8 !== undefined) {\n      g = utf8tohex(h.utf8);\n    }if (h.rstr !== undefined) {\n      g = rstrtohex(h.rstr);\n    }if (h.b64 !== undefined) {\n      g = b64tohex(h.b64);\n    }if (h.b64u !== undefined) {\n      g = b64utohex(h.b64u);\n    }if (g == null) {\n      throw \"KJUR.crypto.Mac unsupported password type: \" + h;\n    }this.pass = CryptoJS.enc.Hex.parse(g);\n  };if (d !== undefined) {\n    if (d.pass !== undefined) {\n      this.setPassword(d.pass);\n    }if (d.alg !== undefined) {\n      this.algName = d.alg;if (d.prov === undefined) {\n        this.provName = KJUR.crypto.Util.DEFAULTPROVIDER[this.algName];\n      }this.setAlgAndProvider(this.algName, this.provName);\n    }\n  }\n};KJUR.crypto.Signature = function (o) {\n  var q = null;var n = null;var r = null;var c = null;var l = null;var d = null;var k = null;var h = null;var p = null;var e = null;var b = -1;var g = null;var j = null;var a = null;var i = null;var f = null;this._setAlgNames = function () {\n    var s = this.algName.match(/^(.+)with(.+)$/);if (s) {\n      this.mdAlgName = s[1].toLowerCase();this.pubkeyAlgName = s[2].toLowerCase();\n    }\n  };this._zeroPaddingOfSignature = function (x, w) {\n    var v = \"\";var t = w / 4 - x.length;for (var u = 0; u < t; u++) {\n      v = v + \"0\";\n    }return v + x;\n  };this.setAlgAndProvider = function (u, t) {\n    this._setAlgNames();if (t != \"cryptojs/jsrsa\") {\n      throw \"provider not supported: \" + t;\n    }if (\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(this.mdAlgName) != -1) {\n      try {\n        this.md = new KJUR.crypto.MessageDigest({ alg: this.mdAlgName });\n      } catch (s) {\n        throw \"setAlgAndProvider hash alg set fail alg=\" + this.mdAlgName + \"/\" + s;\n      }this.init = function (w, x) {\n        var y = null;try {\n          if (x === undefined) {\n            y = KEYUTIL.getKey(w);\n          } else {\n            y = KEYUTIL.getKey(w, x);\n          }\n        } catch (v) {\n          throw \"init failed:\" + v;\n        }if (y.isPrivate === true) {\n          this.prvKey = y;this.state = \"SIGN\";\n        } else {\n          if (y.isPublic === true) {\n            this.pubKey = y;this.state = \"VERIFY\";\n          } else {\n            throw \"init failed.:\" + y;\n          }\n        }\n      };this.updateString = function (v) {\n        this.md.updateString(v);\n      };this.updateHex = function (v) {\n        this.md.updateHex(v);\n      };this.sign = function () {\n        this.sHashHex = this.md.digest();if (typeof this.ecprvhex != \"undefined\" && typeof this.eccurvename != \"undefined\") {\n          var v = new KJUR.crypto.ECDSA({ curve: this.eccurvename });this.hSign = v.signHex(this.sHashHex, this.ecprvhex);\n        } else {\n          if (this.prvKey instanceof RSAKey && this.pubkeyAlgName === \"rsaandmgf1\") {\n            this.hSign = this.prvKey.signWithMessageHashPSS(this.sHashHex, this.mdAlgName, this.pssSaltLen);\n          } else {\n            if (this.prvKey instanceof RSAKey && this.pubkeyAlgName === \"rsa\") {\n              this.hSign = this.prvKey.signWithMessageHash(this.sHashHex, this.mdAlgName);\n            } else {\n              if (this.prvKey instanceof KJUR.crypto.ECDSA) {\n                this.hSign = this.prvKey.signWithMessageHash(this.sHashHex);\n              } else {\n                if (this.prvKey instanceof KJUR.crypto.DSA) {\n                  this.hSign = this.prvKey.signWithMessageHash(this.sHashHex);\n                } else {\n                  throw \"Signature: unsupported private key alg: \" + this.pubkeyAlgName;\n                }\n              }\n            }\n          }\n        }return this.hSign;\n      };this.signString = function (v) {\n        this.updateString(v);return this.sign();\n      };this.signHex = function (v) {\n        this.updateHex(v);return this.sign();\n      };this.verify = function (v) {\n        this.sHashHex = this.md.digest();if (typeof this.ecpubhex != \"undefined\" && typeof this.eccurvename != \"undefined\") {\n          var w = new KJUR.crypto.ECDSA({ curve: this.eccurvename });return w.verifyHex(this.sHashHex, v, this.ecpubhex);\n        } else {\n          if (this.pubKey instanceof RSAKey && this.pubkeyAlgName === \"rsaandmgf1\") {\n            return this.pubKey.verifyWithMessageHashPSS(this.sHashHex, v, this.mdAlgName, this.pssSaltLen);\n          } else {\n            if (this.pubKey instanceof RSAKey && this.pubkeyAlgName === \"rsa\") {\n              return this.pubKey.verifyWithMessageHash(this.sHashHex, v);\n            } else {\n              if (KJUR.crypto.ECDSA !== undefined && this.pubKey instanceof KJUR.crypto.ECDSA) {\n                return this.pubKey.verifyWithMessageHash(this.sHashHex, v);\n              } else {\n                if (KJUR.crypto.DSA !== undefined && this.pubKey instanceof KJUR.crypto.DSA) {\n                  return this.pubKey.verifyWithMessageHash(this.sHashHex, v);\n                } else {\n                  throw \"Signature: unsupported public key alg: \" + this.pubkeyAlgName;\n                }\n              }\n            }\n          }\n        }\n      };\n    }\n  };this.init = function (s, t) {\n    throw \"init(key, pass) not supported for this alg:prov=\" + this.algProvName;\n  };this.updateString = function (s) {\n    throw \"updateString(str) not supported for this alg:prov=\" + this.algProvName;\n  };this.updateHex = function (s) {\n    throw \"updateHex(hex) not supported for this alg:prov=\" + this.algProvName;\n  };this.sign = function () {\n    throw \"sign() not supported for this alg:prov=\" + this.algProvName;\n  };this.signString = function (s) {\n    throw \"digestString(str) not supported for this alg:prov=\" + this.algProvName;\n  };this.signHex = function (s) {\n    throw \"digestHex(hex) not supported for this alg:prov=\" + this.algProvName;\n  };this.verify = function (s) {\n    throw \"verify(hSigVal) not supported for this alg:prov=\" + this.algProvName;\n  };this.initParams = o;if (o !== undefined) {\n    if (o.alg !== undefined) {\n      this.algName = o.alg;if (o.prov === undefined) {\n        this.provName = KJUR.crypto.Util.DEFAULTPROVIDER[this.algName];\n      } else {\n        this.provName = o.prov;\n      }this.algProvName = this.algName + \":\" + this.provName;this.setAlgAndProvider(this.algName, this.provName);this._setAlgNames();\n    }if (o.psssaltlen !== undefined) {\n      this.pssSaltLen = o.psssaltlen;\n    }if (o.prvkeypem !== undefined) {\n      if (o.prvkeypas !== undefined) {\n        throw \"both prvkeypem and prvkeypas parameters not supported\";\n      } else {\n        try {\n          var q = KEYUTIL.getKey(o.prvkeypem);this.init(q);\n        } catch (m) {\n          throw \"fatal error to load pem private key: \" + m;\n        }\n      }\n    }\n  }\n};KJUR.crypto.Cipher = function (a) {};KJUR.crypto.Cipher.encrypt = function (e, f, d) {\n  if (f instanceof RSAKey && f.isPublic) {\n    var c = KJUR.crypto.Cipher.getAlgByKeyAndName(f, d);if (c === \"RSA\") {\n      return f.encrypt(e);\n    }if (c === \"RSAOAEP\") {\n      return f.encryptOAEP(e, \"sha1\");\n    }var b = c.match(/^RSAOAEP(\\d+)$/);if (b !== null) {\n      return f.encryptOAEP(e, \"sha\" + b[1]);\n    }throw \"Cipher.encrypt: unsupported algorithm for RSAKey: \" + d;\n  } else {\n    throw \"Cipher.encrypt: unsupported key or algorithm\";\n  }\n};KJUR.crypto.Cipher.decrypt = function (e, f, d) {\n  if (f instanceof RSAKey && f.isPrivate) {\n    var c = KJUR.crypto.Cipher.getAlgByKeyAndName(f, d);if (c === \"RSA\") {\n      return f.decrypt(e);\n    }if (c === \"RSAOAEP\") {\n      return f.decryptOAEP(e, \"sha1\");\n    }var b = c.match(/^RSAOAEP(\\d+)$/);if (b !== null) {\n      return f.decryptOAEP(e, \"sha\" + b[1]);\n    }throw \"Cipher.decrypt: unsupported algorithm for RSAKey: \" + d;\n  } else {\n    throw \"Cipher.decrypt: unsupported key or algorithm\";\n  }\n};KJUR.crypto.Cipher.getAlgByKeyAndName = function (b, a) {\n  if (b instanceof RSAKey) {\n    if (\":RSA:RSAOAEP:RSAOAEP224:RSAOAEP256:RSAOAEP384:RSAOAEP512:\".indexOf(a) != -1) {\n      return a;\n    }if (a === null || a === undefined) {\n      return \"RSA\";\n    }throw \"getAlgByKeyAndName: not supported algorithm name for RSAKey: \" + a;\n  }throw \"getAlgByKeyAndName: not supported algorithm name: \" + a;\n};KJUR.crypto.OID = new function () {\n  this.oidhex2name = { \"2a864886f70d010101\": \"rsaEncryption\", \"2a8648ce3d0201\": \"ecPublicKey\", \"2a8648ce380401\": \"dsa\", \"2a8648ce3d030107\": \"secp256r1\", \"2b8104001f\": \"secp192k1\", \"2b81040021\": \"secp224r1\", \"2b8104000a\": \"secp256k1\", \"2b81040023\": \"secp521r1\", \"2b81040022\": \"secp384r1\", \"2a8648ce380403\": \"SHA1withDSA\", \"608648016503040301\": \"SHA224withDSA\", \"608648016503040302\": \"SHA256withDSA\" };\n}();\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.crypto == \"undefined\" || !KJUR.crypto) {\n  KJUR.crypto = {};\n}KJUR.crypto.ECDSA = function (h) {\n  var e = \"secp256r1\";var g = null;var b = null;var f = null;var a = new SecureRandom();var d = null;this.type = \"EC\";this.isPrivate = false;this.isPublic = false;function c(s, o, r, n) {\n    var j = Math.max(o.bitLength(), n.bitLength());var t = s.add2D(r);var q = s.curve.getInfinity();for (var p = j - 1; p >= 0; --p) {\n      q = q.twice2D();q.z = BigInteger.ONE;if (o.testBit(p)) {\n        if (n.testBit(p)) {\n          q = q.add2D(t);\n        } else {\n          q = q.add2D(s);\n        }\n      } else {\n        if (n.testBit(p)) {\n          q = q.add2D(r);\n        }\n      }\n    }return q;\n  }this.getBigRandom = function (i) {\n    return new BigInteger(i.bitLength(), a).mod(i.subtract(BigInteger.ONE)).add(BigInteger.ONE);\n  };this.setNamedCurve = function (i) {\n    this.ecparams = KJUR.crypto.ECParameterDB.getByName(i);this.prvKeyHex = null;this.pubKeyHex = null;this.curveName = i;\n  };this.setPrivateKeyHex = function (i) {\n    this.isPrivate = true;this.prvKeyHex = i;\n  };this.setPublicKeyHex = function (i) {\n    this.isPublic = true;this.pubKeyHex = i;\n  };this.getPublicKeyXYHex = function () {\n    var k = this.pubKeyHex;if (k.substr(0, 2) !== \"04\") {\n      throw \"this method supports uncompressed format(04) only\";\n    }var j = this.ecparams.keylen / 4;if (k.length !== 2 + j * 2) {\n      throw \"malformed public key hex length\";\n    }var i = {};i.x = k.substr(2, j);i.y = k.substr(2 + j);return i;\n  };this.getShortNISTPCurveName = function () {\n    var i = this.curveName;if (i === \"secp256r1\" || i === \"NIST P-256\" || i === \"P-256\" || i === \"prime256v1\") {\n      return \"P-256\";\n    }if (i === \"secp384r1\" || i === \"NIST P-384\" || i === \"P-384\") {\n      return \"P-384\";\n    }return null;\n  };this.generateKeyPairHex = function () {\n    var k = this.ecparams.n;var n = this.getBigRandom(k);var l = this.ecparams.G.multiply(n);var q = l.getX().toBigInteger();var o = l.getY().toBigInteger();var i = this.ecparams.keylen / 4;var m = (\"0000000000\" + n.toString(16)).slice(-i);var r = (\"0000000000\" + q.toString(16)).slice(-i);var p = (\"0000000000\" + o.toString(16)).slice(-i);var j = \"04\" + r + p;this.setPrivateKeyHex(m);this.setPublicKeyHex(j);return { ecprvhex: m, ecpubhex: j };\n  };this.signWithMessageHash = function (i) {\n    return this.signHex(i, this.prvKeyHex);\n  };this.signHex = function (o, j) {\n    var t = new BigInteger(j, 16);var l = this.ecparams.n;var q = new BigInteger(o, 16);do {\n      var m = this.getBigRandom(l);var u = this.ecparams.G;var p = u.multiply(m);var i = p.getX().toBigInteger().mod(l);\n    } while (i.compareTo(BigInteger.ZERO) <= 0);var v = m.modInverse(l).multiply(q.add(t.multiply(i))).mod(l);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(i, v);\n  };this.sign = function (m, u) {\n    var q = u;var j = this.ecparams.n;var p = BigInteger.fromByteArrayUnsigned(m);do {\n      var l = this.getBigRandom(j);var t = this.ecparams.G;var o = t.multiply(l);var i = o.getX().toBigInteger().mod(j);\n    } while (i.compareTo(BigInteger.ZERO) <= 0);var v = l.modInverse(j).multiply(p.add(q.multiply(i))).mod(j);return this.serializeSig(i, v);\n  };this.verifyWithMessageHash = function (j, i) {\n    return this.verifyHex(j, i, this.pubKeyHex);\n  };this.verifyHex = function (m, i, p) {\n    var l, j;var o = KJUR.crypto.ECDSA.parseSigHex(i);l = o.r;j = o.s;var k;k = ECPointFp.decodeFromHex(this.ecparams.curve, p);var n = new BigInteger(m, 16);return this.verifyRaw(n, l, j, k);\n  };this.verify = function (o, p, j) {\n    var l, i;if (Bitcoin.Util.isArray(p)) {\n      var n = this.parseSig(p);l = n.r;i = n.s;\n    } else {\n      if (\"object\" === (typeof p === \"undefined\" ? \"undefined\" : _typeof(p)) && p.r && p.s) {\n        l = p.r;i = p.s;\n      } else {\n        throw \"Invalid value for signature\";\n      }\n    }var k;if (j instanceof ECPointFp) {\n      k = j;\n    } else {\n      if (Bitcoin.Util.isArray(j)) {\n        k = ECPointFp.decodeFrom(this.ecparams.curve, j);\n      } else {\n        throw \"Invalid format for pubkey value, must be byte array or ECPointFp\";\n      }\n    }var m = BigInteger.fromByteArrayUnsigned(o);return this.verifyRaw(m, l, i, k);\n  };this.verifyRaw = function (o, i, w, m) {\n    var l = this.ecparams.n;var u = this.ecparams.G;if (i.compareTo(BigInteger.ONE) < 0 || i.compareTo(l) >= 0) {\n      return false;\n    }if (w.compareTo(BigInteger.ONE) < 0 || w.compareTo(l) >= 0) {\n      return false;\n    }var p = w.modInverse(l);var k = o.multiply(p).mod(l);var j = i.multiply(p).mod(l);var q = u.multiply(k).add(m.multiply(j));var t = q.getX().toBigInteger().mod(l);return t.equals(i);\n  };this.serializeSig = function (k, j) {\n    var l = k.toByteArraySigned();var i = j.toByteArraySigned();var m = [];m.push(2);m.push(l.length);m = m.concat(l);m.push(2);m.push(i.length);m = m.concat(i);m.unshift(m.length);m.unshift(48);return m;\n  };this.parseSig = function (n) {\n    var m;if (n[0] != 48) {\n      throw new Error(\"Signature not a valid DERSequence\");\n    }m = 2;if (n[m] != 2) {\n      throw new Error(\"First element in signature must be a DERInteger\");\n    }var l = n.slice(m + 2, m + 2 + n[m + 1]);m += 2 + n[m + 1];if (n[m] != 2) {\n      throw new Error(\"Second element in signature must be a DERInteger\");\n    }var i = n.slice(m + 2, m + 2 + n[m + 1]);m += 2 + n[m + 1];var k = BigInteger.fromByteArrayUnsigned(l);var j = BigInteger.fromByteArrayUnsigned(i);return { r: k, s: j };\n  };this.parseSigCompact = function (m) {\n    if (m.length !== 65) {\n      throw \"Signature has the wrong length\";\n    }var j = m[0] - 27;if (j < 0 || j > 7) {\n      throw \"Invalid signature type\";\n    }var o = this.ecparams.n;var l = BigInteger.fromByteArrayUnsigned(m.slice(1, 33)).mod(o);var k = BigInteger.fromByteArrayUnsigned(m.slice(33, 65)).mod(o);return { r: l, s: k, i: j };\n  };this.readPKCS5PrvKeyHex = function (l) {\n    var n = ASN1HEX;var m = KJUR.crypto.ECDSA.getName;var p = n.getVbyList;if (n.isASN1HEX(l) === false) {\n      throw \"not ASN.1 hex string\";\n    }var i, k, o;try {\n      i = p(l, 0, [2, 0], \"06\");k = p(l, 0, [1], \"04\");try {\n        o = p(l, 0, [3, 0], \"03\").substr(2);\n      } catch (j) {}\n    } catch (j) {\n      throw \"malformed PKCS#1/5 plain ECC private key\";\n    }this.curveName = m(i);if (this.curveName === undefined) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(o);this.setPrivateKeyHex(k);this.isPublic = false;\n  };this.readPKCS8PrvKeyHex = function (l) {\n    var q = ASN1HEX;var i = KJUR.crypto.ECDSA.getName;var n = q.getVbyList;if (q.isASN1HEX(l) === false) {\n      throw \"not ASN.1 hex string\";\n    }var j, p, m, k;try {\n      j = n(l, 0, [1, 0], \"06\");p = n(l, 0, [1, 1], \"06\");m = n(l, 0, [2, 0, 1], \"04\");try {\n        k = n(l, 0, [2, 0, 2, 0], \"03\").substr(2);\n      } catch (o) {}\n    } catch (o) {\n      throw \"malformed PKCS#8 plain ECC private key\";\n    }this.curveName = i(p);if (this.curveName === undefined) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(k);this.setPrivateKeyHex(m);this.isPublic = false;\n  };this.readPKCS8PubKeyHex = function (l) {\n    var n = ASN1HEX;var m = KJUR.crypto.ECDSA.getName;var p = n.getVbyList;if (n.isASN1HEX(l) === false) {\n      throw \"not ASN.1 hex string\";\n    }var k, i, o;try {\n      k = p(l, 0, [0, 0], \"06\");i = p(l, 0, [0, 1], \"06\");o = p(l, 0, [1], \"03\").substr(2);\n    } catch (j) {\n      throw \"malformed PKCS#8 ECC public key\";\n    }this.curveName = m(i);if (this.curveName === null) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(o);\n  };this.readCertPubKeyHex = function (k, p) {\n    if (p !== 5) {\n      p = 6;\n    }var m = ASN1HEX;var l = KJUR.crypto.ECDSA.getName;var o = m.getVbyList;if (m.isASN1HEX(k) === false) {\n      throw \"not ASN.1 hex string\";\n    }var i, n;try {\n      i = o(k, 0, [0, p, 0, 1], \"06\");n = o(k, 0, [0, p, 1], \"03\").substr(2);\n    } catch (j) {\n      throw \"malformed X.509 certificate ECC public key\";\n    }this.curveName = l(i);if (this.curveName === null) {\n      throw \"unsupported curve name\";\n    }this.setNamedCurve(this.curveName);this.setPublicKeyHex(n);\n  };if (h !== undefined) {\n    if (h.curve !== undefined) {\n      this.curveName = h.curve;\n    }\n  }if (this.curveName === undefined) {\n    this.curveName = e;\n  }this.setNamedCurve(this.curveName);if (h !== undefined) {\n    if (h.prv !== undefined) {\n      this.setPrivateKeyHex(h.prv);\n    }if (h.pub !== undefined) {\n      this.setPublicKeyHex(h.pub);\n    }\n  }\n};KJUR.crypto.ECDSA.parseSigHex = function (a) {\n  var b = KJUR.crypto.ECDSA.parseSigHexInHexRS(a);var d = new BigInteger(b.r, 16);var c = new BigInteger(b.s, 16);return { r: d, s: c };\n};KJUR.crypto.ECDSA.parseSigHexInHexRS = function (f) {\n  var j = ASN1HEX;var i = j.getChildIdx;var g = j.getV;if (f.substr(0, 2) != \"30\") {\n    throw \"signature is not a ASN.1 sequence\";\n  }var h = i(f, 0);if (h.length != 2) {\n    throw \"number of signature ASN.1 sequence elements seem wrong\";\n  }var e = h[0];var d = h[1];if (f.substr(e, 2) != \"02\") {\n    throw \"1st item of sequene of signature is not ASN.1 integer\";\n  }if (f.substr(d, 2) != \"02\") {\n    throw \"2nd item of sequene of signature is not ASN.1 integer\";\n  }var c = g(f, e);var b = g(f, d);return { r: c, s: b };\n};KJUR.crypto.ECDSA.asn1SigToConcatSig = function (c) {\n  var d = KJUR.crypto.ECDSA.parseSigHexInHexRS(c);var b = d.r;var a = d.s;if (b.substr(0, 2) == \"00\" && b.length % 32 == 2) {\n    b = b.substr(2);\n  }if (a.substr(0, 2) == \"00\" && a.length % 32 == 2) {\n    a = a.substr(2);\n  }if (b.length % 32 == 30) {\n    b = \"00\" + b;\n  }if (a.length % 32 == 30) {\n    a = \"00\" + a;\n  }if (b.length % 32 != 0) {\n    throw \"unknown ECDSA sig r length error\";\n  }if (a.length % 32 != 0) {\n    throw \"unknown ECDSA sig s length error\";\n  }return b + a;\n};KJUR.crypto.ECDSA.concatSigToASN1Sig = function (a) {\n  if (a.length / 2 * 8 % (16 * 8) != 0) {\n    throw \"unknown ECDSA concatinated r-s sig  length error\";\n  }var c = a.substr(0, a.length / 2);var b = a.substr(a.length / 2);return KJUR.crypto.ECDSA.hexRSSigToASN1Sig(c, b);\n};KJUR.crypto.ECDSA.hexRSSigToASN1Sig = function (b, a) {\n  var d = new BigInteger(b, 16);var c = new BigInteger(a, 16);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(d, c);\n};KJUR.crypto.ECDSA.biRSSigToASN1Sig = function (f, d) {\n  var c = KJUR.asn1;var b = new c.DERInteger({ bigint: f });var a = new c.DERInteger({ bigint: d });var e = new c.DERSequence({ array: [b, a] });return e.getEncodedHex();\n};KJUR.crypto.ECDSA.getName = function (a) {\n  if (a === \"2a8648ce3d030107\") {\n    return \"secp256r1\";\n  }if (a === \"2b8104000a\") {\n    return \"secp256k1\";\n  }if (a === \"2b81040022\") {\n    return \"secp384r1\";\n  }if (\"|secp256r1|NIST P-256|P-256|prime256v1|\".indexOf(a) !== -1) {\n    return \"secp256r1\";\n  }if (\"|secp256k1|\".indexOf(a) !== -1) {\n    return \"secp256k1\";\n  }if (\"|secp384r1|NIST P-384|P-384|\".indexOf(a) !== -1) {\n    return \"secp384r1\";\n  }return null;\n};\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.crypto == \"undefined\" || !KJUR.crypto) {\n  KJUR.crypto = {};\n}KJUR.crypto.ECParameterDB = new function () {\n  var b = {};var c = {};function a(d) {\n    return new BigInteger(d, 16);\n  }this.getByName = function (e) {\n    var d = e;if (typeof c[d] != \"undefined\") {\n      d = c[e];\n    }if (typeof b[d] != \"undefined\") {\n      return b[d];\n    }throw \"unregistered EC curve name: \" + d;\n  };this.regist = function (A, l, o, g, m, e, j, f, k, u, d, x) {\n    b[A] = {};var s = a(o);var z = a(g);var y = a(m);var t = a(e);var w = a(j);var r = new ECCurveFp(s, z, y);var q = r.decodePointHex(\"04\" + f + k);b[A][\"name\"] = A;b[A][\"keylen\"] = l;b[A][\"curve\"] = r;b[A][\"G\"] = q;b[A][\"n\"] = t;b[A][\"h\"] = w;b[A][\"oid\"] = d;b[A][\"info\"] = x;for (var v = 0; v < u.length; v++) {\n      c[u[v]] = A;\n    }\n  };\n}();KJUR.crypto.ECParameterDB.regist(\"secp128r1\", 128, \"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF\", \"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFC\", \"E87579C11079F43DD824993C2CEE5ED3\", \"FFFFFFFE0000000075A30D1B9038A115\", \"1\", \"161FF7528B899B2D0C28607CA52C5B86\", \"CF5AC8395BAFEB13C02DA292DDED7A83\", [], \"\", \"secp128r1 : SECG curve over a 128 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160k1\", 160, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73\", \"0\", \"7\", \"0100000000000000000001B8FA16DFAB9ACA16B6B3\", \"1\", \"3B4C382CE37AA192A4019E763036F4F5DD4D7EBB\", \"938CF935318FDCED6BC28286531733C3F03C4FEE\", [], \"\", \"secp160k1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160r1\", 160, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFC\", \"1C97BEFC54BD7A8B65ACF89F81D4D4ADC565FA45\", \"0100000000000000000001F4C8F927AED3CA752257\", \"1\", \"4A96B5688EF573284664698968C38BB913CBFC82\", \"23A628553168947D59DCC912042351377AC5FB32\", [], \"\", \"secp160r1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp192k1\", 192, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFEE37\", \"0\", \"3\", \"FFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D\", \"1\", \"DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D\", \"9B2F2F6D9C5628A7844163D015BE86344082AA88D95E2F9D\", []);KJUR.crypto.ECParameterDB.regist(\"secp192r1\", 192, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC\", \"64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1\", \"FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831\", \"1\", \"188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012\", \"07192B95FFC8DA78631011ED6B24CDD573F977A11E794811\", []);KJUR.crypto.ECParameterDB.regist(\"secp224r1\", 224, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE\", \"B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D\", \"1\", \"B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21\", \"BD376388B5F723FB4C22DFE6CD4375A05A07476444D5819985007E34\", []);KJUR.crypto.ECParameterDB.regist(\"secp256k1\", 256, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F\", \"0\", \"7\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141\", \"1\", \"79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798\", \"483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8\", []);KJUR.crypto.ECParameterDB.regist(\"secp256r1\", 256, \"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF\", \"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFC\", \"5AC635D8AA3A93E7B3EBBD55769886BC651D06B0CC53B0F63BCE3C3E27D2604B\", \"FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551\", \"1\", \"6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296\", \"4FE342E2FE1A7F9B8EE7EB4A7C0F9E162BCE33576B315ECECBB6406837BF51F5\", [\"NIST P-256\", \"P-256\", \"prime256v1\"]);KJUR.crypto.ECParameterDB.regist(\"secp384r1\", 384, \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFC\", \"B3312FA7E23EE7E4988E056BE3F82D19181D9C6EFE8141120314088F5013875AC656398D8A2ED19D2A85C8EDD3EC2AEF\", \"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973\", \"1\", \"AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7\", \"3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5f\", [\"NIST P-384\", \"P-384\"]);KJUR.crypto.ECParameterDB.regist(\"secp521r1\", 521, \"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF\", \"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC\", \"051953EB9618E1C9A1F929A21A0B68540EEA2DA725B99B315F3B8B489918EF109E156193951EC7E937B1652C0BD3BB1BF073573DF883D2C34F1EF451FD46B503F00\", \"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA51868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409\", \"1\", \"C6858E06B70404E9CD9E3ECB662395B4429C648139053FB521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66\", \"011839296a789a3bc0045c8a5fb42c7d1bd998f54449579b446817afbd17273e662c97ee72995ef42640c550b9013fad0761353c7086a272c24088be94769fd16650\", [\"NIST P-521\", \"P-521\"]);\nvar KEYUTIL = function () {\n  var d = function d(p, r, q) {\n    return k(CryptoJS.AES, p, r, q);\n  };var e = function e(p, r, q) {\n    return k(CryptoJS.TripleDES, p, r, q);\n  };var a = function a(p, r, q) {\n    return k(CryptoJS.DES, p, r, q);\n  };var k = function k(s, x, u, q) {\n    var r = CryptoJS.enc.Hex.parse(x);var w = CryptoJS.enc.Hex.parse(u);var p = CryptoJS.enc.Hex.parse(q);var t = {};t.key = w;t.iv = p;t.ciphertext = r;var v = s.decrypt(t, w, { iv: p });return CryptoJS.enc.Hex.stringify(v);\n  };var l = function l(p, r, q) {\n    return g(CryptoJS.AES, p, r, q);\n  };var o = function o(p, r, q) {\n    return g(CryptoJS.TripleDES, p, r, q);\n  };var f = function f(p, r, q) {\n    return g(CryptoJS.DES, p, r, q);\n  };var g = function g(t, y, v, q) {\n    var s = CryptoJS.enc.Hex.parse(y);var x = CryptoJS.enc.Hex.parse(v);var p = CryptoJS.enc.Hex.parse(q);var w = t.encrypt(s, x, { iv: p });var r = CryptoJS.enc.Hex.parse(w.toString());var u = CryptoJS.enc.Base64.stringify(r);return u;\n  };var i = { \"AES-256-CBC\": { proc: d, eproc: l, keylen: 32, ivlen: 16 }, \"AES-192-CBC\": { proc: d, eproc: l, keylen: 24, ivlen: 16 }, \"AES-128-CBC\": { proc: d, eproc: l, keylen: 16, ivlen: 16 }, \"DES-EDE3-CBC\": { proc: e, eproc: o, keylen: 24, ivlen: 8 }, \"DES-CBC\": { proc: a, eproc: f, keylen: 8, ivlen: 8 } };var c = function c(p) {\n    return i[p][\"proc\"];\n  };var m = function m(p) {\n    var r = CryptoJS.lib.WordArray.random(p);var q = CryptoJS.enc.Hex.stringify(r);return q;\n  };var n = function n(v) {\n    var w = {};var q = v.match(new RegExp(\"DEK-Info: ([^,]+),([0-9A-Fa-f]+)\", \"m\"));if (q) {\n      w.cipher = q[1];w.ivsalt = q[2];\n    }var p = v.match(new RegExp(\"-----BEGIN ([A-Z]+) PRIVATE KEY-----\"));if (p) {\n      w.type = p[1];\n    }var u = -1;var x = 0;if (v.indexOf(\"\\r\\n\\r\\n\") != -1) {\n      u = v.indexOf(\"\\r\\n\\r\\n\");x = 2;\n    }if (v.indexOf(\"\\n\\n\") != -1) {\n      u = v.indexOf(\"\\n\\n\");x = 1;\n    }var t = v.indexOf(\"-----END\");if (u != -1 && t != -1) {\n      var r = v.substring(u + x * 2, t - x);r = r.replace(/\\s+/g, \"\");w.data = r;\n    }return w;\n  };var j = function j(q, y, p) {\n    var v = p.substring(0, 16);var t = CryptoJS.enc.Hex.parse(v);var r = CryptoJS.enc.Utf8.parse(y);var u = i[q][\"keylen\"] + i[q][\"ivlen\"];var x = \"\";var w = null;for (;;) {\n      var s = CryptoJS.algo.MD5.create();if (w != null) {\n        s.update(w);\n      }s.update(r);s.update(t);w = s.finalize();x = x + CryptoJS.enc.Hex.stringify(w);if (x.length >= u * 2) {\n        break;\n      }\n    }var z = {};z.keyhex = x.substr(0, i[q][\"keylen\"] * 2);z.ivhex = x.substr(i[q][\"keylen\"] * 2, i[q][\"ivlen\"] * 2);return z;\n  };var b = function b(p, v, r, w) {\n    var s = CryptoJS.enc.Base64.parse(p);var q = CryptoJS.enc.Hex.stringify(s);var u = i[v][\"proc\"];var t = u(q, r, w);return t;\n  };var h = function h(p, s, q, u) {\n    var r = i[s][\"eproc\"];var t = r(p, q, u);return t;\n  };return { version: \"1.0.0\", parsePKCS5PEM: function parsePKCS5PEM(p) {\n      return n(p);\n    }, getKeyAndUnusedIvByPasscodeAndIvsalt: function getKeyAndUnusedIvByPasscodeAndIvsalt(q, p, r) {\n      return j(q, p, r);\n    }, decryptKeyB64: function decryptKeyB64(p, r, q, s) {\n      return b(p, r, q, s);\n    }, getDecryptedKeyHex: function getDecryptedKeyHex(y, x) {\n      var q = n(y);var t = q.type;var r = q.cipher;var p = q.ivsalt;var s = q.data;var w = j(r, x, p);var v = w.keyhex;var u = b(s, r, v, p);return u;\n    }, getEncryptedPKCS5PEMFromPrvKeyHex: function getEncryptedPKCS5PEMFromPrvKeyHex(x, s, A, t, r) {\n      var p = \"\";if (typeof t == \"undefined\" || t == null) {\n        t = \"AES-256-CBC\";\n      }if (typeof i[t] == \"undefined\") {\n        throw \"KEYUTIL unsupported algorithm: \" + t;\n      }if (typeof r == \"undefined\" || r == null) {\n        var v = i[t][\"ivlen\"];var u = m(v);r = u.toUpperCase();\n      }var z = j(t, A, r);var y = z.keyhex;var w = h(s, t, y, r);var q = w.replace(/(.{64})/g, \"$1\\r\\n\");var p = \"-----BEGIN \" + x + \" PRIVATE KEY-----\\r\\n\";p += \"Proc-Type: 4,ENCRYPTED\\r\\n\";p += \"DEK-Info: \" + t + \",\" + r + \"\\r\\n\";p += \"\\r\\n\";p += q;p += \"\\r\\n-----END \" + x + \" PRIVATE KEY-----\\r\\n\";return p;\n    }, parseHexOfEncryptedPKCS8: function parseHexOfEncryptedPKCS8(y) {\n      var B = ASN1HEX;var z = B.getChildIdx;var w = B.getV;var t = {};var r = z(y, 0);if (r.length != 2) {\n        throw \"malformed format: SEQUENCE(0).items != 2: \" + r.length;\n      }t.ciphertext = w(y, r[1]);var A = z(y, r[0]);if (A.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0).items != 2: \" + A.length;\n      }if (w(y, A[0]) != \"2a864886f70d01050d\") {\n        throw \"this only supports pkcs5PBES2\";\n      }var p = z(y, A[1]);if (A.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0.1).items != 2: \" + p.length;\n      }var q = z(y, p[1]);if (q.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0.1.1).items != 2: \" + q.length;\n      }if (w(y, q[0]) != \"2a864886f70d0307\") {\n        throw \"this only supports TripleDES\";\n      }t.encryptionSchemeAlg = \"TripleDES\";t.encryptionSchemeIV = w(y, q[1]);var s = z(y, p[0]);if (s.length != 2) {\n        throw \"malformed format: SEQUENCE(0.0.1.0).items != 2: \" + s.length;\n      }if (w(y, s[0]) != \"2a864886f70d01050c\") {\n        throw \"this only supports pkcs5PBKDF2\";\n      }var x = z(y, s[1]);if (x.length < 2) {\n        throw \"malformed format: SEQUENCE(0.0.1.0.1).items < 2: \" + x.length;\n      }t.pbkdf2Salt = w(y, x[0]);var u = w(y, x[1]);try {\n        t.pbkdf2Iter = parseInt(u, 16);\n      } catch (v) {\n        throw \"malformed format pbkdf2Iter: \" + u;\n      }return t;\n    }, getPBKDF2KeyHexFromParam: function getPBKDF2KeyHexFromParam(u, p) {\n      var t = CryptoJS.enc.Hex.parse(u.pbkdf2Salt);var q = u.pbkdf2Iter;var s = CryptoJS.PBKDF2(p, t, { keySize: 192 / 32, iterations: q });var r = CryptoJS.enc.Hex.stringify(s);return r;\n    }, _getPlainPKCS8HexFromEncryptedPKCS8PEM: function _getPlainPKCS8HexFromEncryptedPKCS8PEM(x, y) {\n      var r = pemtohex(x, \"ENCRYPTED PRIVATE KEY\");var p = this.parseHexOfEncryptedPKCS8(r);var u = KEYUTIL.getPBKDF2KeyHexFromParam(p, y);var v = {};v.ciphertext = CryptoJS.enc.Hex.parse(p.ciphertext);var t = CryptoJS.enc.Hex.parse(u);var s = CryptoJS.enc.Hex.parse(p.encryptionSchemeIV);var w = CryptoJS.TripleDES.decrypt(v, t, { iv: s });var q = CryptoJS.enc.Hex.stringify(w);return q;\n    }, getKeyFromEncryptedPKCS8PEM: function getKeyFromEncryptedPKCS8PEM(s, q) {\n      var p = this._getPlainPKCS8HexFromEncryptedPKCS8PEM(s, q);var r = this.getKeyFromPlainPrivatePKCS8Hex(p);return r;\n    }, parsePlainPrivatePKCS8Hex: function parsePlainPrivatePKCS8Hex(s) {\n      var v = ASN1HEX;var u = v.getChildIdx;var t = v.getV;var q = {};q.algparam = null;if (s.substr(0, 2) != \"30\") {\n        throw \"malformed plain PKCS8 private key(code:001)\";\n      }var r = u(s, 0);if (r.length != 3) {\n        throw \"malformed plain PKCS8 private key(code:002)\";\n      }if (s.substr(r[1], 2) != \"30\") {\n        throw \"malformed PKCS8 private key(code:003)\";\n      }var p = u(s, r[1]);if (p.length != 2) {\n        throw \"malformed PKCS8 private key(code:004)\";\n      }if (s.substr(p[0], 2) != \"06\") {\n        throw \"malformed PKCS8 private key(code:005)\";\n      }q.algoid = t(s, p[0]);if (s.substr(p[1], 2) == \"06\") {\n        q.algparam = t(s, p[1]);\n      }if (s.substr(r[2], 2) != \"04\") {\n        throw \"malformed PKCS8 private key(code:006)\";\n      }q.keyidx = v.getVidx(s, r[2]);return q;\n    }, getKeyFromPlainPrivatePKCS8PEM: function getKeyFromPlainPrivatePKCS8PEM(q) {\n      var p = pemtohex(q, \"PRIVATE KEY\");var r = this.getKeyFromPlainPrivatePKCS8Hex(p);return r;\n    }, getKeyFromPlainPrivatePKCS8Hex: function getKeyFromPlainPrivatePKCS8Hex(p) {\n      var q = this.parsePlainPrivatePKCS8Hex(p);var r;if (q.algoid == \"2a864886f70d010101\") {\n        r = new RSAKey();\n      } else {\n        if (q.algoid == \"2a8648ce380401\") {\n          r = new KJUR.crypto.DSA();\n        } else {\n          if (q.algoid == \"2a8648ce3d0201\") {\n            r = new KJUR.crypto.ECDSA();\n          } else {\n            throw \"unsupported private key algorithm\";\n          }\n        }\n      }r.readPKCS8PrvKeyHex(p);return r;\n    }, _getKeyFromPublicPKCS8Hex: function _getKeyFromPublicPKCS8Hex(q) {\n      var p;var r = ASN1HEX.getVbyList(q, 0, [0, 0], \"06\");if (r === \"2a864886f70d010101\") {\n        p = new RSAKey();\n      } else {\n        if (r === \"2a8648ce380401\") {\n          p = new KJUR.crypto.DSA();\n        } else {\n          if (r === \"2a8648ce3d0201\") {\n            p = new KJUR.crypto.ECDSA();\n          } else {\n            throw \"unsupported PKCS#8 public key hex\";\n          }\n        }\n      }p.readPKCS8PubKeyHex(q);return p;\n    }, parsePublicRawRSAKeyHex: function parsePublicRawRSAKeyHex(r) {\n      var u = ASN1HEX;var t = u.getChildIdx;var s = u.getV;var p = {};if (r.substr(0, 2) != \"30\") {\n        throw \"malformed RSA key(code:001)\";\n      }var q = t(r, 0);if (q.length != 2) {\n        throw \"malformed RSA key(code:002)\";\n      }if (r.substr(q[0], 2) != \"02\") {\n        throw \"malformed RSA key(code:003)\";\n      }p.n = s(r, q[0]);if (r.substr(q[1], 2) != \"02\") {\n        throw \"malformed RSA key(code:004)\";\n      }p.e = s(r, q[1]);return p;\n    }, parsePublicPKCS8Hex: function parsePublicPKCS8Hex(t) {\n      var v = ASN1HEX;var u = v.getChildIdx;var s = v.getV;var q = {};q.algparam = null;var r = u(t, 0);if (r.length != 2) {\n        throw \"outer DERSequence shall have 2 elements: \" + r.length;\n      }var w = r[0];if (t.substr(w, 2) != \"30\") {\n        throw \"malformed PKCS8 public key(code:001)\";\n      }var p = u(t, w);if (p.length != 2) {\n        throw \"malformed PKCS8 public key(code:002)\";\n      }if (t.substr(p[0], 2) != \"06\") {\n        throw \"malformed PKCS8 public key(code:003)\";\n      }q.algoid = s(t, p[0]);if (t.substr(p[1], 2) == \"06\") {\n        q.algparam = s(t, p[1]);\n      } else {\n        if (t.substr(p[1], 2) == \"30\") {\n          q.algparam = {};q.algparam.p = v.getVbyList(t, p[1], [0], \"02\");q.algparam.q = v.getVbyList(t, p[1], [1], \"02\");q.algparam.g = v.getVbyList(t, p[1], [2], \"02\");\n        }\n      }if (t.substr(r[1], 2) != \"03\") {\n        throw \"malformed PKCS8 public key(code:004)\";\n      }q.key = s(t, r[1]).substr(2);return q;\n    } };\n}();KEYUTIL.getKey = function (l, k, n) {\n  var G = ASN1HEX,\n      L = G.getChildIdx,\n      v = G.getV,\n      d = G.getVbyList,\n      c = KJUR.crypto,\n      i = c.ECDSA,\n      C = c.DSA,\n      w = RSAKey,\n      M = pemtohex,\n      F = KEYUTIL;if (typeof w != \"undefined\" && l instanceof w) {\n    return l;\n  }if (typeof i != \"undefined\" && l instanceof i) {\n    return l;\n  }if (typeof C != \"undefined\" && l instanceof C) {\n    return l;\n  }if (l.curve !== undefined && l.xy !== undefined && l.d === undefined) {\n    return new i({ pub: l.xy, curve: l.curve });\n  }if (l.curve !== undefined && l.d !== undefined) {\n    return new i({ prv: l.d, curve: l.curve });\n  }if (l.kty === undefined && l.n !== undefined && l.e !== undefined && l.d === undefined) {\n    var P = new w();P.setPublic(l.n, l.e);return P;\n  }if (l.kty === undefined && l.n !== undefined && l.e !== undefined && l.d !== undefined && l.p !== undefined && l.q !== undefined && l.dp !== undefined && l.dq !== undefined && l.co !== undefined && l.qi === undefined) {\n    var P = new w();P.setPrivateEx(l.n, l.e, l.d, l.p, l.q, l.dp, l.dq, l.co);return P;\n  }if (l.kty === undefined && l.n !== undefined && l.e !== undefined && l.d !== undefined && l.p === undefined) {\n    var P = new w();P.setPrivate(l.n, l.e, l.d);return P;\n  }if (l.p !== undefined && l.q !== undefined && l.g !== undefined && l.y !== undefined && l.x === undefined) {\n    var P = new C();P.setPublic(l.p, l.q, l.g, l.y);return P;\n  }if (l.p !== undefined && l.q !== undefined && l.g !== undefined && l.y !== undefined && l.x !== undefined) {\n    var P = new C();P.setPrivate(l.p, l.q, l.g, l.y, l.x);return P;\n  }if (l.kty === \"RSA\" && l.n !== undefined && l.e !== undefined && l.d === undefined) {\n    var P = new w();P.setPublic(b64utohex(l.n), b64utohex(l.e));return P;\n  }if (l.kty === \"RSA\" && l.n !== undefined && l.e !== undefined && l.d !== undefined && l.p !== undefined && l.q !== undefined && l.dp !== undefined && l.dq !== undefined && l.qi !== undefined) {\n    var P = new w();P.setPrivateEx(b64utohex(l.n), b64utohex(l.e), b64utohex(l.d), b64utohex(l.p), b64utohex(l.q), b64utohex(l.dp), b64utohex(l.dq), b64utohex(l.qi));return P;\n  }if (l.kty === \"RSA\" && l.n !== undefined && l.e !== undefined && l.d !== undefined) {\n    var P = new w();P.setPrivate(b64utohex(l.n), b64utohex(l.e), b64utohex(l.d));return P;\n  }if (l.kty === \"EC\" && l.crv !== undefined && l.x !== undefined && l.y !== undefined && l.d === undefined) {\n    var j = new i({ curve: l.crv });var t = j.ecparams.keylen / 4;var B = (\"0000000000\" + b64utohex(l.x)).slice(-t);var z = (\"0000000000\" + b64utohex(l.y)).slice(-t);var u = \"04\" + B + z;j.setPublicKeyHex(u);return j;\n  }if (l.kty === \"EC\" && l.crv !== undefined && l.x !== undefined && l.y !== undefined && l.d !== undefined) {\n    var j = new i({ curve: l.crv });var t = j.ecparams.keylen / 4;var B = (\"0000000000\" + b64utohex(l.x)).slice(-t);var z = (\"0000000000\" + b64utohex(l.y)).slice(-t);var u = \"04\" + B + z;var b = (\"0000000000\" + b64utohex(l.d)).slice(-t);j.setPublicKeyHex(u);j.setPrivateKeyHex(b);return j;\n  }if (n === \"pkcs5prv\") {\n    var J = l,\n        G = ASN1HEX,\n        N,\n        P;N = L(J, 0);if (N.length === 9) {\n      P = new w();P.readPKCS5PrvKeyHex(J);\n    } else {\n      if (N.length === 6) {\n        P = new C();P.readPKCS5PrvKeyHex(J);\n      } else {\n        if (N.length > 2 && J.substr(N[1], 2) === \"04\") {\n          P = new i();P.readPKCS5PrvKeyHex(J);\n        } else {\n          throw \"unsupported PKCS#1/5 hexadecimal key\";\n        }\n      }\n    }return P;\n  }if (n === \"pkcs8prv\") {\n    var P = F.getKeyFromPlainPrivatePKCS8Hex(l);return P;\n  }if (n === \"pkcs8pub\") {\n    return F._getKeyFromPublicPKCS8Hex(l);\n  }if (n === \"x509pub\") {\n    return X509.getPublicKeyFromCertHex(l);\n  }if (l.indexOf(\"-END CERTIFICATE-\", 0) != -1 || l.indexOf(\"-END X509 CERTIFICATE-\", 0) != -1 || l.indexOf(\"-END TRUSTED CERTIFICATE-\", 0) != -1) {\n    return X509.getPublicKeyFromCertPEM(l);\n  }if (l.indexOf(\"-END PUBLIC KEY-\") != -1) {\n    var O = pemtohex(l, \"PUBLIC KEY\");return F._getKeyFromPublicPKCS8Hex(O);\n  }if (l.indexOf(\"-END RSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") == -1) {\n    var m = M(l, \"RSA PRIVATE KEY\");return F.getKey(m, null, \"pkcs5prv\");\n  }if (l.indexOf(\"-END DSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") == -1) {\n    var I = M(l, \"DSA PRIVATE KEY\");var E = d(I, 0, [1], \"02\");var D = d(I, 0, [2], \"02\");var K = d(I, 0, [3], \"02\");var r = d(I, 0, [4], \"02\");var s = d(I, 0, [5], \"02\");var P = new C();P.setPrivate(new BigInteger(E, 16), new BigInteger(D, 16), new BigInteger(K, 16), new BigInteger(r, 16), new BigInteger(s, 16));return P;\n  }if (l.indexOf(\"-END PRIVATE KEY-\") != -1) {\n    return F.getKeyFromPlainPrivatePKCS8PEM(l);\n  }if (l.indexOf(\"-END RSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") != -1) {\n    var o = F.getDecryptedKeyHex(l, k);var H = new RSAKey();H.readPKCS5PrvKeyHex(o);return H;\n  }if (l.indexOf(\"-END EC PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") != -1) {\n    var I = F.getDecryptedKeyHex(l, k);var P = d(I, 0, [1], \"04\");var f = d(I, 0, [2, 0], \"06\");var A = d(I, 0, [3, 0], \"03\").substr(2);var e = \"\";if (KJUR.crypto.OID.oidhex2name[f] !== undefined) {\n      e = KJUR.crypto.OID.oidhex2name[f];\n    } else {\n      throw \"undefined OID(hex) in KJUR.crypto.OID: \" + f;\n    }var j = new i({ curve: e });j.setPublicKeyHex(A);j.setPrivateKeyHex(P);j.isPublic = false;return j;\n  }if (l.indexOf(\"-END DSA PRIVATE KEY-\") != -1 && l.indexOf(\"4,ENCRYPTED\") != -1) {\n    var I = F.getDecryptedKeyHex(l, k);var E = d(I, 0, [1], \"02\");var D = d(I, 0, [2], \"02\");var K = d(I, 0, [3], \"02\");var r = d(I, 0, [4], \"02\");var s = d(I, 0, [5], \"02\");var P = new C();P.setPrivate(new BigInteger(E, 16), new BigInteger(D, 16), new BigInteger(K, 16), new BigInteger(r, 16), new BigInteger(s, 16));return P;\n  }if (l.indexOf(\"-END ENCRYPTED PRIVATE KEY-\") != -1) {\n    return F.getKeyFromEncryptedPKCS8PEM(l, k);\n  }throw \"not supported argument\";\n};KEYUTIL.generateKeypair = function (a, c) {\n  if (a == \"RSA\") {\n    var b = c;var h = new RSAKey();h.generate(b, \"10001\");h.isPrivate = true;h.isPublic = true;var f = new RSAKey();var e = h.n.toString(16);var i = h.e.toString(16);f.setPublic(e, i);f.isPrivate = false;f.isPublic = true;var k = {};k.prvKeyObj = h;k.pubKeyObj = f;return k;\n  } else {\n    if (a == \"EC\") {\n      var d = c;var g = new KJUR.crypto.ECDSA({ curve: d });var j = g.generateKeyPairHex();var h = new KJUR.crypto.ECDSA({ curve: d });h.setPublicKeyHex(j.ecpubhex);h.setPrivateKeyHex(j.ecprvhex);h.isPrivate = true;h.isPublic = false;var f = new KJUR.crypto.ECDSA({ curve: d });f.setPublicKeyHex(j.ecpubhex);f.isPrivate = false;f.isPublic = true;var k = {};k.prvKeyObj = h;k.pubKeyObj = f;return k;\n    } else {\n      throw \"unknown algorithm: \" + a;\n    }\n  }\n};KEYUTIL.getPEM = function (b, D, y, m, q, j) {\n  var F = KJUR,\n      k = F.asn1,\n      z = k.DERObjectIdentifier,\n      f = k.DERInteger,\n      l = k.ASN1Util.newObject,\n      a = k.x509,\n      C = a.SubjectPublicKeyInfo,\n      e = F.crypto,\n      u = e.DSA,\n      r = e.ECDSA,\n      n = RSAKey;function A(s) {\n    var G = l({ seq: [{ \"int\": 0 }, { \"int\": { bigint: s.n } }, { \"int\": s.e }, { \"int\": { bigint: s.d } }, { \"int\": { bigint: s.p } }, { \"int\": { bigint: s.q } }, { \"int\": { bigint: s.dmp1 } }, { \"int\": { bigint: s.dmq1 } }, { \"int\": { bigint: s.coeff } }] });return G;\n  }function B(G) {\n    var s = l({ seq: [{ \"int\": 1 }, { octstr: { hex: G.prvKeyHex } }, { tag: [\"a0\", true, { oid: { name: G.curveName } }] }, { tag: [\"a1\", true, { bitstr: { hex: \"00\" + G.pubKeyHex } }] }] });return s;\n  }function x(s) {\n    var G = l({ seq: [{ \"int\": 0 }, { \"int\": { bigint: s.p } }, { \"int\": { bigint: s.q } }, { \"int\": { bigint: s.g } }, { \"int\": { bigint: s.y } }, { \"int\": { bigint: s.x } }] });return G;\n  }if ((n !== undefined && b instanceof n || u !== undefined && b instanceof u || r !== undefined && b instanceof r) && b.isPublic == true && (D === undefined || D == \"PKCS8PUB\")) {\n    var E = new C(b);var w = E.getEncodedHex();return hextopem(w, \"PUBLIC KEY\");\n  }if (D == \"PKCS1PRV\" && n !== undefined && b instanceof n && (y === undefined || y == null) && b.isPrivate == true) {\n    var E = A(b);var w = E.getEncodedHex();return hextopem(w, \"RSA PRIVATE KEY\");\n  }if (D == \"PKCS1PRV\" && r !== undefined && b instanceof r && (y === undefined || y == null) && b.isPrivate == true) {\n    var i = new z({ name: b.curveName });var v = i.getEncodedHex();var h = B(b);var t = h.getEncodedHex();var p = \"\";p += hextopem(v, \"EC PARAMETERS\");p += hextopem(t, \"EC PRIVATE KEY\");return p;\n  }if (D == \"PKCS1PRV\" && u !== undefined && b instanceof u && (y === undefined || y == null) && b.isPrivate == true) {\n    var E = x(b);var w = E.getEncodedHex();return hextopem(w, \"DSA PRIVATE KEY\");\n  }if (D == \"PKCS5PRV\" && n !== undefined && b instanceof n && y !== undefined && y != null && b.isPrivate == true) {\n    var E = A(b);var w = E.getEncodedHex();if (m === undefined) {\n      m = \"DES-EDE3-CBC\";\n    }return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"RSA\", w, y, m, j);\n  }if (D == \"PKCS5PRV\" && r !== undefined && b instanceof r && y !== undefined && y != null && b.isPrivate == true) {\n    var E = B(b);var w = E.getEncodedHex();if (m === undefined) {\n      m = \"DES-EDE3-CBC\";\n    }return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"EC\", w, y, m, j);\n  }if (D == \"PKCS5PRV\" && u !== undefined && b instanceof u && y !== undefined && y != null && b.isPrivate == true) {\n    var E = x(b);var w = E.getEncodedHex();if (m === undefined) {\n      m = \"DES-EDE3-CBC\";\n    }return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"DSA\", w, y, m, j);\n  }var o = function o(G, s) {\n    var I = c(G, s);var H = new l({ seq: [{ seq: [{ oid: { name: \"pkcs5PBES2\" } }, { seq: [{ seq: [{ oid: { name: \"pkcs5PBKDF2\" } }, { seq: [{ octstr: { hex: I.pbkdf2Salt } }, { \"int\": I.pbkdf2Iter }] }] }, { seq: [{ oid: { name: \"des-EDE3-CBC\" } }, { octstr: { hex: I.encryptionSchemeIV } }] }] }] }, { octstr: { hex: I.ciphertext } }] });return H.getEncodedHex();\n  };var c = function c(N, O) {\n    var H = 100;var M = CryptoJS.lib.WordArray.random(8);var L = \"DES-EDE3-CBC\";var s = CryptoJS.lib.WordArray.random(8);var I = CryptoJS.PBKDF2(O, M, { keySize: 192 / 32, iterations: H });var J = CryptoJS.enc.Hex.parse(N);var K = CryptoJS.TripleDES.encrypt(J, I, { iv: s }) + \"\";var G = {};G.ciphertext = K;G.pbkdf2Salt = CryptoJS.enc.Hex.stringify(M);G.pbkdf2Iter = H;G.encryptionSchemeAlg = L;G.encryptionSchemeIV = CryptoJS.enc.Hex.stringify(s);return G;\n  };if (D == \"PKCS8PRV\" && n != undefined && b instanceof n && b.isPrivate == true) {\n    var g = A(b);var d = g.getEncodedHex();var E = l({ seq: [{ \"int\": 0 }, { seq: [{ oid: { name: \"rsaEncryption\" } }, { \"null\": true }] }, { octstr: { hex: d } }] });var w = E.getEncodedHex();if (y === undefined || y == null) {\n      return hextopem(w, \"PRIVATE KEY\");\n    } else {\n      var t = o(w, y);return hextopem(t, \"ENCRYPTED PRIVATE KEY\");\n    }\n  }if (D == \"PKCS8PRV\" && r !== undefined && b instanceof r && b.isPrivate == true) {\n    var g = new l({ seq: [{ \"int\": 1 }, { octstr: { hex: b.prvKeyHex } }, { tag: [\"a1\", true, { bitstr: { hex: \"00\" + b.pubKeyHex } }] }] });var d = g.getEncodedHex();var E = l({ seq: [{ \"int\": 0 }, { seq: [{ oid: { name: \"ecPublicKey\" } }, { oid: { name: b.curveName } }] }, { octstr: { hex: d } }] });var w = E.getEncodedHex();if (y === undefined || y == null) {\n      return hextopem(w, \"PRIVATE KEY\");\n    } else {\n      var t = o(w, y);return hextopem(t, \"ENCRYPTED PRIVATE KEY\");\n    }\n  }if (D == \"PKCS8PRV\" && u !== undefined && b instanceof u && b.isPrivate == true) {\n    var g = new f({ bigint: b.x });var d = g.getEncodedHex();var E = l({ seq: [{ \"int\": 0 }, { seq: [{ oid: { name: \"dsa\" } }, { seq: [{ \"int\": { bigint: b.p } }, { \"int\": { bigint: b.q } }, { \"int\": { bigint: b.g } }] }] }, { octstr: { hex: d } }] });var w = E.getEncodedHex();if (y === undefined || y == null) {\n      return hextopem(w, \"PRIVATE KEY\");\n    } else {\n      var t = o(w, y);return hextopem(t, \"ENCRYPTED PRIVATE KEY\");\n    }\n  }throw \"unsupported object nor format\";\n};KEYUTIL.getKeyFromCSRPEM = function (b) {\n  var a = pemtohex(b, \"CERTIFICATE REQUEST\");var c = KEYUTIL.getKeyFromCSRHex(a);return c;\n};KEYUTIL.getKeyFromCSRHex = function (a) {\n  var c = KEYUTIL.parseCSRHex(a);var b = KEYUTIL.getKey(c.p8pubkeyhex, null, \"pkcs8pub\");return b;\n};KEYUTIL.parseCSRHex = function (d) {\n  var i = ASN1HEX;var f = i.getChildIdx;var c = i.getTLV;var b = {};var g = d;if (g.substr(0, 2) != \"30\") {\n    throw \"malformed CSR(code:001)\";\n  }var e = f(g, 0);if (e.length < 1) {\n    throw \"malformed CSR(code:002)\";\n  }if (g.substr(e[0], 2) != \"30\") {\n    throw \"malformed CSR(code:003)\";\n  }var a = f(g, e[0]);if (a.length < 3) {\n    throw \"malformed CSR(code:004)\";\n  }b.p8pubkeyhex = c(g, a[2]);return b;\n};KEYUTIL.getJWKFromKey = function (d) {\n  var b = {};if (d instanceof RSAKey && d.isPrivate) {\n    b.kty = \"RSA\";b.n = hextob64u(d.n.toString(16));b.e = hextob64u(d.e.toString(16));b.d = hextob64u(d.d.toString(16));b.p = hextob64u(d.p.toString(16));b.q = hextob64u(d.q.toString(16));b.dp = hextob64u(d.dmp1.toString(16));b.dq = hextob64u(d.dmq1.toString(16));b.qi = hextob64u(d.coeff.toString(16));return b;\n  } else {\n    if (d instanceof RSAKey && d.isPublic) {\n      b.kty = \"RSA\";b.n = hextob64u(d.n.toString(16));b.e = hextob64u(d.e.toString(16));return b;\n    } else {\n      if (d instanceof KJUR.crypto.ECDSA && d.isPrivate) {\n        var a = d.getShortNISTPCurveName();if (a !== \"P-256\" && a !== \"P-384\") {\n          throw \"unsupported curve name for JWT: \" + a;\n        }var c = d.getPublicKeyXYHex();b.kty = \"EC\";b.crv = a;b.x = hextob64u(c.x);b.y = hextob64u(c.y);b.d = hextob64u(d.prvKeyHex);return b;\n      } else {\n        if (d instanceof KJUR.crypto.ECDSA && d.isPublic) {\n          var a = d.getShortNISTPCurveName();if (a !== \"P-256\" && a !== \"P-384\") {\n            throw \"unsupported curve name for JWT: \" + a;\n          }var c = d.getPublicKeyXYHex();b.kty = \"EC\";b.crv = a;b.x = hextob64u(c.x);b.y = hextob64u(c.y);return b;\n        }\n      }\n    }\n  }throw \"not supported key object\";\n};\nRSAKey.getPosArrayOfChildrenFromHex = function (a) {\n  return ASN1HEX.getChildIdx(a, 0);\n};RSAKey.getHexValueArrayOfChildrenFromHex = function (f) {\n  var n = ASN1HEX;var i = n.getV;var k = RSAKey.getPosArrayOfChildrenFromHex(f);var e = i(f, k[0]);var j = i(f, k[1]);var b = i(f, k[2]);var c = i(f, k[3]);var h = i(f, k[4]);var g = i(f, k[5]);var m = i(f, k[6]);var l = i(f, k[7]);var d = i(f, k[8]);var k = new Array();k.push(e, j, b, c, h, g, m, l, d);return k;\n};RSAKey.prototype.readPrivateKeyFromPEMString = function (d) {\n  var c = pemtohex(d);var b = RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1], b[2], b[3], b[4], b[5], b[6], b[7], b[8]);\n};RSAKey.prototype.readPKCS5PrvKeyHex = function (c) {\n  var b = RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1], b[2], b[3], b[4], b[5], b[6], b[7], b[8]);\n};RSAKey.prototype.readPKCS8PrvKeyHex = function (e) {\n  var c, j, l, b, a, f, d, k;var m = ASN1HEX;var g = m.getVbyList;if (m.isASN1HEX(e) === false) {\n    throw \"not ASN.1 hex string\";\n  }try {\n    c = g(e, 0, [2, 0, 1], \"02\");j = g(e, 0, [2, 0, 2], \"02\");l = g(e, 0, [2, 0, 3], \"02\");b = g(e, 0, [2, 0, 4], \"02\");a = g(e, 0, [2, 0, 5], \"02\");f = g(e, 0, [2, 0, 6], \"02\");d = g(e, 0, [2, 0, 7], \"02\");k = g(e, 0, [2, 0, 8], \"02\");\n  } catch (i) {\n    throw \"malformed PKCS#8 plain RSA private key\";\n  }this.setPrivateEx(c, j, l, b, a, f, d, k);\n};RSAKey.prototype.readPKCS5PubKeyHex = function (c) {\n  var e = ASN1HEX;var b = e.getV;if (e.isASN1HEX(c) === false) {\n    throw \"keyHex is not ASN.1 hex string\";\n  }var a = e.getChildIdx(c, 0);if (a.length !== 2 || c.substr(a[0], 2) !== \"02\" || c.substr(a[1], 2) !== \"02\") {\n    throw \"wrong hex for PKCS#5 public key\";\n  }var f = b(c, a[0]);var d = b(c, a[1]);this.setPublic(f, d);\n};RSAKey.prototype.readPKCS8PubKeyHex = function (b) {\n  var c = ASN1HEX;if (c.isASN1HEX(b) === false) {\n    throw \"not ASN.1 hex string\";\n  }if (c.getTLVbyList(b, 0, [0, 0]) !== \"06092a864886f70d010101\") {\n    throw \"not PKCS8 RSA public key\";\n  }var a = c.getTLVbyList(b, 0, [1, 0]);this.readPKCS5PubKeyHex(a);\n};RSAKey.prototype.readCertPubKeyHex = function (b, d) {\n  var a, c;a = new X509();a.readCertHex(b);c = a.getPublicKeyHex();this.readPKCS8PubKeyHex(c);\n};\nvar _RE_HEXDECONLY = new RegExp(\"\");_RE_HEXDECONLY.compile(\"[^0-9a-f]\", \"gi\");function _rsasign_getHexPaddedDigestInfoForString(d, e, a) {\n  var b = function b(f) {\n    return KJUR.crypto.Util.hashString(f, a);\n  };var c = b(d);return KJUR.crypto.Util.getPaddedDigestInfoHex(c, a, e);\n}function _zeroPaddingOfSignature(e, d) {\n  var c = \"\";var a = d / 4 - e.length;for (var b = 0; b < a; b++) {\n    c = c + \"0\";\n  }return c + e;\n}RSAKey.prototype.sign = function (d, a) {\n  var b = function b(e) {\n    return KJUR.crypto.Util.hashString(e, a);\n  };var c = b(d);return this.signWithMessageHash(c, a);\n};RSAKey.prototype.signWithMessageHash = function (e, c) {\n  var f = KJUR.crypto.Util.getPaddedDigestInfoHex(e, c, this.n.bitLength());var b = parseBigInt(f, 16);var d = this.doPrivate(b);var a = d.toString(16);return _zeroPaddingOfSignature(a, this.n.bitLength());\n};function pss_mgf1_str(c, a, e) {\n  var b = \"\",\n      d = 0;while (b.length < a) {\n    b += hextorstr(e(rstrtohex(c + String.fromCharCode.apply(String, [(d & 4278190080) >> 24, (d & 16711680) >> 16, (d & 65280) >> 8, d & 255]))));d += 1;\n  }return b;\n}RSAKey.prototype.signPSS = function (e, a, d) {\n  var c = function c(f) {\n    return KJUR.crypto.Util.hashHex(f, a);\n  };var b = c(rstrtohex(e));if (d === undefined) {\n    d = -1;\n  }return this.signWithMessageHashPSS(b, a, d);\n};RSAKey.prototype.signWithMessageHashPSS = function (l, a, k) {\n  var b = hextorstr(l);var g = b.length;var m = this.n.bitLength() - 1;var c = Math.ceil(m / 8);var d;var o = function o(i) {\n    return KJUR.crypto.Util.hashHex(i, a);\n  };if (k === -1 || k === undefined) {\n    k = g;\n  } else {\n    if (k === -2) {\n      k = c - g - 2;\n    } else {\n      if (k < -2) {\n        throw \"invalid salt length\";\n      }\n    }\n  }if (c < g + k + 2) {\n    throw \"data too long\";\n  }var f = \"\";if (k > 0) {\n    f = new Array(k);new SecureRandom().nextBytes(f);f = String.fromCharCode.apply(String, f);\n  }var n = hextorstr(o(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" + b + f)));var j = [];for (d = 0; d < c - k - g - 2; d += 1) {\n    j[d] = 0;\n  }var e = String.fromCharCode.apply(String, j) + \"\\x01\" + f;var h = pss_mgf1_str(n, e.length, o);var q = [];for (d = 0; d < e.length; d += 1) {\n    q[d] = e.charCodeAt(d) ^ h.charCodeAt(d);\n  }var p = 65280 >> 8 * c - m & 255;q[0] &= ~p;for (d = 0; d < g; d++) {\n    q.push(n.charCodeAt(d));\n  }q.push(188);return _zeroPaddingOfSignature(this.doPrivate(new BigInteger(q)).toString(16), this.n.bitLength());\n};function _rsasign_getDecryptSignatureBI(a, d, c) {\n  var b = new RSAKey();b.setPublic(d, c);var e = b.doPublic(a);return e;\n}function _rsasign_getHexDigestInfoFromSig(a, c, b) {\n  var e = _rsasign_getDecryptSignatureBI(a, c, b);var d = e.toString(16).replace(/^1f+00/, \"\");return d;\n}function _rsasign_getAlgNameAndHashFromHexDisgestInfo(f) {\n  for (var e in KJUR.crypto.Util.DIGESTINFOHEAD) {\n    var d = KJUR.crypto.Util.DIGESTINFOHEAD[e];var b = d.length;if (f.substring(0, b) == d) {\n      var c = [e, f.substring(b)];return c;\n    }\n  }return [];\n}RSAKey.prototype.verify = function (f, j) {\n  j = j.replace(_RE_HEXDECONLY, \"\");j = j.replace(/[ \\n]+/g, \"\");var b = parseBigInt(j, 16);if (b.bitLength() > this.n.bitLength()) {\n    return 0;\n  }var i = this.doPublic(b);var e = i.toString(16).replace(/^1f+00/, \"\");var g = _rsasign_getAlgNameAndHashFromHexDisgestInfo(e);if (g.length == 0) {\n    return false;\n  }var d = g[0];var h = g[1];var a = function a(k) {\n    return KJUR.crypto.Util.hashString(k, d);\n  };var c = a(f);return h == c;\n};RSAKey.prototype.verifyWithMessageHash = function (e, a) {\n  a = a.replace(_RE_HEXDECONLY, \"\");a = a.replace(/[ \\n]+/g, \"\");var b = parseBigInt(a, 16);if (b.bitLength() > this.n.bitLength()) {\n    return 0;\n  }var h = this.doPublic(b);var g = h.toString(16).replace(/^1f+00/, \"\");var c = _rsasign_getAlgNameAndHashFromHexDisgestInfo(g);if (c.length == 0) {\n    return false;\n  }var d = c[0];var f = c[1];return f == e;\n};RSAKey.prototype.verifyPSS = function (c, b, a, f) {\n  var e = function e(g) {\n    return KJUR.crypto.Util.hashHex(g, a);\n  };var d = e(rstrtohex(c));if (f === undefined) {\n    f = -1;\n  }return this.verifyWithMessageHashPSS(d, b, a, f);\n};RSAKey.prototype.verifyWithMessageHashPSS = function (f, s, l, c) {\n  var k = new BigInteger(s, 16);if (k.bitLength() > this.n.bitLength()) {\n    return false;\n  }var r = function r(i) {\n    return KJUR.crypto.Util.hashHex(i, l);\n  };var j = hextorstr(f);var h = j.length;var g = this.n.bitLength() - 1;var m = Math.ceil(g / 8);var q;if (c === -1 || c === undefined) {\n    c = h;\n  } else {\n    if (c === -2) {\n      c = m - h - 2;\n    } else {\n      if (c < -2) {\n        throw \"invalid salt length\";\n      }\n    }\n  }if (m < h + c + 2) {\n    throw \"data too long\";\n  }var a = this.doPublic(k).toByteArray();for (q = 0; q < a.length; q += 1) {\n    a[q] &= 255;\n  }while (a.length < m) {\n    a.unshift(0);\n  }if (a[m - 1] !== 188) {\n    throw \"encoded message does not end in 0xbc\";\n  }a = String.fromCharCode.apply(String, a);var d = a.substr(0, m - h - 1);var e = a.substr(d.length, h);var p = 65280 >> 8 * m - g & 255;if ((d.charCodeAt(0) & p) !== 0) {\n    throw \"bits beyond keysize not zero\";\n  }var n = pss_mgf1_str(e, d.length, r);var o = [];for (q = 0; q < d.length; q += 1) {\n    o[q] = d.charCodeAt(q) ^ n.charCodeAt(q);\n  }o[0] &= ~p;var b = m - h - c - 2;for (q = 0; q < b; q += 1) {\n    if (o[q] !== 0) {\n      throw \"leftmost octets not zero\";\n    }\n  }if (o[b] !== 1) {\n    throw \"0x01 marker not found\";\n  }return e === hextorstr(r(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\" + j + String.fromCharCode.apply(String, o.slice(-c)))));\n};RSAKey.SALT_LEN_HLEN = -1;RSAKey.SALT_LEN_MAX = -2;RSAKey.SALT_LEN_RECOVER = -2;\nfunction X509() {\n  var k = ASN1HEX,\n      j = k.getChildIdx,\n      h = k.getV,\n      b = k.getTLV,\n      f = k.getVbyList,\n      c = k.getTLVbyList,\n      g = k.getIdxbyList,\n      d = k.getVidx,\n      i = k.oidname,\n      a = X509,\n      e = pemtohex;this.hex = null;this.version = 0;this.foffset = 0;this.aExtInfo = null;this.getVersion = function () {\n    if (this.hex === null || this.version !== 0) {\n      return this.version;\n    }if (c(this.hex, 0, [0, 0]) !== \"a003020102\") {\n      this.version = 1;this.foffset = -1;return 1;\n    }this.version = 3;return 3;\n  };this.getSerialNumberHex = function () {\n    return f(this.hex, 0, [0, 1 + this.foffset], \"02\");\n  };this.getSignatureAlgorithmField = function () {\n    return i(f(this.hex, 0, [0, 2 + this.foffset, 0], \"06\"));\n  };this.getIssuerHex = function () {\n    return c(this.hex, 0, [0, 3 + this.foffset], \"30\");\n  };this.getIssuerString = function () {\n    return a.hex2dn(this.getIssuerHex());\n  };this.getSubjectHex = function () {\n    return c(this.hex, 0, [0, 5 + this.foffset], \"30\");\n  };this.getSubjectString = function () {\n    return a.hex2dn(this.getSubjectHex());\n  };this.getNotBefore = function () {\n    var l = f(this.hex, 0, [0, 4 + this.foffset, 0]);l = l.replace(/(..)/g, \"%$1\");l = decodeURIComponent(l);return l;\n  };this.getNotAfter = function () {\n    var l = f(this.hex, 0, [0, 4 + this.foffset, 1]);l = l.replace(/(..)/g, \"%$1\");l = decodeURIComponent(l);return l;\n  };this.getPublicKeyHex = function () {\n    return k.getTLVbyList(this.hex, 0, [0, 6 + this.foffset], \"30\");\n  };this.getPublicKeyIdx = function () {\n    return g(this.hex, 0, [0, 6 + this.foffset], \"30\");\n  };this.getPublicKeyContentIdx = function () {\n    var l = this.getPublicKeyIdx();return g(this.hex, l, [1, 0], \"30\");\n  };this.getPublicKey = function () {\n    return KEYUTIL.getKey(this.getPublicKeyHex(), null, \"pkcs8pub\");\n  };this.getSignatureAlgorithmName = function () {\n    return i(f(this.hex, 0, [1, 0], \"06\"));\n  };this.getSignatureValueHex = function () {\n    return f(this.hex, 0, [2], \"03\", true);\n  };this.verifySignature = function (n) {\n    var o = this.getSignatureAlgorithmName();var l = this.getSignatureValueHex();var m = c(this.hex, 0, [0], \"30\");var p = new KJUR.crypto.Signature({ alg: o });p.init(n);p.updateHex(m);return p.verify(l);\n  };this.parseExt = function () {\n    if (this.version !== 3) {\n      return -1;\n    }var p = g(this.hex, 0, [0, 7, 0], \"30\");var m = j(this.hex, p);this.aExtInfo = new Array();for (var n = 0; n < m.length; n++) {\n      var q = {};q.critical = false;var l = j(this.hex, m[n]);var r = 0;if (l.length === 3) {\n        q.critical = true;r = 1;\n      }q.oid = k.hextooidstr(f(this.hex, m[n], [0], \"06\"));var o = g(this.hex, m[n], [1 + r]);q.vidx = d(this.hex, o);this.aExtInfo.push(q);\n    }\n  };this.getExtInfo = function (n) {\n    var l = this.aExtInfo;var o = n;if (!n.match(/^[0-9.]+$/)) {\n      o = KJUR.asn1.x509.OID.name2oid(n);\n    }if (o === \"\") {\n      return undefined;\n    }for (var m = 0; m < l.length; m++) {\n      if (l[m].oid === o) {\n        return l[m];\n      }\n    }return undefined;\n  };this.getExtBasicConstraints = function () {\n    var n = this.getExtInfo(\"basicConstraints\");if (n === undefined) {\n      return n;\n    }var l = h(this.hex, n.vidx);if (l === \"\") {\n      return {};\n    }if (l === \"0101ff\") {\n      return { cA: true };\n    }if (l.substr(0, 8) === \"0101ff02\") {\n      var o = h(l, 6);var m = parseInt(o, 16);return { cA: true, pathLen: m };\n    }throw \"basicConstraints parse error\";\n  };this.getExtKeyUsageBin = function () {\n    var o = this.getExtInfo(\"keyUsage\");if (o === undefined) {\n      return \"\";\n    }var m = h(this.hex, o.vidx);if (m.length % 2 != 0 || m.length <= 2) {\n      throw \"malformed key usage value\";\n    }var l = parseInt(m.substr(0, 2));var n = parseInt(m.substr(2), 16).toString(2);return n.substr(0, n.length - l);\n  };this.getExtKeyUsageString = function () {\n    var n = this.getExtKeyUsageBin();var l = new Array();for (var m = 0; m < n.length; m++) {\n      if (n.substr(m, 1) == \"1\") {\n        l.push(X509.KEYUSAGE_NAME[m]);\n      }\n    }return l.join(\",\");\n  };this.getExtSubjectKeyIdentifier = function () {\n    var l = this.getExtInfo(\"subjectKeyIdentifier\");if (l === undefined) {\n      return l;\n    }return h(this.hex, l.vidx);\n  };this.getExtAuthorityKeyIdentifier = function () {\n    var p = this.getExtInfo(\"authorityKeyIdentifier\");if (p === undefined) {\n      return p;\n    }var l = {};var o = b(this.hex, p.vidx);var m = j(o, 0);for (var n = 0; n < m.length; n++) {\n      if (o.substr(m[n], 2) === \"80\") {\n        l.kid = h(o, m[n]);\n      }\n    }return l;\n  };this.getExtExtKeyUsageName = function () {\n    var p = this.getExtInfo(\"extKeyUsage\");if (p === undefined) {\n      return p;\n    }var l = new Array();var o = b(this.hex, p.vidx);if (o === \"\") {\n      return l;\n    }var m = j(o, 0);for (var n = 0; n < m.length; n++) {\n      l.push(i(h(o, m[n])));\n    }return l;\n  };this.getExtSubjectAltName = function () {\n    var m = this.getExtSubjectAltName2();var l = new Array();for (var n = 0; n < m.length; n++) {\n      if (m[n][0] === \"DNS\") {\n        l.push(m[n][1]);\n      }\n    }return l;\n  };this.getExtSubjectAltName2 = function () {\n    var p, s, r;var q = this.getExtInfo(\"subjectAltName\");if (q === undefined) {\n      return q;\n    }var l = new Array();var o = b(this.hex, q.vidx);var m = j(o, 0);for (var n = 0; n < m.length; n++) {\n      r = o.substr(m[n], 2);p = h(o, m[n]);if (r === \"81\") {\n        s = hextoutf8(p);l.push([\"MAIL\", s]);\n      }if (r === \"82\") {\n        s = hextoutf8(p);l.push([\"DNS\", s]);\n      }if (r === \"84\") {\n        s = X509.hex2dn(p, 0);l.push([\"DN\", s]);\n      }if (r === \"86\") {\n        s = hextoutf8(p);l.push([\"URI\", s]);\n      }if (r === \"87\") {\n        s = hextoip(p);l.push([\"IP\", s]);\n      }\n    }return l;\n  };this.getExtCRLDistributionPointsURI = function () {\n    var q = this.getExtInfo(\"cRLDistributionPoints\");if (q === undefined) {\n      return q;\n    }var l = new Array();var m = j(this.hex, q.vidx);for (var o = 0; o < m.length; o++) {\n      try {\n        var r = f(this.hex, m[o], [0, 0, 0], \"86\");var p = hextoutf8(r);l.push(p);\n      } catch (n) {}\n    }return l;\n  };this.getExtAIAInfo = function () {\n    var p = this.getExtInfo(\"authorityInfoAccess\");if (p === undefined) {\n      return p;\n    }var l = { ocsp: [], caissuer: [] };var m = j(this.hex, p.vidx);for (var n = 0; n < m.length; n++) {\n      var q = f(this.hex, m[n], [0], \"06\");var o = f(this.hex, m[n], [1], \"86\");if (q === \"2b06010505073001\") {\n        l.ocsp.push(hextoutf8(o));\n      }if (q === \"2b06010505073002\") {\n        l.caissuer.push(hextoutf8(o));\n      }\n    }return l;\n  };this.getExtCertificatePolicies = function () {\n    var o = this.getExtInfo(\"certificatePolicies\");if (o === undefined) {\n      return o;\n    }var l = b(this.hex, o.vidx);var u = [];var s = j(l, 0);for (var r = 0; r < s.length; r++) {\n      var t = {};var n = j(l, s[r]);t.id = i(h(l, n[0]));if (n.length === 2) {\n        var m = j(l, n[1]);for (var q = 0; q < m.length; q++) {\n          var p = f(l, m[q], [0], \"06\");if (p === \"2b06010505070201\") {\n            t.cps = hextoutf8(f(l, m[q], [1]));\n          } else {\n            if (p === \"2b06010505070202\") {\n              t.unotice = hextoutf8(f(l, m[q], [1, 0]));\n            }\n          }\n        }\n      }u.push(t);\n    }return u;\n  };this.readCertPEM = function (l) {\n    this.readCertHex(e(l));\n  };this.readCertHex = function (l) {\n    this.hex = l;this.getVersion();try {\n      g(this.hex, 0, [0, 7], \"a3\");this.parseExt();\n    } catch (m) {}\n  };this.getInfo = function () {\n    var m = X509;var B, u, z;B = \"Basic Fields\\n\";B += \"  serial number: \" + this.getSerialNumberHex() + \"\\n\";B += \"  signature algorithm: \" + this.getSignatureAlgorithmField() + \"\\n\";B += \"  issuer: \" + this.getIssuerString() + \"\\n\";B += \"  notBefore: \" + this.getNotBefore() + \"\\n\";B += \"  notAfter: \" + this.getNotAfter() + \"\\n\";B += \"  subject: \" + this.getSubjectString() + \"\\n\";B += \"  subject public key info: \\n\";u = this.getPublicKey();B += \"    key algorithm: \" + u.type + \"\\n\";if (u.type === \"RSA\") {\n      B += \"    n=\" + hextoposhex(u.n.toString(16)).substr(0, 16) + \"...\\n\";B += \"    e=\" + hextoposhex(u.e.toString(16)) + \"\\n\";\n    }z = this.aExtInfo;if (z !== undefined && z !== null) {\n      B += \"X509v3 Extensions:\\n\";for (var r = 0; r < z.length; r++) {\n        var n = z[r];var A = KJUR.asn1.x509.OID.oid2name(n.oid);if (A === \"\") {\n          A = n.oid;\n        }var x = \"\";if (n.critical === true) {\n          x = \"CRITICAL\";\n        }B += \"  \" + A + \" \" + x + \":\\n\";if (A === \"basicConstraints\") {\n          var v = this.getExtBasicConstraints();if (v.cA === undefined) {\n            B += \"    {}\\n\";\n          } else {\n            B += \"    cA=true\";if (v.pathLen !== undefined) {\n              B += \", pathLen=\" + v.pathLen;\n            }B += \"\\n\";\n          }\n        } else {\n          if (A === \"keyUsage\") {\n            B += \"    \" + this.getExtKeyUsageString() + \"\\n\";\n          } else {\n            if (A === \"subjectKeyIdentifier\") {\n              B += \"    \" + this.getExtSubjectKeyIdentifier() + \"\\n\";\n            } else {\n              if (A === \"authorityKeyIdentifier\") {\n                var l = this.getExtAuthorityKeyIdentifier();if (l.kid !== undefined) {\n                  B += \"    kid=\" + l.kid + \"\\n\";\n                }\n              } else {\n                if (A === \"extKeyUsage\") {\n                  var w = this.getExtExtKeyUsageName();B += \"    \" + w.join(\", \") + \"\\n\";\n                } else {\n                  if (A === \"subjectAltName\") {\n                    var t = this.getExtSubjectAltName2();B += \"    \" + t + \"\\n\";\n                  } else {\n                    if (A === \"cRLDistributionPoints\") {\n                      var y = this.getExtCRLDistributionPointsURI();B += \"    \" + y + \"\\n\";\n                    } else {\n                      if (A === \"authorityInfoAccess\") {\n                        var p = this.getExtAIAInfo();if (p.ocsp !== undefined) {\n                          B += \"    ocsp: \" + p.ocsp.join(\",\") + \"\\n\";\n                        }if (p.caissuer !== undefined) {\n                          B += \"    caissuer: \" + p.caissuer.join(\",\") + \"\\n\";\n                        }\n                      } else {\n                        if (A === \"certificatePolicies\") {\n                          var o = this.getExtCertificatePolicies();for (var q = 0; q < o.length; q++) {\n                            if (o[q].id !== undefined) {\n                              B += \"    policy oid: \" + o[q].id + \"\\n\";\n                            }if (o[q].cps !== undefined) {\n                              B += \"    cps: \" + o[q].cps + \"\\n\";\n                            }\n                          }\n                        }\n                      }\n                    }\n                  }\n                }\n              }\n            }\n          }\n        }\n      }\n    }B += \"signature algorithm: \" + this.getSignatureAlgorithmName() + \"\\n\";B += \"signature: \" + this.getSignatureValueHex().substr(0, 16) + \"...\\n\";return B;\n  };\n}X509.hex2dn = function (f, b) {\n  if (b === undefined) {\n    b = 0;\n  }if (f.substr(b, 2) !== \"30\") {\n    throw \"malformed DN\";\n  }var c = new Array();var d = ASN1HEX.getChildIdx(f, b);for (var e = 0; e < d.length; e++) {\n    c.push(X509.hex2rdn(f, d[e]));\n  }c = c.map(function (a) {\n    return a.replace(\"/\", \"\\\\/\");\n  });return \"/\" + c.join(\"/\");\n};X509.hex2rdn = function (f, b) {\n  if (b === undefined) {\n    b = 0;\n  }if (f.substr(b, 2) !== \"31\") {\n    throw \"malformed RDN\";\n  }var c = new Array();var d = ASN1HEX.getChildIdx(f, b);for (var e = 0; e < d.length; e++) {\n    c.push(X509.hex2attrTypeValue(f, d[e]));\n  }c = c.map(function (a) {\n    return a.replace(\"+\", \"\\\\+\");\n  });return c.join(\"+\");\n};X509.hex2attrTypeValue = function (d, i) {\n  var j = ASN1HEX;var h = j.getV;if (i === undefined) {\n    i = 0;\n  }if (d.substr(i, 2) !== \"30\") {\n    throw \"malformed attribute type and value\";\n  }var g = j.getChildIdx(d, i);if (g.length !== 2 || d.substr(g[0], 2) !== \"06\") {\n    \"malformed attribute type and value\";\n  }var b = h(d, g[0]);var f = KJUR.asn1.ASN1Util.oidHexToInt(b);var e = KJUR.asn1.x509.OID.oid2atype(f);var a = h(d, g[1]);var c = hextorstr(a);return e + \"=\" + c;\n};X509.getPublicKeyFromCertHex = function (b) {\n  var a = new X509();a.readCertHex(b);return a.getPublicKey();\n};X509.getPublicKeyFromCertPEM = function (b) {\n  var a = new X509();a.readCertPEM(b);return a.getPublicKey();\n};X509.getPublicKeyInfoPropOfCertPEM = function (c) {\n  var e = ASN1HEX;var g = e.getVbyList;var b = {};var a, f, d;b.algparam = null;a = new X509();a.readCertPEM(c);f = a.getPublicKeyHex();b.keyhex = g(f, 0, [1], \"03\").substr(2);b.algoid = g(f, 0, [0, 0], \"06\");if (b.algoid === \"2a8648ce3d0201\") {\n    b.algparam = g(f, 0, [0, 1], \"06\");\n  }return b;\n};X509.KEYUSAGE_NAME = [\"digitalSignature\", \"nonRepudiation\", \"keyEncipherment\", \"dataEncipherment\", \"keyAgreement\", \"keyCertSign\", \"cRLSign\", \"encipherOnly\", \"decipherOnly\"];\nif (typeof KJUR == \"undefined\" || !KJUR) {\n  exports.KJUR = KJUR = {};\n}if (typeof KJUR.jws == \"undefined\" || !KJUR.jws) {\n  KJUR.jws = {};\n}KJUR.jws.JWS = function () {\n  var b = KJUR,\n      a = b.jws.JWS,\n      c = a.isSafeJSONString;this.parseJWS = function (g, j) {\n    if (this.parsedJWS !== undefined && (j || this.parsedJWS.sigvalH !== undefined)) {\n      return;\n    }var i = g.match(/^([^.]+)\\.([^.]+)\\.([^.]+)$/);if (i == null) {\n      throw \"JWS signature is not a form of 'Head.Payload.SigValue'.\";\n    }var k = i[1];var e = i[2];var l = i[3];var n = k + \".\" + e;this.parsedJWS = {};this.parsedJWS.headB64U = k;this.parsedJWS.payloadB64U = e;this.parsedJWS.sigvalB64U = l;this.parsedJWS.si = n;if (!j) {\n      var h = b64utohex(l);var f = parseBigInt(h, 16);this.parsedJWS.sigvalH = h;this.parsedJWS.sigvalBI = f;\n    }var d = b64utoutf8(k);var m = b64utoutf8(e);this.parsedJWS.headS = d;this.parsedJWS.payloadS = m;if (!c(d, this.parsedJWS, \"headP\")) {\n      throw \"malformed JSON string for JWS Head: \" + d;\n    }\n  };\n};KJUR.jws.JWS.sign = function (i, v, y, z, a) {\n  var w = KJUR,\n      m = w.jws,\n      q = m.JWS,\n      g = q.readSafeJSONString,\n      p = q.isSafeJSONString,\n      d = w.crypto,\n      k = d.ECDSA,\n      o = d.Mac,\n      c = d.Signature,\n      t = JSON;var s, j, n;if (typeof v != \"string\" && (typeof v === \"undefined\" ? \"undefined\" : _typeof(v)) != \"object\") {\n    throw \"spHeader must be JSON string or object: \" + v;\n  }if ((typeof v === \"undefined\" ? \"undefined\" : _typeof(v)) == \"object\") {\n    j = v;s = t.stringify(j);\n  }if (typeof v == \"string\") {\n    s = v;if (!p(s)) {\n      throw \"JWS Head is not safe JSON string: \" + s;\n    }j = g(s);\n  }n = y;if ((typeof y === \"undefined\" ? \"undefined\" : _typeof(y)) == \"object\") {\n    n = t.stringify(y);\n  }if ((i == \"\" || i == null) && j.alg !== undefined) {\n    i = j.alg;\n  }if (i != \"\" && i != null && j.alg === undefined) {\n    j.alg = i;s = t.stringify(j);\n  }if (i !== j.alg) {\n    throw \"alg and sHeader.alg doesn't match: \" + i + \"!=\" + j.alg;\n  }var r = null;if (q.jwsalg2sigalg[i] === undefined) {\n    throw \"unsupported alg name: \" + i;\n  } else {\n    r = q.jwsalg2sigalg[i];\n  }var e = utf8tob64u(s);var l = utf8tob64u(n);var b = e + \".\" + l;var x = \"\";if (r.substr(0, 4) == \"Hmac\") {\n    if (z === undefined) {\n      throw \"mac key shall be specified for HS* alg\";\n    }var h = new o({ alg: r, prov: \"cryptojs\", pass: z });h.updateString(b);x = h.doFinal();\n  } else {\n    if (r.indexOf(\"withECDSA\") != -1) {\n      var f = new c({ alg: r });f.init(z, a);f.updateString(b);hASN1Sig = f.sign();x = KJUR.crypto.ECDSA.asn1SigToConcatSig(hASN1Sig);\n    } else {\n      if (r != \"none\") {\n        var f = new c({ alg: r });f.init(z, a);f.updateString(b);x = f.sign();\n      }\n    }\n  }var u = hextob64u(x);return b + \".\" + u;\n};KJUR.jws.JWS.verify = function (w, B, n) {\n  var x = KJUR,\n      q = x.jws,\n      t = q.JWS,\n      i = t.readSafeJSONString,\n      e = x.crypto,\n      p = e.ECDSA,\n      s = e.Mac,\n      d = e.Signature,\n      m;if ((typeof RSAKey === \"undefined\" ? \"undefined\" : _typeof(RSAKey)) !== undefined) {\n    m = RSAKey;\n  }var y = w.split(\".\");if (y.length !== 3) {\n    return false;\n  }var f = y[0];var r = y[1];var c = f + \".\" + r;var A = b64utohex(y[2]);var l = i(b64utoutf8(y[0]));var k = null;var z = null;if (l.alg === undefined) {\n    throw \"algorithm not specified in header\";\n  } else {\n    k = l.alg;z = k.substr(0, 2);\n  }if (n != null && Object.prototype.toString.call(n) === \"[object Array]\" && n.length > 0) {\n    var b = \":\" + n.join(\":\") + \":\";if (b.indexOf(\":\" + k + \":\") == -1) {\n      throw \"algorithm '\" + k + \"' not accepted in the list\";\n    }\n  }if (k != \"none\" && B === null) {\n    throw \"key shall be specified to verify.\";\n  }if (typeof B == \"string\" && B.indexOf(\"-----BEGIN \") != -1) {\n    B = KEYUTIL.getKey(B);\n  }if (z == \"RS\" || z == \"PS\") {\n    if (!(B instanceof m)) {\n      throw \"key shall be a RSAKey obj for RS* and PS* algs\";\n    }\n  }if (z == \"ES\") {\n    if (!(B instanceof p)) {\n      throw \"key shall be a ECDSA obj for ES* algs\";\n    }\n  }if (k == \"none\") {}var u = null;if (t.jwsalg2sigalg[l.alg] === undefined) {\n    throw \"unsupported alg name: \" + k;\n  } else {\n    u = t.jwsalg2sigalg[k];\n  }if (u == \"none\") {\n    throw \"not supported\";\n  } else {\n    if (u.substr(0, 4) == \"Hmac\") {\n      var o = null;if (B === undefined) {\n        throw \"hexadecimal key shall be specified for HMAC\";\n      }var j = new s({ alg: u, pass: B });j.updateString(c);o = j.doFinal();return A == o;\n    } else {\n      if (u.indexOf(\"withECDSA\") != -1) {\n        var h = null;try {\n          h = p.concatSigToASN1Sig(A);\n        } catch (v) {\n          return false;\n        }var g = new d({ alg: u });g.init(B);g.updateString(c);return g.verify(h);\n      } else {\n        var g = new d({ alg: u });g.init(B);g.updateString(c);return g.verify(A);\n      }\n    }\n  }\n};KJUR.jws.JWS.parse = function (g) {\n  var c = g.split(\".\");var b = {};var f, e, d;if (c.length != 2 && c.length != 3) {\n    throw \"malformed sJWS: wrong number of '.' splitted elements\";\n  }f = c[0];e = c[1];if (c.length == 3) {\n    d = c[2];\n  }b.headerObj = KJUR.jws.JWS.readSafeJSONString(b64utoutf8(f));b.payloadObj = KJUR.jws.JWS.readSafeJSONString(b64utoutf8(e));b.headerPP = JSON.stringify(b.headerObj, null, \"  \");if (b.payloadObj == null) {\n    b.payloadPP = b64utoutf8(e);\n  } else {\n    b.payloadPP = JSON.stringify(b.payloadObj, null, \"  \");\n  }if (d !== undefined) {\n    b.sigHex = b64utohex(d);\n  }return b;\n};KJUR.jws.JWS.verifyJWT = function (e, l, r) {\n  var d = KJUR,\n      j = d.jws,\n      o = j.JWS,\n      n = o.readSafeJSONString,\n      p = o.inArray,\n      f = o.includedArray;var k = e.split(\".\");var c = k[0];var i = k[1];var q = c + \".\" + i;var m = b64utohex(k[2]);var h = n(b64utoutf8(c));var g = n(b64utoutf8(i));if (h.alg === undefined) {\n    return false;\n  }if (r.alg === undefined) {\n    throw \"acceptField.alg shall be specified\";\n  }if (!p(h.alg, r.alg)) {\n    return false;\n  }if (g.iss !== undefined && _typeof(r.iss) === \"object\") {\n    if (!p(g.iss, r.iss)) {\n      return false;\n    }\n  }if (g.sub !== undefined && _typeof(r.sub) === \"object\") {\n    if (!p(g.sub, r.sub)) {\n      return false;\n    }\n  }if (g.aud !== undefined && _typeof(r.aud) === \"object\") {\n    if (typeof g.aud == \"string\") {\n      if (!p(g.aud, r.aud)) {\n        return false;\n      }\n    } else {\n      if (_typeof(g.aud) == \"object\") {\n        if (!f(g.aud, r.aud)) {\n          return false;\n        }\n      }\n    }\n  }var b = j.IntDate.getNow();if (r.verifyAt !== undefined && typeof r.verifyAt === \"number\") {\n    b = r.verifyAt;\n  }if (r.gracePeriod === undefined || typeof r.gracePeriod !== \"number\") {\n    r.gracePeriod = 0;\n  }if (g.exp !== undefined && typeof g.exp == \"number\") {\n    if (g.exp + r.gracePeriod < b) {\n      return false;\n    }\n  }if (g.nbf !== undefined && typeof g.nbf == \"number\") {\n    if (b < g.nbf - r.gracePeriod) {\n      return false;\n    }\n  }if (g.iat !== undefined && typeof g.iat == \"number\") {\n    if (b < g.iat - r.gracePeriod) {\n      return false;\n    }\n  }if (g.jti !== undefined && r.jti !== undefined) {\n    if (g.jti !== r.jti) {\n      return false;\n    }\n  }if (!o.verify(e, l, r.alg)) {\n    return false;\n  }return true;\n};KJUR.jws.JWS.includedArray = function (b, a) {\n  var c = KJUR.jws.JWS.inArray;if (b === null) {\n    return false;\n  }if ((typeof b === \"undefined\" ? \"undefined\" : _typeof(b)) !== \"object\") {\n    return false;\n  }if (typeof b.length !== \"number\") {\n    return false;\n  }for (var d = 0; d < b.length; d++) {\n    if (!c(b[d], a)) {\n      return false;\n    }\n  }return true;\n};KJUR.jws.JWS.inArray = function (d, b) {\n  if (b === null) {\n    return false;\n  }if ((typeof b === \"undefined\" ? \"undefined\" : _typeof(b)) !== \"object\") {\n    return false;\n  }if (typeof b.length !== \"number\") {\n    return false;\n  }for (var c = 0; c < b.length; c++) {\n    if (b[c] == d) {\n      return true;\n    }\n  }return false;\n};KJUR.jws.JWS.jwsalg2sigalg = { HS256: \"HmacSHA256\", HS384: \"HmacSHA384\", HS512: \"HmacSHA512\", RS256: \"SHA256withRSA\", RS384: \"SHA384withRSA\", RS512: \"SHA512withRSA\", ES256: \"SHA256withECDSA\", ES384: \"SHA384withECDSA\", PS256: \"SHA256withRSAandMGF1\", PS384: \"SHA384withRSAandMGF1\", PS512: \"SHA512withRSAandMGF1\", none: \"none\" };KJUR.jws.JWS.isSafeJSONString = function (c, b, d) {\n  var e = null;try {\n    e = jsonParse(c);if ((typeof e === \"undefined\" ? \"undefined\" : _typeof(e)) != \"object\") {\n      return 0;\n    }if (e.constructor === Array) {\n      return 0;\n    }if (b) {\n      b[d] = e;\n    }return 1;\n  } catch (a) {\n    return 0;\n  }\n};KJUR.jws.JWS.readSafeJSONString = function (b) {\n  var c = null;try {\n    c = jsonParse(b);if ((typeof c === \"undefined\" ? \"undefined\" : _typeof(c)) != \"object\") {\n      return null;\n    }if (c.constructor === Array) {\n      return null;\n    }return c;\n  } catch (a) {\n    return null;\n  }\n};KJUR.jws.JWS.getEncodedSignatureValueFromJWS = function (b) {\n  var a = b.match(/^[^.]+\\.[^.]+\\.([^.]+)$/);if (a == null) {\n    throw \"JWS signature is not a form of 'Head.Payload.SigValue'.\";\n  }return a[1];\n};KJUR.jws.JWS.getJWKthumbprint = function (d) {\n  if (d.kty !== \"RSA\" && d.kty !== \"EC\" && d.kty !== \"oct\") {\n    throw \"unsupported algorithm for JWK Thumprint\";\n  }var a = \"{\";if (d.kty === \"RSA\") {\n    if (typeof d.n != \"string\" || typeof d.e != \"string\") {\n      throw \"wrong n and e value for RSA key\";\n    }a += '\"e\":\"' + d.e + '\",';a += '\"kty\":\"' + d.kty + '\",';a += '\"n\":\"' + d.n + '\"}';\n  } else {\n    if (d.kty === \"EC\") {\n      if (typeof d.crv != \"string\" || typeof d.x != \"string\" || typeof d.y != \"string\") {\n        throw \"wrong crv, x and y value for EC key\";\n      }a += '\"crv\":\"' + d.crv + '\",';a += '\"kty\":\"' + d.kty + '\",';a += '\"x\":\"' + d.x + '\",';a += '\"y\":\"' + d.y + '\"}';\n    } else {\n      if (d.kty === \"oct\") {\n        if (typeof d.k != \"string\") {\n          throw \"wrong k value for oct(symmetric) key\";\n        }a += '\"kty\":\"' + d.kty + '\",';a += '\"k\":\"' + d.k + '\"}';\n      }\n    }\n  }var b = rstrtohex(a);var c = KJUR.crypto.Util.hashHex(b, \"sha256\");var e = hextob64u(c);return e;\n};KJUR.jws.IntDate = {};KJUR.jws.IntDate.get = function (c) {\n  var b = KJUR.jws.IntDate,\n      d = b.getNow,\n      a = b.getZulu;if (c == \"now\") {\n    return d();\n  } else {\n    if (c == \"now + 1hour\") {\n      return d() + 60 * 60;\n    } else {\n      if (c == \"now + 1day\") {\n        return d() + 60 * 60 * 24;\n      } else {\n        if (c == \"now + 1month\") {\n          return d() + 60 * 60 * 24 * 30;\n        } else {\n          if (c == \"now + 1year\") {\n            return d() + 60 * 60 * 24 * 365;\n          } else {\n            if (c.match(/Z$/)) {\n              return a(c);\n            } else {\n              if (c.match(/^[0-9]+$/)) {\n                return parseInt(c);\n              }\n            }\n          }\n        }\n      }\n    }\n  }throw \"unsupported format: \" + c;\n};KJUR.jws.IntDate.getZulu = function (a) {\n  return zulutosec(a);\n};KJUR.jws.IntDate.getNow = function () {\n  var a = ~~(new Date() / 1000);return a;\n};KJUR.jws.IntDate.intDate2UTCString = function (a) {\n  var b = new Date(a * 1000);return b.toUTCString();\n};KJUR.jws.IntDate.intDate2Zulu = function (e) {\n  var i = new Date(e * 1000),\n      h = (\"0000\" + i.getUTCFullYear()).slice(-4),\n      g = (\"00\" + (i.getUTCMonth() + 1)).slice(-2),\n      b = (\"00\" + i.getUTCDate()).slice(-2),\n      a = (\"00\" + i.getUTCHours()).slice(-2),\n      c = (\"00\" + i.getUTCMinutes()).slice(-2),\n      f = (\"00\" + i.getUTCSeconds()).slice(-2);return h + g + b + a + c + f + \"Z\";\n};\nexports.SecureRandom = SecureRandom;\nexports.rng_seed_time = rng_seed_time;\nexports.BigInteger = BigInteger;\nexports.RSAKey = RSAKey;\nvar EDSA = KJUR.crypto.EDSA;\nexports.EDSA = EDSA;\nvar DSA = KJUR.crypto.DSA;\nexports.DSA = DSA;\nvar Signature = KJUR.crypto.Signature;\nexports.Signature = Signature;\nvar MessageDigest = KJUR.crypto.MessageDigest;\nexports.MessageDigest = MessageDigest;\nvar Mac = KJUR.crypto.Mac;\nexports.Mac = Mac;\nvar Cipher = KJUR.crypto.Cipher;\nexports.Cipher = Cipher;\nexports.KEYUTIL = KEYUTIL;\nexports.ASN1HEX = ASN1HEX;\nexports.X509 = X509;\nexports.CryptoJS = CryptoJS;\n\n// ext/base64.js\n\nexports.b64tohex = b64tohex;\nexports.b64toBA = b64toBA;\n\n// base64x.js\n\nexports.stoBA = stoBA;\nexports.BAtos = BAtos;\nexports.BAtohex = BAtohex;\nexports.stohex = stohex;\nexports.stob64 = stob64;\nexports.stob64u = stob64u;\nexports.b64utos = b64utos;\nexports.b64tob64u = b64tob64u;\nexports.b64utob64 = b64utob64;\nexports.hex2b64 = hex2b64;\nexports.hextob64u = hextob64u;\nexports.b64utohex = b64utohex;\nexports.utf8tob64u = utf8tob64u;\nexports.b64utoutf8 = b64utoutf8;\nexports.utf8tob64 = utf8tob64;\nexports.b64toutf8 = b64toutf8;\nexports.utf8tohex = utf8tohex;\nexports.hextoutf8 = hextoutf8;\nexports.hextorstr = hextorstr;\nexports.rstrtohex = rstrtohex;\nexports.hextob64 = hextob64;\nexports.hextob64nl = hextob64nl;\nexports.b64nltohex = b64nltohex;\nexports.hextopem = hextopem;\nexports.pemtohex = pemtohex;\nexports.hextoArrayBuffer = hextoArrayBuffer;\nexports.ArrayBuffertohex = ArrayBuffertohex;\nexports.zulutomsec = zulutomsec;\nexports.zulutosec = zulutosec;\nexports.zulutodate = zulutodate;\nexports.datetozulu = datetozulu;\nexports.uricmptohex = uricmptohex;\nexports.hextouricmp = hextouricmp;\nexports.ipv6tohex = ipv6tohex;\nexports.hextoipv6 = hextoipv6;\nexports.hextoip = hextoip;\nexports.iptohex = iptohex;\nexports.encodeURIComponentAll = encodeURIComponentAll;\nexports.newline_toUnix = newline_toUnix;\nexports.newline_toDos = newline_toDos;\nexports.hextoposhex = hextoposhex;\nexports.intarystrtohex = intarystrtohex;\nexports.strdiffidx = strdiffidx;\n\n// name spaces\n\nexports.KJUR = KJUR;\n\nvar _crypto = KJUR.crypto;\nexports.crypto = _crypto;\nvar _KJUR = KJUR;\nvar asn1 = _KJUR.asn1;\nexports.asn1 = asn1;\nvar _KJUR2 = KJUR;\nvar jws = _KJUR2.jws;\nexports.jws = jws;\nvar _KJUR3 = KJUR;\nvar lang = _KJUR3.lang;\nexports.lang = lang;\n/* WEBPACK VAR INJECTION */}.call(this, __webpack_require__(/*! ./../../node_modules/buffer/index.js */ \"./node_modules/buffer/index.js\").Buffer))\n\n/***/ }),\n\n/***/ \"./node_modules/babel-polyfill/lib/index.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/babel-polyfill/lib/index.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n/* WEBPACK VAR INJECTION */(function(global) {\n\n__webpack_require__(/*! core-js/shim */ \"./node_modules/core-js/shim.js\");\n\n__webpack_require__(/*! regenerator-runtime/runtime */ \"./node_modules/babel-polyfill/node_modules/regenerator-runtime/runtime.js\");\n\n__webpack_require__(/*! core-js/fn/regexp/escape */ \"./node_modules/core-js/fn/regexp/escape.js\");\n\nif (global._babelPolyfill) {\n  throw new Error(\"only one instance of babel-polyfill is allowed\");\n}\nglobal._babelPolyfill = true;\n\nvar DEFINE_PROPERTY = \"defineProperty\";\nfunction define(O, key, value) {\n  O[key] || Object[DEFINE_PROPERTY](O, key, {\n    writable: true,\n    configurable: true,\n    value: value\n  });\n}\n\ndefine(String.prototype, \"padLeft\", \"\".padStart);\ndefine(String.prototype, \"padRight\", \"\".padEnd);\n\n\"pop,reverse,shift,keys,values,entries,indexOf,every,some,forEach,map,filter,find,findIndex,includes,join,slice,concat,push,splice,unshift,sort,lastIndexOf,reduce,reduceRight,copyWithin,fill\".split(\",\").forEach(function (key) {\n  [][key] && define(Array, key, Function.call.bind([][key]));\n});\n/* WEBPACK VAR INJECTION */}.call(this, __webpack_require__(/*! ./../../webpack/buildin/global.js */ \"./node_modules/webpack/buildin/global.js\")))\n\n/***/ }),\n\n/***/ \"./node_modules/babel-polyfill/node_modules/regenerator-runtime/runtime.js\":\n/*!*********************************************************************************!*\\\n  !*** ./node_modules/babel-polyfill/node_modules/regenerator-runtime/runtime.js ***!\n  \\*********************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n/* WEBPACK VAR INJECTION */(function(global) {/**\n * Copyright (c) 2014, Facebook, Inc.\n * All rights reserved.\n *\n * This source code is licensed under the BSD-style license found in the\n * https://raw.github.com/facebook/regenerator/master/LICENSE file. An\n * additional grant of patent rights can be found in the PATENTS file in\n * the same directory.\n */\n\n!(function(global) {\n  \"use strict\";\n\n  var Op = Object.prototype;\n  var hasOwn = Op.hasOwnProperty;\n  var undefined; // More compressible than void 0.\n  var $Symbol = typeof Symbol === \"function\" ? Symbol : {};\n  var iteratorSymbol = $Symbol.iterator || \"@@iterator\";\n  var asyncIteratorSymbol = $Symbol.asyncIterator || \"@@asyncIterator\";\n  var toStringTagSymbol = $Symbol.toStringTag || \"@@toStringTag\";\n\n  var inModule = typeof module === \"object\";\n  var runtime = global.regeneratorRuntime;\n  if (runtime) {\n    if (inModule) {\n      // If regeneratorRuntime is defined globally and we're in a module,\n      // make the exports object identical to regeneratorRuntime.\n      module.exports = runtime;\n    }\n    // Don't bother evaluating the rest of this file if the runtime was\n    // already defined globally.\n    return;\n  }\n\n  // Define the runtime globally (as expected by generated code) as either\n  // module.exports (if we're in a module) or a new, empty object.\n  runtime = global.regeneratorRuntime = inModule ? module.exports : {};\n\n  function wrap(innerFn, outerFn, self, tryLocsList) {\n    // If outerFn provided and outerFn.prototype is a Generator, then outerFn.prototype instanceof Generator.\n    var protoGenerator = outerFn && outerFn.prototype instanceof Generator ? outerFn : Generator;\n    var generator = Object.create(protoGenerator.prototype);\n    var context = new Context(tryLocsList || []);\n\n    // The ._invoke method unifies the implementations of the .next,\n    // .throw, and .return methods.\n    generator._invoke = makeInvokeMethod(innerFn, self, context);\n\n    return generator;\n  }\n  runtime.wrap = wrap;\n\n  // Try/catch helper to minimize deoptimizations. Returns a completion\n  // record like context.tryEntries[i].completion. This interface could\n  // have been (and was previously) designed to take a closure to be\n  // invoked without arguments, but in all the cases we care about we\n  // already have an existing method we want to call, so there's no need\n  // to create a new function object. We can even get away with assuming\n  // the method takes exactly one argument, since that happens to be true\n  // in every case, so we don't have to touch the arguments object. The\n  // only additional allocation required is the completion record, which\n  // has a stable shape and so hopefully should be cheap to allocate.\n  function tryCatch(fn, obj, arg) {\n    try {\n      return { type: \"normal\", arg: fn.call(obj, arg) };\n    } catch (err) {\n      return { type: \"throw\", arg: err };\n    }\n  }\n\n  var GenStateSuspendedStart = \"suspendedStart\";\n  var GenStateSuspendedYield = \"suspendedYield\";\n  var GenStateExecuting = \"executing\";\n  var GenStateCompleted = \"completed\";\n\n  // Returning this object from the innerFn has the same effect as\n  // breaking out of the dispatch switch statement.\n  var ContinueSentinel = {};\n\n  // Dummy constructor functions that we use as the .constructor and\n  // .constructor.prototype properties for functions that return Generator\n  // objects. For full spec compliance, you may wish to configure your\n  // minifier not to mangle the names of these two functions.\n  function Generator() {}\n  function GeneratorFunction() {}\n  function GeneratorFunctionPrototype() {}\n\n  // This is a polyfill for %IteratorPrototype% for environments that\n  // don't natively support it.\n  var IteratorPrototype = {};\n  IteratorPrototype[iteratorSymbol] = function () {\n    return this;\n  };\n\n  var getProto = Object.getPrototypeOf;\n  var NativeIteratorPrototype = getProto && getProto(getProto(values([])));\n  if (NativeIteratorPrototype &&\n      NativeIteratorPrototype !== Op &&\n      hasOwn.call(NativeIteratorPrototype, iteratorSymbol)) {\n    // This environment has a native %IteratorPrototype%; use it instead\n    // of the polyfill.\n    IteratorPrototype = NativeIteratorPrototype;\n  }\n\n  var Gp = GeneratorFunctionPrototype.prototype =\n    Generator.prototype = Object.create(IteratorPrototype);\n  GeneratorFunction.prototype = Gp.constructor = GeneratorFunctionPrototype;\n  GeneratorFunctionPrototype.constructor = GeneratorFunction;\n  GeneratorFunctionPrototype[toStringTagSymbol] =\n    GeneratorFunction.displayName = \"GeneratorFunction\";\n\n  // Helper for defining the .next, .throw, and .return methods of the\n  // Iterator interface in terms of a single ._invoke method.\n  function defineIteratorMethods(prototype) {\n    [\"next\", \"throw\", \"return\"].forEach(function(method) {\n      prototype[method] = function(arg) {\n        return this._invoke(method, arg);\n      };\n    });\n  }\n\n  runtime.isGeneratorFunction = function(genFun) {\n    var ctor = typeof genFun === \"function\" && genFun.constructor;\n    return ctor\n      ? ctor === GeneratorFunction ||\n        // For the native GeneratorFunction constructor, the best we can\n        // do is to check its .name property.\n        (ctor.displayName || ctor.name) === \"GeneratorFunction\"\n      : false;\n  };\n\n  runtime.mark = function(genFun) {\n    if (Object.setPrototypeOf) {\n      Object.setPrototypeOf(genFun, GeneratorFunctionPrototype);\n    } else {\n      genFun.__proto__ = GeneratorFunctionPrototype;\n      if (!(toStringTagSymbol in genFun)) {\n        genFun[toStringTagSymbol] = \"GeneratorFunction\";\n      }\n    }\n    genFun.prototype = Object.create(Gp);\n    return genFun;\n  };\n\n  // Within the body of any async function, `await x` is transformed to\n  // `yield regeneratorRuntime.awrap(x)`, so that the runtime can test\n  // `hasOwn.call(value, \"__await\")` to determine if the yielded value is\n  // meant to be awaited.\n  runtime.awrap = function(arg) {\n    return { __await: arg };\n  };\n\n  function AsyncIterator(generator) {\n    function invoke(method, arg, resolve, reject) {\n      var record = tryCatch(generator[method], generator, arg);\n      if (record.type === \"throw\") {\n        reject(record.arg);\n      } else {\n        var result = record.arg;\n        var value = result.value;\n        if (value &&\n            typeof value === \"object\" &&\n            hasOwn.call(value, \"__await\")) {\n          return Promise.resolve(value.__await).then(function(value) {\n            invoke(\"next\", value, resolve, reject);\n          }, function(err) {\n            invoke(\"throw\", err, resolve, reject);\n          });\n        }\n\n        return Promise.resolve(value).then(function(unwrapped) {\n          // When a yielded Promise is resolved, its final value becomes\n          // the .value of the Promise<{value,done}> result for the\n          // current iteration. If the Promise is rejected, however, the\n          // result for this iteration will be rejected with the same\n          // reason. Note that rejections of yielded Promises are not\n          // thrown back into the generator function, as is the case\n          // when an awaited Promise is rejected. This difference in\n          // behavior between yield and await is important, because it\n          // allows the consumer to decide what to do with the yielded\n          // rejection (swallow it and continue, manually .throw it back\n          // into the generator, abandon iteration, whatever). With\n          // await, by contrast, there is no opportunity to examine the\n          // rejection reason outside the generator function, so the\n          // only option is to throw it from the await expression, and\n          // let the generator function handle the exception.\n          result.value = unwrapped;\n          resolve(result);\n        }, reject);\n      }\n    }\n\n    if (typeof global.process === \"object\" && global.process.domain) {\n      invoke = global.process.domain.bind(invoke);\n    }\n\n    var previousPromise;\n\n    function enqueue(method, arg) {\n      function callInvokeWithMethodAndArg() {\n        return new Promise(function(resolve, reject) {\n          invoke(method, arg, resolve, reject);\n        });\n      }\n\n      return previousPromise =\n        // If enqueue has been called before, then we want to wait until\n        // all previous Promises have been resolved before calling invoke,\n        // so that results are always delivered in the correct order. If\n        // enqueue has not been called before, then it is important to\n        // call invoke immediately, without waiting on a callback to fire,\n        // so that the async generator function has the opportunity to do\n        // any necessary setup in a predictable way. This predictability\n        // is why the Promise constructor synchronously invokes its\n        // executor callback, and why async functions synchronously\n        // execute code before the first await. Since we implement simple\n        // async functions in terms of async generators, it is especially\n        // important to get this right, even though it requires care.\n        previousPromise ? previousPromise.then(\n          callInvokeWithMethodAndArg,\n          // Avoid propagating failures to Promises returned by later\n          // invocations of the iterator.\n          callInvokeWithMethodAndArg\n        ) : callInvokeWithMethodAndArg();\n    }\n\n    // Define the unified helper method that is used to implement .next,\n    // .throw, and .return (see defineIteratorMethods).\n    this._invoke = enqueue;\n  }\n\n  defineIteratorMethods(AsyncIterator.prototype);\n  AsyncIterator.prototype[asyncIteratorSymbol] = function () {\n    return this;\n  };\n  runtime.AsyncIterator = AsyncIterator;\n\n  // Note that simple async functions are implemented on top of\n  // AsyncIterator objects; they just return a Promise for the value of\n  // the final result produced by the iterator.\n  runtime.async = function(innerFn, outerFn, self, tryLocsList) {\n    var iter = new AsyncIterator(\n      wrap(innerFn, outerFn, self, tryLocsList)\n    );\n\n    return runtime.isGeneratorFunction(outerFn)\n      ? iter // If outerFn is a generator, return the full iterator.\n      : iter.next().then(function(result) {\n          return result.done ? result.value : iter.next();\n        });\n  };\n\n  function makeInvokeMethod(innerFn, self, context) {\n    var state = GenStateSuspendedStart;\n\n    return function invoke(method, arg) {\n      if (state === GenStateExecuting) {\n        throw new Error(\"Generator is already running\");\n      }\n\n      if (state === GenStateCompleted) {\n        if (method === \"throw\") {\n          throw arg;\n        }\n\n        // Be forgiving, per 25.3.3.3.3 of the spec:\n        // https://people.mozilla.org/~jorendorff/es6-draft.html#sec-generatorresume\n        return doneResult();\n      }\n\n      context.method = method;\n      context.arg = arg;\n\n      while (true) {\n        var delegate = context.delegate;\n        if (delegate) {\n          var delegateResult = maybeInvokeDelegate(delegate, context);\n          if (delegateResult) {\n            if (delegateResult === ContinueSentinel) continue;\n            return delegateResult;\n          }\n        }\n\n        if (context.method === \"next\") {\n          // Setting context._sent for legacy support of Babel's\n          // function.sent implementation.\n          context.sent = context._sent = context.arg;\n\n        } else if (context.method === \"throw\") {\n          if (state === GenStateSuspendedStart) {\n            state = GenStateCompleted;\n            throw context.arg;\n          }\n\n          context.dispatchException(context.arg);\n\n        } else if (context.method === \"return\") {\n          context.abrupt(\"return\", context.arg);\n        }\n\n        state = GenStateExecuting;\n\n        var record = tryCatch(innerFn, self, context);\n        if (record.type === \"normal\") {\n          // If an exception is thrown from innerFn, we leave state ===\n          // GenStateExecuting and loop back for another invocation.\n          state = context.done\n            ? GenStateCompleted\n            : GenStateSuspendedYield;\n\n          if (record.arg === ContinueSentinel) {\n            continue;\n          }\n\n          return {\n            value: record.arg,\n            done: context.done\n          };\n\n        } else if (record.type === \"throw\") {\n          state = GenStateCompleted;\n          // Dispatch the exception by looping back around to the\n          // context.dispatchException(context.arg) call above.\n          context.method = \"throw\";\n          context.arg = record.arg;\n        }\n      }\n    };\n  }\n\n  // Call delegate.iterator[context.method](context.arg) and handle the\n  // result, either by returning a { value, done } result from the\n  // delegate iterator, or by modifying context.method and context.arg,\n  // setting context.delegate to null, and returning the ContinueSentinel.\n  function maybeInvokeDelegate(delegate, context) {\n    var method = delegate.iterator[context.method];\n    if (method === undefined) {\n      // A .throw or .return when the delegate iterator has no .throw\n      // method always terminates the yield* loop.\n      context.delegate = null;\n\n      if (context.method === \"throw\") {\n        if (delegate.iterator.return) {\n          // If the delegate iterator has a return method, give it a\n          // chance to clean up.\n          context.method = \"return\";\n          context.arg = undefined;\n          maybeInvokeDelegate(delegate, context);\n\n          if (context.method === \"throw\") {\n            // If maybeInvokeDelegate(context) changed context.method from\n            // \"return\" to \"throw\", let that override the TypeError below.\n            return ContinueSentinel;\n          }\n        }\n\n        context.method = \"throw\";\n        context.arg = new TypeError(\n          \"The iterator does not provide a 'throw' method\");\n      }\n\n      return ContinueSentinel;\n    }\n\n    var record = tryCatch(method, delegate.iterator, context.arg);\n\n    if (record.type === \"throw\") {\n      context.method = \"throw\";\n      context.arg = record.arg;\n      context.delegate = null;\n      return ContinueSentinel;\n    }\n\n    var info = record.arg;\n\n    if (! info) {\n      context.method = \"throw\";\n      context.arg = new TypeError(\"iterator result is not an object\");\n      context.delegate = null;\n      return ContinueSentinel;\n    }\n\n    if (info.done) {\n      // Assign the result of the finished delegate to the temporary\n      // variable specified by delegate.resultName (see delegateYield).\n      context[delegate.resultName] = info.value;\n\n      // Resume execution at the desired location (see delegateYield).\n      context.next = delegate.nextLoc;\n\n      // If context.method was \"throw\" but the delegate handled the\n      // exception, let the outer generator proceed normally. If\n      // context.method was \"next\", forget context.arg since it has been\n      // \"consumed\" by the delegate iterator. If context.method was\n      // \"return\", allow the original .return call to continue in the\n      // outer generator.\n      if (context.method !== \"return\") {\n        context.method = \"next\";\n        context.arg = undefined;\n      }\n\n    } else {\n      // Re-yield the result returned by the delegate method.\n      return info;\n    }\n\n    // The delegate iterator is finished, so forget it and continue with\n    // the outer generator.\n    context.delegate = null;\n    return ContinueSentinel;\n  }\n\n  // Define Generator.prototype.{next,throw,return} in terms of the\n  // unified ._invoke helper method.\n  defineIteratorMethods(Gp);\n\n  Gp[toStringTagSymbol] = \"Generator\";\n\n  // A Generator should always return itself as the iterator object when the\n  // @@iterator function is called on it. Some browsers' implementations of the\n  // iterator prototype chain incorrectly implement this, causing the Generator\n  // object to not be returned from this call. This ensures that doesn't happen.\n  // See https://github.com/facebook/regenerator/issues/274 for more details.\n  Gp[iteratorSymbol] = function() {\n    return this;\n  };\n\n  Gp.toString = function() {\n    return \"[object Generator]\";\n  };\n\n  function pushTryEntry(locs) {\n    var entry = { tryLoc: locs[0] };\n\n    if (1 in locs) {\n      entry.catchLoc = locs[1];\n    }\n\n    if (2 in locs) {\n      entry.finallyLoc = locs[2];\n      entry.afterLoc = locs[3];\n    }\n\n    this.tryEntries.push(entry);\n  }\n\n  function resetTryEntry(entry) {\n    var record = entry.completion || {};\n    record.type = \"normal\";\n    delete record.arg;\n    entry.completion = record;\n  }\n\n  function Context(tryLocsList) {\n    // The root entry object (effectively a try statement without a catch\n    // or a finally block) gives us a place to store values thrown from\n    // locations where there is no enclosing try statement.\n    this.tryEntries = [{ tryLoc: \"root\" }];\n    tryLocsList.forEach(pushTryEntry, this);\n    this.reset(true);\n  }\n\n  runtime.keys = function(object) {\n    var keys = [];\n    for (var key in object) {\n      keys.push(key);\n    }\n    keys.reverse();\n\n    // Rather than returning an object with a next method, we keep\n    // things simple and return the next function itself.\n    return function next() {\n      while (keys.length) {\n        var key = keys.pop();\n        if (key in object) {\n          next.value = key;\n          next.done = false;\n          return next;\n        }\n      }\n\n      // To avoid creating an additional object, we just hang the .value\n      // and .done properties off the next function object itself. This\n      // also ensures that the minifier will not anonymize the function.\n      next.done = true;\n      return next;\n    };\n  };\n\n  function values(iterable) {\n    if (iterable) {\n      var iteratorMethod = iterable[iteratorSymbol];\n      if (iteratorMethod) {\n        return iteratorMethod.call(iterable);\n      }\n\n      if (typeof iterable.next === \"function\") {\n        return iterable;\n      }\n\n      if (!isNaN(iterable.length)) {\n        var i = -1, next = function next() {\n          while (++i < iterable.length) {\n            if (hasOwn.call(iterable, i)) {\n              next.value = iterable[i];\n              next.done = false;\n              return next;\n            }\n          }\n\n          next.value = undefined;\n          next.done = true;\n\n          return next;\n        };\n\n        return next.next = next;\n      }\n    }\n\n    // Return an iterator with no values.\n    return { next: doneResult };\n  }\n  runtime.values = values;\n\n  function doneResult() {\n    return { value: undefined, done: true };\n  }\n\n  Context.prototype = {\n    constructor: Context,\n\n    reset: function(skipTempReset) {\n      this.prev = 0;\n      this.next = 0;\n      // Resetting context._sent for legacy support of Babel's\n      // function.sent implementation.\n      this.sent = this._sent = undefined;\n      this.done = false;\n      this.delegate = null;\n\n      this.method = \"next\";\n      this.arg = undefined;\n\n      this.tryEntries.forEach(resetTryEntry);\n\n      if (!skipTempReset) {\n        for (var name in this) {\n          // Not sure about the optimal order of these conditions:\n          if (name.charAt(0) === \"t\" &&\n              hasOwn.call(this, name) &&\n              !isNaN(+name.slice(1))) {\n            this[name] = undefined;\n          }\n        }\n      }\n    },\n\n    stop: function() {\n      this.done = true;\n\n      var rootEntry = this.tryEntries[0];\n      var rootRecord = rootEntry.completion;\n      if (rootRecord.type === \"throw\") {\n        throw rootRecord.arg;\n      }\n\n      return this.rval;\n    },\n\n    dispatchException: function(exception) {\n      if (this.done) {\n        throw exception;\n      }\n\n      var context = this;\n      function handle(loc, caught) {\n        record.type = \"throw\";\n        record.arg = exception;\n        context.next = loc;\n\n        if (caught) {\n          // If the dispatched exception was caught by a catch block,\n          // then let that catch block handle the exception normally.\n          context.method = \"next\";\n          context.arg = undefined;\n        }\n\n        return !! caught;\n      }\n\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        var record = entry.completion;\n\n        if (entry.tryLoc === \"root\") {\n          // Exception thrown outside of any try block that could handle\n          // it, so set the completion value of the entire function to\n          // throw the exception.\n          return handle(\"end\");\n        }\n\n        if (entry.tryLoc <= this.prev) {\n          var hasCatch = hasOwn.call(entry, \"catchLoc\");\n          var hasFinally = hasOwn.call(entry, \"finallyLoc\");\n\n          if (hasCatch && hasFinally) {\n            if (this.prev < entry.catchLoc) {\n              return handle(entry.catchLoc, true);\n            } else if (this.prev < entry.finallyLoc) {\n              return handle(entry.finallyLoc);\n            }\n\n          } else if (hasCatch) {\n            if (this.prev < entry.catchLoc) {\n              return handle(entry.catchLoc, true);\n            }\n\n          } else if (hasFinally) {\n            if (this.prev < entry.finallyLoc) {\n              return handle(entry.finallyLoc);\n            }\n\n          } else {\n            throw new Error(\"try statement without catch or finally\");\n          }\n        }\n      }\n    },\n\n    abrupt: function(type, arg) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.tryLoc <= this.prev &&\n            hasOwn.call(entry, \"finallyLoc\") &&\n            this.prev < entry.finallyLoc) {\n          var finallyEntry = entry;\n          break;\n        }\n      }\n\n      if (finallyEntry &&\n          (type === \"break\" ||\n           type === \"continue\") &&\n          finallyEntry.tryLoc <= arg &&\n          arg <= finallyEntry.finallyLoc) {\n        // Ignore the finally entry if control is not jumping to a\n        // location outside the try/catch block.\n        finallyEntry = null;\n      }\n\n      var record = finallyEntry ? finallyEntry.completion : {};\n      record.type = type;\n      record.arg = arg;\n\n      if (finallyEntry) {\n        this.method = \"next\";\n        this.next = finallyEntry.finallyLoc;\n        return ContinueSentinel;\n      }\n\n      return this.complete(record);\n    },\n\n    complete: function(record, afterLoc) {\n      if (record.type === \"throw\") {\n        throw record.arg;\n      }\n\n      if (record.type === \"break\" ||\n          record.type === \"continue\") {\n        this.next = record.arg;\n      } else if (record.type === \"return\") {\n        this.rval = this.arg = record.arg;\n        this.method = \"return\";\n        this.next = \"end\";\n      } else if (record.type === \"normal\" && afterLoc) {\n        this.next = afterLoc;\n      }\n\n      return ContinueSentinel;\n    },\n\n    finish: function(finallyLoc) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.finallyLoc === finallyLoc) {\n          this.complete(entry.completion, entry.afterLoc);\n          resetTryEntry(entry);\n          return ContinueSentinel;\n        }\n      }\n    },\n\n    \"catch\": function(tryLoc) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.tryLoc === tryLoc) {\n          var record = entry.completion;\n          if (record.type === \"throw\") {\n            var thrown = record.arg;\n            resetTryEntry(entry);\n          }\n          return thrown;\n        }\n      }\n\n      // The context.catch method must only be called with a location\n      // argument that corresponds to a known catch block.\n      throw new Error(\"illegal catch attempt\");\n    },\n\n    delegateYield: function(iterable, resultName, nextLoc) {\n      this.delegate = {\n        iterator: values(iterable),\n        resultName: resultName,\n        nextLoc: nextLoc\n      };\n\n      if (this.method === \"next\") {\n        // Deliberately forget the last sent value so that we don't\n        // accidentally pass it on to the delegate.\n        this.arg = undefined;\n      }\n\n      return ContinueSentinel;\n    }\n  };\n})(\n  // Among the various tricks for obtaining a reference to the global\n  // object, this seems to be the most reliable technique that does not\n  // use indirect eval (which violates Content Security Policy).\n  typeof global === \"object\" ? global :\n  typeof window === \"object\" ? window :\n  typeof self === \"object\" ? self : this\n);\n\n/* WEBPACK VAR INJECTION */}.call(this, __webpack_require__(/*! ./../../../webpack/buildin/global.js */ \"./node_modules/webpack/buildin/global.js\")))\n\n/***/ }),\n\n/***/ \"./node_modules/base64-js/index.js\":\n/*!*****************************************!*\\\n  !*** ./node_modules/base64-js/index.js ***!\n  \\*****************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nexports.byteLength = byteLength\nexports.toByteArray = toByteArray\nexports.fromByteArray = fromByteArray\n\nvar lookup = []\nvar revLookup = []\nvar Arr = typeof Uint8Array !== 'undefined' ? Uint8Array : Array\n\nvar code = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'\nfor (var i = 0, len = code.length; i < len; ++i) {\n  lookup[i] = code[i]\n  revLookup[code.charCodeAt(i)] = i\n}\n\n// Support decoding URL-safe base64 strings, as Node.js does.\n// See: https://en.wikipedia.org/wiki/Base64#URL_applications\nrevLookup['-'.charCodeAt(0)] = 62\nrevLookup['_'.charCodeAt(0)] = 63\n\nfunction getLens (b64) {\n  var len = b64.length\n\n  if (len % 4 > 0) {\n    throw new Error('Invalid string. Length must be a multiple of 4')\n  }\n\n  // Trim off extra bytes after placeholder bytes are found\n  // See: https://github.com/beatgammit/base64-js/issues/42\n  var validLen = b64.indexOf('=')\n  if (validLen === -1) validLen = len\n\n  var placeHoldersLen = validLen === len\n    ? 0\n    : 4 - (validLen % 4)\n\n  return [validLen, placeHoldersLen]\n}\n\n// base64 is 4/3 + up to two characters of the original data\nfunction byteLength (b64) {\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction _byteLength (b64, validLen, placeHoldersLen) {\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction toByteArray (b64) {\n  var tmp\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n\n  var arr = new Arr(_byteLength(b64, validLen, placeHoldersLen))\n\n  var curByte = 0\n\n  // if there are placeholders, only get up to the last complete 4 chars\n  var len = placeHoldersLen > 0\n    ? validLen - 4\n    : validLen\n\n  for (var i = 0; i < len; i += 4) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 18) |\n      (revLookup[b64.charCodeAt(i + 1)] << 12) |\n      (revLookup[b64.charCodeAt(i + 2)] << 6) |\n      revLookup[b64.charCodeAt(i + 3)]\n    arr[curByte++] = (tmp >> 16) & 0xFF\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 2) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 2) |\n      (revLookup[b64.charCodeAt(i + 1)] >> 4)\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 1) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 10) |\n      (revLookup[b64.charCodeAt(i + 1)] << 4) |\n      (revLookup[b64.charCodeAt(i + 2)] >> 2)\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  return arr\n}\n\nfunction tripletToBase64 (num) {\n  return lookup[num >> 18 & 0x3F] +\n    lookup[num >> 12 & 0x3F] +\n    lookup[num >> 6 & 0x3F] +\n    lookup[num & 0x3F]\n}\n\nfunction encodeChunk (uint8, start, end) {\n  var tmp\n  var output = []\n  for (var i = start; i < end; i += 3) {\n    tmp =\n      ((uint8[i] << 16) & 0xFF0000) +\n      ((uint8[i + 1] << 8) & 0xFF00) +\n      (uint8[i + 2] & 0xFF)\n    output.push(tripletToBase64(tmp))\n  }\n  return output.join('')\n}\n\nfunction fromByteArray (uint8) {\n  var tmp\n  var len = uint8.length\n  var extraBytes = len % 3 // if we have 1 byte left, pad 2 bytes\n  var parts = []\n  var maxChunkLength = 16383 // must be multiple of 3\n\n  // go through the array every three bytes, we'll deal with trailing stuff later\n  for (var i = 0, len2 = len - extraBytes; i < len2; i += maxChunkLength) {\n    parts.push(encodeChunk(\n      uint8, i, (i + maxChunkLength) > len2 ? len2 : (i + maxChunkLength)\n    ))\n  }\n\n  // pad the end with zeros, but make sure to not forget the extra bytes\n  if (extraBytes === 1) {\n    tmp = uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 2] +\n      lookup[(tmp << 4) & 0x3F] +\n      '=='\n    )\n  } else if (extraBytes === 2) {\n    tmp = (uint8[len - 2] << 8) + uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 10] +\n      lookup[(tmp >> 4) & 0x3F] +\n      lookup[(tmp << 2) & 0x3F] +\n      '='\n    )\n  }\n\n  return parts.join('')\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/buffer/index.js\":\n/*!**************************************!*\\\n  !*** ./node_modules/buffer/index.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n/* WEBPACK VAR INJECTION */(function(global) {/*!\n * The buffer module from node.js, for the browser.\n *\n * @author   Feross Aboukhadijeh <feross@feross.org> <http://feross.org>\n * @license  MIT\n */\n/* eslint-disable no-proto */\n\n\n\nvar base64 = __webpack_require__(/*! base64-js */ \"./node_modules/base64-js/index.js\")\nvar ieee754 = __webpack_require__(/*! ieee754 */ \"./node_modules/ieee754/index.js\")\nvar isArray = __webpack_require__(/*! isarray */ \"./node_modules/buffer/node_modules/isarray/index.js\")\n\nexports.Buffer = Buffer\nexports.SlowBuffer = SlowBuffer\nexports.INSPECT_MAX_BYTES = 50\n\n/**\n * If `Buffer.TYPED_ARRAY_SUPPORT`:\n *   === true    Use Uint8Array implementation (fastest)\n *   === false   Use Object implementation (most compatible, even IE6)\n *\n * Browsers that support typed arrays are IE 10+, Firefox 4+, Chrome 7+, Safari 5.1+,\n * Opera 11.6+, iOS 4.2+.\n *\n * Due to various browser bugs, sometimes the Object implementation will be used even\n * when the browser supports typed arrays.\n *\n * Note:\n *\n *   - Firefox 4-29 lacks support for adding new properties to `Uint8Array` instances,\n *     See: https://bugzilla.mozilla.org/show_bug.cgi?id=695438.\n *\n *   - Chrome 9-10 is missing the `TypedArray.prototype.subarray` function.\n *\n *   - IE10 has a broken `TypedArray.prototype.subarray` function which returns arrays of\n *     incorrect length in some situations.\n\n * We detect these buggy browsers and set `Buffer.TYPED_ARRAY_SUPPORT` to `false` so they\n * get the Object implementation, which is slower but behaves correctly.\n */\nBuffer.TYPED_ARRAY_SUPPORT = global.TYPED_ARRAY_SUPPORT !== undefined\n  ? global.TYPED_ARRAY_SUPPORT\n  : typedArraySupport()\n\n/*\n * Export kMaxLength after typed array support is determined.\n */\nexports.kMaxLength = kMaxLength()\n\nfunction typedArraySupport () {\n  try {\n    var arr = new Uint8Array(1)\n    arr.__proto__ = {__proto__: Uint8Array.prototype, foo: function () { return 42 }}\n    return arr.foo() === 42 && // typed array instances can be augmented\n        typeof arr.subarray === 'function' && // chrome 9-10 lack `subarray`\n        arr.subarray(1, 1).byteLength === 0 // ie10 has broken `subarray`\n  } catch (e) {\n    return false\n  }\n}\n\nfunction kMaxLength () {\n  return Buffer.TYPED_ARRAY_SUPPORT\n    ? 0x7fffffff\n    : 0x3fffffff\n}\n\nfunction createBuffer (that, length) {\n  if (kMaxLength() < length) {\n    throw new RangeError('Invalid typed array length')\n  }\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = new Uint8Array(length)\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    if (that === null) {\n      that = new Buffer(length)\n    }\n    that.length = length\n  }\n\n  return that\n}\n\n/**\n * The Buffer constructor returns instances of `Uint8Array` that have their\n * prototype changed to `Buffer.prototype`. Furthermore, `Buffer` is a subclass of\n * `Uint8Array`, so the returned instances will have all the node `Buffer` methods\n * and the `Uint8Array` methods. Square bracket notation works as expected -- it\n * returns a single octet.\n *\n * The `Uint8Array` prototype remains unmodified.\n */\n\nfunction Buffer (arg, encodingOrOffset, length) {\n  if (!Buffer.TYPED_ARRAY_SUPPORT && !(this instanceof Buffer)) {\n    return new Buffer(arg, encodingOrOffset, length)\n  }\n\n  // Common case.\n  if (typeof arg === 'number') {\n    if (typeof encodingOrOffset === 'string') {\n      throw new Error(\n        'If encoding is specified then the first argument must be a string'\n      )\n    }\n    return allocUnsafe(this, arg)\n  }\n  return from(this, arg, encodingOrOffset, length)\n}\n\nBuffer.poolSize = 8192 // not used by this implementation\n\n// TODO: Legacy, not needed anymore. Remove in next major version.\nBuffer._augment = function (arr) {\n  arr.__proto__ = Buffer.prototype\n  return arr\n}\n\nfunction from (that, value, encodingOrOffset, length) {\n  if (typeof value === 'number') {\n    throw new TypeError('\"value\" argument must not be a number')\n  }\n\n  if (typeof ArrayBuffer !== 'undefined' && value instanceof ArrayBuffer) {\n    return fromArrayBuffer(that, value, encodingOrOffset, length)\n  }\n\n  if (typeof value === 'string') {\n    return fromString(that, value, encodingOrOffset)\n  }\n\n  return fromObject(that, value)\n}\n\n/**\n * Functionally equivalent to Buffer(arg, encoding) but throws a TypeError\n * if value is a number.\n * Buffer.from(str[, encoding])\n * Buffer.from(array)\n * Buffer.from(buffer)\n * Buffer.from(arrayBuffer[, byteOffset[, length]])\n **/\nBuffer.from = function (value, encodingOrOffset, length) {\n  return from(null, value, encodingOrOffset, length)\n}\n\nif (Buffer.TYPED_ARRAY_SUPPORT) {\n  Buffer.prototype.__proto__ = Uint8Array.prototype\n  Buffer.__proto__ = Uint8Array\n  if (typeof Symbol !== 'undefined' && Symbol.species &&\n      Buffer[Symbol.species] === Buffer) {\n    // Fix subarray() in ES2016. See: https://github.com/feross/buffer/pull/97\n    Object.defineProperty(Buffer, Symbol.species, {\n      value: null,\n      configurable: true\n    })\n  }\n}\n\nfunction assertSize (size) {\n  if (typeof size !== 'number') {\n    throw new TypeError('\"size\" argument must be a number')\n  } else if (size < 0) {\n    throw new RangeError('\"size\" argument must not be negative')\n  }\n}\n\nfunction alloc (that, size, fill, encoding) {\n  assertSize(size)\n  if (size <= 0) {\n    return createBuffer(that, size)\n  }\n  if (fill !== undefined) {\n    // Only pay attention to encoding if it's a string. This\n    // prevents accidentally sending in a number that would\n    // be interpretted as a start offset.\n    return typeof encoding === 'string'\n      ? createBuffer(that, size).fill(fill, encoding)\n      : createBuffer(that, size).fill(fill)\n  }\n  return createBuffer(that, size)\n}\n\n/**\n * Creates a new filled Buffer instance.\n * alloc(size[, fill[, encoding]])\n **/\nBuffer.alloc = function (size, fill, encoding) {\n  return alloc(null, size, fill, encoding)\n}\n\nfunction allocUnsafe (that, size) {\n  assertSize(size)\n  that = createBuffer(that, size < 0 ? 0 : checked(size) | 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) {\n    for (var i = 0; i < size; ++i) {\n      that[i] = 0\n    }\n  }\n  return that\n}\n\n/**\n * Equivalent to Buffer(num), by default creates a non-zero-filled Buffer instance.\n * */\nBuffer.allocUnsafe = function (size) {\n  return allocUnsafe(null, size)\n}\n/**\n * Equivalent to SlowBuffer(num), by default creates a non-zero-filled Buffer instance.\n */\nBuffer.allocUnsafeSlow = function (size) {\n  return allocUnsafe(null, size)\n}\n\nfunction fromString (that, string, encoding) {\n  if (typeof encoding !== 'string' || encoding === '') {\n    encoding = 'utf8'\n  }\n\n  if (!Buffer.isEncoding(encoding)) {\n    throw new TypeError('\"encoding\" must be a valid string encoding')\n  }\n\n  var length = byteLength(string, encoding) | 0\n  that = createBuffer(that, length)\n\n  var actual = that.write(string, encoding)\n\n  if (actual !== length) {\n    // Writing a hex string, for example, that contains invalid characters will\n    // cause everything after the first invalid character to be ignored. (e.g.\n    // 'abxxcd' will be treated as 'ab')\n    that = that.slice(0, actual)\n  }\n\n  return that\n}\n\nfunction fromArrayLike (that, array) {\n  var length = array.length < 0 ? 0 : checked(array.length) | 0\n  that = createBuffer(that, length)\n  for (var i = 0; i < length; i += 1) {\n    that[i] = array[i] & 255\n  }\n  return that\n}\n\nfunction fromArrayBuffer (that, array, byteOffset, length) {\n  array.byteLength // this throws if `array` is not a valid ArrayBuffer\n\n  if (byteOffset < 0 || array.byteLength < byteOffset) {\n    throw new RangeError('\\'offset\\' is out of bounds')\n  }\n\n  if (array.byteLength < byteOffset + (length || 0)) {\n    throw new RangeError('\\'length\\' is out of bounds')\n  }\n\n  if (byteOffset === undefined && length === undefined) {\n    array = new Uint8Array(array)\n  } else if (length === undefined) {\n    array = new Uint8Array(array, byteOffset)\n  } else {\n    array = new Uint8Array(array, byteOffset, length)\n  }\n\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = array\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    that = fromArrayLike(that, array)\n  }\n  return that\n}\n\nfunction fromObject (that, obj) {\n  if (Buffer.isBuffer(obj)) {\n    var len = checked(obj.length) | 0\n    that = createBuffer(that, len)\n\n    if (that.length === 0) {\n      return that\n    }\n\n    obj.copy(that, 0, 0, len)\n    return that\n  }\n\n  if (obj) {\n    if ((typeof ArrayBuffer !== 'undefined' &&\n        obj.buffer instanceof ArrayBuffer) || 'length' in obj) {\n      if (typeof obj.length !== 'number' || isnan(obj.length)) {\n        return createBuffer(that, 0)\n      }\n      return fromArrayLike(that, obj)\n    }\n\n    if (obj.type === 'Buffer' && isArray(obj.data)) {\n      return fromArrayLike(that, obj.data)\n    }\n  }\n\n  throw new TypeError('First argument must be a string, Buffer, ArrayBuffer, Array, or array-like object.')\n}\n\nfunction checked (length) {\n  // Note: cannot use `length < kMaxLength()` here because that fails when\n  // length is NaN (which is otherwise coerced to zero.)\n  if (length >= kMaxLength()) {\n    throw new RangeError('Attempt to allocate Buffer larger than maximum ' +\n                         'size: 0x' + kMaxLength().toString(16) + ' bytes')\n  }\n  return length | 0\n}\n\nfunction SlowBuffer (length) {\n  if (+length != length) { // eslint-disable-line eqeqeq\n    length = 0\n  }\n  return Buffer.alloc(+length)\n}\n\nBuffer.isBuffer = function isBuffer (b) {\n  return !!(b != null && b._isBuffer)\n}\n\nBuffer.compare = function compare (a, b) {\n  if (!Buffer.isBuffer(a) || !Buffer.isBuffer(b)) {\n    throw new TypeError('Arguments must be Buffers')\n  }\n\n  if (a === b) return 0\n\n  var x = a.length\n  var y = b.length\n\n  for (var i = 0, len = Math.min(x, y); i < len; ++i) {\n    if (a[i] !== b[i]) {\n      x = a[i]\n      y = b[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\nBuffer.isEncoding = function isEncoding (encoding) {\n  switch (String(encoding).toLowerCase()) {\n    case 'hex':\n    case 'utf8':\n    case 'utf-8':\n    case 'ascii':\n    case 'latin1':\n    case 'binary':\n    case 'base64':\n    case 'ucs2':\n    case 'ucs-2':\n    case 'utf16le':\n    case 'utf-16le':\n      return true\n    default:\n      return false\n  }\n}\n\nBuffer.concat = function concat (list, length) {\n  if (!isArray(list)) {\n    throw new TypeError('\"list\" argument must be an Array of Buffers')\n  }\n\n  if (list.length === 0) {\n    return Buffer.alloc(0)\n  }\n\n  var i\n  if (length === undefined) {\n    length = 0\n    for (i = 0; i < list.length; ++i) {\n      length += list[i].length\n    }\n  }\n\n  var buffer = Buffer.allocUnsafe(length)\n  var pos = 0\n  for (i = 0; i < list.length; ++i) {\n    var buf = list[i]\n    if (!Buffer.isBuffer(buf)) {\n      throw new TypeError('\"list\" argument must be an Array of Buffers')\n    }\n    buf.copy(buffer, pos)\n    pos += buf.length\n  }\n  return buffer\n}\n\nfunction byteLength (string, encoding) {\n  if (Buffer.isBuffer(string)) {\n    return string.length\n  }\n  if (typeof ArrayBuffer !== 'undefined' && typeof ArrayBuffer.isView === 'function' &&\n      (ArrayBuffer.isView(string) || string instanceof ArrayBuffer)) {\n    return string.byteLength\n  }\n  if (typeof string !== 'string') {\n    string = '' + string\n  }\n\n  var len = string.length\n  if (len === 0) return 0\n\n  // Use a for loop to avoid recursion\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'ascii':\n      case 'latin1':\n      case 'binary':\n        return len\n      case 'utf8':\n      case 'utf-8':\n      case undefined:\n        return utf8ToBytes(string).length\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return len * 2\n      case 'hex':\n        return len >>> 1\n      case 'base64':\n        return base64ToBytes(string).length\n      default:\n        if (loweredCase) return utf8ToBytes(string).length // assume utf8\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\nBuffer.byteLength = byteLength\n\nfunction slowToString (encoding, start, end) {\n  var loweredCase = false\n\n  // No need to verify that \"this.length <= MAX_UINT32\" since it's a read-only\n  // property of a typed array.\n\n  // This behaves neither like String nor Uint8Array in that we set start/end\n  // to their upper/lower bounds if the value passed is out of range.\n  // undefined is handled specially as per ECMA-262 6th Edition,\n  // Section 13.3.3.7 Runtime Semantics: KeyedBindingInitialization.\n  if (start === undefined || start < 0) {\n    start = 0\n  }\n  // Return early if start > this.length. Done here to prevent potential uint32\n  // coercion fail below.\n  if (start > this.length) {\n    return ''\n  }\n\n  if (end === undefined || end > this.length) {\n    end = this.length\n  }\n\n  if (end <= 0) {\n    return ''\n  }\n\n  // Force coersion to uint32. This will also coerce falsey/NaN values to 0.\n  end >>>= 0\n  start >>>= 0\n\n  if (end <= start) {\n    return ''\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  while (true) {\n    switch (encoding) {\n      case 'hex':\n        return hexSlice(this, start, end)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Slice(this, start, end)\n\n      case 'ascii':\n        return asciiSlice(this, start, end)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Slice(this, start, end)\n\n      case 'base64':\n        return base64Slice(this, start, end)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return utf16leSlice(this, start, end)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = (encoding + '').toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\n// The property is used by `Buffer.isBuffer` and `is-buffer` (in Safari 5-7) to detect\n// Buffer instances.\nBuffer.prototype._isBuffer = true\n\nfunction swap (b, n, m) {\n  var i = b[n]\n  b[n] = b[m]\n  b[m] = i\n}\n\nBuffer.prototype.swap16 = function swap16 () {\n  var len = this.length\n  if (len % 2 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 16-bits')\n  }\n  for (var i = 0; i < len; i += 2) {\n    swap(this, i, i + 1)\n  }\n  return this\n}\n\nBuffer.prototype.swap32 = function swap32 () {\n  var len = this.length\n  if (len % 4 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 32-bits')\n  }\n  for (var i = 0; i < len; i += 4) {\n    swap(this, i, i + 3)\n    swap(this, i + 1, i + 2)\n  }\n  return this\n}\n\nBuffer.prototype.swap64 = function swap64 () {\n  var len = this.length\n  if (len % 8 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 64-bits')\n  }\n  for (var i = 0; i < len; i += 8) {\n    swap(this, i, i + 7)\n    swap(this, i + 1, i + 6)\n    swap(this, i + 2, i + 5)\n    swap(this, i + 3, i + 4)\n  }\n  return this\n}\n\nBuffer.prototype.toString = function toString () {\n  var length = this.length | 0\n  if (length === 0) return ''\n  if (arguments.length === 0) return utf8Slice(this, 0, length)\n  return slowToString.apply(this, arguments)\n}\n\nBuffer.prototype.equals = function equals (b) {\n  if (!Buffer.isBuffer(b)) throw new TypeError('Argument must be a Buffer')\n  if (this === b) return true\n  return Buffer.compare(this, b) === 0\n}\n\nBuffer.prototype.inspect = function inspect () {\n  var str = ''\n  var max = exports.INSPECT_MAX_BYTES\n  if (this.length > 0) {\n    str = this.toString('hex', 0, max).match(/.{2}/g).join(' ')\n    if (this.length > max) str += ' ... '\n  }\n  return '<Buffer ' + str + '>'\n}\n\nBuffer.prototype.compare = function compare (target, start, end, thisStart, thisEnd) {\n  if (!Buffer.isBuffer(target)) {\n    throw new TypeError('Argument must be a Buffer')\n  }\n\n  if (start === undefined) {\n    start = 0\n  }\n  if (end === undefined) {\n    end = target ? target.length : 0\n  }\n  if (thisStart === undefined) {\n    thisStart = 0\n  }\n  if (thisEnd === undefined) {\n    thisEnd = this.length\n  }\n\n  if (start < 0 || end > target.length || thisStart < 0 || thisEnd > this.length) {\n    throw new RangeError('out of range index')\n  }\n\n  if (thisStart >= thisEnd && start >= end) {\n    return 0\n  }\n  if (thisStart >= thisEnd) {\n    return -1\n  }\n  if (start >= end) {\n    return 1\n  }\n\n  start >>>= 0\n  end >>>= 0\n  thisStart >>>= 0\n  thisEnd >>>= 0\n\n  if (this === target) return 0\n\n  var x = thisEnd - thisStart\n  var y = end - start\n  var len = Math.min(x, y)\n\n  var thisCopy = this.slice(thisStart, thisEnd)\n  var targetCopy = target.slice(start, end)\n\n  for (var i = 0; i < len; ++i) {\n    if (thisCopy[i] !== targetCopy[i]) {\n      x = thisCopy[i]\n      y = targetCopy[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\n// Finds either the first index of `val` in `buffer` at offset >= `byteOffset`,\n// OR the last index of `val` in `buffer` at offset <= `byteOffset`.\n//\n// Arguments:\n// - buffer - a Buffer to search\n// - val - a string, Buffer, or number\n// - byteOffset - an index into `buffer`; will be clamped to an int32\n// - encoding - an optional encoding, relevant is val is a string\n// - dir - true for indexOf, false for lastIndexOf\nfunction bidirectionalIndexOf (buffer, val, byteOffset, encoding, dir) {\n  // Empty buffer means no match\n  if (buffer.length === 0) return -1\n\n  // Normalize byteOffset\n  if (typeof byteOffset === 'string') {\n    encoding = byteOffset\n    byteOffset = 0\n  } else if (byteOffset > 0x7fffffff) {\n    byteOffset = 0x7fffffff\n  } else if (byteOffset < -0x80000000) {\n    byteOffset = -0x80000000\n  }\n  byteOffset = +byteOffset  // Coerce to Number.\n  if (isNaN(byteOffset)) {\n    // byteOffset: it it's undefined, null, NaN, \"foo\", etc, search whole buffer\n    byteOffset = dir ? 0 : (buffer.length - 1)\n  }\n\n  // Normalize byteOffset: negative offsets start from the end of the buffer\n  if (byteOffset < 0) byteOffset = buffer.length + byteOffset\n  if (byteOffset >= buffer.length) {\n    if (dir) return -1\n    else byteOffset = buffer.length - 1\n  } else if (byteOffset < 0) {\n    if (dir) byteOffset = 0\n    else return -1\n  }\n\n  // Normalize val\n  if (typeof val === 'string') {\n    val = Buffer.from(val, encoding)\n  }\n\n  // Finally, search either indexOf (if dir is true) or lastIndexOf\n  if (Buffer.isBuffer(val)) {\n    // Special case: looking for empty string/buffer always fails\n    if (val.length === 0) {\n      return -1\n    }\n    return arrayIndexOf(buffer, val, byteOffset, encoding, dir)\n  } else if (typeof val === 'number') {\n    val = val & 0xFF // Search for a byte value [0-255]\n    if (Buffer.TYPED_ARRAY_SUPPORT &&\n        typeof Uint8Array.prototype.indexOf === 'function') {\n      if (dir) {\n        return Uint8Array.prototype.indexOf.call(buffer, val, byteOffset)\n      } else {\n        return Uint8Array.prototype.lastIndexOf.call(buffer, val, byteOffset)\n      }\n    }\n    return arrayIndexOf(buffer, [ val ], byteOffset, encoding, dir)\n  }\n\n  throw new TypeError('val must be string, number or Buffer')\n}\n\nfunction arrayIndexOf (arr, val, byteOffset, encoding, dir) {\n  var indexSize = 1\n  var arrLength = arr.length\n  var valLength = val.length\n\n  if (encoding !== undefined) {\n    encoding = String(encoding).toLowerCase()\n    if (encoding === 'ucs2' || encoding === 'ucs-2' ||\n        encoding === 'utf16le' || encoding === 'utf-16le') {\n      if (arr.length < 2 || val.length < 2) {\n        return -1\n      }\n      indexSize = 2\n      arrLength /= 2\n      valLength /= 2\n      byteOffset /= 2\n    }\n  }\n\n  function read (buf, i) {\n    if (indexSize === 1) {\n      return buf[i]\n    } else {\n      return buf.readUInt16BE(i * indexSize)\n    }\n  }\n\n  var i\n  if (dir) {\n    var foundIndex = -1\n    for (i = byteOffset; i < arrLength; i++) {\n      if (read(arr, i) === read(val, foundIndex === -1 ? 0 : i - foundIndex)) {\n        if (foundIndex === -1) foundIndex = i\n        if (i - foundIndex + 1 === valLength) return foundIndex * indexSize\n      } else {\n        if (foundIndex !== -1) i -= i - foundIndex\n        foundIndex = -1\n      }\n    }\n  } else {\n    if (byteOffset + valLength > arrLength) byteOffset = arrLength - valLength\n    for (i = byteOffset; i >= 0; i--) {\n      var found = true\n      for (var j = 0; j < valLength; j++) {\n        if (read(arr, i + j) !== read(val, j)) {\n          found = false\n          break\n        }\n      }\n      if (found) return i\n    }\n  }\n\n  return -1\n}\n\nBuffer.prototype.includes = function includes (val, byteOffset, encoding) {\n  return this.indexOf(val, byteOffset, encoding) !== -1\n}\n\nBuffer.prototype.indexOf = function indexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, true)\n}\n\nBuffer.prototype.lastIndexOf = function lastIndexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, false)\n}\n\nfunction hexWrite (buf, string, offset, length) {\n  offset = Number(offset) || 0\n  var remaining = buf.length - offset\n  if (!length) {\n    length = remaining\n  } else {\n    length = Number(length)\n    if (length > remaining) {\n      length = remaining\n    }\n  }\n\n  // must be an even number of digits\n  var strLen = string.length\n  if (strLen % 2 !== 0) throw new TypeError('Invalid hex string')\n\n  if (length > strLen / 2) {\n    length = strLen / 2\n  }\n  for (var i = 0; i < length; ++i) {\n    var parsed = parseInt(string.substr(i * 2, 2), 16)\n    if (isNaN(parsed)) return i\n    buf[offset + i] = parsed\n  }\n  return i\n}\n\nfunction utf8Write (buf, string, offset, length) {\n  return blitBuffer(utf8ToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nfunction asciiWrite (buf, string, offset, length) {\n  return blitBuffer(asciiToBytes(string), buf, offset, length)\n}\n\nfunction latin1Write (buf, string, offset, length) {\n  return asciiWrite(buf, string, offset, length)\n}\n\nfunction base64Write (buf, string, offset, length) {\n  return blitBuffer(base64ToBytes(string), buf, offset, length)\n}\n\nfunction ucs2Write (buf, string, offset, length) {\n  return blitBuffer(utf16leToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nBuffer.prototype.write = function write (string, offset, length, encoding) {\n  // Buffer#write(string)\n  if (offset === undefined) {\n    encoding = 'utf8'\n    length = this.length\n    offset = 0\n  // Buffer#write(string, encoding)\n  } else if (length === undefined && typeof offset === 'string') {\n    encoding = offset\n    length = this.length\n    offset = 0\n  // Buffer#write(string, offset[, length][, encoding])\n  } else if (isFinite(offset)) {\n    offset = offset | 0\n    if (isFinite(length)) {\n      length = length | 0\n      if (encoding === undefined) encoding = 'utf8'\n    } else {\n      encoding = length\n      length = undefined\n    }\n  // legacy write(string, encoding, offset, length) - remove in v0.13\n  } else {\n    throw new Error(\n      'Buffer.write(string, encoding, offset[, length]) is no longer supported'\n    )\n  }\n\n  var remaining = this.length - offset\n  if (length === undefined || length > remaining) length = remaining\n\n  if ((string.length > 0 && (length < 0 || offset < 0)) || offset > this.length) {\n    throw new RangeError('Attempt to write outside buffer bounds')\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'hex':\n        return hexWrite(this, string, offset, length)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Write(this, string, offset, length)\n\n      case 'ascii':\n        return asciiWrite(this, string, offset, length)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Write(this, string, offset, length)\n\n      case 'base64':\n        // Warning: maxLength not taken into account in base64Write\n        return base64Write(this, string, offset, length)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return ucs2Write(this, string, offset, length)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\nBuffer.prototype.toJSON = function toJSON () {\n  return {\n    type: 'Buffer',\n    data: Array.prototype.slice.call(this._arr || this, 0)\n  }\n}\n\nfunction base64Slice (buf, start, end) {\n  if (start === 0 && end === buf.length) {\n    return base64.fromByteArray(buf)\n  } else {\n    return base64.fromByteArray(buf.slice(start, end))\n  }\n}\n\nfunction utf8Slice (buf, start, end) {\n  end = Math.min(buf.length, end)\n  var res = []\n\n  var i = start\n  while (i < end) {\n    var firstByte = buf[i]\n    var codePoint = null\n    var bytesPerSequence = (firstByte > 0xEF) ? 4\n      : (firstByte > 0xDF) ? 3\n      : (firstByte > 0xBF) ? 2\n      : 1\n\n    if (i + bytesPerSequence <= end) {\n      var secondByte, thirdByte, fourthByte, tempCodePoint\n\n      switch (bytesPerSequence) {\n        case 1:\n          if (firstByte < 0x80) {\n            codePoint = firstByte\n          }\n          break\n        case 2:\n          secondByte = buf[i + 1]\n          if ((secondByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0x1F) << 0x6 | (secondByte & 0x3F)\n            if (tempCodePoint > 0x7F) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 3:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0xC | (secondByte & 0x3F) << 0x6 | (thirdByte & 0x3F)\n            if (tempCodePoint > 0x7FF && (tempCodePoint < 0xD800 || tempCodePoint > 0xDFFF)) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 4:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          fourthByte = buf[i + 3]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80 && (fourthByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0x12 | (secondByte & 0x3F) << 0xC | (thirdByte & 0x3F) << 0x6 | (fourthByte & 0x3F)\n            if (tempCodePoint > 0xFFFF && tempCodePoint < 0x110000) {\n              codePoint = tempCodePoint\n            }\n          }\n      }\n    }\n\n    if (codePoint === null) {\n      // we did not generate a valid codePoint so insert a\n      // replacement char (U+FFFD) and advance only 1 byte\n      codePoint = 0xFFFD\n      bytesPerSequence = 1\n    } else if (codePoint > 0xFFFF) {\n      // encode to utf16 (surrogate pair dance)\n      codePoint -= 0x10000\n      res.push(codePoint >>> 10 & 0x3FF | 0xD800)\n      codePoint = 0xDC00 | codePoint & 0x3FF\n    }\n\n    res.push(codePoint)\n    i += bytesPerSequence\n  }\n\n  return decodeCodePointsArray(res)\n}\n\n// Based on http://stackoverflow.com/a/22747272/680742, the browser with\n// the lowest limit is Chrome, with 0x10000 args.\n// We go 1 magnitude less, for safety\nvar MAX_ARGUMENTS_LENGTH = 0x1000\n\nfunction decodeCodePointsArray (codePoints) {\n  var len = codePoints.length\n  if (len <= MAX_ARGUMENTS_LENGTH) {\n    return String.fromCharCode.apply(String, codePoints) // avoid extra slice()\n  }\n\n  // Decode in chunks to avoid \"call stack size exceeded\".\n  var res = ''\n  var i = 0\n  while (i < len) {\n    res += String.fromCharCode.apply(\n      String,\n      codePoints.slice(i, i += MAX_ARGUMENTS_LENGTH)\n    )\n  }\n  return res\n}\n\nfunction asciiSlice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i] & 0x7F)\n  }\n  return ret\n}\n\nfunction latin1Slice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i])\n  }\n  return ret\n}\n\nfunction hexSlice (buf, start, end) {\n  var len = buf.length\n\n  if (!start || start < 0) start = 0\n  if (!end || end < 0 || end > len) end = len\n\n  var out = ''\n  for (var i = start; i < end; ++i) {\n    out += toHex(buf[i])\n  }\n  return out\n}\n\nfunction utf16leSlice (buf, start, end) {\n  var bytes = buf.slice(start, end)\n  var res = ''\n  for (var i = 0; i < bytes.length; i += 2) {\n    res += String.fromCharCode(bytes[i] + bytes[i + 1] * 256)\n  }\n  return res\n}\n\nBuffer.prototype.slice = function slice (start, end) {\n  var len = this.length\n  start = ~~start\n  end = end === undefined ? len : ~~end\n\n  if (start < 0) {\n    start += len\n    if (start < 0) start = 0\n  } else if (start > len) {\n    start = len\n  }\n\n  if (end < 0) {\n    end += len\n    if (end < 0) end = 0\n  } else if (end > len) {\n    end = len\n  }\n\n  if (end < start) end = start\n\n  var newBuf\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    newBuf = this.subarray(start, end)\n    newBuf.__proto__ = Buffer.prototype\n  } else {\n    var sliceLen = end - start\n    newBuf = new Buffer(sliceLen, undefined)\n    for (var i = 0; i < sliceLen; ++i) {\n      newBuf[i] = this[i + start]\n    }\n  }\n\n  return newBuf\n}\n\n/*\n * Need to make sure that buffer isn't trying to write out of bounds.\n */\nfunction checkOffset (offset, ext, length) {\n  if ((offset % 1) !== 0 || offset < 0) throw new RangeError('offset is not uint')\n  if (offset + ext > length) throw new RangeError('Trying to access beyond buffer length')\n}\n\nBuffer.prototype.readUIntLE = function readUIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUIntBE = function readUIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    checkOffset(offset, byteLength, this.length)\n  }\n\n  var val = this[offset + --byteLength]\n  var mul = 1\n  while (byteLength > 0 && (mul *= 0x100)) {\n    val += this[offset + --byteLength] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUInt8 = function readUInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  return this[offset]\n}\n\nBuffer.prototype.readUInt16LE = function readUInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return this[offset] | (this[offset + 1] << 8)\n}\n\nBuffer.prototype.readUInt16BE = function readUInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return (this[offset] << 8) | this[offset + 1]\n}\n\nBuffer.prototype.readUInt32LE = function readUInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return ((this[offset]) |\n      (this[offset + 1] << 8) |\n      (this[offset + 2] << 16)) +\n      (this[offset + 3] * 0x1000000)\n}\n\nBuffer.prototype.readUInt32BE = function readUInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] * 0x1000000) +\n    ((this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    this[offset + 3])\n}\n\nBuffer.prototype.readIntLE = function readIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readIntBE = function readIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var i = byteLength\n  var mul = 1\n  var val = this[offset + --i]\n  while (i > 0 && (mul *= 0x100)) {\n    val += this[offset + --i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readInt8 = function readInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  if (!(this[offset] & 0x80)) return (this[offset])\n  return ((0xff - this[offset] + 1) * -1)\n}\n\nBuffer.prototype.readInt16LE = function readInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset] | (this[offset + 1] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt16BE = function readInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset + 1] | (this[offset] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt32LE = function readInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset]) |\n    (this[offset + 1] << 8) |\n    (this[offset + 2] << 16) |\n    (this[offset + 3] << 24)\n}\n\nBuffer.prototype.readInt32BE = function readInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] << 24) |\n    (this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    (this[offset + 3])\n}\n\nBuffer.prototype.readFloatLE = function readFloatLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, true, 23, 4)\n}\n\nBuffer.prototype.readFloatBE = function readFloatBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, false, 23, 4)\n}\n\nBuffer.prototype.readDoubleLE = function readDoubleLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, true, 52, 8)\n}\n\nBuffer.prototype.readDoubleBE = function readDoubleBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, false, 52, 8)\n}\n\nfunction checkInt (buf, value, offset, ext, max, min) {\n  if (!Buffer.isBuffer(buf)) throw new TypeError('\"buffer\" argument must be a Buffer instance')\n  if (value > max || value < min) throw new RangeError('\"value\" argument is out of bounds')\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n}\n\nBuffer.prototype.writeUIntLE = function writeUIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var mul = 1\n  var i = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUIntBE = function writeUIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUInt8 = function writeUInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0xff, 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nfunction objectWriteUInt16 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 2); i < j; ++i) {\n    buf[offset + i] = (value & (0xff << (8 * (littleEndian ? i : 1 - i)))) >>>\n      (littleEndian ? i : 1 - i) * 8\n  }\n}\n\nBuffer.prototype.writeUInt16LE = function writeUInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeUInt16BE = function writeUInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nfunction objectWriteUInt32 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffffffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 4); i < j; ++i) {\n    buf[offset + i] = (value >>> (littleEndian ? i : 3 - i) * 8) & 0xff\n  }\n}\n\nBuffer.prototype.writeUInt32LE = function writeUInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset + 3] = (value >>> 24)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 1] = (value >>> 8)\n    this[offset] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeUInt32BE = function writeUInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeIntLE = function writeIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = 0\n  var mul = 1\n  var sub = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i - 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeIntBE = function writeIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  var sub = 0\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i + 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeInt8 = function writeInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0x7f, -0x80)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  if (value < 0) value = 0xff + value + 1\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nBuffer.prototype.writeInt16LE = function writeInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt16BE = function writeInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt32LE = function writeInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 3] = (value >>> 24)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeInt32BE = function writeInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (value < 0) value = 0xffffffff + value + 1\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nfunction checkIEEE754 (buf, value, offset, ext, max, min) {\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n  if (offset < 0) throw new RangeError('Index out of range')\n}\n\nfunction writeFloat (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 4, 3.4028234663852886e+38, -3.4028234663852886e+38)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 23, 4)\n  return offset + 4\n}\n\nBuffer.prototype.writeFloatLE = function writeFloatLE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeFloatBE = function writeFloatBE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, false, noAssert)\n}\n\nfunction writeDouble (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 8, 1.7976931348623157E+308, -1.7976931348623157E+308)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 52, 8)\n  return offset + 8\n}\n\nBuffer.prototype.writeDoubleLE = function writeDoubleLE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeDoubleBE = function writeDoubleBE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, false, noAssert)\n}\n\n// copy(targetBuffer, targetStart=0, sourceStart=0, sourceEnd=buffer.length)\nBuffer.prototype.copy = function copy (target, targetStart, start, end) {\n  if (!start) start = 0\n  if (!end && end !== 0) end = this.length\n  if (targetStart >= target.length) targetStart = target.length\n  if (!targetStart) targetStart = 0\n  if (end > 0 && end < start) end = start\n\n  // Copy 0 bytes; we're done\n  if (end === start) return 0\n  if (target.length === 0 || this.length === 0) return 0\n\n  // Fatal error conditions\n  if (targetStart < 0) {\n    throw new RangeError('targetStart out of bounds')\n  }\n  if (start < 0 || start >= this.length) throw new RangeError('sourceStart out of bounds')\n  if (end < 0) throw new RangeError('sourceEnd out of bounds')\n\n  // Are we oob?\n  if (end > this.length) end = this.length\n  if (target.length - targetStart < end - start) {\n    end = target.length - targetStart + start\n  }\n\n  var len = end - start\n  var i\n\n  if (this === target && start < targetStart && targetStart < end) {\n    // descending copy from end\n    for (i = len - 1; i >= 0; --i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else if (len < 1000 || !Buffer.TYPED_ARRAY_SUPPORT) {\n    // ascending copy from start\n    for (i = 0; i < len; ++i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else {\n    Uint8Array.prototype.set.call(\n      target,\n      this.subarray(start, start + len),\n      targetStart\n    )\n  }\n\n  return len\n}\n\n// Usage:\n//    buffer.fill(number[, offset[, end]])\n//    buffer.fill(buffer[, offset[, end]])\n//    buffer.fill(string[, offset[, end]][, encoding])\nBuffer.prototype.fill = function fill (val, start, end, encoding) {\n  // Handle string cases:\n  if (typeof val === 'string') {\n    if (typeof start === 'string') {\n      encoding = start\n      start = 0\n      end = this.length\n    } else if (typeof end === 'string') {\n      encoding = end\n      end = this.length\n    }\n    if (val.length === 1) {\n      var code = val.charCodeAt(0)\n      if (code < 256) {\n        val = code\n      }\n    }\n    if (encoding !== undefined && typeof encoding !== 'string') {\n      throw new TypeError('encoding must be a string')\n    }\n    if (typeof encoding === 'string' && !Buffer.isEncoding(encoding)) {\n      throw new TypeError('Unknown encoding: ' + encoding)\n    }\n  } else if (typeof val === 'number') {\n    val = val & 255\n  }\n\n  // Invalid ranges are not set to a default, so can range check early.\n  if (start < 0 || this.length < start || this.length < end) {\n    throw new RangeError('Out of range index')\n  }\n\n  if (end <= start) {\n    return this\n  }\n\n  start = start >>> 0\n  end = end === undefined ? this.length : end >>> 0\n\n  if (!val) val = 0\n\n  var i\n  if (typeof val === 'number') {\n    for (i = start; i < end; ++i) {\n      this[i] = val\n    }\n  } else {\n    var bytes = Buffer.isBuffer(val)\n      ? val\n      : utf8ToBytes(new Buffer(val, encoding).toString())\n    var len = bytes.length\n    for (i = 0; i < end - start; ++i) {\n      this[i + start] = bytes[i % len]\n    }\n  }\n\n  return this\n}\n\n// HELPER FUNCTIONS\n// ================\n\nvar INVALID_BASE64_RE = /[^+\\/0-9A-Za-z-_]/g\n\nfunction base64clean (str) {\n  // Node strips out invalid characters like \\n and \\t from the string, base64-js does not\n  str = stringtrim(str).replace(INVALID_BASE64_RE, '')\n  // Node converts strings with length < 2 to ''\n  if (str.length < 2) return ''\n  // Node allows for non-padded base64 strings (missing trailing ===), base64-js does not\n  while (str.length % 4 !== 0) {\n    str = str + '='\n  }\n  return str\n}\n\nfunction stringtrim (str) {\n  if (str.trim) return str.trim()\n  return str.replace(/^\\s+|\\s+$/g, '')\n}\n\nfunction toHex (n) {\n  if (n < 16) return '0' + n.toString(16)\n  return n.toString(16)\n}\n\nfunction utf8ToBytes (string, units) {\n  units = units || Infinity\n  var codePoint\n  var length = string.length\n  var leadSurrogate = null\n  var bytes = []\n\n  for (var i = 0; i < length; ++i) {\n    codePoint = string.charCodeAt(i)\n\n    // is surrogate component\n    if (codePoint > 0xD7FF && codePoint < 0xE000) {\n      // last char was a lead\n      if (!leadSurrogate) {\n        // no lead yet\n        if (codePoint > 0xDBFF) {\n          // unexpected trail\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        } else if (i + 1 === length) {\n          // unpaired lead\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        }\n\n        // valid lead\n        leadSurrogate = codePoint\n\n        continue\n      }\n\n      // 2 leads in a row\n      if (codePoint < 0xDC00) {\n        if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n        leadSurrogate = codePoint\n        continue\n      }\n\n      // valid surrogate pair\n      codePoint = (leadSurrogate - 0xD800 << 10 | codePoint - 0xDC00) + 0x10000\n    } else if (leadSurrogate) {\n      // valid bmp char, but last char was a lead\n      if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n    }\n\n    leadSurrogate = null\n\n    // encode utf8\n    if (codePoint < 0x80) {\n      if ((units -= 1) < 0) break\n      bytes.push(codePoint)\n    } else if (codePoint < 0x800) {\n      if ((units -= 2) < 0) break\n      bytes.push(\n        codePoint >> 0x6 | 0xC0,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x10000) {\n      if ((units -= 3) < 0) break\n      bytes.push(\n        codePoint >> 0xC | 0xE0,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x110000) {\n      if ((units -= 4) < 0) break\n      bytes.push(\n        codePoint >> 0x12 | 0xF0,\n        codePoint >> 0xC & 0x3F | 0x80,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else {\n      throw new Error('Invalid code point')\n    }\n  }\n\n  return bytes\n}\n\nfunction asciiToBytes (str) {\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    // Node's code seems to be doing this and not & 0x7F..\n    byteArray.push(str.charCodeAt(i) & 0xFF)\n  }\n  return byteArray\n}\n\nfunction utf16leToBytes (str, units) {\n  var c, hi, lo\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    if ((units -= 2) < 0) break\n\n    c = str.charCodeAt(i)\n    hi = c >> 8\n    lo = c % 256\n    byteArray.push(lo)\n    byteArray.push(hi)\n  }\n\n  return byteArray\n}\n\nfunction base64ToBytes (str) {\n  return base64.toByteArray(base64clean(str))\n}\n\nfunction blitBuffer (src, dst, offset, length) {\n  for (var i = 0; i < length; ++i) {\n    if ((i + offset >= dst.length) || (i >= src.length)) break\n    dst[i + offset] = src[i]\n  }\n  return i\n}\n\nfunction isnan (val) {\n  return val !== val // eslint-disable-line no-self-compare\n}\n\n/* WEBPACK VAR INJECTION */}.call(this, __webpack_require__(/*! ./../webpack/buildin/global.js */ \"./node_modules/webpack/buildin/global.js\")))\n\n/***/ }),\n\n/***/ \"./node_modules/buffer/node_modules/isarray/index.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/buffer/node_modules/isarray/index.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar toString = {}.toString;\n\nmodule.exports = Array.isArray || function (arr) {\n  return toString.call(arr) == '[object Array]';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/fn/regexp/escape.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/fn/regexp/escape.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ../../modules/core.regexp.escape */ \"./node_modules/core-js/modules/core.regexp.escape.js\");\nmodule.exports = __webpack_require__(/*! ../../modules/_core */ \"./node_modules/core-js/modules/_core.js\").RegExp.escape;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_a-function.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_a-function.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it) {\n  if (typeof it != 'function') throw TypeError(it + ' is not a function!');\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_a-number-value.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_a-number-value.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nmodule.exports = function (it, msg) {\n  if (typeof it != 'number' && cof(it) != 'Number') throw TypeError(msg);\n  return +it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_add-to-unscopables.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_add-to-unscopables.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.3.31 Array.prototype[@@unscopables]\nvar UNSCOPABLES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('unscopables');\nvar ArrayProto = Array.prototype;\nif (ArrayProto[UNSCOPABLES] == undefined) __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")(ArrayProto, UNSCOPABLES, {});\nmodule.exports = function (key) {\n  ArrayProto[UNSCOPABLES][key] = true;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_advance-string-index.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_advance-string-index.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar at = __webpack_require__(/*! ./_string-at */ \"./node_modules/core-js/modules/_string-at.js\")(true);\n\n // `AdvanceStringIndex` abstract operation\n// https://tc39.github.io/ecma262/#sec-advancestringindex\nmodule.exports = function (S, index, unicode) {\n  return index + (unicode ? at(S, index).length : 1);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_an-instance.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_an-instance.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it, Constructor, name, forbiddenField) {\n  if (!(it instanceof Constructor) || (forbiddenField !== undefined && forbiddenField in it)) {\n    throw TypeError(name + ': incorrect invocation!');\n  } return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_an-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_an-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nmodule.exports = function (it) {\n  if (!isObject(it)) throw TypeError(it + ' is not an object!');\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-copy-within.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-copy-within.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// 22.1.3.3 Array.prototype.copyWithin(target, start, end = this.length)\n\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\n\nmodule.exports = [].copyWithin || function copyWithin(target /* = 0 */, start /* = 0, end = @length */) {\n  var O = toObject(this);\n  var len = toLength(O.length);\n  var to = toAbsoluteIndex(target, len);\n  var from = toAbsoluteIndex(start, len);\n  var end = arguments.length > 2 ? arguments[2] : undefined;\n  var count = Math.min((end === undefined ? len : toAbsoluteIndex(end, len)) - from, len - to);\n  var inc = 1;\n  if (from < to && to < from + count) {\n    inc = -1;\n    from += count - 1;\n    to += count - 1;\n  }\n  while (count-- > 0) {\n    if (from in O) O[to] = O[from];\n    else delete O[to];\n    to += inc;\n    from += inc;\n  } return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-fill.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-fill.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// 22.1.3.6 Array.prototype.fill(value, start = 0, end = this.length)\n\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nmodule.exports = function fill(value /* , start = 0, end = @length */) {\n  var O = toObject(this);\n  var length = toLength(O.length);\n  var aLen = arguments.length;\n  var index = toAbsoluteIndex(aLen > 1 ? arguments[1] : undefined, length);\n  var end = aLen > 2 ? arguments[2] : undefined;\n  var endPos = end === undefined ? length : toAbsoluteIndex(end, length);\n  while (endPos > index) O[index++] = value;\n  return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-from-iterable.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-from-iterable.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\n\nmodule.exports = function (iter, ITERATOR) {\n  var result = [];\n  forOf(iter, false, result.push, result, ITERATOR);\n  return result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-includes.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-includes.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// false -> Array#indexOf\n// true  -> Array#includes\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nmodule.exports = function (IS_INCLUDES) {\n  return function ($this, el, fromIndex) {\n    var O = toIObject($this);\n    var length = toLength(O.length);\n    var index = toAbsoluteIndex(fromIndex, length);\n    var value;\n    // Array#includes uses SameValueZero equality algorithm\n    // eslint-disable-next-line no-self-compare\n    if (IS_INCLUDES && el != el) while (length > index) {\n      value = O[index++];\n      // eslint-disable-next-line no-self-compare\n      if (value != value) return true;\n    // Array#indexOf ignores holes, Array#includes - not\n    } else for (;length > index; index++) if (IS_INCLUDES || index in O) {\n      if (O[index] === el) return IS_INCLUDES || index || 0;\n    } return !IS_INCLUDES && -1;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-methods.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-methods.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 0 -> Array#forEach\n// 1 -> Array#map\n// 2 -> Array#filter\n// 3 -> Array#some\n// 4 -> Array#every\n// 5 -> Array#find\n// 6 -> Array#findIndex\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar asc = __webpack_require__(/*! ./_array-species-create */ \"./node_modules/core-js/modules/_array-species-create.js\");\nmodule.exports = function (TYPE, $create) {\n  var IS_MAP = TYPE == 1;\n  var IS_FILTER = TYPE == 2;\n  var IS_SOME = TYPE == 3;\n  var IS_EVERY = TYPE == 4;\n  var IS_FIND_INDEX = TYPE == 6;\n  var NO_HOLES = TYPE == 5 || IS_FIND_INDEX;\n  var create = $create || asc;\n  return function ($this, callbackfn, that) {\n    var O = toObject($this);\n    var self = IObject(O);\n    var f = ctx(callbackfn, that, 3);\n    var length = toLength(self.length);\n    var index = 0;\n    var result = IS_MAP ? create($this, length) : IS_FILTER ? create($this, 0) : undefined;\n    var val, res;\n    for (;length > index; index++) if (NO_HOLES || index in self) {\n      val = self[index];\n      res = f(val, index, O);\n      if (TYPE) {\n        if (IS_MAP) result[index] = res;   // map\n        else if (res) switch (TYPE) {\n          case 3: return true;             // some\n          case 5: return val;              // find\n          case 6: return index;            // findIndex\n          case 2: result.push(val);        // filter\n        } else if (IS_EVERY) return false; // every\n      }\n    }\n    return IS_FIND_INDEX ? -1 : IS_SOME || IS_EVERY ? IS_EVERY : result;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-reduce.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-reduce.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\n\nmodule.exports = function (that, callbackfn, aLen, memo, isRight) {\n  aFunction(callbackfn);\n  var O = toObject(that);\n  var self = IObject(O);\n  var length = toLength(O.length);\n  var index = isRight ? length - 1 : 0;\n  var i = isRight ? -1 : 1;\n  if (aLen < 2) for (;;) {\n    if (index in self) {\n      memo = self[index];\n      index += i;\n      break;\n    }\n    index += i;\n    if (isRight ? index < 0 : length <= index) {\n      throw TypeError('Reduce of empty array with no initial value');\n    }\n  }\n  for (;isRight ? index >= 0 : length > index; index += i) if (index in self) {\n    memo = callbackfn(memo, self[index], index, O);\n  }\n  return memo;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-species-constructor.js\":\n/*!********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-species-constructor.js ***!\n  \\********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar isArray = __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\n\nmodule.exports = function (original) {\n  var C;\n  if (isArray(original)) {\n    C = original.constructor;\n    // cross-realm fallback\n    if (typeof C == 'function' && (C === Array || isArray(C.prototype))) C = undefined;\n    if (isObject(C)) {\n      C = C[SPECIES];\n      if (C === null) C = undefined;\n    }\n  } return C === undefined ? Array : C;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_array-species-create.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_array-species-create.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 9.4.2.3 ArraySpeciesCreate(originalArray, length)\nvar speciesConstructor = __webpack_require__(/*! ./_array-species-constructor */ \"./node_modules/core-js/modules/_array-species-constructor.js\");\n\nmodule.exports = function (original, length) {\n  return new (speciesConstructor(original))(length);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_bind.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_bind.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar invoke = __webpack_require__(/*! ./_invoke */ \"./node_modules/core-js/modules/_invoke.js\");\nvar arraySlice = [].slice;\nvar factories = {};\n\nvar construct = function (F, len, args) {\n  if (!(len in factories)) {\n    for (var n = [], i = 0; i < len; i++) n[i] = 'a[' + i + ']';\n    // eslint-disable-next-line no-new-func\n    factories[len] = Function('F,a', 'return new F(' + n.join(',') + ')');\n  } return factories[len](F, args);\n};\n\nmodule.exports = Function.bind || function bind(that /* , ...args */) {\n  var fn = aFunction(this);\n  var partArgs = arraySlice.call(arguments, 1);\n  var bound = function (/* args... */) {\n    var args = partArgs.concat(arraySlice.call(arguments));\n    return this instanceof bound ? construct(fn, args.length, args) : invoke(fn, args, that);\n  };\n  if (isObject(fn.prototype)) bound.prototype = fn.prototype;\n  return bound;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_classof.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_classof.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// getting tag from 19.1.3.6 Object.prototype.toString()\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nvar TAG = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag');\n// ES3 wrong here\nvar ARG = cof(function () { return arguments; }()) == 'Arguments';\n\n// fallback for IE11 Script Access Denied error\nvar tryGet = function (it, key) {\n  try {\n    return it[key];\n  } catch (e) { /* empty */ }\n};\n\nmodule.exports = function (it) {\n  var O, T, B;\n  return it === undefined ? 'Undefined' : it === null ? 'Null'\n    // @@toStringTag case\n    : typeof (T = tryGet(O = Object(it), TAG)) == 'string' ? T\n    // builtinTag case\n    : ARG ? cof(O)\n    // ES3 arguments fallback\n    : (B = cof(O)) == 'Object' && typeof O.callee == 'function' ? 'Arguments' : B;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_cof.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_cof.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar toString = {}.toString;\n\nmodule.exports = function (it) {\n  return toString.call(it).slice(8, -1);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_collection-strong.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_collection-strong.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\nvar redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar $iterDefine = __webpack_require__(/*! ./_iter-define */ \"./node_modules/core-js/modules/_iter-define.js\");\nvar step = __webpack_require__(/*! ./_iter-step */ \"./node_modules/core-js/modules/_iter-step.js\");\nvar setSpecies = __webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar fastKey = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").fastKey;\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar SIZE = DESCRIPTORS ? '_s' : 'size';\n\nvar getEntry = function (that, key) {\n  // fast case\n  var index = fastKey(key);\n  var entry;\n  if (index !== 'F') return that._i[index];\n  // frozen object case\n  for (entry = that._f; entry; entry = entry.n) {\n    if (entry.k == key) return entry;\n  }\n};\n\nmodule.exports = {\n  getConstructor: function (wrapper, NAME, IS_MAP, ADDER) {\n    var C = wrapper(function (that, iterable) {\n      anInstance(that, C, NAME, '_i');\n      that._t = NAME;         // collection type\n      that._i = create(null); // index\n      that._f = undefined;    // first entry\n      that._l = undefined;    // last entry\n      that[SIZE] = 0;         // size\n      if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n    });\n    redefineAll(C.prototype, {\n      // 23.1.3.1 Map.prototype.clear()\n      // 23.2.3.2 Set.prototype.clear()\n      clear: function clear() {\n        for (var that = validate(this, NAME), data = that._i, entry = that._f; entry; entry = entry.n) {\n          entry.r = true;\n          if (entry.p) entry.p = entry.p.n = undefined;\n          delete data[entry.i];\n        }\n        that._f = that._l = undefined;\n        that[SIZE] = 0;\n      },\n      // 23.1.3.3 Map.prototype.delete(key)\n      // 23.2.3.4 Set.prototype.delete(value)\n      'delete': function (key) {\n        var that = validate(this, NAME);\n        var entry = getEntry(that, key);\n        if (entry) {\n          var next = entry.n;\n          var prev = entry.p;\n          delete that._i[entry.i];\n          entry.r = true;\n          if (prev) prev.n = next;\n          if (next) next.p = prev;\n          if (that._f == entry) that._f = next;\n          if (that._l == entry) that._l = prev;\n          that[SIZE]--;\n        } return !!entry;\n      },\n      // 23.2.3.6 Set.prototype.forEach(callbackfn, thisArg = undefined)\n      // 23.1.3.5 Map.prototype.forEach(callbackfn, thisArg = undefined)\n      forEach: function forEach(callbackfn /* , that = undefined */) {\n        validate(this, NAME);\n        var f = ctx(callbackfn, arguments.length > 1 ? arguments[1] : undefined, 3);\n        var entry;\n        while (entry = entry ? entry.n : this._f) {\n          f(entry.v, entry.k, this);\n          // revert to the last existing entry\n          while (entry && entry.r) entry = entry.p;\n        }\n      },\n      // 23.1.3.7 Map.prototype.has(key)\n      // 23.2.3.7 Set.prototype.has(value)\n      has: function has(key) {\n        return !!getEntry(validate(this, NAME), key);\n      }\n    });\n    if (DESCRIPTORS) dP(C.prototype, 'size', {\n      get: function () {\n        return validate(this, NAME)[SIZE];\n      }\n    });\n    return C;\n  },\n  def: function (that, key, value) {\n    var entry = getEntry(that, key);\n    var prev, index;\n    // change existing entry\n    if (entry) {\n      entry.v = value;\n    // create new entry\n    } else {\n      that._l = entry = {\n        i: index = fastKey(key, true), // <- index\n        k: key,                        // <- key\n        v: value,                      // <- value\n        p: prev = that._l,             // <- previous entry\n        n: undefined,                  // <- next entry\n        r: false                       // <- removed\n      };\n      if (!that._f) that._f = entry;\n      if (prev) prev.n = entry;\n      that[SIZE]++;\n      // add to index\n      if (index !== 'F') that._i[index] = entry;\n    } return that;\n  },\n  getEntry: getEntry,\n  setStrong: function (C, NAME, IS_MAP) {\n    // add .keys, .values, .entries, [@@iterator]\n    // 23.1.3.4, 23.1.3.8, 23.1.3.11, 23.1.3.12, 23.2.3.5, 23.2.3.8, 23.2.3.10, 23.2.3.11\n    $iterDefine(C, NAME, function (iterated, kind) {\n      this._t = validate(iterated, NAME); // target\n      this._k = kind;                     // kind\n      this._l = undefined;                // previous\n    }, function () {\n      var that = this;\n      var kind = that._k;\n      var entry = that._l;\n      // revert to the last existing entry\n      while (entry && entry.r) entry = entry.p;\n      // get next entry\n      if (!that._t || !(that._l = entry = entry ? entry.n : that._t._f)) {\n        // or finish the iteration\n        that._t = undefined;\n        return step(1);\n      }\n      // return step by kind\n      if (kind == 'keys') return step(0, entry.k);\n      if (kind == 'values') return step(0, entry.v);\n      return step(0, [entry.k, entry.v]);\n    }, IS_MAP ? 'entries' : 'values', !IS_MAP, true);\n\n    // add [@@species], 23.1.2.2, 23.2.2.2\n    setSpecies(NAME);\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_collection-to-json.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_collection-to-json.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar from = __webpack_require__(/*! ./_array-from-iterable */ \"./node_modules/core-js/modules/_array-from-iterable.js\");\nmodule.exports = function (NAME) {\n  return function toJSON() {\n    if (classof(this) != NAME) throw TypeError(NAME + \"#toJSON isn't generic\");\n    return from(this);\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_collection-weak.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_collection-weak.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\nvar getWeak = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").getWeak;\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar createArrayMethod = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\");\nvar $has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar arrayFind = createArrayMethod(5);\nvar arrayFindIndex = createArrayMethod(6);\nvar id = 0;\n\n// fallback for uncaught frozen keys\nvar uncaughtFrozenStore = function (that) {\n  return that._l || (that._l = new UncaughtFrozenStore());\n};\nvar UncaughtFrozenStore = function () {\n  this.a = [];\n};\nvar findUncaughtFrozen = function (store, key) {\n  return arrayFind(store.a, function (it) {\n    return it[0] === key;\n  });\n};\nUncaughtFrozenStore.prototype = {\n  get: function (key) {\n    var entry = findUncaughtFrozen(this, key);\n    if (entry) return entry[1];\n  },\n  has: function (key) {\n    return !!findUncaughtFrozen(this, key);\n  },\n  set: function (key, value) {\n    var entry = findUncaughtFrozen(this, key);\n    if (entry) entry[1] = value;\n    else this.a.push([key, value]);\n  },\n  'delete': function (key) {\n    var index = arrayFindIndex(this.a, function (it) {\n      return it[0] === key;\n    });\n    if (~index) this.a.splice(index, 1);\n    return !!~index;\n  }\n};\n\nmodule.exports = {\n  getConstructor: function (wrapper, NAME, IS_MAP, ADDER) {\n    var C = wrapper(function (that, iterable) {\n      anInstance(that, C, NAME, '_i');\n      that._t = NAME;      // collection type\n      that._i = id++;      // collection id\n      that._l = undefined; // leak store for uncaught frozen objects\n      if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n    });\n    redefineAll(C.prototype, {\n      // 23.3.3.2 WeakMap.prototype.delete(key)\n      // 23.4.3.3 WeakSet.prototype.delete(value)\n      'delete': function (key) {\n        if (!isObject(key)) return false;\n        var data = getWeak(key);\n        if (data === true) return uncaughtFrozenStore(validate(this, NAME))['delete'](key);\n        return data && $has(data, this._i) && delete data[this._i];\n      },\n      // 23.3.3.4 WeakMap.prototype.has(key)\n      // 23.4.3.4 WeakSet.prototype.has(value)\n      has: function has(key) {\n        if (!isObject(key)) return false;\n        var data = getWeak(key);\n        if (data === true) return uncaughtFrozenStore(validate(this, NAME)).has(key);\n        return data && $has(data, this._i);\n      }\n    });\n    return C;\n  },\n  def: function (that, key, value) {\n    var data = getWeak(anObject(key), true);\n    if (data === true) uncaughtFrozenStore(that).set(key, value);\n    else data[that._i] = value;\n    return that;\n  },\n  ufstore: uncaughtFrozenStore\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_collection.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_collection.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\nvar meta = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar $iterDetect = __webpack_require__(/*! ./_iter-detect */ \"./node_modules/core-js/modules/_iter-detect.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar inheritIfRequired = __webpack_require__(/*! ./_inherit-if-required */ \"./node_modules/core-js/modules/_inherit-if-required.js\");\n\nmodule.exports = function (NAME, wrapper, methods, common, IS_MAP, IS_WEAK) {\n  var Base = global[NAME];\n  var C = Base;\n  var ADDER = IS_MAP ? 'set' : 'add';\n  var proto = C && C.prototype;\n  var O = {};\n  var fixMethod = function (KEY) {\n    var fn = proto[KEY];\n    redefine(proto, KEY,\n      KEY == 'delete' ? function (a) {\n        return IS_WEAK && !isObject(a) ? false : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'has' ? function has(a) {\n        return IS_WEAK && !isObject(a) ? false : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'get' ? function get(a) {\n        return IS_WEAK && !isObject(a) ? undefined : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'add' ? function add(a) { fn.call(this, a === 0 ? 0 : a); return this; }\n        : function set(a, b) { fn.call(this, a === 0 ? 0 : a, b); return this; }\n    );\n  };\n  if (typeof C != 'function' || !(IS_WEAK || proto.forEach && !fails(function () {\n    new C().entries().next();\n  }))) {\n    // create collection constructor\n    C = common.getConstructor(wrapper, NAME, IS_MAP, ADDER);\n    redefineAll(C.prototype, methods);\n    meta.NEED = true;\n  } else {\n    var instance = new C();\n    // early implementations not supports chaining\n    var HASNT_CHAINING = instance[ADDER](IS_WEAK ? {} : -0, 1) != instance;\n    // V8 ~  Chromium 40- weak-collections throws on primitives, but should return false\n    var THROWS_ON_PRIMITIVES = fails(function () { instance.has(1); });\n    // most early implementations doesn't supports iterables, most modern - not close it correctly\n    var ACCEPT_ITERABLES = $iterDetect(function (iter) { new C(iter); }); // eslint-disable-line no-new\n    // for early implementations -0 and +0 not the same\n    var BUGGY_ZERO = !IS_WEAK && fails(function () {\n      // V8 ~ Chromium 42- fails only with 5+ elements\n      var $instance = new C();\n      var index = 5;\n      while (index--) $instance[ADDER](index, index);\n      return !$instance.has(-0);\n    });\n    if (!ACCEPT_ITERABLES) {\n      C = wrapper(function (target, iterable) {\n        anInstance(target, C, NAME);\n        var that = inheritIfRequired(new Base(), target, C);\n        if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n        return that;\n      });\n      C.prototype = proto;\n      proto.constructor = C;\n    }\n    if (THROWS_ON_PRIMITIVES || BUGGY_ZERO) {\n      fixMethod('delete');\n      fixMethod('has');\n      IS_MAP && fixMethod('get');\n    }\n    if (BUGGY_ZERO || HASNT_CHAINING) fixMethod(ADDER);\n    // weak collections should not contains .clear method\n    if (IS_WEAK && proto.clear) delete proto.clear;\n  }\n\n  setToStringTag(C, NAME);\n\n  O[NAME] = C;\n  $export($export.G + $export.W + $export.F * (C != Base), O);\n\n  if (!IS_WEAK) common.setStrong(C, NAME, IS_MAP);\n\n  return C;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_core.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_core.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar core = module.exports = { version: '2.6.4' };\nif (typeof __e == 'number') __e = core; // eslint-disable-line no-undef\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_create-property.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_create-property.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $defineProperty = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\n\nmodule.exports = function (object, index, value) {\n  if (index in object) $defineProperty.f(object, index, createDesc(0, value));\n  else object[index] = value;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_ctx.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_ctx.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// optional / simple context binding\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nmodule.exports = function (fn, that, length) {\n  aFunction(fn);\n  if (that === undefined) return fn;\n  switch (length) {\n    case 1: return function (a) {\n      return fn.call(that, a);\n    };\n    case 2: return function (a, b) {\n      return fn.call(that, a, b);\n    };\n    case 3: return function (a, b, c) {\n      return fn.call(that, a, b, c);\n    };\n  }\n  return function (/* ...args */) {\n    return fn.apply(that, arguments);\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_date-to-iso-string.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_date-to-iso-string.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 20.3.4.36 / 15.9.5.43 Date.prototype.toISOString()\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar getTime = Date.prototype.getTime;\nvar $toISOString = Date.prototype.toISOString;\n\nvar lz = function (num) {\n  return num > 9 ? num : '0' + num;\n};\n\n// PhantomJS / old WebKit has a broken implementations\nmodule.exports = (fails(function () {\n  return $toISOString.call(new Date(-5e13 - 1)) != '0385-07-25T07:06:39.999Z';\n}) || !fails(function () {\n  $toISOString.call(new Date(NaN));\n})) ? function toISOString() {\n  if (!isFinite(getTime.call(this))) throw RangeError('Invalid time value');\n  var d = this;\n  var y = d.getUTCFullYear();\n  var m = d.getUTCMilliseconds();\n  var s = y < 0 ? '-' : y > 9999 ? '+' : '';\n  return s + ('00000' + Math.abs(y)).slice(s ? -6 : -4) +\n    '-' + lz(d.getUTCMonth() + 1) + '-' + lz(d.getUTCDate()) +\n    'T' + lz(d.getUTCHours()) + ':' + lz(d.getUTCMinutes()) +\n    ':' + lz(d.getUTCSeconds()) + '.' + (m > 99 ? m : '0' + lz(m)) + 'Z';\n} : $toISOString;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_date-to-primitive.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_date-to-primitive.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar NUMBER = 'number';\n\nmodule.exports = function (hint) {\n  if (hint !== 'string' && hint !== NUMBER && hint !== 'default') throw TypeError('Incorrect hint');\n  return toPrimitive(anObject(this), hint != NUMBER);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_defined.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_defined.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 7.2.1 RequireObjectCoercible(argument)\nmodule.exports = function (it) {\n  if (it == undefined) throw TypeError(\"Can't call method on  \" + it);\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_descriptors.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_descriptors.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// Thank's IE8 for his funny defineProperty\nmodule.exports = !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return Object.defineProperty({}, 'a', { get: function () { return 7; } }).a != 7;\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_dom-create.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_dom-create.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar document = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").document;\n// typeof document.createElement is 'object' in old IE\nvar is = isObject(document) && isObject(document.createElement);\nmodule.exports = function (it) {\n  return is ? document.createElement(it) : {};\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_enum-bug-keys.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_enum-bug-keys.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// IE 8- don't enum bug keys\nmodule.exports = (\n  'constructor,hasOwnProperty,isPrototypeOf,propertyIsEnumerable,toLocaleString,toString,valueOf'\n).split(',');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_enum-keys.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_enum-keys.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// all enumerable object keys, includes symbols\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar gOPS = __webpack_require__(/*! ./_object-gops */ \"./node_modules/core-js/modules/_object-gops.js\");\nvar pIE = __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\");\nmodule.exports = function (it) {\n  var result = getKeys(it);\n  var getSymbols = gOPS.f;\n  if (getSymbols) {\n    var symbols = getSymbols(it);\n    var isEnum = pIE.f;\n    var i = 0;\n    var key;\n    while (symbols.length > i) if (isEnum.call(it, key = symbols[i++])) result.push(key);\n  } return result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_export.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_export.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar PROTOTYPE = 'prototype';\n\nvar $export = function (type, name, source) {\n  var IS_FORCED = type & $export.F;\n  var IS_GLOBAL = type & $export.G;\n  var IS_STATIC = type & $export.S;\n  var IS_PROTO = type & $export.P;\n  var IS_BIND = type & $export.B;\n  var target = IS_GLOBAL ? global : IS_STATIC ? global[name] || (global[name] = {}) : (global[name] || {})[PROTOTYPE];\n  var exports = IS_GLOBAL ? core : core[name] || (core[name] = {});\n  var expProto = exports[PROTOTYPE] || (exports[PROTOTYPE] = {});\n  var key, own, out, exp;\n  if (IS_GLOBAL) source = name;\n  for (key in source) {\n    // contains in native\n    own = !IS_FORCED && target && target[key] !== undefined;\n    // export native or passed\n    out = (own ? target : source)[key];\n    // bind timers to global for call from export context\n    exp = IS_BIND && own ? ctx(out, global) : IS_PROTO && typeof out == 'function' ? ctx(Function.call, out) : out;\n    // extend global\n    if (target) redefine(target, key, out, type & $export.U);\n    // export\n    if (exports[key] != out) hide(exports, key, exp);\n    if (IS_PROTO && expProto[key] != out) expProto[key] = out;\n  }\n};\nglobal.core = core;\n// type bitmap\n$export.F = 1;   // forced\n$export.G = 2;   // global\n$export.S = 4;   // static\n$export.P = 8;   // proto\n$export.B = 16;  // bind\n$export.W = 32;  // wrap\n$export.U = 64;  // safe\n$export.R = 128; // real proto method for `library`\nmodule.exports = $export;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_fails-is-regexp.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_fails-is-regexp.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar MATCH = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('match');\nmodule.exports = function (KEY) {\n  var re = /./;\n  try {\n    '/./'[KEY](re);\n  } catch (e) {\n    try {\n      re[MATCH] = false;\n      return !'/./'[KEY](re);\n    } catch (f) { /* empty */ }\n  } return true;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_fails.js\":\n/*!************************************************!*\\\n  !*** ./node_modules/core-js/modules/_fails.js ***!\n  \\************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (exec) {\n  try {\n    return !!exec();\n  } catch (e) {\n    return true;\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_fix-re-wks.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_fix-re-wks.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n__webpack_require__(/*! ./es6.regexp.exec */ \"./node_modules/core-js/modules/es6.regexp.exec.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nvar wks = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\nvar regexpExec = __webpack_require__(/*! ./_regexp-exec */ \"./node_modules/core-js/modules/_regexp-exec.js\");\n\nvar SPECIES = wks('species');\n\nvar REPLACE_SUPPORTS_NAMED_GROUPS = !fails(function () {\n  // #replace needs built-in support for named groups.\n  // #match works fine because it just return the exec results, even if it has\n  // a \"grops\" property.\n  var re = /./;\n  re.exec = function () {\n    var result = [];\n    result.groups = { a: '7' };\n    return result;\n  };\n  return ''.replace(re, '$<a>') !== '7';\n});\n\nvar SPLIT_WORKS_WITH_OVERWRITTEN_EXEC = (function () {\n  // Chrome 51 has a buggy \"split\" implementation when RegExp#exec !== nativeExec\n  var re = /(?:)/;\n  var originalExec = re.exec;\n  re.exec = function () { return originalExec.apply(this, arguments); };\n  var result = 'ab'.split(re);\n  return result.length === 2 && result[0] === 'a' && result[1] === 'b';\n})();\n\nmodule.exports = function (KEY, length, exec) {\n  var SYMBOL = wks(KEY);\n\n  var DELEGATES_TO_SYMBOL = !fails(function () {\n    // String methods call symbol-named RegEp methods\n    var O = {};\n    O[SYMBOL] = function () { return 7; };\n    return ''[KEY](O) != 7;\n  });\n\n  var DELEGATES_TO_EXEC = DELEGATES_TO_SYMBOL ? !fails(function () {\n    // Symbol-named RegExp methods call .exec\n    var execCalled = false;\n    var re = /a/;\n    re.exec = function () { execCalled = true; return null; };\n    if (KEY === 'split') {\n      // RegExp[@@split] doesn't call the regex's exec method, but first creates\n      // a new one. We need to return the patched regex when creating the new one.\n      re.constructor = {};\n      re.constructor[SPECIES] = function () { return re; };\n    }\n    re[SYMBOL]('');\n    return !execCalled;\n  }) : undefined;\n\n  if (\n    !DELEGATES_TO_SYMBOL ||\n    !DELEGATES_TO_EXEC ||\n    (KEY === 'replace' && !REPLACE_SUPPORTS_NAMED_GROUPS) ||\n    (KEY === 'split' && !SPLIT_WORKS_WITH_OVERWRITTEN_EXEC)\n  ) {\n    var nativeRegExpMethod = /./[SYMBOL];\n    var fns = exec(\n      defined,\n      SYMBOL,\n      ''[KEY],\n      function maybeCallNative(nativeMethod, regexp, str, arg2, forceStringMethod) {\n        if (regexp.exec === regexpExec) {\n          if (DELEGATES_TO_SYMBOL && !forceStringMethod) {\n            // The native String method already delegates to @@method (this\n            // polyfilled function), leasing to infinite recursion.\n            // We avoid it by directly calling the native @@method method.\n            return { done: true, value: nativeRegExpMethod.call(regexp, str, arg2) };\n          }\n          return { done: true, value: nativeMethod.call(str, regexp, arg2) };\n        }\n        return { done: false };\n      }\n    );\n    var strfn = fns[0];\n    var rxfn = fns[1];\n\n    redefine(String.prototype, KEY, strfn);\n    hide(RegExp.prototype, SYMBOL, length == 2\n      // 21.2.5.8 RegExp.prototype[@@replace](string, replaceValue)\n      // 21.2.5.11 RegExp.prototype[@@split](string, limit)\n      ? function (string, arg) { return rxfn.call(string, this, arg); }\n      // 21.2.5.6 RegExp.prototype[@@match](string)\n      // 21.2.5.9 RegExp.prototype[@@search](string)\n      : function (string) { return rxfn.call(string, this); }\n    );\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_flags.js\":\n/*!************************************************!*\\\n  !*** ./node_modules/core-js/modules/_flags.js ***!\n  \\************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 21.2.5.3 get RegExp.prototype.flags\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nmodule.exports = function () {\n  var that = anObject(this);\n  var result = '';\n  if (that.global) result += 'g';\n  if (that.ignoreCase) result += 'i';\n  if (that.multiline) result += 'm';\n  if (that.unicode) result += 'u';\n  if (that.sticky) result += 'y';\n  return result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_flatten-into-array.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_flatten-into-array.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/proposal-flatMap/#sec-FlattenIntoArray\nvar isArray = __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar IS_CONCAT_SPREADABLE = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('isConcatSpreadable');\n\nfunction flattenIntoArray(target, original, source, sourceLen, start, depth, mapper, thisArg) {\n  var targetIndex = start;\n  var sourceIndex = 0;\n  var mapFn = mapper ? ctx(mapper, thisArg, 3) : false;\n  var element, spreadable;\n\n  while (sourceIndex < sourceLen) {\n    if (sourceIndex in source) {\n      element = mapFn ? mapFn(source[sourceIndex], sourceIndex, original) : source[sourceIndex];\n\n      spreadable = false;\n      if (isObject(element)) {\n        spreadable = element[IS_CONCAT_SPREADABLE];\n        spreadable = spreadable !== undefined ? !!spreadable : isArray(element);\n      }\n\n      if (spreadable && depth > 0) {\n        targetIndex = flattenIntoArray(target, original, element, toLength(element.length), targetIndex, depth - 1) - 1;\n      } else {\n        if (targetIndex >= 0x1fffffffffffff) throw TypeError();\n        target[targetIndex] = element;\n      }\n\n      targetIndex++;\n    }\n    sourceIndex++;\n  }\n  return targetIndex;\n}\n\nmodule.exports = flattenIntoArray;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_for-of.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_for-of.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar call = __webpack_require__(/*! ./_iter-call */ \"./node_modules/core-js/modules/_iter-call.js\");\nvar isArrayIter = __webpack_require__(/*! ./_is-array-iter */ \"./node_modules/core-js/modules/_is-array-iter.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar getIterFn = __webpack_require__(/*! ./core.get-iterator-method */ \"./node_modules/core-js/modules/core.get-iterator-method.js\");\nvar BREAK = {};\nvar RETURN = {};\nvar exports = module.exports = function (iterable, entries, fn, that, ITERATOR) {\n  var iterFn = ITERATOR ? function () { return iterable; } : getIterFn(iterable);\n  var f = ctx(fn, that, entries ? 2 : 1);\n  var index = 0;\n  var length, step, iterator, result;\n  if (typeof iterFn != 'function') throw TypeError(iterable + ' is not iterable!');\n  // fast case for arrays with default iterator\n  if (isArrayIter(iterFn)) for (length = toLength(iterable.length); length > index; index++) {\n    result = entries ? f(anObject(step = iterable[index])[0], step[1]) : f(iterable[index]);\n    if (result === BREAK || result === RETURN) return result;\n  } else for (iterator = iterFn.call(iterable); !(step = iterator.next()).done;) {\n    result = call(iterator, f, step.value, entries);\n    if (result === BREAK || result === RETURN) return result;\n  }\n};\nexports.BREAK = BREAK;\nexports.RETURN = RETURN;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_function-to-string.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_function-to-string.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nmodule.exports = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('native-function-to-string', Function.toString);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_global.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_global.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// https://github.com/zloirock/core-js/issues/86#issuecomment-115759028\nvar global = module.exports = typeof window != 'undefined' && window.Math == Math\n  ? window : typeof self != 'undefined' && self.Math == Math ? self\n  // eslint-disable-next-line no-new-func\n  : Function('return this')();\nif (typeof __g == 'number') __g = global; // eslint-disable-line no-undef\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_has.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_has.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar hasOwnProperty = {}.hasOwnProperty;\nmodule.exports = function (it, key) {\n  return hasOwnProperty.call(it, key);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_hide.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_hide.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nmodule.exports = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? function (object, key, value) {\n  return dP.f(object, key, createDesc(1, value));\n} : function (object, key, value) {\n  object[key] = value;\n  return object;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_html.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_html.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar document = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").document;\nmodule.exports = document && document.documentElement;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_ie8-dom-define.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_ie8-dom-define.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nmodule.exports = !__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return Object.defineProperty(__webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\")('div'), 'a', { get: function () { return 7; } }).a != 7;\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_inherit-if-required.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_inherit-if-required.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar setPrototypeOf = __webpack_require__(/*! ./_set-proto */ \"./node_modules/core-js/modules/_set-proto.js\").set;\nmodule.exports = function (that, target, C) {\n  var S = target.constructor;\n  var P;\n  if (S !== C && typeof S == 'function' && (P = S.prototype) !== C.prototype && isObject(P) && setPrototypeOf) {\n    setPrototypeOf(that, P);\n  } return that;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_invoke.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_invoke.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// fast apply, http://jsperf.lnkit.com/fast-apply/5\nmodule.exports = function (fn, args, that) {\n  var un = that === undefined;\n  switch (args.length) {\n    case 0: return un ? fn()\n                      : fn.call(that);\n    case 1: return un ? fn(args[0])\n                      : fn.call(that, args[0]);\n    case 2: return un ? fn(args[0], args[1])\n                      : fn.call(that, args[0], args[1]);\n    case 3: return un ? fn(args[0], args[1], args[2])\n                      : fn.call(that, args[0], args[1], args[2]);\n    case 4: return un ? fn(args[0], args[1], args[2], args[3])\n                      : fn.call(that, args[0], args[1], args[2], args[3]);\n  } return fn.apply(that, args);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iobject.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iobject.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// fallback for non-array-like ES3 and non-enumerable old V8 strings\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\n// eslint-disable-next-line no-prototype-builtins\nmodule.exports = Object('z').propertyIsEnumerable(0) ? Object : function (it) {\n  return cof(it) == 'String' ? it.split('') : Object(it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-array-iter.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-array-iter.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// check on default Array iterator\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar ArrayProto = Array.prototype;\n\nmodule.exports = function (it) {\n  return it !== undefined && (Iterators.Array === it || ArrayProto[ITERATOR] === it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-array.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-array.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.2.2 IsArray(argument)\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nmodule.exports = Array.isArray || function isArray(arg) {\n  return cof(arg) == 'Array';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-integer.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-integer.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.3 Number.isInteger(number)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar floor = Math.floor;\nmodule.exports = function isInteger(it) {\n  return !isObject(it) && isFinite(it) && floor(it) === it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (it) {\n  return typeof it === 'object' ? it !== null : typeof it === 'function';\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_is-regexp.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_is-regexp.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.2.8 IsRegExp(argument)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nvar MATCH = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('match');\nmodule.exports = function (it) {\n  var isRegExp;\n  return isObject(it) && ((isRegExp = it[MATCH]) !== undefined ? !!isRegExp : cof(it) == 'RegExp');\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-call.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-call.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// call something on iterator step with safe closing on error\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nmodule.exports = function (iterator, fn, value, entries) {\n  try {\n    return entries ? fn(anObject(value)[0], value[1]) : fn(value);\n  // 7.4.6 IteratorClose(iterator, completion)\n  } catch (e) {\n    var ret = iterator['return'];\n    if (ret !== undefined) anObject(ret.call(iterator));\n    throw e;\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-create.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-create.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\nvar descriptor = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar IteratorPrototype = {};\n\n// 25.1.2.1.1 %IteratorPrototype%[@@iterator]()\n__webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")(IteratorPrototype, __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator'), function () { return this; });\n\nmodule.exports = function (Constructor, NAME, next) {\n  Constructor.prototype = create(IteratorPrototype, { next: descriptor(1, next) });\n  setToStringTag(Constructor, NAME + ' Iterator');\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-define.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-define.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar $iterCreate = __webpack_require__(/*! ./_iter-create */ \"./node_modules/core-js/modules/_iter-create.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar BUGGY = !([].keys && 'next' in [].keys()); // Safari has buggy iterators w/o `next`\nvar FF_ITERATOR = '@@iterator';\nvar KEYS = 'keys';\nvar VALUES = 'values';\n\nvar returnThis = function () { return this; };\n\nmodule.exports = function (Base, NAME, Constructor, next, DEFAULT, IS_SET, FORCED) {\n  $iterCreate(Constructor, NAME, next);\n  var getMethod = function (kind) {\n    if (!BUGGY && kind in proto) return proto[kind];\n    switch (kind) {\n      case KEYS: return function keys() { return new Constructor(this, kind); };\n      case VALUES: return function values() { return new Constructor(this, kind); };\n    } return function entries() { return new Constructor(this, kind); };\n  };\n  var TAG = NAME + ' Iterator';\n  var DEF_VALUES = DEFAULT == VALUES;\n  var VALUES_BUG = false;\n  var proto = Base.prototype;\n  var $native = proto[ITERATOR] || proto[FF_ITERATOR] || DEFAULT && proto[DEFAULT];\n  var $default = $native || getMethod(DEFAULT);\n  var $entries = DEFAULT ? !DEF_VALUES ? $default : getMethod('entries') : undefined;\n  var $anyNative = NAME == 'Array' ? proto.entries || $native : $native;\n  var methods, key, IteratorPrototype;\n  // Fix native\n  if ($anyNative) {\n    IteratorPrototype = getPrototypeOf($anyNative.call(new Base()));\n    if (IteratorPrototype !== Object.prototype && IteratorPrototype.next) {\n      // Set @@toStringTag to native iterators\n      setToStringTag(IteratorPrototype, TAG, true);\n      // fix for some old engines\n      if (!LIBRARY && typeof IteratorPrototype[ITERATOR] != 'function') hide(IteratorPrototype, ITERATOR, returnThis);\n    }\n  }\n  // fix Array#{values, @@iterator}.name in V8 / FF\n  if (DEF_VALUES && $native && $native.name !== VALUES) {\n    VALUES_BUG = true;\n    $default = function values() { return $native.call(this); };\n  }\n  // Define iterator\n  if ((!LIBRARY || FORCED) && (BUGGY || VALUES_BUG || !proto[ITERATOR])) {\n    hide(proto, ITERATOR, $default);\n  }\n  // Plug for library\n  Iterators[NAME] = $default;\n  Iterators[TAG] = returnThis;\n  if (DEFAULT) {\n    methods = {\n      values: DEF_VALUES ? $default : getMethod(VALUES),\n      keys: IS_SET ? $default : getMethod(KEYS),\n      entries: $entries\n    };\n    if (FORCED) for (key in methods) {\n      if (!(key in proto)) redefine(proto, key, methods[key]);\n    } else $export($export.P + $export.F * (BUGGY || VALUES_BUG), NAME, methods);\n  }\n  return methods;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-detect.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-detect.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar SAFE_CLOSING = false;\n\ntry {\n  var riter = [7][ITERATOR]();\n  riter['return'] = function () { SAFE_CLOSING = true; };\n  // eslint-disable-next-line no-throw-literal\n  Array.from(riter, function () { throw 2; });\n} catch (e) { /* empty */ }\n\nmodule.exports = function (exec, skipClosing) {\n  if (!skipClosing && !SAFE_CLOSING) return false;\n  var safe = false;\n  try {\n    var arr = [7];\n    var iter = arr[ITERATOR]();\n    iter.next = function () { return { done: safe = true }; };\n    arr[ITERATOR] = function () { return iter; };\n    exec(arr);\n  } catch (e) { /* empty */ }\n  return safe;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iter-step.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iter-step.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (done, value) {\n  return { value: value, done: !!done };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_iterators.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_iterators.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = {};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_library.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_library.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = false;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_math-expm1.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_math-expm1.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 20.2.2.14 Math.expm1(x)\nvar $expm1 = Math.expm1;\nmodule.exports = (!$expm1\n  // Old FF bug\n  || $expm1(10) > 22025.465794806719 || $expm1(10) < 22025.4657948067165168\n  // Tor Browser bug\n  || $expm1(-2e-17) != -2e-17\n) ? function expm1(x) {\n  return (x = +x) == 0 ? x : x > -1e-6 && x < 1e-6 ? x + x * x / 2 : Math.exp(x) - 1;\n} : $expm1;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_math-fround.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_math-fround.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.16 Math.fround(x)\nvar sign = __webpack_require__(/*! ./_math-sign */ \"./node_modules/core-js/modules/_math-sign.js\");\nvar pow = Math.pow;\nvar EPSILON = pow(2, -52);\nvar EPSILON32 = pow(2, -23);\nvar MAX32 = pow(2, 127) * (2 - EPSILON32);\nvar MIN32 = pow(2, -126);\n\nvar roundTiesToEven = function (n) {\n  return n + 1 / EPSILON - 1 / EPSILON;\n};\n\nmodule.exports = Math.fround || function fround(x) {\n  var $abs = Math.abs(x);\n  var $sign = sign(x);\n  var a, result;\n  if ($abs < MIN32) return $sign * roundTiesToEven($abs / MIN32 / EPSILON32) * MIN32 * EPSILON32;\n  a = (1 + EPSILON32 / EPSILON) * $abs;\n  result = a - (a - $abs);\n  // eslint-disable-next-line no-self-compare\n  if (result > MAX32 || result != result) return $sign * Infinity;\n  return $sign * result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_math-log1p.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_math-log1p.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 20.2.2.20 Math.log1p(x)\nmodule.exports = Math.log1p || function log1p(x) {\n  return (x = +x) > -1e-8 && x < 1e-8 ? x - x * x / 2 : Math.log(1 + x);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_math-scale.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_math-scale.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nmodule.exports = Math.scale || function scale(x, inLow, inHigh, outLow, outHigh) {\n  if (\n    arguments.length === 0\n      // eslint-disable-next-line no-self-compare\n      || x != x\n      // eslint-disable-next-line no-self-compare\n      || inLow != inLow\n      // eslint-disable-next-line no-self-compare\n      || inHigh != inHigh\n      // eslint-disable-next-line no-self-compare\n      || outLow != outLow\n      // eslint-disable-next-line no-self-compare\n      || outHigh != outHigh\n  ) return NaN;\n  if (x === Infinity || x === -Infinity) return x;\n  return (x - inLow) * (outHigh - outLow) / (inHigh - inLow) + outLow;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_math-sign.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_math-sign.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 20.2.2.28 Math.sign(x)\nmodule.exports = Math.sign || function sign(x) {\n  // eslint-disable-next-line no-self-compare\n  return (x = +x) == 0 || x != x ? x : x < 0 ? -1 : 1;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_meta.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_meta.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar META = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\")('meta');\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar setDesc = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar id = 0;\nvar isExtensible = Object.isExtensible || function () {\n  return true;\n};\nvar FREEZE = !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return isExtensible(Object.preventExtensions({}));\n});\nvar setMeta = function (it) {\n  setDesc(it, META, { value: {\n    i: 'O' + ++id, // object ID\n    w: {}          // weak collections IDs\n  } });\n};\nvar fastKey = function (it, create) {\n  // return primitive with prefix\n  if (!isObject(it)) return typeof it == 'symbol' ? it : (typeof it == 'string' ? 'S' : 'P') + it;\n  if (!has(it, META)) {\n    // can't set metadata to uncaught frozen object\n    if (!isExtensible(it)) return 'F';\n    // not necessary to add metadata\n    if (!create) return 'E';\n    // add missing metadata\n    setMeta(it);\n  // return object ID\n  } return it[META].i;\n};\nvar getWeak = function (it, create) {\n  if (!has(it, META)) {\n    // can't set metadata to uncaught frozen object\n    if (!isExtensible(it)) return true;\n    // not necessary to add metadata\n    if (!create) return false;\n    // add missing metadata\n    setMeta(it);\n  // return hash weak collections IDs\n  } return it[META].w;\n};\n// add metadata on freeze-family methods calling\nvar onFreeze = function (it) {\n  if (FREEZE && meta.NEED && isExtensible(it) && !has(it, META)) setMeta(it);\n  return it;\n};\nvar meta = module.exports = {\n  KEY: META,\n  NEED: false,\n  fastKey: fastKey,\n  getWeak: getWeak,\n  onFreeze: onFreeze\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_metadata.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_metadata.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar Map = __webpack_require__(/*! ./es6.map */ \"./node_modules/core-js/modules/es6.map.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar shared = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('metadata');\nvar store = shared.store || (shared.store = new (__webpack_require__(/*! ./es6.weak-map */ \"./node_modules/core-js/modules/es6.weak-map.js\"))());\n\nvar getOrCreateMetadataMap = function (target, targetKey, create) {\n  var targetMetadata = store.get(target);\n  if (!targetMetadata) {\n    if (!create) return undefined;\n    store.set(target, targetMetadata = new Map());\n  }\n  var keyMetadata = targetMetadata.get(targetKey);\n  if (!keyMetadata) {\n    if (!create) return undefined;\n    targetMetadata.set(targetKey, keyMetadata = new Map());\n  } return keyMetadata;\n};\nvar ordinaryHasOwnMetadata = function (MetadataKey, O, P) {\n  var metadataMap = getOrCreateMetadataMap(O, P, false);\n  return metadataMap === undefined ? false : metadataMap.has(MetadataKey);\n};\nvar ordinaryGetOwnMetadata = function (MetadataKey, O, P) {\n  var metadataMap = getOrCreateMetadataMap(O, P, false);\n  return metadataMap === undefined ? undefined : metadataMap.get(MetadataKey);\n};\nvar ordinaryDefineOwnMetadata = function (MetadataKey, MetadataValue, O, P) {\n  getOrCreateMetadataMap(O, P, true).set(MetadataKey, MetadataValue);\n};\nvar ordinaryOwnMetadataKeys = function (target, targetKey) {\n  var metadataMap = getOrCreateMetadataMap(target, targetKey, false);\n  var keys = [];\n  if (metadataMap) metadataMap.forEach(function (_, key) { keys.push(key); });\n  return keys;\n};\nvar toMetaKey = function (it) {\n  return it === undefined || typeof it == 'symbol' ? it : String(it);\n};\nvar exp = function (O) {\n  $export($export.S, 'Reflect', O);\n};\n\nmodule.exports = {\n  store: store,\n  map: getOrCreateMetadataMap,\n  has: ordinaryHasOwnMetadata,\n  get: ordinaryGetOwnMetadata,\n  set: ordinaryDefineOwnMetadata,\n  keys: ordinaryOwnMetadataKeys,\n  key: toMetaKey,\n  exp: exp\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_microtask.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_microtask.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar macrotask = __webpack_require__(/*! ./_task */ \"./node_modules/core-js/modules/_task.js\").set;\nvar Observer = global.MutationObserver || global.WebKitMutationObserver;\nvar process = global.process;\nvar Promise = global.Promise;\nvar isNode = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\")(process) == 'process';\n\nmodule.exports = function () {\n  var head, last, notify;\n\n  var flush = function () {\n    var parent, fn;\n    if (isNode && (parent = process.domain)) parent.exit();\n    while (head) {\n      fn = head.fn;\n      head = head.next;\n      try {\n        fn();\n      } catch (e) {\n        if (head) notify();\n        else last = undefined;\n        throw e;\n      }\n    } last = undefined;\n    if (parent) parent.enter();\n  };\n\n  // Node.js\n  if (isNode) {\n    notify = function () {\n      process.nextTick(flush);\n    };\n  // browsers with MutationObserver, except iOS Safari - https://github.com/zloirock/core-js/issues/339\n  } else if (Observer && !(global.navigator && global.navigator.standalone)) {\n    var toggle = true;\n    var node = document.createTextNode('');\n    new Observer(flush).observe(node, { characterData: true }); // eslint-disable-line no-new\n    notify = function () {\n      node.data = toggle = !toggle;\n    };\n  // environments with maybe non-completely correct, but existent Promise\n  } else if (Promise && Promise.resolve) {\n    // Promise.resolve without an argument throws an error in LG WebOS 2\n    var promise = Promise.resolve(undefined);\n    notify = function () {\n      promise.then(flush);\n    };\n  // for other environments - macrotask based on:\n  // - setImmediate\n  // - MessageChannel\n  // - window.postMessag\n  // - onreadystatechange\n  // - setTimeout\n  } else {\n    notify = function () {\n      // strange IE + webpack dev server bug - use .call(global)\n      macrotask.call(global, flush);\n    };\n  }\n\n  return function (fn) {\n    var task = { fn: fn, next: undefined };\n    if (last) last.next = task;\n    if (!head) {\n      head = task;\n      notify();\n    } last = task;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_new-promise-capability.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_new-promise-capability.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 25.4.1.5 NewPromiseCapability(C)\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\n\nfunction PromiseCapability(C) {\n  var resolve, reject;\n  this.promise = new C(function ($$resolve, $$reject) {\n    if (resolve !== undefined || reject !== undefined) throw TypeError('Bad Promise constructor');\n    resolve = $$resolve;\n    reject = $$reject;\n  });\n  this.resolve = aFunction(resolve);\n  this.reject = aFunction(reject);\n}\n\nmodule.exports.f = function (C) {\n  return new PromiseCapability(C);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-assign.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-assign.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 19.1.2.1 Object.assign(target, source, ...)\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar gOPS = __webpack_require__(/*! ./_object-gops */ \"./node_modules/core-js/modules/_object-gops.js\");\nvar pIE = __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar $assign = Object.assign;\n\n// should work with symbols and should have deterministic property order (V8 bug)\nmodule.exports = !$assign || __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  var A = {};\n  var B = {};\n  // eslint-disable-next-line no-undef\n  var S = Symbol();\n  var K = 'abcdefghijklmnopqrst';\n  A[S] = 7;\n  K.split('').forEach(function (k) { B[k] = k; });\n  return $assign({}, A)[S] != 7 || Object.keys($assign({}, B)).join('') != K;\n}) ? function assign(target, source) { // eslint-disable-line no-unused-vars\n  var T = toObject(target);\n  var aLen = arguments.length;\n  var index = 1;\n  var getSymbols = gOPS.f;\n  var isEnum = pIE.f;\n  while (aLen > index) {\n    var S = IObject(arguments[index++]);\n    var keys = getSymbols ? getKeys(S).concat(getSymbols(S)) : getKeys(S);\n    var length = keys.length;\n    var j = 0;\n    var key;\n    while (length > j) if (isEnum.call(S, key = keys[j++])) T[key] = S[key];\n  } return T;\n} : $assign;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-create.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-create.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar dPs = __webpack_require__(/*! ./_object-dps */ \"./node_modules/core-js/modules/_object-dps.js\");\nvar enumBugKeys = __webpack_require__(/*! ./_enum-bug-keys */ \"./node_modules/core-js/modules/_enum-bug-keys.js\");\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\nvar Empty = function () { /* empty */ };\nvar PROTOTYPE = 'prototype';\n\n// Create object with fake `null` prototype: use iframe Object with cleared prototype\nvar createDict = function () {\n  // Thrash, waste and sodomy: IE GC bug\n  var iframe = __webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\")('iframe');\n  var i = enumBugKeys.length;\n  var lt = '<';\n  var gt = '>';\n  var iframeDocument;\n  iframe.style.display = 'none';\n  __webpack_require__(/*! ./_html */ \"./node_modules/core-js/modules/_html.js\").appendChild(iframe);\n  iframe.src = 'javascript:'; // eslint-disable-line no-script-url\n  // createDict = iframe.contentWindow.Object;\n  // html.removeChild(iframe);\n  iframeDocument = iframe.contentWindow.document;\n  iframeDocument.open();\n  iframeDocument.write(lt + 'script' + gt + 'document.F=Object' + lt + '/script' + gt);\n  iframeDocument.close();\n  createDict = iframeDocument.F;\n  while (i--) delete createDict[PROTOTYPE][enumBugKeys[i]];\n  return createDict();\n};\n\nmodule.exports = Object.create || function create(O, Properties) {\n  var result;\n  if (O !== null) {\n    Empty[PROTOTYPE] = anObject(O);\n    result = new Empty();\n    Empty[PROTOTYPE] = null;\n    // add \"__proto__\" for Object.getPrototypeOf polyfill\n    result[IE_PROTO] = O;\n  } else result = createDict();\n  return Properties === undefined ? result : dPs(result, Properties);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-dp.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-dp.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar IE8_DOM_DEFINE = __webpack_require__(/*! ./_ie8-dom-define */ \"./node_modules/core-js/modules/_ie8-dom-define.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar dP = Object.defineProperty;\n\nexports.f = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? Object.defineProperty : function defineProperty(O, P, Attributes) {\n  anObject(O);\n  P = toPrimitive(P, true);\n  anObject(Attributes);\n  if (IE8_DOM_DEFINE) try {\n    return dP(O, P, Attributes);\n  } catch (e) { /* empty */ }\n  if ('get' in Attributes || 'set' in Attributes) throw TypeError('Accessors not supported!');\n  if ('value' in Attributes) O[P] = Attributes.value;\n  return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-dps.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-dps.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\n\nmodule.exports = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? Object.defineProperties : function defineProperties(O, Properties) {\n  anObject(O);\n  var keys = getKeys(Properties);\n  var length = keys.length;\n  var i = 0;\n  var P;\n  while (length > i) dP.f(O, P = keys[i++], Properties[P]);\n  return O;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-forced-pam.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-forced-pam.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// Forced replacement prototype accessors methods\nmodule.exports = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\") || !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  var K = Math.random();\n  // In FF throws only define methods\n  // eslint-disable-next-line no-undef, no-useless-call\n  __defineSetter__.call(null, K, function () { /* empty */ });\n  delete __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\")[K];\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gopd.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gopd.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar pIE = __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar IE8_DOM_DEFINE = __webpack_require__(/*! ./_ie8-dom-define */ \"./node_modules/core-js/modules/_ie8-dom-define.js\");\nvar gOPD = Object.getOwnPropertyDescriptor;\n\nexports.f = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? gOPD : function getOwnPropertyDescriptor(O, P) {\n  O = toIObject(O);\n  P = toPrimitive(P, true);\n  if (IE8_DOM_DEFINE) try {\n    return gOPD(O, P);\n  } catch (e) { /* empty */ }\n  if (has(O, P)) return createDesc(!pIE.f.call(O, P), O[P]);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gopn-ext.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gopn-ext.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// fallback for IE11 buggy Object.getOwnPropertyNames with iframe and window\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f;\nvar toString = {}.toString;\n\nvar windowNames = typeof window == 'object' && window && Object.getOwnPropertyNames\n  ? Object.getOwnPropertyNames(window) : [];\n\nvar getWindowNames = function (it) {\n  try {\n    return gOPN(it);\n  } catch (e) {\n    return windowNames.slice();\n  }\n};\n\nmodule.exports.f = function getOwnPropertyNames(it) {\n  return windowNames && toString.call(it) == '[object Window]' ? getWindowNames(it) : gOPN(toIObject(it));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gopn.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gopn.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.7 / 15.2.3.4 Object.getOwnPropertyNames(O)\nvar $keys = __webpack_require__(/*! ./_object-keys-internal */ \"./node_modules/core-js/modules/_object-keys-internal.js\");\nvar hiddenKeys = __webpack_require__(/*! ./_enum-bug-keys */ \"./node_modules/core-js/modules/_enum-bug-keys.js\").concat('length', 'prototype');\n\nexports.f = Object.getOwnPropertyNames || function getOwnPropertyNames(O) {\n  return $keys(O, hiddenKeys);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gops.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gops.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.f = Object.getOwnPropertySymbols;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-gpo.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-gpo.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.9 / 15.2.3.2 Object.getPrototypeOf(O)\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\nvar ObjectProto = Object.prototype;\n\nmodule.exports = Object.getPrototypeOf || function (O) {\n  O = toObject(O);\n  if (has(O, IE_PROTO)) return O[IE_PROTO];\n  if (typeof O.constructor == 'function' && O instanceof O.constructor) {\n    return O.constructor.prototype;\n  } return O instanceof Object ? ObjectProto : null;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-keys-internal.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-keys-internal.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar arrayIndexOf = __webpack_require__(/*! ./_array-includes */ \"./node_modules/core-js/modules/_array-includes.js\")(false);\nvar IE_PROTO = __webpack_require__(/*! ./_shared-key */ \"./node_modules/core-js/modules/_shared-key.js\")('IE_PROTO');\n\nmodule.exports = function (object, names) {\n  var O = toIObject(object);\n  var i = 0;\n  var result = [];\n  var key;\n  for (key in O) if (key != IE_PROTO) has(O, key) && result.push(key);\n  // Don't enum bug & hidden keys\n  while (names.length > i) if (has(O, key = names[i++])) {\n    ~arrayIndexOf(result, key) || result.push(key);\n  }\n  return result;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-keys.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-keys.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.14 / 15.2.3.14 Object.keys(O)\nvar $keys = __webpack_require__(/*! ./_object-keys-internal */ \"./node_modules/core-js/modules/_object-keys-internal.js\");\nvar enumBugKeys = __webpack_require__(/*! ./_enum-bug-keys */ \"./node_modules/core-js/modules/_enum-bug-keys.js\");\n\nmodule.exports = Object.keys || function keys(O) {\n  return $keys(O, enumBugKeys);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-pie.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-pie.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.f = {}.propertyIsEnumerable;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-sap.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-sap.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// most Object methods by ES6 should accept primitives\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nmodule.exports = function (KEY, exec) {\n  var fn = (core.Object || {})[KEY] || Object[KEY];\n  var exp = {};\n  exp[KEY] = exec(fn);\n  $export($export.S + $export.F * fails(function () { fn(1); }), 'Object', exp);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_object-to-array.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_object-to-array.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar isEnum = __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\").f;\nmodule.exports = function (isEntries) {\n  return function (it) {\n    var O = toIObject(it);\n    var keys = getKeys(O);\n    var length = keys.length;\n    var i = 0;\n    var result = [];\n    var key;\n    while (length > i) if (isEnum.call(O, key = keys[i++])) {\n      result.push(isEntries ? [key, O[key]] : O[key]);\n    } return result;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_own-keys.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_own-keys.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// all object keys, includes non-enumerable and symbols\nvar gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\");\nvar gOPS = __webpack_require__(/*! ./_object-gops */ \"./node_modules/core-js/modules/_object-gops.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar Reflect = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").Reflect;\nmodule.exports = Reflect && Reflect.ownKeys || function ownKeys(it) {\n  var keys = gOPN.f(anObject(it));\n  var getSymbols = gOPS.f;\n  return getSymbols ? keys.concat(getSymbols(it)) : keys;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_parse-float.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_parse-float.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $parseFloat = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").parseFloat;\nvar $trim = __webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\").trim;\n\nmodule.exports = 1 / $parseFloat(__webpack_require__(/*! ./_string-ws */ \"./node_modules/core-js/modules/_string-ws.js\") + '-0') !== -Infinity ? function parseFloat(str) {\n  var string = $trim(String(str), 3);\n  var result = $parseFloat(string);\n  return result === 0 && string.charAt(0) == '-' ? -0 : result;\n} : $parseFloat;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_parse-int.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_parse-int.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $parseInt = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").parseInt;\nvar $trim = __webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\").trim;\nvar ws = __webpack_require__(/*! ./_string-ws */ \"./node_modules/core-js/modules/_string-ws.js\");\nvar hex = /^[-+]?0[xX]/;\n\nmodule.exports = $parseInt(ws + '08') !== 8 || $parseInt(ws + '0x16') !== 22 ? function parseInt(str, radix) {\n  var string = $trim(String(str), 3);\n  return $parseInt(string, (radix >>> 0) || (hex.test(string) ? 16 : 10));\n} : $parseInt;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_perform.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_perform.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (exec) {\n  try {\n    return { e: false, v: exec() };\n  } catch (e) {\n    return { e: true, v: e };\n  }\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_promise-resolve.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_promise-resolve.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar newPromiseCapability = __webpack_require__(/*! ./_new-promise-capability */ \"./node_modules/core-js/modules/_new-promise-capability.js\");\n\nmodule.exports = function (C, x) {\n  anObject(C);\n  if (isObject(x) && x.constructor === C) return x;\n  var promiseCapability = newPromiseCapability.f(C);\n  var resolve = promiseCapability.resolve;\n  resolve(x);\n  return promiseCapability.promise;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_property-desc.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_property-desc.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (bitmap, value) {\n  return {\n    enumerable: !(bitmap & 1),\n    configurable: !(bitmap & 2),\n    writable: !(bitmap & 4),\n    value: value\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_redefine-all.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_redefine-all.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nmodule.exports = function (target, src, safe) {\n  for (var key in src) redefine(target, key, src[key], safe);\n  return target;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_redefine.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_redefine.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar SRC = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\")('src');\nvar $toString = __webpack_require__(/*! ./_function-to-string */ \"./node_modules/core-js/modules/_function-to-string.js\");\nvar TO_STRING = 'toString';\nvar TPL = ('' + $toString).split(TO_STRING);\n\n__webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\").inspectSource = function (it) {\n  return $toString.call(it);\n};\n\n(module.exports = function (O, key, val, safe) {\n  var isFunction = typeof val == 'function';\n  if (isFunction) has(val, 'name') || hide(val, 'name', key);\n  if (O[key] === val) return;\n  if (isFunction) has(val, SRC) || hide(val, SRC, O[key] ? '' + O[key] : TPL.join(String(key)));\n  if (O === global) {\n    O[key] = val;\n  } else if (!safe) {\n    delete O[key];\n    hide(O, key, val);\n  } else if (O[key]) {\n    O[key] = val;\n  } else {\n    hide(O, key, val);\n  }\n// add fake Function#toString for correct work wrapped methods / constructors with methods like LoDash isNative\n})(Function.prototype, TO_STRING, function toString() {\n  return typeof this == 'function' && this[SRC] || $toString.call(this);\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_regexp-exec-abstract.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_regexp-exec-abstract.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar builtinExec = RegExp.prototype.exec;\n\n // `RegExpExec` abstract operation\n// https://tc39.github.io/ecma262/#sec-regexpexec\nmodule.exports = function (R, S) {\n  var exec = R.exec;\n  if (typeof exec === 'function') {\n    var result = exec.call(R, S);\n    if (typeof result !== 'object') {\n      throw new TypeError('RegExp exec method returned something other than an Object or null');\n    }\n    return result;\n  }\n  if (classof(R) !== 'RegExp') {\n    throw new TypeError('RegExp#exec called on incompatible receiver');\n  }\n  return builtinExec.call(R, S);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_regexp-exec.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_regexp-exec.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar regexpFlags = __webpack_require__(/*! ./_flags */ \"./node_modules/core-js/modules/_flags.js\");\n\nvar nativeExec = RegExp.prototype.exec;\n// This always refers to the native implementation, because the\n// String#replace polyfill uses ./fix-regexp-well-known-symbol-logic.js,\n// which loads this file before patching the method.\nvar nativeReplace = String.prototype.replace;\n\nvar patchedExec = nativeExec;\n\nvar LAST_INDEX = 'lastIndex';\n\nvar UPDATES_LAST_INDEX_WRONG = (function () {\n  var re1 = /a/,\n      re2 = /b*/g;\n  nativeExec.call(re1, 'a');\n  nativeExec.call(re2, 'a');\n  return re1[LAST_INDEX] !== 0 || re2[LAST_INDEX] !== 0;\n})();\n\n// nonparticipating capturing group, copied from es5-shim's String#split patch.\nvar NPCG_INCLUDED = /()??/.exec('')[1] !== undefined;\n\nvar PATCH = UPDATES_LAST_INDEX_WRONG || NPCG_INCLUDED;\n\nif (PATCH) {\n  patchedExec = function exec(str) {\n    var re = this;\n    var lastIndex, reCopy, match, i;\n\n    if (NPCG_INCLUDED) {\n      reCopy = new RegExp('^' + re.source + '$(?!\\\\s)', regexpFlags.call(re));\n    }\n    if (UPDATES_LAST_INDEX_WRONG) lastIndex = re[LAST_INDEX];\n\n    match = nativeExec.call(re, str);\n\n    if (UPDATES_LAST_INDEX_WRONG && match) {\n      re[LAST_INDEX] = re.global ? match.index + match[0].length : lastIndex;\n    }\n    if (NPCG_INCLUDED && match && match.length > 1) {\n      // Fix browsers whose `exec` methods don't consistently return `undefined`\n      // for NPCG, like IE8. NOTE: This doesn' work for /(.?)?/\n      // eslint-disable-next-line no-loop-func\n      nativeReplace.call(match[0], reCopy, function () {\n        for (i = 1; i < arguments.length - 2; i++) {\n          if (arguments[i] === undefined) match[i] = undefined;\n        }\n      });\n    }\n\n    return match;\n  };\n}\n\nmodule.exports = patchedExec;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_replacer.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_replacer.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = function (regExp, replace) {\n  var replacer = replace === Object(replace) ? function (part) {\n    return replace[part];\n  } : replace;\n  return function (it) {\n    return String(it).replace(regExp, replacer);\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_same-value.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_same-value.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 7.2.9 SameValue(x, y)\nmodule.exports = Object.is || function is(x, y) {\n  // eslint-disable-next-line no-self-compare\n  return x === y ? x !== 0 || 1 / x === 1 / y : x != x && y != y;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-collection-from.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-collection-from.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/proposal-setmap-offrom/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\n\nmodule.exports = function (COLLECTION) {\n  $export($export.S, COLLECTION, { from: function from(source /* , mapFn, thisArg */) {\n    var mapFn = arguments[1];\n    var mapping, A, n, cb;\n    aFunction(this);\n    mapping = mapFn !== undefined;\n    if (mapping) aFunction(mapFn);\n    if (source == undefined) return new this();\n    A = [];\n    if (mapping) {\n      n = 0;\n      cb = ctx(mapFn, arguments[2], 2);\n      forOf(source, false, function (nextItem) {\n        A.push(cb(nextItem, n++));\n      });\n    } else {\n      forOf(source, false, A.push, A);\n    }\n    return new this(A);\n  } });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-collection-of.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-collection-of.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/proposal-setmap-offrom/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\nmodule.exports = function (COLLECTION) {\n  $export($export.S, COLLECTION, { of: function of() {\n    var length = arguments.length;\n    var A = new Array(length);\n    while (length--) A[length] = arguments[length];\n    return new this(A);\n  } });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-proto.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-proto.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// Works with __proto__ only. Old v8 can't work with null proto objects.\n/* eslint-disable no-proto */\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar check = function (O, proto) {\n  anObject(O);\n  if (!isObject(proto) && proto !== null) throw TypeError(proto + \": can't set as prototype!\");\n};\nmodule.exports = {\n  set: Object.setPrototypeOf || ('__proto__' in {} ? // eslint-disable-line\n    function (test, buggy, set) {\n      try {\n        set = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\")(Function.call, __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f(Object.prototype, '__proto__').set, 2);\n        set(test, []);\n        buggy = !(test instanceof Array);\n      } catch (e) { buggy = true; }\n      return function setPrototypeOf(O, proto) {\n        check(O, proto);\n        if (buggy) O.__proto__ = proto;\n        else set(O, proto);\n        return O;\n      };\n    }({}, false) : undefined),\n  check: check\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-species.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-species.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\n\nmodule.exports = function (KEY) {\n  var C = global[KEY];\n  if (DESCRIPTORS && C && !C[SPECIES]) dP.f(C, SPECIES, {\n    configurable: true,\n    get: function () { return this; }\n  });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_set-to-string-tag.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_set-to-string-tag.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar def = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar TAG = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag');\n\nmodule.exports = function (it, tag, stat) {\n  if (it && !has(it = stat ? it : it.prototype, TAG)) def(it, TAG, { configurable: true, value: tag });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_shared-key.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_shared-key.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar shared = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('keys');\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nmodule.exports = function (key) {\n  return shared[key] || (shared[key] = uid(key));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_shared.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/_shared.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar SHARED = '__core-js_shared__';\nvar store = global[SHARED] || (global[SHARED] = {});\n\n(module.exports = function (key, value) {\n  return store[key] || (store[key] = value !== undefined ? value : {});\n})('versions', []).push({\n  version: core.version,\n  mode: __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\") ? 'pure' : 'global',\n  copyright: '© 2019 Denis Pushkarev (zloirock.ru)'\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_species-constructor.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_species-constructor.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.3.20 SpeciesConstructor(O, defaultConstructor)\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar SPECIES = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species');\nmodule.exports = function (O, D) {\n  var C = anObject(O).constructor;\n  var S;\n  return C === undefined || (S = anObject(C)[SPECIES]) == undefined ? D : aFunction(S);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_strict-method.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_strict-method.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\n\nmodule.exports = function (method, arg) {\n  return !!method && fails(function () {\n    // eslint-disable-next-line no-useless-call\n    arg ? method.call(null, function () { /* empty */ }, 1) : method.call(null);\n  });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-at.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-at.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\n// true  -> String#at\n// false -> String#codePointAt\nmodule.exports = function (TO_STRING) {\n  return function (that, pos) {\n    var s = String(defined(that));\n    var i = toInteger(pos);\n    var l = s.length;\n    var a, b;\n    if (i < 0 || i >= l) return TO_STRING ? '' : undefined;\n    a = s.charCodeAt(i);\n    return a < 0xd800 || a > 0xdbff || i + 1 === l || (b = s.charCodeAt(i + 1)) < 0xdc00 || b > 0xdfff\n      ? TO_STRING ? s.charAt(i) : a\n      : TO_STRING ? s.slice(i, i + 2) : (a - 0xd800 << 10) + (b - 0xdc00) + 0x10000;\n  };\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-context.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-context.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// helper for String#{startsWith, endsWith, includes}\nvar isRegExp = __webpack_require__(/*! ./_is-regexp */ \"./node_modules/core-js/modules/_is-regexp.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\n\nmodule.exports = function (that, searchString, NAME) {\n  if (isRegExp(searchString)) throw TypeError('String#' + NAME + \" doesn't accept regex!\");\n  return String(defined(that));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-html.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-html.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nvar quot = /\"/g;\n// B.2.3.2.1 CreateHTML(string, tag, attribute, value)\nvar createHTML = function (string, tag, attribute, value) {\n  var S = String(defined(string));\n  var p1 = '<' + tag;\n  if (attribute !== '') p1 += ' ' + attribute + '=\"' + String(value).replace(quot, '&quot;') + '\"';\n  return p1 + '>' + S + '</' + tag + '>';\n};\nmodule.exports = function (NAME, exec) {\n  var O = {};\n  O[NAME] = exec(createHTML);\n  $export($export.P + $export.F * fails(function () {\n    var test = ''[NAME]('\"');\n    return test !== test.toLowerCase() || test.split('\"').length > 3;\n  }), 'String', O);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-pad.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-pad.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-string-pad-start-end\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar repeat = __webpack_require__(/*! ./_string-repeat */ \"./node_modules/core-js/modules/_string-repeat.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\n\nmodule.exports = function (that, maxLength, fillString, left) {\n  var S = String(defined(that));\n  var stringLength = S.length;\n  var fillStr = fillString === undefined ? ' ' : String(fillString);\n  var intMaxLength = toLength(maxLength);\n  if (intMaxLength <= stringLength || fillStr == '') return S;\n  var fillLen = intMaxLength - stringLength;\n  var stringFiller = repeat.call(fillStr, Math.ceil(fillLen / fillStr.length));\n  if (stringFiller.length > fillLen) stringFiller = stringFiller.slice(0, fillLen);\n  return left ? stringFiller + S : S + stringFiller;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-repeat.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-repeat.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\n\nmodule.exports = function repeat(count) {\n  var str = String(defined(this));\n  var res = '';\n  var n = toInteger(count);\n  if (n < 0 || n == Infinity) throw RangeError(\"Count can't be negative\");\n  for (;n > 0; (n >>>= 1) && (str += str)) if (n & 1) res += str;\n  return res;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-trim.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-trim.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar spaces = __webpack_require__(/*! ./_string-ws */ \"./node_modules/core-js/modules/_string-ws.js\");\nvar space = '[' + spaces + ']';\nvar non = '\\u200b\\u0085';\nvar ltrim = RegExp('^' + space + space + '*');\nvar rtrim = RegExp(space + space + '*$');\n\nvar exporter = function (KEY, exec, ALIAS) {\n  var exp = {};\n  var FORCE = fails(function () {\n    return !!spaces[KEY]() || non[KEY]() != non;\n  });\n  var fn = exp[KEY] = FORCE ? exec(trim) : spaces[KEY];\n  if (ALIAS) exp[ALIAS] = fn;\n  $export($export.P + $export.F * FORCE, 'String', exp);\n};\n\n// 1 -> String#trimLeft\n// 2 -> String#trimRight\n// 3 -> String#trim\nvar trim = exporter.trim = function (string, TYPE) {\n  string = String(defined(string));\n  if (TYPE & 1) string = string.replace(ltrim, '');\n  if (TYPE & 2) string = string.replace(rtrim, '');\n  return string;\n};\n\nmodule.exports = exporter;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_string-ws.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_string-ws.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nmodule.exports = '\\x09\\x0A\\x0B\\x0C\\x0D\\x20\\xA0\\u1680\\u180E\\u2000\\u2001\\u2002\\u2003' +\n  '\\u2004\\u2005\\u2006\\u2007\\u2008\\u2009\\u200A\\u202F\\u205F\\u3000\\u2028\\u2029\\uFEFF';\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_task.js\":\n/*!***********************************************!*\\\n  !*** ./node_modules/core-js/modules/_task.js ***!\n  \\***********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar invoke = __webpack_require__(/*! ./_invoke */ \"./node_modules/core-js/modules/_invoke.js\");\nvar html = __webpack_require__(/*! ./_html */ \"./node_modules/core-js/modules/_html.js\");\nvar cel = __webpack_require__(/*! ./_dom-create */ \"./node_modules/core-js/modules/_dom-create.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar process = global.process;\nvar setTask = global.setImmediate;\nvar clearTask = global.clearImmediate;\nvar MessageChannel = global.MessageChannel;\nvar Dispatch = global.Dispatch;\nvar counter = 0;\nvar queue = {};\nvar ONREADYSTATECHANGE = 'onreadystatechange';\nvar defer, channel, port;\nvar run = function () {\n  var id = +this;\n  // eslint-disable-next-line no-prototype-builtins\n  if (queue.hasOwnProperty(id)) {\n    var fn = queue[id];\n    delete queue[id];\n    fn();\n  }\n};\nvar listener = function (event) {\n  run.call(event.data);\n};\n// Node.js 0.9+ & IE10+ has setImmediate, otherwise:\nif (!setTask || !clearTask) {\n  setTask = function setImmediate(fn) {\n    var args = [];\n    var i = 1;\n    while (arguments.length > i) args.push(arguments[i++]);\n    queue[++counter] = function () {\n      // eslint-disable-next-line no-new-func\n      invoke(typeof fn == 'function' ? fn : Function(fn), args);\n    };\n    defer(counter);\n    return counter;\n  };\n  clearTask = function clearImmediate(id) {\n    delete queue[id];\n  };\n  // Node.js 0.8-\n  if (__webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\")(process) == 'process') {\n    defer = function (id) {\n      process.nextTick(ctx(run, id, 1));\n    };\n  // Sphere (JS game engine) Dispatch API\n  } else if (Dispatch && Dispatch.now) {\n    defer = function (id) {\n      Dispatch.now(ctx(run, id, 1));\n    };\n  // Browsers with MessageChannel, includes WebWorkers\n  } else if (MessageChannel) {\n    channel = new MessageChannel();\n    port = channel.port2;\n    channel.port1.onmessage = listener;\n    defer = ctx(port.postMessage, port, 1);\n  // Browsers with postMessage, skip WebWorkers\n  // IE8 has postMessage, but it's sync & typeof its postMessage is 'object'\n  } else if (global.addEventListener && typeof postMessage == 'function' && !global.importScripts) {\n    defer = function (id) {\n      global.postMessage(id + '', '*');\n    };\n    global.addEventListener('message', listener, false);\n  // IE8-\n  } else if (ONREADYSTATECHANGE in cel('script')) {\n    defer = function (id) {\n      html.appendChild(cel('script'))[ONREADYSTATECHANGE] = function () {\n        html.removeChild(this);\n        run.call(id);\n      };\n    };\n  // Rest old browsers\n  } else {\n    defer = function (id) {\n      setTimeout(ctx(run, id, 1), 0);\n    };\n  }\n}\nmodule.exports = {\n  set: setTask,\n  clear: clearTask\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-absolute-index.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-absolute-index.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar max = Math.max;\nvar min = Math.min;\nmodule.exports = function (index, length) {\n  index = toInteger(index);\n  return index < 0 ? max(index + length, 0) : min(index, length);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-index.js\":\n/*!***************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-index.js ***!\n  \\***************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/ecma262/#sec-toindex\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nmodule.exports = function (it) {\n  if (it === undefined) return 0;\n  var number = toInteger(it);\n  var length = toLength(number);\n  if (number !== length) throw RangeError('Wrong length!');\n  return length;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-integer.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-integer.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// 7.1.4 ToInteger\nvar ceil = Math.ceil;\nvar floor = Math.floor;\nmodule.exports = function (it) {\n  return isNaN(it = +it) ? 0 : (it > 0 ? floor : ceil)(it);\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-iobject.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-iobject.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// to indexed object, toObject with fallback for non-array-like ES3 strings\nvar IObject = __webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nmodule.exports = function (it) {\n  return IObject(defined(it));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-length.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-length.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.15 ToLength\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar min = Math.min;\nmodule.exports = function (it) {\n  return it > 0 ? min(toInteger(it), 0x1fffffffffffff) : 0; // pow(2, 53) - 1 == 9007199254740991\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-object.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-object.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.13 ToObject(argument)\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nmodule.exports = function (it) {\n  return Object(defined(it));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_to-primitive.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_to-primitive.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 7.1.1 ToPrimitive(input [, PreferredType])\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n// instead of the ES6 spec version, we didn't implement @@toPrimitive case\n// and the second argument - flag - preferred type is a string\nmodule.exports = function (it, S) {\n  if (!isObject(it)) return it;\n  var fn, val;\n  if (S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (typeof (fn = it.valueOf) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (!S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  throw TypeError(\"Can't convert object to primitive value\");\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_typed-array.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_typed-array.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nif (__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\")) {\n  var LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\n  var global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\n  var fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\n  var $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n  var $typed = __webpack_require__(/*! ./_typed */ \"./node_modules/core-js/modules/_typed.js\");\n  var $buffer = __webpack_require__(/*! ./_typed-buffer */ \"./node_modules/core-js/modules/_typed-buffer.js\");\n  var ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\n  var anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\n  var propertyDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\n  var hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\n  var redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\n  var toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\n  var toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\n  var toIndex = __webpack_require__(/*! ./_to-index */ \"./node_modules/core-js/modules/_to-index.js\");\n  var toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\n  var toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\n  var has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\n  var classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\n  var isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n  var toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\n  var isArrayIter = __webpack_require__(/*! ./_is-array-iter */ \"./node_modules/core-js/modules/_is-array-iter.js\");\n  var create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\n  var getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\n  var gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f;\n  var getIterFn = __webpack_require__(/*! ./core.get-iterator-method */ \"./node_modules/core-js/modules/core.get-iterator-method.js\");\n  var uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\n  var wks = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\n  var createArrayMethod = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\");\n  var createArrayIncludes = __webpack_require__(/*! ./_array-includes */ \"./node_modules/core-js/modules/_array-includes.js\");\n  var speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\n  var ArrayIterators = __webpack_require__(/*! ./es6.array.iterator */ \"./node_modules/core-js/modules/es6.array.iterator.js\");\n  var Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\n  var $iterDetect = __webpack_require__(/*! ./_iter-detect */ \"./node_modules/core-js/modules/_iter-detect.js\");\n  var setSpecies = __webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\");\n  var arrayFill = __webpack_require__(/*! ./_array-fill */ \"./node_modules/core-js/modules/_array-fill.js\");\n  var arrayCopyWithin = __webpack_require__(/*! ./_array-copy-within */ \"./node_modules/core-js/modules/_array-copy-within.js\");\n  var $DP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\n  var $GOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\n  var dP = $DP.f;\n  var gOPD = $GOPD.f;\n  var RangeError = global.RangeError;\n  var TypeError = global.TypeError;\n  var Uint8Array = global.Uint8Array;\n  var ARRAY_BUFFER = 'ArrayBuffer';\n  var SHARED_BUFFER = 'Shared' + ARRAY_BUFFER;\n  var BYTES_PER_ELEMENT = 'BYTES_PER_ELEMENT';\n  var PROTOTYPE = 'prototype';\n  var ArrayProto = Array[PROTOTYPE];\n  var $ArrayBuffer = $buffer.ArrayBuffer;\n  var $DataView = $buffer.DataView;\n  var arrayForEach = createArrayMethod(0);\n  var arrayFilter = createArrayMethod(2);\n  var arraySome = createArrayMethod(3);\n  var arrayEvery = createArrayMethod(4);\n  var arrayFind = createArrayMethod(5);\n  var arrayFindIndex = createArrayMethod(6);\n  var arrayIncludes = createArrayIncludes(true);\n  var arrayIndexOf = createArrayIncludes(false);\n  var arrayValues = ArrayIterators.values;\n  var arrayKeys = ArrayIterators.keys;\n  var arrayEntries = ArrayIterators.entries;\n  var arrayLastIndexOf = ArrayProto.lastIndexOf;\n  var arrayReduce = ArrayProto.reduce;\n  var arrayReduceRight = ArrayProto.reduceRight;\n  var arrayJoin = ArrayProto.join;\n  var arraySort = ArrayProto.sort;\n  var arraySlice = ArrayProto.slice;\n  var arrayToString = ArrayProto.toString;\n  var arrayToLocaleString = ArrayProto.toLocaleString;\n  var ITERATOR = wks('iterator');\n  var TAG = wks('toStringTag');\n  var TYPED_CONSTRUCTOR = uid('typed_constructor');\n  var DEF_CONSTRUCTOR = uid('def_constructor');\n  var ALL_CONSTRUCTORS = $typed.CONSTR;\n  var TYPED_ARRAY = $typed.TYPED;\n  var VIEW = $typed.VIEW;\n  var WRONG_LENGTH = 'Wrong length!';\n\n  var $map = createArrayMethod(1, function (O, length) {\n    return allocate(speciesConstructor(O, O[DEF_CONSTRUCTOR]), length);\n  });\n\n  var LITTLE_ENDIAN = fails(function () {\n    // eslint-disable-next-line no-undef\n    return new Uint8Array(new Uint16Array([1]).buffer)[0] === 1;\n  });\n\n  var FORCED_SET = !!Uint8Array && !!Uint8Array[PROTOTYPE].set && fails(function () {\n    new Uint8Array(1).set({});\n  });\n\n  var toOffset = function (it, BYTES) {\n    var offset = toInteger(it);\n    if (offset < 0 || offset % BYTES) throw RangeError('Wrong offset!');\n    return offset;\n  };\n\n  var validate = function (it) {\n    if (isObject(it) && TYPED_ARRAY in it) return it;\n    throw TypeError(it + ' is not a typed array!');\n  };\n\n  var allocate = function (C, length) {\n    if (!(isObject(C) && TYPED_CONSTRUCTOR in C)) {\n      throw TypeError('It is not a typed array constructor!');\n    } return new C(length);\n  };\n\n  var speciesFromList = function (O, list) {\n    return fromList(speciesConstructor(O, O[DEF_CONSTRUCTOR]), list);\n  };\n\n  var fromList = function (C, list) {\n    var index = 0;\n    var length = list.length;\n    var result = allocate(C, length);\n    while (length > index) result[index] = list[index++];\n    return result;\n  };\n\n  var addGetter = function (it, key, internal) {\n    dP(it, key, { get: function () { return this._d[internal]; } });\n  };\n\n  var $from = function from(source /* , mapfn, thisArg */) {\n    var O = toObject(source);\n    var aLen = arguments.length;\n    var mapfn = aLen > 1 ? arguments[1] : undefined;\n    var mapping = mapfn !== undefined;\n    var iterFn = getIterFn(O);\n    var i, length, values, result, step, iterator;\n    if (iterFn != undefined && !isArrayIter(iterFn)) {\n      for (iterator = iterFn.call(O), values = [], i = 0; !(step = iterator.next()).done; i++) {\n        values.push(step.value);\n      } O = values;\n    }\n    if (mapping && aLen > 2) mapfn = ctx(mapfn, arguments[2], 2);\n    for (i = 0, length = toLength(O.length), result = allocate(this, length); length > i; i++) {\n      result[i] = mapping ? mapfn(O[i], i) : O[i];\n    }\n    return result;\n  };\n\n  var $of = function of(/* ...items */) {\n    var index = 0;\n    var length = arguments.length;\n    var result = allocate(this, length);\n    while (length > index) result[index] = arguments[index++];\n    return result;\n  };\n\n  // iOS Safari 6.x fails here\n  var TO_LOCALE_BUG = !!Uint8Array && fails(function () { arrayToLocaleString.call(new Uint8Array(1)); });\n\n  var $toLocaleString = function toLocaleString() {\n    return arrayToLocaleString.apply(TO_LOCALE_BUG ? arraySlice.call(validate(this)) : validate(this), arguments);\n  };\n\n  var proto = {\n    copyWithin: function copyWithin(target, start /* , end */) {\n      return arrayCopyWithin.call(validate(this), target, start, arguments.length > 2 ? arguments[2] : undefined);\n    },\n    every: function every(callbackfn /* , thisArg */) {\n      return arrayEvery(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    fill: function fill(value /* , start, end */) { // eslint-disable-line no-unused-vars\n      return arrayFill.apply(validate(this), arguments);\n    },\n    filter: function filter(callbackfn /* , thisArg */) {\n      return speciesFromList(this, arrayFilter(validate(this), callbackfn,\n        arguments.length > 1 ? arguments[1] : undefined));\n    },\n    find: function find(predicate /* , thisArg */) {\n      return arrayFind(validate(this), predicate, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    findIndex: function findIndex(predicate /* , thisArg */) {\n      return arrayFindIndex(validate(this), predicate, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    forEach: function forEach(callbackfn /* , thisArg */) {\n      arrayForEach(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    indexOf: function indexOf(searchElement /* , fromIndex */) {\n      return arrayIndexOf(validate(this), searchElement, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    includes: function includes(searchElement /* , fromIndex */) {\n      return arrayIncludes(validate(this), searchElement, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    join: function join(separator) { // eslint-disable-line no-unused-vars\n      return arrayJoin.apply(validate(this), arguments);\n    },\n    lastIndexOf: function lastIndexOf(searchElement /* , fromIndex */) { // eslint-disable-line no-unused-vars\n      return arrayLastIndexOf.apply(validate(this), arguments);\n    },\n    map: function map(mapfn /* , thisArg */) {\n      return $map(validate(this), mapfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    reduce: function reduce(callbackfn /* , initialValue */) { // eslint-disable-line no-unused-vars\n      return arrayReduce.apply(validate(this), arguments);\n    },\n    reduceRight: function reduceRight(callbackfn /* , initialValue */) { // eslint-disable-line no-unused-vars\n      return arrayReduceRight.apply(validate(this), arguments);\n    },\n    reverse: function reverse() {\n      var that = this;\n      var length = validate(that).length;\n      var middle = Math.floor(length / 2);\n      var index = 0;\n      var value;\n      while (index < middle) {\n        value = that[index];\n        that[index++] = that[--length];\n        that[length] = value;\n      } return that;\n    },\n    some: function some(callbackfn /* , thisArg */) {\n      return arraySome(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    sort: function sort(comparefn) {\n      return arraySort.call(validate(this), comparefn);\n    },\n    subarray: function subarray(begin, end) {\n      var O = validate(this);\n      var length = O.length;\n      var $begin = toAbsoluteIndex(begin, length);\n      return new (speciesConstructor(O, O[DEF_CONSTRUCTOR]))(\n        O.buffer,\n        O.byteOffset + $begin * O.BYTES_PER_ELEMENT,\n        toLength((end === undefined ? length : toAbsoluteIndex(end, length)) - $begin)\n      );\n    }\n  };\n\n  var $slice = function slice(start, end) {\n    return speciesFromList(this, arraySlice.call(validate(this), start, end));\n  };\n\n  var $set = function set(arrayLike /* , offset */) {\n    validate(this);\n    var offset = toOffset(arguments[1], 1);\n    var length = this.length;\n    var src = toObject(arrayLike);\n    var len = toLength(src.length);\n    var index = 0;\n    if (len + offset > length) throw RangeError(WRONG_LENGTH);\n    while (index < len) this[offset + index] = src[index++];\n  };\n\n  var $iterators = {\n    entries: function entries() {\n      return arrayEntries.call(validate(this));\n    },\n    keys: function keys() {\n      return arrayKeys.call(validate(this));\n    },\n    values: function values() {\n      return arrayValues.call(validate(this));\n    }\n  };\n\n  var isTAIndex = function (target, key) {\n    return isObject(target)\n      && target[TYPED_ARRAY]\n      && typeof key != 'symbol'\n      && key in target\n      && String(+key) == String(key);\n  };\n  var $getDesc = function getOwnPropertyDescriptor(target, key) {\n    return isTAIndex(target, key = toPrimitive(key, true))\n      ? propertyDesc(2, target[key])\n      : gOPD(target, key);\n  };\n  var $setDesc = function defineProperty(target, key, desc) {\n    if (isTAIndex(target, key = toPrimitive(key, true))\n      && isObject(desc)\n      && has(desc, 'value')\n      && !has(desc, 'get')\n      && !has(desc, 'set')\n      // TODO: add validation descriptor w/o calling accessors\n      && !desc.configurable\n      && (!has(desc, 'writable') || desc.writable)\n      && (!has(desc, 'enumerable') || desc.enumerable)\n    ) {\n      target[key] = desc.value;\n      return target;\n    } return dP(target, key, desc);\n  };\n\n  if (!ALL_CONSTRUCTORS) {\n    $GOPD.f = $getDesc;\n    $DP.f = $setDesc;\n  }\n\n  $export($export.S + $export.F * !ALL_CONSTRUCTORS, 'Object', {\n    getOwnPropertyDescriptor: $getDesc,\n    defineProperty: $setDesc\n  });\n\n  if (fails(function () { arrayToString.call({}); })) {\n    arrayToString = arrayToLocaleString = function toString() {\n      return arrayJoin.call(this);\n    };\n  }\n\n  var $TypedArrayPrototype$ = redefineAll({}, proto);\n  redefineAll($TypedArrayPrototype$, $iterators);\n  hide($TypedArrayPrototype$, ITERATOR, $iterators.values);\n  redefineAll($TypedArrayPrototype$, {\n    slice: $slice,\n    set: $set,\n    constructor: function () { /* noop */ },\n    toString: arrayToString,\n    toLocaleString: $toLocaleString\n  });\n  addGetter($TypedArrayPrototype$, 'buffer', 'b');\n  addGetter($TypedArrayPrototype$, 'byteOffset', 'o');\n  addGetter($TypedArrayPrototype$, 'byteLength', 'l');\n  addGetter($TypedArrayPrototype$, 'length', 'e');\n  dP($TypedArrayPrototype$, TAG, {\n    get: function () { return this[TYPED_ARRAY]; }\n  });\n\n  // eslint-disable-next-line max-statements\n  module.exports = function (KEY, BYTES, wrapper, CLAMPED) {\n    CLAMPED = !!CLAMPED;\n    var NAME = KEY + (CLAMPED ? 'Clamped' : '') + 'Array';\n    var GETTER = 'get' + KEY;\n    var SETTER = 'set' + KEY;\n    var TypedArray = global[NAME];\n    var Base = TypedArray || {};\n    var TAC = TypedArray && getPrototypeOf(TypedArray);\n    var FORCED = !TypedArray || !$typed.ABV;\n    var O = {};\n    var TypedArrayPrototype = TypedArray && TypedArray[PROTOTYPE];\n    var getter = function (that, index) {\n      var data = that._d;\n      return data.v[GETTER](index * BYTES + data.o, LITTLE_ENDIAN);\n    };\n    var setter = function (that, index, value) {\n      var data = that._d;\n      if (CLAMPED) value = (value = Math.round(value)) < 0 ? 0 : value > 0xff ? 0xff : value & 0xff;\n      data.v[SETTER](index * BYTES + data.o, value, LITTLE_ENDIAN);\n    };\n    var addElement = function (that, index) {\n      dP(that, index, {\n        get: function () {\n          return getter(this, index);\n        },\n        set: function (value) {\n          return setter(this, index, value);\n        },\n        enumerable: true\n      });\n    };\n    if (FORCED) {\n      TypedArray = wrapper(function (that, data, $offset, $length) {\n        anInstance(that, TypedArray, NAME, '_d');\n        var index = 0;\n        var offset = 0;\n        var buffer, byteLength, length, klass;\n        if (!isObject(data)) {\n          length = toIndex(data);\n          byteLength = length * BYTES;\n          buffer = new $ArrayBuffer(byteLength);\n        } else if (data instanceof $ArrayBuffer || (klass = classof(data)) == ARRAY_BUFFER || klass == SHARED_BUFFER) {\n          buffer = data;\n          offset = toOffset($offset, BYTES);\n          var $len = data.byteLength;\n          if ($length === undefined) {\n            if ($len % BYTES) throw RangeError(WRONG_LENGTH);\n            byteLength = $len - offset;\n            if (byteLength < 0) throw RangeError(WRONG_LENGTH);\n          } else {\n            byteLength = toLength($length) * BYTES;\n            if (byteLength + offset > $len) throw RangeError(WRONG_LENGTH);\n          }\n          length = byteLength / BYTES;\n        } else if (TYPED_ARRAY in data) {\n          return fromList(TypedArray, data);\n        } else {\n          return $from.call(TypedArray, data);\n        }\n        hide(that, '_d', {\n          b: buffer,\n          o: offset,\n          l: byteLength,\n          e: length,\n          v: new $DataView(buffer)\n        });\n        while (index < length) addElement(that, index++);\n      });\n      TypedArrayPrototype = TypedArray[PROTOTYPE] = create($TypedArrayPrototype$);\n      hide(TypedArrayPrototype, 'constructor', TypedArray);\n    } else if (!fails(function () {\n      TypedArray(1);\n    }) || !fails(function () {\n      new TypedArray(-1); // eslint-disable-line no-new\n    }) || !$iterDetect(function (iter) {\n      new TypedArray(); // eslint-disable-line no-new\n      new TypedArray(null); // eslint-disable-line no-new\n      new TypedArray(1.5); // eslint-disable-line no-new\n      new TypedArray(iter); // eslint-disable-line no-new\n    }, true)) {\n      TypedArray = wrapper(function (that, data, $offset, $length) {\n        anInstance(that, TypedArray, NAME);\n        var klass;\n        // `ws` module bug, temporarily remove validation length for Uint8Array\n        // https://github.com/websockets/ws/pull/645\n        if (!isObject(data)) return new Base(toIndex(data));\n        if (data instanceof $ArrayBuffer || (klass = classof(data)) == ARRAY_BUFFER || klass == SHARED_BUFFER) {\n          return $length !== undefined\n            ? new Base(data, toOffset($offset, BYTES), $length)\n            : $offset !== undefined\n              ? new Base(data, toOffset($offset, BYTES))\n              : new Base(data);\n        }\n        if (TYPED_ARRAY in data) return fromList(TypedArray, data);\n        return $from.call(TypedArray, data);\n      });\n      arrayForEach(TAC !== Function.prototype ? gOPN(Base).concat(gOPN(TAC)) : gOPN(Base), function (key) {\n        if (!(key in TypedArray)) hide(TypedArray, key, Base[key]);\n      });\n      TypedArray[PROTOTYPE] = TypedArrayPrototype;\n      if (!LIBRARY) TypedArrayPrototype.constructor = TypedArray;\n    }\n    var $nativeIterator = TypedArrayPrototype[ITERATOR];\n    var CORRECT_ITER_NAME = !!$nativeIterator\n      && ($nativeIterator.name == 'values' || $nativeIterator.name == undefined);\n    var $iterator = $iterators.values;\n    hide(TypedArray, TYPED_CONSTRUCTOR, true);\n    hide(TypedArrayPrototype, TYPED_ARRAY, NAME);\n    hide(TypedArrayPrototype, VIEW, true);\n    hide(TypedArrayPrototype, DEF_CONSTRUCTOR, TypedArray);\n\n    if (CLAMPED ? new TypedArray(1)[TAG] != NAME : !(TAG in TypedArrayPrototype)) {\n      dP(TypedArrayPrototype, TAG, {\n        get: function () { return NAME; }\n      });\n    }\n\n    O[NAME] = TypedArray;\n\n    $export($export.G + $export.W + $export.F * (TypedArray != Base), O);\n\n    $export($export.S, NAME, {\n      BYTES_PER_ELEMENT: BYTES\n    });\n\n    $export($export.S + $export.F * fails(function () { Base.of.call(TypedArray, 1); }), NAME, {\n      from: $from,\n      of: $of\n    });\n\n    if (!(BYTES_PER_ELEMENT in TypedArrayPrototype)) hide(TypedArrayPrototype, BYTES_PER_ELEMENT, BYTES);\n\n    $export($export.P, NAME, proto);\n\n    setSpecies(NAME);\n\n    $export($export.P + $export.F * FORCED_SET, NAME, { set: $set });\n\n    $export($export.P + $export.F * !CORRECT_ITER_NAME, NAME, $iterators);\n\n    if (!LIBRARY && TypedArrayPrototype.toString != arrayToString) TypedArrayPrototype.toString = arrayToString;\n\n    $export($export.P + $export.F * fails(function () {\n      new TypedArray(1).slice();\n    }), NAME, { slice: $slice });\n\n    $export($export.P + $export.F * (fails(function () {\n      return [1, 2].toLocaleString() != new TypedArray([1, 2]).toLocaleString();\n    }) || !fails(function () {\n      TypedArrayPrototype.toLocaleString.call([1, 2]);\n    })), NAME, { toLocaleString: $toLocaleString });\n\n    Iterators[NAME] = CORRECT_ITER_NAME ? $nativeIterator : $iterator;\n    if (!LIBRARY && !CORRECT_ITER_NAME) hide(TypedArrayPrototype, ITERATOR, $iterator);\n  };\n} else module.exports = function () { /* empty */ };\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_typed-buffer.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/_typed-buffer.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar $typed = __webpack_require__(/*! ./_typed */ \"./node_modules/core-js/modules/_typed.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar toIndex = __webpack_require__(/*! ./_to-index */ \"./node_modules/core-js/modules/_to-index.js\");\nvar gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f;\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar arrayFill = __webpack_require__(/*! ./_array-fill */ \"./node_modules/core-js/modules/_array-fill.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar ARRAY_BUFFER = 'ArrayBuffer';\nvar DATA_VIEW = 'DataView';\nvar PROTOTYPE = 'prototype';\nvar WRONG_LENGTH = 'Wrong length!';\nvar WRONG_INDEX = 'Wrong index!';\nvar $ArrayBuffer = global[ARRAY_BUFFER];\nvar $DataView = global[DATA_VIEW];\nvar Math = global.Math;\nvar RangeError = global.RangeError;\n// eslint-disable-next-line no-shadow-restricted-names\nvar Infinity = global.Infinity;\nvar BaseBuffer = $ArrayBuffer;\nvar abs = Math.abs;\nvar pow = Math.pow;\nvar floor = Math.floor;\nvar log = Math.log;\nvar LN2 = Math.LN2;\nvar BUFFER = 'buffer';\nvar BYTE_LENGTH = 'byteLength';\nvar BYTE_OFFSET = 'byteOffset';\nvar $BUFFER = DESCRIPTORS ? '_b' : BUFFER;\nvar $LENGTH = DESCRIPTORS ? '_l' : BYTE_LENGTH;\nvar $OFFSET = DESCRIPTORS ? '_o' : BYTE_OFFSET;\n\n// IEEE754 conversions based on https://github.com/feross/ieee754\nfunction packIEEE754(value, mLen, nBytes) {\n  var buffer = new Array(nBytes);\n  var eLen = nBytes * 8 - mLen - 1;\n  var eMax = (1 << eLen) - 1;\n  var eBias = eMax >> 1;\n  var rt = mLen === 23 ? pow(2, -24) - pow(2, -77) : 0;\n  var i = 0;\n  var s = value < 0 || value === 0 && 1 / value < 0 ? 1 : 0;\n  var e, m, c;\n  value = abs(value);\n  // eslint-disable-next-line no-self-compare\n  if (value != value || value === Infinity) {\n    // eslint-disable-next-line no-self-compare\n    m = value != value ? 1 : 0;\n    e = eMax;\n  } else {\n    e = floor(log(value) / LN2);\n    if (value * (c = pow(2, -e)) < 1) {\n      e--;\n      c *= 2;\n    }\n    if (e + eBias >= 1) {\n      value += rt / c;\n    } else {\n      value += rt * pow(2, 1 - eBias);\n    }\n    if (value * c >= 2) {\n      e++;\n      c /= 2;\n    }\n    if (e + eBias >= eMax) {\n      m = 0;\n      e = eMax;\n    } else if (e + eBias >= 1) {\n      m = (value * c - 1) * pow(2, mLen);\n      e = e + eBias;\n    } else {\n      m = value * pow(2, eBias - 1) * pow(2, mLen);\n      e = 0;\n    }\n  }\n  for (; mLen >= 8; buffer[i++] = m & 255, m /= 256, mLen -= 8);\n  e = e << mLen | m;\n  eLen += mLen;\n  for (; eLen > 0; buffer[i++] = e & 255, e /= 256, eLen -= 8);\n  buffer[--i] |= s * 128;\n  return buffer;\n}\nfunction unpackIEEE754(buffer, mLen, nBytes) {\n  var eLen = nBytes * 8 - mLen - 1;\n  var eMax = (1 << eLen) - 1;\n  var eBias = eMax >> 1;\n  var nBits = eLen - 7;\n  var i = nBytes - 1;\n  var s = buffer[i--];\n  var e = s & 127;\n  var m;\n  s >>= 7;\n  for (; nBits > 0; e = e * 256 + buffer[i], i--, nBits -= 8);\n  m = e & (1 << -nBits) - 1;\n  e >>= -nBits;\n  nBits += mLen;\n  for (; nBits > 0; m = m * 256 + buffer[i], i--, nBits -= 8);\n  if (e === 0) {\n    e = 1 - eBias;\n  } else if (e === eMax) {\n    return m ? NaN : s ? -Infinity : Infinity;\n  } else {\n    m = m + pow(2, mLen);\n    e = e - eBias;\n  } return (s ? -1 : 1) * m * pow(2, e - mLen);\n}\n\nfunction unpackI32(bytes) {\n  return bytes[3] << 24 | bytes[2] << 16 | bytes[1] << 8 | bytes[0];\n}\nfunction packI8(it) {\n  return [it & 0xff];\n}\nfunction packI16(it) {\n  return [it & 0xff, it >> 8 & 0xff];\n}\nfunction packI32(it) {\n  return [it & 0xff, it >> 8 & 0xff, it >> 16 & 0xff, it >> 24 & 0xff];\n}\nfunction packF64(it) {\n  return packIEEE754(it, 52, 8);\n}\nfunction packF32(it) {\n  return packIEEE754(it, 23, 4);\n}\n\nfunction addGetter(C, key, internal) {\n  dP(C[PROTOTYPE], key, { get: function () { return this[internal]; } });\n}\n\nfunction get(view, bytes, index, isLittleEndian) {\n  var numIndex = +index;\n  var intIndex = toIndex(numIndex);\n  if (intIndex + bytes > view[$LENGTH]) throw RangeError(WRONG_INDEX);\n  var store = view[$BUFFER]._b;\n  var start = intIndex + view[$OFFSET];\n  var pack = store.slice(start, start + bytes);\n  return isLittleEndian ? pack : pack.reverse();\n}\nfunction set(view, bytes, index, conversion, value, isLittleEndian) {\n  var numIndex = +index;\n  var intIndex = toIndex(numIndex);\n  if (intIndex + bytes > view[$LENGTH]) throw RangeError(WRONG_INDEX);\n  var store = view[$BUFFER]._b;\n  var start = intIndex + view[$OFFSET];\n  var pack = conversion(+value);\n  for (var i = 0; i < bytes; i++) store[start + i] = pack[isLittleEndian ? i : bytes - i - 1];\n}\n\nif (!$typed.ABV) {\n  $ArrayBuffer = function ArrayBuffer(length) {\n    anInstance(this, $ArrayBuffer, ARRAY_BUFFER);\n    var byteLength = toIndex(length);\n    this._b = arrayFill.call(new Array(byteLength), 0);\n    this[$LENGTH] = byteLength;\n  };\n\n  $DataView = function DataView(buffer, byteOffset, byteLength) {\n    anInstance(this, $DataView, DATA_VIEW);\n    anInstance(buffer, $ArrayBuffer, DATA_VIEW);\n    var bufferLength = buffer[$LENGTH];\n    var offset = toInteger(byteOffset);\n    if (offset < 0 || offset > bufferLength) throw RangeError('Wrong offset!');\n    byteLength = byteLength === undefined ? bufferLength - offset : toLength(byteLength);\n    if (offset + byteLength > bufferLength) throw RangeError(WRONG_LENGTH);\n    this[$BUFFER] = buffer;\n    this[$OFFSET] = offset;\n    this[$LENGTH] = byteLength;\n  };\n\n  if (DESCRIPTORS) {\n    addGetter($ArrayBuffer, BYTE_LENGTH, '_l');\n    addGetter($DataView, BUFFER, '_b');\n    addGetter($DataView, BYTE_LENGTH, '_l');\n    addGetter($DataView, BYTE_OFFSET, '_o');\n  }\n\n  redefineAll($DataView[PROTOTYPE], {\n    getInt8: function getInt8(byteOffset) {\n      return get(this, 1, byteOffset)[0] << 24 >> 24;\n    },\n    getUint8: function getUint8(byteOffset) {\n      return get(this, 1, byteOffset)[0];\n    },\n    getInt16: function getInt16(byteOffset /* , littleEndian */) {\n      var bytes = get(this, 2, byteOffset, arguments[1]);\n      return (bytes[1] << 8 | bytes[0]) << 16 >> 16;\n    },\n    getUint16: function getUint16(byteOffset /* , littleEndian */) {\n      var bytes = get(this, 2, byteOffset, arguments[1]);\n      return bytes[1] << 8 | bytes[0];\n    },\n    getInt32: function getInt32(byteOffset /* , littleEndian */) {\n      return unpackI32(get(this, 4, byteOffset, arguments[1]));\n    },\n    getUint32: function getUint32(byteOffset /* , littleEndian */) {\n      return unpackI32(get(this, 4, byteOffset, arguments[1])) >>> 0;\n    },\n    getFloat32: function getFloat32(byteOffset /* , littleEndian */) {\n      return unpackIEEE754(get(this, 4, byteOffset, arguments[1]), 23, 4);\n    },\n    getFloat64: function getFloat64(byteOffset /* , littleEndian */) {\n      return unpackIEEE754(get(this, 8, byteOffset, arguments[1]), 52, 8);\n    },\n    setInt8: function setInt8(byteOffset, value) {\n      set(this, 1, byteOffset, packI8, value);\n    },\n    setUint8: function setUint8(byteOffset, value) {\n      set(this, 1, byteOffset, packI8, value);\n    },\n    setInt16: function setInt16(byteOffset, value /* , littleEndian */) {\n      set(this, 2, byteOffset, packI16, value, arguments[2]);\n    },\n    setUint16: function setUint16(byteOffset, value /* , littleEndian */) {\n      set(this, 2, byteOffset, packI16, value, arguments[2]);\n    },\n    setInt32: function setInt32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packI32, value, arguments[2]);\n    },\n    setUint32: function setUint32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packI32, value, arguments[2]);\n    },\n    setFloat32: function setFloat32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packF32, value, arguments[2]);\n    },\n    setFloat64: function setFloat64(byteOffset, value /* , littleEndian */) {\n      set(this, 8, byteOffset, packF64, value, arguments[2]);\n    }\n  });\n} else {\n  if (!fails(function () {\n    $ArrayBuffer(1);\n  }) || !fails(function () {\n    new $ArrayBuffer(-1); // eslint-disable-line no-new\n  }) || fails(function () {\n    new $ArrayBuffer(); // eslint-disable-line no-new\n    new $ArrayBuffer(1.5); // eslint-disable-line no-new\n    new $ArrayBuffer(NaN); // eslint-disable-line no-new\n    return $ArrayBuffer.name != ARRAY_BUFFER;\n  })) {\n    $ArrayBuffer = function ArrayBuffer(length) {\n      anInstance(this, $ArrayBuffer);\n      return new BaseBuffer(toIndex(length));\n    };\n    var ArrayBufferProto = $ArrayBuffer[PROTOTYPE] = BaseBuffer[PROTOTYPE];\n    for (var keys = gOPN(BaseBuffer), j = 0, key; keys.length > j;) {\n      if (!((key = keys[j++]) in $ArrayBuffer)) hide($ArrayBuffer, key, BaseBuffer[key]);\n    }\n    if (!LIBRARY) ArrayBufferProto.constructor = $ArrayBuffer;\n  }\n  // iOS Safari 7.x bug\n  var view = new $DataView(new $ArrayBuffer(2));\n  var $setInt8 = $DataView[PROTOTYPE].setInt8;\n  view.setInt8(0, 2147483648);\n  view.setInt8(1, 2147483649);\n  if (view.getInt8(0) || !view.getInt8(1)) redefineAll($DataView[PROTOTYPE], {\n    setInt8: function setInt8(byteOffset, value) {\n      $setInt8.call(this, byteOffset, value << 24 >> 24);\n    },\n    setUint8: function setUint8(byteOffset, value) {\n      $setInt8.call(this, byteOffset, value << 24 >> 24);\n    }\n  }, true);\n}\nsetToStringTag($ArrayBuffer, ARRAY_BUFFER);\nsetToStringTag($DataView, DATA_VIEW);\nhide($DataView[PROTOTYPE], $typed.VIEW, true);\nexports[ARRAY_BUFFER] = $ArrayBuffer;\nexports[DATA_VIEW] = $DataView;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_typed.js\":\n/*!************************************************!*\\\n  !*** ./node_modules/core-js/modules/_typed.js ***!\n  \\************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nvar TYPED = uid('typed_array');\nvar VIEW = uid('view');\nvar ABV = !!(global.ArrayBuffer && global.DataView);\nvar CONSTR = ABV;\nvar i = 0;\nvar l = 9;\nvar Typed;\n\nvar TypedArrayConstructors = (\n  'Int8Array,Uint8Array,Uint8ClampedArray,Int16Array,Uint16Array,Int32Array,Uint32Array,Float32Array,Float64Array'\n).split(',');\n\nwhile (i < l) {\n  if (Typed = global[TypedArrayConstructors[i++]]) {\n    hide(Typed.prototype, TYPED, true);\n    hide(Typed.prototype, VIEW, true);\n  } else CONSTR = false;\n}\n\nmodule.exports = {\n  ABV: ABV,\n  CONSTR: CONSTR,\n  TYPED: TYPED,\n  VIEW: VIEW\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_uid.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_uid.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar id = 0;\nvar px = Math.random();\nmodule.exports = function (key) {\n  return 'Symbol('.concat(key === undefined ? '' : key, ')_', (++id + px).toString(36));\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_user-agent.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_user-agent.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar navigator = global.navigator;\n\nmodule.exports = navigator && navigator.userAgent || '';\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_validate-collection.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/_validate-collection.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nmodule.exports = function (it, TYPE) {\n  if (!isObject(it) || it._t !== TYPE) throw TypeError('Incompatible receiver, ' + TYPE + ' required!');\n  return it;\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_wks-define.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/_wks-define.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar wksExt = __webpack_require__(/*! ./_wks-ext */ \"./node_modules/core-js/modules/_wks-ext.js\");\nvar defineProperty = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nmodule.exports = function (name) {\n  var $Symbol = core.Symbol || (core.Symbol = LIBRARY ? {} : global.Symbol || {});\n  if (name.charAt(0) != '_' && !(name in $Symbol)) defineProperty($Symbol, name, { value: wksExt.f(name) });\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_wks-ext.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/_wks-ext.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nexports.f = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/_wks.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/core-js/modules/_wks.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar store = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\")('wks');\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nvar Symbol = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").Symbol;\nvar USE_SYMBOL = typeof Symbol == 'function';\n\nvar $exports = module.exports = function (name) {\n  return store[name] || (store[name] =\n    USE_SYMBOL && Symbol[name] || (USE_SYMBOL ? Symbol : uid)('Symbol.' + name));\n};\n\n$exports.store = store;\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/core.get-iterator-method.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/core.get-iterator-method.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar ITERATOR = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('iterator');\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nmodule.exports = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\").getIteratorMethod = function (it) {\n  if (it != undefined) return it[ITERATOR]\n    || it['@@iterator']\n    || Iterators[classof(it)];\n};\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/core.regexp.escape.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/core.regexp.escape.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/benjamingr/RexExp.escape\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $re = __webpack_require__(/*! ./_replacer */ \"./node_modules/core-js/modules/_replacer.js\")(/[\\\\^$*+?.()|[\\]{}]/g, '\\\\$&');\n\n$export($export.S, 'RegExp', { escape: function escape(it) { return $re(it); } });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.copy-within.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.copy-within.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.3.3 Array.prototype.copyWithin(target, start, end = this.length)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P, 'Array', { copyWithin: __webpack_require__(/*! ./_array-copy-within */ \"./node_modules/core-js/modules/_array-copy-within.js\") });\n\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")('copyWithin');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.every.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.every.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $every = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(4);\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].every, true), 'Array', {\n  // 22.1.3.5 / 15.4.4.16 Array.prototype.every(callbackfn [, thisArg])\n  every: function every(callbackfn /* , thisArg */) {\n    return $every(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.fill.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.fill.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.3.6 Array.prototype.fill(value, start = 0, end = this.length)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P, 'Array', { fill: __webpack_require__(/*! ./_array-fill */ \"./node_modules/core-js/modules/_array-fill.js\") });\n\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")('fill');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.filter.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.filter.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $filter = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(2);\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].filter, true), 'Array', {\n  // 22.1.3.7 / 15.4.4.20 Array.prototype.filter(callbackfn [, thisArg])\n  filter: function filter(callbackfn /* , thisArg */) {\n    return $filter(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.find-index.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.find-index.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 22.1.3.9 Array.prototype.findIndex(predicate, thisArg = undefined)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $find = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(6);\nvar KEY = 'findIndex';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  findIndex: function findIndex(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")(KEY);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.find.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.find.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 22.1.3.8 Array.prototype.find(predicate, thisArg = undefined)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $find = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(5);\nvar KEY = 'find';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  find: function find(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")(KEY);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.for-each.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.for-each.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $forEach = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(0);\nvar STRICT = __webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].forEach, true);\n\n$export($export.P + $export.F * !STRICT, 'Array', {\n  // 22.1.3.10 / 15.4.4.18 Array.prototype.forEach(callbackfn [, thisArg])\n  forEach: function forEach(callbackfn /* , thisArg */) {\n    return $forEach(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.from.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.from.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar call = __webpack_require__(/*! ./_iter-call */ \"./node_modules/core-js/modules/_iter-call.js\");\nvar isArrayIter = __webpack_require__(/*! ./_is-array-iter */ \"./node_modules/core-js/modules/_is-array-iter.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar createProperty = __webpack_require__(/*! ./_create-property */ \"./node_modules/core-js/modules/_create-property.js\");\nvar getIterFn = __webpack_require__(/*! ./core.get-iterator-method */ \"./node_modules/core-js/modules/core.get-iterator-method.js\");\n\n$export($export.S + $export.F * !__webpack_require__(/*! ./_iter-detect */ \"./node_modules/core-js/modules/_iter-detect.js\")(function (iter) { Array.from(iter); }), 'Array', {\n  // 22.1.2.1 Array.from(arrayLike, mapfn = undefined, thisArg = undefined)\n  from: function from(arrayLike /* , mapfn = undefined, thisArg = undefined */) {\n    var O = toObject(arrayLike);\n    var C = typeof this == 'function' ? this : Array;\n    var aLen = arguments.length;\n    var mapfn = aLen > 1 ? arguments[1] : undefined;\n    var mapping = mapfn !== undefined;\n    var index = 0;\n    var iterFn = getIterFn(O);\n    var length, result, step, iterator;\n    if (mapping) mapfn = ctx(mapfn, aLen > 2 ? arguments[2] : undefined, 2);\n    // if object isn't iterable or it's array with default iterator - use simple case\n    if (iterFn != undefined && !(C == Array && isArrayIter(iterFn))) {\n      for (iterator = iterFn.call(O), result = new C(); !(step = iterator.next()).done; index++) {\n        createProperty(result, index, mapping ? call(iterator, mapfn, [step.value, index], true) : step.value);\n      }\n    } else {\n      length = toLength(O.length);\n      for (result = new C(length); length > index; index++) {\n        createProperty(result, index, mapping ? mapfn(O[index], index) : O[index]);\n      }\n    }\n    result.length = index;\n    return result;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.index-of.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.index-of.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $indexOf = __webpack_require__(/*! ./_array-includes */ \"./node_modules/core-js/modules/_array-includes.js\")(false);\nvar $native = [].indexOf;\nvar NEGATIVE_ZERO = !!$native && 1 / [1].indexOf(1, -0) < 0;\n\n$export($export.P + $export.F * (NEGATIVE_ZERO || !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")($native)), 'Array', {\n  // 22.1.3.11 / 15.4.4.14 Array.prototype.indexOf(searchElement [, fromIndex])\n  indexOf: function indexOf(searchElement /* , fromIndex = 0 */) {\n    return NEGATIVE_ZERO\n      // convert -0 to +0\n      ? $native.apply(this, arguments) || 0\n      : $indexOf(this, searchElement, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.is-array.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.is-array.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 22.1.2.2 / 15.4.3.2 Array.isArray(arg)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Array', { isArray: __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.iterator.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.iterator.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar addToUnscopables = __webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\");\nvar step = __webpack_require__(/*! ./_iter-step */ \"./node_modules/core-js/modules/_iter-step.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\n\n// 22.1.3.4 Array.prototype.entries()\n// 22.1.3.13 Array.prototype.keys()\n// 22.1.3.29 Array.prototype.values()\n// 22.1.3.30 Array.prototype[@@iterator]()\nmodule.exports = __webpack_require__(/*! ./_iter-define */ \"./node_modules/core-js/modules/_iter-define.js\")(Array, 'Array', function (iterated, kind) {\n  this._t = toIObject(iterated); // target\n  this._i = 0;                   // next index\n  this._k = kind;                // kind\n// 22.1.5.2.1 %ArrayIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var kind = this._k;\n  var index = this._i++;\n  if (!O || index >= O.length) {\n    this._t = undefined;\n    return step(1);\n  }\n  if (kind == 'keys') return step(0, index);\n  if (kind == 'values') return step(0, O[index]);\n  return step(0, [index, O[index]]);\n}, 'values');\n\n// argumentsList[@@iterator] is %ArrayProto_values% (9.4.4.6, 9.4.4.7)\nIterators.Arguments = Iterators.Array;\n\naddToUnscopables('keys');\naddToUnscopables('values');\naddToUnscopables('entries');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.join.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.join.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 22.1.3.13 Array.prototype.join(separator)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar arrayJoin = [].join;\n\n// fallback for not array-like strings\n$export($export.P + $export.F * (__webpack_require__(/*! ./_iobject */ \"./node_modules/core-js/modules/_iobject.js\") != Object || !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")(arrayJoin)), 'Array', {\n  join: function join(separator) {\n    return arrayJoin.call(toIObject(this), separator === undefined ? ',' : separator);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.last-index-of.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.last-index-of.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar $native = [].lastIndexOf;\nvar NEGATIVE_ZERO = !!$native && 1 / [1].lastIndexOf(1, -0) < 0;\n\n$export($export.P + $export.F * (NEGATIVE_ZERO || !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")($native)), 'Array', {\n  // 22.1.3.14 / 15.4.4.15 Array.prototype.lastIndexOf(searchElement [, fromIndex])\n  lastIndexOf: function lastIndexOf(searchElement /* , fromIndex = @[*-1] */) {\n    // convert -0 to +0\n    if (NEGATIVE_ZERO) return $native.apply(this, arguments) || 0;\n    var O = toIObject(this);\n    var length = toLength(O.length);\n    var index = length - 1;\n    if (arguments.length > 1) index = Math.min(index, toInteger(arguments[1]));\n    if (index < 0) index = length + index;\n    for (;index >= 0; index--) if (index in O) if (O[index] === searchElement) return index || 0;\n    return -1;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.map.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.map.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $map = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(1);\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].map, true), 'Array', {\n  // 22.1.3.15 / 15.4.4.19 Array.prototype.map(callbackfn [, thisArg])\n  map: function map(callbackfn /* , thisArg */) {\n    return $map(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.of.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.of.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar createProperty = __webpack_require__(/*! ./_create-property */ \"./node_modules/core-js/modules/_create-property.js\");\n\n// WebKit Array.of isn't generic\n$export($export.S + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  function F() { /* empty */ }\n  return !(Array.of.call(F) instanceof F);\n}), 'Array', {\n  // 22.1.2.3 Array.of( ...items)\n  of: function of(/* ...args */) {\n    var index = 0;\n    var aLen = arguments.length;\n    var result = new (typeof this == 'function' ? this : Array)(aLen);\n    while (aLen > index) createProperty(result, index, arguments[index++]);\n    result.length = aLen;\n    return result;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.reduce-right.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.reduce-right.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $reduce = __webpack_require__(/*! ./_array-reduce */ \"./node_modules/core-js/modules/_array-reduce.js\");\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].reduceRight, true), 'Array', {\n  // 22.1.3.19 / 15.4.4.22 Array.prototype.reduceRight(callbackfn [, initialValue])\n  reduceRight: function reduceRight(callbackfn /* , initialValue */) {\n    return $reduce(this, callbackfn, arguments.length, arguments[1], true);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.reduce.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.reduce.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $reduce = __webpack_require__(/*! ./_array-reduce */ \"./node_modules/core-js/modules/_array-reduce.js\");\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].reduce, true), 'Array', {\n  // 22.1.3.18 / 15.4.4.21 Array.prototype.reduce(callbackfn [, initialValue])\n  reduce: function reduce(callbackfn /* , initialValue */) {\n    return $reduce(this, callbackfn, arguments.length, arguments[1], false);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.slice.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.slice.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar html = __webpack_require__(/*! ./_html */ \"./node_modules/core-js/modules/_html.js\");\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar arraySlice = [].slice;\n\n// fallback for not array-like ES3 strings and DOM objects\n$export($export.P + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  if (html) arraySlice.call(html);\n}), 'Array', {\n  slice: function slice(begin, end) {\n    var len = toLength(this.length);\n    var klass = cof(this);\n    end = end === undefined ? len : end;\n    if (klass == 'Array') return arraySlice.call(this, begin, end);\n    var start = toAbsoluteIndex(begin, len);\n    var upTo = toAbsoluteIndex(end, len);\n    var size = toLength(upTo - start);\n    var cloned = new Array(size);\n    var i = 0;\n    for (; i < size; i++) cloned[i] = klass == 'String'\n      ? this.charAt(start + i)\n      : this[start + i];\n    return cloned;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.some.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.some.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $some = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(3);\n\n$export($export.P + $export.F * !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")([].some, true), 'Array', {\n  // 22.1.3.23 / 15.4.4.17 Array.prototype.some(callbackfn [, thisArg])\n  some: function some(callbackfn /* , thisArg */) {\n    return $some(this, callbackfn, arguments[1]);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.sort.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.sort.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar $sort = [].sort;\nvar test = [1, 2, 3];\n\n$export($export.P + $export.F * (fails(function () {\n  // IE8-\n  test.sort(undefined);\n}) || !fails(function () {\n  // V8 bug\n  test.sort(null);\n  // Old WebKit\n}) || !__webpack_require__(/*! ./_strict-method */ \"./node_modules/core-js/modules/_strict-method.js\")($sort)), 'Array', {\n  // 22.1.3.25 Array.prototype.sort(comparefn)\n  sort: function sort(comparefn) {\n    return comparefn === undefined\n      ? $sort.call(toObject(this))\n      : $sort.call(toObject(this), aFunction(comparefn));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.array.species.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.array.species.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")('Array');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.date.now.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.date.now.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.3.3.1 / 15.9.4.4 Date.now()\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Date', { now: function () { return new Date().getTime(); } });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.date.to-iso-string.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.date.to-iso-string.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.3.4.36 / 15.9.5.43 Date.prototype.toISOString()\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toISOString = __webpack_require__(/*! ./_date-to-iso-string */ \"./node_modules/core-js/modules/_date-to-iso-string.js\");\n\n// PhantomJS / old WebKit has a broken implementations\n$export($export.P + $export.F * (Date.prototype.toISOString !== toISOString), 'Date', {\n  toISOString: toISOString\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.date.to-json.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.date.to-json.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\n\n$export($export.P + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return new Date(NaN).toJSON() !== null\n    || Date.prototype.toJSON.call({ toISOString: function () { return 1; } }) !== 1;\n}), 'Date', {\n  // eslint-disable-next-line no-unused-vars\n  toJSON: function toJSON(key) {\n    var O = toObject(this);\n    var pv = toPrimitive(O);\n    return typeof pv == 'number' && !isFinite(pv) ? null : O.toISOString();\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.date.to-primitive.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.date.to-primitive.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar TO_PRIMITIVE = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toPrimitive');\nvar proto = Date.prototype;\n\nif (!(TO_PRIMITIVE in proto)) __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")(proto, TO_PRIMITIVE, __webpack_require__(/*! ./_date-to-primitive */ \"./node_modules/core-js/modules/_date-to-primitive.js\"));\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.date.to-string.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.date.to-string.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar DateProto = Date.prototype;\nvar INVALID_DATE = 'Invalid Date';\nvar TO_STRING = 'toString';\nvar $toString = DateProto[TO_STRING];\nvar getTime = DateProto.getTime;\nif (new Date(NaN) + '' != INVALID_DATE) {\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(DateProto, TO_STRING, function toString() {\n    var value = getTime.call(this);\n    // eslint-disable-next-line no-self-compare\n    return value === value ? $toString.call(this) : INVALID_DATE;\n  });\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.function.bind.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.function.bind.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.2.3.2 / 15.3.4.5 Function.prototype.bind(thisArg, args...)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P, 'Function', { bind: __webpack_require__(/*! ./_bind */ \"./node_modules/core-js/modules/_bind.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.function.has-instance.js\":\n/*!*******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.function.has-instance.js ***!\n  \\*******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar HAS_INSTANCE = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('hasInstance');\nvar FunctionProto = Function.prototype;\n// 19.2.3.6 Function.prototype[@@hasInstance](V)\nif (!(HAS_INSTANCE in FunctionProto)) __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f(FunctionProto, HAS_INSTANCE, { value: function (O) {\n  if (typeof this != 'function' || !isObject(O)) return false;\n  if (!isObject(this.prototype)) return O instanceof this;\n  // for environment w/o native `@@hasInstance` logic enough `instanceof`, but add this:\n  while (O = getPrototypeOf(O)) if (this.prototype === O) return true;\n  return false;\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.function.name.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.function.name.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar FProto = Function.prototype;\nvar nameRE = /^\\s*function ([^ (]*)/;\nvar NAME = 'name';\n\n// 19.2.4.2 name\nNAME in FProto || __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && dP(FProto, NAME, {\n  configurable: true,\n  get: function () {\n    try {\n      return ('' + this).match(nameRE)[1];\n    } catch (e) {\n      return '';\n    }\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.map.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.map.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar strong = __webpack_require__(/*! ./_collection-strong */ \"./node_modules/core-js/modules/_collection-strong.js\");\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar MAP = 'Map';\n\n// 23.1 Map Objects\nmodule.exports = __webpack_require__(/*! ./_collection */ \"./node_modules/core-js/modules/_collection.js\")(MAP, function (get) {\n  return function Map() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.1.3.6 Map.prototype.get(key)\n  get: function get(key) {\n    var entry = strong.getEntry(validate(this, MAP), key);\n    return entry && entry.v;\n  },\n  // 23.1.3.9 Map.prototype.set(key, value)\n  set: function set(key, value) {\n    return strong.def(validate(this, MAP), key === 0 ? 0 : key, value);\n  }\n}, strong, true);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.acosh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.acosh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.3 Math.acosh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar log1p = __webpack_require__(/*! ./_math-log1p */ \"./node_modules/core-js/modules/_math-log1p.js\");\nvar sqrt = Math.sqrt;\nvar $acosh = Math.acosh;\n\n$export($export.S + $export.F * !($acosh\n  // V8 bug: https://code.google.com/p/v8/issues/detail?id=3509\n  && Math.floor($acosh(Number.MAX_VALUE)) == 710\n  // Tor Browser bug: Math.acosh(Infinity) -> NaN\n  && $acosh(Infinity) == Infinity\n), 'Math', {\n  acosh: function acosh(x) {\n    return (x = +x) < 1 ? NaN : x > 94906265.62425156\n      ? Math.log(x) + Math.LN2\n      : log1p(x - 1 + sqrt(x - 1) * sqrt(x + 1));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.asinh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.asinh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.5 Math.asinh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $asinh = Math.asinh;\n\nfunction asinh(x) {\n  return !isFinite(x = +x) || x == 0 ? x : x < 0 ? -asinh(-x) : Math.log(x + Math.sqrt(x * x + 1));\n}\n\n// Tor Browser bug: Math.asinh(0) -> -0\n$export($export.S + $export.F * !($asinh && 1 / $asinh(0) > 0), 'Math', { asinh: asinh });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.atanh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.atanh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.7 Math.atanh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $atanh = Math.atanh;\n\n// Tor Browser bug: Math.atanh(-0) -> 0\n$export($export.S + $export.F * !($atanh && 1 / $atanh(-0) < 0), 'Math', {\n  atanh: function atanh(x) {\n    return (x = +x) == 0 ? x : Math.log((1 + x) / (1 - x)) / 2;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.cbrt.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.cbrt.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.9 Math.cbrt(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar sign = __webpack_require__(/*! ./_math-sign */ \"./node_modules/core-js/modules/_math-sign.js\");\n\n$export($export.S, 'Math', {\n  cbrt: function cbrt(x) {\n    return sign(x = +x) * Math.pow(Math.abs(x), 1 / 3);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.clz32.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.clz32.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.11 Math.clz32(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  clz32: function clz32(x) {\n    return (x >>>= 0) ? 31 - Math.floor(Math.log(x + 0.5) * Math.LOG2E) : 32;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.cosh.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.cosh.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.12 Math.cosh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar exp = Math.exp;\n\n$export($export.S, 'Math', {\n  cosh: function cosh(x) {\n    return (exp(x = +x) + exp(-x)) / 2;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.expm1.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.expm1.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.14 Math.expm1(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $expm1 = __webpack_require__(/*! ./_math-expm1 */ \"./node_modules/core-js/modules/_math-expm1.js\");\n\n$export($export.S + $export.F * ($expm1 != Math.expm1), 'Math', { expm1: $expm1 });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.fround.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.fround.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.16 Math.fround(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { fround: __webpack_require__(/*! ./_math-fround */ \"./node_modules/core-js/modules/_math-fround.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.hypot.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.hypot.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.17 Math.hypot([value1[, value2[, … ]]])\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar abs = Math.abs;\n\n$export($export.S, 'Math', {\n  hypot: function hypot(value1, value2) { // eslint-disable-line no-unused-vars\n    var sum = 0;\n    var i = 0;\n    var aLen = arguments.length;\n    var larg = 0;\n    var arg, div;\n    while (i < aLen) {\n      arg = abs(arguments[i++]);\n      if (larg < arg) {\n        div = larg / arg;\n        sum = sum * div * div + 1;\n        larg = arg;\n      } else if (arg > 0) {\n        div = arg / larg;\n        sum += div * div;\n      } else sum += arg;\n    }\n    return larg === Infinity ? Infinity : larg * Math.sqrt(sum);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.imul.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.imul.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.18 Math.imul(x, y)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $imul = Math.imul;\n\n// some WebKit versions fails with big numbers, some has wrong arity\n$export($export.S + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return $imul(0xffffffff, 5) != -5 || $imul.length != 2;\n}), 'Math', {\n  imul: function imul(x, y) {\n    var UINT16 = 0xffff;\n    var xn = +x;\n    var yn = +y;\n    var xl = UINT16 & xn;\n    var yl = UINT16 & yn;\n    return 0 | xl * yl + ((UINT16 & xn >>> 16) * yl + xl * (UINT16 & yn >>> 16) << 16 >>> 0);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.log10.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.log10.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.21 Math.log10(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  log10: function log10(x) {\n    return Math.log(x) * Math.LOG10E;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.log1p.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.log1p.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.20 Math.log1p(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { log1p: __webpack_require__(/*! ./_math-log1p */ \"./node_modules/core-js/modules/_math-log1p.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.log2.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.log2.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.22 Math.log2(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  log2: function log2(x) {\n    return Math.log(x) / Math.LN2;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.sign.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.sign.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.28 Math.sign(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { sign: __webpack_require__(/*! ./_math-sign */ \"./node_modules/core-js/modules/_math-sign.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.sinh.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.sinh.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.30 Math.sinh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar expm1 = __webpack_require__(/*! ./_math-expm1 */ \"./node_modules/core-js/modules/_math-expm1.js\");\nvar exp = Math.exp;\n\n// V8 near Chromium 38 has a problem with very small numbers\n$export($export.S + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return !Math.sinh(-2e-17) != -2e-17;\n}), 'Math', {\n  sinh: function sinh(x) {\n    return Math.abs(x = +x) < 1\n      ? (expm1(x) - expm1(-x)) / 2\n      : (exp(x - 1) - exp(-x - 1)) * (Math.E / 2);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.tanh.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.tanh.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.33 Math.tanh(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar expm1 = __webpack_require__(/*! ./_math-expm1 */ \"./node_modules/core-js/modules/_math-expm1.js\");\nvar exp = Math.exp;\n\n$export($export.S, 'Math', {\n  tanh: function tanh(x) {\n    var a = expm1(x = +x);\n    var b = expm1(-x);\n    return a == Infinity ? 1 : b == Infinity ? -1 : (a - b) / (exp(x) + exp(-x));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.math.trunc.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.math.trunc.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.2.2.34 Math.trunc(x)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  trunc: function trunc(it) {\n    return (it > 0 ? Math.floor : Math.ceil)(it);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.constructor.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.constructor.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\nvar inheritIfRequired = __webpack_require__(/*! ./_inherit-if-required */ \"./node_modules/core-js/modules/_inherit-if-required.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f;\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f;\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar $trim = __webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\").trim;\nvar NUMBER = 'Number';\nvar $Number = global[NUMBER];\nvar Base = $Number;\nvar proto = $Number.prototype;\n// Opera ~12 has broken Object#toString\nvar BROKEN_COF = cof(__webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\")(proto)) == NUMBER;\nvar TRIM = 'trim' in String.prototype;\n\n// 7.1.3 ToNumber(argument)\nvar toNumber = function (argument) {\n  var it = toPrimitive(argument, false);\n  if (typeof it == 'string' && it.length > 2) {\n    it = TRIM ? it.trim() : $trim(it, 3);\n    var first = it.charCodeAt(0);\n    var third, radix, maxCode;\n    if (first === 43 || first === 45) {\n      third = it.charCodeAt(2);\n      if (third === 88 || third === 120) return NaN; // Number('+0x1') should be NaN, old V8 fix\n    } else if (first === 48) {\n      switch (it.charCodeAt(1)) {\n        case 66: case 98: radix = 2; maxCode = 49; break; // fast equal /^0b[01]+$/i\n        case 79: case 111: radix = 8; maxCode = 55; break; // fast equal /^0o[0-7]+$/i\n        default: return +it;\n      }\n      for (var digits = it.slice(2), i = 0, l = digits.length, code; i < l; i++) {\n        code = digits.charCodeAt(i);\n        // parseInt parses a string to a first unavailable symbol\n        // but ToNumber should return NaN if a string contains unavailable symbols\n        if (code < 48 || code > maxCode) return NaN;\n      } return parseInt(digits, radix);\n    }\n  } return +it;\n};\n\nif (!$Number(' 0o1') || !$Number('0b1') || $Number('+0x1')) {\n  $Number = function Number(value) {\n    var it = arguments.length < 1 ? 0 : value;\n    var that = this;\n    return that instanceof $Number\n      // check on 1..constructor(foo) case\n      && (BROKEN_COF ? fails(function () { proto.valueOf.call(that); }) : cof(that) != NUMBER)\n        ? inheritIfRequired(new Base(toNumber(it)), that, $Number) : toNumber(it);\n  };\n  for (var keys = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") ? gOPN(Base) : (\n    // ES3:\n    'MAX_VALUE,MIN_VALUE,NaN,NEGATIVE_INFINITY,POSITIVE_INFINITY,' +\n    // ES6 (in case, if modules with ES6 Number statics required before):\n    'EPSILON,isFinite,isInteger,isNaN,isSafeInteger,MAX_SAFE_INTEGER,' +\n    'MIN_SAFE_INTEGER,parseFloat,parseInt,isInteger'\n  ).split(','), j = 0, key; keys.length > j; j++) {\n    if (has(Base, key = keys[j]) && !has($Number, key)) {\n      dP($Number, key, gOPD(Base, key));\n    }\n  }\n  $Number.prototype = proto;\n  proto.constructor = $Number;\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(global, NUMBER, $Number);\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.epsilon.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.epsilon.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.1 Number.EPSILON\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Number', { EPSILON: Math.pow(2, -52) });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.is-finite.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.is-finite.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.2 Number.isFinite(number)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar _isFinite = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").isFinite;\n\n$export($export.S, 'Number', {\n  isFinite: function isFinite(it) {\n    return typeof it == 'number' && _isFinite(it);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.is-integer.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.is-integer.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.3 Number.isInteger(number)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Number', { isInteger: __webpack_require__(/*! ./_is-integer */ \"./node_modules/core-js/modules/_is-integer.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.is-nan.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.is-nan.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.4 Number.isNaN(number)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Number', {\n  isNaN: function isNaN(number) {\n    // eslint-disable-next-line no-self-compare\n    return number != number;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.is-safe-integer.js\":\n/*!********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.is-safe-integer.js ***!\n  \\********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.5 Number.isSafeInteger(number)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar isInteger = __webpack_require__(/*! ./_is-integer */ \"./node_modules/core-js/modules/_is-integer.js\");\nvar abs = Math.abs;\n\n$export($export.S, 'Number', {\n  isSafeInteger: function isSafeInteger(number) {\n    return isInteger(number) && abs(number) <= 0x1fffffffffffff;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.max-safe-integer.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.max-safe-integer.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.6 Number.MAX_SAFE_INTEGER\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Number', { MAX_SAFE_INTEGER: 0x1fffffffffffff });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.min-safe-integer.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.min-safe-integer.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 20.1.2.10 Number.MIN_SAFE_INTEGER\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Number', { MIN_SAFE_INTEGER: -0x1fffffffffffff });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.parse-float.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.parse-float.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $parseFloat = __webpack_require__(/*! ./_parse-float */ \"./node_modules/core-js/modules/_parse-float.js\");\n// 20.1.2.12 Number.parseFloat(string)\n$export($export.S + $export.F * (Number.parseFloat != $parseFloat), 'Number', { parseFloat: $parseFloat });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.parse-int.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.parse-int.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $parseInt = __webpack_require__(/*! ./_parse-int */ \"./node_modules/core-js/modules/_parse-int.js\");\n// 20.1.2.13 Number.parseInt(string, radix)\n$export($export.S + $export.F * (Number.parseInt != $parseInt), 'Number', { parseInt: $parseInt });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.to-fixed.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.to-fixed.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar aNumberValue = __webpack_require__(/*! ./_a-number-value */ \"./node_modules/core-js/modules/_a-number-value.js\");\nvar repeat = __webpack_require__(/*! ./_string-repeat */ \"./node_modules/core-js/modules/_string-repeat.js\");\nvar $toFixed = 1.0.toFixed;\nvar floor = Math.floor;\nvar data = [0, 0, 0, 0, 0, 0];\nvar ERROR = 'Number.toFixed: incorrect invocation!';\nvar ZERO = '0';\n\nvar multiply = function (n, c) {\n  var i = -1;\n  var c2 = c;\n  while (++i < 6) {\n    c2 += n * data[i];\n    data[i] = c2 % 1e7;\n    c2 = floor(c2 / 1e7);\n  }\n};\nvar divide = function (n) {\n  var i = 6;\n  var c = 0;\n  while (--i >= 0) {\n    c += data[i];\n    data[i] = floor(c / n);\n    c = (c % n) * 1e7;\n  }\n};\nvar numToString = function () {\n  var i = 6;\n  var s = '';\n  while (--i >= 0) {\n    if (s !== '' || i === 0 || data[i] !== 0) {\n      var t = String(data[i]);\n      s = s === '' ? t : s + repeat.call(ZERO, 7 - t.length) + t;\n    }\n  } return s;\n};\nvar pow = function (x, n, acc) {\n  return n === 0 ? acc : n % 2 === 1 ? pow(x, n - 1, acc * x) : pow(x * x, n / 2, acc);\n};\nvar log = function (x) {\n  var n = 0;\n  var x2 = x;\n  while (x2 >= 4096) {\n    n += 12;\n    x2 /= 4096;\n  }\n  while (x2 >= 2) {\n    n += 1;\n    x2 /= 2;\n  } return n;\n};\n\n$export($export.P + $export.F * (!!$toFixed && (\n  0.00008.toFixed(3) !== '0.000' ||\n  0.9.toFixed(0) !== '1' ||\n  1.255.toFixed(2) !== '1.25' ||\n  1000000000000000128.0.toFixed(0) !== '1000000000000000128'\n) || !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  // V8 ~ Android 4.3-\n  $toFixed.call({});\n})), 'Number', {\n  toFixed: function toFixed(fractionDigits) {\n    var x = aNumberValue(this, ERROR);\n    var f = toInteger(fractionDigits);\n    var s = '';\n    var m = ZERO;\n    var e, z, j, k;\n    if (f < 0 || f > 20) throw RangeError(ERROR);\n    // eslint-disable-next-line no-self-compare\n    if (x != x) return 'NaN';\n    if (x <= -1e21 || x >= 1e21) return String(x);\n    if (x < 0) {\n      s = '-';\n      x = -x;\n    }\n    if (x > 1e-21) {\n      e = log(x * pow(2, 69, 1)) - 69;\n      z = e < 0 ? x * pow(2, -e, 1) : x / pow(2, e, 1);\n      z *= 0x10000000000000;\n      e = 52 - e;\n      if (e > 0) {\n        multiply(0, z);\n        j = f;\n        while (j >= 7) {\n          multiply(1e7, 0);\n          j -= 7;\n        }\n        multiply(pow(10, j, 1), 0);\n        j = e - 1;\n        while (j >= 23) {\n          divide(1 << 23);\n          j -= 23;\n        }\n        divide(1 << j);\n        multiply(1, 1);\n        divide(2);\n        m = numToString();\n      } else {\n        multiply(0, z);\n        multiply(1 << -e, 0);\n        m = numToString() + repeat.call(ZERO, f);\n      }\n    }\n    if (f > 0) {\n      k = m.length;\n      m = s + (k <= f ? '0.' + repeat.call(ZERO, f - k) + m : m.slice(0, k - f) + '.' + m.slice(k - f));\n    } else {\n      m = s + m;\n    } return m;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.number.to-precision.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.number.to-precision.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar aNumberValue = __webpack_require__(/*! ./_a-number-value */ \"./node_modules/core-js/modules/_a-number-value.js\");\nvar $toPrecision = 1.0.toPrecision;\n\n$export($export.P + $export.F * ($fails(function () {\n  // IE7-\n  return $toPrecision.call(1, undefined) !== '1';\n}) || !$fails(function () {\n  // V8 ~ Android 4.3-\n  $toPrecision.call({});\n})), 'Number', {\n  toPrecision: function toPrecision(precision) {\n    var that = aNumberValue(this, 'Number#toPrecision: incorrect invocation!');\n    return precision === undefined ? $toPrecision.call(that) : $toPrecision.call(that, precision);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.assign.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.assign.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.3.1 Object.assign(target, source)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S + $export.F, 'Object', { assign: __webpack_require__(/*! ./_object-assign */ \"./node_modules/core-js/modules/_object-assign.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.create.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.create.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\n$export($export.S, 'Object', { create: __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.define-properties.js\":\n/*!**********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.define-properties.js ***!\n  \\**********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n// 19.1.2.3 / 15.2.3.7 Object.defineProperties(O, Properties)\n$export($export.S + $export.F * !__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\"), 'Object', { defineProperties: __webpack_require__(/*! ./_object-dps */ \"./node_modules/core-js/modules/_object-dps.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.define-property.js\":\n/*!********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.define-property.js ***!\n  \\********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n// 19.1.2.4 / 15.2.3.6 Object.defineProperty(O, P, Attributes)\n$export($export.S + $export.F * !__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\"), 'Object', { defineProperty: __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.freeze.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.freeze.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.5 Object.freeze(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar meta = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").onFreeze;\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('freeze', function ($freeze) {\n  return function freeze(it) {\n    return $freeze && isObject(it) ? $freeze(meta(it)) : it;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.get-own-property-descriptor.js\":\n/*!********************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.get-own-property-descriptor.js ***!\n  \\********************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.6 Object.getOwnPropertyDescriptor(O, P)\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar $getOwnPropertyDescriptor = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f;\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('getOwnPropertyDescriptor', function () {\n  return function getOwnPropertyDescriptor(it, key) {\n    return $getOwnPropertyDescriptor(toIObject(it), key);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.get-own-property-names.js\":\n/*!***************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.get-own-property-names.js ***!\n  \\***************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.7 Object.getOwnPropertyNames(O)\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('getOwnPropertyNames', function () {\n  return __webpack_require__(/*! ./_object-gopn-ext */ \"./node_modules/core-js/modules/_object-gopn-ext.js\").f;\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.get-prototype-of.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.get-prototype-of.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.9 Object.getPrototypeOf(O)\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar $getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('getPrototypeOf', function () {\n  return function getPrototypeOf(it) {\n    return $getPrototypeOf(toObject(it));\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.is-extensible.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.is-extensible.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.11 Object.isExtensible(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('isExtensible', function ($isExtensible) {\n  return function isExtensible(it) {\n    return isObject(it) ? $isExtensible ? $isExtensible(it) : true : false;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.is-frozen.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.is-frozen.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.12 Object.isFrozen(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('isFrozen', function ($isFrozen) {\n  return function isFrozen(it) {\n    return isObject(it) ? $isFrozen ? $isFrozen(it) : false : true;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.is-sealed.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.is-sealed.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.13 Object.isSealed(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('isSealed', function ($isSealed) {\n  return function isSealed(it) {\n    return isObject(it) ? $isSealed ? $isSealed(it) : false : true;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.is.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.is.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.3.10 Object.is(value1, value2)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n$export($export.S, 'Object', { is: __webpack_require__(/*! ./_same-value */ \"./node_modules/core-js/modules/_same-value.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.keys.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.keys.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.14 Object.keys(O)\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar $keys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('keys', function () {\n  return function keys(it) {\n    return $keys(toObject(it));\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.prevent-extensions.js\":\n/*!***********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.prevent-extensions.js ***!\n  \\***********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.15 Object.preventExtensions(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar meta = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").onFreeze;\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('preventExtensions', function ($preventExtensions) {\n  return function preventExtensions(it) {\n    return $preventExtensions && isObject(it) ? $preventExtensions(meta(it)) : it;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.seal.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.seal.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.2.17 Object.seal(O)\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar meta = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").onFreeze;\n\n__webpack_require__(/*! ./_object-sap */ \"./node_modules/core-js/modules/_object-sap.js\")('seal', function ($seal) {\n  return function seal(it) {\n    return $seal && isObject(it) ? $seal(meta(it)) : it;\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.set-prototype-of.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.set-prototype-of.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 19.1.3.19 Object.setPrototypeOf(O, proto)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n$export($export.S, 'Object', { setPrototypeOf: __webpack_require__(/*! ./_set-proto */ \"./node_modules/core-js/modules/_set-proto.js\").set });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.object.to-string.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.object.to-string.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 19.1.3.6 Object.prototype.toString()\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar test = {};\ntest[__webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('toStringTag')] = 'z';\nif (test + '' != '[object z]') {\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(Object.prototype, 'toString', function toString() {\n    return '[object ' + classof(this) + ']';\n  }, true);\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.parse-float.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.parse-float.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $parseFloat = __webpack_require__(/*! ./_parse-float */ \"./node_modules/core-js/modules/_parse-float.js\");\n// 18.2.4 parseFloat(string)\n$export($export.G + $export.F * (parseFloat != $parseFloat), { parseFloat: $parseFloat });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.parse-int.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.parse-int.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $parseInt = __webpack_require__(/*! ./_parse-int */ \"./node_modules/core-js/modules/_parse-int.js\");\n// 18.2.5 parseInt(string, radix)\n$export($export.G + $export.F * (parseInt != $parseInt), { parseInt: $parseInt });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.promise.js\":\n/*!*****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.promise.js ***!\n  \\*****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar LIBRARY = __webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar ctx = __webpack_require__(/*! ./_ctx */ \"./node_modules/core-js/modules/_ctx.js\");\nvar classof = __webpack_require__(/*! ./_classof */ \"./node_modules/core-js/modules/_classof.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\nvar task = __webpack_require__(/*! ./_task */ \"./node_modules/core-js/modules/_task.js\").set;\nvar microtask = __webpack_require__(/*! ./_microtask */ \"./node_modules/core-js/modules/_microtask.js\")();\nvar newPromiseCapabilityModule = __webpack_require__(/*! ./_new-promise-capability */ \"./node_modules/core-js/modules/_new-promise-capability.js\");\nvar perform = __webpack_require__(/*! ./_perform */ \"./node_modules/core-js/modules/_perform.js\");\nvar userAgent = __webpack_require__(/*! ./_user-agent */ \"./node_modules/core-js/modules/_user-agent.js\");\nvar promiseResolve = __webpack_require__(/*! ./_promise-resolve */ \"./node_modules/core-js/modules/_promise-resolve.js\");\nvar PROMISE = 'Promise';\nvar TypeError = global.TypeError;\nvar process = global.process;\nvar versions = process && process.versions;\nvar v8 = versions && versions.v8 || '';\nvar $Promise = global[PROMISE];\nvar isNode = classof(process) == 'process';\nvar empty = function () { /* empty */ };\nvar Internal, newGenericPromiseCapability, OwnPromiseCapability, Wrapper;\nvar newPromiseCapability = newGenericPromiseCapability = newPromiseCapabilityModule.f;\n\nvar USE_NATIVE = !!function () {\n  try {\n    // correct subclassing with @@species support\n    var promise = $Promise.resolve(1);\n    var FakePromise = (promise.constructor = {})[__webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('species')] = function (exec) {\n      exec(empty, empty);\n    };\n    // unhandled rejections tracking support, NodeJS Promise without it fails @@species test\n    return (isNode || typeof PromiseRejectionEvent == 'function')\n      && promise.then(empty) instanceof FakePromise\n      // v8 6.6 (Node 10 and Chrome 66) have a bug with resolving custom thenables\n      // https://bugs.chromium.org/p/chromium/issues/detail?id=830565\n      // we can't detect it synchronously, so just check versions\n      && v8.indexOf('6.6') !== 0\n      && userAgent.indexOf('Chrome/66') === -1;\n  } catch (e) { /* empty */ }\n}();\n\n// helpers\nvar isThenable = function (it) {\n  var then;\n  return isObject(it) && typeof (then = it.then) == 'function' ? then : false;\n};\nvar notify = function (promise, isReject) {\n  if (promise._n) return;\n  promise._n = true;\n  var chain = promise._c;\n  microtask(function () {\n    var value = promise._v;\n    var ok = promise._s == 1;\n    var i = 0;\n    var run = function (reaction) {\n      var handler = ok ? reaction.ok : reaction.fail;\n      var resolve = reaction.resolve;\n      var reject = reaction.reject;\n      var domain = reaction.domain;\n      var result, then, exited;\n      try {\n        if (handler) {\n          if (!ok) {\n            if (promise._h == 2) onHandleUnhandled(promise);\n            promise._h = 1;\n          }\n          if (handler === true) result = value;\n          else {\n            if (domain) domain.enter();\n            result = handler(value); // may throw\n            if (domain) {\n              domain.exit();\n              exited = true;\n            }\n          }\n          if (result === reaction.promise) {\n            reject(TypeError('Promise-chain cycle'));\n          } else if (then = isThenable(result)) {\n            then.call(result, resolve, reject);\n          } else resolve(result);\n        } else reject(value);\n      } catch (e) {\n        if (domain && !exited) domain.exit();\n        reject(e);\n      }\n    };\n    while (chain.length > i) run(chain[i++]); // variable length - can't use forEach\n    promise._c = [];\n    promise._n = false;\n    if (isReject && !promise._h) onUnhandled(promise);\n  });\n};\nvar onUnhandled = function (promise) {\n  task.call(global, function () {\n    var value = promise._v;\n    var unhandled = isUnhandled(promise);\n    var result, handler, console;\n    if (unhandled) {\n      result = perform(function () {\n        if (isNode) {\n          process.emit('unhandledRejection', value, promise);\n        } else if (handler = global.onunhandledrejection) {\n          handler({ promise: promise, reason: value });\n        } else if ((console = global.console) && console.error) {\n          console.error('Unhandled promise rejection', value);\n        }\n      });\n      // Browsers should not trigger `rejectionHandled` event if it was handled here, NodeJS - should\n      promise._h = isNode || isUnhandled(promise) ? 2 : 1;\n    } promise._a = undefined;\n    if (unhandled && result.e) throw result.v;\n  });\n};\nvar isUnhandled = function (promise) {\n  return promise._h !== 1 && (promise._a || promise._c).length === 0;\n};\nvar onHandleUnhandled = function (promise) {\n  task.call(global, function () {\n    var handler;\n    if (isNode) {\n      process.emit('rejectionHandled', promise);\n    } else if (handler = global.onrejectionhandled) {\n      handler({ promise: promise, reason: promise._v });\n    }\n  });\n};\nvar $reject = function (value) {\n  var promise = this;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  promise._v = value;\n  promise._s = 2;\n  if (!promise._a) promise._a = promise._c.slice();\n  notify(promise, true);\n};\nvar $resolve = function (value) {\n  var promise = this;\n  var then;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  try {\n    if (promise === value) throw TypeError(\"Promise can't be resolved itself\");\n    if (then = isThenable(value)) {\n      microtask(function () {\n        var wrapper = { _w: promise, _d: false }; // wrap\n        try {\n          then.call(value, ctx($resolve, wrapper, 1), ctx($reject, wrapper, 1));\n        } catch (e) {\n          $reject.call(wrapper, e);\n        }\n      });\n    } else {\n      promise._v = value;\n      promise._s = 1;\n      notify(promise, false);\n    }\n  } catch (e) {\n    $reject.call({ _w: promise, _d: false }, e); // wrap\n  }\n};\n\n// constructor polyfill\nif (!USE_NATIVE) {\n  // 25.4.3.1 Promise(executor)\n  $Promise = function Promise(executor) {\n    anInstance(this, $Promise, PROMISE, '_h');\n    aFunction(executor);\n    Internal.call(this);\n    try {\n      executor(ctx($resolve, this, 1), ctx($reject, this, 1));\n    } catch (err) {\n      $reject.call(this, err);\n    }\n  };\n  // eslint-disable-next-line no-unused-vars\n  Internal = function Promise(executor) {\n    this._c = [];             // <- awaiting reactions\n    this._a = undefined;      // <- checked in isUnhandled reactions\n    this._s = 0;              // <- state\n    this._d = false;          // <- done\n    this._v = undefined;      // <- value\n    this._h = 0;              // <- rejection state, 0 - default, 1 - handled, 2 - unhandled\n    this._n = false;          // <- notify\n  };\n  Internal.prototype = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\")($Promise.prototype, {\n    // 25.4.5.3 Promise.prototype.then(onFulfilled, onRejected)\n    then: function then(onFulfilled, onRejected) {\n      var reaction = newPromiseCapability(speciesConstructor(this, $Promise));\n      reaction.ok = typeof onFulfilled == 'function' ? onFulfilled : true;\n      reaction.fail = typeof onRejected == 'function' && onRejected;\n      reaction.domain = isNode ? process.domain : undefined;\n      this._c.push(reaction);\n      if (this._a) this._a.push(reaction);\n      if (this._s) notify(this, false);\n      return reaction.promise;\n    },\n    // 25.4.5.1 Promise.prototype.catch(onRejected)\n    'catch': function (onRejected) {\n      return this.then(undefined, onRejected);\n    }\n  });\n  OwnPromiseCapability = function () {\n    var promise = new Internal();\n    this.promise = promise;\n    this.resolve = ctx($resolve, promise, 1);\n    this.reject = ctx($reject, promise, 1);\n  };\n  newPromiseCapabilityModule.f = newPromiseCapability = function (C) {\n    return C === $Promise || C === Wrapper\n      ? new OwnPromiseCapability(C)\n      : newGenericPromiseCapability(C);\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Promise: $Promise });\n__webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\")($Promise, PROMISE);\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")(PROMISE);\nWrapper = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\")[PROMISE];\n\n// statics\n$export($export.S + $export.F * !USE_NATIVE, PROMISE, {\n  // 25.4.4.5 Promise.reject(r)\n  reject: function reject(r) {\n    var capability = newPromiseCapability(this);\n    var $$reject = capability.reject;\n    $$reject(r);\n    return capability.promise;\n  }\n});\n$export($export.S + $export.F * (LIBRARY || !USE_NATIVE), PROMISE, {\n  // 25.4.4.6 Promise.resolve(x)\n  resolve: function resolve(x) {\n    return promiseResolve(LIBRARY && this === Wrapper ? $Promise : this, x);\n  }\n});\n$export($export.S + $export.F * !(USE_NATIVE && __webpack_require__(/*! ./_iter-detect */ \"./node_modules/core-js/modules/_iter-detect.js\")(function (iter) {\n  $Promise.all(iter)['catch'](empty);\n})), PROMISE, {\n  // 25.4.4.1 Promise.all(iterable)\n  all: function all(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var resolve = capability.resolve;\n    var reject = capability.reject;\n    var result = perform(function () {\n      var values = [];\n      var index = 0;\n      var remaining = 1;\n      forOf(iterable, false, function (promise) {\n        var $index = index++;\n        var alreadyCalled = false;\n        values.push(undefined);\n        remaining++;\n        C.resolve(promise).then(function (value) {\n          if (alreadyCalled) return;\n          alreadyCalled = true;\n          values[$index] = value;\n          --remaining || resolve(values);\n        }, reject);\n      });\n      --remaining || resolve(values);\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  },\n  // 25.4.4.4 Promise.race(iterable)\n  race: function race(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var reject = capability.reject;\n    var result = perform(function () {\n      forOf(iterable, false, function (promise) {\n        C.resolve(promise).then(capability.resolve, reject);\n      });\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.apply.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.apply.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.1 Reflect.apply(target, thisArgument, argumentsList)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar rApply = (__webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").Reflect || {}).apply;\nvar fApply = Function.apply;\n// MS Edge argumentsList argument is optional\n$export($export.S + $export.F * !__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  rApply(function () { /* empty */ });\n}), 'Reflect', {\n  apply: function apply(target, thisArgument, argumentsList) {\n    var T = aFunction(target);\n    var L = anObject(argumentsList);\n    return rApply ? rApply(T, thisArgument, L) : fApply.call(T, thisArgument, L);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.construct.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.construct.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.2 Reflect.construct(target, argumentsList [, newTarget])\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar bind = __webpack_require__(/*! ./_bind */ \"./node_modules/core-js/modules/_bind.js\");\nvar rConstruct = (__webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").Reflect || {}).construct;\n\n// MS Edge supports only 2 arguments and argumentsList argument is optional\n// FF Nightly sets third argument as `new.target`, but does not create `this` from it\nvar NEW_TARGET_BUG = fails(function () {\n  function F() { /* empty */ }\n  return !(rConstruct(function () { /* empty */ }, [], F) instanceof F);\n});\nvar ARGS_BUG = !fails(function () {\n  rConstruct(function () { /* empty */ });\n});\n\n$export($export.S + $export.F * (NEW_TARGET_BUG || ARGS_BUG), 'Reflect', {\n  construct: function construct(Target, args /* , newTarget */) {\n    aFunction(Target);\n    anObject(args);\n    var newTarget = arguments.length < 3 ? Target : aFunction(arguments[2]);\n    if (ARGS_BUG && !NEW_TARGET_BUG) return rConstruct(Target, args, newTarget);\n    if (Target == newTarget) {\n      // w/o altered newTarget, optimization for 0-4 arguments\n      switch (args.length) {\n        case 0: return new Target();\n        case 1: return new Target(args[0]);\n        case 2: return new Target(args[0], args[1]);\n        case 3: return new Target(args[0], args[1], args[2]);\n        case 4: return new Target(args[0], args[1], args[2], args[3]);\n      }\n      // w/o altered newTarget, lot of arguments case\n      var $args = [null];\n      $args.push.apply($args, args);\n      return new (bind.apply(Target, $args))();\n    }\n    // with altered newTarget, not support built-in constructors\n    var proto = newTarget.prototype;\n    var instance = create(isObject(proto) ? proto : Object.prototype);\n    var result = Function.apply.call(Target, instance, args);\n    return isObject(result) ? result : instance;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.define-property.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.define-property.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.3 Reflect.defineProperty(target, propertyKey, attributes)\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\n\n// MS Edge has broken Reflect.defineProperty - throwing instead of returning false\n$export($export.S + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  // eslint-disable-next-line no-undef\n  Reflect.defineProperty(dP.f({}, 1, { value: 1 }), 1, { value: 2 });\n}), 'Reflect', {\n  defineProperty: function defineProperty(target, propertyKey, attributes) {\n    anObject(target);\n    propertyKey = toPrimitive(propertyKey, true);\n    anObject(attributes);\n    try {\n      dP.f(target, propertyKey, attributes);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.delete-property.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.delete-property.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.4 Reflect.deleteProperty(target, propertyKey)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f;\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\n\n$export($export.S, 'Reflect', {\n  deleteProperty: function deleteProperty(target, propertyKey) {\n    var desc = gOPD(anObject(target), propertyKey);\n    return desc && !desc.configurable ? false : delete target[propertyKey];\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.enumerate.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.enumerate.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 26.1.5 Reflect.enumerate(target)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar Enumerate = function (iterated) {\n  this._t = anObject(iterated); // target\n  this._i = 0;                  // next index\n  var keys = this._k = [];      // keys\n  var key;\n  for (key in iterated) keys.push(key);\n};\n__webpack_require__(/*! ./_iter-create */ \"./node_modules/core-js/modules/_iter-create.js\")(Enumerate, 'Object', function () {\n  var that = this;\n  var keys = that._k;\n  var key;\n  do {\n    if (that._i >= keys.length) return { value: undefined, done: true };\n  } while (!((key = keys[that._i++]) in that._t));\n  return { value: key, done: false };\n});\n\n$export($export.S, 'Reflect', {\n  enumerate: function enumerate(target) {\n    return new Enumerate(target);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.get-own-property-descriptor.js\":\n/*!*********************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.get-own-property-descriptor.js ***!\n  \\*********************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.7 Reflect.getOwnPropertyDescriptor(target, propertyKey)\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\n\n$export($export.S, 'Reflect', {\n  getOwnPropertyDescriptor: function getOwnPropertyDescriptor(target, propertyKey) {\n    return gOPD.f(anObject(target), propertyKey);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.get-prototype-of.js\":\n/*!**********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.get-prototype-of.js ***!\n  \\**********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.8 Reflect.getPrototypeOf(target)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar getProto = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\n\n$export($export.S, 'Reflect', {\n  getPrototypeOf: function getPrototypeOf(target) {\n    return getProto(anObject(target));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.get.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.get.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.6 Reflect.get(target, propertyKey [, receiver])\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\n\nfunction get(target, propertyKey /* , receiver */) {\n  var receiver = arguments.length < 3 ? target : arguments[2];\n  var desc, proto;\n  if (anObject(target) === receiver) return target[propertyKey];\n  if (desc = gOPD.f(target, propertyKey)) return has(desc, 'value')\n    ? desc.value\n    : desc.get !== undefined\n      ? desc.get.call(receiver)\n      : undefined;\n  if (isObject(proto = getPrototypeOf(target))) return get(proto, propertyKey, receiver);\n}\n\n$export($export.S, 'Reflect', { get: get });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.has.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.has.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.9 Reflect.has(target, propertyKey)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Reflect', {\n  has: function has(target, propertyKey) {\n    return propertyKey in target;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.is-extensible.js\":\n/*!*******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.is-extensible.js ***!\n  \\*******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.10 Reflect.isExtensible(target)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar $isExtensible = Object.isExtensible;\n\n$export($export.S, 'Reflect', {\n  isExtensible: function isExtensible(target) {\n    anObject(target);\n    return $isExtensible ? $isExtensible(target) : true;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.own-keys.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.own-keys.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.11 Reflect.ownKeys(target)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Reflect', { ownKeys: __webpack_require__(/*! ./_own-keys */ \"./node_modules/core-js/modules/_own-keys.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.prevent-extensions.js\":\n/*!************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.prevent-extensions.js ***!\n  \\************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.12 Reflect.preventExtensions(target)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar $preventExtensions = Object.preventExtensions;\n\n$export($export.S, 'Reflect', {\n  preventExtensions: function preventExtensions(target) {\n    anObject(target);\n    try {\n      if ($preventExtensions) $preventExtensions(target);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.set-prototype-of.js\":\n/*!**********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.set-prototype-of.js ***!\n  \\**********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.14 Reflect.setPrototypeOf(target, proto)\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar setProto = __webpack_require__(/*! ./_set-proto */ \"./node_modules/core-js/modules/_set-proto.js\");\n\nif (setProto) $export($export.S, 'Reflect', {\n  setPrototypeOf: function setPrototypeOf(target, proto) {\n    setProto.check(target, proto);\n    try {\n      setProto.set(target, proto);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.reflect.set.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.reflect.set.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 26.1.13 Reflect.set(target, propertyKey, V [, receiver])\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\n\nfunction set(target, propertyKey, V /* , receiver */) {\n  var receiver = arguments.length < 4 ? target : arguments[3];\n  var ownDesc = gOPD.f(anObject(target), propertyKey);\n  var existingDescriptor, proto;\n  if (!ownDesc) {\n    if (isObject(proto = getPrototypeOf(target))) {\n      return set(proto, propertyKey, V, receiver);\n    }\n    ownDesc = createDesc(0);\n  }\n  if (has(ownDesc, 'value')) {\n    if (ownDesc.writable === false || !isObject(receiver)) return false;\n    if (existingDescriptor = gOPD.f(receiver, propertyKey)) {\n      if (existingDescriptor.get || existingDescriptor.set || existingDescriptor.writable === false) return false;\n      existingDescriptor.value = V;\n      dP.f(receiver, propertyKey, existingDescriptor);\n    } else dP.f(receiver, propertyKey, createDesc(0, V));\n    return true;\n  }\n  return ownDesc.set === undefined ? false : (ownDesc.set.call(receiver, V), true);\n}\n\n$export($export.S, 'Reflect', { set: set });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.constructor.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.constructor.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar inheritIfRequired = __webpack_require__(/*! ./_inherit-if-required */ \"./node_modules/core-js/modules/_inherit-if-required.js\");\nvar dP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f;\nvar gOPN = __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f;\nvar isRegExp = __webpack_require__(/*! ./_is-regexp */ \"./node_modules/core-js/modules/_is-regexp.js\");\nvar $flags = __webpack_require__(/*! ./_flags */ \"./node_modules/core-js/modules/_flags.js\");\nvar $RegExp = global.RegExp;\nvar Base = $RegExp;\nvar proto = $RegExp.prototype;\nvar re1 = /a/g;\nvar re2 = /a/g;\n// \"new\" creates a new object, old webkit buggy here\nvar CORRECT_NEW = new $RegExp(re1) !== re1;\n\nif (__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && (!CORRECT_NEW || __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  re2[__webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('match')] = false;\n  // RegExp constructor can alter flags and IsRegExp works correct with @@match\n  return $RegExp(re1) != re1 || $RegExp(re2) == re2 || $RegExp(re1, 'i') != '/a/i';\n}))) {\n  $RegExp = function RegExp(p, f) {\n    var tiRE = this instanceof $RegExp;\n    var piRE = isRegExp(p);\n    var fiU = f === undefined;\n    return !tiRE && piRE && p.constructor === $RegExp && fiU ? p\n      : inheritIfRequired(CORRECT_NEW\n        ? new Base(piRE && !fiU ? p.source : p, f)\n        : Base((piRE = p instanceof $RegExp) ? p.source : p, piRE && fiU ? $flags.call(p) : f)\n      , tiRE ? this : proto, $RegExp);\n  };\n  var proxy = function (key) {\n    key in $RegExp || dP($RegExp, key, {\n      configurable: true,\n      get: function () { return Base[key]; },\n      set: function (it) { Base[key] = it; }\n    });\n  };\n  for (var keys = gOPN(Base), i = 0; keys.length > i;) proxy(keys[i++]);\n  proto.constructor = $RegExp;\n  $RegExp.prototype = proto;\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(global, 'RegExp', $RegExp);\n}\n\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")('RegExp');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.exec.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.exec.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar regexpExec = __webpack_require__(/*! ./_regexp-exec */ \"./node_modules/core-js/modules/_regexp-exec.js\");\n__webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\")({\n  target: 'RegExp',\n  proto: true,\n  forced: regexpExec !== /./.exec\n}, {\n  exec: regexpExec\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.flags.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.flags.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// 21.2.5.3 get RegExp.prototype.flags()\nif (__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && /./g.flags != 'g') __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\").f(RegExp.prototype, 'flags', {\n  configurable: true,\n  get: __webpack_require__(/*! ./_flags */ \"./node_modules/core-js/modules/_flags.js\")\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.match.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.match.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar advanceStringIndex = __webpack_require__(/*! ./_advance-string-index */ \"./node_modules/core-js/modules/_advance-string-index.js\");\nvar regExpExec = __webpack_require__(/*! ./_regexp-exec-abstract */ \"./node_modules/core-js/modules/_regexp-exec-abstract.js\");\n\n// @@match logic\n__webpack_require__(/*! ./_fix-re-wks */ \"./node_modules/core-js/modules/_fix-re-wks.js\")('match', 1, function (defined, MATCH, $match, maybeCallNative) {\n  return [\n    // `String.prototype.match` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.match\n    function match(regexp) {\n      var O = defined(this);\n      var fn = regexp == undefined ? undefined : regexp[MATCH];\n      return fn !== undefined ? fn.call(regexp, O) : new RegExp(regexp)[MATCH](String(O));\n    },\n    // `RegExp.prototype[@@match]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@match\n    function (regexp) {\n      var res = maybeCallNative($match, regexp, this);\n      if (res.done) return res.value;\n      var rx = anObject(regexp);\n      var S = String(this);\n      if (!rx.global) return regExpExec(rx, S);\n      var fullUnicode = rx.unicode;\n      rx.lastIndex = 0;\n      var A = [];\n      var n = 0;\n      var result;\n      while ((result = regExpExec(rx, S)) !== null) {\n        var matchStr = String(result[0]);\n        A[n] = matchStr;\n        if (matchStr === '') rx.lastIndex = advanceStringIndex(S, toLength(rx.lastIndex), fullUnicode);\n        n++;\n      }\n      return n === 0 ? null : A;\n    }\n  ];\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.replace.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.replace.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar advanceStringIndex = __webpack_require__(/*! ./_advance-string-index */ \"./node_modules/core-js/modules/_advance-string-index.js\");\nvar regExpExec = __webpack_require__(/*! ./_regexp-exec-abstract */ \"./node_modules/core-js/modules/_regexp-exec-abstract.js\");\nvar max = Math.max;\nvar min = Math.min;\nvar floor = Math.floor;\nvar SUBSTITUTION_SYMBOLS = /\\$([$&`']|\\d\\d?|<[^>]*>)/g;\nvar SUBSTITUTION_SYMBOLS_NO_NAMED = /\\$([$&`']|\\d\\d?)/g;\n\nvar maybeToString = function (it) {\n  return it === undefined ? it : String(it);\n};\n\n// @@replace logic\n__webpack_require__(/*! ./_fix-re-wks */ \"./node_modules/core-js/modules/_fix-re-wks.js\")('replace', 2, function (defined, REPLACE, $replace, maybeCallNative) {\n  return [\n    // `String.prototype.replace` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.replace\n    function replace(searchValue, replaceValue) {\n      var O = defined(this);\n      var fn = searchValue == undefined ? undefined : searchValue[REPLACE];\n      return fn !== undefined\n        ? fn.call(searchValue, O, replaceValue)\n        : $replace.call(String(O), searchValue, replaceValue);\n    },\n    // `RegExp.prototype[@@replace]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@replace\n    function (regexp, replaceValue) {\n      var res = maybeCallNative($replace, regexp, this, replaceValue);\n      if (res.done) return res.value;\n\n      var rx = anObject(regexp);\n      var S = String(this);\n      var functionalReplace = typeof replaceValue === 'function';\n      if (!functionalReplace) replaceValue = String(replaceValue);\n      var global = rx.global;\n      if (global) {\n        var fullUnicode = rx.unicode;\n        rx.lastIndex = 0;\n      }\n      var results = [];\n      while (true) {\n        var result = regExpExec(rx, S);\n        if (result === null) break;\n        results.push(result);\n        if (!global) break;\n        var matchStr = String(result[0]);\n        if (matchStr === '') rx.lastIndex = advanceStringIndex(S, toLength(rx.lastIndex), fullUnicode);\n      }\n      var accumulatedResult = '';\n      var nextSourcePosition = 0;\n      for (var i = 0; i < results.length; i++) {\n        result = results[i];\n        var matched = String(result[0]);\n        var position = max(min(toInteger(result.index), S.length), 0);\n        var captures = [];\n        // NOTE: This is equivalent to\n        //   captures = result.slice(1).map(maybeToString)\n        // but for some reason `nativeSlice.call(result, 1, result.length)` (called in\n        // the slice polyfill when slicing native arrays) \"doesn't work\" in safari 9 and\n        // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it.\n        for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j]));\n        var namedCaptures = result.groups;\n        if (functionalReplace) {\n          var replacerArgs = [matched].concat(captures, position, S);\n          if (namedCaptures !== undefined) replacerArgs.push(namedCaptures);\n          var replacement = String(replaceValue.apply(undefined, replacerArgs));\n        } else {\n          replacement = getSubstitution(matched, S, position, captures, namedCaptures, replaceValue);\n        }\n        if (position >= nextSourcePosition) {\n          accumulatedResult += S.slice(nextSourcePosition, position) + replacement;\n          nextSourcePosition = position + matched.length;\n        }\n      }\n      return accumulatedResult + S.slice(nextSourcePosition);\n    }\n  ];\n\n    // https://tc39.github.io/ecma262/#sec-getsubstitution\n  function getSubstitution(matched, str, position, captures, namedCaptures, replacement) {\n    var tailPos = position + matched.length;\n    var m = captures.length;\n    var symbols = SUBSTITUTION_SYMBOLS_NO_NAMED;\n    if (namedCaptures !== undefined) {\n      namedCaptures = toObject(namedCaptures);\n      symbols = SUBSTITUTION_SYMBOLS;\n    }\n    return $replace.call(replacement, symbols, function (match, ch) {\n      var capture;\n      switch (ch.charAt(0)) {\n        case '$': return '$';\n        case '&': return matched;\n        case '`': return str.slice(0, position);\n        case \"'\": return str.slice(tailPos);\n        case '<':\n          capture = namedCaptures[ch.slice(1, -1)];\n          break;\n        default: // \\d\\d?\n          var n = +ch;\n          if (n === 0) return match;\n          if (n > m) {\n            var f = floor(n / 10);\n            if (f === 0) return match;\n            if (f <= m) return captures[f - 1] === undefined ? ch.charAt(1) : captures[f - 1] + ch.charAt(1);\n            return match;\n          }\n          capture = captures[n - 1];\n      }\n      return capture === undefined ? '' : capture;\n    });\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.search.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.search.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar sameValue = __webpack_require__(/*! ./_same-value */ \"./node_modules/core-js/modules/_same-value.js\");\nvar regExpExec = __webpack_require__(/*! ./_regexp-exec-abstract */ \"./node_modules/core-js/modules/_regexp-exec-abstract.js\");\n\n// @@search logic\n__webpack_require__(/*! ./_fix-re-wks */ \"./node_modules/core-js/modules/_fix-re-wks.js\")('search', 1, function (defined, SEARCH, $search, maybeCallNative) {\n  return [\n    // `String.prototype.search` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.search\n    function search(regexp) {\n      var O = defined(this);\n      var fn = regexp == undefined ? undefined : regexp[SEARCH];\n      return fn !== undefined ? fn.call(regexp, O) : new RegExp(regexp)[SEARCH](String(O));\n    },\n    // `RegExp.prototype[@@search]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@search\n    function (regexp) {\n      var res = maybeCallNative($search, regexp, this);\n      if (res.done) return res.value;\n      var rx = anObject(regexp);\n      var S = String(this);\n      var previousLastIndex = rx.lastIndex;\n      if (!sameValue(previousLastIndex, 0)) rx.lastIndex = 0;\n      var result = regExpExec(rx, S);\n      if (!sameValue(rx.lastIndex, previousLastIndex)) rx.lastIndex = previousLastIndex;\n      return result === null ? -1 : result.index;\n    }\n  ];\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.split.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.split.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nvar isRegExp = __webpack_require__(/*! ./_is-regexp */ \"./node_modules/core-js/modules/_is-regexp.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\nvar advanceStringIndex = __webpack_require__(/*! ./_advance-string-index */ \"./node_modules/core-js/modules/_advance-string-index.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar callRegExpExec = __webpack_require__(/*! ./_regexp-exec-abstract */ \"./node_modules/core-js/modules/_regexp-exec-abstract.js\");\nvar regexpExec = __webpack_require__(/*! ./_regexp-exec */ \"./node_modules/core-js/modules/_regexp-exec.js\");\nvar fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar $min = Math.min;\nvar $push = [].push;\nvar $SPLIT = 'split';\nvar LENGTH = 'length';\nvar LAST_INDEX = 'lastIndex';\nvar MAX_UINT32 = 0xffffffff;\n\n// babel-minify transpiles RegExp('x', 'y') -> /x/y and it causes SyntaxError\nvar SUPPORTS_Y = !fails(function () { RegExp(MAX_UINT32, 'y'); });\n\n// @@split logic\n__webpack_require__(/*! ./_fix-re-wks */ \"./node_modules/core-js/modules/_fix-re-wks.js\")('split', 2, function (defined, SPLIT, $split, maybeCallNative) {\n  var internalSplit;\n  if (\n    'abbc'[$SPLIT](/(b)*/)[1] == 'c' ||\n    'test'[$SPLIT](/(?:)/, -1)[LENGTH] != 4 ||\n    'ab'[$SPLIT](/(?:ab)*/)[LENGTH] != 2 ||\n    '.'[$SPLIT](/(.?)(.?)/)[LENGTH] != 4 ||\n    '.'[$SPLIT](/()()/)[LENGTH] > 1 ||\n    ''[$SPLIT](/.?/)[LENGTH]\n  ) {\n    // based on es5-shim implementation, need to rework it\n    internalSplit = function (separator, limit) {\n      var string = String(this);\n      if (separator === undefined && limit === 0) return [];\n      // If `separator` is not a regex, use native split\n      if (!isRegExp(separator)) return $split.call(string, separator, limit);\n      var output = [];\n      var flags = (separator.ignoreCase ? 'i' : '') +\n                  (separator.multiline ? 'm' : '') +\n                  (separator.unicode ? 'u' : '') +\n                  (separator.sticky ? 'y' : '');\n      var lastLastIndex = 0;\n      var splitLimit = limit === undefined ? MAX_UINT32 : limit >>> 0;\n      // Make `global` and avoid `lastIndex` issues by working with a copy\n      var separatorCopy = new RegExp(separator.source, flags + 'g');\n      var match, lastIndex, lastLength;\n      while (match = regexpExec.call(separatorCopy, string)) {\n        lastIndex = separatorCopy[LAST_INDEX];\n        if (lastIndex > lastLastIndex) {\n          output.push(string.slice(lastLastIndex, match.index));\n          if (match[LENGTH] > 1 && match.index < string[LENGTH]) $push.apply(output, match.slice(1));\n          lastLength = match[0][LENGTH];\n          lastLastIndex = lastIndex;\n          if (output[LENGTH] >= splitLimit) break;\n        }\n        if (separatorCopy[LAST_INDEX] === match.index) separatorCopy[LAST_INDEX]++; // Avoid an infinite loop\n      }\n      if (lastLastIndex === string[LENGTH]) {\n        if (lastLength || !separatorCopy.test('')) output.push('');\n      } else output.push(string.slice(lastLastIndex));\n      return output[LENGTH] > splitLimit ? output.slice(0, splitLimit) : output;\n    };\n  // Chakra, V8\n  } else if ('0'[$SPLIT](undefined, 0)[LENGTH]) {\n    internalSplit = function (separator, limit) {\n      return separator === undefined && limit === 0 ? [] : $split.call(this, separator, limit);\n    };\n  } else {\n    internalSplit = $split;\n  }\n\n  return [\n    // `String.prototype.split` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.split\n    function split(separator, limit) {\n      var O = defined(this);\n      var splitter = separator == undefined ? undefined : separator[SPLIT];\n      return splitter !== undefined\n        ? splitter.call(separator, O, limit)\n        : internalSplit.call(String(O), separator, limit);\n    },\n    // `RegExp.prototype[@@split]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@split\n    //\n    // NOTE: This cannot be properly polyfilled in engines that don't support\n    // the 'y' flag.\n    function (regexp, limit) {\n      var res = maybeCallNative(internalSplit, regexp, this, limit, internalSplit !== $split);\n      if (res.done) return res.value;\n\n      var rx = anObject(regexp);\n      var S = String(this);\n      var C = speciesConstructor(rx, RegExp);\n\n      var unicodeMatching = rx.unicode;\n      var flags = (rx.ignoreCase ? 'i' : '') +\n                  (rx.multiline ? 'm' : '') +\n                  (rx.unicode ? 'u' : '') +\n                  (SUPPORTS_Y ? 'y' : 'g');\n\n      // ^(? + rx + ) is needed, in combination with some S slicing, to\n      // simulate the 'y' flag.\n      var splitter = new C(SUPPORTS_Y ? rx : '^(?:' + rx.source + ')', flags);\n      var lim = limit === undefined ? MAX_UINT32 : limit >>> 0;\n      if (lim === 0) return [];\n      if (S.length === 0) return callRegExpExec(splitter, S) === null ? [S] : [];\n      var p = 0;\n      var q = 0;\n      var A = [];\n      while (q < S.length) {\n        splitter.lastIndex = SUPPORTS_Y ? q : 0;\n        var z = callRegExpExec(splitter, SUPPORTS_Y ? S : S.slice(q));\n        var e;\n        if (\n          z === null ||\n          (e = $min(toLength(splitter.lastIndex + (SUPPORTS_Y ? 0 : q)), S.length)) === p\n        ) {\n          q = advanceStringIndex(S, q, unicodeMatching);\n        } else {\n          A.push(S.slice(p, q));\n          if (A.length === lim) return A;\n          for (var i = 1; i <= z.length - 1; i++) {\n            A.push(z[i]);\n            if (A.length === lim) return A;\n          }\n          q = p = e;\n        }\n      }\n      A.push(S.slice(p));\n      return A;\n    }\n  ];\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.regexp.to-string.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.regexp.to-string.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n__webpack_require__(/*! ./es6.regexp.flags */ \"./node_modules/core-js/modules/es6.regexp.flags.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar $flags = __webpack_require__(/*! ./_flags */ \"./node_modules/core-js/modules/_flags.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar TO_STRING = 'toString';\nvar $toString = /./[TO_STRING];\n\nvar define = function (fn) {\n  __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\")(RegExp.prototype, TO_STRING, fn, true);\n};\n\n// 21.2.5.14 RegExp.prototype.toString()\nif (__webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () { return $toString.call({ source: 'a', flags: 'b' }) != '/a/b'; })) {\n  define(function toString() {\n    var R = anObject(this);\n    return '/'.concat(R.source, '/',\n      'flags' in R ? R.flags : !DESCRIPTORS && R instanceof RegExp ? $flags.call(R) : undefined);\n  });\n// FF44- RegExp#toString has a wrong name\n} else if ($toString.name != TO_STRING) {\n  define(function toString() {\n    return $toString.call(this);\n  });\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.set.js\":\n/*!*************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.set.js ***!\n  \\*************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar strong = __webpack_require__(/*! ./_collection-strong */ \"./node_modules/core-js/modules/_collection-strong.js\");\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar SET = 'Set';\n\n// 23.2 Set Objects\nmodule.exports = __webpack_require__(/*! ./_collection */ \"./node_modules/core-js/modules/_collection.js\")(SET, function (get) {\n  return function Set() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.2.3.1 Set.prototype.add(value)\n  add: function add(value) {\n    return strong.def(validate(this, SET), value = value === 0 ? 0 : value, value);\n  }\n}, strong);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.anchor.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.anchor.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.2 String.prototype.anchor(name)\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('anchor', function (createHTML) {\n  return function anchor(name) {\n    return createHTML(this, 'a', 'name', name);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.big.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.big.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.3 String.prototype.big()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('big', function (createHTML) {\n  return function big() {\n    return createHTML(this, 'big', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.blink.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.blink.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.4 String.prototype.blink()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('blink', function (createHTML) {\n  return function blink() {\n    return createHTML(this, 'blink', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.bold.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.bold.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.5 String.prototype.bold()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('bold', function (createHTML) {\n  return function bold() {\n    return createHTML(this, 'b', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.code-point-at.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.code-point-at.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $at = __webpack_require__(/*! ./_string-at */ \"./node_modules/core-js/modules/_string-at.js\")(false);\n$export($export.P, 'String', {\n  // 21.1.3.3 String.prototype.codePointAt(pos)\n  codePointAt: function codePointAt(pos) {\n    return $at(this, pos);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.ends-with.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.ends-with.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// 21.1.3.6 String.prototype.endsWith(searchString [, endPosition])\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar context = __webpack_require__(/*! ./_string-context */ \"./node_modules/core-js/modules/_string-context.js\");\nvar ENDS_WITH = 'endsWith';\nvar $endsWith = ''[ENDS_WITH];\n\n$export($export.P + $export.F * __webpack_require__(/*! ./_fails-is-regexp */ \"./node_modules/core-js/modules/_fails-is-regexp.js\")(ENDS_WITH), 'String', {\n  endsWith: function endsWith(searchString /* , endPosition = @length */) {\n    var that = context(this, searchString, ENDS_WITH);\n    var endPosition = arguments.length > 1 ? arguments[1] : undefined;\n    var len = toLength(that.length);\n    var end = endPosition === undefined ? len : Math.min(toLength(endPosition), len);\n    var search = String(searchString);\n    return $endsWith\n      ? $endsWith.call(that, search, end)\n      : that.slice(end - search.length, end) === search;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.fixed.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.fixed.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.6 String.prototype.fixed()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('fixed', function (createHTML) {\n  return function fixed() {\n    return createHTML(this, 'tt', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.fontcolor.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.fontcolor.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.7 String.prototype.fontcolor(color)\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('fontcolor', function (createHTML) {\n  return function fontcolor(color) {\n    return createHTML(this, 'font', 'color', color);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.fontsize.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.fontsize.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.8 String.prototype.fontsize(size)\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('fontsize', function (createHTML) {\n  return function fontsize(size) {\n    return createHTML(this, 'font', 'size', size);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.from-code-point.js\":\n/*!********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.from-code-point.js ***!\n  \\********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nvar fromCharCode = String.fromCharCode;\nvar $fromCodePoint = String.fromCodePoint;\n\n// length should be 1, old FF problem\n$export($export.S + $export.F * (!!$fromCodePoint && $fromCodePoint.length != 1), 'String', {\n  // 21.1.2.2 String.fromCodePoint(...codePoints)\n  fromCodePoint: function fromCodePoint(x) { // eslint-disable-line no-unused-vars\n    var res = [];\n    var aLen = arguments.length;\n    var i = 0;\n    var code;\n    while (aLen > i) {\n      code = +arguments[i++];\n      if (toAbsoluteIndex(code, 0x10ffff) !== code) throw RangeError(code + ' is not a valid code point');\n      res.push(code < 0x10000\n        ? fromCharCode(code)\n        : fromCharCode(((code -= 0x10000) >> 10) + 0xd800, code % 0x400 + 0xdc00)\n      );\n    } return res.join('');\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.includes.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.includes.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// 21.1.3.7 String.prototype.includes(searchString, position = 0)\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar context = __webpack_require__(/*! ./_string-context */ \"./node_modules/core-js/modules/_string-context.js\");\nvar INCLUDES = 'includes';\n\n$export($export.P + $export.F * __webpack_require__(/*! ./_fails-is-regexp */ \"./node_modules/core-js/modules/_fails-is-regexp.js\")(INCLUDES), 'String', {\n  includes: function includes(searchString /* , position = 0 */) {\n    return !!~context(this, searchString, INCLUDES)\n      .indexOf(searchString, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.italics.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.italics.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.9 String.prototype.italics()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('italics', function (createHTML) {\n  return function italics() {\n    return createHTML(this, 'i', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.iterator.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.iterator.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $at = __webpack_require__(/*! ./_string-at */ \"./node_modules/core-js/modules/_string-at.js\")(true);\n\n// 21.1.3.27 String.prototype[@@iterator]()\n__webpack_require__(/*! ./_iter-define */ \"./node_modules/core-js/modules/_iter-define.js\")(String, 'String', function (iterated) {\n  this._t = String(iterated); // target\n  this._i = 0;                // next index\n// 21.1.5.2.1 %StringIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var index = this._i;\n  var point;\n  if (index >= O.length) return { value: undefined, done: true };\n  point = $at(O, index);\n  this._i += point.length;\n  return { value: point, done: false };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.link.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.link.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.10 String.prototype.link(url)\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('link', function (createHTML) {\n  return function link(url) {\n    return createHTML(this, 'a', 'href', url);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.raw.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.raw.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\n\n$export($export.S, 'String', {\n  // 21.1.2.4 String.raw(callSite, ...substitutions)\n  raw: function raw(callSite) {\n    var tpl = toIObject(callSite.raw);\n    var len = toLength(tpl.length);\n    var aLen = arguments.length;\n    var res = [];\n    var i = 0;\n    while (len > i) {\n      res.push(String(tpl[i++]));\n      if (i < aLen) res.push(String(arguments[i]));\n    } return res.join('');\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.repeat.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.repeat.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P, 'String', {\n  // 21.1.3.13 String.prototype.repeat(count)\n  repeat: __webpack_require__(/*! ./_string-repeat */ \"./node_modules/core-js/modules/_string-repeat.js\")\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.small.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.small.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.11 String.prototype.small()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('small', function (createHTML) {\n  return function small() {\n    return createHTML(this, 'small', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.starts-with.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.starts-with.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// 21.1.3.18 String.prototype.startsWith(searchString [, position ])\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar context = __webpack_require__(/*! ./_string-context */ \"./node_modules/core-js/modules/_string-context.js\");\nvar STARTS_WITH = 'startsWith';\nvar $startsWith = ''[STARTS_WITH];\n\n$export($export.P + $export.F * __webpack_require__(/*! ./_fails-is-regexp */ \"./node_modules/core-js/modules/_fails-is-regexp.js\")(STARTS_WITH), 'String', {\n  startsWith: function startsWith(searchString /* , position = 0 */) {\n    var that = context(this, searchString, STARTS_WITH);\n    var index = toLength(Math.min(arguments.length > 1 ? arguments[1] : undefined, that.length));\n    var search = String(searchString);\n    return $startsWith\n      ? $startsWith.call(that, search, index)\n      : that.slice(index, index + search.length) === search;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.strike.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.strike.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.12 String.prototype.strike()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('strike', function (createHTML) {\n  return function strike() {\n    return createHTML(this, 'strike', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.sub.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.sub.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.13 String.prototype.sub()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('sub', function (createHTML) {\n  return function sub() {\n    return createHTML(this, 'sub', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.sup.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.sup.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// B.2.3.14 String.prototype.sup()\n__webpack_require__(/*! ./_string-html */ \"./node_modules/core-js/modules/_string-html.js\")('sup', function (createHTML) {\n  return function sup() {\n    return createHTML(this, 'sup', '', '');\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.string.trim.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.string.trim.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// 21.1.3.25 String.prototype.trim()\n__webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\")('trim', function ($trim) {\n  return function trim() {\n    return $trim(this, 3);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.symbol.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.symbol.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// ECMAScript 6 symbols shim\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar has = __webpack_require__(/*! ./_has */ \"./node_modules/core-js/modules/_has.js\");\nvar DESCRIPTORS = __webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar META = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\").KEY;\nvar $fails = __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\");\nvar shared = __webpack_require__(/*! ./_shared */ \"./node_modules/core-js/modules/_shared.js\");\nvar setToStringTag = __webpack_require__(/*! ./_set-to-string-tag */ \"./node_modules/core-js/modules/_set-to-string-tag.js\");\nvar uid = __webpack_require__(/*! ./_uid */ \"./node_modules/core-js/modules/_uid.js\");\nvar wks = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\nvar wksExt = __webpack_require__(/*! ./_wks-ext */ \"./node_modules/core-js/modules/_wks-ext.js\");\nvar wksDefine = __webpack_require__(/*! ./_wks-define */ \"./node_modules/core-js/modules/_wks-define.js\");\nvar enumKeys = __webpack_require__(/*! ./_enum-keys */ \"./node_modules/core-js/modules/_enum-keys.js\");\nvar isArray = __webpack_require__(/*! ./_is-array */ \"./node_modules/core-js/modules/_is-array.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar createDesc = __webpack_require__(/*! ./_property-desc */ \"./node_modules/core-js/modules/_property-desc.js\");\nvar _create = __webpack_require__(/*! ./_object-create */ \"./node_modules/core-js/modules/_object-create.js\");\nvar gOPNExt = __webpack_require__(/*! ./_object-gopn-ext */ \"./node_modules/core-js/modules/_object-gopn-ext.js\");\nvar $GOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\nvar $DP = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\nvar $keys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar gOPD = $GOPD.f;\nvar dP = $DP.f;\nvar gOPN = gOPNExt.f;\nvar $Symbol = global.Symbol;\nvar $JSON = global.JSON;\nvar _stringify = $JSON && $JSON.stringify;\nvar PROTOTYPE = 'prototype';\nvar HIDDEN = wks('_hidden');\nvar TO_PRIMITIVE = wks('toPrimitive');\nvar isEnum = {}.propertyIsEnumerable;\nvar SymbolRegistry = shared('symbol-registry');\nvar AllSymbols = shared('symbols');\nvar OPSymbols = shared('op-symbols');\nvar ObjectProto = Object[PROTOTYPE];\nvar USE_NATIVE = typeof $Symbol == 'function';\nvar QObject = global.QObject;\n// Don't use setters in Qt Script, https://github.com/zloirock/core-js/issues/173\nvar setter = !QObject || !QObject[PROTOTYPE] || !QObject[PROTOTYPE].findChild;\n\n// fallback for old Android, https://code.google.com/p/v8/issues/detail?id=687\nvar setSymbolDesc = DESCRIPTORS && $fails(function () {\n  return _create(dP({}, 'a', {\n    get: function () { return dP(this, 'a', { value: 7 }).a; }\n  })).a != 7;\n}) ? function (it, key, D) {\n  var protoDesc = gOPD(ObjectProto, key);\n  if (protoDesc) delete ObjectProto[key];\n  dP(it, key, D);\n  if (protoDesc && it !== ObjectProto) dP(ObjectProto, key, protoDesc);\n} : dP;\n\nvar wrap = function (tag) {\n  var sym = AllSymbols[tag] = _create($Symbol[PROTOTYPE]);\n  sym._k = tag;\n  return sym;\n};\n\nvar isSymbol = USE_NATIVE && typeof $Symbol.iterator == 'symbol' ? function (it) {\n  return typeof it == 'symbol';\n} : function (it) {\n  return it instanceof $Symbol;\n};\n\nvar $defineProperty = function defineProperty(it, key, D) {\n  if (it === ObjectProto) $defineProperty(OPSymbols, key, D);\n  anObject(it);\n  key = toPrimitive(key, true);\n  anObject(D);\n  if (has(AllSymbols, key)) {\n    if (!D.enumerable) {\n      if (!has(it, HIDDEN)) dP(it, HIDDEN, createDesc(1, {}));\n      it[HIDDEN][key] = true;\n    } else {\n      if (has(it, HIDDEN) && it[HIDDEN][key]) it[HIDDEN][key] = false;\n      D = _create(D, { enumerable: createDesc(0, false) });\n    } return setSymbolDesc(it, key, D);\n  } return dP(it, key, D);\n};\nvar $defineProperties = function defineProperties(it, P) {\n  anObject(it);\n  var keys = enumKeys(P = toIObject(P));\n  var i = 0;\n  var l = keys.length;\n  var key;\n  while (l > i) $defineProperty(it, key = keys[i++], P[key]);\n  return it;\n};\nvar $create = function create(it, P) {\n  return P === undefined ? _create(it) : $defineProperties(_create(it), P);\n};\nvar $propertyIsEnumerable = function propertyIsEnumerable(key) {\n  var E = isEnum.call(this, key = toPrimitive(key, true));\n  if (this === ObjectProto && has(AllSymbols, key) && !has(OPSymbols, key)) return false;\n  return E || !has(this, key) || !has(AllSymbols, key) || has(this, HIDDEN) && this[HIDDEN][key] ? E : true;\n};\nvar $getOwnPropertyDescriptor = function getOwnPropertyDescriptor(it, key) {\n  it = toIObject(it);\n  key = toPrimitive(key, true);\n  if (it === ObjectProto && has(AllSymbols, key) && !has(OPSymbols, key)) return;\n  var D = gOPD(it, key);\n  if (D && has(AllSymbols, key) && !(has(it, HIDDEN) && it[HIDDEN][key])) D.enumerable = true;\n  return D;\n};\nvar $getOwnPropertyNames = function getOwnPropertyNames(it) {\n  var names = gOPN(toIObject(it));\n  var result = [];\n  var i = 0;\n  var key;\n  while (names.length > i) {\n    if (!has(AllSymbols, key = names[i++]) && key != HIDDEN && key != META) result.push(key);\n  } return result;\n};\nvar $getOwnPropertySymbols = function getOwnPropertySymbols(it) {\n  var IS_OP = it === ObjectProto;\n  var names = gOPN(IS_OP ? OPSymbols : toIObject(it));\n  var result = [];\n  var i = 0;\n  var key;\n  while (names.length > i) {\n    if (has(AllSymbols, key = names[i++]) && (IS_OP ? has(ObjectProto, key) : true)) result.push(AllSymbols[key]);\n  } return result;\n};\n\n// 19.4.1.1 Symbol([description])\nif (!USE_NATIVE) {\n  $Symbol = function Symbol() {\n    if (this instanceof $Symbol) throw TypeError('Symbol is not a constructor!');\n    var tag = uid(arguments.length > 0 ? arguments[0] : undefined);\n    var $set = function (value) {\n      if (this === ObjectProto) $set.call(OPSymbols, value);\n      if (has(this, HIDDEN) && has(this[HIDDEN], tag)) this[HIDDEN][tag] = false;\n      setSymbolDesc(this, tag, createDesc(1, value));\n    };\n    if (DESCRIPTORS && setter) setSymbolDesc(ObjectProto, tag, { configurable: true, set: $set });\n    return wrap(tag);\n  };\n  redefine($Symbol[PROTOTYPE], 'toString', function toString() {\n    return this._k;\n  });\n\n  $GOPD.f = $getOwnPropertyDescriptor;\n  $DP.f = $defineProperty;\n  __webpack_require__(/*! ./_object-gopn */ \"./node_modules/core-js/modules/_object-gopn.js\").f = gOPNExt.f = $getOwnPropertyNames;\n  __webpack_require__(/*! ./_object-pie */ \"./node_modules/core-js/modules/_object-pie.js\").f = $propertyIsEnumerable;\n  __webpack_require__(/*! ./_object-gops */ \"./node_modules/core-js/modules/_object-gops.js\").f = $getOwnPropertySymbols;\n\n  if (DESCRIPTORS && !__webpack_require__(/*! ./_library */ \"./node_modules/core-js/modules/_library.js\")) {\n    redefine(ObjectProto, 'propertyIsEnumerable', $propertyIsEnumerable, true);\n  }\n\n  wksExt.f = function (name) {\n    return wrap(wks(name));\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Symbol: $Symbol });\n\nfor (var es6Symbols = (\n  // 19.4.2.2, 19.4.2.3, 19.4.2.4, 19.4.2.6, 19.4.2.8, 19.4.2.9, 19.4.2.10, 19.4.2.11, 19.4.2.12, 19.4.2.13, 19.4.2.14\n  'hasInstance,isConcatSpreadable,iterator,match,replace,search,species,split,toPrimitive,toStringTag,unscopables'\n).split(','), j = 0; es6Symbols.length > j;)wks(es6Symbols[j++]);\n\nfor (var wellKnownSymbols = $keys(wks.store), k = 0; wellKnownSymbols.length > k;) wksDefine(wellKnownSymbols[k++]);\n\n$export($export.S + $export.F * !USE_NATIVE, 'Symbol', {\n  // 19.4.2.1 Symbol.for(key)\n  'for': function (key) {\n    return has(SymbolRegistry, key += '')\n      ? SymbolRegistry[key]\n      : SymbolRegistry[key] = $Symbol(key);\n  },\n  // 19.4.2.5 Symbol.keyFor(sym)\n  keyFor: function keyFor(sym) {\n    if (!isSymbol(sym)) throw TypeError(sym + ' is not a symbol!');\n    for (var key in SymbolRegistry) if (SymbolRegistry[key] === sym) return key;\n  },\n  useSetter: function () { setter = true; },\n  useSimple: function () { setter = false; }\n});\n\n$export($export.S + $export.F * !USE_NATIVE, 'Object', {\n  // 19.1.2.2 Object.create(O [, Properties])\n  create: $create,\n  // 19.1.2.4 Object.defineProperty(O, P, Attributes)\n  defineProperty: $defineProperty,\n  // 19.1.2.3 Object.defineProperties(O, Properties)\n  defineProperties: $defineProperties,\n  // 19.1.2.6 Object.getOwnPropertyDescriptor(O, P)\n  getOwnPropertyDescriptor: $getOwnPropertyDescriptor,\n  // 19.1.2.7 Object.getOwnPropertyNames(O)\n  getOwnPropertyNames: $getOwnPropertyNames,\n  // 19.1.2.8 Object.getOwnPropertySymbols(O)\n  getOwnPropertySymbols: $getOwnPropertySymbols\n});\n\n// 24.3.2 JSON.stringify(value [, replacer [, space]])\n$JSON && $export($export.S + $export.F * (!USE_NATIVE || $fails(function () {\n  var S = $Symbol();\n  // MS Edge converts symbol values to JSON as {}\n  // WebKit converts symbol values to JSON as null\n  // V8 throws on boxed symbols\n  return _stringify([S]) != '[null]' || _stringify({ a: S }) != '{}' || _stringify(Object(S)) != '{}';\n})), 'JSON', {\n  stringify: function stringify(it) {\n    var args = [it];\n    var i = 1;\n    var replacer, $replacer;\n    while (arguments.length > i) args.push(arguments[i++]);\n    $replacer = replacer = args[1];\n    if (!isObject(replacer) && it === undefined || isSymbol(it)) return; // IE8 returns string on undefined\n    if (!isArray(replacer)) replacer = function (key, value) {\n      if (typeof $replacer == 'function') value = $replacer.call(this, key, value);\n      if (!isSymbol(value)) return value;\n    };\n    args[1] = replacer;\n    return _stringify.apply($JSON, args);\n  }\n});\n\n// 19.4.3.4 Symbol.prototype[@@toPrimitive](hint)\n$Symbol[PROTOTYPE][TO_PRIMITIVE] || __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\")($Symbol[PROTOTYPE], TO_PRIMITIVE, $Symbol[PROTOTYPE].valueOf);\n// 19.4.3.5 Symbol.prototype[@@toStringTag]\nsetToStringTag($Symbol, 'Symbol');\n// 20.2.1.9 Math[@@toStringTag]\nsetToStringTag(Math, 'Math', true);\n// 24.3.3 JSON[@@toStringTag]\nsetToStringTag(global.JSON, 'JSON', true);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.array-buffer.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.array-buffer.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $typed = __webpack_require__(/*! ./_typed */ \"./node_modules/core-js/modules/_typed.js\");\nvar buffer = __webpack_require__(/*! ./_typed-buffer */ \"./node_modules/core-js/modules/_typed-buffer.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toAbsoluteIndex = __webpack_require__(/*! ./_to-absolute-index */ \"./node_modules/core-js/modules/_to-absolute-index.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar ArrayBuffer = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").ArrayBuffer;\nvar speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\nvar $ArrayBuffer = buffer.ArrayBuffer;\nvar $DataView = buffer.DataView;\nvar $isView = $typed.ABV && ArrayBuffer.isView;\nvar $slice = $ArrayBuffer.prototype.slice;\nvar VIEW = $typed.VIEW;\nvar ARRAY_BUFFER = 'ArrayBuffer';\n\n$export($export.G + $export.W + $export.F * (ArrayBuffer !== $ArrayBuffer), { ArrayBuffer: $ArrayBuffer });\n\n$export($export.S + $export.F * !$typed.CONSTR, ARRAY_BUFFER, {\n  // 24.1.3.1 ArrayBuffer.isView(arg)\n  isView: function isView(it) {\n    return $isView && $isView(it) || isObject(it) && VIEW in it;\n  }\n});\n\n$export($export.P + $export.U + $export.F * __webpack_require__(/*! ./_fails */ \"./node_modules/core-js/modules/_fails.js\")(function () {\n  return !new $ArrayBuffer(2).slice(1, undefined).byteLength;\n}), ARRAY_BUFFER, {\n  // 24.1.4.3 ArrayBuffer.prototype.slice(start, end)\n  slice: function slice(start, end) {\n    if ($slice !== undefined && end === undefined) return $slice.call(anObject(this), start); // FF fix\n    var len = anObject(this).byteLength;\n    var first = toAbsoluteIndex(start, len);\n    var fin = toAbsoluteIndex(end === undefined ? len : end, len);\n    var result = new (speciesConstructor(this, $ArrayBuffer))(toLength(fin - first));\n    var viewS = new $DataView(this);\n    var viewT = new $DataView(result);\n    var index = 0;\n    while (first < fin) {\n      viewT.setUint8(index++, viewS.getUint8(first++));\n    } return result;\n  }\n});\n\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")(ARRAY_BUFFER);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.data-view.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.data-view.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n$export($export.G + $export.W + $export.F * !__webpack_require__(/*! ./_typed */ \"./node_modules/core-js/modules/_typed.js\").ABV, {\n  DataView: __webpack_require__(/*! ./_typed-buffer */ \"./node_modules/core-js/modules/_typed-buffer.js\").DataView\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.float32-array.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.float32-array.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Float32', 4, function (init) {\n  return function Float32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.float64-array.js\":\n/*!*****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.float64-array.js ***!\n  \\*****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Float64', 8, function (init) {\n  return function Float64Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.int16-array.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.int16-array.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Int16', 2, function (init) {\n  return function Int16Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.int32-array.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.int32-array.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Int32', 4, function (init) {\n  return function Int32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.int8-array.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.int8-array.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Int8', 1, function (init) {\n  return function Int8Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.uint16-array.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.uint16-array.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Uint16', 2, function (init) {\n  return function Uint16Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.uint32-array.js\":\n/*!****************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.uint32-array.js ***!\n  \\****************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Uint32', 4, function (init) {\n  return function Uint32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.uint8-array.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.uint8-array.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Uint8', 1, function (init) {\n  return function Uint8Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.typed.uint8-clamped-array.js\":\n/*!***********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.typed.uint8-clamped-array.js ***!\n  \\***********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_typed-array */ \"./node_modules/core-js/modules/_typed-array.js\")('Uint8', 1, function (init) {\n  return function Uint8ClampedArray(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n}, true);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.weak-map.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.weak-map.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar each = __webpack_require__(/*! ./_array-methods */ \"./node_modules/core-js/modules/_array-methods.js\")(0);\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar meta = __webpack_require__(/*! ./_meta */ \"./node_modules/core-js/modules/_meta.js\");\nvar assign = __webpack_require__(/*! ./_object-assign */ \"./node_modules/core-js/modules/_object-assign.js\");\nvar weak = __webpack_require__(/*! ./_collection-weak */ \"./node_modules/core-js/modules/_collection-weak.js\");\nvar isObject = __webpack_require__(/*! ./_is-object */ \"./node_modules/core-js/modules/_is-object.js\");\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar NATIVE_WEAK_MAP = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar IS_IE11 = !global.ActiveXObject && 'ActiveXObject' in global;\nvar WEAK_MAP = 'WeakMap';\nvar getWeak = meta.getWeak;\nvar isExtensible = Object.isExtensible;\nvar uncaughtFrozenStore = weak.ufstore;\nvar InternalMap;\n\nvar wrapper = function (get) {\n  return function WeakMap() {\n    return get(this, arguments.length > 0 ? arguments[0] : undefined);\n  };\n};\n\nvar methods = {\n  // 23.3.3.3 WeakMap.prototype.get(key)\n  get: function get(key) {\n    if (isObject(key)) {\n      var data = getWeak(key);\n      if (data === true) return uncaughtFrozenStore(validate(this, WEAK_MAP)).get(key);\n      return data ? data[this._i] : undefined;\n    }\n  },\n  // 23.3.3.5 WeakMap.prototype.set(key, value)\n  set: function set(key, value) {\n    return weak.def(validate(this, WEAK_MAP), key, value);\n  }\n};\n\n// 23.3 WeakMap Objects\nvar $WeakMap = module.exports = __webpack_require__(/*! ./_collection */ \"./node_modules/core-js/modules/_collection.js\")(WEAK_MAP, wrapper, methods, weak, true, true);\n\n// IE11 WeakMap frozen keys fix\nif (NATIVE_WEAK_MAP && IS_IE11) {\n  InternalMap = weak.getConstructor(wrapper, WEAK_MAP);\n  assign(InternalMap.prototype, methods);\n  meta.NEED = true;\n  each(['delete', 'has', 'get', 'set'], function (key) {\n    var proto = $WeakMap.prototype;\n    var method = proto[key];\n    redefine(proto, key, function (a, b) {\n      // store frozen objects on internal weakmap shim\n      if (isObject(a) && !isExtensible(a)) {\n        if (!this._f) this._f = new InternalMap();\n        var result = this._f[key](a, b);\n        return key == 'set' ? this : result;\n      // store all the rest on native weakmap\n      } return method.call(this, a, b);\n    });\n  });\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es6.weak-set.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es6.weak-set.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar weak = __webpack_require__(/*! ./_collection-weak */ \"./node_modules/core-js/modules/_collection-weak.js\");\nvar validate = __webpack_require__(/*! ./_validate-collection */ \"./node_modules/core-js/modules/_validate-collection.js\");\nvar WEAK_SET = 'WeakSet';\n\n// 23.4 WeakSet Objects\n__webpack_require__(/*! ./_collection */ \"./node_modules/core-js/modules/_collection.js\")(WEAK_SET, function (get) {\n  return function WeakSet() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.4.3.1 WeakSet.prototype.add(value)\n  add: function add(value) {\n    return weak.def(validate(this, WEAK_SET), value, true);\n  }\n}, weak, false, true);\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.array.flat-map.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.array.flat-map.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/proposal-flatMap/#sec-Array.prototype.flatMap\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar flattenIntoArray = __webpack_require__(/*! ./_flatten-into-array */ \"./node_modules/core-js/modules/_flatten-into-array.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar arraySpeciesCreate = __webpack_require__(/*! ./_array-species-create */ \"./node_modules/core-js/modules/_array-species-create.js\");\n\n$export($export.P, 'Array', {\n  flatMap: function flatMap(callbackfn /* , thisArg */) {\n    var O = toObject(this);\n    var sourceLen, A;\n    aFunction(callbackfn);\n    sourceLen = toLength(O.length);\n    A = arraySpeciesCreate(O, 0);\n    flattenIntoArray(A, O, O, sourceLen, 0, 1, callbackfn, arguments[1]);\n    return A;\n  }\n});\n\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")('flatMap');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.array.flatten.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.array.flatten.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/proposal-flatMap/#sec-Array.prototype.flatten\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar flattenIntoArray = __webpack_require__(/*! ./_flatten-into-array */ \"./node_modules/core-js/modules/_flatten-into-array.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar toInteger = __webpack_require__(/*! ./_to-integer */ \"./node_modules/core-js/modules/_to-integer.js\");\nvar arraySpeciesCreate = __webpack_require__(/*! ./_array-species-create */ \"./node_modules/core-js/modules/_array-species-create.js\");\n\n$export($export.P, 'Array', {\n  flatten: function flatten(/* depthArg = 1 */) {\n    var depthArg = arguments[0];\n    var O = toObject(this);\n    var sourceLen = toLength(O.length);\n    var A = arraySpeciesCreate(O, 0);\n    flattenIntoArray(A, O, O, sourceLen, 0, depthArg === undefined ? 1 : toInteger(depthArg));\n    return A;\n  }\n});\n\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")('flatten');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.array.includes.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.array.includes.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/tc39/Array.prototype.includes\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $includes = __webpack_require__(/*! ./_array-includes */ \"./node_modules/core-js/modules/_array-includes.js\")(true);\n\n$export($export.P, 'Array', {\n  includes: function includes(el /* , fromIndex = 0 */) {\n    return $includes(this, el, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n\n__webpack_require__(/*! ./_add-to-unscopables */ \"./node_modules/core-js/modules/_add-to-unscopables.js\")('includes');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.asap.js\":\n/*!**************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.asap.js ***!\n  \\**************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/rwaldron/tc39-notes/blob/master/es6/2014-09/sept-25.md#510-globalasap-for-enqueuing-a-microtask\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar microtask = __webpack_require__(/*! ./_microtask */ \"./node_modules/core-js/modules/_microtask.js\")();\nvar process = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\").process;\nvar isNode = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\")(process) == 'process';\n\n$export($export.G, {\n  asap: function asap(fn) {\n    var domain = isNode && process.domain;\n    microtask(domain ? domain.bind(fn) : fn);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.error.is-error.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.error.is-error.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/ljharb/proposal-is-error\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar cof = __webpack_require__(/*! ./_cof */ \"./node_modules/core-js/modules/_cof.js\");\n\n$export($export.S, 'Error', {\n  isError: function isError(it) {\n    return cof(it) === 'Error';\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.global.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.global.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-global\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.G, { global: __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.map.from.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.map.from.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-map.from\n__webpack_require__(/*! ./_set-collection-from */ \"./node_modules/core-js/modules/_set-collection-from.js\")('Map');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.map.of.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.map.of.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-map.of\n__webpack_require__(/*! ./_set-collection-of */ \"./node_modules/core-js/modules/_set-collection-of.js\")('Map');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.map.to-json.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.map.to-json.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P + $export.R, 'Map', { toJSON: __webpack_require__(/*! ./_collection-to-json */ \"./node_modules/core-js/modules/_collection-to-json.js\")('Map') });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.clamp.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.clamp.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  clamp: function clamp(x, lower, upper) {\n    return Math.min(upper, Math.max(lower, x));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.deg-per-rad.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.deg-per-rad.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { DEG_PER_RAD: Math.PI / 180 });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.degrees.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.degrees.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar RAD_PER_DEG = 180 / Math.PI;\n\n$export($export.S, 'Math', {\n  degrees: function degrees(radians) {\n    return radians * RAD_PER_DEG;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.fscale.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.fscale.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar scale = __webpack_require__(/*! ./_math-scale */ \"./node_modules/core-js/modules/_math-scale.js\");\nvar fround = __webpack_require__(/*! ./_math-fround */ \"./node_modules/core-js/modules/_math-fround.js\");\n\n$export($export.S, 'Math', {\n  fscale: function fscale(x, inLow, inHigh, outLow, outHigh) {\n    return fround(scale(x, inLow, inHigh, outLow, outHigh));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.iaddh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.iaddh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  iaddh: function iaddh(x0, x1, y0, y1) {\n    var $x0 = x0 >>> 0;\n    var $x1 = x1 >>> 0;\n    var $y0 = y0 >>> 0;\n    return $x1 + (y1 >>> 0) + (($x0 & $y0 | ($x0 | $y0) & ~($x0 + $y0 >>> 0)) >>> 31) | 0;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.imulh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.imulh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  imulh: function imulh(u, v) {\n    var UINT16 = 0xffff;\n    var $u = +u;\n    var $v = +v;\n    var u0 = $u & UINT16;\n    var v0 = $v & UINT16;\n    var u1 = $u >> 16;\n    var v1 = $v >> 16;\n    var t = (u1 * v0 >>> 0) + (u0 * v0 >>> 16);\n    return u1 * v1 + (t >> 16) + ((u0 * v1 >>> 0) + (t & UINT16) >> 16);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.isubh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.isubh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  isubh: function isubh(x0, x1, y0, y1) {\n    var $x0 = x0 >>> 0;\n    var $x1 = x1 >>> 0;\n    var $y0 = y0 >>> 0;\n    return $x1 - (y1 >>> 0) - ((~$x0 & $y0 | ~($x0 ^ $y0) & $x0 - $y0 >>> 0) >>> 31) | 0;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.rad-per-deg.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.rad-per-deg.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { RAD_PER_DEG: 180 / Math.PI });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.radians.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.radians.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar DEG_PER_RAD = Math.PI / 180;\n\n$export($export.S, 'Math', {\n  radians: function radians(degrees) {\n    return degrees * DEG_PER_RAD;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.scale.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.scale.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { scale: __webpack_require__(/*! ./_math-scale */ \"./node_modules/core-js/modules/_math-scale.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.signbit.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.signbit.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// http://jfbastien.github.io/papers/Math.signbit.html\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', { signbit: function signbit(x) {\n  // eslint-disable-next-line no-self-compare\n  return (x = +x) != x ? x : x == 0 ? 1 / x == Infinity : x > 0;\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.math.umulh.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.math.umulh.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'Math', {\n  umulh: function umulh(u, v) {\n    var UINT16 = 0xffff;\n    var $u = +u;\n    var $v = +v;\n    var u0 = $u & UINT16;\n    var v0 = $v & UINT16;\n    var u1 = $u >>> 16;\n    var v1 = $v >>> 16;\n    var t = (u1 * v0 >>> 0) + (u0 * v0 >>> 16);\n    return u1 * v1 + (t >>> 16) + ((u0 * v1 >>> 0) + (t & UINT16) >>> 16);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.define-getter.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.define-getter.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar $defineProperty = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\n\n// B.2.2.2 Object.prototype.__defineGetter__(P, getter)\n__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && $export($export.P + __webpack_require__(/*! ./_object-forced-pam */ \"./node_modules/core-js/modules/_object-forced-pam.js\"), 'Object', {\n  __defineGetter__: function __defineGetter__(P, getter) {\n    $defineProperty.f(toObject(this), P, { get: aFunction(getter), enumerable: true, configurable: true });\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.define-setter.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.define-setter.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar $defineProperty = __webpack_require__(/*! ./_object-dp */ \"./node_modules/core-js/modules/_object-dp.js\");\n\n// B.2.2.3 Object.prototype.__defineSetter__(P, setter)\n__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && $export($export.P + __webpack_require__(/*! ./_object-forced-pam */ \"./node_modules/core-js/modules/_object-forced-pam.js\"), 'Object', {\n  __defineSetter__: function __defineSetter__(P, setter) {\n    $defineProperty.f(toObject(this), P, { set: aFunction(setter), enumerable: true, configurable: true });\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.entries.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.entries.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-object-values-entries\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $entries = __webpack_require__(/*! ./_object-to-array */ \"./node_modules/core-js/modules/_object-to-array.js\")(true);\n\n$export($export.S, 'Object', {\n  entries: function entries(it) {\n    return $entries(it);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.get-own-property-descriptors.js\":\n/*!*********************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.get-own-property-descriptors.js ***!\n  \\*********************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-object-getownpropertydescriptors\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar ownKeys = __webpack_require__(/*! ./_own-keys */ \"./node_modules/core-js/modules/_own-keys.js\");\nvar toIObject = __webpack_require__(/*! ./_to-iobject */ \"./node_modules/core-js/modules/_to-iobject.js\");\nvar gOPD = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\");\nvar createProperty = __webpack_require__(/*! ./_create-property */ \"./node_modules/core-js/modules/_create-property.js\");\n\n$export($export.S, 'Object', {\n  getOwnPropertyDescriptors: function getOwnPropertyDescriptors(object) {\n    var O = toIObject(object);\n    var getDesc = gOPD.f;\n    var keys = ownKeys(O);\n    var result = {};\n    var i = 0;\n    var key, desc;\n    while (keys.length > i) {\n      desc = getDesc(O, key = keys[i++]);\n      if (desc !== undefined) createProperty(result, key, desc);\n    }\n    return result;\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.lookup-getter.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.lookup-getter.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar getOwnPropertyDescriptor = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f;\n\n// B.2.2.4 Object.prototype.__lookupGetter__(P)\n__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && $export($export.P + __webpack_require__(/*! ./_object-forced-pam */ \"./node_modules/core-js/modules/_object-forced-pam.js\"), 'Object', {\n  __lookupGetter__: function __lookupGetter__(P) {\n    var O = toObject(this);\n    var K = toPrimitive(P, true);\n    var D;\n    do {\n      if (D = getOwnPropertyDescriptor(O, K)) return D.get;\n    } while (O = getPrototypeOf(O));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.lookup-setter.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.lookup-setter.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar toObject = __webpack_require__(/*! ./_to-object */ \"./node_modules/core-js/modules/_to-object.js\");\nvar toPrimitive = __webpack_require__(/*! ./_to-primitive */ \"./node_modules/core-js/modules/_to-primitive.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar getOwnPropertyDescriptor = __webpack_require__(/*! ./_object-gopd */ \"./node_modules/core-js/modules/_object-gopd.js\").f;\n\n// B.2.2.5 Object.prototype.__lookupSetter__(P)\n__webpack_require__(/*! ./_descriptors */ \"./node_modules/core-js/modules/_descriptors.js\") && $export($export.P + __webpack_require__(/*! ./_object-forced-pam */ \"./node_modules/core-js/modules/_object-forced-pam.js\"), 'Object', {\n  __lookupSetter__: function __lookupSetter__(P) {\n    var O = toObject(this);\n    var K = toPrimitive(P, true);\n    var D;\n    do {\n      if (D = getOwnPropertyDescriptor(O, K)) return D.set;\n    } while (O = getPrototypeOf(O));\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.object.values.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.object.values.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-object-values-entries\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $values = __webpack_require__(/*! ./_object-to-array */ \"./node_modules/core-js/modules/_object-to-array.js\")(false);\n\n$export($export.S, 'Object', {\n  values: function values(it) {\n    return $values(it);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.observable.js\":\n/*!********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.observable.js ***!\n  \\********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/zenparsing/es-observable\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar microtask = __webpack_require__(/*! ./_microtask */ \"./node_modules/core-js/modules/_microtask.js\")();\nvar OBSERVABLE = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\")('observable');\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar anInstance = __webpack_require__(/*! ./_an-instance */ \"./node_modules/core-js/modules/_an-instance.js\");\nvar redefineAll = __webpack_require__(/*! ./_redefine-all */ \"./node_modules/core-js/modules/_redefine-all.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar forOf = __webpack_require__(/*! ./_for-of */ \"./node_modules/core-js/modules/_for-of.js\");\nvar RETURN = forOf.RETURN;\n\nvar getMethod = function (fn) {\n  return fn == null ? undefined : aFunction(fn);\n};\n\nvar cleanupSubscription = function (subscription) {\n  var cleanup = subscription._c;\n  if (cleanup) {\n    subscription._c = undefined;\n    cleanup();\n  }\n};\n\nvar subscriptionClosed = function (subscription) {\n  return subscription._o === undefined;\n};\n\nvar closeSubscription = function (subscription) {\n  if (!subscriptionClosed(subscription)) {\n    subscription._o = undefined;\n    cleanupSubscription(subscription);\n  }\n};\n\nvar Subscription = function (observer, subscriber) {\n  anObject(observer);\n  this._c = undefined;\n  this._o = observer;\n  observer = new SubscriptionObserver(this);\n  try {\n    var cleanup = subscriber(observer);\n    var subscription = cleanup;\n    if (cleanup != null) {\n      if (typeof cleanup.unsubscribe === 'function') cleanup = function () { subscription.unsubscribe(); };\n      else aFunction(cleanup);\n      this._c = cleanup;\n    }\n  } catch (e) {\n    observer.error(e);\n    return;\n  } if (subscriptionClosed(this)) cleanupSubscription(this);\n};\n\nSubscription.prototype = redefineAll({}, {\n  unsubscribe: function unsubscribe() { closeSubscription(this); }\n});\n\nvar SubscriptionObserver = function (subscription) {\n  this._s = subscription;\n};\n\nSubscriptionObserver.prototype = redefineAll({}, {\n  next: function next(value) {\n    var subscription = this._s;\n    if (!subscriptionClosed(subscription)) {\n      var observer = subscription._o;\n      try {\n        var m = getMethod(observer.next);\n        if (m) return m.call(observer, value);\n      } catch (e) {\n        try {\n          closeSubscription(subscription);\n        } finally {\n          throw e;\n        }\n      }\n    }\n  },\n  error: function error(value) {\n    var subscription = this._s;\n    if (subscriptionClosed(subscription)) throw value;\n    var observer = subscription._o;\n    subscription._o = undefined;\n    try {\n      var m = getMethod(observer.error);\n      if (!m) throw value;\n      value = m.call(observer, value);\n    } catch (e) {\n      try {\n        cleanupSubscription(subscription);\n      } finally {\n        throw e;\n      }\n    } cleanupSubscription(subscription);\n    return value;\n  },\n  complete: function complete(value) {\n    var subscription = this._s;\n    if (!subscriptionClosed(subscription)) {\n      var observer = subscription._o;\n      subscription._o = undefined;\n      try {\n        var m = getMethod(observer.complete);\n        value = m ? m.call(observer, value) : undefined;\n      } catch (e) {\n        try {\n          cleanupSubscription(subscription);\n        } finally {\n          throw e;\n        }\n      } cleanupSubscription(subscription);\n      return value;\n    }\n  }\n});\n\nvar $Observable = function Observable(subscriber) {\n  anInstance(this, $Observable, 'Observable', '_f')._f = aFunction(subscriber);\n};\n\nredefineAll($Observable.prototype, {\n  subscribe: function subscribe(observer) {\n    return new Subscription(observer, this._f);\n  },\n  forEach: function forEach(fn) {\n    var that = this;\n    return new (core.Promise || global.Promise)(function (resolve, reject) {\n      aFunction(fn);\n      var subscription = that.subscribe({\n        next: function (value) {\n          try {\n            return fn(value);\n          } catch (e) {\n            reject(e);\n            subscription.unsubscribe();\n          }\n        },\n        error: reject,\n        complete: resolve\n      });\n    });\n  }\n});\n\nredefineAll($Observable, {\n  from: function from(x) {\n    var C = typeof this === 'function' ? this : $Observable;\n    var method = getMethod(anObject(x)[OBSERVABLE]);\n    if (method) {\n      var observable = anObject(method.call(x));\n      return observable.constructor === C ? observable : new C(function (observer) {\n        return observable.subscribe(observer);\n      });\n    }\n    return new C(function (observer) {\n      var done = false;\n      microtask(function () {\n        if (!done) {\n          try {\n            if (forOf(x, false, function (it) {\n              observer.next(it);\n              if (done) return RETURN;\n            }) === RETURN) return;\n          } catch (e) {\n            if (done) throw e;\n            observer.error(e);\n            return;\n          } observer.complete();\n        }\n      });\n      return function () { done = true; };\n    });\n  },\n  of: function of() {\n    for (var i = 0, l = arguments.length, items = new Array(l); i < l;) items[i] = arguments[i++];\n    return new (typeof this === 'function' ? this : $Observable)(function (observer) {\n      var done = false;\n      microtask(function () {\n        if (!done) {\n          for (var j = 0; j < items.length; ++j) {\n            observer.next(items[j]);\n            if (done) return;\n          } observer.complete();\n        }\n      });\n      return function () { done = true; };\n    });\n  }\n});\n\nhide($Observable.prototype, OBSERVABLE, function () { return this; });\n\n$export($export.G, { Observable: $Observable });\n\n__webpack_require__(/*! ./_set-species */ \"./node_modules/core-js/modules/_set-species.js\")('Observable');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.promise.finally.js\":\n/*!*************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.promise.finally.js ***!\n  \\*************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n// https://github.com/tc39/proposal-promise-finally\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar core = __webpack_require__(/*! ./_core */ \"./node_modules/core-js/modules/_core.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar speciesConstructor = __webpack_require__(/*! ./_species-constructor */ \"./node_modules/core-js/modules/_species-constructor.js\");\nvar promiseResolve = __webpack_require__(/*! ./_promise-resolve */ \"./node_modules/core-js/modules/_promise-resolve.js\");\n\n$export($export.P + $export.R, 'Promise', { 'finally': function (onFinally) {\n  var C = speciesConstructor(this, core.Promise || global.Promise);\n  var isFunction = typeof onFinally == 'function';\n  return this.then(\n    isFunction ? function (x) {\n      return promiseResolve(C, onFinally()).then(function () { return x; });\n    } : onFinally,\n    isFunction ? function (e) {\n      return promiseResolve(C, onFinally()).then(function () { throw e; });\n    } : onFinally\n  );\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.promise.try.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.promise.try.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/tc39/proposal-promise-try\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar newPromiseCapability = __webpack_require__(/*! ./_new-promise-capability */ \"./node_modules/core-js/modules/_new-promise-capability.js\");\nvar perform = __webpack_require__(/*! ./_perform */ \"./node_modules/core-js/modules/_perform.js\");\n\n$export($export.S, 'Promise', { 'try': function (callbackfn) {\n  var promiseCapability = newPromiseCapability.f(this);\n  var result = perform(callbackfn);\n  (result.e ? promiseCapability.reject : promiseCapability.resolve)(result.v);\n  return promiseCapability.promise;\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.define-metadata.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.define-metadata.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toMetaKey = metadata.key;\nvar ordinaryDefineOwnMetadata = metadata.set;\n\nmetadata.exp({ defineMetadata: function defineMetadata(metadataKey, metadataValue, target, targetKey) {\n  ordinaryDefineOwnMetadata(metadataKey, metadataValue, anObject(target), toMetaKey(targetKey));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.delete-metadata.js\":\n/*!*********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.delete-metadata.js ***!\n  \\*********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar toMetaKey = metadata.key;\nvar getOrCreateMetadataMap = metadata.map;\nvar store = metadata.store;\n\nmetadata.exp({ deleteMetadata: function deleteMetadata(metadataKey, target /* , targetKey */) {\n  var targetKey = arguments.length < 3 ? undefined : toMetaKey(arguments[2]);\n  var metadataMap = getOrCreateMetadataMap(anObject(target), targetKey, false);\n  if (metadataMap === undefined || !metadataMap['delete'](metadataKey)) return false;\n  if (metadataMap.size) return true;\n  var targetMetadata = store.get(target);\n  targetMetadata['delete'](targetKey);\n  return !!targetMetadata.size || store['delete'](target);\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.get-metadata-keys.js\":\n/*!***********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.get-metadata-keys.js ***!\n  \\***********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar Set = __webpack_require__(/*! ./es6.set */ \"./node_modules/core-js/modules/es6.set.js\");\nvar from = __webpack_require__(/*! ./_array-from-iterable */ \"./node_modules/core-js/modules/_array-from-iterable.js\");\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar ordinaryOwnMetadataKeys = metadata.keys;\nvar toMetaKey = metadata.key;\n\nvar ordinaryMetadataKeys = function (O, P) {\n  var oKeys = ordinaryOwnMetadataKeys(O, P);\n  var parent = getPrototypeOf(O);\n  if (parent === null) return oKeys;\n  var pKeys = ordinaryMetadataKeys(parent, P);\n  return pKeys.length ? oKeys.length ? from(new Set(oKeys.concat(pKeys))) : pKeys : oKeys;\n};\n\nmetadata.exp({ getMetadataKeys: function getMetadataKeys(target /* , targetKey */) {\n  return ordinaryMetadataKeys(anObject(target), arguments.length < 2 ? undefined : toMetaKey(arguments[1]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.get-metadata.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.get-metadata.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar ordinaryHasOwnMetadata = metadata.has;\nvar ordinaryGetOwnMetadata = metadata.get;\nvar toMetaKey = metadata.key;\n\nvar ordinaryGetMetadata = function (MetadataKey, O, P) {\n  var hasOwn = ordinaryHasOwnMetadata(MetadataKey, O, P);\n  if (hasOwn) return ordinaryGetOwnMetadata(MetadataKey, O, P);\n  var parent = getPrototypeOf(O);\n  return parent !== null ? ordinaryGetMetadata(MetadataKey, parent, P) : undefined;\n};\n\nmetadata.exp({ getMetadata: function getMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryGetMetadata(metadataKey, anObject(target), arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.get-own-metadata-keys.js\":\n/*!***************************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.get-own-metadata-keys.js ***!\n  \\***************************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar ordinaryOwnMetadataKeys = metadata.keys;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ getOwnMetadataKeys: function getOwnMetadataKeys(target /* , targetKey */) {\n  return ordinaryOwnMetadataKeys(anObject(target), arguments.length < 2 ? undefined : toMetaKey(arguments[1]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.get-own-metadata.js\":\n/*!**********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.get-own-metadata.js ***!\n  \\**********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar ordinaryGetOwnMetadata = metadata.get;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ getOwnMetadata: function getOwnMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryGetOwnMetadata(metadataKey, anObject(target)\n    , arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.has-metadata.js\":\n/*!******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.has-metadata.js ***!\n  \\******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar getPrototypeOf = __webpack_require__(/*! ./_object-gpo */ \"./node_modules/core-js/modules/_object-gpo.js\");\nvar ordinaryHasOwnMetadata = metadata.has;\nvar toMetaKey = metadata.key;\n\nvar ordinaryHasMetadata = function (MetadataKey, O, P) {\n  var hasOwn = ordinaryHasOwnMetadata(MetadataKey, O, P);\n  if (hasOwn) return true;\n  var parent = getPrototypeOf(O);\n  return parent !== null ? ordinaryHasMetadata(MetadataKey, parent, P) : false;\n};\n\nmetadata.exp({ hasMetadata: function hasMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryHasMetadata(metadataKey, anObject(target), arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.has-own-metadata.js\":\n/*!**********************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.has-own-metadata.js ***!\n  \\**********************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar ordinaryHasOwnMetadata = metadata.has;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ hasOwnMetadata: function hasOwnMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryHasOwnMetadata(metadataKey, anObject(target)\n    , arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.reflect.metadata.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.reflect.metadata.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $metadata = __webpack_require__(/*! ./_metadata */ \"./node_modules/core-js/modules/_metadata.js\");\nvar anObject = __webpack_require__(/*! ./_an-object */ \"./node_modules/core-js/modules/_an-object.js\");\nvar aFunction = __webpack_require__(/*! ./_a-function */ \"./node_modules/core-js/modules/_a-function.js\");\nvar toMetaKey = $metadata.key;\nvar ordinaryDefineOwnMetadata = $metadata.set;\n\n$metadata.exp({ metadata: function metadata(metadataKey, metadataValue) {\n  return function decorator(target, targetKey) {\n    ordinaryDefineOwnMetadata(\n      metadataKey, metadataValue,\n      (targetKey !== undefined ? anObject : aFunction)(target),\n      toMetaKey(targetKey)\n    );\n  };\n} });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.set.from.js\":\n/*!******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.set.from.js ***!\n  \\******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-set.from\n__webpack_require__(/*! ./_set-collection-from */ \"./node_modules/core-js/modules/_set-collection-from.js\")('Set');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.set.of.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.set.of.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-set.of\n__webpack_require__(/*! ./_set-collection-of */ \"./node_modules/core-js/modules/_set-collection-of.js\")('Set');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.set.to-json.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.set.to-json.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.P + $export.R, 'Set', { toJSON: __webpack_require__(/*! ./_collection-to-json */ \"./node_modules/core-js/modules/_collection-to-json.js\")('Set') });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.at.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.at.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/mathiasbynens/String.prototype.at\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $at = __webpack_require__(/*! ./_string-at */ \"./node_modules/core-js/modules/_string-at.js\")(true);\n\n$export($export.P, 'String', {\n  at: function at(pos) {\n    return $at(this, pos);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.match-all.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.match-all.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://tc39.github.io/String.prototype.matchAll/\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar defined = __webpack_require__(/*! ./_defined */ \"./node_modules/core-js/modules/_defined.js\");\nvar toLength = __webpack_require__(/*! ./_to-length */ \"./node_modules/core-js/modules/_to-length.js\");\nvar isRegExp = __webpack_require__(/*! ./_is-regexp */ \"./node_modules/core-js/modules/_is-regexp.js\");\nvar getFlags = __webpack_require__(/*! ./_flags */ \"./node_modules/core-js/modules/_flags.js\");\nvar RegExpProto = RegExp.prototype;\n\nvar $RegExpStringIterator = function (regexp, string) {\n  this._r = regexp;\n  this._s = string;\n};\n\n__webpack_require__(/*! ./_iter-create */ \"./node_modules/core-js/modules/_iter-create.js\")($RegExpStringIterator, 'RegExp String', function next() {\n  var match = this._r.exec(this._s);\n  return { value: match, done: match === null };\n});\n\n$export($export.P, 'String', {\n  matchAll: function matchAll(regexp) {\n    defined(this);\n    if (!isRegExp(regexp)) throw TypeError(regexp + ' is not a regexp!');\n    var S = String(this);\n    var flags = 'flags' in RegExpProto ? String(regexp.flags) : getFlags.call(regexp);\n    var rx = new RegExp(regexp.source, ~flags.indexOf('g') ? flags : 'g' + flags);\n    rx.lastIndex = toLength(regexp.lastIndex);\n    return new $RegExpStringIterator(rx, S);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.pad-end.js\":\n/*!************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.pad-end.js ***!\n  \\************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/tc39/proposal-string-pad-start-end\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $pad = __webpack_require__(/*! ./_string-pad */ \"./node_modules/core-js/modules/_string-pad.js\");\nvar userAgent = __webpack_require__(/*! ./_user-agent */ \"./node_modules/core-js/modules/_user-agent.js\");\n\n// https://github.com/zloirock/core-js/issues/280\n$export($export.P + $export.F * /Version\\/10\\.\\d+(\\.\\d+)? Safari\\//.test(userAgent), 'String', {\n  padEnd: function padEnd(maxLength /* , fillString = ' ' */) {\n    return $pad(this, maxLength, arguments.length > 1 ? arguments[1] : undefined, false);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.pad-start.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.pad-start.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/tc39/proposal-string-pad-start-end\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $pad = __webpack_require__(/*! ./_string-pad */ \"./node_modules/core-js/modules/_string-pad.js\");\nvar userAgent = __webpack_require__(/*! ./_user-agent */ \"./node_modules/core-js/modules/_user-agent.js\");\n\n// https://github.com/zloirock/core-js/issues/280\n$export($export.P + $export.F * /Version\\/10\\.\\d+(\\.\\d+)? Safari\\//.test(userAgent), 'String', {\n  padStart: function padStart(maxLength /* , fillString = ' ' */) {\n    return $pad(this, maxLength, arguments.length > 1 ? arguments[1] : undefined, true);\n  }\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.trim-left.js\":\n/*!**************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.trim-left.js ***!\n  \\**************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/sebmarkbage/ecmascript-string-left-right-trim\n__webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\")('trimLeft', function ($trim) {\n  return function trimLeft() {\n    return $trim(this, 1);\n  };\n}, 'trimStart');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.string.trim-right.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.string.trim-right.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n// https://github.com/sebmarkbage/ecmascript-string-left-right-trim\n__webpack_require__(/*! ./_string-trim */ \"./node_modules/core-js/modules/_string-trim.js\")('trimRight', function ($trim) {\n  return function trimRight() {\n    return $trim(this, 2);\n  };\n}, 'trimEnd');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.symbol.async-iterator.js\":\n/*!*******************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.symbol.async-iterator.js ***!\n  \\*******************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_wks-define */ \"./node_modules/core-js/modules/_wks-define.js\")('asyncIterator');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.symbol.observable.js\":\n/*!***************************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.symbol.observable.js ***!\n  \\***************************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./_wks-define */ \"./node_modules/core-js/modules/_wks-define.js\")('observable');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.system.global.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.system.global.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://github.com/tc39/proposal-global\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\n\n$export($export.S, 'System', { global: __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\") });\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.weak-map.from.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.weak-map.from.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-weakmap.from\n__webpack_require__(/*! ./_set-collection-from */ \"./node_modules/core-js/modules/_set-collection-from.js\")('WeakMap');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.weak-map.of.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.weak-map.of.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-weakmap.of\n__webpack_require__(/*! ./_set-collection-of */ \"./node_modules/core-js/modules/_set-collection-of.js\")('WeakMap');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.weak-set.from.js\":\n/*!***********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.weak-set.from.js ***!\n  \\***********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-weakset.from\n__webpack_require__(/*! ./_set-collection-from */ \"./node_modules/core-js/modules/_set-collection-from.js\")('WeakSet');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/es7.weak-set.of.js\":\n/*!*********************************************************!*\\\n  !*** ./node_modules/core-js/modules/es7.weak-set.of.js ***!\n  \\*********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// https://tc39.github.io/proposal-setmap-offrom/#sec-weakset.of\n__webpack_require__(/*! ./_set-collection-of */ \"./node_modules/core-js/modules/_set-collection-of.js\")('WeakSet');\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/web.dom.iterable.js\":\n/*!**********************************************************!*\\\n  !*** ./node_modules/core-js/modules/web.dom.iterable.js ***!\n  \\**********************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $iterators = __webpack_require__(/*! ./es6.array.iterator */ \"./node_modules/core-js/modules/es6.array.iterator.js\");\nvar getKeys = __webpack_require__(/*! ./_object-keys */ \"./node_modules/core-js/modules/_object-keys.js\");\nvar redefine = __webpack_require__(/*! ./_redefine */ \"./node_modules/core-js/modules/_redefine.js\");\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar hide = __webpack_require__(/*! ./_hide */ \"./node_modules/core-js/modules/_hide.js\");\nvar Iterators = __webpack_require__(/*! ./_iterators */ \"./node_modules/core-js/modules/_iterators.js\");\nvar wks = __webpack_require__(/*! ./_wks */ \"./node_modules/core-js/modules/_wks.js\");\nvar ITERATOR = wks('iterator');\nvar TO_STRING_TAG = wks('toStringTag');\nvar ArrayValues = Iterators.Array;\n\nvar DOMIterables = {\n  CSSRuleList: true, // TODO: Not spec compliant, should be false.\n  CSSStyleDeclaration: false,\n  CSSValueList: false,\n  ClientRectList: false,\n  DOMRectList: false,\n  DOMStringList: false,\n  DOMTokenList: true,\n  DataTransferItemList: false,\n  FileList: false,\n  HTMLAllCollection: false,\n  HTMLCollection: false,\n  HTMLFormElement: false,\n  HTMLSelectElement: false,\n  MediaList: true, // TODO: Not spec compliant, should be false.\n  MimeTypeArray: false,\n  NamedNodeMap: false,\n  NodeList: true,\n  PaintRequestList: false,\n  Plugin: false,\n  PluginArray: false,\n  SVGLengthList: false,\n  SVGNumberList: false,\n  SVGPathSegList: false,\n  SVGPointList: false,\n  SVGStringList: false,\n  SVGTransformList: false,\n  SourceBufferList: false,\n  StyleSheetList: true, // TODO: Not spec compliant, should be false.\n  TextTrackCueList: false,\n  TextTrackList: false,\n  TouchList: false\n};\n\nfor (var collections = getKeys(DOMIterables), i = 0; i < collections.length; i++) {\n  var NAME = collections[i];\n  var explicit = DOMIterables[NAME];\n  var Collection = global[NAME];\n  var proto = Collection && Collection.prototype;\n  var key;\n  if (proto) {\n    if (!proto[ITERATOR]) hide(proto, ITERATOR, ArrayValues);\n    if (!proto[TO_STRING_TAG]) hide(proto, TO_STRING_TAG, NAME);\n    Iterators[NAME] = ArrayValues;\n    if (explicit) for (key in $iterators) if (!proto[key]) redefine(proto, key, $iterators[key], true);\n  }\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/web.immediate.js\":\n/*!*******************************************************!*\\\n  !*** ./node_modules/core-js/modules/web.immediate.js ***!\n  \\*******************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar $task = __webpack_require__(/*! ./_task */ \"./node_modules/core-js/modules/_task.js\");\n$export($export.G + $export.B, {\n  setImmediate: $task.set,\n  clearImmediate: $task.clear\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/modules/web.timers.js\":\n/*!****************************************************!*\\\n  !*** ./node_modules/core-js/modules/web.timers.js ***!\n  \\****************************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n// ie9- setTimeout & setInterval additional parameters fix\nvar global = __webpack_require__(/*! ./_global */ \"./node_modules/core-js/modules/_global.js\");\nvar $export = __webpack_require__(/*! ./_export */ \"./node_modules/core-js/modules/_export.js\");\nvar userAgent = __webpack_require__(/*! ./_user-agent */ \"./node_modules/core-js/modules/_user-agent.js\");\nvar slice = [].slice;\nvar MSIE = /MSIE .\\./.test(userAgent); // <- dirty ie9- check\nvar wrap = function (set) {\n  return function (fn, time /* , ...args */) {\n    var boundArgs = arguments.length > 2;\n    var args = boundArgs ? slice.call(arguments, 2) : false;\n    return set(boundArgs ? function () {\n      // eslint-disable-next-line no-new-func\n      (typeof fn == 'function' ? fn : Function(fn)).apply(this, args);\n    } : fn, time);\n  };\n};\n$export($export.G + $export.B + $export.F * MSIE, {\n  setTimeout: wrap(global.setTimeout),\n  setInterval: wrap(global.setInterval)\n});\n\n\n/***/ }),\n\n/***/ \"./node_modules/core-js/shim.js\":\n/*!**************************************!*\\\n  !*** ./node_modules/core-js/shim.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! ./modules/es6.symbol */ \"./node_modules/core-js/modules/es6.symbol.js\");\n__webpack_require__(/*! ./modules/es6.object.create */ \"./node_modules/core-js/modules/es6.object.create.js\");\n__webpack_require__(/*! ./modules/es6.object.define-property */ \"./node_modules/core-js/modules/es6.object.define-property.js\");\n__webpack_require__(/*! ./modules/es6.object.define-properties */ \"./node_modules/core-js/modules/es6.object.define-properties.js\");\n__webpack_require__(/*! ./modules/es6.object.get-own-property-descriptor */ \"./node_modules/core-js/modules/es6.object.get-own-property-descriptor.js\");\n__webpack_require__(/*! ./modules/es6.object.get-prototype-of */ \"./node_modules/core-js/modules/es6.object.get-prototype-of.js\");\n__webpack_require__(/*! ./modules/es6.object.keys */ \"./node_modules/core-js/modules/es6.object.keys.js\");\n__webpack_require__(/*! ./modules/es6.object.get-own-property-names */ \"./node_modules/core-js/modules/es6.object.get-own-property-names.js\");\n__webpack_require__(/*! ./modules/es6.object.freeze */ \"./node_modules/core-js/modules/es6.object.freeze.js\");\n__webpack_require__(/*! ./modules/es6.object.seal */ \"./node_modules/core-js/modules/es6.object.seal.js\");\n__webpack_require__(/*! ./modules/es6.object.prevent-extensions */ \"./node_modules/core-js/modules/es6.object.prevent-extensions.js\");\n__webpack_require__(/*! ./modules/es6.object.is-frozen */ \"./node_modules/core-js/modules/es6.object.is-frozen.js\");\n__webpack_require__(/*! ./modules/es6.object.is-sealed */ \"./node_modules/core-js/modules/es6.object.is-sealed.js\");\n__webpack_require__(/*! ./modules/es6.object.is-extensible */ \"./node_modules/core-js/modules/es6.object.is-extensible.js\");\n__webpack_require__(/*! ./modules/es6.object.assign */ \"./node_modules/core-js/modules/es6.object.assign.js\");\n__webpack_require__(/*! ./modules/es6.object.is */ \"./node_modules/core-js/modules/es6.object.is.js\");\n__webpack_require__(/*! ./modules/es6.object.set-prototype-of */ \"./node_modules/core-js/modules/es6.object.set-prototype-of.js\");\n__webpack_require__(/*! ./modules/es6.object.to-string */ \"./node_modules/core-js/modules/es6.object.to-string.js\");\n__webpack_require__(/*! ./modules/es6.function.bind */ \"./node_modules/core-js/modules/es6.function.bind.js\");\n__webpack_require__(/*! ./modules/es6.function.name */ \"./node_modules/core-js/modules/es6.function.name.js\");\n__webpack_require__(/*! ./modules/es6.function.has-instance */ \"./node_modules/core-js/modules/es6.function.has-instance.js\");\n__webpack_require__(/*! ./modules/es6.parse-int */ \"./node_modules/core-js/modules/es6.parse-int.js\");\n__webpack_require__(/*! ./modules/es6.parse-float */ \"./node_modules/core-js/modules/es6.parse-float.js\");\n__webpack_require__(/*! ./modules/es6.number.constructor */ \"./node_modules/core-js/modules/es6.number.constructor.js\");\n__webpack_require__(/*! ./modules/es6.number.to-fixed */ \"./node_modules/core-js/modules/es6.number.to-fixed.js\");\n__webpack_require__(/*! ./modules/es6.number.to-precision */ \"./node_modules/core-js/modules/es6.number.to-precision.js\");\n__webpack_require__(/*! ./modules/es6.number.epsilon */ \"./node_modules/core-js/modules/es6.number.epsilon.js\");\n__webpack_require__(/*! ./modules/es6.number.is-finite */ \"./node_modules/core-js/modules/es6.number.is-finite.js\");\n__webpack_require__(/*! ./modules/es6.number.is-integer */ \"./node_modules/core-js/modules/es6.number.is-integer.js\");\n__webpack_require__(/*! ./modules/es6.number.is-nan */ \"./node_modules/core-js/modules/es6.number.is-nan.js\");\n__webpack_require__(/*! ./modules/es6.number.is-safe-integer */ \"./node_modules/core-js/modules/es6.number.is-safe-integer.js\");\n__webpack_require__(/*! ./modules/es6.number.max-safe-integer */ \"./node_modules/core-js/modules/es6.number.max-safe-integer.js\");\n__webpack_require__(/*! ./modules/es6.number.min-safe-integer */ \"./node_modules/core-js/modules/es6.number.min-safe-integer.js\");\n__webpack_require__(/*! ./modules/es6.number.parse-float */ \"./node_modules/core-js/modules/es6.number.parse-float.js\");\n__webpack_require__(/*! ./modules/es6.number.parse-int */ \"./node_modules/core-js/modules/es6.number.parse-int.js\");\n__webpack_require__(/*! ./modules/es6.math.acosh */ \"./node_modules/core-js/modules/es6.math.acosh.js\");\n__webpack_require__(/*! ./modules/es6.math.asinh */ \"./node_modules/core-js/modules/es6.math.asinh.js\");\n__webpack_require__(/*! ./modules/es6.math.atanh */ \"./node_modules/core-js/modules/es6.math.atanh.js\");\n__webpack_require__(/*! ./modules/es6.math.cbrt */ \"./node_modules/core-js/modules/es6.math.cbrt.js\");\n__webpack_require__(/*! ./modules/es6.math.clz32 */ \"./node_modules/core-js/modules/es6.math.clz32.js\");\n__webpack_require__(/*! ./modules/es6.math.cosh */ \"./node_modules/core-js/modules/es6.math.cosh.js\");\n__webpack_require__(/*! ./modules/es6.math.expm1 */ \"./node_modules/core-js/modules/es6.math.expm1.js\");\n__webpack_require__(/*! ./modules/es6.math.fround */ \"./node_modules/core-js/modules/es6.math.fround.js\");\n__webpack_require__(/*! ./modules/es6.math.hypot */ \"./node_modules/core-js/modules/es6.math.hypot.js\");\n__webpack_require__(/*! ./modules/es6.math.imul */ \"./node_modules/core-js/modules/es6.math.imul.js\");\n__webpack_require__(/*! ./modules/es6.math.log10 */ \"./node_modules/core-js/modules/es6.math.log10.js\");\n__webpack_require__(/*! ./modules/es6.math.log1p */ \"./node_modules/core-js/modules/es6.math.log1p.js\");\n__webpack_require__(/*! ./modules/es6.math.log2 */ \"./node_modules/core-js/modules/es6.math.log2.js\");\n__webpack_require__(/*! ./modules/es6.math.sign */ \"./node_modules/core-js/modules/es6.math.sign.js\");\n__webpack_require__(/*! ./modules/es6.math.sinh */ \"./node_modules/core-js/modules/es6.math.sinh.js\");\n__webpack_require__(/*! ./modules/es6.math.tanh */ \"./node_modules/core-js/modules/es6.math.tanh.js\");\n__webpack_require__(/*! ./modules/es6.math.trunc */ \"./node_modules/core-js/modules/es6.math.trunc.js\");\n__webpack_require__(/*! ./modules/es6.string.from-code-point */ \"./node_modules/core-js/modules/es6.string.from-code-point.js\");\n__webpack_require__(/*! ./modules/es6.string.raw */ \"./node_modules/core-js/modules/es6.string.raw.js\");\n__webpack_require__(/*! ./modules/es6.string.trim */ \"./node_modules/core-js/modules/es6.string.trim.js\");\n__webpack_require__(/*! ./modules/es6.string.iterator */ \"./node_modules/core-js/modules/es6.string.iterator.js\");\n__webpack_require__(/*! ./modules/es6.string.code-point-at */ \"./node_modules/core-js/modules/es6.string.code-point-at.js\");\n__webpack_require__(/*! ./modules/es6.string.ends-with */ \"./node_modules/core-js/modules/es6.string.ends-with.js\");\n__webpack_require__(/*! ./modules/es6.string.includes */ \"./node_modules/core-js/modules/es6.string.includes.js\");\n__webpack_require__(/*! ./modules/es6.string.repeat */ \"./node_modules/core-js/modules/es6.string.repeat.js\");\n__webpack_require__(/*! ./modules/es6.string.starts-with */ \"./node_modules/core-js/modules/es6.string.starts-with.js\");\n__webpack_require__(/*! ./modules/es6.string.anchor */ \"./node_modules/core-js/modules/es6.string.anchor.js\");\n__webpack_require__(/*! ./modules/es6.string.big */ \"./node_modules/core-js/modules/es6.string.big.js\");\n__webpack_require__(/*! ./modules/es6.string.blink */ \"./node_modules/core-js/modules/es6.string.blink.js\");\n__webpack_require__(/*! ./modules/es6.string.bold */ \"./node_modules/core-js/modules/es6.string.bold.js\");\n__webpack_require__(/*! ./modules/es6.string.fixed */ \"./node_modules/core-js/modules/es6.string.fixed.js\");\n__webpack_require__(/*! ./modules/es6.string.fontcolor */ \"./node_modules/core-js/modules/es6.string.fontcolor.js\");\n__webpack_require__(/*! ./modules/es6.string.fontsize */ \"./node_modules/core-js/modules/es6.string.fontsize.js\");\n__webpack_require__(/*! ./modules/es6.string.italics */ \"./node_modules/core-js/modules/es6.string.italics.js\");\n__webpack_require__(/*! ./modules/es6.string.link */ \"./node_modules/core-js/modules/es6.string.link.js\");\n__webpack_require__(/*! ./modules/es6.string.small */ \"./node_modules/core-js/modules/es6.string.small.js\");\n__webpack_require__(/*! ./modules/es6.string.strike */ \"./node_modules/core-js/modules/es6.string.strike.js\");\n__webpack_require__(/*! ./modules/es6.string.sub */ \"./node_modules/core-js/modules/es6.string.sub.js\");\n__webpack_require__(/*! ./modules/es6.string.sup */ \"./node_modules/core-js/modules/es6.string.sup.js\");\n__webpack_require__(/*! ./modules/es6.date.now */ \"./node_modules/core-js/modules/es6.date.now.js\");\n__webpack_require__(/*! ./modules/es6.date.to-json */ \"./node_modules/core-js/modules/es6.date.to-json.js\");\n__webpack_require__(/*! ./modules/es6.date.to-iso-string */ \"./node_modules/core-js/modules/es6.date.to-iso-string.js\");\n__webpack_require__(/*! ./modules/es6.date.to-string */ \"./node_modules/core-js/modules/es6.date.to-string.js\");\n__webpack_require__(/*! ./modules/es6.date.to-primitive */ \"./node_modules/core-js/modules/es6.date.to-primitive.js\");\n__webpack_require__(/*! ./modules/es6.array.is-array */ \"./node_modules/core-js/modules/es6.array.is-array.js\");\n__webpack_require__(/*! ./modules/es6.array.from */ \"./node_modules/core-js/modules/es6.array.from.js\");\n__webpack_require__(/*! ./modules/es6.array.of */ \"./node_modules/core-js/modules/es6.array.of.js\");\n__webpack_require__(/*! ./modules/es6.array.join */ \"./node_modules/core-js/modules/es6.array.join.js\");\n__webpack_require__(/*! ./modules/es6.array.slice */ \"./node_modules/core-js/modules/es6.array.slice.js\");\n__webpack_require__(/*! ./modules/es6.array.sort */ \"./node_modules/core-js/modules/es6.array.sort.js\");\n__webpack_require__(/*! ./modules/es6.array.for-each */ \"./node_modules/core-js/modules/es6.array.for-each.js\");\n__webpack_require__(/*! ./modules/es6.array.map */ \"./node_modules/core-js/modules/es6.array.map.js\");\n__webpack_require__(/*! ./modules/es6.array.filter */ \"./node_modules/core-js/modules/es6.array.filter.js\");\n__webpack_require__(/*! ./modules/es6.array.some */ \"./node_modules/core-js/modules/es6.array.some.js\");\n__webpack_require__(/*! ./modules/es6.array.every */ \"./node_modules/core-js/modules/es6.array.every.js\");\n__webpack_require__(/*! ./modules/es6.array.reduce */ \"./node_modules/core-js/modules/es6.array.reduce.js\");\n__webpack_require__(/*! ./modules/es6.array.reduce-right */ \"./node_modules/core-js/modules/es6.array.reduce-right.js\");\n__webpack_require__(/*! ./modules/es6.array.index-of */ \"./node_modules/core-js/modules/es6.array.index-of.js\");\n__webpack_require__(/*! ./modules/es6.array.last-index-of */ \"./node_modules/core-js/modules/es6.array.last-index-of.js\");\n__webpack_require__(/*! ./modules/es6.array.copy-within */ \"./node_modules/core-js/modules/es6.array.copy-within.js\");\n__webpack_require__(/*! ./modules/es6.array.fill */ \"./node_modules/core-js/modules/es6.array.fill.js\");\n__webpack_require__(/*! ./modules/es6.array.find */ \"./node_modules/core-js/modules/es6.array.find.js\");\n__webpack_require__(/*! ./modules/es6.array.find-index */ \"./node_modules/core-js/modules/es6.array.find-index.js\");\n__webpack_require__(/*! ./modules/es6.array.species */ \"./node_modules/core-js/modules/es6.array.species.js\");\n__webpack_require__(/*! ./modules/es6.array.iterator */ \"./node_modules/core-js/modules/es6.array.iterator.js\");\n__webpack_require__(/*! ./modules/es6.regexp.constructor */ \"./node_modules/core-js/modules/es6.regexp.constructor.js\");\n__webpack_require__(/*! ./modules/es6.regexp.exec */ \"./node_modules/core-js/modules/es6.regexp.exec.js\");\n__webpack_require__(/*! ./modules/es6.regexp.to-string */ \"./node_modules/core-js/modules/es6.regexp.to-string.js\");\n__webpack_require__(/*! ./modules/es6.regexp.flags */ \"./node_modules/core-js/modules/es6.regexp.flags.js\");\n__webpack_require__(/*! ./modules/es6.regexp.match */ \"./node_modules/core-js/modules/es6.regexp.match.js\");\n__webpack_require__(/*! ./modules/es6.regexp.replace */ \"./node_modules/core-js/modules/es6.regexp.replace.js\");\n__webpack_require__(/*! ./modules/es6.regexp.search */ \"./node_modules/core-js/modules/es6.regexp.search.js\");\n__webpack_require__(/*! ./modules/es6.regexp.split */ \"./node_modules/core-js/modules/es6.regexp.split.js\");\n__webpack_require__(/*! ./modules/es6.promise */ \"./node_modules/core-js/modules/es6.promise.js\");\n__webpack_require__(/*! ./modules/es6.map */ \"./node_modules/core-js/modules/es6.map.js\");\n__webpack_require__(/*! ./modules/es6.set */ \"./node_modules/core-js/modules/es6.set.js\");\n__webpack_require__(/*! ./modules/es6.weak-map */ \"./node_modules/core-js/modules/es6.weak-map.js\");\n__webpack_require__(/*! ./modules/es6.weak-set */ \"./node_modules/core-js/modules/es6.weak-set.js\");\n__webpack_require__(/*! ./modules/es6.typed.array-buffer */ \"./node_modules/core-js/modules/es6.typed.array-buffer.js\");\n__webpack_require__(/*! ./modules/es6.typed.data-view */ \"./node_modules/core-js/modules/es6.typed.data-view.js\");\n__webpack_require__(/*! ./modules/es6.typed.int8-array */ \"./node_modules/core-js/modules/es6.typed.int8-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.uint8-array */ \"./node_modules/core-js/modules/es6.typed.uint8-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.uint8-clamped-array */ \"./node_modules/core-js/modules/es6.typed.uint8-clamped-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.int16-array */ \"./node_modules/core-js/modules/es6.typed.int16-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.uint16-array */ \"./node_modules/core-js/modules/es6.typed.uint16-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.int32-array */ \"./node_modules/core-js/modules/es6.typed.int32-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.uint32-array */ \"./node_modules/core-js/modules/es6.typed.uint32-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.float32-array */ \"./node_modules/core-js/modules/es6.typed.float32-array.js\");\n__webpack_require__(/*! ./modules/es6.typed.float64-array */ \"./node_modules/core-js/modules/es6.typed.float64-array.js\");\n__webpack_require__(/*! ./modules/es6.reflect.apply */ \"./node_modules/core-js/modules/es6.reflect.apply.js\");\n__webpack_require__(/*! ./modules/es6.reflect.construct */ \"./node_modules/core-js/modules/es6.reflect.construct.js\");\n__webpack_require__(/*! ./modules/es6.reflect.define-property */ \"./node_modules/core-js/modules/es6.reflect.define-property.js\");\n__webpack_require__(/*! ./modules/es6.reflect.delete-property */ \"./node_modules/core-js/modules/es6.reflect.delete-property.js\");\n__webpack_require__(/*! ./modules/es6.reflect.enumerate */ \"./node_modules/core-js/modules/es6.reflect.enumerate.js\");\n__webpack_require__(/*! ./modules/es6.reflect.get */ \"./node_modules/core-js/modules/es6.reflect.get.js\");\n__webpack_require__(/*! ./modules/es6.reflect.get-own-property-descriptor */ \"./node_modules/core-js/modules/es6.reflect.get-own-property-descriptor.js\");\n__webpack_require__(/*! ./modules/es6.reflect.get-prototype-of */ \"./node_modules/core-js/modules/es6.reflect.get-prototype-of.js\");\n__webpack_require__(/*! ./modules/es6.reflect.has */ \"./node_modules/core-js/modules/es6.reflect.has.js\");\n__webpack_require__(/*! ./modules/es6.reflect.is-extensible */ \"./node_modules/core-js/modules/es6.reflect.is-extensible.js\");\n__webpack_require__(/*! ./modules/es6.reflect.own-keys */ \"./node_modules/core-js/modules/es6.reflect.own-keys.js\");\n__webpack_require__(/*! ./modules/es6.reflect.prevent-extensions */ \"./node_modules/core-js/modules/es6.reflect.prevent-extensions.js\");\n__webpack_require__(/*! ./modules/es6.reflect.set */ \"./node_modules/core-js/modules/es6.reflect.set.js\");\n__webpack_require__(/*! ./modules/es6.reflect.set-prototype-of */ \"./node_modules/core-js/modules/es6.reflect.set-prototype-of.js\");\n__webpack_require__(/*! ./modules/es7.array.includes */ \"./node_modules/core-js/modules/es7.array.includes.js\");\n__webpack_require__(/*! ./modules/es7.array.flat-map */ \"./node_modules/core-js/modules/es7.array.flat-map.js\");\n__webpack_require__(/*! ./modules/es7.array.flatten */ \"./node_modules/core-js/modules/es7.array.flatten.js\");\n__webpack_require__(/*! ./modules/es7.string.at */ \"./node_modules/core-js/modules/es7.string.at.js\");\n__webpack_require__(/*! ./modules/es7.string.pad-start */ \"./node_modules/core-js/modules/es7.string.pad-start.js\");\n__webpack_require__(/*! ./modules/es7.string.pad-end */ \"./node_modules/core-js/modules/es7.string.pad-end.js\");\n__webpack_require__(/*! ./modules/es7.string.trim-left */ \"./node_modules/core-js/modules/es7.string.trim-left.js\");\n__webpack_require__(/*! ./modules/es7.string.trim-right */ \"./node_modules/core-js/modules/es7.string.trim-right.js\");\n__webpack_require__(/*! ./modules/es7.string.match-all */ \"./node_modules/core-js/modules/es7.string.match-all.js\");\n__webpack_require__(/*! ./modules/es7.symbol.async-iterator */ \"./node_modules/core-js/modules/es7.symbol.async-iterator.js\");\n__webpack_require__(/*! ./modules/es7.symbol.observable */ \"./node_modules/core-js/modules/es7.symbol.observable.js\");\n__webpack_require__(/*! ./modules/es7.object.get-own-property-descriptors */ \"./node_modules/core-js/modules/es7.object.get-own-property-descriptors.js\");\n__webpack_require__(/*! ./modules/es7.object.values */ \"./node_modules/core-js/modules/es7.object.values.js\");\n__webpack_require__(/*! ./modules/es7.object.entries */ \"./node_modules/core-js/modules/es7.object.entries.js\");\n__webpack_require__(/*! ./modules/es7.object.define-getter */ \"./node_modules/core-js/modules/es7.object.define-getter.js\");\n__webpack_require__(/*! ./modules/es7.object.define-setter */ \"./node_modules/core-js/modules/es7.object.define-setter.js\");\n__webpack_require__(/*! ./modules/es7.object.lookup-getter */ \"./node_modules/core-js/modules/es7.object.lookup-getter.js\");\n__webpack_require__(/*! ./modules/es7.object.lookup-setter */ \"./node_modules/core-js/modules/es7.object.lookup-setter.js\");\n__webpack_require__(/*! ./modules/es7.map.to-json */ \"./node_modules/core-js/modules/es7.map.to-json.js\");\n__webpack_require__(/*! ./modules/es7.set.to-json */ \"./node_modules/core-js/modules/es7.set.to-json.js\");\n__webpack_require__(/*! ./modules/es7.map.of */ \"./node_modules/core-js/modules/es7.map.of.js\");\n__webpack_require__(/*! ./modules/es7.set.of */ \"./node_modules/core-js/modules/es7.set.of.js\");\n__webpack_require__(/*! ./modules/es7.weak-map.of */ \"./node_modules/core-js/modules/es7.weak-map.of.js\");\n__webpack_require__(/*! ./modules/es7.weak-set.of */ \"./node_modules/core-js/modules/es7.weak-set.of.js\");\n__webpack_require__(/*! ./modules/es7.map.from */ \"./node_modules/core-js/modules/es7.map.from.js\");\n__webpack_require__(/*! ./modules/es7.set.from */ \"./node_modules/core-js/modules/es7.set.from.js\");\n__webpack_require__(/*! ./modules/es7.weak-map.from */ \"./node_modules/core-js/modules/es7.weak-map.from.js\");\n__webpack_require__(/*! ./modules/es7.weak-set.from */ \"./node_modules/core-js/modules/es7.weak-set.from.js\");\n__webpack_require__(/*! ./modules/es7.global */ \"./node_modules/core-js/modules/es7.global.js\");\n__webpack_require__(/*! ./modules/es7.system.global */ \"./node_modules/core-js/modules/es7.system.global.js\");\n__webpack_require__(/*! ./modules/es7.error.is-error */ \"./node_modules/core-js/modules/es7.error.is-error.js\");\n__webpack_require__(/*! ./modules/es7.math.clamp */ \"./node_modules/core-js/modules/es7.math.clamp.js\");\n__webpack_require__(/*! ./modules/es7.math.deg-per-rad */ \"./node_modules/core-js/modules/es7.math.deg-per-rad.js\");\n__webpack_require__(/*! ./modules/es7.math.degrees */ \"./node_modules/core-js/modules/es7.math.degrees.js\");\n__webpack_require__(/*! ./modules/es7.math.fscale */ \"./node_modules/core-js/modules/es7.math.fscale.js\");\n__webpack_require__(/*! ./modules/es7.math.iaddh */ \"./node_modules/core-js/modules/es7.math.iaddh.js\");\n__webpack_require__(/*! ./modules/es7.math.isubh */ \"./node_modules/core-js/modules/es7.math.isubh.js\");\n__webpack_require__(/*! ./modules/es7.math.imulh */ \"./node_modules/core-js/modules/es7.math.imulh.js\");\n__webpack_require__(/*! ./modules/es7.math.rad-per-deg */ \"./node_modules/core-js/modules/es7.math.rad-per-deg.js\");\n__webpack_require__(/*! ./modules/es7.math.radians */ \"./node_modules/core-js/modules/es7.math.radians.js\");\n__webpack_require__(/*! ./modules/es7.math.scale */ \"./node_modules/core-js/modules/es7.math.scale.js\");\n__webpack_require__(/*! ./modules/es7.math.umulh */ \"./node_modules/core-js/modules/es7.math.umulh.js\");\n__webpack_require__(/*! ./modules/es7.math.signbit */ \"./node_modules/core-js/modules/es7.math.signbit.js\");\n__webpack_require__(/*! ./modules/es7.promise.finally */ \"./node_modules/core-js/modules/es7.promise.finally.js\");\n__webpack_require__(/*! ./modules/es7.promise.try */ \"./node_modules/core-js/modules/es7.promise.try.js\");\n__webpack_require__(/*! ./modules/es7.reflect.define-metadata */ \"./node_modules/core-js/modules/es7.reflect.define-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.delete-metadata */ \"./node_modules/core-js/modules/es7.reflect.delete-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.get-metadata */ \"./node_modules/core-js/modules/es7.reflect.get-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.get-metadata-keys */ \"./node_modules/core-js/modules/es7.reflect.get-metadata-keys.js\");\n__webpack_require__(/*! ./modules/es7.reflect.get-own-metadata */ \"./node_modules/core-js/modules/es7.reflect.get-own-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.get-own-metadata-keys */ \"./node_modules/core-js/modules/es7.reflect.get-own-metadata-keys.js\");\n__webpack_require__(/*! ./modules/es7.reflect.has-metadata */ \"./node_modules/core-js/modules/es7.reflect.has-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.has-own-metadata */ \"./node_modules/core-js/modules/es7.reflect.has-own-metadata.js\");\n__webpack_require__(/*! ./modules/es7.reflect.metadata */ \"./node_modules/core-js/modules/es7.reflect.metadata.js\");\n__webpack_require__(/*! ./modules/es7.asap */ \"./node_modules/core-js/modules/es7.asap.js\");\n__webpack_require__(/*! ./modules/es7.observable */ \"./node_modules/core-js/modules/es7.observable.js\");\n__webpack_require__(/*! ./modules/web.timers */ \"./node_modules/core-js/modules/web.timers.js\");\n__webpack_require__(/*! ./modules/web.immediate */ \"./node_modules/core-js/modules/web.immediate.js\");\n__webpack_require__(/*! ./modules/web.dom.iterable */ \"./node_modules/core-js/modules/web.dom.iterable.js\");\nmodule.exports = __webpack_require__(/*! ./modules/_core */ \"./node_modules/core-js/modules/_core.js\");\n\n\n/***/ }),\n\n/***/ \"./node_modules/ieee754/index.js\":\n/*!***************************************!*\\\n  !*** ./node_modules/ieee754/index.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nexports.read = function (buffer, offset, isLE, mLen, nBytes) {\n  var e, m\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var nBits = -7\n  var i = isLE ? (nBytes - 1) : 0\n  var d = isLE ? -1 : 1\n  var s = buffer[offset + i]\n\n  i += d\n\n  e = s & ((1 << (-nBits)) - 1)\n  s >>= (-nBits)\n  nBits += eLen\n  for (; nBits > 0; e = (e * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  m = e & ((1 << (-nBits)) - 1)\n  e >>= (-nBits)\n  nBits += mLen\n  for (; nBits > 0; m = (m * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  if (e === 0) {\n    e = 1 - eBias\n  } else if (e === eMax) {\n    return m ? NaN : ((s ? -1 : 1) * Infinity)\n  } else {\n    m = m + Math.pow(2, mLen)\n    e = e - eBias\n  }\n  return (s ? -1 : 1) * m * Math.pow(2, e - mLen)\n}\n\nexports.write = function (buffer, value, offset, isLE, mLen, nBytes) {\n  var e, m, c\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var rt = (mLen === 23 ? Math.pow(2, -24) - Math.pow(2, -77) : 0)\n  var i = isLE ? 0 : (nBytes - 1)\n  var d = isLE ? 1 : -1\n  var s = value < 0 || (value === 0 && 1 / value < 0) ? 1 : 0\n\n  value = Math.abs(value)\n\n  if (isNaN(value) || value === Infinity) {\n    m = isNaN(value) ? 1 : 0\n    e = eMax\n  } else {\n    e = Math.floor(Math.log(value) / Math.LN2)\n    if (value * (c = Math.pow(2, -e)) < 1) {\n      e--\n      c *= 2\n    }\n    if (e + eBias >= 1) {\n      value += rt / c\n    } else {\n      value += rt * Math.pow(2, 1 - eBias)\n    }\n    if (value * c >= 2) {\n      e++\n      c /= 2\n    }\n\n    if (e + eBias >= eMax) {\n      m = 0\n      e = eMax\n    } else if (e + eBias >= 1) {\n      m = ((value * c) - 1) * Math.pow(2, mLen)\n      e = e + eBias\n    } else {\n      m = value * Math.pow(2, eBias - 1) * Math.pow(2, mLen)\n      e = 0\n    }\n  }\n\n  for (; mLen >= 8; buffer[offset + i] = m & 0xff, i += d, m /= 256, mLen -= 8) {}\n\n  e = (e << mLen) | m\n  eLen += mLen\n  for (; eLen > 0; buffer[offset + i] = e & 0xff, i += d, e /= 256, eLen -= 8) {}\n\n  buffer[offset + i - d] |= s * 128\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/lib/bytesToUuid.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/uuid/lib/bytesToUuid.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n/**\n * Convert array of 16 byte values to UUID string format of the form:\n * XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX\n */\nvar byteToHex = [];\nfor (var i = 0; i < 256; ++i) {\n  byteToHex[i] = (i + 0x100).toString(16).substr(1);\n}\n\nfunction bytesToUuid(buf, offset) {\n  var i = offset || 0;\n  var bth = byteToHex;\n  // join used to fix memory issue caused by concatenation: https://bugs.chromium.org/p/v8/issues/detail?id=3175#c4\n  return ([bth[buf[i++]], bth[buf[i++]], \n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]]]).join('');\n}\n\nmodule.exports = bytesToUuid;\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/lib/rng-browser.js\":\n/*!**********************************************!*\\\n  !*** ./node_modules/uuid/lib/rng-browser.js ***!\n  \\**********************************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\n// Unique ID creation requires a high quality random # generator.  In the\n// browser this is a little complicated due to unknown quality of Math.random()\n// and inconsistent support for the `crypto` API.  We do the best we can via\n// feature-detection\n\n// getRandomValues needs to be invoked in a context where \"this\" is a Crypto\n// implementation. Also, find the complete implementation of crypto on IE11.\nvar getRandomValues = (typeof(crypto) != 'undefined' && crypto.getRandomValues && crypto.getRandomValues.bind(crypto)) ||\n                      (typeof(msCrypto) != 'undefined' && typeof window.msCrypto.getRandomValues == 'function' && msCrypto.getRandomValues.bind(msCrypto));\n\nif (getRandomValues) {\n  // WHATWG crypto RNG - http://wiki.whatwg.org/wiki/Crypto\n  var rnds8 = new Uint8Array(16); // eslint-disable-line no-undef\n\n  module.exports = function whatwgRNG() {\n    getRandomValues(rnds8);\n    return rnds8;\n  };\n} else {\n  // Math.random()-based (RNG)\n  //\n  // If all else fails, use Math.random().  It's fast, but is of unspecified\n  // quality.\n  var rnds = new Array(16);\n\n  module.exports = function mathRNG() {\n    for (var i = 0, r; i < 16; i++) {\n      if ((i & 0x03) === 0) r = Math.random() * 0x100000000;\n      rnds[i] = r >>> ((i & 0x03) << 3) & 0xff;\n    }\n\n    return rnds;\n  };\n}\n\n\n/***/ }),\n\n/***/ \"./node_modules/uuid/v4.js\":\n/*!*********************************!*\\\n  !*** ./node_modules/uuid/v4.js ***!\n  \\*********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\nvar rng = __webpack_require__(/*! ./lib/rng */ \"./node_modules/uuid/lib/rng-browser.js\");\nvar bytesToUuid = __webpack_require__(/*! ./lib/bytesToUuid */ \"./node_modules/uuid/lib/bytesToUuid.js\");\n\nfunction v4(options, buf, offset) {\n  var i = buf && offset || 0;\n\n  if (typeof(options) == 'string') {\n    buf = options === 'binary' ? new Array(16) : null;\n    options = null;\n  }\n  options = options || {};\n\n  var rnds = options.random || (options.rng || rng)();\n\n  // Per 4.4, set bits for version and `clock_seq_hi_and_reserved`\n  rnds[6] = (rnds[6] & 0x0f) | 0x40;\n  rnds[8] = (rnds[8] & 0x3f) | 0x80;\n\n  // Copy bytes to buffer, if provided\n  if (buf) {\n    for (var ii = 0; ii < 16; ++ii) {\n      buf[i + ii] = rnds[ii];\n    }\n  }\n\n  return buf || bytesToUuid(rnds);\n}\n\nmodule.exports = v4;\n\n\n/***/ }),\n\n/***/ \"./node_modules/webpack/buildin/global.js\":\n/*!***********************************!*\\\n  !*** (webpack)/buildin/global.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports) {\n\nvar g;\n\n// This works in non-strict mode\ng = (function() {\n\treturn this;\n})();\n\ntry {\n\t// This works if eval is allowed (see CSP)\n\tg = g || new Function(\"return this\")();\n} catch (e) {\n\t// This works if the window reference is available\n\tif (typeof window === \"object\") g = window;\n}\n\n// g can still be undefined, but nothing to do about it...\n// We return undefined, instead of nothing here, so it's\n// easier to handle this case. if(!global) { ...}\n\nmodule.exports = g;\n\n\n/***/ }),\n\n/***/ \"./src/AccessTokenEvents.js\":\n/*!**********************************!*\\\n  !*** ./src/AccessTokenEvents.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.AccessTokenEvents = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Timer = __webpack_require__(/*! ./Timer.js */ \"./src/Timer.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultAccessTokenExpiringNotificationTime = 60; // seconds\n\nvar AccessTokenEvents = exports.AccessTokenEvents = function () {\n    function AccessTokenEvents() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            _ref$accessTokenExpir = _ref.accessTokenExpiringNotificationTime,\n            accessTokenExpiringNotificationTime = _ref$accessTokenExpir === undefined ? DefaultAccessTokenExpiringNotificationTime : _ref$accessTokenExpir,\n            _ref$accessTokenExpir2 = _ref.accessTokenExpiringTimer,\n            accessTokenExpiringTimer = _ref$accessTokenExpir2 === undefined ? new _Timer.Timer(\"Access token expiring\") : _ref$accessTokenExpir2,\n            _ref$accessTokenExpir3 = _ref.accessTokenExpiredTimer,\n            accessTokenExpiredTimer = _ref$accessTokenExpir3 === undefined ? new _Timer.Timer(\"Access token expired\") : _ref$accessTokenExpir3;\n\n        _classCallCheck(this, AccessTokenEvents);\n\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\n\n        this._accessTokenExpiring = accessTokenExpiringTimer;\n        this._accessTokenExpired = accessTokenExpiredTimer;\n    }\n\n    AccessTokenEvents.prototype.load = function load(container) {\n        // only register events if there's an access token and it has an expiration\n        if (container.access_token && container.expires_in !== undefined) {\n            var duration = container.expires_in;\n            _Log.Log.debug(\"AccessTokenEvents.load: access token present, remaining duration:\", duration);\n\n            if (duration > 0) {\n                // only register expiring if we still have time\n                var expiring = duration - this._accessTokenExpiringNotificationTime;\n                if (expiring <= 0) {\n                    expiring = 1;\n                }\n\n                _Log.Log.debug(\"AccessTokenEvents.load: registering expiring timer in:\", expiring);\n                this._accessTokenExpiring.init(expiring);\n            } else {\n                _Log.Log.debug(\"AccessTokenEvents.load: canceling existing expiring timer becase we're past expiration.\");\n                this._accessTokenExpiring.cancel();\n            }\n\n            // if it's negative, it will still fire\n            var expired = duration + 1;\n            _Log.Log.debug(\"AccessTokenEvents.load: registering expired timer in:\", expired);\n            this._accessTokenExpired.init(expired);\n        } else {\n            this._accessTokenExpiring.cancel();\n            this._accessTokenExpired.cancel();\n        }\n    };\n\n    AccessTokenEvents.prototype.unload = function unload() {\n        _Log.Log.debug(\"AccessTokenEvents.unload: canceling existing access token timers\");\n        this._accessTokenExpiring.cancel();\n        this._accessTokenExpired.cancel();\n    };\n\n    AccessTokenEvents.prototype.addAccessTokenExpiring = function addAccessTokenExpiring(cb) {\n        this._accessTokenExpiring.addHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.removeAccessTokenExpiring = function removeAccessTokenExpiring(cb) {\n        this._accessTokenExpiring.removeHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.addAccessTokenExpired = function addAccessTokenExpired(cb) {\n        this._accessTokenExpired.addHandler(cb);\n    };\n\n    AccessTokenEvents.prototype.removeAccessTokenExpired = function removeAccessTokenExpired(cb) {\n        this._accessTokenExpired.removeHandler(cb);\n    };\n\n    return AccessTokenEvents;\n}();\n\n/***/ }),\n\n/***/ \"./src/CheckSessionIFrame.js\":\n/*!***********************************!*\\\n  !*** ./src/CheckSessionIFrame.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CheckSessionIFrame = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultInterval = 2000;\n\nvar CheckSessionIFrame = exports.CheckSessionIFrame = function () {\n    function CheckSessionIFrame(callback, client_id, url, interval) {\n        var stopOnError = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : true;\n\n        _classCallCheck(this, CheckSessionIFrame);\n\n        this._callback = callback;\n        this._client_id = client_id;\n        this._url = url;\n        this._interval = interval || DefaultInterval;\n        this._stopOnError = stopOnError;\n\n        var idx = url.indexOf(\"/\", url.indexOf(\"//\") + 2);\n        this._frame_origin = url.substr(0, idx);\n\n        this._frame = window.document.createElement(\"iframe\");\n\n        // shotgun approach\n        this._frame.style.visibility = \"hidden\";\n        this._frame.style.position = \"absolute\";\n        this._frame.style.display = \"none\";\n        this._frame.style.width = 0;\n        this._frame.style.height = 0;\n\n        this._frame.src = url;\n    }\n\n    CheckSessionIFrame.prototype.load = function load() {\n        var _this = this;\n\n        return new Promise(function (resolve) {\n            _this._frame.onload = function () {\n                resolve();\n            };\n\n            window.document.body.appendChild(_this._frame);\n            _this._boundMessageEvent = _this._message.bind(_this);\n            window.addEventListener(\"message\", _this._boundMessageEvent, false);\n        });\n    };\n\n    CheckSessionIFrame.prototype._message = function _message(e) {\n        if (e.origin === this._frame_origin && e.source === this._frame.contentWindow) {\n            if (e.data === \"error\") {\n                _Log.Log.error(\"CheckSessionIFrame: error message from check session op iframe\");\n                if (this._stopOnError) {\n                    this.stop();\n                }\n            } else if (e.data === \"changed\") {\n                _Log.Log.debug(\"CheckSessionIFrame: changed message from check session op iframe\");\n                this.stop();\n                this._callback();\n            } else {\n                _Log.Log.debug(\"CheckSessionIFrame: \" + e.data + \" message from check session op iframe\");\n            }\n        }\n    };\n\n    CheckSessionIFrame.prototype.start = function start(session_state) {\n        var _this2 = this;\n\n        if (this._session_state !== session_state) {\n            _Log.Log.debug(\"CheckSessionIFrame.start\");\n\n            this.stop();\n\n            this._session_state = session_state;\n\n            var send = function send() {\n                _this2._frame.contentWindow.postMessage(_this2._client_id + \" \" + _this2._session_state, _this2._frame_origin);\n            };\n\n            // trigger now\n            send();\n\n            // and setup timer\n            this._timer = window.setInterval(send, this._interval);\n        }\n    };\n\n    CheckSessionIFrame.prototype.stop = function stop() {\n        this._session_state = null;\n\n        if (this._timer) {\n            _Log.Log.debug(\"CheckSessionIFrame.stop\");\n\n            window.clearInterval(this._timer);\n            this._timer = null;\n        }\n    };\n\n    return CheckSessionIFrame;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaIFrameNavigator.js\":\n/*!***************************************!*\\\n  !*** ./src/CordovaIFrameNavigator.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaIFrameNavigator = undefined;\n\nvar _CordovaPopupWindow = __webpack_require__(/*! ./CordovaPopupWindow.js */ \"./src/CordovaPopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar CordovaIFrameNavigator = exports.CordovaIFrameNavigator = function () {\n    function CordovaIFrameNavigator() {\n        _classCallCheck(this, CordovaIFrameNavigator);\n    }\n\n    CordovaIFrameNavigator.prototype.prepare = function prepare(params) {\n        params.popupWindowFeatures = 'hidden=yes';\n        var popup = new _CordovaPopupWindow.CordovaPopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    return CordovaIFrameNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaPopupNavigator.js\":\n/*!**************************************!*\\\n  !*** ./src/CordovaPopupNavigator.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaPopupNavigator = undefined;\n\nvar _CordovaPopupWindow = __webpack_require__(/*! ./CordovaPopupWindow.js */ \"./src/CordovaPopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar CordovaPopupNavigator = exports.CordovaPopupNavigator = function () {\n    function CordovaPopupNavigator() {\n        _classCallCheck(this, CordovaPopupNavigator);\n    }\n\n    CordovaPopupNavigator.prototype.prepare = function prepare(params) {\n        var popup = new _CordovaPopupWindow.CordovaPopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    return CordovaPopupNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/CordovaPopupWindow.js\":\n/*!***********************************!*\\\n  !*** ./src/CordovaPopupWindow.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.CordovaPopupWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar DefaultPopupFeatures = 'location=no,toolbar=no,zoom=no';\nvar DefaultPopupTarget = \"_blank\";\n\nvar CordovaPopupWindow = exports.CordovaPopupWindow = function () {\n    function CordovaPopupWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, CordovaPopupWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        this.features = params.popupWindowFeatures || DefaultPopupFeatures;\n        this.target = params.popupWindowTarget || DefaultPopupTarget;\n\n        this.redirect_uri = params.startUrl;\n        _Log.Log.debug(\"CordovaPopupWindow.ctor: redirect_uri: \" + this.redirect_uri);\n    }\n\n    CordovaPopupWindow.prototype._isInAppBrowserInstalled = function _isInAppBrowserInstalled(cordovaMetadata) {\n        return [\"cordova-plugin-inappbrowser\", \"cordova-plugin-inappbrowser.inappbrowser\", \"org.apache.cordova.inappbrowser\"].some(function (name) {\n            return cordovaMetadata.hasOwnProperty(name);\n        });\n    };\n\n    CordovaPopupWindow.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            this._error(\"No url provided\");\n        } else {\n            if (!window.cordova) {\n                return this._error(\"cordova is undefined\");\n            }\n\n            var cordovaMetadata = window.cordova.require(\"cordova/plugin_list\").metadata;\n            if (this._isInAppBrowserInstalled(cordovaMetadata) === false) {\n                return this._error(\"InAppBrowser plugin not found\");\n            }\n            this._popup = cordova.InAppBrowser.open(params.url, this.target, this.features);\n            if (this._popup) {\n                _Log.Log.debug(\"CordovaPopupWindow.navigate: popup successfully created\");\n\n                this._exitCallbackEvent = this._exitCallback.bind(this);\n                this._loadStartCallbackEvent = this._loadStartCallback.bind(this);\n\n                this._popup.addEventListener(\"exit\", this._exitCallbackEvent, false);\n                this._popup.addEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\n            } else {\n                this._error(\"Error opening popup window\");\n            }\n        }\n        return this.promise;\n    };\n\n    CordovaPopupWindow.prototype._loadStartCallback = function _loadStartCallback(event) {\n        if (event.url.indexOf(this.redirect_uri) === 0) {\n            this._success({ url: event.url });\n        }\n    };\n\n    CordovaPopupWindow.prototype._exitCallback = function _exitCallback(message) {\n        this._error(message);\n    };\n\n    CordovaPopupWindow.prototype._success = function _success(data) {\n        this._cleanup();\n\n        _Log.Log.debug(\"CordovaPopupWindow: Successful response from cordova popup window\");\n        this._resolve(data);\n    };\n\n    CordovaPopupWindow.prototype._error = function _error(message) {\n        this._cleanup();\n\n        _Log.Log.error(message);\n        this._reject(new Error(message));\n    };\n\n    CordovaPopupWindow.prototype.close = function close() {\n        this._cleanup();\n    };\n\n    CordovaPopupWindow.prototype._cleanup = function _cleanup() {\n        if (this._popup) {\n            _Log.Log.debug(\"CordovaPopupWindow: cleaning up popup\");\n            this._popup.removeEventListener(\"exit\", this._exitCallbackEvent, false);\n            this._popup.removeEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\n            this._popup.close();\n        }\n        this._popup = null;\n    };\n\n    _createClass(CordovaPopupWindow, [{\n        key: 'promise',\n        get: function get() {\n            return this._promise;\n        }\n    }]);\n\n    return CordovaPopupWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/ErrorResponse.js\":\n/*!******************************!*\\\n  !*** ./src/ErrorResponse.js ***!\n  \\******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n        value: true\n});\nexports.ErrorResponse = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar ErrorResponse = exports.ErrorResponse = function (_Error) {\n        _inherits(ErrorResponse, _Error);\n\n        function ErrorResponse() {\n                var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n                    error = _ref.error,\n                    error_description = _ref.error_description,\n                    error_uri = _ref.error_uri,\n                    state = _ref.state,\n                    session_state = _ref.session_state;\n\n                _classCallCheck(this, ErrorResponse);\n\n                if (!error) {\n                        _Log.Log.error(\"No error passed to ErrorResponse\");\n                        throw new Error(\"error\");\n                }\n\n                var _this = _possibleConstructorReturn(this, _Error.call(this, error_description || error));\n\n                _this.name = \"ErrorResponse\";\n\n                _this.error = error;\n                _this.error_description = error_description;\n                _this.error_uri = error_uri;\n\n                _this.state = state;\n                _this.session_state = session_state;\n                return _this;\n        }\n\n        return ErrorResponse;\n}(Error);\n\n/***/ }),\n\n/***/ \"./src/Event.js\":\n/*!**********************!*\\\n  !*** ./src/Event.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.Event = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar Event = exports.Event = function () {\n    function Event(name) {\n        _classCallCheck(this, Event);\n\n        this._name = name;\n        this._callbacks = [];\n    }\n\n    Event.prototype.addHandler = function addHandler(cb) {\n        this._callbacks.push(cb);\n    };\n\n    Event.prototype.removeHandler = function removeHandler(cb) {\n        var idx = this._callbacks.findIndex(function (item) {\n            return item === cb;\n        });\n        if (idx >= 0) {\n            this._callbacks.splice(idx, 1);\n        }\n    };\n\n    Event.prototype.raise = function raise() {\n        _Log.Log.debug(\"Event: Raising event: \" + this._name);\n        for (var i = 0; i < this._callbacks.length; i++) {\n            var _callbacks;\n\n            (_callbacks = this._callbacks)[i].apply(_callbacks, arguments);\n        }\n    };\n\n    return Event;\n}();\n\n/***/ }),\n\n/***/ \"./src/Global.js\":\n/*!***********************!*\\\n  !*** ./src/Global.js ***!\n  \\***********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar timer = {\n    setInterval: function (_setInterval) {\n        function setInterval(_x, _x2) {\n            return _setInterval.apply(this, arguments);\n        }\n\n        setInterval.toString = function () {\n            return _setInterval.toString();\n        };\n\n        return setInterval;\n    }(function (cb, duration) {\n        return setInterval(cb, duration);\n    }),\n    clearInterval: function (_clearInterval) {\n        function clearInterval(_x3) {\n            return _clearInterval.apply(this, arguments);\n        }\n\n        clearInterval.toString = function () {\n            return _clearInterval.toString();\n        };\n\n        return clearInterval;\n    }(function (handle) {\n        return clearInterval(handle);\n    })\n};\n\nvar testing = false;\nvar request = null;\n\nvar Global = exports.Global = function () {\n    function Global() {\n        _classCallCheck(this, Global);\n    }\n\n    Global._testing = function _testing() {\n        testing = true;\n    };\n\n    Global.setXMLHttpRequest = function setXMLHttpRequest(newRequest) {\n        request = newRequest;\n    };\n\n    _createClass(Global, null, [{\n        key: 'location',\n        get: function get() {\n            if (!testing) {\n                return location;\n            }\n        }\n    }, {\n        key: 'localStorage',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return localStorage;\n            }\n        }\n    }, {\n        key: 'sessionStorage',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return sessionStorage;\n            }\n        }\n    }, {\n        key: 'XMLHttpRequest',\n        get: function get() {\n            if (!testing && typeof window !== 'undefined') {\n                return request || XMLHttpRequest;\n            }\n        }\n    }, {\n        key: 'timer',\n        get: function get() {\n            if (!testing) {\n                return timer;\n            }\n        }\n    }]);\n\n    return Global;\n}();\n\n/***/ }),\n\n/***/ \"./src/IFrameNavigator.js\":\n/*!********************************!*\\\n  !*** ./src/IFrameNavigator.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.IFrameNavigator = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _IFrameWindow = __webpack_require__(/*! ./IFrameWindow.js */ \"./src/IFrameWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar IFrameNavigator = exports.IFrameNavigator = function () {\n    function IFrameNavigator() {\n        _classCallCheck(this, IFrameNavigator);\n    }\n\n    IFrameNavigator.prototype.prepare = function prepare(params) {\n        var frame = new _IFrameWindow.IFrameWindow(params);\n        return Promise.resolve(frame);\n    };\n\n    IFrameNavigator.prototype.callback = function callback(url) {\n        _Log.Log.debug(\"IFrameNavigator.callback\");\n\n        try {\n            _IFrameWindow.IFrameWindow.notifyParent(url);\n            return Promise.resolve();\n        } catch (e) {\n            return Promise.reject(e);\n        }\n    };\n\n    return IFrameNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/IFrameWindow.js\":\n/*!*****************************!*\\\n  !*** ./src/IFrameWindow.js ***!\n  \\*****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.IFrameWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar DefaultTimeout = 10000;\n\nvar IFrameWindow = exports.IFrameWindow = function () {\n    function IFrameWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, IFrameWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        this._boundMessageEvent = this._message.bind(this);\n        window.addEventListener(\"message\", this._boundMessageEvent, false);\n\n        this._frame = window.document.createElement(\"iframe\");\n\n        // shotgun approach\n        this._frame.style.visibility = \"hidden\";\n        this._frame.style.position = \"absolute\";\n        this._frame.style.display = \"none\";\n        this._frame.style.width = 0;\n        this._frame.style.height = 0;\n\n        window.document.body.appendChild(this._frame);\n    }\n\n    IFrameWindow.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            this._error(\"No url provided\");\n        } else {\n            var timeout = params.silentRequestTimeout || DefaultTimeout;\n            _Log.Log.debug(\"IFrameWindow.navigate: Using timeout of:\", timeout);\n            this._timer = window.setTimeout(this._timeout.bind(this), timeout);\n            this._frame.src = params.url;\n        }\n\n        return this.promise;\n    };\n\n    IFrameWindow.prototype._success = function _success(data) {\n        this._cleanup();\n\n        _Log.Log.debug(\"IFrameWindow: Successful response from frame window\");\n        this._resolve(data);\n    };\n\n    IFrameWindow.prototype._error = function _error(message) {\n        this._cleanup();\n\n        _Log.Log.error(message);\n        this._reject(new Error(message));\n    };\n\n    IFrameWindow.prototype.close = function close() {\n        this._cleanup();\n    };\n\n    IFrameWindow.prototype._cleanup = function _cleanup() {\n        if (this._frame) {\n            _Log.Log.debug(\"IFrameWindow: cleanup\");\n\n            window.removeEventListener(\"message\", this._boundMessageEvent, false);\n            window.clearTimeout(this._timer);\n            window.document.body.removeChild(this._frame);\n\n            this._timer = null;\n            this._frame = null;\n            this._boundMessageEvent = null;\n        }\n    };\n\n    IFrameWindow.prototype._timeout = function _timeout() {\n        _Log.Log.debug(\"IFrameWindow.timeout\");\n        this._error(\"Frame window timed out\");\n    };\n\n    IFrameWindow.prototype._message = function _message(e) {\n        _Log.Log.debug(\"IFrameWindow.message\");\n\n        if (this._timer && e.origin === this._origin && e.source === this._frame.contentWindow) {\n            var url = e.data;\n            if (url) {\n                this._success({ url: url });\n            } else {\n                this._error(\"Invalid response from frame\");\n            }\n        }\n    };\n\n    IFrameWindow.notifyParent = function notifyParent(url) {\n        _Log.Log.debug(\"IFrameWindow.notifyParent\");\n        if (window.frameElement) {\n            url = url || window.location.href;\n            if (url) {\n                _Log.Log.debug(\"IFrameWindow.notifyParent: posting url message to parent\");\n                window.parent.postMessage(url, location.protocol + \"//\" + location.host);\n            }\n        }\n    };\n\n    _createClass(IFrameWindow, [{\n        key: \"promise\",\n        get: function get() {\n            return this._promise;\n        }\n    }, {\n        key: \"_origin\",\n        get: function get() {\n            return location.protocol + \"//\" + location.host;\n        }\n    }]);\n\n    return IFrameWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/InMemoryWebStorage.js\":\n/*!***********************************!*\\\n  !*** ./src/InMemoryWebStorage.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.InMemoryWebStorage = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar InMemoryWebStorage = exports.InMemoryWebStorage = function () {\n    function InMemoryWebStorage() {\n        _classCallCheck(this, InMemoryWebStorage);\n\n        this._data = {};\n    }\n\n    InMemoryWebStorage.prototype.getItem = function getItem(key) {\n        _Log.Log.debug(\"InMemoryWebStorage.getItem\", key);\n        return this._data[key];\n    };\n\n    InMemoryWebStorage.prototype.setItem = function setItem(key, value) {\n        _Log.Log.debug(\"InMemoryWebStorage.setItem\", key);\n        this._data[key] = value;\n    };\n\n    InMemoryWebStorage.prototype.removeItem = function removeItem(key) {\n        _Log.Log.debug(\"InMemoryWebStorage.removeItem\", key);\n        delete this._data[key];\n    };\n\n    InMemoryWebStorage.prototype.key = function key(index) {\n        return Object.getOwnPropertyNames(this._data)[index];\n    };\n\n    _createClass(InMemoryWebStorage, [{\n        key: \"length\",\n        get: function get() {\n            return Object.getOwnPropertyNames(this._data).length;\n        }\n    }]);\n\n    return InMemoryWebStorage;\n}();\n\n/***/ }),\n\n/***/ \"./src/JoseUtil.js\":\n/*!*************************!*\\\n  !*** ./src/JoseUtil.js ***!\n  \\*************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nexports.JoseUtil = undefined;\n\nvar _jsrsasign = __webpack_require__(/*! ./crypto/jsrsasign */ \"./src/crypto/jsrsasign.js\");\n\nvar _JoseUtilImpl = __webpack_require__(/*! ./JoseUtilImpl */ \"./src/JoseUtilImpl.js\");\n\nvar _JoseUtilImpl2 = _interopRequireDefault(_JoseUtilImpl);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nvar JoseUtil = exports.JoseUtil = (0, _JoseUtilImpl2.default)({ jws: _jsrsasign.jws, KeyUtil: _jsrsasign.KeyUtil, X509: _jsrsasign.X509, crypto: _jsrsasign.crypto, hextob64u: _jsrsasign.hextob64u, b64tohex: _jsrsasign.b64tohex, AllowedSigningAlgs: _jsrsasign.AllowedSigningAlgs });\n\n/***/ }),\n\n/***/ \"./src/JoseUtilImpl.js\":\n/*!*****************************!*\\\n  !*** ./src/JoseUtilImpl.js ***!\n  \\*****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.default = getJoseUtil;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nfunction getJoseUtil(_ref) {\n    var jws = _ref.jws,\n        KeyUtil = _ref.KeyUtil,\n        X509 = _ref.X509,\n        crypto = _ref.crypto,\n        hextob64u = _ref.hextob64u,\n        b64tohex = _ref.b64tohex,\n        AllowedSigningAlgs = _ref.AllowedSigningAlgs;\n\n    return function () {\n        function JoseUtil() {\n            _classCallCheck(this, JoseUtil);\n        }\n\n        JoseUtil.parseJwt = function parseJwt(jwt) {\n            _Log.Log.debug(\"JoseUtil.parseJwt\");\n            try {\n                var token = jws.JWS.parse(jwt);\n                return {\n                    header: token.headerObj,\n                    payload: token.payloadObj\n                };\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        JoseUtil.validateJwt = function validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\n            _Log.Log.debug(\"JoseUtil.validateJwt\");\n\n            try {\n                if (key.kty === \"RSA\") {\n                    if (key.e && key.n) {\n                        key = KeyUtil.getKey(key);\n                    } else if (key.x5c && key.x5c.length) {\n                        var hex = b64tohex(key.x5c[0]);\n                        key = X509.getPublicKeyFromCertHex(hex);\n                    } else {\n                        _Log.Log.error(\"JoseUtil.validateJwt: RSA key missing key material\", key);\n                        return Promise.reject(new Error(\"RSA key missing key material\"));\n                    }\n                } else if (key.kty === \"EC\") {\n                    if (key.crv && key.x && key.y) {\n                        key = KeyUtil.getKey(key);\n                    } else {\n                        _Log.Log.error(\"JoseUtil.validateJwt: EC key missing key material\", key);\n                        return Promise.reject(new Error(\"EC key missing key material\"));\n                    }\n                } else {\n                    _Log.Log.error(\"JoseUtil.validateJwt: Unsupported key type\", key && key.kty);\n                    return Promise.reject(new Error( true && key.kty));\n                }\n\n                return JoseUtil._validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive);\n            } catch (e) {\n                _Log.Log.error(e && e.message || e);\n                return Promise.reject(\"JWT validation failed\");\n            }\n        };\n\n        JoseUtil.validateJwtAttributes = function validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive) {\n            if (!clockSkew) {\n                clockSkew = 0;\n            }\n\n            if (!now) {\n                now = parseInt(Date.now() / 1000);\n            }\n\n            var payload = JoseUtil.parseJwt(jwt).payload;\n\n            if (!payload.iss) {\n                _Log.Log.error(\"JoseUtil._validateJwt: issuer was not provided\");\n                return Promise.reject(new Error(\"issuer was not provided\"));\n            }\n            if (payload.iss !== issuer) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid issuer in token\", payload.iss);\n                return Promise.reject(new Error(\"Invalid issuer in token: \" + payload.iss));\n            }\n\n            if (!payload.aud) {\n                _Log.Log.error(\"JoseUtil._validateJwt: aud was not provided\");\n                return Promise.reject(new Error(\"aud was not provided\"));\n            }\n            var validAudience = payload.aud === audience || Array.isArray(payload.aud) && payload.aud.indexOf(audience) >= 0;\n            if (!validAudience) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid audience in token\", payload.aud);\n                return Promise.reject(new Error(\"Invalid audience in token: \" + payload.aud));\n            }\n            if (payload.azp && payload.azp !== audience) {\n                _Log.Log.error(\"JoseUtil._validateJwt: Invalid azp in token\", payload.azp);\n                return Promise.reject(new Error(\"Invalid azp in token: \" + payload.azp));\n            }\n\n            if (!timeInsensitive) {\n                var lowerNow = now + clockSkew;\n                var upperNow = now - clockSkew;\n\n                if (!payload.iat) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: iat was not provided\");\n                    return Promise.reject(new Error(\"iat was not provided\"));\n                }\n                if (lowerNow < payload.iat) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: iat is in the future\", payload.iat);\n                    return Promise.reject(new Error(\"iat is in the future: \" + payload.iat));\n                }\n\n                if (payload.nbf && lowerNow < payload.nbf) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: nbf is in the future\", payload.nbf);\n                    return Promise.reject(new Error(\"nbf is in the future: \" + payload.nbf));\n                }\n\n                if (!payload.exp) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: exp was not provided\");\n                    return Promise.reject(new Error(\"exp was not provided\"));\n                }\n                if (payload.exp < upperNow) {\n                    _Log.Log.error(\"JoseUtil._validateJwt: exp is in the past\", payload.exp);\n                    return Promise.reject(new Error(\"exp is in the past:\" + payload.exp));\n                }\n            }\n\n            return Promise.resolve(payload);\n        };\n\n        JoseUtil._validateJwt = function _validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\n\n            return JoseUtil.validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive).then(function (payload) {\n                try {\n                    if (!jws.JWS.verify(jwt, key, AllowedSigningAlgs)) {\n                        _Log.Log.error(\"JoseUtil._validateJwt: signature validation failed\");\n                        return Promise.reject(new Error(\"signature validation failed\"));\n                    }\n\n                    return payload;\n                } catch (e) {\n                    _Log.Log.error(e && e.message || e);\n                    return Promise.reject(new Error(\"signature validation failed\"));\n                }\n            });\n        };\n\n        JoseUtil.hashString = function hashString(value, alg) {\n            try {\n                return crypto.Util.hashString(value, alg);\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        JoseUtil.hexToBase64Url = function hexToBase64Url(value) {\n            try {\n                return hextob64u(value);\n            } catch (e) {\n                _Log.Log.error(e);\n            }\n        };\n\n        return JoseUtil;\n    }();\n}\nmodule.exports = exports[\"default\"];\n\n/***/ }),\n\n/***/ \"./src/JsonService.js\":\n/*!****************************!*\\\n  !*** ./src/JsonService.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.JsonService = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar JsonService = exports.JsonService = function () {\n    function JsonService() {\n        var additionalContentTypes = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : null;\n        var XMLHttpRequestCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.XMLHttpRequest;\n        var jwtHandler = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : null;\n\n        _classCallCheck(this, JsonService);\n\n        if (additionalContentTypes && Array.isArray(additionalContentTypes)) {\n            this._contentTypes = additionalContentTypes.slice();\n        } else {\n            this._contentTypes = [];\n        }\n        this._contentTypes.push('application/json');\n        if (jwtHandler) {\n            this._contentTypes.push('application/jwt');\n        }\n\n        this._XMLHttpRequest = XMLHttpRequestCtor;\n        this._jwtHandler = jwtHandler;\n    }\n\n    JsonService.prototype.getJson = function getJson(url, token) {\n        var _this = this;\n\n        if (!url) {\n            _Log.Log.error(\"JsonService.getJson: No url passed\");\n            throw new Error(\"url\");\n        }\n\n        _Log.Log.debug(\"JsonService.getJson, url: \", url);\n\n        return new Promise(function (resolve, reject) {\n\n            var req = new _this._XMLHttpRequest();\n            req.open('GET', url);\n\n            var allowedContentTypes = _this._contentTypes;\n            var jwtHandler = _this._jwtHandler;\n\n            req.onload = function () {\n                _Log.Log.debug(\"JsonService.getJson: HTTP response received, status\", req.status);\n\n                if (req.status === 200) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found == \"application/jwt\") {\n                            jwtHandler(req).then(resolve, reject);\n                            return;\n                        }\n\n                        if (found) {\n                            try {\n                                resolve(JSON.parse(req.responseText));\n                                return;\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.getJson: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\n                } else {\n                    reject(Error(req.statusText + \" (\" + req.status + \")\"));\n                }\n            };\n\n            req.onerror = function () {\n                _Log.Log.error(\"JsonService.getJson: network error\");\n                reject(Error(\"Network Error\"));\n            };\n\n            if (token) {\n                _Log.Log.debug(\"JsonService.getJson: token passed, setting Authorization header\");\n                req.setRequestHeader(\"Authorization\", \"Bearer \" + token);\n            }\n\n            req.send();\n        });\n    };\n\n    JsonService.prototype.postForm = function postForm(url, payload) {\n        var _this2 = this;\n\n        if (!url) {\n            _Log.Log.error(\"JsonService.postForm: No url passed\");\n            throw new Error(\"url\");\n        }\n\n        _Log.Log.debug(\"JsonService.postForm, url: \", url);\n\n        return new Promise(function (resolve, reject) {\n\n            var req = new _this2._XMLHttpRequest();\n            req.open('POST', url);\n\n            var allowedContentTypes = _this2._contentTypes;\n\n            req.onload = function () {\n                _Log.Log.debug(\"JsonService.postForm: HTTP response received, status\", req.status);\n\n                if (req.status === 200) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found) {\n                            try {\n                                resolve(JSON.parse(req.responseText));\n                                return;\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\n                    return;\n                }\n\n                if (req.status === 400) {\n\n                    var contentType = req.getResponseHeader(\"Content-Type\");\n                    if (contentType) {\n\n                        var found = allowedContentTypes.find(function (item) {\n                            if (contentType.startsWith(item)) {\n                                return true;\n                            }\n                        });\n\n                        if (found) {\n                            try {\n                                var payload = JSON.parse(req.responseText);\n                                if (payload && payload.error) {\n                                    _Log.Log.error(\"JsonService.postForm: Error from server: \", payload.error);\n                                    reject(new Error(payload.error));\n                                    return;\n                                }\n                            } catch (e) {\n                                _Log.Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\n                                reject(e);\n                                return;\n                            }\n                        }\n                    }\n                }\n\n                reject(Error(req.statusText + \" (\" + req.status + \")\"));\n            };\n\n            req.onerror = function () {\n                _Log.Log.error(\"JsonService.postForm: network error\");\n                reject(Error(\"Network Error\"));\n            };\n\n            var body = \"\";\n            for (var key in payload) {\n\n                var value = payload[key];\n\n                if (value) {\n\n                    if (body.length > 0) {\n                        body += \"&\";\n                    }\n\n                    body += encodeURIComponent(key);\n                    body += \"=\";\n                    body += encodeURIComponent(value);\n                }\n            }\n\n            req.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\n            req.send(body);\n        });\n    };\n\n    return JsonService;\n}();\n\n/***/ }),\n\n/***/ \"./src/Log.js\":\n/*!********************!*\\\n  !*** ./src/Log.js ***!\n  \\********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\n// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar nopLogger = {\n    debug: function debug() {},\n    info: function info() {},\n    warn: function warn() {},\n    error: function error() {}\n};\n\nvar NONE = 0;\nvar ERROR = 1;\nvar WARN = 2;\nvar INFO = 3;\nvar DEBUG = 4;\n\nvar logger = void 0;\nvar level = void 0;\n\nvar Log = exports.Log = function () {\n    function Log() {\n        _classCallCheck(this, Log);\n    }\n\n    Log.reset = function reset() {\n        level = INFO;\n        logger = nopLogger;\n    };\n\n    Log.debug = function debug() {\n        if (level >= DEBUG) {\n            for (var _len = arguments.length, args = Array(_len), _key = 0; _key < _len; _key++) {\n                args[_key] = arguments[_key];\n            }\n\n            logger.debug.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.info = function info() {\n        if (level >= INFO) {\n            for (var _len2 = arguments.length, args = Array(_len2), _key2 = 0; _key2 < _len2; _key2++) {\n                args[_key2] = arguments[_key2];\n            }\n\n            logger.info.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.warn = function warn() {\n        if (level >= WARN) {\n            for (var _len3 = arguments.length, args = Array(_len3), _key3 = 0; _key3 < _len3; _key3++) {\n                args[_key3] = arguments[_key3];\n            }\n\n            logger.warn.apply(logger, Array.from(args));\n        }\n    };\n\n    Log.error = function error() {\n        if (level >= ERROR) {\n            for (var _len4 = arguments.length, args = Array(_len4), _key4 = 0; _key4 < _len4; _key4++) {\n                args[_key4] = arguments[_key4];\n            }\n\n            logger.error.apply(logger, Array.from(args));\n        }\n    };\n\n    _createClass(Log, null, [{\n        key: \"NONE\",\n        get: function get() {\n            return NONE;\n        }\n    }, {\n        key: \"ERROR\",\n        get: function get() {\n            return ERROR;\n        }\n    }, {\n        key: \"WARN\",\n        get: function get() {\n            return WARN;\n        }\n    }, {\n        key: \"INFO\",\n        get: function get() {\n            return INFO;\n        }\n    }, {\n        key: \"DEBUG\",\n        get: function get() {\n            return DEBUG;\n        }\n    }, {\n        key: \"level\",\n        get: function get() {\n            return level;\n        },\n        set: function set(value) {\n            if (NONE <= value && value <= DEBUG) {\n                level = value;\n            } else {\n                throw new Error(\"Invalid log level\");\n            }\n        }\n    }, {\n        key: \"logger\",\n        get: function get() {\n            return logger;\n        },\n        set: function set(value) {\n            if (!value.debug && value.info) {\n                // just to stay backwards compat. can remove in 2.0\n                value.debug = value.info;\n            }\n\n            if (value.debug && value.info && value.warn && value.error) {\n                logger = value;\n            } else {\n                throw new Error(\"Invalid logger\");\n            }\n        }\n    }]);\n\n    return Log;\n}();\n\nLog.reset();\n\n/***/ }),\n\n/***/ \"./src/MetadataService.js\":\n/*!********************************!*\\\n  !*** ./src/MetadataService.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.MetadataService = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcMetadataUrlPath = '.well-known/openid-configuration';\n\nvar MetadataService = exports.MetadataService = function () {\n    function MetadataService(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n\n        _classCallCheck(this, MetadataService);\n\n        if (!settings) {\n            _Log.Log.error(\"MetadataService: No settings passed to MetadataService\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor(['application/jwk-set+json']);\n    }\n\n    MetadataService.prototype.getMetadata = function getMetadata() {\n        var _this = this;\n\n        if (this._settings.metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadata: Returning metadata from settings\");\n            return Promise.resolve(this._settings.metadata);\n        }\n\n        if (!this.metadataUrl) {\n            _Log.Log.error(\"MetadataService.getMetadata: No authority or metadataUrl configured on settings\");\n            return Promise.reject(new Error(\"No authority or metadataUrl configured on settings\"));\n        }\n\n        _Log.Log.debug(\"MetadataService.getMetadata: getting metadata from\", this.metadataUrl);\n\n        return this._jsonService.getJson(this.metadataUrl).then(function (metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadata: json received\");\n            _this._settings.metadata = metadata;\n            return metadata;\n        });\n    };\n\n    MetadataService.prototype.getIssuer = function getIssuer() {\n        return this._getMetadataProperty(\"issuer\");\n    };\n\n    MetadataService.prototype.getAuthorizationEndpoint = function getAuthorizationEndpoint() {\n        return this._getMetadataProperty(\"authorization_endpoint\");\n    };\n\n    MetadataService.prototype.getUserInfoEndpoint = function getUserInfoEndpoint() {\n        return this._getMetadataProperty(\"userinfo_endpoint\");\n    };\n\n    MetadataService.prototype.getTokenEndpoint = function getTokenEndpoint() {\n        var optional = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : true;\n\n        return this._getMetadataProperty(\"token_endpoint\", optional);\n    };\n\n    MetadataService.prototype.getCheckSessionIframe = function getCheckSessionIframe() {\n        return this._getMetadataProperty(\"check_session_iframe\", true);\n    };\n\n    MetadataService.prototype.getEndSessionEndpoint = function getEndSessionEndpoint() {\n        return this._getMetadataProperty(\"end_session_endpoint\", true);\n    };\n\n    MetadataService.prototype.getRevocationEndpoint = function getRevocationEndpoint() {\n        return this._getMetadataProperty(\"revocation_endpoint\", true);\n    };\n\n    MetadataService.prototype.getKeysEndpoint = function getKeysEndpoint() {\n        return this._getMetadataProperty(\"jwks_uri\", true);\n    };\n\n    MetadataService.prototype._getMetadataProperty = function _getMetadataProperty(name) {\n        var optional = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : false;\n\n        _Log.Log.debug(\"MetadataService.getMetadataProperty for: \" + name);\n\n        return this.getMetadata().then(function (metadata) {\n            _Log.Log.debug(\"MetadataService.getMetadataProperty: metadata recieved\");\n\n            if (metadata[name] === undefined) {\n\n                if (optional === true) {\n                    _Log.Log.warn(\"MetadataService.getMetadataProperty: Metadata does not contain optional property \" + name);\n                    return undefined;\n                } else {\n                    _Log.Log.error(\"MetadataService.getMetadataProperty: Metadata does not contain property \" + name);\n                    throw new Error(\"Metadata does not contain property \" + name);\n                }\n            }\n\n            return metadata[name];\n        });\n    };\n\n    MetadataService.prototype.getSigningKeys = function getSigningKeys() {\n        var _this2 = this;\n\n        if (this._settings.signingKeys) {\n            _Log.Log.debug(\"MetadataService.getSigningKeys: Returning signingKeys from settings\");\n            return Promise.resolve(this._settings.signingKeys);\n        }\n\n        return this._getMetadataProperty(\"jwks_uri\").then(function (jwks_uri) {\n            _Log.Log.debug(\"MetadataService.getSigningKeys: jwks_uri received\", jwks_uri);\n\n            return _this2._jsonService.getJson(jwks_uri).then(function (keySet) {\n                _Log.Log.debug(\"MetadataService.getSigningKeys: key set received\", keySet);\n\n                if (!keySet.keys) {\n                    _Log.Log.error(\"MetadataService.getSigningKeys: Missing keys on keyset\");\n                    throw new Error(\"Missing keys on keyset\");\n                }\n\n                _this2._settings.signingKeys = keySet.keys;\n                return _this2._settings.signingKeys;\n            });\n        });\n    };\n\n    _createClass(MetadataService, [{\n        key: 'metadataUrl',\n        get: function get() {\n            if (!this._metadataUrl) {\n                if (this._settings.metadataUrl) {\n                    this._metadataUrl = this._settings.metadataUrl;\n                } else {\n                    this._metadataUrl = this._settings.authority;\n\n                    if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\n                        if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\n                            this._metadataUrl += '/';\n                        }\n                        this._metadataUrl += OidcMetadataUrlPath;\n                    }\n                }\n            }\n\n            return this._metadataUrl;\n        }\n    }]);\n\n    return MetadataService;\n}();\n\n/***/ }),\n\n/***/ \"./src/OidcClient.js\":\n/*!***************************!*\\\n  !*** ./src/OidcClient.js ***!\n  \\***************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.OidcClient = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClientSettings = __webpack_require__(/*! ./OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _ErrorResponse = __webpack_require__(/*! ./ErrorResponse.js */ \"./src/ErrorResponse.js\");\n\nvar _SigninRequest = __webpack_require__(/*! ./SigninRequest.js */ \"./src/SigninRequest.js\");\n\nvar _SigninResponse = __webpack_require__(/*! ./SigninResponse.js */ \"./src/SigninResponse.js\");\n\nvar _SignoutRequest = __webpack_require__(/*! ./SignoutRequest.js */ \"./src/SignoutRequest.js\");\n\nvar _SignoutResponse = __webpack_require__(/*! ./SignoutResponse.js */ \"./src/SignoutResponse.js\");\n\nvar _SigninState = __webpack_require__(/*! ./SigninState.js */ \"./src/SigninState.js\");\n\nvar _State = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcClient = exports.OidcClient = function () {\n    function OidcClient() {\n        var settings = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        _classCallCheck(this, OidcClient);\n\n        if (settings instanceof _OidcClientSettings.OidcClientSettings) {\n            this._settings = settings;\n        } else {\n            this._settings = new _OidcClientSettings.OidcClientSettings(settings);\n        }\n    }\n\n    OidcClient.prototype.createSigninRequest = function createSigninRequest() {\n        var _this = this;\n\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            response_type = _ref.response_type,\n            scope = _ref.scope,\n            redirect_uri = _ref.redirect_uri,\n            data = _ref.data,\n            state = _ref.state,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            id_token_hint = _ref.id_token_hint,\n            login_hint = _ref.login_hint,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            request = _ref.request,\n            request_uri = _ref.request_uri,\n            response_mode = _ref.response_mode,\n            extraQueryParams = _ref.extraQueryParams,\n            extraTokenParams = _ref.extraTokenParams,\n            request_type = _ref.request_type,\n            skipUserInfo = _ref.skipUserInfo;\n\n        var stateStore = arguments[1];\n\n        _Log.Log.debug(\"OidcClient.createSigninRequest\");\n\n        var client_id = this._settings.client_id;\n        response_type = response_type || this._settings.response_type;\n        scope = scope || this._settings.scope;\n        redirect_uri = redirect_uri || this._settings.redirect_uri;\n\n        // id_token_hint, login_hint aren't allowed on _settings\n        prompt = prompt || this._settings.prompt;\n        display = display || this._settings.display;\n        max_age = max_age || this._settings.max_age;\n        ui_locales = ui_locales || this._settings.ui_locales;\n        acr_values = acr_values || this._settings.acr_values;\n        resource = resource || this._settings.resource;\n        response_mode = response_mode || this._settings.response_mode;\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\n        extraTokenParams = extraTokenParams || this._settings.extraTokenParams;\n\n        var authority = this._settings.authority;\n\n        if (_SigninRequest.SigninRequest.isCode(response_type) && response_type !== \"code\") {\n            return Promise.reject(new Error(\"OpenID Connect hybrid flow is not supported\"));\n        }\n\n        return this._metadataService.getAuthorizationEndpoint().then(function (url) {\n            _Log.Log.debug(\"OidcClient.createSigninRequest: Received authorization endpoint\", url);\n\n            var signinRequest = new _SigninRequest.SigninRequest({\n                url: url,\n                client_id: client_id,\n                redirect_uri: redirect_uri,\n                response_type: response_type,\n                scope: scope,\n                data: data || state,\n                authority: authority,\n                prompt: prompt, display: display, max_age: max_age, ui_locales: ui_locales, id_token_hint: id_token_hint, login_hint: login_hint, acr_values: acr_values,\n                resource: resource, request: request, request_uri: request_uri, extraQueryParams: extraQueryParams, extraTokenParams: extraTokenParams, request_type: request_type, response_mode: response_mode,\n                client_secret: _this._settings.client_secret,\n                skipUserInfo: skipUserInfo\n            });\n\n            var signinState = signinRequest.state;\n            stateStore = stateStore || _this._stateStore;\n\n            return stateStore.set(signinState.id, signinState.toStorageString()).then(function () {\n                return signinRequest;\n            });\n        });\n    };\n\n    OidcClient.prototype.readSigninResponseState = function readSigninResponseState(url, stateStore) {\n        var removeState = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : false;\n\n        _Log.Log.debug(\"OidcClient.readSigninResponseState\");\n\n        var useQuery = this._settings.response_mode === \"query\" || !this._settings.response_mode && _SigninRequest.SigninRequest.isCode(this._settings.response_type);\n        var delimiter = useQuery ? \"?\" : \"#\";\n\n        var response = new _SigninResponse.SigninResponse(url, delimiter);\n\n        if (!response.state) {\n            _Log.Log.error(\"OidcClient.readSigninResponseState: No state in response\");\n            return Promise.reject(new Error(\"No state in response\"));\n        }\n\n        stateStore = stateStore || this._stateStore;\n\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\n\n        return stateApi(response.state).then(function (storedStateString) {\n            if (!storedStateString) {\n                _Log.Log.error(\"OidcClient.readSigninResponseState: No matching state found in storage\");\n                throw new Error(\"No matching state found in storage\");\n            }\n\n            var state = _SigninState.SigninState.fromStorageString(storedStateString);\n            return { state: state, response: response };\n        });\n    };\n\n    OidcClient.prototype.processSigninResponse = function processSigninResponse(url, stateStore) {\n        var _this2 = this;\n\n        _Log.Log.debug(\"OidcClient.processSigninResponse\");\n\n        return this.readSigninResponseState(url, stateStore, true).then(function (_ref2) {\n            var state = _ref2.state,\n                response = _ref2.response;\n\n            _Log.Log.debug(\"OidcClient.processSigninResponse: Received state from storage; validating response\");\n            return _this2._validator.validateSigninResponse(state, response);\n        });\n    };\n\n    OidcClient.prototype.createSignoutRequest = function createSignoutRequest() {\n        var _this3 = this;\n\n        var _ref3 = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            id_token_hint = _ref3.id_token_hint,\n            data = _ref3.data,\n            state = _ref3.state,\n            post_logout_redirect_uri = _ref3.post_logout_redirect_uri,\n            extraQueryParams = _ref3.extraQueryParams,\n            request_type = _ref3.request_type;\n\n        var stateStore = arguments[1];\n\n        _Log.Log.debug(\"OidcClient.createSignoutRequest\");\n\n        post_logout_redirect_uri = post_logout_redirect_uri || this._settings.post_logout_redirect_uri;\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\n\n        return this._metadataService.getEndSessionEndpoint().then(function (url) {\n            if (!url) {\n                _Log.Log.error(\"OidcClient.createSignoutRequest: No end session endpoint url returned\");\n                throw new Error(\"no end session endpoint\");\n            }\n\n            _Log.Log.debug(\"OidcClient.createSignoutRequest: Received end session endpoint\", url);\n\n            var request = new _SignoutRequest.SignoutRequest({\n                url: url,\n                id_token_hint: id_token_hint,\n                post_logout_redirect_uri: post_logout_redirect_uri,\n                data: data || state,\n                extraQueryParams: extraQueryParams,\n                request_type: request_type\n            });\n\n            var signoutState = request.state;\n            if (signoutState) {\n                _Log.Log.debug(\"OidcClient.createSignoutRequest: Signout request has state to persist\");\n\n                stateStore = stateStore || _this3._stateStore;\n                stateStore.set(signoutState.id, signoutState.toStorageString());\n            }\n\n            return request;\n        });\n    };\n\n    OidcClient.prototype.readSignoutResponseState = function readSignoutResponseState(url, stateStore) {\n        var removeState = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : false;\n\n        _Log.Log.debug(\"OidcClient.readSignoutResponseState\");\n\n        var response = new _SignoutResponse.SignoutResponse(url);\n        if (!response.state) {\n            _Log.Log.debug(\"OidcClient.readSignoutResponseState: No state in response\");\n\n            if (response.error) {\n                _Log.Log.warn(\"OidcClient.readSignoutResponseState: Response was error: \", response.error);\n                return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n            }\n\n            return Promise.resolve({ undefined: undefined, response: response });\n        }\n\n        var stateKey = response.state;\n\n        stateStore = stateStore || this._stateStore;\n\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\n        return stateApi(stateKey).then(function (storedStateString) {\n            if (!storedStateString) {\n                _Log.Log.error(\"OidcClient.readSignoutResponseState: No matching state found in storage\");\n                throw new Error(\"No matching state found in storage\");\n            }\n\n            var state = _State.State.fromStorageString(storedStateString);\n\n            return { state: state, response: response };\n        });\n    };\n\n    OidcClient.prototype.processSignoutResponse = function processSignoutResponse(url, stateStore) {\n        var _this4 = this;\n\n        _Log.Log.debug(\"OidcClient.processSignoutResponse\");\n\n        return this.readSignoutResponseState(url, stateStore, true).then(function (_ref4) {\n            var state = _ref4.state,\n                response = _ref4.response;\n\n            if (state) {\n                _Log.Log.debug(\"OidcClient.processSignoutResponse: Received state from storage; validating response\");\n                return _this4._validator.validateSignoutResponse(state, response);\n            } else {\n                _Log.Log.debug(\"OidcClient.processSignoutResponse: No state from storage; skipping validating response\");\n                return response;\n            }\n        });\n    };\n\n    OidcClient.prototype.clearStaleState = function clearStaleState(stateStore) {\n        _Log.Log.debug(\"OidcClient.clearStaleState\");\n\n        stateStore = stateStore || this._stateStore;\n\n        return _State.State.clearStaleState(stateStore, this.settings.staleStateAge);\n    };\n\n    _createClass(OidcClient, [{\n        key: '_stateStore',\n        get: function get() {\n            return this.settings.stateStore;\n        }\n    }, {\n        key: '_validator',\n        get: function get() {\n            return this.settings.validator;\n        }\n    }, {\n        key: '_metadataService',\n        get: function get() {\n            return this.settings.metadataService;\n        }\n    }, {\n        key: 'settings',\n        get: function get() {\n            return this._settings;\n        }\n    }, {\n        key: 'metadataService',\n        get: function get() {\n            return this._metadataService;\n        }\n    }]);\n\n    return OidcClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/OidcClientSettings.js\":\n/*!***********************************!*\\\n  !*** ./src/OidcClientSettings.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.OidcClientSettings = undefined;\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _ResponseValidator = __webpack_require__(/*! ./ResponseValidator.js */ \"./src/ResponseValidator.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcMetadataUrlPath = '.well-known/openid-configuration';\n\nvar DefaultResponseType = \"id_token\";\nvar DefaultScope = \"openid\";\nvar DefaultStaleStateAge = 60 * 15; // seconds\nvar DefaultClockSkewInSeconds = 60 * 5;\n\nvar OidcClientSettings = exports.OidcClientSettings = function () {\n    function OidcClientSettings() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            authority = _ref.authority,\n            metadataUrl = _ref.metadataUrl,\n            metadata = _ref.metadata,\n            signingKeys = _ref.signingKeys,\n            client_id = _ref.client_id,\n            client_secret = _ref.client_secret,\n            _ref$response_type = _ref.response_type,\n            response_type = _ref$response_type === undefined ? DefaultResponseType : _ref$response_type,\n            _ref$scope = _ref.scope,\n            scope = _ref$scope === undefined ? DefaultScope : _ref$scope,\n            redirect_uri = _ref.redirect_uri,\n            post_logout_redirect_uri = _ref.post_logout_redirect_uri,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            response_mode = _ref.response_mode,\n            _ref$filterProtocolCl = _ref.filterProtocolClaims,\n            filterProtocolClaims = _ref$filterProtocolCl === undefined ? true : _ref$filterProtocolCl,\n            _ref$loadUserInfo = _ref.loadUserInfo,\n            loadUserInfo = _ref$loadUserInfo === undefined ? true : _ref$loadUserInfo,\n            _ref$staleStateAge = _ref.staleStateAge,\n            staleStateAge = _ref$staleStateAge === undefined ? DefaultStaleStateAge : _ref$staleStateAge,\n            _ref$clockSkew = _ref.clockSkew,\n            clockSkew = _ref$clockSkew === undefined ? DefaultClockSkewInSeconds : _ref$clockSkew,\n            _ref$userInfoJwtIssue = _ref.userInfoJwtIssuer,\n            userInfoJwtIssuer = _ref$userInfoJwtIssue === undefined ? 'OP' : _ref$userInfoJwtIssue,\n            _ref$stateStore = _ref.stateStore,\n            stateStore = _ref$stateStore === undefined ? new _WebStorageStateStore.WebStorageStateStore() : _ref$stateStore,\n            _ref$ResponseValidato = _ref.ResponseValidatorCtor,\n            ResponseValidatorCtor = _ref$ResponseValidato === undefined ? _ResponseValidator.ResponseValidator : _ref$ResponseValidato,\n            _ref$MetadataServiceC = _ref.MetadataServiceCtor,\n            MetadataServiceCtor = _ref$MetadataServiceC === undefined ? _MetadataService.MetadataService : _ref$MetadataServiceC,\n            _ref$extraQueryParams = _ref.extraQueryParams,\n            extraQueryParams = _ref$extraQueryParams === undefined ? {} : _ref$extraQueryParams,\n            _ref$extraTokenParams = _ref.extraTokenParams,\n            extraTokenParams = _ref$extraTokenParams === undefined ? {} : _ref$extraTokenParams;\n\n        _classCallCheck(this, OidcClientSettings);\n\n        this._authority = authority;\n        this._metadataUrl = metadataUrl;\n        this._metadata = metadata;\n        this._signingKeys = signingKeys;\n\n        this._client_id = client_id;\n        this._client_secret = client_secret;\n        this._response_type = response_type;\n        this._scope = scope;\n        this._redirect_uri = redirect_uri;\n        this._post_logout_redirect_uri = post_logout_redirect_uri;\n\n        this._prompt = prompt;\n        this._display = display;\n        this._max_age = max_age;\n        this._ui_locales = ui_locales;\n        this._acr_values = acr_values;\n        this._resource = resource;\n        this._response_mode = response_mode;\n\n        this._filterProtocolClaims = !!filterProtocolClaims;\n        this._loadUserInfo = !!loadUserInfo;\n        this._staleStateAge = staleStateAge;\n        this._clockSkew = clockSkew;\n        this._userInfoJwtIssuer = userInfoJwtIssuer;\n\n        this._stateStore = stateStore;\n        this._validator = new ResponseValidatorCtor(this);\n        this._metadataService = new MetadataServiceCtor(this);\n\n        this._extraQueryParams = (typeof extraQueryParams === 'undefined' ? 'undefined' : _typeof(extraQueryParams)) === 'object' ? extraQueryParams : {};\n        this._extraTokenParams = (typeof extraTokenParams === 'undefined' ? 'undefined' : _typeof(extraTokenParams)) === 'object' ? extraTokenParams : {};\n    }\n\n    // client config\n\n\n    _createClass(OidcClientSettings, [{\n        key: 'client_id',\n        get: function get() {\n            return this._client_id;\n        },\n        set: function set(value) {\n            if (!this._client_id) {\n                // one-time set only\n                this._client_id = value;\n            } else {\n                _Log.Log.error(\"OidcClientSettings.set_client_id: client_id has already been assigned.\");\n                throw new Error(\"client_id has already been assigned.\");\n            }\n        }\n    }, {\n        key: 'client_secret',\n        get: function get() {\n            return this._client_secret;\n        }\n    }, {\n        key: 'response_type',\n        get: function get() {\n            return this._response_type;\n        }\n    }, {\n        key: 'scope',\n        get: function get() {\n            return this._scope;\n        }\n    }, {\n        key: 'redirect_uri',\n        get: function get() {\n            return this._redirect_uri;\n        }\n    }, {\n        key: 'post_logout_redirect_uri',\n        get: function get() {\n            return this._post_logout_redirect_uri;\n        }\n\n        // optional protocol params\n\n    }, {\n        key: 'prompt',\n        get: function get() {\n            return this._prompt;\n        }\n    }, {\n        key: 'display',\n        get: function get() {\n            return this._display;\n        }\n    }, {\n        key: 'max_age',\n        get: function get() {\n            return this._max_age;\n        }\n    }, {\n        key: 'ui_locales',\n        get: function get() {\n            return this._ui_locales;\n        }\n    }, {\n        key: 'acr_values',\n        get: function get() {\n            return this._acr_values;\n        }\n    }, {\n        key: 'resource',\n        get: function get() {\n            return this._resource;\n        }\n    }, {\n        key: 'response_mode',\n        get: function get() {\n            return this._response_mode;\n        }\n\n        // metadata\n\n    }, {\n        key: 'authority',\n        get: function get() {\n            return this._authority;\n        },\n        set: function set(value) {\n            if (!this._authority) {\n                // one-time set only\n                this._authority = value;\n            } else {\n                _Log.Log.error(\"OidcClientSettings.set_authority: authority has already been assigned.\");\n                throw new Error(\"authority has already been assigned.\");\n            }\n        }\n    }, {\n        key: 'metadataUrl',\n        get: function get() {\n            if (!this._metadataUrl) {\n                this._metadataUrl = this.authority;\n\n                if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\n                    if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\n                        this._metadataUrl += '/';\n                    }\n                    this._metadataUrl += OidcMetadataUrlPath;\n                }\n            }\n\n            return this._metadataUrl;\n        }\n\n        // settable/cachable metadata values\n\n    }, {\n        key: 'metadata',\n        get: function get() {\n            return this._metadata;\n        },\n        set: function set(value) {\n            this._metadata = value;\n        }\n    }, {\n        key: 'signingKeys',\n        get: function get() {\n            return this._signingKeys;\n        },\n        set: function set(value) {\n            this._signingKeys = value;\n        }\n\n        // behavior flags\n\n    }, {\n        key: 'filterProtocolClaims',\n        get: function get() {\n            return this._filterProtocolClaims;\n        }\n    }, {\n        key: 'loadUserInfo',\n        get: function get() {\n            return this._loadUserInfo;\n        }\n    }, {\n        key: 'staleStateAge',\n        get: function get() {\n            return this._staleStateAge;\n        }\n    }, {\n        key: 'clockSkew',\n        get: function get() {\n            return this._clockSkew;\n        }\n    }, {\n        key: 'userInfoJwtIssuer',\n        get: function get() {\n            return this._userInfoJwtIssuer;\n        }\n    }, {\n        key: 'stateStore',\n        get: function get() {\n            return this._stateStore;\n        }\n    }, {\n        key: 'validator',\n        get: function get() {\n            return this._validator;\n        }\n    }, {\n        key: 'metadataService',\n        get: function get() {\n            return this._metadataService;\n        }\n\n        // extra query params\n\n    }, {\n        key: 'extraQueryParams',\n        get: function get() {\n            return this._extraQueryParams;\n        },\n        set: function set(value) {\n            if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                this._extraQueryParams = value;\n            } else {\n                this._extraQueryParams = {};\n            }\n        }\n\n        // extra token params\n\n    }, {\n        key: 'extraTokenParams',\n        get: function get() {\n            return this._extraTokenParams;\n        },\n        set: function set(value) {\n            if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                this._extraTokenParams = value;\n            } else {\n                this._extraTokenParams = {};\n            }\n        }\n    }]);\n\n    return OidcClientSettings;\n}();\n\n/***/ }),\n\n/***/ \"./src/PopupNavigator.js\":\n/*!*******************************!*\\\n  !*** ./src/PopupNavigator.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.PopupNavigator = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _PopupWindow = __webpack_require__(/*! ./PopupWindow.js */ \"./src/PopupWindow.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar PopupNavigator = exports.PopupNavigator = function () {\n    function PopupNavigator() {\n        _classCallCheck(this, PopupNavigator);\n    }\n\n    PopupNavigator.prototype.prepare = function prepare(params) {\n        var popup = new _PopupWindow.PopupWindow(params);\n        return Promise.resolve(popup);\n    };\n\n    PopupNavigator.prototype.callback = function callback(url, keepOpen, delimiter) {\n        _Log.Log.debug(\"PopupNavigator.callback\");\n\n        try {\n            _PopupWindow.PopupWindow.notifyOpener(url, keepOpen, delimiter);\n            return Promise.resolve();\n        } catch (e) {\n            return Promise.reject(e);\n        }\n    };\n\n    return PopupNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/PopupWindow.js\":\n/*!****************************!*\\\n  !*** ./src/PopupWindow.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.PopupWindow = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar CheckForPopupClosedInterval = 500;\nvar DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;';\n//const DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;resizable=yes';\n\nvar DefaultPopupTarget = \"_blank\";\n\nvar PopupWindow = exports.PopupWindow = function () {\n    function PopupWindow(params) {\n        var _this = this;\n\n        _classCallCheck(this, PopupWindow);\n\n        this._promise = new Promise(function (resolve, reject) {\n            _this._resolve = resolve;\n            _this._reject = reject;\n        });\n\n        var target = params.popupWindowTarget || DefaultPopupTarget;\n        var features = params.popupWindowFeatures || DefaultPopupFeatures;\n\n        this._popup = window.open('', target, features);\n        if (this._popup) {\n            _Log.Log.debug(\"PopupWindow.ctor: popup successfully created\");\n            this._checkForPopupClosedTimer = window.setInterval(this._checkForPopupClosed.bind(this), CheckForPopupClosedInterval);\n        }\n    }\n\n    PopupWindow.prototype.navigate = function navigate(params) {\n        if (!this._popup) {\n            this._error(\"PopupWindow.navigate: Error opening popup window\");\n        } else if (!params || !params.url) {\n            this._error(\"PopupWindow.navigate: no url provided\");\n            this._error(\"No url provided\");\n        } else {\n            _Log.Log.debug(\"PopupWindow.navigate: Setting URL in popup\");\n\n            this._id = params.id;\n            if (this._id) {\n                window[\"popupCallback_\" + params.id] = this._callback.bind(this);\n            }\n\n            this._popup.focus();\n            this._popup.window.location = params.url;\n        }\n\n        return this.promise;\n    };\n\n    PopupWindow.prototype._success = function _success(data) {\n        _Log.Log.debug(\"PopupWindow.callback: Successful response from popup window\");\n\n        this._cleanup();\n        this._resolve(data);\n    };\n\n    PopupWindow.prototype._error = function _error(message) {\n        _Log.Log.error(\"PopupWindow.error: \", message);\n\n        this._cleanup();\n        this._reject(new Error(message));\n    };\n\n    PopupWindow.prototype.close = function close() {\n        this._cleanup(false);\n    };\n\n    PopupWindow.prototype._cleanup = function _cleanup(keepOpen) {\n        _Log.Log.debug(\"PopupWindow.cleanup\");\n\n        window.clearInterval(this._checkForPopupClosedTimer);\n        this._checkForPopupClosedTimer = null;\n\n        delete window[\"popupCallback_\" + this._id];\n\n        if (this._popup && !keepOpen) {\n            this._popup.close();\n        }\n        this._popup = null;\n    };\n\n    PopupWindow.prototype._checkForPopupClosed = function _checkForPopupClosed() {\n        if (!this._popup || this._popup.closed) {\n            this._error(\"Popup window closed\");\n        }\n    };\n\n    PopupWindow.prototype._callback = function _callback(url, keepOpen) {\n        this._cleanup(keepOpen);\n\n        if (url) {\n            _Log.Log.debug(\"PopupWindow.callback success\");\n            this._success({ url: url });\n        } else {\n            _Log.Log.debug(\"PopupWindow.callback: Invalid response from popup\");\n            this._error(\"Invalid response from popup\");\n        }\n    };\n\n    PopupWindow.notifyOpener = function notifyOpener(url, keepOpen, delimiter) {\n        if (window.opener) {\n            url = url || window.location.href;\n            if (url) {\n                var data = _UrlUtility.UrlUtility.parseUrlFragment(url, delimiter);\n\n                if (data.state) {\n                    var name = \"popupCallback_\" + data.state;\n                    var callback = window.opener[name];\n                    if (callback) {\n                        _Log.Log.debug(\"PopupWindow.notifyOpener: passing url message to opener\");\n                        callback(url, keepOpen);\n                    } else {\n                        _Log.Log.warn(\"PopupWindow.notifyOpener: no matching callback found on opener\");\n                    }\n                } else {\n                    _Log.Log.warn(\"PopupWindow.notifyOpener: no state found in response url\");\n                }\n            }\n        } else {\n            _Log.Log.warn(\"PopupWindow.notifyOpener: no window.opener. Can't complete notification.\");\n        }\n    };\n\n    _createClass(PopupWindow, [{\n        key: 'promise',\n        get: function get() {\n            return this._promise;\n        }\n    }]);\n\n    return PopupWindow;\n}();\n\n/***/ }),\n\n/***/ \"./src/RedirectNavigator.js\":\n/*!**********************************!*\\\n  !*** ./src/RedirectNavigator.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.RedirectNavigator = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar RedirectNavigator = exports.RedirectNavigator = function () {\n    function RedirectNavigator() {\n        _classCallCheck(this, RedirectNavigator);\n    }\n\n    RedirectNavigator.prototype.prepare = function prepare() {\n        return Promise.resolve(this);\n    };\n\n    RedirectNavigator.prototype.navigate = function navigate(params) {\n        if (!params || !params.url) {\n            _Log.Log.error(\"RedirectNavigator.navigate: No url provided\");\n            return Promise.reject(new Error(\"No url provided\"));\n        }\n\n        if (params.useReplaceToNavigate) {\n            window.location.replace(params.url);\n        } else {\n            window.location = params.url;\n        }\n\n        return Promise.resolve();\n    };\n\n    _createClass(RedirectNavigator, [{\n        key: \"url\",\n        get: function get() {\n            return window.location.href;\n        }\n    }]);\n\n    return RedirectNavigator;\n}();\n\n/***/ }),\n\n/***/ \"./src/ResponseValidator.js\":\n/*!**********************************!*\\\n  !*** ./src/ResponseValidator.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.ResponseValidator = undefined;\n\nvar _typeof = typeof Symbol === \"function\" && typeof Symbol.iterator === \"symbol\" ? function (obj) { return typeof obj; } : function (obj) { return obj && typeof Symbol === \"function\" && obj.constructor === Symbol && obj !== Symbol.prototype ? \"symbol\" : typeof obj; };\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _UserInfoService = __webpack_require__(/*! ./UserInfoService.js */ \"./src/UserInfoService.js\");\n\nvar _TokenClient = __webpack_require__(/*! ./TokenClient.js */ \"./src/TokenClient.js\");\n\nvar _ErrorResponse = __webpack_require__(/*! ./ErrorResponse.js */ \"./src/ErrorResponse.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar ProtocolClaims = [\"nonce\", \"at_hash\", \"iat\", \"nbf\", \"exp\", \"aud\", \"iss\", \"c_hash\"];\n\nvar ResponseValidator = exports.ResponseValidator = function () {\n    function ResponseValidator(settings) {\n        var MetadataServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _MetadataService.MetadataService;\n        var UserInfoServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _UserInfoService.UserInfoService;\n        var joseUtil = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _JoseUtil.JoseUtil;\n        var TokenClientCtor = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : _TokenClient.TokenClient;\n\n        _classCallCheck(this, ResponseValidator);\n\n        if (!settings) {\n            _Log.Log.error(\"ResponseValidator.ctor: No settings passed to ResponseValidator\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._metadataService = new MetadataServiceCtor(this._settings);\n        this._userInfoService = new UserInfoServiceCtor(this._settings);\n        this._joseUtil = joseUtil;\n        this._tokenClient = new TokenClientCtor(this._settings);\n    }\n\n    ResponseValidator.prototype.validateSigninResponse = function validateSigninResponse(state, response) {\n        var _this = this;\n\n        _Log.Log.debug(\"ResponseValidator.validateSigninResponse\");\n\n        return this._processSigninParams(state, response).then(function (response) {\n            _Log.Log.debug(\"ResponseValidator.validateSigninResponse: state processed\");\n            return _this._validateTokens(state, response).then(function (response) {\n                _Log.Log.debug(\"ResponseValidator.validateSigninResponse: tokens validated\");\n                return _this._processClaims(state, response).then(function (response) {\n                    _Log.Log.debug(\"ResponseValidator.validateSigninResponse: claims processed\");\n                    return response;\n                });\n            });\n        });\n    };\n\n    ResponseValidator.prototype.validateSignoutResponse = function validateSignoutResponse(state, response) {\n        if (state.id !== response.state) {\n            _Log.Log.error(\"ResponseValidator.validateSignoutResponse: State does not match\");\n            return Promise.reject(new Error(\"State does not match\"));\n        }\n\n        // now that we know the state matches, take the stored data\n        // and set it into the response so callers can get their state\n        // this is important for both success & error outcomes\n        _Log.Log.debug(\"ResponseValidator.validateSignoutResponse: state validated\");\n        response.state = state.data;\n\n        if (response.error) {\n            _Log.Log.warn(\"ResponseValidator.validateSignoutResponse: Response was error\", response.error);\n            return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processSigninParams = function _processSigninParams(state, response) {\n        if (state.id !== response.state) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: State does not match\");\n            return Promise.reject(new Error(\"State does not match\"));\n        }\n\n        if (!state.client_id) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: No client_id on state\");\n            return Promise.reject(new Error(\"No client_id on state\"));\n        }\n\n        if (!state.authority) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: No authority on state\");\n            return Promise.reject(new Error(\"No authority on state\"));\n        }\n\n        // this allows the authority to be loaded from the signin state\n        if (!this._settings.authority) {\n            this._settings.authority = state.authority;\n        }\n        // ensure we're using the correct authority if the authority is not loaded from signin state\n        else if (this._settings.authority && this._settings.authority !== state.authority) {\n                _Log.Log.error(\"ResponseValidator._processSigninParams: authority mismatch on settings vs. signin state\");\n                return Promise.reject(new Error(\"authority mismatch on settings vs. signin state\"));\n            }\n        // this allows the client_id to be loaded from the signin state\n        if (!this._settings.client_id) {\n            this._settings.client_id = state.client_id;\n        }\n        // ensure we're using the correct client_id if the client_id is not loaded from signin state\n        else if (this._settings.client_id && this._settings.client_id !== state.client_id) {\n                _Log.Log.error(\"ResponseValidator._processSigninParams: client_id mismatch on settings vs. signin state\");\n                return Promise.reject(new Error(\"client_id mismatch on settings vs. signin state\"));\n            }\n\n        // now that we know the state matches, take the stored data\n        // and set it into the response so callers can get their state\n        // this is important for both success & error outcomes\n        _Log.Log.debug(\"ResponseValidator._processSigninParams: state validated\");\n        response.state = state.data;\n\n        if (response.error) {\n            _Log.Log.warn(\"ResponseValidator._processSigninParams: Response was error\", response.error);\n            return Promise.reject(new _ErrorResponse.ErrorResponse(response));\n        }\n\n        if (state.nonce && !response.id_token) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Expecting id_token in response\");\n            return Promise.reject(new Error(\"No id_token in response\"));\n        }\n\n        if (!state.nonce && response.id_token) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Not expecting id_token in response\");\n            return Promise.reject(new Error(\"Unexpected id_token in response\"));\n        }\n\n        if (state.code_verifier && !response.code) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Expecting code in response\");\n            return Promise.reject(new Error(\"No code in response\"));\n        }\n\n        if (!state.code_verifier && response.code) {\n            _Log.Log.error(\"ResponseValidator._processSigninParams: Not expecting code in response\");\n            return Promise.reject(new Error(\"Unexpected code in response\"));\n        }\n\n        if (!response.scope) {\n            // if there's no scope on the response, then assume all scopes granted (per-spec) and copy over scopes from original request\n            response.scope = state.scope;\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processClaims = function _processClaims(state, response) {\n        var _this2 = this;\n\n        if (response.isOpenIdConnect) {\n            _Log.Log.debug(\"ResponseValidator._processClaims: response is OIDC, processing claims\");\n\n            response.profile = this._filterProtocolClaims(response.profile);\n\n            if (state.skipUserInfo !== true && this._settings.loadUserInfo && response.access_token) {\n                _Log.Log.debug(\"ResponseValidator._processClaims: loading user info\");\n\n                return this._userInfoService.getClaims(response.access_token).then(function (claims) {\n                    _Log.Log.debug(\"ResponseValidator._processClaims: user info claims received from user info endpoint\");\n\n                    if (claims.sub !== response.profile.sub) {\n                        _Log.Log.error(\"ResponseValidator._processClaims: sub from user info endpoint does not match sub in access_token\");\n                        return Promise.reject(new Error(\"sub from user info endpoint does not match sub in access_token\"));\n                    }\n\n                    response.profile = _this2._mergeClaims(response.profile, claims);\n                    _Log.Log.debug(\"ResponseValidator._processClaims: user info claims received, updated profile:\", response.profile);\n\n                    return response;\n                });\n            } else {\n                _Log.Log.debug(\"ResponseValidator._processClaims: not loading user info\");\n            }\n        } else {\n            _Log.Log.debug(\"ResponseValidator._processClaims: response is not OIDC, not processing claims\");\n        }\n\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._mergeClaims = function _mergeClaims(claims1, claims2) {\n        var result = Object.assign({}, claims1);\n\n        for (var name in claims2) {\n            var values = claims2[name];\n            if (!Array.isArray(values)) {\n                values = [values];\n            }\n\n            for (var i = 0; i < values.length; i++) {\n                var value = values[i];\n                if (!result[name]) {\n                    result[name] = value;\n                } else if (Array.isArray(result[name])) {\n                    if (result[name].indexOf(value) < 0) {\n                        result[name].push(value);\n                    }\n                } else if (result[name] !== value) {\n                    if ((typeof value === 'undefined' ? 'undefined' : _typeof(value)) === 'object') {\n                        result[name] = this._mergeClaims(result[name], value);\n                    } else {\n                        result[name] = [result[name], value];\n                    }\n                }\n            }\n        }\n\n        return result;\n    };\n\n    ResponseValidator.prototype._filterProtocolClaims = function _filterProtocolClaims(claims) {\n        _Log.Log.debug(\"ResponseValidator._filterProtocolClaims, incoming claims:\", claims);\n\n        var result = Object.assign({}, claims);\n\n        if (this._settings._filterProtocolClaims) {\n            ProtocolClaims.forEach(function (type) {\n                delete result[type];\n            });\n\n            _Log.Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims filtered\", result);\n        } else {\n            _Log.Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims not filtered\");\n        }\n\n        return result;\n    };\n\n    ResponseValidator.prototype._validateTokens = function _validateTokens(state, response) {\n        if (response.code) {\n            _Log.Log.debug(\"ResponseValidator._validateTokens: Validating code\");\n            return this._processCode(state, response);\n        }\n\n        if (response.id_token) {\n            if (response.access_token) {\n                _Log.Log.debug(\"ResponseValidator._validateTokens: Validating id_token and access_token\");\n                return this._validateIdTokenAndAccessToken(state, response);\n            }\n\n            _Log.Log.debug(\"ResponseValidator._validateTokens: Validating id_token\");\n            return this._validateIdToken(state, response);\n        }\n\n        _Log.Log.debug(\"ResponseValidator._validateTokens: No code to process or id_token to validate\");\n        return Promise.resolve(response);\n    };\n\n    ResponseValidator.prototype._processCode = function _processCode(state, response) {\n        var _this3 = this;\n\n        var request = {\n            client_id: state.client_id,\n            client_secret: state.client_secret,\n            code: response.code,\n            redirect_uri: state.redirect_uri,\n            code_verifier: state.code_verifier\n        };\n\n        if (state.extraTokenParams && _typeof(state.extraTokenParams) === 'object') {\n            Object.assign(request, state.extraTokenParams);\n        }\n\n        return this._tokenClient.exchangeCode(request).then(function (tokenResponse) {\n\n            for (var key in tokenResponse) {\n                response[key] = tokenResponse[key];\n            }\n\n            if (response.id_token) {\n                _Log.Log.debug(\"ResponseValidator._processCode: token response successful, processing id_token\");\n                return _this3._validateIdTokenAttributes(state, response);\n            } else {\n                _Log.Log.debug(\"ResponseValidator._processCode: token response successful, returning response\");\n            }\n\n            return response;\n        });\n    };\n\n    ResponseValidator.prototype._validateIdTokenAttributes = function _validateIdTokenAttributes(state, response) {\n        var _this4 = this;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n\n            var audience = state.client_id;\n            var clockSkewInSeconds = _this4._settings.clockSkew;\n            _Log.Log.debug(\"ResponseValidator._validateIdTokenAttributes: Validaing JWT attributes; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n            return _this4._joseUtil.validateJwtAttributes(response.id_token, issuer, audience, clockSkewInSeconds).then(function (payload) {\n\n                if (state.nonce && state.nonce !== payload.nonce) {\n                    _Log.Log.error(\"ResponseValidator._validateIdTokenAttributes: Invalid nonce in id_token\");\n                    return Promise.reject(new Error(\"Invalid nonce in id_token\"));\n                }\n\n                if (!payload.sub) {\n                    _Log.Log.error(\"ResponseValidator._validateIdTokenAttributes: No sub present in id_token\");\n                    return Promise.reject(new Error(\"No sub present in id_token\"));\n                }\n\n                response.profile = payload;\n                return response;\n            });\n        });\n    };\n\n    ResponseValidator.prototype._validateIdTokenAndAccessToken = function _validateIdTokenAndAccessToken(state, response) {\n        var _this5 = this;\n\n        return this._validateIdToken(state, response).then(function (response) {\n            return _this5._validateAccessToken(response);\n        });\n    };\n\n    ResponseValidator.prototype._validateIdToken = function _validateIdToken(state, response) {\n        var _this6 = this;\n\n        if (!state.nonce) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: No nonce on state\");\n            return Promise.reject(new Error(\"No nonce on state\"));\n        }\n\n        var jwt = this._joseUtil.parseJwt(response.id_token);\n        if (!jwt || !jwt.header || !jwt.payload) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: Failed to parse id_token\", jwt);\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\n        }\n\n        if (state.nonce !== jwt.payload.nonce) {\n            _Log.Log.error(\"ResponseValidator._validateIdToken: Invalid nonce in id_token\");\n            return Promise.reject(new Error(\"Invalid nonce in id_token\"));\n        }\n\n        var kid = jwt.header.kid;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n            _Log.Log.debug(\"ResponseValidator._validateIdToken: Received issuer\");\n\n            return _this6._metadataService.getSigningKeys().then(function (keys) {\n                if (!keys) {\n                    _Log.Log.error(\"ResponseValidator._validateIdToken: No signing keys from metadata\");\n                    return Promise.reject(new Error(\"No signing keys from metadata\"));\n                }\n\n                _Log.Log.debug(\"ResponseValidator._validateIdToken: Received signing keys\");\n                var key = void 0;\n                if (!kid) {\n                    keys = _this6._filterByAlg(keys, jwt.header.alg);\n\n                    if (keys.length > 1) {\n                        _Log.Log.error(\"ResponseValidator._validateIdToken: No kid found in id_token and more than one key found in metadata\");\n                        return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\n                    } else {\n                        // kid is mandatory only when there are multiple keys in the referenced JWK Set document\n                        // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\n                        key = keys[0];\n                    }\n                } else {\n                    key = keys.filter(function (key) {\n                        return key.kid === kid;\n                    })[0];\n                }\n\n                if (!key) {\n                    _Log.Log.error(\"ResponseValidator._validateIdToken: No key matching kid or alg found in signing keys\");\n                    return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\n                }\n\n                var audience = state.client_id;\n\n                var clockSkewInSeconds = _this6._settings.clockSkew;\n                _Log.Log.debug(\"ResponseValidator._validateIdToken: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n                return _this6._joseUtil.validateJwt(response.id_token, key, issuer, audience, clockSkewInSeconds).then(function () {\n                    _Log.Log.debug(\"ResponseValidator._validateIdToken: JWT validation successful\");\n\n                    if (!jwt.payload.sub) {\n                        _Log.Log.error(\"ResponseValidator._validateIdToken: No sub present in id_token\");\n                        return Promise.reject(new Error(\"No sub present in id_token\"));\n                    }\n\n                    response.profile = jwt.payload;\n\n                    return response;\n                });\n            });\n        });\n    };\n\n    ResponseValidator.prototype._filterByAlg = function _filterByAlg(keys, alg) {\n        var kty = null;\n        if (alg.startsWith(\"RS\")) {\n            kty = \"RSA\";\n        } else if (alg.startsWith(\"PS\")) {\n            kty = \"PS\";\n        } else if (alg.startsWith(\"ES\")) {\n            kty = \"EC\";\n        } else {\n            _Log.Log.debug(\"ResponseValidator._filterByAlg: alg not supported: \", alg);\n            return [];\n        }\n\n        _Log.Log.debug(\"ResponseValidator._filterByAlg: Looking for keys that match kty: \", kty);\n\n        keys = keys.filter(function (key) {\n            return key.kty === kty;\n        });\n\n        _Log.Log.debug(\"ResponseValidator._filterByAlg: Number of keys that match kty: \", kty, keys.length);\n\n        return keys;\n    };\n\n    ResponseValidator.prototype._validateAccessToken = function _validateAccessToken(response) {\n        if (!response.profile) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No profile loaded from id_token\");\n            return Promise.reject(new Error(\"No profile loaded from id_token\"));\n        }\n\n        if (!response.profile.at_hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No at_hash in id_token\");\n            return Promise.reject(new Error(\"No at_hash in id_token\"));\n        }\n\n        if (!response.id_token) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: No id_token\");\n            return Promise.reject(new Error(\"No id_token\"));\n        }\n\n        var jwt = this._joseUtil.parseJwt(response.id_token);\n        if (!jwt || !jwt.header) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Failed to parse id_token\", jwt);\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\n        }\n\n        var hashAlg = jwt.header.alg;\n        if (!hashAlg || hashAlg.length !== 5) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        var hashBits = hashAlg.substr(2, 3);\n        if (!hashBits) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        hashBits = parseInt(hashBits);\n        if (hashBits !== 256 && hashBits !== 384 && hashBits !== 512) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\n        }\n\n        var sha = \"sha\" + hashBits;\n        var hash = this._joseUtil.hashString(response.access_token, sha);\n        if (!hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: access_token hash failed:\", sha);\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\n        }\n\n        var left = hash.substr(0, hash.length / 2);\n        var left_b64u = this._joseUtil.hexToBase64Url(left);\n        if (left_b64u !== response.profile.at_hash) {\n            _Log.Log.error(\"ResponseValidator._validateAccessToken: Failed to validate at_hash\", left_b64u, response.profile.at_hash);\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\n        }\n\n        _Log.Log.debug(\"ResponseValidator._validateAccessToken: success\");\n\n        return Promise.resolve(response);\n    };\n\n    return ResponseValidator;\n}();\n\n/***/ }),\n\n/***/ \"./src/SessionMonitor.js\":\n/*!*******************************!*\\\n  !*** ./src/SessionMonitor.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SessionMonitor = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _CheckSessionIFrame = __webpack_require__(/*! ./CheckSessionIFrame.js */ \"./src/CheckSessionIFrame.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar SessionMonitor = exports.SessionMonitor = function () {\n    function SessionMonitor(userManager) {\n        var _this = this;\n\n        var CheckSessionIFrameCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _CheckSessionIFrame.CheckSessionIFrame;\n        var timer = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _Global.Global.timer;\n\n        _classCallCheck(this, SessionMonitor);\n\n        if (!userManager) {\n            _Log.Log.error(\"SessionMonitor.ctor: No user manager passed to SessionMonitor\");\n            throw new Error(\"userManager\");\n        }\n\n        this._userManager = userManager;\n        this._CheckSessionIFrameCtor = CheckSessionIFrameCtor;\n        this._timer = timer;\n\n        this._userManager.events.addUserLoaded(this._start.bind(this));\n        this._userManager.events.addUserUnloaded(this._stop.bind(this));\n\n        this._userManager.getUser().then(function (user) {\n            // doing this manually here since calling getUser \n            // doesn't trigger load event.\n            if (user) {\n                _this._start(user);\n            } else if (_this._settings.monitorAnonymousSession) {\n                _this._userManager.querySessionStatus().then(function (session) {\n                    var tmpUser = {\n                        session_state: session.session_state\n                    };\n                    if (session.sub && session.sid) {\n                        tmpUser.profile = {\n                            sub: session.sub,\n                            sid: session.sid\n                        };\n                    }\n                    _this._start(tmpUser);\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in a ctor\n                    _Log.Log.error(\"SessionMonitor ctor: error from querySessionStatus:\", err.message);\n                });\n            }\n        }).catch(function (err) {\n            // catch to suppress errors since we're in a ctor\n            _Log.Log.error(\"SessionMonitor ctor: error from getUser:\", err.message);\n        });\n    }\n\n    SessionMonitor.prototype._start = function _start(user) {\n        var _this2 = this;\n\n        var session_state = user.session_state;\n\n        if (session_state) {\n            if (user.profile) {\n                this._sub = user.profile.sub;\n                this._sid = user.profile.sid;\n                _Log.Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", sub:\", this._sub);\n            } else {\n                this._sub = undefined;\n                this._sid = undefined;\n                _Log.Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", anonymous user\");\n            }\n\n            if (!this._checkSessionIFrame) {\n                this._metadataService.getCheckSessionIframe().then(function (url) {\n                    if (url) {\n                        _Log.Log.debug(\"SessionMonitor._start: Initializing check session iframe\");\n\n                        var client_id = _this2._client_id;\n                        var interval = _this2._checkSessionInterval;\n                        var stopOnError = _this2._stopCheckSessionOnError;\n\n                        _this2._checkSessionIFrame = new _this2._CheckSessionIFrameCtor(_this2._callback.bind(_this2), client_id, url, interval, stopOnError);\n                        _this2._checkSessionIFrame.load().then(function () {\n                            _this2._checkSessionIFrame.start(session_state);\n                        });\n                    } else {\n                        _Log.Log.warn(\"SessionMonitor._start: No check session iframe found in the metadata\");\n                    }\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in non-promise callback\n                    _Log.Log.error(\"SessionMonitor._start: Error from getCheckSessionIframe:\", err.message);\n                });\n            } else {\n                this._checkSessionIFrame.start(session_state);\n            }\n        }\n    };\n\n    SessionMonitor.prototype._stop = function _stop() {\n        var _this3 = this;\n\n        this._sub = undefined;\n        this._sid = undefined;\n\n        if (this._checkSessionIFrame) {\n            _Log.Log.debug(\"SessionMonitor._stop\");\n            this._checkSessionIFrame.stop();\n        }\n\n        if (this._settings.monitorAnonymousSession) {\n            // using a timer to delay re-initialization to avoid race conditions during signout\n            var timerHandle = this._timer.setInterval(function () {\n                _this3._timer.clearInterval(timerHandle);\n\n                _this3._userManager.querySessionStatus().then(function (session) {\n                    var tmpUser = {\n                        session_state: session.session_state\n                    };\n                    if (session.sub && session.sid) {\n                        tmpUser.profile = {\n                            sub: session.sub,\n                            sid: session.sid\n                        };\n                    }\n                    _this3._start(tmpUser);\n                }).catch(function (err) {\n                    // catch to suppress errors since we're in a callback\n                    _Log.Log.error(\"SessionMonitor: error from querySessionStatus:\", err.message);\n                });\n            }, 1000);\n        }\n    };\n\n    SessionMonitor.prototype._callback = function _callback() {\n        var _this4 = this;\n\n        this._userManager.querySessionStatus().then(function (session) {\n            var raiseEvent = true;\n\n            if (session) {\n                if (session.sub === _this4._sub) {\n                    raiseEvent = false;\n                    _this4._checkSessionIFrame.start(session.session_state);\n\n                    if (session.sid === _this4._sid) {\n                        _Log.Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, restarting check session iframe; session_state:\", session.session_state);\n                    } else {\n                        _Log.Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, session state has changed, restarting check session iframe; session_state:\", session.session_state);\n                        _this4._userManager.events._raiseUserSessionChanged();\n                    }\n                } else {\n                    _Log.Log.debug(\"SessionMonitor._callback: Different subject signed into OP:\", session.sub);\n                }\n            } else {\n                _Log.Log.debug(\"SessionMonitor._callback: Subject no longer signed into OP\");\n            }\n\n            if (raiseEvent) {\n                if (_this4._sub) {\n                    _Log.Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed out event\");\n                    _this4._userManager.events._raiseUserSignedOut();\n                } else {\n                    _Log.Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed in event\");\n                    _this4._userManager.events._raiseUserSignedIn();\n                }\n            }\n        }).catch(function (err) {\n            if (_this4._sub) {\n                _Log.Log.debug(\"SessionMonitor._callback: Error calling queryCurrentSigninSession; raising signed out event\", err.message);\n                _this4._userManager.events._raiseUserSignedOut();\n            }\n        });\n    };\n\n    _createClass(SessionMonitor, [{\n        key: '_settings',\n        get: function get() {\n            return this._userManager.settings;\n        }\n    }, {\n        key: '_metadataService',\n        get: function get() {\n            return this._userManager.metadataService;\n        }\n    }, {\n        key: '_client_id',\n        get: function get() {\n            return this._settings.client_id;\n        }\n    }, {\n        key: '_checkSessionInterval',\n        get: function get() {\n            return this._settings.checkSessionInterval;\n        }\n    }, {\n        key: '_stopCheckSessionOnError',\n        get: function get() {\n            return this._settings.stopCheckSessionOnError;\n        }\n    }]);\n\n    return SessionMonitor;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninRequest.js\":\n/*!******************************!*\\\n  !*** ./src/SigninRequest.js ***!\n  \\******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninRequest = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nvar _SigninState = __webpack_require__(/*! ./SigninState.js */ \"./src/SigninState.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SigninRequest = exports.SigninRequest = function () {\n    function SigninRequest(_ref) {\n        var url = _ref.url,\n            client_id = _ref.client_id,\n            redirect_uri = _ref.redirect_uri,\n            response_type = _ref.response_type,\n            scope = _ref.scope,\n            authority = _ref.authority,\n            data = _ref.data,\n            prompt = _ref.prompt,\n            display = _ref.display,\n            max_age = _ref.max_age,\n            ui_locales = _ref.ui_locales,\n            id_token_hint = _ref.id_token_hint,\n            login_hint = _ref.login_hint,\n            acr_values = _ref.acr_values,\n            resource = _ref.resource,\n            response_mode = _ref.response_mode,\n            request = _ref.request,\n            request_uri = _ref.request_uri,\n            extraQueryParams = _ref.extraQueryParams,\n            request_type = _ref.request_type,\n            client_secret = _ref.client_secret,\n            extraTokenParams = _ref.extraTokenParams,\n            skipUserInfo = _ref.skipUserInfo;\n\n        _classCallCheck(this, SigninRequest);\n\n        if (!url) {\n            _Log.Log.error(\"SigninRequest.ctor: No url passed\");\n            throw new Error(\"url\");\n        }\n        if (!client_id) {\n            _Log.Log.error(\"SigninRequest.ctor: No client_id passed\");\n            throw new Error(\"client_id\");\n        }\n        if (!redirect_uri) {\n            _Log.Log.error(\"SigninRequest.ctor: No redirect_uri passed\");\n            throw new Error(\"redirect_uri\");\n        }\n        if (!response_type) {\n            _Log.Log.error(\"SigninRequest.ctor: No response_type passed\");\n            throw new Error(\"response_type\");\n        }\n        if (!scope) {\n            _Log.Log.error(\"SigninRequest.ctor: No scope passed\");\n            throw new Error(\"scope\");\n        }\n        if (!authority) {\n            _Log.Log.error(\"SigninRequest.ctor: No authority passed\");\n            throw new Error(\"authority\");\n        }\n\n        var oidc = SigninRequest.isOidc(response_type);\n        var code = SigninRequest.isCode(response_type);\n\n        if (!response_mode) {\n            response_mode = SigninRequest.isCode(response_type) ? \"query\" : null;\n        }\n\n        this.state = new _SigninState.SigninState({ nonce: oidc,\n            data: data, client_id: client_id, authority: authority, redirect_uri: redirect_uri,\n            code_verifier: code,\n            request_type: request_type, response_mode: response_mode,\n            client_secret: client_secret, scope: scope, extraTokenParams: extraTokenParams, skipUserInfo: skipUserInfo });\n\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"client_id\", client_id);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"redirect_uri\", redirect_uri);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"response_type\", response_type);\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"scope\", scope);\n\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"state\", this.state.id);\n        if (oidc) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"nonce\", this.state.nonce);\n        }\n        if (code) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"code_challenge\", this.state.code_challenge);\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"code_challenge_method\", \"S256\");\n        }\n\n        var optional = { prompt: prompt, display: display, max_age: max_age, ui_locales: ui_locales, id_token_hint: id_token_hint, login_hint: login_hint, acr_values: acr_values, resource: resource, request: request, request_uri: request_uri, response_mode: response_mode };\n        for (var key in optional) {\n            if (optional[key]) {\n                url = _UrlUtility.UrlUtility.addQueryParam(url, key, optional[key]);\n            }\n        }\n\n        for (var _key in extraQueryParams) {\n            url = _UrlUtility.UrlUtility.addQueryParam(url, _key, extraQueryParams[_key]);\n        }\n\n        this.url = url;\n    }\n\n    SigninRequest.isOidc = function isOidc(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"id_token\";\n        });\n        return !!result[0];\n    };\n\n    SigninRequest.isOAuth = function isOAuth(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"token\";\n        });\n        return !!result[0];\n    };\n\n    SigninRequest.isCode = function isCode(response_type) {\n        var result = response_type.split(/\\s+/g).filter(function (item) {\n            return item === \"code\";\n        });\n        return !!result[0];\n    };\n\n    return SigninRequest;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninResponse.js\":\n/*!*******************************!*\\\n  !*** ./src/SigninResponse.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninResponse = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar OidcScope = \"openid\";\n\nvar SigninResponse = exports.SigninResponse = function () {\n    function SigninResponse(url) {\n        var delimiter = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : \"#\";\n\n        _classCallCheck(this, SigninResponse);\n\n        var values = _UrlUtility.UrlUtility.parseUrlFragment(url, delimiter);\n\n        this.error = values.error;\n        this.error_description = values.error_description;\n        this.error_uri = values.error_uri;\n\n        this.code = values.code;\n        this.state = values.state;\n        this.id_token = values.id_token;\n        this.session_state = values.session_state;\n        this.access_token = values.access_token;\n        this.token_type = values.token_type;\n        this.scope = values.scope;\n        this.profile = undefined; // will be set from ResponseValidator\n\n        this.expires_in = values.expires_in;\n    }\n\n    _createClass(SigninResponse, [{\n        key: \"expires_in\",\n        get: function get() {\n            if (this.expires_at) {\n                var now = parseInt(Date.now() / 1000);\n                return this.expires_at - now;\n            }\n            return undefined;\n        },\n        set: function set(value) {\n            var expires_in = parseInt(value);\n            if (typeof expires_in === 'number' && expires_in > 0) {\n                var now = parseInt(Date.now() / 1000);\n                this.expires_at = now + expires_in;\n            }\n        }\n    }, {\n        key: \"expired\",\n        get: function get() {\n            var expires_in = this.expires_in;\n            if (expires_in !== undefined) {\n                return expires_in <= 0;\n            }\n            return undefined;\n        }\n    }, {\n        key: \"scopes\",\n        get: function get() {\n            return (this.scope || \"\").split(\" \");\n        }\n    }, {\n        key: \"isOpenIdConnect\",\n        get: function get() {\n            return this.scopes.indexOf(OidcScope) >= 0 || !!this.id_token;\n        }\n    }]);\n\n    return SigninResponse;\n}();\n\n/***/ }),\n\n/***/ \"./src/SigninState.js\":\n/*!****************************!*\\\n  !*** ./src/SigninState.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SigninState = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _State2 = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nvar _random = __webpack_require__(/*! ./random.js */ \"./src/random.js\");\n\nvar _random2 = _interopRequireDefault(_random);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SigninState = exports.SigninState = function (_State) {\n    _inherits(SigninState, _State);\n\n    function SigninState() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            nonce = _ref.nonce,\n            authority = _ref.authority,\n            client_id = _ref.client_id,\n            redirect_uri = _ref.redirect_uri,\n            code_verifier = _ref.code_verifier,\n            response_mode = _ref.response_mode,\n            client_secret = _ref.client_secret,\n            scope = _ref.scope,\n            extraTokenParams = _ref.extraTokenParams,\n            skipUserInfo = _ref.skipUserInfo;\n\n        _classCallCheck(this, SigninState);\n\n        var _this = _possibleConstructorReturn(this, _State.call(this, arguments[0]));\n\n        if (nonce === true) {\n            _this._nonce = (0, _random2.default)();\n        } else if (nonce) {\n            _this._nonce = nonce;\n        }\n\n        if (code_verifier === true) {\n            // random() produces 32 length\n            _this._code_verifier = (0, _random2.default)() + (0, _random2.default)() + (0, _random2.default)();\n        } else if (code_verifier) {\n            _this._code_verifier = code_verifier;\n        }\n\n        if (_this.code_verifier) {\n            var hash = _JoseUtil.JoseUtil.hashString(_this.code_verifier, \"SHA256\");\n            _this._code_challenge = _JoseUtil.JoseUtil.hexToBase64Url(hash);\n        }\n\n        _this._redirect_uri = redirect_uri;\n        _this._authority = authority;\n        _this._client_id = client_id;\n        _this._response_mode = response_mode;\n        _this._client_secret = client_secret;\n        _this._scope = scope;\n        _this._extraTokenParams = extraTokenParams;\n        _this._skipUserInfo = skipUserInfo;\n        return _this;\n    }\n\n    SigninState.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"SigninState.toStorageString\");\n        return JSON.stringify({\n            id: this.id,\n            data: this.data,\n            created: this.created,\n            request_type: this.request_type,\n            nonce: this.nonce,\n            code_verifier: this.code_verifier,\n            redirect_uri: this.redirect_uri,\n            authority: this.authority,\n            client_id: this.client_id,\n            response_mode: this.response_mode,\n            client_secret: this.client_secret,\n            scope: this.scope,\n            extraTokenParams: this.extraTokenParams,\n            skipUserInfo: this.skipUserInfo\n        });\n    };\n\n    SigninState.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"SigninState.fromStorageString\");\n        var data = JSON.parse(storageString);\n        return new SigninState(data);\n    };\n\n    _createClass(SigninState, [{\n        key: 'nonce',\n        get: function get() {\n            return this._nonce;\n        }\n    }, {\n        key: 'authority',\n        get: function get() {\n            return this._authority;\n        }\n    }, {\n        key: 'client_id',\n        get: function get() {\n            return this._client_id;\n        }\n    }, {\n        key: 'redirect_uri',\n        get: function get() {\n            return this._redirect_uri;\n        }\n    }, {\n        key: 'code_verifier',\n        get: function get() {\n            return this._code_verifier;\n        }\n    }, {\n        key: 'code_challenge',\n        get: function get() {\n            return this._code_challenge;\n        }\n    }, {\n        key: 'response_mode',\n        get: function get() {\n            return this._response_mode;\n        }\n    }, {\n        key: 'client_secret',\n        get: function get() {\n            return this._client_secret;\n        }\n    }, {\n        key: 'scope',\n        get: function get() {\n            return this._scope;\n        }\n    }, {\n        key: 'extraTokenParams',\n        get: function get() {\n            return this._extraTokenParams;\n        }\n    }, {\n        key: 'skipUserInfo',\n        get: function get() {\n            return this._skipUserInfo;\n        }\n    }]);\n\n    return SigninState;\n}(_State2.State);\n\n/***/ }),\n\n/***/ \"./src/SignoutRequest.js\":\n/*!*******************************!*\\\n  !*** ./src/SignoutRequest.js ***!\n  \\*******************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SignoutRequest = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nvar _State = __webpack_require__(/*! ./State.js */ \"./src/State.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SignoutRequest = exports.SignoutRequest = function SignoutRequest(_ref) {\n    var url = _ref.url,\n        id_token_hint = _ref.id_token_hint,\n        post_logout_redirect_uri = _ref.post_logout_redirect_uri,\n        data = _ref.data,\n        extraQueryParams = _ref.extraQueryParams,\n        request_type = _ref.request_type;\n\n    _classCallCheck(this, SignoutRequest);\n\n    if (!url) {\n        _Log.Log.error(\"SignoutRequest.ctor: No url passed\");\n        throw new Error(\"url\");\n    }\n\n    if (id_token_hint) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"id_token_hint\", id_token_hint);\n    }\n\n    if (post_logout_redirect_uri) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, \"post_logout_redirect_uri\", post_logout_redirect_uri);\n\n        if (data) {\n            this.state = new _State.State({ data: data, request_type: request_type });\n\n            url = _UrlUtility.UrlUtility.addQueryParam(url, \"state\", this.state.id);\n        }\n    }\n\n    for (var key in extraQueryParams) {\n        url = _UrlUtility.UrlUtility.addQueryParam(url, key, extraQueryParams[key]);\n    }\n\n    this.url = url;\n};\n\n/***/ }),\n\n/***/ \"./src/SignoutResponse.js\":\n/*!********************************!*\\\n  !*** ./src/SignoutResponse.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n        value: true\n});\nexports.SignoutResponse = undefined;\n\nvar _UrlUtility = __webpack_require__(/*! ./UrlUtility.js */ \"./src/UrlUtility.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SignoutResponse = exports.SignoutResponse = function SignoutResponse(url) {\n        _classCallCheck(this, SignoutResponse);\n\n        var values = _UrlUtility.UrlUtility.parseUrlFragment(url, \"?\");\n\n        this.error = values.error;\n        this.error_description = values.error_description;\n        this.error_uri = values.error_uri;\n\n        this.state = values.state;\n};\n\n/***/ }),\n\n/***/ \"./src/SilentRenewService.js\":\n/*!***********************************!*\\\n  !*** ./src/SilentRenewService.js ***!\n  \\***********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.SilentRenewService = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar SilentRenewService = exports.SilentRenewService = function () {\n    function SilentRenewService(userManager) {\n        _classCallCheck(this, SilentRenewService);\n\n        this._userManager = userManager;\n    }\n\n    SilentRenewService.prototype.start = function start() {\n        if (!this._callback) {\n            this._callback = this._tokenExpiring.bind(this);\n            this._userManager.events.addAccessTokenExpiring(this._callback);\n\n            // this will trigger loading of the user so the expiring events can be initialized\n            this._userManager.getUser().then(function (user) {\n                // deliberate nop\n            }).catch(function (err) {\n                // catch to suppress errors since we're in a ctor\n                _Log.Log.error(\"SilentRenewService.start: Error from getUser:\", err.message);\n            });\n        }\n    };\n\n    SilentRenewService.prototype.stop = function stop() {\n        if (this._callback) {\n            this._userManager.events.removeAccessTokenExpiring(this._callback);\n            delete this._callback;\n        }\n    };\n\n    SilentRenewService.prototype._tokenExpiring = function _tokenExpiring() {\n        var _this = this;\n\n        this._userManager.signinSilent().then(function (user) {\n            _Log.Log.debug(\"SilentRenewService._tokenExpiring: Silent token renewal successful\");\n        }, function (err) {\n            _Log.Log.error(\"SilentRenewService._tokenExpiring: Error from signinSilent:\", err.message);\n            _this._userManager.events._raiseSilentRenewError(err);\n        });\n    };\n\n    return SilentRenewService;\n}();\n\n/***/ }),\n\n/***/ \"./src/State.js\":\n/*!**********************!*\\\n  !*** ./src/State.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.State = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _random = __webpack_require__(/*! ./random.js */ \"./src/random.js\");\n\nvar _random2 = _interopRequireDefault(_random);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar State = exports.State = function () {\n    function State() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            id = _ref.id,\n            data = _ref.data,\n            created = _ref.created,\n            request_type = _ref.request_type;\n\n        _classCallCheck(this, State);\n\n        this._id = id || (0, _random2.default)();\n        this._data = data;\n\n        if (typeof created === 'number' && created > 0) {\n            this._created = created;\n        } else {\n            this._created = parseInt(Date.now() / 1000);\n        }\n        this._request_type = request_type;\n    }\n\n    State.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"State.toStorageString\");\n        return JSON.stringify({\n            id: this.id,\n            data: this.data,\n            created: this.created,\n            request_type: this.request_type\n        });\n    };\n\n    State.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"State.fromStorageString\");\n        return new State(JSON.parse(storageString));\n    };\n\n    State.clearStaleState = function clearStaleState(storage, age) {\n\n        var cutoff = Date.now() / 1000 - age;\n\n        return storage.getAllKeys().then(function (keys) {\n            _Log.Log.debug(\"State.clearStaleState: got keys\", keys);\n\n            var promises = [];\n\n            var _loop = function _loop(i) {\n                var key = keys[i];\n                p = storage.get(key).then(function (item) {\n                    var remove = false;\n\n                    if (item) {\n                        try {\n                            var state = State.fromStorageString(item);\n\n                            _Log.Log.debug(\"State.clearStaleState: got item from key: \", key, state.created);\n\n                            if (state.created <= cutoff) {\n                                remove = true;\n                            }\n                        } catch (e) {\n                            _Log.Log.error(\"State.clearStaleState: Error parsing state for key\", key, e.message);\n                            remove = true;\n                        }\n                    } else {\n                        _Log.Log.debug(\"State.clearStaleState: no item in storage for key: \", key);\n                        remove = true;\n                    }\n\n                    if (remove) {\n                        _Log.Log.debug(\"State.clearStaleState: removed item for key: \", key);\n                        return storage.remove(key);\n                    }\n                });\n\n\n                promises.push(p);\n            };\n\n            for (var i = 0; i < keys.length; i++) {\n                var p;\n\n                _loop(i);\n            }\n\n            _Log.Log.debug(\"State.clearStaleState: waiting on promise count:\", promises.length);\n            return Promise.all(promises);\n        });\n    };\n\n    _createClass(State, [{\n        key: 'id',\n        get: function get() {\n            return this._id;\n        }\n    }, {\n        key: 'data',\n        get: function get() {\n            return this._data;\n        }\n    }, {\n        key: 'created',\n        get: function get() {\n            return this._created;\n        }\n    }, {\n        key: 'request_type',\n        get: function get() {\n            return this._request_type;\n        }\n    }]);\n\n    return State;\n}();\n\n/***/ }),\n\n/***/ \"./src/Timer.js\":\n/*!**********************!*\\\n  !*** ./src/Timer.js ***!\n  \\**********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.Timer = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nvar _Event2 = __webpack_require__(/*! ./Event.js */ \"./src/Event.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar TimerDuration = 5; // seconds\n\nvar Timer = exports.Timer = function (_Event) {\n    _inherits(Timer, _Event);\n\n    function Timer(name) {\n        var timer = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.timer;\n        var nowFunc = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : undefined;\n\n        _classCallCheck(this, Timer);\n\n        var _this = _possibleConstructorReturn(this, _Event.call(this, name));\n\n        _this._timer = timer;\n\n        if (nowFunc) {\n            _this._nowFunc = nowFunc;\n        } else {\n            _this._nowFunc = function () {\n                return Date.now() / 1000;\n            };\n        }\n        return _this;\n    }\n\n    Timer.prototype.init = function init(duration) {\n        if (duration <= 0) {\n            duration = 1;\n        }\n        duration = parseInt(duration);\n\n        var expiration = this.now + duration;\n        if (this.expiration === expiration && this._timerHandle) {\n            // no need to reinitialize to same expiration, so bail out\n            _Log.Log.debug(\"Timer.init timer \" + this._name + \" skipping initialization since already initialized for expiration:\", this.expiration);\n            return;\n        }\n\n        this.cancel();\n\n        _Log.Log.debug(\"Timer.init timer \" + this._name + \" for duration:\", duration);\n        this._expiration = expiration;\n\n        // we're using a fairly short timer and then checking the expiration in the\n        // callback to handle scenarios where the browser device sleeps, and then\n        // the timers end up getting delayed.\n        var timerDuration = TimerDuration;\n        if (duration < timerDuration) {\n            timerDuration = duration;\n        }\n        this._timerHandle = this._timer.setInterval(this._callback.bind(this), timerDuration * 1000);\n    };\n\n    Timer.prototype.cancel = function cancel() {\n        if (this._timerHandle) {\n            _Log.Log.debug(\"Timer.cancel: \", this._name);\n            this._timer.clearInterval(this._timerHandle);\n            this._timerHandle = null;\n        }\n    };\n\n    Timer.prototype._callback = function _callback() {\n        var diff = this._expiration - this.now;\n        _Log.Log.debug(\"Timer.callback; \" + this._name + \" timer expires in:\", diff);\n\n        if (this._expiration <= this.now) {\n            this.cancel();\n            _Event.prototype.raise.call(this);\n        }\n    };\n\n    _createClass(Timer, [{\n        key: 'now',\n        get: function get() {\n            return parseInt(this._nowFunc());\n        }\n    }, {\n        key: 'expiration',\n        get: function get() {\n            return this._expiration;\n        }\n    }]);\n\n    return Timer;\n}(_Event2.Event);\n\n/***/ }),\n\n/***/ \"./src/TokenClient.js\":\n/*!****************************!*\\\n  !*** ./src/TokenClient.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.TokenClient = undefined;\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar TokenClient = exports.TokenClient = function () {\n    function TokenClient(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n\n        _classCallCheck(this, TokenClient);\n\n        if (!settings) {\n            _Log.Log.error(\"TokenClient.ctor: No settings passed\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor();\n        this._metadataService = new MetadataServiceCtor(this._settings);\n    }\n\n    TokenClient.prototype.exchangeCode = function exchangeCode() {\n        var _this = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.grant_type = args.grant_type || \"authorization_code\";\n        args.client_id = args.client_id || this._settings.client_id;\n        args.redirect_uri = args.redirect_uri || this._settings.redirect_uri;\n\n        if (!args.code) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No code passed\");\n            return Promise.reject(new Error(\"A code is required\"));\n        }\n        if (!args.redirect_uri) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No redirect_uri passed\");\n            return Promise.reject(new Error(\"A redirect_uri is required\"));\n        }\n        if (!args.code_verifier) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No code_verifier passed\");\n            return Promise.reject(new Error(\"A code_verifier is required\"));\n        }\n        if (!args.client_id) {\n            _Log.Log.error(\"TokenClient.exchangeCode: No client_id passed\");\n            return Promise.reject(new Error(\"A client_id is required\"));\n        }\n\n        return this._metadataService.getTokenEndpoint(false).then(function (url) {\n            _Log.Log.debug(\"TokenClient.exchangeCode: Received token endpoint\");\n\n            return _this._jsonService.postForm(url, args).then(function (response) {\n                _Log.Log.debug(\"TokenClient.exchangeCode: response received\");\n                return response;\n            });\n        });\n    };\n\n    TokenClient.prototype.exchangeRefreshToken = function exchangeRefreshToken() {\n        var _this2 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.grant_type = args.grant_type || \"refresh_token\";\n        args.client_id = args.client_id || this._settings.client_id;\n        args.client_secret = args.client_secret || this._settings.client_secret;\n\n        if (!args.refresh_token) {\n            _Log.Log.error(\"TokenClient.exchangeRefreshToken: No refresh_token passed\");\n            return Promise.reject(new Error(\"A refresh_token is required\"));\n        }\n        if (!args.client_id) {\n            _Log.Log.error(\"TokenClient.exchangeRefreshToken: No client_id passed\");\n            return Promise.reject(new Error(\"A client_id is required\"));\n        }\n\n        return this._metadataService.getTokenEndpoint(false).then(function (url) {\n            _Log.Log.debug(\"TokenClient.exchangeRefreshToken: Received token endpoint\");\n\n            return _this2._jsonService.postForm(url, args).then(function (response) {\n                _Log.Log.debug(\"TokenClient.exchangeRefreshToken: response received\");\n                return response;\n            });\n        });\n    };\n\n    return TokenClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/TokenRevocationClient.js\":\n/*!**************************************!*\\\n  !*** ./src/TokenRevocationClient.js ***!\n  \\**************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.TokenRevocationClient = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar AccessTokenTypeHint = \"access_token\";\nvar RefreshTokenTypeHint = \"refresh_token\";\n\nvar TokenRevocationClient = exports.TokenRevocationClient = function () {\n    function TokenRevocationClient(settings) {\n        var XMLHttpRequestCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _Global.Global.XMLHttpRequest;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n\n        _classCallCheck(this, TokenRevocationClient);\n\n        if (!settings) {\n            _Log.Log.error(\"TokenRevocationClient.ctor: No settings provided\");\n            throw new Error(\"No settings provided.\");\n        }\n\n        this._settings = settings;\n        this._XMLHttpRequestCtor = XMLHttpRequestCtor;\n        this._metadataService = new MetadataServiceCtor(this._settings);\n    }\n\n    TokenRevocationClient.prototype.revoke = function revoke(token, required) {\n        var _this = this;\n\n        var type = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : \"access_token\";\n\n        if (!token) {\n            _Log.Log.error(\"TokenRevocationClient.revoke: No token provided\");\n            throw new Error(\"No token provided.\");\n        }\n\n        if (type !== AccessTokenTypeHint && type != RefreshTokenTypeHint) {\n            _Log.Log.error(\"TokenRevocationClient.revoke: Invalid token type\");\n            throw new Error(\"Invalid token type.\");\n        }\n\n        return this._metadataService.getRevocationEndpoint().then(function (url) {\n            if (!url) {\n                if (required) {\n                    _Log.Log.error(\"TokenRevocationClient.revoke: Revocation not supported\");\n                    throw new Error(\"Revocation not supported\");\n                }\n\n                // not required, so don't error and just return\n                return;\n            }\n\n            _Log.Log.debug(\"TokenRevocationClient.revoke: Revoking \" + type);\n            var client_id = _this._settings.client_id;\n            var client_secret = _this._settings.client_secret;\n            return _this._revoke(url, client_id, client_secret, token, type);\n        });\n    };\n\n    TokenRevocationClient.prototype._revoke = function _revoke(url, client_id, client_secret, token, type) {\n        var _this2 = this;\n\n        return new Promise(function (resolve, reject) {\n\n            var xhr = new _this2._XMLHttpRequestCtor();\n            xhr.open(\"POST\", url);\n\n            xhr.onload = function () {\n                _Log.Log.debug(\"TokenRevocationClient.revoke: HTTP response received, status\", xhr.status);\n\n                if (xhr.status === 200) {\n                    resolve();\n                } else {\n                    reject(Error(xhr.statusText + \" (\" + xhr.status + \")\"));\n                }\n            };\n            xhr.onerror = function () {\n                _Log.Log.debug(\"TokenRevocationClient.revoke: Network Error.\");\n                reject(\"Network Error\");\n            };\n\n            var body = \"client_id=\" + encodeURIComponent(client_id);\n            if (client_secret) {\n                body += \"&client_secret=\" + encodeURIComponent(client_secret);\n            }\n            body += \"&token_type_hint=\" + encodeURIComponent(type);\n            body += \"&token=\" + encodeURIComponent(token);\n\n            xhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\n            xhr.send(body);\n        });\n    };\n\n    return TokenRevocationClient;\n}();\n\n/***/ }),\n\n/***/ \"./src/UrlUtility.js\":\n/*!***************************!*\\\n  !*** ./src/UrlUtility.js ***!\n  \\***************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UrlUtility = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UrlUtility = exports.UrlUtility = function () {\n    function UrlUtility() {\n        _classCallCheck(this, UrlUtility);\n    }\n\n    UrlUtility.addQueryParam = function addQueryParam(url, name, value) {\n        if (url.indexOf('?') < 0) {\n            url += \"?\";\n        }\n\n        if (url[url.length - 1] !== \"?\") {\n            url += \"&\";\n        }\n\n        url += encodeURIComponent(name);\n        url += \"=\";\n        url += encodeURIComponent(value);\n\n        return url;\n    };\n\n    UrlUtility.parseUrlFragment = function parseUrlFragment(value) {\n        var delimiter = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : \"#\";\n        var global = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _Global.Global;\n\n        if (typeof value !== 'string') {\n            value = global.location.href;\n        }\n\n        var idx = value.lastIndexOf(delimiter);\n        if (idx >= 0) {\n            value = value.substr(idx + 1);\n        }\n\n        if (delimiter === \"?\") {\n            // if we're doing query, then strip off hash fragment before we parse\n            idx = value.indexOf('#');\n            if (idx >= 0) {\n                value = value.substr(0, idx);\n            }\n        }\n\n        var params = {},\n            regex = /([^&=]+)=([^&]*)/g,\n            m;\n\n        var counter = 0;\n        while (m = regex.exec(value)) {\n            params[decodeURIComponent(m[1])] = decodeURIComponent(m[2]);\n            if (counter++ > 50) {\n                _Log.Log.error(\"UrlUtility.parseUrlFragment: response exceeded expected number of parameters\", value);\n                return {\n                    error: \"Response exceeded expected number of parameters\"\n                };\n            }\n        }\n\n        for (var prop in params) {\n            return params;\n        }\n\n        return {};\n    };\n\n    return UrlUtility;\n}();\n\n/***/ }),\n\n/***/ \"./src/User.js\":\n/*!*********************!*\\\n  !*** ./src/User.js ***!\n  \\*********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.User = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }(); // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nvar User = exports.User = function () {\n    function User(_ref) {\n        var id_token = _ref.id_token,\n            session_state = _ref.session_state,\n            access_token = _ref.access_token,\n            refresh_token = _ref.refresh_token,\n            token_type = _ref.token_type,\n            scope = _ref.scope,\n            profile = _ref.profile,\n            expires_at = _ref.expires_at,\n            state = _ref.state;\n\n        _classCallCheck(this, User);\n\n        this.id_token = id_token;\n        this.session_state = session_state;\n        this.access_token = access_token;\n        this.refresh_token = refresh_token;\n        this.token_type = token_type;\n        this.scope = scope;\n        this.profile = profile;\n        this.expires_at = expires_at;\n        this.state = state;\n    }\n\n    User.prototype.toStorageString = function toStorageString() {\n        _Log.Log.debug(\"User.toStorageString\");\n        return JSON.stringify({\n            id_token: this.id_token,\n            session_state: this.session_state,\n            access_token: this.access_token,\n            refresh_token: this.refresh_token,\n            token_type: this.token_type,\n            scope: this.scope,\n            profile: this.profile,\n            expires_at: this.expires_at\n        });\n    };\n\n    User.fromStorageString = function fromStorageString(storageString) {\n        _Log.Log.debug(\"User.fromStorageString\");\n        return new User(JSON.parse(storageString));\n    };\n\n    _createClass(User, [{\n        key: 'expires_in',\n        get: function get() {\n            if (this.expires_at) {\n                var now = parseInt(Date.now() / 1000);\n                return this.expires_at - now;\n            }\n            return undefined;\n        },\n        set: function set(value) {\n            var expires_in = parseInt(value);\n            if (typeof expires_in === 'number' && expires_in > 0) {\n                var now = parseInt(Date.now() / 1000);\n                this.expires_at = now + expires_in;\n            }\n        }\n    }, {\n        key: 'expired',\n        get: function get() {\n            var expires_in = this.expires_in;\n            if (expires_in !== undefined) {\n                return expires_in <= 0;\n            }\n            return undefined;\n        }\n    }, {\n        key: 'scopes',\n        get: function get() {\n            return (this.scope || \"\").split(\" \");\n        }\n    }]);\n\n    return User;\n}();\n\n/***/ }),\n\n/***/ \"./src/UserInfoService.js\":\n/*!********************************!*\\\n  !*** ./src/UserInfoService.js ***!\n  \\********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserInfoService = undefined;\n\nvar _JsonService = __webpack_require__(/*! ./JsonService.js */ \"./src/JsonService.js\");\n\nvar _MetadataService = __webpack_require__(/*! ./MetadataService.js */ \"./src/MetadataService.js\");\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserInfoService = exports.UserInfoService = function () {\n    function UserInfoService(settings) {\n        var JsonServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _JsonService.JsonService;\n        var MetadataServiceCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _MetadataService.MetadataService;\n        var joseUtil = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _JoseUtil.JoseUtil;\n\n        _classCallCheck(this, UserInfoService);\n\n        if (!settings) {\n            _Log.Log.error(\"UserInfoService.ctor: No settings passed\");\n            throw new Error(\"settings\");\n        }\n\n        this._settings = settings;\n        this._jsonService = new JsonServiceCtor(undefined, undefined, this._getClaimsFromJwt.bind(this));\n        this._metadataService = new MetadataServiceCtor(this._settings);\n        this._joseUtil = joseUtil;\n    }\n\n    UserInfoService.prototype.getClaims = function getClaims(token) {\n        var _this = this;\n\n        if (!token) {\n            _Log.Log.error(\"UserInfoService.getClaims: No token passed\");\n            return Promise.reject(new Error(\"A token is required\"));\n        }\n\n        return this._metadataService.getUserInfoEndpoint().then(function (url) {\n            _Log.Log.debug(\"UserInfoService.getClaims: received userinfo url\", url);\n\n            return _this._jsonService.getJson(url, token).then(function (claims) {\n                _Log.Log.debug(\"UserInfoService.getClaims: claims received\", claims);\n                return claims;\n            });\n        });\n    };\n\n    UserInfoService.prototype._getClaimsFromJwt = function _getClaimsFromJwt(req) {\n        var _this2 = this;\n\n        try {\n            var jwt = this._joseUtil.parseJwt(req.responseText);\n            if (!jwt || !jwt.header || !jwt.payload) {\n                _Log.Log.error(\"UserInfoService._getClaimsFromJwt: Failed to parse JWT\", jwt);\n                return Promise.reject(new Error(\"Failed to parse id_token\"));\n            }\n\n            var kid = jwt.header.kid;\n\n            var issuerPromise = void 0;\n            switch (this._settings.userInfoJwtIssuer) {\n                case 'OP':\n                    issuerPromise = this._metadataService.getIssuer();\n                    break;\n                case 'ANY':\n                    issuerPromise = Promise.resolve(jwt.payload.iss);\n                    break;\n                default:\n                    issuerPromise = Promise.resolve(this._settings.userInfoJwtIssuer);\n                    break;\n            }\n\n            return issuerPromise.then(function (issuer) {\n                _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Received issuer:\" + issuer);\n\n                return _this2._metadataService.getSigningKeys().then(function (keys) {\n                    if (!keys) {\n                        _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No signing keys from metadata\");\n                        return Promise.reject(new Error(\"No signing keys from metadata\"));\n                    }\n\n                    _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Received signing keys\");\n                    var key = void 0;\n                    if (!kid) {\n                        keys = _this2._filterByAlg(keys, jwt.header.alg);\n\n                        if (keys.length > 1) {\n                            _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No kid found in id_token and more than one key found in metadata\");\n                            return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\n                        } else {\n                            // kid is mandatory only when there are multiple keys in the referenced JWK Set document\n                            // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\n                            key = keys[0];\n                        }\n                    } else {\n                        key = keys.filter(function (key) {\n                            return key.kid === kid;\n                        })[0];\n                    }\n\n                    if (!key) {\n                        _Log.Log.error(\"UserInfoService._getClaimsFromJwt: No key matching kid or alg found in signing keys\");\n                        return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\n                    }\n\n                    var audience = _this2._settings.client_id;\n\n                    var clockSkewInSeconds = _this2._settings.clockSkew;\n                    _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\n\n                    return _this2._joseUtil.validateJwt(req.responseText, key, issuer, audience, clockSkewInSeconds, undefined, true).then(function () {\n                        _Log.Log.debug(\"UserInfoService._getClaimsFromJwt: JWT validation successful\");\n                        return jwt.payload;\n                    });\n                });\n            });\n            return;\n        } catch (e) {\n            _Log.Log.error(\"UserInfoService._getClaimsFromJwt: Error parsing JWT response\", e.message);\n            reject(e);\n            return;\n        }\n    };\n\n    UserInfoService.prototype._filterByAlg = function _filterByAlg(keys, alg) {\n        var kty = null;\n        if (alg.startsWith(\"RS\")) {\n            kty = \"RSA\";\n        } else if (alg.startsWith(\"PS\")) {\n            kty = \"PS\";\n        } else if (alg.startsWith(\"ES\")) {\n            kty = \"EC\";\n        } else {\n            _Log.Log.debug(\"UserInfoService._filterByAlg: alg not supported: \", alg);\n            return [];\n        }\n\n        _Log.Log.debug(\"UserInfoService._filterByAlg: Looking for keys that match kty: \", kty);\n\n        keys = keys.filter(function (key) {\n            return key.kty === kty;\n        });\n\n        _Log.Log.debug(\"UserInfoService._filterByAlg: Number of keys that match kty: \", kty, keys.length);\n\n        return keys;\n    };\n\n    return UserInfoService;\n}();\n\n/***/ }),\n\n/***/ \"./src/UserManager.js\":\n/*!****************************!*\\\n  !*** ./src/UserManager.js ***!\n  \\****************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManager = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClient2 = __webpack_require__(/*! ./OidcClient.js */ \"./src/OidcClient.js\");\n\nvar _UserManagerSettings = __webpack_require__(/*! ./UserManagerSettings.js */ \"./src/UserManagerSettings.js\");\n\nvar _User = __webpack_require__(/*! ./User.js */ \"./src/User.js\");\n\nvar _UserManagerEvents = __webpack_require__(/*! ./UserManagerEvents.js */ \"./src/UserManagerEvents.js\");\n\nvar _SilentRenewService = __webpack_require__(/*! ./SilentRenewService.js */ \"./src/SilentRenewService.js\");\n\nvar _SessionMonitor = __webpack_require__(/*! ./SessionMonitor.js */ \"./src/SessionMonitor.js\");\n\nvar _TokenRevocationClient = __webpack_require__(/*! ./TokenRevocationClient.js */ \"./src/TokenRevocationClient.js\");\n\nvar _TokenClient = __webpack_require__(/*! ./TokenClient.js */ \"./src/TokenClient.js\");\n\nvar _JoseUtil = __webpack_require__(/*! ./JoseUtil.js */ \"./src/JoseUtil.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserManager = exports.UserManager = function (_OidcClient) {\n    _inherits(UserManager, _OidcClient);\n\n    function UserManager() {\n        var settings = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n        var SilentRenewServiceCtor = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : _SilentRenewService.SilentRenewService;\n        var SessionMonitorCtor = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : _SessionMonitor.SessionMonitor;\n        var TokenRevocationClientCtor = arguments.length > 3 && arguments[3] !== undefined ? arguments[3] : _TokenRevocationClient.TokenRevocationClient;\n        var TokenClientCtor = arguments.length > 4 && arguments[4] !== undefined ? arguments[4] : _TokenClient.TokenClient;\n        var joseUtil = arguments.length > 5 && arguments[5] !== undefined ? arguments[5] : _JoseUtil.JoseUtil;\n\n        _classCallCheck(this, UserManager);\n\n        if (!(settings instanceof _UserManagerSettings.UserManagerSettings)) {\n            settings = new _UserManagerSettings.UserManagerSettings(settings);\n        }\n\n        var _this = _possibleConstructorReturn(this, _OidcClient.call(this, settings));\n\n        _this._events = new _UserManagerEvents.UserManagerEvents(settings);\n        _this._silentRenewService = new SilentRenewServiceCtor(_this);\n\n        // order is important for the following properties; these services depend upon the events.\n        if (_this.settings.automaticSilentRenew) {\n            _Log.Log.debug(\"UserManager.ctor: automaticSilentRenew is configured, setting up silent renew\");\n            _this.startSilentRenew();\n        }\n\n        if (_this.settings.monitorSession) {\n            _Log.Log.debug(\"UserManager.ctor: monitorSession is configured, setting up session monitor\");\n            _this._sessionMonitor = new SessionMonitorCtor(_this);\n        }\n\n        _this._tokenRevocationClient = new TokenRevocationClientCtor(_this._settings);\n        _this._tokenClient = new TokenClientCtor(_this._settings);\n        _this._joseUtil = joseUtil;\n        return _this;\n    }\n\n    UserManager.prototype.getUser = function getUser() {\n        var _this2 = this;\n\n        return this._loadUser().then(function (user) {\n            if (user) {\n                _Log.Log.info(\"UserManager.getUser: user loaded\");\n\n                _this2._events.load(user, false);\n\n                return user;\n            } else {\n                _Log.Log.info(\"UserManager.getUser: user not found in storage\");\n                return null;\n            }\n        });\n    };\n\n    UserManager.prototype.removeUser = function removeUser() {\n        var _this3 = this;\n\n        return this.storeUser(null).then(function () {\n            _Log.Log.info(\"UserManager.removeUser: user removed from storage\");\n            _this3._events.unload();\n        });\n    };\n\n    UserManager.prototype.signinRedirect = function signinRedirect() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:r\";\n        var navParams = {\n            useReplaceToNavigate: args.useReplaceToNavigate\n        };\n        return this._signinStart(args, this._redirectNavigator, navParams).then(function () {\n            _Log.Log.info(\"UserManager.signinRedirect: successful\");\n        });\n    };\n\n    UserManager.prototype.signinRedirectCallback = function signinRedirectCallback(url) {\n        return this._signinEnd(url || this._redirectNavigator.url).then(function (user) {\n            if (user.profile && user.profile.sub) {\n                _Log.Log.info(\"UserManager.signinRedirectCallback: successful, signed in sub: \", user.profile.sub);\n            } else {\n                _Log.Log.info(\"UserManager.signinRedirectCallback: no sub\");\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinPopup = function signinPopup() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:p\";\n        var url = args.redirect_uri || this.settings.popup_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.signinPopup: No popup_redirect_uri or redirect_uri configured\");\n            return Promise.reject(new Error(\"No popup_redirect_uri or redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.display = \"popup\";\n\n        return this._signin(args, this._popupNavigator, {\n            startUrl: url,\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\n        }).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinPopup: signinPopup successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinPopup: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinPopupCallback = function signinPopupCallback(url) {\n        return this._signinCallback(url, this._popupNavigator).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinPopupCallback: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinPopupCallback: no sub\");\n                }\n            }\n\n            return user;\n        }).catch(function (err) {\n            _Log.Log.error( true && err.message);\n        });\n    };\n\n    UserManager.prototype.signinSilent = function signinSilent() {\n        var _this4 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:s\";\n        // first determine if we have a refresh token, or need to use iframe\n        return this._loadUser().then(function (user) {\n            if (user && user.refresh_token) {\n                args.refresh_token = user.refresh_token;\n                return _this4._useRefreshToken(args);\n            } else {\n                args.id_token_hint = args.id_token_hint || _this4.settings.includeIdTokenInSilentRenew && user && user.id_token;\n                if (user && _this4._settings.validateSubOnSilentRenew) {\n                    _Log.Log.debug(\"UserManager.signinSilent, subject prior to silent renew: \", user.profile.sub);\n                    args.current_sub = user.profile.sub;\n                }\n                return _this4._signinSilentIframe(args);\n            }\n        });\n    };\n\n    UserManager.prototype._useRefreshToken = function _useRefreshToken() {\n        var _this5 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        return this._tokenClient.exchangeRefreshToken(args).then(function (result) {\n            if (!result) {\n                _Log.Log.error(\"UserManager._useRefreshToken: No response returned from token endpoint\");\n                return Promise.reject(\"No response returned from token endpoint\");\n            }\n            if (!result.access_token) {\n                _Log.Log.error(\"UserManager._useRefreshToken: No access token returned from token endpoint\");\n                return Promise.reject(\"No access token returned from token endpoint\");\n            }\n\n            return _this5._loadUser().then(function (user) {\n                if (user) {\n                    var idTokenValidation = Promise.resolve();\n                    if (result.id_token) {\n                        idTokenValidation = _this5._validateIdTokenFromTokenRefreshToken(user.profile, result.id_token);\n                    }\n\n                    return idTokenValidation.then(function () {\n                        _Log.Log.debug(\"UserManager._useRefreshToken: refresh token response success\");\n                        user.id_token = result.id_token;\n                        user.access_token = result.access_token;\n                        user.refresh_token = result.refresh_token || user.refresh_token;\n                        user.expires_in = result.expires_in;\n\n                        return _this5.storeUser(user).then(function () {\n                            _this5._events.load(user);\n                            return user;\n                        });\n                    });\n                } else {\n                    return null;\n                }\n            });\n        });\n    };\n\n    UserManager.prototype._validateIdTokenFromTokenRefreshToken = function _validateIdTokenFromTokenRefreshToken(profile, id_token) {\n        var _this6 = this;\n\n        return this._metadataService.getIssuer().then(function (issuer) {\n            return _this6._joseUtil.validateJwtAttributes(id_token, issuer, _this6._settings.client_id, _this6._settings.clockSkew).then(function (payload) {\n                if (!payload) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: Failed to validate id_token\");\n                    return Promise.reject(new Error(\"Failed to validate id_token\"));\n                }\n                if (payload.sub !== profile.sub) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: sub in id_token does not match current sub\");\n                    return Promise.reject(new Error(\"sub in id_token does not match current sub\"));\n                }\n                if (payload.auth_time && payload.auth_time !== profile.auth_time) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: auth_time in id_token does not match original auth_time\");\n                    return Promise.reject(new Error(\"auth_time in id_token does not match original auth_time\"));\n                }\n                if (payload.azp && payload.azp !== profile.azp) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp in id_token does not match original azp\");\n                    return Promise.reject(new Error(\"azp in id_token does not match original azp\"));\n                }\n                if (!payload.azp && profile.azp) {\n                    _Log.Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp not in id_token, but present in original id_token\");\n                    return Promise.reject(new Error(\"azp not in id_token, but present in original id_token\"));\n                }\n            });\n        });\n    };\n\n    UserManager.prototype._signinSilentIframe = function _signinSilentIframe() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        var url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.signinSilent: No silent_redirect_uri configured\");\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.prompt = args.prompt || \"none\";\n\n        return this._signin(args, this._iframeNavigator, {\n            startUrl: url,\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\n        }).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinSilent: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinSilent: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinSilentCallback = function signinSilentCallback(url) {\n        return this._signinCallback(url, this._iframeNavigator).then(function (user) {\n            if (user) {\n                if (user.profile && user.profile.sub) {\n                    _Log.Log.info(\"UserManager.signinSilentCallback: successful, signed in sub: \", user.profile.sub);\n                } else {\n                    _Log.Log.info(\"UserManager.signinSilentCallback: no sub\");\n                }\n            }\n\n            return user;\n        });\n    };\n\n    UserManager.prototype.signinCallback = function signinCallback(url) {\n        var _this7 = this;\n\n        return this.readSigninResponseState(url).then(function (_ref) {\n            var state = _ref.state,\n                response = _ref.response;\n\n            if (state.request_type === \"si:r\") {\n                return _this7.signinRedirectCallback(url);\n            }\n            if (state.request_type === \"si:p\") {\n                return _this7.signinPopupCallback(url);\n            }\n            if (state.request_type === \"si:s\") {\n                return _this7.signinSilentCallback(url);\n            }\n            return Promise.reject(new Error(\"invalid response_type in state\"));\n        });\n    };\n\n    UserManager.prototype.signoutCallback = function signoutCallback(url, keepOpen) {\n        var _this8 = this;\n\n        return this.readSignoutResponseState(url).then(function (_ref2) {\n            var state = _ref2.state,\n                response = _ref2.response;\n\n            if (state) {\n                if (state.request_type === \"so:r\") {\n                    return _this8.signoutRedirectCallback(url);\n                }\n                if (state.request_type === \"so:p\") {\n                    return _this8.signoutPopupCallback(url, keepOpen);\n                }\n                return Promise.reject(new Error(\"invalid response_type in state\"));\n            }\n            return response;\n        });\n    };\n\n    UserManager.prototype.querySessionStatus = function querySessionStatus() {\n        var _this9 = this;\n\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"si:s\"; // this acts like a signin silent\n        var url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\n        if (!url) {\n            _Log.Log.error(\"UserManager.querySessionStatus: No silent_redirect_uri configured\");\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\n        }\n\n        args.redirect_uri = url;\n        args.prompt = \"none\";\n        args.response_type = args.response_type || this.settings.query_status_response_type;\n        args.scope = args.scope || \"openid\";\n        args.skipUserInfo = true;\n\n        return this._signinStart(args, this._iframeNavigator, {\n            startUrl: url,\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\n        }).then(function (navResponse) {\n            return _this9.processSigninResponse(navResponse.url).then(function (signinResponse) {\n                _Log.Log.debug(\"UserManager.querySessionStatus: got signin response\");\n\n                if (signinResponse.session_state && signinResponse.profile.sub) {\n                    _Log.Log.info(\"UserManager.querySessionStatus: querySessionStatus success for sub: \", signinResponse.profile.sub);\n                    return {\n                        session_state: signinResponse.session_state,\n                        sub: signinResponse.profile.sub,\n                        sid: signinResponse.profile.sid\n                    };\n                } else {\n                    _Log.Log.info(\"querySessionStatus successful, user not authenticated\");\n                }\n            }).catch(function (err) {\n                if (err.session_state && _this9.settings.monitorAnonymousSession) {\n                    if (err.message == \"login_required\" || err.message == \"consent_required\" || err.message == \"interaction_required\" || err.message == \"account_selection_required\") {\n                        _Log.Log.info(\"UserManager.querySessionStatus: querySessionStatus success for anonymous user\");\n                        return {\n                            session_state: err.session_state\n                        };\n                    }\n                }\n\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signin = function _signin(args, navigator) {\n        var _this10 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return this._signinStart(args, navigator, navigatorParams).then(function (navResponse) {\n            return _this10._signinEnd(navResponse.url, args);\n        });\n    };\n\n    UserManager.prototype._signinStart = function _signinStart(args, navigator) {\n        var _this11 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n\n        return navigator.prepare(navigatorParams).then(function (handle) {\n            _Log.Log.debug(\"UserManager._signinStart: got navigator window handle\");\n\n            return _this11.createSigninRequest(args).then(function (signinRequest) {\n                _Log.Log.debug(\"UserManager._signinStart: got signin request\");\n\n                navigatorParams.url = signinRequest.url;\n                navigatorParams.id = signinRequest.state.id;\n\n                return handle.navigate(navigatorParams);\n            }).catch(function (err) {\n                if (handle.close) {\n                    _Log.Log.debug(\"UserManager._signinStart: Error after preparing navigator, closing navigator window\");\n                    handle.close();\n                }\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signinEnd = function _signinEnd(url) {\n        var _this12 = this;\n\n        var args = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {};\n\n        return this.processSigninResponse(url).then(function (signinResponse) {\n            _Log.Log.debug(\"UserManager._signinEnd: got signin response\");\n\n            var user = new _User.User(signinResponse);\n\n            if (args.current_sub) {\n                if (args.current_sub !== user.profile.sub) {\n                    _Log.Log.debug(\"UserManager._signinEnd: current user does not match user returned from signin. sub from signin: \", user.profile.sub);\n                    return Promise.reject(new Error(\"login_required\"));\n                } else {\n                    _Log.Log.debug(\"UserManager._signinEnd: current user matches user returned from signin\");\n                }\n            }\n\n            return _this12.storeUser(user).then(function () {\n                _Log.Log.debug(\"UserManager._signinEnd: user stored\");\n\n                _this12._events.load(user);\n\n                return user;\n            });\n        });\n    };\n\n    UserManager.prototype._signinCallback = function _signinCallback(url, navigator) {\n        _Log.Log.debug(\"UserManager._signinCallback\");\n        return navigator.callback(url);\n    };\n\n    UserManager.prototype.signoutRedirect = function signoutRedirect() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"so:r\";\n        var postLogoutRedirectUri = args.post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\n        if (postLogoutRedirectUri) {\n            args.post_logout_redirect_uri = postLogoutRedirectUri;\n        }\n        var navParams = {\n            useReplaceToNavigate: args.useReplaceToNavigate\n        };\n        return this._signoutStart(args, this._redirectNavigator, navParams).then(function () {\n            _Log.Log.info(\"UserManager.signoutRedirect: successful\");\n        });\n    };\n\n    UserManager.prototype.signoutRedirectCallback = function signoutRedirectCallback(url) {\n        return this._signoutEnd(url || this._redirectNavigator.url).then(function (response) {\n            _Log.Log.info(\"UserManager.signoutRedirectCallback: successful\");\n            return response;\n        });\n    };\n\n    UserManager.prototype.signoutPopup = function signoutPopup() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        args = Object.assign({}, args);\n\n        args.request_type = \"so:p\";\n        var url = args.post_logout_redirect_uri || this.settings.popup_post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\n        args.post_logout_redirect_uri = url;\n        args.display = \"popup\";\n        if (args.post_logout_redirect_uri) {\n            // we're putting a dummy entry in here because we\n            // need a unique id from the state for notification\n            // to the parent window, which is necessary if we\n            // plan to return back to the client after signout\n            // and so we can close the popup after signout\n            args.state = args.state || {};\n        }\n\n        return this._signout(args, this._popupNavigator, {\n            startUrl: url,\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\n        }).then(function () {\n            _Log.Log.info(\"UserManager.signoutPopup: successful\");\n        });\n    };\n\n    UserManager.prototype.signoutPopupCallback = function signoutPopupCallback(url, keepOpen) {\n        if (typeof keepOpen === 'undefined' && typeof url === 'boolean') {\n            keepOpen = url;\n            url = null;\n        }\n\n        var delimiter = '?';\n        return this._popupNavigator.callback(url, keepOpen, delimiter).then(function () {\n            _Log.Log.info(\"UserManager.signoutPopupCallback: successful\");\n        });\n    };\n\n    UserManager.prototype._signout = function _signout(args, navigator) {\n        var _this13 = this;\n\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return this._signoutStart(args, navigator, navigatorParams).then(function (navResponse) {\n            return _this13._signoutEnd(navResponse.url);\n        });\n    };\n\n    UserManager.prototype._signoutStart = function _signoutStart() {\n        var args = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {};\n\n        var _this14 = this;\n\n        var navigator = arguments[1];\n        var navigatorParams = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};\n\n        return navigator.prepare(navigatorParams).then(function (handle) {\n            _Log.Log.debug(\"UserManager._signoutStart: got navigator window handle\");\n\n            return _this14._loadUser().then(function (user) {\n                _Log.Log.debug(\"UserManager._signoutStart: loaded current user from storage\");\n\n                var revokePromise = _this14._settings.revokeAccessTokenOnSignout ? _this14._revokeInternal(user) : Promise.resolve();\n                return revokePromise.then(function () {\n\n                    var id_token = args.id_token_hint || user && user.id_token;\n                    if (id_token) {\n                        _Log.Log.debug(\"UserManager._signoutStart: Setting id_token into signout request\");\n                        args.id_token_hint = id_token;\n                    }\n\n                    return _this14.removeUser().then(function () {\n                        _Log.Log.debug(\"UserManager._signoutStart: user removed, creating signout request\");\n\n                        return _this14.createSignoutRequest(args).then(function (signoutRequest) {\n                            _Log.Log.debug(\"UserManager._signoutStart: got signout request\");\n\n                            navigatorParams.url = signoutRequest.url;\n                            if (signoutRequest.state) {\n                                navigatorParams.id = signoutRequest.state.id;\n                            }\n                            return handle.navigate(navigatorParams);\n                        });\n                    });\n                });\n            }).catch(function (err) {\n                if (handle.close) {\n                    _Log.Log.debug(\"UserManager._signoutStart: Error after preparing navigator, closing navigator window\");\n                    handle.close();\n                }\n                throw err;\n            });\n        });\n    };\n\n    UserManager.prototype._signoutEnd = function _signoutEnd(url) {\n        return this.processSignoutResponse(url).then(function (signoutResponse) {\n            _Log.Log.debug(\"UserManager._signoutEnd: got signout response\");\n\n            return signoutResponse;\n        });\n    };\n\n    UserManager.prototype.revokeAccessToken = function revokeAccessToken() {\n        var _this15 = this;\n\n        return this._loadUser().then(function (user) {\n            return _this15._revokeInternal(user, true).then(function (success) {\n                if (success) {\n                    _Log.Log.debug(\"UserManager.revokeAccessToken: removing token properties from user and re-storing\");\n\n                    user.access_token = null;\n                    user.refresh_token = null;\n                    user.expires_at = null;\n                    user.token_type = null;\n\n                    return _this15.storeUser(user).then(function () {\n                        _Log.Log.debug(\"UserManager.revokeAccessToken: user stored\");\n                        _this15._events.load(user);\n                    });\n                }\n            });\n        }).then(function () {\n            _Log.Log.info(\"UserManager.revokeAccessToken: access token revoked successfully\");\n        });\n    };\n\n    UserManager.prototype._revokeInternal = function _revokeInternal(user, required) {\n        var _this16 = this;\n\n        if (user) {\n            var access_token = user.access_token;\n            var refresh_token = user.refresh_token;\n\n            return this._revokeAccessTokenInternal(access_token, required).then(function (atSuccess) {\n                return _this16._revokeRefreshTokenInternal(refresh_token, required).then(function (rtSuccess) {\n                    if (!atSuccess && !rtSuccess) {\n                        _Log.Log.debug(\"UserManager.revokeAccessToken: no need to revoke due to no token(s), or JWT format\");\n                    }\n\n                    return atSuccess || rtSuccess;\n                });\n            });\n        }\n\n        return Promise.resolve(false);\n    };\n\n    UserManager.prototype._revokeAccessTokenInternal = function _revokeAccessTokenInternal(access_token, required) {\n        // check for JWT vs. reference token\n        if (!access_token || access_token.indexOf('.') >= 0) {\n            return Promise.resolve(false);\n        }\n\n        return this._tokenRevocationClient.revoke(access_token, required).then(function () {\n            return true;\n        });\n    };\n\n    UserManager.prototype._revokeRefreshTokenInternal = function _revokeRefreshTokenInternal(refresh_token, required) {\n        if (!refresh_token) {\n            return Promise.resolve(false);\n        }\n\n        return this._tokenRevocationClient.revoke(refresh_token, required, \"refresh_token\").then(function () {\n            return true;\n        });\n    };\n\n    UserManager.prototype.startSilentRenew = function startSilentRenew() {\n        this._silentRenewService.start();\n    };\n\n    UserManager.prototype.stopSilentRenew = function stopSilentRenew() {\n        this._silentRenewService.stop();\n    };\n\n    UserManager.prototype._loadUser = function _loadUser() {\n        return this._userStore.get(this._userStoreKey).then(function (storageString) {\n            if (storageString) {\n                _Log.Log.debug(\"UserManager._loadUser: user storageString loaded\");\n                return _User.User.fromStorageString(storageString);\n            }\n\n            _Log.Log.debug(\"UserManager._loadUser: no user storageString\");\n            return null;\n        });\n    };\n\n    UserManager.prototype.storeUser = function storeUser(user) {\n        if (user) {\n            _Log.Log.debug(\"UserManager.storeUser: storing user\");\n\n            var storageString = user.toStorageString();\n            return this._userStore.set(this._userStoreKey, storageString);\n        } else {\n            _Log.Log.debug(\"storeUser.storeUser: removing user\");\n            return this._userStore.remove(this._userStoreKey);\n        }\n    };\n\n    _createClass(UserManager, [{\n        key: '_redirectNavigator',\n        get: function get() {\n            return this.settings.redirectNavigator;\n        }\n    }, {\n        key: '_popupNavigator',\n        get: function get() {\n            return this.settings.popupNavigator;\n        }\n    }, {\n        key: '_iframeNavigator',\n        get: function get() {\n            return this.settings.iframeNavigator;\n        }\n    }, {\n        key: '_userStore',\n        get: function get() {\n            return this.settings.userStore;\n        }\n    }, {\n        key: 'events',\n        get: function get() {\n            return this._events;\n        }\n    }, {\n        key: '_userStoreKey',\n        get: function get() {\n            return 'user:' + this.settings.authority + ':' + this.settings.client_id;\n        }\n    }]);\n\n    return UserManager;\n}(_OidcClient2.OidcClient);\n\n/***/ }),\n\n/***/ \"./src/UserManagerEvents.js\":\n/*!**********************************!*\\\n  !*** ./src/UserManagerEvents.js ***!\n  \\**********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManagerEvents = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _AccessTokenEvents2 = __webpack_require__(/*! ./AccessTokenEvents.js */ \"./src/AccessTokenEvents.js\");\n\nvar _Event = __webpack_require__(/*! ./Event.js */ \"./src/Event.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar UserManagerEvents = exports.UserManagerEvents = function (_AccessTokenEvents) {\n    _inherits(UserManagerEvents, _AccessTokenEvents);\n\n    function UserManagerEvents(settings) {\n        _classCallCheck(this, UserManagerEvents);\n\n        var _this = _possibleConstructorReturn(this, _AccessTokenEvents.call(this, settings));\n\n        _this._userLoaded = new _Event.Event(\"User loaded\");\n        _this._userUnloaded = new _Event.Event(\"User unloaded\");\n        _this._silentRenewError = new _Event.Event(\"Silent renew error\");\n        _this._userSignedIn = new _Event.Event(\"User signed in\");\n        _this._userSignedOut = new _Event.Event(\"User signed out\");\n        _this._userSessionChanged = new _Event.Event(\"User session changed\");\n        return _this;\n    }\n\n    UserManagerEvents.prototype.load = function load(user) {\n        var raiseEvent = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : true;\n\n        _Log.Log.debug(\"UserManagerEvents.load\");\n        _AccessTokenEvents.prototype.load.call(this, user);\n        if (raiseEvent) {\n            this._userLoaded.raise(user);\n        }\n    };\n\n    UserManagerEvents.prototype.unload = function unload() {\n        _Log.Log.debug(\"UserManagerEvents.unload\");\n        _AccessTokenEvents.prototype.unload.call(this);\n        this._userUnloaded.raise();\n    };\n\n    UserManagerEvents.prototype.addUserLoaded = function addUserLoaded(cb) {\n        this._userLoaded.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserLoaded = function removeUserLoaded(cb) {\n        this._userLoaded.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype.addUserUnloaded = function addUserUnloaded(cb) {\n        this._userUnloaded.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserUnloaded = function removeUserUnloaded(cb) {\n        this._userUnloaded.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype.addSilentRenewError = function addSilentRenewError(cb) {\n        this._silentRenewError.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeSilentRenewError = function removeSilentRenewError(cb) {\n        this._silentRenewError.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseSilentRenewError = function _raiseSilentRenewError(e) {\n        _Log.Log.debug(\"UserManagerEvents._raiseSilentRenewError\", e.message);\n        this._silentRenewError.raise(e);\n    };\n\n    UserManagerEvents.prototype.addUserSignedIn = function addUserSignedIn(cb) {\n        this._userSignedIn.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSignedIn = function removeUserSignedIn(cb) {\n        this._userSignedIn.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSignedIn = function _raiseUserSignedIn() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSignedIn\");\n        this._userSignedIn.raise();\n    };\n\n    UserManagerEvents.prototype.addUserSignedOut = function addUserSignedOut(cb) {\n        this._userSignedOut.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSignedOut = function removeUserSignedOut(cb) {\n        this._userSignedOut.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSignedOut = function _raiseUserSignedOut() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSignedOut\");\n        this._userSignedOut.raise();\n    };\n\n    UserManagerEvents.prototype.addUserSessionChanged = function addUserSessionChanged(cb) {\n        this._userSessionChanged.addHandler(cb);\n    };\n\n    UserManagerEvents.prototype.removeUserSessionChanged = function removeUserSessionChanged(cb) {\n        this._userSessionChanged.removeHandler(cb);\n    };\n\n    UserManagerEvents.prototype._raiseUserSessionChanged = function _raiseUserSessionChanged() {\n        _Log.Log.debug(\"UserManagerEvents._raiseUserSessionChanged\");\n        this._userSessionChanged.raise();\n    };\n\n    return UserManagerEvents;\n}(_AccessTokenEvents2.AccessTokenEvents);\n\n/***/ }),\n\n/***/ \"./src/UserManagerSettings.js\":\n/*!************************************!*\\\n  !*** ./src/UserManagerSettings.js ***!\n  \\************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.UserManagerSettings = undefined;\n\nvar _createClass = function () { function defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if (\"value\" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } } return function (Constructor, protoProps, staticProps) { if (protoProps) defineProperties(Constructor.prototype, protoProps); if (staticProps) defineProperties(Constructor, staticProps); return Constructor; }; }();\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _OidcClientSettings2 = __webpack_require__(/*! ./OidcClientSettings.js */ \"./src/OidcClientSettings.js\");\n\nvar _RedirectNavigator = __webpack_require__(/*! ./RedirectNavigator.js */ \"./src/RedirectNavigator.js\");\n\nvar _PopupNavigator = __webpack_require__(/*! ./PopupNavigator.js */ \"./src/PopupNavigator.js\");\n\nvar _IFrameNavigator = __webpack_require__(/*! ./IFrameNavigator.js */ \"./src/IFrameNavigator.js\");\n\nvar _WebStorageStateStore = __webpack_require__(/*! ./WebStorageStateStore.js */ \"./src/WebStorageStateStore.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nvar _SigninRequest = __webpack_require__(/*! ./SigninRequest.js */ \"./src/SigninRequest.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } }\n\nfunction _possibleConstructorReturn(self, call) { if (!self) { throw new ReferenceError(\"this hasn't been initialised - super() hasn't been called\"); } return call && (typeof call === \"object\" || typeof call === \"function\") ? call : self; }\n\nfunction _inherits(subClass, superClass) { if (typeof superClass !== \"function\" && superClass !== null) { throw new TypeError(\"Super expression must either be null or a function, not \" + typeof superClass); } subClass.prototype = Object.create(superClass && superClass.prototype, { constructor: { value: subClass, enumerable: false, writable: true, configurable: true } }); if (superClass) Object.setPrototypeOf ? Object.setPrototypeOf(subClass, superClass) : subClass.__proto__ = superClass; } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar DefaultAccessTokenExpiringNotificationTime = 60;\nvar DefaultCheckSessionInterval = 2000;\n\nvar UserManagerSettings = exports.UserManagerSettings = function (_OidcClientSettings) {\n    _inherits(UserManagerSettings, _OidcClientSettings);\n\n    function UserManagerSettings() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            popup_redirect_uri = _ref.popup_redirect_uri,\n            popup_post_logout_redirect_uri = _ref.popup_post_logout_redirect_uri,\n            popupWindowFeatures = _ref.popupWindowFeatures,\n            popupWindowTarget = _ref.popupWindowTarget,\n            silent_redirect_uri = _ref.silent_redirect_uri,\n            silentRequestTimeout = _ref.silentRequestTimeout,\n            _ref$automaticSilentR = _ref.automaticSilentRenew,\n            automaticSilentRenew = _ref$automaticSilentR === undefined ? false : _ref$automaticSilentR,\n            _ref$validateSubOnSil = _ref.validateSubOnSilentRenew,\n            validateSubOnSilentRenew = _ref$validateSubOnSil === undefined ? false : _ref$validateSubOnSil,\n            _ref$includeIdTokenIn = _ref.includeIdTokenInSilentRenew,\n            includeIdTokenInSilentRenew = _ref$includeIdTokenIn === undefined ? true : _ref$includeIdTokenIn,\n            _ref$monitorSession = _ref.monitorSession,\n            monitorSession = _ref$monitorSession === undefined ? true : _ref$monitorSession,\n            _ref$monitorAnonymous = _ref.monitorAnonymousSession,\n            monitorAnonymousSession = _ref$monitorAnonymous === undefined ? false : _ref$monitorAnonymous,\n            _ref$checkSessionInte = _ref.checkSessionInterval,\n            checkSessionInterval = _ref$checkSessionInte === undefined ? DefaultCheckSessionInterval : _ref$checkSessionInte,\n            _ref$stopCheckSession = _ref.stopCheckSessionOnError,\n            stopCheckSessionOnError = _ref$stopCheckSession === undefined ? true : _ref$stopCheckSession,\n            query_status_response_type = _ref.query_status_response_type,\n            _ref$revokeAccessToke = _ref.revokeAccessTokenOnSignout,\n            revokeAccessTokenOnSignout = _ref$revokeAccessToke === undefined ? false : _ref$revokeAccessToke,\n            _ref$accessTokenExpir = _ref.accessTokenExpiringNotificationTime,\n            accessTokenExpiringNotificationTime = _ref$accessTokenExpir === undefined ? DefaultAccessTokenExpiringNotificationTime : _ref$accessTokenExpir,\n            _ref$redirectNavigato = _ref.redirectNavigator,\n            redirectNavigator = _ref$redirectNavigato === undefined ? new _RedirectNavigator.RedirectNavigator() : _ref$redirectNavigato,\n            _ref$popupNavigator = _ref.popupNavigator,\n            popupNavigator = _ref$popupNavigator === undefined ? new _PopupNavigator.PopupNavigator() : _ref$popupNavigator,\n            _ref$iframeNavigator = _ref.iframeNavigator,\n            iframeNavigator = _ref$iframeNavigator === undefined ? new _IFrameNavigator.IFrameNavigator() : _ref$iframeNavigator,\n            _ref$userStore = _ref.userStore,\n            userStore = _ref$userStore === undefined ? new _WebStorageStateStore.WebStorageStateStore({ store: _Global.Global.sessionStorage }) : _ref$userStore;\n\n        _classCallCheck(this, UserManagerSettings);\n\n        var _this = _possibleConstructorReturn(this, _OidcClientSettings.call(this, arguments[0]));\n\n        _this._popup_redirect_uri = popup_redirect_uri;\n        _this._popup_post_logout_redirect_uri = popup_post_logout_redirect_uri;\n        _this._popupWindowFeatures = popupWindowFeatures;\n        _this._popupWindowTarget = popupWindowTarget;\n\n        _this._silent_redirect_uri = silent_redirect_uri;\n        _this._silentRequestTimeout = silentRequestTimeout;\n        _this._automaticSilentRenew = automaticSilentRenew;\n        _this._validateSubOnSilentRenew = validateSubOnSilentRenew;\n        _this._includeIdTokenInSilentRenew = includeIdTokenInSilentRenew;\n        _this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\n\n        _this._monitorSession = monitorSession;\n        _this._monitorAnonymousSession = monitorAnonymousSession;\n        _this._checkSessionInterval = checkSessionInterval;\n        _this._stopCheckSessionOnError = stopCheckSessionOnError;\n        if (query_status_response_type) {\n            _this._query_status_response_type = query_status_response_type;\n        } else if (arguments[0] && arguments[0].response_type) {\n            _this._query_status_response_type = _SigninRequest.SigninRequest.isOidc(arguments[0].response_type) ? \"id_token\" : \"code\";\n        } else {\n            _this._query_status_response_type = \"id_token\";\n        }\n        _this._revokeAccessTokenOnSignout = revokeAccessTokenOnSignout;\n\n        _this._redirectNavigator = redirectNavigator;\n        _this._popupNavigator = popupNavigator;\n        _this._iframeNavigator = iframeNavigator;\n\n        _this._userStore = userStore;\n        return _this;\n    }\n\n    _createClass(UserManagerSettings, [{\n        key: 'popup_redirect_uri',\n        get: function get() {\n            return this._popup_redirect_uri;\n        }\n    }, {\n        key: 'popup_post_logout_redirect_uri',\n        get: function get() {\n            return this._popup_post_logout_redirect_uri;\n        }\n    }, {\n        key: 'popupWindowFeatures',\n        get: function get() {\n            return this._popupWindowFeatures;\n        }\n    }, {\n        key: 'popupWindowTarget',\n        get: function get() {\n            return this._popupWindowTarget;\n        }\n    }, {\n        key: 'silent_redirect_uri',\n        get: function get() {\n            return this._silent_redirect_uri;\n        }\n    }, {\n        key: 'silentRequestTimeout',\n        get: function get() {\n            return this._silentRequestTimeout;\n        }\n    }, {\n        key: 'automaticSilentRenew',\n        get: function get() {\n            return this._automaticSilentRenew;\n        }\n    }, {\n        key: 'validateSubOnSilentRenew',\n        get: function get() {\n            return this._validateSubOnSilentRenew;\n        }\n    }, {\n        key: 'includeIdTokenInSilentRenew',\n        get: function get() {\n            return this._includeIdTokenInSilentRenew;\n        }\n    }, {\n        key: 'accessTokenExpiringNotificationTime',\n        get: function get() {\n            return this._accessTokenExpiringNotificationTime;\n        }\n    }, {\n        key: 'monitorSession',\n        get: function get() {\n            return this._monitorSession;\n        }\n    }, {\n        key: 'monitorAnonymousSession',\n        get: function get() {\n            return this._monitorAnonymousSession;\n        }\n    }, {\n        key: 'checkSessionInterval',\n        get: function get() {\n            return this._checkSessionInterval;\n        }\n    }, {\n        key: 'stopCheckSessionOnError',\n        get: function get() {\n            return this._stopCheckSessionOnError;\n        }\n    }, {\n        key: 'query_status_response_type',\n        get: function get() {\n            return this._query_status_response_type;\n        }\n    }, {\n        key: 'revokeAccessTokenOnSignout',\n        get: function get() {\n            return this._revokeAccessTokenOnSignout;\n        }\n    }, {\n        key: 'redirectNavigator',\n        get: function get() {\n            return this._redirectNavigator;\n        }\n    }, {\n        key: 'popupNavigator',\n        get: function get() {\n            return this._popupNavigator;\n        }\n    }, {\n        key: 'iframeNavigator',\n        get: function get() {\n            return this._iframeNavigator;\n        }\n    }, {\n        key: 'userStore',\n        get: function get() {\n            return this._userStore;\n        }\n    }]);\n\n    return UserManagerSettings;\n}(_OidcClientSettings2.OidcClientSettings);\n\n/***/ }),\n\n/***/ \"./src/WebStorageStateStore.js\":\n/*!*************************************!*\\\n  !*** ./src/WebStorageStateStore.js ***!\n  \\*************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.WebStorageStateStore = undefined;\n\nvar _Log = __webpack_require__(/*! ./Log.js */ \"./src/Log.js\");\n\nvar _Global = __webpack_require__(/*! ./Global.js */ \"./src/Global.js\");\n\nfunction _classCallCheck(instance, Constructor) { if (!(instance instanceof Constructor)) { throw new TypeError(\"Cannot call a class as a function\"); } } // Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\n\nvar WebStorageStateStore = exports.WebStorageStateStore = function () {\n    function WebStorageStateStore() {\n        var _ref = arguments.length > 0 && arguments[0] !== undefined ? arguments[0] : {},\n            _ref$prefix = _ref.prefix,\n            prefix = _ref$prefix === undefined ? \"oidc.\" : _ref$prefix,\n            _ref$store = _ref.store,\n            store = _ref$store === undefined ? _Global.Global.localStorage : _ref$store;\n\n        _classCallCheck(this, WebStorageStateStore);\n\n        this._store = store;\n        this._prefix = prefix;\n    }\n\n    WebStorageStateStore.prototype.set = function set(key, value) {\n        _Log.Log.debug(\"WebStorageStateStore.set\", key);\n\n        key = this._prefix + key;\n\n        this._store.setItem(key, value);\n\n        return Promise.resolve();\n    };\n\n    WebStorageStateStore.prototype.get = function get(key) {\n        _Log.Log.debug(\"WebStorageStateStore.get\", key);\n\n        key = this._prefix + key;\n\n        var item = this._store.getItem(key);\n\n        return Promise.resolve(item);\n    };\n\n    WebStorageStateStore.prototype.remove = function remove(key) {\n        _Log.Log.debug(\"WebStorageStateStore.remove\", key);\n\n        key = this._prefix + key;\n\n        var item = this._store.getItem(key);\n        this._store.removeItem(key);\n\n        return Promise.resolve(item);\n    };\n\n    WebStorageStateStore.prototype.getAllKeys = function getAllKeys() {\n        _Log.Log.debug(\"WebStorageStateStore.getAllKeys\");\n\n        var keys = [];\n\n        for (var index = 0; index < this._store.length; index++) {\n            var key = this._store.key(index);\n\n            if (key.indexOf(this._prefix) === 0) {\n                keys.push(key.substr(this._prefix.length));\n            }\n        }\n\n        return Promise.resolve(keys);\n    };\n\n    return WebStorageStateStore;\n}();\n\n/***/ }),\n\n/***/ \"./src/crypto/jsrsasign.js\":\n/*!*********************************!*\\\n  !*** ./src/crypto/jsrsasign.js ***!\n  \\*********************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n    value: true\n});\nexports.AllowedSigningAlgs = exports.b64tohex = exports.hextob64u = exports.crypto = exports.X509 = exports.KeyUtil = exports.jws = undefined;\n\nvar _jsrsasign = __webpack_require__(/*! ../../jsrsasign/dist/jsrsasign.js */ \"./jsrsasign/dist/jsrsasign.js\");\n\nvar AllowedSigningAlgs = ['RS256', 'RS384', 'RS512', 'PS256', 'PS384', 'PS512', 'ES256', 'ES384', 'ES512'];\n\nexports.jws = _jsrsasign.jws;\nexports.KeyUtil = _jsrsasign.KEYUTIL;\nexports.X509 = _jsrsasign.X509;\nexports.crypto = _jsrsasign.crypto;\nexports.hextob64u = _jsrsasign.hextob64u;\nexports.b64tohex = _jsrsasign.b64tohex;\nexports.AllowedSigningAlgs = AllowedSigningAlgs;\n\n/***/ }),\n\n/***/ \"./src/random.js\":\n/*!***********************!*\\\n  !*** ./src/random.js ***!\n  \\***********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nexports.default = random;\n\nvar _v = __webpack_require__(/*! uuid/v4 */ \"./node_modules/uuid/v4.js\");\n\nvar _v2 = _interopRequireDefault(_v);\n\nfunction _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { default: obj }; }\n\n/**\n * Generates RFC4122 version 4 guid ()\n */\n\nfunction random() {\n  return (0, _v2.default)().replace(/-/g, '');\n}\nmodule.exports = exports['default'];\n\n/***/ }),\n\n/***/ \"./version.js\":\n/*!********************!*\\\n  !*** ./version.js ***!\n  \\********************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n\"use strict\";\n\n\nObject.defineProperty(exports, \"__esModule\", {\n  value: true\n});\nvar Version = \"1.10.1\";exports.Version = Version;\n\n/***/ }),\n\n/***/ 0:\n/*!***************************************!*\\\n  !*** multi babel-polyfill ./index.js ***!\n  \\***************************************/\n/*! no static exports found */\n/***/ (function(module, exports, __webpack_require__) {\n\n__webpack_require__(/*! babel-polyfill */\"./node_modules/babel-polyfill/lib/index.js\");\nmodule.exports = __webpack_require__(/*! ./index.js */\"./index.js\");\n\n\n/***/ })\n\n/******/ });\n//# sourceMappingURL=data:application/json;charset=utf-8;base64,{"version":3,"sources":["webpack://Oidc/webpack/bootstrap","webpack://Oidc/./index.js","webpack://Oidc/./jsrsasign/dist/jsrsasign.js","webpack://Oidc/./node_modules/babel-polyfill/lib/index.js","webpack://Oidc/./node_modules/babel-polyfill/node_modules/regenerator-runtime/runtime.js","webpack://Oidc/./node_modules/base64-js/index.js","webpack://Oidc/./node_modules/buffer/index.js","webpack://Oidc/./node_modules/buffer/node_modules/isarray/index.js","webpack://Oidc/./node_modules/core-js/fn/regexp/escape.js","webpack://Oidc/./node_modules/core-js/modules/_a-function.js","webpack://Oidc/./node_modules/core-js/modules/_a-number-value.js","webpack://Oidc/./node_modules/core-js/modules/_add-to-unscopables.js","webpack://Oidc/./node_modules/core-js/modules/_advance-string-index.js","webpack://Oidc/./node_modules/core-js/modules/_an-instance.js","webpack://Oidc/./node_modules/core-js/modules/_an-object.js","webpack://Oidc/./node_modules/core-js/modules/_array-copy-within.js","webpack://Oidc/./node_modules/core-js/modules/_array-fill.js","webpack://Oidc/./node_modules/core-js/modules/_array-from-iterable.js","webpack://Oidc/./node_modules/core-js/modules/_array-includes.js","webpack://Oidc/./node_modules/core-js/modules/_array-methods.js","webpack://Oidc/./node_modules/core-js/modules/_array-reduce.js","webpack://Oidc/./node_modules/core-js/modules/_array-species-constructor.js","webpack://Oidc/./node_modules/core-js/modules/_array-species-create.js","webpack://Oidc/./node_modules/core-js/modules/_bind.js","webpack://Oidc/./node_modules/core-js/modules/_classof.js","webpack://Oidc/./node_modules/core-js/modules/_cof.js","webpack://Oidc/./node_modules/core-js/modules/_collection-strong.js","webpack://Oidc/./node_modules/core-js/modules/_collection-to-json.js","webpack://Oidc/./node_modules/core-js/modules/_collection-weak.js","webpack://Oidc/./node_modules/core-js/modules/_collection.js","webpack://Oidc/./node_modules/core-js/modules/_core.js","webpack://Oidc/./node_modules/core-js/modules/_create-property.js","webpack://Oidc/./node_modules/core-js/modules/_ctx.js","webpack://Oidc/./node_modules/core-js/modules/_date-to-iso-string.js","webpack://Oidc/./node_modules/core-js/modules/_date-to-primitive.js","webpack://Oidc/./node_modules/core-js/modules/_defined.js","webpack://Oidc/./node_modules/core-js/modules/_descriptors.js","webpack://Oidc/./node_modules/core-js/modules/_dom-create.js","webpack://Oidc/./node_modules/core-js/modules/_enum-bug-keys.js","webpack://Oidc/./node_modules/core-js/modules/_enum-keys.js","webpack://Oidc/./node_modules/core-js/modules/_export.js","webpack://Oidc/./node_modules/core-js/modules/_fails-is-regexp.js","webpack://Oidc/./node_modules/core-js/modules/_fails.js","webpack://Oidc/./node_modules/core-js/modules/_fix-re-wks.js","webpack://Oidc/./node_modules/core-js/modules/_flags.js","webpack://Oidc/./node_modules/core-js/modules/_flatten-into-array.js","webpack://Oidc/./node_modules/core-js/modules/_for-of.js","webpack://Oidc/./node_modules/core-js/modules/_function-to-string.js","webpack://Oidc/./node_modules/core-js/modules/_global.js","webpack://Oidc/./node_modules/core-js/modules/_has.js","webpack://Oidc/./node_modules/core-js/modules/_hide.js","webpack://Oidc/./node_modules/core-js/modules/_html.js","webpack://Oidc/./node_modules/core-js/modules/_ie8-dom-define.js","webpack://Oidc/./node_modules/core-js/modules/_inherit-if-required.js","webpack://Oidc/./node_modules/core-js/modules/_invoke.js","webpack://Oidc/./node_modules/core-js/modules/_iobject.js","webpack://Oidc/./node_modules/core-js/modules/_is-array-iter.js","webpack://Oidc/./node_modules/core-js/modules/_is-array.js","webpack://Oidc/./node_modules/core-js/modules/_is-integer.js","webpack://Oidc/./node_modules/core-js/modules/_is-object.js","webpack://Oidc/./node_modules/core-js/modules/_is-regexp.js","webpack://Oidc/./node_modules/core-js/modules/_iter-call.js","webpack://Oidc/./node_modules/core-js/modules/_iter-create.js","webpack://Oidc/./node_modules/core-js/modules/_iter-define.js","webpack://Oidc/./node_modules/core-js/modules/_iter-detect.js","webpack://Oidc/./node_modules/core-js/modules/_iter-step.js","webpack://Oidc/./node_modules/core-js/modules/_iterators.js","webpack://Oidc/./node_modules/core-js/modules/_library.js","webpack://Oidc/./node_modules/core-js/modules/_math-expm1.js","webpack://Oidc/./node_modules/core-js/modules/_math-fround.js","webpack://Oidc/./node_modules/core-js/modules/_math-log1p.js","webpack://Oidc/./node_modules/core-js/modules/_math-scale.js","webpack://Oidc/./node_modules/core-js/modules/_math-sign.js","webpack://Oidc/./node_modules/core-js/modules/_meta.js","webpack://Oidc/./node_modules/core-js/modules/_metadata.js","webpack://Oidc/./node_modules/core-js/modules/_microtask.js","webpack://Oidc/./node_modules/core-js/modules/_new-promise-capability.js","webpack://Oidc/./node_modules/core-js/modules/_object-assign.js","webpack://Oidc/./node_modules/core-js/modules/_object-create.js","webpack://Oidc/./node_modules/core-js/modules/_object-dp.js","webpack://Oidc/./node_modules/core-js/modules/_object-dps.js","webpack://Oidc/./node_modules/core-js/modules/_object-forced-pam.js","webpack://Oidc/./node_modules/core-js/modules/_object-gopd.js","webpack://Oidc/./node_modules/core-js/modules/_object-gopn-ext.js","webpack://Oidc/./node_modules/core-js/modules/_object-gopn.js","webpack://Oidc/./node_modules/core-js/modules/_object-gops.js","webpack://Oidc/./node_modules/core-js/modules/_object-gpo.js","webpack://Oidc/./node_modules/core-js/modules/_object-keys-internal.js","webpack://Oidc/./node_modules/core-js/modules/_object-keys.js","webpack://Oidc/./node_modules/core-js/modules/_object-pie.js","webpack://Oidc/./node_modules/core-js/modules/_object-sap.js","webpack://Oidc/./node_modules/core-js/modules/_object-to-array.js","webpack://Oidc/./node_modules/core-js/modules/_own-keys.js","webpack://Oidc/./node_modules/core-js/modules/_parse-float.js","webpack://Oidc/./node_modules/core-js/modules/_parse-int.js","webpack://Oidc/./node_modules/core-js/modules/_perform.js","webpack://Oidc/./node_modules/core-js/modules/_promise-resolve.js","webpack://Oidc/./node_modules/core-js/modules/_property-desc.js","webpack://Oidc/./node_modules/core-js/modules/_redefine-all.js","webpack://Oidc/./node_modules/core-js/modules/_redefine.js","webpack://Oidc/./node_modules/core-js/modules/_regexp-exec-abstract.js","webpack://Oidc/./node_modules/core-js/modules/_regexp-exec.js","webpack://Oidc/./node_modules/core-js/modules/_replacer.js","webpack://Oidc/./node_modules/core-js/modules/_same-value.js","webpack://Oidc/./node_modules/core-js/modules/_set-collection-from.js","webpack://Oidc/./node_modules/core-js/modules/_set-collection-of.js","webpack://Oidc/./node_modules/core-js/modules/_set-proto.js","webpack://Oidc/./node_modules/core-js/modules/_set-species.js","webpack://Oidc/./node_modules/core-js/modules/_set-to-string-tag.js","webpack://Oidc/./node_modules/core-js/modules/_shared-key.js","webpack://Oidc/./node_modules/core-js/modules/_shared.js","webpack://Oidc/./node_modules/core-js/modules/_species-constructor.js","webpack://Oidc/./node_modules/core-js/modules/_strict-method.js","webpack://Oidc/./node_modules/core-js/modules/_string-at.js","webpack://Oidc/./node_modules/core-js/modules/_string-context.js","webpack://Oidc/./node_modules/core-js/modules/_string-html.js","webpack://Oidc/./node_modules/core-js/modules/_string-pad.js","webpack://Oidc/./node_modules/core-js/modules/_string-repeat.js","webpack://Oidc/./node_modules/core-js/modules/_string-trim.js","webpack://Oidc/./node_modules/core-js/modules/_string-ws.js","webpack://Oidc/./node_modules/core-js/modules/_task.js","webpack://Oidc/./node_modules/core-js/modules/_to-absolute-index.js","webpack://Oidc/./node_modules/core-js/modules/_to-index.js","webpack://Oidc/./node_modules/core-js/modules/_to-integer.js","webpack://Oidc/./node_modules/core-js/modules/_to-iobject.js","webpack://Oidc/./node_modules/core-js/modules/_to-length.js","webpack://Oidc/./node_modules/core-js/modules/_to-object.js","webpack://Oidc/./node_modules/core-js/modules/_to-primitive.js","webpack://Oidc/./node_modules/core-js/modules/_typed-array.js","webpack://Oidc/./node_modules/core-js/modules/_typed-buffer.js","webpack://Oidc/./node_modules/core-js/modules/_typed.js","webpack://Oidc/./node_modules/core-js/modules/_uid.js","webpack://Oidc/./node_modules/core-js/modules/_user-agent.js","webpack://Oidc/./node_modules/core-js/modules/_validate-collection.js","webpack://Oidc/./node_modules/core-js/modules/_wks-define.js","webpack://Oidc/./node_modules/core-js/modules/_wks-ext.js","webpack://Oidc/./node_modules/core-js/modules/_wks.js","webpack://Oidc/./node_modules/core-js/modules/core.get-iterator-method.js","webpack://Oidc/./node_modules/core-js/modules/core.regexp.escape.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.copy-within.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.every.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.fill.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.filter.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.find-index.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.find.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.for-each.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.from.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.index-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.is-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.iterator.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.join.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.last-index-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.map.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.of.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.reduce-right.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.reduce.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.slice.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.some.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.sort.js","webpack://Oidc/./node_modules/core-js/modules/es6.array.species.js","webpack://Oidc/./node_modules/core-js/modules/es6.date.now.js","webpack://Oidc/./node_modules/core-js/modules/es6.date.to-iso-string.js","webpack://Oidc/./node_modules/core-js/modules/es6.date.to-json.js","webpack://Oidc/./node_modules/core-js/modules/es6.date.to-primitive.js","webpack://Oidc/./node_modules/core-js/modules/es6.date.to-string.js","webpack://Oidc/./node_modules/core-js/modules/es6.function.bind.js","webpack://Oidc/./node_modules/core-js/modules/es6.function.has-instance.js","webpack://Oidc/./node_modules/core-js/modules/es6.function.name.js","webpack://Oidc/./node_modules/core-js/modules/es6.map.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.acosh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.asinh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.atanh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.cbrt.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.clz32.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.cosh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.expm1.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.fround.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.hypot.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.imul.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.log10.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.log1p.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.log2.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.sign.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.sinh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.tanh.js","webpack://Oidc/./node_modules/core-js/modules/es6.math.trunc.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.constructor.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.epsilon.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.is-finite.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.is-integer.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.is-nan.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.is-safe-integer.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.max-safe-integer.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.min-safe-integer.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.parse-float.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.parse-int.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.to-fixed.js","webpack://Oidc/./node_modules/core-js/modules/es6.number.to-precision.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.assign.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.create.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.define-properties.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.define-property.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.freeze.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.get-own-property-descriptor.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.get-own-property-names.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.get-prototype-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.is-extensible.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.is-frozen.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.is-sealed.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.is.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.keys.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.prevent-extensions.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.seal.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.set-prototype-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.object.to-string.js","webpack://Oidc/./node_modules/core-js/modules/es6.parse-float.js","webpack://Oidc/./node_modules/core-js/modules/es6.parse-int.js","webpack://Oidc/./node_modules/core-js/modules/es6.promise.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.apply.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.construct.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.define-property.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.delete-property.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.enumerate.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.get-own-property-descriptor.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.get-prototype-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.get.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.has.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.is-extensible.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.own-keys.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.prevent-extensions.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.set-prototype-of.js","webpack://Oidc/./node_modules/core-js/modules/es6.reflect.set.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.constructor.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.exec.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.flags.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.match.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.replace.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.search.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.split.js","webpack://Oidc/./node_modules/core-js/modules/es6.regexp.to-string.js","webpack://Oidc/./node_modules/core-js/modules/es6.set.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.anchor.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.big.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.blink.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.bold.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.code-point-at.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.ends-with.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.fixed.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.fontcolor.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.fontsize.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.from-code-point.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.includes.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.italics.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.iterator.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.link.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.raw.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.repeat.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.small.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.starts-with.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.strike.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.sub.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.sup.js","webpack://Oidc/./node_modules/core-js/modules/es6.string.trim.js","webpack://Oidc/./node_modules/core-js/modules/es6.symbol.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.array-buffer.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.data-view.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.float32-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.float64-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.int16-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.int32-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.int8-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.uint16-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.uint32-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.uint8-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.typed.uint8-clamped-array.js","webpack://Oidc/./node_modules/core-js/modules/es6.weak-map.js","webpack://Oidc/./node_modules/core-js/modules/es6.weak-set.js","webpack://Oidc/./node_modules/core-js/modules/es7.array.flat-map.js","webpack://Oidc/./node_modules/core-js/modules/es7.array.flatten.js","webpack://Oidc/./node_modules/core-js/modules/es7.array.includes.js","webpack://Oidc/./node_modules/core-js/modules/es7.asap.js","webpack://Oidc/./node_modules/core-js/modules/es7.error.is-error.js","webpack://Oidc/./node_modules/core-js/modules/es7.global.js","webpack://Oidc/./node_modules/core-js/modules/es7.map.from.js","webpack://Oidc/./node_modules/core-js/modules/es7.map.of.js","webpack://Oidc/./node_modules/core-js/modules/es7.map.to-json.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.clamp.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.deg-per-rad.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.degrees.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.fscale.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.iaddh.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.imulh.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.isubh.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.rad-per-deg.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.radians.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.scale.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.signbit.js","webpack://Oidc/./node_modules/core-js/modules/es7.math.umulh.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.define-getter.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.define-setter.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.entries.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.get-own-property-descriptors.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.lookup-getter.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.lookup-setter.js","webpack://Oidc/./node_modules/core-js/modules/es7.object.values.js","webpack://Oidc/./node_modules/core-js/modules/es7.observable.js","webpack://Oidc/./node_modules/core-js/modules/es7.promise.finally.js","webpack://Oidc/./node_modules/core-js/modules/es7.promise.try.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.define-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.delete-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.get-metadata-keys.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.get-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.get-own-metadata-keys.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.get-own-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.has-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.has-own-metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.reflect.metadata.js","webpack://Oidc/./node_modules/core-js/modules/es7.set.from.js","webpack://Oidc/./node_modules/core-js/modules/es7.set.of.js","webpack://Oidc/./node_modules/core-js/modules/es7.set.to-json.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.at.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.match-all.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.pad-end.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.pad-start.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.trim-left.js","webpack://Oidc/./node_modules/core-js/modules/es7.string.trim-right.js","webpack://Oidc/./node_modules/core-js/modules/es7.symbol.async-iterator.js","webpack://Oidc/./node_modules/core-js/modules/es7.symbol.observable.js","webpack://Oidc/./node_modules/core-js/modules/es7.system.global.js","webpack://Oidc/./node_modules/core-js/modules/es7.weak-map.from.js","webpack://Oidc/./node_modules/core-js/modules/es7.weak-map.of.js","webpack://Oidc/./node_modules/core-js/modules/es7.weak-set.from.js","webpack://Oidc/./node_modules/core-js/modules/es7.weak-set.of.js","webpack://Oidc/./node_modules/core-js/modules/web.dom.iterable.js","webpack://Oidc/./node_modules/core-js/modules/web.immediate.js","webpack://Oidc/./node_modules/core-js/modules/web.timers.js","webpack://Oidc/./node_modules/core-js/shim.js","webpack://Oidc/./node_modules/ieee754/index.js","webpack://Oidc/./node_modules/uuid/lib/bytesToUuid.js","webpack://Oidc/./node_modules/uuid/lib/rng-browser.js","webpack://Oidc/./node_modules/uuid/v4.js","webpack://Oidc/(webpack)/buildin/global.js","webpack://Oidc/./src/AccessTokenEvents.js","webpack://Oidc/./src/CheckSessionIFrame.js","webpack://Oidc/./src/CordovaIFrameNavigator.js","webpack://Oidc/./src/CordovaPopupNavigator.js","webpack://Oidc/./src/CordovaPopupWindow.js","webpack://Oidc/./src/ErrorResponse.js","webpack://Oidc/./src/Event.js","webpack://Oidc/./src/Global.js","webpack://Oidc/./src/IFrameNavigator.js","webpack://Oidc/./src/IFrameWindow.js","webpack://Oidc/./src/InMemoryWebStorage.js","webpack://Oidc/./src/JoseUtil.js","webpack://Oidc/./src/JoseUtilImpl.js","webpack://Oidc/./src/JsonService.js","webpack://Oidc/./src/Log.js","webpack://Oidc/./src/MetadataService.js","webpack://Oidc/./src/OidcClient.js","webpack://Oidc/./src/OidcClientSettings.js","webpack://Oidc/./src/PopupNavigator.js","webpack://Oidc/./src/PopupWindow.js","webpack://Oidc/./src/RedirectNavigator.js","webpack://Oidc/./src/ResponseValidator.js","webpack://Oidc/./src/SessionMonitor.js","webpack://Oidc/./src/SigninRequest.js","webpack://Oidc/./src/SigninResponse.js","webpack://Oidc/./src/SigninState.js","webpack://Oidc/./src/SignoutRequest.js","webpack://Oidc/./src/SignoutResponse.js","webpack://Oidc/./src/SilentRenewService.js","webpack://Oidc/./src/State.js","webpack://Oidc/./src/Timer.js","webpack://Oidc/./src/TokenClient.js","webpack://Oidc/./src/TokenRevocationClient.js","webpack://Oidc/./src/UrlUtility.js","webpack://Oidc/./src/User.js","webpack://Oidc/./src/UserInfoService.js","webpack://Oidc/./src/UserManager.js","webpack://Oidc/./src/UserManagerEvents.js","webpack://Oidc/./src/UserManagerSettings.js","webpack://Oidc/./src/WebStorageStateStore.js","webpack://Oidc/./src/crypto/jsrsasign.js","webpack://Oidc/./src/random.js","webpack://Oidc/./version.js"],"names":["Version","Log","OidcClient","OidcClientSettings","WebStorageStateStore","InMemoryWebStorage","UserManager","AccessTokenEvents","MetadataService","CordovaPopupNavigator","CordovaIFrameNavigator","CheckSessionIFrame","TokenRevocationClient","SessionMonitor","Global","User","navigator","userAgent","window","YAHOO","undefined","lang","extend","g","h","f","Error","d","prototype","constructor","superclass","Object","b","e","c","test","j","i","length","l","k","a","CryptoJS","lib","Base","n","p","o","mixIn","hasOwnProperty","init","$super","apply","arguments","create","toString","clone","WordArray","words","sigBytes","stringify","concat","t","q","s","clamp","r","ceil","call","slice","random","push","m","enc","Hex","join","parse","parseInt","substr","Latin1","String","fromCharCode","charCodeAt","Utf8","decodeURIComponent","escape","unescape","encodeURIComponent","BufferedBlockAlgorithm","reset","_data","_nDataBytes","_append","_process","w","x","blockSize","v","u","max","_minBufferSize","min","_doProcessBlock","splice","Hasher","cfg","_doReset","update","finalize","_doFinalize","_createHelper","_createHmacHelper","HMAC","algo","Math","x64","Word","high","low","toX32","Base64","_map","charAt","indexOf","sqrt","pow","SHA256","_hash","floor","HmacSHA256","T","ea","SHA512","F","G","H","I","J","X","K","Y","L","Z","M","$","N","aa","O","ba","P","ca","Q","z","A","y","U","B","R","C","S","D","V","E","W","fa","da","HmacSHA512","SHA384","HmacSHA384","b64map","b64pad","hex2b64","substring","b64tohex","int2char","b64toBA","Array","dbits","canary","j_lm","BigInteger","fromNumber","fromString","nbi","am1","am2","am3","appName","am","DB","DM","DV","BI_FP","FV","F1","F2","BI_RM","BI_RC","rr","vv","intAt","bnpCopyTo","bnpFromInt","nbv","fromInt","bnpFromString","fromRadix","ZERO","subTo","bnpClamp","bnToString","negate","toRadix","bnNegate","bnAbs","bnCompareTo","nbits","bnBitLength","bnpDLShiftTo","bnpDRShiftTo","bnpLShiftTo","bnpRShiftTo","bnpSubTo","bnpMultiplyTo","abs","bnpSquareTo","bnpDivRemTo","copyTo","lShiftTo","dlShiftTo","compareTo","ONE","drShiftTo","rShiftTo","bnMod","divRemTo","Classic","cConvert","mod","cRevert","cReduce","cMulTo","multiplyTo","reduce","cSqrTo","squareTo","convert","revert","mulTo","sqrTo","bnpInvDigit","Montgomery","mp","invDigit","mpl","mph","um","mt2","montConvert","montRevert","montReduce","montSqrTo","montMulTo","bnpIsEven","bnpExp","bnModPowInt","isEven","exp","bitLength","modPowInt","bnClone","bnIntValue","bnByteValue","bnShortValue","bnpChunkSize","LN2","log","bnSigNum","bnpToRadix","signum","chunkSize","intValue","bnpFromRadix","dMultiply","dAddOffset","bnpFromNumber","testBit","bitwiseTo","shiftLeft","op_or","isProbablePrime","nextBytes","bnToByteArray","bnEquals","bnMin","bnMax","bnpBitwiseTo","op_and","bnAnd","bnOr","op_xor","bnXor","op_andnot","bnAndNot","bnNot","bnShiftLeft","bnShiftRight","lbit","bnGetLowestSetBit","cbit","bnBitCount","bnTestBit","bnpChangeBit","bnSetBit","changeBit","bnClearBit","bnFlipBit","bnpAddTo","bnAdd","addTo","bnSubtract","bnMultiply","bnSquare","bnDivide","bnRemainder","bnDivideAndRemainder","bnpDMultiply","bnpDAddOffset","NullExp","nNop","nMulTo","nSqrTo","bnPow","bnpMultiplyLowerTo","bnpMultiplyUpperTo","Barrett","r2","q3","mu","divide","barrettConvert","barrettRevert","barrettReduce","multiplyUpperTo","multiplyLowerTo","barrettSqrTo","barrettMulTo","bnModPow","bnGCD","getLowestSetBit","bnpModInt","bnModInverse","subtract","add","lowprimes","lplim","bnIsProbablePrime","modInt","millerRabin","bnpMillerRabin","shiftRight","modPow","byteValue","shortValue","toByteArray","equals","and","or","xor","andNot","not","bitCount","setBit","clearBit","flipBit","multiply","remainder","divideAndRemainder","modInverse","gcd","square","Arcfour","ARC4init","ARC4next","next","prng_newstate","rng_psize","rng_state","rng_pool","rng_pptr","rng_seed_int","rng_seed_time","Date","getTime","crypto","msCrypto","getRandomValues","ua","Uint8Array","appVersion","rng_get_byte","rng_get_bytes","SecureRandom","parseBigInt","linebrk","byte2Hex","pkcs1pad2","oaep_mgf1_arr","oaep_pad","KJUR","MessageDigest","Util","getCanonicalAlgName","getHashLength","hextorstr","hashHex","rstrtohex","RSAKey","dmp1","dmq1","coeff","RSASetPublic","isPublic","isPrivate","RSADoPublic","RSAEncrypt","doPublic","RSAEncryptOAEP","setPublic","encrypt","encryptOAEP","type","ECFieldElementFp","feFpEquals","feFpToBigInteger","feFpNegate","feFpAdd","toBigInteger","feFpSubtract","feFpMultiply","feFpSquare","feFpDivide","ECPointFp","curve","zinv","pointFpGetX","fromBigInteger","pointFpGetY","pointFpEquals","isInfinity","pointFpIsInfinity","pointFpNegate","pointFpAdd","twice","getInfinity","pointFpTwice","pointFpMultiply","pointFpMultiplyTwo","getX","getY","multiplyTwo","ECCurveFp","infinity","curveFpGetQ","curveFpGetA","curveFpGetB","curveFpEquals","curveFpGetInfinity","curveFpFromBigInteger","curveFpDecodePointHex","getQ","getA","getB","decodePointHex","getByteLength","getEncoded","toByteArrayUnsigned","unshift","decodeFrom","decodeFromHex","add2D","twice2D","valueOf","multiply2D","isOnCurve","validate","jsonParse","RegExp","match","replace","shift","asn1","ASN1Util","integerToByteHex","bigIntToMinTwosComplementsHex","getPEMStringFromHex","hextopem","newObject","DERBoolean","DERInteger","DERBitString","DEROctetString","DERNull","DERObjectIdentifier","DEREnumerated","DERUTF8String","DERNumericString","DERPrintableString","DERTeletexString","DERIA5String","DERUTCTime","DERGeneralizedTime","DERSequence","DERSet","DERTaggedObject","keys","array","tag","explicit","obj","jsonToASN1HEX","getEncodedHex","oidHexToInt","oidIntToHex","split","ASN1Object","getLengthHexFromValue","hV","hTLV","isModified","getFreshValueHex","hL","hT","getValueHex","DERAbstractString","getString","setString","utf8tohex","toLowerCase","setStringHex","str","hex","DERAbstractTime","localDateToUTC","utc","getTimezoneOffset","formatDate","zeroPadding","getFullYear","getMonth","getDate","getHours","getMinutes","getSeconds","getMilliseconds","stohex","setByDateValue","UTC","setByDate","DERAbstractStructured","setByASN1ObjectArray","asn1Array","appendASN1Object","setByBigInteger","setByInteger","setValueHex","bigint","setHexValueIncludingUnusedBits","setUnusedBitsAndHexValue","setByBinaryString","setByBooleanArray","newFalseArray","bin","setValueOidString","setValueName","x509","OID","name2oid","oid","name","date","withMillis","millis","sortFlag","sort","sortflag","isExplicit","asn1Object","setASN1Object","ASN1HEX","getLblen","getL","getVblen","getVidx","getV","getTLV","getNextSiblingIdx","getChildIdx","getNthChildIdx","getIdxbyList","getTLVbyList","getVbyList","hextooidstr","dump","ommit_long_octet","isASN1HEX","oid2name","hextoutf8","oidname","JSON","x509ExtName","isHex","Base64x","stoBA","BAtos","BAtohex","stob64","stob64u","b64tob64u","b64utos","b64utob64","hextob64u","b64utohex","utf8tob64u","b64utoutf8","Buffer","uricmptohex","encodeURIComponentAll","hextouricmp","utf8tob64","b64toutf8","hextob64","hextob64nl","b64nltohex","pemtohex","hextoArrayBuffer","ArrayBuffer","DataView","setUint8","ArrayBuffertohex","byteLength","getUint8","zulutomsec","zulutosec","zulutodate","datetozulu","getUTCFullYear","getUTCMonth","getUTCDate","getUTCHours","getUTCMinutes","getUTCSeconds","getUTCMilliseconds","ipv6tohex","repeat","hextoipv6","hextoip","iptohex","newline_toUnix","newline_toDos","isInteger","isBase64","isBase64URL","isIntegerArray","hextoposhex","intarystrtohex","map","strdiffidx","DIGESTINFOHEAD","sha1","sha224","sha256","sha384","sha512","md2","md5","ripemd160","DEFAULTPROVIDER","hmacmd5","hmacsha1","hmacsha224","hmacsha256","hmacsha384","hmacsha512","hmacripemd160","MD5withRSA","SHA1withRSA","SHA224withRSA","SHA256withRSA","SHA384withRSA","SHA512withRSA","RIPEMD160withRSA","MD5withECDSA","SHA1withECDSA","SHA224withECDSA","SHA256withECDSA","SHA384withECDSA","SHA512withECDSA","RIPEMD160withECDSA","SHA1withDSA","SHA224withDSA","SHA256withDSA","MD5withRSAandMGF1","SHA1withRSAandMGF1","SHA224withRSAandMGF1","SHA256withRSAandMGF1","SHA384withRSAandMGF1","SHA512withRSAandMGF1","RIPEMD160withRSAandMGF1","CRYPTOJSMESSAGEDIGESTNAME","MD5","SHA1","SHA224","RIPEMD160","getDigestInfoHex","getPaddedDigestInfoHex","hashString","alg","digestString","digestHex","prov","sha256Hex","sha512Hex","SECURERANDOMGEN","getRandomHexOfNbytes","getRandomBigIntegerOfNbytes","getRandomHexOfNbits","getRandomBigIntegerOfNbits","getRandomBigIntegerZeroToMax","getRandomBigIntegerMinToMax","setAlgAndProvider","md","updateString","updateHex","digest","sjcl","hash","codec","toBits","fromBits","algName","provName","HASHLENGTH","Mac","algProv","mac","pass","doFinal","doFinalString","doFinalHex","setPassword","utf8","rstr","b64","b64u","Signature","_setAlgNames","mdAlgName","pubkeyAlgName","_zeroPaddingOfSignature","KEYUTIL","getKey","prvKey","state","pubKey","sign","sHashHex","ecprvhex","eccurvename","ECDSA","hSign","signHex","signWithMessageHashPSS","pssSaltLen","signWithMessageHash","DSA","signString","verify","ecpubhex","verifyHex","verifyWithMessageHashPSS","verifyWithMessageHash","algProvName","initParams","psssaltlen","prvkeypem","prvkeypas","Cipher","getAlgByKeyAndName","decrypt","decryptOAEP","oidhex2name","getBigRandom","setNamedCurve","ecparams","ECParameterDB","getByName","prvKeyHex","pubKeyHex","curveName","setPrivateKeyHex","setPublicKeyHex","getPublicKeyXYHex","keylen","getShortNISTPCurveName","generateKeyPairHex","biRSSigToASN1Sig","fromByteArrayUnsigned","serializeSig","parseSigHex","verifyRaw","Bitcoin","isArray","parseSig","toByteArraySigned","parseSigCompact","readPKCS5PrvKeyHex","getName","readPKCS8PrvKeyHex","readPKCS8PubKeyHex","readCertPubKeyHex","prv","pub","parseSigHexInHexRS","asn1SigToConcatSig","concatSigToASN1Sig","hexRSSigToASN1Sig","regist","AES","TripleDES","DES","key","iv","ciphertext","proc","eproc","ivlen","cipher","ivsalt","data","keyhex","ivhex","version","parsePKCS5PEM","getKeyAndUnusedIvByPasscodeAndIvsalt","decryptKeyB64","getDecryptedKeyHex","getEncryptedPKCS5PEMFromPrvKeyHex","toUpperCase","parseHexOfEncryptedPKCS8","encryptionSchemeAlg","encryptionSchemeIV","pbkdf2Salt","pbkdf2Iter","getPBKDF2KeyHexFromParam","PBKDF2","keySize","iterations","_getPlainPKCS8HexFromEncryptedPKCS8PEM","getKeyFromEncryptedPKCS8PEM","getKeyFromPlainPrivatePKCS8Hex","parsePlainPrivatePKCS8Hex","algparam","algoid","keyidx","getKeyFromPlainPrivatePKCS8PEM","_getKeyFromPublicPKCS8Hex","parsePublicRawRSAKeyHex","parsePublicPKCS8Hex","xy","kty","dp","dq","co","qi","setPrivateEx","setPrivate","crv","X509","getPublicKeyFromCertHex","getPublicKeyFromCertPEM","generateKeypair","generate","prvKeyObj","pubKeyObj","getPEM","SubjectPublicKeyInfo","seq","octstr","bitstr","getKeyFromCSRPEM","getKeyFromCSRHex","parseCSRHex","p8pubkeyhex","getJWKFromKey","getPosArrayOfChildrenFromHex","getHexValueArrayOfChildrenFromHex","readPrivateKeyFromPEMString","readPKCS5PubKeyHex","readCertHex","getPublicKeyHex","_RE_HEXDECONLY","compile","_rsasign_getHexPaddedDigestInfoForString","doPrivate","pss_mgf1_str","signPSS","_rsasign_getDecryptSignatureBI","_rsasign_getHexDigestInfoFromSig","_rsasign_getAlgNameAndHashFromHexDisgestInfo","verifyPSS","SALT_LEN_HLEN","SALT_LEN_MAX","SALT_LEN_RECOVER","foffset","aExtInfo","getVersion","getSerialNumberHex","getSignatureAlgorithmField","getIssuerHex","getIssuerString","hex2dn","getSubjectHex","getSubjectString","getNotBefore","getNotAfter","getPublicKeyIdx","getPublicKeyContentIdx","getPublicKey","getSignatureAlgorithmName","getSignatureValueHex","verifySignature","parseExt","critical","vidx","getExtInfo","getExtBasicConstraints","cA","pathLen","getExtKeyUsageBin","getExtKeyUsageString","KEYUSAGE_NAME","getExtSubjectKeyIdentifier","getExtAuthorityKeyIdentifier","kid","getExtExtKeyUsageName","getExtSubjectAltName","getExtSubjectAltName2","getExtCRLDistributionPointsURI","getExtAIAInfo","ocsp","caissuer","getExtCertificatePolicies","id","cps","unotice","readCertPEM","getInfo","hex2rdn","hex2attrTypeValue","oid2atype","getPublicKeyInfoPropOfCertPEM","jws","JWS","isSafeJSONString","parseJWS","parsedJWS","sigvalH","headB64U","payloadB64U","sigvalB64U","si","sigvalBI","headS","payloadS","readSafeJSONString","jwsalg2sigalg","hASN1Sig","headerObj","payloadObj","headerPP","payloadPP","sigHex","verifyJWT","inArray","includedArray","iss","sub","aud","IntDate","getNow","verifyAt","gracePeriod","nbf","iat","jti","HS256","HS384","HS512","RS256","RS384","RS512","ES256","ES384","PS256","PS384","PS512","none","getEncodedSignatureValueFromJWS","getJWKthumbprint","get","getZulu","intDate2UTCString","toUTCString","intDate2Zulu","EDSA","_crypto","DefaultAccessTokenExpiringNotificationTime","accessTokenExpiringNotificationTime","accessTokenExpiringTimer","Timer","accessTokenExpiredTimer","_accessTokenExpiringNotificationTime","_accessTokenExpiring","_accessTokenExpired","load","container","access_token","expires_in","duration","debug","expiring","cancel","expired","unload","addAccessTokenExpiring","cb","addHandler","removeAccessTokenExpiring","removeHandler","addAccessTokenExpired","removeAccessTokenExpired","DefaultInterval","callback","client_id","url","interval","stopOnError","_callback","_client_id","_url","_interval","_stopOnError","idx","_frame_origin","_frame","document","createElement","style","visibility","position","display","width","height","src","Promise","resolve","onload","body","appendChild","_boundMessageEvent","_message","bind","addEventListener","origin","source","contentWindow","error","stop","start","session_state","_session_state","send","postMessage","_timer","setInterval","clearInterval","prepare","params","popupWindowFeatures","popup","CordovaPopupWindow","DefaultPopupFeatures","DefaultPopupTarget","_promise","reject","_resolve","_reject","features","target","popupWindowTarget","redirect_uri","startUrl","_isInAppBrowserInstalled","cordovaMetadata","some","navigate","_error","cordova","require","metadata","_popup","InAppBrowser","open","_exitCallbackEvent","_exitCallback","_loadStartCallbackEvent","_loadStartCallback","promise","event","_success","message","_cleanup","close","removeEventListener","ErrorResponse","error_description","error_uri","Event","_name","_callbacks","findIndex","item","raise","timer","handle","testing","request","_testing","setXMLHttpRequest","newRequest","location","localStorage","sessionStorage","XMLHttpRequest","IFrameNavigator","frame","IFrameWindow","notifyParent","DefaultTimeout","timeout","silentRequestTimeout","setTimeout","_timeout","clearTimeout","removeChild","_origin","frameElement","href","parent","protocol","host","getItem","setItem","value","removeItem","index","getOwnPropertyNames","JoseUtil","KeyUtil","AllowedSigningAlgs","getJoseUtil","parseJwt","jwt","token","header","payload","validateJwt","issuer","audience","clockSkew","now","timeInsensitive","x5c","_validateJwt","validateJwtAttributes","validAudience","azp","lowerNow","upperNow","then","hexToBase64Url","JsonService","additionalContentTypes","XMLHttpRequestCtor","jwtHandler","_contentTypes","_XMLHttpRequest","_jwtHandler","getJson","req","allowedContentTypes","status","contentType","getResponseHeader","found","find","startsWith","responseText","statusText","onerror","setRequestHeader","postForm","nopLogger","info","warn","NONE","ERROR","WARN","INFO","DEBUG","logger","level","args","from","OidcMetadataUrlPath","settings","JsonServiceCtor","_settings","_jsonService","getMetadata","metadataUrl","getIssuer","_getMetadataProperty","getAuthorizationEndpoint","getUserInfoEndpoint","getTokenEndpoint","optional","getCheckSessionIframe","getEndSessionEndpoint","getRevocationEndpoint","getKeysEndpoint","getSigningKeys","signingKeys","jwks_uri","keySet","_metadataUrl","authority","createSigninRequest","response_type","scope","prompt","max_age","ui_locales","id_token_hint","login_hint","acr_values","resource","request_uri","response_mode","extraQueryParams","extraTokenParams","request_type","skipUserInfo","stateStore","SigninRequest","isCode","_metadataService","signinRequest","client_secret","signinState","_stateStore","set","toStorageString","readSigninResponseState","removeState","useQuery","delimiter","response","SigninResponse","stateApi","remove","storedStateString","SigninState","fromStorageString","processSigninResponse","_validator","validateSigninResponse","createSignoutRequest","post_logout_redirect_uri","SignoutRequest","signoutState","readSignoutResponseState","SignoutResponse","stateKey","State","processSignoutResponse","validateSignoutResponse","clearStaleState","staleStateAge","validator","metadataService","DefaultResponseType","DefaultScope","DefaultStaleStateAge","DefaultClockSkewInSeconds","filterProtocolClaims","loadUserInfo","userInfoJwtIssuer","ResponseValidatorCtor","ResponseValidator","MetadataServiceCtor","_authority","_metadata","_signingKeys","_client_secret","_response_type","_scope","_redirect_uri","_post_logout_redirect_uri","_prompt","_display","_max_age","_ui_locales","_acr_values","_resource","_response_mode","_filterProtocolClaims","_loadUserInfo","_staleStateAge","_clockSkew","_userInfoJwtIssuer","_extraQueryParams","_extraTokenParams","PopupNavigator","PopupWindow","keepOpen","notifyOpener","CheckForPopupClosedInterval","_checkForPopupClosedTimer","_checkForPopupClosed","_id","focus","closed","opener","UrlUtility","parseUrlFragment","RedirectNavigator","useReplaceToNavigate","ProtocolClaims","UserInfoServiceCtor","UserInfoService","joseUtil","TokenClientCtor","TokenClient","_userInfoService","_joseUtil","_tokenClient","_processSigninParams","_validateTokens","_processClaims","nonce","id_token","code_verifier","code","isOpenIdConnect","profile","getClaims","claims","_mergeClaims","claims1","claims2","result","assign","values","forEach","_processCode","_validateIdTokenAndAccessToken","_validateIdToken","exchangeCode","tokenResponse","_validateIdTokenAttributes","clockSkewInSeconds","_validateAccessToken","_filterByAlg","filter","at_hash","hashAlg","hashBits","sha","left","left_b64u","userManager","CheckSessionIFrameCtor","_userManager","_CheckSessionIFrameCtor","events","addUserLoaded","_start","addUserUnloaded","_stop","getUser","user","monitorAnonymousSession","querySessionStatus","tmpUser","session","sid","catch","err","_sub","_sid","_checkSessionIFrame","_checkSessionInterval","_stopCheckSessionOnError","timerHandle","raiseEvent","_raiseUserSessionChanged","_raiseUserSignedOut","_raiseUserSignedIn","checkSessionInterval","stopCheckSessionOnError","oidc","isOidc","addQueryParam","code_challenge","isOAuth","OidcScope","token_type","expires_at","scopes","_nonce","_code_verifier","_code_challenge","_skipUserInfo","created","storageString","SilentRenewService","_tokenExpiring","signinSilent","_raiseSilentRenewError","_created","_request_type","storage","age","cutoff","getAllKeys","promises","all","TimerDuration","nowFunc","_nowFunc","expiration","_timerHandle","_expiration","timerDuration","diff","grant_type","exchangeRefreshToken","refresh_token","AccessTokenTypeHint","RefreshTokenTypeHint","_XMLHttpRequestCtor","revoke","required","_revoke","xhr","global","lastIndexOf","regex","counter","exec","prop","_getClaimsFromJwt","issuerPromise","SilentRenewServiceCtor","SessionMonitorCtor","TokenRevocationClientCtor","UserManagerSettings","_events","UserManagerEvents","_silentRenewService","automaticSilentRenew","startSilentRenew","monitorSession","_sessionMonitor","_tokenRevocationClient","_loadUser","removeUser","storeUser","signinRedirect","navParams","_signinStart","_redirectNavigator","signinRedirectCallback","_signinEnd","signinPopup","popup_redirect_uri","_signin","_popupNavigator","signinPopupCallback","_signinCallback","_useRefreshToken","includeIdTokenInSilentRenew","validateSubOnSilentRenew","current_sub","_signinSilentIframe","idTokenValidation","_validateIdTokenFromTokenRefreshToken","auth_time","silent_redirect_uri","_iframeNavigator","signinSilentCallback","signinCallback","signoutCallback","signoutRedirectCallback","signoutPopupCallback","query_status_response_type","navResponse","signinResponse","navigatorParams","signoutRedirect","postLogoutRedirectUri","_signoutStart","_signoutEnd","signoutPopup","popup_post_logout_redirect_uri","_signout","revokePromise","revokeAccessTokenOnSignout","_revokeInternal","signoutRequest","signoutResponse","revokeAccessToken","success","_revokeAccessTokenInternal","_revokeRefreshTokenInternal","atSuccess","rtSuccess","stopSilentRenew","_userStore","_userStoreKey","redirectNavigator","popupNavigator","iframeNavigator","userStore","_userLoaded","_userUnloaded","_silentRenewError","_userSignedIn","_userSignedOut","_userSessionChanged","removeUserLoaded","removeUserUnloaded","addSilentRenewError","removeSilentRenewError","addUserSignedIn","removeUserSignedIn","addUserSignedOut","removeUserSignedOut","addUserSessionChanged","removeUserSessionChanged","DefaultCheckSessionInterval","store","_popup_redirect_uri","_popup_post_logout_redirect_uri","_popupWindowFeatures","_popupWindowTarget","_silent_redirect_uri","_silentRequestTimeout","_automaticSilentRenew","_validateSubOnSilentRenew","_includeIdTokenInSilentRenew","_monitorSession","_monitorAnonymousSession","_query_status_response_type","_revokeAccessTokenOnSignout","prefix","_store","_prefix"],"mappings":";;AAAA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;;AAGA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA,kDAA0C,gCAAgC;AAC1E;AACA;;AAEA;AACA;AACA;AACA,gEAAwD,kBAAkB;AAC1E;AACA,yDAAiD,cAAc;AAC/D;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,iDAAyC,iCAAiC;AAC1E,wHAAgH,mBAAmB,EAAE;AACrI;AACA;;AAEA;AACA;AACA;AACA,mCAA2B,0BAA0B,EAAE;AACvD,yCAAiC,eAAe;AAChD;AACA;AACA;;AAEA;AACA,8DAAsD,+DAA+D;;AAErH;AACA;;;AAGA;AACA;;;;;;;;;;;;;;;;;;;AC/EA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AAEA;;AAnBA;AACA;;kBAoBe;AACXA,6BADW;AAEXC,iBAFW;AAGXC,sCAHW;AAIXC,8DAJW;AAKXC,oEALW;AAMXC,8DANW;AAOXC,yCAPW;AAQXC,2DARW;AASXC,qDATW;AAUXC,uEAVW;AAWXC,0EAXW;AAYXC,8DAZW;AAaXC,uEAbW;AAcXC,kDAdW;AAeXC,0BAfW;AAgBXC;AAhBW,C;;;;;;;;;;;;;;;;;;;;;ACrBf;;;;AAIA,IAAIC,YAAY,EAAhB;AACAA,UAAUC,SAAV,GAAsB,KAAtB;;AAEA,IAAIC,SAAS,EAAb;;AAEA;;;;;;AAMA,IAAGC,UAAQC,SAAX,EAAqB;AAAC,MAAID,QAAM,EAAV;AAAa,OAAME,IAAN,GAAW,EAACC,QAAO,gBAASC,CAAT,EAAWC,CAAX,EAAaC,CAAb,EAAe;AAAC,QAAG,CAACD,CAAD,IAAI,CAACD,CAAR,EAAU;AAAC,YAAM,IAAIG,KAAJ,CAAU,4EAAV,CAAN;AAA8F,SAAIC,IAAE,SAAFA,CAAE,GAAU,CAAE,CAAlB,CAAmBA,EAAEC,SAAF,GAAYJ,EAAEI,SAAd,CAAwBL,EAAEK,SAAF,GAAY,IAAID,CAAJ,EAAZ,CAAoBJ,EAAEK,SAAF,CAAYC,WAAZ,GAAwBN,CAAxB,CAA0BA,EAAEO,UAAF,GAAaN,EAAEI,SAAf,CAAyB,IAAGJ,EAAEI,SAAF,CAAYC,WAAZ,IAAyBE,OAAOH,SAAP,CAAiBC,WAA7C,EAAyD;AAACL,QAAEI,SAAF,CAAYC,WAAZ,GAAwBL,CAAxB;AAA0B,SAAGC,CAAH,EAAK;AAAC,UAAIO,CAAJ,CAAM,KAAIA,CAAJ,IAASP,CAAT,EAAW;AAACF,UAAEK,SAAF,CAAYI,CAAZ,IAAeP,EAAEO,CAAF,CAAf;AAAoB,WAAIC,IAAE,aAAU,CAAE,CAAlB;AAAA,UAAmBC,IAAE,CAAC,UAAD,EAAY,SAAZ,CAArB,CAA4C,IAAG;AAAC,YAAG,OAAOC,IAAP,CAAYnB,UAAUC,SAAtB,CAAH,EAAoC;AAACgB,cAAE,WAASG,CAAT,EAAWC,CAAX,EAAa;AAAC,iBAAIL,IAAE,CAAN,EAAQA,IAAEE,EAAEI,MAAZ,EAAmBN,IAAEA,IAAE,CAAvB,EAAyB;AAAC,kBAAIO,IAAEL,EAAEF,CAAF,CAAN;AAAA,kBAAWQ,IAAEH,EAAEE,CAAF,CAAb,CAAkB,IAAG,OAAOC,CAAP,KAAW,UAAX,IAAuBA,KAAGT,OAAOH,SAAP,CAAiBW,CAAjB,CAA7B,EAAiD;AAACH,kBAAEG,CAAF,IAAKC,CAAL;AAAO;AAAC;AAAC,WAAvH;AAAwH;AAAC,OAAlK,CAAkK,OAAMC,CAAN,EAAQ,CAAE,GAAElB,EAAEK,SAAJ,EAAcH,CAAd;AAAiB;AAAC,GAA7lB,EAAX;AACnC;;;;;;;;AAQA,IAAIiB,WAASA,YAAW,UAAST,CAAT,EAAWV,CAAX,EAAa;AAAC,MAAIkB,IAAE,EAAN,CAAS,IAAIT,IAAES,EAAEE,GAAF,GAAM,EAAZ,CAAe,IAAIP,IAAEJ,EAAEY,IAAF,GAAQ,YAAU;AAAC,aAASC,CAAT,GAAY,CAAE,QAAM,EAACvB,QAAO,gBAASwB,CAAT,EAAW;AAACD,UAAEjB,SAAF,GAAY,IAAZ,CAAiB,IAAImB,IAAE,IAAIF,CAAJ,EAAN,CAAc,IAAGC,CAAH,EAAK;AAACC,YAAEC,KAAF,CAAQF,CAAR;AAAW,aAAG,CAACC,EAAEE,cAAF,CAAiB,MAAjB,CAAJ,EAA6B;AAACF,YAAEG,IAAF,GAAO,YAAU;AAACH,cAAEI,MAAF,CAASD,IAAT,CAAcE,KAAd,CAAoB,IAApB,EAAyBC,SAAzB;AAAoC,WAAtD;AAAuD,WAAEH,IAAF,CAAOtB,SAAP,GAAiBmB,CAAjB,CAAmBA,EAAEI,MAAF,GAAS,IAAT,CAAc,OAAOJ,CAAP;AAAS,OAAnM,EAAoMO,QAAO,kBAAU;AAAC,YAAIP,IAAE,KAAKzB,MAAL,EAAN,CAAoByB,EAAEG,IAAF,CAAOE,KAAP,CAAaL,CAAb,EAAeM,SAAf,EAA0B,OAAON,CAAP;AAAS,OAA7Q,EAA8QG,MAAK,gBAAU,CAAE,CAA/R,EAAgSF,OAAM,eAASF,CAAT,EAAW;AAAC,aAAI,IAAIC,CAAR,IAAaD,CAAb,EAAe;AAAC,cAAGA,EAAEG,cAAF,CAAiBF,CAAjB,CAAH,EAAuB;AAAC,iBAAKA,CAAL,IAAQD,EAAEC,CAAF,CAAR;AAAa;AAAC,aAAGD,EAAEG,cAAF,CAAiB,UAAjB,CAAH,EAAgC;AAAC,eAAKM,QAAL,GAAcT,EAAES,QAAhB;AAAyB;AAAC,OAAna,EAAoaC,OAAM,iBAAU;AAAC,eAAO,KAAKN,IAAL,CAAUtB,SAAV,CAAoBN,MAApB,CAA2B,IAA3B,CAAP;AAAwC,OAA7d,EAAN;AAAqe,GAA9f,EAAd,CAAghB,IAAIiB,IAAEP,EAAEyB,SAAF,GAAYrB,EAAEd,MAAF,CAAS,EAAC4B,MAAK,cAASH,CAAT,EAAWF,CAAX,EAAa;AAACE,UAAE,KAAKW,KAAL,GAAWX,KAAG,EAAhB,CAAmB,IAAGF,KAAGtB,CAAN,EAAQ;AAAC,aAAKoC,QAAL,GAAcd,CAAd;AAAgB,OAAzB,MAA6B;AAAC,aAAKc,QAAL,GAAcZ,EAAET,MAAF,GAAS,CAAvB;AAAyB;AAAC,KAA/F,EAAgGiB,UAAS,kBAASV,CAAT,EAAW;AAAC,aAAM,CAACA,KAAGrB,CAAJ,EAAOoC,SAAP,CAAiB,IAAjB,CAAN;AAA6B,KAAlJ,EAAmJC,QAAO,gBAASC,CAAT,EAAW;AAAC,UAAIC,IAAE,KAAKL,KAAX,CAAiB,IAAIZ,IAAEgB,EAAEJ,KAAR,CAAc,IAAIb,IAAE,KAAKc,QAAX,CAAoB,IAAIK,IAAEF,EAAEH,QAAR,CAAiB,KAAKM,KAAL,GAAa,IAAGpB,IAAE,CAAL,EAAO;AAAC,aAAI,IAAIqB,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,GAAhB,EAAoB;AAAC,cAAInB,IAAGD,EAAEoB,MAAI,CAAN,MAAY,KAAIA,IAAE,CAAH,GAAM,CAAtB,GAA0B,GAAhC,CAAoCH,EAAGlB,IAAEqB,CAAH,KAAQ,CAAV,KAAcnB,KAAI,KAAI,CAACF,IAAEqB,CAAH,IAAM,CAAP,GAAU,CAA/B;AAAkC;AAAC,OAApG,MAAwG;AAAC,aAAI,IAAIA,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,KAAG,CAAnB,EAAqB;AAACH,YAAGlB,IAAEqB,CAAH,KAAQ,CAAV,IAAapB,EAAEoB,MAAI,CAAN,CAAb;AAAsB;AAAC,YAAKP,QAAL,IAAeK,CAAf,CAAiB,OAAO,IAAP;AAAY,KAA1a,EAA2aC,OAAM,iBAAU;AAAC,UAAIlB,IAAE,KAAKW,KAAX,CAAiB,IAAIb,IAAE,KAAKc,QAAX,CAAoBZ,EAAEF,MAAI,CAAN,KAAU,cAAa,KAAIA,IAAE,CAAH,GAAM,CAAhC,CAAmCE,EAAET,MAAF,GAASL,EAAEkC,IAAF,CAAOtB,IAAE,CAAT,CAAT;AAAqB,KAAzhB,EAA0hBW,OAAM,iBAAU;AAAC,UAAIX,IAAET,EAAEoB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyBvB,EAAEa,KAAF,GAAQ,KAAKA,KAAL,CAAWW,KAAX,CAAiB,CAAjB,CAAR,CAA4B,OAAOxB,CAAP;AAAS,KAAzmB,EAA0mByB,QAAO,gBAASxB,CAAT,EAAW;AAAC,UAAIC,IAAE,EAAN,CAAS,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAEC,CAAd,EAAgBD,KAAG,CAAnB,EAAqB;AAACE,UAAEwB,IAAF,CAAQtC,EAAEqC,MAAF,KAAW,UAAZ,GAAwB,CAA/B;AAAkC,cAAO,IAAI/B,EAAEW,IAAN,CAAWH,CAAX,EAAaD,CAAb,CAAP;AAAuB,KAArtB,EAAT,CAAlB,CAAmvB,IAAI0B,IAAE/B,EAAEgC,GAAF,GAAM,EAAZ,CAAe,IAAIjD,IAAEgD,EAAEE,GAAF,GAAM,EAACd,WAAU,mBAASd,CAAT,EAAW;AAAC,UAAIoB,IAAEpB,EAAEY,KAAR,CAAc,IAAIX,IAAED,EAAEa,QAAR,CAAiB,IAAII,IAAE,EAAN,CAAS,KAAI,IAAIlB,IAAE,CAAV,EAAYA,IAAEE,CAAd,EAAgBF,GAAhB,EAAoB;AAAC,YAAImB,IAAGE,EAAErB,MAAI,CAAN,MAAY,KAAIA,IAAE,CAAH,GAAM,CAAtB,GAA0B,GAAhC,CAAoCkB,EAAEQ,IAAF,CAAO,CAACP,MAAI,CAAL,EAAQT,QAAR,CAAiB,EAAjB,CAAP,EAA6BQ,EAAEQ,IAAF,CAAO,CAACP,IAAE,EAAH,EAAOT,QAAP,CAAgB,EAAhB,CAAP;AAA4B,cAAOQ,EAAEY,IAAF,CAAO,EAAP,CAAP;AAAkB,KAAnM,EAAoMC,OAAM,eAAS9B,CAAT,EAAW;AAAC,UAAID,IAAEC,EAAER,MAAR,CAAe,IAAIyB,IAAE,EAAN,CAAS,KAAI,IAAIhB,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,KAAG,CAAnB,EAAqB;AAACgB,UAAEhB,MAAI,CAAN,KAAU8B,SAAS/B,EAAEgC,MAAF,CAAS/B,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,KAA6B,KAAIA,IAAE,CAAH,GAAM,CAAhD;AAAmD,cAAO,IAAIR,EAAEW,IAAN,CAAWa,CAAX,EAAalB,IAAE,CAAf,CAAP;AAAyB,KAAhV,EAAZ,CAA8V,IAAIlB,IAAE6C,EAAEO,MAAF,GAAS,EAACnB,WAAU,mBAASG,CAAT,EAAW;AAAC,UAAIG,IAAEH,EAAEL,KAAR,CAAc,IAAIZ,IAAEiB,EAAEJ,QAAR,CAAiB,IAAId,IAAE,EAAN,CAAS,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAED,CAAd,EAAgBC,GAAhB,EAAoB;AAAC,YAAIiB,IAAGE,EAAEnB,MAAI,CAAN,MAAY,KAAIA,IAAE,CAAH,GAAM,CAAtB,GAA0B,GAAhC,CAAoCF,EAAE0B,IAAF,CAAOS,OAAOC,YAAP,CAAoBjB,CAApB,CAAP;AAA+B,cAAOnB,EAAE8B,IAAF,CAAO,EAAP,CAAP;AAAkB,KAAzK,EAA0KC,OAAM,eAAS9B,CAAT,EAAW;AAAC,UAAID,IAAEC,EAAER,MAAR,CAAe,IAAIyB,IAAE,EAAN,CAAS,KAAI,IAAIhB,IAAE,CAAV,EAAYA,IAAEF,CAAd,EAAgBE,GAAhB,EAAoB;AAACgB,UAAEhB,MAAI,CAAN,KAAU,CAACD,EAAEoC,UAAF,CAAanC,CAAb,IAAgB,GAAjB,KAAwB,KAAIA,IAAE,CAAH,GAAM,CAA3C;AAA8C,cAAO,IAAIR,EAAEW,IAAN,CAAWa,CAAX,EAAalB,CAAb,CAAP;AAAuB,KAA9S,EAAf,CAA+T,IAAIX,IAAEsC,EAAEW,IAAF,GAAO,EAACvB,WAAU,mBAASf,CAAT,EAAW;AAAC,UAAG;AAAC,eAAOuC,mBAAmBC,OAAO1D,EAAEiC,SAAF,CAAYf,CAAZ,CAAP,CAAnB,CAAP;AAAkD,OAAtD,CAAsD,OAAME,CAAN,EAAQ;AAAC,cAAM,IAAIrB,KAAJ,CAAU,sBAAV,CAAN;AAAwC;AAAC,KAA/H,EAAgIkD,OAAM,eAAS/B,CAAT,EAAW;AAAC,aAAOlB,EAAEiD,KAAF,CAAQU,SAASC,mBAAmB1C,CAAnB,CAAT,CAAR,CAAP;AAAgD,KAAlM,EAAb,CAAiN,IAAIR,IAAEL,EAAEwD,sBAAF,GAAyBpD,EAAEd,MAAF,CAAS,EAACmE,OAAM,iBAAU;AAAC,WAAKC,KAAL,GAAW,IAAInD,EAAEW,IAAN,EAAX,CAAwB,KAAKyC,WAAL,GAAiB,CAAjB;AAAmB,KAA7D,EAA8DC,SAAQ,iBAAS/C,CAAT,EAAW;AAAC,UAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAACA,YAAEX,EAAE0C,KAAF,CAAQ/B,CAAR,CAAF;AAAa,YAAK6C,KAAL,CAAW7B,MAAX,CAAkBhB,CAAlB,EAAqB,KAAK8C,WAAL,IAAkB9C,EAAEc,QAApB;AAA6B,KAAxK,EAAyKkC,UAAS,kBAASC,CAAT,EAAW;AAAC,UAAI/B,IAAE,KAAK2B,KAAX,CAAiB,IAAIK,IAAEhC,EAAEL,KAAR,CAAc,IAAIb,IAAEkB,EAAEJ,QAAR,CAAiB,IAAIG,IAAE,KAAKkC,SAAX,CAAqB,IAAIC,IAAEnC,IAAE,CAAR,CAAU,IAAIoC,IAAErD,IAAEoD,CAAR,CAAU,IAAGH,CAAH,EAAK;AAACI,YAAEjE,EAAEkC,IAAF,CAAO+B,CAAP,CAAF;AAAY,OAAlB,MAAsB;AAACA,YAAEjE,EAAEkE,GAAF,CAAM,CAACD,IAAE,CAAH,IAAM,KAAKE,cAAjB,EAAgC,CAAhC,CAAF;AAAqC,WAAIpC,IAAEkC,IAAEpC,CAAR,CAAU,IAAII,IAAEjC,EAAEoE,GAAF,CAAMrC,IAAE,CAAR,EAAUnB,CAAV,CAAN,CAAmB,IAAGmB,CAAH,EAAK;AAAC,aAAI,IAAIlB,IAAE,CAAV,EAAYA,IAAEkB,CAAd,EAAgBlB,KAAGgB,CAAnB,EAAqB;AAAC,eAAKwC,eAAL,CAAqBP,CAArB,EAAuBjD,CAAvB;AAA0B,aAAIC,IAAEgD,EAAEQ,MAAF,CAAS,CAAT,EAAWvC,CAAX,CAAN,CAAoBD,EAAEJ,QAAF,IAAYO,CAAZ;AAAc,cAAO,IAAI3B,EAAEW,IAAN,CAAWH,CAAX,EAAamB,CAAb,CAAP;AAAuB,KAA/d,EAAgeV,OAAM,iBAAU;AAAC,UAAIX,IAAET,EAAEoB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyBvB,EAAE6C,KAAF,GAAQ,KAAKA,KAAL,CAAWlC,KAAX,EAAR,CAA2B,OAAOX,CAAP;AAAS,KAA9iB,EAA+iBuD,gBAAe,CAA9jB,EAAT,CAA/B,CAA0mB,IAAI3E,IAAEO,EAAEwE,MAAF,GAASnE,EAAEf,MAAF,CAAS,EAACmF,KAAIrE,EAAEd,MAAF,EAAL,EAAgB4B,MAAK,cAASL,CAAT,EAAW;AAAC,WAAK4D,GAAL,GAAS,KAAKA,GAAL,CAASnF,MAAT,CAAgBuB,CAAhB,CAAT,CAA4B,KAAK4C,KAAL;AAAa,KAA1E,EAA2EA,OAAM,iBAAU;AAACpD,QAAEoD,KAAF,CAAQrB,IAAR,CAAa,IAAb,EAAmB,KAAKsC,QAAL;AAAgB,KAA/H,EAAgIC,QAAO,gBAAS9D,CAAT,EAAW;AAAC,WAAK+C,OAAL,CAAa/C,CAAb,EAAgB,KAAKgD,QAAL,GAAgB,OAAO,IAAP;AAAY,KAA/L,EAAgMe,UAAS,kBAAS/D,CAAT,EAAW;AAAC,UAAGA,CAAH,EAAK;AAAC,aAAK+C,OAAL,CAAa/C,CAAb;AAAgB,WAAIE,IAAE,KAAK8D,WAAL,EAAN,CAAyB,OAAO9D,CAAP;AAAS,KAA7Q,EAA8QiD,WAAU,MAAI,EAA5R,EAA+Rc,eAAc,uBAASjE,CAAT,EAAW;AAAC,aAAO,UAASC,CAAT,EAAWC,CAAX,EAAa;AAAC,eAAO,IAAIF,EAAEK,IAAN,CAAWH,CAAX,EAAc6D,QAAd,CAAuB9D,CAAvB,CAAP;AAAiC,OAAtD;AAAuD,KAAhX,EAAiXiE,mBAAkB,2BAASlE,CAAT,EAAW;AAAC,aAAO,UAASC,CAAT,EAAWC,CAAX,EAAa;AAAC,eAAO,IAAIP,EAAEwE,IAAF,CAAO9D,IAAX,CAAgBL,CAAhB,EAAkBE,CAAlB,EAAqB6D,QAArB,CAA8B9D,CAA9B,CAAP;AAAwC,OAA7D;AAA8D,KAA7c,EAAT,CAAf,CAAwe,IAAIN,IAAEC,EAAEwE,IAAF,GAAO,EAAb,CAAgB,OAAOxE,CAAP;AAAS,CAAjxG,CAAkxGyE,IAAlxG,CAAxB;AACA;;;;;;AAMA,CAAC,UAAS3F,CAAT,EAAW;AAAC,MAAIkB,IAAEC,QAAN;AAAA,MAAejB,IAAEgB,EAAEE,GAAnB;AAAA,MAAuBV,IAAER,EAAEmB,IAA3B;AAAA,MAAgCpB,IAAEC,EAAEgC,SAApC;AAAA,MAA8ChB,IAAEA,EAAE0E,GAAF,GAAM,EAAtD,CAAyD1E,EAAE2E,IAAF,GAAOnF,EAAEX,MAAF,CAAS,EAAC4B,MAAK,cAASlB,CAAT,EAAWE,CAAX,EAAa;AAAC,WAAKmF,IAAL,GAAUrF,CAAV,CAAY,KAAKsF,GAAL,GAASpF,CAAT;AAAW,KAA3C,EAAT,CAAP,CAA8DO,EAAEgB,SAAF,GAAYxB,EAAEX,MAAF,CAAS,EAAC4B,MAAK,cAASlB,CAAT,EAAWE,CAAX,EAAa;AAACF,UAAE,KAAK0B,KAAL,GAAW1B,KAAG,EAAhB,CAAmB,KAAK2B,QAAL,GAAczB,KAAGX,CAAH,GAAKW,CAAL,GAAO,IAAEF,EAAEM,MAAzB;AAAgC,KAAvE,EAAwEiF,OAAM,iBAAU;AAAC,WAAI,IAAIvF,IAAE,KAAK0B,KAAX,EAAiBxB,IAAEF,EAAEM,MAArB,EAA4BG,IAAE,EAA9B,EAAiCd,IAAE,CAAvC,EAAyCA,IAAEO,CAA3C,EAA6CP,GAA7C,EAAiD;AAAC,YAAIM,IAAED,EAAEL,CAAF,CAAN,CAAWc,EAAE8B,IAAF,CAAOtC,EAAEoF,IAAT,EAAe5E,EAAE8B,IAAF,CAAOtC,EAAEqF,GAAT;AAAc,cAAO9F,EAAE8B,MAAF,CAASb,CAAT,EAAW,KAAKkB,QAAhB,CAAP;AAAiC,KAApN,EAAqNH,OAAM,iBAAU;AAAC,WAAI,IAAIxB,IAAEC,EAAEuB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,EAAyBlC,IAAEF,EAAE0B,KAAF,GAAQ,KAAKA,KAAL,CAAWW,KAAX,CAAiB,CAAjB,CAAnC,EAAuD5B,IAAEP,EAAEI,MAA3D,EAAkEX,IAAE,CAAxE,EAA0EA,IAAEc,CAA5E,EAA8Ed,GAA9E;AAAkFO,UAAEP,CAAF,IAAKO,EAAEP,CAAF,EAAK6B,KAAL,EAAL;AAAlF,OAAoG,OAAOxB,CAAP;AAAS,KAAnV,EAAT,CAAZ;AAA2W,CAA/e;;AAEA;;;;;;AAMA,CAAC,YAAU;AAAC,MAAIR,IAAEkB,QAAN;AAAA,MAAeN,IAAEZ,EAAEmB,GAAF,CAAMc,SAAvB,CAAiCjC,EAAEiD,GAAF,CAAM+C,MAAN,GAAa,EAAC5D,WAAU,mBAAS5B,CAAT,EAAW;AAAC,UAAIC,IAAED,EAAE0B,KAAR;AAAA,UAAcjC,IAAEO,EAAE2B,QAAlB;AAAA,UAA2BzB,IAAE,KAAKuF,IAAlC,CAAuCzF,EAAEiC,KAAF,GAAUjC,IAAE,EAAF,CAAK,KAAI,IAAIS,IAAE,CAAV,EAAYA,IAAEhB,CAAd,EAAgBgB,KAAG,CAAnB;AAAqB,aAAI,IAAId,IAAE,CAACM,EAAEQ,MAAI,CAAN,MAAW,KAAG,KAAGA,IAAE,CAAL,CAAd,GAAsB,GAAvB,KAA6B,EAA7B,GAAgC,CAACR,EAAEQ,IAAE,CAAF,KAAM,CAAR,MAAa,KAAG,KAAG,CAACA,IAAE,CAAH,IAAM,CAAT,CAAhB,GAA4B,GAA7B,KAAmC,CAAnE,GAAqER,EAAEQ,IAAE,CAAF,KAAM,CAAR,MAAa,KAAG,KAAG,CAACA,IAAE,CAAH,IAAM,CAAT,CAAhB,GAA4B,GAAvG,EAA2GlB,IAAE,CAAjH,EAAmH,IAAEA,CAAF,IAAKkB,IAAE,OAAKlB,CAAP,GAASE,CAAjI,EAAmIF,GAAnI;AAAuIS,YAAEuC,IAAF,CAAOrC,EAAEwF,MAAF,CAAS/F,MAAI,KAAG,IAAEJ,CAAL,CAAJ,GAAY,EAArB,CAAP;AAAvI;AAArB,OAA6L,IAAGU,IAAEC,EAAEwF,MAAF,CAAS,EAAT,CAAL,EAAkB,OAAK1F,EAAEM,MAAF,GAAS,CAAd;AAAiBN,UAAEuC,IAAF,CAAOtC,CAAP;AAAjB,OAA2B,OAAOD,EAAE2C,IAAF,CAAO,EAAP,CAAP;AAAkB,KAAzU,EAA0UC,OAAM,eAAS5C,CAAT,EAAW;AAAC,UAAIC,IAAED,EAAEM,MAAR;AAAA,UAAeb,IAAE,KAAKgG,IAAtB;AAAA,UAA2BvF,IAAET,EAAEiG,MAAF,CAAS,EAAT,CAA7B,CAA0CxF,MAAIA,IAAEF,EAAE2F,OAAF,CAAUzF,CAAV,CAAF,EAAe,CAAC,CAAD,IAAIA,CAAJ,KAAQD,IAAEC,CAAV,CAAnB,EAAiC,KAAI,IAAIA,IAAE,EAAN,EAASO,IAAE,CAAX,EAAad,IAAE,CAAnB,EAAqBA,IACtfM,CADie,EAC/dN,GAD+d;AAC3d,YAAGA,IAAE,CAAL,EAAO;AAAC,cAAIJ,IAAEE,EAAEkG,OAAF,CAAU3F,EAAE0F,MAAF,CAAS/F,IAAE,CAAX,CAAV,KAA0B,KAAGA,IAAE,CAAL,CAAhC;AAAA,cAAwCH,IAAEC,EAAEkG,OAAF,CAAU3F,EAAE0F,MAAF,CAAS/F,CAAT,CAAV,MAAyB,IAAE,KAAGA,IAAE,CAAL,CAArE,CAA6EO,EAAEO,MAAI,CAAN,KAAU,CAAClB,IAAEC,CAAH,KAAO,KAAG,KAAGiB,IAAE,CAAL,CAApB,CAA4BA;AAAI;AADsW,OACtW,OAAOL,EAAEkB,MAAF,CAASpB,CAAT,EAAWO,CAAX,CAAP;AAAqB,KADtF,EACuFgF,MAAK,mEAD5F,EAAb;AAC8K,CAD3N;;AAGA;;;;;;AAMA,CAAC,UAASjF,CAAT,EAAW;AAAC,OAAI,IAAIjB,IAAEmB,QAAN,EAAelB,IAAED,EAAEoB,GAAnB,EAAuBsD,IAAEzE,EAAEiC,SAA3B,EAAqCrB,IAAEZ,EAAEgF,MAAzC,EAAgDhF,IAAED,EAAE0F,IAApD,EAAyDjD,IAAE,EAA3D,EAA8DF,IAAE,EAAhE,EAAmEoC,IAAE,SAAFA,CAAE,CAASnC,CAAT,EAAW;AAAC,WAAO,cAAYA,KAAGA,IAAE,CAAL,CAAZ,IAAqB,CAA5B;AAA8B,GAA/G,EAAgHxB,IAAE,CAAlH,EAAoHP,IAAE,CAA1H,EAA4H,KAAGA,CAA/H,GAAkI;AAAC,QAAIL,CAAJ,CAAMc,GAAE;AAACd,UAAEY,CAAF,CAAI,KAAI,IAAIuD,IAAEtD,EAAEoF,IAAF,CAAOjG,CAAP,CAAN,EAAgBuC,IAAE,CAAtB,EAAwBA,KAAG4B,CAA3B,EAA6B5B,GAA7B;AAAiC,YAAG,EAAEvC,IAAEuC,CAAJ,CAAH,EAAU;AAACvC,cAAE,CAAC,CAAH,CAAK,MAAMc,CAAN;AAAQ;AAAzD,OAAyDd,IAAE,CAAC,CAAH;AAAK,WAAI,IAAEK,CAAF,KAAMgC,EAAEhC,CAAF,IAAKkE,EAAE1D,EAAEqF,GAAF,CAAMtF,CAAN,EAAQ,GAAR,CAAF,CAAX,GAA4BuB,EAAE9B,CAAF,IAAKkE,EAAE1D,EAAEqF,GAAF,CAAMtF,CAAN,EAAQ,IAAE,CAAV,CAAF,CAAjC,EAAiDP,GAArD,EAA0DO;AAAI,OAAIM,IAAE,EAAN;AAAA,MAASrB,IAAEA,EAAEsG,MAAF,GAAS1F,EAAEd,MAAF,CAAS,EAACoF,UAAS,oBAAU;AAAC,WAAKqB,KAAL,GAAW,IAAI9B,EAAE/C,IAAN,CAAWc,EAAEK,KAAF,CAAQ,CAAR,CAAX,CAAX;AAAkC,KAAvD,EAAwDiC,iBAAgB,yBAASvC,CAAT,EAAWvC,CAAX,EAAa;AAAC,WAAI,IAAIiB,IAAE,KAAKsF,KAAL,CAAWrE,KAAjB,EAAuBxB,IAAEO,EAAE,CAAF,CAAzB,EAA8Bd,IAAEc,EAAE,CAAF,CAAhC,EAAqCT,IAAES,EAAE,CAAF,CAAvC,EAA4CD,IAAEC,EAAE,CAAF,CAA9C,EAAmDhB,IAAEgB,EAAE,CAAF,CAArD,EAA0DlB,IAAEkB,EAAE,CAAF,CAA5D,EAAiEL,IAAEK,EAAE,CAAF,CAAnE,EAAwEF,IAAEE,EAAE,CAAF,CAA1E,EAA+ER,IAAE,CAArF,EAAuF,KAAGA,CAA1F,EAA4FA,GAA5F,EAAgG;AAAC,YAAG,KAAGA,CAAN,EAAQY,EAAEZ,CAAF,IACrf8B,EAAEvC,IAAES,CAAJ,IAAO,CAD8e,CAAR,KAChe;AAAC,cAAIuC,IAAE3B,EAAEZ,IAAE,EAAJ,CAAN;AAAA,cAAca,IAAED,EAAEZ,IAAE,CAAJ,CAAhB,CAAuBY,EAAEZ,CAAF,IAAK,CAAC,CAACuC,KAAG,EAAH,GAAMA,MAAI,CAAX,KAAeA,KAAG,EAAH,GAAMA,MAAI,EAAzB,IAA6BA,MAAI,CAAlC,IAAqC3B,EAAEZ,IAAE,CAAJ,CAArC,IAA6C,CAACa,KAAG,EAAH,GAAMA,MAAI,EAAX,KAAgBA,KAAG,EAAH,GAAMA,MAAI,EAA1B,IAA8BA,MAAI,EAA/E,IAAmFD,EAAEZ,IAAE,EAAJ,CAAxF;AAAgG,aAAEM,KAAG,CAACd,KAAG,EAAH,GAAMA,MAAI,CAAX,KAAeA,KAAG,EAAH,GAAMA,MAAI,EAAzB,KAA8BA,KAAG,CAAH,GAAKA,MAAI,EAAvC,CAAH,KAAgDA,IAAEF,CAAF,GAAI,CAACE,CAAD,GAAGW,CAAvD,IAA0D0B,EAAE7B,CAAF,CAA1D,GAA+DY,EAAEZ,CAAF,CAAjE,CAAsEa,IAAE,CAAC,CAACZ,KAAG,EAAH,GAAMA,MAAI,CAAX,KAAeA,KAAG,EAAH,GAAMA,MAAI,EAAzB,KAA8BA,KAAG,EAAH,GAAMA,MAAI,EAAxC,CAAD,KAA+CA,IAAEP,CAAF,GAAIO,IAAEF,CAAN,GAAQL,IAAEK,CAAzD,CAAF,CAA8DO,IAAEH,CAAF,CAAIA,IAAEb,CAAF,CAAIA,IAAEE,CAAF,CAAIA,IAAEe,IAAEgC,CAAF,GAAI,CAAN,CAAQhC,IAAER,CAAF,CAAIA,IAAEL,CAAF,CAAIA,IAAEO,CAAF,CAAIA,IAAEsC,IAAE1B,CAAF,GAAI,CAAN;AAAQ,SAAE,CAAF,IAAKL,EAAE,CAAF,IAAKP,CAAL,GAAO,CAAZ,CAAcO,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKd,CAAL,GAAO,CAAZ,CAAcc,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKT,CAAL,GAAO,CAAZ,CAAcS,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKD,CAAL,GAAO,CAAZ,CAAcC,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKhB,CAAL,GAAO,CAAZ,CAAcgB,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKlB,CAAL,GAAO,CAAZ,CAAckB,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKL,CAAL,GAAO,CAAZ,CAAcK,EAAE,CAAF,IAAKA,EAAE,CAAF,IAAKF,CAAL,GAAO,CAAZ;AAAc,KAD3G,EAC4GsE,aAAY,uBAAU;AAAC,UAAIlF,IAAE,KAAK+D,KAAX;AAAA,UAAiB1D,IAAEL,EAAE+B,KAArB;AAAA,UAA2BjB,IAAE,IAAE,KAAKkD,WAApC;AAAA,UAAgDzD,IAAE,IAAEP,EAAEgC,QAAtD;AACzb3B,QAAEE,MAAI,CAAN,KAAU,OAAK,KAAGA,IAAE,EAApB,CAAuBF,EAAE,CAACE,IAAE,EAAF,KAAO,CAAP,IAAU,CAAX,IAAc,EAAhB,IAAoBM,EAAEwF,KAAF,CAAQvF,IAAE,UAAV,CAApB,CAA0CT,EAAE,CAACE,IAAE,EAAF,KAAO,CAAP,IAAU,CAAX,IAAc,EAAhB,IAAoBO,CAApB,CAAsBd,EAAEgC,QAAF,GAAW,IAAE3B,EAAEM,MAAf,CAAsB,KAAKuD,QAAL,GAAgB,OAAO,KAAKkC,KAAZ;AAAkB,KAFuK,EAEtKvE,OAAM,iBAAU;AAAC,UAAIxB,IAAEI,EAAEoB,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyBpC,EAAE+F,KAAF,GAAQ,KAAKA,KAAL,CAAWvE,KAAX,EAAR,CAA2B,OAAOxB,CAAP;AAAS,KAFwF,EAAT,CAApB,CAExDT,EAAEuG,MAAF,GAAS1F,EAAE0E,aAAF,CAAgBtF,CAAhB,CAAT,CAA4BD,EAAE0G,UAAF,GAAa7F,EAAE2E,iBAAF,CAAoBvF,CAApB,CAAb;AAAoC,CAFjS,EAEmS0F,IAFnS;;AAIA;;;;;;AAMA,CAAC,YAAU;AAAC,WAASzE,CAAT,GAAY;AAAC,WAAOd,EAAE2B,MAAF,CAASF,KAAT,CAAezB,CAAf,EAAiB0B,SAAjB,CAAP;AAAmC,QAAI,IAAIR,IAAEH,QAAN,EAAewB,IAAErB,EAAEF,GAAF,CAAM6D,MAAvB,EAA8BvE,IAAEY,EAAEsE,GAAlC,EAAsCxF,IAAEM,EAAEmF,IAA1C,EAA+Cc,IAAEjG,EAAEwB,SAAnD,EAA6DxB,IAAEY,EAAEoE,IAAjE,EAAsEkB,KAAG,CAAC1F,EAAE,UAAF,EAAa,UAAb,CAAD,EAA0BA,EAAE,UAAF,EAAa,SAAb,CAA1B,EAAkDA,EAAE,UAAF,EAAa,UAAb,CAAlD,EAA2EA,EAAE,UAAF,EAAa,UAAb,CAA3E,EAAoGA,EAAE,SAAF,EAAY,UAAZ,CAApG,EAA4HA,EAAE,UAAF,EAAa,UAAb,CAA5H,EAAqJA,EAAE,UAAF,EAAa,UAAb,CAArJ,EAA8KA,EAAE,UAAF,EAAa,UAAb,CAA9K,EAAuMA,EAAE,UAAF,EAAa,UAAb,CAAvM,EAAgOA,EAAE,SAAF,EAAY,UAAZ,CAAhO,EAAwPA,EAAE,SAAF,EAAY,UAAZ,CAAxP,EAAgRA,EAAE,UAAF,EAAa,UAAb,CAAhR,EAAySA,EAAE,UAAF,EAAa,UAAb,CAAzS,EAAkUA,EAAE,UAAF,EAAa,SAAb,CAAlU,EAA0VA,EAAE,UAAF,EAAa,SAAb,CAA1V,EACzIA,EAAE,UAAF,EAAa,UAAb,CADyI,EAChHA,EAAE,UAAF,EAAa,UAAb,CADgH,EACvFA,EAAE,UAAF,EAAa,SAAb,CADuF,EAC/DA,EAAE,SAAF,EAAY,UAAZ,CAD+D,EACvCA,EAAE,SAAF,EAAY,UAAZ,CADuC,EACfA,EAAE,SAAF,EAAY,UAAZ,CADe,EACSA,EAAE,UAAF,EAAa,UAAb,CADT,EACkCA,EAAE,UAAF,EAAa,UAAb,CADlC,EAC2DA,EAAE,UAAF,EAAa,UAAb,CAD3D,EACoFA,EAAE,UAAF,EAAa,UAAb,CADpF,EAC6GA,EAAE,UAAF,EAAa,SAAb,CAD7G,EACqIA,EAAE,UAAF,EAAa,UAAb,CADrI,EAC8JA,EAAE,UAAF,EAAa,UAAb,CAD9J,EACuLA,EAAE,UAAF,EAAa,UAAb,CADvL,EACgNA,EAAE,UAAF,EAAa,UAAb,CADhN,EACyOA,EAAE,SAAF,EAAY,UAAZ,CADzO,EACiQA,EAAE,SAAF,EAAY,SAAZ,CADjQ,EACwRA,EAAE,SAAF,EAAY,UAAZ,CADxR,EACgTA,EAAE,SAAF,EAAY,UAAZ,CADhT,EACwUA,EAAE,UAAF,EAAa,UAAb,CADxU,EACiWA,EAAE,UAAF,EAC1e,UAD0e,CADjW,EAE7HA,EAAE,UAAF,EAAa,UAAb,CAF6H,EAEpGA,EAAE,UAAF,EAAa,UAAb,CAFoG,EAE3EA,EAAE,UAAF,EAAa,UAAb,CAF2E,EAElDA,EAAE,UAAF,EAAa,SAAb,CAFkD,EAE1BA,EAAE,UAAF,EAAa,UAAb,CAF0B,EAEDA,EAAE,UAAF,EAAa,UAAb,CAFC,EAEwBA,EAAE,UAAF,EAAa,UAAb,CAFxB,EAEiDA,EAAE,UAAF,EAAa,SAAb,CAFjD,EAEyEA,EAAE,UAAF,EAAa,UAAb,CAFzE,EAEkGA,EAAE,UAAF,EAAa,UAAb,CAFlG,EAE2HA,EAAE,UAAF,EAAa,UAAb,CAF3H,EAEoJA,EAAE,SAAF,EAAY,SAAZ,CAFpJ,EAE2KA,EAAE,SAAF,EAAY,UAAZ,CAF3K,EAEmMA,EAAE,SAAF,EAAY,UAAZ,CAFnM,EAE2NA,EAAE,SAAF,EAAY,UAAZ,CAF3N,EAEmPA,EAAE,SAAF,EAAY,UAAZ,CAFnP,EAE2QA,EAAE,SAAF,EAAY,UAAZ,CAF3Q,EAEmSA,EAAE,UAAF,EAAa,UAAb,CAFnS,EAE4TA,EAAE,UAAF,EAAa,UAAb,CAF5T,EAEqVA,EAAE,UAAF,EAAa,UAAb,CAFrV,EAGzIA,EAAE,UAAF,EAAa,UAAb,CAHyI,EAGhHA,EAAE,UAAF,EAAa,UAAb,CAHgH,EAGvFA,EAAE,UAAF,EAAa,UAAb,CAHuF,EAG9DA,EAAE,UAAF,EAAa,SAAb,CAH8D,EAGtCA,EAAE,UAAF,EAAa,SAAb,CAHsC,EAGdA,EAAE,UAAF,EAAa,UAAb,CAHc,EAGWA,EAAE,UAAF,EAAa,UAAb,CAHX,EAGoCA,EAAE,UAAF,EAAa,UAAb,CAHpC,EAG6DA,EAAE,UAAF,EAAa,UAAb,CAH7D,EAGsFA,EAAE,UAAF,EAAa,SAAb,CAHtF,EAG8GA,EAAE,UAAF,EAAa,UAAb,CAH9G,EAGuIA,EAAE,UAAF,EAAa,UAAb,CAHvI,EAGgKA,EAAE,SAAF,EAAY,UAAZ,CAHhK,EAGwLA,EAAE,SAAF,EAAY,UAAZ,CAHxL,EAGgNA,EAAE,SAAF,EAAY,UAAZ,CAHhN,EAGwOA,EAAE,SAAF,EAAY,SAAZ,CAHxO,EAG+PA,EAAE,SAAF,EAAY,SAAZ,CAH/P,EAGsRA,EAAE,SAAF,EAAY,UAAZ,CAHtR,EAG8SA,EAAE,UAAF,EAAa,SAAb,CAH9S,EAGsUA,EAAE,UAAF,EAAa,UAAb,CAHtU,EAG+VA,EAAE,UAAF,EACxe,UADwe,CAH/V,EAI7HA,EAAE,UAAF,EAAa,UAAb,CAJ6H,EAIpGA,EAAE,UAAF,EAAa,SAAb,CAJoG,EAI5EA,EAAE,UAAF,EAAa,UAAb,CAJ4E,CAAzE,EAIuBwD,IAAE,EAJzB,EAI4BH,IAAE,CAJlC,EAIoC,KAAGA,CAJvC,EAIyCA,GAJzC;AAI6CG,MAAEH,CAAF,IAAKrD,GAAL;AAJ7C,GAIsDR,IAAEA,EAAEmG,MAAF,GAASlE,EAAE5C,MAAF,CAAS,EAACoF,UAAS,oBAAU;AAAC,WAAKqB,KAAL,GAAW,IAAIG,EAAEhF,IAAN,CAAW,CAAC,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAD,EAAmC,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAnC,EAAqE,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAArE,EAAuG,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAvG,EAAyI,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAzI,EAA2K,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAA3K,EAA4M,IAAIvB,EAAEuB,IAAN,CAAW,SAAX,EAAqB,UAArB,CAA5M,EAA6O,IAAIvB,EAAEuB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAA7O,CAAX,CAAX;AAAsS,KAA3T,EAA4ToD,iBAAgB,yBAAS7D,CAAT,EAAWd,CAAX,EAAa;AAAC,WAAI,IAAIF,IAAE,KAAKsG,KAAL,CAAWrE,KAAjB,EACpe2E,IAAE5G,EAAE,CAAF,CADke,EAC7dQ,IAAER,EAAE,CAAF,CAD2d,EACtdoB,IAAEpB,EAAE,CAAF,CADod,EAC/cyC,IAAEzC,EAAE,CAAF,CAD6c,EACxc6G,IAAE7G,EAAE,CAAF,CADsc,EACjc8G,IAAE9G,EAAE,CAAF,CAD+b,EAC1b+G,IAAE/G,EAAE,CAAF,CADwb,EACnbA,IAAEA,EAAE,CAAF,CADib,EAC5aqE,IAAEuC,EAAEhB,IADwa,EACnaoB,IAAEJ,EAAEf,GAD+Z,EAC3ZoB,IAAEzG,EAAEoF,IADuZ,EAClZsB,IAAE1G,EAAEqF,GAD8Y,EAC1YsB,IAAE/F,EAAEwE,IADsY,EACjYwB,IAAEhG,EAAEyE,GAD6X,EACzXwB,IAAE5E,EAAEmD,IADqX,EAChX0B,IAAE7E,EAAEoD,GAD4W,EACxW0B,IAAEV,EAAEjB,IADoW,EAC/V4B,IAAEX,EAAEhB,GAD2V,EACvV4B,KAAGX,EAAElB,IADkV,EAC7U8B,IAAEZ,EAAEjB,GADyU,EACrU8B,KAAGZ,EAAEnB,IADgU,EAC3TgC,IAAEb,EAAElB,GADuT,EACnTgC,KAAG7H,EAAE4F,IAD8S,EACzSkC,IAAE9H,EAAE6F,GADqS,EACjS9E,IAAEsD,CAD+R,EAC7RvE,IAAEkH,CAD2R,EACzRe,IAAEd,CADuR,EACrR3C,IAAE4C,CADmR,EACjRc,IAAEb,CAD+Q,EAC7Qc,IAAEb,CAD2Q,EACzQc,IAAEb,CADuQ,EACrQc,IAAEb,CADmQ,EACjQxG,IAAEyG,CAD+P,EAC7PxH,IAAEyH,CAD2P,EACzPY,IAAEX,EADuP,EACpPY,IAAEX,CADkP,EAChPY,IAAEX,EAD8O,EAC3OY,IAAEX,CADyO,EACvOY,IAAEX,EADqO,EAClOY,IAAEX,CADgO,EAC9N/E,IAAE,CADwN,EACtN,KAAGA,CADmN,EACjNA,GADiN,EAC7M;AAAC,YAAIR,IAAEiC,EAAEzB,CAAF,CAAN,CAAW,IAAG,KAAGA,CAAN,EAAQ,IAAIpC,IAAE4B,EAAEqD,IAAF,GAAO5E,EAAEd,IAAE,IAAE6C,CAAN,IAAS,CAAtB;AAAA,YAAwBxC,IAAEgC,EAAEsD,GAAF,GAAM7E,EAAEd,IAAE,IAAE6C,CAAJ,GAAM,CAAR,IAAW,CAA3C,CAAR,KAAyD;AAAC,cAAIpC,IAAE6D,EAAEzB,IAAE,EAAJ,CAAN;AAAA,cAAcxC,IAAEI,EAAEiF,IAAlB;AAAA,cAAuBvE,IAAEV,EAAEkF,GAA3B;AAAA,cAA+BlF,IAAE,CAACJ,MAAI,CAAJ,GAAMc,KAAG,EAAV,KAAed,MAAI,CAAJ,GAAMc,KAAG,EAAxB,IAA4Bd,MAAI,CAAjE;AAAA,cAAmEc,IAAE,CAACA,MAAI,CAAJ,GAAMd,KAAG,EAAV,KAAec,MAAI,CAAJ,GAAMd,KAAG,EAAxB,KAA6Bc,MAAI,CAAJ,GAAMd,KAAG,EAAtC,CAArE;AAAA,cAA+GkE,IAAED,EAAEzB,IAAE,CAAJ,CAAjH;AAAA,cAAwHxC,IAAEkE,EAAEmB,IAA5H;AAAA,cAAiInF,IAAEgE,EAAEoB,GAArI;AAAA,cAAyIpB,IAAE,CAAClE,MAAI,EAAJ,GAAOE,KAAG,EAAX,KAAgBF,KACpf,CADof,GAClfE,MAAI,EAD8d,IAC1dF,MAAI,CAD2U;AAAA,cACzUE,IAAE,CAACA,MAAI,EAAJ,GAAOF,KAAG,EAAX,KAAgBE,KAAG,CAAH,GAAKF,MAAI,EAAzB,KAA8BE,MAAI,CAAJ,GAAMF,KAAG,EAAvC,CADuU;AAAA,cAC5RA,IAAEiE,EAAEzB,IAAE,CAAJ,CAD0R;AAAA,cACnR2F,IAAEnI,EAAEqF,IAD+Q;AAAA,cAC1QvD,IAAEmC,EAAEzB,IAAE,EAAJ,CADwQ;AAAA,cAChQT,IAAED,EAAEuD,IAD4P;AAAA,cACvPvD,IAAEA,EAAEwD,GADmP;AAAA,cAC/OtF,IAAEc,IAAEd,EAAEsF,GADyO;AAAA,cACrOlF,IAAEA,IAAE+H,CAAF,IAAKnI,MAAI,CAAJ,GAAMc,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADmO;AAAA,cAC7Md,IAAEA,IAAEE,CADyM;AAAA,cACvME,IAAEA,IAAE8D,CAAF,IAAKlE,MAAI,CAAJ,GAAME,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADqM;AAAA,cAC/KF,IAAEA,IAAE8B,CAD2K;AAAA,cACzK1B,IAAEA,IAAE2B,CAAF,IAAK/B,MAAI,CAAJ,GAAM8B,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADuK,CACjJE,EAAEqD,IAAF,GAAOjF,CAAP,CAAS4B,EAAEsD,GAAF,GAAMtF,CAAN;AAAQ,aAAImI,IAAE5H,IAAEsH,CAAF,GAAI,CAACtH,CAAD,GAAGwH,CAAb;AAAA,YAAejG,IAAEtC,IAAEsI,CAAF,GAAI,CAACtI,CAAD,GAAGwI,CAAxB;AAAA,YAA0BhG,IAAExB,IAAEgH,CAAF,GAAIhH,IAAEiH,CAAN,GAAQD,IAAEC,CAAtC;AAAA,YAAwCvB,IAAE3G,IAAEwE,CAAF,GAAIxE,IAAEmI,CAAN,GAAQ3D,IAAE2D,CAApD;AAAA,YAAsD5G,IAAE,CAACN,MAAI,EAAJ,GAAOjB,KAAG,CAAX,KAAeiB,KAAG,EAAH,GAAMjB,MAAI,CAAzB,KAA6BiB,KAAG,EAAH,GAAMjB,MAAI,CAAvC,CAAxD;AAAA,YAAkG2E,IAAE,CAAC3E,MAAI,EAAJ,GAAOiB,KAAG,CAAX,KAAejB,KAAG,EAAH,GAAMiB,MAAI,CAAzB,KAA6BjB,KAAG,EAAH,GAAMiB,MAAI,CAAvC,CAApG;AAAA,YAA8IN,IAAEiG,GAAG3D,CAAH,CAAhJ;AAAA,YAAsJ4F,KAAGlI,EAAEmF,IAA3J;AAAA,YAAgKgD,KAAGnI,EAAEoF,GAArK;AAAA,YAAyKpF,IAAEgI,KAAG,CAAC1I,MAAI,EAAJ,GAAOe,KAAG,EAAX,KAAgBf,MAAI,EAAJ,GAAOe,KAAG,EAA1B,KAA+Bf,KAAG,EAAH,GAAMe,MAAI,CAAzC,CAAH,CAA3K;AAAA,YAA2NwB,IAAEkG,KAAG,CAAC1H,MAAI,EAAJ,GAAOf,KAAG,EAAX,KAAgBe,MAAI,EAAJ,GAAOf,KAAG,EAA1B,KAA+Be,KAAG,EAAH,GAAMf,MAAI,CAAzC,CAAH,KAAiDU,MAAI,CAAJ,GAAMgI,MAAI,CAAV,GAAY,CAAZ,GACve,CADsb,CAA7N;AAAA,YACtNhI,IAAEA,IAAE4B,CADkN;AAAA,YAChNC,IAAEA,IAAEoG,CAAF,IAAKjI,MAAI,CAAJ,GAAM4B,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAD8M;AAAA,YACxL5B,IAAEA,IAAEmI,EADoL;AAAA,YACjLtG,IAAEA,IAAEqG,EAAF,IAAMlI,MAAI,CAAJ,GAAMmI,OAAK,CAAX,GAAa,CAAb,GAAe,CAArB,CAD+K;AAAA,YACvJnI,IAAEA,IAAEF,CADmJ;AAAA,YACjJ+B,IAAEA,IAAE3B,CAAF,IAAKF,MAAI,CAAJ,GAAMF,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAD+I;AAAA,YACzHA,IAAEkE,IAAEgC,CADqH;AAAA,YACnHlE,IAAElB,IAAEkB,CAAF,IAAKhC,MAAI,CAAJ,GAAMkE,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CADiH;AAAA,YAC3F+D,IAAEF,CADyF;AAAA,YACvFG,IAAEF,CADqF;AAAA,YACnFD,IAAEF,CADiF;AAAA,YAC/EG,IAAEF,CAD6E;AAAA,YAC3ED,IAAEtH,CADyE;AAAA,YACvEuH,IAAEtI,CADqE;AAAA,YACnEA,IAAEoI,IAAE1H,CAAF,GAAI,CAD6D;AAAA,YAC3DK,IAAEoH,IAAE5F,CAAF,IAAKvC,MAAI,CAAJ,GAAMoI,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,IAAsB,CADmC;AAAA,YACjCD,IAAEF,CAD+B;AAAA,YAC7BG,IAAEF,CAD2B;AAAA,YACzBD,IAAED,CADuB;AAAA,YACrBE,IAAE3D,CADmB;AAAA,YACjByD,IAAEhH,CADe;AAAA,YACbuD,IAAExE,CADW;AAAA,YACTA,IAAEW,IAAEF,CAAF,GAAI,CADG;AAAA,YACDQ,IAAEuB,IAAEC,CAAF,IAAKzC,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,IAAsB,CADvB;AACyB,WAAEmG,EAAEf,GAAF,GAAMmB,IAAElH,CAAV,CAAY8G,EAAEhB,IAAF,GAAOvB,IAAEtD,CAAF,IAAKiG,MAAI,CAAJ,GAAMlH,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6BoH,IAAE1G,EAAEqF,GAAF,GAAMqB,IAAE5C,CAAV,CAAY9D,EAAEoF,IAAF,GAAOqB,IAAEc,CAAF,IAAKb,MAAI,CAAJ,GAAM5C,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6B8C,IAAEhG,EAAEyE,GAAF,GAAMuB,IAAEa,CAAV,CAAY7G,EAAEwE,IAAF,GAAOuB,IAAEa,CAAF,IAAKZ,MAAI,CAAJ,GAAMa,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6BX,IAAE7E,EAAEoD,GAAF,GAAMyB,IAAEa,CAAV,CAAY1F,EAAEmD,IAAF,GAAOyB,IAAEa,CAAF,IAAKZ,MAAI,CAAJ,GAAMa,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6BX,IAAEX,EAAEhB,GAAF,GAAM2B,IAAEzH,CAAV,CAAY8G,EAAEjB,IAAF,GAAO2B,IAAEzG,CAAF,IAAK0G,MAAI,CAAJ,GAAMzH,MAAI,CAAV,GAAY,CAAZ,GAAc,CAAnB,CAAP,CAA6B2H,IAAEZ,EAAEjB,GAAF,GAAM6B,IAAEW,CAAV,CAAYvB,EAAElB,IAAF,GAAO6B,KAAGW,CAAH,IAAMV,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAApB,CAAP,CAA8BT,IAAEb,EAAElB,GAAF,GAAM+B,IAAEW,CAAV;AACzexB,QAAEnB,IAAF,GAAO+B,KAAGW,CAAH,IAAMV,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAApB,CAAP,CAA8BT,IAAE9H,EAAE6F,GAAF,GAAMiC,IAAEW,CAAV,CAAYzI,EAAE4F,IAAF,GAAOiC,KAAGW,CAAH,IAAMV,MAAI,CAAJ,GAAMW,MAAI,CAAV,GAAY,CAAZ,GAAc,CAApB,CAAP;AAA8B,KAJ8D,EAI7DrD,aAAY,uBAAU;AAAC,UAAIpE,IAAE,KAAKiD,KAAX;AAAA,UAAiB/D,IAAEc,EAAEiB,KAArB;AAAA,UAA2BjC,IAAE,IAAE,KAAKkE,WAApC;AAAA,UAAgD1D,IAAE,IAAEQ,EAAEkB,QAAtD,CAA+DhC,EAAEM,MAAI,CAAN,KAAU,OAAK,KAAGA,IAAE,EAApB,CAAuBN,EAAE,CAACM,IAAE,GAAF,KAAQ,EAAR,IAAY,CAAb,IAAgB,EAAlB,IAAsBiF,KAAKc,KAAL,CAAWvG,IAAE,UAAb,CAAtB,CAA+CE,EAAE,CAACM,IAAE,GAAF,KAAQ,EAAR,IAAY,CAAb,IAAgB,EAAlB,IAAsBR,CAAtB,CAAwBgB,EAAEkB,QAAF,GAAW,IAAEhC,EAAEW,MAAf,CAAsB,KAAKuD,QAAL,GAAgB,OAAO,KAAKkC,KAAL,CAAWR,KAAX,EAAP;AAA0B,KAJvL,EAIwL/D,OAAM,iBAAU;AAAC,UAAIf,IAAEyB,EAAEV,KAAF,CAAQY,IAAR,CAAa,IAAb,CAAN,CAAyB3B,EAAEsF,KAAF,GAAQ,KAAKA,KAAL,CAAWvE,KAAX,EAAR,CAA2B,OAAOf,CAAP;AAAS,KAJtQ,EAIuQuD,WAAU,EAJjR,EAAT,CAAX,CAI0SnD,EAAEuF,MAAF,GAASlE,EAAE4C,aAAF,CAAgB7E,CAAhB,CAAT,CAA4BY,EAAEyH,UAAF,GAAapG,EAAE6C,iBAAF,CAAoB9E,CAApB,CAAb;AAAoC,CAR5d;;AAUA;;;;;;AAMA,CAAC,YAAU;AAAC,MAAIC,IAAEQ,QAAN;AAAA,MAAeD,IAAEP,EAAEiF,GAAnB;AAAA,MAAuBnF,IAAES,EAAE2E,IAA3B;AAAA,MAAgCnF,IAAEQ,EAAEgB,SAApC;AAAA,MAA8ChB,IAAEP,EAAE+E,IAAlD;AAAA,MAAuDtF,IAAEc,EAAE2F,MAA3D;AAAA,MAAkE3F,IAAEA,EAAE8H,MAAF,GAAS5I,EAAEL,MAAF,CAAS,EAACoF,UAAS,oBAAU;AAAC,WAAKqB,KAAL,GAAW,IAAI9F,EAAEiB,IAAN,CAAW,CAAC,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAD,EAAmC,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAAnC,EAAoE,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,SAAtB,CAApE,EAAqG,IAAIlB,EAAEkB,IAAN,CAAW,SAAX,EAAqB,UAArB,CAArG,EAAsI,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAtI,EAAwK,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAAxK,EAA0M,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAA1M,EAA4O,IAAIlB,EAAEkB,IAAN,CAAW,UAAX,EAAsB,UAAtB,CAA5O,CAAX,CAAX;AAAsS,KAA3T,EAA4T2D,aAAY,uBAAU;AAAC,UAAIpE,IAAEd,EAAEkF,WAAF,CAAczC,IAAd,CAAmB,IAAnB,CAAN,CAA+B3B,EAAEkB,QAAF,IAAY,EAAZ,CAAe,OAAOlB,CAAP;AAAS,KAA1Y,EAAT,CAA7E,CAAmeP,EAAEqI,MAAF,GAC/e5I,EAAEmF,aAAF,CAAgBrE,CAAhB,CAD+e,CAC5dP,EAAEsI,UAAF,GAAa7I,EAAEoF,iBAAF,CAAoBtE,CAApB,CAAb;AAAoC,CADvD;;AAGA;;AAEA,IAAIgI,SAAO,kEAAX,CAA8E,IAAIC,SAAO,GAAX,CAAe,SAASC,OAAT,CAAiBhJ,CAAjB,EAAmB;AAAC,MAAIK,CAAJ,CAAM,IAAIC,CAAJ,CAAM,IAAIQ,IAAE,EAAN,CAAS,KAAIT,IAAE,CAAN,EAAQA,IAAE,CAAF,IAAKL,EAAEW,MAAf,EAAsBN,KAAG,CAAzB,EAA2B;AAACC,QAAE4C,SAASlD,EAAEiJ,SAAF,CAAY5I,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAF,CAAkCS,KAAGgI,OAAO/C,MAAP,CAAczF,KAAG,CAAjB,IAAoBwI,OAAO/C,MAAP,CAAczF,IAAE,EAAhB,CAAvB;AAA2C,OAAGD,IAAE,CAAF,IAAKL,EAAEW,MAAV,EAAiB;AAACL,QAAE4C,SAASlD,EAAEiJ,SAAF,CAAY5I,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAF,CAAkCS,KAAGgI,OAAO/C,MAAP,CAAczF,KAAG,CAAjB,CAAH;AAAuB,GAA3E,MAA+E;AAAC,QAAGD,IAAE,CAAF,IAAKL,EAAEW,MAAV,EAAiB;AAACL,UAAE4C,SAASlD,EAAEiJ,SAAF,CAAY5I,CAAZ,EAAcA,IAAE,CAAhB,CAAT,EAA4B,EAA5B,CAAF,CAAkCS,KAAGgI,OAAO/C,MAAP,CAAczF,KAAG,CAAjB,IAAoBwI,OAAO/C,MAAP,CAAc,CAACzF,IAAE,CAAH,KAAO,CAArB,CAAvB;AAA+C;AAAC,OAAGyI,MAAH,EAAU;AAAC,WAAM,CAACjI,EAAEH,MAAF,GAAS,CAAV,IAAa,CAAnB,EAAqB;AAACG,WAAGiI,MAAH;AAAU;AAAC,UAAOjI,CAAP;AAAS,UAASoI,QAAT,CAAkBpJ,CAAlB,EAAoB;AAAC,MAAIE,IAAE,EAAN,CAAS,IAAIM,CAAJ,CAAM,IAAID,IAAE,CAAN,CAAQ,IAAIE,CAAJ,CAAM,IAAIO,CAAJ,CAAM,KAAIR,IAAE,CAAN,EAAQA,IAAER,EAAEa,MAAZ,EAAmB,EAAEL,CAArB,EAAuB;AAAC,QAAGR,EAAEiG,MAAF,CAASzF,CAAT,KAAayI,MAAhB,EAAuB;AAAC;AAAM,SAAED,OAAO9C,OAAP,CAAelG,EAAEiG,MAAF,CAASzF,CAAT,CAAf,CAAF,CAA8B,IAAGQ,IAAE,CAAL,EAAO;AAAC;AAAS,SAAGT,KAAG,CAAN,EAAQ;AAACL,WAAGmJ,SAASrI,KAAG,CAAZ,CAAH,CAAkBP,IAAEO,IAAE,CAAJ,CAAMT,IAAE,CAAF;AAAI,KAArC,MAAyC;AAAC,UAAGA,KAAG,CAAN,EAAQ;AAACL,aAAGmJ,SAAU5I,KAAG,CAAJ,GAAQO,KAAG,CAApB,CAAH,CAA2BP,IAAEO,IAAE,EAAJ,CAAOT,IAAE,CAAF;AAAI,OAA/C,MAAmD;AAAC,YAAGA,KAAG,CAAN,EAAQ;AAACL,eAAGmJ,SAAS5I,CAAT,CAAH,CAAeP,KAAGmJ,SAASrI,KAAG,CAAZ,CAAH,CAAkBP,IAAEO,IAAE,CAAJ,CAAMT,IAAE,CAAF;AAAI,SAApD,MAAwD;AAACL,eAAGmJ,SAAU5I,KAAG,CAAJ,GAAQO,KAAG,CAApB,CAAH,CAA2Bd,KAAGmJ,SAASrI,IAAE,EAAX,CAAH,CAAkBT,IAAE,CAAF;AAAI;AAAC;AAAC;AAAC,OAAGA,KAAG,CAAN,EAAQ;AAACL,SAAGmJ,SAAS5I,KAAG,CAAZ,CAAH;AAAkB,UAAOP,CAAP;AAAS,UAASoJ,OAAT,CAAiB9I,CAAjB,EAAmB;AAAC,MAAIN,IAAEkJ,SAAS5I,CAAT,CAAN,CAAkB,IAAIC,CAAJ,CAAM,IAAIF,IAAE,IAAIgJ,KAAJ,EAAN,CAAkB,KAAI9I,IAAE,CAAN,EAAQ,IAAEA,CAAF,GAAIP,EAAEW,MAAd,EAAqB,EAAEJ,CAAvB,EAAyB;AAACF,MAAEE,CAAF,IAAK2C,SAASlD,EAAEiJ,SAAF,CAAY,IAAE1I,CAAd,EAAgB,IAAEA,CAAF,GAAI,CAApB,CAAT,EAAgC,EAAhC,CAAL;AAAyC,UAAOF,CAAP;AAAS;AAC9+B;;AAEA,IAAIiJ,KAAJ,CAAU,IAAIC,SAAO,eAAX,CAA2B,IAAIC,OAAM,CAACD,SAAO,QAAR,KAAmB,QAA7B,CAAuC,SAASE,UAAT,CAAoBnJ,CAApB,EAAsBN,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,MAAGQ,KAAG,IAAN,EAAW;AAAC,QAAG,YAAU,OAAOA,CAApB,EAAsB;AAAC,WAAKoJ,UAAL,CAAgBpJ,CAAhB,EAAkBN,CAAlB,EAAoBF,CAApB;AAAuB,KAA9C,MAAkD;AAAC,UAAGE,KAAG,IAAH,IAAS,YAAU,OAAOM,CAA7B,EAA+B;AAAC,aAAKqJ,UAAL,CAAgBrJ,CAAhB,EAAkB,GAAlB;AAAuB,OAAvD,MAA2D;AAAC,aAAKqJ,UAAL,CAAgBrJ,CAAhB,EAAkBN,CAAlB;AAAqB;AAAC;AAAC;AAAC,UAAS4J,GAAT,GAAc;AAAC,SAAO,IAAIH,UAAJ,CAAe,IAAf,CAAP;AAA4B,UAASI,GAAT,CAAa/J,CAAb,EAAegB,CAAf,EAAiBT,CAAjB,EAAmBC,CAAnB,EAAqBT,CAArB,EAAuBD,CAAvB,EAAyB;AAAC,SAAM,EAAEA,CAAF,IAAK,CAAX,EAAa;AAAC,QAAII,IAAEc,IAAE,KAAKhB,GAAL,CAAF,GAAYO,EAAEC,CAAF,CAAZ,GAAiBT,CAAvB,CAAyBA,IAAE0F,KAAKc,KAAL,CAAWrG,IAAE,QAAb,CAAF,CAAyBK,EAAEC,GAAF,IAAON,IAAE,QAAT;AAAkB,UAAOH,CAAP;AAAS,UAASiK,GAAT,CAAahK,CAAb,EAAesC,CAAf,EAAiBG,CAAjB,EAAmBjC,CAAnB,EAAqBc,CAArB,EAAuBN,CAAvB,EAAyB;AAAC,MAAID,IAAEuB,IAAE,KAAR;AAAA,MAAcjB,IAAEiB,KAAG,EAAnB,CAAsB,OAAM,EAAEtB,CAAF,IAAK,CAAX,EAAa;AAAC,QAAId,IAAE,KAAKF,CAAL,IAAQ,KAAd,CAAoB,IAAIF,IAAE,KAAKE,GAAL,KAAW,EAAjB,CAAoB,IAAIO,IAAEc,IAAEnB,CAAF,GAAIJ,IAAEiB,CAAZ,CAAcb,IAAEa,IAAEb,CAAF,IAAK,CAACK,IAAE,KAAH,KAAW,EAAhB,IAAoBkC,EAAEjC,CAAF,CAApB,IAA0Bc,IAAE,UAA5B,CAAF,CAA0CA,IAAE,CAACpB,MAAI,EAAL,KAAUK,MAAI,EAAd,IAAkBc,IAAEvB,CAApB,IAAuBwB,MAAI,EAA3B,CAAF,CAAiCmB,EAAEjC,GAAF,IAAON,IAAE,UAAT;AAAoB,UAAOoB,CAAP;AAAS,UAAS2I,GAAT,CAAajK,CAAb,EAAesC,CAAf,EAAiBG,CAAjB,EAAmBjC,CAAnB,EAAqBc,CAArB,EAAuBN,CAAvB,EAAyB;AAAC,MAAID,IAAEuB,IAAE,KAAR;AAAA,MAAcjB,IAAEiB,KAAG,EAAnB,CAAsB,OAAM,EAAEtB,CAAF,IAAK,CAAX,EAAa;AAAC,QAAId,IAAE,KAAKF,CAAL,IAAQ,KAAd,CAAoB,IAAIF,IAAE,KAAKE,GAAL,KAAW,EAAjB,CAAoB,IAAIO,IAAEc,IAAEnB,CAAF,GAAIJ,IAAEiB,CAAZ,CAAcb,IAAEa,IAAEb,CAAF,IAAK,CAACK,IAAE,KAAH,KAAW,EAAhB,IAAoBkC,EAAEjC,CAAF,CAApB,GAAyBc,CAA3B,CAA6BA,IAAE,CAACpB,KAAG,EAAJ,KAASK,KAAG,EAAZ,IAAgBc,IAAEvB,CAApB,CAAsB2C,EAAEjC,GAAF,IAAON,IAAE,SAAT;AAAmB,UAAOoB,CAAP;AAAS,KAAGoI,QAAOnK,UAAU2K,OAAV,IAAmB,6BAA7B,EAA4D;AAACP,aAAWxJ,SAAX,CAAqBgK,EAArB,GAAwBH,GAAxB,CAA4BR,QAAM,EAAN;AAAS,CAAlG,MAAsG;AAAC,MAAGE,QAAOnK,UAAU2K,OAAV,IAAmB,UAA7B,EAAyC;AAACP,eAAWxJ,SAAX,CAAqBgK,EAArB,GAAwBJ,GAAxB,CAA4BP,QAAM,EAAN;AAAS,GAA/E,MAAmF;AAACG,eAAWxJ,SAAX,CAAqBgK,EAArB,GAAwBF,GAAxB,CAA4BT,QAAM,EAAN;AAAS;AAAC,YAAWrJ,SAAX,CAAqBiK,EAArB,GAAwBZ,KAAxB,CAA8BG,WAAWxJ,SAAX,CAAqBkK,EAArB,GAAyB,CAAC,KAAGb,KAAJ,IAAW,CAApC,CAAuCG,WAAWxJ,SAAX,CAAqBmK,EAArB,GAAyB,KAAGd,KAA5B,CAAmC,IAAIe,QAAM,EAAV,CAAaZ,WAAWxJ,SAAX,CAAqBqK,EAArB,GAAwB/E,KAAKW,GAAL,CAAS,CAAT,EAAWmE,KAAX,CAAxB,CAA0CZ,WAAWxJ,SAAX,CAAqBsK,EAArB,GAAwBF,QAAMf,KAA9B,CAAoCG,WAAWxJ,SAAX,CAAqBuK,EAArB,GAAwB,IAAElB,KAAF,GAAQe,KAAhC,CAAsC,IAAII,QAAM,sCAAV,CAAiD,IAAIC,QAAM,IAAIrB,KAAJ,EAAV,CAAsB,IAAIsB,EAAJ,EAAOC,EAAP,CAAUD,KAAG,IAAIpH,UAAJ,CAAe,CAAf,CAAH,CAAqB,KAAIqH,KAAG,CAAP,EAASA,MAAI,CAAb,EAAe,EAAEA,EAAjB,EAAoB;AAACF,QAAMC,IAAN,IAAYC,EAAZ;AAAe,MAAG,IAAIrH,UAAJ,CAAe,CAAf,CAAH,CAAqB,KAAIqH,KAAG,EAAP,EAAUA,KAAG,EAAb,EAAgB,EAAEA,EAAlB,EAAqB;AAACF,QAAMC,IAAN,IAAYC,EAAZ;AAAe,MAAG,IAAIrH,UAAJ,CAAe,CAAf,CAAH,CAAqB,KAAIqH,KAAG,EAAP,EAAUA,KAAG,EAAb,EAAgB,EAAEA,EAAlB,EAAqB;AAACF,QAAMC,IAAN,IAAYC,EAAZ;AAAe,UAASzB,QAAT,CAAkBrI,CAAlB,EAAoB;AAAC,SAAO2J,MAAM1E,MAAN,CAAajF,CAAb,CAAP;AAAuB,UAAS+J,KAAT,CAAexK,CAAf,EAAiBS,CAAjB,EAAmB;AAAC,MAAId,IAAE0K,MAAMrK,EAAEkD,UAAF,CAAazC,CAAb,CAAN,CAAN,CAA6B,OAAOd,KAAG,IAAJ,GAAU,CAAC,CAAX,GAAaA,CAAnB;AAAqB,UAAS8K,SAAT,CAAmBzK,CAAnB,EAAqB;AAAC,OAAI,IAAIS,IAAE,KAAKqB,CAAL,GAAO,CAAjB,EAAmBrB,KAAG,CAAtB,EAAwB,EAAEA,CAA1B,EAA4B;AAACT,MAAES,CAAF,IAAK,KAAKA,CAAL,CAAL;AAAa,KAAEqB,CAAF,GAAI,KAAKA,CAAT,CAAW9B,EAAEgC,CAAF,GAAI,KAAKA,CAAT;AAAW,UAAS0I,UAAT,CAAoBjK,CAApB,EAAsB;AAAC,OAAKqB,CAAL,GAAO,CAAP,CAAS,KAAKE,CAAL,GAAQvB,IAAE,CAAH,GAAM,CAAC,CAAP,GAAS,CAAhB,CAAkB,IAAGA,IAAE,CAAL,EAAO;AAAC,SAAK,CAAL,IAAQA,CAAR;AAAU,GAAlB,MAAsB;AAAC,QAAGA,IAAE,CAAC,CAAN,EAAQ;AAAC,WAAK,CAAL,IAAQA,IAAE,KAAKsJ,EAAf;AAAkB,KAA3B,MAA+B;AAAC,WAAKjI,CAAL,GAAO,CAAP;AAAS;AAAC;AAAC,UAAS6I,GAAT,CAAalK,CAAb,EAAe;AAAC,MAAIT,IAAEuJ,KAAN,CAAYvJ,EAAE4K,OAAF,CAAUnK,CAAV,EAAa,OAAOT,CAAP;AAAS,UAAS6K,aAAT,CAAuBrL,CAAvB,EAAyBU,CAAzB,EAA2B;AAAC,MAAID,CAAJ,CAAM,IAAGC,KAAG,EAAN,EAAS;AAACD,QAAE,CAAF;AAAI,GAAd,MAAkB;AAAC,QAAGC,KAAG,CAAN,EAAQ;AAACD,UAAE,CAAF;AAAI,KAAb,MAAiB;AAAC,UAAGC,KAAG,GAAN,EAAU;AAACD,YAAE,CAAF;AAAI,OAAf,MAAmB;AAAC,YAAGC,KAAG,CAAN,EAAQ;AAACD,cAAE,CAAF;AAAI,SAAb,MAAiB;AAAC,cAAGC,KAAG,EAAN,EAAS;AAACD,gBAAE,CAAF;AAAI,WAAd,MAAkB;AAAC,gBAAGC,KAAG,CAAN,EAAQ;AAACD,kBAAE,CAAF;AAAI,aAAb,MAAiB;AAAC,mBAAK6K,SAAL,CAAetL,CAAf,EAAiBU,CAAjB,EAAoB;AAAO;AAAC;AAAC;AAAC;AAAC;AAAC,QAAK4B,CAAL,GAAO,CAAP,CAAS,KAAKE,CAAL,GAAO,CAAP,CAAS,IAAIzC,IAAEC,EAAEc,MAAR;AAAA,MAAeX,IAAE,KAAjB;AAAA,MAAuBF,IAAE,CAAzB,CAA2B,OAAM,EAAEF,CAAF,IAAK,CAAX,EAAa;AAAC,QAAIkB,IAAGR,KAAG,CAAJ,GAAOT,EAAED,CAAF,IAAK,GAAZ,GAAgBiL,MAAMhL,CAAN,EAAQD,CAAR,CAAtB,CAAiC,IAAGkB,IAAE,CAAL,EAAO;AAAC,UAAGjB,EAAEkG,MAAF,CAASnG,CAAT,KAAa,GAAhB,EAAoB;AAACI,YAAE,IAAF;AAAO;AAAS,SAAE,KAAF,CAAQ,IAAGF,KAAG,CAAN,EAAQ;AAAC,WAAK,KAAKqC,CAAL,EAAL,IAAerB,CAAf;AAAiB,KAA1B,MAA8B;AAAC,UAAGhB,IAAEQ,CAAF,GAAI,KAAK4J,EAAZ,EAAe;AAAC,aAAK,KAAK/H,CAAL,GAAO,CAAZ,KAAgB,CAACrB,IAAG,CAAC,KAAI,KAAKoJ,EAAL,GAAQpK,CAAb,IAAiB,CAArB,KAA0BA,CAA1C,CAA4C,KAAK,KAAKqC,CAAL,EAAL,IAAgBrB,KAAI,KAAKoJ,EAAL,GAAQpK,CAA5B;AAAgC,OAA5F,MAAgG;AAAC,aAAK,KAAKqC,CAAL,GAAO,CAAZ,KAAgBrB,KAAGhB,CAAnB;AAAqB;AAAC,UAAGQ,CAAH,CAAK,IAAGR,KAAG,KAAKoK,EAAX,EAAc;AAACpK,WAAG,KAAKoK,EAAR;AAAW;AAAC,OAAG5J,KAAG,CAAH,IAAM,CAACT,EAAE,CAAF,IAAK,GAAN,KAAY,CAArB,EAAuB;AAAC,SAAKwC,CAAL,GAAO,CAAC,CAAR,CAAU,IAAGvC,IAAE,CAAL,EAAO;AAAC,WAAK,KAAKqC,CAAL,GAAO,CAAZ,KAAiB,CAAC,KAAI,KAAK+H,EAAL,GAAQpK,CAAb,IAAiB,CAAlB,IAAsBA,CAAtC;AAAwC;AAAC,QAAKwC,KAAL,GAAa,IAAGtC,CAAH,EAAK;AAACyJ,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsB,IAAtB,EAA2B,IAA3B;AAAiC;AAAC,UAASC,QAAT,GAAmB;AAAC,MAAIxK,IAAE,KAAKuB,CAAL,GAAO,KAAK8H,EAAlB,CAAqB,OAAM,KAAKhI,CAAL,GAAO,CAAP,IAAU,KAAK,KAAKA,CAAL,GAAO,CAAZ,KAAgBrB,CAAhC,EAAkC;AAAC,MAAE,KAAKqB,CAAP;AAAS;AAAC,UAASoJ,UAAT,CAAoBhL,CAApB,EAAsB;AAAC,MAAG,KAAK8B,CAAL,GAAO,CAAV,EAAY;AAAC,WAAM,MAAI,KAAKmJ,MAAL,GAAc5J,QAAd,CAAuBrB,CAAvB,CAAV;AAAoC,OAAID,CAAJ,CAAM,IAAGC,KAAG,EAAN,EAAS;AAACD,QAAE,CAAF;AAAI,GAAd,MAAkB;AAAC,QAAGC,KAAG,CAAN,EAAQ;AAACD,UAAE,CAAF;AAAI,KAAb,MAAiB;AAAC,UAAGC,KAAG,CAAN,EAAQ;AAACD,YAAE,CAAF;AAAI,OAAb,MAAiB;AAAC,YAAGC,KAAG,EAAN,EAAS;AAACD,cAAE,CAAF;AAAI,SAAd,MAAkB;AAAC,cAAGC,KAAG,CAAN,EAAQ;AAACD,gBAAE,CAAF;AAAI,WAAb,MAAiB;AAAC,mBAAO,KAAKmL,OAAL,CAAalL,CAAb,CAAP;AAAuB;AAAC;AAAC;AAAC;AAAC,OAAIX,IAAE,CAAC,KAAGU,CAAJ,IAAO,CAAb;AAAA,MAAeM,CAAf;AAAA,MAAiBE,IAAE,KAAnB;AAAA,MAAyBjB,IAAE,EAA3B;AAAA,MAA8BC,IAAE,KAAKqC,CAArC,CAAuC,IAAI1B,IAAE,KAAKyJ,EAAL,GAASpK,IAAE,KAAKoK,EAAR,GAAY5J,CAA1B,CAA4B,IAAGR,MAAI,CAAP,EAAS;AAAC,QAAGW,IAAE,KAAKyJ,EAAP,IAAW,CAACtJ,IAAE,KAAKd,CAAL,KAASW,CAAZ,IAAe,CAA7B,EAA+B;AAACK,UAAE,IAAF,CAAOjB,IAAEsJ,SAASvI,CAAT,CAAF;AAAc,YAAMd,KAAG,CAAT,EAAW;AAAC,UAAGW,IAAEH,CAAL,EAAO;AAACM,YAAE,CAAC,KAAKd,CAAL,IAAS,CAAC,KAAGW,CAAJ,IAAO,CAAjB,KAAuBH,IAAEG,CAA3B,CAA8BG,KAAG,KAAK,EAAEd,CAAP,MAAYW,KAAG,KAAKyJ,EAAL,GAAQ5J,CAAvB,CAAH;AAA6B,OAAnE,MAAuE;AAACM,YAAG,KAAKd,CAAL,MAAUW,KAAGH,CAAb,CAAD,GAAkBV,CAApB,CAAsB,IAAGa,KAAG,CAAN,EAAQ;AAACA,eAAG,KAAKyJ,EAAR,CAAW,EAAEpK,CAAF;AAAI;AAAC,WAAGc,IAAE,CAAL,EAAO;AAACE,YAAE,IAAF;AAAO,WAAGA,CAAH,EAAK;AAACjB,aAAGsJ,SAASvI,CAAT,CAAH;AAAe;AAAC;AAAC,UAAOE,IAAEjB,CAAF,GAAI,GAAX;AAAe,UAAS6L,QAAT,GAAmB;AAAC,MAAI5K,IAAE8I,KAAN,CAAYH,WAAW2B,IAAX,CAAgBC,KAAhB,CAAsB,IAAtB,EAA2BvK,CAA3B,EAA8B,OAAOA,CAAP;AAAS,UAAS6K,KAAT,GAAgB;AAAC,SAAO,KAAKtJ,CAAL,GAAO,CAAR,GAAW,KAAKmJ,MAAL,EAAX,GAAyB,IAA/B;AAAoC,UAASI,WAAT,CAAqBvL,CAArB,EAAuB;AAAC,MAAIL,IAAE,KAAKqC,CAAL,GAAOhC,EAAEgC,CAAf,CAAiB,IAAGrC,KAAG,CAAN,EAAQ;AAAC,WAAOA,CAAP;AAAS,OAAIO,IAAE,KAAK4B,CAAX,CAAanC,IAAEO,IAAEF,EAAE8B,CAAN,CAAQ,IAAGnC,KAAG,CAAN,EAAQ;AAAC,WAAO,KAAKqC,CAAL,GAAO,CAAR,GAAW,CAACrC,CAAZ,GAAcA,CAApB;AAAsB,UAAM,EAAEO,CAAF,IAAK,CAAX,EAAa;AAAC,QAAG,CAACP,IAAE,KAAKO,CAAL,IAAQF,EAAEE,CAAF,CAAX,KAAkB,CAArB,EAAuB;AAAC,aAAOP,CAAP;AAAS;AAAC,UAAO,CAAP;AAAS,UAAS6L,KAAT,CAAe/K,CAAf,EAAiB;AAAC,MAAIP,IAAE,CAAN;AAAA,MAAQF,CAAR,CAAU,IAAG,CAACA,IAAES,MAAI,EAAP,KAAY,CAAf,EAAiB;AAACA,QAAET,CAAF,CAAIE,KAAG,EAAH;AAAM,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,OAAG,CAACF,IAAES,KAAG,CAAN,KAAU,CAAb,EAAe;AAACA,QAAET,CAAF,CAAIE,KAAG,CAAH;AAAK,UAAOA,CAAP;AAAS,UAASuL,WAAT,GAAsB;AAAC,MAAG,KAAK3J,CAAL,IAAQ,CAAX,EAAa;AAAC,WAAO,CAAP;AAAS,UAAO,KAAK+H,EAAL,IAAS,KAAK/H,CAAL,GAAO,CAAhB,IAAmB0J,MAAM,KAAK,KAAK1J,CAAL,GAAO,CAAZ,IAAgB,KAAKE,CAAL,GAAO,KAAK8H,EAAlC,CAA1B;AAAiE,UAAS4B,YAAT,CAAsBxL,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,MAAIS,CAAJ,CAAM,KAAIA,IAAE,KAAKqB,CAAL,GAAO,CAAb,EAAerB,KAAG,CAAlB,EAAoB,EAAEA,CAAtB,EAAwB;AAACT,MAAES,IAAEP,CAAJ,IAAO,KAAKO,CAAL,CAAP;AAAe,QAAIA,IAAEP,IAAE,CAAR,EAAUO,KAAG,CAAb,EAAe,EAAEA,CAAjB,EAAmB;AAACT,MAAES,CAAF,IAAK,CAAL;AAAO,KAAEqB,CAAF,GAAI,KAAKA,CAAL,GAAO5B,CAAX,CAAaF,EAAEgC,CAAF,GAAI,KAAKA,CAAT;AAAW,UAAS2J,YAAT,CAAsBzL,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,OAAI,IAAIS,IAAEP,CAAV,EAAYO,IAAE,KAAKqB,CAAnB,EAAqB,EAAErB,CAAvB,EAAyB;AAACT,MAAES,IAAEP,CAAJ,IAAO,KAAKO,CAAL,CAAP;AAAe,KAAEqB,CAAF,GAAIoD,KAAKf,GAAL,CAAS,KAAKrC,CAAL,GAAO5B,CAAhB,EAAkB,CAAlB,CAAJ,CAAyBF,EAAEgC,CAAF,GAAI,KAAKA,CAAT;AAAW,UAAS4J,WAAT,CAAqBxL,CAArB,EAAuBH,CAAvB,EAAyB;AAAC,MAAID,IAAEI,IAAE,KAAKyJ,EAAb,CAAgB,IAAIpJ,IAAE,KAAKoJ,EAAL,GAAQ7J,CAAd,CAAgB,IAAIT,IAAE,CAAC,KAAGkB,CAAJ,IAAO,CAAb,CAAe,IAAIhB,IAAEyF,KAAKc,KAAL,CAAW5F,IAAE,KAAKyJ,EAAlB,CAAN;AAAA,MAA4BrK,IAAG,KAAKwC,CAAL,IAAQhC,CAAT,GAAY,KAAK8J,EAA/C;AAAA,MAAkDnK,CAAlD,CAAoD,KAAIA,IAAE,KAAKmC,CAAL,GAAO,CAAb,EAAenC,KAAG,CAAlB,EAAoB,EAAEA,CAAtB,EAAwB;AAACM,MAAEN,IAAEF,CAAF,GAAI,CAAN,IAAU,KAAKE,CAAL,KAASc,CAAV,GAAajB,CAAtB,CAAwBA,IAAE,CAAC,KAAKG,CAAL,IAAQJ,CAAT,KAAaS,CAAf;AAAiB,QAAIL,IAAEF,IAAE,CAAR,EAAUE,KAAG,CAAb,EAAe,EAAEA,CAAjB,EAAmB;AAACM,MAAEN,CAAF,IAAK,CAAL;AAAO,KAAEF,CAAF,IAAKD,CAAL,CAAOS,EAAE6B,CAAF,GAAI,KAAKA,CAAL,GAAOrC,CAAP,GAAS,CAAb,CAAeQ,EAAE+B,CAAF,GAAI,KAAKA,CAAT,CAAW/B,EAAEgC,KAAF;AAAU,UAAS4J,WAAT,CAAqBtM,CAArB,EAAuBI,CAAvB,EAAyB;AAACA,IAAEqC,CAAF,GAAI,KAAKA,CAAT,CAAW,IAAI/B,IAAEiF,KAAKc,KAAL,CAAWzG,IAAE,KAAKsK,EAAlB,CAAN,CAA4B,IAAG5J,KAAG,KAAK6B,CAAX,EAAa;AAACnC,MAAEmC,CAAF,GAAI,CAAJ,CAAM;AAAO,OAAI9B,IAAET,IAAE,KAAKsK,EAAb,CAAgB,IAAIpJ,IAAE,KAAKoJ,EAAL,GAAQ7J,CAAd,CAAgB,IAAIP,IAAE,CAAC,KAAGO,CAAJ,IAAO,CAAb,CAAeL,EAAE,CAAF,IAAK,KAAKM,CAAL,KAASD,CAAd,CAAgB,KAAI,IAAIE,IAAED,IAAE,CAAZ,EAAcC,IAAE,KAAK4B,CAArB,EAAuB,EAAE5B,CAAzB,EAA2B;AAACP,MAAEO,IAAED,CAAF,GAAI,CAAN,KAAU,CAAC,KAAKC,CAAL,IAAQT,CAAT,KAAagB,CAAvB,CAAyBd,EAAEO,IAAED,CAAJ,IAAO,KAAKC,CAAL,KAASF,CAAhB;AAAkB,OAAGA,IAAE,CAAL,EAAO;AAACL,MAAE,KAAKmC,CAAL,GAAO7B,CAAP,GAAS,CAAX,KAAe,CAAC,KAAK+B,CAAL,GAAOvC,CAAR,KAAYgB,CAA3B;AAA6B,KAAEqB,CAAF,GAAI,KAAKA,CAAL,GAAO7B,CAAX,CAAaN,EAAEsC,KAAF;AAAU,UAAS6J,QAAT,CAAkBnM,CAAlB,EAAoBF,CAApB,EAAsB;AAAC,MAAIQ,IAAE,CAAN;AAAA,MAAQV,IAAE,CAAV;AAAA,MAAYS,IAAEkF,KAAKb,GAAL,CAAS1E,EAAEmC,CAAX,EAAa,KAAKA,CAAlB,CAAd,CAAmC,OAAM7B,IAAED,CAAR,EAAU;AAACT,SAAG,KAAKU,CAAL,IAAQN,EAAEM,CAAF,CAAX,CAAgBR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,OAAGlK,EAAEmC,CAAF,GAAI,KAAKA,CAAZ,EAAc;AAACvC,SAAGI,EAAEqC,CAAL,CAAO,OAAM/B,IAAE,KAAK6B,CAAb,EAAe;AAACvC,WAAG,KAAKU,CAAL,CAAH,CAAWR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAG,KAAK7H,CAAR;AAAU,GAAxF,MAA4F;AAACzC,SAAG,KAAKyC,CAAR,CAAU,OAAM/B,IAAEN,EAAEmC,CAAV,EAAY;AAACvC,WAAGI,EAAEM,CAAF,CAAH,CAAQR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAGlK,EAAEqC,CAAL;AAAO,KAAEA,CAAF,GAAKzC,IAAE,CAAH,GAAM,CAAC,CAAP,GAAS,CAAb,CAAe,IAAGA,IAAE,CAAC,CAAN,EAAQ;AAACE,MAAEQ,GAAF,IAAO,KAAK8J,EAAL,GAAQxK,CAAf;AAAiB,GAA1B,MAA8B;AAAC,QAAGA,IAAE,CAAL,EAAO;AAACE,QAAEQ,GAAF,IAAOV,CAAP;AAAS;AAAC,KAAEuC,CAAF,GAAI7B,CAAJ,CAAMR,EAAEwC,KAAF;AAAU,UAAS8J,aAAT,CAAuB7L,CAAvB,EAAyBD,CAAzB,EAA2B;AAAC,MAAID,IAAE,KAAKgM,GAAL,EAAN;AAAA,MAAiBvM,IAAES,EAAE8L,GAAF,EAAnB,CAA2B,IAAIrM,IAAEK,EAAE8B,CAAR,CAAU7B,EAAE6B,CAAF,GAAInC,IAAEF,EAAEqC,CAAR,CAAU,OAAM,EAAEnC,CAAF,IAAK,CAAX,EAAa;AAACM,MAAEN,CAAF,IAAK,CAAL;AAAO,QAAIA,IAAE,CAAN,EAAQA,IAAEF,EAAEqC,CAAZ,EAAc,EAAEnC,CAAhB,EAAkB;AAACM,MAAEN,IAAEK,EAAE8B,CAAN,IAAS9B,EAAE4J,EAAF,CAAK,CAAL,EAAOnK,EAAEE,CAAF,CAAP,EAAYM,CAAZ,EAAcN,CAAd,EAAgB,CAAhB,EAAkBK,EAAE8B,CAApB,CAAT;AAAgC,KAAEE,CAAF,GAAI,CAAJ,CAAM/B,EAAEgC,KAAF,GAAU,IAAG,KAAKD,CAAL,IAAQ9B,EAAE8B,CAAb,EAAe;AAACoH,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsB/K,CAAtB,EAAwBA,CAAxB;AAA2B;AAAC,UAASgM,WAAT,CAAqBtM,CAArB,EAAuB;AAAC,MAAIc,IAAE,KAAKuL,GAAL,EAAN,CAAiB,IAAIhM,IAAEL,EAAEmC,CAAF,GAAI,IAAErB,EAAEqB,CAAd,CAAgB,OAAM,EAAE9B,CAAF,IAAK,CAAX,EAAa;AAACL,MAAEK,CAAF,IAAK,CAAL;AAAO,QAAIA,IAAE,CAAN,EAAQA,IAAES,EAAEqB,CAAF,GAAI,CAAd,EAAgB,EAAE9B,CAAlB,EAAoB;AAAC,QAAIC,IAAEQ,EAAEmJ,EAAF,CAAK5J,CAAL,EAAOS,EAAET,CAAF,CAAP,EAAYL,CAAZ,EAAc,IAAEK,CAAhB,EAAkB,CAAlB,EAAoB,CAApB,CAAN,CAA6B,IAAG,CAACL,EAAEK,IAAES,EAAEqB,CAAN,KAAUrB,EAAEmJ,EAAF,CAAK5J,IAAE,CAAP,EAAS,IAAES,EAAET,CAAF,CAAX,EAAgBL,CAAhB,EAAkB,IAAEK,CAAF,GAAI,CAAtB,EAAwBC,CAAxB,EAA0BQ,EAAEqB,CAAF,GAAI9B,CAAJ,GAAM,CAAhC,CAAX,KAAgDS,EAAEsJ,EAArD,EAAwD;AAACpK,QAAEK,IAAES,EAAEqB,CAAN,KAAUrB,EAAEsJ,EAAZ,CAAepK,EAAEK,IAAES,EAAEqB,CAAJ,GAAM,CAAR,IAAW,CAAX;AAAa;AAAC,OAAGnC,EAAEmC,CAAF,GAAI,CAAP,EAAS;AAACnC,MAAEA,EAAEmC,CAAF,GAAI,CAAN,KAAUrB,EAAEmJ,EAAF,CAAK5J,CAAL,EAAOS,EAAET,CAAF,CAAP,EAAYL,CAAZ,EAAc,IAAEK,CAAhB,EAAkB,CAAlB,EAAoB,CAApB,CAAV;AAAiC,KAAEgC,CAAF,GAAI,CAAJ,CAAMrC,EAAEsC,KAAF;AAAU,UAASiK,WAAT,CAAqBrL,CAArB,EAAuBrB,CAAvB,EAAyBD,CAAzB,EAA2B;AAAC,MAAIuE,IAAEjD,EAAEmL,GAAF,EAAN,CAAc,IAAGlI,EAAEhC,CAAF,IAAK,CAAR,EAAU;AAAC;AAAO,OAAItB,IAAE,KAAKwL,GAAL,EAAN,CAAiB,IAAGxL,EAAEsB,CAAF,GAAIgC,EAAEhC,CAAT,EAAW;AAAC,QAAGtC,KAAG,IAAN,EAAW;AAACA,QAAEoL,OAAF,CAAU,CAAV;AAAa,SAAGrL,KAAG,IAAN,EAAW;AAAC,WAAK4M,MAAL,CAAY5M,CAAZ;AAAe;AAAO,OAAGA,KAAG,IAAN,EAAW;AAACA,QAAEgK,KAAF;AAAQ,OAAI5J,IAAE4J,KAAN;AAAA,MAAY9I,IAAE,KAAKuB,CAAnB;AAAA,MAAqBzB,IAAEM,EAAEmB,CAAzB,CAA2B,IAAIiC,IAAE,KAAK4F,EAAL,GAAQ2B,MAAM1H,EAAEA,EAAEhC,CAAF,GAAI,CAAN,CAAN,CAAd,CAA8B,IAAGmC,IAAE,CAAL,EAAO;AAACH,MAAEsI,QAAF,CAAWnI,CAAX,EAAatE,CAAb,EAAgBa,EAAE4L,QAAF,CAAWnI,CAAX,EAAa1E,CAAb;AAAgB,GAAxC,MAA4C;AAACuE,MAAEqI,MAAF,CAASxM,CAAT,EAAYa,EAAE2L,MAAF,CAAS5M,CAAT;AAAY,OAAIuB,IAAEnB,EAAEmC,CAAR,CAAU,IAAI9B,IAAEL,EAAEmB,IAAE,CAAJ,CAAN,CAAa,IAAGd,KAAG,CAAN,EAAQ;AAAC;AAAO,OAAIe,IAAEf,KAAG,KAAG,KAAKkK,EAAX,KAAiBpJ,IAAE,CAAH,GAAMnB,EAAEmB,IAAE,CAAJ,KAAQ,KAAKqJ,EAAnB,GAAsB,CAAtC,CAAN,CAA+C,IAAI1C,IAAE,KAAKwC,EAAL,GAAQlJ,CAAd;AAAA,MAAgByG,IAAE,CAAC,KAAG,KAAK0C,EAAT,IAAanJ,CAA/B;AAAA,MAAiCgD,IAAE,KAAG,KAAKoG,EAA3C,CAA8C,IAAIjG,IAAE3E,EAAEuC,CAAR;AAAA,MAAUE,IAAEkC,IAAEpD,CAAd;AAAA,MAAgBrB,IAAGD,KAAG,IAAJ,GAAU+J,KAAV,GAAgB/J,CAAlC,CAAoCG,EAAE0M,SAAF,CAAYrK,CAAZ,EAAcvC,CAAd,EAAiB,IAAGF,EAAE+M,SAAF,CAAY7M,CAAZ,KAAgB,CAAnB,EAAqB;AAACF,MAAEA,EAAEuC,CAAF,EAAF,IAAS,CAAT,CAAWvC,EAAEyL,KAAF,CAAQvL,CAAR,EAAUF,CAAV;AAAa,cAAWgN,GAAX,CAAeF,SAAf,CAAyBvL,CAAzB,EAA2BrB,CAA3B,EAA8BA,EAAEuL,KAAF,CAAQrL,CAAR,EAAUA,CAAV,EAAa,OAAMA,EAAEmC,CAAF,GAAIhB,CAAV,EAAY;AAACnB,MAAEA,EAAEmC,CAAF,EAAF,IAAS,CAAT;AAAW,UAAM,EAAEE,CAAF,IAAK,CAAX,EAAa;AAAC,QAAI9B,IAAGX,EAAE,EAAE2E,CAAJ,KAAQlE,CAAT,GAAY,KAAK8J,EAAjB,GAAoB5E,KAAKc,KAAL,CAAWzG,EAAE2E,CAAF,IAAKuD,CAAL,GAAO,CAAClI,EAAE2E,IAAE,CAAJ,IAAOH,CAAR,IAAWyD,CAA7B,CAA1B,CAA0D,IAAG,CAACjI,EAAE2E,CAAF,KAAMvE,EAAEiK,EAAF,CAAK,CAAL,EAAO1J,CAAP,EAASX,CAAT,EAAWyC,CAAX,EAAa,CAAb,EAAelB,CAAf,CAAP,IAA0BZ,CAA7B,EAA+B;AAACP,QAAE0M,SAAF,CAAYrK,CAAZ,EAAcvC,CAAd,EAAiBF,EAAEyL,KAAF,CAAQvL,CAAR,EAAUF,CAAV,EAAa,OAAMA,EAAE2E,CAAF,IAAK,EAAEhE,CAAb,EAAe;AAACX,UAAEyL,KAAF,CAAQvL,CAAR,EAAUF,CAAV;AAAa;AAAC;AAAC,OAAGC,KAAG,IAAN,EAAW;AAACD,MAAEiN,SAAF,CAAY1L,CAAZ,EAActB,CAAd,EAAiB,IAAGiB,KAAGF,CAAN,EAAQ;AAAC6I,iBAAW2B,IAAX,CAAgBC,KAAhB,CAAsBxL,CAAtB,EAAwBA,CAAxB;AAA2B;AAAC,KAAEsC,CAAF,GAAIhB,CAAJ,CAAMvB,EAAE0C,KAAF,GAAU,IAAGgC,IAAE,CAAL,EAAO;AAAC1E,MAAEkN,QAAF,CAAWxI,CAAX,EAAa1E,CAAb;AAAgB,OAAGkB,IAAE,CAAL,EAAO;AAAC2I,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsBzL,CAAtB,EAAwBA,CAAxB;AAA2B;AAAC,UAASmN,KAAT,CAAe1M,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKyC,GAAL,GAAWW,QAAX,CAAoB3M,CAApB,EAAsB,IAAtB,EAA2BE,CAA3B,EAA8B,IAAG,KAAK8B,CAAL,GAAO,CAAP,IAAU9B,EAAEoM,SAAF,CAAYlD,WAAW2B,IAAvB,IAA6B,CAA1C,EAA4C;AAAC/K,MAAEgL,KAAF,CAAQ9K,CAAR,EAAUA,CAAV;AAAa,UAAOA,CAAP;AAAS,UAAS0M,OAAT,CAAiBnM,CAAjB,EAAmB;AAAC,OAAK+B,CAAL,GAAO/B,CAAP;AAAS,UAASoM,QAAT,CAAkBpM,CAAlB,EAAoB;AAAC,MAAGA,EAAEuB,CAAF,GAAI,CAAJ,IAAOvB,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,KAAqB,CAA/B,EAAiC;AAAC,WAAO/B,EAAEqM,GAAF,CAAM,KAAKtK,CAAX,CAAP;AAAqB,GAAvD,MAA2D;AAAC,WAAO/B,CAAP;AAAS;AAAC,UAASsM,OAAT,CAAiBtM,CAAjB,EAAmB;AAAC,SAAOA,CAAP;AAAS,UAASuM,OAAT,CAAiBvM,CAAjB,EAAmB;AAACA,IAAEkM,QAAF,CAAW,KAAKnK,CAAhB,EAAkB,IAAlB,EAAuB/B,CAAvB;AAA0B,UAASwM,MAAT,CAAgBxM,CAAhB,EAAkBP,CAAlB,EAAoBF,CAApB,EAAsB;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf,EAAkB,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,UAASoN,MAAT,CAAgB3M,CAAhB,EAAkBT,CAAlB,EAAoB;AAACS,IAAE4M,QAAF,CAAWrN,CAAX,EAAc,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,SAAQJ,SAAR,CAAkB0N,OAAlB,GAA0BT,QAA1B,CAAmCD,QAAQhN,SAAR,CAAkB2N,MAAlB,GAAyBR,OAAzB,CAAiCH,QAAQhN,SAAR,CAAkBuN,MAAlB,GAAyBH,OAAzB,CAAiCJ,QAAQhN,SAAR,CAAkB4N,KAAlB,GAAwBP,MAAxB,CAA+BL,QAAQhN,SAAR,CAAkB6N,KAAlB,GAAwBL,MAAxB,CAA+B,SAASM,WAAT,GAAsB;AAAC,MAAG,KAAK5L,CAAL,GAAO,CAAV,EAAY;AAAC,WAAO,CAAP;AAAS,OAAIrB,IAAE,KAAK,CAAL,CAAN,CAAc,IAAG,CAACA,IAAE,CAAH,KAAO,CAAV,EAAY;AAAC,WAAO,CAAP;AAAS,OAAIT,IAAES,IAAE,CAAR,CAAUT,IAAGA,KAAG,IAAE,CAACS,IAAE,EAAH,IAAOT,CAAZ,CAAD,GAAiB,EAAnB,CAAsBA,IAAGA,KAAG,IAAE,CAACS,IAAE,GAAH,IAAQT,CAAb,CAAD,GAAkB,GAApB,CAAwBA,IAAGA,KAAG,KAAI,CAACS,IAAE,KAAH,IAAUT,CAAX,GAAc,KAAjB,CAAH,CAAD,GAA8B,KAAhC,CAAsCA,IAAGA,KAAG,IAAES,IAAET,CAAF,GAAI,KAAK+J,EAAd,CAAD,GAAoB,KAAKA,EAA3B,CAA8B,OAAO/J,IAAE,CAAH,GAAM,KAAK+J,EAAL,GAAQ/J,CAAd,GAAgB,CAACA,CAAvB;AAAyB,UAAS2N,UAAT,CAAoBlN,CAApB,EAAsB;AAAC,OAAK+B,CAAL,GAAO/B,CAAP,CAAS,KAAKmN,EAAL,GAAQnN,EAAEoN,QAAF,EAAR,CAAqB,KAAKC,GAAL,GAAS,KAAKF,EAAL,GAAQ,KAAjB,CAAuB,KAAKG,GAAL,GAAS,KAAKH,EAAL,IAAS,EAAlB,CAAqB,KAAKI,EAAL,GAAQ,CAAC,KAAIvN,EAAEoJ,EAAF,GAAK,EAAV,IAAe,CAAvB,CAAyB,KAAKoE,GAAL,GAAS,IAAExN,EAAEqB,CAAb;AAAe,UAASoM,WAAT,CAAqBzN,CAArB,EAAuB;AAAC,MAAIT,IAAEuJ,KAAN,CAAY9I,EAAEuL,GAAF,GAAQK,SAAR,CAAkB,KAAK7J,CAAL,CAAOV,CAAzB,EAA2B9B,CAA3B,EAA8BA,EAAE2M,QAAF,CAAW,KAAKnK,CAAhB,EAAkB,IAAlB,EAAuBxC,CAAvB,EAA0B,IAAGS,EAAEuB,CAAF,GAAI,CAAJ,IAAOhC,EAAEsM,SAAF,CAAYlD,WAAW2B,IAAvB,IAA6B,CAAvC,EAAyC;AAAC,SAAKvI,CAAL,CAAOwI,KAAP,CAAahL,CAAb,EAAeA,CAAf;AAAkB,UAAOA,CAAP;AAAS,UAASmO,UAAT,CAAoB1N,CAApB,EAAsB;AAAC,MAAIT,IAAEuJ,KAAN,CAAY9I,EAAE0L,MAAF,CAASnM,CAAT,EAAY,KAAKmN,MAAL,CAAYnN,CAAZ,EAAe,OAAOA,CAAP;AAAS,UAASoO,UAAT,CAAoB3N,CAApB,EAAsB;AAAC,SAAMA,EAAEqB,CAAF,IAAK,KAAKmM,GAAhB,EAAoB;AAACxN,MAAEA,EAAEqB,CAAF,EAAF,IAAS,CAAT;AAAW,QAAI,IAAI5B,IAAE,CAAV,EAAYA,IAAE,KAAKsC,CAAL,CAAOV,CAArB,EAAuB,EAAE5B,CAAzB,EAA2B;AAAC,QAAIF,IAAES,EAAEP,CAAF,IAAK,KAAX,CAAiB,IAAIP,IAAGK,IAAE,KAAK8N,GAAP,IAAY,CAAE9N,IAAE,KAAK+N,GAAP,GAAW,CAACtN,EAAEP,CAAF,KAAM,EAAP,IAAW,KAAK4N,GAA5B,GAAiC,KAAKE,EAAvC,KAA4C,EAAxD,CAAD,GAA8DvN,EAAEqJ,EAAtE,CAAyE9J,IAAEE,IAAE,KAAKsC,CAAL,CAAOV,CAAX,CAAarB,EAAET,CAAF,KAAM,KAAKwC,CAAL,CAAOoH,EAAP,CAAU,CAAV,EAAYjK,CAAZ,EAAcc,CAAd,EAAgBP,CAAhB,EAAkB,CAAlB,EAAoB,KAAKsC,CAAL,CAAOV,CAA3B,CAAN,CAAoC,OAAMrB,EAAET,CAAF,KAAMS,EAAEsJ,EAAd,EAAiB;AAACtJ,QAAET,CAAF,KAAMS,EAAEsJ,EAAR,CAAWtJ,EAAE,EAAET,CAAJ;AAAS;AAAC,KAAEiC,KAAF,GAAUxB,EAAE+L,SAAF,CAAY,KAAKhK,CAAL,CAAOV,CAAnB,EAAqBrB,CAArB,EAAwB,IAAGA,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,KAAqB,CAAxB,EAA0B;AAAC/B,MAAEuK,KAAF,CAAQ,KAAKxI,CAAb,EAAe/B,CAAf;AAAkB;AAAC,UAAS4N,SAAT,CAAmB5N,CAAnB,EAAqBT,CAArB,EAAuB;AAACS,IAAE4M,QAAF,CAAWrN,CAAX,EAAc,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,UAASsO,SAAT,CAAmB7N,CAAnB,EAAqBP,CAArB,EAAuBF,CAAvB,EAAyB;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf,EAAkB,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,YAAWJ,SAAX,CAAqB0N,OAArB,GAA6BY,WAA7B,CAAyCP,WAAW/N,SAAX,CAAqB2N,MAArB,GAA4BY,UAA5B,CAAuCR,WAAW/N,SAAX,CAAqBuN,MAArB,GAA4BiB,UAA5B,CAAuCT,WAAW/N,SAAX,CAAqB4N,KAArB,GAA2Bc,SAA3B,CAAqCX,WAAW/N,SAAX,CAAqB6N,KAArB,GAA2BY,SAA3B,CAAqC,SAASE,SAAT,GAAoB;AAAC,SAAM,CAAE,KAAKzM,CAAL,GAAO,CAAR,GAAY,KAAK,CAAL,IAAQ,CAApB,GAAuB,KAAKE,CAA7B,KAAiC,CAAvC;AAAyC,UAASwM,MAAT,CAAgBhP,CAAhB,EAAkBY,CAAlB,EAAoB;AAAC,MAAGZ,IAAE,UAAF,IAAcA,IAAE,CAAnB,EAAqB;AAAC,WAAO4J,WAAWmD,GAAlB;AAAsB,OAAI9M,IAAE8J,KAAN;AAAA,MAAY9I,IAAE8I,KAAd;AAAA,MAAoB5J,IAAES,EAAEkN,OAAF,CAAU,IAAV,CAAtB;AAAA,MAAsCpN,IAAEsL,MAAMhM,CAAN,IAAS,CAAjD,CAAmDG,EAAEwM,MAAF,CAAS1M,CAAT,EAAY,OAAM,EAAES,CAAF,IAAK,CAAX,EAAa;AAACE,MAAEqN,KAAF,CAAQhO,CAAR,EAAUgB,CAAV,EAAa,IAAG,CAACjB,IAAG,KAAGU,CAAP,IAAW,CAAd,EAAgB;AAACE,QAAEoN,KAAF,CAAQ/M,CAAR,EAAUd,CAAV,EAAYF,CAAZ;AAAe,KAAhC,MAAoC;AAAC,UAAIO,IAAEP,CAAN,CAAQA,IAAEgB,CAAF,CAAIA,IAAET,CAAF;AAAI;AAAC,UAAOI,EAAEmN,MAAF,CAAS9N,CAAT,CAAP;AAAmB,UAASgP,WAAT,CAAqBzO,CAArB,EAAuBS,CAAvB,EAAyB;AAAC,MAAIP,CAAJ,CAAM,IAAGF,IAAE,GAAF,IAAOS,EAAEiO,MAAF,EAAV,EAAqB;AAACxO,QAAE,IAAI0M,OAAJ,CAAYnM,CAAZ,CAAF;AAAiB,GAAvC,MAA2C;AAACP,QAAE,IAAIyN,UAAJ,CAAelN,CAAf,CAAF;AAAoB,UAAO,KAAKkO,GAAL,CAAS3O,CAAT,EAAWE,CAAX,CAAP;AAAqB,YAAWN,SAAX,CAAqBuM,MAArB,GAA4B1B,SAA5B,CAAsCrB,WAAWxJ,SAAX,CAAqBgL,OAArB,GAA6BF,UAA7B,CAAwCtB,WAAWxJ,SAAX,CAAqB0J,UAArB,GAAgCuB,aAAhC,CAA8CzB,WAAWxJ,SAAX,CAAqBqC,KAArB,GAA2BgJ,QAA3B,CAAoC7B,WAAWxJ,SAAX,CAAqByM,SAArB,GAA+BX,YAA/B,CAA4CtC,WAAWxJ,SAAX,CAAqB4M,SAArB,GAA+Bb,YAA/B,CAA4CvC,WAAWxJ,SAAX,CAAqBwM,QAArB,GAA8BR,WAA9B,CAA0CxC,WAAWxJ,SAAX,CAAqB6M,QAArB,GAA8BZ,WAA9B,CAA0CzC,WAAWxJ,SAAX,CAAqBoL,KAArB,GAA2Bc,QAA3B,CAAoC1C,WAAWxJ,SAAX,CAAqBsN,UAArB,GAAgCnB,aAAhC,CAA8C3C,WAAWxJ,SAAX,CAAqByN,QAArB,GAA8BpB,WAA9B,CAA0C7C,WAAWxJ,SAAX,CAAqB+M,QAArB,GAA8BT,WAA9B,CAA0C9C,WAAWxJ,SAAX,CAAqBiO,QAArB,GAA8BH,WAA9B,CAA0CtE,WAAWxJ,SAAX,CAAqB8O,MAArB,GAA4BH,SAA5B,CAAsCnF,WAAWxJ,SAAX,CAAqB+O,GAArB,GAAyBH,MAAzB,CAAgCpF,WAAWxJ,SAAX,CAAqB2B,QAArB,GAA8B2J,UAA9B,CAAyC9B,WAAWxJ,SAAX,CAAqBuL,MAArB,GAA4BE,QAA5B,CAAqCjC,WAAWxJ,SAAX,CAAqBoM,GAArB,GAAyBV,KAAzB,CAA+BlC,WAAWxJ,SAAX,CAAqB0M,SAArB,GAA+Bf,WAA/B,CAA2CnC,WAAWxJ,SAAX,CAAqBgP,SAArB,GAA+BnD,WAA/B,CAA2CrC,WAAWxJ,SAAX,CAAqBkN,GAArB,GAAyBJ,KAAzB,CAA+BtD,WAAWxJ,SAAX,CAAqBiP,SAArB,GAA+BJ,WAA/B,CAA2CrF,WAAW2B,IAAX,GAAgBJ,IAAI,CAAJ,CAAhB,CAAuBvB,WAAWmD,GAAX,GAAe5B,IAAI,CAAJ,CAAf;AAClpS;;AAEA,SAASmE,OAAT,GAAkB;AAAC,MAAIrO,IAAE8I,KAAN,CAAY,KAAK4C,MAAL,CAAY1L,CAAZ,EAAe,OAAOA,CAAP;AAAS,UAASsO,UAAT,GAAqB;AAAC,MAAG,KAAK/M,CAAL,GAAO,CAAV,EAAY;AAAC,QAAG,KAAKF,CAAL,IAAQ,CAAX,EAAa;AAAC,aAAO,KAAK,CAAL,IAAQ,KAAKiI,EAApB;AAAuB,KAArC,MAAyC;AAAC,UAAG,KAAKjI,CAAL,IAAQ,CAAX,EAAa;AAAC,eAAO,CAAC,CAAR;AAAU;AAAC;AAAC,GAAjF,MAAqF;AAAC,QAAG,KAAKA,CAAL,IAAQ,CAAX,EAAa;AAAC,aAAO,KAAK,CAAL,CAAP;AAAe,KAA7B,MAAiC;AAAC,UAAG,KAAKA,CAAL,IAAQ,CAAX,EAAa;AAAC,eAAO,CAAP;AAAS;AAAC;AAAC,UAAO,CAAC,KAAK,CAAL,IAAS,CAAC,KAAI,KAAG,KAAK+H,EAAb,IAAkB,CAA5B,KAAiC,KAAKA,EAAvC,GAA2C,KAAK,CAAL,CAAjD;AAAyD,UAASmF,WAAT,GAAsB;AAAC,SAAO,KAAKlN,CAAL,IAAQ,CAAT,GAAY,KAAKE,CAAjB,GAAoB,KAAK,CAAL,KAAS,EAAV,IAAe,EAAxC;AAA2C,UAASiN,YAAT,GAAuB;AAAC,SAAO,KAAKnN,CAAL,IAAQ,CAAT,GAAY,KAAKE,CAAjB,GAAoB,KAAK,CAAL,KAAS,EAAV,IAAe,EAAxC;AAA2C,UAASkN,YAAT,CAAsBzO,CAAtB,EAAwB;AAAC,SAAOyE,KAAKc,KAAL,CAAWd,KAAKiK,GAAL,GAAS,KAAKtF,EAAd,GAAiB3E,KAAKkK,GAAL,CAAS3O,CAAT,CAA5B,CAAP;AAAgD,UAAS4O,QAAT,GAAmB;AAAC,MAAG,KAAKrN,CAAL,GAAO,CAAV,EAAY;AAAC,WAAO,CAAC,CAAR;AAAU,GAAvB,MAA2B;AAAC,QAAG,KAAKF,CAAL,IAAQ,CAAR,IAAY,KAAKA,CAAL,IAAQ,CAAR,IAAW,KAAK,CAAL,KAAS,CAAnC,EAAsC;AAAC,aAAO,CAAP;AAAS,KAAhD,MAAoD;AAAC,aAAO,CAAP;AAAS;AAAC;AAAC,UAASwN,UAAT,CAAoBpP,CAApB,EAAsB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAACA,QAAE,EAAF;AAAK,OAAG,KAAKqP,MAAL,MAAe,CAAf,IAAkBrP,IAAE,CAApB,IAAuBA,IAAE,EAA5B,EAA+B;AAAC,WAAM,GAAN;AAAU,OAAIT,IAAE,KAAK+P,SAAL,CAAetP,CAAf,CAAN,CAAwB,IAAID,IAAEiF,KAAKW,GAAL,CAAS3F,CAAT,EAAWT,CAAX,CAAN,CAAoB,IAAIY,IAAEsK,IAAI1K,CAAJ,CAAN;AAAA,MAAaG,IAAEmJ,KAAf;AAAA,MAAqB/J,IAAE+J,KAAvB;AAAA,MAA6BhK,IAAE,EAA/B,CAAkC,KAAKoN,QAAL,CAActM,CAAd,EAAgBD,CAAhB,EAAkBZ,CAAlB,EAAqB,OAAMY,EAAEmP,MAAF,KAAW,CAAjB,EAAmB;AAAChQ,QAAE,CAACU,IAAET,EAAEiQ,QAAF,EAAH,EAAiBlO,QAAjB,CAA0BrB,CAA1B,EAA6B4C,MAA7B,CAAoC,CAApC,IAAuCvD,CAAzC,CAA2Ca,EAAEuM,QAAF,CAAWtM,CAAX,EAAaD,CAAb,EAAeZ,CAAf;AAAkB,UAAOA,EAAEiQ,QAAF,GAAalO,QAAb,CAAsBrB,CAAtB,IAAyBX,CAAhC;AAAkC,UAASmQ,YAAT,CAAsBlN,CAAtB,EAAwBhD,CAAxB,EAA0B;AAAC,OAAKoL,OAAL,CAAa,CAAb,EAAgB,IAAGpL,KAAG,IAAN,EAAW;AAACA,QAAE,EAAF;AAAK,OAAIC,IAAE,KAAK+P,SAAL,CAAehQ,CAAf,CAAN,CAAwB,IAAID,IAAE2F,KAAKW,GAAL,CAASrG,CAAT,EAAWC,CAAX,CAAN;AAAA,MAAoBQ,IAAE,KAAtB;AAAA,MAA4BQ,IAAE,CAA9B;AAAA,MAAgCF,IAAE,CAAlC,CAAoC,KAAI,IAAIL,IAAE,CAAV,EAAYA,IAAEsC,EAAElC,MAAhB,EAAuB,EAAEJ,CAAzB,EAA2B;AAAC,QAAIM,IAAEgK,MAAMhI,CAAN,EAAQtC,CAAR,CAAN,CAAiB,IAAGM,IAAE,CAAL,EAAO;AAAC,UAAGgC,EAAEkD,MAAF,CAASxF,CAAT,KAAa,GAAb,IAAkB,KAAKqP,MAAL,MAAe,CAApC,EAAsC;AAACtP,YAAE,IAAF;AAAO;AAAS,SAAET,IAAEe,CAAF,GAAIC,CAAN,CAAQ,IAAG,EAAEC,CAAF,IAAKhB,CAAR,EAAU;AAAC,WAAKkQ,SAAL,CAAepQ,CAAf,EAAkB,KAAKqQ,UAAL,CAAgBrP,CAAhB,EAAkB,CAAlB,EAAqBE,IAAE,CAAF,CAAIF,IAAE,CAAF;AAAI;AAAC,OAAGE,IAAE,CAAL,EAAO;AAAC,SAAKkP,SAAL,CAAezK,KAAKW,GAAL,CAASrG,CAAT,EAAWiB,CAAX,CAAf,EAA8B,KAAKmP,UAAL,CAAgBrP,CAAhB,EAAkB,CAAlB;AAAqB,OAAGN,CAAH,EAAK;AAACmJ,eAAW2B,IAAX,CAAgBC,KAAhB,CAAsB,IAAtB,EAA2B,IAA3B;AAAiC;AAAC,UAAS6E,aAAT,CAAuBpQ,CAAvB,EAAyBQ,CAAzB,EAA2BT,CAA3B,EAA6B;AAAC,MAAG,YAAU,OAAOS,CAApB,EAAsB;AAAC,QAAGR,IAAE,CAAL,EAAO;AAAC,WAAKmL,OAAL,CAAa,CAAb;AAAgB,KAAxB,MAA4B;AAAC,WAAKvB,UAAL,CAAgB5J,CAAhB,EAAkBD,CAAlB,EAAqB,IAAG,CAAC,KAAKsQ,OAAL,CAAarQ,IAAE,CAAf,CAAJ,EAAsB;AAAC,aAAKsQ,SAAL,CAAe3G,WAAWmD,GAAX,CAAeyD,SAAf,CAAyBvQ,IAAE,CAA3B,CAAf,EAA6CwQ,KAA7C,EAAmD,IAAnD;AAAyD,WAAG,KAAKvB,MAAL,EAAH,EAAiB;AAAC,aAAKkB,UAAL,CAAgB,CAAhB,EAAkB,CAAlB;AAAqB,cAAM,CAAC,KAAKM,eAAL,CAAqBjQ,CAArB,CAAP,EAA+B;AAAC,aAAK2P,UAAL,CAAgB,CAAhB,EAAkB,CAAlB,EAAqB,IAAG,KAAKhB,SAAL,KAAiBnP,CAApB,EAAsB;AAAC,eAAKuL,KAAL,CAAW5B,WAAWmD,GAAX,CAAeyD,SAAf,CAAyBvQ,IAAE,CAA3B,CAAX,EAAyC,IAAzC;AAA+C;AAAC;AAAC;AAAC,GAA9T,MAAkU;AAAC,QAAIE,IAAE,IAAIqJ,KAAJ,EAAN;AAAA,QAAkBzJ,IAAEE,IAAE,CAAtB,CAAwBE,EAAEW,MAAF,GAAS,CAACb,KAAG,CAAJ,IAAO,CAAhB,CAAkBQ,EAAEkQ,SAAF,CAAYxQ,CAAZ,EAAe,IAAGJ,IAAE,CAAL,EAAO;AAACI,QAAE,CAAF,KAAO,CAAC,KAAGJ,CAAJ,IAAO,CAAd;AAAiB,KAAzB,MAA6B;AAACI,QAAE,CAAF,IAAK,CAAL;AAAO,UAAK2J,UAAL,CAAgB3J,CAAhB,EAAkB,GAAlB;AAAuB;AAAC,UAASyQ,aAAT,GAAwB;AAAC,MAAIpQ,IAAE,KAAK8B,CAAX;AAAA,MAAa5B,IAAE,IAAI8I,KAAJ,EAAf,CAA2B9I,EAAE,CAAF,IAAK,KAAK8B,CAAV,CAAY,IAAI/B,IAAE,KAAK4J,EAAL,GAAS7J,IAAE,KAAK6J,EAAR,GAAY,CAA1B;AAAA,MAA4BpK,CAA5B;AAAA,MAA8BgB,IAAE,CAAhC,CAAkC,IAAGT,MAAI,CAAP,EAAS;AAAC,QAAGC,IAAE,KAAK4J,EAAP,IAAW,CAACpK,IAAE,KAAKO,CAAL,KAASC,CAAZ,KAAgB,CAAC,KAAK+B,CAAL,GAAO,KAAK8H,EAAb,KAAkB7J,CAAhD,EAAkD;AAACC,QAAEO,GAAF,IAAOhB,IAAG,KAAKuC,CAAL,IAAS,KAAK6H,EAAL,GAAQ5J,CAA3B;AAA+B,YAAMD,KAAG,CAAT,EAAW;AAAC,UAAGC,IAAE,CAAL,EAAO;AAACR,YAAE,CAAC,KAAKO,CAAL,IAAS,CAAC,KAAGC,CAAJ,IAAO,CAAjB,KAAuB,IAAEA,CAA3B,CAA8BR,KAAG,KAAK,EAAEO,CAAP,MAAYC,KAAG,KAAK4J,EAAL,GAAQ,CAAvB,CAAH;AAA6B,OAAnE,MAAuE;AAACpK,YAAG,KAAKO,CAAL,MAAUC,KAAG,CAAb,CAAD,GAAkB,GAApB,CAAwB,IAAGA,KAAG,CAAN,EAAQ;AAACA,eAAG,KAAK4J,EAAR,CAAW,EAAE7J,CAAF;AAAI;AAAC,WAAG,CAACP,IAAE,GAAH,KAAS,CAAZ,EAAc;AAACA,aAAG,CAAC,GAAJ;AAAQ,WAAGgB,KAAG,CAAH,IAAM,CAAC,KAAKuB,CAAL,GAAO,GAAR,MAAevC,IAAE,GAAjB,CAAT,EAA+B;AAAC,UAAEgB,CAAF;AAAI,WAAGA,IAAE,CAAF,IAAKhB,KAAG,KAAKuC,CAAhB,EAAkB;AAAC9B,UAAEO,GAAF,IAAOhB,CAAP;AAAS;AAAC;AAAC,UAAOS,CAAP;AAAS,UAASmQ,QAAT,CAAkBrQ,CAAlB,EAAoB;AAAC,SAAO,KAAKsM,SAAL,CAAetM,CAAf,KAAmB,CAA1B;AAA6B,UAASsQ,KAAT,CAAetQ,CAAf,EAAiB;AAAC,SAAO,KAAKsM,SAAL,CAAetM,CAAf,IAAkB,CAAnB,GAAsB,IAAtB,GAA2BA,CAAjC;AAAmC,UAASuQ,KAAT,CAAevQ,CAAf,EAAiB;AAAC,SAAO,KAAKsM,SAAL,CAAetM,CAAf,IAAkB,CAAnB,GAAsB,IAAtB,GAA2BA,CAAjC;AAAmC,UAASwQ,YAAT,CAAsBtQ,CAAtB,EAAwBV,CAAxB,EAA0BS,CAA1B,EAA4B;AAAC,MAAIN,CAAJ;AAAA,MAAMJ,CAAN;AAAA,MAAQS,IAAEkF,KAAKb,GAAL,CAASnE,EAAE4B,CAAX,EAAa,KAAKA,CAAlB,CAAV,CAA+B,KAAInC,IAAE,CAAN,EAAQA,IAAEK,CAAV,EAAY,EAAEL,CAAd,EAAgB;AAACM,MAAEN,CAAF,IAAKH,EAAE,KAAKG,CAAL,CAAF,EAAUO,EAAEP,CAAF,CAAV,CAAL;AAAqB,OAAGO,EAAE4B,CAAF,GAAI,KAAKA,CAAZ,EAAc;AAACvC,QAAEW,EAAE8B,CAAF,GAAI,KAAK8H,EAAX,CAAc,KAAInK,IAAEK,CAAN,EAAQL,IAAE,KAAKmC,CAAf,EAAiB,EAAEnC,CAAnB,EAAqB;AAACM,QAAEN,CAAF,IAAKH,EAAE,KAAKG,CAAL,CAAF,EAAUJ,CAAV,CAAL;AAAkB,OAAEuC,CAAF,GAAI,KAAKA,CAAT;AAAW,GAAhF,MAAoF;AAACvC,QAAE,KAAKyC,CAAL,GAAO,KAAK8H,EAAd,CAAiB,KAAInK,IAAEK,CAAN,EAAQL,IAAEO,EAAE4B,CAAZ,EAAc,EAAEnC,CAAhB,EAAkB;AAACM,QAAEN,CAAF,IAAKH,EAAED,CAAF,EAAIW,EAAEP,CAAF,CAAJ,CAAL;AAAe,OAAEmC,CAAF,GAAI5B,EAAE4B,CAAN;AAAQ,KAAEE,CAAF,GAAIxC,EAAE,KAAKwC,CAAP,EAAS9B,EAAE8B,CAAX,CAAJ,CAAkB/B,EAAEgC,KAAF;AAAU,UAASwO,MAAT,CAAgBhQ,CAAhB,EAAkBT,CAAlB,EAAoB;AAAC,SAAOS,IAAET,CAAT;AAAW,UAAS0Q,KAAT,CAAe1Q,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiByQ,MAAjB,EAAwBvQ,CAAxB,EAA2B,OAAOA,CAAP;AAAS,UAAS+P,KAAT,CAAexP,CAAf,EAAiBT,CAAjB,EAAmB;AAAC,SAAOS,IAAET,CAAT;AAAW,UAAS2Q,IAAT,CAAc3Q,CAAd,EAAgB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiBiQ,KAAjB,EAAuB/P,CAAvB,EAA0B,OAAOA,CAAP;AAAS,UAAS0Q,MAAT,CAAgBnQ,CAAhB,EAAkBT,CAAlB,EAAoB;AAAC,SAAOS,IAAET,CAAT;AAAW,UAAS6Q,KAAT,CAAe7Q,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiB4Q,MAAjB,EAAwB1Q,CAAxB,EAA2B,OAAOA,CAAP;AAAS,UAAS4Q,SAAT,CAAmBrQ,CAAnB,EAAqBT,CAArB,EAAuB;AAAC,SAAOS,IAAE,CAACT,CAAV;AAAY,UAAS+Q,QAAT,CAAkB/Q,CAAlB,EAAoB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwG,SAAL,CAAe/P,CAAf,EAAiB8Q,SAAjB,EAA2B5Q,CAA3B,EAA8B,OAAOA,CAAP;AAAS,UAAS8Q,KAAT,GAAgB;AAAC,MAAIhR,IAAEuJ,KAAN,CAAY,KAAI,IAAI9I,IAAE,CAAV,EAAYA,IAAE,KAAKqB,CAAnB,EAAqB,EAAErB,CAAvB,EAAyB;AAACT,MAAES,CAAF,IAAK,KAAKqJ,EAAL,GAAQ,CAAC,KAAKrJ,CAAL,CAAd;AAAsB,KAAEqB,CAAF,GAAI,KAAKA,CAAT,CAAW9B,EAAEgC,CAAF,GAAI,CAAC,KAAKA,CAAV,CAAY,OAAOhC,CAAP;AAAS,UAASiR,WAAT,CAAqBjR,CAArB,EAAuB;AAAC,MAAIS,IAAE8I,KAAN,CAAY,IAAGvJ,IAAE,CAAL,EAAO;AAAC,SAAKyM,QAAL,CAAc,CAACzM,CAAf,EAAiBS,CAAjB;AAAoB,GAA5B,MAAgC;AAAC,SAAK2L,QAAL,CAAcpM,CAAd,EAAgBS,CAAhB;AAAmB,UAAOA,CAAP;AAAS,UAASyQ,YAAT,CAAsBlR,CAAtB,EAAwB;AAAC,MAAIS,IAAE8I,KAAN,CAAY,IAAGvJ,IAAE,CAAL,EAAO;AAAC,SAAKoM,QAAL,CAAc,CAACpM,CAAf,EAAiBS,CAAjB;AAAoB,GAA5B,MAAgC;AAAC,SAAKgM,QAAL,CAAczM,CAAd,EAAgBS,CAAhB;AAAmB,UAAOA,CAAP;AAAS,UAAS0Q,IAAT,CAAc1Q,CAAd,EAAgB;AAAC,MAAGA,KAAG,CAAN,EAAQ;AAAC,WAAO,CAAC,CAAR;AAAU,OAAIT,IAAE,CAAN,CAAQ,IAAG,CAACS,IAAE,KAAH,KAAW,CAAd,EAAgB;AAACA,UAAI,EAAJ,CAAOT,KAAG,EAAH;AAAM,OAAG,CAACS,IAAE,GAAH,KAAS,CAAZ,EAAc;AAACA,UAAI,CAAJ,CAAMT,KAAG,CAAH;AAAK,OAAG,CAACS,IAAE,EAAH,KAAQ,CAAX,EAAa;AAACA,UAAI,CAAJ,CAAMT,KAAG,CAAH;AAAK,OAAG,CAACS,IAAE,CAAH,KAAO,CAAV,EAAY;AAACA,UAAI,CAAJ,CAAMT,KAAG,CAAH;AAAK,OAAG,CAACS,IAAE,CAAH,KAAO,CAAV,EAAY;AAAC,MAAET,CAAF;AAAI,UAAOA,CAAP;AAAS,UAASoR,iBAAT,GAA4B;AAAC,OAAI,IAAI3Q,IAAE,CAAV,EAAYA,IAAE,KAAKqB,CAAnB,EAAqB,EAAErB,CAAvB,EAAyB;AAAC,QAAG,KAAKA,CAAL,KAAS,CAAZ,EAAc;AAAC,aAAOA,IAAE,KAAKoJ,EAAP,GAAUsH,KAAK,KAAK1Q,CAAL,CAAL,CAAjB;AAA+B;AAAC,OAAG,KAAKuB,CAAL,GAAO,CAAV,EAAY;AAAC,WAAO,KAAKF,CAAL,GAAO,KAAK+H,EAAnB;AAAsB,UAAO,CAAC,CAAR;AAAU,UAASwH,IAAT,CAAc5Q,CAAd,EAAgB;AAAC,MAAIT,IAAE,CAAN,CAAQ,OAAMS,KAAG,CAAT,EAAW;AAACA,SAAGA,IAAE,CAAL,CAAO,EAAET,CAAF;AAAI,UAAOA,CAAP;AAAS,UAASsR,UAAT,GAAqB;AAAC,MAAIpR,IAAE,CAAN;AAAA,MAAQO,IAAE,KAAKuB,CAAL,GAAO,KAAK8H,EAAtB,CAAyB,KAAI,IAAI9J,IAAE,CAAV,EAAYA,IAAE,KAAK8B,CAAnB,EAAqB,EAAE9B,CAAvB,EAAyB;AAACE,SAAGmR,KAAK,KAAKrR,CAAL,IAAQS,CAAb,CAAH;AAAmB,UAAOP,CAAP;AAAS,UAASqR,SAAT,CAAmBvR,CAAnB,EAAqB;AAAC,MAAIS,IAAEyE,KAAKc,KAAL,CAAWhG,IAAE,KAAK6J,EAAlB,CAAN,CAA4B,IAAGpJ,KAAG,KAAKqB,CAAX,EAAa;AAAC,WAAO,KAAKE,CAAL,IAAQ,CAAf;AAAkB,UAAO,CAAC,KAAKvB,CAAL,IAAS,KAAIT,IAAE,KAAK6J,EAArB,KAA4B,CAAnC;AAAsC,UAAS2H,YAAT,CAAsBtR,CAAtB,EAAwBF,CAAxB,EAA0B;AAAC,MAAIS,IAAE2I,WAAWmD,GAAX,CAAeyD,SAAf,CAAyB9P,CAAzB,CAAN,CAAkC,KAAK6P,SAAL,CAAetP,CAAf,EAAiBT,CAAjB,EAAmBS,CAAnB,EAAsB,OAAOA,CAAP;AAAS,UAASgR,QAAT,CAAkBhR,CAAlB,EAAoB;AAAC,SAAO,KAAKiR,SAAL,CAAejR,CAAf,EAAiBwP,KAAjB,CAAP;AAA+B,UAAS0B,UAAT,CAAoBlR,CAApB,EAAsB;AAAC,SAAO,KAAKiR,SAAL,CAAejR,CAAf,EAAiBqQ,SAAjB,CAAP;AAAmC,UAASc,SAAT,CAAmBnR,CAAnB,EAAqB;AAAC,SAAO,KAAKiR,SAAL,CAAejR,CAAf,EAAiBmQ,MAAjB,CAAP;AAAgC,UAASiB,QAAT,CAAkBlS,CAAlB,EAAoBF,CAApB,EAAsB;AAAC,MAAIQ,IAAE,CAAN;AAAA,MAAQV,IAAE,CAAV;AAAA,MAAYS,IAAEkF,KAAKb,GAAL,CAAS1E,EAAEmC,CAAX,EAAa,KAAKA,CAAlB,CAAd,CAAmC,OAAM7B,IAAED,CAAR,EAAU;AAACT,SAAG,KAAKU,CAAL,IAAQN,EAAEM,CAAF,CAAX,CAAgBR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,OAAGlK,EAAEmC,CAAF,GAAI,KAAKA,CAAZ,EAAc;AAACvC,SAAGI,EAAEqC,CAAL,CAAO,OAAM/B,IAAE,KAAK6B,CAAb,EAAe;AAACvC,WAAG,KAAKU,CAAL,CAAH,CAAWR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAG,KAAK7H,CAAR;AAAU,GAAxF,MAA4F;AAACzC,SAAG,KAAKyC,CAAR,CAAU,OAAM/B,IAAEN,EAAEmC,CAAV,EAAY;AAACvC,WAAGI,EAAEM,CAAF,CAAH,CAAQR,EAAEQ,GAAF,IAAOV,IAAE,KAAKuK,EAAd,CAAiBvK,MAAI,KAAKsK,EAAT;AAAY,UAAGlK,EAAEqC,CAAL;AAAO,KAAEA,CAAF,GAAKzC,IAAE,CAAH,GAAM,CAAC,CAAP,GAAS,CAAb,CAAe,IAAGA,IAAE,CAAL,EAAO;AAACE,MAAEQ,GAAF,IAAOV,CAAP;AAAS,GAAjB,MAAqB;AAAC,QAAGA,IAAE,CAAC,CAAN,EAAQ;AAACE,QAAEQ,GAAF,IAAO,KAAK8J,EAAL,GAAQxK,CAAf;AAAiB;AAAC,KAAEuC,CAAF,GAAI7B,CAAJ,CAAMR,EAAEwC,KAAF;AAAU,UAAS6P,KAAT,CAAe9R,CAAf,EAAiB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKwI,KAAL,CAAW/R,CAAX,EAAaE,CAAb,EAAgB,OAAOA,CAAP;AAAS,UAAS8R,UAAT,CAAoBhS,CAApB,EAAsB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKyB,KAAL,CAAWhL,CAAX,EAAaE,CAAb,EAAgB,OAAOA,CAAP;AAAS,UAAS+R,UAAT,CAAoBjS,CAApB,EAAsB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAK2D,UAAL,CAAgBlN,CAAhB,EAAkBE,CAAlB,EAAqB,OAAOA,CAAP;AAAS,UAASgS,QAAT,GAAmB;AAAC,MAAIzR,IAAE8I,KAAN,CAAY,KAAK8D,QAAL,CAAc5M,CAAd,EAAiB,OAAOA,CAAP;AAAS,UAAS0R,QAAT,CAAkBnS,CAAlB,EAAoB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKoD,QAAL,CAAc3M,CAAd,EAAgBE,CAAhB,EAAkB,IAAlB,EAAwB,OAAOA,CAAP;AAAS,UAASkS,WAAT,CAAqBpS,CAArB,EAAuB;AAAC,MAAIE,IAAEqJ,KAAN,CAAY,KAAKoD,QAAL,CAAc3M,CAAd,EAAgB,IAAhB,EAAqBE,CAArB,EAAwB,OAAOA,CAAP;AAAS,UAASmS,oBAAT,CAA8BrS,CAA9B,EAAgC;AAAC,MAAIL,IAAE4J,KAAN;AAAA,MAAYrJ,IAAEqJ,KAAd,CAAoB,KAAKoD,QAAL,CAAc3M,CAAd,EAAgBL,CAAhB,EAAkBO,CAAlB,EAAqB,OAAO,IAAI8I,KAAJ,CAAUrJ,CAAV,EAAYO,CAAZ,CAAP;AAAsB,UAASoS,YAAT,CAAsB7R,CAAtB,EAAwB;AAAC,OAAK,KAAKqB,CAAV,IAAa,KAAK8H,EAAL,CAAQ,CAAR,EAAUnJ,IAAE,CAAZ,EAAc,IAAd,EAAmB,CAAnB,EAAqB,CAArB,EAAuB,KAAKqB,CAA5B,CAAb,CAA4C,EAAE,KAAKA,CAAP,CAAS,KAAKG,KAAL;AAAa,UAASsQ,aAAT,CAAuBvS,CAAvB,EAAyBS,CAAzB,EAA2B;AAAC,MAAGT,KAAG,CAAN,EAAQ;AAAC;AAAO,UAAM,KAAK8B,CAAL,IAAQrB,CAAd,EAAgB;AAAC,SAAK,KAAKqB,CAAL,EAAL,IAAe,CAAf;AAAiB,QAAKrB,CAAL,KAAST,CAAT,CAAW,OAAM,KAAKS,CAAL,KAAS,KAAKsJ,EAApB,EAAuB;AAAC,SAAKtJ,CAAL,KAAS,KAAKsJ,EAAd,CAAiB,IAAG,EAAEtJ,CAAF,IAAK,KAAKqB,CAAb,EAAe;AAAC,WAAK,KAAKA,CAAL,EAAL,IAAe,CAAf;AAAiB,OAAE,KAAKrB,CAAL,CAAF;AAAU;AAAC,UAAS+R,OAAT,GAAkB,CAAE,UAASC,IAAT,CAAchS,CAAd,EAAgB;AAAC,SAAOA,CAAP;AAAS,UAASiS,MAAT,CAAgBjS,CAAhB,EAAkBP,CAAlB,EAAoBF,CAApB,EAAsB;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf;AAAkB,UAAS2S,MAAT,CAAgBlS,CAAhB,EAAkBT,CAAlB,EAAoB;AAACS,IAAE4M,QAAF,CAAWrN,CAAX;AAAc,SAAQJ,SAAR,CAAkB0N,OAAlB,GAA0BmF,IAA1B,CAA+BD,QAAQ5S,SAAR,CAAkB2N,MAAlB,GAAyBkF,IAAzB,CAA8BD,QAAQ5S,SAAR,CAAkB4N,KAAlB,GAAwBkF,MAAxB,CAA+BF,QAAQ5S,SAAR,CAAkB6N,KAAlB,GAAwBkF,MAAxB,CAA+B,SAASC,KAAT,CAAenS,CAAf,EAAiB;AAAC,SAAO,KAAKkO,GAAL,CAASlO,CAAT,EAAW,IAAI+R,OAAJ,EAAX,CAAP;AAAiC,UAASK,kBAAT,CAA4B7S,CAA5B,EAA8BP,CAA9B,EAAgCQ,CAAhC,EAAkC;AAAC,MAAIN,IAAEuF,KAAKb,GAAL,CAAS,KAAKvC,CAAL,GAAO9B,EAAE8B,CAAlB,EAAoBrC,CAApB,CAAN,CAA6BQ,EAAE+B,CAAF,GAAI,CAAJ,CAAM/B,EAAE6B,CAAF,GAAInC,CAAJ,CAAM,OAAMA,IAAE,CAAR,EAAU;AAACM,MAAE,EAAEN,CAAJ,IAAO,CAAP;AAAS,OAAIO,CAAJ,CAAM,KAAIA,IAAED,EAAE6B,CAAF,GAAI,KAAKA,CAAf,EAAiBnC,IAAEO,CAAnB,EAAqB,EAAEP,CAAvB,EAAyB;AAACM,MAAEN,IAAE,KAAKmC,CAAT,IAAY,KAAK8H,EAAL,CAAQ,CAAR,EAAU5J,EAAEL,CAAF,CAAV,EAAeM,CAAf,EAAiBN,CAAjB,EAAmB,CAAnB,EAAqB,KAAKmC,CAA1B,CAAZ;AAAyC,QAAI5B,IAAEgF,KAAKb,GAAL,CAASrE,EAAE8B,CAAX,EAAarC,CAAb,CAAN,EAAsBE,IAAEO,CAAxB,EAA0B,EAAEP,CAA5B,EAA8B;AAAC,SAAKiK,EAAL,CAAQ,CAAR,EAAU5J,EAAEL,CAAF,CAAV,EAAeM,CAAf,EAAiBN,CAAjB,EAAmB,CAAnB,EAAqBF,IAAEE,CAAvB;AAA0B,KAAEsC,KAAF;AAAU,UAAS6Q,kBAAT,CAA4B9S,CAA5B,EAA8BC,CAA9B,EAAgCN,CAAhC,EAAkC;AAAC,IAAEM,CAAF,CAAI,IAAIC,IAAEP,EAAEmC,CAAF,GAAI,KAAKA,CAAL,GAAO9B,EAAE8B,CAAT,GAAW7B,CAArB,CAAuBN,EAAEqC,CAAF,GAAI,CAAJ,CAAM,OAAM,EAAE9B,CAAF,IAAK,CAAX,EAAa;AAACP,MAAEO,CAAF,IAAK,CAAL;AAAO,QAAIA,IAAEgF,KAAKf,GAAL,CAASlE,IAAE,KAAK6B,CAAhB,EAAkB,CAAlB,CAAN,EAA2B5B,IAAEF,EAAE8B,CAA/B,EAAiC,EAAE5B,CAAnC,EAAqC;AAACP,MAAE,KAAKmC,CAAL,GAAO5B,CAAP,GAASD,CAAX,IAAc,KAAK2J,EAAL,CAAQ3J,IAAEC,CAAV,EAAYF,EAAEE,CAAF,CAAZ,EAAiBP,CAAjB,EAAmB,CAAnB,EAAqB,CAArB,EAAuB,KAAKmC,CAAL,GAAO5B,CAAP,GAASD,CAAhC,CAAd;AAAiD,KAAEgC,KAAF,GAAUtC,EAAE6M,SAAF,CAAY,CAAZ,EAAc7M,CAAd;AAAiB,UAASoT,OAAT,CAAiBtS,CAAjB,EAAmB;AAAC,OAAKuS,EAAL,GAAQzJ,KAAR,CAAc,KAAK0J,EAAL,GAAQ1J,KAAR,CAAcH,WAAWmD,GAAX,CAAeF,SAAf,CAAyB,IAAE5L,EAAEqB,CAA7B,EAA+B,KAAKkR,EAApC,EAAwC,KAAKE,EAAL,GAAQ,KAAKF,EAAL,CAAQG,MAAR,CAAe1S,CAAf,CAAR,CAA0B,KAAK+B,CAAL,GAAO/B,CAAP;AAAS,UAAS2S,cAAT,CAAwB3S,CAAxB,EAA0B;AAAC,MAAGA,EAAEuB,CAAF,GAAI,CAAJ,IAAOvB,EAAEqB,CAAF,GAAI,IAAE,KAAKU,CAAL,CAAOV,CAAvB,EAAyB;AAAC,WAAOrB,EAAEqM,GAAF,CAAM,KAAKtK,CAAX,CAAP;AAAqB,GAA/C,MAAmD;AAAC,QAAG/B,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,IAAoB,CAAvB,EAAyB;AAAC,aAAO/B,CAAP;AAAS,KAAnC,MAAuC;AAAC,UAAIT,IAAEuJ,KAAN,CAAY9I,EAAE0L,MAAF,CAASnM,CAAT,EAAY,KAAKmN,MAAL,CAAYnN,CAAZ,EAAe,OAAOA,CAAP;AAAS;AAAC;AAAC,UAASqT,aAAT,CAAuB5S,CAAvB,EAAyB;AAAC,SAAOA,CAAP;AAAS,UAAS6S,aAAT,CAAuB7S,CAAvB,EAAyB;AAACA,IAAE+L,SAAF,CAAY,KAAKhK,CAAL,CAAOV,CAAP,GAAS,CAArB,EAAuB,KAAKkR,EAA5B,EAAgC,IAAGvS,EAAEqB,CAAF,GAAI,KAAKU,CAAL,CAAOV,CAAP,GAAS,CAAhB,EAAkB;AAACrB,MAAEqB,CAAF,GAAI,KAAKU,CAAL,CAAOV,CAAP,GAAS,CAAb,CAAerB,EAAEwB,KAAF;AAAU,QAAKiR,EAAL,CAAQK,eAAR,CAAwB,KAAKP,EAA7B,EAAgC,KAAKxQ,CAAL,CAAOV,CAAP,GAAS,CAAzC,EAA2C,KAAKmR,EAAhD,EAAoD,KAAKzQ,CAAL,CAAOgR,eAAP,CAAuB,KAAKP,EAA5B,EAA+B,KAAKzQ,CAAL,CAAOV,CAAP,GAAS,CAAxC,EAA0C,KAAKkR,EAA/C,EAAmD,OAAMvS,EAAE6L,SAAF,CAAY,KAAK0G,EAAjB,IAAqB,CAA3B,EAA6B;AAACvS,MAAEmP,UAAF,CAAa,CAAb,EAAe,KAAKpN,CAAL,CAAOV,CAAP,GAAS,CAAxB;AAA2B,KAAEkJ,KAAF,CAAQ,KAAKgI,EAAb,EAAgBvS,CAAhB,EAAmB,OAAMA,EAAE6L,SAAF,CAAY,KAAK9J,CAAjB,KAAqB,CAA3B,EAA6B;AAAC/B,MAAEuK,KAAF,CAAQ,KAAKxI,CAAb,EAAe/B,CAAf;AAAkB;AAAC,UAASgT,YAAT,CAAsBhT,CAAtB,EAAwBT,CAAxB,EAA0B;AAACS,IAAE4M,QAAF,CAAWrN,CAAX,EAAc,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,UAAS0T,YAAT,CAAsBjT,CAAtB,EAAwBP,CAAxB,EAA0BF,CAA1B,EAA4B;AAACS,IAAEyM,UAAF,CAAahN,CAAb,EAAeF,CAAf,EAAkB,KAAKmN,MAAL,CAAYnN,CAAZ;AAAe,SAAQJ,SAAR,CAAkB0N,OAAlB,GAA0B8F,cAA1B,CAAyCL,QAAQnT,SAAR,CAAkB2N,MAAlB,GAAyB8F,aAAzB,CAAuCN,QAAQnT,SAAR,CAAkBuN,MAAlB,GAAyBmG,aAAzB,CAAuCP,QAAQnT,SAAR,CAAkB4N,KAAlB,GAAwBkG,YAAxB,CAAqCX,QAAQnT,SAAR,CAAkB6N,KAAlB,GAAwBgG,YAAxB,CAAqC,SAASE,QAAT,CAAkB5R,CAAlB,EAAoBtC,CAApB,EAAsB;AAAC,MAAIsB,IAAEgB,EAAE6M,SAAF,EAAN;AAAA,MAAoBpP,CAApB;AAAA,MAAsBQ,IAAE2K,IAAI,CAAJ,CAAxB;AAAA,MAA+B1G,CAA/B,CAAiC,IAAGlD,KAAG,CAAN,EAAQ;AAAC,WAAOf,CAAP;AAAS,GAAlB,MAAsB;AAAC,QAAGe,IAAE,EAAL,EAAQ;AAACvB,UAAE,CAAF;AAAI,KAAb,MAAiB;AAAC,UAAGuB,IAAE,EAAL,EAAQ;AAACvB,YAAE,CAAF;AAAI,OAAb,MAAiB;AAAC,YAAGuB,IAAE,GAAL,EAAS;AAACvB,cAAE,CAAF;AAAI,SAAd,MAAkB;AAAC,cAAGuB,IAAE,GAAL,EAAS;AAACvB,gBAAE,CAAF;AAAI,WAAd,MAAkB;AAACA,gBAAE,CAAF;AAAI;AAAC;AAAC;AAAC;AAAC,OAAGuB,IAAE,CAAL,EAAO;AAACkD,QAAE,IAAI2I,OAAJ,CAAYnN,CAAZ,CAAF;AAAiB,GAAzB,MAA6B;AAAC,QAAGA,EAAEiP,MAAF,EAAH,EAAc;AAACzK,UAAE,IAAI8O,OAAJ,CAAYtT,CAAZ,CAAF;AAAiB,KAAhC,MAAoC;AAACwE,UAAE,IAAI0J,UAAJ,CAAelO,CAAf,CAAF;AAAoB;AAAC,OAAIqB,IAAE,IAAIkI,KAAJ,EAAN;AAAA,MAAkBrJ,IAAE,CAApB;AAAA,MAAsBqC,IAAExC,IAAE,CAA1B;AAAA,MAA4BiB,IAAE,CAAC,KAAGjB,CAAJ,IAAO,CAArC,CAAuCsB,EAAE,CAAF,IAAKmD,EAAEqJ,OAAF,CAAU,IAAV,CAAL,CAAqB,IAAG9N,IAAE,CAAL,EAAO;AAAC,QAAIiI,IAAE8B,KAAN,CAAYtF,EAAEwJ,KAAF,CAAQ3M,EAAE,CAAF,CAAR,EAAa2G,CAAb,EAAgB,OAAM9H,KAAGc,CAAT,EAAW;AAACK,QAAEnB,CAAF,IAAK4J,KAAL,CAAWtF,EAAEuJ,KAAF,CAAQ/F,CAAR,EAAU3G,EAAEnB,IAAE,CAAJ,CAAV,EAAiBmB,EAAEnB,CAAF,CAAjB,EAAuBA,KAAG,CAAH;AAAK;AAAC,OAAIY,IAAEwB,EAAED,CAAF,GAAI,CAAV;AAAA,MAAYiC,CAAZ;AAAA,MAAcG,IAAE,IAAhB;AAAA,MAAqBhE,IAAEqJ,KAAvB;AAAA,MAA6B7B,CAA7B,CAA+B3G,IAAEyK,MAAMzJ,EAAExB,CAAF,CAAN,IAAY,CAAd,CAAgB,OAAMA,KAAG,CAAT,EAAW;AAAC,QAAGQ,KAAGiB,CAAN,EAAQ;AAAC+B,UAAGhC,EAAExB,CAAF,KAAOQ,IAAEiB,CAAV,GAAcvB,CAAhB;AAAkB,KAA3B,MAA+B;AAACsD,UAAE,CAAChC,EAAExB,CAAF,IAAM,CAAC,KAAIQ,IAAE,CAAP,IAAW,CAAlB,KAAwBiB,IAAEjB,CAA5B,CAA+B,IAAGR,IAAE,CAAL,EAAO;AAACwD,aAAGhC,EAAExB,IAAE,CAAJ,KAAS,KAAKsJ,EAAL,GAAQ9I,CAAR,GAAUiB,CAAtB;AAAyB;AAAC,SAAExC,CAAF,CAAI,OAAM,CAACuE,IAAE,CAAH,KAAO,CAAb,EAAe;AAACA,YAAI,CAAJ,CAAM,EAAEpE,CAAF;AAAI,SAAG,CAACoB,KAAGpB,CAAJ,IAAO,CAAV,EAAY;AAACoB,WAAG,KAAK8I,EAAR,CAAW,EAAEtJ,CAAF;AAAI,SAAG2D,CAAH,EAAK;AAACpD,QAAEiD,CAAF,EAAKoI,MAAL,CAAYnM,CAAZ,EAAekE,IAAE,KAAF;AAAQ,KAA7B,MAAiC;AAAC,aAAMvE,IAAE,CAAR,EAAU;AAACsE,UAAEwJ,KAAF,CAAQzN,CAAR,EAAUE,CAAV,EAAa+D,EAAEwJ,KAAF,CAAQvN,CAAR,EAAUF,CAAV,EAAaL,KAAG,CAAH;AAAK,WAAGA,IAAE,CAAL,EAAO;AAACsE,UAAEwJ,KAAF,CAAQzN,CAAR,EAAUE,CAAV;AAAa,OAArB,MAAyB;AAACwH,YAAE1H,CAAF,CAAIA,IAAEE,CAAF,CAAIA,IAAEwH,CAAF;AAAI,SAAE8F,KAAF,CAAQtN,CAAR,EAAUY,EAAEiD,CAAF,CAAV,EAAe/D,CAAf;AAAkB,YAAMO,KAAG,CAAH,IAAM,CAACwB,EAAExB,CAAF,IAAM,KAAGQ,CAAV,KAAe,CAA3B,EAA6B;AAACkD,QAAEwJ,KAAF,CAAQzN,CAAR,EAAUE,CAAV,EAAawH,IAAE1H,CAAF,CAAIA,IAAEE,CAAF,CAAIA,IAAEwH,CAAF,CAAI,IAAG,EAAE3G,CAAF,GAAI,CAAP,EAAS;AAACA,YAAE,KAAK8I,EAAL,GAAQ,CAAV,CAAY,EAAEtJ,CAAF;AAAI;AAAC;AAAC,UAAO0D,EAAEsJ,MAAF,CAASvN,CAAT,CAAP;AAAmB,UAAS4T,KAAT,CAAe1T,CAAf,EAAiB;AAAC,MAAIF,IAAG,KAAKgC,CAAL,GAAO,CAAR,GAAW,KAAKmJ,MAAL,EAAX,GAAyB,KAAK3J,KAAL,EAA/B,CAA4C,IAAIhC,IAAGU,EAAE8B,CAAF,GAAI,CAAL,GAAQ9B,EAAEiL,MAAF,EAAR,GAAmBjL,EAAEsB,KAAF,EAAzB,CAAmC,IAAGxB,EAAEsM,SAAF,CAAY9M,CAAZ,IAAe,CAAlB,EAAoB;AAAC,QAAIS,IAAED,CAAN,CAAQA,IAAER,CAAF,CAAIA,IAAES,CAAF;AAAI,OAAIN,IAAEK,EAAE6T,eAAF,EAAN;AAAA,MAA0BpU,IAAED,EAAEqU,eAAF,EAA5B,CAAgD,IAAGpU,IAAE,CAAL,EAAO;AAAC,WAAOO,CAAP;AAAS,OAAGL,IAAEF,CAAL,EAAO;AAACA,QAAEE,CAAF;AAAI,OAAGF,IAAE,CAAL,EAAO;AAACO,MAAEyM,QAAF,CAAWhN,CAAX,EAAaO,CAAb,EAAgBR,EAAEiN,QAAF,CAAWhN,CAAX,EAAaD,CAAb;AAAgB,UAAMQ,EAAEuP,MAAF,KAAW,CAAjB,EAAmB;AAAC,QAAG,CAAC5P,IAAEK,EAAE6T,eAAF,EAAH,IAAwB,CAA3B,EAA6B;AAAC7T,QAAEyM,QAAF,CAAW9M,CAAX,EAAaK,CAAb;AAAgB,SAAG,CAACL,IAAEH,EAAEqU,eAAF,EAAH,IAAwB,CAA3B,EAA6B;AAACrU,QAAEiN,QAAF,CAAW9M,CAAX,EAAaH,CAAb;AAAgB,SAAGQ,EAAEsM,SAAF,CAAY9M,CAAZ,KAAgB,CAAnB,EAAqB;AAACQ,QAAEgL,KAAF,CAAQxL,CAAR,EAAUQ,CAAV,EAAaA,EAAEyM,QAAF,CAAW,CAAX,EAAazM,CAAb;AAAgB,KAAnD,MAAuD;AAACR,QAAEwL,KAAF,CAAQhL,CAAR,EAAUR,CAAV,EAAaA,EAAEiN,QAAF,CAAW,CAAX,EAAajN,CAAb;AAAgB;AAAC,OAAGC,IAAE,CAAL,EAAO;AAACD,MAAE4M,QAAF,CAAW3M,CAAX,EAAaD,CAAb;AAAgB,UAAOA,CAAP;AAAS,UAASsU,SAAT,CAAmB7T,CAAnB,EAAqB;AAAC,MAAGA,KAAG,CAAN,EAAQ;AAAC,WAAO,CAAP;AAAS,OAAIC,IAAE,KAAK6J,EAAL,GAAQ9J,CAAd;AAAA,MAAgBD,IAAG,KAAKgC,CAAL,GAAO,CAAR,GAAW/B,IAAE,CAAb,GAAe,CAAjC,CAAmC,IAAG,KAAK6B,CAAL,GAAO,CAAV,EAAY;AAAC,QAAG5B,KAAG,CAAN,EAAQ;AAACF,UAAE,KAAK,CAAL,IAAQC,CAAV;AAAY,KAArB,MAAyB;AAAC,WAAI,IAAIQ,IAAE,KAAKqB,CAAL,GAAO,CAAjB,EAAmBrB,KAAG,CAAtB,EAAwB,EAAEA,CAA1B,EAA4B;AAACT,YAAE,CAACE,IAAEF,CAAF,GAAI,KAAKS,CAAL,CAAL,IAAcR,CAAhB;AAAkB;AAAC;AAAC,UAAOD,CAAP;AAAS,UAAS+T,YAAT,CAAsBtU,CAAtB,EAAwB;AAAC,MAAIW,IAAEX,EAAEiP,MAAF,EAAN,CAAiB,IAAI,KAAKA,MAAL,MAAetO,CAAhB,IAAoBX,EAAE8P,MAAF,MAAY,CAAnC,EAAqC;AAAC,WAAOnG,WAAW2B,IAAlB;AAAuB,OAAI1K,IAAEZ,EAAE+B,KAAF,EAAN;AAAA,MAAgBhC,IAAE,KAAKgC,KAAL,EAAlB,CAA+B,IAAIjC,IAAEoL,IAAI,CAAJ,CAAN;AAAA,MAAa1K,IAAE0K,IAAI,CAAJ,CAAf;AAAA,MAAsBpK,IAAEoK,IAAI,CAAJ,CAAxB;AAAA,MAA+BnK,IAAEmK,IAAI,CAAJ,CAAjC,CAAwC,OAAMtK,EAAEkP,MAAF,MAAY,CAAlB,EAAoB;AAAC,WAAMlP,EAAEqO,MAAF,EAAN,EAAiB;AAACrO,QAAEoM,QAAF,CAAW,CAAX,EAAapM,CAAb,EAAgB,IAAGD,CAAH,EAAK;AAAC,YAAG,CAACb,EAAEmP,MAAF,EAAD,IAAa,CAACzO,EAAEyO,MAAF,EAAjB,EAA4B;AAACnP,YAAEwS,KAAF,CAAQ,IAAR,EAAaxS,CAAb,EAAgBU,EAAE+K,KAAF,CAAQvL,CAAR,EAAUQ,CAAV;AAAa,WAAEwM,QAAF,CAAW,CAAX,EAAalN,CAAb;AAAgB,OAAhF,MAAoF;AAAC,YAAG,CAACU,EAAEyO,MAAF,EAAJ,EAAe;AAACzO,YAAE+K,KAAF,CAAQvL,CAAR,EAAUQ,CAAV;AAAa;AAAC,SAAEwM,QAAF,CAAW,CAAX,EAAaxM,CAAb;AAAgB,YAAMT,EAAEkP,MAAF,EAAN,EAAiB;AAAClP,QAAEiN,QAAF,CAAW,CAAX,EAAajN,CAAb,EAAgB,IAAGY,CAAH,EAAK;AAAC,YAAG,CAACG,EAAEmO,MAAF,EAAD,IAAa,CAAClO,EAAEkO,MAAF,EAAjB,EAA4B;AAACnO,YAAEwR,KAAF,CAAQ,IAAR,EAAaxR,CAAb,EAAgBC,EAAEwK,KAAF,CAAQvL,CAAR,EAAUe,CAAV;AAAa,WAAEiM,QAAF,CAAW,CAAX,EAAalM,CAAb;AAAgB,OAAhF,MAAoF;AAAC,YAAG,CAACC,EAAEkO,MAAF,EAAJ,EAAe;AAAClO,YAAEwK,KAAF,CAAQvL,CAAR,EAAUe,CAAV;AAAa;AAAC,SAAEiM,QAAF,CAAW,CAAX,EAAajM,CAAb;AAAgB,SAAGH,EAAEiM,SAAF,CAAY9M,CAAZ,KAAgB,CAAnB,EAAqB;AAACa,QAAE2K,KAAF,CAAQxL,CAAR,EAAUa,CAAV,EAAa,IAAGD,CAAH,EAAK;AAACb,UAAEyL,KAAF,CAAQzK,CAAR,EAAUhB,CAAV;AAAa,SAAEyL,KAAF,CAAQxK,CAAR,EAAUP,CAAV;AAAa,KAAnE,MAAuE;AAACT,QAAEwL,KAAF,CAAQ3K,CAAR,EAAUb,CAAV,EAAa,IAAGY,CAAH,EAAK;AAACG,UAAEyK,KAAF,CAAQzL,CAAR,EAAUgB,CAAV;AAAa,SAAEyK,KAAF,CAAQ/K,CAAR,EAAUO,CAAV;AAAa;AAAC,OAAGhB,EAAE8M,SAAF,CAAYlD,WAAWmD,GAAvB,KAA6B,CAAhC,EAAkC;AAAC,WAAOnD,WAAW2B,IAAlB;AAAuB,OAAGvK,EAAE8L,SAAF,CAAY7M,CAAZ,KAAgB,CAAnB,EAAqB;AAAC,WAAOe,EAAEwT,QAAF,CAAWvU,CAAX,CAAP;AAAqB,OAAGe,EAAE+O,MAAF,KAAW,CAAd,EAAgB;AAAC/O,MAAEuR,KAAF,CAAQtS,CAAR,EAAUe,CAAV;AAAa,GAA9B,MAAkC;AAAC,WAAOA,CAAP;AAAS,OAAGA,EAAE+O,MAAF,KAAW,CAAd,EAAgB;AAAC,WAAO/O,EAAEyT,GAAF,CAAMxU,CAAN,CAAP;AAAgB,GAAjC,MAAqC;AAAC,WAAOe,CAAP;AAAS;AAAC,KAAI0T,YAAU,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,EAAO,CAAP,EAAS,EAAT,EAAY,EAAZ,EAAe,EAAf,EAAkB,EAAlB,EAAqB,EAArB,EAAwB,EAAxB,EAA2B,EAA3B,EAA8B,EAA9B,EAAiC,EAAjC,EAAoC,EAApC,EAAuC,EAAvC,EAA0C,EAA1C,EAA6C,EAA7C,EAAgD,EAAhD,EAAmD,EAAnD,EAAsD,EAAtD,EAAyD,EAAzD,EAA4D,EAA5D,EAA+D,EAA/D,EAAkE,EAAlE,EAAqE,EAArE,EAAwE,GAAxE,EAA4E,GAA5E,EAAgF,GAAhF,EAAoF,GAApF,EAAwF,GAAxF,EAA4F,GAA5F,EAAgG,GAAhG,EAAoG,GAApG,EAAwG,GAAxG,EAA4G,GAA5G,EAAgH,GAAhH,EAAoH,GAApH,EAAwH,GAAxH,EAA4H,GAA5H,EAAgI,GAAhI,EAAoI,GAApI,EAAwI,GAAxI,EAA4I,GAA5I,EAAgJ,GAAhJ,EAAoJ,GAApJ,EAAwJ,GAAxJ,EAA4J,GAA5J,EAAgK,GAAhK,EAAoK,GAApK,EAAwK,GAAxK,EAA4K,GAA5K,EAAgL,GAAhL,EAAoL,GAApL,EAAwL,GAAxL,EAA4L,GAA5L,EAAgM,GAAhM,EAAoM,GAApM,EAAwM,GAAxM,EAA4M,GAA5M,EAAgN,GAAhN,EAAoN,GAApN,EAAwN,GAAxN,EAA4N,GAA5N,EAAgO,GAAhO,EAAoO,GAApO,EAAwO,GAAxO,EAA4O,GAA5O,EAAgP,GAAhP,EAAoP,GAApP,EAAwP,GAAxP,EAA4P,GAA5P,EAAgQ,GAAhQ,EAAoQ,GAApQ,EAAwQ,GAAxQ,EAA4Q,GAA5Q,EAAgR,GAAhR,EAAoR,GAApR,EAAwR,GAAxR,EAA4R,GAA5R,EAAgS,GAAhS,EAAoS,GAApS,EAAwS,GAAxS,EAA4S,GAA5S,EAAgT,GAAhT,EAAoT,GAApT,EAAwT,GAAxT,EAA4T,GAA5T,EAAgU,GAAhU,EAAoU,GAApU,EAAwU,GAAxU,EAA4U,GAA5U,EAAgV,GAAhV,EAAoV,GAApV,EAAwV,GAAxV,EAA4V,GAA5V,EAAgW,GAAhW,EAAoW,GAApW,EAAwW,GAAxW,EAA4W,GAA5W,EAAgX,GAAhX,EAAoX,GAApX,EAAwX,GAAxX,EAA4X,GAA5X,EAAgY,GAAhY,EAAoY,GAApY,EAAwY,GAAxY,EAA4Y,GAA5Y,EAAgZ,GAAhZ,EAAoZ,GAApZ,EAAwZ,GAAxZ,EAA4Z,GAA5Z,EAAga,GAAha,EAAoa,GAApa,EAAwa,GAAxa,EAA4a,GAA5a,EAAgb,GAAhb,EAAob,GAApb,EAAwb,GAAxb,EAA4b,GAA5b,EAAgc,GAAhc,EAAoc,GAApc,EAAwc,GAAxc,EAA4c,GAA5c,EAAgd,GAAhd,EAAod,GAApd,EAAwd,GAAxd,EAA4d,GAA5d,EAAge,GAAhe,EAAoe,GAApe,EAAwe,GAAxe,EAA4e,GAA5e,EAAgf,GAAhf,EAAof,GAApf,EAAwf,GAAxf,EAA4f,GAA5f,EAAggB,GAAhgB,EAAogB,GAApgB,EAAwgB,GAAxgB,EAA4gB,GAA5gB,EAAghB,GAAhhB,EAAohB,GAAphB,EAAwhB,GAAxhB,EAA4hB,GAA5hB,EAAgiB,GAAhiB,EAAoiB,GAApiB,EAAwiB,GAAxiB,EAA4iB,GAA5iB,EAAgjB,GAAhjB,EAAojB,GAApjB,EAAwjB,GAAxjB,EAA4jB,GAA5jB,EAAgkB,GAAhkB,EAAokB,GAApkB,EAAwkB,GAAxkB,EAA4kB,GAA5kB,EAAglB,GAAhlB,EAAolB,GAAplB,EAAwlB,GAAxlB,EAA4lB,GAA5lB,EAAgmB,GAAhmB,EAAomB,GAApmB,EAAwmB,GAAxmB,EAA4mB,GAA5mB,EAAgnB,GAAhnB,EAAonB,GAApnB,EAAwnB,GAAxnB,EAA4nB,GAA5nB,EAAgoB,GAAhoB,CAAd,CAAmpB,IAAIC,QAAM,CAAC,KAAG,EAAJ,IAAQD,UAAUA,UAAU5T,MAAV,GAAiB,CAA3B,CAAlB,CAAgD,SAAS8T,iBAAT,CAA2BnU,CAA3B,EAA6B;AAAC,MAAIN,CAAJ;AAAA,MAAMK,IAAE,KAAKgM,GAAL,EAAR,CAAmB,IAAGhM,EAAE8B,CAAF,IAAK,CAAL,IAAQ9B,EAAE,CAAF,KAAMkU,UAAUA,UAAU5T,MAAV,GAAiB,CAA3B,CAAjB,EAA+C;AAAC,SAAIX,IAAE,CAAN,EAAQA,IAAEuU,UAAU5T,MAApB,EAA2B,EAAEX,CAA7B,EAA+B;AAAC,UAAGK,EAAE,CAAF,KAAMkU,UAAUvU,CAAV,CAAT,EAAsB;AAAC,eAAO,IAAP;AAAY;AAAC,YAAO,KAAP;AAAa,OAAGK,EAAE0O,MAAF,EAAH,EAAc;AAAC,WAAO,KAAP;AAAa,OAAE,CAAF,CAAI,OAAM/O,IAAEuU,UAAU5T,MAAlB,EAAyB;AAAC,QAAIG,IAAEyT,UAAUvU,CAAV,CAAN;AAAA,QAAmBO,IAAEP,IAAE,CAAvB,CAAyB,OAAMO,IAAEgU,UAAU5T,MAAZ,IAAoBG,IAAE0T,KAA5B,EAAkC;AAAC1T,WAAGyT,UAAUhU,GAAV,CAAH;AAAkB,SAAEF,EAAEqU,MAAF,CAAS5T,CAAT,CAAF,CAAc,OAAMd,IAAEO,CAAR,EAAU;AAAC,UAAGO,IAAEyT,UAAUvU,GAAV,CAAF,IAAkB,CAArB,EAAuB;AAAC,eAAO,KAAP;AAAa;AAAC;AAAC,UAAOK,EAAEsU,WAAF,CAAcrU,CAAd,CAAP;AAAwB,UAASsU,cAAT,CAAwB9U,CAAxB,EAA0B;AAAC,MAAIF,IAAE,KAAKyU,QAAL,CAAc5K,WAAWmD,GAAzB,CAAN,CAAoC,IAAIrM,IAAEX,EAAEsU,eAAF,EAAN,CAA0B,IAAG3T,KAAG,CAAN,EAAQ;AAAC,WAAO,KAAP;AAAa,OAAIV,IAAED,EAAEiV,UAAF,CAAatU,CAAb,CAAN,CAAsBT,IAAGA,IAAE,CAAH,IAAO,CAAT,CAAW,IAAGA,IAAEyU,UAAU5T,MAAf,EAAsB;AAACb,QAAEyU,UAAU5T,MAAZ;AAAmB,OAAIN,IAAEuJ,KAAN,CAAY,KAAI,IAAItJ,IAAE,CAAV,EAAYA,IAAER,CAAd,EAAgB,EAAEQ,CAAlB,EAAoB;AAACD,MAAE4K,OAAF,CAAUsJ,UAAUhP,KAAKc,KAAL,CAAWd,KAAK5C,MAAL,KAAc4R,UAAU5T,MAAnC,CAAV,CAAV,EAAiE,IAAIC,IAAEP,EAAEyU,MAAF,CAASjV,CAAT,EAAW,IAAX,CAAN,CAAuB,IAAGe,EAAE+L,SAAF,CAAYlD,WAAWmD,GAAvB,KAA6B,CAA7B,IAAgChM,EAAE+L,SAAF,CAAY/M,CAAZ,KAAgB,CAAnD,EAAqD;AAAC,UAAII,IAAE,CAAN,CAAQ,OAAMA,MAAIO,CAAJ,IAAOK,EAAE+L,SAAF,CAAY/M,CAAZ,KAAgB,CAA7B,EAA+B;AAACgB,YAAEA,EAAEsO,SAAF,CAAY,CAAZ,EAAc,IAAd,CAAF,CAAsB,IAAGtO,EAAE+L,SAAF,CAAYlD,WAAWmD,GAAvB,KAA6B,CAAhC,EAAkC;AAAC,iBAAO,KAAP;AAAa;AAAC,WAAGhM,EAAE+L,SAAF,CAAY/M,CAAZ,KAAgB,CAAnB,EAAqB;AAAC,eAAO,KAAP;AAAa;AAAC;AAAC,UAAO,IAAP;AAAY,YAAWK,SAAX,CAAqB4P,SAArB,GAA+BN,YAA/B,CAA4C9F,WAAWxJ,SAAX,CAAqBwL,OAArB,GAA6BkE,UAA7B,CAAwClG,WAAWxJ,SAAX,CAAqBkL,SAArB,GAA+B4E,YAA/B,CAA4CtG,WAAWxJ,SAAX,CAAqByJ,UAArB,GAAgCwG,aAAhC,CAA8CzG,WAAWxJ,SAAX,CAAqBmQ,SAArB,GAA+BS,YAA/B,CAA4CpH,WAAWxJ,SAAX,CAAqB8R,SAArB,GAA+BF,YAA/B,CAA4CpI,WAAWxJ,SAAX,CAAqBmS,KAArB,GAA2BF,QAA3B,CAAoCzI,WAAWxJ,SAAX,CAAqB+P,SAArB,GAA+B2C,YAA/B,CAA4ClJ,WAAWxJ,SAAX,CAAqBgQ,UAArB,GAAgC2C,aAAhC,CAA8CnJ,WAAWxJ,SAAX,CAAqB4T,eAArB,GAAqCX,kBAArC,CAAwDzJ,WAAWxJ,SAAX,CAAqB2T,eAArB,GAAqCT,kBAArC,CAAwD1J,WAAWxJ,SAAX,CAAqByU,MAArB,GAA4BP,SAA5B,CAAsC1K,WAAWxJ,SAAX,CAAqB0U,WAArB,GAAiCC,cAAjC,CAAgDnL,WAAWxJ,SAAX,CAAqB4B,KAArB,GAA2BsN,OAA3B,CAAmC1F,WAAWxJ,SAAX,CAAqB6P,QAArB,GAA8BV,UAA9B,CAAyC3F,WAAWxJ,SAAX,CAAqB8U,SAArB,GAA+B1F,WAA/B,CAA2C5F,WAAWxJ,SAAX,CAAqB+U,UAArB,GAAgC1F,YAAhC,CAA6C7F,WAAWxJ,SAAX,CAAqB2P,MAArB,GAA4BF,QAA5B,CAAqCjG,WAAWxJ,SAAX,CAAqBgV,WAArB,GAAiCxE,aAAjC,CAA+ChH,WAAWxJ,SAAX,CAAqBiV,MAArB,GAA4BxE,QAA5B,CAAqCjH,WAAWxJ,SAAX,CAAqByE,GAArB,GAAyBiM,KAAzB,CAA+BlH,WAAWxJ,SAAX,CAAqBuE,GAArB,GAAyBoM,KAAzB,CAA+BnH,WAAWxJ,SAAX,CAAqBkV,GAArB,GAAyBpE,KAAzB,CAA+BtH,WAAWxJ,SAAX,CAAqBmV,EAArB,GAAwBpE,IAAxB,CAA6BvH,WAAWxJ,SAAX,CAAqBoV,GAArB,GAAyBnE,KAAzB,CAA+BzH,WAAWxJ,SAAX,CAAqBqV,MAArB,GAA4BlE,QAA5B,CAAqC3H,WAAWxJ,SAAX,CAAqBsV,GAArB,GAAyBlE,KAAzB,CAA+B5H,WAAWxJ,SAAX,CAAqBoQ,SAArB,GAA+BiB,WAA/B,CAA2C7H,WAAWxJ,SAAX,CAAqB4U,UAArB,GAAgCtD,YAAhC,CAA6C9H,WAAWxJ,SAAX,CAAqBiU,eAArB,GAAqCzC,iBAArC,CAAuDhI,WAAWxJ,SAAX,CAAqBuV,QAArB,GAA8B7D,UAA9B,CAAyClI,WAAWxJ,SAAX,CAAqBkQ,OAArB,GAA6ByB,SAA7B,CAAuCnI,WAAWxJ,SAAX,CAAqBwV,MAArB,GAA4B3D,QAA5B,CAAqCrI,WAAWxJ,SAAX,CAAqByV,QAArB,GAA8B1D,UAA9B,CAAyCvI,WAAWxJ,SAAX,CAAqB0V,OAArB,GAA6B1D,SAA7B,CAAuCxI,WAAWxJ,SAAX,CAAqBqU,GAArB,GAAyBnC,KAAzB,CAA+B1I,WAAWxJ,SAAX,CAAqBoU,QAArB,GAA8BhC,UAA9B,CAAyC5I,WAAWxJ,SAAX,CAAqB2V,QAArB,GAA8BtD,UAA9B,CAAyC7I,WAAWxJ,SAAX,CAAqBuT,MAArB,GAA4BhB,QAA5B,CAAqC/I,WAAWxJ,SAAX,CAAqB4V,SAArB,GAA+BpD,WAA/B,CAA2ChJ,WAAWxJ,SAAX,CAAqB6V,kBAArB,GAAwCpD,oBAAxC,CAA6DjJ,WAAWxJ,SAAX,CAAqB6U,MAArB,GAA4Bd,QAA5B,CAAqCvK,WAAWxJ,SAAX,CAAqB8V,UAArB,GAAgC3B,YAAhC,CAA6C3K,WAAWxJ,SAAX,CAAqBiG,GAArB,GAAyB+M,KAAzB,CAA+BxJ,WAAWxJ,SAAX,CAAqB+V,GAArB,GAAyB/B,KAAzB,CAA+BxK,WAAWxJ,SAAX,CAAqBsQ,eAArB,GAAqCkE,iBAArC,CAAuDhL,WAAWxJ,SAAX,CAAqBgW,MAArB,GAA4B1D,QAA5B;AACrgZ;;AAEA,SAAS2D,OAAT,GAAkB;AAAC,OAAKxV,CAAL,GAAO,CAAP,CAAS,KAAKD,CAAL,GAAO,CAAP,CAAS,KAAK2H,CAAL,GAAO,IAAIiB,KAAJ,EAAP;AAAmB,UAAS8M,QAAT,CAAkBnW,CAAlB,EAAoB;AAAC,MAAIO,CAAJ,EAAMO,CAAN,EAAQT,CAAR,CAAU,KAAIE,IAAE,CAAN,EAAQA,IAAE,GAAV,EAAc,EAAEA,CAAhB,EAAkB;AAAC,SAAK6H,CAAL,CAAO7H,CAAP,IAAUA,CAAV;AAAY,OAAE,CAAF,CAAI,KAAIA,IAAE,CAAN,EAAQA,IAAE,GAAV,EAAc,EAAEA,CAAhB,EAAkB;AAACO,QAAGA,IAAE,KAAKsH,CAAL,CAAO7H,CAAP,CAAF,GAAYP,EAAEO,IAAEP,EAAEW,MAAN,CAAb,GAA4B,GAA9B,CAAkCN,IAAE,KAAK+H,CAAL,CAAO7H,CAAP,CAAF,CAAY,KAAK6H,CAAL,CAAO7H,CAAP,IAAU,KAAK6H,CAAL,CAAOtH,CAAP,CAAV,CAAoB,KAAKsH,CAAL,CAAOtH,CAAP,IAAUT,CAAV;AAAY,QAAKK,CAAL,GAAO,CAAP,CAAS,KAAKD,CAAL,GAAO,CAAP;AAAS,UAAS2V,QAAT,GAAmB;AAAC,MAAItV,CAAJ,CAAM,KAAKJ,CAAL,GAAQ,KAAKA,CAAL,GAAO,CAAR,GAAW,GAAlB,CAAsB,KAAKD,CAAL,GAAQ,KAAKA,CAAL,GAAO,KAAK2H,CAAL,CAAO,KAAK1H,CAAZ,CAAR,GAAwB,GAA/B,CAAmCI,IAAE,KAAKsH,CAAL,CAAO,KAAK1H,CAAZ,CAAF,CAAiB,KAAK0H,CAAL,CAAO,KAAK1H,CAAZ,IAAe,KAAK0H,CAAL,CAAO,KAAK3H,CAAZ,CAAf,CAA8B,KAAK2H,CAAL,CAAO,KAAK3H,CAAZ,IAAeK,CAAf,CAAiB,OAAO,KAAKsH,CAAL,CAAQtH,IAAE,KAAKsH,CAAL,CAAO,KAAK1H,CAAZ,CAAH,GAAmB,GAA1B,CAAP;AAAsC,SAAQT,SAAR,CAAkBsB,IAAlB,GAAuB4U,QAAvB,CAAgCD,QAAQjW,SAAR,CAAkBoW,IAAlB,GAAuBD,QAAvB,CAAgC,SAASE,aAAT,GAAwB;AAAC,SAAO,IAAIJ,OAAJ,EAAP;AAAqB,KAAIK,YAAU,GAAd;AACphB;;AAEA,IAAIC,SAAJ,CAAc,IAAIC,QAAJ,CAAa,IAAIC,QAAJ,CAAa,SAASC,YAAT,CAAsB7V,CAAtB,EAAwB;AAAC2V,WAASC,UAAT,KAAsB5V,IAAE,GAAxB,CAA4B2V,SAASC,UAAT,KAAuB5V,KAAG,CAAJ,GAAO,GAA7B,CAAiC2V,SAASC,UAAT,KAAuB5V,KAAG,EAAJ,GAAQ,GAA9B,CAAkC2V,SAASC,UAAT,KAAuB5V,KAAG,EAAJ,GAAQ,GAA9B,CAAkC,IAAG4V,YAAUH,SAAb,EAAuB;AAACG,gBAAUH,SAAV;AAAoB;AAAC,UAASK,aAAT,GAAwB;AAACD,eAAa,IAAIE,IAAJ,GAAWC,OAAX,EAAb;AAAmC,KAAGL,YAAU,IAAb,EAAkB;AAACA,aAAS,IAAIpN,KAAJ,EAAT,CAAqBqN,WAAS,CAAT,CAAW,IAAIvU,CAAJ,CAAM,IAAG5C,WAASE,SAAT,KAAqBF,OAAOwX,MAAP,KAAgBtX,SAAhB,IAA2BF,OAAOyX,QAAP,KAAkBvX,SAAlE,CAAH,EAAgF;AAAC,QAAIsX,SAAOxX,OAAOwX,MAAP,IAAexX,OAAOyX,QAAjC,CAA0C,IAAGD,OAAOE,eAAV,EAA0B;AAAC,UAAIC,KAAG,IAAIC,UAAJ,CAAe,EAAf,CAAP,CAA0BJ,OAAOE,eAAP,CAAuBC,EAAvB,EAA2B,KAAI/U,IAAE,CAAN,EAAQA,IAAE,EAAV,EAAa,EAAEA,CAAf,EAAiB;AAACsU,iBAASC,UAAT,IAAqBQ,GAAG/U,CAAH,CAArB;AAA2B;AAAC,KAA9H,MAAkI;AAAC,UAAG9C,UAAU2K,OAAV,IAAmB,UAAnB,IAA+B3K,UAAU+X,UAAV,GAAqB,GAAvD,EAA2D;AAAC,YAAIvP,IAAEtI,OAAOwX,MAAP,CAAcpU,MAAd,CAAqB,EAArB,CAAN,CAA+B,KAAIR,IAAE,CAAN,EAAQA,IAAE0F,EAAElH,MAAZ,EAAmB,EAAEwB,CAArB,EAAuB;AAACsU,mBAASC,UAAT,IAAqB7O,EAAEtE,UAAF,CAAapB,CAAb,IAAgB,GAArC;AAAyC;AAAC;AAAC;AAAC,UAAMuU,WAASH,SAAf,EAAyB;AAACpU,QAAEoD,KAAKc,KAAL,CAAW,QAAMd,KAAK5C,MAAL,EAAjB,CAAF,CAAkC8T,SAASC,UAAT,IAAqBvU,MAAI,CAAzB,CAA2BsU,SAASC,UAAT,IAAqBvU,IAAE,GAAvB;AAA2B,cAAS,CAAT,CAAWyU;AAAgB,UAASS,YAAT,GAAuB;AAAC,MAAGb,aAAW,IAAd,EAAmB;AAACI,oBAAgBJ,YAAUF,eAAV,CAA0BE,UAAUjV,IAAV,CAAekV,QAAf,EAAyB,KAAIC,WAAS,CAAb,EAAeA,WAASD,SAAS9V,MAAjC,EAAwC,EAAE+V,QAA1C,EAAmD;AAACD,eAASC,QAAT,IAAmB,CAAnB;AAAqB,gBAAS,CAAT;AAAW,UAAOF,UAAUH,IAAV,EAAP;AAAwB,UAASiB,aAAT,CAAuBjX,CAAvB,EAAyB;AAAC,MAAIS,CAAJ,CAAM,KAAIA,IAAE,CAAN,EAAQA,IAAET,EAAEM,MAAZ,EAAmB,EAAEG,CAArB,EAAuB;AAACT,MAAES,CAAF,IAAKuW,cAAL;AAAoB;AAAC,UAASE,YAAT,GAAuB,CAAE,cAAatX,SAAb,CAAuBuQ,SAAvB,GAAiC8G,aAAjC;AAC/sC;;AAEA,SAASE,WAAT,CAAqBnX,CAArB,EAAuBS,CAAvB,EAAyB;AAAC,SAAO,IAAI2I,UAAJ,CAAepJ,CAAf,EAAiBS,CAAjB,CAAP;AAA2B,UAAS2W,OAAT,CAAiBlX,CAAjB,EAAmBP,CAAnB,EAAqB;AAAC,MAAIc,IAAE,EAAN,CAAS,IAAIT,IAAE,CAAN,CAAQ,OAAMA,IAAEL,CAAF,GAAIO,EAAEI,MAAZ,EAAmB;AAACG,SAAGP,EAAE0I,SAAF,CAAY5I,CAAZ,EAAcA,IAAEL,CAAhB,IAAmB,IAAtB,CAA2BK,KAAGL,CAAH;AAAK,UAAOc,IAAEP,EAAE0I,SAAF,CAAY5I,CAAZ,EAAcE,EAAEI,MAAhB,CAAT;AAAiC,UAAS+W,QAAT,CAAkB5W,CAAlB,EAAoB;AAAC,MAAGA,IAAE,EAAL,EAAQ;AAAC,WAAM,MAAIA,EAAEc,QAAF,CAAW,EAAX,CAAV;AAAyB,GAAlC,MAAsC;AAAC,WAAOd,EAAEc,QAAF,CAAW,EAAX,CAAP;AAAsB;AAAC,UAAS+V,SAAT,CAAmBrX,CAAnB,EAAqBT,CAArB,EAAuB;AAAC,MAAGA,IAAES,EAAEK,MAAF,GAAS,EAAd,EAAiB;AAAC,UAAK,0BAAL,CAAgC,OAAO,IAAP;AAAY,OAAIf,IAAE,IAAIyJ,KAAJ,EAAN,CAAkB,IAAIrJ,IAAEM,EAAEK,MAAF,GAAS,CAAf,CAAiB,OAAMX,KAAG,CAAH,IAAMH,IAAE,CAAd,EAAgB;AAAC,QAAIC,IAAEQ,EAAEiD,UAAF,CAAavD,GAAb,CAAN,CAAwB,IAAGF,IAAE,GAAL,EAAS;AAACF,QAAE,EAAEC,CAAJ,IAAOC,CAAP;AAAS,KAAnB,MAAuB;AAAC,UAAIA,IAAE,GAAH,IAAUA,IAAE,IAAf,EAAqB;AAACF,UAAE,EAAEC,CAAJ,IAAQC,IAAE,EAAH,GAAO,GAAd,CAAkBF,EAAE,EAAEC,CAAJ,IAAQC,KAAG,CAAJ,GAAO,GAAd;AAAkB,OAA1D,MAA8D;AAACF,UAAE,EAAEC,CAAJ,IAAQC,IAAE,EAAH,GAAO,GAAd,CAAkBF,EAAE,EAAEC,CAAJ,IAASC,KAAG,CAAJ,GAAO,EAAR,GAAY,GAAnB,CAAuBF,EAAE,EAAEC,CAAJ,IAAQC,KAAG,EAAJ,GAAQ,GAAf;AAAmB;AAAC;AAAC,KAAE,EAAED,CAAJ,IAAO,CAAP,CAAS,IAAIQ,IAAE,IAAIkX,YAAJ,EAAN,CAAyB,IAAIzW,IAAE,IAAIuI,KAAJ,EAAN,CAAkB,OAAMxJ,IAAE,CAAR,EAAU;AAACiB,MAAE,CAAF,IAAK,CAAL,CAAO,OAAMA,EAAE,CAAF,KAAM,CAAZ,EAAc;AAACT,QAAEmQ,SAAF,CAAY1P,CAAZ;AAAe,OAAE,EAAEjB,CAAJ,IAAOiB,EAAE,CAAF,CAAP;AAAY,KAAE,EAAEjB,CAAJ,IAAO,CAAP,CAASD,EAAE,EAAEC,CAAJ,IAAO,CAAP,CAAS,OAAO,IAAI4J,UAAJ,CAAe7J,CAAf,CAAP;AAAyB,UAASgY,aAAT,CAAuBrX,CAAvB,EAAyBO,CAAzB,EAA2BR,CAA3B,EAA6B;AAAC,MAAID,IAAE,EAAN;AAAA,MAASL,IAAE,CAAX,CAAa,OAAMK,EAAEM,MAAF,GAASG,CAAf,EAAiB;AAACT,SAAGC,EAAE+C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiC9C,EAAE2B,MAAF,CAAS,CAAC,CAAClC,IAAE,UAAH,KAAgB,EAAjB,EAAoB,CAACA,IAAE,QAAH,KAAc,EAAlC,EAAqC,CAACA,IAAE,KAAH,KAAW,CAAhD,EAAkDA,IAAE,GAApD,CAAT,CAAjC,CAAF,CAAH,CAA2GA,KAAG,CAAH;AAAK,UAAOK,CAAP;AAAS,UAASwX,QAAT,CAAkBzV,CAAlB,EAAoBtB,CAApB,EAAsBhB,CAAtB,EAAwBc,CAAxB,EAA0B;AAAC,MAAIL,IAAEuX,KAAKf,MAAL,CAAYgB,aAAlB,CAAgC,IAAI3W,IAAE0W,KAAKf,MAAL,CAAYiB,IAAlB,CAAuB,IAAI3X,IAAE,IAAN,CAAW,IAAG,CAACP,CAAJ,EAAM;AAACA,QAAE,MAAF;AAAS,OAAG,OAAOA,CAAP,KAAW,QAAd,EAAuB;AAACO,QAAEE,EAAE0X,mBAAF,CAAsBnY,CAAtB,CAAF,CAA2Bc,IAAEL,EAAE2X,aAAF,CAAgB7X,CAAhB,CAAF,CAAqBP,IAAE,WAASY,CAAT,EAAW;AAAC,aAAOyX,UAAU/W,EAAEgX,OAAF,CAAUC,UAAU3X,CAAV,CAAV,EAAuBL,CAAvB,CAAV,CAAP;AAA4C,KAA1D;AAA2D,OAAG+B,EAAEzB,MAAF,GAAS,IAAEC,CAAX,GAAa,CAAb,GAAeE,CAAlB,EAAoB;AAAC,UAAK,0BAAL;AAAgC,OAAID,IAAE,EAAN;AAAA,MAASP,CAAT,CAAW,KAAIA,IAAE,CAAN,EAAQA,IAAEQ,IAAEsB,EAAEzB,MAAJ,GAAW,IAAEC,CAAb,GAAe,CAAzB,EAA2BN,KAAG,CAA9B,EAAgC;AAACO,SAAG,MAAH;AAAU,OAAIhB,IAAEC,EAAE,EAAF,IAAMe,CAAN,GAAQ,MAAR,GAAeuB,CAArB,CAAuB,IAAIxC,IAAE,IAAIyJ,KAAJ,CAAUzI,CAAV,CAAN,CAAmB,IAAI2W,YAAJ,GAAmB/G,SAAnB,CAA6B5Q,CAA7B,EAAgC,IAAIa,IAAEmX,cAAchY,CAAd,EAAgBC,EAAEc,MAAlB,EAAyBb,CAAzB,CAAN,CAAkC,IAAIqB,IAAE,EAAN,CAAS,KAAIb,IAAE,CAAN,EAAQA,IAAET,EAAEc,MAAZ,EAAmBL,KAAG,CAAtB,EAAwB;AAACa,MAAEb,CAAF,IAAKT,EAAE0D,UAAF,CAAajD,CAAb,IAAgBG,EAAE8C,UAAF,CAAajD,CAAb,CAArB;AAAqC,OAAIuC,IAAE+U,cAAczW,CAAd,EAAgBvB,EAAEe,MAAlB,EAAyBb,CAAzB,CAAN,CAAkC,IAAIE,IAAE,CAAC,CAAD,CAAN,CAAU,KAAIM,IAAE,CAAN,EAAQA,IAAEV,EAAEe,MAAZ,EAAmBL,KAAG,CAAtB,EAAwB;AAACN,MAAEM,IAAE,CAAJ,IAAOV,EAAEU,CAAF,IAAKuC,EAAEU,UAAF,CAAajD,CAAb,CAAZ;AAA4B,UAAO,IAAImJ,UAAJ,CAAezJ,EAAEkC,MAAF,CAASf,CAAT,CAAf,CAAP;AAAmC,UAASmX,MAAT,GAAiB;AAAC,OAAKpX,CAAL,GAAO,IAAP,CAAY,KAAKZ,CAAL,GAAO,CAAP,CAAS,KAAKN,CAAL,GAAO,IAAP,CAAY,KAAKmB,CAAL,GAAO,IAAP,CAAY,KAAKiB,CAAL,GAAO,IAAP,CAAY,KAAKmW,IAAL,GAAU,IAAV,CAAe,KAAKC,IAAL,GAAU,IAAV,CAAe,KAAKC,KAAL,GAAW,IAAX;AAAgB,UAASC,YAAT,CAAsBrY,CAAtB,EAAwBS,CAAxB,EAA0B;AAAC,OAAK6X,QAAL,GAAc,IAAd,CAAmB,KAAKC,SAAL,GAAe,KAAf,CAAqB,IAAG,OAAOvY,CAAP,KAAW,QAAd,EAAuB;AAAC,SAAKa,CAAL,GAAOb,CAAP,CAAS,KAAKC,CAAL,GAAOQ,CAAP;AAAS,GAA1C,MAA8C;AAAC,QAAGT,KAAG,IAAH,IAASS,KAAG,IAAZ,IAAkBT,EAAEM,MAAF,GAAS,CAA3B,IAA8BG,EAAEH,MAAF,GAAS,CAA1C,EAA4C;AAAC,WAAKO,CAAL,GAAOsW,YAAYnX,CAAZ,EAAc,EAAd,CAAP,CAAyB,KAAKC,CAAL,GAAO4C,SAASpC,CAAT,EAAW,EAAX,CAAP;AAAsB,KAA5F,MAAgG;AAAC,YAAK,wBAAL;AAA8B;AAAC;AAAC,UAAS+X,WAAT,CAAqB/X,CAArB,EAAuB;AAAC,SAAOA,EAAEoO,SAAF,CAAY,KAAK5O,CAAjB,EAAmB,KAAKY,CAAxB,CAAP;AAAkC,UAAS4X,UAAT,CAAoB9Y,CAApB,EAAsB;AAAC,MAAIc,IAAE6W,UAAU3X,CAAV,EAAa,KAAKkB,CAAL,CAAO+N,SAAP,KAAmB,CAApB,IAAwB,CAApC,CAAN,CAA6C,IAAGnO,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAIR,IAAE,KAAKyY,QAAL,CAAcjY,CAAd,CAAN,CAAuB,IAAGR,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAID,IAAEC,EAAEsB,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG,CAACvB,EAAEM,MAAF,GAAS,CAAV,KAAc,CAAjB,EAAmB;AAAC,WAAON,CAAP;AAAS,GAA7B,MAAiC;AAAC,WAAM,MAAIA,CAAV;AAAY;AAAC,UAAS2Y,cAAT,CAAwBlZ,CAAxB,EAA0BQ,CAA1B,EAA4BD,CAA5B,EAA8B;AAAC,MAAIS,IAAE+W,SAAS/X,CAAT,EAAY,KAAKoB,CAAL,CAAO+N,SAAP,KAAmB,CAApB,IAAwB,CAAnC,EAAqC3O,CAArC,EAAuCD,CAAvC,CAAN,CAAgD,IAAGS,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAIlB,IAAE,KAAKmZ,QAAL,CAAcjY,CAAd,CAAN,CAAuB,IAAGlB,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAII,IAAEJ,EAAEgC,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG,CAAC5B,EAAEW,MAAF,GAAS,CAAV,KAAc,CAAjB,EAAmB;AAAC,WAAOX,CAAP;AAAS,GAA7B,MAAiC;AAAC,WAAM,MAAIA,CAAV;AAAY;AAAC,QAAOC,SAAP,CAAiB8Y,QAAjB,GAA0BF,WAA1B,CAAsCP,OAAOrY,SAAP,CAAiBgZ,SAAjB,GAA2BP,YAA3B,CAAwCJ,OAAOrY,SAAP,CAAiBiZ,OAAjB,GAAyBJ,UAAzB,CAAoCR,OAAOrY,SAAP,CAAiBkZ,WAAjB,GAA6BH,cAA7B,CAA4CV,OAAOrY,SAAP,CAAiBmZ,IAAjB,GAAsB,KAAtB;AAC3gF;;AAEA,SAASC,gBAAT,CAA0BhZ,CAA1B,EAA4BS,CAA5B,EAA8B;AAAC,OAAKsD,CAAL,GAAOtD,CAAP,CAAS,KAAKsB,CAAL,GAAO/B,CAAP;AAAS,UAASiZ,UAAT,CAAoBxY,CAApB,EAAsB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,UAAO,KAAKsB,CAAL,CAAO8S,MAAP,CAAcpU,EAAEsB,CAAhB,KAAoB,KAAKgC,CAAL,CAAO8Q,MAAP,CAAcpU,EAAEsD,CAAhB,CAA3B;AAA+C,UAASmV,gBAAT,GAA2B;AAAC,SAAO,KAAKnV,CAAZ;AAAc,UAASoV,UAAT,GAAqB;AAAC,SAAO,IAAIH,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOoH,MAAP,GAAgB2B,GAAhB,CAAoB,KAAK/K,CAAzB,CAA5B,CAAP;AAAgE,UAASqX,OAAT,CAAiB3Y,CAAjB,EAAmB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOkQ,GAAP,CAAWxT,EAAE4Y,YAAF,EAAX,EAA6BvM,GAA7B,CAAiC,KAAK/K,CAAtC,CAA5B,CAAP;AAA6E,UAASuX,YAAT,CAAsB7Y,CAAtB,EAAwB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOiQ,QAAP,CAAgBvT,EAAE4Y,YAAF,EAAhB,EAAkCvM,GAAlC,CAAsC,KAAK/K,CAA3C,CAA5B,CAAP;AAAkF,UAASwX,YAAT,CAAsB9Y,CAAtB,EAAwB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOwR,QAAP,CAAgB9U,EAAE4Y,YAAF,EAAhB,EAAkCvM,GAAlC,CAAsC,KAAK/K,CAA3C,CAA5B,CAAP;AAAkF,UAASyX,UAAT,GAAqB;AAAC,SAAO,IAAIR,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAO6R,MAAP,GAAgB9I,GAAhB,CAAoB,KAAK/K,CAAzB,CAA5B,CAAP;AAAgE,UAAS0X,UAAT,CAAoBhZ,CAApB,EAAsB;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4B,KAAKgC,CAAL,CAAOwR,QAAP,CAAgB9U,EAAE4Y,YAAF,GAAiB3D,UAAjB,CAA4B,KAAK3T,CAAjC,CAAhB,EAAqD+K,GAArD,CAAyD,KAAK/K,CAA9D,CAA5B,CAAP;AAAqG,kBAAiBnC,SAAjB,CAA2BiV,MAA3B,GAAkCoE,UAAlC,CAA6CD,iBAAiBpZ,SAAjB,CAA2ByZ,YAA3B,GAAwCH,gBAAxC,CAAyDF,iBAAiBpZ,SAAjB,CAA2BuL,MAA3B,GAAkCgO,UAAlC,CAA6CH,iBAAiBpZ,SAAjB,CAA2BqU,GAA3B,GAA+BmF,OAA/B,CAAuCJ,iBAAiBpZ,SAAjB,CAA2BoU,QAA3B,GAAoCsF,YAApC,CAAiDN,iBAAiBpZ,SAAjB,CAA2B2V,QAA3B,GAAoCgE,YAApC,CAAiDP,iBAAiBpZ,SAAjB,CAA2BgW,MAA3B,GAAkC4D,UAAlC,CAA6CR,iBAAiBpZ,SAAjB,CAA2BuT,MAA3B,GAAkCsG,UAAlC,CAA6C,SAASC,SAAT,CAAmBxZ,CAAnB,EAAqBO,CAArB,EAAuBd,CAAvB,EAAyBK,CAAzB,EAA2B;AAAC,OAAK2Z,KAAL,GAAWzZ,CAAX,CAAa,KAAK6D,CAAL,GAAOtD,CAAP,CAAS,KAAKiH,CAAL,GAAO/H,CAAP,CAAS,IAAGK,KAAG,IAAN,EAAW;AAAC,SAAKwH,CAAL,GAAO4B,WAAWmD,GAAlB;AAAsB,GAAlC,MAAsC;AAAC,SAAK/E,CAAL,GAAOxH,CAAP;AAAS,QAAK4Z,IAAL,GAAU,IAAV;AAAe,UAASC,WAAT,GAAsB;AAAC,MAAG,KAAKD,IAAL,IAAW,IAAd,EAAmB;AAAC,SAAKA,IAAL,GAAU,KAAKpS,CAAL,CAAOkO,UAAP,CAAkB,KAAKiE,KAAL,CAAW5X,CAA7B,CAAV;AAA0C,UAAO,KAAK4X,KAAL,CAAWG,cAAX,CAA0B,KAAK/V,CAAL,CAAOsV,YAAP,GAAsB9D,QAAtB,CAA+B,KAAKqE,IAApC,EAA0C9M,GAA1C,CAA8C,KAAK6M,KAAL,CAAW5X,CAAzD,CAA1B,CAAP;AAA8F,UAASgY,WAAT,GAAsB;AAAC,MAAG,KAAKH,IAAL,IAAW,IAAd,EAAmB;AAAC,SAAKA,IAAL,GAAU,KAAKpS,CAAL,CAAOkO,UAAP,CAAkB,KAAKiE,KAAL,CAAW5X,CAA7B,CAAV;AAA0C,UAAO,KAAK4X,KAAL,CAAWG,cAAX,CAA0B,KAAKpS,CAAL,CAAO2R,YAAP,GAAsB9D,QAAtB,CAA+B,KAAKqE,IAApC,EAA0C9M,GAA1C,CAA8C,KAAK6M,KAAL,CAAW5X,CAAzD,CAA1B,CAAP;AAA8F,UAASiY,aAAT,CAAuBvZ,CAAvB,EAAyB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKwZ,UAAL,EAAH,EAAqB;AAAC,WAAOxZ,EAAEwZ,UAAF,EAAP;AAAsB,OAAGxZ,EAAEwZ,UAAF,EAAH,EAAkB;AAAC,WAAO,KAAKA,UAAL,EAAP;AAAyB,OAAI/Z,CAAJ,EAAMF,CAAN,CAAQE,IAAEO,EAAEiH,CAAF,CAAI2R,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKtM,CAAL,CAAO2R,YAAP,GAAsB9D,QAAtB,CAA+B9U,EAAE+G,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAF,CAAsG,IAAG,CAAC7B,EAAE2U,MAAF,CAASzL,WAAW2B,IAApB,CAAJ,EAA8B;AAAC,WAAO,KAAP;AAAa,OAAEtK,EAAEsD,CAAF,CAAIsV,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKjQ,CAAL,CAAOsV,YAAP,GAAsB9D,QAAtB,CAA+B9U,EAAE+G,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAF,CAAsG,OAAO/B,EAAE6U,MAAF,CAASzL,WAAW2B,IAApB,CAAP;AAAiC,UAASmP,iBAAT,GAA4B;AAAC,MAAI,KAAKnW,CAAL,IAAQ,IAAT,IAAiB,KAAK2D,CAAL,IAAQ,IAA5B,EAAkC;AAAC,WAAO,IAAP;AAAY,UAAO,KAAKF,CAAL,CAAOqN,MAAP,CAAczL,WAAW2B,IAAzB,KAAgC,CAAC,KAAKrD,CAAL,CAAO2R,YAAP,GAAsBxE,MAAtB,CAA6BzL,WAAW2B,IAAxC,CAAxC;AAAsF,UAASoP,aAAT,GAAwB;AAAC,SAAO,IAAIT,SAAJ,CAAc,KAAKC,KAAnB,EAAyB,KAAK5V,CAA9B,EAAgC,KAAK2D,CAAL,CAAOyD,MAAP,EAAhC,EAAgD,KAAK3D,CAArD,CAAP;AAA+D,UAAS4S,UAAT,CAAoB7Z,CAApB,EAAsB;AAAC,MAAG,KAAK0Z,UAAL,EAAH,EAAqB;AAAC,WAAO1Z,CAAP;AAAS,OAAGA,EAAE0Z,UAAF,EAAH,EAAkB;AAAC,WAAO,IAAP;AAAY,OAAInZ,IAAEP,EAAEmH,CAAF,CAAI2R,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKtM,CAAL,CAAO2R,YAAP,GAAsB9D,QAAtB,CAA+BhV,EAAEiH,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAN,CAA0G,IAAIhB,IAAER,EAAEwD,CAAF,CAAIsV,YAAJ,GAAmB9D,QAAnB,CAA4B,KAAK/N,CAAjC,EAAoCwM,QAApC,CAA6C,KAAKjQ,CAAL,CAAOsV,YAAP,GAAsB9D,QAAtB,CAA+BhV,EAAEiH,CAAjC,CAA7C,EAAkFsF,GAAlF,CAAsF,KAAK6M,KAAL,CAAW5X,CAAjG,CAAN,CAA0G,IAAGqH,WAAW2B,IAAX,CAAgB8J,MAAhB,CAAuB9T,CAAvB,CAAH,EAA6B;AAAC,QAAGqI,WAAW2B,IAAX,CAAgB8J,MAAhB,CAAuB/T,CAAvB,CAAH,EAA6B;AAAC,aAAO,KAAKuZ,KAAL,EAAP;AAAoB,YAAO,KAAKV,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAIla,IAAE,IAAIgJ,UAAJ,CAAe,GAAf,CAAN,CAA0B,IAAInJ,IAAE,KAAK8D,CAAL,CAAOsV,YAAP,EAAN,CAA4B,IAAIxY,IAAE,KAAK6G,CAAL,CAAO2R,YAAP,EAAN,CAA4B,IAAInZ,IAAEK,EAAEwD,CAAF,CAAIsV,YAAJ,EAAN,CAAyB,IAAI7Y,IAAED,EAAEmH,CAAF,CAAI2R,YAAJ,EAAN,CAAyB,IAAI7W,IAAEzB,EAAE6U,MAAF,EAAN,CAAiB,IAAIvV,IAAEmC,EAAE+S,QAAF,CAAWxU,CAAX,CAAN,CAAoB,IAAIpB,IAAEM,EAAEsV,QAAF,CAAW/S,CAAX,CAAN,CAAoB,IAAIjD,IAAEuB,EAAE8U,MAAF,GAAWL,QAAX,CAAoB,KAAK/N,CAAzB,CAAN,CAAkC,IAAI/G,IAAElB,EAAEyU,QAAF,CAAWrU,EAAEqQ,SAAF,CAAY,CAAZ,CAAX,EAA2BuF,QAA3B,CAAoChV,EAAEiH,CAAtC,EAAyCwM,QAAzC,CAAkD3T,CAAlD,EAAqDkV,QAArD,CAA8DxU,CAA9D,EAAiE+L,GAAjE,CAAqE,KAAK6M,KAAL,CAAW5X,CAAhF,CAAN,CAAyF,IAAIvC,IAAEG,EAAE4V,QAAF,CAAWnV,CAAX,EAAcmV,QAAd,CAAuBzU,CAAvB,EAA0BkT,QAA1B,CAAmCnT,EAAE0U,QAAF,CAAWlV,CAAX,CAAnC,EAAkD2T,QAAlD,CAA2DzU,EAAEgW,QAAF,CAAWzU,CAAX,CAA3D,EAA0EyU,QAA1E,CAAmFhV,EAAEiH,CAArF,EAAwFyM,GAAxF,CAA4FnT,EAAEyU,QAAF,CAAWlV,CAAX,CAA5F,EAA2GyM,GAA3G,CAA+G,KAAK6M,KAAL,CAAW5X,CAA1H,CAAN,CAAmI,IAAItC,IAAEY,EAAEkV,QAAF,CAAW,KAAK/N,CAAhB,EAAmB+N,QAAnB,CAA4BhV,EAAEiH,CAA9B,EAAiCsF,GAAjC,CAAqC,KAAK6M,KAAL,CAAW5X,CAAhD,CAAN,CAAyD,OAAO,IAAI2X,SAAJ,CAAc,KAAKC,KAAnB,EAAyB,KAAKA,KAAL,CAAWG,cAAX,CAA0BrZ,CAA1B,CAAzB,EAAsD,KAAKkZ,KAAL,CAAWG,cAAX,CAA0Bta,CAA1B,CAAtD,EAAmFC,CAAnF,CAAP;AAA6F,UAAS8a,YAAT,GAAuB;AAAC,MAAG,KAAKN,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKvS,CAAL,CAAO2R,YAAP,GAAsB9J,MAAtB,MAAgC,CAAnC,EAAqC;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAE,IAAI6J,UAAJ,CAAe,GAAf,CAAN,CAA0B,IAAIlJ,IAAE,KAAK6D,CAAL,CAAOsV,YAAP,EAAN,CAA4B,IAAI7Z,IAAE,KAAKkI,CAAL,CAAO2R,YAAP,EAAN,CAA4B,IAAIpZ,IAAET,EAAE+V,QAAF,CAAW,KAAK/N,CAAhB,CAAN,CAAyB,IAAIpH,IAAEH,EAAEsV,QAAF,CAAW/V,CAAX,EAAcsN,GAAd,CAAkB,KAAK6M,KAAL,CAAW5X,CAA7B,CAAN,CAAsC,IAAI1B,IAAE,KAAKsZ,KAAL,CAAWlZ,CAAX,CAAa4Y,YAAb,EAAN,CAAkC,IAAI7Y,IAAEN,EAAE0V,MAAF,GAAWL,QAAX,CAAoBhW,CAApB,CAAN,CAA6B,IAAG,CAAC6J,WAAW2B,IAAX,CAAgB8J,MAAhB,CAAuBxU,CAAvB,CAAJ,EAA8B;AAACG,QAAEA,EAAEyT,GAAF,CAAM,KAAKzM,CAAL,CAAOoO,MAAP,GAAgBL,QAAhB,CAAyBlV,CAAzB,CAAN,CAAF;AAAqC,OAAEG,EAAEsM,GAAF,CAAM,KAAK6M,KAAL,CAAW5X,CAAjB,CAAF,CAAsB,IAAI/B,IAAEQ,EAAEoV,MAAF,GAAW5B,QAAX,CAAoB9T,EAAE8P,SAAF,CAAY,CAAZ,EAAeuF,QAAf,CAAwBnV,CAAxB,CAApB,EAAgD4P,SAAhD,CAA0D,CAA1D,EAA6DuF,QAA7D,CAAsEtV,CAAtE,EAAyE6M,GAAzE,CAA6E,KAAK6M,KAAL,CAAW5X,CAAxF,CAAN,CAAiG,IAAItC,IAAEe,EAAE+U,QAAF,CAAWhW,CAAX,EAAcgW,QAAd,CAAuBrV,CAAvB,EAA0B8T,QAA1B,CAAmC5T,EAAE4P,SAAF,CAAY,CAAZ,CAAnC,EAAmDA,SAAnD,CAA6D,CAA7D,EAAgEuF,QAAhE,CAAyEnV,CAAzE,EAA4E4T,QAA5E,CAAqFxT,EAAEoV,MAAF,GAAWL,QAAX,CAAoB/U,CAApB,CAArF,EAA6GsM,GAA7G,CAAiH,KAAK6M,KAAL,CAAW5X,CAA5H,CAAN,CAAqI,IAAIpC,IAAEM,EAAE2V,MAAF,GAAWL,QAAX,CAAoBtV,CAApB,EAAuB+P,SAAvB,CAAiC,CAAjC,EAAoClD,GAApC,CAAwC,KAAK6M,KAAL,CAAW5X,CAAnD,CAAN,CAA4D,OAAO,IAAI2X,SAAJ,CAAc,KAAKC,KAAnB,EAAyB,KAAKA,KAAL,CAAWG,cAAX,CAA0B9Z,CAA1B,CAAzB,EAAsD,KAAK2Z,KAAL,CAAWG,cAAX,CAA0Bra,CAA1B,CAAtD,EAAmFE,CAAnF,CAAP;AAA6F,UAAS6a,eAAT,CAAyBxa,CAAzB,EAA2B;AAAC,MAAG,KAAKia,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAGja,EAAEuP,MAAF,MAAY,CAAf,EAAiB;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAES,CAAN,CAAQ,IAAIP,IAAEF,EAAEgW,QAAF,CAAW,IAAInM,UAAJ,CAAe,GAAf,CAAX,CAAN,CAAsC,IAAI7I,IAAE,KAAK4K,MAAL,EAAN,CAAoB,IAAIxL,IAAE,IAAN,CAAW,IAAIO,CAAJ,CAAM,KAAIA,IAAET,EAAEmP,SAAF,KAAc,CAApB,EAAsB1O,IAAE,CAAxB,EAA0B,EAAEA,CAA5B,EAA8B;AAACP,QAAEA,EAAE0a,KAAF,EAAF,CAAY,IAAI5Z,IAAEhB,EAAEqQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAIE,IAAEb,EAAEuQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAGO,KAAGL,CAAN,EAAQ;AAACT,UAAEA,EAAEsU,GAAF,CAAMxT,IAAE,IAAF,GAAOF,CAAb,CAAF;AAAkB;AAAC,UAAOZ,CAAP;AAAS,UAAS8a,kBAAT,CAA4Bva,CAA5B,EAA8BO,CAA9B,EAAgCT,CAAhC,EAAkC;AAAC,MAAIL,CAAJ,CAAM,IAAGO,EAAE0O,SAAF,KAAc5O,EAAE4O,SAAF,EAAjB,EAA+B;AAACjP,QAAEO,EAAE0O,SAAF,KAAc,CAAhB;AAAkB,GAAlD,MAAsD;AAACjP,QAAEK,EAAE4O,SAAF,KAAc,CAAhB;AAAkB,OAAInP,IAAE,KAAKka,KAAL,CAAWW,WAAX,EAAN,CAA+B,IAAIra,IAAE,KAAKgU,GAAL,CAASxT,CAAT,CAAN,CAAkB,OAAMd,KAAG,CAAT,EAAW;AAACF,QAAEA,EAAE4a,KAAF,EAAF,CAAY,IAAGna,EAAE4P,OAAF,CAAUnQ,CAAV,CAAH,EAAgB;AAAC,UAAGK,EAAE8P,OAAF,CAAUnQ,CAAV,CAAH,EAAgB;AAACF,YAAEA,EAAEwU,GAAF,CAAMhU,CAAN,CAAF;AAAW,OAA5B,MAAgC;AAACR,YAAEA,EAAEwU,GAAF,CAAM,IAAN,CAAF;AAAc;AAAC,KAAjE,MAAqE;AAAC,UAAGjU,EAAE8P,OAAF,CAAUnQ,CAAV,CAAH,EAAgB;AAACF,YAAEA,EAAEwU,GAAF,CAAMxT,CAAN,CAAF;AAAW;AAAC,OAAEd,CAAF;AAAI,UAAOF,CAAP;AAAS,WAAUG,SAAV,CAAoB8a,IAApB,GAAyBb,WAAzB,CAAqCH,UAAU9Z,SAAV,CAAoB+a,IAApB,GAAyBZ,WAAzB,CAAqCL,UAAU9Z,SAAV,CAAoBiV,MAApB,GAA2BmF,aAA3B,CAAyCN,UAAU9Z,SAAV,CAAoBqa,UAApB,GAA+BC,iBAA/B,CAAiDR,UAAU9Z,SAAV,CAAoBuL,MAApB,GAA2BgP,aAA3B,CAAyCT,UAAU9Z,SAAV,CAAoBqU,GAApB,GAAwBmG,UAAxB,CAAmCV,UAAU9Z,SAAV,CAAoBya,KAApB,GAA0BE,YAA1B,CAAuCb,UAAU9Z,SAAV,CAAoB2V,QAApB,GAA6BiF,eAA7B,CAA6Cd,UAAU9Z,SAAV,CAAoBgb,WAApB,GAAgCH,kBAAhC,CAAmD,SAASI,SAAT,CAAmB5a,CAAnB,EAAqBN,CAArB,EAAuBO,CAAvB,EAAyB;AAAC,OAAK6B,CAAL,GAAO9B,CAAP,CAAS,KAAKQ,CAAL,GAAO,KAAKqZ,cAAL,CAAoBna,CAApB,CAAP,CAA8B,KAAKK,CAAL,GAAO,KAAK8Z,cAAL,CAAoB5Z,CAApB,CAAP,CAA8B,KAAK4a,QAAL,GAAc,IAAIpB,SAAJ,CAAc,IAAd,EAAmB,IAAnB,EAAwB,IAAxB,CAAd;AAA4C,UAASqB,WAAT,GAAsB;AAAC,SAAO,KAAKhZ,CAAZ;AAAc,UAASiZ,WAAT,GAAsB;AAAC,SAAO,KAAKva,CAAZ;AAAc,UAASwa,WAAT,GAAsB;AAAC,SAAO,KAAKjb,CAAZ;AAAc,UAASkb,aAAT,CAAuBza,CAAvB,EAAyB;AAAC,MAAGA,KAAG,IAAN,EAAW;AAAC,WAAO,IAAP;AAAY,UAAO,KAAKsB,CAAL,CAAO8S,MAAP,CAAcpU,EAAEsB,CAAhB,KAAoB,KAAKtB,CAAL,CAAOoU,MAAP,CAAcpU,EAAEA,CAAhB,CAApB,IAAwC,KAAKT,CAAL,CAAO6U,MAAP,CAAcpU,EAAET,CAAhB,CAA/C;AAAmE,UAASmb,kBAAT,GAA6B;AAAC,SAAO,KAAKL,QAAZ;AAAqB,UAASM,qBAAT,CAA+B3a,CAA/B,EAAiC;AAAC,SAAO,IAAIuY,gBAAJ,CAAqB,KAAKjX,CAA1B,EAA4BtB,CAA5B,CAAP;AAAsC,UAAS4a,qBAAT,CAA+B1b,CAA/B,EAAiC;AAAC,UAAOkD,SAASlD,EAAEmD,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAP,GAAmC,KAAK,CAAL;AAAO,aAAO,KAAKgY,QAAZ,CAAqB,KAAK,CAAL,CAAO,KAAK,CAAL;AAAO,aAAO,IAAP,CAAY,KAAK,CAAL,CAAO,KAAK,CAAL,CAAO,KAAK,CAAL;AAAO,UAAIra,IAAE,CAACd,EAAEW,MAAF,GAAS,CAAV,IAAa,CAAnB,CAAqB,IAAIJ,IAAEP,EAAEmD,MAAF,CAAS,CAAT,EAAWrC,CAAX,CAAN,CAAoB,IAAIT,IAAEL,EAAEmD,MAAF,CAASrC,IAAE,CAAX,EAAaA,CAAb,CAAN,CAAsB,OAAO,IAAIiZ,SAAJ,CAAc,IAAd,EAAmB,KAAKI,cAAL,CAAoB,IAAI1Q,UAAJ,CAAelJ,CAAf,EAAiB,EAAjB,CAApB,CAAnB,EAA6D,KAAK4Z,cAAL,CAAoB,IAAI1Q,UAAJ,CAAepJ,CAAf,EAAiB,EAAjB,CAApB,CAA7D,CAAP,CAA+G;AAAQ,aAAO,IAAP,CAApS;AAAiT,WAAUJ,SAAV,CAAoB0b,IAApB,GAAyBP,WAAzB,CAAqCF,UAAUjb,SAAV,CAAoB2b,IAApB,GAAyBP,WAAzB,CAAqCH,UAAUjb,SAAV,CAAoB4b,IAApB,GAAyBP,WAAzB,CAAqCJ,UAAUjb,SAAV,CAAoBiV,MAApB,GAA2BqG,aAA3B,CAAyCL,UAAUjb,SAAV,CAAoB0a,WAApB,GAAgCa,kBAAhC,CAAmDN,UAAUjb,SAAV,CAAoBka,cAApB,GAAmCsB,qBAAnC,CAAyDP,UAAUjb,SAAV,CAAoB6b,cAApB,GAAmCJ,qBAAnC;AAClkM;;AAEArC,iBAAiBpZ,SAAjB,CAA2B8b,aAA3B,GAAyC,YAAU;AAAC,SAAOxW,KAAKc,KAAL,CAAW,CAAC,KAAKqT,YAAL,GAAoBzK,SAApB,KAAgC,CAAjC,IAAoC,CAA/C,CAAP;AAAyD,CAA7G,CAA8G8K,UAAU9Z,SAAV,CAAoB+b,UAApB,GAA+B,UAASzb,CAAT,EAAW;AAAC,MAAIP,IAAE,SAAFA,CAAE,CAASH,CAAT,EAAWC,CAAX,EAAa;AAAC,QAAIF,IAAEC,EAAEoc,mBAAF,EAAN,CAA8B,IAAGnc,IAAEF,EAAEe,MAAP,EAAc;AAACf,UAAEA,EAAE8C,KAAF,CAAQ9C,EAAEe,MAAF,GAASb,CAAjB,CAAF;AAAsB,KAArC,MAAyC;AAAC,aAAMA,IAAEF,EAAEe,MAAV,EAAiB;AAACf,UAAEsc,OAAF,CAAU,CAAV;AAAa;AAAC,YAAOtc,CAAP;AAAS,GAArI,CAAsI,IAAIkB,IAAE,KAAKia,IAAL,GAAYrB,YAAZ,EAAN,CAAiC,IAAIpZ,IAAE,KAAK0a,IAAL,GAAYtB,YAAZ,EAAN,CAAiC,IAAIrZ,IAAEL,EAAEc,CAAF,EAAI,EAAJ,CAAN,CAAc,IAAGP,CAAH,EAAK;AAAC,QAAGD,EAAEyO,MAAF,EAAH,EAAc;AAAC1O,QAAE6b,OAAF,CAAU,CAAV;AAAa,KAA5B,MAAgC;AAAC7b,QAAE6b,OAAF,CAAU,CAAV;AAAa;AAAC,GAArD,MAAyD;AAAC7b,MAAE6b,OAAF,CAAU,CAAV,EAAa7b,IAAEA,EAAE6B,MAAF,CAASlC,EAAEM,CAAF,EAAI,EAAJ,CAAT,CAAF;AAAoB,UAAOD,CAAP;AAAS,CAArW,CAAsW0Z,UAAUoC,UAAV,GAAqB,UAASvc,CAAT,EAAWW,CAAX,EAAa;AAAC,MAAIT,IAAES,EAAE,CAAF,CAAN,CAAW,IAAID,IAAEC,EAAEI,MAAF,GAAS,CAAf,CAAiB,IAAIX,IAAEO,EAAEmC,KAAF,CAAQ,CAAR,EAAU,IAAEpC,IAAE,CAAd,CAAN,CAAuB,IAAID,IAAEE,EAAEmC,KAAF,CAAQ,IAAEpC,IAAE,CAAZ,EAAc,IAAEA,CAAhB,CAAN,CAAyBN,EAAEkc,OAAF,CAAU,CAAV,EAAa7b,EAAE6b,OAAF,CAAU,CAAV,EAAa,IAAIpb,IAAE,IAAI2I,UAAJ,CAAezJ,CAAf,CAAN,CAAwB,IAAIH,IAAE,IAAI4J,UAAJ,CAAepJ,CAAf,CAAN,CAAwB,OAAO,IAAI0Z,SAAJ,CAAcna,CAAd,EAAgBA,EAAEua,cAAF,CAAiBrZ,CAAjB,CAAhB,EAAoClB,EAAEua,cAAF,CAAiBta,CAAjB,CAApC,CAAP;AAAgE,CAAzP,CAA0Pka,UAAUqC,aAAV,GAAwB,UAASxc,CAAT,EAAWW,CAAX,EAAa;AAAC,MAAIT,IAAES,EAAE4C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAI7C,IAAEC,EAAEI,MAAF,GAAS,CAAf,CAAiB,IAAIX,IAAEO,EAAE4C,MAAF,CAAS,CAAT,EAAW7C,IAAE,CAAb,CAAN,CAAsB,IAAID,IAAEE,EAAE4C,MAAF,CAAS,IAAE7C,IAAE,CAAb,EAAeA,IAAE,CAAjB,CAAN,CAA0B,IAAIQ,IAAE,IAAI2I,UAAJ,CAAezJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIH,IAAE,IAAI4J,UAAJ,CAAepJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,OAAO,IAAI0Z,SAAJ,CAAcna,CAAd,EAAgBA,EAAEua,cAAF,CAAiBrZ,CAAjB,CAAhB,EAAoClB,EAAEua,cAAF,CAAiBta,CAAjB,CAApC,CAAP;AAAgE,CAAjP,CAAkPka,UAAU9Z,SAAV,CAAoBoc,KAApB,GAA0B,UAAS9b,CAAT,EAAW;AAAC,MAAG,KAAK+Z,UAAL,EAAH,EAAqB;AAAC,WAAO/Z,CAAP;AAAS,OAAGA,EAAE+Z,UAAF,EAAH,EAAkB;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKlW,CAAL,CAAO8Q,MAAP,CAAc3U,EAAE6D,CAAhB,CAAH,EAAsB;AAAC,QAAG,KAAK2D,CAAL,CAAOmN,MAAP,CAAc3U,EAAEwH,CAAhB,CAAH,EAAsB;AAAC,aAAO,KAAK2S,KAAL,EAAP;AAAoB,YAAO,KAAKV,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAEW,EAAE6D,CAAF,CAAIiQ,QAAJ,CAAa,KAAKjQ,CAAlB,CAAN,CAA2B,IAAI9D,IAAEC,EAAEwH,CAAF,CAAIsM,QAAJ,CAAa,KAAKtM,CAAlB,CAAN,CAA2B,IAAIjH,IAAER,EAAEkT,MAAF,CAAS5T,CAAT,CAAN,CAAkB,IAAII,IAAEc,EAAEmV,MAAF,GAAW5B,QAAX,CAAoB,KAAKjQ,CAAzB,EAA4BiQ,QAA5B,CAAqC9T,EAAE6D,CAAvC,CAAN,CAAgD,IAAItE,IAAEgB,EAAE8U,QAAF,CAAW,KAAKxR,CAAL,CAAOiQ,QAAP,CAAgBrU,CAAhB,CAAX,EAA+BqU,QAA/B,CAAwC,KAAKtM,CAA7C,CAAN,CAAsD,OAAO,IAAIgS,SAAJ,CAAc,KAAKC,KAAnB,EAAyBha,CAAzB,EAA2BF,CAA3B,CAAP;AAAqC,CAAzZ,CAA0Zia,UAAU9Z,SAAV,CAAoBqc,OAApB,GAA4B,YAAU;AAAC,MAAG,KAAKhC,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAG,KAAKvS,CAAL,CAAO2R,YAAP,GAAsB9J,MAAtB,MAAgC,CAAnC,EAAqC;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAIta,IAAE,KAAK2Z,KAAL,CAAWG,cAAX,CAA0B1Q,WAAW8S,OAAX,CAAmB,CAAnB,CAA1B,CAAN,CAAuD,IAAIjc,IAAE,KAAK0Z,KAAL,CAAWG,cAAX,CAA0B1Q,WAAW8S,OAAX,CAAmB,CAAnB,CAA1B,CAAN,CAAuD,IAAIzb,IAAE,KAAKsD,CAAL,CAAO6R,MAAP,GAAgBL,QAAhB,CAAyBtV,CAAzB,EAA4BgU,GAA5B,CAAgC,KAAK0F,KAAL,CAAWlZ,CAA3C,EAA8C0S,MAA9C,CAAqD,KAAKzL,CAAL,CAAO6N,QAAP,CAAgBvV,CAAhB,CAArD,CAAN,CAA+E,IAAIE,IAAEO,EAAEmV,MAAF,GAAW5B,QAAX,CAAoB,KAAKjQ,CAAL,CAAOwR,QAAP,CAAgBvV,CAAhB,CAApB,CAAN,CAA8C,IAAIL,IAAEc,EAAE8U,QAAF,CAAW,KAAKxR,CAAL,CAAOiQ,QAAP,CAAgB9T,CAAhB,CAAX,EAA+B8T,QAA/B,CAAwC,KAAKtM,CAA7C,CAAN,CAAsD,OAAO,IAAIgS,SAAJ,CAAc,KAAKC,KAAnB,EAAyBzZ,CAAzB,EAA2BP,CAA3B,CAAP;AAAqC,CAArd,CAAsd+Z,UAAU9Z,SAAV,CAAoBuc,UAApB,GAA+B,UAASnc,CAAT,EAAW;AAAC,MAAG,KAAKia,UAAL,EAAH,EAAqB;AAAC,WAAO,IAAP;AAAY,OAAGja,EAAEuP,MAAF,MAAY,CAAf,EAAiB;AAAC,WAAO,KAAKoK,KAAL,CAAWW,WAAX,EAAP;AAAgC,OAAI/a,IAAES,CAAN,CAAQ,IAAIP,IAAEF,EAAEgW,QAAF,CAAW,IAAInM,UAAJ,CAAe,GAAf,CAAX,CAAN,CAAsC,IAAI7I,IAAE,KAAK4K,MAAL,EAAN,CAAoB,IAAIxL,IAAE,IAAN,CAAW,IAAIO,CAAJ,CAAM,KAAIA,IAAET,EAAEmP,SAAF,KAAc,CAApB,EAAsB1O,IAAE,CAAxB,EAA0B,EAAEA,CAA5B,EAA8B;AAACP,QAAEA,EAAE0a,KAAF,EAAF,CAAY,IAAI5Z,IAAEhB,EAAEqQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAIE,IAAEb,EAAEuQ,OAAF,CAAU5P,CAAV,CAAN,CAAmB,IAAGO,KAAGL,CAAN,EAAQ;AAACT,UAAEA,EAAEqc,KAAF,CAAQvb,IAAE,IAAF,GAAOF,CAAf,CAAF;AAAoB;AAAC,UAAOZ,CAAP;AAAS,CAA1U,CAA2U+Z,UAAU9Z,SAAV,CAAoBwc,SAApB,GAA8B,YAAU;AAAC,MAAIzc,IAAE,KAAK+a,IAAL,GAAYrB,YAAZ,EAAN,CAAiC,IAAIhZ,IAAE,KAAKsa,IAAL,GAAYtB,YAAZ,EAAN,CAAiC,IAAI5Z,IAAE,KAAKka,KAAL,CAAW4B,IAAX,GAAkBlC,YAAlB,EAAN,CAAuC,IAAInZ,IAAE,KAAKyZ,KAAL,CAAW6B,IAAX,GAAkBnC,YAAlB,EAAN,CAAuC,IAAI7Z,IAAE,KAAKma,KAAL,CAAW2B,IAAX,EAAN,CAAwB,IAAIrb,IAAEI,EAAEkV,QAAF,CAAWlV,CAAX,EAAcyM,GAAd,CAAkBtN,CAAlB,CAAN,CAA2B,IAAID,IAAEI,EAAE4V,QAAF,CAAW5V,CAAX,EAAc4V,QAAd,CAAuB5V,CAAvB,EAA0BsU,GAA1B,CAA8BxU,EAAE8V,QAAF,CAAW5V,CAAX,CAA9B,EAA6CsU,GAA7C,CAAiD/T,CAAjD,EAAoD4M,GAApD,CAAwDtN,CAAxD,CAAN,CAAiE,OAAOS,EAAE4U,MAAF,CAAStV,CAAT,CAAP;AAAmB,CAAhU,CAAiUma,UAAU9Z,SAAV,CAAoB2B,QAApB,GAA6B,YAAU;AAAC,SAAM,MAAI,KAAKmZ,IAAL,GAAYrB,YAAZ,GAA2B9X,QAA3B,EAAJ,GAA0C,GAA1C,GAA8C,KAAKoZ,IAAL,GAAYtB,YAAZ,GAA2B9X,QAA3B,EAA9C,GAAoF,GAA1F;AAA8F,CAAtI,CAAuImY,UAAU9Z,SAAV,CAAoByc,QAApB,GAA6B,YAAU;AAAC,MAAInc,IAAE,KAAKyZ,KAAL,CAAW2B,IAAX,EAAN,CAAwB,IAAG,KAAKrB,UAAL,EAAH,EAAqB;AAAC,UAAM,IAAIva,KAAJ,CAAU,uBAAV,CAAN;AAAyC,OAAIe,IAAE,KAAKia,IAAL,GAAYrB,YAAZ,EAAN,CAAiC,IAAIrZ,IAAE,KAAK2a,IAAL,GAAYtB,YAAZ,EAAN,CAAiC,IAAG5Y,EAAE6L,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+B9L,EAAE6L,SAAF,CAAYpM,EAAE8T,QAAF,CAAW5K,WAAWmD,GAAtB,CAAZ,IAAwC,CAA1E,EAA4E;AAAC,UAAM,IAAI7M,KAAJ,CAAU,4BAAV,CAAN;AAA8C,OAAGM,EAAEsM,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+BvM,EAAEsM,SAAF,CAAYpM,EAAE8T,QAAF,CAAW5K,WAAWmD,GAAtB,CAAZ,IAAwC,CAA1E,EAA4E;AAAC,UAAM,IAAI7M,KAAJ,CAAU,4BAAV,CAAN;AAA8C,OAAG,CAAC,KAAK0c,SAAL,EAAJ,EAAqB;AAAC,UAAM,IAAI1c,KAAJ,CAAU,4BAAV,CAAN;AAA8C,OAAG,KAAK6V,QAAL,CAAcrV,CAAd,EAAiB+Z,UAAjB,EAAH,EAAiC;AAAC,UAAM,IAAIva,KAAJ,CAAU,sCAAV,CAAN;AAAwD,UAAO,IAAP;AAAY,CAAjmB;AACnkF;;AAEA,IAAI4c,YAAW,YAAU;AAAC,MAAIrc,IAAE,iEAAN,CAAwE,IAAIG,IAAE,wEAAN,CAA+E,IAAIC,IAAE,SAAOD,CAAP,GAAS,KAAf,CAAqB,IAAIT,IAAE,IAAI4c,MAAJ,CAAW,uCAAqCtc,CAArC,GAAuC,GAAvC,GAA2CI,CAA3C,GAA6C,GAAxD,EAA4D,GAA5D,CAAN,CAAuE,IAAIG,IAAE,IAAI+b,MAAJ,CAAW,wBAAX,EAAoC,GAApC,CAAN,CAA+C,IAAIhd,IAAE,EAAC,KAAI,GAAL,EAAS,KAAI,GAAb,EAAiB,MAAK,IAAtB,EAA2BS,GAAE,IAA7B,EAAkCP,GAAE,IAApC,EAAyCoB,GAAE,IAA3C,EAAgDqB,GAAE,IAAlD,EAAuDJ,GAAE,IAAzD,EAAN,CAAqE,SAAStC,CAAT,CAAWe,CAAX,EAAaiC,CAAb,EAAe3B,CAAf,EAAiB;AAAC,WAAO2B,IAAEjD,EAAEiD,CAAF,CAAF,GAAOQ,OAAOC,YAAP,CAAoBJ,SAAShC,CAAT,EAAW,EAAX,CAApB,CAAd;AAAkD,OAAIX,IAAE,IAAI8C,MAAJ,CAAW,EAAX,CAAN,CAAqB,IAAIvC,IAAE,IAAN,CAAW,IAAIhB,IAAE,EAAC,KAAIM,MAAL,EAAY,KAAIiJ,KAAhB,EAAN,CAA6B,IAAIhJ,IAAED,OAAOkB,cAAb,CAA4B,OAAO,UAASiD,CAAT,EAAWnC,CAAX,EAAa;AAAC,QAAIjB,IAAEoD,EAAEsY,KAAF,CAAQ7c,CAAR,CAAN,CAAiB,IAAIoE,CAAJ,CAAM,IAAIE,IAAEnD,EAAE,CAAF,CAAN,CAAW,IAAIP,IAAE,KAAN,CAAY,IAAG,QAAM0D,CAAT,EAAW;AAACF,UAAE,EAAF;AAAK,KAAjB,MAAqB;AAAC,UAAG,QAAME,CAAT,EAAW;AAACF,YAAE,EAAF;AAAK,OAAjB,MAAqB;AAACA,YAAE,EAAF,CAAKxD,IAAE,IAAF;AAAO;AAAC,SAAIuB,CAAJ,CAAM,IAAII,IAAE,CAAC6B,CAAD,CAAN,CAAU,KAAI,IAAIhD,IAAE,IAAER,CAAR,EAAUiC,IAAE1B,EAAER,MAAlB,EAAyBS,IAAEyB,CAA3B,EAA6B,EAAEzB,CAA/B,EAAiC;AAACkD,UAAEnD,EAAEC,CAAF,CAAF,CAAO,IAAI+C,CAAJ,CAAM,QAAOG,EAAEf,UAAF,CAAa,CAAb,CAAP,GAAwB;AAAQY,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,CAAE2D,CAAjB,CAAoBnC,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,EAAL;AAAQmC,cAAEA,EAAE2E,SAAF,CAAY,CAAZ,EAAc3E,EAAE3D,MAAF,GAAS,CAAvB,CAAF,CAA4B,IAAG2D,EAAE0B,OAAF,CAAUlF,CAAV,MAAe,CAAC,CAAnB,EAAqB;AAACwD,gBAAEA,EAAEwY,OAAF,CAAUjc,CAAV,EAAYhB,CAAZ,CAAF;AAAiB,eAAE0C,EAAE,CAAF,CAAF,CAAO,IAAG,CAACJ,CAAJ,EAAM;AAAC,gBAAGgC,aAAakF,KAAhB,EAAsB;AAAClH,kBAAEgC,EAAExD,MAAJ;AAAW,aAAlC,MAAsC;AAACwB,kBAAEmC,KAAG/D,CAAL,CAAO;AAAM;AAAC,aAAE4B,CAAF,IAAKmC,CAAL,CAAOnC,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,EAAL;AAAQgC,cAAE5B,EAAE,CAAF,CAAF,CAAOA,EAAE2Z,OAAF,CAAU/X,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,EAAzB,EAA6BwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,EAAL;AAAQI,YAAEwa,KAAF,GAAU,MAAM,KAAK,GAAL;AAAS5Y,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,KAAf,CAAqBwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASgC,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,IAAf,CAAoBwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASgC,cAAE5B,EAAE,CAAF,CAAF,CAAO4B,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,IAAf,CAAoBwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASgC,cAAE5B,EAAE,CAAF,CAAF,CAAOA,EAAE2Z,OAAF,CAAU/X,EAAEhC,KAAGgC,EAAExD,MAAP,IAAe,EAAzB,EAA6BwB,IAAE,KAAK,CAAP,CAAS,MAAM,KAAK,GAAL;AAASI,YAAEwa,KAAF,GAAU,MAA1iB;AAAijB,SAAGnc,CAAH,EAAK;AAAC,UAAG2B,EAAE5B,MAAF,KAAW,CAAd,EAAgB;AAAC,cAAM,IAAIZ,KAAJ,EAAN;AAAkB,WAAEqE,EAAE,CAAF,CAAF;AAAO,KAAhD,MAAoD;AAAC,UAAG7B,EAAE5B,MAAL,EAAY;AAAC,cAAM,IAAIZ,KAAJ,EAAN;AAAkB;AAAC,SAAGqC,CAAH,EAAK;AAAC,UAAIC,IAAE,SAAFA,CAAE,CAAS8F,CAAT,EAAWF,CAAX,EAAa;AAAC,YAAII,IAAEF,EAAEF,CAAF,CAAN,CAAW,IAAGI,KAAG,QAAOA,CAAP,yCAAOA,CAAP,OAAW,QAAjB,EAA0B;AAAC,cAAInH,IAAE,IAAN,CAAW,KAAI,IAAI2G,CAAR,IAAaQ,CAAb,EAAe;AAAC,gBAAGhI,EAAEoC,IAAF,CAAO4F,CAAP,EAASR,CAAT,KAAaQ,MAAIF,CAApB,EAAsB;AAAC,kBAAIJ,IAAE1F,EAAEgG,CAAF,EAAIR,CAAJ,CAAN,CAAa,IAAGE,MAAI,KAAK,CAAZ,EAAc;AAACM,kBAAER,CAAF,IAAKE,CAAL;AAAO,eAAtB,MAA0B;AAAC,oBAAG,CAAC7G,CAAJ,EAAM;AAACA,sBAAE,EAAF;AAAK,mBAAE0B,IAAF,CAAOiF,CAAP;AAAU;AAAC;AAAC,eAAG3G,CAAH,EAAK;AAAC,iBAAI,IAAI4G,IAAE5G,EAAEP,MAAZ,EAAmB,EAAEmH,CAAF,IAAK,CAAxB,GAA2B;AAAC,qBAAOO,EAAEnH,EAAE4G,CAAF,CAAF,CAAP;AAAe;AAAC;AAAC,gBAAO1F,EAAEK,IAAF,CAAO0F,CAAP,EAASF,CAAT,EAAWI,CAAX,CAAP;AAAqB,OAApP,CAAqPjE,IAAE/B,EAAE,EAAC,IAAG+B,CAAJ,EAAF,EAAS,EAAT,CAAF;AAAe,YAAOA,CAAP;AAAS,GAAplC;AAAqlC,CAArmD,EAAd;AACA,IAAG,OAAO0T,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UA6E3BA,IA7E2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKkF,IAAZ,IAAkB,WAAlB,IAA+B,CAAClF,KAAKkF,IAAxC,EAA6C;AAAClF,OAAKkF,IAAL,GAAU,EAAV;AAAa,MAAKA,IAAL,CAAUC,QAAV,GAAmB,IAAI,YAAU;AAAC,OAAKC,gBAAL,GAAsB,UAASpc,CAAT,EAAW;AAAC,QAAIT,IAAES,EAAEc,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAIvB,EAAEM,MAAF,GAAS,CAAV,IAAc,CAAjB,EAAmB;AAACN,UAAE,MAAIA,CAAN;AAAQ,YAAOA,CAAP;AAAS,GAA5F,CAA6F,KAAK8c,6BAAL,GAAmC,UAAS1c,CAAT,EAAW;AAAC,QAAIX,IAAEW,EAAEmB,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG9B,EAAEqD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,GAAlB,EAAsB;AAAC,UAAGrD,EAAEa,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACb,YAAE,MAAIA,CAAN;AAAQ,OAA1B,MAA8B;AAAC,YAAG,CAACA,EAAE+c,KAAF,CAAQ,QAAR,CAAJ,EAAsB;AAAC/c,cAAE,OAAKA,CAAP;AAAS;AAAC;AAAC,KAAxF,MAA4F;AAAC,UAAIgB,IAAEhB,EAAEqD,MAAF,CAAS,CAAT,CAAN,CAAkB,IAAI7C,IAAEQ,EAAEH,MAAR,CAAe,IAAGL,IAAE,CAAF,IAAK,CAAR,EAAU;AAACA,aAAG,CAAH;AAAK,OAAhB,MAAoB;AAAC,YAAG,CAACR,EAAE+c,KAAF,CAAQ,QAAR,CAAJ,EAAsB;AAACvc,eAAG,CAAH;AAAK;AAAC,WAAIV,IAAE,EAAN,CAAS,KAAI,IAAII,IAAE,CAAV,EAAYA,IAAEM,CAAd,EAAgBN,GAAhB,EAAoB;AAACJ,aAAG,GAAH;AAAO,WAAIW,IAAE,IAAIkJ,UAAJ,CAAe7J,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIS,IAAEE,EAAE8U,GAAF,CAAM5U,CAAN,EAAS6T,GAAT,CAAa7K,WAAWmD,GAAxB,CAAN,CAAmC9M,IAAEO,EAAEuB,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,IAAvB,EAA4B,EAA5B,CAAF;AAAkC,YAAOhd,CAAP;AAAS,GAAlY,CAAmY,KAAKsd,mBAAL,GAAyB,UAAStc,CAAT,EAAWT,CAAX,EAAa;AAAC,WAAOgd,SAASvc,CAAT,EAAWT,CAAX,CAAP;AAAqB,GAA5D,CAA6D,KAAKid,SAAL,GAAe,UAASzc,CAAT,EAAW;AAAC,QAAIwH,IAAEyP,IAAN;AAAA,QAAW5W,IAAEmH,EAAE2U,IAAf;AAAA,QAAoBnV,IAAE3G,EAAEqc,UAAxB;AAAA,QAAmCjd,IAAEY,EAAEsc,UAAvC;AAAA,QAAkDnb,IAAEnB,EAAEuc,YAAtD;AAAA,QAAmE5d,IAAEqB,EAAEwc,cAAvE;AAAA,QAAsFpZ,IAAEpD,EAAEyc,OAA1F;AAAA,QAAkGxZ,IAAEjD,EAAE0c,mBAAtG;AAAA,QAA0Hhd,IAAEM,EAAE2c,aAA9H;AAAA,QAA4Ije,IAAEsB,EAAE4c,aAAhJ;AAAA,QAA8Jhe,IAAEoB,EAAE6c,gBAAlK;AAAA,QAAmLhW,IAAE7G,EAAE8c,kBAAvL;AAAA,QAA0MzZ,IAAErD,EAAE+c,gBAA9M;AAAA,QAA+N9c,IAAED,EAAEgd,YAAnO;AAAA,QAAgP/V,IAAEjH,EAAEid,UAApP;AAAA,QAA+P1d,IAAES,EAAEkd,kBAAnQ;AAAA,QAAsRvb,IAAE3B,EAAEmd,WAA1R;AAAA,QAAsS9d,IAAEW,EAAEod,MAA1S;AAAA,QAAiT/b,IAAErB,EAAEqd,eAArT;AAAA,QAAqUnd,IAAEF,EAAE+b,QAAF,CAAWK,SAAlV,CAA4V,IAAInb,IAAE/B,OAAOoe,IAAP,CAAY3d,CAAZ,CAAN,CAAqB,IAAGsB,EAAExB,MAAF,IAAU,CAAb,EAAe;AAAC,YAAK,iCAAL;AAAuC,SAAI+F,IAAEvE,EAAE,CAAF,CAAN,CAAW,IAAG,yGAAyG6D,OAAzG,CAAiH,MAAIU,CAAJ,GAAM,GAAvH,KAA6H,CAAC,CAAjI,EAAmI;AAAC,YAAK,oBAAkBA,CAAvB;AAAyB,SAAGA,KAAG,MAAN,EAAa;AAAC,aAAO,IAAImB,CAAJ,CAAMhH,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,KAAN,EAAY;AAAC,aAAO,IAAIpG,CAAJ,CAAMO,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAIrE,CAAJ,CAAMxB,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAI7G,CAAJ,CAAMgB,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,MAAN,EAAa;AAAC,aAAO,IAAIpC,CAAJ,CAAMzD,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,KAAN,EAAY;AAAC,aAAO,IAAIvC,CAAJ,CAAMtD,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,MAAN,EAAa;AAAC,aAAO,IAAI9F,CAAJ,CAAMC,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,SAAN,EAAgB;AAAC,aAAO,IAAI9G,CAAJ,CAAMiB,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAI5G,CAAJ,CAAMe,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAIqB,CAAJ,CAAMlH,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAInC,CAAJ,CAAM1D,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,QAAN,EAAe;AAAC,aAAO,IAAIvF,CAAJ,CAAMN,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,SAAN,EAAgB;AAAC,aAAO,IAAIyB,CAAJ,CAAMtH,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,SAAN,EAAgB;AAAC,aAAO,IAAIjG,CAAJ,CAAMI,EAAE6F,CAAF,CAAN,CAAP;AAAmB,SAAGA,KAAG,KAAN,EAAY;AAAC,UAAI1G,IAAEa,EAAE6F,CAAF,CAAN,CAAW,IAAI6B,IAAE,EAAN,CAAS,KAAI,IAAInE,IAAE,CAAV,EAAYA,IAAEpE,EAAEW,MAAhB,EAAuByD,GAAvB,EAA2B;AAAC,YAAI6D,IAAE7G,EAAEpB,EAAEoE,CAAF,CAAF,CAAN,CAAcmE,EAAE3F,IAAF,CAAOqF,CAAP;AAAU,cAAO,IAAIpF,CAAJ,CAAM,EAAC4b,OAAMlW,CAAP,EAAN,CAAP;AAAwB,SAAG7B,KAAG,KAAN,EAAY;AAAC,UAAI1G,IAAEa,EAAE6F,CAAF,CAAN,CAAW,IAAI6B,IAAE,EAAN,CAAS,KAAI,IAAInE,IAAE,CAAV,EAAYA,IAAEpE,EAAEW,MAAhB,EAAuByD,GAAvB,EAA2B;AAAC,YAAI6D,IAAE7G,EAAEpB,EAAEoE,CAAF,CAAF,CAAN,CAAcmE,EAAE3F,IAAF,CAAOqF,CAAP;AAAU,cAAO,IAAI1H,CAAJ,CAAM,EAACke,OAAMlW,CAAP,EAAN,CAAP;AAAwB,SAAG7B,KAAG,KAAN,EAAY;AAAC,UAAIoB,IAAEjH,EAAE6F,CAAF,CAAN,CAAW,IAAGtG,OAAOH,SAAP,CAAiB2B,QAAjB,CAA0Ba,IAA1B,CAA+BqF,CAA/B,MAAoC,gBAApC,IAAsDA,EAAEnH,MAAF,IAAU,CAAnE,EAAqE;AAAC,YAAIyB,IAAEhB,EAAE0G,EAAE,CAAF,CAAF,CAAN,CAAc,OAAO,IAAIvF,CAAJ,CAAM,EAACmc,KAAI5W,EAAE,CAAF,CAAL,EAAU6W,UAAS7W,EAAE,CAAF,CAAnB,EAAwB8W,KAAIxc,CAA5B,EAAN,CAAP;AAA6C,OAAjI,MAAqI;AAAC,YAAI/B,IAAE,EAAN,CAAS,IAAGyH,EAAE6W,QAAF,KAAalf,SAAhB,EAA0B;AAACY,YAAEse,QAAF,GAAW7W,EAAE6W,QAAb;AAAsB,aAAG7W,EAAE4W,GAAF,KAAQjf,SAAX,EAAqB;AAACY,YAAEqe,GAAF,GAAM5W,EAAE4W,GAAR;AAAY,aAAG5W,EAAE8W,GAAF,KAAQnf,SAAX,EAAqB;AAAC,gBAAK,mCAAL;AAAyC,WAAEmf,GAAF,GAAMxd,EAAE0G,EAAE8W,GAAJ,CAAN,CAAe,OAAO,IAAIrc,CAAJ,CAAMlC,CAAN,CAAP;AAAgB;AAAC;AAAC,GAAhoD,CAAioD,KAAKwe,aAAL,GAAmB,UAASxe,CAAT,EAAW;AAAC,QAAIS,IAAE,KAAKwc,SAAL,CAAejd,CAAf,CAAN,CAAwB,OAAOS,EAAEge,aAAF,EAAP;AAAyB,GAAhF;AAAiF,CAA9vE,EAAnB,CAAkxEhH,KAAKkF,IAAL,CAAUC,QAAV,CAAmB8B,WAAnB,GAA+B,UAASje,CAAT,EAAW;AAAC,MAAIL,IAAE,EAAN,CAAS,IAAII,IAAEqC,SAASpC,EAAEqC,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAN,CAAiC,IAAInD,IAAEuF,KAAKc,KAAL,CAAWxF,IAAE,EAAb,CAAN,CAAuB,IAAIN,IAAEM,IAAE,EAAR,CAAW,IAAIJ,IAAET,IAAE,GAAF,GAAMO,CAAZ,CAAc,IAAID,IAAE,EAAN,CAAS,KAAI,IAAIR,IAAE,CAAV,EAAYA,IAAEgB,EAAEH,MAAhB,EAAuBb,KAAG,CAA1B,EAA4B;AAAC,QAAIF,IAAEsD,SAASpC,EAAEqC,MAAF,CAASrD,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAN,CAAiC,IAAID,IAAE,CAAC,aAAWD,EAAEgC,QAAF,CAAW,CAAX,CAAZ,EAA2Bc,KAA3B,CAAiC,CAAC,CAAlC,CAAN,CAA2CpC,IAAEA,IAAET,EAAEsD,MAAF,CAAS,CAAT,EAAW,CAAX,CAAJ,CAAkB,IAAGtD,EAAEsD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,GAAlB,EAAsB;AAAC,UAAI9C,IAAE,IAAIoJ,UAAJ,CAAenJ,CAAf,EAAiB,CAAjB,CAAN,CAA0BG,IAAEA,IAAE,GAAF,GAAMJ,EAAEuB,QAAF,CAAW,EAAX,CAAR,CAAuBtB,IAAE,EAAF;AAAK;AAAC,UAAOG,CAAP;AAAS,CAAhW,CAAiWqX,KAAKkF,IAAL,CAAUC,QAAV,CAAmB+B,WAAnB,GAA+B,UAASlf,CAAT,EAAW;AAAC,MAAIQ,IAAE,SAAFA,CAAE,CAASQ,CAAT,EAAW;AAAC,QAAID,IAAEC,EAAEc,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAGf,EAAEF,MAAF,IAAU,CAAb,EAAe;AAACE,UAAE,MAAIA,CAAN;AAAQ,YAAOA,CAAP;AAAS,GAAxE,CAAyE,IAAIb,IAAE,SAAFA,CAAE,CAASoB,CAAT,EAAW;AAAC,QAAIF,IAAE,EAAN,CAAS,IAAIL,IAAE,IAAI4I,UAAJ,CAAerI,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIN,IAAED,EAAEe,QAAF,CAAW,CAAX,CAAN,CAAoB,IAAIhB,IAAE,IAAEE,EAAEH,MAAF,GAAS,CAAjB,CAAmB,IAAGC,KAAG,CAAN,EAAQ;AAACA,UAAE,CAAF;AAAI,SAAIwB,IAAE,EAAN,CAAS,KAAI,IAAIS,IAAE,CAAV,EAAYA,IAAEjC,CAAd,EAAgBiC,GAAhB,EAAoB;AAACT,WAAG,GAAH;AAAO,SAAEA,IAAEtB,CAAJ,CAAM,KAAI,IAAI+B,IAAE,CAAV,EAAYA,IAAE/B,EAAEH,MAAF,GAAS,CAAvB,EAAyBkC,KAAG,CAA5B,EAA8B;AAAC,UAAI1B,IAAEL,EAAEqC,MAAF,CAASN,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAGA,KAAG/B,EAAEH,MAAF,GAAS,CAAf,EAAiB;AAACQ,YAAE,MAAIA,CAAN;AAAQ,YAAGb,EAAE4C,SAAS/B,CAAT,EAAW,CAAX,CAAF,CAAH;AAAoB,YAAOD,CAAP;AAAS,GAA/P,CAAgQ,IAAG,CAACpB,EAAE+c,KAAF,CAAQ,WAAR,CAAJ,EAAyB;AAAC,UAAK,2BAAyB/c,CAA9B;AAAgC,OAAIF,IAAE,EAAN,CAAS,IAAIS,IAAEP,EAAEmf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAIxe,IAAEyC,SAAS7C,EAAE,CAAF,CAAT,IAAe,EAAf,GAAkB6C,SAAS7C,EAAE,CAAF,CAAT,CAAxB,CAAuCT,KAAGU,EAAEG,CAAF,CAAH,CAAQJ,EAAEuE,MAAF,CAAS,CAAT,EAAW,CAAX,EAAc,KAAI,IAAIrE,IAAE,CAAV,EAAYA,IAAEF,EAAEM,MAAhB,EAAuBJ,GAAvB,EAA2B;AAACX,SAAGI,EAAEK,EAAEE,CAAF,CAAF,CAAH;AAAW,UAAOX,CAAP;AAAS,CAAvjB,CAAwjBkY,KAAKkF,IAAL,CAAUkC,UAAV,GAAqB,YAAU;AAAC,MAAI3e,IAAE,IAAN,CAAW,IAAIF,IAAE,IAAN,CAAW,IAAIL,IAAE,IAAN,CAAW,IAAIM,IAAE,IAAN,CAAW,IAAIQ,IAAE,EAAN,CAAS,KAAKqe,qBAAL,GAA2B,YAAU;AAAC,QAAG,OAAO,KAAKC,EAAZ,IAAgB,WAAhB,IAA6B,KAAKA,EAAL,IAAS,IAAzC,EAA8C;AAAC,YAAK,+BAAL;AAAqC,SAAG,KAAKA,EAAL,CAAQze,MAAR,GAAe,CAAf,IAAkB,CAArB,EAAuB;AAAC,YAAK,sCAAoCG,EAAEH,MAAtC,GAA6C,KAA7C,GAAmD,KAAKye,EAA7D;AAAgE,SAAI1e,IAAE,KAAK0e,EAAL,CAAQze,MAAR,GAAe,CAArB,CAAuB,IAAId,IAAEa,EAAEkB,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAG/B,EAAEc,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACd,UAAE,MAAIA,CAAN;AAAQ,SAAGa,IAAE,GAAL,EAAS;AAAC,aAAOb,CAAP;AAAS,KAAnB,MAAuB;AAAC,UAAID,IAAEC,EAAEc,MAAF,GAAS,CAAf,CAAiB,IAAGf,IAAE,EAAL,EAAQ;AAAC,cAAK,mDAAiDc,EAAEkB,QAAF,CAAW,EAAX,CAAtD;AAAqE,WAAI9B,IAAE,MAAIF,CAAV,CAAY,OAAOE,EAAE8B,QAAF,CAAW,EAAX,IAAe/B,CAAtB;AAAwB;AAAC,GAApb,CAAqb,KAAKif,aAAL,GAAmB,YAAU;AAAC,QAAG,KAAKO,IAAL,IAAW,IAAX,IAAiB,KAAKC,UAAzB,EAAoC;AAAC,WAAKF,EAAL,GAAQ,KAAKG,gBAAL,EAAR,CAAgC,KAAKC,EAAL,GAAQ,KAAKL,qBAAL,EAAR,CAAqC,KAAKE,IAAL,GAAU,KAAKI,EAAL,GAAQ,KAAKD,EAAb,GAAgB,KAAKJ,EAA/B,CAAkC,KAAKE,UAAL,GAAgB,KAAhB;AAAsB,YAAO,KAAKD,IAAZ;AAAiB,GAAjN,CAAkN,KAAKK,WAAL,GAAiB,YAAU;AAAC,SAAKZ,aAAL,GAAqB,OAAO,KAAKM,EAAZ;AAAe,GAAhE,CAAiE,KAAKG,gBAAL,GAAsB,YAAU;AAAC,WAAM,EAAN;AAAS,GAA1C;AAA2C,CAAx0B,CAAy0BzH,KAAKkF,IAAL,CAAU2C,iBAAV,GAA4B,UAASpf,CAAT,EAAW;AAACuX,OAAKkF,IAAL,CAAU2C,iBAAV,CAA4Bxf,UAA5B,CAAuCD,WAAvC,CAAmDuC,IAAnD,CAAwD,IAAxD,EAA8D,IAAIpC,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,KAAK8e,SAAL,GAAe,YAAU;AAAC,WAAO,KAAKvd,CAAZ;AAAc,GAAxC,CAAyC,KAAKwd,SAAL,GAAe,UAAS7f,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAOrC,CAAP,CAAS,KAAKof,EAAL,GAAQU,UAAU,KAAKzd,CAAf,EAAkB0d,WAAlB,EAAR;AAAwC,GAAhH,CAAiH,KAAKC,YAAL,GAAkB,UAAShgB,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAO,IAAP,CAAY,KAAK+c,EAAL,GAAQpf,CAAR;AAAU,GAAxF,CAAyF,KAAKuf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAO7e,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,WAAKsf,SAAL,CAAetf,CAAf;AAAkB,KAAzC,MAA6C;AAAC,UAAG,OAAOA,EAAE0f,GAAT,IAAc,WAAjB,EAA6B;AAAC,aAAKJ,SAAL,CAAetf,EAAE0f,GAAjB;AAAsB,OAApD,MAAwD;AAAC,YAAG,OAAO1f,EAAE2f,GAAT,IAAc,WAAjB,EAA6B;AAAC,eAAKF,YAAL,CAAkBzf,EAAE2f,GAApB;AAAyB;AAAC;AAAC;AAAC;AAAC,CAA5lB,CAA6lB1gB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAU2C,iBAA5B,EAA8C7H,KAAKkF,IAAL,CAAUkC,UAAxD,EAAoEpH,KAAKkF,IAAL,CAAUmD,eAAV,GAA0B,UAAS5f,CAAT,EAAW;AAACuX,OAAKkF,IAAL,CAAUmD,eAAV,CAA0BhgB,UAA1B,CAAqCD,WAArC,CAAiDuC,IAAjD,CAAsD,IAAtD,EAA4D,IAAIpC,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,KAAKsf,cAAL,GAAoB,UAAStgB,CAAT,EAAW;AAACugB,UAAIvgB,EAAEgX,OAAF,KAAahX,EAAEwgB,iBAAF,KAAsB,KAAvC,CAA8C,IAAIhgB,IAAE,IAAIuW,IAAJ,CAASwJ,GAAT,CAAN,CAAoB,OAAO/f,CAAP;AAAS,GAA3G,CAA4G,KAAKigB,UAAL,GAAgB,UAAS1d,CAAT,EAAWzB,CAAX,EAAad,CAAb,EAAe;AAAC,QAAIV,IAAE,KAAK4gB,WAAX,CAAuB,IAAItf,IAAE,KAAKkf,cAAL,CAAoBvd,CAApB,CAAN,CAA6B,IAAI1B,IAAEkC,OAAOnC,EAAEuf,WAAF,EAAP,CAAN,CAA8B,IAAGrf,KAAG,KAAN,EAAY;AAACD,UAAEA,EAAEgC,MAAF,CAAS,CAAT,EAAW,CAAX,CAAF;AAAgB,SAAIvC,IAAEhB,EAAEyD,OAAOnC,EAAEwf,QAAF,KAAa,CAApB,CAAF,EAAyB,CAAzB,CAAN,CAAkC,IAAIte,IAAExC,EAAEyD,OAAOnC,EAAEyf,OAAF,EAAP,CAAF,EAAsB,CAAtB,CAAN,CAA+B,IAAI9gB,IAAED,EAAEyD,OAAOnC,EAAE0f,QAAF,EAAP,CAAF,EAAuB,CAAvB,CAAN,CAAgC,IAAIlgB,IAAEd,EAAEyD,OAAOnC,EAAE2f,UAAF,EAAP,CAAF,EAAyB,CAAzB,CAAN,CAAkC,IAAIpgB,IAAEb,EAAEyD,OAAOnC,EAAE4f,UAAF,EAAP,CAAF,EAAyB,CAAzB,CAAN,CAAkC,IAAIve,IAAEpB,IAAEP,CAAF,GAAIwB,CAAJ,GAAMvC,CAAN,GAAQa,CAAR,GAAUD,CAAhB,CAAkB,IAAGH,MAAI,IAAP,EAAY;AAAC,UAAIR,IAAEoB,EAAE6f,eAAF,EAAN,CAA0B,IAAGjhB,KAAG,CAAN,EAAQ;AAAC,YAAIe,IAAEjB,EAAEyD,OAAOvD,CAAP,CAAF,EAAY,CAAZ,CAAN,CAAqBe,IAAEA,EAAEic,OAAF,CAAU,OAAV,EAAkB,EAAlB,CAAF,CAAwBva,IAAEA,IAAE,GAAF,GAAM1B,CAAR;AAAU;AAAC,YAAO0B,IAAE,GAAT;AAAa,GAA3b,CAA4b,KAAKie,WAAL,GAAiB,UAASlgB,CAAT,EAAWN,CAAX,EAAa;AAAC,QAAGM,EAAEK,MAAF,IAAUX,CAAb,EAAe;AAAC,aAAOM,CAAP;AAAS,YAAO,IAAI+I,KAAJ,CAAUrJ,IAAEM,EAAEK,MAAJ,GAAW,CAArB,EAAwBqC,IAAxB,CAA6B,GAA7B,IAAkC1C,CAAzC;AAA2C,GAAnG,CAAoG,KAAKsf,SAAL,GAAe,YAAU;AAAC,WAAO,KAAKvd,CAAZ;AAAc,GAAxC,CAAyC,KAAKwd,SAAL,GAAe,UAAS7f,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAOrC,CAAP,CAAS,KAAKof,EAAL,GAAQ4B,OAAOhhB,CAAP,CAAR;AAAkB,GAA1F,CAA2F,KAAKihB,cAAL,GAAoB,UAASphB,CAAT,EAAWY,CAAX,EAAaH,CAAb,EAAeN,CAAf,EAAiBF,CAAjB,EAAmBF,CAAnB,EAAqB;AAAC,QAAIc,IAAE,IAAImW,IAAJ,CAASA,KAAKqK,GAAL,CAASrhB,CAAT,EAAWY,IAAE,CAAb,EAAeH,CAAf,EAAiBN,CAAjB,EAAmBF,CAAnB,EAAqBF,CAArB,EAAuB,CAAvB,CAAT,CAAN,CAA0C,KAAKuhB,SAAL,CAAezgB,CAAf;AAAkB,GAAtG,CAAuG,KAAK6e,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD;AAAiD,CAAhiC,CAAiiC5f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUmD,eAA5B,EAA4CrI,KAAKkF,IAAL,CAAUkC,UAAtD,EAAkEpH,KAAKkF,IAAL,CAAUoE,qBAAV,GAAgC,UAAS/gB,CAAT,EAAW;AAACyX,OAAKkF,IAAL,CAAU2C,iBAAV,CAA4Bxf,UAA5B,CAAuCD,WAAvC,CAAmDuC,IAAnD,CAAwD,IAAxD,EAA8D,IAAI3B,IAAE,IAAN,CAAW,KAAKugB,oBAAL,GAA0B,UAAS9gB,CAAT,EAAW;AAAC,SAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKgC,SAAL,GAAe/gB,CAAf;AAAiB,GAA3F,CAA4F,KAAKghB,gBAAL,GAAsB,UAAShhB,CAAT,EAAW;AAAC,SAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKgC,SAAL,CAAe1e,IAAf,CAAoBrC,CAApB;AAAuB,GAA7F,CAA8F,KAAK+gB,SAAL,GAAe,IAAIjY,KAAJ,EAAf,CAA2B,IAAG,OAAOhJ,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAEoe,KAAT,IAAgB,WAAnB,EAA+B;AAAC,WAAK6C,SAAL,GAAejhB,EAAEoe,KAAjB;AAAuB;AAAC;AAAC,CAA7Z,CAA8Zjf,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUoE,qBAA5B,EAAkDtJ,KAAKkF,IAAL,CAAUkC,UAA5D,EAAwEpH,KAAKkF,IAAL,CAAUO,UAAV,GAAqB,YAAU;AAACzF,OAAKkF,IAAL,CAAUO,UAAV,CAAqBpd,UAArB,CAAgCD,WAAhC,CAA4CuC,IAA5C,CAAiD,IAAjD,EAAuD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKJ,IAAL,GAAU,QAAV;AAAmB,CAAvH,CAAwH7f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUO,UAA5B,EAAuCzF,KAAKkF,IAAL,CAAUkC,UAAjD,EAA6DpH,KAAKkF,IAAL,CAAUQ,UAAV,GAAqB,UAAS1c,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUQ,UAAV,CAAqBrd,UAArB,CAAgCD,WAAhC,CAA4CuC,IAA5C,CAAiD,IAAjD,EAAuD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAK+B,eAAL,GAAqB,UAASnhB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQtH,KAAKkF,IAAL,CAAUC,QAAV,CAAmBE,6BAAnB,CAAiD9c,CAAjD,CAAR;AAA4D,GAAjI,CAAkI,KAAKohB,YAAL,GAAkB,UAASlhB,CAAT,EAAW;AAAC,QAAIF,IAAE,IAAIoJ,UAAJ,CAAepG,OAAO9C,CAAP,CAAf,EAAyB,EAAzB,CAAN,CAAmC,KAAKihB,eAAL,CAAqBnhB,CAArB;AAAwB,GAAzF,CAA0F,KAAKqhB,WAAL,GAAiB,UAASrhB,CAAT,EAAW;AAAC,SAAK+e,EAAL,GAAQ/e,CAAR;AAAU,GAAvC,CAAwC,KAAKkf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAE6gB,MAAT,IAAiB,WAApB,EAAgC;AAAC,WAAKH,eAAL,CAAqB1gB,EAAE6gB,MAAvB;AAA+B,KAAhE,MAAoE;AAAC,UAAG,OAAO7gB,EAAE,KAAF,CAAP,IAAiB,WAApB,EAAgC;AAAC,aAAK2gB,YAAL,CAAkB3gB,EAAE,KAAF,CAAlB;AAA4B,OAA7D,MAAiE;AAAC,YAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,eAAK2gB,YAAL,CAAkB3gB,CAAlB;AAAqB,SAA5C,MAAgD;AAAC,cAAG,OAAOA,EAAEof,GAAT,IAAc,WAAjB,EAA6B;AAAC,iBAAKwB,WAAL,CAAiB5gB,EAAEof,GAAnB;AAAwB;AAAC;AAAC;AAAC;AAAC;AAAC,CAAvqB,CAAwqB1gB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUQ,UAA5B,EAAuC1F,KAAKkF,IAAL,CAAUkC,UAAjD,EAA6DpH,KAAKkF,IAAL,CAAUS,YAAV,GAAuB,UAASpd,CAAT,EAAW;AAAC,MAAGA,MAAIZ,SAAJ,IAAe,OAAOY,EAAEue,GAAT,KAAe,WAAjC,EAA6C;AAAC,QAAI9d,IAAEgX,KAAKkF,IAAL,CAAUC,QAAV,CAAmBK,SAAnB,CAA6Bjd,EAAEue,GAA/B,CAAN,CAA0Cve,EAAE6f,GAAF,GAAM,OAAKpf,EAAEge,aAAF,EAAX;AAA6B,QAAK9B,IAAL,CAAUS,YAAV,CAAuBtd,UAAvB,CAAkCD,WAAlC,CAA8CuC,IAA9C,CAAmD,IAAnD,EAAyD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKmC,8BAAL,GAAoC,UAASrhB,CAAT,EAAW;AAAC,SAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQ7e,CAAR;AAAU,GAA9F,CAA+F,KAAKshB,wBAAL,GAA8B,UAASthB,CAAT,EAAWD,CAAX,EAAa;AAAC,QAAGC,IAAE,CAAF,IAAK,IAAEA,CAAV,EAAY;AAAC,YAAK,2CAAyCA,CAA9C;AAAgD,SAAIP,IAAE,MAAIO,CAAV,CAAY,KAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQpf,IAAEM,CAAV;AAAY,GAArK,CAAsK,KAAKwhB,iBAAL,GAAuB,UAASxhB,CAAT,EAAW;AAACA,QAAEA,EAAEwc,OAAF,CAAU,KAAV,EAAgB,EAAhB,CAAF,CAAsB,IAAIhd,IAAE,IAAEQ,EAAEK,MAAF,GAAS,CAAjB,CAAmB,IAAGb,KAAG,CAAN,EAAQ;AAACA,UAAE,CAAF;AAAI,UAAI,IAAIF,IAAE,CAAV,EAAYA,KAAGE,CAAf,EAAiBF,GAAjB,EAAqB;AAACU,WAAG,GAAH;AAAO,SAAIG,IAAE,EAAN,CAAS,KAAI,IAAIb,IAAE,CAAV,EAAYA,IAAEU,EAAEK,MAAF,GAAS,CAAvB,EAAyBf,KAAG,CAA5B,EAA8B;AAAC,UAAII,IAAEM,EAAE6C,MAAF,CAASvD,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAIW,IAAE2C,SAASlD,CAAT,EAAW,CAAX,EAAc4B,QAAd,CAAuB,EAAvB,CAAN,CAAiC,IAAGrB,EAAEI,MAAF,IAAU,CAAb,EAAe;AAACJ,YAAE,MAAIA,CAAN;AAAQ,YAAGA,CAAH;AAAK,UAAK8e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQ,MAAItf,CAAJ,GAAMW,CAAd;AAAgB,GAApS,CAAqS,KAAKshB,iBAAL,GAAuB,UAASzhB,CAAT,EAAW;AAAC,QAAIN,IAAE,EAAN,CAAS,KAAI,IAAIO,IAAE,CAAV,EAAYA,IAAED,EAAEK,MAAhB,EAAuBJ,GAAvB,EAA2B;AAAC,UAAGD,EAAEC,CAAF,KAAM,IAAT,EAAc;AAACP,aAAG,GAAH;AAAO,OAAtB,MAA0B;AAACA,aAAG,GAAH;AAAO;AAAC,UAAK8hB,iBAAL,CAAuB9hB,CAAvB;AAA0B,GAArI,CAAsI,KAAKgiB,aAAL,GAAmB,UAAS1hB,CAAT,EAAW;AAAC,QAAIC,IAAE,IAAI8I,KAAJ,CAAU/I,CAAV,CAAN,CAAmB,KAAI,IAAIN,IAAE,CAAV,EAAYA,IAAEM,CAAd,EAAgBN,GAAhB,EAAoB;AAACO,QAAEP,CAAF,IAAK,KAAL;AAAW,YAAOO,CAAP;AAAS,GAA3F,CAA4F,KAAKgf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAO/e,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,CAAP,IAAU,QAAV,IAAoBA,EAAE0f,WAAF,GAAgBlD,KAAhB,CAAsB,aAAtB,CAAvB,EAA4D;AAAC,WAAK+E,8BAAL,CAAoCvhB,CAApC;AAAuC,KAApG,MAAwG;AAAC,UAAG,OAAOA,EAAE6f,GAAT,IAAc,WAAjB,EAA6B;AAAC,aAAK0B,8BAAL,CAAoCvhB,EAAE6f,GAAtC;AAA2C,OAAzE,MAA6E;AAAC,YAAG,OAAO7f,EAAE4hB,GAAT,IAAc,WAAjB,EAA6B;AAAC,eAAKH,iBAAL,CAAuBzhB,EAAE4hB,GAAzB;AAA8B,SAA5D,MAAgE;AAAC,cAAG,OAAO5hB,EAAEoe,KAAT,IAAgB,WAAnB,EAA+B;AAAC,iBAAKsD,iBAAL,CAAuB1hB,EAAEoe,KAAzB;AAAgC;AAAC;AAAC;AAAC;AAAC;AAAC,CAAl3C,CAAm3Cjf,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUS,YAA5B,EAAyC3F,KAAKkF,IAAL,CAAUkC,UAAnD,EAA+DpH,KAAKkF,IAAL,CAAUU,cAAV,GAAyB,UAASrd,CAAT,EAAW;AAAC,MAAGA,MAAIZ,SAAJ,IAAe,OAAOY,EAAEue,GAAT,KAAe,WAAjC,EAA6C;AAAC,QAAI9d,IAAEgX,KAAKkF,IAAL,CAAUC,QAAV,CAAmBK,SAAnB,CAA6Bjd,EAAEue,GAA/B,CAAN,CAA0Cve,EAAE6f,GAAF,GAAMpf,EAAEge,aAAF,EAAN;AAAwB,QAAK9B,IAAL,CAAUU,cAAV,CAAyBvd,UAAzB,CAAoCD,WAApC,CAAgDuC,IAAhD,CAAqD,IAArD,EAA0DpC,CAA1D,EAA6D,KAAKof,EAAL,GAAQ,IAAR;AAAa,CAA/N,CAAgOjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUU,cAA5B,EAA2C5F,KAAKkF,IAAL,CAAU2C,iBAArD,EAAwE7H,KAAKkF,IAAL,CAAUW,OAAV,GAAkB,YAAU;AAAC7F,OAAKkF,IAAL,CAAUW,OAAV,CAAkBxd,UAAlB,CAA6BD,WAA7B,CAAyCuC,IAAzC,CAA8C,IAA9C,EAAoD,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKJ,IAAL,GAAU,MAAV;AAAiB,CAA/G,CAAgH7f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUW,OAA5B,EAAoC7F,KAAKkF,IAAL,CAAUkC,UAA9C,EAA0DpH,KAAKkF,IAAL,CAAUY,mBAAV,GAA8B,UAASrd,CAAT,EAAW;AAAC,MAAIF,IAAE,SAAFA,CAAE,CAASL,CAAT,EAAW;AAAC,QAAIM,IAAEN,EAAE4B,QAAF,CAAW,EAAX,CAAN,CAAqB,IAAGtB,EAAEK,MAAF,IAAU,CAAb,EAAe;AAACL,UAAE,MAAIA,CAAN;AAAQ,YAAOA,CAAP;AAAS,GAAxE,CAAyE,IAAIQ,IAAE,SAAFA,CAAE,CAASD,CAAT,EAAW;AAAC,QAAIJ,IAAE,EAAN,CAAS,IAAIH,IAAE,IAAImJ,UAAJ,CAAe5I,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIb,IAAEM,EAAEsB,QAAF,CAAW,CAAX,CAAN,CAAoB,IAAI9B,IAAE,IAAEE,EAAEW,MAAF,GAAS,CAAjB,CAAmB,IAAGb,KAAG,CAAN,EAAQ;AAACA,UAAE,CAAF;AAAI,SAAI+C,IAAE,EAAN,CAAS,KAAI,IAAIjD,IAAE,CAAV,EAAYA,IAAEE,CAAd,EAAgBF,GAAhB,EAAoB;AAACiD,WAAG,GAAH;AAAO,SAAEA,IAAE7C,CAAJ,CAAM,KAAI,IAAIJ,IAAE,CAAV,EAAYA,IAAEI,EAAEW,MAAF,GAAS,CAAvB,EAAyBf,KAAG,CAA5B,EAA8B;AAAC,UAAIgB,IAAEZ,EAAEmD,MAAF,CAASvD,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAGA,KAAGI,EAAEW,MAAF,GAAS,CAAf,EAAiB;AAACC,YAAE,MAAIA,CAAN;AAAQ,YAAGP,EAAE6C,SAAStC,CAAT,EAAW,CAAX,CAAF,CAAH;AAAoB,YAAOH,CAAP;AAAS,GAA/P,CAAgQqX,KAAKkF,IAAL,CAAUY,mBAAV,CAA8Bzd,UAA9B,CAAyCD,WAAzC,CAAqDuC,IAArD,CAA0D,IAA1D,EAAgE,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKiC,WAAL,GAAiB,UAAS1hB,CAAT,EAAW;AAAC,SAAKqf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAO,IAAP,CAAY,KAAK+c,EAAL,GAAQpf,CAAR;AAAU,GAAvF,CAAwF,KAAKkiB,iBAAL,GAAuB,UAASpiB,CAAT,EAAW;AAAC,QAAG,CAACA,EAAE+c,KAAF,CAAQ,WAAR,CAAJ,EAAyB;AAAC,YAAK,2BAAyB/c,CAA9B;AAAgC,SAAIF,IAAE,EAAN,CAAS,IAAII,IAAEF,EAAEmf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAIxe,IAAEyC,SAASlD,EAAE,CAAF,CAAT,IAAe,EAAf,GAAkBkD,SAASlD,EAAE,CAAF,CAAT,CAAxB,CAAuCJ,KAAGS,EAAEI,CAAF,CAAH,CAAQT,EAAE4E,MAAF,CAAS,CAAT,EAAW,CAAX,EAAc,KAAI,IAAItE,IAAE,CAAV,EAAYA,IAAEN,EAAEW,MAAhB,EAAuBL,GAAvB,EAA2B;AAACV,WAAGkB,EAAEd,EAAEM,CAAF,CAAF,CAAH;AAAW,UAAK+e,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKjd,CAAL,GAAO,IAAP,CAAY,KAAK+c,EAAL,GAAQxf,CAAR;AAAU,GAAvR,CAAwR,KAAKuiB,YAAL,GAAkB,UAAS7hB,CAAT,EAAW;AAAC,QAAIN,IAAE8X,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmBC,QAAnB,CAA4BhiB,CAA5B,CAAN,CAAqC,IAAGN,MAAI,EAAP,EAAU;AAAC,WAAKkiB,iBAAL,CAAuBliB,CAAvB;AAA0B,KAArC,MAAyC;AAAC,YAAK,4CAA0CM,CAA/C;AAAiD;AAAC,GAA/J,CAAgK,KAAKif,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG7e,MAAId,SAAP,EAAiB;AAAC,QAAG,OAAOc,CAAP,KAAW,QAAd,EAAuB;AAAC,UAAGA,EAAEsc,KAAF,CAAQ,iBAAR,CAAH,EAA8B;AAAC,aAAKqF,iBAAL,CAAuB3hB,CAAvB;AAA0B,OAAzD,MAA6D;AAAC,aAAK4hB,YAAL,CAAkB5hB,CAAlB;AAAqB;AAAC,KAA5G,MAAgH;AAAC,UAAGA,EAAEgiB,GAAF,KAAQ9iB,SAAX,EAAqB;AAAC,aAAKyiB,iBAAL,CAAuB3hB,EAAEgiB,GAAzB;AAA8B,OAApD,MAAwD;AAAC,YAAGhiB,EAAE2f,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,eAAKiiB,WAAL,CAAiBnhB,EAAE2f,GAAnB;AAAwB,SAA9C,MAAkD;AAAC,cAAG3f,EAAEiiB,IAAF,KAAS/iB,SAAZ,EAAsB;AAAC,iBAAK0iB,YAAL,CAAkB5hB,EAAEiiB,IAApB;AAA0B;AAAC;AAAC;AAAC;AAAC;AAAC,CAAtyC,CAAuyChjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUY,mBAA5B,EAAgD9F,KAAKkF,IAAL,CAAUkC,UAA1D,EAAsEpH,KAAKkF,IAAL,CAAUa,aAAV,GAAwB,UAAS/c,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUa,aAAV,CAAwB1d,UAAxB,CAAmCD,WAAnC,CAA+CuC,IAA/C,CAAoD,IAApD,EAA0D,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAK+B,eAAL,GAAqB,UAASnhB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKF,EAAL,GAAQtH,KAAKkF,IAAL,CAAUC,QAAV,CAAmBE,6BAAnB,CAAiD9c,CAAjD,CAAR;AAA4D,GAAjI,CAAkI,KAAKohB,YAAL,GAAkB,UAASlhB,CAAT,EAAW;AAAC,QAAIF,IAAE,IAAIoJ,UAAJ,CAAepG,OAAO9C,CAAP,CAAf,EAAyB,EAAzB,CAAN,CAAmC,KAAKihB,eAAL,CAAqBnhB,CAArB;AAAwB,GAAzF,CAA0F,KAAKqhB,WAAL,GAAiB,UAASrhB,CAAT,EAAW;AAAC,SAAK+e,EAAL,GAAQ/e,CAAR;AAAU,GAAvC,CAAwC,KAAKkf,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAE,KAAF,CAAP,IAAiB,WAApB,EAAgC;AAAC,WAAK2gB,YAAL,CAAkB3gB,EAAE,KAAF,CAAlB;AAA4B,KAA7D,MAAiE;AAAC,UAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,aAAK2gB,YAAL,CAAkB3gB,CAAlB;AAAqB,OAA5C,MAAgD;AAAC,YAAG,OAAOA,EAAEof,GAAT,IAAc,WAAjB,EAA6B;AAAC,eAAKwB,WAAL,CAAiB5gB,EAAEof,GAAnB;AAAwB;AAAC;AAAC;AAAC;AAAC,CAAvmB,CAAwmB1gB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUa,aAA5B,EAA0C/F,KAAKkF,IAAL,CAAUkC,UAApD,EAAgEpH,KAAKkF,IAAL,CAAUc,aAAV,GAAwB,UAAShd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUc,aAAV,CAAwB3d,UAAxB,CAAmCD,WAAnC,CAA+CuC,IAA/C,CAAoD,IAApD,EAAyD3B,CAAzD,EAA4D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAA7G,CAA8GjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUc,aAA5B,EAA0ChG,KAAKkF,IAAL,CAAU2C,iBAApD,EAAuE7H,KAAKkF,IAAL,CAAUe,gBAAV,GAA2B,UAASjd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUe,gBAAV,CAA2B5d,UAA3B,CAAsCD,WAAtC,CAAkDuC,IAAlD,CAAuD,IAAvD,EAA4D3B,CAA5D,EAA+D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAAnH,CAAoHjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUe,gBAA5B,EAA6CjG,KAAKkF,IAAL,CAAU2C,iBAAvD,EAA0E7H,KAAKkF,IAAL,CAAUgB,kBAAV,GAA6B,UAASld,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUgB,kBAAV,CAA6B7d,UAA7B,CAAwCD,WAAxC,CAAoDuC,IAApD,CAAyD,IAAzD,EAA8D3B,CAA9D,EAAiE,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAAvH,CAAwHjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUgB,kBAA5B,EAA+ClG,KAAKkF,IAAL,CAAU2C,iBAAzD,EAA4E7H,KAAKkF,IAAL,CAAUiB,gBAAV,GAA2B,UAASnd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUiB,gBAAV,CAA2B9d,UAA3B,CAAsCD,WAAtC,CAAkDuC,IAAlD,CAAuD,IAAvD,EAA4D3B,CAA5D,EAA+D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAAnH,CAAoHjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUiB,gBAA5B,EAA6CnG,KAAKkF,IAAL,CAAU2C,iBAAvD,EAA0E7H,KAAKkF,IAAL,CAAUkB,YAAV,GAAuB,UAASpd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUkB,YAAV,CAAuB/d,UAAvB,CAAkCD,WAAlC,CAA8CuC,IAA9C,CAAmD,IAAnD,EAAwD3B,CAAxD,EAA2D,KAAK2e,EAAL,GAAQ,IAAR;AAAa,CAA3G,CAA4GjgB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUkB,YAA5B,EAAyCpG,KAAKkF,IAAL,CAAU2C,iBAAnD,EAAsE7H,KAAKkF,IAAL,CAAUmB,UAAV,GAAqB,UAASrd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUmB,UAAV,CAAqBhe,UAArB,CAAgCD,WAAhC,CAA4CuC,IAA5C,CAAiD,IAAjD,EAAsD3B,CAAtD,EAAyD,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAK0B,SAAL,GAAe,UAAS9gB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKmD,IAAL,GAAUpiB,CAAV,CAAY,KAAKgC,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,CAAP,CAAwC,KAAKrD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,GAA1I,CAA2I,KAAKkd,gBAAL,GAAsB,YAAU;AAAC,QAAG,OAAO,KAAKkD,IAAZ,IAAkB,WAAlB,IAA+B,OAAO,KAAKpgB,CAAZ,IAAe,WAAjD,EAA6D;AAAC,WAAKogB,IAAL,GAAU,IAAI5L,IAAJ,EAAV,CAAqB,KAAKxU,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,CAAP,CAAwC,KAAKrD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,YAAO,KAAK+c,EAAZ;AAAe,GAAlM,CAAmM,IAAGte,MAAIrB,SAAP,EAAiB;AAAC,QAAGqB,EAAEmf,GAAF,KAAQxgB,SAAX,EAAqB;AAAC,WAAKogB,SAAL,CAAe/e,EAAEmf,GAAjB;AAAsB,KAA5C,MAAgD;AAAC,UAAG,OAAOnf,CAAP,IAAU,QAAV,IAAoBA,EAAE+b,KAAF,CAAQ,cAAR,CAAvB,EAA+C;AAAC,aAAKgD,SAAL,CAAe/e,CAAf;AAAkB,OAAlE,MAAsE;AAAC,YAAGA,EAAEof,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,eAAKugB,YAAL,CAAkBlf,EAAEof,GAApB;AAAyB,SAA/C,MAAmD;AAAC,cAAGpf,EAAE2hB,IAAF,KAAShjB,SAAZ,EAAsB;AAAC,iBAAK0hB,SAAL,CAAergB,EAAE2hB,IAAjB;AAAuB;AAAC;AAAC;AAAC;AAAC;AAAC,CAAtqB,CAAuqBjjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUmB,UAA5B,EAAuCrG,KAAKkF,IAAL,CAAUmD,eAAjD,EAAkErI,KAAKkF,IAAL,CAAUoB,kBAAV,GAA6B,UAAStd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUoB,kBAAV,CAA6Bje,UAA7B,CAAwCD,WAAxC,CAAoDuC,IAApD,CAAyD,IAAzD,EAA8D3B,CAA9D,EAAiE,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAKiD,UAAL,GAAgB,KAAhB,CAAsB,KAAKvB,SAAL,GAAe,UAAS9gB,CAAT,EAAW;AAAC,SAAKgf,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKmD,IAAL,GAAUpiB,CAAV,CAAY,KAAKgC,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,EAAgC,KAAKC,UAArC,CAAP,CAAwD,KAAKtD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,GAA1J,CAA2J,KAAKkd,gBAAL,GAAsB,YAAU;AAAC,QAAG,KAAKkD,IAAL,KAAYhjB,SAAZ,IAAuB,KAAK4C,CAAL,KAAS5C,SAAnC,EAA6C;AAAC,WAAKgjB,IAAL,GAAU,IAAI5L,IAAJ,EAAV,CAAqB,KAAKxU,CAAL,GAAO,KAAKke,UAAL,CAAgB,KAAKkC,IAArB,EAA0B,KAA1B,EAAgC,KAAKC,UAArC,CAAP,CAAwD,KAAKtD,EAAL,GAAQ4B,OAAO,KAAK3e,CAAZ,CAAR;AAAuB,YAAO,KAAK+c,EAAZ;AAAe,GAAlM,CAAmM,IAAGte,MAAIrB,SAAP,EAAiB;AAAC,QAAGqB,EAAEmf,GAAF,KAAQxgB,SAAX,EAAqB;AAAC,WAAKogB,SAAL,CAAe/e,EAAEmf,GAAjB;AAAsB,KAA5C,MAAgD;AAAC,UAAG,OAAOnf,CAAP,IAAU,QAAV,IAAoBA,EAAE+b,KAAF,CAAQ,cAAR,CAAvB,EAA+C;AAAC,aAAKgD,SAAL,CAAe/e,CAAf;AAAkB,OAAlE,MAAsE;AAAC,YAAGA,EAAEof,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,eAAKugB,YAAL,CAAkBlf,EAAEof,GAApB;AAAyB,SAA/C,MAAmD;AAAC,cAAGpf,EAAE2hB,IAAF,KAAShjB,SAAZ,EAAsB;AAAC,iBAAK0hB,SAAL,CAAergB,EAAE2hB,IAAjB;AAAuB;AAAC;AAAC;AAAC,SAAG3hB,EAAE6hB,MAAF,KAAW,IAAd,EAAmB;AAAC,WAAKD,UAAL,GAAgB,IAAhB;AAAqB;AAAC;AAAC,CAArwB,CAAswBljB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUoB,kBAA5B,EAA+CtG,KAAKkF,IAAL,CAAUmD,eAAzD,EAA0ErI,KAAKkF,IAAL,CAAUqB,WAAV,GAAsB,UAASvd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUqB,WAAV,CAAsBle,UAAtB,CAAiCD,WAAjC,CAA6CuC,IAA7C,CAAkD,IAAlD,EAAuD3B,CAAvD,EAA0D,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAKF,gBAAL,GAAsB,YAAU;AAAC,QAAIhf,IAAE,EAAN,CAAS,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE,KAAKihB,SAAL,CAAe3gB,MAA7B,EAAoCN,GAApC,EAAwC;AAAC,UAAIL,IAAE,KAAKshB,SAAL,CAAejhB,CAAf,CAAN,CAAwBE,KAAGP,EAAE8e,aAAF,EAAH;AAAqB,UAAKM,EAAL,GAAQ7e,CAAR,CAAU,OAAO,KAAK6e,EAAZ;AAAe,GAAzJ;AAA0J,CAAnQ,CAAoQ5f,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUqB,WAA5B,EAAwCvG,KAAKkF,IAAL,CAAUoE,qBAAlD,EAAyEtJ,KAAKkF,IAAL,CAAUsB,MAAV,GAAiB,UAASxd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUsB,MAAV,CAAiBne,UAAjB,CAA4BD,WAA5B,CAAwCuC,IAAxC,CAA6C,IAA7C,EAAkD3B,CAAlD,EAAqD,KAAK2e,EAAL,GAAQ,IAAR,CAAa,KAAKmD,QAAL,GAAc,IAAd,CAAmB,KAAKrD,gBAAL,GAAsB,YAAU;AAAC,QAAIlf,IAAE,IAAIgJ,KAAJ,EAAN,CAAkB,KAAI,IAAI9I,IAAE,CAAV,EAAYA,IAAE,KAAK+gB,SAAL,CAAe3gB,MAA7B,EAAoCJ,GAApC,EAAwC;AAAC,UAAIP,IAAE,KAAKshB,SAAL,CAAe/gB,CAAf,CAAN,CAAwBF,EAAEuC,IAAF,CAAO5C,EAAE8e,aAAF,EAAP;AAA0B,SAAG,KAAK8D,QAAL,IAAe,IAAlB,EAAuB;AAACviB,QAAEwiB,IAAF;AAAS,UAAKzD,EAAL,GAAQ/e,EAAE2C,IAAF,CAAO,EAAP,CAAR,CAAmB,OAAO,KAAKoc,EAAZ;AAAe,GAAjN,CAAkN,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAEgiB,QAAT,IAAmB,WAAnB,IAAgChiB,EAAEgiB,QAAF,IAAY,KAA/C,EAAqD;AAAC,WAAKF,QAAL,GAAc,KAAd;AAAoB;AAAC;AAAC,CAA1a,CAA2apjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUsB,MAA5B,EAAmCxG,KAAKkF,IAAL,CAAUoE,qBAA7C,EAAoEtJ,KAAKkF,IAAL,CAAUuB,eAAV,GAA0B,UAASzd,CAAT,EAAW;AAACgX,OAAKkF,IAAL,CAAUuB,eAAV,CAA0Bpe,UAA1B,CAAqCD,WAArC,CAAiDuC,IAAjD,CAAsD,IAAtD,EAA4D,KAAKgd,EAAL,GAAQ,IAAR,CAAa,KAAKL,EAAL,GAAQ,EAAR,CAAW,KAAK2D,UAAL,GAAgB,IAAhB,CAAqB,KAAKC,UAAL,GAAgB,IAAhB,CAAqB,KAAKC,aAAL,GAAmB,UAAS5iB,CAAT,EAAWE,CAAX,EAAaP,CAAb,EAAe;AAAC,SAAKyf,EAAL,GAAQlf,CAAR,CAAU,KAAKwiB,UAAL,GAAgB1iB,CAAhB,CAAkB,KAAK2iB,UAAL,GAAgBhjB,CAAhB,CAAkB,IAAG,KAAK+iB,UAAR,EAAmB;AAAC,WAAK3D,EAAL,GAAQ,KAAK4D,UAAL,CAAgBlE,aAAhB,EAAR,CAAwC,KAAKO,IAAL,GAAU,IAAV,CAAe,KAAKC,UAAL,GAAgB,IAAhB;AAAqB,KAAhG,MAAoG;AAAC,WAAKF,EAAL,GAAQ,IAAR,CAAa,KAAKC,IAAL,GAAUrf,EAAE8e,aAAF,EAAV,CAA4B,KAAKO,IAAL,GAAU,KAAKA,IAAL,CAAUvC,OAAV,CAAkB,KAAlB,EAAwBvc,CAAxB,CAAV,CAAqC,KAAK+e,UAAL,GAAgB,KAAhB;AAAsB;AAAC,GAA3R,CAA4R,KAAKC,gBAAL,GAAsB,YAAU;AAAC,WAAO,KAAKH,EAAZ;AAAe,GAAhD,CAAiD,IAAG,OAAOte,CAAP,IAAU,WAAb,EAAyB;AAAC,QAAG,OAAOA,EAAE4d,GAAT,IAAc,WAAjB,EAA6B;AAAC,WAAKe,EAAL,GAAQ3e,EAAE4d,GAAV;AAAc,SAAG,OAAO5d,EAAE6d,QAAT,IAAmB,WAAtB,EAAkC;AAAC,WAAKoE,UAAL,GAAgBjiB,EAAE6d,QAAlB;AAA2B,SAAG,OAAO7d,EAAE8d,GAAT,IAAc,WAAjB,EAA6B;AAAC,WAAKoE,UAAL,GAAgBliB,EAAE8d,GAAlB,CAAsB,KAAKqE,aAAL,CAAmB,KAAKF,UAAxB,EAAmC,KAAKtD,EAAxC,EAA2C,KAAKuD,UAAhD;AAA4D;AAAC;AAAC,CAAvuB,CAAwuBxjB,MAAME,IAAN,CAAWC,MAAX,CAAkBmY,KAAKkF,IAAL,CAAUuB,eAA5B,EAA4CzG,KAAKkF,IAAL,CAAUkC,UAAtD;AAC5ne,IAAIgE,UAAQ,IAAI,YAAU,CAAE,CAAhB,EAAZ,CAA6BA,QAAQC,QAAR,GAAiB,UAAS5iB,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAGP,EAAE4C,MAAF,CAASrC,IAAE,CAAX,EAAa,CAAb,KAAiB,GAApB,EAAwB;AAAC,WAAO,CAAP;AAAS,OAAIT,IAAE6C,SAAS3C,EAAE4C,MAAF,CAASrC,IAAE,CAAX,EAAa,CAAb,CAAT,CAAN,CAAgC,IAAGT,KAAG,CAAN,EAAQ;AAAC,WAAO,CAAC,CAAR;AAAU,OAAG,IAAEA,CAAF,IAAKA,IAAE,EAAV,EAAa;AAAC,WAAOA,IAAE,CAAT;AAAW,UAAO,CAAC,CAAR;AAAU,CAAvJ,CAAwJ6iB,QAAQE,IAAR,GAAa,UAAS7iB,CAAT,EAAWF,CAAX,EAAa;AAAC,MAAIS,IAAEoiB,QAAQC,QAAR,CAAiB5iB,CAAjB,EAAmBF,CAAnB,CAAN,CAA4B,IAAGS,IAAE,CAAL,EAAO;AAAC,WAAM,EAAN;AAAS,UAAOP,EAAE4C,MAAF,CAAS9C,IAAE,CAAX,EAAaS,IAAE,CAAf,CAAP;AAAyB,CAAjG,CAAkGoiB,QAAQG,QAAR,GAAiB,UAASrjB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIP,CAAJ,EAAMF,CAAN,CAAQE,IAAE2iB,QAAQE,IAAR,CAAapjB,CAAb,EAAec,CAAf,CAAF,CAAoB,IAAGP,KAAG,EAAN,EAAS;AAAC,WAAO,CAAC,CAAR;AAAU,OAAGA,EAAE4C,MAAF,CAAS,CAAT,EAAW,CAAX,MAAgB,GAAnB,EAAuB;AAAC9C,QAAE,IAAIoJ,UAAJ,CAAelJ,EAAE4C,MAAF,CAAS,CAAT,CAAf,EAA2B,EAA3B,CAAF;AAAiC,GAAzD,MAA6D;AAAC9C,QAAE,IAAIoJ,UAAJ,CAAelJ,CAAf,EAAiB,EAAjB,CAAF;AAAuB,UAAOF,EAAEyP,QAAF,EAAP;AAAoB,CAAxL,CAAyLoT,QAAQI,OAAR,GAAgB,UAAS/iB,CAAT,EAAWF,CAAX,EAAa;AAAC,MAAIS,IAAEoiB,QAAQC,QAAR,CAAiB5iB,CAAjB,EAAmBF,CAAnB,CAAN,CAA4B,IAAGS,IAAE,CAAL,EAAO;AAAC,WAAOA,CAAP;AAAS,UAAOT,IAAE,CAACS,IAAE,CAAH,IAAM,CAAf;AAAiB,CAA5F,CAA6FoiB,QAAQK,IAAR,GAAa,UAASvjB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIP,IAAE2iB,QAAQI,OAAR,CAAgBtjB,CAAhB,EAAkBc,CAAlB,CAAN,CAA2B,IAAIT,IAAE6iB,QAAQG,QAAR,CAAiBrjB,CAAjB,EAAmBc,CAAnB,CAAN,CAA4B,OAAOd,EAAEmD,MAAF,CAAS5C,CAAT,EAAWF,IAAE,CAAb,CAAP;AAAuB,CAAzG,CAA0G6iB,QAAQM,MAAR,GAAe,UAASnjB,CAAT,EAAWS,CAAX,EAAa;AAAC,SAAOT,EAAE8C,MAAF,CAASrC,CAAT,EAAW,CAAX,IAAcoiB,QAAQE,IAAR,CAAa/iB,CAAb,EAAeS,CAAf,CAAd,GAAgCoiB,QAAQK,IAAR,CAAaljB,CAAb,EAAeS,CAAf,CAAvC;AAAyD,CAAtF,CAAuFoiB,QAAQO,iBAAR,GAA0B,UAASzjB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIP,IAAE2iB,QAAQI,OAAR,CAAgBtjB,CAAhB,EAAkBc,CAAlB,CAAN,CAA2B,IAAIT,IAAE6iB,QAAQG,QAAR,CAAiBrjB,CAAjB,EAAmBc,CAAnB,CAAN,CAA4B,OAAOP,IAAEF,IAAE,CAAX;AAAa,CAA5G,CAA6G6iB,QAAQQ,WAAR,GAAoB,UAASpjB,CAAT,EAAWR,CAAX,EAAa;AAAC,MAAIW,IAAEyiB,OAAN,CAAc,IAAItjB,IAAE,IAAIyJ,KAAJ,EAAN,CAAkB,IAAI3I,IAAED,EAAE6iB,OAAF,CAAUhjB,CAAV,EAAYR,CAAZ,CAAN,CAAqB,IAAGQ,EAAE6C,MAAF,CAASrD,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAACF,MAAEgD,IAAF,CAAOlC,IAAE,CAAT;AAAY,GAApC,MAAwC;AAACd,MAAEgD,IAAF,CAAOlC,CAAP;AAAU,OAAIE,IAAEH,EAAE4iB,QAAF,CAAW/iB,CAAX,EAAaR,CAAb,CAAN,CAAsB,IAAIS,IAAEG,CAAN,CAAQ,IAAIV,IAAE,CAAN,CAAQ,OAAM,CAAN,EAAQ;AAAC,QAAIK,IAAEI,EAAEgjB,iBAAF,CAAoBnjB,CAApB,EAAsBC,CAAtB,CAAN,CAA+B,IAAGF,KAAG,IAAH,IAAUA,IAAEK,CAAF,IAAME,IAAE,CAArB,EAAyB;AAAC;AAAM,SAAGZ,KAAG,GAAN,EAAU;AAAC;AAAM,OAAE4C,IAAF,CAAOvC,CAAP,EAAUE,IAAEF,CAAF,CAAIL;AAAI,UAAOJ,CAAP;AAAS,CAApS,CAAqSsjB,QAAQS,cAAR,GAAuB,UAAS3jB,CAAT,EAAWK,CAAX,EAAaC,CAAb,EAAe;AAAC,MAAIC,IAAE2iB,QAAQQ,WAAR,CAAoB1jB,CAApB,EAAsBK,CAAtB,CAAN,CAA+B,OAAOE,EAAED,CAAF,CAAP;AAAY,CAAlF,CAAmF4iB,QAAQU,YAAR,GAAqB,UAAStjB,CAAT,EAAWN,CAAX,EAAaO,CAAb,EAAeG,CAAf,EAAiB;AAAC,MAAId,IAAEsjB,OAAN,CAAc,IAAIpjB,CAAJ,EAAMO,CAAN,CAAQ,IAAGE,EAAEI,MAAF,IAAU,CAAb,EAAe;AAAC,QAAGD,MAAIjB,SAAP,EAAiB;AAAC,UAAGa,EAAE6C,MAAF,CAASnD,CAAT,EAAW,CAAX,MAAgBU,CAAnB,EAAqB;AAAC,cAAK,iCAA+BJ,EAAE6C,MAAF,CAASnD,CAAT,EAAW,CAAX,CAA/B,GAA6C,IAA7C,GAAkDU,CAAvD;AAAyD;AAAC,YAAOV,CAAP;AAAS,OAAEO,EAAEwc,KAAF,EAAF,CAAY1c,IAAET,EAAE8jB,WAAF,CAAcpjB,CAAd,EAAgBN,CAAhB,CAAF,CAAqB,OAAOJ,EAAEgkB,YAAF,CAAetjB,CAAf,EAAiBD,EAAEP,CAAF,CAAjB,EAAsBS,CAAtB,EAAwBG,CAAxB,CAAP;AAAkC,CAA3P,CAA4PwiB,QAAQW,YAAR,GAAqB,UAAS7jB,CAAT,EAAWO,CAAX,EAAaF,CAAb,EAAeP,CAAf,EAAiB;AAAC,MAAIQ,IAAE4iB,OAAN,CAAc,IAAIpiB,IAAER,EAAEsjB,YAAF,CAAe5jB,CAAf,EAAiBO,CAAjB,EAAmBF,CAAnB,CAAN,CAA4B,IAAGS,MAAIrB,SAAP,EAAiB;AAAC,UAAK,2BAAL;AAAiC,OAAGK,MAAIL,SAAP,EAAiB;AAAC,QAAGO,EAAEmD,MAAF,CAASrC,CAAT,EAAW,CAAX,KAAehB,CAAlB,EAAoB;AAAC,YAAK,iCAA+BE,EAAEmD,MAAF,CAASrC,CAAT,EAAW,CAAX,CAA/B,GAA6C,IAA7C,GAAkDhB,CAAvD;AAAyD;AAAC,UAAOQ,EAAEkjB,MAAF,CAASxjB,CAAT,EAAWc,CAAX,CAAP;AAAqB,CAA1P,CAA2PoiB,QAAQY,UAAR,GAAmB,UAASxjB,CAAT,EAAWC,CAAX,EAAaF,CAAb,EAAeT,CAAf,EAAiBc,CAAjB,EAAmB;AAAC,MAAIZ,IAAEojB,OAAN,CAAc,IAAIpiB,CAAJ,EAAMd,CAAN,CAAQc,IAAEhB,EAAE8jB,YAAF,CAAetjB,CAAf,EAAiBC,CAAjB,EAAmBF,CAAnB,EAAqBT,CAArB,CAAF,CAA0B,IAAGkB,MAAIrB,SAAP,EAAiB;AAAC,UAAK,2BAAL;AAAiC,OAAEK,EAAEyjB,IAAF,CAAOjjB,CAAP,EAASQ,CAAT,CAAF,CAAc,IAAGJ,MAAI,IAAP,EAAY;AAACV,QAAEA,EAAEmD,MAAF,CAAS,CAAT,CAAF;AAAc,UAAOnD,CAAP;AAAS,CAA5L,CAA6LkjB,QAAQa,WAAR,GAAoB,UAASzjB,CAAT,EAAW;AAAC,MAAIT,IAAE,SAAFA,CAAE,CAASQ,CAAT,EAAWS,CAAX,EAAa;AAAC,QAAGT,EAAEM,MAAF,IAAUG,CAAb,EAAe;AAAC,aAAOT,CAAP;AAAS,YAAO,IAAIgJ,KAAJ,CAAUvI,IAAET,EAAEM,MAAJ,GAAW,CAArB,EAAwBqC,IAAxB,CAA6B,GAA7B,IAAkC3C,CAAzC;AAA2C,GAAxF,CAAyF,IAAIO,IAAE,EAAN,CAAS,IAAIQ,IAAEd,EAAE6C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAIrD,IAAEoD,SAAS9B,CAAT,EAAW,EAAX,CAAN,CAAqBR,EAAE,CAAF,IAAK,IAAIyC,MAAJ,CAAWkC,KAAKc,KAAL,CAAWvG,IAAE,EAAb,CAAX,CAAL,CAAkCc,EAAE,CAAF,IAAK,IAAIyC,MAAJ,CAAWvD,IAAE,EAAb,CAAL,CAAsB,IAAI+C,IAAEvC,EAAE6C,MAAF,CAAS,CAAT,CAAN,CAAkB,IAAItC,IAAE,EAAN,CAAS,KAAI,IAAIjB,IAAE,CAAV,EAAYA,IAAEiD,EAAElC,MAAF,GAAS,CAAvB,EAAyBf,GAAzB,EAA6B;AAACiB,MAAE+B,IAAF,CAAOM,SAASL,EAAEM,MAAF,CAASvD,IAAE,CAAX,EAAa,CAAb,CAAT,EAAyB,EAAzB,CAAP;AAAqC,OAAIa,IAAE,EAAN,CAAS,IAAIT,IAAE,EAAN,CAAS,KAAI,IAAIJ,IAAE,CAAV,EAAYA,IAAEiB,EAAEF,MAAhB,EAAuBf,GAAvB,EAA2B;AAAC,QAAGiB,EAAEjB,CAAF,IAAK,GAAR,EAAY;AAACI,UAAEA,IAAEH,EAAE,CAACgB,EAAEjB,CAAF,IAAK,GAAN,EAAWgC,QAAX,CAAoB,CAApB,CAAF,EAAyB,CAAzB,CAAJ;AAAgC,KAA7C,MAAiD;AAAC5B,UAAEA,IAAEH,EAAE,CAACgB,EAAEjB,CAAF,IAAK,GAAN,EAAWgC,QAAX,CAAoB,CAApB,CAAF,EAAyB,CAAzB,CAAJ,CAAgCnB,EAAEmC,IAAF,CAAO,IAAIS,MAAJ,CAAWH,SAASlD,CAAT,EAAW,CAAX,CAAX,CAAP,EAAkCA,IAAE,EAAF;AAAK;AAAC,OAAIkB,IAAEN,EAAEoC,IAAF,CAAO,GAAP,CAAN,CAAkB,IAAGvC,EAAEE,MAAF,GAAS,CAAZ,EAAc;AAACO,QAAEA,IAAE,GAAF,GAAMT,EAAEuC,IAAF,CAAO,GAAP,CAAR;AAAoB,UAAO9B,CAAP;AAAS,CAAviB,CAAwiBgiB,QAAQc,IAAR,GAAa,UAAS7hB,CAAT,EAAW5B,CAAX,EAAaK,CAAb,EAAehB,CAAf,EAAiB;AAAC,MAAIuB,IAAE+hB,OAAN,CAAc,IAAIziB,IAAEU,EAAEoiB,IAAR,CAAa,IAAIxb,IAAE5G,EAAE6iB,IAAR,CAAa,IAAI7f,IAAEhD,EAAEuiB,WAAR,CAAoB,IAAIpjB,IAAE6B,CAAN,CAAQ,IAAGA,aAAa2V,KAAKkF,IAAL,CAAUkC,UAA1B,EAAqC;AAAC5e,QAAE6B,EAAE2c,aAAF,EAAF;AAAoB,OAAI1c,IAAE,SAAFA,CAAE,CAAS0F,CAAT,EAAWpH,CAAX,EAAa;AAAC,QAAGoH,EAAEnH,MAAF,IAAUD,IAAE,CAAf,EAAiB;AAAC,aAAOoH,CAAP;AAAS,KAA3B,MAA+B;AAAC,UAAIxD,IAAEwD,EAAE3E,MAAF,CAAS,CAAT,EAAWzC,CAAX,IAAc,WAAd,GAA0BoH,EAAEnH,MAAF,GAAS,CAAnC,GAAqC,UAArC,GAAgDmH,EAAE3E,MAAF,CAAS2E,EAAEnH,MAAF,GAASD,CAAlB,EAAoBA,CAApB,CAAtD,CAA6E,OAAO4D,CAAP;AAAS;AAAC,GAA3I,CAA4I,IAAG/D,MAAId,SAAP,EAAiB;AAACc,QAAE,EAAC0jB,kBAAiB,EAAlB,EAAF;AAAwB,OAAGrjB,MAAInB,SAAP,EAAiB;AAACmB,QAAE,CAAF;AAAI,OAAGhB,MAAIH,SAAP,EAAiB;AAACG,QAAE,EAAF;AAAK,OAAIwE,IAAE7D,EAAE0jB,gBAAR,CAAyB,IAAG3jB,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAGf,KAAG,IAAN,EAAW;AAAC,aAAOD,IAAE,iBAAT;AAA2B,KAAvC,MAA2C;AAAC,aAAOA,IAAE,gBAAT;AAA0B;AAAC,OAAGU,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,OAAOhB,IAAE,UAAF,GAAawC,EAAEvC,CAAF,EAAIuE,CAAJ,CAAb,GAAoB,IAA3B;AAAgC,OAAG9D,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,OAAOhB,IAAE,YAAF,GAAewC,EAAEvC,CAAF,EAAIuE,CAAJ,CAAf,GAAsB,IAA7B;AAAkC,OAAG9D,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIf,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAGO,EAAE+iB,SAAF,CAAYrkB,CAAZ,CAAH,EAAkB;AAAC,UAAIgB,IAAEjB,IAAE,6BAAR,CAAsCiB,IAAEA,IAAEkH,EAAElI,CAAF,EAAIU,CAAJ,EAAM,CAAN,EAAQX,IAAE,IAAV,CAAJ,CAAoB,OAAOiB,CAAP;AAAS,KAAtF,MAA0F;AAAC,aAAOjB,IAAE,cAAF,GAAiBwC,EAAEvC,CAAF,EAAIuE,CAAJ,CAAjB,GAAwB,IAA/B;AAAoC;AAAC,OAAG9D,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,QAAT;AAAkB,OAAGU,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIiC,IAAEpC,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAIE,IAAEgX,KAAKkF,IAAL,CAAUC,QAAV,CAAmB8B,WAAnB,CAA+Blc,CAA/B,CAAN,CAAwC,IAAIzB,IAAE0W,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmB8B,QAAnB,CAA4BrjB,CAA5B,CAAN,CAAqC,IAAIT,IAAES,EAAEgc,OAAF,CAAU,KAAV,EAAgB,GAAhB,CAAN,CAA2B,IAAG1b,KAAG,EAAN,EAAS;AAAC,aAAOxB,IAAE,mBAAF,GAAsBwB,CAAtB,GAAwB,IAAxB,GAA6Bf,CAA7B,GAA+B,KAAtC;AAA4C,KAAtD,MAA0D;AAAC,aAAOT,IAAE,oBAAF,GAAuBS,CAAvB,GAAyB,KAAhC;AAAsC;AAAC,OAAGC,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,cAAF,GAAiBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAjB,GAAmC,KAA1C;AAAgD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,mBAAF,GAAsBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAtB,GAAwC,KAA/C;AAAqD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,iBAAF,GAAoBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAApB,GAAsC,KAA7C;AAAmD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,aAAF,GAAgBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAhB,GAAkC,KAAzC;AAA+C,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,UAAF,GAAawkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAAb,GAA+B,IAAtC;AAA2C,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,WAAOhB,IAAE,kBAAF,GAAqBwkB,UAAU3jB,EAAEH,CAAF,EAAIM,CAAJ,CAAV,CAArB,GAAuC,IAA9C;AAAmD,OAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAGN,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,aAAOhB,IAAE,eAAT;AAAyB,SAAIiB,IAAEjB,IAAE,YAAR,CAAqB,IAAII,IAAEmE,EAAE7D,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAId,IAAES,CAAN,CAAQ,IAAG,CAACP,EAAEW,MAAF,IAAU,CAAV,IAAaX,EAAEW,MAAF,IAAU,CAAxB,KAA4BL,EAAE6C,MAAF,CAASnD,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAA9C,IAAoDM,EAAE6C,MAAF,CAASnD,EAAEA,EAAEW,MAAF,GAAS,CAAX,CAAT,EAAuB,CAAvB,KAA2B,IAAlF,EAAuF;AAAC,UAAIS,IAAED,EAAEkjB,OAAF,CAAU5jB,EAAEH,CAAF,EAAIN,EAAE,CAAF,CAAJ,CAAV,CAAN,CAA2B,IAAIuC,IAAE+hB,KAAKrhB,KAAL,CAAWqhB,KAAKriB,SAAL,CAAe1B,CAAf,CAAX,CAAN,CAAoCgC,EAAEgiB,WAAF,GAAcnjB,CAAd,CAAgBtB,IAAEyC,CAAF;AAAI,UAAI,IAAIgC,IAAE,CAAV,EAAYA,IAAEvE,EAAEW,MAAhB,EAAuB4D,GAAvB,EAA2B;AAAC1D,UAAEA,IAAEkH,EAAEzH,CAAF,EAAIR,CAAJ,EAAME,EAAEuE,CAAF,CAAN,EAAW3E,IAAE,IAAb,CAAJ;AAAuB,YAAOiB,CAAP;AAAS,OAAGP,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,QAAIC,IAAEjB,IAAE,OAAR,CAAgB,IAAII,IAAEmE,EAAE7D,CAAF,EAAIM,CAAJ,CAAN,CAAa,KAAI,IAAI2D,IAAE,CAAV,EAAYA,IAAEvE,EAAEW,MAAhB,EAAuB4D,GAAvB,EAA2B;AAAC1D,UAAEA,IAAEkH,EAAEzH,CAAF,EAAIC,CAAJ,EAAMP,EAAEuE,CAAF,CAAN,EAAW3E,IAAE,IAAb,CAAJ;AAAuB,YAAOiB,CAAP;AAAS,OAAIgH,IAAE3E,SAAS5C,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAAN,CAAiC,IAAG,CAACiH,IAAE,GAAH,KAAS,CAAZ,EAAc;AAAC,QAAI3G,IAAE2G,IAAE,EAAR,CAAW,IAAG,CAACA,IAAE,EAAH,KAAQ,CAAX,EAAa;AAAC,UAAIhH,IAAEjB,IAAE,GAAF,GAAMsB,CAAN,GAAQ,KAAd,CAAoB,IAAIlB,IAAEmE,EAAE7D,CAAF,EAAIM,CAAJ,CAAN,CAAa,KAAI,IAAI2D,IAAE,CAAV,EAAYA,IAAEvE,EAAEW,MAAhB,EAAuB4D,GAAvB,EAA2B;AAAC1D,YAAEA,IAAEkH,EAAEzH,CAAF,EAAIC,CAAJ,EAAMP,EAAEuE,CAAF,CAAN,EAAW3E,IAAE,IAAb,CAAJ;AAAuB,cAAOiB,CAAP;AAAS,KAA3G,MAA+G;AAAC,UAAIhB,IAAEY,EAAEH,CAAF,EAAIM,CAAJ,CAAN,CAAa,IAAGf,EAAEsD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,UAAlB,EAA6B;AAACtD,YAAEukB,UAAUvkB,CAAV,CAAF;AAAe,WAAGU,EAAEgkB,WAAF,KAAgB,gBAAhB,IAAkCrjB,KAAG,CAAxC,EAA0C;AAACrB,YAAEukB,UAAUvkB,CAAV,CAAF;AAAe,WAAIgB,IAAEjB,IAAE,GAAF,GAAMsB,CAAN,GAAQ,IAAR,GAAarB,CAAb,GAAe,IAArB,CAA0B,OAAOgB,CAAP;AAAS;AAAC,UAAOjB,IAAE,UAAF,GAAaU,EAAE6C,MAAF,CAASvC,CAAT,EAAW,CAAX,CAAb,GAA2B,IAA3B,GAAgCH,EAAEH,CAAF,EAAIM,CAAJ,CAAhC,GAAuC,IAA9C;AAAmD,CAAv0E,CAAw0EsiB,QAAQgB,SAAR,GAAkB,UAAS5jB,CAAT,EAAW;AAAC,MAAIN,IAAEkjB,OAAN,CAAc,IAAG5iB,EAAEK,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAAC,WAAO,KAAP;AAAa,OAAIJ,IAAEP,EAAEqjB,QAAF,CAAW/iB,CAAX,EAAa,CAAb,CAAN,CAAsB,IAAID,IAAEC,EAAE6C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAN,CAAoB,IAAIrD,IAAEE,EAAEojB,IAAF,CAAO9iB,CAAP,EAAS,CAAT,CAAN,CAAkB,IAAIQ,IAAER,EAAEK,MAAF,GAASN,EAAEM,MAAX,GAAkBb,EAAEa,MAA1B,CAAiC,IAAGG,KAAGP,IAAE,CAAR,EAAU;AAAC,WAAO,IAAP;AAAY,UAAO,KAAP;AAAa,CAA5M,CAA6M2iB,QAAQmB,OAAR,GAAgB,UAASvjB,CAAT,EAAW;AAAC,MAAIP,IAAEuX,KAAKkF,IAAX,CAAgB,IAAGlF,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBmhB,KAAjB,CAAuB1jB,CAAvB,CAAH,EAA6B;AAACA,QAAEP,EAAE0c,QAAF,CAAW8B,WAAX,CAAuBje,CAAvB,CAAF;AAA4B,OAAIT,IAAEE,EAAE6hB,IAAF,CAAOC,GAAP,CAAW8B,QAAX,CAAoBrjB,CAApB,CAAN,CAA6B,IAAGT,MAAI,EAAP,EAAU;AAACA,QAAES,CAAF;AAAI,UAAOT,CAAP;AAAS,CAA3J;AACp8J,IAAIyX,IAAJ,CAAS,IAAG,OAAOA,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UA2EpCA,IA3EoC,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKpY,IAAZ,IAAkB,WAAlB,IAA+B,CAACoY,KAAKpY,IAAxC,EAA6C;AAACoY,OAAKpY,IAAL,GAAU,EAAV;AAAa,MAAKA,IAAL,CAAU2D,MAAV,GAAiB,YAAU,CAAE,CAA7B,CAA8B,SAASohB,OAAT,GAAkB,CAAE,UAASC,KAAT,CAAe1kB,CAAf,EAAiB;AAAC,MAAIK,IAAE,IAAIgJ,KAAJ,EAAN,CAAkB,KAAI,IAAI9I,IAAE,CAAV,EAAYA,IAAEP,EAAEW,MAAhB,EAAuBJ,GAAvB,EAA2B;AAACF,MAAEE,CAAF,IAAKP,EAAEuD,UAAF,CAAahD,CAAb,CAAL;AAAqB,UAAOF,CAAP;AAAS,UAASskB,KAAT,CAAetkB,CAAf,EAAiB;AAAC,MAAIL,IAAE,EAAN,CAAS,KAAI,IAAIO,IAAE,CAAV,EAAYA,IAAEF,EAAEM,MAAhB,EAAuBJ,GAAvB,EAA2B;AAACP,QAAEA,IAAEqD,OAAOC,YAAP,CAAoBjD,EAAEE,CAAF,CAApB,CAAJ;AAA8B,UAAOP,CAAP;AAAS,UAAS4kB,OAAT,CAAiBvkB,CAAjB,EAAmB;AAAC,MAAIC,IAAE,EAAN,CAAS,KAAI,IAAIN,IAAE,CAAV,EAAYA,IAAEK,EAAEM,MAAhB,EAAuBX,GAAvB,EAA2B;AAAC,QAAIO,IAAEF,EAAEL,CAAF,EAAK4B,QAAL,CAAc,EAAd,CAAN,CAAwB,IAAGrB,EAAEI,MAAF,IAAU,CAAb,EAAe;AAACJ,UAAE,MAAIA,CAAN;AAAQ,SAAED,IAAEC,CAAJ;AAAM,UAAOD,CAAP;AAAS,UAAS0gB,MAAT,CAAgBlgB,CAAhB,EAAkB;AAAC,SAAO8jB,QAAQF,MAAM5jB,CAAN,CAAR,CAAP;AAAyB,UAAS+jB,MAAT,CAAgB/jB,CAAhB,EAAkB;AAAC,SAAOkI,QAAQgY,OAAOlgB,CAAP,CAAR,CAAP;AAA0B,UAASgkB,OAAT,CAAiBhkB,CAAjB,EAAmB;AAAC,SAAOikB,UAAU/b,QAAQgY,OAAOlgB,CAAP,CAAR,CAAV,CAAP;AAAqC,UAASkkB,OAAT,CAAiBlkB,CAAjB,EAAmB;AAAC,SAAO6jB,MAAMvb,QAAQ6b,UAAUnkB,CAAV,CAAR,CAAN,CAAP;AAAoC,UAASikB,SAAT,CAAmBjkB,CAAnB,EAAqB;AAACA,MAAEA,EAAEgc,OAAF,CAAU,KAAV,EAAgB,EAAhB,CAAF,CAAsBhc,IAAEA,EAAEgc,OAAF,CAAU,KAAV,EAAgB,GAAhB,CAAF,CAAuBhc,IAAEA,EAAEgc,OAAF,CAAU,KAAV,EAAgB,GAAhB,CAAF,CAAuB,OAAOhc,CAAP;AAAS,UAASmkB,SAAT,CAAmBnkB,CAAnB,EAAqB;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACG,QAAEA,IAAE,IAAJ;AAAS,GAA3B,MAA+B;AAAC,QAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACG,UAAEA,IAAE,GAAJ;AAAQ;AAAC,OAAEA,EAAEgc,OAAF,CAAU,IAAV,EAAe,GAAf,CAAF,CAAsBhc,IAAEA,EAAEgc,OAAF,CAAU,IAAV,EAAe,GAAf,CAAF,CAAsB,OAAOhc,CAAP;AAAS,UAASokB,SAAT,CAAmBpkB,CAAnB,EAAqB;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAACG,QAAE,MAAIA,CAAN;AAAQ,UAAOikB,UAAU/b,QAAQlI,CAAR,CAAV,CAAP;AAA6B,UAASqkB,SAAT,CAAmBrkB,CAAnB,EAAqB;AAAC,SAAOoI,SAAS+b,UAAUnkB,CAAV,CAAT,CAAP;AAA8B,KAAIskB,UAAJ,EAAeC,UAAf,CAA0B,IAAG,OAAOC,MAAP,KAAgB,UAAnB,EAA8B;AAAC,UA0C1jCF,UA1C0jC,gBAAW,oBAAStkB,CAAT,EAAW;AAAC,WAAOikB,UAAU,IAAIO,MAAJ,CAAWxkB,CAAX,EAAa,MAAb,EAAqBc,QAArB,CAA8B,QAA9B,CAAV,CAAP;AAA0D,GAAjF,CAAkF,QA2C5oCyjB,UA3C4oC,gBAAW,oBAASvkB,CAAT,EAAW;AAAC,WAAO,IAAIwkB,MAAJ,CAAWL,UAAUnkB,CAAV,CAAX,EAAwB,QAAxB,EAAkCc,QAAlC,CAA2C,MAA3C,CAAP;AAA0D,GAAjF;AAAkF,CAAnM,MAAuM;AAAC,UA0CnuCwjB,UA1CmuC,gBAAW,oBAAStkB,CAAT,EAAW;AAAC,WAAOokB,UAAUK,YAAYC,sBAAsB1kB,CAAtB,CAAZ,CAAV,CAAP;AAAwD,GAA/E,CAAgF,QA2CnzCukB,UA3CmzC,gBAAW,oBAASvkB,CAAT,EAAW;AAAC,WAAO2C,mBAAmBgiB,YAAYN,UAAUrkB,CAAV,CAAZ,CAAnB,CAAP;AAAqD,GAA5E;AAA6E,UAAS4kB,SAAT,CAAmB5kB,CAAnB,EAAqB;AAAC,SAAOkI,QAAQuc,YAAYC,sBAAsB1kB,CAAtB,CAAZ,CAAR,CAAP;AAAsD,UAAS6kB,SAAT,CAAmB7kB,CAAnB,EAAqB;AAAC,SAAO2C,mBAAmBgiB,YAAYvc,SAASpI,CAAT,CAAZ,CAAnB,CAAP;AAAoD,UAASgf,SAAT,CAAmBhf,CAAnB,EAAqB;AAAC,SAAOykB,YAAYC,sBAAsB1kB,CAAtB,CAAZ,CAAP;AAA6C,UAASsjB,SAAT,CAAmBtjB,CAAnB,EAAqB;AAAC,SAAO2C,mBAAmBgiB,YAAY3kB,CAAZ,CAAnB,CAAP;AAA0C,UAASqX,SAAT,CAAmB5X,CAAnB,EAAqB;AAAC,MAAIF,IAAE,EAAN,CAAS,KAAI,IAAIS,IAAE,CAAV,EAAYA,IAAEP,EAAEI,MAAF,GAAS,CAAvB,EAAyBG,KAAG,CAA5B,EAA8B;AAACT,SAAGgD,OAAOC,YAAP,CAAoBJ,SAAS3C,EAAE4C,MAAF,CAASrC,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAApB,CAAH;AAAmD,UAAOT,CAAP;AAAS,UAASgY,SAAT,CAAmB9X,CAAnB,EAAqB;AAAC,MAAIO,IAAE,EAAN,CAAS,KAAI,IAAIT,IAAE,CAAV,EAAYA,IAAEE,EAAEI,MAAhB,EAAuBN,GAAvB,EAA2B;AAACS,SAAG,CAAC,MAAIP,EAAEgD,UAAF,CAAalD,CAAb,EAAgBuB,QAAhB,CAAyB,EAAzB,CAAL,EAAmCc,KAAnC,CAAyC,CAAC,CAA1C,CAAH;AAAgD,UAAO5B,CAAP;AAAS,UAAS8kB,QAAT,CAAkB9kB,CAAlB,EAAoB;AAAC,SAAOkI,QAAQlI,CAAR,CAAP;AAAkB,UAAS+kB,UAAT,CAAoBxlB,CAApB,EAAsB;AAAC,MAAIS,IAAE8kB,SAASvlB,CAAT,CAAN,CAAkB,IAAIE,IAAEO,EAAEgc,OAAF,CAAU,UAAV,EAAqB,QAArB,CAAN,CAAqCvc,IAAEA,EAAEuc,OAAF,CAAU,OAAV,EAAkB,EAAlB,CAAF,CAAwB,OAAOvc,CAAP;AAAS,UAASulB,UAAT,CAAoBzlB,CAApB,EAAsB;AAAC,MAAIS,IAAET,EAAEyc,OAAF,CAAU,oBAAV,EAA+B,EAA/B,CAAN,CAAyC,IAAIvc,IAAE2I,SAASpI,CAAT,CAAN,CAAkB,OAAOP,CAAP;AAAS,UAAS8c,QAAT,CAAkBvc,CAAlB,EAAoBT,CAApB,EAAsB;AAAC,MAAIE,IAAEslB,WAAW/kB,CAAX,CAAN,CAAoB,OAAM,gBAAcT,CAAd,GAAgB,WAAhB,GAA4BE,CAA5B,GAA8B,eAA9B,GAA8CF,CAA9C,GAAgD,WAAtD;AAAkE,UAAS0lB,QAAT,CAAkBjlB,CAAlB,EAAoBT,CAApB,EAAsB;AAAC,MAAGS,EAAEkF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAA9B,EAAgC;AAAC,UAAK,4BAA0B3F,CAA/B;AAAiC,OAAGA,MAAIZ,SAAP,EAAiB;AAACqB,QAAEA,EAAEgc,OAAF,CAAU,gBAAczc,CAAd,GAAgB,OAA1B,EAAkC,EAAlC,CAAF,CAAwCS,IAAEA,EAAEgc,OAAF,CAAU,cAAYzc,CAAZ,GAAc,OAAxB,EAAgC,EAAhC,CAAF;AAAsC,GAAhG,MAAoG;AAACS,QAAEA,EAAEgc,OAAF,CAAU,uBAAV,EAAkC,EAAlC,CAAF,CAAwChc,IAAEA,EAAEgc,OAAF,CAAU,qBAAV,EAAgC,EAAhC,CAAF;AAAsC,UAAOgJ,WAAWhlB,CAAX,CAAP;AAAqB,UAASklB,gBAAT,CAA0BhmB,CAA1B,EAA4B;AAAC,MAAGA,EAAEW,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAAC,UAAK,0BAAL;AAAgC,OAAGX,EAAE6c,KAAF,CAAQ,gBAAR,KAA2B,IAA9B,EAAmC;AAAC,UAAK,0BAAL;AAAgC,OAAIxc,IAAE,IAAI4lB,WAAJ,CAAgBjmB,EAAEW,MAAF,GAAS,CAAzB,CAAN,CAAkC,IAAIG,IAAE,IAAIolB,QAAJ,CAAa7lB,CAAb,CAAN,CAAsB,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEP,EAAEW,MAAF,GAAS,CAAvB,EAAyBJ,GAAzB,EAA6B;AAACO,MAAEqlB,QAAF,CAAW5lB,CAAX,EAAa2C,SAASlD,EAAEmD,MAAF,CAAS5C,IAAE,CAAX,EAAa,CAAb,CAAT,EAAyB,EAAzB,CAAb;AAA2C,UAAOF,CAAP;AAAS,UAAS+lB,gBAAT,CAA0B/lB,CAA1B,EAA4B;AAAC,MAAIL,IAAE,EAAN,CAAS,IAAIc,IAAE,IAAIolB,QAAJ,CAAa7lB,CAAb,CAAN,CAAsB,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEF,EAAEgmB,UAAhB,EAA2B9lB,GAA3B,EAA+B;AAACP,SAAG,CAAC,OAAKc,EAAEwlB,QAAF,CAAW/lB,CAAX,EAAcqB,QAAd,CAAuB,EAAvB,CAAN,EAAkCc,KAAlC,CAAwC,CAAC,CAAzC,CAAH;AAA+C,UAAO1C,CAAP;AAAS,UAASumB,UAAT,CAAoBrlB,CAApB,EAAsB;AAAC,MAAIN,CAAJ,EAAMH,CAAN,EAAQoC,CAAR,EAAUvC,CAAV,EAAYR,CAAZ,EAAcY,CAAd,EAAgBL,CAAhB,EAAkBQ,CAAlB,CAAoB,IAAIC,CAAJ,EAAMjB,CAAN,EAAQD,CAAR,EAAUW,CAAV,CAAYA,IAAEW,EAAE2b,KAAF,CAAQ,wDAAR,CAAF,CAAoE,IAAGtc,CAAH,EAAK;AAACO,QAAEP,EAAE,CAAF,CAAF,CAAOK,IAAEsC,SAASpC,CAAT,CAAF,CAAc,IAAGA,EAAEH,MAAF,KAAW,CAAd,EAAgB;AAAC,UAAG,MAAIC,CAAJ,IAAOA,IAAE,GAAZ,EAAgB;AAACA,YAAE,OAAKA,CAAP;AAAS,OAA1B,MAA8B;AAAC,YAAG,KAAGA,CAAH,IAAMA,IAAE,EAAX,EAAc;AAACA,cAAE,OAAKA,CAAP;AAAS;AAAC;AAAC,SAAEsC,SAAS3C,EAAE,CAAF,CAAT,IAAe,CAAjB,CAAmBsC,IAAEK,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBD,IAAE4C,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBT,IAAEoD,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBG,IAAEwC,SAAS3C,EAAE,CAAF,CAAT,CAAF,CAAiBF,IAAE,CAAF,CAAIR,IAAEU,EAAE,CAAF,CAAF,CAAO,IAAGV,MAAI,EAAP,EAAU;AAACD,UAAE,CAACC,EAAEsD,MAAF,CAAS,CAAT,IAAY,IAAb,EAAmBA,MAAnB,CAA0B,CAA1B,EAA4B,CAA5B,CAAF,CAAiC9C,IAAE6C,SAAStD,CAAT,CAAF;AAAc,YAAOiX,KAAKqK,GAAL,CAAStgB,CAAT,EAAWH,CAAX,EAAaoC,CAAb,EAAevC,CAAf,EAAiBR,CAAjB,EAAmBY,CAAnB,EAAqBL,CAArB,CAAP;AAA+B,SAAK,8BAA4Ba,CAAjC;AAAmC,UAASslB,SAAT,CAAmB1lB,CAAnB,EAAqB;AAAC,MAAIT,IAAEkmB,WAAWzlB,CAAX,CAAN,CAAoB,OAAO,CAAC,EAAET,IAAE,IAAJ,CAAR;AAAkB,UAASomB,UAAT,CAAoB3lB,CAApB,EAAsB;AAAC,SAAO,IAAI+V,IAAJ,CAAS0P,WAAWzlB,CAAX,CAAT,CAAP;AAA+B,UAAS4lB,UAAT,CAAoB9mB,CAApB,EAAsBU,CAAtB,EAAwBR,CAAxB,EAA0B;AAAC,MAAIO,CAAJ,CAAM,IAAIS,IAAElB,EAAE+mB,cAAF,EAAN,CAAyB,IAAGrmB,CAAH,EAAK;AAAC,QAAGQ,IAAE,IAAF,IAAQ,OAAKA,CAAhB,EAAkB;AAAC,YAAK,kCAAgCA,CAArC;AAAuC,SAAE,CAAC,KAAGA,CAAJ,EAAO4B,KAAP,CAAa,CAAC,CAAd,CAAF;AAAmB,GAAnF,MAAuF;AAACrC,QAAE,CAAC,QAAMS,CAAP,EAAU4B,KAAV,CAAgB,CAAC,CAAjB,CAAF;AAAsB,QAAG,CAAC,OAAK9C,EAAEgnB,WAAF,KAAgB,CAArB,CAAD,EAA0BlkB,KAA1B,CAAgC,CAAC,CAAjC,CAAH,CAAuCrC,KAAG,CAAC,MAAIT,EAAEinB,UAAF,EAAL,EAAqBnkB,KAArB,CAA2B,CAAC,CAA5B,CAAH,CAAkCrC,KAAG,CAAC,MAAIT,EAAEknB,WAAF,EAAL,EAAsBpkB,KAAtB,CAA4B,CAAC,CAA7B,CAAH,CAAmCrC,KAAG,CAAC,MAAIT,EAAEmnB,aAAF,EAAL,EAAwBrkB,KAAxB,CAA8B,CAAC,CAA/B,CAAH,CAAqCrC,KAAG,CAAC,MAAIT,EAAEonB,aAAF,EAAL,EAAwBtkB,KAAxB,CAA8B,CAAC,CAA/B,CAAH,CAAqC,IAAG5C,CAAH,EAAK;AAAC,QAAIS,IAAEX,EAAEqnB,kBAAF,EAAN,CAA6B,IAAG1mB,MAAI,CAAP,EAAS;AAACA,UAAE,CAAC,OAAKA,CAAN,EAASmC,KAAT,CAAe,CAAC,CAAhB,CAAF,CAAqBnC,IAAEA,EAAEuc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuBzc,KAAG,MAAIE,CAAP;AAAS;AAAC,QAAG,GAAH,CAAO,OAAOF,CAAP;AAAS,UAASklB,WAAT,CAAqBzkB,CAArB,EAAuB;AAAC,SAAOA,EAAEgc,OAAF,CAAU,IAAV,EAAe,EAAf,CAAP;AAA0B,UAAS2I,WAAT,CAAqB3kB,CAArB,EAAuB;AAAC,SAAOA,EAAEgc,OAAF,CAAU,OAAV,EAAkB,KAAlB,CAAP;AAAgC,UAASoK,SAAT,CAAmBtnB,CAAnB,EAAqB;AAAC,MAAIS,IAAE,wBAAN,CAA+B,IAAG,CAACT,EAAEid,KAAF,CAAQ,iBAAR,CAAJ,EAA+B;AAAC,UAAMxc,CAAN;AAAQ,OAAET,EAAEmgB,WAAF,EAAF,CAAkB,IAAI/f,IAAEJ,EAAEqf,KAAF,CAAQ,GAAR,EAAate,MAAb,GAAoB,CAA1B,CAA4B,IAAGX,IAAE,CAAL,EAAO;AAAC,UAAMK,CAAN;AAAQ,OAAIC,IAAE,IAAI6mB,MAAJ,CAAW,IAAEnnB,CAAF,GAAI,CAAf,CAAN,CAAwBJ,IAAEA,EAAEkd,OAAF,CAAU,IAAV,EAAexc,CAAf,CAAF,CAAoB,IAAIC,IAAEX,EAAEqf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAG1e,EAAEI,MAAF,IAAU,CAAb,EAAe;AAAC,UAAMN,CAAN;AAAQ,QAAI,IAAIP,IAAE,CAAV,EAAYA,IAAE,CAAd,EAAgBA,GAAhB,EAAoB;AAACS,MAAET,CAAF,IAAK,CAAC,SAAOS,EAAET,CAAF,CAAR,EAAc4C,KAAd,CAAoB,CAAC,CAArB,CAAL;AAA6B,UAAOnC,EAAEyC,IAAF,CAAO,EAAP,CAAP;AAAkB,UAASokB,SAAT,CAAmB9mB,CAAnB,EAAqB;AAAC,MAAG,CAACA,EAAEuc,KAAF,CAAQ,mBAAR,CAAJ,EAAiC;AAAC,UAAK,8BAAL;AAAoC,OAAEvc,EAAEyf,WAAF,EAAF,CAAkB,IAAI1f,IAAEC,EAAEuc,KAAF,CAAQ,SAAR,CAAN,CAAyB,KAAI,IAAI7c,IAAE,CAAV,EAAYA,IAAE,CAAd,EAAgBA,GAAhB,EAAoB;AAACK,MAAEL,CAAF,IAAKK,EAAEL,CAAF,EAAK8c,OAAL,CAAa,KAAb,EAAmB,EAAnB,CAAL,CAA4B,IAAGzc,EAAEL,CAAF,KAAM,EAAT,EAAY;AAACK,QAAEL,CAAF,IAAK,GAAL;AAAS;AAAC,OAAE,MAAIK,EAAE2C,IAAF,CAAO,GAAP,CAAJ,GAAgB,GAAlB,CAAsB,IAAIzC,IAAED,EAAEuc,KAAF,CAAQ,YAAR,CAAN,CAA4B,IAAGtc,MAAI,IAAP,EAAY;AAAC,WAAOD,EAAEoC,KAAF,CAAQ,CAAR,EAAU,CAAC,CAAX,CAAP;AAAqB,OAAI5C,IAAE,EAAN,CAAS,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEO,EAAEI,MAAhB,EAAuBX,GAAvB,EAA2B;AAAC,QAAGO,EAAEP,CAAF,EAAKW,MAAL,GAAYb,EAAEa,MAAjB,EAAwB;AAACb,UAAES,EAAEP,CAAF,CAAF;AAAO;AAAC,OAAEM,EAAEwc,OAAF,CAAUhd,CAAV,EAAY,IAAZ,CAAF,CAAoB,OAAOQ,EAAEoC,KAAF,CAAQ,CAAR,EAAU,CAAC,CAAX,CAAP;AAAqB,UAAS2kB,OAAT,CAAiBhnB,CAAjB,EAAmB;AAAC,MAAIL,IAAE,qBAAN,CAA4B,IAAG,CAACK,EAAEwc,KAAF,CAAQ,gCAAR,CAAJ,EAA8C;AAAC,UAAM7c,CAAN;AAAQ,OAAGK,EAAEM,MAAF,IAAU,CAAb,EAAe;AAAC,QAAIJ,CAAJ,CAAM,IAAG;AAACA,UAAE2C,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,IAA2B,GAA3B,GAA+BD,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAA/B,GAA0D,GAA1D,GAA8DD,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAA9D,GAAyF,GAAzF,GAA6FD,SAAS7C,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,EAAuB,EAAvB,CAA/F,CAA0H,OAAO5C,CAAP;AAAS,KAAvI,CAAuI,OAAMO,CAAN,EAAQ;AAAC,YAAMd,CAAN;AAAQ;AAAC,GAA/K,MAAmL;AAAC,QAAGK,EAAEM,MAAF,IAAU,EAAb,EAAgB;AAAC,aAAOymB,UAAU/mB,CAAV,CAAP;AAAoB,KAArC,MAAyC;AAAC,aAAOA,CAAP;AAAS;AAAC;AAAC,UAASinB,OAAT,CAAiBxnB,CAAjB,EAAmB;AAAC,MAAIW,IAAE,sBAAN,CAA6BX,IAAEA,EAAEigB,WAAF,CAAcjgB,CAAd,CAAF,CAAmB,IAAGA,EAAE+c,KAAF,CAAQ,WAAR,CAAH,EAAwB;AAAC,QAAIxc,IAAEP,EAAEmf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAG5e,EAAEM,MAAF,KAAW,CAAd,EAAgB;AAAC,YAAMF,CAAN;AAAQ,SAAIb,IAAE,EAAN,CAAS,IAAG;AAAC,WAAI,IAAIU,IAAE,CAAV,EAAYA,IAAE,CAAd,EAAgBA,GAAhB,EAAoB;AAAC,YAAIT,IAAEqD,SAAS7C,EAAEC,CAAF,CAAT,CAAN,CAAqBV,KAAG,CAAC,MAAIC,EAAE+B,QAAF,CAAW,EAAX,CAAL,EAAqBc,KAArB,CAA2B,CAAC,CAA5B,CAAH;AAAkC,cAAO9C,CAAP;AAAS,KAAzF,CAAyF,OAAMW,CAAN,EAAQ;AAAC,YAAME,CAAN;AAAQ;AAAC,GAAzL,MAA6L;AAAC,QAAGX,EAAE+c,KAAF,CAAQ,cAAR,KAAyB/c,EAAEkG,OAAF,CAAU,GAAV,MAAiB,CAAC,CAA9C,EAAgD;AAAC,aAAOkhB,UAAUpnB,CAAV,CAAP;AAAoB,KAArE,MAAyE;AAAC,YAAMW,CAAN;AAAQ;AAAC;AAAC,UAAS+kB,qBAAT,CAA+B1kB,CAA/B,EAAiC;AAAC,MAAId,IAAE4D,mBAAmB9C,CAAnB,CAAN,CAA4B,IAAIT,IAAE,EAAN,CAAS,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEP,EAAEW,MAAhB,EAAuBJ,GAAvB,EAA2B;AAAC,QAAGP,EAAEO,CAAF,KAAM,GAAT,EAAa;AAACF,UAAEA,IAAEL,EAAEmD,MAAF,CAAS5C,CAAT,EAAW,CAAX,CAAJ,CAAkBA,IAAEA,IAAE,CAAJ;AAAM,KAAtC,MAA0C;AAACF,UAAEA,IAAE,GAAF,GAAM2gB,OAAOhhB,EAAEO,CAAF,CAAP,CAAR;AAAqB;AAAC,UAAOF,CAAP;AAAS,UAASknB,cAAT,CAAwBzmB,CAAxB,EAA0B;AAACA,MAAEA,EAAEgc,OAAF,CAAU,QAAV,EAAmB,IAAnB,CAAF,CAA2B,OAAOhc,CAAP;AAAS,UAAS0mB,aAAT,CAAuB1mB,CAAvB,EAAyB;AAACA,MAAEA,EAAEgc,OAAF,CAAU,QAAV,EAAmB,IAAnB,CAAF,CAA2Bhc,IAAEA,EAAEgc,OAAF,CAAU,MAAV,EAAiB,MAAjB,CAAF,CAA2B,OAAOhc,CAAP;AAAS,MAAKpB,IAAL,CAAU2D,MAAV,CAAiBokB,SAAjB,GAA2B,UAAS3mB,CAAT,EAAW;AAAC,MAAGA,EAAE+b,KAAF,CAAQ,UAAR,CAAH,EAAuB;AAAC,WAAO,IAAP;AAAY,GAApC,MAAwC;AAAC,QAAG/b,EAAE+b,KAAF,CAAQ,WAAR,CAAH,EAAwB;AAAC,aAAO,IAAP;AAAY,KAArC,MAAyC;AAAC,aAAO,KAAP;AAAa;AAAC;AAAC,CAAzI,CAA0I/E,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBmhB,KAAjB,GAAuB,UAAS1jB,CAAT,EAAW;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAZ,KAAgBG,EAAE+b,KAAF,CAAQ,aAAR,KAAwB/b,EAAE+b,KAAF,CAAQ,aAAR,CAAxC,CAAH,EAAmE;AAAC,WAAO,IAAP;AAAY,GAAhF,MAAoF;AAAC,WAAO,KAAP;AAAa;AAAC,CAAtI,CAAuI/E,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBqkB,QAAjB,GAA0B,UAAS5mB,CAAT,EAAW;AAACA,MAAEA,EAAEgc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB,IAAGhc,EAAE+b,KAAF,CAAQ,yBAAR,KAAoC/b,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAnD,EAAqD;AAAC,WAAO,IAAP;AAAY,GAAlE,MAAsE;AAAC,WAAO,KAAP;AAAa;AAAC,CAAlJ,CAAmJmX,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBskB,WAAjB,GAA6B,UAAS7mB,CAAT,EAAW;AAAC,MAAGA,EAAE+b,KAAF,CAAQ,OAAR,CAAH,EAAoB;AAAC,WAAO,KAAP;AAAa,OAAEoI,UAAUnkB,CAAV,CAAF,CAAe,OAAOgX,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBqkB,QAAjB,CAA0B5mB,CAA1B,CAAP;AAAoC,CAA9H,CAA+HgX,KAAKpY,IAAL,CAAU2D,MAAV,CAAiBukB,cAAjB,GAAgC,UAAS9mB,CAAT,EAAW;AAACA,MAAEA,EAAEgc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB,IAAGhc,EAAE+b,KAAF,CAAQ,eAAR,CAAH,EAA4B;AAAC,WAAO,IAAP;AAAY,GAAzC,MAA6C;AAAC,WAAO,KAAP;AAAa;AAAC,CAA/H,CAAgI,SAASgL,WAAT,CAAqB/mB,CAArB,EAAuB;AAAC,MAAGA,EAAEH,MAAF,GAAS,CAAT,IAAY,CAAf,EAAiB;AAAC,WAAM,MAAIG,CAAV;AAAY,OAAGA,EAAEqC,MAAF,CAAS,CAAT,EAAW,CAAX,IAAc,GAAjB,EAAqB;AAAC,WAAM,OAAKrC,CAAX;AAAa,UAAOA,CAAP;AAAS,UAASgnB,cAAT,CAAwBznB,CAAxB,EAA0B;AAACA,MAAEA,EAAEyc,OAAF,CAAU,WAAV,EAAsB,EAAtB,CAAF,CAA4Bzc,IAAEA,EAAEyc,OAAF,CAAU,WAAV,EAAsB,EAAtB,CAAF,CAA4Bzc,IAAEA,EAAEyc,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB,IAAG;AAAC,QAAIvc,IAAEF,EAAE4e,KAAF,CAAQ,GAAR,EAAa8I,GAAb,CAAiB,UAASnoB,CAAT,EAAWU,CAAX,EAAaT,CAAb,EAAe;AAAC,UAAIC,IAAEoD,SAAStD,CAAT,CAAN,CAAkB,IAAGE,IAAE,CAAF,IAAK,MAAIA,CAAZ,EAAc;AAAC,cAAK,4BAAL;AAAkC,WAAIE,IAAE,CAAC,OAAKF,EAAE8B,QAAF,CAAW,EAAX,CAAN,EAAsBc,KAAtB,CAA4B,CAAC,CAA7B,CAAN,CAAsC,OAAO1C,CAAP;AAAS,KAAnJ,EAAqJgD,IAArJ,CAA0J,EAA1J,CAAN,CAAoK,OAAOzC,CAAP;AAAS,GAAjL,CAAiL,OAAMO,CAAN,EAAQ;AAAC,UAAK,qCAAmCA,CAAxC;AAA0C;AAAC,KAAIknB,aAAW,SAAXA,UAAW,CAASznB,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAId,IAAEO,EAAEI,MAAR,CAAe,IAAGJ,EAAEI,MAAF,GAASG,EAAEH,MAAd,EAAqB;AAACX,QAAEc,EAAEH,MAAJ;AAAW,QAAI,IAAIN,IAAE,CAAV,EAAYA,IAAEL,CAAd,EAAgBK,GAAhB,EAAoB;AAAC,QAAGE,EAAEgD,UAAF,CAAalD,CAAb,KAAiBS,EAAEyC,UAAF,CAAalD,CAAb,CAApB,EAAoC;AAAC,aAAOA,CAAP;AAAS;AAAC,OAAGE,EAAEI,MAAF,IAAUG,EAAEH,MAAf,EAAsB;AAAC,WAAOX,CAAP;AAAS,UAAO,CAAC,CAAR;AAAU,CAA3L;AAClzN,IAAG,OAAO8X,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UA0E3BA,IA1E2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKf,MAAZ,IAAoB,WAApB,IAAiC,CAACe,KAAKf,MAA1C,EAAiD;AAACe,OAAKf,MAAL,GAAY,EAAZ;AAAe,MAAKA,MAAL,CAAYiB,IAAZ,GAAiB,IAAI,YAAU;AAAC,OAAKiQ,cAAL,GAAoB,EAACC,MAAK,gCAAN,EAAuCC,QAAO,wCAA9C,EAAuFC,QAAO,wCAA9F,EAAuIC,QAAO,wCAA9I,EAAuLC,QAAO,wCAA9L,EAAuOC,KAAI,sCAA3O,EAAkRC,KAAI,sCAAtR,EAA6TC,WAAU,gCAAvU,EAApB,CAA8X,KAAKC,eAAL,GAAqB,EAACF,KAAI,UAAL,EAAgBN,MAAK,UAArB,EAAgCC,QAAO,UAAvC,EAAkDC,QAAO,UAAzD,EAAoEC,QAAO,UAA3E,EAAsFC,QAAO,UAA7F,EAAwGG,WAAU,UAAlH,EAA6HE,SAAQ,UAArI,EAAgJC,UAAS,UAAzJ,EAAoKC,YAAW,UAA/K,EAA0LC,YAAW,UAArM,EAAgNC,YAAW,UAA3N,EAAsOC,YAAW,UAAjP,EAA4PC,eAAc,UAA1Q,EAAqRC,YAAW,gBAAhS,EAAiTC,aAAY,gBAA7T,EAA8UC,eAAc,gBAA5V,EAA6WC,eAAc,gBAA3X,EAA4YC,eAAc,gBAA1Z,EAA2aC,eAAc,gBAAzb,EAA0cC,kBAAiB,gBAA3d,EAA4eC,cAAa,gBAAzf,EAA0gBC,eAAc,gBAAxhB,EAAyiBC,iBAAgB,gBAAzjB,EAA0kBC,iBAAgB,gBAA1lB,EAA2mBC,iBAAgB,gBAA3nB,EAA4oBC,iBAAgB,gBAA5pB,EAA6qBC,oBAAmB,gBAAhsB,EAAitBC,aAAY,gBAA7tB,EAA8uBC,eAAc,gBAA5vB,EAA6wBC,eAAc,gBAA3xB,EAA4yBC,mBAAkB,gBAA9zB,EAA+0BC,oBAAmB,gBAAl2B,EAAm3BC,sBAAqB,gBAAx4B,EAAy5BC,sBAAqB,gBAA96B,EAA+7BC,sBAAqB,gBAAp9B,EAAq+BC,sBAAqB,gBAA1/B,EAA2gCC,yBAAwB,gBAAniC,EAArB,CAA2kC,KAAKC,yBAAL,GAA+B,EAAClC,KAAIznB,SAASuE,IAAT,CAAcqlB,GAAnB,EAAuBzC,MAAKnnB,SAASuE,IAAT,CAAcslB,IAA1C,EAA+CzC,QAAOpnB,SAASuE,IAAT,CAAculB,MAApE,EAA2EzC,QAAOrnB,SAASuE,IAAT,CAAca,MAAhG,EAAuGkiB,QAAOtnB,SAASuE,IAAT,CAAcsD,MAA5H,EAAmI0f,QAAOvnB,SAASuE,IAAT,CAAcmB,MAAxJ,EAA+JgiB,WAAU1nB,SAASuE,IAAT,CAAcwlB,SAAvL,EAA/B,CAAiO,KAAKC,gBAAL,GAAsB,UAASjqB,CAAT,EAAWT,CAAX,EAAa;AAAC,QAAG,OAAO,KAAK4nB,cAAL,CAAoB5nB,CAApB,CAAP,IAA+B,WAAlC,EAA8C;AAAC,YAAK,+CAA6CA,CAAlD;AAAoD,YAAO,KAAK4nB,cAAL,CAAoB5nB,CAApB,IAAuBS,CAA9B;AAAgC,GAAvK,CAAwK,KAAKkqB,sBAAL,GAA4B,UAASnrB,CAAT,EAAWiB,CAAX,EAAaL,CAAb,EAAe;AAAC,QAAIF,IAAE,KAAKwqB,gBAAL,CAAsBlrB,CAAtB,EAAwBiB,CAAxB,CAAN,CAAiC,IAAId,IAAES,IAAE,CAAR,CAAU,IAAGF,EAAEI,MAAF,GAAS,EAAT,GAAYX,CAAf,EAAiB;AAAC,YAAK,yCAAuCS,CAAvC,GAAyC,GAAzC,GAA6CK,CAAlD;AAAoD,SAAIT,IAAE,MAAN,CAAa,IAAIQ,IAAE,OAAKN,CAAX,CAAa,IAAIX,IAAE,EAAN,CAAS,IAAIgB,IAAEZ,IAAEK,EAAEM,MAAJ,GAAWE,EAAEF,MAAnB,CAA0B,KAAI,IAAIb,IAAE,CAAV,EAAYA,IAAEc,CAAd,EAAgBd,KAAG,CAAnB,EAAqB;AAACF,WAAG,IAAH;AAAQ,SAAIU,IAAED,IAAET,CAAF,GAAIiB,CAAV,CAAY,OAAOP,CAAP;AAAS,GAA7Q,CAA8Q,KAAK2qB,UAAL,GAAgB,UAASnqB,CAAT,EAAWP,CAAX,EAAa;AAAC,QAAIF,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI3qB,CAAL,EAA9B,CAAN,CAA6C,OAAOF,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAApG,CAAqG,KAAKsX,OAAL,GAAa,UAAS/X,CAAT,EAAWE,CAAX,EAAa;AAAC,QAAIO,IAAE,IAAIgX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI3qB,CAAL,EAA9B,CAAN,CAA6C,OAAOO,EAAEsqB,SAAF,CAAY/qB,CAAZ,CAAP;AAAsB,GAA9F,CAA+F,KAAK6nB,IAAL,GAAU,UAASpnB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,MAAL,EAAYG,MAAK,UAAjB,EAA9B,CAAN,CAAkE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAAjH,CAAkH,KAAKsnB,MAAL,GAAY,UAAStnB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAArH,CAAsH,KAAKwqB,SAAL,GAAe,UAASxqB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE+qB,SAAF,CAAYtqB,CAAZ,CAAP;AAAsB,GAArH,CAAsH,KAAKwnB,MAAL,GAAY,UAASxnB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,GAArH,CAAsH,KAAKyqB,SAAL,GAAe,UAASzqB,CAAT,EAAW;AAAC,QAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,QAAL,EAAcG,MAAK,UAAnB,EAA9B,CAAN,CAAoE,OAAOhrB,EAAE+qB,SAAF,CAAYtqB,CAAZ,CAAP;AAAsB,GAArH;AAAsH,CAA73F,EAAjB,CAA+4FgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwQ,GAAjB,GAAqB,UAAS1nB,CAAT,EAAW;AAAC,MAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,KAAL,EAAWG,MAAK,UAAhB,EAA9B,CAAN,CAAiE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,CAA3H,CAA4HgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiByQ,SAAjB,GAA2B,UAAS3nB,CAAT,EAAW;AAAC,MAAIT,IAAE,IAAIyX,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,WAAL,EAAiBG,MAAK,UAAtB,EAA9B,CAAN,CAAuE,OAAOhrB,EAAE8qB,YAAF,CAAerqB,CAAf,CAAP;AAAyB,CAAvI,CAAwIgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwT,eAAjB,GAAiC,IAAIjU,YAAJ,EAAjC,CAAoDO,KAAKf,MAAL,CAAYiB,IAAZ,CAAiByT,oBAAjB,GAAsC,UAASprB,CAAT,EAAW;AAAC,MAAIS,IAAE,IAAIuI,KAAJ,CAAUhJ,CAAV,CAAN,CAAmByX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwT,eAAjB,CAAiChb,SAAjC,CAA2C1P,CAA3C,EAA8C,OAAO8jB,QAAQ9jB,CAAR,CAAP;AAAkB,CAArI,CAAsIgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0T,2BAAjB,GAA6C,UAAS5qB,CAAT,EAAW;AAAC,SAAO,IAAI2I,UAAJ,CAAeqO,KAAKf,MAAL,CAAYiB,IAAZ,CAAiByT,oBAAjB,CAAsC3qB,CAAtC,CAAf,EAAwD,EAAxD,CAAP;AAAmE,CAA5H,CAA6HgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB2T,mBAAjB,GAAqC,UAAS3rB,CAAT,EAAW;AAAC,MAAIO,IAAEP,IAAE,CAAR,CAAU,IAAIc,IAAE,CAACd,IAAEO,CAAH,IAAM,CAAZ,CAAc,IAAIF,IAAE,IAAIgJ,KAAJ,CAAUvI,IAAE,CAAZ,CAAN,CAAqBgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBwT,eAAjB,CAAiChb,SAAjC,CAA2CnQ,CAA3C,EAA8CA,EAAE,CAAF,IAAK,CAAG,OAAKE,CAAN,GAAS,GAAV,GAAe,GAAhB,IAAqBF,EAAE,CAAF,CAA1B,CAA+B,OAAOukB,QAAQvkB,CAAR,CAAP;AAAkB,CAA7L,CAA8LyX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB4T,0BAAjB,GAA4C,UAAS9qB,CAAT,EAAW;AAAC,SAAO,IAAI2I,UAAJ,CAAeqO,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB2T,mBAAjB,CAAqC7qB,CAArC,CAAf,EAAuD,EAAvD,CAAP;AAAkE,CAA1H,CAA2HgX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB6T,4BAAjB,GAA8C,UAASxrB,CAAT,EAAW;AAAC,MAAIS,IAAET,EAAE4O,SAAF,EAAN,CAAoB,OAAM,CAAN,EAAQ;AAAC,QAAI1O,IAAEuX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB4T,0BAAjB,CAA4C9qB,CAA5C,CAAN,CAAqD,IAAGT,EAAEsM,SAAF,CAAYpM,CAAZ,KAAgB,CAAC,CAApB,EAAsB;AAAC,aAAOA,CAAP;AAAS;AAAC;AAAC,CAA9K,CAA+KuX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB8T,2BAAjB,GAA6C,UAASxrB,CAAT,EAAWD,CAAX,EAAa;AAAC,MAAIE,IAAED,EAAEqM,SAAF,CAAYtM,CAAZ,CAAN,CAAqB,IAAGE,KAAG,CAAN,EAAQ;AAAC,UAAK,6BAAL;AAAmC,OAAGA,KAAG,CAAN,EAAQ;AAAC,WAAOD,CAAP;AAAS,OAAIQ,IAAET,EAAEgU,QAAF,CAAW/T,CAAX,CAAN,CAAoB,IAAIN,IAAE8X,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB6T,4BAAjB,CAA8C/qB,CAA9C,CAAN,CAAuD,OAAOd,EAAEsU,GAAF,CAAMhU,CAAN,CAAP;AAAgB,CAAzO,CAA0OwX,KAAKf,MAAL,CAAYgB,aAAZ,GAA0B,UAASxX,CAAT,EAAW;AAAC,MAAIF,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,IAAId,IAAE,IAAN,CAAW,KAAK+rB,iBAAL,GAAuB,UAASnsB,CAAT,EAAWE,CAAX,EAAa;AAACF,QAAEkY,KAAKf,MAAL,CAAYgB,aAAZ,CAA0BE,mBAA1B,CAA8CrY,CAA9C,CAAF,CAAmD,IAAGA,MAAI,IAAJ,IAAUE,MAAIL,SAAjB,EAA2B;AAACK,UAAEgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC9oB,CAAjC,CAAF;AAAsC,SAAG,mDAAmDoG,OAAnD,CAA2DpG,CAA3D,KAA+D,CAAC,CAAhE,IAAmEE,KAAG,UAAzE,EAAoF;AAAC,UAAG;AAAC,aAAKksB,EAAL,GAAQlU,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0S,yBAAjB,CAA2C9qB,CAA3C,EAA8C+B,MAA9C,EAAR;AAA+D,OAAnE,CAAmE,OAAMrB,CAAN,EAAQ;AAAC,cAAK,6CAA2CV,CAA3C,GAA6C,GAA7C,GAAiDU,CAAtD;AAAwD,YAAK2rB,YAAL,GAAkB,UAASpsB,CAAT,EAAW;AAAC,aAAKmsB,EAAL,CAAQhnB,MAAR,CAAenF,CAAf;AAAkB,OAAhD,CAAiD,KAAKqsB,SAAL,GAAe,UAASrsB,CAAT,EAAW;AAAC,YAAIa,IAAEK,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBpD,CAAvB,CAAN,CAAgC,KAAKmsB,EAAL,CAAQhnB,MAAR,CAAetE,CAAf;AAAkB,OAA7E,CAA8E,KAAKyrB,MAAL,GAAY,YAAU;AAAC,YAAItsB,IAAE,KAAKmsB,EAAL,CAAQ/mB,QAAR,EAAN,CAAyB,OAAOpF,EAAE+B,QAAF,CAAWb,SAAS+B,GAAT,CAAaC,GAAxB,CAAP;AAAoC,OAApF,CAAqF,KAAKooB,YAAL,GAAkB,UAAStrB,CAAT,EAAW;AAAC,aAAKosB,YAAL,CAAkBpsB,CAAlB,EAAqB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAxE,CAAyE,KAAKf,SAAL,GAAe,UAASvrB,CAAT,EAAW;AAAC,aAAKqsB,SAAL,CAAersB,CAAf,EAAkB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAlE;AAAmE,SAAG,WAAWnmB,OAAX,CAAmBpG,CAAnB,KAAuB,CAAC,CAAxB,IAA2BE,KAAG,MAAjC,EAAwC;AAAC,UAAG;AAAC,aAAKksB,EAAL,GAAQ,IAAII,KAAKC,IAAL,CAAUjE,MAAd,EAAR;AAA+B,OAAnC,CAAmC,OAAM9nB,CAAN,EAAQ;AAAC,cAAK,6CAA2CV,CAA3C,GAA6C,GAA7C,GAAiDU,CAAtD;AAAwD,YAAK2rB,YAAL,GAAkB,UAASpsB,CAAT,EAAW;AAAC,aAAKmsB,EAAL,CAAQhnB,MAAR,CAAenF,CAAf;AAAkB,OAAhD,CAAiD,KAAKqsB,SAAL,GAAe,UAASxrB,CAAT,EAAW;AAAC,YAAIb,IAAEusB,KAAKE,KAAL,CAAWpM,GAAX,CAAeqM,MAAf,CAAsB7rB,CAAtB,CAAN,CAA+B,KAAKsrB,EAAL,CAAQhnB,MAAR,CAAenF,CAAf;AAAkB,OAA5E,CAA6E,KAAKssB,MAAL,GAAY,YAAU;AAAC,YAAItsB,IAAE,KAAKmsB,EAAL,CAAQ/mB,QAAR,EAAN,CAAyB,OAAOmnB,KAAKE,KAAL,CAAWpM,GAAX,CAAesM,QAAf,CAAwB3sB,CAAxB,CAAP;AAAkC,OAAlF,CAAmF,KAAKsrB,YAAL,GAAkB,UAAStrB,CAAT,EAAW;AAAC,aAAKosB,YAAL,CAAkBpsB,CAAlB,EAAqB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAxE,CAAyE,KAAKf,SAAL,GAAe,UAASvrB,CAAT,EAAW;AAAC,aAAKqsB,SAAL,CAAersB,CAAf,EAAkB,OAAO,KAAKssB,MAAL,EAAP;AAAqB,OAAlE;AAAmE;AAAC,GAA9rC,CAA+rC,KAAKF,YAAL,GAAkB,UAAS3rB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKmsB,OAA3D,GAAmE,GAAnE,GAAuE,KAAKC,QAAjF;AAA0F,GAAxH,CAAyH,KAAKR,SAAL,GAAe,UAAS5rB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKmsB,OAAxD,GAAgE,GAAhE,GAAoE,KAAKC,QAA9E;AAAuF,GAAlH,CAAmH,KAAKP,MAAL,GAAY,YAAU;AAAC,UAAK,+CAA6C,KAAKM,OAAlD,GAA0D,GAA1D,GAA8D,KAAKC,QAAxE;AAAiF,GAAxG,CAAyG,KAAKvB,YAAL,GAAkB,UAAS7qB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKmsB,OAA3D,GAAmE,GAAnE,GAAuE,KAAKC,QAAjF;AAA0F,GAAxH,CAAyH,KAAKtB,SAAL,GAAe,UAAS9qB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKmsB,OAAxD,GAAgE,GAAhE,GAAoE,KAAKC,QAA9E;AAAuF,GAAlH,CAAmH,IAAGnsB,MAAId,SAAP,EAAiB;AAAC,QAAGc,EAAE2qB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAKgtB,OAAL,GAAalsB,EAAE2qB,GAAf,CAAmB,IAAG3qB,EAAE8qB,IAAF,KAAS5rB,SAAZ,EAAsB;AAAC,aAAKitB,QAAL,GAAc5U,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC,KAAK+D,OAAtC,CAAd;AAA6D,YAAKV,iBAAL,CAAuB,KAAKU,OAA5B,EAAoC,KAAKC,QAAzC;AAAmD;AAAC;AAAC,CAA3gE,CAA4gE5U,KAAKf,MAAL,CAAYgB,aAAZ,CAA0BE,mBAA1B,GAA8C,UAASnX,CAAT,EAAW;AAAC,MAAG,OAAOA,CAAP,KAAW,QAAd,EAAuB;AAACA,QAAEA,EAAEif,WAAF,EAAF,CAAkBjf,IAAEA,EAAEgc,OAAF,CAAU,GAAV,EAAc,EAAd,CAAF;AAAoB,UAAOhc,CAAP;AAAS,CAAjI,CAAkIgX,KAAKf,MAAL,CAAYgB,aAAZ,CAA0BG,aAA1B,GAAwC,UAAS3X,CAAT,EAAW;AAAC,MAAIF,IAAEyX,KAAKf,MAAL,CAAYgB,aAAlB,CAAgC,IAAIjX,IAAET,EAAE4X,mBAAF,CAAsB1X,CAAtB,CAAN,CAA+B,IAAGF,EAAEssB,UAAF,CAAa7rB,CAAb,MAAkBrB,SAArB,EAA+B;AAAC,UAAK,8BAA4Bc,CAAjC;AAAmC,UAAOF,EAAEssB,UAAF,CAAa7rB,CAAb,CAAP;AAAuB,CAA7M,CAA8MgX,KAAKf,MAAL,CAAYgB,aAAZ,CAA0B4U,UAA1B,GAAqC,EAACnE,KAAI,EAAL,EAAQN,MAAK,EAAb,EAAgBC,QAAO,EAAvB,EAA0BC,QAAO,EAAjC,EAAoCC,QAAO,EAA3C,EAA8CC,QAAO,EAArD,EAAwDG,WAAU,EAAlE,EAArC,CAA2G3Q,KAAKf,MAAL,CAAY6V,GAAZ,GAAgB,UAAS5sB,CAAT,EAAW;AAAC,MAAIF,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,IAAIO,IAAE,IAAN,CAAW,IAAIR,IAAE,IAAN,CAAW,IAAID,IAAE,IAAN,CAAW,KAAK0rB,iBAAL,GAAuB,UAASlrB,CAAT,EAAWH,CAAX,EAAa;AAACG,QAAEA,EAAEkf,WAAF,EAAF,CAAkB,IAAGlf,KAAG,IAAN,EAAW;AAACA,UAAE,UAAF;AAAa,SAAEA,EAAEkf,WAAF,EAAF,CAAkB,IAAGlf,EAAEsC,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,YAAK,6CAA2CtC,CAAhD;AAAkD,SAAGH,MAAIjB,SAAP,EAAiB;AAACiB,UAAEoX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC7nB,CAAjC,CAAF;AAAsC,UAAKgsB,OAAL,GAAahsB,IAAE,GAAF,GAAMH,CAAnB,CAAqB,IAAId,IAAEiB,EAAEsC,MAAF,CAAS,CAAT,CAAN,CAAkB,IAAG,mDAAmD6C,OAAnD,CAA2DpG,CAA3D,KAA+D,CAAC,CAAhE,IAAmEc,KAAG,UAAzE,EAAoF;AAAC,UAAG;AAAC,YAAID,IAAEqX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0S,yBAAjB,CAA2C9qB,CAA3C,CAAN,CAAoD,KAAKktB,GAAL,GAAS/rB,SAASuE,IAAT,CAAcD,IAAd,CAAmB1D,MAAnB,CAA0BlB,CAA1B,EAA4B,KAAKssB,IAAjC,CAAT;AAAgD,OAAxG,CAAwG,OAAMltB,CAAN,EAAQ;AAAC,cAAK,iDAA+CD,CAA/C,GAAiD,GAAjD,GAAqDC,CAA1D;AAA4D,YAAKosB,YAAL,GAAkB,UAASrrB,CAAT,EAAW;AAAC,aAAKksB,GAAL,CAAS9nB,MAAT,CAAgBpE,CAAhB;AAAmB,OAAjD,CAAkD,KAAKsrB,SAAL,GAAe,UAAStrB,CAAT,EAAW;AAAC,YAAIiC,IAAE9B,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBrC,CAAvB,CAAN,CAAgC,KAAKksB,GAAL,CAAS9nB,MAAT,CAAgBnC,CAAhB;AAAmB,OAA9E,CAA+E,KAAKmqB,OAAL,GAAa,YAAU;AAAC,YAAIpsB,IAAE,KAAKksB,GAAL,CAAS7nB,QAAT,EAAN,CAA0B,OAAOrE,EAAEgB,QAAF,CAAWb,SAAS+B,GAAT,CAAaC,GAAxB,CAAP;AAAoC,OAAtF,CAAuF,KAAKkqB,aAAL,GAAmB,UAASrsB,CAAT,EAAW;AAAC,aAAKqrB,YAAL,CAAkBrrB,CAAlB,EAAqB,OAAO,KAAKosB,OAAL,EAAP;AAAsB,OAA1E,CAA2E,KAAKE,UAAL,GAAgB,UAAStsB,CAAT,EAAW;AAAC,aAAKsrB,SAAL,CAAetrB,CAAf,EAAkB,OAAO,KAAKosB,OAAL,EAAP;AAAsB,OAApE;AAAqE;AAAC,GAAx3B,CAAy3B,KAAKf,YAAL,GAAkB,UAASrsB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKitB,OAAhE;AAAwE,GAAtG,CAAuG,KAAKX,SAAL,GAAe,UAAStsB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKitB,OAA7D;AAAqE,GAAhG,CAAiG,KAAKG,OAAL,GAAa,YAAU;AAAC,UAAK,+CAA6C,KAAKH,OAAvD;AAA+D,GAAvF,CAAwF,KAAKI,aAAL,GAAmB,UAASrtB,CAAT,EAAW;AAAC,UAAK,wDAAsD,KAAKitB,OAAhE;AAAwE,GAAvG,CAAwG,KAAKK,UAAL,GAAgB,UAASttB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAKitB,OAA7D;AAAqE,GAAjG,CAAkG,KAAKM,WAAL,GAAiB,UAASttB,CAAT,EAAW;AAAC,QAAG,OAAOA,CAAP,IAAU,QAAb,EAAsB;AAAC,UAAID,IAAEC,CAAN,CAAQ,IAAGA,EAAEc,MAAF,GAAS,CAAT,IAAY,CAAZ,IAAe,CAACd,EAAEgd,KAAF,CAAQ,gBAAR,CAAnB,EAA6C;AAACjd,YAAEyY,UAAUxY,CAAV,CAAF;AAAe,YAAKktB,IAAL,GAAUhsB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBrD,CAAvB,CAAV,CAAoC;AAAO,SAAG,QAAOC,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC,YAAK,gDAA8CA,CAAnD;AAAqD,SAAID,IAAE,IAAN,CAAW,IAAGC,EAAEqgB,GAAF,KAAQzgB,SAAX,EAAqB;AAAC,UAAGI,EAAEqgB,GAAF,CAAMvf,MAAN,GAAa,CAAb,IAAgB,CAAhB,IAAmB,CAACd,EAAEqgB,GAAF,CAAMrD,KAAN,CAAY,gBAAZ,CAAvB,EAAqD;AAAC,cAAK,8BAA4Bhd,EAAEqgB,GAAnC;AAAuC,WAAErgB,EAAEqgB,GAAJ;AAAQ,SAAGrgB,EAAEutB,IAAF,KAAS3tB,SAAZ,EAAsB;AAACG,UAAEkgB,UAAUjgB,EAAEutB,IAAZ,CAAF;AAAoB,SAAGvtB,EAAEwtB,IAAF,KAAS5tB,SAAZ,EAAsB;AAACG,UAAEyY,UAAUxY,EAAEwtB,IAAZ,CAAF;AAAoB,SAAGxtB,EAAEytB,GAAF,KAAQ7tB,SAAX,EAAqB;AAACG,UAAEsJ,SAASrJ,EAAEytB,GAAX,CAAF;AAAkB,SAAGztB,EAAE0tB,IAAF,KAAS9tB,SAAZ,EAAsB;AAACG,UAAEulB,UAAUtlB,EAAE0tB,IAAZ,CAAF;AAAoB,SAAG3tB,KAAG,IAAN,EAAW;AAAC,YAAK,gDAA8CC,CAAnD;AAAqD,UAAKktB,IAAL,GAAUhsB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBrD,CAAvB,CAAV;AAAoC,GAApoB,CAAqoB,IAAGI,MAAIP,SAAP,EAAiB;AAAC,QAAGO,EAAE+sB,IAAF,KAASttB,SAAZ,EAAsB;AAAC,WAAK0tB,WAAL,CAAiBntB,EAAE+sB,IAAnB;AAAyB,SAAG/sB,EAAEkrB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAKgtB,OAAL,GAAazsB,EAAEkrB,GAAf,CAAmB,IAAGlrB,EAAEqrB,IAAF,KAAS5rB,SAAZ,EAAsB;AAAC,aAAKitB,QAAL,GAAc5U,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC,KAAK+D,OAAtC,CAAd;AAA6D,YAAKV,iBAAL,CAAuB,KAAKU,OAA5B,EAAoC,KAAKC,QAAzC;AAAmD;AAAC;AAAC,CAA/yE,CAAgzE5U,KAAKf,MAAL,CAAYyW,SAAZ,GAAsB,UAASpsB,CAAT,EAAW;AAAC,MAAIgB,IAAE,IAAN,CAAW,IAAIlB,IAAE,IAAN,CAAW,IAAIqB,IAAE,IAAN,CAAW,IAAIhC,IAAE,IAAN,CAAW,IAAIK,IAAE,IAAN,CAAW,IAAIZ,IAAE,IAAN,CAAW,IAAIa,IAAE,IAAN,CAAW,IAAIhB,IAAE,IAAN,CAAW,IAAIsB,IAAE,IAAN,CAAW,IAAIb,IAAE,IAAN,CAAW,IAAID,IAAE,CAAC,CAAP,CAAS,IAAIT,IAAE,IAAN,CAAW,IAAIa,IAAE,IAAN,CAAW,IAAIK,IAAE,IAAN,CAAW,IAAIJ,IAAE,IAAN,CAAW,IAAIZ,IAAE,IAAN,CAAW,KAAK2tB,YAAL,GAAkB,YAAU;AAAC,QAAIprB,IAAE,KAAKoqB,OAAL,CAAa5P,KAAb,CAAmB,gBAAnB,CAAN,CAA2C,IAAGxa,CAAH,EAAK;AAAC,WAAKqrB,SAAL,GAAerrB,EAAE,CAAF,EAAK0d,WAAL,EAAf,CAAkC,KAAK4N,aAAL,GAAmBtrB,EAAE,CAAF,EAAK0d,WAAL,EAAnB;AAAsC;AAAC,GAAvJ,CAAwJ,KAAK6N,uBAAL,GAA6B,UAASxpB,CAAT,EAAWD,CAAX,EAAa;AAAC,QAAIG,IAAE,EAAN,CAAS,IAAInC,IAAEgC,IAAE,CAAF,GAAIC,EAAEzD,MAAZ,CAAmB,KAAI,IAAI4D,IAAE,CAAV,EAAYA,IAAEpC,CAAd,EAAgBoC,GAAhB,EAAoB;AAACD,UAAEA,IAAE,GAAJ;AAAQ,YAAOA,IAAEF,CAAT;AAAW,GAA/G,CAAgH,KAAK2nB,iBAAL,GAAuB,UAASxnB,CAAT,EAAWpC,CAAX,EAAa;AAAC,SAAKsrB,YAAL,GAAoB,IAAGtrB,KAAG,gBAAN,EAAuB;AAAC,YAAK,6BAA2BA,CAAhC;AAAkC,SAAG,mDAAmD6D,OAAnD,CAA2D,KAAK0nB,SAAhE,KAA4E,CAAC,CAAhF,EAAkF;AAAC,UAAG;AAAC,aAAK1B,EAAL,GAAQ,IAAIlU,KAAKf,MAAL,CAAYgB,aAAhB,CAA8B,EAACmT,KAAI,KAAKwC,SAAV,EAA9B,CAAR;AAA4D,OAAhE,CAAgE,OAAMrrB,CAAN,EAAQ;AAAC,cAAK,6CAA2C,KAAKqrB,SAAhD,GAA0D,GAA1D,GAA8DrrB,CAAnE;AAAqE,YAAKd,IAAL,GAAU,UAAS4C,CAAT,EAAWC,CAAX,EAAa;AAAC,YAAI2D,IAAE,IAAN,CAAW,IAAG;AAAC,cAAG3D,MAAI3E,SAAP,EAAiB;AAACsI,gBAAE8lB,QAAQC,MAAR,CAAe3pB,CAAf,CAAF;AAAoB,WAAtC,MAA0C;AAAC4D,gBAAE8lB,QAAQC,MAAR,CAAe3pB,CAAf,EAAiBC,CAAjB,CAAF;AAAsB;AAAC,SAAtE,CAAsE,OAAME,CAAN,EAAQ;AAAC,gBAAK,iBAAeA,CAApB;AAAsB,aAAGyD,EAAE6Q,SAAF,KAAc,IAAjB,EAAsB;AAAC,eAAKmV,MAAL,GAAYhmB,CAAZ,CAAc,KAAKimB,KAAL,GAAW,MAAX;AAAkB,SAAvD,MAA2D;AAAC,cAAGjmB,EAAE4Q,QAAF,KAAa,IAAhB,EAAqB;AAAC,iBAAKsV,MAAL,GAAYlmB,CAAZ,CAAc,KAAKimB,KAAL,GAAW,QAAX;AAAoB,WAAxD,MAA4D;AAAC,kBAAK,kBAAgBjmB,CAArB;AAAuB;AAAC;AAAC,OAA1R,CAA2R,KAAKkkB,YAAL,GAAkB,UAAS3nB,CAAT,EAAW;AAAC,aAAK0nB,EAAL,CAAQC,YAAR,CAAqB3nB,CAArB;AAAwB,OAAtD,CAAuD,KAAK4nB,SAAL,GAAe,UAAS5nB,CAAT,EAAW;AAAC,aAAK0nB,EAAL,CAAQE,SAAR,CAAkB5nB,CAAlB;AAAqB,OAAhD,CAAiD,KAAK4pB,IAAL,GAAU,YAAU;AAAC,aAAKC,QAAL,GAAc,KAAKnC,EAAL,CAAQG,MAAR,EAAd,CAA+B,IAAG,OAAO,KAAKiC,QAAZ,IAAsB,WAAtB,IAAmC,OAAO,KAAKC,WAAZ,IAAyB,WAA/D,EAA2E;AAAC,cAAI/pB,IAAE,IAAIwT,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAM,KAAKqU,WAAZ,EAAtB,CAAN,CAAsD,KAAKE,KAAL,GAAWjqB,EAAEkqB,OAAF,CAAU,KAAKL,QAAf,EAAwB,KAAKC,QAA7B,CAAX;AAAkD,SAApL,MAAwL;AAAC,cAAG,KAAKL,MAAL,YAAuBzV,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,YAAvD,EAAoE;AAAC,iBAAKY,KAAL,GAAW,KAAKR,MAAL,CAAYU,sBAAZ,CAAmC,KAAKN,QAAxC,EAAiD,KAAKT,SAAtD,EAAgE,KAAKgB,UAArE,CAAX;AAA4F,WAAjK,MAAqK;AAAC,gBAAG,KAAKX,MAAL,YAAuBzV,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,KAAvD,EAA6D;AAAC,mBAAKY,KAAL,GAAW,KAAKR,MAAL,CAAYY,mBAAZ,CAAgC,KAAKR,QAArC,EAA8C,KAAKT,SAAnD,CAAX;AAAyE,aAAvI,MAA2I;AAAC,kBAAG,KAAKK,MAAL,YAAuBjW,KAAKf,MAAL,CAAYuX,KAAtC,EAA4C;AAAC,qBAAKC,KAAL,GAAW,KAAKR,MAAL,CAAYY,mBAAZ,CAAgC,KAAKR,QAArC,CAAX;AAA0D,eAAvG,MAA2G;AAAC,oBAAG,KAAKJ,MAAL,YAAuBjW,KAAKf,MAAL,CAAY6X,GAAtC,EAA0C;AAAC,uBAAKL,KAAL,GAAW,KAAKR,MAAL,CAAYY,mBAAZ,CAAgC,KAAKR,QAArC,CAAX;AAA0D,iBAArG,MAAyG;AAAC,wBAAK,6CAA2C,KAAKR,aAArD;AAAmE;AAAC;AAAC;AAAC;AAAC,gBAAO,KAAKY,KAAZ;AAAkB,OAA90B,CAA+0B,KAAKM,UAAL,GAAgB,UAASvqB,CAAT,EAAW;AAAC,aAAK2nB,YAAL,CAAkB3nB,CAAlB,EAAqB,OAAO,KAAK4pB,IAAL,EAAP;AAAmB,OAApE,CAAqE,KAAKM,OAAL,GAAa,UAASlqB,CAAT,EAAW;AAAC,aAAK4nB,SAAL,CAAe5nB,CAAf,EAAkB,OAAO,KAAK4pB,IAAL,EAAP;AAAmB,OAA9D,CAA+D,KAAKY,MAAL,GAAY,UAASxqB,CAAT,EAAW;AAAC,aAAK6pB,QAAL,GAAc,KAAKnC,EAAL,CAAQG,MAAR,EAAd,CAA+B,IAAG,OAAO,KAAK4C,QAAZ,IAAsB,WAAtB,IAAmC,OAAO,KAAKV,WAAZ,IAAyB,WAA/D,EAA2E;AAAC,cAAIlqB,IAAE,IAAI2T,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAM,KAAKqU,WAAZ,EAAtB,CAAN,CAAsD,OAAOlqB,EAAE6qB,SAAF,CAAY,KAAKb,QAAjB,EAA0B7pB,CAA1B,EAA4B,KAAKyqB,QAAjC,CAAP;AAAkD,SAApL,MAAwL;AAAC,cAAG,KAAKd,MAAL,YAAuB3V,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,YAAvD,EAAoE;AAAC,mBAAO,KAAKM,MAAL,CAAYgB,wBAAZ,CAAqC,KAAKd,QAA1C,EAAmD7pB,CAAnD,EAAqD,KAAKopB,SAA1D,EAAoE,KAAKgB,UAAzE,CAAP;AAA4F,WAAjK,MAAqK;AAAC,gBAAG,KAAKT,MAAL,YAAuB3V,MAAvB,IAA+B,KAAKqV,aAAL,KAAqB,KAAvD,EAA6D;AAAC,qBAAO,KAAKM,MAAL,CAAYiB,qBAAZ,CAAkC,KAAKf,QAAvC,EAAgD7pB,CAAhD,CAAP;AAA0D,aAAxH,MAA4H;AAAC,kBAAGwT,KAAKf,MAAL,CAAYuX,KAAZ,KAAoB7uB,SAApB,IAA+B,KAAKwuB,MAAL,YAAuBnW,KAAKf,MAAL,CAAYuX,KAArE,EAA2E;AAAC,uBAAO,KAAKL,MAAL,CAAYiB,qBAAZ,CAAkC,KAAKf,QAAvC,EAAgD7pB,CAAhD,CAAP;AAA0D,eAAtI,MAA0I;AAAC,oBAAGwT,KAAKf,MAAL,CAAY6X,GAAZ,KAAkBnvB,SAAlB,IAA6B,KAAKwuB,MAAL,YAAuBnW,KAAKf,MAAL,CAAY6X,GAAnE,EAAuE;AAAC,yBAAO,KAAKX,MAAL,CAAYiB,qBAAZ,CAAkC,KAAKf,QAAvC,EAAgD7pB,CAAhD,CAAP;AAA0D,iBAAlI,MAAsI;AAAC,wBAAK,4CAA0C,KAAKqpB,aAApD;AAAkE;AAAC;AAAC;AAAC;AAAC;AAAC,OAA52B;AAA62B;AAAC,GAAxhF,CAAyhF,KAAKpsB,IAAL,GAAU,UAASc,CAAT,EAAWF,CAAX,EAAa;AAAC,UAAK,qDAAmD,KAAKgtB,WAA7D;AAAyE,GAAjG,CAAkG,KAAKlD,YAAL,GAAkB,UAAS5pB,CAAT,EAAW;AAAC,UAAK,uDAAqD,KAAK8sB,WAA/D;AAA2E,GAAzG,CAA0G,KAAKjD,SAAL,GAAe,UAAS7pB,CAAT,EAAW;AAAC,UAAK,oDAAkD,KAAK8sB,WAA5D;AAAwE,GAAnG,CAAoG,KAAKjB,IAAL,GAAU,YAAU;AAAC,UAAK,4CAA0C,KAAKiB,WAApD;AAAgE,GAArF,CAAsF,KAAKN,UAAL,GAAgB,UAASxsB,CAAT,EAAW;AAAC,UAAK,uDAAqD,KAAK8sB,WAA/D;AAA2E,GAAvG,CAAwG,KAAKX,OAAL,GAAa,UAASnsB,CAAT,EAAW;AAAC,UAAK,oDAAkD,KAAK8sB,WAA5D;AAAwE,GAAjG,CAAkG,KAAKL,MAAL,GAAY,UAASzsB,CAAT,EAAW;AAAC,UAAK,qDAAmD,KAAK8sB,WAA7D;AAAyE,GAAjG,CAAkG,KAAKC,UAAL,GAAgBhuB,CAAhB,CAAkB,IAAGA,MAAI3B,SAAP,EAAiB;AAAC,QAAG2B,EAAE8pB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAKgtB,OAAL,GAAarrB,EAAE8pB,GAAf,CAAmB,IAAG9pB,EAAEiqB,IAAF,KAAS5rB,SAAZ,EAAsB;AAAC,aAAKitB,QAAL,GAAc5U,KAAKf,MAAL,CAAYiB,IAAZ,CAAiB0Q,eAAjB,CAAiC,KAAK+D,OAAtC,CAAd;AAA6D,OAApF,MAAwF;AAAC,aAAKC,QAAL,GAActrB,EAAEiqB,IAAhB;AAAqB,YAAK8D,WAAL,GAAiB,KAAK1C,OAAL,GAAa,GAAb,GAAiB,KAAKC,QAAvC,CAAgD,KAAKX,iBAAL,CAAuB,KAAKU,OAA5B,EAAoC,KAAKC,QAAzC,EAAmD,KAAKe,YAAL;AAAoB,SAAGrsB,EAAEiuB,UAAF,KAAe5vB,SAAlB,EAA4B;AAAC,WAAKivB,UAAL,GAAgBttB,EAAEiuB,UAAlB;AAA6B,SAAGjuB,EAAEkuB,SAAF,KAAc7vB,SAAjB,EAA2B;AAAC,UAAG2B,EAAEmuB,SAAF,KAAc9vB,SAAjB,EAA2B;AAAC,cAAK,uDAAL;AAA6D,OAAzF,MAA6F;AAAC,YAAG;AAAC,cAAI2C,IAAEyrB,QAAQC,MAAR,CAAe1sB,EAAEkuB,SAAjB,CAAN,CAAkC,KAAK/tB,IAAL,CAAUa,CAAV;AAAa,SAAnD,CAAmD,OAAMS,CAAN,EAAQ;AAAC,gBAAK,0CAAwCA,CAA7C;AAA+C;AAAC;AAAC;AAAC;AAAC,CAAxvI,CAAyvIiV,KAAKf,MAAL,CAAYyY,MAAZ,GAAmB,UAAS1uB,CAAT,EAAW,CAAE,CAAhC,CAAiCgX,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBtW,OAAnB,GAA2B,UAAS5Y,CAAT,EAAWR,CAAX,EAAaE,CAAb,EAAe;AAAC,MAAGF,aAAawY,MAAb,IAAqBxY,EAAE6Y,QAA1B,EAAmC;AAAC,QAAIpY,IAAEuX,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBC,kBAAnB,CAAsC3vB,CAAtC,EAAwCE,CAAxC,CAAN,CAAiD,IAAGO,MAAI,KAAP,EAAa;AAAC,aAAOT,EAAEoZ,OAAF,CAAU5Y,CAAV,CAAP;AAAoB,SAAGC,MAAI,SAAP,EAAiB;AAAC,aAAOT,EAAEqZ,WAAF,CAAc7Y,CAAd,EAAgB,MAAhB,CAAP;AAA+B,SAAID,IAAEE,EAAEsc,KAAF,CAAQ,gBAAR,CAAN,CAAgC,IAAGxc,MAAI,IAAP,EAAY;AAAC,aAAOP,EAAEqZ,WAAF,CAAc7Y,CAAd,EAAgB,QAAMD,EAAE,CAAF,CAAtB,CAAP;AAAmC,WAAK,uDAAqDL,CAA1D;AAA4D,GAApT,MAAwT;AAAC,UAAK,8CAAL;AAAoD;AAAC,CAAzZ,CAA0Z8X,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBE,OAAnB,GAA2B,UAASpvB,CAAT,EAAWR,CAAX,EAAaE,CAAb,EAAe;AAAC,MAAGF,aAAawY,MAAb,IAAqBxY,EAAE8Y,SAA1B,EAAoC;AAAC,QAAIrY,IAAEuX,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBC,kBAAnB,CAAsC3vB,CAAtC,EAAwCE,CAAxC,CAAN,CAAiD,IAAGO,MAAI,KAAP,EAAa;AAAC,aAAOT,EAAE4vB,OAAF,CAAUpvB,CAAV,CAAP;AAAoB,SAAGC,MAAI,SAAP,EAAiB;AAAC,aAAOT,EAAE6vB,WAAF,CAAcrvB,CAAd,EAAgB,MAAhB,CAAP;AAA+B,SAAID,IAAEE,EAAEsc,KAAF,CAAQ,gBAAR,CAAN,CAAgC,IAAGxc,MAAI,IAAP,EAAY;AAAC,aAAOP,EAAE6vB,WAAF,CAAcrvB,CAAd,EAAgB,QAAMD,EAAE,CAAF,CAAtB,CAAP;AAAmC,WAAK,uDAAqDL,CAA1D;AAA4D,GAArT,MAAyT;AAAC,UAAK,8CAAL;AAAoD;AAAC,CAA1Z,CAA2Z8X,KAAKf,MAAL,CAAYyY,MAAZ,CAAmBC,kBAAnB,GAAsC,UAASpvB,CAAT,EAAWS,CAAX,EAAa;AAAC,MAAGT,aAAaiY,MAAhB,EAAuB;AAAC,QAAG,4DAA4DtS,OAA5D,CAAoElF,CAApE,KAAwE,CAAC,CAA5E,EAA8E;AAAC,aAAOA,CAAP;AAAS,SAAGA,MAAI,IAAJ,IAAUA,MAAIrB,SAAjB,EAA2B;AAAC,aAAM,KAAN;AAAY,WAAK,kEAAgEqB,CAArE;AAAuE,SAAK,uDAAqDA,CAA1D;AAA4D,CAA/U,CAAgVgX,KAAKf,MAAL,CAAYsL,GAAZ,GAAgB,IAAI,YAAU;AAAC,OAAKuN,WAAL,GAAiB,EAAC,sBAAqB,eAAtB,EAAsC,kBAAiB,aAAvD,EAAqE,kBAAiB,KAAtF,EAA4F,oBAAmB,WAA/G,EAA2H,cAAa,WAAxI,EAAoJ,cAAa,WAAjK,EAA6K,cAAa,WAA1L,EAAsM,cAAa,WAAnN,EAA+N,cAAa,WAA5O,EAAwP,kBAAiB,aAAzQ,EAAuR,sBAAqB,eAA5S,EAA4T,sBAAqB,eAAjV,EAAjB;AAAoX,CAAnY,EAAhB;AAC/5c,IAAG,OAAO9X,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UAyE3BA,IAzE2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKf,MAAZ,IAAoB,WAApB,IAAiC,CAACe,KAAKf,MAA1C,EAAiD;AAACe,OAAKf,MAAL,GAAY,EAAZ;AAAe,MAAKA,MAAL,CAAYuX,KAAZ,GAAkB,UAASzuB,CAAT,EAAW;AAAC,MAAIS,IAAE,WAAN,CAAkB,IAAIV,IAAE,IAAN,CAAW,IAAIS,IAAE,IAAN,CAAW,IAAIP,IAAE,IAAN,CAAW,IAAIgB,IAAE,IAAIyW,YAAJ,EAAN,CAAyB,IAAIvX,IAAE,IAAN,CAAW,KAAKoZ,IAAL,GAAU,IAAV,CAAe,KAAKR,SAAL,GAAe,KAAf,CAAqB,KAAKD,QAAL,GAAc,KAAd,CAAoB,SAASpY,CAAT,CAAW8B,CAAX,EAAajB,CAAb,EAAemB,CAAf,EAAiBrB,CAAjB,EAAmB;AAAC,QAAIT,IAAE8E,KAAKf,GAAL,CAASpD,EAAE6N,SAAF,EAAT,EAAuB/N,EAAE+N,SAAF,EAAvB,CAAN,CAA4C,IAAI9M,IAAEE,EAAEga,KAAF,CAAQ9Z,CAAR,CAAN,CAAiB,IAAIH,IAAEC,EAAE2X,KAAF,CAAQW,WAAR,EAAN,CAA4B,KAAI,IAAIxZ,IAAEV,IAAE,CAAZ,EAAcU,KAAG,CAAjB,EAAmB,EAAEA,CAArB,EAAuB;AAACiB,UAAEA,EAAEka,OAAF,EAAF,CAAcla,EAAEyF,CAAF,GAAI4B,WAAWmD,GAAf,CAAmB,IAAGxL,EAAE+O,OAAF,CAAUhP,CAAV,CAAH,EAAgB;AAAC,YAAGD,EAAEiP,OAAF,CAAUhP,CAAV,CAAH,EAAgB;AAACiB,cAAEA,EAAEia,KAAF,CAAQla,CAAR,CAAF;AAAa,SAA9B,MAAkC;AAACC,cAAEA,EAAEia,KAAF,CAAQha,CAAR,CAAF;AAAa;AAAC,OAAlE,MAAsE;AAAC,YAAGnB,EAAEiP,OAAF,CAAUhP,CAAV,CAAH,EAAgB;AAACiB,cAAEA,EAAEia,KAAF,CAAQ9Z,CAAR,CAAF;AAAa;AAAC;AAAC,YAAOH,CAAP;AAAS,QAAKytB,YAAL,GAAkB,UAASnvB,CAAT,EAAW;AAAC,WAAO,IAAI+I,UAAJ,CAAe/I,EAAEuO,SAAF,EAAf,EAA6BnO,CAA7B,EAAgCqM,GAAhC,CAAoCzM,EAAE2T,QAAF,CAAW5K,WAAWmD,GAAtB,CAApC,EAAgE0H,GAAhE,CAAoE7K,WAAWmD,GAA/E,CAAP;AAA2F,GAAzH,CAA0H,KAAKkjB,aAAL,GAAmB,UAASpvB,CAAT,EAAW;AAAC,SAAKqvB,QAAL,GAAcjY,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BC,SAA1B,CAAoCvvB,CAApC,CAAd,CAAqD,KAAKwvB,SAAL,GAAe,IAAf,CAAoB,KAAKC,SAAL,GAAe,IAAf,CAAoB,KAAKC,SAAL,GAAe1vB,CAAf;AAAiB,GAA7I,CAA8I,KAAK2vB,gBAAL,GAAsB,UAAS3vB,CAAT,EAAW;AAAC,SAAKkY,SAAL,GAAe,IAAf,CAAoB,KAAKsX,SAAL,GAAexvB,CAAf;AAAiB,GAAvE,CAAwE,KAAK4vB,eAAL,GAAqB,UAAS5vB,CAAT,EAAW;AAAC,SAAKiY,QAAL,GAAc,IAAd,CAAmB,KAAKwX,SAAL,GAAezvB,CAAf;AAAiB,GAArE,CAAsE,KAAK6vB,iBAAL,GAAuB,YAAU;AAAC,QAAI1vB,IAAE,KAAKsvB,SAAX,CAAqB,IAAGtvB,EAAEsC,MAAF,CAAS,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,YAAK,mDAAL;AAAyD,SAAI1C,IAAE,KAAKsvB,QAAL,CAAcS,MAAd,GAAqB,CAA3B,CAA6B,IAAG3vB,EAAEF,MAAF,KAAW,IAAEF,IAAE,CAAlB,EAAoB;AAAC,YAAK,iCAAL;AAAuC,SAAIC,IAAE,EAAN,CAASA,EAAE0D,CAAF,GAAIvD,EAAEsC,MAAF,CAAS,CAAT,EAAW1C,CAAX,CAAJ,CAAkBC,EAAEqH,CAAF,GAAIlH,EAAEsC,MAAF,CAAS,IAAE1C,CAAX,CAAJ,CAAkB,OAAOC,CAAP;AAAS,GAAxR,CAAyR,KAAK+vB,sBAAL,GAA4B,YAAU;AAAC,QAAI/vB,IAAE,KAAK0vB,SAAX,CAAqB,IAAG1vB,MAAI,WAAJ,IAAiBA,MAAI,YAArB,IAAmCA,MAAI,OAAvC,IAAgDA,MAAI,YAAvD,EAAoE;AAAC,aAAM,OAAN;AAAc,SAAGA,MAAI,WAAJ,IAAiBA,MAAI,YAArB,IAAmCA,MAAI,OAA1C,EAAkD;AAAC,aAAM,OAAN;AAAc,YAAO,IAAP;AAAY,GAA5N,CAA6N,KAAKgwB,kBAAL,GAAwB,YAAU;AAAC,QAAI7vB,IAAE,KAAKkvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIA,IAAE,KAAK2uB,YAAL,CAAkBhvB,CAAlB,CAAN,CAA2B,IAAID,IAAE,KAAKmvB,QAAL,CAAcppB,CAAd,CAAgBiP,QAAhB,CAAyB1U,CAAzB,CAAN,CAAkC,IAAIkB,IAAExB,EAAEma,IAAF,GAASrB,YAAT,EAAN,CAA8B,IAAItY,IAAER,EAAEoa,IAAF,GAAStB,YAAT,EAAN,CAA8B,IAAIhZ,IAAE,KAAKqvB,QAAL,CAAcS,MAAd,GAAqB,CAA3B,CAA6B,IAAI3tB,IAAE,CAAC,eAAa3B,EAAEU,QAAF,CAAW,EAAX,CAAd,EAA8Bc,KAA9B,CAAoC,CAAChC,CAArC,CAAN,CAA8C,IAAI6B,IAAE,CAAC,eAAaH,EAAER,QAAF,CAAW,EAAX,CAAd,EAA8Bc,KAA9B,CAAoC,CAAChC,CAArC,CAAN,CAA8C,IAAIS,IAAE,CAAC,eAAaC,EAAEQ,QAAF,CAAW,EAAX,CAAd,EAA8Bc,KAA9B,CAAoC,CAAChC,CAArC,CAAN,CAA8C,IAAID,IAAE,OAAK8B,CAAL,GAAOpB,CAAb,CAAe,KAAKkvB,gBAAL,CAAsBxtB,CAAtB,EAAyB,KAAKytB,eAAL,CAAqB7vB,CAArB,EAAwB,OAAM,EAAC2tB,UAASvrB,CAAV,EAAYksB,UAAStuB,CAArB,EAAN;AAA8B,GAAvb,CAAwb,KAAKkuB,mBAAL,GAAyB,UAASjuB,CAAT,EAAW;AAAC,WAAO,KAAK8tB,OAAL,CAAa9tB,CAAb,EAAe,KAAKwvB,SAApB,CAAP;AAAsC,GAA3E,CAA4E,KAAK1B,OAAL,GAAa,UAASptB,CAAT,EAAWX,CAAX,EAAa;AAAC,QAAI0B,IAAE,IAAIsH,UAAJ,CAAehJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIG,IAAE,KAAKmvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIkB,IAAE,IAAIqH,UAAJ,CAAerI,CAAf,EAAiB,EAAjB,CAAN,CAA2B,GAAE;AAAC,UAAIyB,IAAE,KAAKgtB,YAAL,CAAkBjvB,CAAlB,CAAN,CAA2B,IAAI2D,IAAE,KAAKwrB,QAAL,CAAcppB,CAApB,CAAsB,IAAIxF,IAAEoD,EAAEqR,QAAF,CAAW/S,CAAX,CAAN,CAAoB,IAAInC,IAAES,EAAE4Z,IAAF,GAASrB,YAAT,GAAwBvM,GAAxB,CAA4BvM,CAA5B,CAAN;AAAqC,KAA7G,QAAmHF,EAAEiM,SAAF,CAAYlD,WAAW2B,IAAvB,KAA8B,CAAjJ,EAAoJ,IAAI9G,IAAEzB,EAAEkT,UAAF,CAAanV,CAAb,EAAgBgV,QAAhB,CAAyBxT,EAAEkS,GAAF,CAAMnS,EAAEyT,QAAF,CAAWlV,CAAX,CAAN,CAAzB,EAA+CyM,GAA/C,CAAmDvM,CAAnD,CAAN,CAA4D,OAAOkX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBqC,gBAAlB,CAAmCjwB,CAAnC,EAAqC4D,CAArC,CAAP;AAA+C,GAAtW,CAAuW,KAAK4pB,IAAL,GAAU,UAASrrB,CAAT,EAAW0B,CAAX,EAAa;AAAC,QAAInC,IAAEmC,CAAN,CAAQ,IAAI9D,IAAE,KAAKsvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIC,IAAEsI,WAAWmnB,qBAAX,CAAiC/tB,CAAjC,CAAN,CAA0C,GAAE;AAAC,UAAIjC,IAAE,KAAKivB,YAAL,CAAkBpvB,CAAlB,CAAN,CAA2B,IAAI0B,IAAE,KAAK4tB,QAAL,CAAcppB,CAApB,CAAsB,IAAIvF,IAAEe,EAAEyT,QAAF,CAAWhV,CAAX,CAAN,CAAoB,IAAIF,IAAEU,EAAE2Z,IAAF,GAASrB,YAAT,GAAwBvM,GAAxB,CAA4B1M,CAA5B,CAAN;AAAqC,KAA7G,QAAmHC,EAAEiM,SAAF,CAAYlD,WAAW2B,IAAvB,KAA8B,CAAjJ,EAAoJ,IAAI9G,IAAE1D,EAAEmV,UAAF,CAAatV,CAAb,EAAgBmV,QAAhB,CAAyBzU,EAAEmT,GAAF,CAAMlS,EAAEwT,QAAF,CAAWlV,CAAX,CAAN,CAAzB,EAA+CyM,GAA/C,CAAmD1M,CAAnD,CAAN,CAA4D,OAAO,KAAKowB,YAAL,CAAkBnwB,CAAlB,EAAoB4D,CAApB,CAAP;AAA8B,GAA9U,CAA+U,KAAK4qB,qBAAL,GAA2B,UAASzuB,CAAT,EAAWC,CAAX,EAAa;AAAC,WAAO,KAAKsuB,SAAL,CAAevuB,CAAf,EAAiBC,CAAjB,EAAmB,KAAKyvB,SAAxB,CAAP;AAA0C,GAAnF,CAAoF,KAAKnB,SAAL,GAAe,UAASnsB,CAAT,EAAWnC,CAAX,EAAaS,CAAb,EAAe;AAAC,QAAIP,CAAJ,EAAMH,CAAN,CAAQ,IAAIW,IAAE0W,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBwC,WAAlB,CAA8BpwB,CAA9B,CAAN,CAAuCE,IAAEQ,EAAEmB,CAAJ,CAAM9B,IAAEW,EAAEiB,CAAJ,CAAM,IAAIxB,CAAJ,CAAMA,IAAEkZ,UAAUqC,aAAV,CAAwB,KAAK2T,QAAL,CAAc/V,KAAtC,EAA4C7Y,CAA5C,CAAF,CAAiD,IAAID,IAAE,IAAIuI,UAAJ,CAAe5G,CAAf,EAAiB,EAAjB,CAAN,CAA2B,OAAO,KAAKkuB,SAAL,CAAe7vB,CAAf,EAAiBN,CAAjB,EAAmBH,CAAnB,EAAqBI,CAArB,CAAP;AAA+B,GAA3M,CAA4M,KAAKiuB,MAAL,GAAY,UAAS1tB,CAAT,EAAWD,CAAX,EAAaV,CAAb,EAAe;AAAC,QAAIG,CAAJ,EAAMF,CAAN,CAAQ,IAAGswB,QAAQhZ,IAAR,CAAaiZ,OAAb,CAAqB9vB,CAArB,CAAH,EAA2B;AAAC,UAAID,IAAE,KAAKgwB,QAAL,CAAc/vB,CAAd,CAAN,CAAuBP,IAAEM,EAAEqB,CAAJ,CAAM7B,IAAEQ,EAAEmB,CAAJ;AAAM,KAA/D,MAAmE;AAAC,UAAG,qBAAkBlB,CAAlB,yCAAkBA,CAAlB,MAAqBA,EAAEoB,CAAvB,IAA0BpB,EAAEkB,CAA/B,EAAiC;AAACzB,YAAEO,EAAEoB,CAAJ,CAAM7B,IAAES,EAAEkB,CAAJ;AAAM,OAA9C,MAAkD;AAAC,cAAK,6BAAL;AAAmC;AAAC,SAAIxB,CAAJ,CAAM,IAAGJ,aAAasZ,SAAhB,EAA0B;AAAClZ,UAAEJ,CAAF;AAAI,KAA/B,MAAmC;AAAC,UAAGuwB,QAAQhZ,IAAR,CAAaiZ,OAAb,CAAqBxwB,CAArB,CAAH,EAA2B;AAACI,YAAEkZ,UAAUoC,UAAV,CAAqB,KAAK4T,QAAL,CAAc/V,KAAnC,EAAyCvZ,CAAzC,CAAF;AAA8C,OAA1E,MAA8E;AAAC,cAAK,kEAAL;AAAwE;AAAC,SAAIoC,IAAE4G,WAAWmnB,qBAAX,CAAiCxvB,CAAjC,CAAN,CAA0C,OAAO,KAAK2vB,SAAL,CAAeluB,CAAf,EAAiBjC,CAAjB,EAAmBF,CAAnB,EAAqBG,CAArB,CAAP;AAA+B,GAA1c,CAA2c,KAAKkwB,SAAL,GAAe,UAAS3vB,CAAT,EAAWV,CAAX,EAAayD,CAAb,EAAetB,CAAf,EAAiB;AAAC,QAAIjC,IAAE,KAAKmvB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIqD,IAAE,KAAKwrB,QAAL,CAAcppB,CAApB,CAAsB,IAAGjG,EAAEiM,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+BlM,EAAEiM,SAAF,CAAY/L,CAAZ,KAAgB,CAAlD,EAAoD;AAAC,aAAO,KAAP;AAAa,SAAGuD,EAAEwI,SAAF,CAAYlD,WAAWmD,GAAvB,IAA4B,CAA5B,IAA+BzI,EAAEwI,SAAF,CAAY/L,CAAZ,KAAgB,CAAlD,EAAoD;AAAC,aAAO,KAAP;AAAa,SAAIO,IAAEgD,EAAE4R,UAAF,CAAanV,CAAb,CAAN,CAAsB,IAAIC,IAAEO,EAAEwU,QAAF,CAAWzU,CAAX,EAAcgM,GAAd,CAAkBvM,CAAlB,CAAN,CAA2B,IAAIH,IAAEC,EAAEkV,QAAF,CAAWzU,CAAX,EAAcgM,GAAd,CAAkBvM,CAAlB,CAAN,CAA2B,IAAIwB,IAAEmC,EAAEqR,QAAF,CAAW/U,CAAX,EAAcyT,GAAd,CAAkBzR,EAAE+S,QAAF,CAAWnV,CAAX,CAAlB,CAAN,CAAuC,IAAI0B,IAAEC,EAAE2Y,IAAF,GAASrB,YAAT,GAAwBvM,GAAxB,CAA4BvM,CAA5B,CAAN,CAAqC,OAAOuB,EAAE+S,MAAF,CAASxU,CAAT,CAAP;AAAmB,GAA5X,CAA6X,KAAKmwB,YAAL,GAAkB,UAAShwB,CAAT,EAAWJ,CAAX,EAAa;AAAC,QAAIG,IAAEC,EAAEswB,iBAAF,EAAN,CAA4B,IAAIzwB,IAAED,EAAE0wB,iBAAF,EAAN,CAA4B,IAAItuB,IAAE,EAAN,CAASA,EAAED,IAAF,CAAO,CAAP,EAAUC,EAAED,IAAF,CAAOhC,EAAED,MAAT,EAAiBkC,IAAEA,EAAEX,MAAF,CAAStB,CAAT,CAAF,CAAciC,EAAED,IAAF,CAAO,CAAP,EAAUC,EAAED,IAAF,CAAOlC,EAAEC,MAAT,EAAiBkC,IAAEA,EAAEX,MAAF,CAASxB,CAAT,CAAF,CAAcmC,EAAEqZ,OAAF,CAAUrZ,EAAElC,MAAZ,EAAoBkC,EAAEqZ,OAAF,CAAU,EAAV,EAAc,OAAOrZ,CAAP;AAAS,GAA9N,CAA+N,KAAKquB,QAAL,GAAc,UAAShwB,CAAT,EAAW;AAAC,QAAI2B,CAAJ,CAAM,IAAG3B,EAAE,CAAF,KAAM,EAAT,EAAY;AAAC,YAAM,IAAInB,KAAJ,CAAU,mCAAV,CAAN;AAAqD,SAAE,CAAF,CAAI,IAAGmB,EAAE2B,CAAF,KAAM,CAAT,EAAW;AAAC,YAAM,IAAI9C,KAAJ,CAAU,iDAAV,CAAN;AAAmE,SAAIa,IAAEM,EAAEwB,KAAF,CAAQG,IAAE,CAAV,EAAYA,IAAE,CAAF,GAAI3B,EAAE2B,IAAE,CAAJ,CAAhB,CAAN,CAA8BA,KAAG,IAAE3B,EAAE2B,IAAE,CAAJ,CAAL,CAAY,IAAG3B,EAAE2B,CAAF,KAAM,CAAT,EAAW;AAAC,YAAM,IAAI9C,KAAJ,CAAU,kDAAV,CAAN;AAAoE,SAAIW,IAAEQ,EAAEwB,KAAF,CAAQG,IAAE,CAAV,EAAYA,IAAE,CAAF,GAAI3B,EAAE2B,IAAE,CAAJ,CAAhB,CAAN,CAA8BA,KAAG,IAAE3B,EAAE2B,IAAE,CAAJ,CAAL,CAAY,IAAIhC,IAAE4I,WAAWmnB,qBAAX,CAAiChwB,CAAjC,CAAN,CAA0C,IAAIH,IAAEgJ,WAAWmnB,qBAAX,CAAiClwB,CAAjC,CAAN,CAA0C,OAAM,EAAC6B,GAAE1B,CAAH,EAAKwB,GAAE5B,CAAP,EAAN;AAAgB,GAA7b,CAA8b,KAAK2wB,eAAL,GAAqB,UAASvuB,CAAT,EAAW;AAAC,QAAGA,EAAElC,MAAF,KAAW,EAAd,EAAiB;AAAC,YAAK,gCAAL;AAAsC,SAAIF,IAAEoC,EAAE,CAAF,IAAK,EAAX,CAAc,IAAGpC,IAAE,CAAF,IAAKA,IAAE,CAAV,EAAY;AAAC,YAAK,wBAAL;AAA8B,SAAIW,IAAE,KAAK2uB,QAAL,CAAc7uB,CAApB,CAAsB,IAAIN,IAAE6I,WAAWmnB,qBAAX,CAAiC/tB,EAAEH,KAAF,CAAQ,CAAR,EAAU,EAAV,CAAjC,EAAgDyK,GAAhD,CAAoD/L,CAApD,CAAN,CAA6D,IAAIP,IAAE4I,WAAWmnB,qBAAX,CAAiC/tB,EAAEH,KAAF,CAAQ,EAAR,EAAW,EAAX,CAAjC,EAAiDyK,GAAjD,CAAqD/L,CAArD,CAAN,CAA8D,OAAM,EAACmB,GAAE3B,CAAH,EAAKyB,GAAExB,CAAP,EAASH,GAAED,CAAX,EAAN;AAAoB,GAAvT,CAAwT,KAAK4wB,kBAAL,GAAwB,UAASzwB,CAAT,EAAW;AAAC,QAAIM,IAAEgiB,OAAN,CAAc,IAAIrgB,IAAEiV,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAInwB,IAAED,EAAE4iB,UAAR,CAAmB,IAAG5iB,EAAEgjB,SAAF,CAAYtjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIF,CAAJ,EAAMG,CAAN,EAAQO,CAAR,CAAU,IAAG;AAACV,UAAES,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBC,IAAEM,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAF,CAAkB,IAAG;AAACQ,YAAED,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,EAAkBuC,MAAlB,CAAyB,CAAzB,CAAF;AAA8B,OAAlC,CAAkC,OAAM1C,CAAN,EAAQ,CAAE;AAAC,KAAvF,CAAuF,OAAMA,CAAN,EAAQ;AAAC,YAAK,0CAAL;AAAgD,UAAK2vB,SAAL,GAAevtB,EAAEnC,CAAF,CAAf,CAAoB,IAAG,KAAK0vB,SAAL,KAAiB3wB,SAApB,EAA8B;AAAC,YAAK,wBAAL;AAA8B,UAAKqwB,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBlvB,CAArB,EAAwB,KAAKivB,gBAAL,CAAsBxvB,CAAtB,EAAyB,KAAK8X,QAAL,GAAc,KAAd;AAAoB,GAA/e,CAAgf,KAAK4Y,kBAAL,GAAwB,UAAS3wB,CAAT,EAAW;AAAC,QAAIwB,IAAE8gB,OAAN,CAAc,IAAIxiB,IAAEoX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAIpwB,IAAEkB,EAAE0hB,UAAR,CAAmB,IAAG1hB,EAAE8hB,SAAF,CAAYtjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIH,CAAJ,EAAMU,CAAN,EAAQ0B,CAAR,EAAUhC,CAAV,CAAY,IAAG;AAACJ,UAAES,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBO,IAAED,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBiC,IAAE3B,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsB,IAAG;AAACC,YAAEK,EAAEN,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,EAAO,CAAP,CAAN,EAAgB,IAAhB,EAAsBuC,MAAtB,CAA6B,CAA7B,CAAF;AAAkC,OAAtC,CAAsC,OAAM/B,CAAN,EAAQ,CAAE;AAAC,KAAnH,CAAmH,OAAMA,CAAN,EAAQ;AAAC,YAAK,wCAAL;AAA8C,UAAKgvB,SAAL,GAAe1vB,EAAES,CAAF,CAAf,CAAoB,IAAG,KAAKivB,SAAL,KAAiB3wB,SAApB,EAA8B;AAAC,YAAK,wBAAL;AAA8B,UAAKqwB,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBzvB,CAArB,EAAwB,KAAKwvB,gBAAL,CAAsBxtB,CAAtB,EAAyB,KAAK8V,QAAL,GAAc,KAAd;AAAoB,GAA3gB,CAA4gB,KAAK6Y,kBAAL,GAAwB,UAAS5wB,CAAT,EAAW;AAAC,QAAIM,IAAEgiB,OAAN,CAAc,IAAIrgB,IAAEiV,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAInwB,IAAED,EAAE4iB,UAAR,CAAmB,IAAG5iB,EAAEgjB,SAAF,CAAYtjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIC,CAAJ,EAAMH,CAAN,EAAQU,CAAR,CAAU,IAAG;AAACP,UAAEM,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBF,IAAES,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAF,CAAoBQ,IAAED,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,EAAgBuC,MAAhB,CAAuB,CAAvB,CAAF;AAA4B,KAAxE,CAAwE,OAAM1C,CAAN,EAAQ;AAAC,YAAK,iCAAL;AAAuC,UAAK2vB,SAAL,GAAevtB,EAAEnC,CAAF,CAAf,CAAoB,IAAG,KAAK0vB,SAAL,KAAiB,IAApB,EAAyB;AAAC,YAAK,wBAAL;AAA8B,UAAKN,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBlvB,CAArB;AAAwB,GAAra,CAAsa,KAAKqwB,iBAAL,GAAuB,UAAS5wB,CAAT,EAAWM,CAAX,EAAa;AAAC,QAAGA,MAAI,CAAP,EAAS;AAACA,UAAE,CAAF;AAAI,SAAI0B,IAAEqgB,OAAN,CAAc,IAAItiB,IAAEkX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAxB,CAAgC,IAAIlwB,IAAEyB,EAAEihB,UAAR,CAAmB,IAAGjhB,EAAEqhB,SAAF,CAAYrjB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,YAAK,sBAAL;AAA4B,SAAIH,CAAJ,EAAMQ,CAAN,CAAQ,IAAG;AAACR,UAAEU,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAGM,CAAH,EAAK,CAAL,EAAO,CAAP,CAAN,EAAgB,IAAhB,CAAF,CAAwBD,IAAEE,EAAEP,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAGM,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,EAAoBgC,MAApB,CAA2B,CAA3B,CAAF;AAAgC,KAA5D,CAA4D,OAAM1C,CAAN,EAAQ;AAAC,YAAK,4CAAL;AAAkD,UAAK2vB,SAAL,GAAexvB,EAAEF,CAAF,CAAf,CAAoB,IAAG,KAAK0vB,SAAL,KAAiB,IAApB,EAAyB;AAAC,YAAK,wBAAL;AAA8B,UAAKN,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,KAAKE,eAAL,CAAqBpvB,CAArB;AAAwB,GAAjb,CAAkb,IAAGrB,MAAIJ,SAAP,EAAiB;AAAC,QAAGI,EAAEma,KAAF,KAAUva,SAAb,EAAuB;AAAC,WAAK2wB,SAAL,GAAevwB,EAAEma,KAAjB;AAAuB;AAAC,OAAG,KAAKoW,SAAL,KAAiB3wB,SAApB,EAA8B;AAAC,SAAK2wB,SAAL,GAAe9vB,CAAf;AAAiB,QAAKwvB,aAAL,CAAmB,KAAKM,SAAxB,EAAmC,IAAGvwB,MAAIJ,SAAP,EAAiB;AAAC,QAAGI,EAAE6xB,GAAF,KAAQjyB,SAAX,EAAqB;AAAC,WAAK4wB,gBAAL,CAAsBxwB,EAAE6xB,GAAxB;AAA6B,SAAG7xB,EAAE8xB,GAAF,KAAQlyB,SAAX,EAAqB;AAAC,WAAK6wB,eAAL,CAAqBzwB,EAAE8xB,GAAvB;AAA4B;AAAC;AAAC,CAAxqN,CAAyqN7Z,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBwC,WAAlB,GAA8B,UAAShwB,CAAT,EAAW;AAAC,MAAIT,IAAEyX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBsD,kBAAlB,CAAqC9wB,CAArC,CAAN,CAA8C,IAAId,IAAE,IAAIyJ,UAAJ,CAAepJ,EAAEkC,CAAjB,EAAmB,EAAnB,CAAN,CAA6B,IAAIhC,IAAE,IAAIkJ,UAAJ,CAAepJ,EAAEgC,CAAjB,EAAmB,EAAnB,CAAN,CAA6B,OAAM,EAACE,GAAEvC,CAAH,EAAKqC,GAAE9B,CAAP,EAAN;AAAgB,CAAlK,CAAmKuX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBsD,kBAAlB,GAAqC,UAAS9xB,CAAT,EAAW;AAAC,MAAIW,IAAEyiB,OAAN,CAAc,IAAIxiB,IAAED,EAAEijB,WAAR,CAAoB,IAAI9jB,IAAEa,EAAE8iB,IAAR,CAAa,IAAGzjB,EAAEqD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,mCAAL;AAAyC,OAAItD,IAAEa,EAAEZ,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGD,EAAEc,MAAF,IAAU,CAAb,EAAe;AAAC,UAAK,wDAAL;AAA8D,OAAIL,IAAET,EAAE,CAAF,CAAN,CAAW,IAAIG,IAAEH,EAAE,CAAF,CAAN,CAAW,IAAGC,EAAEqD,MAAF,CAAS7C,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,uDAAL;AAA6D,OAAGR,EAAEqD,MAAF,CAASnD,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,uDAAL;AAA6D,OAAIO,IAAEX,EAAEE,CAAF,EAAIQ,CAAJ,CAAN,CAAa,IAAID,IAAET,EAAEE,CAAF,EAAIE,CAAJ,CAAN,CAAa,OAAM,EAACuC,GAAEhC,CAAH,EAAK8B,GAAEhC,CAAP,EAAN;AAAgB,CAAte,CAAueyX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBuD,kBAAlB,GAAqC,UAAStxB,CAAT,EAAW;AAAC,MAAIP,IAAE8X,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBsD,kBAAlB,CAAqCrxB,CAArC,CAAN,CAA8C,IAAIF,IAAEL,EAAEuC,CAAR,CAAU,IAAIzB,IAAEd,EAAEqC,CAAR,CAAU,IAAGhC,EAAE8C,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAf,IAAsB9C,EAAEM,MAAF,GAAS,EAAV,IAAe,CAAvC,EAAyC;AAACN,QAAEA,EAAE8C,MAAF,CAAS,CAAT,CAAF;AAAc,OAAGrC,EAAEqC,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAf,IAAsBrC,EAAEH,MAAF,GAAS,EAAV,IAAe,CAAvC,EAAyC;AAACG,QAAEA,EAAEqC,MAAF,CAAS,CAAT,CAAF;AAAc,OAAI9C,EAAEM,MAAF,GAAS,EAAV,IAAe,EAAlB,EAAqB;AAACN,QAAE,OAAKA,CAAP;AAAS,OAAIS,EAAEH,MAAF,GAAS,EAAV,IAAe,EAAlB,EAAqB;AAACG,QAAE,OAAKA,CAAP;AAAS,OAAGT,EAAEM,MAAF,GAAS,EAAT,IAAa,CAAhB,EAAkB;AAAC,UAAK,kCAAL;AAAwC,OAAGG,EAAEH,MAAF,GAAS,EAAT,IAAa,CAAhB,EAAkB;AAAC,UAAK,kCAAL;AAAwC,UAAON,IAAES,CAAT;AAAW,CAAla,CAAmagX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBwD,kBAAlB,GAAqC,UAAShxB,CAAT,EAAW;AAAC,MAAMA,EAAEH,MAAF,GAAS,CAAV,GAAa,CAAd,IAAkB,KAAG,CAArB,CAAD,IAA2B,CAA9B,EAAgC;AAAC,UAAK,kDAAL;AAAwD,OAAIJ,IAAEO,EAAEqC,MAAF,CAAS,CAAT,EAAWrC,EAAEH,MAAF,GAAS,CAApB,CAAN,CAA6B,IAAIN,IAAES,EAAEqC,MAAF,CAASrC,EAAEH,MAAF,GAAS,CAAlB,CAAN,CAA2B,OAAOmX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkByD,iBAAlB,CAAoCxxB,CAApC,EAAsCF,CAAtC,CAAP;AAAgD,CAAlP,CAAmPyX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkByD,iBAAlB,GAAoC,UAAS1xB,CAAT,EAAWS,CAAX,EAAa;AAAC,MAAId,IAAE,IAAIyJ,UAAJ,CAAepJ,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAIE,IAAE,IAAIkJ,UAAJ,CAAe3I,CAAf,EAAiB,EAAjB,CAAN,CAA2B,OAAOgX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBqC,gBAAlB,CAAmC3wB,CAAnC,EAAqCO,CAArC,CAAP;AAA+C,CAAvJ,CAAwJuX,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBqC,gBAAlB,GAAmC,UAAS7wB,CAAT,EAAWE,CAAX,EAAa;AAAC,MAAIO,IAAEuX,KAAKkF,IAAX,CAAgB,IAAI3c,IAAE,IAAIE,EAAEid,UAAN,CAAiB,EAACmE,QAAO7hB,CAAR,EAAjB,CAAN,CAAmC,IAAIgB,IAAE,IAAIP,EAAEid,UAAN,CAAiB,EAACmE,QAAO3hB,CAAR,EAAjB,CAAN,CAAmC,IAAIM,IAAE,IAAIC,EAAE8d,WAAN,CAAkB,EAACI,OAAM,CAACpe,CAAD,EAAGS,CAAH,CAAP,EAAlB,CAAN,CAAuC,OAAOR,EAAEwe,aAAF,EAAP;AAAyB,CAAvM,CAAwMhH,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBgD,OAAlB,GAA0B,UAASxwB,CAAT,EAAW;AAAC,MAAGA,MAAI,kBAAP,EAA0B;AAAC,WAAM,WAAN;AAAkB,OAAGA,MAAI,YAAP,EAAoB;AAAC,WAAM,WAAN;AAAkB,OAAGA,MAAI,YAAP,EAAoB;AAAC,WAAM,WAAN;AAAkB,OAAG,0CAA0CkF,OAA1C,CAAkDlF,CAAlD,MAAuD,CAAC,CAA3D,EAA6D;AAAC,WAAM,WAAN;AAAkB,OAAG,cAAckF,OAAd,CAAsBlF,CAAtB,MAA2B,CAAC,CAA/B,EAAiC;AAAC,WAAM,WAAN;AAAkB,OAAG,+BAA+BkF,OAA/B,CAAuClF,CAAvC,MAA4C,CAAC,CAAhD,EAAkD;AAAC,WAAM,WAAN;AAAkB,UAAO,IAAP;AAAY,CAAtX;AACt5Q,IAAG,OAAOgX,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UAwE3BA,IAxE2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKf,MAAZ,IAAoB,WAApB,IAAiC,CAACe,KAAKf,MAA1C,EAAiD;AAACe,OAAKf,MAAL,GAAY,EAAZ;AAAe,MAAKA,MAAL,CAAYiZ,aAAZ,GAA0B,IAAI,YAAU;AAAC,MAAI3vB,IAAE,EAAN,CAAS,IAAIE,IAAE,EAAN,CAAS,SAASO,CAAT,CAAWd,CAAX,EAAa;AAAC,WAAO,IAAIyJ,UAAJ,CAAezJ,CAAf,EAAiB,EAAjB,CAAP;AAA4B,QAAKiwB,SAAL,GAAe,UAAS3vB,CAAT,EAAW;AAAC,QAAIN,IAAEM,CAAN,CAAQ,IAAG,OAAOC,EAAEP,CAAF,CAAP,IAAa,WAAhB,EAA4B;AAACA,UAAEO,EAAED,CAAF,CAAF;AAAO,SAAG,OAAOD,EAAEL,CAAF,CAAP,IAAa,WAAhB,EAA4B;AAAC,aAAOK,EAAEL,CAAF,CAAP;AAAY,WAAK,iCAA+BA,CAApC;AAAsC,GAAtJ,CAAuJ,KAAKgyB,MAAL,GAAY,UAASlqB,CAAT,EAAWlH,CAAX,EAAaQ,CAAb,EAAexB,CAAf,EAAiBiD,CAAjB,EAAmBvC,CAAnB,EAAqBG,CAArB,EAAuBX,CAAvB,EAAyBe,CAAzB,EAA2B0D,CAA3B,EAA6BvE,CAA7B,EAA+BoE,CAA/B,EAAiC;AAAC/D,MAAEyH,CAAF,IAAK,EAAL,CAAQ,IAAIzF,IAAEvB,EAAEM,CAAF,CAAN,CAAW,IAAIyG,IAAE/G,EAAElB,CAAF,CAAN,CAAW,IAAImI,IAAEjH,EAAE+B,CAAF,CAAN,CAAW,IAAIV,IAAErB,EAAER,CAAF,CAAN,CAAW,IAAI6D,IAAErD,EAAEL,CAAF,CAAN,CAAW,IAAI8B,IAAE,IAAI2Y,SAAJ,CAAc7Y,CAAd,EAAgBwF,CAAhB,EAAkBE,CAAlB,CAAN,CAA2B,IAAI3F,IAAEG,EAAEuZ,cAAF,CAAiB,OAAKhc,CAAL,GAAOe,CAAxB,CAAN,CAAiCR,EAAEyH,CAAF,EAAK,MAAL,IAAaA,CAAb,CAAezH,EAAEyH,CAAF,EAAK,QAAL,IAAelH,CAAf,CAAiBP,EAAEyH,CAAF,EAAK,OAAL,IAAcvF,CAAd,CAAgBlC,EAAEyH,CAAF,EAAK,GAAL,IAAU1F,CAAV,CAAY/B,EAAEyH,CAAF,EAAK,GAAL,IAAU3F,CAAV,CAAY9B,EAAEyH,CAAF,EAAK,GAAL,IAAU3D,CAAV,CAAY9D,EAAEyH,CAAF,EAAK,KAAL,IAAY9H,CAAZ,CAAcK,EAAEyH,CAAF,EAAK,MAAL,IAAa1D,CAAb,CAAe,KAAI,IAAIE,IAAE,CAAV,EAAYA,IAAEC,EAAE5D,MAAhB,EAAuB2D,GAAvB,EAA2B;AAAC/D,QAAEgE,EAAED,CAAF,CAAF,IAAQwD,CAAR;AAAU;AAAC,GAAjU;AAAkU,CAApiB,EAA1B,CAA+jBgQ,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kCAAjD,EAAoF,kCAApF,EAAuH,kCAAvH,EAA0J,kCAA1J,EAA6L,GAA7L,EAAiM,kCAAjM,EAAoO,kCAApO,EAAuQ,EAAvQ,EAA0Q,EAA1Q,EAA6Q,mDAA7Q,EAAkUla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,0CAAjD,EAA4F,GAA5F,EAAgG,GAAhG,EAAoG,4CAApG,EAAiJ,GAAjJ,EAAqJ,0CAArJ,EAAgM,0CAAhM,EAA2O,EAA3O,EAA8O,EAA9O,EAAiP,mDAAjP,EAAsSla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,0CAAjD,EAA4F,0CAA5F,EAAuI,0CAAvI,EAAkL,4CAAlL,EAA+N,GAA/N,EAAmO,0CAAnO,EAA8Q,0CAA9Q,EAAyT,EAAzT,EAA4T,EAA5T,EAA+T,mDAA/T,EAAoXla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kDAAjD,EAAoG,GAApG,EAAwG,GAAxG,EAA4G,kDAA5G,EAA+J,GAA/J,EAAmK,kDAAnK,EAAsN,kDAAtN,EAAyQ,EAAzQ,EAA6Qla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kDAAjD,EAAoG,kDAApG,EAAuJ,kDAAvJ,EAA0M,kDAA1M,EAA6P,GAA7P,EAAiQ,kDAAjQ,EAAoT,kDAApT,EAAuW,EAAvW,EAA2Wla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,0DAAjD,EAA4G,0DAA5G,EAAuK,0DAAvK,EAAkO,0DAAlO,EAA6R,GAA7R,EAAiS,0DAAjS,EAA4V,0DAA5V,EAAuZ,EAAvZ,EAA2Zla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kEAAjD,EAAoH,GAApH,EAAwH,GAAxH,EAA4H,kEAA5H,EAA+L,GAA/L,EAAmM,kEAAnM,EAAsQ,kEAAtQ,EAAyU,EAAzU,EAA6Ula,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kEAAjD,EAAoH,kEAApH,EAAuL,kEAAvL,EAA0P,kEAA1P,EAA6T,GAA7T,EAAiU,kEAAjU,EAAoY,kEAApY,EAAuc,CAAC,YAAD,EAAc,OAAd,EAAsB,YAAtB,CAAvc,EAA4ela,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,kGAAjD,EAAoJ,kGAApJ,EAAuP,kGAAvP,EAA0V,kGAA1V,EAA6b,GAA7b,EAAic,kGAAjc,EAAoiB,kGAApiB,EAAuoB,CAAC,YAAD,EAAc,OAAd,CAAvoB,EAA+pBla,KAAKf,MAAL,CAAYiZ,aAAZ,CAA0BgC,MAA1B,CAAiC,WAAjC,EAA6C,GAA7C,EAAiD,qIAAjD,EAAuL,qIAAvL,EAA6T,qIAA7T,EAAmc,qIAAnc,EAAykB,GAAzkB,EAA6kB,oIAA7kB,EAAktB,sIAAltB,EAAy1B,CAAC,YAAD,EAAc,OAAd,CAAz1B;AACnnI,IAAInE,UAAQ,YAAU;AAAC,MAAI7tB,IAAE,SAAFA,CAAE,CAASmB,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOvB,EAAEE,SAASkxB,GAAX,EAAe9wB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAI9B,IAAE,SAAFA,CAAE,CAASa,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOvB,EAAEE,SAASmxB,SAAX,EAAqB/wB,CAArB,EAAuBoB,CAAvB,EAAyBH,CAAzB,CAAP;AAAmC,GAAzD,CAA0D,IAAItB,IAAE,SAAFA,CAAE,CAASK,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOvB,EAAEE,SAASoxB,GAAX,EAAehxB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAIvB,IAAE,SAAFA,CAAE,CAASwB,CAAT,EAAW+B,CAAX,EAAaG,CAAb,EAAenC,CAAf,EAAiB;AAAC,QAAIG,IAAExB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBmB,CAAvB,CAAN,CAAgC,IAAID,IAAEpD,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBsB,CAAvB,CAAN,CAAgC,IAAIpD,IAAEJ,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBb,CAAvB,CAAN,CAAgC,IAAID,IAAE,EAAN,CAASA,EAAEiwB,GAAF,GAAMjuB,CAAN,CAAQhC,EAAEkwB,EAAF,GAAKlxB,CAAL,CAAOgB,EAAEmwB,UAAF,GAAa/vB,CAAb,CAAe,IAAI+B,IAAEjC,EAAEqtB,OAAF,CAAUvtB,CAAV,EAAYgC,CAAZ,EAAc,EAACkuB,IAAGlxB,CAAJ,EAAd,CAAN,CAA4B,OAAOJ,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BqC,CAA3B,CAAP;AAAqC,GAAhO,CAAiO,IAAI1D,IAAE,SAAFA,CAAE,CAASO,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOxC,EAAEmB,SAASkxB,GAAX,EAAe9wB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAIhB,IAAE,SAAFA,CAAE,CAASD,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOxC,EAAEmB,SAASmxB,SAAX,EAAqB/wB,CAArB,EAAuBoB,CAAvB,EAAyBH,CAAzB,CAAP;AAAmC,GAAzD,CAA0D,IAAItC,IAAE,SAAFA,CAAE,CAASqB,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAe;AAAC,WAAOxC,EAAEmB,SAASoxB,GAAX,EAAehxB,CAAf,EAAiBoB,CAAjB,EAAmBH,CAAnB,CAAP;AAA6B,GAAnD,CAAoD,IAAIxC,IAAE,SAAFA,CAAE,CAASuC,CAAT,EAAW4F,CAAX,EAAazD,CAAb,EAAelC,CAAf,EAAiB;AAAC,QAAIC,IAAEtB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuB8E,CAAvB,CAAN,CAAgC,IAAI3D,IAAErD,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBqB,CAAvB,CAAN,CAAgC,IAAInD,IAAEJ,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBb,CAAvB,CAAN,CAAgC,IAAI+B,IAAEhC,EAAE+W,OAAF,CAAU7W,CAAV,EAAY+B,CAAZ,EAAc,EAACiuB,IAAGlxB,CAAJ,EAAd,CAAN,CAA4B,IAAIoB,IAAExB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBkB,EAAEvC,QAAF,EAAvB,CAAN,CAA2C,IAAI2C,IAAExD,SAAS+B,GAAT,CAAa+C,MAAb,CAAoB5D,SAApB,CAA8BM,CAA9B,CAAN,CAAuC,OAAOgC,CAAP;AAAS,GAA/O,CAAgP,IAAI7D,IAAE,EAAC,eAAc,EAAC6xB,MAAKvyB,CAAN,EAAQwyB,OAAM5xB,CAAd,EAAgB4vB,QAAO,EAAvB,EAA0BiC,OAAM,EAAhC,EAAf,EAAmD,eAAc,EAACF,MAAKvyB,CAAN,EAAQwyB,OAAM5xB,CAAd,EAAgB4vB,QAAO,EAAvB,EAA0BiC,OAAM,EAAhC,EAAjE,EAAqG,eAAc,EAACF,MAAKvyB,CAAN,EAAQwyB,OAAM5xB,CAAd,EAAgB4vB,QAAO,EAAvB,EAA0BiC,OAAM,EAAhC,EAAnH,EAAuJ,gBAAe,EAACF,MAAKjyB,CAAN,EAAQkyB,OAAMpxB,CAAd,EAAgBovB,QAAO,EAAvB,EAA0BiC,OAAM,CAAhC,EAAtK,EAAyM,WAAU,EAACF,MAAKzxB,CAAN,EAAQ0xB,OAAM1yB,CAAd,EAAgB0wB,QAAO,CAAvB,EAAyBiC,OAAM,CAA/B,EAAnN,EAAN,CAA4P,IAAIlyB,IAAE,SAAFA,CAAE,CAASY,CAAT,EAAW;AAAC,WAAOT,EAAES,CAAF,EAAK,MAAL,CAAP;AAAoB,GAAtC,CAAuC,IAAI0B,IAAE,SAAFA,CAAE,CAAS1B,CAAT,EAAW;AAAC,QAAIoB,IAAExB,SAASC,GAAT,CAAac,SAAb,CAAuBa,MAAvB,CAA8BxB,CAA9B,CAAN,CAAuC,IAAIiB,IAAErB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BM,CAA3B,CAAN,CAAoC,OAAOH,CAAP;AAAS,GAAtG,CAAuG,IAAIlB,IAAE,SAAFA,CAAE,CAASoD,CAAT,EAAW;AAAC,QAAIH,IAAE,EAAN,CAAS,IAAI/B,IAAEkC,EAAEuY,KAAF,CAAQ,IAAID,MAAJ,CAAW,kCAAX,EAA8C,GAA9C,CAAR,CAAN,CAAkE,IAAGxa,CAAH,EAAK;AAAC+B,QAAEuuB,MAAF,GAAStwB,EAAE,CAAF,CAAT,CAAc+B,EAAEwuB,MAAF,GAASvwB,EAAE,CAAF,CAAT;AAAc,SAAIjB,IAAEmD,EAAEuY,KAAF,CAAQ,IAAID,MAAJ,CAAW,sCAAX,CAAR,CAAN,CAAkE,IAAGzb,CAAH,EAAK;AAACgD,QAAEiV,IAAF,GAAOjY,EAAE,CAAF,CAAP;AAAY,SAAIoD,IAAE,CAAC,CAAP,CAAS,IAAIH,IAAE,CAAN,CAAQ,IAAGE,EAAE0B,OAAF,CAAU,UAAV,KAAuB,CAAC,CAA3B,EAA6B;AAACzB,UAAED,EAAE0B,OAAF,CAAU,UAAV,CAAF,CAAwB5B,IAAE,CAAF;AAAI,SAAGE,EAAE0B,OAAF,CAAU,MAAV,KAAmB,CAAC,CAAvB,EAAyB;AAACzB,UAAED,EAAE0B,OAAF,CAAU,MAAV,CAAF,CAAoB5B,IAAE,CAAF;AAAI,SAAIjC,IAAEmC,EAAE0B,OAAF,CAAU,UAAV,CAAN,CAA4B,IAAGzB,KAAG,CAAC,CAAJ,IAAOpC,KAAG,CAAC,CAAd,EAAgB;AAAC,UAAII,IAAE+B,EAAE2E,SAAF,CAAY1E,IAAEH,IAAE,CAAhB,EAAkBjC,IAAEiC,CAApB,CAAN,CAA6B7B,IAAEA,EAAEua,OAAF,CAAU,MAAV,EAAiB,EAAjB,CAAF,CAAuB3Y,EAAEyuB,IAAF,GAAOrwB,CAAP;AAAS,YAAO4B,CAAP;AAAS,GAAnc,CAAoc,IAAI1D,IAAE,SAAFA,CAAE,CAAS2B,CAAT,EAAW2F,CAAX,EAAa5G,CAAb,EAAe;AAAC,QAAImD,IAAEnD,EAAE8H,SAAF,CAAY,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAI9G,IAAEpB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBqB,CAAvB,CAAN,CAAgC,IAAI/B,IAAExB,SAAS+B,GAAT,CAAaU,IAAb,CAAkBP,KAAlB,CAAwB8E,CAAxB,CAAN,CAAiC,IAAIxD,IAAE7D,EAAE0B,CAAF,EAAK,QAAL,IAAe1B,EAAE0B,CAAF,EAAK,OAAL,CAArB,CAAmC,IAAIgC,IAAE,EAAN,CAAS,IAAID,IAAE,IAAN,CAAW,SAAO;AAAC,UAAI9B,IAAEtB,SAASuE,IAAT,CAAcqlB,GAAd,CAAkBhpB,MAAlB,EAAN,CAAiC,IAAGwC,KAAG,IAAN,EAAW;AAAC9B,UAAE2C,MAAF,CAASb,CAAT;AAAY,SAAEa,MAAF,CAASzC,CAAT,EAAYF,EAAE2C,MAAF,CAAS7C,CAAT,EAAYgC,IAAE9B,EAAE4C,QAAF,EAAF,CAAeb,IAAEA,IAAErD,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BkC,CAA3B,CAAJ,CAAkC,IAAGC,EAAEzD,MAAF,IAAU4D,IAAE,CAAf,EAAiB;AAAC;AAAM;AAAC,SAAIsD,IAAE,EAAN,CAASA,EAAEgrB,MAAF,GAASzuB,EAAEjB,MAAF,CAAS,CAAT,EAAWzC,EAAE0B,CAAF,EAAK,QAAL,IAAe,CAA1B,CAAT,CAAsCyF,EAAEirB,KAAF,GAAQ1uB,EAAEjB,MAAF,CAASzC,EAAE0B,CAAF,EAAK,QAAL,IAAe,CAAxB,EAA0B1B,EAAE0B,CAAF,EAAK,OAAL,IAAc,CAAxC,CAAR,CAAmD,OAAOyF,CAAP;AAAS,GAApb,CAAqb,IAAIxH,IAAE,SAAFA,CAAE,CAASc,CAAT,EAAWmD,CAAX,EAAa/B,CAAb,EAAe4B,CAAf,EAAiB;AAAC,QAAI9B,IAAEtB,SAAS+B,GAAT,CAAa+C,MAAb,CAAoB5C,KAApB,CAA0B9B,CAA1B,CAAN,CAAmC,IAAIiB,IAAErB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BI,CAA3B,CAAN,CAAoC,IAAIkC,IAAE7D,EAAE4D,CAAF,EAAK,MAAL,CAAN,CAAmB,IAAInC,IAAEoC,EAAEnC,CAAF,EAAIG,CAAJ,EAAM4B,CAAN,CAAN,CAAe,OAAOhC,CAAP;AAAS,GAA1I,CAA2I,IAAItC,IAAE,SAAFA,CAAE,CAASsB,CAAT,EAAWkB,CAAX,EAAaD,CAAb,EAAemC,CAAf,EAAiB;AAAC,QAAIhC,IAAE7B,EAAE2B,CAAF,EAAK,OAAL,CAAN,CAAoB,IAAIF,IAAEI,EAAEpB,CAAF,EAAIiB,CAAJ,EAAMmC,CAAN,CAAN,CAAe,OAAOpC,CAAP;AAAS,GAApE,CAAqE,OAAM,EAAC4wB,SAAQ,OAAT,EAAiBC,eAAc,uBAAS7xB,CAAT,EAAW;AAAC,aAAOD,EAAEC,CAAF,CAAP;AAAY,KAAvD,EAAwD8xB,sCAAqC,8CAAS7wB,CAAT,EAAWjB,CAAX,EAAaoB,CAAb,EAAe;AAAC,aAAO9B,EAAE2B,CAAF,EAAIjB,CAAJ,EAAMoB,CAAN,CAAP;AAAgB,KAA7H,EAA8H2wB,eAAc,uBAAS/xB,CAAT,EAAWoB,CAAX,EAAaH,CAAb,EAAeC,CAAf,EAAiB;AAAC,aAAOhC,EAAEc,CAAF,EAAIoB,CAAJ,EAAMH,CAAN,EAAQC,CAAR,CAAP;AAAkB,KAAhL,EAAiL8wB,oBAAmB,4BAASprB,CAAT,EAAW3D,CAAX,EAAa;AAAC,UAAIhC,IAAElB,EAAE6G,CAAF,CAAN,CAAW,IAAI5F,IAAEC,EAAEgX,IAAR,CAAa,IAAI7W,IAAEH,EAAEswB,MAAR,CAAe,IAAIvxB,IAAEiB,EAAEuwB,MAAR,CAAe,IAAItwB,IAAED,EAAEwwB,IAAR,CAAa,IAAIzuB,IAAE1D,EAAE8B,CAAF,EAAI6B,CAAJ,EAAMjD,CAAN,CAAN,CAAe,IAAImD,IAAEH,EAAE0uB,MAAR,CAAe,IAAItuB,IAAElE,EAAEgC,CAAF,EAAIE,CAAJ,EAAM+B,CAAN,EAAQnD,CAAR,CAAN,CAAiB,OAAOoD,CAAP;AAAS,KAA7U,EAA8U6uB,mCAAkC,2CAAShvB,CAAT,EAAW/B,CAAX,EAAayF,CAAb,EAAe3F,CAAf,EAAiBI,CAAjB,EAAmB;AAAC,UAAIpB,IAAE,EAAN,CAAS,IAAG,OAAOgB,CAAP,IAAU,WAAV,IAAuBA,KAAG,IAA7B,EAAkC;AAACA,YAAE,aAAF;AAAgB,WAAG,OAAOzB,EAAEyB,CAAF,CAAP,IAAa,WAAhB,EAA4B;AAAC,cAAK,oCAAkCA,CAAvC;AAAyC,WAAG,OAAOI,CAAP,IAAU,WAAV,IAAuBA,KAAG,IAA7B,EAAkC;AAAC,YAAI+B,IAAE5D,EAAEyB,CAAF,EAAK,OAAL,CAAN,CAAoB,IAAIoC,IAAE1B,EAAEyB,CAAF,CAAN,CAAW/B,IAAEgC,EAAE8uB,WAAF,EAAF;AAAkB,WAAIxrB,IAAEpH,EAAE0B,CAAF,EAAI2F,CAAJ,EAAMvF,CAAN,CAAN,CAAe,IAAIwF,IAAEF,EAAEgrB,MAAR,CAAe,IAAI1uB,IAAEtE,EAAEwC,CAAF,EAAIF,CAAJ,EAAM4F,CAAN,EAAQxF,CAAR,CAAN,CAAiB,IAAIH,IAAE+B,EAAE2Y,OAAF,CAAU,UAAV,EAAqB,QAArB,CAAN,CAAqC,IAAI3b,IAAE,gBAAciD,CAAd,GAAgB,uBAAtB,CAA8CjD,KAAG,4BAAH,CAAgCA,KAAG,eAAagB,CAAb,GAAe,GAAf,GAAmBI,CAAnB,GAAqB,MAAxB,CAA+BpB,KAAG,MAAH,CAAUA,KAAGiB,CAAH,CAAKjB,KAAG,kBAAgBiD,CAAhB,GAAkB,uBAArB,CAA6C,OAAOjD,CAAP;AAAS,KAAh2B,EAAi2BmyB,0BAAyB,kCAASvrB,CAAT,EAAW;AAAC,UAAIE,IAAEib,OAAN,CAAc,IAAIrb,IAAEI,EAAEyb,WAAR,CAAoB,IAAIvf,IAAE8D,EAAEsb,IAAR,CAAa,IAAIphB,IAAE,EAAN,CAAS,IAAII,IAAEsF,EAAEE,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGxF,EAAE5B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,+CAA6C4B,EAAE5B,MAApD;AAA2D,SAAE2xB,UAAF,GAAanuB,EAAE4D,CAAF,EAAIxF,EAAE,CAAF,CAAJ,CAAb,CAAuB,IAAIuF,IAAED,EAAEE,CAAF,EAAIxF,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGuF,EAAEnH,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,iDAA+CmH,EAAEnH,MAAtD;AAA6D,WAAGwD,EAAE4D,CAAF,EAAID,EAAE,CAAF,CAAJ,KAAW,oBAAd,EAAmC;AAAC,cAAK,+BAAL;AAAqC,WAAI3G,IAAE0G,EAAEE,CAAF,EAAID,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGA,EAAEnH,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,mDAAiDQ,EAAER,MAAxD;AAA+D,WAAIyB,IAAEyF,EAAEE,CAAF,EAAI5G,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGiB,EAAEzB,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,qDAAmDyB,EAAEzB,MAA1D;AAAiE,WAAGwD,EAAE4D,CAAF,EAAI3F,EAAE,CAAF,CAAJ,KAAW,kBAAd,EAAiC;AAAC,cAAK,8BAAL;AAAoC,SAAEmxB,mBAAF,GAAsB,WAAtB,CAAkCpxB,EAAEqxB,kBAAF,GAAqBrvB,EAAE4D,CAAF,EAAI3F,EAAE,CAAF,CAAJ,CAArB,CAA+B,IAAIC,IAAEwF,EAAEE,CAAF,EAAI5G,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGkB,EAAE1B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,qDAAmD0B,EAAE1B,MAA1D;AAAiE,WAAGwD,EAAE4D,CAAF,EAAI1F,EAAE,CAAF,CAAJ,KAAW,oBAAd,EAAmC;AAAC,cAAK,gCAAL;AAAsC,WAAI+B,IAAEyD,EAAEE,CAAF,EAAI1F,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAG+B,EAAEzD,MAAF,GAAS,CAAZ,EAAc;AAAC,cAAK,sDAAoDyD,EAAEzD,MAA3D;AAAkE,SAAE8yB,UAAF,GAAatvB,EAAE4D,CAAF,EAAI3D,EAAE,CAAF,CAAJ,CAAb,CAAuB,IAAIG,IAAEJ,EAAE4D,CAAF,EAAI3D,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAG;AAACjC,UAAEuxB,UAAF,GAAaxwB,SAASqB,CAAT,EAAW,EAAX,CAAb;AAA4B,OAAhC,CAAgC,OAAMD,CAAN,EAAQ;AAAC,cAAK,kCAAgCC,CAArC;AAAuC,cAAOpC,CAAP;AAAS,KAAt6D,EAAu6DwxB,0BAAyB,kCAASpvB,CAAT,EAAWpD,CAAX,EAAa;AAAC,UAAIgB,IAAEpB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBsB,EAAEkvB,UAAzB,CAAN,CAA2C,IAAIrxB,IAAEmC,EAAEmvB,UAAR,CAAmB,IAAIrxB,IAAEtB,SAAS6yB,MAAT,CAAgBzyB,CAAhB,EAAkBgB,CAAlB,EAAoB,EAAC0xB,SAAQ,MAAI,EAAb,EAAgBC,YAAW1xB,CAA3B,EAApB,CAAN,CAAyD,IAAIG,IAAExB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BI,CAA3B,CAAN,CAAoC,OAAOE,CAAP;AAAS,KAAlnE,EAAmnEwxB,wCAAuC,gDAAS3vB,CAAT,EAAW2D,CAAX,EAAa;AAAC,UAAIxF,IAAEwjB,SAAS3hB,CAAT,EAAW,uBAAX,CAAN,CAA0C,IAAIjD,IAAE,KAAKmyB,wBAAL,CAA8B/wB,CAA9B,CAAN,CAAuC,IAAIgC,IAAEspB,QAAQ8F,wBAAR,CAAiCxyB,CAAjC,EAAmC4G,CAAnC,CAAN,CAA4C,IAAIzD,IAAE,EAAN,CAASA,EAAEguB,UAAF,GAAavxB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuB9B,EAAEmxB,UAAzB,CAAb,CAAkD,IAAInwB,IAAEpB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBsB,CAAvB,CAAN,CAAgC,IAAIlC,IAAEtB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuB9B,EAAEqyB,kBAAzB,CAAN,CAAmD,IAAIrvB,IAAEpD,SAASmxB,SAAT,CAAmBxC,OAAnB,CAA2BprB,CAA3B,EAA6BnC,CAA7B,EAA+B,EAACkwB,IAAGhwB,CAAJ,EAA/B,CAAN,CAA6C,IAAID,IAAErB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BkC,CAA3B,CAAN,CAAoC,OAAO/B,CAAP;AAAS,KAA7gF,EAA8gF4xB,6BAA4B,qCAAS3xB,CAAT,EAAWD,CAAX,EAAa;AAAC,UAAIjB,IAAE,KAAK4yB,sCAAL,CAA4C1xB,CAA5C,EAA8CD,CAA9C,CAAN,CAAuD,IAAIG,IAAE,KAAK0xB,8BAAL,CAAoC9yB,CAApC,CAAN,CAA6C,OAAOoB,CAAP;AAAS,KAArqF,EAAsqF2xB,2BAA0B,mCAAS7xB,CAAT,EAAW;AAAC,UAAIiC,IAAE4e,OAAN,CAAc,IAAI3e,IAAED,EAAEof,WAAR,CAAoB,IAAIvhB,IAAEmC,EAAEif,IAAR,CAAa,IAAInhB,IAAE,EAAN,CAASA,EAAE+xB,QAAF,GAAW,IAAX,CAAgB,IAAG9xB,EAAEc,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,cAAK,6CAAL;AAAmD,WAAIZ,IAAEgC,EAAElC,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGE,EAAE5B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,6CAAL;AAAmD,WAAG0B,EAAEc,MAAF,CAASZ,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,uCAAL;AAA6C,WAAIpB,IAAEoD,EAAElC,CAAF,EAAIE,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGpB,EAAER,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,uCAAL;AAA6C,WAAG0B,EAAEc,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,uCAAL;AAA6C,SAAEizB,MAAF,GAASjyB,EAAEE,CAAF,EAAIlB,EAAE,CAAF,CAAJ,CAAT,CAAmB,IAAGkB,EAAEc,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAACiB,UAAE+xB,QAAF,GAAWhyB,EAAEE,CAAF,EAAIlB,EAAE,CAAF,CAAJ,CAAX;AAAqB,WAAGkB,EAAEc,MAAF,CAASZ,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,uCAAL;AAA6C,SAAE8xB,MAAF,GAAS/vB,EAAEgf,OAAF,CAAUjhB,CAAV,EAAYE,EAAE,CAAF,CAAZ,CAAT,CAA2B,OAAOH,CAAP;AAAS,KAA3zG,EAA4zGkyB,gCAA+B,wCAASlyB,CAAT,EAAW;AAAC,UAAIjB,IAAE4kB,SAAS3jB,CAAT,EAAW,aAAX,CAAN,CAAgC,IAAIG,IAAE,KAAK0xB,8BAAL,CAAoC9yB,CAApC,CAAN,CAA6C,OAAOoB,CAAP;AAAS,KAA77G,EAA87G0xB,gCAA+B,wCAAS9yB,CAAT,EAAW;AAAC,UAAIiB,IAAE,KAAK8xB,yBAAL,CAA+B/yB,CAA/B,CAAN,CAAwC,IAAIoB,CAAJ,CAAM,IAAGH,EAAEgyB,MAAF,IAAU,oBAAb,EAAkC;AAAC7xB,YAAE,IAAI+V,MAAJ,EAAF;AAAe,OAAlD,MAAsD;AAAC,YAAGlW,EAAEgyB,MAAF,IAAU,gBAAb,EAA8B;AAAC7xB,cAAE,IAAIuV,KAAKf,MAAL,CAAY6X,GAAhB,EAAF;AAAwB,SAAvD,MAA2D;AAAC,cAAGxsB,EAAEgyB,MAAF,IAAU,gBAAb,EAA8B;AAAC7xB,gBAAE,IAAIuV,KAAKf,MAAL,CAAYuX,KAAhB,EAAF;AAA0B,WAAzD,MAA6D;AAAC,kBAAK,mCAAL;AAAyC;AAAC;AAAC,SAAEiD,kBAAF,CAAqBpwB,CAArB,EAAwB,OAAOoB,CAAP;AAAS,KAApxH,EAAqxHgyB,2BAA0B,mCAASnyB,CAAT,EAAW;AAAC,UAAIjB,CAAJ,CAAM,IAAIoB,IAAE2gB,QAAQY,UAAR,CAAmB1hB,CAAnB,EAAqB,CAArB,EAAuB,CAAC,CAAD,EAAG,CAAH,CAAvB,EAA6B,IAA7B,CAAN,CAAyC,IAAGG,MAAI,oBAAP,EAA4B;AAACpB,YAAE,IAAImX,MAAJ,EAAF;AAAe,OAA5C,MAAgD;AAAC,YAAG/V,MAAI,gBAAP,EAAwB;AAACpB,cAAE,IAAI2W,KAAKf,MAAL,CAAY6X,GAAhB,EAAF;AAAwB,SAAjD,MAAqD;AAAC,cAAGrsB,MAAI,gBAAP,EAAwB;AAACpB,gBAAE,IAAI2W,KAAKf,MAAL,CAAYuX,KAAhB,EAAF;AAA0B,WAAnD,MAAuD;AAAC,kBAAK,mCAAL;AAAyC;AAAC;AAAC,SAAEkD,kBAAF,CAAqBpvB,CAArB,EAAwB,OAAOjB,CAAP;AAAS,KAArlI,EAAslIqzB,yBAAwB,iCAASjyB,CAAT,EAAW;AAAC,UAAIgC,IAAE2e,OAAN,CAAc,IAAI/gB,IAAEoC,EAAEmf,WAAR,CAAoB,IAAIrhB,IAAEkC,EAAEgf,IAAR,CAAa,IAAIpiB,IAAE,EAAN,CAAS,IAAGoB,EAAEY,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,cAAK,6BAAL;AAAmC,WAAIf,IAAED,EAAEI,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGH,EAAEzB,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,6BAAL;AAAmC,WAAG4B,EAAEY,MAAF,CAASf,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,6BAAL;AAAmC,SAAElB,CAAF,GAAImB,EAAEE,CAAF,EAAIH,EAAE,CAAF,CAAJ,CAAJ,CAAc,IAAGG,EAAEY,MAAF,CAASf,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,6BAAL;AAAmC,SAAE9B,CAAF,GAAI+B,EAAEE,CAAF,EAAIH,EAAE,CAAF,CAAJ,CAAJ,CAAc,OAAOjB,CAAP;AAAS,KAA98I,EAA+8IszB,qBAAoB,6BAAStyB,CAAT,EAAW;AAAC,UAAImC,IAAE4e,OAAN,CAAc,IAAI3e,IAAED,EAAEof,WAAR,CAAoB,IAAIrhB,IAAEiC,EAAEif,IAAR,CAAa,IAAInhB,IAAE,EAAN,CAASA,EAAE+xB,QAAF,GAAW,IAAX,CAAgB,IAAI5xB,IAAEgC,EAAEpC,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGI,EAAE5B,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,8CAA4C4B,EAAE5B,MAAnD;AAA0D,WAAIwD,IAAE5B,EAAE,CAAF,CAAN,CAAW,IAAGJ,EAAEgB,MAAF,CAASgB,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,cAAK,sCAAL;AAA4C,WAAIhD,IAAEoD,EAAEpC,CAAF,EAAIgC,CAAJ,CAAN,CAAa,IAAGhD,EAAER,MAAF,IAAU,CAAb,EAAe;AAAC,cAAK,sCAAL;AAA4C,WAAGwB,EAAEgB,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,sCAAL;AAA4C,SAAEizB,MAAF,GAAS/xB,EAAEF,CAAF,EAAIhB,EAAE,CAAF,CAAJ,CAAT,CAAmB,IAAGgB,EAAEgB,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAACiB,UAAE+xB,QAAF,GAAW9xB,EAAEF,CAAF,EAAIhB,EAAE,CAAF,CAAJ,CAAX;AAAqB,OAAhD,MAAoD;AAAC,YAAGgB,EAAEgB,MAAF,CAAShC,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAACiB,YAAE+xB,QAAF,GAAW,EAAX,CAAc/xB,EAAE+xB,QAAF,CAAWhzB,CAAX,GAAamD,EAAEwf,UAAF,CAAa3hB,CAAb,EAAehB,EAAE,CAAF,CAAf,EAAoB,CAAC,CAAD,CAApB,EAAwB,IAAxB,CAAb,CAA2CiB,EAAE+xB,QAAF,CAAW/xB,CAAX,GAAakC,EAAEwf,UAAF,CAAa3hB,CAAb,EAAehB,EAAE,CAAF,CAAf,EAAoB,CAAC,CAAD,CAApB,EAAwB,IAAxB,CAAb,CAA2CiB,EAAE+xB,QAAF,CAAWv0B,CAAX,GAAa0E,EAAEwf,UAAF,CAAa3hB,CAAb,EAAehB,EAAE,CAAF,CAAf,EAAoB,CAAC,CAAD,CAApB,EAAwB,IAAxB,CAAb;AAA2C;AAAC,WAAGgB,EAAEgB,MAAF,CAASZ,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,cAAK,sCAAL;AAA4C,SAAE6vB,GAAF,GAAM/vB,EAAEF,CAAF,EAAII,EAAE,CAAF,CAAJ,EAAUY,MAAV,CAAiB,CAAjB,CAAN,CAA0B,OAAOf,CAAP;AAAS,KAA1sK,EAAN;AAAmtK,CAAt8O,EAAZ,CAAq9OyrB,QAAQC,MAAR,GAAe,UAASltB,CAAT,EAAWC,CAAX,EAAaK,CAAb,EAAe;AAAC,MAAIyF,IAAEuc,OAAN;AAAA,MAAchc,IAAEP,EAAE+c,WAAlB;AAAA,MAA8Bpf,IAAEqC,EAAE4c,IAAlC;AAAA,MAAuCvjB,IAAE2G,EAAEmd,UAA3C;AAAA,MAAsDvjB,IAAEuX,KAAKf,MAA7D;AAAA,MAAoErW,IAAEH,EAAE+tB,KAAxE;AAAA,MAA8EnmB,IAAE5H,EAAEquB,GAAlF;AAAA,MAAsFzqB,IAAEmU,MAAxF;AAAA,MAA+FlR,IAAE2e,QAAjG;AAAA,MAA0Grf,IAAEmnB,OAA5G,CAAoH,IAAG,OAAO1pB,CAAP,IAAU,WAAV,IAAuBvD,aAAauD,CAAvC,EAAyC;AAAC,WAAOvD,CAAP;AAAS,OAAG,OAAOF,CAAP,IAAU,WAAV,IAAuBE,aAAaF,CAAvC,EAAyC;AAAC,WAAOE,CAAP;AAAS,OAAG,OAAOuH,CAAP,IAAU,WAAV,IAAuBvH,aAAauH,CAAvC,EAAyC;AAAC,WAAOvH,CAAP;AAAS,OAAGA,EAAEoZ,KAAF,KAAUva,SAAV,IAAqBmB,EAAE8zB,EAAF,KAAOj1B,SAA5B,IAAuCmB,EAAEZ,CAAF,KAAMP,SAAhD,EAA0D;AAAC,WAAO,IAAIiB,CAAJ,CAAM,EAACixB,KAAI/wB,EAAE8zB,EAAP,EAAU1a,OAAMpZ,EAAEoZ,KAAlB,EAAN,CAAP;AAAuC,OAAGpZ,EAAEoZ,KAAF,KAAUva,SAAV,IAAqBmB,EAAEZ,CAAF,KAAMP,SAA9B,EAAwC;AAAC,WAAO,IAAIiB,CAAJ,CAAM,EAACgxB,KAAI9wB,EAAEZ,CAAP,EAASga,OAAMpZ,EAAEoZ,KAAjB,EAAN,CAAP;AAAsC,OAAGpZ,EAAE+zB,GAAF,KAAQl1B,SAAR,IAAmBmB,EAAEM,CAAF,KAAMzB,SAAzB,IAAoCmB,EAAEN,CAAF,KAAMb,SAA1C,IAAqDmB,EAAEZ,CAAF,KAAMP,SAA9D,EAAwE;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEuR,SAAF,CAAYrY,EAAEM,CAAd,EAAgBN,EAAEN,CAAlB,EAAqB,OAAOoH,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQl1B,SAAR,IAAmBmB,EAAEM,CAAF,KAAMzB,SAAzB,IAAoCmB,EAAEN,CAAF,KAAMb,SAA1C,IAAqDmB,EAAEZ,CAAF,KAAMP,SAA3D,IAAsEmB,EAAEO,CAAF,KAAM1B,SAA5E,IAAuFmB,EAAEwB,CAAF,KAAM3C,SAA7F,IAAwGmB,EAAEg0B,EAAF,KAAOn1B,SAA/G,IAA0HmB,EAAEi0B,EAAF,KAAOp1B,SAAjI,IAA4ImB,EAAEk0B,EAAF,KAAOr1B,SAAnJ,IAA8JmB,EAAEm0B,EAAF,KAAOt1B,SAAxK,EAAkL;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEstB,YAAF,CAAep0B,EAAEM,CAAjB,EAAmBN,EAAEN,CAArB,EAAuBM,EAAEZ,CAAzB,EAA2BY,EAAEO,CAA7B,EAA+BP,EAAEwB,CAAjC,EAAmCxB,EAAEg0B,EAArC,EAAwCh0B,EAAEi0B,EAA1C,EAA6Cj0B,EAAEk0B,EAA/C,EAAmD,OAAOptB,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQl1B,SAAR,IAAmBmB,EAAEM,CAAF,KAAMzB,SAAzB,IAAoCmB,EAAEN,CAAF,KAAMb,SAA1C,IAAqDmB,EAAEZ,CAAF,KAAMP,SAA3D,IAAsEmB,EAAEO,CAAF,KAAM1B,SAA/E,EAAyF;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEutB,UAAF,CAAar0B,EAAEM,CAAf,EAAiBN,EAAEN,CAAnB,EAAqBM,EAAEZ,CAAvB,EAA0B,OAAO0H,CAAP;AAAS,OAAG9G,EAAEO,CAAF,KAAM1B,SAAN,IAAiBmB,EAAEwB,CAAF,KAAM3C,SAAvB,IAAkCmB,EAAEhB,CAAF,KAAMH,SAAxC,IAAmDmB,EAAEmH,CAAF,KAAMtI,SAAzD,IAAoEmB,EAAEwD,CAAF,KAAM3E,SAA7E,EAAuF;AAAC,QAAIiI,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEuR,SAAF,CAAYrY,EAAEO,CAAd,EAAgBP,EAAEwB,CAAlB,EAAoBxB,EAAEhB,CAAtB,EAAwBgB,EAAEmH,CAA1B,EAA6B,OAAOL,CAAP;AAAS,OAAG9G,EAAEO,CAAF,KAAM1B,SAAN,IAAiBmB,EAAEwB,CAAF,KAAM3C,SAAvB,IAAkCmB,EAAEhB,CAAF,KAAMH,SAAxC,IAAmDmB,EAAEmH,CAAF,KAAMtI,SAAzD,IAAoEmB,EAAEwD,CAAF,KAAM3E,SAA7E,EAAuF;AAAC,QAAIiI,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEutB,UAAF,CAAar0B,EAAEO,CAAf,EAAiBP,EAAEwB,CAAnB,EAAqBxB,EAAEhB,CAAvB,EAAyBgB,EAAEmH,CAA3B,EAA6BnH,EAAEwD,CAA/B,EAAkC,OAAOsD,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,KAAR,IAAe/zB,EAAEM,CAAF,KAAMzB,SAArB,IAAgCmB,EAAEN,CAAF,KAAMb,SAAtC,IAAiDmB,EAAEZ,CAAF,KAAMP,SAA1D,EAAoE;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEuR,SAAF,CAAYkM,UAAUvkB,EAAEM,CAAZ,CAAZ,EAA2BikB,UAAUvkB,EAAEN,CAAZ,CAA3B,EAA2C,OAAOoH,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,KAAR,IAAe/zB,EAAEM,CAAF,KAAMzB,SAArB,IAAgCmB,EAAEN,CAAF,KAAMb,SAAtC,IAAiDmB,EAAEZ,CAAF,KAAMP,SAAvD,IAAkEmB,EAAEO,CAAF,KAAM1B,SAAxE,IAAmFmB,EAAEwB,CAAF,KAAM3C,SAAzF,IAAoGmB,EAAEg0B,EAAF,KAAOn1B,SAA3G,IAAsHmB,EAAEi0B,EAAF,KAAOp1B,SAA7H,IAAwImB,EAAEm0B,EAAF,KAAOt1B,SAAlJ,EAA4J;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEstB,YAAF,CAAe7P,UAAUvkB,EAAEM,CAAZ,CAAf,EAA8BikB,UAAUvkB,EAAEN,CAAZ,CAA9B,EAA6C6kB,UAAUvkB,EAAEZ,CAAZ,CAA7C,EAA4DmlB,UAAUvkB,EAAEO,CAAZ,CAA5D,EAA2EgkB,UAAUvkB,EAAEwB,CAAZ,CAA3E,EAA0F+iB,UAAUvkB,EAAEg0B,EAAZ,CAA1F,EAA0GzP,UAAUvkB,EAAEi0B,EAAZ,CAA1G,EAA0H1P,UAAUvkB,EAAEm0B,EAAZ,CAA1H,EAA2I,OAAOrtB,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,KAAR,IAAe/zB,EAAEM,CAAF,KAAMzB,SAArB,IAAgCmB,EAAEN,CAAF,KAAMb,SAAtC,IAAiDmB,EAAEZ,CAAF,KAAMP,SAA1D,EAAoE;AAAC,QAAIiI,IAAE,IAAIvD,CAAJ,EAAN,CAAcuD,EAAEutB,UAAF,CAAa9P,UAAUvkB,EAAEM,CAAZ,CAAb,EAA4BikB,UAAUvkB,EAAEN,CAAZ,CAA5B,EAA2C6kB,UAAUvkB,EAAEZ,CAAZ,CAA3C,EAA2D,OAAO0H,CAAP;AAAS,OAAG9G,EAAE+zB,GAAF,KAAQ,IAAR,IAAc/zB,EAAEs0B,GAAF,KAAQz1B,SAAtB,IAAiCmB,EAAEwD,CAAF,KAAM3E,SAAvC,IAAkDmB,EAAEmH,CAAF,KAAMtI,SAAxD,IAAmEmB,EAAEZ,CAAF,KAAMP,SAA5E,EAAsF;AAAC,QAAIgB,IAAE,IAAIC,CAAJ,CAAM,EAACsZ,OAAMpZ,EAAEs0B,GAAT,EAAN,CAAN,CAA2B,IAAI/yB,IAAE1B,EAAEsvB,QAAF,CAAWS,MAAX,GAAkB,CAAxB,CAA0B,IAAIvoB,IAAE,CAAC,eAAakd,UAAUvkB,EAAEwD,CAAZ,CAAd,EAA8B1B,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAI0F,IAAE,CAAC,eAAasd,UAAUvkB,EAAEmH,CAAZ,CAAd,EAA8BrF,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAIoC,IAAE,OAAK0D,CAAL,GAAOJ,CAAb,CAAepH,EAAE6vB,eAAF,CAAkB/rB,CAAlB,EAAqB,OAAO9D,CAAP;AAAS,OAAGG,EAAE+zB,GAAF,KAAQ,IAAR,IAAc/zB,EAAEs0B,GAAF,KAAQz1B,SAAtB,IAAiCmB,EAAEwD,CAAF,KAAM3E,SAAvC,IAAkDmB,EAAEmH,CAAF,KAAMtI,SAAxD,IAAmEmB,EAAEZ,CAAF,KAAMP,SAA5E,EAAsF;AAAC,QAAIgB,IAAE,IAAIC,CAAJ,CAAM,EAACsZ,OAAMpZ,EAAEs0B,GAAT,EAAN,CAAN,CAA2B,IAAI/yB,IAAE1B,EAAEsvB,QAAF,CAAWS,MAAX,GAAkB,CAAxB,CAA0B,IAAIvoB,IAAE,CAAC,eAAakd,UAAUvkB,EAAEwD,CAAZ,CAAd,EAA8B1B,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAI0F,IAAE,CAAC,eAAasd,UAAUvkB,EAAEmH,CAAZ,CAAd,EAA8BrF,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C,IAAIoC,IAAE,OAAK0D,CAAL,GAAOJ,CAAb,CAAe,IAAIxH,IAAE,CAAC,eAAa8kB,UAAUvkB,EAAEZ,CAAZ,CAAd,EAA8B0C,KAA9B,CAAoC,CAACP,CAArC,CAAN,CAA8C1B,EAAE6vB,eAAF,CAAkB/rB,CAAlB,EAAqB9D,EAAE4vB,gBAAF,CAAmBhwB,CAAnB,EAAsB,OAAOI,CAAP;AAAS,OAAGS,MAAI,UAAP,EAAkB;AAAC,QAAI4F,IAAElG,CAAN;AAAA,QAAQ+F,IAAEuc,OAAV;AAAA,QAAkB5b,CAAlB;AAAA,QAAoBI,CAApB,CAAsBJ,IAAEJ,EAAEJ,CAAF,EAAI,CAAJ,CAAF,CAAS,IAAGQ,EAAE3G,MAAF,KAAW,CAAd,EAAgB;AAAC+G,UAAE,IAAIvD,CAAJ,EAAF,CAAUuD,EAAE2pB,kBAAF,CAAqBvqB,CAArB;AAAwB,KAAnD,MAAuD;AAAC,UAAGQ,EAAE3G,MAAF,KAAW,CAAd,EAAgB;AAAC+G,YAAE,IAAIS,CAAJ,EAAF,CAAUT,EAAE2pB,kBAAF,CAAqBvqB,CAArB;AAAwB,OAAnD,MAAuD;AAAC,YAAGQ,EAAE3G,MAAF,GAAS,CAAT,IAAYmG,EAAE3D,MAAF,CAASmE,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAAlC,EAAuC;AAACI,cAAE,IAAIhH,CAAJ,EAAF,CAAUgH,EAAE2pB,kBAAF,CAAqBvqB,CAArB;AAAwB,SAA1E,MAA8E;AAAC,gBAAK,sCAAL;AAA4C;AAAC;AAAC,YAAOY,CAAP;AAAS,OAAGxG,MAAI,UAAP,EAAkB;AAAC,QAAIwG,IAAEhB,EAAEutB,8BAAF,CAAiCrzB,CAAjC,CAAN,CAA0C,OAAO8G,CAAP;AAAS,OAAGxG,MAAI,UAAP,EAAkB;AAAC,WAAOwF,EAAE6tB,yBAAF,CAA4B3zB,CAA5B,CAAP;AAAsC,OAAGM,MAAI,SAAP,EAAiB;AAAC,WAAOi0B,KAAKC,uBAAL,CAA6Bx0B,CAA7B,CAAP;AAAuC,OAAGA,EAAEoF,OAAF,CAAU,mBAAV,EAA8B,CAA9B,KAAkC,CAAC,CAAnC,IAAsCpF,EAAEoF,OAAF,CAAU,wBAAV,EAAmC,CAAnC,KAAuC,CAAC,CAA9E,IAAiFpF,EAAEoF,OAAF,CAAU,2BAAV,EAAsC,CAAtC,KAA0C,CAAC,CAA/H,EAAiI;AAAC,WAAOmvB,KAAKE,uBAAL,CAA6Bz0B,CAA7B,CAAP;AAAuC,OAAGA,EAAEoF,OAAF,CAAU,kBAAV,KAA+B,CAAC,CAAnC,EAAqC;AAAC,QAAIwB,IAAEue,SAASnlB,CAAT,EAAW,YAAX,CAAN,CAA+B,OAAO8F,EAAE6tB,yBAAF,CAA4B/sB,CAA5B,CAAP;AAAsC,OAAG5G,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAInD,IAAEuE,EAAExG,CAAF,EAAI,iBAAJ,CAAN,CAA6B,OAAO8F,EAAEonB,MAAF,CAASjrB,CAAT,EAAW,IAAX,EAAgB,UAAhB,CAAP;AAAmC,OAAGjC,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAIa,IAAEO,EAAExG,CAAF,EAAI,iBAAJ,CAAN,CAA6B,IAAI2H,IAAEvI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIwB,IAAErI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIG,IAAEhH,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAItE,IAAEvC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIxE,IAAErC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIa,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEutB,UAAF,CAAa,IAAIxrB,UAAJ,CAAelB,CAAf,EAAiB,EAAjB,CAAb,EAAkC,IAAIkB,UAAJ,CAAepB,CAAf,EAAiB,EAAjB,CAAlC,EAAuD,IAAIoB,UAAJ,CAAezC,CAAf,EAAiB,EAAjB,CAAvD,EAA4E,IAAIyC,UAAJ,CAAelH,CAAf,EAAiB,EAAjB,CAA5E,EAAiG,IAAIkH,UAAJ,CAAepH,CAAf,EAAiB,EAAjB,CAAjG,EAAuH,OAAOqF,CAAP;AAAS,OAAG9G,EAAEoF,OAAF,CAAU,mBAAV,KAAgC,CAAC,CAApC,EAAsC;AAAC,WAAOU,EAAE4tB,8BAAF,CAAiC1zB,CAAjC,CAAP;AAA2C,OAAGA,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAI5E,IAAEsF,EAAEysB,kBAAF,CAAqBvyB,CAArB,EAAuBC,CAAvB,CAAN,CAAgC,IAAI+F,IAAE,IAAI0R,MAAJ,EAAN,CAAmB1R,EAAEyqB,kBAAF,CAAqBjwB,CAArB,EAAwB,OAAOwF,CAAP;AAAS,OAAGhG,EAAEoF,OAAF,CAAU,sBAAV,KAAmC,CAAC,CAApC,IAAuCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAArE,EAAuE;AAAC,QAAIa,IAAEH,EAAEysB,kBAAF,CAAqBvyB,CAArB,EAAuBC,CAAvB,CAAN,CAAgC,IAAI6G,IAAE1H,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAI/G,IAAEE,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAN,CAAwB,IAAIiB,IAAE9H,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,EAAkB1D,MAAlB,CAAyB,CAAzB,CAAN,CAAkC,IAAI7C,IAAE,EAAN,CAAS,IAAGwX,KAAKf,MAAL,CAAYsL,GAAZ,CAAgBuN,WAAhB,CAA4B9vB,CAA5B,MAAiCL,SAApC,EAA8C;AAACa,UAAEwX,KAAKf,MAAL,CAAYsL,GAAZ,CAAgBuN,WAAhB,CAA4B9vB,CAA5B,CAAF;AAAiC,KAAhF,MAAoF;AAAC,YAAK,4CAA0CA,CAA/C;AAAiD,SAAIW,IAAE,IAAIC,CAAJ,CAAM,EAACsZ,OAAM1Z,CAAP,EAAN,CAAN,CAAuBG,EAAE6vB,eAAF,CAAkBxoB,CAAlB,EAAqBrH,EAAE4vB,gBAAF,CAAmB3oB,CAAnB,EAAsBjH,EAAEkY,QAAF,GAAW,KAAX,CAAiB,OAAOlY,CAAP;AAAS,OAAGG,EAAEoF,OAAF,CAAU,uBAAV,KAAoC,CAAC,CAArC,IAAwCpF,EAAEoF,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAtE,EAAwE;AAAC,QAAIa,IAAEH,EAAEysB,kBAAF,CAAqBvyB,CAArB,EAAuBC,CAAvB,CAAN,CAAgC,IAAI0H,IAAEvI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIwB,IAAErI,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIG,IAAEhH,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAItE,IAAEvC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIxE,IAAErC,EAAE6G,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,CAAN,CAAsB,IAAIa,IAAE,IAAIS,CAAJ,EAAN,CAAcT,EAAEutB,UAAF,CAAa,IAAIxrB,UAAJ,CAAelB,CAAf,EAAiB,EAAjB,CAAb,EAAkC,IAAIkB,UAAJ,CAAepB,CAAf,EAAiB,EAAjB,CAAlC,EAAuD,IAAIoB,UAAJ,CAAezC,CAAf,EAAiB,EAAjB,CAAvD,EAA4E,IAAIyC,UAAJ,CAAelH,CAAf,EAAiB,EAAjB,CAA5E,EAAiG,IAAIkH,UAAJ,CAAepH,CAAf,EAAiB,EAAjB,CAAjG,EAAuH,OAAOqF,CAAP;AAAS,OAAG9G,EAAEoF,OAAF,CAAU,6BAAV,KAA0C,CAAC,CAA9C,EAAgD;AAAC,WAAOU,EAAEstB,2BAAF,CAA8BpzB,CAA9B,EAAgCC,CAAhC,CAAP;AAA0C,SAAK,wBAAL;AAA8B,CAAjxJ,CAAkxJgtB,QAAQyH,eAAR,GAAwB,UAASx0B,CAAT,EAAWP,CAAX,EAAa;AAAC,MAAGO,KAAG,KAAN,EAAY;AAAC,QAAIT,IAAEE,CAAN,CAAQ,IAAIV,IAAE,IAAIyY,MAAJ,EAAN,CAAmBzY,EAAE01B,QAAF,CAAWl1B,CAAX,EAAa,OAAb,EAAsBR,EAAE+Y,SAAF,GAAY,IAAZ,CAAiB/Y,EAAE8Y,QAAF,GAAW,IAAX,CAAgB,IAAI7Y,IAAE,IAAIwY,MAAJ,EAAN,CAAmB,IAAIhY,IAAET,EAAEqB,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAN,CAAuB,IAAIlB,IAAEb,EAAES,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAN,CAAuB9B,EAAEmZ,SAAF,CAAY3Y,CAAZ,EAAcI,CAAd,EAAiBZ,EAAE8Y,SAAF,GAAY,KAAZ,CAAkB9Y,EAAE6Y,QAAF,GAAW,IAAX,CAAgB,IAAI9X,IAAE,EAAN,CAASA,EAAE20B,SAAF,GAAY31B,CAAZ,CAAcgB,EAAE40B,SAAF,GAAY31B,CAAZ,CAAc,OAAOe,CAAP;AAAS,GAAjQ,MAAqQ;AAAC,QAAGC,KAAG,IAAN,EAAW;AAAC,UAAId,IAAEO,CAAN,CAAQ,IAAIX,IAAE,IAAIkY,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAMha,CAAP,EAAtB,CAAN,CAAuC,IAAIS,IAAEb,EAAE8wB,kBAAF,EAAN,CAA6B,IAAI7wB,IAAE,IAAIiY,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAMha,CAAP,EAAtB,CAAN,CAAuCH,EAAEywB,eAAF,CAAkB7vB,EAAEsuB,QAApB,EAA8BlvB,EAAEwwB,gBAAF,CAAmB5vB,EAAE2tB,QAArB,EAA+BvuB,EAAE+Y,SAAF,GAAY,IAAZ,CAAiB/Y,EAAE8Y,QAAF,GAAW,KAAX,CAAiB,IAAI7Y,IAAE,IAAIgY,KAAKf,MAAL,CAAYuX,KAAhB,CAAsB,EAACtU,OAAMha,CAAP,EAAtB,CAAN,CAAuCF,EAAEwwB,eAAF,CAAkB7vB,EAAEsuB,QAApB,EAA8BjvB,EAAE8Y,SAAF,GAAY,KAAZ,CAAkB9Y,EAAE6Y,QAAF,GAAW,IAAX,CAAgB,IAAI9X,IAAE,EAAN,CAASA,EAAE20B,SAAF,GAAY31B,CAAZ,CAAcgB,EAAE40B,SAAF,GAAY31B,CAAZ,CAAc,OAAOe,CAAP;AAAS,KAAnX,MAAuX;AAAC,YAAK,wBAAsBC,CAA3B;AAA6B;AAAC;AAAC,CAAnsB,CAAosB+sB,QAAQ6H,MAAR,GAAe,UAASr1B,CAAT,EAAWgI,CAAX,EAAaN,CAAb,EAAelF,CAAf,EAAiBT,CAAjB,EAAmB3B,CAAnB,EAAqB;AAAC,MAAIiG,IAAEoR,IAAN;AAAA,MAAWjX,IAAE6F,EAAEsW,IAAf;AAAA,MAAoBnV,IAAEhH,EAAE+c,mBAAxB;AAAA,MAA4C9d,IAAEe,EAAE2c,UAAhD;AAAA,MAA2D5c,IAAEC,EAAEoc,QAAF,CAAWK,SAAxE;AAAA,MAAkFxc,IAAED,EAAEuhB,IAAtF;AAAA,MAA2Fja,IAAErH,EAAE60B,oBAA/F;AAAA,MAAoHr1B,IAAEoG,EAAEqQ,MAAxH;AAAA,MAA+HxS,IAAEjE,EAAEsuB,GAAnI;AAAA,MAAuIrsB,IAAEjC,EAAEguB,KAA3I;AAAA,MAAiJptB,IAAEoX,MAAnJ,CAA0J,SAASxQ,CAAT,CAAWzF,CAAX,EAAa;AAAC,QAAIsE,IAAE/F,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAAC,OAAM,EAACjU,QAAOtf,EAAEnB,CAAV,EAAP,EAAX,EAAgC,EAAC,OAAMmB,EAAE/B,CAAT,EAAhC,EAA4C,EAAC,OAAM,EAACqhB,QAAOtf,EAAErC,CAAV,EAAP,EAA5C,EAAiE,EAAC,OAAM,EAAC2hB,QAAOtf,EAAElB,CAAV,EAAP,EAAjE,EAAsF,EAAC,OAAM,EAACwgB,QAAOtf,EAAED,CAAV,EAAP,EAAtF,EAA2G,EAAC,OAAM,EAACuf,QAAOtf,EAAEkW,IAAV,EAAP,EAA3G,EAAmI,EAAC,OAAM,EAACoJ,QAAOtf,EAAEmW,IAAV,EAAP,EAAnI,EAA2J,EAAC,OAAM,EAACmJ,QAAOtf,EAAEoW,KAAV,EAAP,EAA3J,CAAL,EAAF,CAAN,CAAoM,OAAO9R,CAAP;AAAS,YAASsB,CAAT,CAAWtB,CAAX,EAAa;AAAC,QAAItE,IAAEzB,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACC,QAAO,EAAC3V,KAAIvZ,EAAEupB,SAAP,EAAR,EAAX,EAAsC,EAACxR,KAAI,CAAC,IAAD,EAAM,IAAN,EAAW,EAAC6D,KAAI,EAACC,MAAK7b,EAAEypB,SAAR,EAAL,EAAX,CAAL,EAAtC,EAAiF,EAAC1R,KAAI,CAAC,IAAD,EAAM,IAAN,EAAW,EAACoX,QAAO,EAAC5V,KAAI,OAAKvZ,EAAEwpB,SAAZ,EAAR,EAAX,CAAL,EAAjF,CAAL,EAAF,CAAN,CAAmJ,OAAO9tB,CAAP;AAAS,YAAS+B,CAAT,CAAW/B,CAAX,EAAa;AAAC,QAAIsE,IAAE/F,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAAC,OAAM,EAACjU,QAAOtf,EAAElB,CAAV,EAAP,EAAX,EAAgC,EAAC,OAAM,EAACwgB,QAAOtf,EAAED,CAAV,EAAP,EAAhC,EAAqD,EAAC,OAAM,EAACuf,QAAOtf,EAAEzC,CAAV,EAAP,EAArD,EAA0E,EAAC,OAAM,EAAC+hB,QAAOtf,EAAE0F,CAAV,EAAP,EAA1E,EAA+F,EAAC,OAAM,EAAC4Z,QAAOtf,EAAE+B,CAAV,EAAP,EAA/F,CAAL,EAAF,CAAN,CAAoI,OAAOuC,CAAP;AAAS,OAAG,CAAEzF,MAAIzB,SAAJ,IAAeY,aAAaa,CAA7B,IAAkCqD,MAAI9E,SAAJ,IAAeY,aAAakE,CAA9D,IAAmEhC,MAAI9C,SAAJ,IAAeY,aAAakC,CAAhG,KAAqGlC,EAAEsY,QAAF,IAAY,IAAjH,KAAwHtQ,MAAI5I,SAAJ,IAAe4I,KAAG,UAA1I,CAAH,EAAyJ;AAAC,QAAIE,IAAE,IAAIJ,CAAJ,CAAM9H,CAAN,CAAN,CAAe,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,OAAOzB,SAASlZ,CAAT,EAAW,YAAX,CAAP;AAAgC,OAAGkE,KAAG,UAAH,IAAenH,MAAIzB,SAAnB,IAA8BY,aAAaa,CAA3C,KAA+C6G,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,KAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAET,EAAEzH,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,OAAOzB,SAASlZ,CAAT,EAAW,iBAAX,CAAP;AAAqC,OAAGkE,KAAG,UAAH,IAAe9F,MAAI9C,SAAnB,IAA8BY,aAAakC,CAA3C,KAA+CwF,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,KAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIlY,IAAE,IAAImH,CAAJ,CAAM,EAAC2a,MAAKniB,EAAE+vB,SAAR,EAAN,CAAN,CAAgC,IAAI9rB,IAAE5D,EAAEoe,aAAF,EAAN,CAAwB,IAAIjf,IAAEoI,EAAE5H,CAAF,CAAN,CAAW,IAAI8B,IAAEtC,EAAEif,aAAF,EAAN,CAAwB,IAAI3d,IAAE,EAAN,CAASA,KAAGkc,SAAS/Y,CAAT,EAAW,eAAX,CAAH,CAA+BnD,KAAGkc,SAASlb,CAAT,EAAW,gBAAX,CAAH,CAAgC,OAAOhB,CAAP;AAAS,OAAGkH,KAAG,UAAH,IAAe9D,MAAI9E,SAAnB,IAA8BY,aAAakE,CAA3C,KAA+CwD,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,KAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAEnE,EAAE/D,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,OAAOzB,SAASlZ,CAAT,EAAW,iBAAX,CAAP;AAAqC,OAAGkE,KAAG,UAAH,IAAenH,MAAIzB,SAAnB,IAA8BY,aAAaa,CAA3C,IAA+C6G,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,IAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAET,EAAEzH,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAGjc,MAAIpD,SAAP,EAAiB;AAACoD,UAAE,cAAF;AAAiB,YAAO,KAAKuwB,iCAAL,CAAuC,KAAvC,EAA6CjvB,CAA7C,EAA+C4D,CAA/C,EAAiDlF,CAAjD,EAAmDpC,CAAnD,CAAP;AAA6D,OAAG4H,KAAG,UAAH,IAAe9F,MAAI9C,SAAnB,IAA8BY,aAAakC,CAA3C,IAA+CwF,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,IAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAEN,EAAE5H,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAGjc,MAAIpD,SAAP,EAAiB;AAACoD,UAAE,cAAF;AAAiB,YAAO,KAAKuwB,iCAAL,CAAuC,IAAvC,EAA4CjvB,CAA5C,EAA8C4D,CAA9C,EAAgDlF,CAAhD,EAAkDpC,CAAlD,CAAP;AAA4D,OAAG4H,KAAG,UAAH,IAAe9D,MAAI9E,SAAnB,IAA8BY,aAAakE,CAA3C,IAA+CwD,MAAItI,SAAJ,IAAesI,KAAG,IAAjE,IAAwE1H,EAAEuY,SAAF,IAAa,IAAxF,EAA6F;AAAC,QAAIrQ,IAAEnE,EAAE/D,CAAF,CAAN,CAAW,IAAI8D,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAGjc,MAAIpD,SAAP,EAAiB;AAACoD,UAAE,cAAF;AAAiB,YAAO,KAAKuwB,iCAAL,CAAuC,KAAvC,EAA6CjvB,CAA7C,EAA+C4D,CAA/C,EAAiDlF,CAAjD,EAAmDpC,CAAnD,CAAP;AAA6D,OAAIW,IAAE,SAAFA,CAAE,CAASuF,CAAT,EAAWtE,CAAX,EAAa;AAAC,QAAIwE,IAAEtG,EAAEoG,CAAF,EAAItE,CAAJ,CAAN,CAAa,IAAIuE,IAAE,IAAIhG,CAAJ,CAAM,EAACg1B,KAAI,CAAC,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,YAAN,EAAL,EAAD,EAA2B,EAACoT,KAAI,CAAC,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,aAAN,EAAL,EAAD,EAA4B,EAACoT,KAAI,CAAC,EAACC,QAAO,EAAC3V,KAAIrZ,EAAE4sB,UAAP,EAAR,EAAD,EAA6B,EAAC,OAAM5sB,EAAE6sB,UAAT,EAA7B,CAAL,EAA5B,CAAL,EAAD,EAA6F,EAACkC,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,cAAN,EAAL,EAAD,EAA6B,EAACqT,QAAO,EAAC3V,KAAIrZ,EAAE2sB,kBAAP,EAAR,EAA7B,CAAL,EAA7F,CAAL,EAA3B,CAAL,EAAD,EAA+M,EAACqC,QAAO,EAAC3V,KAAIrZ,EAAEyrB,UAAP,EAAR,EAA/M,CAAL,EAAN,CAAN,CAA+P,OAAO1rB,EAAEkY,aAAF,EAAP;AAAyB,GAAzT,CAA0T,IAAIve,IAAE,SAAFA,CAAE,CAAS+G,CAAT,EAAWE,CAAX,EAAa;AAAC,QAAIZ,IAAE,GAAN,CAAU,IAAIQ,IAAErG,SAASC,GAAT,CAAac,SAAb,CAAuBa,MAAvB,CAA8B,CAA9B,CAAN,CAAuC,IAAIuE,IAAE,cAAN,CAAqB,IAAI7E,IAAEtB,SAASC,GAAT,CAAac,SAAb,CAAuBa,MAAvB,CAA8B,CAA9B,CAAN,CAAuC,IAAIkE,IAAE9F,SAAS6yB,MAAT,CAAgBpsB,CAAhB,EAAkBJ,CAAlB,EAAoB,EAACysB,SAAQ,MAAI,EAAb,EAAgBC,YAAWltB,CAA3B,EAApB,CAAN,CAAyD,IAAIE,IAAE/F,SAAS+B,GAAT,CAAaC,GAAb,CAAiBE,KAAjB,CAAuBqE,CAAvB,CAAN,CAAgC,IAAIN,IAAEjG,SAASmxB,SAAT,CAAmBhZ,OAAnB,CAA2BpS,CAA3B,EAA6BD,CAA7B,EAA+B,EAACwrB,IAAGhwB,CAAJ,EAA/B,IAAuC,EAA7C,CAAgD,IAAIsE,IAAE,EAAN,CAASA,EAAE2rB,UAAF,GAAatrB,CAAb,CAAeL,EAAE8sB,UAAF,GAAa1yB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BmF,CAA3B,CAAb,CAA2CT,EAAE+sB,UAAF,GAAa9sB,CAAb,CAAeD,EAAE4sB,mBAAF,GAAsBrsB,CAAtB,CAAwBP,EAAE6sB,kBAAF,GAAqBzyB,SAAS+B,GAAT,CAAaC,GAAb,CAAiBd,SAAjB,CAA2BI,CAA3B,CAArB,CAAmD,OAAOsE,CAAP;AAAS,GAAhb,CAAib,IAAG0B,KAAG,UAAH,IAAenH,KAAGzB,SAAlB,IAA6BY,aAAaa,CAA1C,IAA6Cb,EAAEuY,SAAF,IAAa,IAA7D,EAAkE;AAAC,QAAIhZ,IAAEkI,EAAEzH,CAAF,CAAN,CAAW,IAAIL,IAAEJ,EAAEkf,aAAF,EAAN,CAAwB,IAAIvW,IAAE3H,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,eAAN,EAAL,EAAD,EAA8B,EAAC,QAAO,IAAR,EAA9B,CAAL,EAAX,EAA8D,EAACqT,QAAO,EAAC3V,KAAIlgB,CAAL,EAAR,EAA9D,CAAL,EAAF,CAAN,CAA+F,IAAImE,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAG/W,MAAItI,SAAJ,IAAesI,KAAG,IAArB,EAA0B;AAAC,aAAOsV,SAASlZ,CAAT,EAAW,aAAX,CAAP;AAAiC,KAA5D,MAAgE;AAAC,UAAIhC,IAAEf,EAAE+C,CAAF,EAAI4D,CAAJ,CAAN,CAAa,OAAOsV,SAASlb,CAAT,EAAW,uBAAX,CAAP;AAA2C;AAAC,OAAGkG,KAAG,UAAH,IAAe9F,MAAI9C,SAAnB,IAA8BY,aAAakC,CAA3C,IAA8ClC,EAAEuY,SAAF,IAAa,IAA9D,EAAmE;AAAC,QAAIhZ,IAAE,IAAIgB,CAAJ,CAAM,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACC,QAAO,EAAC3V,KAAI7f,EAAE6vB,SAAP,EAAR,EAAX,EAAsC,EAACxR,KAAI,CAAC,IAAD,EAAM,IAAN,EAAW,EAACoX,QAAO,EAAC5V,KAAI,OAAK7f,EAAE8vB,SAAZ,EAAR,EAAX,CAAL,EAAtC,CAAL,EAAN,CAAN,CAA4G,IAAInwB,IAAEJ,EAAEkf,aAAF,EAAN,CAAwB,IAAIvW,IAAE3H,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,aAAN,EAAL,EAAD,EAA4B,EAACD,KAAI,EAACC,MAAKniB,EAAE+vB,SAAR,EAAL,EAA5B,CAAL,EAAX,EAAuE,EAACyF,QAAO,EAAC3V,KAAIlgB,CAAL,EAAR,EAAvE,CAAL,EAAF,CAAN,CAAwG,IAAImE,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAG/W,MAAItI,SAAJ,IAAesI,KAAG,IAArB,EAA0B;AAAC,aAAOsV,SAASlZ,CAAT,EAAW,aAAX,CAAP;AAAiC,KAA5D,MAAgE;AAAC,UAAIhC,IAAEf,EAAE+C,CAAF,EAAI4D,CAAJ,CAAN,CAAa,OAAOsV,SAASlb,CAAT,EAAW,uBAAX,CAAP;AAA2C;AAAC,OAAGkG,KAAG,UAAH,IAAe9D,MAAI9E,SAAnB,IAA8BY,aAAakE,CAA3C,IAA8ClE,EAAEuY,SAAF,IAAa,IAA9D,EAAmE;AAAC,QAAIhZ,IAAE,IAAIE,CAAJ,CAAM,EAAC6hB,QAAOthB,EAAE+D,CAAV,EAAN,CAAN,CAA0B,IAAIpE,IAAEJ,EAAEkf,aAAF,EAAN,CAAwB,IAAIvW,IAAE3H,EAAE,EAACg1B,KAAI,CAAC,EAAC,OAAM,CAAP,EAAD,EAAW,EAACA,KAAI,CAAC,EAACrT,KAAI,EAACC,MAAK,KAAN,EAAL,EAAD,EAAoB,EAACoT,KAAI,CAAC,EAAC,OAAM,EAACjU,QAAOthB,EAAEc,CAAV,EAAP,EAAD,EAAsB,EAAC,OAAM,EAACwgB,QAAOthB,EAAE+B,CAAV,EAAP,EAAtB,EAA2C,EAAC,OAAM,EAACuf,QAAOthB,EAAET,CAAV,EAAP,EAA3C,CAAL,EAApB,CAAL,EAAX,EAA6G,EAACi2B,QAAO,EAAC3V,KAAIlgB,CAAL,EAAR,EAA7G,CAAL,EAAF,CAAN,CAA8I,IAAImE,IAAEoE,EAAEuW,aAAF,EAAN,CAAwB,IAAG/W,MAAItI,SAAJ,IAAesI,KAAG,IAArB,EAA0B;AAAC,aAAOsV,SAASlZ,CAAT,EAAW,aAAX,CAAP;AAAiC,KAA5D,MAAgE;AAAC,UAAIhC,IAAEf,EAAE+C,CAAF,EAAI4D,CAAJ,CAAN,CAAa,OAAOsV,SAASlb,CAAT,EAAW,uBAAX,CAAP;AAA2C;AAAC,SAAK,+BAAL;AAAqC,CAAvnI,CAAwnI0rB,QAAQkI,gBAAR,GAAyB,UAAS11B,CAAT,EAAW;AAAC,MAAIS,IAAEilB,SAAS1lB,CAAT,EAAW,qBAAX,CAAN,CAAwC,IAAIE,IAAEstB,QAAQmI,gBAAR,CAAyBl1B,CAAzB,CAAN,CAAkC,OAAOP,CAAP;AAAS,CAAxH,CAAyHstB,QAAQmI,gBAAR,GAAyB,UAASl1B,CAAT,EAAW;AAAC,MAAIP,IAAEstB,QAAQoI,WAAR,CAAoBn1B,CAApB,CAAN,CAA6B,IAAIT,IAAEwtB,QAAQC,MAAR,CAAevtB,EAAE21B,WAAjB,EAA6B,IAA7B,EAAkC,UAAlC,CAAN,CAAoD,OAAO71B,CAAP;AAAS,CAA/H,CAAgIwtB,QAAQoI,WAAR,GAAoB,UAASj2B,CAAT,EAAW;AAAC,MAAIU,IAAEwiB,OAAN,CAAc,IAAIpjB,IAAEY,EAAEgjB,WAAR,CAAoB,IAAInjB,IAAEG,EAAE8iB,MAAR,CAAe,IAAInjB,IAAE,EAAN,CAAS,IAAIT,IAAEI,CAAN,CAAQ,IAAGJ,EAAEuD,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,IAAlB,EAAuB;AAAC,UAAK,yBAAL;AAA+B,OAAI7C,IAAER,EAAEF,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAGU,EAAEK,MAAF,GAAS,CAAZ,EAAc;AAAC,UAAK,yBAAL;AAA+B,OAAGf,EAAEuD,MAAF,CAAS7C,EAAE,CAAF,CAAT,EAAc,CAAd,KAAkB,IAArB,EAA0B;AAAC,UAAK,yBAAL;AAA+B,OAAIQ,IAAEhB,EAAEF,CAAF,EAAIU,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAGQ,EAAEH,MAAF,GAAS,CAAZ,EAAc;AAAC,UAAK,yBAAL;AAA+B,KAAEu1B,WAAF,GAAc31B,EAAEX,CAAF,EAAIkB,EAAE,CAAF,CAAJ,CAAd,CAAwB,OAAOT,CAAP;AAAS,CAA7W,CAA8WwtB,QAAQsI,aAAR,GAAsB,UAASn2B,CAAT,EAAW;AAAC,MAAIK,IAAE,EAAN,CAAS,IAAGL,aAAasY,MAAb,IAAqBtY,EAAE4Y,SAA1B,EAAoC;AAACvY,MAAEs0B,GAAF,GAAM,KAAN,CAAYt0B,EAAEa,CAAF,GAAIgkB,UAAUllB,EAAEkB,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEC,CAAF,GAAI4kB,UAAUllB,EAAEM,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEL,CAAF,GAAIklB,UAAUllB,EAAEA,CAAF,CAAI4B,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEc,CAAF,GAAI+jB,UAAUllB,EAAEmB,CAAF,CAAIS,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAE+B,CAAF,GAAI8iB,UAAUllB,EAAEoC,CAAF,CAAIR,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEu0B,EAAF,GAAK1P,UAAUllB,EAAEuY,IAAF,CAAO3W,QAAP,CAAgB,EAAhB,CAAV,CAAL,CAAoCvB,EAAEw0B,EAAF,GAAK3P,UAAUllB,EAAEwY,IAAF,CAAO5W,QAAP,CAAgB,EAAhB,CAAV,CAAL,CAAoCvB,EAAE00B,EAAF,GAAK7P,UAAUllB,EAAEyY,KAAF,CAAQ7W,QAAR,CAAiB,EAAjB,CAAV,CAAL,CAAqC,OAAOvB,CAAP;AAAS,GAAvU,MAA2U;AAAC,QAAGL,aAAasY,MAAb,IAAqBtY,EAAE2Y,QAA1B,EAAmC;AAACtY,QAAEs0B,GAAF,GAAM,KAAN,CAAYt0B,EAAEa,CAAF,GAAIgkB,UAAUllB,EAAEkB,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgCvB,EAAEC,CAAF,GAAI4kB,UAAUllB,EAAEM,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAV,CAAJ,CAAgC,OAAOvB,CAAP;AAAS,KAAzH,MAA6H;AAAC,UAAGL,aAAa8X,KAAKf,MAAL,CAAYuX,KAAzB,IAAgCtuB,EAAE4Y,SAArC,EAA+C;AAAC,YAAI9X,IAAEd,EAAEywB,sBAAF,EAAN,CAAiC,IAAG3vB,MAAI,OAAJ,IAAaA,MAAI,OAApB,EAA4B;AAAC,gBAAK,qCAAmCA,CAAxC;AAA0C,aAAIP,IAAEP,EAAEuwB,iBAAF,EAAN,CAA4BlwB,EAAEs0B,GAAF,GAAM,IAAN,CAAWt0B,EAAE60B,GAAF,GAAMp0B,CAAN,CAAQT,EAAE+D,CAAF,GAAI8gB,UAAU3kB,EAAE6D,CAAZ,CAAJ,CAAmB/D,EAAE0H,CAAF,GAAImd,UAAU3kB,EAAEwH,CAAZ,CAAJ,CAAmB1H,EAAEL,CAAF,GAAIklB,UAAUllB,EAAEkwB,SAAZ,CAAJ,CAA2B,OAAO7vB,CAAP;AAAS,OAAjR,MAAqR;AAAC,YAAGL,aAAa8X,KAAKf,MAAL,CAAYuX,KAAzB,IAAgCtuB,EAAE2Y,QAArC,EAA8C;AAAC,cAAI7X,IAAEd,EAAEywB,sBAAF,EAAN,CAAiC,IAAG3vB,MAAI,OAAJ,IAAaA,MAAI,OAApB,EAA4B;AAAC,kBAAK,qCAAmCA,CAAxC;AAA0C,eAAIP,IAAEP,EAAEuwB,iBAAF,EAAN,CAA4BlwB,EAAEs0B,GAAF,GAAM,IAAN,CAAWt0B,EAAE60B,GAAF,GAAMp0B,CAAN,CAAQT,EAAE+D,CAAF,GAAI8gB,UAAU3kB,EAAE6D,CAAZ,CAAJ,CAAmB/D,EAAE0H,CAAF,GAAImd,UAAU3kB,EAAEwH,CAAZ,CAAJ,CAAmB,OAAO1H,CAAP;AAAS;AAAC;AAAC;AAAC,SAAK,0BAAL;AAAgC,CAAniC;AAC1ojBiY,OAAO8d,4BAAP,GAAoC,UAASt1B,CAAT,EAAW;AAAC,SAAOoiB,QAAQQ,WAAR,CAAoB5iB,CAApB,EAAsB,CAAtB,CAAP;AAAgC,CAAhF,CAAiFwX,OAAO+d,iCAAP,GAAyC,UAASv2B,CAAT,EAAW;AAAC,MAAIoB,IAAEgiB,OAAN,CAAc,IAAIxiB,IAAEQ,EAAEqiB,IAAR,CAAa,IAAI1iB,IAAEyX,OAAO8d,4BAAP,CAAoCt2B,CAApC,CAAN,CAA6C,IAAIQ,IAAEI,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIJ,IAAEC,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIR,IAAEK,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIN,IAAEG,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIhB,IAAEa,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIjB,IAAEc,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIgC,IAAEnC,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAID,IAAEF,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIb,IAAEU,EAAEZ,CAAF,EAAIe,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIA,IAAE,IAAIwI,KAAJ,EAAN,CAAkBxI,EAAE+B,IAAF,CAAOtC,CAAP,EAASG,CAAT,EAAWJ,CAAX,EAAaE,CAAb,EAAeV,CAAf,EAAiBD,CAAjB,EAAmBiD,CAAnB,EAAqBjC,CAArB,EAAuBZ,CAAvB,EAA0B,OAAOa,CAAP;AAAS,CAAlU,CAAmUyX,OAAOrY,SAAP,CAAiBq2B,2BAAjB,GAA6C,UAASt2B,CAAT,EAAW;AAAC,MAAIO,IAAEwlB,SAAS/lB,CAAT,CAAN,CAAkB,IAAIK,IAAEiY,OAAO+d,iCAAP,CAAyC91B,CAAzC,CAAN,CAAkD,KAAKy0B,YAAL,CAAkB30B,EAAE,CAAF,CAAlB,EAAuBA,EAAE,CAAF,CAAvB,EAA4BA,EAAE,CAAF,CAA5B,EAAiCA,EAAE,CAAF,CAAjC,EAAsCA,EAAE,CAAF,CAAtC,EAA2CA,EAAE,CAAF,CAA3C,EAAgDA,EAAE,CAAF,CAAhD,EAAqDA,EAAE,CAAF,CAArD;AAA2D,CAAxL,CAAyLiY,OAAOrY,SAAP,CAAiBoxB,kBAAjB,GAAoC,UAAS9wB,CAAT,EAAW;AAAC,MAAIF,IAAEiY,OAAO+d,iCAAP,CAAyC91B,CAAzC,CAAN,CAAkD,KAAKy0B,YAAL,CAAkB30B,EAAE,CAAF,CAAlB,EAAuBA,EAAE,CAAF,CAAvB,EAA4BA,EAAE,CAAF,CAA5B,EAAiCA,EAAE,CAAF,CAAjC,EAAsCA,EAAE,CAAF,CAAtC,EAA2CA,EAAE,CAAF,CAA3C,EAAgDA,EAAE,CAAF,CAAhD,EAAqDA,EAAE,CAAF,CAArD;AAA2D,CAA7J,CAA8JiY,OAAOrY,SAAP,CAAiBsxB,kBAAjB,GAAoC,UAASjxB,CAAT,EAAW;AAAC,MAAIC,CAAJ,EAAME,CAAN,EAAQG,CAAR,EAAUP,CAAV,EAAYS,CAAZ,EAAchB,CAAd,EAAgBE,CAAhB,EAAkBa,CAAlB,CAAoB,IAAIgC,IAAEqgB,OAAN,CAAc,IAAItjB,IAAEiD,EAAEihB,UAAR,CAAmB,IAAGjhB,EAAEqhB,SAAF,CAAY5jB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,UAAK,sBAAL;AAA4B,OAAG;AAACC,QAAEX,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBG,IAAEb,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBM,IAAEhB,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBD,IAAET,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBQ,IAAElB,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBR,IAAEF,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBN,IAAEJ,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF,CAAsBO,IAAEjB,EAAEU,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAN,EAAc,IAAd,CAAF;AAAsB,GAApL,CAAoL,OAAMI,CAAN,EAAQ;AAAC,UAAK,wCAAL;AAA8C,QAAKs0B,YAAL,CAAkBz0B,CAAlB,EAAoBE,CAApB,EAAsBG,CAAtB,EAAwBP,CAAxB,EAA0BS,CAA1B,EAA4BhB,CAA5B,EAA8BE,CAA9B,EAAgCa,CAAhC;AAAmC,CAA1a,CAA2ayX,OAAOrY,SAAP,CAAiBs2B,kBAAjB,GAAoC,UAASh2B,CAAT,EAAW;AAAC,MAAID,IAAE4iB,OAAN,CAAc,IAAI7iB,IAAEC,EAAEijB,IAAR,CAAa,IAAGjjB,EAAE4jB,SAAF,CAAY3jB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,UAAK,gCAAL;AAAsC,OAAIO,IAAER,EAAEojB,WAAF,CAAcnjB,CAAd,EAAgB,CAAhB,CAAN,CAAyB,IAAGO,EAAEH,MAAF,KAAW,CAAX,IAAcJ,EAAE4C,MAAF,CAASrC,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAAjC,IAAuCP,EAAE4C,MAAF,CAASrC,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAA7D,EAAkE;AAAC,UAAK,iCAAL;AAAuC,OAAIhB,IAAEO,EAAEE,CAAF,EAAIO,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAId,IAAEK,EAAEE,CAAF,EAAIO,EAAE,CAAF,CAAJ,CAAN,CAAgB,KAAKmY,SAAL,CAAenZ,CAAf,EAAiBE,CAAjB;AAAoB,CAAnU,CAAoUsY,OAAOrY,SAAP,CAAiBuxB,kBAAjB,GAAoC,UAASnxB,CAAT,EAAW;AAAC,MAAIE,IAAE2iB,OAAN,CAAc,IAAG3iB,EAAE2jB,SAAF,CAAY7jB,CAAZ,MAAiB,KAApB,EAA0B;AAAC,UAAK,sBAAL;AAA4B,OAAGE,EAAEsjB,YAAF,CAAexjB,CAAf,EAAiB,CAAjB,EAAmB,CAAC,CAAD,EAAG,CAAH,CAAnB,MAA4B,wBAA/B,EAAwD;AAAC,UAAK,0BAAL;AAAgC,OAAIS,IAAEP,EAAEsjB,YAAF,CAAexjB,CAAf,EAAiB,CAAjB,EAAmB,CAAC,CAAD,EAAG,CAAH,CAAnB,CAAN,CAAgC,KAAKk2B,kBAAL,CAAwBz1B,CAAxB;AAA2B,CAAzQ,CAA0QwX,OAAOrY,SAAP,CAAiBwxB,iBAAjB,GAAmC,UAASpxB,CAAT,EAAWL,CAAX,EAAa;AAAC,MAAIc,CAAJ,EAAMP,CAAN,CAAQO,IAAE,IAAIq0B,IAAJ,EAAF,CAAar0B,EAAE01B,WAAF,CAAcn2B,CAAd,EAAiBE,IAAEO,EAAE21B,eAAF,EAAF,CAAsB,KAAKjF,kBAAL,CAAwBjxB,CAAxB;AAA2B,CAAxI;AACpuD,IAAIm2B,iBAAe,IAAI9Z,MAAJ,CAAW,EAAX,CAAnB,CAAkC8Z,eAAeC,OAAf,CAAuB,WAAvB,EAAmC,IAAnC,EAAyC,SAASC,wCAAT,CAAkD52B,CAAlD,EAAoDM,CAApD,EAAsDQ,CAAtD,EAAwD;AAAC,MAAIT,IAAE,SAAFA,CAAE,CAASP,CAAT,EAAW;AAAC,WAAOgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiT,UAAjB,CAA4BnrB,CAA5B,EAA8BgB,CAA9B,CAAP;AAAwC,GAA1D,CAA2D,IAAIP,IAAEF,EAAEL,CAAF,CAAN,CAAW,OAAO8X,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBgT,sBAAjB,CAAwCzqB,CAAxC,EAA0CO,CAA1C,EAA4CR,CAA5C,CAAP;AAAsD,UAASstB,uBAAT,CAAiCttB,CAAjC,EAAmCN,CAAnC,EAAqC;AAAC,MAAIO,IAAE,EAAN,CAAS,IAAIO,IAAEd,IAAE,CAAF,GAAIM,EAAEK,MAAZ,CAAmB,KAAI,IAAIN,IAAE,CAAV,EAAYA,IAAES,CAAd,EAAgBT,GAAhB,EAAoB;AAACE,QAAEA,IAAE,GAAJ;AAAQ,UAAOA,IAAED,CAAT;AAAW,QAAOL,SAAP,CAAiBiuB,IAAjB,GAAsB,UAASluB,CAAT,EAAWc,CAAX,EAAa;AAAC,MAAIT,IAAE,SAAFA,CAAE,CAASC,CAAT,EAAW;AAAC,WAAOwX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiT,UAAjB,CAA4B3qB,CAA5B,EAA8BQ,CAA9B,CAAP;AAAwC,GAA1D,CAA2D,IAAIP,IAAEF,EAAEL,CAAF,CAAN,CAAW,OAAO,KAAK2uB,mBAAL,CAAyBpuB,CAAzB,EAA2BO,CAA3B,CAAP;AAAqC,CAA/I,CAAgJwX,OAAOrY,SAAP,CAAiB0uB,mBAAjB,GAAqC,UAASruB,CAAT,EAAWC,CAAX,EAAa;AAAC,MAAIT,IAAEgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBgT,sBAAjB,CAAwC1qB,CAAxC,EAA0CC,CAA1C,EAA4C,KAAKW,CAAL,CAAO+N,SAAP,EAA5C,CAAN,CAAsE,IAAI5O,IAAEmX,YAAY1X,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAIE,IAAE,KAAK62B,SAAL,CAAex2B,CAAf,CAAN,CAAwB,IAAIS,IAAEd,EAAE4B,QAAF,CAAW,EAAX,CAAN,CAAqB,OAAOgsB,wBAAwB9sB,CAAxB,EAA0B,KAAKI,CAAL,CAAO+N,SAAP,EAA1B,CAAP;AAAqD,CAAnP,CAAoP,SAAS6nB,YAAT,CAAsBv2B,CAAtB,EAAwBO,CAAxB,EAA0BR,CAA1B,EAA4B;AAAC,MAAID,IAAE,EAAN;AAAA,MAASL,IAAE,CAAX,CAAa,OAAMK,EAAEM,MAAF,GAASG,CAAf,EAAiB;AAACT,SAAG8X,UAAU7X,EAAE+X,UAAU9X,IAAE8C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiC,CAAC,CAACrD,IAAE,UAAH,KAAgB,EAAjB,EAAoB,CAACA,IAAE,QAAH,KAAc,EAAlC,EAAqC,CAACA,IAAE,KAAH,KAAW,CAAhD,EAAkDA,IAAE,GAApD,CAAjC,CAAZ,CAAF,CAAV,CAAH,CAAyHA,KAAG,CAAH;AAAK,UAAOK,CAAP;AAAS,QAAOJ,SAAP,CAAiB82B,OAAjB,GAAyB,UAASz2B,CAAT,EAAWQ,CAAX,EAAad,CAAb,EAAe;AAAC,MAAIO,IAAE,SAAFA,CAAE,CAAST,CAAT,EAAW;AAAC,WAAOgY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyBtY,CAAzB,EAA2BgB,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAIT,IAAEE,EAAE8X,UAAU/X,CAAV,CAAF,CAAN,CAAsB,IAAGN,MAAIP,SAAP,EAAiB;AAACO,QAAE,CAAC,CAAH;AAAK,UAAO,KAAKyuB,sBAAL,CAA4BpuB,CAA5B,EAA8BS,CAA9B,EAAgCd,CAAhC,CAAP;AAA0C,CAAxL,CAAyLsY,OAAOrY,SAAP,CAAiBwuB,sBAAjB,GAAwC,UAAS7tB,CAAT,EAAWE,CAAX,EAAaD,CAAb,EAAe;AAAC,MAAIR,IAAE8X,UAAUvX,CAAV,CAAN,CAAmB,IAAIhB,IAAES,EAAEM,MAAR,CAAe,IAAIkC,IAAE,KAAK3B,CAAL,CAAO+N,SAAP,KAAmB,CAAzB,CAA2B,IAAI1O,IAAEgF,KAAK/C,IAAL,CAAUK,IAAE,CAAZ,CAAN,CAAqB,IAAI7C,CAAJ,CAAM,IAAIoB,IAAE,SAAFA,CAAE,CAASV,CAAT,EAAW;AAAC,WAAOoX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyB1X,CAAzB,EAA2BI,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAGD,MAAI,CAAC,CAAL,IAAQA,MAAIpB,SAAf,EAAyB;AAACoB,QAAEjB,CAAF;AAAI,GAA9B,MAAkC;AAAC,QAAGiB,MAAI,CAAC,CAAR,EAAU;AAACA,UAAEN,IAAEX,CAAF,GAAI,CAAN;AAAQ,KAAnB,MAAuB;AAAC,UAAGiB,IAAE,CAAC,CAAN,EAAQ;AAAC,cAAK,qBAAL;AAA2B;AAAC;AAAC,OAAGN,IAAGX,IAAEiB,CAAF,GAAI,CAAV,EAAa;AAAC,UAAK,eAAL;AAAqB,OAAIf,IAAE,EAAN,CAAS,IAAGe,IAAE,CAAL,EAAO;AAACf,QAAE,IAAIuJ,KAAJ,CAAUxI,CAAV,CAAF,CAAe,IAAI0W,YAAJ,GAAmB/G,SAAnB,CAA6B1Q,CAA7B,EAAgCA,IAAEuD,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiCvD,CAAjC,CAAF;AAAsC,OAAIoB,IAAEiX,UAAU/W,EAAEiX,UAAU,qCAAmChY,CAAnC,GAAqCP,CAA/C,CAAF,CAAV,CAAN,CAAsE,IAAIW,IAAE,EAAN,CAAS,KAAIT,IAAE,CAAN,EAAQA,IAAEO,IAAEM,CAAF,GAAIjB,CAAJ,GAAM,CAAhB,EAAkBI,KAAG,CAArB,EAAuB;AAACS,MAAET,CAAF,IAAK,CAAL;AAAO,OAAIM,IAAE+C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiC5C,CAAjC,IAAoC,MAApC,GAA2CX,CAAjD,CAAmD,IAAID,IAAEi3B,aAAa51B,CAAb,EAAeZ,EAAEK,MAAjB,EAAwBS,CAAxB,CAAN,CAAiC,IAAIgB,IAAE,EAAN,CAAS,KAAIpC,IAAE,CAAN,EAAQA,IAAEM,EAAEK,MAAZ,EAAmBX,KAAG,CAAtB,EAAwB;AAACoC,MAAEpC,CAAF,IAAKM,EAAEiD,UAAF,CAAavD,CAAb,IAAgBH,EAAE0D,UAAF,CAAavD,CAAb,CAArB;AAAqC,OAAImB,IAAG,SAAQ,IAAEZ,CAAF,GAAIsC,CAAb,GAAiB,GAAvB,CAA2BT,EAAE,CAAF,KAAM,CAACjB,CAAP,CAAS,KAAInB,IAAE,CAAN,EAAQA,IAAEJ,CAAV,EAAYI,GAAZ,EAAgB;AAACoC,MAAEQ,IAAF,CAAO1B,EAAEqC,UAAF,CAAavD,CAAb,CAAP;AAAwB,KAAE4C,IAAF,CAAO,GAAP,EAAY,OAAOgrB,wBAAwB,KAAKiJ,SAAL,CAAe,IAAIptB,UAAJ,CAAerH,CAAf,CAAf,EAAkCR,QAAlC,CAA2C,EAA3C,CAAxB,EAAuE,KAAKV,CAAL,CAAO+N,SAAP,EAAvE,CAAP;AAAkG,CAAt3B,CAAu3B,SAAS+nB,8BAAT,CAAwCl2B,CAAxC,EAA0Cd,CAA1C,EAA4CO,CAA5C,EAA8C;AAAC,MAAIF,IAAE,IAAIiY,MAAJ,EAAN,CAAmBjY,EAAE4Y,SAAF,CAAYjZ,CAAZ,EAAcO,CAAd,EAAiB,IAAID,IAAED,EAAE0Y,QAAF,CAAWjY,CAAX,CAAN,CAAoB,OAAOR,CAAP;AAAS,UAAS22B,gCAAT,CAA0Cn2B,CAA1C,EAA4CP,CAA5C,EAA8CF,CAA9C,EAAgD;AAAC,MAAIC,IAAE02B,+BAA+Bl2B,CAA/B,EAAiCP,CAAjC,EAAmCF,CAAnC,CAAN,CAA4C,IAAIL,IAAEM,EAAEsB,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,QAAvB,EAAgC,EAAhC,CAAN,CAA0C,OAAO9c,CAAP;AAAS,UAASk3B,4CAAT,CAAsDp3B,CAAtD,EAAwD;AAAC,OAAI,IAAIQ,CAAR,IAAawX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiQ,cAA9B,EAA6C;AAAC,QAAIjoB,IAAE8X,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiQ,cAAjB,CAAgC3nB,CAAhC,CAAN,CAAyC,IAAID,IAAEL,EAAEW,MAAR,CAAe,IAAGb,EAAEmJ,SAAF,CAAY,CAAZ,EAAc5I,CAAd,KAAkBL,CAArB,EAAuB;AAAC,UAAIO,IAAE,CAACD,CAAD,EAAGR,EAAEmJ,SAAF,CAAY5I,CAAZ,CAAH,CAAN,CAAyB,OAAOE,CAAP;AAAS;AAAC,UAAM,EAAN;AAAS,QAAON,SAAP,CAAiB6uB,MAAjB,GAAwB,UAAShvB,CAAT,EAAWW,CAAX,EAAa;AAACA,MAAEA,EAAEqc,OAAF,CAAU4Z,cAAV,EAAyB,EAAzB,CAAF,CAA+Bj2B,IAAEA,EAAEqc,OAAF,CAAU,SAAV,EAAoB,EAApB,CAAF,CAA0B,IAAIzc,IAAEmX,YAAY/W,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAGJ,EAAE4O,SAAF,KAAc,KAAK/N,CAAL,CAAO+N,SAAP,EAAjB,EAAoC;AAAC,WAAO,CAAP;AAAS,OAAIvO,IAAE,KAAKqY,QAAL,CAAc1Y,CAAd,CAAN,CAAuB,IAAIC,IAAEI,EAAEkB,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,QAAvB,EAAgC,EAAhC,CAAN,CAA0C,IAAIld,IAAEs3B,6CAA6C52B,CAA7C,CAAN,CAAsD,IAAGV,EAAEe,MAAF,IAAU,CAAb,EAAe;AAAC,WAAO,KAAP;AAAa,OAAIX,IAAEJ,EAAE,CAAF,CAAN,CAAW,IAAIC,IAAED,EAAE,CAAF,CAAN,CAAW,IAAIkB,IAAE,SAAFA,CAAE,CAASD,CAAT,EAAW;AAAC,WAAOiX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBiT,UAAjB,CAA4BpqB,CAA5B,EAA8Bb,CAA9B,CAAP;AAAwC,GAA1D,CAA2D,IAAIO,IAAEO,EAAEhB,CAAF,CAAN,CAAW,OAAOD,KAAGU,CAAV;AAAa,CAAla,CAAma+X,OAAOrY,SAAP,CAAiBivB,qBAAjB,GAAuC,UAAS5uB,CAAT,EAAWQ,CAAX,EAAa;AAACA,MAAEA,EAAEgc,OAAF,CAAU4Z,cAAV,EAAyB,EAAzB,CAAF,CAA+B51B,IAAEA,EAAEgc,OAAF,CAAU,SAAV,EAAoB,EAApB,CAAF,CAA0B,IAAIzc,IAAEmX,YAAY1W,CAAZ,EAAc,EAAd,CAAN,CAAwB,IAAGT,EAAE4O,SAAF,KAAc,KAAK/N,CAAL,CAAO+N,SAAP,EAAjB,EAAoC;AAAC,WAAO,CAAP;AAAS,OAAIpP,IAAE,KAAKkZ,QAAL,CAAc1Y,CAAd,CAAN,CAAuB,IAAIT,IAAEC,EAAE+B,QAAF,CAAW,EAAX,EAAekb,OAAf,CAAuB,QAAvB,EAAgC,EAAhC,CAAN,CAA0C,IAAIvc,IAAE22B,6CAA6Ct3B,CAA7C,CAAN,CAAsD,IAAGW,EAAEI,MAAF,IAAU,CAAb,EAAe;AAAC,WAAO,KAAP;AAAa,OAAIX,IAAEO,EAAE,CAAF,CAAN,CAAW,IAAIT,IAAES,EAAE,CAAF,CAAN,CAAW,OAAOT,KAAGQ,CAAV;AAAa,CAA3W,CAA4WgY,OAAOrY,SAAP,CAAiBk3B,SAAjB,GAA2B,UAAS52B,CAAT,EAAWF,CAAX,EAAaS,CAAb,EAAehB,CAAf,EAAiB;AAAC,MAAIQ,IAAE,SAAFA,CAAE,CAASV,CAAT,EAAW;AAAC,WAAOkY,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyBxY,CAAzB,EAA2BkB,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAId,IAAEM,EAAE+X,UAAU9X,CAAV,CAAF,CAAN,CAAsB,IAAGT,MAAIL,SAAP,EAAiB;AAACK,QAAE,CAAC,CAAH;AAAK,UAAO,KAAKmvB,wBAAL,CAA8BjvB,CAA9B,EAAgCK,CAAhC,EAAkCS,CAAlC,EAAoChB,CAApC,CAAP;AAA8C,CAAhM,CAAiMwY,OAAOrY,SAAP,CAAiBgvB,wBAAjB,GAA0C,UAASnvB,CAAT,EAAWuC,CAAX,EAAazB,CAAb,EAAeL,CAAf,EAAiB;AAAC,MAAIM,IAAE,IAAI4I,UAAJ,CAAepH,CAAf,EAAiB,EAAjB,CAAN,CAA2B,IAAGxB,EAAEoO,SAAF,KAAc,KAAK/N,CAAL,CAAO+N,SAAP,EAAjB,EAAoC;AAAC,WAAO,KAAP;AAAa,OAAI1M,IAAE,SAAFA,CAAE,CAAS7B,CAAT,EAAW;AAAC,WAAOoX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyB1X,CAAzB,EAA2BE,CAA3B,CAAP;AAAqC,GAAvD,CAAwD,IAAIH,IAAE0X,UAAUrY,CAAV,CAAN,CAAmB,IAAID,IAAEY,EAAEE,MAAR,CAAe,IAAIf,IAAE,KAAKsB,CAAL,CAAO+N,SAAP,KAAmB,CAAzB,CAA2B,IAAIpM,IAAE0C,KAAK/C,IAAL,CAAU5C,IAAE,CAAZ,CAAN,CAAqB,IAAIwC,CAAJ,CAAM,IAAG7B,MAAI,CAAC,CAAL,IAAQA,MAAId,SAAf,EAAyB;AAACc,QAAEV,CAAF;AAAI,GAA9B,MAAkC;AAAC,QAAGU,MAAI,CAAC,CAAR,EAAU;AAACA,UAAEsC,IAAEhD,CAAF,GAAI,CAAN;AAAQ,KAAnB,MAAuB;AAAC,UAAGU,IAAE,CAAC,CAAN,EAAQ;AAAC,cAAK,qBAAL;AAA2B;AAAC;AAAC,OAAGsC,IAAGhD,IAAEU,CAAF,GAAI,CAAV,EAAa;AAAC,UAAK,eAAL;AAAqB,OAAIO,IAAE,KAAKiY,QAAL,CAAclY,CAAd,EAAiBoU,WAAjB,EAAN,CAAqC,KAAI7S,IAAE,CAAN,EAAQA,IAAEtB,EAAEH,MAAZ,EAAmByB,KAAG,CAAtB,EAAwB;AAACtB,MAAEsB,CAAF,KAAM,GAAN;AAAU,UAAMtB,EAAEH,MAAF,GAASkC,CAAf,EAAiB;AAAC/B,MAAEob,OAAF,CAAU,CAAV;AAAa,OAAGpb,EAAE+B,IAAE,CAAJ,MAAS,GAAZ,EAAgB;AAAC,UAAK,sCAAL;AAA4C,OAAEQ,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiCvC,CAAjC,CAAF,CAAsC,IAAId,IAAEc,EAAEqC,MAAF,CAAS,CAAT,EAAWN,IAAEhD,CAAF,GAAI,CAAf,CAAN,CAAwB,IAAIS,IAAEQ,EAAEqC,MAAF,CAASnD,EAAEW,MAAX,EAAkBd,CAAlB,CAAN,CAA2B,IAAIsB,IAAG,SAAQ,IAAE0B,CAAF,GAAIjD,CAAb,GAAiB,GAAvB,CAA2B,IAAG,CAACI,EAAEuD,UAAF,CAAa,CAAb,IAAgBpC,CAAjB,MAAsB,CAAzB,EAA2B;AAAC,UAAK,8BAAL;AAAoC,OAAID,IAAE41B,aAAax2B,CAAb,EAAeN,EAAEW,MAAjB,EAAwB4B,CAAxB,CAAN,CAAiC,IAAInB,IAAE,EAAN,CAAS,KAAIgB,IAAE,CAAN,EAAQA,IAAEpC,EAAEW,MAAZ,EAAmByB,KAAG,CAAtB,EAAwB;AAAChB,MAAEgB,CAAF,IAAKpC,EAAEuD,UAAF,CAAanB,CAAb,IAAgBlB,EAAEqC,UAAF,CAAanB,CAAb,CAArB;AAAqC,KAAE,CAAF,KAAM,CAACjB,CAAP,CAAS,IAAId,IAAEwC,IAAEhD,CAAF,GAAIU,CAAJ,GAAM,CAAZ,CAAc,KAAI6B,IAAE,CAAN,EAAQA,IAAE/B,CAAV,EAAY+B,KAAG,CAAf,EAAiB;AAAC,QAAGhB,EAAEgB,CAAF,MAAO,CAAV,EAAY;AAAC,YAAK,0BAAL;AAAgC;AAAC,OAAGhB,EAAEf,CAAF,MAAO,CAAV,EAAY;AAAC,UAAK,uBAAL;AAA6B,UAAOC,MAAI6X,UAAU5V,EAAE8V,UAAU,qCAAmC5X,CAAnC,GAAqC4C,OAAOC,YAAP,CAAoB7B,KAApB,CAA0B4B,MAA1B,EAAiCjC,EAAEsB,KAAF,CAAQ,CAACnC,CAAT,CAAjC,CAA/C,CAAF,CAAV,CAAX;AAAuH,CAArlC,CAAslC+X,OAAO8e,aAAP,GAAqB,CAAC,CAAtB,CAAwB9e,OAAO+e,YAAP,GAAoB,CAAC,CAArB,CAAuB/e,OAAOgf,gBAAP,GAAwB,CAAC,CAAzB;AACzhJ,SAASnC,IAAT,GAAe;AAAC,MAAIt0B,IAAEqiB,OAAN;AAAA,MAAcziB,IAAEI,EAAE6iB,WAAlB;AAAA,MAA8B7jB,IAAEgB,EAAE0iB,IAAlC;AAAA,MAAuCljB,IAAEQ,EAAE2iB,MAA3C;AAAA,MAAkD1jB,IAAEe,EAAEijB,UAAtD;AAAA,MAAiEvjB,IAAEM,EAAEgjB,YAArE;AAAA,MAAkFjkB,IAAEiB,EAAE+iB,YAAtF;AAAA,MAAmG5jB,IAAEa,EAAEyiB,OAAvG;AAAA,MAA+G5iB,IAAEG,EAAEwjB,OAAnH;AAAA,MAA2HvjB,IAAEq0B,IAA7H;AAAA,MAAkI70B,IAAEylB,QAApI,CAA6I,KAAK7F,GAAL,GAAS,IAAT,CAAc,KAAK6S,OAAL,GAAa,CAAb,CAAe,KAAKwE,OAAL,GAAa,CAAb,CAAe,KAAKC,QAAL,GAAc,IAAd,CAAmB,KAAKC,UAAL,GAAgB,YAAU;AAAC,QAAG,KAAKvX,GAAL,KAAW,IAAX,IAAiB,KAAK6S,OAAL,KAAe,CAAnC,EAAqC;AAAC,aAAO,KAAKA,OAAZ;AAAoB,SAAGxyB,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,MAAsB,YAAzB,EAAsC;AAAC,WAAK6S,OAAL,GAAa,CAAb,CAAe,KAAKwE,OAAL,GAAa,CAAC,CAAd,CAAgB,OAAO,CAAP;AAAS,UAAKxE,OAAL,GAAa,CAAb,CAAe,OAAO,CAAP;AAAS,GAA5L,CAA6L,KAAK2E,kBAAL,GAAwB,YAAU;AAAC,WAAO53B,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAAhF,CAAiF,KAAKI,0BAAL,GAAgC,YAAU;AAAC,WAAOj3B,EAAEZ,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,EAAkB,CAAlB,CAAb,EAAkC,IAAlC,CAAF,CAAP;AAAkD,GAA7F,CAA8F,KAAKK,YAAL,GAAkB,YAAU;AAAC,WAAOr3B,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAA1E,CAA2E,KAAKM,eAAL,GAAqB,YAAU;AAAC,WAAO/2B,EAAEg3B,MAAF,CAAS,KAAKF,YAAL,EAAT,CAAP;AAAqC,GAArE,CAAsE,KAAKG,aAAL,GAAmB,YAAU;AAAC,WAAOx3B,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAA3E,CAA4E,KAAKS,gBAAL,GAAsB,YAAU;AAAC,WAAOl3B,EAAEg3B,MAAF,CAAS,KAAKC,aAAL,EAAT,CAAP;AAAsC,GAAvE,CAAwE,KAAKE,YAAL,GAAkB,YAAU;AAAC,QAAIr3B,IAAEd,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,EAAkB,CAAlB,CAAb,CAAN,CAAyC32B,IAAEA,EAAEkc,OAAF,CAAU,OAAV,EAAkB,KAAlB,CAAF,CAA2Blc,IAAE6C,mBAAmB7C,CAAnB,CAAF,CAAwB,OAAOA,CAAP;AAAS,GAAlI,CAAmI,KAAKs3B,WAAL,GAAiB,YAAU;AAAC,QAAIt3B,IAAEd,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,EAAkB,CAAlB,CAAb,CAAN,CAAyC32B,IAAEA,EAAEkc,OAAF,CAAU,OAAV,EAAkB,KAAlB,CAAF,CAA2Blc,IAAE6C,mBAAmB7C,CAAnB,CAAF,CAAwB,OAAOA,CAAP;AAAS,GAAjI,CAAkI,KAAK61B,eAAL,GAAqB,YAAU;AAAC,WAAO51B,EAAEgjB,YAAF,CAAe,KAAK3D,GAApB,EAAwB,CAAxB,EAA0B,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAA1B,EAA6C,IAA7C,CAAP;AAA0D,GAA1F,CAA2F,KAAKY,eAAL,GAAqB,YAAU;AAAC,WAAOv4B,EAAE,KAAKsgB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,IAAE,KAAKqX,OAAV,CAAb,EAAgC,IAAhC,CAAP;AAA6C,GAA7E,CAA8E,KAAKa,sBAAL,GAA4B,YAAU;AAAC,QAAIx3B,IAAE,KAAKu3B,eAAL,EAAN,CAA6B,OAAOv4B,EAAE,KAAKsgB,GAAP,EAAWtf,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,EAAmB,IAAnB,CAAP;AAAgC,GAApG,CAAqG,KAAKy3B,YAAL,GAAkB,YAAU;AAAC,WAAOxK,QAAQC,MAAR,CAAe,KAAK2I,eAAL,EAAf,EAAsC,IAAtC,EAA2C,UAA3C,CAAP;AAA8D,GAA3F,CAA4F,KAAK6B,yBAAL,GAA+B,YAAU;AAAC,WAAO53B,EAAEZ,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,EAAmB,IAAnB,CAAF,CAAP;AAAmC,GAA7E,CAA8E,KAAKqY,oBAAL,GAA0B,YAAU;AAAC,WAAOz4B,EAAE,KAAKogB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,CAAb,EAAiB,IAAjB,EAAsB,IAAtB,CAAP;AAAmC,GAAxE,CAAyE,KAAKsY,eAAL,GAAqB,UAASt3B,CAAT,EAAW;AAAC,QAAIE,IAAE,KAAKk3B,yBAAL,EAAN,CAAuC,IAAI13B,IAAE,KAAK23B,oBAAL,EAAN,CAAkC,IAAI11B,IAAEtC,EAAE,KAAK2f,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,CAAb,EAAiB,IAAjB,CAAN,CAA6B,IAAI/e,IAAE,IAAI2W,KAAKf,MAAL,CAAYyW,SAAhB,CAA0B,EAACtC,KAAI9pB,CAAL,EAA1B,CAAN,CAAyCD,EAAEI,IAAF,CAAOL,CAAP,EAAUC,EAAE+qB,SAAF,CAAYrpB,CAAZ,EAAe,OAAO1B,EAAE2tB,MAAF,CAASluB,CAAT,CAAP;AAAmB,GAA5N,CAA6N,KAAK63B,QAAL,GAAc,YAAU;AAAC,QAAG,KAAK1F,OAAL,KAAe,CAAlB,EAAoB;AAAC,aAAO,CAAC,CAAR;AAAU,SAAI5xB,IAAEvB,EAAE,KAAKsgB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAb,EAAqB,IAArB,CAAN,CAAiC,IAAIrd,IAAEpC,EAAE,KAAKyf,GAAP,EAAW/e,CAAX,CAAN,CAAoB,KAAKq2B,QAAL,GAAc,IAAInuB,KAAJ,EAAd,CAA0B,KAAI,IAAInI,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAIkB,IAAE,EAAN,CAASA,EAAEs2B,QAAF,GAAW,KAAX,CAAiB,IAAI93B,IAAEH,EAAE,KAAKyf,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,CAAN,CAAuB,IAAIqB,IAAE,CAAN,CAAQ,IAAG3B,EAAED,MAAF,KAAW,CAAd,EAAgB;AAACyB,UAAEs2B,QAAF,GAAW,IAAX,CAAgBn2B,IAAE,CAAF;AAAI,SAAEggB,GAAF,GAAM1hB,EAAEkjB,WAAF,CAAcjkB,EAAE,KAAKogB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,CAAD,CAAhB,EAAoB,IAApB,CAAd,CAAN,CAA+C,IAAIE,IAAExB,EAAE,KAAKsgB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,IAAEqB,CAAH,CAAhB,CAAN,CAA6BH,EAAEu2B,IAAF,GAAO34B,EAAE,KAAKkgB,GAAP,EAAW9e,CAAX,CAAP,CAAqB,KAAKo2B,QAAL,CAAc50B,IAAd,CAAmBR,CAAnB;AAAsB;AAAC,GAAzX,CAA0X,KAAKw2B,UAAL,GAAgB,UAAS13B,CAAT,EAAW;AAAC,QAAIN,IAAE,KAAK42B,QAAX,CAAoB,IAAIp2B,IAAEF,CAAN,CAAQ,IAAG,CAACA,EAAE2b,KAAF,CAAQ,WAAR,CAAJ,EAAyB;AAACzb,UAAE0W,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmBC,QAAnB,CAA4BphB,CAA5B,CAAF;AAAiC,SAAGE,MAAI,EAAP,EAAU;AAAC,aAAO3B,SAAP;AAAiB,UAAI,IAAIoD,IAAE,CAAV,EAAYA,IAAEjC,EAAED,MAAhB,EAAuBkC,GAAvB,EAA2B;AAAC,UAAGjC,EAAEiC,CAAF,EAAK0f,GAAL,KAAWnhB,CAAd,EAAgB;AAAC,eAAOR,EAAEiC,CAAF,CAAP;AAAY;AAAC,YAAOpD,SAAP;AAAiB,GAA1N,CAA2N,KAAKo5B,sBAAL,GAA4B,YAAU;AAAC,QAAI33B,IAAE,KAAK03B,UAAL,CAAgB,kBAAhB,CAAN,CAA0C,IAAG13B,MAAIzB,SAAP,EAAiB;AAAC,aAAOyB,CAAP;AAAS,SAAIN,IAAEf,EAAE,KAAKqgB,GAAP,EAAWhf,EAAEy3B,IAAb,CAAN,CAAyB,IAAG/3B,MAAI,EAAP,EAAU;AAAC,aAAM,EAAN;AAAS,SAAGA,MAAI,QAAP,EAAgB;AAAC,aAAM,EAACk4B,IAAG,IAAJ,EAAN;AAAgB,SAAGl4B,EAAEuC,MAAF,CAAS,CAAT,EAAW,CAAX,MAAgB,UAAnB,EAA8B;AAAC,UAAI/B,IAAEvB,EAAEe,CAAF,EAAI,CAAJ,CAAN,CAAa,IAAIiC,IAAEK,SAAS9B,CAAT,EAAW,EAAX,CAAN,CAAqB,OAAM,EAAC03B,IAAG,IAAJ,EAASC,SAAQl2B,CAAjB,EAAN;AAA0B,WAAK,8BAAL;AAAoC,GAAzT,CAA0T,KAAKm2B,iBAAL,GAAuB,YAAU;AAAC,QAAI53B,IAAE,KAAKw3B,UAAL,CAAgB,UAAhB,CAAN,CAAkC,IAAGx3B,MAAI3B,SAAP,EAAiB;AAAC,aAAM,EAAN;AAAS,SAAIoD,IAAEhD,EAAE,KAAKqgB,GAAP,EAAW9e,EAAEu3B,IAAb,CAAN,CAAyB,IAAG91B,EAAElC,MAAF,GAAS,CAAT,IAAY,CAAZ,IAAekC,EAAElC,MAAF,IAAU,CAA5B,EAA8B;AAAC,YAAK,2BAAL;AAAiC,SAAIC,IAAEsC,SAASL,EAAEM,MAAF,CAAS,CAAT,EAAW,CAAX,CAAT,CAAN,CAA8B,IAAIjC,IAAEgC,SAASL,EAAEM,MAAF,CAAS,CAAT,CAAT,EAAqB,EAArB,EAAyBvB,QAAzB,CAAkC,CAAlC,CAAN,CAA2C,OAAOV,EAAEiC,MAAF,CAAS,CAAT,EAAWjC,EAAEP,MAAF,GAASC,CAApB,CAAP;AAA8B,GAA/R,CAAgS,KAAKq4B,oBAAL,GAA0B,YAAU;AAAC,QAAI/3B,IAAE,KAAK83B,iBAAL,EAAN,CAA+B,IAAIp4B,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,KAAI,IAAIxG,IAAE,CAAV,EAAYA,IAAE3B,EAAEP,MAAhB,EAAuBkC,GAAvB,EAA2B;AAAC,UAAG3B,EAAEiC,MAAF,CAASN,CAAT,EAAW,CAAX,KAAe,GAAlB,EAAsB;AAACjC,UAAEgC,IAAF,CAAOuyB,KAAK+D,aAAL,CAAmBr2B,CAAnB,CAAP;AAA8B;AAAC,YAAOjC,EAAEoC,IAAF,CAAO,GAAP,CAAP;AAAmB,GAA3L,CAA4L,KAAKm2B,0BAAL,GAAgC,YAAU;AAAC,QAAIv4B,IAAE,KAAKg4B,UAAL,CAAgB,sBAAhB,CAAN,CAA8C,IAAGh4B,MAAInB,SAAP,EAAiB;AAAC,aAAOmB,CAAP;AAAS,YAAOf,EAAE,KAAKqgB,GAAP,EAAWtf,EAAE+3B,IAAb,CAAP;AAA0B,GAA9I,CAA+I,KAAKS,4BAAL,GAAkC,YAAU;AAAC,QAAIj4B,IAAE,KAAKy3B,UAAL,CAAgB,wBAAhB,CAAN,CAAgD,IAAGz3B,MAAI1B,SAAP,EAAiB;AAAC,aAAO0B,CAAP;AAAS,SAAIP,IAAE,EAAN,CAAS,IAAIQ,IAAEf,EAAE,KAAK6f,GAAP,EAAW/e,EAAEw3B,IAAb,CAAN,CAAyB,IAAI91B,IAAEpC,EAAEW,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAGE,EAAE+B,MAAF,CAASN,EAAE3B,CAAF,CAAT,EAAc,CAAd,MAAmB,IAAtB,EAA2B;AAACN,UAAEy4B,GAAF,GAAMx5B,EAAEuB,CAAF,EAAIyB,EAAE3B,CAAF,CAAJ,CAAN;AAAgB;AAAC,YAAON,CAAP;AAAS,GAAzP,CAA0P,KAAK04B,qBAAL,GAA2B,YAAU;AAAC,QAAIn4B,IAAE,KAAKy3B,UAAL,CAAgB,aAAhB,CAAN,CAAqC,IAAGz3B,MAAI1B,SAAP,EAAiB;AAAC,aAAO0B,CAAP;AAAS,SAAIP,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,IAAIjI,IAAEf,EAAE,KAAK6f,GAAP,EAAW/e,EAAEw3B,IAAb,CAAN,CAAyB,IAAGv3B,MAAI,EAAP,EAAU;AAAC,aAAOR,CAAP;AAAS,SAAIiC,IAAEpC,EAAEW,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAACN,QAAEgC,IAAF,CAAOlC,EAAEb,EAAEuB,CAAF,EAAIyB,EAAE3B,CAAF,CAAJ,CAAF,CAAP;AAAqB,YAAON,CAAP;AAAS,GAA5O,CAA6O,KAAK24B,oBAAL,GAA0B,YAAU;AAAC,QAAI12B,IAAE,KAAK22B,qBAAL,EAAN,CAAmC,IAAI54B,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,KAAI,IAAInI,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAG2B,EAAE3B,CAAF,EAAK,CAAL,MAAU,KAAb,EAAmB;AAACN,UAAEgC,IAAF,CAAOC,EAAE3B,CAAF,EAAK,CAAL,CAAP;AAAgB;AAAC,YAAON,CAAP;AAAS,GAApK,CAAqK,KAAK44B,qBAAL,GAA2B,YAAU;AAAC,QAAIr4B,CAAJ,EAAMkB,CAAN,EAAQE,CAAR,CAAU,IAAIH,IAAE,KAAKw2B,UAAL,CAAgB,gBAAhB,CAAN,CAAwC,IAAGx2B,MAAI3C,SAAP,EAAiB;AAAC,aAAO2C,CAAP;AAAS,SAAIxB,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,IAAIjI,IAAEf,EAAE,KAAK6f,GAAP,EAAW9d,EAAEu2B,IAAb,CAAN,CAAyB,IAAI91B,IAAEpC,EAAEW,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAIF,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAACqB,UAAEnB,EAAE+B,MAAF,CAASN,EAAE3B,CAAF,CAAT,EAAc,CAAd,CAAF,CAAmBC,IAAEtB,EAAEuB,CAAF,EAAIyB,EAAE3B,CAAF,CAAJ,CAAF,CAAY,IAAGqB,MAAI,IAAP,EAAY;AAACF,YAAE+hB,UAAUjjB,CAAV,CAAF,CAAeP,EAAEgC,IAAF,CAAO,CAAC,MAAD,EAAQP,CAAR,CAAP;AAAmB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAE+hB,UAAUjjB,CAAV,CAAF,CAAeP,EAAEgC,IAAF,CAAO,CAAC,KAAD,EAAOP,CAAP,CAAP;AAAkB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAE8yB,KAAK2C,MAAL,CAAY32B,CAAZ,EAAc,CAAd,CAAF,CAAmBP,EAAEgC,IAAF,CAAO,CAAC,IAAD,EAAMP,CAAN,CAAP;AAAiB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAE+hB,UAAUjjB,CAAV,CAAF,CAAeP,EAAEgC,IAAF,CAAO,CAAC,KAAD,EAAOP,CAAP,CAAP;AAAkB,WAAGE,MAAI,IAAP,EAAY;AAACF,YAAEglB,QAAQlmB,CAAR,CAAF,CAAaP,EAAEgC,IAAF,CAAO,CAAC,IAAD,EAAMP,CAAN,CAAP;AAAiB;AAAC,YAAOzB,CAAP;AAAS,GAAvd,CAAwd,KAAK64B,8BAAL,GAAoC,YAAU;AAAC,QAAIr3B,IAAE,KAAKw2B,UAAL,CAAgB,uBAAhB,CAAN,CAA+C,IAAGx2B,MAAI3C,SAAP,EAAiB;AAAC,aAAO2C,CAAP;AAAS,SAAIxB,IAAE,IAAIyI,KAAJ,EAAN,CAAkB,IAAIxG,IAAEpC,EAAE,KAAKyf,GAAP,EAAW9d,EAAEu2B,IAAb,CAAN,CAAyB,KAAI,IAAIv3B,IAAE,CAAV,EAAYA,IAAEyB,EAAElC,MAAhB,EAAuBS,GAAvB,EAA2B;AAAC,UAAG;AAAC,YAAImB,IAAEzC,EAAE,KAAKogB,GAAP,EAAWrd,EAAEzB,CAAF,CAAX,EAAgB,CAAC,CAAD,EAAG,CAAH,EAAK,CAAL,CAAhB,EAAwB,IAAxB,CAAN,CAAoC,IAAID,IAAEijB,UAAU7hB,CAAV,CAAN,CAAmB3B,EAAEgC,IAAF,CAAOzB,CAAP;AAAU,OAArE,CAAqE,OAAMD,CAAN,EAAQ,CAAE;AAAC,YAAON,CAAP;AAAS,GAAzR,CAA0R,KAAK84B,aAAL,GAAmB,YAAU;AAAC,QAAIv4B,IAAE,KAAKy3B,UAAL,CAAgB,qBAAhB,CAAN,CAA6C,IAAGz3B,MAAI1B,SAAP,EAAiB;AAAC,aAAO0B,CAAP;AAAS,SAAIP,IAAE,EAAC+4B,MAAK,EAAN,EAASC,UAAS,EAAlB,EAAN,CAA4B,IAAI/2B,IAAEpC,EAAE,KAAKyf,GAAP,EAAW/e,EAAEw3B,IAAb,CAAN,CAAyB,KAAI,IAAIz3B,IAAE,CAAV,EAAYA,IAAE2B,EAAElC,MAAhB,EAAuBO,GAAvB,EAA2B;AAAC,UAAIkB,IAAEtC,EAAE,KAAKogB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,CAAD,CAAhB,EAAoB,IAApB,CAAN,CAAgC,IAAIE,IAAEtB,EAAE,KAAKogB,GAAP,EAAWrd,EAAE3B,CAAF,CAAX,EAAgB,CAAC,CAAD,CAAhB,EAAoB,IAApB,CAAN,CAAgC,IAAGkB,MAAI,kBAAP,EAA0B;AAACxB,UAAE+4B,IAAF,CAAO/2B,IAAP,CAAYwhB,UAAUhjB,CAAV,CAAZ;AAA0B,WAAGgB,MAAI,kBAAP,EAA0B;AAACxB,UAAEg5B,QAAF,CAAWh3B,IAAX,CAAgBwhB,UAAUhjB,CAAV,CAAhB;AAA8B;AAAC,YAAOR,CAAP;AAAS,GAA/W,CAAgX,KAAKi5B,yBAAL,GAA+B,YAAU;AAAC,QAAIz4B,IAAE,KAAKw3B,UAAL,CAAgB,qBAAhB,CAAN,CAA6C,IAAGx3B,MAAI3B,SAAP,EAAiB;AAAC,aAAO2B,CAAP;AAAS,SAAIR,IAAEP,EAAE,KAAK6f,GAAP,EAAW9e,EAAEu3B,IAAb,CAAN,CAAyB,IAAIp0B,IAAE,EAAN,CAAS,IAAIlC,IAAE5B,EAAEG,CAAF,EAAI,CAAJ,CAAN,CAAa,KAAI,IAAI2B,IAAE,CAAV,EAAYA,IAAEF,EAAE1B,MAAhB,EAAuB4B,GAAvB,EAA2B;AAAC,UAAIJ,IAAE,EAAN,CAAS,IAAIjB,IAAET,EAAEG,CAAF,EAAIyB,EAAEE,CAAF,CAAJ,CAAN,CAAgBJ,EAAE23B,EAAF,GAAKp5B,EAAEb,EAAEe,CAAF,EAAIM,EAAE,CAAF,CAAJ,CAAF,CAAL,CAAkB,IAAGA,EAAEP,MAAF,KAAW,CAAd,EAAgB;AAAC,YAAIkC,IAAEpC,EAAEG,CAAF,EAAIM,EAAE,CAAF,CAAJ,CAAN,CAAgB,KAAI,IAAIkB,IAAE,CAAV,EAAYA,IAAES,EAAElC,MAAhB,EAAuByB,GAAvB,EAA2B;AAAC,cAAIjB,IAAErB,EAAEc,CAAF,EAAIiC,EAAET,CAAF,CAAJ,EAAS,CAAC,CAAD,CAAT,EAAa,IAAb,CAAN,CAAyB,IAAGjB,MAAI,kBAAP,EAA0B;AAACgB,cAAE43B,GAAF,GAAM3V,UAAUtkB,EAAEc,CAAF,EAAIiC,EAAET,CAAF,CAAJ,EAAS,CAAC,CAAD,CAAT,CAAV,CAAN;AAA+B,WAA1D,MAA8D;AAAC,gBAAGjB,MAAI,kBAAP,EAA0B;AAACgB,gBAAE63B,OAAF,GAAU5V,UAAUtkB,EAAEc,CAAF,EAAIiC,EAAET,CAAF,CAAJ,EAAS,CAAC,CAAD,EAAG,CAAH,CAAT,CAAV,CAAV;AAAqC;AAAC;AAAC;AAAC,SAAEQ,IAAF,CAAOT,CAAP;AAAU,YAAOoC,CAAP;AAAS,GAAnd,CAAod,KAAK01B,WAAL,GAAiB,UAASr5B,CAAT,EAAW;AAAC,SAAK41B,WAAL,CAAiBl2B,EAAEM,CAAF,CAAjB;AAAuB,GAApD,CAAqD,KAAK41B,WAAL,GAAiB,UAAS51B,CAAT,EAAW;AAAC,SAAKsf,GAAL,GAAStf,CAAT,CAAW,KAAK62B,UAAL,GAAkB,IAAG;AAAC73B,QAAE,KAAKsgB,GAAP,EAAW,CAAX,EAAa,CAAC,CAAD,EAAG,CAAH,CAAb,EAAmB,IAAnB,EAAyB,KAAKuY,QAAL;AAAgB,KAA7C,CAA6C,OAAM51B,CAAN,EAAQ,CAAE;AAAC,GAAlH,CAAmH,KAAKq3B,OAAL,GAAa,YAAU;AAAC,QAAIr3B,IAAEsyB,IAAN,CAAW,IAAIltB,CAAJ,EAAM1D,CAAN,EAAQsD,CAAR,CAAUI,IAAE,gBAAF,CAAmBA,KAAG,sBAAoB,KAAKyvB,kBAAL,EAApB,GAA8C,IAAjD,CAAsDzvB,KAAG,4BAA0B,KAAK0vB,0BAAL,EAA1B,GAA4D,IAA/D,CAAoE1vB,KAAG,eAAa,KAAK4vB,eAAL,EAAb,GAAoC,IAAvC,CAA4C5vB,KAAG,kBAAgB,KAAKgwB,YAAL,EAAhB,GAAoC,IAAvC,CAA4ChwB,KAAG,iBAAe,KAAKiwB,WAAL,EAAf,GAAkC,IAArC,CAA0CjwB,KAAG,gBAAc,KAAK+vB,gBAAL,EAAd,GAAsC,IAAzC,CAA8C/vB,KAAG,+BAAH,CAAmC1D,IAAE,KAAK8zB,YAAL,EAAF,CAAsBpwB,KAAG,wBAAsB1D,EAAE6U,IAAxB,GAA6B,IAAhC,CAAqC,IAAG7U,EAAE6U,IAAF,KAAS,KAAZ,EAAkB;AAACnR,WAAG,WAAS4f,YAAYtjB,EAAErD,CAAF,CAAIU,QAAJ,CAAa,EAAb,CAAZ,EAA8BuB,MAA9B,CAAqC,CAArC,EAAuC,EAAvC,CAAT,GAAoD,OAAvD,CAA+D8E,KAAG,WAAS4f,YAAYtjB,EAAEjE,CAAF,CAAIsB,QAAJ,CAAa,EAAb,CAAZ,CAAT,GAAuC,IAA1C;AAA+C,SAAE,KAAK41B,QAAP,CAAgB,IAAG3vB,MAAIpI,SAAJ,IAAeoI,MAAI,IAAtB,EAA2B;AAACI,WAAG,sBAAH,CAA0B,KAAI,IAAI1F,IAAE,CAAV,EAAYA,IAAEsF,EAAElH,MAAhB,EAAuB4B,GAAvB,EAA2B;AAAC,YAAIrB,IAAE2G,EAAEtF,CAAF,CAAN,CAAW,IAAIuF,IAAEgQ,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmB8B,QAAnB,CAA4BjjB,EAAEqhB,GAA9B,CAAN,CAAyC,IAAGza,MAAI,EAAP,EAAU;AAACA,cAAE5G,EAAEqhB,GAAJ;AAAQ,aAAIne,IAAE,EAAN,CAAS,IAAGlD,EAAEw3B,QAAF,KAAa,IAAhB,EAAqB;AAACt0B,cAAE,UAAF;AAAa,cAAG,OAAK0D,CAAL,GAAO,GAAP,GAAW1D,CAAX,GAAa,KAAhB,CAAsB,IAAG0D,MAAI,kBAAP,EAA0B;AAAC,cAAIxD,IAAE,KAAKu0B,sBAAL,EAAN,CAAoC,IAAGv0B,EAAEw0B,EAAF,KAAOr5B,SAAV,EAAoB;AAACwI,iBAAG,UAAH;AAAc,WAAnC,MAAuC;AAACA,iBAAG,aAAH,CAAiB,IAAG3D,EAAEy0B,OAAF,KAAYt5B,SAAf,EAAyB;AAACwI,mBAAG,eAAa3D,EAAEy0B,OAAlB;AAA0B,kBAAG,IAAH;AAAQ;AAAC,SAArL,MAAyL;AAAC,cAAGjxB,MAAI,UAAP,EAAkB;AAACG,iBAAG,SAAO,KAAKgxB,oBAAL,EAAP,GAAmC,IAAtC;AAA2C,WAA9D,MAAkE;AAAC,gBAAGnxB,MAAI,sBAAP,EAA8B;AAACG,mBAAG,SAAO,KAAKkxB,0BAAL,EAAP,GAAyC,IAA5C;AAAiD,aAAhF,MAAoF;AAAC,kBAAGrxB,MAAI,wBAAP,EAAgC;AAAC,oBAAIlH,IAAE,KAAKw4B,4BAAL,EAAN,CAA0C,IAAGx4B,EAAEy4B,GAAF,KAAQ55B,SAAX,EAAqB;AAACwI,uBAAG,aAAWrH,EAAEy4B,GAAb,GAAiB,IAApB;AAAyB;AAAC,eAA3H,MAA+H;AAAC,oBAAGvxB,MAAI,aAAP,EAAqB;AAAC,sBAAI3D,IAAE,KAAKm1B,qBAAL,EAAN,CAAmCrxB,KAAG,SAAO9D,EAAEnB,IAAF,CAAO,IAAP,CAAP,GAAoB,IAAvB;AAA4B,iBAArF,MAAyF;AAAC,sBAAG8E,MAAI,gBAAP,EAAwB;AAAC,wBAAI3F,IAAE,KAAKq3B,qBAAL,EAAN,CAAmCvxB,KAAG,SAAO9F,CAAP,GAAS,IAAZ;AAAiB,mBAA7E,MAAiF;AAAC,wBAAG2F,MAAI,uBAAP,EAA+B;AAAC,0BAAIC,IAAE,KAAK0xB,8BAAL,EAAN,CAA4CxxB,KAAG,SAAOF,CAAP,GAAS,IAAZ;AAAiB,qBAA7F,MAAiG;AAAC,0BAAGD,MAAI,qBAAP,EAA6B;AAAC,4BAAI3G,IAAE,KAAKu4B,aAAL,EAAN,CAA2B,IAAGv4B,EAAEw4B,IAAF,KAASl6B,SAAZ,EAAsB;AAACwI,+BAAG,eAAa9G,EAAEw4B,IAAF,CAAO32B,IAAP,CAAY,GAAZ,CAAb,GAA8B,IAAjC;AAAsC,6BAAG7B,EAAEy4B,QAAF,KAAan6B,SAAhB,EAA0B;AAACwI,+BAAG,mBAAiB9G,EAAEy4B,QAAF,CAAW52B,IAAX,CAAgB,GAAhB,CAAjB,GAAsC,IAAzC;AAA8C;AAAC,uBAAhM,MAAoM;AAAC,4BAAG8E,MAAI,qBAAP,EAA6B;AAAC,8BAAI1G,IAAE,KAAKy4B,yBAAL,EAAN,CAAuC,KAAI,IAAIz3B,IAAE,CAAV,EAAYA,IAAEhB,EAAET,MAAhB,EAAuByB,GAAvB,EAA2B;AAAC,gCAAGhB,EAAEgB,CAAF,EAAK03B,EAAL,KAAUr6B,SAAb,EAAuB;AAACwI,mCAAG,qBAAmB7G,EAAEgB,CAAF,EAAK03B,EAAxB,GAA2B,IAA9B;AAAmC,iCAAG14B,EAAEgB,CAAF,EAAK23B,GAAL,KAAWt6B,SAAd,EAAwB;AAACwI,mCAAG,cAAY7G,EAAEgB,CAAF,EAAK23B,GAAjB,GAAqB,IAAxB;AAA6B;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC,UAAG,0BAAwB,KAAKzB,yBAAL,EAAxB,GAAyD,IAA5D,CAAiErwB,KAAG,gBAAc,KAAKswB,oBAAL,GAA4Bp1B,MAA5B,CAAmC,CAAnC,EAAqC,EAArC,CAAd,GAAuD,OAA1D,CAAkE,OAAO8E,CAAP;AAAS,GAAnkE;AAAokE,MAAK6vB,MAAL,GAAY,UAASh4B,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAGA,MAAIZ,SAAP,EAAiB;AAACY,QAAE,CAAF;AAAI,OAAGP,EAAEqD,MAAF,CAAS9C,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,UAAK,cAAL;AAAoB,OAAIE,IAAE,IAAI8I,KAAJ,EAAN,CAAkB,IAAIrJ,IAAEkjB,QAAQQ,WAAR,CAAoB5jB,CAApB,EAAsBO,CAAtB,CAAN,CAA+B,KAAI,IAAIC,IAAE,CAAV,EAAYA,IAAEN,EAAEW,MAAhB,EAAuBL,GAAvB,EAA2B;AAACC,MAAEqC,IAAF,CAAOuyB,KAAKgF,OAAL,CAAar6B,CAAb,EAAeE,EAAEM,CAAF,CAAf,CAAP;AAA6B,OAAEC,EAAEwnB,GAAF,CAAM,UAASjnB,CAAT,EAAW;AAAC,WAAOA,EAAEgc,OAAF,CAAU,GAAV,EAAc,KAAd,CAAP;AAA4B,GAA9C,CAAF,CAAkD,OAAM,MAAIvc,EAAEyC,IAAF,CAAO,GAAP,CAAV;AAAsB,CAA/Q,CAAgRmyB,KAAKgF,OAAL,GAAa,UAASr6B,CAAT,EAAWO,CAAX,EAAa;AAAC,MAAGA,MAAIZ,SAAP,EAAiB;AAACY,QAAE,CAAF;AAAI,OAAGP,EAAEqD,MAAF,CAAS9C,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,UAAK,eAAL;AAAqB,OAAIE,IAAE,IAAI8I,KAAJ,EAAN,CAAkB,IAAIrJ,IAAEkjB,QAAQQ,WAAR,CAAoB5jB,CAApB,EAAsBO,CAAtB,CAAN,CAA+B,KAAI,IAAIC,IAAE,CAAV,EAAYA,IAAEN,EAAEW,MAAhB,EAAuBL,GAAvB,EAA2B;AAACC,MAAEqC,IAAF,CAAOuyB,KAAKiF,iBAAL,CAAuBt6B,CAAvB,EAAyBE,EAAEM,CAAF,CAAzB,CAAP;AAAuC,OAAEC,EAAEwnB,GAAF,CAAM,UAASjnB,CAAT,EAAW;AAAC,WAAOA,EAAEgc,OAAF,CAAU,GAAV,EAAc,KAAd,CAAP;AAA4B,GAA9C,CAAF,CAAkD,OAAOvc,EAAEyC,IAAF,CAAO,GAAP,CAAP;AAAmB,CAAxR,CAAyRmyB,KAAKiF,iBAAL,GAAuB,UAASp6B,CAAT,EAAWU,CAAX,EAAa;AAAC,MAAID,IAAEyiB,OAAN,CAAc,IAAIrjB,IAAEY,EAAE8iB,IAAR,CAAa,IAAG7iB,MAAIjB,SAAP,EAAiB;AAACiB,QAAE,CAAF;AAAI,OAAGV,EAAEmD,MAAF,CAASzC,CAAT,EAAW,CAAX,MAAgB,IAAnB,EAAwB;AAAC,UAAK,oCAAL;AAA0C,OAAId,IAAEa,EAAEijB,WAAF,CAAc1jB,CAAd,EAAgBU,CAAhB,CAAN,CAAyB,IAAGd,EAAEe,MAAF,KAAW,CAAX,IAAcX,EAAEmD,MAAF,CAASvD,EAAE,CAAF,CAAT,EAAc,CAAd,MAAmB,IAApC,EAAyC;AAAC;AAAqC,OAAIS,IAAER,EAAEG,CAAF,EAAIJ,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIE,IAAEgY,KAAKkF,IAAL,CAAUC,QAAV,CAAmB8B,WAAnB,CAA+B1e,CAA/B,CAAN,CAAwC,IAAIC,IAAEwX,KAAKkF,IAAL,CAAUoF,IAAV,CAAeC,GAAf,CAAmBgY,SAAnB,CAA6Bv6B,CAA7B,CAAN,CAAsC,IAAIgB,IAAEjB,EAAEG,CAAF,EAAIJ,EAAE,CAAF,CAAJ,CAAN,CAAgB,IAAIW,IAAE4X,UAAUrX,CAAV,CAAN,CAAmB,OAAOR,IAAE,GAAF,GAAMC,CAAb;AAAe,CAAjZ,CAAkZ40B,KAAKC,uBAAL,GAA6B,UAAS/0B,CAAT,EAAW;AAAC,MAAIS,IAAE,IAAIq0B,IAAJ,EAAN,CAAiBr0B,EAAE01B,WAAF,CAAcn2B,CAAd,EAAiB,OAAOS,EAAEu3B,YAAF,EAAP;AAAwB,CAAnG,CAAoGlD,KAAKE,uBAAL,GAA6B,UAASh1B,CAAT,EAAW;AAAC,MAAIS,IAAE,IAAIq0B,IAAJ,EAAN,CAAiBr0B,EAAEm5B,WAAF,CAAc55B,CAAd,EAAiB,OAAOS,EAAEu3B,YAAF,EAAP;AAAwB,CAAnG,CAAoGlD,KAAKmF,6BAAL,GAAmC,UAAS/5B,CAAT,EAAW;AAAC,MAAID,IAAE4iB,OAAN,CAAc,IAAItjB,IAAEU,EAAEwjB,UAAR,CAAmB,IAAIzjB,IAAE,EAAN,CAAS,IAAIS,CAAJ,EAAMhB,CAAN,EAAQE,CAAR,CAAUK,EAAE8zB,QAAF,GAAW,IAAX,CAAgBrzB,IAAE,IAAIq0B,IAAJ,EAAF,CAAar0B,EAAEm5B,WAAF,CAAc15B,CAAd,EAAiBT,IAAEgB,EAAE21B,eAAF,EAAF,CAAsBp2B,EAAEwyB,MAAF,GAASjzB,EAAEE,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,CAAN,EAAU,IAAV,EAAgBqD,MAAhB,CAAuB,CAAvB,CAAT,CAAmC9C,EAAE+zB,MAAF,GAASx0B,EAAEE,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAT,CAA2B,IAAGO,EAAE+zB,MAAF,KAAW,gBAAd,EAA+B;AAAC/zB,MAAE8zB,QAAF,GAAWv0B,EAAEE,CAAF,EAAI,CAAJ,EAAM,CAAC,CAAD,EAAG,CAAH,CAAN,EAAY,IAAZ,CAAX;AAA6B,UAAOO,CAAP;AAAS,CAA3S,CAA4S80B,KAAK+D,aAAL,GAAmB,CAAC,kBAAD,EAAoB,gBAApB,EAAqC,iBAArC,EAAuD,kBAAvD,EAA0E,cAA1E,EAAyF,aAAzF,EAAuG,SAAvG,EAAiH,cAAjH,EAAgI,cAAhI,CAAnB;AACvqS,IAAG,OAAOphB,IAAP,IAAa,WAAb,IAA0B,CAACA,IAA9B,EAAmC;AAAC,UAmE3BA,IAnE2B,UAAK,EAAL;AAAQ,KAAG,OAAOA,KAAKyiB,GAAZ,IAAiB,WAAjB,IAA8B,CAACziB,KAAKyiB,GAAvC,EAA2C;AAACziB,OAAKyiB,GAAL,GAAS,EAAT;AAAY,MAAKA,GAAL,CAASC,GAAT,GAAa,YAAU;AAAC,MAAIn6B,IAAEyX,IAAN;AAAA,MAAWhX,IAAET,EAAEk6B,GAAF,CAAMC,GAAnB;AAAA,MAAuBj6B,IAAEO,EAAE25B,gBAA3B,CAA4C,KAAKC,QAAL,GAAc,UAAS96B,CAAT,EAAWa,CAAX,EAAa;AAAC,QAAI,KAAKk6B,SAAL,KAAiBl7B,SAAlB,KAA+BgB,KAAI,KAAKk6B,SAAL,CAAeC,OAAf,KAAyBn7B,SAA5D,CAAH,EAA2E;AAAC;AAAO,SAAIiB,IAAEd,EAAEid,KAAF,CAAQ,6BAAR,CAAN,CAA6C,IAAGnc,KAAG,IAAN,EAAW;AAAC,YAAK,yDAAL;AAA+D,SAAIG,IAAEH,EAAE,CAAF,CAAN,CAAW,IAAIJ,IAAEI,EAAE,CAAF,CAAN,CAAW,IAAIE,IAAEF,EAAE,CAAF,CAAN,CAAW,IAAIQ,IAAEL,IAAE,GAAF,GAAMP,CAAZ,CAAc,KAAKq6B,SAAL,GAAe,EAAf,CAAkB,KAAKA,SAAL,CAAeE,QAAf,GAAwBh6B,CAAxB,CAA0B,KAAK85B,SAAL,CAAeG,WAAf,GAA2Bx6B,CAA3B,CAA6B,KAAKq6B,SAAL,CAAeI,UAAf,GAA0Bn6B,CAA1B,CAA4B,KAAK+5B,SAAL,CAAeK,EAAf,GAAkB95B,CAAlB,CAAoB,IAAG,CAACT,CAAJ,EAAM;AAAC,UAAIZ,IAAEslB,UAAUvkB,CAAV,CAAN,CAAmB,IAAId,IAAE0X,YAAY3X,CAAZ,EAAc,EAAd,CAAN,CAAwB,KAAK86B,SAAL,CAAeC,OAAf,GAAuB/6B,CAAvB,CAAyB,KAAK86B,SAAL,CAAeM,QAAf,GAAwBn7B,CAAxB;AAA0B,SAAIE,IAAEqlB,WAAWxkB,CAAX,CAAN,CAAoB,IAAIgC,IAAEwiB,WAAW/kB,CAAX,CAAN,CAAoB,KAAKq6B,SAAL,CAAeO,KAAf,GAAqBl7B,CAArB,CAAuB,KAAK26B,SAAL,CAAeQ,QAAf,GAAwBt4B,CAAxB,CAA0B,IAAG,CAACtC,EAAEP,CAAF,EAAI,KAAK26B,SAAT,EAAmB,OAAnB,CAAJ,EAAgC;AAAC,YAAK,yCAAuC36B,CAA5C;AAA8C;AAAC,GAA7pB;AAA8pB,CAAluB,CAAmuB8X,KAAKyiB,GAAL,CAASC,GAAT,CAAatM,IAAb,GAAkB,UAASxtB,CAAT,EAAW4D,CAAX,EAAayD,CAAb,EAAeF,CAAf,EAAiB/G,CAAjB,EAAmB;AAAC,MAAIqD,IAAE2T,IAAN;AAAA,MAAWjV,IAAEsB,EAAEo2B,GAAf;AAAA,MAAmBn4B,IAAES,EAAE23B,GAAvB;AAAA,MAA2B56B,IAAEwC,EAAEg5B,kBAA/B;AAAA,MAAkDj6B,IAAEiB,EAAEq4B,gBAAtD;AAAA,MAAuEz6B,IAAEmE,EAAE4S,MAA3E;AAAA,MAAkFlW,IAAEb,EAAEsuB,KAAtF;AAAA,MAA4FltB,IAAEpB,EAAE4sB,GAAhG;AAAA,MAAoGrsB,IAAEP,EAAEwtB,SAAxG;AAAA,MAAkHrrB,IAAEmiB,IAApH,CAAyH,IAAIjiB,CAAJ,EAAM5B,CAAN,EAAQS,CAAR,CAAU,IAAG,OAAOoD,CAAP,IAAU,QAAV,IAAoB,QAAOA,CAAP,yCAAOA,CAAP,MAAU,QAAjC,EAA0C;AAAC,UAAK,6CAA2CA,CAAhD;AAAkD,OAAG,QAAOA,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC7D,QAAE6D,CAAF,CAAIjC,IAAEF,EAAEF,SAAF,CAAYxB,CAAZ,CAAF;AAAiB,OAAG,OAAO6D,CAAP,IAAU,QAAb,EAAsB;AAACjC,QAAEiC,CAAF,CAAI,IAAG,CAACnD,EAAEkB,CAAF,CAAJ,EAAS;AAAC,YAAK,uCAAqCA,CAA1C;AAA4C,SAAEzC,EAAEyC,CAAF,CAAF;AAAO,OAAE0F,CAAF,CAAI,IAAG,QAAOA,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC7G,QAAEiB,EAAEF,SAAF,CAAY8F,CAAZ,CAAF;AAAiB,OAAG,CAACrH,KAAG,EAAH,IAAOA,KAAG,IAAX,KAAkBD,EAAEyqB,GAAF,KAAQzrB,SAA7B,EAAuC;AAACiB,QAAED,EAAEyqB,GAAJ;AAAQ,OAAIxqB,KAAG,EAAH,IAAOA,KAAG,IAAX,IAAkBD,EAAEyqB,GAAF,KAAQzrB,SAA7B,EAAuC;AAACgB,MAAEyqB,GAAF,GAAMxqB,CAAN,CAAQ2B,IAAEF,EAAEF,SAAF,CAAYxB,CAAZ,CAAF;AAAiB,OAAGC,MAAID,EAAEyqB,GAAT,EAAa;AAAC,UAAK,wCAAsCxqB,CAAtC,GAAwC,IAAxC,GAA6CD,EAAEyqB,GAApD;AAAwD,OAAI3oB,IAAE,IAAN,CAAW,IAAGH,EAAEi5B,aAAF,CAAgB36B,CAAhB,MAAqBjB,SAAxB,EAAkC;AAAC,UAAK,2BAAyBiB,CAA9B;AAAgC,GAAnE,MAAuE;AAAC6B,QAAEH,EAAEi5B,aAAF,CAAgB36B,CAAhB,CAAF;AAAqB,OAAIJ,IAAE8kB,WAAW/iB,CAAX,CAAN,CAAoB,IAAIzB,IAAEwkB,WAAWlkB,CAAX,CAAN,CAAoB,IAAIb,IAAEC,IAAE,GAAF,GAAMM,CAAZ,CAAc,IAAIwD,IAAE,EAAN,CAAS,IAAG7B,EAAEY,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,QAAG0E,MAAIpI,SAAP,EAAiB;AAAC,YAAK,wCAAL;AAA8C,SAAII,IAAE,IAAIuB,CAAJ,CAAM,EAAC8pB,KAAI3oB,CAAL,EAAO8oB,MAAK,UAAZ,EAAuB0B,MAAKllB,CAA5B,EAAN,CAAN,CAA4ChI,EAAEosB,YAAF,CAAe5rB,CAAf,EAAkB+D,IAAEvE,EAAEmtB,OAAF,EAAF;AAAc,GAAtK,MAA0K;AAAC,QAAGzqB,EAAEyD,OAAF,CAAU,WAAV,KAAwB,CAAC,CAA5B,EAA8B;AAAC,UAAIlG,IAAE,IAAIS,CAAJ,CAAM,EAAC2qB,KAAI3oB,CAAL,EAAN,CAAN,CAAqBzC,EAAEyB,IAAF,CAAOsG,CAAP,EAAS/G,CAAT,EAAYhB,EAAEmsB,YAAF,CAAe5rB,CAAf,EAAkBi7B,WAASx7B,EAAEouB,IAAF,EAAT,CAAkB9pB,IAAE0T,KAAKf,MAAL,CAAYuX,KAAZ,CAAkBuD,kBAAlB,CAAqCyJ,QAArC,CAAF;AAAiD,KAArJ,MAAyJ;AAAC,UAAG/4B,KAAG,MAAN,EAAa;AAAC,YAAIzC,IAAE,IAAIS,CAAJ,CAAM,EAAC2qB,KAAI3oB,CAAL,EAAN,CAAN,CAAqBzC,EAAEyB,IAAF,CAAOsG,CAAP,EAAS/G,CAAT,EAAYhB,EAAEmsB,YAAF,CAAe5rB,CAAf,EAAkB+D,IAAEtE,EAAEouB,IAAF,EAAF;AAAW;AAAC;AAAC,OAAI3pB,IAAE2gB,UAAU9gB,CAAV,CAAN,CAAmB,OAAO/D,IAAE,GAAF,GAAMkE,CAAb;AAAe,CAAzsC,CAA0sCuT,KAAKyiB,GAAL,CAASC,GAAT,CAAa1L,MAAb,GAAoB,UAAS3qB,CAAT,EAAW8D,CAAX,EAAa/G,CAAb,EAAe;AAAC,MAAIkD,IAAE0T,IAAN;AAAA,MAAW1V,IAAEgC,EAAEm2B,GAAf;AAAA,MAAmBp4B,IAAEC,EAAEo4B,GAAvB;AAAA,MAA2B95B,IAAEyB,EAAEi5B,kBAA/B;AAAA,MAAkD96B,IAAE8D,EAAE2S,MAAtD;AAAA,MAA6D5V,IAAEb,EAAEguB,KAAjE;AAAA,MAAuEjsB,IAAE/B,EAAEssB,GAA3E;AAAA,MAA+E5sB,IAAEM,EAAEktB,SAAnF;AAAA,MAA6F3qB,CAA7F,CAA+F,IAAG,QAAOyV,MAAP,yCAAOA,MAAP,OAAgB7Y,SAAnB,EAA6B;AAACoD,QAAEyV,MAAF;AAAS,OAAIvQ,IAAE5D,EAAE8a,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAGlX,EAAEpH,MAAF,KAAW,CAAd,EAAgB;AAAC,WAAO,KAAP;AAAa,OAAIb,IAAEiI,EAAE,CAAF,CAAN,CAAW,IAAIxF,IAAEwF,EAAE,CAAF,CAAN,CAAW,IAAIxH,IAAET,IAAE,GAAF,GAAMyC,CAAZ,CAAc,IAAIuF,IAAEqd,UAAUpd,EAAE,CAAF,CAAV,CAAN,CAAsB,IAAInH,IAAEF,EAAE2kB,WAAWtd,EAAE,CAAF,CAAX,CAAF,CAAN,CAA0B,IAAIlH,IAAE,IAAN,CAAW,IAAIgH,IAAE,IAAN,CAAW,IAAGjH,EAAEsqB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,UAAK,mCAAL;AAAyC,GAA/D,MAAmE;AAACoB,QAAED,EAAEsqB,GAAJ,CAAQrjB,IAAEhH,EAAEsC,MAAF,CAAS,CAAT,EAAW,CAAX,CAAF;AAAgB,OAAGjC,KAAG,IAAH,IAASd,OAAOH,SAAP,CAAiB2B,QAAjB,CAA0Ba,IAA1B,CAA+BvB,CAA/B,MAAoC,gBAA7C,IAA+DA,EAAEP,MAAF,GAAS,CAA3E,EAA6E;AAAC,QAAIN,IAAE,MAAIa,EAAE8B,IAAF,CAAO,GAAP,CAAJ,GAAgB,GAAtB,CAA0B,IAAG3C,EAAE2F,OAAF,CAAU,MAAInF,CAAJ,GAAM,GAAhB,KAAsB,CAAC,CAA1B,EAA4B;AAAC,YAAK,gBAAcA,CAAd,GAAgB,4BAArB;AAAkD;AAAC,OAAGA,KAAG,MAAH,IAAWoH,MAAI,IAAlB,EAAuB;AAAC,UAAK,mCAAL;AAAyC,OAAG,OAAOA,CAAP,IAAU,QAAV,IAAoBA,EAAEjC,OAAF,CAAU,aAAV,KAA0B,CAAC,CAAlD,EAAoD;AAACiC,QAAE4lB,QAAQC,MAAR,CAAe7lB,CAAf,CAAF;AAAoB,OAAGJ,KAAG,IAAH,IAASA,KAAG,IAAf,EAAoB;AAAC,QAAG,EAAEI,aAAapF,CAAf,CAAH,EAAqB;AAAC,YAAK,gDAAL;AAAsD;AAAC,OAAGgF,KAAG,IAAN,EAAW;AAAC,QAAG,EAAEI,aAAa9G,CAAf,CAAH,EAAqB;AAAC,YAAK,uCAAL;AAA6C;AAAC,OAAGN,KAAG,MAAN,EAAa,CAAE,KAAI0D,IAAE,IAAN,CAAW,IAAGpC,EAAEk5B,aAAF,CAAgBz6B,EAAEsqB,GAAlB,MAAyBzrB,SAA5B,EAAsC;AAAC,UAAK,2BAAyBoB,CAA9B;AAAgC,GAAvE,MAA2E;AAAC0D,QAAEpC,EAAEk5B,aAAF,CAAgBx6B,CAAhB,CAAF;AAAqB,OAAG0D,KAAG,MAAN,EAAa;AAAC,UAAK,eAAL;AAAqB,GAAnC,MAAuC;AAAC,QAAGA,EAAEpB,MAAF,CAAS,CAAT,EAAW,CAAX,KAAe,MAAlB,EAAyB;AAAC,UAAI/B,IAAE,IAAN,CAAW,IAAG6G,MAAIxI,SAAP,EAAiB;AAAC,cAAK,6CAAL;AAAmD,WAAIgB,IAAE,IAAI4B,CAAJ,CAAM,EAAC6oB,KAAI3mB,CAAL,EAAOwoB,MAAK9kB,CAAZ,EAAN,CAAN,CAA4BxH,EAAEwrB,YAAF,CAAe1rB,CAAf,EAAkBa,IAAEX,EAAEusB,OAAF,EAAF,CAAc,OAAOllB,KAAG1G,CAAV;AAAY,KAAlL,MAAsL;AAAC,UAAGmD,EAAEyB,OAAF,CAAU,WAAV,KAAwB,CAAC,CAA5B,EAA8B;AAAC,YAAInG,IAAE,IAAN,CAAW,IAAG;AAACA,cAAEsB,EAAE2wB,kBAAF,CAAqBhqB,CAArB,CAAF;AAA0B,SAA9B,CAA8B,OAAMxD,CAAN,EAAQ;AAAC,iBAAO,KAAP;AAAa,aAAI1E,IAAE,IAAII,CAAJ,CAAM,EAACkrB,KAAI3mB,CAAL,EAAN,CAAN,CAAqB3E,EAAE2B,IAAF,CAAO0G,CAAP,EAAUrI,EAAEqsB,YAAF,CAAe1rB,CAAf,EAAkB,OAAOX,EAAEkvB,MAAF,CAASjvB,CAAT,CAAP;AAAmB,OAAlK,MAAsK;AAAC,YAAID,IAAE,IAAII,CAAJ,CAAM,EAACkrB,KAAI3mB,CAAL,EAAN,CAAN,CAAqB3E,EAAE2B,IAAF,CAAO0G,CAAP,EAAUrI,EAAEqsB,YAAF,CAAe1rB,CAAf,EAAkB,OAAOX,EAAEkvB,MAAF,CAAShnB,CAAT,CAAP;AAAmB;AAAC;AAAC;AAAC,CAA79C,CAA89CgQ,KAAKyiB,GAAL,CAASC,GAAT,CAAav3B,KAAb,GAAmB,UAASrD,CAAT,EAAW;AAAC,MAAIW,IAAEX,EAAEqf,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAI5e,IAAE,EAAN,CAAS,IAAIP,CAAJ,EAAMQ,CAAN,EAAQN,CAAR,CAAU,IAAGO,EAAEI,MAAF,IAAU,CAAV,IAAaJ,EAAEI,MAAF,IAAU,CAA1B,EAA4B;AAAC,UAAK,uDAAL;AAA6D,OAAEJ,EAAE,CAAF,CAAF,CAAOD,IAAEC,EAAE,CAAF,CAAF,CAAO,IAAGA,EAAEI,MAAF,IAAU,CAAb,EAAe;AAACX,QAAEO,EAAE,CAAF,CAAF;AAAO,KAAEg7B,SAAF,GAAYzjB,KAAKyiB,GAAL,CAASC,GAAT,CAAaY,kBAAb,CAAgC/V,WAAWvlB,CAAX,CAAhC,CAAZ,CAA2DO,EAAEm7B,UAAF,GAAa1jB,KAAKyiB,GAAL,CAASC,GAAT,CAAaY,kBAAb,CAAgC/V,WAAW/kB,CAAX,CAAhC,CAAb,CAA4DD,EAAEo7B,QAAF,GAAWnX,KAAKriB,SAAL,CAAe5B,EAAEk7B,SAAjB,EAA2B,IAA3B,EAAgC,IAAhC,CAAX,CAAiD,IAAGl7B,EAAEm7B,UAAF,IAAc,IAAjB,EAAsB;AAACn7B,MAAEq7B,SAAF,GAAYrW,WAAW/kB,CAAX,CAAZ;AAA0B,GAAjD,MAAqD;AAACD,MAAEq7B,SAAF,GAAYpX,KAAKriB,SAAL,CAAe5B,EAAEm7B,UAAjB,EAA4B,IAA5B,EAAiC,IAAjC,CAAZ;AAAmD,OAAGx7B,MAAIP,SAAP,EAAiB;AAACY,MAAEs7B,MAAF,GAASxW,UAAUnlB,CAAV,CAAT;AAAsB,UAAOK,CAAP;AAAS,CAAtgB,CAAugByX,KAAKyiB,GAAL,CAASC,GAAT,CAAaoB,SAAb,GAAuB,UAASt7B,CAAT,EAAWM,CAAX,EAAa2B,CAAb,EAAe;AAAC,MAAIvC,IAAE8X,IAAN;AAAA,MAAWrX,IAAET,EAAEu6B,GAAf;AAAA,MAAmBn5B,IAAEX,EAAE+5B,GAAvB;AAAA,MAA2Bt5B,IAAEE,EAAEg6B,kBAA/B;AAAA,MAAkDj6B,IAAEC,EAAEy6B,OAAtD;AAAA,MAA8D/7B,IAAEsB,EAAE06B,aAAlE,CAAgF,IAAIj7B,IAAEP,EAAE2e,KAAF,CAAQ,GAAR,CAAN,CAAmB,IAAI1e,IAAEM,EAAE,CAAF,CAAN,CAAW,IAAIH,IAAEG,EAAE,CAAF,CAAN,CAAW,IAAIuB,IAAE7B,IAAE,GAAF,GAAMG,CAAZ,CAAc,IAAImC,IAAEsiB,UAAUtkB,EAAE,CAAF,CAAV,CAAN,CAAsB,IAAIhB,IAAEqB,EAAEmkB,WAAW9kB,CAAX,CAAF,CAAN,CAAuB,IAAIX,IAAEsB,EAAEmkB,WAAW3kB,CAAX,CAAF,CAAN,CAAuB,IAAGb,EAAEqrB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,WAAO,KAAP;AAAa,OAAG8C,EAAE2oB,GAAF,KAAQzrB,SAAX,EAAqB;AAAC,UAAK,oCAAL;AAA0C,OAAG,CAAC0B,EAAEtB,EAAEqrB,GAAJ,EAAQ3oB,EAAE2oB,GAAV,CAAJ,EAAmB;AAAC,WAAO,KAAP;AAAa,OAAGtrB,EAAEm8B,GAAF,KAAQt8B,SAAR,IAAmB,QAAO8C,EAAEw5B,GAAT,MAAe,QAArC,EAA8C;AAAC,QAAG,CAAC56B,EAAEvB,EAAEm8B,GAAJ,EAAQx5B,EAAEw5B,GAAV,CAAJ,EAAmB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGn8B,EAAEo8B,GAAF,KAAQv8B,SAAR,IAAmB,QAAO8C,EAAEy5B,GAAT,MAAe,QAArC,EAA8C;AAAC,QAAG,CAAC76B,EAAEvB,EAAEo8B,GAAJ,EAAQz5B,EAAEy5B,GAAV,CAAJ,EAAmB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGp8B,EAAEq8B,GAAF,KAAQx8B,SAAR,IAAmB,QAAO8C,EAAE05B,GAAT,MAAe,QAArC,EAA8C;AAAC,QAAG,OAAOr8B,EAAEq8B,GAAT,IAAc,QAAjB,EAA0B;AAAC,UAAG,CAAC96B,EAAEvB,EAAEq8B,GAAJ,EAAQ15B,EAAE05B,GAAV,CAAJ,EAAmB;AAAC,eAAO,KAAP;AAAa;AAAC,KAA7D,MAAiE;AAAC,UAAG,QAAOr8B,EAAEq8B,GAAT,KAAc,QAAjB,EAA0B;AAAC,YAAG,CAACn8B,EAAEF,EAAEq8B,GAAJ,EAAQ15B,EAAE05B,GAAV,CAAJ,EAAmB;AAAC,iBAAO,KAAP;AAAa;AAAC;AAAC;AAAC,OAAI57B,IAAEI,EAAEy7B,OAAF,CAAUC,MAAV,EAAN,CAAyB,IAAG55B,EAAE65B,QAAF,KAAa38B,SAAb,IAAwB,OAAO8C,EAAE65B,QAAT,KAAoB,QAA/C,EAAwD;AAAC/7B,QAAEkC,EAAE65B,QAAJ;AAAa,OAAG75B,EAAE85B,WAAF,KAAgB58B,SAAhB,IAA2B,OAAO8C,EAAE85B,WAAT,KAAuB,QAArD,EAA8D;AAAC95B,MAAE85B,WAAF,GAAc,CAAd;AAAgB,OAAGz8B,EAAEoP,GAAF,KAAQvP,SAAR,IAAmB,OAAOG,EAAEoP,GAAT,IAAc,QAApC,EAA6C;AAAC,QAAGpP,EAAEoP,GAAF,GAAMzM,EAAE85B,WAAR,GAAoBh8B,CAAvB,EAAyB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGT,EAAE08B,GAAF,KAAQ78B,SAAR,IAAmB,OAAOG,EAAE08B,GAAT,IAAc,QAApC,EAA6C;AAAC,QAAGj8B,IAAET,EAAE08B,GAAF,GAAM/5B,EAAE85B,WAAb,EAAyB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGz8B,EAAE28B,GAAF,KAAQ98B,SAAR,IAAmB,OAAOG,EAAE28B,GAAT,IAAc,QAApC,EAA6C;AAAC,QAAGl8B,IAAET,EAAE28B,GAAF,GAAMh6B,EAAE85B,WAAb,EAAyB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAGz8B,EAAE48B,GAAF,KAAQ/8B,SAAR,IAAmB8C,EAAEi6B,GAAF,KAAQ/8B,SAA9B,EAAwC;AAAC,QAAGG,EAAE48B,GAAF,KAAQj6B,EAAEi6B,GAAb,EAAiB;AAAC,aAAO,KAAP;AAAa;AAAC,OAAG,CAACp7B,EAAE0tB,MAAF,CAASxuB,CAAT,EAAWM,CAAX,EAAa2B,EAAE2oB,GAAf,CAAJ,EAAwB;AAAC,WAAO,KAAP;AAAa,UAAO,IAAP;AAAY,CAAnvC,CAAovCpT,KAAKyiB,GAAL,CAASC,GAAT,CAAasB,aAAb,GAA2B,UAASz7B,CAAT,EAAWS,CAAX,EAAa;AAAC,MAAIP,IAAEuX,KAAKyiB,GAAL,CAASC,GAAT,CAAaqB,OAAnB,CAA2B,IAAGx7B,MAAI,IAAP,EAAY;AAAC,WAAO,KAAP;AAAa,OAAG,QAAOA,CAAP,yCAAOA,CAAP,OAAW,QAAd,EAAuB;AAAC,WAAO,KAAP;AAAa,OAAG,OAAOA,EAAEM,MAAT,KAAkB,QAArB,EAA8B;AAAC,WAAO,KAAP;AAAa,QAAI,IAAIX,IAAE,CAAV,EAAYA,IAAEK,EAAEM,MAAhB,EAAuBX,GAAvB,EAA2B;AAAC,QAAG,CAACO,EAAEF,EAAEL,CAAF,CAAF,EAAOc,CAAP,CAAJ,EAAc;AAAC,aAAO,KAAP;AAAa;AAAC,UAAO,IAAP;AAAY,CAApP,CAAqPgX,KAAKyiB,GAAL,CAASC,GAAT,CAAaqB,OAAb,GAAqB,UAAS77B,CAAT,EAAWK,CAAX,EAAa;AAAC,MAAGA,MAAI,IAAP,EAAY;AAAC,WAAO,KAAP;AAAa,OAAG,QAAOA,CAAP,yCAAOA,CAAP,OAAW,QAAd,EAAuB;AAAC,WAAO,KAAP;AAAa,OAAG,OAAOA,EAAEM,MAAT,KAAkB,QAArB,EAA8B;AAAC,WAAO,KAAP;AAAa,QAAI,IAAIJ,IAAE,CAAV,EAAYA,IAAEF,EAAEM,MAAhB,EAAuBJ,GAAvB,EAA2B;AAAC,QAAGF,EAAEE,CAAF,KAAMP,CAAT,EAAW;AAAC,aAAO,IAAP;AAAY;AAAC,UAAO,KAAP;AAAa,CAAhN,CAAiN8X,KAAKyiB,GAAL,CAASC,GAAT,CAAaa,aAAb,GAA2B,EAACoB,OAAM,YAAP,EAAoBC,OAAM,YAA1B,EAAuCC,OAAM,YAA7C,EAA0DC,OAAM,eAAhE,EAAgFC,OAAM,eAAtF,EAAsGC,OAAM,eAA5G,EAA4HC,OAAM,iBAAlI,EAAoJC,OAAM,iBAA1J,EAA4KC,OAAM,sBAAlL,EAAyMC,OAAM,sBAA/M,EAAsOC,OAAM,sBAA5O,EAAmQC,MAAK,MAAxQ,EAA3B,CAA4StlB,KAAKyiB,GAAL,CAASC,GAAT,CAAaC,gBAAb,GAA8B,UAASl6B,CAAT,EAAWF,CAAX,EAAaL,CAAb,EAAe;AAAC,MAAIM,IAAE,IAAN,CAAW,IAAG;AAACA,QAAEqc,UAAUpc,CAAV,CAAF,CAAe,IAAG,QAAOD,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC,aAAO,CAAP;AAAS,SAAGA,EAAEJ,WAAF,KAAgBmJ,KAAnB,EAAyB;AAAC,aAAO,CAAP;AAAS,SAAGhJ,CAAH,EAAK;AAACA,QAAEL,CAAF,IAAKM,CAAL;AAAO,YAAO,CAAP;AAAS,GAA5G,CAA4G,OAAMQ,CAAN,EAAQ;AAAC,WAAO,CAAP;AAAS;AAAC,CAAxL,CAAyLgX,KAAKyiB,GAAL,CAASC,GAAT,CAAaY,kBAAb,GAAgC,UAAS/6B,CAAT,EAAW;AAAC,MAAIE,IAAE,IAAN,CAAW,IAAG;AAACA,QAAEoc,UAAUtc,CAAV,CAAF,CAAe,IAAG,QAAOE,CAAP,yCAAOA,CAAP,MAAU,QAAb,EAAsB;AAAC,aAAO,IAAP;AAAY,SAAGA,EAAEL,WAAF,KAAgBmJ,KAAnB,EAAyB;AAAC,aAAO,IAAP;AAAY,YAAO9I,CAAP;AAAS,GAArG,CAAqG,OAAMO,CAAN,EAAQ;AAAC,WAAO,IAAP;AAAY;AAAC,CAAlL,CAAmLgX,KAAKyiB,GAAL,CAASC,GAAT,CAAa6C,+BAAb,GAA6C,UAASh9B,CAAT,EAAW;AAAC,MAAIS,IAAET,EAAEwc,KAAF,CAAQ,yBAAR,CAAN,CAAyC,IAAG/b,KAAG,IAAN,EAAW;AAAC,UAAK,yDAAL;AAA+D,UAAOA,EAAE,CAAF,CAAP;AAAY,CAAzL,CAA0LgX,KAAKyiB,GAAL,CAASC,GAAT,CAAa8C,gBAAb,GAA8B,UAASt9B,CAAT,EAAW;AAAC,MAAGA,EAAE20B,GAAF,KAAQ,KAAR,IAAe30B,EAAE20B,GAAF,KAAQ,IAAvB,IAA6B30B,EAAE20B,GAAF,KAAQ,KAAxC,EAA8C;AAAC,UAAK,yCAAL;AAA+C,OAAI7zB,IAAE,GAAN,CAAU,IAAGd,EAAE20B,GAAF,KAAQ,KAAX,EAAiB;AAAC,QAAG,OAAO30B,EAAEkB,CAAT,IAAY,QAAZ,IAAsB,OAAOlB,EAAEM,CAAT,IAAY,QAArC,EAA8C;AAAC,YAAK,iCAAL;AAAuC,UAAG,UAAQN,EAAEM,CAAV,GAAY,IAAf,CAAoBQ,KAAG,YAAUd,EAAE20B,GAAZ,GAAgB,IAAnB,CAAwB7zB,KAAG,UAAQd,EAAEkB,CAAV,GAAY,IAAf;AAAoB,GAAxK,MAA4K;AAAC,QAAGlB,EAAE20B,GAAF,KAAQ,IAAX,EAAgB;AAAC,UAAG,OAAO30B,EAAEk1B,GAAT,IAAc,QAAd,IAAwB,OAAOl1B,EAAEoE,CAAT,IAAY,QAApC,IAA8C,OAAOpE,EAAE+H,CAAT,IAAY,QAA7D,EAAsE;AAAC,cAAK,qCAAL;AAA2C,YAAG,YAAU/H,EAAEk1B,GAAZ,GAAgB,IAAnB,CAAwBp0B,KAAG,YAAUd,EAAE20B,GAAZ,GAAgB,IAAnB,CAAwB7zB,KAAG,UAAQd,EAAEoE,CAAV,GAAY,IAAf,CAAoBtD,KAAG,UAAQd,EAAE+H,CAAV,GAAY,IAAf;AAAoB,KAA3N,MAA+N;AAAC,UAAG/H,EAAE20B,GAAF,KAAQ,KAAX,EAAiB;AAAC,YAAG,OAAO30B,EAAEa,CAAT,IAAY,QAAf,EAAwB;AAAC,gBAAK,sCAAL;AAA4C,cAAG,YAAUb,EAAE20B,GAAZ,GAAgB,IAAnB,CAAwB7zB,KAAG,UAAQd,EAAEa,CAAV,GAAY,IAAf;AAAoB;AAAC;AAAC,OAAIR,IAAEgY,UAAUvX,CAAV,CAAN,CAAmB,IAAIP,IAAEuX,KAAKf,MAAL,CAAYiB,IAAZ,CAAiBI,OAAjB,CAAyB/X,CAAzB,EAA2B,QAA3B,CAAN,CAA2C,IAAIC,IAAE4kB,UAAU3kB,CAAV,CAAN,CAAmB,OAAOD,CAAP;AAAS,CAA9vB,CAA+vBwX,KAAKyiB,GAAL,CAAS2B,OAAT,GAAiB,EAAjB,CAAoBpkB,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBqB,GAAjB,GAAqB,UAASh9B,CAAT,EAAW;AAAC,MAAIF,IAAEyX,KAAKyiB,GAAL,CAAS2B,OAAf;AAAA,MAAuBl8B,IAAEK,EAAE87B,MAA3B;AAAA,MAAkCr7B,IAAET,EAAEm9B,OAAtC,CAA8C,IAAGj9B,KAAG,KAAN,EAAY;AAAC,WAAOP,GAAP;AAAW,GAAxB,MAA4B;AAAC,QAAGO,KAAG,aAAN,EAAoB;AAAC,aAAOP,MAAI,KAAG,EAAd;AAAiB,KAAtC,MAA0C;AAAC,UAAGO,KAAG,YAAN,EAAmB;AAAC,eAAOP,MAAI,KAAG,EAAH,GAAM,EAAjB;AAAoB,OAAxC,MAA4C;AAAC,YAAGO,KAAG,cAAN,EAAqB;AAAC,iBAAOP,MAAI,KAAG,EAAH,GAAM,EAAN,GAAS,EAApB;AAAuB,SAA7C,MAAiD;AAAC,cAAGO,KAAG,aAAN,EAAoB;AAAC,mBAAOP,MAAI,KAAG,EAAH,GAAM,EAAN,GAAS,GAApB;AAAwB,WAA7C,MAAiD;AAAC,gBAAGO,EAAEsc,KAAF,CAAQ,IAAR,CAAH,EAAiB;AAAC,qBAAO/b,EAAEP,CAAF,CAAP;AAAY,aAA9B,MAAkC;AAAC,kBAAGA,EAAEsc,KAAF,CAAQ,UAAR,CAAH,EAAuB;AAAC,uBAAO3Z,SAAS3C,CAAT,CAAP;AAAmB;AAAC;AAAC;AAAC;AAAC;AAAC;AAAC,SAAK,yBAAuBA,CAA5B;AAA8B,CAA1Z,CAA2ZuX,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBsB,OAAjB,GAAyB,UAAS18B,CAAT,EAAW;AAAC,SAAO0lB,UAAU1lB,CAAV,CAAP;AAAoB,CAAzD,CAA0DgX,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBC,MAAjB,GAAwB,YAAU;AAAC,MAAIr7B,IAAE,CAAC,EAAE,IAAI+V,IAAJ,KAAW,IAAb,CAAP,CAA0B,OAAO/V,CAAP;AAAS,CAAtE,CAAuEgX,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiBuB,iBAAjB,GAAmC,UAAS38B,CAAT,EAAW;AAAC,MAAIT,IAAE,IAAIwW,IAAJ,CAAS/V,IAAE,IAAX,CAAN,CAAuB,OAAOT,EAAEq9B,WAAF,EAAP;AAAuB,CAA7F,CAA8F5lB,KAAKyiB,GAAL,CAAS2B,OAAT,CAAiByB,YAAjB,GAA8B,UAASr9B,CAAT,EAAW;AAAC,MAAII,IAAE,IAAImW,IAAJ,CAASvW,IAAE,IAAX,CAAN;AAAA,MAAuBT,IAAE,CAAC,SAAOa,EAAEimB,cAAF,EAAR,EAA4BjkB,KAA5B,CAAkC,CAAC,CAAnC,CAAzB;AAAA,MAA+D9C,IAAE,CAAC,QAAMc,EAAEkmB,WAAF,KAAgB,CAAtB,CAAD,EAA2BlkB,KAA3B,CAAiC,CAAC,CAAlC,CAAjE;AAAA,MAAsGrC,IAAE,CAAC,OAAKK,EAAEmmB,UAAF,EAAN,EAAsBnkB,KAAtB,CAA4B,CAAC,CAA7B,CAAxG;AAAA,MAAwI5B,IAAE,CAAC,OAAKJ,EAAEomB,WAAF,EAAN,EAAuBpkB,KAAvB,CAA6B,CAAC,CAA9B,CAA1I;AAAA,MAA2KnC,IAAE,CAAC,OAAKG,EAAEqmB,aAAF,EAAN,EAAyBrkB,KAAzB,CAA+B,CAAC,CAAhC,CAA7K;AAAA,MAAgN5C,IAAE,CAAC,OAAKY,EAAEsmB,aAAF,EAAN,EAAyBtkB,KAAzB,CAA+B,CAAC,CAAhC,CAAlN,CAAqP,OAAO7C,IAAED,CAAF,GAAIS,CAAJ,GAAMS,CAAN,GAAQP,CAAR,GAAUT,CAAV,GAAY,GAAnB;AAAuB,CAAtT;QACt4PyX,Y,GAAAA,Y;QACAX,a,GAAAA,a;QAEAnN,U,GAAAA,U;QACA6O,M,GAAAA,M;IACMslB,I,GAAS9lB,KAAKf,M,CAAd6mB,I;;IACAhP,G,GAAQ9W,KAAKf,M,CAAb6X,G;;IACApB,S,GAAc1V,KAAKf,M,CAAnByW,S;;IACAzV,a,GAAmBD,KAAKf,M,CAAxBgB,a;;IACA6U,G,GAAQ9U,KAAKf,M,CAAb6V,G;;IACA4C,M,GAAY1X,KAAKf,M,CAAjByY,M;;QACN3B,O,GAAAA,O;QACA3K,O,GAAAA,O;QACAiS,I,GAAAA,I;QACAp0B,Q,GAAAA,Q;;AAET;;QACSmI,Q,GAAAA,Q;QACAE,O,GAAAA,O;;AAET;;QACSsb,K,GAAAA,K;QACAC,K,GAAAA,K;QACAC,O,GAAAA,O;QACA5D,M,GAAAA,M;QACA6D,M,GAAAA,M;QACAC,O,GAAAA,O;QACAE,O,GAAAA,O;QACAD,S,GAAAA,S;QACAE,S,GAAAA,S;QACAjc,O,GAAAA,O;QACAkc,S,GAAAA,S;QACAC,S,GAAAA,S;QACAC,U,GAAAA,U;QACAC,U,GAAAA,U;QACAK,S,GAAAA,S;QACAC,S,GAAAA,S;QACA7F,S,GAAAA,S;QACAsE,S,GAAAA,S;QACAjM,S,GAAAA,S;QACAE,S,GAAAA,S;QACAuN,Q,GAAAA,Q;QACAC,U,GAAAA,U;QACAC,U,GAAAA,U;QACAzI,Q,GAAAA,Q;QACA0I,Q,GAAAA,Q;QACAC,gB,GAAAA,gB;QACAI,gB,GAAAA,gB;QACAG,U,GAAAA,U;QACAC,S,GAAAA,S;QACAC,U,GAAAA,U;QACAC,U,GAAAA,U;QACAnB,W,GAAAA,W;QACAE,W,GAAAA,W;QACAyB,S,GAAAA,S;QACAE,S,GAAAA,S;QACAC,O,GAAAA,O;QACAC,O,GAAAA,O;QACA9B,qB,GAAAA,qB;QACA+B,c,GAAAA,c;QACAC,a,GAAAA,a;QACAK,W,GAAAA,W;QACAC,c,GAAAA,c;QACAE,U,GAAAA,U;;AAET;;QACSlQ,I,GAAAA,I;;AACT,IAAM+lB,UAAW/lB,KAAKf,MAAtB;QACoBA,M,GAAX8mB,O;YACe/lB,I;IAATkF,I,SAAAA,I;;aACQlF,I;IAARyiB,G,UAAAA,G;;aACSziB,I;IAATpY,I,UAAAA,I;;;;;;;;;;;;;;AC1Lf,8CAAa;;AAEb,mBAAO,CAAC,oDAAc;;AAEtB,mBAAO,CAAC,8GAA6B;;AAErC,mBAAO,CAAC,4EAA0B;;AAElC;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;AAEA;AACA;;AAEA;AACA;AACA,CAAC,E;;;;;;;;;;;;AC3BD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,gBAAgB;AAChB;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,cAAc;AACd,KAAK;AACL,cAAc;AACd;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,yDAAyD;AACzD;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,YAAY;AACZ;;AAEA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA,WAAW;AACX;AACA,WAAW;AACX;;AAEA;AACA;AACA,wCAAwC,WAAW;AACnD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;;AAEA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA,SAAS;AACT;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA,2BAA2B;AAC3B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,SAAS;AACT;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA,SAAS;AACT;AACA;AACA;AACA;;AAEA;;AAEA,SAAS;AACT;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,oCAAoC,cAAc;AAClD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,KAAK;AACL;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA,iCAAiC,kBAAkB;AACnD;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,iBAAiB;;AAEjB;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,wBAAwB,iBAAiB;AACzC;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,YAAY;AACZ;AACA;;AAEA;AACA,YAAY;AACZ;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;;AAEL;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA,KAAK;;AAEL;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA,8CAA8C,QAAQ;AACtD;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA,aAAa;AACb;AACA;;AAEA,WAAW;AACX;AACA;AACA;;AAEA,WAAW;AACX;AACA;AACA;;AAEA,WAAW;AACX;AACA;AACA;AACA;AACA,KAAK;;AAEL;AACA,8CAA8C,QAAQ;AACtD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA,KAAK;;AAEL;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA,OAAO;AACP;AACA;;AAEA;AACA,KAAK;;AAEL;AACA,8CAA8C,QAAQ;AACtD;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;;AAEL;AACA,8CAA8C,QAAQ;AACtD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;;AAEL;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;;AC/tBY;;AAEZ;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,kCAAkC,SAAS;AAC3C;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;;AAEA;AACA;AACA;AACA;;AAEA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,0CAA0C,UAAU;AACpD;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;;;;;;;;;;;;ACtJA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEY;;AAEZ,aAAa,mBAAO,CAAC,oDAAW;AAChC,cAAc,mBAAO,CAAC,gDAAS;AAC/B,cAAc,mBAAO,CAAC,oEAAS;;AAE/B;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,qBAAqB,mDAAmD;AACxE;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,mBAAmB,UAAU;AAC7B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,YAAY;AAC7B;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,0BAA0B;AAC1B;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA,uCAAuC,SAAS;AAChD;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA,eAAe,iBAAiB;AAChC;AACA;AACA;;AAEA;AACA;AACA,aAAa,iBAAiB;AAC9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,gDAAgD,EAAE;AAClD;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA,iBAAiB,SAAS;AAC1B;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,yCAAyC;AACzC;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;;AAEA;AACA;AACA;AACA,wBAAwB,eAAe;AACvC;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA,GAAG;AACH;AACA,wBAAwB,QAAQ;AAChC;AACA,qBAAqB,eAAe;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,YAAY;AAC7B;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;;AAEA;AACA,SAAS;AACT;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA,qBAAqB,SAAS;AAC9B;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,kBAAkB;AACnC;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,mBAAmB,cAAc;AACjC;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,uDAAuD,OAAO;AAC9D;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA,uDAAuD,OAAO;AAC9D;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,kBAAkB;AAClB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,qBAAqB,QAAQ;AAC7B;AACA;AACA,GAAG;AACH;AACA,eAAe,SAAS;AACxB;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA,mBAAmB,SAAS;AAC5B;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,eAAe,iBAAiB;AAChC;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA,iBAAiB,YAAY;AAC7B;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,KAAK;AACL;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA,iBAAiB,gBAAgB;AACjC;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,iBAAiB,gBAAgB;AACjC;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,iBAAiB,YAAY;AAC7B;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;AC5vDA,iBAAiB;;AAEjB;AACA;AACA;;;;;;;;;;;;ACJA,mBAAO,CAAC,8FAAkC;AAC1C,iBAAiB,mBAAO,CAAC,oEAAqB;;;;;;;;;;;;ACD9C;AACA;AACA;AACA;;;;;;;;;;;;ACHA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;AACA;;;;;;;;;;;;ACJA;AACA,kBAAkB,mBAAO,CAAC,sDAAQ;AAClC;AACA,0CAA0C,mBAAO,CAAC,wDAAS,6BAA6B;AACxF;AACA;AACA;;;;;;;;;;;;;ACNa;AACb,SAAS,mBAAO,CAAC,kEAAc;;AAE/B;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACPA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACJA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;;;;;;;;;;;;;ACJA;AACa;AACb,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;;ACzBA;AACa;AACb,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACdA,YAAY,mBAAO,CAAC,4DAAW;;AAE/B;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACNA;AACA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK,YAAY,eAAe;AAChC;AACA,KAAK;AACL;AACA;;;;;;;;;;;;ACtBA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,wFAAyB;AAC3C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,eAAe;AACzB;AACA;AACA;AACA,wCAAwC;AACxC;AACA,8BAA8B;AAC9B,6BAA6B;AAC7B,+BAA+B;AAC/B,mCAAmC;AACnC,SAAS,iCAAiC;AAC1C;AACA;AACA;AACA;AACA;;;;;;;;;;;;AC3CA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,uBAAuB;AACvB;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,QAAQ,sCAAsC;AAC9C;AACA;AACA;AACA;;;;;;;;;;;;AC3BA,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,gEAAa;AACnC,cAAc,mBAAO,CAAC,sDAAQ;;AAE9B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACfA;AACA,yBAAyB,mBAAO,CAAC,kGAA8B;;AAE/D;AACA;AACA;;;;;;;;;;;;;ACLa;AACb,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA;;AAEA;AACA;AACA,2BAA2B,SAAS;AACpC;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACxBA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA,2BAA2B,kBAAkB,EAAE;;AAE/C;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACtBA,iBAAiB;;AAEjB;AACA;AACA;;;;;;;;;;;;;ACJa;AACb,SAAS,mBAAO,CAAC,kEAAc;AAC/B,aAAa,mBAAO,CAAC,0EAAkB;AACvC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,YAAY,mBAAO,CAAC,4DAAW;AAC/B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,WAAW,mBAAO,CAAC,kEAAc;AACjC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,cAAc,mBAAO,CAAC,wDAAS;AAC/B,eAAe,mBAAO,CAAC,sFAAwB;AAC/C;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,uBAAuB,OAAO;AAC9B;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,qBAAqB;AACrB,6BAA6B;AAC7B,0BAA0B;AAC1B,0BAA0B;AAC1B,qBAAqB;AACrB;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,8EAA8E,OAAO;AACrF;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,yCAAyC;AACzC,qBAAqB;AACrB,0BAA0B;AAC1B,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;;AAEL;AACA;AACA;AACA;;;;;;;;;;;;AC/IA;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC,WAAW,mBAAO,CAAC,sFAAwB;AAC3C;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACRa;AACb,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,cAAc,mBAAO,CAAC,wDAAS;AAC/B,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,YAAY,mBAAO,CAAC,4DAAW;AAC/B,wBAAwB,mBAAO,CAAC,0EAAkB;AAClD,WAAW,mBAAO,CAAC,sDAAQ;AAC3B,eAAe,mBAAO,CAAC,sFAAwB;AAC/C;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,qBAAqB;AACrB,qBAAqB;AACrB,0BAA0B;AAC1B;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;;;;;;;;;;;;;ACpFa;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,gEAAa;AACpC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,WAAW,mBAAO,CAAC,wDAAS;AAC5B,YAAY,mBAAO,CAAC,4DAAW;AAC/B,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,eAAe,mBAAO,CAAC,kEAAc;AACrC,YAAY,mBAAO,CAAC,0DAAU;AAC9B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD,wBAAwB,mBAAO,CAAC,sFAAwB;;AAExD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA,OAAO;AACP;AACA,OAAO,mCAAmC,gCAAgC,aAAa;AACvF,8BAA8B,mCAAmC,aAAa;AAC9E;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,qDAAqD;AACrD;AACA,kDAAkD,iBAAiB,EAAE;AACrE;AACA,wDAAwD,aAAa,EAAE,EAAE;AACzE;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;;AAEA;;AAEA;AACA;;;;;;;;;;;;ACpFA,6BAA6B;AAC7B,uCAAuC;;;;;;;;;;;;;ACD1B;AACb,sBAAsB,mBAAO,CAAC,kEAAc;AAC5C,iBAAiB,mBAAO,CAAC,0EAAkB;;AAE3C;AACA;AACA;AACA;;;;;;;;;;;;ACPA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACnBa;AACb;AACA,YAAY,mBAAO,CAAC,0DAAU;AAC9B;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA,CAAC;AACD;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACzBY;AACb,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C;;AAEA;AACA;AACA;AACA;;;;;;;;;;;;ACRA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACJA;AACA,kBAAkB,mBAAO,CAAC,0DAAU;AACpC,iCAAiC,QAAQ,mBAAmB,UAAU,EAAE,EAAE;AAC1E,CAAC;;;;;;;;;;;;ACHD,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,4DAAW;AAClC;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACNA;AACA;AACA;AACA;;;;;;;;;;;;ACHA;AACA,cAAc,mBAAO,CAAC,sEAAgB;AACtC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,UAAU,mBAAO,CAAC,oEAAe;AACjC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACdA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,WAAW,mBAAO,CAAC,wDAAS;AAC5B,eAAe,mBAAO,CAAC,gEAAa;AACpC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,kFAAkF,uBAAuB;AACzG,iEAAiE;AACjE,+DAA+D;AAC/D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,cAAc;AACd,cAAc;AACd,cAAc;AACd,cAAc;AACd,eAAe;AACf,eAAe;AACf,eAAe;AACf,gBAAgB;AAChB;;;;;;;;;;;;AC1CA,YAAY,mBAAO,CAAC,sDAAQ;AAC5B;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA,KAAK,YAAY;AACjB,GAAG;AACH;;;;;;;;;;;;ACXA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;;;;;;;;;;;;ACNa;AACb,mBAAO,CAAC,4EAAmB;AAC3B,eAAe,mBAAO,CAAC,gEAAa;AACpC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,YAAY,mBAAO,CAAC,0DAAU;AAC9B,cAAc,mBAAO,CAAC,8DAAY;AAClC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,iBAAiB,mBAAO,CAAC,sEAAgB;;AAEzC;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,qBAAqB;AACrB;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;AACA;AACA,yBAAyB,4CAA4C;AACrE;AACA;AACA,CAAC;;AAED;AACA;;AAEA;AACA;AACA;AACA,6BAA6B,UAAU;AACvC;AACA,GAAG;;AAEH;AACA;AACA;AACA;AACA,2BAA2B,mBAAmB,aAAa;AAC3D;AACA;AACA;AACA;AACA,6CAA6C,WAAW;AACxD;AACA;AACA;AACA,GAAG;;AAEH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oBAAoB;AACpB;AACA,kBAAkB;AAClB;AACA,gBAAgB;AAChB;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,gCAAgC,qCAAqC;AACrE;AACA;AACA,2BAA2B,gCAAgC;AAC3D;AACA;AACA;;;;;;;;;;;;;AC/Fa;AACb;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACZa;AACb;AACA,cAAc,mBAAO,CAAC,gEAAa;AACnC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,2BAA2B,mBAAO,CAAC,sDAAQ;;AAE3C;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,OAAO;AACP;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;ACtCA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,WAAW,mBAAO,CAAC,kEAAc;AACjC,kBAAkB,mBAAO,CAAC,0EAAkB;AAC5C,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,8FAA4B;AACpD;AACA;AACA;AACA,uCAAuC,iBAAiB,EAAE;AAC1D;AACA;AACA;AACA;AACA;AACA,mEAAmE,gBAAgB;AACnF;AACA;AACA,GAAG,4CAA4C,gCAAgC;AAC/E;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACxBA,iBAAiB,mBAAO,CAAC,4DAAW;;;;;;;;;;;;ACApC;AACA;AACA;AACA;AACA;AACA,yCAAyC;;;;;;;;;;;;ACLzC,uBAAuB;AACvB;AACA;AACA;;;;;;;;;;;;ACHA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC;AACA,CAAC;AACD;AACA;AACA;;;;;;;;;;;;ACPA,eAAe,mBAAO,CAAC,4DAAW;AAClC;;;;;;;;;;;;ACDA,kBAAkB,mBAAO,CAAC,sEAAgB,MAAM,mBAAO,CAAC,0DAAU;AAClE,+BAA+B,mBAAO,CAAC,oEAAe,gBAAgB,mBAAmB,UAAU,EAAE,EAAE;AACvG,CAAC;;;;;;;;;;;;ACFD,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,kEAAc;AAC3C;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACRA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACfA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;AACA;;;;;;;;;;;;ACLA;AACA,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,eAAe,mBAAO,CAAC,sDAAQ;AAC/B;;AAEA;AACA;AACA;;;;;;;;;;;;ACPA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;;;;;;;;;;;ACJA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;;;;;;;;;;;;ACLA;AACA;AACA;;;;;;;;;;;;ACFA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,YAAY,mBAAO,CAAC,sDAAQ;AAC5B;AACA;AACA;AACA;;;;;;;;;;;;ACPA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACXa;AACb,aAAa,mBAAO,CAAC,0EAAkB;AACvC,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD;;AAEA;AACA,mBAAO,CAAC,wDAAS,qBAAqB,mBAAO,CAAC,sDAAQ,4BAA4B,aAAa,EAAE;;AAEjG;AACA,qDAAqD,4BAA4B;AACjF;AACA;;;;;;;;;;;;;ACZa;AACb,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,gEAAa;AACpC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,eAAe,mBAAO,CAAC,sDAAQ;AAC/B,8CAA8C;AAC9C;AACA;AACA;;AAEA,8BAA8B,aAAa;;AAE3C;AACA;AACA;AACA;AACA;AACA,yCAAyC,oCAAoC;AAC7E,6CAA6C,oCAAoC;AACjF,KAAK,4BAA4B,oCAAoC;AACrE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,gBAAgB,mBAAmB;AACnC;AACA;AACA,kCAAkC,2BAA2B;AAC7D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;;;;;;;;;;;;ACpEA,eAAe,mBAAO,CAAC,sDAAQ;AAC/B;;AAEA;AACA;AACA,iCAAiC,qBAAqB;AACtD;AACA,iCAAiC,SAAS,EAAE;AAC5C,CAAC,YAAY;;AAEb;AACA;AACA;AACA;AACA;AACA;AACA,6BAA6B,SAAS,qBAAqB;AAC3D,iCAAiC,aAAa;AAC9C;AACA,GAAG,YAAY;AACf;AACA;;;;;;;;;;;;ACrBA;AACA,UAAU;AACV;;;;;;;;;;;;ACFA;;;;;;;;;;;;ACAA;;;;;;;;;;;;ACAA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,WAAW,mBAAO,CAAC,kEAAc;AACjC;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACtBA;AACA;AACA;AACA;;;;;;;;;;;;ACHA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACjBA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACJA,WAAW,mBAAO,CAAC,sDAAQ;AAC3B,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,kEAAc;AACpC;AACA;AACA;AACA;AACA,cAAc,mBAAO,CAAC,0DAAU;AAChC,iDAAiD;AACjD,CAAC;AACD;AACA,qBAAqB;AACrB;AACA,SAAS;AACT,GAAG,EAAE;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACpDA,UAAU,mBAAO,CAAC,4DAAW;AAC7B,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,4DAAW;AAChC,iDAAiD,mBAAO,CAAC,sEAAgB;;AAEzE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,0DAA0D,gBAAgB,EAAE;AAC5E;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AClDA,aAAa,mBAAO,CAAC,4DAAW;AAChC,gBAAgB,mBAAO,CAAC,wDAAS;AACjC;AACA;AACA;AACA,aAAa,mBAAO,CAAC,sDAAQ;;AAE7B;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,uCAAuC,sBAAsB,EAAE;AAC/D;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA,gBAAgB;AAChB;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;;;;;;;;;;;;ACpEa;AACb;AACA,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;ACjBa;AACb;AACA,cAAc,mBAAO,CAAC,sEAAgB;AACtC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,UAAU,mBAAO,CAAC,oEAAe;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,8DAAY;AAClC;;AAEA;AACA,6BAA6B,mBAAO,CAAC,0DAAU;AAC/C;AACA;AACA;AACA;AACA;AACA;AACA,oCAAoC,UAAU,EAAE;AAChD,mBAAmB,sCAAsC;AACzD,CAAC,qCAAqC;AACtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH,CAAC;;;;;;;;;;;;ACjCD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,UAAU,mBAAO,CAAC,oEAAe;AACjC,kBAAkB,mBAAO,CAAC,0EAAkB;AAC5C,eAAe,mBAAO,CAAC,oEAAe;AACtC,yBAAyB;AACzB;;AAEA;AACA;AACA;AACA,eAAe,mBAAO,CAAC,oEAAe;AACtC;AACA;AACA;AACA;AACA;AACA,EAAE,mBAAO,CAAC,wDAAS;AACnB,6BAA6B;AAC7B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;;;;;;;;;;;;ACxCA,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,4EAAmB;AAChD,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C;;AAEA,YAAY,mBAAO,CAAC,sEAAgB;AACpC;AACA;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf;AACA;AACA;AACA;;;;;;;;;;;;ACfA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,sEAAgB;;AAEtC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACZa;AACb;AACA,iBAAiB,mBAAO,CAAC,8DAAY,MAAM,mBAAO,CAAC,0DAAU;AAC7D;AACA;AACA;AACA,8CAA8C,cAAc;AAC5D,SAAS,mBAAO,CAAC,4DAAW;AAC5B,CAAC;;;;;;;;;;;;ACRD,UAAU,mBAAO,CAAC,oEAAe;AACjC,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,qBAAqB,mBAAO,CAAC,4EAAmB;AAChD;;AAEA,YAAY,mBAAO,CAAC,sEAAgB;AACpC;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf;AACA;;;;;;;;;;;;ACfA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,iBAAiB;;AAEjB;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;AClBA;AACA,YAAY,mBAAO,CAAC,wFAAyB;AAC7C,iBAAiB,mBAAO,CAAC,0EAAkB;;AAE3C;AACA;AACA;;;;;;;;;;;;ACNA;;;;;;;;;;;;ACAA;AACA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,oEAAe;AACtC;;AAEA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACZA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,mBAAmB,mBAAO,CAAC,4EAAmB;AAC9C,eAAe,mBAAO,CAAC,oEAAe;;AAEtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AChBA;AACA,YAAY,mBAAO,CAAC,wFAAyB;AAC7C,kBAAkB,mBAAO,CAAC,0EAAkB;;AAE5C;AACA;AACA;;;;;;;;;;;;ACNA,cAAc;;;;;;;;;;;;ACAd;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,YAAY,mBAAO,CAAC,0DAAU;AAC9B;AACA,6BAA6B;AAC7B;AACA;AACA,qDAAqD,OAAO,EAAE;AAC9D;;;;;;;;;;;;ACTA,cAAc,mBAAO,CAAC,sEAAgB;AACtC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,aAAa,mBAAO,CAAC,oEAAe;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;;;;;;;;;;;;ACfA;AACA,WAAW,mBAAO,CAAC,sEAAgB;AACnC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,4DAAW;AACjC;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACTA,kBAAkB,mBAAO,CAAC,4DAAW;AACrC,YAAY,mBAAO,CAAC,sEAAgB;;AAEpC,iCAAiC,mBAAO,CAAC,kEAAc;AACvD;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD,gBAAgB,mBAAO,CAAC,4DAAW;AACnC,YAAY,mBAAO,CAAC,sEAAgB;AACpC,SAAS,mBAAO,CAAC,kEAAc;AAC/B;;AAEA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA;AACA,YAAY;AACZ,GAAG;AACH,YAAY;AACZ;AACA;;;;;;;;;;;;ACNA,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,2BAA2B,mBAAO,CAAC,4FAA2B;;AAE9D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACXA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACPA,eAAe,mBAAO,CAAC,gEAAa;AACpC;AACA;AACA;AACA;;;;;;;;;;;;ACJA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,gBAAgB,mBAAO,CAAC,oFAAuB;AAC/C;AACA;;AAEA,mBAAO,CAAC,wDAAS;AACjB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA;AACA,CAAC;AACD;AACA,CAAC;;;;;;;;;;;;;AC9BY;;AAEb,cAAc,mBAAO,CAAC,8DAAY;AAClC;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACpBa;;AAEb,kBAAkB,mBAAO,CAAC,0DAAU;;AAEpC;AACA;AACA;AACA;AACA;;AAEA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA;;AAEA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,mBAAmB,0BAA0B;AAC7C;AACA;AACA,OAAO;AACP;;AAEA;AACA;AACA;;AAEA;;;;;;;;;;;;ACzDA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;;;;;;;;;;;ACPA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACJa;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,YAAY,mBAAO,CAAC,4DAAW;;AAE/B;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA;AACA,GAAG,EAAE;AACL;;;;;;;;;;;;;AC3Ba;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA,GAAG,EAAE;AACL;;;;;;;;;;;;ACXA;AACA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA,kDAAkD;AAClD;AACA;AACA,cAAc,mBAAO,CAAC,sDAAQ,iBAAiB,mBAAO,CAAC,sEAAgB;AACvE;AACA;AACA,OAAO,YAAY,cAAc;AACjC;AACA;AACA;AACA;AACA;AACA;AACA,KAAK,GAAG;AACR;AACA;;;;;;;;;;;;;ACxBa;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,SAAS,mBAAO,CAAC,kEAAc;AAC/B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,cAAc,mBAAO,CAAC,sDAAQ;;AAE9B;AACA;AACA;AACA;AACA,sBAAsB,aAAa;AACnC,GAAG;AACH;;;;;;;;;;;;ACZA,UAAU,mBAAO,CAAC,kEAAc;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;;AAE1B;AACA,oEAAoE,iCAAiC;AACrG;;;;;;;;;;;;ACNA,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;;;;;;;;;;;ACJA,WAAW,mBAAO,CAAC,wDAAS;AAC5B,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA,kDAAkD;;AAElD;AACA,qEAAqE;AACrE,CAAC;AACD;AACA,QAAQ,mBAAO,CAAC,8DAAY;AAC5B;AACA,CAAC;;;;;;;;;;;;ACXD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,cAAc,mBAAO,CAAC,sDAAQ;AAC9B;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACRa;AACb,YAAY,mBAAO,CAAC,0DAAU;;AAE9B;AACA;AACA;AACA,yCAAyC,cAAc;AACvD,GAAG;AACH;;;;;;;;;;;;ACRA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AChBA,sBAAsB;AACtB,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,8DAAY;;AAElC;AACA;AACA;AACA;;;;;;;;;;;;ACPA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0DAAU;AAC9B,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;AACA;AACA;AACA,0FAA0F;AAC1F;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;AClBA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,aAAa,mBAAO,CAAC,0EAAkB;AACvC,cAAc,mBAAO,CAAC,8DAAY;;AAElC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACfa;AACb,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,cAAc,mBAAO,CAAC,8DAAY;;AAElC;AACA;AACA;AACA;AACA;AACA,QAAQ,MAAM;AACd;AACA;;;;;;;;;;;;ACXA,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,8DAAY;AAClC,YAAY,mBAAO,CAAC,0DAAU;AAC9B,aAAa,mBAAO,CAAC,kEAAc;AACnC;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;AC7BA;AACA;;;;;;;;;;;;ACDA,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,oEAAe;AACjC,aAAa,mBAAO,CAAC,4DAAW;AAChC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,MAAM,mBAAO,CAAC,sDAAQ;AACtB;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACnFA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACNA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACTA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACLA;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;;;;;;;;;;;;ACLA;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;AACA,2DAA2D;AAC3D;;;;;;;;;;;;ACLA;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA;AACA;;;;;;;;;;;;ACJA;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACXa;AACb,IAAI,mBAAO,CAAC,sEAAgB;AAC5B,gBAAgB,mBAAO,CAAC,8DAAY;AACpC,eAAe,mBAAO,CAAC,4DAAW;AAClC,cAAc,mBAAO,CAAC,0DAAU;AAChC,gBAAgB,mBAAO,CAAC,4DAAW;AACnC,eAAe,mBAAO,CAAC,0DAAU;AACjC,gBAAgB,mBAAO,CAAC,wEAAiB;AACzC,YAAY,mBAAO,CAAC,sDAAQ;AAC5B,mBAAmB,mBAAO,CAAC,sEAAgB;AAC3C,qBAAqB,mBAAO,CAAC,0EAAkB;AAC/C,aAAa,mBAAO,CAAC,wDAAS;AAC9B,oBAAoB,mBAAO,CAAC,wEAAiB;AAC7C,kBAAkB,mBAAO,CAAC,oEAAe;AACzC,iBAAiB,mBAAO,CAAC,kEAAc;AACvC,gBAAgB,mBAAO,CAAC,gEAAa;AACrC,wBAAwB,mBAAO,CAAC,kFAAsB;AACtD,oBAAoB,mBAAO,CAAC,wEAAiB;AAC7C,YAAY,mBAAO,CAAC,sDAAQ;AAC5B,gBAAgB,mBAAO,CAAC,8DAAY;AACpC,iBAAiB,mBAAO,CAAC,kEAAc;AACvC,iBAAiB,mBAAO,CAAC,kEAAc;AACvC,oBAAoB,mBAAO,CAAC,0EAAkB;AAC9C,eAAe,mBAAO,CAAC,0EAAkB;AACzC,uBAAuB,mBAAO,CAAC,oEAAe;AAC9C,aAAa,mBAAO,CAAC,sEAAgB;AACrC,kBAAkB,mBAAO,CAAC,8FAA4B;AACtD,YAAY,mBAAO,CAAC,sDAAQ;AAC5B,YAAY,mBAAO,CAAC,sDAAQ;AAC5B,0BAA0B,mBAAO,CAAC,0EAAkB;AACpD,4BAA4B,mBAAO,CAAC,4EAAmB;AACvD,2BAA2B,mBAAO,CAAC,sFAAwB;AAC3D,uBAAuB,mBAAO,CAAC,kFAAsB;AACrD,kBAAkB,mBAAO,CAAC,kEAAc;AACxC,oBAAoB,mBAAO,CAAC,sEAAgB;AAC5C,mBAAmB,mBAAO,CAAC,sEAAgB;AAC3C,kBAAkB,mBAAO,CAAC,oEAAe;AACzC,wBAAwB,mBAAO,CAAC,kFAAsB;AACtD,YAAY,mBAAO,CAAC,kEAAc;AAClC,cAAc,mBAAO,CAAC,sEAAgB;AACtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,GAAG;;AAEH;AACA;AACA;AACA,GAAG;;AAEH;AACA,4BAA4B;AAC5B,GAAG;;AAEH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,iBAAiB,mBAAmB,0BAA0B,EAAE,EAAE;AAClE;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,yDAAyD,gCAAgC;AACzF;AACA,OAAO;AACP;AACA;AACA,6EAA6E,YAAY;AACzF;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,yDAAyD,6CAA6C,EAAE;;AAExG;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL,mDAAmD;AACnD;AACA,KAAK;AACL;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL,oCAAoC;AACpC;AACA,KAAK;AACL,wEAAwE;AACxE;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL,8DAA8D;AAC9D;AACA,KAAK;AACL,wEAAwE;AACxE;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,GAAG;;AAEH,yBAAyB,sBAAsB,EAAE,EAAE;AACnD;AACA;AACA;AACA;;AAEA,4CAA4C;AAC5C;AACA;AACA;AACA;AACA;AACA,8BAA8B,aAAa;AAC3C;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,sBAAsB,0BAA0B;AAChD,GAAG;;AAEH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA,SAAS;AACT;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA,WAAW;AACX;AACA;AACA;AACA;AACA,SAAS;AACT;AACA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA,OAAO;AACP;AACA;AACA,KAAK;AACL;AACA,KAAK;AACL,yBAAyB;AACzB,KAAK;AACL,uBAAuB;AACvB,2BAA2B;AAC3B,0BAA0B;AAC1B,2BAA2B;AAC3B,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,0BAA0B,aAAa;AACvC,OAAO;AACP;;AAEA;;AAEA;;AAEA;AACA;AACA,KAAK;;AAEL,uDAAuD,6BAA6B,EAAE;AACtF;AACA;AACA,KAAK;;AAEL;;AAEA;;AAEA;;AAEA,uDAAuD,YAAY;;AAEnE;;AAEA;;AAEA;AACA;AACA,KAAK,UAAU,gBAAgB;;AAE/B;AACA;AACA,KAAK;AACL;AACA,KAAK,WAAW,kCAAkC;;AAElD;AACA;AACA;AACA,CAAC,oCAAoC;;;;;;;;;;;;;AC/dxB;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,cAAc,mBAAO,CAAC,8DAAY;AAClC,aAAa,mBAAO,CAAC,0DAAU;AAC/B,WAAW,mBAAO,CAAC,wDAAS;AAC5B,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,YAAY,mBAAO,CAAC,0DAAU;AAC9B,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,gEAAa;AACnC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,SAAS,mBAAO,CAAC,kEAAc;AAC/B,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,QAAQ,WAAW;AACnB;AACA;AACA,QAAQ,UAAU;AAClB;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,QAAQ,WAAW;AACnB;AACA;AACA;AACA,QAAQ,WAAW;AACnB;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,yBAAyB,mBAAmB,uBAAuB,EAAE,EAAE;AACvE;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,iBAAiB,WAAW;AAC5B;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,GAAG;AACH,CAAC;AACD;AACA;AACA,GAAG;AACH,yBAAyB;AACzB,GAAG;AACH,uBAAuB;AACvB,0BAA0B;AAC1B,0BAA0B;AAC1B;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,iDAAiD,iBAAiB;AAClE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACnRA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;AC3BA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACJA,aAAa,mBAAO,CAAC,4DAAW;AAChC;;AAEA;;;;;;;;;;;;ACHA,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;AACA;;;;;;;;;;;;ACJA,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,cAAc,mBAAO,CAAC,8DAAY;AAClC,aAAa,mBAAO,CAAC,8DAAY;AACjC,qBAAqB,mBAAO,CAAC,kEAAc;AAC3C;AACA,0DAA0D,sBAAsB;AAChF,kFAAkF,wBAAwB;AAC1G;;;;;;;;;;;;ACRA,YAAY,mBAAO,CAAC,sDAAQ;;;;;;;;;;;;ACA5B,YAAY,mBAAO,CAAC,4DAAW;AAC/B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,aAAa,mBAAO,CAAC,4DAAW;AAChC;;AAEA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;ACVA,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,sDAAQ;AAC/B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,iBAAiB,mBAAO,CAAC,wDAAS;AAClC;AACA;AACA;AACA;;;;;;;;;;;;ACPA;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,UAAU,mBAAO,CAAC,gEAAa,oBAAoB;;AAEnD,8BAA8B,8BAA8B,gBAAgB,EAAE,EAAE;;;;;;;;;;;;ACJhF;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,6BAA6B,aAAa,mBAAO,CAAC,kFAAsB,GAAG;;AAE3E,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACLlB;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,0EAAkB;;AAEvC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,6BAA6B,OAAO,mBAAO,CAAC,oEAAe,GAAG;;AAE9D,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACLlB;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,0EAAkB;;AAExC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0EAAkB;AACtC;AACA;AACA;AACA,0CAA0C,gBAAgB,EAAE;AAC5D;AACA;AACA;AACA;AACA,CAAC;AACD,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACblB;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0EAAkB;AACtC;AACA;AACA;AACA,0CAA0C,gBAAgB,EAAE;AAC5D;AACA;AACA;AACA;AACA,CAAC;AACD,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACblB;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,0EAAkB;AACzC,aAAa,mBAAO,CAAC,0EAAkB;;AAEvC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACVY;AACb,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,WAAW,mBAAO,CAAC,kEAAc;AACjC,kBAAkB,mBAAO,CAAC,0EAAkB;AAC5C,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,8EAAoB;AACjD,gBAAgB,mBAAO,CAAC,8FAA4B;;AAEpD,iCAAiC,mBAAO,CAAC,sEAAgB,mBAAmB,kBAAkB,EAAE;AAChG;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,uDAAuD,gCAAgC;AACvF;AACA;AACA,KAAK;AACL;AACA,kCAAkC,gBAAgB;AAClD;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACpCY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,4EAAmB;AAC1C;AACA;;AAEA,mDAAmD,mBAAO,CAAC,0EAAkB;AAC7E;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACdD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,6BAA6B,UAAU,mBAAO,CAAC,gEAAa,GAAG;;;;;;;;;;;;;ACHlD;AACb,uBAAuB,mBAAO,CAAC,oFAAuB;AACtD,WAAW,mBAAO,CAAC,kEAAc;AACjC,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,gCAAgC;AAChC,cAAc;AACd,iBAAiB;AACjB;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;;ACjCa;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;;AAEA;AACA,iCAAiC,mBAAO,CAAC,8DAAY,gBAAgB,mBAAO,CAAC,0EAAkB;AAC/F;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACXY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;;AAEA,mDAAmD,mBAAO,CAAC,0EAAkB;AAC7E;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,WAAW;AACrB;AACA;AACA,CAAC;;;;;;;;;;;;;ACrBY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,0EAAkB;;AAErC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,qBAAqB,mBAAO,CAAC,8EAAoB;;AAEjD;AACA,gCAAgC,mBAAO,CAAC,0DAAU;AAClD,gBAAgB;AAChB;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;AClBY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,wEAAiB;;AAEvC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,wEAAiB;;AAEvC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD,eAAe,mBAAO,CAAC,kEAAc;AACrC;;AAEA;AACA,gCAAgC,mBAAO,CAAC,0DAAU;AAClD;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,UAAU,UAAU;AACpB;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;AC3BY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,0EAAkB;;AAEtC,iCAAiC,mBAAO,CAAC,0EAAkB;AAC3D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,YAAY,mBAAO,CAAC,0DAAU;AAC9B;AACA;;AAEA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA,CAAC,MAAM,mBAAO,CAAC,0EAAkB;AACjC;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACtBD,mBAAO,CAAC,sEAAgB;;;;;;;;;;;;ACAxB;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,mBAAmB,6BAA6B,EAAE,EAAE;;;;;;;;;;;;ACHhF;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,kBAAkB,mBAAO,CAAC,oFAAuB;;AAEjD;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACPY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,wEAAiB;;AAE3C,gCAAgC,mBAAO,CAAC,0DAAU;AAClD;AACA,mCAAmC,2BAA2B,UAAU,EAAE,EAAE;AAC5E,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACfD,mBAAmB,mBAAO,CAAC,sDAAQ;AACnC;;AAEA,8BAA8B,mBAAO,CAAC,wDAAS,uBAAuB,mBAAO,CAAC,kFAAsB;;;;;;;;;;;;ACHpG;AACA;AACA;AACA;AACA;AACA;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;AACA;AACA;AACA,GAAG;AACH;;;;;;;;;;;;ACXA;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,gCAAgC,OAAO,mBAAO,CAAC,wDAAS,GAAG;;;;;;;;;;;;;ACH9C;AACb,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,mBAAmB,mBAAO,CAAC,sDAAQ;AACnC;AACA;AACA,sCAAsC,mBAAO,CAAC,kEAAc,kCAAkC;AAC9F;AACA;AACA;AACA;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACZH,SAAS,mBAAO,CAAC,kEAAc;AAC/B;AACA;AACA;;AAEA;AACA,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACfY;AACb,aAAa,mBAAO,CAAC,kFAAsB;AAC3C,eAAe,mBAAO,CAAC,sFAAwB;AAC/C;;AAEA;AACA,iBAAiB,mBAAO,CAAC,oEAAe;AACxC,yBAAyB,mEAAmE;AAC5F,CAAC;AACD;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;AClBD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,oEAAe;AACnC;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACjBD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA;AACA;;AAEA;AACA,yEAAyE,eAAe;;;;;;;;;;;;ACTxF;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,kEAAc;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,oEAAe;;AAEpC,iEAAiE,gBAAgB;;;;;;;;;;;;ACJjF;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,SAAS,mBAAO,CAAC,sEAAgB,GAAG;;;;;;;;;;;;ACHhE;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA,yCAAyC;AACzC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA,OAAO;AACP;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACxBD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA,gCAAgC,mBAAO,CAAC,0DAAU;AAClD;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;AChBD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,QAAQ,mBAAO,CAAC,oEAAe,GAAG;;;;;;;;;;;;ACH9D;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,OAAO,mBAAO,CAAC,kEAAc,GAAG;;;;;;;;;;;;ACH5D;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,oEAAe;AACnC;;AAEA;AACA,gCAAgC,mBAAO,CAAC,0DAAU;AAClD;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACdD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,oEAAe;AACnC;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACXD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACPY;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,wBAAwB,mBAAO,CAAC,sFAAwB;AACxD,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,YAAY,mBAAO,CAAC,0DAAU;AAC9B,WAAW,mBAAO,CAAC,sEAAgB;AACnC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,SAAS,mBAAO,CAAC,kEAAc;AAC/B,YAAY,mBAAO,CAAC,sEAAgB;AACpC;AACA;AACA;AACA;AACA;AACA,qBAAqB,mBAAO,CAAC,0EAAkB;AAC/C;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oDAAoD;AACpD,KAAK;AACL;AACA,oCAAoC,cAAc,OAAO;AACzD,qCAAqC,cAAc,OAAO;AAC1D;AACA;AACA,oEAAoE,OAAO;AAC3E;AACA;AACA;AACA;AACA,OAAO;AACP;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,0CAA0C,0BAA0B,EAAE;AACtE;AACA;AACA,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C;AACA;AACA;AACA;AACA;AACA,2BAA2B,iBAAiB;AAC5C;AACA;AACA;AACA;AACA;AACA;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;;;;;;;;;;;;ACpEA;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,8BAA8B,4BAA4B;;;;;;;;;;;;ACH1D;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,4DAAW;;AAEnC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,8BAA8B,YAAY,mBAAO,CAAC,oEAAe,GAAG;;;;;;;;;;;;ACHpE;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;;AAEA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,8BAA8B,qCAAqC;;;;;;;;;;;;ACHnE;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,8BAA8B,sCAAsC;;;;;;;;;;;;ACHpE,cAAc,mBAAO,CAAC,4DAAW;AACjC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C;AACA,+EAA+E,0BAA0B;;;;;;;;;;;;ACHzG,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,kEAAc;AACtC;AACA,2EAA2E,sBAAsB;;;;;;;;;;;;;ACHpF;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,mBAAmB,mBAAO,CAAC,4EAAmB;AAC9C,aAAa,mBAAO,CAAC,0EAAkB;AACvC;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA,MAAM,mBAAO,CAAC,0DAAU;AACxB;AACA,kBAAkB;AAClB,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;;ACjHY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,0DAAU;AAC/B,mBAAmB,mBAAO,CAAC,4EAAmB;AAC9C;;AAEA;AACA;AACA;AACA,CAAC;AACD;AACA,sBAAsB;AACtB,CAAC;AACD;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACjBD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,0CAA0C,SAAS,mBAAO,CAAC,0EAAkB,GAAG;;;;;;;;;;;;ACHhF,cAAc,mBAAO,CAAC,4DAAW;AACjC;AACA,8BAA8B,SAAS,mBAAO,CAAC,0EAAkB,GAAG;;;;;;;;;;;;ACFpE,cAAc,mBAAO,CAAC,4DAAW;AACjC;AACA,iCAAiC,mBAAO,CAAC,sEAAgB,cAAc,mBAAmB,mBAAO,CAAC,oEAAe,GAAG;;;;;;;;;;;;ACFpH,cAAc,mBAAO,CAAC,4DAAW;AACjC;AACA,iCAAiC,mBAAO,CAAC,sEAAgB,cAAc,iBAAiB,mBAAO,CAAC,kEAAc,KAAK;;;;;;;;;;;;ACFnH;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,WAAW,mBAAO,CAAC,wDAAS;;AAE5B,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,gCAAgC,mBAAO,CAAC,sEAAgB;;AAExD,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,mBAAO,CAAC,oEAAe;AACvB,SAAS,mBAAO,CAAC,8EAAoB;AACrC,CAAC;;;;;;;;;;;;ACHD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,oEAAe;;AAE7C,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,eAAe,mBAAO,CAAC,kEAAc;;AAErC,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,eAAe,mBAAO,CAAC,kEAAc;;AAErC,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,eAAe,mBAAO,CAAC,kEAAc;;AAErC,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,8BAA8B,KAAK,mBAAO,CAAC,oEAAe,GAAG;;;;;;;;;;;;ACF7D;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,YAAY,mBAAO,CAAC,sEAAgB;;AAEpC,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,WAAW,mBAAO,CAAC,wDAAS;;AAE5B,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,eAAe,mBAAO,CAAC,kEAAc;AACrC,WAAW,mBAAO,CAAC,wDAAS;;AAE5B,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,8BAA8B,iBAAiB,mBAAO,CAAC,kEAAc,OAAO;;;;;;;;;;;;;ACF/D;AACb;AACA,cAAc,mBAAO,CAAC,8DAAY;AAClC;AACA,KAAK,mBAAO,CAAC,sDAAQ;AACrB;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;AACA,GAAG;AACH;;;;;;;;;;;;ACTA,cAAc,mBAAO,CAAC,4DAAW;AACjC,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C;AACA,8DAA8D,0BAA0B;;;;;;;;;;;;ACHxF,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,kEAAc;AACtC;AACA,0DAA0D,sBAAsB;;;;;;;;;;;;;ACHnE;AACb,cAAc,mBAAO,CAAC,8DAAY;AAClC,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,8DAAY;AAClC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,YAAY,mBAAO,CAAC,4DAAW;AAC/B,yBAAyB,mBAAO,CAAC,sFAAwB;AACzD,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,iCAAiC,mBAAO,CAAC,4FAA2B;AACpE,cAAc,mBAAO,CAAC,8DAAY;AAClC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,qBAAqB,mBAAO,CAAC,8EAAoB;AACjD;AACA;AACA;AACA;AACA;AACA;AACA;AACA,yBAAyB;AACzB;AACA;;AAEA;AACA;AACA;AACA;AACA,+CAA+C,EAAE,mBAAO,CAAC,sDAAQ;AACjE;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG,YAAY;AACf,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,oCAAoC;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,WAAW;AACX;AACA,WAAW;AACX,SAAS;AACT,OAAO;AACP;AACA;AACA;AACA;AACA,6CAA6C;AAC7C;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT,mBAAmB,kCAAkC;AACrD,SAAS;AACT;AACA;AACA,OAAO;AACP;AACA;AACA,KAAK;AACL;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL,eAAe,uCAAuC;AACtD;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,kCAAkC;AAClC;AACA;AACA;AACA;AACA,uBAAuB,0BAA0B;AACjD;AACA;AACA,SAAS;AACT;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH,kBAAkB,yBAAyB,KAAK;AAChD;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA,iBAAiB;AACjB,wBAAwB;AACxB,gBAAgB;AAChB,oBAAoB;AACpB,wBAAwB;AACxB,gBAAgB;AAChB,oBAAoB;AACpB;AACA,uBAAuB,mBAAO,CAAC,wEAAiB;AAChD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,0DAA0D,oBAAoB;AAC9E,mBAAO,CAAC,kFAAsB;AAC9B,mBAAO,CAAC,sEAAgB;AACxB,UAAU,mBAAO,CAAC,wDAAS;;AAE3B;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA,CAAC;AACD,gDAAgD,mBAAO,CAAC,sEAAgB;AACxE;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT,OAAO;AACP;AACA,KAAK;AACL;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;AC7RD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,4DAAW,eAAe;AAChD;AACA;AACA,iCAAiC,mBAAO,CAAC,0DAAU;AACnD,sBAAsB,cAAc;AACpC,CAAC;AACD;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACfD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,0EAAkB;AACvC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,YAAY,mBAAO,CAAC,0DAAU;AAC9B,WAAW,mBAAO,CAAC,wDAAS;AAC5B,kBAAkB,mBAAO,CAAC,4DAAW,eAAe;;AAEpD;AACA;AACA;AACA,gBAAgB;AAChB,mCAAmC,cAAc;AACjD,CAAC;AACD;AACA,0BAA0B,cAAc;AACxC,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;AC9CD;AACA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,wEAAiB;;AAE3C;AACA,gCAAgC,mBAAO,CAAC,0DAAU;AAClD;AACA,gCAAgC,MAAM,WAAW,OAAO,WAAW;AACnE,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACtBD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACVY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA,+BAA+B;AAC/B,cAAc;AACd,0BAA0B;AAC1B;AACA;AACA;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA;AACA,wCAAwC;AACxC,GAAG;AACH,UAAU;AACV,CAAC;;AAED;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACzBD;AACA,WAAW,mBAAO,CAAC,sEAAgB;AACnC,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,oEAAe;AACtC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,WAAW,mBAAO,CAAC,sEAAgB;AACnC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,+BAA+B,WAAW;;;;;;;;;;;;ACpB1C;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC;;AAEA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACVD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,+BAA+B,UAAU,mBAAO,CAAC,gEAAa,GAAG;;;;;;;;;;;;ACHjE;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACfD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACdD;AACA,SAAS,mBAAO,CAAC,kEAAc;AAC/B,WAAW,mBAAO,CAAC,sEAAgB;AACnC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,cAAc,mBAAO,CAAC,4DAAW;AACjC,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;;AAEA,+BAA+B,WAAW;;;;;;;;;;;;AChC1C,aAAa,mBAAO,CAAC,4DAAW;AAChC,wBAAwB,mBAAO,CAAC,sFAAwB;AACxD,SAAS,mBAAO,CAAC,kEAAc;AAC/B,WAAW,mBAAO,CAAC,sEAAgB;AACnC,eAAe,mBAAO,CAAC,kEAAc;AACrC,aAAa,mBAAO,CAAC,0DAAU;AAC/B;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,IAAI,mBAAO,CAAC,sEAAgB,sBAAsB,mBAAO,CAAC,0DAAU;AACpE,MAAM,mBAAO,CAAC,sDAAQ;AACtB;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,wBAAwB,kBAAkB,EAAE;AAC5C,0BAA0B,gBAAgB;AAC1C,KAAK;AACL;AACA,oCAAoC,iBAAiB;AACrD;AACA;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;;AAEA,mBAAO,CAAC,sEAAgB;;;;;;;;;;;;;AC1CX;AACb,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,mBAAO,CAAC,4DAAW;AACnB;AACA;AACA;AACA,CAAC;AACD;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,IAAI,mBAAO,CAAC,sEAAgB,wBAAwB,mBAAO,CAAC,kEAAc;AAC1E;AACA,OAAO,mBAAO,CAAC,0DAAU;AACzB,CAAC;;;;;;;;;;;;;ACJY;;AAEb,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,yBAAyB,mBAAO,CAAC,wFAAyB;AAC1D,iBAAiB,mBAAO,CAAC,wFAAyB;;AAElD;AACA,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACvCY;;AAEb,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,yBAAyB,mBAAO,CAAC,wFAAyB;AAC1D,iBAAiB,mBAAO,CAAC,wFAAyB;AAClD;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,qBAAqB,oBAAoB;AACzC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,uBAAuB,mBAAmB;AAC1C;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;;ACrHY;;AAEb,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,iBAAiB,mBAAO,CAAC,wFAAyB;;AAElD;AACA,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;AC9BY;;AAEb,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,yBAAyB,mBAAO,CAAC,sFAAwB;AACzD,yBAAyB,mBAAO,CAAC,wFAAyB;AAC1D,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,wFAAyB;AACtD,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,YAAY,mBAAO,CAAC,0DAAU;AAC9B;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA,qCAAqC,yBAAyB,EAAE;;AAEhE;AACA,mBAAO,CAAC,oEAAe;AACvB;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,mFAAmF;AACnF;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA,GAAG;AACH;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,SAAS;AACT;AACA;AACA,yBAAyB,mBAAmB;AAC5C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACrIY;AACb,mBAAO,CAAC,8EAAoB;AAC5B,eAAe,mBAAO,CAAC,kEAAc;AACrC,aAAa,mBAAO,CAAC,0DAAU;AAC/B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C;AACA;;AAEA;AACA,EAAE,mBAAO,CAAC,gEAAa;AACvB;;AAEA;AACA,IAAI,mBAAO,CAAC,0DAAU,eAAe,wBAAwB,0BAA0B,YAAY,EAAE;AACrG;AACA;AACA;AACA;AACA,GAAG;AACH;AACA,CAAC;AACD;AACA;AACA,GAAG;AACH;;;;;;;;;;;;;ACxBa;AACb,aAAa,mBAAO,CAAC,kFAAsB;AAC3C,eAAe,mBAAO,CAAC,sFAAwB;AAC/C;;AAEA;AACA,iBAAiB,mBAAO,CAAC,oEAAe;AACxC,yBAAyB,mEAAmE;AAC5F,CAAC;AACD;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACbY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,UAAU,mBAAO,CAAC,kEAAc;AAChC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACRD;AACa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,4EAAmB;AACzC;AACA;;AAEA,gCAAgC,mBAAO,CAAC,8EAAoB;AAC5D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACnBY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACND,cAAc,mBAAO,CAAC,4DAAW;AACjC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD;AACA;;AAEA;AACA;AACA;AACA,4CAA4C;AAC5C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;;ACtBD;AACa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,4EAAmB;AACzC;;AAEA,gCAAgC,mBAAO,CAAC,8EAAoB;AAC5D;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACXY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb,UAAU,mBAAO,CAAC,kEAAc;;AAEhC;AACA,mBAAO,CAAC,sEAAgB;AACxB,6BAA6B;AAC7B,cAAc;AACd;AACA,CAAC;AACD;AACA;AACA;AACA,iCAAiC;AACjC;AACA;AACA,UAAU;AACV,CAAC;;;;;;;;;;;;;AChBY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACND,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;;AAErC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;ACjBD,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA,UAAU,mBAAO,CAAC,0EAAkB;AACpC,CAAC;;;;;;;;;;;;;ACLY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACND;AACa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,4EAAmB;AACzC;AACA;;AAEA,gCAAgC,mBAAO,CAAC,8EAAoB;AAC5D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACjBY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,aAAa,mBAAO,CAAC,4DAAW;AAChC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,kBAAkB,mBAAO,CAAC,sEAAgB;AAC1C,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,gEAAa;AACpC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,aAAa,mBAAO,CAAC,0DAAU;AAC/B,aAAa,mBAAO,CAAC,4DAAW;AAChC,qBAAqB,mBAAO,CAAC,kFAAsB;AACnD,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,UAAU,mBAAO,CAAC,sDAAQ;AAC1B,aAAa,mBAAO,CAAC,8DAAY;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,cAAc,mBAAO,CAAC,gEAAa;AACnC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,iBAAiB,mBAAO,CAAC,0EAAkB;AAC3C,cAAc,mBAAO,CAAC,0EAAkB;AACxC,cAAc,mBAAO,CAAC,8EAAoB;AAC1C,YAAY,mBAAO,CAAC,sEAAgB;AACpC,UAAU,mBAAO,CAAC,kEAAc;AAChC,YAAY,mBAAO,CAAC,sEAAgB;AACpC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,eAAe;AACf;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,sBAAsB;AACtB,sBAAsB,uBAAuB,WAAW,IAAI;AAC5D,GAAG;AACH,CAAC;AACD;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA,CAAC;AACD;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,2DAA2D;AAC3D;AACA,KAAK;AACL;AACA,sBAAsB,mCAAmC;AACzD,KAAK;AACL,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,gEAAgE,gCAAgC;AAChG;AACA;AACA;AACA;AACA,GAAG;;AAEH;AACA;AACA,EAAE,mBAAO,CAAC,sEAAgB;AAC1B,EAAE,mBAAO,CAAC,oEAAe;AACzB,EAAE,mBAAO,CAAC,sEAAgB;;AAE1B,sBAAsB,mBAAO,CAAC,8DAAY;AAC1C;AACA;;AAEA;AACA;AACA;AACA;;AAEA,0DAA0D,kBAAkB;;AAE5E;AACA;AACA;AACA,oBAAoB,uBAAuB;;AAE3C,oDAAoD,6BAA6B;;AAEjF;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA,GAAG;AACH,0BAA0B,eAAe,EAAE;AAC3C,0BAA0B,gBAAgB;AAC1C,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA,oDAAoD,OAAO,QAAQ,iCAAiC;AACpG,CAAC;AACD;AACA;AACA;AACA;AACA;AACA;AACA,wEAAwE;AACxE;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED;AACA,oCAAoC,mBAAO,CAAC,wDAAS;AACrD;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;;ACzOa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,0DAAU;AAC/B,aAAa,mBAAO,CAAC,wEAAiB;AACtC,eAAe,mBAAO,CAAC,kEAAc;AACrC,sBAAsB,mBAAO,CAAC,kFAAsB;AACpD,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,4DAAW;AACrC,yBAAyB,mBAAO,CAAC,sFAAwB;AACzD;AACA;AACA;AACA;AACA;AACA;;AAEA,6EAA6E,4BAA4B;;AAEzG;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED,4CAA4C,mBAAO,CAAC,0DAAU;AAC9D;AACA,CAAC;AACD;AACA;AACA,6FAA6F;AAC7F;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;AAED,mBAAO,CAAC,sEAAgB;;;;;;;;;;;;AC7CxB,cAAc,mBAAO,CAAC,4DAAW;AACjC,6CAA6C,mBAAO,CAAC,0DAAU;AAC/D,YAAY,mBAAO,CAAC,wEAAiB;AACrC,CAAC;;;;;;;;;;;;ACHD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACJD,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACJY;AACb,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,0EAAkB;AACrC,eAAe,mBAAO,CAAC,gEAAa;AACpC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,aAAa,mBAAO,CAAC,0EAAkB;AACvC,WAAW,mBAAO,CAAC,8EAAoB;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,sFAAwB;AAC/C,sBAAsB,mBAAO,CAAC,sFAAwB;AACtD;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA,gCAAgC,mBAAO,CAAC,oEAAe;;AAEvD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP,KAAK;AACL,GAAG;AACH;;;;;;;;;;;;;AC3Da;AACb,WAAW,mBAAO,CAAC,8EAAoB;AACvC,eAAe,mBAAO,CAAC,sFAAwB;AAC/C;;AAEA;AACA,mBAAO,CAAC,oEAAe;AACvB,6BAA6B,mEAAmE;AAChG,CAAC;AACD;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACbY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,uBAAuB,mBAAO,CAAC,oFAAuB;AACtD,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,yBAAyB,mBAAO,CAAC,wFAAyB;;AAE1D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACrBlB;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,uBAAuB,mBAAO,CAAC,oFAAuB;AACtD,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,yBAAyB,mBAAO,CAAC,wFAAyB;;AAE1D;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;AAED,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;;ACpBlB;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,4EAAmB;;AAE3C;AACA;AACA;AACA;AACA,CAAC;;AAED,mBAAO,CAAC,oFAAuB;;;;;;;;;;;;ACX/B;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,sDAAQ;;AAE7B;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACXD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,UAAU,mBAAO,CAAC,sDAAQ;;AAE1B;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,oBAAoB,SAAS,mBAAO,CAAC,4DAAW,GAAG;;;;;;;;;;;;ACHnD;AACA,mBAAO,CAAC,sFAAwB;;;;;;;;;;;;ACDhC;AACA,mBAAO,CAAC,kFAAsB;;;;;;;;;;;;ACD9B;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,uCAAuC,SAAS,mBAAO,CAAC,oFAAuB,UAAU;;;;;;;;;;;;ACHzF;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACPD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,6BAA6B;;;;;;;;;;;;ACHzD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,oEAAe;AACnC,aAAa,mBAAO,CAAC,sEAAgB;;AAErC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACTD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACVD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACfD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACVD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,6BAA6B;;;;;;;;;;;;ACHzD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC;;AAEA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B,QAAQ,mBAAO,CAAC,oEAAe,GAAG;;;;;;;;;;;;ACH9D;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,4BAA4B;AAC5B;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACNH;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACfY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,sBAAsB,mBAAO,CAAC,kEAAc;;AAE5C;AACA,mBAAO,CAAC,sEAAgB,yBAAyB,mBAAO,CAAC,kFAAsB;AAC/E;AACA,0CAA0C,+DAA+D;AACzG;AACA,CAAC;;;;;;;;;;;;;ACXY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,sBAAsB,mBAAO,CAAC,kEAAc;;AAE5C;AACA,mBAAO,CAAC,sEAAgB,yBAAyB,mBAAO,CAAC,kFAAsB;AAC/E;AACA,0CAA0C,+DAA+D;AACzG;AACA,CAAC;;;;;;;;;;;;ACXD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,8EAAoB;;AAE3C;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACRD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,gEAAa;AACnC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,WAAW,mBAAO,CAAC,sEAAgB;AACnC,qBAAqB,mBAAO,CAAC,8EAAoB;;AAEjD;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACrBY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,+BAA+B,mBAAO,CAAC,sEAAgB;;AAEvD;AACA,mBAAO,CAAC,sEAAgB,yBAAyB,mBAAO,CAAC,kFAAsB;AAC/E;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;;ACjBY;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,eAAe,mBAAO,CAAC,kEAAc;AACrC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C,+BAA+B,mBAAO,CAAC,sEAAgB;;AAEvD;AACA,mBAAO,CAAC,sEAAgB,yBAAyB,mBAAO,CAAC,kFAAsB;AAC/E;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA,CAAC;;;;;;;;;;;;ACjBD;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,8EAAoB;;AAE1C;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACRY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,iBAAiB,mBAAO,CAAC,sDAAQ;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC,eAAe,mBAAO,CAAC,kEAAc;AACrC,iBAAiB,mBAAO,CAAC,sEAAgB;AACzC,kBAAkB,mBAAO,CAAC,wEAAiB;AAC3C,WAAW,mBAAO,CAAC,wDAAS;AAC5B,YAAY,mBAAO,CAAC,4DAAW;AAC/B;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,4EAA4E,4BAA4B;AACxG;AACA;AACA;AACA,GAAG;AACH;AACA;AACA,GAAG;AACH;;AAEA,uCAAuC;AACvC,uCAAuC,yBAAyB;AAChE,CAAC;;AAED;AACA;AACA;;AAEA,+CAA+C;AAC/C;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA,SAAS;AACT;AACA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,OAAO;AACP;AACA;AACA,KAAK;AACL;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA,SAAS;AACT;AACA;AACA,OAAO;AACP;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,WAAW;AACX;AACA;AACA;AACA,SAAS;AACT;AACA;AACA,OAAO;AACP,KAAK;AACL;AACA,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,OAAO;AACP;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,aAAa;AACb,WAAW;AACX;AACA;AACA;AACA,WAAW;AACX;AACA,OAAO;AACP,0BAA0B,aAAa;AACvC,KAAK;AACL,GAAG;AACH;AACA,+DAA+D,OAAO;AACtE;AACA;AACA;AACA;AACA,yBAAyB,kBAAkB;AAC3C;AACA;AACA,WAAW;AACX;AACA,OAAO;AACP,0BAA0B,aAAa;AACvC,KAAK;AACL;AACA,CAAC;;AAED,qDAAqD,aAAa,EAAE;;AAEpE,oBAAoB,0BAA0B;;AAE9C,mBAAO,CAAC,sEAAgB;;;;;;;;;;;;;ACtMxB;AACa;AACb,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,aAAa,mBAAO,CAAC,4DAAW;AAChC,yBAAyB,mBAAO,CAAC,sFAAwB;AACzD,qBAAqB,mBAAO,CAAC,8EAAoB;;AAEjD,2CAA2C;AAC3C;AACA;AACA;AACA;AACA,8DAA8D,UAAU,EAAE;AAC1E,KAAK;AACL;AACA,8DAA8D,SAAS,EAAE;AACzE,KAAK;AACL;AACA,CAAC,EAAE;;;;;;;;;;;;;ACnBU;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,2BAA2B,mBAAO,CAAC,4FAA2B;AAC9D,cAAc,mBAAO,CAAC,8DAAY;;AAElC,+BAA+B;AAC/B;AACA;AACA;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACXH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;;AAEA,cAAc;AACd;AACA,CAAC,EAAE;;;;;;;;;;;;ACPH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;AACA;;AAEA,cAAc;AACd;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACdH,UAAU,mBAAO,CAAC,4DAAW;AAC7B,WAAW,mBAAO,CAAC,sFAAwB;AAC3C,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,cAAc;AACd;AACA,CAAC,EAAE;;;;;;;;;;;;AClBH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA,cAAc;AACd;AACA,CAAC,EAAE;;;;;;;;;;;;AChBH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;;AAEA,cAAc;AACd;AACA,CAAC,EAAE;;;;;;;;;;;;ACPH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;;AAEA,cAAc;AACd;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACRH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC,qBAAqB,mBAAO,CAAC,oEAAe;AAC5C;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;;AAEA,cAAc;AACd;AACA,CAAC,EAAE;;;;;;;;;;;;ACfH,eAAe,mBAAO,CAAC,gEAAa;AACpC,eAAe,mBAAO,CAAC,kEAAc;AACrC;AACA;;AAEA,cAAc;AACd;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACRH,gBAAgB,mBAAO,CAAC,gEAAa;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA;;AAEA,eAAe;AACf;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC,EAAE;;;;;;;;;;;;ACdH;AACA,mBAAO,CAAC,sFAAwB;;;;;;;;;;;;ACDhC;AACA,mBAAO,CAAC,kFAAsB;;;;;;;;;;;;ACD9B;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,uCAAuC,SAAS,mBAAO,CAAC,oFAAuB,UAAU;;;;;;;;;;;;;ACH5E;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,UAAU,mBAAO,CAAC,kEAAc;;AAEhC;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACTY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,cAAc,mBAAO,CAAC,8DAAY;AAClC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,kEAAc;AACrC,eAAe,mBAAO,CAAC,0DAAU;AACjC;;AAEA;AACA;AACA;AACA;;AAEA,mBAAO,CAAC,sEAAgB;AACxB;AACA,UAAU;AACV,CAAC;;AAED;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;AC7BY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,oEAAe;AAClC,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACXY;AACb;AACA,cAAc,mBAAO,CAAC,4DAAW;AACjC,WAAW,mBAAO,CAAC,oEAAe;AAClC,gBAAgB,mBAAO,CAAC,oEAAe;;AAEvC;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACXY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;;ACNY;AACb;AACA,mBAAO,CAAC,sEAAgB;AACxB;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACND,mBAAO,CAAC,oEAAe;;;;;;;;;;;;ACAvB,mBAAO,CAAC,oEAAe;;;;;;;;;;;;ACAvB;AACA,cAAc,mBAAO,CAAC,4DAAW;;AAEjC,8BAA8B,SAAS,mBAAO,CAAC,4DAAW,GAAG;;;;;;;;;;;;ACH7D;AACA,mBAAO,CAAC,sFAAwB;;;;;;;;;;;;ACDhC;AACA,mBAAO,CAAC,kFAAsB;;;;;;;;;;;;ACD9B;AACA,mBAAO,CAAC,sFAAwB;;;;;;;;;;;;ACDhC;AACA,mBAAO,CAAC,kFAAsB;;;;;;;;;;;;ACD9B,iBAAiB,mBAAO,CAAC,kFAAsB;AAC/C,cAAc,mBAAO,CAAC,sEAAgB;AACtC,eAAe,mBAAO,CAAC,gEAAa;AACpC,aAAa,mBAAO,CAAC,4DAAW;AAChC,WAAW,mBAAO,CAAC,wDAAS;AAC5B,gBAAgB,mBAAO,CAAC,kEAAc;AACtC,UAAU,mBAAO,CAAC,sDAAQ;AAC1B;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA,oDAAoD,wBAAwB;AAC5E;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;;;;;;;;;;;ACzDA,cAAc,mBAAO,CAAC,4DAAW;AACjC,YAAY,mBAAO,CAAC,wDAAS;AAC7B;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACLD;AACA,aAAa,mBAAO,CAAC,4DAAW;AAChC,cAAc,mBAAO,CAAC,4DAAW;AACjC,gBAAgB,mBAAO,CAAC,oEAAe;AACvC;AACA,sCAAsC;AACtC;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA,CAAC;;;;;;;;;;;;ACnBD,mBAAO,CAAC,0EAAsB;AAC9B,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0GAAsC;AAC9C,mBAAO,CAAC,8GAAwC;AAChD,mBAAO,CAAC,kIAAkD;AAC1D,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,wHAA6C;AACrD,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,gHAAyC;AACjD,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,wGAAqC;AAC7C,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,oGAAmC;AAC3C,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0GAAsC;AAC9C,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,0GAAsC;AAC9C,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,oGAAmC;AAC3C,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,4EAAuB;AAC/B,mBAAO,CAAC,oEAAmB;AAC3B,mBAAO,CAAC,oEAAmB;AAC3B,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,gHAAyC;AACjD,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,kGAAkC;AAC1C,mBAAO,CAAC,oGAAmC;AAC3C,mBAAO,CAAC,oGAAmC;AAC3C,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,oIAAmD;AAC3D,mBAAO,CAAC,8GAAwC;AAChD,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,wGAAqC;AAC7C,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,kHAA0C;AAClD,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,8GAAwC;AAChD,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,wGAAqC;AAC7C,mBAAO,CAAC,gGAAiC;AACzC,mBAAO,CAAC,oIAAmD;AAC3D,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,0EAAsB;AAC9B,mBAAO,CAAC,0EAAsB;AAC9B,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,8EAAwB;AAChC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0EAAsB;AAC9B,mBAAO,CAAC,wFAA6B;AACrC,mBAAO,CAAC,0FAA8B;AACtC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,sFAA4B;AACpC,mBAAO,CAAC,4FAA+B;AACvC,mBAAO,CAAC,oFAA2B;AACnC,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,4GAAuC;AAC/C,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,gHAAyC;AACjD,mBAAO,CAAC,8GAAwC;AAChD,mBAAO,CAAC,wHAA6C;AACrD,mBAAO,CAAC,sGAAoC;AAC5C,mBAAO,CAAC,8GAAwC;AAChD,mBAAO,CAAC,8FAAgC;AACxC,mBAAO,CAAC,sEAAoB;AAC5B,mBAAO,CAAC,kFAA0B;AAClC,mBAAO,CAAC,0EAAsB;AAC9B,mBAAO,CAAC,gFAAyB;AACjC,mBAAO,CAAC,sFAA4B;AACpC,iBAAiB,mBAAO,CAAC,gEAAiB;;;;;;;;;;;;ACrM1C;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA,QAAQ,WAAW;;AAEnB;AACA;AACA;AACA,QAAQ,WAAW;;AAEnB;AACA;AACA,GAAG;AACH;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;AACA,GAAG;AACH;AACA;AACA;AACA;AACA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA,KAAK;AACL;AACA;AACA,KAAK;AACL;AACA;AACA;AACA;;AAEA,QAAQ,WAAW;;AAEnB;AACA;AACA,QAAQ,UAAU;;AAElB;AACA;;;;;;;;;;;;ACnFA;AACA;AACA;AACA;AACA;AACA,eAAe,SAAS;AACxB;AACA;;AAEA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;AACA;;AAEA;;;;;;;;;;;;ACvBA;AACA;AACA;AACA;;AAEA;AACA;AACA;AACA;;AAEA;AACA;AACA,iCAAiC;;AAEjC;AACA;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;AACA;AACA;;AAEA;AACA,sBAAsB,QAAQ;AAC9B;AACA;AACA;;AAEA;AACA;AACA;;;;;;;;;;;;ACjCA,UAAU,mBAAO,CAAC,yDAAW;AAC7B,kBAAkB,mBAAO,CAAC,iEAAmB;;AAE7C;AACA;;AAEA;AACA;AACA;AACA;AACA;;AAEA;;AAEA;AACA;AACA;;AAEA;AACA;AACA,oBAAoB,SAAS;AAC7B;AACA;AACA;;AAEA;AACA;;AAEA;;;;;;;;;;;;AC5BA;;AAEA;AACA;AACA;AACA,CAAC;;AAED;AACA;AACA;AACA,CAAC;AACD;AACA;AACA;;AAEA;AACA;AACA,4CAA4C;;AAE5C;;;;;;;;;;;;;;;;;;;;AChBA;;AACA;;0JAJA;AACA;;AAKA,IAAMo+B,6CAA6C,EAAnD,C,CAAuD;;IAE1Cl/B,iB,WAAAA,iB;AAET,iCAIQ;AAAA,uFAAJ,EAAI;AAAA,yCAHJm/B,mCAGI;AAAA,YAHJA,mCAGI,yCAHkCD,0CAGlC;AAAA,0CAFJE,wBAEI;AAAA,YAFJA,wBAEI,0CAFuB,IAAIC,YAAJ,CAAU,uBAAV,CAEvB;AAAA,0CADJC,uBACI;AAAA,YADJA,uBACI,0CADsB,IAAID,YAAJ,CAAU,sBAAV,CACtB;;AAAA;;AACJ,aAAKE,oCAAL,GAA4CJ,mCAA5C;;AAEA,aAAKK,oBAAL,GAA4BJ,wBAA5B;AACA,aAAKK,mBAAL,GAA2BH,uBAA3B;AACH;;gCAEDI,I,iBAAKC,S,EAAW;AACZ;AACA,YAAIA,UAAUC,YAAV,IAA0BD,UAAUE,UAAV,KAAyBh/B,SAAvD,EAAkE;AAC9D,gBAAIi/B,WAAWH,UAAUE,UAAzB;AACAngC,qBAAIqgC,KAAJ,CAAU,mEAAV,EAA+ED,QAA/E;;AAEA,gBAAIA,WAAW,CAAf,EAAkB;AACd;AACA,oBAAIE,WAAWF,WAAW,KAAKP,oCAA/B;AACA,oBAAIS,YAAY,CAAhB,EAAkB;AACdA,+BAAW,CAAX;AACH;;AAEDtgC,yBAAIqgC,KAAJ,CAAU,wDAAV,EAAoEC,QAApE;AACA,qBAAKR,oBAAL,CAA0B78B,IAA1B,CAA+Bq9B,QAA/B;AACH,aATD,MAUK;AACDtgC,yBAAIqgC,KAAJ,CAAU,yFAAV;AACA,qBAAKP,oBAAL,CAA0BS,MAA1B;AACH;;AAED;AACA,gBAAIC,UAAUJ,WAAW,CAAzB;AACApgC,qBAAIqgC,KAAJ,CAAU,uDAAV,EAAmEG,OAAnE;AACA,iBAAKT,mBAAL,CAAyB98B,IAAzB,CAA8Bu9B,OAA9B;AACH,SAvBD,MAwBK;AACD,iBAAKV,oBAAL,CAA0BS,MAA1B;AACA,iBAAKR,mBAAL,CAAyBQ,MAAzB;AACH;AACJ,K;;gCAEDE,M,qBAAS;AACLzgC,iBAAIqgC,KAAJ,CAAU,kEAAV;AACA,aAAKP,oBAAL,CAA0BS,MAA1B;AACA,aAAKR,mBAAL,CAAyBQ,MAAzB;AACH,K;;gCAEDG,sB,mCAAuBC,E,EAAI;AACvB,aAAKb,oBAAL,CAA0Bc,UAA1B,CAAqCD,EAArC;AACH,K;;gCACDE,yB,sCAA0BF,E,EAAI;AAC1B,aAAKb,oBAAL,CAA0BgB,aAA1B,CAAwCH,EAAxC;AACH,K;;gCAEDI,qB,kCAAsBJ,E,EAAI;AACtB,aAAKZ,mBAAL,CAAyBa,UAAzB,CAAoCD,EAApC;AACH,K;;gCACDK,wB,qCAAyBL,E,EAAI;AACzB,aAAKZ,mBAAL,CAAyBe,aAAzB,CAAuCH,EAAvC;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACpEL;;0JAHA;AACA;;AAIA,IAAMM,kBAAkB,IAAxB;;IAEavgC,kB,WAAAA,kB;AACT,gCAAYwgC,QAAZ,EAAsBC,SAAtB,EAAiCC,GAAjC,EAAsCC,QAAtC,EAAoE;AAAA,YAApBC,WAAoB,uEAAN,IAAM;;AAAA;;AAChE,aAAKC,SAAL,GAAiBL,QAAjB;AACA,aAAKM,UAAL,GAAkBL,SAAlB;AACA,aAAKM,IAAL,GAAYL,GAAZ;AACA,aAAKM,SAAL,GAAiBL,YAAYJ,eAA7B;AACA,aAAKU,YAAL,GAAoBL,WAApB;;AAEA,YAAIM,MAAMR,IAAI15B,OAAJ,CAAY,GAAZ,EAAiB05B,IAAI15B,OAAJ,CAAY,IAAZ,IAAoB,CAArC,CAAV;AACA,aAAKm6B,aAAL,GAAqBT,IAAIv8B,MAAJ,CAAW,CAAX,EAAc+8B,GAAd,CAArB;;AAEA,aAAKE,MAAL,GAAc7gC,OAAO8gC,QAAP,CAAgBC,aAAhB,CAA8B,QAA9B,CAAd;;AAEA;AACA,aAAKF,MAAL,CAAYG,KAAZ,CAAkBC,UAAlB,GAA+B,QAA/B;AACA,aAAKJ,MAAL,CAAYG,KAAZ,CAAkBE,QAAlB,GAA6B,UAA7B;AACA,aAAKL,MAAL,CAAYG,KAAZ,CAAkBG,OAAlB,GAA4B,MAA5B;AACA,aAAKN,MAAL,CAAYG,KAAZ,CAAkBI,KAAlB,GAA0B,CAA1B;AACA,aAAKP,MAAL,CAAYG,KAAZ,CAAkBK,MAAlB,GAA2B,CAA3B;;AAEA,aAAKR,MAAL,CAAYS,GAAZ,GAAkBnB,GAAlB;AACH;;iCACDpB,I,mBAAO;AAAA;;AACH,eAAO,IAAIwC,OAAJ,CAAY,UAACC,OAAD,EAAa;AAC5B,kBAAKX,MAAL,CAAYY,MAAZ,GAAqB,YAAM;AACvBD;AACH,aAFD;;AAIAxhC,mBAAO8gC,QAAP,CAAgBY,IAAhB,CAAqBC,WAArB,CAAiC,MAAKd,MAAtC;AACA,kBAAKe,kBAAL,GAA0B,MAAKC,QAAL,CAAcC,IAAd,CAAmB,KAAnB,CAA1B;AACA9hC,mBAAO+hC,gBAAP,CAAwB,SAAxB,EAAmC,MAAKH,kBAAxC,EAA4D,KAA5D;AACH,SARM,CAAP;AASH,K;;iCACDC,Q,qBAAS9gC,C,EAAG;AACR,YAAIA,EAAEihC,MAAF,KAAa,KAAKpB,aAAlB,IACA7/B,EAAEkhC,MAAF,KAAa,KAAKpB,MAAL,CAAYqB,aAD7B,EAEE;AACE,gBAAInhC,EAAEsyB,IAAF,KAAW,OAAf,EAAwB;AACpBt0B,yBAAIojC,KAAJ,CAAU,gEAAV;AACA,oBAAI,KAAKzB,YAAT,EAAuB;AACnB,yBAAK0B,IAAL;AACH;AACJ,aALD,MAMK,IAAIrhC,EAAEsyB,IAAF,KAAW,SAAf,EAA0B;AAC3Bt0B,yBAAIqgC,KAAJ,CAAU,kEAAV;AACA,qBAAKgD,IAAL;AACA,qBAAK9B,SAAL;AACH,aAJI,MAKA;AACDvhC,yBAAIqgC,KAAJ,CAAU,yBAAyBr+B,EAAEsyB,IAA3B,GAAkC,uCAA5C;AACH;AACJ;AACJ,K;;iCACDgP,K,kBAAMC,a,EAAe;AAAA;;AACjB,YAAI,KAAKC,cAAL,KAAwBD,aAA5B,EAA2C;AACvCvjC,qBAAIqgC,KAAJ,CAAU,0BAAV;;AAEA,iBAAKgD,IAAL;;AAEA,iBAAKG,cAAL,GAAsBD,aAAtB;;AAEA,gBAAIE,OAAO,SAAPA,IAAO,GAAM;AACb,uBAAK3B,MAAL,CAAYqB,aAAZ,CAA0BO,WAA1B,CAAsC,OAAKlC,UAAL,GAAkB,GAAlB,GAAwB,OAAKgC,cAAnE,EAAmF,OAAK3B,aAAxF;AACH,aAFD;;AAIA;AACA4B;;AAEA;AACA,iBAAKE,MAAL,GAAc1iC,OAAO2iC,WAAP,CAAmBH,IAAnB,EAAyB,KAAK/B,SAA9B,CAAd;AACH;AACJ,K;;iCAED2B,I,mBAAO;AACH,aAAKG,cAAL,GAAsB,IAAtB;;AAEA,YAAI,KAAKG,MAAT,EAAiB;AACb3jC,qBAAIqgC,KAAJ,CAAU,yBAAV;;AAEAp/B,mBAAO4iC,aAAP,CAAqB,KAAKF,MAA1B;AACA,iBAAKA,MAAL,GAAc,IAAd;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;ACtFL;;0JAHA;AACA;;IAIaljC,sB,WAAAA,sB;;;;;qCAETqjC,O,oBAAQC,M,EAAQ;AACZA,eAAOC,mBAAP,GAA6B,YAA7B;AACA,YAAIC,QAAQ,IAAIC,sCAAJ,CAAuBH,MAAvB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBwB,KAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACRL;;0JAHA;AACA;;IAIazjC,qB,WAAAA,qB;;;;;oCAETsjC,O,oBAAQC,M,EAAQ;AACZ,YAAIE,QAAQ,IAAIC,sCAAJ,CAAuBH,MAAvB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBwB,KAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCVL;AACA;;AAEA;;;;AAEA,IAAME,uBAAuB,gCAA7B;AACA,IAAMC,qBAAqB,QAA3B;;IAEaF,kB,WAAAA,kB;AAET,gCAAYH,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI7B,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgB9B,OAAhB;AACA,kBAAK+B,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,aAAKG,QAAL,GAAgBV,OAAOC,mBAAP,IAA8BG,oBAA9C;AACA,aAAKO,MAAL,GAAcX,OAAOY,iBAAP,IAA4BP,kBAA1C;;AAEA,aAAKQ,YAAL,GAAoBb,OAAOc,QAA3B;AACA7kC,iBAAIqgC,KAAJ,CAAU,4CAA4C,KAAKuE,YAA3D;AACH;;iCAEDE,wB,qCAAyBC,e,EAAiB;AACtC,eAAO,CAAC,6BAAD,EAAgC,0CAAhC,EAA4E,iCAA5E,EAA+GC,IAA/G,CAAoH,UAAU9gB,IAAV,EAAgB;AACvI,mBAAO6gB,gBAAgB/hC,cAAhB,CAA+BkhB,IAA/B,CAAP;AACH,SAFM,CAAP;AAGH,K;;iCAED+gB,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AACxB,iBAAK8D,MAAL,CAAY,iBAAZ;AACH,SAFD,MAEO;AACH,gBAAI,CAACjkC,OAAOkkC,OAAZ,EAAqB;AACjB,uBAAO,KAAKD,MAAL,CAAY,sBAAZ,CAAP;AACH;;AAED,gBAAIH,kBAAkB9jC,OAAOkkC,OAAP,CAAeC,OAAf,CAAuB,qBAAvB,EAA8CC,QAApE;AACA,gBAAI,KAAKP,wBAAL,CAA8BC,eAA9B,MAAmD,KAAvD,EAA8D;AAC1D,uBAAO,KAAKG,MAAL,CAAY,+BAAZ,CAAP;AACH;AACD,iBAAKI,MAAL,GAAcH,QAAQI,YAAR,CAAqBC,IAArB,CAA0BzB,OAAO3C,GAAjC,EAAsC,KAAKsD,MAA3C,EAAmD,KAAKD,QAAxD,CAAd;AACA,gBAAI,KAAKa,MAAT,EAAiB;AACbtlC,yBAAIqgC,KAAJ,CAAU,yDAAV;;AAEA,qBAAKoF,kBAAL,GAA0B,KAAKC,aAAL,CAAmB3C,IAAnB,CAAwB,IAAxB,CAA1B;AACA,qBAAK4C,uBAAL,GAA+B,KAAKC,kBAAL,CAAwB7C,IAAxB,CAA6B,IAA7B,CAA/B;;AAEA,qBAAKuC,MAAL,CAAYtC,gBAAZ,CAA6B,MAA7B,EAAqC,KAAKyC,kBAA1C,EAA8D,KAA9D;AACA,qBAAKH,MAAL,CAAYtC,gBAAZ,CAA6B,WAA7B,EAA0C,KAAK2C,uBAA/C,EAAwE,KAAxE;AACH,aARD,MAQO;AACH,qBAAKT,MAAL,CAAY,4BAAZ;AACH;AACJ;AACD,eAAO,KAAKW,OAAZ;AACH,K;;iCAMDD,kB,+BAAmBE,K,EAAO;AACtB,YAAIA,MAAM1E,GAAN,CAAU15B,OAAV,CAAkB,KAAKk9B,YAAvB,MAAyC,CAA7C,EAAgD;AAC5C,iBAAKmB,QAAL,CAAc,EAAE3E,KAAK0E,MAAM1E,GAAb,EAAd;AACH;AACJ,K;;iCACDsE,a,0BAAcM,O,EAAS;AACnB,aAAKd,MAAL,CAAYc,OAAZ;AACH,K;;iCAEDD,Q,qBAASzR,I,EAAM;AACX,aAAK2R,QAAL;;AAEAjmC,iBAAIqgC,KAAJ,CAAU,mEAAV;AACA,aAAKkE,QAAL,CAAcjQ,IAAd;AACH,K;;iCACD4Q,M,mBAAOc,O,EAAS;AACZ,aAAKC,QAAL;;AAEAjmC,iBAAIojC,KAAJ,CAAU4C,OAAV;AACA,aAAKxB,OAAL,CAAa,IAAI/iC,KAAJ,CAAUukC,OAAV,CAAb;AACH,K;;iCAEDE,K,oBAAQ;AACJ,aAAKD,QAAL;AACH,K;;iCAEDA,Q,uBAAW;AACP,YAAI,KAAKX,MAAT,EAAgB;AACZtlC,qBAAIqgC,KAAJ,CAAU,uCAAV;AACA,iBAAKiF,MAAL,CAAYa,mBAAZ,CAAgC,MAAhC,EAAwC,KAAKV,kBAA7C,EAAiE,KAAjE;AACA,iBAAKH,MAAL,CAAYa,mBAAZ,CAAgC,WAAhC,EAA6C,KAAKR,uBAAlD,EAA2E,KAA3E;AACA,iBAAKL,MAAL,CAAYY,KAAZ;AACH;AACD,aAAKZ,MAAL,GAAc,IAAd;AACH,K;;;;4BAtCa;AACV,mBAAO,KAAKjB,QAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;ACxDL;;;;;;+eAHA;AACA;;IAIa+B,a,WAAAA,a;;;AACT,iCACE;AAAA,+FADsE,EACtE;AAAA,oBADWhD,KACX,QADWA,KACX;AAAA,oBADkBiD,iBAClB,QADkBA,iBAClB;AAAA,oBADqCC,SACrC,QADqCA,SACrC;AAAA,oBADgD5W,KAChD,QADgDA,KAChD;AAAA,oBADuD6T,aACvD,QADuDA,aACvD;;AAAA;;AACG,oBAAI,CAACH,KAAL,EAAW;AACRpjC,iCAAIojC,KAAJ,CAAU,kCAAV;AACA,8BAAM,IAAI3hC,KAAJ,CAAU,OAAV,CAAN;AACH;;AAJH,6DAME,kBAAM4kC,qBAAqBjD,KAA3B,CANF;;AAQE,sBAAKlf,IAAL,GAAY,eAAZ;;AAEA,sBAAKkf,KAAL,GAAaA,KAAb;AACA,sBAAKiD,iBAAL,GAAyBA,iBAAzB;AACA,sBAAKC,SAAL,GAAiBA,SAAjB;;AAEA,sBAAK5W,KAAL,GAAaA,KAAb;AACA,sBAAK6T,aAAL,GAAqBA,aAArB;AAfF;AAgBD;;;EAlB8B9hC,K;;;;;;;;;;;;;;;;;;;ACFnC;;0JAHA;AACA;;IAIa8kC,K,WAAAA,K;AAET,mBAAYriB,IAAZ,EAAkB;AAAA;;AACd,aAAKsiB,KAAL,GAAatiB,IAAb;AACA,aAAKuiB,UAAL,GAAkB,EAAlB;AACH;;oBAED7F,U,uBAAWD,E,EAAI;AACX,aAAK8F,UAAL,CAAgBniC,IAAhB,CAAqBq8B,EAArB;AACH,K;;oBAEDG,a,0BAAcH,E,EAAI;AACd,YAAIiB,MAAM,KAAK6E,UAAL,CAAgBC,SAAhB,CAA0B;AAAA,mBAAQC,SAAShG,EAAjB;AAAA,SAA1B,CAAV;AACA,YAAIiB,OAAO,CAAX,EAAc;AACV,iBAAK6E,UAAL,CAAgBngC,MAAhB,CAAuBs7B,GAAvB,EAA4B,CAA5B;AACH;AACJ,K;;oBAEDgF,K,oBAAiB;AACb5mC,iBAAIqgC,KAAJ,CAAU,2BAA2B,KAAKmG,KAA1C;AACA,aAAK,IAAIpkC,IAAI,CAAb,EAAgBA,IAAI,KAAKqkC,UAAL,CAAgBpkC,MAApC,EAA4CD,GAA5C,EAAiD;AAAA;;AAC7C,+BAAKqkC,UAAL,EAAgBrkC,CAAhB;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;;;;AC5BL;AACA;;AAEA,IAAMykC,QAAQ;AACVjD;AAAA;AAAA;AAAA;;AAAA;AAAA;AAAA;;AAAA;AAAA,MAAa,UAAUjD,EAAV,EAAcP,QAAd,EAAwB;AACjC,eAAOwD,YAAYjD,EAAZ,EAAgBP,QAAhB,CAAP;AACH,KAFD,CADU;AAIVyD;AAAA;AAAA;AAAA;;AAAA;AAAA;AAAA;;AAAA;AAAA,MAAe,UAAUiD,MAAV,EAAkB;AAC7B,eAAOjD,cAAciD,MAAd,CAAP;AACH,KAFD;AAJU,CAAd;;AASA,IAAIC,UAAU,KAAd;AACA,IAAIC,UAAU,IAAd;;IAEanmC,M,WAAAA,M;;;;;WAEFomC,Q,uBAAW;AACdF,kBAAU,IAAV;AACH,K;;WAoBMG,iB,8BAAkBC,U,EAAY;AACjCH,kBAAUG,UAAV;AACH,K;;;;4BApBqB;AAClB,gBAAI,CAACJ,OAAL,EAAc;AACV,uBAAOK,QAAP;AACH;AACJ;;;4BAEyB;AACtB,gBAAI,CAACL,OAAD,IAAY,OAAO9lC,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAOomC,YAAP;AACH;AACJ;;;4BAE2B;AACxB,gBAAI,CAACN,OAAD,IAAY,OAAO9lC,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAOqmC,cAAP;AACH;AACJ;;;4BAM2B;AACxB,gBAAI,CAACP,OAAD,IAAY,OAAO9lC,MAAP,KAAkB,WAAlC,EAA+C;AAC3C,uBAAO+lC,WAAWO,cAAlB;AACH;AACJ;;;4BAEkB;AACf,gBAAI,CAACR,OAAL,EAAc;AACV,uBAAOF,KAAP;AACH;AACJ;;;;;;;;;;;;;;;;;;;;;;;AClDL;;AACA;;0JAJA;AACA;;IAKaW,e,WAAAA,e;;;;;8BAET1D,O,oBAAQC,M,EAAQ;AACZ,YAAI0D,QAAQ,IAAIC,0BAAJ,CAAiB3D,MAAjB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBgF,KAAhB,CAAP;AACH,K;;8BAEDvG,Q,qBAASE,G,EAAK;AACVphC,iBAAIqgC,KAAJ,CAAU,0BAAV;;AAEA,YAAI;AACAqH,uCAAaC,YAAb,CAA0BvG,GAA1B;AACA,mBAAOoB,QAAQC,OAAR,EAAP;AACH,SAHD,CAIA,OAAOzgC,CAAP,EAAU;AACN,mBAAOwgC,QAAQ8B,MAAR,CAAetiC,CAAf,CAAP;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;qjBCvBL;AACA;;AAEA;;;;AAEA,IAAM4lC,iBAAiB,KAAvB;;IAEaF,Y,WAAAA,Y;AAET,0BAAY3D,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI7B,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgB9B,OAAhB;AACA,kBAAK+B,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,aAAKzB,kBAAL,GAA0B,KAAKC,QAAL,CAAcC,IAAd,CAAmB,IAAnB,CAA1B;AACA9hC,eAAO+hC,gBAAP,CAAwB,SAAxB,EAAmC,KAAKH,kBAAxC,EAA4D,KAA5D;;AAEA,aAAKf,MAAL,GAAc7gC,OAAO8gC,QAAP,CAAgBC,aAAhB,CAA8B,QAA9B,CAAd;;AAEA;AACA,aAAKF,MAAL,CAAYG,KAAZ,CAAkBC,UAAlB,GAA+B,QAA/B;AACA,aAAKJ,MAAL,CAAYG,KAAZ,CAAkBE,QAAlB,GAA6B,UAA7B;AACA,aAAKL,MAAL,CAAYG,KAAZ,CAAkBG,OAAlB,GAA4B,MAA5B;AACA,aAAKN,MAAL,CAAYG,KAAZ,CAAkBI,KAAlB,GAA0B,CAA1B;AACA,aAAKP,MAAL,CAAYG,KAAZ,CAAkBK,MAAlB,GAA2B,CAA3B;;AAEArhC,eAAO8gC,QAAP,CAAgBY,IAAhB,CAAqBC,WAArB,CAAiC,KAAKd,MAAtC;AACH;;2BAEDmD,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AACxB,iBAAK8D,MAAL,CAAY,iBAAZ;AACH,SAFD,MAGK;AACD,gBAAI2C,UAAU9D,OAAO+D,oBAAP,IAA+BF,cAA7C;AACA5nC,qBAAIqgC,KAAJ,CAAU,0CAAV,EAAsDwH,OAAtD;AACA,iBAAKlE,MAAL,GAAc1iC,OAAO8mC,UAAP,CAAkB,KAAKC,QAAL,CAAcjF,IAAd,CAAmB,IAAnB,CAAlB,EAA4C8E,OAA5C,CAAd;AACA,iBAAK/F,MAAL,CAAYS,GAAZ,GAAkBwB,OAAO3C,GAAzB;AACH;;AAED,eAAO,KAAKyE,OAAZ;AACH,K;;2BAMDE,Q,qBAASzR,I,EAAM;AACX,aAAK2R,QAAL;;AAEAjmC,iBAAIqgC,KAAJ,CAAU,qDAAV;AACA,aAAKkE,QAAL,CAAcjQ,IAAd;AACH,K;;2BACD4Q,M,mBAAOc,O,EAAS;AACZ,aAAKC,QAAL;;AAEAjmC,iBAAIojC,KAAJ,CAAU4C,OAAV;AACA,aAAKxB,OAAL,CAAa,IAAI/iC,KAAJ,CAAUukC,OAAV,CAAb;AACH,K;;2BAEDE,K,oBAAQ;AACJ,aAAKD,QAAL;AACH,K;;2BAEDA,Q,uBAAW;AACP,YAAI,KAAKnE,MAAT,EAAiB;AACb9hC,qBAAIqgC,KAAJ,CAAU,uBAAV;;AAEAp/B,mBAAOklC,mBAAP,CAA2B,SAA3B,EAAsC,KAAKtD,kBAA3C,EAA+D,KAA/D;AACA5hC,mBAAOgnC,YAAP,CAAoB,KAAKtE,MAAzB;AACA1iC,mBAAO8gC,QAAP,CAAgBY,IAAhB,CAAqBuF,WAArB,CAAiC,KAAKpG,MAAtC;;AAEA,iBAAK6B,MAAL,GAAc,IAAd;AACA,iBAAK7B,MAAL,GAAc,IAAd;AACA,iBAAKe,kBAAL,GAA0B,IAA1B;AACH;AACJ,K;;2BAEDmF,Q,uBAAW;AACPhoC,iBAAIqgC,KAAJ,CAAU,sBAAV;AACA,aAAK6E,MAAL,CAAY,wBAAZ;AACH,K;;2BAEDpC,Q,qBAAS9gC,C,EAAG;AACRhC,iBAAIqgC,KAAJ,CAAU,sBAAV;;AAEA,YAAI,KAAKsD,MAAL,IACA3hC,EAAEihC,MAAF,KAAa,KAAKkF,OADlB,IAEAnmC,EAAEkhC,MAAF,KAAa,KAAKpB,MAAL,CAAYqB,aAF7B,EAGE;AACE,gBAAI/B,MAAMp/B,EAAEsyB,IAAZ;AACA,gBAAI8M,GAAJ,EAAS;AACL,qBAAK2E,QAAL,CAAc,EAAE3E,KAAKA,GAAP,EAAd;AACH,aAFD,MAGK;AACD,qBAAK8D,MAAL,CAAY,6BAAZ;AACH;AACJ;AACJ,K;;iBAMMyC,Y,yBAAavG,G,EAAK;AACrBphC,iBAAIqgC,KAAJ,CAAU,2BAAV;AACA,YAAIp/B,OAAOmnC,YAAX,EAAyB;AACrBhH,kBAAMA,OAAOngC,OAAOmmC,QAAP,CAAgBiB,IAA7B;AACA,gBAAIjH,GAAJ,EAAS;AACLphC,yBAAIqgC,KAAJ,CAAU,0DAAV;AACAp/B,uBAAOqnC,MAAP,CAAc5E,WAAd,CAA0BtC,GAA1B,EAA+BgG,SAASmB,QAAT,GAAoB,IAApB,GAA2BnB,SAASoB,IAAnE;AACH;AACJ;AACJ,K;;;;4BAtEa;AACV,mBAAO,KAAKnE,QAAZ;AACH;;;4BAuDa;AACV,mBAAO+C,SAASmB,QAAT,GAAoB,IAApB,GAA2BnB,SAASoB,IAA3C;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBCvGL;AACA;;AAEA;;;;IAEapoC,kB,WAAAA,kB;AACT,kCAAa;AAAA;;AACT,aAAKqF,KAAL,GAAa,EAAb;AACH;;iCAEDgjC,O,oBAAQ3U,G,EAAK;AACT9zB,iBAAIqgC,KAAJ,CAAU,4BAAV,EAAwCvM,GAAxC;AACA,eAAO,KAAKruB,KAAL,CAAWquB,GAAX,CAAP;AACH,K;;iCAED4U,O,oBAAQ5U,G,EAAK6U,K,EAAM;AACf3oC,iBAAIqgC,KAAJ,CAAU,4BAAV,EAAwCvM,GAAxC;AACA,aAAKruB,KAAL,CAAWquB,GAAX,IAAkB6U,KAAlB;AACH,K;;iCAEDC,U,uBAAW9U,G,EAAI;AACX9zB,iBAAIqgC,KAAJ,CAAU,+BAAV,EAA2CvM,GAA3C;AACA,eAAO,KAAKruB,KAAL,CAAWquB,GAAX,CAAP;AACH,K;;iCAMDA,G,gBAAI+U,K,EAAO;AACP,eAAO/mC,OAAOgnC,mBAAP,CAA2B,KAAKrjC,KAAhC,EAAuCojC,KAAvC,CAAP;AACH,K;;;;4BANY;AACT,mBAAO/mC,OAAOgnC,mBAAP,CAA2B,KAAKrjC,KAAhC,EAAuCpD,MAA9C;AACH;;;;;;;;;;;;;;;;;;;;;;;AC3BL;;AACA;;;;;;AAEO,IAAM0mC,8BAAW,4BAAY,EAAE9M,mBAAF,EAAO+M,2BAAP,EAAgBnS,qBAAhB,EAAsBpe,yBAAtB,EAA8BmO,+BAA9B,EAAyChc,6BAAzC,EAAmDq+B,iDAAnD,EAAZ,CAAjB,C;;;;;;;;;;;;;;;;;kBCEiBC,W;;AAFxB;;0JAHA;AACA;;AAIe,SAASA,WAAT,OAA8F;AAAA,QAAvEjN,GAAuE,QAAvEA,GAAuE;AAAA,QAAlE+M,OAAkE,QAAlEA,OAAkE;AAAA,QAAzDnS,IAAyD,QAAzDA,IAAyD;AAAA,QAAnDpe,MAAmD,QAAnDA,MAAmD;AAAA,QAA3CmO,SAA2C,QAA3CA,SAA2C;AAAA,QAAhChc,QAAgC,QAAhCA,QAAgC;AAAA,QAAtBq+B,kBAAsB,QAAtBA,kBAAsB;;AACzG;AAAA;AAAA;AAAA;;AAAA,iBAEWE,QAFX,qBAEoBC,GAFpB,EAEyB;AACjBppC,qBAAIqgC,KAAJ,CAAU,mBAAV;AACA,gBAAI;AACA,oBAAIgJ,QAAQpN,IAAIC,GAAJ,CAAQv3B,KAAR,CAAcykC,GAAd,CAAZ;AACA,uBAAO;AACHE,4BAAQD,MAAMpM,SADX;AAEHsM,6BAASF,MAAMnM;AAFZ,iBAAP;AAIH,aAND,CAME,OAAOl7B,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,CAAV;AACH;AACJ,SAbL;;AAAA,iBAeWwnC,WAfX,wBAeuBJ,GAfvB,EAe4BtV,GAf5B,EAeiC2V,MAfjC,EAeyCC,QAfzC,EAemDC,SAfnD,EAe8DC,GAf9D,EAemEC,eAfnE,EAeoF;AAC5E7pC,qBAAIqgC,KAAJ,CAAU,sBAAV;;AAEA,gBAAI;AACA,oBAAIvM,IAAIuC,GAAJ,KAAY,KAAhB,EAAuB;AACnB,wBAAIvC,IAAI9xB,CAAJ,IAAS8xB,IAAIlxB,CAAjB,EAAoB;AAChBkxB,8BAAMkV,QAAQxZ,MAAR,CAAesE,GAAf,CAAN;AACH,qBAFD,MAEO,IAAIA,IAAIgW,GAAJ,IAAWhW,IAAIgW,GAAJ,CAAQznC,MAAvB,EAA+B;AAClC,4BAAIuf,MAAMhX,SAASkpB,IAAIgW,GAAJ,CAAQ,CAAR,CAAT,CAAV;AACAhW,8BAAM+C,KAAKC,uBAAL,CAA6BlV,GAA7B,CAAN;AACH,qBAHM,MAGA;AACH5hB,iCAAIojC,KAAJ,CAAU,oDAAV,EAAgEtP,GAAhE;AACA,+BAAO0O,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,8BAAV,CAAf,CAAP;AACH;AACJ,iBAVD,MAUO,IAAIqyB,IAAIuC,GAAJ,KAAY,IAAhB,EAAsB;AACzB,wBAAIvC,IAAI8C,GAAJ,IAAW9C,IAAIhuB,CAAf,IAAoBguB,IAAIrqB,CAA5B,EAA+B;AAC3BqqB,8BAAMkV,QAAQxZ,MAAR,CAAesE,GAAf,CAAN;AACH,qBAFD,MAEO;AACH9zB,iCAAIojC,KAAJ,CAAU,mDAAV,EAA+DtP,GAA/D;AACA,+BAAO0O,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACJ,iBAPM,MAOA;AACHzB,6BAAIojC,KAAJ,CAAU,4CAAV,EAAwDtP,OAAOA,IAAIuC,GAAnE;AACA,2BAAOmM,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,SAAkCqyB,IAAIuC,GAAhD,CAAf,CAAP;AACH;;AAED,uBAAO0S,SAASgB,YAAT,CAAsBX,GAAtB,EAA2BtV,GAA3B,EAAgC2V,MAAhC,EAAwCC,QAAxC,EAAkDC,SAAlD,EAA6DC,GAA7D,EAAkEC,eAAlE,CAAP;AACH,aAxBD,CAwBE,OAAO7nC,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,KAAKA,EAAEgkC,OAAP,IAAkBhkC,CAA5B;AACA,uBAAOwgC,QAAQ8B,MAAR,CAAe,uBAAf,CAAP;AACH;AACJ,SA9CL;;AAAA,iBAgDW0F,qBAhDX,kCAgDiCZ,GAhDjC,EAgDsCK,MAhDtC,EAgD8CC,QAhD9C,EAgDwDC,SAhDxD,EAgDmEC,GAhDnE,EAgDwEC,eAhDxE,EAgDyF;AACjF,gBAAI,CAACF,SAAL,EAAgB;AACZA,4BAAY,CAAZ;AACH;;AAED,gBAAI,CAACC,GAAL,EAAU;AACNA,sBAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAN;AACH;;AAED,gBAAIL,UAAUR,SAASI,QAAT,CAAkBC,GAAlB,EAAuBG,OAArC;;AAEA,gBAAI,CAACA,QAAQ9L,GAAb,EAAkB;AACdz9B,yBAAIojC,KAAJ,CAAU,gDAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;AACD,gBAAI8nC,QAAQ9L,GAAR,KAAgBgM,MAApB,EAA4B;AACxBzpC,yBAAIojC,KAAJ,CAAU,gDAAV,EAA4DmG,QAAQ9L,GAApE;AACA,uBAAO+E,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,8BAA8B8nC,QAAQ9L,GAAhD,CAAf,CAAP;AACH;;AAED,gBAAI,CAAC8L,QAAQ5L,GAAb,EAAkB;AACd39B,yBAAIojC,KAAJ,CAAU,6CAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,gBAAIwoC,gBAAgBV,QAAQ5L,GAAR,KAAgB+L,QAAhB,IAA6B3+B,MAAM4nB,OAAN,CAAc4W,QAAQ5L,GAAtB,KAA8B4L,QAAQ5L,GAAR,CAAYj2B,OAAZ,CAAoBgiC,QAApB,KAAiC,CAAhH;AACA,gBAAI,CAACO,aAAL,EAAoB;AAChBjqC,yBAAIojC,KAAJ,CAAU,kDAAV,EAA8DmG,QAAQ5L,GAAtE;AACA,uBAAO6E,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gCAAgC8nC,QAAQ5L,GAAlD,CAAf,CAAP;AACH;AACD,gBAAI4L,QAAQW,GAAR,IAAeX,QAAQW,GAAR,KAAgBR,QAAnC,EAA6C;AACzC1pC,yBAAIojC,KAAJ,CAAU,6CAAV,EAAyDmG,QAAQW,GAAjE;AACA,uBAAO1H,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAA2B8nC,QAAQW,GAA7C,CAAf,CAAP;AACH;;AAED,gBAAI,CAACL,eAAL,EAAsB;AAClB,oBAAIM,WAAWP,MAAMD,SAArB;AACA,oBAAIS,WAAWR,MAAMD,SAArB;;AAEA,oBAAI,CAACJ,QAAQtL,GAAb,EAAkB;AACdj+B,6BAAIojC,KAAJ,CAAU,6CAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,oBAAI0oC,WAAWZ,QAAQtL,GAAvB,EAA4B;AACxBj+B,6BAAIojC,KAAJ,CAAU,6CAAV,EAAyDmG,QAAQtL,GAAjE;AACA,2BAAOuE,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAA2B8nC,QAAQtL,GAA7C,CAAf,CAAP;AACH;;AAED,oBAAIsL,QAAQvL,GAAR,IAAemM,WAAWZ,QAAQvL,GAAtC,EAA2C;AACvCh+B,6BAAIojC,KAAJ,CAAU,6CAAV,EAAyDmG,QAAQvL,GAAjE;AACA,2BAAOwE,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAA2B8nC,QAAQvL,GAA7C,CAAf,CAAP;AACH;;AAED,oBAAI,CAACuL,QAAQ74B,GAAb,EAAkB;AACd1Q,6BAAIojC,KAAJ,CAAU,6CAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQ74B,GAAR,GAAc05B,QAAlB,EAA4B;AACxBpqC,6BAAIojC,KAAJ,CAAU,2CAAV,EAAuDmG,QAAQ74B,GAA/D;AACA,2BAAO8xB,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,wBAAwB8nC,QAAQ74B,GAA1C,CAAf,CAAP;AACH;AACJ;;AAED,mBAAO8xB,QAAQC,OAAR,CAAgB8G,OAAhB,CAAP;AACH,SA/GL;;AAAA,iBAiHWQ,YAjHX,yBAiHwBX,GAjHxB,EAiH6BtV,GAjH7B,EAiHkC2V,MAjHlC,EAiH0CC,QAjH1C,EAiHoDC,SAjHpD,EAiH+DC,GAjH/D,EAiHoEC,eAjHpE,EAiHqF;;AAE7E,mBAAOd,SAASiB,qBAAT,CAA+BZ,GAA/B,EAAoCK,MAApC,EAA4CC,QAA5C,EAAsDC,SAAtD,EAAiEC,GAAjE,EAAsEC,eAAtE,EAAuFQ,IAAvF,CAA4F,mBAAW;AAC1G,oBAAI;AACA,wBAAI,CAACpO,IAAIC,GAAJ,CAAQ1L,MAAR,CAAe4Y,GAAf,EAAoBtV,GAApB,EAAyBmV,kBAAzB,CAAL,EAAmD;AAC/CjpC,iCAAIojC,KAAJ,CAAU,oDAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;;AAED,2BAAO8nC,OAAP;AACH,iBAPD,CAOE,OAAOvnC,CAAP,EAAU;AACRhC,6BAAIojC,KAAJ,CAAUphC,KAAKA,EAAEgkC,OAAP,IAAkBhkC,CAA5B;AACA,2BAAOwgC,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACJ,aAZM,CAAP;AAaH,SAhIL;;AAAA,iBAkIWkrB,UAlIX,uBAkIsBgc,KAlItB,EAkI6B/b,GAlI7B,EAkIkC;AAC1B,gBAAI;AACA,uBAAOnU,OAAOiB,IAAP,CAAYiT,UAAZ,CAAuBgc,KAAvB,EAA8B/b,GAA9B,CAAP;AACH,aAFD,CAEE,OAAO5qB,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,CAAV;AACH;AACJ,SAxIL;;AAAA,iBA0IWsoC,cA1IX,2BA0I0B3B,KA1I1B,EA0IiC;AACzB,gBAAI;AACA,uBAAO/hB,UAAU+hB,KAAV,CAAP;AACH,aAFD,CAEE,OAAO3mC,CAAP,EAAU;AACRhC,yBAAIojC,KAAJ,CAAUphC,CAAV;AACH;AACJ,SAhJL;;AAAA;AAAA;AAkJH;;;;;;;;;;;;;;;;;;;;ACrJD;;AACA;;0JAJA;AACA;;IAKauoC,W,WAAAA,W;AACT,2BAIE;AAAA,YAHEC,sBAGF,uEAH2B,IAG3B;AAAA,YAFEC,kBAEF,uEAFuB5pC,eAAO0mC,cAE9B;AAAA,YADEmD,UACF,uEADe,IACf;;AAAA;;AACE,YAAIF,0BAA0Bz/B,MAAM4nB,OAAN,CAAc6X,sBAAd,CAA9B,EACA;AACI,iBAAKG,aAAL,GAAqBH,uBAAuBpmC,KAAvB,EAArB;AACH,SAHD,MAKA;AACI,iBAAKumC,aAAL,GAAqB,EAArB;AACH;AACD,aAAKA,aAAL,CAAmBrmC,IAAnB,CAAwB,kBAAxB;AACA,YAAIomC,UAAJ,EAAgB;AACZ,iBAAKC,aAAL,CAAmBrmC,IAAnB,CAAwB,iBAAxB;AACH;;AAED,aAAKsmC,eAAL,GAAuBH,kBAAvB;AACA,aAAKI,WAAL,GAAmBH,UAAnB;AACH;;0BAEDI,O,oBAAQ1J,G,EAAKiI,K,EAAO;AAAA;;AAChB,YAAI,CAACjI,GAAL,EAAS;AACLphC,qBAAIojC,KAAJ,CAAU,oCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,4BAAV,EAAwCe,GAAxC;;AAEA,eAAO,IAAIoB,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;;AAEpC,gBAAIyG,MAAM,IAAI,MAAKH,eAAT,EAAV;AACAG,gBAAIvF,IAAJ,CAAS,KAAT,EAAgBpE,GAAhB;;AAEA,gBAAI4J,sBAAsB,MAAKL,aAA/B;AACA,gBAAID,aAAa,MAAKG,WAAtB;;AAEAE,gBAAIrI,MAAJ,GAAa,YAAW;AACpB1iC,yBAAIqgC,KAAJ,CAAU,qDAAV,EAAiE0K,IAAIE,MAArE;;AAEA,oBAAIF,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuB3E,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAIyE,SAAS,iBAAb,EAAgC;AAC5BV,uCAAWK,GAAX,EAAgBV,IAAhB,CAAqB5H,OAArB,EAA8B6B,MAA9B;AACA;AACH;;AAED,4BAAI8G,KAAJ,EAAW;AACP,gCAAI;AACA3I,wCAAQzc,KAAKrhB,KAAL,CAAWomC,IAAIQ,YAAf,CAAR;AACA;AACH,6BAHD,CAIA,OAAOvpC,CAAP,EAAU;AACNhC,yCAAIojC,KAAJ,CAAU,kDAAV,EAA8DphC,EAAEgkC,OAAhE;AACA1B,uCAAOtiC,CAAP;AACA;AACH;AACJ;AACJ;;AAEDsiC,2BAAO7iC,MAAM,oCAAoCypC,WAApC,GAAkD,cAAlD,GAAmE9J,GAAzE,CAAP;AACH,iBA9BD,MA+BK;AACDkD,2BAAO7iC,MAAMspC,IAAIS,UAAJ,GAAiB,IAAjB,GAAwBT,IAAIE,MAA5B,GAAqC,GAA3C,CAAP;AACH;AACJ,aArCD;;AAuCAF,gBAAIU,OAAJ,GAAc,YAAW;AACrBzrC,yBAAIojC,KAAJ,CAAU,oCAAV;AACAkB,uBAAO7iC,MAAM,eAAN,CAAP;AACH,aAHD;;AAKA,gBAAI4nC,KAAJ,EAAW;AACPrpC,yBAAIqgC,KAAJ,CAAU,iEAAV;AACA0K,oBAAIW,gBAAJ,CAAqB,eAArB,EAAsC,YAAYrC,KAAlD;AACH;;AAED0B,gBAAItH,IAAJ;AACH,SA1DM,CAAP;AA2DH,K;;0BAEDkI,Q,qBAASvK,G,EAAKmI,O,EAAS;AAAA;;AACnB,YAAI,CAACnI,GAAL,EAAS;AACLphC,qBAAIojC,KAAJ,CAAU,qCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,6BAAV,EAAyCe,GAAzC;;AAEA,eAAO,IAAIoB,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;;AAEpC,gBAAIyG,MAAM,IAAI,OAAKH,eAAT,EAAV;AACAG,gBAAIvF,IAAJ,CAAS,MAAT,EAAiBpE,GAAjB;;AAEA,gBAAI4J,sBAAsB,OAAKL,aAA/B;;AAEAI,gBAAIrI,MAAJ,GAAa,YAAW;AACpB1iC,yBAAIqgC,KAAJ,CAAU,sDAAV,EAAkE0K,IAAIE,MAAtE;;AAEA,oBAAIF,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuB3E,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAIyE,KAAJ,EAAW;AACP,gCAAI;AACA3I,wCAAQzc,KAAKrhB,KAAL,CAAWomC,IAAIQ,YAAf,CAAR;AACA;AACH,6BAHD,CAIA,OAAOvpC,CAAP,EAAU;AACNhC,yCAAIojC,KAAJ,CAAU,mDAAV,EAA+DphC,EAAEgkC,OAAjE;AACA1B,uCAAOtiC,CAAP;AACA;AACH;AACJ;AACJ;;AAEDsiC,2BAAO7iC,MAAM,oCAAoCypC,WAApC,GAAkD,cAAlD,GAAmE9J,GAAzE,CAAP;AACA;AACH;;AAED,oBAAI2J,IAAIE,MAAJ,KAAe,GAAnB,EAAwB;;AAEpB,wBAAIC,cAAcH,IAAII,iBAAJ,CAAsB,cAAtB,CAAlB;AACA,wBAAID,WAAJ,EAAiB;;AAEb,4BAAIE,QAAQJ,oBAAoBK,IAApB,CAAyB,gBAAM;AACvC,gCAAIH,YAAYI,UAAZ,CAAuB3E,IAAvB,CAAJ,EAAkC;AAC9B,uCAAO,IAAP;AACH;AACJ,yBAJW,CAAZ;;AAMA,4BAAIyE,KAAJ,EAAW;AACP,gCAAI;AACA,oCAAI7B,UAAUvjB,KAAKrhB,KAAL,CAAWomC,IAAIQ,YAAf,CAAd;AACA,oCAAIhC,WAAWA,QAAQnG,KAAvB,EAA8B;AAC1BpjC,6CAAIojC,KAAJ,CAAU,2CAAV,EAAuDmG,QAAQnG,KAA/D;AACAkB,2CAAO,IAAI7iC,KAAJ,CAAU8nC,QAAQnG,KAAlB,CAAP;AACA;AACH;AACJ,6BAPD,CAQA,OAAOphC,CAAP,EAAU;AACNhC,yCAAIojC,KAAJ,CAAU,mDAAV,EAA+DphC,EAAEgkC,OAAjE;AACA1B,uCAAOtiC,CAAP;AACA;AACH;AACJ;AACJ;AACJ;;AAEDsiC,uBAAO7iC,MAAMspC,IAAIS,UAAJ,GAAiB,IAAjB,GAAwBT,IAAIE,MAA5B,GAAqC,GAA3C,CAAP;AACH,aA7DD;;AA+DAF,gBAAIU,OAAJ,GAAc,YAAW;AACrBzrC,yBAAIojC,KAAJ,CAAU,qCAAV;AACAkB,uBAAO7iC,MAAM,eAAN,CAAP;AACH,aAHD;;AAKA,gBAAIkhC,OAAO,EAAX;AACA,iBAAI,IAAI7O,GAAR,IAAeyV,OAAf,EAAwB;;AAEpB,oBAAIZ,QAAQY,QAAQzV,GAAR,CAAZ;;AAEA,oBAAI6U,KAAJ,EAAW;;AAEP,wBAAIhG,KAAKtgC,MAAL,GAAc,CAAlB,EAAqB;AACjBsgC,gCAAQ,GAAR;AACH;;AAEDA,4BAAQr9B,mBAAmBwuB,GAAnB,CAAR;AACA6O,4BAAQ,GAAR;AACAA,4BAAQr9B,mBAAmBqjC,KAAnB,CAAR;AACH;AACJ;;AAEDoC,gBAAIW,gBAAJ,CAAqB,cAArB,EAAqC,mCAArC;AACAX,gBAAItH,IAAJ,CAASd,IAAT;AACH,SA9FM,CAAP;AA+FH,K;;;;;;;;;;;;;;;;;;;;;;;;;ACzML;AACA;;AAEA,IAAIiJ,YAAY;AACZvL,SADY,mBACL,CAAE,CADG;AAEZwL,QAFY,kBAEN,CAAE,CAFI;AAGZC,QAHY,kBAGN,CAAE,CAHI;AAIZ1I,SAJY,mBAIL,CAAE;AAJG,CAAhB;;AAOA,IAAM2I,OAAO,CAAb;AACA,IAAMC,QAAQ,CAAd;AACA,IAAMC,OAAO,CAAb;AACA,IAAMC,OAAO,CAAb;AACA,IAAMC,QAAQ,CAAd;;AAEA,IAAIC,eAAJ;AACA,IAAIC,cAAJ;;IAEarsC,G,WAAAA,G;;;;;QAOFwF,K,oBAAO;AACV6mC,gBAAQH,IAAR;AACAE,iBAASR,SAAT;AACH,K;;QA+BMvL,K,oBAAc;AACjB,YAAIgM,SAASF,KAAb,EAAmB;AAAA,8CADPG,IACO;AADPA,oBACO;AAAA;;AACfF,mBAAO/L,KAAP,CAAal9B,KAAb,CAAmBipC,MAAnB,EAA2BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA3B;AACH;AACJ,K;;QACMT,I,mBAAa;AAChB,YAAIQ,SAASH,IAAb,EAAkB;AAAA,+CADPI,IACO;AADPA,oBACO;AAAA;;AACdF,mBAAOP,IAAP,CAAY1oC,KAAZ,CAAkBipC,MAAlB,EAA0BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA1B;AACH;AACJ,K;;QACMR,I,mBAAa;AAChB,YAAIO,SAASJ,IAAb,EAAkB;AAAA,+CADPK,IACO;AADPA,oBACO;AAAA;;AACdF,mBAAON,IAAP,CAAY3oC,KAAZ,CAAkBipC,MAAlB,EAA0BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA1B;AACH;AACJ,K;;QACMlJ,K,oBAAc;AACjB,YAAIiJ,SAASL,KAAb,EAAmB;AAAA,+CADPM,IACO;AADPA,oBACO;AAAA;;AACfF,mBAAOhJ,KAAP,CAAajgC,KAAb,CAAmBipC,MAAnB,EAA2BrhC,MAAMwhC,IAAN,CAAWD,IAAX,CAA3B;AACH;AACJ,K;;;;4BA3DiB;AAAC,mBAAOP,IAAP;AAAY;;;4BACZ;AAAC,mBAAOC,KAAP;AAAa;;;4BACf;AAAC,mBAAOC,IAAP;AAAY;;;4BACb;AAAC,mBAAOC,IAAP;AAAY;;;4BACZ;AAAC,mBAAOC,KAAP;AAAa;;;4BAOf;AACd,mBAAOE,KAAP;AACH,S;0BACgB1D,K,EAAM;AACnB,gBAAIoD,QAAQpD,KAAR,IAAiBA,SAASwD,KAA9B,EAAoC;AAChCE,wBAAQ1D,KAAR;AACH,aAFD,MAGK;AACD,sBAAM,IAAIlnC,KAAJ,CAAU,mBAAV,CAAN;AACH;AACJ;;;4BAEkB;AACf,mBAAO2qC,MAAP;AACH,S;0BACiBzD,K,EAAM;AACpB,gBAAI,CAACA,MAAMtI,KAAP,IAAgBsI,MAAMkD,IAA1B,EAAgC;AAC5B;AACAlD,sBAAMtI,KAAN,GAAcsI,MAAMkD,IAApB;AACH;;AAED,gBAAIlD,MAAMtI,KAAN,IAAesI,MAAMkD,IAArB,IAA6BlD,MAAMmD,IAAnC,IAA2CnD,MAAMvF,KAArD,EAA2D;AACvDgJ,yBAASzD,KAAT;AACH,aAFD,MAGK;AACD,sBAAM,IAAIlnC,KAAJ,CAAU,gBAAV,CAAN;AACH;AACJ;;;;;;AAwBLzB,IAAIwF,KAAJ,G;;;;;;;;;;;;;;;;;;;qjBClFA;AACA;;AAEA;;AACA;;;;AAEA,IAAMgnC,sBAAsB,kCAA5B;;IAEajsC,e,WAAAA,e;AACT,6BAAYksC,QAAZ,EAAqD;AAAA,YAA/BC,eAA+B,uEAAbnC,wBAAa;;AAAA;;AACjD,YAAI,CAACkC,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,wDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,CAAoB,CAAC,0BAAD,CAApB,CAApB;AACH;;8BAsBDG,W,0BAAc;AAAA;;AACV,YAAI,KAAKF,SAAL,CAAetH,QAAnB,EAA6B;AACzBrlC,qBAAIqgC,KAAJ,CAAU,+DAAV;AACA,mBAAOmC,QAAQC,OAAR,CAAgB,KAAKkK,SAAL,CAAetH,QAA/B,CAAP;AACH;;AAED,YAAI,CAAC,KAAKyH,WAAV,EAAuB;AACnB9sC,qBAAIojC,KAAJ,CAAU,iFAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,oDAAV,CAAf,CAAP;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,oDAAV,EAAgE,KAAKyM,WAArE;;AAEA,eAAO,KAAKF,YAAL,CAAkB9B,OAAlB,CAA0B,KAAKgC,WAA/B,EACFzC,IADE,CACG,oBAAY;AACdrqC,qBAAIqgC,KAAJ,CAAU,4CAAV;AACA,kBAAKsM,SAAL,CAAetH,QAAf,GAA0BA,QAA1B;AACA,mBAAOA,QAAP;AACH,SALE,CAAP;AAMH,K;;8BAED0H,S,wBAAY;AACR,eAAO,KAAKC,oBAAL,CAA0B,QAA1B,CAAP;AACH,K;;8BAEDC,wB,uCAA2B;AACvB,eAAO,KAAKD,oBAAL,CAA0B,wBAA1B,CAAP;AACH,K;;8BAEDE,mB,kCAAsB;AAClB,eAAO,KAAKF,oBAAL,CAA0B,mBAA1B,CAAP;AACH,K;;8BAEDG,gB,+BAAgC;AAAA,YAAfC,QAAe,uEAAN,IAAM;;AAC5B,eAAO,KAAKJ,oBAAL,CAA0B,gBAA1B,EAA4CI,QAA5C,CAAP;AACH,K;;8BAEDC,qB,oCAAwB;AACpB,eAAO,KAAKL,oBAAL,CAA0B,sBAA1B,EAAkD,IAAlD,CAAP;AACH,K;;8BAEDM,qB,oCAAwB;AACpB,eAAO,KAAKN,oBAAL,CAA0B,sBAA1B,EAAkD,IAAlD,CAAP;AACH,K;;8BAEDO,qB,oCAAwB;AACpB,eAAO,KAAKP,oBAAL,CAA0B,qBAA1B,EAAiD,IAAjD,CAAP;AACH,K;;8BAEDQ,e,8BAAkB;AACd,eAAO,KAAKR,oBAAL,CAA0B,UAA1B,EAAsC,IAAtC,CAAP;AACH,K;;8BAEDA,oB,iCAAqB9oB,I,EAAsB;AAAA,YAAhBkpB,QAAgB,uEAAP,KAAO;;AACvCptC,iBAAIqgC,KAAJ,CAAU,8CAA8Cnc,IAAxD;;AAEA,eAAO,KAAK2oB,WAAL,GAAmBxC,IAAnB,CAAwB,oBAAY;AACvCrqC,qBAAIqgC,KAAJ,CAAU,wDAAV;;AAEA,gBAAIgF,SAASnhB,IAAT,MAAmB/iB,SAAvB,EAAkC;;AAE9B,oBAAIisC,aAAa,IAAjB,EAAuB;AACnBptC,6BAAI8rC,IAAJ,CAAS,sFAAsF5nB,IAA/F;AACA,2BAAO/iB,SAAP;AACH,iBAHD,MAIK;AACDnB,6BAAIojC,KAAJ,CAAU,6EAA6Elf,IAAvF;AACA,0BAAM,IAAIziB,KAAJ,CAAU,wCAAwCyiB,IAAlD,CAAN;AACH;AACJ;;AAED,mBAAOmhB,SAASnhB,IAAT,CAAP;AACH,SAhBM,CAAP;AAiBH,K;;8BAEDupB,c,6BAAiB;AAAA;;AACb,YAAI,KAAKd,SAAL,CAAee,WAAnB,EAAgC;AAC5B1tC,qBAAIqgC,KAAJ,CAAU,qEAAV;AACA,mBAAOmC,QAAQC,OAAR,CAAgB,KAAKkK,SAAL,CAAee,WAA/B,CAAP;AACH;;AAED,eAAO,KAAKV,oBAAL,CAA0B,UAA1B,EAAsC3C,IAAtC,CAA2C,oBAAY;AAC1DrqC,qBAAIqgC,KAAJ,CAAU,mDAAV,EAA+DsN,QAA/D;;AAEA,mBAAO,OAAKf,YAAL,CAAkB9B,OAAlB,CAA0B6C,QAA1B,EAAoCtD,IAApC,CAAyC,kBAAU;AACtDrqC,yBAAIqgC,KAAJ,CAAU,kDAAV,EAA8DuN,MAA9D;;AAEA,oBAAI,CAACA,OAAO1tB,IAAZ,EAAkB;AACdlgB,6BAAIojC,KAAJ,CAAU,wDAAV;AACA,0BAAM,IAAI3hC,KAAJ,CAAU,wBAAV,CAAN;AACH;;AAED,uBAAKkrC,SAAL,CAAee,WAAf,GAA6BE,OAAO1tB,IAApC;AACA,uBAAO,OAAKysB,SAAL,CAAee,WAAtB;AACH,aAVM,CAAP;AAWH,SAdM,CAAP;AAeH,K;;;;4BApHiB;AACd,gBAAI,CAAC,KAAKG,YAAV,EAAwB;AACpB,oBAAI,KAAKlB,SAAL,CAAeG,WAAnB,EAAgC;AAC5B,yBAAKe,YAAL,GAAoB,KAAKlB,SAAL,CAAeG,WAAnC;AACH,iBAFD,MAGK;AACD,yBAAKe,YAAL,GAAoB,KAAKlB,SAAL,CAAemB,SAAnC;;AAEA,wBAAI,KAAKD,YAAL,IAAqB,KAAKA,YAAL,CAAkBnmC,OAAlB,CAA0B8kC,mBAA1B,IAAiD,CAA1E,EAA6E;AACzE,4BAAI,KAAKqB,YAAL,CAAkB,KAAKA,YAAL,CAAkBxrC,MAAlB,GAA2B,CAA7C,MAAoD,GAAxD,EAA6D;AACzD,iCAAKwrC,YAAL,IAAqB,GAArB;AACH;AACD,6BAAKA,YAAL,IAAqBrB,mBAArB;AACH;AACJ;AACJ;;AAED,mBAAO,KAAKqB,YAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBCrCL;AACA;;AAEA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;IAEa5tC,U,WAAAA,U;AACT,0BAA2B;AAAA,YAAfwsC,QAAe,uEAAJ,EAAI;;AAAA;;AACvB,YAAIA,oBAAoBvsC,sCAAxB,EAA4C;AACxC,iBAAKysC,SAAL,GAAiBF,QAAjB;AACH,SAFD,MAGK;AACD,iBAAKE,SAAL,GAAiB,IAAIzsC,sCAAJ,CAAuBusC,QAAvB,CAAjB;AACH;AACJ;;yBAmBDsB,mB,kCAQE;AAAA;;AAAA,uFAFoH,EAEpH;AAAA,YAPEC,aAOF,QAPEA,aAOF;AAAA,YAPiBC,KAOjB,QAPiBA,KAOjB;AAAA,YAPwBrJ,YAOxB,QAPwBA,YAOxB;AAAA,YAHEtQ,IAGF,QAHEA,IAGF;AAAA,YAHQ5E,KAGR,QAHQA,KAGR;AAAA,YAHewe,MAGf,QAHeA,MAGf;AAAA,YAHuB9L,OAGvB,QAHuBA,OAGvB;AAAA,YAHgC+L,OAGhC,QAHgCA,OAGhC;AAAA,YAHyCC,UAGzC,QAHyCA,UAGzC;AAAA,YAHqDC,aAGrD,QAHqDA,aAGrD;AAAA,YAHoEC,UAGpE,QAHoEA,UAGpE;AAAA,YAHgFC,UAGhF,QAHgFA,UAGhF;AAAA,YAFEC,QAEF,QAFEA,QAEF;AAAA,YAFYxH,OAEZ,QAFYA,OAEZ;AAAA,YAFqByH,WAErB,QAFqBA,WAErB;AAAA,YAFkCC,aAElC,QAFkCA,aAElC;AAAA,YAFiDC,gBAEjD,QAFiDA,gBAEjD;AAAA,YAFmEC,gBAEnE,QAFmEA,gBAEnE;AAAA,YAFqFC,YAErF,QAFqFA,YAErF;AAAA,YAFmGC,YAEnG,QAFmGA,YAEnG;;AAAA,YADEC,UACF;;AACE/uC,iBAAIqgC,KAAJ,CAAU,gCAAV;;AAEA,YAAIc,YAAY,KAAKwL,SAAL,CAAexL,SAA/B;AACA6M,wBAAgBA,iBAAiB,KAAKrB,SAAL,CAAeqB,aAAhD;AACAC,gBAAQA,SAAS,KAAKtB,SAAL,CAAesB,KAAhC;AACArJ,uBAAeA,gBAAgB,KAAK+H,SAAL,CAAe/H,YAA9C;;AAEA;AACAsJ,iBAASA,UAAU,KAAKvB,SAAL,CAAeuB,MAAlC;AACA9L,kBAAUA,WAAW,KAAKuK,SAAL,CAAevK,OAApC;AACA+L,kBAAUA,WAAW,KAAKxB,SAAL,CAAewB,OAApC;AACAC,qBAAaA,cAAc,KAAKzB,SAAL,CAAeyB,UAA1C;AACAG,qBAAaA,cAAc,KAAK5B,SAAL,CAAe4B,UAA1C;AACAC,mBAAWA,YAAY,KAAK7B,SAAL,CAAe6B,QAAtC;AACAE,wBAAgBA,iBAAiB,KAAK/B,SAAL,CAAe+B,aAAhD;AACAC,2BAAmBA,oBAAoB,KAAKhC,SAAL,CAAegC,gBAAtD;AACAC,2BAAmBA,oBAAoB,KAAKjC,SAAL,CAAeiC,gBAAtD;;AAEA,YAAId,YAAY,KAAKnB,SAAL,CAAemB,SAA/B;;AAEA,YAAIkB,6BAAcC,MAAd,CAAqBjB,aAArB,KAAuCA,kBAAkB,MAA7D,EAAqE;AACjE,mBAAOxL,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6CAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsBjC,wBAAtB,GAAiD5C,IAAjD,CAAsD,eAAO;AAChErqC,qBAAIqgC,KAAJ,CAAU,iEAAV,EAA6Ee,GAA7E;;AAEA,gBAAI+N,gBAAgB,IAAIH,4BAAJ,CAAkB;AAClC5N,wBADkC;AAElCD,oCAFkC;AAGlCyD,0CAHkC;AAIlCoJ,4CAJkC;AAKlCC,4BALkC;AAMlC3Z,sBAAMA,QAAQ5E,KANoB;AAOlCoe,oCAPkC;AAQlCI,8BARkC,EAQ1B9L,gBAR0B,EAQjB+L,gBARiB,EAQRC,sBARQ,EAQIC,4BARJ,EAQmBC,sBARnB,EAQ+BC,sBAR/B;AASlCC,kCATkC,EASxBxH,gBATwB,EASfyH,wBATe,EASFE,kCATE,EASgBC,kCAThB,EASkCC,0BATlC,EASgDH,4BAThD;AAUlCU,+BAAe,MAAKzC,SAAL,CAAeyC,aAVI;AAWlCN;AAXkC,aAAlB,CAApB;;AAcA,gBAAIO,cAAcF,cAAczf,KAAhC;AACAqf,yBAAaA,cAAc,MAAKO,WAAhC;;AAEA,mBAAOP,WAAWQ,GAAX,CAAeF,YAAY7T,EAA3B,EAA+B6T,YAAYG,eAAZ,EAA/B,EAA8DnF,IAA9D,CAAmE,YAAM;AAC5E,uBAAO8E,aAAP;AACH,aAFM,CAAP;AAGH,SAvBM,CAAP;AAwBH,K;;yBAEDM,uB,oCAAwBrO,G,EAAK2N,U,EAAiC;AAAA,YAArBW,WAAqB,uEAAP,KAAO;;AAC1D1vC,iBAAIqgC,KAAJ,CAAU,oCAAV;;AAEA,YAAIsP,WAAW,KAAKhD,SAAL,CAAe+B,aAAf,KAAiC,OAAjC,IACV,CAAC,KAAK/B,SAAL,CAAe+B,aAAhB,IAAiCM,6BAAcC,MAAd,CAAqB,KAAKtC,SAAL,CAAeqB,aAApC,CADtC;AAEA,YAAI4B,YAAYD,WAAW,GAAX,GAAiB,GAAjC;;AAEA,YAAIE,WAAW,IAAIC,8BAAJ,CAAmB1O,GAAnB,EAAwBwO,SAAxB,CAAf;;AAEA,YAAI,CAACC,SAASngB,KAAd,EAAqB;AACjB1vB,qBAAIojC,KAAJ,CAAU,0DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAEDstC,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,YAAIS,WAAWL,cAAcX,WAAWiB,MAAX,CAAkBjN,IAAlB,CAAuBgM,UAAvB,CAAd,GAAmDA,WAAW9P,GAAX,CAAe8D,IAAf,CAAoBgM,UAApB,CAAlE;;AAEA,eAAOgB,SAASF,SAASngB,KAAlB,EAAyB2a,IAAzB,CAA8B,6BAAqB;AACtD,gBAAI,CAAC4F,iBAAL,EAAwB;AACpBjwC,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,oCAAV,CAAN;AACH;;AAED,gBAAIiuB,QAAQwgB,yBAAYC,iBAAZ,CAA8BF,iBAA9B,CAAZ;AACA,mBAAO,EAACvgB,YAAD,EAAQmgB,kBAAR,EAAP;AACH,SARM,CAAP;AASH,K;;yBAEDO,qB,kCAAsBhP,G,EAAK2N,U,EAAY;AAAA;;AACnC/uC,iBAAIqgC,KAAJ,CAAU,kCAAV;;AAEA,eAAO,KAAKoP,uBAAL,CAA6BrO,GAA7B,EAAkC2N,UAAlC,EAA8C,IAA9C,EAAoD1E,IAApD,CAAyD,iBAAuB;AAAA,gBAArB3a,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,SAAdA,QAAc;;AACnF7vC,qBAAIqgC,KAAJ,CAAU,oFAAV;AACA,mBAAO,OAAKgQ,UAAL,CAAgBC,sBAAhB,CAAuC5gB,KAAvC,EAA8CmgB,QAA9C,CAAP;AACH,SAHM,CAAP;AAIH,K;;yBAEDU,oB,mCAEE;AAAA;;AAAA,wFAF6G,EAE7G;AAAA,YAFoBlC,aAEpB,SAFoBA,aAEpB;AAAA,YAFmC/Z,IAEnC,SAFmCA,IAEnC;AAAA,YAFyC5E,KAEzC,SAFyCA,KAEzC;AAAA,YAFgD8gB,wBAEhD,SAFgDA,wBAEhD;AAAA,YAF0E7B,gBAE1E,SAF0EA,gBAE1E;AAAA,YAF4FE,YAE5F,SAF4FA,YAE5F;;AAAA,YADEE,UACF;;AACE/uC,iBAAIqgC,KAAJ,CAAU,iCAAV;;AAEAmQ,mCAA2BA,4BAA4B,KAAK7D,SAAL,CAAe6D,wBAAtE;AACA7B,2BAAmBA,oBAAoB,KAAKhC,SAAL,CAAegC,gBAAtD;;AAEA,eAAO,KAAKO,gBAAL,CAAsB5B,qBAAtB,GAA8CjD,IAA9C,CAAmD,eAAO;AAC7D,gBAAI,CAACjJ,GAAL,EAAU;AACNphC,yBAAIojC,KAAJ,CAAU,uEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,yBAAV,CAAN;AACH;;AAEDzB,qBAAIqgC,KAAJ,CAAU,gEAAV,EAA4Ee,GAA5E;;AAEA,gBAAI4F,UAAU,IAAIyJ,8BAAJ,CAAmB;AAC7BrP,wBAD6B;AAE7BiN,4CAF6B;AAG7BmC,kEAH6B;AAI7Blc,sBAAMA,QAAQ5E,KAJe;AAK7Bif,kDAL6B;AAM7BE;AAN6B,aAAnB,CAAd;;AASA,gBAAI6B,eAAe1J,QAAQtX,KAA3B;AACA,gBAAIghB,YAAJ,EAAkB;AACd1wC,yBAAIqgC,KAAJ,CAAU,uEAAV;;AAEA0O,6BAAaA,cAAc,OAAKO,WAAhC;AACAP,2BAAWQ,GAAX,CAAemB,aAAalV,EAA5B,EAAgCkV,aAAalB,eAAb,EAAhC;AACH;;AAED,mBAAOxI,OAAP;AACH,SA1BM,CAAP;AA2BH,K;;yBAED2J,wB,qCAAyBvP,G,EAAK2N,U,EAAiC;AAAA,YAArBW,WAAqB,uEAAP,KAAO;;AAC3D1vC,iBAAIqgC,KAAJ,CAAU,qCAAV;;AAEA,YAAIwP,WAAW,IAAIe,gCAAJ,CAAoBxP,GAApB,CAAf;AACA,YAAI,CAACyO,SAASngB,KAAd,EAAqB;AACjB1vB,qBAAIqgC,KAAJ,CAAU,2DAAV;;AAEA,gBAAIwP,SAASzM,KAAb,EAAoB;AAChBpjC,yBAAI8rC,IAAJ,CAAS,2DAAT,EAAsE+D,SAASzM,KAA/E;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI8B,4BAAJ,CAAkByJ,QAAlB,CAAf,CAAP;AACH;;AAED,mBAAOrN,QAAQC,OAAR,CAAgB,EAACthC,oBAAD,EAAY0uC,kBAAZ,EAAhB,CAAP;AACH;;AAED,YAAIgB,WAAWhB,SAASngB,KAAxB;;AAEAqf,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,YAAIS,WAAWL,cAAcX,WAAWiB,MAAX,CAAkBjN,IAAlB,CAAuBgM,UAAvB,CAAd,GAAmDA,WAAW9P,GAAX,CAAe8D,IAAf,CAAoBgM,UAApB,CAAlE;AACA,eAAOgB,SAASc,QAAT,EAAmBxG,IAAnB,CAAwB,6BAAqB;AAChD,gBAAI,CAAC4F,iBAAL,EAAwB;AACpBjwC,yBAAIojC,KAAJ,CAAU,yEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,oCAAV,CAAN;AACH;;AAED,gBAAIiuB,QAAQohB,aAAMX,iBAAN,CAAwBF,iBAAxB,CAAZ;;AAEA,mBAAO,EAACvgB,YAAD,EAAQmgB,kBAAR,EAAP;AACH,SATM,CAAP;AAUH,K;;yBAEDkB,sB,mCAAuB3P,G,EAAK2N,U,EAAY;AAAA;;AACpC/uC,iBAAIqgC,KAAJ,CAAU,mCAAV;;AAEA,eAAO,KAAKsQ,wBAAL,CAA8BvP,GAA9B,EAAmC2N,UAAnC,EAA+C,IAA/C,EAAqD1E,IAArD,CAA0D,iBAAuB;AAAA,gBAArB3a,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,SAAdA,QAAc;;AACpF,gBAAIngB,KAAJ,EAAW;AACP1vB,yBAAIqgC,KAAJ,CAAU,qFAAV;AACA,uBAAO,OAAKgQ,UAAL,CAAgBW,uBAAhB,CAAwCthB,KAAxC,EAA+CmgB,QAA/C,CAAP;AACH,aAHD,MAIK;AACD7vC,yBAAIqgC,KAAJ,CAAU,wFAAV;AACA,uBAAOwP,QAAP;AACH;AACJ,SATM,CAAP;AAUH,K;;yBAEDoB,e,4BAAgBlC,U,EAAY;AACxB/uC,iBAAIqgC,KAAJ,CAAU,4BAAV;;AAEA0O,qBAAaA,cAAc,KAAKO,WAAhC;;AAEA,eAAOwB,aAAMG,eAAN,CAAsBlC,UAAtB,EAAkC,KAAKtC,QAAL,CAAcyE,aAAhD,CAAP;AACH,K;;;;4BA5MiB;AACd,mBAAO,KAAKzE,QAAL,CAAcsC,UAArB;AACH;;;4BACgB;AACb,mBAAO,KAAKtC,QAAL,CAAc0E,SAArB;AACH;;;4BACsB;AACnB,mBAAO,KAAK1E,QAAL,CAAc2E,eAArB;AACH;;;4BAEc;AACX,mBAAO,KAAKzE,SAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKuC,gBAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;;;qjBCtCL;AACA;;AAEA;;AACA;;AACA;;AACA;;;;AAEA,IAAM1C,sBAAsB,kCAA5B;;AAEA,IAAM6E,sBAAsB,UAA5B;AACA,IAAMC,eAAe,QAArB;AACA,IAAMC,uBAAuB,KAAK,EAAlC,C,CAAsC;AACtC,IAAMC,4BAA4B,KAAK,CAAvC;;IAEatxC,kB,WAAAA,kB;AACT,kCAmBQ;AAAA,uFAAJ,EAAI;AAAA,YAjBJ4tC,SAiBI,QAjBJA,SAiBI;AAAA,YAjBOhB,WAiBP,QAjBOA,WAiBP;AAAA,YAjBoBzH,QAiBpB,QAjBoBA,QAiBpB;AAAA,YAjB8BqI,WAiB9B,QAjB8BA,WAiB9B;AAAA,YAfJvM,SAeI,QAfJA,SAeI;AAAA,YAfOiO,aAeP,QAfOA,aAeP;AAAA,sCAfsBpB,aAetB;AAAA,YAfsBA,aAetB,sCAfsCqD,mBAetC;AAAA,8BAf2DpD,KAe3D;AAAA,YAf2DA,KAe3D,8BAfmEqD,YAenE;AAAA,YAdJ1M,YAcI,QAdJA,YAcI;AAAA,YAdU4L,wBAcV,QAdUA,wBAcV;AAAA,YAZJtC,MAYI,QAZJA,MAYI;AAAA,YAZI9L,OAYJ,QAZIA,OAYJ;AAAA,YAZa+L,OAYb,QAZaA,OAYb;AAAA,YAZsBC,UAYtB,QAZsBA,UAYtB;AAAA,YAZkCG,UAYlC,QAZkCA,UAYlC;AAAA,YAZ8CC,QAY9C,QAZ8CA,QAY9C;AAAA,YAZwDE,aAYxD,QAZwDA,aAYxD;AAAA,yCAVJ+C,oBAUI;AAAA,YAVJA,oBAUI,yCAVmB,IAUnB;AAAA,qCAVyBC,YAUzB;AAAA,YAVyBA,YAUzB,qCAVwC,IAUxC;AAAA,sCATJR,aASI;AAAA,YATJA,aASI,sCATYK,oBASZ;AAAA,kCATkC5H,SASlC;AAAA,YATkCA,SASlC,kCAT8C6H,yBAS9C;AAAA,yCARJG,iBAQI;AAAA,YARJA,iBAQI,yCARgB,IAQhB;AAAA,mCANJ5C,UAMI;AAAA,YANJA,UAMI,mCANS,IAAI5uC,0CAAJ,EAMT;AAAA,yCALJyxC,qBAKI;AAAA,YALJA,qBAKI,yCALoBC,oCAKpB;AAAA,yCAJJC,mBAII;AAAA,YAJJA,mBAII,yCAJkBvxC,gCAIlB;AAAA,yCAFJouC,gBAEI;AAAA,YAFJA,gBAEI,yCAFe,EAEf;AAAA,yCADJC,gBACI;AAAA,YADJA,gBACI,yCADe,EACf;;AAAA;;AAEJ,aAAKmD,UAAL,GAAkBjE,SAAlB;AACA,aAAKD,YAAL,GAAoBf,WAApB;AACA,aAAKkF,SAAL,GAAiB3M,QAAjB;AACA,aAAK4M,YAAL,GAAoBvE,WAApB;;AAEA,aAAKlM,UAAL,GAAkBL,SAAlB;AACA,aAAK+Q,cAAL,GAAsB9C,aAAtB;AACA,aAAK+C,cAAL,GAAsBnE,aAAtB;AACA,aAAKoE,MAAL,GAAcnE,KAAd;AACA,aAAKoE,aAAL,GAAqBzN,YAArB;AACA,aAAK0N,yBAAL,GAAiC9B,wBAAjC;;AAEA,aAAK+B,OAAL,GAAerE,MAAf;AACA,aAAKsE,QAAL,GAAgBpQ,OAAhB;AACA,aAAKqQ,QAAL,GAAgBtE,OAAhB;AACA,aAAKuE,WAAL,GAAmBtE,UAAnB;AACA,aAAKuE,WAAL,GAAmBpE,UAAnB;AACA,aAAKqE,SAAL,GAAiBpE,QAAjB;AACA,aAAKqE,cAAL,GAAsBnE,aAAtB;;AAEA,aAAKoE,qBAAL,GAA6B,CAAC,CAACrB,oBAA/B;AACA,aAAKsB,aAAL,GAAqB,CAAC,CAACrB,YAAvB;AACA,aAAKsB,cAAL,GAAsB9B,aAAtB;AACA,aAAK+B,UAAL,GAAkBtJ,SAAlB;AACA,aAAKuJ,kBAAL,GAA0BvB,iBAA1B;;AAEA,aAAKrC,WAAL,GAAmBP,UAAnB;AACA,aAAKsB,UAAL,GAAkB,IAAIuB,qBAAJ,CAA0B,IAA1B,CAAlB;AACA,aAAK1C,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,IAAxB,CAAxB;;AAEA,aAAKqB,iBAAL,GAAyB,QAAOxE,gBAAP,yCAAOA,gBAAP,OAA4B,QAA5B,GAAuCA,gBAAvC,GAA0D,EAAnF;AACA,aAAKyE,iBAAL,GAAyB,QAAOxE,gBAAP,yCAAOA,gBAAP,OAA4B,QAA5B,GAAuCA,gBAAvC,GAA0D,EAAnF;AACH;;AAED;;;;;4BACgB;AACZ,mBAAO,KAAKpN,UAAZ;AACH,S;0BACamH,K,EAAO;AACjB,gBAAI,CAAC,KAAKnH,UAAV,EAAsB;AAClB;AACA,qBAAKA,UAAL,GAAkBmH,KAAlB;AACH,aAHD,MAIK;AACD3oC,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,sCAAV,CAAN;AACH;AACJ;;;4BACmB;AAChB,mBAAO,KAAKywC,cAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;;4BACW;AACR,mBAAO,KAAKC,MAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKC,yBAAZ;AACH;;AAGD;;;;4BACa;AACT,mBAAO,KAAKC,OAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKC,QAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKC,QAAZ;AACH;;;4BACgB;AACb,mBAAO,KAAKC,WAAZ;AACH;;;4BACgB;AACb,mBAAO,KAAKC,WAAZ;AACH;;;4BACc;AACX,mBAAO,KAAKC,SAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;AAGD;;;;4BACgB;AACZ,mBAAO,KAAKd,UAAZ;AACH,S;0BACapJ,K,EAAO;AACjB,gBAAI,CAAC,KAAKoJ,UAAV,EAAsB;AAClB;AACA,qBAAKA,UAAL,GAAkBpJ,KAAlB;AACH,aAHD,MAIK;AACD3oC,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,sBAAM,IAAI3hC,KAAJ,CAAU,sCAAV,CAAN;AACH;AACJ;;;4BACiB;AACd,gBAAI,CAAC,KAAKosC,YAAV,EAAwB;AACpB,qBAAKA,YAAL,GAAoB,KAAKC,SAAzB;;AAEA,oBAAI,KAAKD,YAAL,IAAqB,KAAKA,YAAL,CAAkBnmC,OAAlB,CAA0B8kC,mBAA1B,IAAiD,CAA1E,EAA6E;AACzE,wBAAI,KAAKqB,YAAL,CAAkB,KAAKA,YAAL,CAAkBxrC,MAAlB,GAA2B,CAA7C,MAAoD,GAAxD,EAA6D;AACzD,6BAAKwrC,YAAL,IAAqB,GAArB;AACH;AACD,yBAAKA,YAAL,IAAqBrB,mBAArB;AACH;AACJ;;AAED,mBAAO,KAAKqB,YAAZ;AACH;;AAED;;;;4BACe;AACX,mBAAO,KAAKmE,SAAZ;AACH,S;0BACYrJ,K,EAAO;AAChB,iBAAKqJ,SAAL,GAAiBrJ,KAAjB;AACH;;;4BAEiB;AACd,mBAAO,KAAKsJ,YAAZ;AACH,S;0BACetJ,K,EAAO;AACnB,iBAAKsJ,YAAL,GAAoBtJ,KAApB;AACH;;AAED;;;;4BAC2B;AACvB,mBAAO,KAAKmK,qBAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKC,cAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKC,UAAZ;AACH;;;4BACuB;AACpB,mBAAO,KAAKC,kBAAZ;AACH;;;4BAEgB;AACb,mBAAO,KAAK5D,WAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKe,UAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKnB,gBAAZ;AACH;;AAED;;;;4BACuB;AACnB,mBAAO,KAAKiE,iBAAZ;AACH,S;0BACoBxK,K,EAAO;AACxB,gBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA8B;AAC1B,qBAAKwK,iBAAL,GAAyBxK,KAAzB;AACH,aAFD,MAEO;AACH,qBAAKwK,iBAAL,GAAyB,EAAzB;AACH;AACJ;;AAED;;;;4BACuB;AACnB,mBAAO,KAAKC,iBAAZ;AACH,S;0BACoBzK,K,EAAO;AACxB,gBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA8B;AAC1B,qBAAKyK,iBAAL,GAAyBzK,KAAzB;AACH,aAFD,MAEO;AACH,qBAAKyK,iBAAL,GAAyB,EAAzB;AACH;AACJ;;;;;;;;;;;;;;;;;;;;;;;ACxNL;;AACA;;0JAJA;AACA;;IAKaC,c,WAAAA,c;;;;;6BAETvP,O,oBAAQC,M,EAAQ;AACZ,YAAIE,QAAQ,IAAIqP,wBAAJ,CAAgBvP,MAAhB,CAAZ;AACA,eAAOvB,QAAQC,OAAR,CAAgBwB,KAAhB,CAAP;AACH,K;;6BAED/C,Q,qBAASE,G,EAAKmS,Q,EAAU3D,S,EAAW;AAC/B5vC,iBAAIqgC,KAAJ,CAAU,yBAAV;;AAEA,YAAI;AACAiT,qCAAYE,YAAZ,CAAyBpS,GAAzB,EAA8BmS,QAA9B,EAAwC3D,SAAxC;AACA,mBAAOpN,QAAQC,OAAR,EAAP;AACH,SAHD,CAIA,OAAOzgC,CAAP,EAAU;AACN,mBAAOwgC,QAAQ8B,MAAR,CAAetiC,CAAf,CAAP;AACH;AACJ,K;;;;;;;;;;;;;;;;;;;;;;qjBCvBL;AACA;;AAEA;;AACA;;;;AAEA,IAAMyxC,8BAA8B,GAApC;AACA,IAAMtP,uBAAuB,+DAA7B;AACA;;AAEA,IAAMC,qBAAqB,QAA3B;;IAEakP,W,WAAAA,W;AAET,yBAAYvP,MAAZ,EAAoB;AAAA;;AAAA;;AAChB,aAAKM,QAAL,GAAgB,IAAI7B,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;AAC7C,kBAAKC,QAAL,GAAgB9B,OAAhB;AACA,kBAAK+B,OAAL,GAAeF,MAAf;AACH,SAHe,CAAhB;;AAKA,YAAII,SAASX,OAAOY,iBAAP,IAA4BP,kBAAzC;AACA,YAAIK,WAAWV,OAAOC,mBAAP,IAA8BG,oBAA7C;;AAEA,aAAKmB,MAAL,GAAcrkC,OAAOukC,IAAP,CAAY,EAAZ,EAAgBd,MAAhB,EAAwBD,QAAxB,CAAd;AACA,YAAI,KAAKa,MAAT,EAAiB;AACbtlC,qBAAIqgC,KAAJ,CAAU,8CAAV;AACA,iBAAKqT,yBAAL,GAAiCzyC,OAAO2iC,WAAP,CAAmB,KAAK+P,oBAAL,CAA0B5Q,IAA1B,CAA+B,IAA/B,CAAnB,EAAyD0Q,2BAAzD,CAAjC;AACH;AACJ;;0BAMDxO,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAAC,KAAKuB,MAAV,EAAkB;AACd,iBAAKJ,MAAL,CAAY,kDAAZ;AACH,SAFD,MAGK,IAAI,CAACnB,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AAC7B,iBAAK8D,MAAL,CAAY,uCAAZ;AACA,iBAAKA,MAAL,CAAY,iBAAZ;AACH,SAHI,MAIA;AACDllC,qBAAIqgC,KAAJ,CAAU,4CAAV;;AAEA,iBAAKuT,GAAL,GAAW7P,OAAOvI,EAAlB;AACA,gBAAI,KAAKoY,GAAT,EAAc;AACV3yC,uBAAO,mBAAmB8iC,OAAOvI,EAAjC,IAAuC,KAAK+F,SAAL,CAAewB,IAAf,CAAoB,IAApB,CAAvC;AACH;;AAED,iBAAKuC,MAAL,CAAYuO,KAAZ;AACA,iBAAKvO,MAAL,CAAYrkC,MAAZ,CAAmBmmC,QAAnB,GAA8BrD,OAAO3C,GAArC;AACH;;AAED,eAAO,KAAKyE,OAAZ;AACH,K;;0BAEDE,Q,qBAASzR,I,EAAM;AACXt0B,iBAAIqgC,KAAJ,CAAU,6DAAV;;AAEA,aAAK4F,QAAL;AACA,aAAK1B,QAAL,CAAcjQ,IAAd;AACH,K;;0BACD4Q,M,mBAAOc,O,EAAS;AACZhmC,iBAAIojC,KAAJ,CAAU,qBAAV,EAAiC4C,OAAjC;;AAEA,aAAKC,QAAL;AACA,aAAKzB,OAAL,CAAa,IAAI/iC,KAAJ,CAAUukC,OAAV,CAAb;AACH,K;;0BAEDE,K,oBAAQ;AACJ,aAAKD,QAAL,CAAc,KAAd;AACH,K;;0BAEDA,Q,qBAASsN,Q,EAAU;AACfvzC,iBAAIqgC,KAAJ,CAAU,qBAAV;;AAEAp/B,eAAO4iC,aAAP,CAAqB,KAAK6P,yBAA1B;AACA,aAAKA,yBAAL,GAAiC,IAAjC;;AAEA,eAAOzyC,OAAO,mBAAmB,KAAK2yC,GAA/B,CAAP;;AAEA,YAAI,KAAKtO,MAAL,IAAe,CAACiO,QAApB,EAA8B;AAC1B,iBAAKjO,MAAL,CAAYY,KAAZ;AACH;AACD,aAAKZ,MAAL,GAAc,IAAd;AACH,K;;0BAEDqO,oB,mCAAuB;AACnB,YAAI,CAAC,KAAKrO,MAAN,IAAgB,KAAKA,MAAL,CAAYwO,MAAhC,EAAwC;AACpC,iBAAK5O,MAAL,CAAY,qBAAZ;AACH;AACJ,K;;0BAED3D,S,sBAAUH,G,EAAKmS,Q,EAAU;AACrB,aAAKtN,QAAL,CAAcsN,QAAd;;AAEA,YAAInS,GAAJ,EAAS;AACLphC,qBAAIqgC,KAAJ,CAAU,8BAAV;AACA,iBAAK0F,QAAL,CAAc,EAAE3E,KAAKA,GAAP,EAAd;AACH,SAHD,MAIK;AACDphC,qBAAIqgC,KAAJ,CAAU,mDAAV;AACA,iBAAK6E,MAAL,CAAY,6BAAZ;AACH;AACJ,K;;gBAEMsO,Y,yBAAapS,G,EAAKmS,Q,EAAU3D,S,EAAW;AAC1C,YAAI3uC,OAAO8yC,MAAX,EAAmB;AACf3S,kBAAMA,OAAOngC,OAAOmmC,QAAP,CAAgBiB,IAA7B;AACA,gBAAIjH,GAAJ,EAAS;AACL,oBAAI9M,OAAO0f,uBAAWC,gBAAX,CAA4B7S,GAA5B,EAAiCwO,SAAjC,CAAX;;AAEA,oBAAItb,KAAK5E,KAAT,EAAgB;AACZ,wBAAIxL,OAAO,mBAAmBoQ,KAAK5E,KAAnC;AACA,wBAAIwR,WAAWjgC,OAAO8yC,MAAP,CAAc7vB,IAAd,CAAf;AACA,wBAAIgd,QAAJ,EAAc;AACVlhC,iCAAIqgC,KAAJ,CAAU,yDAAV;AACAa,iCAASE,GAAT,EAAcmS,QAAd;AACH,qBAHD,MAIK;AACDvzC,iCAAI8rC,IAAJ,CAAS,gEAAT;AACH;AACJ,iBAVD,MAWK;AACD9rC,6BAAI8rC,IAAJ,CAAS,0DAAT;AACH;AACJ;AACJ,SApBD,MAqBK;AACD9rC,qBAAI8rC,IAAJ,CAAS,0EAAT;AACH;AACJ,K;;;;4BAtGa;AACV,mBAAO,KAAKzH,QAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;qjBChCL;AACA;;AAEA;;;;IAEa6P,iB,WAAAA,iB;;;;;gCAETpQ,O,sBAAU;AACN,eAAOtB,QAAQC,OAAR,CAAgB,IAAhB,CAAP;AACH,K;;gCAEDwC,Q,qBAASlB,M,EAAQ;AACb,YAAI,CAACA,MAAD,IAAW,CAACA,OAAO3C,GAAvB,EAA4B;AACxBphC,qBAAIojC,KAAJ,CAAU,6CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iBAAV,CAAf,CAAP;AACH;;AAED,YAAIsiC,OAAOoQ,oBAAX,EAAiC;AAC7BlzC,mBAAOmmC,QAAP,CAAgB5oB,OAAhB,CAAwBulB,OAAO3C,GAA/B;AACH,SAFD,MAGK;AACDngC,mBAAOmmC,QAAP,GAAkBrD,OAAO3C,GAAzB;AACH;;AAED,eAAOoB,QAAQC,OAAR,EAAP;AACH,K;;;;4BAES;AACN,mBAAOxhC,OAAOmmC,QAAP,CAAgBiB,IAAvB;AACH;;;;;;;;;;;;;;;;;;;;;;;;;AC1BL;;AACA;;AACA;;AACA;;AACA;;AACA;;0JARA;AACA;;AASA,IAAM+L,iBAAiB,CAAC,OAAD,EAAU,SAAV,EAAqB,KAArB,EAA4B,KAA5B,EAAmC,KAAnC,EAA0C,KAA1C,EAAiD,KAAjD,EAAwD,QAAxD,CAAvB;;IAEavC,iB,WAAAA,iB;AAET,+BAAYpF,QAAZ,EAImC;AAAA,YAH/BqF,mBAG+B,uEAHTvxC,gCAGS;AAAA,YAF/B8zC,mBAE+B,uEAFTC,gCAES;AAAA,YAD/BC,QAC+B,uEADpBxL,kBACoB;AAAA,YAA/ByL,eAA+B,uEAAbC,wBAAa;;AAAA;;AAC/B,YAAI,CAAChI,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,iEAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKyC,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACA,aAAK+H,gBAAL,GAAwB,IAAIL,mBAAJ,CAAwB,KAAK1H,SAA7B,CAAxB;AACA,aAAKgI,SAAL,GAAiBJ,QAAjB;AACA,aAAKK,YAAL,GAAoB,IAAIJ,eAAJ,CAAoB,KAAK7H,SAAzB,CAApB;AACH;;gCAED2D,sB,mCAAuB5gB,K,EAAOmgB,Q,EAAU;AAAA;;AACpC7vC,iBAAIqgC,KAAJ,CAAU,0CAAV;;AAEA,eAAO,KAAKwU,oBAAL,CAA0BnlB,KAA1B,EAAiCmgB,QAAjC,EAA2CxF,IAA3C,CAAgD,oBAAY;AAC/DrqC,qBAAIqgC,KAAJ,CAAU,2DAAV;AACA,mBAAO,MAAKyU,eAAL,CAAqBplB,KAArB,EAA4BmgB,QAA5B,EAAsCxF,IAAtC,CAA2C,oBAAY;AAC1DrqC,yBAAIqgC,KAAJ,CAAU,4DAAV;AACA,uBAAO,MAAK0U,cAAL,CAAoBrlB,KAApB,EAA2BmgB,QAA3B,EAAqCxF,IAArC,CAA0C,oBAAY;AACzDrqC,6BAAIqgC,KAAJ,CAAU,4DAAV;AACA,2BAAOwP,QAAP;AACH,iBAHM,CAAP;AAIH,aANM,CAAP;AAOH,SATM,CAAP;AAUH,K;;gCAEDmB,uB,oCAAwBthB,K,EAAOmgB,Q,EAAU;AACrC,YAAIngB,MAAM8L,EAAN,KAAaqU,SAASngB,KAA1B,EAAiC;AAC7B1vB,qBAAIojC,KAAJ,CAAU,iEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAED;AACA;AACA;AACAzB,iBAAIqgC,KAAJ,CAAU,4DAAV;AACAwP,iBAASngB,KAAT,GAAiBA,MAAM4E,IAAvB;;AAEA,YAAIub,SAASzM,KAAb,EAAoB;AAChBpjC,qBAAI8rC,IAAJ,CAAS,+DAAT,EAA0E+D,SAASzM,KAAnF;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI8B,4BAAJ,CAAkByJ,QAAlB,CAAf,CAAP;AACH;;AAED,eAAOrN,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAEDgF,oB,iCAAqBnlB,K,EAAOmgB,Q,EAAU;AAClC,YAAIngB,MAAM8L,EAAN,KAAaqU,SAASngB,KAA1B,EAAiC;AAC7B1vB,qBAAIojC,KAAJ,CAAU,8DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMyR,SAAX,EAAsB;AAClBnhC,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,uBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMoe,SAAX,EAAsB;AAClB9tC,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,uBAAV,CAAf,CAAP;AACH;;AAED;AACA,YAAI,CAAC,KAAKkrC,SAAL,CAAemB,SAApB,EAA+B;AAC3B,iBAAKnB,SAAL,CAAemB,SAAf,GAA2Bpe,MAAMoe,SAAjC;AACH;AACD;AAHA,aAIK,IAAI,KAAKnB,SAAL,CAAemB,SAAf,IAA4B,KAAKnB,SAAL,CAAemB,SAAf,KAA6Bpe,MAAMoe,SAAnE,EAA8E;AAC/E9tC,yBAAIojC,KAAJ,CAAU,yFAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iDAAV,CAAf,CAAP;AACH;AACD;AACA,YAAI,CAAC,KAAKkrC,SAAL,CAAexL,SAApB,EAA+B;AAC3B,iBAAKwL,SAAL,CAAexL,SAAf,GAA2BzR,MAAMyR,SAAjC;AACH;AACD;AAHA,aAIK,IAAI,KAAKwL,SAAL,CAAexL,SAAf,IAA4B,KAAKwL,SAAL,CAAexL,SAAf,KAA6BzR,MAAMyR,SAAnE,EAA8E;AAC/EnhC,yBAAIojC,KAAJ,CAAU,yFAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iDAAV,CAAf,CAAP;AACH;;AAED;AACA;AACA;AACAzB,iBAAIqgC,KAAJ,CAAU,yDAAV;AACAwP,iBAASngB,KAAT,GAAiBA,MAAM4E,IAAvB;;AAEA,YAAIub,SAASzM,KAAb,EAAoB;AAChBpjC,qBAAI8rC,IAAJ,CAAS,4DAAT,EAAuE+D,SAASzM,KAAhF;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI8B,4BAAJ,CAAkByJ,QAAlB,CAAf,CAAP;AACH;;AAED,YAAIngB,MAAMslB,KAAN,IAAe,CAACnF,SAASoF,QAA7B,EAAuC;AACnCj1C,qBAAIojC,KAAJ,CAAU,wEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMslB,KAAP,IAAgBnF,SAASoF,QAA7B,EAAuC;AACnCj1C,qBAAIojC,KAAJ,CAAU,4EAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iCAAV,CAAf,CAAP;AACH;;AAED,YAAIiuB,MAAMwlB,aAAN,IAAuB,CAACrF,SAASsF,IAArC,EAA2C;AACvCn1C,qBAAIojC,KAAJ,CAAU,oEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,qBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACiuB,MAAMwlB,aAAP,IAAwBrF,SAASsF,IAArC,EAA2C;AACvCn1C,qBAAIojC,KAAJ,CAAU,wEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACouC,SAAS5B,KAAd,EAAqB;AACjB;AACA4B,qBAAS5B,KAAT,GAAiBve,MAAMue,KAAvB;AACH;;AAED,eAAOzL,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAEDkF,c,2BAAerlB,K,EAAOmgB,Q,EAAU;AAAA;;AAC5B,YAAIA,SAASuF,eAAb,EAA8B;AAC1Bp1C,qBAAIqgC,KAAJ,CAAU,uEAAV;;AAEAwP,qBAASwF,OAAT,GAAmB,KAAKvC,qBAAL,CAA2BjD,SAASwF,OAApC,CAAnB;;AAEA,gBAAI3lB,MAAMof,YAAN,KAAuB,IAAvB,IAA+B,KAAKnC,SAAL,CAAe+E,YAA9C,IAA8D7B,SAAS3P,YAA3E,EAAyF;AACrFlgC,yBAAIqgC,KAAJ,CAAU,qDAAV;;AAEA,uBAAO,KAAKqU,gBAAL,CAAsBY,SAAtB,CAAgCzF,SAAS3P,YAAzC,EAAuDmK,IAAvD,CAA4D,kBAAU;AACzErqC,6BAAIqgC,KAAJ,CAAU,qFAAV;;AAEA,wBAAIkV,OAAO7X,GAAP,KAAemS,SAASwF,OAAT,CAAiB3X,GAApC,EAAyC;AACrC19B,iCAAIojC,KAAJ,CAAU,kGAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gEAAV,CAAf,CAAP;AACH;;AAEDouC,6BAASwF,OAAT,GAAmB,OAAKG,YAAL,CAAkB3F,SAASwF,OAA3B,EAAoCE,MAApC,CAAnB;AACAv1C,6BAAIqgC,KAAJ,CAAU,+EAAV,EAA2FwP,SAASwF,OAApG;;AAEA,2BAAOxF,QAAP;AACH,iBAZM,CAAP;AAaH,aAhBD,MAiBK;AACD7vC,yBAAIqgC,KAAJ,CAAU,yDAAV;AACH;AACJ,SAzBD,MA0BK;AACDrgC,qBAAIqgC,KAAJ,CAAU,+EAAV;AACH;;AAED,eAAOmC,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAED2F,Y,yBAAaC,O,EAASC,O,EAAS;AAC3B,YAAIC,SAAS7zC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBH,OAAlB,CAAb;;AAEA,aAAK,IAAIvxB,IAAT,IAAiBwxB,OAAjB,EAA0B;AACtB,gBAAIG,SAASH,QAAQxxB,IAAR,CAAb;AACA,gBAAI,CAACnZ,MAAM4nB,OAAN,CAAckjB,MAAd,CAAL,EAA4B;AACxBA,yBAAS,CAACA,MAAD,CAAT;AACH;;AAED,iBAAK,IAAIzzC,IAAI,CAAb,EAAgBA,IAAIyzC,OAAOxzC,MAA3B,EAAmCD,GAAnC,EAAwC;AACpC,oBAAIumC,QAAQkN,OAAOzzC,CAAP,CAAZ;AACA,oBAAI,CAACuzC,OAAOzxB,IAAP,CAAL,EAAmB;AACfyxB,2BAAOzxB,IAAP,IAAeykB,KAAf;AACH,iBAFD,MAGK,IAAI59B,MAAM4nB,OAAN,CAAcgjB,OAAOzxB,IAAP,CAAd,CAAJ,EAAiC;AAClC,wBAAIyxB,OAAOzxB,IAAP,EAAaxc,OAAb,CAAqBihC,KAArB,IAA8B,CAAlC,EAAqC;AACjCgN,+BAAOzxB,IAAP,EAAa5f,IAAb,CAAkBqkC,KAAlB;AACH;AACJ,iBAJI,MAKA,IAAIgN,OAAOzxB,IAAP,MAAiBykB,KAArB,EAA4B;AAC7B,wBAAI,QAAOA,KAAP,yCAAOA,KAAP,OAAiB,QAArB,EAA+B;AAC3BgN,+BAAOzxB,IAAP,IAAe,KAAKsxB,YAAL,CAAkBG,OAAOzxB,IAAP,CAAlB,EAAgCykB,KAAhC,CAAf;AACH,qBAFD,MAGK;AACDgN,+BAAOzxB,IAAP,IAAe,CAACyxB,OAAOzxB,IAAP,CAAD,EAAeykB,KAAf,CAAf;AACH;AACJ;AACJ;AACJ;;AAED,eAAOgN,MAAP;AACH,K;;gCAED7C,qB,kCAAsByC,M,EAAQ;AAC1Bv1C,iBAAIqgC,KAAJ,CAAU,2DAAV,EAAuEkV,MAAvE;;AAEA,YAAII,SAAS7zC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBL,MAAlB,CAAb;;AAEA,YAAI,KAAK5I,SAAL,CAAemG,qBAAnB,EAA0C;AACtCsB,2BAAe0B,OAAf,CAAuB,gBAAQ;AAC3B,uBAAOH,OAAO76B,IAAP,CAAP;AACH,aAFD;;AAIA9a,qBAAIqgC,KAAJ,CAAU,mEAAV,EAA+EsV,MAA/E;AACH,SAND,MAOK;AACD31C,qBAAIqgC,KAAJ,CAAU,uEAAV;AACH;;AAED,eAAOsV,MAAP;AACH,K;;gCAEDb,e,4BAAgBplB,K,EAAOmgB,Q,EAAU;AAC7B,YAAIA,SAASsF,IAAb,EAAmB;AACfn1C,qBAAIqgC,KAAJ,CAAU,oDAAV;AACA,mBAAO,KAAK0V,YAAL,CAAkBrmB,KAAlB,EAAyBmgB,QAAzB,CAAP;AACH;;AAED,YAAIA,SAASoF,QAAb,EAAuB;AACnB,gBAAIpF,SAAS3P,YAAb,EAA2B;AACvBlgC,yBAAIqgC,KAAJ,CAAU,yEAAV;AACA,uBAAO,KAAK2V,8BAAL,CAAoCtmB,KAApC,EAA2CmgB,QAA3C,CAAP;AACH;;AAED7vC,qBAAIqgC,KAAJ,CAAU,wDAAV;AACA,mBAAO,KAAK4V,gBAAL,CAAsBvmB,KAAtB,EAA6BmgB,QAA7B,CAAP;AACH;;AAED7vC,iBAAIqgC,KAAJ,CAAU,+EAAV;AACA,eAAOmC,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;gCAEDkG,Y,yBAAarmB,K,EAAOmgB,Q,EAAU;AAAA;;AAC1B,YAAI7I,UAAU;AACV7F,uBAAWzR,MAAMyR,SADP;AAEViO,2BAAe1f,MAAM0f,aAFX;AAGV+F,kBAAOtF,SAASsF,IAHN;AAIVvQ,0BAAclV,MAAMkV,YAJV;AAKVsQ,2BAAexlB,MAAMwlB;AALX,SAAd;;AAQA,YAAIxlB,MAAMkf,gBAAN,IAA0B,QAAOlf,MAAMkf,gBAAb,MAAmC,QAAjE,EAA2E;AACvE9sC,mBAAO8zC,MAAP,CAAc5O,OAAd,EAAuBtX,MAAMkf,gBAA7B;AACH;;AAED,eAAO,KAAKgG,YAAL,CAAkBsB,YAAlB,CAA+BlP,OAA/B,EAAwCqD,IAAxC,CAA6C,yBAAiB;;AAEjE,iBAAI,IAAIvW,GAAR,IAAeqiB,aAAf,EAA8B;AAC1BtG,yBAAS/b,GAAT,IAAgBqiB,cAAcriB,GAAd,CAAhB;AACH;;AAED,gBAAI+b,SAASoF,QAAb,EAAuB;AACnBj1C,yBAAIqgC,KAAJ,CAAU,gFAAV;AACA,uBAAO,OAAK+V,0BAAL,CAAgC1mB,KAAhC,EAAuCmgB,QAAvC,CAAP;AACH,aAHD,MAIK;AACD7vC,yBAAIqgC,KAAJ,CAAU,+EAAV;AACH;;AAED,mBAAOwP,QAAP;AACH,SAfM,CAAP;AAgBH,K;;gCAEDuG,0B,uCAA2B1mB,K,EAAOmgB,Q,EAAU;AAAA;;AACxC,eAAO,KAAKX,gBAAL,CAAsBnC,SAAtB,GAAkC1C,IAAlC,CAAuC,kBAAU;;AAEpD,gBAAIX,WAAWha,MAAMyR,SAArB;AACA,gBAAIkV,qBAAqB,OAAK1J,SAAL,CAAehD,SAAxC;AACA3pC,qBAAIqgC,KAAJ,CAAU,4GAAV,EAAwHgW,kBAAxH;;AAEA,mBAAO,OAAK1B,SAAL,CAAe3K,qBAAf,CAAqC6F,SAASoF,QAA9C,EAAwDxL,MAAxD,EAAgEC,QAAhE,EAA0E2M,kBAA1E,EAA8FhM,IAA9F,CAAmG,mBAAW;;AAEjH,oBAAI3a,MAAMslB,KAAN,IAAetlB,MAAMslB,KAAN,KAAgBzL,QAAQyL,KAA3C,EAAkD;AAC9Ch1C,6BAAIojC,KAAJ,CAAU,yEAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAAV,CAAf,CAAP;AACH;;AAED,oBAAI,CAAC8nC,QAAQ7L,GAAb,EAAkB;AACd19B,6BAAIojC,KAAJ,CAAU,0EAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDouC,yBAASwF,OAAT,GAAmB9L,OAAnB;AACA,uBAAOsG,QAAP;AACH,aAdM,CAAP;AAeH,SArBM,CAAP;AAsBH,K;;gCAEDmG,8B,2CAA+BtmB,K,EAAOmgB,Q,EAAU;AAAA;;AAC5C,eAAO,KAAKoG,gBAAL,CAAsBvmB,KAAtB,EAA6BmgB,QAA7B,EAAuCxF,IAAvC,CAA4C,oBAAY;AAC3D,mBAAO,OAAKiM,oBAAL,CAA0BzG,QAA1B,CAAP;AACH,SAFM,CAAP;AAGH,K;;gCAEDoG,gB,6BAAiBvmB,K,EAAOmgB,Q,EAAU;AAAA;;AAC9B,YAAI,CAACngB,MAAMslB,KAAX,EAAkB;AACdh1C,qBAAIojC,KAAJ,CAAU,uDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,mBAAV,CAAf,CAAP;AACH;;AAED,YAAI2nC,MAAM,KAAKuL,SAAL,CAAexL,QAAf,CAAwB0G,SAASoF,QAAjC,CAAV;AACA,YAAI,CAAC7L,GAAD,IAAQ,CAACA,IAAIE,MAAb,IAAuB,CAACF,IAAIG,OAAhC,EAAyC;AACrCvpC,qBAAIojC,KAAJ,CAAU,8DAAV,EAA0EgG,GAA1E;AACA,mBAAO5G,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,YAAIiuB,MAAMslB,KAAN,KAAgB5L,IAAIG,OAAJ,CAAYyL,KAAhC,EAAuC;AACnCh1C,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,2BAAV,CAAf,CAAP;AACH;;AAED,YAAIs5B,MAAMqO,IAAIE,MAAJ,CAAWvO,GAArB;;AAEA,eAAO,KAAKmU,gBAAL,CAAsBnC,SAAtB,GAAkC1C,IAAlC,CAAuC,kBAAU;AACpDrqC,qBAAIqgC,KAAJ,CAAU,qDAAV;;AAEA,mBAAO,OAAK6O,gBAAL,CAAsBzB,cAAtB,GAAuCpD,IAAvC,CAA4C,gBAAQ;AACvD,oBAAI,CAACnqB,IAAL,EAAW;AACPlgB,6BAAIojC,KAAJ,CAAU,mEAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,+BAAV,CAAf,CAAP;AACH;;AAEDzB,yBAAIqgC,KAAJ,CAAU,2DAAV;AACA,oBAAIvM,YAAJ;AACA,oBAAI,CAACiH,GAAL,EAAU;AACN7a,2BAAO,OAAKq2B,YAAL,CAAkBr2B,IAAlB,EAAwBkpB,IAAIE,MAAJ,CAAW1c,GAAnC,CAAP;;AAEA,wBAAI1M,KAAK7d,MAAL,GAAc,CAAlB,EAAqB;AACjBrC,iCAAIojC,KAAJ,CAAU,sGAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kEAAV,CAAf,CAAP;AACH,qBAHD,MAIK;AACD;AACA;AACAqyB,8BAAM5T,KAAK,CAAL,CAAN;AACH;AACJ,iBAZD,MAaK;AACD4T,0BAAM5T,KAAKs2B,MAAL,CAAY,eAAO;AACrB,+BAAO1iB,IAAIiH,GAAJ,KAAYA,GAAnB;AACH,qBAFK,EAEH,CAFG,CAAN;AAGH;;AAED,oBAAI,CAACjH,GAAL,EAAU;AACN9zB,6BAAIojC,KAAJ,CAAU,sFAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED,oBAAIioC,WAAWha,MAAMyR,SAArB;;AAEA,oBAAIkV,qBAAqB,OAAK1J,SAAL,CAAehD,SAAxC;AACA3pC,yBAAIqgC,KAAJ,CAAU,uFAAV,EAAmGgW,kBAAnG;;AAEA,uBAAO,OAAK1B,SAAL,CAAenL,WAAf,CAA2BqG,SAASoF,QAApC,EAA8CnhB,GAA9C,EAAmD2V,MAAnD,EAA2DC,QAA3D,EAAqE2M,kBAArE,EAAyFhM,IAAzF,CAA8F,YAAI;AACrGrqC,6BAAIqgC,KAAJ,CAAU,+DAAV;;AAEA,wBAAI,CAAC+I,IAAIG,OAAJ,CAAY7L,GAAjB,EAAsB;AAClB19B,iCAAIojC,KAAJ,CAAU,gEAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDouC,6BAASwF,OAAT,GAAmBjM,IAAIG,OAAvB;;AAEA,2BAAOsG,QAAP;AACH,iBAXM,CAAP;AAYH,aAjDM,CAAP;AAkDH,SArDM,CAAP;AAsDH,K;;gCAED0G,Y,yBAAar2B,I,EAAM0M,G,EAAI;AACnB,YAAIyJ,MAAM,IAAV;AACA,YAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AACtBjV,kBAAM,KAAN;AACH,SAFD,MAGK,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA;AACDr2B,qBAAIqgC,KAAJ,CAAU,qDAAV,EAAiEzT,GAAjE;AACA,mBAAO,EAAP;AACH;;AAED5sB,iBAAIqgC,KAAJ,CAAU,mEAAV,EAA+EhK,GAA/E;;AAEAnW,eAAOA,KAAKs2B,MAAL,CAAY,eAAO;AACtB,mBAAO1iB,IAAIuC,GAAJ,KAAYA,GAAnB;AACH,SAFM,CAAP;;AAIAr2B,iBAAIqgC,KAAJ,CAAU,iEAAV,EAA6EhK,GAA7E,EAAkFnW,KAAK7d,MAAvF;;AAEA,eAAO6d,IAAP;AACH,K;;gCAEDo2B,oB,iCAAqBzG,Q,EAAU;AAC3B,YAAI,CAACA,SAASwF,OAAd,EAAuB;AACnBr1C,qBAAIojC,KAAJ,CAAU,yEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,iCAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACouC,SAASwF,OAAT,CAAiBoB,OAAtB,EAA+B;AAC3Bz2C,qBAAIojC,KAAJ,CAAU,gEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,wBAAV,CAAf,CAAP;AACH;;AAED,YAAI,CAACouC,SAASoF,QAAd,EAAwB;AACpBj1C,qBAAIojC,KAAJ,CAAU,qDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,aAAV,CAAf,CAAP;AACH;;AAED,YAAI2nC,MAAM,KAAKuL,SAAL,CAAexL,QAAf,CAAwB0G,SAASoF,QAAjC,CAAV;AACA,YAAI,CAAC7L,GAAD,IAAQ,CAACA,IAAIE,MAAjB,EAAyB;AACrBtpC,qBAAIojC,KAAJ,CAAU,kEAAV,EAA8EgG,GAA9E;AACA,mBAAO5G,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,YAAIi1C,UAAUtN,IAAIE,MAAJ,CAAW1c,GAAzB;AACA,YAAI,CAAC8pB,OAAD,IAAYA,QAAQr0C,MAAR,KAAmB,CAAnC,EAAsC;AAClCrC,qBAAIojC,KAAJ,CAAU,0DAAV,EAAsEsT,OAAtE;AACA,mBAAOlU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAsBi1C,OAAhC,CAAf,CAAP;AACH;;AAED,YAAIC,WAAWD,QAAQ7xC,MAAR,CAAe,CAAf,EAAkB,CAAlB,CAAf;AACA,YAAI,CAAC8xC,QAAL,EAAe;AACX32C,qBAAIojC,KAAJ,CAAU,0DAAV,EAAsEsT,OAAtE,EAA+EC,QAA/E;AACA,mBAAOnU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAsBi1C,OAAhC,CAAf,CAAP;AACH;;AAEDC,mBAAW/xC,SAAS+xC,QAAT,CAAX;AACA,YAAIA,aAAa,GAAb,IAAoBA,aAAa,GAAjC,IAAwCA,aAAa,GAAzD,EAA8D;AAC1D32C,qBAAIojC,KAAJ,CAAU,0DAAV,EAAsEsT,OAAtE,EAA+EC,QAA/E;AACA,mBAAOnU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,sBAAsBi1C,OAAhC,CAAf,CAAP;AACH;;AAED,YAAIE,MAAM,QAAQD,QAAlB;AACA,YAAI5oB,OAAO,KAAK4mB,SAAL,CAAehoB,UAAf,CAA0BkjB,SAAS3P,YAAnC,EAAiD0W,GAAjD,CAAX;AACA,YAAI,CAAC7oB,IAAL,EAAW;AACP/tB,qBAAIojC,KAAJ,CAAU,mEAAV,EAA+EwT,GAA/E;AACA,mBAAOpU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAED,YAAIo1C,OAAO9oB,KAAKlpB,MAAL,CAAY,CAAZ,EAAekpB,KAAK1rB,MAAL,GAAc,CAA7B,CAAX;AACA,YAAIy0C,YAAY,KAAKnC,SAAL,CAAerK,cAAf,CAA8BuM,IAA9B,CAAhB;AACA,YAAIC,cAAcjH,SAASwF,OAAT,CAAiBoB,OAAnC,EAA4C;AACxCz2C,qBAAIojC,KAAJ,CAAU,oEAAV,EAAgF0T,SAAhF,EAA2FjH,SAASwF,OAAT,CAAiBoB,OAA5G;AACA,mBAAOjU,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;;AAEDzB,iBAAIqgC,KAAJ,CAAU,iDAAV;;AAEA,eAAOmC,QAAQC,OAAR,CAAgBoN,QAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCndL;AACA;;AAEA;;AACA;;AACA;;;;IAEajvC,c,WAAAA,c;AAET,4BAAYm2C,WAAZ,EAA4F;AAAA;;AAAA,YAAnEC,sBAAmE,uEAA1Ct2C,sCAA0C;AAAA,YAAtBmmC,KAAsB,uEAAdhmC,eAAOgmC,KAAO;;AAAA;;AACxF,YAAI,CAACkQ,WAAL,EAAkB;AACd/2C,qBAAIojC,KAAJ,CAAU,+DAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,aAAV,CAAN;AACH;;AAED,aAAKw1C,YAAL,GAAoBF,WAApB;AACA,aAAKG,uBAAL,GAA+BF,sBAA/B;AACA,aAAKrT,MAAL,GAAckD,KAAd;;AAEA,aAAKoQ,YAAL,CAAkBE,MAAlB,CAAyBC,aAAzB,CAAuC,KAAKC,MAAL,CAAYtU,IAAZ,CAAiB,IAAjB,CAAvC;AACA,aAAKkU,YAAL,CAAkBE,MAAlB,CAAyBG,eAAzB,CAAyC,KAAKC,KAAL,CAAWxU,IAAX,CAAgB,IAAhB,CAAzC;;AAEA,aAAKkU,YAAL,CAAkBO,OAAlB,GAA4BnN,IAA5B,CAAiC,gBAAQ;AACrC;AACA;AACA,gBAAIoN,IAAJ,EAAU;AACN,sBAAKJ,MAAL,CAAYI,IAAZ;AACH,aAFD,MAGK,IAAI,MAAK9K,SAAL,CAAe+K,uBAAnB,EAA4C;AAC7C,sBAAKT,YAAL,CAAkBU,kBAAlB,GAAuCtN,IAAvC,CAA4C,mBAAW;AACnD,wBAAIuN,UAAU;AACVrU,uCAAgBsU,QAAQtU;AADd,qBAAd;AAGA,wBAAIsU,QAAQna,GAAR,IAAema,QAAQC,GAA3B,EAAgC;AAC5BF,gCAAQvC,OAAR,GAAkB;AACd3X,iCAAKma,QAAQna,GADC;AAEdoa,iCAAKD,QAAQC;AAFC,yBAAlB;AAIH;AACD,0BAAKT,MAAL,CAAYO,OAAZ;AACH,iBAXD,EAYCG,KAZD,CAYO,eAAO;AACV;AACA/3C,6BAAIojC,KAAJ,CAAU,qDAAV,EAAiE4U,IAAIhS,OAArE;AACH,iBAfD;AAgBH;AACJ,SAxBD,EAwBG+R,KAxBH,CAwBS,eAAO;AACZ;AACA/3C,qBAAIojC,KAAJ,CAAU,0CAAV,EAAsD4U,IAAIhS,OAA1D;AACH,SA3BD;AA4BH;;6BAkBDqR,M,mBAAOI,I,EAAM;AAAA;;AACT,YAAIlU,gBAAgBkU,KAAKlU,aAAzB;;AAEA,YAAIA,aAAJ,EAAmB;AACf,gBAAIkU,KAAKpC,OAAT,EAAkB;AACd,qBAAK4C,IAAL,GAAYR,KAAKpC,OAAL,CAAa3X,GAAzB;AACA,qBAAKwa,IAAL,GAAYT,KAAKpC,OAAL,CAAayC,GAAzB;AACA93C,yBAAIqgC,KAAJ,CAAU,uCAAV,EAAmDkD,aAAnD,EAAkE,QAAlE,EAA4E,KAAK0U,IAAjF;AACH,aAJD,MAKK;AACD,qBAAKA,IAAL,GAAY92C,SAAZ;AACA,qBAAK+2C,IAAL,GAAY/2C,SAAZ;AACAnB,yBAAIqgC,KAAJ,CAAU,uCAAV,EAAmDkD,aAAnD,EAAkE,kBAAlE;AACH;;AAED,gBAAI,CAAC,KAAK4U,mBAAV,EAA+B;AAC3B,qBAAKjJ,gBAAL,CAAsB7B,qBAAtB,GAA8ChD,IAA9C,CAAmD,eAAO;AACtD,wBAAIjJ,GAAJ,EAAS;AACLphC,iCAAIqgC,KAAJ,CAAU,0DAAV;;AAEA,4BAAIc,YAAY,OAAKK,UAArB;AACA,4BAAIH,WAAW,OAAK+W,qBAApB;AACA,4BAAI9W,cAAc,OAAK+W,wBAAvB;;AAEA,+BAAKF,mBAAL,GAA2B,IAAI,OAAKjB,uBAAT,CAAiC,OAAK3V,SAAL,CAAewB,IAAf,CAAoB,MAApB,CAAjC,EAA4D5B,SAA5D,EAAuEC,GAAvE,EAA4EC,QAA5E,EAAsFC,WAAtF,CAA3B;AACA,+BAAK6W,mBAAL,CAAyBnY,IAAzB,GAAgCqK,IAAhC,CAAqC,YAAM;AACvC,mCAAK8N,mBAAL,CAAyB7U,KAAzB,CAA+BC,aAA/B;AACH,yBAFD;AAGH,qBAXD,MAYK;AACDvjC,iCAAI8rC,IAAJ,CAAS,sEAAT;AACH;AACJ,iBAhBD,EAgBGiM,KAhBH,CAgBS,eAAO;AACZ;AACA/3C,6BAAIojC,KAAJ,CAAU,0DAAV,EAAsE4U,IAAIhS,OAA1E;AACH,iBAnBD;AAoBH,aArBD,MAsBK;AACD,qBAAKmS,mBAAL,CAAyB7U,KAAzB,CAA+BC,aAA/B;AACH;AACJ;AACJ,K;;6BAEDgU,K,oBAAQ;AAAA;;AACJ,aAAKU,IAAL,GAAY92C,SAAZ;AACA,aAAK+2C,IAAL,GAAY/2C,SAAZ;;AAEA,YAAI,KAAKg3C,mBAAT,EAA8B;AAC1Bn4C,qBAAIqgC,KAAJ,CAAU,sBAAV;AACA,iBAAK8X,mBAAL,CAAyB9U,IAAzB;AACH;;AAED,YAAI,KAAKsJ,SAAL,CAAe+K,uBAAnB,EAA4C;AACxC;AACA,gBAAIY,cAAc,KAAK3U,MAAL,CAAYC,WAAZ,CAAwB,YAAI;AAC1C,uBAAKD,MAAL,CAAYE,aAAZ,CAA0ByU,WAA1B;;AAEA,uBAAKrB,YAAL,CAAkBU,kBAAlB,GAAuCtN,IAAvC,CAA4C,mBAAW;AACnD,wBAAIuN,UAAU;AACVrU,uCAAgBsU,QAAQtU;AADd,qBAAd;AAGA,wBAAIsU,QAAQna,GAAR,IAAema,QAAQC,GAA3B,EAAgC;AAC5BF,gCAAQvC,OAAR,GAAkB;AACd3X,iCAAKma,QAAQna,GADC;AAEdoa,iCAAKD,QAAQC;AAFC,yBAAlB;AAIH;AACD,2BAAKT,MAAL,CAAYO,OAAZ;AACH,iBAXD,EAYCG,KAZD,CAYO,eAAO;AACV;AACA/3C,6BAAIojC,KAAJ,CAAU,gDAAV,EAA4D4U,IAAIhS,OAAhE;AACH,iBAfD;AAiBH,aApBiB,EAoBf,IApBe,CAAlB;AAqBH;AACJ,K;;6BAEDzE,S,wBAAY;AAAA;;AACR,aAAK0V,YAAL,CAAkBU,kBAAlB,GAAuCtN,IAAvC,CAA4C,mBAAW;AACnD,gBAAIkO,aAAa,IAAjB;;AAEA,gBAAIV,OAAJ,EAAa;AACT,oBAAIA,QAAQna,GAAR,KAAgB,OAAKua,IAAzB,EAA+B;AAC3BM,iCAAa,KAAb;AACA,2BAAKJ,mBAAL,CAAyB7U,KAAzB,CAA+BuU,QAAQtU,aAAvC;;AAEA,wBAAIsU,QAAQC,GAAR,KAAgB,OAAKI,IAAzB,EAA+B;AAC3Bl4C,iCAAIqgC,KAAJ,CAAU,2GAAV,EAAuHwX,QAAQtU,aAA/H;AACH,qBAFD,MAGK;AACDvjC,iCAAIqgC,KAAJ,CAAU,sIAAV,EAAkJwX,QAAQtU,aAA1J;AACA,+BAAK0T,YAAL,CAAkBE,MAAlB,CAAyBqB,wBAAzB;AACH;AACJ,iBAXD,MAYK;AACDx4C,6BAAIqgC,KAAJ,CAAU,6DAAV,EAAyEwX,QAAQna,GAAjF;AACH;AACJ,aAhBD,MAiBK;AACD19B,yBAAIqgC,KAAJ,CAAU,4DAAV;AACH;;AAED,gBAAIkY,UAAJ,EAAgB;AACZ,oBAAI,OAAKN,IAAT,EAAe;AACXj4C,6BAAIqgC,KAAJ,CAAU,8EAAV;AACA,2BAAK4W,YAAL,CAAkBE,MAAlB,CAAyBsB,mBAAzB;AACH,iBAHD,MAIK;AACDz4C,6BAAIqgC,KAAJ,CAAU,6EAAV;AACA,2BAAK4W,YAAL,CAAkBE,MAAlB,CAAyBuB,kBAAzB;AACH;AACJ;AACJ,SAlCD,EAkCGX,KAlCH,CAkCS,eAAO;AACZ,gBAAI,OAAKE,IAAT,EAAe;AACXj4C,yBAAIqgC,KAAJ,CAAU,6FAAV,EAAyG2X,IAAIhS,OAA7G;AACA,uBAAKiR,YAAL,CAAkBE,MAAlB,CAAyBsB,mBAAzB;AACH;AACJ,SAvCD;AAwCH,K;;;;4BAvIe;AACZ,mBAAO,KAAKxB,YAAL,CAAkBxK,QAAzB;AACH;;;4BACsB;AACnB,mBAAO,KAAKwK,YAAL,CAAkB7F,eAAzB;AACH;;;4BACgB;AACb,mBAAO,KAAKzE,SAAL,CAAexL,SAAtB;AACH;;;4BAC2B;AACxB,mBAAO,KAAKwL,SAAL,CAAegM,oBAAtB;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKhM,SAAL,CAAeiM,uBAAtB;AACH;;;;;;;;;;;;;;;;;;;;;;;AC/DL;;AACA;;AACA;;0JALA;AACA;;IAMa5J,a,WAAAA,a;AACT,iCAMG;AAAA,YAJC5N,GAID,QAJCA,GAID;AAAA,YAJMD,SAIN,QAJMA,SAIN;AAAA,YAJiByD,YAIjB,QAJiBA,YAIjB;AAAA,YAJ+BoJ,aAI/B,QAJ+BA,aAI/B;AAAA,YAJ8CC,KAI9C,QAJ8CA,KAI9C;AAAA,YAJqDH,SAIrD,QAJqDA,SAIrD;AAAA,YAFCxZ,IAED,QAFCA,IAED;AAAA,YAFO4Z,MAEP,QAFOA,MAEP;AAAA,YAFe9L,OAEf,QAFeA,OAEf;AAAA,YAFwB+L,OAExB,QAFwBA,OAExB;AAAA,YAFiCC,UAEjC,QAFiCA,UAEjC;AAAA,YAF6CC,aAE7C,QAF6CA,aAE7C;AAAA,YAF4DC,UAE5D,QAF4DA,UAE5D;AAAA,YAFwEC,UAExE,QAFwEA,UAExE;AAAA,YAFoFC,QAEpF,QAFoFA,QAEpF;AAAA,YAF8FE,aAE9F,QAF8FA,aAE9F;AAAA,YADC1H,OACD,QADCA,OACD;AAAA,YADUyH,WACV,QADUA,WACV;AAAA,YADuBE,gBACvB,QADuBA,gBACvB;AAAA,YADyCE,YACzC,QADyCA,YACzC;AAAA,YADuDO,aACvD,QADuDA,aACvD;AAAA,YADsER,gBACtE,QADsEA,gBACtE;AAAA,YADwFE,YACxF,QADwFA,YACxF;;AAAA;;AACC,YAAI,CAAC1N,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,mCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;AACD,YAAI,CAAC0/B,SAAL,EAAgB;AACZnhC,qBAAIojC,KAAJ,CAAU,yCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,WAAV,CAAN;AACH;AACD,YAAI,CAACmjC,YAAL,EAAmB;AACf5kC,qBAAIojC,KAAJ,CAAU,4CAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,cAAV,CAAN;AACH;AACD,YAAI,CAACusC,aAAL,EAAoB;AAChBhuC,qBAAIojC,KAAJ,CAAU,6CAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,eAAV,CAAN;AACH;AACD,YAAI,CAACwsC,KAAL,EAAY;AACRjuC,qBAAIojC,KAAJ,CAAU,qCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,OAAV,CAAN;AACH;AACD,YAAI,CAACqsC,SAAL,EAAgB;AACZ9tC,qBAAIojC,KAAJ,CAAU,yCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,WAAV,CAAN;AACH;;AAED,YAAIo3C,OAAO7J,cAAc8J,MAAd,CAAqB9K,aAArB,CAAX;AACA,YAAImH,OAAOnG,cAAcC,MAAd,CAAqBjB,aAArB,CAAX;;AAEA,YAAI,CAACU,aAAL,EAAoB;AAChBA,4BAAgBM,cAAcC,MAAd,CAAqBjB,aAArB,IAAsC,OAAtC,GAAgD,IAAhE;AACH;;AAED,aAAKte,KAAL,GAAa,IAAIwgB,wBAAJ,CAAgB,EAAE8E,OAAO6D,IAAT;AACzBvkB,sBADyB,EACnB6M,oBADmB,EACR2M,oBADQ,EACGlJ,0BADH;AAEzBsQ,2BAAeC,IAFU;AAGzBtG,sCAHyB,EAGXH,4BAHW;AAIzBU,wCAJyB,EAIVnB,YAJU,EAIHW,kCAJG,EAIeE,0BAJf,EAAhB,CAAb;;AAMA1N,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,WAA9B,EAA2CD,SAA3C,CAAN;AACAC,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,cAA9B,EAA8CwD,YAA9C,CAAN;AACAxD,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,eAA9B,EAA+C4M,aAA/C,CAAN;AACA5M,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC6M,KAAvC,CAAN;;AAEA7M,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC,KAAK1R,KAAL,CAAW8L,EAAlD,CAAN;AACA,YAAIqd,IAAJ,EAAU;AACNzX,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC,KAAK1R,KAAL,CAAWslB,KAAlD,CAAN;AACH;AACD,YAAIG,IAAJ,EAAU;AACN/T,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,gBAA9B,EAAgD,KAAK1R,KAAL,CAAWspB,cAA3D,CAAN;AACA5X,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,uBAA9B,EAAuD,MAAvD,CAAN;AACH;;AAED,YAAIgM,WAAW,EAAEc,cAAF,EAAU9L,gBAAV,EAAmB+L,gBAAnB,EAA4BC,sBAA5B,EAAwCC,4BAAxC,EAAuDC,sBAAvD,EAAmEC,sBAAnE,EAA+EC,kBAA/E,EAAyFxH,gBAAzF,EAAkGyH,wBAAlG,EAA+GC,4BAA/G,EAAf;AACA,aAAI,IAAI5a,GAAR,IAAesZ,QAAf,EAAwB;AACpB,gBAAIA,SAAStZ,GAAT,CAAJ,EAAmB;AACfsN,sBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8BtN,GAA9B,EAAmCsZ,SAAStZ,GAAT,CAAnC,CAAN;AACH;AACJ;;AAED,aAAI,IAAIA,IAAR,IAAe6a,gBAAf,EAAgC;AAC5BvN,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8BtN,IAA9B,EAAmC6a,iBAAiB7a,IAAjB,CAAnC,CAAN;AACH;;AAED,aAAKsN,GAAL,GAAWA,GAAX;AACH;;kBAEM0X,M,mBAAO9K,a,EAAe;AACzB,YAAI2H,SAAS3H,cAAcrtB,KAAd,CAAoB,MAApB,EAA4B61B,MAA5B,CAAmC,UAAS7P,IAAT,EAAe;AAC3D,mBAAOA,SAAS,UAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAEgP,OAAO,CAAP,CAAV;AACH,K;;kBAEMsD,O,oBAAQjL,a,EAAe;AAC1B,YAAI2H,SAAS3H,cAAcrtB,KAAd,CAAoB,MAApB,EAA4B61B,MAA5B,CAAmC,UAAS7P,IAAT,EAAe;AAC3D,mBAAOA,SAAS,OAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAEgP,OAAO,CAAP,CAAV;AACH,K;;kBAEM1G,M,mBAAOjB,a,EAAe;AACzB,YAAI2H,SAAS3H,cAAcrtB,KAAd,CAAoB,MAApB,EAA4B61B,MAA5B,CAAmC,UAAS7P,IAAT,EAAe;AAC3D,mBAAOA,SAAS,MAAhB;AACH,SAFY,CAAb;AAGA,eAAO,CAAC,CAAEgP,OAAO,CAAP,CAAV;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBCpGL;AACA;;AAEA;;;;AAEA,IAAMuD,YAAY,QAAlB;;IAEapJ,c,WAAAA,c;AACT,4BAAY1O,GAAZ,EAAkC;AAAA,YAAjBwO,SAAiB,uEAAL,GAAK;;AAAA;;AAE9B,YAAIiG,SAAS7B,uBAAWC,gBAAX,CAA4B7S,GAA5B,EAAiCwO,SAAjC,CAAb;;AAEA,aAAKxM,KAAL,GAAayS,OAAOzS,KAApB;AACA,aAAKiD,iBAAL,GAAyBwP,OAAOxP,iBAAhC;AACA,aAAKC,SAAL,GAAiBuP,OAAOvP,SAAxB;;AAEA,aAAK6O,IAAL,GAAYU,OAAOV,IAAnB;AACA,aAAKzlB,KAAL,GAAammB,OAAOnmB,KAApB;AACA,aAAKulB,QAAL,GAAgBY,OAAOZ,QAAvB;AACA,aAAK1R,aAAL,GAAqBsS,OAAOtS,aAA5B;AACA,aAAKrD,YAAL,GAAoB2V,OAAO3V,YAA3B;AACA,aAAKiZ,UAAL,GAAkBtD,OAAOsD,UAAzB;AACA,aAAKlL,KAAL,GAAa4H,OAAO5H,KAApB;AACA,aAAKoH,OAAL,GAAel0C,SAAf,CAf8B,CAeJ;;AAE1B,aAAKg/B,UAAL,GAAkB0V,OAAO1V,UAAzB;AACH;;;;4BAEgB;AACb,gBAAI,KAAKiZ,UAAT,EAAqB;AACjB,oBAAIxP,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,uBAAO,KAAKwP,UAAL,GAAkBxP,GAAzB;AACH;AACD,mBAAOzoC,SAAP;AACH,S;0BACcwnC,K,EAAM;AACjB,gBAAIxI,aAAav7B,SAAS+jC,KAAT,CAAjB;AACA,gBAAI,OAAOxI,UAAP,KAAsB,QAAtB,IAAkCA,aAAa,CAAnD,EAAsD;AAClD,oBAAIyJ,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,qBAAKwP,UAAL,GAAkBxP,MAAMzJ,UAAxB;AACH;AACJ;;;4BAEa;AACV,gBAAIA,aAAa,KAAKA,UAAtB;AACA,gBAAIA,eAAeh/B,SAAnB,EAA8B;AAC1B,uBAAOg/B,cAAc,CAArB;AACH;AACD,mBAAOh/B,SAAP;AACH;;;4BAEY;AACT,mBAAO,CAAC,KAAK8sC,KAAL,IAAc,EAAf,EAAmBttB,KAAnB,CAAyB,GAAzB,CAAP;AACH;;;4BAEqB;AAClB,mBAAO,KAAK04B,MAAL,CAAY3xC,OAAZ,CAAoBwxC,SAApB,KAAkC,CAAlC,IAAuC,CAAC,CAAC,KAAKjE,QAArD;AACH;;;;;;;;;;;;;;;;;;;;;;;;;ACtDL;;AACA;;AACA;;AACA;;;;;;;;;;+eANA;AACA;;IAOa/E,W,WAAAA,W;;;AACT,2BAAkJ;AAAA,uFAAJ,EAAI;AAAA,YAArI8E,KAAqI,QAArIA,KAAqI;AAAA,YAA9HlH,SAA8H,QAA9HA,SAA8H;AAAA,YAAnH3M,SAAmH,QAAnHA,SAAmH;AAAA,YAAxGyD,YAAwG,QAAxGA,YAAwG;AAAA,YAA1FsQ,aAA0F,QAA1FA,aAA0F;AAAA,YAA3ExG,aAA2E,QAA3EA,aAA2E;AAAA,YAA5DU,aAA4D,QAA5DA,aAA4D;AAAA,YAA7CnB,KAA6C,QAA7CA,KAA6C;AAAA,YAAtCW,gBAAsC,QAAtCA,gBAAsC;AAAA,YAApBE,YAAoB,QAApBA,YAAoB;;AAAA;;AAAA,qDAC9I,kBAAM1rC,UAAU,CAAV,CAAN,CAD8I;;AAG9I,YAAI4xC,UAAU,IAAd,EAAoB;AAChB,kBAAKsE,MAAL,GAAc,uBAAd;AACH,SAFD,MAGK,IAAItE,KAAJ,EAAW;AACZ,kBAAKsE,MAAL,GAActE,KAAd;AACH;;AAED,YAAIE,kBAAkB,IAAtB,EAA4B;AACxB;AACA,kBAAKqE,cAAL,GAAsB,0BAAW,uBAAX,GAAsB,uBAA5C;AACH,SAHD,MAIK,IAAIrE,aAAJ,EAAmB;AACpB,kBAAKqE,cAAL,GAAsBrE,aAAtB;AACH;;AAED,YAAI,MAAKA,aAAT,EAAwB;AACpB,gBAAInnB,OAAOgb,mBAASpc,UAAT,CAAoB,MAAKuoB,aAAzB,EAAwC,QAAxC,CAAX;AACA,kBAAKsE,eAAL,GAAuBzQ,mBAASuB,cAAT,CAAwBvc,IAAxB,CAAvB;AACH;;AAED,cAAKskB,aAAL,GAAqBzN,YAArB;AACA,cAAKmN,UAAL,GAAkBjE,SAAlB;AACA,cAAKtM,UAAL,GAAkBL,SAAlB;AACA,cAAK0R,cAAL,GAAsBnE,aAAtB;AACA,cAAKwD,cAAL,GAAsB9C,aAAtB;AACA,cAAKgD,MAAL,GAAcnE,KAAd;AACA,cAAKmF,iBAAL,GAAyBxE,gBAAzB;AACA,cAAK6K,aAAL,GAAqB3K,YAArB;AA9B8I;AA+BjJ;;0BAoCDU,e,8BAAkB;AACdxvC,iBAAIqgC,KAAJ,CAAU,6BAAV;AACA,eAAOra,KAAKriB,SAAL,CAAe;AAClB63B,gBAAI,KAAKA,EADS;AAElBlH,kBAAM,KAAKA,IAFO;AAGlBolB,qBAAS,KAAKA,OAHI;AAIlB7K,0BAAc,KAAKA,YAJD;AAKlBmG,mBAAO,KAAKA,KALM;AAMlBE,2BAAe,KAAKA,aANF;AAOlBtQ,0BAAc,KAAKA,YAPD;AAQlBkJ,uBAAW,KAAKA,SARE;AASlB3M,uBAAW,KAAKA,SATE;AAUlBuN,2BAAe,KAAKA,aAVF;AAWlBU,2BAAe,KAAKA,aAXF;AAYlBnB,mBAAO,KAAKA,KAZM;AAalBW,8BAAmB,KAAKA,gBAbN;AAclBE,0BAAc,KAAKA;AAdD,SAAf,CAAP;AAgBH,K;;gBAEMqB,iB,8BAAkBwJ,a,EAAe;AACpC35C,iBAAIqgC,KAAJ,CAAU,+BAAV;AACA,YAAI/L,OAAOtO,KAAKrhB,KAAL,CAAWg1C,aAAX,CAAX;AACA,eAAO,IAAIzJ,WAAJ,CAAgB5b,IAAhB,CAAP;AACH,K;;;;4BA1DW;AACR,mBAAO,KAAKglB,MAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKvH,UAAZ;AACH;;;4BACe;AACZ,mBAAO,KAAKvQ,UAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAK6Q,aAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKkH,cAAZ;AACH;;;4BACoB;AACjB,mBAAO,KAAKC,eAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAK3G,cAAZ;AACH;;;4BACmB;AAChB,mBAAO,KAAKX,cAAZ;AACH;;;4BACW;AACR,mBAAO,KAAKE,MAAZ;AACH;;;4BACsB;AACnB,mBAAO,KAAKgB,iBAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKqG,aAAZ;AACH;;;;EAlE4B3I,a;;;;;;;;;;;;;;;;;;;ACLjC;;AACA;;AACA;;0JALA;AACA;;IAMaL,c,WAAAA,c,GACT,8BAAkG;AAAA,QAArFrP,GAAqF,QAArFA,GAAqF;AAAA,QAAhFiN,aAAgF,QAAhFA,aAAgF;AAAA,QAAjEmC,wBAAiE,QAAjEA,wBAAiE;AAAA,QAAvClc,IAAuC,QAAvCA,IAAuC;AAAA,QAAjCqa,gBAAiC,QAAjCA,gBAAiC;AAAA,QAAfE,YAAe,QAAfA,YAAe;;AAAA;;AAC9F,QAAI,CAACzN,GAAL,EAAU;AACNphC,iBAAIojC,KAAJ,CAAU,oCAAV;AACA,cAAM,IAAI3hC,KAAJ,CAAU,KAAV,CAAN;AACH;;AAED,QAAI4sC,aAAJ,EAAmB;AACfjN,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,eAA9B,EAA+CiN,aAA/C,CAAN;AACH;;AAED,QAAImC,wBAAJ,EAA8B;AAC1BpP,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,0BAA9B,EAA0DoP,wBAA1D,CAAN;;AAEA,YAAIlc,IAAJ,EAAU;AACN,iBAAK5E,KAAL,GAAa,IAAIohB,YAAJ,CAAU,EAAExc,UAAF,EAAQua,0BAAR,EAAV,CAAb;;AAEAzN,kBAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8B,OAA9B,EAAuC,KAAK1R,KAAL,CAAW8L,EAAlD,CAAN;AACH;AACJ;;AAED,SAAI,IAAI1H,GAAR,IAAe6a,gBAAf,EAAgC;AAC5BvN,cAAM4S,uBAAW+E,aAAX,CAAyB3X,GAAzB,EAA8BtN,GAA9B,EAAmC6a,iBAAiB7a,GAAjB,CAAnC,CAAN;AACH;;AAED,SAAKsN,GAAL,GAAWA,GAAX;AACH,C;;;;;;;;;;;;;;;;;;;AC9BL;;0JAHA;AACA;;IAIawP,e,WAAAA,e,GACT,yBAAYxP,GAAZ,EAAiB;AAAA;;AAEb,YAAIyU,SAAS7B,uBAAWC,gBAAX,CAA4B7S,GAA5B,EAAiC,GAAjC,CAAb;;AAEA,aAAKgC,KAAL,GAAayS,OAAOzS,KAApB;AACA,aAAKiD,iBAAL,GAAyBwP,OAAOxP,iBAAhC;AACA,aAAKC,SAAL,GAAiBuP,OAAOvP,SAAxB;;AAEA,aAAK5W,KAAL,GAAammB,OAAOnmB,KAApB;AACH,C;;;;;;;;;;;;;;;;;;;ACZL;;0JAHA;AACA;;IAIakqB,kB,WAAAA,kB;AAET,gCAAY7C,WAAZ,EAAyB;AAAA;;AACrB,aAAKE,YAAL,GAAoBF,WAApB;AACH;;iCAEDzT,K,oBAAQ;AACJ,YAAI,CAAC,KAAK/B,SAAV,EAAqB;AACjB,iBAAKA,SAAL,GAAiB,KAAKsY,cAAL,CAAoB9W,IAApB,CAAyB,IAAzB,CAAjB;AACA,iBAAKkU,YAAL,CAAkBE,MAAlB,CAAyBzW,sBAAzB,CAAgD,KAAKa,SAArD;;AAEA;AACA,iBAAK0V,YAAL,CAAkBO,OAAlB,GAA4BnN,IAA5B,CAAiC,gBAAM;AACnC;AACH,aAFD,EAEG0N,KAFH,CAES,eAAK;AACV;AACA/3C,yBAAIojC,KAAJ,CAAU,+CAAV,EAA2D4U,IAAIhS,OAA/D;AACH,aALD;AAMH;AACJ,K;;iCAED3C,I,mBAAO;AACH,YAAI,KAAK9B,SAAT,EAAoB;AAChB,iBAAK0V,YAAL,CAAkBE,MAAlB,CAAyBtW,yBAAzB,CAAmD,KAAKU,SAAxD;AACA,mBAAO,KAAKA,SAAZ;AACH;AACJ,K;;iCAEDsY,c,6BAAiB;AAAA;;AACb,aAAK5C,YAAL,CAAkB6C,YAAlB,GAAiCzP,IAAjC,CAAsC,gBAAQ;AAC1CrqC,qBAAIqgC,KAAJ,CAAU,oEAAV;AACH,SAFD,EAEG,eAAO;AACNrgC,qBAAIojC,KAAJ,CAAU,6DAAV,EAAyE4U,IAAIhS,OAA7E;AACA,kBAAKiR,YAAL,CAAkBE,MAAlB,CAAyB4C,sBAAzB,CAAgD/B,GAAhD;AACH,SALD;AAMH,K;;;;;;;;;;;;;;;;;;;;;;qjBCxCL;AACA;;AAEA;;AACA;;;;;;;;IAEalH,K,WAAAA,K;AACT,qBAAoD;AAAA,uFAAJ,EAAI;AAAA,YAAvCtV,EAAuC,QAAvCA,EAAuC;AAAA,YAAnClH,IAAmC,QAAnCA,IAAmC;AAAA,YAA7BolB,OAA6B,QAA7BA,OAA6B;AAAA,YAApB7K,YAAoB,QAApBA,YAAoB;;AAAA;;AAChD,aAAK+E,GAAL,GAAWpY,MAAM,uBAAjB;AACA,aAAK/1B,KAAL,GAAa6uB,IAAb;;AAEA,YAAI,OAAOolB,OAAP,KAAmB,QAAnB,IAA+BA,UAAU,CAA7C,EAAgD;AAC5C,iBAAKM,QAAL,GAAgBN,OAAhB;AACH,SAFD,MAGK;AACD,iBAAKM,QAAL,GAAgBp1C,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAhB;AACH;AACD,aAAKqQ,aAAL,GAAsBpL,YAAtB;AACH;;oBAeDW,e,8BAAkB;AACdxvC,iBAAIqgC,KAAJ,CAAU,uBAAV;AACA,eAAOra,KAAKriB,SAAL,CAAe;AAClB63B,gBAAI,KAAKA,EADS;AAElBlH,kBAAM,KAAKA,IAFO;AAGlBolB,qBAAS,KAAKA,OAHI;AAIlB7K,0BAAc,KAAKA;AAJD,SAAf,CAAP;AAMH,K;;UAEMsB,iB,8BAAkBwJ,a,EAAe;AACpC35C,iBAAIqgC,KAAJ,CAAU,yBAAV;AACA,eAAO,IAAIyQ,KAAJ,CAAU9qB,KAAKrhB,KAAL,CAAWg1C,aAAX,CAAV,CAAP;AACH,K;;UAEM1I,e,4BAAgBiJ,O,EAASC,G,EAAK;;AAEjC,YAAIC,SAAS7hC,KAAKqxB,GAAL,KAAa,IAAb,GAAoBuQ,GAAjC;;AAEA,eAAOD,QAAQG,UAAR,GAAqBhQ,IAArB,CAA0B,gBAAQ;AACrCrqC,qBAAIqgC,KAAJ,CAAU,iCAAV,EAA6CngB,IAA7C;;AAEA,gBAAIo6B,WAAW,EAAf;;AAHqC,uCAI5Bl4C,CAJ4B;AAKjC,oBAAI0xB,MAAM5T,KAAK9d,CAAL,CAAV;AACIS,oBAAIq3C,QAAQjb,GAAR,CAAYnL,GAAZ,EAAiBuW,IAAjB,CAAsB,gBAAQ;AAClC,wBAAI2F,SAAS,KAAb;;AAEA,wBAAIrJ,IAAJ,EAAU;AACN,4BAAI;AACA,gCAAIjX,QAAQohB,MAAMX,iBAAN,CAAwBxJ,IAAxB,CAAZ;;AAEA3mC,qCAAIqgC,KAAJ,CAAU,4CAAV,EAAwDvM,GAAxD,EAA6DpE,MAAMgqB,OAAnE;;AAEA,gCAAIhqB,MAAMgqB,OAAN,IAAiBU,MAArB,EAA6B;AACzBpK,yCAAS,IAAT;AACH;AACJ,yBARD,CASA,OAAOhuC,CAAP,EAAU;AACNhC,qCAAIojC,KAAJ,CAAU,oDAAV,EAAgEtP,GAAhE,EAAqE9xB,EAAEgkC,OAAvE;AACAgK,qCAAS,IAAT;AACH;AACJ,qBAdD,MAeK;AACDhwC,iCAAIqgC,KAAJ,CAAU,qDAAV,EAAiEvM,GAAjE;AACAkc,iCAAS,IAAT;AACH;;AAED,wBAAIA,MAAJ,EAAY;AACRhwC,iCAAIqgC,KAAJ,CAAU,+CAAV,EAA2DvM,GAA3D;AACA,+BAAOomB,QAAQlK,MAAR,CAAelc,GAAf,CAAP;AACH;AACJ,iBA3BO,CANyB;;;AAmCjCwmB,yBAASh2C,IAAT,CAAczB,CAAd;AAnCiC;;AAIrC,iBAAK,IAAIT,IAAI,CAAb,EAAgBA,IAAI8d,KAAK7d,MAAzB,EAAiCD,GAAjC,EAAsC;AAAA,oBAE9BS,CAF8B;;AAAA,sBAA7BT,CAA6B;AAgCrC;;AAEDpC,qBAAIqgC,KAAJ,CAAU,kDAAV,EAA8Dia,SAASj4C,MAAvE;AACA,mBAAOmgC,QAAQ+X,GAAR,CAAYD,QAAZ,CAAP;AACH,SAxCM,CAAP;AAyCH,K;;;;4BAzEQ;AACL,mBAAO,KAAK1G,GAAZ;AACH;;;4BACU;AACP,mBAAO,KAAKnuC,KAAZ;AACH;;;4BACa;AACV,mBAAO,KAAKu0C,QAAZ;AACH;;;4BACkB;AACf,mBAAO,KAAKC,aAAZ;AACH;;;;;;;;;;;;;;;;;;;;;;;;;AC5BL;;AACA;;AACA;;;;;;+eALA;AACA;;AAMA,IAAMO,gBAAgB,CAAtB,C,CAAyB;;IAEZ7a,K,WAAAA,K;;;AAET,mBAAYzb,IAAZ,EAA6D;AAAA,YAA3C2iB,KAA2C,uEAAnChmC,eAAOgmC,KAA4B;AAAA,YAArB4T,OAAqB,uEAAXt5C,SAAW;;AAAA;;AAAA,qDACzD,kBAAM+iB,IAAN,CADyD;;AAEzD,cAAKyf,MAAL,GAAckD,KAAd;;AAEA,YAAI4T,OAAJ,EAAa;AACT,kBAAKC,QAAL,GAAgBD,OAAhB;AACH,SAFD,MAGK;AACD,kBAAKC,QAAL,GAAgB;AAAA,uBAAMniC,KAAKqxB,GAAL,KAAa,IAAnB;AAAA,aAAhB;AACH;AATwD;AAU5D;;oBAMD3mC,I,iBAAKm9B,Q,EAAU;AACX,YAAIA,YAAY,CAAhB,EAAmB;AACfA,uBAAW,CAAX;AACH;AACDA,mBAAWx7B,SAASw7B,QAAT,CAAX;;AAEA,YAAIua,aAAa,KAAK/Q,GAAL,GAAWxJ,QAA5B;AACA,YAAI,KAAKua,UAAL,KAAoBA,UAApB,IAAkC,KAAKC,YAA3C,EAAyD;AACrD;AACA56C,qBAAIqgC,KAAJ,CAAU,sBAAsB,KAAKmG,KAA3B,GAAmC,oEAA7C,EAAmH,KAAKmU,UAAxH;AACA;AACH;;AAED,aAAKpa,MAAL;;AAEAvgC,iBAAIqgC,KAAJ,CAAU,sBAAsB,KAAKmG,KAA3B,GAAmC,gBAA7C,EAA+DpG,QAA/D;AACA,aAAKya,WAAL,GAAmBF,UAAnB;;AAEA;AACA;AACA;AACA,YAAIG,gBAAgBN,aAApB;AACA,YAAIpa,WAAW0a,aAAf,EAA8B;AAC1BA,4BAAgB1a,QAAhB;AACH;AACD,aAAKwa,YAAL,GAAoB,KAAKjX,MAAL,CAAYC,WAAZ,CAAwB,KAAKrC,SAAL,CAAewB,IAAf,CAAoB,IAApB,CAAxB,EAAmD+X,gBAAgB,IAAnE,CAApB;AACH,K;;oBAMDva,M,qBAAS;AACL,YAAI,KAAKqa,YAAT,EAAuB;AACnB56C,qBAAIqgC,KAAJ,CAAU,gBAAV,EAA4B,KAAKmG,KAAjC;AACA,iBAAK7C,MAAL,CAAYE,aAAZ,CAA0B,KAAK+W,YAA/B;AACA,iBAAKA,YAAL,GAAoB,IAApB;AACH;AACJ,K;;oBAEDrZ,S,wBAAY;AACR,YAAIwZ,OAAO,KAAKF,WAAL,GAAmB,KAAKjR,GAAnC;AACA5pC,iBAAIqgC,KAAJ,CAAU,qBAAqB,KAAKmG,KAA1B,GAAkC,oBAA5C,EAAkEuU,IAAlE;;AAEA,YAAI,KAAKF,WAAL,IAAoB,KAAKjR,GAA7B,EAAkC;AAC9B,iBAAKrJ,MAAL;AACA,6BAAMqG,KAAN;AACH;AACJ,K;;;;4BApDS;AACN,mBAAOhiC,SAAS,KAAK81C,QAAL,EAAT,CAAP;AACH;;;4BA8BgB;AACb,mBAAO,KAAKG,WAAZ;AACH;;;;EAhDsBtU,a;;;;;;;;;;;;;;;;;;;ACN3B;;AACA;;AACA;;0JALA;AACA;;IAMakO,W,WAAAA,W;AACT,yBAAYhI,QAAZ,EAA4F;AAAA,YAAtEC,eAAsE,uEAApDnC,wBAAoD;AAAA,YAAvCuH,mBAAuC,uEAAjBvxC,gCAAiB;;AAAA;;AACxF,YAAI,CAACksC,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,sCAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,EAApB;AACA,aAAKwC,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACH;;0BAEDuJ,Y,2BAAwB;AAAA;;AAAA,YAAX5J,IAAW,uEAAJ,EAAI;;AACpBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAK0O,UAAL,GAAkB1O,KAAK0O,UAAL,IAAmB,oBAArC;AACA1O,aAAKnL,SAAL,GAAiBmL,KAAKnL,SAAL,IAAkB,KAAKwL,SAAL,CAAexL,SAAlD;AACAmL,aAAK1H,YAAL,GAAoB0H,KAAK1H,YAAL,IAAqB,KAAK+H,SAAL,CAAe/H,YAAxD;;AAEA,YAAI,CAAC0H,KAAK6I,IAAV,EAAgB;AACZn1C,qBAAIojC,KAAJ,CAAU,0CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,oBAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAK1H,YAAV,EAAwB;AACpB5kC,qBAAIojC,KAAJ,CAAU,kDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAK4I,aAAV,EAAyB;AACrBl1C,qBAAIojC,KAAJ,CAAU,mDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAKnL,SAAV,EAAqB;AACjBnhC,qBAAIojC,KAAJ,CAAU,+CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsB/B,gBAAtB,CAAuC,KAAvC,EAA8C9C,IAA9C,CAAmD,eAAO;AAC7DrqC,qBAAIqgC,KAAJ,CAAU,mDAAV;;AAEA,mBAAO,MAAKuM,YAAL,CAAkBjB,QAAlB,CAA2BvK,GAA3B,EAAgCkL,IAAhC,EAAsCjC,IAAtC,CAA2C,oBAAY;AAC1DrqC,yBAAIqgC,KAAJ,CAAU,6CAAV;AACA,uBAAOwP,QAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;0BAEDoL,oB,mCAAgC;AAAA;;AAAA,YAAX3O,IAAW,uEAAJ,EAAI;;AAC5BA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAK0O,UAAL,GAAkB1O,KAAK0O,UAAL,IAAmB,eAArC;AACA1O,aAAKnL,SAAL,GAAiBmL,KAAKnL,SAAL,IAAkB,KAAKwL,SAAL,CAAexL,SAAlD;AACAmL,aAAK8C,aAAL,GAAqB9C,KAAK8C,aAAL,IAAsB,KAAKzC,SAAL,CAAeyC,aAA1D;;AAEA,YAAI,CAAC9C,KAAK4O,aAAV,EAAyB;AACrBl7C,qBAAIojC,KAAJ,CAAU,2DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,YAAI,CAAC6qC,KAAKnL,SAAV,EAAqB;AACjBnhC,qBAAIojC,KAAJ,CAAU,uDAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsB/B,gBAAtB,CAAuC,KAAvC,EAA8C9C,IAA9C,CAAmD,eAAO;AAC7DrqC,qBAAIqgC,KAAJ,CAAU,2DAAV;;AAEA,mBAAO,OAAKuM,YAAL,CAAkBjB,QAAlB,CAA2BvK,GAA3B,EAAgCkL,IAAhC,EAAsCjC,IAAtC,CAA2C,oBAAY;AAC1DrqC,yBAAIqgC,KAAJ,CAAU,qDAAV;AACA,uBAAOwP,QAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;;;;;;;;;;;;;;;;;;;;;AC1EL;;AACA;;AACA;;0JALA;AACA;;AAMA,IAAMsL,sBAAsB,cAA5B;AACA,IAAMC,uBAAuB,eAA7B;;IAEaz6C,qB,WAAAA,qB;AACT,mCAAY8rC,QAAZ,EAAyG;AAAA,YAAnFhC,kBAAmF,uEAA9D5pC,eAAO0mC,cAAuD;AAAA,YAAvCuK,mBAAuC,uEAAjBvxC,gCAAiB;;AAAA;;AACrG,YAAI,CAACksC,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,kDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,uBAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAK4O,mBAAL,GAA2B5Q,kBAA3B;AACA,aAAKyE,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACH;;oCAED2O,M,mBAAOjS,K,EAAOkS,Q,EAAiC;AAAA;;AAAA,YAAvBzgC,IAAuB,uEAAhB,cAAgB;;AAC3C,YAAI,CAACuuB,KAAL,EAAY;AACRrpC,qBAAIojC,KAAJ,CAAU,iDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,oBAAV,CAAN;AACH;;AAED,YAAIqZ,SAASqgC,mBAAT,IAAgCrgC,QAAQsgC,oBAA5C,EAAkE;AAC9Dp7C,qBAAIojC,KAAJ,CAAU,kDAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,qBAAV,CAAN;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsB3B,qBAAtB,GAA8ClD,IAA9C,CAAmD,eAAO;AAC7D,gBAAI,CAACjJ,GAAL,EAAU;AACN,oBAAIma,QAAJ,EAAc;AACVv7C,6BAAIojC,KAAJ,CAAU,wDAAV;AACA,0BAAM,IAAI3hC,KAAJ,CAAU,0BAAV,CAAN;AACH;;AAED;AACA;AACH;;AAEDzB,qBAAIqgC,KAAJ,CAAU,4CAA4CvlB,IAAtD;AACA,gBAAIqmB,YAAY,MAAKwL,SAAL,CAAexL,SAA/B;AACA,gBAAIiO,gBAAgB,MAAKzC,SAAL,CAAeyC,aAAnC;AACA,mBAAO,MAAKoM,OAAL,CAAapa,GAAb,EAAkBD,SAAlB,EAA6BiO,aAA7B,EAA4C/F,KAA5C,EAAmDvuB,IAAnD,CAAP;AACH,SAfM,CAAP;AAgBH,K;;oCAED0gC,O,oBAAQpa,G,EAAKD,S,EAAWiO,a,EAAe/F,K,EAAOvuB,I,EAAM;AAAA;;AAEhD,eAAO,IAAI0nB,OAAJ,CAAY,UAACC,OAAD,EAAU6B,MAAV,EAAqB;;AAEpC,gBAAImX,MAAM,IAAI,OAAKJ,mBAAT,EAAV;AACAI,gBAAIjW,IAAJ,CAAS,MAAT,EAAiBpE,GAAjB;;AAEAqa,gBAAI/Y,MAAJ,GAAa,YAAM;AACf1iC,yBAAIqgC,KAAJ,CAAU,8DAAV,EAA0Eob,IAAIxQ,MAA9E;;AAEA,oBAAIwQ,IAAIxQ,MAAJ,KAAe,GAAnB,EAAwB;AACpBxI;AACH,iBAFD,MAGK;AACD6B,2BAAO7iC,MAAMg6C,IAAIjQ,UAAJ,GAAiB,IAAjB,GAAwBiQ,IAAIxQ,MAA5B,GAAqC,GAA3C,CAAP;AACH;AACJ,aATD;AAUAwQ,gBAAIhQ,OAAJ,GAAc,YAAM;AAChBzrC,yBAAIqgC,KAAJ,CAAU,8CAAV;AACAiE,uBAAO,eAAP;AACH,aAHD;;AAKA,gBAAI3B,OAAO,eAAer9B,mBAAmB67B,SAAnB,CAA1B;AACA,gBAAIiO,aAAJ,EAAmB;AACfzM,wBAAQ,oBAAoBr9B,mBAAmB8pC,aAAnB,CAA5B;AACH;AACDzM,oBAAQ,sBAAsBr9B,mBAAmBwV,IAAnB,CAA9B;AACA6nB,oBAAQ,YAAYr9B,mBAAmB+jC,KAAnB,CAApB;;AAEAoS,gBAAI/P,gBAAJ,CAAqB,cAArB,EAAqC,mCAArC;AACA+P,gBAAIhY,IAAJ,CAASd,IAAT;AACH,SA7BM,CAAP;AA8BH,K;;;;;;;;;;;;;;;;;;;;;;AChFL;;AACA;;0JAJA;AACA;;IAKaqR,U,WAAAA,U;;;;;eACF+E,a,0BAAc3X,G,EAAKld,I,EAAMykB,K,EAAO;AACnC,YAAIvH,IAAI15B,OAAJ,CAAY,GAAZ,IAAmB,CAAvB,EAA0B;AACtB05B,mBAAO,GAAP;AACH;;AAED,YAAIA,IAAIA,IAAI/+B,MAAJ,GAAa,CAAjB,MAAwB,GAA5B,EAAiC;AAC7B++B,mBAAO,GAAP;AACH;;AAEDA,eAAO97B,mBAAmB4e,IAAnB,CAAP;AACAkd,eAAO,GAAP;AACAA,eAAO97B,mBAAmBqjC,KAAnB,CAAP;;AAEA,eAAOvH,GAAP;AACH,K;;eAEM6S,gB,6BAAiBtL,K,EAAyC;AAAA,YAAlCiH,SAAkC,uEAAtB,GAAsB;AAAA,YAAjB8L,MAAiB,uEAAR76C,cAAQ;;AAC7D,YAAI,OAAO8nC,KAAP,KAAiB,QAArB,EAA8B;AAC1BA,oBAAQ+S,OAAOtU,QAAP,CAAgBiB,IAAxB;AACH;;AAED,YAAIzG,MAAM+G,MAAMgT,WAAN,CAAkB/L,SAAlB,CAAV;AACA,YAAIhO,OAAO,CAAX,EAAc;AACV+G,oBAAQA,MAAM9jC,MAAN,CAAa+8B,MAAM,CAAnB,CAAR;AACH;;AAED,YAAIgO,cAAc,GAAlB,EAAuB;AACnB;AACAhO,kBAAM+G,MAAMjhC,OAAN,CAAc,GAAd,CAAN;AACA,gBAAIk6B,OAAO,CAAX,EAAc;AACV+G,wBAAQA,MAAM9jC,MAAN,CAAa,CAAb,EAAgB+8B,GAAhB,CAAR;AACH;AACJ;;AAED,YAAImC,SAAS,EAAb;AAAA,YACI6X,QAAQ,mBADZ;AAAA,YAEIr3C,CAFJ;;AAIA,YAAIs3C,UAAU,CAAd;AACA,eAAOt3C,IAAIq3C,MAAME,IAAN,CAAWnT,KAAX,CAAX,EAA8B;AAC1B5E,mBAAO5+B,mBAAmBZ,EAAE,CAAF,CAAnB,CAAP,IAAmCY,mBAAmBZ,EAAE,CAAF,CAAnB,CAAnC;AACA,gBAAIs3C,YAAY,EAAhB,EAAoB;AAChB77C,yBAAIojC,KAAJ,CAAU,8EAAV,EAA0FuF,KAA1F;AACA,uBAAO;AACHvF,2BAAO;AADJ,iBAAP;AAGH;AACJ;;AAED,aAAK,IAAI2Y,IAAT,IAAiBhY,MAAjB,EAAyB;AACrB,mBAAOA,MAAP;AACH;;AAED,eAAO,EAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;qjBC7DL;AACA;;AAEA;;;;IAEajjC,I,WAAAA,I;AACT,wBAAmH;AAAA,YAAtGm0C,QAAsG,QAAtGA,QAAsG;AAAA,YAA5F1R,aAA4F,QAA5FA,aAA4F;AAAA,YAA7ErD,YAA6E,QAA7EA,YAA6E;AAAA,YAA/Dgb,aAA+D,QAA/DA,aAA+D;AAAA,YAAhD/B,UAAgD,QAAhDA,UAAgD;AAAA,YAApClL,KAAoC,QAApCA,KAAoC;AAAA,YAA7BoH,OAA6B,QAA7BA,OAA6B;AAAA,YAApB+D,UAAoB,QAApBA,UAAoB;AAAA,YAAR1pB,KAAQ,QAARA,KAAQ;;AAAA;;AAC/G,aAAKulB,QAAL,GAAgBA,QAAhB;AACA,aAAK1R,aAAL,GAAqBA,aAArB;AACA,aAAKrD,YAAL,GAAoBA,YAApB;AACA,aAAKgb,aAAL,GAAqBA,aAArB;AACA,aAAK/B,UAAL,GAAkBA,UAAlB;AACA,aAAKlL,KAAL,GAAaA,KAAb;AACA,aAAKoH,OAAL,GAAeA,OAAf;AACA,aAAK+D,UAAL,GAAkBA,UAAlB;AACA,aAAK1pB,KAAL,GAAaA,KAAb;AACH;;mBA6BD8f,e,8BAAkB;AACdxvC,iBAAIqgC,KAAJ,CAAU,sBAAV;AACA,eAAOra,KAAKriB,SAAL,CAAe;AAClBsxC,sBAAU,KAAKA,QADG;AAElB1R,2BAAe,KAAKA,aAFF;AAGlBrD,0BAAc,KAAKA,YAHD;AAIlBgb,2BAAe,KAAKA,aAJF;AAKlB/B,wBAAY,KAAKA,UALC;AAMlBlL,mBAAO,KAAKA,KANM;AAOlBoH,qBAAS,KAAKA,OAPI;AAQlB+D,wBAAY,KAAKA;AARC,SAAf,CAAP;AAUH,K;;SAEMjJ,iB,8BAAkBwJ,a,EAAe;AACpC35C,iBAAIqgC,KAAJ,CAAU,wBAAV;AACA,eAAO,IAAIv/B,IAAJ,CAASklB,KAAKrhB,KAAL,CAAWg1C,aAAX,CAAT,CAAP;AACH,K;;;;4BA5CgB;AACb,gBAAI,KAAKP,UAAT,EAAqB;AACjB,oBAAIxP,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,uBAAO,KAAKwP,UAAL,GAAkBxP,GAAzB;AACH;AACD,mBAAOzoC,SAAP;AACH,S;0BACcwnC,K,EAAO;AAClB,gBAAIxI,aAAav7B,SAAS+jC,KAAT,CAAjB;AACA,gBAAI,OAAOxI,UAAP,KAAsB,QAAtB,IAAkCA,aAAa,CAAnD,EAAsD;AAClD,oBAAIyJ,MAAMhlC,SAAS2T,KAAKqxB,GAAL,KAAa,IAAtB,CAAV;AACA,qBAAKwP,UAAL,GAAkBxP,MAAMzJ,UAAxB;AACH;AACJ;;;4BAEa;AACV,gBAAIA,aAAa,KAAKA,UAAtB;AACA,gBAAIA,eAAeh/B,SAAnB,EAA8B;AAC1B,uBAAOg/B,cAAc,CAArB;AACH;AACD,mBAAOh/B,SAAP;AACH;;;4BAEY;AACT,mBAAO,CAAC,KAAK8sC,KAAL,IAAc,EAAf,EAAmBttB,KAAnB,CAAyB,GAAzB,CAAP;AACH;;;;;;;;;;;;;;;;;;;;;;;ACxCL;;AACA;;AACA;;AACA;;0JANA;AACA;;IAOa2zB,e,WAAAA,e;AACT,6BACI7H,QADJ,EAKE;AAAA,YAHEC,eAGF,uEAHoBnC,wBAGpB;AAAA,YAFEuH,mBAEF,uEAFwBvxC,gCAExB;AAAA,YADEg0C,QACF,uEADaxL,kBACb;;AAAA;;AACE,YAAI,CAAC0D,QAAL,EAAe;AACXzsC,qBAAIojC,KAAJ,CAAU,0CAAV;AACA,kBAAM,IAAI3hC,KAAJ,CAAU,UAAV,CAAN;AACH;;AAED,aAAKkrC,SAAL,GAAiBF,QAAjB;AACA,aAAKG,YAAL,GAAoB,IAAIF,eAAJ,CAAoBvrC,SAApB,EAA+BA,SAA/B,EAA0C,KAAK66C,iBAAL,CAAuBjZ,IAAvB,CAA4B,IAA5B,CAA1C,CAApB;AACA,aAAKmM,gBAAL,GAAwB,IAAI4C,mBAAJ,CAAwB,KAAKnF,SAA7B,CAAxB;AACA,aAAKgI,SAAL,GAAiBJ,QAAjB;AACH;;8BAEDe,S,sBAAUjM,K,EAAO;AAAA;;AACb,YAAI,CAACA,KAAL,EAAY;AACRrpC,qBAAIojC,KAAJ,CAAU,4CAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,qBAAV,CAAf,CAAP;AACH;;AAED,eAAO,KAAKytC,gBAAL,CAAsBhC,mBAAtB,GAA4C7C,IAA5C,CAAiD,eAAO;AAC3DrqC,qBAAIqgC,KAAJ,CAAU,kDAAV,EAA8De,GAA9D;;AAEA,mBAAO,MAAKwL,YAAL,CAAkB9B,OAAlB,CAA0B1J,GAA1B,EAA+BiI,KAA/B,EAAsCgB,IAAtC,CAA2C,kBAAU;AACxDrqC,yBAAIqgC,KAAJ,CAAU,4CAAV,EAAwDkV,MAAxD;AACA,uBAAOA,MAAP;AACH,aAHM,CAAP;AAIH,SAPM,CAAP;AAQH,K;;8BAEDyG,iB,8BAAkBjR,G,EAAK;AAAA;;AACnB,YAAI;AACA,gBAAI3B,MAAM,KAAKuL,SAAL,CAAexL,QAAf,CAAwB4B,IAAIQ,YAA5B,CAAV;AACA,gBAAI,CAACnC,GAAD,IAAQ,CAACA,IAAIE,MAAb,IAAuB,CAACF,IAAIG,OAAhC,EAAyC;AACrCvpC,yBAAIojC,KAAJ,CAAU,wDAAV,EAAoEgG,GAApE;AACA,uBAAO5G,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,0BAAV,CAAf,CAAP;AACH;;AAED,gBAAIs5B,MAAMqO,IAAIE,MAAJ,CAAWvO,GAArB;;AAEA,gBAAIkhB,sBAAJ;AACA,oBAAQ,KAAKtP,SAAL,CAAegF,iBAAvB;AACI,qBAAK,IAAL;AACIsK,oCAAgB,KAAK/M,gBAAL,CAAsBnC,SAAtB,EAAhB;AACA;AACJ,qBAAK,KAAL;AACIkP,oCAAgBzZ,QAAQC,OAAR,CAAgB2G,IAAIG,OAAJ,CAAY9L,GAA5B,CAAhB;AACA;AACJ;AACIwe,oCAAgBzZ,QAAQC,OAAR,CAAgB,KAAKkK,SAAL,CAAegF,iBAA/B,CAAhB;AACA;AATR;;AAYA,mBAAOsK,cAAc5R,IAAd,CAAmB,kBAAU;AAChCrqC,yBAAIqgC,KAAJ,CAAU,wDAAwDoJ,MAAlE;;AAEA,uBAAO,OAAKyF,gBAAL,CAAsBzB,cAAtB,GAAuCpD,IAAvC,CAA4C,gBAAQ;AACvD,wBAAI,CAACnqB,IAAL,EAAW;AACPlgB,iCAAIojC,KAAJ,CAAU,kEAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,+BAAV,CAAf,CAAP;AACH;;AAEDzB,6BAAIqgC,KAAJ,CAAU,0DAAV;AACA,wBAAIvM,YAAJ;AACA,wBAAI,CAACiH,GAAL,EAAU;AACN7a,+BAAO,OAAKq2B,YAAL,CAAkBr2B,IAAlB,EAAwBkpB,IAAIE,MAAJ,CAAW1c,GAAnC,CAAP;;AAEA,4BAAI1M,KAAK7d,MAAL,GAAc,CAAlB,EAAqB;AACjBrC,qCAAIojC,KAAJ,CAAU,qGAAV;AACA,mCAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kEAAV,CAAf,CAAP;AACH,yBAHD,MAIK;AACD;AACA;AACAqyB,kCAAM5T,KAAK,CAAL,CAAN;AACH;AACJ,qBAZD,MAaK;AACD4T,8BAAM5T,KAAKs2B,MAAL,CAAY,eAAO;AACrB,mCAAO1iB,IAAIiH,GAAJ,KAAYA,GAAnB;AACH,yBAFK,EAEH,CAFG,CAAN;AAGH;;AAED,wBAAI,CAACjH,GAAL,EAAU;AACN9zB,iCAAIojC,KAAJ,CAAU,qFAAV;AACA,+BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED,wBAAIioC,WAAW,OAAKiD,SAAL,CAAexL,SAA9B;;AAEA,wBAAIkV,qBAAqB,OAAK1J,SAAL,CAAehD,SAAxC;AACA3pC,6BAAIqgC,KAAJ,CAAU,sFAAV,EAAkGgW,kBAAlG;;AAEA,2BAAO,OAAK1B,SAAL,CAAenL,WAAf,CAA2BuB,IAAIQ,YAA/B,EAA6CzX,GAA7C,EAAkD2V,MAAlD,EAA0DC,QAA1D,EAAoE2M,kBAApE,EAAwFl1C,SAAxF,EAAmG,IAAnG,EAAyGkpC,IAAzG,CAA8G,YAAM;AACvHrqC,iCAAIqgC,KAAJ,CAAU,8DAAV;AACA,+BAAO+I,IAAIG,OAAX;AACH,qBAHM,CAAP;AAIH,iBAzCM,CAAP;AA0CH,aA7CM,CAAP;AA8CA;AACH,SArED,CAsEA,OAAOvnC,CAAP,EAAU;AACNhC,qBAAIojC,KAAJ,CAAU,+DAAV,EAA2EphC,EAAEgkC,OAA7E;AACA1B,mBAAOtiC,CAAP;AACA;AACH;AACJ,K;;8BAEDu0C,Y,yBAAar2B,I,EAAM0M,G,EAAK;AACpB,YAAIyJ,MAAM,IAAV;AACA,YAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AACtBjV,kBAAM,KAAN;AACH,SAFD,MAGK,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA,IAAIzJ,IAAI0e,UAAJ,CAAe,IAAf,CAAJ,EAA0B;AAC3BjV,kBAAM,IAAN;AACH,SAFI,MAGA;AACDr2B,qBAAIqgC,KAAJ,CAAU,mDAAV,EAA+DzT,GAA/D;AACA,mBAAO,EAAP;AACH;;AAED5sB,iBAAIqgC,KAAJ,CAAU,iEAAV,EAA6EhK,GAA7E;;AAEAnW,eAAOA,KAAKs2B,MAAL,CAAY,eAAO;AACtB,mBAAO1iB,IAAIuC,GAAJ,KAAYA,GAAnB;AACH,SAFM,CAAP;;AAIAr2B,iBAAIqgC,KAAJ,CAAU,+DAAV,EAA2EhK,GAA3E,EAAgFnW,KAAK7d,MAArF;;AAEA,eAAO6d,IAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;;;AC9IL;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;;;+eAZA;AACA;;IAca7f,W,WAAAA,W;;;AACT,2BAME;AAAA,YANUosC,QAMV,uEANqB,EAMrB;AAAA,YALEyP,sBAKF,uEAL2BtC,sCAK3B;AAAA,YAJEuC,kBAIF,uEAJuBv7C,8BAIvB;AAAA,YAHEw7C,yBAGF,uEAH8Bz7C,4CAG9B;AAAA,YAFE6zC,eAEF,uEAFoBC,wBAEpB;AAAA,YADEF,QACF,uEADaxL,kBACb;;AAAA;;AAEE,YAAI,EAAE0D,oBAAoB4P,wCAAtB,CAAJ,EAAgD;AAC5C5P,uBAAW,IAAI4P,wCAAJ,CAAwB5P,QAAxB,CAAX;AACH;;AAJH,qDAKE,uBAAMA,QAAN,CALF;;AAOE,cAAK6P,OAAL,GAAe,IAAIC,oCAAJ,CAAsB9P,QAAtB,CAAf;AACA,cAAK+P,mBAAL,GAA2B,IAAIN,sBAAJ,OAA3B;;AAEA;AACA,YAAI,MAAKzP,QAAL,CAAcgQ,oBAAlB,EAAwC;AACpCz8C,qBAAIqgC,KAAJ,CAAU,+EAAV;AACA,kBAAKqc,gBAAL;AACH;;AAED,YAAI,MAAKjQ,QAAL,CAAckQ,cAAlB,EAAkC;AAC9B38C,qBAAIqgC,KAAJ,CAAU,4EAAV;AACA,kBAAKuc,eAAL,GAAuB,IAAIT,kBAAJ,OAAvB;AACH;;AAED,cAAKU,sBAAL,GAA8B,IAAIT,yBAAJ,CAA8B,MAAKzP,SAAnC,CAA9B;AACA,cAAKiI,YAAL,GAAoB,IAAIJ,eAAJ,CAAoB,MAAK7H,SAAzB,CAApB;AACA,cAAKgI,SAAL,GAAiBJ,QAAjB;AAvBF;AAwBD;;0BAmBDiD,O,sBAAU;AAAA;;AACN,eAAO,KAAKsF,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,gBAAIoN,IAAJ,EAAU;AACNz3C,yBAAI6rC,IAAJ,CAAS,kCAAT;;AAEA,uBAAKyQ,OAAL,CAAatc,IAAb,CAAkByX,IAAlB,EAAwB,KAAxB;;AAEA,uBAAOA,IAAP;AACH,aAND,MAOK;AACDz3C,yBAAI6rC,IAAJ,CAAS,gDAAT;AACA,uBAAO,IAAP;AACH;AACJ,SAZM,CAAP;AAaH,K;;0BAEDkR,U,yBAAa;AAAA;;AACT,eAAO,KAAKC,SAAL,CAAe,IAAf,EAAqB3S,IAArB,CAA0B,YAAM;AACnCrqC,qBAAI6rC,IAAJ,CAAS,mDAAT;AACA,mBAAKyQ,OAAL,CAAa7b,MAAb;AACH,SAHM,CAAP;AAIH,K;;0BAEDwc,c,6BAA0B;AAAA,YAAX3Q,IAAW,uEAAJ,EAAI;;AACtBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIqO,YAAY;AACZ/I,kCAAuB7H,KAAK6H;AADhB,SAAhB;AAGA,eAAO,KAAKgJ,YAAL,CAAkB7Q,IAAlB,EAAwB,KAAK8Q,kBAA7B,EAAiDF,SAAjD,EAA4D7S,IAA5D,CAAiE,YAAI;AACxErqC,qBAAI6rC,IAAJ,CAAS,wCAAT;AACH,SAFM,CAAP;AAGH,K;;0BACDwR,sB,mCAAuBjc,G,EAAK;AACxB,eAAO,KAAKkc,UAAL,CAAgBlc,OAAO,KAAKgc,kBAAL,CAAwBhc,GAA/C,EAAoDiJ,IAApD,CAAyD,gBAAQ;AACpE,gBAAIoN,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,yBAAI6rC,IAAJ,CAAS,iEAAT,EAA4E4L,KAAKpC,OAAL,CAAa3X,GAAzF;AACH,aAFD,MAGK;AACD19B,yBAAI6rC,IAAJ,CAAS,4CAAT;AACH;;AAED,mBAAO4L,IAAP;AACH,SATM,CAAP;AAUH,K;;0BAED8F,W,0BAAuB;AAAA,YAAXjR,IAAW,uEAAJ,EAAI;;AACnBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIzN,MAAMkL,KAAK1H,YAAL,IAAqB,KAAK6H,QAAL,CAAc+Q,kBAAnC,IAAyD,KAAK/Q,QAAL,CAAc7H,YAAjF;AACA,YAAI,CAACxD,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,2EAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,kDAAV,CAAf,CAAP;AACH;;AAED6qC,aAAK1H,YAAL,GAAoBxD,GAApB;AACAkL,aAAKlK,OAAL,GAAe,OAAf;;AAEA,eAAO,KAAKqb,OAAL,CAAanR,IAAb,EAAmB,KAAKoR,eAAxB,EAAyC;AAC5C7Y,sBAAUzD,GADkC;AAE5C4C,iCAAqBsI,KAAKtI,mBAAL,IAA4B,KAAKyI,QAAL,CAAczI,mBAFnB;AAG5CW,+BAAmB2H,KAAK3H,iBAAL,IAA0B,KAAK8H,QAAL,CAAc9H;AAHf,SAAzC,EAIJ0F,IAJI,CAIC,gBAAQ;AACZ,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,kEAAT,EAA6E4L,KAAKpC,OAAL,CAAa3X,GAA1F;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,iCAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAfM,CAAP;AAgBH,K;;0BACDkG,mB,gCAAoBvc,G,EAAK;AACrB,eAAO,KAAKwc,eAAL,CAAqBxc,GAArB,EAA0B,KAAKsc,eAA/B,EAAgDrT,IAAhD,CAAqD,gBAAQ;AAChE,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,8DAAT,EAAyE4L,KAAKpC,OAAL,CAAa3X,GAAtF;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,yCAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAXM,EAWJM,KAXI,CAWE,eAAK;AACV/3C,qBAAIojC,KAAJ,CAAU,SAAmD4U,IAAIhS,OAAjE;AACH,SAbM,CAAP;AAcH,K;;0BAED8T,Y,2BAAwB;AAAA;;AAAA,YAAXxN,IAAW,uEAAJ,EAAI;;AACpBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA;AACA,eAAO,KAAKiO,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,gBAAIoN,QAAQA,KAAKyD,aAAjB,EAAgC;AAC5B5O,qBAAK4O,aAAL,GAAqBzD,KAAKyD,aAA1B;AACA,uBAAO,OAAK2C,gBAAL,CAAsBvR,IAAtB,CAAP;AACH,aAHD,MAIK;AACDA,qBAAK+B,aAAL,GAAqB/B,KAAK+B,aAAL,IAAuB,OAAK5B,QAAL,CAAcqR,2BAAd,IAA6CrG,IAA7C,IAAqDA,KAAKxC,QAAtG;AACA,oBAAIwC,QAAQ,OAAK9K,SAAL,CAAeoR,wBAA3B,EAAqD;AACjD/9C,6BAAIqgC,KAAJ,CAAU,2DAAV,EAAuEoX,KAAKpC,OAAL,CAAa3X,GAApF;AACA4O,yBAAK0R,WAAL,GAAmBvG,KAAKpC,OAAL,CAAa3X,GAAhC;AACH;AACD,uBAAO,OAAKugB,mBAAL,CAAyB3R,IAAzB,CAAP;AACH;AACJ,SAbM,CAAP;AAcH,K;;0BAEDuR,gB,+BAA4B;AAAA;;AAAA,YAAXvR,IAAW,uEAAJ,EAAI;;AACxB,eAAO,KAAKsI,YAAL,CAAkBqG,oBAAlB,CAAuC3O,IAAvC,EAA6CjC,IAA7C,CAAkD,kBAAU;AAC/D,gBAAI,CAACsL,MAAL,EAAa;AACT31C,yBAAIojC,KAAJ,CAAU,wEAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,0CAAf,CAAP;AACH;AACD,gBAAI,CAACqR,OAAOzV,YAAZ,EAA0B;AACtBlgC,yBAAIojC,KAAJ,CAAU,4EAAV;AACA,uBAAOZ,QAAQ8B,MAAR,CAAe,8CAAf,CAAP;AACH;;AAED,mBAAO,OAAKwY,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,oBAAIoN,IAAJ,EAAU;AACN,wBAAIyG,oBAAoB1b,QAAQC,OAAR,EAAxB;AACA,wBAAIkT,OAAOV,QAAX,EAAqB;AACjBiJ,4CAAoB,OAAKC,qCAAL,CAA2C1G,KAAKpC,OAAhD,EAAyDM,OAAOV,QAAhE,CAApB;AACH;;AAED,2BAAOiJ,kBAAkB7T,IAAlB,CAAuB,YAAM;AAChCrqC,iCAAIqgC,KAAJ,CAAU,8DAAV;AACAoX,6BAAKxC,QAAL,GAAgBU,OAAOV,QAAvB;AACAwC,6BAAKvX,YAAL,GAAoByV,OAAOzV,YAA3B;AACAuX,6BAAKyD,aAAL,GAAqBvF,OAAOuF,aAAP,IAAwBzD,KAAKyD,aAAlD;AACAzD,6BAAKtX,UAAL,GAAkBwV,OAAOxV,UAAzB;;AAEA,+BAAO,OAAK6c,SAAL,CAAevF,IAAf,EAAqBpN,IAArB,CAA0B,YAAI;AACjC,mCAAKiS,OAAL,CAAatc,IAAb,CAAkByX,IAAlB;AACA,mCAAOA,IAAP;AACH,yBAHM,CAAP;AAIH,qBAXM,CAAP;AAYH,iBAlBD,MAmBK;AACD,2BAAO,IAAP;AACH;AACJ,aAvBM,CAAP;AAwBH,SAlCM,CAAP;AAmCH,K;;0BAED0G,qC,kDAAsC9I,O,EAASJ,Q,EAAU;AAAA;;AACrD,eAAO,KAAK/F,gBAAL,CAAsBnC,SAAtB,GAAkC1C,IAAlC,CAAuC,kBAAU;AACpD,mBAAO,OAAKsK,SAAL,CAAe3K,qBAAf,CAAqCiL,QAArC,EAA+CxL,MAA/C,EAAuD,OAAKkD,SAAL,CAAexL,SAAtE,EAAiF,OAAKwL,SAAL,CAAehD,SAAhG,EAA2GU,IAA3G,CAAgH,mBAAW;AAC9H,oBAAI,CAACd,OAAL,EAAc;AACVvpC,6BAAIojC,KAAJ,CAAU,gFAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6BAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQ7L,GAAR,KAAgB2X,QAAQ3X,GAA5B,EAAiC;AAC7B19B,6BAAIojC,KAAJ,CAAU,+FAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,4CAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQ6U,SAAR,IAAqB7U,QAAQ6U,SAAR,KAAsB/I,QAAQ+I,SAAvD,EAAkE;AAC9Dp+C,6BAAIojC,KAAJ,CAAU,4GAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,yDAAV,CAAf,CAAP;AACH;AACD,oBAAI8nC,QAAQW,GAAR,IAAeX,QAAQW,GAAR,KAAgBmL,QAAQnL,GAA3C,EAAgD;AAC5ClqC,6BAAIojC,KAAJ,CAAU,gGAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,6CAAV,CAAf,CAAP;AACH;AACD,oBAAI,CAAC8nC,QAAQW,GAAT,IAAgBmL,QAAQnL,GAA5B,EAAiC;AAC7BlqC,6BAAIojC,KAAJ,CAAU,0GAAV;AACA,2BAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,uDAAV,CAAf,CAAP;AACH;AACJ,aArBM,CAAP;AAsBH,SAvBM,CAAP;AAwBH,K;;0BAEDw8C,mB,kCAA+B;AAAA,YAAX3R,IAAW,uEAAJ,EAAI;;AAC3B,YAAIlL,MAAMkL,KAAK1H,YAAL,IAAqB,KAAK6H,QAAL,CAAc4R,mBAAnC,IAA0D,KAAK5R,QAAL,CAAc7H,YAAlF;AACA,YAAI,CAACxD,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,6DAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,mCAAV,CAAf,CAAP;AACH;;AAED6qC,aAAK1H,YAAL,GAAoBxD,GAApB;AACAkL,aAAK4B,MAAL,GAAc5B,KAAK4B,MAAL,IAAe,MAA7B;;AAEA,eAAO,KAAKuP,OAAL,CAAanR,IAAb,EAAmB,KAAKgS,gBAAxB,EAA0C;AAC7CzZ,sBAAUzD,GADmC;AAE7C0G,kCAAsBwE,KAAKxE,oBAAL,IAA6B,KAAK2E,QAAL,CAAc3E;AAFpB,SAA1C,EAGJuC,IAHI,CAGC,gBAAQ;AACZ,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,uDAAT,EAAkE4L,KAAKpC,OAAL,CAAa3X,GAA/E;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,kCAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAdM,CAAP;AAeH,K;;0BAED8G,oB,iCAAqBnd,G,EAAK;AACtB,eAAO,KAAKwc,eAAL,CAAqBxc,GAArB,EAA0B,KAAKkd,gBAA/B,EAAiDjU,IAAjD,CAAsD,gBAAQ;AACjE,gBAAIoN,IAAJ,EAAU;AACN,oBAAIA,KAAKpC,OAAL,IAAgBoC,KAAKpC,OAAL,CAAa3X,GAAjC,EAAsC;AAClC19B,6BAAI6rC,IAAJ,CAAS,+DAAT,EAA0E4L,KAAKpC,OAAL,CAAa3X,GAAvF;AACH,iBAFD,MAGK;AACD19B,6BAAI6rC,IAAJ,CAAS,0CAAT;AACH;AACJ;;AAED,mBAAO4L,IAAP;AACH,SAXM,CAAP;AAYH,K;;0BAED+G,c,2BAAepd,G,EAAK;AAAA;;AAChB,eAAO,KAAKqO,uBAAL,CAA6BrO,GAA7B,EAAkCiJ,IAAlC,CAAuC,gBAAuB;AAAA,gBAArB3a,KAAqB,QAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,QAAdA,QAAc;;AACjE,gBAAIngB,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAKwO,sBAAL,CAA4Bjc,GAA5B,CAAP;AACH;AACD,gBAAI1R,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAK8O,mBAAL,CAAyBvc,GAAzB,CAAP;AACH;AACD,gBAAI1R,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,uBAAO,OAAK0P,oBAAL,CAA0Bnd,GAA1B,CAAP;AACH;AACD,mBAAOoB,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gCAAV,CAAf,CAAP;AACH,SAXM,CAAP;AAYH,K;;0BAEDg9C,e,4BAAgBrd,G,EAAKmS,Q,EAAU;AAAA;;AAC3B,eAAO,KAAK5C,wBAAL,CAA8BvP,GAA9B,EAAmCiJ,IAAnC,CAAwC,iBAAuB;AAAA,gBAArB3a,KAAqB,SAArBA,KAAqB;AAAA,gBAAdmgB,QAAc,SAAdA,QAAc;;AAClE,gBAAIngB,KAAJ,EAAW;AACP,oBAAIA,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,2BAAO,OAAK6P,uBAAL,CAA6Btd,GAA7B,CAAP;AACH;AACD,oBAAI1R,MAAMmf,YAAN,KAAuB,MAA3B,EAAmC;AAC/B,2BAAO,OAAK8P,oBAAL,CAA0Bvd,GAA1B,EAA+BmS,QAA/B,CAAP;AACH;AACD,uBAAO/Q,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gCAAV,CAAf,CAAP;AACH;AACD,mBAAOouC,QAAP;AACH,SAXM,CAAP;AAYH,K;;0BAED8H,kB,iCAA8B;AAAA;;AAAA,YAAXrL,IAAW,uEAAJ,EAAI;;AAC1BA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB,CAH0B,CAGE;AAC5B,YAAIzN,MAAMkL,KAAK1H,YAAL,IAAqB,KAAK6H,QAAL,CAAc4R,mBAAnC,IAA0D,KAAK5R,QAAL,CAAc7H,YAAlF;AACA,YAAI,CAACxD,GAAL,EAAU;AACNphC,qBAAIojC,KAAJ,CAAU,mEAAV;AACA,mBAAOZ,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,mCAAV,CAAf,CAAP;AACH;;AAED6qC,aAAK1H,YAAL,GAAoBxD,GAApB;AACAkL,aAAK4B,MAAL,GAAc,MAAd;AACA5B,aAAK0B,aAAL,GAAqB1B,KAAK0B,aAAL,IAAsB,KAAKvB,QAAL,CAAcmS,0BAAzD;AACAtS,aAAK2B,KAAL,GAAa3B,KAAK2B,KAAL,IAAc,QAA3B;AACA3B,aAAKwC,YAAL,GAAoB,IAApB;;AAEA,eAAO,KAAKqO,YAAL,CAAkB7Q,IAAlB,EAAwB,KAAKgS,gBAA7B,EAA+C;AAClDzZ,sBAAUzD,GADwC;AAElD0G,kCAAsBwE,KAAKxE,oBAAL,IAA6B,KAAK2E,QAAL,CAAc3E;AAFf,SAA/C,EAGJuC,IAHI,CAGC,uBAAe;AACnB,mBAAO,OAAK+F,qBAAL,CAA2ByO,YAAYzd,GAAvC,EAA4CiJ,IAA5C,CAAiD,0BAAkB;AACtErqC,yBAAIqgC,KAAJ,CAAU,qDAAV;;AAEA,oBAAIye,eAAevb,aAAf,IAAgCub,eAAezJ,OAAf,CAAuB3X,GAA3D,EAAgE;AAC5D19B,6BAAI6rC,IAAJ,CAAS,sEAAT,EAAkFiT,eAAezJ,OAAf,CAAuB3X,GAAzG;AACA,2BAAO;AACH6F,uCAAeub,eAAevb,aAD3B;AAEH7F,6BAAKohB,eAAezJ,OAAf,CAAuB3X,GAFzB;AAGHoa,6BAAKgH,eAAezJ,OAAf,CAAuByC;AAHzB,qBAAP;AAKH,iBAPD,MAQK;AACD93C,6BAAI6rC,IAAJ,CAAS,uDAAT;AACH;AACJ,aAdM,EAeNkM,KAfM,CAeA,eAAO;AACV,oBAAIC,IAAIzU,aAAJ,IAAqB,OAAKkJ,QAAL,CAAciL,uBAAvC,EAAgE;AAC5D,wBAAIM,IAAIhS,OAAJ,IAAe,gBAAf,IACAgS,IAAIhS,OAAJ,IAAe,kBADf,IAEAgS,IAAIhS,OAAJ,IAAe,sBAFf,IAGAgS,IAAIhS,OAAJ,IAAe,4BAHnB,EAIE;AACEhmC,iCAAI6rC,IAAJ,CAAS,+EAAT;AACA,+BAAO;AACHtI,2CAAeyU,IAAIzU;AADhB,yBAAP;AAGH;AACJ;;AAED,sBAAMyU,GAAN;AACH,aA9BM,CAAP;AA+BH,SAnCM,CAAP;AAoCH,K;;0BAEDyF,O,oBAAQnR,I,EAAMvrC,S,EAAiC;AAAA;;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;AAC3C,eAAO,KAAK5B,YAAL,CAAkB7Q,IAAlB,EAAwBvrC,SAAxB,EAAmCg+C,eAAnC,EAAoD1U,IAApD,CAAyD,uBAAe;AAC3E,mBAAO,QAAKiT,UAAL,CAAgBuB,YAAYzd,GAA5B,EAAiCkL,IAAjC,CAAP;AACH,SAFM,CAAP;AAGH,K;;0BACD6Q,Y,yBAAa7Q,I,EAAMvrC,S,EAAiC;AAAA;;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;;AAEhD,eAAOh+C,UAAU+iC,OAAV,CAAkBib,eAAlB,EAAmC1U,IAAnC,CAAwC,kBAAU;AACrDrqC,qBAAIqgC,KAAJ,CAAU,uDAAV;;AAEA,mBAAO,QAAK0N,mBAAL,CAAyBzB,IAAzB,EAA+BjC,IAA/B,CAAoC,yBAAiB;AACxDrqC,yBAAIqgC,KAAJ,CAAU,8CAAV;;AAEA0e,gCAAgB3d,GAAhB,GAAsB+N,cAAc/N,GAApC;AACA2d,gCAAgBvjB,EAAhB,GAAqB2T,cAAczf,KAAd,CAAoB8L,EAAzC;;AAEA,uBAAOsL,OAAO7B,QAAP,CAAgB8Z,eAAhB,CAAP;AACH,aAPM,EAOJhH,KAPI,CAOE,eAAO;AACZ,oBAAIjR,OAAOZ,KAAX,EAAkB;AACdlmC,6BAAIqgC,KAAJ,CAAU,qFAAV;AACAyG,2BAAOZ,KAAP;AACH;AACD,sBAAM8R,GAAN;AACH,aAbM,CAAP;AAcH,SAjBM,CAAP;AAkBH,K;;0BACDsF,U,uBAAWlc,G,EAAgB;AAAA;;AAAA,YAAXkL,IAAW,uEAAJ,EAAI;;AACvB,eAAO,KAAK8D,qBAAL,CAA2BhP,GAA3B,EAAgCiJ,IAAhC,CAAqC,0BAAkB;AAC1DrqC,qBAAIqgC,KAAJ,CAAU,6CAAV;;AAEA,gBAAIoX,OAAO,IAAI32C,UAAJ,CAASg+C,cAAT,CAAX;;AAEA,gBAAIxS,KAAK0R,WAAT,EAAsB;AAClB,oBAAI1R,KAAK0R,WAAL,KAAqBvG,KAAKpC,OAAL,CAAa3X,GAAtC,EAA2C;AACvC19B,6BAAIqgC,KAAJ,CAAU,kGAAV,EAA8GoX,KAAKpC,OAAL,CAAa3X,GAA3H;AACA,2BAAO8E,QAAQ8B,MAAR,CAAe,IAAI7iC,KAAJ,CAAU,gBAAV,CAAf,CAAP;AACH,iBAHD,MAIK;AACDzB,6BAAIqgC,KAAJ,CAAU,wEAAV;AACH;AACJ;;AAED,mBAAO,QAAK2c,SAAL,CAAevF,IAAf,EAAqBpN,IAArB,CAA0B,YAAM;AACnCrqC,yBAAIqgC,KAAJ,CAAU,qCAAV;;AAEA,wBAAKic,OAAL,CAAatc,IAAb,CAAkByX,IAAlB;;AAEA,uBAAOA,IAAP;AACH,aANM,CAAP;AAOH,SAtBM,CAAP;AAuBH,K;;0BACDmG,e,4BAAgBxc,G,EAAKrgC,S,EAAW;AAC5Bf,iBAAIqgC,KAAJ,CAAU,6BAAV;AACA,eAAOt/B,UAAUmgC,QAAV,CAAmBE,GAAnB,CAAP;AACH,K;;0BAED4d,e,8BAA2B;AAAA,YAAX1S,IAAW,uEAAJ,EAAI;;AACvBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIoQ,wBAAwB3S,KAAKkE,wBAAL,IAAiC,KAAK/D,QAAL,CAAc+D,wBAA3E;AACA,YAAIyO,qBAAJ,EAA0B;AACtB3S,iBAAKkE,wBAAL,GAAgCyO,qBAAhC;AACH;AACD,YAAI/B,YAAY;AACZ/I,kCAAuB7H,KAAK6H;AADhB,SAAhB;AAGA,eAAO,KAAK+K,aAAL,CAAmB5S,IAAnB,EAAyB,KAAK8Q,kBAA9B,EAAkDF,SAAlD,EAA6D7S,IAA7D,CAAkE,YAAI;AACzErqC,qBAAI6rC,IAAJ,CAAS,yCAAT;AACH,SAFM,CAAP;AAGH,K;;0BACD6S,uB,oCAAwBtd,G,EAAK;AACzB,eAAO,KAAK+d,WAAL,CAAiB/d,OAAO,KAAKgc,kBAAL,CAAwBhc,GAAhD,EAAqDiJ,IAArD,CAA0D,oBAAU;AACvErqC,qBAAI6rC,IAAJ,CAAS,iDAAT;AACA,mBAAOgE,QAAP;AACH,SAHM,CAAP;AAIH,K;;0BAEDuP,Y,2BAAwB;AAAA,YAAX9S,IAAW,uEAAJ,EAAI;;AACpBA,eAAOxqC,OAAO8zC,MAAP,CAAc,EAAd,EAAkBtJ,IAAlB,CAAP;;AAEAA,aAAKuC,YAAL,GAAoB,MAApB;AACA,YAAIzN,MAAMkL,KAAKkE,wBAAL,IAAiC,KAAK/D,QAAL,CAAc4S,8BAA/C,IAAiF,KAAK5S,QAAL,CAAc+D,wBAAzG;AACAlE,aAAKkE,wBAAL,GAAgCpP,GAAhC;AACAkL,aAAKlK,OAAL,GAAe,OAAf;AACA,YAAIkK,KAAKkE,wBAAT,EAAkC;AAC9B;AACA;AACA;AACA;AACA;AACAlE,iBAAK5c,KAAL,GAAa4c,KAAK5c,KAAL,IAAc,EAA3B;AACH;;AAED,eAAO,KAAK4vB,QAAL,CAAchT,IAAd,EAAoB,KAAKoR,eAAzB,EAA0C;AAC7C7Y,sBAAUzD,GADmC;AAE7C4C,iCAAqBsI,KAAKtI,mBAAL,IAA4B,KAAKyI,QAAL,CAAczI,mBAFlB;AAG7CW,+BAAmB2H,KAAK3H,iBAAL,IAA0B,KAAK8H,QAAL,CAAc9H;AAHd,SAA1C,EAIJ0F,IAJI,CAIC,YAAM;AACVrqC,qBAAI6rC,IAAJ,CAAS,sCAAT;AACH,SANM,CAAP;AAOH,K;;0BACD8S,oB,iCAAqBvd,G,EAAKmS,Q,EAAU;AAChC,YAAI,OAAOA,QAAP,KAAqB,WAArB,IAAoC,OAAOnS,GAAP,KAAgB,SAAxD,EAAmE;AAC/DmS,uBAAWnS,GAAX;AACAA,kBAAM,IAAN;AACH;;AAED,YAAIwO,YAAY,GAAhB;AACA,eAAO,KAAK8N,eAAL,CAAqBxc,QAArB,CAA8BE,GAA9B,EAAmCmS,QAAnC,EAA6C3D,SAA7C,EAAwDvF,IAAxD,CAA6D,YAAM;AACtErqC,qBAAI6rC,IAAJ,CAAS,8CAAT;AACH,SAFM,CAAP;AAGH,K;;0BAEDyT,Q,qBAAShT,I,EAAMvrC,S,EAAiC;AAAA;;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;AAC5C,eAAO,KAAKG,aAAL,CAAmB5S,IAAnB,EAAyBvrC,SAAzB,EAAoCg+C,eAApC,EAAqD1U,IAArD,CAA0D,uBAAe;AAC5E,mBAAO,QAAK8U,WAAL,CAAiBN,YAAYzd,GAA7B,CAAP;AACH,SAFM,CAAP;AAGH,K;;0BACD8d,a,4BAA0D;AAAA,YAA5C5S,IAA4C,uEAArC,EAAqC;;AAAA;;AAAA,YAAjCvrC,SAAiC;AAAA,YAAtBg+C,eAAsB,uEAAJ,EAAI;;AACtD,eAAOh+C,UAAU+iC,OAAV,CAAkBib,eAAlB,EAAmC1U,IAAnC,CAAwC,kBAAU;AACrDrqC,qBAAIqgC,KAAJ,CAAU,wDAAV;;AAEA,mBAAO,QAAKyc,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjCrqC,yBAAIqgC,KAAJ,CAAU,6DAAV;;AAEA,oBAAIkf,gBAAgB,QAAK5S,SAAL,CAAe6S,0BAAf,GAA4C,QAAKC,eAAL,CAAqBhI,IAArB,CAA5C,GAAyEjV,QAAQC,OAAR,EAA7F;AACA,uBAAO8c,cAAclV,IAAd,CAAmB,YAAM;;AAE5B,wBAAI4K,WAAW3I,KAAK+B,aAAL,IAAsBoJ,QAAQA,KAAKxC,QAAlD;AACA,wBAAIA,QAAJ,EAAc;AACVj1C,iCAAIqgC,KAAJ,CAAU,kEAAV;AACAiM,6BAAK+B,aAAL,GAAqB4G,QAArB;AACH;;AAED,2BAAO,QAAK8H,UAAL,GAAkB1S,IAAlB,CAAuB,YAAM;AAChCrqC,iCAAIqgC,KAAJ,CAAU,mEAAV;;AAEA,+BAAO,QAAKkQ,oBAAL,CAA0BjE,IAA1B,EAAgCjC,IAAhC,CAAqC,0BAAkB;AAC1DrqC,qCAAIqgC,KAAJ,CAAU,gDAAV;;AAEA0e,4CAAgB3d,GAAhB,GAAsBse,eAAete,GAArC;AACA,gCAAIse,eAAehwB,KAAnB,EAA0B;AACtBqvB,gDAAgBvjB,EAAhB,GAAqBkkB,eAAehwB,KAAf,CAAqB8L,EAA1C;AACH;AACD,mCAAOsL,OAAO7B,QAAP,CAAgB8Z,eAAhB,CAAP;AACH,yBARM,CAAP;AASH,qBAZM,CAAP;AAaH,iBArBM,CAAP;AAsBH,aA1BM,EA0BJhH,KA1BI,CA0BE,eAAO;AACZ,oBAAIjR,OAAOZ,KAAX,EAAkB;AACdlmC,6BAAIqgC,KAAJ,CAAU,sFAAV;AACAyG,2BAAOZ,KAAP;AACH;AACD,sBAAM8R,GAAN;AACH,aAhCM,CAAP;AAiCH,SApCM,CAAP;AAqCH,K;;0BACDmH,W,wBAAY/d,G,EAAK;AACb,eAAO,KAAK2P,sBAAL,CAA4B3P,GAA5B,EAAiCiJ,IAAjC,CAAsC,2BAAmB;AAC5DrqC,qBAAIqgC,KAAJ,CAAU,+CAAV;;AAEA,mBAAOsf,eAAP;AACH,SAJM,CAAP;AAKH,K;;0BAEDC,iB,gCAAoB;AAAA;;AAChB,eAAO,KAAK9C,SAAL,GAAiBzS,IAAjB,CAAsB,gBAAQ;AACjC,mBAAO,QAAKoV,eAAL,CAAqBhI,IAArB,EAA2B,IAA3B,EAAiCpN,IAAjC,CAAsC,mBAAW;AACpD,oBAAIwV,OAAJ,EAAa;AACT7/C,6BAAIqgC,KAAJ,CAAU,mFAAV;;AAEAoX,yBAAKvX,YAAL,GAAoB,IAApB;AACAuX,yBAAKyD,aAAL,GAAqB,IAArB;AACAzD,yBAAK2B,UAAL,GAAkB,IAAlB;AACA3B,yBAAK0B,UAAL,GAAkB,IAAlB;;AAEA,2BAAO,QAAK6D,SAAL,CAAevF,IAAf,EAAqBpN,IAArB,CAA0B,YAAM;AACnCrqC,iCAAIqgC,KAAJ,CAAU,4CAAV;AACA,gCAAKic,OAAL,CAAatc,IAAb,CAAkByX,IAAlB;AACH,qBAHM,CAAP;AAIH;AACJ,aAdM,CAAP;AAeH,SAhBM,EAgBJpN,IAhBI,CAgBC,YAAI;AACRrqC,qBAAI6rC,IAAJ,CAAS,kEAAT;AACH,SAlBM,CAAP;AAmBH,K;;0BAED4T,e,4BAAgBhI,I,EAAM8D,Q,EAAU;AAAA;;AAC5B,YAAI9D,IAAJ,EAAU;AACN,gBAAIvX,eAAeuX,KAAKvX,YAAxB;AACA,gBAAIgb,gBAAgBzD,KAAKyD,aAAzB;;AAEA,mBAAO,KAAK4E,0BAAL,CAAgC5f,YAAhC,EAA8Cqb,QAA9C,EACFlR,IADE,CACG,qBAAa;AACf,uBAAO,QAAK0V,2BAAL,CAAiC7E,aAAjC,EAAgDK,QAAhD,EACFlR,IADE,CACG,qBAAa;AACf,wBAAI,CAAC2V,SAAD,IAAc,CAACC,SAAnB,EAA8B;AAC1BjgD,iCAAIqgC,KAAJ,CAAU,oFAAV;AACH;;AAED,2BAAO2f,aAAaC,SAApB;AACH,iBAPE,CAAP;AAQH,aAVE,CAAP;AAWH;;AAED,eAAOzd,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH,K;;0BAEDqd,0B,uCAA2B5f,Y,EAAcqb,Q,EAAU;AAC/C;AACA,YAAI,CAACrb,YAAD,IAAiBA,aAAax4B,OAAb,CAAqB,GAArB,KAA6B,CAAlD,EAAqD;AACjD,mBAAO86B,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH;;AAED,eAAO,KAAKoa,sBAAL,CAA4BvB,MAA5B,CAAmCpb,YAAnC,EAAiDqb,QAAjD,EAA2DlR,IAA3D,CAAgE;AAAA,mBAAM,IAAN;AAAA,SAAhE,CAAP;AACH,K;;0BAED0V,2B,wCAA4B7E,a,EAAeK,Q,EAAU;AACjD,YAAI,CAACL,aAAL,EAAoB;AAChB,mBAAO1Y,QAAQC,OAAR,CAAgB,KAAhB,CAAP;AACH;;AAED,eAAO,KAAKoa,sBAAL,CAA4BvB,MAA5B,CAAmCJ,aAAnC,EAAkDK,QAAlD,EAA4D,eAA5D,EAA6ElR,IAA7E,CAAkF;AAAA,mBAAM,IAAN;AAAA,SAAlF,CAAP;AACH,K;;0BAEDqS,gB,+BAAmB;AACf,aAAKF,mBAAL,CAAyBlZ,KAAzB;AACH,K;;0BAED4c,e,8BAAkB;AACd,aAAK1D,mBAAL,CAAyBnZ,IAAzB;AACH,K;;0BAMDyZ,S,wBAAY;AACR,eAAO,KAAKqD,UAAL,CAAgBlhB,GAAhB,CAAoB,KAAKmhB,aAAzB,EAAwC/V,IAAxC,CAA6C,yBAAiB;AACjE,gBAAIsP,aAAJ,EAAmB;AACf35C,yBAAIqgC,KAAJ,CAAU,kDAAV;AACA,uBAAOv/B,WAAKqvC,iBAAL,CAAuBwJ,aAAvB,CAAP;AACH;;AAED35C,qBAAIqgC,KAAJ,CAAU,8CAAV;AACA,mBAAO,IAAP;AACH,SARM,CAAP;AASH,K;;0BAED2c,S,sBAAUvF,I,EAAM;AACZ,YAAIA,IAAJ,EAAU;AACNz3C,qBAAIqgC,KAAJ,CAAU,qCAAV;;AAEA,gBAAIsZ,gBAAgBlC,KAAKjI,eAAL,EAApB;AACA,mBAAO,KAAK2Q,UAAL,CAAgB5Q,GAAhB,CAAoB,KAAK6Q,aAAzB,EAAwCzG,aAAxC,CAAP;AACH,SALD,MAMK;AACD35C,qBAAIqgC,KAAJ,CAAU,oCAAV;AACA,mBAAO,KAAK8f,UAAL,CAAgBnQ,MAAhB,CAAuB,KAAKoQ,aAA5B,CAAP;AACH;AACJ,K;;;;4BAxkBwB;AACrB,mBAAO,KAAK3T,QAAL,CAAc4T,iBAArB;AACH;;;4BACqB;AAClB,mBAAO,KAAK5T,QAAL,CAAc6T,cAArB;AACH;;;4BACsB;AACnB,mBAAO,KAAK7T,QAAL,CAAc8T,eAArB;AACH;;;4BACgB;AACb,mBAAO,KAAK9T,QAAL,CAAc+T,SAArB;AACH;;;4BAEY;AACT,mBAAO,KAAKlE,OAAZ;AACH;;;4BA8hBmB;AAChB,6BAAe,KAAK7P,QAAL,CAAcqB,SAA7B,SAA0C,KAAKrB,QAAL,CAActL,SAAxD;AACH;;;;EAhlB4BlhC,uB;;;;;;;;;;;;;;;;;;;ACZjC;;AACA;;AACA;;;;;;+eALA;AACA;;IAMas8C,iB,WAAAA,iB;;;AAET,+BAAY9P,QAAZ,EAAsB;AAAA;;AAAA,qDAClB,8BAAMA,QAAN,CADkB;;AAElB,cAAKgU,WAAL,GAAmB,IAAIla,YAAJ,CAAU,aAAV,CAAnB;AACA,cAAKma,aAAL,GAAqB,IAAIna,YAAJ,CAAU,eAAV,CAArB;AACA,cAAKoa,iBAAL,GAAyB,IAAIpa,YAAJ,CAAU,oBAAV,CAAzB;AACA,cAAKqa,aAAL,GAAqB,IAAIra,YAAJ,CAAU,gBAAV,CAArB;AACA,cAAKsa,cAAL,GAAsB,IAAIta,YAAJ,CAAU,iBAAV,CAAtB;AACA,cAAKua,mBAAL,GAA2B,IAAIva,YAAJ,CAAU,sBAAV,CAA3B;AAPkB;AAQrB;;gCAEDvG,I,iBAAKyX,I,EAAuB;AAAA,YAAjBc,UAAiB,uEAAN,IAAM;;AACxBv4C,iBAAIqgC,KAAJ,CAAU,wBAAV;AACA,qCAAML,IAAN,YAAWyX,IAAX;AACA,YAAIc,UAAJ,EAAgB;AACZ,iBAAKkI,WAAL,CAAiB7Z,KAAjB,CAAuB6Q,IAAvB;AACH;AACJ,K;;gCACDhX,M,qBAAS;AACLzgC,iBAAIqgC,KAAJ,CAAU,0BAAV;AACA,qCAAMI,MAAN;AACA,aAAKigB,aAAL,CAAmB9Z,KAAnB;AACH,K;;gCAEDwQ,a,0BAAczW,E,EAAI;AACd,aAAK8f,WAAL,CAAiB7f,UAAjB,CAA4BD,EAA5B;AACH,K;;gCACDogB,gB,6BAAiBpgB,E,EAAI;AACjB,aAAK8f,WAAL,CAAiB3f,aAAjB,CAA+BH,EAA/B;AACH,K;;gCAED2W,e,4BAAgB3W,E,EAAI;AAChB,aAAK+f,aAAL,CAAmB9f,UAAnB,CAA8BD,EAA9B;AACH,K;;gCACDqgB,kB,+BAAmBrgB,E,EAAI;AACnB,aAAK+f,aAAL,CAAmB5f,aAAnB,CAAiCH,EAAjC;AACH,K;;gCAEDsgB,mB,gCAAoBtgB,E,EAAI;AACpB,aAAKggB,iBAAL,CAAuB/f,UAAvB,CAAkCD,EAAlC;AACH,K;;gCACDugB,sB,mCAAuBvgB,E,EAAI;AACvB,aAAKggB,iBAAL,CAAuB7f,aAAvB,CAAqCH,EAArC;AACH,K;;gCACDoZ,sB,mCAAuB/3C,C,EAAG;AACtBhC,iBAAIqgC,KAAJ,CAAU,0CAAV,EAAsDr+B,EAAEgkC,OAAxD;AACA,aAAK2a,iBAAL,CAAuB/Z,KAAvB,CAA6B5kC,CAA7B;AACH,K;;gCAEDm/C,e,4BAAgBxgB,E,EAAI;AAChB,aAAKigB,aAAL,CAAmBhgB,UAAnB,CAA8BD,EAA9B;AACH,K;;gCACDygB,kB,+BAAmBzgB,E,EAAI;AACnB,aAAKigB,aAAL,CAAmB9f,aAAnB,CAAiCH,EAAjC;AACH,K;;gCACD+X,kB,iCAAqB;AACjB14C,iBAAIqgC,KAAJ,CAAU,sCAAV;AACA,aAAKugB,aAAL,CAAmBha,KAAnB;AACH,K;;gCAEDya,gB,6BAAiB1gB,E,EAAI;AACjB,aAAKkgB,cAAL,CAAoBjgB,UAApB,CAA+BD,EAA/B;AACH,K;;gCACD2gB,mB,gCAAoB3gB,E,EAAI;AACpB,aAAKkgB,cAAL,CAAoB/f,aAApB,CAAkCH,EAAlC;AACH,K;;gCACD8X,mB,kCAAsB;AAClBz4C,iBAAIqgC,KAAJ,CAAU,uCAAV;AACA,aAAKwgB,cAAL,CAAoBja,KAApB;AACH,K;;gCAED2a,qB,kCAAsB5gB,E,EAAI;AACtB,aAAKmgB,mBAAL,CAAyBlgB,UAAzB,CAAoCD,EAApC;AACH,K;;gCACD6gB,wB,qCAAyB7gB,E,EAAI;AACzB,aAAKmgB,mBAAL,CAAyBhgB,aAAzB,CAAuCH,EAAvC;AACH,K;;gCACD6X,wB,uCAA2B;AACvBx4C,iBAAIqgC,KAAJ,CAAU,4CAAV;AACA,aAAKygB,mBAAL,CAAyBla,KAAzB;AACH,K;;;EAjFkCtmC,qC;;;;;;;;;;;;;;;;;;;;;ACJvC;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;AACA;;;;;;+eAVA;AACA;;AAWA,IAAMk/B,6CAA6C,EAAnD;AACA,IAAMiiB,8BAA8B,IAApC;;IAEapF,mB,WAAAA,mB;;;AACT,mCAqBQ;AAAA,uFAAJ,EAAI;AAAA,YApBJmB,kBAoBI,QApBJA,kBAoBI;AAAA,YAnBJ6B,8BAmBI,QAnBJA,8BAmBI;AAAA,YAlBJrb,mBAkBI,QAlBJA,mBAkBI;AAAA,YAjBJW,iBAiBI,QAjBJA,iBAiBI;AAAA,YAhBJ0Z,mBAgBI,QAhBJA,mBAgBI;AAAA,YAfJvW,oBAeI,QAfJA,oBAeI;AAAA,yCAdJ2U,oBAcI;AAAA,YAdJA,oBAcI,yCAdmB,KAcnB;AAAA,yCAbJsB,wBAaI;AAAA,YAbJA,wBAaI,yCAbuB,KAavB;AAAA,yCAZJD,2BAYI;AAAA,YAZJA,2BAYI,yCAZ0B,IAY1B;AAAA,uCAXJnB,cAWI;AAAA,YAXJA,cAWI,uCAXa,IAWb;AAAA,yCAVJjF,uBAUI;AAAA,YAVJA,uBAUI,yCAVsB,KAUtB;AAAA,yCATJiB,oBASI;AAAA,YATJA,oBASI,yCATmB8I,2BASnB;AAAA,yCARJ7I,uBAQI;AAAA,YARJA,uBAQI,yCARsB,IAQtB;AAAA,YAPJgG,0BAOI,QAPJA,0BAOI;AAAA,yCANJY,0BAMI;AAAA,YANJA,0BAMI,yCANyB,KAMzB;AAAA,yCALJ/f,mCAKI;AAAA,YALJA,mCAKI,yCALkCD,0CAKlC;AAAA,yCAJJ6gB,iBAII;AAAA,YAJJA,iBAII,yCAJgB,IAAInM,oCAAJ,EAIhB;AAAA,uCAHJoM,cAGI;AAAA,YAHJA,cAGI,uCAHa,IAAIjN,8BAAJ,EAGb;AAAA,wCAFJkN,eAEI;AAAA,YAFJA,eAEI,wCAFc,IAAI/Y,gCAAJ,EAEd;AAAA,kCADJgZ,SACI;AAAA,YADJA,SACI,kCADQ,IAAIrgD,0CAAJ,CAAyB,EAAEuhD,OAAO7gD,eAAOymC,cAAhB,EAAzB,CACR;;AAAA;;AAAA,qDACJ,+BAAMlkC,UAAU,CAAV,CAAN,CADI;;AAGJ,cAAKu+C,mBAAL,GAA2BnE,kBAA3B;AACA,cAAKoE,+BAAL,GAAuCvC,8BAAvC;AACA,cAAKwC,oBAAL,GAA4B7d,mBAA5B;AACA,cAAK8d,kBAAL,GAA0Bnd,iBAA1B;;AAEA,cAAKod,oBAAL,GAA4B1D,mBAA5B;AACA,cAAK2D,qBAAL,GAA6Bla,oBAA7B;AACA,cAAKma,qBAAL,GAA6BxF,oBAA7B;AACA,cAAKyF,yBAAL,GAAiCnE,wBAAjC;AACA,cAAKoE,4BAAL,GAAoCrE,2BAApC;AACA,cAAKje,oCAAL,GAA4CJ,mCAA5C;;AAEA,cAAK2iB,eAAL,GAAuBzF,cAAvB;AACA,cAAK0F,wBAAL,GAAgC3K,uBAAhC;AACA,cAAKU,qBAAL,GAA6BO,oBAA7B;AACA,cAAKN,wBAAL,GAAgCO,uBAAhC;AACA,YAAIgG,0BAAJ,EAAgC;AAC5B,kBAAK0D,2BAAL,GAAmC1D,0BAAnC;AACH,SAFD,MAGK,IAAIx7C,UAAU,CAAV,KAAgBA,UAAU,CAAV,EAAa4qC,aAAjC,EAAgD;AACjD,kBAAKsU,2BAAL,GAAmCtT,6BAAc8J,MAAd,CAAqB11C,UAAU,CAAV,EAAa4qC,aAAlC,IAAmD,UAAnD,GAAgE,MAAnG;AACH,SAFI,MAGA;AACD,kBAAKsU,2BAAL,GAAmC,UAAnC;AACH;AACD,cAAKC,2BAAL,GAAmC/C,0BAAnC;;AAEA,cAAKpC,kBAAL,GAA0BiD,iBAA1B;AACA,cAAK3C,eAAL,GAAuB4C,cAAvB;AACA,cAAKhC,gBAAL,GAAwBiC,eAAxB;;AAEA,cAAKJ,UAAL,GAAkBK,SAAlB;AAlCI;AAmCP;;;;4BAEwB;AACrB,mBAAO,KAAKmB,mBAAZ;AACH;;;4BACoC;AACjC,mBAAO,KAAKC,+BAAZ;AACH;;;4BACyB;AACtB,mBAAO,KAAKC,oBAAZ;AACH;;;4BACuB;AACpB,mBAAO,KAAKC,kBAAZ;AACH;;;4BAEyB;AACtB,mBAAO,KAAKC,oBAAZ;AACH;;;4BAC2B;AACxB,mBAAO,KAAKC,qBAAZ;AACH;;;4BAC0B;AACvB,mBAAO,KAAKC,qBAAZ;AACH;;;4BAC8B;AAC3B,mBAAO,KAAKC,yBAAZ;AACH;;;4BACiC;AAC9B,mBAAO,KAAKC,4BAAZ;AACH;;;4BACyC;AACtC,mBAAO,KAAKtiB,oCAAZ;AACH;;;4BAEoB;AACjB,mBAAO,KAAKuiB,eAAZ;AACH;;;4BAC6B;AAC1B,mBAAO,KAAKC,wBAAZ;AACH;;;4BAC0B;AACvB,mBAAO,KAAKjK,qBAAZ;AACH;;;4BAC4B;AACzB,mBAAO,KAAKC,wBAAZ;AACH;;;4BAC+B;AAC5B,mBAAO,KAAKiK,2BAAZ;AACH;;;4BACgC;AAC7B,mBAAO,KAAKC,2BAAZ;AACH;;;4BAEuB;AACpB,mBAAO,KAAKnF,kBAAZ;AACH;;;4BACoB;AACjB,mBAAO,KAAKM,eAAZ;AACH;;;4BACqB;AAClB,mBAAO,KAAKY,gBAAZ;AACH;;;4BAEe;AACZ,mBAAO,KAAK6B,UAAZ;AACH;;;;EA1HoCjgD,uC;;;;;;;;;;;;;;;;;;;ACZzC;;AACA;;0JAJA;AACA;;IAKaC,oB,WAAAA,oB;AACT,oCAAkE;AAAA,uFAAJ,EAAI;AAAA,+BAArDqiD,MAAqD;AAAA,YAArDA,MAAqD,+BAA5C,OAA4C;AAAA,8BAAnCd,KAAmC;AAAA,YAAnCA,KAAmC,8BAA3B7gD,eAAOwmC,YAAoB;;AAAA;;AAC9D,aAAKob,MAAL,GAAcf,KAAd;AACA,aAAKgB,OAAL,GAAeF,MAAf;AACH;;mCAEDjT,G,gBAAIzb,G,EAAK6U,K,EAAO;AACZ3oC,iBAAIqgC,KAAJ,CAAU,0BAAV,EAAsCvM,GAAtC;;AAEAA,cAAM,KAAK4uB,OAAL,GAAe5uB,GAArB;;AAEA,aAAK2uB,MAAL,CAAY/Z,OAAZ,CAAoB5U,GAApB,EAAyB6U,KAAzB;;AAEA,eAAOnG,QAAQC,OAAR,EAAP;AACH,K;;mCAEDxD,G,gBAAInL,G,EAAK;AACL9zB,iBAAIqgC,KAAJ,CAAU,0BAAV,EAAsCvM,GAAtC;;AAEAA,cAAM,KAAK4uB,OAAL,GAAe5uB,GAArB;;AAEA,YAAI6S,OAAO,KAAK8b,MAAL,CAAYha,OAAZ,CAAoB3U,GAApB,CAAX;;AAEA,eAAO0O,QAAQC,OAAR,CAAgBkE,IAAhB,CAAP;AACH,K;;mCAEDqJ,M,mBAAOlc,G,EAAK;AACR9zB,iBAAIqgC,KAAJ,CAAU,6BAAV,EAAyCvM,GAAzC;;AAEAA,cAAM,KAAK4uB,OAAL,GAAe5uB,GAArB;;AAEA,YAAI6S,OAAO,KAAK8b,MAAL,CAAYha,OAAZ,CAAoB3U,GAApB,CAAX;AACA,aAAK2uB,MAAL,CAAY7Z,UAAZ,CAAuB9U,GAAvB;;AAEA,eAAO0O,QAAQC,OAAR,CAAgBkE,IAAhB,CAAP;AACH,K;;mCAED0T,U,yBAAa;AACTr6C,iBAAIqgC,KAAJ,CAAU,iCAAV;;AAEA,YAAIngB,OAAO,EAAX;;AAEA,aAAK,IAAI2oB,QAAQ,CAAjB,EAAoBA,QAAQ,KAAK4Z,MAAL,CAAYpgD,MAAxC,EAAgDwmC,OAAhD,EAAyD;AACrD,gBAAI/U,MAAM,KAAK2uB,MAAL,CAAY3uB,GAAZ,CAAgB+U,KAAhB,CAAV;;AAEA,gBAAI/U,IAAIpsB,OAAJ,CAAY,KAAKg7C,OAAjB,MAA8B,CAAlC,EAAqC;AACjCxiC,qBAAK5b,IAAL,CAAUwvB,IAAIjvB,MAAJ,CAAW,KAAK69C,OAAL,CAAargD,MAAxB,CAAV;AACH;AACJ;;AAED,eAAOmgC,QAAQC,OAAR,CAAgBviB,IAAhB,CAAP;AACH,K;;;;;;;;;;;;;;;;;;;;;;ACzDL;;AAEA,IAAM+oB,qBAAqB,CAAC,OAAD,EAAU,OAAV,EAAmB,OAAnB,EAA4B,OAA5B,EAAqC,OAArC,EAA8C,OAA9C,EAAuD,OAAvD,EAAgE,OAAhE,EAAyE,OAAzE,CAA3B;;QAGIhN,G,GAAAA,c;QACA+M,O,GAAAA,kB;QACAnS,I,GAAAA,e;QACApe,M,GAAAA,iB;QACAmO,S,GAAAA,oB;QACAhc,Q,GAAAA,mB;QACAq+B,kB,GAAAA,kB;;;;;;;;;;;;;;;;;kBCLoB5kC,M;;AANxB;;;;;;AAEA;;;;AAIe,SAASA,MAAT,GAAkB;AAC/B,SAAO,mBAAQma,OAAR,CAAgB,IAAhB,EAAsB,EAAtB,CAAP;AACD;;;;;;;;;;;;;;;;;;ACRD,IAAMze,UAAU,QAAhB,C,QAAkCA,O,GAAAA,O","file":"oidc-client.js","sourcesContent":[" \t// The module cache\n \tvar installedModules = {};\n\n \t// The require function\n \tfunction __webpack_require__(moduleId) {\n\n \t\t// Check if module is in cache\n \t\tif(installedModules[moduleId]) {\n \t\t\treturn installedModules[moduleId].exports;\n \t\t}\n \t\t// Create a new module (and put it into the cache)\n \t\tvar module = installedModules[moduleId] = {\n \t\t\ti: moduleId,\n \t\t\tl: false,\n \t\t\texports: {}\n \t\t};\n\n \t\t// Execute the module function\n \t\tmodules[moduleId].call(module.exports, module, module.exports, __webpack_require__);\n\n \t\t// Flag the module as loaded\n \t\tmodule.l = true;\n\n \t\t// Return the exports of the module\n \t\treturn module.exports;\n \t}\n\n\n \t// expose the modules object (__webpack_modules__)\n \t__webpack_require__.m = modules;\n\n \t// expose the module cache\n \t__webpack_require__.c = installedModules;\n\n \t// define getter function for harmony exports\n \t__webpack_require__.d = function(exports, name, getter) {\n \t\tif(!__webpack_require__.o(exports, name)) {\n \t\t\tObject.defineProperty(exports, name, { enumerable: true, get: getter });\n \t\t}\n \t};\n\n \t// define __esModule on exports\n \t__webpack_require__.r = function(exports) {\n \t\tif(typeof Symbol !== 'undefined' && Symbol.toStringTag) {\n \t\t\tObject.defineProperty(exports, Symbol.toStringTag, { value: 'Module' });\n \t\t}\n \t\tObject.defineProperty(exports, '__esModule', { value: true });\n \t};\n\n \t// create a fake namespace object\n \t// mode & 1: value is a module id, require it\n \t// mode & 2: merge all properties of value into the ns\n \t// mode & 4: return value when already ns object\n \t// mode & 8|1: behave like require\n \t__webpack_require__.t = function(value, mode) {\n \t\tif(mode & 1) value = __webpack_require__(value);\n \t\tif(mode & 8) return value;\n \t\tif((mode & 4) && typeof value === 'object' && value && value.__esModule) return value;\n \t\tvar ns = Object.create(null);\n \t\t__webpack_require__.r(ns);\n \t\tObject.defineProperty(ns, 'default', { enumerable: true, value: value });\n \t\tif(mode & 2 && typeof value != 'string') for(var key in value) __webpack_require__.d(ns, key, function(key) { return value[key]; }.bind(null, key));\n \t\treturn ns;\n \t};\n\n \t// getDefaultExport function for compatibility with non-harmony modules\n \t__webpack_require__.n = function(module) {\n \t\tvar getter = module && module.__esModule ?\n \t\t\tfunction getDefault() { return module['default']; } :\n \t\t\tfunction getModuleExports() { return module; };\n \t\t__webpack_require__.d(getter, 'a', getter);\n \t\treturn getter;\n \t};\n\n \t// Object.prototype.hasOwnProperty.call\n \t__webpack_require__.o = function(object, property) { return Object.prototype.hasOwnProperty.call(object, property); };\n\n \t// __webpack_public_path__\n \t__webpack_require__.p = \"\";\n\n\n \t// Load entry module and return exports\n \treturn __webpack_require__(__webpack_require__.s = 0);\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './src/Log.js';\r\nimport { OidcClient } from './src/OidcClient.js';\r\nimport { OidcClientSettings } from './src/OidcClientSettings.js';\r\nimport { WebStorageStateStore } from './src/WebStorageStateStore.js';\r\nimport { InMemoryWebStorage } from './src/InMemoryWebStorage.js';\r\nimport { UserManager } from './src/UserManager.js';\r\nimport { AccessTokenEvents } from './src/AccessTokenEvents.js';\r\nimport { MetadataService } from './src/MetadataService.js';\r\nimport { CordovaPopupNavigator } from './src/CordovaPopupNavigator.js';\r\nimport { CordovaIFrameNavigator } from './src/CordovaIFrameNavigator.js';\r\nimport { CheckSessionIFrame } from './src/CheckSessionIFrame.js';\r\nimport { TokenRevocationClient } from './src/TokenRevocationClient.js';\r\nimport { SessionMonitor } from './src/SessionMonitor.js';\r\nimport { Global } from './src/Global.js';\r\nimport { User } from './src/User.js';\r\n\r\nimport { Version } from './version.js';\r\n\r\nexport default {\r\n    Version,\r\n    Log,\r\n    OidcClient,\r\n    OidcClientSettings,\r\n    WebStorageStateStore,\r\n    InMemoryWebStorage,\r\n    UserManager,\r\n    AccessTokenEvents,\r\n    MetadataService,\r\n    CordovaPopupNavigator,\r\n    CordovaIFrameNavigator,\r\n    CheckSessionIFrame,\r\n    TokenRevocationClient,\r\n    SessionMonitor,\r\n    Global,\r\n    User\r\n};\r\n","/*\r\n * jsrsasign(all) 8.0.12 (2018-04-22) (c) 2010-2018 Kenji Urushima | kjur.github.com/jsrsasign/license\r\n */\r\n\r\nvar navigator = {};\r\nnavigator.userAgent = false;\r\n\r\nvar window = {};\r\n\n/*!\r\nCopyright (c) 2011, Yahoo! Inc. All rights reserved.\r\nCode licensed under the BSD License:\r\nhttp://developer.yahoo.com/yui/license.html\r\nversion: 2.9.0\r\n*/\r\nif(YAHOO===undefined){var YAHOO={}}YAHOO.lang={extend:function(g,h,f){if(!h||!g){throw new Error(\"YAHOO.lang.extend failed, please check that all dependencies are included.\")}var d=function(){};d.prototype=h.prototype;g.prototype=new d();g.prototype.constructor=g;g.superclass=h.prototype;if(h.prototype.constructor==Object.prototype.constructor){h.prototype.constructor=h}if(f){var b;for(b in f){g.prototype[b]=f[b]}var e=function(){},c=[\"toString\",\"valueOf\"];try{if(/MSIE/.test(navigator.userAgent)){e=function(j,i){for(b=0;b<c.length;b=b+1){var l=c[b],k=i[l];if(typeof k===\"function\"&&k!=Object.prototype[l]){j[l]=k}}}}}catch(a){}e(g.prototype,f)}}};\n/*! CryptoJS v3.1.2 core-fix.js\r\n * code.google.com/p/crypto-js\r\n * (c) 2009-2013 by Jeff Mott. All rights reserved.\r\n * code.google.com/p/crypto-js/wiki/License\r\n * THIS IS FIX of 'core.js' to fix Hmac issue.\r\n * https://code.google.com/p/crypto-js/issues/detail?id=84\r\n * https://crypto-js.googlecode.com/svn-history/r667/branches/3.x/src/core.js\r\n */\r\nvar CryptoJS=CryptoJS||(function(e,g){var a={};var b=a.lib={};var j=b.Base=(function(){function n(){}return{extend:function(p){n.prototype=this;var o=new n();if(p){o.mixIn(p)}if(!o.hasOwnProperty(\"init\")){o.init=function(){o.$super.init.apply(this,arguments)}}o.init.prototype=o;o.$super=this;return o},create:function(){var o=this.extend();o.init.apply(o,arguments);return o},init:function(){},mixIn:function(p){for(var o in p){if(p.hasOwnProperty(o)){this[o]=p[o]}}if(p.hasOwnProperty(\"toString\")){this.toString=p.toString}},clone:function(){return this.init.prototype.extend(this)}}}());var l=b.WordArray=j.extend({init:function(o,n){o=this.words=o||[];if(n!=g){this.sigBytes=n}else{this.sigBytes=o.length*4}},toString:function(n){return(n||h).stringify(this)},concat:function(t){var q=this.words;var p=t.words;var n=this.sigBytes;var s=t.sigBytes;this.clamp();if(n%4){for(var r=0;r<s;r++){var o=(p[r>>>2]>>>(24-(r%4)*8))&255;q[(n+r)>>>2]|=o<<(24-((n+r)%4)*8)}}else{for(var r=0;r<s;r+=4){q[(n+r)>>>2]=p[r>>>2]}}this.sigBytes+=s;return this},clamp:function(){var o=this.words;var n=this.sigBytes;o[n>>>2]&=4294967295<<(32-(n%4)*8);o.length=e.ceil(n/4)},clone:function(){var n=j.clone.call(this);n.words=this.words.slice(0);return n},random:function(p){var o=[];for(var n=0;n<p;n+=4){o.push((e.random()*4294967296)|0)}return new l.init(o,p)}});var m=a.enc={};var h=m.Hex={stringify:function(p){var r=p.words;var o=p.sigBytes;var q=[];for(var n=0;n<o;n++){var s=(r[n>>>2]>>>(24-(n%4)*8))&255;q.push((s>>>4).toString(16));q.push((s&15).toString(16))}return q.join(\"\")},parse:function(p){var n=p.length;var q=[];for(var o=0;o<n;o+=2){q[o>>>3]|=parseInt(p.substr(o,2),16)<<(24-(o%8)*4)}return new l.init(q,n/2)}};var d=m.Latin1={stringify:function(q){var r=q.words;var p=q.sigBytes;var n=[];for(var o=0;o<p;o++){var s=(r[o>>>2]>>>(24-(o%4)*8))&255;n.push(String.fromCharCode(s))}return n.join(\"\")},parse:function(p){var n=p.length;var q=[];for(var o=0;o<n;o++){q[o>>>2]|=(p.charCodeAt(o)&255)<<(24-(o%4)*8)}return new l.init(q,n)}};var c=m.Utf8={stringify:function(n){try{return decodeURIComponent(escape(d.stringify(n)))}catch(o){throw new Error(\"Malformed UTF-8 data\")}},parse:function(n){return d.parse(unescape(encodeURIComponent(n)))}};var i=b.BufferedBlockAlgorithm=j.extend({reset:function(){this._data=new l.init();this._nDataBytes=0},_append:function(n){if(typeof n==\"string\"){n=c.parse(n)}this._data.concat(n);this._nDataBytes+=n.sigBytes},_process:function(w){var q=this._data;var x=q.words;var n=q.sigBytes;var t=this.blockSize;var v=t*4;var u=n/v;if(w){u=e.ceil(u)}else{u=e.max((u|0)-this._minBufferSize,0)}var s=u*t;var r=e.min(s*4,n);if(s){for(var p=0;p<s;p+=t){this._doProcessBlock(x,p)}var o=x.splice(0,s);q.sigBytes-=r}return new l.init(o,r)},clone:function(){var n=j.clone.call(this);n._data=this._data.clone();return n},_minBufferSize:0});var f=b.Hasher=i.extend({cfg:j.extend(),init:function(n){this.cfg=this.cfg.extend(n);this.reset()},reset:function(){i.reset.call(this);this._doReset()},update:function(n){this._append(n);this._process();return this},finalize:function(n){if(n){this._append(n)}var o=this._doFinalize();return o},blockSize:512/32,_createHelper:function(n){return function(p,o){return new n.init(o).finalize(p)}},_createHmacHelper:function(n){return function(p,o){return new k.HMAC.init(n,o).finalize(p)}}});var k=a.algo={};return a}(Math));\n/*\r\nCryptoJS v3.1.2 x64-core-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(g){var a=CryptoJS,f=a.lib,e=f.Base,h=f.WordArray,a=a.x64={};a.Word=e.extend({init:function(b,c){this.high=b;this.low=c}});a.WordArray=e.extend({init:function(b,c){b=this.words=b||[];this.sigBytes=c!=g?c:8*b.length},toX32:function(){for(var b=this.words,c=b.length,a=[],d=0;d<c;d++){var e=b[d];a.push(e.high);a.push(e.low)}return h.create(a,this.sigBytes)},clone:function(){for(var b=e.clone.call(this),c=b.words=this.words.slice(0),a=c.length,d=0;d<a;d++)c[d]=c[d].clone();return b}})})();\r\n\n/*\r\nCryptoJS v3.1.2 enc-base64.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(){var h=CryptoJS,j=h.lib.WordArray;h.enc.Base64={stringify:function(b){var e=b.words,f=b.sigBytes,c=this._map;b.clamp();b=[];for(var a=0;a<f;a+=3)for(var d=(e[a>>>2]>>>24-8*(a%4)&255)<<16|(e[a+1>>>2]>>>24-8*((a+1)%4)&255)<<8|e[a+2>>>2]>>>24-8*((a+2)%4)&255,g=0;4>g&&a+0.75*g<f;g++)b.push(c.charAt(d>>>6*(3-g)&63));if(e=c.charAt(64))for(;b.length%4;)b.push(e);return b.join(\"\")},parse:function(b){var e=b.length,f=this._map,c=f.charAt(64);c&&(c=b.indexOf(c),-1!=c&&(e=c));for(var c=[],a=0,d=0;d<\r\ne;d++)if(d%4){var g=f.indexOf(b.charAt(d-1))<<2*(d%4),h=f.indexOf(b.charAt(d))>>>6-2*(d%4);c[a>>>2]|=(g|h)<<24-8*(a%4);a++}return j.create(c,a)},_map:\"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=\"}})();\r\n\n/*\r\nCryptoJS v3.1.2 sha256-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(k){for(var g=CryptoJS,h=g.lib,v=h.WordArray,j=h.Hasher,h=g.algo,s=[],t=[],u=function(q){return 4294967296*(q-(q|0))|0},l=2,b=0;64>b;){var d;a:{d=l;for(var w=k.sqrt(d),r=2;r<=w;r++)if(!(d%r)){d=!1;break a}d=!0}d&&(8>b&&(s[b]=u(k.pow(l,0.5))),t[b]=u(k.pow(l,1/3)),b++);l++}var n=[],h=h.SHA256=j.extend({_doReset:function(){this._hash=new v.init(s.slice(0))},_doProcessBlock:function(q,h){for(var a=this._hash.words,c=a[0],d=a[1],b=a[2],k=a[3],f=a[4],g=a[5],j=a[6],l=a[7],e=0;64>e;e++){if(16>e)n[e]=\r\nq[h+e]|0;else{var m=n[e-15],p=n[e-2];n[e]=((m<<25|m>>>7)^(m<<14|m>>>18)^m>>>3)+n[e-7]+((p<<15|p>>>17)^(p<<13|p>>>19)^p>>>10)+n[e-16]}m=l+((f<<26|f>>>6)^(f<<21|f>>>11)^(f<<7|f>>>25))+(f&g^~f&j)+t[e]+n[e];p=((c<<30|c>>>2)^(c<<19|c>>>13)^(c<<10|c>>>22))+(c&d^c&b^d&b);l=j;j=g;g=f;f=k+m|0;k=b;b=d;d=c;c=m+p|0}a[0]=a[0]+c|0;a[1]=a[1]+d|0;a[2]=a[2]+b|0;a[3]=a[3]+k|0;a[4]=a[4]+f|0;a[5]=a[5]+g|0;a[6]=a[6]+j|0;a[7]=a[7]+l|0},_doFinalize:function(){var d=this._data,b=d.words,a=8*this._nDataBytes,c=8*d.sigBytes;\r\nb[c>>>5]|=128<<24-c%32;b[(c+64>>>9<<4)+14]=k.floor(a/4294967296);b[(c+64>>>9<<4)+15]=a;d.sigBytes=4*b.length;this._process();return this._hash},clone:function(){var b=j.clone.call(this);b._hash=this._hash.clone();return b}});g.SHA256=j._createHelper(h);g.HmacSHA256=j._createHmacHelper(h)})(Math);\r\n\n/*\r\nCryptoJS v3.1.2 sha512-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(){function a(){return d.create.apply(d,arguments)}for(var n=CryptoJS,r=n.lib.Hasher,e=n.x64,d=e.Word,T=e.WordArray,e=n.algo,ea=[a(1116352408,3609767458),a(1899447441,602891725),a(3049323471,3964484399),a(3921009573,2173295548),a(961987163,4081628472),a(1508970993,3053834265),a(2453635748,2937671579),a(2870763221,3664609560),a(3624381080,2734883394),a(310598401,1164996542),a(607225278,1323610764),a(1426881987,3590304994),a(1925078388,4068182383),a(2162078206,991336113),a(2614888103,633803317),\r\na(3248222580,3479774868),a(3835390401,2666613458),a(4022224774,944711139),a(264347078,2341262773),a(604807628,2007800933),a(770255983,1495990901),a(1249150122,1856431235),a(1555081692,3175218132),a(1996064986,2198950837),a(2554220882,3999719339),a(2821834349,766784016),a(2952996808,2566594879),a(3210313671,3203337956),a(3336571891,1034457026),a(3584528711,2466948901),a(113926993,3758326383),a(338241895,168717936),a(666307205,1188179964),a(773529912,1546045734),a(1294757372,1522805485),a(1396182291,\r\n2643833823),a(1695183700,2343527390),a(1986661051,1014477480),a(2177026350,1206759142),a(2456956037,344077627),a(2730485921,1290863460),a(2820302411,3158454273),a(3259730800,3505952657),a(3345764771,106217008),a(3516065817,3606008344),a(3600352804,1432725776),a(4094571909,1467031594),a(275423344,851169720),a(430227734,3100823752),a(506948616,1363258195),a(659060556,3750685593),a(883997877,3785050280),a(958139571,3318307427),a(1322822218,3812723403),a(1537002063,2003034995),a(1747873779,3602036899),\r\na(1955562222,1575990012),a(2024104815,1125592928),a(2227730452,2716904306),a(2361852424,442776044),a(2428436474,593698344),a(2756734187,3733110249),a(3204031479,2999351573),a(3329325298,3815920427),a(3391569614,3928383900),a(3515267271,566280711),a(3940187606,3454069534),a(4118630271,4000239992),a(116418474,1914138554),a(174292421,2731055270),a(289380356,3203993006),a(460393269,320620315),a(685471733,587496836),a(852142971,1086792851),a(1017036298,365543100),a(1126000580,2618297676),a(1288033470,\r\n3409855158),a(1501505948,4234509866),a(1607167915,987167468),a(1816402316,1246189591)],v=[],w=0;80>w;w++)v[w]=a();e=e.SHA512=r.extend({_doReset:function(){this._hash=new T.init([new d.init(1779033703,4089235720),new d.init(3144134277,2227873595),new d.init(1013904242,4271175723),new d.init(2773480762,1595750129),new d.init(1359893119,2917565137),new d.init(2600822924,725511199),new d.init(528734635,4215389547),new d.init(1541459225,327033209)])},_doProcessBlock:function(a,d){for(var f=this._hash.words,\r\nF=f[0],e=f[1],n=f[2],r=f[3],G=f[4],H=f[5],I=f[6],f=f[7],w=F.high,J=F.low,X=e.high,K=e.low,Y=n.high,L=n.low,Z=r.high,M=r.low,$=G.high,N=G.low,aa=H.high,O=H.low,ba=I.high,P=I.low,ca=f.high,Q=f.low,k=w,g=J,z=X,x=K,A=Y,y=L,U=Z,B=M,l=$,h=N,R=aa,C=O,S=ba,D=P,V=ca,E=Q,m=0;80>m;m++){var s=v[m];if(16>m)var j=s.high=a[d+2*m]|0,b=s.low=a[d+2*m+1]|0;else{var j=v[m-15],b=j.high,p=j.low,j=(b>>>1|p<<31)^(b>>>8|p<<24)^b>>>7,p=(p>>>1|b<<31)^(p>>>8|b<<24)^(p>>>7|b<<25),u=v[m-2],b=u.high,c=u.low,u=(b>>>19|c<<13)^(b<<\r\n3|c>>>29)^b>>>6,c=(c>>>19|b<<13)^(c<<3|b>>>29)^(c>>>6|b<<26),b=v[m-7],W=b.high,t=v[m-16],q=t.high,t=t.low,b=p+b.low,j=j+W+(b>>>0<p>>>0?1:0),b=b+c,j=j+u+(b>>>0<c>>>0?1:0),b=b+t,j=j+q+(b>>>0<t>>>0?1:0);s.high=j;s.low=b}var W=l&R^~l&S,t=h&C^~h&D,s=k&z^k&A^z&A,T=g&x^g&y^x&y,p=(k>>>28|g<<4)^(k<<30|g>>>2)^(k<<25|g>>>7),u=(g>>>28|k<<4)^(g<<30|k>>>2)^(g<<25|k>>>7),c=ea[m],fa=c.high,da=c.low,c=E+((h>>>14|l<<18)^(h>>>18|l<<14)^(h<<23|l>>>9)),q=V+((l>>>14|h<<18)^(l>>>18|h<<14)^(l<<23|h>>>9))+(c>>>0<E>>>0?1:\r\n0),c=c+t,q=q+W+(c>>>0<t>>>0?1:0),c=c+da,q=q+fa+(c>>>0<da>>>0?1:0),c=c+b,q=q+j+(c>>>0<b>>>0?1:0),b=u+T,s=p+s+(b>>>0<u>>>0?1:0),V=S,E=D,S=R,D=C,R=l,C=h,h=B+c|0,l=U+q+(h>>>0<B>>>0?1:0)|0,U=A,B=y,A=z,y=x,z=k,x=g,g=c+b|0,k=q+s+(g>>>0<c>>>0?1:0)|0}J=F.low=J+g;F.high=w+k+(J>>>0<g>>>0?1:0);K=e.low=K+x;e.high=X+z+(K>>>0<x>>>0?1:0);L=n.low=L+y;n.high=Y+A+(L>>>0<y>>>0?1:0);M=r.low=M+B;r.high=Z+U+(M>>>0<B>>>0?1:0);N=G.low=N+h;G.high=$+l+(N>>>0<h>>>0?1:0);O=H.low=O+C;H.high=aa+R+(O>>>0<C>>>0?1:0);P=I.low=P+D;\r\nI.high=ba+S+(P>>>0<D>>>0?1:0);Q=f.low=Q+E;f.high=ca+V+(Q>>>0<E>>>0?1:0)},_doFinalize:function(){var a=this._data,d=a.words,f=8*this._nDataBytes,e=8*a.sigBytes;d[e>>>5]|=128<<24-e%32;d[(e+128>>>10<<5)+30]=Math.floor(f/4294967296);d[(e+128>>>10<<5)+31]=f;a.sigBytes=4*d.length;this._process();return this._hash.toX32()},clone:function(){var a=r.clone.call(this);a._hash=this._hash.clone();return a},blockSize:32});n.SHA512=r._createHelper(e);n.HmacSHA512=r._createHmacHelper(e)})();\r\n\n/*\r\nCryptoJS v3.1.2 sha384-min.js\r\ncode.google.com/p/crypto-js\r\n(c) 2009-2013 by Jeff Mott. All rights reserved.\r\ncode.google.com/p/crypto-js/wiki/License\r\n*/\r\n(function(){var c=CryptoJS,a=c.x64,b=a.Word,e=a.WordArray,a=c.algo,d=a.SHA512,a=a.SHA384=d.extend({_doReset:function(){this._hash=new e.init([new b.init(3418070365,3238371032),new b.init(1654270250,914150663),new b.init(2438529370,812702999),new b.init(355462360,4144912697),new b.init(1731405415,4290775857),new b.init(2394180231,1750603025),new b.init(3675008525,1694076839),new b.init(1203062813,3204075428)])},_doFinalize:function(){var a=d._doFinalize.call(this);a.sigBytes-=16;return a}});c.SHA384=\r\nd._createHelper(a);c.HmacSHA384=d._createHmacHelper(a)})();\r\n\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nvar b64map=\"ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/\";var b64pad=\"=\";function hex2b64(d){var b;var e;var a=\"\";for(b=0;b+3<=d.length;b+=3){e=parseInt(d.substring(b,b+3),16);a+=b64map.charAt(e>>6)+b64map.charAt(e&63)}if(b+1==d.length){e=parseInt(d.substring(b,b+1),16);a+=b64map.charAt(e<<2)}else{if(b+2==d.length){e=parseInt(d.substring(b,b+2),16);a+=b64map.charAt(e>>2)+b64map.charAt((e&3)<<4)}}if(b64pad){while((a.length&3)>0){a+=b64pad}}return a}function b64tohex(f){var d=\"\";var e;var b=0;var c;var a;for(e=0;e<f.length;++e){if(f.charAt(e)==b64pad){break}a=b64map.indexOf(f.charAt(e));if(a<0){continue}if(b==0){d+=int2char(a>>2);c=a&3;b=1}else{if(b==1){d+=int2char((c<<2)|(a>>4));c=a&15;b=2}else{if(b==2){d+=int2char(c);d+=int2char(a>>2);c=a&3;b=3}else{d+=int2char((c<<2)|(a>>4));d+=int2char(a&15);b=0}}}}if(b==1){d+=int2char(c<<2)}return d}function b64toBA(e){var d=b64tohex(e);var c;var b=new Array();for(c=0;2*c<d.length;++c){b[c]=parseInt(d.substring(2*c,2*c+2),16)}return b};\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nvar dbits;var canary=244837814094590;var j_lm=((canary&16777215)==15715070);function BigInteger(e,d,f){if(e!=null){if(\"number\"==typeof e){this.fromNumber(e,d,f)}else{if(d==null&&\"string\"!=typeof e){this.fromString(e,256)}else{this.fromString(e,d)}}}}function nbi(){return new BigInteger(null)}function am1(f,a,b,e,h,g){while(--g>=0){var d=a*this[f++]+b[e]+h;h=Math.floor(d/67108864);b[e++]=d&67108863}return h}function am2(f,q,r,e,o,a){var k=q&32767,p=q>>15;while(--a>=0){var d=this[f]&32767;var g=this[f++]>>15;var b=p*d+g*k;d=k*d+((b&32767)<<15)+r[e]+(o&1073741823);o=(d>>>30)+(b>>>15)+p*g+(o>>>30);r[e++]=d&1073741823}return o}function am3(f,q,r,e,o,a){var k=q&16383,p=q>>14;while(--a>=0){var d=this[f]&16383;var g=this[f++]>>14;var b=p*d+g*k;d=k*d+((b&16383)<<14)+r[e]+o;o=(d>>28)+(b>>14)+p*g;r[e++]=d&268435455}return o}if(j_lm&&(navigator.appName==\"Microsoft Internet Explorer\")){BigInteger.prototype.am=am2;dbits=30}else{if(j_lm&&(navigator.appName!=\"Netscape\")){BigInteger.prototype.am=am1;dbits=26}else{BigInteger.prototype.am=am3;dbits=28}}BigInteger.prototype.DB=dbits;BigInteger.prototype.DM=((1<<dbits)-1);BigInteger.prototype.DV=(1<<dbits);var BI_FP=52;BigInteger.prototype.FV=Math.pow(2,BI_FP);BigInteger.prototype.F1=BI_FP-dbits;BigInteger.prototype.F2=2*dbits-BI_FP;var BI_RM=\"0123456789abcdefghijklmnopqrstuvwxyz\";var BI_RC=new Array();var rr,vv;rr=\"0\".charCodeAt(0);for(vv=0;vv<=9;++vv){BI_RC[rr++]=vv}rr=\"a\".charCodeAt(0);for(vv=10;vv<36;++vv){BI_RC[rr++]=vv}rr=\"A\".charCodeAt(0);for(vv=10;vv<36;++vv){BI_RC[rr++]=vv}function int2char(a){return BI_RM.charAt(a)}function intAt(b,a){var d=BI_RC[b.charCodeAt(a)];return(d==null)?-1:d}function bnpCopyTo(b){for(var a=this.t-1;a>=0;--a){b[a]=this[a]}b.t=this.t;b.s=this.s}function bnpFromInt(a){this.t=1;this.s=(a<0)?-1:0;if(a>0){this[0]=a}else{if(a<-1){this[0]=a+this.DV}else{this.t=0}}}function nbv(a){var b=nbi();b.fromInt(a);return b}function bnpFromString(h,c){var e;if(c==16){e=4}else{if(c==8){e=3}else{if(c==256){e=8}else{if(c==2){e=1}else{if(c==32){e=5}else{if(c==4){e=2}else{this.fromRadix(h,c);return}}}}}}this.t=0;this.s=0;var g=h.length,d=false,f=0;while(--g>=0){var a=(e==8)?h[g]&255:intAt(h,g);if(a<0){if(h.charAt(g)==\"-\"){d=true}continue}d=false;if(f==0){this[this.t++]=a}else{if(f+e>this.DB){this[this.t-1]|=(a&((1<<(this.DB-f))-1))<<f;this[this.t++]=(a>>(this.DB-f))}else{this[this.t-1]|=a<<f}}f+=e;if(f>=this.DB){f-=this.DB}}if(e==8&&(h[0]&128)!=0){this.s=-1;if(f>0){this[this.t-1]|=((1<<(this.DB-f))-1)<<f}}this.clamp();if(d){BigInteger.ZERO.subTo(this,this)}}function bnpClamp(){var a=this.s&this.DM;while(this.t>0&&this[this.t-1]==a){--this.t}}function bnToString(c){if(this.s<0){return\"-\"+this.negate().toString(c)}var e;if(c==16){e=4}else{if(c==8){e=3}else{if(c==2){e=1}else{if(c==32){e=5}else{if(c==4){e=2}else{return this.toRadix(c)}}}}}var g=(1<<e)-1,l,a=false,h=\"\",f=this.t;var j=this.DB-(f*this.DB)%e;if(f-->0){if(j<this.DB&&(l=this[f]>>j)>0){a=true;h=int2char(l)}while(f>=0){if(j<e){l=(this[f]&((1<<j)-1))<<(e-j);l|=this[--f]>>(j+=this.DB-e)}else{l=(this[f]>>(j-=e))&g;if(j<=0){j+=this.DB;--f}}if(l>0){a=true}if(a){h+=int2char(l)}}}return a?h:\"0\"}function bnNegate(){var a=nbi();BigInteger.ZERO.subTo(this,a);return a}function bnAbs(){return(this.s<0)?this.negate():this}function bnCompareTo(b){var d=this.s-b.s;if(d!=0){return d}var c=this.t;d=c-b.t;if(d!=0){return(this.s<0)?-d:d}while(--c>=0){if((d=this[c]-b[c])!=0){return d}}return 0}function nbits(a){var c=1,b;if((b=a>>>16)!=0){a=b;c+=16}if((b=a>>8)!=0){a=b;c+=8}if((b=a>>4)!=0){a=b;c+=4}if((b=a>>2)!=0){a=b;c+=2}if((b=a>>1)!=0){a=b;c+=1}return c}function bnBitLength(){if(this.t<=0){return 0}return this.DB*(this.t-1)+nbits(this[this.t-1]^(this.s&this.DM))}function bnpDLShiftTo(c,b){var a;for(a=this.t-1;a>=0;--a){b[a+c]=this[a]}for(a=c-1;a>=0;--a){b[a]=0}b.t=this.t+c;b.s=this.s}function bnpDRShiftTo(c,b){for(var a=c;a<this.t;++a){b[a-c]=this[a]}b.t=Math.max(this.t-c,0);b.s=this.s}function bnpLShiftTo(j,e){var b=j%this.DB;var a=this.DB-b;var g=(1<<a)-1;var f=Math.floor(j/this.DB),h=(this.s<<b)&this.DM,d;for(d=this.t-1;d>=0;--d){e[d+f+1]=(this[d]>>a)|h;h=(this[d]&g)<<b}for(d=f-1;d>=0;--d){e[d]=0}e[f]=h;e.t=this.t+f+1;e.s=this.s;e.clamp()}function bnpRShiftTo(g,d){d.s=this.s;var e=Math.floor(g/this.DB);if(e>=this.t){d.t=0;return}var b=g%this.DB;var a=this.DB-b;var f=(1<<b)-1;d[0]=this[e]>>b;for(var c=e+1;c<this.t;++c){d[c-e-1]|=(this[c]&f)<<a;d[c-e]=this[c]>>b}if(b>0){d[this.t-e-1]|=(this.s&f)<<a}d.t=this.t-e;d.clamp()}function bnpSubTo(d,f){var e=0,g=0,b=Math.min(d.t,this.t);while(e<b){g+=this[e]-d[e];f[e++]=g&this.DM;g>>=this.DB}if(d.t<this.t){g-=d.s;while(e<this.t){g+=this[e];f[e++]=g&this.DM;g>>=this.DB}g+=this.s}else{g+=this.s;while(e<d.t){g-=d[e];f[e++]=g&this.DM;g>>=this.DB}g-=d.s}f.s=(g<0)?-1:0;if(g<-1){f[e++]=this.DV+g}else{if(g>0){f[e++]=g}}f.t=e;f.clamp()}function bnpMultiplyTo(c,e){var b=this.abs(),f=c.abs();var d=b.t;e.t=d+f.t;while(--d>=0){e[d]=0}for(d=0;d<f.t;++d){e[d+b.t]=b.am(0,f[d],e,d,0,b.t)}e.s=0;e.clamp();if(this.s!=c.s){BigInteger.ZERO.subTo(e,e)}}function bnpSquareTo(d){var a=this.abs();var b=d.t=2*a.t;while(--b>=0){d[b]=0}for(b=0;b<a.t-1;++b){var e=a.am(b,a[b],d,2*b,0,1);if((d[b+a.t]+=a.am(b+1,2*a[b],d,2*b+1,e,a.t-b-1))>=a.DV){d[b+a.t]-=a.DV;d[b+a.t+1]=1}}if(d.t>0){d[d.t-1]+=a.am(b,a[b],d,2*b,0,1)}d.s=0;d.clamp()}function bnpDivRemTo(n,h,g){var w=n.abs();if(w.t<=0){return}var k=this.abs();if(k.t<w.t){if(h!=null){h.fromInt(0)}if(g!=null){this.copyTo(g)}return}if(g==null){g=nbi()}var d=nbi(),a=this.s,l=n.s;var v=this.DB-nbits(w[w.t-1]);if(v>0){w.lShiftTo(v,d);k.lShiftTo(v,g)}else{w.copyTo(d);k.copyTo(g)}var p=d.t;var b=d[p-1];if(b==0){return}var o=b*(1<<this.F1)+((p>1)?d[p-2]>>this.F2:0);var A=this.FV/o,z=(1<<this.F1)/o,x=1<<this.F2;var u=g.t,s=u-p,f=(h==null)?nbi():h;d.dlShiftTo(s,f);if(g.compareTo(f)>=0){g[g.t++]=1;g.subTo(f,g)}BigInteger.ONE.dlShiftTo(p,f);f.subTo(d,d);while(d.t<p){d[d.t++]=0}while(--s>=0){var c=(g[--u]==b)?this.DM:Math.floor(g[u]*A+(g[u-1]+x)*z);if((g[u]+=d.am(0,c,g,s,0,p))<c){d.dlShiftTo(s,f);g.subTo(f,g);while(g[u]<--c){g.subTo(f,g)}}}if(h!=null){g.drShiftTo(p,h);if(a!=l){BigInteger.ZERO.subTo(h,h)}}g.t=p;g.clamp();if(v>0){g.rShiftTo(v,g)}if(a<0){BigInteger.ZERO.subTo(g,g)}}function bnMod(b){var c=nbi();this.abs().divRemTo(b,null,c);if(this.s<0&&c.compareTo(BigInteger.ZERO)>0){b.subTo(c,c)}return c}function Classic(a){this.m=a}function cConvert(a){if(a.s<0||a.compareTo(this.m)>=0){return a.mod(this.m)}else{return a}}function cRevert(a){return a}function cReduce(a){a.divRemTo(this.m,null,a)}function cMulTo(a,c,b){a.multiplyTo(c,b);this.reduce(b)}function cSqrTo(a,b){a.squareTo(b);this.reduce(b)}Classic.prototype.convert=cConvert;Classic.prototype.revert=cRevert;Classic.prototype.reduce=cReduce;Classic.prototype.mulTo=cMulTo;Classic.prototype.sqrTo=cSqrTo;function bnpInvDigit(){if(this.t<1){return 0}var a=this[0];if((a&1)==0){return 0}var b=a&3;b=(b*(2-(a&15)*b))&15;b=(b*(2-(a&255)*b))&255;b=(b*(2-(((a&65535)*b)&65535)))&65535;b=(b*(2-a*b%this.DV))%this.DV;return(b>0)?this.DV-b:-b}function Montgomery(a){this.m=a;this.mp=a.invDigit();this.mpl=this.mp&32767;this.mph=this.mp>>15;this.um=(1<<(a.DB-15))-1;this.mt2=2*a.t}function montConvert(a){var b=nbi();a.abs().dlShiftTo(this.m.t,b);b.divRemTo(this.m,null,b);if(a.s<0&&b.compareTo(BigInteger.ZERO)>0){this.m.subTo(b,b)}return b}function montRevert(a){var b=nbi();a.copyTo(b);this.reduce(b);return b}function montReduce(a){while(a.t<=this.mt2){a[a.t++]=0}for(var c=0;c<this.m.t;++c){var b=a[c]&32767;var d=(b*this.mpl+(((b*this.mph+(a[c]>>15)*this.mpl)&this.um)<<15))&a.DM;b=c+this.m.t;a[b]+=this.m.am(0,d,a,c,0,this.m.t);while(a[b]>=a.DV){a[b]-=a.DV;a[++b]++}}a.clamp();a.drShiftTo(this.m.t,a);if(a.compareTo(this.m)>=0){a.subTo(this.m,a)}}function montSqrTo(a,b){a.squareTo(b);this.reduce(b)}function montMulTo(a,c,b){a.multiplyTo(c,b);this.reduce(b)}Montgomery.prototype.convert=montConvert;Montgomery.prototype.revert=montRevert;Montgomery.prototype.reduce=montReduce;Montgomery.prototype.mulTo=montMulTo;Montgomery.prototype.sqrTo=montSqrTo;function bnpIsEven(){return((this.t>0)?(this[0]&1):this.s)==0}function bnpExp(h,j){if(h>4294967295||h<1){return BigInteger.ONE}var f=nbi(),a=nbi(),d=j.convert(this),c=nbits(h)-1;d.copyTo(f);while(--c>=0){j.sqrTo(f,a);if((h&(1<<c))>0){j.mulTo(a,d,f)}else{var b=f;f=a;a=b}}return j.revert(f)}function bnModPowInt(b,a){var c;if(b<256||a.isEven()){c=new Classic(a)}else{c=new Montgomery(a)}return this.exp(b,c)}BigInteger.prototype.copyTo=bnpCopyTo;BigInteger.prototype.fromInt=bnpFromInt;BigInteger.prototype.fromString=bnpFromString;BigInteger.prototype.clamp=bnpClamp;BigInteger.prototype.dlShiftTo=bnpDLShiftTo;BigInteger.prototype.drShiftTo=bnpDRShiftTo;BigInteger.prototype.lShiftTo=bnpLShiftTo;BigInteger.prototype.rShiftTo=bnpRShiftTo;BigInteger.prototype.subTo=bnpSubTo;BigInteger.prototype.multiplyTo=bnpMultiplyTo;BigInteger.prototype.squareTo=bnpSquareTo;BigInteger.prototype.divRemTo=bnpDivRemTo;BigInteger.prototype.invDigit=bnpInvDigit;BigInteger.prototype.isEven=bnpIsEven;BigInteger.prototype.exp=bnpExp;BigInteger.prototype.toString=bnToString;BigInteger.prototype.negate=bnNegate;BigInteger.prototype.abs=bnAbs;BigInteger.prototype.compareTo=bnCompareTo;BigInteger.prototype.bitLength=bnBitLength;BigInteger.prototype.mod=bnMod;BigInteger.prototype.modPowInt=bnModPowInt;BigInteger.ZERO=nbv(0);BigInteger.ONE=nbv(1);\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction bnClone(){var a=nbi();this.copyTo(a);return a}function bnIntValue(){if(this.s<0){if(this.t==1){return this[0]-this.DV}else{if(this.t==0){return -1}}}else{if(this.t==1){return this[0]}else{if(this.t==0){return 0}}}return((this[1]&((1<<(32-this.DB))-1))<<this.DB)|this[0]}function bnByteValue(){return(this.t==0)?this.s:(this[0]<<24)>>24}function bnShortValue(){return(this.t==0)?this.s:(this[0]<<16)>>16}function bnpChunkSize(a){return Math.floor(Math.LN2*this.DB/Math.log(a))}function bnSigNum(){if(this.s<0){return -1}else{if(this.t<=0||(this.t==1&&this[0]<=0)){return 0}else{return 1}}}function bnpToRadix(c){if(c==null){c=10}if(this.signum()==0||c<2||c>36){return\"0\"}var f=this.chunkSize(c);var e=Math.pow(c,f);var i=nbv(e),j=nbi(),h=nbi(),g=\"\";this.divRemTo(i,j,h);while(j.signum()>0){g=(e+h.intValue()).toString(c).substr(1)+g;j.divRemTo(i,j,h)}return h.intValue().toString(c)+g}function bnpFromRadix(m,h){this.fromInt(0);if(h==null){h=10}var f=this.chunkSize(h);var g=Math.pow(h,f),e=false,a=0,l=0;for(var c=0;c<m.length;++c){var k=intAt(m,c);if(k<0){if(m.charAt(c)==\"-\"&&this.signum()==0){e=true}continue}l=h*l+k;if(++a>=f){this.dMultiply(g);this.dAddOffset(l,0);a=0;l=0}}if(a>0){this.dMultiply(Math.pow(h,a));this.dAddOffset(l,0)}if(e){BigInteger.ZERO.subTo(this,this)}}function bnpFromNumber(f,e,h){if(\"number\"==typeof e){if(f<2){this.fromInt(1)}else{this.fromNumber(f,h);if(!this.testBit(f-1)){this.bitwiseTo(BigInteger.ONE.shiftLeft(f-1),op_or,this)}if(this.isEven()){this.dAddOffset(1,0)}while(!this.isProbablePrime(e)){this.dAddOffset(2,0);if(this.bitLength()>f){this.subTo(BigInteger.ONE.shiftLeft(f-1),this)}}}}else{var d=new Array(),g=f&7;d.length=(f>>3)+1;e.nextBytes(d);if(g>0){d[0]&=((1<<g)-1)}else{d[0]=0}this.fromString(d,256)}}function bnToByteArray(){var b=this.t,c=new Array();c[0]=this.s;var e=this.DB-(b*this.DB)%8,f,a=0;if(b-->0){if(e<this.DB&&(f=this[b]>>e)!=(this.s&this.DM)>>e){c[a++]=f|(this.s<<(this.DB-e))}while(b>=0){if(e<8){f=(this[b]&((1<<e)-1))<<(8-e);f|=this[--b]>>(e+=this.DB-8)}else{f=(this[b]>>(e-=8))&255;if(e<=0){e+=this.DB;--b}}if((f&128)!=0){f|=-256}if(a==0&&(this.s&128)!=(f&128)){++a}if(a>0||f!=this.s){c[a++]=f}}}return c}function bnEquals(b){return(this.compareTo(b)==0)}function bnMin(b){return(this.compareTo(b)<0)?this:b}function bnMax(b){return(this.compareTo(b)>0)?this:b}function bnpBitwiseTo(c,h,e){var d,g,b=Math.min(c.t,this.t);for(d=0;d<b;++d){e[d]=h(this[d],c[d])}if(c.t<this.t){g=c.s&this.DM;for(d=b;d<this.t;++d){e[d]=h(this[d],g)}e.t=this.t}else{g=this.s&this.DM;for(d=b;d<c.t;++d){e[d]=h(g,c[d])}e.t=c.t}e.s=h(this.s,c.s);e.clamp()}function op_and(a,b){return a&b}function bnAnd(b){var c=nbi();this.bitwiseTo(b,op_and,c);return c}function op_or(a,b){return a|b}function bnOr(b){var c=nbi();this.bitwiseTo(b,op_or,c);return c}function op_xor(a,b){return a^b}function bnXor(b){var c=nbi();this.bitwiseTo(b,op_xor,c);return c}function op_andnot(a,b){return a&~b}function bnAndNot(b){var c=nbi();this.bitwiseTo(b,op_andnot,c);return c}function bnNot(){var b=nbi();for(var a=0;a<this.t;++a){b[a]=this.DM&~this[a]}b.t=this.t;b.s=~this.s;return b}function bnShiftLeft(b){var a=nbi();if(b<0){this.rShiftTo(-b,a)}else{this.lShiftTo(b,a)}return a}function bnShiftRight(b){var a=nbi();if(b<0){this.lShiftTo(-b,a)}else{this.rShiftTo(b,a)}return a}function lbit(a){if(a==0){return -1}var b=0;if((a&65535)==0){a>>=16;b+=16}if((a&255)==0){a>>=8;b+=8}if((a&15)==0){a>>=4;b+=4}if((a&3)==0){a>>=2;b+=2}if((a&1)==0){++b}return b}function bnGetLowestSetBit(){for(var a=0;a<this.t;++a){if(this[a]!=0){return a*this.DB+lbit(this[a])}}if(this.s<0){return this.t*this.DB}return -1}function cbit(a){var b=0;while(a!=0){a&=a-1;++b}return b}function bnBitCount(){var c=0,a=this.s&this.DM;for(var b=0;b<this.t;++b){c+=cbit(this[b]^a)}return c}function bnTestBit(b){var a=Math.floor(b/this.DB);if(a>=this.t){return(this.s!=0)}return((this[a]&(1<<(b%this.DB)))!=0)}function bnpChangeBit(c,b){var a=BigInteger.ONE.shiftLeft(c);this.bitwiseTo(a,b,a);return a}function bnSetBit(a){return this.changeBit(a,op_or)}function bnClearBit(a){return this.changeBit(a,op_andnot)}function bnFlipBit(a){return this.changeBit(a,op_xor)}function bnpAddTo(d,f){var e=0,g=0,b=Math.min(d.t,this.t);while(e<b){g+=this[e]+d[e];f[e++]=g&this.DM;g>>=this.DB}if(d.t<this.t){g+=d.s;while(e<this.t){g+=this[e];f[e++]=g&this.DM;g>>=this.DB}g+=this.s}else{g+=this.s;while(e<d.t){g+=d[e];f[e++]=g&this.DM;g>>=this.DB}g+=d.s}f.s=(g<0)?-1:0;if(g>0){f[e++]=g}else{if(g<-1){f[e++]=this.DV+g}}f.t=e;f.clamp()}function bnAdd(b){var c=nbi();this.addTo(b,c);return c}function bnSubtract(b){var c=nbi();this.subTo(b,c);return c}function bnMultiply(b){var c=nbi();this.multiplyTo(b,c);return c}function bnSquare(){var a=nbi();this.squareTo(a);return a}function bnDivide(b){var c=nbi();this.divRemTo(b,c,null);return c}function bnRemainder(b){var c=nbi();this.divRemTo(b,null,c);return c}function bnDivideAndRemainder(b){var d=nbi(),c=nbi();this.divRemTo(b,d,c);return new Array(d,c)}function bnpDMultiply(a){this[this.t]=this.am(0,a-1,this,0,0,this.t);++this.t;this.clamp()}function bnpDAddOffset(b,a){if(b==0){return}while(this.t<=a){this[this.t++]=0}this[a]+=b;while(this[a]>=this.DV){this[a]-=this.DV;if(++a>=this.t){this[this.t++]=0}++this[a]}}function NullExp(){}function nNop(a){return a}function nMulTo(a,c,b){a.multiplyTo(c,b)}function nSqrTo(a,b){a.squareTo(b)}NullExp.prototype.convert=nNop;NullExp.prototype.revert=nNop;NullExp.prototype.mulTo=nMulTo;NullExp.prototype.sqrTo=nSqrTo;function bnPow(a){return this.exp(a,new NullExp())}function bnpMultiplyLowerTo(b,f,e){var d=Math.min(this.t+b.t,f);e.s=0;e.t=d;while(d>0){e[--d]=0}var c;for(c=e.t-this.t;d<c;++d){e[d+this.t]=this.am(0,b[d],e,d,0,this.t)}for(c=Math.min(b.t,f);d<c;++d){this.am(0,b[d],e,d,0,f-d)}e.clamp()}function bnpMultiplyUpperTo(b,e,d){--e;var c=d.t=this.t+b.t-e;d.s=0;while(--c>=0){d[c]=0}for(c=Math.max(e-this.t,0);c<b.t;++c){d[this.t+c-e]=this.am(e-c,b[c],d,0,0,this.t+c-e)}d.clamp();d.drShiftTo(1,d)}function Barrett(a){this.r2=nbi();this.q3=nbi();BigInteger.ONE.dlShiftTo(2*a.t,this.r2);this.mu=this.r2.divide(a);this.m=a}function barrettConvert(a){if(a.s<0||a.t>2*this.m.t){return a.mod(this.m)}else{if(a.compareTo(this.m)<0){return a}else{var b=nbi();a.copyTo(b);this.reduce(b);return b}}}function barrettRevert(a){return a}function barrettReduce(a){a.drShiftTo(this.m.t-1,this.r2);if(a.t>this.m.t+1){a.t=this.m.t+1;a.clamp()}this.mu.multiplyUpperTo(this.r2,this.m.t+1,this.q3);this.m.multiplyLowerTo(this.q3,this.m.t+1,this.r2);while(a.compareTo(this.r2)<0){a.dAddOffset(1,this.m.t+1)}a.subTo(this.r2,a);while(a.compareTo(this.m)>=0){a.subTo(this.m,a)}}function barrettSqrTo(a,b){a.squareTo(b);this.reduce(b)}function barrettMulTo(a,c,b){a.multiplyTo(c,b);this.reduce(b)}Barrett.prototype.convert=barrettConvert;Barrett.prototype.revert=barrettRevert;Barrett.prototype.reduce=barrettReduce;Barrett.prototype.mulTo=barrettMulTo;Barrett.prototype.sqrTo=barrettSqrTo;function bnModPow(q,f){var o=q.bitLength(),h,b=nbv(1),v;if(o<=0){return b}else{if(o<18){h=1}else{if(o<48){h=3}else{if(o<144){h=4}else{if(o<768){h=5}else{h=6}}}}}if(o<8){v=new Classic(f)}else{if(f.isEven()){v=new Barrett(f)}else{v=new Montgomery(f)}}var p=new Array(),d=3,s=h-1,a=(1<<h)-1;p[1]=v.convert(this);if(h>1){var A=nbi();v.sqrTo(p[1],A);while(d<=a){p[d]=nbi();v.mulTo(A,p[d-2],p[d]);d+=2}}var l=q.t-1,x,u=true,c=nbi(),y;o=nbits(q[l])-1;while(l>=0){if(o>=s){x=(q[l]>>(o-s))&a}else{x=(q[l]&((1<<(o+1))-1))<<(s-o);if(l>0){x|=q[l-1]>>(this.DB+o-s)}}d=h;while((x&1)==0){x>>=1;--d}if((o-=d)<0){o+=this.DB;--l}if(u){p[x].copyTo(b);u=false}else{while(d>1){v.sqrTo(b,c);v.sqrTo(c,b);d-=2}if(d>0){v.sqrTo(b,c)}else{y=b;b=c;c=y}v.mulTo(c,p[x],b)}while(l>=0&&(q[l]&(1<<o))==0){v.sqrTo(b,c);y=b;b=c;c=y;if(--o<0){o=this.DB-1;--l}}}return v.revert(b)}function bnGCD(c){var b=(this.s<0)?this.negate():this.clone();var h=(c.s<0)?c.negate():c.clone();if(b.compareTo(h)<0){var e=b;b=h;h=e}var d=b.getLowestSetBit(),f=h.getLowestSetBit();if(f<0){return b}if(d<f){f=d}if(f>0){b.rShiftTo(f,b);h.rShiftTo(f,h)}while(b.signum()>0){if((d=b.getLowestSetBit())>0){b.rShiftTo(d,b)}if((d=h.getLowestSetBit())>0){h.rShiftTo(d,h)}if(b.compareTo(h)>=0){b.subTo(h,b);b.rShiftTo(1,b)}else{h.subTo(b,h);h.rShiftTo(1,h)}}if(f>0){h.lShiftTo(f,h)}return h}function bnpModInt(e){if(e<=0){return 0}var c=this.DV%e,b=(this.s<0)?e-1:0;if(this.t>0){if(c==0){b=this[0]%e}else{for(var a=this.t-1;a>=0;--a){b=(c*b+this[a])%e}}}return b}function bnModInverse(f){var j=f.isEven();if((this.isEven()&&j)||f.signum()==0){return BigInteger.ZERO}var i=f.clone(),h=this.clone();var g=nbv(1),e=nbv(0),l=nbv(0),k=nbv(1);while(i.signum()!=0){while(i.isEven()){i.rShiftTo(1,i);if(j){if(!g.isEven()||!e.isEven()){g.addTo(this,g);e.subTo(f,e)}g.rShiftTo(1,g)}else{if(!e.isEven()){e.subTo(f,e)}}e.rShiftTo(1,e)}while(h.isEven()){h.rShiftTo(1,h);if(j){if(!l.isEven()||!k.isEven()){l.addTo(this,l);k.subTo(f,k)}l.rShiftTo(1,l)}else{if(!k.isEven()){k.subTo(f,k)}}k.rShiftTo(1,k)}if(i.compareTo(h)>=0){i.subTo(h,i);if(j){g.subTo(l,g)}e.subTo(k,e)}else{h.subTo(i,h);if(j){l.subTo(g,l)}k.subTo(e,k)}}if(h.compareTo(BigInteger.ONE)!=0){return BigInteger.ZERO}if(k.compareTo(f)>=0){return k.subtract(f)}if(k.signum()<0){k.addTo(f,k)}else{return k}if(k.signum()<0){return k.add(f)}else{return k}}var lowprimes=[2,3,5,7,11,13,17,19,23,29,31,37,41,43,47,53,59,61,67,71,73,79,83,89,97,101,103,107,109,113,127,131,137,139,149,151,157,163,167,173,179,181,191,193,197,199,211,223,227,229,233,239,241,251,257,263,269,271,277,281,283,293,307,311,313,317,331,337,347,349,353,359,367,373,379,383,389,397,401,409,419,421,431,433,439,443,449,457,461,463,467,479,487,491,499,503,509,521,523,541,547,557,563,569,571,577,587,593,599,601,607,613,617,619,631,641,643,647,653,659,661,673,677,683,691,701,709,719,727,733,739,743,751,757,761,769,773,787,797,809,811,821,823,827,829,839,853,857,859,863,877,881,883,887,907,911,919,929,937,941,947,953,967,971,977,983,991,997];var lplim=(1<<26)/lowprimes[lowprimes.length-1];function bnIsProbablePrime(e){var d,b=this.abs();if(b.t==1&&b[0]<=lowprimes[lowprimes.length-1]){for(d=0;d<lowprimes.length;++d){if(b[0]==lowprimes[d]){return true}}return false}if(b.isEven()){return false}d=1;while(d<lowprimes.length){var a=lowprimes[d],c=d+1;while(c<lowprimes.length&&a<lplim){a*=lowprimes[c++]}a=b.modInt(a);while(d<c){if(a%lowprimes[d++]==0){return false}}}return b.millerRabin(e)}function bnpMillerRabin(f){var g=this.subtract(BigInteger.ONE);var c=g.getLowestSetBit();if(c<=0){return false}var h=g.shiftRight(c);f=(f+1)>>1;if(f>lowprimes.length){f=lowprimes.length}var b=nbi();for(var e=0;e<f;++e){b.fromInt(lowprimes[Math.floor(Math.random()*lowprimes.length)]);var l=b.modPow(h,this);if(l.compareTo(BigInteger.ONE)!=0&&l.compareTo(g)!=0){var d=1;while(d++<c&&l.compareTo(g)!=0){l=l.modPowInt(2,this);if(l.compareTo(BigInteger.ONE)==0){return false}}if(l.compareTo(g)!=0){return false}}}return true}BigInteger.prototype.chunkSize=bnpChunkSize;BigInteger.prototype.toRadix=bnpToRadix;BigInteger.prototype.fromRadix=bnpFromRadix;BigInteger.prototype.fromNumber=bnpFromNumber;BigInteger.prototype.bitwiseTo=bnpBitwiseTo;BigInteger.prototype.changeBit=bnpChangeBit;BigInteger.prototype.addTo=bnpAddTo;BigInteger.prototype.dMultiply=bnpDMultiply;BigInteger.prototype.dAddOffset=bnpDAddOffset;BigInteger.prototype.multiplyLowerTo=bnpMultiplyLowerTo;BigInteger.prototype.multiplyUpperTo=bnpMultiplyUpperTo;BigInteger.prototype.modInt=bnpModInt;BigInteger.prototype.millerRabin=bnpMillerRabin;BigInteger.prototype.clone=bnClone;BigInteger.prototype.intValue=bnIntValue;BigInteger.prototype.byteValue=bnByteValue;BigInteger.prototype.shortValue=bnShortValue;BigInteger.prototype.signum=bnSigNum;BigInteger.prototype.toByteArray=bnToByteArray;BigInteger.prototype.equals=bnEquals;BigInteger.prototype.min=bnMin;BigInteger.prototype.max=bnMax;BigInteger.prototype.and=bnAnd;BigInteger.prototype.or=bnOr;BigInteger.prototype.xor=bnXor;BigInteger.prototype.andNot=bnAndNot;BigInteger.prototype.not=bnNot;BigInteger.prototype.shiftLeft=bnShiftLeft;BigInteger.prototype.shiftRight=bnShiftRight;BigInteger.prototype.getLowestSetBit=bnGetLowestSetBit;BigInteger.prototype.bitCount=bnBitCount;BigInteger.prototype.testBit=bnTestBit;BigInteger.prototype.setBit=bnSetBit;BigInteger.prototype.clearBit=bnClearBit;BigInteger.prototype.flipBit=bnFlipBit;BigInteger.prototype.add=bnAdd;BigInteger.prototype.subtract=bnSubtract;BigInteger.prototype.multiply=bnMultiply;BigInteger.prototype.divide=bnDivide;BigInteger.prototype.remainder=bnRemainder;BigInteger.prototype.divideAndRemainder=bnDivideAndRemainder;BigInteger.prototype.modPow=bnModPow;BigInteger.prototype.modInverse=bnModInverse;BigInteger.prototype.pow=bnPow;BigInteger.prototype.gcd=bnGCD;BigInteger.prototype.isProbablePrime=bnIsProbablePrime;BigInteger.prototype.square=bnSquare;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction Arcfour(){this.i=0;this.j=0;this.S=new Array()}function ARC4init(d){var c,a,b;for(c=0;c<256;++c){this.S[c]=c}a=0;for(c=0;c<256;++c){a=(a+this.S[c]+d[c%d.length])&255;b=this.S[c];this.S[c]=this.S[a];this.S[a]=b}this.i=0;this.j=0}function ARC4next(){var a;this.i=(this.i+1)&255;this.j=(this.j+this.S[this.i])&255;a=this.S[this.i];this.S[this.i]=this.S[this.j];this.S[this.j]=a;return this.S[(a+this.S[this.i])&255]}Arcfour.prototype.init=ARC4init;Arcfour.prototype.next=ARC4next;function prng_newstate(){return new Arcfour()}var rng_psize=256;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nvar rng_state;var rng_pool;var rng_pptr;function rng_seed_int(a){rng_pool[rng_pptr++]^=a&255;rng_pool[rng_pptr++]^=(a>>8)&255;rng_pool[rng_pptr++]^=(a>>16)&255;rng_pool[rng_pptr++]^=(a>>24)&255;if(rng_pptr>=rng_psize){rng_pptr-=rng_psize}}function rng_seed_time(){rng_seed_int(new Date().getTime())}if(rng_pool==null){rng_pool=new Array();rng_pptr=0;var t;if(window!==undefined&&(window.crypto!==undefined||window.msCrypto!==undefined)){var crypto=window.crypto||window.msCrypto;if(crypto.getRandomValues){var ua=new Uint8Array(32);crypto.getRandomValues(ua);for(t=0;t<32;++t){rng_pool[rng_pptr++]=ua[t]}}else{if(navigator.appName==\"Netscape\"&&navigator.appVersion<\"5\"){var z=window.crypto.random(32);for(t=0;t<z.length;++t){rng_pool[rng_pptr++]=z.charCodeAt(t)&255}}}}while(rng_pptr<rng_psize){t=Math.floor(65536*Math.random());rng_pool[rng_pptr++]=t>>>8;rng_pool[rng_pptr++]=t&255}rng_pptr=0;rng_seed_time()}function rng_get_byte(){if(rng_state==null){rng_seed_time();rng_state=prng_newstate();rng_state.init(rng_pool);for(rng_pptr=0;rng_pptr<rng_pool.length;++rng_pptr){rng_pool[rng_pptr]=0}rng_pptr=0}return rng_state.next()}function rng_get_bytes(b){var a;for(a=0;a<b.length;++a){b[a]=rng_get_byte()}}function SecureRandom(){}SecureRandom.prototype.nextBytes=rng_get_bytes;\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction parseBigInt(b,a){return new BigInteger(b,a)}function linebrk(c,d){var a=\"\";var b=0;while(b+d<c.length){a+=c.substring(b,b+d)+\"\\n\";b+=d}return a+c.substring(b,c.length)}function byte2Hex(a){if(a<16){return\"0\"+a.toString(16)}else{return a.toString(16)}}function pkcs1pad2(e,h){if(h<e.length+11){throw\"Message too long for RSA\";return null}var g=new Array();var d=e.length-1;while(d>=0&&h>0){var f=e.charCodeAt(d--);if(f<128){g[--h]=f}else{if((f>127)&&(f<2048)){g[--h]=(f&63)|128;g[--h]=(f>>6)|192}else{g[--h]=(f&63)|128;g[--h]=((f>>6)&63)|128;g[--h]=(f>>12)|224}}}g[--h]=0;var b=new SecureRandom();var a=new Array();while(h>2){a[0]=0;while(a[0]==0){b.nextBytes(a)}g[--h]=a[0]}g[--h]=2;g[--h]=0;return new BigInteger(g)}function oaep_mgf1_arr(c,a,e){var b=\"\",d=0;while(b.length<a){b+=e(String.fromCharCode.apply(String,c.concat([(d&4278190080)>>24,(d&16711680)>>16,(d&65280)>>8,d&255])));d+=1}return b}function oaep_pad(q,a,f,l){var c=KJUR.crypto.MessageDigest;var o=KJUR.crypto.Util;var b=null;if(!f){f=\"sha1\"}if(typeof f===\"string\"){b=c.getCanonicalAlgName(f);l=c.getHashLength(b);f=function(i){return hextorstr(o.hashHex(rstrtohex(i),b))}}if(q.length+2*l+2>a){throw\"Message too long for RSA\"}var k=\"\",e;for(e=0;e<a-q.length-2*l-2;e+=1){k+=\"\\x00\"}var h=f(\"\")+k+\"\\x01\"+q;var g=new Array(l);new SecureRandom().nextBytes(g);var j=oaep_mgf1_arr(g,h.length,f);var p=[];for(e=0;e<h.length;e+=1){p[e]=h.charCodeAt(e)^j.charCodeAt(e)}var m=oaep_mgf1_arr(p,g.length,f);var d=[0];for(e=0;e<g.length;e+=1){d[e+1]=g[e]^m.charCodeAt(e)}return new BigInteger(d.concat(p))}function RSAKey(){this.n=null;this.e=0;this.d=null;this.p=null;this.q=null;this.dmp1=null;this.dmq1=null;this.coeff=null}function RSASetPublic(b,a){this.isPublic=true;this.isPrivate=false;if(typeof b!==\"string\"){this.n=b;this.e=a}else{if(b!=null&&a!=null&&b.length>0&&a.length>0){this.n=parseBigInt(b,16);this.e=parseInt(a,16)}else{throw\"Invalid RSA public key\"}}}function RSADoPublic(a){return a.modPowInt(this.e,this.n)}function RSAEncrypt(d){var a=pkcs1pad2(d,(this.n.bitLength()+7)>>3);if(a==null){return null}var e=this.doPublic(a);if(e==null){return null}var b=e.toString(16);if((b.length&1)==0){return b}else{return\"0\"+b}}function RSAEncryptOAEP(f,e,b){var a=oaep_pad(f,(this.n.bitLength()+7)>>3,e,b);if(a==null){return null}var g=this.doPublic(a);if(g==null){return null}var d=g.toString(16);if((d.length&1)==0){return d}else{return\"0\"+d}}RSAKey.prototype.doPublic=RSADoPublic;RSAKey.prototype.setPublic=RSASetPublic;RSAKey.prototype.encrypt=RSAEncrypt;RSAKey.prototype.encryptOAEP=RSAEncryptOAEP;RSAKey.prototype.type=\"RSA\";\n/*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/\r\n */\r\nfunction ECFieldElementFp(b,a){this.x=a;this.q=b}function feFpEquals(a){if(a==this){return true}return(this.q.equals(a.q)&&this.x.equals(a.x))}function feFpToBigInteger(){return this.x}function feFpNegate(){return new ECFieldElementFp(this.q,this.x.negate().mod(this.q))}function feFpAdd(a){return new ECFieldElementFp(this.q,this.x.add(a.toBigInteger()).mod(this.q))}function feFpSubtract(a){return new ECFieldElementFp(this.q,this.x.subtract(a.toBigInteger()).mod(this.q))}function feFpMultiply(a){return new ECFieldElementFp(this.q,this.x.multiply(a.toBigInteger()).mod(this.q))}function feFpSquare(){return new ECFieldElementFp(this.q,this.x.square().mod(this.q))}function feFpDivide(a){return new ECFieldElementFp(this.q,this.x.multiply(a.toBigInteger().modInverse(this.q)).mod(this.q))}ECFieldElementFp.prototype.equals=feFpEquals;ECFieldElementFp.prototype.toBigInteger=feFpToBigInteger;ECFieldElementFp.prototype.negate=feFpNegate;ECFieldElementFp.prototype.add=feFpAdd;ECFieldElementFp.prototype.subtract=feFpSubtract;ECFieldElementFp.prototype.multiply=feFpMultiply;ECFieldElementFp.prototype.square=feFpSquare;ECFieldElementFp.prototype.divide=feFpDivide;function ECPointFp(c,a,d,b){this.curve=c;this.x=a;this.y=d;if(b==null){this.z=BigInteger.ONE}else{this.z=b}this.zinv=null}function pointFpGetX(){if(this.zinv==null){this.zinv=this.z.modInverse(this.curve.q)}return this.curve.fromBigInteger(this.x.toBigInteger().multiply(this.zinv).mod(this.curve.q))}function pointFpGetY(){if(this.zinv==null){this.zinv=this.z.modInverse(this.curve.q)}return this.curve.fromBigInteger(this.y.toBigInteger().multiply(this.zinv).mod(this.curve.q))}function pointFpEquals(a){if(a==this){return true}if(this.isInfinity()){return a.isInfinity()}if(a.isInfinity()){return this.isInfinity()}var c,b;c=a.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(a.z)).mod(this.curve.q);if(!c.equals(BigInteger.ZERO)){return false}b=a.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(a.z)).mod(this.curve.q);return b.equals(BigInteger.ZERO)}function pointFpIsInfinity(){if((this.x==null)&&(this.y==null)){return true}return this.z.equals(BigInteger.ZERO)&&!this.y.toBigInteger().equals(BigInteger.ZERO)}function pointFpNegate(){return new ECPointFp(this.curve,this.x,this.y.negate(),this.z)}function pointFpAdd(l){if(this.isInfinity()){return l}if(l.isInfinity()){return this}var p=l.y.toBigInteger().multiply(this.z).subtract(this.y.toBigInteger().multiply(l.z)).mod(this.curve.q);var o=l.x.toBigInteger().multiply(this.z).subtract(this.x.toBigInteger().multiply(l.z)).mod(this.curve.q);if(BigInteger.ZERO.equals(o)){if(BigInteger.ZERO.equals(p)){return this.twice()}return this.curve.getInfinity()}var j=new BigInteger(\"3\");var e=this.x.toBigInteger();var n=this.y.toBigInteger();var c=l.x.toBigInteger();var k=l.y.toBigInteger();var m=o.square();var i=m.multiply(o);var d=e.multiply(m);var g=p.square().multiply(this.z);var a=g.subtract(d.shiftLeft(1)).multiply(l.z).subtract(i).multiply(o).mod(this.curve.q);var h=d.multiply(j).multiply(p).subtract(n.multiply(i)).subtract(g.multiply(p)).multiply(l.z).add(p.multiply(i)).mod(this.curve.q);var f=i.multiply(this.z).multiply(l.z).mod(this.curve.q);return new ECPointFp(this.curve,this.curve.fromBigInteger(a),this.curve.fromBigInteger(h),f)}function pointFpTwice(){if(this.isInfinity()){return this}if(this.y.toBigInteger().signum()==0){return this.curve.getInfinity()}var g=new BigInteger(\"3\");var c=this.x.toBigInteger();var h=this.y.toBigInteger();var e=h.multiply(this.z);var j=e.multiply(h).mod(this.curve.q);var i=this.curve.a.toBigInteger();var k=c.square().multiply(g);if(!BigInteger.ZERO.equals(i)){k=k.add(this.z.square().multiply(i))}k=k.mod(this.curve.q);var b=k.square().subtract(c.shiftLeft(3).multiply(j)).shiftLeft(1).multiply(e).mod(this.curve.q);var f=k.multiply(g).multiply(c).subtract(j.shiftLeft(1)).shiftLeft(2).multiply(j).subtract(k.square().multiply(k)).mod(this.curve.q);var d=e.square().multiply(e).shiftLeft(3).mod(this.curve.q);return new ECPointFp(this.curve,this.curve.fromBigInteger(b),this.curve.fromBigInteger(f),d)}function pointFpMultiply(b){if(this.isInfinity()){return this}if(b.signum()==0){return this.curve.getInfinity()}var g=b;var f=g.multiply(new BigInteger(\"3\"));var l=this.negate();var d=this;var c;for(c=f.bitLength()-2;c>0;--c){d=d.twice();var a=f.testBit(c);var j=g.testBit(c);if(a!=j){d=d.add(a?this:l)}}return d}function pointFpMultiplyTwo(c,a,b){var d;if(c.bitLength()>b.bitLength()){d=c.bitLength()-1}else{d=b.bitLength()-1}var f=this.curve.getInfinity();var e=this.add(a);while(d>=0){f=f.twice();if(c.testBit(d)){if(b.testBit(d)){f=f.add(e)}else{f=f.add(this)}}else{if(b.testBit(d)){f=f.add(a)}}--d}return f}ECPointFp.prototype.getX=pointFpGetX;ECPointFp.prototype.getY=pointFpGetY;ECPointFp.prototype.equals=pointFpEquals;ECPointFp.prototype.isInfinity=pointFpIsInfinity;ECPointFp.prototype.negate=pointFpNegate;ECPointFp.prototype.add=pointFpAdd;ECPointFp.prototype.twice=pointFpTwice;ECPointFp.prototype.multiply=pointFpMultiply;ECPointFp.prototype.multiplyTwo=pointFpMultiplyTwo;function ECCurveFp(e,d,c){this.q=e;this.a=this.fromBigInteger(d);this.b=this.fromBigInteger(c);this.infinity=new ECPointFp(this,null,null)}function curveFpGetQ(){return this.q}function curveFpGetA(){return this.a}function curveFpGetB(){return this.b}function curveFpEquals(a){if(a==this){return true}return(this.q.equals(a.q)&&this.a.equals(a.a)&&this.b.equals(a.b))}function curveFpGetInfinity(){return this.infinity}function curveFpFromBigInteger(a){return new ECFieldElementFp(this.q,a)}function curveFpDecodePointHex(d){switch(parseInt(d.substr(0,2),16)){case 0:return this.infinity;case 2:case 3:return null;case 4:case 6:case 7:var a=(d.length-2)/2;var c=d.substr(2,a);var b=d.substr(a+2,a);return new ECPointFp(this,this.fromBigInteger(new BigInteger(c,16)),this.fromBigInteger(new BigInteger(b,16)));default:return null}}ECCurveFp.prototype.getQ=curveFpGetQ;ECCurveFp.prototype.getA=curveFpGetA;ECCurveFp.prototype.getB=curveFpGetB;ECCurveFp.prototype.equals=curveFpEquals;ECCurveFp.prototype.getInfinity=curveFpGetInfinity;ECCurveFp.prototype.fromBigInteger=curveFpFromBigInteger;ECCurveFp.prototype.decodePointHex=curveFpDecodePointHex;\n/*! (c) Stefan Thomas | https://github.com/bitcoinjs/bitcoinjs-lib\r\n */\r\nECFieldElementFp.prototype.getByteLength=function(){return Math.floor((this.toBigInteger().bitLength()+7)/8)};ECPointFp.prototype.getEncoded=function(c){var d=function(h,f){var g=h.toByteArrayUnsigned();if(f<g.length){g=g.slice(g.length-f)}else{while(f>g.length){g.unshift(0)}}return g};var a=this.getX().toBigInteger();var e=this.getY().toBigInteger();var b=d(a,32);if(c){if(e.isEven()){b.unshift(2)}else{b.unshift(3)}}else{b.unshift(4);b=b.concat(d(e,32))}return b};ECPointFp.decodeFrom=function(g,c){var f=c[0];var e=c.length-1;var d=c.slice(1,1+e/2);var b=c.slice(1+e/2,1+e);d.unshift(0);b.unshift(0);var a=new BigInteger(d);var h=new BigInteger(b);return new ECPointFp(g,g.fromBigInteger(a),g.fromBigInteger(h))};ECPointFp.decodeFromHex=function(g,c){var f=c.substr(0,2);var e=c.length-2;var d=c.substr(2,e/2);var b=c.substr(2+e/2,e/2);var a=new BigInteger(d,16);var h=new BigInteger(b,16);return new ECPointFp(g,g.fromBigInteger(a),g.fromBigInteger(h))};ECPointFp.prototype.add2D=function(c){if(this.isInfinity()){return c}if(c.isInfinity()){return this}if(this.x.equals(c.x)){if(this.y.equals(c.y)){return this.twice()}return this.curve.getInfinity()}var g=c.x.subtract(this.x);var e=c.y.subtract(this.y);var a=e.divide(g);var d=a.square().subtract(this.x).subtract(c.x);var f=a.multiply(this.x.subtract(d)).subtract(this.y);return new ECPointFp(this.curve,d,f)};ECPointFp.prototype.twice2D=function(){if(this.isInfinity()){return this}if(this.y.toBigInteger().signum()==0){return this.curve.getInfinity()}var b=this.curve.fromBigInteger(BigInteger.valueOf(2));var e=this.curve.fromBigInteger(BigInteger.valueOf(3));var a=this.x.square().multiply(e).add(this.curve.a).divide(this.y.multiply(b));var c=a.square().subtract(this.x.multiply(b));var d=a.multiply(this.x.subtract(c)).subtract(this.y);return new ECPointFp(this.curve,c,d)};ECPointFp.prototype.multiply2D=function(b){if(this.isInfinity()){return this}if(b.signum()==0){return this.curve.getInfinity()}var g=b;var f=g.multiply(new BigInteger(\"3\"));var l=this.negate();var d=this;var c;for(c=f.bitLength()-2;c>0;--c){d=d.twice();var a=f.testBit(c);var j=g.testBit(c);if(a!=j){d=d.add2D(a?this:l)}}return d};ECPointFp.prototype.isOnCurve=function(){var d=this.getX().toBigInteger();var i=this.getY().toBigInteger();var f=this.curve.getA().toBigInteger();var c=this.curve.getB().toBigInteger();var h=this.curve.getQ();var e=i.multiply(i).mod(h);var g=d.multiply(d).multiply(d).add(f.multiply(d)).add(c).mod(h);return e.equals(g)};ECPointFp.prototype.toString=function(){return\"(\"+this.getX().toBigInteger().toString()+\",\"+this.getY().toBigInteger().toString()+\")\"};ECPointFp.prototype.validate=function(){var c=this.curve.getQ();if(this.isInfinity()){throw new Error(\"Point is at infinity.\")}var a=this.getX().toBigInteger();var b=this.getY().toBigInteger();if(a.compareTo(BigInteger.ONE)<0||a.compareTo(c.subtract(BigInteger.ONE))>0){throw new Error(\"x coordinate out of bounds\")}if(b.compareTo(BigInteger.ONE)<0||b.compareTo(c.subtract(BigInteger.ONE))>0){throw new Error(\"y coordinate out of bounds\")}if(!this.isOnCurve()){throw new Error(\"Point is not on the curve.\")}if(this.multiply(c).isInfinity()){throw new Error(\"Point is not a scalar multiple of G.\")}return true};\n/*! Mike Samuel (c) 2009 | code.google.com/p/json-sans-eval\r\n */\r\nvar jsonParse=(function(){var e=\"(?:-?\\\\b(?:0|[1-9][0-9]*)(?:\\\\.[0-9]+)?(?:[eE][+-]?[0-9]+)?\\\\b)\";var j='(?:[^\\\\0-\\\\x08\\\\x0a-\\\\x1f\"\\\\\\\\]|\\\\\\\\(?:[\"/\\\\\\\\bfnrt]|u[0-9A-Fa-f]{4}))';var i='(?:\"'+j+'*\")';var d=new RegExp(\"(?:false|true|null|[\\\\{\\\\}\\\\[\\\\]]|\"+e+\"|\"+i+\")\",\"g\");var k=new RegExp(\"\\\\\\\\(?:([^u])|u(.{4}))\",\"g\");var g={'\"':'\"',\"/\":\"/\",\"\\\\\":\"\\\\\",b:\"\\b\",f:\"\\f\",n:\"\\n\",r:\"\\r\",t:\"\\t\"};function h(l,m,n){return m?g[m]:String.fromCharCode(parseInt(n,16))}var c=new String(\"\");var a=\"\\\\\";var f={\"{\":Object,\"[\":Array};var b=Object.hasOwnProperty;return function(u,q){var p=u.match(d);var x;var v=p[0];var l=false;if(\"{\"===v){x={}}else{if(\"[\"===v){x=[]}else{x=[];l=true}}var t;var r=[x];for(var o=1-l,m=p.length;o<m;++o){v=p[o];var w;switch(v.charCodeAt(0)){default:w=r[0];w[t||w.length]=+(v);t=void 0;break;case 34:v=v.substring(1,v.length-1);if(v.indexOf(a)!==-1){v=v.replace(k,h)}w=r[0];if(!t){if(w instanceof Array){t=w.length}else{t=v||c;break}}w[t]=v;t=void 0;break;case 91:w=r[0];r.unshift(w[t||w.length]=[]);t=void 0;break;case 93:r.shift();break;case 102:w=r[0];w[t||w.length]=false;t=void 0;break;case 110:w=r[0];w[t||w.length]=null;t=void 0;break;case 116:w=r[0];w[t||w.length]=true;t=void 0;break;case 123:w=r[0];r.unshift(w[t||w.length]={});t=void 0;break;case 125:r.shift();break}}if(l){if(r.length!==1){throw new Error()}x=x[0]}else{if(r.length){throw new Error()}}if(q){var s=function(C,B){var D=C[B];if(D&&typeof D===\"object\"){var n=null;for(var z in D){if(b.call(D,z)&&D!==C){var y=s(D,z);if(y!==void 0){D[z]=y}else{if(!n){n=[]}n.push(z)}}}if(n){for(var A=n.length;--A>=0;){delete D[n[A]]}}}return q.call(C,B,D)};x=s({\"\":x},\"\")}return x}})();\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.asn1==\"undefined\"||!KJUR.asn1){KJUR.asn1={}}KJUR.asn1.ASN1Util=new function(){this.integerToByteHex=function(a){var b=a.toString(16);if((b.length%2)==1){b=\"0\"+b}return b};this.bigIntToMinTwosComplementsHex=function(j){var f=j.toString(16);if(f.substr(0,1)!=\"-\"){if(f.length%2==1){f=\"0\"+f}else{if(!f.match(/^[0-7]/)){f=\"00\"+f}}}else{var a=f.substr(1);var e=a.length;if(e%2==1){e+=1}else{if(!f.match(/^[0-7]/)){e+=2}}var g=\"\";for(var d=0;d<e;d++){g+=\"f\"}var c=new BigInteger(g,16);var b=c.xor(j).add(BigInteger.ONE);f=b.toString(16).replace(/^-/,\"\")}return f};this.getPEMStringFromHex=function(a,b){return hextopem(a,b)};this.newObject=function(k){var D=KJUR,n=D.asn1,z=n.DERBoolean,e=n.DERInteger,s=n.DERBitString,h=n.DEROctetString,v=n.DERNull,w=n.DERObjectIdentifier,l=n.DEREnumerated,g=n.DERUTF8String,f=n.DERNumericString,y=n.DERPrintableString,u=n.DERTeletexString,p=n.DERIA5String,C=n.DERUTCTime,j=n.DERGeneralizedTime,m=n.DERSequence,c=n.DERSet,r=n.DERTaggedObject,o=n.ASN1Util.newObject;var t=Object.keys(k);if(t.length!=1){throw\"key of param shall be only one.\"}var F=t[0];if(\":bool:int:bitstr:octstr:null:oid:enum:utf8str:numstr:prnstr:telstr:ia5str:utctime:gentime:seq:set:tag:\".indexOf(\":\"+F+\":\")==-1){throw\"undefined key: \"+F}if(F==\"bool\"){return new z(k[F])}if(F==\"int\"){return new e(k[F])}if(F==\"bitstr\"){return new s(k[F])}if(F==\"octstr\"){return new h(k[F])}if(F==\"null\"){return new v(k[F])}if(F==\"oid\"){return new w(k[F])}if(F==\"enum\"){return new l(k[F])}if(F==\"utf8str\"){return new g(k[F])}if(F==\"numstr\"){return new f(k[F])}if(F==\"prnstr\"){return new y(k[F])}if(F==\"telstr\"){return new u(k[F])}if(F==\"ia5str\"){return new p(k[F])}if(F==\"utctime\"){return new C(k[F])}if(F==\"gentime\"){return new j(k[F])}if(F==\"seq\"){var d=k[F];var E=[];for(var x=0;x<d.length;x++){var B=o(d[x]);E.push(B)}return new m({array:E})}if(F==\"set\"){var d=k[F];var E=[];for(var x=0;x<d.length;x++){var B=o(d[x]);E.push(B)}return new c({array:E})}if(F==\"tag\"){var A=k[F];if(Object.prototype.toString.call(A)===\"[object Array]\"&&A.length==3){var q=o(A[2]);return new r({tag:A[0],explicit:A[1],obj:q})}else{var b={};if(A.explicit!==undefined){b.explicit=A.explicit}if(A.tag!==undefined){b.tag=A.tag}if(A.obj===undefined){throw\"obj shall be specified for 'tag'.\"}b.obj=o(A.obj);return new r(b)}}};this.jsonToASN1HEX=function(b){var a=this.newObject(b);return a.getEncodedHex()}};KJUR.asn1.ASN1Util.oidHexToInt=function(a){var j=\"\";var k=parseInt(a.substr(0,2),16);var d=Math.floor(k/40);var c=k%40;var j=d+\".\"+c;var e=\"\";for(var f=2;f<a.length;f+=2){var g=parseInt(a.substr(f,2),16);var h=(\"00000000\"+g.toString(2)).slice(-8);e=e+h.substr(1,7);if(h.substr(0,1)==\"0\"){var b=new BigInteger(e,2);j=j+\".\"+b.toString(10);e=\"\"}}return j};KJUR.asn1.ASN1Util.oidIntToHex=function(f){var e=function(a){var k=a.toString(16);if(k.length==1){k=\"0\"+k}return k};var d=function(o){var n=\"\";var k=new BigInteger(o,10);var a=k.toString(2);var l=7-a.length%7;if(l==7){l=0}var q=\"\";for(var m=0;m<l;m++){q+=\"0\"}a=q+a;for(var m=0;m<a.length-1;m+=7){var p=a.substr(m,7);if(m!=a.length-7){p=\"1\"+p}n+=e(parseInt(p,2))}return n};if(!f.match(/^[0-9.]+$/)){throw\"malformed oid string: \"+f}var g=\"\";var b=f.split(\".\");var j=parseInt(b[0])*40+parseInt(b[1]);g+=e(j);b.splice(0,2);for(var c=0;c<b.length;c++){g+=d(b[c])}return g};KJUR.asn1.ASN1Object=function(){var c=true;var b=null;var d=\"00\";var e=\"00\";var a=\"\";this.getLengthHexFromValue=function(){if(typeof this.hV==\"undefined\"||this.hV==null){throw\"this.hV is null or undefined.\"}if(this.hV.length%2==1){throw\"value hex must be even length: n=\"+a.length+\",v=\"+this.hV}var i=this.hV.length/2;var h=i.toString(16);if(h.length%2==1){h=\"0\"+h}if(i<128){return h}else{var g=h.length/2;if(g>15){throw\"ASN.1 length too long to represent by 8x: n = \"+i.toString(16)}var f=128+g;return f.toString(16)+h}};this.getEncodedHex=function(){if(this.hTLV==null||this.isModified){this.hV=this.getFreshValueHex();this.hL=this.getLengthHexFromValue();this.hTLV=this.hT+this.hL+this.hV;this.isModified=false}return this.hTLV};this.getValueHex=function(){this.getEncodedHex();return this.hV};this.getFreshValueHex=function(){return\"\"}};KJUR.asn1.DERAbstractString=function(c){KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var b=null;var a=null;this.getString=function(){return this.s};this.setString=function(d){this.hTLV=null;this.isModified=true;this.s=d;this.hV=utf8tohex(this.s).toLowerCase()};this.setStringHex=function(d){this.hTLV=null;this.isModified=true;this.s=null;this.hV=d};this.getFreshValueHex=function(){return this.hV};if(typeof c!=\"undefined\"){if(typeof c==\"string\"){this.setString(c)}else{if(typeof c.str!=\"undefined\"){this.setString(c.str)}else{if(typeof c.hex!=\"undefined\"){this.setStringHex(c.hex)}}}}};YAHOO.lang.extend(KJUR.asn1.DERAbstractString,KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractTime=function(c){KJUR.asn1.DERAbstractTime.superclass.constructor.call(this);var b=null;var a=null;this.localDateToUTC=function(f){utc=f.getTime()+(f.getTimezoneOffset()*60000);var e=new Date(utc);return e};this.formatDate=function(m,o,e){var g=this.zeroPadding;var n=this.localDateToUTC(m);var p=String(n.getFullYear());if(o==\"utc\"){p=p.substr(2,2)}var l=g(String(n.getMonth()+1),2);var q=g(String(n.getDate()),2);var h=g(String(n.getHours()),2);var i=g(String(n.getMinutes()),2);var j=g(String(n.getSeconds()),2);var r=p+l+q+h+i+j;if(e===true){var f=n.getMilliseconds();if(f!=0){var k=g(String(f),3);k=k.replace(/[0]+$/,\"\");r=r+\".\"+k}}return r+\"Z\"};this.zeroPadding=function(e,d){if(e.length>=d){return e}return new Array(d-e.length+1).join(\"0\")+e};this.getString=function(){return this.s};this.setString=function(d){this.hTLV=null;this.isModified=true;this.s=d;this.hV=stohex(d)};this.setByDateValue=function(h,j,e,d,f,g){var i=new Date(Date.UTC(h,j-1,e,d,f,g,0));this.setByDate(i)};this.getFreshValueHex=function(){return this.hV}};YAHOO.lang.extend(KJUR.asn1.DERAbstractTime,KJUR.asn1.ASN1Object);KJUR.asn1.DERAbstractStructured=function(b){KJUR.asn1.DERAbstractString.superclass.constructor.call(this);var a=null;this.setByASN1ObjectArray=function(c){this.hTLV=null;this.isModified=true;this.asn1Array=c};this.appendASN1Object=function(c){this.hTLV=null;this.isModified=true;this.asn1Array.push(c)};this.asn1Array=new Array();if(typeof b!=\"undefined\"){if(typeof b.array!=\"undefined\"){this.asn1Array=b.array}}};YAHOO.lang.extend(KJUR.asn1.DERAbstractStructured,KJUR.asn1.ASN1Object);KJUR.asn1.DERBoolean=function(){KJUR.asn1.DERBoolean.superclass.constructor.call(this);this.hT=\"01\";this.hTLV=\"0101ff\"};YAHOO.lang.extend(KJUR.asn1.DERBoolean,KJUR.asn1.ASN1Object);KJUR.asn1.DERInteger=function(a){KJUR.asn1.DERInteger.superclass.constructor.call(this);this.hT=\"02\";this.setByBigInteger=function(b){this.hTLV=null;this.isModified=true;this.hV=KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b)};this.setByInteger=function(c){var b=new BigInteger(String(c),10);this.setByBigInteger(b)};this.setValueHex=function(b){this.hV=b};this.getFreshValueHex=function(){return this.hV};if(typeof a!=\"undefined\"){if(typeof a.bigint!=\"undefined\"){this.setByBigInteger(a.bigint)}else{if(typeof a[\"int\"]!=\"undefined\"){this.setByInteger(a[\"int\"])}else{if(typeof a==\"number\"){this.setByInteger(a)}else{if(typeof a.hex!=\"undefined\"){this.setValueHex(a.hex)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERInteger,KJUR.asn1.ASN1Object);KJUR.asn1.DERBitString=function(b){if(b!==undefined&&typeof b.obj!==\"undefined\"){var a=KJUR.asn1.ASN1Util.newObject(b.obj);b.hex=\"00\"+a.getEncodedHex()}KJUR.asn1.DERBitString.superclass.constructor.call(this);this.hT=\"03\";this.setHexValueIncludingUnusedBits=function(c){this.hTLV=null;this.isModified=true;this.hV=c};this.setUnusedBitsAndHexValue=function(c,e){if(c<0||7<c){throw\"unused bits shall be from 0 to 7: u = \"+c}var d=\"0\"+c;this.hTLV=null;this.isModified=true;this.hV=d+e};this.setByBinaryString=function(e){e=e.replace(/0+$/,\"\");var f=8-e.length%8;if(f==8){f=0}for(var g=0;g<=f;g++){e+=\"0\"}var j=\"\";for(var g=0;g<e.length-1;g+=8){var d=e.substr(g,8);var c=parseInt(d,2).toString(16);if(c.length==1){c=\"0\"+c}j+=c}this.hTLV=null;this.isModified=true;this.hV=\"0\"+f+j};this.setByBooleanArray=function(e){var d=\"\";for(var c=0;c<e.length;c++){if(e[c]==true){d+=\"1\"}else{d+=\"0\"}}this.setByBinaryString(d)};this.newFalseArray=function(e){var c=new Array(e);for(var d=0;d<e;d++){c[d]=false}return c};this.getFreshValueHex=function(){return this.hV};if(typeof b!=\"undefined\"){if(typeof b==\"string\"&&b.toLowerCase().match(/^[0-9a-f]+$/)){this.setHexValueIncludingUnusedBits(b)}else{if(typeof b.hex!=\"undefined\"){this.setHexValueIncludingUnusedBits(b.hex)}else{if(typeof b.bin!=\"undefined\"){this.setByBinaryString(b.bin)}else{if(typeof b.array!=\"undefined\"){this.setByBooleanArray(b.array)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERBitString,KJUR.asn1.ASN1Object);KJUR.asn1.DEROctetString=function(b){if(b!==undefined&&typeof b.obj!==\"undefined\"){var a=KJUR.asn1.ASN1Util.newObject(b.obj);b.hex=a.getEncodedHex()}KJUR.asn1.DEROctetString.superclass.constructor.call(this,b);this.hT=\"04\"};YAHOO.lang.extend(KJUR.asn1.DEROctetString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERNull=function(){KJUR.asn1.DERNull.superclass.constructor.call(this);this.hT=\"05\";this.hTLV=\"0500\"};YAHOO.lang.extend(KJUR.asn1.DERNull,KJUR.asn1.ASN1Object);KJUR.asn1.DERObjectIdentifier=function(c){var b=function(d){var e=d.toString(16);if(e.length==1){e=\"0\"+e}return e};var a=function(k){var j=\"\";var e=new BigInteger(k,10);var d=e.toString(2);var f=7-d.length%7;if(f==7){f=0}var m=\"\";for(var g=0;g<f;g++){m+=\"0\"}d=m+d;for(var g=0;g<d.length-1;g+=7){var l=d.substr(g,7);if(g!=d.length-7){l=\"1\"+l}j+=b(parseInt(l,2))}return j};KJUR.asn1.DERObjectIdentifier.superclass.constructor.call(this);this.hT=\"06\";this.setValueHex=function(d){this.hTLV=null;this.isModified=true;this.s=null;this.hV=d};this.setValueOidString=function(f){if(!f.match(/^[0-9.]+$/)){throw\"malformed oid string: \"+f}var g=\"\";var d=f.split(\".\");var j=parseInt(d[0])*40+parseInt(d[1]);g+=b(j);d.splice(0,2);for(var e=0;e<d.length;e++){g+=a(d[e])}this.hTLV=null;this.isModified=true;this.s=null;this.hV=g};this.setValueName=function(e){var d=KJUR.asn1.x509.OID.name2oid(e);if(d!==\"\"){this.setValueOidString(d)}else{throw\"DERObjectIdentifier oidName undefined: \"+e}};this.getFreshValueHex=function(){return this.hV};if(c!==undefined){if(typeof c===\"string\"){if(c.match(/^[0-2].[0-9.]+$/)){this.setValueOidString(c)}else{this.setValueName(c)}}else{if(c.oid!==undefined){this.setValueOidString(c.oid)}else{if(c.hex!==undefined){this.setValueHex(c.hex)}else{if(c.name!==undefined){this.setValueName(c.name)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERObjectIdentifier,KJUR.asn1.ASN1Object);KJUR.asn1.DEREnumerated=function(a){KJUR.asn1.DEREnumerated.superclass.constructor.call(this);this.hT=\"0a\";this.setByBigInteger=function(b){this.hTLV=null;this.isModified=true;this.hV=KJUR.asn1.ASN1Util.bigIntToMinTwosComplementsHex(b)};this.setByInteger=function(c){var b=new BigInteger(String(c),10);this.setByBigInteger(b)};this.setValueHex=function(b){this.hV=b};this.getFreshValueHex=function(){return this.hV};if(typeof a!=\"undefined\"){if(typeof a[\"int\"]!=\"undefined\"){this.setByInteger(a[\"int\"])}else{if(typeof a==\"number\"){this.setByInteger(a)}else{if(typeof a.hex!=\"undefined\"){this.setValueHex(a.hex)}}}}};YAHOO.lang.extend(KJUR.asn1.DEREnumerated,KJUR.asn1.ASN1Object);KJUR.asn1.DERUTF8String=function(a){KJUR.asn1.DERUTF8String.superclass.constructor.call(this,a);this.hT=\"0c\"};YAHOO.lang.extend(KJUR.asn1.DERUTF8String,KJUR.asn1.DERAbstractString);KJUR.asn1.DERNumericString=function(a){KJUR.asn1.DERNumericString.superclass.constructor.call(this,a);this.hT=\"12\"};YAHOO.lang.extend(KJUR.asn1.DERNumericString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERPrintableString=function(a){KJUR.asn1.DERPrintableString.superclass.constructor.call(this,a);this.hT=\"13\"};YAHOO.lang.extend(KJUR.asn1.DERPrintableString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERTeletexString=function(a){KJUR.asn1.DERTeletexString.superclass.constructor.call(this,a);this.hT=\"14\"};YAHOO.lang.extend(KJUR.asn1.DERTeletexString,KJUR.asn1.DERAbstractString);KJUR.asn1.DERIA5String=function(a){KJUR.asn1.DERIA5String.superclass.constructor.call(this,a);this.hT=\"16\"};YAHOO.lang.extend(KJUR.asn1.DERIA5String,KJUR.asn1.DERAbstractString);KJUR.asn1.DERUTCTime=function(a){KJUR.asn1.DERUTCTime.superclass.constructor.call(this,a);this.hT=\"17\";this.setByDate=function(b){this.hTLV=null;this.isModified=true;this.date=b;this.s=this.formatDate(this.date,\"utc\");this.hV=stohex(this.s)};this.getFreshValueHex=function(){if(typeof this.date==\"undefined\"&&typeof this.s==\"undefined\"){this.date=new Date();this.s=this.formatDate(this.date,\"utc\");this.hV=stohex(this.s)}return this.hV};if(a!==undefined){if(a.str!==undefined){this.setString(a.str)}else{if(typeof a==\"string\"&&a.match(/^[0-9]{12}Z$/)){this.setString(a)}else{if(a.hex!==undefined){this.setStringHex(a.hex)}else{if(a.date!==undefined){this.setByDate(a.date)}}}}}};YAHOO.lang.extend(KJUR.asn1.DERUTCTime,KJUR.asn1.DERAbstractTime);KJUR.asn1.DERGeneralizedTime=function(a){KJUR.asn1.DERGeneralizedTime.superclass.constructor.call(this,a);this.hT=\"18\";this.withMillis=false;this.setByDate=function(b){this.hTLV=null;this.isModified=true;this.date=b;this.s=this.formatDate(this.date,\"gen\",this.withMillis);this.hV=stohex(this.s)};this.getFreshValueHex=function(){if(this.date===undefined&&this.s===undefined){this.date=new Date();this.s=this.formatDate(this.date,\"gen\",this.withMillis);this.hV=stohex(this.s)}return this.hV};if(a!==undefined){if(a.str!==undefined){this.setString(a.str)}else{if(typeof a==\"string\"&&a.match(/^[0-9]{14}Z$/)){this.setString(a)}else{if(a.hex!==undefined){this.setStringHex(a.hex)}else{if(a.date!==undefined){this.setByDate(a.date)}}}}if(a.millis===true){this.withMillis=true}}};YAHOO.lang.extend(KJUR.asn1.DERGeneralizedTime,KJUR.asn1.DERAbstractTime);KJUR.asn1.DERSequence=function(a){KJUR.asn1.DERSequence.superclass.constructor.call(this,a);this.hT=\"30\";this.getFreshValueHex=function(){var c=\"\";for(var b=0;b<this.asn1Array.length;b++){var d=this.asn1Array[b];c+=d.getEncodedHex()}this.hV=c;return this.hV}};YAHOO.lang.extend(KJUR.asn1.DERSequence,KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERSet=function(a){KJUR.asn1.DERSet.superclass.constructor.call(this,a);this.hT=\"31\";this.sortFlag=true;this.getFreshValueHex=function(){var b=new Array();for(var c=0;c<this.asn1Array.length;c++){var d=this.asn1Array[c];b.push(d.getEncodedHex())}if(this.sortFlag==true){b.sort()}this.hV=b.join(\"\");return this.hV};if(typeof a!=\"undefined\"){if(typeof a.sortflag!=\"undefined\"&&a.sortflag==false){this.sortFlag=false}}};YAHOO.lang.extend(KJUR.asn1.DERSet,KJUR.asn1.DERAbstractStructured);KJUR.asn1.DERTaggedObject=function(a){KJUR.asn1.DERTaggedObject.superclass.constructor.call(this);this.hT=\"a0\";this.hV=\"\";this.isExplicit=true;this.asn1Object=null;this.setASN1Object=function(b,c,d){this.hT=c;this.isExplicit=b;this.asn1Object=d;if(this.isExplicit){this.hV=this.asn1Object.getEncodedHex();this.hTLV=null;this.isModified=true}else{this.hV=null;this.hTLV=d.getEncodedHex();this.hTLV=this.hTLV.replace(/^../,c);this.isModified=false}};this.getFreshValueHex=function(){return this.hV};if(typeof a!=\"undefined\"){if(typeof a.tag!=\"undefined\"){this.hT=a.tag}if(typeof a.explicit!=\"undefined\"){this.isExplicit=a.explicit}if(typeof a.obj!=\"undefined\"){this.asn1Object=a.obj;this.setASN1Object(this.isExplicit,this.hT,this.asn1Object)}}};YAHOO.lang.extend(KJUR.asn1.DERTaggedObject,KJUR.asn1.ASN1Object);\nvar ASN1HEX=new function(){};ASN1HEX.getLblen=function(c,a){if(c.substr(a+2,1)!=\"8\"){return 1}var b=parseInt(c.substr(a+3,1));if(b==0){return -1}if(0<b&&b<10){return b+1}return -2};ASN1HEX.getL=function(c,b){var a=ASN1HEX.getLblen(c,b);if(a<1){return\"\"}return c.substr(b+2,a*2)};ASN1HEX.getVblen=function(d,a){var c,b;c=ASN1HEX.getL(d,a);if(c==\"\"){return -1}if(c.substr(0,1)===\"8\"){b=new BigInteger(c.substr(2),16)}else{b=new BigInteger(c,16)}return b.intValue()};ASN1HEX.getVidx=function(c,b){var a=ASN1HEX.getLblen(c,b);if(a<0){return a}return b+(a+1)*2};ASN1HEX.getV=function(d,a){var c=ASN1HEX.getVidx(d,a);var b=ASN1HEX.getVblen(d,a);return d.substr(c,b*2)};ASN1HEX.getTLV=function(b,a){return b.substr(a,2)+ASN1HEX.getL(b,a)+ASN1HEX.getV(b,a)};ASN1HEX.getNextSiblingIdx=function(d,a){var c=ASN1HEX.getVidx(d,a);var b=ASN1HEX.getVblen(d,a);return c+b*2};ASN1HEX.getChildIdx=function(e,f){var j=ASN1HEX;var g=new Array();var i=j.getVidx(e,f);if(e.substr(f,2)==\"03\"){g.push(i+2)}else{g.push(i)}var l=j.getVblen(e,f);var c=i;var d=0;while(1){var b=j.getNextSiblingIdx(e,c);if(b==null||(b-i>=(l*2))){break}if(d>=200){break}g.push(b);c=b;d++}return g};ASN1HEX.getNthChildIdx=function(d,b,e){var c=ASN1HEX.getChildIdx(d,b);return c[e]};ASN1HEX.getIdxbyList=function(e,d,c,i){var g=ASN1HEX;var f,b;if(c.length==0){if(i!==undefined){if(e.substr(d,2)!==i){throw\"checking tag doesn't match: \"+e.substr(d,2)+\"!=\"+i}}return d}f=c.shift();b=g.getChildIdx(e,d);return g.getIdxbyList(e,b[f],c,i)};ASN1HEX.getTLVbyList=function(d,c,b,f){var e=ASN1HEX;var a=e.getIdxbyList(d,c,b);if(a===undefined){throw\"can't find nthList object\"}if(f!==undefined){if(d.substr(a,2)!=f){throw\"checking tag doesn't match: \"+d.substr(a,2)+\"!=\"+f}}return e.getTLV(d,a)};ASN1HEX.getVbyList=function(e,c,b,g,i){var f=ASN1HEX;var a,d;a=f.getIdxbyList(e,c,b,g);if(a===undefined){throw\"can't find nthList object\"}d=f.getV(e,a);if(i===true){d=d.substr(2)}return d};ASN1HEX.hextooidstr=function(e){var h=function(b,a){if(b.length>=a){return b}return new Array(a-b.length+1).join(\"0\")+b};var l=[];var o=e.substr(0,2);var f=parseInt(o,16);l[0]=new String(Math.floor(f/40));l[1]=new String(f%40);var m=e.substr(2);var k=[];for(var g=0;g<m.length/2;g++){k.push(parseInt(m.substr(g*2,2),16))}var j=[];var d=\"\";for(var g=0;g<k.length;g++){if(k[g]&128){d=d+h((k[g]&127).toString(2),7)}else{d=d+h((k[g]&127).toString(2),7);j.push(new String(parseInt(d,2)));d=\"\"}}var n=l.join(\".\");if(j.length>0){n=n+\".\"+j.join(\".\")}return n};ASN1HEX.dump=function(t,c,l,g){var p=ASN1HEX;var j=p.getV;var y=p.dump;var w=p.getChildIdx;var e=t;if(t instanceof KJUR.asn1.ASN1Object){e=t.getEncodedHex()}var q=function(A,i){if(A.length<=i*2){return A}else{var v=A.substr(0,i)+\"..(total \"+A.length/2+\"bytes)..\"+A.substr(A.length-i,i);return v}};if(c===undefined){c={ommit_long_octet:32}}if(l===undefined){l=0}if(g===undefined){g=\"\"}var x=c.ommit_long_octet;if(e.substr(l,2)==\"01\"){var h=j(e,l);if(h==\"00\"){return g+\"BOOLEAN FALSE\\n\"}else{return g+\"BOOLEAN TRUE\\n\"}}if(e.substr(l,2)==\"02\"){var h=j(e,l);return g+\"INTEGER \"+q(h,x)+\"\\n\"}if(e.substr(l,2)==\"03\"){var h=j(e,l);return g+\"BITSTRING \"+q(h,x)+\"\\n\"}if(e.substr(l,2)==\"04\"){var h=j(e,l);if(p.isASN1HEX(h)){var k=g+\"OCTETSTRING, encapsulates\\n\";k=k+y(h,c,0,g+\"  \");return k}else{return g+\"OCTETSTRING \"+q(h,x)+\"\\n\"}}if(e.substr(l,2)==\"05\"){return g+\"NULL\\n\"}if(e.substr(l,2)==\"06\"){var m=j(e,l);var a=KJUR.asn1.ASN1Util.oidHexToInt(m);var o=KJUR.asn1.x509.OID.oid2name(a);var b=a.replace(/\\./g,\" \");if(o!=\"\"){return g+\"ObjectIdentifier \"+o+\" (\"+b+\")\\n\"}else{return g+\"ObjectIdentifier (\"+b+\")\\n\"}}if(e.substr(l,2)==\"0c\"){return g+\"UTF8String '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"13\"){return g+\"PrintableString '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"14\"){return g+\"TeletexString '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"16\"){return g+\"IA5String '\"+hextoutf8(j(e,l))+\"'\\n\"}if(e.substr(l,2)==\"17\"){return g+\"UTCTime \"+hextoutf8(j(e,l))+\"\\n\"}if(e.substr(l,2)==\"18\"){return g+\"GeneralizedTime \"+hextoutf8(j(e,l))+\"\\n\"}if(e.substr(l,2)==\"30\"){if(e.substr(l,4)==\"3000\"){return g+\"SEQUENCE {}\\n\"}var k=g+\"SEQUENCE\\n\";var d=w(e,l);var f=c;if((d.length==2||d.length==3)&&e.substr(d[0],2)==\"06\"&&e.substr(d[d.length-1],2)==\"04\"){var o=p.oidname(j(e,d[0]));var r=JSON.parse(JSON.stringify(c));r.x509ExtName=o;f=r}for(var u=0;u<d.length;u++){k=k+y(e,f,d[u],g+\"  \")}return k}if(e.substr(l,2)==\"31\"){var k=g+\"SET\\n\";var d=w(e,l);for(var u=0;u<d.length;u++){k=k+y(e,c,d[u],g+\"  \")}return k}var z=parseInt(e.substr(l,2),16);if((z&128)!=0){var n=z&31;if((z&32)!=0){var k=g+\"[\"+n+\"]\\n\";var d=w(e,l);for(var u=0;u<d.length;u++){k=k+y(e,c,d[u],g+\"  \")}return k}else{var h=j(e,l);if(h.substr(0,8)==\"68747470\"){h=hextoutf8(h)}if(c.x509ExtName===\"subjectAltName\"&&n==2){h=hextoutf8(h)}var k=g+\"[\"+n+\"] \"+h+\"\\n\";return k}}return g+\"UNKNOWN(\"+e.substr(l,2)+\") \"+j(e,l)+\"\\n\"};ASN1HEX.isASN1HEX=function(e){var d=ASN1HEX;if(e.length%2==1){return false}var c=d.getVblen(e,0);var b=e.substr(0,2);var f=d.getL(e,0);var a=e.length-b.length-f.length;if(a==c*2){return true}return false};ASN1HEX.oidname=function(a){var c=KJUR.asn1;if(KJUR.lang.String.isHex(a)){a=c.ASN1Util.oidHexToInt(a)}var b=c.x509.OID.oid2name(a);if(b===\"\"){b=a}return b};\nvar KJUR;if(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.lang==\"undefined\"||!KJUR.lang){KJUR.lang={}}KJUR.lang.String=function(){};function Base64x(){}function stoBA(d){var b=new Array();for(var c=0;c<d.length;c++){b[c]=d.charCodeAt(c)}return b}function BAtos(b){var d=\"\";for(var c=0;c<b.length;c++){d=d+String.fromCharCode(b[c])}return d}function BAtohex(b){var e=\"\";for(var d=0;d<b.length;d++){var c=b[d].toString(16);if(c.length==1){c=\"0\"+c}e=e+c}return e}function stohex(a){return BAtohex(stoBA(a))}function stob64(a){return hex2b64(stohex(a))}function stob64u(a){return b64tob64u(hex2b64(stohex(a)))}function b64utos(a){return BAtos(b64toBA(b64utob64(a)))}function b64tob64u(a){a=a.replace(/\\=/g,\"\");a=a.replace(/\\+/g,\"-\");a=a.replace(/\\//g,\"_\");return a}function b64utob64(a){if(a.length%4==2){a=a+\"==\"}else{if(a.length%4==3){a=a+\"=\"}}a=a.replace(/-/g,\"+\");a=a.replace(/_/g,\"/\");return a}function hextob64u(a){if(a.length%2==1){a=\"0\"+a}return b64tob64u(hex2b64(a))}function b64utohex(a){return b64tohex(b64utob64(a))}var utf8tob64u,b64utoutf8;if(typeof Buffer===\"function\"){utf8tob64u=function(a){return b64tob64u(new Buffer(a,\"utf8\").toString(\"base64\"))};b64utoutf8=function(a){return new Buffer(b64utob64(a),\"base64\").toString(\"utf8\")}}else{utf8tob64u=function(a){return hextob64u(uricmptohex(encodeURIComponentAll(a)))};b64utoutf8=function(a){return decodeURIComponent(hextouricmp(b64utohex(a)))}}function utf8tob64(a){return hex2b64(uricmptohex(encodeURIComponentAll(a)))}function b64toutf8(a){return decodeURIComponent(hextouricmp(b64tohex(a)))}function utf8tohex(a){return uricmptohex(encodeURIComponentAll(a))}function hextoutf8(a){return decodeURIComponent(hextouricmp(a))}function hextorstr(c){var b=\"\";for(var a=0;a<c.length-1;a+=2){b+=String.fromCharCode(parseInt(c.substr(a,2),16))}return b}function rstrtohex(c){var a=\"\";for(var b=0;b<c.length;b++){a+=(\"0\"+c.charCodeAt(b).toString(16)).slice(-2)}return a}function hextob64(a){return hex2b64(a)}function hextob64nl(b){var a=hextob64(b);var c=a.replace(/(.{64})/g,\"$1\\r\\n\");c=c.replace(/\\r\\n$/,\"\");return c}function b64nltohex(b){var a=b.replace(/[^0-9A-Za-z\\/+=]*/g,\"\");var c=b64tohex(a);return c}function hextopem(a,b){var c=hextob64nl(a);return\"-----BEGIN \"+b+\"-----\\r\\n\"+c+\"\\r\\n-----END \"+b+\"-----\\r\\n\"}function pemtohex(a,b){if(a.indexOf(\"-----BEGIN \")==-1){throw\"can't find PEM header: \"+b}if(b!==undefined){a=a.replace(\"-----BEGIN \"+b+\"-----\",\"\");a=a.replace(\"-----END \"+b+\"-----\",\"\")}else{a=a.replace(/-----BEGIN [^-]+-----/,\"\");a=a.replace(/-----END [^-]+-----/,\"\")}return b64nltohex(a)}function hextoArrayBuffer(d){if(d.length%2!=0){throw\"input is not even length\"}if(d.match(/^[0-9A-Fa-f]+$/)==null){throw\"input is not hexadecimal\"}var b=new ArrayBuffer(d.length/2);var a=new DataView(b);for(var c=0;c<d.length/2;c++){a.setUint8(c,parseInt(d.substr(c*2,2),16))}return b}function ArrayBuffertohex(b){var d=\"\";var a=new DataView(b);for(var c=0;c<b.byteLength;c++){d+=(\"00\"+a.getUint8(c).toString(16)).slice(-2)}return d}function zulutomsec(n){var l,j,m,e,f,i,b,k;var a,h,g,c;c=n.match(/^(\\d{2}|\\d{4})(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(\\d\\d)(|\\.\\d+)Z$/);if(c){a=c[1];l=parseInt(a);if(a.length===2){if(50<=l&&l<100){l=1900+l}else{if(0<=l&&l<50){l=2000+l}}}j=parseInt(c[2])-1;m=parseInt(c[3]);e=parseInt(c[4]);f=parseInt(c[5]);i=parseInt(c[6]);b=0;h=c[7];if(h!==\"\"){g=(h.substr(1)+\"00\").substr(0,3);b=parseInt(g)}return Date.UTC(l,j,m,e,f,i,b)}throw\"unsupported zulu format: \"+n}function zulutosec(a){var b=zulutomsec(a);return ~~(b/1000)}function zulutodate(a){return new Date(zulutomsec(a))}function datetozulu(g,e,f){var b;var a=g.getUTCFullYear();if(e){if(a<1950||2049<a){throw\"not proper year for UTCTime: \"+a}b=(\"\"+a).slice(-2)}else{b=(\"000\"+a).slice(-4)}b+=(\"0\"+(g.getUTCMonth()+1)).slice(-2);b+=(\"0\"+g.getUTCDate()).slice(-2);b+=(\"0\"+g.getUTCHours()).slice(-2);b+=(\"0\"+g.getUTCMinutes()).slice(-2);b+=(\"0\"+g.getUTCSeconds()).slice(-2);if(f){var c=g.getUTCMilliseconds();if(c!==0){c=(\"00\"+c).slice(-3);c=c.replace(/0+$/g,\"\");b+=\".\"+c}}b+=\"Z\";return b}function uricmptohex(a){return a.replace(/%/g,\"\")}function hextouricmp(a){return a.replace(/(..)/g,\"%$1\")}function ipv6tohex(g){var b=\"malformed IPv6 address\";if(!g.match(/^[0-9A-Fa-f:]+$/)){throw b}g=g.toLowerCase();var d=g.split(\":\").length-1;if(d<2){throw b}var e=\":\".repeat(7-d+2);g=g.replace(\"::\",e);var c=g.split(\":\");if(c.length!=8){throw b}for(var f=0;f<8;f++){c[f]=(\"0000\"+c[f]).slice(-4)}return c.join(\"\")}function hextoipv6(e){if(!e.match(/^[0-9A-Fa-f]{32}$/)){throw\"malformed IPv6 address octet\"}e=e.toLowerCase();var b=e.match(/.{1,4}/g);for(var d=0;d<8;d++){b[d]=b[d].replace(/^0+/,\"\");if(b[d]==\"\"){b[d]=\"0\"}}e=\":\"+b.join(\":\")+\":\";var c=e.match(/:(0:){2,}/g);if(c===null){return e.slice(1,-1)}var f=\"\";for(var d=0;d<c.length;d++){if(c[d].length>f.length){f=c[d]}}e=e.replace(f,\"::\");return e.slice(1,-1)}function hextoip(b){var d=\"malformed hex value\";if(!b.match(/^([0-9A-Fa-f][0-9A-Fa-f]){1,}$/)){throw d}if(b.length==8){var c;try{c=parseInt(b.substr(0,2),16)+\".\"+parseInt(b.substr(2,2),16)+\".\"+parseInt(b.substr(4,2),16)+\".\"+parseInt(b.substr(6,2),16);return c}catch(a){throw d}}else{if(b.length==32){return hextoipv6(b)}else{return b}}}function iptohex(f){var j=\"malformed IP address\";f=f.toLowerCase(f);if(f.match(/^[0-9.]+$/)){var b=f.split(\".\");if(b.length!==4){throw j}var g=\"\";try{for(var e=0;e<4;e++){var h=parseInt(b[e]);g+=(\"0\"+h.toString(16)).slice(-2)}return g}catch(c){throw j}}else{if(f.match(/^[0-9a-f:]+$/)&&f.indexOf(\":\")!==-1){return ipv6tohex(f)}else{throw j}}}function encodeURIComponentAll(a){var d=encodeURIComponent(a);var b=\"\";for(var c=0;c<d.length;c++){if(d[c]==\"%\"){b=b+d.substr(c,3);c=c+2}else{b=b+\"%\"+stohex(d[c])}}return b}function newline_toUnix(a){a=a.replace(/\\r\\n/mg,\"\\n\");return a}function newline_toDos(a){a=a.replace(/\\r\\n/mg,\"\\n\");a=a.replace(/\\n/mg,\"\\r\\n\");return a}KJUR.lang.String.isInteger=function(a){if(a.match(/^[0-9]+$/)){return true}else{if(a.match(/^-[0-9]+$/)){return true}else{return false}}};KJUR.lang.String.isHex=function(a){if(a.length%2==0&&(a.match(/^[0-9a-f]+$/)||a.match(/^[0-9A-F]+$/))){return true}else{return false}};KJUR.lang.String.isBase64=function(a){a=a.replace(/\\s+/g,\"\");if(a.match(/^[0-9A-Za-z+\\/]+={0,3}$/)&&a.length%4==0){return true}else{return false}};KJUR.lang.String.isBase64URL=function(a){if(a.match(/[+/=]/)){return false}a=b64utob64(a);return KJUR.lang.String.isBase64(a)};KJUR.lang.String.isIntegerArray=function(a){a=a.replace(/\\s+/g,\"\");if(a.match(/^\\[[0-9,]+\\]$/)){return true}else{return false}};function hextoposhex(a){if(a.length%2==1){return\"0\"+a}if(a.substr(0,1)>\"7\"){return\"00\"+a}return a}function intarystrtohex(b){b=b.replace(/^\\s*\\[\\s*/,\"\");b=b.replace(/\\s*\\]\\s*$/,\"\");b=b.replace(/\\s*/g,\"\");try{var c=b.split(/,/).map(function(g,e,h){var f=parseInt(g);if(f<0||255<f){throw\"integer not in range 0-255\"}var d=(\"00\"+f.toString(16)).slice(-2);return d}).join(\"\");return c}catch(a){throw\"malformed integer array string: \"+a}}var strdiffidx=function(c,a){var d=c.length;if(c.length>a.length){d=a.length}for(var b=0;b<d;b++){if(c.charCodeAt(b)!=a.charCodeAt(b)){return b}}if(c.length!=a.length){return d}return -1};\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.crypto==\"undefined\"||!KJUR.crypto){KJUR.crypto={}}KJUR.crypto.Util=new function(){this.DIGESTINFOHEAD={sha1:\"3021300906052b0e03021a05000414\",sha224:\"302d300d06096086480165030402040500041c\",sha256:\"3031300d060960864801650304020105000420\",sha384:\"3041300d060960864801650304020205000430\",sha512:\"3051300d060960864801650304020305000440\",md2:\"3020300c06082a864886f70d020205000410\",md5:\"3020300c06082a864886f70d020505000410\",ripemd160:\"3021300906052b2403020105000414\",};this.DEFAULTPROVIDER={md5:\"cryptojs\",sha1:\"cryptojs\",sha224:\"cryptojs\",sha256:\"cryptojs\",sha384:\"cryptojs\",sha512:\"cryptojs\",ripemd160:\"cryptojs\",hmacmd5:\"cryptojs\",hmacsha1:\"cryptojs\",hmacsha224:\"cryptojs\",hmacsha256:\"cryptojs\",hmacsha384:\"cryptojs\",hmacsha512:\"cryptojs\",hmacripemd160:\"cryptojs\",MD5withRSA:\"cryptojs/jsrsa\",SHA1withRSA:\"cryptojs/jsrsa\",SHA224withRSA:\"cryptojs/jsrsa\",SHA256withRSA:\"cryptojs/jsrsa\",SHA384withRSA:\"cryptojs/jsrsa\",SHA512withRSA:\"cryptojs/jsrsa\",RIPEMD160withRSA:\"cryptojs/jsrsa\",MD5withECDSA:\"cryptojs/jsrsa\",SHA1withECDSA:\"cryptojs/jsrsa\",SHA224withECDSA:\"cryptojs/jsrsa\",SHA256withECDSA:\"cryptojs/jsrsa\",SHA384withECDSA:\"cryptojs/jsrsa\",SHA512withECDSA:\"cryptojs/jsrsa\",RIPEMD160withECDSA:\"cryptojs/jsrsa\",SHA1withDSA:\"cryptojs/jsrsa\",SHA224withDSA:\"cryptojs/jsrsa\",SHA256withDSA:\"cryptojs/jsrsa\",MD5withRSAandMGF1:\"cryptojs/jsrsa\",SHA1withRSAandMGF1:\"cryptojs/jsrsa\",SHA224withRSAandMGF1:\"cryptojs/jsrsa\",SHA256withRSAandMGF1:\"cryptojs/jsrsa\",SHA384withRSAandMGF1:\"cryptojs/jsrsa\",SHA512withRSAandMGF1:\"cryptojs/jsrsa\",RIPEMD160withRSAandMGF1:\"cryptojs/jsrsa\",};this.CRYPTOJSMESSAGEDIGESTNAME={md5:CryptoJS.algo.MD5,sha1:CryptoJS.algo.SHA1,sha224:CryptoJS.algo.SHA224,sha256:CryptoJS.algo.SHA256,sha384:CryptoJS.algo.SHA384,sha512:CryptoJS.algo.SHA512,ripemd160:CryptoJS.algo.RIPEMD160};this.getDigestInfoHex=function(a,b){if(typeof this.DIGESTINFOHEAD[b]==\"undefined\"){throw\"alg not supported in Util.DIGESTINFOHEAD: \"+b}return this.DIGESTINFOHEAD[b]+a};this.getPaddedDigestInfoHex=function(h,a,j){var c=this.getDigestInfoHex(h,a);var d=j/4;if(c.length+22>d){throw\"key is too short for SigAlg: keylen=\"+j+\",\"+a}var b=\"0001\";var k=\"00\"+c;var g=\"\";var l=d-b.length-k.length;for(var f=0;f<l;f+=2){g+=\"ff\"}var e=b+g+k;return e};this.hashString=function(a,c){var b=new KJUR.crypto.MessageDigest({alg:c});return b.digestString(a)};this.hashHex=function(b,c){var a=new KJUR.crypto.MessageDigest({alg:c});return a.digestHex(b)};this.sha1=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha1\",prov:\"cryptojs\"});return b.digestString(a)};this.sha256=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha256\",prov:\"cryptojs\"});return b.digestString(a)};this.sha256Hex=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha256\",prov:\"cryptojs\"});return b.digestHex(a)};this.sha512=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha512\",prov:\"cryptojs\"});return b.digestString(a)};this.sha512Hex=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"sha512\",prov:\"cryptojs\"});return b.digestHex(a)}};KJUR.crypto.Util.md5=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"md5\",prov:\"cryptojs\"});return b.digestString(a)};KJUR.crypto.Util.ripemd160=function(a){var b=new KJUR.crypto.MessageDigest({alg:\"ripemd160\",prov:\"cryptojs\"});return b.digestString(a)};KJUR.crypto.Util.SECURERANDOMGEN=new SecureRandom();KJUR.crypto.Util.getRandomHexOfNbytes=function(b){var a=new Array(b);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(a);return BAtohex(a)};KJUR.crypto.Util.getRandomBigIntegerOfNbytes=function(a){return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbytes(a),16)};KJUR.crypto.Util.getRandomHexOfNbits=function(d){var c=d%8;var a=(d-c)/8;var b=new Array(a+1);KJUR.crypto.Util.SECURERANDOMGEN.nextBytes(b);b[0]=(((255<<c)&255)^255)&b[0];return BAtohex(b)};KJUR.crypto.Util.getRandomBigIntegerOfNbits=function(a){return new BigInteger(KJUR.crypto.Util.getRandomHexOfNbits(a),16)};KJUR.crypto.Util.getRandomBigIntegerZeroToMax=function(b){var a=b.bitLength();while(1){var c=KJUR.crypto.Util.getRandomBigIntegerOfNbits(a);if(b.compareTo(c)!=-1){return c}}};KJUR.crypto.Util.getRandomBigIntegerMinToMax=function(e,b){var c=e.compareTo(b);if(c==1){throw\"biMin is greater than biMax\"}if(c==0){return e}var a=b.subtract(e);var d=KJUR.crypto.Util.getRandomBigIntegerZeroToMax(a);return d.add(e)};KJUR.crypto.MessageDigest=function(c){var b=null;var a=null;var d=null;this.setAlgAndProvider=function(g,f){g=KJUR.crypto.MessageDigest.getCanonicalAlgName(g);if(g!==null&&f===undefined){f=KJUR.crypto.Util.DEFAULTPROVIDER[g]}if(\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g)!=-1&&f==\"cryptojs\"){try{this.md=KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g].create()}catch(e){throw\"setAlgAndProvider hash alg set fail alg=\"+g+\"/\"+e}this.updateString=function(h){this.md.update(h)};this.updateHex=function(h){var i=CryptoJS.enc.Hex.parse(h);this.md.update(i)};this.digest=function(){var h=this.md.finalize();return h.toString(CryptoJS.enc.Hex)};this.digestString=function(h){this.updateString(h);return this.digest()};this.digestHex=function(h){this.updateHex(h);return this.digest()}}if(\":sha256:\".indexOf(g)!=-1&&f==\"sjcl\"){try{this.md=new sjcl.hash.sha256()}catch(e){throw\"setAlgAndProvider hash alg set fail alg=\"+g+\"/\"+e}this.updateString=function(h){this.md.update(h)};this.updateHex=function(i){var h=sjcl.codec.hex.toBits(i);this.md.update(h)};this.digest=function(){var h=this.md.finalize();return sjcl.codec.hex.fromBits(h)};this.digestString=function(h){this.updateString(h);return this.digest()};this.digestHex=function(h){this.updateHex(h);return this.digest()}}};this.updateString=function(e){throw\"updateString(str) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.updateHex=function(e){throw\"updateHex(hex) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.digest=function(){throw\"digest() not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.digestString=function(e){throw\"digestString(str) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};this.digestHex=function(e){throw\"digestHex(hex) not supported for this alg/prov: \"+this.algName+\"/\"+this.provName};if(c!==undefined){if(c.alg!==undefined){this.algName=c.alg;if(c.prov===undefined){this.provName=KJUR.crypto.Util.DEFAULTPROVIDER[this.algName]}this.setAlgAndProvider(this.algName,this.provName)}}};KJUR.crypto.MessageDigest.getCanonicalAlgName=function(a){if(typeof a===\"string\"){a=a.toLowerCase();a=a.replace(/-/,\"\")}return a};KJUR.crypto.MessageDigest.getHashLength=function(c){var b=KJUR.crypto.MessageDigest;var a=b.getCanonicalAlgName(c);if(b.HASHLENGTH[a]===undefined){throw\"not supported algorithm: \"+c}return b.HASHLENGTH[a]};KJUR.crypto.MessageDigest.HASHLENGTH={md5:16,sha1:20,sha224:28,sha256:32,sha384:48,sha512:64,ripemd160:20};KJUR.crypto.Mac=function(d){var f=null;var c=null;var a=null;var e=null;var b=null;this.setAlgAndProvider=function(k,i){k=k.toLowerCase();if(k==null){k=\"hmacsha1\"}k=k.toLowerCase();if(k.substr(0,4)!=\"hmac\"){throw\"setAlgAndProvider unsupported HMAC alg: \"+k}if(i===undefined){i=KJUR.crypto.Util.DEFAULTPROVIDER[k]}this.algProv=k+\"/\"+i;var g=k.substr(4);if(\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(g)!=-1&&i==\"cryptojs\"){try{var j=KJUR.crypto.Util.CRYPTOJSMESSAGEDIGESTNAME[g];this.mac=CryptoJS.algo.HMAC.create(j,this.pass)}catch(h){throw\"setAlgAndProvider hash alg set fail hashAlg=\"+g+\"/\"+h}this.updateString=function(l){this.mac.update(l)};this.updateHex=function(l){var m=CryptoJS.enc.Hex.parse(l);this.mac.update(m)};this.doFinal=function(){var l=this.mac.finalize();return l.toString(CryptoJS.enc.Hex)};this.doFinalString=function(l){this.updateString(l);return this.doFinal()};this.doFinalHex=function(l){this.updateHex(l);return this.doFinal()}}};this.updateString=function(g){throw\"updateString(str) not supported for this alg/prov: \"+this.algProv};this.updateHex=function(g){throw\"updateHex(hex) not supported for this alg/prov: \"+this.algProv};this.doFinal=function(){throw\"digest() not supported for this alg/prov: \"+this.algProv};this.doFinalString=function(g){throw\"digestString(str) not supported for this alg/prov: \"+this.algProv};this.doFinalHex=function(g){throw\"digestHex(hex) not supported for this alg/prov: \"+this.algProv};this.setPassword=function(h){if(typeof h==\"string\"){var g=h;if(h.length%2==1||!h.match(/^[0-9A-Fa-f]+$/)){g=rstrtohex(h)}this.pass=CryptoJS.enc.Hex.parse(g);return}if(typeof h!=\"object\"){throw\"KJUR.crypto.Mac unsupported password type: \"+h}var g=null;if(h.hex!==undefined){if(h.hex.length%2!=0||!h.hex.match(/^[0-9A-Fa-f]+$/)){throw\"Mac: wrong hex password: \"+h.hex}g=h.hex}if(h.utf8!==undefined){g=utf8tohex(h.utf8)}if(h.rstr!==undefined){g=rstrtohex(h.rstr)}if(h.b64!==undefined){g=b64tohex(h.b64)}if(h.b64u!==undefined){g=b64utohex(h.b64u)}if(g==null){throw\"KJUR.crypto.Mac unsupported password type: \"+h}this.pass=CryptoJS.enc.Hex.parse(g)};if(d!==undefined){if(d.pass!==undefined){this.setPassword(d.pass)}if(d.alg!==undefined){this.algName=d.alg;if(d.prov===undefined){this.provName=KJUR.crypto.Util.DEFAULTPROVIDER[this.algName]}this.setAlgAndProvider(this.algName,this.provName)}}};KJUR.crypto.Signature=function(o){var q=null;var n=null;var r=null;var c=null;var l=null;var d=null;var k=null;var h=null;var p=null;var e=null;var b=-1;var g=null;var j=null;var a=null;var i=null;var f=null;this._setAlgNames=function(){var s=this.algName.match(/^(.+)with(.+)$/);if(s){this.mdAlgName=s[1].toLowerCase();this.pubkeyAlgName=s[2].toLowerCase()}};this._zeroPaddingOfSignature=function(x,w){var v=\"\";var t=w/4-x.length;for(var u=0;u<t;u++){v=v+\"0\"}return v+x};this.setAlgAndProvider=function(u,t){this._setAlgNames();if(t!=\"cryptojs/jsrsa\"){throw\"provider not supported: \"+t}if(\":md5:sha1:sha224:sha256:sha384:sha512:ripemd160:\".indexOf(this.mdAlgName)!=-1){try{this.md=new KJUR.crypto.MessageDigest({alg:this.mdAlgName})}catch(s){throw\"setAlgAndProvider hash alg set fail alg=\"+this.mdAlgName+\"/\"+s}this.init=function(w,x){var y=null;try{if(x===undefined){y=KEYUTIL.getKey(w)}else{y=KEYUTIL.getKey(w,x)}}catch(v){throw\"init failed:\"+v}if(y.isPrivate===true){this.prvKey=y;this.state=\"SIGN\"}else{if(y.isPublic===true){this.pubKey=y;this.state=\"VERIFY\"}else{throw\"init failed.:\"+y}}};this.updateString=function(v){this.md.updateString(v)};this.updateHex=function(v){this.md.updateHex(v)};this.sign=function(){this.sHashHex=this.md.digest();if(typeof this.ecprvhex!=\"undefined\"&&typeof this.eccurvename!=\"undefined\"){var v=new KJUR.crypto.ECDSA({curve:this.eccurvename});this.hSign=v.signHex(this.sHashHex,this.ecprvhex)}else{if(this.prvKey instanceof RSAKey&&this.pubkeyAlgName===\"rsaandmgf1\"){this.hSign=this.prvKey.signWithMessageHashPSS(this.sHashHex,this.mdAlgName,this.pssSaltLen)}else{if(this.prvKey instanceof RSAKey&&this.pubkeyAlgName===\"rsa\"){this.hSign=this.prvKey.signWithMessageHash(this.sHashHex,this.mdAlgName)}else{if(this.prvKey instanceof KJUR.crypto.ECDSA){this.hSign=this.prvKey.signWithMessageHash(this.sHashHex)}else{if(this.prvKey instanceof KJUR.crypto.DSA){this.hSign=this.prvKey.signWithMessageHash(this.sHashHex)}else{throw\"Signature: unsupported private key alg: \"+this.pubkeyAlgName}}}}}return this.hSign};this.signString=function(v){this.updateString(v);return this.sign()};this.signHex=function(v){this.updateHex(v);return this.sign()};this.verify=function(v){this.sHashHex=this.md.digest();if(typeof this.ecpubhex!=\"undefined\"&&typeof this.eccurvename!=\"undefined\"){var w=new KJUR.crypto.ECDSA({curve:this.eccurvename});return w.verifyHex(this.sHashHex,v,this.ecpubhex)}else{if(this.pubKey instanceof RSAKey&&this.pubkeyAlgName===\"rsaandmgf1\"){return this.pubKey.verifyWithMessageHashPSS(this.sHashHex,v,this.mdAlgName,this.pssSaltLen)}else{if(this.pubKey instanceof RSAKey&&this.pubkeyAlgName===\"rsa\"){return this.pubKey.verifyWithMessageHash(this.sHashHex,v)}else{if(KJUR.crypto.ECDSA!==undefined&&this.pubKey instanceof KJUR.crypto.ECDSA){return this.pubKey.verifyWithMessageHash(this.sHashHex,v)}else{if(KJUR.crypto.DSA!==undefined&&this.pubKey instanceof KJUR.crypto.DSA){return this.pubKey.verifyWithMessageHash(this.sHashHex,v)}else{throw\"Signature: unsupported public key alg: \"+this.pubkeyAlgName}}}}}}}};this.init=function(s,t){throw\"init(key, pass) not supported for this alg:prov=\"+this.algProvName};this.updateString=function(s){throw\"updateString(str) not supported for this alg:prov=\"+this.algProvName};this.updateHex=function(s){throw\"updateHex(hex) not supported for this alg:prov=\"+this.algProvName};this.sign=function(){throw\"sign() not supported for this alg:prov=\"+this.algProvName};this.signString=function(s){throw\"digestString(str) not supported for this alg:prov=\"+this.algProvName};this.signHex=function(s){throw\"digestHex(hex) not supported for this alg:prov=\"+this.algProvName};this.verify=function(s){throw\"verify(hSigVal) not supported for this alg:prov=\"+this.algProvName};this.initParams=o;if(o!==undefined){if(o.alg!==undefined){this.algName=o.alg;if(o.prov===undefined){this.provName=KJUR.crypto.Util.DEFAULTPROVIDER[this.algName]}else{this.provName=o.prov}this.algProvName=this.algName+\":\"+this.provName;this.setAlgAndProvider(this.algName,this.provName);this._setAlgNames()}if(o.psssaltlen!==undefined){this.pssSaltLen=o.psssaltlen}if(o.prvkeypem!==undefined){if(o.prvkeypas!==undefined){throw\"both prvkeypem and prvkeypas parameters not supported\"}else{try{var q=KEYUTIL.getKey(o.prvkeypem);this.init(q)}catch(m){throw\"fatal error to load pem private key: \"+m}}}}};KJUR.crypto.Cipher=function(a){};KJUR.crypto.Cipher.encrypt=function(e,f,d){if(f instanceof RSAKey&&f.isPublic){var c=KJUR.crypto.Cipher.getAlgByKeyAndName(f,d);if(c===\"RSA\"){return f.encrypt(e)}if(c===\"RSAOAEP\"){return f.encryptOAEP(e,\"sha1\")}var b=c.match(/^RSAOAEP(\\d+)$/);if(b!==null){return f.encryptOAEP(e,\"sha\"+b[1])}throw\"Cipher.encrypt: unsupported algorithm for RSAKey: \"+d}else{throw\"Cipher.encrypt: unsupported key or algorithm\"}};KJUR.crypto.Cipher.decrypt=function(e,f,d){if(f instanceof RSAKey&&f.isPrivate){var c=KJUR.crypto.Cipher.getAlgByKeyAndName(f,d);if(c===\"RSA\"){return f.decrypt(e)}if(c===\"RSAOAEP\"){return f.decryptOAEP(e,\"sha1\")}var b=c.match(/^RSAOAEP(\\d+)$/);if(b!==null){return f.decryptOAEP(e,\"sha\"+b[1])}throw\"Cipher.decrypt: unsupported algorithm for RSAKey: \"+d}else{throw\"Cipher.decrypt: unsupported key or algorithm\"}};KJUR.crypto.Cipher.getAlgByKeyAndName=function(b,a){if(b instanceof RSAKey){if(\":RSA:RSAOAEP:RSAOAEP224:RSAOAEP256:RSAOAEP384:RSAOAEP512:\".indexOf(a)!=-1){return a}if(a===null||a===undefined){return\"RSA\"}throw\"getAlgByKeyAndName: not supported algorithm name for RSAKey: \"+a}throw\"getAlgByKeyAndName: not supported algorithm name: \"+a};KJUR.crypto.OID=new function(){this.oidhex2name={\"2a864886f70d010101\":\"rsaEncryption\",\"2a8648ce3d0201\":\"ecPublicKey\",\"2a8648ce380401\":\"dsa\",\"2a8648ce3d030107\":\"secp256r1\",\"2b8104001f\":\"secp192k1\",\"2b81040021\":\"secp224r1\",\"2b8104000a\":\"secp256k1\",\"2b81040023\":\"secp521r1\",\"2b81040022\":\"secp384r1\",\"2a8648ce380403\":\"SHA1withDSA\",\"608648016503040301\":\"SHA224withDSA\",\"608648016503040302\":\"SHA256withDSA\",}};\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.crypto==\"undefined\"||!KJUR.crypto){KJUR.crypto={}}KJUR.crypto.ECDSA=function(h){var e=\"secp256r1\";var g=null;var b=null;var f=null;var a=new SecureRandom();var d=null;this.type=\"EC\";this.isPrivate=false;this.isPublic=false;function c(s,o,r,n){var j=Math.max(o.bitLength(),n.bitLength());var t=s.add2D(r);var q=s.curve.getInfinity();for(var p=j-1;p>=0;--p){q=q.twice2D();q.z=BigInteger.ONE;if(o.testBit(p)){if(n.testBit(p)){q=q.add2D(t)}else{q=q.add2D(s)}}else{if(n.testBit(p)){q=q.add2D(r)}}}return q}this.getBigRandom=function(i){return new BigInteger(i.bitLength(),a).mod(i.subtract(BigInteger.ONE)).add(BigInteger.ONE)};this.setNamedCurve=function(i){this.ecparams=KJUR.crypto.ECParameterDB.getByName(i);this.prvKeyHex=null;this.pubKeyHex=null;this.curveName=i};this.setPrivateKeyHex=function(i){this.isPrivate=true;this.prvKeyHex=i};this.setPublicKeyHex=function(i){this.isPublic=true;this.pubKeyHex=i};this.getPublicKeyXYHex=function(){var k=this.pubKeyHex;if(k.substr(0,2)!==\"04\"){throw\"this method supports uncompressed format(04) only\"}var j=this.ecparams.keylen/4;if(k.length!==2+j*2){throw\"malformed public key hex length\"}var i={};i.x=k.substr(2,j);i.y=k.substr(2+j);return i};this.getShortNISTPCurveName=function(){var i=this.curveName;if(i===\"secp256r1\"||i===\"NIST P-256\"||i===\"P-256\"||i===\"prime256v1\"){return\"P-256\"}if(i===\"secp384r1\"||i===\"NIST P-384\"||i===\"P-384\"){return\"P-384\"}return null};this.generateKeyPairHex=function(){var k=this.ecparams.n;var n=this.getBigRandom(k);var l=this.ecparams.G.multiply(n);var q=l.getX().toBigInteger();var o=l.getY().toBigInteger();var i=this.ecparams.keylen/4;var m=(\"0000000000\"+n.toString(16)).slice(-i);var r=(\"0000000000\"+q.toString(16)).slice(-i);var p=(\"0000000000\"+o.toString(16)).slice(-i);var j=\"04\"+r+p;this.setPrivateKeyHex(m);this.setPublicKeyHex(j);return{ecprvhex:m,ecpubhex:j}};this.signWithMessageHash=function(i){return this.signHex(i,this.prvKeyHex)};this.signHex=function(o,j){var t=new BigInteger(j,16);var l=this.ecparams.n;var q=new BigInteger(o,16);do{var m=this.getBigRandom(l);var u=this.ecparams.G;var p=u.multiply(m);var i=p.getX().toBigInteger().mod(l)}while(i.compareTo(BigInteger.ZERO)<=0);var v=m.modInverse(l).multiply(q.add(t.multiply(i))).mod(l);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(i,v)};this.sign=function(m,u){var q=u;var j=this.ecparams.n;var p=BigInteger.fromByteArrayUnsigned(m);do{var l=this.getBigRandom(j);var t=this.ecparams.G;var o=t.multiply(l);var i=o.getX().toBigInteger().mod(j)}while(i.compareTo(BigInteger.ZERO)<=0);var v=l.modInverse(j).multiply(p.add(q.multiply(i))).mod(j);return this.serializeSig(i,v)};this.verifyWithMessageHash=function(j,i){return this.verifyHex(j,i,this.pubKeyHex)};this.verifyHex=function(m,i,p){var l,j;var o=KJUR.crypto.ECDSA.parseSigHex(i);l=o.r;j=o.s;var k;k=ECPointFp.decodeFromHex(this.ecparams.curve,p);var n=new BigInteger(m,16);return this.verifyRaw(n,l,j,k)};this.verify=function(o,p,j){var l,i;if(Bitcoin.Util.isArray(p)){var n=this.parseSig(p);l=n.r;i=n.s}else{if(\"object\"===typeof p&&p.r&&p.s){l=p.r;i=p.s}else{throw\"Invalid value for signature\"}}var k;if(j instanceof ECPointFp){k=j}else{if(Bitcoin.Util.isArray(j)){k=ECPointFp.decodeFrom(this.ecparams.curve,j)}else{throw\"Invalid format for pubkey value, must be byte array or ECPointFp\"}}var m=BigInteger.fromByteArrayUnsigned(o);return this.verifyRaw(m,l,i,k)};this.verifyRaw=function(o,i,w,m){var l=this.ecparams.n;var u=this.ecparams.G;if(i.compareTo(BigInteger.ONE)<0||i.compareTo(l)>=0){return false}if(w.compareTo(BigInteger.ONE)<0||w.compareTo(l)>=0){return false}var p=w.modInverse(l);var k=o.multiply(p).mod(l);var j=i.multiply(p).mod(l);var q=u.multiply(k).add(m.multiply(j));var t=q.getX().toBigInteger().mod(l);return t.equals(i)};this.serializeSig=function(k,j){var l=k.toByteArraySigned();var i=j.toByteArraySigned();var m=[];m.push(2);m.push(l.length);m=m.concat(l);m.push(2);m.push(i.length);m=m.concat(i);m.unshift(m.length);m.unshift(48);return m};this.parseSig=function(n){var m;if(n[0]!=48){throw new Error(\"Signature not a valid DERSequence\")}m=2;if(n[m]!=2){throw new Error(\"First element in signature must be a DERInteger\")}var l=n.slice(m+2,m+2+n[m+1]);m+=2+n[m+1];if(n[m]!=2){throw new Error(\"Second element in signature must be a DERInteger\")}var i=n.slice(m+2,m+2+n[m+1]);m+=2+n[m+1];var k=BigInteger.fromByteArrayUnsigned(l);var j=BigInteger.fromByteArrayUnsigned(i);return{r:k,s:j}};this.parseSigCompact=function(m){if(m.length!==65){throw\"Signature has the wrong length\"}var j=m[0]-27;if(j<0||j>7){throw\"Invalid signature type\"}var o=this.ecparams.n;var l=BigInteger.fromByteArrayUnsigned(m.slice(1,33)).mod(o);var k=BigInteger.fromByteArrayUnsigned(m.slice(33,65)).mod(o);return{r:l,s:k,i:j}};this.readPKCS5PrvKeyHex=function(l){var n=ASN1HEX;var m=KJUR.crypto.ECDSA.getName;var p=n.getVbyList;if(n.isASN1HEX(l)===false){throw\"not ASN.1 hex string\"}var i,k,o;try{i=p(l,0,[2,0],\"06\");k=p(l,0,[1],\"04\");try{o=p(l,0,[3,0],\"03\").substr(2)}catch(j){}}catch(j){throw\"malformed PKCS#1/5 plain ECC private key\"}this.curveName=m(i);if(this.curveName===undefined){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(o);this.setPrivateKeyHex(k);this.isPublic=false};this.readPKCS8PrvKeyHex=function(l){var q=ASN1HEX;var i=KJUR.crypto.ECDSA.getName;var n=q.getVbyList;if(q.isASN1HEX(l)===false){throw\"not ASN.1 hex string\"}var j,p,m,k;try{j=n(l,0,[1,0],\"06\");p=n(l,0,[1,1],\"06\");m=n(l,0,[2,0,1],\"04\");try{k=n(l,0,[2,0,2,0],\"03\").substr(2)}catch(o){}}catch(o){throw\"malformed PKCS#8 plain ECC private key\"}this.curveName=i(p);if(this.curveName===undefined){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(k);this.setPrivateKeyHex(m);this.isPublic=false};this.readPKCS8PubKeyHex=function(l){var n=ASN1HEX;var m=KJUR.crypto.ECDSA.getName;var p=n.getVbyList;if(n.isASN1HEX(l)===false){throw\"not ASN.1 hex string\"}var k,i,o;try{k=p(l,0,[0,0],\"06\");i=p(l,0,[0,1],\"06\");o=p(l,0,[1],\"03\").substr(2)}catch(j){throw\"malformed PKCS#8 ECC public key\"}this.curveName=m(i);if(this.curveName===null){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(o)};this.readCertPubKeyHex=function(k,p){if(p!==5){p=6}var m=ASN1HEX;var l=KJUR.crypto.ECDSA.getName;var o=m.getVbyList;if(m.isASN1HEX(k)===false){throw\"not ASN.1 hex string\"}var i,n;try{i=o(k,0,[0,p,0,1],\"06\");n=o(k,0,[0,p,1],\"03\").substr(2)}catch(j){throw\"malformed X.509 certificate ECC public key\"}this.curveName=l(i);if(this.curveName===null){throw\"unsupported curve name\"}this.setNamedCurve(this.curveName);this.setPublicKeyHex(n)};if(h!==undefined){if(h.curve!==undefined){this.curveName=h.curve}}if(this.curveName===undefined){this.curveName=e}this.setNamedCurve(this.curveName);if(h!==undefined){if(h.prv!==undefined){this.setPrivateKeyHex(h.prv)}if(h.pub!==undefined){this.setPublicKeyHex(h.pub)}}};KJUR.crypto.ECDSA.parseSigHex=function(a){var b=KJUR.crypto.ECDSA.parseSigHexInHexRS(a);var d=new BigInteger(b.r,16);var c=new BigInteger(b.s,16);return{r:d,s:c}};KJUR.crypto.ECDSA.parseSigHexInHexRS=function(f){var j=ASN1HEX;var i=j.getChildIdx;var g=j.getV;if(f.substr(0,2)!=\"30\"){throw\"signature is not a ASN.1 sequence\"}var h=i(f,0);if(h.length!=2){throw\"number of signature ASN.1 sequence elements seem wrong\"}var e=h[0];var d=h[1];if(f.substr(e,2)!=\"02\"){throw\"1st item of sequene of signature is not ASN.1 integer\"}if(f.substr(d,2)!=\"02\"){throw\"2nd item of sequene of signature is not ASN.1 integer\"}var c=g(f,e);var b=g(f,d);return{r:c,s:b}};KJUR.crypto.ECDSA.asn1SigToConcatSig=function(c){var d=KJUR.crypto.ECDSA.parseSigHexInHexRS(c);var b=d.r;var a=d.s;if(b.substr(0,2)==\"00\"&&(b.length%32)==2){b=b.substr(2)}if(a.substr(0,2)==\"00\"&&(a.length%32)==2){a=a.substr(2)}if((b.length%32)==30){b=\"00\"+b}if((a.length%32)==30){a=\"00\"+a}if(b.length%32!=0){throw\"unknown ECDSA sig r length error\"}if(a.length%32!=0){throw\"unknown ECDSA sig s length error\"}return b+a};KJUR.crypto.ECDSA.concatSigToASN1Sig=function(a){if((((a.length/2)*8)%(16*8))!=0){throw\"unknown ECDSA concatinated r-s sig  length error\"}var c=a.substr(0,a.length/2);var b=a.substr(a.length/2);return KJUR.crypto.ECDSA.hexRSSigToASN1Sig(c,b)};KJUR.crypto.ECDSA.hexRSSigToASN1Sig=function(b,a){var d=new BigInteger(b,16);var c=new BigInteger(a,16);return KJUR.crypto.ECDSA.biRSSigToASN1Sig(d,c)};KJUR.crypto.ECDSA.biRSSigToASN1Sig=function(f,d){var c=KJUR.asn1;var b=new c.DERInteger({bigint:f});var a=new c.DERInteger({bigint:d});var e=new c.DERSequence({array:[b,a]});return e.getEncodedHex()};KJUR.crypto.ECDSA.getName=function(a){if(a===\"2a8648ce3d030107\"){return\"secp256r1\"}if(a===\"2b8104000a\"){return\"secp256k1\"}if(a===\"2b81040022\"){return\"secp384r1\"}if(\"|secp256r1|NIST P-256|P-256|prime256v1|\".indexOf(a)!==-1){return\"secp256r1\"}if(\"|secp256k1|\".indexOf(a)!==-1){return\"secp256k1\"}if(\"|secp384r1|NIST P-384|P-384|\".indexOf(a)!==-1){return\"secp384r1\"}return null};\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.crypto==\"undefined\"||!KJUR.crypto){KJUR.crypto={}}KJUR.crypto.ECParameterDB=new function(){var b={};var c={};function a(d){return new BigInteger(d,16)}this.getByName=function(e){var d=e;if(typeof c[d]!=\"undefined\"){d=c[e]}if(typeof b[d]!=\"undefined\"){return b[d]}throw\"unregistered EC curve name: \"+d};this.regist=function(A,l,o,g,m,e,j,f,k,u,d,x){b[A]={};var s=a(o);var z=a(g);var y=a(m);var t=a(e);var w=a(j);var r=new ECCurveFp(s,z,y);var q=r.decodePointHex(\"04\"+f+k);b[A][\"name\"]=A;b[A][\"keylen\"]=l;b[A][\"curve\"]=r;b[A][\"G\"]=q;b[A][\"n\"]=t;b[A][\"h\"]=w;b[A][\"oid\"]=d;b[A][\"info\"]=x;for(var v=0;v<u.length;v++){c[u[v]]=A}}};KJUR.crypto.ECParameterDB.regist(\"secp128r1\",128,\"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFF\",\"FFFFFFFDFFFFFFFFFFFFFFFFFFFFFFFC\",\"E87579C11079F43DD824993C2CEE5ED3\",\"FFFFFFFE0000000075A30D1B9038A115\",\"1\",\"161FF7528B899B2D0C28607CA52C5B86\",\"CF5AC8395BAFEB13C02DA292DDED7A83\",[],\"\",\"secp128r1 : SECG curve over a 128 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160k1\",160,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73\",\"0\",\"7\",\"0100000000000000000001B8FA16DFAB9ACA16B6B3\",\"1\",\"3B4C382CE37AA192A4019E763036F4F5DD4D7EBB\",\"938CF935318FDCED6BC28286531733C3F03C4FEE\",[],\"\",\"secp160k1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp160r1\",160,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFC\",\"1C97BEFC54BD7A8B65ACF89F81D4D4ADC565FA45\",\"0100000000000000000001F4C8F927AED3CA752257\",\"1\",\"4A96B5688EF573284664698968C38BB913CBFC82\",\"23A628553168947D59DCC912042351377AC5FB32\",[],\"\",\"secp160r1 : SECG curve over a 160 bit prime field\");KJUR.crypto.ECParameterDB.regist(\"secp192k1\",192,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFEE37\",\"0\",\"3\",\"FFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D\",\"1\",\"DB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D\",\"9B2F2F6D9C5628A7844163D015BE86344082AA88D95E2F9D\",[]);KJUR.crypto.ECParameterDB.regist(\"secp192r1\",192,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC\",\"64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1\",\"FFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831\",\"1\",\"188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012\",\"07192B95FFC8DA78631011ED6B24CDD573F977A11E794811\",[]);KJUR.crypto.ECParameterDB.regist(\"secp224r1\",224,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE\",\"B4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D\",\"1\",\"B70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21\",\"BD376388B5F723FB4C22DFE6CD4375A05A07476444D5819985007E34\",[]);KJUR.crypto.ECParameterDB.regist(\"secp256k1\",256,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F\",\"0\",\"7\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141\",\"1\",\"79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798\",\"483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8\",[]);KJUR.crypto.ECParameterDB.regist(\"secp256r1\",256,\"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF\",\"FFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFC\",\"5AC635D8AA3A93E7B3EBBD55769886BC651D06B0CC53B0F63BCE3C3E27D2604B\",\"FFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551\",\"1\",\"6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296\",\"4FE342E2FE1A7F9B8EE7EB4A7C0F9E162BCE33576B315ECECBB6406837BF51F5\",[\"NIST P-256\",\"P-256\",\"prime256v1\"]);KJUR.crypto.ECParameterDB.regist(\"secp384r1\",384,\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFC\",\"B3312FA7E23EE7E4988E056BE3F82D19181D9C6EFE8141120314088F5013875AC656398D8A2ED19D2A85C8EDD3EC2AEF\",\"FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973\",\"1\",\"AA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7\",\"3617de4a96262c6f5d9e98bf9292dc29f8f41dbd289a147ce9da3113b5f0b8c00a60b1ce1d7e819d7a431d7c90ea0e5f\",[\"NIST P-384\",\"P-384\"]);KJUR.crypto.ECParameterDB.regist(\"secp521r1\",521,\"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF\",\"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC\",\"051953EB9618E1C9A1F929A21A0B68540EEA2DA725B99B315F3B8B489918EF109E156193951EC7E937B1652C0BD3BB1BF073573DF883D2C34F1EF451FD46B503F00\",\"1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA51868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409\",\"1\",\"C6858E06B70404E9CD9E3ECB662395B4429C648139053FB521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66\",\"011839296a789a3bc0045c8a5fb42c7d1bd998f54449579b446817afbd17273e662c97ee72995ef42640c550b9013fad0761353c7086a272c24088be94769fd16650\",[\"NIST P-521\",\"P-521\"]);\nvar KEYUTIL=function(){var d=function(p,r,q){return k(CryptoJS.AES,p,r,q)};var e=function(p,r,q){return k(CryptoJS.TripleDES,p,r,q)};var a=function(p,r,q){return k(CryptoJS.DES,p,r,q)};var k=function(s,x,u,q){var r=CryptoJS.enc.Hex.parse(x);var w=CryptoJS.enc.Hex.parse(u);var p=CryptoJS.enc.Hex.parse(q);var t={};t.key=w;t.iv=p;t.ciphertext=r;var v=s.decrypt(t,w,{iv:p});return CryptoJS.enc.Hex.stringify(v)};var l=function(p,r,q){return g(CryptoJS.AES,p,r,q)};var o=function(p,r,q){return g(CryptoJS.TripleDES,p,r,q)};var f=function(p,r,q){return g(CryptoJS.DES,p,r,q)};var g=function(t,y,v,q){var s=CryptoJS.enc.Hex.parse(y);var x=CryptoJS.enc.Hex.parse(v);var p=CryptoJS.enc.Hex.parse(q);var w=t.encrypt(s,x,{iv:p});var r=CryptoJS.enc.Hex.parse(w.toString());var u=CryptoJS.enc.Base64.stringify(r);return u};var i={\"AES-256-CBC\":{proc:d,eproc:l,keylen:32,ivlen:16},\"AES-192-CBC\":{proc:d,eproc:l,keylen:24,ivlen:16},\"AES-128-CBC\":{proc:d,eproc:l,keylen:16,ivlen:16},\"DES-EDE3-CBC\":{proc:e,eproc:o,keylen:24,ivlen:8},\"DES-CBC\":{proc:a,eproc:f,keylen:8,ivlen:8}};var c=function(p){return i[p][\"proc\"]};var m=function(p){var r=CryptoJS.lib.WordArray.random(p);var q=CryptoJS.enc.Hex.stringify(r);return q};var n=function(v){var w={};var q=v.match(new RegExp(\"DEK-Info: ([^,]+),([0-9A-Fa-f]+)\",\"m\"));if(q){w.cipher=q[1];w.ivsalt=q[2]}var p=v.match(new RegExp(\"-----BEGIN ([A-Z]+) PRIVATE KEY-----\"));if(p){w.type=p[1]}var u=-1;var x=0;if(v.indexOf(\"\\r\\n\\r\\n\")!=-1){u=v.indexOf(\"\\r\\n\\r\\n\");x=2}if(v.indexOf(\"\\n\\n\")!=-1){u=v.indexOf(\"\\n\\n\");x=1}var t=v.indexOf(\"-----END\");if(u!=-1&&t!=-1){var r=v.substring(u+x*2,t-x);r=r.replace(/\\s+/g,\"\");w.data=r}return w};var j=function(q,y,p){var v=p.substring(0,16);var t=CryptoJS.enc.Hex.parse(v);var r=CryptoJS.enc.Utf8.parse(y);var u=i[q][\"keylen\"]+i[q][\"ivlen\"];var x=\"\";var w=null;for(;;){var s=CryptoJS.algo.MD5.create();if(w!=null){s.update(w)}s.update(r);s.update(t);w=s.finalize();x=x+CryptoJS.enc.Hex.stringify(w);if(x.length>=u*2){break}}var z={};z.keyhex=x.substr(0,i[q][\"keylen\"]*2);z.ivhex=x.substr(i[q][\"keylen\"]*2,i[q][\"ivlen\"]*2);return z};var b=function(p,v,r,w){var s=CryptoJS.enc.Base64.parse(p);var q=CryptoJS.enc.Hex.stringify(s);var u=i[v][\"proc\"];var t=u(q,r,w);return t};var h=function(p,s,q,u){var r=i[s][\"eproc\"];var t=r(p,q,u);return t};return{version:\"1.0.0\",parsePKCS5PEM:function(p){return n(p)},getKeyAndUnusedIvByPasscodeAndIvsalt:function(q,p,r){return j(q,p,r)},decryptKeyB64:function(p,r,q,s){return b(p,r,q,s)},getDecryptedKeyHex:function(y,x){var q=n(y);var t=q.type;var r=q.cipher;var p=q.ivsalt;var s=q.data;var w=j(r,x,p);var v=w.keyhex;var u=b(s,r,v,p);return u},getEncryptedPKCS5PEMFromPrvKeyHex:function(x,s,A,t,r){var p=\"\";if(typeof t==\"undefined\"||t==null){t=\"AES-256-CBC\"}if(typeof i[t]==\"undefined\"){throw\"KEYUTIL unsupported algorithm: \"+t}if(typeof r==\"undefined\"||r==null){var v=i[t][\"ivlen\"];var u=m(v);r=u.toUpperCase()}var z=j(t,A,r);var y=z.keyhex;var w=h(s,t,y,r);var q=w.replace(/(.{64})/g,\"$1\\r\\n\");var p=\"-----BEGIN \"+x+\" PRIVATE KEY-----\\r\\n\";p+=\"Proc-Type: 4,ENCRYPTED\\r\\n\";p+=\"DEK-Info: \"+t+\",\"+r+\"\\r\\n\";p+=\"\\r\\n\";p+=q;p+=\"\\r\\n-----END \"+x+\" PRIVATE KEY-----\\r\\n\";return p},parseHexOfEncryptedPKCS8:function(y){var B=ASN1HEX;var z=B.getChildIdx;var w=B.getV;var t={};var r=z(y,0);if(r.length!=2){throw\"malformed format: SEQUENCE(0).items != 2: \"+r.length}t.ciphertext=w(y,r[1]);var A=z(y,r[0]);if(A.length!=2){throw\"malformed format: SEQUENCE(0.0).items != 2: \"+A.length}if(w(y,A[0])!=\"2a864886f70d01050d\"){throw\"this only supports pkcs5PBES2\"}var p=z(y,A[1]);if(A.length!=2){throw\"malformed format: SEQUENCE(0.0.1).items != 2: \"+p.length}var q=z(y,p[1]);if(q.length!=2){throw\"malformed format: SEQUENCE(0.0.1.1).items != 2: \"+q.length}if(w(y,q[0])!=\"2a864886f70d0307\"){throw\"this only supports TripleDES\"}t.encryptionSchemeAlg=\"TripleDES\";t.encryptionSchemeIV=w(y,q[1]);var s=z(y,p[0]);if(s.length!=2){throw\"malformed format: SEQUENCE(0.0.1.0).items != 2: \"+s.length}if(w(y,s[0])!=\"2a864886f70d01050c\"){throw\"this only supports pkcs5PBKDF2\"}var x=z(y,s[1]);if(x.length<2){throw\"malformed format: SEQUENCE(0.0.1.0.1).items < 2: \"+x.length}t.pbkdf2Salt=w(y,x[0]);var u=w(y,x[1]);try{t.pbkdf2Iter=parseInt(u,16)}catch(v){throw\"malformed format pbkdf2Iter: \"+u}return t},getPBKDF2KeyHexFromParam:function(u,p){var t=CryptoJS.enc.Hex.parse(u.pbkdf2Salt);var q=u.pbkdf2Iter;var s=CryptoJS.PBKDF2(p,t,{keySize:192/32,iterations:q});var r=CryptoJS.enc.Hex.stringify(s);return r},_getPlainPKCS8HexFromEncryptedPKCS8PEM:function(x,y){var r=pemtohex(x,\"ENCRYPTED PRIVATE KEY\");var p=this.parseHexOfEncryptedPKCS8(r);var u=KEYUTIL.getPBKDF2KeyHexFromParam(p,y);var v={};v.ciphertext=CryptoJS.enc.Hex.parse(p.ciphertext);var t=CryptoJS.enc.Hex.parse(u);var s=CryptoJS.enc.Hex.parse(p.encryptionSchemeIV);var w=CryptoJS.TripleDES.decrypt(v,t,{iv:s});var q=CryptoJS.enc.Hex.stringify(w);return q},getKeyFromEncryptedPKCS8PEM:function(s,q){var p=this._getPlainPKCS8HexFromEncryptedPKCS8PEM(s,q);var r=this.getKeyFromPlainPrivatePKCS8Hex(p);return r},parsePlainPrivatePKCS8Hex:function(s){var v=ASN1HEX;var u=v.getChildIdx;var t=v.getV;var q={};q.algparam=null;if(s.substr(0,2)!=\"30\"){throw\"malformed plain PKCS8 private key(code:001)\"}var r=u(s,0);if(r.length!=3){throw\"malformed plain PKCS8 private key(code:002)\"}if(s.substr(r[1],2)!=\"30\"){throw\"malformed PKCS8 private key(code:003)\"}var p=u(s,r[1]);if(p.length!=2){throw\"malformed PKCS8 private key(code:004)\"}if(s.substr(p[0],2)!=\"06\"){throw\"malformed PKCS8 private key(code:005)\"}q.algoid=t(s,p[0]);if(s.substr(p[1],2)==\"06\"){q.algparam=t(s,p[1])}if(s.substr(r[2],2)!=\"04\"){throw\"malformed PKCS8 private key(code:006)\"}q.keyidx=v.getVidx(s,r[2]);return q},getKeyFromPlainPrivatePKCS8PEM:function(q){var p=pemtohex(q,\"PRIVATE KEY\");var r=this.getKeyFromPlainPrivatePKCS8Hex(p);return r},getKeyFromPlainPrivatePKCS8Hex:function(p){var q=this.parsePlainPrivatePKCS8Hex(p);var r;if(q.algoid==\"2a864886f70d010101\"){r=new RSAKey()}else{if(q.algoid==\"2a8648ce380401\"){r=new KJUR.crypto.DSA()}else{if(q.algoid==\"2a8648ce3d0201\"){r=new KJUR.crypto.ECDSA()}else{throw\"unsupported private key algorithm\"}}}r.readPKCS8PrvKeyHex(p);return r},_getKeyFromPublicPKCS8Hex:function(q){var p;var r=ASN1HEX.getVbyList(q,0,[0,0],\"06\");if(r===\"2a864886f70d010101\"){p=new RSAKey()}else{if(r===\"2a8648ce380401\"){p=new KJUR.crypto.DSA()}else{if(r===\"2a8648ce3d0201\"){p=new KJUR.crypto.ECDSA()}else{throw\"unsupported PKCS#8 public key hex\"}}}p.readPKCS8PubKeyHex(q);return p},parsePublicRawRSAKeyHex:function(r){var u=ASN1HEX;var t=u.getChildIdx;var s=u.getV;var p={};if(r.substr(0,2)!=\"30\"){throw\"malformed RSA key(code:001)\"}var q=t(r,0);if(q.length!=2){throw\"malformed RSA key(code:002)\"}if(r.substr(q[0],2)!=\"02\"){throw\"malformed RSA key(code:003)\"}p.n=s(r,q[0]);if(r.substr(q[1],2)!=\"02\"){throw\"malformed RSA key(code:004)\"}p.e=s(r,q[1]);return p},parsePublicPKCS8Hex:function(t){var v=ASN1HEX;var u=v.getChildIdx;var s=v.getV;var q={};q.algparam=null;var r=u(t,0);if(r.length!=2){throw\"outer DERSequence shall have 2 elements: \"+r.length}var w=r[0];if(t.substr(w,2)!=\"30\"){throw\"malformed PKCS8 public key(code:001)\"}var p=u(t,w);if(p.length!=2){throw\"malformed PKCS8 public key(code:002)\"}if(t.substr(p[0],2)!=\"06\"){throw\"malformed PKCS8 public key(code:003)\"}q.algoid=s(t,p[0]);if(t.substr(p[1],2)==\"06\"){q.algparam=s(t,p[1])}else{if(t.substr(p[1],2)==\"30\"){q.algparam={};q.algparam.p=v.getVbyList(t,p[1],[0],\"02\");q.algparam.q=v.getVbyList(t,p[1],[1],\"02\");q.algparam.g=v.getVbyList(t,p[1],[2],\"02\")}}if(t.substr(r[1],2)!=\"03\"){throw\"malformed PKCS8 public key(code:004)\"}q.key=s(t,r[1]).substr(2);return q},}}();KEYUTIL.getKey=function(l,k,n){var G=ASN1HEX,L=G.getChildIdx,v=G.getV,d=G.getVbyList,c=KJUR.crypto,i=c.ECDSA,C=c.DSA,w=RSAKey,M=pemtohex,F=KEYUTIL;if(typeof w!=\"undefined\"&&l instanceof w){return l}if(typeof i!=\"undefined\"&&l instanceof i){return l}if(typeof C!=\"undefined\"&&l instanceof C){return l}if(l.curve!==undefined&&l.xy!==undefined&&l.d===undefined){return new i({pub:l.xy,curve:l.curve})}if(l.curve!==undefined&&l.d!==undefined){return new i({prv:l.d,curve:l.curve})}if(l.kty===undefined&&l.n!==undefined&&l.e!==undefined&&l.d===undefined){var P=new w();P.setPublic(l.n,l.e);return P}if(l.kty===undefined&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined&&l.p!==undefined&&l.q!==undefined&&l.dp!==undefined&&l.dq!==undefined&&l.co!==undefined&&l.qi===undefined){var P=new w();P.setPrivateEx(l.n,l.e,l.d,l.p,l.q,l.dp,l.dq,l.co);return P}if(l.kty===undefined&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined&&l.p===undefined){var P=new w();P.setPrivate(l.n,l.e,l.d);return P}if(l.p!==undefined&&l.q!==undefined&&l.g!==undefined&&l.y!==undefined&&l.x===undefined){var P=new C();P.setPublic(l.p,l.q,l.g,l.y);return P}if(l.p!==undefined&&l.q!==undefined&&l.g!==undefined&&l.y!==undefined&&l.x!==undefined){var P=new C();P.setPrivate(l.p,l.q,l.g,l.y,l.x);return P}if(l.kty===\"RSA\"&&l.n!==undefined&&l.e!==undefined&&l.d===undefined){var P=new w();P.setPublic(b64utohex(l.n),b64utohex(l.e));return P}if(l.kty===\"RSA\"&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined&&l.p!==undefined&&l.q!==undefined&&l.dp!==undefined&&l.dq!==undefined&&l.qi!==undefined){var P=new w();P.setPrivateEx(b64utohex(l.n),b64utohex(l.e),b64utohex(l.d),b64utohex(l.p),b64utohex(l.q),b64utohex(l.dp),b64utohex(l.dq),b64utohex(l.qi));return P}if(l.kty===\"RSA\"&&l.n!==undefined&&l.e!==undefined&&l.d!==undefined){var P=new w();P.setPrivate(b64utohex(l.n),b64utohex(l.e),b64utohex(l.d));return P}if(l.kty===\"EC\"&&l.crv!==undefined&&l.x!==undefined&&l.y!==undefined&&l.d===undefined){var j=new i({curve:l.crv});var t=j.ecparams.keylen/4;var B=(\"0000000000\"+b64utohex(l.x)).slice(-t);var z=(\"0000000000\"+b64utohex(l.y)).slice(-t);var u=\"04\"+B+z;j.setPublicKeyHex(u);return j}if(l.kty===\"EC\"&&l.crv!==undefined&&l.x!==undefined&&l.y!==undefined&&l.d!==undefined){var j=new i({curve:l.crv});var t=j.ecparams.keylen/4;var B=(\"0000000000\"+b64utohex(l.x)).slice(-t);var z=(\"0000000000\"+b64utohex(l.y)).slice(-t);var u=\"04\"+B+z;var b=(\"0000000000\"+b64utohex(l.d)).slice(-t);j.setPublicKeyHex(u);j.setPrivateKeyHex(b);return j}if(n===\"pkcs5prv\"){var J=l,G=ASN1HEX,N,P;N=L(J,0);if(N.length===9){P=new w();P.readPKCS5PrvKeyHex(J)}else{if(N.length===6){P=new C();P.readPKCS5PrvKeyHex(J)}else{if(N.length>2&&J.substr(N[1],2)===\"04\"){P=new i();P.readPKCS5PrvKeyHex(J)}else{throw\"unsupported PKCS#1/5 hexadecimal key\"}}}return P}if(n===\"pkcs8prv\"){var P=F.getKeyFromPlainPrivatePKCS8Hex(l);return P}if(n===\"pkcs8pub\"){return F._getKeyFromPublicPKCS8Hex(l)}if(n===\"x509pub\"){return X509.getPublicKeyFromCertHex(l)}if(l.indexOf(\"-END CERTIFICATE-\",0)!=-1||l.indexOf(\"-END X509 CERTIFICATE-\",0)!=-1||l.indexOf(\"-END TRUSTED CERTIFICATE-\",0)!=-1){return X509.getPublicKeyFromCertPEM(l)}if(l.indexOf(\"-END PUBLIC KEY-\")!=-1){var O=pemtohex(l,\"PUBLIC KEY\");return F._getKeyFromPublicPKCS8Hex(O)}if(l.indexOf(\"-END RSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")==-1){var m=M(l,\"RSA PRIVATE KEY\");return F.getKey(m,null,\"pkcs5prv\")}if(l.indexOf(\"-END DSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")==-1){var I=M(l,\"DSA PRIVATE KEY\");var E=d(I,0,[1],\"02\");var D=d(I,0,[2],\"02\");var K=d(I,0,[3],\"02\");var r=d(I,0,[4],\"02\");var s=d(I,0,[5],\"02\");var P=new C();P.setPrivate(new BigInteger(E,16),new BigInteger(D,16),new BigInteger(K,16),new BigInteger(r,16),new BigInteger(s,16));return P}if(l.indexOf(\"-END PRIVATE KEY-\")!=-1){return F.getKeyFromPlainPrivatePKCS8PEM(l)}if(l.indexOf(\"-END RSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")!=-1){var o=F.getDecryptedKeyHex(l,k);var H=new RSAKey();H.readPKCS5PrvKeyHex(o);return H}if(l.indexOf(\"-END EC PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")!=-1){var I=F.getDecryptedKeyHex(l,k);var P=d(I,0,[1],\"04\");var f=d(I,0,[2,0],\"06\");var A=d(I,0,[3,0],\"03\").substr(2);var e=\"\";if(KJUR.crypto.OID.oidhex2name[f]!==undefined){e=KJUR.crypto.OID.oidhex2name[f]}else{throw\"undefined OID(hex) in KJUR.crypto.OID: \"+f}var j=new i({curve:e});j.setPublicKeyHex(A);j.setPrivateKeyHex(P);j.isPublic=false;return j}if(l.indexOf(\"-END DSA PRIVATE KEY-\")!=-1&&l.indexOf(\"4,ENCRYPTED\")!=-1){var I=F.getDecryptedKeyHex(l,k);var E=d(I,0,[1],\"02\");var D=d(I,0,[2],\"02\");var K=d(I,0,[3],\"02\");var r=d(I,0,[4],\"02\");var s=d(I,0,[5],\"02\");var P=new C();P.setPrivate(new BigInteger(E,16),new BigInteger(D,16),new BigInteger(K,16),new BigInteger(r,16),new BigInteger(s,16));return P}if(l.indexOf(\"-END ENCRYPTED PRIVATE KEY-\")!=-1){return F.getKeyFromEncryptedPKCS8PEM(l,k)}throw\"not supported argument\"};KEYUTIL.generateKeypair=function(a,c){if(a==\"RSA\"){var b=c;var h=new RSAKey();h.generate(b,\"10001\");h.isPrivate=true;h.isPublic=true;var f=new RSAKey();var e=h.n.toString(16);var i=h.e.toString(16);f.setPublic(e,i);f.isPrivate=false;f.isPublic=true;var k={};k.prvKeyObj=h;k.pubKeyObj=f;return k}else{if(a==\"EC\"){var d=c;var g=new KJUR.crypto.ECDSA({curve:d});var j=g.generateKeyPairHex();var h=new KJUR.crypto.ECDSA({curve:d});h.setPublicKeyHex(j.ecpubhex);h.setPrivateKeyHex(j.ecprvhex);h.isPrivate=true;h.isPublic=false;var f=new KJUR.crypto.ECDSA({curve:d});f.setPublicKeyHex(j.ecpubhex);f.isPrivate=false;f.isPublic=true;var k={};k.prvKeyObj=h;k.pubKeyObj=f;return k}else{throw\"unknown algorithm: \"+a}}};KEYUTIL.getPEM=function(b,D,y,m,q,j){var F=KJUR,k=F.asn1,z=k.DERObjectIdentifier,f=k.DERInteger,l=k.ASN1Util.newObject,a=k.x509,C=a.SubjectPublicKeyInfo,e=F.crypto,u=e.DSA,r=e.ECDSA,n=RSAKey;function A(s){var G=l({seq:[{\"int\":0},{\"int\":{bigint:s.n}},{\"int\":s.e},{\"int\":{bigint:s.d}},{\"int\":{bigint:s.p}},{\"int\":{bigint:s.q}},{\"int\":{bigint:s.dmp1}},{\"int\":{bigint:s.dmq1}},{\"int\":{bigint:s.coeff}}]});return G}function B(G){var s=l({seq:[{\"int\":1},{octstr:{hex:G.prvKeyHex}},{tag:[\"a0\",true,{oid:{name:G.curveName}}]},{tag:[\"a1\",true,{bitstr:{hex:\"00\"+G.pubKeyHex}}]}]});return s}function x(s){var G=l({seq:[{\"int\":0},{\"int\":{bigint:s.p}},{\"int\":{bigint:s.q}},{\"int\":{bigint:s.g}},{\"int\":{bigint:s.y}},{\"int\":{bigint:s.x}}]});return G}if(((n!==undefined&&b instanceof n)||(u!==undefined&&b instanceof u)||(r!==undefined&&b instanceof r))&&b.isPublic==true&&(D===undefined||D==\"PKCS8PUB\")){var E=new C(b);var w=E.getEncodedHex();return hextopem(w,\"PUBLIC KEY\")}if(D==\"PKCS1PRV\"&&n!==undefined&&b instanceof n&&(y===undefined||y==null)&&b.isPrivate==true){var E=A(b);var w=E.getEncodedHex();return hextopem(w,\"RSA PRIVATE KEY\")}if(D==\"PKCS1PRV\"&&r!==undefined&&b instanceof r&&(y===undefined||y==null)&&b.isPrivate==true){var i=new z({name:b.curveName});var v=i.getEncodedHex();var h=B(b);var t=h.getEncodedHex();var p=\"\";p+=hextopem(v,\"EC PARAMETERS\");p+=hextopem(t,\"EC PRIVATE KEY\");return p}if(D==\"PKCS1PRV\"&&u!==undefined&&b instanceof u&&(y===undefined||y==null)&&b.isPrivate==true){var E=x(b);var w=E.getEncodedHex();return hextopem(w,\"DSA PRIVATE KEY\")}if(D==\"PKCS5PRV\"&&n!==undefined&&b instanceof n&&(y!==undefined&&y!=null)&&b.isPrivate==true){var E=A(b);var w=E.getEncodedHex();if(m===undefined){m=\"DES-EDE3-CBC\"}return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"RSA\",w,y,m,j)}if(D==\"PKCS5PRV\"&&r!==undefined&&b instanceof r&&(y!==undefined&&y!=null)&&b.isPrivate==true){var E=B(b);var w=E.getEncodedHex();if(m===undefined){m=\"DES-EDE3-CBC\"}return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"EC\",w,y,m,j)}if(D==\"PKCS5PRV\"&&u!==undefined&&b instanceof u&&(y!==undefined&&y!=null)&&b.isPrivate==true){var E=x(b);var w=E.getEncodedHex();if(m===undefined){m=\"DES-EDE3-CBC\"}return this.getEncryptedPKCS5PEMFromPrvKeyHex(\"DSA\",w,y,m,j)}var o=function(G,s){var I=c(G,s);var H=new l({seq:[{seq:[{oid:{name:\"pkcs5PBES2\"}},{seq:[{seq:[{oid:{name:\"pkcs5PBKDF2\"}},{seq:[{octstr:{hex:I.pbkdf2Salt}},{\"int\":I.pbkdf2Iter}]}]},{seq:[{oid:{name:\"des-EDE3-CBC\"}},{octstr:{hex:I.encryptionSchemeIV}}]}]}]},{octstr:{hex:I.ciphertext}}]});return H.getEncodedHex()};var c=function(N,O){var H=100;var M=CryptoJS.lib.WordArray.random(8);var L=\"DES-EDE3-CBC\";var s=CryptoJS.lib.WordArray.random(8);var I=CryptoJS.PBKDF2(O,M,{keySize:192/32,iterations:H});var J=CryptoJS.enc.Hex.parse(N);var K=CryptoJS.TripleDES.encrypt(J,I,{iv:s})+\"\";var G={};G.ciphertext=K;G.pbkdf2Salt=CryptoJS.enc.Hex.stringify(M);G.pbkdf2Iter=H;G.encryptionSchemeAlg=L;G.encryptionSchemeIV=CryptoJS.enc.Hex.stringify(s);return G};if(D==\"PKCS8PRV\"&&n!=undefined&&b instanceof n&&b.isPrivate==true){var g=A(b);var d=g.getEncodedHex();var E=l({seq:[{\"int\":0},{seq:[{oid:{name:\"rsaEncryption\"}},{\"null\":true}]},{octstr:{hex:d}}]});var w=E.getEncodedHex();if(y===undefined||y==null){return hextopem(w,\"PRIVATE KEY\")}else{var t=o(w,y);return hextopem(t,\"ENCRYPTED PRIVATE KEY\")}}if(D==\"PKCS8PRV\"&&r!==undefined&&b instanceof r&&b.isPrivate==true){var g=new l({seq:[{\"int\":1},{octstr:{hex:b.prvKeyHex}},{tag:[\"a1\",true,{bitstr:{hex:\"00\"+b.pubKeyHex}}]}]});var d=g.getEncodedHex();var E=l({seq:[{\"int\":0},{seq:[{oid:{name:\"ecPublicKey\"}},{oid:{name:b.curveName}}]},{octstr:{hex:d}}]});var w=E.getEncodedHex();if(y===undefined||y==null){return hextopem(w,\"PRIVATE KEY\")}else{var t=o(w,y);return hextopem(t,\"ENCRYPTED PRIVATE KEY\")}}if(D==\"PKCS8PRV\"&&u!==undefined&&b instanceof u&&b.isPrivate==true){var g=new f({bigint:b.x});var d=g.getEncodedHex();var E=l({seq:[{\"int\":0},{seq:[{oid:{name:\"dsa\"}},{seq:[{\"int\":{bigint:b.p}},{\"int\":{bigint:b.q}},{\"int\":{bigint:b.g}}]}]},{octstr:{hex:d}}]});var w=E.getEncodedHex();if(y===undefined||y==null){return hextopem(w,\"PRIVATE KEY\")}else{var t=o(w,y);return hextopem(t,\"ENCRYPTED PRIVATE KEY\")}}throw\"unsupported object nor format\"};KEYUTIL.getKeyFromCSRPEM=function(b){var a=pemtohex(b,\"CERTIFICATE REQUEST\");var c=KEYUTIL.getKeyFromCSRHex(a);return c};KEYUTIL.getKeyFromCSRHex=function(a){var c=KEYUTIL.parseCSRHex(a);var b=KEYUTIL.getKey(c.p8pubkeyhex,null,\"pkcs8pub\");return b};KEYUTIL.parseCSRHex=function(d){var i=ASN1HEX;var f=i.getChildIdx;var c=i.getTLV;var b={};var g=d;if(g.substr(0,2)!=\"30\"){throw\"malformed CSR(code:001)\"}var e=f(g,0);if(e.length<1){throw\"malformed CSR(code:002)\"}if(g.substr(e[0],2)!=\"30\"){throw\"malformed CSR(code:003)\"}var a=f(g,e[0]);if(a.length<3){throw\"malformed CSR(code:004)\"}b.p8pubkeyhex=c(g,a[2]);return b};KEYUTIL.getJWKFromKey=function(d){var b={};if(d instanceof RSAKey&&d.isPrivate){b.kty=\"RSA\";b.n=hextob64u(d.n.toString(16));b.e=hextob64u(d.e.toString(16));b.d=hextob64u(d.d.toString(16));b.p=hextob64u(d.p.toString(16));b.q=hextob64u(d.q.toString(16));b.dp=hextob64u(d.dmp1.toString(16));b.dq=hextob64u(d.dmq1.toString(16));b.qi=hextob64u(d.coeff.toString(16));return b}else{if(d instanceof RSAKey&&d.isPublic){b.kty=\"RSA\";b.n=hextob64u(d.n.toString(16));b.e=hextob64u(d.e.toString(16));return b}else{if(d instanceof KJUR.crypto.ECDSA&&d.isPrivate){var a=d.getShortNISTPCurveName();if(a!==\"P-256\"&&a!==\"P-384\"){throw\"unsupported curve name for JWT: \"+a}var c=d.getPublicKeyXYHex();b.kty=\"EC\";b.crv=a;b.x=hextob64u(c.x);b.y=hextob64u(c.y);b.d=hextob64u(d.prvKeyHex);return b}else{if(d instanceof KJUR.crypto.ECDSA&&d.isPublic){var a=d.getShortNISTPCurveName();if(a!==\"P-256\"&&a!==\"P-384\"){throw\"unsupported curve name for JWT: \"+a}var c=d.getPublicKeyXYHex();b.kty=\"EC\";b.crv=a;b.x=hextob64u(c.x);b.y=hextob64u(c.y);return b}}}}throw\"not supported key object\"};\nRSAKey.getPosArrayOfChildrenFromHex=function(a){return ASN1HEX.getChildIdx(a,0)};RSAKey.getHexValueArrayOfChildrenFromHex=function(f){var n=ASN1HEX;var i=n.getV;var k=RSAKey.getPosArrayOfChildrenFromHex(f);var e=i(f,k[0]);var j=i(f,k[1]);var b=i(f,k[2]);var c=i(f,k[3]);var h=i(f,k[4]);var g=i(f,k[5]);var m=i(f,k[6]);var l=i(f,k[7]);var d=i(f,k[8]);var k=new Array();k.push(e,j,b,c,h,g,m,l,d);return k};RSAKey.prototype.readPrivateKeyFromPEMString=function(d){var c=pemtohex(d);var b=RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1],b[2],b[3],b[4],b[5],b[6],b[7],b[8])};RSAKey.prototype.readPKCS5PrvKeyHex=function(c){var b=RSAKey.getHexValueArrayOfChildrenFromHex(c);this.setPrivateEx(b[1],b[2],b[3],b[4],b[5],b[6],b[7],b[8])};RSAKey.prototype.readPKCS8PrvKeyHex=function(e){var c,j,l,b,a,f,d,k;var m=ASN1HEX;var g=m.getVbyList;if(m.isASN1HEX(e)===false){throw\"not ASN.1 hex string\"}try{c=g(e,0,[2,0,1],\"02\");j=g(e,0,[2,0,2],\"02\");l=g(e,0,[2,0,3],\"02\");b=g(e,0,[2,0,4],\"02\");a=g(e,0,[2,0,5],\"02\");f=g(e,0,[2,0,6],\"02\");d=g(e,0,[2,0,7],\"02\");k=g(e,0,[2,0,8],\"02\")}catch(i){throw\"malformed PKCS#8 plain RSA private key\"}this.setPrivateEx(c,j,l,b,a,f,d,k)};RSAKey.prototype.readPKCS5PubKeyHex=function(c){var e=ASN1HEX;var b=e.getV;if(e.isASN1HEX(c)===false){throw\"keyHex is not ASN.1 hex string\"}var a=e.getChildIdx(c,0);if(a.length!==2||c.substr(a[0],2)!==\"02\"||c.substr(a[1],2)!==\"02\"){throw\"wrong hex for PKCS#5 public key\"}var f=b(c,a[0]);var d=b(c,a[1]);this.setPublic(f,d)};RSAKey.prototype.readPKCS8PubKeyHex=function(b){var c=ASN1HEX;if(c.isASN1HEX(b)===false){throw\"not ASN.1 hex string\"}if(c.getTLVbyList(b,0,[0,0])!==\"06092a864886f70d010101\"){throw\"not PKCS8 RSA public key\"}var a=c.getTLVbyList(b,0,[1,0]);this.readPKCS5PubKeyHex(a)};RSAKey.prototype.readCertPubKeyHex=function(b,d){var a,c;a=new X509();a.readCertHex(b);c=a.getPublicKeyHex();this.readPKCS8PubKeyHex(c)};\nvar _RE_HEXDECONLY=new RegExp(\"\");_RE_HEXDECONLY.compile(\"[^0-9a-f]\",\"gi\");function _rsasign_getHexPaddedDigestInfoForString(d,e,a){var b=function(f){return KJUR.crypto.Util.hashString(f,a)};var c=b(d);return KJUR.crypto.Util.getPaddedDigestInfoHex(c,a,e)}function _zeroPaddingOfSignature(e,d){var c=\"\";var a=d/4-e.length;for(var b=0;b<a;b++){c=c+\"0\"}return c+e}RSAKey.prototype.sign=function(d,a){var b=function(e){return KJUR.crypto.Util.hashString(e,a)};var c=b(d);return this.signWithMessageHash(c,a)};RSAKey.prototype.signWithMessageHash=function(e,c){var f=KJUR.crypto.Util.getPaddedDigestInfoHex(e,c,this.n.bitLength());var b=parseBigInt(f,16);var d=this.doPrivate(b);var a=d.toString(16);return _zeroPaddingOfSignature(a,this.n.bitLength())};function pss_mgf1_str(c,a,e){var b=\"\",d=0;while(b.length<a){b+=hextorstr(e(rstrtohex(c+String.fromCharCode.apply(String,[(d&4278190080)>>24,(d&16711680)>>16,(d&65280)>>8,d&255]))));d+=1}return b}RSAKey.prototype.signPSS=function(e,a,d){var c=function(f){return KJUR.crypto.Util.hashHex(f,a)};var b=c(rstrtohex(e));if(d===undefined){d=-1}return this.signWithMessageHashPSS(b,a,d)};RSAKey.prototype.signWithMessageHashPSS=function(l,a,k){var b=hextorstr(l);var g=b.length;var m=this.n.bitLength()-1;var c=Math.ceil(m/8);var d;var o=function(i){return KJUR.crypto.Util.hashHex(i,a)};if(k===-1||k===undefined){k=g}else{if(k===-2){k=c-g-2}else{if(k<-2){throw\"invalid salt length\"}}}if(c<(g+k+2)){throw\"data too long\"}var f=\"\";if(k>0){f=new Array(k);new SecureRandom().nextBytes(f);f=String.fromCharCode.apply(String,f)}var n=hextorstr(o(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"+b+f)));var j=[];for(d=0;d<c-k-g-2;d+=1){j[d]=0}var e=String.fromCharCode.apply(String,j)+\"\\x01\"+f;var h=pss_mgf1_str(n,e.length,o);var q=[];for(d=0;d<e.length;d+=1){q[d]=e.charCodeAt(d)^h.charCodeAt(d)}var p=(65280>>(8*c-m))&255;q[0]&=~p;for(d=0;d<g;d++){q.push(n.charCodeAt(d))}q.push(188);return _zeroPaddingOfSignature(this.doPrivate(new BigInteger(q)).toString(16),this.n.bitLength())};function _rsasign_getDecryptSignatureBI(a,d,c){var b=new RSAKey();b.setPublic(d,c);var e=b.doPublic(a);return e}function _rsasign_getHexDigestInfoFromSig(a,c,b){var e=_rsasign_getDecryptSignatureBI(a,c,b);var d=e.toString(16).replace(/^1f+00/,\"\");return d}function _rsasign_getAlgNameAndHashFromHexDisgestInfo(f){for(var e in KJUR.crypto.Util.DIGESTINFOHEAD){var d=KJUR.crypto.Util.DIGESTINFOHEAD[e];var b=d.length;if(f.substring(0,b)==d){var c=[e,f.substring(b)];return c}}return[]}RSAKey.prototype.verify=function(f,j){j=j.replace(_RE_HEXDECONLY,\"\");j=j.replace(/[ \\n]+/g,\"\");var b=parseBigInt(j,16);if(b.bitLength()>this.n.bitLength()){return 0}var i=this.doPublic(b);var e=i.toString(16).replace(/^1f+00/,\"\");var g=_rsasign_getAlgNameAndHashFromHexDisgestInfo(e);if(g.length==0){return false}var d=g[0];var h=g[1];var a=function(k){return KJUR.crypto.Util.hashString(k,d)};var c=a(f);return(h==c)};RSAKey.prototype.verifyWithMessageHash=function(e,a){a=a.replace(_RE_HEXDECONLY,\"\");a=a.replace(/[ \\n]+/g,\"\");var b=parseBigInt(a,16);if(b.bitLength()>this.n.bitLength()){return 0}var h=this.doPublic(b);var g=h.toString(16).replace(/^1f+00/,\"\");var c=_rsasign_getAlgNameAndHashFromHexDisgestInfo(g);if(c.length==0){return false}var d=c[0];var f=c[1];return(f==e)};RSAKey.prototype.verifyPSS=function(c,b,a,f){var e=function(g){return KJUR.crypto.Util.hashHex(g,a)};var d=e(rstrtohex(c));if(f===undefined){f=-1}return this.verifyWithMessageHashPSS(d,b,a,f)};RSAKey.prototype.verifyWithMessageHashPSS=function(f,s,l,c){var k=new BigInteger(s,16);if(k.bitLength()>this.n.bitLength()){return false}var r=function(i){return KJUR.crypto.Util.hashHex(i,l)};var j=hextorstr(f);var h=j.length;var g=this.n.bitLength()-1;var m=Math.ceil(g/8);var q;if(c===-1||c===undefined){c=h}else{if(c===-2){c=m-h-2}else{if(c<-2){throw\"invalid salt length\"}}}if(m<(h+c+2)){throw\"data too long\"}var a=this.doPublic(k).toByteArray();for(q=0;q<a.length;q+=1){a[q]&=255}while(a.length<m){a.unshift(0)}if(a[m-1]!==188){throw\"encoded message does not end in 0xbc\"}a=String.fromCharCode.apply(String,a);var d=a.substr(0,m-h-1);var e=a.substr(d.length,h);var p=(65280>>(8*m-g))&255;if((d.charCodeAt(0)&p)!==0){throw\"bits beyond keysize not zero\"}var n=pss_mgf1_str(e,d.length,r);var o=[];for(q=0;q<d.length;q+=1){o[q]=d.charCodeAt(q)^n.charCodeAt(q)}o[0]&=~p;var b=m-h-c-2;for(q=0;q<b;q+=1){if(o[q]!==0){throw\"leftmost octets not zero\"}}if(o[b]!==1){throw\"0x01 marker not found\"}return e===hextorstr(r(rstrtohex(\"\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\"+j+String.fromCharCode.apply(String,o.slice(-c)))))};RSAKey.SALT_LEN_HLEN=-1;RSAKey.SALT_LEN_MAX=-2;RSAKey.SALT_LEN_RECOVER=-2;\nfunction X509(){var k=ASN1HEX,j=k.getChildIdx,h=k.getV,b=k.getTLV,f=k.getVbyList,c=k.getTLVbyList,g=k.getIdxbyList,d=k.getVidx,i=k.oidname,a=X509,e=pemtohex;this.hex=null;this.version=0;this.foffset=0;this.aExtInfo=null;this.getVersion=function(){if(this.hex===null||this.version!==0){return this.version}if(c(this.hex,0,[0,0])!==\"a003020102\"){this.version=1;this.foffset=-1;return 1}this.version=3;return 3};this.getSerialNumberHex=function(){return f(this.hex,0,[0,1+this.foffset],\"02\")};this.getSignatureAlgorithmField=function(){return i(f(this.hex,0,[0,2+this.foffset,0],\"06\"))};this.getIssuerHex=function(){return c(this.hex,0,[0,3+this.foffset],\"30\")};this.getIssuerString=function(){return a.hex2dn(this.getIssuerHex())};this.getSubjectHex=function(){return c(this.hex,0,[0,5+this.foffset],\"30\")};this.getSubjectString=function(){return a.hex2dn(this.getSubjectHex())};this.getNotBefore=function(){var l=f(this.hex,0,[0,4+this.foffset,0]);l=l.replace(/(..)/g,\"%$1\");l=decodeURIComponent(l);return l};this.getNotAfter=function(){var l=f(this.hex,0,[0,4+this.foffset,1]);l=l.replace(/(..)/g,\"%$1\");l=decodeURIComponent(l);return l};this.getPublicKeyHex=function(){return k.getTLVbyList(this.hex,0,[0,6+this.foffset],\"30\")};this.getPublicKeyIdx=function(){return g(this.hex,0,[0,6+this.foffset],\"30\")};this.getPublicKeyContentIdx=function(){var l=this.getPublicKeyIdx();return g(this.hex,l,[1,0],\"30\")};this.getPublicKey=function(){return KEYUTIL.getKey(this.getPublicKeyHex(),null,\"pkcs8pub\")};this.getSignatureAlgorithmName=function(){return i(f(this.hex,0,[1,0],\"06\"))};this.getSignatureValueHex=function(){return f(this.hex,0,[2],\"03\",true)};this.verifySignature=function(n){var o=this.getSignatureAlgorithmName();var l=this.getSignatureValueHex();var m=c(this.hex,0,[0],\"30\");var p=new KJUR.crypto.Signature({alg:o});p.init(n);p.updateHex(m);return p.verify(l)};this.parseExt=function(){if(this.version!==3){return -1}var p=g(this.hex,0,[0,7,0],\"30\");var m=j(this.hex,p);this.aExtInfo=new Array();for(var n=0;n<m.length;n++){var q={};q.critical=false;var l=j(this.hex,m[n]);var r=0;if(l.length===3){q.critical=true;r=1}q.oid=k.hextooidstr(f(this.hex,m[n],[0],\"06\"));var o=g(this.hex,m[n],[1+r]);q.vidx=d(this.hex,o);this.aExtInfo.push(q)}};this.getExtInfo=function(n){var l=this.aExtInfo;var o=n;if(!n.match(/^[0-9.]+$/)){o=KJUR.asn1.x509.OID.name2oid(n)}if(o===\"\"){return undefined}for(var m=0;m<l.length;m++){if(l[m].oid===o){return l[m]}}return undefined};this.getExtBasicConstraints=function(){var n=this.getExtInfo(\"basicConstraints\");if(n===undefined){return n}var l=h(this.hex,n.vidx);if(l===\"\"){return{}}if(l===\"0101ff\"){return{cA:true}}if(l.substr(0,8)===\"0101ff02\"){var o=h(l,6);var m=parseInt(o,16);return{cA:true,pathLen:m}}throw\"basicConstraints parse error\"};this.getExtKeyUsageBin=function(){var o=this.getExtInfo(\"keyUsage\");if(o===undefined){return\"\"}var m=h(this.hex,o.vidx);if(m.length%2!=0||m.length<=2){throw\"malformed key usage value\"}var l=parseInt(m.substr(0,2));var n=parseInt(m.substr(2),16).toString(2);return n.substr(0,n.length-l)};this.getExtKeyUsageString=function(){var n=this.getExtKeyUsageBin();var l=new Array();for(var m=0;m<n.length;m++){if(n.substr(m,1)==\"1\"){l.push(X509.KEYUSAGE_NAME[m])}}return l.join(\",\")};this.getExtSubjectKeyIdentifier=function(){var l=this.getExtInfo(\"subjectKeyIdentifier\");if(l===undefined){return l}return h(this.hex,l.vidx)};this.getExtAuthorityKeyIdentifier=function(){var p=this.getExtInfo(\"authorityKeyIdentifier\");if(p===undefined){return p}var l={};var o=b(this.hex,p.vidx);var m=j(o,0);for(var n=0;n<m.length;n++){if(o.substr(m[n],2)===\"80\"){l.kid=h(o,m[n])}}return l};this.getExtExtKeyUsageName=function(){var p=this.getExtInfo(\"extKeyUsage\");if(p===undefined){return p}var l=new Array();var o=b(this.hex,p.vidx);if(o===\"\"){return l}var m=j(o,0);for(var n=0;n<m.length;n++){l.push(i(h(o,m[n])))}return l};this.getExtSubjectAltName=function(){var m=this.getExtSubjectAltName2();var l=new Array();for(var n=0;n<m.length;n++){if(m[n][0]===\"DNS\"){l.push(m[n][1])}}return l};this.getExtSubjectAltName2=function(){var p,s,r;var q=this.getExtInfo(\"subjectAltName\");if(q===undefined){return q}var l=new Array();var o=b(this.hex,q.vidx);var m=j(o,0);for(var n=0;n<m.length;n++){r=o.substr(m[n],2);p=h(o,m[n]);if(r===\"81\"){s=hextoutf8(p);l.push([\"MAIL\",s])}if(r===\"82\"){s=hextoutf8(p);l.push([\"DNS\",s])}if(r===\"84\"){s=X509.hex2dn(p,0);l.push([\"DN\",s])}if(r===\"86\"){s=hextoutf8(p);l.push([\"URI\",s])}if(r===\"87\"){s=hextoip(p);l.push([\"IP\",s])}}return l};this.getExtCRLDistributionPointsURI=function(){var q=this.getExtInfo(\"cRLDistributionPoints\");if(q===undefined){return q}var l=new Array();var m=j(this.hex,q.vidx);for(var o=0;o<m.length;o++){try{var r=f(this.hex,m[o],[0,0,0],\"86\");var p=hextoutf8(r);l.push(p)}catch(n){}}return l};this.getExtAIAInfo=function(){var p=this.getExtInfo(\"authorityInfoAccess\");if(p===undefined){return p}var l={ocsp:[],caissuer:[]};var m=j(this.hex,p.vidx);for(var n=0;n<m.length;n++){var q=f(this.hex,m[n],[0],\"06\");var o=f(this.hex,m[n],[1],\"86\");if(q===\"2b06010505073001\"){l.ocsp.push(hextoutf8(o))}if(q===\"2b06010505073002\"){l.caissuer.push(hextoutf8(o))}}return l};this.getExtCertificatePolicies=function(){var o=this.getExtInfo(\"certificatePolicies\");if(o===undefined){return o}var l=b(this.hex,o.vidx);var u=[];var s=j(l,0);for(var r=0;r<s.length;r++){var t={};var n=j(l,s[r]);t.id=i(h(l,n[0]));if(n.length===2){var m=j(l,n[1]);for(var q=0;q<m.length;q++){var p=f(l,m[q],[0],\"06\");if(p===\"2b06010505070201\"){t.cps=hextoutf8(f(l,m[q],[1]))}else{if(p===\"2b06010505070202\"){t.unotice=hextoutf8(f(l,m[q],[1,0]))}}}}u.push(t)}return u};this.readCertPEM=function(l){this.readCertHex(e(l))};this.readCertHex=function(l){this.hex=l;this.getVersion();try{g(this.hex,0,[0,7],\"a3\");this.parseExt()}catch(m){}};this.getInfo=function(){var m=X509;var B,u,z;B=\"Basic Fields\\n\";B+=\"  serial number: \"+this.getSerialNumberHex()+\"\\n\";B+=\"  signature algorithm: \"+this.getSignatureAlgorithmField()+\"\\n\";B+=\"  issuer: \"+this.getIssuerString()+\"\\n\";B+=\"  notBefore: \"+this.getNotBefore()+\"\\n\";B+=\"  notAfter: \"+this.getNotAfter()+\"\\n\";B+=\"  subject: \"+this.getSubjectString()+\"\\n\";B+=\"  subject public key info: \\n\";u=this.getPublicKey();B+=\"    key algorithm: \"+u.type+\"\\n\";if(u.type===\"RSA\"){B+=\"    n=\"+hextoposhex(u.n.toString(16)).substr(0,16)+\"...\\n\";B+=\"    e=\"+hextoposhex(u.e.toString(16))+\"\\n\"}z=this.aExtInfo;if(z!==undefined&&z!==null){B+=\"X509v3 Extensions:\\n\";for(var r=0;r<z.length;r++){var n=z[r];var A=KJUR.asn1.x509.OID.oid2name(n.oid);if(A===\"\"){A=n.oid}var x=\"\";if(n.critical===true){x=\"CRITICAL\"}B+=\"  \"+A+\" \"+x+\":\\n\";if(A===\"basicConstraints\"){var v=this.getExtBasicConstraints();if(v.cA===undefined){B+=\"    {}\\n\"}else{B+=\"    cA=true\";if(v.pathLen!==undefined){B+=\", pathLen=\"+v.pathLen}B+=\"\\n\"}}else{if(A===\"keyUsage\"){B+=\"    \"+this.getExtKeyUsageString()+\"\\n\"}else{if(A===\"subjectKeyIdentifier\"){B+=\"    \"+this.getExtSubjectKeyIdentifier()+\"\\n\"}else{if(A===\"authorityKeyIdentifier\"){var l=this.getExtAuthorityKeyIdentifier();if(l.kid!==undefined){B+=\"    kid=\"+l.kid+\"\\n\"}}else{if(A===\"extKeyUsage\"){var w=this.getExtExtKeyUsageName();B+=\"    \"+w.join(\", \")+\"\\n\"}else{if(A===\"subjectAltName\"){var t=this.getExtSubjectAltName2();B+=\"    \"+t+\"\\n\"}else{if(A===\"cRLDistributionPoints\"){var y=this.getExtCRLDistributionPointsURI();B+=\"    \"+y+\"\\n\"}else{if(A===\"authorityInfoAccess\"){var p=this.getExtAIAInfo();if(p.ocsp!==undefined){B+=\"    ocsp: \"+p.ocsp.join(\",\")+\"\\n\"}if(p.caissuer!==undefined){B+=\"    caissuer: \"+p.caissuer.join(\",\")+\"\\n\"}}else{if(A===\"certificatePolicies\"){var o=this.getExtCertificatePolicies();for(var q=0;q<o.length;q++){if(o[q].id!==undefined){B+=\"    policy oid: \"+o[q].id+\"\\n\"}if(o[q].cps!==undefined){B+=\"    cps: \"+o[q].cps+\"\\n\"}}}}}}}}}}}}}B+=\"signature algorithm: \"+this.getSignatureAlgorithmName()+\"\\n\";B+=\"signature: \"+this.getSignatureValueHex().substr(0,16)+\"...\\n\";return B}}X509.hex2dn=function(f,b){if(b===undefined){b=0}if(f.substr(b,2)!==\"30\"){throw\"malformed DN\"}var c=new Array();var d=ASN1HEX.getChildIdx(f,b);for(var e=0;e<d.length;e++){c.push(X509.hex2rdn(f,d[e]))}c=c.map(function(a){return a.replace(\"/\",\"\\\\/\")});return\"/\"+c.join(\"/\")};X509.hex2rdn=function(f,b){if(b===undefined){b=0}if(f.substr(b,2)!==\"31\"){throw\"malformed RDN\"}var c=new Array();var d=ASN1HEX.getChildIdx(f,b);for(var e=0;e<d.length;e++){c.push(X509.hex2attrTypeValue(f,d[e]))}c=c.map(function(a){return a.replace(\"+\",\"\\\\+\")});return c.join(\"+\")};X509.hex2attrTypeValue=function(d,i){var j=ASN1HEX;var h=j.getV;if(i===undefined){i=0}if(d.substr(i,2)!==\"30\"){throw\"malformed attribute type and value\"}var g=j.getChildIdx(d,i);if(g.length!==2||d.substr(g[0],2)!==\"06\"){\"malformed attribute type and value\"}var b=h(d,g[0]);var f=KJUR.asn1.ASN1Util.oidHexToInt(b);var e=KJUR.asn1.x509.OID.oid2atype(f);var a=h(d,g[1]);var c=hextorstr(a);return e+\"=\"+c};X509.getPublicKeyFromCertHex=function(b){var a=new X509();a.readCertHex(b);return a.getPublicKey()};X509.getPublicKeyFromCertPEM=function(b){var a=new X509();a.readCertPEM(b);return a.getPublicKey()};X509.getPublicKeyInfoPropOfCertPEM=function(c){var e=ASN1HEX;var g=e.getVbyList;var b={};var a,f,d;b.algparam=null;a=new X509();a.readCertPEM(c);f=a.getPublicKeyHex();b.keyhex=g(f,0,[1],\"03\").substr(2);b.algoid=g(f,0,[0,0],\"06\");if(b.algoid===\"2a8648ce3d0201\"){b.algparam=g(f,0,[0,1],\"06\")}return b};X509.KEYUSAGE_NAME=[\"digitalSignature\",\"nonRepudiation\",\"keyEncipherment\",\"dataEncipherment\",\"keyAgreement\",\"keyCertSign\",\"cRLSign\",\"encipherOnly\",\"decipherOnly\"];\nif(typeof KJUR==\"undefined\"||!KJUR){KJUR={}}if(typeof KJUR.jws==\"undefined\"||!KJUR.jws){KJUR.jws={}}KJUR.jws.JWS=function(){var b=KJUR,a=b.jws.JWS,c=a.isSafeJSONString;this.parseJWS=function(g,j){if((this.parsedJWS!==undefined)&&(j||(this.parsedJWS.sigvalH!==undefined))){return}var i=g.match(/^([^.]+)\\.([^.]+)\\.([^.]+)$/);if(i==null){throw\"JWS signature is not a form of 'Head.Payload.SigValue'.\"}var k=i[1];var e=i[2];var l=i[3];var n=k+\".\"+e;this.parsedJWS={};this.parsedJWS.headB64U=k;this.parsedJWS.payloadB64U=e;this.parsedJWS.sigvalB64U=l;this.parsedJWS.si=n;if(!j){var h=b64utohex(l);var f=parseBigInt(h,16);this.parsedJWS.sigvalH=h;this.parsedJWS.sigvalBI=f}var d=b64utoutf8(k);var m=b64utoutf8(e);this.parsedJWS.headS=d;this.parsedJWS.payloadS=m;if(!c(d,this.parsedJWS,\"headP\")){throw\"malformed JSON string for JWS Head: \"+d}}};KJUR.jws.JWS.sign=function(i,v,y,z,a){var w=KJUR,m=w.jws,q=m.JWS,g=q.readSafeJSONString,p=q.isSafeJSONString,d=w.crypto,k=d.ECDSA,o=d.Mac,c=d.Signature,t=JSON;var s,j,n;if(typeof v!=\"string\"&&typeof v!=\"object\"){throw\"spHeader must be JSON string or object: \"+v}if(typeof v==\"object\"){j=v;s=t.stringify(j)}if(typeof v==\"string\"){s=v;if(!p(s)){throw\"JWS Head is not safe JSON string: \"+s}j=g(s)}n=y;if(typeof y==\"object\"){n=t.stringify(y)}if((i==\"\"||i==null)&&j.alg!==undefined){i=j.alg}if((i!=\"\"&&i!=null)&&j.alg===undefined){j.alg=i;s=t.stringify(j)}if(i!==j.alg){throw\"alg and sHeader.alg doesn't match: \"+i+\"!=\"+j.alg}var r=null;if(q.jwsalg2sigalg[i]===undefined){throw\"unsupported alg name: \"+i}else{r=q.jwsalg2sigalg[i]}var e=utf8tob64u(s);var l=utf8tob64u(n);var b=e+\".\"+l;var x=\"\";if(r.substr(0,4)==\"Hmac\"){if(z===undefined){throw\"mac key shall be specified for HS* alg\"}var h=new o({alg:r,prov:\"cryptojs\",pass:z});h.updateString(b);x=h.doFinal()}else{if(r.indexOf(\"withECDSA\")!=-1){var f=new c({alg:r});f.init(z,a);f.updateString(b);hASN1Sig=f.sign();x=KJUR.crypto.ECDSA.asn1SigToConcatSig(hASN1Sig)}else{if(r!=\"none\"){var f=new c({alg:r});f.init(z,a);f.updateString(b);x=f.sign()}}}var u=hextob64u(x);return b+\".\"+u};KJUR.jws.JWS.verify=function(w,B,n){var x=KJUR,q=x.jws,t=q.JWS,i=t.readSafeJSONString,e=x.crypto,p=e.ECDSA,s=e.Mac,d=e.Signature,m;if(typeof RSAKey!==undefined){m=RSAKey}var y=w.split(\".\");if(y.length!==3){return false}var f=y[0];var r=y[1];var c=f+\".\"+r;var A=b64utohex(y[2]);var l=i(b64utoutf8(y[0]));var k=null;var z=null;if(l.alg===undefined){throw\"algorithm not specified in header\"}else{k=l.alg;z=k.substr(0,2)}if(n!=null&&Object.prototype.toString.call(n)===\"[object Array]\"&&n.length>0){var b=\":\"+n.join(\":\")+\":\";if(b.indexOf(\":\"+k+\":\")==-1){throw\"algorithm '\"+k+\"' not accepted in the list\"}}if(k!=\"none\"&&B===null){throw\"key shall be specified to verify.\"}if(typeof B==\"string\"&&B.indexOf(\"-----BEGIN \")!=-1){B=KEYUTIL.getKey(B)}if(z==\"RS\"||z==\"PS\"){if(!(B instanceof m)){throw\"key shall be a RSAKey obj for RS* and PS* algs\"}}if(z==\"ES\"){if(!(B instanceof p)){throw\"key shall be a ECDSA obj for ES* algs\"}}if(k==\"none\"){}var u=null;if(t.jwsalg2sigalg[l.alg]===undefined){throw\"unsupported alg name: \"+k}else{u=t.jwsalg2sigalg[k]}if(u==\"none\"){throw\"not supported\"}else{if(u.substr(0,4)==\"Hmac\"){var o=null;if(B===undefined){throw\"hexadecimal key shall be specified for HMAC\"}var j=new s({alg:u,pass:B});j.updateString(c);o=j.doFinal();return A==o}else{if(u.indexOf(\"withECDSA\")!=-1){var h=null;try{h=p.concatSigToASN1Sig(A)}catch(v){return false}var g=new d({alg:u});g.init(B);g.updateString(c);return g.verify(h)}else{var g=new d({alg:u});g.init(B);g.updateString(c);return g.verify(A)}}}};KJUR.jws.JWS.parse=function(g){var c=g.split(\".\");var b={};var f,e,d;if(c.length!=2&&c.length!=3){throw\"malformed sJWS: wrong number of '.' splitted elements\"}f=c[0];e=c[1];if(c.length==3){d=c[2]}b.headerObj=KJUR.jws.JWS.readSafeJSONString(b64utoutf8(f));b.payloadObj=KJUR.jws.JWS.readSafeJSONString(b64utoutf8(e));b.headerPP=JSON.stringify(b.headerObj,null,\"  \");if(b.payloadObj==null){b.payloadPP=b64utoutf8(e)}else{b.payloadPP=JSON.stringify(b.payloadObj,null,\"  \")}if(d!==undefined){b.sigHex=b64utohex(d)}return b};KJUR.jws.JWS.verifyJWT=function(e,l,r){var d=KJUR,j=d.jws,o=j.JWS,n=o.readSafeJSONString,p=o.inArray,f=o.includedArray;var k=e.split(\".\");var c=k[0];var i=k[1];var q=c+\".\"+i;var m=b64utohex(k[2]);var h=n(b64utoutf8(c));var g=n(b64utoutf8(i));if(h.alg===undefined){return false}if(r.alg===undefined){throw\"acceptField.alg shall be specified\"}if(!p(h.alg,r.alg)){return false}if(g.iss!==undefined&&typeof r.iss===\"object\"){if(!p(g.iss,r.iss)){return false}}if(g.sub!==undefined&&typeof r.sub===\"object\"){if(!p(g.sub,r.sub)){return false}}if(g.aud!==undefined&&typeof r.aud===\"object\"){if(typeof g.aud==\"string\"){if(!p(g.aud,r.aud)){return false}}else{if(typeof g.aud==\"object\"){if(!f(g.aud,r.aud)){return false}}}}var b=j.IntDate.getNow();if(r.verifyAt!==undefined&&typeof r.verifyAt===\"number\"){b=r.verifyAt}if(r.gracePeriod===undefined||typeof r.gracePeriod!==\"number\"){r.gracePeriod=0}if(g.exp!==undefined&&typeof g.exp==\"number\"){if(g.exp+r.gracePeriod<b){return false}}if(g.nbf!==undefined&&typeof g.nbf==\"number\"){if(b<g.nbf-r.gracePeriod){return false}}if(g.iat!==undefined&&typeof g.iat==\"number\"){if(b<g.iat-r.gracePeriod){return false}}if(g.jti!==undefined&&r.jti!==undefined){if(g.jti!==r.jti){return false}}if(!o.verify(e,l,r.alg)){return false}return true};KJUR.jws.JWS.includedArray=function(b,a){var c=KJUR.jws.JWS.inArray;if(b===null){return false}if(typeof b!==\"object\"){return false}if(typeof b.length!==\"number\"){return false}for(var d=0;d<b.length;d++){if(!c(b[d],a)){return false}}return true};KJUR.jws.JWS.inArray=function(d,b){if(b===null){return false}if(typeof b!==\"object\"){return false}if(typeof b.length!==\"number\"){return false}for(var c=0;c<b.length;c++){if(b[c]==d){return true}}return false};KJUR.jws.JWS.jwsalg2sigalg={HS256:\"HmacSHA256\",HS384:\"HmacSHA384\",HS512:\"HmacSHA512\",RS256:\"SHA256withRSA\",RS384:\"SHA384withRSA\",RS512:\"SHA512withRSA\",ES256:\"SHA256withECDSA\",ES384:\"SHA384withECDSA\",PS256:\"SHA256withRSAandMGF1\",PS384:\"SHA384withRSAandMGF1\",PS512:\"SHA512withRSAandMGF1\",none:\"none\",};KJUR.jws.JWS.isSafeJSONString=function(c,b,d){var e=null;try{e=jsonParse(c);if(typeof e!=\"object\"){return 0}if(e.constructor===Array){return 0}if(b){b[d]=e}return 1}catch(a){return 0}};KJUR.jws.JWS.readSafeJSONString=function(b){var c=null;try{c=jsonParse(b);if(typeof c!=\"object\"){return null}if(c.constructor===Array){return null}return c}catch(a){return null}};KJUR.jws.JWS.getEncodedSignatureValueFromJWS=function(b){var a=b.match(/^[^.]+\\.[^.]+\\.([^.]+)$/);if(a==null){throw\"JWS signature is not a form of 'Head.Payload.SigValue'.\"}return a[1]};KJUR.jws.JWS.getJWKthumbprint=function(d){if(d.kty!==\"RSA\"&&d.kty!==\"EC\"&&d.kty!==\"oct\"){throw\"unsupported algorithm for JWK Thumprint\"}var a=\"{\";if(d.kty===\"RSA\"){if(typeof d.n!=\"string\"||typeof d.e!=\"string\"){throw\"wrong n and e value for RSA key\"}a+='\"e\":\"'+d.e+'\",';a+='\"kty\":\"'+d.kty+'\",';a+='\"n\":\"'+d.n+'\"}'}else{if(d.kty===\"EC\"){if(typeof d.crv!=\"string\"||typeof d.x!=\"string\"||typeof d.y!=\"string\"){throw\"wrong crv, x and y value for EC key\"}a+='\"crv\":\"'+d.crv+'\",';a+='\"kty\":\"'+d.kty+'\",';a+='\"x\":\"'+d.x+'\",';a+='\"y\":\"'+d.y+'\"}'}else{if(d.kty===\"oct\"){if(typeof d.k!=\"string\"){throw\"wrong k value for oct(symmetric) key\"}a+='\"kty\":\"'+d.kty+'\",';a+='\"k\":\"'+d.k+'\"}'}}}var b=rstrtohex(a);var c=KJUR.crypto.Util.hashHex(b,\"sha256\");var e=hextob64u(c);return e};KJUR.jws.IntDate={};KJUR.jws.IntDate.get=function(c){var b=KJUR.jws.IntDate,d=b.getNow,a=b.getZulu;if(c==\"now\"){return d()}else{if(c==\"now + 1hour\"){return d()+60*60}else{if(c==\"now + 1day\"){return d()+60*60*24}else{if(c==\"now + 1month\"){return d()+60*60*24*30}else{if(c==\"now + 1year\"){return d()+60*60*24*365}else{if(c.match(/Z$/)){return a(c)}else{if(c.match(/^[0-9]+$/)){return parseInt(c)}}}}}}}throw\"unsupported format: \"+c};KJUR.jws.IntDate.getZulu=function(a){return zulutosec(a)};KJUR.jws.IntDate.getNow=function(){var a=~~(new Date()/1000);return a};KJUR.jws.IntDate.intDate2UTCString=function(a){var b=new Date(a*1000);return b.toUTCString()};KJUR.jws.IntDate.intDate2Zulu=function(e){var i=new Date(e*1000),h=(\"0000\"+i.getUTCFullYear()).slice(-4),g=(\"00\"+(i.getUTCMonth()+1)).slice(-2),b=(\"00\"+i.getUTCDate()).slice(-2),a=(\"00\"+i.getUTCHours()).slice(-2),c=(\"00\"+i.getUTCMinutes()).slice(-2),f=(\"00\"+i.getUTCSeconds()).slice(-2);return h+g+b+a+c+f+\"Z\"};\nexport { SecureRandom };\r\nexport { rng_seed_time };\r\n\r\nexport { BigInteger };\r\nexport { RSAKey };\r\nexport const { EDSA } = KJUR.crypto;\r\nexport const { DSA } = KJUR.crypto;\r\nexport const { Signature } = KJUR.crypto;\r\nexport const { MessageDigest } =  KJUR.crypto;\r\nexport const { Mac } = KJUR.crypto;\r\nexport const { Cipher } =  KJUR.crypto;\r\nexport { KEYUTIL };\r\nexport { ASN1HEX };\r\nexport { X509 };\r\nexport { CryptoJS };\r\n\r\n// ext/base64.js\r\nexport { b64tohex };\r\nexport { b64toBA };\r\n\r\n// base64x.js\r\nexport { stoBA };\r\nexport { BAtos };\r\nexport { BAtohex };\r\nexport { stohex };\r\nexport { stob64 };\r\nexport { stob64u };\r\nexport { b64utos };\r\nexport { b64tob64u };\r\nexport { b64utob64 };\r\nexport { hex2b64 };\r\nexport { hextob64u };\r\nexport { b64utohex };\r\nexport { utf8tob64u };\r\nexport { b64utoutf8 };\r\nexport { utf8tob64 };\r\nexport { b64toutf8 };\r\nexport { utf8tohex };\r\nexport { hextoutf8 };\r\nexport { hextorstr };\r\nexport { rstrtohex };\r\nexport { hextob64 };\r\nexport { hextob64nl };\r\nexport { b64nltohex };\r\nexport { hextopem };\r\nexport { pemtohex };\r\nexport { hextoArrayBuffer };\r\nexport { ArrayBuffertohex };\r\nexport { zulutomsec };\r\nexport { zulutosec };\r\nexport { zulutodate };\r\nexport { datetozulu };\r\nexport { uricmptohex };\r\nexport { hextouricmp };\r\nexport { ipv6tohex };\r\nexport { hextoipv6 };\r\nexport { hextoip };\r\nexport { iptohex };\r\nexport { encodeURIComponentAll };\r\nexport { newline_toUnix };\r\nexport { newline_toDos };\r\nexport { hextoposhex };\r\nexport { intarystrtohex };\r\nexport { strdiffidx };\r\n\r\n// name spaces\r\nexport { KJUR };\r\nconst _crypto =  KJUR.crypto;\r\nexport { _crypto as crypto };\r\nexport const { asn1 } = KJUR;\r\nexport const { jws } = KJUR;\r\nexport const { lang } = KJUR;\r\n\r\n\r\n","\"use strict\";\n\nrequire(\"core-js/shim\");\n\nrequire(\"regenerator-runtime/runtime\");\n\nrequire(\"core-js/fn/regexp/escape\");\n\nif (global._babelPolyfill) {\n  throw new Error(\"only one instance of babel-polyfill is allowed\");\n}\nglobal._babelPolyfill = true;\n\nvar DEFINE_PROPERTY = \"defineProperty\";\nfunction define(O, key, value) {\n  O[key] || Object[DEFINE_PROPERTY](O, key, {\n    writable: true,\n    configurable: true,\n    value: value\n  });\n}\n\ndefine(String.prototype, \"padLeft\", \"\".padStart);\ndefine(String.prototype, \"padRight\", \"\".padEnd);\n\n\"pop,reverse,shift,keys,values,entries,indexOf,every,some,forEach,map,filter,find,findIndex,includes,join,slice,concat,push,splice,unshift,sort,lastIndexOf,reduce,reduceRight,copyWithin,fill\".split(\",\").forEach(function (key) {\n  [][key] && define(Array, key, Function.call.bind([][key]));\n});","/**\n * Copyright (c) 2014, Facebook, Inc.\n * All rights reserved.\n *\n * This source code is licensed under the BSD-style license found in the\n * https://raw.github.com/facebook/regenerator/master/LICENSE file. An\n * additional grant of patent rights can be found in the PATENTS file in\n * the same directory.\n */\n\n!(function(global) {\n  \"use strict\";\n\n  var Op = Object.prototype;\n  var hasOwn = Op.hasOwnProperty;\n  var undefined; // More compressible than void 0.\n  var $Symbol = typeof Symbol === \"function\" ? Symbol : {};\n  var iteratorSymbol = $Symbol.iterator || \"@@iterator\";\n  var asyncIteratorSymbol = $Symbol.asyncIterator || \"@@asyncIterator\";\n  var toStringTagSymbol = $Symbol.toStringTag || \"@@toStringTag\";\n\n  var inModule = typeof module === \"object\";\n  var runtime = global.regeneratorRuntime;\n  if (runtime) {\n    if (inModule) {\n      // If regeneratorRuntime is defined globally and we're in a module,\n      // make the exports object identical to regeneratorRuntime.\n      module.exports = runtime;\n    }\n    // Don't bother evaluating the rest of this file if the runtime was\n    // already defined globally.\n    return;\n  }\n\n  // Define the runtime globally (as expected by generated code) as either\n  // module.exports (if we're in a module) or a new, empty object.\n  runtime = global.regeneratorRuntime = inModule ? module.exports : {};\n\n  function wrap(innerFn, outerFn, self, tryLocsList) {\n    // If outerFn provided and outerFn.prototype is a Generator, then outerFn.prototype instanceof Generator.\n    var protoGenerator = outerFn && outerFn.prototype instanceof Generator ? outerFn : Generator;\n    var generator = Object.create(protoGenerator.prototype);\n    var context = new Context(tryLocsList || []);\n\n    // The ._invoke method unifies the implementations of the .next,\n    // .throw, and .return methods.\n    generator._invoke = makeInvokeMethod(innerFn, self, context);\n\n    return generator;\n  }\n  runtime.wrap = wrap;\n\n  // Try/catch helper to minimize deoptimizations. Returns a completion\n  // record like context.tryEntries[i].completion. This interface could\n  // have been (and was previously) designed to take a closure to be\n  // invoked without arguments, but in all the cases we care about we\n  // already have an existing method we want to call, so there's no need\n  // to create a new function object. We can even get away with assuming\n  // the method takes exactly one argument, since that happens to be true\n  // in every case, so we don't have to touch the arguments object. The\n  // only additional allocation required is the completion record, which\n  // has a stable shape and so hopefully should be cheap to allocate.\n  function tryCatch(fn, obj, arg) {\n    try {\n      return { type: \"normal\", arg: fn.call(obj, arg) };\n    } catch (err) {\n      return { type: \"throw\", arg: err };\n    }\n  }\n\n  var GenStateSuspendedStart = \"suspendedStart\";\n  var GenStateSuspendedYield = \"suspendedYield\";\n  var GenStateExecuting = \"executing\";\n  var GenStateCompleted = \"completed\";\n\n  // Returning this object from the innerFn has the same effect as\n  // breaking out of the dispatch switch statement.\n  var ContinueSentinel = {};\n\n  // Dummy constructor functions that we use as the .constructor and\n  // .constructor.prototype properties for functions that return Generator\n  // objects. For full spec compliance, you may wish to configure your\n  // minifier not to mangle the names of these two functions.\n  function Generator() {}\n  function GeneratorFunction() {}\n  function GeneratorFunctionPrototype() {}\n\n  // This is a polyfill for %IteratorPrototype% for environments that\n  // don't natively support it.\n  var IteratorPrototype = {};\n  IteratorPrototype[iteratorSymbol] = function () {\n    return this;\n  };\n\n  var getProto = Object.getPrototypeOf;\n  var NativeIteratorPrototype = getProto && getProto(getProto(values([])));\n  if (NativeIteratorPrototype &&\n      NativeIteratorPrototype !== Op &&\n      hasOwn.call(NativeIteratorPrototype, iteratorSymbol)) {\n    // This environment has a native %IteratorPrototype%; use it instead\n    // of the polyfill.\n    IteratorPrototype = NativeIteratorPrototype;\n  }\n\n  var Gp = GeneratorFunctionPrototype.prototype =\n    Generator.prototype = Object.create(IteratorPrototype);\n  GeneratorFunction.prototype = Gp.constructor = GeneratorFunctionPrototype;\n  GeneratorFunctionPrototype.constructor = GeneratorFunction;\n  GeneratorFunctionPrototype[toStringTagSymbol] =\n    GeneratorFunction.displayName = \"GeneratorFunction\";\n\n  // Helper for defining the .next, .throw, and .return methods of the\n  // Iterator interface in terms of a single ._invoke method.\n  function defineIteratorMethods(prototype) {\n    [\"next\", \"throw\", \"return\"].forEach(function(method) {\n      prototype[method] = function(arg) {\n        return this._invoke(method, arg);\n      };\n    });\n  }\n\n  runtime.isGeneratorFunction = function(genFun) {\n    var ctor = typeof genFun === \"function\" && genFun.constructor;\n    return ctor\n      ? ctor === GeneratorFunction ||\n        // For the native GeneratorFunction constructor, the best we can\n        // do is to check its .name property.\n        (ctor.displayName || ctor.name) === \"GeneratorFunction\"\n      : false;\n  };\n\n  runtime.mark = function(genFun) {\n    if (Object.setPrototypeOf) {\n      Object.setPrototypeOf(genFun, GeneratorFunctionPrototype);\n    } else {\n      genFun.__proto__ = GeneratorFunctionPrototype;\n      if (!(toStringTagSymbol in genFun)) {\n        genFun[toStringTagSymbol] = \"GeneratorFunction\";\n      }\n    }\n    genFun.prototype = Object.create(Gp);\n    return genFun;\n  };\n\n  // Within the body of any async function, `await x` is transformed to\n  // `yield regeneratorRuntime.awrap(x)`, so that the runtime can test\n  // `hasOwn.call(value, \"__await\")` to determine if the yielded value is\n  // meant to be awaited.\n  runtime.awrap = function(arg) {\n    return { __await: arg };\n  };\n\n  function AsyncIterator(generator) {\n    function invoke(method, arg, resolve, reject) {\n      var record = tryCatch(generator[method], generator, arg);\n      if (record.type === \"throw\") {\n        reject(record.arg);\n      } else {\n        var result = record.arg;\n        var value = result.value;\n        if (value &&\n            typeof value === \"object\" &&\n            hasOwn.call(value, \"__await\")) {\n          return Promise.resolve(value.__await).then(function(value) {\n            invoke(\"next\", value, resolve, reject);\n          }, function(err) {\n            invoke(\"throw\", err, resolve, reject);\n          });\n        }\n\n        return Promise.resolve(value).then(function(unwrapped) {\n          // When a yielded Promise is resolved, its final value becomes\n          // the .value of the Promise<{value,done}> result for the\n          // current iteration. If the Promise is rejected, however, the\n          // result for this iteration will be rejected with the same\n          // reason. Note that rejections of yielded Promises are not\n          // thrown back into the generator function, as is the case\n          // when an awaited Promise is rejected. This difference in\n          // behavior between yield and await is important, because it\n          // allows the consumer to decide what to do with the yielded\n          // rejection (swallow it and continue, manually .throw it back\n          // into the generator, abandon iteration, whatever). With\n          // await, by contrast, there is no opportunity to examine the\n          // rejection reason outside the generator function, so the\n          // only option is to throw it from the await expression, and\n          // let the generator function handle the exception.\n          result.value = unwrapped;\n          resolve(result);\n        }, reject);\n      }\n    }\n\n    if (typeof global.process === \"object\" && global.process.domain) {\n      invoke = global.process.domain.bind(invoke);\n    }\n\n    var previousPromise;\n\n    function enqueue(method, arg) {\n      function callInvokeWithMethodAndArg() {\n        return new Promise(function(resolve, reject) {\n          invoke(method, arg, resolve, reject);\n        });\n      }\n\n      return previousPromise =\n        // If enqueue has been called before, then we want to wait until\n        // all previous Promises have been resolved before calling invoke,\n        // so that results are always delivered in the correct order. If\n        // enqueue has not been called before, then it is important to\n        // call invoke immediately, without waiting on a callback to fire,\n        // so that the async generator function has the opportunity to do\n        // any necessary setup in a predictable way. This predictability\n        // is why the Promise constructor synchronously invokes its\n        // executor callback, and why async functions synchronously\n        // execute code before the first await. Since we implement simple\n        // async functions in terms of async generators, it is especially\n        // important to get this right, even though it requires care.\n        previousPromise ? previousPromise.then(\n          callInvokeWithMethodAndArg,\n          // Avoid propagating failures to Promises returned by later\n          // invocations of the iterator.\n          callInvokeWithMethodAndArg\n        ) : callInvokeWithMethodAndArg();\n    }\n\n    // Define the unified helper method that is used to implement .next,\n    // .throw, and .return (see defineIteratorMethods).\n    this._invoke = enqueue;\n  }\n\n  defineIteratorMethods(AsyncIterator.prototype);\n  AsyncIterator.prototype[asyncIteratorSymbol] = function () {\n    return this;\n  };\n  runtime.AsyncIterator = AsyncIterator;\n\n  // Note that simple async functions are implemented on top of\n  // AsyncIterator objects; they just return a Promise for the value of\n  // the final result produced by the iterator.\n  runtime.async = function(innerFn, outerFn, self, tryLocsList) {\n    var iter = new AsyncIterator(\n      wrap(innerFn, outerFn, self, tryLocsList)\n    );\n\n    return runtime.isGeneratorFunction(outerFn)\n      ? iter // If outerFn is a generator, return the full iterator.\n      : iter.next().then(function(result) {\n          return result.done ? result.value : iter.next();\n        });\n  };\n\n  function makeInvokeMethod(innerFn, self, context) {\n    var state = GenStateSuspendedStart;\n\n    return function invoke(method, arg) {\n      if (state === GenStateExecuting) {\n        throw new Error(\"Generator is already running\");\n      }\n\n      if (state === GenStateCompleted) {\n        if (method === \"throw\") {\n          throw arg;\n        }\n\n        // Be forgiving, per 25.3.3.3.3 of the spec:\n        // https://people.mozilla.org/~jorendorff/es6-draft.html#sec-generatorresume\n        return doneResult();\n      }\n\n      context.method = method;\n      context.arg = arg;\n\n      while (true) {\n        var delegate = context.delegate;\n        if (delegate) {\n          var delegateResult = maybeInvokeDelegate(delegate, context);\n          if (delegateResult) {\n            if (delegateResult === ContinueSentinel) continue;\n            return delegateResult;\n          }\n        }\n\n        if (context.method === \"next\") {\n          // Setting context._sent for legacy support of Babel's\n          // function.sent implementation.\n          context.sent = context._sent = context.arg;\n\n        } else if (context.method === \"throw\") {\n          if (state === GenStateSuspendedStart) {\n            state = GenStateCompleted;\n            throw context.arg;\n          }\n\n          context.dispatchException(context.arg);\n\n        } else if (context.method === \"return\") {\n          context.abrupt(\"return\", context.arg);\n        }\n\n        state = GenStateExecuting;\n\n        var record = tryCatch(innerFn, self, context);\n        if (record.type === \"normal\") {\n          // If an exception is thrown from innerFn, we leave state ===\n          // GenStateExecuting and loop back for another invocation.\n          state = context.done\n            ? GenStateCompleted\n            : GenStateSuspendedYield;\n\n          if (record.arg === ContinueSentinel) {\n            continue;\n          }\n\n          return {\n            value: record.arg,\n            done: context.done\n          };\n\n        } else if (record.type === \"throw\") {\n          state = GenStateCompleted;\n          // Dispatch the exception by looping back around to the\n          // context.dispatchException(context.arg) call above.\n          context.method = \"throw\";\n          context.arg = record.arg;\n        }\n      }\n    };\n  }\n\n  // Call delegate.iterator[context.method](context.arg) and handle the\n  // result, either by returning a { value, done } result from the\n  // delegate iterator, or by modifying context.method and context.arg,\n  // setting context.delegate to null, and returning the ContinueSentinel.\n  function maybeInvokeDelegate(delegate, context) {\n    var method = delegate.iterator[context.method];\n    if (method === undefined) {\n      // A .throw or .return when the delegate iterator has no .throw\n      // method always terminates the yield* loop.\n      context.delegate = null;\n\n      if (context.method === \"throw\") {\n        if (delegate.iterator.return) {\n          // If the delegate iterator has a return method, give it a\n          // chance to clean up.\n          context.method = \"return\";\n          context.arg = undefined;\n          maybeInvokeDelegate(delegate, context);\n\n          if (context.method === \"throw\") {\n            // If maybeInvokeDelegate(context) changed context.method from\n            // \"return\" to \"throw\", let that override the TypeError below.\n            return ContinueSentinel;\n          }\n        }\n\n        context.method = \"throw\";\n        context.arg = new TypeError(\n          \"The iterator does not provide a 'throw' method\");\n      }\n\n      return ContinueSentinel;\n    }\n\n    var record = tryCatch(method, delegate.iterator, context.arg);\n\n    if (record.type === \"throw\") {\n      context.method = \"throw\";\n      context.arg = record.arg;\n      context.delegate = null;\n      return ContinueSentinel;\n    }\n\n    var info = record.arg;\n\n    if (! info) {\n      context.method = \"throw\";\n      context.arg = new TypeError(\"iterator result is not an object\");\n      context.delegate = null;\n      return ContinueSentinel;\n    }\n\n    if (info.done) {\n      // Assign the result of the finished delegate to the temporary\n      // variable specified by delegate.resultName (see delegateYield).\n      context[delegate.resultName] = info.value;\n\n      // Resume execution at the desired location (see delegateYield).\n      context.next = delegate.nextLoc;\n\n      // If context.method was \"throw\" but the delegate handled the\n      // exception, let the outer generator proceed normally. If\n      // context.method was \"next\", forget context.arg since it has been\n      // \"consumed\" by the delegate iterator. If context.method was\n      // \"return\", allow the original .return call to continue in the\n      // outer generator.\n      if (context.method !== \"return\") {\n        context.method = \"next\";\n        context.arg = undefined;\n      }\n\n    } else {\n      // Re-yield the result returned by the delegate method.\n      return info;\n    }\n\n    // The delegate iterator is finished, so forget it and continue with\n    // the outer generator.\n    context.delegate = null;\n    return ContinueSentinel;\n  }\n\n  // Define Generator.prototype.{next,throw,return} in terms of the\n  // unified ._invoke helper method.\n  defineIteratorMethods(Gp);\n\n  Gp[toStringTagSymbol] = \"Generator\";\n\n  // A Generator should always return itself as the iterator object when the\n  // @@iterator function is called on it. Some browsers' implementations of the\n  // iterator prototype chain incorrectly implement this, causing the Generator\n  // object to not be returned from this call. This ensures that doesn't happen.\n  // See https://github.com/facebook/regenerator/issues/274 for more details.\n  Gp[iteratorSymbol] = function() {\n    return this;\n  };\n\n  Gp.toString = function() {\n    return \"[object Generator]\";\n  };\n\n  function pushTryEntry(locs) {\n    var entry = { tryLoc: locs[0] };\n\n    if (1 in locs) {\n      entry.catchLoc = locs[1];\n    }\n\n    if (2 in locs) {\n      entry.finallyLoc = locs[2];\n      entry.afterLoc = locs[3];\n    }\n\n    this.tryEntries.push(entry);\n  }\n\n  function resetTryEntry(entry) {\n    var record = entry.completion || {};\n    record.type = \"normal\";\n    delete record.arg;\n    entry.completion = record;\n  }\n\n  function Context(tryLocsList) {\n    // The root entry object (effectively a try statement without a catch\n    // or a finally block) gives us a place to store values thrown from\n    // locations where there is no enclosing try statement.\n    this.tryEntries = [{ tryLoc: \"root\" }];\n    tryLocsList.forEach(pushTryEntry, this);\n    this.reset(true);\n  }\n\n  runtime.keys = function(object) {\n    var keys = [];\n    for (var key in object) {\n      keys.push(key);\n    }\n    keys.reverse();\n\n    // Rather than returning an object with a next method, we keep\n    // things simple and return the next function itself.\n    return function next() {\n      while (keys.length) {\n        var key = keys.pop();\n        if (key in object) {\n          next.value = key;\n          next.done = false;\n          return next;\n        }\n      }\n\n      // To avoid creating an additional object, we just hang the .value\n      // and .done properties off the next function object itself. This\n      // also ensures that the minifier will not anonymize the function.\n      next.done = true;\n      return next;\n    };\n  };\n\n  function values(iterable) {\n    if (iterable) {\n      var iteratorMethod = iterable[iteratorSymbol];\n      if (iteratorMethod) {\n        return iteratorMethod.call(iterable);\n      }\n\n      if (typeof iterable.next === \"function\") {\n        return iterable;\n      }\n\n      if (!isNaN(iterable.length)) {\n        var i = -1, next = function next() {\n          while (++i < iterable.length) {\n            if (hasOwn.call(iterable, i)) {\n              next.value = iterable[i];\n              next.done = false;\n              return next;\n            }\n          }\n\n          next.value = undefined;\n          next.done = true;\n\n          return next;\n        };\n\n        return next.next = next;\n      }\n    }\n\n    // Return an iterator with no values.\n    return { next: doneResult };\n  }\n  runtime.values = values;\n\n  function doneResult() {\n    return { value: undefined, done: true };\n  }\n\n  Context.prototype = {\n    constructor: Context,\n\n    reset: function(skipTempReset) {\n      this.prev = 0;\n      this.next = 0;\n      // Resetting context._sent for legacy support of Babel's\n      // function.sent implementation.\n      this.sent = this._sent = undefined;\n      this.done = false;\n      this.delegate = null;\n\n      this.method = \"next\";\n      this.arg = undefined;\n\n      this.tryEntries.forEach(resetTryEntry);\n\n      if (!skipTempReset) {\n        for (var name in this) {\n          // Not sure about the optimal order of these conditions:\n          if (name.charAt(0) === \"t\" &&\n              hasOwn.call(this, name) &&\n              !isNaN(+name.slice(1))) {\n            this[name] = undefined;\n          }\n        }\n      }\n    },\n\n    stop: function() {\n      this.done = true;\n\n      var rootEntry = this.tryEntries[0];\n      var rootRecord = rootEntry.completion;\n      if (rootRecord.type === \"throw\") {\n        throw rootRecord.arg;\n      }\n\n      return this.rval;\n    },\n\n    dispatchException: function(exception) {\n      if (this.done) {\n        throw exception;\n      }\n\n      var context = this;\n      function handle(loc, caught) {\n        record.type = \"throw\";\n        record.arg = exception;\n        context.next = loc;\n\n        if (caught) {\n          // If the dispatched exception was caught by a catch block,\n          // then let that catch block handle the exception normally.\n          context.method = \"next\";\n          context.arg = undefined;\n        }\n\n        return !! caught;\n      }\n\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        var record = entry.completion;\n\n        if (entry.tryLoc === \"root\") {\n          // Exception thrown outside of any try block that could handle\n          // it, so set the completion value of the entire function to\n          // throw the exception.\n          return handle(\"end\");\n        }\n\n        if (entry.tryLoc <= this.prev) {\n          var hasCatch = hasOwn.call(entry, \"catchLoc\");\n          var hasFinally = hasOwn.call(entry, \"finallyLoc\");\n\n          if (hasCatch && hasFinally) {\n            if (this.prev < entry.catchLoc) {\n              return handle(entry.catchLoc, true);\n            } else if (this.prev < entry.finallyLoc) {\n              return handle(entry.finallyLoc);\n            }\n\n          } else if (hasCatch) {\n            if (this.prev < entry.catchLoc) {\n              return handle(entry.catchLoc, true);\n            }\n\n          } else if (hasFinally) {\n            if (this.prev < entry.finallyLoc) {\n              return handle(entry.finallyLoc);\n            }\n\n          } else {\n            throw new Error(\"try statement without catch or finally\");\n          }\n        }\n      }\n    },\n\n    abrupt: function(type, arg) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.tryLoc <= this.prev &&\n            hasOwn.call(entry, \"finallyLoc\") &&\n            this.prev < entry.finallyLoc) {\n          var finallyEntry = entry;\n          break;\n        }\n      }\n\n      if (finallyEntry &&\n          (type === \"break\" ||\n           type === \"continue\") &&\n          finallyEntry.tryLoc <= arg &&\n          arg <= finallyEntry.finallyLoc) {\n        // Ignore the finally entry if control is not jumping to a\n        // location outside the try/catch block.\n        finallyEntry = null;\n      }\n\n      var record = finallyEntry ? finallyEntry.completion : {};\n      record.type = type;\n      record.arg = arg;\n\n      if (finallyEntry) {\n        this.method = \"next\";\n        this.next = finallyEntry.finallyLoc;\n        return ContinueSentinel;\n      }\n\n      return this.complete(record);\n    },\n\n    complete: function(record, afterLoc) {\n      if (record.type === \"throw\") {\n        throw record.arg;\n      }\n\n      if (record.type === \"break\" ||\n          record.type === \"continue\") {\n        this.next = record.arg;\n      } else if (record.type === \"return\") {\n        this.rval = this.arg = record.arg;\n        this.method = \"return\";\n        this.next = \"end\";\n      } else if (record.type === \"normal\" && afterLoc) {\n        this.next = afterLoc;\n      }\n\n      return ContinueSentinel;\n    },\n\n    finish: function(finallyLoc) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.finallyLoc === finallyLoc) {\n          this.complete(entry.completion, entry.afterLoc);\n          resetTryEntry(entry);\n          return ContinueSentinel;\n        }\n      }\n    },\n\n    \"catch\": function(tryLoc) {\n      for (var i = this.tryEntries.length - 1; i >= 0; --i) {\n        var entry = this.tryEntries[i];\n        if (entry.tryLoc === tryLoc) {\n          var record = entry.completion;\n          if (record.type === \"throw\") {\n            var thrown = record.arg;\n            resetTryEntry(entry);\n          }\n          return thrown;\n        }\n      }\n\n      // The context.catch method must only be called with a location\n      // argument that corresponds to a known catch block.\n      throw new Error(\"illegal catch attempt\");\n    },\n\n    delegateYield: function(iterable, resultName, nextLoc) {\n      this.delegate = {\n        iterator: values(iterable),\n        resultName: resultName,\n        nextLoc: nextLoc\n      };\n\n      if (this.method === \"next\") {\n        // Deliberately forget the last sent value so that we don't\n        // accidentally pass it on to the delegate.\n        this.arg = undefined;\n      }\n\n      return ContinueSentinel;\n    }\n  };\n})(\n  // Among the various tricks for obtaining a reference to the global\n  // object, this seems to be the most reliable technique that does not\n  // use indirect eval (which violates Content Security Policy).\n  typeof global === \"object\" ? global :\n  typeof window === \"object\" ? window :\n  typeof self === \"object\" ? self : this\n);\n","'use strict'\n\nexports.byteLength = byteLength\nexports.toByteArray = toByteArray\nexports.fromByteArray = fromByteArray\n\nvar lookup = []\nvar revLookup = []\nvar Arr = typeof Uint8Array !== 'undefined' ? Uint8Array : Array\n\nvar code = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'\nfor (var i = 0, len = code.length; i < len; ++i) {\n  lookup[i] = code[i]\n  revLookup[code.charCodeAt(i)] = i\n}\n\n// Support decoding URL-safe base64 strings, as Node.js does.\n// See: https://en.wikipedia.org/wiki/Base64#URL_applications\nrevLookup['-'.charCodeAt(0)] = 62\nrevLookup['_'.charCodeAt(0)] = 63\n\nfunction getLens (b64) {\n  var len = b64.length\n\n  if (len % 4 > 0) {\n    throw new Error('Invalid string. Length must be a multiple of 4')\n  }\n\n  // Trim off extra bytes after placeholder bytes are found\n  // See: https://github.com/beatgammit/base64-js/issues/42\n  var validLen = b64.indexOf('=')\n  if (validLen === -1) validLen = len\n\n  var placeHoldersLen = validLen === len\n    ? 0\n    : 4 - (validLen % 4)\n\n  return [validLen, placeHoldersLen]\n}\n\n// base64 is 4/3 + up to two characters of the original data\nfunction byteLength (b64) {\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction _byteLength (b64, validLen, placeHoldersLen) {\n  return ((validLen + placeHoldersLen) * 3 / 4) - placeHoldersLen\n}\n\nfunction toByteArray (b64) {\n  var tmp\n  var lens = getLens(b64)\n  var validLen = lens[0]\n  var placeHoldersLen = lens[1]\n\n  var arr = new Arr(_byteLength(b64, validLen, placeHoldersLen))\n\n  var curByte = 0\n\n  // if there are placeholders, only get up to the last complete 4 chars\n  var len = placeHoldersLen > 0\n    ? validLen - 4\n    : validLen\n\n  for (var i = 0; i < len; i += 4) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 18) |\n      (revLookup[b64.charCodeAt(i + 1)] << 12) |\n      (revLookup[b64.charCodeAt(i + 2)] << 6) |\n      revLookup[b64.charCodeAt(i + 3)]\n    arr[curByte++] = (tmp >> 16) & 0xFF\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 2) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 2) |\n      (revLookup[b64.charCodeAt(i + 1)] >> 4)\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  if (placeHoldersLen === 1) {\n    tmp =\n      (revLookup[b64.charCodeAt(i)] << 10) |\n      (revLookup[b64.charCodeAt(i + 1)] << 4) |\n      (revLookup[b64.charCodeAt(i + 2)] >> 2)\n    arr[curByte++] = (tmp >> 8) & 0xFF\n    arr[curByte++] = tmp & 0xFF\n  }\n\n  return arr\n}\n\nfunction tripletToBase64 (num) {\n  return lookup[num >> 18 & 0x3F] +\n    lookup[num >> 12 & 0x3F] +\n    lookup[num >> 6 & 0x3F] +\n    lookup[num & 0x3F]\n}\n\nfunction encodeChunk (uint8, start, end) {\n  var tmp\n  var output = []\n  for (var i = start; i < end; i += 3) {\n    tmp =\n      ((uint8[i] << 16) & 0xFF0000) +\n      ((uint8[i + 1] << 8) & 0xFF00) +\n      (uint8[i + 2] & 0xFF)\n    output.push(tripletToBase64(tmp))\n  }\n  return output.join('')\n}\n\nfunction fromByteArray (uint8) {\n  var tmp\n  var len = uint8.length\n  var extraBytes = len % 3 // if we have 1 byte left, pad 2 bytes\n  var parts = []\n  var maxChunkLength = 16383 // must be multiple of 3\n\n  // go through the array every three bytes, we'll deal with trailing stuff later\n  for (var i = 0, len2 = len - extraBytes; i < len2; i += maxChunkLength) {\n    parts.push(encodeChunk(\n      uint8, i, (i + maxChunkLength) > len2 ? len2 : (i + maxChunkLength)\n    ))\n  }\n\n  // pad the end with zeros, but make sure to not forget the extra bytes\n  if (extraBytes === 1) {\n    tmp = uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 2] +\n      lookup[(tmp << 4) & 0x3F] +\n      '=='\n    )\n  } else if (extraBytes === 2) {\n    tmp = (uint8[len - 2] << 8) + uint8[len - 1]\n    parts.push(\n      lookup[tmp >> 10] +\n      lookup[(tmp >> 4) & 0x3F] +\n      lookup[(tmp << 2) & 0x3F] +\n      '='\n    )\n  }\n\n  return parts.join('')\n}\n","/*!\n * The buffer module from node.js, for the browser.\n *\n * @author   Feross Aboukhadijeh <feross@feross.org> <http://feross.org>\n * @license  MIT\n */\n/* eslint-disable no-proto */\n\n'use strict'\n\nvar base64 = require('base64-js')\nvar ieee754 = require('ieee754')\nvar isArray = require('isarray')\n\nexports.Buffer = Buffer\nexports.SlowBuffer = SlowBuffer\nexports.INSPECT_MAX_BYTES = 50\n\n/**\n * If `Buffer.TYPED_ARRAY_SUPPORT`:\n *   === true    Use Uint8Array implementation (fastest)\n *   === false   Use Object implementation (most compatible, even IE6)\n *\n * Browsers that support typed arrays are IE 10+, Firefox 4+, Chrome 7+, Safari 5.1+,\n * Opera 11.6+, iOS 4.2+.\n *\n * Due to various browser bugs, sometimes the Object implementation will be used even\n * when the browser supports typed arrays.\n *\n * Note:\n *\n *   - Firefox 4-29 lacks support for adding new properties to `Uint8Array` instances,\n *     See: https://bugzilla.mozilla.org/show_bug.cgi?id=695438.\n *\n *   - Chrome 9-10 is missing the `TypedArray.prototype.subarray` function.\n *\n *   - IE10 has a broken `TypedArray.prototype.subarray` function which returns arrays of\n *     incorrect length in some situations.\n\n * We detect these buggy browsers and set `Buffer.TYPED_ARRAY_SUPPORT` to `false` so they\n * get the Object implementation, which is slower but behaves correctly.\n */\nBuffer.TYPED_ARRAY_SUPPORT = global.TYPED_ARRAY_SUPPORT !== undefined\n  ? global.TYPED_ARRAY_SUPPORT\n  : typedArraySupport()\n\n/*\n * Export kMaxLength after typed array support is determined.\n */\nexports.kMaxLength = kMaxLength()\n\nfunction typedArraySupport () {\n  try {\n    var arr = new Uint8Array(1)\n    arr.__proto__ = {__proto__: Uint8Array.prototype, foo: function () { return 42 }}\n    return arr.foo() === 42 && // typed array instances can be augmented\n        typeof arr.subarray === 'function' && // chrome 9-10 lack `subarray`\n        arr.subarray(1, 1).byteLength === 0 // ie10 has broken `subarray`\n  } catch (e) {\n    return false\n  }\n}\n\nfunction kMaxLength () {\n  return Buffer.TYPED_ARRAY_SUPPORT\n    ? 0x7fffffff\n    : 0x3fffffff\n}\n\nfunction createBuffer (that, length) {\n  if (kMaxLength() < length) {\n    throw new RangeError('Invalid typed array length')\n  }\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = new Uint8Array(length)\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    if (that === null) {\n      that = new Buffer(length)\n    }\n    that.length = length\n  }\n\n  return that\n}\n\n/**\n * The Buffer constructor returns instances of `Uint8Array` that have their\n * prototype changed to `Buffer.prototype`. Furthermore, `Buffer` is a subclass of\n * `Uint8Array`, so the returned instances will have all the node `Buffer` methods\n * and the `Uint8Array` methods. Square bracket notation works as expected -- it\n * returns a single octet.\n *\n * The `Uint8Array` prototype remains unmodified.\n */\n\nfunction Buffer (arg, encodingOrOffset, length) {\n  if (!Buffer.TYPED_ARRAY_SUPPORT && !(this instanceof Buffer)) {\n    return new Buffer(arg, encodingOrOffset, length)\n  }\n\n  // Common case.\n  if (typeof arg === 'number') {\n    if (typeof encodingOrOffset === 'string') {\n      throw new Error(\n        'If encoding is specified then the first argument must be a string'\n      )\n    }\n    return allocUnsafe(this, arg)\n  }\n  return from(this, arg, encodingOrOffset, length)\n}\n\nBuffer.poolSize = 8192 // not used by this implementation\n\n// TODO: Legacy, not needed anymore. Remove in next major version.\nBuffer._augment = function (arr) {\n  arr.__proto__ = Buffer.prototype\n  return arr\n}\n\nfunction from (that, value, encodingOrOffset, length) {\n  if (typeof value === 'number') {\n    throw new TypeError('\"value\" argument must not be a number')\n  }\n\n  if (typeof ArrayBuffer !== 'undefined' && value instanceof ArrayBuffer) {\n    return fromArrayBuffer(that, value, encodingOrOffset, length)\n  }\n\n  if (typeof value === 'string') {\n    return fromString(that, value, encodingOrOffset)\n  }\n\n  return fromObject(that, value)\n}\n\n/**\n * Functionally equivalent to Buffer(arg, encoding) but throws a TypeError\n * if value is a number.\n * Buffer.from(str[, encoding])\n * Buffer.from(array)\n * Buffer.from(buffer)\n * Buffer.from(arrayBuffer[, byteOffset[, length]])\n **/\nBuffer.from = function (value, encodingOrOffset, length) {\n  return from(null, value, encodingOrOffset, length)\n}\n\nif (Buffer.TYPED_ARRAY_SUPPORT) {\n  Buffer.prototype.__proto__ = Uint8Array.prototype\n  Buffer.__proto__ = Uint8Array\n  if (typeof Symbol !== 'undefined' && Symbol.species &&\n      Buffer[Symbol.species] === Buffer) {\n    // Fix subarray() in ES2016. See: https://github.com/feross/buffer/pull/97\n    Object.defineProperty(Buffer, Symbol.species, {\n      value: null,\n      configurable: true\n    })\n  }\n}\n\nfunction assertSize (size) {\n  if (typeof size !== 'number') {\n    throw new TypeError('\"size\" argument must be a number')\n  } else if (size < 0) {\n    throw new RangeError('\"size\" argument must not be negative')\n  }\n}\n\nfunction alloc (that, size, fill, encoding) {\n  assertSize(size)\n  if (size <= 0) {\n    return createBuffer(that, size)\n  }\n  if (fill !== undefined) {\n    // Only pay attention to encoding if it's a string. This\n    // prevents accidentally sending in a number that would\n    // be interpretted as a start offset.\n    return typeof encoding === 'string'\n      ? createBuffer(that, size).fill(fill, encoding)\n      : createBuffer(that, size).fill(fill)\n  }\n  return createBuffer(that, size)\n}\n\n/**\n * Creates a new filled Buffer instance.\n * alloc(size[, fill[, encoding]])\n **/\nBuffer.alloc = function (size, fill, encoding) {\n  return alloc(null, size, fill, encoding)\n}\n\nfunction allocUnsafe (that, size) {\n  assertSize(size)\n  that = createBuffer(that, size < 0 ? 0 : checked(size) | 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) {\n    for (var i = 0; i < size; ++i) {\n      that[i] = 0\n    }\n  }\n  return that\n}\n\n/**\n * Equivalent to Buffer(num), by default creates a non-zero-filled Buffer instance.\n * */\nBuffer.allocUnsafe = function (size) {\n  return allocUnsafe(null, size)\n}\n/**\n * Equivalent to SlowBuffer(num), by default creates a non-zero-filled Buffer instance.\n */\nBuffer.allocUnsafeSlow = function (size) {\n  return allocUnsafe(null, size)\n}\n\nfunction fromString (that, string, encoding) {\n  if (typeof encoding !== 'string' || encoding === '') {\n    encoding = 'utf8'\n  }\n\n  if (!Buffer.isEncoding(encoding)) {\n    throw new TypeError('\"encoding\" must be a valid string encoding')\n  }\n\n  var length = byteLength(string, encoding) | 0\n  that = createBuffer(that, length)\n\n  var actual = that.write(string, encoding)\n\n  if (actual !== length) {\n    // Writing a hex string, for example, that contains invalid characters will\n    // cause everything after the first invalid character to be ignored. (e.g.\n    // 'abxxcd' will be treated as 'ab')\n    that = that.slice(0, actual)\n  }\n\n  return that\n}\n\nfunction fromArrayLike (that, array) {\n  var length = array.length < 0 ? 0 : checked(array.length) | 0\n  that = createBuffer(that, length)\n  for (var i = 0; i < length; i += 1) {\n    that[i] = array[i] & 255\n  }\n  return that\n}\n\nfunction fromArrayBuffer (that, array, byteOffset, length) {\n  array.byteLength // this throws if `array` is not a valid ArrayBuffer\n\n  if (byteOffset < 0 || array.byteLength < byteOffset) {\n    throw new RangeError('\\'offset\\' is out of bounds')\n  }\n\n  if (array.byteLength < byteOffset + (length || 0)) {\n    throw new RangeError('\\'length\\' is out of bounds')\n  }\n\n  if (byteOffset === undefined && length === undefined) {\n    array = new Uint8Array(array)\n  } else if (length === undefined) {\n    array = new Uint8Array(array, byteOffset)\n  } else {\n    array = new Uint8Array(array, byteOffset, length)\n  }\n\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    // Return an augmented `Uint8Array` instance, for best performance\n    that = array\n    that.__proto__ = Buffer.prototype\n  } else {\n    // Fallback: Return an object instance of the Buffer class\n    that = fromArrayLike(that, array)\n  }\n  return that\n}\n\nfunction fromObject (that, obj) {\n  if (Buffer.isBuffer(obj)) {\n    var len = checked(obj.length) | 0\n    that = createBuffer(that, len)\n\n    if (that.length === 0) {\n      return that\n    }\n\n    obj.copy(that, 0, 0, len)\n    return that\n  }\n\n  if (obj) {\n    if ((typeof ArrayBuffer !== 'undefined' &&\n        obj.buffer instanceof ArrayBuffer) || 'length' in obj) {\n      if (typeof obj.length !== 'number' || isnan(obj.length)) {\n        return createBuffer(that, 0)\n      }\n      return fromArrayLike(that, obj)\n    }\n\n    if (obj.type === 'Buffer' && isArray(obj.data)) {\n      return fromArrayLike(that, obj.data)\n    }\n  }\n\n  throw new TypeError('First argument must be a string, Buffer, ArrayBuffer, Array, or array-like object.')\n}\n\nfunction checked (length) {\n  // Note: cannot use `length < kMaxLength()` here because that fails when\n  // length is NaN (which is otherwise coerced to zero.)\n  if (length >= kMaxLength()) {\n    throw new RangeError('Attempt to allocate Buffer larger than maximum ' +\n                         'size: 0x' + kMaxLength().toString(16) + ' bytes')\n  }\n  return length | 0\n}\n\nfunction SlowBuffer (length) {\n  if (+length != length) { // eslint-disable-line eqeqeq\n    length = 0\n  }\n  return Buffer.alloc(+length)\n}\n\nBuffer.isBuffer = function isBuffer (b) {\n  return !!(b != null && b._isBuffer)\n}\n\nBuffer.compare = function compare (a, b) {\n  if (!Buffer.isBuffer(a) || !Buffer.isBuffer(b)) {\n    throw new TypeError('Arguments must be Buffers')\n  }\n\n  if (a === b) return 0\n\n  var x = a.length\n  var y = b.length\n\n  for (var i = 0, len = Math.min(x, y); i < len; ++i) {\n    if (a[i] !== b[i]) {\n      x = a[i]\n      y = b[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\nBuffer.isEncoding = function isEncoding (encoding) {\n  switch (String(encoding).toLowerCase()) {\n    case 'hex':\n    case 'utf8':\n    case 'utf-8':\n    case 'ascii':\n    case 'latin1':\n    case 'binary':\n    case 'base64':\n    case 'ucs2':\n    case 'ucs-2':\n    case 'utf16le':\n    case 'utf-16le':\n      return true\n    default:\n      return false\n  }\n}\n\nBuffer.concat = function concat (list, length) {\n  if (!isArray(list)) {\n    throw new TypeError('\"list\" argument must be an Array of Buffers')\n  }\n\n  if (list.length === 0) {\n    return Buffer.alloc(0)\n  }\n\n  var i\n  if (length === undefined) {\n    length = 0\n    for (i = 0; i < list.length; ++i) {\n      length += list[i].length\n    }\n  }\n\n  var buffer = Buffer.allocUnsafe(length)\n  var pos = 0\n  for (i = 0; i < list.length; ++i) {\n    var buf = list[i]\n    if (!Buffer.isBuffer(buf)) {\n      throw new TypeError('\"list\" argument must be an Array of Buffers')\n    }\n    buf.copy(buffer, pos)\n    pos += buf.length\n  }\n  return buffer\n}\n\nfunction byteLength (string, encoding) {\n  if (Buffer.isBuffer(string)) {\n    return string.length\n  }\n  if (typeof ArrayBuffer !== 'undefined' && typeof ArrayBuffer.isView === 'function' &&\n      (ArrayBuffer.isView(string) || string instanceof ArrayBuffer)) {\n    return string.byteLength\n  }\n  if (typeof string !== 'string') {\n    string = '' + string\n  }\n\n  var len = string.length\n  if (len === 0) return 0\n\n  // Use a for loop to avoid recursion\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'ascii':\n      case 'latin1':\n      case 'binary':\n        return len\n      case 'utf8':\n      case 'utf-8':\n      case undefined:\n        return utf8ToBytes(string).length\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return len * 2\n      case 'hex':\n        return len >>> 1\n      case 'base64':\n        return base64ToBytes(string).length\n      default:\n        if (loweredCase) return utf8ToBytes(string).length // assume utf8\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\nBuffer.byteLength = byteLength\n\nfunction slowToString (encoding, start, end) {\n  var loweredCase = false\n\n  // No need to verify that \"this.length <= MAX_UINT32\" since it's a read-only\n  // property of a typed array.\n\n  // This behaves neither like String nor Uint8Array in that we set start/end\n  // to their upper/lower bounds if the value passed is out of range.\n  // undefined is handled specially as per ECMA-262 6th Edition,\n  // Section 13.3.3.7 Runtime Semantics: KeyedBindingInitialization.\n  if (start === undefined || start < 0) {\n    start = 0\n  }\n  // Return early if start > this.length. Done here to prevent potential uint32\n  // coercion fail below.\n  if (start > this.length) {\n    return ''\n  }\n\n  if (end === undefined || end > this.length) {\n    end = this.length\n  }\n\n  if (end <= 0) {\n    return ''\n  }\n\n  // Force coersion to uint32. This will also coerce falsey/NaN values to 0.\n  end >>>= 0\n  start >>>= 0\n\n  if (end <= start) {\n    return ''\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  while (true) {\n    switch (encoding) {\n      case 'hex':\n        return hexSlice(this, start, end)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Slice(this, start, end)\n\n      case 'ascii':\n        return asciiSlice(this, start, end)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Slice(this, start, end)\n\n      case 'base64':\n        return base64Slice(this, start, end)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return utf16leSlice(this, start, end)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = (encoding + '').toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\n// The property is used by `Buffer.isBuffer` and `is-buffer` (in Safari 5-7) to detect\n// Buffer instances.\nBuffer.prototype._isBuffer = true\n\nfunction swap (b, n, m) {\n  var i = b[n]\n  b[n] = b[m]\n  b[m] = i\n}\n\nBuffer.prototype.swap16 = function swap16 () {\n  var len = this.length\n  if (len % 2 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 16-bits')\n  }\n  for (var i = 0; i < len; i += 2) {\n    swap(this, i, i + 1)\n  }\n  return this\n}\n\nBuffer.prototype.swap32 = function swap32 () {\n  var len = this.length\n  if (len % 4 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 32-bits')\n  }\n  for (var i = 0; i < len; i += 4) {\n    swap(this, i, i + 3)\n    swap(this, i + 1, i + 2)\n  }\n  return this\n}\n\nBuffer.prototype.swap64 = function swap64 () {\n  var len = this.length\n  if (len % 8 !== 0) {\n    throw new RangeError('Buffer size must be a multiple of 64-bits')\n  }\n  for (var i = 0; i < len; i += 8) {\n    swap(this, i, i + 7)\n    swap(this, i + 1, i + 6)\n    swap(this, i + 2, i + 5)\n    swap(this, i + 3, i + 4)\n  }\n  return this\n}\n\nBuffer.prototype.toString = function toString () {\n  var length = this.length | 0\n  if (length === 0) return ''\n  if (arguments.length === 0) return utf8Slice(this, 0, length)\n  return slowToString.apply(this, arguments)\n}\n\nBuffer.prototype.equals = function equals (b) {\n  if (!Buffer.isBuffer(b)) throw new TypeError('Argument must be a Buffer')\n  if (this === b) return true\n  return Buffer.compare(this, b) === 0\n}\n\nBuffer.prototype.inspect = function inspect () {\n  var str = ''\n  var max = exports.INSPECT_MAX_BYTES\n  if (this.length > 0) {\n    str = this.toString('hex', 0, max).match(/.{2}/g).join(' ')\n    if (this.length > max) str += ' ... '\n  }\n  return '<Buffer ' + str + '>'\n}\n\nBuffer.prototype.compare = function compare (target, start, end, thisStart, thisEnd) {\n  if (!Buffer.isBuffer(target)) {\n    throw new TypeError('Argument must be a Buffer')\n  }\n\n  if (start === undefined) {\n    start = 0\n  }\n  if (end === undefined) {\n    end = target ? target.length : 0\n  }\n  if (thisStart === undefined) {\n    thisStart = 0\n  }\n  if (thisEnd === undefined) {\n    thisEnd = this.length\n  }\n\n  if (start < 0 || end > target.length || thisStart < 0 || thisEnd > this.length) {\n    throw new RangeError('out of range index')\n  }\n\n  if (thisStart >= thisEnd && start >= end) {\n    return 0\n  }\n  if (thisStart >= thisEnd) {\n    return -1\n  }\n  if (start >= end) {\n    return 1\n  }\n\n  start >>>= 0\n  end >>>= 0\n  thisStart >>>= 0\n  thisEnd >>>= 0\n\n  if (this === target) return 0\n\n  var x = thisEnd - thisStart\n  var y = end - start\n  var len = Math.min(x, y)\n\n  var thisCopy = this.slice(thisStart, thisEnd)\n  var targetCopy = target.slice(start, end)\n\n  for (var i = 0; i < len; ++i) {\n    if (thisCopy[i] !== targetCopy[i]) {\n      x = thisCopy[i]\n      y = targetCopy[i]\n      break\n    }\n  }\n\n  if (x < y) return -1\n  if (y < x) return 1\n  return 0\n}\n\n// Finds either the first index of `val` in `buffer` at offset >= `byteOffset`,\n// OR the last index of `val` in `buffer` at offset <= `byteOffset`.\n//\n// Arguments:\n// - buffer - a Buffer to search\n// - val - a string, Buffer, or number\n// - byteOffset - an index into `buffer`; will be clamped to an int32\n// - encoding - an optional encoding, relevant is val is a string\n// - dir - true for indexOf, false for lastIndexOf\nfunction bidirectionalIndexOf (buffer, val, byteOffset, encoding, dir) {\n  // Empty buffer means no match\n  if (buffer.length === 0) return -1\n\n  // Normalize byteOffset\n  if (typeof byteOffset === 'string') {\n    encoding = byteOffset\n    byteOffset = 0\n  } else if (byteOffset > 0x7fffffff) {\n    byteOffset = 0x7fffffff\n  } else if (byteOffset < -0x80000000) {\n    byteOffset = -0x80000000\n  }\n  byteOffset = +byteOffset  // Coerce to Number.\n  if (isNaN(byteOffset)) {\n    // byteOffset: it it's undefined, null, NaN, \"foo\", etc, search whole buffer\n    byteOffset = dir ? 0 : (buffer.length - 1)\n  }\n\n  // Normalize byteOffset: negative offsets start from the end of the buffer\n  if (byteOffset < 0) byteOffset = buffer.length + byteOffset\n  if (byteOffset >= buffer.length) {\n    if (dir) return -1\n    else byteOffset = buffer.length - 1\n  } else if (byteOffset < 0) {\n    if (dir) byteOffset = 0\n    else return -1\n  }\n\n  // Normalize val\n  if (typeof val === 'string') {\n    val = Buffer.from(val, encoding)\n  }\n\n  // Finally, search either indexOf (if dir is true) or lastIndexOf\n  if (Buffer.isBuffer(val)) {\n    // Special case: looking for empty string/buffer always fails\n    if (val.length === 0) {\n      return -1\n    }\n    return arrayIndexOf(buffer, val, byteOffset, encoding, dir)\n  } else if (typeof val === 'number') {\n    val = val & 0xFF // Search for a byte value [0-255]\n    if (Buffer.TYPED_ARRAY_SUPPORT &&\n        typeof Uint8Array.prototype.indexOf === 'function') {\n      if (dir) {\n        return Uint8Array.prototype.indexOf.call(buffer, val, byteOffset)\n      } else {\n        return Uint8Array.prototype.lastIndexOf.call(buffer, val, byteOffset)\n      }\n    }\n    return arrayIndexOf(buffer, [ val ], byteOffset, encoding, dir)\n  }\n\n  throw new TypeError('val must be string, number or Buffer')\n}\n\nfunction arrayIndexOf (arr, val, byteOffset, encoding, dir) {\n  var indexSize = 1\n  var arrLength = arr.length\n  var valLength = val.length\n\n  if (encoding !== undefined) {\n    encoding = String(encoding).toLowerCase()\n    if (encoding === 'ucs2' || encoding === 'ucs-2' ||\n        encoding === 'utf16le' || encoding === 'utf-16le') {\n      if (arr.length < 2 || val.length < 2) {\n        return -1\n      }\n      indexSize = 2\n      arrLength /= 2\n      valLength /= 2\n      byteOffset /= 2\n    }\n  }\n\n  function read (buf, i) {\n    if (indexSize === 1) {\n      return buf[i]\n    } else {\n      return buf.readUInt16BE(i * indexSize)\n    }\n  }\n\n  var i\n  if (dir) {\n    var foundIndex = -1\n    for (i = byteOffset; i < arrLength; i++) {\n      if (read(arr, i) === read(val, foundIndex === -1 ? 0 : i - foundIndex)) {\n        if (foundIndex === -1) foundIndex = i\n        if (i - foundIndex + 1 === valLength) return foundIndex * indexSize\n      } else {\n        if (foundIndex !== -1) i -= i - foundIndex\n        foundIndex = -1\n      }\n    }\n  } else {\n    if (byteOffset + valLength > arrLength) byteOffset = arrLength - valLength\n    for (i = byteOffset; i >= 0; i--) {\n      var found = true\n      for (var j = 0; j < valLength; j++) {\n        if (read(arr, i + j) !== read(val, j)) {\n          found = false\n          break\n        }\n      }\n      if (found) return i\n    }\n  }\n\n  return -1\n}\n\nBuffer.prototype.includes = function includes (val, byteOffset, encoding) {\n  return this.indexOf(val, byteOffset, encoding) !== -1\n}\n\nBuffer.prototype.indexOf = function indexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, true)\n}\n\nBuffer.prototype.lastIndexOf = function lastIndexOf (val, byteOffset, encoding) {\n  return bidirectionalIndexOf(this, val, byteOffset, encoding, false)\n}\n\nfunction hexWrite (buf, string, offset, length) {\n  offset = Number(offset) || 0\n  var remaining = buf.length - offset\n  if (!length) {\n    length = remaining\n  } else {\n    length = Number(length)\n    if (length > remaining) {\n      length = remaining\n    }\n  }\n\n  // must be an even number of digits\n  var strLen = string.length\n  if (strLen % 2 !== 0) throw new TypeError('Invalid hex string')\n\n  if (length > strLen / 2) {\n    length = strLen / 2\n  }\n  for (var i = 0; i < length; ++i) {\n    var parsed = parseInt(string.substr(i * 2, 2), 16)\n    if (isNaN(parsed)) return i\n    buf[offset + i] = parsed\n  }\n  return i\n}\n\nfunction utf8Write (buf, string, offset, length) {\n  return blitBuffer(utf8ToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nfunction asciiWrite (buf, string, offset, length) {\n  return blitBuffer(asciiToBytes(string), buf, offset, length)\n}\n\nfunction latin1Write (buf, string, offset, length) {\n  return asciiWrite(buf, string, offset, length)\n}\n\nfunction base64Write (buf, string, offset, length) {\n  return blitBuffer(base64ToBytes(string), buf, offset, length)\n}\n\nfunction ucs2Write (buf, string, offset, length) {\n  return blitBuffer(utf16leToBytes(string, buf.length - offset), buf, offset, length)\n}\n\nBuffer.prototype.write = function write (string, offset, length, encoding) {\n  // Buffer#write(string)\n  if (offset === undefined) {\n    encoding = 'utf8'\n    length = this.length\n    offset = 0\n  // Buffer#write(string, encoding)\n  } else if (length === undefined && typeof offset === 'string') {\n    encoding = offset\n    length = this.length\n    offset = 0\n  // Buffer#write(string, offset[, length][, encoding])\n  } else if (isFinite(offset)) {\n    offset = offset | 0\n    if (isFinite(length)) {\n      length = length | 0\n      if (encoding === undefined) encoding = 'utf8'\n    } else {\n      encoding = length\n      length = undefined\n    }\n  // legacy write(string, encoding, offset, length) - remove in v0.13\n  } else {\n    throw new Error(\n      'Buffer.write(string, encoding, offset[, length]) is no longer supported'\n    )\n  }\n\n  var remaining = this.length - offset\n  if (length === undefined || length > remaining) length = remaining\n\n  if ((string.length > 0 && (length < 0 || offset < 0)) || offset > this.length) {\n    throw new RangeError('Attempt to write outside buffer bounds')\n  }\n\n  if (!encoding) encoding = 'utf8'\n\n  var loweredCase = false\n  for (;;) {\n    switch (encoding) {\n      case 'hex':\n        return hexWrite(this, string, offset, length)\n\n      case 'utf8':\n      case 'utf-8':\n        return utf8Write(this, string, offset, length)\n\n      case 'ascii':\n        return asciiWrite(this, string, offset, length)\n\n      case 'latin1':\n      case 'binary':\n        return latin1Write(this, string, offset, length)\n\n      case 'base64':\n        // Warning: maxLength not taken into account in base64Write\n        return base64Write(this, string, offset, length)\n\n      case 'ucs2':\n      case 'ucs-2':\n      case 'utf16le':\n      case 'utf-16le':\n        return ucs2Write(this, string, offset, length)\n\n      default:\n        if (loweredCase) throw new TypeError('Unknown encoding: ' + encoding)\n        encoding = ('' + encoding).toLowerCase()\n        loweredCase = true\n    }\n  }\n}\n\nBuffer.prototype.toJSON = function toJSON () {\n  return {\n    type: 'Buffer',\n    data: Array.prototype.slice.call(this._arr || this, 0)\n  }\n}\n\nfunction base64Slice (buf, start, end) {\n  if (start === 0 && end === buf.length) {\n    return base64.fromByteArray(buf)\n  } else {\n    return base64.fromByteArray(buf.slice(start, end))\n  }\n}\n\nfunction utf8Slice (buf, start, end) {\n  end = Math.min(buf.length, end)\n  var res = []\n\n  var i = start\n  while (i < end) {\n    var firstByte = buf[i]\n    var codePoint = null\n    var bytesPerSequence = (firstByte > 0xEF) ? 4\n      : (firstByte > 0xDF) ? 3\n      : (firstByte > 0xBF) ? 2\n      : 1\n\n    if (i + bytesPerSequence <= end) {\n      var secondByte, thirdByte, fourthByte, tempCodePoint\n\n      switch (bytesPerSequence) {\n        case 1:\n          if (firstByte < 0x80) {\n            codePoint = firstByte\n          }\n          break\n        case 2:\n          secondByte = buf[i + 1]\n          if ((secondByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0x1F) << 0x6 | (secondByte & 0x3F)\n            if (tempCodePoint > 0x7F) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 3:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0xC | (secondByte & 0x3F) << 0x6 | (thirdByte & 0x3F)\n            if (tempCodePoint > 0x7FF && (tempCodePoint < 0xD800 || tempCodePoint > 0xDFFF)) {\n              codePoint = tempCodePoint\n            }\n          }\n          break\n        case 4:\n          secondByte = buf[i + 1]\n          thirdByte = buf[i + 2]\n          fourthByte = buf[i + 3]\n          if ((secondByte & 0xC0) === 0x80 && (thirdByte & 0xC0) === 0x80 && (fourthByte & 0xC0) === 0x80) {\n            tempCodePoint = (firstByte & 0xF) << 0x12 | (secondByte & 0x3F) << 0xC | (thirdByte & 0x3F) << 0x6 | (fourthByte & 0x3F)\n            if (tempCodePoint > 0xFFFF && tempCodePoint < 0x110000) {\n              codePoint = tempCodePoint\n            }\n          }\n      }\n    }\n\n    if (codePoint === null) {\n      // we did not generate a valid codePoint so insert a\n      // replacement char (U+FFFD) and advance only 1 byte\n      codePoint = 0xFFFD\n      bytesPerSequence = 1\n    } else if (codePoint > 0xFFFF) {\n      // encode to utf16 (surrogate pair dance)\n      codePoint -= 0x10000\n      res.push(codePoint >>> 10 & 0x3FF | 0xD800)\n      codePoint = 0xDC00 | codePoint & 0x3FF\n    }\n\n    res.push(codePoint)\n    i += bytesPerSequence\n  }\n\n  return decodeCodePointsArray(res)\n}\n\n// Based on http://stackoverflow.com/a/22747272/680742, the browser with\n// the lowest limit is Chrome, with 0x10000 args.\n// We go 1 magnitude less, for safety\nvar MAX_ARGUMENTS_LENGTH = 0x1000\n\nfunction decodeCodePointsArray (codePoints) {\n  var len = codePoints.length\n  if (len <= MAX_ARGUMENTS_LENGTH) {\n    return String.fromCharCode.apply(String, codePoints) // avoid extra slice()\n  }\n\n  // Decode in chunks to avoid \"call stack size exceeded\".\n  var res = ''\n  var i = 0\n  while (i < len) {\n    res += String.fromCharCode.apply(\n      String,\n      codePoints.slice(i, i += MAX_ARGUMENTS_LENGTH)\n    )\n  }\n  return res\n}\n\nfunction asciiSlice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i] & 0x7F)\n  }\n  return ret\n}\n\nfunction latin1Slice (buf, start, end) {\n  var ret = ''\n  end = Math.min(buf.length, end)\n\n  for (var i = start; i < end; ++i) {\n    ret += String.fromCharCode(buf[i])\n  }\n  return ret\n}\n\nfunction hexSlice (buf, start, end) {\n  var len = buf.length\n\n  if (!start || start < 0) start = 0\n  if (!end || end < 0 || end > len) end = len\n\n  var out = ''\n  for (var i = start; i < end; ++i) {\n    out += toHex(buf[i])\n  }\n  return out\n}\n\nfunction utf16leSlice (buf, start, end) {\n  var bytes = buf.slice(start, end)\n  var res = ''\n  for (var i = 0; i < bytes.length; i += 2) {\n    res += String.fromCharCode(bytes[i] + bytes[i + 1] * 256)\n  }\n  return res\n}\n\nBuffer.prototype.slice = function slice (start, end) {\n  var len = this.length\n  start = ~~start\n  end = end === undefined ? len : ~~end\n\n  if (start < 0) {\n    start += len\n    if (start < 0) start = 0\n  } else if (start > len) {\n    start = len\n  }\n\n  if (end < 0) {\n    end += len\n    if (end < 0) end = 0\n  } else if (end > len) {\n    end = len\n  }\n\n  if (end < start) end = start\n\n  var newBuf\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    newBuf = this.subarray(start, end)\n    newBuf.__proto__ = Buffer.prototype\n  } else {\n    var sliceLen = end - start\n    newBuf = new Buffer(sliceLen, undefined)\n    for (var i = 0; i < sliceLen; ++i) {\n      newBuf[i] = this[i + start]\n    }\n  }\n\n  return newBuf\n}\n\n/*\n * Need to make sure that buffer isn't trying to write out of bounds.\n */\nfunction checkOffset (offset, ext, length) {\n  if ((offset % 1) !== 0 || offset < 0) throw new RangeError('offset is not uint')\n  if (offset + ext > length) throw new RangeError('Trying to access beyond buffer length')\n}\n\nBuffer.prototype.readUIntLE = function readUIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUIntBE = function readUIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    checkOffset(offset, byteLength, this.length)\n  }\n\n  var val = this[offset + --byteLength]\n  var mul = 1\n  while (byteLength > 0 && (mul *= 0x100)) {\n    val += this[offset + --byteLength] * mul\n  }\n\n  return val\n}\n\nBuffer.prototype.readUInt8 = function readUInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  return this[offset]\n}\n\nBuffer.prototype.readUInt16LE = function readUInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return this[offset] | (this[offset + 1] << 8)\n}\n\nBuffer.prototype.readUInt16BE = function readUInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  return (this[offset] << 8) | this[offset + 1]\n}\n\nBuffer.prototype.readUInt32LE = function readUInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return ((this[offset]) |\n      (this[offset + 1] << 8) |\n      (this[offset + 2] << 16)) +\n      (this[offset + 3] * 0x1000000)\n}\n\nBuffer.prototype.readUInt32BE = function readUInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] * 0x1000000) +\n    ((this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    this[offset + 3])\n}\n\nBuffer.prototype.readIntLE = function readIntLE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var val = this[offset]\n  var mul = 1\n  var i = 0\n  while (++i < byteLength && (mul *= 0x100)) {\n    val += this[offset + i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readIntBE = function readIntBE (offset, byteLength, noAssert) {\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) checkOffset(offset, byteLength, this.length)\n\n  var i = byteLength\n  var mul = 1\n  var val = this[offset + --i]\n  while (i > 0 && (mul *= 0x100)) {\n    val += this[offset + --i] * mul\n  }\n  mul *= 0x80\n\n  if (val >= mul) val -= Math.pow(2, 8 * byteLength)\n\n  return val\n}\n\nBuffer.prototype.readInt8 = function readInt8 (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 1, this.length)\n  if (!(this[offset] & 0x80)) return (this[offset])\n  return ((0xff - this[offset] + 1) * -1)\n}\n\nBuffer.prototype.readInt16LE = function readInt16LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset] | (this[offset + 1] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt16BE = function readInt16BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 2, this.length)\n  var val = this[offset + 1] | (this[offset] << 8)\n  return (val & 0x8000) ? val | 0xFFFF0000 : val\n}\n\nBuffer.prototype.readInt32LE = function readInt32LE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset]) |\n    (this[offset + 1] << 8) |\n    (this[offset + 2] << 16) |\n    (this[offset + 3] << 24)\n}\n\nBuffer.prototype.readInt32BE = function readInt32BE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n\n  return (this[offset] << 24) |\n    (this[offset + 1] << 16) |\n    (this[offset + 2] << 8) |\n    (this[offset + 3])\n}\n\nBuffer.prototype.readFloatLE = function readFloatLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, true, 23, 4)\n}\n\nBuffer.prototype.readFloatBE = function readFloatBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 4, this.length)\n  return ieee754.read(this, offset, false, 23, 4)\n}\n\nBuffer.prototype.readDoubleLE = function readDoubleLE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, true, 52, 8)\n}\n\nBuffer.prototype.readDoubleBE = function readDoubleBE (offset, noAssert) {\n  if (!noAssert) checkOffset(offset, 8, this.length)\n  return ieee754.read(this, offset, false, 52, 8)\n}\n\nfunction checkInt (buf, value, offset, ext, max, min) {\n  if (!Buffer.isBuffer(buf)) throw new TypeError('\"buffer\" argument must be a Buffer instance')\n  if (value > max || value < min) throw new RangeError('\"value\" argument is out of bounds')\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n}\n\nBuffer.prototype.writeUIntLE = function writeUIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var mul = 1\n  var i = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUIntBE = function writeUIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  byteLength = byteLength | 0\n  if (!noAssert) {\n    var maxBytes = Math.pow(2, 8 * byteLength) - 1\n    checkInt(this, value, offset, byteLength, maxBytes, 0)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    this[offset + i] = (value / mul) & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeUInt8 = function writeUInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0xff, 0)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nfunction objectWriteUInt16 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 2); i < j; ++i) {\n    buf[offset + i] = (value & (0xff << (8 * (littleEndian ? i : 1 - i)))) >>>\n      (littleEndian ? i : 1 - i) * 8\n  }\n}\n\nBuffer.prototype.writeUInt16LE = function writeUInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeUInt16BE = function writeUInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0xffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nfunction objectWriteUInt32 (buf, value, offset, littleEndian) {\n  if (value < 0) value = 0xffffffff + value + 1\n  for (var i = 0, j = Math.min(buf.length - offset, 4); i < j; ++i) {\n    buf[offset + i] = (value >>> (littleEndian ? i : 3 - i) * 8) & 0xff\n  }\n}\n\nBuffer.prototype.writeUInt32LE = function writeUInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset + 3] = (value >>> 24)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 1] = (value >>> 8)\n    this[offset] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeUInt32BE = function writeUInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0xffffffff, 0)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeIntLE = function writeIntLE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = 0\n  var mul = 1\n  var sub = 0\n  this[offset] = value & 0xFF\n  while (++i < byteLength && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i - 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeIntBE = function writeIntBE (value, offset, byteLength, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) {\n    var limit = Math.pow(2, 8 * byteLength - 1)\n\n    checkInt(this, value, offset, byteLength, limit - 1, -limit)\n  }\n\n  var i = byteLength - 1\n  var mul = 1\n  var sub = 0\n  this[offset + i] = value & 0xFF\n  while (--i >= 0 && (mul *= 0x100)) {\n    if (value < 0 && sub === 0 && this[offset + i + 1] !== 0) {\n      sub = 1\n    }\n    this[offset + i] = ((value / mul) >> 0) - sub & 0xFF\n  }\n\n  return offset + byteLength\n}\n\nBuffer.prototype.writeInt8 = function writeInt8 (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 1, 0x7f, -0x80)\n  if (!Buffer.TYPED_ARRAY_SUPPORT) value = Math.floor(value)\n  if (value < 0) value = 0xff + value + 1\n  this[offset] = (value & 0xff)\n  return offset + 1\n}\n\nBuffer.prototype.writeInt16LE = function writeInt16LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n  } else {\n    objectWriteUInt16(this, value, offset, true)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt16BE = function writeInt16BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 2, 0x7fff, -0x8000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 8)\n    this[offset + 1] = (value & 0xff)\n  } else {\n    objectWriteUInt16(this, value, offset, false)\n  }\n  return offset + 2\n}\n\nBuffer.prototype.writeInt32LE = function writeInt32LE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value & 0xff)\n    this[offset + 1] = (value >>> 8)\n    this[offset + 2] = (value >>> 16)\n    this[offset + 3] = (value >>> 24)\n  } else {\n    objectWriteUInt32(this, value, offset, true)\n  }\n  return offset + 4\n}\n\nBuffer.prototype.writeInt32BE = function writeInt32BE (value, offset, noAssert) {\n  value = +value\n  offset = offset | 0\n  if (!noAssert) checkInt(this, value, offset, 4, 0x7fffffff, -0x80000000)\n  if (value < 0) value = 0xffffffff + value + 1\n  if (Buffer.TYPED_ARRAY_SUPPORT) {\n    this[offset] = (value >>> 24)\n    this[offset + 1] = (value >>> 16)\n    this[offset + 2] = (value >>> 8)\n    this[offset + 3] = (value & 0xff)\n  } else {\n    objectWriteUInt32(this, value, offset, false)\n  }\n  return offset + 4\n}\n\nfunction checkIEEE754 (buf, value, offset, ext, max, min) {\n  if (offset + ext > buf.length) throw new RangeError('Index out of range')\n  if (offset < 0) throw new RangeError('Index out of range')\n}\n\nfunction writeFloat (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 4, 3.4028234663852886e+38, -3.4028234663852886e+38)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 23, 4)\n  return offset + 4\n}\n\nBuffer.prototype.writeFloatLE = function writeFloatLE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeFloatBE = function writeFloatBE (value, offset, noAssert) {\n  return writeFloat(this, value, offset, false, noAssert)\n}\n\nfunction writeDouble (buf, value, offset, littleEndian, noAssert) {\n  if (!noAssert) {\n    checkIEEE754(buf, value, offset, 8, 1.7976931348623157E+308, -1.7976931348623157E+308)\n  }\n  ieee754.write(buf, value, offset, littleEndian, 52, 8)\n  return offset + 8\n}\n\nBuffer.prototype.writeDoubleLE = function writeDoubleLE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, true, noAssert)\n}\n\nBuffer.prototype.writeDoubleBE = function writeDoubleBE (value, offset, noAssert) {\n  return writeDouble(this, value, offset, false, noAssert)\n}\n\n// copy(targetBuffer, targetStart=0, sourceStart=0, sourceEnd=buffer.length)\nBuffer.prototype.copy = function copy (target, targetStart, start, end) {\n  if (!start) start = 0\n  if (!end && end !== 0) end = this.length\n  if (targetStart >= target.length) targetStart = target.length\n  if (!targetStart) targetStart = 0\n  if (end > 0 && end < start) end = start\n\n  // Copy 0 bytes; we're done\n  if (end === start) return 0\n  if (target.length === 0 || this.length === 0) return 0\n\n  // Fatal error conditions\n  if (targetStart < 0) {\n    throw new RangeError('targetStart out of bounds')\n  }\n  if (start < 0 || start >= this.length) throw new RangeError('sourceStart out of bounds')\n  if (end < 0) throw new RangeError('sourceEnd out of bounds')\n\n  // Are we oob?\n  if (end > this.length) end = this.length\n  if (target.length - targetStart < end - start) {\n    end = target.length - targetStart + start\n  }\n\n  var len = end - start\n  var i\n\n  if (this === target && start < targetStart && targetStart < end) {\n    // descending copy from end\n    for (i = len - 1; i >= 0; --i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else if (len < 1000 || !Buffer.TYPED_ARRAY_SUPPORT) {\n    // ascending copy from start\n    for (i = 0; i < len; ++i) {\n      target[i + targetStart] = this[i + start]\n    }\n  } else {\n    Uint8Array.prototype.set.call(\n      target,\n      this.subarray(start, start + len),\n      targetStart\n    )\n  }\n\n  return len\n}\n\n// Usage:\n//    buffer.fill(number[, offset[, end]])\n//    buffer.fill(buffer[, offset[, end]])\n//    buffer.fill(string[, offset[, end]][, encoding])\nBuffer.prototype.fill = function fill (val, start, end, encoding) {\n  // Handle string cases:\n  if (typeof val === 'string') {\n    if (typeof start === 'string') {\n      encoding = start\n      start = 0\n      end = this.length\n    } else if (typeof end === 'string') {\n      encoding = end\n      end = this.length\n    }\n    if (val.length === 1) {\n      var code = val.charCodeAt(0)\n      if (code < 256) {\n        val = code\n      }\n    }\n    if (encoding !== undefined && typeof encoding !== 'string') {\n      throw new TypeError('encoding must be a string')\n    }\n    if (typeof encoding === 'string' && !Buffer.isEncoding(encoding)) {\n      throw new TypeError('Unknown encoding: ' + encoding)\n    }\n  } else if (typeof val === 'number') {\n    val = val & 255\n  }\n\n  // Invalid ranges are not set to a default, so can range check early.\n  if (start < 0 || this.length < start || this.length < end) {\n    throw new RangeError('Out of range index')\n  }\n\n  if (end <= start) {\n    return this\n  }\n\n  start = start >>> 0\n  end = end === undefined ? this.length : end >>> 0\n\n  if (!val) val = 0\n\n  var i\n  if (typeof val === 'number') {\n    for (i = start; i < end; ++i) {\n      this[i] = val\n    }\n  } else {\n    var bytes = Buffer.isBuffer(val)\n      ? val\n      : utf8ToBytes(new Buffer(val, encoding).toString())\n    var len = bytes.length\n    for (i = 0; i < end - start; ++i) {\n      this[i + start] = bytes[i % len]\n    }\n  }\n\n  return this\n}\n\n// HELPER FUNCTIONS\n// ================\n\nvar INVALID_BASE64_RE = /[^+\\/0-9A-Za-z-_]/g\n\nfunction base64clean (str) {\n  // Node strips out invalid characters like \\n and \\t from the string, base64-js does not\n  str = stringtrim(str).replace(INVALID_BASE64_RE, '')\n  // Node converts strings with length < 2 to ''\n  if (str.length < 2) return ''\n  // Node allows for non-padded base64 strings (missing trailing ===), base64-js does not\n  while (str.length % 4 !== 0) {\n    str = str + '='\n  }\n  return str\n}\n\nfunction stringtrim (str) {\n  if (str.trim) return str.trim()\n  return str.replace(/^\\s+|\\s+$/g, '')\n}\n\nfunction toHex (n) {\n  if (n < 16) return '0' + n.toString(16)\n  return n.toString(16)\n}\n\nfunction utf8ToBytes (string, units) {\n  units = units || Infinity\n  var codePoint\n  var length = string.length\n  var leadSurrogate = null\n  var bytes = []\n\n  for (var i = 0; i < length; ++i) {\n    codePoint = string.charCodeAt(i)\n\n    // is surrogate component\n    if (codePoint > 0xD7FF && codePoint < 0xE000) {\n      // last char was a lead\n      if (!leadSurrogate) {\n        // no lead yet\n        if (codePoint > 0xDBFF) {\n          // unexpected trail\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        } else if (i + 1 === length) {\n          // unpaired lead\n          if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n          continue\n        }\n\n        // valid lead\n        leadSurrogate = codePoint\n\n        continue\n      }\n\n      // 2 leads in a row\n      if (codePoint < 0xDC00) {\n        if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n        leadSurrogate = codePoint\n        continue\n      }\n\n      // valid surrogate pair\n      codePoint = (leadSurrogate - 0xD800 << 10 | codePoint - 0xDC00) + 0x10000\n    } else if (leadSurrogate) {\n      // valid bmp char, but last char was a lead\n      if ((units -= 3) > -1) bytes.push(0xEF, 0xBF, 0xBD)\n    }\n\n    leadSurrogate = null\n\n    // encode utf8\n    if (codePoint < 0x80) {\n      if ((units -= 1) < 0) break\n      bytes.push(codePoint)\n    } else if (codePoint < 0x800) {\n      if ((units -= 2) < 0) break\n      bytes.push(\n        codePoint >> 0x6 | 0xC0,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x10000) {\n      if ((units -= 3) < 0) break\n      bytes.push(\n        codePoint >> 0xC | 0xE0,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else if (codePoint < 0x110000) {\n      if ((units -= 4) < 0) break\n      bytes.push(\n        codePoint >> 0x12 | 0xF0,\n        codePoint >> 0xC & 0x3F | 0x80,\n        codePoint >> 0x6 & 0x3F | 0x80,\n        codePoint & 0x3F | 0x80\n      )\n    } else {\n      throw new Error('Invalid code point')\n    }\n  }\n\n  return bytes\n}\n\nfunction asciiToBytes (str) {\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    // Node's code seems to be doing this and not & 0x7F..\n    byteArray.push(str.charCodeAt(i) & 0xFF)\n  }\n  return byteArray\n}\n\nfunction utf16leToBytes (str, units) {\n  var c, hi, lo\n  var byteArray = []\n  for (var i = 0; i < str.length; ++i) {\n    if ((units -= 2) < 0) break\n\n    c = str.charCodeAt(i)\n    hi = c >> 8\n    lo = c % 256\n    byteArray.push(lo)\n    byteArray.push(hi)\n  }\n\n  return byteArray\n}\n\nfunction base64ToBytes (str) {\n  return base64.toByteArray(base64clean(str))\n}\n\nfunction blitBuffer (src, dst, offset, length) {\n  for (var i = 0; i < length; ++i) {\n    if ((i + offset >= dst.length) || (i >= src.length)) break\n    dst[i + offset] = src[i]\n  }\n  return i\n}\n\nfunction isnan (val) {\n  return val !== val // eslint-disable-line no-self-compare\n}\n","var toString = {}.toString;\n\nmodule.exports = Array.isArray || function (arr) {\n  return toString.call(arr) == '[object Array]';\n};\n","require('../../modules/core.regexp.escape');\nmodule.exports = require('../../modules/_core').RegExp.escape;\n","module.exports = function (it) {\n  if (typeof it != 'function') throw TypeError(it + ' is not a function!');\n  return it;\n};\n","var cof = require('./_cof');\nmodule.exports = function (it, msg) {\n  if (typeof it != 'number' && cof(it) != 'Number') throw TypeError(msg);\n  return +it;\n};\n","// 22.1.3.31 Array.prototype[@@unscopables]\nvar UNSCOPABLES = require('./_wks')('unscopables');\nvar ArrayProto = Array.prototype;\nif (ArrayProto[UNSCOPABLES] == undefined) require('./_hide')(ArrayProto, UNSCOPABLES, {});\nmodule.exports = function (key) {\n  ArrayProto[UNSCOPABLES][key] = true;\n};\n","'use strict';\nvar at = require('./_string-at')(true);\n\n // `AdvanceStringIndex` abstract operation\n// https://tc39.github.io/ecma262/#sec-advancestringindex\nmodule.exports = function (S, index, unicode) {\n  return index + (unicode ? at(S, index).length : 1);\n};\n","module.exports = function (it, Constructor, name, forbiddenField) {\n  if (!(it instanceof Constructor) || (forbiddenField !== undefined && forbiddenField in it)) {\n    throw TypeError(name + ': incorrect invocation!');\n  } return it;\n};\n","var isObject = require('./_is-object');\nmodule.exports = function (it) {\n  if (!isObject(it)) throw TypeError(it + ' is not an object!');\n  return it;\n};\n","// 22.1.3.3 Array.prototype.copyWithin(target, start, end = this.length)\n'use strict';\nvar toObject = require('./_to-object');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nvar toLength = require('./_to-length');\n\nmodule.exports = [].copyWithin || function copyWithin(target /* = 0 */, start /* = 0, end = @length */) {\n  var O = toObject(this);\n  var len = toLength(O.length);\n  var to = toAbsoluteIndex(target, len);\n  var from = toAbsoluteIndex(start, len);\n  var end = arguments.length > 2 ? arguments[2] : undefined;\n  var count = Math.min((end === undefined ? len : toAbsoluteIndex(end, len)) - from, len - to);\n  var inc = 1;\n  if (from < to && to < from + count) {\n    inc = -1;\n    from += count - 1;\n    to += count - 1;\n  }\n  while (count-- > 0) {\n    if (from in O) O[to] = O[from];\n    else delete O[to];\n    to += inc;\n    from += inc;\n  } return O;\n};\n","// 22.1.3.6 Array.prototype.fill(value, start = 0, end = this.length)\n'use strict';\nvar toObject = require('./_to-object');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nvar toLength = require('./_to-length');\nmodule.exports = function fill(value /* , start = 0, end = @length */) {\n  var O = toObject(this);\n  var length = toLength(O.length);\n  var aLen = arguments.length;\n  var index = toAbsoluteIndex(aLen > 1 ? arguments[1] : undefined, length);\n  var end = aLen > 2 ? arguments[2] : undefined;\n  var endPos = end === undefined ? length : toAbsoluteIndex(end, length);\n  while (endPos > index) O[index++] = value;\n  return O;\n};\n","var forOf = require('./_for-of');\n\nmodule.exports = function (iter, ITERATOR) {\n  var result = [];\n  forOf(iter, false, result.push, result, ITERATOR);\n  return result;\n};\n","// false -> Array#indexOf\n// true  -> Array#includes\nvar toIObject = require('./_to-iobject');\nvar toLength = require('./_to-length');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nmodule.exports = function (IS_INCLUDES) {\n  return function ($this, el, fromIndex) {\n    var O = toIObject($this);\n    var length = toLength(O.length);\n    var index = toAbsoluteIndex(fromIndex, length);\n    var value;\n    // Array#includes uses SameValueZero equality algorithm\n    // eslint-disable-next-line no-self-compare\n    if (IS_INCLUDES && el != el) while (length > index) {\n      value = O[index++];\n      // eslint-disable-next-line no-self-compare\n      if (value != value) return true;\n    // Array#indexOf ignores holes, Array#includes - not\n    } else for (;length > index; index++) if (IS_INCLUDES || index in O) {\n      if (O[index] === el) return IS_INCLUDES || index || 0;\n    } return !IS_INCLUDES && -1;\n  };\n};\n","// 0 -> Array#forEach\n// 1 -> Array#map\n// 2 -> Array#filter\n// 3 -> Array#some\n// 4 -> Array#every\n// 5 -> Array#find\n// 6 -> Array#findIndex\nvar ctx = require('./_ctx');\nvar IObject = require('./_iobject');\nvar toObject = require('./_to-object');\nvar toLength = require('./_to-length');\nvar asc = require('./_array-species-create');\nmodule.exports = function (TYPE, $create) {\n  var IS_MAP = TYPE == 1;\n  var IS_FILTER = TYPE == 2;\n  var IS_SOME = TYPE == 3;\n  var IS_EVERY = TYPE == 4;\n  var IS_FIND_INDEX = TYPE == 6;\n  var NO_HOLES = TYPE == 5 || IS_FIND_INDEX;\n  var create = $create || asc;\n  return function ($this, callbackfn, that) {\n    var O = toObject($this);\n    var self = IObject(O);\n    var f = ctx(callbackfn, that, 3);\n    var length = toLength(self.length);\n    var index = 0;\n    var result = IS_MAP ? create($this, length) : IS_FILTER ? create($this, 0) : undefined;\n    var val, res;\n    for (;length > index; index++) if (NO_HOLES || index in self) {\n      val = self[index];\n      res = f(val, index, O);\n      if (TYPE) {\n        if (IS_MAP) result[index] = res;   // map\n        else if (res) switch (TYPE) {\n          case 3: return true;             // some\n          case 5: return val;              // find\n          case 6: return index;            // findIndex\n          case 2: result.push(val);        // filter\n        } else if (IS_EVERY) return false; // every\n      }\n    }\n    return IS_FIND_INDEX ? -1 : IS_SOME || IS_EVERY ? IS_EVERY : result;\n  };\n};\n","var aFunction = require('./_a-function');\nvar toObject = require('./_to-object');\nvar IObject = require('./_iobject');\nvar toLength = require('./_to-length');\n\nmodule.exports = function (that, callbackfn, aLen, memo, isRight) {\n  aFunction(callbackfn);\n  var O = toObject(that);\n  var self = IObject(O);\n  var length = toLength(O.length);\n  var index = isRight ? length - 1 : 0;\n  var i = isRight ? -1 : 1;\n  if (aLen < 2) for (;;) {\n    if (index in self) {\n      memo = self[index];\n      index += i;\n      break;\n    }\n    index += i;\n    if (isRight ? index < 0 : length <= index) {\n      throw TypeError('Reduce of empty array with no initial value');\n    }\n  }\n  for (;isRight ? index >= 0 : length > index; index += i) if (index in self) {\n    memo = callbackfn(memo, self[index], index, O);\n  }\n  return memo;\n};\n","var isObject = require('./_is-object');\nvar isArray = require('./_is-array');\nvar SPECIES = require('./_wks')('species');\n\nmodule.exports = function (original) {\n  var C;\n  if (isArray(original)) {\n    C = original.constructor;\n    // cross-realm fallback\n    if (typeof C == 'function' && (C === Array || isArray(C.prototype))) C = undefined;\n    if (isObject(C)) {\n      C = C[SPECIES];\n      if (C === null) C = undefined;\n    }\n  } return C === undefined ? Array : C;\n};\n","// 9.4.2.3 ArraySpeciesCreate(originalArray, length)\nvar speciesConstructor = require('./_array-species-constructor');\n\nmodule.exports = function (original, length) {\n  return new (speciesConstructor(original))(length);\n};\n","'use strict';\nvar aFunction = require('./_a-function');\nvar isObject = require('./_is-object');\nvar invoke = require('./_invoke');\nvar arraySlice = [].slice;\nvar factories = {};\n\nvar construct = function (F, len, args) {\n  if (!(len in factories)) {\n    for (var n = [], i = 0; i < len; i++) n[i] = 'a[' + i + ']';\n    // eslint-disable-next-line no-new-func\n    factories[len] = Function('F,a', 'return new F(' + n.join(',') + ')');\n  } return factories[len](F, args);\n};\n\nmodule.exports = Function.bind || function bind(that /* , ...args */) {\n  var fn = aFunction(this);\n  var partArgs = arraySlice.call(arguments, 1);\n  var bound = function (/* args... */) {\n    var args = partArgs.concat(arraySlice.call(arguments));\n    return this instanceof bound ? construct(fn, args.length, args) : invoke(fn, args, that);\n  };\n  if (isObject(fn.prototype)) bound.prototype = fn.prototype;\n  return bound;\n};\n","// getting tag from 19.1.3.6 Object.prototype.toString()\nvar cof = require('./_cof');\nvar TAG = require('./_wks')('toStringTag');\n// ES3 wrong here\nvar ARG = cof(function () { return arguments; }()) == 'Arguments';\n\n// fallback for IE11 Script Access Denied error\nvar tryGet = function (it, key) {\n  try {\n    return it[key];\n  } catch (e) { /* empty */ }\n};\n\nmodule.exports = function (it) {\n  var O, T, B;\n  return it === undefined ? 'Undefined' : it === null ? 'Null'\n    // @@toStringTag case\n    : typeof (T = tryGet(O = Object(it), TAG)) == 'string' ? T\n    // builtinTag case\n    : ARG ? cof(O)\n    // ES3 arguments fallback\n    : (B = cof(O)) == 'Object' && typeof O.callee == 'function' ? 'Arguments' : B;\n};\n","var toString = {}.toString;\n\nmodule.exports = function (it) {\n  return toString.call(it).slice(8, -1);\n};\n","'use strict';\nvar dP = require('./_object-dp').f;\nvar create = require('./_object-create');\nvar redefineAll = require('./_redefine-all');\nvar ctx = require('./_ctx');\nvar anInstance = require('./_an-instance');\nvar forOf = require('./_for-of');\nvar $iterDefine = require('./_iter-define');\nvar step = require('./_iter-step');\nvar setSpecies = require('./_set-species');\nvar DESCRIPTORS = require('./_descriptors');\nvar fastKey = require('./_meta').fastKey;\nvar validate = require('./_validate-collection');\nvar SIZE = DESCRIPTORS ? '_s' : 'size';\n\nvar getEntry = function (that, key) {\n  // fast case\n  var index = fastKey(key);\n  var entry;\n  if (index !== 'F') return that._i[index];\n  // frozen object case\n  for (entry = that._f; entry; entry = entry.n) {\n    if (entry.k == key) return entry;\n  }\n};\n\nmodule.exports = {\n  getConstructor: function (wrapper, NAME, IS_MAP, ADDER) {\n    var C = wrapper(function (that, iterable) {\n      anInstance(that, C, NAME, '_i');\n      that._t = NAME;         // collection type\n      that._i = create(null); // index\n      that._f = undefined;    // first entry\n      that._l = undefined;    // last entry\n      that[SIZE] = 0;         // size\n      if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n    });\n    redefineAll(C.prototype, {\n      // 23.1.3.1 Map.prototype.clear()\n      // 23.2.3.2 Set.prototype.clear()\n      clear: function clear() {\n        for (var that = validate(this, NAME), data = that._i, entry = that._f; entry; entry = entry.n) {\n          entry.r = true;\n          if (entry.p) entry.p = entry.p.n = undefined;\n          delete data[entry.i];\n        }\n        that._f = that._l = undefined;\n        that[SIZE] = 0;\n      },\n      // 23.1.3.3 Map.prototype.delete(key)\n      // 23.2.3.4 Set.prototype.delete(value)\n      'delete': function (key) {\n        var that = validate(this, NAME);\n        var entry = getEntry(that, key);\n        if (entry) {\n          var next = entry.n;\n          var prev = entry.p;\n          delete that._i[entry.i];\n          entry.r = true;\n          if (prev) prev.n = next;\n          if (next) next.p = prev;\n          if (that._f == entry) that._f = next;\n          if (that._l == entry) that._l = prev;\n          that[SIZE]--;\n        } return !!entry;\n      },\n      // 23.2.3.6 Set.prototype.forEach(callbackfn, thisArg = undefined)\n      // 23.1.3.5 Map.prototype.forEach(callbackfn, thisArg = undefined)\n      forEach: function forEach(callbackfn /* , that = undefined */) {\n        validate(this, NAME);\n        var f = ctx(callbackfn, arguments.length > 1 ? arguments[1] : undefined, 3);\n        var entry;\n        while (entry = entry ? entry.n : this._f) {\n          f(entry.v, entry.k, this);\n          // revert to the last existing entry\n          while (entry && entry.r) entry = entry.p;\n        }\n      },\n      // 23.1.3.7 Map.prototype.has(key)\n      // 23.2.3.7 Set.prototype.has(value)\n      has: function has(key) {\n        return !!getEntry(validate(this, NAME), key);\n      }\n    });\n    if (DESCRIPTORS) dP(C.prototype, 'size', {\n      get: function () {\n        return validate(this, NAME)[SIZE];\n      }\n    });\n    return C;\n  },\n  def: function (that, key, value) {\n    var entry = getEntry(that, key);\n    var prev, index;\n    // change existing entry\n    if (entry) {\n      entry.v = value;\n    // create new entry\n    } else {\n      that._l = entry = {\n        i: index = fastKey(key, true), // <- index\n        k: key,                        // <- key\n        v: value,                      // <- value\n        p: prev = that._l,             // <- previous entry\n        n: undefined,                  // <- next entry\n        r: false                       // <- removed\n      };\n      if (!that._f) that._f = entry;\n      if (prev) prev.n = entry;\n      that[SIZE]++;\n      // add to index\n      if (index !== 'F') that._i[index] = entry;\n    } return that;\n  },\n  getEntry: getEntry,\n  setStrong: function (C, NAME, IS_MAP) {\n    // add .keys, .values, .entries, [@@iterator]\n    // 23.1.3.4, 23.1.3.8, 23.1.3.11, 23.1.3.12, 23.2.3.5, 23.2.3.8, 23.2.3.10, 23.2.3.11\n    $iterDefine(C, NAME, function (iterated, kind) {\n      this._t = validate(iterated, NAME); // target\n      this._k = kind;                     // kind\n      this._l = undefined;                // previous\n    }, function () {\n      var that = this;\n      var kind = that._k;\n      var entry = that._l;\n      // revert to the last existing entry\n      while (entry && entry.r) entry = entry.p;\n      // get next entry\n      if (!that._t || !(that._l = entry = entry ? entry.n : that._t._f)) {\n        // or finish the iteration\n        that._t = undefined;\n        return step(1);\n      }\n      // return step by kind\n      if (kind == 'keys') return step(0, entry.k);\n      if (kind == 'values') return step(0, entry.v);\n      return step(0, [entry.k, entry.v]);\n    }, IS_MAP ? 'entries' : 'values', !IS_MAP, true);\n\n    // add [@@species], 23.1.2.2, 23.2.2.2\n    setSpecies(NAME);\n  }\n};\n","// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar classof = require('./_classof');\nvar from = require('./_array-from-iterable');\nmodule.exports = function (NAME) {\n  return function toJSON() {\n    if (classof(this) != NAME) throw TypeError(NAME + \"#toJSON isn't generic\");\n    return from(this);\n  };\n};\n","'use strict';\nvar redefineAll = require('./_redefine-all');\nvar getWeak = require('./_meta').getWeak;\nvar anObject = require('./_an-object');\nvar isObject = require('./_is-object');\nvar anInstance = require('./_an-instance');\nvar forOf = require('./_for-of');\nvar createArrayMethod = require('./_array-methods');\nvar $has = require('./_has');\nvar validate = require('./_validate-collection');\nvar arrayFind = createArrayMethod(5);\nvar arrayFindIndex = createArrayMethod(6);\nvar id = 0;\n\n// fallback for uncaught frozen keys\nvar uncaughtFrozenStore = function (that) {\n  return that._l || (that._l = new UncaughtFrozenStore());\n};\nvar UncaughtFrozenStore = function () {\n  this.a = [];\n};\nvar findUncaughtFrozen = function (store, key) {\n  return arrayFind(store.a, function (it) {\n    return it[0] === key;\n  });\n};\nUncaughtFrozenStore.prototype = {\n  get: function (key) {\n    var entry = findUncaughtFrozen(this, key);\n    if (entry) return entry[1];\n  },\n  has: function (key) {\n    return !!findUncaughtFrozen(this, key);\n  },\n  set: function (key, value) {\n    var entry = findUncaughtFrozen(this, key);\n    if (entry) entry[1] = value;\n    else this.a.push([key, value]);\n  },\n  'delete': function (key) {\n    var index = arrayFindIndex(this.a, function (it) {\n      return it[0] === key;\n    });\n    if (~index) this.a.splice(index, 1);\n    return !!~index;\n  }\n};\n\nmodule.exports = {\n  getConstructor: function (wrapper, NAME, IS_MAP, ADDER) {\n    var C = wrapper(function (that, iterable) {\n      anInstance(that, C, NAME, '_i');\n      that._t = NAME;      // collection type\n      that._i = id++;      // collection id\n      that._l = undefined; // leak store for uncaught frozen objects\n      if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n    });\n    redefineAll(C.prototype, {\n      // 23.3.3.2 WeakMap.prototype.delete(key)\n      // 23.4.3.3 WeakSet.prototype.delete(value)\n      'delete': function (key) {\n        if (!isObject(key)) return false;\n        var data = getWeak(key);\n        if (data === true) return uncaughtFrozenStore(validate(this, NAME))['delete'](key);\n        return data && $has(data, this._i) && delete data[this._i];\n      },\n      // 23.3.3.4 WeakMap.prototype.has(key)\n      // 23.4.3.4 WeakSet.prototype.has(value)\n      has: function has(key) {\n        if (!isObject(key)) return false;\n        var data = getWeak(key);\n        if (data === true) return uncaughtFrozenStore(validate(this, NAME)).has(key);\n        return data && $has(data, this._i);\n      }\n    });\n    return C;\n  },\n  def: function (that, key, value) {\n    var data = getWeak(anObject(key), true);\n    if (data === true) uncaughtFrozenStore(that).set(key, value);\n    else data[that._i] = value;\n    return that;\n  },\n  ufstore: uncaughtFrozenStore\n};\n","'use strict';\nvar global = require('./_global');\nvar $export = require('./_export');\nvar redefine = require('./_redefine');\nvar redefineAll = require('./_redefine-all');\nvar meta = require('./_meta');\nvar forOf = require('./_for-of');\nvar anInstance = require('./_an-instance');\nvar isObject = require('./_is-object');\nvar fails = require('./_fails');\nvar $iterDetect = require('./_iter-detect');\nvar setToStringTag = require('./_set-to-string-tag');\nvar inheritIfRequired = require('./_inherit-if-required');\n\nmodule.exports = function (NAME, wrapper, methods, common, IS_MAP, IS_WEAK) {\n  var Base = global[NAME];\n  var C = Base;\n  var ADDER = IS_MAP ? 'set' : 'add';\n  var proto = C && C.prototype;\n  var O = {};\n  var fixMethod = function (KEY) {\n    var fn = proto[KEY];\n    redefine(proto, KEY,\n      KEY == 'delete' ? function (a) {\n        return IS_WEAK && !isObject(a) ? false : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'has' ? function has(a) {\n        return IS_WEAK && !isObject(a) ? false : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'get' ? function get(a) {\n        return IS_WEAK && !isObject(a) ? undefined : fn.call(this, a === 0 ? 0 : a);\n      } : KEY == 'add' ? function add(a) { fn.call(this, a === 0 ? 0 : a); return this; }\n        : function set(a, b) { fn.call(this, a === 0 ? 0 : a, b); return this; }\n    );\n  };\n  if (typeof C != 'function' || !(IS_WEAK || proto.forEach && !fails(function () {\n    new C().entries().next();\n  }))) {\n    // create collection constructor\n    C = common.getConstructor(wrapper, NAME, IS_MAP, ADDER);\n    redefineAll(C.prototype, methods);\n    meta.NEED = true;\n  } else {\n    var instance = new C();\n    // early implementations not supports chaining\n    var HASNT_CHAINING = instance[ADDER](IS_WEAK ? {} : -0, 1) != instance;\n    // V8 ~  Chromium 40- weak-collections throws on primitives, but should return false\n    var THROWS_ON_PRIMITIVES = fails(function () { instance.has(1); });\n    // most early implementations doesn't supports iterables, most modern - not close it correctly\n    var ACCEPT_ITERABLES = $iterDetect(function (iter) { new C(iter); }); // eslint-disable-line no-new\n    // for early implementations -0 and +0 not the same\n    var BUGGY_ZERO = !IS_WEAK && fails(function () {\n      // V8 ~ Chromium 42- fails only with 5+ elements\n      var $instance = new C();\n      var index = 5;\n      while (index--) $instance[ADDER](index, index);\n      return !$instance.has(-0);\n    });\n    if (!ACCEPT_ITERABLES) {\n      C = wrapper(function (target, iterable) {\n        anInstance(target, C, NAME);\n        var that = inheritIfRequired(new Base(), target, C);\n        if (iterable != undefined) forOf(iterable, IS_MAP, that[ADDER], that);\n        return that;\n      });\n      C.prototype = proto;\n      proto.constructor = C;\n    }\n    if (THROWS_ON_PRIMITIVES || BUGGY_ZERO) {\n      fixMethod('delete');\n      fixMethod('has');\n      IS_MAP && fixMethod('get');\n    }\n    if (BUGGY_ZERO || HASNT_CHAINING) fixMethod(ADDER);\n    // weak collections should not contains .clear method\n    if (IS_WEAK && proto.clear) delete proto.clear;\n  }\n\n  setToStringTag(C, NAME);\n\n  O[NAME] = C;\n  $export($export.G + $export.W + $export.F * (C != Base), O);\n\n  if (!IS_WEAK) common.setStrong(C, NAME, IS_MAP);\n\n  return C;\n};\n","var core = module.exports = { version: '2.6.4' };\nif (typeof __e == 'number') __e = core; // eslint-disable-line no-undef\n","'use strict';\nvar $defineProperty = require('./_object-dp');\nvar createDesc = require('./_property-desc');\n\nmodule.exports = function (object, index, value) {\n  if (index in object) $defineProperty.f(object, index, createDesc(0, value));\n  else object[index] = value;\n};\n","// optional / simple context binding\nvar aFunction = require('./_a-function');\nmodule.exports = function (fn, that, length) {\n  aFunction(fn);\n  if (that === undefined) return fn;\n  switch (length) {\n    case 1: return function (a) {\n      return fn.call(that, a);\n    };\n    case 2: return function (a, b) {\n      return fn.call(that, a, b);\n    };\n    case 3: return function (a, b, c) {\n      return fn.call(that, a, b, c);\n    };\n  }\n  return function (/* ...args */) {\n    return fn.apply(that, arguments);\n  };\n};\n","'use strict';\n// 20.3.4.36 / 15.9.5.43 Date.prototype.toISOString()\nvar fails = require('./_fails');\nvar getTime = Date.prototype.getTime;\nvar $toISOString = Date.prototype.toISOString;\n\nvar lz = function (num) {\n  return num > 9 ? num : '0' + num;\n};\n\n// PhantomJS / old WebKit has a broken implementations\nmodule.exports = (fails(function () {\n  return $toISOString.call(new Date(-5e13 - 1)) != '0385-07-25T07:06:39.999Z';\n}) || !fails(function () {\n  $toISOString.call(new Date(NaN));\n})) ? function toISOString() {\n  if (!isFinite(getTime.call(this))) throw RangeError('Invalid time value');\n  var d = this;\n  var y = d.getUTCFullYear();\n  var m = d.getUTCMilliseconds();\n  var s = y < 0 ? '-' : y > 9999 ? '+' : '';\n  return s + ('00000' + Math.abs(y)).slice(s ? -6 : -4) +\n    '-' + lz(d.getUTCMonth() + 1) + '-' + lz(d.getUTCDate()) +\n    'T' + lz(d.getUTCHours()) + ':' + lz(d.getUTCMinutes()) +\n    ':' + lz(d.getUTCSeconds()) + '.' + (m > 99 ? m : '0' + lz(m)) + 'Z';\n} : $toISOString;\n","'use strict';\nvar anObject = require('./_an-object');\nvar toPrimitive = require('./_to-primitive');\nvar NUMBER = 'number';\n\nmodule.exports = function (hint) {\n  if (hint !== 'string' && hint !== NUMBER && hint !== 'default') throw TypeError('Incorrect hint');\n  return toPrimitive(anObject(this), hint != NUMBER);\n};\n","// 7.2.1 RequireObjectCoercible(argument)\nmodule.exports = function (it) {\n  if (it == undefined) throw TypeError(\"Can't call method on  \" + it);\n  return it;\n};\n","// Thank's IE8 for his funny defineProperty\nmodule.exports = !require('./_fails')(function () {\n  return Object.defineProperty({}, 'a', { get: function () { return 7; } }).a != 7;\n});\n","var isObject = require('./_is-object');\nvar document = require('./_global').document;\n// typeof document.createElement is 'object' in old IE\nvar is = isObject(document) && isObject(document.createElement);\nmodule.exports = function (it) {\n  return is ? document.createElement(it) : {};\n};\n","// IE 8- don't enum bug keys\nmodule.exports = (\n  'constructor,hasOwnProperty,isPrototypeOf,propertyIsEnumerable,toLocaleString,toString,valueOf'\n).split(',');\n","// all enumerable object keys, includes symbols\nvar getKeys = require('./_object-keys');\nvar gOPS = require('./_object-gops');\nvar pIE = require('./_object-pie');\nmodule.exports = function (it) {\n  var result = getKeys(it);\n  var getSymbols = gOPS.f;\n  if (getSymbols) {\n    var symbols = getSymbols(it);\n    var isEnum = pIE.f;\n    var i = 0;\n    var key;\n    while (symbols.length > i) if (isEnum.call(it, key = symbols[i++])) result.push(key);\n  } return result;\n};\n","var global = require('./_global');\nvar core = require('./_core');\nvar hide = require('./_hide');\nvar redefine = require('./_redefine');\nvar ctx = require('./_ctx');\nvar PROTOTYPE = 'prototype';\n\nvar $export = function (type, name, source) {\n  var IS_FORCED = type & $export.F;\n  var IS_GLOBAL = type & $export.G;\n  var IS_STATIC = type & $export.S;\n  var IS_PROTO = type & $export.P;\n  var IS_BIND = type & $export.B;\n  var target = IS_GLOBAL ? global : IS_STATIC ? global[name] || (global[name] = {}) : (global[name] || {})[PROTOTYPE];\n  var exports = IS_GLOBAL ? core : core[name] || (core[name] = {});\n  var expProto = exports[PROTOTYPE] || (exports[PROTOTYPE] = {});\n  var key, own, out, exp;\n  if (IS_GLOBAL) source = name;\n  for (key in source) {\n    // contains in native\n    own = !IS_FORCED && target && target[key] !== undefined;\n    // export native or passed\n    out = (own ? target : source)[key];\n    // bind timers to global for call from export context\n    exp = IS_BIND && own ? ctx(out, global) : IS_PROTO && typeof out == 'function' ? ctx(Function.call, out) : out;\n    // extend global\n    if (target) redefine(target, key, out, type & $export.U);\n    // export\n    if (exports[key] != out) hide(exports, key, exp);\n    if (IS_PROTO && expProto[key] != out) expProto[key] = out;\n  }\n};\nglobal.core = core;\n// type bitmap\n$export.F = 1;   // forced\n$export.G = 2;   // global\n$export.S = 4;   // static\n$export.P = 8;   // proto\n$export.B = 16;  // bind\n$export.W = 32;  // wrap\n$export.U = 64;  // safe\n$export.R = 128; // real proto method for `library`\nmodule.exports = $export;\n","var MATCH = require('./_wks')('match');\nmodule.exports = function (KEY) {\n  var re = /./;\n  try {\n    '/./'[KEY](re);\n  } catch (e) {\n    try {\n      re[MATCH] = false;\n      return !'/./'[KEY](re);\n    } catch (f) { /* empty */ }\n  } return true;\n};\n","module.exports = function (exec) {\n  try {\n    return !!exec();\n  } catch (e) {\n    return true;\n  }\n};\n","'use strict';\nrequire('./es6.regexp.exec');\nvar redefine = require('./_redefine');\nvar hide = require('./_hide');\nvar fails = require('./_fails');\nvar defined = require('./_defined');\nvar wks = require('./_wks');\nvar regexpExec = require('./_regexp-exec');\n\nvar SPECIES = wks('species');\n\nvar REPLACE_SUPPORTS_NAMED_GROUPS = !fails(function () {\n  // #replace needs built-in support for named groups.\n  // #match works fine because it just return the exec results, even if it has\n  // a \"grops\" property.\n  var re = /./;\n  re.exec = function () {\n    var result = [];\n    result.groups = { a: '7' };\n    return result;\n  };\n  return ''.replace(re, '$<a>') !== '7';\n});\n\nvar SPLIT_WORKS_WITH_OVERWRITTEN_EXEC = (function () {\n  // Chrome 51 has a buggy \"split\" implementation when RegExp#exec !== nativeExec\n  var re = /(?:)/;\n  var originalExec = re.exec;\n  re.exec = function () { return originalExec.apply(this, arguments); };\n  var result = 'ab'.split(re);\n  return result.length === 2 && result[0] === 'a' && result[1] === 'b';\n})();\n\nmodule.exports = function (KEY, length, exec) {\n  var SYMBOL = wks(KEY);\n\n  var DELEGATES_TO_SYMBOL = !fails(function () {\n    // String methods call symbol-named RegEp methods\n    var O = {};\n    O[SYMBOL] = function () { return 7; };\n    return ''[KEY](O) != 7;\n  });\n\n  var DELEGATES_TO_EXEC = DELEGATES_TO_SYMBOL ? !fails(function () {\n    // Symbol-named RegExp methods call .exec\n    var execCalled = false;\n    var re = /a/;\n    re.exec = function () { execCalled = true; return null; };\n    if (KEY === 'split') {\n      // RegExp[@@split] doesn't call the regex's exec method, but first creates\n      // a new one. We need to return the patched regex when creating the new one.\n      re.constructor = {};\n      re.constructor[SPECIES] = function () { return re; };\n    }\n    re[SYMBOL]('');\n    return !execCalled;\n  }) : undefined;\n\n  if (\n    !DELEGATES_TO_SYMBOL ||\n    !DELEGATES_TO_EXEC ||\n    (KEY === 'replace' && !REPLACE_SUPPORTS_NAMED_GROUPS) ||\n    (KEY === 'split' && !SPLIT_WORKS_WITH_OVERWRITTEN_EXEC)\n  ) {\n    var nativeRegExpMethod = /./[SYMBOL];\n    var fns = exec(\n      defined,\n      SYMBOL,\n      ''[KEY],\n      function maybeCallNative(nativeMethod, regexp, str, arg2, forceStringMethod) {\n        if (regexp.exec === regexpExec) {\n          if (DELEGATES_TO_SYMBOL && !forceStringMethod) {\n            // The native String method already delegates to @@method (this\n            // polyfilled function), leasing to infinite recursion.\n            // We avoid it by directly calling the native @@method method.\n            return { done: true, value: nativeRegExpMethod.call(regexp, str, arg2) };\n          }\n          return { done: true, value: nativeMethod.call(str, regexp, arg2) };\n        }\n        return { done: false };\n      }\n    );\n    var strfn = fns[0];\n    var rxfn = fns[1];\n\n    redefine(String.prototype, KEY, strfn);\n    hide(RegExp.prototype, SYMBOL, length == 2\n      // 21.2.5.8 RegExp.prototype[@@replace](string, replaceValue)\n      // 21.2.5.11 RegExp.prototype[@@split](string, limit)\n      ? function (string, arg) { return rxfn.call(string, this, arg); }\n      // 21.2.5.6 RegExp.prototype[@@match](string)\n      // 21.2.5.9 RegExp.prototype[@@search](string)\n      : function (string) { return rxfn.call(string, this); }\n    );\n  }\n};\n","'use strict';\n// 21.2.5.3 get RegExp.prototype.flags\nvar anObject = require('./_an-object');\nmodule.exports = function () {\n  var that = anObject(this);\n  var result = '';\n  if (that.global) result += 'g';\n  if (that.ignoreCase) result += 'i';\n  if (that.multiline) result += 'm';\n  if (that.unicode) result += 'u';\n  if (that.sticky) result += 'y';\n  return result;\n};\n","'use strict';\n// https://tc39.github.io/proposal-flatMap/#sec-FlattenIntoArray\nvar isArray = require('./_is-array');\nvar isObject = require('./_is-object');\nvar toLength = require('./_to-length');\nvar ctx = require('./_ctx');\nvar IS_CONCAT_SPREADABLE = require('./_wks')('isConcatSpreadable');\n\nfunction flattenIntoArray(target, original, source, sourceLen, start, depth, mapper, thisArg) {\n  var targetIndex = start;\n  var sourceIndex = 0;\n  var mapFn = mapper ? ctx(mapper, thisArg, 3) : false;\n  var element, spreadable;\n\n  while (sourceIndex < sourceLen) {\n    if (sourceIndex in source) {\n      element = mapFn ? mapFn(source[sourceIndex], sourceIndex, original) : source[sourceIndex];\n\n      spreadable = false;\n      if (isObject(element)) {\n        spreadable = element[IS_CONCAT_SPREADABLE];\n        spreadable = spreadable !== undefined ? !!spreadable : isArray(element);\n      }\n\n      if (spreadable && depth > 0) {\n        targetIndex = flattenIntoArray(target, original, element, toLength(element.length), targetIndex, depth - 1) - 1;\n      } else {\n        if (targetIndex >= 0x1fffffffffffff) throw TypeError();\n        target[targetIndex] = element;\n      }\n\n      targetIndex++;\n    }\n    sourceIndex++;\n  }\n  return targetIndex;\n}\n\nmodule.exports = flattenIntoArray;\n","var ctx = require('./_ctx');\nvar call = require('./_iter-call');\nvar isArrayIter = require('./_is-array-iter');\nvar anObject = require('./_an-object');\nvar toLength = require('./_to-length');\nvar getIterFn = require('./core.get-iterator-method');\nvar BREAK = {};\nvar RETURN = {};\nvar exports = module.exports = function (iterable, entries, fn, that, ITERATOR) {\n  var iterFn = ITERATOR ? function () { return iterable; } : getIterFn(iterable);\n  var f = ctx(fn, that, entries ? 2 : 1);\n  var index = 0;\n  var length, step, iterator, result;\n  if (typeof iterFn != 'function') throw TypeError(iterable + ' is not iterable!');\n  // fast case for arrays with default iterator\n  if (isArrayIter(iterFn)) for (length = toLength(iterable.length); length > index; index++) {\n    result = entries ? f(anObject(step = iterable[index])[0], step[1]) : f(iterable[index]);\n    if (result === BREAK || result === RETURN) return result;\n  } else for (iterator = iterFn.call(iterable); !(step = iterator.next()).done;) {\n    result = call(iterator, f, step.value, entries);\n    if (result === BREAK || result === RETURN) return result;\n  }\n};\nexports.BREAK = BREAK;\nexports.RETURN = RETURN;\n","module.exports = require('./_shared')('native-function-to-string', Function.toString);\n","// https://github.com/zloirock/core-js/issues/86#issuecomment-115759028\nvar global = module.exports = typeof window != 'undefined' && window.Math == Math\n  ? window : typeof self != 'undefined' && self.Math == Math ? self\n  // eslint-disable-next-line no-new-func\n  : Function('return this')();\nif (typeof __g == 'number') __g = global; // eslint-disable-line no-undef\n","var hasOwnProperty = {}.hasOwnProperty;\nmodule.exports = function (it, key) {\n  return hasOwnProperty.call(it, key);\n};\n","var dP = require('./_object-dp');\nvar createDesc = require('./_property-desc');\nmodule.exports = require('./_descriptors') ? function (object, key, value) {\n  return dP.f(object, key, createDesc(1, value));\n} : function (object, key, value) {\n  object[key] = value;\n  return object;\n};\n","var document = require('./_global').document;\nmodule.exports = document && document.documentElement;\n","module.exports = !require('./_descriptors') && !require('./_fails')(function () {\n  return Object.defineProperty(require('./_dom-create')('div'), 'a', { get: function () { return 7; } }).a != 7;\n});\n","var isObject = require('./_is-object');\nvar setPrototypeOf = require('./_set-proto').set;\nmodule.exports = function (that, target, C) {\n  var S = target.constructor;\n  var P;\n  if (S !== C && typeof S == 'function' && (P = S.prototype) !== C.prototype && isObject(P) && setPrototypeOf) {\n    setPrototypeOf(that, P);\n  } return that;\n};\n","// fast apply, http://jsperf.lnkit.com/fast-apply/5\nmodule.exports = function (fn, args, that) {\n  var un = that === undefined;\n  switch (args.length) {\n    case 0: return un ? fn()\n                      : fn.call(that);\n    case 1: return un ? fn(args[0])\n                      : fn.call(that, args[0]);\n    case 2: return un ? fn(args[0], args[1])\n                      : fn.call(that, args[0], args[1]);\n    case 3: return un ? fn(args[0], args[1], args[2])\n                      : fn.call(that, args[0], args[1], args[2]);\n    case 4: return un ? fn(args[0], args[1], args[2], args[3])\n                      : fn.call(that, args[0], args[1], args[2], args[3]);\n  } return fn.apply(that, args);\n};\n","// fallback for non-array-like ES3 and non-enumerable old V8 strings\nvar cof = require('./_cof');\n// eslint-disable-next-line no-prototype-builtins\nmodule.exports = Object('z').propertyIsEnumerable(0) ? Object : function (it) {\n  return cof(it) == 'String' ? it.split('') : Object(it);\n};\n","// check on default Array iterator\nvar Iterators = require('./_iterators');\nvar ITERATOR = require('./_wks')('iterator');\nvar ArrayProto = Array.prototype;\n\nmodule.exports = function (it) {\n  return it !== undefined && (Iterators.Array === it || ArrayProto[ITERATOR] === it);\n};\n","// 7.2.2 IsArray(argument)\nvar cof = require('./_cof');\nmodule.exports = Array.isArray || function isArray(arg) {\n  return cof(arg) == 'Array';\n};\n","// 20.1.2.3 Number.isInteger(number)\nvar isObject = require('./_is-object');\nvar floor = Math.floor;\nmodule.exports = function isInteger(it) {\n  return !isObject(it) && isFinite(it) && floor(it) === it;\n};\n","module.exports = function (it) {\n  return typeof it === 'object' ? it !== null : typeof it === 'function';\n};\n","// 7.2.8 IsRegExp(argument)\nvar isObject = require('./_is-object');\nvar cof = require('./_cof');\nvar MATCH = require('./_wks')('match');\nmodule.exports = function (it) {\n  var isRegExp;\n  return isObject(it) && ((isRegExp = it[MATCH]) !== undefined ? !!isRegExp : cof(it) == 'RegExp');\n};\n","// call something on iterator step with safe closing on error\nvar anObject = require('./_an-object');\nmodule.exports = function (iterator, fn, value, entries) {\n  try {\n    return entries ? fn(anObject(value)[0], value[1]) : fn(value);\n  // 7.4.6 IteratorClose(iterator, completion)\n  } catch (e) {\n    var ret = iterator['return'];\n    if (ret !== undefined) anObject(ret.call(iterator));\n    throw e;\n  }\n};\n","'use strict';\nvar create = require('./_object-create');\nvar descriptor = require('./_property-desc');\nvar setToStringTag = require('./_set-to-string-tag');\nvar IteratorPrototype = {};\n\n// 25.1.2.1.1 %IteratorPrototype%[@@iterator]()\nrequire('./_hide')(IteratorPrototype, require('./_wks')('iterator'), function () { return this; });\n\nmodule.exports = function (Constructor, NAME, next) {\n  Constructor.prototype = create(IteratorPrototype, { next: descriptor(1, next) });\n  setToStringTag(Constructor, NAME + ' Iterator');\n};\n","'use strict';\nvar LIBRARY = require('./_library');\nvar $export = require('./_export');\nvar redefine = require('./_redefine');\nvar hide = require('./_hide');\nvar Iterators = require('./_iterators');\nvar $iterCreate = require('./_iter-create');\nvar setToStringTag = require('./_set-to-string-tag');\nvar getPrototypeOf = require('./_object-gpo');\nvar ITERATOR = require('./_wks')('iterator');\nvar BUGGY = !([].keys && 'next' in [].keys()); // Safari has buggy iterators w/o `next`\nvar FF_ITERATOR = '@@iterator';\nvar KEYS = 'keys';\nvar VALUES = 'values';\n\nvar returnThis = function () { return this; };\n\nmodule.exports = function (Base, NAME, Constructor, next, DEFAULT, IS_SET, FORCED) {\n  $iterCreate(Constructor, NAME, next);\n  var getMethod = function (kind) {\n    if (!BUGGY && kind in proto) return proto[kind];\n    switch (kind) {\n      case KEYS: return function keys() { return new Constructor(this, kind); };\n      case VALUES: return function values() { return new Constructor(this, kind); };\n    } return function entries() { return new Constructor(this, kind); };\n  };\n  var TAG = NAME + ' Iterator';\n  var DEF_VALUES = DEFAULT == VALUES;\n  var VALUES_BUG = false;\n  var proto = Base.prototype;\n  var $native = proto[ITERATOR] || proto[FF_ITERATOR] || DEFAULT && proto[DEFAULT];\n  var $default = $native || getMethod(DEFAULT);\n  var $entries = DEFAULT ? !DEF_VALUES ? $default : getMethod('entries') : undefined;\n  var $anyNative = NAME == 'Array' ? proto.entries || $native : $native;\n  var methods, key, IteratorPrototype;\n  // Fix native\n  if ($anyNative) {\n    IteratorPrototype = getPrototypeOf($anyNative.call(new Base()));\n    if (IteratorPrototype !== Object.prototype && IteratorPrototype.next) {\n      // Set @@toStringTag to native iterators\n      setToStringTag(IteratorPrototype, TAG, true);\n      // fix for some old engines\n      if (!LIBRARY && typeof IteratorPrototype[ITERATOR] != 'function') hide(IteratorPrototype, ITERATOR, returnThis);\n    }\n  }\n  // fix Array#{values, @@iterator}.name in V8 / FF\n  if (DEF_VALUES && $native && $native.name !== VALUES) {\n    VALUES_BUG = true;\n    $default = function values() { return $native.call(this); };\n  }\n  // Define iterator\n  if ((!LIBRARY || FORCED) && (BUGGY || VALUES_BUG || !proto[ITERATOR])) {\n    hide(proto, ITERATOR, $default);\n  }\n  // Plug for library\n  Iterators[NAME] = $default;\n  Iterators[TAG] = returnThis;\n  if (DEFAULT) {\n    methods = {\n      values: DEF_VALUES ? $default : getMethod(VALUES),\n      keys: IS_SET ? $default : getMethod(KEYS),\n      entries: $entries\n    };\n    if (FORCED) for (key in methods) {\n      if (!(key in proto)) redefine(proto, key, methods[key]);\n    } else $export($export.P + $export.F * (BUGGY || VALUES_BUG), NAME, methods);\n  }\n  return methods;\n};\n","var ITERATOR = require('./_wks')('iterator');\nvar SAFE_CLOSING = false;\n\ntry {\n  var riter = [7][ITERATOR]();\n  riter['return'] = function () { SAFE_CLOSING = true; };\n  // eslint-disable-next-line no-throw-literal\n  Array.from(riter, function () { throw 2; });\n} catch (e) { /* empty */ }\n\nmodule.exports = function (exec, skipClosing) {\n  if (!skipClosing && !SAFE_CLOSING) return false;\n  var safe = false;\n  try {\n    var arr = [7];\n    var iter = arr[ITERATOR]();\n    iter.next = function () { return { done: safe = true }; };\n    arr[ITERATOR] = function () { return iter; };\n    exec(arr);\n  } catch (e) { /* empty */ }\n  return safe;\n};\n","module.exports = function (done, value) {\n  return { value: value, done: !!done };\n};\n","module.exports = {};\n","module.exports = false;\n","// 20.2.2.14 Math.expm1(x)\nvar $expm1 = Math.expm1;\nmodule.exports = (!$expm1\n  // Old FF bug\n  || $expm1(10) > 22025.465794806719 || $expm1(10) < 22025.4657948067165168\n  // Tor Browser bug\n  || $expm1(-2e-17) != -2e-17\n) ? function expm1(x) {\n  return (x = +x) == 0 ? x : x > -1e-6 && x < 1e-6 ? x + x * x / 2 : Math.exp(x) - 1;\n} : $expm1;\n","// 20.2.2.16 Math.fround(x)\nvar sign = require('./_math-sign');\nvar pow = Math.pow;\nvar EPSILON = pow(2, -52);\nvar EPSILON32 = pow(2, -23);\nvar MAX32 = pow(2, 127) * (2 - EPSILON32);\nvar MIN32 = pow(2, -126);\n\nvar roundTiesToEven = function (n) {\n  return n + 1 / EPSILON - 1 / EPSILON;\n};\n\nmodule.exports = Math.fround || function fround(x) {\n  var $abs = Math.abs(x);\n  var $sign = sign(x);\n  var a, result;\n  if ($abs < MIN32) return $sign * roundTiesToEven($abs / MIN32 / EPSILON32) * MIN32 * EPSILON32;\n  a = (1 + EPSILON32 / EPSILON) * $abs;\n  result = a - (a - $abs);\n  // eslint-disable-next-line no-self-compare\n  if (result > MAX32 || result != result) return $sign * Infinity;\n  return $sign * result;\n};\n","// 20.2.2.20 Math.log1p(x)\nmodule.exports = Math.log1p || function log1p(x) {\n  return (x = +x) > -1e-8 && x < 1e-8 ? x - x * x / 2 : Math.log(1 + x);\n};\n","// https://rwaldron.github.io/proposal-math-extensions/\nmodule.exports = Math.scale || function scale(x, inLow, inHigh, outLow, outHigh) {\n  if (\n    arguments.length === 0\n      // eslint-disable-next-line no-self-compare\n      || x != x\n      // eslint-disable-next-line no-self-compare\n      || inLow != inLow\n      // eslint-disable-next-line no-self-compare\n      || inHigh != inHigh\n      // eslint-disable-next-line no-self-compare\n      || outLow != outLow\n      // eslint-disable-next-line no-self-compare\n      || outHigh != outHigh\n  ) return NaN;\n  if (x === Infinity || x === -Infinity) return x;\n  return (x - inLow) * (outHigh - outLow) / (inHigh - inLow) + outLow;\n};\n","// 20.2.2.28 Math.sign(x)\nmodule.exports = Math.sign || function sign(x) {\n  // eslint-disable-next-line no-self-compare\n  return (x = +x) == 0 || x != x ? x : x < 0 ? -1 : 1;\n};\n","var META = require('./_uid')('meta');\nvar isObject = require('./_is-object');\nvar has = require('./_has');\nvar setDesc = require('./_object-dp').f;\nvar id = 0;\nvar isExtensible = Object.isExtensible || function () {\n  return true;\n};\nvar FREEZE = !require('./_fails')(function () {\n  return isExtensible(Object.preventExtensions({}));\n});\nvar setMeta = function (it) {\n  setDesc(it, META, { value: {\n    i: 'O' + ++id, // object ID\n    w: {}          // weak collections IDs\n  } });\n};\nvar fastKey = function (it, create) {\n  // return primitive with prefix\n  if (!isObject(it)) return typeof it == 'symbol' ? it : (typeof it == 'string' ? 'S' : 'P') + it;\n  if (!has(it, META)) {\n    // can't set metadata to uncaught frozen object\n    if (!isExtensible(it)) return 'F';\n    // not necessary to add metadata\n    if (!create) return 'E';\n    // add missing metadata\n    setMeta(it);\n  // return object ID\n  } return it[META].i;\n};\nvar getWeak = function (it, create) {\n  if (!has(it, META)) {\n    // can't set metadata to uncaught frozen object\n    if (!isExtensible(it)) return true;\n    // not necessary to add metadata\n    if (!create) return false;\n    // add missing metadata\n    setMeta(it);\n  // return hash weak collections IDs\n  } return it[META].w;\n};\n// add metadata on freeze-family methods calling\nvar onFreeze = function (it) {\n  if (FREEZE && meta.NEED && isExtensible(it) && !has(it, META)) setMeta(it);\n  return it;\n};\nvar meta = module.exports = {\n  KEY: META,\n  NEED: false,\n  fastKey: fastKey,\n  getWeak: getWeak,\n  onFreeze: onFreeze\n};\n","var Map = require('./es6.map');\nvar $export = require('./_export');\nvar shared = require('./_shared')('metadata');\nvar store = shared.store || (shared.store = new (require('./es6.weak-map'))());\n\nvar getOrCreateMetadataMap = function (target, targetKey, create) {\n  var targetMetadata = store.get(target);\n  if (!targetMetadata) {\n    if (!create) return undefined;\n    store.set(target, targetMetadata = new Map());\n  }\n  var keyMetadata = targetMetadata.get(targetKey);\n  if (!keyMetadata) {\n    if (!create) return undefined;\n    targetMetadata.set(targetKey, keyMetadata = new Map());\n  } return keyMetadata;\n};\nvar ordinaryHasOwnMetadata = function (MetadataKey, O, P) {\n  var metadataMap = getOrCreateMetadataMap(O, P, false);\n  return metadataMap === undefined ? false : metadataMap.has(MetadataKey);\n};\nvar ordinaryGetOwnMetadata = function (MetadataKey, O, P) {\n  var metadataMap = getOrCreateMetadataMap(O, P, false);\n  return metadataMap === undefined ? undefined : metadataMap.get(MetadataKey);\n};\nvar ordinaryDefineOwnMetadata = function (MetadataKey, MetadataValue, O, P) {\n  getOrCreateMetadataMap(O, P, true).set(MetadataKey, MetadataValue);\n};\nvar ordinaryOwnMetadataKeys = function (target, targetKey) {\n  var metadataMap = getOrCreateMetadataMap(target, targetKey, false);\n  var keys = [];\n  if (metadataMap) metadataMap.forEach(function (_, key) { keys.push(key); });\n  return keys;\n};\nvar toMetaKey = function (it) {\n  return it === undefined || typeof it == 'symbol' ? it : String(it);\n};\nvar exp = function (O) {\n  $export($export.S, 'Reflect', O);\n};\n\nmodule.exports = {\n  store: store,\n  map: getOrCreateMetadataMap,\n  has: ordinaryHasOwnMetadata,\n  get: ordinaryGetOwnMetadata,\n  set: ordinaryDefineOwnMetadata,\n  keys: ordinaryOwnMetadataKeys,\n  key: toMetaKey,\n  exp: exp\n};\n","var global = require('./_global');\nvar macrotask = require('./_task').set;\nvar Observer = global.MutationObserver || global.WebKitMutationObserver;\nvar process = global.process;\nvar Promise = global.Promise;\nvar isNode = require('./_cof')(process) == 'process';\n\nmodule.exports = function () {\n  var head, last, notify;\n\n  var flush = function () {\n    var parent, fn;\n    if (isNode && (parent = process.domain)) parent.exit();\n    while (head) {\n      fn = head.fn;\n      head = head.next;\n      try {\n        fn();\n      } catch (e) {\n        if (head) notify();\n        else last = undefined;\n        throw e;\n      }\n    } last = undefined;\n    if (parent) parent.enter();\n  };\n\n  // Node.js\n  if (isNode) {\n    notify = function () {\n      process.nextTick(flush);\n    };\n  // browsers with MutationObserver, except iOS Safari - https://github.com/zloirock/core-js/issues/339\n  } else if (Observer && !(global.navigator && global.navigator.standalone)) {\n    var toggle = true;\n    var node = document.createTextNode('');\n    new Observer(flush).observe(node, { characterData: true }); // eslint-disable-line no-new\n    notify = function () {\n      node.data = toggle = !toggle;\n    };\n  // environments with maybe non-completely correct, but existent Promise\n  } else if (Promise && Promise.resolve) {\n    // Promise.resolve without an argument throws an error in LG WebOS 2\n    var promise = Promise.resolve(undefined);\n    notify = function () {\n      promise.then(flush);\n    };\n  // for other environments - macrotask based on:\n  // - setImmediate\n  // - MessageChannel\n  // - window.postMessag\n  // - onreadystatechange\n  // - setTimeout\n  } else {\n    notify = function () {\n      // strange IE + webpack dev server bug - use .call(global)\n      macrotask.call(global, flush);\n    };\n  }\n\n  return function (fn) {\n    var task = { fn: fn, next: undefined };\n    if (last) last.next = task;\n    if (!head) {\n      head = task;\n      notify();\n    } last = task;\n  };\n};\n","'use strict';\n// 25.4.1.5 NewPromiseCapability(C)\nvar aFunction = require('./_a-function');\n\nfunction PromiseCapability(C) {\n  var resolve, reject;\n  this.promise = new C(function ($$resolve, $$reject) {\n    if (resolve !== undefined || reject !== undefined) throw TypeError('Bad Promise constructor');\n    resolve = $$resolve;\n    reject = $$reject;\n  });\n  this.resolve = aFunction(resolve);\n  this.reject = aFunction(reject);\n}\n\nmodule.exports.f = function (C) {\n  return new PromiseCapability(C);\n};\n","'use strict';\n// 19.1.2.1 Object.assign(target, source, ...)\nvar getKeys = require('./_object-keys');\nvar gOPS = require('./_object-gops');\nvar pIE = require('./_object-pie');\nvar toObject = require('./_to-object');\nvar IObject = require('./_iobject');\nvar $assign = Object.assign;\n\n// should work with symbols and should have deterministic property order (V8 bug)\nmodule.exports = !$assign || require('./_fails')(function () {\n  var A = {};\n  var B = {};\n  // eslint-disable-next-line no-undef\n  var S = Symbol();\n  var K = 'abcdefghijklmnopqrst';\n  A[S] = 7;\n  K.split('').forEach(function (k) { B[k] = k; });\n  return $assign({}, A)[S] != 7 || Object.keys($assign({}, B)).join('') != K;\n}) ? function assign(target, source) { // eslint-disable-line no-unused-vars\n  var T = toObject(target);\n  var aLen = arguments.length;\n  var index = 1;\n  var getSymbols = gOPS.f;\n  var isEnum = pIE.f;\n  while (aLen > index) {\n    var S = IObject(arguments[index++]);\n    var keys = getSymbols ? getKeys(S).concat(getSymbols(S)) : getKeys(S);\n    var length = keys.length;\n    var j = 0;\n    var key;\n    while (length > j) if (isEnum.call(S, key = keys[j++])) T[key] = S[key];\n  } return T;\n} : $assign;\n","// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\nvar anObject = require('./_an-object');\nvar dPs = require('./_object-dps');\nvar enumBugKeys = require('./_enum-bug-keys');\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\nvar Empty = function () { /* empty */ };\nvar PROTOTYPE = 'prototype';\n\n// Create object with fake `null` prototype: use iframe Object with cleared prototype\nvar createDict = function () {\n  // Thrash, waste and sodomy: IE GC bug\n  var iframe = require('./_dom-create')('iframe');\n  var i = enumBugKeys.length;\n  var lt = '<';\n  var gt = '>';\n  var iframeDocument;\n  iframe.style.display = 'none';\n  require('./_html').appendChild(iframe);\n  iframe.src = 'javascript:'; // eslint-disable-line no-script-url\n  // createDict = iframe.contentWindow.Object;\n  // html.removeChild(iframe);\n  iframeDocument = iframe.contentWindow.document;\n  iframeDocument.open();\n  iframeDocument.write(lt + 'script' + gt + 'document.F=Object' + lt + '/script' + gt);\n  iframeDocument.close();\n  createDict = iframeDocument.F;\n  while (i--) delete createDict[PROTOTYPE][enumBugKeys[i]];\n  return createDict();\n};\n\nmodule.exports = Object.create || function create(O, Properties) {\n  var result;\n  if (O !== null) {\n    Empty[PROTOTYPE] = anObject(O);\n    result = new Empty();\n    Empty[PROTOTYPE] = null;\n    // add \"__proto__\" for Object.getPrototypeOf polyfill\n    result[IE_PROTO] = O;\n  } else result = createDict();\n  return Properties === undefined ? result : dPs(result, Properties);\n};\n","var anObject = require('./_an-object');\nvar IE8_DOM_DEFINE = require('./_ie8-dom-define');\nvar toPrimitive = require('./_to-primitive');\nvar dP = Object.defineProperty;\n\nexports.f = require('./_descriptors') ? Object.defineProperty : function defineProperty(O, P, Attributes) {\n  anObject(O);\n  P = toPrimitive(P, true);\n  anObject(Attributes);\n  if (IE8_DOM_DEFINE) try {\n    return dP(O, P, Attributes);\n  } catch (e) { /* empty */ }\n  if ('get' in Attributes || 'set' in Attributes) throw TypeError('Accessors not supported!');\n  if ('value' in Attributes) O[P] = Attributes.value;\n  return O;\n};\n","var dP = require('./_object-dp');\nvar anObject = require('./_an-object');\nvar getKeys = require('./_object-keys');\n\nmodule.exports = require('./_descriptors') ? Object.defineProperties : function defineProperties(O, Properties) {\n  anObject(O);\n  var keys = getKeys(Properties);\n  var length = keys.length;\n  var i = 0;\n  var P;\n  while (length > i) dP.f(O, P = keys[i++], Properties[P]);\n  return O;\n};\n","'use strict';\n// Forced replacement prototype accessors methods\nmodule.exports = require('./_library') || !require('./_fails')(function () {\n  var K = Math.random();\n  // In FF throws only define methods\n  // eslint-disable-next-line no-undef, no-useless-call\n  __defineSetter__.call(null, K, function () { /* empty */ });\n  delete require('./_global')[K];\n});\n","var pIE = require('./_object-pie');\nvar createDesc = require('./_property-desc');\nvar toIObject = require('./_to-iobject');\nvar toPrimitive = require('./_to-primitive');\nvar has = require('./_has');\nvar IE8_DOM_DEFINE = require('./_ie8-dom-define');\nvar gOPD = Object.getOwnPropertyDescriptor;\n\nexports.f = require('./_descriptors') ? gOPD : function getOwnPropertyDescriptor(O, P) {\n  O = toIObject(O);\n  P = toPrimitive(P, true);\n  if (IE8_DOM_DEFINE) try {\n    return gOPD(O, P);\n  } catch (e) { /* empty */ }\n  if (has(O, P)) return createDesc(!pIE.f.call(O, P), O[P]);\n};\n","// fallback for IE11 buggy Object.getOwnPropertyNames with iframe and window\nvar toIObject = require('./_to-iobject');\nvar gOPN = require('./_object-gopn').f;\nvar toString = {}.toString;\n\nvar windowNames = typeof window == 'object' && window && Object.getOwnPropertyNames\n  ? Object.getOwnPropertyNames(window) : [];\n\nvar getWindowNames = function (it) {\n  try {\n    return gOPN(it);\n  } catch (e) {\n    return windowNames.slice();\n  }\n};\n\nmodule.exports.f = function getOwnPropertyNames(it) {\n  return windowNames && toString.call(it) == '[object Window]' ? getWindowNames(it) : gOPN(toIObject(it));\n};\n","// 19.1.2.7 / 15.2.3.4 Object.getOwnPropertyNames(O)\nvar $keys = require('./_object-keys-internal');\nvar hiddenKeys = require('./_enum-bug-keys').concat('length', 'prototype');\n\nexports.f = Object.getOwnPropertyNames || function getOwnPropertyNames(O) {\n  return $keys(O, hiddenKeys);\n};\n","exports.f = Object.getOwnPropertySymbols;\n","// 19.1.2.9 / 15.2.3.2 Object.getPrototypeOf(O)\nvar has = require('./_has');\nvar toObject = require('./_to-object');\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\nvar ObjectProto = Object.prototype;\n\nmodule.exports = Object.getPrototypeOf || function (O) {\n  O = toObject(O);\n  if (has(O, IE_PROTO)) return O[IE_PROTO];\n  if (typeof O.constructor == 'function' && O instanceof O.constructor) {\n    return O.constructor.prototype;\n  } return O instanceof Object ? ObjectProto : null;\n};\n","var has = require('./_has');\nvar toIObject = require('./_to-iobject');\nvar arrayIndexOf = require('./_array-includes')(false);\nvar IE_PROTO = require('./_shared-key')('IE_PROTO');\n\nmodule.exports = function (object, names) {\n  var O = toIObject(object);\n  var i = 0;\n  var result = [];\n  var key;\n  for (key in O) if (key != IE_PROTO) has(O, key) && result.push(key);\n  // Don't enum bug & hidden keys\n  while (names.length > i) if (has(O, key = names[i++])) {\n    ~arrayIndexOf(result, key) || result.push(key);\n  }\n  return result;\n};\n","// 19.1.2.14 / 15.2.3.14 Object.keys(O)\nvar $keys = require('./_object-keys-internal');\nvar enumBugKeys = require('./_enum-bug-keys');\n\nmodule.exports = Object.keys || function keys(O) {\n  return $keys(O, enumBugKeys);\n};\n","exports.f = {}.propertyIsEnumerable;\n","// most Object methods by ES6 should accept primitives\nvar $export = require('./_export');\nvar core = require('./_core');\nvar fails = require('./_fails');\nmodule.exports = function (KEY, exec) {\n  var fn = (core.Object || {})[KEY] || Object[KEY];\n  var exp = {};\n  exp[KEY] = exec(fn);\n  $export($export.S + $export.F * fails(function () { fn(1); }), 'Object', exp);\n};\n","var getKeys = require('./_object-keys');\nvar toIObject = require('./_to-iobject');\nvar isEnum = require('./_object-pie').f;\nmodule.exports = function (isEntries) {\n  return function (it) {\n    var O = toIObject(it);\n    var keys = getKeys(O);\n    var length = keys.length;\n    var i = 0;\n    var result = [];\n    var key;\n    while (length > i) if (isEnum.call(O, key = keys[i++])) {\n      result.push(isEntries ? [key, O[key]] : O[key]);\n    } return result;\n  };\n};\n","// all object keys, includes non-enumerable and symbols\nvar gOPN = require('./_object-gopn');\nvar gOPS = require('./_object-gops');\nvar anObject = require('./_an-object');\nvar Reflect = require('./_global').Reflect;\nmodule.exports = Reflect && Reflect.ownKeys || function ownKeys(it) {\n  var keys = gOPN.f(anObject(it));\n  var getSymbols = gOPS.f;\n  return getSymbols ? keys.concat(getSymbols(it)) : keys;\n};\n","var $parseFloat = require('./_global').parseFloat;\nvar $trim = require('./_string-trim').trim;\n\nmodule.exports = 1 / $parseFloat(require('./_string-ws') + '-0') !== -Infinity ? function parseFloat(str) {\n  var string = $trim(String(str), 3);\n  var result = $parseFloat(string);\n  return result === 0 && string.charAt(0) == '-' ? -0 : result;\n} : $parseFloat;\n","var $parseInt = require('./_global').parseInt;\nvar $trim = require('./_string-trim').trim;\nvar ws = require('./_string-ws');\nvar hex = /^[-+]?0[xX]/;\n\nmodule.exports = $parseInt(ws + '08') !== 8 || $parseInt(ws + '0x16') !== 22 ? function parseInt(str, radix) {\n  var string = $trim(String(str), 3);\n  return $parseInt(string, (radix >>> 0) || (hex.test(string) ? 16 : 10));\n} : $parseInt;\n","module.exports = function (exec) {\n  try {\n    return { e: false, v: exec() };\n  } catch (e) {\n    return { e: true, v: e };\n  }\n};\n","var anObject = require('./_an-object');\nvar isObject = require('./_is-object');\nvar newPromiseCapability = require('./_new-promise-capability');\n\nmodule.exports = function (C, x) {\n  anObject(C);\n  if (isObject(x) && x.constructor === C) return x;\n  var promiseCapability = newPromiseCapability.f(C);\n  var resolve = promiseCapability.resolve;\n  resolve(x);\n  return promiseCapability.promise;\n};\n","module.exports = function (bitmap, value) {\n  return {\n    enumerable: !(bitmap & 1),\n    configurable: !(bitmap & 2),\n    writable: !(bitmap & 4),\n    value: value\n  };\n};\n","var redefine = require('./_redefine');\nmodule.exports = function (target, src, safe) {\n  for (var key in src) redefine(target, key, src[key], safe);\n  return target;\n};\n","var global = require('./_global');\nvar hide = require('./_hide');\nvar has = require('./_has');\nvar SRC = require('./_uid')('src');\nvar $toString = require('./_function-to-string');\nvar TO_STRING = 'toString';\nvar TPL = ('' + $toString).split(TO_STRING);\n\nrequire('./_core').inspectSource = function (it) {\n  return $toString.call(it);\n};\n\n(module.exports = function (O, key, val, safe) {\n  var isFunction = typeof val == 'function';\n  if (isFunction) has(val, 'name') || hide(val, 'name', key);\n  if (O[key] === val) return;\n  if (isFunction) has(val, SRC) || hide(val, SRC, O[key] ? '' + O[key] : TPL.join(String(key)));\n  if (O === global) {\n    O[key] = val;\n  } else if (!safe) {\n    delete O[key];\n    hide(O, key, val);\n  } else if (O[key]) {\n    O[key] = val;\n  } else {\n    hide(O, key, val);\n  }\n// add fake Function#toString for correct work wrapped methods / constructors with methods like LoDash isNative\n})(Function.prototype, TO_STRING, function toString() {\n  return typeof this == 'function' && this[SRC] || $toString.call(this);\n});\n","'use strict';\n\nvar classof = require('./_classof');\nvar builtinExec = RegExp.prototype.exec;\n\n // `RegExpExec` abstract operation\n// https://tc39.github.io/ecma262/#sec-regexpexec\nmodule.exports = function (R, S) {\n  var exec = R.exec;\n  if (typeof exec === 'function') {\n    var result = exec.call(R, S);\n    if (typeof result !== 'object') {\n      throw new TypeError('RegExp exec method returned something other than an Object or null');\n    }\n    return result;\n  }\n  if (classof(R) !== 'RegExp') {\n    throw new TypeError('RegExp#exec called on incompatible receiver');\n  }\n  return builtinExec.call(R, S);\n};\n","'use strict';\n\nvar regexpFlags = require('./_flags');\n\nvar nativeExec = RegExp.prototype.exec;\n// This always refers to the native implementation, because the\n// String#replace polyfill uses ./fix-regexp-well-known-symbol-logic.js,\n// which loads this file before patching the method.\nvar nativeReplace = String.prototype.replace;\n\nvar patchedExec = nativeExec;\n\nvar LAST_INDEX = 'lastIndex';\n\nvar UPDATES_LAST_INDEX_WRONG = (function () {\n  var re1 = /a/,\n      re2 = /b*/g;\n  nativeExec.call(re1, 'a');\n  nativeExec.call(re2, 'a');\n  return re1[LAST_INDEX] !== 0 || re2[LAST_INDEX] !== 0;\n})();\n\n// nonparticipating capturing group, copied from es5-shim's String#split patch.\nvar NPCG_INCLUDED = /()??/.exec('')[1] !== undefined;\n\nvar PATCH = UPDATES_LAST_INDEX_WRONG || NPCG_INCLUDED;\n\nif (PATCH) {\n  patchedExec = function exec(str) {\n    var re = this;\n    var lastIndex, reCopy, match, i;\n\n    if (NPCG_INCLUDED) {\n      reCopy = new RegExp('^' + re.source + '$(?!\\\\s)', regexpFlags.call(re));\n    }\n    if (UPDATES_LAST_INDEX_WRONG) lastIndex = re[LAST_INDEX];\n\n    match = nativeExec.call(re, str);\n\n    if (UPDATES_LAST_INDEX_WRONG && match) {\n      re[LAST_INDEX] = re.global ? match.index + match[0].length : lastIndex;\n    }\n    if (NPCG_INCLUDED && match && match.length > 1) {\n      // Fix browsers whose `exec` methods don't consistently return `undefined`\n      // for NPCG, like IE8. NOTE: This doesn' work for /(.?)?/\n      // eslint-disable-next-line no-loop-func\n      nativeReplace.call(match[0], reCopy, function () {\n        for (i = 1; i < arguments.length - 2; i++) {\n          if (arguments[i] === undefined) match[i] = undefined;\n        }\n      });\n    }\n\n    return match;\n  };\n}\n\nmodule.exports = patchedExec;\n","module.exports = function (regExp, replace) {\n  var replacer = replace === Object(replace) ? function (part) {\n    return replace[part];\n  } : replace;\n  return function (it) {\n    return String(it).replace(regExp, replacer);\n  };\n};\n","// 7.2.9 SameValue(x, y)\nmodule.exports = Object.is || function is(x, y) {\n  // eslint-disable-next-line no-self-compare\n  return x === y ? x !== 0 || 1 / x === 1 / y : x != x && y != y;\n};\n","'use strict';\n// https://tc39.github.io/proposal-setmap-offrom/\nvar $export = require('./_export');\nvar aFunction = require('./_a-function');\nvar ctx = require('./_ctx');\nvar forOf = require('./_for-of');\n\nmodule.exports = function (COLLECTION) {\n  $export($export.S, COLLECTION, { from: function from(source /* , mapFn, thisArg */) {\n    var mapFn = arguments[1];\n    var mapping, A, n, cb;\n    aFunction(this);\n    mapping = mapFn !== undefined;\n    if (mapping) aFunction(mapFn);\n    if (source == undefined) return new this();\n    A = [];\n    if (mapping) {\n      n = 0;\n      cb = ctx(mapFn, arguments[2], 2);\n      forOf(source, false, function (nextItem) {\n        A.push(cb(nextItem, n++));\n      });\n    } else {\n      forOf(source, false, A.push, A);\n    }\n    return new this(A);\n  } });\n};\n","'use strict';\n// https://tc39.github.io/proposal-setmap-offrom/\nvar $export = require('./_export');\n\nmodule.exports = function (COLLECTION) {\n  $export($export.S, COLLECTION, { of: function of() {\n    var length = arguments.length;\n    var A = new Array(length);\n    while (length--) A[length] = arguments[length];\n    return new this(A);\n  } });\n};\n","// Works with __proto__ only. Old v8 can't work with null proto objects.\n/* eslint-disable no-proto */\nvar isObject = require('./_is-object');\nvar anObject = require('./_an-object');\nvar check = function (O, proto) {\n  anObject(O);\n  if (!isObject(proto) && proto !== null) throw TypeError(proto + \": can't set as prototype!\");\n};\nmodule.exports = {\n  set: Object.setPrototypeOf || ('__proto__' in {} ? // eslint-disable-line\n    function (test, buggy, set) {\n      try {\n        set = require('./_ctx')(Function.call, require('./_object-gopd').f(Object.prototype, '__proto__').set, 2);\n        set(test, []);\n        buggy = !(test instanceof Array);\n      } catch (e) { buggy = true; }\n      return function setPrototypeOf(O, proto) {\n        check(O, proto);\n        if (buggy) O.__proto__ = proto;\n        else set(O, proto);\n        return O;\n      };\n    }({}, false) : undefined),\n  check: check\n};\n","'use strict';\nvar global = require('./_global');\nvar dP = require('./_object-dp');\nvar DESCRIPTORS = require('./_descriptors');\nvar SPECIES = require('./_wks')('species');\n\nmodule.exports = function (KEY) {\n  var C = global[KEY];\n  if (DESCRIPTORS && C && !C[SPECIES]) dP.f(C, SPECIES, {\n    configurable: true,\n    get: function () { return this; }\n  });\n};\n","var def = require('./_object-dp').f;\nvar has = require('./_has');\nvar TAG = require('./_wks')('toStringTag');\n\nmodule.exports = function (it, tag, stat) {\n  if (it && !has(it = stat ? it : it.prototype, TAG)) def(it, TAG, { configurable: true, value: tag });\n};\n","var shared = require('./_shared')('keys');\nvar uid = require('./_uid');\nmodule.exports = function (key) {\n  return shared[key] || (shared[key] = uid(key));\n};\n","var core = require('./_core');\nvar global = require('./_global');\nvar SHARED = '__core-js_shared__';\nvar store = global[SHARED] || (global[SHARED] = {});\n\n(module.exports = function (key, value) {\n  return store[key] || (store[key] = value !== undefined ? value : {});\n})('versions', []).push({\n  version: core.version,\n  mode: require('./_library') ? 'pure' : 'global',\n  copyright: '© 2019 Denis Pushkarev (zloirock.ru)'\n});\n","// 7.3.20 SpeciesConstructor(O, defaultConstructor)\nvar anObject = require('./_an-object');\nvar aFunction = require('./_a-function');\nvar SPECIES = require('./_wks')('species');\nmodule.exports = function (O, D) {\n  var C = anObject(O).constructor;\n  var S;\n  return C === undefined || (S = anObject(C)[SPECIES]) == undefined ? D : aFunction(S);\n};\n","'use strict';\nvar fails = require('./_fails');\n\nmodule.exports = function (method, arg) {\n  return !!method && fails(function () {\n    // eslint-disable-next-line no-useless-call\n    arg ? method.call(null, function () { /* empty */ }, 1) : method.call(null);\n  });\n};\n","var toInteger = require('./_to-integer');\nvar defined = require('./_defined');\n// true  -> String#at\n// false -> String#codePointAt\nmodule.exports = function (TO_STRING) {\n  return function (that, pos) {\n    var s = String(defined(that));\n    var i = toInteger(pos);\n    var l = s.length;\n    var a, b;\n    if (i < 0 || i >= l) return TO_STRING ? '' : undefined;\n    a = s.charCodeAt(i);\n    return a < 0xd800 || a > 0xdbff || i + 1 === l || (b = s.charCodeAt(i + 1)) < 0xdc00 || b > 0xdfff\n      ? TO_STRING ? s.charAt(i) : a\n      : TO_STRING ? s.slice(i, i + 2) : (a - 0xd800 << 10) + (b - 0xdc00) + 0x10000;\n  };\n};\n","// helper for String#{startsWith, endsWith, includes}\nvar isRegExp = require('./_is-regexp');\nvar defined = require('./_defined');\n\nmodule.exports = function (that, searchString, NAME) {\n  if (isRegExp(searchString)) throw TypeError('String#' + NAME + \" doesn't accept regex!\");\n  return String(defined(that));\n};\n","var $export = require('./_export');\nvar fails = require('./_fails');\nvar defined = require('./_defined');\nvar quot = /\"/g;\n// B.2.3.2.1 CreateHTML(string, tag, attribute, value)\nvar createHTML = function (string, tag, attribute, value) {\n  var S = String(defined(string));\n  var p1 = '<' + tag;\n  if (attribute !== '') p1 += ' ' + attribute + '=\"' + String(value).replace(quot, '&quot;') + '\"';\n  return p1 + '>' + S + '</' + tag + '>';\n};\nmodule.exports = function (NAME, exec) {\n  var O = {};\n  O[NAME] = exec(createHTML);\n  $export($export.P + $export.F * fails(function () {\n    var test = ''[NAME]('\"');\n    return test !== test.toLowerCase() || test.split('\"').length > 3;\n  }), 'String', O);\n};\n","// https://github.com/tc39/proposal-string-pad-start-end\nvar toLength = require('./_to-length');\nvar repeat = require('./_string-repeat');\nvar defined = require('./_defined');\n\nmodule.exports = function (that, maxLength, fillString, left) {\n  var S = String(defined(that));\n  var stringLength = S.length;\n  var fillStr = fillString === undefined ? ' ' : String(fillString);\n  var intMaxLength = toLength(maxLength);\n  if (intMaxLength <= stringLength || fillStr == '') return S;\n  var fillLen = intMaxLength - stringLength;\n  var stringFiller = repeat.call(fillStr, Math.ceil(fillLen / fillStr.length));\n  if (stringFiller.length > fillLen) stringFiller = stringFiller.slice(0, fillLen);\n  return left ? stringFiller + S : S + stringFiller;\n};\n","'use strict';\nvar toInteger = require('./_to-integer');\nvar defined = require('./_defined');\n\nmodule.exports = function repeat(count) {\n  var str = String(defined(this));\n  var res = '';\n  var n = toInteger(count);\n  if (n < 0 || n == Infinity) throw RangeError(\"Count can't be negative\");\n  for (;n > 0; (n >>>= 1) && (str += str)) if (n & 1) res += str;\n  return res;\n};\n","var $export = require('./_export');\nvar defined = require('./_defined');\nvar fails = require('./_fails');\nvar spaces = require('./_string-ws');\nvar space = '[' + spaces + ']';\nvar non = '\\u200b\\u0085';\nvar ltrim = RegExp('^' + space + space + '*');\nvar rtrim = RegExp(space + space + '*$');\n\nvar exporter = function (KEY, exec, ALIAS) {\n  var exp = {};\n  var FORCE = fails(function () {\n    return !!spaces[KEY]() || non[KEY]() != non;\n  });\n  var fn = exp[KEY] = FORCE ? exec(trim) : spaces[KEY];\n  if (ALIAS) exp[ALIAS] = fn;\n  $export($export.P + $export.F * FORCE, 'String', exp);\n};\n\n// 1 -> String#trimLeft\n// 2 -> String#trimRight\n// 3 -> String#trim\nvar trim = exporter.trim = function (string, TYPE) {\n  string = String(defined(string));\n  if (TYPE & 1) string = string.replace(ltrim, '');\n  if (TYPE & 2) string = string.replace(rtrim, '');\n  return string;\n};\n\nmodule.exports = exporter;\n","module.exports = '\\x09\\x0A\\x0B\\x0C\\x0D\\x20\\xA0\\u1680\\u180E\\u2000\\u2001\\u2002\\u2003' +\n  '\\u2004\\u2005\\u2006\\u2007\\u2008\\u2009\\u200A\\u202F\\u205F\\u3000\\u2028\\u2029\\uFEFF';\n","var ctx = require('./_ctx');\nvar invoke = require('./_invoke');\nvar html = require('./_html');\nvar cel = require('./_dom-create');\nvar global = require('./_global');\nvar process = global.process;\nvar setTask = global.setImmediate;\nvar clearTask = global.clearImmediate;\nvar MessageChannel = global.MessageChannel;\nvar Dispatch = global.Dispatch;\nvar counter = 0;\nvar queue = {};\nvar ONREADYSTATECHANGE = 'onreadystatechange';\nvar defer, channel, port;\nvar run = function () {\n  var id = +this;\n  // eslint-disable-next-line no-prototype-builtins\n  if (queue.hasOwnProperty(id)) {\n    var fn = queue[id];\n    delete queue[id];\n    fn();\n  }\n};\nvar listener = function (event) {\n  run.call(event.data);\n};\n// Node.js 0.9+ & IE10+ has setImmediate, otherwise:\nif (!setTask || !clearTask) {\n  setTask = function setImmediate(fn) {\n    var args = [];\n    var i = 1;\n    while (arguments.length > i) args.push(arguments[i++]);\n    queue[++counter] = function () {\n      // eslint-disable-next-line no-new-func\n      invoke(typeof fn == 'function' ? fn : Function(fn), args);\n    };\n    defer(counter);\n    return counter;\n  };\n  clearTask = function clearImmediate(id) {\n    delete queue[id];\n  };\n  // Node.js 0.8-\n  if (require('./_cof')(process) == 'process') {\n    defer = function (id) {\n      process.nextTick(ctx(run, id, 1));\n    };\n  // Sphere (JS game engine) Dispatch API\n  } else if (Dispatch && Dispatch.now) {\n    defer = function (id) {\n      Dispatch.now(ctx(run, id, 1));\n    };\n  // Browsers with MessageChannel, includes WebWorkers\n  } else if (MessageChannel) {\n    channel = new MessageChannel();\n    port = channel.port2;\n    channel.port1.onmessage = listener;\n    defer = ctx(port.postMessage, port, 1);\n  // Browsers with postMessage, skip WebWorkers\n  // IE8 has postMessage, but it's sync & typeof its postMessage is 'object'\n  } else if (global.addEventListener && typeof postMessage == 'function' && !global.importScripts) {\n    defer = function (id) {\n      global.postMessage(id + '', '*');\n    };\n    global.addEventListener('message', listener, false);\n  // IE8-\n  } else if (ONREADYSTATECHANGE in cel('script')) {\n    defer = function (id) {\n      html.appendChild(cel('script'))[ONREADYSTATECHANGE] = function () {\n        html.removeChild(this);\n        run.call(id);\n      };\n    };\n  // Rest old browsers\n  } else {\n    defer = function (id) {\n      setTimeout(ctx(run, id, 1), 0);\n    };\n  }\n}\nmodule.exports = {\n  set: setTask,\n  clear: clearTask\n};\n","var toInteger = require('./_to-integer');\nvar max = Math.max;\nvar min = Math.min;\nmodule.exports = function (index, length) {\n  index = toInteger(index);\n  return index < 0 ? max(index + length, 0) : min(index, length);\n};\n","// https://tc39.github.io/ecma262/#sec-toindex\nvar toInteger = require('./_to-integer');\nvar toLength = require('./_to-length');\nmodule.exports = function (it) {\n  if (it === undefined) return 0;\n  var number = toInteger(it);\n  var length = toLength(number);\n  if (number !== length) throw RangeError('Wrong length!');\n  return length;\n};\n","// 7.1.4 ToInteger\nvar ceil = Math.ceil;\nvar floor = Math.floor;\nmodule.exports = function (it) {\n  return isNaN(it = +it) ? 0 : (it > 0 ? floor : ceil)(it);\n};\n","// to indexed object, toObject with fallback for non-array-like ES3 strings\nvar IObject = require('./_iobject');\nvar defined = require('./_defined');\nmodule.exports = function (it) {\n  return IObject(defined(it));\n};\n","// 7.1.15 ToLength\nvar toInteger = require('./_to-integer');\nvar min = Math.min;\nmodule.exports = function (it) {\n  return it > 0 ? min(toInteger(it), 0x1fffffffffffff) : 0; // pow(2, 53) - 1 == 9007199254740991\n};\n","// 7.1.13 ToObject(argument)\nvar defined = require('./_defined');\nmodule.exports = function (it) {\n  return Object(defined(it));\n};\n","// 7.1.1 ToPrimitive(input [, PreferredType])\nvar isObject = require('./_is-object');\n// instead of the ES6 spec version, we didn't implement @@toPrimitive case\n// and the second argument - flag - preferred type is a string\nmodule.exports = function (it, S) {\n  if (!isObject(it)) return it;\n  var fn, val;\n  if (S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (typeof (fn = it.valueOf) == 'function' && !isObject(val = fn.call(it))) return val;\n  if (!S && typeof (fn = it.toString) == 'function' && !isObject(val = fn.call(it))) return val;\n  throw TypeError(\"Can't convert object to primitive value\");\n};\n","'use strict';\nif (require('./_descriptors')) {\n  var LIBRARY = require('./_library');\n  var global = require('./_global');\n  var fails = require('./_fails');\n  var $export = require('./_export');\n  var $typed = require('./_typed');\n  var $buffer = require('./_typed-buffer');\n  var ctx = require('./_ctx');\n  var anInstance = require('./_an-instance');\n  var propertyDesc = require('./_property-desc');\n  var hide = require('./_hide');\n  var redefineAll = require('./_redefine-all');\n  var toInteger = require('./_to-integer');\n  var toLength = require('./_to-length');\n  var toIndex = require('./_to-index');\n  var toAbsoluteIndex = require('./_to-absolute-index');\n  var toPrimitive = require('./_to-primitive');\n  var has = require('./_has');\n  var classof = require('./_classof');\n  var isObject = require('./_is-object');\n  var toObject = require('./_to-object');\n  var isArrayIter = require('./_is-array-iter');\n  var create = require('./_object-create');\n  var getPrototypeOf = require('./_object-gpo');\n  var gOPN = require('./_object-gopn').f;\n  var getIterFn = require('./core.get-iterator-method');\n  var uid = require('./_uid');\n  var wks = require('./_wks');\n  var createArrayMethod = require('./_array-methods');\n  var createArrayIncludes = require('./_array-includes');\n  var speciesConstructor = require('./_species-constructor');\n  var ArrayIterators = require('./es6.array.iterator');\n  var Iterators = require('./_iterators');\n  var $iterDetect = require('./_iter-detect');\n  var setSpecies = require('./_set-species');\n  var arrayFill = require('./_array-fill');\n  var arrayCopyWithin = require('./_array-copy-within');\n  var $DP = require('./_object-dp');\n  var $GOPD = require('./_object-gopd');\n  var dP = $DP.f;\n  var gOPD = $GOPD.f;\n  var RangeError = global.RangeError;\n  var TypeError = global.TypeError;\n  var Uint8Array = global.Uint8Array;\n  var ARRAY_BUFFER = 'ArrayBuffer';\n  var SHARED_BUFFER = 'Shared' + ARRAY_BUFFER;\n  var BYTES_PER_ELEMENT = 'BYTES_PER_ELEMENT';\n  var PROTOTYPE = 'prototype';\n  var ArrayProto = Array[PROTOTYPE];\n  var $ArrayBuffer = $buffer.ArrayBuffer;\n  var $DataView = $buffer.DataView;\n  var arrayForEach = createArrayMethod(0);\n  var arrayFilter = createArrayMethod(2);\n  var arraySome = createArrayMethod(3);\n  var arrayEvery = createArrayMethod(4);\n  var arrayFind = createArrayMethod(5);\n  var arrayFindIndex = createArrayMethod(6);\n  var arrayIncludes = createArrayIncludes(true);\n  var arrayIndexOf = createArrayIncludes(false);\n  var arrayValues = ArrayIterators.values;\n  var arrayKeys = ArrayIterators.keys;\n  var arrayEntries = ArrayIterators.entries;\n  var arrayLastIndexOf = ArrayProto.lastIndexOf;\n  var arrayReduce = ArrayProto.reduce;\n  var arrayReduceRight = ArrayProto.reduceRight;\n  var arrayJoin = ArrayProto.join;\n  var arraySort = ArrayProto.sort;\n  var arraySlice = ArrayProto.slice;\n  var arrayToString = ArrayProto.toString;\n  var arrayToLocaleString = ArrayProto.toLocaleString;\n  var ITERATOR = wks('iterator');\n  var TAG = wks('toStringTag');\n  var TYPED_CONSTRUCTOR = uid('typed_constructor');\n  var DEF_CONSTRUCTOR = uid('def_constructor');\n  var ALL_CONSTRUCTORS = $typed.CONSTR;\n  var TYPED_ARRAY = $typed.TYPED;\n  var VIEW = $typed.VIEW;\n  var WRONG_LENGTH = 'Wrong length!';\n\n  var $map = createArrayMethod(1, function (O, length) {\n    return allocate(speciesConstructor(O, O[DEF_CONSTRUCTOR]), length);\n  });\n\n  var LITTLE_ENDIAN = fails(function () {\n    // eslint-disable-next-line no-undef\n    return new Uint8Array(new Uint16Array([1]).buffer)[0] === 1;\n  });\n\n  var FORCED_SET = !!Uint8Array && !!Uint8Array[PROTOTYPE].set && fails(function () {\n    new Uint8Array(1).set({});\n  });\n\n  var toOffset = function (it, BYTES) {\n    var offset = toInteger(it);\n    if (offset < 0 || offset % BYTES) throw RangeError('Wrong offset!');\n    return offset;\n  };\n\n  var validate = function (it) {\n    if (isObject(it) && TYPED_ARRAY in it) return it;\n    throw TypeError(it + ' is not a typed array!');\n  };\n\n  var allocate = function (C, length) {\n    if (!(isObject(C) && TYPED_CONSTRUCTOR in C)) {\n      throw TypeError('It is not a typed array constructor!');\n    } return new C(length);\n  };\n\n  var speciesFromList = function (O, list) {\n    return fromList(speciesConstructor(O, O[DEF_CONSTRUCTOR]), list);\n  };\n\n  var fromList = function (C, list) {\n    var index = 0;\n    var length = list.length;\n    var result = allocate(C, length);\n    while (length > index) result[index] = list[index++];\n    return result;\n  };\n\n  var addGetter = function (it, key, internal) {\n    dP(it, key, { get: function () { return this._d[internal]; } });\n  };\n\n  var $from = function from(source /* , mapfn, thisArg */) {\n    var O = toObject(source);\n    var aLen = arguments.length;\n    var mapfn = aLen > 1 ? arguments[1] : undefined;\n    var mapping = mapfn !== undefined;\n    var iterFn = getIterFn(O);\n    var i, length, values, result, step, iterator;\n    if (iterFn != undefined && !isArrayIter(iterFn)) {\n      for (iterator = iterFn.call(O), values = [], i = 0; !(step = iterator.next()).done; i++) {\n        values.push(step.value);\n      } O = values;\n    }\n    if (mapping && aLen > 2) mapfn = ctx(mapfn, arguments[2], 2);\n    for (i = 0, length = toLength(O.length), result = allocate(this, length); length > i; i++) {\n      result[i] = mapping ? mapfn(O[i], i) : O[i];\n    }\n    return result;\n  };\n\n  var $of = function of(/* ...items */) {\n    var index = 0;\n    var length = arguments.length;\n    var result = allocate(this, length);\n    while (length > index) result[index] = arguments[index++];\n    return result;\n  };\n\n  // iOS Safari 6.x fails here\n  var TO_LOCALE_BUG = !!Uint8Array && fails(function () { arrayToLocaleString.call(new Uint8Array(1)); });\n\n  var $toLocaleString = function toLocaleString() {\n    return arrayToLocaleString.apply(TO_LOCALE_BUG ? arraySlice.call(validate(this)) : validate(this), arguments);\n  };\n\n  var proto = {\n    copyWithin: function copyWithin(target, start /* , end */) {\n      return arrayCopyWithin.call(validate(this), target, start, arguments.length > 2 ? arguments[2] : undefined);\n    },\n    every: function every(callbackfn /* , thisArg */) {\n      return arrayEvery(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    fill: function fill(value /* , start, end */) { // eslint-disable-line no-unused-vars\n      return arrayFill.apply(validate(this), arguments);\n    },\n    filter: function filter(callbackfn /* , thisArg */) {\n      return speciesFromList(this, arrayFilter(validate(this), callbackfn,\n        arguments.length > 1 ? arguments[1] : undefined));\n    },\n    find: function find(predicate /* , thisArg */) {\n      return arrayFind(validate(this), predicate, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    findIndex: function findIndex(predicate /* , thisArg */) {\n      return arrayFindIndex(validate(this), predicate, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    forEach: function forEach(callbackfn /* , thisArg */) {\n      arrayForEach(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    indexOf: function indexOf(searchElement /* , fromIndex */) {\n      return arrayIndexOf(validate(this), searchElement, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    includes: function includes(searchElement /* , fromIndex */) {\n      return arrayIncludes(validate(this), searchElement, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    join: function join(separator) { // eslint-disable-line no-unused-vars\n      return arrayJoin.apply(validate(this), arguments);\n    },\n    lastIndexOf: function lastIndexOf(searchElement /* , fromIndex */) { // eslint-disable-line no-unused-vars\n      return arrayLastIndexOf.apply(validate(this), arguments);\n    },\n    map: function map(mapfn /* , thisArg */) {\n      return $map(validate(this), mapfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    reduce: function reduce(callbackfn /* , initialValue */) { // eslint-disable-line no-unused-vars\n      return arrayReduce.apply(validate(this), arguments);\n    },\n    reduceRight: function reduceRight(callbackfn /* , initialValue */) { // eslint-disable-line no-unused-vars\n      return arrayReduceRight.apply(validate(this), arguments);\n    },\n    reverse: function reverse() {\n      var that = this;\n      var length = validate(that).length;\n      var middle = Math.floor(length / 2);\n      var index = 0;\n      var value;\n      while (index < middle) {\n        value = that[index];\n        that[index++] = that[--length];\n        that[length] = value;\n      } return that;\n    },\n    some: function some(callbackfn /* , thisArg */) {\n      return arraySome(validate(this), callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n    },\n    sort: function sort(comparefn) {\n      return arraySort.call(validate(this), comparefn);\n    },\n    subarray: function subarray(begin, end) {\n      var O = validate(this);\n      var length = O.length;\n      var $begin = toAbsoluteIndex(begin, length);\n      return new (speciesConstructor(O, O[DEF_CONSTRUCTOR]))(\n        O.buffer,\n        O.byteOffset + $begin * O.BYTES_PER_ELEMENT,\n        toLength((end === undefined ? length : toAbsoluteIndex(end, length)) - $begin)\n      );\n    }\n  };\n\n  var $slice = function slice(start, end) {\n    return speciesFromList(this, arraySlice.call(validate(this), start, end));\n  };\n\n  var $set = function set(arrayLike /* , offset */) {\n    validate(this);\n    var offset = toOffset(arguments[1], 1);\n    var length = this.length;\n    var src = toObject(arrayLike);\n    var len = toLength(src.length);\n    var index = 0;\n    if (len + offset > length) throw RangeError(WRONG_LENGTH);\n    while (index < len) this[offset + index] = src[index++];\n  };\n\n  var $iterators = {\n    entries: function entries() {\n      return arrayEntries.call(validate(this));\n    },\n    keys: function keys() {\n      return arrayKeys.call(validate(this));\n    },\n    values: function values() {\n      return arrayValues.call(validate(this));\n    }\n  };\n\n  var isTAIndex = function (target, key) {\n    return isObject(target)\n      && target[TYPED_ARRAY]\n      && typeof key != 'symbol'\n      && key in target\n      && String(+key) == String(key);\n  };\n  var $getDesc = function getOwnPropertyDescriptor(target, key) {\n    return isTAIndex(target, key = toPrimitive(key, true))\n      ? propertyDesc(2, target[key])\n      : gOPD(target, key);\n  };\n  var $setDesc = function defineProperty(target, key, desc) {\n    if (isTAIndex(target, key = toPrimitive(key, true))\n      && isObject(desc)\n      && has(desc, 'value')\n      && !has(desc, 'get')\n      && !has(desc, 'set')\n      // TODO: add validation descriptor w/o calling accessors\n      && !desc.configurable\n      && (!has(desc, 'writable') || desc.writable)\n      && (!has(desc, 'enumerable') || desc.enumerable)\n    ) {\n      target[key] = desc.value;\n      return target;\n    } return dP(target, key, desc);\n  };\n\n  if (!ALL_CONSTRUCTORS) {\n    $GOPD.f = $getDesc;\n    $DP.f = $setDesc;\n  }\n\n  $export($export.S + $export.F * !ALL_CONSTRUCTORS, 'Object', {\n    getOwnPropertyDescriptor: $getDesc,\n    defineProperty: $setDesc\n  });\n\n  if (fails(function () { arrayToString.call({}); })) {\n    arrayToString = arrayToLocaleString = function toString() {\n      return arrayJoin.call(this);\n    };\n  }\n\n  var $TypedArrayPrototype$ = redefineAll({}, proto);\n  redefineAll($TypedArrayPrototype$, $iterators);\n  hide($TypedArrayPrototype$, ITERATOR, $iterators.values);\n  redefineAll($TypedArrayPrototype$, {\n    slice: $slice,\n    set: $set,\n    constructor: function () { /* noop */ },\n    toString: arrayToString,\n    toLocaleString: $toLocaleString\n  });\n  addGetter($TypedArrayPrototype$, 'buffer', 'b');\n  addGetter($TypedArrayPrototype$, 'byteOffset', 'o');\n  addGetter($TypedArrayPrototype$, 'byteLength', 'l');\n  addGetter($TypedArrayPrototype$, 'length', 'e');\n  dP($TypedArrayPrototype$, TAG, {\n    get: function () { return this[TYPED_ARRAY]; }\n  });\n\n  // eslint-disable-next-line max-statements\n  module.exports = function (KEY, BYTES, wrapper, CLAMPED) {\n    CLAMPED = !!CLAMPED;\n    var NAME = KEY + (CLAMPED ? 'Clamped' : '') + 'Array';\n    var GETTER = 'get' + KEY;\n    var SETTER = 'set' + KEY;\n    var TypedArray = global[NAME];\n    var Base = TypedArray || {};\n    var TAC = TypedArray && getPrototypeOf(TypedArray);\n    var FORCED = !TypedArray || !$typed.ABV;\n    var O = {};\n    var TypedArrayPrototype = TypedArray && TypedArray[PROTOTYPE];\n    var getter = function (that, index) {\n      var data = that._d;\n      return data.v[GETTER](index * BYTES + data.o, LITTLE_ENDIAN);\n    };\n    var setter = function (that, index, value) {\n      var data = that._d;\n      if (CLAMPED) value = (value = Math.round(value)) < 0 ? 0 : value > 0xff ? 0xff : value & 0xff;\n      data.v[SETTER](index * BYTES + data.o, value, LITTLE_ENDIAN);\n    };\n    var addElement = function (that, index) {\n      dP(that, index, {\n        get: function () {\n          return getter(this, index);\n        },\n        set: function (value) {\n          return setter(this, index, value);\n        },\n        enumerable: true\n      });\n    };\n    if (FORCED) {\n      TypedArray = wrapper(function (that, data, $offset, $length) {\n        anInstance(that, TypedArray, NAME, '_d');\n        var index = 0;\n        var offset = 0;\n        var buffer, byteLength, length, klass;\n        if (!isObject(data)) {\n          length = toIndex(data);\n          byteLength = length * BYTES;\n          buffer = new $ArrayBuffer(byteLength);\n        } else if (data instanceof $ArrayBuffer || (klass = classof(data)) == ARRAY_BUFFER || klass == SHARED_BUFFER) {\n          buffer = data;\n          offset = toOffset($offset, BYTES);\n          var $len = data.byteLength;\n          if ($length === undefined) {\n            if ($len % BYTES) throw RangeError(WRONG_LENGTH);\n            byteLength = $len - offset;\n            if (byteLength < 0) throw RangeError(WRONG_LENGTH);\n          } else {\n            byteLength = toLength($length) * BYTES;\n            if (byteLength + offset > $len) throw RangeError(WRONG_LENGTH);\n          }\n          length = byteLength / BYTES;\n        } else if (TYPED_ARRAY in data) {\n          return fromList(TypedArray, data);\n        } else {\n          return $from.call(TypedArray, data);\n        }\n        hide(that, '_d', {\n          b: buffer,\n          o: offset,\n          l: byteLength,\n          e: length,\n          v: new $DataView(buffer)\n        });\n        while (index < length) addElement(that, index++);\n      });\n      TypedArrayPrototype = TypedArray[PROTOTYPE] = create($TypedArrayPrototype$);\n      hide(TypedArrayPrototype, 'constructor', TypedArray);\n    } else if (!fails(function () {\n      TypedArray(1);\n    }) || !fails(function () {\n      new TypedArray(-1); // eslint-disable-line no-new\n    }) || !$iterDetect(function (iter) {\n      new TypedArray(); // eslint-disable-line no-new\n      new TypedArray(null); // eslint-disable-line no-new\n      new TypedArray(1.5); // eslint-disable-line no-new\n      new TypedArray(iter); // eslint-disable-line no-new\n    }, true)) {\n      TypedArray = wrapper(function (that, data, $offset, $length) {\n        anInstance(that, TypedArray, NAME);\n        var klass;\n        // `ws` module bug, temporarily remove validation length for Uint8Array\n        // https://github.com/websockets/ws/pull/645\n        if (!isObject(data)) return new Base(toIndex(data));\n        if (data instanceof $ArrayBuffer || (klass = classof(data)) == ARRAY_BUFFER || klass == SHARED_BUFFER) {\n          return $length !== undefined\n            ? new Base(data, toOffset($offset, BYTES), $length)\n            : $offset !== undefined\n              ? new Base(data, toOffset($offset, BYTES))\n              : new Base(data);\n        }\n        if (TYPED_ARRAY in data) return fromList(TypedArray, data);\n        return $from.call(TypedArray, data);\n      });\n      arrayForEach(TAC !== Function.prototype ? gOPN(Base).concat(gOPN(TAC)) : gOPN(Base), function (key) {\n        if (!(key in TypedArray)) hide(TypedArray, key, Base[key]);\n      });\n      TypedArray[PROTOTYPE] = TypedArrayPrototype;\n      if (!LIBRARY) TypedArrayPrototype.constructor = TypedArray;\n    }\n    var $nativeIterator = TypedArrayPrototype[ITERATOR];\n    var CORRECT_ITER_NAME = !!$nativeIterator\n      && ($nativeIterator.name == 'values' || $nativeIterator.name == undefined);\n    var $iterator = $iterators.values;\n    hide(TypedArray, TYPED_CONSTRUCTOR, true);\n    hide(TypedArrayPrototype, TYPED_ARRAY, NAME);\n    hide(TypedArrayPrototype, VIEW, true);\n    hide(TypedArrayPrototype, DEF_CONSTRUCTOR, TypedArray);\n\n    if (CLAMPED ? new TypedArray(1)[TAG] != NAME : !(TAG in TypedArrayPrototype)) {\n      dP(TypedArrayPrototype, TAG, {\n        get: function () { return NAME; }\n      });\n    }\n\n    O[NAME] = TypedArray;\n\n    $export($export.G + $export.W + $export.F * (TypedArray != Base), O);\n\n    $export($export.S, NAME, {\n      BYTES_PER_ELEMENT: BYTES\n    });\n\n    $export($export.S + $export.F * fails(function () { Base.of.call(TypedArray, 1); }), NAME, {\n      from: $from,\n      of: $of\n    });\n\n    if (!(BYTES_PER_ELEMENT in TypedArrayPrototype)) hide(TypedArrayPrototype, BYTES_PER_ELEMENT, BYTES);\n\n    $export($export.P, NAME, proto);\n\n    setSpecies(NAME);\n\n    $export($export.P + $export.F * FORCED_SET, NAME, { set: $set });\n\n    $export($export.P + $export.F * !CORRECT_ITER_NAME, NAME, $iterators);\n\n    if (!LIBRARY && TypedArrayPrototype.toString != arrayToString) TypedArrayPrototype.toString = arrayToString;\n\n    $export($export.P + $export.F * fails(function () {\n      new TypedArray(1).slice();\n    }), NAME, { slice: $slice });\n\n    $export($export.P + $export.F * (fails(function () {\n      return [1, 2].toLocaleString() != new TypedArray([1, 2]).toLocaleString();\n    }) || !fails(function () {\n      TypedArrayPrototype.toLocaleString.call([1, 2]);\n    })), NAME, { toLocaleString: $toLocaleString });\n\n    Iterators[NAME] = CORRECT_ITER_NAME ? $nativeIterator : $iterator;\n    if (!LIBRARY && !CORRECT_ITER_NAME) hide(TypedArrayPrototype, ITERATOR, $iterator);\n  };\n} else module.exports = function () { /* empty */ };\n","'use strict';\nvar global = require('./_global');\nvar DESCRIPTORS = require('./_descriptors');\nvar LIBRARY = require('./_library');\nvar $typed = require('./_typed');\nvar hide = require('./_hide');\nvar redefineAll = require('./_redefine-all');\nvar fails = require('./_fails');\nvar anInstance = require('./_an-instance');\nvar toInteger = require('./_to-integer');\nvar toLength = require('./_to-length');\nvar toIndex = require('./_to-index');\nvar gOPN = require('./_object-gopn').f;\nvar dP = require('./_object-dp').f;\nvar arrayFill = require('./_array-fill');\nvar setToStringTag = require('./_set-to-string-tag');\nvar ARRAY_BUFFER = 'ArrayBuffer';\nvar DATA_VIEW = 'DataView';\nvar PROTOTYPE = 'prototype';\nvar WRONG_LENGTH = 'Wrong length!';\nvar WRONG_INDEX = 'Wrong index!';\nvar $ArrayBuffer = global[ARRAY_BUFFER];\nvar $DataView = global[DATA_VIEW];\nvar Math = global.Math;\nvar RangeError = global.RangeError;\n// eslint-disable-next-line no-shadow-restricted-names\nvar Infinity = global.Infinity;\nvar BaseBuffer = $ArrayBuffer;\nvar abs = Math.abs;\nvar pow = Math.pow;\nvar floor = Math.floor;\nvar log = Math.log;\nvar LN2 = Math.LN2;\nvar BUFFER = 'buffer';\nvar BYTE_LENGTH = 'byteLength';\nvar BYTE_OFFSET = 'byteOffset';\nvar $BUFFER = DESCRIPTORS ? '_b' : BUFFER;\nvar $LENGTH = DESCRIPTORS ? '_l' : BYTE_LENGTH;\nvar $OFFSET = DESCRIPTORS ? '_o' : BYTE_OFFSET;\n\n// IEEE754 conversions based on https://github.com/feross/ieee754\nfunction packIEEE754(value, mLen, nBytes) {\n  var buffer = new Array(nBytes);\n  var eLen = nBytes * 8 - mLen - 1;\n  var eMax = (1 << eLen) - 1;\n  var eBias = eMax >> 1;\n  var rt = mLen === 23 ? pow(2, -24) - pow(2, -77) : 0;\n  var i = 0;\n  var s = value < 0 || value === 0 && 1 / value < 0 ? 1 : 0;\n  var e, m, c;\n  value = abs(value);\n  // eslint-disable-next-line no-self-compare\n  if (value != value || value === Infinity) {\n    // eslint-disable-next-line no-self-compare\n    m = value != value ? 1 : 0;\n    e = eMax;\n  } else {\n    e = floor(log(value) / LN2);\n    if (value * (c = pow(2, -e)) < 1) {\n      e--;\n      c *= 2;\n    }\n    if (e + eBias >= 1) {\n      value += rt / c;\n    } else {\n      value += rt * pow(2, 1 - eBias);\n    }\n    if (value * c >= 2) {\n      e++;\n      c /= 2;\n    }\n    if (e + eBias >= eMax) {\n      m = 0;\n      e = eMax;\n    } else if (e + eBias >= 1) {\n      m = (value * c - 1) * pow(2, mLen);\n      e = e + eBias;\n    } else {\n      m = value * pow(2, eBias - 1) * pow(2, mLen);\n      e = 0;\n    }\n  }\n  for (; mLen >= 8; buffer[i++] = m & 255, m /= 256, mLen -= 8);\n  e = e << mLen | m;\n  eLen += mLen;\n  for (; eLen > 0; buffer[i++] = e & 255, e /= 256, eLen -= 8);\n  buffer[--i] |= s * 128;\n  return buffer;\n}\nfunction unpackIEEE754(buffer, mLen, nBytes) {\n  var eLen = nBytes * 8 - mLen - 1;\n  var eMax = (1 << eLen) - 1;\n  var eBias = eMax >> 1;\n  var nBits = eLen - 7;\n  var i = nBytes - 1;\n  var s = buffer[i--];\n  var e = s & 127;\n  var m;\n  s >>= 7;\n  for (; nBits > 0; e = e * 256 + buffer[i], i--, nBits -= 8);\n  m = e & (1 << -nBits) - 1;\n  e >>= -nBits;\n  nBits += mLen;\n  for (; nBits > 0; m = m * 256 + buffer[i], i--, nBits -= 8);\n  if (e === 0) {\n    e = 1 - eBias;\n  } else if (e === eMax) {\n    return m ? NaN : s ? -Infinity : Infinity;\n  } else {\n    m = m + pow(2, mLen);\n    e = e - eBias;\n  } return (s ? -1 : 1) * m * pow(2, e - mLen);\n}\n\nfunction unpackI32(bytes) {\n  return bytes[3] << 24 | bytes[2] << 16 | bytes[1] << 8 | bytes[0];\n}\nfunction packI8(it) {\n  return [it & 0xff];\n}\nfunction packI16(it) {\n  return [it & 0xff, it >> 8 & 0xff];\n}\nfunction packI32(it) {\n  return [it & 0xff, it >> 8 & 0xff, it >> 16 & 0xff, it >> 24 & 0xff];\n}\nfunction packF64(it) {\n  return packIEEE754(it, 52, 8);\n}\nfunction packF32(it) {\n  return packIEEE754(it, 23, 4);\n}\n\nfunction addGetter(C, key, internal) {\n  dP(C[PROTOTYPE], key, { get: function () { return this[internal]; } });\n}\n\nfunction get(view, bytes, index, isLittleEndian) {\n  var numIndex = +index;\n  var intIndex = toIndex(numIndex);\n  if (intIndex + bytes > view[$LENGTH]) throw RangeError(WRONG_INDEX);\n  var store = view[$BUFFER]._b;\n  var start = intIndex + view[$OFFSET];\n  var pack = store.slice(start, start + bytes);\n  return isLittleEndian ? pack : pack.reverse();\n}\nfunction set(view, bytes, index, conversion, value, isLittleEndian) {\n  var numIndex = +index;\n  var intIndex = toIndex(numIndex);\n  if (intIndex + bytes > view[$LENGTH]) throw RangeError(WRONG_INDEX);\n  var store = view[$BUFFER]._b;\n  var start = intIndex + view[$OFFSET];\n  var pack = conversion(+value);\n  for (var i = 0; i < bytes; i++) store[start + i] = pack[isLittleEndian ? i : bytes - i - 1];\n}\n\nif (!$typed.ABV) {\n  $ArrayBuffer = function ArrayBuffer(length) {\n    anInstance(this, $ArrayBuffer, ARRAY_BUFFER);\n    var byteLength = toIndex(length);\n    this._b = arrayFill.call(new Array(byteLength), 0);\n    this[$LENGTH] = byteLength;\n  };\n\n  $DataView = function DataView(buffer, byteOffset, byteLength) {\n    anInstance(this, $DataView, DATA_VIEW);\n    anInstance(buffer, $ArrayBuffer, DATA_VIEW);\n    var bufferLength = buffer[$LENGTH];\n    var offset = toInteger(byteOffset);\n    if (offset < 0 || offset > bufferLength) throw RangeError('Wrong offset!');\n    byteLength = byteLength === undefined ? bufferLength - offset : toLength(byteLength);\n    if (offset + byteLength > bufferLength) throw RangeError(WRONG_LENGTH);\n    this[$BUFFER] = buffer;\n    this[$OFFSET] = offset;\n    this[$LENGTH] = byteLength;\n  };\n\n  if (DESCRIPTORS) {\n    addGetter($ArrayBuffer, BYTE_LENGTH, '_l');\n    addGetter($DataView, BUFFER, '_b');\n    addGetter($DataView, BYTE_LENGTH, '_l');\n    addGetter($DataView, BYTE_OFFSET, '_o');\n  }\n\n  redefineAll($DataView[PROTOTYPE], {\n    getInt8: function getInt8(byteOffset) {\n      return get(this, 1, byteOffset)[0] << 24 >> 24;\n    },\n    getUint8: function getUint8(byteOffset) {\n      return get(this, 1, byteOffset)[0];\n    },\n    getInt16: function getInt16(byteOffset /* , littleEndian */) {\n      var bytes = get(this, 2, byteOffset, arguments[1]);\n      return (bytes[1] << 8 | bytes[0]) << 16 >> 16;\n    },\n    getUint16: function getUint16(byteOffset /* , littleEndian */) {\n      var bytes = get(this, 2, byteOffset, arguments[1]);\n      return bytes[1] << 8 | bytes[0];\n    },\n    getInt32: function getInt32(byteOffset /* , littleEndian */) {\n      return unpackI32(get(this, 4, byteOffset, arguments[1]));\n    },\n    getUint32: function getUint32(byteOffset /* , littleEndian */) {\n      return unpackI32(get(this, 4, byteOffset, arguments[1])) >>> 0;\n    },\n    getFloat32: function getFloat32(byteOffset /* , littleEndian */) {\n      return unpackIEEE754(get(this, 4, byteOffset, arguments[1]), 23, 4);\n    },\n    getFloat64: function getFloat64(byteOffset /* , littleEndian */) {\n      return unpackIEEE754(get(this, 8, byteOffset, arguments[1]), 52, 8);\n    },\n    setInt8: function setInt8(byteOffset, value) {\n      set(this, 1, byteOffset, packI8, value);\n    },\n    setUint8: function setUint8(byteOffset, value) {\n      set(this, 1, byteOffset, packI8, value);\n    },\n    setInt16: function setInt16(byteOffset, value /* , littleEndian */) {\n      set(this, 2, byteOffset, packI16, value, arguments[2]);\n    },\n    setUint16: function setUint16(byteOffset, value /* , littleEndian */) {\n      set(this, 2, byteOffset, packI16, value, arguments[2]);\n    },\n    setInt32: function setInt32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packI32, value, arguments[2]);\n    },\n    setUint32: function setUint32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packI32, value, arguments[2]);\n    },\n    setFloat32: function setFloat32(byteOffset, value /* , littleEndian */) {\n      set(this, 4, byteOffset, packF32, value, arguments[2]);\n    },\n    setFloat64: function setFloat64(byteOffset, value /* , littleEndian */) {\n      set(this, 8, byteOffset, packF64, value, arguments[2]);\n    }\n  });\n} else {\n  if (!fails(function () {\n    $ArrayBuffer(1);\n  }) || !fails(function () {\n    new $ArrayBuffer(-1); // eslint-disable-line no-new\n  }) || fails(function () {\n    new $ArrayBuffer(); // eslint-disable-line no-new\n    new $ArrayBuffer(1.5); // eslint-disable-line no-new\n    new $ArrayBuffer(NaN); // eslint-disable-line no-new\n    return $ArrayBuffer.name != ARRAY_BUFFER;\n  })) {\n    $ArrayBuffer = function ArrayBuffer(length) {\n      anInstance(this, $ArrayBuffer);\n      return new BaseBuffer(toIndex(length));\n    };\n    var ArrayBufferProto = $ArrayBuffer[PROTOTYPE] = BaseBuffer[PROTOTYPE];\n    for (var keys = gOPN(BaseBuffer), j = 0, key; keys.length > j;) {\n      if (!((key = keys[j++]) in $ArrayBuffer)) hide($ArrayBuffer, key, BaseBuffer[key]);\n    }\n    if (!LIBRARY) ArrayBufferProto.constructor = $ArrayBuffer;\n  }\n  // iOS Safari 7.x bug\n  var view = new $DataView(new $ArrayBuffer(2));\n  var $setInt8 = $DataView[PROTOTYPE].setInt8;\n  view.setInt8(0, 2147483648);\n  view.setInt8(1, 2147483649);\n  if (view.getInt8(0) || !view.getInt8(1)) redefineAll($DataView[PROTOTYPE], {\n    setInt8: function setInt8(byteOffset, value) {\n      $setInt8.call(this, byteOffset, value << 24 >> 24);\n    },\n    setUint8: function setUint8(byteOffset, value) {\n      $setInt8.call(this, byteOffset, value << 24 >> 24);\n    }\n  }, true);\n}\nsetToStringTag($ArrayBuffer, ARRAY_BUFFER);\nsetToStringTag($DataView, DATA_VIEW);\nhide($DataView[PROTOTYPE], $typed.VIEW, true);\nexports[ARRAY_BUFFER] = $ArrayBuffer;\nexports[DATA_VIEW] = $DataView;\n","var global = require('./_global');\nvar hide = require('./_hide');\nvar uid = require('./_uid');\nvar TYPED = uid('typed_array');\nvar VIEW = uid('view');\nvar ABV = !!(global.ArrayBuffer && global.DataView);\nvar CONSTR = ABV;\nvar i = 0;\nvar l = 9;\nvar Typed;\n\nvar TypedArrayConstructors = (\n  'Int8Array,Uint8Array,Uint8ClampedArray,Int16Array,Uint16Array,Int32Array,Uint32Array,Float32Array,Float64Array'\n).split(',');\n\nwhile (i < l) {\n  if (Typed = global[TypedArrayConstructors[i++]]) {\n    hide(Typed.prototype, TYPED, true);\n    hide(Typed.prototype, VIEW, true);\n  } else CONSTR = false;\n}\n\nmodule.exports = {\n  ABV: ABV,\n  CONSTR: CONSTR,\n  TYPED: TYPED,\n  VIEW: VIEW\n};\n","var id = 0;\nvar px = Math.random();\nmodule.exports = function (key) {\n  return 'Symbol('.concat(key === undefined ? '' : key, ')_', (++id + px).toString(36));\n};\n","var global = require('./_global');\nvar navigator = global.navigator;\n\nmodule.exports = navigator && navigator.userAgent || '';\n","var isObject = require('./_is-object');\nmodule.exports = function (it, TYPE) {\n  if (!isObject(it) || it._t !== TYPE) throw TypeError('Incompatible receiver, ' + TYPE + ' required!');\n  return it;\n};\n","var global = require('./_global');\nvar core = require('./_core');\nvar LIBRARY = require('./_library');\nvar wksExt = require('./_wks-ext');\nvar defineProperty = require('./_object-dp').f;\nmodule.exports = function (name) {\n  var $Symbol = core.Symbol || (core.Symbol = LIBRARY ? {} : global.Symbol || {});\n  if (name.charAt(0) != '_' && !(name in $Symbol)) defineProperty($Symbol, name, { value: wksExt.f(name) });\n};\n","exports.f = require('./_wks');\n","var store = require('./_shared')('wks');\nvar uid = require('./_uid');\nvar Symbol = require('./_global').Symbol;\nvar USE_SYMBOL = typeof Symbol == 'function';\n\nvar $exports = module.exports = function (name) {\n  return store[name] || (store[name] =\n    USE_SYMBOL && Symbol[name] || (USE_SYMBOL ? Symbol : uid)('Symbol.' + name));\n};\n\n$exports.store = store;\n","var classof = require('./_classof');\nvar ITERATOR = require('./_wks')('iterator');\nvar Iterators = require('./_iterators');\nmodule.exports = require('./_core').getIteratorMethod = function (it) {\n  if (it != undefined) return it[ITERATOR]\n    || it['@@iterator']\n    || Iterators[classof(it)];\n};\n","// https://github.com/benjamingr/RexExp.escape\nvar $export = require('./_export');\nvar $re = require('./_replacer')(/[\\\\^$*+?.()|[\\]{}]/g, '\\\\$&');\n\n$export($export.S, 'RegExp', { escape: function escape(it) { return $re(it); } });\n","// 22.1.3.3 Array.prototype.copyWithin(target, start, end = this.length)\nvar $export = require('./_export');\n\n$export($export.P, 'Array', { copyWithin: require('./_array-copy-within') });\n\nrequire('./_add-to-unscopables')('copyWithin');\n","'use strict';\nvar $export = require('./_export');\nvar $every = require('./_array-methods')(4);\n\n$export($export.P + $export.F * !require('./_strict-method')([].every, true), 'Array', {\n  // 22.1.3.5 / 15.4.4.16 Array.prototype.every(callbackfn [, thisArg])\n  every: function every(callbackfn /* , thisArg */) {\n    return $every(this, callbackfn, arguments[1]);\n  }\n});\n","// 22.1.3.6 Array.prototype.fill(value, start = 0, end = this.length)\nvar $export = require('./_export');\n\n$export($export.P, 'Array', { fill: require('./_array-fill') });\n\nrequire('./_add-to-unscopables')('fill');\n","'use strict';\nvar $export = require('./_export');\nvar $filter = require('./_array-methods')(2);\n\n$export($export.P + $export.F * !require('./_strict-method')([].filter, true), 'Array', {\n  // 22.1.3.7 / 15.4.4.20 Array.prototype.filter(callbackfn [, thisArg])\n  filter: function filter(callbackfn /* , thisArg */) {\n    return $filter(this, callbackfn, arguments[1]);\n  }\n});\n","'use strict';\n// 22.1.3.9 Array.prototype.findIndex(predicate, thisArg = undefined)\nvar $export = require('./_export');\nvar $find = require('./_array-methods')(6);\nvar KEY = 'findIndex';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  findIndex: function findIndex(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\nrequire('./_add-to-unscopables')(KEY);\n","'use strict';\n// 22.1.3.8 Array.prototype.find(predicate, thisArg = undefined)\nvar $export = require('./_export');\nvar $find = require('./_array-methods')(5);\nvar KEY = 'find';\nvar forced = true;\n// Shouldn't skip holes\nif (KEY in []) Array(1)[KEY](function () { forced = false; });\n$export($export.P + $export.F * forced, 'Array', {\n  find: function find(callbackfn /* , that = undefined */) {\n    return $find(this, callbackfn, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\nrequire('./_add-to-unscopables')(KEY);\n","'use strict';\nvar $export = require('./_export');\nvar $forEach = require('./_array-methods')(0);\nvar STRICT = require('./_strict-method')([].forEach, true);\n\n$export($export.P + $export.F * !STRICT, 'Array', {\n  // 22.1.3.10 / 15.4.4.18 Array.prototype.forEach(callbackfn [, thisArg])\n  forEach: function forEach(callbackfn /* , thisArg */) {\n    return $forEach(this, callbackfn, arguments[1]);\n  }\n});\n","'use strict';\nvar ctx = require('./_ctx');\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar call = require('./_iter-call');\nvar isArrayIter = require('./_is-array-iter');\nvar toLength = require('./_to-length');\nvar createProperty = require('./_create-property');\nvar getIterFn = require('./core.get-iterator-method');\n\n$export($export.S + $export.F * !require('./_iter-detect')(function (iter) { Array.from(iter); }), 'Array', {\n  // 22.1.2.1 Array.from(arrayLike, mapfn = undefined, thisArg = undefined)\n  from: function from(arrayLike /* , mapfn = undefined, thisArg = undefined */) {\n    var O = toObject(arrayLike);\n    var C = typeof this == 'function' ? this : Array;\n    var aLen = arguments.length;\n    var mapfn = aLen > 1 ? arguments[1] : undefined;\n    var mapping = mapfn !== undefined;\n    var index = 0;\n    var iterFn = getIterFn(O);\n    var length, result, step, iterator;\n    if (mapping) mapfn = ctx(mapfn, aLen > 2 ? arguments[2] : undefined, 2);\n    // if object isn't iterable or it's array with default iterator - use simple case\n    if (iterFn != undefined && !(C == Array && isArrayIter(iterFn))) {\n      for (iterator = iterFn.call(O), result = new C(); !(step = iterator.next()).done; index++) {\n        createProperty(result, index, mapping ? call(iterator, mapfn, [step.value, index], true) : step.value);\n      }\n    } else {\n      length = toLength(O.length);\n      for (result = new C(length); length > index; index++) {\n        createProperty(result, index, mapping ? mapfn(O[index], index) : O[index]);\n      }\n    }\n    result.length = index;\n    return result;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $indexOf = require('./_array-includes')(false);\nvar $native = [].indexOf;\nvar NEGATIVE_ZERO = !!$native && 1 / [1].indexOf(1, -0) < 0;\n\n$export($export.P + $export.F * (NEGATIVE_ZERO || !require('./_strict-method')($native)), 'Array', {\n  // 22.1.3.11 / 15.4.4.14 Array.prototype.indexOf(searchElement [, fromIndex])\n  indexOf: function indexOf(searchElement /* , fromIndex = 0 */) {\n    return NEGATIVE_ZERO\n      // convert -0 to +0\n      ? $native.apply(this, arguments) || 0\n      : $indexOf(this, searchElement, arguments[1]);\n  }\n});\n","// 22.1.2.2 / 15.4.3.2 Array.isArray(arg)\nvar $export = require('./_export');\n\n$export($export.S, 'Array', { isArray: require('./_is-array') });\n","'use strict';\nvar addToUnscopables = require('./_add-to-unscopables');\nvar step = require('./_iter-step');\nvar Iterators = require('./_iterators');\nvar toIObject = require('./_to-iobject');\n\n// 22.1.3.4 Array.prototype.entries()\n// 22.1.3.13 Array.prototype.keys()\n// 22.1.3.29 Array.prototype.values()\n// 22.1.3.30 Array.prototype[@@iterator]()\nmodule.exports = require('./_iter-define')(Array, 'Array', function (iterated, kind) {\n  this._t = toIObject(iterated); // target\n  this._i = 0;                   // next index\n  this._k = kind;                // kind\n// 22.1.5.2.1 %ArrayIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var kind = this._k;\n  var index = this._i++;\n  if (!O || index >= O.length) {\n    this._t = undefined;\n    return step(1);\n  }\n  if (kind == 'keys') return step(0, index);\n  if (kind == 'values') return step(0, O[index]);\n  return step(0, [index, O[index]]);\n}, 'values');\n\n// argumentsList[@@iterator] is %ArrayProto_values% (9.4.4.6, 9.4.4.7)\nIterators.Arguments = Iterators.Array;\n\naddToUnscopables('keys');\naddToUnscopables('values');\naddToUnscopables('entries');\n","'use strict';\n// 22.1.3.13 Array.prototype.join(separator)\nvar $export = require('./_export');\nvar toIObject = require('./_to-iobject');\nvar arrayJoin = [].join;\n\n// fallback for not array-like strings\n$export($export.P + $export.F * (require('./_iobject') != Object || !require('./_strict-method')(arrayJoin)), 'Array', {\n  join: function join(separator) {\n    return arrayJoin.call(toIObject(this), separator === undefined ? ',' : separator);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar toIObject = require('./_to-iobject');\nvar toInteger = require('./_to-integer');\nvar toLength = require('./_to-length');\nvar $native = [].lastIndexOf;\nvar NEGATIVE_ZERO = !!$native && 1 / [1].lastIndexOf(1, -0) < 0;\n\n$export($export.P + $export.F * (NEGATIVE_ZERO || !require('./_strict-method')($native)), 'Array', {\n  // 22.1.3.14 / 15.4.4.15 Array.prototype.lastIndexOf(searchElement [, fromIndex])\n  lastIndexOf: function lastIndexOf(searchElement /* , fromIndex = @[*-1] */) {\n    // convert -0 to +0\n    if (NEGATIVE_ZERO) return $native.apply(this, arguments) || 0;\n    var O = toIObject(this);\n    var length = toLength(O.length);\n    var index = length - 1;\n    if (arguments.length > 1) index = Math.min(index, toInteger(arguments[1]));\n    if (index < 0) index = length + index;\n    for (;index >= 0; index--) if (index in O) if (O[index] === searchElement) return index || 0;\n    return -1;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $map = require('./_array-methods')(1);\n\n$export($export.P + $export.F * !require('./_strict-method')([].map, true), 'Array', {\n  // 22.1.3.15 / 15.4.4.19 Array.prototype.map(callbackfn [, thisArg])\n  map: function map(callbackfn /* , thisArg */) {\n    return $map(this, callbackfn, arguments[1]);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar createProperty = require('./_create-property');\n\n// WebKit Array.of isn't generic\n$export($export.S + $export.F * require('./_fails')(function () {\n  function F() { /* empty */ }\n  return !(Array.of.call(F) instanceof F);\n}), 'Array', {\n  // 22.1.2.3 Array.of( ...items)\n  of: function of(/* ...args */) {\n    var index = 0;\n    var aLen = arguments.length;\n    var result = new (typeof this == 'function' ? this : Array)(aLen);\n    while (aLen > index) createProperty(result, index, arguments[index++]);\n    result.length = aLen;\n    return result;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $reduce = require('./_array-reduce');\n\n$export($export.P + $export.F * !require('./_strict-method')([].reduceRight, true), 'Array', {\n  // 22.1.3.19 / 15.4.4.22 Array.prototype.reduceRight(callbackfn [, initialValue])\n  reduceRight: function reduceRight(callbackfn /* , initialValue */) {\n    return $reduce(this, callbackfn, arguments.length, arguments[1], true);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $reduce = require('./_array-reduce');\n\n$export($export.P + $export.F * !require('./_strict-method')([].reduce, true), 'Array', {\n  // 22.1.3.18 / 15.4.4.21 Array.prototype.reduce(callbackfn [, initialValue])\n  reduce: function reduce(callbackfn /* , initialValue */) {\n    return $reduce(this, callbackfn, arguments.length, arguments[1], false);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar html = require('./_html');\nvar cof = require('./_cof');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nvar toLength = require('./_to-length');\nvar arraySlice = [].slice;\n\n// fallback for not array-like ES3 strings and DOM objects\n$export($export.P + $export.F * require('./_fails')(function () {\n  if (html) arraySlice.call(html);\n}), 'Array', {\n  slice: function slice(begin, end) {\n    var len = toLength(this.length);\n    var klass = cof(this);\n    end = end === undefined ? len : end;\n    if (klass == 'Array') return arraySlice.call(this, begin, end);\n    var start = toAbsoluteIndex(begin, len);\n    var upTo = toAbsoluteIndex(end, len);\n    var size = toLength(upTo - start);\n    var cloned = new Array(size);\n    var i = 0;\n    for (; i < size; i++) cloned[i] = klass == 'String'\n      ? this.charAt(start + i)\n      : this[start + i];\n    return cloned;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $some = require('./_array-methods')(3);\n\n$export($export.P + $export.F * !require('./_strict-method')([].some, true), 'Array', {\n  // 22.1.3.23 / 15.4.4.17 Array.prototype.some(callbackfn [, thisArg])\n  some: function some(callbackfn /* , thisArg */) {\n    return $some(this, callbackfn, arguments[1]);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar aFunction = require('./_a-function');\nvar toObject = require('./_to-object');\nvar fails = require('./_fails');\nvar $sort = [].sort;\nvar test = [1, 2, 3];\n\n$export($export.P + $export.F * (fails(function () {\n  // IE8-\n  test.sort(undefined);\n}) || !fails(function () {\n  // V8 bug\n  test.sort(null);\n  // Old WebKit\n}) || !require('./_strict-method')($sort)), 'Array', {\n  // 22.1.3.25 Array.prototype.sort(comparefn)\n  sort: function sort(comparefn) {\n    return comparefn === undefined\n      ? $sort.call(toObject(this))\n      : $sort.call(toObject(this), aFunction(comparefn));\n  }\n});\n","require('./_set-species')('Array');\n","// 20.3.3.1 / 15.9.4.4 Date.now()\nvar $export = require('./_export');\n\n$export($export.S, 'Date', { now: function () { return new Date().getTime(); } });\n","// 20.3.4.36 / 15.9.5.43 Date.prototype.toISOString()\nvar $export = require('./_export');\nvar toISOString = require('./_date-to-iso-string');\n\n// PhantomJS / old WebKit has a broken implementations\n$export($export.P + $export.F * (Date.prototype.toISOString !== toISOString), 'Date', {\n  toISOString: toISOString\n});\n","'use strict';\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar toPrimitive = require('./_to-primitive');\n\n$export($export.P + $export.F * require('./_fails')(function () {\n  return new Date(NaN).toJSON() !== null\n    || Date.prototype.toJSON.call({ toISOString: function () { return 1; } }) !== 1;\n}), 'Date', {\n  // eslint-disable-next-line no-unused-vars\n  toJSON: function toJSON(key) {\n    var O = toObject(this);\n    var pv = toPrimitive(O);\n    return typeof pv == 'number' && !isFinite(pv) ? null : O.toISOString();\n  }\n});\n","var TO_PRIMITIVE = require('./_wks')('toPrimitive');\nvar proto = Date.prototype;\n\nif (!(TO_PRIMITIVE in proto)) require('./_hide')(proto, TO_PRIMITIVE, require('./_date-to-primitive'));\n","var DateProto = Date.prototype;\nvar INVALID_DATE = 'Invalid Date';\nvar TO_STRING = 'toString';\nvar $toString = DateProto[TO_STRING];\nvar getTime = DateProto.getTime;\nif (new Date(NaN) + '' != INVALID_DATE) {\n  require('./_redefine')(DateProto, TO_STRING, function toString() {\n    var value = getTime.call(this);\n    // eslint-disable-next-line no-self-compare\n    return value === value ? $toString.call(this) : INVALID_DATE;\n  });\n}\n","// 19.2.3.2 / 15.3.4.5 Function.prototype.bind(thisArg, args...)\nvar $export = require('./_export');\n\n$export($export.P, 'Function', { bind: require('./_bind') });\n","'use strict';\nvar isObject = require('./_is-object');\nvar getPrototypeOf = require('./_object-gpo');\nvar HAS_INSTANCE = require('./_wks')('hasInstance');\nvar FunctionProto = Function.prototype;\n// 19.2.3.6 Function.prototype[@@hasInstance](V)\nif (!(HAS_INSTANCE in FunctionProto)) require('./_object-dp').f(FunctionProto, HAS_INSTANCE, { value: function (O) {\n  if (typeof this != 'function' || !isObject(O)) return false;\n  if (!isObject(this.prototype)) return O instanceof this;\n  // for environment w/o native `@@hasInstance` logic enough `instanceof`, but add this:\n  while (O = getPrototypeOf(O)) if (this.prototype === O) return true;\n  return false;\n} });\n","var dP = require('./_object-dp').f;\nvar FProto = Function.prototype;\nvar nameRE = /^\\s*function ([^ (]*)/;\nvar NAME = 'name';\n\n// 19.2.4.2 name\nNAME in FProto || require('./_descriptors') && dP(FProto, NAME, {\n  configurable: true,\n  get: function () {\n    try {\n      return ('' + this).match(nameRE)[1];\n    } catch (e) {\n      return '';\n    }\n  }\n});\n","'use strict';\nvar strong = require('./_collection-strong');\nvar validate = require('./_validate-collection');\nvar MAP = 'Map';\n\n// 23.1 Map Objects\nmodule.exports = require('./_collection')(MAP, function (get) {\n  return function Map() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.1.3.6 Map.prototype.get(key)\n  get: function get(key) {\n    var entry = strong.getEntry(validate(this, MAP), key);\n    return entry && entry.v;\n  },\n  // 23.1.3.9 Map.prototype.set(key, value)\n  set: function set(key, value) {\n    return strong.def(validate(this, MAP), key === 0 ? 0 : key, value);\n  }\n}, strong, true);\n","// 20.2.2.3 Math.acosh(x)\nvar $export = require('./_export');\nvar log1p = require('./_math-log1p');\nvar sqrt = Math.sqrt;\nvar $acosh = Math.acosh;\n\n$export($export.S + $export.F * !($acosh\n  // V8 bug: https://code.google.com/p/v8/issues/detail?id=3509\n  && Math.floor($acosh(Number.MAX_VALUE)) == 710\n  // Tor Browser bug: Math.acosh(Infinity) -> NaN\n  && $acosh(Infinity) == Infinity\n), 'Math', {\n  acosh: function acosh(x) {\n    return (x = +x) < 1 ? NaN : x > 94906265.62425156\n      ? Math.log(x) + Math.LN2\n      : log1p(x - 1 + sqrt(x - 1) * sqrt(x + 1));\n  }\n});\n","// 20.2.2.5 Math.asinh(x)\nvar $export = require('./_export');\nvar $asinh = Math.asinh;\n\nfunction asinh(x) {\n  return !isFinite(x = +x) || x == 0 ? x : x < 0 ? -asinh(-x) : Math.log(x + Math.sqrt(x * x + 1));\n}\n\n// Tor Browser bug: Math.asinh(0) -> -0\n$export($export.S + $export.F * !($asinh && 1 / $asinh(0) > 0), 'Math', { asinh: asinh });\n","// 20.2.2.7 Math.atanh(x)\nvar $export = require('./_export');\nvar $atanh = Math.atanh;\n\n// Tor Browser bug: Math.atanh(-0) -> 0\n$export($export.S + $export.F * !($atanh && 1 / $atanh(-0) < 0), 'Math', {\n  atanh: function atanh(x) {\n    return (x = +x) == 0 ? x : Math.log((1 + x) / (1 - x)) / 2;\n  }\n});\n","// 20.2.2.9 Math.cbrt(x)\nvar $export = require('./_export');\nvar sign = require('./_math-sign');\n\n$export($export.S, 'Math', {\n  cbrt: function cbrt(x) {\n    return sign(x = +x) * Math.pow(Math.abs(x), 1 / 3);\n  }\n});\n","// 20.2.2.11 Math.clz32(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  clz32: function clz32(x) {\n    return (x >>>= 0) ? 31 - Math.floor(Math.log(x + 0.5) * Math.LOG2E) : 32;\n  }\n});\n","// 20.2.2.12 Math.cosh(x)\nvar $export = require('./_export');\nvar exp = Math.exp;\n\n$export($export.S, 'Math', {\n  cosh: function cosh(x) {\n    return (exp(x = +x) + exp(-x)) / 2;\n  }\n});\n","// 20.2.2.14 Math.expm1(x)\nvar $export = require('./_export');\nvar $expm1 = require('./_math-expm1');\n\n$export($export.S + $export.F * ($expm1 != Math.expm1), 'Math', { expm1: $expm1 });\n","// 20.2.2.16 Math.fround(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { fround: require('./_math-fround') });\n","// 20.2.2.17 Math.hypot([value1[, value2[, … ]]])\nvar $export = require('./_export');\nvar abs = Math.abs;\n\n$export($export.S, 'Math', {\n  hypot: function hypot(value1, value2) { // eslint-disable-line no-unused-vars\n    var sum = 0;\n    var i = 0;\n    var aLen = arguments.length;\n    var larg = 0;\n    var arg, div;\n    while (i < aLen) {\n      arg = abs(arguments[i++]);\n      if (larg < arg) {\n        div = larg / arg;\n        sum = sum * div * div + 1;\n        larg = arg;\n      } else if (arg > 0) {\n        div = arg / larg;\n        sum += div * div;\n      } else sum += arg;\n    }\n    return larg === Infinity ? Infinity : larg * Math.sqrt(sum);\n  }\n});\n","// 20.2.2.18 Math.imul(x, y)\nvar $export = require('./_export');\nvar $imul = Math.imul;\n\n// some WebKit versions fails with big numbers, some has wrong arity\n$export($export.S + $export.F * require('./_fails')(function () {\n  return $imul(0xffffffff, 5) != -5 || $imul.length != 2;\n}), 'Math', {\n  imul: function imul(x, y) {\n    var UINT16 = 0xffff;\n    var xn = +x;\n    var yn = +y;\n    var xl = UINT16 & xn;\n    var yl = UINT16 & yn;\n    return 0 | xl * yl + ((UINT16 & xn >>> 16) * yl + xl * (UINT16 & yn >>> 16) << 16 >>> 0);\n  }\n});\n","// 20.2.2.21 Math.log10(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  log10: function log10(x) {\n    return Math.log(x) * Math.LOG10E;\n  }\n});\n","// 20.2.2.20 Math.log1p(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { log1p: require('./_math-log1p') });\n","// 20.2.2.22 Math.log2(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  log2: function log2(x) {\n    return Math.log(x) / Math.LN2;\n  }\n});\n","// 20.2.2.28 Math.sign(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { sign: require('./_math-sign') });\n","// 20.2.2.30 Math.sinh(x)\nvar $export = require('./_export');\nvar expm1 = require('./_math-expm1');\nvar exp = Math.exp;\n\n// V8 near Chromium 38 has a problem with very small numbers\n$export($export.S + $export.F * require('./_fails')(function () {\n  return !Math.sinh(-2e-17) != -2e-17;\n}), 'Math', {\n  sinh: function sinh(x) {\n    return Math.abs(x = +x) < 1\n      ? (expm1(x) - expm1(-x)) / 2\n      : (exp(x - 1) - exp(-x - 1)) * (Math.E / 2);\n  }\n});\n","// 20.2.2.33 Math.tanh(x)\nvar $export = require('./_export');\nvar expm1 = require('./_math-expm1');\nvar exp = Math.exp;\n\n$export($export.S, 'Math', {\n  tanh: function tanh(x) {\n    var a = expm1(x = +x);\n    var b = expm1(-x);\n    return a == Infinity ? 1 : b == Infinity ? -1 : (a - b) / (exp(x) + exp(-x));\n  }\n});\n","// 20.2.2.34 Math.trunc(x)\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  trunc: function trunc(it) {\n    return (it > 0 ? Math.floor : Math.ceil)(it);\n  }\n});\n","'use strict';\nvar global = require('./_global');\nvar has = require('./_has');\nvar cof = require('./_cof');\nvar inheritIfRequired = require('./_inherit-if-required');\nvar toPrimitive = require('./_to-primitive');\nvar fails = require('./_fails');\nvar gOPN = require('./_object-gopn').f;\nvar gOPD = require('./_object-gopd').f;\nvar dP = require('./_object-dp').f;\nvar $trim = require('./_string-trim').trim;\nvar NUMBER = 'Number';\nvar $Number = global[NUMBER];\nvar Base = $Number;\nvar proto = $Number.prototype;\n// Opera ~12 has broken Object#toString\nvar BROKEN_COF = cof(require('./_object-create')(proto)) == NUMBER;\nvar TRIM = 'trim' in String.prototype;\n\n// 7.1.3 ToNumber(argument)\nvar toNumber = function (argument) {\n  var it = toPrimitive(argument, false);\n  if (typeof it == 'string' && it.length > 2) {\n    it = TRIM ? it.trim() : $trim(it, 3);\n    var first = it.charCodeAt(0);\n    var third, radix, maxCode;\n    if (first === 43 || first === 45) {\n      third = it.charCodeAt(2);\n      if (third === 88 || third === 120) return NaN; // Number('+0x1') should be NaN, old V8 fix\n    } else if (first === 48) {\n      switch (it.charCodeAt(1)) {\n        case 66: case 98: radix = 2; maxCode = 49; break; // fast equal /^0b[01]+$/i\n        case 79: case 111: radix = 8; maxCode = 55; break; // fast equal /^0o[0-7]+$/i\n        default: return +it;\n      }\n      for (var digits = it.slice(2), i = 0, l = digits.length, code; i < l; i++) {\n        code = digits.charCodeAt(i);\n        // parseInt parses a string to a first unavailable symbol\n        // but ToNumber should return NaN if a string contains unavailable symbols\n        if (code < 48 || code > maxCode) return NaN;\n      } return parseInt(digits, radix);\n    }\n  } return +it;\n};\n\nif (!$Number(' 0o1') || !$Number('0b1') || $Number('+0x1')) {\n  $Number = function Number(value) {\n    var it = arguments.length < 1 ? 0 : value;\n    var that = this;\n    return that instanceof $Number\n      // check on 1..constructor(foo) case\n      && (BROKEN_COF ? fails(function () { proto.valueOf.call(that); }) : cof(that) != NUMBER)\n        ? inheritIfRequired(new Base(toNumber(it)), that, $Number) : toNumber(it);\n  };\n  for (var keys = require('./_descriptors') ? gOPN(Base) : (\n    // ES3:\n    'MAX_VALUE,MIN_VALUE,NaN,NEGATIVE_INFINITY,POSITIVE_INFINITY,' +\n    // ES6 (in case, if modules with ES6 Number statics required before):\n    'EPSILON,isFinite,isInteger,isNaN,isSafeInteger,MAX_SAFE_INTEGER,' +\n    'MIN_SAFE_INTEGER,parseFloat,parseInt,isInteger'\n  ).split(','), j = 0, key; keys.length > j; j++) {\n    if (has(Base, key = keys[j]) && !has($Number, key)) {\n      dP($Number, key, gOPD(Base, key));\n    }\n  }\n  $Number.prototype = proto;\n  proto.constructor = $Number;\n  require('./_redefine')(global, NUMBER, $Number);\n}\n","// 20.1.2.1 Number.EPSILON\nvar $export = require('./_export');\n\n$export($export.S, 'Number', { EPSILON: Math.pow(2, -52) });\n","// 20.1.2.2 Number.isFinite(number)\nvar $export = require('./_export');\nvar _isFinite = require('./_global').isFinite;\n\n$export($export.S, 'Number', {\n  isFinite: function isFinite(it) {\n    return typeof it == 'number' && _isFinite(it);\n  }\n});\n","// 20.1.2.3 Number.isInteger(number)\nvar $export = require('./_export');\n\n$export($export.S, 'Number', { isInteger: require('./_is-integer') });\n","// 20.1.2.4 Number.isNaN(number)\nvar $export = require('./_export');\n\n$export($export.S, 'Number', {\n  isNaN: function isNaN(number) {\n    // eslint-disable-next-line no-self-compare\n    return number != number;\n  }\n});\n","// 20.1.2.5 Number.isSafeInteger(number)\nvar $export = require('./_export');\nvar isInteger = require('./_is-integer');\nvar abs = Math.abs;\n\n$export($export.S, 'Number', {\n  isSafeInteger: function isSafeInteger(number) {\n    return isInteger(number) && abs(number) <= 0x1fffffffffffff;\n  }\n});\n","// 20.1.2.6 Number.MAX_SAFE_INTEGER\nvar $export = require('./_export');\n\n$export($export.S, 'Number', { MAX_SAFE_INTEGER: 0x1fffffffffffff });\n","// 20.1.2.10 Number.MIN_SAFE_INTEGER\nvar $export = require('./_export');\n\n$export($export.S, 'Number', { MIN_SAFE_INTEGER: -0x1fffffffffffff });\n","var $export = require('./_export');\nvar $parseFloat = require('./_parse-float');\n// 20.1.2.12 Number.parseFloat(string)\n$export($export.S + $export.F * (Number.parseFloat != $parseFloat), 'Number', { parseFloat: $parseFloat });\n","var $export = require('./_export');\nvar $parseInt = require('./_parse-int');\n// 20.1.2.13 Number.parseInt(string, radix)\n$export($export.S + $export.F * (Number.parseInt != $parseInt), 'Number', { parseInt: $parseInt });\n","'use strict';\nvar $export = require('./_export');\nvar toInteger = require('./_to-integer');\nvar aNumberValue = require('./_a-number-value');\nvar repeat = require('./_string-repeat');\nvar $toFixed = 1.0.toFixed;\nvar floor = Math.floor;\nvar data = [0, 0, 0, 0, 0, 0];\nvar ERROR = 'Number.toFixed: incorrect invocation!';\nvar ZERO = '0';\n\nvar multiply = function (n, c) {\n  var i = -1;\n  var c2 = c;\n  while (++i < 6) {\n    c2 += n * data[i];\n    data[i] = c2 % 1e7;\n    c2 = floor(c2 / 1e7);\n  }\n};\nvar divide = function (n) {\n  var i = 6;\n  var c = 0;\n  while (--i >= 0) {\n    c += data[i];\n    data[i] = floor(c / n);\n    c = (c % n) * 1e7;\n  }\n};\nvar numToString = function () {\n  var i = 6;\n  var s = '';\n  while (--i >= 0) {\n    if (s !== '' || i === 0 || data[i] !== 0) {\n      var t = String(data[i]);\n      s = s === '' ? t : s + repeat.call(ZERO, 7 - t.length) + t;\n    }\n  } return s;\n};\nvar pow = function (x, n, acc) {\n  return n === 0 ? acc : n % 2 === 1 ? pow(x, n - 1, acc * x) : pow(x * x, n / 2, acc);\n};\nvar log = function (x) {\n  var n = 0;\n  var x2 = x;\n  while (x2 >= 4096) {\n    n += 12;\n    x2 /= 4096;\n  }\n  while (x2 >= 2) {\n    n += 1;\n    x2 /= 2;\n  } return n;\n};\n\n$export($export.P + $export.F * (!!$toFixed && (\n  0.00008.toFixed(3) !== '0.000' ||\n  0.9.toFixed(0) !== '1' ||\n  1.255.toFixed(2) !== '1.25' ||\n  1000000000000000128.0.toFixed(0) !== '1000000000000000128'\n) || !require('./_fails')(function () {\n  // V8 ~ Android 4.3-\n  $toFixed.call({});\n})), 'Number', {\n  toFixed: function toFixed(fractionDigits) {\n    var x = aNumberValue(this, ERROR);\n    var f = toInteger(fractionDigits);\n    var s = '';\n    var m = ZERO;\n    var e, z, j, k;\n    if (f < 0 || f > 20) throw RangeError(ERROR);\n    // eslint-disable-next-line no-self-compare\n    if (x != x) return 'NaN';\n    if (x <= -1e21 || x >= 1e21) return String(x);\n    if (x < 0) {\n      s = '-';\n      x = -x;\n    }\n    if (x > 1e-21) {\n      e = log(x * pow(2, 69, 1)) - 69;\n      z = e < 0 ? x * pow(2, -e, 1) : x / pow(2, e, 1);\n      z *= 0x10000000000000;\n      e = 52 - e;\n      if (e > 0) {\n        multiply(0, z);\n        j = f;\n        while (j >= 7) {\n          multiply(1e7, 0);\n          j -= 7;\n        }\n        multiply(pow(10, j, 1), 0);\n        j = e - 1;\n        while (j >= 23) {\n          divide(1 << 23);\n          j -= 23;\n        }\n        divide(1 << j);\n        multiply(1, 1);\n        divide(2);\n        m = numToString();\n      } else {\n        multiply(0, z);\n        multiply(1 << -e, 0);\n        m = numToString() + repeat.call(ZERO, f);\n      }\n    }\n    if (f > 0) {\n      k = m.length;\n      m = s + (k <= f ? '0.' + repeat.call(ZERO, f - k) + m : m.slice(0, k - f) + '.' + m.slice(k - f));\n    } else {\n      m = s + m;\n    } return m;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar $fails = require('./_fails');\nvar aNumberValue = require('./_a-number-value');\nvar $toPrecision = 1.0.toPrecision;\n\n$export($export.P + $export.F * ($fails(function () {\n  // IE7-\n  return $toPrecision.call(1, undefined) !== '1';\n}) || !$fails(function () {\n  // V8 ~ Android 4.3-\n  $toPrecision.call({});\n})), 'Number', {\n  toPrecision: function toPrecision(precision) {\n    var that = aNumberValue(this, 'Number#toPrecision: incorrect invocation!');\n    return precision === undefined ? $toPrecision.call(that) : $toPrecision.call(that, precision);\n  }\n});\n","// 19.1.3.1 Object.assign(target, source)\nvar $export = require('./_export');\n\n$export($export.S + $export.F, 'Object', { assign: require('./_object-assign') });\n","var $export = require('./_export');\n// 19.1.2.2 / 15.2.3.5 Object.create(O [, Properties])\n$export($export.S, 'Object', { create: require('./_object-create') });\n","var $export = require('./_export');\n// 19.1.2.3 / 15.2.3.7 Object.defineProperties(O, Properties)\n$export($export.S + $export.F * !require('./_descriptors'), 'Object', { defineProperties: require('./_object-dps') });\n","var $export = require('./_export');\n// 19.1.2.4 / 15.2.3.6 Object.defineProperty(O, P, Attributes)\n$export($export.S + $export.F * !require('./_descriptors'), 'Object', { defineProperty: require('./_object-dp').f });\n","// 19.1.2.5 Object.freeze(O)\nvar isObject = require('./_is-object');\nvar meta = require('./_meta').onFreeze;\n\nrequire('./_object-sap')('freeze', function ($freeze) {\n  return function freeze(it) {\n    return $freeze && isObject(it) ? $freeze(meta(it)) : it;\n  };\n});\n","// 19.1.2.6 Object.getOwnPropertyDescriptor(O, P)\nvar toIObject = require('./_to-iobject');\nvar $getOwnPropertyDescriptor = require('./_object-gopd').f;\n\nrequire('./_object-sap')('getOwnPropertyDescriptor', function () {\n  return function getOwnPropertyDescriptor(it, key) {\n    return $getOwnPropertyDescriptor(toIObject(it), key);\n  };\n});\n","// 19.1.2.7 Object.getOwnPropertyNames(O)\nrequire('./_object-sap')('getOwnPropertyNames', function () {\n  return require('./_object-gopn-ext').f;\n});\n","// 19.1.2.9 Object.getPrototypeOf(O)\nvar toObject = require('./_to-object');\nvar $getPrototypeOf = require('./_object-gpo');\n\nrequire('./_object-sap')('getPrototypeOf', function () {\n  return function getPrototypeOf(it) {\n    return $getPrototypeOf(toObject(it));\n  };\n});\n","// 19.1.2.11 Object.isExtensible(O)\nvar isObject = require('./_is-object');\n\nrequire('./_object-sap')('isExtensible', function ($isExtensible) {\n  return function isExtensible(it) {\n    return isObject(it) ? $isExtensible ? $isExtensible(it) : true : false;\n  };\n});\n","// 19.1.2.12 Object.isFrozen(O)\nvar isObject = require('./_is-object');\n\nrequire('./_object-sap')('isFrozen', function ($isFrozen) {\n  return function isFrozen(it) {\n    return isObject(it) ? $isFrozen ? $isFrozen(it) : false : true;\n  };\n});\n","// 19.1.2.13 Object.isSealed(O)\nvar isObject = require('./_is-object');\n\nrequire('./_object-sap')('isSealed', function ($isSealed) {\n  return function isSealed(it) {\n    return isObject(it) ? $isSealed ? $isSealed(it) : false : true;\n  };\n});\n","// 19.1.3.10 Object.is(value1, value2)\nvar $export = require('./_export');\n$export($export.S, 'Object', { is: require('./_same-value') });\n","// 19.1.2.14 Object.keys(O)\nvar toObject = require('./_to-object');\nvar $keys = require('./_object-keys');\n\nrequire('./_object-sap')('keys', function () {\n  return function keys(it) {\n    return $keys(toObject(it));\n  };\n});\n","// 19.1.2.15 Object.preventExtensions(O)\nvar isObject = require('./_is-object');\nvar meta = require('./_meta').onFreeze;\n\nrequire('./_object-sap')('preventExtensions', function ($preventExtensions) {\n  return function preventExtensions(it) {\n    return $preventExtensions && isObject(it) ? $preventExtensions(meta(it)) : it;\n  };\n});\n","// 19.1.2.17 Object.seal(O)\nvar isObject = require('./_is-object');\nvar meta = require('./_meta').onFreeze;\n\nrequire('./_object-sap')('seal', function ($seal) {\n  return function seal(it) {\n    return $seal && isObject(it) ? $seal(meta(it)) : it;\n  };\n});\n","// 19.1.3.19 Object.setPrototypeOf(O, proto)\nvar $export = require('./_export');\n$export($export.S, 'Object', { setPrototypeOf: require('./_set-proto').set });\n","'use strict';\n// 19.1.3.6 Object.prototype.toString()\nvar classof = require('./_classof');\nvar test = {};\ntest[require('./_wks')('toStringTag')] = 'z';\nif (test + '' != '[object z]') {\n  require('./_redefine')(Object.prototype, 'toString', function toString() {\n    return '[object ' + classof(this) + ']';\n  }, true);\n}\n","var $export = require('./_export');\nvar $parseFloat = require('./_parse-float');\n// 18.2.4 parseFloat(string)\n$export($export.G + $export.F * (parseFloat != $parseFloat), { parseFloat: $parseFloat });\n","var $export = require('./_export');\nvar $parseInt = require('./_parse-int');\n// 18.2.5 parseInt(string, radix)\n$export($export.G + $export.F * (parseInt != $parseInt), { parseInt: $parseInt });\n","'use strict';\nvar LIBRARY = require('./_library');\nvar global = require('./_global');\nvar ctx = require('./_ctx');\nvar classof = require('./_classof');\nvar $export = require('./_export');\nvar isObject = require('./_is-object');\nvar aFunction = require('./_a-function');\nvar anInstance = require('./_an-instance');\nvar forOf = require('./_for-of');\nvar speciesConstructor = require('./_species-constructor');\nvar task = require('./_task').set;\nvar microtask = require('./_microtask')();\nvar newPromiseCapabilityModule = require('./_new-promise-capability');\nvar perform = require('./_perform');\nvar userAgent = require('./_user-agent');\nvar promiseResolve = require('./_promise-resolve');\nvar PROMISE = 'Promise';\nvar TypeError = global.TypeError;\nvar process = global.process;\nvar versions = process && process.versions;\nvar v8 = versions && versions.v8 || '';\nvar $Promise = global[PROMISE];\nvar isNode = classof(process) == 'process';\nvar empty = function () { /* empty */ };\nvar Internal, newGenericPromiseCapability, OwnPromiseCapability, Wrapper;\nvar newPromiseCapability = newGenericPromiseCapability = newPromiseCapabilityModule.f;\n\nvar USE_NATIVE = !!function () {\n  try {\n    // correct subclassing with @@species support\n    var promise = $Promise.resolve(1);\n    var FakePromise = (promise.constructor = {})[require('./_wks')('species')] = function (exec) {\n      exec(empty, empty);\n    };\n    // unhandled rejections tracking support, NodeJS Promise without it fails @@species test\n    return (isNode || typeof PromiseRejectionEvent == 'function')\n      && promise.then(empty) instanceof FakePromise\n      // v8 6.6 (Node 10 and Chrome 66) have a bug with resolving custom thenables\n      // https://bugs.chromium.org/p/chromium/issues/detail?id=830565\n      // we can't detect it synchronously, so just check versions\n      && v8.indexOf('6.6') !== 0\n      && userAgent.indexOf('Chrome/66') === -1;\n  } catch (e) { /* empty */ }\n}();\n\n// helpers\nvar isThenable = function (it) {\n  var then;\n  return isObject(it) && typeof (then = it.then) == 'function' ? then : false;\n};\nvar notify = function (promise, isReject) {\n  if (promise._n) return;\n  promise._n = true;\n  var chain = promise._c;\n  microtask(function () {\n    var value = promise._v;\n    var ok = promise._s == 1;\n    var i = 0;\n    var run = function (reaction) {\n      var handler = ok ? reaction.ok : reaction.fail;\n      var resolve = reaction.resolve;\n      var reject = reaction.reject;\n      var domain = reaction.domain;\n      var result, then, exited;\n      try {\n        if (handler) {\n          if (!ok) {\n            if (promise._h == 2) onHandleUnhandled(promise);\n            promise._h = 1;\n          }\n          if (handler === true) result = value;\n          else {\n            if (domain) domain.enter();\n            result = handler(value); // may throw\n            if (domain) {\n              domain.exit();\n              exited = true;\n            }\n          }\n          if (result === reaction.promise) {\n            reject(TypeError('Promise-chain cycle'));\n          } else if (then = isThenable(result)) {\n            then.call(result, resolve, reject);\n          } else resolve(result);\n        } else reject(value);\n      } catch (e) {\n        if (domain && !exited) domain.exit();\n        reject(e);\n      }\n    };\n    while (chain.length > i) run(chain[i++]); // variable length - can't use forEach\n    promise._c = [];\n    promise._n = false;\n    if (isReject && !promise._h) onUnhandled(promise);\n  });\n};\nvar onUnhandled = function (promise) {\n  task.call(global, function () {\n    var value = promise._v;\n    var unhandled = isUnhandled(promise);\n    var result, handler, console;\n    if (unhandled) {\n      result = perform(function () {\n        if (isNode) {\n          process.emit('unhandledRejection', value, promise);\n        } else if (handler = global.onunhandledrejection) {\n          handler({ promise: promise, reason: value });\n        } else if ((console = global.console) && console.error) {\n          console.error('Unhandled promise rejection', value);\n        }\n      });\n      // Browsers should not trigger `rejectionHandled` event if it was handled here, NodeJS - should\n      promise._h = isNode || isUnhandled(promise) ? 2 : 1;\n    } promise._a = undefined;\n    if (unhandled && result.e) throw result.v;\n  });\n};\nvar isUnhandled = function (promise) {\n  return promise._h !== 1 && (promise._a || promise._c).length === 0;\n};\nvar onHandleUnhandled = function (promise) {\n  task.call(global, function () {\n    var handler;\n    if (isNode) {\n      process.emit('rejectionHandled', promise);\n    } else if (handler = global.onrejectionhandled) {\n      handler({ promise: promise, reason: promise._v });\n    }\n  });\n};\nvar $reject = function (value) {\n  var promise = this;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  promise._v = value;\n  promise._s = 2;\n  if (!promise._a) promise._a = promise._c.slice();\n  notify(promise, true);\n};\nvar $resolve = function (value) {\n  var promise = this;\n  var then;\n  if (promise._d) return;\n  promise._d = true;\n  promise = promise._w || promise; // unwrap\n  try {\n    if (promise === value) throw TypeError(\"Promise can't be resolved itself\");\n    if (then = isThenable(value)) {\n      microtask(function () {\n        var wrapper = { _w: promise, _d: false }; // wrap\n        try {\n          then.call(value, ctx($resolve, wrapper, 1), ctx($reject, wrapper, 1));\n        } catch (e) {\n          $reject.call(wrapper, e);\n        }\n      });\n    } else {\n      promise._v = value;\n      promise._s = 1;\n      notify(promise, false);\n    }\n  } catch (e) {\n    $reject.call({ _w: promise, _d: false }, e); // wrap\n  }\n};\n\n// constructor polyfill\nif (!USE_NATIVE) {\n  // 25.4.3.1 Promise(executor)\n  $Promise = function Promise(executor) {\n    anInstance(this, $Promise, PROMISE, '_h');\n    aFunction(executor);\n    Internal.call(this);\n    try {\n      executor(ctx($resolve, this, 1), ctx($reject, this, 1));\n    } catch (err) {\n      $reject.call(this, err);\n    }\n  };\n  // eslint-disable-next-line no-unused-vars\n  Internal = function Promise(executor) {\n    this._c = [];             // <- awaiting reactions\n    this._a = undefined;      // <- checked in isUnhandled reactions\n    this._s = 0;              // <- state\n    this._d = false;          // <- done\n    this._v = undefined;      // <- value\n    this._h = 0;              // <- rejection state, 0 - default, 1 - handled, 2 - unhandled\n    this._n = false;          // <- notify\n  };\n  Internal.prototype = require('./_redefine-all')($Promise.prototype, {\n    // 25.4.5.3 Promise.prototype.then(onFulfilled, onRejected)\n    then: function then(onFulfilled, onRejected) {\n      var reaction = newPromiseCapability(speciesConstructor(this, $Promise));\n      reaction.ok = typeof onFulfilled == 'function' ? onFulfilled : true;\n      reaction.fail = typeof onRejected == 'function' && onRejected;\n      reaction.domain = isNode ? process.domain : undefined;\n      this._c.push(reaction);\n      if (this._a) this._a.push(reaction);\n      if (this._s) notify(this, false);\n      return reaction.promise;\n    },\n    // 25.4.5.1 Promise.prototype.catch(onRejected)\n    'catch': function (onRejected) {\n      return this.then(undefined, onRejected);\n    }\n  });\n  OwnPromiseCapability = function () {\n    var promise = new Internal();\n    this.promise = promise;\n    this.resolve = ctx($resolve, promise, 1);\n    this.reject = ctx($reject, promise, 1);\n  };\n  newPromiseCapabilityModule.f = newPromiseCapability = function (C) {\n    return C === $Promise || C === Wrapper\n      ? new OwnPromiseCapability(C)\n      : newGenericPromiseCapability(C);\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Promise: $Promise });\nrequire('./_set-to-string-tag')($Promise, PROMISE);\nrequire('./_set-species')(PROMISE);\nWrapper = require('./_core')[PROMISE];\n\n// statics\n$export($export.S + $export.F * !USE_NATIVE, PROMISE, {\n  // 25.4.4.5 Promise.reject(r)\n  reject: function reject(r) {\n    var capability = newPromiseCapability(this);\n    var $$reject = capability.reject;\n    $$reject(r);\n    return capability.promise;\n  }\n});\n$export($export.S + $export.F * (LIBRARY || !USE_NATIVE), PROMISE, {\n  // 25.4.4.6 Promise.resolve(x)\n  resolve: function resolve(x) {\n    return promiseResolve(LIBRARY && this === Wrapper ? $Promise : this, x);\n  }\n});\n$export($export.S + $export.F * !(USE_NATIVE && require('./_iter-detect')(function (iter) {\n  $Promise.all(iter)['catch'](empty);\n})), PROMISE, {\n  // 25.4.4.1 Promise.all(iterable)\n  all: function all(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var resolve = capability.resolve;\n    var reject = capability.reject;\n    var result = perform(function () {\n      var values = [];\n      var index = 0;\n      var remaining = 1;\n      forOf(iterable, false, function (promise) {\n        var $index = index++;\n        var alreadyCalled = false;\n        values.push(undefined);\n        remaining++;\n        C.resolve(promise).then(function (value) {\n          if (alreadyCalled) return;\n          alreadyCalled = true;\n          values[$index] = value;\n          --remaining || resolve(values);\n        }, reject);\n      });\n      --remaining || resolve(values);\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  },\n  // 25.4.4.4 Promise.race(iterable)\n  race: function race(iterable) {\n    var C = this;\n    var capability = newPromiseCapability(C);\n    var reject = capability.reject;\n    var result = perform(function () {\n      forOf(iterable, false, function (promise) {\n        C.resolve(promise).then(capability.resolve, reject);\n      });\n    });\n    if (result.e) reject(result.v);\n    return capability.promise;\n  }\n});\n","// 26.1.1 Reflect.apply(target, thisArgument, argumentsList)\nvar $export = require('./_export');\nvar aFunction = require('./_a-function');\nvar anObject = require('./_an-object');\nvar rApply = (require('./_global').Reflect || {}).apply;\nvar fApply = Function.apply;\n// MS Edge argumentsList argument is optional\n$export($export.S + $export.F * !require('./_fails')(function () {\n  rApply(function () { /* empty */ });\n}), 'Reflect', {\n  apply: function apply(target, thisArgument, argumentsList) {\n    var T = aFunction(target);\n    var L = anObject(argumentsList);\n    return rApply ? rApply(T, thisArgument, L) : fApply.call(T, thisArgument, L);\n  }\n});\n","// 26.1.2 Reflect.construct(target, argumentsList [, newTarget])\nvar $export = require('./_export');\nvar create = require('./_object-create');\nvar aFunction = require('./_a-function');\nvar anObject = require('./_an-object');\nvar isObject = require('./_is-object');\nvar fails = require('./_fails');\nvar bind = require('./_bind');\nvar rConstruct = (require('./_global').Reflect || {}).construct;\n\n// MS Edge supports only 2 arguments and argumentsList argument is optional\n// FF Nightly sets third argument as `new.target`, but does not create `this` from it\nvar NEW_TARGET_BUG = fails(function () {\n  function F() { /* empty */ }\n  return !(rConstruct(function () { /* empty */ }, [], F) instanceof F);\n});\nvar ARGS_BUG = !fails(function () {\n  rConstruct(function () { /* empty */ });\n});\n\n$export($export.S + $export.F * (NEW_TARGET_BUG || ARGS_BUG), 'Reflect', {\n  construct: function construct(Target, args /* , newTarget */) {\n    aFunction(Target);\n    anObject(args);\n    var newTarget = arguments.length < 3 ? Target : aFunction(arguments[2]);\n    if (ARGS_BUG && !NEW_TARGET_BUG) return rConstruct(Target, args, newTarget);\n    if (Target == newTarget) {\n      // w/o altered newTarget, optimization for 0-4 arguments\n      switch (args.length) {\n        case 0: return new Target();\n        case 1: return new Target(args[0]);\n        case 2: return new Target(args[0], args[1]);\n        case 3: return new Target(args[0], args[1], args[2]);\n        case 4: return new Target(args[0], args[1], args[2], args[3]);\n      }\n      // w/o altered newTarget, lot of arguments case\n      var $args = [null];\n      $args.push.apply($args, args);\n      return new (bind.apply(Target, $args))();\n    }\n    // with altered newTarget, not support built-in constructors\n    var proto = newTarget.prototype;\n    var instance = create(isObject(proto) ? proto : Object.prototype);\n    var result = Function.apply.call(Target, instance, args);\n    return isObject(result) ? result : instance;\n  }\n});\n","// 26.1.3 Reflect.defineProperty(target, propertyKey, attributes)\nvar dP = require('./_object-dp');\nvar $export = require('./_export');\nvar anObject = require('./_an-object');\nvar toPrimitive = require('./_to-primitive');\n\n// MS Edge has broken Reflect.defineProperty - throwing instead of returning false\n$export($export.S + $export.F * require('./_fails')(function () {\n  // eslint-disable-next-line no-undef\n  Reflect.defineProperty(dP.f({}, 1, { value: 1 }), 1, { value: 2 });\n}), 'Reflect', {\n  defineProperty: function defineProperty(target, propertyKey, attributes) {\n    anObject(target);\n    propertyKey = toPrimitive(propertyKey, true);\n    anObject(attributes);\n    try {\n      dP.f(target, propertyKey, attributes);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n","// 26.1.4 Reflect.deleteProperty(target, propertyKey)\nvar $export = require('./_export');\nvar gOPD = require('./_object-gopd').f;\nvar anObject = require('./_an-object');\n\n$export($export.S, 'Reflect', {\n  deleteProperty: function deleteProperty(target, propertyKey) {\n    var desc = gOPD(anObject(target), propertyKey);\n    return desc && !desc.configurable ? false : delete target[propertyKey];\n  }\n});\n","'use strict';\n// 26.1.5 Reflect.enumerate(target)\nvar $export = require('./_export');\nvar anObject = require('./_an-object');\nvar Enumerate = function (iterated) {\n  this._t = anObject(iterated); // target\n  this._i = 0;                  // next index\n  var keys = this._k = [];      // keys\n  var key;\n  for (key in iterated) keys.push(key);\n};\nrequire('./_iter-create')(Enumerate, 'Object', function () {\n  var that = this;\n  var keys = that._k;\n  var key;\n  do {\n    if (that._i >= keys.length) return { value: undefined, done: true };\n  } while (!((key = keys[that._i++]) in that._t));\n  return { value: key, done: false };\n});\n\n$export($export.S, 'Reflect', {\n  enumerate: function enumerate(target) {\n    return new Enumerate(target);\n  }\n});\n","// 26.1.7 Reflect.getOwnPropertyDescriptor(target, propertyKey)\nvar gOPD = require('./_object-gopd');\nvar $export = require('./_export');\nvar anObject = require('./_an-object');\n\n$export($export.S, 'Reflect', {\n  getOwnPropertyDescriptor: function getOwnPropertyDescriptor(target, propertyKey) {\n    return gOPD.f(anObject(target), propertyKey);\n  }\n});\n","// 26.1.8 Reflect.getPrototypeOf(target)\nvar $export = require('./_export');\nvar getProto = require('./_object-gpo');\nvar anObject = require('./_an-object');\n\n$export($export.S, 'Reflect', {\n  getPrototypeOf: function getPrototypeOf(target) {\n    return getProto(anObject(target));\n  }\n});\n","// 26.1.6 Reflect.get(target, propertyKey [, receiver])\nvar gOPD = require('./_object-gopd');\nvar getPrototypeOf = require('./_object-gpo');\nvar has = require('./_has');\nvar $export = require('./_export');\nvar isObject = require('./_is-object');\nvar anObject = require('./_an-object');\n\nfunction get(target, propertyKey /* , receiver */) {\n  var receiver = arguments.length < 3 ? target : arguments[2];\n  var desc, proto;\n  if (anObject(target) === receiver) return target[propertyKey];\n  if (desc = gOPD.f(target, propertyKey)) return has(desc, 'value')\n    ? desc.value\n    : desc.get !== undefined\n      ? desc.get.call(receiver)\n      : undefined;\n  if (isObject(proto = getPrototypeOf(target))) return get(proto, propertyKey, receiver);\n}\n\n$export($export.S, 'Reflect', { get: get });\n","// 26.1.9 Reflect.has(target, propertyKey)\nvar $export = require('./_export');\n\n$export($export.S, 'Reflect', {\n  has: function has(target, propertyKey) {\n    return propertyKey in target;\n  }\n});\n","// 26.1.10 Reflect.isExtensible(target)\nvar $export = require('./_export');\nvar anObject = require('./_an-object');\nvar $isExtensible = Object.isExtensible;\n\n$export($export.S, 'Reflect', {\n  isExtensible: function isExtensible(target) {\n    anObject(target);\n    return $isExtensible ? $isExtensible(target) : true;\n  }\n});\n","// 26.1.11 Reflect.ownKeys(target)\nvar $export = require('./_export');\n\n$export($export.S, 'Reflect', { ownKeys: require('./_own-keys') });\n","// 26.1.12 Reflect.preventExtensions(target)\nvar $export = require('./_export');\nvar anObject = require('./_an-object');\nvar $preventExtensions = Object.preventExtensions;\n\n$export($export.S, 'Reflect', {\n  preventExtensions: function preventExtensions(target) {\n    anObject(target);\n    try {\n      if ($preventExtensions) $preventExtensions(target);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n","// 26.1.14 Reflect.setPrototypeOf(target, proto)\nvar $export = require('./_export');\nvar setProto = require('./_set-proto');\n\nif (setProto) $export($export.S, 'Reflect', {\n  setPrototypeOf: function setPrototypeOf(target, proto) {\n    setProto.check(target, proto);\n    try {\n      setProto.set(target, proto);\n      return true;\n    } catch (e) {\n      return false;\n    }\n  }\n});\n","// 26.1.13 Reflect.set(target, propertyKey, V [, receiver])\nvar dP = require('./_object-dp');\nvar gOPD = require('./_object-gopd');\nvar getPrototypeOf = require('./_object-gpo');\nvar has = require('./_has');\nvar $export = require('./_export');\nvar createDesc = require('./_property-desc');\nvar anObject = require('./_an-object');\nvar isObject = require('./_is-object');\n\nfunction set(target, propertyKey, V /* , receiver */) {\n  var receiver = arguments.length < 4 ? target : arguments[3];\n  var ownDesc = gOPD.f(anObject(target), propertyKey);\n  var existingDescriptor, proto;\n  if (!ownDesc) {\n    if (isObject(proto = getPrototypeOf(target))) {\n      return set(proto, propertyKey, V, receiver);\n    }\n    ownDesc = createDesc(0);\n  }\n  if (has(ownDesc, 'value')) {\n    if (ownDesc.writable === false || !isObject(receiver)) return false;\n    if (existingDescriptor = gOPD.f(receiver, propertyKey)) {\n      if (existingDescriptor.get || existingDescriptor.set || existingDescriptor.writable === false) return false;\n      existingDescriptor.value = V;\n      dP.f(receiver, propertyKey, existingDescriptor);\n    } else dP.f(receiver, propertyKey, createDesc(0, V));\n    return true;\n  }\n  return ownDesc.set === undefined ? false : (ownDesc.set.call(receiver, V), true);\n}\n\n$export($export.S, 'Reflect', { set: set });\n","var global = require('./_global');\nvar inheritIfRequired = require('./_inherit-if-required');\nvar dP = require('./_object-dp').f;\nvar gOPN = require('./_object-gopn').f;\nvar isRegExp = require('./_is-regexp');\nvar $flags = require('./_flags');\nvar $RegExp = global.RegExp;\nvar Base = $RegExp;\nvar proto = $RegExp.prototype;\nvar re1 = /a/g;\nvar re2 = /a/g;\n// \"new\" creates a new object, old webkit buggy here\nvar CORRECT_NEW = new $RegExp(re1) !== re1;\n\nif (require('./_descriptors') && (!CORRECT_NEW || require('./_fails')(function () {\n  re2[require('./_wks')('match')] = false;\n  // RegExp constructor can alter flags and IsRegExp works correct with @@match\n  return $RegExp(re1) != re1 || $RegExp(re2) == re2 || $RegExp(re1, 'i') != '/a/i';\n}))) {\n  $RegExp = function RegExp(p, f) {\n    var tiRE = this instanceof $RegExp;\n    var piRE = isRegExp(p);\n    var fiU = f === undefined;\n    return !tiRE && piRE && p.constructor === $RegExp && fiU ? p\n      : inheritIfRequired(CORRECT_NEW\n        ? new Base(piRE && !fiU ? p.source : p, f)\n        : Base((piRE = p instanceof $RegExp) ? p.source : p, piRE && fiU ? $flags.call(p) : f)\n      , tiRE ? this : proto, $RegExp);\n  };\n  var proxy = function (key) {\n    key in $RegExp || dP($RegExp, key, {\n      configurable: true,\n      get: function () { return Base[key]; },\n      set: function (it) { Base[key] = it; }\n    });\n  };\n  for (var keys = gOPN(Base), i = 0; keys.length > i;) proxy(keys[i++]);\n  proto.constructor = $RegExp;\n  $RegExp.prototype = proto;\n  require('./_redefine')(global, 'RegExp', $RegExp);\n}\n\nrequire('./_set-species')('RegExp');\n","'use strict';\nvar regexpExec = require('./_regexp-exec');\nrequire('./_export')({\n  target: 'RegExp',\n  proto: true,\n  forced: regexpExec !== /./.exec\n}, {\n  exec: regexpExec\n});\n","// 21.2.5.3 get RegExp.prototype.flags()\nif (require('./_descriptors') && /./g.flags != 'g') require('./_object-dp').f(RegExp.prototype, 'flags', {\n  configurable: true,\n  get: require('./_flags')\n});\n","'use strict';\n\nvar anObject = require('./_an-object');\nvar toLength = require('./_to-length');\nvar advanceStringIndex = require('./_advance-string-index');\nvar regExpExec = require('./_regexp-exec-abstract');\n\n// @@match logic\nrequire('./_fix-re-wks')('match', 1, function (defined, MATCH, $match, maybeCallNative) {\n  return [\n    // `String.prototype.match` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.match\n    function match(regexp) {\n      var O = defined(this);\n      var fn = regexp == undefined ? undefined : regexp[MATCH];\n      return fn !== undefined ? fn.call(regexp, O) : new RegExp(regexp)[MATCH](String(O));\n    },\n    // `RegExp.prototype[@@match]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@match\n    function (regexp) {\n      var res = maybeCallNative($match, regexp, this);\n      if (res.done) return res.value;\n      var rx = anObject(regexp);\n      var S = String(this);\n      if (!rx.global) return regExpExec(rx, S);\n      var fullUnicode = rx.unicode;\n      rx.lastIndex = 0;\n      var A = [];\n      var n = 0;\n      var result;\n      while ((result = regExpExec(rx, S)) !== null) {\n        var matchStr = String(result[0]);\n        A[n] = matchStr;\n        if (matchStr === '') rx.lastIndex = advanceStringIndex(S, toLength(rx.lastIndex), fullUnicode);\n        n++;\n      }\n      return n === 0 ? null : A;\n    }\n  ];\n});\n","'use strict';\n\nvar anObject = require('./_an-object');\nvar toObject = require('./_to-object');\nvar toLength = require('./_to-length');\nvar toInteger = require('./_to-integer');\nvar advanceStringIndex = require('./_advance-string-index');\nvar regExpExec = require('./_regexp-exec-abstract');\nvar max = Math.max;\nvar min = Math.min;\nvar floor = Math.floor;\nvar SUBSTITUTION_SYMBOLS = /\\$([$&`']|\\d\\d?|<[^>]*>)/g;\nvar SUBSTITUTION_SYMBOLS_NO_NAMED = /\\$([$&`']|\\d\\d?)/g;\n\nvar maybeToString = function (it) {\n  return it === undefined ? it : String(it);\n};\n\n// @@replace logic\nrequire('./_fix-re-wks')('replace', 2, function (defined, REPLACE, $replace, maybeCallNative) {\n  return [\n    // `String.prototype.replace` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.replace\n    function replace(searchValue, replaceValue) {\n      var O = defined(this);\n      var fn = searchValue == undefined ? undefined : searchValue[REPLACE];\n      return fn !== undefined\n        ? fn.call(searchValue, O, replaceValue)\n        : $replace.call(String(O), searchValue, replaceValue);\n    },\n    // `RegExp.prototype[@@replace]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@replace\n    function (regexp, replaceValue) {\n      var res = maybeCallNative($replace, regexp, this, replaceValue);\n      if (res.done) return res.value;\n\n      var rx = anObject(regexp);\n      var S = String(this);\n      var functionalReplace = typeof replaceValue === 'function';\n      if (!functionalReplace) replaceValue = String(replaceValue);\n      var global = rx.global;\n      if (global) {\n        var fullUnicode = rx.unicode;\n        rx.lastIndex = 0;\n      }\n      var results = [];\n      while (true) {\n        var result = regExpExec(rx, S);\n        if (result === null) break;\n        results.push(result);\n        if (!global) break;\n        var matchStr = String(result[0]);\n        if (matchStr === '') rx.lastIndex = advanceStringIndex(S, toLength(rx.lastIndex), fullUnicode);\n      }\n      var accumulatedResult = '';\n      var nextSourcePosition = 0;\n      for (var i = 0; i < results.length; i++) {\n        result = results[i];\n        var matched = String(result[0]);\n        var position = max(min(toInteger(result.index), S.length), 0);\n        var captures = [];\n        // NOTE: This is equivalent to\n        //   captures = result.slice(1).map(maybeToString)\n        // but for some reason `nativeSlice.call(result, 1, result.length)` (called in\n        // the slice polyfill when slicing native arrays) \"doesn't work\" in safari 9 and\n        // causes a crash (https://pastebin.com/N21QzeQA) when trying to debug it.\n        for (var j = 1; j < result.length; j++) captures.push(maybeToString(result[j]));\n        var namedCaptures = result.groups;\n        if (functionalReplace) {\n          var replacerArgs = [matched].concat(captures, position, S);\n          if (namedCaptures !== undefined) replacerArgs.push(namedCaptures);\n          var replacement = String(replaceValue.apply(undefined, replacerArgs));\n        } else {\n          replacement = getSubstitution(matched, S, position, captures, namedCaptures, replaceValue);\n        }\n        if (position >= nextSourcePosition) {\n          accumulatedResult += S.slice(nextSourcePosition, position) + replacement;\n          nextSourcePosition = position + matched.length;\n        }\n      }\n      return accumulatedResult + S.slice(nextSourcePosition);\n    }\n  ];\n\n    // https://tc39.github.io/ecma262/#sec-getsubstitution\n  function getSubstitution(matched, str, position, captures, namedCaptures, replacement) {\n    var tailPos = position + matched.length;\n    var m = captures.length;\n    var symbols = SUBSTITUTION_SYMBOLS_NO_NAMED;\n    if (namedCaptures !== undefined) {\n      namedCaptures = toObject(namedCaptures);\n      symbols = SUBSTITUTION_SYMBOLS;\n    }\n    return $replace.call(replacement, symbols, function (match, ch) {\n      var capture;\n      switch (ch.charAt(0)) {\n        case '$': return '$';\n        case '&': return matched;\n        case '`': return str.slice(0, position);\n        case \"'\": return str.slice(tailPos);\n        case '<':\n          capture = namedCaptures[ch.slice(1, -1)];\n          break;\n        default: // \\d\\d?\n          var n = +ch;\n          if (n === 0) return match;\n          if (n > m) {\n            var f = floor(n / 10);\n            if (f === 0) return match;\n            if (f <= m) return captures[f - 1] === undefined ? ch.charAt(1) : captures[f - 1] + ch.charAt(1);\n            return match;\n          }\n          capture = captures[n - 1];\n      }\n      return capture === undefined ? '' : capture;\n    });\n  }\n});\n","'use strict';\n\nvar anObject = require('./_an-object');\nvar sameValue = require('./_same-value');\nvar regExpExec = require('./_regexp-exec-abstract');\n\n// @@search logic\nrequire('./_fix-re-wks')('search', 1, function (defined, SEARCH, $search, maybeCallNative) {\n  return [\n    // `String.prototype.search` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.search\n    function search(regexp) {\n      var O = defined(this);\n      var fn = regexp == undefined ? undefined : regexp[SEARCH];\n      return fn !== undefined ? fn.call(regexp, O) : new RegExp(regexp)[SEARCH](String(O));\n    },\n    // `RegExp.prototype[@@search]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@search\n    function (regexp) {\n      var res = maybeCallNative($search, regexp, this);\n      if (res.done) return res.value;\n      var rx = anObject(regexp);\n      var S = String(this);\n      var previousLastIndex = rx.lastIndex;\n      if (!sameValue(previousLastIndex, 0)) rx.lastIndex = 0;\n      var result = regExpExec(rx, S);\n      if (!sameValue(rx.lastIndex, previousLastIndex)) rx.lastIndex = previousLastIndex;\n      return result === null ? -1 : result.index;\n    }\n  ];\n});\n","'use strict';\n\nvar isRegExp = require('./_is-regexp');\nvar anObject = require('./_an-object');\nvar speciesConstructor = require('./_species-constructor');\nvar advanceStringIndex = require('./_advance-string-index');\nvar toLength = require('./_to-length');\nvar callRegExpExec = require('./_regexp-exec-abstract');\nvar regexpExec = require('./_regexp-exec');\nvar fails = require('./_fails');\nvar $min = Math.min;\nvar $push = [].push;\nvar $SPLIT = 'split';\nvar LENGTH = 'length';\nvar LAST_INDEX = 'lastIndex';\nvar MAX_UINT32 = 0xffffffff;\n\n// babel-minify transpiles RegExp('x', 'y') -> /x/y and it causes SyntaxError\nvar SUPPORTS_Y = !fails(function () { RegExp(MAX_UINT32, 'y'); });\n\n// @@split logic\nrequire('./_fix-re-wks')('split', 2, function (defined, SPLIT, $split, maybeCallNative) {\n  var internalSplit;\n  if (\n    'abbc'[$SPLIT](/(b)*/)[1] == 'c' ||\n    'test'[$SPLIT](/(?:)/, -1)[LENGTH] != 4 ||\n    'ab'[$SPLIT](/(?:ab)*/)[LENGTH] != 2 ||\n    '.'[$SPLIT](/(.?)(.?)/)[LENGTH] != 4 ||\n    '.'[$SPLIT](/()()/)[LENGTH] > 1 ||\n    ''[$SPLIT](/.?/)[LENGTH]\n  ) {\n    // based on es5-shim implementation, need to rework it\n    internalSplit = function (separator, limit) {\n      var string = String(this);\n      if (separator === undefined && limit === 0) return [];\n      // If `separator` is not a regex, use native split\n      if (!isRegExp(separator)) return $split.call(string, separator, limit);\n      var output = [];\n      var flags = (separator.ignoreCase ? 'i' : '') +\n                  (separator.multiline ? 'm' : '') +\n                  (separator.unicode ? 'u' : '') +\n                  (separator.sticky ? 'y' : '');\n      var lastLastIndex = 0;\n      var splitLimit = limit === undefined ? MAX_UINT32 : limit >>> 0;\n      // Make `global` and avoid `lastIndex` issues by working with a copy\n      var separatorCopy = new RegExp(separator.source, flags + 'g');\n      var match, lastIndex, lastLength;\n      while (match = regexpExec.call(separatorCopy, string)) {\n        lastIndex = separatorCopy[LAST_INDEX];\n        if (lastIndex > lastLastIndex) {\n          output.push(string.slice(lastLastIndex, match.index));\n          if (match[LENGTH] > 1 && match.index < string[LENGTH]) $push.apply(output, match.slice(1));\n          lastLength = match[0][LENGTH];\n          lastLastIndex = lastIndex;\n          if (output[LENGTH] >= splitLimit) break;\n        }\n        if (separatorCopy[LAST_INDEX] === match.index) separatorCopy[LAST_INDEX]++; // Avoid an infinite loop\n      }\n      if (lastLastIndex === string[LENGTH]) {\n        if (lastLength || !separatorCopy.test('')) output.push('');\n      } else output.push(string.slice(lastLastIndex));\n      return output[LENGTH] > splitLimit ? output.slice(0, splitLimit) : output;\n    };\n  // Chakra, V8\n  } else if ('0'[$SPLIT](undefined, 0)[LENGTH]) {\n    internalSplit = function (separator, limit) {\n      return separator === undefined && limit === 0 ? [] : $split.call(this, separator, limit);\n    };\n  } else {\n    internalSplit = $split;\n  }\n\n  return [\n    // `String.prototype.split` method\n    // https://tc39.github.io/ecma262/#sec-string.prototype.split\n    function split(separator, limit) {\n      var O = defined(this);\n      var splitter = separator == undefined ? undefined : separator[SPLIT];\n      return splitter !== undefined\n        ? splitter.call(separator, O, limit)\n        : internalSplit.call(String(O), separator, limit);\n    },\n    // `RegExp.prototype[@@split]` method\n    // https://tc39.github.io/ecma262/#sec-regexp.prototype-@@split\n    //\n    // NOTE: This cannot be properly polyfilled in engines that don't support\n    // the 'y' flag.\n    function (regexp, limit) {\n      var res = maybeCallNative(internalSplit, regexp, this, limit, internalSplit !== $split);\n      if (res.done) return res.value;\n\n      var rx = anObject(regexp);\n      var S = String(this);\n      var C = speciesConstructor(rx, RegExp);\n\n      var unicodeMatching = rx.unicode;\n      var flags = (rx.ignoreCase ? 'i' : '') +\n                  (rx.multiline ? 'm' : '') +\n                  (rx.unicode ? 'u' : '') +\n                  (SUPPORTS_Y ? 'y' : 'g');\n\n      // ^(? + rx + ) is needed, in combination with some S slicing, to\n      // simulate the 'y' flag.\n      var splitter = new C(SUPPORTS_Y ? rx : '^(?:' + rx.source + ')', flags);\n      var lim = limit === undefined ? MAX_UINT32 : limit >>> 0;\n      if (lim === 0) return [];\n      if (S.length === 0) return callRegExpExec(splitter, S) === null ? [S] : [];\n      var p = 0;\n      var q = 0;\n      var A = [];\n      while (q < S.length) {\n        splitter.lastIndex = SUPPORTS_Y ? q : 0;\n        var z = callRegExpExec(splitter, SUPPORTS_Y ? S : S.slice(q));\n        var e;\n        if (\n          z === null ||\n          (e = $min(toLength(splitter.lastIndex + (SUPPORTS_Y ? 0 : q)), S.length)) === p\n        ) {\n          q = advanceStringIndex(S, q, unicodeMatching);\n        } else {\n          A.push(S.slice(p, q));\n          if (A.length === lim) return A;\n          for (var i = 1; i <= z.length - 1; i++) {\n            A.push(z[i]);\n            if (A.length === lim) return A;\n          }\n          q = p = e;\n        }\n      }\n      A.push(S.slice(p));\n      return A;\n    }\n  ];\n});\n","'use strict';\nrequire('./es6.regexp.flags');\nvar anObject = require('./_an-object');\nvar $flags = require('./_flags');\nvar DESCRIPTORS = require('./_descriptors');\nvar TO_STRING = 'toString';\nvar $toString = /./[TO_STRING];\n\nvar define = function (fn) {\n  require('./_redefine')(RegExp.prototype, TO_STRING, fn, true);\n};\n\n// 21.2.5.14 RegExp.prototype.toString()\nif (require('./_fails')(function () { return $toString.call({ source: 'a', flags: 'b' }) != '/a/b'; })) {\n  define(function toString() {\n    var R = anObject(this);\n    return '/'.concat(R.source, '/',\n      'flags' in R ? R.flags : !DESCRIPTORS && R instanceof RegExp ? $flags.call(R) : undefined);\n  });\n// FF44- RegExp#toString has a wrong name\n} else if ($toString.name != TO_STRING) {\n  define(function toString() {\n    return $toString.call(this);\n  });\n}\n","'use strict';\nvar strong = require('./_collection-strong');\nvar validate = require('./_validate-collection');\nvar SET = 'Set';\n\n// 23.2 Set Objects\nmodule.exports = require('./_collection')(SET, function (get) {\n  return function Set() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.2.3.1 Set.prototype.add(value)\n  add: function add(value) {\n    return strong.def(validate(this, SET), value = value === 0 ? 0 : value, value);\n  }\n}, strong);\n","'use strict';\n// B.2.3.2 String.prototype.anchor(name)\nrequire('./_string-html')('anchor', function (createHTML) {\n  return function anchor(name) {\n    return createHTML(this, 'a', 'name', name);\n  };\n});\n","'use strict';\n// B.2.3.3 String.prototype.big()\nrequire('./_string-html')('big', function (createHTML) {\n  return function big() {\n    return createHTML(this, 'big', '', '');\n  };\n});\n","'use strict';\n// B.2.3.4 String.prototype.blink()\nrequire('./_string-html')('blink', function (createHTML) {\n  return function blink() {\n    return createHTML(this, 'blink', '', '');\n  };\n});\n","'use strict';\n// B.2.3.5 String.prototype.bold()\nrequire('./_string-html')('bold', function (createHTML) {\n  return function bold() {\n    return createHTML(this, 'b', '', '');\n  };\n});\n","'use strict';\nvar $export = require('./_export');\nvar $at = require('./_string-at')(false);\n$export($export.P, 'String', {\n  // 21.1.3.3 String.prototype.codePointAt(pos)\n  codePointAt: function codePointAt(pos) {\n    return $at(this, pos);\n  }\n});\n","// 21.1.3.6 String.prototype.endsWith(searchString [, endPosition])\n'use strict';\nvar $export = require('./_export');\nvar toLength = require('./_to-length');\nvar context = require('./_string-context');\nvar ENDS_WITH = 'endsWith';\nvar $endsWith = ''[ENDS_WITH];\n\n$export($export.P + $export.F * require('./_fails-is-regexp')(ENDS_WITH), 'String', {\n  endsWith: function endsWith(searchString /* , endPosition = @length */) {\n    var that = context(this, searchString, ENDS_WITH);\n    var endPosition = arguments.length > 1 ? arguments[1] : undefined;\n    var len = toLength(that.length);\n    var end = endPosition === undefined ? len : Math.min(toLength(endPosition), len);\n    var search = String(searchString);\n    return $endsWith\n      ? $endsWith.call(that, search, end)\n      : that.slice(end - search.length, end) === search;\n  }\n});\n","'use strict';\n// B.2.3.6 String.prototype.fixed()\nrequire('./_string-html')('fixed', function (createHTML) {\n  return function fixed() {\n    return createHTML(this, 'tt', '', '');\n  };\n});\n","'use strict';\n// B.2.3.7 String.prototype.fontcolor(color)\nrequire('./_string-html')('fontcolor', function (createHTML) {\n  return function fontcolor(color) {\n    return createHTML(this, 'font', 'color', color);\n  };\n});\n","'use strict';\n// B.2.3.8 String.prototype.fontsize(size)\nrequire('./_string-html')('fontsize', function (createHTML) {\n  return function fontsize(size) {\n    return createHTML(this, 'font', 'size', size);\n  };\n});\n","var $export = require('./_export');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nvar fromCharCode = String.fromCharCode;\nvar $fromCodePoint = String.fromCodePoint;\n\n// length should be 1, old FF problem\n$export($export.S + $export.F * (!!$fromCodePoint && $fromCodePoint.length != 1), 'String', {\n  // 21.1.2.2 String.fromCodePoint(...codePoints)\n  fromCodePoint: function fromCodePoint(x) { // eslint-disable-line no-unused-vars\n    var res = [];\n    var aLen = arguments.length;\n    var i = 0;\n    var code;\n    while (aLen > i) {\n      code = +arguments[i++];\n      if (toAbsoluteIndex(code, 0x10ffff) !== code) throw RangeError(code + ' is not a valid code point');\n      res.push(code < 0x10000\n        ? fromCharCode(code)\n        : fromCharCode(((code -= 0x10000) >> 10) + 0xd800, code % 0x400 + 0xdc00)\n      );\n    } return res.join('');\n  }\n});\n","// 21.1.3.7 String.prototype.includes(searchString, position = 0)\n'use strict';\nvar $export = require('./_export');\nvar context = require('./_string-context');\nvar INCLUDES = 'includes';\n\n$export($export.P + $export.F * require('./_fails-is-regexp')(INCLUDES), 'String', {\n  includes: function includes(searchString /* , position = 0 */) {\n    return !!~context(this, searchString, INCLUDES)\n      .indexOf(searchString, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n","'use strict';\n// B.2.3.9 String.prototype.italics()\nrequire('./_string-html')('italics', function (createHTML) {\n  return function italics() {\n    return createHTML(this, 'i', '', '');\n  };\n});\n","'use strict';\nvar $at = require('./_string-at')(true);\n\n// 21.1.3.27 String.prototype[@@iterator]()\nrequire('./_iter-define')(String, 'String', function (iterated) {\n  this._t = String(iterated); // target\n  this._i = 0;                // next index\n// 21.1.5.2.1 %StringIteratorPrototype%.next()\n}, function () {\n  var O = this._t;\n  var index = this._i;\n  var point;\n  if (index >= O.length) return { value: undefined, done: true };\n  point = $at(O, index);\n  this._i += point.length;\n  return { value: point, done: false };\n});\n","'use strict';\n// B.2.3.10 String.prototype.link(url)\nrequire('./_string-html')('link', function (createHTML) {\n  return function link(url) {\n    return createHTML(this, 'a', 'href', url);\n  };\n});\n","var $export = require('./_export');\nvar toIObject = require('./_to-iobject');\nvar toLength = require('./_to-length');\n\n$export($export.S, 'String', {\n  // 21.1.2.4 String.raw(callSite, ...substitutions)\n  raw: function raw(callSite) {\n    var tpl = toIObject(callSite.raw);\n    var len = toLength(tpl.length);\n    var aLen = arguments.length;\n    var res = [];\n    var i = 0;\n    while (len > i) {\n      res.push(String(tpl[i++]));\n      if (i < aLen) res.push(String(arguments[i]));\n    } return res.join('');\n  }\n});\n","var $export = require('./_export');\n\n$export($export.P, 'String', {\n  // 21.1.3.13 String.prototype.repeat(count)\n  repeat: require('./_string-repeat')\n});\n","'use strict';\n// B.2.3.11 String.prototype.small()\nrequire('./_string-html')('small', function (createHTML) {\n  return function small() {\n    return createHTML(this, 'small', '', '');\n  };\n});\n","// 21.1.3.18 String.prototype.startsWith(searchString [, position ])\n'use strict';\nvar $export = require('./_export');\nvar toLength = require('./_to-length');\nvar context = require('./_string-context');\nvar STARTS_WITH = 'startsWith';\nvar $startsWith = ''[STARTS_WITH];\n\n$export($export.P + $export.F * require('./_fails-is-regexp')(STARTS_WITH), 'String', {\n  startsWith: function startsWith(searchString /* , position = 0 */) {\n    var that = context(this, searchString, STARTS_WITH);\n    var index = toLength(Math.min(arguments.length > 1 ? arguments[1] : undefined, that.length));\n    var search = String(searchString);\n    return $startsWith\n      ? $startsWith.call(that, search, index)\n      : that.slice(index, index + search.length) === search;\n  }\n});\n","'use strict';\n// B.2.3.12 String.prototype.strike()\nrequire('./_string-html')('strike', function (createHTML) {\n  return function strike() {\n    return createHTML(this, 'strike', '', '');\n  };\n});\n","'use strict';\n// B.2.3.13 String.prototype.sub()\nrequire('./_string-html')('sub', function (createHTML) {\n  return function sub() {\n    return createHTML(this, 'sub', '', '');\n  };\n});\n","'use strict';\n// B.2.3.14 String.prototype.sup()\nrequire('./_string-html')('sup', function (createHTML) {\n  return function sup() {\n    return createHTML(this, 'sup', '', '');\n  };\n});\n","'use strict';\n// 21.1.3.25 String.prototype.trim()\nrequire('./_string-trim')('trim', function ($trim) {\n  return function trim() {\n    return $trim(this, 3);\n  };\n});\n","'use strict';\n// ECMAScript 6 symbols shim\nvar global = require('./_global');\nvar has = require('./_has');\nvar DESCRIPTORS = require('./_descriptors');\nvar $export = require('./_export');\nvar redefine = require('./_redefine');\nvar META = require('./_meta').KEY;\nvar $fails = require('./_fails');\nvar shared = require('./_shared');\nvar setToStringTag = require('./_set-to-string-tag');\nvar uid = require('./_uid');\nvar wks = require('./_wks');\nvar wksExt = require('./_wks-ext');\nvar wksDefine = require('./_wks-define');\nvar enumKeys = require('./_enum-keys');\nvar isArray = require('./_is-array');\nvar anObject = require('./_an-object');\nvar isObject = require('./_is-object');\nvar toIObject = require('./_to-iobject');\nvar toPrimitive = require('./_to-primitive');\nvar createDesc = require('./_property-desc');\nvar _create = require('./_object-create');\nvar gOPNExt = require('./_object-gopn-ext');\nvar $GOPD = require('./_object-gopd');\nvar $DP = require('./_object-dp');\nvar $keys = require('./_object-keys');\nvar gOPD = $GOPD.f;\nvar dP = $DP.f;\nvar gOPN = gOPNExt.f;\nvar $Symbol = global.Symbol;\nvar $JSON = global.JSON;\nvar _stringify = $JSON && $JSON.stringify;\nvar PROTOTYPE = 'prototype';\nvar HIDDEN = wks('_hidden');\nvar TO_PRIMITIVE = wks('toPrimitive');\nvar isEnum = {}.propertyIsEnumerable;\nvar SymbolRegistry = shared('symbol-registry');\nvar AllSymbols = shared('symbols');\nvar OPSymbols = shared('op-symbols');\nvar ObjectProto = Object[PROTOTYPE];\nvar USE_NATIVE = typeof $Symbol == 'function';\nvar QObject = global.QObject;\n// Don't use setters in Qt Script, https://github.com/zloirock/core-js/issues/173\nvar setter = !QObject || !QObject[PROTOTYPE] || !QObject[PROTOTYPE].findChild;\n\n// fallback for old Android, https://code.google.com/p/v8/issues/detail?id=687\nvar setSymbolDesc = DESCRIPTORS && $fails(function () {\n  return _create(dP({}, 'a', {\n    get: function () { return dP(this, 'a', { value: 7 }).a; }\n  })).a != 7;\n}) ? function (it, key, D) {\n  var protoDesc = gOPD(ObjectProto, key);\n  if (protoDesc) delete ObjectProto[key];\n  dP(it, key, D);\n  if (protoDesc && it !== ObjectProto) dP(ObjectProto, key, protoDesc);\n} : dP;\n\nvar wrap = function (tag) {\n  var sym = AllSymbols[tag] = _create($Symbol[PROTOTYPE]);\n  sym._k = tag;\n  return sym;\n};\n\nvar isSymbol = USE_NATIVE && typeof $Symbol.iterator == 'symbol' ? function (it) {\n  return typeof it == 'symbol';\n} : function (it) {\n  return it instanceof $Symbol;\n};\n\nvar $defineProperty = function defineProperty(it, key, D) {\n  if (it === ObjectProto) $defineProperty(OPSymbols, key, D);\n  anObject(it);\n  key = toPrimitive(key, true);\n  anObject(D);\n  if (has(AllSymbols, key)) {\n    if (!D.enumerable) {\n      if (!has(it, HIDDEN)) dP(it, HIDDEN, createDesc(1, {}));\n      it[HIDDEN][key] = true;\n    } else {\n      if (has(it, HIDDEN) && it[HIDDEN][key]) it[HIDDEN][key] = false;\n      D = _create(D, { enumerable: createDesc(0, false) });\n    } return setSymbolDesc(it, key, D);\n  } return dP(it, key, D);\n};\nvar $defineProperties = function defineProperties(it, P) {\n  anObject(it);\n  var keys = enumKeys(P = toIObject(P));\n  var i = 0;\n  var l = keys.length;\n  var key;\n  while (l > i) $defineProperty(it, key = keys[i++], P[key]);\n  return it;\n};\nvar $create = function create(it, P) {\n  return P === undefined ? _create(it) : $defineProperties(_create(it), P);\n};\nvar $propertyIsEnumerable = function propertyIsEnumerable(key) {\n  var E = isEnum.call(this, key = toPrimitive(key, true));\n  if (this === ObjectProto && has(AllSymbols, key) && !has(OPSymbols, key)) return false;\n  return E || !has(this, key) || !has(AllSymbols, key) || has(this, HIDDEN) && this[HIDDEN][key] ? E : true;\n};\nvar $getOwnPropertyDescriptor = function getOwnPropertyDescriptor(it, key) {\n  it = toIObject(it);\n  key = toPrimitive(key, true);\n  if (it === ObjectProto && has(AllSymbols, key) && !has(OPSymbols, key)) return;\n  var D = gOPD(it, key);\n  if (D && has(AllSymbols, key) && !(has(it, HIDDEN) && it[HIDDEN][key])) D.enumerable = true;\n  return D;\n};\nvar $getOwnPropertyNames = function getOwnPropertyNames(it) {\n  var names = gOPN(toIObject(it));\n  var result = [];\n  var i = 0;\n  var key;\n  while (names.length > i) {\n    if (!has(AllSymbols, key = names[i++]) && key != HIDDEN && key != META) result.push(key);\n  } return result;\n};\nvar $getOwnPropertySymbols = function getOwnPropertySymbols(it) {\n  var IS_OP = it === ObjectProto;\n  var names = gOPN(IS_OP ? OPSymbols : toIObject(it));\n  var result = [];\n  var i = 0;\n  var key;\n  while (names.length > i) {\n    if (has(AllSymbols, key = names[i++]) && (IS_OP ? has(ObjectProto, key) : true)) result.push(AllSymbols[key]);\n  } return result;\n};\n\n// 19.4.1.1 Symbol([description])\nif (!USE_NATIVE) {\n  $Symbol = function Symbol() {\n    if (this instanceof $Symbol) throw TypeError('Symbol is not a constructor!');\n    var tag = uid(arguments.length > 0 ? arguments[0] : undefined);\n    var $set = function (value) {\n      if (this === ObjectProto) $set.call(OPSymbols, value);\n      if (has(this, HIDDEN) && has(this[HIDDEN], tag)) this[HIDDEN][tag] = false;\n      setSymbolDesc(this, tag, createDesc(1, value));\n    };\n    if (DESCRIPTORS && setter) setSymbolDesc(ObjectProto, tag, { configurable: true, set: $set });\n    return wrap(tag);\n  };\n  redefine($Symbol[PROTOTYPE], 'toString', function toString() {\n    return this._k;\n  });\n\n  $GOPD.f = $getOwnPropertyDescriptor;\n  $DP.f = $defineProperty;\n  require('./_object-gopn').f = gOPNExt.f = $getOwnPropertyNames;\n  require('./_object-pie').f = $propertyIsEnumerable;\n  require('./_object-gops').f = $getOwnPropertySymbols;\n\n  if (DESCRIPTORS && !require('./_library')) {\n    redefine(ObjectProto, 'propertyIsEnumerable', $propertyIsEnumerable, true);\n  }\n\n  wksExt.f = function (name) {\n    return wrap(wks(name));\n  };\n}\n\n$export($export.G + $export.W + $export.F * !USE_NATIVE, { Symbol: $Symbol });\n\nfor (var es6Symbols = (\n  // 19.4.2.2, 19.4.2.3, 19.4.2.4, 19.4.2.6, 19.4.2.8, 19.4.2.9, 19.4.2.10, 19.4.2.11, 19.4.2.12, 19.4.2.13, 19.4.2.14\n  'hasInstance,isConcatSpreadable,iterator,match,replace,search,species,split,toPrimitive,toStringTag,unscopables'\n).split(','), j = 0; es6Symbols.length > j;)wks(es6Symbols[j++]);\n\nfor (var wellKnownSymbols = $keys(wks.store), k = 0; wellKnownSymbols.length > k;) wksDefine(wellKnownSymbols[k++]);\n\n$export($export.S + $export.F * !USE_NATIVE, 'Symbol', {\n  // 19.4.2.1 Symbol.for(key)\n  'for': function (key) {\n    return has(SymbolRegistry, key += '')\n      ? SymbolRegistry[key]\n      : SymbolRegistry[key] = $Symbol(key);\n  },\n  // 19.4.2.5 Symbol.keyFor(sym)\n  keyFor: function keyFor(sym) {\n    if (!isSymbol(sym)) throw TypeError(sym + ' is not a symbol!');\n    for (var key in SymbolRegistry) if (SymbolRegistry[key] === sym) return key;\n  },\n  useSetter: function () { setter = true; },\n  useSimple: function () { setter = false; }\n});\n\n$export($export.S + $export.F * !USE_NATIVE, 'Object', {\n  // 19.1.2.2 Object.create(O [, Properties])\n  create: $create,\n  // 19.1.2.4 Object.defineProperty(O, P, Attributes)\n  defineProperty: $defineProperty,\n  // 19.1.2.3 Object.defineProperties(O, Properties)\n  defineProperties: $defineProperties,\n  // 19.1.2.6 Object.getOwnPropertyDescriptor(O, P)\n  getOwnPropertyDescriptor: $getOwnPropertyDescriptor,\n  // 19.1.2.7 Object.getOwnPropertyNames(O)\n  getOwnPropertyNames: $getOwnPropertyNames,\n  // 19.1.2.8 Object.getOwnPropertySymbols(O)\n  getOwnPropertySymbols: $getOwnPropertySymbols\n});\n\n// 24.3.2 JSON.stringify(value [, replacer [, space]])\n$JSON && $export($export.S + $export.F * (!USE_NATIVE || $fails(function () {\n  var S = $Symbol();\n  // MS Edge converts symbol values to JSON as {}\n  // WebKit converts symbol values to JSON as null\n  // V8 throws on boxed symbols\n  return _stringify([S]) != '[null]' || _stringify({ a: S }) != '{}' || _stringify(Object(S)) != '{}';\n})), 'JSON', {\n  stringify: function stringify(it) {\n    var args = [it];\n    var i = 1;\n    var replacer, $replacer;\n    while (arguments.length > i) args.push(arguments[i++]);\n    $replacer = replacer = args[1];\n    if (!isObject(replacer) && it === undefined || isSymbol(it)) return; // IE8 returns string on undefined\n    if (!isArray(replacer)) replacer = function (key, value) {\n      if (typeof $replacer == 'function') value = $replacer.call(this, key, value);\n      if (!isSymbol(value)) return value;\n    };\n    args[1] = replacer;\n    return _stringify.apply($JSON, args);\n  }\n});\n\n// 19.4.3.4 Symbol.prototype[@@toPrimitive](hint)\n$Symbol[PROTOTYPE][TO_PRIMITIVE] || require('./_hide')($Symbol[PROTOTYPE], TO_PRIMITIVE, $Symbol[PROTOTYPE].valueOf);\n// 19.4.3.5 Symbol.prototype[@@toStringTag]\nsetToStringTag($Symbol, 'Symbol');\n// 20.2.1.9 Math[@@toStringTag]\nsetToStringTag(Math, 'Math', true);\n// 24.3.3 JSON[@@toStringTag]\nsetToStringTag(global.JSON, 'JSON', true);\n","'use strict';\nvar $export = require('./_export');\nvar $typed = require('./_typed');\nvar buffer = require('./_typed-buffer');\nvar anObject = require('./_an-object');\nvar toAbsoluteIndex = require('./_to-absolute-index');\nvar toLength = require('./_to-length');\nvar isObject = require('./_is-object');\nvar ArrayBuffer = require('./_global').ArrayBuffer;\nvar speciesConstructor = require('./_species-constructor');\nvar $ArrayBuffer = buffer.ArrayBuffer;\nvar $DataView = buffer.DataView;\nvar $isView = $typed.ABV && ArrayBuffer.isView;\nvar $slice = $ArrayBuffer.prototype.slice;\nvar VIEW = $typed.VIEW;\nvar ARRAY_BUFFER = 'ArrayBuffer';\n\n$export($export.G + $export.W + $export.F * (ArrayBuffer !== $ArrayBuffer), { ArrayBuffer: $ArrayBuffer });\n\n$export($export.S + $export.F * !$typed.CONSTR, ARRAY_BUFFER, {\n  // 24.1.3.1 ArrayBuffer.isView(arg)\n  isView: function isView(it) {\n    return $isView && $isView(it) || isObject(it) && VIEW in it;\n  }\n});\n\n$export($export.P + $export.U + $export.F * require('./_fails')(function () {\n  return !new $ArrayBuffer(2).slice(1, undefined).byteLength;\n}), ARRAY_BUFFER, {\n  // 24.1.4.3 ArrayBuffer.prototype.slice(start, end)\n  slice: function slice(start, end) {\n    if ($slice !== undefined && end === undefined) return $slice.call(anObject(this), start); // FF fix\n    var len = anObject(this).byteLength;\n    var first = toAbsoluteIndex(start, len);\n    var fin = toAbsoluteIndex(end === undefined ? len : end, len);\n    var result = new (speciesConstructor(this, $ArrayBuffer))(toLength(fin - first));\n    var viewS = new $DataView(this);\n    var viewT = new $DataView(result);\n    var index = 0;\n    while (first < fin) {\n      viewT.setUint8(index++, viewS.getUint8(first++));\n    } return result;\n  }\n});\n\nrequire('./_set-species')(ARRAY_BUFFER);\n","var $export = require('./_export');\n$export($export.G + $export.W + $export.F * !require('./_typed').ABV, {\n  DataView: require('./_typed-buffer').DataView\n});\n","require('./_typed-array')('Float32', 4, function (init) {\n  return function Float32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Float64', 8, function (init) {\n  return function Float64Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Int16', 2, function (init) {\n  return function Int16Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Int32', 4, function (init) {\n  return function Int32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Int8', 1, function (init) {\n  return function Int8Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Uint16', 2, function (init) {\n  return function Uint16Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Uint32', 4, function (init) {\n  return function Uint32Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Uint8', 1, function (init) {\n  return function Uint8Array(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n});\n","require('./_typed-array')('Uint8', 1, function (init) {\n  return function Uint8ClampedArray(data, byteOffset, length) {\n    return init(this, data, byteOffset, length);\n  };\n}, true);\n","'use strict';\nvar global = require('./_global');\nvar each = require('./_array-methods')(0);\nvar redefine = require('./_redefine');\nvar meta = require('./_meta');\nvar assign = require('./_object-assign');\nvar weak = require('./_collection-weak');\nvar isObject = require('./_is-object');\nvar validate = require('./_validate-collection');\nvar NATIVE_WEAK_MAP = require('./_validate-collection');\nvar IS_IE11 = !global.ActiveXObject && 'ActiveXObject' in global;\nvar WEAK_MAP = 'WeakMap';\nvar getWeak = meta.getWeak;\nvar isExtensible = Object.isExtensible;\nvar uncaughtFrozenStore = weak.ufstore;\nvar InternalMap;\n\nvar wrapper = function (get) {\n  return function WeakMap() {\n    return get(this, arguments.length > 0 ? arguments[0] : undefined);\n  };\n};\n\nvar methods = {\n  // 23.3.3.3 WeakMap.prototype.get(key)\n  get: function get(key) {\n    if (isObject(key)) {\n      var data = getWeak(key);\n      if (data === true) return uncaughtFrozenStore(validate(this, WEAK_MAP)).get(key);\n      return data ? data[this._i] : undefined;\n    }\n  },\n  // 23.3.3.5 WeakMap.prototype.set(key, value)\n  set: function set(key, value) {\n    return weak.def(validate(this, WEAK_MAP), key, value);\n  }\n};\n\n// 23.3 WeakMap Objects\nvar $WeakMap = module.exports = require('./_collection')(WEAK_MAP, wrapper, methods, weak, true, true);\n\n// IE11 WeakMap frozen keys fix\nif (NATIVE_WEAK_MAP && IS_IE11) {\n  InternalMap = weak.getConstructor(wrapper, WEAK_MAP);\n  assign(InternalMap.prototype, methods);\n  meta.NEED = true;\n  each(['delete', 'has', 'get', 'set'], function (key) {\n    var proto = $WeakMap.prototype;\n    var method = proto[key];\n    redefine(proto, key, function (a, b) {\n      // store frozen objects on internal weakmap shim\n      if (isObject(a) && !isExtensible(a)) {\n        if (!this._f) this._f = new InternalMap();\n        var result = this._f[key](a, b);\n        return key == 'set' ? this : result;\n      // store all the rest on native weakmap\n      } return method.call(this, a, b);\n    });\n  });\n}\n","'use strict';\nvar weak = require('./_collection-weak');\nvar validate = require('./_validate-collection');\nvar WEAK_SET = 'WeakSet';\n\n// 23.4 WeakSet Objects\nrequire('./_collection')(WEAK_SET, function (get) {\n  return function WeakSet() { return get(this, arguments.length > 0 ? arguments[0] : undefined); };\n}, {\n  // 23.4.3.1 WeakSet.prototype.add(value)\n  add: function add(value) {\n    return weak.def(validate(this, WEAK_SET), value, true);\n  }\n}, weak, false, true);\n","'use strict';\n// https://tc39.github.io/proposal-flatMap/#sec-Array.prototype.flatMap\nvar $export = require('./_export');\nvar flattenIntoArray = require('./_flatten-into-array');\nvar toObject = require('./_to-object');\nvar toLength = require('./_to-length');\nvar aFunction = require('./_a-function');\nvar arraySpeciesCreate = require('./_array-species-create');\n\n$export($export.P, 'Array', {\n  flatMap: function flatMap(callbackfn /* , thisArg */) {\n    var O = toObject(this);\n    var sourceLen, A;\n    aFunction(callbackfn);\n    sourceLen = toLength(O.length);\n    A = arraySpeciesCreate(O, 0);\n    flattenIntoArray(A, O, O, sourceLen, 0, 1, callbackfn, arguments[1]);\n    return A;\n  }\n});\n\nrequire('./_add-to-unscopables')('flatMap');\n","'use strict';\n// https://tc39.github.io/proposal-flatMap/#sec-Array.prototype.flatten\nvar $export = require('./_export');\nvar flattenIntoArray = require('./_flatten-into-array');\nvar toObject = require('./_to-object');\nvar toLength = require('./_to-length');\nvar toInteger = require('./_to-integer');\nvar arraySpeciesCreate = require('./_array-species-create');\n\n$export($export.P, 'Array', {\n  flatten: function flatten(/* depthArg = 1 */) {\n    var depthArg = arguments[0];\n    var O = toObject(this);\n    var sourceLen = toLength(O.length);\n    var A = arraySpeciesCreate(O, 0);\n    flattenIntoArray(A, O, O, sourceLen, 0, depthArg === undefined ? 1 : toInteger(depthArg));\n    return A;\n  }\n});\n\nrequire('./_add-to-unscopables')('flatten');\n","'use strict';\n// https://github.com/tc39/Array.prototype.includes\nvar $export = require('./_export');\nvar $includes = require('./_array-includes')(true);\n\n$export($export.P, 'Array', {\n  includes: function includes(el /* , fromIndex = 0 */) {\n    return $includes(this, el, arguments.length > 1 ? arguments[1] : undefined);\n  }\n});\n\nrequire('./_add-to-unscopables')('includes');\n","// https://github.com/rwaldron/tc39-notes/blob/master/es6/2014-09/sept-25.md#510-globalasap-for-enqueuing-a-microtask\nvar $export = require('./_export');\nvar microtask = require('./_microtask')();\nvar process = require('./_global').process;\nvar isNode = require('./_cof')(process) == 'process';\n\n$export($export.G, {\n  asap: function asap(fn) {\n    var domain = isNode && process.domain;\n    microtask(domain ? domain.bind(fn) : fn);\n  }\n});\n","// https://github.com/ljharb/proposal-is-error\nvar $export = require('./_export');\nvar cof = require('./_cof');\n\n$export($export.S, 'Error', {\n  isError: function isError(it) {\n    return cof(it) === 'Error';\n  }\n});\n","// https://github.com/tc39/proposal-global\nvar $export = require('./_export');\n\n$export($export.G, { global: require('./_global') });\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-map.from\nrequire('./_set-collection-from')('Map');\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-map.of\nrequire('./_set-collection-of')('Map');\n","// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar $export = require('./_export');\n\n$export($export.P + $export.R, 'Map', { toJSON: require('./_collection-to-json')('Map') });\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  clamp: function clamp(x, lower, upper) {\n    return Math.min(upper, Math.max(lower, x));\n  }\n});\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { DEG_PER_RAD: Math.PI / 180 });\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\nvar RAD_PER_DEG = 180 / Math.PI;\n\n$export($export.S, 'Math', {\n  degrees: function degrees(radians) {\n    return radians * RAD_PER_DEG;\n  }\n});\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\nvar scale = require('./_math-scale');\nvar fround = require('./_math-fround');\n\n$export($export.S, 'Math', {\n  fscale: function fscale(x, inLow, inHigh, outLow, outHigh) {\n    return fround(scale(x, inLow, inHigh, outLow, outHigh));\n  }\n});\n","// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  iaddh: function iaddh(x0, x1, y0, y1) {\n    var $x0 = x0 >>> 0;\n    var $x1 = x1 >>> 0;\n    var $y0 = y0 >>> 0;\n    return $x1 + (y1 >>> 0) + (($x0 & $y0 | ($x0 | $y0) & ~($x0 + $y0 >>> 0)) >>> 31) | 0;\n  }\n});\n","// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  imulh: function imulh(u, v) {\n    var UINT16 = 0xffff;\n    var $u = +u;\n    var $v = +v;\n    var u0 = $u & UINT16;\n    var v0 = $v & UINT16;\n    var u1 = $u >> 16;\n    var v1 = $v >> 16;\n    var t = (u1 * v0 >>> 0) + (u0 * v0 >>> 16);\n    return u1 * v1 + (t >> 16) + ((u0 * v1 >>> 0) + (t & UINT16) >> 16);\n  }\n});\n","// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  isubh: function isubh(x0, x1, y0, y1) {\n    var $x0 = x0 >>> 0;\n    var $x1 = x1 >>> 0;\n    var $y0 = y0 >>> 0;\n    return $x1 - (y1 >>> 0) - ((~$x0 & $y0 | ~($x0 ^ $y0) & $x0 - $y0 >>> 0) >>> 31) | 0;\n  }\n});\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { RAD_PER_DEG: 180 / Math.PI });\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\nvar DEG_PER_RAD = Math.PI / 180;\n\n$export($export.S, 'Math', {\n  radians: function radians(degrees) {\n    return degrees * DEG_PER_RAD;\n  }\n});\n","// https://rwaldron.github.io/proposal-math-extensions/\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { scale: require('./_math-scale') });\n","// http://jfbastien.github.io/papers/Math.signbit.html\nvar $export = require('./_export');\n\n$export($export.S, 'Math', { signbit: function signbit(x) {\n  // eslint-disable-next-line no-self-compare\n  return (x = +x) != x ? x : x == 0 ? 1 / x == Infinity : x > 0;\n} });\n","// https://gist.github.com/BrendanEich/4294d5c212a6d2254703\nvar $export = require('./_export');\n\n$export($export.S, 'Math', {\n  umulh: function umulh(u, v) {\n    var UINT16 = 0xffff;\n    var $u = +u;\n    var $v = +v;\n    var u0 = $u & UINT16;\n    var v0 = $v & UINT16;\n    var u1 = $u >>> 16;\n    var v1 = $v >>> 16;\n    var t = (u1 * v0 >>> 0) + (u0 * v0 >>> 16);\n    return u1 * v1 + (t >>> 16) + ((u0 * v1 >>> 0) + (t & UINT16) >>> 16);\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar aFunction = require('./_a-function');\nvar $defineProperty = require('./_object-dp');\n\n// B.2.2.2 Object.prototype.__defineGetter__(P, getter)\nrequire('./_descriptors') && $export($export.P + require('./_object-forced-pam'), 'Object', {\n  __defineGetter__: function __defineGetter__(P, getter) {\n    $defineProperty.f(toObject(this), P, { get: aFunction(getter), enumerable: true, configurable: true });\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar aFunction = require('./_a-function');\nvar $defineProperty = require('./_object-dp');\n\n// B.2.2.3 Object.prototype.__defineSetter__(P, setter)\nrequire('./_descriptors') && $export($export.P + require('./_object-forced-pam'), 'Object', {\n  __defineSetter__: function __defineSetter__(P, setter) {\n    $defineProperty.f(toObject(this), P, { set: aFunction(setter), enumerable: true, configurable: true });\n  }\n});\n","// https://github.com/tc39/proposal-object-values-entries\nvar $export = require('./_export');\nvar $entries = require('./_object-to-array')(true);\n\n$export($export.S, 'Object', {\n  entries: function entries(it) {\n    return $entries(it);\n  }\n});\n","// https://github.com/tc39/proposal-object-getownpropertydescriptors\nvar $export = require('./_export');\nvar ownKeys = require('./_own-keys');\nvar toIObject = require('./_to-iobject');\nvar gOPD = require('./_object-gopd');\nvar createProperty = require('./_create-property');\n\n$export($export.S, 'Object', {\n  getOwnPropertyDescriptors: function getOwnPropertyDescriptors(object) {\n    var O = toIObject(object);\n    var getDesc = gOPD.f;\n    var keys = ownKeys(O);\n    var result = {};\n    var i = 0;\n    var key, desc;\n    while (keys.length > i) {\n      desc = getDesc(O, key = keys[i++]);\n      if (desc !== undefined) createProperty(result, key, desc);\n    }\n    return result;\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar toPrimitive = require('./_to-primitive');\nvar getPrototypeOf = require('./_object-gpo');\nvar getOwnPropertyDescriptor = require('./_object-gopd').f;\n\n// B.2.2.4 Object.prototype.__lookupGetter__(P)\nrequire('./_descriptors') && $export($export.P + require('./_object-forced-pam'), 'Object', {\n  __lookupGetter__: function __lookupGetter__(P) {\n    var O = toObject(this);\n    var K = toPrimitive(P, true);\n    var D;\n    do {\n      if (D = getOwnPropertyDescriptor(O, K)) return D.get;\n    } while (O = getPrototypeOf(O));\n  }\n});\n","'use strict';\nvar $export = require('./_export');\nvar toObject = require('./_to-object');\nvar toPrimitive = require('./_to-primitive');\nvar getPrototypeOf = require('./_object-gpo');\nvar getOwnPropertyDescriptor = require('./_object-gopd').f;\n\n// B.2.2.5 Object.prototype.__lookupSetter__(P)\nrequire('./_descriptors') && $export($export.P + require('./_object-forced-pam'), 'Object', {\n  __lookupSetter__: function __lookupSetter__(P) {\n    var O = toObject(this);\n    var K = toPrimitive(P, true);\n    var D;\n    do {\n      if (D = getOwnPropertyDescriptor(O, K)) return D.set;\n    } while (O = getPrototypeOf(O));\n  }\n});\n","// https://github.com/tc39/proposal-object-values-entries\nvar $export = require('./_export');\nvar $values = require('./_object-to-array')(false);\n\n$export($export.S, 'Object', {\n  values: function values(it) {\n    return $values(it);\n  }\n});\n","'use strict';\n// https://github.com/zenparsing/es-observable\nvar $export = require('./_export');\nvar global = require('./_global');\nvar core = require('./_core');\nvar microtask = require('./_microtask')();\nvar OBSERVABLE = require('./_wks')('observable');\nvar aFunction = require('./_a-function');\nvar anObject = require('./_an-object');\nvar anInstance = require('./_an-instance');\nvar redefineAll = require('./_redefine-all');\nvar hide = require('./_hide');\nvar forOf = require('./_for-of');\nvar RETURN = forOf.RETURN;\n\nvar getMethod = function (fn) {\n  return fn == null ? undefined : aFunction(fn);\n};\n\nvar cleanupSubscription = function (subscription) {\n  var cleanup = subscription._c;\n  if (cleanup) {\n    subscription._c = undefined;\n    cleanup();\n  }\n};\n\nvar subscriptionClosed = function (subscription) {\n  return subscription._o === undefined;\n};\n\nvar closeSubscription = function (subscription) {\n  if (!subscriptionClosed(subscription)) {\n    subscription._o = undefined;\n    cleanupSubscription(subscription);\n  }\n};\n\nvar Subscription = function (observer, subscriber) {\n  anObject(observer);\n  this._c = undefined;\n  this._o = observer;\n  observer = new SubscriptionObserver(this);\n  try {\n    var cleanup = subscriber(observer);\n    var subscription = cleanup;\n    if (cleanup != null) {\n      if (typeof cleanup.unsubscribe === 'function') cleanup = function () { subscription.unsubscribe(); };\n      else aFunction(cleanup);\n      this._c = cleanup;\n    }\n  } catch (e) {\n    observer.error(e);\n    return;\n  } if (subscriptionClosed(this)) cleanupSubscription(this);\n};\n\nSubscription.prototype = redefineAll({}, {\n  unsubscribe: function unsubscribe() { closeSubscription(this); }\n});\n\nvar SubscriptionObserver = function (subscription) {\n  this._s = subscription;\n};\n\nSubscriptionObserver.prototype = redefineAll({}, {\n  next: function next(value) {\n    var subscription = this._s;\n    if (!subscriptionClosed(subscription)) {\n      var observer = subscription._o;\n      try {\n        var m = getMethod(observer.next);\n        if (m) return m.call(observer, value);\n      } catch (e) {\n        try {\n          closeSubscription(subscription);\n        } finally {\n          throw e;\n        }\n      }\n    }\n  },\n  error: function error(value) {\n    var subscription = this._s;\n    if (subscriptionClosed(subscription)) throw value;\n    var observer = subscription._o;\n    subscription._o = undefined;\n    try {\n      var m = getMethod(observer.error);\n      if (!m) throw value;\n      value = m.call(observer, value);\n    } catch (e) {\n      try {\n        cleanupSubscription(subscription);\n      } finally {\n        throw e;\n      }\n    } cleanupSubscription(subscription);\n    return value;\n  },\n  complete: function complete(value) {\n    var subscription = this._s;\n    if (!subscriptionClosed(subscription)) {\n      var observer = subscription._o;\n      subscription._o = undefined;\n      try {\n        var m = getMethod(observer.complete);\n        value = m ? m.call(observer, value) : undefined;\n      } catch (e) {\n        try {\n          cleanupSubscription(subscription);\n        } finally {\n          throw e;\n        }\n      } cleanupSubscription(subscription);\n      return value;\n    }\n  }\n});\n\nvar $Observable = function Observable(subscriber) {\n  anInstance(this, $Observable, 'Observable', '_f')._f = aFunction(subscriber);\n};\n\nredefineAll($Observable.prototype, {\n  subscribe: function subscribe(observer) {\n    return new Subscription(observer, this._f);\n  },\n  forEach: function forEach(fn) {\n    var that = this;\n    return new (core.Promise || global.Promise)(function (resolve, reject) {\n      aFunction(fn);\n      var subscription = that.subscribe({\n        next: function (value) {\n          try {\n            return fn(value);\n          } catch (e) {\n            reject(e);\n            subscription.unsubscribe();\n          }\n        },\n        error: reject,\n        complete: resolve\n      });\n    });\n  }\n});\n\nredefineAll($Observable, {\n  from: function from(x) {\n    var C = typeof this === 'function' ? this : $Observable;\n    var method = getMethod(anObject(x)[OBSERVABLE]);\n    if (method) {\n      var observable = anObject(method.call(x));\n      return observable.constructor === C ? observable : new C(function (observer) {\n        return observable.subscribe(observer);\n      });\n    }\n    return new C(function (observer) {\n      var done = false;\n      microtask(function () {\n        if (!done) {\n          try {\n            if (forOf(x, false, function (it) {\n              observer.next(it);\n              if (done) return RETURN;\n            }) === RETURN) return;\n          } catch (e) {\n            if (done) throw e;\n            observer.error(e);\n            return;\n          } observer.complete();\n        }\n      });\n      return function () { done = true; };\n    });\n  },\n  of: function of() {\n    for (var i = 0, l = arguments.length, items = new Array(l); i < l;) items[i] = arguments[i++];\n    return new (typeof this === 'function' ? this : $Observable)(function (observer) {\n      var done = false;\n      microtask(function () {\n        if (!done) {\n          for (var j = 0; j < items.length; ++j) {\n            observer.next(items[j]);\n            if (done) return;\n          } observer.complete();\n        }\n      });\n      return function () { done = true; };\n    });\n  }\n});\n\nhide($Observable.prototype, OBSERVABLE, function () { return this; });\n\n$export($export.G, { Observable: $Observable });\n\nrequire('./_set-species')('Observable');\n","// https://github.com/tc39/proposal-promise-finally\n'use strict';\nvar $export = require('./_export');\nvar core = require('./_core');\nvar global = require('./_global');\nvar speciesConstructor = require('./_species-constructor');\nvar promiseResolve = require('./_promise-resolve');\n\n$export($export.P + $export.R, 'Promise', { 'finally': function (onFinally) {\n  var C = speciesConstructor(this, core.Promise || global.Promise);\n  var isFunction = typeof onFinally == 'function';\n  return this.then(\n    isFunction ? function (x) {\n      return promiseResolve(C, onFinally()).then(function () { return x; });\n    } : onFinally,\n    isFunction ? function (e) {\n      return promiseResolve(C, onFinally()).then(function () { throw e; });\n    } : onFinally\n  );\n} });\n","'use strict';\n// https://github.com/tc39/proposal-promise-try\nvar $export = require('./_export');\nvar newPromiseCapability = require('./_new-promise-capability');\nvar perform = require('./_perform');\n\n$export($export.S, 'Promise', { 'try': function (callbackfn) {\n  var promiseCapability = newPromiseCapability.f(this);\n  var result = perform(callbackfn);\n  (result.e ? promiseCapability.reject : promiseCapability.resolve)(result.v);\n  return promiseCapability.promise;\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar toMetaKey = metadata.key;\nvar ordinaryDefineOwnMetadata = metadata.set;\n\nmetadata.exp({ defineMetadata: function defineMetadata(metadataKey, metadataValue, target, targetKey) {\n  ordinaryDefineOwnMetadata(metadataKey, metadataValue, anObject(target), toMetaKey(targetKey));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar toMetaKey = metadata.key;\nvar getOrCreateMetadataMap = metadata.map;\nvar store = metadata.store;\n\nmetadata.exp({ deleteMetadata: function deleteMetadata(metadataKey, target /* , targetKey */) {\n  var targetKey = arguments.length < 3 ? undefined : toMetaKey(arguments[2]);\n  var metadataMap = getOrCreateMetadataMap(anObject(target), targetKey, false);\n  if (metadataMap === undefined || !metadataMap['delete'](metadataKey)) return false;\n  if (metadataMap.size) return true;\n  var targetMetadata = store.get(target);\n  targetMetadata['delete'](targetKey);\n  return !!targetMetadata.size || store['delete'](target);\n} });\n","var Set = require('./es6.set');\nvar from = require('./_array-from-iterable');\nvar metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar getPrototypeOf = require('./_object-gpo');\nvar ordinaryOwnMetadataKeys = metadata.keys;\nvar toMetaKey = metadata.key;\n\nvar ordinaryMetadataKeys = function (O, P) {\n  var oKeys = ordinaryOwnMetadataKeys(O, P);\n  var parent = getPrototypeOf(O);\n  if (parent === null) return oKeys;\n  var pKeys = ordinaryMetadataKeys(parent, P);\n  return pKeys.length ? oKeys.length ? from(new Set(oKeys.concat(pKeys))) : pKeys : oKeys;\n};\n\nmetadata.exp({ getMetadataKeys: function getMetadataKeys(target /* , targetKey */) {\n  return ordinaryMetadataKeys(anObject(target), arguments.length < 2 ? undefined : toMetaKey(arguments[1]));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar getPrototypeOf = require('./_object-gpo');\nvar ordinaryHasOwnMetadata = metadata.has;\nvar ordinaryGetOwnMetadata = metadata.get;\nvar toMetaKey = metadata.key;\n\nvar ordinaryGetMetadata = function (MetadataKey, O, P) {\n  var hasOwn = ordinaryHasOwnMetadata(MetadataKey, O, P);\n  if (hasOwn) return ordinaryGetOwnMetadata(MetadataKey, O, P);\n  var parent = getPrototypeOf(O);\n  return parent !== null ? ordinaryGetMetadata(MetadataKey, parent, P) : undefined;\n};\n\nmetadata.exp({ getMetadata: function getMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryGetMetadata(metadataKey, anObject(target), arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar ordinaryOwnMetadataKeys = metadata.keys;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ getOwnMetadataKeys: function getOwnMetadataKeys(target /* , targetKey */) {\n  return ordinaryOwnMetadataKeys(anObject(target), arguments.length < 2 ? undefined : toMetaKey(arguments[1]));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar ordinaryGetOwnMetadata = metadata.get;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ getOwnMetadata: function getOwnMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryGetOwnMetadata(metadataKey, anObject(target)\n    , arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar getPrototypeOf = require('./_object-gpo');\nvar ordinaryHasOwnMetadata = metadata.has;\nvar toMetaKey = metadata.key;\n\nvar ordinaryHasMetadata = function (MetadataKey, O, P) {\n  var hasOwn = ordinaryHasOwnMetadata(MetadataKey, O, P);\n  if (hasOwn) return true;\n  var parent = getPrototypeOf(O);\n  return parent !== null ? ordinaryHasMetadata(MetadataKey, parent, P) : false;\n};\n\nmetadata.exp({ hasMetadata: function hasMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryHasMetadata(metadataKey, anObject(target), arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n","var metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar ordinaryHasOwnMetadata = metadata.has;\nvar toMetaKey = metadata.key;\n\nmetadata.exp({ hasOwnMetadata: function hasOwnMetadata(metadataKey, target /* , targetKey */) {\n  return ordinaryHasOwnMetadata(metadataKey, anObject(target)\n    , arguments.length < 3 ? undefined : toMetaKey(arguments[2]));\n} });\n","var $metadata = require('./_metadata');\nvar anObject = require('./_an-object');\nvar aFunction = require('./_a-function');\nvar toMetaKey = $metadata.key;\nvar ordinaryDefineOwnMetadata = $metadata.set;\n\n$metadata.exp({ metadata: function metadata(metadataKey, metadataValue) {\n  return function decorator(target, targetKey) {\n    ordinaryDefineOwnMetadata(\n      metadataKey, metadataValue,\n      (targetKey !== undefined ? anObject : aFunction)(target),\n      toMetaKey(targetKey)\n    );\n  };\n} });\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-set.from\nrequire('./_set-collection-from')('Set');\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-set.of\nrequire('./_set-collection-of')('Set');\n","// https://github.com/DavidBruant/Map-Set.prototype.toJSON\nvar $export = require('./_export');\n\n$export($export.P + $export.R, 'Set', { toJSON: require('./_collection-to-json')('Set') });\n","'use strict';\n// https://github.com/mathiasbynens/String.prototype.at\nvar $export = require('./_export');\nvar $at = require('./_string-at')(true);\n\n$export($export.P, 'String', {\n  at: function at(pos) {\n    return $at(this, pos);\n  }\n});\n","'use strict';\n// https://tc39.github.io/String.prototype.matchAll/\nvar $export = require('./_export');\nvar defined = require('./_defined');\nvar toLength = require('./_to-length');\nvar isRegExp = require('./_is-regexp');\nvar getFlags = require('./_flags');\nvar RegExpProto = RegExp.prototype;\n\nvar $RegExpStringIterator = function (regexp, string) {\n  this._r = regexp;\n  this._s = string;\n};\n\nrequire('./_iter-create')($RegExpStringIterator, 'RegExp String', function next() {\n  var match = this._r.exec(this._s);\n  return { value: match, done: match === null };\n});\n\n$export($export.P, 'String', {\n  matchAll: function matchAll(regexp) {\n    defined(this);\n    if (!isRegExp(regexp)) throw TypeError(regexp + ' is not a regexp!');\n    var S = String(this);\n    var flags = 'flags' in RegExpProto ? String(regexp.flags) : getFlags.call(regexp);\n    var rx = new RegExp(regexp.source, ~flags.indexOf('g') ? flags : 'g' + flags);\n    rx.lastIndex = toLength(regexp.lastIndex);\n    return new $RegExpStringIterator(rx, S);\n  }\n});\n","'use strict';\n// https://github.com/tc39/proposal-string-pad-start-end\nvar $export = require('./_export');\nvar $pad = require('./_string-pad');\nvar userAgent = require('./_user-agent');\n\n// https://github.com/zloirock/core-js/issues/280\n$export($export.P + $export.F * /Version\\/10\\.\\d+(\\.\\d+)? Safari\\//.test(userAgent), 'String', {\n  padEnd: function padEnd(maxLength /* , fillString = ' ' */) {\n    return $pad(this, maxLength, arguments.length > 1 ? arguments[1] : undefined, false);\n  }\n});\n","'use strict';\n// https://github.com/tc39/proposal-string-pad-start-end\nvar $export = require('./_export');\nvar $pad = require('./_string-pad');\nvar userAgent = require('./_user-agent');\n\n// https://github.com/zloirock/core-js/issues/280\n$export($export.P + $export.F * /Version\\/10\\.\\d+(\\.\\d+)? Safari\\//.test(userAgent), 'String', {\n  padStart: function padStart(maxLength /* , fillString = ' ' */) {\n    return $pad(this, maxLength, arguments.length > 1 ? arguments[1] : undefined, true);\n  }\n});\n","'use strict';\n// https://github.com/sebmarkbage/ecmascript-string-left-right-trim\nrequire('./_string-trim')('trimLeft', function ($trim) {\n  return function trimLeft() {\n    return $trim(this, 1);\n  };\n}, 'trimStart');\n","'use strict';\n// https://github.com/sebmarkbage/ecmascript-string-left-right-trim\nrequire('./_string-trim')('trimRight', function ($trim) {\n  return function trimRight() {\n    return $trim(this, 2);\n  };\n}, 'trimEnd');\n","require('./_wks-define')('asyncIterator');\n","require('./_wks-define')('observable');\n","// https://github.com/tc39/proposal-global\nvar $export = require('./_export');\n\n$export($export.S, 'System', { global: require('./_global') });\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-weakmap.from\nrequire('./_set-collection-from')('WeakMap');\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-weakmap.of\nrequire('./_set-collection-of')('WeakMap');\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-weakset.from\nrequire('./_set-collection-from')('WeakSet');\n","// https://tc39.github.io/proposal-setmap-offrom/#sec-weakset.of\nrequire('./_set-collection-of')('WeakSet');\n","var $iterators = require('./es6.array.iterator');\nvar getKeys = require('./_object-keys');\nvar redefine = require('./_redefine');\nvar global = require('./_global');\nvar hide = require('./_hide');\nvar Iterators = require('./_iterators');\nvar wks = require('./_wks');\nvar ITERATOR = wks('iterator');\nvar TO_STRING_TAG = wks('toStringTag');\nvar ArrayValues = Iterators.Array;\n\nvar DOMIterables = {\n  CSSRuleList: true, // TODO: Not spec compliant, should be false.\n  CSSStyleDeclaration: false,\n  CSSValueList: false,\n  ClientRectList: false,\n  DOMRectList: false,\n  DOMStringList: false,\n  DOMTokenList: true,\n  DataTransferItemList: false,\n  FileList: false,\n  HTMLAllCollection: false,\n  HTMLCollection: false,\n  HTMLFormElement: false,\n  HTMLSelectElement: false,\n  MediaList: true, // TODO: Not spec compliant, should be false.\n  MimeTypeArray: false,\n  NamedNodeMap: false,\n  NodeList: true,\n  PaintRequestList: false,\n  Plugin: false,\n  PluginArray: false,\n  SVGLengthList: false,\n  SVGNumberList: false,\n  SVGPathSegList: false,\n  SVGPointList: false,\n  SVGStringList: false,\n  SVGTransformList: false,\n  SourceBufferList: false,\n  StyleSheetList: true, // TODO: Not spec compliant, should be false.\n  TextTrackCueList: false,\n  TextTrackList: false,\n  TouchList: false\n};\n\nfor (var collections = getKeys(DOMIterables), i = 0; i < collections.length; i++) {\n  var NAME = collections[i];\n  var explicit = DOMIterables[NAME];\n  var Collection = global[NAME];\n  var proto = Collection && Collection.prototype;\n  var key;\n  if (proto) {\n    if (!proto[ITERATOR]) hide(proto, ITERATOR, ArrayValues);\n    if (!proto[TO_STRING_TAG]) hide(proto, TO_STRING_TAG, NAME);\n    Iterators[NAME] = ArrayValues;\n    if (explicit) for (key in $iterators) if (!proto[key]) redefine(proto, key, $iterators[key], true);\n  }\n}\n","var $export = require('./_export');\nvar $task = require('./_task');\n$export($export.G + $export.B, {\n  setImmediate: $task.set,\n  clearImmediate: $task.clear\n});\n","// ie9- setTimeout & setInterval additional parameters fix\nvar global = require('./_global');\nvar $export = require('./_export');\nvar userAgent = require('./_user-agent');\nvar slice = [].slice;\nvar MSIE = /MSIE .\\./.test(userAgent); // <- dirty ie9- check\nvar wrap = function (set) {\n  return function (fn, time /* , ...args */) {\n    var boundArgs = arguments.length > 2;\n    var args = boundArgs ? slice.call(arguments, 2) : false;\n    return set(boundArgs ? function () {\n      // eslint-disable-next-line no-new-func\n      (typeof fn == 'function' ? fn : Function(fn)).apply(this, args);\n    } : fn, time);\n  };\n};\n$export($export.G + $export.B + $export.F * MSIE, {\n  setTimeout: wrap(global.setTimeout),\n  setInterval: wrap(global.setInterval)\n});\n","require('./modules/es6.symbol');\nrequire('./modules/es6.object.create');\nrequire('./modules/es6.object.define-property');\nrequire('./modules/es6.object.define-properties');\nrequire('./modules/es6.object.get-own-property-descriptor');\nrequire('./modules/es6.object.get-prototype-of');\nrequire('./modules/es6.object.keys');\nrequire('./modules/es6.object.get-own-property-names');\nrequire('./modules/es6.object.freeze');\nrequire('./modules/es6.object.seal');\nrequire('./modules/es6.object.prevent-extensions');\nrequire('./modules/es6.object.is-frozen');\nrequire('./modules/es6.object.is-sealed');\nrequire('./modules/es6.object.is-extensible');\nrequire('./modules/es6.object.assign');\nrequire('./modules/es6.object.is');\nrequire('./modules/es6.object.set-prototype-of');\nrequire('./modules/es6.object.to-string');\nrequire('./modules/es6.function.bind');\nrequire('./modules/es6.function.name');\nrequire('./modules/es6.function.has-instance');\nrequire('./modules/es6.parse-int');\nrequire('./modules/es6.parse-float');\nrequire('./modules/es6.number.constructor');\nrequire('./modules/es6.number.to-fixed');\nrequire('./modules/es6.number.to-precision');\nrequire('./modules/es6.number.epsilon');\nrequire('./modules/es6.number.is-finite');\nrequire('./modules/es6.number.is-integer');\nrequire('./modules/es6.number.is-nan');\nrequire('./modules/es6.number.is-safe-integer');\nrequire('./modules/es6.number.max-safe-integer');\nrequire('./modules/es6.number.min-safe-integer');\nrequire('./modules/es6.number.parse-float');\nrequire('./modules/es6.number.parse-int');\nrequire('./modules/es6.math.acosh');\nrequire('./modules/es6.math.asinh');\nrequire('./modules/es6.math.atanh');\nrequire('./modules/es6.math.cbrt');\nrequire('./modules/es6.math.clz32');\nrequire('./modules/es6.math.cosh');\nrequire('./modules/es6.math.expm1');\nrequire('./modules/es6.math.fround');\nrequire('./modules/es6.math.hypot');\nrequire('./modules/es6.math.imul');\nrequire('./modules/es6.math.log10');\nrequire('./modules/es6.math.log1p');\nrequire('./modules/es6.math.log2');\nrequire('./modules/es6.math.sign');\nrequire('./modules/es6.math.sinh');\nrequire('./modules/es6.math.tanh');\nrequire('./modules/es6.math.trunc');\nrequire('./modules/es6.string.from-code-point');\nrequire('./modules/es6.string.raw');\nrequire('./modules/es6.string.trim');\nrequire('./modules/es6.string.iterator');\nrequire('./modules/es6.string.code-point-at');\nrequire('./modules/es6.string.ends-with');\nrequire('./modules/es6.string.includes');\nrequire('./modules/es6.string.repeat');\nrequire('./modules/es6.string.starts-with');\nrequire('./modules/es6.string.anchor');\nrequire('./modules/es6.string.big');\nrequire('./modules/es6.string.blink');\nrequire('./modules/es6.string.bold');\nrequire('./modules/es6.string.fixed');\nrequire('./modules/es6.string.fontcolor');\nrequire('./modules/es6.string.fontsize');\nrequire('./modules/es6.string.italics');\nrequire('./modules/es6.string.link');\nrequire('./modules/es6.string.small');\nrequire('./modules/es6.string.strike');\nrequire('./modules/es6.string.sub');\nrequire('./modules/es6.string.sup');\nrequire('./modules/es6.date.now');\nrequire('./modules/es6.date.to-json');\nrequire('./modules/es6.date.to-iso-string');\nrequire('./modules/es6.date.to-string');\nrequire('./modules/es6.date.to-primitive');\nrequire('./modules/es6.array.is-array');\nrequire('./modules/es6.array.from');\nrequire('./modules/es6.array.of');\nrequire('./modules/es6.array.join');\nrequire('./modules/es6.array.slice');\nrequire('./modules/es6.array.sort');\nrequire('./modules/es6.array.for-each');\nrequire('./modules/es6.array.map');\nrequire('./modules/es6.array.filter');\nrequire('./modules/es6.array.some');\nrequire('./modules/es6.array.every');\nrequire('./modules/es6.array.reduce');\nrequire('./modules/es6.array.reduce-right');\nrequire('./modules/es6.array.index-of');\nrequire('./modules/es6.array.last-index-of');\nrequire('./modules/es6.array.copy-within');\nrequire('./modules/es6.array.fill');\nrequire('./modules/es6.array.find');\nrequire('./modules/es6.array.find-index');\nrequire('./modules/es6.array.species');\nrequire('./modules/es6.array.iterator');\nrequire('./modules/es6.regexp.constructor');\nrequire('./modules/es6.regexp.exec');\nrequire('./modules/es6.regexp.to-string');\nrequire('./modules/es6.regexp.flags');\nrequire('./modules/es6.regexp.match');\nrequire('./modules/es6.regexp.replace');\nrequire('./modules/es6.regexp.search');\nrequire('./modules/es6.regexp.split');\nrequire('./modules/es6.promise');\nrequire('./modules/es6.map');\nrequire('./modules/es6.set');\nrequire('./modules/es6.weak-map');\nrequire('./modules/es6.weak-set');\nrequire('./modules/es6.typed.array-buffer');\nrequire('./modules/es6.typed.data-view');\nrequire('./modules/es6.typed.int8-array');\nrequire('./modules/es6.typed.uint8-array');\nrequire('./modules/es6.typed.uint8-clamped-array');\nrequire('./modules/es6.typed.int16-array');\nrequire('./modules/es6.typed.uint16-array');\nrequire('./modules/es6.typed.int32-array');\nrequire('./modules/es6.typed.uint32-array');\nrequire('./modules/es6.typed.float32-array');\nrequire('./modules/es6.typed.float64-array');\nrequire('./modules/es6.reflect.apply');\nrequire('./modules/es6.reflect.construct');\nrequire('./modules/es6.reflect.define-property');\nrequire('./modules/es6.reflect.delete-property');\nrequire('./modules/es6.reflect.enumerate');\nrequire('./modules/es6.reflect.get');\nrequire('./modules/es6.reflect.get-own-property-descriptor');\nrequire('./modules/es6.reflect.get-prototype-of');\nrequire('./modules/es6.reflect.has');\nrequire('./modules/es6.reflect.is-extensible');\nrequire('./modules/es6.reflect.own-keys');\nrequire('./modules/es6.reflect.prevent-extensions');\nrequire('./modules/es6.reflect.set');\nrequire('./modules/es6.reflect.set-prototype-of');\nrequire('./modules/es7.array.includes');\nrequire('./modules/es7.array.flat-map');\nrequire('./modules/es7.array.flatten');\nrequire('./modules/es7.string.at');\nrequire('./modules/es7.string.pad-start');\nrequire('./modules/es7.string.pad-end');\nrequire('./modules/es7.string.trim-left');\nrequire('./modules/es7.string.trim-right');\nrequire('./modules/es7.string.match-all');\nrequire('./modules/es7.symbol.async-iterator');\nrequire('./modules/es7.symbol.observable');\nrequire('./modules/es7.object.get-own-property-descriptors');\nrequire('./modules/es7.object.values');\nrequire('./modules/es7.object.entries');\nrequire('./modules/es7.object.define-getter');\nrequire('./modules/es7.object.define-setter');\nrequire('./modules/es7.object.lookup-getter');\nrequire('./modules/es7.object.lookup-setter');\nrequire('./modules/es7.map.to-json');\nrequire('./modules/es7.set.to-json');\nrequire('./modules/es7.map.of');\nrequire('./modules/es7.set.of');\nrequire('./modules/es7.weak-map.of');\nrequire('./modules/es7.weak-set.of');\nrequire('./modules/es7.map.from');\nrequire('./modules/es7.set.from');\nrequire('./modules/es7.weak-map.from');\nrequire('./modules/es7.weak-set.from');\nrequire('./modules/es7.global');\nrequire('./modules/es7.system.global');\nrequire('./modules/es7.error.is-error');\nrequire('./modules/es7.math.clamp');\nrequire('./modules/es7.math.deg-per-rad');\nrequire('./modules/es7.math.degrees');\nrequire('./modules/es7.math.fscale');\nrequire('./modules/es7.math.iaddh');\nrequire('./modules/es7.math.isubh');\nrequire('./modules/es7.math.imulh');\nrequire('./modules/es7.math.rad-per-deg');\nrequire('./modules/es7.math.radians');\nrequire('./modules/es7.math.scale');\nrequire('./modules/es7.math.umulh');\nrequire('./modules/es7.math.signbit');\nrequire('./modules/es7.promise.finally');\nrequire('./modules/es7.promise.try');\nrequire('./modules/es7.reflect.define-metadata');\nrequire('./modules/es7.reflect.delete-metadata');\nrequire('./modules/es7.reflect.get-metadata');\nrequire('./modules/es7.reflect.get-metadata-keys');\nrequire('./modules/es7.reflect.get-own-metadata');\nrequire('./modules/es7.reflect.get-own-metadata-keys');\nrequire('./modules/es7.reflect.has-metadata');\nrequire('./modules/es7.reflect.has-own-metadata');\nrequire('./modules/es7.reflect.metadata');\nrequire('./modules/es7.asap');\nrequire('./modules/es7.observable');\nrequire('./modules/web.timers');\nrequire('./modules/web.immediate');\nrequire('./modules/web.dom.iterable');\nmodule.exports = require('./modules/_core');\n","exports.read = function (buffer, offset, isLE, mLen, nBytes) {\n  var e, m\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var nBits = -7\n  var i = isLE ? (nBytes - 1) : 0\n  var d = isLE ? -1 : 1\n  var s = buffer[offset + i]\n\n  i += d\n\n  e = s & ((1 << (-nBits)) - 1)\n  s >>= (-nBits)\n  nBits += eLen\n  for (; nBits > 0; e = (e * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  m = e & ((1 << (-nBits)) - 1)\n  e >>= (-nBits)\n  nBits += mLen\n  for (; nBits > 0; m = (m * 256) + buffer[offset + i], i += d, nBits -= 8) {}\n\n  if (e === 0) {\n    e = 1 - eBias\n  } else if (e === eMax) {\n    return m ? NaN : ((s ? -1 : 1) * Infinity)\n  } else {\n    m = m + Math.pow(2, mLen)\n    e = e - eBias\n  }\n  return (s ? -1 : 1) * m * Math.pow(2, e - mLen)\n}\n\nexports.write = function (buffer, value, offset, isLE, mLen, nBytes) {\n  var e, m, c\n  var eLen = (nBytes * 8) - mLen - 1\n  var eMax = (1 << eLen) - 1\n  var eBias = eMax >> 1\n  var rt = (mLen === 23 ? Math.pow(2, -24) - Math.pow(2, -77) : 0)\n  var i = isLE ? 0 : (nBytes - 1)\n  var d = isLE ? 1 : -1\n  var s = value < 0 || (value === 0 && 1 / value < 0) ? 1 : 0\n\n  value = Math.abs(value)\n\n  if (isNaN(value) || value === Infinity) {\n    m = isNaN(value) ? 1 : 0\n    e = eMax\n  } else {\n    e = Math.floor(Math.log(value) / Math.LN2)\n    if (value * (c = Math.pow(2, -e)) < 1) {\n      e--\n      c *= 2\n    }\n    if (e + eBias >= 1) {\n      value += rt / c\n    } else {\n      value += rt * Math.pow(2, 1 - eBias)\n    }\n    if (value * c >= 2) {\n      e++\n      c /= 2\n    }\n\n    if (e + eBias >= eMax) {\n      m = 0\n      e = eMax\n    } else if (e + eBias >= 1) {\n      m = ((value * c) - 1) * Math.pow(2, mLen)\n      e = e + eBias\n    } else {\n      m = value * Math.pow(2, eBias - 1) * Math.pow(2, mLen)\n      e = 0\n    }\n  }\n\n  for (; mLen >= 8; buffer[offset + i] = m & 0xff, i += d, m /= 256, mLen -= 8) {}\n\n  e = (e << mLen) | m\n  eLen += mLen\n  for (; eLen > 0; buffer[offset + i] = e & 0xff, i += d, e /= 256, eLen -= 8) {}\n\n  buffer[offset + i - d] |= s * 128\n}\n","/**\n * Convert array of 16 byte values to UUID string format of the form:\n * XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX\n */\nvar byteToHex = [];\nfor (var i = 0; i < 256; ++i) {\n  byteToHex[i] = (i + 0x100).toString(16).substr(1);\n}\n\nfunction bytesToUuid(buf, offset) {\n  var i = offset || 0;\n  var bth = byteToHex;\n  // join used to fix memory issue caused by concatenation: https://bugs.chromium.org/p/v8/issues/detail?id=3175#c4\n  return ([bth[buf[i++]], bth[buf[i++]], \n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]], '-',\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]],\n\tbth[buf[i++]], bth[buf[i++]]]).join('');\n}\n\nmodule.exports = bytesToUuid;\n","// Unique ID creation requires a high quality random # generator.  In the\n// browser this is a little complicated due to unknown quality of Math.random()\n// and inconsistent support for the `crypto` API.  We do the best we can via\n// feature-detection\n\n// getRandomValues needs to be invoked in a context where \"this\" is a Crypto\n// implementation. Also, find the complete implementation of crypto on IE11.\nvar getRandomValues = (typeof(crypto) != 'undefined' && crypto.getRandomValues && crypto.getRandomValues.bind(crypto)) ||\n                      (typeof(msCrypto) != 'undefined' && typeof window.msCrypto.getRandomValues == 'function' && msCrypto.getRandomValues.bind(msCrypto));\n\nif (getRandomValues) {\n  // WHATWG crypto RNG - http://wiki.whatwg.org/wiki/Crypto\n  var rnds8 = new Uint8Array(16); // eslint-disable-line no-undef\n\n  module.exports = function whatwgRNG() {\n    getRandomValues(rnds8);\n    return rnds8;\n  };\n} else {\n  // Math.random()-based (RNG)\n  //\n  // If all else fails, use Math.random().  It's fast, but is of unspecified\n  // quality.\n  var rnds = new Array(16);\n\n  module.exports = function mathRNG() {\n    for (var i = 0, r; i < 16; i++) {\n      if ((i & 0x03) === 0) r = Math.random() * 0x100000000;\n      rnds[i] = r >>> ((i & 0x03) << 3) & 0xff;\n    }\n\n    return rnds;\n  };\n}\n","var rng = require('./lib/rng');\nvar bytesToUuid = require('./lib/bytesToUuid');\n\nfunction v4(options, buf, offset) {\n  var i = buf && offset || 0;\n\n  if (typeof(options) == 'string') {\n    buf = options === 'binary' ? new Array(16) : null;\n    options = null;\n  }\n  options = options || {};\n\n  var rnds = options.random || (options.rng || rng)();\n\n  // Per 4.4, set bits for version and `clock_seq_hi_and_reserved`\n  rnds[6] = (rnds[6] & 0x0f) | 0x40;\n  rnds[8] = (rnds[8] & 0x3f) | 0x80;\n\n  // Copy bytes to buffer, if provided\n  if (buf) {\n    for (var ii = 0; ii < 16; ++ii) {\n      buf[i + ii] = rnds[ii];\n    }\n  }\n\n  return buf || bytesToUuid(rnds);\n}\n\nmodule.exports = v4;\n","var g;\n\n// This works in non-strict mode\ng = (function() {\n\treturn this;\n})();\n\ntry {\n\t// This works if eval is allowed (see CSP)\n\tg = g || new Function(\"return this\")();\n} catch (e) {\n\t// This works if the window reference is available\n\tif (typeof window === \"object\") g = window;\n}\n\n// g can still be undefined, but nothing to do about it...\n// We return undefined, instead of nothing here, so it's\n// easier to handle this case. if(!global) { ...}\n\nmodule.exports = g;\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Timer } from './Timer.js';\r\n\r\nconst DefaultAccessTokenExpiringNotificationTime = 60; // seconds\r\n\r\nexport class AccessTokenEvents {\r\n\r\n    constructor({\r\n        accessTokenExpiringNotificationTime = DefaultAccessTokenExpiringNotificationTime,\r\n        accessTokenExpiringTimer = new Timer(\"Access token expiring\"),\r\n        accessTokenExpiredTimer = new Timer(\"Access token expired\")\r\n    } = {}) {\r\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\r\n\r\n        this._accessTokenExpiring = accessTokenExpiringTimer;\r\n        this._accessTokenExpired = accessTokenExpiredTimer;\r\n    }\r\n\r\n    load(container) {\r\n        // only register events if there's an access token and it has an expiration\r\n        if (container.access_token && container.expires_in !== undefined) {\r\n            let duration = container.expires_in;\r\n            Log.debug(\"AccessTokenEvents.load: access token present, remaining duration:\", duration);\r\n\r\n            if (duration > 0) {\r\n                // only register expiring if we still have time\r\n                let expiring = duration - this._accessTokenExpiringNotificationTime;\r\n                if (expiring <= 0){\r\n                    expiring = 1;\r\n                }\r\n                \r\n                Log.debug(\"AccessTokenEvents.load: registering expiring timer in:\", expiring);\r\n                this._accessTokenExpiring.init(expiring);\r\n            }\r\n            else {\r\n                Log.debug(\"AccessTokenEvents.load: canceling existing expiring timer becase we're past expiration.\");\r\n                this._accessTokenExpiring.cancel();\r\n            }\r\n\r\n            // if it's negative, it will still fire\r\n            let expired = duration + 1;\r\n            Log.debug(\"AccessTokenEvents.load: registering expired timer in:\", expired);\r\n            this._accessTokenExpired.init(expired);\r\n        }\r\n        else {\r\n            this._accessTokenExpiring.cancel();\r\n            this._accessTokenExpired.cancel();\r\n        }\r\n    }\r\n\r\n    unload() {\r\n        Log.debug(\"AccessTokenEvents.unload: canceling existing access token timers\");\r\n        this._accessTokenExpiring.cancel();\r\n        this._accessTokenExpired.cancel();\r\n    }\r\n\r\n    addAccessTokenExpiring(cb) {\r\n        this._accessTokenExpiring.addHandler(cb);\r\n    }\r\n    removeAccessTokenExpiring(cb) {\r\n        this._accessTokenExpiring.removeHandler(cb);\r\n    }\r\n\r\n    addAccessTokenExpired(cb) {\r\n        this._accessTokenExpired.addHandler(cb);\r\n    }\r\n    removeAccessTokenExpired(cb) {\r\n        this._accessTokenExpired.removeHandler(cb);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultInterval = 2000;\r\n\r\nexport class CheckSessionIFrame {\r\n    constructor(callback, client_id, url, interval, stopOnError = true) {\r\n        this._callback = callback;\r\n        this._client_id = client_id;\r\n        this._url = url;\r\n        this._interval = interval || DefaultInterval;\r\n        this._stopOnError = stopOnError;\r\n\r\n        var idx = url.indexOf(\"/\", url.indexOf(\"//\") + 2);\r\n        this._frame_origin = url.substr(0, idx);\r\n\r\n        this._frame = window.document.createElement(\"iframe\");\r\n\r\n        // shotgun approach\r\n        this._frame.style.visibility = \"hidden\";\r\n        this._frame.style.position = \"absolute\";\r\n        this._frame.style.display = \"none\";\r\n        this._frame.style.width = 0;\r\n        this._frame.style.height = 0;\r\n\r\n        this._frame.src = url;\r\n    }\r\n    load() {\r\n        return new Promise((resolve) => {\r\n            this._frame.onload = () => {\r\n                resolve();\r\n            }\r\n\r\n            window.document.body.appendChild(this._frame);\r\n            this._boundMessageEvent = this._message.bind(this);\r\n            window.addEventListener(\"message\", this._boundMessageEvent, false);\r\n        });\r\n    }\r\n    _message(e) {\r\n        if (e.origin === this._frame_origin &&\r\n            e.source === this._frame.contentWindow\r\n        ) {\r\n            if (e.data === \"error\") {\r\n                Log.error(\"CheckSessionIFrame: error message from check session op iframe\");\r\n                if (this._stopOnError) {\r\n                    this.stop();\r\n                }\r\n            }\r\n            else if (e.data === \"changed\") {\r\n                Log.debug(\"CheckSessionIFrame: changed message from check session op iframe\");\r\n                this.stop();\r\n                this._callback();\r\n            }\r\n            else {\r\n                Log.debug(\"CheckSessionIFrame: \" + e.data + \" message from check session op iframe\");\r\n            }\r\n        }\r\n    }\r\n    start(session_state) {\r\n        if (this._session_state !== session_state) {\r\n            Log.debug(\"CheckSessionIFrame.start\");\r\n\r\n            this.stop();\r\n\r\n            this._session_state = session_state;\r\n\r\n            let send = () => {\r\n                this._frame.contentWindow.postMessage(this._client_id + \" \" + this._session_state, this._frame_origin);\r\n            };\r\n            \r\n            // trigger now\r\n            send();\r\n\r\n            // and setup timer\r\n            this._timer = window.setInterval(send, this._interval);\r\n        }\r\n    }\r\n\r\n    stop() {\r\n        this._session_state = null;\r\n\r\n        if (this._timer) {\r\n            Log.debug(\"CheckSessionIFrame.stop\");\r\n\r\n            window.clearInterval(this._timer);\r\n            this._timer = null;\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { CordovaPopupWindow } from './CordovaPopupWindow.js';\r\n\r\nexport class CordovaIFrameNavigator {\r\n\r\n    prepare(params) {\r\n        params.popupWindowFeatures = 'hidden=yes';\r\n        let popup = new CordovaPopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { CordovaPopupWindow } from './CordovaPopupWindow.js';\r\n\r\nexport class CordovaPopupNavigator {\r\n\r\n    prepare(params) {\r\n        let popup = new CordovaPopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultPopupFeatures = 'location=no,toolbar=no,zoom=no';\r\nconst DefaultPopupTarget = \"_blank\";\r\n\r\nexport class CordovaPopupWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        this.features = params.popupWindowFeatures || DefaultPopupFeatures;\r\n        this.target = params.popupWindowTarget || DefaultPopupTarget;\r\n        \r\n        this.redirect_uri = params.startUrl;\r\n        Log.debug(\"CordovaPopupWindow.ctor: redirect_uri: \" + this.redirect_uri);\r\n    }\r\n\r\n    _isInAppBrowserInstalled(cordovaMetadata) {\r\n        return [\"cordova-plugin-inappbrowser\", \"cordova-plugin-inappbrowser.inappbrowser\", \"org.apache.cordova.inappbrowser\"].some(function (name) {\r\n            return cordovaMetadata.hasOwnProperty(name)\r\n        })\r\n    }\r\n    \r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            this._error(\"No url provided\");\r\n        } else {\r\n            if (!window.cordova) {\r\n                return this._error(\"cordova is undefined\")\r\n            }\r\n            \r\n            var cordovaMetadata = window.cordova.require(\"cordova/plugin_list\").metadata;\r\n            if (this._isInAppBrowserInstalled(cordovaMetadata) === false) {\r\n                return this._error(\"InAppBrowser plugin not found\")\r\n            }\r\n            this._popup = cordova.InAppBrowser.open(params.url, this.target, this.features);\r\n            if (this._popup) {\r\n                Log.debug(\"CordovaPopupWindow.navigate: popup successfully created\");\r\n                \r\n                this._exitCallbackEvent = this._exitCallback.bind(this); \r\n                this._loadStartCallbackEvent = this._loadStartCallback.bind(this);\r\n                \r\n                this._popup.addEventListener(\"exit\", this._exitCallbackEvent, false);\r\n                this._popup.addEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\r\n            } else {\r\n                this._error(\"Error opening popup window\");\r\n            }\r\n        }\r\n        return this.promise;\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    _loadStartCallback(event) {\r\n        if (event.url.indexOf(this.redirect_uri) === 0) {\r\n            this._success({ url: event.url });\r\n        }    \r\n    }\r\n    _exitCallback(message) {\r\n        this._error(message);    \r\n    }\r\n    \r\n    _success(data) {\r\n        this._cleanup();\r\n\r\n        Log.debug(\"CordovaPopupWindow: Successful response from cordova popup window\");\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        this._cleanup();\r\n\r\n        Log.error(message);\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup();\r\n    }\r\n\r\n    _cleanup() {\r\n        if (this._popup){\r\n            Log.debug(\"CordovaPopupWindow: cleaning up popup\");\r\n            this._popup.removeEventListener(\"exit\", this._exitCallbackEvent, false);\r\n            this._popup.removeEventListener(\"loadstart\", this._loadStartCallbackEvent, false);\r\n            this._popup.close();\r\n        }\r\n        this._popup = null;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class ErrorResponse extends Error {\r\n    constructor({error, error_description, error_uri, state, session_state}={}\r\n    ) {\r\n         if (!error){\r\n            Log.error(\"No error passed to ErrorResponse\");\r\n            throw new Error(\"error\");\r\n        }\r\n\r\n        super(error_description || error);\r\n\r\n        this.name = \"ErrorResponse\";\r\n\r\n        this.error = error;\r\n        this.error_description = error_description;\r\n        this.error_uri = error_uri;\r\n\r\n        this.state = state;\r\n        this.session_state = session_state;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class Event {\r\n\r\n    constructor(name) {\r\n        this._name = name;\r\n        this._callbacks = [];\r\n    }\r\n\r\n    addHandler(cb) {\r\n        this._callbacks.push(cb);\r\n    }\r\n\r\n    removeHandler(cb) {\r\n        var idx = this._callbacks.findIndex(item => item === cb);\r\n        if (idx >= 0) {\r\n            this._callbacks.splice(idx, 1);\r\n        }\r\n    }\r\n\r\n    raise(...params) {\r\n        Log.debug(\"Event: Raising event: \" + this._name);\r\n        for (let i = 0; i < this._callbacks.length; i++) {\r\n            this._callbacks[i](...params);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nconst timer = {\r\n    setInterval: function (cb, duration) {\r\n        return setInterval(cb, duration);\r\n    },\r\n    clearInterval: function (handle) {\r\n        return clearInterval(handle);\r\n    }\r\n};\r\n\r\nlet testing = false;\r\nlet request = null;\r\n\r\nexport class Global {\r\n\r\n    static _testing() {\r\n        testing = true;\r\n    }\r\n\r\n    static get location() {\r\n        if (!testing) {\r\n            return location;\r\n        }\r\n    }\r\n\r\n    static get localStorage() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return localStorage;\r\n        }\r\n    }\r\n\r\n    static get sessionStorage() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return sessionStorage;\r\n        }\r\n    }\r\n\r\n    static setXMLHttpRequest(newRequest) {\r\n        request = newRequest;\r\n    }\r\n\r\n    static get XMLHttpRequest() {\r\n        if (!testing && typeof window !== 'undefined') {\r\n            return request || XMLHttpRequest;\r\n        }\r\n    }\r\n\r\n    static get timer() {\r\n        if (!testing) {\r\n            return timer;\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { IFrameWindow } from './IFrameWindow.js';\r\n\r\nexport class IFrameNavigator {\r\n\r\n    prepare(params) {\r\n        let frame = new IFrameWindow(params);\r\n        return Promise.resolve(frame);\r\n    }\r\n\r\n    callback(url) {\r\n        Log.debug(\"IFrameNavigator.callback\");\r\n\r\n        try {\r\n            IFrameWindow.notifyParent(url);\r\n            return Promise.resolve();\r\n        }\r\n        catch (e) {\r\n            return Promise.reject(e);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nconst DefaultTimeout = 10000;\r\n\r\nexport class IFrameWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        this._boundMessageEvent = this._message.bind(this);\r\n        window.addEventListener(\"message\", this._boundMessageEvent, false);\r\n\r\n        this._frame = window.document.createElement(\"iframe\");\r\n\r\n        // shotgun approach\r\n        this._frame.style.visibility = \"hidden\";\r\n        this._frame.style.position = \"absolute\";\r\n        this._frame.style.display = \"none\";\r\n        this._frame.style.width = 0;\r\n        this._frame.style.height = 0;\r\n\r\n        window.document.body.appendChild(this._frame);\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            this._error(\"No url provided\");\r\n        }\r\n        else {\r\n            let timeout = params.silentRequestTimeout || DefaultTimeout;\r\n            Log.debug(\"IFrameWindow.navigate: Using timeout of:\", timeout);\r\n            this._timer = window.setTimeout(this._timeout.bind(this), timeout);\r\n            this._frame.src = params.url;\r\n        }\r\n\r\n        return this.promise;\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    _success(data) {\r\n        this._cleanup();\r\n\r\n        Log.debug(\"IFrameWindow: Successful response from frame window\");\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        this._cleanup();\r\n\r\n        Log.error(message);\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup();\r\n    }\r\n\r\n    _cleanup() {\r\n        if (this._frame) {\r\n            Log.debug(\"IFrameWindow: cleanup\");\r\n\r\n            window.removeEventListener(\"message\", this._boundMessageEvent, false);\r\n            window.clearTimeout(this._timer);\r\n            window.document.body.removeChild(this._frame);\r\n\r\n            this._timer = null;\r\n            this._frame = null;\r\n            this._boundMessageEvent = null;\r\n        }\r\n    }\r\n\r\n    _timeout() {\r\n        Log.debug(\"IFrameWindow.timeout\");\r\n        this._error(\"Frame window timed out\");\r\n    }\r\n\r\n    _message(e) {\r\n        Log.debug(\"IFrameWindow.message\");\r\n\r\n        if (this._timer &&\r\n            e.origin === this._origin &&\r\n            e.source === this._frame.contentWindow\r\n        ) {\r\n            let url = e.data;\r\n            if (url) {\r\n                this._success({ url: url });\r\n            }\r\n            else {\r\n                this._error(\"Invalid response from frame\");\r\n            }\r\n        }\r\n    }\r\n\r\n    get _origin() {\r\n        return location.protocol + \"//\" + location.host;\r\n    }\r\n\r\n    static notifyParent(url) {\r\n        Log.debug(\"IFrameWindow.notifyParent\");\r\n        if (window.frameElement) {\r\n            url = url || window.location.href;\r\n            if (url) {\r\n                Log.debug(\"IFrameWindow.notifyParent: posting url message to parent\");\r\n                window.parent.postMessage(url, location.protocol + \"//\" + location.host);\r\n            }\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class InMemoryWebStorage{\r\n    constructor(){\r\n        this._data = {};\r\n    }\r\n\r\n    getItem(key) {\r\n        Log.debug(\"InMemoryWebStorage.getItem\", key);\r\n        return this._data[key];\r\n    }\r\n\r\n    setItem(key, value){\r\n        Log.debug(\"InMemoryWebStorage.setItem\", key);\r\n        this._data[key] = value;\r\n    }\r\n\r\n    removeItem(key){\r\n        Log.debug(\"InMemoryWebStorage.removeItem\", key);\r\n        delete this._data[key];\r\n    }\r\n\r\n    get length() {\r\n        return Object.getOwnPropertyNames(this._data).length;\r\n    }\r\n\r\n    key(index) {\r\n        return Object.getOwnPropertyNames(this._data)[index];\r\n    }\r\n}\r\n","import { jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs } from './crypto/jsrsasign';\r\nimport getJoseUtil from './JoseUtilImpl';\r\n\r\nexport const JoseUtil = getJoseUtil({ jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs });\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport default function getJoseUtil({ jws, KeyUtil, X509, crypto, hextob64u, b64tohex, AllowedSigningAlgs }) {\r\n    return class JoseUtil {\r\n\r\n        static parseJwt(jwt) {\r\n            Log.debug(\"JoseUtil.parseJwt\");\r\n            try {\r\n                var token = jws.JWS.parse(jwt);\r\n                return {\r\n                    header: token.headerObj,\r\n                    payload: token.payloadObj\r\n                }\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n\r\n        static validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\r\n            Log.debug(\"JoseUtil.validateJwt\");\r\n\r\n            try {\r\n                if (key.kty === \"RSA\") {\r\n                    if (key.e && key.n) {\r\n                        key = KeyUtil.getKey(key);\r\n                    } else if (key.x5c && key.x5c.length) {\r\n                        var hex = b64tohex(key.x5c[0]);\r\n                        key = X509.getPublicKeyFromCertHex(hex);\r\n                    } else {\r\n                        Log.error(\"JoseUtil.validateJwt: RSA key missing key material\", key);\r\n                        return Promise.reject(new Error(\"RSA key missing key material\"));\r\n                    }\r\n                } else if (key.kty === \"EC\") {\r\n                    if (key.crv && key.x && key.y) {\r\n                        key = KeyUtil.getKey(key);\r\n                    } else {\r\n                        Log.error(\"JoseUtil.validateJwt: EC key missing key material\", key);\r\n                        return Promise.reject(new Error(\"EC key missing key material\"));\r\n                    }\r\n                } else {\r\n                    Log.error(\"JoseUtil.validateJwt: Unsupported key type\", key && key.kty);\r\n                    return Promise.reject(new Error(\"Unsupported key type: \" + key && key.kty));\r\n                }\r\n\r\n                return JoseUtil._validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive);\r\n            } catch (e) {\r\n                Log.error(e && e.message || e);\r\n                return Promise.reject(\"JWT validation failed\");\r\n            }\r\n        }\r\n\r\n        static validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive) {\r\n            if (!clockSkew) {\r\n                clockSkew = 0;\r\n            }\r\n\r\n            if (!now) {\r\n                now = parseInt(Date.now() / 1000);\r\n            }\r\n\r\n            var payload = JoseUtil.parseJwt(jwt).payload;\r\n\r\n            if (!payload.iss) {\r\n                Log.error(\"JoseUtil._validateJwt: issuer was not provided\");\r\n                return Promise.reject(new Error(\"issuer was not provided\"));\r\n            }\r\n            if (payload.iss !== issuer) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid issuer in token\", payload.iss);\r\n                return Promise.reject(new Error(\"Invalid issuer in token: \" + payload.iss));\r\n            }\r\n\r\n            if (!payload.aud) {\r\n                Log.error(\"JoseUtil._validateJwt: aud was not provided\");\r\n                return Promise.reject(new Error(\"aud was not provided\"));\r\n            }\r\n            var validAudience = payload.aud === audience || (Array.isArray(payload.aud) && payload.aud.indexOf(audience) >= 0);\r\n            if (!validAudience) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid audience in token\", payload.aud);\r\n                return Promise.reject(new Error(\"Invalid audience in token: \" + payload.aud));\r\n            }\r\n            if (payload.azp && payload.azp !== audience) {\r\n                Log.error(\"JoseUtil._validateJwt: Invalid azp in token\", payload.azp);\r\n                return Promise.reject(new Error(\"Invalid azp in token: \" + payload.azp));\r\n            }\r\n\r\n            if (!timeInsensitive) {\r\n                var lowerNow = now + clockSkew;\r\n                var upperNow = now - clockSkew;\r\n\r\n                if (!payload.iat) {\r\n                    Log.error(\"JoseUtil._validateJwt: iat was not provided\");\r\n                    return Promise.reject(new Error(\"iat was not provided\"));\r\n                }\r\n                if (lowerNow < payload.iat) {\r\n                    Log.error(\"JoseUtil._validateJwt: iat is in the future\", payload.iat);\r\n                    return Promise.reject(new Error(\"iat is in the future: \" + payload.iat));\r\n                }\r\n\r\n                if (payload.nbf && lowerNow < payload.nbf) {\r\n                    Log.error(\"JoseUtil._validateJwt: nbf is in the future\", payload.nbf);\r\n                    return Promise.reject(new Error(\"nbf is in the future: \" + payload.nbf));\r\n                }\r\n\r\n                if (!payload.exp) {\r\n                    Log.error(\"JoseUtil._validateJwt: exp was not provided\");\r\n                    return Promise.reject(new Error(\"exp was not provided\"));\r\n                }\r\n                if (payload.exp < upperNow) {\r\n                    Log.error(\"JoseUtil._validateJwt: exp is in the past\", payload.exp);\r\n                    return Promise.reject(new Error(\"exp is in the past:\" + payload.exp));\r\n                }\r\n            }\r\n\r\n            return Promise.resolve(payload);\r\n        }\r\n\r\n        static _validateJwt(jwt, key, issuer, audience, clockSkew, now, timeInsensitive) {\r\n\r\n            return JoseUtil.validateJwtAttributes(jwt, issuer, audience, clockSkew, now, timeInsensitive).then(payload => {\r\n                try {\r\n                    if (!jws.JWS.verify(jwt, key, AllowedSigningAlgs)) {\r\n                        Log.error(\"JoseUtil._validateJwt: signature validation failed\");\r\n                        return Promise.reject(new Error(\"signature validation failed\"));\r\n                    }\r\n\r\n                    return payload;\r\n                } catch (e) {\r\n                    Log.error(e && e.message || e);\r\n                    return Promise.reject(new Error(\"signature validation failed\"));\r\n                }\r\n            });\r\n        }\r\n\r\n        static hashString(value, alg) {\r\n            try {\r\n                return crypto.Util.hashString(value, alg);\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n\r\n        static hexToBase64Url(value) {\r\n            try {\r\n                return hextob64u(value);\r\n            } catch (e) {\r\n                Log.error(e);\r\n            }\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class JsonService {\r\n    constructor(\r\n        additionalContentTypes = null, \r\n        XMLHttpRequestCtor = Global.XMLHttpRequest, \r\n        jwtHandler = null\r\n    ) {\r\n        if (additionalContentTypes && Array.isArray(additionalContentTypes))\r\n        {\r\n            this._contentTypes = additionalContentTypes.slice();\r\n        }\r\n        else\r\n        {\r\n            this._contentTypes = [];\r\n        }\r\n        this._contentTypes.push('application/json');\r\n        if (jwtHandler) {\r\n            this._contentTypes.push('application/jwt');\r\n        }\r\n\r\n        this._XMLHttpRequest = XMLHttpRequestCtor;\r\n        this._jwtHandler = jwtHandler;\r\n    }\r\n\r\n    getJson(url, token) {\r\n        if (!url){\r\n            Log.error(\"JsonService.getJson: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        Log.debug(\"JsonService.getJson, url: \", url);\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var req = new this._XMLHttpRequest();\r\n            req.open('GET', url);\r\n\r\n            var allowedContentTypes = this._contentTypes;\r\n            var jwtHandler = this._jwtHandler;\r\n\r\n            req.onload = function() {\r\n                Log.debug(\"JsonService.getJson: HTTP response received, status\", req.status);\r\n\r\n                if (req.status === 200) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found == \"application/jwt\") {\r\n                            jwtHandler(req).then(resolve, reject);\r\n                            return;\r\n                        }\r\n\r\n                        if (found) {\r\n                            try {\r\n                                resolve(JSON.parse(req.responseText));\r\n                                return;\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.getJson: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n\r\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\r\n                }\r\n                else {\r\n                    reject(Error(req.statusText + \" (\" + req.status + \")\"));\r\n                }\r\n            };\r\n\r\n            req.onerror = function() {\r\n                Log.error(\"JsonService.getJson: network error\");\r\n                reject(Error(\"Network Error\"));\r\n            };\r\n\r\n            if (token) {\r\n                Log.debug(\"JsonService.getJson: token passed, setting Authorization header\");\r\n                req.setRequestHeader(\"Authorization\", \"Bearer \" + token);\r\n            }\r\n\r\n            req.send();\r\n        });\r\n    }\r\n\r\n    postForm(url, payload) {\r\n        if (!url){\r\n            Log.error(\"JsonService.postForm: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        Log.debug(\"JsonService.postForm, url: \", url);\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var req = new this._XMLHttpRequest();\r\n            req.open('POST', url);\r\n\r\n            var allowedContentTypes = this._contentTypes;\r\n\r\n            req.onload = function() {\r\n                Log.debug(\"JsonService.postForm: HTTP response received, status\", req.status);\r\n\r\n                if (req.status === 200) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found) {\r\n                            try {\r\n                                resolve(JSON.parse(req.responseText));\r\n                                return;\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n\r\n                    reject(Error(\"Invalid response Content-Type: \" + contentType + \", from URL: \" + url));\r\n                    return;\r\n                }\r\n\r\n                if (req.status === 400) {\r\n\r\n                    var contentType = req.getResponseHeader(\"Content-Type\");\r\n                    if (contentType) {\r\n\r\n                        var found = allowedContentTypes.find(item=>{\r\n                            if (contentType.startsWith(item)) {\r\n                                return true;\r\n                            }\r\n                        });\r\n\r\n                        if (found) {\r\n                            try {\r\n                                var payload = JSON.parse(req.responseText);\r\n                                if (payload && payload.error) {\r\n                                    Log.error(\"JsonService.postForm: Error from server: \", payload.error);\r\n                                    reject(new Error(payload.error));\r\n                                    return;\r\n                                }\r\n                            }\r\n                            catch (e) {\r\n                                Log.error(\"JsonService.postForm: Error parsing JSON response\", e.message);\r\n                                reject(e);\r\n                                return;\r\n                            }\r\n                        }\r\n                    }\r\n                }\r\n\r\n                reject(Error(req.statusText + \" (\" + req.status + \")\"));\r\n            };\r\n\r\n            req.onerror = function() {\r\n                Log.error(\"JsonService.postForm: network error\");\r\n                reject(Error(\"Network Error\"));\r\n            };\r\n\r\n            let body = \"\";\r\n            for(let key in payload) {\r\n\r\n                let value = payload[key];\r\n\r\n                if (value) {\r\n\r\n                    if (body.length > 0) {\r\n                        body += \"&\";\r\n                    }\r\n\r\n                    body += encodeURIComponent(key);\r\n                    body += \"=\";\r\n                    body += encodeURIComponent(value);\r\n                }\r\n            }\r\n\r\n            req.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\r\n            req.send(body);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nlet nopLogger = {\r\n    debug(){},\r\n    info(){},\r\n    warn(){},\r\n    error(){}\r\n};\r\n\r\nconst NONE = 0;\r\nconst ERROR = 1;\r\nconst WARN = 2;\r\nconst INFO = 3;\r\nconst DEBUG = 4;\r\n\r\nlet logger;\r\nlet level;\r\n\r\nexport class Log {\r\n    static get NONE() {return NONE};\r\n    static get ERROR() {return ERROR};\r\n    static get WARN() {return WARN};\r\n    static get INFO() {return INFO};\r\n    static get DEBUG() {return DEBUG};\r\n    \r\n    static reset(){\r\n        level = INFO;\r\n        logger = nopLogger;\r\n    }\r\n    \r\n    static get level(){\r\n        return level;\r\n    }\r\n    static set level(value){\r\n        if (NONE <= value && value <= DEBUG){\r\n            level = value;\r\n        }\r\n        else {\r\n            throw new Error(\"Invalid log level\");\r\n        }\r\n    }\r\n    \r\n    static get logger(){\r\n        return logger;\r\n    }\r\n    static set logger(value){\r\n        if (!value.debug && value.info) {\r\n            // just to stay backwards compat. can remove in 2.0\r\n            value.debug = value.info;\r\n        }\r\n\r\n        if (value.debug && value.info && value.warn && value.error){\r\n            logger = value;\r\n        }\r\n        else {\r\n            throw new Error(\"Invalid logger\");\r\n        }\r\n    }\r\n    \r\n    static debug(...args){\r\n        if (level >= DEBUG){\r\n            logger.debug.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static info(...args){\r\n        if (level >= INFO){\r\n            logger.info.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static warn(...args){\r\n        if (level >= WARN){\r\n            logger.warn.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n    static error(...args){\r\n        if (level >= ERROR){\r\n            logger.error.apply(logger, Array.from(args));\r\n        }\r\n    }\r\n}\r\n\r\nLog.reset();\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { JsonService } from './JsonService.js';\r\n\r\nconst OidcMetadataUrlPath = '.well-known/openid-configuration';\r\n\r\nexport class MetadataService {\r\n    constructor(settings, JsonServiceCtor = JsonService) {\r\n        if (!settings) {\r\n            Log.error(\"MetadataService: No settings passed to MetadataService\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor(['application/jwk-set+json']);\r\n    }\r\n\r\n    get metadataUrl() {\r\n        if (!this._metadataUrl) {\r\n            if (this._settings.metadataUrl) {\r\n                this._metadataUrl = this._settings.metadataUrl;\r\n            }\r\n            else {\r\n                this._metadataUrl = this._settings.authority;\r\n\r\n                if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\r\n                    if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\r\n                        this._metadataUrl += '/';\r\n                    }\r\n                    this._metadataUrl += OidcMetadataUrlPath;\r\n                }\r\n            }\r\n        }\r\n\r\n        return this._metadataUrl;\r\n    }\r\n\r\n    getMetadata() {\r\n        if (this._settings.metadata) {\r\n            Log.debug(\"MetadataService.getMetadata: Returning metadata from settings\");\r\n            return Promise.resolve(this._settings.metadata);\r\n        }\r\n\r\n        if (!this.metadataUrl) {\r\n            Log.error(\"MetadataService.getMetadata: No authority or metadataUrl configured on settings\");\r\n            return Promise.reject(new Error(\"No authority or metadataUrl configured on settings\"));\r\n        }\r\n\r\n        Log.debug(\"MetadataService.getMetadata: getting metadata from\", this.metadataUrl);\r\n\r\n        return this._jsonService.getJson(this.metadataUrl)\r\n            .then(metadata => {\r\n                Log.debug(\"MetadataService.getMetadata: json received\");\r\n                this._settings.metadata = metadata;\r\n                return metadata;\r\n            });\r\n    }\r\n\r\n    getIssuer() {\r\n        return this._getMetadataProperty(\"issuer\");\r\n    }\r\n\r\n    getAuthorizationEndpoint() {\r\n        return this._getMetadataProperty(\"authorization_endpoint\");\r\n    }\r\n\r\n    getUserInfoEndpoint() {\r\n        return this._getMetadataProperty(\"userinfo_endpoint\");\r\n    }\r\n\r\n    getTokenEndpoint(optional=true) {\r\n        return this._getMetadataProperty(\"token_endpoint\", optional);\r\n    }\r\n\r\n    getCheckSessionIframe() {\r\n        return this._getMetadataProperty(\"check_session_iframe\", true);\r\n    }\r\n\r\n    getEndSessionEndpoint() {\r\n        return this._getMetadataProperty(\"end_session_endpoint\", true);\r\n    }\r\n\r\n    getRevocationEndpoint() {\r\n        return this._getMetadataProperty(\"revocation_endpoint\", true);\r\n    }\r\n\r\n    getKeysEndpoint() {\r\n        return this._getMetadataProperty(\"jwks_uri\", true);\r\n    }\r\n\r\n    _getMetadataProperty(name, optional=false) {\r\n        Log.debug(\"MetadataService.getMetadataProperty for: \" + name);\r\n\r\n        return this.getMetadata().then(metadata => {\r\n            Log.debug(\"MetadataService.getMetadataProperty: metadata recieved\");\r\n\r\n            if (metadata[name] === undefined) {\r\n\r\n                if (optional === true) {\r\n                    Log.warn(\"MetadataService.getMetadataProperty: Metadata does not contain optional property \" + name);\r\n                    return undefined;\r\n                }\r\n                else {\r\n                    Log.error(\"MetadataService.getMetadataProperty: Metadata does not contain property \" + name);\r\n                    throw new Error(\"Metadata does not contain property \" + name);\r\n                }\r\n            }\r\n\r\n            return metadata[name];\r\n        });\r\n    }\r\n\r\n    getSigningKeys() {\r\n        if (this._settings.signingKeys) {\r\n            Log.debug(\"MetadataService.getSigningKeys: Returning signingKeys from settings\");\r\n            return Promise.resolve(this._settings.signingKeys);\r\n        }\r\n\r\n        return this._getMetadataProperty(\"jwks_uri\").then(jwks_uri => {\r\n            Log.debug(\"MetadataService.getSigningKeys: jwks_uri received\", jwks_uri);\r\n\r\n            return this._jsonService.getJson(jwks_uri).then(keySet => {\r\n                Log.debug(\"MetadataService.getSigningKeys: key set received\", keySet);\r\n\r\n                if (!keySet.keys) {\r\n                    Log.error(\"MetadataService.getSigningKeys: Missing keys on keyset\");\r\n                    throw new Error(\"Missing keys on keyset\");\r\n                }\r\n\r\n                this._settings.signingKeys = keySet.keys;\r\n                return this._settings.signingKeys;\r\n            });\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClientSettings } from './OidcClientSettings.js';\r\nimport { ErrorResponse } from './ErrorResponse.js';\r\nimport { SigninRequest } from './SigninRequest.js';\r\nimport { SigninResponse } from './SigninResponse.js';\r\nimport { SignoutRequest } from './SignoutRequest.js';\r\nimport { SignoutResponse } from './SignoutResponse.js';\r\nimport { SigninState } from './SigninState.js';\r\nimport { State } from './State.js';\r\n\r\nexport class OidcClient {\r\n    constructor(settings = {}) {\r\n        if (settings instanceof OidcClientSettings) {\r\n            this._settings = settings;\r\n        }\r\n        else {\r\n            this._settings = new OidcClientSettings(settings);\r\n        }\r\n    }\r\n\r\n    get _stateStore() {\r\n        return this.settings.stateStore;\r\n    }\r\n    get _validator() {\r\n        return this.settings.validator;\r\n    }\r\n    get _metadataService() {\r\n        return this.settings.metadataService;\r\n    }\r\n\r\n    get settings() {\r\n        return this._settings;\r\n    }\r\n    get metadataService() {\r\n        return this._metadataService;\r\n    }\r\n\r\n    createSigninRequest({\r\n        response_type, scope, redirect_uri,\r\n        // data was meant to be the place a caller could indicate the data to\r\n        // have round tripped, but people were getting confused, so i added state (since that matches the spec)\r\n        // and so now if data is not passed, but state is then state will be used\r\n        data, state, prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values,\r\n        resource, request, request_uri, response_mode, extraQueryParams, extraTokenParams, request_type, skipUserInfo } = {},\r\n        stateStore\r\n    ) {\r\n        Log.debug(\"OidcClient.createSigninRequest\");\r\n\r\n        let client_id = this._settings.client_id;\r\n        response_type = response_type || this._settings.response_type;\r\n        scope = scope || this._settings.scope;\r\n        redirect_uri = redirect_uri || this._settings.redirect_uri;\r\n\r\n        // id_token_hint, login_hint aren't allowed on _settings\r\n        prompt = prompt || this._settings.prompt;\r\n        display = display || this._settings.display;\r\n        max_age = max_age || this._settings.max_age;\r\n        ui_locales = ui_locales || this._settings.ui_locales;\r\n        acr_values = acr_values || this._settings.acr_values;\r\n        resource = resource || this._settings.resource;\r\n        response_mode = response_mode || this._settings.response_mode;\r\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\r\n        extraTokenParams = extraTokenParams || this._settings.extraTokenParams;\r\n\r\n        let authority = this._settings.authority;\r\n\r\n        if (SigninRequest.isCode(response_type) && response_type !== \"code\") {\r\n            return Promise.reject(new Error(\"OpenID Connect hybrid flow is not supported\"));\r\n        }\r\n\r\n        return this._metadataService.getAuthorizationEndpoint().then(url => {\r\n            Log.debug(\"OidcClient.createSigninRequest: Received authorization endpoint\", url);\r\n\r\n            let signinRequest = new SigninRequest({\r\n                url,\r\n                client_id,\r\n                redirect_uri,\r\n                response_type,\r\n                scope,\r\n                data: data || state,\r\n                authority,\r\n                prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values,\r\n                resource, request, request_uri, extraQueryParams, extraTokenParams, request_type, response_mode,\r\n                client_secret: this._settings.client_secret,\r\n                skipUserInfo\r\n            });\r\n\r\n            var signinState = signinRequest.state;\r\n            stateStore = stateStore || this._stateStore;\r\n\r\n            return stateStore.set(signinState.id, signinState.toStorageString()).then(() => {\r\n                return signinRequest;\r\n            });\r\n        });\r\n    }\r\n\r\n    readSigninResponseState(url, stateStore, removeState = false) {\r\n        Log.debug(\"OidcClient.readSigninResponseState\");\r\n\r\n        let useQuery = this._settings.response_mode === \"query\" || \r\n            (!this._settings.response_mode && SigninRequest.isCode(this._settings.response_type));\r\n        let delimiter = useQuery ? \"?\" : \"#\";\r\n\r\n        var response = new SigninResponse(url, delimiter);\r\n\r\n        if (!response.state) {\r\n            Log.error(\"OidcClient.readSigninResponseState: No state in response\");\r\n            return Promise.reject(new Error(\"No state in response\"));\r\n        }\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\r\n\r\n        return stateApi(response.state).then(storedStateString => {\r\n            if (!storedStateString) {\r\n                Log.error(\"OidcClient.readSigninResponseState: No matching state found in storage\");\r\n                throw new Error(\"No matching state found in storage\");\r\n            }\r\n\r\n            let state = SigninState.fromStorageString(storedStateString);\r\n            return {state, response};\r\n        });\r\n    }\r\n\r\n    processSigninResponse(url, stateStore) {\r\n        Log.debug(\"OidcClient.processSigninResponse\");\r\n\r\n        return this.readSigninResponseState(url, stateStore, true).then(({state, response}) => {\r\n            Log.debug(\"OidcClient.processSigninResponse: Received state from storage; validating response\");\r\n            return this._validator.validateSigninResponse(state, response);\r\n        });\r\n    }\r\n\r\n    createSignoutRequest({id_token_hint, data, state, post_logout_redirect_uri, extraQueryParams, request_type } = {},\r\n        stateStore\r\n    ) {\r\n        Log.debug(\"OidcClient.createSignoutRequest\");\r\n\r\n        post_logout_redirect_uri = post_logout_redirect_uri || this._settings.post_logout_redirect_uri;\r\n        extraQueryParams = extraQueryParams || this._settings.extraQueryParams;\r\n\r\n        return this._metadataService.getEndSessionEndpoint().then(url => {\r\n            if (!url) {\r\n                Log.error(\"OidcClient.createSignoutRequest: No end session endpoint url returned\");\r\n                throw new Error(\"no end session endpoint\");\r\n            }\r\n\r\n            Log.debug(\"OidcClient.createSignoutRequest: Received end session endpoint\", url);\r\n\r\n            let request = new SignoutRequest({\r\n                url,\r\n                id_token_hint,\r\n                post_logout_redirect_uri,\r\n                data: data || state,\r\n                extraQueryParams,\r\n                request_type\r\n            });\r\n\r\n            var signoutState = request.state;\r\n            if (signoutState) {\r\n                Log.debug(\"OidcClient.createSignoutRequest: Signout request has state to persist\");\r\n\r\n                stateStore = stateStore || this._stateStore;\r\n                stateStore.set(signoutState.id, signoutState.toStorageString());\r\n            }\r\n\r\n            return request;\r\n        });\r\n    }\r\n\r\n    readSignoutResponseState(url, stateStore, removeState = false) {\r\n        Log.debug(\"OidcClient.readSignoutResponseState\");\r\n\r\n        var response = new SignoutResponse(url);\r\n        if (!response.state) {\r\n            Log.debug(\"OidcClient.readSignoutResponseState: No state in response\");\r\n\r\n            if (response.error) {\r\n                Log.warn(\"OidcClient.readSignoutResponseState: Response was error: \", response.error);\r\n                return Promise.reject(new ErrorResponse(response));\r\n            }\r\n\r\n            return Promise.resolve({undefined, response});\r\n        }\r\n\r\n        var stateKey = response.state;\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        var stateApi = removeState ? stateStore.remove.bind(stateStore) : stateStore.get.bind(stateStore);\r\n        return stateApi(stateKey).then(storedStateString => {\r\n            if (!storedStateString) {\r\n                Log.error(\"OidcClient.readSignoutResponseState: No matching state found in storage\");\r\n                throw new Error(\"No matching state found in storage\");\r\n            }\r\n\r\n            let state = State.fromStorageString(storedStateString);\r\n\r\n            return {state, response};\r\n        });\r\n    }\r\n\r\n    processSignoutResponse(url, stateStore) {\r\n        Log.debug(\"OidcClient.processSignoutResponse\");\r\n\r\n        return this.readSignoutResponseState(url, stateStore, true).then(({state, response}) => {\r\n            if (state) {\r\n                Log.debug(\"OidcClient.processSignoutResponse: Received state from storage; validating response\");\r\n                return this._validator.validateSignoutResponse(state, response);\r\n            }\r\n            else {\r\n                Log.debug(\"OidcClient.processSignoutResponse: No state from storage; skipping validating response\");\r\n                return response;\r\n            }\r\n        });\r\n    }\r\n\r\n    clearStaleState(stateStore) {\r\n        Log.debug(\"OidcClient.clearStaleState\");\r\n\r\n        stateStore = stateStore || this._stateStore;\r\n\r\n        return State.clearStaleState(stateStore, this.settings.staleStateAge);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { WebStorageStateStore } from './WebStorageStateStore.js';\r\nimport { ResponseValidator } from './ResponseValidator.js';\r\nimport { MetadataService } from './MetadataService.js';\r\n\r\nconst OidcMetadataUrlPath = '.well-known/openid-configuration';\r\n\r\nconst DefaultResponseType = \"id_token\";\r\nconst DefaultScope = \"openid\";\r\nconst DefaultStaleStateAge = 60 * 15; // seconds\r\nconst DefaultClockSkewInSeconds = 60 * 5;\r\n\r\nexport class OidcClientSettings {\r\n    constructor({\r\n        // metadata related\r\n        authority, metadataUrl, metadata, signingKeys,\r\n        // client related\r\n        client_id, client_secret, response_type = DefaultResponseType, scope = DefaultScope,\r\n        redirect_uri, post_logout_redirect_uri,\r\n        // optional protocol\r\n        prompt, display, max_age, ui_locales, acr_values, resource, response_mode,\r\n        // behavior flags\r\n        filterProtocolClaims = true, loadUserInfo = true,\r\n        staleStateAge = DefaultStaleStateAge, clockSkew = DefaultClockSkewInSeconds,\r\n        userInfoJwtIssuer = 'OP',\r\n        // other behavior\r\n        stateStore = new WebStorageStateStore(),\r\n        ResponseValidatorCtor = ResponseValidator,\r\n        MetadataServiceCtor = MetadataService,\r\n        // extra query params\r\n        extraQueryParams = {},\r\n        extraTokenParams = {}\r\n    } = {}) {\r\n\r\n        this._authority = authority;\r\n        this._metadataUrl = metadataUrl;\r\n        this._metadata = metadata;\r\n        this._signingKeys = signingKeys;\r\n\r\n        this._client_id = client_id;\r\n        this._client_secret = client_secret;\r\n        this._response_type = response_type;\r\n        this._scope = scope;\r\n        this._redirect_uri = redirect_uri;\r\n        this._post_logout_redirect_uri = post_logout_redirect_uri;\r\n\r\n        this._prompt = prompt;\r\n        this._display = display;\r\n        this._max_age = max_age;\r\n        this._ui_locales = ui_locales;\r\n        this._acr_values = acr_values;\r\n        this._resource = resource;\r\n        this._response_mode = response_mode;\r\n\r\n        this._filterProtocolClaims = !!filterProtocolClaims;\r\n        this._loadUserInfo = !!loadUserInfo;\r\n        this._staleStateAge = staleStateAge;\r\n        this._clockSkew = clockSkew;\r\n        this._userInfoJwtIssuer = userInfoJwtIssuer;\r\n\r\n        this._stateStore = stateStore;\r\n        this._validator = new ResponseValidatorCtor(this);\r\n        this._metadataService = new MetadataServiceCtor(this);\r\n\r\n        this._extraQueryParams = typeof extraQueryParams === 'object' ? extraQueryParams : {};\r\n        this._extraTokenParams = typeof extraTokenParams === 'object' ? extraTokenParams : {};\r\n    }\r\n\r\n    // client config\r\n    get client_id() {\r\n        return this._client_id;\r\n    }\r\n    set client_id(value) {\r\n        if (!this._client_id) {\r\n            // one-time set only\r\n            this._client_id = value;\r\n        }\r\n        else {\r\n            Log.error(\"OidcClientSettings.set_client_id: client_id has already been assigned.\")\r\n            throw new Error(\"client_id has already been assigned.\")\r\n        }\r\n    }\r\n    get client_secret() {\r\n        return this._client_secret;\r\n    }\r\n    get response_type() {\r\n        return this._response_type;\r\n    }\r\n    get scope() {\r\n        return this._scope;\r\n    }\r\n    get redirect_uri() {\r\n        return this._redirect_uri;\r\n    }\r\n    get post_logout_redirect_uri() {\r\n        return this._post_logout_redirect_uri;\r\n    }\r\n\r\n\r\n    // optional protocol params\r\n    get prompt() {\r\n        return this._prompt;\r\n    }\r\n    get display() {\r\n        return this._display;\r\n    }\r\n    get max_age() {\r\n        return this._max_age;\r\n    }\r\n    get ui_locales() {\r\n        return this._ui_locales;\r\n    }\r\n    get acr_values() {\r\n        return this._acr_values;\r\n    }\r\n    get resource() {\r\n        return this._resource;\r\n    }\r\n    get response_mode() {\r\n        return this._response_mode;\r\n    }\r\n\r\n\r\n    // metadata\r\n    get authority() {\r\n        return this._authority;\r\n    }\r\n    set authority(value) {\r\n        if (!this._authority) {\r\n            // one-time set only\r\n            this._authority = value;\r\n        }\r\n        else {\r\n            Log.error(\"OidcClientSettings.set_authority: authority has already been assigned.\")\r\n            throw new Error(\"authority has already been assigned.\")\r\n        }\r\n    }\r\n    get metadataUrl() {\r\n        if (!this._metadataUrl) {\r\n            this._metadataUrl = this.authority;\r\n\r\n            if (this._metadataUrl && this._metadataUrl.indexOf(OidcMetadataUrlPath) < 0) {\r\n                if (this._metadataUrl[this._metadataUrl.length - 1] !== '/') {\r\n                    this._metadataUrl += '/';\r\n                }\r\n                this._metadataUrl += OidcMetadataUrlPath;\r\n            }\r\n        }\r\n\r\n        return this._metadataUrl;\r\n    }\r\n\r\n    // settable/cachable metadata values\r\n    get metadata() {\r\n        return this._metadata;\r\n    }\r\n    set metadata(value) {\r\n        this._metadata = value;\r\n    }\r\n\r\n    get signingKeys() {\r\n        return this._signingKeys;\r\n    }\r\n    set signingKeys(value) {\r\n        this._signingKeys = value;\r\n    }\r\n\r\n    // behavior flags\r\n    get filterProtocolClaims() {\r\n        return this._filterProtocolClaims;\r\n    }\r\n    get loadUserInfo() {\r\n        return this._loadUserInfo;\r\n    }\r\n    get staleStateAge() {\r\n        return this._staleStateAge;\r\n    }\r\n    get clockSkew() {\r\n        return this._clockSkew;\r\n    }\r\n    get userInfoJwtIssuer() {\r\n        return this._userInfoJwtIssuer;\r\n    }\r\n\r\n    get stateStore() {\r\n        return this._stateStore;\r\n    }\r\n    get validator() {\r\n        return this._validator;\r\n    }\r\n    get metadataService() {\r\n        return this._metadataService;\r\n    }\r\n\r\n    // extra query params\r\n    get extraQueryParams() {\r\n        return this._extraQueryParams;\r\n    }\r\n    set extraQueryParams(value) {\r\n        if (typeof value === 'object'){\r\n            this._extraQueryParams = value;\r\n        } else {\r\n            this._extraQueryParams = {};\r\n        }\r\n    }\r\n\r\n    // extra token params\r\n    get extraTokenParams() {\r\n        return this._extraTokenParams;\r\n    }\r\n    set extraTokenParams(value) {\r\n        if (typeof value === 'object'){\r\n            this._extraTokenParams = value;\r\n        } else {\r\n            this._extraTokenParams = {};\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { PopupWindow } from './PopupWindow.js';\r\n\r\nexport class PopupNavigator {\r\n\r\n    prepare(params) {\r\n        let popup = new PopupWindow(params);\r\n        return Promise.resolve(popup);\r\n    }\r\n\r\n    callback(url, keepOpen, delimiter) {\r\n        Log.debug(\"PopupNavigator.callback\");\r\n\r\n        try {\r\n            PopupWindow.notifyOpener(url, keepOpen, delimiter);\r\n            return Promise.resolve();\r\n        }\r\n        catch (e) {\r\n            return Promise.reject(e);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nconst CheckForPopupClosedInterval = 500;\r\nconst DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;';\r\n//const DefaultPopupFeatures = 'location=no,toolbar=no,width=500,height=500,left=100,top=100;resizable=yes';\r\n\r\nconst DefaultPopupTarget = \"_blank\";\r\n\r\nexport class PopupWindow {\r\n\r\n    constructor(params) {\r\n        this._promise = new Promise((resolve, reject) => {\r\n            this._resolve = resolve;\r\n            this._reject = reject;\r\n        });\r\n\r\n        let target = params.popupWindowTarget || DefaultPopupTarget;\r\n        let features = params.popupWindowFeatures || DefaultPopupFeatures;\r\n\r\n        this._popup = window.open('', target, features);\r\n        if (this._popup) {\r\n            Log.debug(\"PopupWindow.ctor: popup successfully created\");\r\n            this._checkForPopupClosedTimer = window.setInterval(this._checkForPopupClosed.bind(this), CheckForPopupClosedInterval);\r\n        }\r\n    }\r\n\r\n    get promise() {\r\n        return this._promise;\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!this._popup) {\r\n            this._error(\"PopupWindow.navigate: Error opening popup window\");\r\n        }\r\n        else if (!params || !params.url) {\r\n            this._error(\"PopupWindow.navigate: no url provided\");\r\n            this._error(\"No url provided\");\r\n        }\r\n        else {\r\n            Log.debug(\"PopupWindow.navigate: Setting URL in popup\");\r\n\r\n            this._id = params.id;\r\n            if (this._id) {\r\n                window[\"popupCallback_\" + params.id] = this._callback.bind(this);\r\n            }\r\n\r\n            this._popup.focus();\r\n            this._popup.window.location = params.url;\r\n        }\r\n\r\n        return this.promise;\r\n    }\r\n\r\n    _success(data) {\r\n        Log.debug(\"PopupWindow.callback: Successful response from popup window\");\r\n\r\n        this._cleanup();\r\n        this._resolve(data);\r\n    }\r\n    _error(message) {\r\n        Log.error(\"PopupWindow.error: \", message);\r\n        \r\n        this._cleanup();\r\n        this._reject(new Error(message));\r\n    }\r\n\r\n    close() {\r\n        this._cleanup(false);\r\n    }\r\n\r\n    _cleanup(keepOpen) {\r\n        Log.debug(\"PopupWindow.cleanup\");\r\n\r\n        window.clearInterval(this._checkForPopupClosedTimer);\r\n        this._checkForPopupClosedTimer = null;\r\n\r\n        delete window[\"popupCallback_\" + this._id];\r\n\r\n        if (this._popup && !keepOpen) {\r\n            this._popup.close();\r\n        }\r\n        this._popup = null;\r\n    }\r\n\r\n    _checkForPopupClosed() {\r\n        if (!this._popup || this._popup.closed) {\r\n            this._error(\"Popup window closed\");\r\n        }\r\n    }\r\n\r\n    _callback(url, keepOpen) {\r\n        this._cleanup(keepOpen);\r\n\r\n        if (url) {\r\n            Log.debug(\"PopupWindow.callback success\");\r\n            this._success({ url: url });\r\n        }\r\n        else {\r\n            Log.debug(\"PopupWindow.callback: Invalid response from popup\");\r\n            this._error(\"Invalid response from popup\");\r\n        }\r\n    }\r\n\r\n    static notifyOpener(url, keepOpen, delimiter) {\r\n        if (window.opener) {\r\n            url = url || window.location.href;\r\n            if (url) {\r\n                var data = UrlUtility.parseUrlFragment(url, delimiter);\r\n\r\n                if (data.state) {\r\n                    var name = \"popupCallback_\" + data.state;\r\n                    var callback = window.opener[name];\r\n                    if (callback) {\r\n                        Log.debug(\"PopupWindow.notifyOpener: passing url message to opener\");\r\n                        callback(url, keepOpen);\r\n                    }\r\n                    else {\r\n                        Log.warn(\"PopupWindow.notifyOpener: no matching callback found on opener\");\r\n                    }\r\n                }\r\n                else {\r\n                    Log.warn(\"PopupWindow.notifyOpener: no state found in response url\");\r\n                }\r\n            }\r\n        }\r\n        else {\r\n            Log.warn(\"PopupWindow.notifyOpener: no window.opener. Can't complete notification.\");\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class RedirectNavigator {\r\n\r\n    prepare() {\r\n        return Promise.resolve(this);\r\n    }\r\n\r\n    navigate(params) {\r\n        if (!params || !params.url) {\r\n            Log.error(\"RedirectNavigator.navigate: No url provided\");\r\n            return Promise.reject(new Error(\"No url provided\"));\r\n        }\r\n\r\n        if (params.useReplaceToNavigate) {\r\n            window.location.replace(params.url);\r\n        }\r\n        else {\r\n            window.location = params.url;\r\n        }\r\n\r\n        return Promise.resolve();\r\n    }\r\n\r\n    get url() {\r\n        return window.location.href;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { UserInfoService } from './UserInfoService.js';\r\nimport { TokenClient } from './TokenClient.js';\r\nimport { ErrorResponse } from './ErrorResponse.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\nconst ProtocolClaims = [\"nonce\", \"at_hash\", \"iat\", \"nbf\", \"exp\", \"aud\", \"iss\", \"c_hash\"];\r\n\r\nexport class ResponseValidator {\r\n\r\n    constructor(settings, \r\n        MetadataServiceCtor = MetadataService,\r\n        UserInfoServiceCtor = UserInfoService, \r\n        joseUtil = JoseUtil,\r\n        TokenClientCtor = TokenClient) {\r\n        if (!settings) {\r\n            Log.error(\"ResponseValidator.ctor: No settings passed to ResponseValidator\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n        this._userInfoService = new UserInfoServiceCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n        this._tokenClient = new TokenClientCtor(this._settings);\r\n    }\r\n\r\n    validateSigninResponse(state, response) {\r\n        Log.debug(\"ResponseValidator.validateSigninResponse\");\r\n\r\n        return this._processSigninParams(state, response).then(response => {\r\n            Log.debug(\"ResponseValidator.validateSigninResponse: state processed\");\r\n            return this._validateTokens(state, response).then(response => {\r\n                Log.debug(\"ResponseValidator.validateSigninResponse: tokens validated\");\r\n                return this._processClaims(state, response).then(response => {\r\n                    Log.debug(\"ResponseValidator.validateSigninResponse: claims processed\");\r\n                    return response;\r\n                });\r\n            });\r\n        });\r\n    }\r\n\r\n    validateSignoutResponse(state, response) {\r\n        if (state.id !== response.state) {\r\n            Log.error(\"ResponseValidator.validateSignoutResponse: State does not match\");\r\n            return Promise.reject(new Error(\"State does not match\"));\r\n        }\r\n\r\n        // now that we know the state matches, take the stored data\r\n        // and set it into the response so callers can get their state\r\n        // this is important for both success & error outcomes\r\n        Log.debug(\"ResponseValidator.validateSignoutResponse: state validated\");\r\n        response.state = state.data;\r\n\r\n        if (response.error) {\r\n            Log.warn(\"ResponseValidator.validateSignoutResponse: Response was error\", response.error);\r\n            return Promise.reject(new ErrorResponse(response));\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processSigninParams(state, response) {\r\n        if (state.id !== response.state) {\r\n            Log.error(\"ResponseValidator._processSigninParams: State does not match\");\r\n            return Promise.reject(new Error(\"State does not match\"));\r\n        }\r\n\r\n        if (!state.client_id) {\r\n            Log.error(\"ResponseValidator._processSigninParams: No client_id on state\");\r\n            return Promise.reject(new Error(\"No client_id on state\"));\r\n        }\r\n\r\n        if (!state.authority) {\r\n            Log.error(\"ResponseValidator._processSigninParams: No authority on state\");\r\n            return Promise.reject(new Error(\"No authority on state\"));\r\n        }\r\n\r\n        // this allows the authority to be loaded from the signin state\r\n        if (!this._settings.authority) {\r\n            this._settings.authority = state.authority;\r\n        }\r\n        // ensure we're using the correct authority if the authority is not loaded from signin state\r\n        else if (this._settings.authority && this._settings.authority !== state.authority) {\r\n            Log.error(\"ResponseValidator._processSigninParams: authority mismatch on settings vs. signin state\");\r\n            return Promise.reject(new Error(\"authority mismatch on settings vs. signin state\"));\r\n        }\r\n        // this allows the client_id to be loaded from the signin state\r\n        if (!this._settings.client_id) {\r\n            this._settings.client_id = state.client_id;\r\n        }\r\n        // ensure we're using the correct client_id if the client_id is not loaded from signin state\r\n        else if (this._settings.client_id && this._settings.client_id !== state.client_id) {\r\n            Log.error(\"ResponseValidator._processSigninParams: client_id mismatch on settings vs. signin state\");\r\n            return Promise.reject(new Error(\"client_id mismatch on settings vs. signin state\"));\r\n        }\r\n\r\n        // now that we know the state matches, take the stored data\r\n        // and set it into the response so callers can get their state\r\n        // this is important for both success & error outcomes\r\n        Log.debug(\"ResponseValidator._processSigninParams: state validated\");\r\n        response.state = state.data;\r\n\r\n        if (response.error) {\r\n            Log.warn(\"ResponseValidator._processSigninParams: Response was error\", response.error);\r\n            return Promise.reject(new ErrorResponse(response));\r\n        }\r\n\r\n        if (state.nonce && !response.id_token) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Expecting id_token in response\");\r\n            return Promise.reject(new Error(\"No id_token in response\"));\r\n        }\r\n\r\n        if (!state.nonce && response.id_token) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Not expecting id_token in response\");\r\n            return Promise.reject(new Error(\"Unexpected id_token in response\"));\r\n        }\r\n\r\n        if (state.code_verifier && !response.code) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Expecting code in response\");\r\n            return Promise.reject(new Error(\"No code in response\"));\r\n        }\r\n\r\n        if (!state.code_verifier && response.code) {\r\n            Log.error(\"ResponseValidator._processSigninParams: Not expecting code in response\");\r\n            return Promise.reject(new Error(\"Unexpected code in response\"));\r\n        }\r\n\r\n        if (!response.scope) {\r\n            // if there's no scope on the response, then assume all scopes granted (per-spec) and copy over scopes from original request\r\n            response.scope = state.scope;\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processClaims(state, response) {\r\n        if (response.isOpenIdConnect) {\r\n            Log.debug(\"ResponseValidator._processClaims: response is OIDC, processing claims\");\r\n\r\n            response.profile = this._filterProtocolClaims(response.profile);\r\n\r\n            if (state.skipUserInfo !== true && this._settings.loadUserInfo && response.access_token) {\r\n                Log.debug(\"ResponseValidator._processClaims: loading user info\");\r\n\r\n                return this._userInfoService.getClaims(response.access_token).then(claims => {\r\n                    Log.debug(\"ResponseValidator._processClaims: user info claims received from user info endpoint\");\r\n\r\n                    if (claims.sub !== response.profile.sub) {\r\n                        Log.error(\"ResponseValidator._processClaims: sub from user info endpoint does not match sub in access_token\");\r\n                        return Promise.reject(new Error(\"sub from user info endpoint does not match sub in access_token\"));\r\n                    }\r\n\r\n                    response.profile = this._mergeClaims(response.profile, claims);\r\n                    Log.debug(\"ResponseValidator._processClaims: user info claims received, updated profile:\", response.profile);\r\n\r\n                    return response;\r\n                });\r\n            }\r\n            else {\r\n                Log.debug(\"ResponseValidator._processClaims: not loading user info\");\r\n            }\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._processClaims: response is not OIDC, not processing claims\");\r\n        }\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _mergeClaims(claims1, claims2) {\r\n        var result = Object.assign({}, claims1);\r\n\r\n        for (let name in claims2) {\r\n            var values = claims2[name];\r\n            if (!Array.isArray(values)) {\r\n                values = [values];\r\n            }\r\n\r\n            for (let i = 0; i < values.length; i++) {\r\n                let value = values[i];\r\n                if (!result[name]) {\r\n                    result[name] = value;\r\n                }\r\n                else if (Array.isArray(result[name])) {\r\n                    if (result[name].indexOf(value) < 0) {\r\n                        result[name].push(value);\r\n                    }\r\n                }\r\n                else if (result[name] !== value) {\r\n                    if (typeof value === 'object') {\r\n                        result[name] = this._mergeClaims(result[name], value);\r\n                    } \r\n                    else {\r\n                        result[name] = [result[name], value];\r\n                    }\r\n                }\r\n            }\r\n        }\r\n\r\n        return result;\r\n    }\r\n\r\n    _filterProtocolClaims(claims) {\r\n        Log.debug(\"ResponseValidator._filterProtocolClaims, incoming claims:\", claims);\r\n\r\n        var result = Object.assign({}, claims);\r\n\r\n        if (this._settings._filterProtocolClaims) {\r\n            ProtocolClaims.forEach(type => {\r\n                delete result[type];\r\n            });\r\n\r\n            Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims filtered\", result);\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._filterProtocolClaims: protocol claims not filtered\")\r\n        }\r\n\r\n        return result;\r\n    }\r\n\r\n    _validateTokens(state, response) {\r\n        if (response.code) {\r\n            Log.debug(\"ResponseValidator._validateTokens: Validating code\");\r\n            return this._processCode(state, response);\r\n        }\r\n\r\n        if (response.id_token) {\r\n            if (response.access_token) {\r\n                Log.debug(\"ResponseValidator._validateTokens: Validating id_token and access_token\");\r\n                return this._validateIdTokenAndAccessToken(state, response);\r\n            }\r\n\r\n            Log.debug(\"ResponseValidator._validateTokens: Validating id_token\");\r\n            return this._validateIdToken(state, response);\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._validateTokens: No code to process or id_token to validate\");\r\n        return Promise.resolve(response);\r\n    }\r\n\r\n    _processCode(state, response) {\r\n        var request = {\r\n            client_id: state.client_id,\r\n            client_secret: state.client_secret,\r\n            code : response.code,\r\n            redirect_uri: state.redirect_uri,\r\n            code_verifier: state.code_verifier\r\n        };\r\n\r\n        if (state.extraTokenParams && typeof(state.extraTokenParams) === 'object') {\r\n            Object.assign(request, state.extraTokenParams);\r\n        }\r\n        \r\n        return this._tokenClient.exchangeCode(request).then(tokenResponse => {\r\n            \r\n            for(var key in tokenResponse) {\r\n                response[key] = tokenResponse[key];\r\n            }\r\n\r\n            if (response.id_token) {\r\n                Log.debug(\"ResponseValidator._processCode: token response successful, processing id_token\");\r\n                return this._validateIdTokenAttributes(state, response);\r\n            }\r\n            else {\r\n                Log.debug(\"ResponseValidator._processCode: token response successful, returning response\");\r\n            }\r\n            \r\n            return response;\r\n        });\r\n    }\r\n\r\n    _validateIdTokenAttributes(state, response) {\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n\r\n            let audience = state.client_id;\r\n            let clockSkewInSeconds = this._settings.clockSkew;\r\n            Log.debug(\"ResponseValidator._validateIdTokenAttributes: Validaing JWT attributes; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n            return this._joseUtil.validateJwtAttributes(response.id_token, issuer, audience, clockSkewInSeconds).then(payload => {\r\n            \r\n                if (state.nonce && state.nonce !== payload.nonce) {\r\n                    Log.error(\"ResponseValidator._validateIdTokenAttributes: Invalid nonce in id_token\");\r\n                    return Promise.reject(new Error(\"Invalid nonce in id_token\"));\r\n                }\r\n\r\n                if (!payload.sub) {\r\n                    Log.error(\"ResponseValidator._validateIdTokenAttributes: No sub present in id_token\");\r\n                    return Promise.reject(new Error(\"No sub present in id_token\"));\r\n                }\r\n\r\n                response.profile = payload;\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n\r\n    _validateIdTokenAndAccessToken(state, response) {\r\n        return this._validateIdToken(state, response).then(response => {\r\n            return this._validateAccessToken(response);\r\n        });\r\n    }\r\n\r\n    _validateIdToken(state, response) {\r\n        if (!state.nonce) {\r\n            Log.error(\"ResponseValidator._validateIdToken: No nonce on state\");\r\n            return Promise.reject(new Error(\"No nonce on state\"));\r\n        }\r\n\r\n        let jwt = this._joseUtil.parseJwt(response.id_token);\r\n        if (!jwt || !jwt.header || !jwt.payload) {\r\n            Log.error(\"ResponseValidator._validateIdToken: Failed to parse id_token\", jwt);\r\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n        }\r\n\r\n        if (state.nonce !== jwt.payload.nonce) {\r\n            Log.error(\"ResponseValidator._validateIdToken: Invalid nonce in id_token\");\r\n            return Promise.reject(new Error(\"Invalid nonce in id_token\"));\r\n        }\r\n\r\n        var kid = jwt.header.kid;\r\n\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n            Log.debug(\"ResponseValidator._validateIdToken: Received issuer\");\r\n\r\n            return this._metadataService.getSigningKeys().then(keys => {\r\n                if (!keys) {\r\n                    Log.error(\"ResponseValidator._validateIdToken: No signing keys from metadata\");\r\n                    return Promise.reject(new Error(\"No signing keys from metadata\"));\r\n                }\r\n\r\n                Log.debug(\"ResponseValidator._validateIdToken: Received signing keys\");\r\n                let key;\r\n                if (!kid) {\r\n                    keys = this._filterByAlg(keys, jwt.header.alg);\r\n\r\n                    if (keys.length > 1) {\r\n                        Log.error(\"ResponseValidator._validateIdToken: No kid found in id_token and more than one key found in metadata\");\r\n                        return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\r\n                    }\r\n                    else {\r\n                        // kid is mandatory only when there are multiple keys in the referenced JWK Set document\r\n                        // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\r\n                        key = keys[0];\r\n                    }\r\n                }\r\n                else {\r\n                    key = keys.filter(key => {\r\n                        return key.kid === kid;\r\n                    })[0];\r\n                }\r\n\r\n                if (!key) {\r\n                    Log.error(\"ResponseValidator._validateIdToken: No key matching kid or alg found in signing keys\");\r\n                    return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\r\n                }\r\n\r\n                let audience = state.client_id;\r\n\r\n                let clockSkewInSeconds = this._settings.clockSkew;\r\n                Log.debug(\"ResponseValidator._validateIdToken: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n                return this._joseUtil.validateJwt(response.id_token, key, issuer, audience, clockSkewInSeconds).then(()=>{\r\n                    Log.debug(\"ResponseValidator._validateIdToken: JWT validation successful\");\r\n\r\n                    if (!jwt.payload.sub) {\r\n                        Log.error(\"ResponseValidator._validateIdToken: No sub present in id_token\");\r\n                        return Promise.reject(new Error(\"No sub present in id_token\"));\r\n                    }\r\n\r\n                    response.profile = jwt.payload;\r\n\r\n                    return response;\r\n                });\r\n            });\r\n        });\r\n    }\r\n\r\n    _filterByAlg(keys, alg){\r\n        var kty = null;\r\n        if (alg.startsWith(\"RS\")) {\r\n            kty = \"RSA\";\r\n        }\r\n        else if (alg.startsWith(\"PS\")) {\r\n            kty = \"PS\";\r\n        }\r\n        else if (alg.startsWith(\"ES\")) {\r\n            kty = \"EC\";\r\n        }\r\n        else {\r\n            Log.debug(\"ResponseValidator._filterByAlg: alg not supported: \", alg);\r\n            return [];\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._filterByAlg: Looking for keys that match kty: \", kty);\r\n\r\n        keys = keys.filter(key => {\r\n            return key.kty === kty;\r\n        });\r\n\r\n        Log.debug(\"ResponseValidator._filterByAlg: Number of keys that match kty: \", kty, keys.length);\r\n\r\n        return keys;\r\n    }\r\n\r\n    _validateAccessToken(response) {\r\n        if (!response.profile) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No profile loaded from id_token\");\r\n            return Promise.reject(new Error(\"No profile loaded from id_token\"));\r\n        }\r\n\r\n        if (!response.profile.at_hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No at_hash in id_token\");\r\n            return Promise.reject(new Error(\"No at_hash in id_token\"));\r\n        }\r\n\r\n        if (!response.id_token) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: No id_token\");\r\n            return Promise.reject(new Error(\"No id_token\"));\r\n        }\r\n\r\n        let jwt = this._joseUtil.parseJwt(response.id_token);\r\n        if (!jwt || !jwt.header) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Failed to parse id_token\", jwt);\r\n            return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n        }\r\n\r\n        var hashAlg = jwt.header.alg;\r\n        if (!hashAlg || hashAlg.length !== 5) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        var hashBits = hashAlg.substr(2, 3);\r\n        if (!hashBits) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        hashBits = parseInt(hashBits);\r\n        if (hashBits !== 256 && hashBits !== 384 && hashBits !== 512) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Unsupported alg:\", hashAlg, hashBits);\r\n            return Promise.reject(new Error(\"Unsupported alg: \" + hashAlg));\r\n        }\r\n\r\n        let sha = \"sha\" + hashBits;\r\n        var hash = this._joseUtil.hashString(response.access_token, sha);\r\n        if (!hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: access_token hash failed:\", sha);\r\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\r\n        }\r\n\r\n        var left = hash.substr(0, hash.length / 2);\r\n        var left_b64u = this._joseUtil.hexToBase64Url(left);\r\n        if (left_b64u !== response.profile.at_hash) {\r\n            Log.error(\"ResponseValidator._validateAccessToken: Failed to validate at_hash\", left_b64u, response.profile.at_hash);\r\n            return Promise.reject(new Error(\"Failed to validate at_hash\"));\r\n        }\r\n\r\n        Log.debug(\"ResponseValidator._validateAccessToken: success\");\r\n\r\n        return Promise.resolve(response);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { CheckSessionIFrame } from './CheckSessionIFrame.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class SessionMonitor {\r\n\r\n    constructor(userManager, CheckSessionIFrameCtor = CheckSessionIFrame, timer = Global.timer) {\r\n        if (!userManager) {\r\n            Log.error(\"SessionMonitor.ctor: No user manager passed to SessionMonitor\");\r\n            throw new Error(\"userManager\");\r\n        }\r\n\r\n        this._userManager = userManager;\r\n        this._CheckSessionIFrameCtor = CheckSessionIFrameCtor;\r\n        this._timer = timer;\r\n\r\n        this._userManager.events.addUserLoaded(this._start.bind(this));\r\n        this._userManager.events.addUserUnloaded(this._stop.bind(this));\r\n\r\n        this._userManager.getUser().then(user => {\r\n            // doing this manually here since calling getUser \r\n            // doesn't trigger load event.\r\n            if (user) {\r\n                this._start(user);\r\n            }\r\n            else if (this._settings.monitorAnonymousSession) {\r\n                this._userManager.querySessionStatus().then(session => {\r\n                    let tmpUser = {\r\n                        session_state : session.session_state\r\n                    };\r\n                    if (session.sub && session.sid) {\r\n                        tmpUser.profile = {\r\n                            sub: session.sub,\r\n                            sid: session.sid\r\n                        };\r\n                    }\r\n                    this._start(tmpUser);\r\n                })\r\n                .catch(err => {\r\n                    // catch to suppress errors since we're in a ctor\r\n                    Log.error(\"SessionMonitor ctor: error from querySessionStatus:\", err.message);\r\n                });\r\n            }\r\n        }).catch(err => {\r\n            // catch to suppress errors since we're in a ctor\r\n            Log.error(\"SessionMonitor ctor: error from getUser:\", err.message);\r\n        });\r\n    }\r\n\r\n    get _settings() {\r\n        return this._userManager.settings;\r\n    }\r\n    get _metadataService() {\r\n        return this._userManager.metadataService;\r\n    }\r\n    get _client_id() {\r\n        return this._settings.client_id;\r\n    }\r\n    get _checkSessionInterval() {\r\n        return this._settings.checkSessionInterval;\r\n    }\r\n    get _stopCheckSessionOnError() {\r\n        return this._settings.stopCheckSessionOnError;\r\n    }\r\n\r\n    _start(user) {\r\n        let session_state = user.session_state;\r\n\r\n        if (session_state) {\r\n            if (user.profile) {\r\n                this._sub = user.profile.sub;\r\n                this._sid = user.profile.sid;\r\n                Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", sub:\", this._sub);\r\n            }\r\n            else {\r\n                this._sub = undefined;\r\n                this._sid = undefined;\r\n                Log.debug(\"SessionMonitor._start: session_state:\", session_state, \", anonymous user\");\r\n            }\r\n\r\n            if (!this._checkSessionIFrame) {\r\n                this._metadataService.getCheckSessionIframe().then(url => {\r\n                    if (url) {\r\n                        Log.debug(\"SessionMonitor._start: Initializing check session iframe\")\r\n\r\n                        let client_id = this._client_id;\r\n                        let interval = this._checkSessionInterval;\r\n                        let stopOnError = this._stopCheckSessionOnError;\r\n\r\n                        this._checkSessionIFrame = new this._CheckSessionIFrameCtor(this._callback.bind(this), client_id, url, interval, stopOnError);\r\n                        this._checkSessionIFrame.load().then(() => {\r\n                            this._checkSessionIFrame.start(session_state);\r\n                        });\r\n                    }\r\n                    else {\r\n                        Log.warn(\"SessionMonitor._start: No check session iframe found in the metadata\");\r\n                    }\r\n                }).catch(err => {\r\n                    // catch to suppress errors since we're in non-promise callback\r\n                    Log.error(\"SessionMonitor._start: Error from getCheckSessionIframe:\", err.message);\r\n                });\r\n            }\r\n            else {\r\n                this._checkSessionIFrame.start(session_state);\r\n            }\r\n        }\r\n    }\r\n\r\n    _stop() {\r\n        this._sub = undefined;\r\n        this._sid = undefined;\r\n\r\n        if (this._checkSessionIFrame) {\r\n            Log.debug(\"SessionMonitor._stop\");\r\n            this._checkSessionIFrame.stop();\r\n        }\r\n\r\n        if (this._settings.monitorAnonymousSession) {\r\n            // using a timer to delay re-initialization to avoid race conditions during signout\r\n            let timerHandle = this._timer.setInterval(()=>{\r\n                this._timer.clearInterval(timerHandle);\r\n\r\n                this._userManager.querySessionStatus().then(session => {\r\n                    let tmpUser = {\r\n                        session_state : session.session_state\r\n                    };\r\n                    if (session.sub && session.sid) {\r\n                        tmpUser.profile = {\r\n                            sub: session.sub,\r\n                            sid: session.sid\r\n                        };\r\n                    }\r\n                    this._start(tmpUser);\r\n                })\r\n                .catch(err => {\r\n                    // catch to suppress errors since we're in a callback\r\n                    Log.error(\"SessionMonitor: error from querySessionStatus:\", err.message);\r\n                });\r\n\r\n            }, 1000);\r\n        }\r\n    }\r\n\r\n    _callback() {\r\n        this._userManager.querySessionStatus().then(session => {\r\n            var raiseEvent = true;\r\n\r\n            if (session) {\r\n                if (session.sub === this._sub) {\r\n                    raiseEvent = false;\r\n                    this._checkSessionIFrame.start(session.session_state);\r\n\r\n                    if (session.sid === this._sid) {\r\n                        Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, restarting check session iframe; session_state:\", session.session_state);\r\n                    }\r\n                    else {\r\n                        Log.debug(\"SessionMonitor._callback: Same sub still logged in at OP, session state has changed, restarting check session iframe; session_state:\", session.session_state);\r\n                        this._userManager.events._raiseUserSessionChanged();\r\n                    }\r\n                }\r\n                else {\r\n                    Log.debug(\"SessionMonitor._callback: Different subject signed into OP:\", session.sub);\r\n                }\r\n            }\r\n            else {\r\n                Log.debug(\"SessionMonitor._callback: Subject no longer signed into OP\");\r\n            }\r\n\r\n            if (raiseEvent) {\r\n                if (this._sub) {\r\n                    Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed out event\");\r\n                    this._userManager.events._raiseUserSignedOut();\r\n                }\r\n                else {\r\n                    Log.debug(\"SessionMonitor._callback: SessionMonitor._callback; raising signed in event\");\r\n                    this._userManager.events._raiseUserSignedIn();\r\n                }\r\n            }\r\n        }).catch(err => {\r\n            if (this._sub) {\r\n                Log.debug(\"SessionMonitor._callback: Error calling queryCurrentSigninSession; raising signed out event\", err.message);\r\n                this._userManager.events._raiseUserSignedOut();\r\n            }\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\nimport { SigninState } from './SigninState.js';\r\n\r\nexport class SigninRequest {\r\n    constructor({\r\n        // mandatory\r\n        url, client_id, redirect_uri, response_type, scope, authority,\r\n        // optional\r\n        data, prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values, resource, response_mode,\r\n        request, request_uri, extraQueryParams, request_type, client_secret, extraTokenParams, skipUserInfo\r\n    }) {\r\n        if (!url) {\r\n            Log.error(\"SigninRequest.ctor: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n        if (!client_id) {\r\n            Log.error(\"SigninRequest.ctor: No client_id passed\");\r\n            throw new Error(\"client_id\");\r\n        }\r\n        if (!redirect_uri) {\r\n            Log.error(\"SigninRequest.ctor: No redirect_uri passed\");\r\n            throw new Error(\"redirect_uri\");\r\n        }\r\n        if (!response_type) {\r\n            Log.error(\"SigninRequest.ctor: No response_type passed\");\r\n            throw new Error(\"response_type\");\r\n        }\r\n        if (!scope) {\r\n            Log.error(\"SigninRequest.ctor: No scope passed\");\r\n            throw new Error(\"scope\");\r\n        }\r\n        if (!authority) {\r\n            Log.error(\"SigninRequest.ctor: No authority passed\");\r\n            throw new Error(\"authority\");\r\n        }\r\n\r\n        let oidc = SigninRequest.isOidc(response_type);\r\n        let code = SigninRequest.isCode(response_type);\r\n\r\n        if (!response_mode) {\r\n            response_mode = SigninRequest.isCode(response_type) ? \"query\" : null;\r\n        }\r\n\r\n        this.state = new SigninState({ nonce: oidc, \r\n            data, client_id, authority, redirect_uri, \r\n            code_verifier: code, \r\n            request_type, response_mode,\r\n            client_secret, scope, extraTokenParams, skipUserInfo });\r\n\r\n        url = UrlUtility.addQueryParam(url, \"client_id\", client_id);\r\n        url = UrlUtility.addQueryParam(url, \"redirect_uri\", redirect_uri);\r\n        url = UrlUtility.addQueryParam(url, \"response_type\", response_type);\r\n        url = UrlUtility.addQueryParam(url, \"scope\", scope);\r\n\r\n        url = UrlUtility.addQueryParam(url, \"state\", this.state.id);\r\n        if (oidc) {\r\n            url = UrlUtility.addQueryParam(url, \"nonce\", this.state.nonce);\r\n        }\r\n        if (code) {\r\n            url = UrlUtility.addQueryParam(url, \"code_challenge\", this.state.code_challenge);\r\n            url = UrlUtility.addQueryParam(url, \"code_challenge_method\", \"S256\");\r\n        }\r\n\r\n        var optional = { prompt, display, max_age, ui_locales, id_token_hint, login_hint, acr_values, resource, request, request_uri, response_mode };\r\n        for(let key in optional){\r\n            if (optional[key]) {\r\n                url = UrlUtility.addQueryParam(url, key, optional[key]);\r\n            }\r\n        }\r\n\r\n        for(let key in extraQueryParams){\r\n            url = UrlUtility.addQueryParam(url, key, extraQueryParams[key])\r\n        }\r\n\r\n        this.url = url;\r\n    }\r\n\r\n    static isOidc(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"id_token\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n\r\n    static isOAuth(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"token\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n    \r\n    static isCode(response_type) {\r\n        var result = response_type.split(/\\s+/g).filter(function(item) {\r\n            return item === \"code\";\r\n        });\r\n        return !!(result[0]);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nconst OidcScope = \"openid\";\r\n\r\nexport class SigninResponse {\r\n    constructor(url, delimiter = \"#\") {\r\n\r\n        var values = UrlUtility.parseUrlFragment(url, delimiter);\r\n\r\n        this.error = values.error;\r\n        this.error_description = values.error_description;\r\n        this.error_uri = values.error_uri;\r\n\r\n        this.code = values.code;\r\n        this.state = values.state;\r\n        this.id_token = values.id_token;\r\n        this.session_state = values.session_state;\r\n        this.access_token = values.access_token;\r\n        this.token_type = values.token_type;\r\n        this.scope = values.scope;\r\n        this.profile = undefined; // will be set from ResponseValidator\r\n\r\n        this.expires_in = values.expires_in;\r\n    }\r\n\r\n    get expires_in() {\r\n        if (this.expires_at) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            return this.expires_at - now;\r\n        }\r\n        return undefined;\r\n    }\r\n    set expires_in(value){\r\n        let expires_in = parseInt(value);\r\n        if (typeof expires_in === 'number' && expires_in > 0) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            this.expires_at = now + expires_in;\r\n        }\r\n    }\r\n\r\n    get expired() {\r\n        let expires_in = this.expires_in;\r\n        if (expires_in !== undefined) {\r\n            return expires_in <= 0;\r\n        }\r\n        return undefined;\r\n    }\r\n\r\n    get scopes() {\r\n        return (this.scope || \"\").split(\" \");\r\n    }\r\n\r\n    get isOpenIdConnect() {\r\n        return this.scopes.indexOf(OidcScope) >= 0 || !!this.id_token;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { State } from './State.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\nimport random from './random.js';\r\n\r\nexport class SigninState extends State {\r\n    constructor({nonce, authority, client_id, redirect_uri, code_verifier, response_mode, client_secret, scope, extraTokenParams, skipUserInfo} = {}) {\r\n        super(arguments[0]);\r\n\r\n        if (nonce === true) {\r\n            this._nonce = random();\r\n        }\r\n        else if (nonce) {\r\n            this._nonce = nonce;\r\n        }\r\n\r\n        if (code_verifier === true) {\r\n            // random() produces 32 length\r\n            this._code_verifier = random() + random() + random();\r\n        }\r\n        else if (code_verifier) {\r\n            this._code_verifier = code_verifier;\r\n        }\r\n        \r\n        if (this.code_verifier) {\r\n            let hash = JoseUtil.hashString(this.code_verifier, \"SHA256\");\r\n            this._code_challenge = JoseUtil.hexToBase64Url(hash);\r\n        }\r\n\r\n        this._redirect_uri = redirect_uri;\r\n        this._authority = authority;\r\n        this._client_id = client_id;\r\n        this._response_mode = response_mode;\r\n        this._client_secret = client_secret;\r\n        this._scope = scope;\r\n        this._extraTokenParams = extraTokenParams;\r\n        this._skipUserInfo = skipUserInfo;\r\n    }\r\n\r\n    get nonce() {\r\n        return this._nonce;\r\n    }\r\n    get authority() {\r\n        return this._authority;\r\n    }\r\n    get client_id() {\r\n        return this._client_id;\r\n    }\r\n    get redirect_uri() {\r\n        return this._redirect_uri;\r\n    }\r\n    get code_verifier() {\r\n        return this._code_verifier;\r\n    }\r\n    get code_challenge() {\r\n        return this._code_challenge;\r\n    }\r\n    get response_mode() {\r\n        return this._response_mode;\r\n    }\r\n    get client_secret() {\r\n        return this._client_secret;\r\n    }\r\n    get scope() {\r\n        return this._scope;\r\n    }\r\n    get extraTokenParams() {\r\n        return this._extraTokenParams;\r\n    }\r\n    get skipUserInfo() {\r\n        return this._skipUserInfo;\r\n    }\r\n    \r\n    toStorageString() {\r\n        Log.debug(\"SigninState.toStorageString\");\r\n        return JSON.stringify({\r\n            id: this.id,\r\n            data: this.data,\r\n            created: this.created,\r\n            request_type: this.request_type,\r\n            nonce: this.nonce,\r\n            code_verifier: this.code_verifier,\r\n            redirect_uri: this.redirect_uri,\r\n            authority: this.authority,\r\n            client_id: this.client_id,\r\n            response_mode: this.response_mode,\r\n            client_secret: this.client_secret,\r\n            scope: this.scope,\r\n            extraTokenParams : this.extraTokenParams,\r\n            skipUserInfo: this.skipUserInfo\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"SigninState.fromStorageString\");\r\n        var data = JSON.parse(storageString);\r\n        return new SigninState(data);\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { UrlUtility } from './UrlUtility.js';\r\nimport { State } from './State.js';\r\n\r\nexport class SignoutRequest {\r\n    constructor({url, id_token_hint, post_logout_redirect_uri, data, extraQueryParams, request_type}) {\r\n        if (!url) {\r\n            Log.error(\"SignoutRequest.ctor: No url passed\");\r\n            throw new Error(\"url\");\r\n        }\r\n\r\n        if (id_token_hint) {\r\n            url = UrlUtility.addQueryParam(url, \"id_token_hint\", id_token_hint);\r\n        }\r\n\r\n        if (post_logout_redirect_uri) {\r\n            url = UrlUtility.addQueryParam(url, \"post_logout_redirect_uri\", post_logout_redirect_uri);\r\n\r\n            if (data) {\r\n                this.state = new State({ data, request_type });\r\n\r\n                url = UrlUtility.addQueryParam(url, \"state\", this.state.id);\r\n            }\r\n        }\r\n\r\n        for(let key in extraQueryParams){\r\n            url = UrlUtility.addQueryParam(url, key, extraQueryParams[key])\r\n        }\r\n\r\n        this.url = url;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { UrlUtility } from './UrlUtility.js';\r\n\r\nexport class SignoutResponse {\r\n    constructor(url) {\r\n\r\n        var values = UrlUtility.parseUrlFragment(url, \"?\");\r\n\r\n        this.error = values.error;\r\n        this.error_description = values.error_description;\r\n        this.error_uri = values.error_uri;\r\n\r\n        this.state = values.state;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class SilentRenewService {\r\n\r\n    constructor(userManager) {\r\n        this._userManager = userManager;\r\n    }\r\n\r\n    start() {\r\n        if (!this._callback) {\r\n            this._callback = this._tokenExpiring.bind(this);\r\n            this._userManager.events.addAccessTokenExpiring(this._callback);\r\n\r\n            // this will trigger loading of the user so the expiring events can be initialized\r\n            this._userManager.getUser().then(user=>{\r\n                // deliberate nop\r\n            }).catch(err=>{\r\n                // catch to suppress errors since we're in a ctor\r\n                Log.error(\"SilentRenewService.start: Error from getUser:\", err.message);\r\n            });\r\n        }\r\n    }\r\n\r\n    stop() {\r\n        if (this._callback) {\r\n            this._userManager.events.removeAccessTokenExpiring(this._callback);\r\n            delete this._callback;\r\n        }\r\n    }\r\n\r\n    _tokenExpiring() {\r\n        this._userManager.signinSilent().then(user => {\r\n            Log.debug(\"SilentRenewService._tokenExpiring: Silent token renewal successful\");\r\n        }, err => {\r\n            Log.error(\"SilentRenewService._tokenExpiring: Error from signinSilent:\", err.message);\r\n            this._userManager.events._raiseSilentRenewError(err);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport random from './random.js';\r\n\r\nexport class State {\r\n    constructor({id, data, created, request_type} = {}) {\r\n        this._id = id || random();\r\n        this._data = data;\r\n\r\n        if (typeof created === 'number' && created > 0) {\r\n            this._created = created;\r\n        }\r\n        else {\r\n            this._created = parseInt(Date.now() / 1000);\r\n        }\r\n        this._request_type =  request_type;\r\n    }\r\n\r\n    get id() {\r\n        return this._id;\r\n    }\r\n    get data() {\r\n        return this._data;\r\n    }\r\n    get created() {\r\n        return this._created;\r\n    }\r\n    get request_type() {\r\n        return this._request_type;\r\n    }\r\n\r\n    toStorageString() {\r\n        Log.debug(\"State.toStorageString\");\r\n        return JSON.stringify({\r\n            id: this.id,\r\n            data: this.data,\r\n            created: this.created,\r\n            request_type: this.request_type\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"State.fromStorageString\");\r\n        return new State(JSON.parse(storageString));\r\n    }\r\n\r\n    static clearStaleState(storage, age) {\r\n\r\n        var cutoff = Date.now() / 1000 - age;\r\n\r\n        return storage.getAllKeys().then(keys => {\r\n            Log.debug(\"State.clearStaleState: got keys\", keys);\r\n\r\n            var promises = [];\r\n            for (let i = 0; i < keys.length; i++) {\r\n                let key = keys[i];\r\n                var p = storage.get(key).then(item => {\r\n                    let remove = false;\r\n\r\n                    if (item) {\r\n                        try {\r\n                            var state = State.fromStorageString(item)\r\n\r\n                            Log.debug(\"State.clearStaleState: got item from key: \", key, state.created);\r\n\r\n                            if (state.created <= cutoff) {\r\n                                remove = true;\r\n                            }\r\n                        }\r\n                        catch (e) {\r\n                            Log.error(\"State.clearStaleState: Error parsing state for key\", key, e.message);\r\n                            remove = true;\r\n                        }\r\n                    }\r\n                    else {\r\n                        Log.debug(\"State.clearStaleState: no item in storage for key: \", key);\r\n                        remove = true;\r\n                    }\r\n\r\n                    if (remove) {\r\n                        Log.debug(\"State.clearStaleState: removed item for key: \", key);\r\n                        return storage.remove(key);\r\n                    }\r\n                });\r\n\r\n                promises.push(p);\r\n            }\r\n\r\n            Log.debug(\"State.clearStaleState: waiting on promise count:\", promises.length);\r\n            return Promise.all(promises);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\nimport { Event } from './Event.js';\r\n\r\nconst TimerDuration = 5; // seconds\r\n\r\nexport class Timer extends Event {\r\n\r\n    constructor(name, timer = Global.timer, nowFunc = undefined) {\r\n        super(name);\r\n        this._timer = timer;\r\n\r\n        if (nowFunc) {\r\n            this._nowFunc = nowFunc;\r\n        }\r\n        else {\r\n            this._nowFunc = () => Date.now() / 1000;\r\n        }\r\n    }\r\n\r\n    get now() {\r\n        return parseInt(this._nowFunc());\r\n    }\r\n\r\n    init(duration) {\r\n        if (duration <= 0) {\r\n            duration = 1;\r\n        }\r\n        duration = parseInt(duration);\r\n\r\n        var expiration = this.now + duration;\r\n        if (this.expiration === expiration && this._timerHandle) {\r\n            // no need to reinitialize to same expiration, so bail out\r\n            Log.debug(\"Timer.init timer \" + this._name + \" skipping initialization since already initialized for expiration:\", this.expiration);\r\n            return;\r\n        }\r\n\r\n        this.cancel();\r\n\r\n        Log.debug(\"Timer.init timer \" + this._name + \" for duration:\", duration);\r\n        this._expiration = expiration;\r\n\r\n        // we're using a fairly short timer and then checking the expiration in the\r\n        // callback to handle scenarios where the browser device sleeps, and then\r\n        // the timers end up getting delayed.\r\n        var timerDuration = TimerDuration;\r\n        if (duration < timerDuration) {\r\n            timerDuration = duration;\r\n        }\r\n        this._timerHandle = this._timer.setInterval(this._callback.bind(this), timerDuration * 1000);\r\n    }\r\n    \r\n    get expiration() {\r\n        return this._expiration;\r\n    }\r\n\r\n    cancel() {\r\n        if (this._timerHandle) {\r\n            Log.debug(\"Timer.cancel: \", this._name);\r\n            this._timer.clearInterval(this._timerHandle);\r\n            this._timerHandle = null;\r\n        }\r\n    }\r\n\r\n    _callback() {\r\n        var diff = this._expiration - this.now;\r\n        Log.debug(\"Timer.callback; \" + this._name + \" timer expires in:\", diff);\r\n\r\n        if (this._expiration <= this.now) {\r\n            this.cancel();\r\n            super.raise();\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { JsonService } from './JsonService.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Log } from './Log.js';\r\n\r\nexport class TokenClient {\r\n    constructor(settings, JsonServiceCtor = JsonService, MetadataServiceCtor = MetadataService) {\r\n        if (!settings) {\r\n            Log.error(\"TokenClient.ctor: No settings passed\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor();\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n    }\r\n\r\n    exchangeCode(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.grant_type = args.grant_type || \"authorization_code\";\r\n        args.client_id = args.client_id || this._settings.client_id;\r\n        args.redirect_uri = args.redirect_uri || this._settings.redirect_uri;\r\n\r\n        if (!args.code) {\r\n            Log.error(\"TokenClient.exchangeCode: No code passed\");\r\n            return Promise.reject(new Error(\"A code is required\"));\r\n        }\r\n        if (!args.redirect_uri) {\r\n            Log.error(\"TokenClient.exchangeCode: No redirect_uri passed\");\r\n            return Promise.reject(new Error(\"A redirect_uri is required\"));\r\n        }\r\n        if (!args.code_verifier) {\r\n            Log.error(\"TokenClient.exchangeCode: No code_verifier passed\");\r\n            return Promise.reject(new Error(\"A code_verifier is required\"));\r\n        }\r\n        if (!args.client_id) {\r\n            Log.error(\"TokenClient.exchangeCode: No client_id passed\");\r\n            return Promise.reject(new Error(\"A client_id is required\"));\r\n        }\r\n\r\n        return this._metadataService.getTokenEndpoint(false).then(url => {\r\n            Log.debug(\"TokenClient.exchangeCode: Received token endpoint\");\r\n\r\n            return this._jsonService.postForm(url, args).then(response => {\r\n                Log.debug(\"TokenClient.exchangeCode: response received\");\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n\r\n    exchangeRefreshToken(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.grant_type = args.grant_type || \"refresh_token\";\r\n        args.client_id = args.client_id || this._settings.client_id;\r\n        args.client_secret = args.client_secret || this._settings.client_secret;\r\n\r\n        if (!args.refresh_token) {\r\n            Log.error(\"TokenClient.exchangeRefreshToken: No refresh_token passed\");\r\n            return Promise.reject(new Error(\"A refresh_token is required\"));\r\n        }\r\n        if (!args.client_id) {\r\n            Log.error(\"TokenClient.exchangeRefreshToken: No client_id passed\");\r\n            return Promise.reject(new Error(\"A client_id is required\"));\r\n        }\r\n\r\n        return this._metadataService.getTokenEndpoint(false).then(url => {\r\n            Log.debug(\"TokenClient.exchangeRefreshToken: Received token endpoint\");\r\n\r\n            return this._jsonService.postForm(url, args).then(response => {\r\n                Log.debug(\"TokenClient.exchangeRefreshToken: response received\");\r\n                return response;\r\n            });\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Global } from './Global.js';\r\n\r\nconst AccessTokenTypeHint = \"access_token\";\r\nconst RefreshTokenTypeHint = \"refresh_token\";\r\n\r\nexport class TokenRevocationClient {\r\n    constructor(settings, XMLHttpRequestCtor = Global.XMLHttpRequest, MetadataServiceCtor = MetadataService) {\r\n        if (!settings) {\r\n            Log.error(\"TokenRevocationClient.ctor: No settings provided\");\r\n            throw new Error(\"No settings provided.\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._XMLHttpRequestCtor = XMLHttpRequestCtor;\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n    }\r\n\r\n    revoke(token, required, type = \"access_token\") {\r\n        if (!token) {\r\n            Log.error(\"TokenRevocationClient.revoke: No token provided\");\r\n            throw new Error(\"No token provided.\");\r\n        }\r\n\r\n        if (type !== AccessTokenTypeHint && type != RefreshTokenTypeHint) {\r\n            Log.error(\"TokenRevocationClient.revoke: Invalid token type\");\r\n            throw new Error(\"Invalid token type.\");\r\n        }\r\n\r\n        return this._metadataService.getRevocationEndpoint().then(url => {\r\n            if (!url) {\r\n                if (required) {\r\n                    Log.error(\"TokenRevocationClient.revoke: Revocation not supported\");\r\n                    throw new Error(\"Revocation not supported\");\r\n                }\r\n\r\n                // not required, so don't error and just return\r\n                return;\r\n            }\r\n\r\n            Log.debug(\"TokenRevocationClient.revoke: Revoking \" + type);\r\n            var client_id = this._settings.client_id;\r\n            var client_secret = this._settings.client_secret;\r\n            return this._revoke(url, client_id, client_secret, token, type);\r\n        });\r\n    }\r\n\r\n    _revoke(url, client_id, client_secret, token, type) {\r\n\r\n        return new Promise((resolve, reject) => {\r\n\r\n            var xhr = new this._XMLHttpRequestCtor();\r\n            xhr.open(\"POST\", url);\r\n\r\n            xhr.onload = () => {\r\n                Log.debug(\"TokenRevocationClient.revoke: HTTP response received, status\", xhr.status);\r\n\r\n                if (xhr.status === 200) {\r\n                    resolve();\r\n                }\r\n                else {\r\n                    reject(Error(xhr.statusText + \" (\" + xhr.status + \")\"));\r\n                }\r\n            };\r\n            xhr.onerror = () => { \r\n                Log.debug(\"TokenRevocationClient.revoke: Network Error.\")\r\n                reject(\"Network Error\");\r\n            };\r\n\r\n            var body = \"client_id=\" + encodeURIComponent(client_id);\r\n            if (client_secret) {\r\n                body += \"&client_secret=\" + encodeURIComponent(client_secret);\r\n            }\r\n            body += \"&token_type_hint=\" + encodeURIComponent(type);\r\n            body += \"&token=\" + encodeURIComponent(token);\r\n\r\n            xhr.setRequestHeader(\"Content-Type\", \"application/x-www-form-urlencoded\");\r\n            xhr.send(body);\r\n        });\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class UrlUtility {\r\n    static addQueryParam(url, name, value) {\r\n        if (url.indexOf('?') < 0) {\r\n            url += \"?\";\r\n        }\r\n\r\n        if (url[url.length - 1] !== \"?\") {\r\n            url += \"&\";\r\n        }\r\n\r\n        url += encodeURIComponent(name);\r\n        url += \"=\";\r\n        url += encodeURIComponent(value);\r\n\r\n        return url;\r\n    }\r\n\r\n    static parseUrlFragment(value, delimiter = \"#\", global = Global) {\r\n        if (typeof value !== 'string'){\r\n            value = global.location.href;\r\n        }\r\n\r\n        var idx = value.lastIndexOf(delimiter);\r\n        if (idx >= 0) {\r\n            value = value.substr(idx + 1);\r\n        }\r\n\r\n        if (delimiter === \"?\") {\r\n            // if we're doing query, then strip off hash fragment before we parse\r\n            idx = value.indexOf('#');\r\n            if (idx >= 0) {\r\n                value = value.substr(0, idx);\r\n            }\r\n        }\r\n\r\n        var params = {},\r\n            regex = /([^&=]+)=([^&]*)/g,\r\n            m;\r\n\r\n        var counter = 0;\r\n        while (m = regex.exec(value)) {\r\n            params[decodeURIComponent(m[1])] = decodeURIComponent(m[2]);\r\n            if (counter++ > 50) {\r\n                Log.error(\"UrlUtility.parseUrlFragment: response exceeded expected number of parameters\", value);\r\n                return {\r\n                    error: \"Response exceeded expected number of parameters\"\r\n                };\r\n            }\r\n        }\r\n\r\n        for (var prop in params) {\r\n            return params;\r\n        }\r\n\r\n        return {};\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\n\r\nexport class User {\r\n    constructor({id_token, session_state, access_token, refresh_token, token_type, scope, profile, expires_at, state}) {\r\n        this.id_token = id_token;\r\n        this.session_state = session_state;\r\n        this.access_token = access_token;\r\n        this.refresh_token = refresh_token;\r\n        this.token_type = token_type;\r\n        this.scope = scope;\r\n        this.profile = profile;\r\n        this.expires_at = expires_at;\r\n        this.state = state;\r\n    }\r\n\r\n    get expires_in() {\r\n        if (this.expires_at) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            return this.expires_at - now;\r\n        }\r\n        return undefined;\r\n    }\r\n    set expires_in(value) {\r\n        let expires_in = parseInt(value);\r\n        if (typeof expires_in === 'number' && expires_in > 0) {\r\n            let now = parseInt(Date.now() / 1000);\r\n            this.expires_at = now + expires_in;\r\n        }\r\n    }\r\n\r\n    get expired() {\r\n        let expires_in = this.expires_in;\r\n        if (expires_in !== undefined) {\r\n            return expires_in <= 0;\r\n        }\r\n        return undefined;\r\n    }\r\n\r\n    get scopes() {\r\n        return (this.scope || \"\").split(\" \");\r\n    }\r\n\r\n    toStorageString() {\r\n        Log.debug(\"User.toStorageString\");\r\n        return JSON.stringify({\r\n            id_token: this.id_token,\r\n            session_state: this.session_state,\r\n            access_token: this.access_token,\r\n            refresh_token: this.refresh_token,\r\n            token_type: this.token_type,\r\n            scope: this.scope,\r\n            profile: this.profile,\r\n            expires_at: this.expires_at\r\n        });\r\n    }\r\n\r\n    static fromStorageString(storageString) {\r\n        Log.debug(\"User.fromStorageString\");\r\n        return new User(JSON.parse(storageString));\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { JsonService } from './JsonService.js';\r\nimport { MetadataService } from './MetadataService.js';\r\nimport { Log } from './Log.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\nexport class UserInfoService {\r\n    constructor(\r\n        settings, \r\n        JsonServiceCtor = JsonService, \r\n        MetadataServiceCtor = MetadataService, \r\n        joseUtil = JoseUtil\r\n    ) {\r\n        if (!settings) {\r\n            Log.error(\"UserInfoService.ctor: No settings passed\");\r\n            throw new Error(\"settings\");\r\n        }\r\n\r\n        this._settings = settings;\r\n        this._jsonService = new JsonServiceCtor(undefined, undefined, this._getClaimsFromJwt.bind(this));\r\n        this._metadataService = new MetadataServiceCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n    }\r\n\r\n    getClaims(token) {\r\n        if (!token) {\r\n            Log.error(\"UserInfoService.getClaims: No token passed\");\r\n            return Promise.reject(new Error(\"A token is required\"));\r\n        }\r\n\r\n        return this._metadataService.getUserInfoEndpoint().then(url => {\r\n            Log.debug(\"UserInfoService.getClaims: received userinfo url\", url);\r\n\r\n            return this._jsonService.getJson(url, token).then(claims => {\r\n                Log.debug(\"UserInfoService.getClaims: claims received\", claims);\r\n                return claims;\r\n            });\r\n        });\r\n    }\r\n\r\n    _getClaimsFromJwt(req) {\r\n        try {\r\n            let jwt = this._joseUtil.parseJwt(req.responseText);\r\n            if (!jwt || !jwt.header || !jwt.payload) {\r\n                Log.error(\"UserInfoService._getClaimsFromJwt: Failed to parse JWT\", jwt);\r\n                return Promise.reject(new Error(\"Failed to parse id_token\"));\r\n            }\r\n\r\n            var kid = jwt.header.kid;\r\n\r\n            let issuerPromise;\r\n            switch (this._settings.userInfoJwtIssuer) {\r\n                case 'OP':\r\n                    issuerPromise = this._metadataService.getIssuer();\r\n                    break;\r\n                case 'ANY':\r\n                    issuerPromise = Promise.resolve(jwt.payload.iss);\r\n                    break;\r\n                default:\r\n                    issuerPromise = Promise.resolve(this._settings.userInfoJwtIssuer);\r\n                    break;\r\n            }\r\n\r\n            return issuerPromise.then(issuer => {\r\n                Log.debug(\"UserInfoService._getClaimsFromJwt: Received issuer:\" + issuer);\r\n\r\n                return this._metadataService.getSigningKeys().then(keys => {\r\n                    if (!keys) {\r\n                        Log.error(\"UserInfoService._getClaimsFromJwt: No signing keys from metadata\");\r\n                        return Promise.reject(new Error(\"No signing keys from metadata\"));\r\n                    }\r\n\r\n                    Log.debug(\"UserInfoService._getClaimsFromJwt: Received signing keys\");\r\n                    let key;\r\n                    if (!kid) {\r\n                        keys = this._filterByAlg(keys, jwt.header.alg);\r\n\r\n                        if (keys.length > 1) {\r\n                            Log.error(\"UserInfoService._getClaimsFromJwt: No kid found in id_token and more than one key found in metadata\");\r\n                            return Promise.reject(new Error(\"No kid found in id_token and more than one key found in metadata\"));\r\n                        }\r\n                        else {\r\n                            // kid is mandatory only when there are multiple keys in the referenced JWK Set document\r\n                            // see http://openid.net/specs/openid-connect-core-1_0.html#Signing\r\n                            key = keys[0];\r\n                        }\r\n                    }\r\n                    else {\r\n                        key = keys.filter(key => {\r\n                            return key.kid === kid;\r\n                        })[0];\r\n                    }\r\n\r\n                    if (!key) {\r\n                        Log.error(\"UserInfoService._getClaimsFromJwt: No key matching kid or alg found in signing keys\");\r\n                        return Promise.reject(new Error(\"No key matching kid or alg found in signing keys\"));\r\n                    }\r\n\r\n                    let audience = this._settings.client_id;\r\n\r\n                    let clockSkewInSeconds = this._settings.clockSkew;\r\n                    Log.debug(\"UserInfoService._getClaimsFromJwt: Validaing JWT; using clock skew (in seconds) of: \", clockSkewInSeconds);\r\n\r\n                    return this._joseUtil.validateJwt(req.responseText, key, issuer, audience, clockSkewInSeconds, undefined, true).then(() => {\r\n                        Log.debug(\"UserInfoService._getClaimsFromJwt: JWT validation successful\");\r\n                        return jwt.payload;\r\n                    });\r\n                });\r\n            });\r\n            return;\r\n        }\r\n        catch (e) {\r\n            Log.error(\"UserInfoService._getClaimsFromJwt: Error parsing JWT response\", e.message);\r\n            reject(e);\r\n            return;\r\n        }\r\n    }\r\n\r\n    _filterByAlg(keys, alg) {\r\n        var kty = null;\r\n        if (alg.startsWith(\"RS\")) {\r\n            kty = \"RSA\";\r\n        }\r\n        else if (alg.startsWith(\"PS\")) {\r\n            kty = \"PS\";\r\n        }\r\n        else if (alg.startsWith(\"ES\")) {\r\n            kty = \"EC\";\r\n        }\r\n        else {\r\n            Log.debug(\"UserInfoService._filterByAlg: alg not supported: \", alg);\r\n            return [];\r\n        }\r\n\r\n        Log.debug(\"UserInfoService._filterByAlg: Looking for keys that match kty: \", kty);\r\n\r\n        keys = keys.filter(key => {\r\n            return key.kty === kty;\r\n        });\r\n\r\n        Log.debug(\"UserInfoService._filterByAlg: Number of keys that match kty: \", kty, keys.length);\r\n\r\n        return keys;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClient } from './OidcClient.js';\r\nimport { UserManagerSettings } from './UserManagerSettings.js';\r\nimport { User } from './User.js';\r\nimport { UserManagerEvents } from './UserManagerEvents.js';\r\nimport { SilentRenewService } from './SilentRenewService.js';\r\nimport { SessionMonitor } from './SessionMonitor.js';\r\nimport { TokenRevocationClient } from './TokenRevocationClient.js';\r\nimport { TokenClient } from './TokenClient.js';\r\nimport { JoseUtil } from './JoseUtil.js';\r\n\r\n\r\nexport class UserManager extends OidcClient {\r\n    constructor(settings = {},\r\n        SilentRenewServiceCtor = SilentRenewService,\r\n        SessionMonitorCtor = SessionMonitor,\r\n        TokenRevocationClientCtor = TokenRevocationClient,\r\n        TokenClientCtor = TokenClient,\r\n        joseUtil = JoseUtil\r\n    ) {\r\n\r\n        if (!(settings instanceof UserManagerSettings)) {\r\n            settings = new UserManagerSettings(settings);\r\n        }\r\n        super(settings);\r\n\r\n        this._events = new UserManagerEvents(settings);\r\n        this._silentRenewService = new SilentRenewServiceCtor(this);\r\n\r\n        // order is important for the following properties; these services depend upon the events.\r\n        if (this.settings.automaticSilentRenew) {\r\n            Log.debug(\"UserManager.ctor: automaticSilentRenew is configured, setting up silent renew\");\r\n            this.startSilentRenew();\r\n        }\r\n\r\n        if (this.settings.monitorSession) {\r\n            Log.debug(\"UserManager.ctor: monitorSession is configured, setting up session monitor\");\r\n            this._sessionMonitor = new SessionMonitorCtor(this);\r\n        }\r\n\r\n        this._tokenRevocationClient = new TokenRevocationClientCtor(this._settings);\r\n        this._tokenClient = new TokenClientCtor(this._settings);\r\n        this._joseUtil = joseUtil;\r\n    }\r\n\r\n    get _redirectNavigator() {\r\n        return this.settings.redirectNavigator;\r\n    }\r\n    get _popupNavigator() {\r\n        return this.settings.popupNavigator;\r\n    }\r\n    get _iframeNavigator() {\r\n        return this.settings.iframeNavigator;\r\n    }\r\n    get _userStore() {\r\n        return this.settings.userStore;\r\n    }\r\n\r\n    get events() {\r\n        return this._events;\r\n    }\r\n\r\n    getUser() {\r\n        return this._loadUser().then(user => {\r\n            if (user) {\r\n                Log.info(\"UserManager.getUser: user loaded\");\r\n\r\n                this._events.load(user, false);\r\n\r\n                return user;\r\n            }\r\n            else {\r\n                Log.info(\"UserManager.getUser: user not found in storage\");\r\n                return null;\r\n            }\r\n        });\r\n    }\r\n\r\n    removeUser() {\r\n        return this.storeUser(null).then(() => {\r\n            Log.info(\"UserManager.removeUser: user removed from storage\");\r\n            this._events.unload();\r\n        });\r\n    }\r\n\r\n    signinRedirect(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:r\";\r\n        let navParams = {\r\n            useReplaceToNavigate : args.useReplaceToNavigate\r\n        };\r\n        return this._signinStart(args, this._redirectNavigator, navParams).then(()=>{\r\n            Log.info(\"UserManager.signinRedirect: successful\");\r\n        });\r\n    }\r\n    signinRedirectCallback(url) {\r\n        return this._signinEnd(url || this._redirectNavigator.url).then(user => {\r\n            if (user.profile && user.profile.sub) {\r\n                Log.info(\"UserManager.signinRedirectCallback: successful, signed in sub: \", user.profile.sub);\r\n            }\r\n            else {\r\n                Log.info(\"UserManager.signinRedirectCallback: no sub\");\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinPopup(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:p\";\r\n        let url = args.redirect_uri || this.settings.popup_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.signinPopup: No popup_redirect_uri or redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No popup_redirect_uri or redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.display = \"popup\";\r\n\r\n        return this._signin(args, this._popupNavigator, {\r\n            startUrl: url,\r\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\r\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\r\n        }).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinPopup: signinPopup successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinPopup: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n    signinPopupCallback(url) {\r\n        return this._signinCallback(url, this._popupNavigator).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinPopupCallback: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinPopupCallback: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        }).catch(err=>{\r\n            Log.error(\"UserManager.signinPopupCallback error: \" + err && err.message);\r\n        });\r\n    }\r\n\r\n    signinSilent(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:s\";\r\n        // first determine if we have a refresh token, or need to use iframe\r\n        return this._loadUser().then(user => {\r\n            if (user && user.refresh_token) {\r\n                args.refresh_token = user.refresh_token;\r\n                return this._useRefreshToken(args);\r\n            }\r\n            else {\r\n                args.id_token_hint = args.id_token_hint || (this.settings.includeIdTokenInSilentRenew && user && user.id_token);\r\n                if (user && this._settings.validateSubOnSilentRenew) {\r\n                    Log.debug(\"UserManager.signinSilent, subject prior to silent renew: \", user.profile.sub);\r\n                    args.current_sub = user.profile.sub;\r\n                }\r\n                return this._signinSilentIframe(args);\r\n            }\r\n        });\r\n    }\r\n\r\n    _useRefreshToken(args = {}) {\r\n        return this._tokenClient.exchangeRefreshToken(args).then(result => {\r\n            if (!result) {\r\n                Log.error(\"UserManager._useRefreshToken: No response returned from token endpoint\");\r\n                return Promise.reject(\"No response returned from token endpoint\");\r\n            }\r\n            if (!result.access_token) {\r\n                Log.error(\"UserManager._useRefreshToken: No access token returned from token endpoint\");\r\n                return Promise.reject(\"No access token returned from token endpoint\");\r\n            }\r\n\r\n            return this._loadUser().then(user => {\r\n                if (user) {\r\n                    let idTokenValidation = Promise.resolve();\r\n                    if (result.id_token) {\r\n                        idTokenValidation = this._validateIdTokenFromTokenRefreshToken(user.profile, result.id_token);\r\n                    }\r\n\r\n                    return idTokenValidation.then(() => {\r\n                        Log.debug(\"UserManager._useRefreshToken: refresh token response success\");\r\n                        user.id_token = result.id_token;\r\n                        user.access_token = result.access_token;\r\n                        user.refresh_token = result.refresh_token || user.refresh_token;\r\n                        user.expires_in = result.expires_in;\r\n\r\n                        return this.storeUser(user).then(()=>{\r\n                            this._events.load(user);\r\n                            return user;\r\n                        });\r\n                    });\r\n                }\r\n                else {\r\n                    return null;\r\n                }\r\n            });\r\n        });\r\n    }\r\n\r\n    _validateIdTokenFromTokenRefreshToken(profile, id_token) {\r\n        return this._metadataService.getIssuer().then(issuer => {\r\n            return this._joseUtil.validateJwtAttributes(id_token, issuer, this._settings.client_id, this._settings.clockSkew).then(payload => {\r\n                if (!payload) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: Failed to validate id_token\");\r\n                    return Promise.reject(new Error(\"Failed to validate id_token\"));\r\n                }\r\n                if (payload.sub !== profile.sub) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: sub in id_token does not match current sub\");\r\n                    return Promise.reject(new Error(\"sub in id_token does not match current sub\"));\r\n                }\r\n                if (payload.auth_time && payload.auth_time !== profile.auth_time) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: auth_time in id_token does not match original auth_time\");\r\n                    return Promise.reject(new Error(\"auth_time in id_token does not match original auth_time\"));\r\n                }\r\n                if (payload.azp && payload.azp !== profile.azp) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp in id_token does not match original azp\");\r\n                    return Promise.reject(new Error(\"azp in id_token does not match original azp\"));\r\n                }\r\n                if (!payload.azp && profile.azp) {\r\n                    Log.error(\"UserManager._validateIdTokenFromTokenRefreshToken: azp not in id_token, but present in original id_token\");\r\n                    return Promise.reject(new Error(\"azp not in id_token, but present in original id_token\"));\r\n                }\r\n            });\r\n        });\r\n    }\r\n    \r\n    _signinSilentIframe(args = {}) {\r\n        let url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.signinSilent: No silent_redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.prompt = args.prompt || \"none\";\r\n\r\n        return this._signin(args, this._iframeNavigator, {\r\n            startUrl: url,\r\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\r\n        }).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinSilent: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinSilent: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinSilentCallback(url) {\r\n        return this._signinCallback(url, this._iframeNavigator).then(user => {\r\n            if (user) {\r\n                if (user.profile && user.profile.sub) {\r\n                    Log.info(\"UserManager.signinSilentCallback: successful, signed in sub: \", user.profile.sub);\r\n                }\r\n                else {\r\n                    Log.info(\"UserManager.signinSilentCallback: no sub\");\r\n                }\r\n            }\r\n\r\n            return user;\r\n        });\r\n    }\r\n\r\n    signinCallback(url) {\r\n        return this.readSigninResponseState(url).then(({state, response}) => {\r\n            if (state.request_type === \"si:r\") {\r\n                return this.signinRedirectCallback(url);\r\n            }\r\n            if (state.request_type === \"si:p\") {\r\n                return this.signinPopupCallback(url);\r\n            }\r\n            if (state.request_type === \"si:s\") {\r\n                return this.signinSilentCallback(url);\r\n            }\r\n            return Promise.reject(new Error(\"invalid response_type in state\"));\r\n        });\r\n    }\r\n\r\n    signoutCallback(url, keepOpen) {\r\n        return this.readSignoutResponseState(url).then(({state, response}) => {\r\n            if (state) {\r\n                if (state.request_type === \"so:r\") {\r\n                    return this.signoutRedirectCallback(url);\r\n                }\r\n                if (state.request_type === \"so:p\") {\r\n                    return this.signoutPopupCallback(url, keepOpen);\r\n                }\r\n                return Promise.reject(new Error(\"invalid response_type in state\"));\r\n            }\r\n            return response;\r\n        });\r\n    }\r\n\r\n    querySessionStatus(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"si:s\"; // this acts like a signin silent\r\n        let url = args.redirect_uri || this.settings.silent_redirect_uri || this.settings.redirect_uri;\r\n        if (!url) {\r\n            Log.error(\"UserManager.querySessionStatus: No silent_redirect_uri configured\");\r\n            return Promise.reject(new Error(\"No silent_redirect_uri configured\"));\r\n        }\r\n\r\n        args.redirect_uri = url;\r\n        args.prompt = \"none\";\r\n        args.response_type = args.response_type || this.settings.query_status_response_type;\r\n        args.scope = args.scope || \"openid\";\r\n        args.skipUserInfo = true;\r\n\r\n        return this._signinStart(args, this._iframeNavigator, {\r\n            startUrl: url,\r\n            silentRequestTimeout: args.silentRequestTimeout || this.settings.silentRequestTimeout\r\n        }).then(navResponse => {\r\n            return this.processSigninResponse(navResponse.url).then(signinResponse => {\r\n                Log.debug(\"UserManager.querySessionStatus: got signin response\");\r\n\r\n                if (signinResponse.session_state && signinResponse.profile.sub) {\r\n                    Log.info(\"UserManager.querySessionStatus: querySessionStatus success for sub: \",  signinResponse.profile.sub);\r\n                    return {\r\n                        session_state: signinResponse.session_state,\r\n                        sub: signinResponse.profile.sub,\r\n                        sid: signinResponse.profile.sid\r\n                    };\r\n                }\r\n                else {\r\n                    Log.info(\"querySessionStatus successful, user not authenticated\");\r\n                }\r\n            })\r\n            .catch(err => {\r\n                if (err.session_state && this.settings.monitorAnonymousSession) {\r\n                    if (err.message == \"login_required\" || \r\n                        err.message == \"consent_required\" || \r\n                        err.message == \"interaction_required\" || \r\n                        err.message == \"account_selection_required\"\r\n                    ) {\r\n                        Log.info(\"UserManager.querySessionStatus: querySessionStatus success for anonymous user\");\r\n                        return {\r\n                            session_state: err.session_state\r\n                        };\r\n                    }\r\n                }\r\n\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n\r\n    _signin(args, navigator, navigatorParams = {}) {\r\n        return this._signinStart(args, navigator, navigatorParams).then(navResponse => {\r\n            return this._signinEnd(navResponse.url, args);\r\n        });\r\n    }\r\n    _signinStart(args, navigator, navigatorParams = {}) {\r\n\r\n        return navigator.prepare(navigatorParams).then(handle => {\r\n            Log.debug(\"UserManager._signinStart: got navigator window handle\");\r\n\r\n            return this.createSigninRequest(args).then(signinRequest => {\r\n                Log.debug(\"UserManager._signinStart: got signin request\");\r\n\r\n                navigatorParams.url = signinRequest.url;\r\n                navigatorParams.id = signinRequest.state.id;\r\n\r\n                return handle.navigate(navigatorParams);\r\n            }).catch(err => {\r\n                if (handle.close) {\r\n                    Log.debug(\"UserManager._signinStart: Error after preparing navigator, closing navigator window\");\r\n                    handle.close();\r\n                }\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n    _signinEnd(url, args = {}) {\r\n        return this.processSigninResponse(url).then(signinResponse => {\r\n            Log.debug(\"UserManager._signinEnd: got signin response\");\r\n\r\n            let user = new User(signinResponse);\r\n\r\n            if (args.current_sub) {\r\n                if (args.current_sub !== user.profile.sub) {\r\n                    Log.debug(\"UserManager._signinEnd: current user does not match user returned from signin. sub from signin: \", user.profile.sub);\r\n                    return Promise.reject(new Error(\"login_required\"));\r\n                }\r\n                else {\r\n                    Log.debug(\"UserManager._signinEnd: current user matches user returned from signin\");\r\n                }\r\n            }\r\n\r\n            return this.storeUser(user).then(() => {\r\n                Log.debug(\"UserManager._signinEnd: user stored\");\r\n\r\n                this._events.load(user);\r\n\r\n                return user;\r\n            });\r\n        });\r\n    }\r\n    _signinCallback(url, navigator) {\r\n        Log.debug(\"UserManager._signinCallback\");\r\n        return navigator.callback(url);\r\n    }\r\n\r\n    signoutRedirect(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"so:r\";\r\n        let postLogoutRedirectUri = args.post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\r\n        if (postLogoutRedirectUri){\r\n            args.post_logout_redirect_uri = postLogoutRedirectUri;\r\n        }\r\n        let navParams = {\r\n            useReplaceToNavigate : args.useReplaceToNavigate\r\n        };\r\n        return this._signoutStart(args, this._redirectNavigator, navParams).then(()=>{\r\n            Log.info(\"UserManager.signoutRedirect: successful\");\r\n        });\r\n    }\r\n    signoutRedirectCallback(url) {\r\n        return this._signoutEnd(url || this._redirectNavigator.url).then(response=>{\r\n            Log.info(\"UserManager.signoutRedirectCallback: successful\");\r\n            return response;\r\n        });\r\n    }\r\n\r\n    signoutPopup(args = {}) {\r\n        args = Object.assign({}, args);\r\n\r\n        args.request_type = \"so:p\";\r\n        let url = args.post_logout_redirect_uri || this.settings.popup_post_logout_redirect_uri || this.settings.post_logout_redirect_uri;\r\n        args.post_logout_redirect_uri = url;\r\n        args.display = \"popup\";\r\n        if (args.post_logout_redirect_uri){\r\n            // we're putting a dummy entry in here because we\r\n            // need a unique id from the state for notification\r\n            // to the parent window, which is necessary if we\r\n            // plan to return back to the client after signout\r\n            // and so we can close the popup after signout\r\n            args.state = args.state || {};\r\n        }\r\n\r\n        return this._signout(args, this._popupNavigator, {\r\n            startUrl: url,\r\n            popupWindowFeatures: args.popupWindowFeatures || this.settings.popupWindowFeatures,\r\n            popupWindowTarget: args.popupWindowTarget || this.settings.popupWindowTarget\r\n        }).then(() => {\r\n            Log.info(\"UserManager.signoutPopup: successful\");\r\n        });\r\n    }\r\n    signoutPopupCallback(url, keepOpen) {\r\n        if (typeof(keepOpen) === 'undefined' && typeof(url) === 'boolean') {\r\n            keepOpen = url;\r\n            url = null;\r\n        }\r\n\r\n        let delimiter = '?';\r\n        return this._popupNavigator.callback(url, keepOpen, delimiter).then(() => {\r\n            Log.info(\"UserManager.signoutPopupCallback: successful\");\r\n        });\r\n    }\r\n\r\n    _signout(args, navigator, navigatorParams = {}) {\r\n        return this._signoutStart(args, navigator, navigatorParams).then(navResponse => {\r\n            return this._signoutEnd(navResponse.url);\r\n        });\r\n    }\r\n    _signoutStart(args = {}, navigator, navigatorParams = {}) {\r\n        return navigator.prepare(navigatorParams).then(handle => {\r\n            Log.debug(\"UserManager._signoutStart: got navigator window handle\");\r\n\r\n            return this._loadUser().then(user => {\r\n                Log.debug(\"UserManager._signoutStart: loaded current user from storage\");\r\n\r\n                var revokePromise = this._settings.revokeAccessTokenOnSignout ? this._revokeInternal(user) : Promise.resolve();\r\n                return revokePromise.then(() => {\r\n\r\n                    var id_token = args.id_token_hint || user && user.id_token;\r\n                    if (id_token) {\r\n                        Log.debug(\"UserManager._signoutStart: Setting id_token into signout request\");\r\n                        args.id_token_hint = id_token;\r\n                    }\r\n\r\n                    return this.removeUser().then(() => {\r\n                        Log.debug(\"UserManager._signoutStart: user removed, creating signout request\");\r\n\r\n                        return this.createSignoutRequest(args).then(signoutRequest => {\r\n                            Log.debug(\"UserManager._signoutStart: got signout request\");\r\n\r\n                            navigatorParams.url = signoutRequest.url;\r\n                            if (signoutRequest.state) {\r\n                                navigatorParams.id = signoutRequest.state.id;\r\n                            }\r\n                            return handle.navigate(navigatorParams);\r\n                        });\r\n                    });\r\n                });\r\n            }).catch(err => {\r\n                if (handle.close) {\r\n                    Log.debug(\"UserManager._signoutStart: Error after preparing navigator, closing navigator window\");\r\n                    handle.close();\r\n                }\r\n                throw err;\r\n            });\r\n        });\r\n    }\r\n    _signoutEnd(url) {\r\n        return this.processSignoutResponse(url).then(signoutResponse => {\r\n            Log.debug(\"UserManager._signoutEnd: got signout response\");\r\n\r\n            return signoutResponse;\r\n        });\r\n    }\r\n\r\n    revokeAccessToken() {\r\n        return this._loadUser().then(user => {\r\n            return this._revokeInternal(user, true).then(success => {\r\n                if (success) {\r\n                    Log.debug(\"UserManager.revokeAccessToken: removing token properties from user and re-storing\");\r\n\r\n                    user.access_token = null;\r\n                    user.refresh_token = null;\r\n                    user.expires_at = null;\r\n                    user.token_type = null;\r\n\r\n                    return this.storeUser(user).then(() => {\r\n                        Log.debug(\"UserManager.revokeAccessToken: user stored\");\r\n                        this._events.load(user);\r\n                    });\r\n                }\r\n            });\r\n        }).then(()=>{\r\n            Log.info(\"UserManager.revokeAccessToken: access token revoked successfully\");\r\n        });\r\n    }\r\n\r\n    _revokeInternal(user, required) {\r\n        if (user) {\r\n            var access_token = user.access_token;\r\n            var refresh_token = user.refresh_token;\r\n\r\n            return this._revokeAccessTokenInternal(access_token, required)\r\n                .then(atSuccess => {\r\n                    return this._revokeRefreshTokenInternal(refresh_token, required)\r\n                        .then(rtSuccess => {\r\n                            if (!atSuccess && !rtSuccess) {\r\n                                Log.debug(\"UserManager.revokeAccessToken: no need to revoke due to no token(s), or JWT format\");\r\n                            }\r\n                            \r\n                            return atSuccess || rtSuccess;\r\n                        });\r\n                });\r\n        }\r\n\r\n        return Promise.resolve(false);\r\n    }\r\n\r\n    _revokeAccessTokenInternal(access_token, required) {\r\n        // check for JWT vs. reference token\r\n        if (!access_token || access_token.indexOf('.') >= 0) {\r\n            return Promise.resolve(false);\r\n        }\r\n\r\n        return this._tokenRevocationClient.revoke(access_token, required).then(() => true);\r\n    }\r\n\r\n    _revokeRefreshTokenInternal(refresh_token, required) {\r\n        if (!refresh_token) {\r\n            return Promise.resolve(false);\r\n        }\r\n\r\n        return this._tokenRevocationClient.revoke(refresh_token, required, \"refresh_token\").then(() => true);\r\n    }\r\n\r\n    startSilentRenew() {\r\n        this._silentRenewService.start();\r\n    }\r\n\r\n    stopSilentRenew() {\r\n        this._silentRenewService.stop();\r\n    }\r\n\r\n    get _userStoreKey() {\r\n        return `user:${this.settings.authority}:${this.settings.client_id}`;\r\n    }\r\n\r\n    _loadUser() {\r\n        return this._userStore.get(this._userStoreKey).then(storageString => {\r\n            if (storageString) {\r\n                Log.debug(\"UserManager._loadUser: user storageString loaded\");\r\n                return User.fromStorageString(storageString);\r\n            }\r\n\r\n            Log.debug(\"UserManager._loadUser: no user storageString\");\r\n            return null;\r\n        });\r\n    }\r\n\r\n    storeUser(user) {\r\n        if (user) {\r\n            Log.debug(\"UserManager.storeUser: storing user\");\r\n\r\n            var storageString = user.toStorageString();\r\n            return this._userStore.set(this._userStoreKey, storageString);\r\n        }\r\n        else {\r\n            Log.debug(\"storeUser.storeUser: removing user\");\r\n            return this._userStore.remove(this._userStoreKey);\r\n        }\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { AccessTokenEvents } from './AccessTokenEvents.js';\r\nimport { Event } from './Event.js';\r\n\r\nexport class UserManagerEvents extends AccessTokenEvents {\r\n\r\n    constructor(settings) {\r\n        super(settings);\r\n        this._userLoaded = new Event(\"User loaded\");\r\n        this._userUnloaded = new Event(\"User unloaded\");\r\n        this._silentRenewError = new Event(\"Silent renew error\");\r\n        this._userSignedIn = new Event(\"User signed in\");\r\n        this._userSignedOut = new Event(\"User signed out\");\r\n        this._userSessionChanged = new Event(\"User session changed\");\r\n    }\r\n\r\n    load(user, raiseEvent=true) {\r\n        Log.debug(\"UserManagerEvents.load\");\r\n        super.load(user);\r\n        if (raiseEvent) {\r\n            this._userLoaded.raise(user);\r\n        }\r\n    }\r\n    unload() {\r\n        Log.debug(\"UserManagerEvents.unload\");\r\n        super.unload();\r\n        this._userUnloaded.raise();\r\n    }\r\n\r\n    addUserLoaded(cb) {\r\n        this._userLoaded.addHandler(cb);\r\n    }\r\n    removeUserLoaded(cb) {\r\n        this._userLoaded.removeHandler(cb);\r\n    }\r\n\r\n    addUserUnloaded(cb) {\r\n        this._userUnloaded.addHandler(cb);\r\n    }\r\n    removeUserUnloaded(cb) {\r\n        this._userUnloaded.removeHandler(cb);\r\n    }\r\n\r\n    addSilentRenewError(cb) {\r\n        this._silentRenewError.addHandler(cb);\r\n    }\r\n    removeSilentRenewError(cb) {\r\n        this._silentRenewError.removeHandler(cb);\r\n    }\r\n    _raiseSilentRenewError(e) {\r\n        Log.debug(\"UserManagerEvents._raiseSilentRenewError\", e.message);\r\n        this._silentRenewError.raise(e);\r\n    }\r\n\r\n    addUserSignedIn(cb) {\r\n        this._userSignedIn.addHandler(cb);\r\n    }\r\n    removeUserSignedIn(cb) {\r\n        this._userSignedIn.removeHandler(cb);\r\n    }\r\n    _raiseUserSignedIn() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSignedIn\");\r\n        this._userSignedIn.raise();\r\n    }\r\n\r\n    addUserSignedOut(cb) {\r\n        this._userSignedOut.addHandler(cb);\r\n    }\r\n    removeUserSignedOut(cb) {\r\n        this._userSignedOut.removeHandler(cb);\r\n    }\r\n    _raiseUserSignedOut() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSignedOut\");\r\n        this._userSignedOut.raise();\r\n    }\r\n\r\n    addUserSessionChanged(cb) {\r\n        this._userSessionChanged.addHandler(cb);\r\n    }\r\n    removeUserSessionChanged(cb) {\r\n        this._userSessionChanged.removeHandler(cb);\r\n    }\r\n    _raiseUserSessionChanged() {\r\n        Log.debug(\"UserManagerEvents._raiseUserSessionChanged\");\r\n        this._userSessionChanged.raise();\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { OidcClientSettings } from './OidcClientSettings.js';\r\nimport { RedirectNavigator } from './RedirectNavigator.js';\r\nimport { PopupNavigator } from './PopupNavigator.js';\r\nimport { IFrameNavigator } from './IFrameNavigator.js';\r\nimport { WebStorageStateStore } from './WebStorageStateStore.js';\r\nimport { Global } from './Global.js';\r\nimport { SigninRequest } from './SigninRequest.js';\r\n\r\nconst DefaultAccessTokenExpiringNotificationTime = 60;\r\nconst DefaultCheckSessionInterval = 2000;\r\n\r\nexport class UserManagerSettings extends OidcClientSettings {\r\n    constructor({\r\n        popup_redirect_uri,\r\n        popup_post_logout_redirect_uri,\r\n        popupWindowFeatures,\r\n        popupWindowTarget,\r\n        silent_redirect_uri,\r\n        silentRequestTimeout,\r\n        automaticSilentRenew = false,\r\n        validateSubOnSilentRenew = false,\r\n        includeIdTokenInSilentRenew = true,\r\n        monitorSession = true,\r\n        monitorAnonymousSession = false,\r\n        checkSessionInterval = DefaultCheckSessionInterval,\r\n        stopCheckSessionOnError = true,\r\n        query_status_response_type,\r\n        revokeAccessTokenOnSignout = false,\r\n        accessTokenExpiringNotificationTime = DefaultAccessTokenExpiringNotificationTime,\r\n        redirectNavigator = new RedirectNavigator(),\r\n        popupNavigator = new PopupNavigator(),\r\n        iframeNavigator = new IFrameNavigator(),\r\n        userStore = new WebStorageStateStore({ store: Global.sessionStorage })\r\n    } = {}) {\r\n        super(arguments[0]);\r\n\r\n        this._popup_redirect_uri = popup_redirect_uri;\r\n        this._popup_post_logout_redirect_uri = popup_post_logout_redirect_uri;\r\n        this._popupWindowFeatures = popupWindowFeatures;\r\n        this._popupWindowTarget = popupWindowTarget;\r\n\r\n        this._silent_redirect_uri = silent_redirect_uri;\r\n        this._silentRequestTimeout = silentRequestTimeout;\r\n        this._automaticSilentRenew = automaticSilentRenew;\r\n        this._validateSubOnSilentRenew = validateSubOnSilentRenew;\r\n        this._includeIdTokenInSilentRenew = includeIdTokenInSilentRenew;\r\n        this._accessTokenExpiringNotificationTime = accessTokenExpiringNotificationTime;\r\n\r\n        this._monitorSession = monitorSession;\r\n        this._monitorAnonymousSession = monitorAnonymousSession;\r\n        this._checkSessionInterval = checkSessionInterval;\r\n        this._stopCheckSessionOnError = stopCheckSessionOnError;\r\n        if (query_status_response_type) {\r\n            this._query_status_response_type = query_status_response_type;\r\n        } \r\n        else if (arguments[0] && arguments[0].response_type) {\r\n            this._query_status_response_type = SigninRequest.isOidc(arguments[0].response_type) ? \"id_token\" : \"code\";\r\n        }\r\n        else {\r\n            this._query_status_response_type = \"id_token\";\r\n        }\r\n        this._revokeAccessTokenOnSignout = revokeAccessTokenOnSignout;\r\n\r\n        this._redirectNavigator = redirectNavigator;\r\n        this._popupNavigator = popupNavigator;\r\n        this._iframeNavigator = iframeNavigator;\r\n\r\n        this._userStore = userStore;\r\n    }\r\n\r\n    get popup_redirect_uri() {\r\n        return this._popup_redirect_uri;\r\n    }\r\n    get popup_post_logout_redirect_uri() {\r\n        return this._popup_post_logout_redirect_uri;\r\n    }\r\n    get popupWindowFeatures() {\r\n        return this._popupWindowFeatures;\r\n    }\r\n    get popupWindowTarget() {\r\n        return this._popupWindowTarget;\r\n    }\r\n\r\n    get silent_redirect_uri() {\r\n        return this._silent_redirect_uri;\r\n    }\r\n     get silentRequestTimeout() {\r\n        return this._silentRequestTimeout;\r\n    }\r\n    get automaticSilentRenew() {\r\n        return this._automaticSilentRenew;\r\n    }\r\n    get validateSubOnSilentRenew() {\r\n        return this._validateSubOnSilentRenew;\r\n    }\r\n    get includeIdTokenInSilentRenew() {\r\n        return this._includeIdTokenInSilentRenew;\r\n    }\r\n    get accessTokenExpiringNotificationTime() {\r\n        return this._accessTokenExpiringNotificationTime;\r\n    }\r\n\r\n    get monitorSession() {\r\n        return this._monitorSession;\r\n    }\r\n    get monitorAnonymousSession() {\r\n        return this._monitorAnonymousSession;\r\n    }\r\n    get checkSessionInterval() {\r\n        return this._checkSessionInterval;\r\n    }\r\n    get stopCheckSessionOnError(){\r\n        return this._stopCheckSessionOnError;\r\n    }\r\n    get query_status_response_type(){\r\n        return this._query_status_response_type;\r\n    }\r\n    get revokeAccessTokenOnSignout() {\r\n        return this._revokeAccessTokenOnSignout;\r\n    }\r\n\r\n    get redirectNavigator() {\r\n        return this._redirectNavigator;\r\n    }\r\n    get popupNavigator() {\r\n        return this._popupNavigator;\r\n    }\r\n    get iframeNavigator() {\r\n        return this._iframeNavigator;\r\n    }\r\n\r\n    get userStore() {\r\n        return this._userStore;\r\n    }\r\n}\r\n","// Copyright (c) Brock Allen & Dominick Baier. All rights reserved.\r\n// Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.\r\n\r\nimport { Log } from './Log.js';\r\nimport { Global } from './Global.js';\r\n\r\nexport class WebStorageStateStore {\r\n    constructor({prefix = \"oidc.\", store = Global.localStorage} = {}) {\r\n        this._store = store;\r\n        this._prefix = prefix;\r\n    }\r\n\r\n    set(key, value) {\r\n        Log.debug(\"WebStorageStateStore.set\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        this._store.setItem(key, value);\r\n\r\n        return Promise.resolve();\r\n    }\r\n\r\n    get(key) {\r\n        Log.debug(\"WebStorageStateStore.get\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        let item = this._store.getItem(key);\r\n\r\n        return Promise.resolve(item);\r\n    }\r\n\r\n    remove(key) {\r\n        Log.debug(\"WebStorageStateStore.remove\", key);\r\n\r\n        key = this._prefix + key;\r\n\r\n        let item = this._store.getItem(key);\r\n        this._store.removeItem(key);\r\n\r\n        return Promise.resolve(item);\r\n    }\r\n\r\n    getAllKeys() {\r\n        Log.debug(\"WebStorageStateStore.getAllKeys\");\r\n\r\n        var keys = [];\r\n\r\n        for (let index = 0; index < this._store.length; index++) {\r\n            let key = this._store.key(index);\r\n\r\n            if (key.indexOf(this._prefix) === 0) {\r\n                keys.push(key.substr(this._prefix.length));\r\n            }\r\n        }\r\n\r\n        return Promise.resolve(keys);\r\n    }\r\n}\r\n","import { jws, KEYUTIL as KeyUtil, X509, crypto, hextob64u, b64tohex } from '../../jsrsasign/dist/jsrsasign.js';\r\n\r\nconst AllowedSigningAlgs = ['RS256', 'RS384', 'RS512', 'PS256', 'PS384', 'PS512', 'ES256', 'ES384', 'ES512'];\r\n\r\nexport {\r\n    jws,\r\n    KeyUtil,\r\n    X509,\r\n    crypto,\r\n    hextob64u,\r\n    b64tohex,\r\n    AllowedSigningAlgs\r\n};\r\n","import uuid4 from 'uuid/v4';\r\n\r\n/**\r\n * Generates RFC4122 version 4 guid ()\r\n */\r\n\r\nexport default function random() {\r\n  return uuid4().replace(/-/g, '');\r\n}\r\n","const Version = \"1.10.1\"; export {Version};"],"sourceRoot":""}"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly ILogger<HomeController> _logger;\n\n    public HomeController(ILogger<HomeController> logger)\n    {\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    public async Task<IActionResult> CallApi()\n    {\n        var accessToken = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = new HttpClient();\n        client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue(\"Bearer\", accessToken);\n        var content = await client.GetStringAsync(\"https://localhost:6001/identity\");\n\n        var obj = JsonSerializer.Deserialize<JsonElement>(content);\n        ViewBag.Json = obj.ToString();\n        return View(\"json\");\n    }\n\n    public IActionResult Logout()\n    {\n        return SignOut(\"Cookies\", \"oidc\");\n    }\n\n    [ResponseCache(Duration = 0, Location = ResponseCacheLocation.None, NoStore = true)]\n    public IActionResult Error()\n    {\n        return View(new ErrorViewModel { RequestId = Activity.Current?.Id ?? HttpContext.TraceIdentifier });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using System.Diagnostics;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Net.Http.Headers;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Models/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class ErrorViewModel\n{\n    public string RequestId { get; set; }\n\n    public bool ShowRequestId => !string.IsNullOrEmpty(RequestId);\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/MvcClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.OpenIdConnect\" />\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <Content Update=\"Views\\Shared\\Json.cshtml\">\n      <ExcludeFromSingleFile>true</ExcludeFromSingleFile>\n      <CopyToPublishDirectory>PreserveNewest</CopyToPublishDirectory>\n    </Content>\n  </ItemGroup>\n\n</Project>"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nJwtSecurityTokenHandler.DefaultMapInboundClaims = false;\n\n\nvar builder = WebApplication.CreateBuilder(args);\n\nbuilder.Services.AddControllersWithViews();\nbuilder.Services\n    .AddAuthentication(options =>\n    {\n        options.DefaultScheme = \"Cookies\";\n        options.DefaultChallengeScheme = \"oidc\";\n    })\n    .AddCookie(\"Cookies\")\n    .AddOpenIdConnect(\"oidc\", options =>\n    {\n        options.Authority = \"https://localhost:5001\";\n\n        options.ClientId = \"mvc\";\n        options.ClientSecret = \"secret\";\n        options.ResponseType = \"code\";\n\n        options.Scope.Add(\"api1\");\n\n        options.SaveTokens = true;\n    });\n\n\nusing (var app = builder.Build())\n{\n    if (app.Environment.IsDevelopment())\n        app.UseDeveloperExceptionPage();\n    else\n        app.UseExceptionHandler(\"/Home/Error\");\n\n    app.UseStaticFiles();\n    app.UseRouting();\n    app.UseAuthentication();\n    app.UseAuthorization();\n    app.MapDefaultControllerRoute().RequireAuthorization();\n\n    await app.RunAsync();\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"MvcClient\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5002\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore.Builder;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.Extensions.DependencyInjection;\nusing Microsoft.Extensions.Hosting;\nusing System.IdentityModel.Tokens.Jwt;\n\nnamespace MvcClient\n{\n    public class Startup\n    {\n        public void ConfigureServices(IServiceCollection services)\n        {\n            services.AddControllersWithViews();\n\n            JwtSecurityTokenHandler.DefaultMapInboundClaims = false;\n\n            services.AddAuthentication(options =>\n            {\n                options.DefaultScheme = \"Cookies\";\n                options.DefaultChallengeScheme = \"oidc\";\n            })\n            .AddCookie(\"Cookies\")\n            .AddOpenIdConnect(\"oidc\", options =>\n            {\n                options.Authority = \"https://localhost:5001\";\n\n                options.ClientId = \"mvc\";\n                options.ClientSecret = \"secret\";\n                options.ResponseType = \"code\";\n                \n                options.Scope.Add(\"api1\");\n\n                options.SaveTokens = true;\n            });\n        }\n\n        public void Configure(IApplicationBuilder app, IWebHostEnvironment env)\n        {\n            if (env.IsDevelopment())\n            {\n                app.UseDeveloperExceptionPage();\n            }\n            else\n            {\n                app.UseExceptionHandler(\"/Home/Error\");\n            }\n\n            app.UseStaticFiles();\n\n            app.UseRouting();\n            app.UseAuthentication();\n            app.UseAuthorization();\n\n            app.UseEndpoints(endpoints =>\n            {\n                endpoints.MapDefaultControllerRoute()\n                    .RequireAuthorization();\n            });\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Views/Home/Index.cshtml",
    "content": "@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Views/Home/Privacy.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Privacy Policy\";\n}\n<h1>@ViewData[\"Title\"]</h1>\n\n<p>Use this page to detail your site's privacy policy.</p>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Views/Shared/Error.cshtml",
    "content": "﻿@model ErrorViewModel\n@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n\n@if (Model.ShowRequestId)\n{\n    <p>\n        <strong>Request ID:</strong> <code>@Model.RequestId</code>\n    </p>\n}\n\n<h3>Development Mode</h3>\n<p>\n    Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.\n</p>\n<p>\n    <strong>The Development environment shouldn't be enabled for deployed applications.</strong>\n    It can result in displaying sensitive information from exceptions to end users.\n    For local debugging, enable the <strong>Development</strong> environment by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>\n    and restarting the app.\n</p>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcClient</title>\n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <header>\n        <nav class=\"navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3\">\n            <div class=\"container\">\n                <a class=\"navbar-brand\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">MvcClient</a>\n                <button class=\"navbar-toggler\" type=\"button\" data-toggle=\"collapse\" data-target=\".navbar-collapse\" aria-controls=\"navbarSupportedContent\"\n                        aria-expanded=\"false\" aria-label=\"Toggle navigation\">\n                    <span class=\"navbar-toggler-icon\"></span>\n                </button>\n                <div class=\"navbar-collapse collapse d-sm-inline-flex flex-sm-row-reverse\">\n                    <ul class=\"navbar-nav flex-grow-1\">\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">Home</a>\n                        </li>\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Logout\">Logout</a>\n                        </li>\n                    </ul>\n                </div>\n            </div>\n        </nav>\n    </header>\n    <div class=\"container\">\n        <main role=\"main\" class=\"pb-3\">\n            @RenderBody()\n        </main>\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n    <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    @RenderSection(\"Scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Views/Shared/_ValidationScriptsPartial.cshtml",
    "content": "﻿<script src=\"~/lib/jquery-validation/dist/jquery.validate.min.js\"></script>\n<script src=\"~/lib/jquery-validation-unobtrusive/jquery.validate.unobtrusive.min.js\"></script>\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Views/Shared/json.cshtml",
    "content": "<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/appsettings.Development.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Debug\",\n      \"System\": \"Information\",\n      \"Microsoft\": \"Information\"\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/appsettings.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Information\",\n      \"Microsoft\": \"Warning\",\n      \"Microsoft.Hosting.Lifetime\": \"Information\"\n    }\n  },\n  \"AllowedHosts\": \"*\"\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/wwwroot/css/site.css",
    "content": "﻿/* Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\nfor details on configuring this project to bundle and minify static web assets. */\n\na.navbar-brand {\n  white-space: normal;\n  text-align: center;\n  word-break: break-all;\n}\n\n/* Provide sufficient contrast against white background */\na {\n  color: #0366d6;\n}\n\n.btn-primary {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n.nav-pills .nav-link.active, .nav-pills .show > .nav-link {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  font-size: 14px;\n}\n@media (min-width: 768px) {\n  html {\n    font-size: 16px;\n  }\n}\n\n.border-top {\n  border-top: 1px solid #e5e5e5;\n}\n.border-bottom {\n  border-bottom: 1px solid #e5e5e5;\n}\n\n.box-shadow {\n  box-shadow: 0 .25rem .75rem rgba(0, 0, 0, .05);\n}\n\nbutton.accept-policy {\n  font-size: 1rem;\n  line-height: inherit;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  position: relative;\n  min-height: 100%;\n}\n\nbody {\n  /* Margin bottom by footer height */\n  margin-bottom: 60px;\n}\n.footer {\n  position: absolute;\n  bottom: 0;\n  width: 100%;\n  white-space: nowrap;\n  line-height: 60px; /* Vertically center the text there */\n}\n"
  },
  {
    "path": "samples/Quickstarts/4_JavaScriptClient/src/MvcClient/wwwroot/js/site.js",
    "content": "﻿// Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\n// for details on configuring this project to bundle and minify static web assets.\n\n// Write your JavaScript code.\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/Quickstart.sln",
    "content": "﻿\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 15.0.26124.0\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{BD8BA25C-A91D-419D-99B6-B575ADD6D061}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer\", \"src\\IdentityServer\\IdentityServer.csproj\", \"{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcClient\", \"src\\MvcClient\\MvcClient.csproj\", \"{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Api\", \"..\\Shared\\src\\Api\\Api.csproj\", \"{F555BE49-9B75-4379-96A5-A0490B18EDDB}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Client\", \"..\\Shared\\src\\Client\\Client.csproj\", \"{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tDebug|x64 = Debug|x64\n\t\tDebug|x86 = Debug|x86\n\t\tRelease|Any CPU = Release|Any CPU\n\t\tRelease|x64 = Release|x64\n\t\tRelease|x86 = Release|x86\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x64.Build.0 = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E}.Release|x86.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x64.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x86.Build.0 = Release|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Release|x64.Build.0 = Release|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{F555BE49-9B75-4379-96A5-A0490B18EDDB}.Release|x86.Build.0 = Release|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Release|x64.Build.0 = Release|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{EFC08DC4-FF0B-4B06-A784-4F85C4CCB41C}.Release|x86.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{79D1F107-F3AF-4A93-BF5D-49EF6A46E50E} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {84D5AF06-1243-46F1-9D58-70ED572832C3}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/Quickstart.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft\n Written by Alexander Higgins https://github.com/alexhiggins732/ \n \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code for this software can be found at https://github.com/alexhiggins732/IdentityServer8\n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n\n*/\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Config.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Secret = IdentityServer8.Models.Secret;\n\npublic static class Config\n{\n    public static IEnumerable<IdentityResource> IdentityResources =>\n        new List<IdentityResource>\n        {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n        };\n\n\n    public static IEnumerable<ApiScope> ApiScopes =>\n        new List<ApiScope>\n        {\n            new ApiScope(\"api1\", \"My API\")\n        };\n\n    public static IEnumerable<Client> Clients =>\n        new List<Client>\n        {\n            // machine to machine client\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                // scopes that client has access to\n                AllowedScopes = { \"api1\" }\n            },\n            \n            // interactive ASP.NET Core MVC client\n            new Client\n            {\n                ClientId = \"mvc\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.Code,\n                \n                // where to redirect to after login\n                RedirectUris = { \"https://localhost:5002/signin-oidc\" },\n\n                // where to redirect to after logout\n                PostLogoutRedirectUris = { \"https://localhost:5002/signout-callback-oidc\" },\n\n                AllowedScopes = new List<string>\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    \"api1\"\n                }\n            }\n        };\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Data/Migrations/IdentityServer/ConfigurationDb/20200625203625_InitialIdentityServerConfigurationDbMigration.Designer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\nusing Microsoft.EntityFrameworkCore.Infrastructure;\nusing Microsoft.EntityFrameworkCore.Metadata;\nusing Microsoft.EntityFrameworkCore.Migrations;\n\nnamespace IdentityServer.Data.Migrations.IdentityServer.ConfigurationDb\n{\n    [DbContext(typeof(ConfigurationDbContext))]\n    [Migration(\"20200625203625_InitialIdentityServerConfigurationDbMigration\")]\n    partial class InitialIdentityServerConfigurationDbMigration\n    {\n        protected override void BuildTargetModel(ModelBuilder modelBuilder)\n        {\n#pragma warning disable 612, 618\n            modelBuilder\n                .HasAnnotation(\"ProductVersion\", \"3.1.5\")\n                .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n                .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResource\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"AllowedAccessTokenSigningAlgorithms\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<string>(\"DisplayName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"LastAccessed\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Name\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"NonEditable\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"ShowInDiscoveryDocument\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"Updated\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"Name\")\n                        .IsUnique();\n\n                    b.ToTable(\"ApiResources\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceScope\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Scope\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceScopes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceSecret\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(4000)\")\n                        .HasMaxLength(4000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceSecrets\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScope\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<string>(\"DisplayName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Emphasize\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"Name\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Required\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"ShowInDiscoveryDocument\")\n                        .HasColumnType(\"bit\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"Name\")\n                        .IsUnique();\n\n                    b.ToTable(\"ApiScopes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ScopeId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ScopeId\");\n\n                    b.ToTable(\"ApiScopeClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<int>(\"ScopeId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ScopeId\");\n\n                    b.ToTable(\"ApiScopeProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.Client\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"AbsoluteRefreshTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<int>(\"AccessTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<int>(\"AccessTokenType\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"AllowAccessTokensViaBrowser\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AllowOfflineAccess\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AllowPlainTextPkce\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AllowRememberConsent\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"AllowedIdentityTokenSigningAlgorithms\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<bool>(\"AlwaysIncludeUserClaimsInIdToken\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AlwaysSendClientClaims\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<int>(\"AuthorizationCodeLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"BackChannelLogoutSessionRequired\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"BackChannelLogoutUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<string>(\"ClientClaimsPrefix\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<int?>(\"ConsentLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<int>(\"DeviceCodeLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"EnableLocalLogin\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"FrontChannelLogoutSessionRequired\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"FrontChannelLogoutUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<int>(\"IdentityTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"IncludeJwtId\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"LastAccessed\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"LogoUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<bool>(\"NonEditable\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"PairWiseSubjectSalt\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ProtocolType\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<int>(\"RefreshTokenExpiration\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<int>(\"RefreshTokenUsage\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"RequireClientSecret\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"RequireConsent\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"RequirePkce\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"RequireRequestObject\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<int>(\"SlidingRefreshTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"UpdateAccessTokenClaimsOnRefresh\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"Updated\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"UserCodeType\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<int?>(\"UserSsoLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\")\n                        .IsUnique();\n\n                    b.ToTable(\"Clients\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientCorsOrigin\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Origin\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(150)\")\n                        .HasMaxLength(150);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientCorsOrigins\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientGrantType\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"GrantType\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientGrantTypes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientIdPRestriction\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Provider\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientIdPRestrictions\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientPostLogoutRedirectUri\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"PostLogoutRedirectUri\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientPostLogoutRedirectUris\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientRedirectUri\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"RedirectUri\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientRedirectUris\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientScope\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Scope\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientScopes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientSecret\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(4000)\")\n                        .HasMaxLength(4000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientSecrets\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<string>(\"DisplayName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Emphasize\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"Name\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"NonEditable\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Required\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"ShowInDiscoveryDocument\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"Updated\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"Name\")\n                        .IsUnique();\n\n                    b.ToTable(\"IdentityResources\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"IdentityResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"IdentityResourceId\");\n\n                    b.ToTable(\"IdentityResourceClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"IdentityResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"IdentityResourceId\");\n\n                    b.ToTable(\"IdentityResourceProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"UserClaims\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceScope\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"Scopes\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceSecret\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"Secrets\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiScope\", \"Scope\")\n                        .WithMany(\"UserClaims\")\n                        .HasForeignKey(\"ScopeId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiScope\", \"Scope\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"ScopeId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"Claims\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientCorsOrigin\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"AllowedCorsOrigins\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientGrantType\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"AllowedGrantTypes\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientIdPRestriction\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"IdentityProviderRestrictions\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientPostLogoutRedirectUri\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"PostLogoutRedirectUris\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientRedirectUri\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"RedirectUris\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientScope\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"AllowedScopes\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientSecret\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"ClientSecrets\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", \"IdentityResource\")\n                        .WithMany(\"UserClaims\")\n                        .HasForeignKey(\"IdentityResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", \"IdentityResource\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"IdentityResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n#pragma warning restore 612, 618\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Data/Migrations/IdentityServer/ConfigurationDb/20200625203625_InitialIdentityServerConfigurationDbMigration.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.EntityFrameworkCore.Migrations;\n\nnamespace IdentityServer.Data.Migrations.IdentityServer.ConfigurationDb\n{\n    public partial class InitialIdentityServerConfigurationDbMigration : Migration\n    {\n        protected override void Up(MigrationBuilder migrationBuilder)\n        {\n            migrationBuilder.CreateTable(\n                name: \"ApiResources\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Enabled = table.Column<bool>(nullable: false),\n                    Name = table.Column<string>(maxLength: 200, nullable: false),\n                    DisplayName = table.Column<string>(maxLength: 200, nullable: true),\n                    Description = table.Column<string>(maxLength: 1000, nullable: true),\n                    AllowedAccessTokenSigningAlgorithms = table.Column<string>(maxLength: 100, nullable: true),\n                    ShowInDiscoveryDocument = table.Column<bool>(nullable: false),\n                    Created = table.Column<DateTime>(nullable: false),\n                    Updated = table.Column<DateTime>(nullable: true),\n                    LastAccessed = table.Column<DateTime>(nullable: true),\n                    NonEditable = table.Column<bool>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ApiResources\", x => x.Id);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ApiScopes\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Enabled = table.Column<bool>(nullable: false),\n                    Name = table.Column<string>(maxLength: 200, nullable: false),\n                    DisplayName = table.Column<string>(maxLength: 200, nullable: true),\n                    Description = table.Column<string>(maxLength: 1000, nullable: true),\n                    Required = table.Column<bool>(nullable: false),\n                    Emphasize = table.Column<bool>(nullable: false),\n                    ShowInDiscoveryDocument = table.Column<bool>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ApiScopes\", x => x.Id);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"Clients\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Enabled = table.Column<bool>(nullable: false),\n                    ClientId = table.Column<string>(maxLength: 200, nullable: false),\n                    ProtocolType = table.Column<string>(maxLength: 200, nullable: false),\n                    RequireClientSecret = table.Column<bool>(nullable: false),\n                    ClientName = table.Column<string>(maxLength: 200, nullable: true),\n                    Description = table.Column<string>(maxLength: 1000, nullable: true),\n                    ClientUri = table.Column<string>(maxLength: 2000, nullable: true),\n                    LogoUri = table.Column<string>(maxLength: 2000, nullable: true),\n                    RequireConsent = table.Column<bool>(nullable: false),\n                    AllowRememberConsent = table.Column<bool>(nullable: false),\n                    AlwaysIncludeUserClaimsInIdToken = table.Column<bool>(nullable: false),\n                    RequirePkce = table.Column<bool>(nullable: false),\n                    AllowPlainTextPkce = table.Column<bool>(nullable: false),\n                    RequireRequestObject = table.Column<bool>(nullable: false),\n                    AllowAccessTokensViaBrowser = table.Column<bool>(nullable: false),\n                    FrontChannelLogoutUri = table.Column<string>(maxLength: 2000, nullable: true),\n                    FrontChannelLogoutSessionRequired = table.Column<bool>(nullable: false),\n                    BackChannelLogoutUri = table.Column<string>(maxLength: 2000, nullable: true),\n                    BackChannelLogoutSessionRequired = table.Column<bool>(nullable: false),\n                    AllowOfflineAccess = table.Column<bool>(nullable: false),\n                    IdentityTokenLifetime = table.Column<int>(nullable: false),\n                    AllowedIdentityTokenSigningAlgorithms = table.Column<string>(maxLength: 100, nullable: true),\n                    AccessTokenLifetime = table.Column<int>(nullable: false),\n                    AuthorizationCodeLifetime = table.Column<int>(nullable: false),\n                    ConsentLifetime = table.Column<int>(nullable: true),\n                    AbsoluteRefreshTokenLifetime = table.Column<int>(nullable: false),\n                    SlidingRefreshTokenLifetime = table.Column<int>(nullable: false),\n                    RefreshTokenUsage = table.Column<int>(nullable: false),\n                    UpdateAccessTokenClaimsOnRefresh = table.Column<bool>(nullable: false),\n                    RefreshTokenExpiration = table.Column<int>(nullable: false),\n                    AccessTokenType = table.Column<int>(nullable: false),\n                    EnableLocalLogin = table.Column<bool>(nullable: false),\n                    IncludeJwtId = table.Column<bool>(nullable: false),\n                    AlwaysSendClientClaims = table.Column<bool>(nullable: false),\n                    ClientClaimsPrefix = table.Column<string>(maxLength: 200, nullable: true),\n                    PairWiseSubjectSalt = table.Column<string>(maxLength: 200, nullable: true),\n                    Created = table.Column<DateTime>(nullable: false),\n                    Updated = table.Column<DateTime>(nullable: true),\n                    LastAccessed = table.Column<DateTime>(nullable: true),\n                    UserSsoLifetime = table.Column<int>(nullable: true),\n                    UserCodeType = table.Column<string>(maxLength: 100, nullable: true),\n                    DeviceCodeLifetime = table.Column<int>(nullable: false),\n                    NonEditable = table.Column<bool>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_Clients\", x => x.Id);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"IdentityResources\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Enabled = table.Column<bool>(nullable: false),\n                    Name = table.Column<string>(maxLength: 200, nullable: false),\n                    DisplayName = table.Column<string>(maxLength: 200, nullable: true),\n                    Description = table.Column<string>(maxLength: 1000, nullable: true),\n                    Required = table.Column<bool>(nullable: false),\n                    Emphasize = table.Column<bool>(nullable: false),\n                    ShowInDiscoveryDocument = table.Column<bool>(nullable: false),\n                    Created = table.Column<DateTime>(nullable: false),\n                    Updated = table.Column<DateTime>(nullable: true),\n                    NonEditable = table.Column<bool>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_IdentityResources\", x => x.Id);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ApiResourceClaims\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Type = table.Column<string>(maxLength: 200, nullable: false),\n                    ApiResourceId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ApiResourceClaims\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ApiResourceClaims_ApiResources_ApiResourceId\",\n                        column: x => x.ApiResourceId,\n                        principalTable: \"ApiResources\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ApiResourceProperties\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Key = table.Column<string>(maxLength: 250, nullable: false),\n                    Value = table.Column<string>(maxLength: 2000, nullable: false),\n                    ApiResourceId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ApiResourceProperties\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ApiResourceProperties_ApiResources_ApiResourceId\",\n                        column: x => x.ApiResourceId,\n                        principalTable: \"ApiResources\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ApiResourceScopes\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Scope = table.Column<string>(maxLength: 200, nullable: false),\n                    ApiResourceId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ApiResourceScopes\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ApiResourceScopes_ApiResources_ApiResourceId\",\n                        column: x => x.ApiResourceId,\n                        principalTable: \"ApiResources\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ApiResourceSecrets\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Description = table.Column<string>(maxLength: 1000, nullable: true),\n                    Value = table.Column<string>(maxLength: 4000, nullable: false),\n                    Expiration = table.Column<DateTime>(nullable: true),\n                    Type = table.Column<string>(maxLength: 250, nullable: false),\n                    Created = table.Column<DateTime>(nullable: false),\n                    ApiResourceId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ApiResourceSecrets\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ApiResourceSecrets_ApiResources_ApiResourceId\",\n                        column: x => x.ApiResourceId,\n                        principalTable: \"ApiResources\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ApiScopeClaims\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Type = table.Column<string>(maxLength: 200, nullable: false),\n                    ScopeId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ApiScopeClaims\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ApiScopeClaims_ApiScopes_ScopeId\",\n                        column: x => x.ScopeId,\n                        principalTable: \"ApiScopes\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ApiScopeProperties\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Key = table.Column<string>(maxLength: 250, nullable: false),\n                    Value = table.Column<string>(maxLength: 2000, nullable: false),\n                    ScopeId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ApiScopeProperties\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ApiScopeProperties_ApiScopes_ScopeId\",\n                        column: x => x.ScopeId,\n                        principalTable: \"ApiScopes\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ClientClaims\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Type = table.Column<string>(maxLength: 250, nullable: false),\n                    Value = table.Column<string>(maxLength: 250, nullable: false),\n                    ClientId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ClientClaims\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ClientClaims_Clients_ClientId\",\n                        column: x => x.ClientId,\n                        principalTable: \"Clients\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ClientCorsOrigins\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Origin = table.Column<string>(maxLength: 150, nullable: false),\n                    ClientId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ClientCorsOrigins\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ClientCorsOrigins_Clients_ClientId\",\n                        column: x => x.ClientId,\n                        principalTable: \"Clients\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ClientGrantTypes\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    GrantType = table.Column<string>(maxLength: 250, nullable: false),\n                    ClientId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ClientGrantTypes\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ClientGrantTypes_Clients_ClientId\",\n                        column: x => x.ClientId,\n                        principalTable: \"Clients\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ClientIdPRestrictions\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Provider = table.Column<string>(maxLength: 200, nullable: false),\n                    ClientId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ClientIdPRestrictions\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ClientIdPRestrictions_Clients_ClientId\",\n                        column: x => x.ClientId,\n                        principalTable: \"Clients\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ClientPostLogoutRedirectUris\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    PostLogoutRedirectUri = table.Column<string>(maxLength: 2000, nullable: false),\n                    ClientId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ClientPostLogoutRedirectUris\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ClientPostLogoutRedirectUris_Clients_ClientId\",\n                        column: x => x.ClientId,\n                        principalTable: \"Clients\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ClientProperties\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Key = table.Column<string>(maxLength: 250, nullable: false),\n                    Value = table.Column<string>(maxLength: 2000, nullable: false),\n                    ClientId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ClientProperties\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ClientProperties_Clients_ClientId\",\n                        column: x => x.ClientId,\n                        principalTable: \"Clients\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ClientRedirectUris\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    RedirectUri = table.Column<string>(maxLength: 2000, nullable: false),\n                    ClientId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ClientRedirectUris\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ClientRedirectUris_Clients_ClientId\",\n                        column: x => x.ClientId,\n                        principalTable: \"Clients\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ClientScopes\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Scope = table.Column<string>(maxLength: 200, nullable: false),\n                    ClientId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ClientScopes\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ClientScopes_Clients_ClientId\",\n                        column: x => x.ClientId,\n                        principalTable: \"Clients\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"ClientSecrets\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Description = table.Column<string>(maxLength: 2000, nullable: true),\n                    Value = table.Column<string>(maxLength: 4000, nullable: false),\n                    Expiration = table.Column<DateTime>(nullable: true),\n                    Type = table.Column<string>(maxLength: 250, nullable: false),\n                    Created = table.Column<DateTime>(nullable: false),\n                    ClientId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_ClientSecrets\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_ClientSecrets_Clients_ClientId\",\n                        column: x => x.ClientId,\n                        principalTable: \"Clients\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"IdentityResourceClaims\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Type = table.Column<string>(maxLength: 200, nullable: false),\n                    IdentityResourceId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_IdentityResourceClaims\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_IdentityResourceClaims_IdentityResources_IdentityResourceId\",\n                        column: x => x.IdentityResourceId,\n                        principalTable: \"IdentityResources\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"IdentityResourceProperties\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                    Key = table.Column<string>(maxLength: 250, nullable: false),\n                    Value = table.Column<string>(maxLength: 2000, nullable: false),\n                    IdentityResourceId = table.Column<int>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_IdentityResourceProperties\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_IdentityResourceProperties_IdentityResources_IdentityResourceId\",\n                        column: x => x.IdentityResourceId,\n                        principalTable: \"IdentityResources\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ApiResourceClaims_ApiResourceId\",\n                table: \"ApiResourceClaims\",\n                column: \"ApiResourceId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ApiResourceProperties_ApiResourceId\",\n                table: \"ApiResourceProperties\",\n                column: \"ApiResourceId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ApiResources_Name\",\n                table: \"ApiResources\",\n                column: \"Name\",\n                unique: true);\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ApiResourceScopes_ApiResourceId\",\n                table: \"ApiResourceScopes\",\n                column: \"ApiResourceId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ApiResourceSecrets_ApiResourceId\",\n                table: \"ApiResourceSecrets\",\n                column: \"ApiResourceId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ApiScopeClaims_ScopeId\",\n                table: \"ApiScopeClaims\",\n                column: \"ScopeId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ApiScopeProperties_ScopeId\",\n                table: \"ApiScopeProperties\",\n                column: \"ScopeId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ApiScopes_Name\",\n                table: \"ApiScopes\",\n                column: \"Name\",\n                unique: true);\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ClientClaims_ClientId\",\n                table: \"ClientClaims\",\n                column: \"ClientId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ClientCorsOrigins_ClientId\",\n                table: \"ClientCorsOrigins\",\n                column: \"ClientId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ClientGrantTypes_ClientId\",\n                table: \"ClientGrantTypes\",\n                column: \"ClientId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ClientIdPRestrictions_ClientId\",\n                table: \"ClientIdPRestrictions\",\n                column: \"ClientId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ClientPostLogoutRedirectUris_ClientId\",\n                table: \"ClientPostLogoutRedirectUris\",\n                column: \"ClientId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ClientProperties_ClientId\",\n                table: \"ClientProperties\",\n                column: \"ClientId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ClientRedirectUris_ClientId\",\n                table: \"ClientRedirectUris\",\n                column: \"ClientId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_Clients_ClientId\",\n                table: \"Clients\",\n                column: \"ClientId\",\n                unique: true);\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ClientScopes_ClientId\",\n                table: \"ClientScopes\",\n                column: \"ClientId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_ClientSecrets_ClientId\",\n                table: \"ClientSecrets\",\n                column: \"ClientId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_IdentityResourceClaims_IdentityResourceId\",\n                table: \"IdentityResourceClaims\",\n                column: \"IdentityResourceId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_IdentityResourceProperties_IdentityResourceId\",\n                table: \"IdentityResourceProperties\",\n                column: \"IdentityResourceId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_IdentityResources_Name\",\n                table: \"IdentityResources\",\n                column: \"Name\",\n                unique: true);\n        }\n\n        protected override void Down(MigrationBuilder migrationBuilder)\n        {\n            migrationBuilder.DropTable(\n                name: \"ApiResourceClaims\");\n\n            migrationBuilder.DropTable(\n                name: \"ApiResourceProperties\");\n\n            migrationBuilder.DropTable(\n                name: \"ApiResourceScopes\");\n\n            migrationBuilder.DropTable(\n                name: \"ApiResourceSecrets\");\n\n            migrationBuilder.DropTable(\n                name: \"ApiScopeClaims\");\n\n            migrationBuilder.DropTable(\n                name: \"ApiScopeProperties\");\n\n            migrationBuilder.DropTable(\n                name: \"ClientClaims\");\n\n            migrationBuilder.DropTable(\n                name: \"ClientCorsOrigins\");\n\n            migrationBuilder.DropTable(\n                name: \"ClientGrantTypes\");\n\n            migrationBuilder.DropTable(\n                name: \"ClientIdPRestrictions\");\n\n            migrationBuilder.DropTable(\n                name: \"ClientPostLogoutRedirectUris\");\n\n            migrationBuilder.DropTable(\n                name: \"ClientProperties\");\n\n            migrationBuilder.DropTable(\n                name: \"ClientRedirectUris\");\n\n            migrationBuilder.DropTable(\n                name: \"ClientScopes\");\n\n            migrationBuilder.DropTable(\n                name: \"ClientSecrets\");\n\n            migrationBuilder.DropTable(\n                name: \"IdentityResourceClaims\");\n\n            migrationBuilder.DropTable(\n                name: \"IdentityResourceProperties\");\n\n            migrationBuilder.DropTable(\n                name: \"ApiResources\");\n\n            migrationBuilder.DropTable(\n                name: \"ApiScopes\");\n\n            migrationBuilder.DropTable(\n                name: \"Clients\");\n\n            migrationBuilder.DropTable(\n                name: \"IdentityResources\");\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Data/Migrations/IdentityServer/ConfigurationDb/ConfigurationDbContextModelSnapshot.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\nusing Microsoft.EntityFrameworkCore.Infrastructure;\nusing Microsoft.EntityFrameworkCore.Metadata;\n\nnamespace IdentityServer.Data.Migrations.IdentityServer.ConfigurationDb\n{\n    [DbContext(typeof(ConfigurationDbContext))]\n    partial class ConfigurationDbContextModelSnapshot : ModelSnapshot\n    {\n        protected override void BuildModel(ModelBuilder modelBuilder)\n        {\n#pragma warning disable 612, 618\n            modelBuilder\n                .HasAnnotation(\"ProductVersion\", \"3.1.5\")\n                .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n                .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResource\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"AllowedAccessTokenSigningAlgorithms\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<string>(\"DisplayName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"LastAccessed\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Name\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"NonEditable\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"ShowInDiscoveryDocument\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"Updated\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"Name\")\n                        .IsUnique();\n\n                    b.ToTable(\"ApiResources\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceScope\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Scope\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceScopes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceSecret\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(4000)\")\n                        .HasMaxLength(4000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceSecrets\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScope\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<string>(\"DisplayName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Emphasize\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"Name\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Required\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"ShowInDiscoveryDocument\")\n                        .HasColumnType(\"bit\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"Name\")\n                        .IsUnique();\n\n                    b.ToTable(\"ApiScopes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ScopeId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ScopeId\");\n\n                    b.ToTable(\"ApiScopeClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<int>(\"ScopeId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ScopeId\");\n\n                    b.ToTable(\"ApiScopeProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.Client\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"AbsoluteRefreshTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<int>(\"AccessTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<int>(\"AccessTokenType\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"AllowAccessTokensViaBrowser\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AllowOfflineAccess\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AllowPlainTextPkce\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AllowRememberConsent\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"AllowedIdentityTokenSigningAlgorithms\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<bool>(\"AlwaysIncludeUserClaimsInIdToken\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AlwaysSendClientClaims\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<int>(\"AuthorizationCodeLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"BackChannelLogoutSessionRequired\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"BackChannelLogoutUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<string>(\"ClientClaimsPrefix\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<int?>(\"ConsentLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<int>(\"DeviceCodeLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"EnableLocalLogin\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"FrontChannelLogoutSessionRequired\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"FrontChannelLogoutUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<int>(\"IdentityTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"IncludeJwtId\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"LastAccessed\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"LogoUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<bool>(\"NonEditable\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"PairWiseSubjectSalt\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ProtocolType\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<int>(\"RefreshTokenExpiration\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<int>(\"RefreshTokenUsage\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"RequireClientSecret\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"RequireConsent\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"RequirePkce\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"RequireRequestObject\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<int>(\"SlidingRefreshTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"UpdateAccessTokenClaimsOnRefresh\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"Updated\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"UserCodeType\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<int?>(\"UserSsoLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\")\n                        .IsUnique();\n\n                    b.ToTable(\"Clients\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientCorsOrigin\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Origin\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(150)\")\n                        .HasMaxLength(150);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientCorsOrigins\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientGrantType\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"GrantType\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientGrantTypes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientIdPRestriction\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Provider\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientIdPRestrictions\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientPostLogoutRedirectUri\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"PostLogoutRedirectUri\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientPostLogoutRedirectUris\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientRedirectUri\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"RedirectUri\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientRedirectUris\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientScope\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Scope\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientScopes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientSecret\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(4000)\")\n                        .HasMaxLength(4000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientSecrets\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<string>(\"DisplayName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Emphasize\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"Name\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"NonEditable\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Required\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"ShowInDiscoveryDocument\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"Updated\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"Name\")\n                        .IsUnique();\n\n                    b.ToTable(\"IdentityResources\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"IdentityResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"IdentityResourceId\");\n\n                    b.ToTable(\"IdentityResourceClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"IdentityResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"IdentityResourceId\");\n\n                    b.ToTable(\"IdentityResourceProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"UserClaims\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceScope\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"Scopes\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceSecret\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"Secrets\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiScope\", \"Scope\")\n                        .WithMany(\"UserClaims\")\n                        .HasForeignKey(\"ScopeId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiScope\", \"Scope\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"ScopeId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"Claims\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientCorsOrigin\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"AllowedCorsOrigins\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientGrantType\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"AllowedGrantTypes\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientIdPRestriction\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"IdentityProviderRestrictions\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientPostLogoutRedirectUri\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"PostLogoutRedirectUris\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientRedirectUri\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"RedirectUris\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientScope\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"AllowedScopes\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientSecret\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"ClientSecrets\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", \"IdentityResource\")\n                        .WithMany(\"UserClaims\")\n                        .HasForeignKey(\"IdentityResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", \"IdentityResource\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"IdentityResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n#pragma warning restore 612, 618\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Data/Migrations/IdentityServer/PersistedGrantDb/20200625203357_InitialIdentityServerPersistedGrantDbMigration.Designer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\nusing Microsoft.EntityFrameworkCore.Infrastructure;\nusing Microsoft.EntityFrameworkCore.Metadata;\nusing Microsoft.EntityFrameworkCore.Migrations;\n\nnamespace IdentityServer.Data.Migrations.IdentityServer.PersistedGrantDb\n{\n    [DbContext(typeof(PersistedGrantDbContext))]\n    [Migration(\"20200625203357_InitialIdentityServerPersistedGrantDbMigration\")]\n    partial class InitialIdentityServerPersistedGrantDbMigration\n    {\n        protected override void BuildTargetModel(ModelBuilder modelBuilder)\n        {\n#pragma warning disable 612, 618\n            modelBuilder\n                .HasAnnotation(\"ProductVersion\", \"3.1.5\")\n                .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n                .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.DeviceFlowCodes\", b =>\n                {\n                    b.Property<string>(\"UserCode\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime>(\"CreationTime\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Data\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(max)\")\n                        .HasMaxLength(50000);\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"DeviceCode\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .IsRequired()\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"SessionId\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<string>(\"SubjectId\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"UserCode\");\n\n                    b.HasIndex(\"DeviceCode\")\n                        .IsUnique();\n\n                    b.HasIndex(\"Expiration\");\n\n                    b.ToTable(\"DeviceCodes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.PersistedGrant\", b =>\n                {\n                    b.Property<string>(\"Key\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime?>(\"ConsumedTime\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<DateTime>(\"CreationTime\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Data\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(max)\")\n                        .HasMaxLength(50000);\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"SessionId\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<string>(\"SubjectId\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(50)\")\n                        .HasMaxLength(50);\n\n                    b.HasKey(\"Key\");\n\n                    b.HasIndex(\"Expiration\");\n\n                    b.HasIndex(\"SubjectId\", \"ClientId\", \"Type\");\n\n                    b.HasIndex(\"SubjectId\", \"SessionId\", \"Type\");\n\n                    b.ToTable(\"PersistedGrants\");\n                });\n#pragma warning restore 612, 618\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Data/Migrations/IdentityServer/PersistedGrantDb/20200625203357_InitialIdentityServerPersistedGrantDbMigration.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.EntityFrameworkCore.Migrations;\n\nnamespace IdentityServer.Data.Migrations.IdentityServer.PersistedGrantDb\n{\n    public partial class InitialIdentityServerPersistedGrantDbMigration : Migration\n    {\n        protected override void Up(MigrationBuilder migrationBuilder)\n        {\n            migrationBuilder.CreateTable(\n                name: \"DeviceCodes\",\n                columns: table => new\n                {\n                    UserCode = table.Column<string>(maxLength: 200, nullable: false),\n                    DeviceCode = table.Column<string>(maxLength: 200, nullable: false),\n                    SubjectId = table.Column<string>(maxLength: 200, nullable: true),\n                    SessionId = table.Column<string>(maxLength: 100, nullable: true),\n                    ClientId = table.Column<string>(maxLength: 200, nullable: false),\n                    Description = table.Column<string>(maxLength: 200, nullable: true),\n                    CreationTime = table.Column<DateTime>(nullable: false),\n                    Expiration = table.Column<DateTime>(nullable: false),\n                    Data = table.Column<string>(maxLength: 50000, nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_DeviceCodes\", x => x.UserCode);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"PersistedGrants\",\n                columns: table => new\n                {\n                    Key = table.Column<string>(maxLength: 200, nullable: false),\n                    Type = table.Column<string>(maxLength: 50, nullable: false),\n                    SubjectId = table.Column<string>(maxLength: 200, nullable: true),\n                    SessionId = table.Column<string>(maxLength: 100, nullable: true),\n                    ClientId = table.Column<string>(maxLength: 200, nullable: false),\n                    Description = table.Column<string>(maxLength: 200, nullable: true),\n                    CreationTime = table.Column<DateTime>(nullable: false),\n                    Expiration = table.Column<DateTime>(nullable: true),\n                    ConsumedTime = table.Column<DateTime>(nullable: true),\n                    Data = table.Column<string>(maxLength: 50000, nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_PersistedGrants\", x => x.Key);\n                });\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_DeviceCodes_DeviceCode\",\n                table: \"DeviceCodes\",\n                column: \"DeviceCode\",\n                unique: true);\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_DeviceCodes_Expiration\",\n                table: \"DeviceCodes\",\n                column: \"Expiration\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_PersistedGrants_Expiration\",\n                table: \"PersistedGrants\",\n                column: \"Expiration\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_PersistedGrants_SubjectId_ClientId_Type\",\n                table: \"PersistedGrants\",\n                columns: new[] { \"SubjectId\", \"ClientId\", \"Type\" });\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_PersistedGrants_SubjectId_SessionId_Type\",\n                table: \"PersistedGrants\",\n                columns: new[] { \"SubjectId\", \"SessionId\", \"Type\" });\n        }\n\n        protected override void Down(MigrationBuilder migrationBuilder)\n        {\n            migrationBuilder.DropTable(\n                name: \"DeviceCodes\");\n\n            migrationBuilder.DropTable(\n                name: \"PersistedGrants\");\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Data/Migrations/IdentityServer/PersistedGrantDb/PersistedGrantDbContextModelSnapshot.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\nusing Microsoft.EntityFrameworkCore.Infrastructure;\nusing Microsoft.EntityFrameworkCore.Metadata;\n\nnamespace IdentityServer.Data.Migrations.IdentityServer.PersistedGrantDb\n{\n    [DbContext(typeof(PersistedGrantDbContext))]\n    partial class PersistedGrantDbContextModelSnapshot : ModelSnapshot\n    {\n        protected override void BuildModel(ModelBuilder modelBuilder)\n        {\n#pragma warning disable 612, 618\n            modelBuilder\n                .HasAnnotation(\"ProductVersion\", \"3.1.5\")\n                .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n                .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.DeviceFlowCodes\", b =>\n                {\n                    b.Property<string>(\"UserCode\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime>(\"CreationTime\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Data\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(max)\")\n                        .HasMaxLength(50000);\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"DeviceCode\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .IsRequired()\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"SessionId\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<string>(\"SubjectId\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"UserCode\");\n\n                    b.HasIndex(\"DeviceCode\")\n                        .IsUnique();\n\n                    b.HasIndex(\"Expiration\");\n\n                    b.ToTable(\"DeviceCodes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.PersistedGrant\", b =>\n                {\n                    b.Property<string>(\"Key\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime?>(\"ConsumedTime\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<DateTime>(\"CreationTime\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Data\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(max)\")\n                        .HasMaxLength(50000);\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"SessionId\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<string>(\"SubjectId\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(50)\")\n                        .HasMaxLength(50);\n\n                    b.HasKey(\"Key\");\n\n                    b.HasIndex(\"Expiration\");\n\n                    b.HasIndex(\"SubjectId\", \"ClientId\", \"Type\");\n\n                    b.HasIndex(\"SubjectId\", \"SessionId\", \"Type\");\n\n                    b.ToTable(\"PersistedGrants\");\n                });\n#pragma warning restore 612, 618\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.Configuration;\nglobal using IdentityServer8.EntityFramework.DbContexts;\nglobal using IdentityServer8.EntityFramework.Mappers;\nglobal using IdentityServer8.Events;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Test;\nglobal using IdentityServer8.Validation;\nglobal using IdentityServerHost.Quickstart.UI;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Hosting;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.AspNetCore.Mvc.Filters;\nglobal using Microsoft.EntityFrameworkCore;\nglobal using Microsoft.Extensions.Hosting;\nglobal using Microsoft.Extensions.Options;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\nglobal using System;\nglobal using System.ComponentModel.DataAnnotations;\nglobal using System.Reflection;\nglobal using System.Security.Claims;\nglobal using System.Text;\nglobal using System.Text.Json;\nglobal using static IdentityModel.JwtClaimTypes;\nglobal using IdentityServerClaimValueTypes = IdentityServer8.IdentityServerConstants.ClaimValueTypes;\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/IdentityServer.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n    <ItemGroup>\n        <PackageReference Include=\"HigginsSoft.IdentityServer8\" />\n        <PackageReference Include=\"HigginsSoft.IdentityServer8.EntityFramework\" />\n        <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n\n        <PackageReference Include=\"Microsoft.AspNetCore.Authentication.Google\" />\n        <PackageReference Include=\"Microsoft.EntityFrameworkCore.SqlServer\" />\n        <PackageReference Include=\"Microsoft.EntityFrameworkCore.Design\" />\n    </ItemGroup>\n</Project>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConfigureLogger();\n\ntry\n{\n    Log.Information(\"Starting host...\");\n\n    var builder = WebApplication.CreateBuilder(args);\n\n    var services = builder.Services;\n\n    services.AddControllersWithViews();\n\n    var migrationsAssembly = typeof(Program).GetTypeInfo().Assembly.GetName().Name;\n    const string connectionString = @\"Data Source=(LocalDb)\\MSSQLLocalDB;database=IdentityServer8.Quickstart.EntityFramework-4.0.0;trusted_connection=yes;\";\n\n    services.AddIdentityServer()\n        .AddTestUsers(TestUsers.Users)\n        .AddConfigurationStore(options =>\n        {\n            options.ConfigureDbContext = b => b.UseSqlServer(connectionString,\n                sql => sql.MigrationsAssembly(migrationsAssembly));\n        })\n        .AddOperationalStore(options =>\n        {\n            options.ConfigureDbContext = b => b.UseSqlServer(connectionString,\n                sql => sql.MigrationsAssembly(migrationsAssembly));\n        })\n        .AddDeveloperSigningCredential();\n\n    services.AddAuthentication()\n        .AddGoogle(\"Google\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n            options.ClientId = \"<insert here>\";\n            options.ClientSecret = \"<insert here>\";\n        })\n        .AddOpenIdConnect(\"oidc\", \"Demo IdentityServer\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n            options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n            options.SaveTokens = true;\n\n            options.Authority = \"https://demo.identityserver8.io/\";\n            options.ClientId = \"interactive.confidential\";\n            options.ClientSecret = \"secret\";\n            options.ResponseType = \"code\";\n\n            options.TokenValidationParameters = new()\n            {\n                NameClaimType = \"name\",\n                RoleClaimType = \"role\"\n            };\n        });\n\n\n    using (var app = builder.Build())\n    {\n        // this will do the initial DB population\n        InitializeDatabase(app);\n\n        if (app.Environment.IsDevelopment())\n            app.UseDeveloperExceptionPage();\n\n        app.UseStaticFiles()\n            .UseRouting()\n            .UseIdentityServer()\n            .UseAuthorization();\n\n        app.MapDefaultControllerRoute();\n\n        await app.RunAsync();\n    }\n\n    return 0;\n}\ncatch (Exception ex)\n{\n    Log.Fatal(ex, \"Host terminated unexpectedly.\");\n    return 1;\n}\nfinally\n{\n    Log.CloseAndFlush();\n}\n\n\nvoid ConfigureLogger() => Log.Logger = new LoggerConfiguration()\n    .MinimumLevel.Debug()\n    .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n    .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n    .Enrich.FromLogContext()\n    // uncomment to write to Azure diagnostics stream\n    //.WriteTo.File(\n    //    @\"D:\\home\\LogFiles\\Application\\identityserver.txt\",\n    //    fileSizeLimitBytes: 1_000_000,\n    //    rollOnFileSizeLimit: true,\n    //    shared: true,\n    //    flushToDiskInterval: TimeSpan.FromSeconds(1))\n    .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n    .CreateLogger();\n\n void InitializeDatabase(IApplicationBuilder app)\n{\n    using (var serviceScope = app.ApplicationServices.GetService<IServiceScopeFactory>().CreateScope())\n    {\n        serviceScope.ServiceProvider.GetRequiredService<PersistedGrantDbContext>().Database.Migrate();\n\n        var context = serviceScope.ServiceProvider.GetRequiredService<ConfigurationDbContext>();\n        context.Database.Migrate();\n        if (!context.Clients.Any())\n        {\n            foreach (var client in Config.Clients)\n            {\n                context.Clients.Add(client.ToEntity());\n            }\n            context.SaveChanges();\n        }\n\n        if (!context.IdentityResources.Any())\n        {\n            foreach (var resource in Config.IdentityResources)\n            {\n                context.IdentityResources.Add(resource.ToEntity());\n            }\n            context.SaveChanges();\n        }\n\n        if (!context.ApiScopes.Any())\n        {\n            foreach (var resource in Config.ApiScopes)\n            {\n                context.ApiScopes.Add(resource.ToEntity());\n            }\n            context.SaveChanges();\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"SelfHost\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Account/AccountController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller implements a typical login/logout/provision workflow for local and external accounts.\n/// The login service encapsulates the interactions with the user data store. This data store is in-memory only and cannot be used for production!\n/// The interaction service provides a way for the UI to communicate with identityserver for validation and context retrieval\n/// </summary>\n[SecurityHeaders]\n[AllowAnonymous]\npublic class AccountController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly IAuthenticationSchemeProvider _schemeProvider;\n    private readonly IEventService _events;\n\n    public AccountController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IAuthenticationSchemeProvider schemeProvider,\n        IEventService events,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _schemeProvider = schemeProvider;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Entry point into the login workflow\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Login(string returnUrl)\n    {\n        // build a model so we know what to show on the login page\n        var vm = await BuildLoginViewModelAsync(returnUrl);\n\n        if (vm.IsExternalLoginOnly)\n        {\n            // we only have one option for logging in and it's an external provider\n            return returnUrl.IsAllowedRedirect() ? RedirectToAction(\"Challenge\", \"External\", new { scheme = vm.ExternalLoginScheme, returnUrl = returnUrl.SanitizeForRedirect() }) : Forbid();\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Login(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (ModelState.IsValid)\n        {\n            // validate username/password against in-memory store\n            if (_users.ValidateCredentials(model.Username, model.Password))\n            {\n                var user = _users.FindByUsername(model.Username);\n                await _events.RaiseAsync(new UserLoginSuccessEvent(user.Username, user.SubjectId, user.Username, clientId: context?.Client.ClientId));\n\n                // only set explicit expiration here if user chooses \"remember me\". \n                // otherwise we rely upon expiration configured in cookie middleware.\n                AuthenticationProperties props = null;\n                if (AccountOptions.AllowRememberLogin && model.RememberLogin)\n                {\n                    props = new AuthenticationProperties\n                    {\n                        IsPersistent = true,\n                        ExpiresUtc = DateTimeOffset.UtcNow.Add(AccountOptions.RememberMeLoginDuration)\n                    };\n                };\n\n                // issue authentication cookie with subject ID and username\n                var isuser = new IdentityServerUser(user.SubjectId)\n                {\n                    DisplayName = user.Username\n                };\n\n                await HttpContext.SignInAsync(isuser, props);\n\n                if (context != null)\n                {\n                    if (context.IsNativeClient())\n                    {\n                        // The client is native, so this change in how to\n                        // return the response is for better UX for the end user.\n                        return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                    }\n\n                    // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n\n                // request for a local page\n                if (Url.IsLocalUrl(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n                else if (string.IsNullOrEmpty(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n                }\n                else\n                {\n                    // user might have clicked on a malicious link - should be logged\n                    throw new Exception(\"invalid return URL\");\n                }\n            }\n\n            await _events.RaiseAsync(new UserLoginFailureEvent(model.Username, \"invalid credentials\", clientId: context?.Client.ClientId));\n            ModelState.AddModelError(string.Empty, AccountOptions.InvalidCredentialsErrorMessage);\n        }\n\n        // something went wrong, show form with error\n        var vm = await BuildLoginViewModelAsync(model);\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> LoginCancel(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (context != null)\n        {\n            // if the user cancels, send a result back into IdentityServer as if they \n            // denied the consent (even if this client does not require consent).\n            // this will send back an access denied OIDC error response to the client.\n            await _interaction.DenyAuthorizationAsync(context, AuthorizationError.AccessDenied);\n\n            // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n            }\n\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n        }\n        else\n        {\n            // since we don't have a valid context, then we just go back to the home page\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n        }\n\n    }\n\n    /// <summary>\n    /// Show logout page\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Logout(string logoutId)\n    {\n        // build a model so the logout page knows what to display\n        var vm = await BuildLogoutViewModelAsync(logoutId);\n\n        if (vm.ShowLogoutPrompt == false)\n        {\n            // if the request for logout was properly authenticated from IdentityServer, then\n            // we don't need to show the prompt and can just log the user out directly.\n            return await Logout(vm);\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle logout page postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Logout(LogoutInputModel model)\n    {\n        // build a model so the logged out page knows what to display\n        var vm = await BuildLoggedOutViewModelAsync(model.LogoutId);\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            // delete local authentication cookie\n            await HttpContext.SignOutAsync();\n\n            // raise the logout event\n            await _events.RaiseAsync(new UserLogoutSuccessEvent(User.GetSubjectId(), User.GetDisplayName()));\n        }\n\n        // check if we need to trigger sign-out at an upstream identity provider\n        if (vm.TriggerExternalSignout)\n        {\n            // build a return URL so the upstream provider will redirect back\n            // to us after the user has logged out. this allows us to then\n            // complete our single sign-out processing.\n            string url = Url.Action(\"Logout\", new { logoutId = vm.LogoutId });\n\n            // this triggers a redirect to the external provider for sign-out\n            return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);\n        }\n\n        return View(\"LoggedOut\", vm);\n    }\n\n    [HttpGet]\n    public IActionResult AccessDenied()\n    {\n        return View();\n    }\n\n\n    /*****************************************/\n    /* helper APIs for the AccountController */\n    /*****************************************/\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(string returnUrl)\n    {\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (context?.IdP != null && await _schemeProvider.GetSchemeAsync(context.IdP) != null)\n        {\n            var local = context.IdP == IdentityServer8.IdentityServerConstants.LocalIdentityProvider;\n\n            // this is meant to short circuit the UI and only trigger the one external IdP\n            var vm = new LoginViewModel\n            {\n                EnableLocalLogin = local,\n                ReturnUrl = returnUrl,\n                Username = context?.LoginHint,\n            };\n\n            if (!local)\n            {\n                vm.ExternalProviders = new[] { new ExternalProvider { AuthenticationScheme = context.IdP } };\n            }\n\n            return vm;\n        }\n\n        var schemes = await _schemeProvider.GetAllSchemesAsync();\n\n        var providers = schemes\n            .Where(x => x.DisplayName != null)\n            .Select(x => new ExternalProvider\n            {\n                DisplayName = x.DisplayName ?? x.Name,\n                AuthenticationScheme = x.Name\n            }).ToList();\n\n        var allowLocal = true;\n        if (context?.Client.ClientId != null)\n        {\n            var client = await _clientStore.FindEnabledClientByIdAsync(context.Client.ClientId);\n            if (client != null)\n            {\n                allowLocal = client.EnableLocalLogin;\n\n                if (client.IdentityProviderRestrictions != null && client.IdentityProviderRestrictions.Any())\n                {\n                    providers = providers.Where(provider => client.IdentityProviderRestrictions.Contains(provider.AuthenticationScheme)).ToList();\n                }\n            }\n        }\n\n        return new LoginViewModel\n        {\n            AllowRememberLogin = AccountOptions.AllowRememberLogin,\n            EnableLocalLogin = allowLocal && AccountOptions.AllowLocalLogin,\n            ReturnUrl = returnUrl,\n            Username = context?.LoginHint,\n            ExternalProviders = providers.ToArray()\n        };\n    }\n\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(LoginInputModel model)\n    {\n        var vm = await BuildLoginViewModelAsync(model.ReturnUrl);\n        vm.Username = model.Username;\n        vm.RememberLogin = model.RememberLogin;\n        return vm;\n    }\n\n    private async Task<LogoutViewModel> BuildLogoutViewModelAsync(string logoutId)\n    {\n        var vm = new LogoutViewModel { LogoutId = logoutId, ShowLogoutPrompt = AccountOptions.ShowLogoutPrompt };\n\n        if (User?.Identity.IsAuthenticated != true)\n        {\n            // if the user is not authenticated, then just show logged out page\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        var context = await _interaction.GetLogoutContextAsync(logoutId);\n        if (context?.ShowSignoutPrompt == false)\n        {\n            // it's safe to automatically sign-out\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        // show the logout prompt. this prevents attacks where the user\n        // is automatically signed out by another malicious web page.\n        return vm;\n    }\n\n    private async Task<LoggedOutViewModel> BuildLoggedOutViewModelAsync(string logoutId)\n    {\n        // get context information (client name, post logout redirect URI and iframe for federated signout)\n        var logout = await _interaction.GetLogoutContextAsync(logoutId);\n\n        var vm = new LoggedOutViewModel\n        {\n            AutomaticRedirectAfterSignOut = AccountOptions.AutomaticRedirectAfterSignOut,\n            PostLogoutRedirectUri = logout?.PostLogoutRedirectUri,\n            ClientName = string.IsNullOrEmpty(logout?.ClientName) ? logout?.ClientId : logout?.ClientName,\n            SignOutIframeUrl = logout?.SignOutIFrameUrl,\n            LogoutId = logoutId\n        };\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            var idp = User.FindFirst(JwtClaimTypes.IdentityProvider)?.Value;\n            if (idp != null && idp != IdentityServer8.IdentityServerConstants.LocalIdentityProvider)\n            {\n                var providerSupportsSignout = await HttpContext.GetSchemeSupportsSignOutAsync(idp);\n                if (providerSupportsSignout)\n                {\n                    if (vm.LogoutId == null)\n                    {\n                        // if there's no current logout context, we need to create one\n                        // this captures necessary info from the current logged in user\n                        // before we signout and redirect away to the external IdP for signout\n                        vm.LogoutId = await _interaction.CreateLogoutContextAsync();\n                    }\n\n                    vm.ExternalAuthenticationScheme = idp;\n                }\n            }\n        }\n\n        return vm;\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Account/AccountOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI\n{\n    public class AccountOptions\n    {\n        public static bool AllowLocalLogin = true;\n        public static bool AllowRememberLogin = true;\n        public static TimeSpan RememberMeLoginDuration = TimeSpan.FromDays(30);\n\n        public static bool ShowLogoutPrompt = true;\n        public static bool AutomaticRedirectAfterSignOut = false;\n\n        public static string InvalidCredentialsErrorMessage = \"Invalid username or password\";\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Account/ExternalController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class ExternalController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly ILogger<ExternalController> _logger;\n    private readonly IEventService _events;\n\n    public ExternalController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IEventService events,\n        ILogger<ExternalController> logger,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _logger = logger;\n        _events = events;\n    }\n\n    /// <summary>\n    /// initiate roundtrip to external authentication provider\n    /// </summary>\n    [HttpGet]\n    public IActionResult Challenge(string scheme, string returnUrl)\n    {\n        if (string.IsNullOrEmpty(returnUrl)) returnUrl = \"~/\";\n\n        // validate returnUrl - either it is a valid OIDC URL or back to a local page\n        if (Url.IsLocalUrl(returnUrl) == false && _interaction.IsValidReturnUrl(returnUrl) == false)\n        {\n            // user might have clicked on a malicious link - should be logged\n            throw new Exception(\"invalid return URL\");\n        }\n        \n        // start challenge and roundtrip the return URL and scheme \n        var props = new AuthenticationProperties\n        {\n            RedirectUri = Url.Action(nameof(Callback)), \n            Items =\n            {\n                { \"returnUrl\", returnUrl }, \n                { \"scheme\", scheme },\n            }\n        };\n\n        return Challenge(props, scheme);\n        \n    }\n\n    /// <summary>\n    /// Post processing of external authentication\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Callback()\n    {\n        // read external identity from the temporary cookie\n        var result = await HttpContext.AuthenticateAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n        if (result?.Succeeded != true)\n        {\n            throw new Exception(\"External authentication error\");\n        }\n\n        if (_logger.IsEnabled(LogLevel.Debug))\n        {\n            var externalClaims = result.Principal.Claims.Select(c => $\"{c.Type}: {c.Value}\");\n            _logger.LogDebug(\"External claims: {@claims}\", externalClaims);\n        }\n\n        // lookup our user and external provider info\n        var (user, provider, providerUserId, claims) = FindUserFromExternalProvider(result);\n        if (user == null)\n        {\n            // this might be where you might initiate a custom workflow for user registration\n            // in this sample we don't show how that would be done, as our sample implementation\n            // simply auto-provisions new external user\n            user = AutoProvisionUser(provider, providerUserId, claims);\n        }\n\n        // this allows us to collect any additional claims or properties\n        // for the specific protocols used and store them in the local auth cookie.\n        // this is typically used to store data needed for signout from those protocols.\n        var additionalLocalClaims = new List<Claim>();\n        var localSignInProps = new AuthenticationProperties();\n        ProcessLoginCallback(result, additionalLocalClaims, localSignInProps);\n        \n        // issue authentication cookie for user\n        var isuser = new IdentityServerUser(user.SubjectId)\n        {\n            DisplayName = user.Username,\n            IdentityProvider = provider,\n            AdditionalClaims = additionalLocalClaims\n        };\n\n        await HttpContext.SignInAsync(isuser, localSignInProps);\n\n        // delete temporary cookie used during external authentication\n        await HttpContext.SignOutAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n        // retrieve return URL\n        var returnUrl = result.Properties.Items[\"returnUrl\"] ?? \"~/\";\n\n        // check if external login is in the context of an OIDC request\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        await _events.RaiseAsync(new UserLoginSuccessEvent(provider, providerUserId, user.SubjectId, user.Username, true, context?.Client.ClientId));\n\n        if (context != null)\n        {\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", returnUrl);\n            }\n        }\n\n        return Redirect(returnUrl);\n    }\n\n    private (TestUser user, string provider, string providerUserId, IEnumerable<Claim> claims) FindUserFromExternalProvider(AuthenticateResult result)\n    {\n        var externalUser = result.Principal;\n\n        // try to determine the unique id of the external user (issued by the provider)\n        // the most common claim type for that are the sub claim and the NameIdentifier\n        // depending on the external provider, some other claim type might be used\n        var userIdClaim = externalUser.FindFirst(JwtClaimTypes.Subject) ??\n                          externalUser.FindFirst(ClaimTypes.NameIdentifier) ??\n                          throw new Exception(\"Unknown userid\");\n\n        // remove the user id claim so we don't include it as an extra claim if/when we provision the user\n        var claims = externalUser.Claims.ToList();\n        claims.Remove(userIdClaim);\n\n        var provider = result.Properties.Items[\"scheme\"];\n        var providerUserId = userIdClaim.Value;\n\n        // find external user\n        var user = _users.FindByExternalProvider(provider, providerUserId);\n\n        return (user, provider, providerUserId, claims);\n    }\n\n    private TestUser AutoProvisionUser(string provider, string providerUserId, IEnumerable<Claim> claims)\n    {\n        var user = _users.AutoProvisionUser(provider, providerUserId, claims.ToList());\n        return user;\n    }\n\n    // if the external login is OIDC-based, there are certain things we need to preserve to make logout work\n    // this will be different for WS-Fed, SAML2p or other protocols\n    private void ProcessLoginCallback(AuthenticateResult externalResult, List<Claim> localClaims, AuthenticationProperties localSignInProps)\n    {\n        // if the external system sent a session id claim, copy it over\n        // so we can use it for single sign-out\n        var sid = externalResult.Principal.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.SessionId);\n        if (sid != null)\n        {\n            localClaims.Add(new Claim(JwtClaimTypes.SessionId, sid.Value));\n        }\n\n        // if the external provider issued an id_token, we'll keep it for signout\n        var idToken = externalResult.Properties.GetTokenValue(\"id_token\");\n        if (idToken != null)\n        {\n            localSignInProps.StoreTokens(new[] { new AuthenticationToken { Name = \"id_token\", Value = idToken } });\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Account/ExternalProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ExternalProvider\n{\n    public string DisplayName { get; set; }\n    public string AuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Account/LoggedOutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoggedOutViewModel\n{\n    public string PostLogoutRedirectUri { get; set; }\n    public string ClientName { get; set; }\n    public string SignOutIframeUrl { get; set; }\n\n    public bool AutomaticRedirectAfterSignOut { get; set; }\n\n    public string LogoutId { get; set; }\n    public bool TriggerExternalSignout => ExternalAuthenticationScheme != null;\n    public string ExternalAuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Account/LoginInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginInputModel\n{\n    [Required]\n    public string Username { get; set; }\n    [Required]\n    public string Password { get; set; }\n    public bool RememberLogin { get; set; }\n    public string ReturnUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Account/LoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginViewModel : LoginInputModel\n{\n    public bool AllowRememberLogin { get; set; } = true;\n    public bool EnableLocalLogin { get; set; } = true;\n\n    public IEnumerable<ExternalProvider> ExternalProviders { get; set; } = Enumerable.Empty<ExternalProvider>();\n    public IEnumerable<ExternalProvider> VisibleExternalProviders => ExternalProviders.Where(x => !String.IsNullOrWhiteSpace(x.DisplayName));\n\n    public bool IsExternalLoginOnly => EnableLocalLogin == false && ExternalProviders?.Count() == 1;\n    public string ExternalLoginScheme => IsExternalLoginOnly ? ExternalProviders?.SingleOrDefault()?.AuthenticationScheme : null;\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Account/LogoutInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutInputModel\n{\n    public string LogoutId { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Account/LogoutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutViewModel : LogoutInputModel\n{\n    public bool ShowLogoutPrompt { get; set; } = true;\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Account/RedirectViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class RedirectViewModel\n{\n    public string RedirectUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Consent/ConsentController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This controller processes the consent UI\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class ConsentController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly ILogger<ConsentController> _logger;\n\n    public ConsentController(\n        IIdentityServerInteractionService interaction,\n        IEventService events,\n        ILogger<ConsentController> logger)\n    {\n        _interaction = interaction;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Shows the consent screen\n    /// </summary>\n    /// <param name=\"returnUrl\"></param>\n    /// <returns></returns>\n    [HttpGet]\n    public async Task<IActionResult> Index(string returnUrl)\n    {\n        var vm = await BuildViewModelAsync(returnUrl);\n        if (vm != null)\n        {\n            return View(\"Index\", vm);\n        }\n\n        return View(\"Error\");\n    }\n\n    /// <summary>\n    /// Handles the consent screen postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Index(ConsentInputModel model)\n    {\n        var result = await ProcessConsent(model);\n\n        if (result.IsRedirect)\n        {\n            var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n            if (context?.IsNativeClient() == true)\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", result.RedirectUri);\n            }\n            return result.RedirectUri.IsAllowedRedirect() ? Redirect(result.RedirectUri.SanitizeForRedirect()) : Forbid();\n        }\n\n        if (result.HasValidationError)\n        {\n            ModelState.AddModelError(string.Empty, result.ValidationError);\n        }\n\n        if (result.ShowView)\n        {\n            return View(\"Index\", result.ViewModel);\n        }\n\n        return View(\"Error\");\n    }\n\n    /*****************************************/\n    /* helper APIs for the ConsentController */\n    /*****************************************/\n    private async Task<ProcessConsentResult> ProcessConsent(ConsentInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        // validate return url is still valid\n        var request = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model?.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model?.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.GrantConsentAsync(request, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.ReturnUrl, model);\n        }\n\n        return result;\n    }\n\n    private async Task<ConsentViewModel> BuildViewModelAsync(string returnUrl, ConsentInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (request != null)\n        {\n            return CreateConsentViewModel(model, returnUrl, request);\n        }\n        else\n        {\n            _logger.LogError(\"No consent request matching request: {0}\", returnUrl.SanitizeForLog());\n        }\n\n        return null;\n    }\n\n    private ConsentViewModel CreateConsentViewModel(\n        ConsentInputModel model, string returnUrl,\n        AuthorizationRequest request)\n    {\n        var vm = new ConsentViewModel\n        {\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n            Description = model?.Description,\n\n            ReturnUrl = returnUrl,\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach(var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        var displayName = apiScope.DisplayName ?? apiScope.Name;\n        if (!String.IsNullOrWhiteSpace(parsedScopeValue.ParsedParameter))\n        {\n            displayName += \":\" + parsedScopeValue.ParsedParameter;\n        }\n\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            DisplayName = displayName,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Consent/ConsentInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentInputModel\n{\n    public string Button { get; set; }\n    public IEnumerable<string> ScopesConsented { get; set; }\n    public bool RememberConsent { get; set; }\n    public string ReturnUrl { get; set; }\n    public string Description { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Consent/ConsentOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentOptions\n{\n    public static bool EnableOfflineAccess = true;\n    public static string OfflineAccessDisplayName = \"Offline Access\";\n    public static string OfflineAccessDescription = \"Access to your applications and resources, even when you are offline\";\n\n    public static readonly string MustChooseOneErrorMessage = \"You must pick at least one permission\";\n    public static readonly string InvalidSelectionErrorMessage = \"Invalid selection\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Consent/ConsentViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentViewModel : ConsentInputModel\n{\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public bool AllowRememberConsent { get; set; }\n\n    public IEnumerable<ScopeViewModel> IdentityScopes { get; set; }\n    public IEnumerable<ScopeViewModel> ApiScopes { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Consent/ProcessConsentResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ProcessConsentResult\n{\n    public bool IsRedirect => RedirectUri != null;\n    public string RedirectUri { get; set; }\n    public Client Client { get; set; }\n\n    public bool ShowView => ViewModel != null;\n    public ConsentViewModel ViewModel { get; set; }\n\n    public bool HasValidationError => ValidationError != null;\n    public string ValidationError { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Consent/ScopeViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ScopeViewModel\n{\n    public string Value { get; set; }\n    public string DisplayName { get; set; }\n    public string Description { get; set; }\n    public bool Emphasize { get; set; }\n    public bool Required { get; set; }\n    public bool Checked { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Device/DeviceAuthorizationInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationInputModel : ConsentInputModel\n{\n    public string UserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Device/DeviceAuthorizationViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationViewModel : ConsentViewModel\n{\n    public string UserCode { get; set; }\n    public bool ConfirmUserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Device/DeviceController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[Authorize]\n[SecurityHeaders]\npublic class DeviceController : Controller\n{\n    private readonly IDeviceFlowInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly IOptions<IdentityServerOptions> _options;\n    private readonly ILogger<DeviceController> _logger;\n\n    public DeviceController(\n        IDeviceFlowInteractionService interaction,\n        IEventService eventService,\n        IOptions<IdentityServerOptions> options,\n        ILogger<DeviceController> logger)\n    {\n        _interaction = interaction;\n        _events = eventService;\n        _options = options;\n        _logger = logger;\n    }\n\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        string userCodeParamName = _options.Value.UserInteraction.DeviceVerificationUserCodeParameter;\n        string userCode = Request.Query[userCodeParamName];\n        if (string.IsNullOrWhiteSpace(userCode)) return View(\"UserCodeCapture\");\n\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        vm.ConfirmUserCode = true;\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> UserCodeCapture(string userCode)\n    {\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Callback(DeviceAuthorizationInputModel model)\n    {\n        if (model == null) throw new ArgumentNullException(nameof(model));\n\n        var result = await ProcessConsent(model);\n        if (result.HasValidationError) return View(\"Error\");\n\n        return View(\"Success\");\n    }\n\n    private async Task<ProcessConsentResult> ProcessConsent(DeviceAuthorizationInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        var request = await _interaction.GetAuthorizationContextAsync(model.UserCode);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.HandleRequestAsync(model.UserCode, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.UserCode, model);\n        }\n\n        return result;\n    }\n\n    private async Task<DeviceAuthorizationViewModel> BuildViewModelAsync(string userCode, DeviceAuthorizationInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(userCode);\n        if (request != null)\n        {\n            return CreateConsentViewModel(userCode, model, request);\n        }\n\n        return null;\n    }\n\n    private DeviceAuthorizationViewModel CreateConsentViewModel(string userCode, DeviceAuthorizationInputModel model, DeviceFlowAuthorizationRequest request)\n    {\n        var vm = new DeviceAuthorizationViewModel\n        {\n            UserCode = userCode,\n            Description = model?.Description,\n\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach (var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            // todo: use the parsed scope value in the display?\n            DisplayName = apiScope.DisplayName ?? apiScope.Name,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Diagnostics/DiagnosticsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[Authorize]\npublic class DiagnosticsController : Controller\n{\n    public async Task<IActionResult> Index()\n    {\n        var localAddresses = new string[] { \"127.0.0.1\", \"::1\", HttpContext.Connection.LocalIpAddress.ToString() };\n        if (!localAddresses.Contains(HttpContext.Connection.RemoteIpAddress.ToString()))\n        {\n            return NotFound();\n        }\n\n        var model = new DiagnosticsViewModel(await HttpContext.AuthenticateAsync());\n        return View(model);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Diagnostics/DiagnosticsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DiagnosticsViewModel\n{\n    public DiagnosticsViewModel(AuthenticateResult result)\n    {\n        AuthenticateResult = result;\n\n        if (result.Properties.Items.ContainsKey(\"client_list\"))\n        {\n            var encoded = result.Properties.Items[\"client_list\"];\n            var bytes = Base64Url.Decode(encoded);\n            var value = Encoding.UTF8.GetString(bytes);\n\n            Clients = JsonSerializer.Deserialize<string[]>(value);\n        }\n    }\n\n    public AuthenticateResult AuthenticateResult { get; }\n    public IEnumerable<string> Clients { get; } = new List<string>();\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Extensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic static class Extensions\n{\n    /// <summary>\n    /// Checks if the redirect URI is for a native client.\n    /// </summary>\n    /// <returns></returns>\n    public static bool IsNativeClient(this AuthorizationRequest context)\n    {\n        return !context.RedirectUri.StartsWith(\"https\", StringComparison.Ordinal)\n           && !context.RedirectUri.StartsWith(\"http\", StringComparison.Ordinal);\n    }\n\n    public static IActionResult LoadingPage(this Controller controller, string viewName, string redirectUri)\n    {\n        controller.HttpContext.Response.StatusCode = 200;\n        controller.HttpContext.Response.Headers[\"Location\"] = \"\";\n        \n        return controller.View(viewName, new RedirectViewModel { RedirectUrl = redirectUri });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Grants/GrantsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller allows a user to revoke grants given to clients\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class GrantsController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clients;\n    private readonly IResourceStore _resources;\n    private readonly IEventService _events;\n\n    public GrantsController(IIdentityServerInteractionService interaction,\n        IClientStore clients,\n        IResourceStore resources,\n        IEventService events)\n    {\n        _interaction = interaction;\n        _clients = clients;\n        _resources = resources;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Show list of grants\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        return View(\"Index\", await BuildViewModelAsync());\n    }\n\n    /// <summary>\n    /// Handle postback to revoke a client\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Revoke(string clientId)\n    {\n        await _interaction.RevokeUserConsentAsync(clientId);\n        await _events.RaiseAsync(new GrantsRevokedEvent(User.GetSubjectId(), clientId));\n\n        return RedirectToAction(\"Index\");\n    }\n\n    private async Task<GrantsViewModel> BuildViewModelAsync()\n    {\n        var grants = await _interaction.GetAllUserGrantsAsync();\n\n        var list = new List<GrantViewModel>();\n        foreach(var grant in grants)\n        {\n            var client = await _clients.FindClientByIdAsync(grant.ClientId);\n            if (client != null)\n            {\n                var resources = await _resources.FindResourcesByScopeAsync(grant.Scopes);\n\n                var item = new GrantViewModel()\n                {\n                    ClientId = client.ClientId,\n                    ClientName = client.ClientName ?? client.ClientId,\n                    ClientLogoUrl = client.LogoUri,\n                    ClientUrl = client.ClientUri,\n                    Description = grant.Description,\n                    Created = grant.CreationTime,\n                    Expires = grant.Expiration,\n                    IdentityGrantNames = resources.IdentityResources.Select(x => x.DisplayName ?? x.Name).ToArray(),\n                    ApiGrantNames = resources.ApiScopes.Select(x => x.DisplayName ?? x.Name).ToArray()\n                };\n\n                list.Add(item);\n            }\n        }\n\n        return new GrantsViewModel\n        {\n            Grants = list\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Grants/GrantsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class GrantsViewModel\n{\n    public IEnumerable<GrantViewModel> Grants { get; set; }\n}\n\npublic class GrantViewModel\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public string Description { get; set; }\n    public DateTime Created { get; set; }\n    public DateTime? Expires { get; set; }\n    public IEnumerable<string> IdentityGrantNames { get; set; }\n    public IEnumerable<string> ApiGrantNames { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Home/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ErrorViewModel\n{\n    public ErrorViewModel()\n    {\n    }\n\n    public ErrorViewModel(string error)\n    {\n        Error = new ErrorMessage { Error = error };\n    }\n\n    public ErrorMessage Error { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/Home/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class HomeController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IWebHostEnvironment _environment;\n    private readonly ILogger _logger;\n\n    public HomeController(IIdentityServerInteractionService interaction, IWebHostEnvironment environment, ILogger<HomeController> logger)\n    {\n        _interaction = interaction;\n        _environment = environment;\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        if (_environment.IsDevelopment())\n        {\n            // only show in development\n            return View();\n        }\n\n        _logger.LogInformation(\"Homepage is disabled in production. Returning 404.\");\n        return NotFound();\n    }\n\n    /// <summary>\n    /// Shows the error page\n    /// </summary>\n    public async Task<IActionResult> Error(string errorId)\n    {\n        var vm = new ErrorViewModel();\n\n        // retrieve error details from identityserver\n        var message = await _interaction.GetErrorContextAsync(errorId);\n        if (message != null)\n        {\n            vm.Error = message;\n\n            if (!_environment.IsDevelopment())\n            {\n                // only show in development\n                message.ErrorDescription = null;\n            }\n        }\n\n        return View(\"Error\", vm);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/SecurityHeadersAttribute.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class SecurityHeadersAttribute : ActionFilterAttribute\n{\n    public override void OnResultExecuting(ResultExecutingContext context)\n    {\n        var result = context.Result;\n        if (result is ViewResult)\n        {\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Type-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Type-Options\", \"nosniff\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Frame-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Frame-Options\", \"SAMEORIGIN\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy\n            var csp = \"default-src 'self'; object-src 'none'; frame-ancestors 'none'; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self';\";\n            // also consider adding upgrade-insecure-requests once you have HTTPS in place for production\n            //csp += \"upgrade-insecure-requests;\";\n            // also an example if you need client images to be displayed from twitter\n            // csp += \"img-src 'self' https://pbs.twimg.com;\";\n\n            // once for standards compliant browsers\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Content-Security-Policy\", csp);\n            }\n            // and once again for IE\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Security-Policy\", csp);\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy\n            var referrer_policy = \"no-referrer\";\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Referrer-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Referrer-Policy\", referrer_policy);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Quickstart/TestUsers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class TestUsers\n{\n\n    static readonly object UserAddress = new\n    {\n        street_address = \"One Hacker Way\",\n        locality = \"Heidelberg\",\n        postal_code = 69118,\n        country = \"Germany\"\n    };\n\n    public static List<TestUser> Users => new List<TestUser>\n    {\n        new()\n        {\n            SubjectId = \"818727\",\n            Username = \"alice\",\n            Password = \"alice\",\n            Claims =\n            {\n                new (Name, \"Alice Smith\"),\n                new (GivenName, \"Alice\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"AliceSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://alice.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        },\n        new()\n        {\n            SubjectId = \"88421113\",\n            Username = \"bob\",\n            Password = \"bob\",\n            Claims =\n            {\n                new (Name, \"Bob Smith\"),\n                new (GivenName, \"Bob\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"BobSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://bob.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        }\n    };\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8;\nusing IdentityServer8.EntityFramework.DbContexts;\nusing IdentityServer8.EntityFramework.Mappers;\nusing IdentityServerHost.Quickstart.UI;\nusing Microsoft.AspNetCore.Builder;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.EntityFrameworkCore;\nusing Microsoft.Extensions.DependencyInjection;\nusing Microsoft.Extensions.Hosting;\nusing Microsoft.IdentityModel.Tokens;\nusing System.Linq;\nusing System.Reflection;\n\nnamespace IdentityServer\n{\n    public class Startup\n    {\n        public void ConfigureServices(IServiceCollection services)\n        {\n            services.AddControllersWithViews();\n\n            var migrationsAssembly = typeof(Startup).GetTypeInfo().Assembly.GetName().Name;\n            const string connectionString = @\"Data Source=(LocalDb)\\MSSQLLocalDB;database=IdentityServer8.Quickstart.EntityFramework-4.0.0;trusted_connection=yes;\";\n            \n            var builder = services.AddIdentityServer()\n                .AddTestUsers(TestUsers.Users)\n                .AddConfigurationStore(options =>\n                {\n                    options.ConfigureDbContext = b => b.UseSqlServer(connectionString,\n                        sql => sql.MigrationsAssembly(migrationsAssembly));\n                })\n                .AddOperationalStore(options =>\n                {\n                    options.ConfigureDbContext = b => b.UseSqlServer(connectionString,\n                        sql => sql.MigrationsAssembly(migrationsAssembly));\n                });\n\n            builder.AddDeveloperSigningCredential();\n\n            services.AddAuthentication()\n                .AddGoogle(\"Google\", options =>\n                {\n                    options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n                    options.ClientId = \"<insert here>\";\n                    options.ClientSecret = \"<insert here>\";\n                })\n                .AddOpenIdConnect(\"oidc\", \"Demo IdentityServer\", options =>\n                {\n                    options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n                    options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n                    options.SaveTokens = true;\n\n                    options.Authority = \"https://demo.identityserver8.io/\";\n                    options.ClientId = \"interactive.confidential\";\n                    options.ClientSecret = \"secret\";\n                    options.ResponseType = \"code\";\n\n                    options.TokenValidationParameters = new TokenValidationParameters\n                    {\n                        NameClaimType = \"name\",\n                        RoleClaimType = \"role\"\n                    };\n                });\n        }\n\n        public void Configure(IApplicationBuilder app, IWebHostEnvironment env)\n        {\n            // this will do the initial DB population\n            InitializeDatabase(app);\n\n            if (env.IsDevelopment())\n            {\n                app.UseDeveloperExceptionPage();\n            }\n\n            app.UseStaticFiles();\n            app.UseRouting();\n\n            app.UseIdentityServer();\n            app.UseAuthorization();\n\n            app.UseEndpoints(endpoints =>\n            {\n                endpoints.MapDefaultControllerRoute();\n            });\n        }\n\n        private void InitializeDatabase(IApplicationBuilder app)\n        {\n            using (var serviceScope = app.ApplicationServices.GetService<IServiceScopeFactory>().CreateScope())\n            {\n                serviceScope.ServiceProvider.GetRequiredService<PersistedGrantDbContext>().Database.Migrate();\n\n                var context = serviceScope.ServiceProvider.GetRequiredService<ConfigurationDbContext>();\n                context.Database.Migrate();\n                if (!context.Clients.Any())\n                {\n                    foreach (var client in Config.Clients)\n                    {\n                        context.Clients.Add(client.ToEntity());\n                    }\n                    context.SaveChanges();\n                }\n\n                if (!context.IdentityResources.Any())\n                {\n                    foreach (var resource in Config.IdentityResources)\n                    {\n                        context.IdentityResources.Add(resource.ToEntity());\n                    }\n                    context.SaveChanges();\n                }\n\n                if (!context.ApiScopes.Any())\n                {\n                    foreach (var resource in Config.ApiScopes)\n                    {\n                        context.ApiScopes.Add(resource.ToEntity());\n                    }\n                    context.SaveChanges();\n                }\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Account/AccessDenied.cshtml",
    "content": "﻿\n<div class=\"container\">\n    <div class=\"lead\">\n        <h1>Access Denied</h1>\n        <p>You do not have access to that resource.</p>\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Account/LoggedOut.cshtml",
    "content": "﻿@model LoggedOutViewModel\n\n@{ \n    // set this so the layout rendering sees an anonymous user\n    ViewData[\"signed-out\"] = true;\n}\n\n<div class=\"logged-out-page\">\n    <h1>\n        Logout\n        <small>You are now logged out</small>\n    </h1>\n\n    @if (Model.PostLogoutRedirectUri != null)\n    {\n        <div>\n            Click <a class=\"PostLogoutRedirectUri\" href=\"@Model.PostLogoutRedirectUri\">here</a> to return to the\n            <span>@Model.ClientName</span> application.\n        </div>\n    }\n\n    @if (Model.SignOutIframeUrl != null)\n    {\n        <iframe width=\"0\" height=\"0\" class=\"signout\" src=\"@Model.SignOutIframeUrl\"></iframe>\n    }\n</div>\n\n@section scripts\n{\n    @if (Model.AutomaticRedirectAfterSignOut)\n    {\n        <script src=\"~/js/signout-redirect.js\"></script>\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Account/Login.cshtml",
    "content": "@model LoginViewModel\n\n<div class=\"login-page\">\n    <div class=\"lead\">\n        <h1>Login</h1>\n        <p>Choose how to login</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n\n        @if (Model.EnableLocalLogin)\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>Local Account</h2>\n                    </div>\n\n                    <div class=\"card-body\">\n                        <form asp-route=\"Login\">\n                            <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n\n                            <div class=\"form-group\">\n                                <label asp-for=\"Username\"></label>\n                                <input class=\"form-control\" placeholder=\"Username\" asp-for=\"Username\" autofocus>\n                            </div>\n                            <div class=\"form-group\">\n                                <label asp-for=\"Password\"></label>\n                                <input type=\"password\" class=\"form-control\" placeholder=\"Password\" asp-for=\"Password\" autocomplete=\"off\">\n                            </div>\n                            @if (Model.AllowRememberLogin)\n                            {\n                                <div class=\"form-group\">\n                                    <div class=\"form-check\">\n                                        <input class=\"form-check-input\" asp-for=\"RememberLogin\">\n                                        <label class=\"form-check-label\" asp-for=\"RememberLogin\">\n                                            Remember My Login\n                                        </label>\n                                    </div>\n                                </div>\n                            }\n                            <button class=\"btn btn-primary\" name=\"button\" value=\"login\">Login</button>\n                            <button class=\"btn btn-secondary\" name=\"button\" value=\"cancel\" formaction=\"/Account/LoginCancel\">Cancel</button>\n                        </form>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>External Account</h2>\n                    </div>\n                    <div class=\"card-body\">\n                        <ul class=\"list-inline\">\n                            @foreach (var provider in Model.VisibleExternalProviders)\n                            {\n                                <li class=\"list-inline-item\">\n                                    <a class=\"btn btn-secondary\"\n                                       asp-controller=\"External\"\n                                       asp-action=\"Challenge\"\n                                       asp-route-scheme=\"@provider.AuthenticationScheme\"\n                                       asp-route-returnUrl=\"@Model.ReturnUrl\">\n                                        @provider.DisplayName\n                                    </a>\n                                </li>\n                            }\n                        </ul>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (!Model.EnableLocalLogin && !Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"alert alert-warning\">\n                <strong>Invalid login request</strong>\n                There are no login schemes configured for this request.\n            </div>\n        }\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Account/Logout.cshtml",
    "content": "﻿@model LogoutViewModel\n\n<div class=\"logout-page\">\n    <div class=\"lead\">\n        <h1>Logout</h1>\n        <p>Would you like to logout of IdentityServer?</p>\n    </div>\n\n    <form asp-action=\"Logout\">\n        <input type=\"hidden\" name=\"logoutId\" value=\"@Model.LogoutId\"  />\n        <div class=\"form-group\">\n            <button class=\"btn btn-primary\">Yes</button>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Consent/Index.cshtml",
    "content": "@model ConsentViewModel\n\n<div class=\"page-consent\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Index\">\n        <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Device/Success.cshtml",
    "content": "\n<div class=\"page-device-success\">\n    <div class=\"lead\">\n        <h1>Success</h1>\n        <p>You have successfully authorized the device</p>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Device/UserCodeCapture.cshtml",
    "content": "@model string\n\n<div class=\"page-device-code\">\n    <div class=\"lead\">\n        <h1>User Code</h1>\n        <p>Please enter the code displayed on your device.</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <form asp-action=\"UserCodeCapture\">\n                <div class=\"form-group\">\n                    <label for=\"userCode\">User Code:</label>\n                    <input class=\"form-control\" for=\"userCode\" name=\"userCode\" autofocus />\n                </div>\n\n                <button class=\"btn btn-primary\" name=\"button\">Submit</button>\n            </form>\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Device/UserCodeConfirmation.cshtml",
    "content": "@model DeviceAuthorizationViewModel\n\n<div class=\"page-device-confirmation\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        @if (Model.ConfirmUserCode)\n        {\n            <p>Please confirm that the authorization request quotes the code: <strong>@Model.UserCode</strong>.</p>\n        }\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Callback\">\n        <input asp-for=\"UserCode\" type=\"hidden\" value=\"@Model.UserCode\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Diagnostics/Index.cshtml",
    "content": "@model DiagnosticsViewModel\n\n<div class=\"diagnostics-page\">\n    <div class=\"lead\">\n        <h1>Authentication Cookie</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Claims</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var claim in Model.AuthenticateResult.Principal.Claims)\n                        {\n                            <dt>@claim.Type</dt>\n                            <dd>@claim.Value</dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n        \n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Properties</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var prop in Model.AuthenticateResult.Properties.Items)\n                        {\n                            <dt>@prop.Key</dt>\n                            <dd>@prop.Value</dd>\n                        }\n                        @if (Model.Clients.Any())\n                        {\n                            <dt>Clients</dt>\n                            <dd>\n                            @{\n                                var clients = Model.Clients.ToArray();\n                                for(var i = 0; i < clients.Length; i++)\n                                {\n                                    <text>@clients[i]</text>\n                                    if (i < clients.Length - 1)\n                                    {\n                                        <text>, </text>\n                                    }\n                                }\n                            }\n                            </dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n    </div>\n</div>\n\n\n\n\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Grants/Index.cshtml",
    "content": "﻿@model GrantsViewModel\n\n<div class=\"grants-page\">\n    <div class=\"lead\">\n        <h1>Client Application Permissions</h1>\n        <p>Below is the list of applications you have given permission to and the resources they have access to.</p>\n    </div>\n\n    @if (Model.Grants.Any() == false)\n    {\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                <div class=\"alert alert-info\">\n                    You have not given access to any applications\n                </div>\n            </div>\n        </div>\n    }\n    else\n    {\n        foreach (var grant in Model.Grants)\n        {\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <div class=\"row\">\n                        <div class=\"col-sm-8 card-title\">\n                            @if (grant.ClientLogoUrl != null)\n                            {\n                                <img src=\"@grant.ClientLogoUrl\">\n                            }\n                            <strong>@grant.ClientName</strong>\n                        </div>\n\n                        <div class=\"col-sm-2\">\n                            <form asp-action=\"Revoke\">\n                                <input type=\"hidden\" name=\"clientId\" value=\"@grant.ClientId\">\n                                <button class=\"btn btn-danger\">Revoke Access</button>\n                            </form>\n                        </div>\n                    </div>\n                </div>\n                \n                <ul class=\"list-group list-group-flush\">\n                    @if (grant.Description != null)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Description:</label> @grant.Description\n                        </li>   \n                    }\n                    <li class=\"list-group-item\">\n                        <label>Created:</label> @grant.Created.ToString(\"yyyy-MM-dd\")\n                    </li>\n                    @if (grant.Expires.HasValue)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Expires:</label> @grant.Expires.Value.ToString(\"yyyy-MM-dd\")\n                        </li>\n                    }\n                    @if (grant.IdentityGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Identity Grants</label>\n                            <ul>\n                                @foreach (var name in grant.IdentityGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                    @if (grant.ApiGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>API Grants</label>\n                            <ul>\n                                @foreach (var name in grant.ApiGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                </ul>\n            </div>\n        }\n    }\n</div>"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Home/Index.cshtml",
    "content": "@using System.Diagnostics\n\n@{\n    var version = FileVersionInfo.GetVersionInfo(typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.Location).ProductVersion.Split('+').First();\n}\n\n<div class=\"welcome-page\">\n    <h1>\n        <img src=\"~/icon.jpg\">\n        Welcome to IdentityServer8\n        <small class=\"text-muted\">(version @version)</small>\n    </h1>\n\n    <ul>\n        <li>\n            IdentityServer publishes a\n            <a href=\"~/.well-known/openid-configuration\">discovery document</a>\n            where you can find metadata and links to all the endpoints, key material, etc.\n        </li>\n        <li>\n            Click <a href=\"~/diagnostics\">here</a> to see the claims for your current session.\n        </li>\n        <li>\n            Click <a href=\"~/grants\">here</a> to manage your stored grants.\n        </li>\n        <li>\n            Here are links to the\n            <a href=\"https://github.com/alexhiggins732/IdentityServer8\">source code repository</a>,\n            and <a href=\"https://github.com/alexhiggins732/IdentityServer8/tree/main/samples\">ready to use samples</a>.\n        </li>\n    </ul>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Shared/Error.cshtml",
    "content": "@model ErrorViewModel\n\n@{\n    var error = Model?.Error?.Error;\n    var errorDescription = Model?.Error?.ErrorDescription;\n    var request_id = Model?.Error?.RequestId;\n}\n\n<div class=\"error-page\">\n    <div class=\"lead\">\n        <h1>Error</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <div class=\"alert alert-danger\">\n                Sorry, there was an error\n\n                @if (error != null)\n                {\n                    <strong>\n                        <em>\n                            : @error\n                        </em>\n                    </strong>\n\n                    if (errorDescription != null)\n                    {\n                        <div>@errorDescription</div>\n                    }\n                }\n            </div>\n\n            @if (request_id != null)\n            {\n                <div class=\"request-id\">Request Id: @request_id</div>\n            }\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Shared/Redirect.cshtml",
    "content": "@model RedirectViewModel\n@using Microsoft.Extensions.DependencyInjection;\n<div class=\"redirect-page\">\n    <div class=\"lead\">\n        <h1>You are now being returned to the application</h1>\n        <p>Once complete, you may close this tab.</p>\n    </div>\n</div>\n\n<meta http-equiv=\"refresh\" content=\"0;url=@Model.RedirectUrl\" data-url=\"@Model.RedirectUrl\">\n<script>\n    var url = '@Ioc.Sanitizer.Url.Sanitize(Model.RedirectUrl)';\n    window.location.href = url;\n</script>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0, shrink-to-fit=no\" />\n\n    <title>IdentityServer8</title>\n    \n    <link rel=\"icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    <link rel=\"shortcut icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    \n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <partial name=\"_Nav\" />\n   \n    <div class=\"container body-container\">\n        @RenderBody()\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.slim.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Shared/_Nav.cshtml",
    "content": "@using IdentityServer8.Extensions\n\n@{\n    string name = null;\n    if (!true.Equals(ViewData[\"signed-out\"]))\n    {\n        name = Context.User?.GetDisplayName();\n    }\n}\n\n<div class=\"nav-page\">\n    <nav class=\"navbar navbar-expand-lg navbar-dark bg-dark\">\n\n        <a href=\"~/\" class=\"navbar-brand\">\n            <img src=\"~/icon.png\" class=\"icon-banner\">\n            IdentityServer8\n        </a>\n\n        @if (!string.IsNullOrWhiteSpace(name))\n        {\n            <ul class=\"navbar-nav mr-auto\">\n                <li class=\"nav-item dropdown\">\n                    <a href=\"#\" class=\"nav-link dropdown-toggle\" data-toggle=\"dropdown\">@name <b class=\"caret\"></b></a>\n                    \n                    <div class=\"dropdown-menu\">\n                        <a class=\"dropdown-item\" asp-action=\"Logout\" asp-controller=\"Account\">Logout</a>\n                    </div>\n              </li>\n            </ul>\n        }\n    \n    </nav>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Shared/_ScopeListItem.cshtml",
    "content": "﻿@model ScopeViewModel\n\n<li class=\"list-group-item\">\n    <label>\n        <input class=\"consent-scopecheck\"\n               type=\"checkbox\"\n               name=\"ScopesConsented\"\n               id=\"scopes_@Model.Value\"\n               value=\"@Model.Value\"\n               checked=\"@Model.Checked\"\n               disabled=\"@Model.Required\" />\n        @if (Model.Required)\n        {\n            <input type=\"hidden\"\n                   name=\"ScopesConsented\"\n                   value=\"@Model.Value\" />\n        }\n        <strong>@Model.DisplayName</strong>\n        @if (Model.Emphasize)\n        {\n            <span class=\"glyphicon glyphicon-exclamation-sign\"></span>\n        }\n    </label>\n    @if (Model.Required)\n    {\n        <span><em>(required)</em></span>\n    }\n    @if (Model.Description != null)\n    {\n        <div class=\"consent-description\">\n            <label for=\"scopes_@Model.Value\">@Model.Description</label>\n        </div>\n    }\n</li>"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/Shared/_ValidationSummary.cshtml",
    "content": "﻿@if (ViewContext.ModelState.IsValid == false)\n{\n    <div class=\"alert alert-danger\">\n        <strong>Error</strong>\n        <div asp-validation-summary=\"All\" class=\"danger\"></div>\n    </div>\n}"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/_ViewImports.cshtml",
    "content": "﻿@using IdentityServerHost.Quickstart.UI\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/wwwroot/css/site.css",
    "content": "﻿.body-container {\n  margin-top: 60px;\n  padding-bottom: 40px; }\n\n.welcome-page li {\n  list-style: none;\n  padding: 4px; }\n\n.logged-out-page iframe {\n  display: none;\n  width: 0;\n  height: 0; }\n\n.grants-page .card {\n  margin-top: 20px;\n  border-bottom: 1px solid lightgray; }\n  .grants-page .card .card-title {\n    font-size: 120%;\n    font-weight: bold; }\n    .grants-page .card .card-title img {\n      width: 100px;\n      height: 100px; }\n  .grants-page .card label {\n    font-weight: bold; }\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/wwwroot/css/site.scss",
    "content": "﻿.body-container {\n    margin-top: 60px;\n    padding-bottom:40px;\n}\n\n.welcome-page {\n    li {\n        list-style: none;\n        padding: 4px;\n    }\n}\n\n.logged-out-page {\n    iframe {\n        display: none;\n        width: 0;\n        height: 0;\n    }\n}\n\n.grants-page {\n    .card {\n        margin-top: 20px;\n        border-bottom: 1px solid lightgray;\n\n        .card-title {\n            img {\n                width: 100px;\n                height: 100px;\n            }\n\n            font-size: 120%;\n            font-weight: bold;\n        }\n\n        label {\n            font-weight: bold;\n        }\n    }\n}\n\n\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/wwwroot/js/signin-redirect.js",
    "content": "// window.location.href = document.querySelector(\"meta[http-equiv=refresh]\").getAttribute(\"data-url\");\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/IdentityServer/wwwroot/js/signout-redirect.js",
    "content": "﻿window.addEventListener(\"load\", function () {\n    var a = document.querySelector(\"a.PostLogoutRedirectUri\");\n    if (a) {\n        window.location = a.href;\n    }\n});\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly ILogger<HomeController> _logger;\n\n    public HomeController(ILogger<HomeController> logger)\n    {\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    public async Task<IActionResult> CallApi()\n    {\n        var accessToken = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = new HttpClient();\n        client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue(\"Bearer\", accessToken);\n        var content = await client.GetStringAsync(\"https://localhost:6001/identity\");\n\n        var obj = JsonSerializer.Deserialize<JsonElement>(content);\n        ViewBag.Json = obj.ToString();\n        return View(\"json\");\n    }\n\n    public IActionResult Logout()\n    {\n        return SignOut(\"Cookies\", \"oidc\");\n    }\n\n    [ResponseCache(Duration = 0, Location = ResponseCacheLocation.None, NoStore = true)]\n    public IActionResult Error()\n    {\n        return View(new ErrorViewModel { RequestId = Activity.Current?.Id ?? HttpContext.TraceIdentifier });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using System.Diagnostics;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Net.Http.Headers;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Models/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class ErrorViewModel\n{\n    public string RequestId { get; set; }\n\n    public bool ShowRequestId => !string.IsNullOrEmpty(RequestId);\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/MvcClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.OpenIdConnect\" />\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <Content Update=\"Views\\Shared\\Json.cshtml\">\n      <ExcludeFromSingleFile>true</ExcludeFromSingleFile>\n      <CopyToPublishDirectory>PreserveNewest</CopyToPublishDirectory>\n    </Content>\n  </ItemGroup>\n\n</Project>"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nJwtSecurityTokenHandler.DefaultMapInboundClaims = false;\n\n\nvar builder = WebApplication.CreateBuilder(args);\n\nbuilder.Services.AddControllersWithViews();\nbuilder.Services\n    .AddAuthentication(options =>\n    {\n        options.DefaultScheme = \"Cookies\";\n        options.DefaultChallengeScheme = \"oidc\";\n    })\n    .AddCookie(\"Cookies\")\n    .AddOpenIdConnect(\"oidc\", options =>\n    {\n        options.Authority = \"https://localhost:5001\";\n\n        options.ClientId = \"mvc\";\n        options.ClientSecret = \"secret\";\n        options.ResponseType = \"code\";\n\n        options.Scope.Add(\"api1\");\n\n        options.SaveTokens = true;\n    });\n\n\nusing (var app = builder.Build())\n{\n    if (app.Environment.IsDevelopment())\n        app.UseDeveloperExceptionPage();\n    else\n        app.UseExceptionHandler(\"/Home/Error\");\n\n    app.UseStaticFiles();\n    app.UseRouting();\n    app.UseAuthentication();\n    app.UseAuthorization();\n    app.MapDefaultControllerRoute().RequireAuthorization();\n\n    await app.RunAsync();\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"MvcClient\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5002\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Views/Home/Index.cshtml",
    "content": "@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Views/Home/Privacy.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Privacy Policy\";\n}\n<h1>@ViewData[\"Title\"]</h1>\n\n<p>Use this page to detail your site's privacy policy.</p>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Views/Shared/Error.cshtml",
    "content": "﻿@model ErrorViewModel\n@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n\n@if (Model.ShowRequestId)\n{\n    <p>\n        <strong>Request ID:</strong> <code>@Model.RequestId</code>\n    </p>\n}\n\n<h3>Development Mode</h3>\n<p>\n    Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.\n</p>\n<p>\n    <strong>The Development environment shouldn't be enabled for deployed applications.</strong>\n    It can result in displaying sensitive information from exceptions to end users.\n    For local debugging, enable the <strong>Development</strong> environment by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>\n    and restarting the app.\n</p>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcClient</title>\n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <header>\n        <nav class=\"navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3\">\n            <div class=\"container\">\n                <a class=\"navbar-brand\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">MvcClient</a>\n                <button class=\"navbar-toggler\" type=\"button\" data-toggle=\"collapse\" data-target=\".navbar-collapse\" aria-controls=\"navbarSupportedContent\"\n                        aria-expanded=\"false\" aria-label=\"Toggle navigation\">\n                    <span class=\"navbar-toggler-icon\"></span>\n                </button>\n                <div class=\"navbar-collapse collapse d-sm-inline-flex flex-sm-row-reverse\">\n                    <ul class=\"navbar-nav flex-grow-1\">\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">Home</a>\n                        </li>\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Logout\">Logout</a>\n                        </li>\n                    </ul>\n                </div>\n            </div>\n        </nav>\n    </header>\n    <div class=\"container\">\n        <main role=\"main\" class=\"pb-3\">\n            @RenderBody()\n        </main>\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n    <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    @RenderSection(\"Scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Views/Shared/_ValidationScriptsPartial.cshtml",
    "content": "﻿<script src=\"~/lib/jquery-validation/dist/jquery.validate.min.js\"></script>\n<script src=\"~/lib/jquery-validation-unobtrusive/jquery.validate.unobtrusive.min.js\"></script>\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Views/Shared/json.cshtml",
    "content": "<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/appsettings.Development.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Debug\",\n      \"System\": \"Information\",\n      \"Microsoft\": \"Information\"\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/appsettings.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Information\",\n      \"Microsoft\": \"Warning\",\n      \"Microsoft.Hosting.Lifetime\": \"Information\"\n    }\n  },\n  \"AllowedHosts\": \"*\"\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/wwwroot/css/site.css",
    "content": "﻿/* Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\nfor details on configuring this project to bundle and minify static web assets. */\n\na.navbar-brand {\n  white-space: normal;\n  text-align: center;\n  word-break: break-all;\n}\n\n/* Provide sufficient contrast against white background */\na {\n  color: #0366d6;\n}\n\n.btn-primary {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n.nav-pills .nav-link.active, .nav-pills .show > .nav-link {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  font-size: 14px;\n}\n@media (min-width: 768px) {\n  html {\n    font-size: 16px;\n  }\n}\n\n.border-top {\n  border-top: 1px solid #e5e5e5;\n}\n.border-bottom {\n  border-bottom: 1px solid #e5e5e5;\n}\n\n.box-shadow {\n  box-shadow: 0 .25rem .75rem rgba(0, 0, 0, .05);\n}\n\nbutton.accept-policy {\n  font-size: 1rem;\n  line-height: inherit;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  position: relative;\n  min-height: 100%;\n}\n\nbody {\n  /* Margin bottom by footer height */\n  margin-bottom: 60px;\n}\n.footer {\n  position: absolute;\n  bottom: 0;\n  width: 100%;\n  white-space: nowrap;\n  line-height: 60px; /* Vertically center the text there */\n}\n"
  },
  {
    "path": "samples/Quickstarts/5_EntityFramework/src/MvcClient/wwwroot/js/site.js",
    "content": "﻿// Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\n// for details on configuring this project to bundle and minify static web assets.\n\n// Write your JavaScript code.\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/Quickstart.sln",
    "content": "﻿\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 15.0.26124.0\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{BD8BA25C-A91D-419D-99B6-B575ADD6D061}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"MvcClient\", \"src\\MvcClient\\MvcClient.csproj\", \"{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServerAspNetIdentity\", \"src\\IdentityServerAspNetIdentity\\IdentityServerAspNetIdentity.csproj\", \"{C49859B4-B34C-4594-A307-674719F71122}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Api\", \"..\\Shared\\src\\Api\\Api.csproj\", \"{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Client\", \"..\\Shared\\src\\Client\\Client.csproj\", \"{3BFAC242-776F-4B31-9658-D48F05BF355D}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tDebug|x64 = Debug|x64\n\t\tDebug|x86 = Debug|x86\n\t\tRelease|Any CPU = Release|Any CPU\n\t\tRelease|x64 = Release|x64\n\t\tRelease|x86 = Release|x86\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x64.Build.0 = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12}.Release|x86.Build.0 = Release|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Release|x64.Build.0 = Release|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{C49859B4-B34C-4594-A307-674719F71122}.Release|x86.Build.0 = Release|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Release|x64.Build.0 = Release|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{BC4283E1-A6F7-43BF-B0E4-8D91531DD0BE}.Release|x86.Build.0 = Release|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Release|x64.Build.0 = Release|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{3BFAC242-776F-4B31-9658-D48F05BF355D}.Release|x86.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{BF5923FF-9E93-4C01-93C2-8CE7A3F62D12} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\t\t{C49859B4-B34C-4594-A307-674719F71122} = {BD8BA25C-A91D-419D-99B6-B575ADD6D061}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {84D5AF06-1243-46F1-9D58-70ED572832C3}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/Quickstart.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft\n Written by Alexander Higgins https://github.com/alexhiggins732/ \n \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code for this software can be found at https://github.com/alexhiggins732/IdentityServer8\n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n\n*/\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Config.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic static class Config\n{\n    public static IEnumerable<IdentityResource> IdentityResources =>\n        new List<IdentityResource>\n        {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n        };\n\n\n    public static IEnumerable<ApiScope> ApiScopes =>\n        new List<ApiScope>\n        {\n            new ApiScope(\"api1\", \"My API\")\n        };\n\n    public static IEnumerable<Client> Clients =>\n        new List<Client>\n        {\n            // machine to machine client\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                // scopes that client has access to\n                AllowedScopes = { \"api1\" }\n            },\n            \n            // interactive ASP.NET Core MVC client\n            new Client\n            {\n                ClientId = \"mvc\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.Code,\n                \n                // where to redirect to after login\n                RedirectUris = { \"https://localhost:5002/signin-oidc\" },\n\n                // where to redirect to after logout\n                PostLogoutRedirectUris = { \"https://localhost:5002/signout-callback-oidc\" },\n\n                AllowedScopes = new List<string>\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    \"api1\"\n                }\n            }\n        };\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Data/ApplicationDbContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore.Identity.EntityFrameworkCore;\n\nnamespace IdentityServerAspNetIdentity.Data\n{\n    public class ApplicationDbContext : IdentityDbContext<ApplicationUser>\n    {\n        public ApplicationDbContext(DbContextOptions<ApplicationDbContext> options)\n            : base(options)\n        {\n        }\n\n        protected override void OnModelCreating(ModelBuilder builder)\n        {\n            base.OnModelCreating(builder);\n            // Customize the ASP.NET Identity model and override the defaults if needed.\n            // For example, you can rename the ASP.NET Identity table names and more.\n            // Add your customizations after calling base.OnModelCreating(builder);\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Data/Migrations/20180109192453_CreateIdentitySchema.Designer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\nusing Microsoft.EntityFrameworkCore.Infrastructure;\nusing Microsoft.EntityFrameworkCore.Migrations;\n\nnamespace IdentityServerAspNetIdentity.Data.Migrations\n{\n    [DbContext(typeof(ApplicationDbContext))]\n    [Migration(\"20180109192453_CreateIdentitySchema\")]\n    partial class CreateIdentitySchema\n    {\n        protected override void BuildTargetModel(ModelBuilder modelBuilder)\n        {\n#pragma warning disable 612, 618\n            modelBuilder\n                .HasAnnotation(\"ProductVersion\", \"2.0.1-rtm-125\");\n\n            modelBuilder.Entity(\"IdentityServerAspNetIdentity.Models.ApplicationUser\", b =>\n                {\n                    b.Property<string>(\"Id\")\n                        .ValueGeneratedOnAdd();\n\n                    b.Property<int>(\"AccessFailedCount\");\n\n                    b.Property<string>(\"ConcurrencyStamp\")\n                        .IsConcurrencyToken();\n\n                    b.Property<string>(\"Email\")\n                        .HasMaxLength(256);\n\n                    b.Property<bool>(\"EmailConfirmed\");\n\n                    b.Property<bool>(\"LockoutEnabled\");\n\n                    b.Property<DateTimeOffset?>(\"LockoutEnd\");\n\n                    b.Property<string>(\"NormalizedEmail\")\n                        .HasMaxLength(256);\n\n                    b.Property<string>(\"NormalizedUserName\")\n                        .HasMaxLength(256);\n\n                    b.Property<string>(\"PasswordHash\");\n\n                    b.Property<string>(\"PhoneNumber\");\n\n                    b.Property<bool>(\"PhoneNumberConfirmed\");\n\n                    b.Property<string>(\"SecurityStamp\");\n\n                    b.Property<bool>(\"TwoFactorEnabled\");\n\n                    b.Property<string>(\"UserName\")\n                        .HasMaxLength(256);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"NormalizedEmail\")\n                        .HasName(\"EmailIndex\");\n\n                    b.HasIndex(\"NormalizedUserName\")\n                        .IsUnique()\n                        .HasName(\"UserNameIndex\");\n\n                    b.ToTable(\"AspNetUsers\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRole\", b =>\n                {\n                    b.Property<string>(\"Id\")\n                        .ValueGeneratedOnAdd();\n\n                    b.Property<string>(\"ConcurrencyStamp\")\n                        .IsConcurrencyToken();\n\n                    b.Property<string>(\"Name\")\n                        .HasMaxLength(256);\n\n                    b.Property<string>(\"NormalizedName\")\n                        .HasMaxLength(256);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"NormalizedName\")\n                        .IsUnique()\n                        .HasName(\"RoleNameIndex\");\n\n                    b.ToTable(\"AspNetRoles\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRoleClaim<string>\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd();\n\n                    b.Property<string>(\"ClaimType\");\n\n                    b.Property<string>(\"ClaimValue\");\n\n                    b.Property<string>(\"RoleId\")\n                        .IsRequired();\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"RoleId\");\n\n                    b.ToTable(\"AspNetRoleClaims\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserClaim<string>\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd();\n\n                    b.Property<string>(\"ClaimType\");\n\n                    b.Property<string>(\"ClaimValue\");\n\n                    b.Property<string>(\"UserId\")\n                        .IsRequired();\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"UserId\");\n\n                    b.ToTable(\"AspNetUserClaims\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserLogin<string>\", b =>\n                {\n                    b.Property<string>(\"LoginProvider\");\n\n                    b.Property<string>(\"ProviderKey\");\n\n                    b.Property<string>(\"ProviderDisplayName\");\n\n                    b.Property<string>(\"UserId\")\n                        .IsRequired();\n\n                    b.HasKey(\"LoginProvider\", \"ProviderKey\");\n\n                    b.HasIndex(\"UserId\");\n\n                    b.ToTable(\"AspNetUserLogins\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserRole<string>\", b =>\n                {\n                    b.Property<string>(\"UserId\");\n\n                    b.Property<string>(\"RoleId\");\n\n                    b.HasKey(\"UserId\", \"RoleId\");\n\n                    b.HasIndex(\"RoleId\");\n\n                    b.ToTable(\"AspNetUserRoles\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserToken<string>\", b =>\n                {\n                    b.Property<string>(\"UserId\");\n\n                    b.Property<string>(\"LoginProvider\");\n\n                    b.Property<string>(\"Name\");\n\n                    b.Property<string>(\"Value\");\n\n                    b.HasKey(\"UserId\", \"LoginProvider\", \"Name\");\n\n                    b.ToTable(\"AspNetUserTokens\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRoleClaim<string>\", b =>\n                {\n                    b.HasOne(\"Microsoft.AspNetCore.Identity.IdentityRole\")\n                        .WithMany()\n                        .HasForeignKey(\"RoleId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserClaim<string>\", b =>\n                {\n                    b.HasOne(\"IdentityServerAspNetIdentity.Models.ApplicationUser\")\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserLogin<string>\", b =>\n                {\n                    b.HasOne(\"IdentityServerAspNetIdentity.Models.ApplicationUser\")\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserRole<string>\", b =>\n                {\n                    b.HasOne(\"Microsoft.AspNetCore.Identity.IdentityRole\")\n                        .WithMany()\n                        .HasForeignKey(\"RoleId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n\n                    b.HasOne(\"IdentityServerAspNetIdentity.Models.ApplicationUser\")\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserToken<string>\", b =>\n                {\n                    b.HasOne(\"IdentityServerAspNetIdentity.Models.ApplicationUser\")\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n                });\n#pragma warning restore 612, 618\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Data/Migrations/20180109192453_CreateIdentitySchema.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.EntityFrameworkCore.Migrations;\n\nnamespace IdentityServerAspNetIdentity.Data.Migrations\n{\n    public partial class CreateIdentitySchema : Migration\n    {\n        protected override void Up(MigrationBuilder migrationBuilder)\n        {\n            migrationBuilder.CreateTable(\n                name: \"AspNetRoles\",\n                columns: table => new\n                {\n                    Id = table.Column<string>(nullable: false),\n                    ConcurrencyStamp = table.Column<string>(nullable: true),\n                    Name = table.Column<string>(maxLength: 256, nullable: true),\n                    NormalizedName = table.Column<string>(maxLength: 256, nullable: true)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_AspNetRoles\", x => x.Id);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"AspNetUsers\",\n                columns: table => new\n                {\n                    Id = table.Column<string>(nullable: false),\n                    AccessFailedCount = table.Column<int>(nullable: false),\n                    ConcurrencyStamp = table.Column<string>(nullable: true),\n                    Email = table.Column<string>(maxLength: 256, nullable: true),\n                    EmailConfirmed = table.Column<bool>(nullable: false),\n                    LockoutEnabled = table.Column<bool>(nullable: false),\n                    LockoutEnd = table.Column<DateTimeOffset>(nullable: true),\n                    NormalizedEmail = table.Column<string>(maxLength: 256, nullable: true),\n                    NormalizedUserName = table.Column<string>(maxLength: 256, nullable: true),\n                    PasswordHash = table.Column<string>(nullable: true),\n                    PhoneNumber = table.Column<string>(nullable: true),\n                    PhoneNumberConfirmed = table.Column<bool>(nullable: false),\n                    SecurityStamp = table.Column<string>(nullable: true),\n                    TwoFactorEnabled = table.Column<bool>(nullable: false),\n                    UserName = table.Column<string>(maxLength: 256, nullable: true)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_AspNetUsers\", x => x.Id);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"AspNetRoleClaims\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"Sqlite:Autoincrement\", true),\n                    ClaimType = table.Column<string>(nullable: true),\n                    ClaimValue = table.Column<string>(nullable: true),\n                    RoleId = table.Column<string>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_AspNetRoleClaims\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_AspNetRoleClaims_AspNetRoles_RoleId\",\n                        column: x => x.RoleId,\n                        principalTable: \"AspNetRoles\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"AspNetUserClaims\",\n                columns: table => new\n                {\n                    Id = table.Column<int>(nullable: false)\n                        .Annotation(\"Sqlite:Autoincrement\", true),\n                    ClaimType = table.Column<string>(nullable: true),\n                    ClaimValue = table.Column<string>(nullable: true),\n                    UserId = table.Column<string>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_AspNetUserClaims\", x => x.Id);\n                    table.ForeignKey(\n                        name: \"FK_AspNetUserClaims_AspNetUsers_UserId\",\n                        column: x => x.UserId,\n                        principalTable: \"AspNetUsers\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"AspNetUserLogins\",\n                columns: table => new\n                {\n                    LoginProvider = table.Column<string>(nullable: false),\n                    ProviderKey = table.Column<string>(nullable: false),\n                    ProviderDisplayName = table.Column<string>(nullable: true),\n                    UserId = table.Column<string>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_AspNetUserLogins\", x => new { x.LoginProvider, x.ProviderKey });\n                    table.ForeignKey(\n                        name: \"FK_AspNetUserLogins_AspNetUsers_UserId\",\n                        column: x => x.UserId,\n                        principalTable: \"AspNetUsers\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"AspNetUserRoles\",\n                columns: table => new\n                {\n                    UserId = table.Column<string>(nullable: false),\n                    RoleId = table.Column<string>(nullable: false)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_AspNetUserRoles\", x => new { x.UserId, x.RoleId });\n                    table.ForeignKey(\n                        name: \"FK_AspNetUserRoles_AspNetRoles_RoleId\",\n                        column: x => x.RoleId,\n                        principalTable: \"AspNetRoles\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                    table.ForeignKey(\n                        name: \"FK_AspNetUserRoles_AspNetUsers_UserId\",\n                        column: x => x.UserId,\n                        principalTable: \"AspNetUsers\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateTable(\n                name: \"AspNetUserTokens\",\n                columns: table => new\n                {\n                    UserId = table.Column<string>(nullable: false),\n                    LoginProvider = table.Column<string>(nullable: false),\n                    Name = table.Column<string>(nullable: false),\n                    Value = table.Column<string>(nullable: true)\n                },\n                constraints: table =>\n                {\n                    table.PrimaryKey(\"PK_AspNetUserTokens\", x => new { x.UserId, x.LoginProvider, x.Name });\n                    table.ForeignKey(\n                        name: \"FK_AspNetUserTokens_AspNetUsers_UserId\",\n                        column: x => x.UserId,\n                        principalTable: \"AspNetUsers\",\n                        principalColumn: \"Id\",\n                        onDelete: ReferentialAction.Cascade);\n                });\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_AspNetRoleClaims_RoleId\",\n                table: \"AspNetRoleClaims\",\n                column: \"RoleId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"RoleNameIndex\",\n                table: \"AspNetRoles\",\n                column: \"NormalizedName\",\n                unique: true);\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_AspNetUserClaims_UserId\",\n                table: \"AspNetUserClaims\",\n                column: \"UserId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_AspNetUserLogins_UserId\",\n                table: \"AspNetUserLogins\",\n                column: \"UserId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"IX_AspNetUserRoles_RoleId\",\n                table: \"AspNetUserRoles\",\n                column: \"RoleId\");\n\n            migrationBuilder.CreateIndex(\n                name: \"EmailIndex\",\n                table: \"AspNetUsers\",\n                column: \"NormalizedEmail\");\n\n            migrationBuilder.CreateIndex(\n                name: \"UserNameIndex\",\n                table: \"AspNetUsers\",\n                column: \"NormalizedUserName\",\n                unique: true);\n        }\n\n        protected override void Down(MigrationBuilder migrationBuilder)\n        {\n            migrationBuilder.DropTable(\n                name: \"AspNetRoleClaims\");\n\n            migrationBuilder.DropTable(\n                name: \"AspNetUserClaims\");\n\n            migrationBuilder.DropTable(\n                name: \"AspNetUserLogins\");\n\n            migrationBuilder.DropTable(\n                name: \"AspNetUserRoles\");\n\n            migrationBuilder.DropTable(\n                name: \"AspNetUserTokens\");\n\n            migrationBuilder.DropTable(\n                name: \"AspNetRoles\");\n\n            migrationBuilder.DropTable(\n                name: \"AspNetUsers\");\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Data/Migrations/ApplicationDbContextModelSnapshot.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\nusing Microsoft.EntityFrameworkCore.Infrastructure;\n\nnamespace IdentityServerAspNetIdentity.Data.Migrations\n{\n    [DbContext(typeof(ApplicationDbContext))]\n    partial class ApplicationDbContextModelSnapshot : ModelSnapshot\n    {\n        protected override void BuildModel(ModelBuilder modelBuilder)\n        {\n#pragma warning disable 612, 618\n            modelBuilder\n                .HasAnnotation(\"ProductVersion\", \"2.0.1-rtm-125\");\n\n            modelBuilder.Entity(\"IdentityServerAspNetIdentity.Models.ApplicationUser\", b =>\n                {\n                    b.Property<string>(\"Id\")\n                        .ValueGeneratedOnAdd();\n\n                    b.Property<int>(\"AccessFailedCount\");\n\n                    b.Property<string>(\"ConcurrencyStamp\")\n                        .IsConcurrencyToken();\n\n                    b.Property<string>(\"Email\")\n                        .HasMaxLength(256);\n\n                    b.Property<bool>(\"EmailConfirmed\");\n\n                    b.Property<bool>(\"LockoutEnabled\");\n\n                    b.Property<DateTimeOffset?>(\"LockoutEnd\");\n\n                    b.Property<string>(\"NormalizedEmail\")\n                        .HasMaxLength(256);\n\n                    b.Property<string>(\"NormalizedUserName\")\n                        .HasMaxLength(256);\n\n                    b.Property<string>(\"PasswordHash\");\n\n                    b.Property<string>(\"PhoneNumber\");\n\n                    b.Property<bool>(\"PhoneNumberConfirmed\");\n\n                    b.Property<string>(\"SecurityStamp\");\n\n                    b.Property<bool>(\"TwoFactorEnabled\");\n\n                    b.Property<string>(\"UserName\")\n                        .HasMaxLength(256);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"NormalizedEmail\")\n                        .HasName(\"EmailIndex\");\n\n                    b.HasIndex(\"NormalizedUserName\")\n                        .IsUnique()\n                        .HasName(\"UserNameIndex\");\n\n                    b.ToTable(\"AspNetUsers\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRole\", b =>\n                {\n                    b.Property<string>(\"Id\")\n                        .ValueGeneratedOnAdd();\n\n                    b.Property<string>(\"ConcurrencyStamp\")\n                        .IsConcurrencyToken();\n\n                    b.Property<string>(\"Name\")\n                        .HasMaxLength(256);\n\n                    b.Property<string>(\"NormalizedName\")\n                        .HasMaxLength(256);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"NormalizedName\")\n                        .IsUnique()\n                        .HasName(\"RoleNameIndex\");\n\n                    b.ToTable(\"AspNetRoles\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRoleClaim<string>\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd();\n\n                    b.Property<string>(\"ClaimType\");\n\n                    b.Property<string>(\"ClaimValue\");\n\n                    b.Property<string>(\"RoleId\")\n                        .IsRequired();\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"RoleId\");\n\n                    b.ToTable(\"AspNetRoleClaims\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserClaim<string>\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd();\n\n                    b.Property<string>(\"ClaimType\");\n\n                    b.Property<string>(\"ClaimValue\");\n\n                    b.Property<string>(\"UserId\")\n                        .IsRequired();\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"UserId\");\n\n                    b.ToTable(\"AspNetUserClaims\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserLogin<string>\", b =>\n                {\n                    b.Property<string>(\"LoginProvider\");\n\n                    b.Property<string>(\"ProviderKey\");\n\n                    b.Property<string>(\"ProviderDisplayName\");\n\n                    b.Property<string>(\"UserId\")\n                        .IsRequired();\n\n                    b.HasKey(\"LoginProvider\", \"ProviderKey\");\n\n                    b.HasIndex(\"UserId\");\n\n                    b.ToTable(\"AspNetUserLogins\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserRole<string>\", b =>\n                {\n                    b.Property<string>(\"UserId\");\n\n                    b.Property<string>(\"RoleId\");\n\n                    b.HasKey(\"UserId\", \"RoleId\");\n\n                    b.HasIndex(\"RoleId\");\n\n                    b.ToTable(\"AspNetUserRoles\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserToken<string>\", b =>\n                {\n                    b.Property<string>(\"UserId\");\n\n                    b.Property<string>(\"LoginProvider\");\n\n                    b.Property<string>(\"Name\");\n\n                    b.Property<string>(\"Value\");\n\n                    b.HasKey(\"UserId\", \"LoginProvider\", \"Name\");\n\n                    b.ToTable(\"AspNetUserTokens\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRoleClaim<string>\", b =>\n                {\n                    b.HasOne(\"Microsoft.AspNetCore.Identity.IdentityRole\")\n                        .WithMany()\n                        .HasForeignKey(\"RoleId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserClaim<string>\", b =>\n                {\n                    b.HasOne(\"IdentityServerAspNetIdentity.Models.ApplicationUser\")\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserLogin<string>\", b =>\n                {\n                    b.HasOne(\"IdentityServerAspNetIdentity.Models.ApplicationUser\")\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserRole<string>\", b =>\n                {\n                    b.HasOne(\"Microsoft.AspNetCore.Identity.IdentityRole\")\n                        .WithMany()\n                        .HasForeignKey(\"RoleId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n\n                    b.HasOne(\"IdentityServerAspNetIdentity.Models.ApplicationUser\")\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserToken<string>\", b =>\n                {\n                    b.HasOne(\"IdentityServerAspNetIdentity.Models.ApplicationUser\")\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade);\n                });\n#pragma warning restore 612, 618\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.Configuration;\nglobal using IdentityServer8.Events;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Test;\nglobal using IdentityServer8.Validation;\nglobal using IdentityServerAspNetIdentity;\nglobal using IdentityServerHost.Quickstart.UI;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Hosting;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.AspNetCore.Mvc.Filters;\nglobal using Microsoft.Extensions.Hosting;\nglobal using Microsoft.Extensions.Options;\nglobal using Microsoft.Extensions.DependencyInjection;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\nglobal using System;\nglobal using System.ComponentModel.DataAnnotations;\nglobal using System.Linq;\nglobal using System.Security.Claims;\nglobal using System.Text;\nglobal using System.Text.Json;\nglobal using static IdentityModel.JwtClaimTypes;\nglobal using IdentityServerClaimValueTypes = IdentityServer8.IdentityServerConstants.ClaimValueTypes;\nglobal using IdentityServerAspNetIdentity.Data;\nglobal using IdentityServerAspNetIdentity.Models;\nglobal using Microsoft.AspNetCore.Identity;\nglobal using Microsoft.EntityFrameworkCore;\nglobal using Secret = IdentityServer8.Models.Secret;"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/IdentityServerAspNetIdentity.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n  <ItemGroup>\n    <PackageReference Include=\"jQuery\" />\n    <PackageReference Include=\"jQuery.validation\" />\n    <PackageReference Include=\"HigginsSoft.IdentityServer8\" />\n    <PackageReference Include=\"HigginsSoft.IdentityServer8.AspnetIdentity\" />\n     <PackageReference Include=\"HigginsSoft.IdentityServer8.Security\" />\n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.Google\" />\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n\n\n    <PackageReference Include=\"Microsoft.AspNetCore.Diagnostics.EntityFrameworkCore\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.Sqlite\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.Tools\">\n      <PrivateAssets>all</PrivateAssets>\n      <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n    </PackageReference>\n\n    <PackageReference Include=\"Microsoft.AspNetCore.Identity.EntityFrameworkCore\" />\n    <PackageReference Include=\"Microsoft.AspNetCore.Identity.UI\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Models/ApplicationUser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore.Identity;\n\nnamespace IdentityServerAspNetIdentity.Models\n{\n    // Add profile data for application users by adding properties to the ApplicationUser class\n    public class ApplicationUser : IdentityUser\n    {\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConfigureLogger();\n\ntry\n{\n    var builder = WebApplication.CreateBuilder(args.Where(x => x != \"/seed\").ToArray());\n\n    var services = builder.Services;\n\n    services.AddControllersWithViews();\n\n    services.AddDbContext<ApplicationDbContext>(options =>\n        options.UseSqlite(builder.Configuration.GetConnectionString(\"DefaultConnection\")));\n\n    services.AddIdentity<ApplicationUser, IdentityRole>()\n        .AddEntityFrameworkStores<ApplicationDbContext>()\n        .AddDefaultTokenProviders();\n\n    services.AddIdentityServer(options =>\n         {\n             options.Events.RaiseErrorEvents = true;\n             options.Events.RaiseInformationEvents = true;\n             options.Events.RaiseFailureEvents = true;\n             options.Events.RaiseSuccessEvents = true;\n\n             // see https://IdentityServer8.readthedocs.io/en/latest/topics/resources.html\n             options.EmitStaticAudienceClaim = true;\n         })\n         .AddInMemoryIdentityResources(Config.IdentityResources)\n         .AddInMemoryApiScopes(Config.ApiScopes)\n         .AddInMemoryClients(Config.Clients)\n         .AddAspNetIdentity<ApplicationUser>()\n         // not recommended for production - you need to store your key material somewhere secure\n         .AddDeveloperSigningCredential();\n\n\n    services.AddAuthentication()\n        .AddGoogle(options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n            // register your IdentityServer with Google at https://console.developers.google.com\n            // enable the Google+ API\n            // set the redirect URI to https://localhost:5001/signin-google\n            options.ClientId = \"copy client ID from Google here\";\n            options.ClientSecret = \"copy client secret from Google here\";\n        });\n\n\n    using (var app = builder.Build())\n    {\n\n\n        if (args.Contains(\"/seed\"))\n        {\n            Log.Information(\"Seeding database...\");\n            var config = app.Services.GetRequiredService<IConfiguration>();\n            var connectionString = config.GetConnectionString(\"DefaultConnection\");\n            SeedData.EnsureSeedData(connectionString);\n            Log.Information(\"Done seeding database.\");\n            return 0;\n        }\n\n        if (app.Environment.IsDevelopment())\n        {\n            app.UseDeveloperExceptionPage();\n            app.UseMigrationsEndPoint();\n            app.UseDatabaseErrorPage();\n        }\n        else\n        {\n            app.UseExceptionHandler(\"/Home/Error\");\n            app.UseHsts();\n        }\n\n\n        app.UseStaticFiles();\n\n        app.UseRouting();\n        app.UseIdentityServer();\n        app.UseAuthorization();\n        app.MapDefaultControllerRoute();\n\n\n        Log.Information(\"Starting host...\");\n\n        await app.RunAsync();\n    }\n    return 0;\n}\ncatch (Exception ex)\n{\n    Log.Fatal(ex, \"Host terminated unexpectedly.\");\n    return 1;\n}\nfinally\n{\n    Log.CloseAndFlush();\n}\n\nvoid ConfigureLogger() => Log.Logger = new LoggerConfiguration()\n    .MinimumLevel.Debug()\n    .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n    .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n    .Enrich.FromLogContext()\n    // uncomment to write to Azure diagnostics stream\n    //.WriteTo.File(\n    //    @\"D:\\home\\LogFiles\\Application\\identityserver.txt\",\n    //    fileSizeLimitBytes: 1_000_000,\n    //    rollOnFileSizeLimit: true,\n    //    shared: true,\n    //    flushToDiskInterval: TimeSpan.FromSeconds(1))\n    .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n    .CreateLogger();\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"SelfHost\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Account/AccountController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller implements a typical login/logout/provision workflow for local and external accounts.\n/// The login service encapsulates the interactions with the user data store. This data store is in-memory only and cannot be used for production!\n/// The interaction service provides a way for the UI to communicate with identityserver for validation and context retrieval\n/// </summary>\n[SecurityHeaders]\n[AllowAnonymous]\npublic class AccountController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly IAuthenticationSchemeProvider _schemeProvider;\n    private readonly IEventService _events;\n\n    public AccountController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IAuthenticationSchemeProvider schemeProvider,\n        IEventService events,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _schemeProvider = schemeProvider;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Entry point into the login workflow\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Login(string returnUrl)\n    {\n        // build a model so we know what to show on the login page\n        var vm = await BuildLoginViewModelAsync(returnUrl);\n\n        if (vm.IsExternalLoginOnly)\n        {\n            // we only have one option for logging in and it's an external provider\n            return returnUrl.IsAllowedRedirect() ? RedirectToAction(\"Challenge\", \"External\", new { scheme = vm.ExternalLoginScheme, returnUrl = returnUrl.SanitizeForRedirect() }) : Forbid();\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Login(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (ModelState.IsValid)\n        {\n            // validate username/password against in-memory store\n            if (_users.ValidateCredentials(model.Username, model.Password))\n            {\n                var user = _users.FindByUsername(model.Username);\n                await _events.RaiseAsync(new UserLoginSuccessEvent(user.Username, user.SubjectId, user.Username, clientId: context?.Client.ClientId));\n\n                // only set explicit expiration here if user chooses \"remember me\". \n                // otherwise we rely upon expiration configured in cookie middleware.\n                AuthenticationProperties props = null;\n                if (AccountOptions.AllowRememberLogin && model.RememberLogin)\n                {\n                    props = new AuthenticationProperties\n                    {\n                        IsPersistent = true,\n                        ExpiresUtc = DateTimeOffset.UtcNow.Add(AccountOptions.RememberMeLoginDuration)\n                    };\n                };\n\n                // issue authentication cookie with subject ID and username\n                var isuser = new IdentityServerUser(user.SubjectId)\n                {\n                    DisplayName = user.Username\n                };\n\n                await HttpContext.SignInAsync(isuser, props);\n\n                if (context != null)\n                {\n                    if (context.IsNativeClient())\n                    {\n                        // The client is native, so this change in how to\n                        // return the response is for better UX for the end user.\n                        return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                    }\n\n                    // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n\n                // request for a local page\n                if (Url.IsLocalUrl(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n                else if (string.IsNullOrEmpty(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n                }\n                else\n                {\n                    // user might have clicked on a malicious link - should be logged\n                    throw new Exception(\"invalid return URL\");\n                }\n            }\n\n            await _events.RaiseAsync(new UserLoginFailureEvent(model.Username, \"invalid credentials\", clientId: context?.Client.ClientId));\n            ModelState.AddModelError(string.Empty, AccountOptions.InvalidCredentialsErrorMessage);\n        }\n\n        // something went wrong, show form with error\n        var vm = await BuildLoginViewModelAsync(model);\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> LoginCancel(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (context != null)\n        {\n            // if the user cancels, send a result back into IdentityServer as if they \n            // denied the consent (even if this client does not require consent).\n            // this will send back an access denied OIDC error response to the client.\n            await _interaction.DenyAuthorizationAsync(context, AuthorizationError.AccessDenied);\n\n            // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n            }\n\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n        }\n        else\n        {\n            // since we don't have a valid context, then we just go back to the home page\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n        }\n\n    }\n\n    /// <summary>\n    /// Show logout page\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Logout(string logoutId)\n    {\n        // build a model so the logout page knows what to display\n        var vm = await BuildLogoutViewModelAsync(logoutId);\n\n        if (vm.ShowLogoutPrompt == false)\n        {\n            // if the request for logout was properly authenticated from IdentityServer, then\n            // we don't need to show the prompt and can just log the user out directly.\n            return await Logout(vm);\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle logout page postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Logout(LogoutInputModel model)\n    {\n        // build a model so the logged out page knows what to display\n        var vm = await BuildLoggedOutViewModelAsync(model.LogoutId);\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            // delete local authentication cookie\n            await HttpContext.SignOutAsync();\n\n            // raise the logout event\n            await _events.RaiseAsync(new UserLogoutSuccessEvent(User.GetSubjectId(), User.GetDisplayName()));\n        }\n\n        // check if we need to trigger sign-out at an upstream identity provider\n        if (vm.TriggerExternalSignout)\n        {\n            // build a return URL so the upstream provider will redirect back\n            // to us after the user has logged out. this allows us to then\n            // complete our single sign-out processing.\n            string url = Url.Action(\"Logout\", new { logoutId = vm.LogoutId });\n\n            // this triggers a redirect to the external provider for sign-out\n            return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);\n        }\n\n        return View(\"LoggedOut\", vm);\n    }\n\n    [HttpGet]\n    public IActionResult AccessDenied()\n    {\n        return View();\n    }\n\n\n    /*****************************************/\n    /* helper APIs for the AccountController */\n    /*****************************************/\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(string returnUrl)\n    {\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (context?.IdP != null && await _schemeProvider.GetSchemeAsync(context.IdP) != null)\n        {\n            var local = context.IdP == IdentityServer8.IdentityServerConstants.LocalIdentityProvider;\n\n            // this is meant to short circuit the UI and only trigger the one external IdP\n            var vm = new LoginViewModel\n            {\n                EnableLocalLogin = local,\n                ReturnUrl = returnUrl,\n                Username = context?.LoginHint,\n            };\n\n            if (!local)\n            {\n                vm.ExternalProviders = new[] { new ExternalProvider { AuthenticationScheme = context.IdP } };\n            }\n\n            return vm;\n        }\n\n        var schemes = await _schemeProvider.GetAllSchemesAsync();\n\n        var providers = schemes\n            .Where(x => x.DisplayName != null)\n            .Select(x => new ExternalProvider\n            {\n                DisplayName = x.DisplayName ?? x.Name,\n                AuthenticationScheme = x.Name\n            }).ToList();\n\n        var allowLocal = true;\n        if (context?.Client.ClientId != null)\n        {\n            var client = await _clientStore.FindEnabledClientByIdAsync(context.Client.ClientId);\n            if (client != null)\n            {\n                allowLocal = client.EnableLocalLogin;\n\n                if (client.IdentityProviderRestrictions != null && client.IdentityProviderRestrictions.Any())\n                {\n                    providers = providers.Where(provider => client.IdentityProviderRestrictions.Contains(provider.AuthenticationScheme)).ToList();\n                }\n            }\n        }\n\n        return new LoginViewModel\n        {\n            AllowRememberLogin = AccountOptions.AllowRememberLogin,\n            EnableLocalLogin = allowLocal && AccountOptions.AllowLocalLogin,\n            ReturnUrl = returnUrl,\n            Username = context?.LoginHint,\n            ExternalProviders = providers.ToArray()\n        };\n    }\n\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(LoginInputModel model)\n    {\n        var vm = await BuildLoginViewModelAsync(model.ReturnUrl);\n        vm.Username = model.Username;\n        vm.RememberLogin = model.RememberLogin;\n        return vm;\n    }\n\n    private async Task<LogoutViewModel> BuildLogoutViewModelAsync(string logoutId)\n    {\n        var vm = new LogoutViewModel { LogoutId = logoutId, ShowLogoutPrompt = AccountOptions.ShowLogoutPrompt };\n\n        if (User?.Identity.IsAuthenticated != true)\n        {\n            // if the user is not authenticated, then just show logged out page\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        var context = await _interaction.GetLogoutContextAsync(logoutId);\n        if (context?.ShowSignoutPrompt == false)\n        {\n            // it's safe to automatically sign-out\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        // show the logout prompt. this prevents attacks where the user\n        // is automatically signed out by another malicious web page.\n        return vm;\n    }\n\n    private async Task<LoggedOutViewModel> BuildLoggedOutViewModelAsync(string logoutId)\n    {\n        // get context information (client name, post logout redirect URI and iframe for federated signout)\n        var logout = await _interaction.GetLogoutContextAsync(logoutId);\n\n        var vm = new LoggedOutViewModel\n        {\n            AutomaticRedirectAfterSignOut = AccountOptions.AutomaticRedirectAfterSignOut,\n            PostLogoutRedirectUri = logout?.PostLogoutRedirectUri,\n            ClientName = string.IsNullOrEmpty(logout?.ClientName) ? logout?.ClientId : logout?.ClientName,\n            SignOutIframeUrl = logout?.SignOutIFrameUrl,\n            LogoutId = logoutId\n        };\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            var idp = User.FindFirst(JwtClaimTypes.IdentityProvider)?.Value;\n            if (idp != null && idp != IdentityServer8.IdentityServerConstants.LocalIdentityProvider)\n            {\n                var providerSupportsSignout = await HttpContext.GetSchemeSupportsSignOutAsync(idp);\n                if (providerSupportsSignout)\n                {\n                    if (vm.LogoutId == null)\n                    {\n                        // if there's no current logout context, we need to create one\n                        // this captures necessary info from the current logged in user\n                        // before we signout and redirect away to the external IdP for signout\n                        vm.LogoutId = await _interaction.CreateLogoutContextAsync();\n                    }\n\n                    vm.ExternalAuthenticationScheme = idp;\n                }\n            }\n        }\n\n        return vm;\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Account/AccountOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI\n{\n    public class AccountOptions\n    {\n        public static bool AllowLocalLogin = true;\n        public static bool AllowRememberLogin = true;\n        public static TimeSpan RememberMeLoginDuration = TimeSpan.FromDays(30);\n\n        public static bool ShowLogoutPrompt = true;\n        public static bool AutomaticRedirectAfterSignOut = false;\n\n        public static string InvalidCredentialsErrorMessage = \"Invalid username or password\";\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Account/ExternalController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class ExternalController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly ILogger<ExternalController> _logger;\n    private readonly IEventService _events;\n\n    public ExternalController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IEventService events,\n        ILogger<ExternalController> logger,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _logger = logger;\n        _events = events;\n    }\n\n    /// <summary>\n    /// initiate roundtrip to external authentication provider\n    /// </summary>\n    [HttpGet]\n    public IActionResult Challenge(string scheme, string returnUrl)\n    {\n        if (string.IsNullOrEmpty(returnUrl)) returnUrl = \"~/\";\n\n        // validate returnUrl - either it is a valid OIDC URL or back to a local page\n        if (Url.IsLocalUrl(returnUrl) == false && _interaction.IsValidReturnUrl(returnUrl) == false)\n        {\n            // user might have clicked on a malicious link - should be logged\n            throw new Exception(\"invalid return URL\");\n        }\n        \n        // start challenge and roundtrip the return URL and scheme \n        var props = new AuthenticationProperties\n        {\n            RedirectUri = Url.Action(nameof(Callback)), \n            Items =\n            {\n                { \"returnUrl\", returnUrl }, \n                { \"scheme\", scheme },\n            }\n        };\n\n        return Challenge(props, scheme);\n        \n    }\n\n    /// <summary>\n    /// Post processing of external authentication\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Callback()\n    {\n        // read external identity from the temporary cookie\n        var result = await HttpContext.AuthenticateAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n        if (result?.Succeeded != true)\n        {\n            throw new Exception(\"External authentication error\");\n        }\n\n        if (_logger.IsEnabled(LogLevel.Debug))\n        {\n            var externalClaims = result.Principal.Claims.Select(c => $\"{c.Type}: {c.Value}\");\n            _logger.LogDebug(\"External claims: {@claims}\", externalClaims);\n        }\n\n        // lookup our user and external provider info\n        var (user, provider, providerUserId, claims) = FindUserFromExternalProvider(result);\n        if (user == null)\n        {\n            // this might be where you might initiate a custom workflow for user registration\n            // in this sample we don't show how that would be done, as our sample implementation\n            // simply auto-provisions new external user\n            user = AutoProvisionUser(provider, providerUserId, claims);\n        }\n\n        // this allows us to collect any additional claims or properties\n        // for the specific protocols used and store them in the local auth cookie.\n        // this is typically used to store data needed for signout from those protocols.\n        var additionalLocalClaims = new List<Claim>();\n        var localSignInProps = new AuthenticationProperties();\n        ProcessLoginCallback(result, additionalLocalClaims, localSignInProps);\n        \n        // issue authentication cookie for user\n        var isuser = new IdentityServerUser(user.SubjectId)\n        {\n            DisplayName = user.Username,\n            IdentityProvider = provider,\n            AdditionalClaims = additionalLocalClaims\n        };\n\n        await HttpContext.SignInAsync(isuser, localSignInProps);\n\n        // delete temporary cookie used during external authentication\n        await HttpContext.SignOutAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n        // retrieve return URL\n        var returnUrl = result.Properties.Items[\"returnUrl\"] ?? \"~/\";\n\n        // check if external login is in the context of an OIDC request\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        await _events.RaiseAsync(new UserLoginSuccessEvent(provider, providerUserId, user.SubjectId, user.Username, true, context?.Client.ClientId));\n\n        if (context != null)\n        {\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", returnUrl);\n            }\n        }\n\n        return Redirect(returnUrl);\n    }\n\n    private (TestUser user, string provider, string providerUserId, IEnumerable<Claim> claims) FindUserFromExternalProvider(AuthenticateResult result)\n    {\n        var externalUser = result.Principal;\n\n        // try to determine the unique id of the external user (issued by the provider)\n        // the most common claim type for that are the sub claim and the NameIdentifier\n        // depending on the external provider, some other claim type might be used\n        var userIdClaim = externalUser.FindFirst(JwtClaimTypes.Subject) ??\n                          externalUser.FindFirst(ClaimTypes.NameIdentifier) ??\n                          throw new Exception(\"Unknown userid\");\n\n        // remove the user id claim so we don't include it as an extra claim if/when we provision the user\n        var claims = externalUser.Claims.ToList();\n        claims.Remove(userIdClaim);\n\n        var provider = result.Properties.Items[\"scheme\"];\n        var providerUserId = userIdClaim.Value;\n\n        // find external user\n        var user = _users.FindByExternalProvider(provider, providerUserId);\n\n        return (user, provider, providerUserId, claims);\n    }\n\n    private TestUser AutoProvisionUser(string provider, string providerUserId, IEnumerable<Claim> claims)\n    {\n        var user = _users.AutoProvisionUser(provider, providerUserId, claims.ToList());\n        return user;\n    }\n\n    // if the external login is OIDC-based, there are certain things we need to preserve to make logout work\n    // this will be different for WS-Fed, SAML2p or other protocols\n    private void ProcessLoginCallback(AuthenticateResult externalResult, List<Claim> localClaims, AuthenticationProperties localSignInProps)\n    {\n        // if the external system sent a session id claim, copy it over\n        // so we can use it for single sign-out\n        var sid = externalResult.Principal.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.SessionId);\n        if (sid != null)\n        {\n            localClaims.Add(new Claim(JwtClaimTypes.SessionId, sid.Value));\n        }\n\n        // if the external provider issued an id_token, we'll keep it for signout\n        var idToken = externalResult.Properties.GetTokenValue(\"id_token\");\n        if (idToken != null)\n        {\n            localSignInProps.StoreTokens(new[] { new AuthenticationToken { Name = \"id_token\", Value = idToken } });\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Account/ExternalProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ExternalProvider\n{\n    public string DisplayName { get; set; }\n    public string AuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Account/LoggedOutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoggedOutViewModel\n{\n    public string PostLogoutRedirectUri { get; set; }\n    public string ClientName { get; set; }\n    public string SignOutIframeUrl { get; set; }\n\n    public bool AutomaticRedirectAfterSignOut { get; set; }\n\n    public string LogoutId { get; set; }\n    public bool TriggerExternalSignout => ExternalAuthenticationScheme != null;\n    public string ExternalAuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Account/LoginInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginInputModel\n{\n    [Required]\n    public string Username { get; set; }\n    [Required]\n    public string Password { get; set; }\n    public bool RememberLogin { get; set; }\n    public string ReturnUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Account/LoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginViewModel : LoginInputModel\n{\n    public bool AllowRememberLogin { get; set; } = true;\n    public bool EnableLocalLogin { get; set; } = true;\n\n    public IEnumerable<ExternalProvider> ExternalProviders { get; set; } = Enumerable.Empty<ExternalProvider>();\n    public IEnumerable<ExternalProvider> VisibleExternalProviders => ExternalProviders.Where(x => !String.IsNullOrWhiteSpace(x.DisplayName));\n\n    public bool IsExternalLoginOnly => EnableLocalLogin == false && ExternalProviders?.Count() == 1;\n    public string ExternalLoginScheme => IsExternalLoginOnly ? ExternalProviders?.SingleOrDefault()?.AuthenticationScheme : null;\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Account/LogoutInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutInputModel\n{\n    public string LogoutId { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Account/LogoutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutViewModel : LogoutInputModel\n{\n    public bool ShowLogoutPrompt { get; set; } = true;\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Account/RedirectViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class RedirectViewModel\n{\n    public string RedirectUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Consent/ConsentController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This controller processes the consent UI\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class ConsentController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly ILogger<ConsentController> _logger;\n\n    public ConsentController(\n        IIdentityServerInteractionService interaction,\n        IEventService events,\n        ILogger<ConsentController> logger)\n    {\n        _interaction = interaction;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Shows the consent screen\n    /// </summary>\n    /// <param name=\"returnUrl\"></param>\n    /// <returns></returns>\n    [HttpGet]\n    public async Task<IActionResult> Index(string returnUrl)\n    {\n        var vm = await BuildViewModelAsync(returnUrl);\n        if (vm != null)\n        {\n            return View(\"Index\", vm);\n        }\n\n        return View(\"Error\");\n    }\n\n    /// <summary>\n    /// Handles the consent screen postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Index(ConsentInputModel model)\n    {\n        var result = await ProcessConsent(model);\n\n        if (result.IsRedirect)\n        {\n            var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n            if (context?.IsNativeClient() == true)\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", result.RedirectUri);\n            }\n            return result.RedirectUri.IsAllowedRedirect() ? Redirect(result.RedirectUri.SanitizeForRedirect()) : Forbid();\n        }\n\n        if (result.HasValidationError)\n        {\n            ModelState.AddModelError(string.Empty, result.ValidationError);\n        }\n\n        if (result.ShowView)\n        {\n            return View(\"Index\", result.ViewModel);\n        }\n\n        return View(\"Error\");\n    }\n\n    /*****************************************/\n    /* helper APIs for the ConsentController */\n    /*****************************************/\n    private async Task<ProcessConsentResult> ProcessConsent(ConsentInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        // validate return url is still valid\n        var request = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model?.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model?.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.GrantConsentAsync(request, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.ReturnUrl, model);\n        }\n\n        return result;\n    }\n\n    private async Task<ConsentViewModel> BuildViewModelAsync(string returnUrl, ConsentInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (request != null)\n        {\n            return CreateConsentViewModel(model, returnUrl, request);\n        }\n        else\n        {\n            _logger.LogError(\"No consent request matching request: {0}\", returnUrl.SanitizeForLog());\n        }\n\n        return null;\n    }\n\n    private ConsentViewModel CreateConsentViewModel(\n        ConsentInputModel model, string returnUrl,\n        AuthorizationRequest request)\n    {\n        var vm = new ConsentViewModel\n        {\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n            Description = model?.Description,\n\n            ReturnUrl = returnUrl,\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach(var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        var displayName = apiScope.DisplayName ?? apiScope.Name;\n        if (!String.IsNullOrWhiteSpace(parsedScopeValue.ParsedParameter))\n        {\n            displayName += \":\" + parsedScopeValue.ParsedParameter;\n        }\n\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            DisplayName = displayName,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Consent/ConsentInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentInputModel\n{\n    public string Button { get; set; }\n    public IEnumerable<string> ScopesConsented { get; set; }\n    public bool RememberConsent { get; set; }\n    public string ReturnUrl { get; set; }\n    public string Description { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Consent/ConsentOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentOptions\n{\n    public static bool EnableOfflineAccess = true;\n    public static string OfflineAccessDisplayName = \"Offline Access\";\n    public static string OfflineAccessDescription = \"Access to your applications and resources, even when you are offline\";\n\n    public static readonly string MustChooseOneErrorMessage = \"You must pick at least one permission\";\n    public static readonly string InvalidSelectionErrorMessage = \"Invalid selection\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Consent/ConsentViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentViewModel : ConsentInputModel\n{\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public bool AllowRememberConsent { get; set; }\n\n    public IEnumerable<ScopeViewModel> IdentityScopes { get; set; }\n    public IEnumerable<ScopeViewModel> ApiScopes { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Consent/ProcessConsentResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ProcessConsentResult\n{\n    public bool IsRedirect => RedirectUri != null;\n    public string RedirectUri { get; set; }\n    public Client Client { get; set; }\n\n    public bool ShowView => ViewModel != null;\n    public ConsentViewModel ViewModel { get; set; }\n\n    public bool HasValidationError => ValidationError != null;\n    public string ValidationError { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Consent/ScopeViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ScopeViewModel\n{\n    public string Value { get; set; }\n    public string DisplayName { get; set; }\n    public string Description { get; set; }\n    public bool Emphasize { get; set; }\n    public bool Required { get; set; }\n    public bool Checked { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Device/DeviceAuthorizationInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationInputModel : ConsentInputModel\n{\n    public string UserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Device/DeviceAuthorizationViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationViewModel : ConsentViewModel\n{\n    public string UserCode { get; set; }\n    public bool ConfirmUserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Device/DeviceController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[Authorize]\n[SecurityHeaders]\npublic class DeviceController : Controller\n{\n    private readonly IDeviceFlowInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly IOptions<IdentityServerOptions> _options;\n    private readonly ILogger<DeviceController> _logger;\n\n    public DeviceController(\n        IDeviceFlowInteractionService interaction,\n        IEventService eventService,\n        IOptions<IdentityServerOptions> options,\n        ILogger<DeviceController> logger)\n    {\n        _interaction = interaction;\n        _events = eventService;\n        _options = options;\n        _logger = logger;\n    }\n\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        string userCodeParamName = _options.Value.UserInteraction.DeviceVerificationUserCodeParameter;\n        string userCode = Request.Query[userCodeParamName];\n        if (string.IsNullOrWhiteSpace(userCode)) return View(\"UserCodeCapture\");\n\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        vm.ConfirmUserCode = true;\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> UserCodeCapture(string userCode)\n    {\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Callback(DeviceAuthorizationInputModel model)\n    {\n        if (model == null) throw new ArgumentNullException(nameof(model));\n\n        var result = await ProcessConsent(model);\n        if (result.HasValidationError) return View(\"Error\");\n\n        return View(\"Success\");\n    }\n\n    private async Task<ProcessConsentResult> ProcessConsent(DeviceAuthorizationInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        var request = await _interaction.GetAuthorizationContextAsync(model.UserCode);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.HandleRequestAsync(model.UserCode, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.UserCode, model);\n        }\n\n        return result;\n    }\n\n    private async Task<DeviceAuthorizationViewModel> BuildViewModelAsync(string userCode, DeviceAuthorizationInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(userCode);\n        if (request != null)\n        {\n            return CreateConsentViewModel(userCode, model, request);\n        }\n\n        return null;\n    }\n\n    private DeviceAuthorizationViewModel CreateConsentViewModel(string userCode, DeviceAuthorizationInputModel model, DeviceFlowAuthorizationRequest request)\n    {\n        var vm = new DeviceAuthorizationViewModel\n        {\n            UserCode = userCode,\n            Description = model?.Description,\n\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach (var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            // todo: use the parsed scope value in the display?\n            DisplayName = apiScope.DisplayName ?? apiScope.Name,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Diagnostics/DiagnosticsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[Authorize]\npublic class DiagnosticsController : Controller\n{\n    public async Task<IActionResult> Index()\n    {\n        var localAddresses = new string[] { \"127.0.0.1\", \"::1\", HttpContext.Connection.LocalIpAddress.ToString() };\n        if (!localAddresses.Contains(HttpContext.Connection.RemoteIpAddress.ToString()))\n        {\n            return NotFound();\n        }\n\n        var model = new DiagnosticsViewModel(await HttpContext.AuthenticateAsync());\n        return View(model);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Diagnostics/DiagnosticsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DiagnosticsViewModel\n{\n    public DiagnosticsViewModel(AuthenticateResult result)\n    {\n        AuthenticateResult = result;\n\n        if (result.Properties.Items.ContainsKey(\"client_list\"))\n        {\n            var encoded = result.Properties.Items[\"client_list\"];\n            var bytes = Base64Url.Decode(encoded);\n            var value = Encoding.UTF8.GetString(bytes);\n\n            Clients = JsonSerializer.Deserialize<string[]>(value);\n        }\n    }\n\n    public AuthenticateResult AuthenticateResult { get; }\n    public IEnumerable<string> Clients { get; } = new List<string>();\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Extensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic static class Extensions\n{\n    /// <summary>\n    /// Checks if the redirect URI is for a native client.\n    /// </summary>\n    /// <returns></returns>\n    public static bool IsNativeClient(this AuthorizationRequest context)\n    {\n        return !context.RedirectUri.StartsWith(\"https\", StringComparison.Ordinal)\n           && !context.RedirectUri.StartsWith(\"http\", StringComparison.Ordinal);\n    }\n\n    public static IActionResult LoadingPage(this Controller controller, string viewName, string redirectUri)\n    {\n        controller.HttpContext.Response.StatusCode = 200;\n        controller.HttpContext.Response.Headers[\"Location\"] = \"\";\n        \n        return controller.View(viewName, new RedirectViewModel { RedirectUrl = redirectUri });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Grants/GrantsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller allows a user to revoke grants given to clients\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class GrantsController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clients;\n    private readonly IResourceStore _resources;\n    private readonly IEventService _events;\n\n    public GrantsController(IIdentityServerInteractionService interaction,\n        IClientStore clients,\n        IResourceStore resources,\n        IEventService events)\n    {\n        _interaction = interaction;\n        _clients = clients;\n        _resources = resources;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Show list of grants\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        return View(\"Index\", await BuildViewModelAsync());\n    }\n\n    /// <summary>\n    /// Handle postback to revoke a client\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Revoke(string clientId)\n    {\n        await _interaction.RevokeUserConsentAsync(clientId);\n        await _events.RaiseAsync(new GrantsRevokedEvent(User.GetSubjectId(), clientId));\n\n        return RedirectToAction(\"Index\");\n    }\n\n    private async Task<GrantsViewModel> BuildViewModelAsync()\n    {\n        var grants = await _interaction.GetAllUserGrantsAsync();\n\n        var list = new List<GrantViewModel>();\n        foreach(var grant in grants)\n        {\n            var client = await _clients.FindClientByIdAsync(grant.ClientId);\n            if (client != null)\n            {\n                var resources = await _resources.FindResourcesByScopeAsync(grant.Scopes);\n\n                var item = new GrantViewModel()\n                {\n                    ClientId = client.ClientId,\n                    ClientName = client.ClientName ?? client.ClientId,\n                    ClientLogoUrl = client.LogoUri,\n                    ClientUrl = client.ClientUri,\n                    Description = grant.Description,\n                    Created = grant.CreationTime,\n                    Expires = grant.Expiration,\n                    IdentityGrantNames = resources.IdentityResources.Select(x => x.DisplayName ?? x.Name).ToArray(),\n                    ApiGrantNames = resources.ApiScopes.Select(x => x.DisplayName ?? x.Name).ToArray()\n                };\n\n                list.Add(item);\n            }\n        }\n\n        return new GrantsViewModel\n        {\n            Grants = list\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Grants/GrantsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class GrantsViewModel\n{\n    public IEnumerable<GrantViewModel> Grants { get; set; }\n}\n\npublic class GrantViewModel\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public string Description { get; set; }\n    public DateTime Created { get; set; }\n    public DateTime? Expires { get; set; }\n    public IEnumerable<string> IdentityGrantNames { get; set; }\n    public IEnumerable<string> ApiGrantNames { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Home/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ErrorViewModel\n{\n    public ErrorViewModel()\n    {\n    }\n\n    public ErrorViewModel(string error)\n    {\n        Error = new ErrorMessage { Error = error };\n    }\n\n    public ErrorMessage Error { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/Home/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class HomeController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IWebHostEnvironment _environment;\n    private readonly ILogger _logger;\n\n    public HomeController(IIdentityServerInteractionService interaction, IWebHostEnvironment environment, ILogger<HomeController> logger)\n    {\n        _interaction = interaction;\n        _environment = environment;\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        if (_environment.IsDevelopment())\n        {\n            // only show in development\n            return View();\n        }\n\n        _logger.LogInformation(\"Homepage is disabled in production. Returning 404.\");\n        return NotFound();\n    }\n\n    /// <summary>\n    /// Shows the error page\n    /// </summary>\n    public async Task<IActionResult> Error(string errorId)\n    {\n        var vm = new ErrorViewModel();\n\n        // retrieve error details from identityserver\n        var message = await _interaction.GetErrorContextAsync(errorId);\n        if (message != null)\n        {\n            vm.Error = message;\n\n            if (!_environment.IsDevelopment())\n            {\n                // only show in development\n                message.ErrorDescription = null;\n            }\n        }\n\n        return View(\"Error\", vm);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/SecurityHeadersAttribute.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class SecurityHeadersAttribute : ActionFilterAttribute\n{\n    public override void OnResultExecuting(ResultExecutingContext context)\n    {\n        var result = context.Result;\n        if (result is ViewResult)\n        {\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Type-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Type-Options\", \"nosniff\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Frame-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Frame-Options\", \"SAMEORIGIN\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy\n            var csp = \"default-src 'self'; object-src 'none'; frame-ancestors 'none'; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self';\";\n            // also consider adding upgrade-insecure-requests once you have HTTPS in place for production\n            //csp += \"upgrade-insecure-requests;\";\n            // also an example if you need client images to be displayed from twitter\n            // csp += \"img-src 'self' https://pbs.twimg.com;\";\n\n            // once for standards compliant browsers\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Content-Security-Policy\", csp);\n            }\n            // and once again for IE\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Security-Policy\", csp);\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy\n            var referrer_policy = \"no-referrer\";\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Referrer-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Referrer-Policy\", referrer_policy);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Quickstart/TestUsers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class TestUsers\n{\n\n    static readonly object UserAddress = new\n    {\n        street_address = \"One Hacker Way\",\n        locality = \"Heidelberg\",\n        postal_code = 69118,\n        country = \"Germany\"\n    };\n\n    public static List<TestUser> Users => new List<TestUser>\n    {\n        new()\n        {\n            SubjectId = \"818727\",\n            Username = \"alice\",\n            Password = \"alice\",\n            Claims =\n            {\n                new (Name, \"Alice Smith\"),\n                new (GivenName, \"Alice\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"AliceSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://alice.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        },\n        new()\n        {\n            SubjectId = \"88421113\",\n            Username = \"bob\",\n            Password = \"bob\",\n            Claims =\n            {\n                new (Name, \"Bob Smith\"),\n                new (GivenName, \"Bob\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"BobSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://bob.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        }\n    };\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/SeedData.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerAspNetIdentity\n{\n    public class SeedData\n    {\n        public static void EnsureSeedData(string connectionString)\n        {\n            var services = new ServiceCollection();\n            services.AddLogging();\n            services.AddDbContext<ApplicationDbContext>(options =>\n               options.UseSqlite(connectionString));\n\n            services.AddIdentity<ApplicationUser, IdentityRole>()\n                .AddEntityFrameworkStores<ApplicationDbContext>()\n                .AddDefaultTokenProviders();\n\n            using (var serviceProvider = services.BuildServiceProvider())\n            {\n                using (var scope = serviceProvider.GetRequiredService<IServiceScopeFactory>().CreateScope())\n                {\n                    var context = scope.ServiceProvider.GetService<ApplicationDbContext>();\n                    context.Database.Migrate();\n\n                    var userMgr = scope.ServiceProvider.GetRequiredService<UserManager<ApplicationUser>>();\n                    var alice = userMgr.FindByNameAsync(\"alice\").Result;\n                    if (alice == null)\n                    {\n                        alice = new ApplicationUser\n                        {\n                            UserName = \"alice\",\n                            Email = \"AliceSmith@email.com\",\n                            EmailConfirmed = true,\n                        };\n                        var result = userMgr.CreateAsync(alice, \"Pass123$\").Result;\n                        if (!result.Succeeded)\n                        {\n                            throw new Exception(result.Errors.First().Description);\n                        }\n\n                        result = userMgr.AddClaimsAsync(alice, new Claim[]{\n                            new Claim(JwtClaimTypes.Name, \"Alice Smith\"),\n                            new Claim(JwtClaimTypes.GivenName, \"Alice\"),\n                            new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                            new Claim(JwtClaimTypes.WebSite, \"http://alice.com\"),\n                        }).Result;\n                        if (!result.Succeeded)\n                        {\n                            throw new Exception(result.Errors.First().Description);\n                        }\n                        Log.Debug(\"alice created\");\n                    }\n                    else\n                    {\n                        Log.Debug(\"alice already exists\");\n                    }\n\n                    var bob = userMgr.FindByNameAsync(\"bob\").Result;\n                    if (bob == null)\n                    {\n                        bob = new ApplicationUser\n                        {\n                            UserName = \"bob\",\n                            Email = \"BobSmith@email.com\",\n                            EmailConfirmed = true\n                        };\n                        var result = userMgr.CreateAsync(bob, \"Pass123$\").Result;\n                        if (!result.Succeeded)\n                        {\n                            throw new Exception(result.Errors.First().Description);\n                        }\n\n                        result = userMgr.AddClaimsAsync(bob, new Claim[]{\n                            new Claim(JwtClaimTypes.Name, \"Bob Smith\"),\n                            new Claim(JwtClaimTypes.GivenName, \"Bob\"),\n                            new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                            new Claim(JwtClaimTypes.WebSite, \"http://bob.com\"),\n                            new Claim(\"location\", \"somewhere\")\n                        }).Result;\n                        if (!result.Succeeded)\n                        {\n                            throw new Exception(result.Errors.First().Description);\n                        }\n                        Log.Debug(\"bob created\");\n                    }\n                    else\n                    {\n                        Log.Debug(\"bob already exists\");\n                    }\n                }\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Account/AccessDenied.cshtml",
    "content": "﻿\n<div class=\"container\">\n    <div class=\"lead\">\n        <h1>Access Denied</h1>\n        <p>You do not have access to that resource.</p>\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Account/LoggedOut.cshtml",
    "content": "﻿@model LoggedOutViewModel\n\n@{ \n    // set this so the layout rendering sees an anonymous user\n    ViewData[\"signed-out\"] = true;\n}\n\n<div class=\"logged-out-page\">\n    <h1>\n        Logout\n        <small>You are now logged out</small>\n    </h1>\n\n    @if (Model.PostLogoutRedirectUri != null)\n    {\n        <div>\n            Click <a class=\"PostLogoutRedirectUri\" href=\"@Model.PostLogoutRedirectUri\">here</a> to return to the\n            <span>@Model.ClientName</span> application.\n        </div>\n    }\n\n    @if (Model.SignOutIframeUrl != null)\n    {\n        <iframe width=\"0\" height=\"0\" class=\"signout\" src=\"@Model.SignOutIframeUrl\"></iframe>\n    }\n</div>\n\n@section scripts\n{\n    @if (Model.AutomaticRedirectAfterSignOut)\n    {\n        <script src=\"~/js/signout-redirect.js\"></script>\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Account/Login.cshtml",
    "content": "@model LoginViewModel\n\n<div class=\"login-page\">\n    <div class=\"lead\">\n        <h1>Login</h1>\n        <p>Choose how to login</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n\n        @if (Model.EnableLocalLogin)\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>Local Account</h2>\n                    </div>\n\n                    <div class=\"card-body\">\n                        <form asp-route=\"Login\">\n                            <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n\n                            <div class=\"form-group\">\n                                <label asp-for=\"Username\"></label>\n                                <input class=\"form-control\" placeholder=\"Username\" asp-for=\"Username\" autofocus>\n                            </div>\n                            <div class=\"form-group\">\n                                <label asp-for=\"Password\"></label>\n                                <input type=\"password\" class=\"form-control\" placeholder=\"Password\" asp-for=\"Password\" autocomplete=\"off\">\n                            </div>\n                            @if (Model.AllowRememberLogin)\n                            {\n                                <div class=\"form-group\">\n                                    <div class=\"form-check\">\n                                        <input class=\"form-check-input\" asp-for=\"RememberLogin\">\n                                        <label class=\"form-check-label\" asp-for=\"RememberLogin\">\n                                            Remember My Login\n                                        </label>\n                                    </div>\n                                </div>\n                            }\n                            <button class=\"btn btn-primary\" name=\"button\" value=\"login\">Login</button>\n                            <button class=\"btn btn-secondary\" name=\"button\" value=\"cancel\" formaction=\"/Account/LoginCancel\">Cancel</button>\n                        </form>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>External Account</h2>\n                    </div>\n                    <div class=\"card-body\">\n                        <ul class=\"list-inline\">\n                            @foreach (var provider in Model.VisibleExternalProviders)\n                            {\n                                <li class=\"list-inline-item\">\n                                    <a class=\"btn btn-secondary\"\n                                       asp-controller=\"External\"\n                                       asp-action=\"Challenge\"\n                                       asp-route-scheme=\"@provider.AuthenticationScheme\"\n                                       asp-route-returnUrl=\"@Model.ReturnUrl\">\n                                        @provider.DisplayName\n                                    </a>\n                                </li>\n                            }\n                        </ul>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (!Model.EnableLocalLogin && !Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"alert alert-warning\">\n                <strong>Invalid login request</strong>\n                There are no login schemes configured for this request.\n            </div>\n        }\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Account/Logout.cshtml",
    "content": "﻿@model LogoutViewModel\n\n<div class=\"logout-page\">\n    <div class=\"lead\">\n        <h1>Logout</h1>\n        <p>Would you like to logout of IdentityServer?</p>\n    </div>\n\n    <form asp-action=\"Logout\">\n        <input type=\"hidden\" name=\"logoutId\" value=\"@Model.LogoutId\"  />\n        <div class=\"form-group\">\n            <button class=\"btn btn-primary\">Yes</button>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Consent/Index.cshtml",
    "content": "@model ConsentViewModel\n\n<div class=\"page-consent\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Index\">\n        <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Device/Success.cshtml",
    "content": "\n<div class=\"page-device-success\">\n    <div class=\"lead\">\n        <h1>Success</h1>\n        <p>You have successfully authorized the device</p>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Device/UserCodeCapture.cshtml",
    "content": "@model string\n\n<div class=\"page-device-code\">\n    <div class=\"lead\">\n        <h1>User Code</h1>\n        <p>Please enter the code displayed on your device.</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <form asp-action=\"UserCodeCapture\">\n                <div class=\"form-group\">\n                    <label for=\"userCode\">User Code:</label>\n                    <input class=\"form-control\" for=\"userCode\" name=\"userCode\" autofocus />\n                </div>\n\n                <button class=\"btn btn-primary\" name=\"button\">Submit</button>\n            </form>\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Device/UserCodeConfirmation.cshtml",
    "content": "@model DeviceAuthorizationViewModel\n\n<div class=\"page-device-confirmation\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        @if (Model.ConfirmUserCode)\n        {\n            <p>Please confirm that the authorization request quotes the code: <strong>@Model.UserCode</strong>.</p>\n        }\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Callback\">\n        <input asp-for=\"UserCode\" type=\"hidden\" value=\"@Model.UserCode\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Diagnostics/Index.cshtml",
    "content": "@model DiagnosticsViewModel\n\n<div class=\"diagnostics-page\">\n    <div class=\"lead\">\n        <h1>Authentication Cookie</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Claims</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var claim in Model.AuthenticateResult.Principal.Claims)\n                        {\n                            <dt>@claim.Type</dt>\n                            <dd>@claim.Value</dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n        \n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Properties</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var prop in Model.AuthenticateResult.Properties.Items)\n                        {\n                            <dt>@prop.Key</dt>\n                            <dd>@prop.Value</dd>\n                        }\n                        @if (Model.Clients.Any())\n                        {\n                            <dt>Clients</dt>\n                            <dd>\n                            @{\n                                var clients = Model.Clients.ToArray();\n                                for(var i = 0; i < clients.Length; i++)\n                                {\n                                    <text>@clients[i]</text>\n                                    if (i < clients.Length - 1)\n                                    {\n                                        <text>, </text>\n                                    }\n                                }\n                            }\n                            </dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n    </div>\n</div>\n\n\n\n\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Grants/Index.cshtml",
    "content": "﻿@model GrantsViewModel\n\n<div class=\"grants-page\">\n    <div class=\"lead\">\n        <h1>Client Application Permissions</h1>\n        <p>Below is the list of applications you have given permission to and the resources they have access to.</p>\n    </div>\n\n    @if (Model.Grants.Any() == false)\n    {\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                <div class=\"alert alert-info\">\n                    You have not given access to any applications\n                </div>\n            </div>\n        </div>\n    }\n    else\n    {\n        foreach (var grant in Model.Grants)\n        {\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <div class=\"row\">\n                        <div class=\"col-sm-8 card-title\">\n                            @if (grant.ClientLogoUrl != null)\n                            {\n                                <img src=\"@grant.ClientLogoUrl\">\n                            }\n                            <strong>@grant.ClientName</strong>\n                        </div>\n\n                        <div class=\"col-sm-2\">\n                            <form asp-action=\"Revoke\">\n                                <input type=\"hidden\" name=\"clientId\" value=\"@grant.ClientId\">\n                                <button class=\"btn btn-danger\">Revoke Access</button>\n                            </form>\n                        </div>\n                    </div>\n                </div>\n                \n                <ul class=\"list-group list-group-flush\">\n                    @if (grant.Description != null)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Description:</label> @grant.Description\n                        </li>   \n                    }\n                    <li class=\"list-group-item\">\n                        <label>Created:</label> @grant.Created.ToString(\"yyyy-MM-dd\")\n                    </li>\n                    @if (grant.Expires.HasValue)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Expires:</label> @grant.Expires.Value.ToString(\"yyyy-MM-dd\")\n                        </li>\n                    }\n                    @if (grant.IdentityGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Identity Grants</label>\n                            <ul>\n                                @foreach (var name in grant.IdentityGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                    @if (grant.ApiGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>API Grants</label>\n                            <ul>\n                                @foreach (var name in grant.ApiGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                </ul>\n            </div>\n        }\n    }\n</div>"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Home/Index.cshtml",
    "content": "@using System.Diagnostics\n\n@{\n    var version = FileVersionInfo.GetVersionInfo(typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.Location).ProductVersion.Split('+').First();\n}\n\n<div class=\"welcome-page\">\n    <h1>\n        <img src=\"~/icon.jpg\">\n        Welcome to IdentityServer8\n        <small class=\"text-muted\">(version @version)</small>\n    </h1>\n\n    <ul>\n        <li>\n            IdentityServer publishes a\n            <a href=\"~/.well-known/openid-configuration\">discovery document</a>\n            where you can find metadata and links to all the endpoints, key material, etc.\n        </li>\n        <li>\n            Click <a href=\"~/diagnostics\">here</a> to see the claims for your current session.\n        </li>\n        <li>\n            Click <a href=\"~/grants\">here</a> to manage your stored grants.\n        </li>\n        <li>\n            Here are links to the\n            <a href=\"https://github.com/alexhiggins732/IdentityServer8\">source code repository</a>,\n            and <a href=\"https://github.com/alexhiggins732/IdentityServer8/tree/main/samples\">ready to use samples</a>.\n        </li>\n    </ul>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Shared/Error.cshtml",
    "content": "@model ErrorViewModel\n\n@{\n    var error = Model?.Error?.Error;\n    var errorDescription = Model?.Error?.ErrorDescription;\n    var request_id = Model?.Error?.RequestId;\n}\n\n<div class=\"error-page\">\n    <div class=\"lead\">\n        <h1>Error</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <div class=\"alert alert-danger\">\n                Sorry, there was an error\n\n                @if (error != null)\n                {\n                    <strong>\n                        <em>\n                            : @error\n                        </em>\n                    </strong>\n\n                    if (errorDescription != null)\n                    {\n                        <div>@errorDescription</div>\n                    }\n                }\n            </div>\n\n            @if (request_id != null)\n            {\n                <div class=\"request-id\">Request Id: @request_id</div>\n            }\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Shared/Redirect.cshtml",
    "content": "@model RedirectViewModel\n@using Microsoft.Extensions.DependencyInjection;\n<div class=\"redirect-page\">\n    <div class=\"lead\">\n        <h1>You are now being returned to the application</h1>\n        <p>Once complete, you may close this tab.</p>\n    </div>\n</div>\n\n<meta http-equiv=\"refresh\" content=\"0;url=@Model.RedirectUrl\" data-url=\"@Model.RedirectUrl\">\n<script>\n    var url = '@Ioc.Sanitizer.Url.Sanitize(Model.RedirectUrl)';\n    window.location.href = url;\n</script>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0, shrink-to-fit=no\" />\n\n    <title>IdentityServer8</title>\n    \n    <link rel=\"icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    <link rel=\"shortcut icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    \n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <partial name=\"_Nav\" />\n   \n    <div class=\"container body-container\">\n        @RenderBody()\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.slim.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Shared/_Nav.cshtml",
    "content": "@using IdentityServer8.Extensions\n\n@{\n    string name = null;\n    if (!true.Equals(ViewData[\"signed-out\"]))\n    {\n        name = Context.User?.GetDisplayName();\n    }\n}\n\n<div class=\"nav-page\">\n    <nav class=\"navbar navbar-expand-lg navbar-dark bg-dark\">\n\n        <a href=\"~/\" class=\"navbar-brand\">\n            <img src=\"~/icon.png\" class=\"icon-banner\">\n            IdentityServer8\n        </a>\n\n        @if (!string.IsNullOrWhiteSpace(name))\n        {\n            <ul class=\"navbar-nav mr-auto\">\n                <li class=\"nav-item dropdown\">\n                    <a href=\"#\" class=\"nav-link dropdown-toggle\" data-toggle=\"dropdown\">@name <b class=\"caret\"></b></a>\n                    \n                    <div class=\"dropdown-menu\">\n                        <a class=\"dropdown-item\" asp-action=\"Logout\" asp-controller=\"Account\">Logout</a>\n                    </div>\n              </li>\n            </ul>\n        }\n    \n    </nav>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Shared/_ScopeListItem.cshtml",
    "content": "﻿@model ScopeViewModel\n\n<li class=\"list-group-item\">\n    <label>\n        <input class=\"consent-scopecheck\"\n               type=\"checkbox\"\n               name=\"ScopesConsented\"\n               id=\"scopes_@Model.Value\"\n               value=\"@Model.Value\"\n               checked=\"@Model.Checked\"\n               disabled=\"@Model.Required\" />\n        @if (Model.Required)\n        {\n            <input type=\"hidden\"\n                   name=\"ScopesConsented\"\n                   value=\"@Model.Value\" />\n        }\n        <strong>@Model.DisplayName</strong>\n        @if (Model.Emphasize)\n        {\n            <span class=\"glyphicon glyphicon-exclamation-sign\"></span>\n        }\n    </label>\n    @if (Model.Required)\n    {\n        <span><em>(required)</em></span>\n    }\n    @if (Model.Description != null)\n    {\n        <div class=\"consent-description\">\n            <label for=\"scopes_@Model.Value\">@Model.Description</label>\n        </div>\n    }\n</li>"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/Shared/_ValidationSummary.cshtml",
    "content": "﻿@if (ViewContext.ModelState.IsValid == false)\n{\n    <div class=\"alert alert-danger\">\n        <strong>Error</strong>\n        <div asp-validation-summary=\"All\" class=\"danger\"></div>\n    </div>\n}"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/_ViewImports.cshtml",
    "content": "﻿@using IdentityServerHost.Quickstart.UI\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/appsettings.json",
    "content": "﻿{\n  \"ConnectionStrings\": {\n    \"DefaultConnection\": \"Data Source=AspIdUsers.db;\"\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/updateUI.ps1",
    "content": "iex ((New-Object System.Net.WebClient).DownloadString('https://raw.githubusercontent.com/IdentityServer/IdentityServer8.Quickstart.UI.AspNetIdentity/main/getmain.ps1'))\t\n# SIG # Begin signature block\n# MIIfnQYJKoZIhvcNAQcCoIIfjjCCH4oCAQExDzANBglghkgBZQMEAgEFADB5Bgor\n# BgEEAYI3AgEEoGswaTA0BgorBgEEAYI3AgEeMCYCAwEAAAQQH8w7YFlLCE63JNLG\n# KX7zUQIBAAIBAAIBAAIBAAIBADAxMA0GCWCGSAFlAwQCAQUABCAmjChzA8Tk4hB4\n# nAolI/h9hR7E40n+o1koeC4dCBgwCqCCDgcwggPFMIICraADAgECAhACrFwmagtA\n# m48LefKuRiV3MA0GCSqGSIb3DQEBBQUAMGwxCzAJBgNVBAYTAlVTMRUwEwYDVQQK\n# EwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20xKzApBgNV\n# BAMTIkRpZ2lDZXJ0IEhpZ2ggQXNzdXJhbmNlIEVWIFJvb3QgQ0EwHhcNMDYxMTEw\n# MDAwMDAwWhcNMzExMTEwMDAwMDAwWjBsMQswCQYDVQQGEwJVUzEVMBMGA1UEChMM\n# RGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSswKQYDVQQD\n# EyJEaWdpQ2VydCBIaWdoIEFzc3VyYW5jZSBFViBSb290IENBMIIBIjANBgkqhkiG\n# 9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxszlc+b71LvlLS0ypt/lgT/JzSVJtnEqw9WU\n# NGeiChywX2mmQLHEt7KP0JikqUFZOtPclNY823Q4pErMTSWC90qlUxI47vNJbXGR\n# fmO2q6Zfw6SE+E9iUb74xezbOJLjBuUIkQzEKEFV+8taiRV+ceg1v01yCT2+OjhQ\n# W3cxG42zxyRFmqesbQAUWgS3uhPrUQqYQUEiTmVhh4FBUKZ5XIneGUpX1S7mXRxT\n# LH6YzRoGFqRoc9A0BBNcoXHTWnxV215k4TeHMFYE5RG0KYAS8Xk5iKICEXwnZreI\n# t3jyygqoOKsKZMK/Zl2VhMGhJR6HXRpQCyASzEG7bgtROLhLywIDAQABo2MwYTAO\n# BgNVHQ8BAf8EBAMCAYYwDwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQUsT7DaQP4\n# v0cB1JgmGggC72NkK8MwHwYDVR0jBBgwFoAUsT7DaQP4v0cB1JgmGggC72NkK8Mw\n# DQYJKoZIhvcNAQEFBQADggEBABwaBpfc15yfPIhmBghXIdshR/gqZ6q/GDJ2QBBX\n# wYrzetkRZY41+p78RbWe2UwxS7iR6EMsjrN4ztvjU3lx1uUhlAHaVYeaJGT2imbM\n# 3pw3zag0sWmbI8ieeCIrcEPjVUcxYRnvWMWFL04w9qAxFiPI5+JlFjPLvxoboD34\n# yl6LMYtgCIktDAZcUrfE+QqY0RVfnxK+fDZjOL1EpH/kJisKxJdpDemM4sAQV7jI\n# dhKRVfJIadi8KgJbD0TUIDHb9LpwJl2QYJ68SxcJL7TLHkNoyQcnwdJc9+ohuWgS\n# nDycv578gFybY83sR6olJ2egN/MAgn1U16n46S4To3foH0owggSRMIIDeaADAgEC\n# AhAHsEGNpR4UjDMbvN63E4MjMA0GCSqGSIb3DQEBCwUAMGwxCzAJBgNVBAYTAlVT\n# MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j\n# b20xKzApBgNVBAMTIkRpZ2lDZXJ0IEhpZ2ggQXNzdXJhbmNlIEVWIFJvb3QgQ0Ew\n# HhcNMTgwNDI3MTI0MTU5WhcNMjgwNDI3MTI0MTU5WjBaMQswCQYDVQQGEwJVUzEY\n# MBYGA1UEChMPLk5FVCBGb3VuZGF0aW9uMTEwLwYDVQQDEyguTkVUIEZvdW5kYXRp\n# b24gUHJvamVjdHMgQ29kZSBTaWduaW5nIENBMIIBIjANBgkqhkiG9w0BAQEFAAOC\n# AQ8AMIIBCgKCAQEAwQqv4aI0CI20XeYqTTZmyoxsSQgcCBGQnXnufbuDLhAB6GoT\n# NB7HuEhNSS8ftV+6yq8GztBzYAJ0lALdBjWypMfL451/84AO5ZiZB3V7MB2uxgWo\n# cV1ekDduU9bm1Q48jmR4SVkLItC+oQO/FIA2SBudVZUvYKeCJS5Ri9ibV7La4oo7\n# BJChFiP8uR+v3OU33dgm5BBhWmth4oTyq22zCfP3NO6gBWEIPFR5S+KcefUTYmn2\n# o7IvhvxzJsMCrNH1bxhwOyMl+DQcdWiVPuJBKDOO/hAKIxBG4i6ryQYBaKdhDgaA\n# NSCik0UgZasz8Qgl8n0A73+dISPumD8L/4mdywIDAQABo4IBPzCCATswHQYDVR0O\n# BBYEFMtck66Im/5Db1ZQUgJtePys4bFaMB8GA1UdIwQYMBaAFLE+w2kD+L9HAdSY\n# JhoIAu9jZCvDMA4GA1UdDwEB/wQEAwIBhjATBgNVHSUEDDAKBggrBgEFBQcDAzAS\n# BgNVHRMBAf8ECDAGAQH/AgEAMDQGCCsGAQUFBwEBBCgwJjAkBggrBgEFBQcwAYYY\n# aHR0cDovL29jc3AuZGlnaWNlcnQuY29tMEsGA1UdHwREMEIwQKA+oDyGOmh0dHA6\n# Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9EaWdpQ2VydEhpZ2hBc3N1cmFuY2VFVlJvb3RD\n# QS5jcmwwPQYDVR0gBDYwNDAyBgRVHSAAMCowKAYIKwYBBQUHAgEWHGh0dHBzOi8v\n# d3d3LmRpZ2ljZXJ0LmNvbS9DUFMwDQYJKoZIhvcNAQELBQADggEBALNGxKTz6gq6\n# clMF01GjC3RmJ/ZAoK1V7rwkqOkY3JDl++v1F4KrFWEzS8MbZsI/p4W31Eketazo\n# Nxy23RT0zDsvJrwEC3R+/MRdkB7aTecsYmMeMHgtUrl3xEO3FubnQ0kKEU/HBCTd\n# hR14GsQEccQQE6grFVlglrew+FzehWUu3SUQEp9t+iWpX/KfviDWx0H1azilMX15\n# lzJUxK7kCzmflrk5jCOCjKqhOdGJoQqstmwP+07qXO18bcCzEC908P+TYkh0z9gV\n# rlj7tyW9K9zPVPJZsLRaBp/QjMcH65o9Y1hD1uWtFQYmbEYkT1K9tuXHtQYx1Rpf\n# /dC8Nbl4iukwggWlMIIEjaADAgECAhAL5Ofkz0TFYBmonpg7pehYMA0GCSqGSIb3\n# DQEBCwUAMFoxCzAJBgNVBAYTAlVTMRgwFgYDVQQKEw8uTkVUIEZvdW5kYXRpb24x\n# MTAvBgNVBAMTKC5ORVQgRm91bmRhdGlvbiBQcm9qZWN0cyBDb2RlIFNpZ25pbmcg\n# Q0EwHhcNMTgwNjExMDAwMDAwWhcNMjEwNjE1MTIwMDAwWjCBoDEUMBIGA1UEBRML\n# NjAzIDM4OSAwNjgxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpXYXNoaW5ndG9uMRAw\n# DgYDVQQHEwdSZWRtb25kMSkwJwYDVQQKEyBJZGVudGl0eVNlcnZlciAoLk5FVCBG\n# b3VuZGF0aW9uKTEpMCcGA1UEAxMgSWRlbnRpdHlTZXJ2ZXIgKC5ORVQgRm91bmRh\n# dGlvbikwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCwEhFpSIYi3hrr\n# v/X9BtZkzufk7puhmTCVmQAPNm2R1eZZyMPhfxm5Sh/w/42CzlCG9LFgooha69z3\n# uoMMOKJEEQKZ6ByIV+r81o4lrHtSFbe4VlXavjQVFaVVjPSG6vWGykfHVCAeVpjx\n# fVk/HH6tEX506lBiHgOrQGogoQrwdVnObc3c6RiVSIuvFeCoHvk2GgiqyzFER7iO\n# R1055npVSAAAdxBvPA6KREcLb/qHukYCJZX4mY/SajBXwxupSnhRDbYhb+qHpFIL\n# x7s/azxg7tVRpVh49oJimHA2uZ/jzh/KgUsUe9MFzT7KPduBK/pfX/fXED9Pt1NN\n# 48VfPSuzAgMBAAGjggIeMIICGjAfBgNVHSMEGDAWgBTLXJOuiJv+Q29WUFICbXj8\n# rOGxWjAdBgNVHQ4EFgQU3CQnBPLvFkovKU/is0/LgQF/49swNAYDVR0RBC0wK6Ap\n# BggrBgEFBQcIA6AdMBsMGVVTLVdBU0hJTkdUT04tNjAzIDM4OSAwNjgwDgYDVR0P\n# AQH/BAQDAgeAMBMGA1UdJQQMMAoGCCsGAQUFBwMDMIGZBgNVHR8EgZEwgY4wRaBD\n# oEGGP2h0dHA6Ly9jcmwzLmRpZ2ljZXJ0LmNvbS9ORVRGb3VuZGF0aW9uUHJvamVj\n# dHNDb2RlU2lnbmluZ0NBLmNybDBFoEOgQYY/aHR0cDovL2NybDQuZGlnaWNlcnQu\n# Y29tL05FVEZvdW5kYXRpb25Qcm9qZWN0c0NvZGVTaWduaW5nQ0EuY3JsMEwGA1Ud\n# IARFMEMwNwYJYIZIAYb9bAMBMCowKAYIKwYBBQUHAgEWHGh0dHBzOi8vd3d3LmRp\n# Z2ljZXJ0LmNvbS9DUFMwCAYGZ4EMAQQBMIGEBggrBgEFBQcBAQR4MHYwJAYIKwYB\n# BQUHMAGGGGh0dHA6Ly9vY3NwLmRpZ2ljZXJ0LmNvbTBOBggrBgEFBQcwAoZCaHR0\n# cDovL2NhY2VydHMuZGlnaWNlcnQuY29tL05FVEZvdW5kYXRpb25Qcm9qZWN0c0Nv\n# ZGVTaWduaW5nQ0EuY3J0MAwGA1UdEwEB/wQCMAAwDQYJKoZIhvcNAQELBQADggEB\n# AH0FqXX4p5RlC27jX6tcTEf2HT4mAiqosnYU/napWgQE2U9m73IZO+2MuiQWkUQi\n# 2PLjbQQcOwfMwkt0SDaSAlfC1zhjZkZb2NcpJRg0cUAjcDzqh6hTzXRVJPD/UrW2\n# a5qBhYnSQDSWbYnVwfAQFFvnQcR5i/xnoOxq7+3LIvHoJafpsxcAFS57Vdsuw91u\n# keB6uasOfvdd06Mpl9BLWZHpyEdnPIKMv6ALibTdw9lNzCQ+EmdT5Fwky8wHE8BH\n# hhAdjSuGiyd+AzR3IuL96Q41h34c7pL827atOHwkkjUx+QTVkXbYoal6wwBKhi6I\n# QJEhT0s/yyFFM7BrLhQpRSsxghDsMIIQ6AIBATBuMFoxCzAJBgNVBAYTAlVTMRgw\n# FgYDVQQKEw8uTkVUIEZvdW5kYXRpb24xMTAvBgNVBAMTKC5ORVQgRm91bmRhdGlv\n# biBQcm9qZWN0cyBDb2RlIFNpZ25pbmcgQ0ECEAvk5+TPRMVgGaiemDul6FgwDQYJ\n# YIZIAWUDBAIBBQCggYQwGAYKKwYBBAGCNwIBDDEKMAigAoAAoQKAADAZBgkqhkiG\n# 9w0BCQMxDAYKKwYBBAGCNwIBBDAcBgorBgEEAYI3AgELMQ4wDAYKKwYBBAGCNwIB\n# FTAvBgkqhkiG9w0BCQQxIgQg3M8y2Uovs3GZZGILEzOaZ5eGje/9PkpzoByKnbYv\n# zTYwDQYJKoZIhvcNAQEBBQAEggEAnU9xhSBP/Rv/Cgvmzp0LcG8pjxPlbjvPef7V\n# xvkeQzTvMHYg0LiveMH1y94PyfBdxqUAGRuCblBOmlECw24w8Hdv8dY2LQMhqJu8\n# Qt08UVYtiJQBHwclFmnK8ER8g/Wc5LPsuvzoYzTvvr/FS2wSCaMV7p2WHIwjJxXR\n# sLaccoU2fuPbmE1WVPsjy3ttzkmfyhbl3Mc2QXiLNTQJ+gSNBg2s2eSzf7eDcM2Z\n# kysuAEdu4kKhSsHOhkkpBHffplg9pYrehbUq8QJ+T/9e0vHPbbP5xIPaRqvBEMWy\n# ydh0LWvK6GnJ+/yPHjddtrjpY4ncTlK5ii+wyzyZc9k4rryOKaGCDsgwgg7EBgor\n# BgEEAYI3AwMBMYIOtDCCDrAGCSqGSIb3DQEHAqCCDqEwgg6dAgEDMQ8wDQYJYIZI\n# AWUDBAIBBQAwdwYLKoZIhvcNAQkQAQSgaARmMGQCAQEGCWCGSAGG/WwHATAxMA0G\n# CWCGSAFlAwQCAQUABCDIQfwOJSjewgHOlovqbOQetKuLbiiSjibgzLTQTnzqLAIQ\n# BSEyueNQrxAikpAH0FblzhgPMjAyMDA2MjUxNDI4NTNaoIILuzCCBoIwggVqoAMC\n# AQICEATNP4VornbGG7D+cWDMp20wDQYJKoZIhvcNAQELBQAwcjELMAkGA1UEBhMC\n# VVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3LmRpZ2ljZXJ0\n# LmNvbTExMC8GA1UEAxMoRGlnaUNlcnQgU0hBMiBBc3N1cmVkIElEIFRpbWVzdGFt\n# cGluZyBDQTAeFw0xOTEwMDEwMDAwMDBaFw0zMDEwMTcwMDAwMDBaMEwxCzAJBgNV\n# BAYTAlVTMRcwFQYDVQQKEw5EaWdpQ2VydCwgSW5jLjEkMCIGA1UEAxMbVElNRVNU\n# QU1QLVNIQTI1Ni0yMDE5LTEwLTE1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB\n# CgKCAQEA6WQ1nPqpmGVkG+QX3LgpNsxnCViFTTDgyf/lOzwRKFCvBzHiXQkYwvaJ\n# jGkIBCPgdy2dFeW46KFqjv/UrtJ6Fu/4QbUdOXXBzy+nrEV+lG2sAwGZPGI+fnr9\n# RZcxtPq32UI+p1Wb31pPWAKoMmkiE76Lgi3GmKtrm7TJ8mURDHQNsvAIlnTE6LJI\n# oqEUpfj64YlwRDuN7/uk9MO5vRQs6wwoJyWAqxBLFhJgC2kijE7NxtWyZVkh4Hws\n# Eo1wDo+KyuDT17M5d1DQQiwues6cZ3o4d1RA/0+VBCDU68jOhxQI/h2A3dDnK3jq\n# vx9wxu5CFlM2RZtTGUlinXoCm5UUowIDAQABo4IDODCCAzQwDgYDVR0PAQH/BAQD\n# AgeAMAwGA1UdEwEB/wQCMAAwFgYDVR0lAQH/BAwwCgYIKwYBBQUHAwgwggG/BgNV\n# HSAEggG2MIIBsjCCAaEGCWCGSAGG/WwHATCCAZIwKAYIKwYBBQUHAgEWHGh0dHBz\n# Oi8vd3d3LmRpZ2ljZXJ0LmNvbS9DUFMwggFkBggrBgEFBQcCAjCCAVYeggFSAEEA\n# bgB5ACAAdQBzAGUAIABvAGYAIAB0AGgAaQBzACAAQwBlAHIAdABpAGYAaQBjAGEA\n# dABlACAAYwBvAG4AcwB0AGkAdAB1AHQAZQBzACAAYQBjAGMAZQBwAHQAYQBuAGMA\n# ZQAgAG8AZgAgAHQAaABlACAARABpAGcAaQBDAGUAcgB0ACAAQwBQAC8AQwBQAFMA\n# IABhAG4AZAAgAHQAaABlACAAUgBlAGwAeQBpAG4AZwAgAFAAYQByAHQAeQAgAEEA\n# ZwByAGUAZQBtAGUAbgB0ACAAdwBoAGkAYwBoACAAbABpAG0AaQB0ACAAbABpAGEA\n# YgBpAGwAaQB0AHkAIABhAG4AZAAgAGEAcgBlACAAaQBuAGMAbwByAHAAbwByAGEA\n# dABlAGQAIABoAGUAcgBlAGkAbgAgAGIAeQAgAHIAZQBmAGUAcgBlAG4AYwBlAC4w\n# CwYJYIZIAYb9bAMVMB8GA1UdIwQYMBaAFPS24SAd/imu0uRhpbKiJbLIFzVuMB0G\n# A1UdDgQWBBRWUw/BxgenTdfYbldygFBM5OyewTBxBgNVHR8EajBoMDKgMKAuhixo\n# dHRwOi8vY3JsMy5kaWdpY2VydC5jb20vc2hhMi1hc3N1cmVkLXRzLmNybDAyoDCg\n# LoYsaHR0cDovL2NybDQuZGlnaWNlcnQuY29tL3NoYTItYXNzdXJlZC10cy5jcmww\n# gYUGCCsGAQUFBwEBBHkwdzAkBggrBgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNl\n# cnQuY29tME8GCCsGAQUFBzAChkNodHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5jb20v\n# RGlnaUNlcnRTSEEyQXNzdXJlZElEVGltZXN0YW1waW5nQ0EuY3J0MA0GCSqGSIb3\n# DQEBCwUAA4IBAQAug6FEBUoE47kyUvrZgfAau/gJjSO5PdiSoeZGHEovbno8Y243\n# F6Mav1gjskOclINOOQmwLOjH4eLM7ct5a87eIwFH7ZVUgeCAexKxrwKGqTpzav74\n# n8GN0SGM5CmCw4oLYAACnR9HxJ+0CmhTf1oQpvgi5vhTkjFf2IKDLW0TQq6DwRBO\n# pCT0R5zeDyJyd1x/T+k5mCtXkkTX726T2UPHBDNjUTdWnkcEEcOjWFQh2OKOVtdJ\n# P1f8Cp8jXnv0lI3dnRq733oqptJFplUMj/ZMivKWz4lG3DGykZCjXzMwYFX1/Gsw\n# rKHt5EdOM55naii1TcLtW5eC+MupCGxTCbT3MIIFMTCCBBmgAwIBAgIQCqEl1tYy\n# G35B5AXaNpfCFTANBgkqhkiG9w0BAQsFADBlMQswCQYDVQQGEwJVUzEVMBMGA1UE\n# ChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMSQwIgYD\n# VQQDExtEaWdpQ2VydCBBc3N1cmVkIElEIFJvb3QgQ0EwHhcNMTYwMTA3MTIwMDAw\n# WhcNMzEwMTA3MTIwMDAwWjByMQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNl\n# cnQgSW5jMRkwFwYDVQQLExB3d3cuZGlnaWNlcnQuY29tMTEwLwYDVQQDEyhEaWdp\n# Q2VydCBTSEEyIEFzc3VyZWQgSUQgVGltZXN0YW1waW5nIENBMIIBIjANBgkqhkiG\n# 9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvdAy7kvNj3/dqbqCmcU5VChXtiNKxA4HRTNR\n# EH3Q+X1NaH7ntqD0jbOI5Je/YyGQmL8TvFfTw+F+CNZqFAA49y4eO+7MpvYyWf5f\n# ZT/gm+vjRkcGGlV+Cyd+wKL1oODeIj8O/36V+/OjuiI+GKwR5PCZA207hXwJ0+5d\n# yJoLVOOoCXFr4M8iEA91z3FyTgqt30A6XLdR4aF5FMZNJCMwXbzsPGBqrC8HzP3w\n# 6kfZiFBe/WZuVmEnKYmEUeaC50ZQ/ZQqLKfkdT66mA+Ef58xFNat1fJky3seBdCE\n# GXIX8RcG7z3N1k3vBkL9olMqT4UdxB08r8/arBD13ays6Vb/kwIDAQABo4IBzjCC\n# AcowHQYDVR0OBBYEFPS24SAd/imu0uRhpbKiJbLIFzVuMB8GA1UdIwQYMBaAFEXr\n# oq/0ksuCMS1Ri6enIZ3zbcgPMBIGA1UdEwEB/wQIMAYBAf8CAQAwDgYDVR0PAQH/\n# BAQDAgGGMBMGA1UdJQQMMAoGCCsGAQUFBwMIMHkGCCsGAQUFBwEBBG0wazAkBggr\n# BgEFBQcwAYYYaHR0cDovL29jc3AuZGlnaWNlcnQuY29tMEMGCCsGAQUFBzAChjdo\n# dHRwOi8vY2FjZXJ0cy5kaWdpY2VydC5jb20vRGlnaUNlcnRBc3N1cmVkSURSb290\n# Q0EuY3J0MIGBBgNVHR8EejB4MDqgOKA2hjRodHRwOi8vY3JsNC5kaWdpY2VydC5j\n# b20vRGlnaUNlcnRBc3N1cmVkSURSb290Q0EuY3JsMDqgOKA2hjRodHRwOi8vY3Js\n# My5kaWdpY2VydC5jb20vRGlnaUNlcnRBc3N1cmVkSURSb290Q0EuY3JsMFAGA1Ud\n# IARJMEcwOAYKYIZIAYb9bAACBDAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5k\n# aWdpY2VydC5jb20vQ1BTMAsGCWCGSAGG/WwHATANBgkqhkiG9w0BAQsFAAOCAQEA\n# cZUS6VGHVmnN793afKpjerN4zwY3QITvS4S/ys8DAv3Fp8MOIEIsr3fzKx8MIVoq\n# twU0HWqumfgnoma/Capg33akOpMP+LLR2HwZYuhegiUexLoceywh4tZbLBQ1QwRo\n# stt1AuByx5jWPGTlH0gQGF+JOGFNYkYkh2OMkVIsrymJ5Xgf1gsUpYDXEkdws3XV\n# k4WTfraSZ/tTYYmo9WuWwPRYaQ18yAGxuSh1t5ljhSKMYcp5lH5Z/IwP42+1ASa2\n# bKXuh1Eh5Fhgm7oMLSttosR+u8QlK0cCCHxJrhO24XxCQijGGFbPQTS2Zl22dHv1\n# VjMiLyI2skuiSpXY9aaOUjGCAk0wggJJAgEBMIGGMHIxCzAJBgNVBAYTAlVTMRUw\n# EwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5jb20x\n# MTAvBgNVBAMTKERpZ2lDZXJ0IFNIQTIgQXNzdXJlZCBJRCBUaW1lc3RhbXBpbmcg\n# Q0ECEATNP4VornbGG7D+cWDMp20wDQYJYIZIAWUDBAIBBQCggZgwGgYJKoZIhvcN\n# AQkDMQ0GCyqGSIb3DQEJEAEEMBwGCSqGSIb3DQEJBTEPFw0yMDA2MjUxNDI4NTNa\n# MCsGCyqGSIb3DQEJEAIMMRwwGjAYMBYEFAMlvVBe2pYwLcIvT6AeTCi+KDTFMC8G\n# CSqGSIb3DQEJBDEiBCAvoc+rYs7skpQOtoc7TrhDopI+gY0L5n1xBAzyBSyC8TAN\n# BgkqhkiG9w0BAQEFAASCAQCRIBcC0oeOOjuPQ2x9QeqG+lmZXas8Y2P9oaXzmbFS\n# 6okl0cflVVL3m9EvPJ3ofob8aQ9PRmyJRIaDP24R8GGS9m8ZTLZJvg8wPOtoE/3t\n# mLfPaY1KFSqtKWF8sLSHkWJzF50FvboB00E4f1mRDBCAZPNfyKSBYiW7b60Blcnz\n# mf721nSHxPPbGtoU4ObXcR4qHyWbrlIMcihIkkwf8HEU3MqqsLSnpGoKeNvS/quz\n# N2mp2eJl9YezOn+yzSkDKSQKg5x+2ZI/2UCstJaq73ahuRSpcdw3Lu6FgWs7n8Wc\n# N6gU/Mpvb3GqgwZWpbSoa9PusWSNLjOyrWAwjhdeBCvV\n# SIG # End signature block\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/wwwroot/css/site.css",
    "content": "﻿.body-container {\n  margin-top: 60px;\n  padding-bottom: 40px; }\n\n.welcome-page li {\n  list-style: none;\n  padding: 4px; }\n\n.logged-out-page iframe {\n  display: none;\n  width: 0;\n  height: 0; }\n\n.grants-page .card {\n  margin-top: 20px;\n  border-bottom: 1px solid lightgray; }\n  .grants-page .card .card-title {\n    font-size: 120%;\n    font-weight: bold; }\n    .grants-page .card .card-title img {\n      width: 100px;\n      height: 100px; }\n  .grants-page .card label {\n    font-weight: bold; }\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/wwwroot/css/site.scss",
    "content": "﻿.body-container {\n    margin-top: 60px;\n    padding-bottom:40px;\n}\n\n.welcome-page {\n    li {\n        list-style: none;\n        padding: 4px;\n    }\n}\n\n.logged-out-page {\n    iframe {\n        display: none;\n        width: 0;\n        height: 0;\n    }\n}\n\n.grants-page {\n    .card {\n        margin-top: 20px;\n        border-bottom: 1px solid lightgray;\n\n        .card-title {\n            img {\n                width: 100px;\n                height: 100px;\n            }\n\n            font-size: 120%;\n            font-weight: bold;\n        }\n\n        label {\n            font-weight: bold;\n        }\n    }\n}\n\n\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/wwwroot/js/signin-redirect.js",
    "content": "// window.location.href = document.querySelector(\"meta[http-equiv=refresh]\").getAttribute(\"data-url\");\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/IdentityServerAspNetIdentity/wwwroot/js/signout-redirect.js",
    "content": "﻿window.addEventListener(\"load\", function () {\n    var a = document.querySelector(\"a.PostLogoutRedirectUri\");\n    if (a) {\n        window.location = a.href;\n    }\n});\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly ILogger<HomeController> _logger;\n\n    public HomeController(ILogger<HomeController> logger)\n    {\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    public async Task<IActionResult> CallApi()\n    {\n        var accessToken = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = new HttpClient();\n        client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue(\"Bearer\", accessToken);\n        var content = await client.GetStringAsync(\"https://localhost:6001/identity\");\n\n        var obj = JsonSerializer.Deserialize<JsonElement>(content);\n        ViewBag.Json = obj.ToString();\n        return View(\"json\");\n    }\n\n    public IActionResult Logout()\n    {\n        return SignOut(\"Cookies\", \"oidc\");\n    }\n\n    [ResponseCache(Duration = 0, Location = ResponseCacheLocation.None, NoStore = true)]\n    public IActionResult Error()\n    {\n        return View(new ErrorViewModel { RequestId = Activity.Current?.Id ?? HttpContext.TraceIdentifier });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using System.Diagnostics;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Net.Http.Headers;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Models/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class ErrorViewModel\n{\n    public string RequestId { get; set; }\n\n    public bool ShowRequestId => !string.IsNullOrEmpty(RequestId);\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/MvcClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <Content Update=\"Views\\Shared\\Json.cshtml\">\n      <ExcludeFromSingleFile>true</ExcludeFromSingleFile>\n      <CopyToPublishDirectory>PreserveNewest</CopyToPublishDirectory>\n    </Content>\n  </ItemGroup>\n\n</Project>"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nJwtSecurityTokenHandler.DefaultMapInboundClaims = false;\n\n\nvar builder = WebApplication.CreateBuilder(args);\n\nbuilder.Services.AddControllersWithViews();\nbuilder.Services\n    .AddAuthentication(options =>\n    {\n        options.DefaultScheme = \"Cookies\";\n        options.DefaultChallengeScheme = \"oidc\";\n    })\n    .AddCookie(\"Cookies\")\n    .AddOpenIdConnect(\"oidc\", options =>\n    {\n        options.Authority = \"https://localhost:5001\";\n\n        options.ClientId = \"mvc\";\n        options.ClientSecret = \"secret\";\n        options.ResponseType = \"code\";\n\n        options.Scope.Add(\"api1\");\n\n        options.SaveTokens = true;\n    });\n\n\nusing (var app = builder.Build())\n{\n    if (app.Environment.IsDevelopment())\n        app.UseDeveloperExceptionPage();\n    else\n        app.UseExceptionHandler(\"/Home/Error\");\n\n    app.UseStaticFiles();\n    app.UseRouting();\n    app.UseAuthentication();\n    app.UseAuthorization();\n    app.MapDefaultControllerRoute().RequireAuthorization();\n\n    await app.RunAsync();\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"MvcClient\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5002\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Views/Home/Index.cshtml",
    "content": "@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Views/Home/Privacy.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Privacy Policy\";\n}\n<h1>@ViewData[\"Title\"]</h1>\n\n<p>Use this page to detail your site's privacy policy.</p>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Views/Shared/Error.cshtml",
    "content": "﻿@model ErrorViewModel\n@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n\n@if (Model.ShowRequestId)\n{\n    <p>\n        <strong>Request ID:</strong> <code>@Model.RequestId</code>\n    </p>\n}\n\n<h3>Development Mode</h3>\n<p>\n    Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.\n</p>\n<p>\n    <strong>The Development environment shouldn't be enabled for deployed applications.</strong>\n    It can result in displaying sensitive information from exceptions to end users.\n    For local debugging, enable the <strong>Development</strong> environment by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>\n    and restarting the app.\n</p>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcClient</title>\n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <header>\n        <nav class=\"navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3\">\n            <div class=\"container\">\n                <a class=\"navbar-brand\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">MvcClient</a>\n                <button class=\"navbar-toggler\" type=\"button\" data-toggle=\"collapse\" data-target=\".navbar-collapse\" aria-controls=\"navbarSupportedContent\"\n                        aria-expanded=\"false\" aria-label=\"Toggle navigation\">\n                    <span class=\"navbar-toggler-icon\"></span>\n                </button>\n                <div class=\"navbar-collapse collapse d-sm-inline-flex flex-sm-row-reverse\">\n                    <ul class=\"navbar-nav flex-grow-1\">\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">Home</a>\n                        </li>\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Logout\">Logout</a>\n                        </li>\n                    </ul>\n                </div>\n            </div>\n        </nav>\n    </header>\n    <div class=\"container\">\n        <main role=\"main\" class=\"pb-3\">\n            @RenderBody()\n        </main>\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n    <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    @RenderSection(\"Scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Views/Shared/_ValidationScriptsPartial.cshtml",
    "content": "﻿<script src=\"~/lib/jquery-validation/dist/jquery.validate.min.js\"></script>\n<script src=\"~/lib/jquery-validation-unobtrusive/jquery.validate.unobtrusive.min.js\"></script>\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Views/Shared/json.cshtml",
    "content": "<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/appsettings.Development.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Debug\",\n      \"System\": \"Information\",\n      \"Microsoft\": \"Information\"\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/appsettings.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Information\",\n      \"Microsoft\": \"Warning\",\n      \"Microsoft.Hosting.Lifetime\": \"Information\"\n    }\n  },\n  \"AllowedHosts\": \"*\"\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/wwwroot/css/site.css",
    "content": "﻿/* Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\nfor details on configuring this project to bundle and minify static web assets. */\n\na.navbar-brand {\n  white-space: normal;\n  text-align: center;\n  word-break: break-all;\n}\n\n/* Provide sufficient contrast against white background */\na {\n  color: #0366d6;\n}\n\n.btn-primary {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n.nav-pills .nav-link.active, .nav-pills .show > .nav-link {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  font-size: 14px;\n}\n@media (min-width: 768px) {\n  html {\n    font-size: 16px;\n  }\n}\n\n.border-top {\n  border-top: 1px solid #e5e5e5;\n}\n.border-bottom {\n  border-bottom: 1px solid #e5e5e5;\n}\n\n.box-shadow {\n  box-shadow: 0 .25rem .75rem rgba(0, 0, 0, .05);\n}\n\nbutton.accept-policy {\n  font-size: 1rem;\n  line-height: inherit;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  position: relative;\n  min-height: 100%;\n}\n\nbody {\n  /* Margin bottom by footer height */\n  margin-bottom: 60px;\n}\n.footer {\n  position: absolute;\n  bottom: 0;\n  width: 100%;\n  white-space: nowrap;\n  line-height: 60px; /* Vertically center the text there */\n}\n"
  },
  {
    "path": "samples/Quickstarts/6_AspNetIdentity/src/MvcClient/wwwroot/js/site.js",
    "content": "﻿// Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\n// for details on configuring this project to bundle and minify static web assets.\n\n// Write your JavaScript code.\n"
  },
  {
    "path": "samples/Quickstarts/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "samples/Quickstarts/Quickstart.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft\n Written by Alexander Higgins https://github.com/alexhiggins732/ \n \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code for this software can be found at https://github.com/alexhiggins732/IdentityServer8\n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n\n*/\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/Api/Api.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n</Project>"
  },
  {
    "path": "samples/Quickstarts/Shared/src/Api/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore.Mvc;\n\nConsole.Title = \"API\";\n\nvar builder = WebApplication.CreateBuilder(args);\n\nvar services = builder.Services;\n\n// accepts any access token issued by identity server\n// adds an authorization policy for scope 'api1'\nservices\n    .AddAuthorization(options =>\n    {\n        options.AddPolicy(\"ApiScope\", policy =>\n        {\n            policy\n                .RequireAuthenticatedUser()\n                .RequireClaim(\"scope\", \"api1\");\n        });\n    })\n    .AddCors(options =>\n    {\n        // this defines a CORS policy called \"default\"\n        options.AddPolicy(\"default\", policy =>\n        {\n            policy.WithOrigins(\"https://localhost:5003\")\n                .AllowAnyHeader()\n                .AllowAnyMethod();\n        });\n    })\n    .AddControllers();\n\n// accepts any access token issued by identity server\nservices\n    .AddAuthentication(\"Bearer\")\n    .AddJwtBearer(\"Bearer\", options =>\n    {\n        options.Authority = \"https://localhost:5001\";\n        options.TokenValidationParameters =\n            new() { ValidateAudience = false };\n    });\n\n\n\nusing (var app = builder.Build())\n{\n    if (app.Environment.IsDevelopment())\n        app.UseDeveloperExceptionPage();\n\n    app\n        .UseRouting()\n        .UseAuthentication()\n        .UseAuthorization()\n        .UseCors(\"default\");\n\n    app.MapGet(\"/identity\", (HttpContext context) =>\n            new JsonResult(context?.User?.Claims.Select(c => new { c.Type, c.Value }))\n        ).RequireAuthorization(\"ApiScope\");\n\n    await app.RunAsync();\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/Api/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"SelfHost\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:6001\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/Shared/src/Client/Client.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n  </PropertyGroup>\n\n  <ItemGroup>\n    <PackageReference Include=\"IdentityModel\" />\n  </ItemGroup>\n\n</Project>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/Client/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityModel.Client;\nusing System.Diagnostics;\nusing System.Text.Json;\n\n// discover endpoints from metadata\nusing HttpClient client = new();\n\nvar disco = await client.GetDiscoveryDocumentAsync(\"https://localhost:5001\");\nif (disco.IsError)\n    Exit(disco.Error);\n\n// request token\nvar tokenResponse = await client.RequestClientCredentialsTokenAsync(\n    new()\n{\n    Address = disco.TokenEndpoint,\n    ClientId = \"client\",\n    ClientSecret = \"secret\",\n\n    Scope = \"api1\"\n});\n\nif (tokenResponse.IsError)\n    Exit(tokenResponse.Error);\n\nConsole.WriteLine(tokenResponse.Json);\nConsole.WriteLine(\"\\n\\n\");\n\n// call api\nclient.SetBearerToken(tokenResponse.AccessToken);\n\nvar response = await client.GetAsync(\"https://localhost:6001/identity\");\nif (!response.IsSuccessStatusCode)\n    Console.WriteLine(response.StatusCode);\nelse\n{\n    var responseJson = await response.Content.ReadAsStringAsync();\n    var obj = JsonSerializer.Deserialize<JsonElement>(responseJson);\n    Console.WriteLine(obj);\n}\n\nExit(\"Done!\", 0);\n\nvoid Exit(string message, int exitCode = 1)\n{\n    Console.WriteLine(message);\n    if (Debugger.IsAttached)\n        Debugger.Break();\n    Environment.Exit(exitCode);\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Config.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic static class Config\n{\n    public static IEnumerable<IdentityResource> IdentityResources =>\n        new List<IdentityResource>\n        {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n        };\n\n\n    public static IEnumerable<ApiScope> ApiScopes =>\n        new List<ApiScope>\n        {\n            new ApiScope(\"api1\", \"My API\")\n        };\n\n    public static IEnumerable<Client> Clients =>\n        new List<Client>\n        {\n            // machine to machine client\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                // scopes that client has access to\n                AllowedScopes = { \"api1\" }\n            },\n            \n            // interactive ASP.NET Core MVC client\n            new Client\n            {\n                ClientId = \"mvc\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                AllowedGrantTypes = GrantTypes.Code,\n                \n                // where to redirect to after login\n                RedirectUris = { \"https://localhost:5002/signin-oidc\" },\n\n                // where to redirect to after logout\n                PostLogoutRedirectUris = { \"https://localhost:5002/signout-callback-oidc\" },\n\n                AllowedScopes = new List<string>\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    \"api1\"\n                }\n            }\n        };\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.Configuration;\nglobal using IdentityServer8.Events;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Test;\nglobal using IdentityServer8.Validation;\nglobal using IdentityServerHost.Quickstart.UI;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Hosting;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.AspNetCore.Mvc.Filters;\nglobal using Microsoft.Extensions.Hosting;\nglobal using Microsoft.Extensions.Options;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\nglobal using System;\nglobal using System.ComponentModel.DataAnnotations;\nglobal using System.Security.Claims;\nglobal using System.Text;\nglobal using System.Text.Json;\nglobal using static IdentityModel.JwtClaimTypes;\nglobal using IdentityServerClaimValueTypes = IdentityServer8.IdentityServerConstants.ClaimValueTypes;\nglobal using ILogger = Microsoft.Extensions.Logging.ILogger;\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/IdentityServer.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"HigginsSoft.IdentityServer8\" />\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n    <PackageReference Include=\"Serilog.AspNetCore\" />  \n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.Google\" />\n  </ItemGroup>\n</Project>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nConfigureLogger();\n\ntry\n{\n    Log.Information(\"Starting host...\");\n\n    var builder = WebApplication.CreateBuilder(args);\n\n    var services = builder.Services;\n\n    services.AddControllersWithViews();\n\n    services\n        .AddIdentityServer()\n        .AddInMemoryIdentityResources(Config.IdentityResources)\n        .AddInMemoryApiScopes(Config.ApiScopes)\n        .AddInMemoryClients(Config.Clients)\n        .AddTestUsers(TestUsers.Users)\n        .AddDeveloperSigningCredential();\n\n    services.AddAuthentication()\n        .AddGoogle(\"Google\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n\n            options.ClientId = \"<insert here>\";\n            options.ClientSecret = \"<insert here>\";\n        })\n        .AddOpenIdConnect(\"oidc\", \"Demo IdentityServer\", options =>\n        {\n            options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n            options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n            options.SaveTokens = true;\n\n            options.Authority = \"https://demo.identityserver8.io/\";\n            options.ClientId = \"interactive.confidential\";\n            options.ClientSecret = \"secret\";\n            options.ResponseType = \"code\";\n\n            options.TokenValidationParameters = new()\n            {\n                NameClaimType = \"name\",\n                RoleClaimType = \"role\"\n            };\n        });\n\n\n    using (var app = builder.Build())\n    {\n        if (app.Environment.IsDevelopment())\n            app.UseDeveloperExceptionPage();\n\n        app.UseStaticFiles()\n            .UseRouting()\n            .UseIdentityServer()\n            .UseAuthorization();\n\n        app.MapDefaultControllerRoute();\n\n        await app.RunAsync();\n    }\n\n    return 0;\n}\ncatch (Exception ex)\n{\n    Log.Fatal(ex, \"Host terminated unexpectedly.\");\n    return 1;\n}\nfinally\n{\n    Log.CloseAndFlush();\n}\n\n\nvoid ConfigureLogger() => Log.Logger = new LoggerConfiguration()\n    .MinimumLevel.Debug()\n    .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n    .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n    .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n    .Enrich.FromLogContext()\n    // uncomment to write to Azure diagnostics stream\n    //.WriteTo.File(\n    //    @\"D:\\home\\LogFiles\\Application\\identityserver.txt\",\n    //    fileSizeLimitBytes: 1_000_000,\n    //    rollOnFileSizeLimit: true,\n    //    shared: true,\n    //    flushToDiskInterval: TimeSpan.FromSeconds(1))\n    .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n    .CreateLogger();\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"SelfHost\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Account/AccountController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller implements a typical login/logout/provision workflow for local and external accounts.\n/// The login service encapsulates the interactions with the user data store. This data store is in-memory only and cannot be used for production!\n/// The interaction service provides a way for the UI to communicate with identityserver for validation and context retrieval\n/// </summary>\n[SecurityHeaders]\n[AllowAnonymous]\npublic class AccountController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly IAuthenticationSchemeProvider _schemeProvider;\n    private readonly IEventService _events;\n\n    public AccountController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IAuthenticationSchemeProvider schemeProvider,\n        IEventService events,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _schemeProvider = schemeProvider;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Entry point into the login workflow\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Login(string returnUrl)\n    {\n        // build a model so we know what to show on the login page\n        var vm = await BuildLoginViewModelAsync(returnUrl);\n\n        if (vm.IsExternalLoginOnly)\n        {\n            // we only have one option for logging in and it's an external provider\n            return returnUrl.IsAllowedRedirect() ? RedirectToAction(\"Challenge\", \"External\", new { scheme = vm.ExternalLoginScheme, returnUrl = returnUrl.SanitizeForRedirect() }) : Forbid();\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Login(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (ModelState.IsValid)\n        {\n            // validate username/password against in-memory store\n            if (_users.ValidateCredentials(model.Username, model.Password))\n            {\n                var user = _users.FindByUsername(model.Username);\n                await _events.RaiseAsync(new UserLoginSuccessEvent(user.Username, user.SubjectId, user.Username, clientId: context?.Client.ClientId));\n\n                // only set explicit expiration here if user chooses \"remember me\". \n                // otherwise we rely upon expiration configured in cookie middleware.\n                AuthenticationProperties props = null;\n                if (AccountOptions.AllowRememberLogin && model.RememberLogin)\n                {\n                    props = new AuthenticationProperties\n                    {\n                        IsPersistent = true,\n                        ExpiresUtc = DateTimeOffset.UtcNow.Add(AccountOptions.RememberMeLoginDuration)\n                    };\n                };\n\n                // issue authentication cookie with subject ID and username\n                var isuser = new IdentityServerUser(user.SubjectId)\n                {\n                    DisplayName = user.Username\n                };\n\n                await HttpContext.SignInAsync(isuser, props);\n\n                if (context != null)\n                {\n                    if (context.IsNativeClient())\n                    {\n                        // The client is native, so this change in how to\n                        // return the response is for better UX for the end user.\n                        return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                    }\n\n                    // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n\n                // request for a local page\n                if (Url.IsLocalUrl(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n                else if (string.IsNullOrEmpty(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n                }\n                else\n                {\n                    // user might have clicked on a malicious link - should be logged\n                    throw new Exception(\"invalid return URL\");\n                }\n            }\n\n            await _events.RaiseAsync(new UserLoginFailureEvent(model.Username, \"invalid credentials\", clientId: context?.Client.ClientId));\n            ModelState.AddModelError(string.Empty, AccountOptions.InvalidCredentialsErrorMessage);\n        }\n\n        // something went wrong, show form with error\n        var vm = await BuildLoginViewModelAsync(model);\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> LoginCancel(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (context != null)\n        {\n            // if the user cancels, send a result back into IdentityServer as if they \n            // denied the consent (even if this client does not require consent).\n            // this will send back an access denied OIDC error response to the client.\n            await _interaction.DenyAuthorizationAsync(context, AuthorizationError.AccessDenied);\n\n            // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n            }\n\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n        }\n        else\n        {\n            // since we don't have a valid context, then we just go back to the home page\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n        }\n\n    }\n\n    /// <summary>\n    /// Show logout page\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Logout(string logoutId)\n    {\n        // build a model so the logout page knows what to display\n        var vm = await BuildLogoutViewModelAsync(logoutId);\n\n        if (vm.ShowLogoutPrompt == false)\n        {\n            // if the request for logout was properly authenticated from IdentityServer, then\n            // we don't need to show the prompt and can just log the user out directly.\n            return await Logout(vm);\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle logout page postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Logout(LogoutInputModel model)\n    {\n        // build a model so the logged out page knows what to display\n        var vm = await BuildLoggedOutViewModelAsync(model.LogoutId);\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            // delete local authentication cookie\n            await HttpContext.SignOutAsync();\n\n            // raise the logout event\n            await _events.RaiseAsync(new UserLogoutSuccessEvent(User.GetSubjectId(), User.GetDisplayName()));\n        }\n\n        // check if we need to trigger sign-out at an upstream identity provider\n        if (vm.TriggerExternalSignout)\n        {\n            // build a return URL so the upstream provider will redirect back\n            // to us after the user has logged out. this allows us to then\n            // complete our single sign-out processing.\n            string url = Url.Action(\"Logout\", new { logoutId = vm.LogoutId });\n\n            // this triggers a redirect to the external provider for sign-out\n            return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);\n        }\n\n        return View(\"LoggedOut\", vm);\n    }\n\n    [HttpGet]\n    public IActionResult AccessDenied()\n    {\n        return View();\n    }\n\n\n    /*****************************************/\n    /* helper APIs for the AccountController */\n    /*****************************************/\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(string returnUrl)\n    {\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (context?.IdP != null && await _schemeProvider.GetSchemeAsync(context.IdP) != null)\n        {\n            var local = context.IdP == IdentityServer8.IdentityServerConstants.LocalIdentityProvider;\n\n            // this is meant to short circuit the UI and only trigger the one external IdP\n            var vm = new LoginViewModel\n            {\n                EnableLocalLogin = local,\n                ReturnUrl = returnUrl,\n                Username = context?.LoginHint,\n            };\n\n            if (!local)\n            {\n                vm.ExternalProviders = new[] { new ExternalProvider { AuthenticationScheme = context.IdP } };\n            }\n\n            return vm;\n        }\n\n        var schemes = await _schemeProvider.GetAllSchemesAsync();\n\n        var providers = schemes\n            .Where(x => x.DisplayName != null)\n            .Select(x => new ExternalProvider\n            {\n                DisplayName = x.DisplayName ?? x.Name,\n                AuthenticationScheme = x.Name\n            }).ToList();\n\n        var allowLocal = true;\n        if (context?.Client.ClientId != null)\n        {\n            var client = await _clientStore.FindEnabledClientByIdAsync(context.Client.ClientId);\n            if (client != null)\n            {\n                allowLocal = client.EnableLocalLogin;\n\n                if (client.IdentityProviderRestrictions != null && client.IdentityProviderRestrictions.Any())\n                {\n                    providers = providers.Where(provider => client.IdentityProviderRestrictions.Contains(provider.AuthenticationScheme)).ToList();\n                }\n            }\n        }\n\n        return new LoginViewModel\n        {\n            AllowRememberLogin = AccountOptions.AllowRememberLogin,\n            EnableLocalLogin = allowLocal && AccountOptions.AllowLocalLogin,\n            ReturnUrl = returnUrl,\n            Username = context?.LoginHint,\n            ExternalProviders = providers.ToArray()\n        };\n    }\n\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(LoginInputModel model)\n    {\n        var vm = await BuildLoginViewModelAsync(model.ReturnUrl);\n        vm.Username = model.Username;\n        vm.RememberLogin = model.RememberLogin;\n        return vm;\n    }\n\n    private async Task<LogoutViewModel> BuildLogoutViewModelAsync(string logoutId)\n    {\n        var vm = new LogoutViewModel { LogoutId = logoutId, ShowLogoutPrompt = AccountOptions.ShowLogoutPrompt };\n\n        if (User?.Identity.IsAuthenticated != true)\n        {\n            // if the user is not authenticated, then just show logged out page\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        var context = await _interaction.GetLogoutContextAsync(logoutId);\n        if (context?.ShowSignoutPrompt == false)\n        {\n            // it's safe to automatically sign-out\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        // show the logout prompt. this prevents attacks where the user\n        // is automatically signed out by another malicious web page.\n        return vm;\n    }\n\n    private async Task<LoggedOutViewModel> BuildLoggedOutViewModelAsync(string logoutId)\n    {\n        // get context information (client name, post logout redirect URI and iframe for federated signout)\n        var logout = await _interaction.GetLogoutContextAsync(logoutId);\n\n        var vm = new LoggedOutViewModel\n        {\n            AutomaticRedirectAfterSignOut = AccountOptions.AutomaticRedirectAfterSignOut,\n            PostLogoutRedirectUri = logout?.PostLogoutRedirectUri,\n            ClientName = string.IsNullOrEmpty(logout?.ClientName) ? logout?.ClientId : logout?.ClientName,\n            SignOutIframeUrl = logout?.SignOutIFrameUrl,\n            LogoutId = logoutId\n        };\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            var idp = User.FindFirst(JwtClaimTypes.IdentityProvider)?.Value;\n            if (idp != null && idp != IdentityServer8.IdentityServerConstants.LocalIdentityProvider)\n            {\n                var providerSupportsSignout = await HttpContext.GetSchemeSupportsSignOutAsync(idp);\n                if (providerSupportsSignout)\n                {\n                    if (vm.LogoutId == null)\n                    {\n                        // if there's no current logout context, we need to create one\n                        // this captures necessary info from the current logged in user\n                        // before we signout and redirect away to the external IdP for signout\n                        vm.LogoutId = await _interaction.CreateLogoutContextAsync();\n                    }\n\n                    vm.ExternalAuthenticationScheme = idp;\n                }\n            }\n        }\n\n        return vm;\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Account/AccountOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI\n{\n    public class AccountOptions\n    {\n        public static bool AllowLocalLogin = true;\n        public static bool AllowRememberLogin = true;\n        public static TimeSpan RememberMeLoginDuration = TimeSpan.FromDays(30);\n\n        public static bool ShowLogoutPrompt = true;\n        public static bool AutomaticRedirectAfterSignOut = false;\n\n        public static string InvalidCredentialsErrorMessage = \"Invalid username or password\";\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Account/ExternalController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class ExternalController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly ILogger<ExternalController> _logger;\n    private readonly IEventService _events;\n\n    public ExternalController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IEventService events,\n        ILogger<ExternalController> logger,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _logger = logger;\n        _events = events;\n    }\n\n    /// <summary>\n    /// initiate roundtrip to external authentication provider\n    /// </summary>\n    [HttpGet]\n    public IActionResult Challenge(string scheme, string returnUrl)\n    {\n        if (string.IsNullOrEmpty(returnUrl)) returnUrl = \"~/\";\n\n        // validate returnUrl - either it is a valid OIDC URL or back to a local page\n        if (Url.IsLocalUrl(returnUrl) == false && _interaction.IsValidReturnUrl(returnUrl) == false)\n        {\n            // user might have clicked on a malicious link - should be logged\n            throw new Exception(\"invalid return URL\");\n        }\n        \n        // start challenge and roundtrip the return URL and scheme \n        var props = new AuthenticationProperties\n        {\n            RedirectUri = Url.Action(nameof(Callback)), \n            Items =\n            {\n                { \"returnUrl\", returnUrl }, \n                { \"scheme\", scheme },\n            }\n        };\n\n        return Challenge(props, scheme);\n        \n    }\n\n    /// <summary>\n    /// Post processing of external authentication\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Callback()\n    {\n        // read external identity from the temporary cookie\n        var result = await HttpContext.AuthenticateAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n        if (result?.Succeeded != true)\n        {\n            throw new Exception(\"External authentication error\");\n        }\n\n        if (_logger.IsEnabled(LogLevel.Debug))\n        {\n            var externalClaims = result.Principal.Claims.Select(c => $\"{c.Type}: {c.Value}\");\n            _logger.LogDebug(\"External claims: {@claims}\", externalClaims);\n        }\n\n        // lookup our user and external provider info\n        var (user, provider, providerUserId, claims) = FindUserFromExternalProvider(result);\n        if (user == null)\n        {\n            // this might be where you might initiate a custom workflow for user registration\n            // in this sample we don't show how that would be done, as our sample implementation\n            // simply auto-provisions new external user\n            user = AutoProvisionUser(provider, providerUserId, claims);\n        }\n\n        // this allows us to collect any additional claims or properties\n        // for the specific protocols used and store them in the local auth cookie.\n        // this is typically used to store data needed for signout from those protocols.\n        var additionalLocalClaims = new List<Claim>();\n        var localSignInProps = new AuthenticationProperties();\n        ProcessLoginCallback(result, additionalLocalClaims, localSignInProps);\n        \n        // issue authentication cookie for user\n        var isuser = new IdentityServerUser(user.SubjectId)\n        {\n            DisplayName = user.Username,\n            IdentityProvider = provider,\n            AdditionalClaims = additionalLocalClaims\n        };\n\n        await HttpContext.SignInAsync(isuser, localSignInProps);\n\n        // delete temporary cookie used during external authentication\n        await HttpContext.SignOutAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n        // retrieve return URL\n        var returnUrl = result.Properties.Items[\"returnUrl\"] ?? \"~/\";\n\n        // check if external login is in the context of an OIDC request\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        await _events.RaiseAsync(new UserLoginSuccessEvent(provider, providerUserId, user.SubjectId, user.Username, true, context?.Client.ClientId));\n\n        if (context != null)\n        {\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", returnUrl);\n            }\n        }\n\n        return Redirect(returnUrl);\n    }\n\n    private (TestUser user, string provider, string providerUserId, IEnumerable<Claim> claims) FindUserFromExternalProvider(AuthenticateResult result)\n    {\n        var externalUser = result.Principal;\n\n        // try to determine the unique id of the external user (issued by the provider)\n        // the most common claim type for that are the sub claim and the NameIdentifier\n        // depending on the external provider, some other claim type might be used\n        var userIdClaim = externalUser.FindFirst(JwtClaimTypes.Subject) ??\n                          externalUser.FindFirst(ClaimTypes.NameIdentifier) ??\n                          throw new Exception(\"Unknown userid\");\n\n        // remove the user id claim so we don't include it as an extra claim if/when we provision the user\n        var claims = externalUser.Claims.ToList();\n        claims.Remove(userIdClaim);\n\n        var provider = result.Properties.Items[\"scheme\"];\n        var providerUserId = userIdClaim.Value;\n\n        // find external user\n        var user = _users.FindByExternalProvider(provider, providerUserId);\n\n        return (user, provider, providerUserId, claims);\n    }\n\n    private TestUser AutoProvisionUser(string provider, string providerUserId, IEnumerable<Claim> claims)\n    {\n        var user = _users.AutoProvisionUser(provider, providerUserId, claims.ToList());\n        return user;\n    }\n\n    // if the external login is OIDC-based, there are certain things we need to preserve to make logout work\n    // this will be different for WS-Fed, SAML2p or other protocols\n    private void ProcessLoginCallback(AuthenticateResult externalResult, List<Claim> localClaims, AuthenticationProperties localSignInProps)\n    {\n        // if the external system sent a session id claim, copy it over\n        // so we can use it for single sign-out\n        var sid = externalResult.Principal.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.SessionId);\n        if (sid != null)\n        {\n            localClaims.Add(new Claim(JwtClaimTypes.SessionId, sid.Value));\n        }\n\n        // if the external provider issued an id_token, we'll keep it for signout\n        var idToken = externalResult.Properties.GetTokenValue(\"id_token\");\n        if (idToken != null)\n        {\n            localSignInProps.StoreTokens(new[] { new AuthenticationToken { Name = \"id_token\", Value = idToken } });\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Account/ExternalProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ExternalProvider\n{\n    public string DisplayName { get; set; }\n    public string AuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Account/LoggedOutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoggedOutViewModel\n{\n    public string PostLogoutRedirectUri { get; set; }\n    public string ClientName { get; set; }\n    public string SignOutIframeUrl { get; set; }\n\n    public bool AutomaticRedirectAfterSignOut { get; set; }\n\n    public string LogoutId { get; set; }\n    public bool TriggerExternalSignout => ExternalAuthenticationScheme != null;\n    public string ExternalAuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Account/LoginInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginInputModel\n{\n    [Required]\n    public string Username { get; set; }\n    [Required]\n    public string Password { get; set; }\n    public bool RememberLogin { get; set; }\n    public string ReturnUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Account/LoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginViewModel : LoginInputModel\n{\n    public bool AllowRememberLogin { get; set; } = true;\n    public bool EnableLocalLogin { get; set; } = true;\n\n    public IEnumerable<ExternalProvider> ExternalProviders { get; set; } = Enumerable.Empty<ExternalProvider>();\n    public IEnumerable<ExternalProvider> VisibleExternalProviders => ExternalProviders.Where(x => !String.IsNullOrWhiteSpace(x.DisplayName));\n\n    public bool IsExternalLoginOnly => EnableLocalLogin == false && ExternalProviders?.Count() == 1;\n    public string ExternalLoginScheme => IsExternalLoginOnly ? ExternalProviders?.SingleOrDefault()?.AuthenticationScheme : null;\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Account/LogoutInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutInputModel\n{\n    public string LogoutId { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Account/LogoutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutViewModel : LogoutInputModel\n{\n    public bool ShowLogoutPrompt { get; set; } = true;\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Account/RedirectViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class RedirectViewModel\n{\n    public string RedirectUrl { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Consent/ConsentController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This controller processes the consent UI\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class ConsentController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly ILogger<ConsentController> _logger;\n\n    public ConsentController(\n        IIdentityServerInteractionService interaction,\n        IEventService events,\n        ILogger<ConsentController> logger)\n    {\n        _interaction = interaction;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Shows the consent screen\n    /// </summary>\n    /// <param name=\"returnUrl\"></param>\n    /// <returns></returns>\n    [HttpGet]\n    public async Task<IActionResult> Index(string returnUrl)\n    {\n        var vm = await BuildViewModelAsync(returnUrl);\n        if (vm != null)\n        {\n            return View(\"Index\", vm);\n        }\n\n        return View(\"Error\");\n    }\n\n    /// <summary>\n    /// Handles the consent screen postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Index(ConsentInputModel model)\n    {\n        var result = await ProcessConsent(model);\n\n        if (result.IsRedirect)\n        {\n            var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n            if (context?.IsNativeClient() == true)\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", result.RedirectUri);\n            }\n            return result.RedirectUri.IsAllowedRedirect() ? Redirect(result.RedirectUri.SanitizeForRedirect()) : Forbid();\n        }\n\n        if (result.HasValidationError)\n        {\n            ModelState.AddModelError(string.Empty, result.ValidationError);\n        }\n\n        if (result.ShowView)\n        {\n            return View(\"Index\", result.ViewModel);\n        }\n\n        return View(\"Error\");\n    }\n\n    /*****************************************/\n    /* helper APIs for the ConsentController */\n    /*****************************************/\n    private async Task<ProcessConsentResult> ProcessConsent(ConsentInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        // validate return url is still valid\n        var request = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model?.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model?.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.GrantConsentAsync(request, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.ReturnUrl, model);\n        }\n\n        return result;\n    }\n\n    private async Task<ConsentViewModel> BuildViewModelAsync(string returnUrl, ConsentInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (request != null)\n        {\n            return CreateConsentViewModel(model, returnUrl, request);\n        }\n        else\n        {\n            _logger.LogError(\"No consent request matching request: {0}\", returnUrl.SanitizeForLog());\n        }\n\n        return null;\n    }\n\n    private ConsentViewModel CreateConsentViewModel(\n        ConsentInputModel model, string returnUrl,\n        AuthorizationRequest request)\n    {\n        var vm = new ConsentViewModel\n        {\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n            Description = model?.Description,\n\n            ReturnUrl = returnUrl,\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach(var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        var displayName = apiScope.DisplayName ?? apiScope.Name;\n        if (!String.IsNullOrWhiteSpace(parsedScopeValue.ParsedParameter))\n        {\n            displayName += \":\" + parsedScopeValue.ParsedParameter;\n        }\n\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            DisplayName = displayName,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Consent/ConsentInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentInputModel\n{\n    public string Button { get; set; }\n    public IEnumerable<string> ScopesConsented { get; set; }\n    public bool RememberConsent { get; set; }\n    public string ReturnUrl { get; set; }\n    public string Description { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Consent/ConsentOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentOptions\n{\n    public static bool EnableOfflineAccess = true;\n    public static string OfflineAccessDisplayName = \"Offline Access\";\n    public static string OfflineAccessDescription = \"Access to your applications and resources, even when you are offline\";\n\n    public static readonly string MustChooseOneErrorMessage = \"You must pick at least one permission\";\n    public static readonly string InvalidSelectionErrorMessage = \"Invalid selection\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Consent/ConsentViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentViewModel : ConsentInputModel\n{\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public bool AllowRememberConsent { get; set; }\n\n    public IEnumerable<ScopeViewModel> IdentityScopes { get; set; }\n    public IEnumerable<ScopeViewModel> ApiScopes { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Consent/ProcessConsentResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ProcessConsentResult\n{\n    public bool IsRedirect => RedirectUri != null;\n    public string RedirectUri { get; set; }\n    public Client Client { get; set; }\n\n    public bool ShowView => ViewModel != null;\n    public ConsentViewModel ViewModel { get; set; }\n\n    public bool HasValidationError => ValidationError != null;\n    public string ValidationError { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Consent/ScopeViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ScopeViewModel\n{\n    public string Value { get; set; }\n    public string DisplayName { get; set; }\n    public string Description { get; set; }\n    public bool Emphasize { get; set; }\n    public bool Required { get; set; }\n    public bool Checked { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Device/DeviceAuthorizationInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationInputModel : ConsentInputModel\n{\n    public string UserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Device/DeviceAuthorizationViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationViewModel : ConsentViewModel\n{\n    public string UserCode { get; set; }\n    public bool ConfirmUserCode { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Device/DeviceController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[Authorize]\n[SecurityHeaders]\npublic class DeviceController : Controller\n{\n    private readonly IDeviceFlowInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly IOptions<IdentityServerOptions> _options;\n    private readonly ILogger<DeviceController> _logger;\n\n    public DeviceController(\n        IDeviceFlowInteractionService interaction,\n        IEventService eventService,\n        IOptions<IdentityServerOptions> options,\n        ILogger<DeviceController> logger)\n    {\n        _interaction = interaction;\n        _events = eventService;\n        _options = options;\n        _logger = logger;\n    }\n\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        string userCodeParamName = _options.Value.UserInteraction.DeviceVerificationUserCodeParameter;\n        string userCode = Request.Query[userCodeParamName];\n        if (string.IsNullOrWhiteSpace(userCode)) return View(\"UserCodeCapture\");\n\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        vm.ConfirmUserCode = true;\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> UserCodeCapture(string userCode)\n    {\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Callback(DeviceAuthorizationInputModel model)\n    {\n        if (model == null) throw new ArgumentNullException(nameof(model));\n\n        var result = await ProcessConsent(model);\n        if (result.HasValidationError) return View(\"Error\");\n\n        return View(\"Success\");\n    }\n\n    private async Task<ProcessConsentResult> ProcessConsent(DeviceAuthorizationInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        var request = await _interaction.GetAuthorizationContextAsync(model.UserCode);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.HandleRequestAsync(model.UserCode, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.UserCode, model);\n        }\n\n        return result;\n    }\n\n    private async Task<DeviceAuthorizationViewModel> BuildViewModelAsync(string userCode, DeviceAuthorizationInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(userCode);\n        if (request != null)\n        {\n            return CreateConsentViewModel(userCode, model, request);\n        }\n\n        return null;\n    }\n\n    private DeviceAuthorizationViewModel CreateConsentViewModel(string userCode, DeviceAuthorizationInputModel model, DeviceFlowAuthorizationRequest request)\n    {\n        var vm = new DeviceAuthorizationViewModel\n        {\n            UserCode = userCode,\n            Description = model?.Description,\n\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach (var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            // todo: use the parsed scope value in the display?\n            DisplayName = apiScope.DisplayName ?? apiScope.Name,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Diagnostics/DiagnosticsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[Authorize]\npublic class DiagnosticsController : Controller\n{\n    public async Task<IActionResult> Index()\n    {\n        var localAddresses = new string[] { \"127.0.0.1\", \"::1\", HttpContext.Connection.LocalIpAddress.ToString() };\n        if (!localAddresses.Contains(HttpContext.Connection.RemoteIpAddress.ToString()))\n        {\n            return NotFound();\n        }\n\n        var model = new DiagnosticsViewModel(await HttpContext.AuthenticateAsync());\n        return View(model);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Diagnostics/DiagnosticsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DiagnosticsViewModel\n{\n    public DiagnosticsViewModel(AuthenticateResult result)\n    {\n        AuthenticateResult = result;\n\n        if (result.Properties.Items.ContainsKey(\"client_list\"))\n        {\n            var encoded = result.Properties.Items[\"client_list\"];\n            var bytes = Base64Url.Decode(encoded);\n            var value = Encoding.UTF8.GetString(bytes);\n\n            Clients = JsonSerializer.Deserialize<string[]>(value);\n        }\n    }\n\n    public AuthenticateResult AuthenticateResult { get; }\n    public IEnumerable<string> Clients { get; } = new List<string>();\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Extensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic static class Extensions\n{\n    /// <summary>\n    /// Checks if the redirect URI is for a native client.\n    /// </summary>\n    /// <returns></returns>\n    public static bool IsNativeClient(this AuthorizationRequest context)\n    {\n        return !context.RedirectUri.StartsWith(\"https\", StringComparison.Ordinal)\n           && !context.RedirectUri.StartsWith(\"http\", StringComparison.Ordinal);\n    }\n\n    public static IActionResult LoadingPage(this Controller controller, string viewName, string redirectUri)\n    {\n        controller.HttpContext.Response.StatusCode = 200;\n        controller.HttpContext.Response.Headers[\"Location\"] = \"\";\n        \n        return controller.View(viewName, new RedirectViewModel { RedirectUrl = redirectUri });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Grants/GrantsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller allows a user to revoke grants given to clients\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class GrantsController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clients;\n    private readonly IResourceStore _resources;\n    private readonly IEventService _events;\n\n    public GrantsController(IIdentityServerInteractionService interaction,\n        IClientStore clients,\n        IResourceStore resources,\n        IEventService events)\n    {\n        _interaction = interaction;\n        _clients = clients;\n        _resources = resources;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Show list of grants\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        return View(\"Index\", await BuildViewModelAsync());\n    }\n\n    /// <summary>\n    /// Handle postback to revoke a client\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Revoke(string clientId)\n    {\n        await _interaction.RevokeUserConsentAsync(clientId);\n        await _events.RaiseAsync(new GrantsRevokedEvent(User.GetSubjectId(), clientId));\n\n        return RedirectToAction(\"Index\");\n    }\n\n    private async Task<GrantsViewModel> BuildViewModelAsync()\n    {\n        var grants = await _interaction.GetAllUserGrantsAsync();\n\n        var list = new List<GrantViewModel>();\n        foreach(var grant in grants)\n        {\n            var client = await _clients.FindClientByIdAsync(grant.ClientId);\n            if (client != null)\n            {\n                var resources = await _resources.FindResourcesByScopeAsync(grant.Scopes);\n\n                var item = new GrantViewModel()\n                {\n                    ClientId = client.ClientId,\n                    ClientName = client.ClientName ?? client.ClientId,\n                    ClientLogoUrl = client.LogoUri,\n                    ClientUrl = client.ClientUri,\n                    Description = grant.Description,\n                    Created = grant.CreationTime,\n                    Expires = grant.Expiration,\n                    IdentityGrantNames = resources.IdentityResources.Select(x => x.DisplayName ?? x.Name).ToArray(),\n                    ApiGrantNames = resources.ApiScopes.Select(x => x.DisplayName ?? x.Name).ToArray()\n                };\n\n                list.Add(item);\n            }\n        }\n\n        return new GrantsViewModel\n        {\n            Grants = list\n        };\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Grants/GrantsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class GrantsViewModel\n{\n    public IEnumerable<GrantViewModel> Grants { get; set; }\n}\n\npublic class GrantViewModel\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public string Description { get; set; }\n    public DateTime Created { get; set; }\n    public DateTime? Expires { get; set; }\n    public IEnumerable<string> IdentityGrantNames { get; set; }\n    public IEnumerable<string> ApiGrantNames { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Home/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ErrorViewModel\n{\n    public ErrorViewModel()\n    {\n    }\n\n    public ErrorViewModel(string error)\n    {\n        Error = new ErrorMessage { Error = error };\n    }\n\n    public ErrorMessage Error { get; set; }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/Home/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class HomeController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IWebHostEnvironment _environment;\n    private readonly ILogger _logger;\n\n    public HomeController(IIdentityServerInteractionService interaction, IWebHostEnvironment environment, ILogger<HomeController> logger)\n    {\n        _interaction = interaction;\n        _environment = environment;\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        if (_environment.IsDevelopment())\n        {\n            // only show in development\n            return View();\n        }\n\n        _logger.LogInformation(\"Homepage is disabled in production. Returning 404.\");\n        return NotFound();\n    }\n\n    /// <summary>\n    /// Shows the error page\n    /// </summary>\n    public async Task<IActionResult> Error(string errorId)\n    {\n        var vm = new ErrorViewModel();\n\n        // retrieve error details from identityserver\n        var message = await _interaction.GetErrorContextAsync(errorId);\n        if (message != null)\n        {\n            vm.Error = message;\n\n            if (!_environment.IsDevelopment())\n            {\n                // only show in development\n                message.ErrorDescription = null;\n            }\n        }\n\n        return View(\"Error\", vm);\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/SecurityHeadersAttribute.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class SecurityHeadersAttribute : ActionFilterAttribute\n{\n    public override void OnResultExecuting(ResultExecutingContext context)\n    {\n        var result = context.Result;\n        if (result is ViewResult)\n        {\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Type-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Type-Options\", \"nosniff\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Frame-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Frame-Options\", \"SAMEORIGIN\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy\n            var csp = \"default-src 'self'; object-src 'none'; frame-ancestors 'none'; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self';\";\n            // also consider adding upgrade-insecure-requests once you have HTTPS in place for production\n            //csp += \"upgrade-insecure-requests;\";\n            // also an example if you need client images to be displayed from twitter\n            // csp += \"img-src 'self' https://pbs.twimg.com;\";\n\n            // once for standards compliant browsers\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Content-Security-Policy\", csp);\n            }\n            // and once again for IE\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Security-Policy\", csp);\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy\n            var referrer_policy = \"no-referrer\";\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Referrer-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Referrer-Policy\", referrer_policy);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Quickstart/TestUsers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class TestUsers\n{\n\n    static readonly object UserAddress = new\n    {\n        street_address = \"One Hacker Way\",\n        locality = \"Heidelberg\",\n        postal_code = 69118,\n        country = \"Germany\"\n    };\n\n    public static List<TestUser> Users => new List<TestUser>\n    {\n        new()\n        {\n            SubjectId = \"818727\",\n            Username = \"alice\",\n            Password = \"alice\",\n            Claims =\n            {\n                new (Name, \"Alice Smith\"),\n                new (GivenName, \"Alice\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"AliceSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://alice.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        },\n        new()\n        {\n            SubjectId = \"88421113\",\n            Username = \"bob\",\n            Password = \"bob\",\n            Claims =\n            {\n                new (Name, \"Bob Smith\"),\n                new (GivenName, \"Bob\"),\n                new (FamilyName, \"Smith\"),\n                new (Email, \"BobSmith@email.com\"),\n                new (EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new (WebSite, \"http://bob.com\"),\n                new (Address, JsonSerializer.Serialize(UserAddress), IdentityServerClaimValueTypes.Json)\n            }\n        }\n    };\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Account/AccessDenied.cshtml",
    "content": "﻿\n<div class=\"container\">\n    <div class=\"lead\">\n        <h1>Access Denied</h1>\n        <p>You do not have access to that resource.</p>\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Account/LoggedOut.cshtml",
    "content": "﻿@model LoggedOutViewModel\n\n@{ \n    // set this so the layout rendering sees an anonymous user\n    ViewData[\"signed-out\"] = true;\n}\n\n<div class=\"logged-out-page\">\n    <h1>\n        Logout\n        <small>You are now logged out</small>\n    </h1>\n\n    @if (Model.PostLogoutRedirectUri != null)\n    {\n        <div>\n            Click <a class=\"PostLogoutRedirectUri\" href=\"@Model.PostLogoutRedirectUri\">here</a> to return to the\n            <span>@Model.ClientName</span> application.\n        </div>\n    }\n\n    @if (Model.SignOutIframeUrl != null)\n    {\n        <iframe width=\"0\" height=\"0\" class=\"signout\" src=\"@Model.SignOutIframeUrl\"></iframe>\n    }\n</div>\n\n@section scripts\n{\n    @if (Model.AutomaticRedirectAfterSignOut)\n    {\n        <script src=\"~/js/signout-redirect.js\"></script>\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Account/Login.cshtml",
    "content": "@model LoginViewModel\n\n<div class=\"login-page\">\n    <div class=\"lead\">\n        <h1>Login</h1>\n        <p>Choose how to login</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n\n        @if (Model.EnableLocalLogin)\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>Local Account</h2>\n                    </div>\n\n                    <div class=\"card-body\">\n                        <form asp-route=\"Login\">\n                            <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n\n                            <div class=\"form-group\">\n                                <label asp-for=\"Username\"></label>\n                                <input class=\"form-control\" placeholder=\"Username\" asp-for=\"Username\" autofocus>\n                            </div>\n                            <div class=\"form-group\">\n                                <label asp-for=\"Password\"></label>\n                                <input type=\"password\" class=\"form-control\" placeholder=\"Password\" asp-for=\"Password\" autocomplete=\"off\">\n                            </div>\n                            @if (Model.AllowRememberLogin)\n                            {\n                                <div class=\"form-group\">\n                                    <div class=\"form-check\">\n                                        <input class=\"form-check-input\" asp-for=\"RememberLogin\">\n                                        <label class=\"form-check-label\" asp-for=\"RememberLogin\">\n                                            Remember My Login\n                                        </label>\n                                    </div>\n                                </div>\n                            }\n                            <button class=\"btn btn-primary\" name=\"button\" value=\"login\">Login</button>\n                            <button class=\"btn btn-secondary\" name=\"button\" value=\"cancel\" formaction=\"/Account/LoginCancel\">Cancel</button>\n                        </form>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>External Account</h2>\n                    </div>\n                    <div class=\"card-body\">\n                        <ul class=\"list-inline\">\n                            @foreach (var provider in Model.VisibleExternalProviders)\n                            {\n                                <li class=\"list-inline-item\">\n                                    <a class=\"btn btn-secondary\"\n                                       asp-controller=\"External\"\n                                       asp-action=\"Challenge\"\n                                       asp-route-scheme=\"@provider.AuthenticationScheme\"\n                                       asp-route-returnUrl=\"@Model.ReturnUrl\">\n                                        @provider.DisplayName\n                                    </a>\n                                </li>\n                            }\n                        </ul>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (!Model.EnableLocalLogin && !Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"alert alert-warning\">\n                <strong>Invalid login request</strong>\n                There are no login schemes configured for this request.\n            </div>\n        }\n    </div>\n</div>"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Account/Logout.cshtml",
    "content": "﻿@model LogoutViewModel\n\n<div class=\"logout-page\">\n    <div class=\"lead\">\n        <h1>Logout</h1>\n        <p>Would you like to logout of IdentityServer?</p>\n    </div>\n\n    <form asp-action=\"Logout\">\n        <input type=\"hidden\" name=\"logoutId\" value=\"@Model.LogoutId\"  />\n        <div class=\"form-group\">\n            <button class=\"btn btn-primary\">Yes</button>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Consent/Index.cshtml",
    "content": "@model ConsentViewModel\n\n<div class=\"page-consent\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Index\">\n        <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Device/Success.cshtml",
    "content": "\n<div class=\"page-device-success\">\n    <div class=\"lead\">\n        <h1>Success</h1>\n        <p>You have successfully authorized the device</p>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Device/UserCodeCapture.cshtml",
    "content": "@model string\n\n<div class=\"page-device-code\">\n    <div class=\"lead\">\n        <h1>User Code</h1>\n        <p>Please enter the code displayed on your device.</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <form asp-action=\"UserCodeCapture\">\n                <div class=\"form-group\">\n                    <label for=\"userCode\">User Code:</label>\n                    <input class=\"form-control\" for=\"userCode\" name=\"userCode\" autofocus />\n                </div>\n\n                <button class=\"btn btn-primary\" name=\"button\">Submit</button>\n            </form>\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Device/UserCodeConfirmation.cshtml",
    "content": "@model DeviceAuthorizationViewModel\n\n<div class=\"page-device-confirmation\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        @if (Model.ConfirmUserCode)\n        {\n            <p>Please confirm that the authorization request quotes the code: <strong>@Model.UserCode</strong>.</p>\n        }\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Callback\">\n        <input asp-for=\"UserCode\" type=\"hidden\" value=\"@Model.UserCode\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Diagnostics/Index.cshtml",
    "content": "@model DiagnosticsViewModel\n\n<div class=\"diagnostics-page\">\n    <div class=\"lead\">\n        <h1>Authentication Cookie</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Claims</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var claim in Model.AuthenticateResult.Principal.Claims)\n                        {\n                            <dt>@claim.Type</dt>\n                            <dd>@claim.Value</dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n        \n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Properties</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var prop in Model.AuthenticateResult.Properties.Items)\n                        {\n                            <dt>@prop.Key</dt>\n                            <dd>@prop.Value</dd>\n                        }\n                        @if (Model.Clients.Any())\n                        {\n                            <dt>Clients</dt>\n                            <dd>\n                            @{\n                                var clients = Model.Clients.ToArray();\n                                for(var i = 0; i < clients.Length; i++)\n                                {\n                                    <text>@clients[i]</text>\n                                    if (i < clients.Length - 1)\n                                    {\n                                        <text>, </text>\n                                    }\n                                }\n                            }\n                            </dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n    </div>\n</div>\n\n\n\n\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Grants/Index.cshtml",
    "content": "﻿@model GrantsViewModel\n\n<div class=\"grants-page\">\n    <div class=\"lead\">\n        <h1>Client Application Permissions</h1>\n        <p>Below is the list of applications you have given permission to and the resources they have access to.</p>\n    </div>\n\n    @if (Model.Grants.Any() == false)\n    {\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                <div class=\"alert alert-info\">\n                    You have not given access to any applications\n                </div>\n            </div>\n        </div>\n    }\n    else\n    {\n        foreach (var grant in Model.Grants)\n        {\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <div class=\"row\">\n                        <div class=\"col-sm-8 card-title\">\n                            @if (grant.ClientLogoUrl != null)\n                            {\n                                <img src=\"@grant.ClientLogoUrl\">\n                            }\n                            <strong>@grant.ClientName</strong>\n                        </div>\n\n                        <div class=\"col-sm-2\">\n                            <form asp-action=\"Revoke\">\n                                <input type=\"hidden\" name=\"clientId\" value=\"@grant.ClientId\">\n                                <button class=\"btn btn-danger\">Revoke Access</button>\n                            </form>\n                        </div>\n                    </div>\n                </div>\n                \n                <ul class=\"list-group list-group-flush\">\n                    @if (grant.Description != null)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Description:</label> @grant.Description\n                        </li>   \n                    }\n                    <li class=\"list-group-item\">\n                        <label>Created:</label> @grant.Created.ToString(\"yyyy-MM-dd\")\n                    </li>\n                    @if (grant.Expires.HasValue)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Expires:</label> @grant.Expires.Value.ToString(\"yyyy-MM-dd\")\n                        </li>\n                    }\n                    @if (grant.IdentityGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Identity Grants</label>\n                            <ul>\n                                @foreach (var name in grant.IdentityGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                    @if (grant.ApiGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>API Grants</label>\n                            <ul>\n                                @foreach (var name in grant.ApiGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                </ul>\n            </div>\n        }\n    }\n</div>"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Home/Index.cshtml",
    "content": "@using System.Diagnostics\n\n@{\n    var version = FileVersionInfo.GetVersionInfo(typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.Location).ProductVersion.Split('+').First();\n}\n\n<div class=\"welcome-page\">\n    <h1>\n        <img src=\"~/icon.jpg\">\n        Welcome to IdentityServer8\n        <small class=\"text-muted\">(version @version)</small>\n    </h1>\n\n    <ul>\n        <li>\n            IdentityServer publishes a\n            <a href=\"~/.well-known/openid-configuration\">discovery document</a>\n            where you can find metadata and links to all the endpoints, key material, etc.\n        </li>\n        <li>\n            Click <a href=\"~/diagnostics\">here</a> to see the claims for your current session.\n        </li>\n        <li>\n            Click <a href=\"~/grants\">here</a> to manage your stored grants.\n        </li>\n        <li>\n            Here are links to the\n            <a href=\"https://github.com/alexhiggins732/IdentityServer8\">source code repository</a>,\n            and <a href=\"https://github.com/alexhiggins732/IdentityServer8/tree/main/samples\">ready to use samples</a>.\n        </li>\n    </ul>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Shared/Error.cshtml",
    "content": "@model ErrorViewModel\n\n@{\n    var error = Model?.Error?.Error;\n    var errorDescription = Model?.Error?.ErrorDescription;\n    var request_id = Model?.Error?.RequestId;\n}\n\n<div class=\"error-page\">\n    <div class=\"lead\">\n        <h1>Error</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <div class=\"alert alert-danger\">\n                Sorry, there was an error\n\n                @if (error != null)\n                {\n                    <strong>\n                        <em>\n                            : @error\n                        </em>\n                    </strong>\n\n                    if (errorDescription != null)\n                    {\n                        <div>@errorDescription</div>\n                    }\n                }\n            </div>\n\n            @if (request_id != null)\n            {\n                <div class=\"request-id\">Request Id: @request_id</div>\n            }\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Shared/Redirect.cshtml",
    "content": "@model RedirectViewModel\n@using Microsoft.Extensions.DependencyInjection;\n<div class=\"redirect-page\">\n    <div class=\"lead\">\n        <h1>You are now being returned to the application</h1>\n        <p>Once complete, you may close this tab.</p>\n    </div>\n</div>\n\n<meta http-equiv=\"refresh\" content=\"0;url=@Model.RedirectUrl\" data-url=\"@Model.RedirectUrl\">\n<script>\n    var url = '@Ioc.Sanitizer.Url.Sanitize(Model.RedirectUrl)';\n    window.location.href = url;\n</script>\n\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0, shrink-to-fit=no\" />\n\n    <title>IdentityServer8</title>\n    \n    <link rel=\"icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    <link rel=\"shortcut icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    \n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <partial name=\"_Nav\" />\n   \n    <div class=\"container body-container\">\n        @RenderBody()\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.slim.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Shared/_Nav.cshtml",
    "content": "@using IdentityServer8.Extensions\n\n@{\n    string name = null;\n    if (!true.Equals(ViewData[\"signed-out\"]))\n    {\n        name = Context.User?.GetDisplayName();\n    }\n}\n\n<div class=\"nav-page\">\n    <nav class=\"navbar navbar-expand-lg navbar-dark bg-dark\">\n\n        <a href=\"~/\" class=\"navbar-brand\">\n            <img src=\"~/icon.png\" class=\"icon-banner\">\n            IdentityServer8\n        </a>\n\n        @if (!string.IsNullOrWhiteSpace(name))\n        {\n            <ul class=\"navbar-nav mr-auto\">\n                <li class=\"nav-item dropdown\">\n                    <a href=\"#\" class=\"nav-link dropdown-toggle\" data-toggle=\"dropdown\">@name <b class=\"caret\"></b></a>\n                    \n                    <div class=\"dropdown-menu\">\n                        <a class=\"dropdown-item\" asp-action=\"Logout\" asp-controller=\"Account\">Logout</a>\n                    </div>\n              </li>\n            </ul>\n        }\n    \n    </nav>\n</div>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Shared/_ScopeListItem.cshtml",
    "content": "﻿@model ScopeViewModel\n\n<li class=\"list-group-item\">\n    <label>\n        <input class=\"consent-scopecheck\"\n               type=\"checkbox\"\n               name=\"ScopesConsented\"\n               id=\"scopes_@Model.Value\"\n               value=\"@Model.Value\"\n               checked=\"@Model.Checked\"\n               disabled=\"@Model.Required\" />\n        @if (Model.Required)\n        {\n            <input type=\"hidden\"\n                   name=\"ScopesConsented\"\n                   value=\"@Model.Value\" />\n        }\n        <strong>@Model.DisplayName</strong>\n        @if (Model.Emphasize)\n        {\n            <span class=\"glyphicon glyphicon-exclamation-sign\"></span>\n        }\n    </label>\n    @if (Model.Required)\n    {\n        <span><em>(required)</em></span>\n    }\n    @if (Model.Description != null)\n    {\n        <div class=\"consent-description\">\n            <label for=\"scopes_@Model.Value\">@Model.Description</label>\n        </div>\n    }\n</li>"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/Shared/_ValidationSummary.cshtml",
    "content": "﻿@if (ViewContext.ModelState.IsValid == false)\n{\n    <div class=\"alert alert-danger\">\n        <strong>Error</strong>\n        <div asp-validation-summary=\"All\" class=\"danger\"></div>\n    </div>\n}"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/_ViewImports.cshtml",
    "content": "﻿@using IdentityServerHost.Quickstart.UI\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/wwwroot/css/site.css",
    "content": "﻿.body-container {\n  margin-top: 60px;\n  padding-bottom: 40px; }\n\n.welcome-page li {\n  list-style: none;\n  padding: 4px; }\n\n.logged-out-page iframe {\n  display: none;\n  width: 0;\n  height: 0; }\n\n.grants-page .card {\n  margin-top: 20px;\n  border-bottom: 1px solid lightgray; }\n  .grants-page .card .card-title {\n    font-size: 120%;\n    font-weight: bold; }\n    .grants-page .card .card-title img {\n      width: 100px;\n      height: 100px; }\n  .grants-page .card label {\n    font-weight: bold; }\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/wwwroot/css/site.scss",
    "content": "﻿.body-container {\n    margin-top: 60px;\n    padding-bottom:40px;\n}\n\n.welcome-page {\n    li {\n        list-style: none;\n        padding: 4px;\n    }\n}\n\n.logged-out-page {\n    iframe {\n        display: none;\n        width: 0;\n        height: 0;\n    }\n}\n\n.grants-page {\n    .card {\n        margin-top: 20px;\n        border-bottom: 1px solid lightgray;\n\n        .card-title {\n            img {\n                width: 100px;\n                height: 100px;\n            }\n\n            font-size: 120%;\n            font-weight: bold;\n        }\n\n        label {\n            font-weight: bold;\n        }\n    }\n}\n\n\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/wwwroot/js/signin-redirect.js",
    "content": "//window.location.href = document.querySelector(\"meta[http-equiv=refresh]\").getAttribute(\"data-url\");\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/IdentityServer/wwwroot/js/signout-redirect.js",
    "content": "﻿window.addEventListener(\"load\", function () {\n    var a = document.querySelector(\"a.PostLogoutRedirectUri\");\n    if (a) {\n        window.location = a.href;\n    }\n});\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Controllers/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class HomeController : Controller\n{\n    private readonly ILogger<HomeController> _logger;\n\n    public HomeController(ILogger<HomeController> logger)\n    {\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        return View();\n    }\n\n    public async Task<IActionResult> CallApi()\n    {\n        var accessToken = await HttpContext.GetTokenAsync(\"access_token\");\n\n        var client = new HttpClient();\n        client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue(\"Bearer\", accessToken);\n        var content = await client.GetStringAsync(\"https://localhost:6001/identity\");\n\n        var obj = JsonSerializer.Deserialize<JsonElement>(content);\n        ViewBag.Json = obj.ToString();\n        return View(\"json\");\n    }\n\n    public IActionResult Logout()\n    {\n        return SignOut(\"Cookies\", \"oidc\");\n    }\n\n    [ResponseCache(Duration = 0, Location = ResponseCacheLocation.None, NoStore = true)]\n    public IActionResult Error()\n    {\n        return View(new ErrorViewModel { RequestId = Activity.Current?.Id ?? HttpContext.TraceIdentifier });\n    }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using System.Diagnostics;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Net.Http.Headers;\nglobal using System.Text.Json;\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Models/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\npublic class ErrorViewModel\n{\n    public string RequestId { get; set; }\n\n    public bool ShowRequestId => !string.IsNullOrEmpty(RequestId);\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/MvcClient.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.OpenIdConnect\" />\n    <PackageReference Include=\"Microsoft.Web.LibraryManager.Build\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <Content Update=\"Views\\Shared\\Json.cshtml\">\n      <ExcludeFromSingleFile>true</ExcludeFromSingleFile>\n      <CopyToPublishDirectory>PreserveNewest</CopyToPublishDirectory>\n    </Content>\n  </ItemGroup>\n\n</Project>"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nJwtSecurityTokenHandler.DefaultMapInboundClaims = false;\n\n\nvar builder = WebApplication.CreateBuilder(args);\n\nbuilder.Services.AddControllersWithViews();\nbuilder.Services\n    .AddAuthentication(options =>\n    {\n        options.DefaultScheme = \"Cookies\";\n        options.DefaultChallengeScheme = \"oidc\";\n    })\n    .AddCookie(\"Cookies\")\n    .AddOpenIdConnect(\"oidc\", options =>\n    {\n        options.Authority = \"https://localhost:5001\";\n\n        options.ClientId = \"mvc\";\n        options.ClientSecret = \"secret\";\n        options.ResponseType = \"code\";\n\n        options.Scope.Add(\"api1\");\n\n        options.SaveTokens = true;\n    });\n\n\nusing (var app = builder.Build())\n{\n    if (app.Environment.IsDevelopment())\n        app.UseDeveloperExceptionPage();\n    else\n        app.UseExceptionHandler(\"/Home/Error\");\n\n    app.UseStaticFiles();\n    app.UseRouting();\n    app.UseAuthentication();\n    app.UseAuthorization();\n    app.MapDefaultControllerRoute().RequireAuthorization();\n\n    await app.RunAsync();\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"MvcClient\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5002\"\n    }\n  }\n}"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Views/Home/Index.cshtml",
    "content": "@using Microsoft.AspNetCore.Authentication\n\n<h2>Claims</h2>\n\n<dl>\n    @foreach (var claim in User.Claims)\n    {\n        <dt>@claim.Type</dt>\n        <dd>@claim.Value</dd>\n    }\n</dl>\n\n<h2>Properties</h2>\n\n<dl>\n    @foreach (var prop in (await Context.AuthenticateAsync()).Properties.Items)\n    {\n        <dt>@prop.Key</dt>\n        <dd>@prop.Value</dd>\n    }\n</dl>"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Views/Home/Privacy.cshtml",
    "content": "﻿@{\n    ViewData[\"Title\"] = \"Privacy Policy\";\n}\n<h1>@ViewData[\"Title\"]</h1>\n\n<p>Use this page to detail your site's privacy policy.</p>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Views/Shared/Error.cshtml",
    "content": "﻿@model ErrorViewModel\n@{\n    ViewData[\"Title\"] = \"Error\";\n}\n\n<h1 class=\"text-danger\">Error.</h1>\n<h2 class=\"text-danger\">An error occurred while processing your request.</h2>\n\n@if (Model.ShowRequestId)\n{\n    <p>\n        <strong>Request ID:</strong> <code>@Model.RequestId</code>\n    </p>\n}\n\n<h3>Development Mode</h3>\n<p>\n    Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.\n</p>\n<p>\n    <strong>The Development environment shouldn't be enabled for deployed applications.</strong>\n    It can result in displaying sensitive information from exceptions to end users.\n    For local debugging, enable the <strong>Development</strong> environment by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>\n    and restarting the app.\n</p>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\" />\n    <title>@ViewData[\"Title\"] - MvcClient</title>\n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <header>\n        <nav class=\"navbar navbar-expand-sm navbar-toggleable-sm navbar-light bg-white border-bottom box-shadow mb-3\">\n            <div class=\"container\">\n                <a class=\"navbar-brand\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">MvcClient</a>\n                <button class=\"navbar-toggler\" type=\"button\" data-toggle=\"collapse\" data-target=\".navbar-collapse\" aria-controls=\"navbarSupportedContent\"\n                        aria-expanded=\"false\" aria-label=\"Toggle navigation\">\n                    <span class=\"navbar-toggler-icon\"></span>\n                </button>\n                <div class=\"navbar-collapse collapse d-sm-inline-flex flex-sm-row-reverse\">\n                    <ul class=\"navbar-nav flex-grow-1\">\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Index\">Home</a>\n                        </li>\n                        <li class=\"nav-item\">\n                            <a class=\"nav-link text-dark\" asp-area=\"\" asp-controller=\"Home\" asp-action=\"Logout\">Logout</a>\n                        </li>\n                    </ul>\n                </div>\n            </div>\n        </nav>\n    </header>\n    <div class=\"container\">\n        <main role=\"main\" class=\"pb-3\">\n            @RenderBody()\n        </main>\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n    <script src=\"~/js/site.js\" asp-append-version=\"true\"></script>\n    @RenderSection(\"Scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Views/Shared/_ValidationScriptsPartial.cshtml",
    "content": "﻿<script src=\"~/lib/jquery-validation/dist/jquery.validate.min.js\"></script>\n<script src=\"~/lib/jquery-validation-unobtrusive/jquery.validate.unobtrusive.min.js\"></script>\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Views/Shared/json.cshtml",
    "content": "<pre>@ViewBag.Json</pre>"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Views/_ViewImports.cshtml",
    "content": "@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/appsettings.Development.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Debug\",\n      \"System\": \"Information\",\n      \"Microsoft\": \"Information\"\n    }\n  }\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/appsettings.json",
    "content": "{\n  \"Logging\": {\n    \"LogLevel\": {\n      \"Default\": \"Information\",\n      \"Microsoft\": \"Warning\",\n      \"Microsoft.Hosting.Lifetime\": \"Information\"\n    }\n  },\n  \"AllowedHosts\": \"*\"\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/wwwroot/css/site.css",
    "content": "﻿/* Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\nfor details on configuring this project to bundle and minify static web assets. */\n\na.navbar-brand {\n  white-space: normal;\n  text-align: center;\n  word-break: break-all;\n}\n\n/* Provide sufficient contrast against white background */\na {\n  color: #0366d6;\n}\n\n.btn-primary {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n.nav-pills .nav-link.active, .nav-pills .show > .nav-link {\n  color: #fff;\n  background-color: #1b6ec2;\n  border-color: #1861ac;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  font-size: 14px;\n}\n@media (min-width: 768px) {\n  html {\n    font-size: 16px;\n  }\n}\n\n.border-top {\n  border-top: 1px solid #e5e5e5;\n}\n.border-bottom {\n  border-bottom: 1px solid #e5e5e5;\n}\n\n.box-shadow {\n  box-shadow: 0 .25rem .75rem rgba(0, 0, 0, .05);\n}\n\nbutton.accept-policy {\n  font-size: 1rem;\n  line-height: inherit;\n}\n\n/* Sticky footer styles\n-------------------------------------------------- */\nhtml {\n  position: relative;\n  min-height: 100%;\n}\n\nbody {\n  /* Margin bottom by footer height */\n  margin-bottom: 60px;\n}\n.footer {\n  position: absolute;\n  bottom: 0;\n  width: 100%;\n  white-space: nowrap;\n  line-height: 60px; /* Vertically center the text there */\n}\n"
  },
  {
    "path": "samples/Quickstarts/Shared/src/MvcClient/wwwroot/js/site.js",
    "content": "﻿// Please see documentation at https://docs.microsoft.com/aspnet/core/client-side/bundling-and-minification\n// for details on configuring this project to bundle and minify static web assets.\n\n// Write your JavaScript code.\n"
  },
  {
    "path": "samples/SamplesGlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityModel.Client;\nglobal using Serilog;\nglobal using System.Diagnostics;\nglobal using System.Text;\nglobal using System.Text.Json;\n\n\nglobal using IdentityModel.OidcClient;\nglobal using IdentityModel.OidcClient.Browser;\nglobal using IdentityModel.AspNetCore.AccessTokenValidation;\n\n\nglobal using Microsoft.AspNetCore.Builder;\nglobal using Microsoft.AspNetCore.DataProtection;\nglobal using Microsoft.AspNetCore.Hosting;\nglobal using Microsoft.AspNetCore.Http;\nglobal using Microsoft.Extensions.DependencyInjection;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\n\nglobal using System.Net;\nglobal using System.Net.Sockets;\nglobal using System.Runtime.InteropServices;\nglobal using System.Security.Cryptography.X509Certificates;\n\n\nglobal using ILogger = Microsoft.Extensions.Logging.ILogger;\n\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Security.Claims;\nglobal using System.Runtime.Versioning;"
  },
  {
    "path": "src/AspNetIdentity/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "src/AspNetIdentity/IdentityServer8.AspNetIdentity.sln",
    "content": "\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio 15\nVisualStudioVersion = 15.0.26228.9\nMinimumVisualStudioVersion = 10.0.40219.1\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{932FA9D0-7FB4-4047-8FFD-B74907B5FA15}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.AspNetIdentity\", \"src\\IdentityServer8.AspNetIdentity.csproj\", \"{A2CDBE15-5898-4A04-94DC-133EE03A78B3}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Host\", \"host\\Host.csproj\", \"{B7FBA07C-A462-4869-AF94-5E36DFC3742D}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"migrations\", \"migrations\", \"{4BC142B6-4922-4203-82A2-F28CB6AC5004}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"SqlServer\", \"migrations\\SqlServer\\SqlServer.csproj\", \"{DD44B9E9-C32E-4F89-92C9-25444A709BBB}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tRelease|Any CPU = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{A2CDBE15-5898-4A04-94DC-133EE03A78B3}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{A2CDBE15-5898-4A04-94DC-133EE03A78B3}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{A2CDBE15-5898-4A04-94DC-133EE03A78B3}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{A2CDBE15-5898-4A04-94DC-133EE03A78B3}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{B7FBA07C-A462-4869-AF94-5E36DFC3742D}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{B7FBA07C-A462-4869-AF94-5E36DFC3742D}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{B7FBA07C-A462-4869-AF94-5E36DFC3742D}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{B7FBA07C-A462-4869-AF94-5E36DFC3742D}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{DD44B9E9-C32E-4F89-92C9-25444A709BBB}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{DD44B9E9-C32E-4F89-92C9-25444A709BBB}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{DD44B9E9-C32E-4F89-92C9-25444A709BBB}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{DD44B9E9-C32E-4F89-92C9-25444A709BBB}.Release|Any CPU.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{A2CDBE15-5898-4A04-94DC-133EE03A78B3} = {932FA9D0-7FB4-4047-8FFD-B74907B5FA15}\n\t\t{B7FBA07C-A462-4869-AF94-5E36DFC3742D} = {932FA9D0-7FB4-4047-8FFD-B74907B5FA15}\n\t\t{DD44B9E9-C32E-4F89-92C9-25444A709BBB} = {4BC142B6-4922-4203-82A2-F28CB6AC5004}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {03AF716A-120B-409D-B384-B65E7FDEFEEF}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "src/AspNetIdentity/README.md",
    "content": "# IdentityServer8.AspNetIdentity\n\nASP.NET Core Identity integration support for IdentityServer8.\n\nYou can find a detailed walk-through for ASP.NET Core Identity integration [here](https://IdentityServer8.readthedocs.io/en/latest/quickstarts/6_aspnet_identity.html).\n\n## Issues\n\nFor issues, use the [consolidated IdentityServer8 issue tracker](https://github.com/alexhiggins732/IdentityServer8/issues).\n"
  },
  {
    "path": "src/AspNetIdentity/build.cmd",
    "content": "@echo off\ndotnet run --project build -- %*"
  },
  {
    "path": "src/AspNetIdentity/build.ps1",
    "content": "$ErrorActionPreference = \"Stop\";\ndotnet run --project build -- $args"
  },
  {
    "path": "src/AspNetIdentity/build.sh",
    "content": "#!/usr/bin/env bash\nset -euo pipefail\ndotnet run --project build -- \"$@\""
  },
  {
    "path": "src/AspNetIdentity/host/Configuration/Clients.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Configuration;\n\npublic static class Clients\n{\n    public static IEnumerable<Client> Get()\n    {\n        var clients = new List<Client>();\n        \n        clients.AddRange(ClientsConsole.Get());\n        clients.AddRange(ClientsWeb.Get());\n\n        return clients;\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Configuration/ClientsConsole.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Configuration;\n\npublic static class ClientsConsole\n{\n    public static IEnumerable<Client> Get()\n    {\n        return new List<Client>\n        {\n            ///////////////////////////////////////////////////////////////\n            // Console-based Client\n            ///////////////////////////////////////////////////////////////\n\n\n            ///////////////////////////////////////////\n            // Console Client Credentials Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets = {new Secret(\"secret\".Sha256())},\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\", IdentityServerConstants.LocalApi.ScopeName}\n            },\n            \n            ///////////////////////////////////////////\n            // Console Structured Scope Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"parameterized.client\",\n                ClientSecrets = {new Secret(\"secret\".Sha256())},\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"transaction\" }\n            },\n\n            ///////////////////////////////////////////\n            // X509 mTLS Client\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mtls\",\n                ClientSecrets =\n                {\n                    // new Secret(@\"CN=mtls.test, OU=ROO\\ballen@roo, O=mkcert development certificate\", \"mtls.test\")\n                    // {\n                    //     Type = SecretTypes.X509CertificateName\n                    // },\n                    new Secret(\"5D9E9B6B333CD42C99D1DE6175CC0F3EF99DDF68\", \"mtls.test\")\n                    {\n                        Type = IdentityServerConstants.SecretTypes.X509CertificateThumbprint\n                    },\n                },\n                \n                AccessTokenType = AccessTokenType.Jwt,\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" }\n            },\n\n            ///////////////////////////////////////////\n            // Console Client Credentials Flow with client JWT assertion\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client.jwt\",\n                ClientSecrets =\n                {\n                    new Secret\n                    {\n                        Type = IdentityServerConstants.SecretTypes.X509CertificateBase64,\n                        Value =\n                            \"MIIEgTCCAumgAwIBAgIQDMMu7l/umJhfEbzJMpcttzANBgkqhkiG9w0BAQsFADCBkzEeMBwGA1UEChMVbWtjZXJ0IGRldmVsb3BtZW50IENBMTQwMgYDVQQLDCtkb21pbmlja0Bkb21icDE2LmZyaXR6LmJveCAoRG9taW5pY2sgQmFpZXIpMTswOQYDVQQDDDJta2NlcnQgZG9taW5pY2tAZG9tYnAxNi5mcml0ei5ib3ggKERvbWluaWNrIEJhaWVyKTAeFw0xOTA2MDEwMDAwMDBaFw0zMDAxMDMxMjM0MDdaMHAxJzAlBgNVBAoTHm1rY2VydCBkZXZlbG9wbWVudCBjZXJ0aWZpY2F0ZTE0MDIGA1UECwwrZG9taW5pY2tAZG9tYnAxNi5mcml0ei5ib3ggKERvbWluaWNrIEJhaWVyKTEPMA0GA1UEAxMGY2xpZW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvNtpipaS8k1zA6w0Aoy8U4l+8zM4jHhhblExf3PULrMR6RauxniTki8p+P8CsZT4V8A4qo+JwsgpLIHrVQrbt9DEhHfBKzxwHqt+GoHt7byTfTtp8A/5nLhYc/5CW4HiR194gVx5+HAlvt+BriMTb1czvTf+H20dj41yUPsN7nMdyRLF+uXapQYMLYnq2BJIDq83mqGwojHk7d+N6GwoO95jlyas7KSoj8/FvfbaqkRNx0446hqPOzFHKc8er8K5VrLp6tVjh8ZJyY0F0dKgx6yWITsL54ctbj/cCyfuGjWEMbS2XXgc+x/xQMnmpfhK1qQAUn9jg5EzF9n6mQomOwIDAQABo3MwcTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUEMUlw41YsKZQVls3pEG6CrJk4O8wEQYDVR0RBAowCIIGY2xpZW50MA0GCSqGSIb3DQEBCwUAA4IBgQC0TjNY4Q3Wmw7ggamDImV6HUng3WbYGLYbbL2e3myBrjIxGd1Bi8ZyOu8qeUMIRAbZt2YsSX5S8kx0biaVg2zC+aO5eHhEWMwKB66huInXFjI4wtxZ22r+33fg1R0cLuEUePhftOWrbL0MS4YXVyn9HUMWO4WptG9PJdxNw1UbEB8nw3FkVOdAC9RGqiqalSK+E2UT/kUbTIQ1gPSdQ3nh52mre0H/T9+IRqiozJtNK/CQg4NuEV7rUXHnp7Fmigp6RIJ4TCozglspL341y0rV8M7npU1FYZC2UKNr4ed+GOO1n/sF3LbXDlPXwne99CVVn85wjDaevoR7Md0y2KwE9EggLYcViXNehx4YVv/BjfgqxW8NxiKAxP6kPOZE0XdBrZj2rmcDcGOXCzzYpcduKhFyTOpA0K5RNGC3j1KOUjPVlOtLvjASP7udBEYNfH3mgqXAgqNDOEKi2jG9LITv2IyGUsXhTAsKNJ6A6qiDBzDrvPAYDvsfabPq6tRTwjA=\"\n                    },\n                    new Secret\n                    {\n                        Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                        Value =\n                            \"{'e':'AQAB','kid':'ZzAjSnraU3bkWGnnAqLapYGpTyNfLbjbzgAPbbW2GEA','kty':'RSA','n':'wWwQFtSzeRjjerpEM5Rmqz_DsNaZ9S1Bw6UbZkDLowuuTCjBWUax0vBMMxdy6XjEEK4Oq9lKMvx9JzjmeJf1knoqSNrox3Ka0rnxXpNAz6sATvme8p9mTXyp0cX4lF4U2J54xa2_S9NF5QWvpXvBeC4GAJx7QaSw4zrUkrc6XyaAiFnLhQEwKJCwUw4NOqIuYvYp_IXhw-5Ti_icDlZS-282PcccnBeOcX7vc21pozibIdmZJKqXNsL1Ibx5Nkx1F1jLnekJAmdaACDjYRLL_6n3W4wUp19UvzB1lGtXcJKLLkqB6YDiZNu16OSiSprfmrRXvYmvD8m6Fnl5aetgKw'}\"\n                    }\n                },\n                \n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" }\n            },\n\n            ///////////////////////////////////////////\n            // Custom Grant Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client.custom\",\n                ClientSecrets = {new Secret(\"secret\".Sha256())},\n                AllowedGrantTypes = {\"custom\", \"custom.nosubject\"},\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" }\n            },\n\n            ///////////////////////////////////////////\n            // Console Resource Owner Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient\",\n                ClientSecrets = {new Secret(\"secret\".Sha256())},\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    \"custom.profile\",\n                    \"resource1.scope1\", \"resource2.scope1\"\n                }\n            },\n\n            ///////////////////////////////////////////\n            // Console Public Resource Owner Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient.public\",\n                RequireClientSecret = false,\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\", \"resource2.scope1\"\n                }\n            },\n\n            ///////////////////////////////////////////\n            // Console with PKCE Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"console.pkce\",\n                ClientName = \"Console with PKCE Sample\",\n                RequireClientSecret = false,\n                AllowedGrantTypes = GrantTypes.Code,\n                RequirePkce = true,\n                RedirectUris = {\"http://127.0.0.1\"},\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\", \"resource2.scope1\"\n                }\n            },\n            ///////////////////////////////////////////\n            // WinConsole with PKCE Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"winconsole\",\n                ClientName = \"Windows Console with PKCE Sample\",\n                RequireClientSecret = false,\n                AllowedGrantTypes = GrantTypes.Code,\n                RequirePkce = true,\n                RedirectUris = {\"sample-windows-client://callback\"},\n                RequireConsent = false,\n                AllowOfflineAccess = true,\n                AllowedIdentityTokenSigningAlgorithms = {\"ES256\"},\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\", \"resource2.scope1\"\n                }\n            },\n\n\n            ///////////////////////////////////////////\n            // Introspection Client Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient.reference\",\n                ClientSecrets = {new Secret(\"secret\".Sha256())},\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" },\n                AccessTokenType = AccessTokenType.Reference\n            },\n            \n            ///////////////////////////////////////////\n            // Device Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"device\",\n                ClientName = \"Device Flow Client\",\n\n                AllowedGrantTypes = GrantTypes.DeviceFlow,\n                RequireClientSecret = false,\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\", \"resource2.scope1\"\n                }\n            }\n        };\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Configuration/ClientsWeb.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Configuration;\n\npublic static class ClientsWeb\n{\n    static string[] allowedScopes = \n    {\n        IdentityServerConstants.StandardScopes.OpenId,\n        IdentityServerConstants.StandardScopes.Profile,\n        IdentityServerConstants.StandardScopes.Email,\n        \"resource1.scope1\", \n        \"resource2.scope1\",\n        \"transaction\"\n    };\n    \n    public static IEnumerable<Client> Get()\n    {\n        return new List<Client>\n        {\n            ///////////////////////////////////////////\n            // JS OIDC Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"js_oidc\",\n                ClientName = \"JavaScript OIDC Client\",\n                ClientUri = \"http://identityserver8.io\",\n                \n                AllowedGrantTypes = GrantTypes.Code,\n                RequireClientSecret = false,\n                \n                RedirectUris = \n                {\n                    \"https://localhost:44300/index.html\",\n                    \"https://localhost:44300/callback.html\",\n                    \"https://localhost:44300/silent.html\",\n                    \"https://localhost:44300/popup.html\"\n                },\n\n                PostLogoutRedirectUris = { \"https://localhost:44300/index.html\" },\n                AllowedCorsOrigins = { \"https://localhost:44300\" },\n\n                AllowedScopes = allowedScopes\n            },\n            \n            ///////////////////////////////////////////\n            // MVC Automatic Token Management Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mvc.tokenmanagement\",\n                \n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.Code,\n                RequirePkce = true,\n\n                AccessTokenLifetime = 75,\n\n                RedirectUris = { \"https://localhost:44301/signin-oidc\" },\n                FrontChannelLogoutUri = \"https://localhost:44301/signout-oidc\",\n                PostLogoutRedirectUris = { \"https://localhost:44301/signout-callback-oidc\" },\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes = allowedScopes\n            },\n            \n            ///////////////////////////////////////////\n            // MVC Code Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mvc.code\",\n                ClientName = \"MVC Code Flow\",\n                ClientUri = \"http://identityserver8.io\",\n\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                RequireConsent = true,\n                AllowedGrantTypes = GrantTypes.Code,\n\n                RedirectUris = { \"https://localhost:44302/signin-oidc\" },\n                FrontChannelLogoutUri = \"https://localhost:44302/signout-oidc\",\n                PostLogoutRedirectUris = { \"https://localhost:44302/signout-callback-oidc\" },\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes = allowedScopes\n            },\n            \n            ///////////////////////////////////////////\n            // MVC Hybrid Flow Sample (Back Channel logout)\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mvc.hybrid.backchannel\",\n                ClientName = \"MVC Hybrid (with BackChannel logout)\",\n                ClientUri = \"http://identityserver8.io\",\n\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.Hybrid,\n                RequirePkce = false,\n\n                RedirectUris = { \"https://localhost:44303/signin-oidc\" },\n                BackChannelLogoutUri = \"https://localhost:44303/logout\",\n                PostLogoutRedirectUris = { \"https://localhost:44303/signout-callback-oidc\" },\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes = allowedScopes\n            }\n        };\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Configuration/Resources.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Configuration;\n\npublic class Resources\n{\n    // identity resources represent identity data about a user that can be requested via the scope parameter (OpenID Connect)\n    public static readonly IEnumerable<IdentityResource> IdentityResources =\n        new[]\n        {\n            // some standard scopes from the OIDC spec\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n            new IdentityResources.Email(),\n\n            // custom identity resource with some consolidated claims\n            new IdentityResource(\"custom.profile\", new[] { JwtClaimTypes.Name, JwtClaimTypes.Email, \"location\" })\n        };\n\n    // API scopes represent values that describe scope of access and can be requested by the scope parameter (OAuth)\n    public static readonly IEnumerable<ApiScope> ApiScopes =\n        new[]\n        {\n            // local API scope\n            new ApiScope(LocalApi.ScopeName),\n\n            // resource specific scopes\n            new ApiScope(\"resource1.scope1\"),\n            new ApiScope(\"resource2.scope1\"), \n            \n            // a scope without resource association\n            new ApiScope(\"scope3\"),\n            \n            // a scope shared by multiple resources\n            new ApiScope(\"shared.scope\"),\n\n            // a parameterized scope\n            new ApiScope(\"transaction\", \"Transaction\")\n            {\n                Description = \"Some Transaction\"\n            }\n        };\n\n    // API resources are more formal representation of a resource with processing rules and their scopes (if any)\n    public static readonly IEnumerable<ApiResource> ApiResources = \n        new[]\n        {\n            new ApiResource(\"resource1\", \"Resource 1\")\n            {\n                ApiSecrets = { new Secret(\"secret\".Sha256()) },\n\n                Scopes = { \"resource1.scope1\", \"shared.scope\" }\n            },\n            \n            // expanded version if more control is needed\n            new ApiResource(\"resource2\", \"Resource 2\")\n            {\n                ApiSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                // additional claims to put into access token\n                UserClaims =\n                {\n                    JwtClaimTypes.Name,\n                    JwtClaimTypes.Email\n                },\n\n                Scopes = { \"resource2.scope1\", \"shared.scope\" }\n            }\n        };\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Data/ApplicationDbContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Data;\n\npublic class ApplicationDbContext : IdentityDbContext<ApplicationUser>\n{\n    public ApplicationDbContext(DbContextOptions<ApplicationDbContext> options)\n        : base(options)\n    {\n    }\n\n    protected override void OnModelCreating(ModelBuilder builder)\n    {\n        base.OnModelCreating(builder);\n        // Customize the ASP.NET Identity model and override the defaults if needed.\n        // For example, you can rename the ASP.NET Identity table names and more.\n        // Add your customizations after calling base.OnModelCreating(builder);\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.Configuration;\nglobal using IdentityServer8.Events;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Test;\nglobal using IdentityServer8.Validation;\nglobal using IdentityServerHost.Configuration;\nglobal using IdentityServerHost.Data;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Identity;\nglobal using Microsoft.AspNetCore.Identity.EntityFrameworkCore;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.AspNetCore.Mvc.Filters;\nglobal using Microsoft.Extensions.DependencyInjection;\nglobal using Microsoft.EntityFrameworkCore;\nglobal using Microsoft.Extensions.Options;\nglobal using Newtonsoft.Json;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\nglobal using System.ComponentModel;\nglobal using System.ComponentModel.DataAnnotations;\nglobal using System.Diagnostics;\nglobal using System.Security.Claims;\nglobal using System.Text;\nglobal using static IdentityServer8.IdentityServerConstants;\nglobal using ILogger = Microsoft.Extensions.Logging.ILogger;\nglobal using ClaimValueTypes = System.Security.Claims.ClaimValueTypes;\n"
  },
  {
    "path": "src/AspNetIdentity/host/Host.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n  <ItemGroup>\n    <PackageReference Include=\"Serilog\" />\n    <PackageReference Include=\"Serilog.AspNetCore\" />\n    <PackageReference Include=\"Serilog.Sinks.Console\" />\n    <PackageReference Include=\"Serilog.Sinks.File\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.AspNetCore.Identity.EntityFrameworkCore\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.SqlServer\" />\n    <PackageReference Include=\"System.Security.Principal.Windows\" />\n    \n    <ProjectReference Include=\"..\\src\\IdentityServer8.AspNetIdentity.csproj\" />\n  </ItemGroup>\n\n</Project>"
  },
  {
    "path": "src/AspNetIdentity/host/Models/AccountViewModels/ExternalLoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.AccountViewModels;\n\npublic class ExternalLoginViewModel\n{\n    [Required]\n    [EmailAddress]\n    public string Email { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/AccountViewModels/ForgotPasswordViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.AccountViewModels;\n\npublic class ForgotPasswordViewModel\n{\n    [Required]\n    [EmailAddress]\n    public string Email { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/AccountViewModels/LoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.AccountViewModels;\n\npublic class LoginViewModel\n{\n    [Required]\n    [EmailAddress]\n    public string Email { get; set; }\n\n    [Required]\n    [DataType(DataType.Password)]\n    public string Password { get; set; }\n\n    [Display(Name = \"Remember me?\")]\n    public bool RememberMe { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/AccountViewModels/LoginWith2faViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.AccountViewModels;\n\npublic class LoginWith2faViewModel\n{\n    [Required]\n    [StringLength(7, ErrorMessage = \"The {0} must be at least {2} and at max {1} characters long.\", MinimumLength = 6)]\n    [DataType(DataType.Text)]\n    [Display(Name = \"Authenticator code\")]\n    public string TwoFactorCode { get; set; }\n\n    [Display(Name = \"Remember this machine\")]\n    public bool RememberMachine { get; set; }\n\n    public bool RememberMe { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/AccountViewModels/LoginWithRecoveryCodeViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.AccountViewModels;\n\npublic class LoginWithRecoveryCodeViewModel\n{\n        [Required]\n        [DataType(DataType.Text)]\n        [Display(Name = \"Recovery Code\")]\n        public string RecoveryCode { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/AccountViewModels/RegisterViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.AccountViewModels;\n\npublic class RegisterViewModel\n{\n    [Required]\n    [EmailAddress]\n    [Display(Name = \"Email\")]\n    public string Email { get; set; }\n\n    [Required]\n    [StringLength(100, ErrorMessage = \"The {0} must be at least {2} and at max {1} characters long.\", MinimumLength = 6)]\n    [DataType(DataType.Password)]\n    [Display(Name = \"Password\")]\n    public string Password { get; set; }\n\n    [DataType(DataType.Password)]\n    [Display(Name = \"Confirm password\")]\n    [Compare(\"Password\", ErrorMessage = \"The password and confirmation password do not match.\")]\n    public string ConfirmPassword { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/AccountViewModels/ResetPasswordViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.AccountViewModels;\n\npublic class ResetPasswordViewModel\n{\n    [Required]\n    [EmailAddress]\n    public string Email { get; set; }\n\n    [Required]\n    [StringLength(100, ErrorMessage = \"The {0} must be at least {2} and at max {1} characters long.\", MinimumLength = 6)]\n    [DataType(DataType.Password)]\n    public string Password { get; set; }\n\n    [DataType(DataType.Password)]\n    [Display(Name = \"Confirm password\")]\n    [Compare(\"Password\", ErrorMessage = \"The password and confirmation password do not match.\")]\n    public string ConfirmPassword { get; set; }\n\n    public string Code { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/ApplicationUser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n// Add profile data for application users by adding properties to the ApplicationUser class\npublic class ApplicationUser : IdentityUser\n{\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/ManageViewModels/ChangePasswordViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.ManageViewModels;\n\npublic class ChangePasswordViewModel\n{\n    [Required]\n    [DataType(DataType.Password)]\n    [Display(Name = \"Current password\")]\n    public string OldPassword { get; set; }\n\n    [Required]\n    [StringLength(100, ErrorMessage = \"The {0} must be at least {2} and at max {1} characters long.\", MinimumLength = 6)]\n    [DataType(DataType.Password)]\n    [Display(Name = \"New password\")]\n    public string NewPassword { get; set; }\n\n    [DataType(DataType.Password)]\n    [Display(Name = \"Confirm new password\")]\n    [Compare(\"NewPassword\", ErrorMessage = \"The new password and confirmation password do not match.\")]\n    public string ConfirmPassword { get; set; }\n\n    public string StatusMessage { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/ManageViewModels/EnableAuthenticatorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.ManageViewModels;\n\npublic class EnableAuthenticatorViewModel\n{\n        [Required]\n        [StringLength(7, ErrorMessage = \"The {0} must be at least {2} and at max {1} characters long.\", MinimumLength = 6)]\n        [DataType(DataType.Text)]\n        [Display(Name = \"Verification Code\")]\n        public string Code { get; set; }\n\n        [ReadOnly(true)]\n        public string SharedKey { get; set; }\n\n        public string AuthenticatorUri { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/ManageViewModels/ExternalLoginsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.ManageViewModels;\n\npublic class ExternalLoginsViewModel\n{\n    public IList<UserLoginInfo> CurrentLogins { get; set; }\n\n    public IList<AuthenticationScheme> OtherLogins { get; set; }\n\n    public bool ShowRemoveButton { get; set; }\n\n    public string StatusMessage { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/ManageViewModels/GenerateRecoveryCodesViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.ManageViewModels;\n\npublic class GenerateRecoveryCodesViewModel\n{\n    public string[] RecoveryCodes { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/ManageViewModels/IndexViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.ManageViewModels;\n\npublic class IndexViewModel\n{\n    public string Username { get; set; }\n\n    public bool IsEmailConfirmed { get; set; }\n\n    [Required]\n    [EmailAddress]\n    public string Email { get; set; }\n\n    [Phone]\n    [Display(Name = \"Phone number\")]\n    public string PhoneNumber { get; set; }\n\n    public string StatusMessage { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/ManageViewModels/RemoveLoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.ManageViewModels;\n\npublic class RemoveLoginViewModel\n{\n    public string LoginProvider { get; set; }\n    public string ProviderKey { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/ManageViewModels/SetPasswordViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.ManageViewModels;\n\npublic class SetPasswordViewModel\n{\n    [Required]\n    [StringLength(100, ErrorMessage = \"The {0} must be at least {2} and at max {1} characters long.\", MinimumLength = 6)]\n    [DataType(DataType.Password)]\n    [Display(Name = \"New password\")]\n    public string NewPassword { get; set; }\n\n    [DataType(DataType.Password)]\n    [Display(Name = \"Confirm new password\")]\n    [Compare(\"NewPassword\", ErrorMessage = \"The new password and confirmation password do not match.\")]\n    public string ConfirmPassword { get; set; }\n\n    public string StatusMessage { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Models/ManageViewModels/TwoFactorAuthenticationViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models.ManageViewModels;\n\npublic class TwoFactorAuthenticationViewModel\n{\n    public bool HasAuthenticator { get; set; }\n\n    public int RecoveryCodesLeft { get; set; }\n\n    public bool Is2faEnabled { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost;\n\npublic class Program\n{\n    public static int Main(string[] args)\n    {\n        Console.Title = \"IdentityServer8.AspNetIdentity\";\n        Activity.DefaultIdFormat = ActivityIdFormat.W3C;\n\n        Log.Logger = new LoggerConfiguration()\n            .MinimumLevel.Debug()\n            .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n            .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n            .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n            .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n            .Enrich.FromLogContext()\n            //.WriteTo.File(@\"IdentityServer8_log.txt\")\n            // uncomment to write to Azure diagnostics stream\n            //.WriteTo.File(\n            //    @\"D:\\home\\LogFiles\\Application\\identityserver.txt\",\n            //    fileSizeLimitBytes: 1_000_000,\n            //    rollOnFileSizeLimit: true,\n            //    shared: true,\n            //    flushToDiskInterval: TimeSpan.FromSeconds(1))\n            .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n            .CreateLogger();\n\n        try\n        {\n            Log.Information(\"Starting host...\");\n            CreateHostBuilder(args).Build().Run();\n            return 0;\n        }\n        catch (Exception ex)\n        {\n            Log.Fatal(ex, \"Host terminated unexpectedly.\");\n            return 1;\n        }\n        finally\n        {\n            Log.CloseAndFlush();\n        }\n    }\n\n    public static IHostBuilder CreateHostBuilder(string[] args) =>\n        Host.CreateDefaultBuilder(args)\n            .UseSerilog()\n            .ConfigureWebHostDefaults(webBuilder =>\n            {\n                webBuilder.UseStartup<Startup>();\n            });\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": true,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:5000\",\n      \"sslPort\": 44334\n    }\n  },\n  \"profiles\": {\n    \"Host\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001\"\n    }\n  }\n}"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Account/AccountController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class AccountController : Controller\n{\n    private readonly UserManager<ApplicationUser> _userManager;\n    private readonly SignInManager<ApplicationUser> _signInManager;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly IAuthenticationSchemeProvider _schemeProvider;\n    private readonly IEventService _events;\n\n    public AccountController(\n        UserManager<ApplicationUser> userManager,\n        SignInManager<ApplicationUser> signInManager,\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IAuthenticationSchemeProvider schemeProvider,\n        IEventService events)\n    {\n        _userManager = userManager;\n        _signInManager = signInManager;\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _schemeProvider = schemeProvider;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Entry point into the login workflow\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Login(string returnUrl)\n    {\n        // build a model so we know what to show on the login page\n        var vm = await BuildLoginViewModelAsync(returnUrl);\n\n        if (vm.IsExternalLoginOnly)\n        {\n            // we only have one option for logging in and it's an external provider\n            return returnUrl.IsAllowedRedirect() ? RedirectToAction(\"Challenge\", \"External\", new { scheme = vm.ExternalLoginScheme, returnUrl = returnUrl.SanitizeForRedirect() }) : Forbid();\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Login(LoginInputModel model)\n    {\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n        // check if we are in the context of an authorization request\n        if (ModelState.IsValid)\n        {\n            var result = await _signInManager.PasswordSignInAsync(model.Username, model.Password, model.RememberLogin, lockoutOnFailure: true);\n            if (result.Succeeded)\n            {\n                var user = await _userManager.FindByNameAsync(model.Username);\n                await _events.RaiseAsync(new UserLoginSuccessEvent(user.UserName, user.Id, user.UserName, clientId: context?.Client.ClientId));\n\n                if (context != null)\n                {\n                    if (context.IsNativeClient())\n                    {\n                        // The client is native, so this change in how to\n                        // return the response is for better UX for the end user.\n                        return this.LoadingPage(\"Redirect\", model.ReturnUrl);\n                    }\n\n                    // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n\n                // request for a local page\n                if (Url.IsLocalUrl(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n                else if (string.IsNullOrEmpty(model.ReturnUrl))\n                {\n                    return Redirect(\"~/\");\n                }\n                else\n                {\n                    // user might have clicked on a malicious link - should be logged\n                    throw new Exception(\"invalid return URL\");\n                }\n            }\n\n            await _events.RaiseAsync(new UserLoginFailureEvent(model.Username, \"invalid credentials\", clientId: context?.Client.ClientId));\n            ModelState.AddModelError(string.Empty, AccountOptions.InvalidCredentialsErrorMessage);\n        }\n\n        // something went wrong, show form with error\n        var vm = await BuildLoginViewModelAsync(model);\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> LoginCancel(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (context != null)\n        {\n            // if the user cancels, send a result back into IdentityServer as if they \n            // denied the consent (even if this client does not require consent).\n            // this will send back an access denied OIDC error response to the client.\n            await _interaction.DenyAuthorizationAsync(context, AuthorizationError.AccessDenied);\n\n            // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl) : Forbid();\n            }\n\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n        }\n        else\n        {\n            // since we don't have a valid context, then we just go back to the home page\n            return Redirect(\"~/\");\n        }\n\n    }\n\n\n    /// <summary>\n    /// Show logout page\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Logout(string logoutId)\n    {\n        // build a model so the logout page knows what to display\n        var vm = await BuildLogoutViewModelAsync(logoutId);\n\n        if (vm.ShowLogoutPrompt == false)\n        {\n            // if the request for logout was properly authenticated from IdentityServer, then\n            // we don't need to show the prompt and can just log the user out directly.\n            return await Logout(vm);\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle logout page postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Logout(LogoutInputModel model)\n    {\n        // build a model so the logged out page knows what to display\n        var vm = await BuildLoggedOutViewModelAsync(model.LogoutId);\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            // delete local authentication cookie\n            await _signInManager.SignOutAsync();\n\n            // raise the logout event\n            await _events.RaiseAsync(new UserLogoutSuccessEvent(User.GetSubjectId(), User.GetDisplayName()));\n        }\n\n        // check if we need to trigger sign-out at an upstream identity provider\n        if (vm.TriggerExternalSignout)\n        {\n            // build a return URL so the upstream provider will redirect back\n            // to us after the user has logged out. this allows us to then\n            // complete our single sign-out processing.\n            string url = Url.Action(\"Logout\", new { logoutId = vm.LogoutId });\n\n            // this triggers a redirect to the external provider for sign-out\n            return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);\n        }\n\n        return View(\"LoggedOut\", vm);\n    }\n\n    [HttpGet]\n    public IActionResult AccessDenied()\n    {\n        return View();\n    }\n\n\n    /*****************************************/\n    /* helper APIs for the AccountController */\n    /*****************************************/\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(string returnUrl)\n    {\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (context?.IdP != null && await _schemeProvider.GetSchemeAsync(context.IdP) != null)\n        {\n            var local = context.IdP == IdentityServer8.IdentityServerConstants.LocalIdentityProvider;\n\n            // this is meant to short circuit the UI and only trigger the one external IdP\n            var vm = new LoginViewModel\n            {\n                EnableLocalLogin = local,\n                ReturnUrl = returnUrl,\n                Username = context?.LoginHint,\n            };\n\n            if (!local)\n            {\n                vm.ExternalProviders = new[] { new ExternalProvider { AuthenticationScheme = context.IdP } };\n            }\n\n            return vm;\n        }\n\n        var schemes = await _schemeProvider.GetAllSchemesAsync();\n\n        var providers = schemes\n            .Where(x => x.DisplayName != null)\n            .Select(x => new ExternalProvider\n            {\n                DisplayName = x.DisplayName ?? x.Name,\n                AuthenticationScheme = x.Name\n            }).ToList();\n\n        var allowLocal = true;\n        if (context?.Client.ClientId != null)\n        {\n            var client = await _clientStore.FindEnabledClientByIdAsync(context.Client.ClientId);\n            if (client != null)\n            {\n                allowLocal = client.EnableLocalLogin;\n\n                if (client.IdentityProviderRestrictions != null && client.IdentityProviderRestrictions.Any())\n                {\n                    providers = providers.Where(provider => client.IdentityProviderRestrictions.Contains(provider.AuthenticationScheme)).ToList();\n                }\n            }\n        }\n\n        return new LoginViewModel\n        {\n            AllowRememberLogin = AccountOptions.AllowRememberLogin,\n            EnableLocalLogin = allowLocal && AccountOptions.AllowLocalLogin,\n            ReturnUrl = returnUrl,\n            Username = context?.LoginHint,\n            ExternalProviders = providers.ToArray()\n        };\n    }\n\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(LoginInputModel model)\n    {\n        var vm = await BuildLoginViewModelAsync(model.ReturnUrl);\n        vm.Username = model.Username;\n        vm.RememberLogin = model.RememberLogin;\n        return vm;\n    }\n\n    private async Task<LogoutViewModel> BuildLogoutViewModelAsync(string logoutId)\n    {\n        var vm = new LogoutViewModel { LogoutId = logoutId, ShowLogoutPrompt = AccountOptions.ShowLogoutPrompt };\n\n        if (User?.Identity.IsAuthenticated != true)\n        {\n            // if the user is not authenticated, then just show logged out page\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        var context = await _interaction.GetLogoutContextAsync(logoutId);\n        if (context?.ShowSignoutPrompt == false)\n        {\n            // it's safe to automatically sign-out\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        // show the logout prompt. this prevents attacks where the user\n        // is automatically signed out by another malicious web page.\n        return vm;\n    }\n\n    private async Task<LoggedOutViewModel> BuildLoggedOutViewModelAsync(string logoutId)\n    {\n        // get context information (client name, post logout redirect URI and iframe for federated signout)\n        var logout = await _interaction.GetLogoutContextAsync(logoutId);\n\n        var vm = new LoggedOutViewModel\n        {\n            AutomaticRedirectAfterSignOut = AccountOptions.AutomaticRedirectAfterSignOut,\n            PostLogoutRedirectUri = logout?.PostLogoutRedirectUri,\n            ClientName = string.IsNullOrEmpty(logout?.ClientName) ? logout?.ClientId : logout?.ClientName,\n            SignOutIframeUrl = logout?.SignOutIFrameUrl,\n            LogoutId = logoutId\n        };\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            var idp = User.FindFirst(JwtClaimTypes.IdentityProvider)?.Value;\n            if (idp != null && idp != IdentityServer8.IdentityServerConstants.LocalIdentityProvider)\n            {\n                var providerSupportsSignout = await HttpContext.GetSchemeSupportsSignOutAsync(idp);\n                if (providerSupportsSignout)\n                {\n                    if (vm.LogoutId == null)\n                    {\n                        // if there's no current logout context, we need to create one\n                        // this captures necessary info from the current logged in user\n                        // before we signout and redirect away to the external IdP for signout\n                        vm.LogoutId = await _interaction.CreateLogoutContextAsync();\n                    }\n\n                    vm.ExternalAuthenticationScheme = idp;\n                }\n            }\n        }\n\n        return vm;\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Account/AccountOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class AccountOptions\n{\n    public static bool AllowLocalLogin = true;\n    public static bool AllowRememberLogin = true;\n    public static TimeSpan RememberMeLoginDuration = TimeSpan.FromDays(30);\n\n    public static bool ShowLogoutPrompt = true;\n    public static bool AutomaticRedirectAfterSignOut = false;\n\n    public static string InvalidCredentialsErrorMessage = \"Invalid username or password\";\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Account/ExternalController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class ExternalController : Controller\n{\n    private readonly UserManager<ApplicationUser> _userManager;\n    private readonly SignInManager<ApplicationUser> _signInManager;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly IEventService _events;\n    private readonly ILogger<ExternalController> _logger;\n\n    public ExternalController(\n        UserManager<ApplicationUser> userManager,\n        SignInManager<ApplicationUser> signInManager,\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IEventService events,\n        ILogger<ExternalController> logger)\n    {\n        _userManager = userManager;\n        _signInManager = signInManager;\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// initiate roundtrip to external authentication provider\n    /// </summary>\n    [HttpGet]\n    public IActionResult Challenge(string scheme, string returnUrl)\n    {\n        if (string.IsNullOrEmpty(returnUrl)) returnUrl = \"~/\";\n\n        // validate returnUrl - either it is a valid OIDC URL or back to a local page\n        if (Url.IsLocalUrl(returnUrl) == false && _interaction.IsValidReturnUrl(returnUrl) == false)\n        {\n            // user might have clicked on a malicious link - should be logged\n            throw new Exception(\"invalid return URL\");\n        }\n        \n        // start challenge and roundtrip the return URL and scheme \n        var props = new AuthenticationProperties\n        {\n            RedirectUri = Url.Action(nameof(Callback)), \n            Items =\n            {\n                { \"returnUrl\", returnUrl }, \n                { \"scheme\", scheme },\n            }\n        };\n\n        return Challenge(props, scheme);\n        \n    }\n\n    /// <summary>\n    /// Post processing of external authentication\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Callback()\n    {\n        // read external identity from the temporary cookie\n        var result = await HttpContext.AuthenticateAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n        if (result?.Succeeded != true)\n        {\n            throw new Exception(\"External authentication error\");\n        }\n\n        if (_logger.IsEnabled(LogLevel.Debug))\n        {\n            var externalClaims = result.Principal.Claims.Select(c => $\"{c.Type}: {c.Value}\");\n            _logger.LogDebug(\"External claims: {@claims}\", externalClaims);\n        }\n\n        // lookup our user and external provider info\n        var (user, provider, providerUserId, claims) = await FindUserFromExternalProviderAsync(result);\n        if (user == null)\n        {\n            // this might be where you might initiate a custom workflow for user registration\n            // in this sample we don't show how that would be done, as our sample implementation\n            // simply auto-provisions new external user\n            user = await AutoProvisionUserAsync(provider, providerUserId, claims);\n        }\n\n        // this allows us to collect any additional claims or properties\n        // for the specific protocols used and store them in the local auth cookie.\n        // this is typically used to store data needed for signout from those protocols.\n        var additionalLocalClaims = new List<Claim>();\n        var localSignInProps = new AuthenticationProperties();\n        ProcessLoginCallback(result, additionalLocalClaims, localSignInProps);\n        \n        // issue authentication cookie for user\n        // we must issue the cookie maually, and can't use the SignInManager because\n        // it doesn't expose an API to issue additional claims from the login workflow\n        var principal = await _signInManager.CreateUserPrincipalAsync(user);\n        additionalLocalClaims.AddRange(principal.Claims);\n        var name = principal.FindFirst(JwtClaimTypes.Name)?.Value ?? user.Id;\n        \n        var isuser = new IdentityServerUser(user.Id)\n        {\n            DisplayName = name,\n            IdentityProvider = provider,\n            AdditionalClaims = additionalLocalClaims\n        };\n\n        await HttpContext.SignInAsync(isuser, localSignInProps);\n\n        // delete temporary cookie used during external authentication\n        await HttpContext.SignOutAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n        // retrieve return URL\n        var returnUrl = result.Properties.Items[\"returnUrl\"] ?? \"~/\";\n\n        // check if external login is in the context of an OIDC request\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        await _events.RaiseAsync(new UserLoginSuccessEvent(provider, providerUserId, user.Id, name, true, context?.Client.ClientId));\n\n        if (context != null)\n        {\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", returnUrl);\n            }\n        }\n\n        return Redirect(returnUrl);\n    }\n\n    private async Task<(ApplicationUser user, string provider, string providerUserId, IEnumerable<Claim> claims)>\n        FindUserFromExternalProviderAsync(AuthenticateResult result)\n    {\n        var externalUser = result.Principal;\n\n        // try to determine the unique id of the external user (issued by the provider)\n        // the most common claim type for that are the sub claim and the NameIdentifier\n        // depending on the external provider, some other claim type might be used\n        var userIdClaim = externalUser.FindFirst(JwtClaimTypes.Subject) ??\n                          externalUser.FindFirst(ClaimTypes.NameIdentifier) ??\n                          throw new Exception(\"Unknown userid\");\n\n        // remove the user id claim so we don't include it as an extra claim if/when we provision the user\n        var claims = externalUser.Claims.ToList();\n        claims.Remove(userIdClaim);\n\n        var provider = result.Properties.Items[\"scheme\"];\n        var providerUserId = userIdClaim.Value;\n\n        // find external user\n        var user = await _userManager.FindByLoginAsync(provider, providerUserId);\n\n        return (user, provider, providerUserId, claims);\n    }\n\n    private async Task<ApplicationUser> AutoProvisionUserAsync(string provider, string providerUserId, IEnumerable<Claim> claims)\n    {\n        // create a list of claims that we want to transfer into our store\n        var filtered = new List<Claim>();\n\n        // user's display name\n        var name = claims.FirstOrDefault(x => x.Type == JwtClaimTypes.Name)?.Value ??\n            claims.FirstOrDefault(x => x.Type == ClaimTypes.Name)?.Value;\n        if (name != null)\n        {\n            filtered.Add(new Claim(JwtClaimTypes.Name, name));\n        }\n        else\n        {\n            var first = claims.FirstOrDefault(x => x.Type == JwtClaimTypes.GivenName)?.Value ??\n                claims.FirstOrDefault(x => x.Type == ClaimTypes.GivenName)?.Value;\n            var last = claims.FirstOrDefault(x => x.Type == JwtClaimTypes.FamilyName)?.Value ??\n                claims.FirstOrDefault(x => x.Type == ClaimTypes.Surname)?.Value;\n            if (first != null && last != null)\n            {\n                filtered.Add(new Claim(JwtClaimTypes.Name, first + \" \" + last));\n            }\n            else if (first != null)\n            {\n                filtered.Add(new Claim(JwtClaimTypes.Name, first));\n            }\n            else if (last != null)\n            {\n                filtered.Add(new Claim(JwtClaimTypes.Name, last));\n            }\n        }\n\n        // email\n        var email = claims.FirstOrDefault(x => x.Type == JwtClaimTypes.Email)?.Value ??\n           claims.FirstOrDefault(x => x.Type == ClaimTypes.Email)?.Value;\n        if (email != null)\n        {\n            filtered.Add(new Claim(JwtClaimTypes.Email, email));\n        }\n\n        var user = new ApplicationUser\n        {\n            UserName = Guid.NewGuid().ToString(),\n        };\n        var identityResult = await _userManager.CreateAsync(user);\n        if (!identityResult.Succeeded) throw new Exception(identityResult.Errors.First().Description);\n\n        if (filtered.Any())\n        {\n            identityResult = await _userManager.AddClaimsAsync(user, filtered);\n            if (!identityResult.Succeeded) throw new Exception(identityResult.Errors.First().Description);\n        }\n\n        identityResult = await _userManager.AddLoginAsync(user, new UserLoginInfo(provider, providerUserId, provider));\n        if (!identityResult.Succeeded) throw new Exception(identityResult.Errors.First().Description);\n\n        return user;\n    }\n\n    // if the external login is OIDC-based, there are certain things we need to preserve to make logout work\n    // this will be different for WS-Fed, SAML2p or other protocols\n    private void ProcessLoginCallback(AuthenticateResult externalResult, List<Claim> localClaims, AuthenticationProperties localSignInProps)\n    {\n        // if the external system sent a session id claim, copy it over\n        // so we can use it for single sign-out\n        var sid = externalResult.Principal.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.SessionId);\n        if (sid != null)\n        {\n            localClaims.Add(new Claim(JwtClaimTypes.SessionId, sid.Value));\n        }\n\n        // if the external provider issued an id_token, we'll keep it for signout\n        var idToken = externalResult.Properties.GetTokenValue(\"id_token\");\n        if (idToken != null)\n        {\n            localSignInProps.StoreTokens(new[] { new AuthenticationToken { Name = \"id_token\", Value = idToken } });\n        }\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Account/ExternalProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ExternalProvider\n{\n    public string DisplayName { get; set; }\n    public string AuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Account/LoggedOutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoggedOutViewModel\n{\n    public string PostLogoutRedirectUri { get; set; }\n    public string ClientName { get; set; }\n    public string SignOutIframeUrl { get; set; }\n\n    public bool AutomaticRedirectAfterSignOut { get; set; }\n\n    public string LogoutId { get; set; }\n    public bool TriggerExternalSignout => ExternalAuthenticationScheme != null;\n    public string ExternalAuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Account/LoginInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginInputModel\n{\n    [Required]\n    public string Username { get; set; }\n    [Required]\n    public string Password { get; set; }\n    public bool RememberLogin { get; set; }\n    public string ReturnUrl { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Account/LoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginViewModel : LoginInputModel\n{\n    public bool AllowRememberLogin { get; set; } = true;\n    public bool EnableLocalLogin { get; set; } = true;\n\n    public IEnumerable<ExternalProvider> ExternalProviders { get; set; } = Enumerable.Empty<ExternalProvider>();\n    public IEnumerable<ExternalProvider> VisibleExternalProviders => ExternalProviders.Where(x => !String.IsNullOrWhiteSpace(x.DisplayName));\n\n    public bool IsExternalLoginOnly => EnableLocalLogin == false && ExternalProviders?.Count() == 1;\n    public string ExternalLoginScheme => IsExternalLoginOnly ? ExternalProviders?.SingleOrDefault()?.AuthenticationScheme : null;\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Account/LogoutInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutInputModel\n{\n    public string LogoutId { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Account/LogoutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutViewModel : LogoutInputModel\n{\n    public bool ShowLogoutPrompt { get; set; } = true;\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Account/RedirectViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class RedirectViewModel\n{\n    public string RedirectUrl { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Consent/ConsentController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This controller processes the consent UI\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class ConsentController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly ILogger<ConsentController> _logger;\n\n    public ConsentController(\n        IIdentityServerInteractionService interaction,\n        IEventService events,\n        ILogger<ConsentController> logger)\n    {\n        _interaction = interaction;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Shows the consent screen\n    /// </summary>\n    /// <param name=\"returnUrl\"></param>\n    /// <returns></returns>\n    [HttpGet]\n    public async Task<IActionResult> Index(string returnUrl)\n    {\n        var vm = await BuildViewModelAsync(returnUrl);\n        if (vm != null)\n        {\n            return View(\"Index\", vm);\n        }\n\n        return View(\"Error\");\n    }\n\n    /// <summary>\n    /// Handles the consent screen postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Index(ConsentInputModel model)\n    {\n        var result = await ProcessConsent(model);\n\n        if (result.IsRedirect)\n        {\n            var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n            if (context?.IsNativeClient() == true)\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", result.RedirectUri);\n            }\n            return result.RedirectUri.IsAllowedRedirect() ? Redirect(result.RedirectUri.SanitizeForRedirect()) : Forbid();\n\n        }\n\n        if (result.HasValidationError)\n        {\n            ModelState.AddModelError(string.Empty, result.ValidationError);\n        }\n\n        if (result.ShowView)\n        {\n            return View(\"Index\", result.ViewModel);\n        }\n\n        return View(\"Error\");\n    }\n\n    /*****************************************/\n    /* helper APIs for the ConsentController */\n    /*****************************************/\n    private async Task<ProcessConsentResult> ProcessConsent(ConsentInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        // validate return url is still valid\n        var request = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model?.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model?.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.GrantConsentAsync(request, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.ReturnUrl, model);\n        }\n\n        return result;\n    }\n\n    private async Task<ConsentViewModel> BuildViewModelAsync(string returnUrl, ConsentInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (request != null)\n        {\n            return CreateConsentViewModel(model, returnUrl, request);\n        }\n        else\n        {\n            _logger.LogError(\"No consent request matching request: {0}\", Ioc.Sanitizer.Log.Sanitize(returnUrl));\n        }\n\n        return null;\n    }\n\n    private ConsentViewModel CreateConsentViewModel(\n        ConsentInputModel model, string returnUrl,\n        AuthorizationRequest request)\n    {\n        var vm = new ConsentViewModel\n        {\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n            Description = model?.Description,\n\n            ReturnUrl = returnUrl,\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach (var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        var displayName = apiScope.DisplayName ?? apiScope.Name;\n        if (!String.IsNullOrWhiteSpace(parsedScopeValue.ParsedParameter))\n        {\n            displayName += \":\" + parsedScopeValue.ParsedParameter;\n        }\n\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            DisplayName = displayName,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Consent/ConsentInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentInputModel\n{\n    public string Button { get; set; }\n    public IEnumerable<string> ScopesConsented { get; set; }\n    public bool RememberConsent { get; set; }\n    public string ReturnUrl { get; set; }\n    public string Description { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Consent/ConsentOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentOptions\n{\n    public static bool EnableOfflineAccess = true;\n    public static string OfflineAccessDisplayName = \"Offline Access\";\n    public static string OfflineAccessDescription = \"Access to your applications and resources, even when you are offline\";\n\n    public static readonly string MustChooseOneErrorMessage = \"You must pick at least one permission\";\n    public static readonly string InvalidSelectionErrorMessage = \"Invalid selection\";\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Consent/ConsentViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentViewModel : ConsentInputModel\n{\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public bool AllowRememberConsent { get; set; }\n\n    public IEnumerable<ScopeViewModel> IdentityScopes { get; set; }\n    public IEnumerable<ScopeViewModel> ApiScopes { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Consent/ProcessConsentResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ProcessConsentResult\n{\n    public bool IsRedirect => RedirectUri != null;\n    public string RedirectUri { get; set; }\n    public Client Client { get; set; }\n\n    public bool ShowView => ViewModel != null;\n    public ConsentViewModel ViewModel { get; set; }\n\n    public bool HasValidationError => ValidationError != null;\n    public string ValidationError { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Consent/ScopeViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ScopeViewModel\n{\n    public string Value { get; set; }\n    public string DisplayName { get; set; }\n    public string Description { get; set; }\n    public bool Emphasize { get; set; }\n    public bool Required { get; set; }\n    public bool Checked { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Device/DeviceAuthorizationInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationInputModel : ConsentInputModel\n{\n    public string UserCode { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Device/DeviceAuthorizationViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationViewModel : ConsentViewModel\n{\n    public string UserCode { get; set; }\n    public bool ConfirmUserCode { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Device/DeviceController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[Authorize]\n[SecurityHeaders]\npublic class DeviceController : Controller\n{\n    private readonly IDeviceFlowInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly IOptions<IdentityServerOptions> _options;\n    private readonly ILogger<DeviceController> _logger;\n\n    public DeviceController(\n        IDeviceFlowInteractionService interaction,\n        IEventService eventService,\n        IOptions<IdentityServerOptions> options,\n        ILogger<DeviceController> logger)\n    {\n        _interaction = interaction;\n        _events = eventService;\n        _options = options;\n        _logger = logger;\n    }\n\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        string userCodeParamName = _options.Value.UserInteraction.DeviceVerificationUserCodeParameter;\n        string userCode = Request.Query[userCodeParamName];\n        if (string.IsNullOrWhiteSpace(userCode)) return View(\"UserCodeCapture\");\n\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        vm.ConfirmUserCode = true;\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> UserCodeCapture(string userCode)\n    {\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Callback(DeviceAuthorizationInputModel model)\n    {\n        if (model == null) throw new ArgumentNullException(nameof(model));\n\n        var result = await ProcessConsent(model);\n        if (result.HasValidationError) return View(\"Error\");\n\n        return View(\"Success\");\n    }\n\n    private async Task<ProcessConsentResult> ProcessConsent(DeviceAuthorizationInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        var request = await _interaction.GetAuthorizationContextAsync(model.UserCode);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.HandleRequestAsync(model.UserCode, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.UserCode, model);\n        }\n\n        return result;\n    }\n\n    private async Task<DeviceAuthorizationViewModel> BuildViewModelAsync(string userCode, DeviceAuthorizationInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(userCode);\n        if (request != null)\n        {\n            return CreateConsentViewModel(userCode, model, request);\n        }\n\n        return null;\n    }\n\n    private DeviceAuthorizationViewModel CreateConsentViewModel(string userCode, DeviceAuthorizationInputModel model, DeviceFlowAuthorizationRequest request)\n    {\n        var vm = new DeviceAuthorizationViewModel\n        {\n            UserCode = userCode,\n            Description = model?.Description,\n\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach (var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            // todo: use the parsed scope value in the display?\n            DisplayName = apiScope.DisplayName ?? apiScope.Name,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Diagnostics/DiagnosticsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[Authorize]\npublic class DiagnosticsController : Controller\n{\n    public async Task<IActionResult> Index()\n    {\n        var localAddresses = new string[] { \"127.0.0.1\", \"::1\", HttpContext.Connection.LocalIpAddress.ToString() };\n        if (!localAddresses.Contains(HttpContext.Connection.RemoteIpAddress.ToString()))\n        {\n            return NotFound();\n        }\n\n        var model = new DiagnosticsViewModel(await HttpContext.AuthenticateAsync());\n        return View(model);\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Diagnostics/DiagnosticsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DiagnosticsViewModel\n{\n    public DiagnosticsViewModel(AuthenticateResult result)\n    {\n        AuthenticateResult = result;\n\n        if (result.Properties.Items.ContainsKey(\"client_list\"))\n        {\n            var encoded = result.Properties.Items[\"client_list\"];\n            var bytes = Base64Url.Decode(encoded);\n            var value = Encoding.UTF8.GetString(bytes);\n\n            Clients = JsonConvert.DeserializeObject<string[]>(value);\n        }\n    }\n\n    public AuthenticateResult AuthenticateResult { get; }\n    public IEnumerable<string> Clients { get; } = new List<string>();\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Extensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic static class Extensions\n{\n    /// <summary>\n    /// Checks if the redirect URI is for a native client.\n    /// </summary>\n    /// <returns></returns>\n    public static bool IsNativeClient(this AuthorizationRequest context)\n    {\n        return !context.RedirectUri.StartsWith(\"https\", StringComparison.Ordinal)\n           && !context.RedirectUri.StartsWith(\"http\", StringComparison.Ordinal);\n    }\n\n    public static IActionResult LoadingPage(this Controller controller, string viewName, string redirectUri)\n    {\n        controller.HttpContext.Response.StatusCode = 200;\n        controller.HttpContext.Response.Headers[\"Location\"] = \"\";\n        \n        return controller.View(viewName, new RedirectViewModel { RedirectUrl = redirectUri });\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Grants/GrantsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller allows a user to revoke grants given to clients\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class GrantsController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clients;\n    private readonly IResourceStore _resources;\n    private readonly IEventService _events;\n\n    public GrantsController(IIdentityServerInteractionService interaction,\n        IClientStore clients,\n        IResourceStore resources,\n        IEventService events)\n    {\n        _interaction = interaction;\n        _clients = clients;\n        _resources = resources;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Show list of grants\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        return View(\"Index\", await BuildViewModelAsync());\n    }\n\n    /// <summary>\n    /// Handle postback to revoke a client\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Revoke(string clientId)\n    {\n        await _interaction.RevokeUserConsentAsync(clientId);\n        await _events.RaiseAsync(new GrantsRevokedEvent(User.GetSubjectId(), clientId));\n\n        return RedirectToAction(\"Index\");\n    }\n\n    private async Task<GrantsViewModel> BuildViewModelAsync()\n    {\n        var grants = await _interaction.GetAllUserGrantsAsync();\n\n        var list = new List<GrantViewModel>();\n        foreach(var grant in grants)\n        {\n            var client = await _clients.FindClientByIdAsync(grant.ClientId);\n            if (client != null)\n            {\n                var resources = await _resources.FindResourcesByScopeAsync(grant.Scopes);\n\n                var item = new GrantViewModel()\n                {\n                    ClientId = client.ClientId,\n                    ClientName = client.ClientName ?? client.ClientId,\n                    ClientLogoUrl = client.LogoUri,\n                    ClientUrl = client.ClientUri,\n                    Description = grant.Description,\n                    Created = grant.CreationTime,\n                    Expires = grant.Expiration,\n                    IdentityGrantNames = resources.IdentityResources.Select(x => x.DisplayName ?? x.Name).ToArray(),\n                    ApiGrantNames = resources.ApiScopes.Select(x => x.DisplayName ?? x.Name).ToArray()\n                };\n\n                list.Add(item);\n            }\n        }\n\n        return new GrantsViewModel\n        {\n            Grants = list\n        };\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Grants/GrantsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class GrantsViewModel\n{\n    public IEnumerable<GrantViewModel> Grants { get; set; }\n}\n\npublic class GrantViewModel\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public string Description { get; set; }\n    public DateTime Created { get; set; }\n    public DateTime? Expires { get; set; }\n    public IEnumerable<string> IdentityGrantNames { get; set; }\n    public IEnumerable<string> ApiGrantNames { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Home/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ErrorViewModel\n{\n    public ErrorViewModel()\n    {\n    }\n\n    public ErrorViewModel(string error)\n    {\n        Error = new ErrorMessage { Error = error };\n    }\n\n    public ErrorMessage Error { get; set; }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/Home/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class HomeController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IWebHostEnvironment _environment;\n    private readonly ILogger _logger;\n\n    public HomeController(IIdentityServerInteractionService interaction, IWebHostEnvironment environment, ILogger<HomeController> logger)\n    {\n        _interaction = interaction;\n        _environment = environment;\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        if (_environment.IsDevelopment())\n        {\n            // only show in development\n            return View();\n        }\n\n        _logger.LogInformation(\"Homepage is disabled in production. Returning 404.\");\n        return NotFound();\n    }\n\n    /// <summary>\n    /// Shows the error page\n    /// </summary>\n    public async Task<IActionResult> Error(string errorId)\n    {\n        var vm = new ErrorViewModel();\n\n        // retrieve error details from identityserver\n        var message = await _interaction.GetErrorContextAsync(errorId);\n        if (message != null)\n        {\n            vm.Error = message;\n\n            if (!_environment.IsDevelopment())\n            {\n                // only show in development\n                message.ErrorDescription = null;\n            }\n        }\n\n        return View(\"Error\", vm);\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/SecurityHeadersAttribute.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class SecurityHeadersAttribute : ActionFilterAttribute\n{\n    public override void OnResultExecuting(ResultExecutingContext context)\n    {\n        var result = context.Result;\n        if (result is ViewResult)\n        {\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Type-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Type-Options\", \"nosniff\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Frame-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Frame-Options\", \"SAMEORIGIN\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy\n            var csp = \"default-src 'self'; object-src 'none'; frame-ancestors 'none'; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self';\";\n            // also consider adding upgrade-insecure-requests once you have HTTPS in place for production\n            //csp += \"upgrade-insecure-requests;\";\n            // also an example if you need client images to be displayed from twitter\n            // csp += \"img-src 'self' https://pbs.twimg.com;\";\n\n            // once for standards compliant browsers\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Content-Security-Policy\", csp);\n            }\n            // and once again for IE\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Security-Policy\", csp);\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy\n            var referrer_policy = \"no-referrer\";\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Referrer-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Referrer-Policy\", referrer_policy);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Quickstart/TestUsers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class TestUsers\n{\n    public static List<TestUser> Users = new List<TestUser>\n    {\n        new TestUser{SubjectId = \"818727\", Username = \"alice\", Password = \"alice\", \n            Claims = \n            {\n                new Claim(JwtClaimTypes.Name, \"Alice Smith\"),\n                new Claim(JwtClaimTypes.GivenName, \"Alice\"),\n                new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                new Claim(JwtClaimTypes.Email, \"AliceSmith@email.com\"),\n                new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new Claim(JwtClaimTypes.WebSite, \"http://alice.com\"),\n                new Claim(JwtClaimTypes.Address, @\"{ 'street_address': 'One Hacker Way', 'locality': 'Heidelberg', 'postal_code': 69118, 'country': 'Germany' }\", IdentityServer8.IdentityServerConstants.ClaimValueTypes.Json)\n            }\n        },\n        new TestUser{SubjectId = \"88421113\", Username = \"bob\", Password = \"bob\", \n            Claims = \n            {\n                new Claim(JwtClaimTypes.Name, \"Bob Smith\"),\n                new Claim(JwtClaimTypes.GivenName, \"Bob\"),\n                new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                new Claim(JwtClaimTypes.Email, \"BobSmith@email.com\"),\n                new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                new Claim(JwtClaimTypes.WebSite, \"http://bob.com\"),\n                new Claim(JwtClaimTypes.Address, @\"{ 'street_address': 'One Hacker Way', 'locality': 'Heidelberg', 'postal_code': 69118, 'country': 'Germany' }\", IdentityServer8.IdentityServerConstants.ClaimValueTypes.Json),\n                new Claim(\"location\", \"somewhere\")\n            }\n        }\n    };\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost\n{\n    public class Startup\n    {\n        public Startup(IConfiguration configuration)\n        {\n            Configuration = configuration;\n        }\n\n        public IConfiguration Configuration { get; }\n\n        public void ConfigureServices(IServiceCollection services)\n        {\n            services.AddDbContext<ApplicationDbContext>(options =>\n                options.UseSqlServer(Configuration.GetConnectionString(\"DefaultConnection\")));\n\n            services.AddIdentity<ApplicationUser, IdentityRole>()\n                .AddEntityFrameworkStores<ApplicationDbContext>()\n                .AddDefaultTokenProviders();\n\n            services.AddControllersWithViews();\n\n            services.AddIdentityServer()\n                .AddDeveloperSigningCredential()\n                .AddInMemoryIdentityResources(IdentityServerHost.Configuration.Resources.IdentityResources)\n                .AddInMemoryApiResources(IdentityServerHost.Configuration.Resources.ApiResources)\n                .AddInMemoryApiScopes(IdentityServerHost.Configuration.Resources.ApiScopes)\n                .AddInMemoryClients(Clients.Get())\n                .AddAspNetIdentity<ApplicationUser>();\n\n            services.AddAuthentication()\n                .AddOpenIdConnect(\"Google\", \"Google\", options =>\n                {\n                    options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n                    options.ForwardSignOut = IdentityServerConstants.DefaultCookieAuthenticationScheme;\n\n                    options.Authority = \"https://accounts.google.com/\";\n                    options.ClientId = \"708996912208-9m4dkjb5hscn7cjrn5u0r4tbgkbj1fko.apps.googleusercontent.com\";\n\n                    options.CallbackPath = \"/signin-google\";\n                    options.Scope.Add(\"email\");\n                });\n        }\n\n        public void Configure(IApplicationBuilder app, IWebHostEnvironment env)\n        {\n            if (env.IsDevelopment())\n            {\n                app.UseDeveloperExceptionPage();\n                //app.UseDatabaseErrorPage();\n            }\n            else\n            {\n                app.UseExceptionHandler(\"/Home/Error\");\n            }\n\n            app.UseStaticFiles();\n\n            app.UseRouting();\n\n            app.UseIdentityServer();\n\n            app.UseAuthorization();\n\n            app.UseEndpoints(endpoints =>\n            {\n                endpoints.MapDefaultControllerRoute();\n            });\n        }\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Account/AccessDenied.cshtml",
    "content": "﻿\n<div class=\"container\">\n    <div class=\"lead\">\n        <h1>Access Denied</h1>\n        <p>You do not have access to that resource.</p>\n    </div>\n</div>"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Account/LoggedOut.cshtml",
    "content": "﻿@model LoggedOutViewModel\n\n@{ \n    // set this so the layout rendering sees an anonymous user\n    ViewData[\"signed-out\"] = true;\n}\n\n<div class=\"logged-out-page\">\n    <h1>\n        Logout\n        <small>You are now logged out</small>\n    </h1>\n\n    @if (Model.PostLogoutRedirectUri != null)\n    {\n        <div>\n            Click <a class=\"PostLogoutRedirectUri\" href=\"@Model.PostLogoutRedirectUri\">here</a> to return to the\n            <span>@Model.ClientName</span> application.\n        </div>\n    }\n\n    @if (Model.SignOutIframeUrl != null)\n    {\n        <iframe width=\"0\" height=\"0\" class=\"signout\" src=\"@Model.SignOutIframeUrl\"></iframe>\n    }\n</div>\n\n@section scripts\n{\n    @if (Model.AutomaticRedirectAfterSignOut)\n    {\n        <script src=\"~/js/signout-redirect.js\"></script>\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Account/Login.cshtml",
    "content": "@model LoginViewModel\n\n<div class=\"login-page\">\n    <div class=\"lead\">\n        <h1>Login</h1>\n        <p>Choose how to login</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n\n        @if (Model.EnableLocalLogin)\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>Local Account</h2>\n                    </div>\n\n                    <div class=\"card-body\">\n                        <form asp-route=\"Login\">\n                            <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n\n                            <div class=\"form-group\">\n                                <label asp-for=\"Username\"></label>\n                                <input class=\"form-control\" placeholder=\"Username\" asp-for=\"Username\" autofocus>\n                            </div>\n                            <div class=\"form-group\">\n                                <label asp-for=\"Password\"></label>\n                                <input type=\"password\" class=\"form-control\" placeholder=\"Password\" asp-for=\"Password\" autocomplete=\"off\">\n                            </div>\n                            @if (Model.AllowRememberLogin)\n                            {\n                                <div class=\"form-group\">\n                                    <div class=\"form-check\">\n                                        <input class=\"form-check-input\" asp-for=\"RememberLogin\">\n                                        <label class=\"form-check-label\" asp-for=\"RememberLogin\">\n                                            Remember My Login\n                                        </label>\n                                    </div>\n                                </div>\n                            }\n                            <button class=\"btn btn-primary\" name=\"button\" value=\"login\">Login</button>\n                            <button class=\"btn btn-secondary\" name=\"button\" value=\"cancel\" formaction=\"/Account/LoginCancel\">Cancel</button>\n                        </form>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>External Account</h2>\n                    </div>\n                    <div class=\"card-body\">\n                        <ul class=\"list-inline\">\n                            @foreach (var provider in Model.VisibleExternalProviders)\n                            {\n                                <li class=\"list-inline-item\">\n                                    <a class=\"btn btn-secondary\"\n                                       asp-controller=\"External\"\n                                       asp-action=\"Challenge\"\n                                       asp-route-scheme=\"@provider.AuthenticationScheme\"\n                                       asp-route-returnUrl=\"@Model.ReturnUrl\">\n                                        @provider.DisplayName\n                                    </a>\n                                </li>\n                            }\n                        </ul>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (!Model.EnableLocalLogin && !Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"alert alert-warning\">\n                <strong>Invalid login request</strong>\n                There are no login schemes configured for this request.\n            </div>\n        }\n    </div>\n</div>"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Account/Logout.cshtml",
    "content": "﻿@model LogoutViewModel\n\n<div class=\"logout-page\">\n    <div class=\"lead\">\n        <h1>Logout</h1>\n        <p>Would you like to logout of IdentityServer?</p>\n    </div>\n\n    <form asp-action=\"Logout\">\n        <input type=\"hidden\" name=\"logoutId\" value=\"@Model.LogoutId\"  />\n        <div class=\"form-group\">\n            <button class=\"btn btn-primary\">Yes</button>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Consent/Index.cshtml",
    "content": "@model ConsentViewModel\n\n<div class=\"page-consent\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Index\">\n        <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Device/Success.cshtml",
    "content": "\n<div class=\"page-device-success\">\n    <div class=\"lead\">\n        <h1>Success</h1>\n        <p>You have successfully authorized the device</p>\n    </div>\n</div>\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Device/UserCodeCapture.cshtml",
    "content": "@model string\n\n<div class=\"page-device-code\">\n    <div class=\"lead\">\n        <h1>User Code</h1>\n        <p>Please enter the code displayed on your device.</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <form asp-action=\"UserCodeCapture\">\n                <div class=\"form-group\">\n                    <label for=\"userCode\">User Code:</label>\n                    <input class=\"form-control\" for=\"userCode\" name=\"userCode\" autofocus />\n                </div>\n\n                <button class=\"btn btn-primary\" name=\"button\">Submit</button>\n            </form>\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Device/UserCodeConfirmation.cshtml",
    "content": "@model DeviceAuthorizationViewModel\n\n<div class=\"page-device-confirmation\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        @if (Model.ConfirmUserCode)\n        {\n            <p>Please confirm that the authorization request quotes the code: <strong>@Model.UserCode</strong>.</p>\n        }\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Callback\">\n        <input asp-for=\"UserCode\" type=\"hidden\" value=\"@Model.UserCode\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Diagnostics/Index.cshtml",
    "content": "@model DiagnosticsViewModel\n\n<div class=\"diagnostics-page\">\n    <div class=\"lead\">\n        <h1>Authentication Cookie</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Claims</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var claim in Model.AuthenticateResult.Principal.Claims)\n                        {\n                            <dt>@claim.Type</dt>\n                            <dd>@claim.Value</dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n        \n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Properties</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var prop in Model.AuthenticateResult.Properties.Items)\n                        {\n                            <dt>@prop.Key</dt>\n                            <dd>@prop.Value</dd>\n                        }\n                        @if (Model.Clients.Any())\n                        {\n                            <dt>Clients</dt>\n                            <dd>\n                            @{\n                                var clients = Model.Clients.ToArray();\n                                for(var i = 0; i < clients.Length; i++)\n                                {\n                                    <text>@clients[i]</text>\n                                    if (i < clients.Length - 1)\n                                    {\n                                        <text>, </text>\n                                    }\n                                }\n                            }\n                            </dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n    </div>\n</div>\n\n\n\n\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Grants/Index.cshtml",
    "content": "﻿@model GrantsViewModel\n\n<div class=\"grants-page\">\n    <div class=\"lead\">\n        <h1>Client Application Permissions</h1>\n        <p>Below is the list of applications you have given permission to and the resources they have access to.</p>\n    </div>\n\n    @if (Model.Grants.Any() == false)\n    {\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                <div class=\"alert alert-info\">\n                    You have not given access to any applications\n                </div>\n            </div>\n        </div>\n    }\n    else\n    {\n        foreach (var grant in Model.Grants)\n        {\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <div class=\"row\">\n                        <div class=\"col-sm-8 card-title\">\n                            @if (grant.ClientLogoUrl != null)\n                            {\n                                <img src=\"@grant.ClientLogoUrl\">\n                            }\n                            <strong>@grant.ClientName</strong>\n                        </div>\n\n                        <div class=\"col-sm-2\">\n                            <form asp-action=\"Revoke\">\n                                <input type=\"hidden\" name=\"clientId\" value=\"@grant.ClientId\">\n                                <button class=\"btn btn-danger\">Revoke Access</button>\n                            </form>\n                        </div>\n                    </div>\n                </div>\n                \n                <ul class=\"list-group list-group-flush\">\n                    @if (grant.Description != null)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Description:</label> @grant.Description\n                        </li>   \n                    }\n                    <li class=\"list-group-item\">\n                        <label>Created:</label> @grant.Created.ToString(\"yyyy-MM-dd\")\n                    </li>\n                    @if (grant.Expires.HasValue)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Expires:</label> @grant.Expires.Value.ToString(\"yyyy-MM-dd\")\n                        </li>\n                    }\n                    @if (grant.IdentityGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Identity Grants</label>\n                            <ul>\n                                @foreach (var name in grant.IdentityGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                    @if (grant.ApiGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>API Grants</label>\n                            <ul>\n                                @foreach (var name in grant.ApiGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                </ul>\n            </div>\n        }\n    }\n</div>"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Home/Index.cshtml",
    "content": "@using System.Diagnostics\n\n@{\n    var version = FileVersionInfo.GetVersionInfo(typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.Location).ProductVersion.Split('+').First();\n}\n\n<div class=\"welcome-page\">\n    <h1>\n        <img src=\"~/icon.jpg\">\n        Welcome to IdentityServer8\n        <small class=\"text-muted\">(version @version)</small>\n    </h1>\n\n    <ul>\n        <li>\n            IdentityServer publishes a\n            <a href=\"~/.well-known/openid-configuration\">discovery document</a>\n            where you can find metadata and links to all the endpoints, key material, etc.\n        </li>\n        <li>\n            Click <a href=\"~/diagnostics\">here</a> to see the claims for your current session.\n        </li>\n        <li>\n            Click <a href=\"~/grants\">here</a> to manage your stored grants.\n        </li>\n        <li>\n            Here are links to the\n            <a href=\"https://github.com/alexhiggins732/IdentityServer8\">source code repository</a>,\n            and <a href=\"https://github.com/alexhiggins732/IdentityServer8/tree/main/samples\">ready to use samples</a>.\n        </li>\n    </ul>\n</div>\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Shared/Error.cshtml",
    "content": "@model ErrorViewModel\n\n@{\n    var error = Model?.Error?.Error;\n    var errorDescription = Model?.Error?.ErrorDescription;\n    var request_id = Model?.Error?.RequestId;\n}\n\n<div class=\"error-page\">\n    <div class=\"lead\">\n        <h1>Error</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <div class=\"alert alert-danger\">\n                Sorry, there was an error\n\n                @if (error != null)\n                {\n                    <strong>\n                        <em>\n                            : @error\n                        </em>\n                    </strong>\n\n                    if (errorDescription != null)\n                    {\n                        <div>@errorDescription</div>\n                    }\n                }\n            </div>\n\n            @if (request_id != null)\n            {\n                <div class=\"request-id\">Request Id: @request_id</div>\n            }\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Shared/Redirect.cshtml",
    "content": "@model RedirectViewModel\n@using Microsoft.Extensions.DependencyInjection;\n<div class=\"redirect-page\">\n    <div class=\"lead\">\n        <h1>You are now being returned to the application</h1>\n        <p>Once complete, you may close this tab.</p>\n    </div>\n</div>\n\n<meta http-equiv=\"refresh\" content=\"0;url=@Model.RedirectUrl\" data-url=\"@Model.RedirectUrl.SantizeForRedirect()\">\n<script>\n    var url = '@Model.RedirectUrl.SanitizeForUrl()';\n    window.location.href = url;\n</script>\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0, shrink-to-fit=no\" />\n\n    <title>IdentityServer8</title>\n    \n    <link rel=\"icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    <link rel=\"shortcut icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    \n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <partial name=\"_Nav\" />\n   \n    <div class=\"container body-container\">\n        @RenderBody()\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.slim.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Shared/_Nav.cshtml",
    "content": "@using IdentityServer8.Extensions\n\n@{\n    string name = null;\n    if (!true.Equals(ViewData[\"signed-out\"]))\n    {\n        name = Context.User?.GetDisplayName();\n    }\n}\n\n<div class=\"nav-page\">\n    <nav class=\"navbar navbar-expand-lg navbar-dark bg-dark\">\n\n        <a href=\"~/\" class=\"navbar-brand\">\n            <img src=\"~/icon.png\" class=\"icon-banner\">\n            IdentityServer8\n        </a>\n\n        @if (!string.IsNullOrWhiteSpace(name))\n        {\n            <ul class=\"navbar-nav mr-auto\">\n                <li class=\"nav-item dropdown\">\n                    <a href=\"#\" class=\"nav-link dropdown-toggle\" data-toggle=\"dropdown\">@name <b class=\"caret\"></b></a>\n                    \n                    <div class=\"dropdown-menu\">\n                        <a class=\"dropdown-item\" asp-action=\"Logout\" asp-controller=\"Account\">Logout</a>\n                    </div>\n              </li>\n            </ul>\n        }\n    \n    </nav>\n</div>\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Shared/_ScopeListItem.cshtml",
    "content": "﻿@model ScopeViewModel\n\n<li class=\"list-group-item\">\n    <label>\n        <input class=\"consent-scopecheck\"\n               type=\"checkbox\"\n               name=\"ScopesConsented\"\n               id=\"scopes_@Model.Value\"\n               value=\"@Model.Value\"\n               checked=\"@Model.Checked\"\n               disabled=\"@Model.Required\" />\n        @if (Model.Required)\n        {\n            <input type=\"hidden\"\n                   name=\"ScopesConsented\"\n                   value=\"@Model.Value\" />\n        }\n        <strong>@Model.DisplayName</strong>\n        @if (Model.Emphasize)\n        {\n            <span class=\"glyphicon glyphicon-exclamation-sign\"></span>\n        }\n    </label>\n    @if (Model.Required)\n    {\n        <span><em>(required)</em></span>\n    }\n    @if (Model.Description != null)\n    {\n        <div class=\"consent-description\">\n            <label for=\"scopes_@Model.Value\">@Model.Description</label>\n        </div>\n    }\n</li>"
  },
  {
    "path": "src/AspNetIdentity/host/Views/Shared/_ValidationSummary.cshtml",
    "content": "﻿@if (ViewContext.ModelState.IsValid == false)\n{\n    <div class=\"alert alert-danger\">\n        <strong>Error</strong>\n        <div asp-validation-summary=\"All\" class=\"danger\"></div>\n    </div>\n}"
  },
  {
    "path": "src/AspNetIdentity/host/Views/_ViewImports.cshtml",
    "content": "﻿@using IdentityServerHost.Quickstart.UI\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "src/AspNetIdentity/host/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/appsettings.json",
    "content": "{\n  \"ConnectionStrings\": {\n    \"DefaultConnection\": \"Server=(localdb)\\\\mssqllocaldb;Database=IdentityServer8.AspNetIdentity-8.0.0;Trusted_Connection=True;MultipleActiveResultSets=true\"\n  },\n  \"Logging\": {\n    \"IncludeScopes\": false,\n    \"LogLevel\": {\n      \"Default\": \"Warning\"\n    }\n  }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/host/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "src/AspNetIdentity/host/wwwroot/css/site.css",
    "content": "﻿.body-container {\n  margin-top: 60px;\n  padding-bottom: 40px; }\n\n.welcome-page li {\n  list-style: none;\n  padding: 4px; }\n\n.logged-out-page iframe {\n  display: none;\n  width: 0;\n  height: 0; }\n\n.grants-page .card {\n  margin-top: 20px;\n  border-bottom: 1px solid lightgray; }\n  .grants-page .card .card-title {\n    font-size: 120%;\n    font-weight: bold; }\n    .grants-page .card .card-title img {\n      width: 100px;\n      height: 100px; }\n  .grants-page .card label {\n    font-weight: bold; }\n"
  },
  {
    "path": "src/AspNetIdentity/host/wwwroot/css/site.scss",
    "content": "﻿.body-container {\n    margin-top: 60px;\n    padding-bottom:40px;\n}\n\n.welcome-page {\n    li {\n        list-style: none;\n        padding: 4px;\n    }\n}\n\n.logged-out-page {\n    iframe {\n        display: none;\n        width: 0;\n        height: 0;\n    }\n}\n\n.grants-page {\n    .card {\n        margin-top: 20px;\n        border-bottom: 1px solid lightgray;\n\n        .card-title {\n            img {\n                width: 100px;\n                height: 100px;\n            }\n\n            font-size: 120%;\n            font-weight: bold;\n        }\n\n        label {\n            font-weight: bold;\n        }\n    }\n}\n\n\n"
  },
  {
    "path": "src/AspNetIdentity/host/wwwroot/js/signin-redirect.js",
    "content": "//window.location.href = document.querySelector(\"meta[http-equiv=refresh]\").getAttribute(\"data-url\");\n"
  },
  {
    "path": "src/AspNetIdentity/host/wwwroot/js/signout-redirect.js",
    "content": "﻿window.addEventListener(\"load\", function () {\n    var a = document.querySelector(\"a.PostLogoutRedirectUri\");\n    if (a) {\n        window.location = a.href;\n    }\n});\n"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8.Models;\nglobal using IdentityServerHost;\nglobal using IdentityServerHost.Data;\nglobal using Microsoft.AspNetCore;\nglobal using Microsoft.AspNetCore.Identity;\nglobal using Microsoft.EntityFrameworkCore;\nglobal using Microsoft.EntityFrameworkCore.Infrastructure;\nglobal using Microsoft.EntityFrameworkCore.Metadata;\nglobal using Microsoft.EntityFrameworkCore.Migrations;\nglobal using System.Security.Claims;\n"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/Migrations/UsersDb/20200323135751_Users.Designer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\n\nnamespace SqlServer.Migrations.UsersDb\n{\n    [DbContext(typeof(ApplicationDbContext))]\n    [Migration(\"20200323135751_Users\")]\n    partial class Users\n    {\n        protected override void BuildTargetModel(ModelBuilder modelBuilder)\n        {\n#pragma warning disable 612, 618\n            modelBuilder\n                .HasAnnotation(\"ProductVersion\", \"3.1.0\")\n                .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n                .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n            modelBuilder.Entity(\"IdentityServer8.Models.ApplicationUser\", b =>\n                {\n                    b.Property<string>(\"Id\")\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.Property<int>(\"AccessFailedCount\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"ConcurrencyStamp\")\n                        .IsConcurrencyToken()\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.Property<string>(\"Email\")\n                        .HasColumnType(\"nvarchar(256)\")\n                        .HasMaxLength(256);\n\n                    b.Property<bool>(\"EmailConfirmed\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"LockoutEnabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTimeOffset?>(\"LockoutEnd\")\n                        .HasColumnType(\"datetimeoffset\");\n\n                    b.Property<string>(\"NormalizedEmail\")\n                        .HasColumnType(\"nvarchar(256)\")\n                        .HasMaxLength(256);\n\n                    b.Property<string>(\"NormalizedUserName\")\n                        .HasColumnType(\"nvarchar(256)\")\n                        .HasMaxLength(256);\n\n                    b.Property<string>(\"PasswordHash\")\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.Property<string>(\"PhoneNumber\")\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.Property<bool>(\"PhoneNumberConfirmed\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"SecurityStamp\")\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.Property<bool>(\"TwoFactorEnabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"UserName\")\n                        .HasColumnType(\"nvarchar(256)\")\n                        .HasMaxLength(256);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"NormalizedEmail\")\n                        .HasName(\"EmailIndex\");\n\n                    b.HasIndex(\"NormalizedUserName\")\n                        .IsUnique()\n                        .HasName(\"UserNameIndex\")\n                        .HasFilter(\"[NormalizedUserName] IS NOT NULL\");\n\n                    b.ToTable(\"AspNetUsers\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRole\", b =>\n                {\n                    b.Property<string>(\"Id\")\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.Property<string>(\"ConcurrencyStamp\")\n                        .IsConcurrencyToken()\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.Property<string>(\"Name\")\n                        .HasColumnType(\"nvarchar(256)\")\n                        .HasMaxLength(256);\n\n                    b.Property<string>(\"NormalizedName\")\n                        .HasColumnType(\"nvarchar(256)\")\n                        .HasMaxLength(256);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"NormalizedName\")\n                        .IsUnique()\n                        .HasName(\"RoleNameIndex\")\n                        .HasFilter(\"[NormalizedName] IS NOT NULL\");\n\n                    b.ToTable(\"AspNetRoles\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRoleClaim<string>\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"ClaimType\")\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.Property<string>(\"ClaimValue\")\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.Property<string>(\"RoleId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"RoleId\");\n\n                    b.ToTable(\"AspNetRoleClaims\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserClaim<string>\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"ClaimType\")\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.Property<string>(\"ClaimValue\")\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.Property<string>(\"UserId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"UserId\");\n\n                    b.ToTable(\"AspNetUserClaims\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserLogin<string>\", b =>\n                {\n                    b.Property<string>(\"LoginProvider\")\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.Property<string>(\"ProviderKey\")\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.Property<string>(\"ProviderDisplayName\")\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.Property<string>(\"UserId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.HasKey(\"LoginProvider\", \"ProviderKey\");\n\n                    b.HasIndex(\"UserId\");\n\n                    b.ToTable(\"AspNetUserLogins\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserRole<string>\", b =>\n                {\n                    b.Property<string>(\"UserId\")\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.Property<string>(\"RoleId\")\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.HasKey(\"UserId\", \"RoleId\");\n\n                    b.HasIndex(\"RoleId\");\n\n                    b.ToTable(\"AspNetUserRoles\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserToken<string>\", b =>\n                {\n                    b.Property<string>(\"UserId\")\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.Property<string>(\"LoginProvider\")\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.Property<string>(\"Name\")\n                        .HasColumnType(\"nvarchar(450)\");\n\n                    b.Property<string>(\"Value\")\n                        .HasColumnType(\"nvarchar(max)\");\n\n                    b.HasKey(\"UserId\", \"LoginProvider\", \"Name\");\n\n                    b.ToTable(\"AspNetUserTokens\");\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRoleClaim<string>\", b =>\n                {\n                    b.HasOne(\"Microsoft.AspNetCore.Identity.IdentityRole\", null)\n                        .WithMany()\n                        .HasForeignKey(\"RoleId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserClaim<string>\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.Models.ApplicationUser\", null)\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserLogin<string>\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.Models.ApplicationUser\", null)\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserRole<string>\", b =>\n                {\n                    b.HasOne(\"Microsoft.AspNetCore.Identity.IdentityRole\", null)\n                        .WithMany()\n                        .HasForeignKey(\"RoleId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n\n                    b.HasOne(\"IdentityServer8.Models.ApplicationUser\", null)\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserToken<string>\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.Models.ApplicationUser\", null)\n                        .WithMany()\n                        .HasForeignKey(\"UserId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n#pragma warning restore 612, 618\n        }\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/Migrations/UsersDb/20200323135751_Users.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace SqlServer.Migrations.UsersDb;\n\npublic partial class Users : Migration\n{\n    protected override void Up(MigrationBuilder migrationBuilder)\n    {\n        migrationBuilder.CreateTable(\n            name: \"AspNetRoles\",\n            columns: table => new\n            {\n                Id = table.Column<string>(nullable: false),\n                Name = table.Column<string>(maxLength: 256, nullable: true),\n                NormalizedName = table.Column<string>(maxLength: 256, nullable: true),\n                ConcurrencyStamp = table.Column<string>(nullable: true)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_AspNetRoles\", x => x.Id);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"AspNetUsers\",\n            columns: table => new\n            {\n                Id = table.Column<string>(nullable: false),\n                UserName = table.Column<string>(maxLength: 256, nullable: true),\n                NormalizedUserName = table.Column<string>(maxLength: 256, nullable: true),\n                Email = table.Column<string>(maxLength: 256, nullable: true),\n                NormalizedEmail = table.Column<string>(maxLength: 256, nullable: true),\n                EmailConfirmed = table.Column<bool>(nullable: false),\n                PasswordHash = table.Column<string>(nullable: true),\n                SecurityStamp = table.Column<string>(nullable: true),\n                ConcurrencyStamp = table.Column<string>(nullable: true),\n                PhoneNumber = table.Column<string>(nullable: true),\n                PhoneNumberConfirmed = table.Column<bool>(nullable: false),\n                TwoFactorEnabled = table.Column<bool>(nullable: false),\n                LockoutEnd = table.Column<DateTimeOffset>(nullable: true),\n                LockoutEnabled = table.Column<bool>(nullable: false),\n                AccessFailedCount = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_AspNetUsers\", x => x.Id);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"AspNetRoleClaims\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                RoleId = table.Column<string>(nullable: false),\n                ClaimType = table.Column<string>(nullable: true),\n                ClaimValue = table.Column<string>(nullable: true)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_AspNetRoleClaims\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_AspNetRoleClaims_AspNetRoles_RoleId\",\n                    column: x => x.RoleId,\n                    principalTable: \"AspNetRoles\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"AspNetUserClaims\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                UserId = table.Column<string>(nullable: false),\n                ClaimType = table.Column<string>(nullable: true),\n                ClaimValue = table.Column<string>(nullable: true)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_AspNetUserClaims\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_AspNetUserClaims_AspNetUsers_UserId\",\n                    column: x => x.UserId,\n                    principalTable: \"AspNetUsers\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"AspNetUserLogins\",\n            columns: table => new\n            {\n                LoginProvider = table.Column<string>(nullable: false),\n                ProviderKey = table.Column<string>(nullable: false),\n                ProviderDisplayName = table.Column<string>(nullable: true),\n                UserId = table.Column<string>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_AspNetUserLogins\", x => new { x.LoginProvider, x.ProviderKey });\n                table.ForeignKey(\n                    name: \"FK_AspNetUserLogins_AspNetUsers_UserId\",\n                    column: x => x.UserId,\n                    principalTable: \"AspNetUsers\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"AspNetUserRoles\",\n            columns: table => new\n            {\n                UserId = table.Column<string>(nullable: false),\n                RoleId = table.Column<string>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_AspNetUserRoles\", x => new { x.UserId, x.RoleId });\n                table.ForeignKey(\n                    name: \"FK_AspNetUserRoles_AspNetRoles_RoleId\",\n                    column: x => x.RoleId,\n                    principalTable: \"AspNetRoles\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n                table.ForeignKey(\n                    name: \"FK_AspNetUserRoles_AspNetUsers_UserId\",\n                    column: x => x.UserId,\n                    principalTable: \"AspNetUsers\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"AspNetUserTokens\",\n            columns: table => new\n            {\n                UserId = table.Column<string>(nullable: false),\n                LoginProvider = table.Column<string>(nullable: false),\n                Name = table.Column<string>(nullable: false),\n                Value = table.Column<string>(nullable: true)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_AspNetUserTokens\", x => new { x.UserId, x.LoginProvider, x.Name });\n                table.ForeignKey(\n                    name: \"FK_AspNetUserTokens_AspNetUsers_UserId\",\n                    column: x => x.UserId,\n                    principalTable: \"AspNetUsers\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_AspNetRoleClaims_RoleId\",\n            table: \"AspNetRoleClaims\",\n            column: \"RoleId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"RoleNameIndex\",\n            table: \"AspNetRoles\",\n            column: \"NormalizedName\",\n            unique: true,\n            filter: \"[NormalizedName] IS NOT NULL\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_AspNetUserClaims_UserId\",\n            table: \"AspNetUserClaims\",\n            column: \"UserId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_AspNetUserLogins_UserId\",\n            table: \"AspNetUserLogins\",\n            column: \"UserId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_AspNetUserRoles_RoleId\",\n            table: \"AspNetUserRoles\",\n            column: \"RoleId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"EmailIndex\",\n            table: \"AspNetUsers\",\n            column: \"NormalizedEmail\");\n\n        migrationBuilder.CreateIndex(\n            name: \"UserNameIndex\",\n            table: \"AspNetUsers\",\n            column: \"NormalizedUserName\",\n            unique: true,\n            filter: \"[NormalizedUserName] IS NOT NULL\");\n    }\n\n    protected override void Down(MigrationBuilder migrationBuilder)\n    {\n        migrationBuilder.DropTable(\n            name: \"AspNetRoleClaims\");\n\n        migrationBuilder.DropTable(\n            name: \"AspNetUserClaims\");\n\n        migrationBuilder.DropTable(\n            name: \"AspNetUserLogins\");\n\n        migrationBuilder.DropTable(\n            name: \"AspNetUserRoles\");\n\n        migrationBuilder.DropTable(\n            name: \"AspNetUserTokens\");\n\n        migrationBuilder.DropTable(\n            name: \"AspNetRoles\");\n\n        migrationBuilder.DropTable(\n            name: \"AspNetUsers\");\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/Migrations/UsersDb/ApplicationDbContextModelSnapshot.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\n\nnamespace SqlServer.Migrations.UsersDb;\n\n[DbContext(typeof(ApplicationDbContext))]\npartial class ApplicationDbContextModelSnapshot : ModelSnapshot\n{\n    protected override void BuildModel(ModelBuilder modelBuilder)\n    {\n#pragma warning disable 612, 618\n        modelBuilder\n            .HasAnnotation(\"ProductVersion\", \"3.1.0\")\n            .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n            .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n        modelBuilder.Entity(\"IdentityServer8.Models.ApplicationUser\", b =>\n            {\n                b.Property<string>(\"Id\")\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.Property<int>(\"AccessFailedCount\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"ConcurrencyStamp\")\n                    .IsConcurrencyToken()\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.Property<string>(\"Email\")\n                    .HasColumnType(\"nvarchar(256)\")\n                    .HasMaxLength(256);\n\n                b.Property<bool>(\"EmailConfirmed\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"LockoutEnabled\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<DateTimeOffset?>(\"LockoutEnd\")\n                    .HasColumnType(\"datetimeoffset\");\n\n                b.Property<string>(\"NormalizedEmail\")\n                    .HasColumnType(\"nvarchar(256)\")\n                    .HasMaxLength(256);\n\n                b.Property<string>(\"NormalizedUserName\")\n                    .HasColumnType(\"nvarchar(256)\")\n                    .HasMaxLength(256);\n\n                b.Property<string>(\"PasswordHash\")\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.Property<string>(\"PhoneNumber\")\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.Property<bool>(\"PhoneNumberConfirmed\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<string>(\"SecurityStamp\")\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.Property<bool>(\"TwoFactorEnabled\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<string>(\"UserName\")\n                    .HasColumnType(\"nvarchar(256)\")\n                    .HasMaxLength(256);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"NormalizedEmail\")\n                    .HasName(\"EmailIndex\");\n\n                b.HasIndex(\"NormalizedUserName\")\n                    .IsUnique()\n                    .HasName(\"UserNameIndex\")\n                    .HasFilter(\"[NormalizedUserName] IS NOT NULL\");\n\n                b.ToTable(\"AspNetUsers\");\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRole\", b =>\n            {\n                b.Property<string>(\"Id\")\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.Property<string>(\"ConcurrencyStamp\")\n                    .IsConcurrencyToken()\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.Property<string>(\"Name\")\n                    .HasColumnType(\"nvarchar(256)\")\n                    .HasMaxLength(256);\n\n                b.Property<string>(\"NormalizedName\")\n                    .HasColumnType(\"nvarchar(256)\")\n                    .HasMaxLength(256);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"NormalizedName\")\n                    .IsUnique()\n                    .HasName(\"RoleNameIndex\")\n                    .HasFilter(\"[NormalizedName] IS NOT NULL\");\n\n                b.ToTable(\"AspNetRoles\");\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRoleClaim<string>\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<string>(\"ClaimType\")\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.Property<string>(\"ClaimValue\")\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.Property<string>(\"RoleId\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"RoleId\");\n\n                b.ToTable(\"AspNetRoleClaims\");\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserClaim<string>\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<string>(\"ClaimType\")\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.Property<string>(\"ClaimValue\")\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.Property<string>(\"UserId\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"UserId\");\n\n                b.ToTable(\"AspNetUserClaims\");\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserLogin<string>\", b =>\n            {\n                b.Property<string>(\"LoginProvider\")\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.Property<string>(\"ProviderKey\")\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.Property<string>(\"ProviderDisplayName\")\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.Property<string>(\"UserId\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.HasKey(\"LoginProvider\", \"ProviderKey\");\n\n                b.HasIndex(\"UserId\");\n\n                b.ToTable(\"AspNetUserLogins\");\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserRole<string>\", b =>\n            {\n                b.Property<string>(\"UserId\")\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.Property<string>(\"RoleId\")\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.HasKey(\"UserId\", \"RoleId\");\n\n                b.HasIndex(\"RoleId\");\n\n                b.ToTable(\"AspNetUserRoles\");\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserToken<string>\", b =>\n            {\n                b.Property<string>(\"UserId\")\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.Property<string>(\"LoginProvider\")\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.Property<string>(\"Name\")\n                    .HasColumnType(\"nvarchar(450)\");\n\n                b.Property<string>(\"Value\")\n                    .HasColumnType(\"nvarchar(max)\");\n\n                b.HasKey(\"UserId\", \"LoginProvider\", \"Name\");\n\n                b.ToTable(\"AspNetUserTokens\");\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityRoleClaim<string>\", b =>\n            {\n                b.HasOne(\"Microsoft.AspNetCore.Identity.IdentityRole\", null)\n                    .WithMany()\n                    .HasForeignKey(\"RoleId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserClaim<string>\", b =>\n            {\n                b.HasOne(\"IdentityServer8.Models.ApplicationUser\", null)\n                    .WithMany()\n                    .HasForeignKey(\"UserId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserLogin<string>\", b =>\n            {\n                b.HasOne(\"IdentityServer8.Models.ApplicationUser\", null)\n                    .WithMany()\n                    .HasForeignKey(\"UserId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserRole<string>\", b =>\n            {\n                b.HasOne(\"Microsoft.AspNetCore.Identity.IdentityRole\", null)\n                    .WithMany()\n                    .HasForeignKey(\"RoleId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n\n                b.HasOne(\"IdentityServer8.Models.ApplicationUser\", null)\n                    .WithMany()\n                    .HasForeignKey(\"UserId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"Microsoft.AspNetCore.Identity.IdentityUserToken<string>\", b =>\n            {\n                b.HasOne(\"IdentityServer8.Models.ApplicationUser\", null)\n                    .WithMany()\n                    .HasForeignKey(\"UserId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n#pragma warning restore 612, 618\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/Migrations/UsersDb.sql",
    "content": "﻿IF OBJECT_ID(N'[__EFMigrationsHistory]') IS NULL\nBEGIN\n    CREATE TABLE [__EFMigrationsHistory] (\n        [MigrationId] nvarchar(150) NOT NULL,\n        [ProductVersion] nvarchar(32) NOT NULL,\n        CONSTRAINT [PK___EFMigrationsHistory] PRIMARY KEY ([MigrationId])\n    );\nEND;\n\nGO\n\nCREATE TABLE [AspNetRoles] (\n    [Id] nvarchar(450) NOT NULL,\n    [Name] nvarchar(256) NULL,\n    [NormalizedName] nvarchar(256) NULL,\n    [ConcurrencyStamp] nvarchar(max) NULL,\n    CONSTRAINT [PK_AspNetRoles] PRIMARY KEY ([Id])\n);\n\nGO\n\nCREATE TABLE [AspNetUsers] (\n    [Id] nvarchar(450) NOT NULL,\n    [UserName] nvarchar(256) NULL,\n    [NormalizedUserName] nvarchar(256) NULL,\n    [Email] nvarchar(256) NULL,\n    [NormalizedEmail] nvarchar(256) NULL,\n    [EmailConfirmed] bit NOT NULL,\n    [PasswordHash] nvarchar(max) NULL,\n    [SecurityStamp] nvarchar(max) NULL,\n    [ConcurrencyStamp] nvarchar(max) NULL,\n    [PhoneNumber] nvarchar(max) NULL,\n    [PhoneNumberConfirmed] bit NOT NULL,\n    [TwoFactorEnabled] bit NOT NULL,\n    [LockoutEnd] datetimeoffset NULL,\n    [LockoutEnabled] bit NOT NULL,\n    [AccessFailedCount] int NOT NULL,\n    CONSTRAINT [PK_AspNetUsers] PRIMARY KEY ([Id])\n);\n\nGO\n\nCREATE TABLE [AspNetRoleClaims] (\n    [Id] int NOT NULL IDENTITY,\n    [RoleId] nvarchar(450) NOT NULL,\n    [ClaimType] nvarchar(max) NULL,\n    [ClaimValue] nvarchar(max) NULL,\n    CONSTRAINT [PK_AspNetRoleClaims] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_AspNetRoleClaims_AspNetRoles_RoleId] FOREIGN KEY ([RoleId]) REFERENCES [AspNetRoles] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [AspNetUserClaims] (\n    [Id] int NOT NULL IDENTITY,\n    [UserId] nvarchar(450) NOT NULL,\n    [ClaimType] nvarchar(max) NULL,\n    [ClaimValue] nvarchar(max) NULL,\n    CONSTRAINT [PK_AspNetUserClaims] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_AspNetUserClaims_AspNetUsers_UserId] FOREIGN KEY ([UserId]) REFERENCES [AspNetUsers] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [AspNetUserLogins] (\n    [LoginProvider] nvarchar(450) NOT NULL,\n    [ProviderKey] nvarchar(450) NOT NULL,\n    [ProviderDisplayName] nvarchar(max) NULL,\n    [UserId] nvarchar(450) NOT NULL,\n    CONSTRAINT [PK_AspNetUserLogins] PRIMARY KEY ([LoginProvider], [ProviderKey]),\n    CONSTRAINT [FK_AspNetUserLogins_AspNetUsers_UserId] FOREIGN KEY ([UserId]) REFERENCES [AspNetUsers] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [AspNetUserRoles] (\n    [UserId] nvarchar(450) NOT NULL,\n    [RoleId] nvarchar(450) NOT NULL,\n    CONSTRAINT [PK_AspNetUserRoles] PRIMARY KEY ([UserId], [RoleId]),\n    CONSTRAINT [FK_AspNetUserRoles_AspNetRoles_RoleId] FOREIGN KEY ([RoleId]) REFERENCES [AspNetRoles] ([Id]) ON DELETE CASCADE,\n    CONSTRAINT [FK_AspNetUserRoles_AspNetUsers_UserId] FOREIGN KEY ([UserId]) REFERENCES [AspNetUsers] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [AspNetUserTokens] (\n    [UserId] nvarchar(450) NOT NULL,\n    [LoginProvider] nvarchar(450) NOT NULL,\n    [Name] nvarchar(450) NOT NULL,\n    [Value] nvarchar(max) NULL,\n    CONSTRAINT [PK_AspNetUserTokens] PRIMARY KEY ([UserId], [LoginProvider], [Name]),\n    CONSTRAINT [FK_AspNetUserTokens_AspNetUsers_UserId] FOREIGN KEY ([UserId]) REFERENCES [AspNetUsers] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE INDEX [IX_AspNetRoleClaims_RoleId] ON [AspNetRoleClaims] ([RoleId]);\n\nGO\n\nCREATE UNIQUE INDEX [RoleNameIndex] ON [AspNetRoles] ([NormalizedName]) WHERE [NormalizedName] IS NOT NULL;\n\nGO\n\nCREATE INDEX [IX_AspNetUserClaims_UserId] ON [AspNetUserClaims] ([UserId]);\n\nGO\n\nCREATE INDEX [IX_AspNetUserLogins_UserId] ON [AspNetUserLogins] ([UserId]);\n\nGO\n\nCREATE INDEX [IX_AspNetUserRoles_RoleId] ON [AspNetUserRoles] ([RoleId]);\n\nGO\n\nCREATE INDEX [EmailIndex] ON [AspNetUsers] ([NormalizedEmail]);\n\nGO\n\nCREATE UNIQUE INDEX [UserNameIndex] ON [AspNetUsers] ([NormalizedUserName]) WHERE [NormalizedUserName] IS NOT NULL;\n\nGO\n\nINSERT INTO [__EFMigrationsHistory] ([MigrationId], [ProductVersion])\nVALUES (N'20200323135751_Users', N'3.1.0');\n\nGO\n\n"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace SqlServer;\n\nclass Program\n{\n    public static void Main(string[] args)\n    {\n        var host = BuildWebHost(args);\n        SeedData.EnsureSeedData(host.Services);\n    }\n\n    public static IWebHost BuildWebHost(string[] args) =>\n        WebHost.CreateDefaultBuilder(args)\n            .UseStartup<Startup>()\n            .Build();\n}\n"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:7603/\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"IIS Express\": {\n      \"commandName\": \"IISExpress\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      }\n    },\n    \"SqlServer\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"http://localhost:7604/\"\n    }\n  }\n}"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/SeedData.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost;\n\npublic class SeedData\n{\n    public static void EnsureSeedData(IServiceProvider serviceProvider)\n    {\n        using (var scope = serviceProvider.GetRequiredService<IServiceScopeFactory>().CreateScope())\n        {\n            var context = scope.ServiceProvider.GetService<ApplicationDbContext>();\n            context.Database.Migrate();\n\n            var userMgr = scope.ServiceProvider.GetRequiredService<UserManager<ApplicationUser>>();\n            var alice = userMgr.FindByNameAsync(\"alice\").Result;\n            if (alice == null)\n            {\n                alice = new ApplicationUser\n                {\n                    UserName = \"alice\"\n                };\n                var result = userMgr.CreateAsync(alice, \"Pass123$\").Result;\n                if (!result.Succeeded)\n                {\n                    throw new Exception(result.Errors.First().Description);\n                }\n\n                result = userMgr.AddClaimsAsync(alice, new Claim[]{\n                    new Claim(JwtClaimTypes.Name, \"Alice Smith\"),\n                    new Claim(JwtClaimTypes.GivenName, \"Alice\"),\n                    new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                    new Claim(JwtClaimTypes.Email, \"AliceSmith@email.com\"),\n                    new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                    new Claim(JwtClaimTypes.WebSite, \"http://alice.com\"),\n                    new Claim(JwtClaimTypes.Address, @\"{ 'street_address': 'One Hacker Way', 'locality': 'Heidelberg', 'postal_code': 69118, 'country': 'Germany' }\", IdentityServer8.IdentityServerConstants.ClaimValueTypes.Json)\n                }).Result;\n                if (!result.Succeeded)\n                {\n                    throw new Exception(result.Errors.First().Description);\n                }\n                Console.WriteLine(\"alice created\");\n            }\n            else\n            {\n                Console.WriteLine(\"alice already exists\");\n            }\n\n            var bob = userMgr.FindByNameAsync(\"bob\").Result;\n            if (bob == null)\n            {\n                bob = new ApplicationUser\n                {\n                    UserName = \"bob\"\n                };\n                var result = userMgr.CreateAsync(bob, \"Pass123$\").Result;\n                if (!result.Succeeded)\n                {\n                    throw new Exception(result.Errors.First().Description);\n                }\n\n                result = userMgr.AddClaimsAsync(bob, new Claim[]{\n                    new Claim(JwtClaimTypes.Name, \"Bob Smith\"),\n                    new Claim(JwtClaimTypes.GivenName, \"Bob\"),\n                    new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                    new Claim(JwtClaimTypes.Email, \"BobSmith@email.com\"),\n                    new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                    new Claim(JwtClaimTypes.WebSite, \"http://bob.com\"),\n                    new Claim(JwtClaimTypes.Address, @\"{ 'street_address': 'One Hacker Way', 'locality': 'Heidelberg', 'postal_code': 69118, 'country': 'Germany' }\", IdentityServer8.IdentityServerConstants.ClaimValueTypes.Json),\n                    new Claim(\"location\", \"somewhere\")\n                }).Result;\n                if (!result.Succeeded)\n                {\n                    throw new Exception(result.Errors.First().Description);\n                }\n                Console.WriteLine(\"bob created\");\n            }\n            else\n            {\n                Console.WriteLine(\"bob already exists\");\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/SqlServer.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.Design\" PrivateAssets=\"All\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\..\\host\\Host.csproj\" />\n    <ProjectReference Include=\"..\\..\\src\\IdentityServer8.AspNetIdentity.csproj\" />\n  </ItemGroup>\n\n</Project>\n"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace SqlServer;\n\npublic class Startup\n{\n    public IConfiguration Configuration { get; }\n\n    public Startup(IConfiguration config)\n    {\n        Configuration = config;\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        var cn = Configuration.GetConnectionString(\"db\");\n        services.AddDbContext<ApplicationDbContext>(options =>\n        {\n            options.UseSqlServer(cn, dbOpts => dbOpts.MigrationsAssembly(typeof(Startup).Assembly.FullName));\n        });\n\n        services.AddIdentity<ApplicationUser, IdentityRole>()\n            .AddEntityFrameworkStores<ApplicationDbContext>()\n            .AddDefaultTokenProviders();\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/appsettings.json",
    "content": "{\n  \"ConnectionStrings\": {\n    \"db\": \"server=(localdb)\\\\mssqllocaldb;database=IdentityServer8.AspNetIdentity-8.0.0;trusted_connection=yes;\"\n  }\n}"
  },
  {
    "path": "src/AspNetIdentity/migrations/SqlServer/builddb.bat",
    "content": "rmdir /S /Q Migrations\n\ndotnet ef database drop\n\ndotnet ef migrations add Users -o Migrations/UsersDb\ndotnet ef migrations script -o Migrations/UsersDb.sql\n\ndotnet ef database update\n"
  },
  {
    "path": "src/AspNetIdentity/src/Decorator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.AspNetIdentity;\n\ninternal class Decorator<TService>\n{\n    public TService Instance { get; set; }\n\n    public Decorator(TService instance)\n    {\n        Instance = instance;\n    }\n}\n\ninternal class Decorator<TService, TImpl> : Decorator<TService>\n    where TImpl : class, TService\n{\n    public Decorator(TImpl instance) : base(instance)\n    {\n    }\n}\n\ninternal class DisposableDecorator<TService> : Decorator<TService>, IDisposable\n{\n    public DisposableDecorator(TService instance) : base(instance)\n    {\n    }\n\n    public void Dispose()\n    {\n        (Instance as IDisposable)?.Dispose();\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/src/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.AspNetIdentity;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Validation;\nglobal using Microsoft.AspNetCore.Authentication.Cookies;\nglobal using Microsoft.AspNetCore.Identity;\nglobal using Microsoft.Extensions.Logging;\nglobal using System.Security.Claims;\nglobal using static IdentityModel.OidcConstants;\n"
  },
  {
    "path": "src/AspNetIdentity/src/IdentityServer8.AspNetIdentity.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n  <PropertyGroup>\n      <Description>ASP.NET Core Identity Integration for IdentityServer8</Description>\n      <IsPackable>true</IsPackable>\n      <GeneratePackageOnBuild>true</GeneratePackageOnBuild>\n      <SignAssembly>true</SignAssembly>\n  </PropertyGroup>\n\n  <PropertyGroup>\n    <ContinuousIntegrationBuild Condition=\"'$(TF_BUILD)' == 'true'\">True</ContinuousIntegrationBuild>\n    <ContinuousIntegrationBuild Condition=\"'$(GITHUB_ACTIONS)' == 'true'\">True</ContinuousIntegrationBuild>\n  </PropertyGroup>\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\..\\IdentityServer8\\src\\IdentityServer8.csproj\" />\n  </ItemGroup>\n\n</Project>"
  },
  {
    "path": "src/AspNetIdentity/src/IdentityServerBuilderExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// Extension methods to add ASP.NET Identity support to IdentityServer.\n/// </summary>\npublic static class IdentityServerBuilderExtensions\n{\n    /// <summary>\n    /// Configures IdentityServer to use the ASP.NET Identity implementations \n    /// of IUserClaimsPrincipalFactory, IResourceOwnerPasswordValidator, and IProfileService.\n    /// Also configures some of ASP.NET Identity's options for use with IdentityServer (such as claim types to use\n    /// and authentication cookie settings).\n    /// </summary>\n    /// <typeparam name=\"TUser\">The type of the user.</typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddAspNetIdentity<TUser>(this IIdentityServerBuilder builder)\n        where TUser : class\n    {\n        builder.Services.AddTransientDecorator<IUserClaimsPrincipalFactory<TUser>, UserClaimsFactory<TUser>>();\n\n        builder.Services.Configure<IdentityOptions>(options =>\n        {\n            options.ClaimsIdentity.UserIdClaimType = JwtClaimTypes.Subject;\n            options.ClaimsIdentity.UserNameClaimType = JwtClaimTypes.Name;\n            options.ClaimsIdentity.RoleClaimType = JwtClaimTypes.Role;\n        });\n\n        builder.Services.Configure<SecurityStampValidatorOptions>(opts =>\n        {\n            opts.OnRefreshingPrincipal = SecurityStampValidatorCallback.UpdatePrincipal;\n        });\n\n        builder.Services.ConfigureApplicationCookie(options =>\n        {\n            options.Cookie.IsEssential = true;\n            // we need to disable to allow iframe for authorize requests\n            options.Cookie.SameSite = AspNetCore.Http.SameSiteMode.None;\n        });\n\n        builder.Services.ConfigureExternalCookie(options =>\n        {\n            options.Cookie.IsEssential = true;\n            // https://github.com/alexhiggins732/IdentityServer8/issues/2595\n            options.Cookie.SameSite = AspNetCore.Http.SameSiteMode.None;\n        });\n\n        builder.Services.Configure<CookieAuthenticationOptions>(IdentityConstants.TwoFactorRememberMeScheme, options =>\n        {\n            options.Cookie.IsEssential = true;\n        });\n\n        builder.Services.Configure<CookieAuthenticationOptions>(IdentityConstants.TwoFactorUserIdScheme, options =>\n        {\n            options.Cookie.IsEssential = true;\n        });\n\n        builder.Services.AddAuthentication(options =>\n        {\n            if (options.DefaultAuthenticateScheme == null &&\n                options.DefaultScheme == IdentityServerConstants.DefaultCookieAuthenticationScheme)\n            {\n                options.DefaultScheme = IdentityConstants.ApplicationScheme;\n            }\n        });\n\n        builder.AddResourceOwnerValidator<ResourceOwnerPasswordValidator<TUser>>();\n        builder.AddProfileService<ProfileService<TUser>>();\n\n        return builder;\n    }\n\n    internal static void AddTransientDecorator<TService, TImplementation>(this IServiceCollection services)\n        where TService : class\n        where TImplementation : class, TService\n    {\n        services.AddDecorator<TService>();\n        services.AddTransient<TService, TImplementation>();\n    }\n\n    internal static void AddDecorator<TService>(this IServiceCollection services)\n    {\n        var registration = services.LastOrDefault(x => x.ServiceType == typeof(TService));\n        if (registration == null)\n        {\n            throw new InvalidOperationException(\"Service type: \" + typeof(TService).Name + \" not registered.\");\n        }\n        if (services.Any(x => x.ServiceType == typeof(Decorator<TService>)))\n        {\n            throw new InvalidOperationException(\"Decorator already registered for type: \" + typeof(TService).Name + \".\");\n        }\n\n        services.Remove(registration);\n\n        if (registration.ImplementationInstance != null)\n        {\n            var type = registration.ImplementationInstance.GetType();\n            var innerType = typeof(Decorator<,>).MakeGenericType(typeof(TService), type);\n            services.Add(new ServiceDescriptor(typeof(Decorator<TService>), innerType, ServiceLifetime.Transient));\n            services.Add(new ServiceDescriptor(type, registration.ImplementationInstance));\n        }\n        else if (registration.ImplementationFactory != null)\n        {\n            services.Add(new ServiceDescriptor(typeof(Decorator<TService>), provider =>\n            {\n                return new DisposableDecorator<TService>((TService)registration.ImplementationFactory(provider));\n            }, registration.Lifetime));\n        }\n        else\n        {\n            var type = registration.ImplementationType;\n            var innerType = typeof(Decorator<,>).MakeGenericType(typeof(TService), registration.ImplementationType);\n            services.Add(new ServiceDescriptor(typeof(Decorator<TService>), innerType, ServiceLifetime.Transient));\n            services.Add(new ServiceDescriptor(type, type, registration.Lifetime));\n        }\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/src/ProfileService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.AspNetIdentity;\n\n/// <summary>\n/// IProfileService to integrate with ASP.NET Identity.\n/// </summary>\n/// <typeparam name=\"TUser\">The type of the user.</typeparam>\n/// <seealso cref=\"IdentityServer8.Services.IProfileService\" />\npublic class ProfileService<TUser> : IProfileService\n    where TUser : class\n{\n    /// <summary>\n    /// The claims factory.\n    /// </summary>\n    protected readonly IUserClaimsPrincipalFactory<TUser> ClaimsFactory;\n    \n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger<ProfileService<TUser>> Logger;\n\n    /// <summary>\n    /// The user manager.\n    /// </summary>\n    protected readonly UserManager<TUser> UserManager;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ProfileService{TUser}\"/> class.\n    /// </summary>\n    /// <param name=\"userManager\">The user manager.</param>\n    /// <param name=\"claimsFactory\">The claims factory.</param>\n    public ProfileService(UserManager<TUser> userManager,\n        IUserClaimsPrincipalFactory<TUser> claimsFactory)\n    {\n        UserManager = userManager;\n        ClaimsFactory = claimsFactory;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ProfileService{TUser}\"/> class.\n    /// </summary>\n    /// <param name=\"userManager\">The user manager.</param>\n    /// <param name=\"claimsFactory\">The claims factory.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public ProfileService(UserManager<TUser> userManager,\n        IUserClaimsPrincipalFactory<TUser> claimsFactory,\n        ILogger<ProfileService<TUser>> logger)\n    {\n        UserManager = userManager;\n        ClaimsFactory = claimsFactory;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// This method is called whenever claims about the user are requested (e.g. during token creation or via the userinfo endpoint)\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public virtual async Task GetProfileDataAsync(ProfileDataRequestContext context)\n    {\n        var sub = context.Subject?.GetSubjectId();\n        if (sub == null) throw new Exception(\"No sub claim present\");\n\n        await GetProfileDataAsync(context, sub);\n    }\n\n    /// <summary>\n    /// Called to get the claims for the subject based on the profile request.\n    /// </summary>\n    /// <param name=\"context\"></param>\n    /// <param name=\"subjectId\"></param>\n    /// <returns></returns>\n    protected virtual async Task GetProfileDataAsync(ProfileDataRequestContext context, string subjectId)\n    {\n        var user = await FindUserAsync(subjectId);\n        if (user != null)\n        {\n            await GetProfileDataAsync(context, user);\n        }\n    }\n\n    /// <summary>\n    /// Called to get the claims for the user based on the profile request.\n    /// </summary>\n    /// <param name=\"context\"></param>\n    /// <param name=\"user\"></param>\n    /// <returns></returns>\n    protected virtual async Task GetProfileDataAsync(ProfileDataRequestContext context, TUser user)\n    {\n        var principal = await GetUserClaimsAsync(user);\n        context.AddRequestedClaims(principal.Claims);\n    }\n\n    /// <summary>\n    /// Gets the claims for a user.\n    /// </summary>\n    /// <param name=\"user\"></param>\n    /// <returns></returns>\n    protected virtual async Task<ClaimsPrincipal> GetUserClaimsAsync(TUser user)\n    {\n        var principal = await ClaimsFactory.CreateAsync(user);\n        if (principal == null) throw new Exception(\"ClaimsFactory failed to create a principal\");\n        \n        return principal;\n    }\n\n    /// <summary>\n    /// This method gets called whenever identity server needs to determine if the user is valid or active (e.g. if the user's account has been deactivated since they logged in).\n    /// (e.g. during token issuance or validation).\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public virtual async Task IsActiveAsync(IsActiveContext context)\n    {\n        var sub = context.Subject?.GetSubjectId();\n        if (sub == null) throw new Exception(\"No subject Id claim present\");\n\n        await IsActiveAsync(context, sub);\n    }\n\n    /// <summary>\n    /// Determines if the subject is active.\n    /// </summary>\n    /// <param name=\"context\"></param>\n    /// <param name=\"subjectId\"></param>\n    /// <returns></returns>\n    protected virtual async Task IsActiveAsync(IsActiveContext context, string subjectId)\n    {\n        var user = await FindUserAsync(subjectId);\n        if (user != null)\n        {\n            await IsActiveAsync(context, user);\n        }\n        else\n        {\n            context.IsActive = false;\n        }\n    }\n\n    /// <summary>\n    /// Determines if the user is active.\n    /// </summary>\n    /// <param name=\"context\"></param>\n    /// <param name=\"user\"></param>\n    /// <returns></returns>\n    protected virtual async Task IsActiveAsync(IsActiveContext context, TUser user)\n    {\n        context.IsActive = await IsUserActiveAsync(user);\n    }\n\n    /// <summary>\n    /// Returns if the user is active.\n    /// </summary>\n    /// <param name=\"user\"></param>\n    /// <returns></returns>\n    public virtual Task<bool> IsUserActiveAsync(TUser user)\n    {\n        return Task.FromResult(true);\n    }\n\n    /// <summary>\n    /// Loads the user by the subject id.\n    /// </summary>\n    /// <param name=\"subjectId\"></param>\n    /// <returns></returns>\n    protected virtual async Task<TUser> FindUserAsync(string subjectId)\n    {\n        var user = await UserManager.FindByIdAsync(subjectId);\n        if (user == null)\n        {\n            Logger?.LogWarning(\"No user found matching subject Id: {subjectId}\", subjectId);\n        }\n\n        return user;\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/src/ResourceOwnerPasswordValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.AspNetIdentity;\n\n/// <summary>\n/// IResourceOwnerPasswordValidator that integrates with ASP.NET Identity.\n/// </summary>\n/// <typeparam name=\"TUser\">The type of the user.</typeparam>\n/// <seealso cref=\"IdentityServer8.Validation.IResourceOwnerPasswordValidator\" />\npublic class ResourceOwnerPasswordValidator<TUser> : IResourceOwnerPasswordValidator\n    where TUser : class\n{\n    private readonly SignInManager<TUser> _signInManager;\n    private readonly UserManager<TUser> _userManager;\n    private readonly ILogger<ResourceOwnerPasswordValidator<TUser>> _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ResourceOwnerPasswordValidator{TUser}\"/> class.\n    /// </summary>\n    /// <param name=\"userManager\">The user manager.</param>\n    /// <param name=\"signInManager\">The sign in manager.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public ResourceOwnerPasswordValidator(\n        UserManager<TUser> userManager,\n        SignInManager<TUser> signInManager,\n        ILogger<ResourceOwnerPasswordValidator<TUser>> logger)\n    {\n        _userManager = userManager;\n        _signInManager = signInManager;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates the resource owner password credential\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public virtual async Task ValidateAsync(ResourceOwnerPasswordValidationContext context)\n    {\n        var user = await _userManager.FindByNameAsync(context.UserName);\n        if (user != null)\n        {\n            var result = await _signInManager.CheckPasswordSignInAsync(user, context.Password, true);\n            if (result.Succeeded)\n            {\n                var sub = await _userManager.GetUserIdAsync(user);\n\n                _logger.LogInformation(\"Credentials validated for username: {username}\", context.UserName);\n\n                context.Result = new GrantValidationResult(sub, AuthenticationMethods.Password);\n                return;\n            }\n            else if (result.IsLockedOut)\n            {\n                _logger.LogInformation(\"Authentication failed for username: {username}, reason: locked out\", context.UserName);\n            }\n            else if (result.IsNotAllowed)\n            {\n                _logger.LogInformation(\"Authentication failed for username: {username}, reason: not allowed\", context.UserName);\n            }\n            else\n            {\n                _logger.LogInformation(\"Authentication failed for username: {username}, reason: invalid credentials\", context.UserName);\n            }\n        }\n        else\n        {\n            _logger.LogInformation(\"No user found matching username: {username}\", context.UserName);\n        }\n\n        context.Result = new GrantValidationResult(TokenRequestErrors.InvalidGrant);\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/src/SecurityStampValidatorCallback.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.AspNetIdentity;\n\n/// <summary>\n/// Implements callback for SecurityStampValidator's OnRefreshingPrincipal event.\n/// </summary>\npublic class SecurityStampValidatorCallback\n{\n    /// <summary>\n    /// Maintains the claims captured at login time that are not being created by ASP.NET Identity.\n    /// This is needed to preserve claims such as idp, auth_time, amr.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public static Task UpdatePrincipal(SecurityStampRefreshingPrincipalContext context)\n    {\n        var newClaimTypes = context.NewPrincipal.Claims.Select(x => x.Type).ToArray();\n        var currentClaimsToKeep = context.CurrentPrincipal.Claims.Where(x => !newClaimTypes.Contains(x.Type)).ToArray();\n\n        var id = context.NewPrincipal.Identities.First();\n        id.AddClaims(currentClaimsToKeep);\n\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/AspNetIdentity/src/UserClaimsFactory.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.AspNetIdentity;\n\ninternal class UserClaimsFactory<TUser> : IUserClaimsPrincipalFactory<TUser>\n    where TUser : class\n{\n    private readonly Decorator<IUserClaimsPrincipalFactory<TUser>> _inner;\n    private UserManager<TUser> _userManager;\n\n    public UserClaimsFactory(Decorator<IUserClaimsPrincipalFactory<TUser>> inner, UserManager<TUser> userManager)\n    {\n        _inner = inner;\n        _userManager = userManager;\n    }\n\n    public async Task<ClaimsPrincipal> CreateAsync(TUser user)\n    {\n        var principal = await _inner.Instance.CreateAsync(user);\n        var identity = principal.Identities.First();\n\n        if (!identity.HasClaim(x => x.Type == JwtClaimTypes.Subject))\n        {\n            var sub = await _userManager.GetUserIdAsync(user);\n            identity.AddClaim(new Claim(JwtClaimTypes.Subject, sub));\n        }\n\n        var username = await _userManager.GetUserNameAsync(user);\n        var usernameClaim = identity.FindFirst(claim => claim.Type == _userManager.Options.ClaimsIdentity.UserNameClaimType && claim.Value == username);\n        if (usernameClaim != null)\n        {\n            identity.RemoveClaim(usernameClaim);\n            identity.AddClaim(new Claim(JwtClaimTypes.PreferredUserName, username));\n        }\n\n        if (!identity.HasClaim(x=>x.Type == JwtClaimTypes.Name))\n        {\n            identity.AddClaim(new Claim(JwtClaimTypes.Name, username));\n        }\n\n        if (_userManager.SupportsUserEmail)\n        {\n            var email = await _userManager.GetEmailAsync(user);\n            if (!String.IsNullOrWhiteSpace(email))\n            {\n                identity.AddClaims(new[]\n                {\n                    new Claim(JwtClaimTypes.Email, email),\n                    new Claim(JwtClaimTypes.EmailVerified,\n                        await _userManager.IsEmailConfirmedAsync(user) ? \"true\" : \"false\", ClaimValueTypes.Boolean)\n                });\n            }\n        }\n\n        if (_userManager.SupportsUserPhoneNumber)\n        {\n            var phoneNumber = await _userManager.GetPhoneNumberAsync(user);\n            if (!String.IsNullOrWhiteSpace(phoneNumber))\n            {\n                identity.AddClaims(new[]\n                {\n                    new Claim(JwtClaimTypes.PhoneNumber, phoneNumber),\n                    new Claim(JwtClaimTypes.PhoneNumberVerified,\n                        await _userManager.IsPhoneNumberConfirmedAsync(user) ? \"true\" : \"false\", ClaimValueTypes.Boolean)\n                });\n            }\n        }\n\n        return principal;\n    }\n}\n"
  },
  {
    "path": "src/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "src/Directory.BuildOld.targets",
    "content": "<Project>\n\n  <PropertyGroup>\n    <FrameworkVersion>3.1.0</FrameworkVersion>\n    <ExtensionsVersion>3.1.0</ExtensionsVersion>\n    <EntityFrameworkVersion>3.1.0</EntityFrameworkVersion>\n    \n    <IdentityServerVersion>4.1.2-*</IdentityServerVersion>\n  </PropertyGroup>\n\n  <ItemGroup>\n    <!--build related-->\n    <PackageReference Include=\"MinVer\" Version=\"2.3.0\" PrivateAssets=\"All\" />\n    <PackageReference Update=\"SimpleExec\" Version=\"6.2.0\" />\n    <PackageReference Update=\"Bullseye\" Version=\"3.3.0\" />\n    <PackageReference Update=\"Microsoft.SourceLink.GitHub\" Version=\"1.0.0\" PrivateAssets=\"All\" />\n\n    <!--tests -->\n    <PackageReference Update=\"FluentAssertions\" Version=\"5.10.2\" />\n    <PackageReference Update=\"Microsoft.NET.Test.Sdk\" Version=\"16.2.0\" />\n    <PackageReference Update=\"xunit\" Version=\"2.4.1\" />\n    <PackageReference Update=\"xunit.runner.visualstudio\" Version=\"2.4.1\" PrivateAssets=\"All\" />\n\n    <!--our stuff -->\n    <PackageReference Update=\"IdentityModel\" Version=\"4.4.0\" />\n\n    <PackageReference Update=\"IdentityServer8\" Version=\"$(IdentityServerVersion)\" />\n    <PackageReference Update=\"IdentityServer8.AspNetIdentity\" Version=\"$(IdentityServerVersion)\" />\n    <PackageReference Update=\"IdentityServer8.Storage\" Version=\"$(IdentityServerVersion)\" />\n    <PackageReference Update=\"IdentityServer8.EntityFramework.Storage\" Version=\"$(IdentityServerVersion)\" />\n    <PackageReference Update=\"IdentityServer8.EntityFramework\" Version=\"$(IdentityServerVersion)\" />\n\n    <!--microsoft extensions -->\n    <PackageReference Update=\"Microsoft.Extensions.Caching.Memory\" Version=\"$(ExtensionsVersion)\" />\n    <PackageReference Update=\"Microsoft.Extensions.Http\" Version=\"$(ExtensionsVersion)\" />\n    <PackageReference Update=\"Microsoft.Extensions.Http.Polly\" Version=\"$(ExtensionsVersion)\" />\n    <PackageReference Update=\"Microsoft.Extensions.Logging\" Version=\"$(ExtensionsVersion)\" />\n    <PackageReference Update=\"Microsoft.Extensions.Logging.Console\" Version=\"$(ExtensionsVersion)\" />\n    <PackageReference Update=\"Microsoft.Extensions.Options.ConfigurationExtensions\" Version=\"$(ExtensionsVersion)\" />\n    \n    <!--misc -->\n    <PackageReference Update=\"Newtonsoft.Json\" Version=\"12.0.2\" />\n    <PackageReference Update=\"Microsoft.IdentityModel.Protocols.OpenIdConnect\" Version=\"5.6.0\" />\n    <PackageReference Update=\"System.IdentityModel.Tokens.Jwt\" Version=\"[5.6.0,6.0)\" />\n    <PackageReference Update=\"System.Security.Principal.Windows\" Version=\"4.7.0\" />\n    <PackageReference Update=\"AutoMapper\" Version=\"[10.0.0,11.0)\" />\n    \n    <!--microsoft asp.net core -->\n    <PackageReference Update=\"Microsoft.AspNetCore.Authentication.OpenIdConnect\" Version=\"$(FrameworkVersion)\" />\n    <PackageReference Update=\"Microsoft.AspNetCore.TestHost\" Version=\"$(FrameworkVersion)\" />\n    <PackageReference Update=\"Microsoft.AspNetCore.Identity\" Version=\"$(FrameworkVersion)\" />\n    <PackageReference Update=\"Microsoft.AspNetCore.Identity.EntityFrameworkCore\" Version=\"$(FrameworkVersion)\" />\n    <PackageReference Update=\"Microsoft.AspNetCore.Mvc.NewtonsoftJson\" Version=\"$(FrameworkVersion)\" />\n    <PackageReference Update=\"Microsoft.AspNetCore.Authentication.Certificate\" Version=\"$(FrameworkVersion)\"/>\n    \n    <!--microsoft entity framework -->\n    <PackageReference Update=\"Microsoft.EntityFrameworkCore.Relational\" Version=\"$(EntityFrameworkVersion)\" />\n    <PackageReference Update=\"Microsoft.EntityFrameworkCore.Sqlite\" Version=\"$(EntityFrameworkVersion)\" />\n    <PackageReference Update=\"Microsoft.EntityFrameworkCore.InMemory\" Version=\"$(EntityFrameworkVersion)\" />\n    <PackageReference Update=\"Microsoft.EntityFrameworkCore.SqlServer\" Version=\"$(EntityFrameworkVersion)\" />\n    <PackageReference Update=\"Microsoft.EntityFrameworkCore.Design\" Version=\"$(EntityFrameworkVersion)\" PrivateAssets=\"All\" />\n\n  </ItemGroup>\n\n  <Target Name=\"SetAssemblyVersion\" AfterTargets=\"MinVer\">\n    <PropertyGroup>\n      <AssemblyVersion>$(MinVerMajor).$(MinVerMinor).$(MinVerPatch).0</AssemblyVersion>\n    </PropertyGroup>\n  </Target>\n</Project>"
  },
  {
    "path": "src/EntityFramework/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "src/EntityFramework/IdentityServer8.EntityFramework.sln",
    "content": "\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 16\nVisualStudioVersion = 16.0.29230.61\nMinimumVisualStudioVersion = 10.0.40219.1\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{8BFDA83B-FD73-4776-9C2C-5F7FFE440C1F}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.EntityFramework\", \"src\\IdentityServer8.EntityFramework.csproj\", \"{AB83F911-8B78-4973-A3A9-2A2D85581F25}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Host\", \"host\\Host.csproj\", \"{9E9EE58E-4B98-4495-8E8B-00281B3EABDA}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"seeding\", \"seeding\", \"{26921EED-9592-4174-94D6-8A0F604029F1}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"SqlServer\", \"migrations\\SqlServer\\SqlServer.csproj\", \"{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"tests\", \"tests\", \"{19FEB622-0912-4F5E-840F-827B4B9EF026}\"\nEndProject\nProject(\"{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}\") = \"IdentityServer8.EntityFramework.Tests\", \"test\\IdentityServer8.EntityFramework.Tests\\IdentityServer8.EntityFramework.Tests.csproj\", \"{E3685B06-F135-4318-B841-889C35479D5C}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tRelease|Any CPU = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{AB83F911-8B78-4973-A3A9-2A2D85581F25}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{AB83F911-8B78-4973-A3A9-2A2D85581F25}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{AB83F911-8B78-4973-A3A9-2A2D85581F25}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{AB83F911-8B78-4973-A3A9-2A2D85581F25}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{9E9EE58E-4B98-4495-8E8B-00281B3EABDA}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{9E9EE58E-4B98-4495-8E8B-00281B3EABDA}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{9E9EE58E-4B98-4495-8E8B-00281B3EABDA}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{9E9EE58E-4B98-4495-8E8B-00281B3EABDA}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{E3685B06-F135-4318-B841-889C35479D5C}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{E3685B06-F135-4318-B841-889C35479D5C}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{E3685B06-F135-4318-B841-889C35479D5C}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{E3685B06-F135-4318-B841-889C35479D5C}.Release|Any CPU.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{AB83F911-8B78-4973-A3A9-2A2D85581F25} = {8BFDA83B-FD73-4776-9C2C-5F7FFE440C1F}\n\t\t{9E9EE58E-4B98-4495-8E8B-00281B3EABDA} = {8BFDA83B-FD73-4776-9C2C-5F7FFE440C1F}\n\t\t{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69} = {26921EED-9592-4174-94D6-8A0F604029F1}\n\t\t{E3685B06-F135-4318-B841-889C35479D5C} = {19FEB622-0912-4F5E-840F-827B4B9EF026}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {A023D63E-FDD1-4984-9746-45981BCFBACA}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "src/EntityFramework/README.md",
    "content": "# IdentityServer8.EntityFramework\n\nIdentityServer8.EntityFramework is a package that provides the configuration APIs to add persistence for IdentityServer 4 configuration data that uses EntityFramework as its database abstraction.\n\n## Issues\n\nFor issues, use the [consolidated IdentityServer8 issue tracker](https://github.com/alexhiggins732/IdentityServer8/issues).\n"
  },
  {
    "path": "src/EntityFramework/build.cmd",
    "content": "@echo off\ndotnet run --project build -- %*"
  },
  {
    "path": "src/EntityFramework/build.ps1",
    "content": "$ErrorActionPreference = \"Stop\";\ndotnet run --project build -- $args"
  },
  {
    "path": "src/EntityFramework/build.sh",
    "content": "#!/usr/bin/env bash\nset -euo pipefail\ndotnet run --project build -- \"$@\""
  },
  {
    "path": "src/EntityFramework/dropdb.bat",
    "content": "cd src\\Host\ndotnet ef database drop -c PersistedGrantDbContext\ndotnet ef database drop -c ConfigurationDbContext\ncd ..\\..\n"
  },
  {
    "path": "src/EntityFramework/host/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.Configuration;\nglobal using IdentityServer8.Events;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Test;\nglobal using IdentityServer8.Validation;\nglobal using IdentityServerHost.Quickstart.UI;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.AspNetCore.Mvc.Filters;\nglobal using Microsoft.Extensions.Options;\nglobal using Newtonsoft.Json;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\nglobal using System.ComponentModel.DataAnnotations;\nglobal using System.Diagnostics;\nglobal using System.Security.Claims;\nglobal using System.Text;\nglobal using ILogger = Microsoft.Extensions.Logging.ILogger;\nglobal using ClaimValueTypes = System.Security.Claims.ClaimValueTypes;\n"
  },
  {
    "path": "src/EntityFramework/host/Host.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\src\\IdentityServer8.EntityFramework.csproj\" />\n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.Certificate\" />\n    \n    <PackageReference Include=\"Serilog.AspNetCore\" />\n\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.SqlServer\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.Design\" PrivateAssets=\"All\" />\n    <PackageReference Include=\"System.Security.Principal.Windows\" />\n  </ItemGroup>\n\n</Project>\n"
  },
  {
    "path": "src/EntityFramework/host/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost;\n\npublic class Program\n{\n        public static int Main(string[] args)\n        {\n            Console.Title = \"IdentityServer8.EntityFramework\";\n            Activity.DefaultIdFormat = ActivityIdFormat.W3C;\n\n            Log.Logger = new LoggerConfiguration()\n                .MinimumLevel.Debug()\n                .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n                .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n                .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n                .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n                .Enrich.FromLogContext()\n                //.WriteTo.File(@\"IdentityServer8_log.txt\")\n                // uncomment to write to Azure diagnostics stream\n                //.WriteTo.File(\n                //    @\"D:\\home\\LogFiles\\Application\\identityserver.txt\",\n                //    fileSizeLimitBytes: 1_000_000,\n                //    rollOnFileSizeLimit: true,\n                //    shared: true,\n                //    flushToDiskInterval: TimeSpan.FromSeconds(1))\n                .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n                .CreateLogger();\n\n            try\n            {\n                Log.Information(\"Starting host...\");\n                CreateHostBuilder(args).Build().Run();\n                return 0;\n            }\n            catch (Exception ex)\n            {\n                Log.Fatal(ex, \"Host terminated unexpectedly.\");\n                return 1;\n            }\n            finally\n            {\n                Log.CloseAndFlush();\n            }\n        }\n\n        public static IHostBuilder CreateHostBuilder(string[] args) =>\n            Host.CreateDefaultBuilder(args)\n                .UseSerilog()\n                .ConfigureWebHostDefaults(webBuilder =>\n                {\n                    webBuilder.UseStartup<Startup>();\n                });\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": true,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:5000\",\n      \"sslPort\": 44334\n    }\n  },\n  \"profiles\": {\n    \"Host\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001\"\n    }\n  }\n}"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Account/AccountController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller implements a typical login/logout/provision workflow for local and external accounts.\n/// The login service encapsulates the interactions with the user data store. This data store is in-memory only and cannot be used for production!\n/// The interaction service provides a way for the UI to communicate with identityserver for validation and context retrieval\n/// </summary>\n[SecurityHeaders]\n[AllowAnonymous]\npublic class AccountController : Controller\n{\n        private readonly TestUserStore _users;\n        private readonly IIdentityServerInteractionService _interaction;\n        private readonly IClientStore _clientStore;\n        private readonly IAuthenticationSchemeProvider _schemeProvider;\n        private readonly IEventService _events;\n\n        public AccountController(\n            IIdentityServerInteractionService interaction,\n            IClientStore clientStore,\n            IAuthenticationSchemeProvider schemeProvider,\n            IEventService events,\n            TestUserStore users = null)\n        {\n            // if the TestUserStore is not in DI, then we'll just use the global users collection\n            // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n            _users = users ?? new TestUserStore(TestUsers.Users);\n\n            _interaction = interaction;\n            _clientStore = clientStore;\n            _schemeProvider = schemeProvider;\n            _events = events;\n        }\n\n        /// <summary>\n        /// Entry point into the login workflow\n        /// </summary>\n        [HttpGet]\n        public async Task<IActionResult> Login(string returnUrl)\n        {\n            // build a model so we know what to show on the login page\n            var vm = await BuildLoginViewModelAsync(returnUrl);\n\n            if (vm.IsExternalLoginOnly)\n            {\n                // we only have one option for logging in and it's an external provider\n            return returnUrl.IsAllowedRedirect() ? RedirectToAction(\"Challenge\", \"External\", new { scheme = vm.ExternalLoginScheme, returnUrl = returnUrl.SanitizeForRedirect() }) : Forbid();\n            }\n\n            return View(vm);\n        }\n\n        /// <summary>\n        /// Handle postback from username/password login\n        /// </summary>\n        [HttpPost]\n        [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Login(LoginInputModel model)\n        {\n            // check if we are in the context of an authorization request\n            var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n            if (ModelState.IsValid)\n            {\n                // validate username/password against in-memory store\n                if (_users.ValidateCredentials(model.Username, model.Password))\n                {\n                    var user = _users.FindByUsername(model.Username);\n                    await _events.RaiseAsync(new UserLoginSuccessEvent(user.Username, user.SubjectId, user.Username, clientId: context?.Client.ClientId));\n\n                    // only set explicit expiration here if user chooses \"remember me\". \n                    // otherwise we rely upon expiration configured in cookie middleware.\n                    AuthenticationProperties props = null;\n                    if (AccountOptions.AllowRememberLogin && model.RememberLogin)\n                    {\n                        props = new AuthenticationProperties\n                        {\n                            IsPersistent = true,\n                            ExpiresUtc = DateTimeOffset.UtcNow.Add(AccountOptions.RememberMeLoginDuration)\n                        };\n                    };\n\n                    // issue authentication cookie with subject ID and username\n                    var isuser = new IdentityServerUser(user.SubjectId)\n                    {\n                        DisplayName = user.Username\n                    };\n\n                    await HttpContext.SignInAsync(isuser, props);\n\n                    if (context != null)\n                    {\n                        if (context.IsNativeClient())\n                        {\n                            // The client is native, so this change in how to\n                            // return the response is for better UX for the end user.\n                        return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                        }\n\n                        // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                    }\n\n                    // request for a local page\n                    if (Url.IsLocalUrl(model.ReturnUrl))\n                    {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                    }\n                    else if (string.IsNullOrEmpty(model.ReturnUrl))\n                    {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n                    }\n                    else\n                    {\n                        // user might have clicked on a malicious link - should be logged\n                        throw new Exception(\"invalid return URL\");\n                    }\n                }\n\n            await _events.RaiseAsync(new UserLoginFailureEvent(model.Username, \"invalid credentials\", clientId: context?.Client.ClientId));\n                ModelState.AddModelError(string.Empty, AccountOptions.InvalidCredentialsErrorMessage);\n            }\n\n            // something went wrong, show form with error\n            var vm = await BuildLoginViewModelAsync(model);\n            return View(vm);\n        }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> LoginCancel(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (context != null)\n        {\n            // if the user cancels, send a result back into IdentityServer as if they \n            // denied the consent (even if this client does not require consent).\n            // this will send back an access denied OIDC error response to the client.\n            await _interaction.DenyAuthorizationAsync(context, AuthorizationError.AccessDenied);\n\n            // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n            }\n\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n        }\n        else\n        {\n            // since we don't have a valid context, then we just go back to the home page\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n        }\n\n    }\n        \n        /// <summary>\n        /// Show logout page\n        /// </summary>\n        [HttpGet]\n        public async Task<IActionResult> Logout(string logoutId)\n        {\n            // build a model so the logout page knows what to display\n            var vm = await BuildLogoutViewModelAsync(logoutId);\n\n            if (vm.ShowLogoutPrompt == false)\n            {\n                // if the request for logout was properly authenticated from IdentityServer, then\n                // we don't need to show the prompt and can just log the user out directly.\n                return await Logout(vm);\n            }\n\n            return View(vm);\n        }\n\n        /// <summary>\n        /// Handle logout page postback\n        /// </summary>\n        [HttpPost]\n        [ValidateAntiForgeryToken]\n        public async Task<IActionResult> Logout(LogoutInputModel model)\n        {\n            // build a model so the logged out page knows what to display\n            var vm = await BuildLoggedOutViewModelAsync(model.LogoutId);\n\n            if (User?.Identity.IsAuthenticated == true)\n            {\n                // delete local authentication cookie\n                await HttpContext.SignOutAsync();\n\n                // raise the logout event\n                await _events.RaiseAsync(new UserLogoutSuccessEvent(User.GetSubjectId(), User.GetDisplayName()));\n            }\n\n            // check if we need to trigger sign-out at an upstream identity provider\n            if (vm.TriggerExternalSignout)\n            {\n                // build a return URL so the upstream provider will redirect back\n                // to us after the user has logged out. this allows us to then\n                // complete our single sign-out processing.\n                string url = Url.Action(\"Logout\", new { logoutId = vm.LogoutId });\n\n                // this triggers a redirect to the external provider for sign-out\n                return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);\n            }\n\n            return View(\"LoggedOut\", vm);\n        }\n\n        [HttpGet]\n        public IActionResult AccessDenied()\n        {\n            return View();\n        }\n\n\n        /*****************************************/\n        /* helper APIs for the AccountController */\n        /*****************************************/\n        private async Task<LoginViewModel> BuildLoginViewModelAsync(string returnUrl)\n        {\n            var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n            if (context?.IdP != null && await _schemeProvider.GetSchemeAsync(context.IdP) != null)\n            {\n                var local = context.IdP == IdentityServer8.IdentityServerConstants.LocalIdentityProvider;\n\n                // this is meant to short circuit the UI and only trigger the one external IdP\n                var vm = new LoginViewModel\n                {\n                    EnableLocalLogin = local,\n                    ReturnUrl = returnUrl,\n                    Username = context?.LoginHint,\n                };\n\n                if (!local)\n                {\n                    vm.ExternalProviders = new[] { new ExternalProvider { AuthenticationScheme = context.IdP } };\n                }\n\n                return vm;\n            }\n\n            var schemes = await _schemeProvider.GetAllSchemesAsync();\n\n            var providers = schemes\n                .Where(x => x.DisplayName != null)\n                .Select(x => new ExternalProvider\n                {\n                    DisplayName = x.DisplayName ?? x.Name,\n                    AuthenticationScheme = x.Name\n                }).ToList();\n\n            var allowLocal = true;\n            if (context?.Client.ClientId != null)\n            {\n                var client = await _clientStore.FindEnabledClientByIdAsync(context.Client.ClientId);\n                if (client != null)\n                {\n                    allowLocal = client.EnableLocalLogin;\n\n                    if (client.IdentityProviderRestrictions != null && client.IdentityProviderRestrictions.Any())\n                    {\n                        providers = providers.Where(provider => client.IdentityProviderRestrictions.Contains(provider.AuthenticationScheme)).ToList();\n                    }\n                }\n            }\n\n            return new LoginViewModel\n            {\n                AllowRememberLogin = AccountOptions.AllowRememberLogin,\n                EnableLocalLogin = allowLocal && AccountOptions.AllowLocalLogin,\n                ReturnUrl = returnUrl,\n                Username = context?.LoginHint,\n                ExternalProviders = providers.ToArray()\n            };\n        }\n\n        private async Task<LoginViewModel> BuildLoginViewModelAsync(LoginInputModel model)\n        {\n            var vm = await BuildLoginViewModelAsync(model.ReturnUrl);\n            vm.Username = model.Username;\n            vm.RememberLogin = model.RememberLogin;\n            return vm;\n        }\n\n        private async Task<LogoutViewModel> BuildLogoutViewModelAsync(string logoutId)\n        {\n            var vm = new LogoutViewModel { LogoutId = logoutId, ShowLogoutPrompt = AccountOptions.ShowLogoutPrompt };\n\n            if (User?.Identity.IsAuthenticated != true)\n            {\n                // if the user is not authenticated, then just show logged out page\n                vm.ShowLogoutPrompt = false;\n                return vm;\n            }\n\n            var context = await _interaction.GetLogoutContextAsync(logoutId);\n            if (context?.ShowSignoutPrompt == false)\n            {\n                // it's safe to automatically sign-out\n                vm.ShowLogoutPrompt = false;\n                return vm;\n            }\n\n            // show the logout prompt. this prevents attacks where the user\n            // is automatically signed out by another malicious web page.\n            return vm;\n        }\n\n        private async Task<LoggedOutViewModel> BuildLoggedOutViewModelAsync(string logoutId)\n        {\n            // get context information (client name, post logout redirect URI and iframe for federated signout)\n            var logout = await _interaction.GetLogoutContextAsync(logoutId);\n\n            var vm = new LoggedOutViewModel\n            {\n                AutomaticRedirectAfterSignOut = AccountOptions.AutomaticRedirectAfterSignOut,\n                PostLogoutRedirectUri = logout?.PostLogoutRedirectUri,\n                ClientName = string.IsNullOrEmpty(logout?.ClientName) ? logout?.ClientId : logout?.ClientName,\n                SignOutIframeUrl = logout?.SignOutIFrameUrl,\n                LogoutId = logoutId\n            };\n\n            if (User?.Identity.IsAuthenticated == true)\n            {\n                var idp = User.FindFirst(JwtClaimTypes.IdentityProvider)?.Value;\n                if (idp != null && idp != IdentityServer8.IdentityServerConstants.LocalIdentityProvider)\n                {\n                    var providerSupportsSignout = await HttpContext.GetSchemeSupportsSignOutAsync(idp);\n                    if (providerSupportsSignout)\n                    {\n                        if (vm.LogoutId == null)\n                        {\n                            // if there's no current logout context, we need to create one\n                            // this captures necessary info from the current logged in user\n                            // before we signout and redirect away to the external IdP for signout\n                            vm.LogoutId = await _interaction.CreateLogoutContextAsync();\n                        }\n\n                        vm.ExternalAuthenticationScheme = idp;\n                    }\n                }\n            }\n\n            return vm;\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Account/AccountOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class AccountOptions\n{\n    public static bool AllowLocalLogin = true;\n    public static bool AllowRememberLogin = true;\n    public static TimeSpan RememberMeLoginDuration = TimeSpan.FromDays(30);\n\n    public static bool ShowLogoutPrompt = true;\n    public static bool AutomaticRedirectAfterSignOut = false;\n\n    public static string InvalidCredentialsErrorMessage = \"Invalid username or password\";\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Account/ExternalController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class ExternalController : Controller\n{\n        private readonly TestUserStore _users;\n        private readonly IIdentityServerInteractionService _interaction;\n        private readonly IClientStore _clientStore;\n        private readonly ILogger<ExternalController> _logger;\n        private readonly IEventService _events;\n\n        public ExternalController(\n            IIdentityServerInteractionService interaction,\n            IClientStore clientStore,\n            IEventService events,\n            ILogger<ExternalController> logger,\n            TestUserStore users = null)\n        {\n            // if the TestUserStore is not in DI, then we'll just use the global users collection\n            // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n            _users = users ?? new TestUserStore(TestUsers.Users);\n\n            _interaction = interaction;\n            _clientStore = clientStore;\n            _logger = logger;\n            _events = events;\n        }\n\n        /// <summary>\n        /// initiate roundtrip to external authentication provider\n        /// </summary>\n        [HttpGet]\n        public IActionResult Challenge(string scheme, string returnUrl)\n        {\n            if (string.IsNullOrEmpty(returnUrl)) returnUrl = \"~/\";\n\n            // validate returnUrl - either it is a valid OIDC URL or back to a local page\n            if (Url.IsLocalUrl(returnUrl) == false && _interaction.IsValidReturnUrl(returnUrl) == false)\n            {\n                // user might have clicked on a malicious link - should be logged\n                throw new Exception(\"invalid return URL\");\n            }\n            \n            // start challenge and roundtrip the return URL and scheme \n            var props = new AuthenticationProperties\n            {\n                RedirectUri = Url.Action(nameof(Callback)), \n                Items =\n                {\n                    { \"returnUrl\", returnUrl }, \n                    { \"scheme\", scheme },\n                }\n            };\n\n            return Challenge(props, scheme);\n            \n        }\n\n        /// <summary>\n        /// Post processing of external authentication\n        /// </summary>\n        [HttpGet]\n        public async Task<IActionResult> Callback()\n        {\n            // read external identity from the temporary cookie\n            var result = await HttpContext.AuthenticateAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n            if (result?.Succeeded != true)\n            {\n                throw new Exception(\"External authentication error\");\n            }\n\n            if (_logger.IsEnabled(LogLevel.Debug))\n            {\n                var externalClaims = result.Principal.Claims.Select(c => $\"{c.Type}: {c.Value}\");\n                _logger.LogDebug(\"External claims: {@claims}\", externalClaims);\n            }\n\n            // lookup our user and external provider info\n            var (user, provider, providerUserId, claims) = FindUserFromExternalProvider(result);\n            if (user == null)\n            {\n                // this might be where you might initiate a custom workflow for user registration\n                // in this sample we don't show how that would be done, as our sample implementation\n                // simply auto-provisions new external user\n                user = AutoProvisionUser(provider, providerUserId, claims);\n            }\n\n            // this allows us to collect any additional claims or properties\n            // for the specific protocols used and store them in the local auth cookie.\n            // this is typically used to store data needed for signout from those protocols.\n            var additionalLocalClaims = new List<Claim>();\n            var localSignInProps = new AuthenticationProperties();\n            ProcessLoginCallback(result, additionalLocalClaims, localSignInProps);\n            \n            // issue authentication cookie for user\n            var isuser = new IdentityServerUser(user.SubjectId)\n            {\n                DisplayName = user.Username,\n                IdentityProvider = provider,\n                AdditionalClaims = additionalLocalClaims\n            };\n\n            await HttpContext.SignInAsync(isuser, localSignInProps);\n\n            // delete temporary cookie used during external authentication\n            await HttpContext.SignOutAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n            // retrieve return URL\n            var returnUrl = result.Properties.Items[\"returnUrl\"] ?? \"~/\";\n\n            // check if external login is in the context of an OIDC request\n            var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n            await _events.RaiseAsync(new UserLoginSuccessEvent(provider, providerUserId, user.SubjectId, user.Username, true, context?.Client.ClientId));\n\n            if (context != null)\n            {\n                if (context.IsNativeClient())\n                {\n                    // The client is native, so this change in how to\n                    // return the response is for better UX for the end user.\n                    return this.LoadingPage(\"Redirect\", returnUrl);\n                }\n            }\n\n            return Redirect(returnUrl);\n        }\n\n        private (TestUser user, string provider, string providerUserId, IEnumerable<Claim> claims) FindUserFromExternalProvider(AuthenticateResult result)\n        {\n            var externalUser = result.Principal;\n\n            // try to determine the unique id of the external user (issued by the provider)\n            // the most common claim type for that are the sub claim and the NameIdentifier\n            // depending on the external provider, some other claim type might be used\n            var userIdClaim = externalUser.FindFirst(JwtClaimTypes.Subject) ??\n                              externalUser.FindFirst(ClaimTypes.NameIdentifier) ??\n                              throw new Exception(\"Unknown userid\");\n\n            // remove the user id claim so we don't include it as an extra claim if/when we provision the user\n            var claims = externalUser.Claims.ToList();\n            claims.Remove(userIdClaim);\n\n            var provider = result.Properties.Items[\"scheme\"];\n            var providerUserId = userIdClaim.Value;\n\n            // find external user\n            var user = _users.FindByExternalProvider(provider, providerUserId);\n\n            return (user, provider, providerUserId, claims);\n        }\n\n        private TestUser AutoProvisionUser(string provider, string providerUserId, IEnumerable<Claim> claims)\n        {\n            var user = _users.AutoProvisionUser(provider, providerUserId, claims.ToList());\n            return user;\n        }\n\n        // if the external login is OIDC-based, there are certain things we need to preserve to make logout work\n        // this will be different for WS-Fed, SAML2p or other protocols\n        private void ProcessLoginCallback(AuthenticateResult externalResult, List<Claim> localClaims, AuthenticationProperties localSignInProps)\n        {\n            // if the external system sent a session id claim, copy it over\n            // so we can use it for single sign-out\n            var sid = externalResult.Principal.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.SessionId);\n            if (sid != null)\n            {\n                localClaims.Add(new Claim(JwtClaimTypes.SessionId, sid.Value));\n            }\n\n            // if the external provider issued an id_token, we'll keep it for signout\n            var idToken = externalResult.Properties.GetTokenValue(\"id_token\");\n            if (idToken != null)\n            {\n                localSignInProps.StoreTokens(new[] { new AuthenticationToken { Name = \"id_token\", Value = idToken } });\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Account/ExternalProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ExternalProvider\n{\n    public string DisplayName { get; set; }\n    public string AuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Account/LoggedOutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoggedOutViewModel\n{\n    public string PostLogoutRedirectUri { get; set; }\n    public string ClientName { get; set; }\n    public string SignOutIframeUrl { get; set; }\n\n    public bool AutomaticRedirectAfterSignOut { get; set; }\n\n    public string LogoutId { get; set; }\n    public bool TriggerExternalSignout => ExternalAuthenticationScheme != null;\n    public string ExternalAuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Account/LoginInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginInputModel\n{\n    [Required]\n    public string Username { get; set; }\n    [Required]\n    public string Password { get; set; }\n    public bool RememberLogin { get; set; }\n    public string ReturnUrl { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Account/LoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginViewModel : LoginInputModel\n{\n    public bool AllowRememberLogin { get; set; } = true;\n    public bool EnableLocalLogin { get; set; } = true;\n\n    public IEnumerable<ExternalProvider> ExternalProviders { get; set; } = Enumerable.Empty<ExternalProvider>();\n    public IEnumerable<ExternalProvider> VisibleExternalProviders => ExternalProviders.Where(x => !String.IsNullOrWhiteSpace(x.DisplayName));\n\n    public bool IsExternalLoginOnly => EnableLocalLogin == false && ExternalProviders?.Count() == 1;\n    public string ExternalLoginScheme => IsExternalLoginOnly ? ExternalProviders?.SingleOrDefault()?.AuthenticationScheme : null;\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Account/LogoutInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutInputModel\n{\n        public string LogoutId { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Account/LogoutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutViewModel : LogoutInputModel\n{\n        public bool ShowLogoutPrompt { get; set; } = true;\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Account/RedirectViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class RedirectViewModel\n{\n        public string RedirectUrl { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Consent/ConsentController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This controller processes the consent UI\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class ConsentController : Controller\n{\n        private readonly IIdentityServerInteractionService _interaction;\n        private readonly IEventService _events;\n        private readonly ILogger<ConsentController> _logger;\n\n        public ConsentController(\n            IIdentityServerInteractionService interaction,\n            IEventService events,\n            ILogger<ConsentController> logger)\n        {\n            _interaction = interaction;\n            _events = events;\n            _logger = logger;\n        }\n\n        /// <summary>\n        /// Shows the consent screen\n        /// </summary>\n        /// <param name=\"returnUrl\"></param>\n        /// <returns></returns>\n        [HttpGet]\n        public async Task<IActionResult> Index(string returnUrl)\n        {\n            var vm = await BuildViewModelAsync(returnUrl);\n            if (vm != null)\n            {\n                return View(\"Index\", vm);\n            }\n\n            return View(\"Error\");\n        }\n\n        /// <summary>\n        /// Handles the consent screen postback\n        /// </summary>\n        [HttpPost]\n        [ValidateAntiForgeryToken]\n        public async Task<IActionResult> Index(ConsentInputModel model)\n        {\n            var result = await ProcessConsent(model);\n\n            if (result.IsRedirect)\n            {\n                var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n                if (context?.IsNativeClient() == true)\n                {\n                    // The client is native, so this change in how to\n                    // return the response is for better UX for the end user.\n                    return this.LoadingPage(\"Redirect\", result.RedirectUri);\n                }\n            return result.RedirectUri.IsAllowedRedirect() ? Redirect(result.RedirectUri.SanitizeForRedirect()) : Forbid();\n            }\n\n            if (result.HasValidationError)\n            {\n                ModelState.AddModelError(string.Empty, result.ValidationError);\n            }\n\n            if (result.ShowView)\n            {\n                return View(\"Index\", result.ViewModel);\n            }\n\n            return View(\"Error\");\n        }\n\n        /*****************************************/\n        /* helper APIs for the ConsentController */\n        /*****************************************/\n        private async Task<ProcessConsentResult> ProcessConsent(ConsentInputModel model)\n        {\n            var result = new ProcessConsentResult();\n\n            // validate return url is still valid\n            var request = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n            if (request == null) return result;\n\n            ConsentResponse grantedConsent = null;\n\n            // user clicked 'no' - send back the standard 'access_denied' response\n            if (model?.Button == \"no\")\n            {\n                grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n            }\n            // user clicked 'yes' - validate the data\n            else if (model?.Button == \"yes\")\n            {\n                // if the user consented to some scope, build the response model\n                if (model.ScopesConsented != null && model.ScopesConsented.Any())\n                {\n                    var scopes = model.ScopesConsented;\n                    if (ConsentOptions.EnableOfflineAccess == false)\n                    {\n                        scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                    }\n\n                    grantedConsent = new ConsentResponse\n                    {\n                        RememberConsent = model.RememberConsent,\n                        ScopesValuesConsented = scopes.ToArray(),\n                        Description = model.Description\n                    };\n\n                    // emit event\n                    await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n                }\n                else\n                {\n                    result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n                }\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n            }\n\n            if (grantedConsent != null)\n            {\n                // communicate outcome of consent back to identityserver\n                await _interaction.GrantConsentAsync(request, grantedConsent);\n\n                // indicate that's it ok to redirect back to authorization endpoint\n                result.RedirectUri = model.ReturnUrl;\n                result.Client = request.Client;\n            }\n            else\n            {\n                // we need to redisplay the consent UI\n                result.ViewModel = await BuildViewModelAsync(model.ReturnUrl, model);\n            }\n\n            return result;\n        }\n\n        private async Task<ConsentViewModel> BuildViewModelAsync(string returnUrl, ConsentInputModel model = null)\n        {\n            var request = await _interaction.GetAuthorizationContextAsync(returnUrl);\n            if (request != null)\n            {\n                return CreateConsentViewModel(model, returnUrl, request);\n            }\n            else\n            {\n            _logger.LogError(\"No consent request matching request: {0}\", returnUrl.SanitizeForLog());\n            }\n\n            return null;\n        }\n\n        private ConsentViewModel CreateConsentViewModel(\n            ConsentInputModel model, string returnUrl,\n            AuthorizationRequest request)\n        {\n            var vm = new ConsentViewModel\n            {\n                RememberConsent = model?.RememberConsent ?? true,\n                ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n                Description = model?.Description,\n\n                ReturnUrl = returnUrl,\n\n                ClientName = request.Client.ClientName ?? request.Client.ClientId,\n                ClientUrl = request.Client.ClientUri,\n                ClientLogoUrl = request.Client.LogoUri,\n                AllowRememberConsent = request.Client.AllowRememberConsent\n            };\n\n            vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n            var apiScopes = new List<ScopeViewModel>();\n            foreach(var parsedScope in request.ValidatedResources.ParsedScopes)\n            {\n                var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n                if (apiScope != null)\n                {\n                    var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                    apiScopes.Add(scopeVm);\n                }\n            }\n            if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n            {\n                apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n            }\n            vm.ApiScopes = apiScopes;\n\n            return vm;\n        }\n\n        private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n        {\n            return new ScopeViewModel\n            {\n                Value = identity.Name,\n                DisplayName = identity.DisplayName ?? identity.Name,\n                Description = identity.Description,\n                Emphasize = identity.Emphasize,\n                Required = identity.Required,\n                Checked = check || identity.Required\n            };\n        }\n\n        public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n        {\n            var displayName = apiScope.DisplayName ?? apiScope.Name;\n            if (!String.IsNullOrWhiteSpace(parsedScopeValue.ParsedParameter))\n            {\n                displayName += \":\" + parsedScopeValue.ParsedParameter;\n            }\n\n            return new ScopeViewModel\n            {\n                Value = parsedScopeValue.RawValue,\n                DisplayName = displayName,\n                Description = apiScope.Description,\n                Emphasize = apiScope.Emphasize,\n                Required = apiScope.Required,\n                Checked = check || apiScope.Required\n            };\n        }\n\n        private ScopeViewModel GetOfflineAccessScope(bool check)\n        {\n            return new ScopeViewModel\n            {\n                Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n                DisplayName = ConsentOptions.OfflineAccessDisplayName,\n                Description = ConsentOptions.OfflineAccessDescription,\n                Emphasize = true,\n                Checked = check\n            };\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Consent/ConsentInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentInputModel\n{\n        public string Button { get; set; }\n        public IEnumerable<string> ScopesConsented { get; set; }\n        public bool RememberConsent { get; set; }\n        public string ReturnUrl { get; set; }\n        public string Description { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Consent/ConsentOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentOptions\n{\n        public static bool EnableOfflineAccess = true;\n        public static string OfflineAccessDisplayName = \"Offline Access\";\n        public static string OfflineAccessDescription = \"Access to your applications and resources, even when you are offline\";\n\n        public static readonly string MustChooseOneErrorMessage = \"You must pick at least one permission\";\n        public static readonly string InvalidSelectionErrorMessage = \"Invalid selection\";\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Consent/ConsentViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentViewModel : ConsentInputModel\n{\n        public string ClientName { get; set; }\n        public string ClientUrl { get; set; }\n        public string ClientLogoUrl { get; set; }\n        public bool AllowRememberConsent { get; set; }\n\n        public IEnumerable<ScopeViewModel> IdentityScopes { get; set; }\n        public IEnumerable<ScopeViewModel> ApiScopes { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Consent/ProcessConsentResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ProcessConsentResult\n{\n        public bool IsRedirect => RedirectUri != null;\n        public string RedirectUri { get; set; }\n        public Client Client { get; set; }\n\n        public bool ShowView => ViewModel != null;\n        public ConsentViewModel ViewModel { get; set; }\n\n        public bool HasValidationError => ValidationError != null;\n        public string ValidationError { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Consent/ScopeViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ScopeViewModel\n{\n        public string Value { get; set; }\n        public string DisplayName { get; set; }\n        public string Description { get; set; }\n        public bool Emphasize { get; set; }\n        public bool Required { get; set; }\n        public bool Checked { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Device/DeviceAuthorizationInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationInputModel : ConsentInputModel\n{\n        public string UserCode { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Device/DeviceAuthorizationViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationViewModel : ConsentViewModel\n{\n        public string UserCode { get; set; }\n        public bool ConfirmUserCode { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Device/DeviceController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[Authorize]\n[SecurityHeaders]\npublic class DeviceController : Controller\n{\n        private readonly IDeviceFlowInteractionService _interaction;\n        private readonly IEventService _events;\n        private readonly IOptions<IdentityServerOptions> _options;\n        private readonly ILogger<DeviceController> _logger;\n\n        public DeviceController(\n            IDeviceFlowInteractionService interaction,\n            IEventService eventService,\n            IOptions<IdentityServerOptions> options,\n            ILogger<DeviceController> logger)\n        {\n            _interaction = interaction;\n            _events = eventService;\n            _options = options;\n            _logger = logger;\n        }\n\n        [HttpGet]\n        public async Task<IActionResult> Index()\n        {\n            string userCodeParamName = _options.Value.UserInteraction.DeviceVerificationUserCodeParameter;\n            string userCode = Request.Query[userCodeParamName];\n            if (string.IsNullOrWhiteSpace(userCode)) return View(\"UserCodeCapture\");\n\n            var vm = await BuildViewModelAsync(userCode);\n            if (vm == null) return View(\"Error\");\n\n            vm.ConfirmUserCode = true;\n            return View(\"UserCodeConfirmation\", vm);\n        }\n\n        [HttpPost]\n        [ValidateAntiForgeryToken]\n        public async Task<IActionResult> UserCodeCapture(string userCode)\n        {\n            var vm = await BuildViewModelAsync(userCode);\n            if (vm == null) return View(\"Error\");\n\n            return View(\"UserCodeConfirmation\", vm);\n        }\n\n        [HttpPost]\n        [ValidateAntiForgeryToken]\n        public async Task<IActionResult> Callback(DeviceAuthorizationInputModel model)\n        {\n            if (model == null) throw new ArgumentNullException(nameof(model));\n\n            var result = await ProcessConsent(model);\n            if (result.HasValidationError) return View(\"Error\");\n\n            return View(\"Success\");\n        }\n\n        private async Task<ProcessConsentResult> ProcessConsent(DeviceAuthorizationInputModel model)\n        {\n            var result = new ProcessConsentResult();\n\n            var request = await _interaction.GetAuthorizationContextAsync(model.UserCode);\n            if (request == null) return result;\n\n            ConsentResponse grantedConsent = null;\n\n            // user clicked 'no' - send back the standard 'access_denied' response\n            if (model.Button == \"no\")\n            {\n                grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n            }\n            // user clicked 'yes' - validate the data\n            else if (model.Button == \"yes\")\n            {\n                // if the user consented to some scope, build the response model\n                if (model.ScopesConsented != null && model.ScopesConsented.Any())\n                {\n                    var scopes = model.ScopesConsented;\n                    if (ConsentOptions.EnableOfflineAccess == false)\n                    {\n                        scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                    }\n\n                    grantedConsent = new ConsentResponse\n                    {\n                        RememberConsent = model.RememberConsent,\n                        ScopesValuesConsented = scopes.ToArray(),\n                        Description = model.Description\n                    };\n\n                    // emit event\n                    await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n                }\n                else\n                {\n                    result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n                }\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n            }\n\n            if (grantedConsent != null)\n            {\n                // communicate outcome of consent back to identityserver\n                await _interaction.HandleRequestAsync(model.UserCode, grantedConsent);\n\n                // indicate that's it ok to redirect back to authorization endpoint\n                result.RedirectUri = model.ReturnUrl;\n                result.Client = request.Client;\n            }\n            else\n            {\n                // we need to redisplay the consent UI\n                result.ViewModel = await BuildViewModelAsync(model.UserCode, model);\n            }\n\n            return result;\n        }\n\n        private async Task<DeviceAuthorizationViewModel> BuildViewModelAsync(string userCode, DeviceAuthorizationInputModel model = null)\n        {\n            var request = await _interaction.GetAuthorizationContextAsync(userCode);\n            if (request != null)\n            {\n                return CreateConsentViewModel(userCode, model, request);\n            }\n\n            return null;\n        }\n\n        private DeviceAuthorizationViewModel CreateConsentViewModel(string userCode, DeviceAuthorizationInputModel model, DeviceFlowAuthorizationRequest request)\n        {\n            var vm = new DeviceAuthorizationViewModel\n            {\n                UserCode = userCode,\n                Description = model?.Description,\n\n                RememberConsent = model?.RememberConsent ?? true,\n                ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n\n                ClientName = request.Client.ClientName ?? request.Client.ClientId,\n                ClientUrl = request.Client.ClientUri,\n                ClientLogoUrl = request.Client.LogoUri,\n                AllowRememberConsent = request.Client.AllowRememberConsent\n            };\n\n            vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n            var apiScopes = new List<ScopeViewModel>();\n            foreach (var parsedScope in request.ValidatedResources.ParsedScopes)\n            {\n                var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n                if (apiScope != null)\n                {\n                    var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                    apiScopes.Add(scopeVm);\n                }\n            }\n            if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n            {\n                apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n            }\n            vm.ApiScopes = apiScopes;\n\n            return vm;\n        }\n\n        private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n        {\n            return new ScopeViewModel\n            {\n                Value = identity.Name,\n                DisplayName = identity.DisplayName ?? identity.Name,\n                Description = identity.Description,\n                Emphasize = identity.Emphasize,\n                Required = identity.Required,\n                Checked = check || identity.Required\n            };\n        }\n\n        public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n        {\n            return new ScopeViewModel\n            {\n                Value = parsedScopeValue.RawValue,\n                // todo: use the parsed scope value in the display?\n                DisplayName = apiScope.DisplayName ?? apiScope.Name,\n                Description = apiScope.Description,\n                Emphasize = apiScope.Emphasize,\n                Required = apiScope.Required,\n                Checked = check || apiScope.Required\n            };\n        }\n        private ScopeViewModel GetOfflineAccessScope(bool check)\n        {\n            return new ScopeViewModel\n            {\n                Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n                DisplayName = ConsentOptions.OfflineAccessDisplayName,\n                Description = ConsentOptions.OfflineAccessDescription,\n                Emphasize = true,\n                Checked = check\n            };\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Diagnostics/DiagnosticsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[Authorize]\npublic class DiagnosticsController : Controller\n{\n        public async Task<IActionResult> Index()\n        {\n            var localAddresses = new string[] { \"127.0.0.1\", \"::1\", HttpContext.Connection.LocalIpAddress.ToString() };\n            if (!localAddresses.Contains(HttpContext.Connection.RemoteIpAddress.ToString()))\n            {\n                return NotFound();\n            }\n\n            var model = new DiagnosticsViewModel(await HttpContext.AuthenticateAsync());\n            return View(model);\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Diagnostics/DiagnosticsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DiagnosticsViewModel\n{\n        public DiagnosticsViewModel(AuthenticateResult result)\n        {\n            AuthenticateResult = result;\n\n            if (result.Properties.Items.ContainsKey(\"client_list\"))\n            {\n                var encoded = result.Properties.Items[\"client_list\"];\n                var bytes = Base64Url.Decode(encoded);\n                var value = Encoding.UTF8.GetString(bytes);\n\n                Clients = JsonConvert.DeserializeObject<string[]>(value);\n            }\n        }\n\n        public AuthenticateResult AuthenticateResult { get; }\n        public IEnumerable<string> Clients { get; } = new List<string>();\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Extensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic static class Extensions\n{\n        /// <summary>\n        /// Checks if the redirect URI is for a native client.\n        /// </summary>\n        /// <returns></returns>\n        public static bool IsNativeClient(this AuthorizationRequest context)\n        {\n            return !context.RedirectUri.StartsWith(\"https\", StringComparison.Ordinal)\n               && !context.RedirectUri.StartsWith(\"http\", StringComparison.Ordinal);\n        }\n\n        public static IActionResult LoadingPage(this Controller controller, string viewName, string redirectUri)\n        {\n            controller.HttpContext.Response.StatusCode = 200;\n            controller.HttpContext.Response.Headers[\"Location\"] = \"\";\n            \n            return controller.View(viewName, new RedirectViewModel { RedirectUrl = redirectUri });\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Grants/GrantsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller allows a user to revoke grants given to clients\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class GrantsController : Controller\n{\n        private readonly IIdentityServerInteractionService _interaction;\n        private readonly IClientStore _clients;\n        private readonly IResourceStore _resources;\n        private readonly IEventService _events;\n\n        public GrantsController(IIdentityServerInteractionService interaction,\n            IClientStore clients,\n            IResourceStore resources,\n            IEventService events)\n        {\n            _interaction = interaction;\n            _clients = clients;\n            _resources = resources;\n            _events = events;\n        }\n\n        /// <summary>\n        /// Show list of grants\n        /// </summary>\n        [HttpGet]\n        public async Task<IActionResult> Index()\n        {\n            return View(\"Index\", await BuildViewModelAsync());\n        }\n\n        /// <summary>\n        /// Handle postback to revoke a client\n        /// </summary>\n        [HttpPost]\n        [ValidateAntiForgeryToken]\n        public async Task<IActionResult> Revoke(string clientId)\n        {\n            await _interaction.RevokeUserConsentAsync(clientId);\n            await _events.RaiseAsync(new GrantsRevokedEvent(User.GetSubjectId(), clientId));\n\n            return RedirectToAction(\"Index\");\n        }\n\n        private async Task<GrantsViewModel> BuildViewModelAsync()\n        {\n            var grants = await _interaction.GetAllUserGrantsAsync();\n\n            var list = new List<GrantViewModel>();\n            foreach(var grant in grants)\n            {\n                var client = await _clients.FindClientByIdAsync(grant.ClientId);\n                if (client != null)\n                {\n                    var resources = await _resources.FindResourcesByScopeAsync(grant.Scopes);\n\n                    var item = new GrantViewModel()\n                    {\n                        ClientId = client.ClientId,\n                        ClientName = client.ClientName ?? client.ClientId,\n                        ClientLogoUrl = client.LogoUri,\n                        ClientUrl = client.ClientUri,\n                        Description = grant.Description,\n                        Created = grant.CreationTime,\n                        Expires = grant.Expiration,\n                        IdentityGrantNames = resources.IdentityResources.Select(x => x.DisplayName ?? x.Name).ToArray(),\n                        ApiGrantNames = resources.ApiScopes.Select(x => x.DisplayName ?? x.Name).ToArray()\n                    };\n\n                    list.Add(item);\n                }\n            }\n\n            return new GrantsViewModel\n            {\n                Grants = list\n            };\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Grants/GrantsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class GrantsViewModel\n{\n        public IEnumerable<GrantViewModel> Grants { get; set; }\n}\n\npublic class GrantViewModel\n{\n        public string ClientId { get; set; }\n        public string ClientName { get; set; }\n        public string ClientUrl { get; set; }\n        public string ClientLogoUrl { get; set; }\n        public string Description { get; set; }\n        public DateTime Created { get; set; }\n        public DateTime? Expires { get; set; }\n        public IEnumerable<string> IdentityGrantNames { get; set; }\n        public IEnumerable<string> ApiGrantNames { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Home/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ErrorViewModel\n{\n        public ErrorViewModel()\n        {\n        }\n\n        public ErrorViewModel(string error)\n        {\n            Error = new ErrorMessage { Error = error };\n        }\n\n        public ErrorMessage Error { get; set; }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/Home/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class HomeController : Controller\n{\n        private readonly IIdentityServerInteractionService _interaction;\n        private readonly IWebHostEnvironment _environment;\n        private readonly ILogger _logger;\n\n        public HomeController(IIdentityServerInteractionService interaction, IWebHostEnvironment environment, ILogger<HomeController> logger)\n        {\n            _interaction = interaction;\n            _environment = environment;\n            _logger = logger;\n        }\n\n        public IActionResult Index()\n        {\n            if (_environment.IsDevelopment())\n            {\n                // only show in development\n                return View();\n            }\n\n            _logger.LogInformation(\"Homepage is disabled in production. Returning 404.\");\n            return NotFound();\n        }\n\n        /// <summary>\n        /// Shows the error page\n        /// </summary>\n        public async Task<IActionResult> Error(string errorId)\n        {\n            var vm = new ErrorViewModel();\n\n            // retrieve error details from identityserver\n            var message = await _interaction.GetErrorContextAsync(errorId);\n            if (message != null)\n            {\n                vm.Error = message;\n\n                if (!_environment.IsDevelopment())\n                {\n                    // only show in development\n                    message.ErrorDescription = null;\n                }\n            }\n\n            return View(\"Error\", vm);\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/SecurityHeadersAttribute.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class SecurityHeadersAttribute : ActionFilterAttribute\n{\n        public override void OnResultExecuting(ResultExecutingContext context)\n        {\n            var result = context.Result;\n            if (result is ViewResult)\n            {\n                // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options\n                if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Type-Options\"))\n                {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Type-Options\", \"nosniff\");\n                }\n\n                // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options\n                if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Frame-Options\"))\n                {\n                context.HttpContext.Response.Headers.Append(\"X-Frame-Options\", \"SAMEORIGIN\");\n                }\n\n                // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy\n                var csp = \"default-src 'self'; object-src 'none'; frame-ancestors 'none'; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self';\";\n                // also consider adding upgrade-insecure-requests once you have HTTPS in place for production\n                //csp += \"upgrade-insecure-requests;\";\n                // also an example if you need client images to be displayed from twitter\n                // csp += \"img-src 'self' https://pbs.twimg.com;\";\n\n                // once for standards compliant browsers\n                if (!context.HttpContext.Response.Headers.ContainsKey(\"Content-Security-Policy\"))\n                {\n                context.HttpContext.Response.Headers.Append(\"Content-Security-Policy\", csp);\n                }\n                // and once again for IE\n                if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Security-Policy\"))\n                {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Security-Policy\", csp);\n                }\n\n                // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy\n                var referrer_policy = \"no-referrer\";\n                if (!context.HttpContext.Response.Headers.ContainsKey(\"Referrer-Policy\"))\n                {\n                context.HttpContext.Response.Headers.Append(\"Referrer-Policy\", referrer_policy);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Quickstart/TestUsers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing JsonSerializer = System.Text.Json.JsonSerializer;\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class TestUsers\n{\n    public static List<TestUser> Users\n    {\n        get\n        {\n            var address = new\n            {\n                street_address = \"One Hacker Way\",\n                locality = \"Heidelberg\",\n                postal_code = 69118,\n                country = \"Germany\"\n            };\n\n            return new List<TestUser>\n    {\n                new TestUser\n        {\n                    SubjectId = \"818727\",\n                    Username = \"alice\",\n                    Password = \"alice\",\n                Claims = \n                {\n                    new Claim(JwtClaimTypes.Name, \"Alice Smith\"),\n                    new Claim(JwtClaimTypes.GivenName, \"Alice\"),\n                    new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                    new Claim(JwtClaimTypes.Email, \"AliceSmith@email.com\"),\n                    new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                    new Claim(JwtClaimTypes.WebSite, \"http://alice.com\"),\n                        new Claim(JwtClaimTypes.Address, JsonSerializer.Serialize(address), IdentityServerConstants.ClaimValueTypes.Json)\n                }\n            },\n                new TestUser\n                {\n                    SubjectId = \"88421113\",\n                    Username = \"bob\",\n                    Password = \"bob\",\n                Claims = \n                {\n                    new Claim(JwtClaimTypes.Name, \"Bob Smith\"),\n                    new Claim(JwtClaimTypes.GivenName, \"Bob\"),\n                    new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                    new Claim(JwtClaimTypes.Email, \"BobSmith@email.com\"),\n                    new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                    new Claim(JwtClaimTypes.WebSite, \"http://bob.com\"),\n                        new Claim(JwtClaimTypes.Address, JsonSerializer.Serialize(address), IdentityServerConstants.ClaimValueTypes.Json)\n                }\n            }\n        };\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.EntityFrameworkCore;\n\nnamespace IdentityServerHost;\n\npublic class Startup\n{\n    private readonly IConfiguration _config;\n\n    public Startup(IConfiguration config)\n    {\n        _config = config;\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        services.AddControllersWithViews();\n\n        var connectionString = _config.GetConnectionString(\"db\");\n\n        services.AddIdentityServer()\n            .AddDeveloperSigningCredential()\n            .AddTestUsers(TestUsers.Users)\n            // this adds the config data from DB (clients, resources, CORS)\n            .AddConfigurationStore(options =>\n            {\n                options.ConfigureDbContext = builder => builder.UseSqlServer(connectionString);\n            })\n            // this adds the operational data from DB (codes, tokens, consents)\n            .AddOperationalStore(options =>\n            {\n                options.ConfigureDbContext = builder => builder.UseSqlServer(connectionString);\n\n                // this enables automatic token cleanup. this is optional.\n                options.EnableTokenCleanup = true;\n                options.TokenCleanupInterval = 5; // interval in seconds, short for testing\n            });\n        // this is something you will want in production to reduce load on and requests to the DB\n        //.AddConfigurationStoreCache();\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n        app.UseDeveloperExceptionPage();\n\n        app.UseStaticFiles();\n\n        app.UseRouting();\n\n        app.UseIdentityServer();\n\n        app.UseAuthorization();\n\n        app.UseEndpoints(endpoints =>\n        {\n            endpoints.MapDefaultControllerRoute();\n        });\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/TestOperationalStoreNotification.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework;\nusing IdentityServer8.EntityFramework.Entities;\nusing PersistedGrant = IdentityServer8.EntityFramework.Entities.PersistedGrant;\n\nnamespace IdentityServerHost\n{\n    public class TestOperationalStoreNotification : IOperationalStoreNotification\n    {\n        public TestOperationalStoreNotification()\n        {\n            Console.WriteLine(\"ctor\");\n        }\n\n        public Task PersistedGrantsRemovedAsync(IEnumerable<PersistedGrant> persistedGrants)\n        {\n            foreach (var grant in persistedGrants)\n            {\n                Console.WriteLine(\"cleaned: \" + grant.Type);\n            }\n            return Task.CompletedTask;\n        }\n\n        public Task DeviceCodesRemovedAsync(IEnumerable<DeviceFlowCodes> deviceCodes)\n        {\n            foreach (var deviceCode in deviceCodes) \n            {\n                Console.WriteLine(\"cleaned device code\");\n            }\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Account/AccessDenied.cshtml",
    "content": "﻿\n<div class=\"container\">\n    <div class=\"lead\">\n        <h1>Access Denied</h1>\n        <p>You do not have access to that resource.</p>\n    </div>\n</div>"
  },
  {
    "path": "src/EntityFramework/host/Views/Account/LoggedOut.cshtml",
    "content": "﻿@model LoggedOutViewModel\n\n@{ \n    // set this so the layout rendering sees an anonymous user\n    ViewData[\"signed-out\"] = true;\n}\n\n<div class=\"logged-out-page\">\n    <h1>\n        Logout\n        <small>You are now logged out</small>\n    </h1>\n\n    @if (Model.PostLogoutRedirectUri != null)\n    {\n        <div>\n            Click <a class=\"PostLogoutRedirectUri\" href=\"@Model.PostLogoutRedirectUri\">here</a> to return to the\n            <span>@Model.ClientName</span> application.\n        </div>\n    }\n\n    @if (Model.SignOutIframeUrl != null)\n    {\n        <iframe width=\"0\" height=\"0\" class=\"signout\" src=\"@Model.SignOutIframeUrl\"></iframe>\n    }\n</div>\n\n@section scripts\n{\n    @if (Model.AutomaticRedirectAfterSignOut)\n    {\n        <script src=\"~/js/signout-redirect.js\"></script>\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Account/Login.cshtml",
    "content": "@model LoginViewModel\n\n<div class=\"login-page\">\n    <div class=\"lead\">\n        <h1>Login</h1>\n        <p>Choose how to login</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n\n        @if (Model.EnableLocalLogin)\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>Local Account</h2>\n                    </div>\n\n                    <div class=\"card-body\">\n                        <form asp-route=\"Login\">\n                            <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n\n                            <div class=\"form-group\">\n                                <label asp-for=\"Username\"></label>\n                                <input class=\"form-control\" placeholder=\"Username\" asp-for=\"Username\" autofocus>\n                            </div>\n                            <div class=\"form-group\">\n                                <label asp-for=\"Password\"></label>\n                                <input type=\"password\" class=\"form-control\" placeholder=\"Password\" asp-for=\"Password\" autocomplete=\"off\">\n                            </div>\n                            @if (Model.AllowRememberLogin)\n                            {\n                                <div class=\"form-group\">\n                                    <div class=\"form-check\">\n                                        <input class=\"form-check-input\" asp-for=\"RememberLogin\">\n                                        <label class=\"form-check-label\" asp-for=\"RememberLogin\">\n                                            Remember My Login\n                                        </label>\n                                    </div>\n                                </div>\n                            }\n                            <button class=\"btn btn-primary\" name=\"button\" value=\"login\">Login</button>\n                            <button class=\"btn btn-secondary\" name=\"button\" value=\"cancel\" formaction=\"/Account/LoginCancel\">Cancel</button>\n                        </form>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>External Account</h2>\n                    </div>\n                    <div class=\"card-body\">\n                        <ul class=\"list-inline\">\n                            @foreach (var provider in Model.VisibleExternalProviders)\n                            {\n                                <li class=\"list-inline-item\">\n                                    <a class=\"btn btn-secondary\"\n                                       asp-controller=\"External\"\n                                       asp-action=\"Challenge\"\n                                       asp-route-scheme=\"@provider.AuthenticationScheme\"\n                                       asp-route-returnUrl=\"@Model.ReturnUrl\">\n                                        @provider.DisplayName\n                                    </a>\n                                </li>\n                            }\n                        </ul>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (!Model.EnableLocalLogin && !Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"alert alert-warning\">\n                <strong>Invalid login request</strong>\n                There are no login schemes configured for this request.\n            </div>\n        }\n    </div>\n</div>"
  },
  {
    "path": "src/EntityFramework/host/Views/Account/Logout.cshtml",
    "content": "﻿@model LogoutViewModel\n\n<div class=\"logout-page\">\n    <div class=\"lead\">\n        <h1>Logout</h1>\n        <p>Would you like to logout of IdentityServer?</p>\n    </div>\n\n    <form asp-action=\"Logout\">\n        <input type=\"hidden\" name=\"logoutId\" value=\"@Model.LogoutId\"  />\n        <div class=\"form-group\">\n            <button class=\"btn btn-primary\">Yes</button>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Consent/Index.cshtml",
    "content": "@model ConsentViewModel\n\n<div class=\"page-consent\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Index\">\n        <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Device/Success.cshtml",
    "content": "\n<div class=\"page-device-success\">\n    <div class=\"lead\">\n        <h1>Success</h1>\n        <p>You have successfully authorized the device</p>\n    </div>\n</div>\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Device/UserCodeCapture.cshtml",
    "content": "@model string\n\n<div class=\"page-device-code\">\n    <div class=\"lead\">\n        <h1>User Code</h1>\n        <p>Please enter the code displayed on your device.</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <form asp-action=\"UserCodeCapture\">\n                <div class=\"form-group\">\n                    <label for=\"userCode\">User Code:</label>\n                    <input class=\"form-control\" for=\"userCode\" name=\"userCode\" autofocus />\n                </div>\n\n                <button class=\"btn btn-primary\" name=\"button\">Submit</button>\n            </form>\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Device/UserCodeConfirmation.cshtml",
    "content": "@model DeviceAuthorizationViewModel\n\n<div class=\"page-device-confirmation\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        @if (Model.ConfirmUserCode)\n        {\n            <p>Please confirm that the authorization request quotes the code: <strong>@Model.UserCode</strong>.</p>\n        }\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Callback\">\n        <input asp-for=\"UserCode\" type=\"hidden\" value=\"@Model.UserCode\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Diagnostics/Index.cshtml",
    "content": "@model DiagnosticsViewModel\n\n<div class=\"diagnostics-page\">\n    <div class=\"lead\">\n        <h1>Authentication Cookie</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Claims</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var claim in Model.AuthenticateResult.Principal.Claims)\n                        {\n                            <dt>@claim.Type</dt>\n                            <dd>@claim.Value</dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n        \n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Properties</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var prop in Model.AuthenticateResult.Properties.Items)\n                        {\n                            <dt>@prop.Key</dt>\n                            <dd>@prop.Value</dd>\n                        }\n                        @if (Model.Clients.Any())\n                        {\n                            <dt>Clients</dt>\n                            <dd>\n                            @{\n                                var clients = Model.Clients.ToArray();\n                                for(var i = 0; i < clients.Length; i++)\n                                {\n                                    <text>@clients[i]</text>\n                                    if (i < clients.Length - 1)\n                                    {\n                                        <text>, </text>\n                                    }\n                                }\n                            }\n                            </dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n    </div>\n</div>\n\n\n\n\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Grants/Index.cshtml",
    "content": "﻿@model GrantsViewModel\n\n<div class=\"grants-page\">\n    <div class=\"lead\">\n        <h1>Client Application Permissions</h1>\n        <p>Below is the list of applications you have given permission to and the resources they have access to.</p>\n    </div>\n\n    @if (Model.Grants.Any() == false)\n    {\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                <div class=\"alert alert-info\">\n                    You have not given access to any applications\n                </div>\n            </div>\n        </div>\n    }\n    else\n    {\n        foreach (var grant in Model.Grants)\n        {\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <div class=\"row\">\n                        <div class=\"col-sm-8 card-title\">\n                            @if (grant.ClientLogoUrl != null)\n                            {\n                                <img src=\"@grant.ClientLogoUrl\">\n                            }\n                            <strong>@grant.ClientName</strong>\n                        </div>\n\n                        <div class=\"col-sm-2\">\n                            <form asp-action=\"Revoke\">\n                                <input type=\"hidden\" name=\"clientId\" value=\"@grant.ClientId\">\n                                <button class=\"btn btn-danger\">Revoke Access</button>\n                            </form>\n                        </div>\n                    </div>\n                </div>\n                \n                <ul class=\"list-group list-group-flush\">\n                    @if (grant.Description != null)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Description:</label> @grant.Description\n                        </li>   \n                    }\n                    <li class=\"list-group-item\">\n                        <label>Created:</label> @grant.Created.ToString(\"yyyy-MM-dd\")\n                    </li>\n                    @if (grant.Expires.HasValue)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Expires:</label> @grant.Expires.Value.ToString(\"yyyy-MM-dd\")\n                        </li>\n                    }\n                    @if (grant.IdentityGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Identity Grants</label>\n                            <ul>\n                                @foreach (var name in grant.IdentityGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                    @if (grant.ApiGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>API Grants</label>\n                            <ul>\n                                @foreach (var name in grant.ApiGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                </ul>\n            </div>\n        }\n    }\n</div>"
  },
  {
    "path": "src/EntityFramework/host/Views/Home/Index.cshtml",
    "content": "@using System.Diagnostics\n@using System.Reflection\n\n@{\n    var version = typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.GetCustomAttribute<AssemblyInformationalVersionAttribute>()?.InformationalVersion.Split('+').First();\n}\n\n<div class=\"welcome-page\">\n    <h1>\n        <img src=\"~/icon.jpg\">\n        Welcome to IdentityServer8\n        <small class=\"text-muted\">(version @version)</small>\n    </h1>\n\n    <ul>\n        <li>\n            IdentityServer publishes a\n            <a href=\"~/.well-known/openid-configuration\">discovery document</a>\n            where you can find metadata and links to all the endpoints, key material, etc.\n        </li>\n        <li>\n            Click <a href=\"~/diagnostics\">here</a> to see the claims for your current session.\n        </li>\n        <li>\n            Click <a href=\"~/grants\">here</a> to manage your stored grants.\n        </li>\n        <li>\n            Here are links to the\n            <a href=\"https://github.com/alexhiggins732/IdentityServer8\">source code repository</a>,\n            and <a href=\"https://github.com/alexhiggins732/IdentityServer8/tree/main/samples\">ready to use samples</a>.\n        </li>\n    </ul>\n</div>\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Shared/Error.cshtml",
    "content": "@model ErrorViewModel\n\n@{\n    var error = Model?.Error?.Error;\n    var errorDescription = Model?.Error?.ErrorDescription;\n    var request_id = Model?.Error?.RequestId;\n}\n\n<div class=\"error-page\">\n    <div class=\"lead\">\n        <h1>Error</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <div class=\"alert alert-danger\">\n                Sorry, there was an error\n\n                @if (error != null)\n                {\n                    <strong>\n                        <em>\n                            : @error\n                        </em>\n                    </strong>\n\n                    if (errorDescription != null)\n                    {\n                        <div>@errorDescription</div>\n                    }\n                }\n            </div>\n\n            @if (request_id != null)\n            {\n                <div class=\"request-id\">Request Id: @request_id</div>\n            }\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Shared/Redirect.cshtml",
    "content": "@model RedirectViewModel\n@using Microsoft.Extensions.DependencyInjection;\n<div class=\"redirect-page\">\n    <div class=\"lead\">\n        <h1>You are now being returned to the application</h1>\n        <p>Once complete, you may close this tab.</p>\n    </div>\n</div>\n\n<meta http-equiv=\"refresh\" content=\"0;url=@Model.RedirectUrl\" data-url=\"@Model.RedirectUrl\">\n<script>\n    var url = '@Model.RedirectUrl.SanitizeForUrl()';\n    window.location.href = url;\n</script>\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0, shrink-to-fit=no\" />\n\n    <title>IdentityServer8</title>\n    \n    <link rel=\"icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    <link rel=\"shortcut icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    \n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <partial name=\"_Nav\" />\n   \n    <div class=\"container body-container\">\n        @RenderBody()\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.slim.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Shared/_Nav.cshtml",
    "content": "@using IdentityServer8.Extensions\n\n@{\n    string name = null;\n    if (!true.Equals(ViewData[\"signed-out\"]))\n    {\n        name = Context.User?.GetDisplayName();\n    }\n}\n\n<div class=\"nav-page\">\n    <nav class=\"navbar navbar-expand-lg navbar-dark bg-dark\">\n\n        <a href=\"~/\" class=\"navbar-brand\">\n            <img src=\"~/icon.png\" class=\"icon-banner\">\n            IdentityServer8\n        </a>\n\n        @if (!string.IsNullOrWhiteSpace(name))\n        {\n            <ul class=\"navbar-nav mr-auto\">\n                <li class=\"nav-item dropdown\">\n                    <a href=\"#\" class=\"nav-link dropdown-toggle\" data-toggle=\"dropdown\">@name <b class=\"caret\"></b></a>\n                    \n                    <div class=\"dropdown-menu\">\n                        <a class=\"dropdown-item\" asp-action=\"Logout\" asp-controller=\"Account\">Logout</a>\n                    </div>\n              </li>\n            </ul>\n        }\n    \n    </nav>\n</div>\n"
  },
  {
    "path": "src/EntityFramework/host/Views/Shared/_ScopeListItem.cshtml",
    "content": "﻿@model ScopeViewModel\n\n<li class=\"list-group-item\">\n    <label>\n        <input class=\"consent-scopecheck\"\n               type=\"checkbox\"\n               name=\"ScopesConsented\"\n               id=\"scopes_@Model.Value\"\n               value=\"@Model.Value\"\n               checked=\"@Model.Checked\"\n               disabled=\"@Model.Required\" />\n        @if (Model.Required)\n        {\n            <input type=\"hidden\"\n                   name=\"ScopesConsented\"\n                   value=\"@Model.Value\" />\n        }\n        <strong>@Model.DisplayName</strong>\n        @if (Model.Emphasize)\n        {\n            <span class=\"glyphicon glyphicon-exclamation-sign\"></span>\n        }\n    </label>\n    @if (Model.Required)\n    {\n        <span><em>(required)</em></span>\n    }\n    @if (Model.Description != null)\n    {\n        <div class=\"consent-description\">\n            <label for=\"scopes_@Model.Value\">@Model.Description</label>\n        </div>\n    }\n</li>"
  },
  {
    "path": "src/EntityFramework/host/Views/Shared/_ValidationSummary.cshtml",
    "content": "﻿@if (ViewContext.ModelState.IsValid == false)\n{\n    <div class=\"alert alert-danger\">\n        <strong>Error</strong>\n        <div asp-validation-summary=\"All\" class=\"danger\"></div>\n    </div>\n}"
  },
  {
    "path": "src/EntityFramework/host/Views/_ViewImports.cshtml",
    "content": "﻿@using IdentityServerHost.Quickstart.UI\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "src/EntityFramework/host/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "src/EntityFramework/host/appsettings.json",
    "content": "{\n  \"ConnectionStrings\": {\n    \"db\": \"server=(localdb)\\\\mssqllocaldb;database=IdentityServer8.EntityFramework-4.0.0;trusted_connection=yes;\",\n  }\n}"
  },
  {
    "path": "src/EntityFramework/host/wwwroot/css/site.css",
    "content": "﻿.body-container {\n  margin-top: 60px;\n  padding-bottom: 40px; }\n\n.welcome-page li {\n  list-style: none;\n  padding: 4px; }\n\n.logged-out-page iframe {\n  display: none;\n  width: 0;\n  height: 0; }\n\n.grants-page .card {\n  margin-top: 20px;\n  border-bottom: 1px solid lightgray; }\n  .grants-page .card .card-title {\n    font-size: 120%;\n    font-weight: bold; }\n    .grants-page .card .card-title img {\n      width: 100px;\n      height: 100px; }\n  .grants-page .card label {\n    font-weight: bold; }\n"
  },
  {
    "path": "src/EntityFramework/host/wwwroot/css/site.scss",
    "content": "﻿.body-container {\n    margin-top: 60px;\n    padding-bottom:40px;\n}\n\n.welcome-page {\n    li {\n        list-style: none;\n        padding: 4px;\n    }\n}\n\n.logged-out-page {\n    iframe {\n        display: none;\n        width: 0;\n        height: 0;\n    }\n}\n\n.grants-page {\n    .card {\n        margin-top: 20px;\n        border-bottom: 1px solid lightgray;\n\n        .card-title {\n            img {\n                width: 100px;\n                height: 100px;\n            }\n\n            font-size: 120%;\n            font-weight: bold;\n        }\n\n        label {\n            font-weight: bold;\n        }\n    }\n}\n\n\n"
  },
  {
    "path": "src/EntityFramework/host/wwwroot/js/signin-redirect.js",
    "content": "//window.location.href = document.querySelector(\"meta[http-equiv=refresh]\").getAttribute(\"data-url\");\n"
  },
  {
    "path": "src/EntityFramework/host/wwwroot/js/signout-redirect.js",
    "content": "﻿window.addEventListener(\"load\", function () {\n    var a = document.querySelector(\"a.PostLogoutRedirectUri\");\n    if (a) {\n        window.location = a.href;\n    }\n});\n"
  },
  {
    "path": "src/EntityFramework/migrations/SqlServer/Configuration/Clients.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\nusing System.Collections.Generic;\n\nnamespace IdentityServerHost.Configuration;\n\npublic static class Clients\n{\n    public static IEnumerable<Client> Get()\n    {\n        var clients = new List<Client>();\n        \n        clients.AddRange(ClientsConsole.Get());\n        clients.AddRange(ClientsWeb.Get());\n\n        return clients;\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/migrations/SqlServer/Configuration/ClientsConsole.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing IdentityServer8;\nusing IdentityServer8.Models;\n\nnamespace IdentityServerHost.Configuration;\n\npublic static class ClientsConsole\n{\n    public static IEnumerable<Client> Get()\n    {\n        return new List<Client>\n        {\n            ///////////////////////////////////////////////////////////////\n            // Console-based Client\n            ///////////////////////////////////////////////////////////////\n\n\n            ///////////////////////////////////////////\n            // Console Client Credentials Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets = {new Secret(\"secret\".Sha256())},\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\", IdentityServerConstants.LocalApi.ScopeName}\n            },\n            \n            ///////////////////////////////////////////\n            // Console Structured Scope Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"parameterized.client\",\n                ClientSecrets = {new Secret(\"secret\".Sha256())},\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"transaction\" }\n            },\n\n            ///////////////////////////////////////////\n            // X509 mTLS Client\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mtls\",\n                ClientSecrets =\n                {\n                    // new Secret(@\"CN=mtls.test, OU=ROO\\ballen@roo, O=mkcert development certificate\", \"mtls.test\")\n                    // {\n                    //     Type = SecretTypes.X509CertificateName\n                    // },\n                    new Secret(\"5D9E9B6B333CD42C99D1DE6175CC0F3EF99DDF68\", \"mtls.test\")\n                    {\n                        Type = IdentityServerConstants.SecretTypes.X509CertificateThumbprint\n                    },\n                },\n                \n                AccessTokenType = AccessTokenType.Jwt,\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" }\n            },\n\n            ///////////////////////////////////////////\n            // Console Client Credentials Flow with client JWT assertion\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client.jwt\",\n                ClientSecrets =\n                {\n                    new Secret\n                    {\n                        Type = IdentityServerConstants.SecretTypes.X509CertificateBase64,\n                        Value =\n                            \"MIIEgTCCAumgAwIBAgIQDMMu7l/umJhfEbzJMpcttzANBgkqhkiG9w0BAQsFADCBkzEeMBwGA1UEChMVbWtjZXJ0IGRldmVsb3BtZW50IENBMTQwMgYDVQQLDCtkb21pbmlja0Bkb21icDE2LmZyaXR6LmJveCAoRG9taW5pY2sgQmFpZXIpMTswOQYDVQQDDDJta2NlcnQgZG9taW5pY2tAZG9tYnAxNi5mcml0ei5ib3ggKERvbWluaWNrIEJhaWVyKTAeFw0xOTA2MDEwMDAwMDBaFw0zMDAxMDMxMjM0MDdaMHAxJzAlBgNVBAoTHm1rY2VydCBkZXZlbG9wbWVudCBjZXJ0aWZpY2F0ZTE0MDIGA1UECwwrZG9taW5pY2tAZG9tYnAxNi5mcml0ei5ib3ggKERvbWluaWNrIEJhaWVyKTEPMA0GA1UEAxMGY2xpZW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvNtpipaS8k1zA6w0Aoy8U4l+8zM4jHhhblExf3PULrMR6RauxniTki8p+P8CsZT4V8A4qo+JwsgpLIHrVQrbt9DEhHfBKzxwHqt+GoHt7byTfTtp8A/5nLhYc/5CW4HiR194gVx5+HAlvt+BriMTb1czvTf+H20dj41yUPsN7nMdyRLF+uXapQYMLYnq2BJIDq83mqGwojHk7d+N6GwoO95jlyas7KSoj8/FvfbaqkRNx0446hqPOzFHKc8er8K5VrLp6tVjh8ZJyY0F0dKgx6yWITsL54ctbj/cCyfuGjWEMbS2XXgc+x/xQMnmpfhK1qQAUn9jg5EzF9n6mQomOwIDAQABo3MwcTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUEMUlw41YsKZQVls3pEG6CrJk4O8wEQYDVR0RBAowCIIGY2xpZW50MA0GCSqGSIb3DQEBCwUAA4IBgQC0TjNY4Q3Wmw7ggamDImV6HUng3WbYGLYbbL2e3myBrjIxGd1Bi8ZyOu8qeUMIRAbZt2YsSX5S8kx0biaVg2zC+aO5eHhEWMwKB66huInXFjI4wtxZ22r+33fg1R0cLuEUePhftOWrbL0MS4YXVyn9HUMWO4WptG9PJdxNw1UbEB8nw3FkVOdAC9RGqiqalSK+E2UT/kUbTIQ1gPSdQ3nh52mre0H/T9+IRqiozJtNK/CQg4NuEV7rUXHnp7Fmigp6RIJ4TCozglspL341y0rV8M7npU1FYZC2UKNr4ed+GOO1n/sF3LbXDlPXwne99CVVn85wjDaevoR7Md0y2KwE9EggLYcViXNehx4YVv/BjfgqxW8NxiKAxP6kPOZE0XdBrZj2rmcDcGOXCzzYpcduKhFyTOpA0K5RNGC3j1KOUjPVlOtLvjASP7udBEYNfH3mgqXAgqNDOEKi2jG9LITv2IyGUsXhTAsKNJ6A6qiDBzDrvPAYDvsfabPq6tRTwjA=\"\n                    },\n                    new Secret\n                    {\n                        Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                        Value =\n                            \"{'e':'AQAB','kid':'ZzAjSnraU3bkWGnnAqLapYGpTyNfLbjbzgAPbbW2GEA','kty':'RSA','n':'wWwQFtSzeRjjerpEM5Rmqz_DsNaZ9S1Bw6UbZkDLowuuTCjBWUax0vBMMxdy6XjEEK4Oq9lKMvx9JzjmeJf1knoqSNrox3Ka0rnxXpNAz6sATvme8p9mTXyp0cX4lF4U2J54xa2_S9NF5QWvpXvBeC4GAJx7QaSw4zrUkrc6XyaAiFnLhQEwKJCwUw4NOqIuYvYp_IXhw-5Ti_icDlZS-282PcccnBeOcX7vc21pozibIdmZJKqXNsL1Ibx5Nkx1F1jLnekJAmdaACDjYRLL_6n3W4wUp19UvzB1lGtXcJKLLkqB6YDiZNu16OSiSprfmrRXvYmvD8m6Fnl5aetgKw'}\"\n                    }\n                },\n                \n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" }\n            },\n\n            ///////////////////////////////////////////\n            // Custom Grant Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client.custom\",\n                ClientSecrets = {new Secret(\"secret\".Sha256())},\n                AllowedGrantTypes = {\"custom\", \"custom.nosubject\"},\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" }\n            },\n\n            ///////////////////////////////////////////\n            // Console Resource Owner Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient\",\n                ClientSecrets = {new Secret(\"secret\".Sha256())},\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    \"custom.profile\",\n                    \"resource1.scope1\", \"resource2.scope1\"\n                }\n            },\n\n            ///////////////////////////////////////////\n            // Console Public Resource Owner Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient.public\",\n                RequireClientSecret = false,\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\", \"resource2.scope1\"\n                }\n            },\n\n            ///////////////////////////////////////////\n            // Console with PKCE Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"console.pkce\",\n                ClientName = \"Console with PKCE Sample\",\n                RequireClientSecret = false,\n                AllowedGrantTypes = GrantTypes.Code,\n                RequirePkce = true,\n                RedirectUris = {\"http://127.0.0.1\"},\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\", \"resource2.scope1\"\n                }\n            },\n            ///////////////////////////////////////////\n            // WinConsole with PKCE Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"winconsole\",\n                ClientName = \"Windows Console with PKCE Sample\",\n                RequireClientSecret = false,\n                AllowedGrantTypes = GrantTypes.Code,\n                RequirePkce = true,\n                RedirectUris = {\"sample-windows-client://callback\"},\n                RequireConsent = false,\n                AllowOfflineAccess = true,\n                AllowedIdentityTokenSigningAlgorithms = {\"ES256\"},\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\", \"resource2.scope1\"\n                }\n            },\n\n\n            ///////////////////////////////////////////\n            // Introspection Client Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient.reference\",\n                ClientSecrets = {new Secret(\"secret\".Sha256())},\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" },\n                AccessTokenType = AccessTokenType.Reference\n            },\n            \n            ///////////////////////////////////////////\n            // Device Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"device\",\n                ClientName = \"Device Flow Client\",\n\n                AllowedGrantTypes = GrantTypes.DeviceFlow,\n                RequireClientSecret = false,\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\", \"resource2.scope1\"\n                }\n            }\n        };\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/migrations/SqlServer/Configuration/ClientsWeb.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing IdentityServer8;\nusing IdentityServer8.Models;\n\nnamespace IdentityServerHost.Configuration;\n\npublic static class ClientsWeb\n{\n    static string[] allowedScopes = \n    {\n        IdentityServerConstants.StandardScopes.OpenId,\n        IdentityServerConstants.StandardScopes.Profile,\n        IdentityServerConstants.StandardScopes.Email,\n        \"resource1.scope1\", \n        \"resource2.scope1\",\n        \"transaction\"\n    };\n    \n    public static IEnumerable<Client> Get()\n    {\n        return new List<Client>\n        {\n            ///////////////////////////////////////////\n            // JS OIDC Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"js_oidc\",\n                ClientName = \"JavaScript OIDC Client\",\n                ClientUri = \"http://identityserver8.io\",\n                \n                AllowedGrantTypes = GrantTypes.Code,\n                RequireClientSecret = false,\n                \n                RedirectUris = \n                {\n                    \"https://localhost:44300/index.html\",\n                    \"https://localhost:44300/callback.html\",\n                    \"https://localhost:44300/silent.html\",\n                    \"https://localhost:44300/popup.html\"\n                },\n\n                PostLogoutRedirectUris = { \"https://localhost:44300/index.html\" },\n                AllowedCorsOrigins = { \"https://localhost:44300\" },\n\n                AllowedScopes = allowedScopes\n            },\n            \n            ///////////////////////////////////////////\n            // MVC Automatic Token Management Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mvc.tokenmanagement\",\n                \n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.Code,\n                RequirePkce = true,\n\n                AccessTokenLifetime = 75,\n\n                RedirectUris = { \"https://localhost:44301/signin-oidc\" },\n                FrontChannelLogoutUri = \"https://localhost:44301/signout-oidc\",\n                PostLogoutRedirectUris = { \"https://localhost:44301/signout-callback-oidc\" },\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes = allowedScopes\n            },\n            \n            ///////////////////////////////////////////\n            // MVC Code Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mvc.code\",\n                ClientName = \"MVC Code Flow\",\n                ClientUri = \"http://identityserver8.io\",\n\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                RequireConsent = true,\n                AllowedGrantTypes = GrantTypes.Code,\n\n                RedirectUris = { \"https://localhost:44302/signin-oidc\" },\n                FrontChannelLogoutUri = \"https://localhost:44302/signout-oidc\",\n                PostLogoutRedirectUris = { \"https://localhost:44302/signout-callback-oidc\" },\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes = allowedScopes\n            },\n            \n            ///////////////////////////////////////////\n            // MVC Hybrid Flow Sample (Back Channel logout)\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mvc.hybrid.backchannel\",\n                ClientName = \"MVC Hybrid (with BackChannel logout)\",\n                ClientUri = \"http://identityserver8.io\",\n\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.Hybrid,\n                RequirePkce = false,\n\n                RedirectUris = { \"https://localhost:44303/signin-oidc\" },\n                BackChannelLogoutUri = \"https://localhost:44303/logout\",\n                PostLogoutRedirectUris = { \"https://localhost:44303/signout-callback-oidc\" },\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes = allowedScopes\n            }\n        };\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/migrations/SqlServer/Configuration/Resources.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityModel;\nusing IdentityServer8.Models;\nusing System.Collections.Generic;\nusing static IdentityServer8.IdentityServerConstants;\n\nnamespace IdentityServerHost.Configuration;\n\npublic class Resources\n{\n    // identity resources represent identity data about a user that can be requested via the scope parameter (OpenID Connect)\n    public static readonly IEnumerable<IdentityResource> IdentityResources =\n        new[]\n        {\n            // some standard scopes from the OIDC spec\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n            new IdentityResources.Email(),\n\n            // custom identity resource with some consolidated claims\n            new IdentityResource(\"custom.profile\", new[] { JwtClaimTypes.Name, JwtClaimTypes.Email, \"location\" })\n        };\n\n    // API scopes represent values that describe scope of access and can be requested by the scope parameter (OAuth)\n    public static readonly IEnumerable<ApiScope> ApiScopes =\n        new[]\n        {\n            // local API scope\n            new ApiScope(LocalApi.ScopeName),\n\n            // resource specific scopes\n            new ApiScope(\"resource1.scope1\"),\n            new ApiScope(\"resource2.scope1\"), \n            \n            // a scope without resource association\n            new ApiScope(\"scope3\"),\n            \n            // a scope shared by multiple resources\n            new ApiScope(\"shared.scope\"),\n\n            // a parameterized scope\n            new ApiScope(\"transaction\", \"Transaction\")\n            {\n                Description = \"Some Transaction\"\n            }\n        };\n\n    // API resources are more formal representation of a resource with processing rules and their scopes (if any)\n    public static readonly IEnumerable<ApiResource> ApiResources = \n        new[]\n        {\n            new ApiResource(\"resource1\", \"Resource 1\")\n            {\n                ApiSecrets = { new Secret(\"secret\".Sha256()) },\n\n                Scopes = { \"resource1.scope1\", \"shared.scope\" }\n            },\n            \n            // expanded version if more control is needed\n            new ApiResource(\"resource2\", \"Resource 2\")\n            {\n                ApiSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                // additional claims to put into access token\n                UserClaims =\n                {\n                    JwtClaimTypes.Name,\n                    JwtClaimTypes.Email\n                },\n\n                Scopes = { \"resource2.scope1\", \"shared.scope\" }\n            }\n        };\n}\n"
  },
  {
    "path": "src/EntityFramework/migrations/SqlServer/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore;\n\nnamespace SqlServer;\n\nclass Program\n{\n    public static void Main(string[] args)\n    {\n        var host = BuildWebHost(args);\n        SeedData.EnsureSeedData(host.Services);\n    }\n\n    public static IWebHost BuildWebHost(string[] args) =>\n        WebHost.CreateDefaultBuilder(args)\n            .UseStartup<Startup>()\n            .Build();\n}\n"
  },
  {
    "path": "src/EntityFramework/migrations/SqlServer/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:7603/\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"IIS Express\": {\n      \"commandName\": \"IISExpress\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      }\n    },\n    \"SqlServer\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"http://localhost:7604/\"\n    }\n  }\n}"
  },
  {
    "path": "src/EntityFramework/migrations/SqlServer/SeedData.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.DbContexts;\nusing IdentityServer8.EntityFramework.Mappers;\nusing IdentityServerHost.Configuration;\n\nnamespace SqlServer;\n\npublic class SeedData\n{\n    public static void EnsureSeedData(IServiceProvider serviceProvider)\n    {\n        using (var scope = serviceProvider.GetRequiredService<IServiceScopeFactory>().CreateScope())\n        {\n            using (var context = scope.ServiceProvider.GetService<ConfigurationDbContext>())\n            {\n                EnsureSeedData(context);\n            }\n        }\n    }\n\n    private static void EnsureSeedData(ConfigurationDbContext context)\n    {\n        Console.WriteLine(\"Seeding database...\");\n\n        if (!context.Clients.Any())\n        {\n            Console.WriteLine(\"Clients being populated\");\n            foreach (var client in Clients.Get())\n            {\n                context.Clients.Add(client.ToEntity());\n            }\n            context.SaveChanges();\n        }\n        else\n        {\n            Console.WriteLine(\"Clients already populated\");\n        }\n\n        if (!context.IdentityResources.Any())\n        {\n            Console.WriteLine(\"IdentityResources being populated\");\n            foreach (var resource in Resources.IdentityResources)\n            {\n                context.IdentityResources.Add(resource.ToEntity());\n            }\n            context.SaveChanges();\n        }\n        else\n        {\n            Console.WriteLine(\"IdentityResources already populated\");\n        }\n\n        if (!context.ApiResources.Any())\n        {\n            Console.WriteLine(\"ApiResources being populated\");\n            foreach (var resource in Resources.ApiResources)\n            {\n                context.ApiResources.Add(resource.ToEntity());\n            }\n            context.SaveChanges();\n        }\n        else\n        {\n            Console.WriteLine(\"ApiResources already populated\");\n        }\n\n        if (!context.ApiScopes.Any())\n        {\n            Console.WriteLine(\"Scopes being populated\");\n            foreach (var resource in Resources.ApiScopes)\n            {\n                context.ApiScopes.Add(resource.ToEntity());\n            }\n            context.SaveChanges();\n        }\n        else\n        {\n            Console.WriteLine(\"Scopes already populated\");\n        }\n\n        Console.WriteLine(\"Done seeding database.\");\n        Console.WriteLine();\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/migrations/SqlServer/SqlServer.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\..\\src\\IdentityServer8.EntityFramework.csproj\" />\n\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.SqlServer\" />\n  </ItemGroup>\n\n</Project>\n"
  },
  {
    "path": "src/EntityFramework/migrations/SqlServer/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.EntityFrameworkCore;\n\nnamespace SqlServer;\n\npublic class Startup\n{\n    public IConfiguration Configuration { get; }\n\n    public Startup(IConfiguration config)\n    {\n        Configuration = config;\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        var cn = Configuration.GetConnectionString(\"db\");\n\n        services.AddIdentityServer()\n            .AddConfigurationStore(options => {\n                options.ConfigureDbContext = b => b.UseSqlServer(cn);\n            })\n            .AddOperationalStore(options => {\n                options.ConfigureDbContext = b => b.UseSqlServer(cn);\n            });\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/migrations/SqlServer/appsettings.json",
    "content": "{\n  \"ConnectionStrings\": {\n    \"db\": \"server=(localdb)\\\\mssqllocaldb;database=IdentityServer8.EntityFramework-8.0.0;trusted_connection=yes;\",\n  }\n}"
  },
  {
    "path": "src/EntityFramework/migrations.bat",
    "content": "cd host\nrmdir /S /Q Migrations\n\ndotnet ef migrations add Grants -c PersistedGrantDbContext -o Migrations/IdentityServer/PersistedGrantDb\ndotnet ef migrations add Config -c ConfigurationDbContext -o Migrations/IdentityServer/ConfigurationDb\ndotnet ef migrations script -c PersistedGrantDbContext -o Migrations/IdentityServer/PersistedGrantDb.sql\ndotnet ef migrations script -c ConfigurationDbContext -o Migrations/IdentityServer/ConfigurationDb.sql\n\ncd ..\n"
  },
  {
    "path": "src/EntityFramework/src/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityServer8.EntityFramework;\nglobal using IdentityServer8.EntityFramework.DbContexts;\nglobal using IdentityServer8.EntityFramework.Interfaces;\nglobal using IdentityServer8.EntityFramework.Options;\nglobal using IdentityServer8.EntityFramework.Services;\nglobal using IdentityServer8.EntityFramework.Storage;\nglobal using IdentityServer8.EntityFramework.Stores;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Stores;\nglobal using Microsoft.AspNetCore.Http;\nglobal using Microsoft.EntityFrameworkCore;\nglobal using Microsoft.Extensions.DependencyInjection;\nglobal using Microsoft.Extensions.Hosting;\nglobal using Microsoft.Extensions.Logging;\n"
  },
  {
    "path": "src/EntityFramework/src/IdentityServer8.EntityFramework.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n    <PropertyGroup>\n        <Description>EntityFramework persistence layer for IdentityServer8</Description>\n        <IsPackable>true</IsPackable>\n        <GeneratePackageOnBuild>true</GeneratePackageOnBuild>\n    </PropertyGroup>\n\n    <PropertyGroup>\n        <ContinuousIntegrationBuild Condition=\"'$(TF_BUILD)' == 'true'\">True</ContinuousIntegrationBuild>\n        <ContinuousIntegrationBuild Condition=\"'$(GITHUB_ACTIONS)' == 'true'\">True</ContinuousIntegrationBuild>\n    </PropertyGroup>\n\n    <ItemGroup>\n        <ProjectReference Include=\"..\\..\\EntityFramework.Storage\\src\\IdentityServer8.EntityFramework.Storage.csproj\" />\n        <ProjectReference Include=\"..\\..\\IdentityServer8\\src\\IdentityServer8.csproj\" />\n    </ItemGroup>\n</Project>"
  },
  {
    "path": "src/EntityFramework/src/IdentityServerEntityFrameworkBuilderExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// Extension methods to add EF database support to IdentityServer.\n/// </summary>\npublic static class IdentityServerEntityFrameworkBuilderExtensions\n{\n    /// <summary>\n    /// Configures EF implementation of IClientStore, IResourceStore, and ICorsPolicyService with IdentityServer.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"storeOptionsAction\">The store options action.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddConfigurationStore(\n        this IIdentityServerBuilder builder,\n        Action<ConfigurationStoreOptions> storeOptionsAction = null)\n    {\n        return builder.AddConfigurationStore<ConfigurationDbContext>(storeOptionsAction);\n    }\n\n    /// <summary>\n    /// Configures EF implementation of IClientStore, IResourceStore, and ICorsPolicyService with IdentityServer.\n    /// </summary>\n    /// <typeparam name=\"TContext\">The IConfigurationDbContext to use.</typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"storeOptionsAction\">The store options action.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddConfigurationStore<TContext>(\n        this IIdentityServerBuilder builder,\n        Action<ConfigurationStoreOptions> storeOptionsAction = null)\n        where TContext : DbContext, IConfigurationDbContext\n    {\n        builder.Services.AddConfigurationDbContext<TContext>(storeOptionsAction);\n\n        builder.AddClientStore<ClientStore>();\n        builder.AddResourceStore<ResourceStore>();\n        builder.AddCorsPolicyService<CorsPolicyService>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Configures caching for IClientStore, IResourceStore, and ICorsPolicyService with IdentityServer.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddConfigurationStoreCache(\n        this IIdentityServerBuilder builder)\n    {\n        builder.AddInMemoryCaching();\n\n        // add the caching decorators\n        builder.AddClientStoreCache<ClientStore>();\n        builder.AddResourceStoreCache<ResourceStore>();\n        builder.AddCorsPolicyCache<CorsPolicyService>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Configures EF implementation of IPersistedGrantStore with IdentityServer.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"storeOptionsAction\">The store options action.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddOperationalStore(\n        this IIdentityServerBuilder builder,\n        Action<OperationalStoreOptions> storeOptionsAction = null)\n    {\n        return builder.AddOperationalStore<PersistedGrantDbContext>(storeOptionsAction);\n    }\n\n    /// <summary>\n    /// Configures EF implementation of IPersistedGrantStore with IdentityServer.\n    /// </summary>\n    /// <typeparam name=\"TContext\">The IPersistedGrantDbContext to use.</typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"storeOptionsAction\">The store options action.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddOperationalStore<TContext>(\n        this IIdentityServerBuilder builder,\n        Action<OperationalStoreOptions> storeOptionsAction = null)\n        where TContext : DbContext, IPersistedGrantDbContext\n    {\n        builder.Services.AddOperationalDbContext<TContext>(storeOptionsAction);\n\n        builder.Services.AddTransient<IPersistedGrantStore, PersistedGrantStore>();\n        builder.Services.AddTransient<IDeviceFlowStore, DeviceFlowStore>();\n        builder.Services.AddSingleton<IHostedService, TokenCleanupHost>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds an implementation of the IOperationalStoreNotification to IdentityServer.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\"></param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddOperationalStoreNotification<T>(\n       this IIdentityServerBuilder builder)\n       where T : class, IOperationalStoreNotification\n    {\n        builder.Services.AddOperationalStoreNotification<T>();\n        return builder;\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/src/Services/CorsPolicyService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Services;\n\n/// <summary>\n/// Implementation of ICorsPolicyService that consults the client configuration in the database for allowed CORS origins.\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.ICorsPolicyService\" />\npublic class CorsPolicyService : ICorsPolicyService\n{\n    private readonly IHttpContextAccessor _context;\n    private readonly ILogger<CorsPolicyService> _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"CorsPolicyService\"/> class.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <param name=\"logger\">The logger.</param>\n    /// <exception cref=\"ArgumentNullException\">context</exception>\n    public CorsPolicyService(IHttpContextAccessor context, ILogger<CorsPolicyService> logger)\n    {\n        _context = context ?? throw new ArgumentNullException(nameof(context));\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Determines whether origin is allowed.\n    /// </summary>\n    /// <param name=\"origin\">The origin.</param>\n    /// <returns></returns>\n    public async Task<bool> IsOriginAllowedAsync(string origin)\n    {\n        origin = origin.ToLowerInvariant();\n\n        // doing this here and not in the ctor because: https://github.com/aspnet/CORS/issues/105\n        var dbContext = _context.HttpContext.RequestServices.GetRequiredService<IConfigurationDbContext>();\n\n        var query = from o in dbContext.ClientCorsOrigins\n                    where o.Origin == origin\n                    select o;\n        \n        var isAllowed = await query.AnyAsync();\n\n        _logger.LogDebug(\"Origin {origin} is allowed: {originAllowed}\", Ioc.Sanitizer.Log.Sanitize(origin), isAllowed);\n\n        return isAllowed;\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/src/TokenCleanupHost.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// Helper to cleanup expired persisted grants.\n/// </summary>\npublic class TokenCleanupHost : IHostedService\n{\n    private readonly IServiceProvider _serviceProvider;\n    private readonly OperationalStoreOptions _options;\n    private readonly ILogger<TokenCleanupHost> _logger;\n\n    private TimeSpan CleanupInterval => TimeSpan.FromSeconds(_options.TokenCleanupInterval);\n    \n    private CancellationTokenSource _source;\n\n    /// <summary>\n    /// Constructor for TokenCleanupHost.\n    /// </summary>\n    /// <param name=\"serviceProvider\"></param>\n    /// <param name=\"options\"></param>\n    /// <param name=\"logger\"></param>\n    public TokenCleanupHost(IServiceProvider serviceProvider, OperationalStoreOptions options, ILogger<TokenCleanupHost> logger)\n    {\n        _serviceProvider = serviceProvider ?? throw new ArgumentNullException(nameof(serviceProvider));\n        _options = options ?? throw new ArgumentNullException(nameof(options));\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Starts the token cleanup polling.\n    /// </summary>\n    public Task StartAsync(CancellationToken cancellationToken)\n    {\n        if (_options.EnableTokenCleanup)\n        {\n            if (_source != null) throw new InvalidOperationException(\"Already started. Call Stop first.\");\n\n            _logger.LogDebug(\"Starting grant removal\");\n\n            _source = CancellationTokenSource.CreateLinkedTokenSource(cancellationToken);\n\n            Task.Factory.StartNew(() => StartInternalAsync(_source.Token));\n        }\n        \n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Stops the token cleanup polling.\n    /// </summary>\n    public Task StopAsync(CancellationToken cancellationToken)\n    {\n        if (_options.EnableTokenCleanup)\n        {\n            if (_source == null) throw new InvalidOperationException(\"Not started. Call Start first.\");\n\n            _logger.LogDebug(\"Stopping grant removal\");\n\n            _source.Cancel();\n            _source = null;\n        }\n\n        return Task.CompletedTask;\n    }\n\n    private async Task StartInternalAsync(CancellationToken cancellationToken)\n    {\n        while (true)\n        {\n            if (cancellationToken.IsCancellationRequested)\n            {\n                _logger.LogDebug(\"CancellationRequested. Exiting.\");\n                break;\n            }\n\n            try\n            {\n                await Task.Delay(CleanupInterval, cancellationToken);\n            }\n            catch (TaskCanceledException)\n            {\n                _logger.LogDebug(\"TaskCanceledException. Exiting.\");\n                break;\n            }\n            catch (Exception ex)\n            {\n                _logger.LogError(\"Task.Delay exception: {0}. Exiting.\", ex.Message);\n                break;\n            }\n\n            if (cancellationToken.IsCancellationRequested)\n            {\n                _logger.LogDebug(\"CancellationRequested. Exiting.\");\n                break;\n            }\n\n            await RemoveExpiredGrantsAsync();\n        }\n    }\n\n    async Task RemoveExpiredGrantsAsync()\n    {\n        try\n        {\n            using (var serviceScope = _serviceProvider.GetRequiredService<IServiceScopeFactory>().CreateScope())\n            {\n                var tokenCleanupService = serviceScope.ServiceProvider.GetRequiredService<TokenCleanupService>();\n                await tokenCleanupService.RemoveExpiredGrantsAsync();\n            }\n        }\n        catch (Exception ex)\n        {\n            _logger.LogError(\"Exception removing expired grants: {exception}\", ex.Message);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/test/IdentityServer8.EntityFramework.Tests/DatabaseProviderBuilder.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.EntityFrameworkCore;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests;\n\n/// <summary>\n/// Helper methods to initialize DbContextOptions for the specified database provider and context.\n/// </summary>\npublic class DatabaseProviderBuilder\n{\n    public static DbContextOptions<T> BuildInMemory<T>(string name) where T : DbContext\n    {\n        var builder = new DbContextOptionsBuilder<T>();\n        builder.UseInMemoryDatabase(name);\n        return builder.Options;\n    }\n\n    public static DbContextOptions<T> BuildSqlite<T>(string name) where T : DbContext\n    {\n        var builder = new DbContextOptionsBuilder<T>();\n        builder.UseSqlite($\"Filename=./Test.IdentityServer8.EntityFramework-3.1.0.{name}.db\");\n        return builder.Options;\n    }\n\n    public static DbContextOptions<T> BuildLocalDb<T>(string name) where T : DbContext\n    {\n        var builder = new DbContextOptionsBuilder<T>();\n        builder.UseSqlServer(\n            $@\"Data Source=(LocalDb)\\MSSQLLocalDB;database=Test.IdentityServer8.EntityFramework-3.1.0.{name};trusted_connection=yes;\");\n        return builder.Options;\n    }\n\n    public static DbContextOptions<T> BuildAppVeyorSqlServer2016<T>(string name) where T : DbContext\n    {\n        var builder = new DbContextOptionsBuilder<T>();\n        builder.UseSqlServer($@\"Server=(local)\\SQL2016;Database=Test.IdentityServer8.EntityFramework-3.1.0.{name};User ID=sa;Password=Password12!\");\n        return builder.Options;\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/test/IdentityServer8.EntityFramework.Tests/DatabaseProviderFixture.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing Microsoft.EntityFrameworkCore;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests;\n\n/// <summary>\n/// xUnit ClassFixture for creating and deleting integration test databases.\n/// </summary>\n/// <typeparam name=\"T\">DbContext of Type T</typeparam>\npublic class DatabaseProviderFixture<T> : IDisposable where T : DbContext\n{\n    public object StoreOptions;\n    public List<DbContextOptions<T>> Options;\n\n    public void Dispose()\n    {\n        if (Options != null) // null check since fixtures are created even when tests are skipped\n        {\n            foreach (var option in Options.ToList())\n            {\n                using (var context = (T)Activator.CreateInstance(typeof(T), option, StoreOptions))\n                {\n                    context.Database.EnsureDeleted();\n                }\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/test/IdentityServer8.EntityFramework.Tests/FakeLogger.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.Extensions.Logging;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests;\n\npublic class FakeLogger<T> : FakeLogger, ILogger<T>\n{\n    public static ILogger<T> Create()\n    {\n        return new FakeLogger<T>();\n    }\n}\n\npublic class FakeLogger : ILogger, IDisposable\n{\n    public IDisposable BeginScope<TState>(TState state)\n    {\n        return this;\n    }\n\n    public void Dispose()\n    {\n    }\n\n    public bool IsEnabled(LogLevel logLevel)\n    {\n        return false;\n    }\n\n    public void Log<TState>(LogLevel logLevel, EventId eventId, TState state, Exception exception, Func<TState, Exception, string> formatter)\n    {\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/test/IdentityServer8.EntityFramework.Tests/IdentityServer8.EntityFramework.Tests.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n  <PropertyGroup>\n    <IsPackable>false</IsPackable>\n  </PropertyGroup>\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.NET.Test.Sdk\" />\n    <PackageReference Include=\"xunit\" />\n    <PackageReference Include=\"xunit.runner.visualstudio\" />\n    <PackageReference Include=\"FluentAssertions\" />\n    <PackageReference Include=\"coverlet.collector\" GeneratePathProperty=\"true\">\n        <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n        <PrivateAssets>all</PrivateAssets>\n    </PackageReference>\n      <PackageReference Include=\"Microsoft.EntityFrameworkCore.Sqlite\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.InMemory\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.SqlServer\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\..\\src\\IdentityServer8.EntityFramework.csproj\" />\n  </ItemGroup>\n  \n  \n\n</Project>\n"
  },
  {
    "path": "src/EntityFramework/test/IdentityServer8.EntityFramework.Tests/IntegrationTest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.EntityFrameworkCore;\nusing Microsoft.Extensions.Configuration;\nusing System.Runtime.InteropServices;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests;\n\n/// <summary>\n/// Base class for integration tests, responsible for initializing test database providers & an xUnit class fixture\n/// </summary>\n/// <typeparam name=\"TClass\">The type of the class.</typeparam>\n/// <typeparam name=\"TDbContext\">The type of the database context.</typeparam>\n/// <typeparam name=\"TStoreOption\">The type of the store option.</typeparam>\n/// <seealso cref=\"DatabaseProviderFixture{T}\" />\npublic class IntegrationTest<TClass, TDbContext, TStoreOption> : IClassFixture<DatabaseProviderFixture<TDbContext>>\n    where TDbContext : DbContext\n{\n    public static readonly TheoryData<DbContextOptions<TDbContext>> TestDatabaseProviders;\n    protected readonly TStoreOption StoreOptions = Activator.CreateInstance<TStoreOption>();\n\n    static IntegrationTest()\n    {\n        var config = new ConfigurationBuilder()\n            .AddEnvironmentVariables()\n            .Build();\n\n        if (RuntimeInformation.IsOSPlatform(OSPlatform.Windows))\n        {\n            Console.WriteLine($\"Running Local Tests for {typeof(TClass).Name}\");\n\n            TestDatabaseProviders = new TheoryData<DbContextOptions<TDbContext>>\n            {\n                DatabaseProviderBuilder.BuildInMemory<TDbContext>(typeof(TClass).Name),\n                DatabaseProviderBuilder.BuildSqlite<TDbContext>(typeof(TClass).Name),\n                DatabaseProviderBuilder.BuildLocalDb<TDbContext>(typeof(TClass).Name)\n            };\n        }\n        else\n        {\n            TestDatabaseProviders = new TheoryData<DbContextOptions<TDbContext>>\n            {\n                DatabaseProviderBuilder.BuildInMemory<TDbContext>(typeof(TClass).Name),\n                DatabaseProviderBuilder.BuildSqlite<TDbContext>(typeof(TClass).Name)\n            };\n            Console.WriteLine(\"Skipping DB integration tests on non-Windows\");\n        }\n    }\n\n    protected IntegrationTest(DatabaseProviderFixture<TDbContext> fixture)\n    {\n        fixture.Options = TestDatabaseProviders.SelectMany(x => x.Select(y => (DbContextOptions<TDbContext>)y)).ToList();\n        fixture.StoreOptions = StoreOptions;\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/test/IdentityServer8.EntityFramework.Tests/Services/CorsPolicyServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.DbContexts;\nusing IdentityServer8.EntityFramework.Interfaces;\nusing IdentityServer8.EntityFramework.Mappers;\nusing IdentityServer8.EntityFramework.Options;\nusing IdentityServer8.EntityFramework.Services;\nusing IdentityServer8.Models;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.EntityFrameworkCore;\nusing Microsoft.Extensions.DependencyInjection;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests.Services;\n\npublic class CorsPolicyServiceTests : IntegrationTest<CorsPolicyServiceTests, ConfigurationDbContext, ConfigurationStoreOptions>\n{\n    public CorsPolicyServiceTests(DatabaseProviderFixture<ConfigurationDbContext> fixture) : base(fixture)\n    {\n        foreach (var options in TestDatabaseProviders.SelectMany(x => x.Select(y => (DbContextOptions<ConfigurationDbContext>)y)).ToList())\n        {\n            using (var context = new ConfigurationDbContext(options, StoreOptions))\n                context.Database.EnsureCreated();\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task IsOriginAllowedAsync_WhenOriginIsAllowed_ExpectTrue(DbContextOptions<ConfigurationDbContext> options)\n    {\n        const string testCorsOrigin = \"https://identityserver8.io/\";\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.Clients.Add(new Client\n            {\n                ClientId = Guid.NewGuid().ToString(),\n                ClientName = Guid.NewGuid().ToString(),\n                AllowedCorsOrigins = new List<string> { \"https://www.identityserver8.com\" }\n            }.ToEntity());\n            context.Clients.Add(new Client\n            {\n                ClientId = \"2\",\n                ClientName = \"2\",\n                AllowedCorsOrigins = new List<string> { \"https://www.identityserver8.com\", testCorsOrigin }\n            }.ToEntity());\n            context.SaveChanges();\n        }\n\n        bool result;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var ctx = new DefaultHttpContext();\n            var svcs = new ServiceCollection();\n            svcs.AddSingleton<IConfigurationDbContext>(context);\n            ctx.RequestServices = svcs.BuildServiceProvider();\n            var ctxAccessor = new HttpContextAccessor();\n            ctxAccessor.HttpContext = ctx;\n\n            var service = new CorsPolicyService(ctxAccessor, FakeLogger<CorsPolicyService>.Create());\n            result = await service.IsOriginAllowedAsync(testCorsOrigin);\n        }\n\n        Assert.True(result);\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task IsOriginAllowedAsync_WhenOriginIsNotAllowed_ExpectFalse(DbContextOptions<ConfigurationDbContext> options)\n    {\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.Clients.Add(new Client\n            {\n                ClientId = Guid.NewGuid().ToString(),\n                ClientName = Guid.NewGuid().ToString(),\n                AllowedCorsOrigins = new List<string> { \"https://www.identityserver8.com\" }\n            }.ToEntity());\n            context.SaveChanges();\n        }\n\n        bool result;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var ctx = new DefaultHttpContext();\n            var svcs = new ServiceCollection();\n            svcs.AddSingleton<IConfigurationDbContext>(context);\n            ctx.RequestServices = svcs.BuildServiceProvider();\n            var ctxAccessor = new HttpContextAccessor();\n            ctxAccessor.HttpContext = ctx;\n\n            var service = new CorsPolicyService(ctxAccessor, FakeLogger<CorsPolicyService>.Create());\n            result = await service.IsOriginAllowedAsync(\"InvalidOrigin\");\n        }\n\n        Assert.False(result);\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework/updatedb.bat",
    "content": "cd host\ndotnet ef database update -c PersistedGrantDbContext\ndotnet ef database update -c ConfigurationDbContext\ndotnet run /seed\ncd ..\n"
  },
  {
    "path": "src/EntityFramework.Storage/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "src/EntityFramework.Storage/IdentityServer8.EntityFramework.Storage.sln",
    "content": "\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 16\nVisualStudioVersion = 16.0.30204.135\nMinimumVisualStudioVersion = 15.0.26124.0\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{AF5DAC33-08AC-45EE-9772-4FF39FB09E57}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.EntityFramework.Storage\", \"src\\IdentityServer8.EntityFramework.Storage.csproj\", \"{5302DAB3-1662-4956-97AA-5EA5E85B10F6}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"test\", \"test\", \"{712ED94A-F982-4667-A9CE-E8F21900BBED}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.EntityFramework.UnitTests\", \"test\\UnitTests\\IdentityServer8.EntityFramework.UnitTests.csproj\", \"{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.EntityFramework.IntegrationTests\", \"test\\IntegrationTests\\IdentityServer8.EntityFramework.IntegrationTests.csproj\", \"{E90F7470-C7F8-464B-9C28-87C474085812}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"migrations\", \"migrations\", \"{E3EF31E0-6658-4899-8BDA-FF84355E2FDD}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"SqlServer\", \"migrations\\SqlServer\\SqlServer.csproj\", \"{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"host\", \"host\", \"{07C56E10-A807-4372-ACD9-ADED2D099BC8}\"\nEndProject\nProject(\"{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}\") = \"ConsoleHost\", \"host\\ConsoleHost\\ConsoleHost.csproj\", \"{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tDebug|x64 = Debug|x64\n\t\tDebug|x86 = Debug|x86\n\t\tRelease|Any CPU = Release|Any CPU\n\t\tRelease|x64 = Release|x64\n\t\tRelease|x86 = Release|x86\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Release|x64.Build.0 = Release|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Release|x86.Build.0 = Release|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Release|x64.Build.0 = Release|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Release|x86.Build.0 = Release|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Release|x64.Build.0 = Release|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Release|x86.Build.0 = Release|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Release|x64.Build.0 = Release|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Release|x86.Build.0 = Release|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Release|x64.Build.0 = Release|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Release|x86.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6} = {AF5DAC33-08AC-45EE-9772-4FF39FB09E57}\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC} = {712ED94A-F982-4667-A9CE-E8F21900BBED}\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812} = {712ED94A-F982-4667-A9CE-E8F21900BBED}\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3} = {E3EF31E0-6658-4899-8BDA-FF84355E2FDD}\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5} = {07C56E10-A807-4372-ACD9-ADED2D099BC8}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {4DB894E3-1BF2-4410-911A-14D32FD79A96}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "src/EntityFramework.Storage/README.md",
    "content": "# IdentityServer8.EntityFramework.Storage\n\nIdentityServer8.EntityFramework.Storage is a persistence layer for IdentityServer 4 configuration data that uses EntityFramework as its database abstraction.\n\n## Issues\n\nFor issues, use the [consolidated IdentityServer8 issue tracker](https://github.com/alexhiggins732/IdentityServer8/issues).\n"
  },
  {
    "path": "src/EntityFramework.Storage/build.cmd",
    "content": "@echo off\ndotnet run --project build -- %*"
  },
  {
    "path": "src/EntityFramework.Storage/build.ps1",
    "content": "$ErrorActionPreference = \"Stop\";\ndotnet run --project build -- $args"
  },
  {
    "path": "src/EntityFramework.Storage/build.sh",
    "content": "#!/usr/bin/env bash\nset -euo pipefail\ndotnet run --project build -- \"$@\""
  },
  {
    "path": "src/EntityFramework.Storage/host/ConsoleHost/ConsoleHost.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n  </PropertyGroup>\n\n  <ItemGroup>\n    <FrameworkReference Include=\"Microsoft.AspNetCore.App\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.SqlServer\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\..\\src\\IdentityServer8.EntityFramework.Storage.csproj\" />\n  </ItemGroup>\n\n</Project>\n"
  },
  {
    "path": "src/EntityFramework.Storage/host/ConsoleHost/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityServer8.EntityFramework;\nglobal using IdentityServer8.EntityFramework.Storage;\nglobal using Microsoft.EntityFrameworkCore;\nglobal using Microsoft.Extensions.DependencyInjection;\nglobal using Microsoft.Extensions.Logging;"
  },
  {
    "path": "src/EntityFramework.Storage/host/ConsoleHost/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace ConsoleHost;\n\nclass Program\n{\n    static void Main(string[] args)\n    {\n        var connectionString = \"server=(localdb)\\\\mssqllocaldb;database=IdentityServer8.EntityFramework-8.0.0;trusted_connection=yes;\";\n\n        var services = new ServiceCollection();\n        services.AddLogging(b => b.AddConsole().SetMinimumLevel(LogLevel.Trace));\n        services.AddOperationalDbContext(options =>\n        {\n            options.ConfigureDbContext = builder => builder.UseSqlServer(connectionString);\n\n            // this enables automatic token cleanup. this is optional.\n            options.EnableTokenCleanup = false;\n            options.TokenCleanupInterval = 5; // interval in seconds, short for testing\n        });\n\n        var sp = services.BuildServiceProvider();\n        using (var scope = sp.CreateScope())\n        {\n            var svc = scope.ServiceProvider.GetRequiredService<TokenCleanupService>();\n            svc.RemoveExpiredGrantsAsync().GetAwaiter().GetResult();\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/host/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityServer8.EntityFramework.DbContexts;\nglobal using IdentityServer8.EntityFramework.Storage;\nglobal using Microsoft.AspNetCore;\nglobal using Microsoft.EntityFrameworkCore;\nglobal using Microsoft.EntityFrameworkCore.Infrastructure;\nglobal using Microsoft.EntityFrameworkCore.Metadata;\nglobal using Microsoft.EntityFrameworkCore.Migrations;\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Migrations/ConfigurationDb/20200522172542_Config.Designer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\n\nnamespace SqlServer.Migrations.ConfigurationDb\n{\n    [DbContext(typeof(ConfigurationDbContext))]\n    [Migration(\"20200522172542_Config\")]\n    partial class Config\n    {\n        protected override void BuildTargetModel(ModelBuilder modelBuilder)\n        {\n#pragma warning disable 612, 618\n            modelBuilder\n                .HasAnnotation(\"ProductVersion\", \"3.1.0\")\n                .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n                .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResource\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"AllowedAccessTokenSigningAlgorithms\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<string>(\"DisplayName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"LastAccessed\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Name\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"NonEditable\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"ShowInDiscoveryDocument\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"Updated\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"Name\")\n                        .IsUnique();\n\n                    b.ToTable(\"ApiResources\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceScope\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Scope\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceScopes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceSecret\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ApiResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(4000)\")\n                        .HasMaxLength(4000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ApiResourceId\");\n\n                    b.ToTable(\"ApiResourceSecrets\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScope\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<string>(\"DisplayName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Emphasize\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"Name\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Required\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"ShowInDiscoveryDocument\")\n                        .HasColumnType(\"bit\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"Name\")\n                        .IsUnique();\n\n                    b.ToTable(\"ApiScopes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ScopeId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ScopeId\");\n\n                    b.ToTable(\"ApiScopeClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<int>(\"ScopeId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ScopeId\");\n\n                    b.ToTable(\"ApiScopeProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.Client\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"AbsoluteRefreshTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<int>(\"AccessTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<int>(\"AccessTokenType\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"AllowAccessTokensViaBrowser\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AllowOfflineAccess\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AllowPlainTextPkce\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AllowRememberConsent\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"AllowedIdentityTokenSigningAlgorithms\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<bool>(\"AlwaysIncludeUserClaimsInIdToken\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"AlwaysSendClientClaims\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<int>(\"AuthorizationCodeLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"BackChannelLogoutSessionRequired\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"BackChannelLogoutUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<string>(\"ClientClaimsPrefix\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<int?>(\"ConsentLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<int>(\"DeviceCodeLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"EnableLocalLogin\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"FrontChannelLogoutSessionRequired\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"FrontChannelLogoutUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<int>(\"IdentityTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"IncludeJwtId\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"LastAccessed\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"LogoUri\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<bool>(\"NonEditable\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"PairWiseSubjectSalt\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ProtocolType\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<int>(\"RefreshTokenExpiration\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<int>(\"RefreshTokenUsage\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"RequireClientSecret\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"RequireConsent\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"RequirePkce\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"RequireRequestObject\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<int>(\"SlidingRefreshTokenLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<bool>(\"UpdateAccessTokenClaimsOnRefresh\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"Updated\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"UserCodeType\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<int?>(\"UserSsoLifetime\")\n                        .HasColumnType(\"int\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\")\n                        .IsUnique();\n\n                    b.ToTable(\"Clients\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientCorsOrigin\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Origin\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(150)\")\n                        .HasMaxLength(150);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientCorsOrigins\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientGrantType\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"GrantType\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientGrantTypes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientIdPRestriction\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Provider\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientIdPRestrictions\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientPostLogoutRedirectUri\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"PostLogoutRedirectUri\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientPostLogoutRedirectUris\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientRedirectUri\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"RedirectUri\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientRedirectUris\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientScope\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Scope\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientScopes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientSecret\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"ClientId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(4000)\")\n                        .HasMaxLength(4000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"ClientId\");\n\n                    b.ToTable(\"ClientSecrets\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<DateTime>(\"Created\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(1000)\")\n                        .HasMaxLength(1000);\n\n                    b.Property<string>(\"DisplayName\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"Emphasize\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Enabled\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<string>(\"Name\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<bool>(\"NonEditable\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"Required\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<bool>(\"ShowInDiscoveryDocument\")\n                        .HasColumnType(\"bit\");\n\n                    b.Property<DateTime?>(\"Updated\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"Name\")\n                        .IsUnique();\n\n                    b.ToTable(\"IdentityResources\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceClaim\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"IdentityResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"IdentityResourceId\");\n\n                    b.ToTable(\"IdentityResourceClaims\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceProperty\", b =>\n                {\n                    b.Property<int>(\"Id\")\n                        .ValueGeneratedOnAdd()\n                        .HasColumnType(\"int\")\n                        .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                    b.Property<int>(\"IdentityResourceId\")\n                        .HasColumnType(\"int\");\n\n                    b.Property<string>(\"Key\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(250)\")\n                        .HasMaxLength(250);\n\n                    b.Property<string>(\"Value\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(2000)\")\n                        .HasMaxLength(2000);\n\n                    b.HasKey(\"Id\");\n\n                    b.HasIndex(\"IdentityResourceId\");\n\n                    b.ToTable(\"IdentityResourceProperties\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"UserClaims\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceScope\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"Scopes\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceSecret\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                        .WithMany(\"Secrets\")\n                        .HasForeignKey(\"ApiResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiScope\", \"Scope\")\n                        .WithMany(\"UserClaims\")\n                        .HasForeignKey(\"ScopeId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiScope\", \"Scope\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"ScopeId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"Claims\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientCorsOrigin\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"AllowedCorsOrigins\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientGrantType\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"AllowedGrantTypes\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientIdPRestriction\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"IdentityProviderRestrictions\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientPostLogoutRedirectUri\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"PostLogoutRedirectUris\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientRedirectUri\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"RedirectUris\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientScope\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"AllowedScopes\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientSecret\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                        .WithMany(\"ClientSecrets\")\n                        .HasForeignKey(\"ClientId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceClaim\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", \"IdentityResource\")\n                        .WithMany(\"UserClaims\")\n                        .HasForeignKey(\"IdentityResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceProperty\", b =>\n                {\n                    b.HasOne(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", \"IdentityResource\")\n                        .WithMany(\"Properties\")\n                        .HasForeignKey(\"IdentityResourceId\")\n                        .OnDelete(DeleteBehavior.Cascade)\n                        .IsRequired();\n                });\n#pragma warning restore 612, 618\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Migrations/ConfigurationDb/20200522172542_Config.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace SqlServer.Migrations.ConfigurationDb;\n\npublic partial class Config : Migration\n{\n    protected override void Up(MigrationBuilder migrationBuilder)\n    {\n        migrationBuilder.CreateTable(\n            name: \"ApiResources\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Enabled = table.Column<bool>(nullable: false),\n                Name = table.Column<string>(maxLength: 200, nullable: false),\n                DisplayName = table.Column<string>(maxLength: 200, nullable: true),\n                Description = table.Column<string>(maxLength: 1000, nullable: true),\n                AllowedAccessTokenSigningAlgorithms = table.Column<string>(maxLength: 100, nullable: true),\n                ShowInDiscoveryDocument = table.Column<bool>(nullable: false),\n                Created = table.Column<DateTime>(nullable: false),\n                Updated = table.Column<DateTime>(nullable: true),\n                LastAccessed = table.Column<DateTime>(nullable: true),\n                NonEditable = table.Column<bool>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ApiResources\", x => x.Id);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ApiScopes\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Enabled = table.Column<bool>(nullable: false),\n                Name = table.Column<string>(maxLength: 200, nullable: false),\n                DisplayName = table.Column<string>(maxLength: 200, nullable: true),\n                Description = table.Column<string>(maxLength: 1000, nullable: true),\n                Required = table.Column<bool>(nullable: false),\n                Emphasize = table.Column<bool>(nullable: false),\n                ShowInDiscoveryDocument = table.Column<bool>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ApiScopes\", x => x.Id);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"Clients\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Enabled = table.Column<bool>(nullable: false),\n                ClientId = table.Column<string>(maxLength: 200, nullable: false),\n                ProtocolType = table.Column<string>(maxLength: 200, nullable: false),\n                RequireClientSecret = table.Column<bool>(nullable: false),\n                ClientName = table.Column<string>(maxLength: 200, nullable: true),\n                Description = table.Column<string>(maxLength: 1000, nullable: true),\n                ClientUri = table.Column<string>(maxLength: 2000, nullable: true),\n                LogoUri = table.Column<string>(maxLength: 2000, nullable: true),\n                RequireConsent = table.Column<bool>(nullable: false),\n                AllowRememberConsent = table.Column<bool>(nullable: false),\n                AlwaysIncludeUserClaimsInIdToken = table.Column<bool>(nullable: false),\n                RequirePkce = table.Column<bool>(nullable: false),\n                AllowPlainTextPkce = table.Column<bool>(nullable: false),\n                RequireRequestObject = table.Column<bool>(nullable: false),\n                AllowAccessTokensViaBrowser = table.Column<bool>(nullable: false),\n                FrontChannelLogoutUri = table.Column<string>(maxLength: 2000, nullable: true),\n                FrontChannelLogoutSessionRequired = table.Column<bool>(nullable: false),\n                BackChannelLogoutUri = table.Column<string>(maxLength: 2000, nullable: true),\n                BackChannelLogoutSessionRequired = table.Column<bool>(nullable: false),\n                AllowOfflineAccess = table.Column<bool>(nullable: false),\n                IdentityTokenLifetime = table.Column<int>(nullable: false),\n                AllowedIdentityTokenSigningAlgorithms = table.Column<string>(maxLength: 100, nullable: true),\n                AccessTokenLifetime = table.Column<int>(nullable: false),\n                AuthorizationCodeLifetime = table.Column<int>(nullable: false),\n                ConsentLifetime = table.Column<int>(nullable: true),\n                AbsoluteRefreshTokenLifetime = table.Column<int>(nullable: false),\n                SlidingRefreshTokenLifetime = table.Column<int>(nullable: false),\n                RefreshTokenUsage = table.Column<int>(nullable: false),\n                UpdateAccessTokenClaimsOnRefresh = table.Column<bool>(nullable: false),\n                RefreshTokenExpiration = table.Column<int>(nullable: false),\n                AccessTokenType = table.Column<int>(nullable: false),\n                EnableLocalLogin = table.Column<bool>(nullable: false),\n                IncludeJwtId = table.Column<bool>(nullable: false),\n                AlwaysSendClientClaims = table.Column<bool>(nullable: false),\n                ClientClaimsPrefix = table.Column<string>(maxLength: 200, nullable: true),\n                PairWiseSubjectSalt = table.Column<string>(maxLength: 200, nullable: true),\n                Created = table.Column<DateTime>(nullable: false),\n                Updated = table.Column<DateTime>(nullable: true),\n                LastAccessed = table.Column<DateTime>(nullable: true),\n                UserSsoLifetime = table.Column<int>(nullable: true),\n                UserCodeType = table.Column<string>(maxLength: 100, nullable: true),\n                DeviceCodeLifetime = table.Column<int>(nullable: false),\n                NonEditable = table.Column<bool>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_Clients\", x => x.Id);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"IdentityResources\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Enabled = table.Column<bool>(nullable: false),\n                Name = table.Column<string>(maxLength: 200, nullable: false),\n                DisplayName = table.Column<string>(maxLength: 200, nullable: true),\n                Description = table.Column<string>(maxLength: 1000, nullable: true),\n                Required = table.Column<bool>(nullable: false),\n                Emphasize = table.Column<bool>(nullable: false),\n                ShowInDiscoveryDocument = table.Column<bool>(nullable: false),\n                Created = table.Column<DateTime>(nullable: false),\n                Updated = table.Column<DateTime>(nullable: true),\n                NonEditable = table.Column<bool>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_IdentityResources\", x => x.Id);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ApiResourceClaims\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Type = table.Column<string>(maxLength: 200, nullable: false),\n                ApiResourceId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ApiResourceClaims\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ApiResourceClaims_ApiResources_ApiResourceId\",\n                    column: x => x.ApiResourceId,\n                    principalTable: \"ApiResources\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ApiResourceProperties\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Key = table.Column<string>(maxLength: 250, nullable: false),\n                Value = table.Column<string>(maxLength: 2000, nullable: false),\n                ApiResourceId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ApiResourceProperties\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ApiResourceProperties_ApiResources_ApiResourceId\",\n                    column: x => x.ApiResourceId,\n                    principalTable: \"ApiResources\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ApiResourceScopes\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Scope = table.Column<string>(maxLength: 200, nullable: false),\n                ApiResourceId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ApiResourceScopes\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ApiResourceScopes_ApiResources_ApiResourceId\",\n                    column: x => x.ApiResourceId,\n                    principalTable: \"ApiResources\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ApiResourceSecrets\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Description = table.Column<string>(maxLength: 1000, nullable: true),\n                Value = table.Column<string>(maxLength: 4000, nullable: false),\n                Expiration = table.Column<DateTime>(nullable: true),\n                Type = table.Column<string>(maxLength: 250, nullable: false),\n                Created = table.Column<DateTime>(nullable: false),\n                ApiResourceId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ApiResourceSecrets\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ApiResourceSecrets_ApiResources_ApiResourceId\",\n                    column: x => x.ApiResourceId,\n                    principalTable: \"ApiResources\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ApiScopeClaims\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Type = table.Column<string>(maxLength: 200, nullable: false),\n                ScopeId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ApiScopeClaims\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ApiScopeClaims_ApiScopes_ScopeId\",\n                    column: x => x.ScopeId,\n                    principalTable: \"ApiScopes\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ApiScopeProperties\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Key = table.Column<string>(maxLength: 250, nullable: false),\n                Value = table.Column<string>(maxLength: 2000, nullable: false),\n                ScopeId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ApiScopeProperties\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ApiScopeProperties_ApiScopes_ScopeId\",\n                    column: x => x.ScopeId,\n                    principalTable: \"ApiScopes\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ClientClaims\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Type = table.Column<string>(maxLength: 250, nullable: false),\n                Value = table.Column<string>(maxLength: 250, nullable: false),\n                ClientId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ClientClaims\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ClientClaims_Clients_ClientId\",\n                    column: x => x.ClientId,\n                    principalTable: \"Clients\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ClientCorsOrigins\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Origin = table.Column<string>(maxLength: 150, nullable: false),\n                ClientId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ClientCorsOrigins\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ClientCorsOrigins_Clients_ClientId\",\n                    column: x => x.ClientId,\n                    principalTable: \"Clients\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ClientGrantTypes\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                GrantType = table.Column<string>(maxLength: 250, nullable: false),\n                ClientId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ClientGrantTypes\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ClientGrantTypes_Clients_ClientId\",\n                    column: x => x.ClientId,\n                    principalTable: \"Clients\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ClientIdPRestrictions\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Provider = table.Column<string>(maxLength: 200, nullable: false),\n                ClientId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ClientIdPRestrictions\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ClientIdPRestrictions_Clients_ClientId\",\n                    column: x => x.ClientId,\n                    principalTable: \"Clients\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ClientPostLogoutRedirectUris\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                PostLogoutRedirectUri = table.Column<string>(maxLength: 2000, nullable: false),\n                ClientId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ClientPostLogoutRedirectUris\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ClientPostLogoutRedirectUris_Clients_ClientId\",\n                    column: x => x.ClientId,\n                    principalTable: \"Clients\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ClientProperties\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Key = table.Column<string>(maxLength: 250, nullable: false),\n                Value = table.Column<string>(maxLength: 2000, nullable: false),\n                ClientId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ClientProperties\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ClientProperties_Clients_ClientId\",\n                    column: x => x.ClientId,\n                    principalTable: \"Clients\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ClientRedirectUris\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                RedirectUri = table.Column<string>(maxLength: 2000, nullable: false),\n                ClientId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ClientRedirectUris\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ClientRedirectUris_Clients_ClientId\",\n                    column: x => x.ClientId,\n                    principalTable: \"Clients\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ClientScopes\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Scope = table.Column<string>(maxLength: 200, nullable: false),\n                ClientId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ClientScopes\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ClientScopes_Clients_ClientId\",\n                    column: x => x.ClientId,\n                    principalTable: \"Clients\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"ClientSecrets\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Description = table.Column<string>(maxLength: 2000, nullable: true),\n                Value = table.Column<string>(maxLength: 4000, nullable: false),\n                Expiration = table.Column<DateTime>(nullable: true),\n                Type = table.Column<string>(maxLength: 250, nullable: false),\n                Created = table.Column<DateTime>(nullable: false),\n                ClientId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_ClientSecrets\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_ClientSecrets_Clients_ClientId\",\n                    column: x => x.ClientId,\n                    principalTable: \"Clients\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"IdentityResourceClaims\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Type = table.Column<string>(maxLength: 200, nullable: false),\n                IdentityResourceId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_IdentityResourceClaims\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_IdentityResourceClaims_IdentityResources_IdentityResourceId\",\n                    column: x => x.IdentityResourceId,\n                    principalTable: \"IdentityResources\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"IdentityResourceProperties\",\n            columns: table => new\n            {\n                Id = table.Column<int>(nullable: false)\n                    .Annotation(\"SqlServer:Identity\", \"1, 1\"),\n                Key = table.Column<string>(maxLength: 250, nullable: false),\n                Value = table.Column<string>(maxLength: 2000, nullable: false),\n                IdentityResourceId = table.Column<int>(nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_IdentityResourceProperties\", x => x.Id);\n                table.ForeignKey(\n                    name: \"FK_IdentityResourceProperties_IdentityResources_IdentityResourceId\",\n                    column: x => x.IdentityResourceId,\n                    principalTable: \"IdentityResources\",\n                    principalColumn: \"Id\",\n                    onDelete: ReferentialAction.Cascade);\n            });\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ApiResourceClaims_ApiResourceId\",\n            table: \"ApiResourceClaims\",\n            column: \"ApiResourceId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ApiResourceProperties_ApiResourceId\",\n            table: \"ApiResourceProperties\",\n            column: \"ApiResourceId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ApiResources_Name\",\n            table: \"ApiResources\",\n            column: \"Name\",\n            unique: true);\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ApiResourceScopes_ApiResourceId\",\n            table: \"ApiResourceScopes\",\n            column: \"ApiResourceId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ApiResourceSecrets_ApiResourceId\",\n            table: \"ApiResourceSecrets\",\n            column: \"ApiResourceId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ApiScopeClaims_ScopeId\",\n            table: \"ApiScopeClaims\",\n            column: \"ScopeId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ApiScopeProperties_ScopeId\",\n            table: \"ApiScopeProperties\",\n            column: \"ScopeId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ApiScopes_Name\",\n            table: \"ApiScopes\",\n            column: \"Name\",\n            unique: true);\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ClientClaims_ClientId\",\n            table: \"ClientClaims\",\n            column: \"ClientId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ClientCorsOrigins_ClientId\",\n            table: \"ClientCorsOrigins\",\n            column: \"ClientId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ClientGrantTypes_ClientId\",\n            table: \"ClientGrantTypes\",\n            column: \"ClientId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ClientIdPRestrictions_ClientId\",\n            table: \"ClientIdPRestrictions\",\n            column: \"ClientId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ClientPostLogoutRedirectUris_ClientId\",\n            table: \"ClientPostLogoutRedirectUris\",\n            column: \"ClientId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ClientProperties_ClientId\",\n            table: \"ClientProperties\",\n            column: \"ClientId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ClientRedirectUris_ClientId\",\n            table: \"ClientRedirectUris\",\n            column: \"ClientId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_Clients_ClientId\",\n            table: \"Clients\",\n            column: \"ClientId\",\n            unique: true);\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ClientScopes_ClientId\",\n            table: \"ClientScopes\",\n            column: \"ClientId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_ClientSecrets_ClientId\",\n            table: \"ClientSecrets\",\n            column: \"ClientId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_IdentityResourceClaims_IdentityResourceId\",\n            table: \"IdentityResourceClaims\",\n            column: \"IdentityResourceId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_IdentityResourceProperties_IdentityResourceId\",\n            table: \"IdentityResourceProperties\",\n            column: \"IdentityResourceId\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_IdentityResources_Name\",\n            table: \"IdentityResources\",\n            column: \"Name\",\n            unique: true);\n    }\n\n    protected override void Down(MigrationBuilder migrationBuilder)\n    {\n        migrationBuilder.DropTable(\n            name: \"ApiResourceClaims\");\n\n        migrationBuilder.DropTable(\n            name: \"ApiResourceProperties\");\n\n        migrationBuilder.DropTable(\n            name: \"ApiResourceScopes\");\n\n        migrationBuilder.DropTable(\n            name: \"ApiResourceSecrets\");\n\n        migrationBuilder.DropTable(\n            name: \"ApiScopeClaims\");\n\n        migrationBuilder.DropTable(\n            name: \"ApiScopeProperties\");\n\n        migrationBuilder.DropTable(\n            name: \"ClientClaims\");\n\n        migrationBuilder.DropTable(\n            name: \"ClientCorsOrigins\");\n\n        migrationBuilder.DropTable(\n            name: \"ClientGrantTypes\");\n\n        migrationBuilder.DropTable(\n            name: \"ClientIdPRestrictions\");\n\n        migrationBuilder.DropTable(\n            name: \"ClientPostLogoutRedirectUris\");\n\n        migrationBuilder.DropTable(\n            name: \"ClientProperties\");\n\n        migrationBuilder.DropTable(\n            name: \"ClientRedirectUris\");\n\n        migrationBuilder.DropTable(\n            name: \"ClientScopes\");\n\n        migrationBuilder.DropTable(\n            name: \"ClientSecrets\");\n\n        migrationBuilder.DropTable(\n            name: \"IdentityResourceClaims\");\n\n        migrationBuilder.DropTable(\n            name: \"IdentityResourceProperties\");\n\n        migrationBuilder.DropTable(\n            name: \"ApiResources\");\n\n        migrationBuilder.DropTable(\n            name: \"ApiScopes\");\n\n        migrationBuilder.DropTable(\n            name: \"Clients\");\n\n        migrationBuilder.DropTable(\n            name: \"IdentityResources\");\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Migrations/ConfigurationDb/ConfigurationDbContextModelSnapshot.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\n\nnamespace SqlServer.Migrations.ConfigurationDb;\n\n[DbContext(typeof(ConfigurationDbContext))]\npartial class ConfigurationDbContextModelSnapshot : ModelSnapshot\n{\n    protected override void BuildModel(ModelBuilder modelBuilder)\n    {\n#pragma warning disable 612, 618\n        modelBuilder\n            .HasAnnotation(\"ProductVersion\", \"3.1.0\")\n            .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n            .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResource\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<string>(\"AllowedAccessTokenSigningAlgorithms\")\n                    .HasColumnType(\"nvarchar(100)\")\n                    .HasMaxLength(100);\n\n                b.Property<DateTime>(\"Created\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Description\")\n                    .HasColumnType(\"nvarchar(1000)\")\n                    .HasMaxLength(1000);\n\n                b.Property<string>(\"DisplayName\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<bool>(\"Enabled\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<DateTime?>(\"LastAccessed\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Name\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<bool>(\"NonEditable\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"ShowInDiscoveryDocument\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<DateTime?>(\"Updated\")\n                    .HasColumnType(\"datetime2\");\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"Name\")\n                    .IsUnique();\n\n                b.ToTable(\"ApiResources\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceClaim\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ApiResourceId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Type\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ApiResourceId\");\n\n                b.ToTable(\"ApiResourceClaims\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceProperty\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ApiResourceId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Key\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(250)\")\n                    .HasMaxLength(250);\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ApiResourceId\");\n\n                b.ToTable(\"ApiResourceProperties\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceScope\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ApiResourceId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Scope\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ApiResourceId\");\n\n                b.ToTable(\"ApiResourceScopes\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceSecret\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ApiResourceId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<DateTime>(\"Created\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Description\")\n                    .HasColumnType(\"nvarchar(1000)\")\n                    .HasMaxLength(1000);\n\n                b.Property<DateTime?>(\"Expiration\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Type\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(250)\")\n                    .HasMaxLength(250);\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(4000)\")\n                    .HasMaxLength(4000);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ApiResourceId\");\n\n                b.ToTable(\"ApiResourceSecrets\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScope\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<string>(\"Description\")\n                    .HasColumnType(\"nvarchar(1000)\")\n                    .HasMaxLength(1000);\n\n                b.Property<string>(\"DisplayName\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<bool>(\"Emphasize\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"Enabled\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<string>(\"Name\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<bool>(\"Required\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"ShowInDiscoveryDocument\")\n                    .HasColumnType(\"bit\");\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"Name\")\n                    .IsUnique();\n\n                b.ToTable(\"ApiScopes\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeClaim\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ScopeId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Type\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ScopeId\");\n\n                b.ToTable(\"ApiScopeClaims\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeProperty\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<string>(\"Key\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(250)\")\n                    .HasMaxLength(250);\n\n                b.Property<int>(\"ScopeId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ScopeId\");\n\n                b.ToTable(\"ApiScopeProperties\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.Client\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"AbsoluteRefreshTokenLifetime\")\n                    .HasColumnType(\"int\");\n\n                b.Property<int>(\"AccessTokenLifetime\")\n                    .HasColumnType(\"int\");\n\n                b.Property<int>(\"AccessTokenType\")\n                    .HasColumnType(\"int\");\n\n                b.Property<bool>(\"AllowAccessTokensViaBrowser\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"AllowOfflineAccess\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"AllowPlainTextPkce\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"AllowRememberConsent\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<string>(\"AllowedIdentityTokenSigningAlgorithms\")\n                    .HasColumnType(\"nvarchar(100)\")\n                    .HasMaxLength(100);\n\n                b.Property<bool>(\"AlwaysIncludeUserClaimsInIdToken\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"AlwaysSendClientClaims\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<int>(\"AuthorizationCodeLifetime\")\n                    .HasColumnType(\"int\");\n\n                b.Property<bool>(\"BackChannelLogoutSessionRequired\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<string>(\"BackChannelLogoutUri\")\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.Property<string>(\"ClientClaimsPrefix\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"ClientId\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"ClientName\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"ClientUri\")\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.Property<int?>(\"ConsentLifetime\")\n                    .HasColumnType(\"int\");\n\n                b.Property<DateTime>(\"Created\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Description\")\n                    .HasColumnType(\"nvarchar(1000)\")\n                    .HasMaxLength(1000);\n\n                b.Property<int>(\"DeviceCodeLifetime\")\n                    .HasColumnType(\"int\");\n\n                b.Property<bool>(\"EnableLocalLogin\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"Enabled\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"FrontChannelLogoutSessionRequired\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<string>(\"FrontChannelLogoutUri\")\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.Property<int>(\"IdentityTokenLifetime\")\n                    .HasColumnType(\"int\");\n\n                b.Property<bool>(\"IncludeJwtId\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<DateTime?>(\"LastAccessed\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"LogoUri\")\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.Property<bool>(\"NonEditable\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<string>(\"PairWiseSubjectSalt\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"ProtocolType\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<int>(\"RefreshTokenExpiration\")\n                    .HasColumnType(\"int\");\n\n                b.Property<int>(\"RefreshTokenUsage\")\n                    .HasColumnType(\"int\");\n\n                b.Property<bool>(\"RequireClientSecret\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"RequireConsent\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"RequirePkce\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"RequireRequestObject\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<int>(\"SlidingRefreshTokenLifetime\")\n                    .HasColumnType(\"int\");\n\n                b.Property<bool>(\"UpdateAccessTokenClaimsOnRefresh\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<DateTime?>(\"Updated\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"UserCodeType\")\n                    .HasColumnType(\"nvarchar(100)\")\n                    .HasMaxLength(100);\n\n                b.Property<int?>(\"UserSsoLifetime\")\n                    .HasColumnType(\"int\");\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ClientId\")\n                    .IsUnique();\n\n                b.ToTable(\"Clients\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientClaim\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ClientId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Type\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(250)\")\n                    .HasMaxLength(250);\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(250)\")\n                    .HasMaxLength(250);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ClientId\");\n\n                b.ToTable(\"ClientClaims\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientCorsOrigin\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ClientId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Origin\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(150)\")\n                    .HasMaxLength(150);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ClientId\");\n\n                b.ToTable(\"ClientCorsOrigins\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientGrantType\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ClientId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"GrantType\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(250)\")\n                    .HasMaxLength(250);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ClientId\");\n\n                b.ToTable(\"ClientGrantTypes\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientIdPRestriction\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ClientId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Provider\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ClientId\");\n\n                b.ToTable(\"ClientIdPRestrictions\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientPostLogoutRedirectUri\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ClientId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"PostLogoutRedirectUri\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ClientId\");\n\n                b.ToTable(\"ClientPostLogoutRedirectUris\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientProperty\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ClientId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Key\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(250)\")\n                    .HasMaxLength(250);\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ClientId\");\n\n                b.ToTable(\"ClientProperties\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientRedirectUri\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ClientId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"RedirectUri\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ClientId\");\n\n                b.ToTable(\"ClientRedirectUris\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientScope\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ClientId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Scope\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ClientId\");\n\n                b.ToTable(\"ClientScopes\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientSecret\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"ClientId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<DateTime>(\"Created\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Description\")\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.Property<DateTime?>(\"Expiration\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Type\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(250)\")\n                    .HasMaxLength(250);\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(4000)\")\n                    .HasMaxLength(4000);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"ClientId\");\n\n                b.ToTable(\"ClientSecrets\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<DateTime>(\"Created\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Description\")\n                    .HasColumnType(\"nvarchar(1000)\")\n                    .HasMaxLength(1000);\n\n                b.Property<string>(\"DisplayName\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<bool>(\"Emphasize\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"Enabled\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<string>(\"Name\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<bool>(\"NonEditable\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"Required\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<bool>(\"ShowInDiscoveryDocument\")\n                    .HasColumnType(\"bit\");\n\n                b.Property<DateTime?>(\"Updated\")\n                    .HasColumnType(\"datetime2\");\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"Name\")\n                    .IsUnique();\n\n                b.ToTable(\"IdentityResources\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceClaim\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"IdentityResourceId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Type\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"IdentityResourceId\");\n\n                b.ToTable(\"IdentityResourceClaims\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceProperty\", b =>\n            {\n                b.Property<int>(\"Id\")\n                    .ValueGeneratedOnAdd()\n                    .HasColumnType(\"int\")\n                    .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n                b.Property<int>(\"IdentityResourceId\")\n                    .HasColumnType(\"int\");\n\n                b.Property<string>(\"Key\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(250)\")\n                    .HasMaxLength(250);\n\n                b.Property<string>(\"Value\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(2000)\")\n                    .HasMaxLength(2000);\n\n                b.HasKey(\"Id\");\n\n                b.HasIndex(\"IdentityResourceId\");\n\n                b.ToTable(\"IdentityResourceProperties\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceClaim\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                    .WithMany(\"UserClaims\")\n                    .HasForeignKey(\"ApiResourceId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceProperty\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                    .WithMany(\"Properties\")\n                    .HasForeignKey(\"ApiResourceId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceScope\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                    .WithMany(\"Scopes\")\n                    .HasForeignKey(\"ApiResourceId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiResourceSecret\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiResource\", \"ApiResource\")\n                    .WithMany(\"Secrets\")\n                    .HasForeignKey(\"ApiResourceId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeClaim\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiScope\", \"Scope\")\n                    .WithMany(\"UserClaims\")\n                    .HasForeignKey(\"ScopeId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ApiScopeProperty\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.ApiScope\", \"Scope\")\n                    .WithMany(\"Properties\")\n                    .HasForeignKey(\"ScopeId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientClaim\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                    .WithMany(\"Claims\")\n                    .HasForeignKey(\"ClientId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientCorsOrigin\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                    .WithMany(\"AllowedCorsOrigins\")\n                    .HasForeignKey(\"ClientId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientGrantType\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                    .WithMany(\"AllowedGrantTypes\")\n                    .HasForeignKey(\"ClientId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientIdPRestriction\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                    .WithMany(\"IdentityProviderRestrictions\")\n                    .HasForeignKey(\"ClientId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientPostLogoutRedirectUri\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                    .WithMany(\"PostLogoutRedirectUris\")\n                    .HasForeignKey(\"ClientId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientProperty\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                    .WithMany(\"Properties\")\n                    .HasForeignKey(\"ClientId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientRedirectUri\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                    .WithMany(\"RedirectUris\")\n                    .HasForeignKey(\"ClientId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientScope\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                    .WithMany(\"AllowedScopes\")\n                    .HasForeignKey(\"ClientId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.ClientSecret\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.Client\", \"Client\")\n                    .WithMany(\"ClientSecrets\")\n                    .HasForeignKey(\"ClientId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceClaim\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", \"IdentityResource\")\n                    .WithMany(\"UserClaims\")\n                    .HasForeignKey(\"IdentityResourceId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.IdentityResourceProperty\", b =>\n            {\n                b.HasOne(\"IdentityServer8.EntityFramework.Entities.IdentityResource\", \"IdentityResource\")\n                    .WithMany(\"Properties\")\n                    .HasForeignKey(\"IdentityResourceId\")\n                    .OnDelete(DeleteBehavior.Cascade)\n                    .IsRequired();\n            });\n#pragma warning restore 612, 618\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Migrations/ConfigurationDb.sql",
    "content": "﻿IF OBJECT_ID(N'[__EFMigrationsHistory]') IS NULL\nBEGIN\n    CREATE TABLE [__EFMigrationsHistory] (\n        [MigrationId] nvarchar(150) NOT NULL,\n        [ProductVersion] nvarchar(32) NOT NULL,\n        CONSTRAINT [PK___EFMigrationsHistory] PRIMARY KEY ([MigrationId])\n    );\nEND;\n\nGO\n\nCREATE TABLE [ApiResources] (\n    [Id] int NOT NULL IDENTITY,\n    [Enabled] bit NOT NULL,\n    [Name] nvarchar(200) NOT NULL,\n    [DisplayName] nvarchar(200) NULL,\n    [Description] nvarchar(1000) NULL,\n    [AllowedAccessTokenSigningAlgorithms] nvarchar(100) NULL,\n    [ShowInDiscoveryDocument] bit NOT NULL,\n    [Created] datetime2 NOT NULL,\n    [Updated] datetime2 NULL,\n    [LastAccessed] datetime2 NULL,\n    [NonEditable] bit NOT NULL,\n    CONSTRAINT [PK_ApiResources] PRIMARY KEY ([Id])\n);\n\nGO\n\nCREATE TABLE [ApiScopes] (\n    [Id] int NOT NULL IDENTITY,\n    [Enabled] bit NOT NULL,\n    [Name] nvarchar(200) NOT NULL,\n    [DisplayName] nvarchar(200) NULL,\n    [Description] nvarchar(1000) NULL,\n    [Required] bit NOT NULL,\n    [Emphasize] bit NOT NULL,\n    [ShowInDiscoveryDocument] bit NOT NULL,\n    CONSTRAINT [PK_ApiScopes] PRIMARY KEY ([Id])\n);\n\nGO\n\nCREATE TABLE [Clients] (\n    [Id] int NOT NULL IDENTITY,\n    [Enabled] bit NOT NULL,\n    [ClientId] nvarchar(200) NOT NULL,\n    [ProtocolType] nvarchar(200) NOT NULL,\n    [RequireClientSecret] bit NOT NULL,\n    [ClientName] nvarchar(200) NULL,\n    [Description] nvarchar(1000) NULL,\n    [ClientUri] nvarchar(2000) NULL,\n    [LogoUri] nvarchar(2000) NULL,\n    [RequireConsent] bit NOT NULL,\n    [AllowRememberConsent] bit NOT NULL,\n    [AlwaysIncludeUserClaimsInIdToken] bit NOT NULL,\n    [RequirePkce] bit NOT NULL,\n    [AllowPlainTextPkce] bit NOT NULL,\n    [RequireRequestObject] bit NOT NULL,\n    [AllowAccessTokensViaBrowser] bit NOT NULL,\n    [FrontChannelLogoutUri] nvarchar(2000) NULL,\n    [FrontChannelLogoutSessionRequired] bit NOT NULL,\n    [BackChannelLogoutUri] nvarchar(2000) NULL,\n    [BackChannelLogoutSessionRequired] bit NOT NULL,\n    [AllowOfflineAccess] bit NOT NULL,\n    [IdentityTokenLifetime] int NOT NULL,\n    [AllowedIdentityTokenSigningAlgorithms] nvarchar(100) NULL,\n    [AccessTokenLifetime] int NOT NULL,\n    [AuthorizationCodeLifetime] int NOT NULL,\n    [ConsentLifetime] int NULL,\n    [AbsoluteRefreshTokenLifetime] int NOT NULL,\n    [SlidingRefreshTokenLifetime] int NOT NULL,\n    [RefreshTokenUsage] int NOT NULL,\n    [UpdateAccessTokenClaimsOnRefresh] bit NOT NULL,\n    [RefreshTokenExpiration] int NOT NULL,\n    [AccessTokenType] int NOT NULL,\n    [EnableLocalLogin] bit NOT NULL,\n    [IncludeJwtId] bit NOT NULL,\n    [AlwaysSendClientClaims] bit NOT NULL,\n    [ClientClaimsPrefix] nvarchar(200) NULL,\n    [PairWiseSubjectSalt] nvarchar(200) NULL,\n    [Created] datetime2 NOT NULL,\n    [Updated] datetime2 NULL,\n    [LastAccessed] datetime2 NULL,\n    [UserSsoLifetime] int NULL,\n    [UserCodeType] nvarchar(100) NULL,\n    [DeviceCodeLifetime] int NOT NULL,\n    [NonEditable] bit NOT NULL,\n    CONSTRAINT [PK_Clients] PRIMARY KEY ([Id])\n);\n\nGO\n\nCREATE TABLE [IdentityResources] (\n    [Id] int NOT NULL IDENTITY,\n    [Enabled] bit NOT NULL,\n    [Name] nvarchar(200) NOT NULL,\n    [DisplayName] nvarchar(200) NULL,\n    [Description] nvarchar(1000) NULL,\n    [Required] bit NOT NULL,\n    [Emphasize] bit NOT NULL,\n    [ShowInDiscoveryDocument] bit NOT NULL,\n    [Created] datetime2 NOT NULL,\n    [Updated] datetime2 NULL,\n    [NonEditable] bit NOT NULL,\n    CONSTRAINT [PK_IdentityResources] PRIMARY KEY ([Id])\n);\n\nGO\n\nCREATE TABLE [ApiResourceClaims] (\n    [Id] int NOT NULL IDENTITY,\n    [Type] nvarchar(200) NOT NULL,\n    [ApiResourceId] int NOT NULL,\n    CONSTRAINT [PK_ApiResourceClaims] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ApiResourceClaims_ApiResources_ApiResourceId] FOREIGN KEY ([ApiResourceId]) REFERENCES [ApiResources] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ApiResourceProperties] (\n    [Id] int NOT NULL IDENTITY,\n    [Key] nvarchar(250) NOT NULL,\n    [Value] nvarchar(2000) NOT NULL,\n    [ApiResourceId] int NOT NULL,\n    CONSTRAINT [PK_ApiResourceProperties] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ApiResourceProperties_ApiResources_ApiResourceId] FOREIGN KEY ([ApiResourceId]) REFERENCES [ApiResources] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ApiResourceScopes] (\n    [Id] int NOT NULL IDENTITY,\n    [Scope] nvarchar(200) NOT NULL,\n    [ApiResourceId] int NOT NULL,\n    CONSTRAINT [PK_ApiResourceScopes] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ApiResourceScopes_ApiResources_ApiResourceId] FOREIGN KEY ([ApiResourceId]) REFERENCES [ApiResources] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ApiResourceSecrets] (\n    [Id] int NOT NULL IDENTITY,\n    [Description] nvarchar(1000) NULL,\n    [Value] nvarchar(4000) NOT NULL,\n    [Expiration] datetime2 NULL,\n    [Type] nvarchar(250) NOT NULL,\n    [Created] datetime2 NOT NULL,\n    [ApiResourceId] int NOT NULL,\n    CONSTRAINT [PK_ApiResourceSecrets] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ApiResourceSecrets_ApiResources_ApiResourceId] FOREIGN KEY ([ApiResourceId]) REFERENCES [ApiResources] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ApiScopeClaims] (\n    [Id] int NOT NULL IDENTITY,\n    [Type] nvarchar(200) NOT NULL,\n    [ScopeId] int NOT NULL,\n    CONSTRAINT [PK_ApiScopeClaims] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ApiScopeClaims_ApiScopes_ScopeId] FOREIGN KEY ([ScopeId]) REFERENCES [ApiScopes] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ApiScopeProperties] (\n    [Id] int NOT NULL IDENTITY,\n    [Key] nvarchar(250) NOT NULL,\n    [Value] nvarchar(2000) NOT NULL,\n    [ScopeId] int NOT NULL,\n    CONSTRAINT [PK_ApiScopeProperties] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ApiScopeProperties_ApiScopes_ScopeId] FOREIGN KEY ([ScopeId]) REFERENCES [ApiScopes] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ClientClaims] (\n    [Id] int NOT NULL IDENTITY,\n    [Type] nvarchar(250) NOT NULL,\n    [Value] nvarchar(250) NOT NULL,\n    [ClientId] int NOT NULL,\n    CONSTRAINT [PK_ClientClaims] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ClientClaims_Clients_ClientId] FOREIGN KEY ([ClientId]) REFERENCES [Clients] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ClientCorsOrigins] (\n    [Id] int NOT NULL IDENTITY,\n    [Origin] nvarchar(150) NOT NULL,\n    [ClientId] int NOT NULL,\n    CONSTRAINT [PK_ClientCorsOrigins] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ClientCorsOrigins_Clients_ClientId] FOREIGN KEY ([ClientId]) REFERENCES [Clients] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ClientGrantTypes] (\n    [Id] int NOT NULL IDENTITY,\n    [GrantType] nvarchar(250) NOT NULL,\n    [ClientId] int NOT NULL,\n    CONSTRAINT [PK_ClientGrantTypes] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ClientGrantTypes_Clients_ClientId] FOREIGN KEY ([ClientId]) REFERENCES [Clients] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ClientIdPRestrictions] (\n    [Id] int NOT NULL IDENTITY,\n    [Provider] nvarchar(200) NOT NULL,\n    [ClientId] int NOT NULL,\n    CONSTRAINT [PK_ClientIdPRestrictions] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ClientIdPRestrictions_Clients_ClientId] FOREIGN KEY ([ClientId]) REFERENCES [Clients] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ClientPostLogoutRedirectUris] (\n    [Id] int NOT NULL IDENTITY,\n    [PostLogoutRedirectUri] nvarchar(2000) NOT NULL,\n    [ClientId] int NOT NULL,\n    CONSTRAINT [PK_ClientPostLogoutRedirectUris] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ClientPostLogoutRedirectUris_Clients_ClientId] FOREIGN KEY ([ClientId]) REFERENCES [Clients] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ClientProperties] (\n    [Id] int NOT NULL IDENTITY,\n    [Key] nvarchar(250) NOT NULL,\n    [Value] nvarchar(2000) NOT NULL,\n    [ClientId] int NOT NULL,\n    CONSTRAINT [PK_ClientProperties] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ClientProperties_Clients_ClientId] FOREIGN KEY ([ClientId]) REFERENCES [Clients] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ClientRedirectUris] (\n    [Id] int NOT NULL IDENTITY,\n    [RedirectUri] nvarchar(2000) NOT NULL,\n    [ClientId] int NOT NULL,\n    CONSTRAINT [PK_ClientRedirectUris] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ClientRedirectUris_Clients_ClientId] FOREIGN KEY ([ClientId]) REFERENCES [Clients] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ClientScopes] (\n    [Id] int NOT NULL IDENTITY,\n    [Scope] nvarchar(200) NOT NULL,\n    [ClientId] int NOT NULL,\n    CONSTRAINT [PK_ClientScopes] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ClientScopes_Clients_ClientId] FOREIGN KEY ([ClientId]) REFERENCES [Clients] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [ClientSecrets] (\n    [Id] int NOT NULL IDENTITY,\n    [Description] nvarchar(2000) NULL,\n    [Value] nvarchar(4000) NOT NULL,\n    [Expiration] datetime2 NULL,\n    [Type] nvarchar(250) NOT NULL,\n    [Created] datetime2 NOT NULL,\n    [ClientId] int NOT NULL,\n    CONSTRAINT [PK_ClientSecrets] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_ClientSecrets_Clients_ClientId] FOREIGN KEY ([ClientId]) REFERENCES [Clients] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [IdentityResourceClaims] (\n    [Id] int NOT NULL IDENTITY,\n    [Type] nvarchar(200) NOT NULL,\n    [IdentityResourceId] int NOT NULL,\n    CONSTRAINT [PK_IdentityResourceClaims] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_IdentityResourceClaims_IdentityResources_IdentityResourceId] FOREIGN KEY ([IdentityResourceId]) REFERENCES [IdentityResources] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE TABLE [IdentityResourceProperties] (\n    [Id] int NOT NULL IDENTITY,\n    [Key] nvarchar(250) NOT NULL,\n    [Value] nvarchar(2000) NOT NULL,\n    [IdentityResourceId] int NOT NULL,\n    CONSTRAINT [PK_IdentityResourceProperties] PRIMARY KEY ([Id]),\n    CONSTRAINT [FK_IdentityResourceProperties_IdentityResources_IdentityResourceId] FOREIGN KEY ([IdentityResourceId]) REFERENCES [IdentityResources] ([Id]) ON DELETE CASCADE\n);\n\nGO\n\nCREATE INDEX [IX_ApiResourceClaims_ApiResourceId] ON [ApiResourceClaims] ([ApiResourceId]);\n\nGO\n\nCREATE INDEX [IX_ApiResourceProperties_ApiResourceId] ON [ApiResourceProperties] ([ApiResourceId]);\n\nGO\n\nCREATE UNIQUE INDEX [IX_ApiResources_Name] ON [ApiResources] ([Name]);\n\nGO\n\nCREATE INDEX [IX_ApiResourceScopes_ApiResourceId] ON [ApiResourceScopes] ([ApiResourceId]);\n\nGO\n\nCREATE INDEX [IX_ApiResourceSecrets_ApiResourceId] ON [ApiResourceSecrets] ([ApiResourceId]);\n\nGO\n\nCREATE INDEX [IX_ApiScopeClaims_ScopeId] ON [ApiScopeClaims] ([ScopeId]);\n\nGO\n\nCREATE INDEX [IX_ApiScopeProperties_ScopeId] ON [ApiScopeProperties] ([ScopeId]);\n\nGO\n\nCREATE UNIQUE INDEX [IX_ApiScopes_Name] ON [ApiScopes] ([Name]);\n\nGO\n\nCREATE INDEX [IX_ClientClaims_ClientId] ON [ClientClaims] ([ClientId]);\n\nGO\n\nCREATE INDEX [IX_ClientCorsOrigins_ClientId] ON [ClientCorsOrigins] ([ClientId]);\n\nGO\n\nCREATE INDEX [IX_ClientGrantTypes_ClientId] ON [ClientGrantTypes] ([ClientId]);\n\nGO\n\nCREATE INDEX [IX_ClientIdPRestrictions_ClientId] ON [ClientIdPRestrictions] ([ClientId]);\n\nGO\n\nCREATE INDEX [IX_ClientPostLogoutRedirectUris_ClientId] ON [ClientPostLogoutRedirectUris] ([ClientId]);\n\nGO\n\nCREATE INDEX [IX_ClientProperties_ClientId] ON [ClientProperties] ([ClientId]);\n\nGO\n\nCREATE INDEX [IX_ClientRedirectUris_ClientId] ON [ClientRedirectUris] ([ClientId]);\n\nGO\n\nCREATE UNIQUE INDEX [IX_Clients_ClientId] ON [Clients] ([ClientId]);\n\nGO\n\nCREATE INDEX [IX_ClientScopes_ClientId] ON [ClientScopes] ([ClientId]);\n\nGO\n\nCREATE INDEX [IX_ClientSecrets_ClientId] ON [ClientSecrets] ([ClientId]);\n\nGO\n\nCREATE INDEX [IX_IdentityResourceClaims_IdentityResourceId] ON [IdentityResourceClaims] ([IdentityResourceId]);\n\nGO\n\nCREATE INDEX [IX_IdentityResourceProperties_IdentityResourceId] ON [IdentityResourceProperties] ([IdentityResourceId]);\n\nGO\n\nCREATE UNIQUE INDEX [IX_IdentityResources_Name] ON [IdentityResources] ([Name]);\n\nGO\n\nINSERT INTO [__EFMigrationsHistory] ([MigrationId], [ProductVersion])\nVALUES (N'20200522172542_Config', N'3.1.0');\n\nGO\n\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Migrations/PersistedGrantDb/20200522172538_Grants.Designer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\n\nnamespace SqlServer.Migrations.PersistedGrantDb\n{\n    [DbContext(typeof(PersistedGrantDbContext))]\n    [Migration(\"20200522172538_Grants\")]\n    partial class Grants\n    {\n        protected override void BuildTargetModel(ModelBuilder modelBuilder)\n        {\n#pragma warning disable 612, 618\n            modelBuilder\n                .HasAnnotation(\"ProductVersion\", \"3.1.0\")\n                .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n                .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.DeviceFlowCodes\", b =>\n                {\n                    b.Property<string>(\"UserCode\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime>(\"CreationTime\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Data\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(max)\")\n                        .HasMaxLength(50000);\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"DeviceCode\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .IsRequired()\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"SessionId\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<string>(\"SubjectId\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.HasKey(\"UserCode\");\n\n                    b.HasIndex(\"DeviceCode\")\n                        .IsUnique();\n\n                    b.HasIndex(\"Expiration\");\n\n                    b.ToTable(\"DeviceCodes\");\n                });\n\n            modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.PersistedGrant\", b =>\n                {\n                    b.Property<string>(\"Key\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"ClientId\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime?>(\"ConsumedTime\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<DateTime>(\"CreationTime\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"Data\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(max)\")\n                        .HasMaxLength(50000);\n\n                    b.Property<string>(\"Description\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<DateTime?>(\"Expiration\")\n                        .HasColumnType(\"datetime2\");\n\n                    b.Property<string>(\"SessionId\")\n                        .HasColumnType(\"nvarchar(100)\")\n                        .HasMaxLength(100);\n\n                    b.Property<string>(\"SubjectId\")\n                        .HasColumnType(\"nvarchar(200)\")\n                        .HasMaxLength(200);\n\n                    b.Property<string>(\"Type\")\n                        .IsRequired()\n                        .HasColumnType(\"nvarchar(50)\")\n                        .HasMaxLength(50);\n\n                    b.HasKey(\"Key\");\n\n                    b.HasIndex(\"Expiration\");\n\n                    b.HasIndex(\"SubjectId\", \"ClientId\", \"Type\");\n\n                    b.HasIndex(\"SubjectId\", \"SessionId\", \"Type\");\n\n                    b.ToTable(\"PersistedGrants\");\n                });\n#pragma warning restore 612, 618\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Migrations/PersistedGrantDb/20200522172538_Grants.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace SqlServer.Migrations.PersistedGrantDb;\n\npublic partial class Grants : Migration\n{\n    protected override void Up(MigrationBuilder migrationBuilder)\n    {\n        migrationBuilder.CreateTable(\n            name: \"DeviceCodes\",\n            columns: table => new\n            {\n                UserCode = table.Column<string>(maxLength: 200, nullable: false),\n                DeviceCode = table.Column<string>(maxLength: 200, nullable: false),\n                SubjectId = table.Column<string>(maxLength: 200, nullable: true),\n                SessionId = table.Column<string>(maxLength: 100, nullable: true),\n                ClientId = table.Column<string>(maxLength: 200, nullable: false),\n                Description = table.Column<string>(maxLength: 200, nullable: true),\n                CreationTime = table.Column<DateTime>(nullable: false),\n                Expiration = table.Column<DateTime>(nullable: false),\n                Data = table.Column<string>(maxLength: 50000, nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_DeviceCodes\", x => x.UserCode);\n            });\n\n        migrationBuilder.CreateTable(\n            name: \"PersistedGrants\",\n            columns: table => new\n            {\n                Key = table.Column<string>(maxLength: 200, nullable: false),\n                Type = table.Column<string>(maxLength: 50, nullable: false),\n                SubjectId = table.Column<string>(maxLength: 200, nullable: true),\n                SessionId = table.Column<string>(maxLength: 100, nullable: true),\n                ClientId = table.Column<string>(maxLength: 200, nullable: false),\n                Description = table.Column<string>(maxLength: 200, nullable: true),\n                CreationTime = table.Column<DateTime>(nullable: false),\n                Expiration = table.Column<DateTime>(nullable: true),\n                ConsumedTime = table.Column<DateTime>(nullable: true),\n                Data = table.Column<string>(maxLength: 50000, nullable: false)\n            },\n            constraints: table =>\n            {\n                table.PrimaryKey(\"PK_PersistedGrants\", x => x.Key);\n            });\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_DeviceCodes_DeviceCode\",\n            table: \"DeviceCodes\",\n            column: \"DeviceCode\",\n            unique: true);\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_DeviceCodes_Expiration\",\n            table: \"DeviceCodes\",\n            column: \"Expiration\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_PersistedGrants_Expiration\",\n            table: \"PersistedGrants\",\n            column: \"Expiration\");\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_PersistedGrants_SubjectId_ClientId_Type\",\n            table: \"PersistedGrants\",\n            columns: new[] { \"SubjectId\", \"ClientId\", \"Type\" });\n\n        migrationBuilder.CreateIndex(\n            name: \"IX_PersistedGrants_SubjectId_SessionId_Type\",\n            table: \"PersistedGrants\",\n            columns: new[] { \"SubjectId\", \"SessionId\", \"Type\" });\n    }\n\n    protected override void Down(MigrationBuilder migrationBuilder)\n    {\n        migrationBuilder.DropTable(\n            name: \"DeviceCodes\");\n\n        migrationBuilder.DropTable(\n            name: \"PersistedGrants\");\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Migrations/PersistedGrantDb/PersistedGrantDbContextModelSnapshot.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n// <auto-generated />\n\nnamespace SqlServer.Migrations.PersistedGrantDb;\n\n[DbContext(typeof(PersistedGrantDbContext))]\npartial class PersistedGrantDbContextModelSnapshot : ModelSnapshot\n{\n    protected override void BuildModel(ModelBuilder modelBuilder)\n    {\n#pragma warning disable 612, 618\n        modelBuilder\n            .HasAnnotation(\"ProductVersion\", \"3.1.0\")\n            .HasAnnotation(\"Relational:MaxIdentifierLength\", 128)\n            .HasAnnotation(\"SqlServer:ValueGenerationStrategy\", SqlServerValueGenerationStrategy.IdentityColumn);\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.DeviceFlowCodes\", b =>\n            {\n                b.Property<string>(\"UserCode\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"ClientId\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<DateTime>(\"CreationTime\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Data\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(max)\")\n                    .HasMaxLength(50000);\n\n                b.Property<string>(\"Description\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"DeviceCode\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<DateTime?>(\"Expiration\")\n                    .IsRequired()\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"SessionId\")\n                    .HasColumnType(\"nvarchar(100)\")\n                    .HasMaxLength(100);\n\n                b.Property<string>(\"SubjectId\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.HasKey(\"UserCode\");\n\n                b.HasIndex(\"DeviceCode\")\n                    .IsUnique();\n\n                b.HasIndex(\"Expiration\");\n\n                b.ToTable(\"DeviceCodes\");\n            });\n\n        modelBuilder.Entity(\"IdentityServer8.EntityFramework.Entities.PersistedGrant\", b =>\n            {\n                b.Property<string>(\"Key\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"ClientId\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<DateTime?>(\"ConsumedTime\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<DateTime>(\"CreationTime\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"Data\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(max)\")\n                    .HasMaxLength(50000);\n\n                b.Property<string>(\"Description\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<DateTime?>(\"Expiration\")\n                    .HasColumnType(\"datetime2\");\n\n                b.Property<string>(\"SessionId\")\n                    .HasColumnType(\"nvarchar(100)\")\n                    .HasMaxLength(100);\n\n                b.Property<string>(\"SubjectId\")\n                    .HasColumnType(\"nvarchar(200)\")\n                    .HasMaxLength(200);\n\n                b.Property<string>(\"Type\")\n                    .IsRequired()\n                    .HasColumnType(\"nvarchar(50)\")\n                    .HasMaxLength(50);\n\n                b.HasKey(\"Key\");\n\n                b.HasIndex(\"Expiration\");\n\n                b.HasIndex(\"SubjectId\", \"ClientId\", \"Type\");\n\n                b.HasIndex(\"SubjectId\", \"SessionId\", \"Type\");\n\n                b.ToTable(\"PersistedGrants\");\n            });\n#pragma warning restore 612, 618\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Migrations/PersistedGrantDb.sql",
    "content": "﻿IF OBJECT_ID(N'[__EFMigrationsHistory]') IS NULL\nBEGIN\n    CREATE TABLE [__EFMigrationsHistory] (\n        [MigrationId] nvarchar(150) NOT NULL,\n        [ProductVersion] nvarchar(32) NOT NULL,\n        CONSTRAINT [PK___EFMigrationsHistory] PRIMARY KEY ([MigrationId])\n    );\nEND;\n\nGO\n\nCREATE TABLE [DeviceCodes] (\n    [UserCode] nvarchar(200) NOT NULL,\n    [DeviceCode] nvarchar(200) NOT NULL,\n    [SubjectId] nvarchar(200) NULL,\n    [SessionId] nvarchar(100) NULL,\n    [ClientId] nvarchar(200) NOT NULL,\n    [Description] nvarchar(200) NULL,\n    [CreationTime] datetime2 NOT NULL,\n    [Expiration] datetime2 NOT NULL,\n    [Data] nvarchar(max) NOT NULL,\n    CONSTRAINT [PK_DeviceCodes] PRIMARY KEY ([UserCode])\n);\n\nGO\n\nCREATE TABLE [PersistedGrants] (\n    [Key] nvarchar(200) NOT NULL,\n    [Type] nvarchar(50) NOT NULL,\n    [SubjectId] nvarchar(200) NULL,\n    [SessionId] nvarchar(100) NULL,\n    [ClientId] nvarchar(200) NOT NULL,\n    [Description] nvarchar(200) NULL,\n    [CreationTime] datetime2 NOT NULL,\n    [Expiration] datetime2 NULL,\n    [ConsumedTime] datetime2 NULL,\n    [Data] nvarchar(max) NOT NULL,\n    CONSTRAINT [PK_PersistedGrants] PRIMARY KEY ([Key])\n);\n\nGO\n\nCREATE UNIQUE INDEX [IX_DeviceCodes_DeviceCode] ON [DeviceCodes] ([DeviceCode]);\n\nGO\n\nCREATE INDEX [IX_DeviceCodes_Expiration] ON [DeviceCodes] ([Expiration]);\n\nGO\n\nCREATE INDEX [IX_PersistedGrants_Expiration] ON [PersistedGrants] ([Expiration]);\n\nGO\n\nCREATE INDEX [IX_PersistedGrants_SubjectId_ClientId_Type] ON [PersistedGrants] ([SubjectId], [ClientId], [Type]);\n\nGO\n\nCREATE INDEX [IX_PersistedGrants_SubjectId_SessionId_Type] ON [PersistedGrants] ([SubjectId], [SessionId], [Type]);\n\nGO\n\nINSERT INTO [__EFMigrationsHistory] ([MigrationId], [ProductVersion])\nVALUES (N'20200522172538_Grants', N'3.1.0');\n\nGO\n\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace SqlServer;\n\nclass Program\n{\n    public static void Main(string[] args)\n    {\n    }\n\n    public static IWebHost BuildWebHost(string[] args) =>\n        WebHost.CreateDefaultBuilder(args)\n            .UseStartup<Startup>()\n            .Build();\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Properties/launchSettings.json",
    "content": "{\n  \"iisSettings\": {\n    \"windowsAuthentication\": false,\n    \"anonymousAuthentication\": true,\n    \"iisExpress\": {\n      \"applicationUrl\": \"http://localhost:7603/\",\n      \"sslPort\": 0\n    }\n  },\n  \"profiles\": {\n    \"IIS Express\": {\n      \"commandName\": \"IISExpress\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      }\n    },\n    \"SqlServer\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"http://localhost:7604/\"\n    }\n  }\n}"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/SqlServer.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.Design\" PrivateAssets=\"All\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.SqlServer\" />\n    <ProjectReference Include=\"..\\..\\src\\IdentityServer8.EntityFramework.Storage.csproj\" />\n  </ItemGroup>\n  \n</Project>"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace SqlServer;\n\npublic class Startup\n{\n    public IConfiguration Configuration { get; }\n\n    public Startup(IConfiguration config)\n    {\n        Configuration = config;\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        var cn = Configuration.GetConnectionString(\"db\");\n\n        services.AddOperationalDbContext(options => {\n            options.ConfigureDbContext = b =>\n                b.UseSqlServer(cn, dbOpts => dbOpts.MigrationsAssembly(typeof(Startup).Assembly.FullName));\n        });\n\n        services.AddConfigurationDbContext(options => {\n            options.ConfigureDbContext = b =>\n                b.UseSqlServer(cn, dbOpts => dbOpts.MigrationsAssembly(typeof(Startup).Assembly.FullName));\n        });\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/appsettings.json",
    "content": "{\n  \"ConnectionStrings\": {\n    \"db\": \"server=(localdb)\\\\mssqllocaldb;database=IdentityServer8.EntityFramework-8.0.0;trusted_connection=yes;\",\n    //\"db\": \"Data Source=IdentityServer.db;\"\n  }\n}"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/buildschema.bat",
    "content": "rmdir /S /Q Migrations\n\ndotnet ef migrations add Grants -c PersistedGrantDbContext -o Migrations/PersistedGrantDb\ndotnet ef migrations add Configuration -c ConfigurationDbContext -o Migrations/ConfigurationDb\n\ndotnet ef migrations script -c PersistedGrantDbContext -o Migrations/PersistedGrantDb.sql\ndotnet ef migrations script -c ConfigurationDbContext -o Migrations/ConfigurationDb.sql\n"
  },
  {
    "path": "src/EntityFramework.Storage/migrations/SqlServer/createdb.bat",
    "content": "dotnet ef database update -c PersistedGrantDbContext\ndotnet ef database update -c ConfigurationDbContext \n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Configuration/ServiceCollectionExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Storage\n{\n    /// <summary>\n    /// Extension methods to add EF database support to IdentityServer.\n    /// </summary>\n    public static class IdentityServerEntityFrameworkBuilderExtensions\n    {\n        /// <summary>\n        /// Add Configuration DbContext to the DI system.\n        /// </summary>\n        /// <param name=\"services\"></param>\n        /// <param name=\"storeOptionsAction\">The store options action.</param>\n        /// <returns></returns>\n        public static IServiceCollection AddConfigurationDbContext(this IServiceCollection services,\n            Action<ConfigurationStoreOptions> storeOptionsAction = null)\n        {\n            return services.AddConfigurationDbContext<ConfigurationDbContext>(storeOptionsAction);\n        }\n\n        /// <summary>\n        /// Add Configuration DbContext to the DI system.\n        /// </summary>\n        /// <typeparam name=\"TContext\">The IConfigurationDbContext to use.</typeparam>\n        /// <param name=\"services\"></param>\n        /// <param name=\"storeOptionsAction\">The store options action.</param>\n        /// <returns></returns>\n        public static IServiceCollection AddConfigurationDbContext<TContext>(this IServiceCollection services,\n        Action<ConfigurationStoreOptions> storeOptionsAction = null)\n        where TContext : DbContext, IConfigurationDbContext\n        {\n            var options = new ConfigurationStoreOptions();\n            services.AddSingleton(options);\n            storeOptionsAction?.Invoke(options);\n\n            if (options.ResolveDbContextOptions != null)\n            {\n                services.AddDbContext<TContext>(options.ResolveDbContextOptions);\n            }\n            else\n            {\n                services.AddDbContext<TContext>(dbCtxBuilder =>\n                {\n                    options.ConfigureDbContext?.Invoke(dbCtxBuilder);\n                });\n            }\n            services.AddScoped<IConfigurationDbContext, TContext>();\n\n            return services;\n        }\n\n        /// <summary>\n        /// Adds operational DbContext to the DI system.\n        /// </summary>\n        /// <param name=\"services\"></param>\n        /// <param name=\"storeOptionsAction\">The store options action.</param>\n        /// <returns></returns>\n        public static IServiceCollection AddOperationalDbContext(this IServiceCollection services,\n            Action<OperationalStoreOptions> storeOptionsAction = null)\n        {\n            return services.AddOperationalDbContext<PersistedGrantDbContext>(storeOptionsAction);\n        }\n\n        /// <summary>\n        /// Adds operational DbContext to the DI system.\n        /// </summary>\n        /// <typeparam name=\"TContext\">The IPersistedGrantDbContext to use.</typeparam>\n        /// <param name=\"services\"></param>\n        /// <param name=\"storeOptionsAction\">The store options action.</param>\n        /// <returns></returns>\n        public static IServiceCollection AddOperationalDbContext<TContext>(this IServiceCollection services,\n            Action<OperationalStoreOptions> storeOptionsAction = null)\n            where TContext : DbContext, IPersistedGrantDbContext\n        {\n            var storeOptions = new OperationalStoreOptions();\n            services.AddSingleton(storeOptions);\n            storeOptionsAction?.Invoke(storeOptions);\n\n            if (storeOptions.ResolveDbContextOptions != null)\n            {\n                services.AddDbContext<TContext>(storeOptions.ResolveDbContextOptions);\n            }\n            else\n            {\n                services.AddDbContext<TContext>(dbCtxBuilder =>\n                {\n                    storeOptions.ConfigureDbContext?.Invoke(dbCtxBuilder);\n                });\n            }\n\n            services.AddScoped<IPersistedGrantDbContext, TContext>();\n            services.AddTransient<TokenCleanupService>();\n\n            return services;\n        }\n\n        /// <summary>\n        /// Adds an implementation of the IOperationalStoreNotification to the DI system.\n        /// </summary>\n        /// <typeparam name=\"T\"></typeparam>\n        /// <param name=\"services\"></param>\n        /// <returns></returns>\n        public static IServiceCollection AddOperationalStoreNotification<T>(this IServiceCollection services)\n           where T : class, IOperationalStoreNotification\n        {\n            services.AddTransient<IOperationalStoreNotification, T>();\n            return services;\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/DbContexts/ConfigurationDbContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Entities;\n\nnamespace IdentityServer8.EntityFramework.DbContexts\n{\n    /// <summary>\n    /// DbContext for the IdentityServer configuration data.\n    /// </summary>\n    /// <seealso cref=\"Microsoft.EntityFrameworkCore.DbContext\" />\n    /// <seealso cref=\"IdentityServer8.EntityFramework.Interfaces.IConfigurationDbContext\" />\n    public class ConfigurationDbContext : ConfigurationDbContext<ConfigurationDbContext>\n    {\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"ConfigurationDbContext\"/> class.\n        /// </summary>\n        /// <param name=\"options\">The options.</param>\n        /// <param name=\"storeOptions\">The store options.</param>\n        /// <exception cref=\"ArgumentNullException\">storeOptions</exception>\n        public ConfigurationDbContext(DbContextOptions<ConfigurationDbContext> options, ConfigurationStoreOptions storeOptions)\n            : base(options, storeOptions)\n        {\n        }\n    }\n\n    /// <summary>\n    /// DbContext for the IdentityServer configuration data.\n    /// </summary>\n    /// <seealso cref=\"Microsoft.EntityFrameworkCore.DbContext\" />\n    /// <seealso cref=\"IdentityServer8.EntityFramework.Interfaces.IConfigurationDbContext\" />\n    public class ConfigurationDbContext<TContext> : DbContext, IConfigurationDbContext\n        where TContext : DbContext, IConfigurationDbContext\n    {\n        private readonly ConfigurationStoreOptions storeOptions;\n\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"ConfigurationDbContext\"/> class.\n        /// </summary>\n        /// <param name=\"options\">The options.</param>\n        /// <param name=\"storeOptions\">The store options.</param>\n        /// <exception cref=\"ArgumentNullException\">storeOptions</exception>\n        public ConfigurationDbContext(DbContextOptions<TContext> options, ConfigurationStoreOptions storeOptions)\n            : base(options)\n        {\n            this.storeOptions = storeOptions ?? throw new ArgumentNullException(nameof(storeOptions));\n        }\n\n        /// <summary>\n        /// Gets or sets the clients.\n        /// </summary>\n        /// <value>\n        /// The clients.\n        /// </value>\n        public DbSet<Client> Clients { get; set; }\n\n        /// <summary>\n        /// Gets or sets the clients' CORS origins.\n        /// </summary>\n        /// <value>\n        /// The clients CORS origins.\n        /// </value>\n        public DbSet<ClientCorsOrigin> ClientCorsOrigins { get; set; }\n\n        /// <summary>\n        /// Gets or sets the identity resources.\n        /// </summary>\n        /// <value>\n        /// The identity resources.\n        /// </value>\n        public DbSet<IdentityResource> IdentityResources { get; set; }\n\n        /// <summary>\n        /// Gets or sets the API resources.\n        /// </summary>\n        /// <value>\n        /// The API resources.\n        /// </value>\n        public DbSet<ApiResource> ApiResources { get; set; }\n\n        /// <summary>\n        /// Gets or sets the API scopes.\n        /// </summary>\n        /// <value>\n        /// The API resources.\n        /// </value>\n        public DbSet<ApiScope> ApiScopes { get; set; }\n\n        /// <summary>\n        /// Override this method to further configure the model that was discovered by convention from the entity types\n        /// exposed in <see cref=\"T:Microsoft.EntityFrameworkCore.DbSet`1\" /> properties on your derived context. The resulting model may be cached\n        /// and re-used for subsequent instances of your derived context.\n        /// </summary>\n        /// <param name=\"modelBuilder\">The builder being used to construct the model for this context. Databases (and other extensions) typically\n        /// define extension methods on this object that allow you to configure aspects of the model that are specific\n        /// to a given database.</param>\n        /// <remarks>\n        /// If a model is explicitly set on the options for this context (via <see cref=\"M:Microsoft.EntityFrameworkCore.DbContextOptionsBuilder.UseModel(Microsoft.EntityFrameworkCore.Metadata.IModel)\" />)\n        /// then this method will not be run.\n        /// </remarks>\n        protected override void OnModelCreating(ModelBuilder modelBuilder)\n        {\n            modelBuilder.ConfigureClientContext(storeOptions);\n            modelBuilder.ConfigureResourcesContext(storeOptions);\n\n            base.OnModelCreating(modelBuilder);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/DbContexts/PersistedGrantDbContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Entities;\n\nnamespace IdentityServer8.EntityFramework.DbContexts\n{\n    /// <summary>\n    /// DbContext for the IdentityServer operational data.\n    /// </summary>\n    /// <seealso cref=\"Microsoft.EntityFrameworkCore.DbContext\" />\n    /// <seealso cref=\"IdentityServer8.EntityFramework.Interfaces.IPersistedGrantDbContext\" />\n    public class PersistedGrantDbContext : PersistedGrantDbContext<PersistedGrantDbContext>\n    {\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"PersistedGrantDbContext\"/> class.\n        /// </summary>\n        /// <param name=\"options\">The options.</param>\n        /// <param name=\"storeOptions\">The store options.</param>\n        /// <exception cref=\"ArgumentNullException\">storeOptions</exception>\n        public PersistedGrantDbContext(DbContextOptions<PersistedGrantDbContext> options, OperationalStoreOptions storeOptions)\n            : base(options, storeOptions)\n        {\n        }\n    }\n\n    /// <summary>\n    /// DbContext for the IdentityServer operational data.\n    /// </summary>\n    /// <seealso cref=\"Microsoft.EntityFrameworkCore.DbContext\" />\n    /// <seealso cref=\"IdentityServer8.EntityFramework.Interfaces.IPersistedGrantDbContext\" />\n    public class PersistedGrantDbContext<TContext> : DbContext, IPersistedGrantDbContext\n        where TContext : DbContext, IPersistedGrantDbContext\n    {\n        private readonly OperationalStoreOptions storeOptions;\n\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"PersistedGrantDbContext\"/> class.\n        /// </summary>\n        /// <param name=\"options\">The options.</param>\n        /// <param name=\"storeOptions\">The store options.</param>\n        /// <exception cref=\"ArgumentNullException\">storeOptions</exception>\n        public PersistedGrantDbContext(DbContextOptions options, OperationalStoreOptions storeOptions)\n            : base(options)\n        {\n            if (storeOptions == null) throw new ArgumentNullException(nameof(storeOptions));\n            this.storeOptions = storeOptions;\n        }\n\n        /// <summary>\n        /// Gets or sets the persisted grants.\n        /// </summary>\n        /// <value>\n        /// The persisted grants.\n        /// </value>\n        public DbSet<PersistedGrant> PersistedGrants { get; set; }\n\n        /// <summary>\n        /// Gets or sets the device codes.\n        /// </summary>\n        /// <value>\n        /// The device codes.\n        /// </value>\n        public DbSet<DeviceFlowCodes> DeviceFlowCodes { get; set; }\n\n        /// <summary>\n        /// Saves the changes.\n        /// </summary>\n        /// <returns></returns>\n        public virtual Task<int> SaveChangesAsync()\n        {\n            return base.SaveChangesAsync();\n        }\n\n        /// <summary>\n        /// Override this method to further configure the model that was discovered by convention from the entity types\n        /// exposed in <see cref=\"T:Microsoft.EntityFrameworkCore.DbSet`1\" /> properties on your derived context. The resulting model may be cached\n        /// and re-used for subsequent instances of your derived context.\n        /// </summary>\n        /// <param name=\"modelBuilder\">The builder being used to construct the model for this context. Databases (and other extensions) typically\n        /// define extension methods on this object that allow you to configure aspects of the model that are specific\n        /// to a given database.</param>\n        /// <remarks>\n        /// If a model is explicitly set on the options for this context (via <see cref=\"M:Microsoft.EntityFrameworkCore.DbContextOptionsBuilder.UseModel(Microsoft.EntityFrameworkCore.Metadata.IModel)\" />)\n        /// then this method will not be run.\n        /// </remarks>\n        protected override void OnModelCreating(ModelBuilder modelBuilder)\n        {\n            modelBuilder.ConfigurePersistedGrantContext(storeOptions);\n\n            base.OnModelCreating(modelBuilder);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ApiResource.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ApiResource\n    {\n        public int Id { get; set; }\n        public bool Enabled { get; set; } = true;\n        public string Name { get; set; }\n        public string DisplayName { get; set; }\n        public string Description { get; set; }\n        public string AllowedAccessTokenSigningAlgorithms { get; set; }\n        public bool ShowInDiscoveryDocument { get; set; } = true;\n        public List<ApiResourceSecret> Secrets { get; set; }\n        public List<ApiResourceScope> Scopes { get; set; }\n        public List<ApiResourceClaim> UserClaims { get; set; }\n        public List<ApiResourceProperty> Properties { get; set; }\n        public DateTime Created { get; set; } = DateTime.UtcNow;\n        public DateTime? Updated { get; set; }\n        public DateTime? LastAccessed { get; set; }\n        public bool NonEditable { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ApiResourceClaim.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ApiResourceClaim : UserClaim\n    {\n        public int ApiResourceId { get; set; }\n        public ApiResource ApiResource { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ApiResourceProperty.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ApiResourceProperty : Property\n    {\n        public int ApiResourceId { get; set; }\n        public ApiResource ApiResource { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ApiResourceScope.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ApiResourceScope\n    {\n        public int Id { get; set; }\n        public string Scope { get; set; }\n\n        public int ApiResourceId { get; set; }\n        public ApiResource ApiResource { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ApiResourceSecret.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ApiResourceSecret : Secret\n    {\n        public int ApiResourceId { get; set; }\n        public ApiResource ApiResource { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ApiScope.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nusing System.Collections.Generic;\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ApiScope\n    {\n        public int Id { get; set; }\n        public bool Enabled { get; set; } = true;\n        public string Name { get; set; }\n        public string DisplayName { get; set; }\n        public string Description { get; set; }\n        public bool Required { get; set; }\n        public bool Emphasize { get; set; }\n        public bool ShowInDiscoveryDocument { get; set; } = true;\n        public List<ApiScopeClaim> UserClaims { get; set; }\n        public List<ApiScopeProperty> Properties { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ApiScopeClaim.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ApiScopeClaim : UserClaim\n    {\n        public int ScopeId { get; set; }\n        public ApiScope Scope { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ApiScopeProperty.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ApiScopeProperty : Property\n    {\n        public int ScopeId { get; set; }\n        public ApiScope Scope { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/Client.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nusing IdentityServer8.Models;\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class Client\n    {\n        public int Id { get; set; }\n        public bool Enabled { get; set; } = true;\n        public string ClientId { get; set; }\n        public string ProtocolType { get; set; } = \"oidc\";\n        public List<ClientSecret> ClientSecrets { get; set; }\n        public bool RequireClientSecret { get; set; } = true;\n        public string ClientName { get; set; }\n        public string Description { get; set; }\n        public string ClientUri { get; set; }\n        public string LogoUri { get; set; }\n        public bool RequireConsent { get; set; } = false;\n        public bool AllowRememberConsent { get; set; } = true;\n        public bool AlwaysIncludeUserClaimsInIdToken { get; set; }\n        public List<ClientGrantType> AllowedGrantTypes { get; set; }\n        public bool RequirePkce { get; set; } = true;\n        public bool AllowPlainTextPkce { get; set; }\n        public bool RequireRequestObject { get; set; }\n        public bool AllowAccessTokensViaBrowser { get; set; }\n        public List<ClientRedirectUri> RedirectUris { get; set; }\n        public List<ClientPostLogoutRedirectUri> PostLogoutRedirectUris { get; set; }\n        public string FrontChannelLogoutUri { get; set; }\n        public bool FrontChannelLogoutSessionRequired { get; set; } = true;\n        public string BackChannelLogoutUri { get; set; }\n        public bool BackChannelLogoutSessionRequired { get; set; } = true;\n        public bool AllowOfflineAccess { get; set; }\n        public List<ClientScope> AllowedScopes { get; set; }\n        public int IdentityTokenLifetime { get; set; } = 300;\n        public string AllowedIdentityTokenSigningAlgorithms { get; set; }\n        public int AccessTokenLifetime { get; set; } = 3600;\n        public int AuthorizationCodeLifetime { get; set; } = 300;\n        public int? ConsentLifetime { get; set; } = null;\n        public int AbsoluteRefreshTokenLifetime { get; set; } = 2592000;\n        public int SlidingRefreshTokenLifetime { get; set; } = 1296000;\n        public int RefreshTokenUsage { get; set; } = (int)TokenUsage.OneTimeOnly;\n        public bool UpdateAccessTokenClaimsOnRefresh { get; set; }\n        public int RefreshTokenExpiration { get; set; } = (int)TokenExpiration.Absolute;\n        public int AccessTokenType { get; set; } = (int)0; // AccessTokenType.Jwt;\n        public bool EnableLocalLogin { get; set; } = true;\n        public List<ClientIdPRestriction> IdentityProviderRestrictions { get; set; }\n        public bool IncludeJwtId { get; set; }\n        public List<ClientClaim> Claims { get; set; }\n        public bool AlwaysSendClientClaims { get; set; }\n        public string ClientClaimsPrefix { get; set; } = \"client_\";\n        public string PairWiseSubjectSalt { get; set; }\n        public List<ClientCorsOrigin> AllowedCorsOrigins { get; set; }\n        public List<ClientProperty> Properties { get; set; }\n        public DateTime Created { get; set; } = DateTime.UtcNow;\n        public DateTime? Updated { get; set; }\n        public DateTime? LastAccessed { get; set; }\n        public int? UserSsoLifetime { get; set; }\n        public string UserCodeType { get; set; }\n        public int DeviceCodeLifetime { get; set; } = 300;\n        public bool NonEditable { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ClientClaim.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ClientClaim\n    {\n        public int Id { get; set; }\n        public string Type { get; set; }\n        public string Value { get; set; }\n\n        public int ClientId { get; set; }\n        public Client Client { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ClientCorsOrigin.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ClientCorsOrigin\n    {\n        public int Id { get; set; }\n        public string Origin { get; set; }\n\n        public int ClientId { get; set; }\n        public Client Client { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ClientGrantType.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ClientGrantType\n    {\n        public int Id { get; set; }\n        public string GrantType { get; set; }\n\n        public int ClientId { get; set; }\n        public Client Client { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ClientIdPRestriction.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ClientIdPRestriction\n    {\n        public int Id { get; set; }\n        public string Provider { get; set; }\n\n        public int ClientId { get; set; }\n        public Client Client { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ClientPostLogoutRedirectUri.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ClientPostLogoutRedirectUri\n    {\n        public int Id { get; set; }\n        public string PostLogoutRedirectUri { get; set; }\n\n        public int ClientId { get; set; }\n        public Client Client { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ClientProperty.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ClientProperty : Property\n    {\n        public int ClientId { get; set; }\n        public Client Client { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ClientRedirectUri.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ClientRedirectUri\n    {\n        public int Id { get; set; }\n        public string RedirectUri { get; set; }\n\n        public int ClientId { get; set; }\n        public Client Client { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ClientScope.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ClientScope\n    {\n        public int Id { get; set; }\n        public string Scope { get; set; }\n\n        public int ClientId { get; set; }\n        public Client Client { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/ClientSecret.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class ClientSecret : Secret\n    {\n        public int ClientId { get; set; }\n        public Client Client { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/DeviceFlowCodes.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    /// <summary>\n    /// Entity for device flow codes\n    /// </summary>\n    public class DeviceFlowCodes\n    {\n        /// <summary>\n        /// Gets or sets the device code.\n        /// </summary>\n        /// <value>\n        /// The device code.\n        /// </value>\n        public string DeviceCode { get; set; }\n\n        /// <summary>\n        /// Gets or sets the user code.\n        /// </summary>\n        /// <value>\n        /// The user code.\n        /// </value>\n        public string UserCode { get; set; }\n\n        /// <summary>\n        /// Gets or sets the subject identifier.\n        /// </summary>\n        /// <value>\n        /// The subject identifier.\n        /// </value>\n        public string SubjectId { get; set; }\n\n        /// <summary>\n        /// Gets or sets the session identifier.\n        /// </summary>\n        /// <value>\n        /// The session identifier.\n        /// </value>\n        public string SessionId { get; set; }\n\n        /// <summary>\n        /// Gets or sets the client identifier.\n        /// </summary>\n        /// <value>\n        /// The client identifier.\n        /// </value>\n        public string ClientId { get; set; }\n\n        /// <summary>\n        /// Gets the description the user assigned to the device being authorized.\n        /// </summary>\n        /// <value>\n        /// The description.\n        /// </value>\n        public string Description { get; set; }\n\n        /// <summary>\n        /// Gets or sets the creation time.\n        /// </summary>\n        /// <value>\n        /// The creation time.\n        /// </value>\n        public DateTime CreationTime { get; set; }\n\n        /// <summary>\n        /// Gets or sets the expiration.\n        /// </summary>\n        /// <value>\n        /// The expiration.\n        /// </value>\n        public DateTime? Expiration { get; set; }\n\n        /// <summary>\n        /// Gets or sets the data.\n        /// </summary>\n        /// <value>\n        /// The data.\n        /// </value>\n        public string Data { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/IdentityResource.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class IdentityResource\n    {\n        public int Id { get; set; }\n        public bool Enabled { get; set; } = true;\n        public string Name { get; set; }\n        public string DisplayName { get; set; }\n        public string Description { get; set; }\n        public bool Required { get; set; }\n        public bool Emphasize { get; set; }\n        public bool ShowInDiscoveryDocument { get; set; } = true;\n        public List<IdentityResourceClaim> UserClaims { get; set; }\n        public List<IdentityResourceProperty> Properties { get; set; }\n        public DateTime Created { get; set; } = DateTime.UtcNow;\n        public DateTime? Updated { get; set; }\n        public bool NonEditable { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/IdentityResourceClaim.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class IdentityResourceClaim : UserClaim\n    {\n        public int IdentityResourceId { get; set; }\n        public IdentityResource IdentityResource { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/IdentityResourceProperty.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class IdentityResourceProperty : Property\n    {\n        public int IdentityResourceId { get; set; }\n        public IdentityResource IdentityResource { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/PersistedGrant.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public class PersistedGrant\n    {\n        public string Key { get; set; }\n        public string Type { get; set; }\n        public string SubjectId { get; set; }\n        public string SessionId { get; set; }\n        public string ClientId { get; set; }\n        public string Description { get; set; }\n        public DateTime CreationTime { get; set; }\n        public DateTime? Expiration { get; set; }\n        public DateTime? ConsumedTime { get; set; }\n        public string Data { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/Property.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public abstract class Property\n    {\n        public int Id { get; set; }\n        public string Key { get; set; }\n        public string Value { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/Secret.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public abstract class Secret\n    {\n        public int Id { get; set; }\n        public string Description { get; set; }\n        public string Value { get; set; }\n        public DateTime? Expiration { get; set; }\n        public string Type { get; set; } = \"SharedSecret\";\n        public DateTime Created { get; set; } = DateTime.UtcNow;\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Entities/UserClaim.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.EntityFramework.Entities\n{\n    public abstract class UserClaim\n    {\n        public int Id { get; set; }\n        public string Type { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Extensions/ModelBuilderExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Entities;\n\nnamespace IdentityServer8.EntityFramework.Extensions\n{\n    /// <summary>\n    /// Extension methods to define the database schema for the configuration and operational data stores.\n    /// </summary>\n    public static class ModelBuilderExtensions\n    {\n        private static EntityTypeBuilder<TEntity> ToTable<TEntity>(this EntityTypeBuilder<TEntity> entityTypeBuilder, TableConfiguration configuration)\n            where TEntity : class\n        {\n            return string.IsNullOrWhiteSpace(configuration.Schema) ? entityTypeBuilder.ToTable(configuration.Name) : entityTypeBuilder.ToTable(configuration.Name, configuration.Schema);\n        }\n\n        /// <summary>\n        /// Configures the client context.\n        /// </summary>\n        /// <param name=\"modelBuilder\">The model builder.</param>\n        /// <param name=\"storeOptions\">The store options.</param>\n        public static void ConfigureClientContext(this ModelBuilder modelBuilder, ConfigurationStoreOptions storeOptions)\n        {\n            if (!string.IsNullOrWhiteSpace(storeOptions.DefaultSchema)) modelBuilder.HasDefaultSchema(storeOptions.DefaultSchema);\n\n            modelBuilder.Entity<Client>(client =>\n            {\n                client.ToTable(storeOptions.Client);\n                client.HasKey(x => x.Id);\n\n                client.Property(x => x.ClientId).HasMaxLength(200).IsRequired();\n                client.Property(x => x.ProtocolType).HasMaxLength(200).IsRequired();\n                client.Property(x => x.ClientName).HasMaxLength(200);\n                client.Property(x => x.ClientUri).HasMaxLength(2000);\n                client.Property(x => x.LogoUri).HasMaxLength(2000);\n                client.Property(x => x.Description).HasMaxLength(1000);\n                client.Property(x => x.FrontChannelLogoutUri).HasMaxLength(2000);\n                client.Property(x => x.BackChannelLogoutUri).HasMaxLength(2000);\n                client.Property(x => x.ClientClaimsPrefix).HasMaxLength(200);\n                client.Property(x => x.PairWiseSubjectSalt).HasMaxLength(200);\n                client.Property(x => x.UserCodeType).HasMaxLength(100);\n                client.Property(x => x.AllowedIdentityTokenSigningAlgorithms).HasMaxLength(100);\n\n                client.HasIndex(x => x.ClientId).IsUnique();\n\n                client.HasMany(x => x.AllowedGrantTypes).WithOne(x => x.Client).HasForeignKey(x=>x.ClientId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                client.HasMany(x => x.RedirectUris).WithOne(x => x.Client).HasForeignKey(x => x.ClientId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                client.HasMany(x => x.PostLogoutRedirectUris).WithOne(x => x.Client).HasForeignKey(x => x.ClientId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                client.HasMany(x => x.AllowedScopes).WithOne(x => x.Client).HasForeignKey(x => x.ClientId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                client.HasMany(x => x.ClientSecrets).WithOne(x => x.Client).HasForeignKey(x => x.ClientId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                client.HasMany(x => x.Claims).WithOne(x => x.Client).HasForeignKey(x => x.ClientId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                client.HasMany(x => x.IdentityProviderRestrictions).WithOne(x => x.Client).HasForeignKey(x => x.ClientId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                client.HasMany(x => x.AllowedCorsOrigins).WithOne(x => x.Client).HasForeignKey(x => x.ClientId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                client.HasMany(x => x.Properties).WithOne(x => x.Client).HasForeignKey(x => x.ClientId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n            });\n\n            modelBuilder.Entity<ClientGrantType>(grantType =>\n            {\n                grantType.ToTable(storeOptions.ClientGrantType);\n                grantType.Property(x => x.GrantType).HasMaxLength(250).IsRequired();\n            });\n\n            modelBuilder.Entity<ClientRedirectUri>(redirectUri =>\n            {\n                redirectUri.ToTable(storeOptions.ClientRedirectUri);\n                redirectUri.Property(x => x.RedirectUri).HasMaxLength(2000).IsRequired();\n            });\n\n            modelBuilder.Entity<ClientPostLogoutRedirectUri>(postLogoutRedirectUri =>\n            {\n                postLogoutRedirectUri.ToTable(storeOptions.ClientPostLogoutRedirectUri);\n                postLogoutRedirectUri.Property(x => x.PostLogoutRedirectUri).HasMaxLength(2000).IsRequired();\n            });\n\n            modelBuilder.Entity<ClientScope>(scope =>\n            {\n                scope.ToTable(storeOptions.ClientScopes);\n                scope.Property(x => x.Scope).HasMaxLength(200).IsRequired();\n            });\n\n            modelBuilder.Entity<ClientSecret>(secret =>\n            {\n                secret.ToTable(storeOptions.ClientSecret);\n                secret.Property(x => x.Value).HasMaxLength(4000).IsRequired();\n                secret.Property(x => x.Type).HasMaxLength(250).IsRequired();\n                secret.Property(x => x.Description).HasMaxLength(2000);\n            });\n\n            modelBuilder.Entity<ClientClaim>(claim =>\n            {\n                claim.ToTable(storeOptions.ClientClaim);\n                claim.Property(x => x.Type).HasMaxLength(250).IsRequired();\n                claim.Property(x => x.Value).HasMaxLength(250).IsRequired();\n            });\n\n            modelBuilder.Entity<ClientIdPRestriction>(idPRestriction =>\n            {\n                idPRestriction.ToTable(storeOptions.ClientIdPRestriction);\n                idPRestriction.Property(x => x.Provider).HasMaxLength(200).IsRequired();\n            });\n\n            modelBuilder.Entity<ClientCorsOrigin>(corsOrigin =>\n            {\n                corsOrigin.ToTable(storeOptions.ClientCorsOrigin);\n                corsOrigin.Property(x => x.Origin).HasMaxLength(150).IsRequired();\n            });\n\n            modelBuilder.Entity<ClientProperty>(property =>\n            {\n                property.ToTable(storeOptions.ClientProperty);\n                property.Property(x => x.Key).HasMaxLength(250).IsRequired();\n                property.Property(x => x.Value).HasMaxLength(2000).IsRequired();\n            });\n        }\n\n        /// <summary>\n        /// Configures the persisted grant context.\n        /// </summary>\n        /// <param name=\"modelBuilder\">The model builder.</param>\n        /// <param name=\"storeOptions\">The store options.</param>\n        public static void ConfigurePersistedGrantContext(this ModelBuilder modelBuilder, OperationalStoreOptions storeOptions)\n        {\n            if (!string.IsNullOrWhiteSpace(storeOptions.DefaultSchema)) modelBuilder.HasDefaultSchema(storeOptions.DefaultSchema);\n\n            modelBuilder.Entity<PersistedGrant>(grant =>\n            {\n                grant.ToTable(storeOptions.PersistedGrants);\n\n                grant.Property(x => x.Key).HasMaxLength(200).ValueGeneratedNever();\n                grant.Property(x => x.Type).HasMaxLength(50).IsRequired();\n                grant.Property(x => x.SubjectId).HasMaxLength(200);\n                grant.Property(x => x.SessionId).HasMaxLength(100);\n                grant.Property(x => x.ClientId).HasMaxLength(200).IsRequired();\n                grant.Property(x => x.Description).HasMaxLength(200);\n                grant.Property(x => x.CreationTime).IsRequired();\n                // 50000 chosen to be explicit to allow enough size to avoid truncation, yet stay beneath the MySql row size limit of ~65K\n                // apparently anything over 4K converts to nvarchar(max) on SqlServer\n                grant.Property(x => x.Data).HasMaxLength(50000).IsRequired();\n\n                grant.HasKey(x => x.Key);\n\n                grant.HasIndex(x => new { x.SubjectId, x.ClientId, x.Type });\n                grant.HasIndex(x => new { x.SubjectId, x.SessionId, x.Type });\n                grant.HasIndex(x => x.Expiration);\n            });\n\n            modelBuilder.Entity<DeviceFlowCodes>(codes =>\n            {\n                codes.ToTable(storeOptions.DeviceFlowCodes);\n\n                codes.Property(x => x.DeviceCode).HasMaxLength(200).IsRequired();\n                codes.Property(x => x.UserCode).HasMaxLength(200).IsRequired();\n                codes.Property(x => x.SubjectId).HasMaxLength(200);\n                codes.Property(x => x.SessionId).HasMaxLength(100);\n                codes.Property(x => x.ClientId).HasMaxLength(200).IsRequired();\n                codes.Property(x => x.Description).HasMaxLength(200);\n                codes.Property(x => x.CreationTime).IsRequired();\n                codes.Property(x => x.Expiration).IsRequired();\n                // 50000 chosen to be explicit to allow enough size to avoid truncation, yet stay beneath the MySql row size limit of ~65K\n                // apparently anything over 4K converts to nvarchar(max) on SqlServer\n                codes.Property(x => x.Data).HasMaxLength(50000).IsRequired();\n\n                codes.HasKey(x => new {x.UserCode});\n\n                codes.HasIndex(x => x.DeviceCode).IsUnique();\n                codes.HasIndex(x => x.Expiration);\n            });\n        }\n\n        /// <summary>\n        /// Configures the resources context.\n        /// </summary>\n        /// <param name=\"modelBuilder\">The model builder.</param>\n        /// <param name=\"storeOptions\">The store options.</param>\n        public static void ConfigureResourcesContext(this ModelBuilder modelBuilder, ConfigurationStoreOptions storeOptions)\n        {\n            if (!string.IsNullOrWhiteSpace(storeOptions.DefaultSchema)) modelBuilder.HasDefaultSchema(storeOptions.DefaultSchema);\n\n            modelBuilder.Entity<IdentityResource>(identityResource =>\n            {\n                identityResource.ToTable(storeOptions.IdentityResource).HasKey(x => x.Id);\n\n                identityResource.Property(x => x.Name).HasMaxLength(200).IsRequired();\n                identityResource.Property(x => x.DisplayName).HasMaxLength(200);\n                identityResource.Property(x => x.Description).HasMaxLength(1000);\n\n                identityResource.HasIndex(x => x.Name).IsUnique();\n\n                identityResource.HasMany(x => x.UserClaims).WithOne(x => x.IdentityResource).HasForeignKey(x => x.IdentityResourceId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                identityResource.HasMany(x => x.Properties).WithOne(x => x.IdentityResource).HasForeignKey(x => x.IdentityResourceId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n            });\n\n            modelBuilder.Entity<IdentityResourceClaim>(claim =>\n            {\n                claim.ToTable(storeOptions.IdentityResourceClaim).HasKey(x => x.Id);\n\n                claim.Property(x => x.Type).HasMaxLength(200).IsRequired();\n            });\n\n            modelBuilder.Entity<IdentityResourceProperty>(property =>\n            {\n                property.ToTable(storeOptions.IdentityResourceProperty);\n                property.Property(x => x.Key).HasMaxLength(250).IsRequired();\n                property.Property(x => x.Value).HasMaxLength(2000).IsRequired();\n            });\n\n\n\n            modelBuilder.Entity<ApiResource>(apiResource =>\n            {\n                apiResource.ToTable(storeOptions.ApiResource).HasKey(x => x.Id);\n\n                apiResource.Property(x => x.Name).HasMaxLength(200).IsRequired();\n                apiResource.Property(x => x.DisplayName).HasMaxLength(200);\n                apiResource.Property(x => x.Description).HasMaxLength(1000);\n                apiResource.Property(x => x.AllowedAccessTokenSigningAlgorithms).HasMaxLength(100);\n\n                apiResource.HasIndex(x => x.Name).IsUnique();\n\n                apiResource.HasMany(x => x.Secrets).WithOne(x => x.ApiResource).HasForeignKey(x => x.ApiResourceId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                apiResource.HasMany(x => x.Scopes).WithOne(x => x.ApiResource).HasForeignKey(x => x.ApiResourceId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                apiResource.HasMany(x => x.UserClaims).WithOne(x => x.ApiResource).HasForeignKey(x => x.ApiResourceId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n                apiResource.HasMany(x => x.Properties).WithOne(x => x.ApiResource).HasForeignKey(x => x.ApiResourceId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n            });\n\n            modelBuilder.Entity<ApiResourceSecret>(apiSecret =>\n            {\n                apiSecret.ToTable(storeOptions.ApiResourceSecret).HasKey(x => x.Id);\n\n                apiSecret.Property(x => x.Description).HasMaxLength(1000);\n                apiSecret.Property(x => x.Value).HasMaxLength(4000).IsRequired();\n                apiSecret.Property(x => x.Type).HasMaxLength(250).IsRequired();\n            });\n\n            modelBuilder.Entity<ApiResourceClaim>(apiClaim =>\n            {\n                apiClaim.ToTable(storeOptions.ApiResourceClaim).HasKey(x => x.Id);\n\n                apiClaim.Property(x => x.Type).HasMaxLength(200).IsRequired();\n            });\n\n            modelBuilder.Entity<ApiResourceScope>((System.Action<EntityTypeBuilder<ApiResourceScope>>)(apiScope =>\n            {\n                apiScope.ToTable((TableConfiguration)storeOptions.ApiResourceScope).HasKey(x => x.Id);\n\n                apiScope.Property(x => x.Scope).HasMaxLength(200).IsRequired();\n            }));\n\n            modelBuilder.Entity<ApiResourceProperty>(property =>\n            {\n                property.ToTable(storeOptions.ApiResourceProperty);\n                property.Property(x => x.Key).HasMaxLength(250).IsRequired();\n                property.Property(x => x.Value).HasMaxLength(2000).IsRequired();\n            });\n\n\n            modelBuilder.Entity<ApiScope>(scope =>\n            {\n                scope.ToTable(storeOptions.ApiScope).HasKey(x => x.Id);\n\n                scope.Property(x => x.Name).HasMaxLength(200).IsRequired();\n                scope.Property(x => x.DisplayName).HasMaxLength(200);\n                scope.Property(x => x.Description).HasMaxLength(1000);\n\n                scope.HasIndex(x => x.Name).IsUnique();\n\n                scope.HasMany(x => x.UserClaims).WithOne(x => x.Scope).HasForeignKey(x => x.ScopeId).IsRequired().OnDelete(DeleteBehavior.Cascade);\n            });\n            modelBuilder.Entity<ApiScopeClaim>(scopeClaim =>\n            {\n                scopeClaim.ToTable(storeOptions.ApiScopeClaim).HasKey(x => x.Id);\n\n                scopeClaim.Property(x => x.Type).HasMaxLength(200).IsRequired();\n            });\n            modelBuilder.Entity<ApiScopeProperty>(property =>\n            {\n                property.ToTable(storeOptions.ApiScopeProperty).HasKey(x => x.Id);\n                property.Property(x => x.Key).HasMaxLength(250).IsRequired();\n                property.Property(x => x.Value).HasMaxLength(2000).IsRequired();\n            });\n\n\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using AutoMapper;\nglobal using IdentityModel;\nglobal using IdentityServer8.EntityFramework.DbContexts;\nglobal using IdentityServer8.EntityFramework.Extensions;\nglobal using IdentityServer8.EntityFramework.Interfaces;\n//global using IdentityServer8.EntityFramework.Entities;\nglobal using IdentityServer8.EntityFramework.Mappers;\nglobal using IdentityServer8.EntityFramework.Options;\nglobal using IdentityServer8.Extensions;\n//global using IdentityServer8.Models;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Stores.Serialization;\nglobal using Microsoft.EntityFrameworkCore;\nglobal using Microsoft.EntityFrameworkCore.Metadata.Builders;\nglobal using Microsoft.Extensions.DependencyInjection;\nglobal using Microsoft.Extensions.Logging;\nglobal using System.Buffers;\nglobal using System.Runtime.CompilerServices;\nglobal using ClaimValueTypes = System.Security.Claims.ClaimValueTypes;\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/IdentityServer8.EntityFramework.Storage.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n    <PropertyGroup>\n        <Description>EntityFramework persistence layer for IdentityServer8</Description>\n        <IsPackable>true</IsPackable>\n        <GeneratePackageOnBuild>true</GeneratePackageOnBuild>\n    </PropertyGroup>\n\n    <PropertyGroup>\n        <ContinuousIntegrationBuild Condition=\"'$(TF_BUILD)' == 'true'\">True</ContinuousIntegrationBuild>\n        <ContinuousIntegrationBuild Condition=\"'$(GITHUB_ACTIONS)' == 'true'\">True</ContinuousIntegrationBuild>\n    </PropertyGroup>\n\n    <ItemGroup>\n        <PackageReference Include=\"AutoMapper\" />\n        <PackageReference Include=\"Microsoft.EntityFrameworkCore.Relational\" />\n    </ItemGroup>\n\n    <ItemGroup>\n        <ProjectReference Include=\"..\\..\\Security\\IdentityServer8.Security\\IdentityServer8.Security.csproj\" />\n        <ProjectReference Include=\"..\\..\\Storage\\src\\IdentityServer8.Storage.csproj\" />\n    </ItemGroup>\n\n</Project>\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Interfaces/IConfigurationDbContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Entities;\n\nnamespace IdentityServer8.EntityFramework.Interfaces\n{\n    /// <summary>\n    /// Abstraction for the configuration context.\n    /// </summary>\n    /// <seealso cref=\"System.IDisposable\" />\n    public interface IConfigurationDbContext : IDisposable\n    {\n        /// <summary>\n        /// Gets or sets the clients.\n        /// </summary>\n        /// <value>\n        /// The clients.\n        /// </value>\n        DbSet<Client> Clients { get; set; }\n        \n        /// <summary>\n        /// Gets or sets the clients' CORS origins.\n        /// </summary>\n        /// <value>\n        /// The clients CORS origins.\n        /// </value>\n        DbSet<ClientCorsOrigin> ClientCorsOrigins { get; set; }\n\n        /// <summary>\n        /// Gets or sets the identity resources.\n        /// </summary>\n        /// <value>\n        /// The identity resources.\n        /// </value>\n        DbSet<IdentityResource> IdentityResources { get; set; }\n\n        /// <summary>\n        /// Gets or sets the API resources.\n        /// </summary>\n        /// <value>\n        /// The API resources.\n        /// </value>\n        DbSet<ApiResource> ApiResources { get; set; }\n\n        /// <summary>\n        /// Gets or sets the scopes.\n        /// </summary>\n        /// <value>\n        /// The identity resources.\n        /// </value>\n        DbSet<ApiScope> ApiScopes { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Interfaces/IPersistedGrantDbContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Entities;\n\nnamespace IdentityServer8.EntityFramework.Interfaces\n{\n    /// <summary>\n    /// Abstraction for the operational data context.\n    /// </summary>\n    /// <seealso cref=\"System.IDisposable\" />\n    public interface IPersistedGrantDbContext : IDisposable\n    {\n        /// <summary>\n        /// Gets or sets the persisted grants.\n        /// </summary>\n        /// <value>\n        /// The persisted grants.\n        /// </value>\n        DbSet<PersistedGrant> PersistedGrants { get; set; }\n\n        /// <summary>\n        /// Gets or sets the device flow codes.\n        /// </summary>\n        /// <value>\n        /// The device flow codes.\n        /// </value>\n        DbSet<DeviceFlowCodes> DeviceFlowCodes { get; set; }\n\n        /// <summary>\n        /// Saves the changes.\n        /// </summary>\n        /// <returns></returns>\n        Task<int> SaveChangesAsync();\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/AllowedSigningAlgorithmsConverter.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    class AllowedSigningAlgorithmsConverter : \n        IValueConverter<ICollection<string>, string>,\n        IValueConverter<string, ICollection<string>>\n    {\n        public static AllowedSigningAlgorithmsConverter Converter = new AllowedSigningAlgorithmsConverter();\n\n        public string Convert(ICollection<string> sourceMember, ResolutionContext context)\n        {\n            if (sourceMember == null || !sourceMember.Any())\n            {\n                return null;\n            }\n            return sourceMember.Aggregate((x, y) => $\"{x},{y}\");\n        }\n\n        public ICollection<string> Convert(string sourceMember, ResolutionContext context)\n        {\n            var list = new HashSet<string>();\n            if (!String.IsNullOrWhiteSpace(sourceMember))\n            {\n                sourceMember = sourceMember.Trim();\n                foreach (var item in sourceMember.Split(new[] { ',' }, StringSplitOptions.RemoveEmptyEntries).Distinct())\n                {\n                    list.Add(item);\n                }\n            }\n            return list;\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/ApiResourceMapperProfile.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    /// <summary>\n    /// Defines entity/model mapping for API resources.\n    /// </summary>\n    /// <seealso cref=\"AutoMapper.Profile\" />\n    public class ApiResourceMapperProfile : Profile\n    {\n        /// <summary>\n        /// <see cref=\"ApiResourceMapperProfile\"/>\n        /// </summary>\n        public ApiResourceMapperProfile()\n        {\n            CreateMap<Entities.ApiResourceProperty, KeyValuePair<string, string>>()\n                .ReverseMap();\n\n            CreateMap<Entities.ApiResource, Models.ApiResource>(MemberList.Destination)\n                .ConstructUsing(src => new Models.ApiResource())\n                .ForMember(x => x.ApiSecrets, opts => opts.MapFrom(x => x.Secrets))\n                .ForMember(x=>x.AllowedAccessTokenSigningAlgorithms, opts => opts.ConvertUsing(AllowedSigningAlgorithmsConverter.Converter, x=>x.AllowedAccessTokenSigningAlgorithms))\n                .ReverseMap()\n                .ForMember(x => x.AllowedAccessTokenSigningAlgorithms, opts => opts.ConvertUsing(AllowedSigningAlgorithmsConverter.Converter, x => x.AllowedAccessTokenSigningAlgorithms));\n\n            CreateMap<Entities.ApiResourceClaim, string>()\n                .ConstructUsing(x => x.Type)\n                .ReverseMap()\n                .ForMember(dest => dest.Type, opt => opt.MapFrom(src => src));\n\n            CreateMap<Entities.ApiResourceSecret, Models.Secret>(MemberList.Destination)\n                .ForMember(dest => dest.Type, opt => opt.Condition(srs => srs != null))\n                .ReverseMap();\n\n            CreateMap<Entities.ApiResourceScope, string>()\n                .ConstructUsing(x => x.Scope)\n                .ReverseMap()\n                .ForMember(dest => dest.Scope, opt => opt.MapFrom(src => src));\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/ApiResourceMappers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Entities;\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    /// <summary>\n    /// Extension methods to map to/from entity/model for API resources.\n    /// </summary>\n    public static class ApiResourceMappers\n    {\n        static ApiResourceMappers()\n        {\n            Mapper = new MapperConfiguration(cfg => cfg.AddProfile<ApiResourceMapperProfile>())\n                .CreateMapper();\n        }\n\n        internal static IMapper Mapper { get; }\n\n        /// <summary>\n        /// Maps an entity to a model.\n        /// </summary>\n        /// <param name=\"entity\">The entity.</param>\n        /// <returns></returns>\n        public static Models.ApiResource ToModel(this ApiResource entity)\n        {\n            return entity == null ? null : Mapper.Map<Models.ApiResource>(entity);\n        }\n\n        /// <summary>\n        /// Maps a model to an entity.\n        /// </summary>\n        /// <param name=\"model\">The model.</param>\n        /// <returns></returns>\n        public static ApiResource ToEntity(this Models.ApiResource model)\n        {\n            return model == null ? null : Mapper.Map<ApiResource>(model);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/ClientMapperProfile.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    /// <summary>\n    /// Defines entity/model mapping for clients.\n    /// </summary>\n    /// <seealso cref=\"AutoMapper.Profile\" />\n    public class ClientMapperProfile : Profile\n    {\n        /// <summary>\n        /// <see>\n        ///     <cref>{ClientMapperProfile}</cref>\n        /// </see>\n        /// </summary>\n        public ClientMapperProfile()\n        {\n            CreateMap<Entities.ClientProperty, KeyValuePair<string, string>>()\n                .ReverseMap();\n\n            CreateMap<Entities.Client, Models.Client>()\n                .ForMember(dest => dest.ProtocolType, opt => opt.Condition(srs => srs != null))\n                .ForMember(x => x.AllowedIdentityTokenSigningAlgorithms, opts => opts.ConvertUsing(AllowedSigningAlgorithmsConverter.Converter, x => x.AllowedIdentityTokenSigningAlgorithms))\n                .ReverseMap()\n                .ForMember(x => x.AllowedIdentityTokenSigningAlgorithms, opts => opts.ConvertUsing(AllowedSigningAlgorithmsConverter.Converter, x => x.AllowedIdentityTokenSigningAlgorithms));\n\n            CreateMap<Entities.ClientCorsOrigin, string>()\n                .ConstructUsing(src => src.Origin)\n                .ReverseMap()\n                .ForMember(dest => dest.Origin, opt => opt.MapFrom(src => src));\n\n            CreateMap<Entities.ClientIdPRestriction, string>()\n                .ConstructUsing(src => src.Provider)\n                .ReverseMap()\n                .ForMember(dest => dest.Provider, opt => opt.MapFrom(src => src));\n\n            CreateMap<Entities.ClientClaim, ClientClaim>(MemberList.None)\n                .ConstructUsing(src => new ClientClaim(src.Type, src.Value, ClaimValueTypes.String))\n                .ReverseMap();\n\n            CreateMap<Entities.ClientScope, string>()\n                .ConstructUsing(src => src.Scope)\n                .ReverseMap()\n                .ForMember(dest => dest.Scope, opt => opt.MapFrom(src => src));\n\n            CreateMap<Entities.ClientPostLogoutRedirectUri, string>()\n                .ConstructUsing(src => src.PostLogoutRedirectUri)\n                .ReverseMap()\n                .ForMember(dest => dest.PostLogoutRedirectUri, opt => opt.MapFrom(src => src));\n\n            CreateMap<Entities.ClientRedirectUri, string>()\n                .ConstructUsing(src => src.RedirectUri)\n                .ReverseMap()\n                .ForMember(dest => dest.RedirectUri, opt => opt.MapFrom(src => src));\n\n            CreateMap<Entities.ClientGrantType, string>()\n                .ConstructUsing(src => src.GrantType)\n                .ReverseMap()\n                .ForMember(dest => dest.GrantType, opt => opt.MapFrom(src => src));\n\n            CreateMap<Entities.ClientSecret, Models.Secret>(MemberList.Destination)\n                .ForMember(dest => dest.Type, opt => opt.Condition(srs => srs != null))\n                .ReverseMap();\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/ClientMappers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    /// <summary>\n    /// Extension methods to map to/from entity/model for clients.\n    /// </summary>\n    public static class ClientMappers\n    {\n        static ClientMappers()\n        {\n            Mapper = new MapperConfiguration(cfg => cfg.AddProfile<ClientMapperProfile>())\n                .CreateMapper();\n        }\n\n        internal static IMapper Mapper { get; }\n\n        /// <summary>\n        /// Maps an entity to a model.\n        /// </summary>\n        /// <param name=\"entity\">The entity.</param>\n        /// <returns></returns>\n        public static Models.Client ToModel(this Entities.Client entity)\n        {\n            return Mapper.Map<Models.Client>(entity);\n        }\n\n        /// <summary>\n        /// Maps a model to an entity.\n        /// </summary>\n        /// <param name=\"model\">The model.</param>\n        /// <returns></returns>\n        public static Entities.Client ToEntity(this Models.Client model)\n        {\n            return Mapper.Map<Entities.Client>(model);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/IdentityResourceMapperProfile.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    /// <summary>\n    /// Defines entity/model mapping for identity resources.\n    /// </summary>\n    /// <seealso cref=\"AutoMapper.Profile\" />\n    public class IdentityResourceMapperProfile : Profile\n    {\n        /// <summary>\n        /// <see cref=\"IdentityResourceMapperProfile\"/>\n        /// </summary>\n        public IdentityResourceMapperProfile()\n        {\n            CreateMap<Entities.IdentityResourceProperty, KeyValuePair<string, string>>()\n                .ReverseMap();\n\n            CreateMap<Entities.IdentityResource, Models.IdentityResource>(MemberList.Destination)\n                .ConstructUsing(src => new Models.IdentityResource())\n                .ReverseMap();\n\n            CreateMap<Entities.IdentityResourceClaim, string>()\n               .ConstructUsing(x => x.Type)\n               .ReverseMap()\n               .ForMember(dest => dest.Type, opt => opt.MapFrom(src => src));\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/IdentityResourceMappers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Entities;\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    /// <summary>\n    /// Extension methods to map to/from entity/model for identity resources.\n    /// </summary>\n    public static class IdentityResourceMappers\n    {\n        static IdentityResourceMappers()\n        {\n            Mapper = new MapperConfiguration(cfg => cfg.AddProfile<IdentityResourceMapperProfile>())\n                .CreateMapper();\n        }\n\n        internal static IMapper Mapper { get; }\n\n        /// <summary>\n        /// Maps an entity to a model.\n        /// </summary>\n        /// <param name=\"entity\">The entity.</param>\n        /// <returns></returns>\n        public static Models.IdentityResource ToModel(this IdentityResource entity)\n        {\n            return entity == null ? null : Mapper.Map<Models.IdentityResource>(entity);\n        }\n\n        /// <summary>\n        /// Maps a model to an entity.\n        /// </summary>\n        /// <param name=\"model\">The model.</param>\n        /// <returns></returns>\n        public static IdentityResource ToEntity(this Models.IdentityResource model)\n        {\n            return model == null ? null : Mapper.Map<IdentityResource>(model);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/PersistedGrantMapperProfile.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    /// <summary>\n    /// Defines entity/model mapping for persisted grants.\n    /// </summary>\n    /// <seealso cref=\"AutoMapper.Profile\" />\n    public class PersistedGrantMapperProfile:Profile\n    {\n        /// <summary>\n        /// <see cref=\"PersistedGrantMapperProfile\">\n        /// </see>\n        /// </summary>\n        public PersistedGrantMapperProfile()\n        {\n            CreateMap<Entities.PersistedGrant, Models.PersistedGrant>(MemberList.Destination)\n                .ReverseMap();\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/PersistedGrantMappers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    /// <summary>\n    /// Extension methods to map to/from entity/model for persisted grants.\n    /// </summary>\n    public static class PersistedGrantMappers\n    {\n        static PersistedGrantMappers()\n        {\n            Mapper = new MapperConfiguration(cfg =>cfg.AddProfile<PersistedGrantMapperProfile>())\n                .CreateMapper();\n        }\n\n        internal static IMapper Mapper { get; }\n\n        /// <summary>\n        /// Maps an entity to a model.\n        /// </summary>\n        /// <param name=\"entity\">The entity.</param>\n        /// <returns></returns>\n        public static PersistedGrant ToModel(this Entities.PersistedGrant entity)\n        {\n            return entity == null ? null : Mapper.Map<PersistedGrant>(entity);\n        }\n\n        /// <summary>\n        /// Maps a model to an entity.\n        /// </summary>\n        /// <param name=\"model\">The model.</param>\n        /// <returns></returns>\n        public static Entities.PersistedGrant ToEntity(this PersistedGrant model)\n        {\n            return model == null ? null : Mapper.Map<Entities.PersistedGrant>(model);\n        }\n\n        /// <summary>\n        /// Updates an entity from a model.\n        /// </summary>\n        /// <param name=\"model\">The model.</param>\n        /// <param name=\"entity\">The entity.</param>\n        public static void UpdateEntity(this PersistedGrant model, Entities.PersistedGrant entity)\n        {\n            Mapper.Map(model, entity);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/ScopeMapperProfile.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    /// <summary>\n    /// Defines entity/model mapping for scopes.\n    /// </summary>\n    /// <seealso cref=\"AutoMapper.Profile\" />\n    public class ScopeMapperProfile : Profile\n    {\n        /// <summary>\n        /// <see cref=\"ScopeMapperProfile\"/>\n        /// </summary>\n        public ScopeMapperProfile()\n        {\n            CreateMap<Entities.ApiScopeProperty, KeyValuePair<string, string>>()\n                .ReverseMap();\n\n            CreateMap<Entities.ApiScopeClaim, string>()\n               .ConstructUsing(x => x.Type)\n               .ReverseMap()\n               .ForMember(dest => dest.Type, opt => opt.MapFrom(src => src));\n\n            CreateMap<Entities.ApiScope, Models.ApiScope>(MemberList.Destination)\n                .ConstructUsing(src => new Models.ApiScope())\n                .ForMember(x => x.Properties, opts => opts.MapFrom(x => x.Properties))\n                .ForMember(x => x.UserClaims, opts => opts.MapFrom(x => x.UserClaims))\n                .ReverseMap();\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Mappers/ScopeMappers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Entities;\n\nnamespace IdentityServer8.EntityFramework.Mappers\n{\n    /// <summary>\n    /// Extension methods to map to/from entity/model for scopes.\n    /// </summary>\n    public static class ScopeMappers\n    {\n        static ScopeMappers()\n        {\n            Mapper = new MapperConfiguration(cfg => cfg.AddProfile<ScopeMapperProfile>())\n                .CreateMapper();\n        }\n\n        internal static IMapper Mapper { get; }\n\n        /// <summary>\n        /// Maps an entity to a model.\n        /// </summary>\n        /// <param name=\"entity\">The entity.</param>\n        /// <returns></returns>\n        public static Models.ApiScope ToModel(this ApiScope entity)\n        {\n            return entity == null ? null : Mapper.Map<Models.ApiScope>(entity);\n        }\n\n        /// <summary>\n        /// Maps a model to an entity.\n        /// </summary>\n        /// <param name=\"model\">The model.</param>\n        /// <returns></returns>\n        public static ApiScope ToEntity(this Models.ApiScope model)\n        {\n            return model == null ? null : Mapper.Map<ApiScope>(model);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Options/ConfigurationStoreOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Options\n{\n    /// <summary>\n    /// Options for configuring the configuration context.\n    /// </summary>\n    public class ConfigurationStoreOptions\n    {\n        /// <summary>\n        /// Callback to configure the EF DbContext.\n        /// </summary>\n        /// <value>\n        /// The configure database context.\n        /// </value>\n        public Action<DbContextOptionsBuilder> ConfigureDbContext { get; set; }\n\n        /// <summary>\n        /// Callback in DI resolve the EF DbContextOptions. If set, ConfigureDbContext will not be used.\n        /// </summary>\n        /// <value>\n        /// The configure database context.\n        /// </value>\n        public Action<IServiceProvider, DbContextOptionsBuilder> ResolveDbContextOptions { get; set; }\n\n        /// <summary>\n        /// Gets or sets the default schema.\n        /// </summary>\n        /// <value>\n        /// The default schema.\n        /// </value>\n        public string DefaultSchema { get; set; } = null;\n\n        /// <summary>\n        /// Gets or sets the identity resource table configuration.\n        /// </summary>\n        /// <value>\n        /// The identity resource.\n        /// </value>\n        public TableConfiguration IdentityResource { get; set; } = new TableConfiguration(\"IdentityResources\");\n        /// <summary>\n        /// Gets or sets the identity claim table configuration.\n        /// </summary>\n        /// <value>\n        /// The identity claim.\n        /// </value>\n        public TableConfiguration IdentityResourceClaim { get; set; } = new TableConfiguration(\"IdentityResourceClaims\");\n        /// <summary>\n        /// Gets or sets the identity resource property table configuration.\n        /// </summary>\n        /// <value>\n        /// The client property.\n        /// </value>\n        public TableConfiguration IdentityResourceProperty { get; set; } = new TableConfiguration(\"IdentityResourceProperties\");\n\n        /// <summary>\n        /// Gets or sets the API resource table configuration.\n        /// </summary>\n        /// <value>\n        /// The API resource.\n        /// </value>\n        public TableConfiguration ApiResource { get; set; } = new TableConfiguration(\"ApiResources\");\n        /// <summary>\n        /// Gets or sets the API secret table configuration.\n        /// </summary>\n        /// <value>\n        /// The API secret.\n        /// </value>\n        public TableConfiguration ApiResourceSecret { get; set; } = new TableConfiguration(\"ApiResourceSecrets\");\n        /// <summary>\n        /// Gets or sets the API scope table configuration.\n        /// </summary>\n        /// <value>\n        /// The API scope.\n        /// </value>\n        public TableConfiguration ApiResourceScope { get; set; } = new TableConfiguration(\"ApiResourceScopes\");\n        /// <summary>\n        /// Gets or sets the API claim table configuration.\n        /// </summary>\n        /// <value>\n        /// The API claim.\n        /// </value>\n        public TableConfiguration ApiResourceClaim { get; set; } = new TableConfiguration(\"ApiResourceClaims\");\n        /// <summary>\n        /// Gets or sets the API resource property table configuration.\n        /// </summary>\n        /// <value>\n        /// The client property.\n        /// </value>\n        public TableConfiguration ApiResourceProperty { get; set; } = new TableConfiguration(\"ApiResourceProperties\");\n\n        /// <summary>\n        /// Gets or sets the client table configuration.\n        /// </summary>\n        /// <value>\n        /// The client.\n        /// </value>\n        public TableConfiguration Client { get; set; } = new TableConfiguration(\"Clients\");\n        /// <summary>\n        /// Gets or sets the type of the client grant table configuration.\n        /// </summary>\n        /// <value>\n        /// The type of the client grant.\n        /// </value>\n        public TableConfiguration ClientGrantType { get; set; } = new TableConfiguration(\"ClientGrantTypes\");\n        /// <summary>\n        /// Gets or sets the client redirect URI table configuration.\n        /// </summary>\n        /// <value>\n        /// The client redirect URI.\n        /// </value>\n        public TableConfiguration ClientRedirectUri { get; set; } = new TableConfiguration(\"ClientRedirectUris\");\n        /// <summary>\n        /// Gets or sets the client post logout redirect URI table configuration.\n        /// </summary>\n        /// <value>\n        /// The client post logout redirect URI.\n        /// </value>\n        public TableConfiguration ClientPostLogoutRedirectUri { get; set; } = new TableConfiguration(\"ClientPostLogoutRedirectUris\");\n        /// <summary>\n        /// Gets or sets the client scopes table configuration.\n        /// </summary>\n        /// <value>\n        /// The client scopes.\n        /// </value>\n        public TableConfiguration ClientScopes { get; set; } = new TableConfiguration(\"ClientScopes\");\n        /// <summary>\n        /// Gets or sets the client secret table configuration.\n        /// </summary>\n        /// <value>\n        /// The client secret.\n        /// </value>\n        public TableConfiguration ClientSecret { get; set; } = new TableConfiguration(\"ClientSecrets\");\n        /// <summary>\n        /// Gets or sets the client claim table configuration.\n        /// </summary>\n        /// <value>\n        /// The client claim.\n        /// </value>\n        public TableConfiguration ClientClaim { get; set; } = new TableConfiguration(\"ClientClaims\");\n        /// <summary>\n        /// Gets or sets the client IdP restriction table configuration.\n        /// </summary>\n        /// <value>\n        /// The client IdP restriction.\n        /// </value>\n        public TableConfiguration ClientIdPRestriction { get; set; } = new TableConfiguration(\"ClientIdPRestrictions\");\n        /// <summary>\n        /// Gets or sets the client cors origin table configuration.\n        /// </summary>\n        /// <value>\n        /// The client cors origin.\n        /// </value>\n        public TableConfiguration ClientCorsOrigin { get; set; } = new TableConfiguration(\"ClientCorsOrigins\");\n        /// <summary>\n        /// Gets or sets the client property table configuration.\n        /// </summary>\n        /// <value>\n        /// The client property.\n        /// </value>\n        public TableConfiguration ClientProperty { get; set; } = new TableConfiguration(\"ClientProperties\");\n\n        /// <summary>\n        /// Gets or sets the scope table configuration.\n        /// </summary>\n        /// <value>\n        /// The API resource.\n        /// </value>\n        public TableConfiguration ApiScope { get; set; } = new TableConfiguration(\"ApiScopes\");\n        /// <summary>\n        /// Gets or sets the scope claim table configuration.\n        /// </summary>\n        /// <value>\n        /// The API scope claim.\n        /// </value>\n        public TableConfiguration ApiScopeClaim { get; set; } = new TableConfiguration(\"ApiScopeClaims\");\n        /// <summary>\n        /// Gets or sets the API resource property table configuration.\n        /// </summary>\n        /// <value>\n        /// The client property.\n        /// </value>\n        public TableConfiguration ApiScopeProperty { get; set; } = new TableConfiguration(\"ApiScopeProperties\");\n\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Options/OperationalStoreOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Options\n{\n    /// <summary>\n    /// Options for configuring the operational context.\n    /// </summary>\n    public class OperationalStoreOptions\n    {\n        /// <summary>\n        /// Callback to configure the EF DbContext.\n        /// </summary>\n        /// <value>\n        /// The configure database context.\n        /// </value>\n        public Action<DbContextOptionsBuilder> ConfigureDbContext { get; set; }\n\n        /// <summary>\n        /// Callback in DI resolve the EF DbContextOptions. If set, ConfigureDbContext will not be used.\n        /// </summary>\n        /// <value>\n        /// The configure database context.\n        /// </value>\n        public Action<IServiceProvider, DbContextOptionsBuilder> ResolveDbContextOptions { get; set; }\n\n        /// <summary>\n        /// Gets or sets the default schema.\n        /// </summary>\n        /// <value>\n        /// The default schema.\n        /// </value>\n        public string DefaultSchema { get; set; } = null;\n\n        /// <summary>\n        /// Gets or sets the persisted grants table configuration.\n        /// </summary>\n        /// <value>\n        /// The persisted grants.\n        /// </value>\n        public TableConfiguration PersistedGrants { get; set; } = new TableConfiguration(\"PersistedGrants\");\n\n        /// <summary>\n        /// Gets or sets the device flow codes table configuration.\n        /// </summary>\n        /// <value>\n        /// The device flow codes.\n        /// </value>\n        public TableConfiguration DeviceFlowCodes { get; set; } = new TableConfiguration(\"DeviceCodes\");\n\n        /// <summary>\n        /// Gets or sets a value indicating whether stale entries will be automatically cleaned up from the database.\n        /// This is implemented by periodically connecting to the database (according to the TokenCleanupInterval) from the hosting application.\n        /// Defaults to false.\n        /// </summary>\n        /// <value>\n        ///   <c>true</c> if [enable token cleanup]; otherwise, <c>false</c>.\n        /// </value>\n        public bool EnableTokenCleanup { get; set; } = false;\n\n        /// <summary>\n        /// Gets or sets the token cleanup interval (in seconds). The default is 3600 (1 hour).\n        /// </summary>\n        /// <value>\n        /// The token cleanup interval.\n        /// </value>\n        public int TokenCleanupInterval { get; set; } = 3600;\n\n        /// <summary>\n        /// Gets or sets the number of records to remove at a time. Defaults to 100.\n        /// </summary>\n        /// <value>\n        /// The size of the token cleanup batch.\n        /// </value>\n        public int TokenCleanupBatchSize { get; set; } = 100;\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Options/TableConfiguration.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework.Options\n{\n    /// <summary>\n    /// Class to control a table's name and schema.\n    /// </summary>\n    public class TableConfiguration\n    {\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"TableConfiguration\"/> class.\n        /// </summary>\n        /// <param name=\"name\">The name.</param>\n        public TableConfiguration(string name)\n        {\n            Name = name;\n        }\n\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"TableConfiguration\"/> class.\n        /// </summary>\n        /// <param name=\"name\">The name.</param>\n        /// <param name=\"schema\">The schema.</param>\n        public TableConfiguration(string name, string schema)\n        {\n            Name = name;\n            Schema = schema;\n        }\n\n        /// <summary>\n        /// Gets or sets the name.\n        /// </summary>\n        /// <value>\n        /// The name.\n        /// </value>\n        public string Name { get; set; }\n\n        /// <summary>\n        /// Gets or sets the schema.\n        /// </summary>\n        /// <value>\n        /// The schema.\n        /// </value>\n        public string Schema { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Properties/AssemblyInfo.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Runtime.CompilerServices;\n\n[assembly: InternalsVisibleTo(\"IdentityServer8.EntityFramework.UnitTests, PublicKey = 002400000480000094000000060200000024000052534131000400000100010057b24455efc2a317afb0644a2169c05644e439985c42cf4eb98706779651801add1da073da8b5e253e8d4335d59b3197bb941ebe943c63f7efbc3005c428f0d69b809e86bdc828fa431fae4b71005f26b52a26a3ee5cf0f6fdf744d4534a7a503683123f58e1082828b018245d2e40d8542f72a623c01490d73a5d3ff94a88c5\")]\n[assembly: InternalsVisibleTo(\"IdentityServer8.EntityFramework.IntegrationTests, PublicKey = 002400000480000094000000060200000024000052534131000400000100010057b24455efc2a317afb0644a2169c05644e439985c42cf4eb98706779651801add1da073da8b5e253e8d4335d59b3197bb941ebe943c63f7efbc3005c428f0d69b809e86bdc828fa431fae4b71005f26b52a26a3ee5cf0f6fdf744d4534a7a503683123f58e1082828b018245d2e40d8542f72a623c01490d73a5d3ff94a88c5\")]\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Stores/ClientStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\n\nnamespace IdentityServer8.EntityFramework.Stores\n{\n    /// <summary>\n    /// Implementation of IClientStore thats uses EF.\n    /// </summary>\n    /// <seealso cref=\"IdentityServer8.Stores.IClientStore\" />\n    public class ClientStore : IClientStore\n    {\n        /// <summary>\n        /// The DbContext.\n        /// </summary>\n        protected readonly IConfigurationDbContext Context;\n\n        /// <summary>\n        /// The logger.\n        /// </summary>\n        protected readonly ILogger<ClientStore> Logger;\n\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"ClientStore\"/> class.\n        /// </summary>\n        /// <param name=\"context\">The context.</param>\n        /// <param name=\"logger\">The logger.</param>\n        /// <exception cref=\"ArgumentNullException\">context</exception>\n        public ClientStore(IConfigurationDbContext context, ILogger<ClientStore> logger)\n        {\n            Context = context ?? throw new ArgumentNullException(nameof(context));\n            Logger = logger;\n        }\n\n        /// <summary>\n        /// Finds a client by id\n        /// </summary>\n        /// <param name=\"clientId\">The client id</param>\n        /// <returns>\n        /// The client\n        /// </returns>\n        public virtual async Task<Client> FindClientByIdAsync(string clientId)\n        {\n            IQueryable<Entities.Client> baseQuery = Context.Clients\n                .Where(x => x.ClientId == clientId);\n\n            var client = (await baseQuery.ToArrayAsync())\n                .SingleOrDefault(x => x.ClientId == clientId);\n            if (client == null) return null;\n\n            await baseQuery.Include(x => x.AllowedCorsOrigins).SelectMany(c => c.AllowedCorsOrigins).LoadAsync();\n            await baseQuery.Include(x => x.AllowedGrantTypes).SelectMany(c => c.AllowedGrantTypes).LoadAsync();\n            await baseQuery.Include(x => x.AllowedScopes).SelectMany(c => c.AllowedScopes).LoadAsync();\n            await baseQuery.Include(x => x.Claims).SelectMany(c => c.Claims).LoadAsync();\n            await baseQuery.Include(x => x.ClientSecrets).SelectMany(c => c.ClientSecrets).LoadAsync();\n            await baseQuery.Include(x => x.IdentityProviderRestrictions).SelectMany(c => c.IdentityProviderRestrictions).LoadAsync();\n            await baseQuery.Include(x => x.PostLogoutRedirectUris).SelectMany(c => c.PostLogoutRedirectUris).LoadAsync();\n            await baseQuery.Include(x => x.Properties).SelectMany(c => c.Properties).LoadAsync();\n            await baseQuery.Include(x => x.RedirectUris).SelectMany(c => c.RedirectUris).LoadAsync();\n\n            var model = client.ToModel();\n\n            Logger.LogDebug(\"{clientId} found in database: {clientIdFound}\", Ioc.Sanitizer.Log.Sanitize(clientId), model != null);\n\n            return model;\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Stores/DeviceFlowStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Entities;\nusing IdentityServer8.Models;\n\nnamespace IdentityServer8.EntityFramework.Stores\n{\n    /// <summary>\n    /// Implementation of IDeviceFlowStore thats uses EF.\n    /// </summary>\n    /// <seealso cref=\"IdentityServer8.Stores.IDeviceFlowStore\" />\n    public class DeviceFlowStore : IDeviceFlowStore\n    {\n        /// <summary>\n        /// The DbContext.\n        /// </summary>\n        protected readonly IPersistedGrantDbContext Context;\n\n        /// <summary>\n        ///  The serializer.\n        /// </summary>\n        protected readonly IPersistentGrantSerializer Serializer;\n\n        /// <summary>\n        /// The logger.\n        /// </summary>\n        protected readonly ILogger Logger;\n\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"DeviceFlowStore\"/> class.\n        /// </summary>\n        /// <param name=\"context\">The context.</param>\n        /// <param name=\"serializer\">The serializer</param>\n        /// <param name=\"logger\">The logger.</param>\n        public DeviceFlowStore(\n            IPersistedGrantDbContext context, \n            IPersistentGrantSerializer serializer, \n            ILogger<DeviceFlowStore> logger)\n        {\n            Context = context;\n            Serializer = serializer;\n            Logger = logger;\n        }\n\n        /// <summary>\n        /// Stores the device authorization request.\n        /// </summary>\n        /// <param name=\"deviceCode\">The device code.</param>\n        /// <param name=\"userCode\">The user code.</param>\n        /// <param name=\"data\">The data.</param>\n        /// <returns></returns>\n        public virtual async Task StoreDeviceAuthorizationAsync(string deviceCode, string userCode, DeviceCode data)\n        {\n            Context.DeviceFlowCodes.Add(ToEntity(data, deviceCode, userCode));\n\n            await Context.SaveChangesAsync();\n        }\n\n        /// <summary>\n        /// Finds device authorization by user code.\n        /// </summary>\n        /// <param name=\"userCode\">The user code.</param>\n        /// <returns></returns>\n        public virtual async Task<DeviceCode> FindByUserCodeAsync(string userCode)\n        {\n            var deviceFlowCodes = (await Context.DeviceFlowCodes.AsNoTracking().Where(x => x.UserCode == userCode).ToArrayAsync())\n                .SingleOrDefault(x => x.UserCode == userCode);\n            var model = ToModel(deviceFlowCodes?.Data);\n\n            Logger.LogDebug(\"{userCode} found in database: {userCodeFound}\", userCode, model != null);\n\n            return model;\n        }\n\n        /// <summary>\n        /// Finds device authorization by device code.\n        /// </summary>\n        /// <param name=\"deviceCode\">The device code.</param>\n        /// <returns></returns>\n        public virtual async Task<DeviceCode> FindByDeviceCodeAsync(string deviceCode)\n        {\n            var deviceFlowCodes = (await Context.DeviceFlowCodes.AsNoTracking().Where(x => x.DeviceCode == deviceCode).ToArrayAsync())\n                .SingleOrDefault(x => x.DeviceCode == deviceCode);\n            var model = ToModel(deviceFlowCodes?.Data);\n\n            Logger.LogDebug(\"{deviceCode} found in database: {deviceCodeFound}\", deviceCode, model != null);\n\n            return model;\n        }\n\n        /// <summary>\n        /// Updates device authorization, searching by user code.\n        /// </summary>\n        /// <param name=\"userCode\">The user code.</param>\n        /// <param name=\"data\">The data.</param>\n        /// <returns></returns>\n        public virtual async Task UpdateByUserCodeAsync(string userCode, DeviceCode data)\n        {\n            var existing = (await Context.DeviceFlowCodes.Where(x => x.UserCode == userCode).ToArrayAsync())\n                .SingleOrDefault(x => x.UserCode == userCode);\n            if (existing == null)\n            {\n                Logger.LogError(\"{userCode} not found in database\", userCode);\n                throw new InvalidOperationException(\"Could not update device code\");\n            }\n\n            var entity = ToEntity(data, existing.DeviceCode, userCode);\n            Logger.LogDebug(\"{userCode} found in database\", userCode);\n\n            existing.SubjectId = data.Subject?.FindFirst(JwtClaimTypes.Subject).Value;\n            existing.Data = entity.Data;\n\n            try\n            {\n                await Context.SaveChangesAsync();\n            }\n            catch (DbUpdateConcurrencyException ex)\n            {\n                Logger.LogWarning(\"exception updating {userCode} user code in database: {error}\", userCode, ex.Message);\n            }\n        }\n\n        /// <summary>\n        /// Removes the device authorization, searching by device code.\n        /// </summary>\n        /// <param name=\"deviceCode\">The device code.</param>\n        /// <returns></returns>\n        public virtual async Task RemoveByDeviceCodeAsync(string deviceCode)\n        {\n            var deviceFlowCodes = (await Context.DeviceFlowCodes.Where(x => x.DeviceCode == deviceCode).ToArrayAsync())\n                .SingleOrDefault(x => x.DeviceCode == deviceCode);\n\n            if(deviceFlowCodes != null)\n            {\n                Logger.LogDebug(\"removing {deviceCode} device code from database\", deviceCode);\n\n                Context.DeviceFlowCodes.Remove(deviceFlowCodes);\n\n                try\n                {\n                    await Context.SaveChangesAsync();\n                }\n                catch (DbUpdateConcurrencyException ex)\n                {\n                    Logger.LogInformation(\"exception removing {deviceCode} device code from database: {error}\", deviceCode, ex.Message);\n                }\n            }\n            else\n            {\n                Logger.LogDebug(\"no {deviceCode} device code found in database\", deviceCode);\n            }\n        }\n\n        /// <summary>\n        /// Converts a model to an entity.\n        /// </summary>\n        /// <param name=\"model\"></param>\n        /// <param name=\"deviceCode\"></param>\n        /// <param name=\"userCode\"></param>\n        /// <returns></returns>\n        protected DeviceFlowCodes ToEntity(DeviceCode model, string deviceCode, string userCode)\n        {\n            if (model == null || deviceCode == null || userCode == null) return null;\n\n            return new DeviceFlowCodes\n            {\n                DeviceCode = deviceCode,\n                UserCode = userCode,\n                ClientId = model.ClientId,\n                SubjectId = model.Subject?.FindFirst(JwtClaimTypes.Subject).Value,\n                CreationTime = model.CreationTime,\n                Expiration = model.CreationTime.AddSeconds(model.Lifetime),\n                Data = Serializer.Serialize(model)\n            };\n        }\n\n        /// <summary>\n        /// Converts a serialized DeviceCode to a model.\n        /// </summary>\n        /// <param name=\"entity\"></param>\n        /// <returns></returns>\n        protected DeviceCode ToModel(string entity)\n        {\n            if (entity == null) return null;\n\n            return Serializer.Deserialize<DeviceCode>(entity);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Stores/PersistedGrantStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\n\nnamespace IdentityServer8.EntityFramework.Stores\n{\n    /// <summary>\n    /// Implementation of IPersistedGrantStore thats uses EF.\n    /// </summary>\n    /// <seealso cref=\"IdentityServer8.Stores.IPersistedGrantStore\" />\n    public class PersistedGrantStore : IPersistedGrantStore\n    {\n        /// <summary>\n        /// The DbContext.\n        /// </summary>\n        protected readonly IPersistedGrantDbContext Context;\n\n        /// <summary>\n        /// The logger.\n        /// </summary>\n        protected readonly ILogger Logger;\n\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"PersistedGrantStore\"/> class.\n        /// </summary>\n        /// <param name=\"context\">The context.</param>\n        /// <param name=\"logger\">The logger.</param>\n        public PersistedGrantStore(IPersistedGrantDbContext context, ILogger<PersistedGrantStore> logger)\n        {\n            Context = context;\n            Logger = logger;\n        }\n\n        /// <inheritdoc/>\n        public virtual async Task StoreAsync(PersistedGrant token)\n        {\n            var existing = (await Context.PersistedGrants.Where(x => x.Key == token.Key).ToArrayAsync())\n                .SingleOrDefault(x => x.Key == token.Key);\n            if (existing == null)\n            {\n                Logger.LogDebug(\"{persistedGrantKey} not found in database\", token.Key);\n\n                var persistedGrant = token.ToEntity();\n                Context.PersistedGrants.Add(persistedGrant);\n            }\n            else\n            {\n                Logger.LogDebug(\"{persistedGrantKey} found in database\", token.Key);\n\n                token.UpdateEntity(existing);\n            }\n\n            try\n            {\n                await Context.SaveChangesAsync();\n            }\n            catch (DbUpdateConcurrencyException ex)\n            {\n                Logger.LogWarning(\"exception updating {persistedGrantKey} persisted grant in database: {error}\", token.Key, ex.Message);\n            }\n        }\n\n        /// <inheritdoc/>\n        public virtual async Task<PersistedGrant> GetAsync(string key)\n        {\n            var persistedGrant = (await Context.PersistedGrants.AsNoTracking().Where(x => x.Key == key).ToArrayAsync())\n                .SingleOrDefault(x => x.Key == key);\n            var model = persistedGrant?.ToModel();\n\n            Logger.LogDebug(\"{persistedGrantKey} found in database: {persistedGrantKeyFound}\", key, model != null);\n\n            return model;\n        }\n\n        /// <inheritdoc/>\n        public async Task<IEnumerable<PersistedGrant>> GetAllAsync(PersistedGrantFilter filter)\n        {\n            filter.Validate();\n\n            var persistedGrants = await Filter(Context.PersistedGrants.AsQueryable(), filter).ToArrayAsync();\n            persistedGrants = Filter(persistedGrants.AsQueryable(), filter).ToArray();\n            \n            var model = persistedGrants.Select(x => x.ToModel());\n\n            Logger.LogDebug(\"{persistedGrantCount} persisted grants found for {@filter}\", persistedGrants.Length, filter);\n\n            return model;\n        }\n\n        /// <inheritdoc/>\n        public virtual async Task RemoveAsync(string key)\n        {\n            var persistedGrant = (await Context.PersistedGrants.Where(x => x.Key == key).ToArrayAsync())\n                .SingleOrDefault(x => x.Key == key);\n            if (persistedGrant!= null)\n            {\n                Logger.LogDebug(\"removing {persistedGrantKey} persisted grant from database\", key);\n\n                Context.PersistedGrants.Remove(persistedGrant);\n\n                try\n                {\n                    await Context.SaveChangesAsync();\n                }\n                catch(DbUpdateConcurrencyException ex)\n                {\n                    Logger.LogInformation(\"exception removing {persistedGrantKey} persisted grant from database: {error}\", key, ex.Message);\n                }\n            }\n            else\n            {\n                Logger.LogDebug(\"no {persistedGrantKey} persisted grant found in database\", key);\n            }\n        }\n\n        /// <inheritdoc/>\n        public async Task RemoveAllAsync(PersistedGrantFilter filter)\n        {\n            filter.Validate();\n\n            var persistedGrants = await Filter(Context.PersistedGrants.AsQueryable(), filter).ToArrayAsync();\n            persistedGrants = Filter(persistedGrants.AsQueryable(), filter).ToArray();\n\n            Logger.LogDebug(\"removing {persistedGrantCount} persisted grants from database for {@filter}\", persistedGrants.Length, filter);\n\n            Context.PersistedGrants.RemoveRange(persistedGrants);\n\n            try\n            {\n                await Context.SaveChangesAsync();\n            }\n            catch (DbUpdateConcurrencyException ex)\n            {\n                Logger.LogInformation(\"removing {persistedGrantCount} persisted grants from database for subject {@filter}: {error}\", persistedGrants.Length, filter, ex.Message);\n            }\n        }\n\n\n        private IQueryable<Entities.PersistedGrant> Filter(IQueryable<Entities.PersistedGrant> query, PersistedGrantFilter filter)\n        {\n            if (!String.IsNullOrWhiteSpace(filter.ClientId))\n            {\n                query = query.Where(x => x.ClientId == filter.ClientId);\n            }\n            if (!String.IsNullOrWhiteSpace(filter.SessionId))\n            {\n                query = query.Where(x => x.SessionId == filter.SessionId);\n            }\n            if (!String.IsNullOrWhiteSpace(filter.SubjectId))\n            {\n                query = query.Where(x => x.SubjectId == filter.SubjectId);\n            }\n            if (!String.IsNullOrWhiteSpace(filter.Type))\n            {\n                query = query.Where(x => x.Type == filter.Type);\n            }\n\n            return query;\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/Stores/ResourceStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\n\nnamespace IdentityServer8.EntityFramework.Stores\n{\n    /// <summary>\n    /// Implementation of IResourceStore thats uses EF.\n    /// </summary>\n    /// <seealso cref=\"IdentityServer8.Stores.IResourceStore\" />\n    public class ResourceStore : IResourceStore\n    {\n        /// <summary>\n        /// The DbContext.\n        /// </summary>\n        protected readonly IConfigurationDbContext Context;\n        \n        /// <summary>\n        /// The logger.\n        /// </summary>\n        protected readonly ILogger<ResourceStore> Logger;\n\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"ResourceStore\"/> class.\n        /// </summary>\n        /// <param name=\"context\">The context.</param>\n        /// <param name=\"logger\">The logger.</param>\n        /// <exception cref=\"ArgumentNullException\">context</exception>\n        public ResourceStore(IConfigurationDbContext context, ILogger<ResourceStore> logger)\n        {\n            Context = context ?? throw new ArgumentNullException(nameof(context));\n            Logger = logger;\n        }\n\n        /// <summary>\n        /// Finds the API resources by name.\n        /// </summary>\n        /// <param name=\"apiResourceNames\">The names.</param>\n        /// <returns></returns>\n        public virtual async Task<IEnumerable<ApiResource>> FindApiResourcesByNameAsync(IEnumerable<string> apiResourceNames)\n        {\n            if (apiResourceNames == null) throw new ArgumentNullException(nameof(apiResourceNames));\n\n            var query =\n                from apiResource in Context.ApiResources\n                where apiResourceNames.Contains(apiResource.Name)\n                select apiResource;\n            \n            var apis = query\n                .Include(x => x.Secrets)\n                .Include(x => x.Scopes)\n                .Include(x => x.UserClaims)\n                .Include(x => x.Properties)\n                .AsNoTracking();\n\n            var result = (await apis.ToArrayAsync())\n                .Where(x => apiResourceNames.Contains(x.Name))\n                .Select(x => x.ToModel()).ToArray();\n\n            if (result.Any())\n            {\n                Logger.LogDebug(\"Found {apis} API resource in database\", result.Select(x => x.Name));\n            }\n            else\n            {\n                Logger.LogDebug(\"Did not find {apis} API resource in database\", apiResourceNames);\n            }\n\n            return result;\n        }\n\n        /// <summary>\n        /// Gets API resources by scope name.\n        /// </summary>\n        /// <param name=\"scopeNames\"></param>\n        /// <returns></returns>\n        public virtual async Task<IEnumerable<ApiResource>> FindApiResourcesByScopeNameAsync(IEnumerable<string> scopeNames)\n        {\n            var names = scopeNames.ToArray();\n\n            var query =\n                from api in Context.ApiResources\n                where api.Scopes.Where(x => names.Contains(x.Scope)).Any()\n                select api;\n\n            var apis = query\n                .Include(x => x.Secrets)\n                .Include(x => x.Scopes)\n                .Include(x => x.UserClaims)\n                .Include(x => x.Properties)\n                .AsNoTracking();\n\n            var results = (await apis.ToArrayAsync())\n                .Where(api => api.Scopes.Any(x => names.Contains(x.Scope)));\n            var models = results.Select(x => x.ToModel()).ToArray();\n\n            Logger.LogDebug(\"Found {apis} API resources in database\", models.Select(x => x.Name));\n\n            return models;\n        }\n\n        /// <summary>\n        /// Gets identity resources by scope name.\n        /// </summary>\n        /// <param name=\"scopeNames\"></param>\n        /// <returns></returns>\n        public virtual async Task<IEnumerable<IdentityResource>> FindIdentityResourcesByScopeNameAsync(IEnumerable<string> scopeNames)\n        {\n            var scopes = scopeNames.ToArray();\n\n            var query =\n                from identityResource in Context.IdentityResources\n                where scopes.Contains(identityResource.Name)\n                select identityResource;\n\n            var resources = query\n                .Include(x => x.UserClaims)\n                .Include(x => x.Properties)\n                .AsNoTracking();\n\n            var results = (await resources.ToArrayAsync())\n                .Where(x => scopes.Contains(x.Name));\n\n            Logger.LogDebug(\"Found {scopes} identity scopes in database\", results.Select(x => x.Name));\n\n            return results.Select(x => x.ToModel()).ToArray();\n        }\n\n        /// <summary>\n        /// Gets scopes by scope name.\n        /// </summary>\n        /// <param name=\"scopeNames\"></param>\n        /// <returns></returns>\n        public virtual async Task<IEnumerable<ApiScope>> FindApiScopesByNameAsync(IEnumerable<string> scopeNames)\n        {\n            var scopes = scopeNames.ToArray();\n\n            var query =\n                from scope in Context.ApiScopes\n                where scopes.Contains(scope.Name)\n                select scope;\n\n            var resources = query\n                .Include(x => x.UserClaims)\n                .Include(x => x.Properties)\n                .AsNoTracking();\n\n            var results = (await resources.ToArrayAsync())\n                .Where(x => scopes.Contains(x.Name));\n\n            Logger.LogDebug(\"Found {scopes} scopes in database\", results.Select(x => x.Name));\n\n            return results.Select(x => x.ToModel()).ToArray();\n        }\n\n        /// <summary>\n        /// Gets all resources.\n        /// </summary>\n        /// <returns></returns>\n        public virtual async Task<Resources> GetAllResourcesAsync()\n        {\n            var identity = Context.IdentityResources\n              .Include(x => x.UserClaims)\n              .Include(x => x.Properties);\n\n            var apis = Context.ApiResources\n                .Include(x => x.Secrets)\n                .Include(x => x.Scopes)\n                .Include(x => x.UserClaims)\n                .Include(x => x.Properties)\n                .AsNoTracking();\n            \n            var scopes = Context.ApiScopes\n                .Include(x => x.UserClaims)\n                .Include(x => x.Properties)\n                .AsNoTracking();\n\n            var result = new Resources(\n                (await identity.ToArrayAsync()).Select(x => x.ToModel()),\n                (await apis.ToArrayAsync()).Select(x => x.ToModel()),\n                (await scopes.ToArrayAsync()).Select(x => x.ToModel())\n            );\n\n            Logger.LogDebug(\"Found {scopes} as all scopes, and {apis} as API resources\", \n                result.IdentityResources.Select(x=>x.Name).Union(result.ApiScopes.Select(x=>x.Name)),\n                result.ApiResources.Select(x=>x.Name));\n\n            return result;\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/TokenCleanup/IOperationalStoreNotification.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Entities;\n\nnamespace IdentityServer8.EntityFramework\n{\n    /// <summary>\n    /// Interface to model notifications from the TokenCleanup feature.\n    /// </summary>\n    public interface IOperationalStoreNotification\n    {\n        /// <summary>\n        /// Notification for persisted grants being removed.\n        /// </summary>\n        /// <param name=\"persistedGrants\"></param>\n        /// <returns></returns>\n        Task PersistedGrantsRemovedAsync(IEnumerable<PersistedGrant> persistedGrants);\n\n        /// <summary>\n        /// Notification for device codes being removed.\n        /// </summary>\n        /// <param name=\"deviceCodes\"></param>\n        /// <returns></returns>\n        Task DeviceCodesRemovedAsync(IEnumerable<DeviceFlowCodes> deviceCodes);\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/src/TokenCleanup/TokenCleanupService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.EntityFramework\n{\n    /// <summary>\n    /// Helper to cleanup stale persisted grants and device codes.\n    /// </summary>\n    public class TokenCleanupService\n    {\n        private readonly OperationalStoreOptions _options;\n        private readonly IPersistedGrantDbContext _persistedGrantDbContext;\n        private readonly IOperationalStoreNotification _operationalStoreNotification;\n        private readonly ILogger<TokenCleanupService> _logger;\n\n        /// <summary>\n        /// Constructor for TokenCleanupService.\n        /// </summary>\n        /// <param name=\"options\"></param>\n        /// <param name=\"persistedGrantDbContext\"></param>\n        /// <param name=\"operationalStoreNotification\"></param>\n        /// <param name=\"logger\"></param>\n        public TokenCleanupService(\n            OperationalStoreOptions options,\n            IPersistedGrantDbContext persistedGrantDbContext, \n            ILogger<TokenCleanupService> logger,\n            IOperationalStoreNotification operationalStoreNotification = null)\n        {\n            _options = options ?? throw new ArgumentNullException(nameof(options));\n            if (_options.TokenCleanupBatchSize < 1) throw new ArgumentException(\"Token cleanup batch size interval must be at least 1\");\n\n            _persistedGrantDbContext = persistedGrantDbContext ?? throw new ArgumentNullException(nameof(persistedGrantDbContext));\n            _logger = logger ?? throw new ArgumentNullException(nameof(logger));\n\n            _operationalStoreNotification = operationalStoreNotification;\n        }\n\n        /// <summary>\n        /// Method to clear expired persisted grants.\n        /// </summary>\n        /// <returns></returns>\n        public async Task RemoveExpiredGrantsAsync()\n        {\n            try\n            {\n                _logger.LogTrace(\"Querying for expired grants to remove\");\n\n                await RemoveGrantsAsync();\n                await RemoveDeviceCodesAsync();\n            }\n            catch (Exception ex)\n            {\n                _logger.LogError(\"Exception removing expired grants: {exception}\", ex.Message);\n            }\n        }\n\n        /// <summary>\n        /// Removes the stale persisted grants.\n        /// </summary>\n        /// <returns></returns>\n        protected virtual async Task RemoveGrantsAsync()\n        {\n            var found = Int32.MaxValue;\n            \n            while (found >= _options.TokenCleanupBatchSize)\n            {\n                var expiredGrants = await _persistedGrantDbContext.PersistedGrants\n                    .Where(x => x.Expiration < DateTime.UtcNow)\n                    .OrderBy(x => x.Expiration)\n                    .Take(_options.TokenCleanupBatchSize)\n                    .ToArrayAsync();\n\n                found = expiredGrants.Length;\n                _logger.LogInformation(\"Removing {grantCount} grants\", found);\n\n                if (found > 0)\n                {\n                    _persistedGrantDbContext.PersistedGrants.RemoveRange(expiredGrants);\n                    await SaveChangesAsync();\n\n                    if (_operationalStoreNotification != null)\n                    {\n                        await _operationalStoreNotification.PersistedGrantsRemovedAsync(expiredGrants);\n                    }\n                }\n            }\n        }\n\n\n        /// <summary>\n        /// Removes the stale device codes.\n        /// </summary>\n        /// <returns></returns>\n        protected virtual async Task RemoveDeviceCodesAsync()\n        {\n            var found = Int32.MaxValue;\n\n            while (found >= _options.TokenCleanupBatchSize)\n            {\n                var expiredCodes = await _persistedGrantDbContext.DeviceFlowCodes\n                    .Where(x => x.Expiration < DateTime.UtcNow)\n                    .OrderBy(x => x.Expiration)\n                    .Take(_options.TokenCleanupBatchSize)\n                    .ToArrayAsync();\n\n                found = expiredCodes.Length;\n                _logger.LogInformation(\"Removing {deviceCodeCount} device flow codes\", found);\n\n                if (found > 0)\n                {\n                    _persistedGrantDbContext.DeviceFlowCodes.RemoveRange(expiredCodes);\n                    await SaveChangesAsync();\n\n                    if (_operationalStoreNotification != null)\n                    {\n                        await _operationalStoreNotification.DeviceCodesRemovedAsync(expiredCodes);\n                    }\n                }\n            }\n        }\n\n        private async Task SaveChangesAsync()\n        {\n            var count = 3;\n\n            while (count > 0)\n            {\n                try\n                {\n                    await _persistedGrantDbContext.SaveChangesAsync();\n                    return;\n                }\n                catch (DbUpdateConcurrencyException ex)\n                {\n                    count--;\n\n                    // we get this if/when someone else already deleted the records\n                    // we want to essentially ignore this, and keep working\n                    _logger.LogDebug(\"Concurrency exception removing expired grants: {exception}\", ex.Message);\n\n                    foreach (var entry in ex.Entries)\n                    {\n                        // mark this entry as not attached anymore so we don't try to re-delete\n                        entry.State = EntityState.Detached;\n                    }\n                }\n            }\n\n            _logger.LogDebug(\"Too many concurrency exceptions. Exiting.\");\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/DatabaseProviderBuilder.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.EntityFrameworkCore;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests;\n\n/// <summary>\n/// Helper methods to initialize DbContextOptions for the specified database provider and context.\n/// </summary>\npublic class DatabaseProviderBuilder\n{\n    public static DbContextOptions<T> BuildInMemory<T>(string name) where T : DbContext\n    {\n        var builder = new DbContextOptionsBuilder<T>();\n        builder.UseInMemoryDatabase(name);\n        return builder.Options;\n    }\n\n    public static DbContextOptions<T> BuildSqlite<T>(string name) where T : DbContext\n    {\n        var builder = new DbContextOptionsBuilder<T>();\n        builder.UseSqlite($\"Filename=./Test.IdentityServer8.EntityFramework-3.1.0.{name}.db\");\n        return builder.Options;\n    }\n\n    public static DbContextOptions<T> BuildLocalDb<T>(string name) where T : DbContext\n    {\n        var builder = new DbContextOptionsBuilder<T>();\n        builder.UseSqlServer(\n            $@\"Data Source=(LocalDb)\\MSSQLLocalDB;database=Test.IdentityServer8.EntityFramework-3.1.0.{name};trusted_connection=yes;\");\n        return builder.Options;\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/DatabaseProviderFixture.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.EntityFrameworkCore;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests;\n\n/// <summary>\n/// xUnit ClassFixture for creating and deleting integration test databases.\n/// </summary>\n/// <typeparam name=\"T\">DbContext of Type T</typeparam>\npublic class DatabaseProviderFixture<T> : IDisposable where T : DbContext\n{\n    public object StoreOptions;\n    public List<DbContextOptions<T>> Options;\n\n    public void Dispose()\n    {\n        if (Options != null) // null check since fixtures are created even when tests are skipped\n        {\n            foreach (var option in Options.ToList())\n            {\n                using (var context = (T)Activator.CreateInstance(typeof(T), option, StoreOptions))\n                {\n                    context.Database.EnsureDeleted();\n                }\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/DbContexts/ClientDbContextTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.DbContexts;\nusing Microsoft.EntityFrameworkCore;\nusing System.Linq;\nusing IdentityServer8.EntityFramework.Entities;\nusing IdentityServer8.EntityFramework.Options;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests.DbContexts;\n\npublic class ClientDbContextTests : IntegrationTest<ClientDbContextTests, ConfigurationDbContext, ConfigurationStoreOptions>\n{\n    public ClientDbContextTests(DatabaseProviderFixture<ConfigurationDbContext> fixture) : base(fixture)\n    {\n        foreach (var options in TestDatabaseProviders.SelectMany(x => x.Select(y => (DbContextOptions<ConfigurationDbContext>)y)).ToList())\n        {\n            using (var context = new ConfigurationDbContext(options, StoreOptions))\n                context.Database.EnsureCreated();\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public void CanAddAndDeleteClientScopes(DbContextOptions<ConfigurationDbContext> options)\n    {\n        using (var db = new ConfigurationDbContext(options, StoreOptions))\n        {\n            db.Clients.Add(new Client\n            {\n                ClientId = \"test-client-scopes\",\n                ClientName = \"Test Client\"\n            });\n\n            db.SaveChanges();\n        }\n\n        using (var db = new ConfigurationDbContext(options, StoreOptions))\n        {\n            // explicit include due to lack of EF Core lazy loading\n            var client = db.Clients.Include(x => x.AllowedScopes).First();\n\n            client.AllowedScopes.Add(new ClientScope\n            {\n                Scope = \"test\"\n            });\n\n            db.SaveChanges();\n        }\n\n        using (var db = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var client = db.Clients.Include(x => x.AllowedScopes).First();\n            var scope = client.AllowedScopes.First();\n\n            client.AllowedScopes.Remove(scope);\n\n            db.SaveChanges();\n        }\n\n        using (var db = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var client = db.Clients.Include(x => x.AllowedScopes).First();\n\n            Assert.Empty(client.AllowedScopes);\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public void CanAddAndDeleteClientRedirectUri(DbContextOptions<ConfigurationDbContext> options)\n    {\n        using (var db = new ConfigurationDbContext(options, StoreOptions))\n        {\n            db.Clients.Add(new Client\n            {\n                ClientId = \"test-client\",\n                ClientName = \"Test Client\"\n            });\n\n            db.SaveChanges();\n        }\n\n        using (var db = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var client = db.Clients.Include(x => x.RedirectUris).First();\n\n            client.RedirectUris.Add(new ClientRedirectUri\n            {\n                RedirectUri = \"https://redirect-uri-1\"\n            });\n\n            db.SaveChanges();\n        }\n\n        using (var db = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var client = db.Clients.Include(x => x.RedirectUris).First();\n            var redirectUri = client.RedirectUris.First();\n\n            client.RedirectUris.Remove(redirectUri);\n\n            db.SaveChanges();\n        }\n\n        using (var db = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var client = db.Clients.Include(x => x.RedirectUris).First();\n\n            Assert.Empty(client.RedirectUris);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/FakeLogger.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.Extensions.Logging;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests;\n\npublic class FakeLogger<T> : FakeLogger, ILogger<T>\n{\n    public static ILogger<T> Create()\n    {\n        return new FakeLogger<T>();\n    }\n}\n\npublic class FakeLogger : ILogger, IDisposable\n{\n    public IDisposable BeginScope<TState>(TState state)\n    {\n        return this;\n    }\n\n    public void Dispose()\n    {\n    }\n\n    public bool IsEnabled(LogLevel logLevel)\n    {\n        return false;\n    }\n\n    public void Log<TState>(LogLevel logLevel, EventId eventId, TState state, Exception exception, Func<TState, Exception, string> formatter)\n    {\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/IdentityServer8.EntityFramework.IntegrationTests.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n  <PropertyGroup>\n\n    <AssemblyOriginatorKeyFile>../../../../key.snk</AssemblyOriginatorKeyFile>\n    <SignAssembly>true</SignAssembly>\n    <PublicSign Condition=\"'$(OS)' != 'Windows_NT'\">true</PublicSign>\n  </PropertyGroup>\n\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\..\\..\\IdentityServer8\\src\\IdentityServer8.csproj\" />\n    <ProjectReference Include=\"..\\..\\..\\Storage\\src\\IdentityServer8.Storage.csproj\" />\n    <ProjectReference Include=\"..\\..\\src\\IdentityServer8.EntityFramework.Storage.csproj\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.NET.Test.Sdk\" />\n    <PackageReference Include=\"xunit\" />\n    <PackageReference Include=\"xunit.runner.visualstudio\" />\n    <PackageReference Include=\"FluentAssertions\" />\n    <PackageReference Include=\"coverlet.collector\" GeneratePathProperty=\"true\">\n      <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n      <PrivateAssets>all</PrivateAssets>\n    </PackageReference>\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.Sqlite\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.InMemory\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.SqlServer\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/IntegrationTest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.EntityFrameworkCore;\nusing Microsoft.Extensions.Configuration;\nusing System.Runtime.InteropServices;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests;\n\n/// <summary>\n/// Base class for integration tests, responsible for initializing test database providers & an xUnit class fixture\n/// </summary>\n/// <typeparam name=\"TClass\">The type of the class.</typeparam>\n/// <typeparam name=\"TDbContext\">The type of the database context.</typeparam>\n/// <typeparam name=\"TStoreOption\">The type of the store option.</typeparam>\n/// <seealso cref=\"DatabaseProviderFixture{T}\" />\npublic class IntegrationTest<TClass, TDbContext, TStoreOption> : IClassFixture<DatabaseProviderFixture<TDbContext>>\n    where TDbContext : DbContext\n{\n    public static readonly TheoryData<DbContextOptions<TDbContext>> TestDatabaseProviders;\n    protected readonly TStoreOption StoreOptions = Activator.CreateInstance<TStoreOption>();\n\n    static IntegrationTest()\n    {\n        var config = new ConfigurationBuilder()\n            .AddEnvironmentVariables()\n            .Build();\n\n        if (RuntimeInformation.IsOSPlatform(OSPlatform.Windows))\n        {\n            Console.WriteLine($\"Running Local Tests for {typeof(TClass).Name}\");\n\n            TestDatabaseProviders = new TheoryData<DbContextOptions<TDbContext>>\n            {\n                DatabaseProviderBuilder.BuildInMemory<TDbContext>(typeof(TClass).Name),\n                //DatabaseProviderBuilder.BuildSqlite<TDbContext>(typeof(TClass).Name),\n                //DatabaseProviderBuilder.BuildLocalDb<TDbContext>(typeof(TClass).Name)\n            };\n        }\n        else\n        {\n            TestDatabaseProviders = new TheoryData<DbContextOptions<TDbContext>>\n            {\n                DatabaseProviderBuilder.BuildInMemory<TDbContext>(typeof(TClass).Name),\n                DatabaseProviderBuilder.BuildSqlite<TDbContext>(typeof(TClass).Name)\n            };\n            Console.WriteLine(\"Skipping DB integration tests on non-Windows\");\n        }\n    }\n\n    protected IntegrationTest(DatabaseProviderFixture<TDbContext> fixture)\n    {\n        fixture.Options = TestDatabaseProviders.SelectMany(x => x.Select(y => (DbContextOptions<TDbContext>)y)).ToList();\n        fixture.StoreOptions = StoreOptions;\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/Stores/ClientStoreTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityServer8.EntityFramework.DbContexts;\nusing IdentityServer8.EntityFramework.Mappers;\nusing IdentityServer8.EntityFramework.Options;\nusing IdentityServer8.EntityFramework.Stores;\nusing IdentityServer8.Models;\nusing Microsoft.EntityFrameworkCore;\nusing Xunit;\nusing Xunit.Sdk;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests.Stores;\n\npublic class ClientStoreTests : IntegrationTest<ClientStoreTests, ConfigurationDbContext, ConfigurationStoreOptions>\n{\n    public ClientStoreTests(DatabaseProviderFixture<ConfigurationDbContext> fixture) : base(fixture)\n    {\n        foreach (var options in TestDatabaseProviders.SelectMany(x => x.Select(y => (DbContextOptions<ConfigurationDbContext>) y)).ToList())\n        {\n            using (var context = new ConfigurationDbContext(options, StoreOptions))\n            {\n                context.Database.EnsureCreated();\n            }\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindClientByIdAsync_WhenClientDoesNotExist_ExpectNull(DbContextOptions<ConfigurationDbContext> options)\n    {\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ClientStore(context, FakeLogger<ClientStore>.Create());\n            var client = await store.FindClientByIdAsync(Guid.NewGuid().ToString());\n            client.Should().BeNull();\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindClientByIdAsync_WhenClientExists_ExpectClientRetured(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var testClient = new Client\n        {\n            ClientId = \"test_client\",\n            ClientName = \"Test Client\"\n        };\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.Clients.Add(testClient.ToEntity());\n            context.SaveChanges();\n        }\n\n        Client client;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ClientStore(context, FakeLogger<ClientStore>.Create());\n            client = await store.FindClientByIdAsync(testClient.ClientId);\n        }\n\n        client.Should().NotBeNull();\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindClientByIdAsync_WhenClientExistsWithCollections_ExpectClientReturnedCollections(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var testClient = new Client\n        {\n            ClientId = \"properties_test_client\",\n            ClientName = \"Properties Test Client\",\n            AllowedCorsOrigins = {\"https://localhost\"},\n            AllowedGrantTypes = GrantTypes.HybridAndClientCredentials,\n            AllowedScopes = {\"openid\", \"profile\", \"api1\"},\n            Claims = {new ClientClaim(\"test\", \"value\")},\n            ClientSecrets = {new Secret(\"secret\".Sha256())},\n            IdentityProviderRestrictions = {\"AD\"},\n            PostLogoutRedirectUris = {\"https://locahost/signout-callback\"},\n            Properties = {{\"foo1\", \"bar1\"}, {\"foo2\", \"bar2\"},},\n            RedirectUris = {\"https://locahost/signin\"}\n        };\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.Clients.Add(testClient.ToEntity());\n            context.SaveChanges();\n        }\n\n        Client client;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ClientStore(context, FakeLogger<ClientStore>.Create());\n            client = await store.FindClientByIdAsync(testClient.ClientId);\n        }\n\n        client.Should().BeEquivalentTo(testClient);\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindClientByIdAsync_WhenClientsExistWithManyCollections_ExpectClientReturnedInUnderFiveSeconds(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var testClient = new Client\n        {\n            ClientId = \"test_client_with_uris\",\n            ClientName = \"Test client with URIs\",\n            AllowedScopes = {\"openid\", \"profile\", \"api1\"},\n            AllowedGrantTypes = GrantTypes.CodeAndClientCredentials\n        };\n\n        for (int i = 0; i < 50; i++)\n        {\n            testClient.RedirectUris.Add($\"https://localhost/{i}\");\n            testClient.PostLogoutRedirectUris.Add($\"https://localhost/{i}\");\n            testClient.AllowedCorsOrigins.Add($\"https://localhost:{i}\");\n        }\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.Clients.Add(testClient.ToEntity());\n\n            for (int i = 0; i < 50; i++)\n            {\n                context.Clients.Add(new Client\n                {\n                    ClientId = testClient.ClientId + i,\n                    ClientName = testClient.ClientName,\n                    AllowedScopes = testClient.AllowedScopes,\n                    AllowedGrantTypes = testClient.AllowedGrantTypes,\n                    RedirectUris = testClient.RedirectUris,\n                    PostLogoutRedirectUris = testClient.PostLogoutRedirectUris,\n                    AllowedCorsOrigins = testClient.AllowedCorsOrigins,\n                }.ToEntity());\n            }\n\n            context.SaveChanges();\n        }\n        \n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ClientStore(context, FakeLogger<ClientStore>.Create());\n\n            const int timeout = 5000;\n            var task = Task.Run(() => store.FindClientByIdAsync(testClient.ClientId));\n\n            if (await Task.WhenAny(task, Task.Delay(timeout)) == task)\n            {\n                var client = await task;\n                client.Should().BeEquivalentTo(testClient);\n            }\n            else\n            {\n                throw new TestTimeoutException(timeout);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/Stores/DeviceFlowStoreTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer8.EntityFramework.DbContexts;\nusing IdentityServer8.EntityFramework.Entities;\nusing IdentityServer8.EntityFramework.Options;\nusing IdentityServer8.EntityFramework.Stores;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores.Serialization;\nusing Microsoft.EntityFrameworkCore;\nusing Microsoft.EntityFrameworkCore.InMemory.Infrastructure.Internal;\nusing System.Security.Claims;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests.Stores;\n\npublic class DeviceFlowStoreTests : IntegrationTest<DeviceFlowStoreTests, PersistedGrantDbContext, OperationalStoreOptions>\n{\n    private readonly IPersistentGrantSerializer serializer = new PersistentGrantSerializer();\n\n    public DeviceFlowStoreTests(DatabaseProviderFixture<PersistedGrantDbContext> fixture) : base(fixture)\n    {\n        foreach (var options in TestDatabaseProviders.SelectMany(x => x.Select(y => (DbContextOptions<PersistedGrantDbContext>)y)).ToList())\n        {\n            using (var context = new PersistedGrantDbContext(options, StoreOptions))\n                context.Database.EnsureCreated();\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task StoreDeviceAuthorizationAsync_WhenSuccessful_ExpectDeviceCodeAndUserCodeStored(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var deviceCode = Guid.NewGuid().ToString();\n        var userCode = Guid.NewGuid().ToString();\n        var data = new DeviceCode\n        {\n            ClientId = Guid.NewGuid().ToString(),\n            CreationTime = DateTime.UtcNow,\n            Lifetime = 300\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n            await store.StoreDeviceAuthorizationAsync(deviceCode, userCode, data);\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var foundDeviceFlowCodes = context.DeviceFlowCodes.FirstOrDefault(x => x.DeviceCode == deviceCode);\n\n            foundDeviceFlowCodes.Should().NotBeNull();\n            foundDeviceFlowCodes?.DeviceCode.Should().Be(deviceCode);\n            foundDeviceFlowCodes?.UserCode.Should().Be(userCode);\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task StoreDeviceAuthorizationAsync_WhenSuccessful_ExpectDataStored(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var deviceCode = Guid.NewGuid().ToString();\n        var userCode = Guid.NewGuid().ToString();\n        var data = new DeviceCode\n        {\n            ClientId = Guid.NewGuid().ToString(),\n            CreationTime = DateTime.UtcNow,\n            Lifetime = 300\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n            await store.StoreDeviceAuthorizationAsync(deviceCode, userCode, data);\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var foundDeviceFlowCodes = context.DeviceFlowCodes.FirstOrDefault(x => x.DeviceCode == deviceCode);\n\n            foundDeviceFlowCodes.Should().NotBeNull();\n            var deserializedData = new PersistentGrantSerializer().Deserialize<DeviceCode>(foundDeviceFlowCodes?.Data);\n\n            deserializedData.CreationTime.Should().BeCloseTo(data.CreationTime, TimeSpan.FromMilliseconds(100));\n            deserializedData.ClientId.Should().Be(data.ClientId);\n            deserializedData.Lifetime.Should().Be(data.Lifetime);\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task StoreDeviceAuthorizationAsync_WhenUserCodeAlreadyExists_ExpectException(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var existingUserCode = $\"user_{Guid.NewGuid().ToString()}\";\n        var deviceCodeData = new DeviceCode\n        {\n            ClientId = \"device_flow\",\n            RequestedScopes = new[] { \"openid\", \"api1\" },\n            CreationTime = new DateTime(2018, 10, 19, 16, 14, 29),\n            Lifetime = 300,\n            IsOpenId = true,\n            Subject = new ClaimsPrincipal(new ClaimsIdentity(\n                new List<Claim> { new Claim(JwtClaimTypes.Subject, $\"sub_{Guid.NewGuid().ToString()}\") }))\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.Add(new DeviceFlowCodes\n            {\n                DeviceCode = $\"device_{Guid.NewGuid().ToString()}\",\n                UserCode = existingUserCode,\n                ClientId = deviceCodeData.ClientId,\n                SubjectId = deviceCodeData.Subject.FindFirst(JwtClaimTypes.Subject).Value,\n                CreationTime = deviceCodeData.CreationTime,\n                Expiration = deviceCodeData.CreationTime.AddSeconds(deviceCodeData.Lifetime),\n                Data = serializer.Serialize(deviceCodeData)\n            });\n            context.SaveChanges();\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n\n            // skip odd behaviour of in-memory provider\n            if (options.Extensions.All(x => x.GetType() != typeof(InMemoryOptionsExtension)))\n            {\n                await Assert.ThrowsAsync<DbUpdateException>(() =>\n                    store.StoreDeviceAuthorizationAsync($\"device_{Guid.NewGuid().ToString()}\", existingUserCode, deviceCodeData));\n            }\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task StoreDeviceAuthorizationAsync_WhenDeviceCodeAlreadyExists_ExpectException(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var existingDeviceCode = $\"device_{Guid.NewGuid().ToString()}\";\n        var deviceCodeData = new DeviceCode\n        {\n            ClientId = \"device_flow\",\n            RequestedScopes = new[] { \"openid\", \"api1\" },\n            CreationTime = new DateTime(2018, 10, 19, 16, 14, 29),\n            Lifetime = 300,\n            IsOpenId = true,\n            Subject = new ClaimsPrincipal(new ClaimsIdentity(\n                new List<Claim> { new Claim(JwtClaimTypes.Subject, $\"sub_{Guid.NewGuid().ToString()}\") }))\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.Add(new DeviceFlowCodes\n            {\n                DeviceCode = existingDeviceCode,\n                UserCode = $\"user_{Guid.NewGuid().ToString()}\",\n                ClientId = deviceCodeData.ClientId,\n                SubjectId = deviceCodeData.Subject.FindFirst(JwtClaimTypes.Subject).Value,\n                CreationTime = deviceCodeData.CreationTime,\n                Expiration = deviceCodeData.CreationTime.AddSeconds(deviceCodeData.Lifetime),\n                Data = serializer.Serialize(deviceCodeData)\n            });\n            context.SaveChanges();\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n\n            // skip odd behaviour of in-memory provider\n            if (options.Extensions.All(x => x.GetType() != typeof(InMemoryOptionsExtension)))\n            {\n                await Assert.ThrowsAsync<DbUpdateException>(() =>\n                    store.StoreDeviceAuthorizationAsync(existingDeviceCode, $\"user_{Guid.NewGuid().ToString()}\", deviceCodeData));\n            }\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindByUserCodeAsync_WhenUserCodeExists_ExpectDataRetrievedCorrectly(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var testDeviceCode = $\"device_{Guid.NewGuid().ToString()}\";\n        var testUserCode = $\"user_{Guid.NewGuid().ToString()}\";\n\n        var expectedSubject = $\"sub_{Guid.NewGuid().ToString()}\";\n        var expectedDeviceCodeData = new DeviceCode\n        {\n            ClientId = \"device_flow\",\n            RequestedScopes = new[] { \"openid\", \"api1\" },\n            CreationTime = new DateTime(2018, 10, 19, 16, 14, 29),\n            Lifetime = 300,\n            IsOpenId = true,\n            Subject = new ClaimsPrincipal(new ClaimsIdentity(new List<Claim> { new Claim(JwtClaimTypes.Subject, expectedSubject) }))\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.Add(new DeviceFlowCodes\n            {\n                DeviceCode = testDeviceCode,\n                UserCode = testUserCode,\n                ClientId = expectedDeviceCodeData.ClientId,\n                SubjectId = expectedDeviceCodeData.Subject.FindFirst(JwtClaimTypes.Subject).Value,\n                CreationTime = expectedDeviceCodeData.CreationTime,\n                Expiration = expectedDeviceCodeData.CreationTime.AddSeconds(expectedDeviceCodeData.Lifetime),\n                Data = serializer.Serialize(expectedDeviceCodeData)\n            });\n            context.SaveChanges();\n        }\n\n        DeviceCode code;\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n            code = await store.FindByUserCodeAsync(testUserCode);\n        }\n        \n        code.Should().BeEquivalentTo(expectedDeviceCodeData, \n            assertionOptions => assertionOptions.Excluding(x=> x.Subject));\n\n        code.Subject.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.Subject && x.Value == expectedSubject).Should().NotBeNull();\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindByUserCodeAsync_WhenUserCodeDoesNotExist_ExpectNull(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n            var code = await store.FindByUserCodeAsync($\"user_{Guid.NewGuid().ToString()}\");\n            code.Should().BeNull();\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindByDeviceCodeAsync_WhenDeviceCodeExists_ExpectDataRetrievedCorrectly(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var testDeviceCode = $\"device_{Guid.NewGuid().ToString()}\";\n        var testUserCode = $\"user_{Guid.NewGuid().ToString()}\";\n\n        var expectedSubject = $\"sub_{Guid.NewGuid().ToString()}\";\n        var expectedDeviceCodeData = new DeviceCode\n        {\n            ClientId = \"device_flow\",\n            RequestedScopes = new[] { \"openid\", \"api1\" },\n            CreationTime = new DateTime(2018, 10, 19, 16, 14, 29),\n            Lifetime = 300,\n            IsOpenId = true,\n            Subject = new ClaimsPrincipal(new ClaimsIdentity(new List<Claim> { new Claim(JwtClaimTypes.Subject, expectedSubject) }))\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.Add(new DeviceFlowCodes\n            {\n                DeviceCode = testDeviceCode,\n                UserCode = testUserCode,\n                ClientId = expectedDeviceCodeData.ClientId,\n                SubjectId = expectedDeviceCodeData.Subject.FindFirst(JwtClaimTypes.Subject).Value,\n                CreationTime = expectedDeviceCodeData.CreationTime,\n                Expiration = expectedDeviceCodeData.CreationTime.AddSeconds(expectedDeviceCodeData.Lifetime),\n                Data = serializer.Serialize(expectedDeviceCodeData)\n            });\n            context.SaveChanges();\n        }\n\n        DeviceCode code;\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n            code = await store.FindByDeviceCodeAsync(testDeviceCode);\n        }\n\n        code.Should().BeEquivalentTo(expectedDeviceCodeData,\n            assertionOptions => assertionOptions.Excluding(x => x.Subject));\n\n        code.Subject.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.Subject && x.Value == expectedSubject).Should().NotBeNull();\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindByDeviceCodeAsync_WhenDeviceCodeDoesNotExist_ExpectNull(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n            var code = await store.FindByDeviceCodeAsync($\"device_{Guid.NewGuid().ToString()}\");\n            code.Should().BeNull();\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task UpdateByUserCodeAsync_WhenDeviceCodeAuthorized_ExpectSubjectAndDataUpdated(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var testDeviceCode = $\"device_{Guid.NewGuid().ToString()}\";\n        var testUserCode = $\"user_{Guid.NewGuid().ToString()}\";\n\n        var expectedSubject = $\"sub_{Guid.NewGuid().ToString()}\";\n        var unauthorizedDeviceCode = new DeviceCode\n        {\n            ClientId = \"device_flow\",\n            RequestedScopes = new[] {\"openid\", \"api1\"},\n            CreationTime = new DateTime(2018, 10, 19, 16, 14, 29),\n            Lifetime = 300,\n            IsOpenId = true\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.Add(new DeviceFlowCodes\n            {\n                DeviceCode = testDeviceCode,\n                UserCode = testUserCode,\n                ClientId = unauthorizedDeviceCode.ClientId,\n                CreationTime = unauthorizedDeviceCode.CreationTime,\n                Expiration = unauthorizedDeviceCode.CreationTime.AddSeconds(unauthorizedDeviceCode.Lifetime),\n                Data = serializer.Serialize(unauthorizedDeviceCode)\n            });\n            context.SaveChanges();\n        }\n\n        var authorizedDeviceCode = new DeviceCode\n        {\n            ClientId = unauthorizedDeviceCode.ClientId,\n            RequestedScopes = unauthorizedDeviceCode.RequestedScopes,\n            AuthorizedScopes = unauthorizedDeviceCode.RequestedScopes,\n            Subject = new ClaimsPrincipal(new ClaimsIdentity(new List<Claim> { new Claim(JwtClaimTypes.Subject, expectedSubject) })),\n            IsAuthorized = true,\n            IsOpenId = true,\n            CreationTime = new DateTime(2018, 10, 19, 16, 14, 29),\n            Lifetime = 300\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n            await store.UpdateByUserCodeAsync(testUserCode, authorizedDeviceCode);\n        }\n\n        DeviceFlowCodes updatedCodes;\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            updatedCodes = context.DeviceFlowCodes.Single(x => x.UserCode == testUserCode);\n        }\n\n        // should be unchanged\n        updatedCodes.DeviceCode.Should().Be(testDeviceCode);\n        updatedCodes.ClientId.Should().Be(unauthorizedDeviceCode.ClientId);\n        updatedCodes.CreationTime.Should().Be(unauthorizedDeviceCode.CreationTime);\n        updatedCodes.Expiration.Should().Be(unauthorizedDeviceCode.CreationTime.AddSeconds(authorizedDeviceCode.Lifetime));\n\n        // should be changed\n        var parsedCode = serializer.Deserialize<DeviceCode>(updatedCodes.Data);\n        parsedCode.Should().BeEquivalentTo(authorizedDeviceCode, assertionOptions => assertionOptions.Excluding(x => x.Subject));\n        parsedCode.Subject.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.Subject && x.Value == expectedSubject).Should().NotBeNull();\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task RemoveByDeviceCodeAsync_WhenDeviceCodeExists_ExpectDeviceCodeDeleted(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var testDeviceCode = $\"device_{Guid.NewGuid().ToString()}\";\n        var testUserCode = $\"user_{Guid.NewGuid().ToString()}\";\n\n        var existingDeviceCode = new DeviceCode\n        {\n            ClientId = \"device_flow\",\n            RequestedScopes = new[] { \"openid\", \"api1\" },\n            CreationTime = new DateTime(2018, 10, 19, 16, 14, 29),\n            Lifetime = 300,\n            IsOpenId = true\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.Add(new DeviceFlowCodes\n            {\n                DeviceCode = testDeviceCode,\n                UserCode = testUserCode,\n                ClientId = existingDeviceCode.ClientId,\n                CreationTime = existingDeviceCode.CreationTime,\n                Expiration = existingDeviceCode.CreationTime.AddSeconds(existingDeviceCode.Lifetime),\n                Data = serializer.Serialize(existingDeviceCode)\n            });\n            context.SaveChanges();\n        }\n        \n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n            await store.RemoveByDeviceCodeAsync(testDeviceCode);\n        }\n        \n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.FirstOrDefault(x => x.UserCode == testUserCode).Should().BeNull();\n        }\n    }\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task RemoveByDeviceCodeAsync_WhenDeviceCodeDoesNotExists_ExpectSuccess(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new DeviceFlowStore(context, new PersistentGrantSerializer(), FakeLogger<DeviceFlowStore>.Create());\n            await store.RemoveByDeviceCodeAsync($\"device_{Guid.NewGuid().ToString()}\");\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/Stores/PersistedGrantStoreTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityServer8.EntityFramework.DbContexts;\nusing IdentityServer8.EntityFramework.Mappers;\nusing IdentityServer8.EntityFramework.Options;\nusing IdentityServer8.EntityFramework.Stores;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Microsoft.EntityFrameworkCore;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests.Stores;\n\npublic class PersistedGrantStoreTests : IntegrationTest<PersistedGrantStoreTests, PersistedGrantDbContext, OperationalStoreOptions>\n{\n    public PersistedGrantStoreTests(DatabaseProviderFixture<PersistedGrantDbContext> fixture) : base(fixture)\n    {\n        foreach (var options in TestDatabaseProviders.SelectMany(x => x.Select(y => (DbContextOptions<PersistedGrantDbContext>)y)).ToList())\n        {\n            using (var context = new PersistedGrantDbContext(options, StoreOptions))\n                context.Database.EnsureCreated();\n        }\n    }\n\n    private static PersistedGrant CreateTestObject(string sub = null, string clientId = null, string sid = null, string type = null)\n    {\n        return new PersistedGrant\n        {\n            Key = Guid.NewGuid().ToString(),\n            Type = type ?? \"authorization_code\",\n            ClientId = clientId ?? Guid.NewGuid().ToString(),\n            SubjectId = sub ?? Guid.NewGuid().ToString(),\n            SessionId = sid ?? Guid.NewGuid().ToString(),\n            CreationTime = new DateTime(2016, 08, 01),\n            Expiration = new DateTime(2016, 08, 31),\n            Data = Guid.NewGuid().ToString()\n        };\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task StoreAsync_WhenPersistedGrantStored_ExpectSuccess(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var persistedGrant = CreateTestObject();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n            await store.StoreAsync(persistedGrant);\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var foundGrant = context.PersistedGrants.FirstOrDefault(x => x.Key == persistedGrant.Key);\n            Assert.NotNull(foundGrant);\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task GetAsync_WithKeyAndPersistedGrantExists_ExpectPersistedGrantReturned(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var persistedGrant = CreateTestObject();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.Add(persistedGrant.ToEntity());\n            context.SaveChanges();\n        }\n\n        PersistedGrant foundPersistedGrant;\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n            foundPersistedGrant = await store.GetAsync(persistedGrant.Key);\n        }\n\n        Assert.NotNull(foundPersistedGrant);\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task GetAllAsync_WithSubAndTypeAndPersistedGrantExists_ExpectPersistedGrantReturned(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var persistedGrant = CreateTestObject();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.Add(persistedGrant.ToEntity());\n            context.SaveChanges();\n        }\n\n        IList<PersistedGrant> foundPersistedGrants;\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n            foundPersistedGrants = (await store.GetAllAsync(new PersistedGrantFilter { SubjectId = persistedGrant.SubjectId })).ToList();\n        }\n\n        Assert.NotNull(foundPersistedGrants);\n        Assert.NotEmpty(foundPersistedGrants);\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task GetAllAsync_Should_Filter(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c1\", sid: \"s1\", type: \"t1\").ToEntity());\n            context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c1\", sid: \"s1\", type: \"t2\").ToEntity());\n            context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c1\", sid: \"s2\", type: \"t1\").ToEntity());\n            context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c1\", sid: \"s2\", type: \"t2\").ToEntity());\n            context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c2\", sid: \"s1\", type: \"t1\").ToEntity());\n            context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c2\", sid: \"s1\", type: \"t2\").ToEntity());\n            context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c2\", sid: \"s2\", type: \"t1\").ToEntity());\n            context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c2\", sid: \"s2\", type: \"t2\").ToEntity());\n            context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c3\", sid: \"s3\", type: \"t3\").ToEntity());\n            context.PersistedGrants.Add(CreateTestObject().ToEntity());\n            context.SaveChanges();\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            (await store.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\"\n            })).ToList().Count.Should().Be(9);\n            (await store.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub2\"\n            })).ToList().Count.Should().Be(0);\n            (await store.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c1\"\n            })).ToList().Count.Should().Be(4);\n            (await store.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c2\"\n            })).ToList().Count.Should().Be(4);\n            (await store.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c3\"\n            })).ToList().Count.Should().Be(1);\n            (await store.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c4\"\n            })).ToList().Count.Should().Be(0);\n            (await store.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c1\",\n                SessionId = \"s1\"\n            })).ToList().Count.Should().Be(2);\n            (await store.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c3\",\n                SessionId = \"s1\"\n            })).ToList().Count.Should().Be(0);\n            (await store.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c1\",\n                SessionId = \"s1\",\n                Type = \"t1\"\n            })).ToList().Count.Should().Be(1);\n            (await store.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c1\",\n                SessionId = \"s1\",\n                Type = \"t3\"\n            })).ToList().Count.Should().Be(0);\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task RemoveAsync_WhenKeyOfExistingReceived_ExpectGrantDeleted(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var persistedGrant = CreateTestObject();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.Add(persistedGrant.ToEntity());\n            context.SaveChanges();\n        }\n        \n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n            await store.RemoveAsync(persistedGrant.Key);\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var foundGrant = context.PersistedGrants.FirstOrDefault(x => x.Key == persistedGrant.Key);\n            Assert.Null(foundGrant);\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task RemoveAllAsync_WhenSubIdAndClientIdOfExistingReceived_ExpectGrantDeleted(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var persistedGrant = CreateTestObject();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.Add(persistedGrant.ToEntity());\n            context.SaveChanges();\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n            await store.RemoveAllAsync(new PersistedGrantFilter { \n                SubjectId = persistedGrant.SubjectId, \n                ClientId = persistedGrant.ClientId \n            });\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var foundGrant = context.PersistedGrants.FirstOrDefault(x => x.Key == persistedGrant.Key);\n            Assert.Null(foundGrant);\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task RemoveAllAsync_WhenSubIdClientIdAndTypeOfExistingReceived_ExpectGrantDeleted(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var persistedGrant = CreateTestObject();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.Add(persistedGrant.ToEntity());\n            context.SaveChanges();\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n            await store.RemoveAllAsync(new PersistedGrantFilter { \n                SubjectId = persistedGrant.SubjectId, \n                ClientId = persistedGrant.ClientId, \n                Type = persistedGrant.Type });\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var foundGrant = context.PersistedGrants.FirstOrDefault(x => x.Key == persistedGrant.Key);\n            Assert.Null(foundGrant);\n        }\n    }\n\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task RemoveAllAsync_Should_Filter(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        void PopulateDb()\n        {\n            using (var context = new PersistedGrantDbContext(options, StoreOptions))\n            {\n                context.PersistedGrants.RemoveRange(context.PersistedGrants.ToArray());\n                context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c1\", sid: \"s1\", type: \"t1\").ToEntity());\n                context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c1\", sid: \"s1\", type: \"t2\").ToEntity());\n                context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c1\", sid: \"s2\", type: \"t1\").ToEntity());\n                context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c1\", sid: \"s2\", type: \"t2\").ToEntity());\n                context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c2\", sid: \"s1\", type: \"t1\").ToEntity());\n                context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c2\", sid: \"s1\", type: \"t2\").ToEntity());\n                context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c2\", sid: \"s2\", type: \"t1\").ToEntity());\n                context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c2\", sid: \"s2\", type: \"t2\").ToEntity());\n                context.PersistedGrants.Add(CreateTestObject(sub: \"sub1\", clientId: \"c3\", sid: \"s3\", type: \"t3\").ToEntity());\n                context.PersistedGrants.Add(CreateTestObject().ToEntity());\n                context.SaveChanges();\n            }\n        }\n\n        PopulateDb();\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            await store.RemoveAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\"\n            });\n            context.PersistedGrants.Count().Should().Be(1);\n        }\n\n        PopulateDb();\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            await store.RemoveAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub2\"\n            });\n            context.PersistedGrants.Count().Should().Be(10);\n        }\n\n        PopulateDb();\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            await store.RemoveAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\", ClientId = \"c1\"\n            });\n            context.PersistedGrants.Count().Should().Be(6);\n        }\n\n        PopulateDb();\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            await store.RemoveAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c2\"\n            });\n            context.PersistedGrants.Count().Should().Be(6);\n        }\n\n        PopulateDb();\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            await store.RemoveAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c3\"\n            });\n            context.PersistedGrants.Count().Should().Be(9);\n        }\n\n\n        PopulateDb();\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            await store.RemoveAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c4\"\n            });\n            context.PersistedGrants.Count().Should().Be(10);\n        }\n\n        PopulateDb();\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            await store.RemoveAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c1\", \n                SessionId = \"s1\"\n            });\n            context.PersistedGrants.Count().Should().Be(8);\n        }\n\n        PopulateDb();\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            await store.RemoveAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c3\",\n                SessionId = \"s1\"\n            });\n            context.PersistedGrants.Count().Should().Be(10);\n        }\n\n        PopulateDb();\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            await store.RemoveAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c1\",\n                SessionId = \"s1\", \n                Type = \"t1\"\n            });\n            context.PersistedGrants.Count().Should().Be(9);\n        }\n\n        PopulateDb();\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n\n            await store.RemoveAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"c1\",\n                SessionId = \"s1\",\n                Type = \"t3\"\n            });\n            context.PersistedGrants.Count().Should().Be(10);\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task Store_should_create_new_record_if_key_does_not_exist(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var persistedGrant = CreateTestObject();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var foundGrant = context.PersistedGrants.FirstOrDefault(x => x.Key == persistedGrant.Key);\n            Assert.Null(foundGrant);\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n            await store.StoreAsync(persistedGrant);\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var foundGrant = context.PersistedGrants.FirstOrDefault(x => x.Key == persistedGrant.Key);\n            Assert.NotNull(foundGrant);\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task Store_should_update_record_if_key_already_exists(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var persistedGrant = CreateTestObject();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.Add(persistedGrant.ToEntity());\n            context.SaveChanges();\n        }\n\n        var newDate = persistedGrant.Expiration.Value.AddHours(1);\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var store = new PersistedGrantStore(context, FakeLogger<PersistedGrantStore>.Create());\n            persistedGrant.Expiration = newDate;\n            await store.StoreAsync(persistedGrant);\n        }\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            var foundGrant = context.PersistedGrants.FirstOrDefault(x => x.Key == persistedGrant.Key);\n            Assert.NotNull(foundGrant);\n            Assert.Equal(newDate, persistedGrant.Expiration);\n        }\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/Stores/ResourceStoreTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityModel;\nusing IdentityServer8.EntityFramework.DbContexts;\nusing IdentityServer8.EntityFramework.Mappers;\nusing IdentityServer8.EntityFramework.Options;\nusing IdentityServer8.EntityFramework.Stores;\nusing IdentityServer8.Models;\nusing Microsoft.EntityFrameworkCore;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests.Stores;\n\npublic class ScopeStoreTests : IntegrationTest<ScopeStoreTests, ConfigurationDbContext, ConfigurationStoreOptions>\n{\n    public ScopeStoreTests(DatabaseProviderFixture<ConfigurationDbContext> fixture) : base(fixture)\n    {\n        foreach (var options in TestDatabaseProviders.SelectMany(x => x.Select(y => (DbContextOptions<ConfigurationDbContext>)y)).ToList())\n        {\n            using (var context = new ConfigurationDbContext(options, StoreOptions))\n                context.Database.EnsureCreated();\n        }\n    }\n\n    private static IdentityResource CreateIdentityTestResource()\n    {\n        return new IdentityResource()\n        {\n            Name = Guid.NewGuid().ToString(),\n            DisplayName = Guid.NewGuid().ToString(),\n            Description = Guid.NewGuid().ToString(),\n            ShowInDiscoveryDocument = true,\n            UserClaims = \n            {\n                JwtClaimTypes.Subject,\n                JwtClaimTypes.Name,\n            }\n        };\n    }\n\n    private static ApiResource CreateApiResourceTestResource()\n    {\n        return new ApiResource()\n        {\n            Name = Guid.NewGuid().ToString(),\n            ApiSecrets = new List<Secret> { new Secret(\"secret\".ToSha256()) },\n            Scopes = { Guid.NewGuid().ToString() },\n            UserClaims =\n            {\n                Guid.NewGuid().ToString(),\n                Guid.NewGuid().ToString(),\n            }\n        };\n    }\n    \n    private static ApiScope CreateApiScopeTestResource()\n    {\n        return new ApiScope()\n        {\n            Name = Guid.NewGuid().ToString(),\n            UserClaims =\n            {\n                Guid.NewGuid().ToString(),\n                Guid.NewGuid().ToString(),\n            }\n        };\n    }\n\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindApiResourcesByNameAsync_WhenResourceExists_ExpectResourceAndCollectionsReturned(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var resource = CreateApiResourceTestResource();\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.ApiResources.Add(resource.ToEntity());\n            context.SaveChanges();\n        }\n\n        ApiResource foundResource;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ResourceStore(context, FakeLogger<ResourceStore>.Create());\n            foundResource = (await store.FindApiResourcesByNameAsync(new[] { resource.Name })).SingleOrDefault();\n        }\n\n        Assert.NotNull(foundResource);\n        Assert.True(foundResource.Name == resource.Name);\n\n        Assert.NotNull(foundResource.UserClaims);\n        Assert.NotEmpty(foundResource.UserClaims);\n        Assert.NotNull(foundResource.ApiSecrets);\n        Assert.NotEmpty(foundResource.ApiSecrets);\n        Assert.NotNull(foundResource.Scopes);\n        Assert.NotEmpty(foundResource.Scopes);\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindApiResourcesByNameAsync_WhenResourcesExist_ExpectOnlyResourcesRequestedReturned(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var resource = CreateApiResourceTestResource();\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.ApiResources.Add(resource.ToEntity());\n            context.ApiResources.Add(CreateApiResourceTestResource().ToEntity());\n            context.SaveChanges();\n        }\n\n        ApiResource foundResource;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ResourceStore(context, FakeLogger<ResourceStore>.Create());\n            foundResource = (await store.FindApiResourcesByNameAsync(new[] { resource.Name })).SingleOrDefault();\n        }\n\n        Assert.NotNull(foundResource);\n        Assert.True(foundResource.Name == resource.Name);\n\n        Assert.NotNull(foundResource.UserClaims);\n        Assert.NotEmpty(foundResource.UserClaims);\n        Assert.NotNull(foundResource.ApiSecrets);\n        Assert.NotEmpty(foundResource.ApiSecrets);\n        Assert.NotNull(foundResource.Scopes);\n        Assert.NotEmpty(foundResource.Scopes);\n    }\n\n\n\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindApiResourcesByScopeNameAsync_WhenResourcesExist_ExpectResourcesReturned(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var testApiResource = CreateApiResourceTestResource();\n        var testApiScope = CreateApiScopeTestResource();\n        testApiResource.Scopes.Add(testApiScope.Name);\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.ApiResources.Add(testApiResource.ToEntity());\n            context.ApiScopes.Add(testApiScope.ToEntity());\n            context.SaveChanges();\n        }\n\n        IEnumerable<ApiResource> resources;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ResourceStore(context, FakeLogger<ResourceStore>.Create());\n            resources = await store.FindApiResourcesByScopeNameAsync(new List<string>\n            {\n                testApiScope.Name\n            });\n        }\n\n        Assert.NotNull(resources);\n        Assert.NotEmpty(resources);\n        Assert.NotNull(resources.Single(x => x.Name == testApiResource.Name));\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindApiResourcesByScopeNameAsync_WhenResourcesExist_ExpectOnlyResourcesRequestedReturned(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var testIdentityResource = CreateIdentityTestResource();\n        var testApiResource = CreateApiResourceTestResource();\n        var testApiScope = CreateApiScopeTestResource();\n        testApiResource.Scopes.Add(testApiScope.Name);\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.IdentityResources.Add(testIdentityResource.ToEntity());\n            context.ApiResources.Add(testApiResource.ToEntity());\n            context.ApiScopes.Add(testApiScope.ToEntity());\n            context.IdentityResources.Add(CreateIdentityTestResource().ToEntity());\n            context.ApiResources.Add(CreateApiResourceTestResource().ToEntity());\n            context.ApiScopes.Add(CreateApiScopeTestResource().ToEntity());\n            context.SaveChanges();\n        }\n\n        IEnumerable<ApiResource> resources;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ResourceStore(context, FakeLogger<ResourceStore>.Create());\n            resources = await store.FindApiResourcesByScopeNameAsync(new[] { testApiScope.Name });\n        }\n\n        Assert.NotNull(resources);\n        Assert.NotEmpty(resources);\n        Assert.NotNull(resources.Single(x => x.Name == testApiResource.Name));\n    }\n\n\n\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindIdentityResourcesByScopeNameAsync_WhenResourceExists_ExpectResourceAndCollectionsReturned(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var resource = CreateIdentityTestResource();\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.IdentityResources.Add(resource.ToEntity());\n            context.SaveChanges();\n        }\n\n        IList<IdentityResource> resources;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ResourceStore(context, FakeLogger<ResourceStore>.Create());\n            resources = (await store.FindIdentityResourcesByScopeNameAsync(new List<string>\n            {\n                resource.Name\n            })).ToList();\n        }\n\n        Assert.NotNull(resources);\n        Assert.NotEmpty(resources);\n        var foundScope = resources.Single();\n\n        Assert.Equal(resource.Name, foundScope.Name);\n        Assert.NotNull(foundScope.UserClaims);\n        Assert.NotEmpty(foundScope.UserClaims);\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindIdentityResourcesByScopeNameAsync_WhenResourcesExist_ExpectOnlyRequestedReturned(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var resource = CreateIdentityTestResource();\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.IdentityResources.Add(resource.ToEntity());\n            context.IdentityResources.Add(CreateIdentityTestResource().ToEntity());\n            context.SaveChanges();\n        }\n\n        IList<IdentityResource> resources;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ResourceStore(context, FakeLogger<ResourceStore>.Create());\n            resources = (await store.FindIdentityResourcesByScopeNameAsync(new List<string>\n            {\n                resource.Name\n            })).ToList();\n        }\n\n        Assert.NotNull(resources);\n        Assert.NotEmpty(resources);\n        Assert.NotNull(resources.Single(x => x.Name == resource.Name));\n    }\n\n\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindApiScopesByNameAsync_WhenResourceExists_ExpectResourceAndCollectionsReturned(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var resource = CreateApiScopeTestResource();\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.ApiScopes.Add(resource.ToEntity());\n            context.SaveChanges();\n        }\n\n        IList<ApiScope> resources;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ResourceStore(context, FakeLogger<ResourceStore>.Create());\n            resources = (await store.FindApiScopesByNameAsync(new List<string>\n            {\n                resource.Name\n            })).ToList();\n        }\n\n        Assert.NotNull(resources);\n        Assert.NotEmpty(resources);\n        var foundScope = resources.Single();\n\n        Assert.Equal(resource.Name, foundScope.Name);\n        Assert.NotNull(foundScope.UserClaims);\n        Assert.NotEmpty(foundScope.UserClaims);\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task FindApiScopesByNameAsync_WhenResourcesExist_ExpectOnlyRequestedReturned(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var resource = CreateApiScopeTestResource();\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.ApiScopes.Add(resource.ToEntity());\n            context.ApiScopes.Add(CreateApiScopeTestResource().ToEntity());\n            context.SaveChanges();\n        }\n\n        IList<ApiScope> resources;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ResourceStore(context, FakeLogger<ResourceStore>.Create());\n            resources = (await store.FindApiScopesByNameAsync(new List<string>\n            {\n                resource.Name\n            })).ToList();\n        }\n\n        Assert.NotNull(resources);\n        Assert.NotEmpty(resources);\n        Assert.NotNull(resources.Single(x => x.Name == resource.Name));\n    }\n\n\n\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task GetAllResources_WhenAllResourcesRequested_ExpectAllResourcesIncludingHidden(DbContextOptions<ConfigurationDbContext> options)\n    {\n        var visibleIdentityResource = CreateIdentityTestResource();\n        var visibleApiResource = CreateApiResourceTestResource();\n        var visibleApiScope = CreateApiScopeTestResource();\n        var hiddenIdentityResource = new IdentityResource { Name = Guid.NewGuid().ToString(), ShowInDiscoveryDocument = false };\n        var hiddenApiResource = new ApiResource\n        {\n            Name = Guid.NewGuid().ToString(),\n            Scopes = { Guid.NewGuid().ToString() },\n            ShowInDiscoveryDocument = false\n        };\n        var hiddenApiScope = new ApiScope\n        {\n            Name = Guid.NewGuid().ToString(),\n            ShowInDiscoveryDocument = false\n        };\n\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            context.IdentityResources.Add(visibleIdentityResource.ToEntity());\n            context.ApiResources.Add(visibleApiResource.ToEntity());\n            context.ApiScopes.Add(visibleApiScope.ToEntity());\n\n            context.IdentityResources.Add(hiddenIdentityResource.ToEntity());\n            context.ApiResources.Add(hiddenApiResource.ToEntity());\n            context.ApiScopes.Add(hiddenApiScope.ToEntity());\n            \n            context.SaveChanges();\n        }\n\n        Resources resources;\n        using (var context = new ConfigurationDbContext(options, StoreOptions))\n        {\n            var store = new ResourceStore(context, FakeLogger<ResourceStore>.Create());\n            resources = await store.GetAllResourcesAsync();\n        }\n\n        Assert.NotNull(resources);\n        Assert.NotEmpty(resources.IdentityResources);\n        Assert.NotEmpty(resources.ApiResources);\n        Assert.NotEmpty(resources.ApiScopes);\n\n        Assert.Contains(resources.IdentityResources, x => x.Name == visibleIdentityResource.Name);\n        Assert.Contains(resources.IdentityResources, x => x.Name == hiddenIdentityResource.Name);\n\n        Assert.Contains(resources.ApiResources, x => x.Name == visibleApiResource.Name);\n        Assert.Contains(resources.ApiResources, x => x.Name == hiddenApiResource.Name);\n\n        Assert.Contains(resources.ApiScopes, x => x.Name == visibleApiScope.Name);\n        Assert.Contains(resources.ApiScopes, x => x.Name == hiddenApiScope.Name);\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/IntegrationTests/TokenCleanup/TokenCleanupTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityServer8.EntityFramework.DbContexts;\nusing IdentityServer8.EntityFramework.Entities;\nusing IdentityServer8.EntityFramework.Interfaces;\nusing IdentityServer8.EntityFramework.Options;\nusing IdentityServer8.EntityFramework.Stores;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Test;\nusing Microsoft.EntityFrameworkCore;\nusing Microsoft.Extensions.DependencyInjection;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.IntegrationTests.TokenCleanup;\n\npublic class TokenCleanupTests : IntegrationTest<TokenCleanupTests, PersistedGrantDbContext, OperationalStoreOptions>\n{\n\n\n    public TokenCleanupTests(DatabaseProviderFixture<PersistedGrantDbContext> fixture) : base(fixture)\n    {\n        foreach (var options in TestDatabaseProviders.SelectMany(x => x.Select(y => (DbContextOptions<PersistedGrantDbContext>)y)).ToList())\n        {\n            using (var context = new PersistedGrantDbContext(options, StoreOptions))\n            {\n                context.Database.EnsureCreated();\n            }\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task RemoveExpiredGrantsAsync_WhenExpiredGrantsExist_ExpectExpiredGrantsRemoved(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var expiredGrant = new PersistedGrant\n        {\n            Key = Guid.NewGuid().ToString(),\n            ClientId = \"app1\",\n            Type = \"reference\",\n            SubjectId = \"123\",\n            Expiration = DateTime.UtcNow.AddDays(-3),\n            Data = \"{!}\"\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.Add(expiredGrant);\n            context.SaveChanges();\n        }\n\n        await CreateSut(options).RemoveExpiredGrantsAsync();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.FirstOrDefault(x => x.Key == expiredGrant.Key).Should().BeNull();\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task RemoveExpiredGrantsAsync_WhenValidGrantsExist_ExpectValidGrantsInDb(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var validGrant = new PersistedGrant\n        {\n            Key = Guid.NewGuid().ToString(),\n            ClientId = \"app1\",\n            Type = \"reference\",\n            SubjectId = \"123\",\n            Expiration = DateTime.UtcNow.AddDays(3),\n            Data = \"{!}\"\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.Add(validGrant);\n            context.SaveChanges();\n        }\n\n        await CreateSut(options).RemoveExpiredGrantsAsync();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.PersistedGrants.FirstOrDefault(x => x.Key == validGrant.Key).Should().NotBeNull();\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task RemoveExpiredGrantsAsync_WhenExpiredDeviceGrantsExist_ExpectExpiredDeviceGrantsRemoved(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var expiredGrant = new DeviceFlowCodes\n        {\n            DeviceCode = Guid.NewGuid().ToString(),\n            UserCode = Guid.NewGuid().ToString(),\n            ClientId = \"app1\",\n            SubjectId = \"123\",\n            CreationTime = DateTime.UtcNow.AddDays(-4),\n            Expiration = DateTime.UtcNow.AddDays(-3),\n            Data = \"{!}\"\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.Add(expiredGrant);\n            context.SaveChanges();\n        }\n\n        await CreateSut(options).RemoveExpiredGrantsAsync();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.FirstOrDefault(x => x.DeviceCode == expiredGrant.DeviceCode).Should().BeNull();\n        }\n    }\n\n    [Theory, MemberData(nameof(TestDatabaseProviders))]\n    public async Task RemoveExpiredGrantsAsync_WhenValidDeviceGrantsExist_ExpectValidDeviceGrantsInDb(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        var validGrant = new DeviceFlowCodes\n        {\n            DeviceCode = Guid.NewGuid().ToString(),\n            UserCode = \"2468\",\n            ClientId = \"app1\",\n            SubjectId = \"123\",\n            CreationTime = DateTime.UtcNow.AddDays(-4),\n            Expiration = DateTime.UtcNow.AddDays(3),\n            Data = \"{!}\"\n        };\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.Add(validGrant);\n            context.SaveChanges();\n        }\n\n        await CreateSut(options).RemoveExpiredGrantsAsync();\n\n        using (var context = new PersistedGrantDbContext(options, StoreOptions))\n        {\n            context.DeviceFlowCodes.FirstOrDefault(x => x.DeviceCode == validGrant.DeviceCode).Should().NotBeNull();\n        }\n    }\n\n    private EntityFramework.TokenCleanupService CreateSut(DbContextOptions<PersistedGrantDbContext> options)\n    {\n        IServiceCollection services = new ServiceCollection();\n        services.AddIdentityServer()\n            .AddTestUsers(new List<TestUser>())\n            .AddInMemoryClients(new List<Models.Client>())\n            .AddInMemoryIdentityResources(new List<Models.IdentityResource>())\n            .AddInMemoryApiResources(new List<Models.ApiResource>());\n\n        services.AddScoped<IPersistedGrantDbContext, PersistedGrantDbContext>(_ =>\n            new PersistedGrantDbContext(options, StoreOptions));\n        services.AddTransient<IPersistedGrantStore, PersistedGrantStore>();\n        services.AddTransient<IDeviceFlowStore, DeviceFlowStore>();\n        \n        services.AddTransient<EntityFramework.TokenCleanupService>();\n        services.AddSingleton(StoreOptions);\n\n        return services.BuildServiceProvider().GetRequiredService<EntityFramework.TokenCleanupService>();\n        //return new EntityFramework.TokenCleanupService(\n        //    services.BuildServiceProvider(),\n        //    new NullLogger<EntityFramework.TokenCleanup>(),\n        //    StoreOptions);\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/UnitTests/IdentityServer8.EntityFramework.UnitTests.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n  <PropertyGroup>\n    <AssemblyOriginatorKeyFile>../../../../key.snk</AssemblyOriginatorKeyFile>\n    <SignAssembly>true</SignAssembly>\n    <PublicSign Condition=\"'$(OS)' != 'Windows_NT'\">true</PublicSign>\n  </PropertyGroup>\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\..\\src\\IdentityServer8.EntityFramework.Storage.csproj\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <PackageReference Include=\"FluentAssertions\" />\n    <PackageReference Include=\"Microsoft.NET.Test.Sdk\" />\n    <PackageReference Include=\"xunit\" />\n    <PackageReference Include=\"xunit.runner.visualstudio\" />\n    <PackageReference Include=\"coverlet.collector\" GeneratePathProperty=\"true\">\n      <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n      <PrivateAssets>all</PrivateAssets>\n    </PackageReference>\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.Sqlite\" />\n  </ItemGroup>\n\n</Project>\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/UnitTests/Mappers/ApiResourceMappersTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Linq;\nusing FluentAssertions;\nusing IdentityServer8.EntityFramework.Mappers;\nusing Xunit;\nusing ApiResource = IdentityServer8.Models.ApiResource;\n\nnamespace IdentityServer8.EntityFramework.UnitTests.Mappers;\n\npublic class ApiResourceMappersTests\n{\n    [Fact]\n    public void AutomapperConfigurationIsValid()\n    {\n        ApiResourceMappers.Mapper.ConfigurationProvider.AssertConfigurationIsValid();\n    }\n\n    [Fact]\n    public void Can_Map()\n    {\n        var model = new ApiResource();\n        var mappedEntity = model.ToEntity();\n        var mappedModel = mappedEntity.ToModel();\n\n        Assert.NotNull(mappedModel);\n        Assert.NotNull(mappedEntity);\n    }\n\n    [Fact]\n    public void Properties_Map()\n    {\n        var model = new ApiResource()\n        {\n           Description = \"description\",\n           DisplayName = \"displayname\",\n           Name = \"foo\",\n           Scopes = { \"foo1\", \"foo2\" },\n           Enabled = false\n        };\n\n\n        var mappedEntity = model.ToEntity();\n\n        mappedEntity.Scopes.Count.Should().Be(2);\n        var foo1 = mappedEntity.Scopes.FirstOrDefault(x => x.Scope == \"foo1\");\n        foo1.Should().NotBeNull();\n        var foo2 = mappedEntity.Scopes.FirstOrDefault(x => x.Scope == \"foo2\");\n        foo2.Should().NotBeNull();\n        \n\n        var mappedModel = mappedEntity.ToModel();\n        \n        mappedModel.Description.Should().Be(\"description\");\n        mappedModel.DisplayName.Should().Be(\"displayname\");\n        mappedModel.Enabled.Should().BeFalse();\n        mappedModel.Name.Should().Be(\"foo\");\n    }\n\n    [Fact]\n    public void missing_values_should_use_defaults()\n    {\n        var entity = new IdentityServer8.EntityFramework.Entities.ApiResource\n        {\n            Secrets = new System.Collections.Generic.List<Entities.ApiResourceSecret>\n            {\n                new Entities.ApiResourceSecret\n                {\n                }\n            }\n        };\n\n        var def = new ApiResource\n        {\n            ApiSecrets = { new Models.Secret(\"foo\") }\n        };\n\n        var model = entity.ToModel();\n        model.ApiSecrets.First().Type.Should().Be(def.ApiSecrets.First().Type);\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/UnitTests/Mappers/ClientMappersTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Linq;\nusing FluentAssertions;\nusing IdentityServer8.EntityFramework.Mappers;\nusing Xunit;\nusing Client = IdentityServer8.Models.Client;\n\nnamespace IdentityServer8.EntityFramework.UnitTests.Mappers;\n\npublic class ClientMappersTests\n{\n    [Fact]\n    public void AutomapperConfigurationIsValid()\n    {\n        ClientMappers.Mapper.ConfigurationProvider.AssertConfigurationIsValid();\n    }\n\n    [Fact]\n    public void Can_Map()\n    {\n        var model = new Client();\n        var mappedEntity = model.ToEntity();\n        var mappedModel = mappedEntity.ToModel();\n\n        Assert.NotNull(mappedModel);\n        Assert.NotNull(mappedEntity);\n    }\n\n    [Fact]\n    public void Properties_Map()\n    {\n        var model = new Client()\n        {\n            Properties =\n            {\n                {\"foo1\", \"bar1\"},\n                {\"foo2\", \"bar2\"},\n            }\n        };\n\n\n        var mappedEntity = model.ToEntity();\n\n        mappedEntity.Properties.Count.Should().Be(2);\n        var foo1 = mappedEntity.Properties.FirstOrDefault(x => x.Key == \"foo1\");\n        foo1.Should().NotBeNull();\n        foo1.Value.Should().Be(\"bar1\");\n        var foo2 = mappedEntity.Properties.FirstOrDefault(x => x.Key == \"foo2\");\n        foo2.Should().NotBeNull();\n        foo2.Value.Should().Be(\"bar2\");\n\n\n\n        var mappedModel = mappedEntity.ToModel();\n\n        mappedModel.Properties.Count.Should().Be(2);\n        mappedModel.Properties.ContainsKey(\"foo1\").Should().BeTrue();\n        mappedModel.Properties.ContainsKey(\"foo2\").Should().BeTrue();\n        mappedModel.Properties[\"foo1\"].Should().Be(\"bar1\");\n        mappedModel.Properties[\"foo2\"].Should().Be(\"bar2\");\n    }\n\n    [Fact]\n    public void duplicates_properties_in_db_map()\n    {\n        var entity = new IdentityServer8.EntityFramework.Entities.Client\n        {\n            Properties = new System.Collections.Generic.List<Entities.ClientProperty>()\n            {\n                new Entities.ClientProperty{Key = \"foo1\", Value = \"bar1\"},\n                new Entities.ClientProperty{Key = \"foo1\", Value = \"bar2\"},\n            }\n        };\n\n        Action modelAction = () => entity.ToModel();\n        modelAction.Should().Throw<Exception>();\n    }\n\n    [Fact]\n    public void missing_values_should_use_defaults()\n    {\n        var entity = new IdentityServer8.EntityFramework.Entities.Client\n        {\n            ClientSecrets = new System.Collections.Generic.List<Entities.ClientSecret>\n            {\n                new Entities.ClientSecret\n                {\n                }\n            }\n        };\n\n        var def = new Client\n        {\n            ClientSecrets = { new Models.Secret(\"foo\") }\n        };\n\n        var model = entity.ToModel();\n        model.ProtocolType.Should().Be(def.ProtocolType);\n        model.ClientSecrets.First().Type.Should().Be(def.ClientSecrets.First().Type);\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/UnitTests/Mappers/IdentityResourcesMappersTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.EntityFramework.Mappers;\nusing IdentityServer8.Models;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.UnitTests.Mappers;\n\npublic class IdentityResourcesMappersTests\n{\n    [Fact]\n    public void IdentityResourceAutomapperConfigurationIsValid()\n    {\n        IdentityResourceMappers.Mapper.ConfigurationProvider.AssertConfigurationIsValid();\n    }\n\n    [Fact]\n    public void CanMapIdentityResources()\n    {\n        var model = new IdentityResource();\n        var mappedEntity = model.ToEntity();\n        var mappedModel = mappedEntity.ToModel();\n\n        Assert.NotNull(mappedModel);\n        Assert.NotNull(mappedEntity);\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/UnitTests/Mappers/PersistedGrantMappersTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityServer8.EntityFramework.Mappers;\nusing IdentityServer8.Models;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.UnitTests.Mappers;\n\npublic class PersistedGrantMappersTests\n{\n    [Fact]\n    public void PersistedGrantAutomapperConfigurationIsValid()\n    {\n        PersistedGrantMappers.Mapper.ConfigurationProvider.AssertConfigurationIsValid();\n    }\n\n    [Fact]\n    public void CanMap()\n    {\n        var model = new PersistedGrant()\n        {\n            ConsumedTime = new System.DateTime(2020, 02, 03, 4, 5, 6)\n        };\n        \n        var mappedEntity = model.ToEntity();\n        mappedEntity.ConsumedTime.Value.Should().Be(new System.DateTime(2020, 02, 03, 4, 5, 6));\n        \n        var mappedModel = mappedEntity.ToModel();\n        mappedModel.ConsumedTime.Value.Should().Be(new System.DateTime(2020, 02, 03, 4, 5, 6));\n\n        Assert.NotNull(mappedModel);\n        Assert.NotNull(mappedEntity);\n    }\n}\n"
  },
  {
    "path": "src/EntityFramework.Storage/test/UnitTests/Mappers/ScopeMappersTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Linq;\nusing FluentAssertions;\nusing IdentityServer8.EntityFramework.Mappers;\nusing IdentityServer8.Models;\nusing Xunit;\n\nnamespace IdentityServer8.EntityFramework.UnitTests.Mappers;\n\npublic class ScopesMappersTests\n{\n    [Fact]\n    public void ScopeAutomapperConfigurationIsValid()\n    {\n        ScopeMappers.Mapper.ConfigurationProvider.AssertConfigurationIsValid();\n    }\n\n    [Fact]\n    public void CanMapScope()\n    {\n        var model = new ApiScope();\n        var mappedEntity = model.ToEntity();\n        var mappedModel = mappedEntity.ToModel();\n\n        Assert.NotNull(mappedModel);\n        Assert.NotNull(mappedEntity);\n    }\n\n    [Fact]\n    public void Properties_Map()\n    {\n        var model = new ApiScope()\n        {\n            Description = \"description\",\n            DisplayName = \"displayname\",\n            Name = \"foo\",\n            UserClaims = { \"c1\", \"c2\" },\n            Properties = {\n                { \"x\", \"xx\" },\n                { \"y\", \"yy\" },\n           },\n            Enabled = false\n        };\n\n\n        var mappedEntity = model.ToEntity();\n        mappedEntity.Description.Should().Be(\"description\");\n        mappedEntity.DisplayName.Should().Be(\"displayname\");\n        mappedEntity.Name.Should().Be(\"foo\");\n\n        mappedEntity.UserClaims.Count.Should().Be(2);\n        mappedEntity.UserClaims.Select(x => x.Type).Should().BeEquivalentTo(new[] { \"c1\", \"c2\" });\n        mappedEntity.Properties.Count.Should().Be(2);\n        mappedEntity.Properties.Should().Contain(x => x.Key == \"x\" && x.Value == \"xx\");\n        mappedEntity.Properties.Should().Contain(x => x.Key == \"y\" && x.Value == \"yy\");\n\n\n        var mappedModel = mappedEntity.ToModel();\n\n        mappedModel.Description.Should().Be(\"description\");\n        mappedModel.DisplayName.Should().Be(\"displayname\");\n        mappedModel.Enabled.Should().BeFalse();\n        mappedModel.Name.Should().Be(\"foo\");\n        mappedModel.UserClaims.Count.Should().Be(2);\n        mappedModel.UserClaims.Should().BeEquivalentTo(new[] { \"c1\", \"c2\" });\n        mappedModel.Properties.Count.Should().Be(2);\n        mappedModel.Properties[\"x\"].Should().Be(\"xx\");\n        mappedModel.Properties[\"y\"].Should().Be(\"yy\");\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "src/IdentityServer8/IdentityServer8.sln",
    "content": "Microsoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 10.0.40219.1\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{5461C61B-B06E-46BA-B206-925B660BE727}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"test\", \"test\", \"{45C22EDD-91B1-4AEF-8620-77F4E3E7C544}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8\", \"src\\IdentityServer8.csproj\", \"{407C030E-60E6-41F7-AF43-0AC48EDCC17D}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Host\", \"host\\Host.csproj\", \"{784B3C88-30FA-415D-B99E-584063064508}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer.UnitTests\", \"test\\IdentityServer.UnitTests\\IdentityServer.UnitTests.csproj\", \"{4291820C-735F-4776-8BC4-6527433BC683}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer.IntegrationTests\", \"test\\IdentityServer.IntegrationTests\\IdentityServer.IntegrationTests.csproj\", \"{94501373-478A-478D-8C17-6AC52E3438CF}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Solution Files\", \"Solution Files\", \"{9CB027A4-3509-4E54-B9D7-AC8F2F648AA2}\"\n\tProjectSection(SolutionItems) = preProject\n\t\t..\\..\\.editorconfig = ..\\..\\.editorconfig\n\t\t..\\..\\.gitattributes = ..\\..\\.gitattributes\n\t\t..\\..\\.gitignore = ..\\..\\.gitignore\n\t\t..\\..\\Directory.Build.props = ..\\..\\Directory.Build.props\n\t\t..\\..\\Directory.Build.targets = ..\\..\\Directory.Build.targets\n\t\t..\\..\\Directory.Packages.props = ..\\..\\Directory.Packages.props\n\t\t..\\..\\global.json = ..\\..\\global.json\n\t\t..\\..\\IdentityServer8.DotNet.ruleset = ..\\..\\IdentityServer8.DotNet.ruleset\n\t\t..\\..\\LICENSE = ..\\..\\LICENSE\n\t\t..\\..\\NuGet.config = ..\\..\\NuGet.config\n\t\t..\\..\\README.md = ..\\..\\README.md\n\t\t..\\..\\SECURITY.MD = ..\\..\\SECURITY.MD\n\t\t..\\..\\SPONSORS.md = ..\\..\\SPONSORS.md\n\tEndProjectSection\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tRelease|Any CPU = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{407C030E-60E6-41F7-AF43-0AC48EDCC17D}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{407C030E-60E6-41F7-AF43-0AC48EDCC17D}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{407C030E-60E6-41F7-AF43-0AC48EDCC17D}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{407C030E-60E6-41F7-AF43-0AC48EDCC17D}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{784B3C88-30FA-415D-B99E-584063064508}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{784B3C88-30FA-415D-B99E-584063064508}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{784B3C88-30FA-415D-B99E-584063064508}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{784B3C88-30FA-415D-B99E-584063064508}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{4291820C-735F-4776-8BC4-6527433BC683}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{4291820C-735F-4776-8BC4-6527433BC683}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{4291820C-735F-4776-8BC4-6527433BC683}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{4291820C-735F-4776-8BC4-6527433BC683}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{94501373-478A-478D-8C17-6AC52E3438CF}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{94501373-478A-478D-8C17-6AC52E3438CF}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{94501373-478A-478D-8C17-6AC52E3438CF}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{94501373-478A-478D-8C17-6AC52E3438CF}.Release|Any CPU.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{407C030E-60E6-41F7-AF43-0AC48EDCC17D} = {5461C61B-B06E-46BA-B206-925B660BE727}\n\t\t{784B3C88-30FA-415D-B99E-584063064508} = {5461C61B-B06E-46BA-B206-925B660BE727}\n\t\t{4291820C-735F-4776-8BC4-6527433BC683} = {45C22EDD-91B1-4AEF-8620-77F4E3E7C544}\n\t\t{94501373-478A-478D-8C17-6AC52E3438CF} = {45C22EDD-91B1-4AEF-8620-77F4E3E7C544}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {176723F7-4A9B-4F05-A9F3-3BA715E4BDC3}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "src/IdentityServer8/build.cmd",
    "content": "@echo off\ndotnet run --project build -- %*"
  },
  {
    "path": "src/IdentityServer8/build.ps1",
    "content": "$ErrorActionPreference = \"Stop\";\ndotnet run --project build -- $args"
  },
  {
    "path": "src/IdentityServer8/build.sh",
    "content": "#!/usr/bin/env bash\nset -euo pipefail\ndotnet run --project build -- \"$@\""
  },
  {
    "path": "src/IdentityServer8/host/Configuration/Clients.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Configuration;\n\npublic static class Clients\n{\n    public static IEnumerable<Client> Get()\n    {\n        var clients = new List<Client>();\n\n        clients.AddRange(ClientsConsole.Get());\n        clients.AddRange(ClientsWeb.Get());\n\n        return clients;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Configuration/ClientsConsole.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Configuration;\n\npublic static class ClientsConsole\n{\n    public static IEnumerable<Client> Get()\n    {\n        return new List<Client>\n        {\n            ///////////////////////////////////////////\n            // Console Client Credentials Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes =\n                {\n                    \"resource1.scope1\", \"resource2.scope1\", IdentityServerConstants.LocalApi.ScopeName\n                }\n            },\n\n            ///////////////////////////////////////////\n            // Console Structured Scope Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"parameterized.client\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"transaction\" }\n            },\n\n            ///////////////////////////////////////////\n            // X509 mTLS Client\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mtls\",\n                ClientSecrets =\n                {\n                    // new Secret(@\"CN=mtls.test, OU=ROO\\ballen@roo, O=mkcert development certificate\", \"mtls.test\")\n                    // {\n                    //     Type = SecretTypes.X509CertificateName\n                    // },\n                    new Secret(\"5D9E9B6B333CD42C99D1DE6175CC0F3EF99DDF68\", \"mtls.test\")\n                    {\n                        Type = IdentityServerConstants.SecretTypes.X509CertificateThumbprint\n                    },\n                },\n                AccessTokenType = AccessTokenType.Jwt,\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" }\n            },\n\n            ///////////////////////////////////////////\n            // Console Client Credentials Flow with client JWT assertion\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client.jwt\",\n                ClientSecrets =\n                {\n                    new Secret\n                    {\n                        Type = IdentityServerConstants.SecretTypes.X509CertificateBase64,\n                        Value =\n                            \"MIIEgTCCAumgAwIBAgIQDMMu7l/umJhfEbzJMpcttzANBgkqhkiG9w0BAQsFADCBkzEeMBwGA1UEChMVbWtjZXJ0IGRldmVsb3BtZW50IENBMTQwMgYDVQQLDCtkb21pbmlja0Bkb21icDE2LmZyaXR6LmJveCAoRG9taW5pY2sgQmFpZXIpMTswOQYDVQQDDDJta2NlcnQgZG9taW5pY2tAZG9tYnAxNi5mcml0ei5ib3ggKERvbWluaWNrIEJhaWVyKTAeFw0xOTA2MDEwMDAwMDBaFw0zMDAxMDMxMjM0MDdaMHAxJzAlBgNVBAoTHm1rY2VydCBkZXZlbG9wbWVudCBjZXJ0aWZpY2F0ZTE0MDIGA1UECwwrZG9taW5pY2tAZG9tYnAxNi5mcml0ei5ib3ggKERvbWluaWNrIEJhaWVyKTEPMA0GA1UEAxMGY2xpZW50MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvNtpipaS8k1zA6w0Aoy8U4l+8zM4jHhhblExf3PULrMR6RauxniTki8p+P8CsZT4V8A4qo+JwsgpLIHrVQrbt9DEhHfBKzxwHqt+GoHt7byTfTtp8A/5nLhYc/5CW4HiR194gVx5+HAlvt+BriMTb1czvTf+H20dj41yUPsN7nMdyRLF+uXapQYMLYnq2BJIDq83mqGwojHk7d+N6GwoO95jlyas7KSoj8/FvfbaqkRNx0446hqPOzFHKc8er8K5VrLp6tVjh8ZJyY0F0dKgx6yWITsL54ctbj/cCyfuGjWEMbS2XXgc+x/xQMnmpfhK1qQAUn9jg5EzF9n6mQomOwIDAQABo3MwcTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgwFoAUEMUlw41YsKZQVls3pEG6CrJk4O8wEQYDVR0RBAowCIIGY2xpZW50MA0GCSqGSIb3DQEBCwUAA4IBgQC0TjNY4Q3Wmw7ggamDImV6HUng3WbYGLYbbL2e3myBrjIxGd1Bi8ZyOu8qeUMIRAbZt2YsSX5S8kx0biaVg2zC+aO5eHhEWMwKB66huInXFjI4wtxZ22r+33fg1R0cLuEUePhftOWrbL0MS4YXVyn9HUMWO4WptG9PJdxNw1UbEB8nw3FkVOdAC9RGqiqalSK+E2UT/kUbTIQ1gPSdQ3nh52mre0H/T9+IRqiozJtNK/CQg4NuEV7rUXHnp7Fmigp6RIJ4TCozglspL341y0rV8M7npU1FYZC2UKNr4ed+GOO1n/sF3LbXDlPXwne99CVVn85wjDaevoR7Md0y2KwE9EggLYcViXNehx4YVv/BjfgqxW8NxiKAxP6kPOZE0XdBrZj2rmcDcGOXCzzYpcduKhFyTOpA0K5RNGC3j1KOUjPVlOtLvjASP7udBEYNfH3mgqXAgqNDOEKi2jG9LITv2IyGUsXhTAsKNJ6A6qiDBzDrvPAYDvsfabPq6tRTwjA=\"\n                    },\n                    new Secret\n                    {\n                        Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                        Value =\n                            \"{'e':'AQAB','kid':'ZzAjSnraU3bkWGnnAqLapYGpTyNfLbjbzgAPbbW2GEA','kty':'RSA','n':'wWwQFtSzeRjjerpEM5Rmqz_DsNaZ9S1Bw6UbZkDLowuuTCjBWUax0vBMMxdy6XjEEK4Oq9lKMvx9JzjmeJf1knoqSNrox3Ka0rnxXpNAz6sATvme8p9mTXyp0cX4lF4U2J54xa2_S9NF5QWvpXvBeC4GAJx7QaSw4zrUkrc6XyaAiFnLhQEwKJCwUw4NOqIuYvYp_IXhw-5Ti_icDlZS-282PcccnBeOcX7vc21pozibIdmZJKqXNsL1Ibx5Nkx1F1jLnekJAmdaACDjYRLL_6n3W4wUp19UvzB1lGtXcJKLLkqB6YDiZNu16OSiSprfmrRXvYmvD8m6Fnl5aetgKw'}\"\n                    }\n                },\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" }\n            },\n\n            ///////////////////////////////////////////\n            // Custom Grant Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client.custom\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n                AllowedGrantTypes = { \"custom\", \"custom.nosubject\" },\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\" }\n            },\n\n            ///////////////////////////////////////////\n            // Console Resource Owner Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    \"custom.profile\",\n                    \"resource1.scope1\",\n                    \"resource2.scope1\"\n                },\n                \n                RefreshTokenUsage = TokenUsage.OneTimeOnly,\n                AbsoluteRefreshTokenLifetime = 3600 * 24,\n                SlidingRefreshTokenLifetime = 10,\n                RefreshTokenExpiration = TokenExpiration.Sliding\n            },\n\n            ///////////////////////////////////////////\n            // Console Public Resource Owner Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient.public\",\n                RequireClientSecret = false,\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\",\n                    \"resource2.scope1\"\n                }\n            },\n\n            ///////////////////////////////////////////\n            // Console with PKCE Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"console.pkce\",\n                ClientName = \"Console with PKCE Sample\",\n                RequireClientSecret = false,\n                AllowedGrantTypes = GrantTypes.Code,\n                RequirePkce = true,\n                RedirectUris = { \"http://127.0.0.1\" },\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\",\n                    \"resource2.scope1\"\n                }\n            },\n            ///////////////////////////////////////////\n            // WinConsole with PKCE Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"winconsole\",\n                ClientName = \"Windows Console with PKCE Sample\",\n                RequireClientSecret = false,\n                AllowedGrantTypes = GrantTypes.Code,\n                RequirePkce = true,\n                RedirectUris = { \"sample-windows-client://callback\" },\n                RequireConsent = false,\n                AllowOfflineAccess = true,\n                AllowedIdentityTokenSigningAlgorithms = { \"ES256\" },\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\",\n                    \"resource2.scope1\"\n                }\n            },\n\n\n            ///////////////////////////////////////////\n            // Introspection Client Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient.reference\",\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                AllowedScopes = { \"resource1.scope1\", \"resource2.scope1\", \"scope3\" },\n                AccessTokenType = AccessTokenType.Reference\n            },\n\n            ///////////////////////////////////////////\n            // Device Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"device\",\n                ClientName = \"Device Flow Client\",\n                AllowedGrantTypes = GrantTypes.DeviceFlow,\n                RequireClientSecret = false,\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Profile,\n                    IdentityServerConstants.StandardScopes.Email,\n                    \"resource1.scope1\",\n                    \"resource2.scope1\"\n                }\n            }\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Configuration/ClientsWeb.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Configuration;\n\npublic static class ClientsWeb\n{\n    static string[] allowedScopes = \n    {\n        IdentityServerConstants.StandardScopes.OpenId,\n        IdentityServerConstants.StandardScopes.Profile,\n        IdentityServerConstants.StandardScopes.Email,\n        \"resource1.scope1\", \n        \"resource2.scope1\",\n        \"transaction\"\n    };\n    \n    public static IEnumerable<Client> Get()\n    {\n        return new List<Client>\n        {\n            ///////////////////////////////////////////\n            // JS OIDC Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"js_oidc\",\n                ClientName = \"JavaScript OIDC Client\",\n                ClientUri = \"http://identityserver8.io\",\n                \n                AllowedGrantTypes = GrantTypes.Code,\n                RequireClientSecret = false,\n                \n                RedirectUris = \n                {\n                    \"https://localhost:44300/index.html\",\n                    \"https://localhost:44300/callback.html\",\n                    \"https://localhost:44300/silent.html\",\n                    \"https://localhost:44300/popup.html\"\n                },\n\n                PostLogoutRedirectUris = { \"https://localhost:44300/index.html\" },\n                AllowedCorsOrigins = { \"https://localhost:44300\" },\n\n                AllowedScopes = allowedScopes\n            },\n            \n            ///////////////////////////////////////////\n            // MVC Automatic Token Management Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mvc.tokenmanagement\",\n                \n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.Code,\n                RequirePkce = true,\n\n                AccessTokenLifetime = 75,\n\n                RedirectUris = { \"https://localhost:44301/signin-oidc\" },\n                FrontChannelLogoutUri = \"https://localhost:44301/signout-oidc\",\n                PostLogoutRedirectUris = { \"https://localhost:44301/signout-callback-oidc\" },\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes = allowedScopes\n            },\n            \n            ///////////////////////////////////////////\n            // MVC Code Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mvc.code\",\n                ClientName = \"MVC Code Flow\",\n                ClientUri = \"http://identityserver8.io\",\n\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                RequireConsent = true,\n                AllowedGrantTypes = GrantTypes.Code,\n\n                RedirectUris = { \"https://localhost:44302/signin-oidc\" },\n                FrontChannelLogoutUri = \"https://localhost:44302/signout-oidc\",\n                PostLogoutRedirectUris = { \"https://localhost:44302/signout-callback-oidc\" },\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes = allowedScopes\n            },\n            \n            ///////////////////////////////////////////\n            // MVC Hybrid Flow Sample (Back Channel logout)\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"mvc.hybrid.backchannel\",\n                ClientName = \"MVC Hybrid (with BackChannel logout)\",\n                ClientUri = \"http://identityserver8.io\",\n\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.Hybrid,\n                RequirePkce = false,\n\n                RedirectUris = { \"https://localhost:44303/signin-oidc\" },\n                BackChannelLogoutUri = \"https://localhost:44303/logout\",\n                PostLogoutRedirectUris = { \"https://localhost:44303/signout-callback-oidc\" },\n\n                AllowOfflineAccess = true,\n\n                AllowedScopes = allowedScopes\n            }\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Configuration/Resources.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Configuration;\n\npublic class Resources\n{\n    // identity resources represent identity data about a user that can be requested via the scope parameter (OpenID Connect)\n    public static readonly IEnumerable<IdentityResource> IdentityResources =\n        new[]\n        {\n            // some standard scopes from the OIDC spec\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n            new IdentityResources.Email(),\n\n            // custom identity resource with some consolidated claims\n            new IdentityResource(\"custom.profile\", new[] { JwtClaimTypes.Name, JwtClaimTypes.Email, \"location\", JwtClaimTypes.Address })\n        };\n\n    // API scopes represent values that describe scope of access and can be requested by the scope parameter (OAuth)\n    public static readonly IEnumerable<ApiScope> ApiScopes =\n        new[]\n        {\n            // local API scope\n            new ApiScope(LocalApi.ScopeName),\n\n            // resource specific scopes\n            new ApiScope(\"resource1.scope1\"),\n            new ApiScope(\"resource2.scope1\"), \n            \n            // a scope without resource association\n            new ApiScope(\"scope3\"),\n            \n            // a scope shared by multiple resources\n            new ApiScope(\"shared.scope\"),\n\n            // a parameterized scope\n            new ApiScope(\"transaction\", \"Transaction\")\n            {\n                Description = \"Some Transaction\"\n            }\n        };\n\n    // API resources are more formal representation of a resource with processing rules and their scopes (if any)\n    public static readonly IEnumerable<ApiResource> ApiResources = \n        new[]\n        {\n            new ApiResource(\"resource1\", \"Resource 1\")\n            {\n                ApiSecrets = { new Secret(\"secret\".Sha256()) },\n\n                Scopes = { \"resource1.scope1\", \"shared.scope\" }\n            },\n            \n            new ApiResource(\"resource2\", \"Resource 2\")\n            {\n                ApiSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                // additional claims to put into access token\n                UserClaims =\n                {\n                    JwtClaimTypes.Name,\n                    JwtClaimTypes.Email\n                },\n\n                Scopes = { \"resource2.scope1\", \"shared.scope\" }\n            }\n        };\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Extensions/ExtensionGrantValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Extensions;\n\npublic class ExtensionGrantValidator : IExtensionGrantValidator\n{\n    public Task ValidateAsync(ExtensionGrantValidationContext context)\n    {\n        var credential = context.Request.Raw.Get(\"custom_credential\");\n\n        if (credential != null)\n        {\n            context.Result = new GrantValidationResult(subject: \"818727\", authenticationMethod: \"custom\");\n        }\n        else\n        {\n            // custom error message\n            context.Result = new GrantValidationResult(TokenRequestErrors.InvalidGrant, \"invalid custom credential\");\n        }\n\n        return Task.CompletedTask;\n    }\n\n    public string GrantType\n    {\n        get { return \"custom\"; }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Extensions/HostProfileService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Extensions;\n\npublic class HostProfileService : TestUserProfileService\n{\n    public HostProfileService(TestUserStore users, ILogger<TestUserProfileService> logger) : base(users, logger)\n    {\n    }\n\n    public override async Task GetProfileDataAsync(ProfileDataRequestContext context)\n    {\n        await base.GetProfileDataAsync(context);\n\n        var transaction = context.RequestedResources.ParsedScopes.FirstOrDefault(x => x.ParsedName == \"transaction\");\n        if (transaction?.ParsedParameter != null)\n        {\n            context.IssuedClaims.Add(new Claim(\"transaction_id\", transaction.ParsedParameter));\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Extensions/NoSubjectExtensionGrantValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Extensions;\n\npublic class NoSubjectExtensionGrantValidator : IExtensionGrantValidator\n{\n    public Task ValidateAsync(ExtensionGrantValidationContext context)\n    {\n        var credential = context.Request.Raw.Get(\"custom_credential\");\n\n        if (credential != null)\n        {\n            context.Result = new GrantValidationResult();\n        }\n        else\n        {\n            // custom error message\n            context.Result = new GrantValidationResult(TokenRequestErrors.InvalidGrant, \"invalid custom credential\");\n        }\n\n        return Task.CompletedTask;\n    }\n\n    public string GrantType\n    {\n        get { return \"custom.nosubject\"; }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Extensions/ParameterizedScopeParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Extensions;\n\npublic class ParameterizedScopeParser : DefaultScopeParser\n{\n    public ParameterizedScopeParser(ILogger<DefaultScopeParser> logger) : base(logger)\n    {\n    }\n\n    public override void ParseScopeValue(ParseScopeContext scopeContext)\n    {\n        const string transactionScopeName = \"transaction\";\n        const string separator = \":\";\n        const string transactionScopePrefix = transactionScopeName + separator;\n\n        var scopeValue = scopeContext.RawValue;\n\n        if (scopeValue.StartsWith(transactionScopePrefix))\n        {\n            // we get in here with a scope like \"transaction:something\"\n            var parts = scopeValue.Split(separator, StringSplitOptions.RemoveEmptyEntries);\n            if (parts.Length == 2)\n            {\n                scopeContext.SetParsedValues(transactionScopeName, parts[1]);\n            }\n            else\n            {\n                scopeContext.SetError(\"transaction scope missing transaction parameter value\");\n            }\n        }\n        else if (scopeValue != transactionScopeName)\n        {\n            // we get in here with a scope not like \"transaction\"\n            base.ParseScopeValue(scopeContext);\n        }\n        else\n        {\n            // we get in here with a scope exactly \"transaction\", which is to say we're ignoring it \n            // and not including it in the results\n            scopeContext.SetIgnore();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Extensions/ParameterizedScopeTokenRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Extensions;\n\npublic class ParameterizedScopeTokenRequestValidator : ICustomTokenRequestValidator\n{\n    public Task ValidateAsync(CustomTokenRequestValidationContext context)\n    {\n        var transaction = context.Result.ValidatedRequest.ValidatedResources.ParsedScopes.FirstOrDefault(x => x.ParsedName == \"transaction\");\n        if (transaction?.ParsedParameter != null)\n        {\n            context.Result.ValidatedRequest.ClientClaims.Add(new Claim(transaction.ParsedName, transaction.ParsedParameter));\n        }\n\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Extensions/SameSiteHandlingExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Extensions;\n\n// copied from https://devblogs.microsoft.com/aspnet/upcoming-samesite-cookie-changes-in-asp-net-and-asp-net-core/\npublic static class SameSiteHandlingExtensions\n{\n    public static IServiceCollection AddSameSiteCookiePolicy(this IServiceCollection services)\n    {\n        services.Configure<CookiePolicyOptions>(options =>\n        {\n            options.MinimumSameSitePolicy = SameSiteMode.Unspecified;\n            options.OnAppendCookie = cookieContext => \n                CheckSameSite(cookieContext.Context, cookieContext.CookieOptions);\n            options.OnDeleteCookie = cookieContext => \n                CheckSameSite(cookieContext.Context, cookieContext.CookieOptions);\n        });\n\n        return services;\n    }\n    \n    private static void CheckSameSite(HttpContext httpContext, CookieOptions options)\n    {\n        if (options.SameSite == SameSiteMode.None)\n        {\n            var userAgent = httpContext.Request.Headers[\"User-Agent\"].ToString();\n            if (!httpContext.Request.IsHttps || DisallowsSameSiteNone(userAgent))\n            {\n                // For .NET Core < 3.1 set SameSite = (SameSiteMode)(-1)\n                options.SameSite = SameSiteMode.Unspecified;\n            }\n        }\n    }\n\n    private static bool DisallowsSameSiteNone(string userAgent)\n    {\n        // Cover all iOS based browsers here. This includes:\n        // - Safari on iOS 12 for iPhone, iPod Touch, iPad\n        // - WkWebview on iOS 12 for iPhone, iPod Touch, iPad\n        // - Chrome on iOS 12 for iPhone, iPod Touch, iPad\n        // All of which are broken by SameSite=None, because they use the iOS networking stack\n        if (userAgent.Contains(\"CPU iPhone OS 12\") || userAgent.Contains(\"iPad; CPU OS 12\"))\n        {\n            return true;\n        }\n\n        // Cover Mac OS X based browsers that use the Mac OS networking stack. This includes:\n        // - Safari on Mac OS X.\n        // This does not include:\n        // - Chrome on Mac OS X\n        // Because they do not use the Mac OS networking stack.\n        if (userAgent.Contains(\"Macintosh; Intel Mac OS X 10_14\") && \n            userAgent.Contains(\"Version/\") && userAgent.Contains(\"Safari\"))\n        {\n            return true;\n        }\n\n        // Cover Chrome 50-69, because some versions are broken by SameSite=None, \n        // and none in this range require it.\n        // Note: this covers some pre-Chromium Edge versions, \n        // but pre-Chromium Edge does not require SameSite=None.\n        if (userAgent.Contains(\"Chrome/5\") || userAgent.Contains(\"Chrome/6\"))\n        {\n            return true;\n        }\n\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.Configuration;\nglobal using IdentityServer8.Events;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Test;\nglobal using IdentityServer8.Validation;\nglobal using IdentityServerHost.Configuration;\nglobal using IdentityServerHost.Extensions;\nglobal using IdentityServerHost.Quickstart.UI;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authentication.Certificate;\nglobal using Microsoft.AspNetCore.Authorization;\nglobal using Microsoft.AspNetCore.HttpOverrides;\nglobal using Microsoft.AspNetCore.Mvc;\nglobal using Microsoft.AspNetCore.Mvc.Filters;\nglobal using Microsoft.Extensions.DependencyInjection;\nglobal using Microsoft.Extensions.Options;\nglobal using Microsoft.IdentityModel.Logging;\nglobal using Microsoft.IdentityModel.Tokens;\nglobal using Newtonsoft.Json;\nglobal using Serilog;\nglobal using Serilog.Events;\nglobal using Serilog.Sinks.SystemConsole.Themes;\nglobal using System.ComponentModel.DataAnnotations;\nglobal using System.Diagnostics;\nglobal using System.Security.Claims;\nglobal using System.Security.Cryptography.X509Certificates;\nglobal using System.Text;\nglobal using static IdentityServer8.IdentityServerConstants;\nglobal using ILogger = Microsoft.Extensions.Logging.ILogger;\nglobal using ClaimValueTypes = System.Security.Claims.ClaimValueTypes;\n"
  },
  {
    "path": "src/IdentityServer8/host/Host.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk.Web\">\n\n\n\n  <ItemGroup>\n    <Content Remove=\"compilerconfig.json\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <None Include=\"compilerconfig.json\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.AspNetCore.Authentication.Certificate\" />\n    \n    <PackageReference Include=\"Serilog.AspNetCore\" />\n\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.Sqlite\" />\n    <PackageReference Include=\"Microsoft.EntityFrameworkCore.Design\" PrivateAssets=\"All\" />\n    <PackageReference Include=\"System.Security.Principal.Windows\" />\n    \n    <ProjectReference Include=\"..\\src\\IdentityServer8.csproj\" />\n  </ItemGroup>\n</Project>"
  },
  {
    "path": "src/IdentityServer8/host/LocalApiController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost;\n\n[Route(\"localApi\")]\n[Authorize(LocalApi.PolicyName)]\npublic class LocalApiController : ControllerBase\n{\n    public IActionResult Get()\n    {\n        var claims = from c in User.Claims select new { c.Type, c.Value };\n        return new JsonResult(claims);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost;\n\npublic class Program\n{\n    public static int Main(string[] args)\n    {\n        Console.Title = \"IdentityServer8\";\n        Activity.DefaultIdFormat = ActivityIdFormat.W3C;\n\n        Log.Logger = new LoggerConfiguration()\n            .MinimumLevel.Debug()\n            .MinimumLevel.Override(\"Microsoft\", LogEventLevel.Warning)\n            .MinimumLevel.Override(\"Microsoft.Hosting.Lifetime\", LogEventLevel.Information)\n            .MinimumLevel.Override(\"System\", LogEventLevel.Warning)\n            .MinimumLevel.Override(\"Microsoft.AspNetCore.Authentication\", LogEventLevel.Information)\n            .Enrich.FromLogContext()\n            //.WriteTo.File(@\"IdentityServer8_log.txt\")\n            // uncomment to write to Azure diagnostics stream\n            //.WriteTo.File(\n            //    @\"D:\\home\\LogFiles\\Application\\identityserver.txt\",\n            //    fileSizeLimitBytes: 1_000_000,\n            //    rollOnFileSizeLimit: true,\n            //    shared: true,\n            //    flushToDiskInterval: TimeSpan.FromSeconds(1))\n            .WriteTo.Console(outputTemplate: \"[{Timestamp:HH:mm:ss} {Level}] {SourceContext}{NewLine}{Message:lj}{NewLine}{Exception}{NewLine}\", theme: AnsiConsoleTheme.Code)\n            .CreateLogger();\n\n        try\n        {\n            Log.Information(\"Starting host...\");\n            CreateHostBuilder(args).Build().Run();\n            return 0;\n        }\n        catch (Exception ex)\n        {\n            Log.Fatal(ex, \"Host terminated unexpectedly.\");\n            return 1;\n        }\n        finally\n        {\n            Log.CloseAndFlush();\n        }\n    }\n\n    public static IHostBuilder CreateHostBuilder(string[] args) =>\n        Host.CreateDefaultBuilder(args)\n            .UseSerilog()\n            .ConfigureWebHostDefaults(webBuilder =>\n            {\n                webBuilder.UseStartup<Startup>();\n            });\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Properties/launchSettings.json",
    "content": "{\n  \"profiles\": {\n    \"Host\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001;http://localhost:5000\"\n    },\n    \"Host (proxy)\": {\n      \"commandName\": \"Project\",\n      \"launchBrowser\": true,\n      \"launchUrl\": \"https://identityserver.local\",\n      \"environmentVariables\": {\n        \"ASPNETCORE_ENVIRONMENT\": \"Development\"\n      },\n      \"applicationUrl\": \"https://localhost:5001;http://localhost:5000\"\n    }\n  }\n}"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Account/AccountController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller implements a typical login/logout/provision workflow for local and external accounts.\n/// The login service encapsulates the interactions with the user data store. This data store is in-memory only and cannot be used for production!\n/// The interaction service provides a way for the UI to communicate with identityserver for validation and context retrieval\n/// </summary>\n[SecurityHeaders]\n[AllowAnonymous]\npublic class AccountController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly IAuthenticationSchemeProvider _schemeProvider;\n    private readonly IEventService _events;\n\n    public AccountController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IAuthenticationSchemeProvider schemeProvider,\n        IEventService events,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _schemeProvider = schemeProvider;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Entry point into the login workflow\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Login(string returnUrl)\n    {\n        // build a model so we know what to show on the login page\n        var vm = await BuildLoginViewModelAsync(returnUrl);\n\n        if (vm.IsExternalLoginOnly)\n        {\n            // we only have one option for logging in and it's an external provider\n            return returnUrl.IsAllowedRedirect() ? RedirectToAction(\"Challenge\", \"External\", new { scheme = vm.ExternalLoginScheme, returnUrl = returnUrl.SanitizeForRedirect() }) : Forbid();\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Login(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (ModelState.IsValid)\n        {\n            // validate username/password against in-memory store\n            if (_users.ValidateCredentials(model.Username, model.Password))\n            {\n                var user = _users.FindByUsername(model.Username);\n                await _events.RaiseAsync(new UserLoginSuccessEvent(user.Username, user.SubjectId, user.Username, clientId: context?.Client.ClientId));\n\n                // only set explicit expiration here if user chooses \"remember me\". \n                // otherwise we rely upon expiration configured in cookie middleware.\n                AuthenticationProperties props = null;\n                if (AccountOptions.AllowRememberLogin && model.RememberLogin)\n                {\n                    props = new AuthenticationProperties\n                    {\n                        IsPersistent = true,\n                        ExpiresUtc = DateTimeOffset.UtcNow.Add(AccountOptions.RememberMeLoginDuration)\n                    };\n                };\n\n                // issue authentication cookie with subject ID and username\n                var isuser = new IdentityServerUser(user.SubjectId)\n                {\n                    DisplayName = user.Username\n                };\n\n                await HttpContext.SignInAsync(isuser, props);\n\n                if (context != null)\n                {\n                    if (context.IsNativeClient())\n                    {\n                        // The client is native, so this change in how to\n                        // return the response is for better UX for the end user.\n                        return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                    }\n\n                    // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n\n                // request for a local page\n                if (Url.IsLocalUrl(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n                }\n                else if (string.IsNullOrEmpty(model.ReturnUrl))\n                {\n                    return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n                }\n                else\n                {\n                    // user might have clicked on a malicious link - should be logged\n                    throw new Exception(\"invalid return URL\");\n                }\n            }\n\n            await _events.RaiseAsync(new UserLoginFailureEvent(model.Username, \"invalid credentials\", clientId: context?.Client.ClientId));\n            ModelState.AddModelError(string.Empty, AccountOptions.InvalidCredentialsErrorMessage);\n        }\n\n        // something went wrong, show form with error\n        var vm = await BuildLoginViewModelAsync(model);\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle postback from username/password login\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> LoginCancel(LoginInputModel model)\n    {\n        // check if we are in the context of an authorization request\n        var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n\n        if (context != null)\n        {\n            // if the user cancels, send a result back into IdentityServer as if they \n            // denied the consent (even if this client does not require consent).\n            // this will send back an access denied OIDC error response to the client.\n            await _interaction.DenyAuthorizationAsync(context, AuthorizationError.AccessDenied);\n\n            // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return model.ReturnUrl.IsAllowedRedirect() ? this.LoadingPage(\"Redirect\", model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n            }\n\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(model.ReturnUrl.SanitizeForRedirect()) : Forbid();\n        }\n        else\n        {\n            // since we don't have a valid context, then we just go back to the home page\n            return model.ReturnUrl.IsAllowedRedirect() ? Redirect(\"~/\") : Forbid();\n        }\n\n    }\n\n    /// <summary>\n    /// Show logout page\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Logout(string logoutId)\n    {\n        // build a model so the logout page knows what to display\n        var vm = await BuildLogoutViewModelAsync(logoutId);\n\n        if (vm.ShowLogoutPrompt == false)\n        {\n            // if the request for logout was properly authenticated from IdentityServer, then\n            // we don't need to show the prompt and can just log the user out directly.\n            return await Logout(vm);\n        }\n\n        return View(vm);\n    }\n\n    /// <summary>\n    /// Handle logout page postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Logout(LogoutInputModel model)\n    {\n        // build a model so the logged out page knows what to display\n        var vm = await BuildLoggedOutViewModelAsync(model.LogoutId);\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            // delete local authentication cookie\n            await HttpContext.SignOutAsync();\n\n            // raise the logout event\n            await _events.RaiseAsync(new UserLogoutSuccessEvent(User.GetSubjectId(), User.GetDisplayName()));\n        }\n\n        // check if we need to trigger sign-out at an upstream identity provider\n        if (vm.TriggerExternalSignout)\n        {\n            // build a return URL so the upstream provider will redirect back\n            // to us after the user has logged out. this allows us to then\n            // complete our single sign-out processing.\n            string url = Url.Action(\"Logout\", new { logoutId = vm.LogoutId });\n\n            // this triggers a redirect to the external provider for sign-out\n            return SignOut(new AuthenticationProperties { RedirectUri = url }, vm.ExternalAuthenticationScheme);\n        }\n\n        return View(\"LoggedOut\", vm);\n    }\n\n    [HttpGet]\n    public IActionResult AccessDenied()\n    {\n        return View();\n    }\n\n\n    /*****************************************/\n    /* helper APIs for the AccountController */\n    /*****************************************/\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(string returnUrl)\n    {\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (context?.IdP != null && await _schemeProvider.GetSchemeAsync(context.IdP) != null)\n        {\n            var local = context.IdP == IdentityServer8.IdentityServerConstants.LocalIdentityProvider;\n\n            // this is meant to short circuit the UI and only trigger the one external IdP\n            var vm = new LoginViewModel\n            {\n                EnableLocalLogin = local,\n                ReturnUrl = returnUrl,\n                Username = context?.LoginHint,\n            };\n\n            if (!local)\n            {\n                vm.ExternalProviders = new[] { new ExternalProvider { AuthenticationScheme = context.IdP } };\n            }\n\n            return vm;\n        }\n\n        var schemes = await _schemeProvider.GetAllSchemesAsync();\n\n        var providers = schemes\n            .Where(x => x.DisplayName != null)\n            .Select(x => new ExternalProvider\n            {\n                DisplayName = x.DisplayName ?? x.Name,\n                AuthenticationScheme = x.Name\n            }).ToList();\n\n        var allowLocal = true;\n        if (context?.Client.ClientId != null)\n        {\n            var client = await _clientStore.FindEnabledClientByIdAsync(context.Client.ClientId);\n            if (client != null)\n            {\n                allowLocal = client.EnableLocalLogin;\n\n                if (client.IdentityProviderRestrictions != null && client.IdentityProviderRestrictions.Any())\n                {\n                    providers = providers.Where(provider => client.IdentityProviderRestrictions.Contains(provider.AuthenticationScheme)).ToList();\n                }\n            }\n        }\n\n        return new LoginViewModel\n        {\n            AllowRememberLogin = AccountOptions.AllowRememberLogin,\n            EnableLocalLogin = allowLocal && AccountOptions.AllowLocalLogin,\n            ReturnUrl = returnUrl,\n            Username = context?.LoginHint,\n            ExternalProviders = providers.ToArray()\n        };\n    }\n\n    private async Task<LoginViewModel> BuildLoginViewModelAsync(LoginInputModel model)\n    {\n        var vm = await BuildLoginViewModelAsync(model.ReturnUrl);\n        vm.Username = model.Username;\n        vm.RememberLogin = model.RememberLogin;\n        return vm;\n    }\n\n    private async Task<LogoutViewModel> BuildLogoutViewModelAsync(string logoutId)\n    {\n        var vm = new LogoutViewModel { LogoutId = logoutId, ShowLogoutPrompt = AccountOptions.ShowLogoutPrompt };\n\n        if (User?.Identity.IsAuthenticated != true)\n        {\n            // if the user is not authenticated, then just show logged out page\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        var context = await _interaction.GetLogoutContextAsync(logoutId);\n        if (context?.ShowSignoutPrompt == false)\n        {\n            // it's safe to automatically sign-out\n            vm.ShowLogoutPrompt = false;\n            return vm;\n        }\n\n        // show the logout prompt. this prevents attacks where the user\n        // is automatically signed out by another malicious web page.\n        return vm;\n    }\n\n    private async Task<LoggedOutViewModel> BuildLoggedOutViewModelAsync(string logoutId)\n    {\n        // get context information (client name, post logout redirect URI and iframe for federated signout)\n        var logout = await _interaction.GetLogoutContextAsync(logoutId);\n\n        var vm = new LoggedOutViewModel\n        {\n            AutomaticRedirectAfterSignOut = AccountOptions.AutomaticRedirectAfterSignOut,\n            PostLogoutRedirectUri = logout?.PostLogoutRedirectUri,\n            ClientName = string.IsNullOrEmpty(logout?.ClientName) ? logout?.ClientId : logout?.ClientName,\n            SignOutIframeUrl = logout?.SignOutIFrameUrl,\n            LogoutId = logoutId\n        };\n\n        if (User?.Identity.IsAuthenticated == true)\n        {\n            var idp = User.FindFirst(JwtClaimTypes.IdentityProvider)?.Value;\n            if (idp != null && idp != IdentityServer8.IdentityServerConstants.LocalIdentityProvider)\n            {\n                var providerSupportsSignout = await HttpContext.GetSchemeSupportsSignOutAsync(idp);\n                if (providerSupportsSignout)\n                {\n                    if (vm.LogoutId == null)\n                    {\n                        // if there's no current logout context, we need to create one\n                        // this captures necessary info from the current logged in user\n                        // before we signout and redirect away to the external IdP for signout\n                        vm.LogoutId = await _interaction.CreateLogoutContextAsync();\n                    }\n\n                    vm.ExternalAuthenticationScheme = idp;\n                }\n            }\n        }\n\n        return vm;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Account/AccountOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class AccountOptions\n{\n    public static bool AllowLocalLogin = true;\n    public static bool AllowRememberLogin = true;\n    public static TimeSpan RememberMeLoginDuration = TimeSpan.FromDays(30);\n\n    public static bool ShowLogoutPrompt = true;\n    public static bool AutomaticRedirectAfterSignOut = false;\n\n    public static string InvalidCredentialsErrorMessage = \"Invalid username or password\";\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Account/ExternalController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class ExternalController : Controller\n{\n    private readonly TestUserStore _users;\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clientStore;\n    private readonly ILogger<ExternalController> _logger;\n    private readonly IEventService _events;\n\n    public ExternalController(\n        IIdentityServerInteractionService interaction,\n        IClientStore clientStore,\n        IEventService events,\n        ILogger<ExternalController> logger,\n        TestUserStore users = null)\n    {\n        // if the TestUserStore is not in DI, then we'll just use the global users collection\n        // this is where you would plug in your own custom identity management library (e.g. ASP.NET Identity)\n        _users = users ?? new TestUserStore(TestUsers.Users);\n\n        _interaction = interaction;\n        _clientStore = clientStore;\n        _logger = logger;\n        _events = events;\n    }\n\n    /// <summary>\n    /// initiate roundtrip to external authentication provider\n    /// </summary>\n    [HttpGet]\n    public IActionResult Challenge(string scheme, string returnUrl)\n    {\n        if (string.IsNullOrEmpty(returnUrl)) returnUrl = \"~/\";\n\n        // validate returnUrl - either it is a valid OIDC URL or back to a local page\n        if (Url.IsLocalUrl(returnUrl) == false && _interaction.IsValidReturnUrl(returnUrl) == false)\n        {\n            // user might have clicked on a malicious link - should be logged\n            throw new Exception(\"invalid return URL\");\n        }\n        \n        // start challenge and roundtrip the return URL and scheme \n        var props = new AuthenticationProperties\n        {\n            RedirectUri = Url.Action(nameof(Callback)), \n            Items =\n            {\n                { \"returnUrl\", returnUrl }, \n                { \"scheme\", scheme },\n            }\n        };\n\n        return Challenge(props, scheme);\n        \n    }\n\n    /// <summary>\n    /// Post processing of external authentication\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Callback()\n    {\n        // read external identity from the temporary cookie\n        var result = await HttpContext.AuthenticateAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n        if (result?.Succeeded != true)\n        {\n            throw new Exception(\"External authentication error\");\n        }\n\n        if (_logger.IsEnabled(LogLevel.Debug))\n        {\n            var externalClaims = result.Principal.Claims.Select(c => $\"{c.Type}: {c.Value}\");\n            _logger.LogDebug(\"External claims: {@claims}\", externalClaims);\n        }\n\n        // lookup our user and external provider info\n        var (user, provider, providerUserId, claims) = FindUserFromExternalProvider(result);\n        if (user == null)\n        {\n            // this might be where you might initiate a custom workflow for user registration\n            // in this sample we don't show how that would be done, as our sample implementation\n            // simply auto-provisions new external user\n            user = AutoProvisionUser(provider, providerUserId, claims);\n        }\n\n        // this allows us to collect any additional claims or properties\n        // for the specific protocols used and store them in the local auth cookie.\n        // this is typically used to store data needed for signout from those protocols.\n        var additionalLocalClaims = new List<Claim>();\n        var localSignInProps = new AuthenticationProperties();\n        ProcessLoginCallback(result, additionalLocalClaims, localSignInProps);\n        \n        // issue authentication cookie for user\n        var isuser = new IdentityServerUser(user.SubjectId)\n        {\n            DisplayName = user.Username,\n            IdentityProvider = provider,\n            AdditionalClaims = additionalLocalClaims\n        };\n\n        await HttpContext.SignInAsync(isuser, localSignInProps);\n\n        // delete temporary cookie used during external authentication\n        await HttpContext.SignOutAsync(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n        // retrieve return URL\n        var returnUrl = result.Properties.Items[\"returnUrl\"] ?? \"~/\";\n\n        // check if external login is in the context of an OIDC request\n        var context = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        await _events.RaiseAsync(new UserLoginSuccessEvent(provider, providerUserId, user.SubjectId, user.Username, true, context?.Client.ClientId));\n\n        if (context != null)\n        {\n            if (context.IsNativeClient())\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", returnUrl);\n            }\n        }\n\n        return Redirect(returnUrl);\n    }\n\n    private (TestUser user, string provider, string providerUserId, IEnumerable<Claim> claims) FindUserFromExternalProvider(AuthenticateResult result)\n    {\n        var externalUser = result.Principal;\n\n        // try to determine the unique id of the external user (issued by the provider)\n        // the most common claim type for that are the sub claim and the NameIdentifier\n        // depending on the external provider, some other claim type might be used\n        var userIdClaim = externalUser.FindFirst(JwtClaimTypes.Subject) ??\n                          externalUser.FindFirst(ClaimTypes.NameIdentifier) ??\n                          throw new Exception(\"Unknown userid\");\n\n        // remove the user id claim so we don't include it as an extra claim if/when we provision the user\n        var claims = externalUser.Claims.ToList();\n        claims.Remove(userIdClaim);\n\n        var provider = result.Properties.Items[\"scheme\"];\n        var providerUserId = userIdClaim.Value;\n\n        // find external user\n        var user = _users.FindByExternalProvider(provider, providerUserId);\n\n        return (user, provider, providerUserId, claims);\n    }\n\n    private TestUser AutoProvisionUser(string provider, string providerUserId, IEnumerable<Claim> claims)\n    {\n        var user = _users.AutoProvisionUser(provider, providerUserId, claims.ToList());\n        return user;\n    }\n\n    // if the external login is OIDC-based, there are certain things we need to preserve to make logout work\n    // this will be different for WS-Fed, SAML2p or other protocols\n    private void ProcessLoginCallback(AuthenticateResult externalResult, List<Claim> localClaims, AuthenticationProperties localSignInProps)\n    {\n        // if the external system sent a session id claim, copy it over\n        // so we can use it for single sign-out\n        var sid = externalResult.Principal.Claims.FirstOrDefault(x => x.Type == JwtClaimTypes.SessionId);\n        if (sid != null)\n        {\n            localClaims.Add(new Claim(JwtClaimTypes.SessionId, sid.Value));\n        }\n\n        // if the external provider issued an id_token, we'll keep it for signout\n        var idToken = externalResult.Properties.GetTokenValue(\"id_token\");\n        if (idToken != null)\n        {\n            localSignInProps.StoreTokens(new[] { new AuthenticationToken { Name = \"id_token\", Value = idToken } });\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Account/ExternalProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ExternalProvider\n{\n    public string DisplayName { get; set; }\n    public string AuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Account/LoggedOutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoggedOutViewModel\n{\n    public string PostLogoutRedirectUri { get; set; }\n    public string ClientName { get; set; }\n    public string SignOutIframeUrl { get; set; }\n\n    public bool AutomaticRedirectAfterSignOut { get; set; }\n\n    public string LogoutId { get; set; }\n    public bool TriggerExternalSignout => ExternalAuthenticationScheme != null;\n    public string ExternalAuthenticationScheme { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Account/LoginInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginInputModel\n{\n    [Required]\n    public string Username { get; set; }\n    [Required]\n    public string Password { get; set; }\n    public bool RememberLogin { get; set; }\n    public string ReturnUrl { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Account/LoginViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LoginViewModel : LoginInputModel\n{\n    public bool AllowRememberLogin { get; set; } = true;\n    public bool EnableLocalLogin { get; set; } = true;\n\n    public IEnumerable<ExternalProvider> ExternalProviders { get; set; } = Enumerable.Empty<ExternalProvider>();\n    public IEnumerable<ExternalProvider> VisibleExternalProviders => ExternalProviders.Where(x => !String.IsNullOrWhiteSpace(x.DisplayName));\n\n    public bool IsExternalLoginOnly => EnableLocalLogin == false && ExternalProviders?.Count() == 1;\n    public string ExternalLoginScheme => IsExternalLoginOnly ? ExternalProviders?.SingleOrDefault()?.AuthenticationScheme : null;\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Account/LogoutInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutInputModel\n{\n    public string LogoutId { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Account/LogoutViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class LogoutViewModel : LogoutInputModel\n{\n    public bool ShowLogoutPrompt { get; set; } = true;\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Account/RedirectViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class RedirectViewModel\n{\n    public string RedirectUrl { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Consent/ConsentController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This controller processes the consent UI\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class ConsentController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly ILogger<ConsentController> _logger;\n\n    public ConsentController(\n        IIdentityServerInteractionService interaction,\n        IEventService events,\n        ILogger<ConsentController> logger)\n    {\n        _interaction = interaction;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Shows the consent screen\n    /// </summary>\n    /// <param name=\"returnUrl\"></param>\n    /// <returns></returns>\n    [HttpGet]\n    public async Task<IActionResult> Index(string returnUrl)\n    {\n        var vm = await BuildViewModelAsync(returnUrl);\n        if (vm != null)\n        {\n            return View(\"Index\", vm);\n        }\n\n        return View(\"Error\");\n    }\n\n    /// <summary>\n    /// Handles the consent screen postback\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Index(ConsentInputModel model)\n    {\n        var result = await ProcessConsent(model);\n\n        if (result.IsRedirect)\n        {\n            var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n            if (context?.IsNativeClient() == true)\n            {\n                // The client is native, so this change in how to\n                // return the response is for better UX for the end user.\n                return this.LoadingPage(\"Redirect\", result.RedirectUri);\n            }\n            return result.RedirectUri.IsAllowedRedirect() ? Redirect(result.RedirectUri.SanitizeForRedirect()) : Forbid();\n        }\n\n        if (result.HasValidationError)\n        {\n            ModelState.AddModelError(string.Empty, result.ValidationError);\n        }\n\n        if (result.ShowView)\n        {\n            return View(\"Index\", result.ViewModel);\n        }\n\n        return View(\"Error\");\n    }\n\n    /*****************************************/\n    /* helper APIs for the ConsentController */\n    /*****************************************/\n    private async Task<ProcessConsentResult> ProcessConsent(ConsentInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        // validate return url is still valid\n        var request = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model?.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model?.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.GrantConsentAsync(request, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.ReturnUrl, model);\n        }\n\n        return result;\n    }\n\n    private async Task<ConsentViewModel> BuildViewModelAsync(string returnUrl, ConsentInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(returnUrl);\n        if (request != null)\n        {\n            return CreateConsentViewModel(model, returnUrl, request);\n        }\n        else\n        {\n            _logger.LogError(\"No consent request matching request: {0}\", returnUrl.SanitizeForLog());\n        }\n\n        return null;\n    }\n\n    private ConsentViewModel CreateConsentViewModel(\n        ConsentInputModel model, string returnUrl,\n        AuthorizationRequest request)\n    {\n        var vm = new ConsentViewModel\n        {\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n            Description = model?.Description,\n\n            ReturnUrl = returnUrl,\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach(var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        var displayName = apiScope.DisplayName ?? apiScope.Name;\n        if (!String.IsNullOrWhiteSpace(parsedScopeValue.ParsedParameter))\n        {\n            displayName += \":\" + parsedScopeValue.ParsedParameter;\n        }\n\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            DisplayName = displayName,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Consent/ConsentInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentInputModel\n{\n    public string Button { get; set; }\n    public IEnumerable<string> ScopesConsented { get; set; }\n    public bool RememberConsent { get; set; }\n    public string ReturnUrl { get; set; }\n    public string Description { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Consent/ConsentOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentOptions\n{\n    public static bool EnableOfflineAccess = true;\n    public static string OfflineAccessDisplayName = \"Offline Access\";\n    public static string OfflineAccessDescription = \"Access to your applications and resources, even when you are offline\";\n\n    public static readonly string MustChooseOneErrorMessage = \"You must pick at least one permission\";\n    public static readonly string InvalidSelectionErrorMessage = \"Invalid selection\";\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Consent/ConsentViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ConsentViewModel : ConsentInputModel\n{\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public bool AllowRememberConsent { get; set; }\n\n    public IEnumerable<ScopeViewModel> IdentityScopes { get; set; }\n    public IEnumerable<ScopeViewModel> ApiScopes { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Consent/ProcessConsentResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ProcessConsentResult\n{\n    public bool IsRedirect => RedirectUri != null;\n    public string RedirectUri { get; set; }\n    public Client Client { get; set; }\n\n    public bool ShowView => ViewModel != null;\n    public ConsentViewModel ViewModel { get; set; }\n\n    public bool HasValidationError => ValidationError != null;\n    public string ValidationError { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Consent/ScopeViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ScopeViewModel\n{\n    public string Value { get; set; }\n    public string DisplayName { get; set; }\n    public string Description { get; set; }\n    public bool Emphasize { get; set; }\n    public bool Required { get; set; }\n    public bool Checked { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Device/DeviceAuthorizationInputModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationInputModel : ConsentInputModel\n{\n    public string UserCode { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Device/DeviceAuthorizationViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DeviceAuthorizationViewModel : ConsentViewModel\n{\n    public string UserCode { get; set; }\n    public bool ConfirmUserCode { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Device/DeviceController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[Authorize]\n[SecurityHeaders]\npublic class DeviceController : Controller\n{\n    private readonly IDeviceFlowInteractionService _interaction;\n    private readonly IEventService _events;\n    private readonly IOptions<IdentityServerOptions> _options;\n    private readonly ILogger<DeviceController> _logger;\n\n    public DeviceController(\n        IDeviceFlowInteractionService interaction,\n        IEventService eventService,\n        IOptions<IdentityServerOptions> options,\n        ILogger<DeviceController> logger)\n    {\n        _interaction = interaction;\n        _events = eventService;\n        _options = options;\n        _logger = logger;\n    }\n\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        string userCodeParamName = _options.Value.UserInteraction.DeviceVerificationUserCodeParameter;\n        string userCode = Request.Query[userCodeParamName];\n        if (string.IsNullOrWhiteSpace(userCode)) return View(\"UserCodeCapture\");\n\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        vm.ConfirmUserCode = true;\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> UserCodeCapture(string userCode)\n    {\n        var vm = await BuildViewModelAsync(userCode);\n        if (vm == null) return View(\"Error\");\n\n        return View(\"UserCodeConfirmation\", vm);\n    }\n\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Callback(DeviceAuthorizationInputModel model)\n    {\n        if (model == null) throw new ArgumentNullException(nameof(model));\n\n        var result = await ProcessConsent(model);\n        if (result.HasValidationError) return View(\"Error\");\n\n        return View(\"Success\");\n    }\n\n    private async Task<ProcessConsentResult> ProcessConsent(DeviceAuthorizationInputModel model)\n    {\n        var result = new ProcessConsentResult();\n\n        var request = await _interaction.GetAuthorizationContextAsync(model.UserCode);\n        if (request == null) return result;\n\n        ConsentResponse grantedConsent = null;\n\n        // user clicked 'no' - send back the standard 'access_denied' response\n        if (model.Button == \"no\")\n        {\n            grantedConsent = new ConsentResponse { Error = AuthorizationError.AccessDenied };\n\n            // emit event\n            await _events.RaiseAsync(new ConsentDeniedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues));\n        }\n        // user clicked 'yes' - validate the data\n        else if (model.Button == \"yes\")\n        {\n            // if the user consented to some scope, build the response model\n            if (model.ScopesConsented != null && model.ScopesConsented.Any())\n            {\n                var scopes = model.ScopesConsented;\n                if (ConsentOptions.EnableOfflineAccess == false)\n                {\n                    scopes = scopes.Where(x => x != IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n\n                grantedConsent = new ConsentResponse\n                {\n                    RememberConsent = model.RememberConsent,\n                    ScopesValuesConsented = scopes.ToArray(),\n                    Description = model.Description\n                };\n\n                // emit event\n                await _events.RaiseAsync(new ConsentGrantedEvent(User.GetSubjectId(), request.Client.ClientId, request.ValidatedResources.RawScopeValues, grantedConsent.ScopesValuesConsented, grantedConsent.RememberConsent));\n            }\n            else\n            {\n                result.ValidationError = ConsentOptions.MustChooseOneErrorMessage;\n            }\n        }\n        else\n        {\n            result.ValidationError = ConsentOptions.InvalidSelectionErrorMessage;\n        }\n\n        if (grantedConsent != null)\n        {\n            // communicate outcome of consent back to identityserver\n            await _interaction.HandleRequestAsync(model.UserCode, grantedConsent);\n\n            // indicate that's it ok to redirect back to authorization endpoint\n            result.RedirectUri = model.ReturnUrl;\n            result.Client = request.Client;\n        }\n        else\n        {\n            // we need to redisplay the consent UI\n            result.ViewModel = await BuildViewModelAsync(model.UserCode, model);\n        }\n\n        return result;\n    }\n\n    private async Task<DeviceAuthorizationViewModel> BuildViewModelAsync(string userCode, DeviceAuthorizationInputModel model = null)\n    {\n        var request = await _interaction.GetAuthorizationContextAsync(userCode);\n        if (request != null)\n        {\n            return CreateConsentViewModel(userCode, model, request);\n        }\n\n        return null;\n    }\n\n    private DeviceAuthorizationViewModel CreateConsentViewModel(string userCode, DeviceAuthorizationInputModel model, DeviceFlowAuthorizationRequest request)\n    {\n        var vm = new DeviceAuthorizationViewModel\n        {\n            UserCode = userCode,\n            Description = model?.Description,\n\n            RememberConsent = model?.RememberConsent ?? true,\n            ScopesConsented = model?.ScopesConsented ?? Enumerable.Empty<string>(),\n\n            ClientName = request.Client.ClientName ?? request.Client.ClientId,\n            ClientUrl = request.Client.ClientUri,\n            ClientLogoUrl = request.Client.LogoUri,\n            AllowRememberConsent = request.Client.AllowRememberConsent\n        };\n\n        vm.IdentityScopes = request.ValidatedResources.Resources.IdentityResources.Select(x => CreateScopeViewModel(x, vm.ScopesConsented.Contains(x.Name) || model == null)).ToArray();\n\n        var apiScopes = new List<ScopeViewModel>();\n        foreach (var parsedScope in request.ValidatedResources.ParsedScopes)\n        {\n            var apiScope = request.ValidatedResources.Resources.FindApiScope(parsedScope.ParsedName);\n            if (apiScope != null)\n            {\n                var scopeVm = CreateScopeViewModel(parsedScope, apiScope, vm.ScopesConsented.Contains(parsedScope.RawValue) || model == null);\n                apiScopes.Add(scopeVm);\n            }\n        }\n        if (ConsentOptions.EnableOfflineAccess && request.ValidatedResources.Resources.OfflineAccess)\n        {\n            apiScopes.Add(GetOfflineAccessScope(vm.ScopesConsented.Contains(IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess) || model == null));\n        }\n        vm.ApiScopes = apiScopes;\n\n        return vm;\n    }\n\n    private ScopeViewModel CreateScopeViewModel(IdentityResource identity, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = identity.Name,\n            DisplayName = identity.DisplayName ?? identity.Name,\n            Description = identity.Description,\n            Emphasize = identity.Emphasize,\n            Required = identity.Required,\n            Checked = check || identity.Required\n        };\n    }\n\n    public ScopeViewModel CreateScopeViewModel(ParsedScopeValue parsedScopeValue, ApiScope apiScope, bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = parsedScopeValue.RawValue,\n            // todo: use the parsed scope value in the display?\n            DisplayName = apiScope.DisplayName ?? apiScope.Name,\n            Description = apiScope.Description,\n            Emphasize = apiScope.Emphasize,\n            Required = apiScope.Required,\n            Checked = check || apiScope.Required\n        };\n    }\n    private ScopeViewModel GetOfflineAccessScope(bool check)\n    {\n        return new ScopeViewModel\n        {\n            Value = IdentityServer8.IdentityServerConstants.StandardScopes.OfflineAccess,\n            DisplayName = ConsentOptions.OfflineAccessDisplayName,\n            Description = ConsentOptions.OfflineAccessDescription,\n            Emphasize = true,\n            Checked = check\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Diagnostics/DiagnosticsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[Authorize]\npublic class DiagnosticsController : Controller\n{\n    public async Task<IActionResult> Index()\n    {\n        var localAddresses = new string[] { \"127.0.0.1\", \"::1\", HttpContext.Connection.LocalIpAddress.ToString() };\n        if (!localAddresses.Contains(HttpContext.Connection.RemoteIpAddress.ToString()))\n        {\n            return NotFound();\n        }\n\n        var model = new DiagnosticsViewModel(await HttpContext.AuthenticateAsync());\n        return View(model);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Diagnostics/DiagnosticsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class DiagnosticsViewModel\n{\n    public DiagnosticsViewModel(AuthenticateResult result)\n    {\n        AuthenticateResult = result;\n\n        if (result.Properties.Items.ContainsKey(\"client_list\"))\n        {\n            var encoded = result.Properties.Items[\"client_list\"];\n            var bytes = Base64Url.Decode(encoded);\n            var value = Encoding.UTF8.GetString(bytes);\n\n            Clients = JsonConvert.DeserializeObject<string[]>(value);\n        }\n    }\n\n    public AuthenticateResult AuthenticateResult { get; }\n    public IEnumerable<string> Clients { get; } = new List<string>();\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Extensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic static class Extensions\n{\n    /// <summary>\n    /// Checks if the redirect URI is for a native client.\n    /// </summary>\n    /// <returns></returns>\n    public static bool IsNativeClient(this AuthorizationRequest context)\n    {\n        return !context.RedirectUri.StartsWith(\"https\", StringComparison.Ordinal)\n           && !context.RedirectUri.StartsWith(\"http\", StringComparison.Ordinal);\n    }\n\n    public static IActionResult LoadingPage(this Controller controller, string viewName, string redirectUri)\n    {\n        controller.HttpContext.Response.StatusCode = 200;\n        controller.HttpContext.Response.Headers[\"Location\"] = \"\";\n        \n        return controller.View(viewName, new RedirectViewModel { RedirectUrl = redirectUri });\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Grants/GrantsController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n/// <summary>\n/// This sample controller allows a user to revoke grants given to clients\n/// </summary>\n[SecurityHeaders]\n[Authorize]\npublic class GrantsController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IClientStore _clients;\n    private readonly IResourceStore _resources;\n    private readonly IEventService _events;\n\n    public GrantsController(IIdentityServerInteractionService interaction,\n        IClientStore clients,\n        IResourceStore resources,\n        IEventService events)\n    {\n        _interaction = interaction;\n        _clients = clients;\n        _resources = resources;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Show list of grants\n    /// </summary>\n    [HttpGet]\n    public async Task<IActionResult> Index()\n    {\n        return View(\"Index\", await BuildViewModelAsync());\n    }\n\n    /// <summary>\n    /// Handle postback to revoke a client\n    /// </summary>\n    [HttpPost]\n    [ValidateAntiForgeryToken]\n    public async Task<IActionResult> Revoke(string clientId)\n    {\n        await _interaction.RevokeUserConsentAsync(clientId);\n        await _events.RaiseAsync(new GrantsRevokedEvent(User.GetSubjectId(), clientId));\n\n        return RedirectToAction(\"Index\");\n    }\n\n    private async Task<GrantsViewModel> BuildViewModelAsync()\n    {\n        var grants = await _interaction.GetAllUserGrantsAsync();\n\n        var list = new List<GrantViewModel>();\n        foreach(var grant in grants)\n        {\n            var client = await _clients.FindClientByIdAsync(grant.ClientId);\n            if (client != null)\n            {\n                var resources = await _resources.FindResourcesByScopeAsync(grant.Scopes);\n\n                var item = new GrantViewModel()\n                {\n                    ClientId = client.ClientId,\n                    ClientName = client.ClientName ?? client.ClientId,\n                    ClientLogoUrl = client.LogoUri,\n                    ClientUrl = client.ClientUri,\n                    Description = grant.Description,\n                    Created = grant.CreationTime,\n                    Expires = grant.Expiration,\n                    IdentityGrantNames = resources.IdentityResources.Select(x => x.DisplayName ?? x.Name).ToArray(),\n                    ApiGrantNames = resources.ApiScopes.Select(x => x.DisplayName ?? x.Name).ToArray()\n                };\n\n                list.Add(item);\n            }\n        }\n\n        return new GrantsViewModel\n        {\n            Grants = list\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Grants/GrantsViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class GrantsViewModel\n{\n    public IEnumerable<GrantViewModel> Grants { get; set; }\n}\n\npublic class GrantViewModel\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string ClientUrl { get; set; }\n    public string ClientLogoUrl { get; set; }\n    public string Description { get; set; }\n    public DateTime Created { get; set; }\n    public DateTime? Expires { get; set; }\n    public IEnumerable<string> IdentityGrantNames { get; set; }\n    public IEnumerable<string> ApiGrantNames { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Home/ErrorViewModel.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class ErrorViewModel\n{\n    public ErrorViewModel()\n    {\n    }\n\n    public ErrorViewModel(string error)\n    {\n        Error = new ErrorMessage { Error = error };\n    }\n\n    public ErrorMessage Error { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/Home/HomeController.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\n[SecurityHeaders]\n[AllowAnonymous]\npublic class HomeController : Controller\n{\n    private readonly IIdentityServerInteractionService _interaction;\n    private readonly IWebHostEnvironment _environment;\n    private readonly ILogger _logger;\n\n    public HomeController(IIdentityServerInteractionService interaction, IWebHostEnvironment environment, ILogger<HomeController> logger)\n    {\n        _interaction = interaction;\n        _environment = environment;\n        _logger = logger;\n    }\n\n    public IActionResult Index()\n    {\n        if (_environment.IsDevelopment())\n        {\n            // only show in development\n            return View();\n        }\n\n        _logger.LogInformation(\"Homepage is disabled in production. Returning 404.\");\n        return NotFound();\n    }\n\n    /// <summary>\n    /// Shows the error page\n    /// </summary>\n    public async Task<IActionResult> Error(string errorId)\n    {\n        var vm = new ErrorViewModel();\n\n        // retrieve error details from identityserver\n        var message = await _interaction.GetErrorContextAsync(errorId);\n        if (message != null)\n        {\n            vm.Error = message;\n\n            if (!_environment.IsDevelopment())\n            {\n                // only show in development\n                message.ErrorDescription = null;\n            }\n        }\n\n        return View(\"Error\", vm);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/SecurityHeadersAttribute.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class SecurityHeadersAttribute : ActionFilterAttribute\n{\n    public override void OnResultExecuting(ResultExecutingContext context)\n    {\n        var result = context.Result;\n        if (result is ViewResult)\n        {\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Content-Type-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Type-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Type-Options\", \"nosniff\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/X-Frame-Options\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Frame-Options\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Frame-Options\", \"SAMEORIGIN\");\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy\n            var csp = \"default-src 'self'; object-src 'none'; frame-ancestors 'none'; sandbox allow-forms allow-same-origin allow-scripts; base-uri 'self';\";\n            // also consider adding upgrade-insecure-requests once you have HTTPS in place for production\n            //csp += \"upgrade-insecure-requests;\";\n            // also an example if you need client images to be displayed from twitter\n            // csp += \"img-src 'self' https://pbs.twimg.com;\";\n\n            // once for standards compliant browsers\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Content-Security-Policy\", csp);\n            }\n            // and once again for IE\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"X-Content-Security-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"X-Content-Security-Policy\", csp);\n            }\n\n            // https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy\n            var referrer_policy = \"no-referrer\";\n            if (!context.HttpContext.Response.Headers.ContainsKey(\"Referrer-Policy\"))\n            {\n                context.HttpContext.Response.Headers.Append(\"Referrer-Policy\", referrer_policy);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Quickstart/TestUsers.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing JsonSerializer = System.Text.Json.JsonSerializer;\n\nnamespace IdentityServerHost.Quickstart.UI;\n\npublic class TestUsers\n{\n    public static List<TestUser> Users\n    {\n        get\n        {\n            var address = new\n            {\n                street_address = \"One Hacker Way\",\n                locality = \"Heidelberg\",\n                postal_code = 69118,\n                country = \"Germany\"\n            };\n            \n            return new List<TestUser>\n            {\n                new TestUser\n                {\n                    SubjectId = \"818727\",\n                    Username = \"alice\",\n                    Password = \"alice\",\n                    Claims =\n                    {\n                        new Claim(JwtClaimTypes.Name, \"Alice Smith\"),\n                        new Claim(JwtClaimTypes.GivenName, \"Alice\"),\n                        new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                        new Claim(JwtClaimTypes.Email, \"AliceSmith@email.com\"),\n                        new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                        new Claim(JwtClaimTypes.WebSite, \"http://alice.com\"),\n                        new Claim(JwtClaimTypes.Address, JsonSerializer.Serialize(address), IdentityServerConstants.ClaimValueTypes.Json)\n                    }\n                },\n                new TestUser\n                {\n                    SubjectId = \"88421113\",\n                    Username = \"bob\",\n                    Password = \"bob\",\n                    Claims =\n                    {\n                        new Claim(JwtClaimTypes.Name, \"Bob Smith\"),\n                        new Claim(JwtClaimTypes.GivenName, \"Bob\"),\n                        new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                        new Claim(JwtClaimTypes.Email, \"BobSmith@email.com\"),\n                        new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                        new Claim(JwtClaimTypes.WebSite, \"http://bob.com\"),\n                        new Claim(JwtClaimTypes.Address, JsonSerializer.Serialize(address), IdentityServerConstants.ClaimValueTypes.Json)\n                    }\n                }\n            };\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Resources = IdentityServerHost.Configuration.Resources;\nusing IdentityServerHost.Extensions;\n\nnamespace IdentityServerHost;\n\npublic class Startup\n{\n    private readonly IConfiguration _config;\n\n    public Startup(IConfiguration config)\n    {\n        _config = config;\n\n        IdentityModelEventSource.ShowPII = true;\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        services.AddControllersWithViews();\n        \n        // cookie policy to deal with temporary browser incompatibilities\n        services.AddSameSiteCookiePolicy();\n\n        var builder = services.AddIdentityServer(options =>\n            {\n                options.Events.RaiseSuccessEvents = true;\n                options.Events.RaiseFailureEvents = true;\n                options.Events.RaiseErrorEvents = true;\n                options.Events.RaiseInformationEvents = true;\n\n                options.EmitScopesAsSpaceDelimitedStringInJwt = true;\n\n                options.MutualTls.Enabled = true;\n                options.MutualTls.DomainName = \"mtls\";\n                //options.MutualTls.AlwaysEmitConfirmationClaim = true;\n            })\n            .AddInMemoryClients(Clients.Get())\n            .AddInMemoryIdentityResources(Resources.IdentityResources)\n            .AddInMemoryApiScopes(Resources.ApiScopes)\n            .AddInMemoryApiResources(Resources.ApiResources)\n            .AddSigningCredential()\n            .AddExtensionGrantValidator<Extensions.ExtensionGrantValidator>()\n            .AddExtensionGrantValidator<Extensions.NoSubjectExtensionGrantValidator>()\n            .AddJwtBearerClientAuthentication()\n            .AddAppAuthRedirectUriValidator()\n            .AddTestUsers(TestUsers.Users)\n            .AddProfileService<HostProfileService>()\n            .AddCustomTokenRequestValidator<ParameterizedScopeTokenRequestValidator>()\n            .AddScopeParser<ParameterizedScopeParser>()\n            .AddMutualTlsSecretValidators();\n\n        // use this for persisted grants store\n        // var migrationsAssembly = typeof(Startup).GetTypeInfo().Assembly.GetName().Name;\n        // const string connectionString = \"DataSource=identityserver.db\";\n        // builder.AddOperationalStore(options =>\n        // {\n        //     options.ConfigureDbContext = b => b.UseSqlite(connectionString,\n        //         sql => sql.MigrationsAssembly(migrationsAssembly));\n        // });\n            \n\n        services.AddExternalIdentityProviders();\n\n        services.AddAuthentication()\n            .AddCertificate(options =>\n            {\n                options.AllowedCertificateTypes = CertificateTypes.All;\n                options.RevocationMode = X509RevocationMode.NoCheck;\n            });\n        \n        services.AddCertificateForwardingForNginx();\n        \n        services.AddLocalApiAuthentication(principal =>\n        {\n            principal.Identities.First().AddClaim(new Claim(\"additional_claim\", \"additional_value\"));\n\n            return Task.FromResult(principal);\n        });\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n        // use this for persisted grants store\n        // app.InitializePersistedGrantsStore();\n        \n        app.UseForwardedHeaders(new ForwardedHeadersOptions\n        {\n            ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto\n        });\n\n        app.UseCertificateForwarding();\n        app.UseCookiePolicy();\n        \n        app.UseSerilogRequestLogging();\n\n        app.UseDeveloperExceptionPage();\n        app.UseStaticFiles();\n\n        app.UseRouting();\n        app.UseIdentityServer();\n\n        app.UseAuthorization();\n\n        app.UseEndpoints(endpoints =>\n        {\n            endpoints.MapDefaultControllerRoute();\n        });\n    }\n}\n\npublic static class BuilderExtensions\n{\n    public static IIdentityServerBuilder AddSigningCredential(this IIdentityServerBuilder builder)\n    {\n        // create random RS256 key\n        //builder.AddDeveloperSigningCredential();\n\n        // use an RSA-based certificate with RS256\n        var rsaCert = new X509Certificate2(\"./keys/identityserver.test.rsa.p12\", \"changeit\");\n        builder.AddSigningCredential(rsaCert, \"RS256\");\n\n        // ...and PS256\n        builder.AddSigningCredential(rsaCert, \"PS256\");\n\n        // or manually extract ECDSA key from certificate (directly using the certificate is not support by Microsoft right now)\n        var ecCert = new X509Certificate2(\"./keys/identityserver.test.ecdsa.p12\", \"changeit\");\n        var key = new ECDsaSecurityKey(ecCert.GetECDsaPrivateKey())\n        {\n            KeyId = CryptoRandom.CreateUniqueId(16, CryptoRandom.OutputFormat.Hex)\n        };\n\n        return builder.AddSigningCredential(\n            key,\n            IdentityServerConstants.ECDsaSigningAlgorithm.ES256);\n    }\n\n    // use this for persisted grants store\n    // public static void InitializePersistedGrantsStore(this IApplicationBuilder app)\n    // {\n    //     using (var serviceScope = app.ApplicationServices.GetService<IServiceScopeFactory>().CreateScope())\n    //     {\n    //         serviceScope.ServiceProvider.GetRequiredService<PersistedGrantDbContext>().Database.Migrate();\n    //     }\n    // }\n}\n\npublic static class ServiceExtensions\n{\n    public static IServiceCollection AddExternalIdentityProviders(this IServiceCollection services)\n    {\n        // configures the OpenIdConnect handlers to persist the state parameter into the server-side IDistributedCache.\n        services.AddOidcStateDataFormatterCache(\"aad\", \"demoidsrv\");\n\n        services.AddAuthentication()\n            .AddOpenIdConnect(\"Google\", \"Google\", options =>\n             {\n                 options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n                 options.ForwardSignOut = IdentityServerConstants.DefaultCookieAuthenticationScheme;\n\n                 options.Authority = \"https://accounts.google.com/\";\n                 options.ClientId = \"708996912208-9m4dkjb5hscn7cjrn5u0r4tbgkbj1fko.apps.googleusercontent.com\";\n\n                 options.CallbackPath = \"/signin-google\";\n                 options.Scope.Add(\"email\");\n             })\n            .AddOpenIdConnect(\"demoidsrv\", \"IdentityServer\", options =>\n            {\n                options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n                options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n\n                options.Authority = \"https://demo.identityserver8.io/\";\n                options.ClientId = \"login\";\n                options.ResponseType = \"id_token\";\n                options.SaveTokens = true;\n                options.CallbackPath = \"/signin-idsrv\";\n                options.SignedOutCallbackPath = \"/signout-callback-idsrv\";\n                options.RemoteSignOutPath = \"/signout-idsrv\";\n\n                options.TokenValidationParameters = new TokenValidationParameters\n                {\n                    NameClaimType = \"name\",\n                    RoleClaimType = \"role\"\n                };\n            })\n            .AddOpenIdConnect(\"aad\", \"Azure AD\", options =>\n            {\n                options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n                options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n\n                options.Authority = \"https://login.windows.net/4ca9cb4c-5e5f-4be9-b700-c532992a3705\";\n                options.ClientId = \"96e3c53e-01cb-4244-b658-a42164cb67a9\";\n                options.ResponseType = \"id_token\";\n                options.CallbackPath = \"/signin-aad\";\n                options.SignedOutCallbackPath = \"/signout-callback-aad\";\n                options.RemoteSignOutPath = \"/signout-aad\";\n                options.TokenValidationParameters = new TokenValidationParameters\n                {\n                    NameClaimType = \"name\",\n                    RoleClaimType = \"role\"\n                };\n            })\n            .AddOpenIdConnect(\"adfs\", \"ADFS\", options =>\n            {\n                options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n                options.SignOutScheme = IdentityServerConstants.SignoutScheme;\n\n                options.Authority = \"https://adfs.leastprivilege.vm/adfs\";\n                options.ClientId = \"c0ea8d99-f1e7-43b0-a100-7dee3f2e5c3c\";\n                options.ResponseType = \"id_token\";\n\n                options.CallbackPath = \"/signin-adfs\";\n                options.SignedOutCallbackPath = \"/signout-callback-adfs\";\n                options.RemoteSignOutPath = \"/signout-adfs\";\n                options.TokenValidationParameters = new TokenValidationParameters\n                {\n                    NameClaimType = \"name\",\n                    RoleClaimType = \"role\"\n                };\n            });\n\n        return services;\n    }\n\n    public static void AddCertificateForwardingForNginx(this IServiceCollection services)\n    {\n        services.AddCertificateForwarding(options =>\n        {\n            options.CertificateHeader = \"X-SSL-CERT\";\n\n            options.HeaderConverter = (headerValue) =>\n            {\n                X509Certificate2 clientCertificate = null;\n\n                if(!string.IsNullOrWhiteSpace(headerValue))\n                {\n                    byte[] bytes = Encoding.UTF8.GetBytes(Uri.UnescapeDataString(headerValue));\n                    clientCertificate = new X509Certificate2(bytes);\n                }\n\n                return clientCertificate;\n            };\n        });\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Account/AccessDenied.cshtml",
    "content": "﻿\n<div class=\"container\">\n    <div class=\"lead\">\n        <h1>Access Denied</h1>\n        <p>You do not have access to that resource.</p>\n    </div>\n</div>"
  },
  {
    "path": "src/IdentityServer8/host/Views/Account/LoggedOut.cshtml",
    "content": "﻿@model LoggedOutViewModel\n\n@{ \n    // set this so the layout rendering sees an anonymous user\n    ViewData[\"signed-out\"] = true;\n}\n\n<div class=\"logged-out-page\">\n    <h1>\n        Logout\n        <small>You are now logged out</small>\n    </h1>\n\n    @if (Model.PostLogoutRedirectUri != null)\n    {\n        <div>\n            Click <a class=\"PostLogoutRedirectUri\" href=\"@Model.PostLogoutRedirectUri\">here</a> to return to the\n            <span>@Model.ClientName</span> application.\n        </div>\n    }\n\n    @if (Model.SignOutIframeUrl != null)\n    {\n        <iframe width=\"0\" height=\"0\" class=\"signout\" src=\"@Model.SignOutIframeUrl\"></iframe>\n    }\n</div>\n\n@section scripts\n{\n    @if (Model.AutomaticRedirectAfterSignOut)\n    {\n        <script src=\"~/js/signout-redirect.js\"></script>\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Account/Login.cshtml",
    "content": "@model LoginViewModel\n\n<div class=\"login-page\">\n    <div class=\"lead\">\n        <h1>Login</h1>\n        <p>Choose how to login</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n\n        @if (Model.EnableLocalLogin)\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>Local Account</h2>\n                    </div>\n\n                    <div class=\"card-body\">\n                        <form asp-route=\"Login\">\n                            <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n\n                            <div class=\"form-group\">\n                                <label asp-for=\"Username\"></label>\n                                <input class=\"form-control\" placeholder=\"Username\" asp-for=\"Username\" autofocus>\n                            </div>\n                            <div class=\"form-group\">\n                                <label asp-for=\"Password\"></label>\n                                <input type=\"password\" class=\"form-control\" placeholder=\"Password\" asp-for=\"Password\" autocomplete=\"off\">\n                            </div>\n                            @if (Model.AllowRememberLogin)\n                            {\n                                <div class=\"form-group\">\n                                    <div class=\"form-check\">\n                                        <input class=\"form-check-input\" asp-for=\"RememberLogin\">\n                                        <label class=\"form-check-label\" asp-for=\"RememberLogin\">\n                                            Remember My Login\n                                        </label>\n                                    </div>\n                                </div>\n                            }\n                            <button class=\"btn btn-primary\" name=\"button\" value=\"login\">Login</button>\n                            <button class=\"btn btn-secondary\" name=\"button\" value=\"cancel\" formaction=\"/Account/LoginCancel\">Cancel</button>\n                        </form>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"col-sm-6\">\n                <div class=\"card\">\n                    <div class=\"card-header\">\n                        <h2>External Account</h2>\n                    </div>\n                    <div class=\"card-body\">\n                        <ul class=\"list-inline\">\n                            @foreach (var provider in Model.VisibleExternalProviders)\n                            {\n                                <li class=\"list-inline-item\">\n                                    <a class=\"btn btn-secondary\"\n                                       asp-controller=\"External\"\n                                       asp-action=\"Challenge\"\n                                       asp-route-scheme=\"@provider.AuthenticationScheme\"\n                                       asp-route-returnUrl=\"@Model.ReturnUrl\">\n                                        @provider.DisplayName\n                                    </a>\n                                </li>\n                            }\n                        </ul>\n                    </div>\n                </div>\n            </div>\n        }\n\n        @if (!Model.EnableLocalLogin && !Model.VisibleExternalProviders.Any())\n        {\n            <div class=\"alert alert-warning\">\n                <strong>Invalid login request</strong>\n                There are no login schemes configured for this request.\n            </div>\n        }\n    </div>\n</div>"
  },
  {
    "path": "src/IdentityServer8/host/Views/Account/Logout.cshtml",
    "content": "﻿@model LogoutViewModel\n\n<div class=\"logout-page\">\n    <div class=\"lead\">\n        <h1>Logout</h1>\n        <p>Would you like to logout of IdentityServer?</p>\n    </div>\n\n    <form asp-action=\"Logout\">\n        <input type=\"hidden\" name=\"logoutId\" value=\"@Model.LogoutId\"  />\n        <div class=\"form-group\">\n            <button class=\"btn btn-primary\">Yes</button>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Consent/Index.cshtml",
    "content": "@model ConsentViewModel\n\n<div class=\"page-consent\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Index\">\n        <input type=\"hidden\" asp-for=\"ReturnUrl\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Device/Success.cshtml",
    "content": "\n<div class=\"page-device-success\">\n    <div class=\"lead\">\n        <h1>Success</h1>\n        <p>You have successfully authorized the device</p>\n    </div>\n</div>\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Device/UserCodeCapture.cshtml",
    "content": "@model string\n\n<div class=\"page-device-code\">\n    <div class=\"lead\">\n        <h1>User Code</h1>\n        <p>Please enter the code displayed on your device.</p>\n    </div>\n\n    <partial name=\"_ValidationSummary\" />\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <form asp-action=\"UserCodeCapture\">\n                <div class=\"form-group\">\n                    <label for=\"userCode\">User Code:</label>\n                    <input class=\"form-control\" for=\"userCode\" name=\"userCode\" autofocus />\n                </div>\n\n                <button class=\"btn btn-primary\" name=\"button\">Submit</button>\n            </form>\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Device/UserCodeConfirmation.cshtml",
    "content": "@model DeviceAuthorizationViewModel\n\n<div class=\"page-device-confirmation\">\n    <div class=\"lead\">\n        @if (Model.ClientLogoUrl != null)\n        {\n            <div class=\"client-logo\"><img src=\"@Model.ClientLogoUrl\"></div>\n        }\n        <h1>\n            @Model.ClientName\n            <small class=\"text-muted\">is requesting your permission</small>\n        </h1>\n        @if (Model.ConfirmUserCode)\n        {\n            <p>Please confirm that the authorization request quotes the code: <strong>@Model.UserCode</strong>.</p>\n        }\n        <p>Uncheck the permissions you do not wish to grant.</p>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-8\">\n            <partial name=\"_ValidationSummary\" />\n        </div>\n    </div>\n\n    <form asp-action=\"Callback\">\n        <input asp-for=\"UserCode\" type=\"hidden\" value=\"@Model.UserCode\" />\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                @if (Model.IdentityScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-user\"></span>\n                                Personal Information\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.IdentityScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"@scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                @if (Model.ApiScopes.Any())\n                {\n                    <div class=\"form-group\">\n                        <div class=\"card\">\n                            <div class=\"card-header\">\n                                <span class=\"glyphicon glyphicon-tasks\"></span>\n                                Application Access\n                            </div>\n                            <ul class=\"list-group list-group-flush\">\n                                @foreach (var scope in Model.ApiScopes)\n                                {\n                                    <partial name=\"_ScopeListItem\" model=\"scope\" />\n                                }\n                            </ul>\n                        </div>\n                    </div>\n                }\n\n                <div class=\"form-group\">\n                    <div class=\"card\">\n                        <div class=\"card-header\">\n                            <span class=\"glyphicon glyphicon-tasks\"></span>\n                            Description\n                        </div>\n                        <div class=\"card-body\">\n                            <input class=\"form-control\" placeholder=\"Description or name of device\" asp-for=\"Description\" autofocus>\n                        </div>\n                    </div>\n                </div>\n\n                @if (Model.AllowRememberConsent)\n                {\n                    <div class=\"form-group\">\n                        <div class=\"form-check\">\n                            <input class=\"form-check-input\" asp-for=\"RememberConsent\">\n                            <label class=\"form-check-label\" asp-for=\"RememberConsent\">\n                                <strong>Remember My Decision</strong>\n                            </label>\n                        </div>\n                    </div>\n                }\n            </div>\n        </div>\n\n        <div class=\"row\">\n            <div class=\"col-sm-4\">\n                <button name=\"button\" value=\"yes\" class=\"btn btn-primary\" autofocus>Yes, Allow</button>\n                <button name=\"button\" value=\"no\" class=\"btn btn-secondary\">No, Do Not Allow</button>\n            </div>\n            <div class=\"col-sm-4 col-lg-auto\">\n                @if (Model.ClientUrl != null)\n                {\n                    <a class=\"btn btn-outline-info\" href=\"@Model.ClientUrl\">\n                        <span class=\"glyphicon glyphicon-info-sign\"></span>\n                        <strong>@Model.ClientName</strong>\n                    </a>\n                }\n            </div>\n        </div>\n    </form>\n</div>\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Diagnostics/Index.cshtml",
    "content": "@model DiagnosticsViewModel\n\n<div class=\"diagnostics-page\">\n    <div class=\"lead\">\n        <h1>Authentication Cookie</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Claims</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var claim in Model.AuthenticateResult.Principal.Claims)\n                        {\n                            <dt>@claim.Type</dt>\n                            <dd>@claim.Value</dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n        \n        <div class=\"col\">\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <h2>Properties</h2>\n                </div>\n                <div class=\"card-body\">\n                    <dl>\n                        @foreach (var prop in Model.AuthenticateResult.Properties.Items)\n                        {\n                            <dt>@prop.Key</dt>\n                            <dd>@prop.Value</dd>\n                        }\n                        @if (Model.Clients.Any())\n                        {\n                            <dt>Clients</dt>\n                            <dd>\n                            @{\n                                var clients = Model.Clients.ToArray();\n                                for(var i = 0; i < clients.Length; i++)\n                                {\n                                    <text>@clients[i]</text>\n                                    if (i < clients.Length - 1)\n                                    {\n                                        <text>, </text>\n                                    }\n                                }\n                            }\n                            </dd>\n                        }\n                    </dl>\n                </div>\n            </div>\n        </div>\n    </div>\n</div>\n\n\n\n\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Grants/Index.cshtml",
    "content": "﻿@model GrantsViewModel\n\n<div class=\"grants-page\">\n    <div class=\"lead\">\n        <h1>Client Application Permissions</h1>\n        <p>Below is the list of applications you have given permission to and the resources they have access to.</p>\n    </div>\n\n    @if (Model.Grants.Any() == false)\n    {\n        <div class=\"row\">\n            <div class=\"col-sm-8\">\n                <div class=\"alert alert-info\">\n                    You have not given access to any applications\n                </div>\n            </div>\n        </div>\n    }\n    else\n    {\n        foreach (var grant in Model.Grants)\n        {\n            <div class=\"card\">\n                <div class=\"card-header\">\n                    <div class=\"row\">\n                        <div class=\"col-sm-8 card-title\">\n                            @if (grant.ClientLogoUrl != null)\n                            {\n                                <img src=\"@grant.ClientLogoUrl\">\n                            }\n                            <strong>@grant.ClientName</strong>\n                        </div>\n\n                        <div class=\"col-sm-2\">\n                            <form asp-action=\"Revoke\">\n                                <input type=\"hidden\" name=\"clientId\" value=\"@grant.ClientId\">\n                                <button class=\"btn btn-danger\">Revoke Access</button>\n                            </form>\n                        </div>\n                    </div>\n                </div>\n                \n                <ul class=\"list-group list-group-flush\">\n                    @if (grant.Description != null)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Description:</label> @grant.Description\n                        </li>   \n                    }\n                    <li class=\"list-group-item\">\n                        <label>Created:</label> @grant.Created.ToString(\"yyyy-MM-dd\")\n                    </li>\n                    @if (grant.Expires.HasValue)\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Expires:</label> @grant.Expires.Value.ToString(\"yyyy-MM-dd\")\n                        </li>\n                    }\n                    @if (grant.IdentityGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>Identity Grants</label>\n                            <ul>\n                                @foreach (var name in grant.IdentityGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                    @if (grant.ApiGrantNames.Any())\n                    {\n                        <li class=\"list-group-item\">\n                            <label>API Grants</label>\n                            <ul>\n                                @foreach (var name in grant.ApiGrantNames)\n                                {\n                                    <li>@name</li>\n                                }\n                            </ul>\n                        </li>\n                    }\n                </ul>\n            </div>\n        }\n    }\n</div>"
  },
  {
    "path": "src/IdentityServer8/host/Views/Home/Index.cshtml",
    "content": "@using System.Diagnostics\n@using System.Reflection\n\n@{\n    var version = typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.GetCustomAttribute<AssemblyInformationalVersionAttribute>()?.InformationalVersion.Split('+').First();\n}\n\n<div class=\"welcome-page\">\n    <h1>\n        <img src=\"~/icon.jpg\">\n        Welcome to IdentityServer8\n        <small class=\"text-muted\">(version @version)</small>\n    </h1>\n\n    <ul>\n        <li>\n            IdentityServer publishes a\n            <a href=\"~/.well-known/openid-configuration\">discovery document</a>\n            where you can find metadata and links to all the endpoints, key material, etc.\n        </li>\n        <li>\n            Click <a href=\"~/diagnostics\">here</a> to see the claims for your current session.\n        </li>\n        <li>\n            Click <a href=\"~/grants\">here</a> to manage your stored grants.\n        </li>\n        <li>\n            Here are links to the\n            <a href=\"https://github.com/alexhiggins732/IdentityServer8\">source code repository</a>,\n            and <a href=\"https://github.com/alexhiggins732/IdentityServer8/tree/main/samples\">ready to use samples</a>.\n        </li>\n    </ul>\n</div>\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Shared/Error.cshtml",
    "content": "@model ErrorViewModel\n\n@{\n    var error = Model?.Error?.Error;\n    var errorDescription = Model?.Error?.ErrorDescription;\n    var request_id = Model?.Error?.RequestId;\n}\n\n<div class=\"error-page\">\n    <div class=\"lead\">\n        <h1>Error</h1>\n    </div>\n\n    <div class=\"row\">\n        <div class=\"col-sm-6\">\n            <div class=\"alert alert-danger\">\n                Sorry, there was an error\n\n                @if (error != null)\n                {\n                    <strong>\n                        <em>\n                            : @error\n                        </em>\n                    </strong>\n\n                    if (errorDescription != null)\n                    {\n                        <div>@errorDescription</div>\n                    }\n                }\n            </div>\n\n            @if (request_id != null)\n            {\n                <div class=\"request-id\">Request Id: @request_id</div>\n            }\n        </div>\n    </div>\n</div>\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Shared/Redirect.cshtml",
    "content": "@model RedirectViewModel\n@using Microsoft.Extensions.DependencyInjection;\n<div class=\"redirect-page\">\n    <div class=\"lead\">\n        <h1>You are now being returned to the application</h1>\n        <p>Once complete, you may close this tab.</p>\n    </div>\n</div>\n\n<meta http-equiv=\"refresh\" content=\"0;url=@Model.RedirectUrl\" data-url=\"@Model.RedirectUrl\">\n<script>\n    var url = '@Model.RedirectUrl.SanitizeForUrl()';\n    window.location.href = url;\n</script>\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Shared/_Layout.cshtml",
    "content": "<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"utf-8\" />\n    <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0, shrink-to-fit=no\" />\n\n    <title>IdentityServer8</title>\n    \n    <link rel=\"icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    <link rel=\"shortcut icon\" type=\"image/x-icon\" href=\"~/favicon.ico\" />\n    \n    <link rel=\"stylesheet\" href=\"~/lib/bootstrap/dist/css/bootstrap.min.css\" />\n    <link rel=\"stylesheet\" href=\"~/css/site.css\" />\n</head>\n<body>\n    <partial name=\"_Nav\" />\n   \n    <div class=\"container body-container\">\n        @RenderBody()\n    </div>\n\n    <script src=\"~/lib/jquery/dist/jquery.slim.min.js\"></script>\n    <script src=\"~/lib/bootstrap/dist/js/bootstrap.bundle.min.js\"></script>\n\n    @RenderSection(\"scripts\", required: false)\n</body>\n</html>\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Shared/_Nav.cshtml",
    "content": "@using IdentityServer8.Extensions\n\n@{\n    string name = null;\n    if (!true.Equals(ViewData[\"signed-out\"]))\n    {\n        name = Context.User?.GetDisplayName();\n    }\n}\n\n<div class=\"nav-page\">\n    <nav class=\"navbar navbar-expand-lg navbar-dark bg-dark\">\n\n        <a href=\"~/\" class=\"navbar-brand\">\n            <img src=\"~/icon.png\" class=\"icon-banner\">\n            IdentityServer8\n        </a>\n\n        @if (!string.IsNullOrWhiteSpace(name))\n        {\n            <ul class=\"navbar-nav mr-auto\">\n                <li class=\"nav-item dropdown\">\n                    <a href=\"#\" class=\"nav-link dropdown-toggle\" data-toggle=\"dropdown\">@name <b class=\"caret\"></b></a>\n                    \n                    <div class=\"dropdown-menu\">\n                        <a class=\"dropdown-item\" asp-action=\"Logout\" asp-controller=\"Account\">Logout</a>\n                    </div>\n              </li>\n            </ul>\n        }\n    \n    </nav>\n</div>\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/Shared/_ScopeListItem.cshtml",
    "content": "﻿@model ScopeViewModel\n\n<li class=\"list-group-item\">\n    <label>\n        <input class=\"consent-scopecheck\"\n               type=\"checkbox\"\n               name=\"ScopesConsented\"\n               id=\"scopes_@Model.Value\"\n               value=\"@Model.Value\"\n               checked=\"@Model.Checked\"\n               disabled=\"@Model.Required\" />\n        @if (Model.Required)\n        {\n            <input type=\"hidden\"\n                   name=\"ScopesConsented\"\n                   value=\"@Model.Value\" />\n        }\n        <strong>@Model.DisplayName</strong>\n        @if (Model.Emphasize)\n        {\n            <span class=\"glyphicon glyphicon-exclamation-sign\"></span>\n        }\n    </label>\n    @if (Model.Required)\n    {\n        <span><em>(required)</em></span>\n    }\n    @if (Model.Description != null)\n    {\n        <div class=\"consent-description\">\n            <label for=\"scopes_@Model.Value\">@Model.Description</label>\n        </div>\n    }\n</li>"
  },
  {
    "path": "src/IdentityServer8/host/Views/Shared/_ValidationSummary.cshtml",
    "content": "﻿@if (ViewContext.ModelState.IsValid == false)\n{\n    <div class=\"alert alert-danger\">\n        <strong>Error</strong>\n        <div asp-validation-summary=\"All\" class=\"danger\"></div>\n    </div>\n}"
  },
  {
    "path": "src/IdentityServer8/host/Views/_ViewImports.cshtml",
    "content": "﻿@using IdentityServerHost.Quickstart.UI\n@addTagHelper *, Microsoft.AspNetCore.Mvc.TagHelpers\n"
  },
  {
    "path": "src/IdentityServer8/host/Views/_ViewStart.cshtml",
    "content": "﻿@{\n    Layout = \"_Layout\";\n}\n"
  },
  {
    "path": "src/IdentityServer8/host/appsettings.json",
    "content": "﻿{\n  \"ApiScopes\": [\n    {\n      \"Name\": \"IdentityServerApi\"\n    },\n    {\n      \"Name\": \"resource1.scope1\"\n    },\n    {\n      \"Name\": \"resource2.scope1\"\n    },\n    {\n      \"Name\": \"scope3\"\n    },\n    {\n      \"Name\": \"shared.scope\"\n    },\n    {\n      \"Name\": \"transaction\",\n      \"DisplayName\": \"Transaction\",\n      \"Description\": \"A transaction\"\n    }\n  ],\n  \n  \"ApiResources\": [\n    {\n      \"Name\": \"resource1\",\n      \"DisplayName\": \"Resource #1\",\n\n      \"Scopes\": [\n        \"resource1.scope1\",\n        \"shared.scope\"\n      ]\n    },\n    {\n      \"Name\": \"resource2\",\n      \"DisplayName\": \"Resource #2\",\n      \n      \"UserClaims\": [\n        \"name\",\n        \"email\"\n      ],\n\n      \"Scopes\": [\n        \"resource2.scope1\",\n        \"shared.scope\"\n      ]\n    }\n  ],\n  \n  \"Clients\": [\n    {\n      \"ClientId\": \"machine_client\",\n      \"ClientSecrets\": [ { \"Value\": \"K7gNU3sdo+OL0wNhqoVWhr3g6s1xYv72ol/pe/Unols=\" } ],\n      \"AllowedGrantTypes\": [ \"client_credentials\" ],\n      \"AllowedScopes\": [ \"resource1.scope1\", \"resource1.scope2\" ],\n      \"Properties\": { \"foo\": \"bar\" },\n      \"Claims\": [\n        {\n          \"type\": \"c1\",\n          \"value\": \"c1value\"\n        },\n        {\n          \"type\": \"c2\",\n          \"value\": \"c2value\"\n        }\n      ]\n    },\n    {\n      \"ClientId\": \"interactive_client\",\n      \"ClientSecrets\": [ { \"Value\": \"K7gNU3sdo+OL0wNhqoVWhr3g6s1xYv72ol/pe/Unols=\" } ],\n      \"AllowedGrantTypes\": [ \"authorization_code\", \"client_credentials\" ],\n      \"AllowedScopes\": [ \"openid\", \"profile\", \"resource1.scope1\", \"resource1.scope2\" ]\n    }\n  ]\n}"
  },
  {
    "path": "src/IdentityServer8/host/compilerconfig.json",
    "content": "﻿[\n  {\n    \"outputFile\": \"wwwroot/css/site.css\",\n    \"inputFile\": \"wwwroot/css/site.scss\"\n  }\n]"
  },
  {
    "path": "src/IdentityServer8/host/compilerconfig.json.defaults",
    "content": "{\n  \"compilers\": {\n    \"less\": {\n      \"autoPrefix\": \"\",\n      \"cssComb\": \"none\",\n      \"ieCompat\": true,\n      \"strictMath\": false,\n      \"strictUnits\": false,\n      \"relativeUrls\": true,\n      \"rootPath\": \"\",\n      \"sourceMapRoot\": \"\",\n      \"sourceMapBasePath\": \"\",\n      \"sourceMap\": false\n    },\n    \"sass\": {\n      \"autoPrefix\": \"\",\n      \"includePath\": \"\",\n      \"indentType\": \"space\",\n      \"indentWidth\": 2,\n      \"outputStyle\": \"nested\",\n      \"Precision\": 5,\n      \"relativeUrls\": true,\n      \"sourceMapRoot\": \"\",\n      \"lineFeed\": \"\",\n      \"sourceMap\": false\n    },\n    \"stylus\": {\n      \"sourceMap\": false\n    },\n    \"babel\": {\n      \"sourceMap\": false\n    },\n    \"coffeescript\": {\n      \"bare\": false,\n      \"runtimeMode\": \"node\",\n      \"sourceMap\": false\n    },\n    \"handlebars\": {\n      \"root\": \"\",\n      \"noBOM\": false,\n      \"name\": \"\",\n      \"namespace\": \"\",\n      \"knownHelpersOnly\": false,\n      \"forcePartial\": false,\n      \"knownHelpers\": [],\n      \"commonjs\": \"\",\n      \"amd\": false,\n      \"sourceMap\": false\n    }\n  },\n  \"minifiers\": {\n    \"css\": {\n      \"enabled\": true,\n      \"termSemicolons\": true,\n      \"gzip\": false\n    },\n    \"javascript\": {\n      \"enabled\": true,\n      \"termSemicolons\": true,\n      \"gzip\": false\n    }\n  }\n}"
  },
  {
    "path": "src/IdentityServer8/host/libman.json",
    "content": "{\n  \"version\": \"1.0\",\n  \"defaultProvider\": \"cdnjs\",\n  \"libraries\": [\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery@3.7.1\",\n      \"destination\": \"wwwroot/lib/jquery/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"bootstrap@5.3.2\",\n      \"destination\": \"wwwroot/lib/bootstrap/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation@1.20.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation/\"\n    },\n    {\n      \"provider\": \"jsdelivr\",\n      \"library\": \"jquery-validation-unobtrusive@4.0.0\",\n      \"destination\": \"wwwroot/lib/jquery-validation-unobtrusive/\"\n    }\n  ]\n}"
  },
  {
    "path": "src/IdentityServer8/host/wwwroot/css/site.css",
    "content": "﻿.body-container {\n  margin-top: 60px;\n  padding-bottom: 40px; }\n\n.welcome-page li {\n  list-style: none;\n  padding: 4px; }\n\n.logged-out-page iframe {\n  display: none;\n  width: 0;\n  height: 0; }\n\n.grants-page .card {\n  margin-top: 20px;\n  border-bottom: 1px solid lightgray; }\n  .grants-page .card .card-title {\n    font-size: 120%;\n    font-weight: bold; }\n    .grants-page .card .card-title img {\n      width: 100px;\n      height: 100px; }\n  .grants-page .card label {\n    font-weight: bold; }\n"
  },
  {
    "path": "src/IdentityServer8/host/wwwroot/css/site.scss",
    "content": "﻿.body-container {\n    margin-top: 60px;\n    padding-bottom:40px;\n}\n\n.welcome-page {\n    li {\n        list-style: none;\n        padding: 4px;\n    }\n}\n\n.logged-out-page {\n    iframe {\n        display: none;\n        width: 0;\n        height: 0;\n    }\n}\n\n.grants-page {\n    .card {\n        margin-top: 20px;\n        border-bottom: 1px solid lightgray;\n\n        .card-title {\n            img {\n                width: 100px;\n                height: 100px;\n            }\n\n            font-size: 120%;\n            font-weight: bold;\n        }\n\n        label {\n            font-weight: bold;\n        }\n    }\n}\n\n\n"
  },
  {
    "path": "src/IdentityServer8/host/wwwroot/js/signin-redirect.js",
    "content": "//window.location.href = document.querySelector(\"meta[http-equiv=refresh]\").getAttribute(\"data-url\");\n"
  },
  {
    "path": "src/IdentityServer8/host/wwwroot/js/signout-redirect.js",
    "content": "﻿window.addEventListener(\"load\", function () {\n    var a = document.querySelector(\"a.PostLogoutRedirectUri\");\n    if (a) {\n        window.location = a.href;\n    }\n});\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/CryptoHelper.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Crypto helper\n/// </summary>\npublic static class CryptoHelper\n{\n    /// <summary>\n    /// Creates a new RSA security key.\n    /// </summary>\n    /// <returns></returns>\n    public static RsaSecurityKey CreateRsaSecurityKey(int keySize = 2048)\n    {\n        return new RsaSecurityKey(RSA.Create(keySize))\n        {\n            KeyId = CryptoRandom.CreateUniqueId(16, CryptoRandom.OutputFormat.Hex)\n        };\n    }\n\n    /// <summary>\n    /// Creates a new ECDSA security key.\n    /// </summary>\n    /// <param name=\"curve\">The name of the curve as defined in\n    /// https://tools.ietf.org/html/rfc7518#section-6.2.1.1.</param>\n    /// <returns></returns>\n    public static ECDsaSecurityKey CreateECDsaSecurityKey(string curve = JsonWebKeyECTypes.P256)\n    {\n        return new ECDsaSecurityKey(ECDsa.Create(GetCurveFromCrvValue(curve)))\n        {\n            KeyId = CryptoRandom.CreateUniqueId(16, CryptoRandom.OutputFormat.Hex)\n        };\n    }\n\n    /// <summary>\n    /// Creates an RSA security key.\n    /// </summary>\n    /// <param name=\"parameters\">The parameters.</param>\n    /// <param name=\"id\">The identifier.</param>\n    /// <returns></returns>\n    public static RsaSecurityKey CreateRsaSecurityKey(RSAParameters parameters, string id)\n    {\n        var key = new RsaSecurityKey(parameters)\n        {\n            KeyId = id\n        };\n\n        return key;\n    }\n\n    /// <summary>\n    /// Creates the hash for the various hash claims (e.g. c_hash, at_hash or s_hash).\n    /// </summary>\n    /// <param name=\"value\">The value to hash.</param>\n    /// <param name=\"tokenSigningAlgorithm\">The token signing algorithm</param>\n    /// <returns></returns>\n    public static string CreateHashClaimValue(string value, string tokenSigningAlgorithm)\n    {\n        using (var sha = GetHashAlgorithmForSigningAlgorithm(tokenSigningAlgorithm))\n        {\n            var hash = sha.ComputeHash(Encoding.ASCII.GetBytes(value));\n            var size = (sha.HashSize / 8) / 2;\n\n            var leftPart = new byte[size];\n            Array.Copy(hash, leftPart, size);\n\n            return Base64Url.Encode(leftPart);\n        }\n    }\n\n    /// <summary>\n    /// Returns the matching hashing algorithm for a token signing algorithm\n    /// </summary>\n    /// <param name=\"signingAlgorithm\">The signing algorithm</param>\n    /// <returns></returns>\n    public static HashAlgorithm GetHashAlgorithmForSigningAlgorithm(string signingAlgorithm)\n    {\n        var signingAlgorithmBits = int.Parse(signingAlgorithm.Substring(signingAlgorithm.Length - 3));\n\n        return signingAlgorithmBits switch\n        {\n            256 => SHA256.Create(),\n            384 => SHA384.Create(),\n            512 => SHA512.Create(),\n            _ => throw new InvalidOperationException($\"Invalid signing algorithm: {signingAlgorithm}\"),\n        };\n    }\n\n    /// <summary>\n    /// Returns the matching named curve for RFC 7518 crv value\n    /// </summary>\n    internal static ECCurve GetCurveFromCrvValue(string crv)\n    {\n        return crv switch\n        {\n            JsonWebKeyECTypes.P256 => ECCurve.NamedCurves.nistP256,\n            JsonWebKeyECTypes.P384 => ECCurve.NamedCurves.nistP384,\n            JsonWebKeyECTypes.P521 => ECCurve.NamedCurves.nistP521,\n            _ => throw new InvalidOperationException($\"Unsupported curve type of {crv}\"),\n        };\n    }\n\n    /// <summary>\n    /// Return the matching RFC 7518 crv value for curve\n    /// </summary>\n    internal static string GetCrvValueFromCurve(ECCurve curve)\n    {\n        return curve.Oid.Value switch\n        {\n            Constants.CurveOids.P256 => JsonWebKeyECTypes.P256,\n            Constants.CurveOids.P384 => JsonWebKeyECTypes.P384,\n            Constants.CurveOids.P521 => JsonWebKeyECTypes.P521,\n            _ => throw new InvalidOperationException($\"Unsupported curve type of {curve.Oid.Value} - {curve.Oid.FriendlyName}\"),\n        };\n    }\n\n    internal static bool IsValidCurveForAlgorithm(ECDsaSecurityKey key, string algorithm)\n    {\n        var parameters = key.ECDsa.ExportParameters(false);\n\n        if (algorithm == SecurityAlgorithms.EcdsaSha256 && parameters.Curve.Oid.Value != Constants.CurveOids.P256\n            || algorithm == SecurityAlgorithms.EcdsaSha384 && parameters.Curve.Oid.Value != Constants.CurveOids.P384\n            || algorithm == SecurityAlgorithms.EcdsaSha512 && parameters.Curve.Oid.Value != Constants.CurveOids.P521)\n        {\n            return false;\n        }\n\n        return true;\n    }\n    internal static bool IsValidCrvValueForAlgorithm(string crv)\n    {\n        return crv == JsonWebKeyECTypes.P256 ||\n               crv == JsonWebKeyECTypes.P384 ||\n               crv == JsonWebKeyECTypes.P521;\n    }\n\n    internal static string GetRsaSigningAlgorithmValue(IdentityServerConstants.RsaSigningAlgorithm value)\n    {\n        return value switch\n        {\n            IdentityServerConstants.RsaSigningAlgorithm.RS256 => SecurityAlgorithms.RsaSha256,\n            IdentityServerConstants.RsaSigningAlgorithm.RS384 => SecurityAlgorithms.RsaSha384,\n            IdentityServerConstants.RsaSigningAlgorithm.RS512 => SecurityAlgorithms.RsaSha512,\n\n            IdentityServerConstants.RsaSigningAlgorithm.PS256 => SecurityAlgorithms.RsaSsaPssSha256,\n            IdentityServerConstants.RsaSigningAlgorithm.PS384 => SecurityAlgorithms.RsaSsaPssSha384,\n            IdentityServerConstants.RsaSigningAlgorithm.PS512 => SecurityAlgorithms.RsaSsaPssSha512,\n            _ => throw new ArgumentException(\"Invalid RSA signing algorithm value\", nameof(value)),\n        };\n    }\n\n    internal static string GetECDsaSigningAlgorithmValue(IdentityServerConstants.ECDsaSigningAlgorithm value)\n    {\n        return value switch\n        {\n            IdentityServerConstants.ECDsaSigningAlgorithm.ES256 => SecurityAlgorithms.EcdsaSha256,\n            IdentityServerConstants.ECDsaSigningAlgorithm.ES384 => SecurityAlgorithms.EcdsaSha384,\n            IdentityServerConstants.ECDsaSigningAlgorithm.ES512 => SecurityAlgorithms.EcdsaSha512,\n            _ => throw new ArgumentException(\"Invalid ECDsa signing algorithm value\", nameof(value)),\n        };\n    }\n\n    internal static X509Certificate2 FindCertificate(string name, StoreLocation location, NameType nameType)\n    {\n        X509Certificate2 certificate = null;\n\n        if (location == StoreLocation.LocalMachine)\n        {\n            if (nameType == NameType.SubjectDistinguishedName)\n            {\n                certificate = X509.LocalMachine.My.SubjectDistinguishedName.Find(name, validOnly: false).FirstOrDefault();\n            }\n            else if (nameType == NameType.Thumbprint)\n            {\n                certificate = X509.LocalMachine.My.Thumbprint.Find(name, validOnly: false).FirstOrDefault();\n            }\n        }\n        else\n        {\n            if (nameType == NameType.SubjectDistinguishedName)\n            {\n                certificate = X509.CurrentUser.My.SubjectDistinguishedName.Find(name, validOnly: false).FirstOrDefault();\n            }\n            else if (nameType == NameType.Thumbprint)\n            {\n                certificate = X509.CurrentUser.My.Thumbprint.Find(name, validOnly: false).FirstOrDefault();\n            }\n        }\n\n        return certificate;\n    }\n}\n\n/// <summary>\n/// Describes the string so we know what to search for in certificate store\n/// </summary>\npublic enum NameType\n{\n    /// <summary>\n    /// subject distinguished name\n    /// </summary>\n    SubjectDistinguishedName,\n\n    /// <summary>\n    /// thumbprint\n    /// </summary>\n    Thumbprint\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/BuilderExtensions/Additional.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// Builder extension methods for registering additional services \n/// </summary>\npublic static class IdentityServerBuilderExtensionsAdditional\n{\n    /// <summary>\n    /// Adds the extension grant validator.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddExtensionGrantValidator<T>(this IIdentityServerBuilder builder)\n        where T : class, IExtensionGrantValidator\n    {\n        builder.Services.AddTransient<IExtensionGrantValidator, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a redirect URI validator.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddRedirectUriValidator<T>(this IIdentityServerBuilder builder)\n        where T : class, IRedirectUriValidator\n    {\n        builder.Services.AddTransient<IRedirectUriValidator, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a an \"AppAuth\" (OAuth 2.0 for Native Apps) compliant redirect URI validator (does strict validation but also allows http://127.0.0.1 with random port)\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddAppAuthRedirectUriValidator(this IIdentityServerBuilder builder)\n    {\n        return builder.AddRedirectUriValidator<StrictRedirectUriValidatorAppAuth>();\n    }\n\n    /// <summary>\n    /// Adds the resource owner validator.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddResourceOwnerValidator<T>(this IIdentityServerBuilder builder)\n       where T : class, IResourceOwnerPasswordValidator\n    {\n        builder.Services.AddTransient<IResourceOwnerPasswordValidator, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the profile service.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddProfileService<T>(this IIdentityServerBuilder builder)\n       where T : class, IProfileService\n    {\n        builder.Services.AddTransient<IProfileService, T>();\n\n        return builder;\n    }\n    \n    /// <summary>\n    /// Adds a resource validator.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddResourceValidator<T>(this IIdentityServerBuilder builder)\n        where T : class, IResourceValidator\n    {\n        builder.Services.AddTransient<IResourceValidator, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a scope parser.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddScopeParser<T>(this IIdentityServerBuilder builder)\n        where T : class, IScopeParser\n    {\n        builder.Services.AddTransient<IScopeParser, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a client store.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddClientStore<T>(this IIdentityServerBuilder builder)\n       where T : class, IClientStore\n    {\n        builder.Services.TryAddTransient(typeof(T));\n        builder.Services.AddTransient<IClientStore, ValidatingClientStore<T>>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a resource store.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddResourceStore<T>(this IIdentityServerBuilder builder)\n       where T : class, IResourceStore\n    {\n        builder.Services.AddTransient<IResourceStore, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a device flow store.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    public static IIdentityServerBuilder AddDeviceFlowStore<T>(this IIdentityServerBuilder builder)\n        where T : class, IDeviceFlowStore\n    {\n        builder.Services.AddTransient<IDeviceFlowStore, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a persisted grant store.\n    /// </summary>\n    /// <typeparam name=\"T\">The type of the concrete grant store that is registered in DI.</typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns>The builder.</returns>\n    public static IIdentityServerBuilder AddPersistedGrantStore<T>(this IIdentityServerBuilder builder)\n        where T : class, IPersistedGrantStore\n    {\n        builder.Services.AddTransient<IPersistedGrantStore, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a CORS policy service.\n    /// </summary>\n    /// <typeparam name=\"T\">The type of the concrete scope store class that is registered in DI.</typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddCorsPolicyService<T>(this IIdentityServerBuilder builder)\n        where T : class, ICorsPolicyService\n    {\n        builder.Services.AddTransient<ICorsPolicyService, T>();\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a CORS policy service cache.\n    /// </summary>\n    /// <typeparam name=\"T\">The type of the concrete CORS policy service that is registered in DI.</typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddCorsPolicyCache<T>(this IIdentityServerBuilder builder)\n        where T : class, ICorsPolicyService\n    {\n        builder.Services.TryAddTransient(typeof(T));\n        builder.Services.AddTransient<ICorsPolicyService, CachingCorsPolicyService<T>>();\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the secret parser.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddSecretParser<T>(this IIdentityServerBuilder builder)\n        where T : class, ISecretParser\n    {\n        builder.Services.AddTransient<ISecretParser, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the secret validator.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddSecretValidator<T>(this IIdentityServerBuilder builder)\n        where T : class, ISecretValidator\n    {\n        builder.Services.AddTransient<ISecretValidator, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the client store cache.\n    /// </summary>\n    /// <typeparam name=\"T\">The type of the concrete client store class that is registered in DI.</typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddClientStoreCache<T>(this IIdentityServerBuilder builder)\n        where T : IClientStore\n    {\n        builder.Services.TryAddTransient(typeof(T));\n        builder.Services.AddTransient<ValidatingClientStore<T>>();\n        builder.Services.AddTransient<IClientStore, CachingClientStore<ValidatingClientStore<T>>>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the client store cache.\n    /// </summary>\n    /// <typeparam name=\"T\">The type of the concrete scope store class that is registered in DI.</typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddResourceStoreCache<T>(this IIdentityServerBuilder builder)\n        where T : IResourceStore\n    {\n        builder.Services.TryAddTransient(typeof(T));\n        builder.Services.AddTransient<IResourceStore, CachingResourceStore<T>>();\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the authorize interaction response generator.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddAuthorizeInteractionResponseGenerator<T>(this IIdentityServerBuilder builder)\n        where T : class, IAuthorizeInteractionResponseGenerator\n    {\n        builder.Services.AddTransient<IAuthorizeInteractionResponseGenerator, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the custom authorize request validator.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddCustomAuthorizeRequestValidator<T>(this IIdentityServerBuilder builder)\n       where T : class, ICustomAuthorizeRequestValidator\n    {\n        builder.Services.AddTransient<ICustomAuthorizeRequestValidator, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the custom authorize request validator.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddCustomTokenRequestValidator<T>(this IIdentityServerBuilder builder)\n       where T : class, ICustomTokenRequestValidator\n    {\n        builder.Services.AddTransient<ICustomTokenRequestValidator, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds support for client authentication using JWT bearer assertions.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddJwtBearerClientAuthentication(this IIdentityServerBuilder builder)\n    {\n        builder.Services.TryAddTransient<IReplayCache, DefaultReplayCache>();\n        builder.AddSecretParser<JwtBearerClientAssertionSecretParser>();\n        builder.AddSecretValidator<PrivateKeyJwtSecretValidator>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a client configuration validator.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddClientConfigurationValidator<T>(this IIdentityServerBuilder builder)\n        where T : class, IClientConfigurationValidator\n    {\n        builder.Services.AddTransient<IClientConfigurationValidator, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the X509 secret validators for mutual TLS.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddMutualTlsSecretValidators(this IIdentityServerBuilder builder)\n    {\n        builder.AddSecretParser<MutualTlsSecretParser>();\n        builder.AddSecretValidator<X509ThumbprintSecretValidator>();\n        builder.AddSecretValidator<X509NameSecretValidator>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a custom back-channel logout service.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddBackChannelLogoutService<T>(this IIdentityServerBuilder builder)\n        where T : class, IBackChannelLogoutService\n    {\n        builder.Services.AddTransient<IBackChannelLogoutService, T>();\n\n        return builder;\n    }\n\n    // todo: check with later previews of ASP.NET Core if this is still required\n    /// <summary>\n    /// Adds configuration for the HttpClient used for back-channel logout notifications.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"configureClient\">The configruation callback.</param>\n    /// <returns></returns>\n    public static IHttpClientBuilder AddBackChannelLogoutHttpClient(this IIdentityServerBuilder builder, Action<HttpClient> configureClient = null)\n    {\n        const string name = IdentityServerConstants.HttpClients.BackChannelLogoutHttpClient;\n        IHttpClientBuilder httpBuilder;\n\n        if (configureClient != null)\n        {\n            httpBuilder = builder.Services.AddHttpClient(name, configureClient);\n        }\n        else\n        {\n            httpBuilder = builder.Services.AddHttpClient(name)\n                .ConfigureHttpClient(client => {\n                    client.Timeout = TimeSpan.FromSeconds(IdentityServerConstants.HttpClients.DefaultTimeoutSeconds);\n                });\n        }\n\n        builder.Services.AddTransient<IBackChannelLogoutHttpClient>(s =>\n        {\n            var httpClientFactory = s.GetRequiredService<IHttpClientFactory>();\n            var httpClient = httpClientFactory.CreateClient(name);\n            var loggerFactory = s.GetRequiredService<ILoggerFactory>();\n            \n            return new DefaultBackChannelLogoutHttpClient(httpClient, loggerFactory);\n        });\n\n        return httpBuilder;\n    }\n\n\n    // todo: check with later previews of ASP.NET Core if this is still required\n    /// <summary>\n    /// Adds configuration for the HttpClient used for JWT request_uri requests.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"configureClient\">The configruation callback.</param>\n    /// <returns></returns>\n    public static IHttpClientBuilder AddJwtRequestUriHttpClient(this IIdentityServerBuilder builder, Action<HttpClient> configureClient = null)\n    {\n        const string name = IdentityServerConstants.HttpClients.JwtRequestUriHttpClient;\n        IHttpClientBuilder httpBuilder;\n\n        if (configureClient != null)\n        {\n            httpBuilder = builder.Services.AddHttpClient(name, configureClient);\n        }\n        else\n        {\n            httpBuilder = builder.Services.AddHttpClient(name)\n                .ConfigureHttpClient(client => {\n                    client.Timeout = TimeSpan.FromSeconds(IdentityServerConstants.HttpClients.DefaultTimeoutSeconds);\n                });\n        }\n        \n        builder.Services.AddTransient<IJwtRequestUriHttpClient, DefaultJwtRequestUriHttpClient>(s =>\n        {\n            var httpClientFactory = s.GetRequiredService<IHttpClientFactory>();\n            var httpClient = httpClientFactory.CreateClient(name);\n            var loggerFactory = s.GetRequiredService<ILoggerFactory>();\n            var options = s.GetRequiredService<IdentityServerOptions>();\n\n            return new DefaultJwtRequestUriHttpClient(httpClient, options, loggerFactory);\n        });\n\n        return httpBuilder;\n    }\n\n    /// <summary>\n    /// Adds a custom authorization request parameter store.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddAuthorizationParametersMessageStore<T>(this IIdentityServerBuilder builder)\n        where T : class, IAuthorizationParametersMessageStore\n    {\n        builder.Services.AddTransient<IAuthorizationParametersMessageStore, T>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds a custom user session.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddUserSession<T>(this IIdentityServerBuilder builder)\n        where T : class, IUserSession\n    {\n        // This is added as scoped due to the note regarding the AuthenticateAsync\n        // method in the IdentityServer8.Services.DefaultUserSession implementation.\n        builder.Services.AddScoped<IUserSession, T>();\n\n        return builder;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/BuilderExtensions/Core.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// Builder extension methods for registering core services\n/// </summary>\npublic static class IdentityServerBuilderExtensionsCore\n{\n    /// <summary>\n    /// Adds the required platform services.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddRequiredPlatformServices(this IIdentityServerBuilder builder)\n    {\n        builder.Services.TryAddSingleton<IHttpContextAccessor, HttpContextAccessor>();            \n        builder.Services.AddOptions();\n        builder.Services.AddSingleton(\n            resolver => resolver.GetRequiredService<IOptions<IdentityServerOptions>>().Value);\n        builder.Services.AddHttpClient();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the default cookie handlers and corresponding configuration\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddCookieAuthentication(this IIdentityServerBuilder builder)\n    {\n        builder.Services.AddAuthentication(IdentityServerConstants.DefaultCookieAuthenticationScheme)\n            .AddCookie(IdentityServerConstants.DefaultCookieAuthenticationScheme)\n            .AddCookie(IdentityServerConstants.ExternalCookieAuthenticationScheme);\n\n        builder.Services.AddSingleton<IConfigureOptions<CookieAuthenticationOptions>, ConfigureInternalCookieOptions>();\n        builder.Services.AddSingleton<IPostConfigureOptions<CookieAuthenticationOptions>, PostConfigureInternalCookieOptions>();\n        builder.Services.AddTransientDecorator<IAuthenticationService, IdentityServerAuthenticationService>();\n        builder.Services.AddTransientDecorator<IAuthenticationHandlerProvider, FederatedSignoutAuthenticationHandlerProvider>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the default endpoints.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddDefaultEndpoints(this IIdentityServerBuilder builder)\n    {\n        builder.Services.AddTransient<IEndpointRouter, EndpointRouter>();\n\n        builder.AddEndpoint<AuthorizeCallbackEndpoint>(EndpointNames.Authorize, ProtocolRoutePaths.AuthorizeCallback.EnsureLeadingSlash());\n        builder.AddEndpoint<AuthorizeEndpoint>(EndpointNames.Authorize, ProtocolRoutePaths.Authorize.EnsureLeadingSlash());\n        builder.AddEndpoint<CheckSessionEndpoint>(EndpointNames.CheckSession, ProtocolRoutePaths.CheckSession.EnsureLeadingSlash());\n        builder.AddEndpoint<DeviceAuthorizationEndpoint>(EndpointNames.DeviceAuthorization, ProtocolRoutePaths.DeviceAuthorization.EnsureLeadingSlash());\n        builder.AddEndpoint<DiscoveryKeyEndpoint>(EndpointNames.Discovery, ProtocolRoutePaths.DiscoveryWebKeys.EnsureLeadingSlash());\n        builder.AddEndpoint<DiscoveryEndpoint>(EndpointNames.Discovery, ProtocolRoutePaths.DiscoveryConfiguration.EnsureLeadingSlash());\n        builder.AddEndpoint<EndSessionCallbackEndpoint>(EndpointNames.EndSession, ProtocolRoutePaths.EndSessionCallback.EnsureLeadingSlash());\n        builder.AddEndpoint<EndSessionEndpoint>(EndpointNames.EndSession, ProtocolRoutePaths.EndSession.EnsureLeadingSlash());\n        builder.AddEndpoint<IntrospectionEndpoint>(EndpointNames.Introspection, ProtocolRoutePaths.Introspection.EnsureLeadingSlash());\n        builder.AddEndpoint<TokenRevocationEndpoint>(EndpointNames.Revocation, ProtocolRoutePaths.Revocation.EnsureLeadingSlash());\n        builder.AddEndpoint<TokenEndpoint>(EndpointNames.Token, ProtocolRoutePaths.Token.EnsureLeadingSlash());\n        builder.AddEndpoint<UserInfoEndpoint>(EndpointNames.UserInfo, ProtocolRoutePaths.UserInfo.EnsureLeadingSlash());\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the endpoint.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"path\">The path.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddEndpoint<T>(this IIdentityServerBuilder builder, string name, PathString path)\n        where T : class, IEndpointHandler\n    {\n        builder.Services.AddTransient<T>();\n        builder.Services.AddSingleton(new IdentityServer8.Hosting.Endpoint(name, path, typeof(T)));\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the core services.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddCoreServices(this IIdentityServerBuilder builder)\n    {\n        builder.Services.AddTransient<ISecretsListParser, SecretParser>();\n        builder.Services.AddTransient<ISecretsListValidator, SecretValidator>();\n        builder.Services.AddTransient<ExtensionGrantValidator>();\n        builder.Services.AddTransient<BearerTokenUsageValidator>();\n        builder.Services.AddTransient<JwtRequestValidator>();\n\n        builder.Services.AddTransient<ReturnUrlParser>();\n        builder.Services.AddTransient<IdentityServerTools>();\n\n        builder.Services.AddTransient<IReturnUrlParser, OidcReturnUrlParser>();\n        builder.Services.AddScoped<IUserSession, DefaultUserSession>();\n        builder.Services.AddTransient(typeof(MessageCookie<>));\n\n        builder.Services.AddCors();\n        builder.Services.AddTransientDecorator<ICorsPolicyProvider, CorsPolicyProvider>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the pluggable services.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddPluggableServices(this IIdentityServerBuilder builder)\n    {\n        builder.Services.TryAddTransient<IPersistedGrantService, DefaultPersistedGrantService>();\n        builder.Services.TryAddTransient<IKeyMaterialService, DefaultKeyMaterialService>();\n        builder.Services.TryAddTransient<ITokenService, DefaultTokenService>();\n        builder.Services.TryAddTransient<ITokenCreationService, DefaultTokenCreationService>();\n        builder.Services.TryAddTransient<IClaimsService, DefaultClaimsService>();\n        builder.Services.TryAddTransient<IRefreshTokenService, DefaultRefreshTokenService>();\n        builder.Services.TryAddTransient<IDeviceFlowCodeService, DefaultDeviceFlowCodeService>();\n        builder.Services.TryAddTransient<IConsentService, DefaultConsentService>();\n        builder.Services.TryAddTransient<ICorsPolicyService, DefaultCorsPolicyService>();\n        builder.Services.TryAddTransient<IProfileService, DefaultProfileService>();\n        builder.Services.TryAddTransient<IConsentMessageStore, ConsentMessageStore>();\n        builder.Services.TryAddTransient<IMessageStore<LogoutMessage>, ProtectedDataMessageStore<LogoutMessage>>();\n        builder.Services.TryAddTransient<IMessageStore<LogoutNotificationContext>, ProtectedDataMessageStore<LogoutNotificationContext>>();\n        builder.Services.TryAddTransient<IMessageStore<ErrorMessage>, ProtectedDataMessageStore<ErrorMessage>>();\n        builder.Services.TryAddTransient<IIdentityServerInteractionService, DefaultIdentityServerInteractionService>();\n        builder.Services.TryAddTransient<IDeviceFlowInteractionService, DefaultDeviceFlowInteractionService>();\n        builder.Services.TryAddTransient<IAuthorizationCodeStore, DefaultAuthorizationCodeStore>();\n        builder.Services.TryAddTransient<IRefreshTokenStore, DefaultRefreshTokenStore>();\n        builder.Services.TryAddTransient<IReferenceTokenStore, DefaultReferenceTokenStore>();\n        builder.Services.TryAddTransient<IUserConsentStore, DefaultUserConsentStore>();\n        builder.Services.TryAddTransient<IHandleGenerationService, DefaultHandleGenerationService>();\n        builder.Services.TryAddTransient<IPersistentGrantSerializer, PersistentGrantSerializer>();\n        builder.Services.TryAddTransient<IEventService, DefaultEventService>();\n        builder.Services.TryAddTransient<IEventSink, DefaultEventSink>();\n        builder.Services.TryAddTransient<IUserCodeService, DefaultUserCodeService>();\n        builder.Services.TryAddTransient<IUserCodeGenerator, NumericUserCodeGenerator>();\n        builder.Services.TryAddTransient<ILogoutNotificationService, LogoutNotificationService>();\n        builder.Services.TryAddTransient<IBackChannelLogoutService, DefaultBackChannelLogoutService>();\n        builder.Services.TryAddTransient<IResourceValidator, DefaultResourceValidator>();\n        builder.Services.TryAddTransient<IScopeParser, DefaultScopeParser>();\n\n        builder.AddJwtRequestUriHttpClient();\n        builder.AddBackChannelLogoutHttpClient();\n\n        builder.Services.AddTransient<IClientSecretValidator, ClientSecretValidator>();\n        builder.Services.AddTransient<IApiSecretValidator, ApiSecretValidator>();\n\n        builder.Services.TryAddTransient<IDeviceFlowThrottlingService, DistributedDeviceFlowThrottlingService>();\n        builder.Services.AddDistributedMemoryCache();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the validators.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddValidators(this IIdentityServerBuilder builder)\n    {\n        // core\n        builder.Services.TryAddTransient<IEndSessionRequestValidator, EndSessionRequestValidator>();\n        builder.Services.TryAddTransient<ITokenRevocationRequestValidator, TokenRevocationRequestValidator>();\n        builder.Services.TryAddTransient<IAuthorizeRequestValidator, AuthorizeRequestValidator>();\n        builder.Services.TryAddTransient<ITokenRequestValidator, TokenRequestValidator>();\n        builder.Services.TryAddTransient<IRedirectUriValidator, StrictRedirectUriValidator>();\n        builder.Services.TryAddTransient<ITokenValidator, TokenValidator>();\n        builder.Services.TryAddTransient<IIntrospectionRequestValidator, IntrospectionRequestValidator>();\n        builder.Services.TryAddTransient<IResourceOwnerPasswordValidator, NotSupportedResourceOwnerPasswordValidator>();\n        builder.Services.TryAddTransient<ICustomTokenRequestValidator, DefaultCustomTokenRequestValidator>();\n        builder.Services.TryAddTransient<IUserInfoRequestValidator, UserInfoRequestValidator>();\n        builder.Services.TryAddTransient<IClientConfigurationValidator, DefaultClientConfigurationValidator>();\n        builder.Services.TryAddTransient<IDeviceAuthorizationRequestValidator, DeviceAuthorizationRequestValidator>();\n        builder.Services.TryAddTransient<IDeviceCodeValidator, DeviceCodeValidator>();\n\n        // optional\n        builder.Services.TryAddTransient<ICustomTokenValidator, DefaultCustomTokenValidator>();\n        builder.Services.TryAddTransient<ICustomAuthorizeRequestValidator, DefaultCustomAuthorizeRequestValidator>();\n        \n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the response generators.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddResponseGenerators(this IIdentityServerBuilder builder)\n    {\n        builder.Services.TryAddTransient<ITokenResponseGenerator, TokenResponseGenerator>();\n        builder.Services.TryAddTransient<IUserInfoResponseGenerator, UserInfoResponseGenerator>();\n        builder.Services.TryAddTransient<IIntrospectionResponseGenerator, IntrospectionResponseGenerator>();\n        builder.Services.TryAddTransient<IAuthorizeInteractionResponseGenerator, AuthorizeInteractionResponseGenerator>();\n        builder.Services.TryAddTransient<IAuthorizeResponseGenerator, AuthorizeResponseGenerator>();\n        builder.Services.TryAddTransient<IDiscoveryResponseGenerator, DiscoveryResponseGenerator>();\n        builder.Services.TryAddTransient<ITokenRevocationResponseGenerator, TokenRevocationResponseGenerator>();\n        builder.Services.TryAddTransient<IDeviceAuthorizationResponseGenerator, DeviceAuthorizationResponseGenerator>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the default secret parsers.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddDefaultSecretParsers(this IIdentityServerBuilder builder)\n    {\n        builder.Services.AddTransient<ISecretParser, BasicAuthenticationSecretParser>();\n        builder.Services.AddTransient<ISecretParser, PostBodySecretParser>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the default secret validators.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddDefaultSecretValidators(this IIdentityServerBuilder builder)\n    {\n        builder.Services.AddTransient<ISecretValidator, HashedSharedSecretValidator>();\n\n        return builder;\n    }\n\n    internal static void AddTransientDecorator<TService, TImplementation>(this IServiceCollection services)\n        where TService : class\n        where TImplementation : class, TService\n    {\n        services.AddDecorator<TService>();\n        services.AddTransient<TService, TImplementation>();\n    }\n\n    internal static void AddDecorator<TService>(this IServiceCollection services)\n    {\n        var registration = services.LastOrDefault(x => x.ServiceType == typeof(TService));\n        if (registration == null)\n        {\n            throw new InvalidOperationException(\"Service type: \" + typeof(TService).Name + \" not registered.\");\n        }\n        if (services.Any(x => x.ServiceType == typeof(Decorator<TService>)))\n        {\n            throw new InvalidOperationException(\"Decorator already registered for type: \" + typeof(TService).Name + \".\");\n        }\n\n        services.Remove(registration);\n\n        if (registration.ImplementationInstance != null)\n        {\n            var type = registration.ImplementationInstance.GetType();\n            var innerType = typeof(Decorator<,>).MakeGenericType(typeof(TService), type);\n            services.Add(new ServiceDescriptor(typeof(Decorator<TService>), innerType, ServiceLifetime.Transient));\n            services.Add(new ServiceDescriptor(type, registration.ImplementationInstance));\n        }\n        else if (registration.ImplementationFactory != null)\n        {\n            services.Add(new ServiceDescriptor(typeof(Decorator<TService>), provider =>\n            {\n                return new DisposableDecorator<TService>((TService)registration.ImplementationFactory(provider));\n            }, registration.Lifetime));\n        }\n        else\n        {\n            var type = registration.ImplementationType;\n            var innerType = typeof(Decorator<,>).MakeGenericType(typeof(TService), registration.ImplementationType);\n            services.Add(new ServiceDescriptor(typeof(Decorator<TService>), innerType, ServiceLifetime.Transient));\n            services.Add(new ServiceDescriptor(type, type, registration.Lifetime));\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/BuilderExtensions/Crypto.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\nusing JsonWebKey = Microsoft.IdentityModel.Tokens.JsonWebKey;\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// Builder extension methods for registering crypto services\n/// </summary>\npublic static class IdentityServerBuilderExtensionsCrypto\n{\n    /// <summary>\n    /// Sets the signing credential.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"credential\">The credential.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddSigningCredential(this IIdentityServerBuilder builder, SigningCredentials credential)\n    {\n        if (!(credential.Key is AsymmetricSecurityKey\n            || credential.Key is IdentityModel.Tokens.JsonWebKey && ((IdentityModel.Tokens.JsonWebKey)credential.Key).HasPrivateKey))\n        {\n            throw new InvalidOperationException(\"Signing key is not asymmetric\");\n        }\n\n        if (!IdentityServerConstants.SupportedSigningAlgorithms.Contains(credential.Algorithm, StringComparer.Ordinal))\n        {\n            throw new InvalidOperationException($\"Signing algorithm {credential.Algorithm} is not supported.\");\n        }\n\n        if (credential.Key is ECDsaSecurityKey key && !CryptoHelper.IsValidCurveForAlgorithm(key, credential.Algorithm))\n        {\n            throw new InvalidOperationException(\"Invalid curve for signing algorithm\");\n        }\n\n        if (credential.Key is IdentityModel.Tokens.JsonWebKey jsonWebKey)\n        {\n            if (jsonWebKey.Kty == JsonWebAlgorithmsKeyTypes.EllipticCurve && !CryptoHelper.IsValidCrvValueForAlgorithm(jsonWebKey.Crv))\n                throw new InvalidOperationException(\"Invalid crv value for signing algorithm\");\n        }\n\n        builder.Services.AddSingleton<ISigningCredentialStore>(new InMemorySigningCredentialsStore(credential));\n\n        var keyInfo = new SecurityKeyInfo\n        {\n            Key = credential.Key,\n            SigningAlgorithm = credential.Algorithm\n        };\n\n        builder.Services.AddSingleton<IValidationKeysStore>(new InMemoryValidationKeysStore(new[] { keyInfo }));\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Sets the signing credential.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"certificate\">The certificate.</param>\n    /// <param name=\"signingAlgorithm\">The signing algorithm (defaults to RS256)</param>\n    /// <returns></returns>\n    /// <exception cref=\"ArgumentNullException\"></exception>\n    /// <exception cref=\"InvalidOperationException\">X509 certificate does not have a private key.</exception>\n    public static IIdentityServerBuilder AddSigningCredential(this IIdentityServerBuilder builder, X509Certificate2 certificate, string signingAlgorithm = SecurityAlgorithms.RsaSha256)\n    {\n        if (certificate == null) throw new ArgumentNullException(nameof(certificate));\n\n        if (!certificate.HasPrivateKey)\n        {\n            throw new InvalidOperationException(\"X509 certificate does not have a private key.\");\n        }\n\n        // add signing algorithm name to key ID to allow using the same key for two different algorithms (e.g. RS256 and PS56);\n        var key = new X509SecurityKey(certificate);\n        key.KeyId += signingAlgorithm;\n\n        var credential = new SigningCredentials(key, signingAlgorithm);\n        return builder.AddSigningCredential(credential);\n    }\n\n    /// <summary>\n    /// Sets the signing credential.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"location\">The location.</param>\n    /// <param name=\"nameType\">Name parameter can be either a distinguished name or a thumbprint</param>\n    /// <param name=\"signingAlgorithm\">The signing algorithm (defaults to RS256)</param>\n    /// <exception cref=\"InvalidOperationException\">certificate: '{name}'</exception>\n    public static IIdentityServerBuilder AddSigningCredential(\n        this IIdentityServerBuilder builder,\n        string name,\n        StoreLocation location = StoreLocation.LocalMachine,\n        NameType nameType = NameType.SubjectDistinguishedName,\n        string signingAlgorithm = SecurityAlgorithms.RsaSha256)\n    {\n        var certificate = CryptoHelper.FindCertificate(name, location, nameType);\n        if (certificate == null) throw new InvalidOperationException($\"certificate: '{name}' not found in certificate store\");\n\n        return builder.AddSigningCredential(certificate, signingAlgorithm);\n    }\n\n    /// <summary>\n    /// Sets the signing credential.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"key\">The key.</param>\n    /// <param name=\"signingAlgorithm\">The signing algorithm</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddSigningCredential(this IIdentityServerBuilder builder, SecurityKey key, string signingAlgorithm)\n    {\n        var credential = new SigningCredentials(key, signingAlgorithm);\n        return builder.AddSigningCredential(credential);\n    }\n\n    /// <summary>\n    /// Sets an RSA-based signing credential.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"key\">The RSA key.</param>\n    /// <param name=\"signingAlgorithm\">The signing algorithm</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddSigningCredential(this IIdentityServerBuilder builder, RsaSecurityKey key, IdentityServerConstants.RsaSigningAlgorithm signingAlgorithm)\n    {\n        var credential = new SigningCredentials(key, CryptoHelper.GetRsaSigningAlgorithmValue(signingAlgorithm));\n        return builder.AddSigningCredential(credential);\n    }\n\n    /// <summary>\n    /// Sets an ECDsa-based signing credential.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"key\">The ECDsa key.</param>\n    /// <param name=\"signingAlgorithm\">The signing algorithm</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddSigningCredential(this IIdentityServerBuilder builder, ECDsaSecurityKey key, IdentityServerConstants.ECDsaSigningAlgorithm signingAlgorithm)\n    {\n        var credential = new SigningCredentials(key, CryptoHelper.GetECDsaSigningAlgorithmValue(signingAlgorithm));\n        return builder.AddSigningCredential(credential);\n    }\n\n    /// <summary>\n    /// Sets the temporary signing credential.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"persistKey\">Specifies if the temporary key should be persisted to disk.</param>\n    /// <param name=\"filename\">The filename.</param>\n    /// <param name=\"signingAlgorithm\">The signing algorithm (defaults to RS256)</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddDeveloperSigningCredential(\n        this IIdentityServerBuilder builder,\n        bool persistKey = true,\n        string filename = null,\n        IdentityServerConstants.RsaSigningAlgorithm signingAlgorithm = IdentityServerConstants.RsaSigningAlgorithm.RS256)\n    {\n        if (filename == null)\n        {\n            filename = Path.Combine(Directory.GetCurrentDirectory(), \"tempkey.jwk\");\n        }\n\n        if (File.Exists(filename))\n        {\n            var json = File.ReadAllText(filename);\n            var jwk = new JsonWebKey(json);\n\n            return builder.AddSigningCredential(jwk, jwk.Alg);\n        }\n        else\n        {\n            var key = CryptoHelper.CreateRsaSecurityKey();\n            var jwk = JsonWebKeyConverter.ConvertFromRSASecurityKey(key);\n            jwk.Alg = signingAlgorithm.ToString();\n\n            if (persistKey)\n            {\n                File.WriteAllText(filename, JsonConvert.SerializeObject(jwk));\n            }\n\n            return builder.AddSigningCredential(key, signingAlgorithm);\n        }\n    }\n\n    /// <summary>\n    /// Adds the validation keys.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"keys\">The keys.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddValidationKey(this IIdentityServerBuilder builder, params SecurityKeyInfo[] keys)\n    {\n        builder.Services.AddSingleton<IValidationKeysStore>(new InMemoryValidationKeysStore(keys));\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds an RSA-based validation key.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"key\">The RSA key</param>\n    /// <param name=\"signingAlgorithm\">The RSA-based signing algorithm</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddValidationKey(\n        this IIdentityServerBuilder builder,\n        RsaSecurityKey key,\n        IdentityServerConstants.RsaSigningAlgorithm signingAlgorithm = IdentityServerConstants.RsaSigningAlgorithm.RS256)\n    {\n        var keyInfo = new SecurityKeyInfo\n        {\n            Key = key,\n            SigningAlgorithm = CryptoHelper.GetRsaSigningAlgorithmValue(signingAlgorithm)\n        };\n\n        return builder.AddValidationKey(keyInfo);\n    }\n\n    /// <summary>\n    /// Adds an ECDSA-based validation key.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"key\">The ECDSA key</param>\n    /// <param name=\"signingAlgorithm\">The ECDSA-based signing algorithm</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddValidationKey(\n        this IIdentityServerBuilder builder,\n        ECDsaSecurityKey key,\n        IdentityServerConstants.ECDsaSigningAlgorithm signingAlgorithm = IdentityServerConstants.ECDsaSigningAlgorithm.ES256)\n    {\n        var keyInfo = new SecurityKeyInfo\n        {\n            Key = key,\n            SigningAlgorithm = CryptoHelper.GetECDsaSigningAlgorithmValue(signingAlgorithm)\n        };\n\n        return builder.AddValidationKey(keyInfo);\n    }\n\n    /// <summary>\n    /// Adds the validation key.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"certificate\">The certificate.</param>\n    /// <param name=\"signingAlgorithm\">The signing algorithm</param>\n    /// <returns></returns>\n    /// <exception cref=\"ArgumentNullException\"></exception>\n    public static IIdentityServerBuilder AddValidationKey(\n        this IIdentityServerBuilder builder,\n        X509Certificate2 certificate,\n        string signingAlgorithm = SecurityAlgorithms.RsaSha256)\n    {\n        if (certificate == null) throw new ArgumentNullException(nameof(certificate));\n\n        // add signing algorithm name to key ID to allow using the same key for two different algorithms (e.g. RS256 and PS56);\n        var key = new X509SecurityKey(certificate);\n        key.KeyId += signingAlgorithm;\n        \n        var keyInfo = new SecurityKeyInfo\n        {\n            Key = key,\n            SigningAlgorithm = signingAlgorithm\n        };\n\n        return builder.AddValidationKey(keyInfo);\n    }\n\n    /// <summary>\n    /// Adds the validation key from the certificate store.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"location\">The location.</param>\n    /// <param name=\"nameType\">Name parameter can be either a distinguished name or a thumbprint</param>\n    /// <param name=\"signingAlgorithm\">The signing algorithm</param>\n    public static IIdentityServerBuilder AddValidationKey(\n        this IIdentityServerBuilder builder,\n        string name,\n        StoreLocation location = StoreLocation.LocalMachine,\n        NameType nameType = NameType.SubjectDistinguishedName,\n        string signingAlgorithm = SecurityAlgorithms.RsaSha256)\n    {\n        var certificate = CryptoHelper.FindCertificate(name, location, nameType);\n        if (certificate == null) throw new InvalidOperationException($\"certificate: '{name}' not found in certificate store\");\n\n        return builder.AddValidationKey(certificate, signingAlgorithm);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/BuilderExtensions/InMemory.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// Builder extension methods for registering in-memory services\n/// </summary>\npublic static class IdentityServerBuilderExtensionsInMemory\n{\n    /// <summary>\n    /// Adds the in memory caching.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddInMemoryCaching(this IIdentityServerBuilder builder)\n    {\n        builder.Services.TryAddSingleton<IMemoryCache, MemoryCache>();\n        builder.Services.TryAddTransient(typeof(ICache<>), typeof(DefaultCache<>));\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the in memory identity resources.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"identityResources\">The identity resources.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddInMemoryIdentityResources(this IIdentityServerBuilder builder, IEnumerable<IdentityResource> identityResources)\n    {\n        builder.Services.AddSingleton(identityResources);\n        builder.AddResourceStore<InMemoryResourcesStore>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the in memory identity resources.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"section\">The configuration section containing the configuration data.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddInMemoryIdentityResources(this IIdentityServerBuilder builder, IConfigurationSection section)\n    {\n        var resources = new List<IdentityResource>();\n        section.Bind(resources);\n\n        return builder.AddInMemoryIdentityResources(resources);\n    }\n\n    /// <summary>\n    /// Adds the in memory API resources.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"apiResources\">The API resources.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddInMemoryApiResources(this IIdentityServerBuilder builder, IEnumerable<ApiResource> apiResources)\n    {\n        builder.Services.AddSingleton(apiResources);\n        builder.AddResourceStore<InMemoryResourcesStore>();\n\n        return builder;\n    }\n    \n    /// <summary>\n    /// Adds the in memory API resources.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"section\">The configuration section containing the configuration data.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddInMemoryApiResources(this IIdentityServerBuilder builder, IConfigurationSection section)\n    {\n        var resources = new List<ApiResource>();\n        section.Bind(resources);\n\n        return builder.AddInMemoryApiResources(resources);\n    }\n\n    /// <summary>\n    /// Adds the in memory API scopes.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"apiScopes\">The API scopes.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddInMemoryApiScopes(this IIdentityServerBuilder builder, IEnumerable<ApiScope> apiScopes)\n    {\n        builder.Services.AddSingleton(apiScopes);\n        builder.AddResourceStore<InMemoryResourcesStore>();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds the in memory scopes.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"section\">The configuration section containing the configuration data.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddInMemoryApiScopes(this IIdentityServerBuilder builder, IConfigurationSection section)\n    {\n        var resources = new List<ApiScope>();\n        section.Bind(resources);\n\n        return builder.AddInMemoryApiScopes(resources);\n    }\n\n    /// <summary>\n    /// Adds the in memory clients.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"clients\">The clients.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddInMemoryClients(this IIdentityServerBuilder builder, IEnumerable<Client> clients)\n    {\n        builder.Services.AddSingleton(clients);\n\n        builder.AddClientStore<InMemoryClientStore>();\n\n        var existingCors = builder.Services.Where(x => x.ServiceType == typeof(ICorsPolicyService)).LastOrDefault();\n        if (existingCors != null && \n            existingCors.ImplementationType == typeof(DefaultCorsPolicyService) && \n            existingCors.Lifetime == ServiceLifetime.Transient)\n        {\n            // if our default is registered, then overwrite with the InMemoryCorsPolicyService\n            // otherwise don't overwrite with the InMemoryCorsPolicyService, which uses the custom one registered by the host\n            builder.Services.AddTransient<ICorsPolicyService, InMemoryCorsPolicyService>();\n        }\n\n        return builder;\n    }\n\n\n    /// <summary>\n    /// Adds the in memory clients.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"section\">The configuration section containing the configuration data.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddInMemoryClients(this IIdentityServerBuilder builder, IConfigurationSection section)\n    {\n        var clients = new List<Client>();\n        section.Bind(clients);\n\n        return builder.AddInMemoryClients(clients);\n    }\n\n\n    /// <summary>\n    /// Adds the in memory stores.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddInMemoryPersistedGrants(this IIdentityServerBuilder builder)\n    {\n        builder.Services.TryAddSingleton<IPersistedGrantStore, InMemoryPersistedGrantStore>();\n        builder.Services.TryAddSingleton<IDeviceFlowStore, InMemoryDeviceFlowStore>();\n\n        return builder;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/ConfigureInternalCookieOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\ninternal class ConfigureInternalCookieOptions : IConfigureNamedOptions<CookieAuthenticationOptions>\n{\n    private readonly IdentityServerOptions _idsrv;\n\n    public ConfigureInternalCookieOptions(IdentityServerOptions idsrv)\n    {\n        _idsrv = idsrv;\n    }\n\n    public void Configure(CookieAuthenticationOptions options)\n    {\n    }\n\n    public void Configure(string name, CookieAuthenticationOptions options)\n    {\n        if (name == IdentityServerConstants.DefaultCookieAuthenticationScheme)\n        {\n            options.SlidingExpiration = _idsrv.Authentication.CookieSlidingExpiration;\n            options.ExpireTimeSpan = _idsrv.Authentication.CookieLifetime;\n            options.Cookie.Name = IdentityServerConstants.DefaultCookieAuthenticationScheme;\n            options.Cookie.IsEssential = true;\n            options.Cookie.SameSite = _idsrv.Authentication.CookieSameSiteMode;\n\n            options.LoginPath = ExtractLocalUrl(_idsrv.UserInteraction.LoginUrl);\n            options.LogoutPath = ExtractLocalUrl(_idsrv.UserInteraction.LogoutUrl);\n            if (_idsrv.UserInteraction.LoginReturnUrlParameter != null)\n            {\n                options.ReturnUrlParameter = _idsrv.UserInteraction.LoginReturnUrlParameter;\n            }\n        }\n\n        if (name == IdentityServerConstants.ExternalCookieAuthenticationScheme)\n        {\n            options.Cookie.Name = IdentityServerConstants.ExternalCookieAuthenticationScheme;\n            options.Cookie.IsEssential = true;\n            // https://github.com/alexhiggins732/IdentityServer8/issues/2595\n            // need to set None because iOS 12 safari considers the POST back to the client from the \n            // IdP as not safe, so cookies issued from response (with lax) then should not be honored.\n            // so we need to make those cookies issued without same-site, thus the browser will\n            // hold onto them and send on the next redirect to the callback page.\n            // see: https://brockallen.com/2019/01/11/same-site-cookies-asp-net-core-and-external-authentication-providers/\n            options.Cookie.SameSite = _idsrv.Authentication.CookieSameSiteMode;\n        }\n    }\n\n    private static string ExtractLocalUrl(string url)\n    {\n        if (url.IsLocalUrl())\n        {\n            if (url.StartsWith(\"~/\"))\n            {\n                url = url.Substring(1);\n            }\n\n            return url;\n        }\n\n        return null;\n    }\n}\n\ninternal class PostConfigureInternalCookieOptions : IPostConfigureOptions<CookieAuthenticationOptions>\n{\n    private readonly IdentityServerOptions _idsrv;\n    private readonly IOptions<Microsoft.AspNetCore.Authentication.AuthenticationOptions> _authOptions;\n    private readonly ILogger _logger;\n\n    public PostConfigureInternalCookieOptions(\n        IdentityServerOptions idsrv,\n        IOptions<Microsoft.AspNetCore.Authentication.AuthenticationOptions> authOptions,\n        ILoggerFactory loggerFactory)\n    {\n        _idsrv = idsrv;\n        _authOptions = authOptions;\n        _logger = loggerFactory.CreateLogger(\"IdentityServer8.Startup\");\n    }\n\n    public void PostConfigure(string name, CookieAuthenticationOptions options)\n    {\n        var scheme = _idsrv.Authentication.CookieAuthenticationScheme ??\n            _authOptions.Value.DefaultAuthenticateScheme ??\n            _authOptions.Value.DefaultScheme;\n\n        if (name == scheme)\n        {\n            _idsrv.UserInteraction.LoginUrl = _idsrv.UserInteraction.LoginUrl ?? options.LoginPath;\n            _idsrv.UserInteraction.LoginReturnUrlParameter = _idsrv.UserInteraction.LoginReturnUrlParameter ?? options.ReturnUrlParameter;\n            _idsrv.UserInteraction.LogoutUrl = _idsrv.UserInteraction.LogoutUrl ?? options.LogoutPath;\n\n            _logger.LogDebug(\"Login Url: {url}\", _idsrv.UserInteraction.LoginUrl);\n            _logger.LogDebug(\"Login Return Url Parameter: {param}\", _idsrv.UserInteraction.LoginReturnUrlParameter);\n            _logger.LogDebug(\"Logout Url: {url}\", _idsrv.UserInteraction.LogoutUrl);\n\n            _logger.LogDebug(\"ConsentUrl Url: {url}\", _idsrv.UserInteraction.ConsentUrl);\n            _logger.LogDebug(\"Consent Return Url Parameter: {param}\", _idsrv.UserInteraction.ConsentReturnUrlParameter);\n\n            _logger.LogDebug(\"Error Url: {url}\", _idsrv.UserInteraction.ErrorUrl);\n            _logger.LogDebug(\"Error Id Parameter: {param}\", _idsrv.UserInteraction.ErrorIdParameter);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/ConfigureOpenIdConnectOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\ninternal class ConfigureOpenIdConnectOptions : IPostConfigureOptions<OpenIdConnectOptions>\n{\n    private string[] _schemes;\n    private readonly IHttpContextAccessor _httpContextAccessor;\n\n    public ConfigureOpenIdConnectOptions(string[] schemes, IHttpContextAccessor httpContextAccessor)\n    {\n        _schemes = schemes ?? throw new ArgumentNullException(nameof(schemes));\n        _httpContextAccessor = httpContextAccessor ?? throw new ArgumentNullException(nameof(httpContextAccessor));\n    }\n\n    public void PostConfigure(string name, OpenIdConnectOptions options)\n    {\n        // no schemes means configure them all\n        if (_schemes.Length == 0 || _schemes.Contains(name))\n        {\n            options.StateDataFormat = new DistributedCacheStateDataFormatter(_httpContextAccessor, name);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Decorator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration.DependencyInjection;\n\ninternal class Decorator<TService>\n{\n    public TService Instance { get; set; }\n\n    public Decorator(TService instance)\n    {\n        Instance = instance;\n    }\n}\n\ninternal class Decorator<TService, TImpl> : Decorator<TService>\n    where TImpl : class, TService\n{\n    public Decorator(TImpl instance) : base(instance)\n    {\n    }\n}\n\ninternal class DisposableDecorator<TService> : Decorator<TService>, IDisposable\n{\n    public DisposableDecorator(TService instance) : base(instance)\n    {\n    }\n\n    public void Dispose()\n    {\n        (Instance as IDisposable)?.Dispose();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/IIdentityServerBuilder.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// IdentityServer builder Interface\n/// </summary>\npublic interface IIdentityServerBuilder\n{\n    /// <summary>\n    /// Gets the services.\n    /// </summary>\n    /// <value>\n    /// The services.\n    /// </value>\n    IServiceCollection Services { get; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/IdentityServerBuilder.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// IdentityServer helper class for DI configuration\n/// </summary>\npublic class IdentityServerBuilder : IIdentityServerBuilder\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IdentityServerBuilder\"/> class.\n    /// </summary>\n    /// <param name=\"services\">The services.</param>\n    /// <exception cref=\"System.ArgumentNullException\">services</exception>\n    public IdentityServerBuilder(IServiceCollection services)\n    {\n        Services = services ?? throw new ArgumentNullException(nameof(services));\n    }\n\n    /// <summary>\n    /// Gets the services.\n    /// </summary>\n    /// <value>\n    /// The services.\n    /// </value>\n    public IServiceCollection Services { get; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/IdentityServerServiceCollectionExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// DI extension methods for adding IdentityServer\n/// </summary>\npublic static class IdentityServerServiceCollectionExtensions\n{\n    /// <summary>\n    /// Creates a builder.\n    /// </summary>\n    /// <param name=\"services\">The services.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddIdentityServerBuilder(this IServiceCollection services)\n    {\n        return new IdentityServerBuilder(services);\n    }\n\n    /// <summary>\n    /// Adds IdentityServer.\n    /// </summary>\n    /// <param name=\"services\">The services.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddIdentityServer(this IServiceCollection services)\n    {\n        var builder = services.AddIdentityServerBuilder();\n\n        builder\n            .AddRequiredPlatformServices()\n            .AddCookieAuthentication()\n            .AddCoreServices()\n            .AddDefaultEndpoints()\n            .AddPluggableServices()\n            .AddValidators()\n            .AddResponseGenerators()\n            .AddDefaultSecretParsers()\n            .AddDefaultSecretValidators();\n\n        // provide default in-memory implementation, not suitable for most production scenarios\n        builder.AddInMemoryPersistedGrants();\n\n        return builder;\n    }\n\n    /// <summary>\n    /// Adds IdentityServer.\n    /// </summary>\n    /// <param name=\"services\">The services.</param>\n    /// <param name=\"setupAction\">The setup action.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddIdentityServer(this IServiceCollection services, Action<IdentityServerOptions> setupAction)\n    {\n        services.Configure(setupAction);\n        return services.AddIdentityServer();\n    }\n\n    /// <summary>\n    /// Adds the IdentityServer.\n    /// </summary>\n    /// <param name=\"services\">The services.</param>\n    /// <param name=\"configuration\">The configuration.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddIdentityServer(this IServiceCollection services, IConfiguration configuration)\n    {\n        services.Configure<IdentityServerOptions>(configuration);\n        return services.AddIdentityServer();\n    }\n\n    /// <summary>\n    /// Configures the OpenIdConnect handlers to persist the state parameter into the server-side IDistributedCache.\n    /// </summary>\n    /// <param name=\"services\">The services.</param>\n    /// <param name=\"schemes\">The schemes to configure. If none provided, then all OpenIdConnect schemes will use the cache.</param>\n    public static IServiceCollection AddOidcStateDataFormatterCache(this IServiceCollection services, params string[] schemes)\n    {\n        services.AddSingleton<IPostConfigureOptions<OpenIdConnectOptions>>(\n            svcs => new ConfigureOpenIdConnectOptions(\n                schemes,\n                svcs.GetRequiredService<IHttpContextAccessor>())\n        );\n\n        return services;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/AuthenticationOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Configures the login and logout views and behavior.\n/// </summary>\npublic class AuthenticationOptions\n{\n    /// <summary>\n    /// Sets the cookie authentication scheme configured by the host used for interactive users. If not set, the scheme will inferred from the host's default authentication scheme.\n    /// This setting is typically used when AddPolicyScheme is used in the host as the default scheme.\n    /// </summary>\n    public string CookieAuthenticationScheme { get; set; }\n\n    /// <summary>\n    /// Sets the cookie lifetime (only effective if the IdentityServer-provided cookie handler is used)\n    /// </summary>\n    public TimeSpan CookieLifetime { get; set; } = Constants.DefaultCookieTimeSpan;\n\n    /// <summary>\n    /// Specified if the cookie should be sliding or not (only effective if the built-in cookie middleware is used)\n    /// </summary>\n    public bool CookieSlidingExpiration { get; set; } = false;\n    \n    /// <summary>\n    /// Specifies the SameSite mode for the internal authentication and temp cookie\n    /// </summary>\n    public SameSiteMode CookieSameSiteMode { get; set; } = SameSiteMode.None;\n\n    /// <summary>\n    /// Indicates if user must be authenticated to accept parameters to end session endpoint. Defaults to false.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if required; otherwise, <c>false</c>.\n    /// </value>\n    public bool RequireAuthenticatedUserForSignOutMessage { get; set; } = false;\n\n    /// <summary>\n    /// Gets or sets the name of the cookie used for the check session endpoint.\n    /// </summary>\n    public string CheckSessionCookieName { get; set; } = IdentityServerConstants.DefaultCheckSessionCookieName;\n    \n    /// <summary>\n    /// Gets or sets the domain of the cookie used for the check session endpoint. Defaults to null.\n    /// </summary>\n    public string CheckSessionCookieDomain { get; set; }\n\n    /// <summary>\n    /// Gets or sets the SameSite mode of the cookie used for the check session endpoint. Defaults to SameSiteMode.None.\n    /// </summary>\n    public SameSiteMode CheckSessionCookieSameSiteMode { get; set; } = SameSiteMode.None;\n\n    /// <summary>\n    /// If set, will require frame-src CSP headers being emitting on the end session callback endpoint which renders iframes to clients for front-channel signout notification.\n    /// </summary>\n    public bool RequireCspFrameSrcForSignout { get; set; } = true;\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/CachingOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Caching options.\n/// </summary>\npublic class CachingOptions\n{\n    private static readonly TimeSpan Default = TimeSpan.FromMinutes(15);\n\n    /// <summary>\n    /// Gets or sets the client store expiration.\n    /// </summary>\n    /// <value>\n    /// The client store expiration.\n    /// </value>\n    public TimeSpan ClientStoreExpiration { get; set; } = Default;\n\n    /// <summary>\n    /// Gets or sets the scope store expiration.\n    /// </summary>\n    /// <value>\n    /// The scope store expiration.\n    /// </value>\n    public TimeSpan ResourceStoreExpiration { get; set; } = Default;\n\n    /// <summary>\n    /// Gets or sets the CORS origin expiration.\n    /// </summary>\n    public TimeSpan CorsExpiration { get; set; } = Default;\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/CorsOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Options for CORS\n/// </summary>\npublic class CorsOptions\n{\n    /// <summary>\n    /// Gets or sets the name of the cors policy.\n    /// </summary>\n    /// <value>\n    /// The name of the cors policy.\n    /// </value>\n    public string CorsPolicyName { get; set; } = Constants.IdentityServerName;\n\n    /// <summary>\n    /// The value to be used in the preflight `Access-Control-Max-Age` response header.\n    /// </summary>\n    public TimeSpan? PreflightCacheDuration { get; set; }\n\n    /// <summary>\n    /// Gets or sets the cors paths.\n    /// </summary>\n    /// <value>\n    /// The cors paths.\n    /// </value>\n    public ICollection<PathString> CorsPaths { get; set; } = Constants.ProtocolRoutePaths.CorsPaths.Select(x => new PathString(x.EnsureLeadingSlash())).ToList();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/CspOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Options for Content Security Policy\n/// </summary>\npublic class CspOptions\n{\n    /// <summary>\n    /// Gets or sets the minimum CSP level.\n    /// </summary>\n    public CspLevel Level { get; set; } = CspLevel.Two;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the deprected X-Content-Security-Policy header should be added.\n    /// </summary>\n    public bool AddDeprecatedHeader { get; set; } = true;\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/DeviceFlowOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Configures device flow\n/// </summary>\npublic class DeviceFlowOptions\n{\n    /// <summary>\n    /// Gets or sets the default type of the user code.\n    /// </summary>\n    /// <value>\n    /// The default type of the user code.\n    /// </value>\n    public string DefaultUserCodeType { get; set; } = IdentityServerConstants.UserCodeTypes.Numeric;\n\n    /// <summary>\n    /// Gets or sets the polling interval in seconds.\n    /// </summary>\n    /// <value>\n    /// The interval in seconds.\n    /// </value>\n    public int Interval { get; set; } = 5;\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/DiscoveryOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Options class to configure discovery endpoint\n/// </summary>\npublic class DiscoveryOptions\n{\n    /// <summary>\n    /// Show endpoints\n    /// </summary>\n    public bool ShowEndpoints { get; set; } = true;\n\n    /// <summary>\n    /// Show signing keys\n    /// </summary>\n    public bool ShowKeySet { get; set; } = true;\n\n    /// <summary>\n    /// Show identity scopes\n    /// </summary>\n    public bool ShowIdentityScopes { get; set; } = true;\n\n    /// <summary>\n    /// Show API scopes\n    /// </summary>\n    public bool ShowApiScopes { get; set; } = true;\n\n    /// <summary>\n    /// Show identity claims\n    /// </summary>\n    public bool ShowClaims { get; set; } = true;\n\n    /// <summary>\n    /// Show response types\n    /// </summary>\n    public bool ShowResponseTypes { get; set; } = true;\n\n    /// <summary>\n    /// Show response modes\n    /// </summary>\n    public bool ShowResponseModes { get; set; } = true;\n\n    /// <summary>\n    /// Show standard grant types\n    /// </summary>\n    public bool ShowGrantTypes { get; set; } = true;\n\n    /// <summary>\n    /// Show custom grant types\n    /// </summary>\n    public bool ShowExtensionGrantTypes { get; set; } = true;\n\n    /// <summary>\n    /// Show token endpoint authentication methods\n    /// </summary>\n    public bool ShowTokenEndpointAuthenticationMethods { get; set; } = true;\n\n    /// <summary>\n    /// Turns relative paths that start with ~/ into absolute paths\n    /// </summary>\n    public bool ExpandRelativePathsInCustomEntries { get; set; } = true;\n\n    /// <summary>\n    /// Sets the maxage value of the cache control header (in seconds) of the HTTP response. This gives clients a hint how often they should refresh their cached copy of the discovery document. If set to 0 no-cache headers will be set. Defaults to null, which does not set the header.\n    /// </summary>\n    /// <value>\n    /// The cache interval in seconds.\n    /// </value>\n    public int? ResponseCacheInterval { get; set; } = null;\n\n    /// <summary>\n    /// Adds custom entries to the discovery document\n    /// </summary>\n    public Dictionary<string, object> CustomEntries { get; set; } = new Dictionary<string, object>();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/EndpointOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Configures which endpoints are enabled or disabled.\n/// </summary>\npublic class EndpointsOptions\n{\n    /// <summary>\n    /// Gets or sets a value indicating whether the authorize endpoint is enabled.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the authorize endpoint is enabled; otherwise, <c>false</c>.\n    /// </value>\n    public bool EnableAuthorizeEndpoint { get; set; } = true;\n    \n    /// <summary>\n    /// Gets or sets if JWT request_uri processing is enabled on the authorize endpoint. \n    /// </summary>\n    public bool EnableJwtRequestUri { get; set; } = false;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the token endpoint is enabled.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the token endpoint is enabled; otherwise, <c>false</c>.\n    /// </value>\n    public bool EnableTokenEndpoint { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the user info endpoint is enabled.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the user info endpoint is enabled; otherwise, <c>false</c>.\n    /// </value>\n    public bool EnableUserInfoEndpoint { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the discovery document endpoint is enabled.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the disdovery document endpoint is enabled; otherwise, <c>false</c>.\n    /// </value>\n    public bool EnableDiscoveryEndpoint { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the end session endpoint is enabled.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the end session endpoint is enabled; otherwise, <c>false</c>.\n    /// </value>\n    public bool EnableEndSessionEndpoint { get; set; } = true;\n    \n    /// <summary>\n    /// Gets or sets a value indicating whether the check session endpoint is enabled.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the check session endpoint is enabled; otherwise, <c>false</c>.\n    /// </value>\n    public bool EnableCheckSessionEndpoint { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the token revocation endpoint is enabled.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the token revocation endpoint is enabled; otherwise, <c>false</c>.\n    /// </value>\n    public bool EnableTokenRevocationEndpoint { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the introspection endpoint is enabled.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the introspection endpoint is enabled; otherwise, <c>false</c>.\n    /// </value>\n    public bool EnableIntrospectionEndpoint { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the device authorization endpoint is enabled.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the device authorization endpoint is enabled; otherwise, <c>false</c>.\n    /// </value>\n    public bool EnableDeviceAuthorizationEndpoint { get; set; } = true;\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/EventsOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Configures events\n/// </summary>\npublic class EventsOptions\n{\n    /// <summary>\n    /// Gets or sets a value indicating whether to raise success events.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if success event should be raised; otherwise, <c>false</c>.\n    /// </value>\n    public bool RaiseSuccessEvents { get; set; } = false;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether to raise failure events.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if failure events should be raised; otherwise, <c>false</c>.\n    /// </value>\n    public bool RaiseFailureEvents { get; set; } = false;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether to raise information events.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if information events should be raised; otherwise, <c>false</c>.\n    /// </value>\n    public bool RaiseInformationEvents { get; set; } = false;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether to raise error events.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if error events should be raised; otherwise, <c>false</c>.\n    /// </value>\n    public bool RaiseErrorEvents { get; set; } = false;\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/IdentityServerOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// The IdentityServerOptions class is the top level container for all configuration settings of IdentityServer.\n/// </summary>\npublic class IdentityServerOptions\n{\n    /// <summary>\n    /// Gets or sets the unique name of this server instance, e.g. https://myissuer.com.\n    /// If not set, the issuer name is inferred from the request\n    /// </summary>\n    /// <value>\n    /// Unique name of this server instance, e.g. https://myissuer.com\n    /// </value>\n    public string IssuerUri { get; set; }\n\n    /// <summary>\n    /// Set to false to preserve the original casing of the IssuerUri. Defaults to true.\n    /// </summary>\n    public bool LowerCaseIssuerUri { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets the value for the JWT typ header for access tokens.\n    /// </summary>\n    /// <value>\n    /// The JWT typ value.\n    /// </value>\n    public string AccessTokenJwtType { get; set; } = \"at+jwt\";\n\n    /// <summary>\n    /// Emits an aud claim with the format issuer/resources. That's needed for some older access token validation plumbing. Defaults to false.\n    /// </summary>\n    public bool EmitStaticAudienceClaim { get; set; } = false;\n\n    /// <summary>\n    /// Specifies whether scopes in JWTs are emitted as array or string\n    /// </summary>\n    public bool EmitScopesAsSpaceDelimitedStringInJwt { get; set; } = false;\n    \n    /// <summary>\n    /// Specifies whether the JWT typ and content-type for JWT secured authorization requests is checked according to IETF spec.\n    /// This might break older OIDC conformant request objects.\n    /// </summary>\n    public bool StrictJarValidation { get; set; } = false;\n\n    /// <summary>\n    /// Gets or sets the endpoint configuration.\n    /// </summary>\n    /// <value>\n    /// The endpoints configuration.\n    /// </value>\n    public EndpointsOptions Endpoints { get; set; } = new EndpointsOptions();\n\n    /// <summary>\n    /// Gets or sets the discovery endpoint configuration.\n    /// </summary>\n    /// <value>\n    /// The discovery endpoint configuration.\n    /// </value>\n    public DiscoveryOptions Discovery { get; set; } = new DiscoveryOptions();\n\n    /// <summary>\n    /// Gets or sets the authentication options.\n    /// </summary>\n    /// <value>\n    /// The authentication options.\n    /// </value>\n    public AuthenticationOptions Authentication { get; set; } = new AuthenticationOptions();\n\n    /// <summary>\n    /// Gets or sets the events options.\n    /// </summary>\n    /// <value>\n    /// The events options.\n    /// </value>\n    public EventsOptions Events { get; set; } = new EventsOptions();\n\n    /// <summary>\n    /// Gets or sets the max input length restrictions.\n    /// </summary>\n    /// <value>\n    /// The length restrictions.\n    /// </value>\n    public InputLengthRestrictions InputLengthRestrictions { get; set; } = new InputLengthRestrictions();\n\n    /// <summary>\n    /// Gets or sets the options for the user interaction.\n    /// </summary>\n    /// <value>\n    /// The user interaction options.\n    /// </value>\n    public UserInteractionOptions UserInteraction { get; set; } = new UserInteractionOptions();\n\n    /// <summary>\n    /// Gets or sets the caching options.\n    /// </summary>\n    /// <value>\n    /// The caching options.\n    /// </value>\n    public CachingOptions Caching { get; set; } = new CachingOptions();\n\n    /// <summary>\n    /// Gets or sets the cors options.\n    /// </summary>\n    /// <value>\n    /// The cors options.\n    /// </value>\n    public CorsOptions Cors { get; set; } = new CorsOptions();\n\n    /// <summary>\n    /// Gets or sets the Content Security Policy options.\n    /// </summary>\n    public CspOptions Csp { get; set; } = new CspOptions();\n\n    /// <summary>\n    /// Gets or sets the validation options.\n    /// </summary>\n    public ValidationOptions Validation { get; set; } = new ValidationOptions();\n\n    /// <summary>\n    /// Gets or sets the device flow options.\n    /// </summary>\n    public DeviceFlowOptions DeviceFlow { get; set; } = new DeviceFlowOptions();\n    \n    /// <summary>\n    /// Gets or sets the logging options\n    /// </summary>\n    public LoggingOptions Logging { get; set; } = new LoggingOptions();\n\n    /// <summary>\n    /// Gets or sets the mutual TLS options.\n    /// </summary>\n    public MutualTlsOptions MutualTls { get; set; } = new MutualTlsOptions();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/InputLengthRestrictions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// \n/// </summary>\npublic class InputLengthRestrictions\n{\n    private const int Default = 100;\n\n    /// <summary>\n    /// Max length for client_id\n    /// </summary>\n    public int ClientId { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for external client secrets\n    /// </summary>\n    public int ClientSecret { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for scope\n    /// </summary>\n    public int Scope { get; set; } = 300;\n\n    /// <summary>\n    /// Max length for redirect_uri\n    /// </summary>\n    public int RedirectUri { get; set; } = 400;\n\n    /// <summary>\n    /// Max length for nonce\n    /// </summary>\n    public int Nonce { get; set; } = 300;\n\n    /// <summary>\n    /// Max length for ui_locale\n    /// </summary>\n    public int UiLocale { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for login_hint\n    /// </summary>\n    public int LoginHint { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for acr_values\n    /// </summary>\n    public int AcrValues { get; set; } = 300;\n\n    /// <summary>\n    /// Max length for grant_type\n    /// </summary>\n    public int GrantType { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for username\n    /// </summary>\n    public int UserName { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for password\n    /// </summary>\n    public int Password { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for CSP reports\n    /// </summary>\n    public int CspReport { get; set; } = 2000;\n\n    /// <summary>\n    /// Max length for external identity provider name\n    /// </summary>\n    public int IdentityProvider { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for external identity provider errors\n    /// </summary>\n    public int ExternalError { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for authorization codes\n    /// </summary>\n    public int AuthorizationCode { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for device codes\n    /// </summary>\n    public int DeviceCode { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for refresh tokens\n    /// </summary>\n    public int RefreshToken { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for token handles\n    /// </summary>\n    public int TokenHandle { get; set; } = Default;\n\n    /// <summary>\n    /// Max length for JWTs\n    /// </summary>\n    public int Jwt { get; set; } = 51200;\n\n    /// <summary>\n    /// Min length for the code challenge\n    /// </summary>\n    public int CodeChallengeMinLength { get; } = 43;\n\n    /// <summary>\n    /// Max length for the code challenge\n    /// </summary>\n    public int CodeChallengeMaxLength { get; } = 128;\n\n    /// <summary>\n    /// Min length for the code verifier\n    /// </summary>\n    public int CodeVerifierMinLength { get; } = 43;\n\n    /// <summary>\n    /// Max length for the code verifier\n    /// </summary>\n    public int CodeVerifierMaxLength { get; } = 128;\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/LoggingOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Options for configuring logging behavior\n/// </summary>\npublic class LoggingOptions\n{\n    /// <summary>\n    /// \n    /// </summary>\n    public ICollection<string> TokenRequestSensitiveValuesFilter { get; set; } = \n        new HashSet<string>\n        {\n            OidcConstants.TokenRequest.ClientSecret,\n            OidcConstants.TokenRequest.Password,\n            OidcConstants.TokenRequest.ClientAssertion,\n            OidcConstants.TokenRequest.RefreshToken,\n            OidcConstants.TokenRequest.DeviceCode\n        };\n\n    /// <summary>\n    /// \n    /// </summary>\n    public ICollection<string> AuthorizeRequestSensitiveValuesFilter { get; set; } = \n        new HashSet<string>\n        {\n            OidcConstants.AuthorizeRequest.IdTokenHint\n        };\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/MtlsOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Options for Mutual TLS features\n/// </summary>\npublic class MutualTlsOptions\n{\n    /// <summary>\n    /// Specifies if MTLS support should be enabled\n    /// </summary>\n    public bool Enabled { get; set; }\n\n    /// <summary>\n    /// Specifies the name of the authentication handler for X.509 client certificates\n    /// </summary>\n    public string ClientCertificateAuthenticationScheme { get; set; } = \"Certificate\";\n\n    /// <summary>\n    /// Specifies a separate domain to run the MTLS endpoints on.\n    /// If the string does not contain any dots, a subdomain is assumed - e.g. main domain: identityserver.local, MTLS domain: mtls.identityserver.local\n    /// If the string contains dots, a completely separate domain is assumend, e.g. main domain: identity.app.com, MTLS domain: mtls.app.com. In this case you must set a static issuer name on the options.\n    /// </summary>\n    public string DomainName { get; set; }\n\n    /// <summary>\n    /// Specifies whether a cnf claim gets emitted for access tokens if a client certificate was present.\n    /// Normally the cnf claims only gets emitted if the client used the client certificate for authentication,\n    /// setting this to true, will set the claim regardless of the authentication method. (defaults to false).\n    /// </summary>\n    public bool AlwaysEmitConfirmationClaim { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/UserInteractionOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// Options for aspects of the user interface.\n/// </summary>\npublic class UserInteractionOptions\n{\n    /// <summary>\n    /// Gets or sets the login URL. If a local URL, the value must start with a leading slash.\n    /// </summary>\n    /// <value>\n    /// The login URL.\n    /// </value>\n    public string LoginUrl { get; set; } //= Constants.UIConstants.DefaultRoutePaths.Login.EnsureLeadingSlash();\n\n    /// <summary>\n    /// Gets or sets the login return URL parameter.\n    /// </summary>\n    /// <value>\n    /// The login return URL parameter.\n    /// </value>\n    public string LoginReturnUrlParameter { get; set; } //= Constants.UIConstants.DefaultRoutePathParams.Login;\n\n    /// <summary>\n    /// Gets or sets the logout URL. If a local URL, the value must start with a leading slash.\n    /// </summary>\n    /// <value>\n    /// The logout URL.\n    /// </value>\n    public string LogoutUrl { get; set; } //= Constants.UIConstants.DefaultRoutePaths.Logout.EnsureLeadingSlash();\n\n    /// <summary>\n    /// Gets or sets the logout identifier parameter.\n    /// </summary>\n    /// <value>\n    /// The logout identifier parameter.\n    /// </value>\n    public string LogoutIdParameter { get; set; } = Constants.UIConstants.DefaultRoutePathParams.Logout;\n\n    /// <summary>\n    /// Gets or sets the consent URL. If a local URL, the value must start with a leading slash.\n    /// </summary>\n    /// <value>\n    /// The consent URL.\n    /// </value>\n    public string ConsentUrl { get; set; } = Constants.UIConstants.DefaultRoutePaths.Consent.EnsureLeadingSlash();\n\n    /// <summary>\n    /// Gets or sets the consent return URL parameter.\n    /// </summary>\n    /// <value>\n    /// The consent return URL parameter.\n    /// </value>\n    public string ConsentReturnUrlParameter { get; set; } = Constants.UIConstants.DefaultRoutePathParams.Consent;\n\n    /// <summary>\n    /// Gets or sets the error URL. If a local URL, the value must start with a leading slash.\n    /// </summary>\n    /// <value>\n    /// The error URL.\n    /// </value>\n    public string ErrorUrl { get; set; } = Constants.UIConstants.DefaultRoutePaths.Error.EnsureLeadingSlash();\n\n    /// <summary>\n    /// Gets or sets the error identifier parameter.\n    /// </summary>\n    /// <value>\n    /// The error identifier parameter.\n    /// </value>\n    public string ErrorIdParameter { get; set; } = Constants.UIConstants.DefaultRoutePathParams.Error;\n\n    /// <summary>\n    /// Gets or sets the custom redirect return URL parameter.\n    /// </summary>\n    /// <value>\n    /// The custom redirect return URL parameter.\n    /// </value>\n    public string CustomRedirectReturnUrlParameter { get; set; } = Constants.UIConstants.DefaultRoutePathParams.Custom;\n\n    /// <summary>\n    /// Gets or sets the cookie message threshold. This limits how many cookies are created, and older ones will be purged.\n    /// </summary>\n    /// <value>\n    /// The cookie message threshold.\n    /// </value>\n    public int CookieMessageThreshold { get; set; } = Constants.UIConstants.CookieMessageThreshold;\n\n    /// <summary>\n    /// Gets or sets the device verification URL.  If a local URL, the value must start with a leading slash.\n    /// </summary>\n    /// <value>\n    /// The device verification URL.\n    /// </value>\n    public string DeviceVerificationUrl { get; set; } = Constants.UIConstants.DefaultRoutePaths.DeviceVerification;\n\n    /// <summary>\n    /// Gets or sets the device verification user code paramater.\n    /// </summary>\n    /// <value>\n    /// The device verification user code parameter.\n    /// </value>\n    public string DeviceVerificationUserCodeParameter { get; set; } = Constants.UIConstants.DefaultRoutePathParams.UserCode;\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/DependencyInjection/Options/ValidationOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Configuration;\n\n/// <summary>\n/// The ValidationOptions contains settings that affect some of the default validation behavior.\n/// </summary>\npublic class ValidationOptions\n{\n    /// <summary>\n    ///  Collection of URI scheme prefixes that should never be used as custom URI schemes in the redirect_uri passed to tha authorize endpoint.\n    /// </summary>\n    public ICollection<string> InvalidRedirectUriPrefixes { get; } = new HashSet<string>\n    {\n        \"javascript:\",\n        \"file:\",\n        \"data:\",\n        \"mailto:\",\n        \"ftp:\",\n        \"blob:\",\n        \"about:\",\n        \"ssh:\",\n        \"tel:\",\n        \"view-source:\",\n        \"ws:\",\n        \"wss:\"\n    };\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/IdentityServerApplicationBuilderExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.AspNetCore.Builder;\n\n/// <summary>\n/// Pipeline extension methods for adding IdentityServer\n/// </summary>\npublic static class IdentityServerApplicationBuilderExtensions\n{\n    /// <summary>\n    /// Adds IdentityServer to the pipeline.\n    /// </summary>\n    /// <param name=\"app\">The application.</param>\n    /// <param name=\"options\">The options.</param>\n    /// <returns></returns>\n    public static IApplicationBuilder UseIdentityServer(this IApplicationBuilder app, IdentityServerMiddlewareOptions options = null)\n    {\n        app.Validate();\n\n        app.UseMiddleware<BaseUrlMiddleware>();\n\n        app.ConfigureCors();\n\n        // it seems ok if we have UseAuthentication more than once in the pipeline --\n        // this will just re-run the various callback handlers and the default authN \n        // handler, which just re-assigns the user on the context. claims transformation\n        // will run twice, since that's not cached (whereas the authN handler result is)\n        // related: https://github.com/aspnet/Security/issues/1399\n        if (options == null) options = new IdentityServerMiddlewareOptions();\n        options.AuthenticationMiddleware(app);\n\n        app.UseMiddleware<MutualTlsEndpointMiddleware>();\n        app.UseMiddleware<IdentityServerMiddleware>();\n\n        return app;\n    }\n\n    internal static void Validate(this IApplicationBuilder app)\n    {\n        var loggerFactory = app.ApplicationServices.GetService(typeof(ILoggerFactory)) as ILoggerFactory;\n        if (loggerFactory == null) throw new ArgumentNullException(nameof(loggerFactory));\n\n        var logger = loggerFactory.CreateLogger(\"IdentityServer8.Startup\");\n        logger.LogInformation(\"Starting IdentityServer8 version {version}\", typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.GetCustomAttribute<AssemblyInformationalVersionAttribute>().InformationalVersion);\n\n        var scopeFactory = app.ApplicationServices.GetService<IServiceScopeFactory>();\n\n        using (var scope = scopeFactory.CreateScope())\n        {\n            var serviceProvider = scope.ServiceProvider;\n\n            TestService(serviceProvider, typeof(IPersistedGrantStore), logger, \"No storage mechanism for grants specified. Use the 'AddInMemoryPersistedGrants' extension method to register a development version.\");\n            TestService(serviceProvider, typeof(IClientStore), logger, \"No storage mechanism for clients specified. Use the 'AddInMemoryClients' extension method to register a development version.\");\n            TestService(serviceProvider, typeof(IResourceStore), logger, \"No storage mechanism for resources specified. Use the 'AddInMemoryIdentityResources' or 'AddInMemoryApiResources' extension method to register a development version.\");\n\n            var persistedGrants = serviceProvider.GetService(typeof(IPersistedGrantStore));\n            if (persistedGrants.GetType().FullName == typeof(InMemoryPersistedGrantStore).FullName)\n            {\n                logger.LogInformation(\"You are using the in-memory version of the persisted grant store. This will store consent decisions, authorization codes, refresh and reference tokens in memory only. If you are using any of those features in production, you want to switch to a different store implementation.\");\n            }\n\n            var options = serviceProvider.GetRequiredService<IdentityServerOptions>();\n            ValidateOptions(options, logger);\n\n            ValidateAsync(serviceProvider, logger).GetAwaiter().GetResult();\n        }\n    }\n\n    private static async Task ValidateAsync(IServiceProvider services, ILogger logger)\n    {\n        var options = services.GetRequiredService<IdentityServerOptions>();\n        var schemes = services.GetRequiredService<IAuthenticationSchemeProvider>();\n\n\n        if (await schemes.GetDefaultAuthenticateSchemeAsync() == null && options.Authentication.CookieAuthenticationScheme == null)\n        {\n            logger.LogWarning(\"No authentication scheme has been set. Setting either a default authentication scheme or a CookieAuthenticationScheme on IdentityServerOptions is required.\");\n        }\n        else\n        {\n            AuthenticationScheme authenticationScheme = null;\n\n            if (options.Authentication.CookieAuthenticationScheme != null)\n            {\n                authenticationScheme = await schemes.GetSchemeAsync(options.Authentication.CookieAuthenticationScheme);\n                logger.LogInformation(\"Using explicitly configured authentication scheme {scheme} for IdentityServer\", options.Authentication.CookieAuthenticationScheme);\n            }\n            else\n            {\n                authenticationScheme = await schemes.GetDefaultAuthenticateSchemeAsync();\n                logger.LogInformation(\"Using the default authentication scheme {scheme} for IdentityServer\", authenticationScheme.Name);\n            }\n\n            if (!typeof(IAuthenticationSignInHandler).IsAssignableFrom(authenticationScheme.HandlerType))\n            {\n                logger.LogInformation(\"Authentication scheme {scheme} is configured for IdentityServer, but it is not a scheme that supports signin (like cookies). If you support interactive logins via the browser, then a cookie-based scheme should be used.\", authenticationScheme.Name);\n            }\n\n            logger.LogDebug(\"Using {scheme} as default ASP.NET Core scheme for authentication\", (await schemes.GetDefaultAuthenticateSchemeAsync())?.Name);\n            logger.LogDebug(\"Using {scheme} as default ASP.NET Core scheme for sign-in\", (await schemes.GetDefaultSignInSchemeAsync())?.Name);\n            logger.LogDebug(\"Using {scheme} as default ASP.NET Core scheme for sign-out\", (await schemes.GetDefaultSignOutSchemeAsync())?.Name);\n            logger.LogDebug(\"Using {scheme} as default ASP.NET Core scheme for challenge\", (await schemes.GetDefaultChallengeSchemeAsync())?.Name);\n            logger.LogDebug(\"Using {scheme} as default ASP.NET Core scheme for forbid\", (await schemes.GetDefaultForbidSchemeAsync())?.Name);\n        }\n    }\n\n    private static void ValidateOptions(IdentityServerOptions options, ILogger logger)\n    {\n        if (options.IssuerUri.IsPresent()) logger.LogDebug(\"Custom IssuerUri set to {0}\", options.IssuerUri);\n        \n        // todo: perhaps different logging messages?\n        //if (options.UserInteraction.LoginUrl.IsMissing()) throw new InvalidOperationException(\"LoginUrl is not configured\");\n        //if (options.UserInteraction.LoginReturnUrlParameter.IsMissing()) throw new InvalidOperationException(\"LoginReturnUrlParameter is not configured\");\n        //if (options.UserInteraction.LogoutUrl.IsMissing()) throw new InvalidOperationException(\"LogoutUrl is not configured\");\n        if (options.UserInteraction.LogoutIdParameter.IsMissing()) throw new InvalidOperationException(\"LogoutIdParameter is not configured\");\n        if (options.UserInteraction.ErrorUrl.IsMissing()) throw new InvalidOperationException(\"ErrorUrl is not configured\");\n        if (options.UserInteraction.ErrorIdParameter.IsMissing()) throw new InvalidOperationException(\"ErrorIdParameter is not configured\");\n        if (options.UserInteraction.ConsentUrl.IsMissing()) throw new InvalidOperationException(\"ConsentUrl is not configured\");\n        if (options.UserInteraction.ConsentReturnUrlParameter.IsMissing()) throw new InvalidOperationException(\"ConsentReturnUrlParameter is not configured\");\n        if (options.UserInteraction.CustomRedirectReturnUrlParameter.IsMissing()) throw new InvalidOperationException(\"CustomRedirectReturnUrlParameter is not configured\");\n\n        if (options.Authentication.CheckSessionCookieName.IsMissing()) throw new InvalidOperationException(\"CheckSessionCookieName is not configured\");\n\n        if (options.Cors.CorsPolicyName.IsMissing()) throw new InvalidOperationException(\"CorsPolicyName is not configured\");\n    }\n\n    internal static object TestService(IServiceProvider serviceProvider, Type service, ILogger logger, string message = null, bool doThrow = true)\n    {\n        var appService = serviceProvider.GetService(service);\n\n        if (appService == null)\n        {\n            var error = message ?? $\"Required service {service.FullName} is not registered in the DI container. Aborting startup\";\n\n            logger.LogCritical(error);\n\n            if (doThrow)\n            {\n                throw new InvalidOperationException(error);\n            }\n        }\n\n        return appService;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Configuration/IdentityServerMiddlewareOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.AspNetCore.Builder;\n\n/// <summary>\n/// Options for the IdentityServer middleware\n/// </summary>\npublic class IdentityServerMiddlewareOptions\n{\n    /// <summary>\n    /// Callback to wire up an authentication middleware\n    /// </summary>\n    public Action<IApplicationBuilder> AuthenticationMiddleware { get; set; } = (app) => app.UseAuthentication();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Constants.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8;\n\ninternal static class Constants\n{\n    public const string IdentityServerName               = \"IdentityServer8\";\n    public const string IdentityServerAuthenticationType = IdentityServerName;\n    public const string ExternalAuthenticationMethod     = \"external\";\n    public const string DefaultHashAlgorithm             = \"SHA256\";\n\n    public static readonly TimeSpan DefaultCookieTimeSpan = TimeSpan.FromHours(10);\n    public static readonly TimeSpan DefaultCacheDuration  = TimeSpan.FromMinutes(60);\n\n    public static readonly List<string> SupportedResponseTypes = new List<string> \n    { \n        OidcConstants.ResponseTypes.Code,\n        OidcConstants.ResponseTypes.Token,\n        OidcConstants.ResponseTypes.IdToken,\n        OidcConstants.ResponseTypes.IdTokenToken,\n        OidcConstants.ResponseTypes.CodeIdToken,\n        OidcConstants.ResponseTypes.CodeToken,\n        OidcConstants.ResponseTypes.CodeIdTokenToken\n    };\n\n    public static readonly Dictionary<string, string> ResponseTypeToGrantTypeMapping = new Dictionary<string, string>\n    {\n        { OidcConstants.ResponseTypes.Code, GrantType.AuthorizationCode },\n        { OidcConstants.ResponseTypes.Token, GrantType.Implicit },\n        { OidcConstants.ResponseTypes.IdToken, GrantType.Implicit },\n        { OidcConstants.ResponseTypes.IdTokenToken, GrantType.Implicit },\n        { OidcConstants.ResponseTypes.CodeIdToken, GrantType.Hybrid },\n        { OidcConstants.ResponseTypes.CodeToken, GrantType.Hybrid },\n        { OidcConstants.ResponseTypes.CodeIdTokenToken, GrantType.Hybrid }\n    };\n\n    public static readonly List<string> AllowedGrantTypesForAuthorizeEndpoint = new List<string>\n    {\n        GrantType.AuthorizationCode,\n        GrantType.Implicit,\n        GrantType.Hybrid\n    };\n\n    public static readonly List<string> SupportedCodeChallengeMethods = new List<string>\n    {\n        OidcConstants.CodeChallengeMethods.Plain,\n        OidcConstants.CodeChallengeMethods.Sha256\n    };\n\n    public enum ScopeRequirement\n    {\n        None, \n        ResourceOnly, \n        IdentityOnly,\n        Identity\n    }\n\n    public static readonly Dictionary<string, ScopeRequirement> ResponseTypeToScopeRequirement = new Dictionary<string, ScopeRequirement>\n    {\n        { OidcConstants.ResponseTypes.Code, ScopeRequirement.None },\n        { OidcConstants.ResponseTypes.Token, ScopeRequirement.ResourceOnly },\n        { OidcConstants.ResponseTypes.IdToken, ScopeRequirement.IdentityOnly },\n        { OidcConstants.ResponseTypes.IdTokenToken, ScopeRequirement.Identity },\n        { OidcConstants.ResponseTypes.CodeIdToken, ScopeRequirement.Identity },\n        { OidcConstants.ResponseTypes.CodeToken, ScopeRequirement.Identity },\n        { OidcConstants.ResponseTypes.CodeIdTokenToken, ScopeRequirement.Identity }\n    };\n                        \n    public static readonly Dictionary<string, IEnumerable<string>> AllowedResponseModesForGrantType = new Dictionary<string, IEnumerable<string>>\n    {\n        { GrantType.AuthorizationCode, new[] { OidcConstants.ResponseModes.Query, OidcConstants.ResponseModes.FormPost, OidcConstants.ResponseModes.Fragment } },\n        { GrantType.Hybrid, new[] { OidcConstants.ResponseModes.Fragment, OidcConstants.ResponseModes.FormPost }},\n        { GrantType.Implicit, new[] { OidcConstants.ResponseModes.Fragment, OidcConstants.ResponseModes.FormPost }}\n    };\n\n    public static readonly List<string> SupportedResponseModes = new List<string>\n    {\n        OidcConstants.ResponseModes.FormPost,\n        OidcConstants.ResponseModes.Query,\n        OidcConstants.ResponseModes.Fragment\n    };\n\n    public static string[] SupportedSubjectTypes =\n    {\n        \"pairwise\", \"public\"\n    };\n\n    public static class SigningAlgorithms\n    {\n        public const string RSA_SHA_256 = \"RS256\";\n    }\n\n    public static readonly List<string> SupportedDisplayModes = new List<string>\n    {\n        OidcConstants.DisplayModes.Page,\n        OidcConstants.DisplayModes.Popup,\n        OidcConstants.DisplayModes.Touch,\n        OidcConstants.DisplayModes.Wap\n    };\n\n    public static readonly List<string> SupportedPromptModes = new List<string>\n    {\n        OidcConstants.PromptModes.None,\n        OidcConstants.PromptModes.Login,\n        OidcConstants.PromptModes.Consent,\n        OidcConstants.PromptModes.SelectAccount\n    };\n\n    public static class KnownAcrValues\n    {\n        public const string HomeRealm = \"idp:\";\n        public const string Tenant = \"tenant:\";\n\n        public static readonly string[] All = { HomeRealm, Tenant };\n    }\n\n    public static Dictionary<string, int> ProtectedResourceErrorStatusCodes = new Dictionary<string, int>\n    {\n        { OidcConstants.ProtectedResourceErrors.InvalidToken,      401 },\n        { OidcConstants.ProtectedResourceErrors.ExpiredToken,      401 },\n        { OidcConstants.ProtectedResourceErrors.InvalidRequest,    400 },\n        { OidcConstants.ProtectedResourceErrors.InsufficientScope, 403 }\n    };\n    \n    public static readonly Dictionary<string, IEnumerable<string>> ScopeToClaimsMapping = new Dictionary<string, IEnumerable<string>>\n    {\n        { IdentityServerConstants.StandardScopes.Profile, new[]\n                        { \n                            JwtClaimTypes.Name,\n                            JwtClaimTypes.FamilyName,\n                            JwtClaimTypes.GivenName,\n                            JwtClaimTypes.MiddleName,\n                            JwtClaimTypes.NickName,\n                            JwtClaimTypes.PreferredUserName,\n                            JwtClaimTypes.Profile,\n                            JwtClaimTypes.Picture,\n                            JwtClaimTypes.WebSite,\n                            JwtClaimTypes.Gender,\n                            JwtClaimTypes.BirthDate,\n                            JwtClaimTypes.ZoneInfo,\n                            JwtClaimTypes.Locale,\n                            JwtClaimTypes.UpdatedAt \n                        }},\n        { IdentityServerConstants.StandardScopes.Email, new[]\n                        { \n                            JwtClaimTypes.Email,\n                            JwtClaimTypes.EmailVerified \n                        }},\n        { IdentityServerConstants.StandardScopes.Address, new[]\n                        {\n                            JwtClaimTypes.Address\n                        }},\n        { IdentityServerConstants.StandardScopes.Phone, new[]\n                        {\n                            JwtClaimTypes.PhoneNumber,\n                            JwtClaimTypes.PhoneNumberVerified\n                        }},\n        { IdentityServerConstants.StandardScopes.OpenId, new[]\n                        {\n                            JwtClaimTypes.Subject\n                        }}\n    };\n\n    public static class UIConstants\n    {\n        // the limit after which old messages are purged\n        public const int CookieMessageThreshold = 2;\n\n        public static class DefaultRoutePathParams\n        {\n            public const string Error = \"errorId\";\n            public const string Login = \"returnUrl\";\n            public const string Consent = \"returnUrl\";\n            public const string Logout = \"logoutId\";\n            public const string EndSessionCallback = \"endSessionId\";\n            public const string Custom = \"returnUrl\";\n            public const string UserCode = \"userCode\";\n        }\n\n        public static class DefaultRoutePaths\n        {\n            public const string Login = \"/account/login\";\n            public const string Logout = \"/account/logout\";\n            public const string Consent = \"/consent\";\n            public const string Error = \"/home/error\";\n            public const string DeviceVerification = \"/device\";\n        }\n    }\n\n    public static class EndpointNames\n    {\n        public const string Authorize = \"Authorize\";\n        public const string Token = \"Token\";\n        public const string DeviceAuthorization = \"DeviceAuthorization\";\n        public const string Discovery = \"Discovery\";\n        public const string Introspection = \"Introspection\";\n        public const string Revocation = \"Revocation\";\n        public const string EndSession = \"Endsession\";\n        public const string CheckSession = \"Checksession\";\n        public const string UserInfo = \"Userinfo\";\n    }\n\n    public static class ProtocolRoutePaths\n    {\n        public const string ConnectPathPrefix       = \"connect\";\n\n        public const string Authorize               = ConnectPathPrefix + \"/authorize\";\n        public const string AuthorizeCallback       = Authorize + \"/callback\";\n        public const string DiscoveryConfiguration  = \".well-known/openid-configuration\";\n        public const string DiscoveryWebKeys        = DiscoveryConfiguration + \"/jwks\";\n        public const string Token                   = ConnectPathPrefix + \"/token\";\n        public const string Revocation              = ConnectPathPrefix + \"/revocation\";\n        public const string UserInfo                = ConnectPathPrefix + \"/userinfo\";\n        public const string Introspection           = ConnectPathPrefix + \"/introspect\";\n        public const string EndSession              = ConnectPathPrefix + \"/endsession\";\n        public const string EndSessionCallback      = EndSession + \"/callback\";\n        public const string CheckSession            = ConnectPathPrefix + \"/checksession\";\n        public const string DeviceAuthorization     = ConnectPathPrefix + \"/deviceauthorization\";\n\n        public const string MtlsPathPrefix          = ConnectPathPrefix + \"/mtls\";\n        public const string MtlsToken               = MtlsPathPrefix + \"/token\";\n        public const string MtlsRevocation          = MtlsPathPrefix + \"/revocation\";\n        public const string MtlsIntrospection       = MtlsPathPrefix + \"/introspect\";\n        public const string MtlsDeviceAuthorization = MtlsPathPrefix + \"/deviceauthorization\";\n\n        public static readonly string[] CorsPaths =\n        {\n            DiscoveryConfiguration,\n            DiscoveryWebKeys,\n            Token,\n            UserInfo,\n            Revocation\n        };\n    }\n\n    public static class EnvironmentKeys\n    {\n        public const string IdentityServerBasePath = \"idsvr:IdentityServerBasePath\";\n        [Obsolete(\"The IdentityServerOrigin constant is obsolete.\")]\n        public const string IdentityServerOrigin = \"idsvr:IdentityServerOrigin\"; // todo: deprecate\n        public const string SignOutCalled = \"idsvr:IdentityServerSignOutCalled\";\n    }\n\n    public static class TokenTypeHints\n    {\n        public const string RefreshToken = \"refresh_token\";\n        public const string AccessToken  = \"access_token\";\n    }\n\n    public static List<string> SupportedTokenTypeHints = new List<string>\n    {\n        TokenTypeHints.RefreshToken,\n        TokenTypeHints.AccessToken\n    };\n\n    public static class RevocationErrors\n    {\n        public const string UnsupportedTokenType = \"unsupported_token_type\";\n    }\n\n    public class Filters\n    {\n        // filter for claims from an incoming access token (e.g. used at the user profile endpoint)\n        public static readonly string[] ProtocolClaimsFilter = {\n            JwtClaimTypes.AccessTokenHash,\n            JwtClaimTypes.Audience,\n            JwtClaimTypes.AuthorizedParty,\n            JwtClaimTypes.AuthorizationCodeHash,\n            JwtClaimTypes.ClientId,\n            JwtClaimTypes.Expiration,\n            JwtClaimTypes.IssuedAt,\n            JwtClaimTypes.Issuer,\n            JwtClaimTypes.JwtId,\n            JwtClaimTypes.Nonce,\n            JwtClaimTypes.NotBefore,\n            JwtClaimTypes.ReferenceTokenId,\n            JwtClaimTypes.SessionId,\n            JwtClaimTypes.Scope\n        };\n\n        // filter list for claims returned from profile service prior to creating tokens\n        public static readonly string[] ClaimsServiceFilterClaimTypes = {\n            // TODO: consider JwtClaimTypes.AuthenticationContextClassReference,\n            JwtClaimTypes.AccessTokenHash,\n            JwtClaimTypes.Audience,\n            JwtClaimTypes.AuthenticationMethod,\n            JwtClaimTypes.AuthenticationTime,\n            JwtClaimTypes.AuthorizedParty,\n            JwtClaimTypes.AuthorizationCodeHash,\n            JwtClaimTypes.ClientId,\n            JwtClaimTypes.Expiration,\n            JwtClaimTypes.IdentityProvider,\n            JwtClaimTypes.IssuedAt,\n            JwtClaimTypes.Issuer,\n            JwtClaimTypes.JwtId,\n            JwtClaimTypes.Nonce,\n            JwtClaimTypes.NotBefore,\n            JwtClaimTypes.ReferenceTokenId,\n            JwtClaimTypes.SessionId,\n            JwtClaimTypes.Subject,\n            JwtClaimTypes.Scope,\n            JwtClaimTypes.Confirmation\n        };\n\n        public static readonly string[] JwtRequestClaimTypesFilter = {\n            JwtClaimTypes.Audience,\n            JwtClaimTypes.Expiration,\n            JwtClaimTypes.IssuedAt,\n            JwtClaimTypes.Issuer,\n            JwtClaimTypes.NotBefore,\n            JwtClaimTypes.JwtId\n        };\n    }\n\n    public static class WsFedSignOut\n    {\n        public const string LogoutUriParameterName = \"wa\";\n        public const string LogoutUriParameterValue = \"wsignoutcleanup1.0\";\n    }\n\n    public static class AuthorizationParamsStore\n    {\n        public const string MessageStoreIdParameterName = \"authzId\";\n    }\n\n    public static class CurveOids\n    {\n        public const string P256 = \"1.2.840.10045.3.1.7\";\n        public const string P384 = \"1.3.132.0.34\";\n        public const string P521 = \"1.3.132.0.35\";\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/AuthorizeCallbackEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\ninternal class AuthorizeCallbackEndpoint : AuthorizeEndpointBase\n{\n    private readonly IConsentMessageStore _consentResponseStore;\n    private readonly IAuthorizationParametersMessageStore _authorizationParametersMessageStore;\n\n    public AuthorizeCallbackEndpoint(\n        IEventService events,\n        ILogger<AuthorizeCallbackEndpoint> logger,\n        IdentityServerOptions options,\n        IAuthorizeRequestValidator validator,\n        IAuthorizeInteractionResponseGenerator interactionGenerator,\n        IAuthorizeResponseGenerator authorizeResponseGenerator,\n        IUserSession userSession,\n        IConsentMessageStore consentResponseStore,\n        IAuthorizationParametersMessageStore authorizationParametersMessageStore = null)\n        : base(events, logger, options, validator, interactionGenerator, authorizeResponseGenerator, userSession)\n    {\n        _consentResponseStore = consentResponseStore;\n        _authorizationParametersMessageStore = authorizationParametersMessageStore;\n    }\n\n    public override async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        if (!HttpMethods.IsGet(context.Request.Method))\n        {\n            Logger.LogWarning(\"Invalid HTTP method for authorize endpoint.\");\n            return new StatusCodeResult(HttpStatusCode.MethodNotAllowed);\n        }\n\n        Logger.LogDebug(\"Start authorize callback request\");\n\n        var parameters = context.Request.Query.AsNameValueCollection();\n        if (_authorizationParametersMessageStore != null)\n        {\n            var messageStoreId = parameters[Constants.AuthorizationParamsStore.MessageStoreIdParameterName];\n            var entry = await _authorizationParametersMessageStore.ReadAsync(messageStoreId);\n            parameters = entry?.Data.FromFullDictionary() ?? new NameValueCollection();\n\n            await _authorizationParametersMessageStore.DeleteAsync(messageStoreId);\n        }\n\n        var user = await UserSession.GetUserAsync();\n        var consentRequest = new ConsentRequest(parameters, user?.GetSubjectId());\n        var consent = await _consentResponseStore.ReadAsync(consentRequest.Id);\n\n        if (consent != null && consent.Data == null)\n        {\n            return await CreateErrorResultAsync(\"consent message is missing data\");\n        }\n\n        try\n        {\n            var result = await ProcessAuthorizeRequestAsync(parameters, user, consent?.Data);\n\n            Logger.LogTrace(\"End Authorize Request. Result type: {0}\", result?.GetType().ToString() ?? \"-none-\");\n\n            return result;\n        }\n        finally\n        {\n            if (consent != null)\n            {\n                await _consentResponseStore.DeleteAsync(consentRequest.Id);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/AuthorizeEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\ninternal class AuthorizeEndpoint : AuthorizeEndpointBase\n{\n    public AuthorizeEndpoint(\n       IEventService events,\n       ILogger<AuthorizeEndpoint> logger,\n       IdentityServerOptions options,\n       IAuthorizeRequestValidator validator,\n       IAuthorizeInteractionResponseGenerator interactionGenerator,\n       IAuthorizeResponseGenerator authorizeResponseGenerator,\n       IUserSession userSession)\n        : base(events, logger, options, validator, interactionGenerator, authorizeResponseGenerator, userSession)\n    {\n    }\n\n    public override async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        Logger.LogDebug(\"Start authorize request\");\n\n        NameValueCollection values;\n\n        if (HttpMethods.IsGet(context.Request.Method))\n        {\n            values = context.Request.Query.AsNameValueCollection();\n        }\n        else if (HttpMethods.IsPost(context.Request.Method))\n        {\n            if (!context.Request.HasApplicationFormContentType())\n            {\n                return new StatusCodeResult(HttpStatusCode.UnsupportedMediaType);\n            }\n\n            values = context.Request.Form.AsNameValueCollection();\n        }\n        else\n        {\n            return new StatusCodeResult(HttpStatusCode.MethodNotAllowed);\n        }\n\n        var user = await UserSession.GetUserAsync();\n        var result = await ProcessAuthorizeRequestAsync(values, user, null);\n\n        Logger.LogTrace(\"End authorize request. result type: {0}\", result?.GetType().ToString() ?? \"-none-\");\n\n        return result;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/AuthorizeEndpointBase.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\ninternal abstract class AuthorizeEndpointBase : IEndpointHandler\n{\n    private readonly IAuthorizeResponseGenerator _authorizeResponseGenerator;\n\n    private readonly IEventService _events;\n    private readonly IdentityServerOptions _options;\n\n    private readonly IAuthorizeInteractionResponseGenerator _interactionGenerator;\n\n    private readonly IAuthorizeRequestValidator _validator;\n\n    protected AuthorizeEndpointBase(\n        IEventService events,\n        ILogger<AuthorizeEndpointBase> logger,\n        IdentityServerOptions options,\n        IAuthorizeRequestValidator validator,\n        IAuthorizeInteractionResponseGenerator interactionGenerator,\n        IAuthorizeResponseGenerator authorizeResponseGenerator,\n        IUserSession userSession)\n    {\n        _events = events;\n        _options = options;\n        Logger = logger;\n        _validator = validator;\n        _interactionGenerator = interactionGenerator;\n        _authorizeResponseGenerator = authorizeResponseGenerator;\n        UserSession = userSession;\n    }\n\n    protected ILogger Logger { get; private set; }\n\n    protected IUserSession UserSession { get; private set; }\n\n    public abstract Task<IEndpointResult> ProcessAsync(HttpContext context);\n\n    internal async Task<IEndpointResult> ProcessAuthorizeRequestAsync(NameValueCollection parameters, ClaimsPrincipal user, ConsentResponse consent)\n    {\n        if (user != null)\n        {\n            Logger.LogDebug(\"User in authorize request: {subjectId}\", user.GetSubjectId());\n        }\n        else\n        {\n            Logger.LogDebug(\"No user present in authorize request\");\n        }\n\n        // validate request\n        var result = await _validator.ValidateAsync(parameters, user);\n        if (result.IsError)\n        {\n            return await CreateErrorResultAsync(\n                \"Request validation failed\",\n                result.ValidatedRequest,\n                result.Error,\n                result.ErrorDescription);\n        }\n\n        var request = result.ValidatedRequest;\n        LogRequest(request);\n\n        // determine user interaction\n        var interactionResult = await _interactionGenerator.ProcessInteractionAsync(request, consent);\n        if (interactionResult.IsError)\n        {\n            return await CreateErrorResultAsync(\"Interaction generator error\", request, interactionResult.Error, interactionResult.ErrorDescription, false);\n        }\n        if (interactionResult.IsLogin)\n        {\n            return new LoginPageResult(request);\n        }\n        if (interactionResult.IsConsent)\n        {\n            return new ConsentPageResult(request);\n        }\n        if (interactionResult.IsRedirect)\n        {\n            return new CustomRedirectResult(request, interactionResult.RedirectUrl);\n        }\n\n        var response = await _authorizeResponseGenerator.CreateResponseAsync(request);\n\n        await RaiseResponseEventAsync(response);\n\n        LogResponse(response);\n\n        return new AuthorizeResult(response);\n    }\n\n    protected async Task<IEndpointResult> CreateErrorResultAsync(\n        string logMessage,\n        ValidatedAuthorizeRequest request = null,\n        string error = OidcConstants.AuthorizeErrors.ServerError,\n        string errorDescription = null,\n        bool logError = true)\n    {\n        if (logError)\n        {\n            Logger.LogError(logMessage);\n        }\n\n        if (request != null)\n        {\n            var details = new AuthorizeRequestValidationLog(request, _options.Logging.AuthorizeRequestSensitiveValuesFilter);\n            Logger.LogInformation(\"{@validationDetails}\", details);\n        }\n\n        // TODO: should we raise a token failure event for all errors to the authorize endpoint?\n        await RaiseFailureEventAsync(request, error, errorDescription);\n\n        return new AuthorizeResult(new AuthorizeResponse\n        {\n            Request = request,\n            Error = error,\n            ErrorDescription = errorDescription,\n            SessionState = request?.GenerateSessionStateValue()\n        });\n    }\n\n    private void LogRequest(ValidatedAuthorizeRequest request)\n    {\n        var details = new AuthorizeRequestValidationLog(request, _options.Logging.AuthorizeRequestSensitiveValuesFilter);\n        Logger.LogDebug(nameof(ValidatedAuthorizeRequest) + Environment.NewLine + \"{@validationDetails}\", details);\n    }\n\n    private void LogResponse(AuthorizeResponse response)\n    {\n        var details = new AuthorizeResponseLog(response);\n        Logger.LogDebug(\"Authorize endpoint response\" + Environment.NewLine + \"{@details}\", details);\n    }\n\n    private void LogTokens(AuthorizeResponse response)\n    {\n        var clientId = $\"{response.Request.ClientId} ({response.Request.Client.ClientName ?? \"no name set\"})\";\n        var subjectId = response.Request.Subject.GetSubjectId();\n\n        if (response.IdentityToken != null)\n        {\n            Logger.LogTrace(\"Identity token issued for {clientId} / {subjectId}: {token}\", clientId, subjectId, response.IdentityToken);\n        }\n        if (response.Code != null)\n        {\n            Logger.LogTrace(\"Code issued for {clientId} / {subjectId}: {token}\", clientId, subjectId, response.Code);\n        }\n        if (response.AccessToken != null)\n        {\n            Logger.LogTrace(\"Access token issued for {clientId} / {subjectId}: {token}\", clientId, subjectId, response.AccessToken);\n        }\n    }\n\n    private Task RaiseFailureEventAsync(ValidatedAuthorizeRequest request, string error, string errorDescription)\n    {\n        return _events.RaiseAsync(new TokenIssuedFailureEvent(request, error, errorDescription));\n    }\n\n    private Task RaiseResponseEventAsync(AuthorizeResponse response)\n    {\n        if (!response.IsError)\n        {\n            LogTokens(response);\n            return _events.RaiseAsync(new TokenIssuedSuccessEvent(response));\n        }\n\n        return RaiseFailureEventAsync(response.Request, response.Error, response.ErrorDescription);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/CheckSessionEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\ninternal class CheckSessionEndpoint : IEndpointHandler\n{\n    private readonly ILogger _logger;\n\n    public CheckSessionEndpoint(ILogger<CheckSessionEndpoint> logger)\n    {\n        _logger = logger;\n    }\n\n    public Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        IEndpointResult result;\n\n        if (!HttpMethods.IsGet(context.Request.Method))\n        {\n            _logger.LogWarning(\"Invalid HTTP method for check session endpoint\");\n            result = new StatusCodeResult(HttpStatusCode.MethodNotAllowed);\n        }\n        else\n        {\n            _logger.LogDebug(\"Rendering check session result\");\n            result = new CheckSessionResult();\n        }\n\n        return Task.FromResult(result);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/DeviceAuthorizationEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\n/// <summary>\n/// The device authorization endpoint\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointHandler\" />\ninternal class DeviceAuthorizationEndpoint : IEndpointHandler\n{\n    private readonly IClientSecretValidator _clientValidator;\n    private readonly IDeviceAuthorizationRequestValidator _requestValidator;\n    private readonly IDeviceAuthorizationResponseGenerator _responseGenerator;\n    private readonly IEventService _events;\n    private readonly ILogger<DeviceAuthorizationEndpoint> _logger;\n\n    public DeviceAuthorizationEndpoint(\n        IClientSecretValidator clientValidator,\n        IDeviceAuthorizationRequestValidator requestValidator,\n        IDeviceAuthorizationResponseGenerator responseGenerator,\n        IEventService events,\n        ILogger<DeviceAuthorizationEndpoint> logger)\n    {\n        _clientValidator = clientValidator;\n        _requestValidator = requestValidator;\n        _responseGenerator = responseGenerator;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Processes the request.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.NotImplementedException\"></exception>\n    public async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        _logger.LogTrace(\"Processing device authorize request.\");\n\n        // validate HTTP\n        if (!HttpMethods.IsPost(context.Request.Method) || !context.Request.HasApplicationFormContentType())\n        {\n            _logger.LogWarning(\"Invalid HTTP request for device authorize endpoint\");\n            return Error(OidcConstants.TokenErrors.InvalidRequest);\n        }\n\n        return await ProcessDeviceAuthorizationRequestAsync(context);\n    }\n\n    private async Task<IEndpointResult> ProcessDeviceAuthorizationRequestAsync(HttpContext context)\n    {\n        _logger.LogDebug(\"Start device authorize request.\");\n\n        // validate client\n        var clientResult = await _clientValidator.ValidateAsync(context);\n        if (clientResult.Client == null) return Error(OidcConstants.TokenErrors.InvalidClient);\n\n        // validate request\n        var form = (await context.Request.ReadFormAsync()).AsNameValueCollection();\n        var requestResult = await _requestValidator.ValidateAsync(form, clientResult);\n\n        if (requestResult.IsError)\n        {\n            await _events.RaiseAsync(new DeviceAuthorizationFailureEvent(requestResult));\n            return Error(requestResult.Error, requestResult.ErrorDescription);\n        }\n\n        var baseUrl = context.GetIdentityServerBaseUrl().EnsureTrailingSlash();\n\n        // create response\n        _logger.LogTrace(\"Calling into device authorize response generator: {type}\", _responseGenerator.GetType().FullName);\n        var response = await _responseGenerator.ProcessAsync(requestResult, baseUrl);\n\n        await _events.RaiseAsync(new DeviceAuthorizationSuccessEvent(response, requestResult));\n\n        // return result\n        _logger.LogDebug(\"Device authorize request success.\");\n        return new DeviceAuthorizationResult(response);\n    }\n\n    private TokenErrorResult Error(string error, string errorDescription = null, Dictionary<string, object> custom = null)\n    {\n        var response = new TokenErrorResponse\n        {\n            Error = error,\n            ErrorDescription = errorDescription,\n            Custom = custom\n        };\n\n        _logger.LogError(\"Device authorization error: {error}:{errorDescriptions}\", error, error ?? \"-no message-\");\n\n        return new TokenErrorResult(response);\n    }\n\n    private void LogResponse(DeviceAuthorizationResponse response, DeviceAuthorizationRequestValidationResult requestResult)\n    {\n        var clientId = $\"{requestResult.ValidatedRequest.Client.ClientId} ({requestResult.ValidatedRequest.Client?.ClientName ?? \"no name set\"})\";\n\n        if (response.DeviceCode != null)\n        {\n            _logger.LogTrace(\"Device code issued for {clientId}: {deviceCode}\", clientId, response.DeviceCode);\n        }\n        if (response.UserCode != null)\n        {\n            _logger.LogTrace(\"User code issued for {clientId}: {userCode}\", clientId, response.UserCode);\n        }\n        if (response.VerificationUri != null)\n        {\n            _logger.LogTrace(\"Verification URI issued for {clientId}: {verificationUri}\", clientId, response.VerificationUri);\n        }\n        if (response.VerificationUriComplete != null)\n        {\n            _logger.LogTrace(\"Verification URI (Complete) issued for {clientId}: {verificationUriComplete}\", clientId, response.VerificationUriComplete);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/DiscoveryEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\ninternal class DiscoveryEndpoint : IEndpointHandler\n{\n    private readonly ILogger _logger;\n\n    private readonly IdentityServerOptions _options;\n\n    private readonly IDiscoveryResponseGenerator _responseGenerator;\n\n    public DiscoveryEndpoint(\n        IdentityServerOptions options,\n        IDiscoveryResponseGenerator responseGenerator,\n        ILogger<DiscoveryEndpoint> logger)\n    {\n        _logger = logger;\n        _options = options;\n        _responseGenerator = responseGenerator;\n    }\n\n    public async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        _logger.LogTrace(\"Processing discovery request.\");\n\n        // validate HTTP\n        if (!HttpMethods.IsGet(context.Request.Method))\n        {\n            _logger.LogWarning(\"Discovery endpoint only supports GET requests\");\n            return new StatusCodeResult(HttpStatusCode.MethodNotAllowed);\n        }\n\n        _logger.LogDebug(\"Start discovery request\");\n\n        if (!_options.Endpoints.EnableDiscoveryEndpoint)\n        {\n            _logger.LogInformation(\"Discovery endpoint disabled. 404.\");\n            return new StatusCodeResult(HttpStatusCode.NotFound);\n        }\n\n        var baseUrl = context.GetIdentityServerBaseUrl().EnsureTrailingSlash();\n        var issuerUri = context.GetIdentityServerIssuerUri();\n\n        // generate response\n        _logger.LogTrace(\"Calling into discovery response generator: {type}\", _responseGenerator.GetType().FullName);\n        var response = await _responseGenerator.CreateDiscoveryDocumentAsync(baseUrl, issuerUri);\n\n        return new DiscoveryDocumentResult(response, _options.Discovery.ResponseCacheInterval);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/DiscoveryKeyEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\ninternal class DiscoveryKeyEndpoint : IEndpointHandler\n{\n    private readonly ILogger _logger;\n\n    private readonly IdentityServerOptions _options;\n\n    private readonly IDiscoveryResponseGenerator _responseGenerator;\n\n    public DiscoveryKeyEndpoint(\n        IdentityServerOptions options,\n        IDiscoveryResponseGenerator responseGenerator,\n        ILogger<DiscoveryKeyEndpoint> logger)\n    {\n        _logger = logger;\n        _options = options;\n        _responseGenerator = responseGenerator;\n    }\n\n    public async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        _logger.LogTrace(\"Processing discovery request.\");\n\n        // validate HTTP\n        if (!HttpMethods.IsGet(context.Request.Method))\n        {\n            _logger.LogWarning(\"Discovery endpoint only supports GET requests\");\n            return new StatusCodeResult(HttpStatusCode.MethodNotAllowed);\n        }\n\n        _logger.LogDebug(\"Start key discovery request\");\n\n        if (_options.Discovery.ShowKeySet == false)\n        {\n            _logger.LogInformation(\"Key discovery disabled. 404.\");\n            return new StatusCodeResult(HttpStatusCode.NotFound);\n        }\n\n        // generate response\n        _logger.LogTrace(\"Calling into discovery response generator: {type}\", _responseGenerator.GetType().FullName);\n        var response = await _responseGenerator.CreateJwkDocumentAsync();\n\n        return new JsonWebKeysResult(response, _options.Discovery.ResponseCacheInterval);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/EndSessionCallbackEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\ninternal class EndSessionCallbackEndpoint : IEndpointHandler\n{\n    private readonly IEndSessionRequestValidator _endSessionRequestValidator;\n    private readonly ILogger _logger;\n\n    public EndSessionCallbackEndpoint(\n        IEndSessionRequestValidator endSessionRequestValidator,\n        ILogger<EndSessionCallbackEndpoint> logger)\n    {\n        _endSessionRequestValidator = endSessionRequestValidator;\n        _logger = logger;\n    }\n\n    public async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        if (!HttpMethods.IsGet(context.Request.Method))\n        {\n            _logger.LogWarning(\"Invalid HTTP method for end session callback endpoint.\");\n            return new StatusCodeResult(HttpStatusCode.MethodNotAllowed);\n        }\n\n        _logger.LogDebug(\"Processing signout callback request\");\n\n        var parameters = context.Request.Query.AsNameValueCollection();\n        var result = await _endSessionRequestValidator.ValidateCallbackAsync(parameters);\n\n        if (!result.IsError)\n        {\n            _logger.LogInformation(\"Successful signout callback.\");\n        }\n        else\n        {\n            _logger.LogError(\"Error validating signout callback: {error}\", result.Error);\n        }\n        \n        return new EndSessionCallbackResult(result);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/EndSessionEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\ninternal class EndSessionEndpoint : IEndpointHandler\n{\n    private readonly IEndSessionRequestValidator _endSessionRequestValidator;\n\n    private readonly ILogger _logger;\n\n    private readonly IUserSession _userSession;\n\n    public EndSessionEndpoint(\n        IEndSessionRequestValidator endSessionRequestValidator,\n        IUserSession userSession,\n        ILogger<EndSessionEndpoint> logger)\n    {\n        _endSessionRequestValidator = endSessionRequestValidator;\n        _userSession = userSession;\n        _logger = logger;\n    }\n\n    public async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        NameValueCollection parameters;\n        if (HttpMethods.IsGet(context.Request.Method))\n        {\n            parameters = context.Request.Query.AsNameValueCollection();\n        }\n        else if (HttpMethods.IsPost(context.Request.Method))\n        {\n            parameters = (await context.Request.ReadFormAsync()).AsNameValueCollection();\n        }\n        else\n        {\n            _logger.LogWarning(\"Invalid HTTP method for end session endpoint.\");\n            return new StatusCodeResult(HttpStatusCode.MethodNotAllowed);\n        }\n\n        var user = await _userSession.GetUserAsync();\n\n        _logger.LogDebug(\"Processing signout request for {subjectId}\", user?.GetSubjectId() ?? \"anonymous\");\n\n        var result = await _endSessionRequestValidator.ValidateAsync(parameters, user);\n\n        if (result.IsError)\n        {\n            _logger.LogError(\"Error processing end session request {error}\", result.Error);\n        }\n        else\n        {\n            _logger.LogDebug(\"Success validating end session request from {clientId}\", result.ValidatedRequest?.Client?.ClientId);\n        }\n\n        return new EndSessionResult(result);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/IntrospectionEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\n/// <summary>\n/// Introspection endpoint\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointHandler\" />\ninternal class IntrospectionEndpoint : IEndpointHandler\n{\n    private readonly IIntrospectionResponseGenerator _responseGenerator;\n    private readonly IEventService _events;\n    private readonly ILogger _logger;\n    private readonly IIntrospectionRequestValidator _requestValidator;\n    private readonly IApiSecretValidator _apiSecretValidator;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IntrospectionEndpoint\" /> class.\n    /// </summary>\n    /// <param name=\"apiSecretValidator\">The API secret validator.</param>\n    /// <param name=\"requestValidator\">The request validator.</param>\n    /// <param name=\"responseGenerator\">The generator.</param>\n    /// <param name=\"events\">The events.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public IntrospectionEndpoint(\n        IApiSecretValidator apiSecretValidator,\n        IIntrospectionRequestValidator requestValidator,\n        IIntrospectionResponseGenerator responseGenerator,\n        IEventService events,\n        ILogger<IntrospectionEndpoint> logger)\n    {\n        _apiSecretValidator = apiSecretValidator;\n        _requestValidator = requestValidator;\n        _responseGenerator = responseGenerator;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Processes the request.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        _logger.LogTrace(\"Processing introspection request.\");\n\n        // validate HTTP\n        if (!HttpMethods.IsPost(context.Request.Method))\n        {\n            _logger.LogWarning(\"Introspection endpoint only supports POST requests\");\n            return new StatusCodeResult(HttpStatusCode.MethodNotAllowed);\n        }\n\n        if (!context.Request.HasApplicationFormContentType())\n        {\n            _logger.LogWarning(\"Invalid media type for introspection endpoint\");\n            return new StatusCodeResult(HttpStatusCode.UnsupportedMediaType);\n        }\n\n        return await ProcessIntrospectionRequestAsync(context);\n    }\n\n    private async Task<IEndpointResult> ProcessIntrospectionRequestAsync(HttpContext context)\n    {\n        _logger.LogDebug(\"Starting introspection request.\");\n\n        // caller validation\n        var apiResult = await _apiSecretValidator.ValidateAsync(context);\n        if (apiResult.Resource == null)\n        {\n            _logger.LogError(\"API unauthorized to call introspection endpoint. aborting.\");\n            return new StatusCodeResult(HttpStatusCode.Unauthorized);\n        }\n\n        var body = await context.Request.ReadFormAsync();\n        if (body == null)\n        {\n            _logger.LogError(\"Malformed request body. aborting.\");\n            await _events.RaiseAsync(new TokenIntrospectionFailureEvent(apiResult.Resource.Name, \"Malformed request body\"));\n\n            return new StatusCodeResult(HttpStatusCode.BadRequest);\n        }\n\n        // request validation\n        _logger.LogTrace(\"Calling into introspection request validator: {type}\", _requestValidator.GetType().FullName);\n        var validationResult = await _requestValidator.ValidateAsync(body.AsNameValueCollection(), apiResult.Resource);\n        if (validationResult.IsError)\n        {\n            LogFailure(validationResult.Error, apiResult.Resource.Name);\n            await _events.RaiseAsync(new TokenIntrospectionFailureEvent(apiResult.Resource.Name, validationResult.Error));\n\n            return new BadRequestResult(validationResult.Error);\n        }\n\n        // response generation\n        _logger.LogTrace(\"Calling into introspection response generator: {type}\", _responseGenerator.GetType().FullName);\n        var response = await _responseGenerator.ProcessAsync(validationResult);\n\n        // render result\n        LogSuccess(validationResult.IsActive, validationResult.Api.Name);\n        return new IntrospectionResult(response);\n    }\n\n    private void LogSuccess(bool tokenActive, string apiName)\n    {\n        _logger.LogInformation(\"Success token introspection. Token active: {tokenActive}, for API name: {apiName}\", tokenActive, apiName);\n    }\n\n    private void LogFailure(string error, string apiName)\n    {\n        _logger.LogError(\"Failed token introspection: {error}, for API name: {apiName}\", error, apiName);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/AuthorizeResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\ninternal class AuthorizeResult : IEndpointResult\n{\n    public AuthorizeResponse Response { get; }\n\n    public AuthorizeResult(AuthorizeResponse response)\n    {\n        Response = response ?? throw new ArgumentNullException(nameof(response));\n    }\n\n    internal AuthorizeResult(\n        AuthorizeResponse response,\n        IdentityServerOptions options,\n        IUserSession userSession,\n        IMessageStore<ErrorMessage> errorMessageStore,\n        ISystemClock clock)\n        : this(response)\n    {\n        _options = options;\n        _userSession = userSession;\n        _errorMessageStore = errorMessageStore;\n        _clock = clock;\n    }\n\n    private IdentityServerOptions _options;\n    private IUserSession _userSession;\n    private IMessageStore<ErrorMessage> _errorMessageStore;\n    private ISystemClock _clock;\n\n    private void Init(HttpContext context)\n    {\n        _options = _options ?? context.RequestServices.GetRequiredService<IdentityServerOptions>();\n        _userSession = _userSession ?? context.RequestServices.GetRequiredService<IUserSession>();\n        _errorMessageStore = _errorMessageStore ?? context.RequestServices.GetRequiredService<IMessageStore<ErrorMessage>>();\n        _clock = _clock ?? context.RequestServices.GetRequiredService<ISystemClock>();\n    }\n\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        Init(context);\n\n        if (Response.IsError)\n        {\n            await ProcessErrorAsync(context);\n        }\n        else\n        {\n            await ProcessResponseAsync(context);\n        }\n    }\n\n    private async Task ProcessErrorAsync(HttpContext context)\n    {\n        // these are the conditions where we can send a response \n        // back directly to the client, otherwise we're only showing the error UI\n        var isSafeError =\n            Response.Error == OidcConstants.AuthorizeErrors.AccessDenied ||\n            Response.Error == OidcConstants.AuthorizeErrors.AccountSelectionRequired ||\n            Response.Error == OidcConstants.AuthorizeErrors.LoginRequired ||\n            Response.Error == OidcConstants.AuthorizeErrors.ConsentRequired ||\n            Response.Error == OidcConstants.AuthorizeErrors.InteractionRequired;\n\n        if (isSafeError)\n        {\n            // this scenario we can return back to the client\n            await ProcessResponseAsync(context);\n        }\n        else\n        {\n            // we now know we must show error page\n            await RedirectToErrorPageAsync(context);\n        }\n    }\n\n    protected async Task ProcessResponseAsync(HttpContext context)\n    {\n        if (!Response.IsError)\n        {\n            // success response -- track client authorization for sign-out\n            //_logger.LogDebug(\"Adding client {0} to client list cookie for subject {1}\", request.ClientId, request.Subject.GetSubjectId());\n            await _userSession.AddClientIdAsync(Response.Request.ClientId);\n        }\n\n        await RenderAuthorizeResponseAsync(context);\n    }\n\n    private async Task RenderAuthorizeResponseAsync(HttpContext context)\n    {\n        if (Response.Request.ResponseMode == OidcConstants.ResponseModes.Query ||\n            Response.Request.ResponseMode == OidcConstants.ResponseModes.Fragment)\n        {\n            context.Response.SetNoCache();\n            context.Response.Redirect(BuildRedirectUri());\n        }\n        else if (Response.Request.ResponseMode == OidcConstants.ResponseModes.FormPost)\n        {\n            context.Response.SetNoCache();\n            AddSecurityHeaders(context);\n            await context.Response.WriteHtmlAsync(GetFormPostHtml());\n        }\n        else\n        {\n            //_logger.LogError(\"Unsupported response mode.\");\n            throw new InvalidOperationException(\"Unsupported response mode\");\n        }\n    }\n\n    private void AddSecurityHeaders(HttpContext context)\n    {\n        context.Response.AddScriptCspHeaders(_options.Csp, \"sha256-orD0/VhH8hLqrLxKHD/HUEMdwqX6/0ve7c5hspX5VJ8=\");\n\n        var referrer_policy = \"no-referrer\";\n        if (!context.Response.Headers.ContainsKey(\"Referrer-Policy\"))\n        {\n            context.Response.Headers.Append(\"Referrer-Policy\", referrer_policy);\n        }\n    }\n\n    private string BuildRedirectUri()\n    {\n        var uri = Response.RedirectUri;\n        var query = Response.ToNameValueCollection().ToQueryString();\n\n        if (Response.Request.ResponseMode == OidcConstants.ResponseModes.Query)\n        {\n            uri = uri.AddQueryString(query);\n        }\n        else\n        {\n            uri = uri.AddHashFragment(query);\n        }\n\n        if (Response.IsError && !uri.Contains(\"#\"))\n        {\n            // https://tools.ietf.org/html/draft-bradley-oauth-open-redirector-00\n            uri += \"#_=_\";\n        }\n\n        return uri;\n    }\n\n    private const string FormPostHtml = \"<html><head><meta http-equiv='X-UA-Compatible' content='IE=edge' /><base target='_self'/></head><body><form method='post' action='{uri}'>{body}<noscript><button>Click to continue</button></noscript></form><script>window.addEventListener('load', function(){document.forms[0].submit();});</script></body></html>\";\n\n    private string GetFormPostHtml()\n    {\n        var html = FormPostHtml;\n\n        var url = Response.Request.RedirectUri;\n        url = HtmlEncoder.Default.Encode(url);\n        html = html.Replace(\"{uri}\", url);\n        html = html.Replace(\"{body}\", Response.ToNameValueCollection().ToFormPost());\n\n        return html;\n    }\n\n    private async Task RedirectToErrorPageAsync(HttpContext context)\n    {\n        var errorModel = new ErrorMessage\n        {\n            RequestId = context.TraceIdentifier,\n            Error = Response.Error,\n            ErrorDescription = Response.ErrorDescription,\n            UiLocales = Response.Request?.UiLocales,\n            DisplayMode = Response.Request?.DisplayMode,\n            ClientId = Response.Request?.ClientId\n        };\n\n        if (Response.RedirectUri != null && Response.Request?.ResponseMode != null)\n        {\n            // if we have a valid redirect uri, then include it to the error page\n            errorModel.RedirectUri = BuildRedirectUri();\n            errorModel.ResponseMode = Response.Request.ResponseMode;\n        }\n\n        var message = new Message<ErrorMessage>(errorModel, _clock.UtcNow.UtcDateTime);\n        var id = await _errorMessageStore.WriteAsync(message);\n\n        var errorUrl = _options.UserInteraction.ErrorUrl;\n\n        var url = errorUrl.AddQueryString(_options.UserInteraction.ErrorIdParameter, id);\n        context.Response.RedirectToAbsoluteUrl(url);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/BadRequestResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\ninternal class BadRequestResult : IEndpointResult\n{\n    public string Error { get; set; }\n    public string ErrorDescription { get; set; }\n\n    public BadRequestResult(string error = null, string errorDescription = null)\n    {\n        Error = error;\n        ErrorDescription = errorDescription;\n    }\n\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        context.Response.StatusCode = 400;\n        context.Response.SetNoCache();\n\n        if (Error.IsPresent())\n        {\n            var dto = new ResultDto\n            {\n                error = Error,\n                error_description = ErrorDescription\n            };\n\n            await context.Response.WriteJsonAsync(dto);\n        }\n    }\n\n    internal class ResultDto\n    {\n        public string error { get; set; }\n        public string error_description { get; set; }\n    }    \n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/CheckSessionResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\ninternal class CheckSessionResult : IEndpointResult\n{\n    public CheckSessionResult()\n    {\n    }\n\n    internal CheckSessionResult(IdentityServerOptions options)\n    {\n        _options = options;\n    }\n\n    private IdentityServerOptions _options;\n    private static volatile string FormattedHtml;\n    private static readonly object Lock = new object();\n    private static volatile string LastCheckSessionCookieName;\n\n    private void Init(HttpContext context)\n    {\n        _options = _options ?? context.RequestServices.GetRequiredService<IdentityServerOptions>();\n    }\n\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        Init(context);\n\n        AddCspHeaders(context);\n\n        var html = GetHtml(_options.Authentication.CheckSessionCookieName);\n        await context.Response.WriteHtmlAsync(html);\n    }\n\n    private void AddCspHeaders(HttpContext context)\n    {\n        context.Response.AddScriptCspHeaders(_options.Csp, \"sha256-fa5rxHhZ799izGRP38+h4ud5QXNT0SFaFlh4eqDumBI=\");\n    }\n    private string GetHtml(string cookieName)\n    {\n        if (cookieName != LastCheckSessionCookieName)\n        {\n            lock (Lock)\n            {\n                if (cookieName != LastCheckSessionCookieName)\n                {\n                    FormattedHtml = Html.Replace(\"{cookieName}\", cookieName);\n                    LastCheckSessionCookieName = cookieName;\n                }\n            }\n        }\n        return FormattedHtml;\n    }\n\n    private const string Html = @\"\n<!DOCTYPE html>\n<!--Copyright (c) Brock Allen & Dominick Baier. All rights reserved.-->\n<!--Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information.-->\n<html>\n<head>\n    <meta http-equiv='X-UA-Compatible' content='IE=edge' />\n    <title>Check Session IFrame</title>\n</head>\n<body>\n    <script id='cookie-name' type='application/json'>{cookieName}</script>\n    <script>\n/* - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -  */\n/*  SHA-256 implementation in JavaScript                (c) Chris Veness 2002-2014 / MIT Licence  */\n/*                                                                                                */\n/*  - see http://csrc.nist.gov/groups/ST/toolkit/secure_hashing.html                              */\n/*        http://csrc.nist.gov/groups/ST/toolkit/examples.html                                    */\n/* - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -  */\n\n/* jshint node:true *//* global define, escape, unescape */\n'use strict';\n\n\n/**\n * SHA-256 hash function reference implementation.\n *\n * @namespace\n */\nvar Sha256 = {};\n\n\n/**\n * Generates SHA-256 hash of string.\n *\n * @param   {string} msg - String to be hashed\n * @returns {string} Hash of msg as hex character string\n */\nSha256.hash = function(msg) {\n    // convert string to UTF-8, as SHA only deals with byte-streams\n    msg = msg.utf8Encode();\n    \n    // constants [§4.2.2]\n    var K = [\n        0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5, 0x3956c25b, 0x59f111f1, 0x923f82a4, 0xab1c5ed5,\n        0xd807aa98, 0x12835b01, 0x243185be, 0x550c7dc3, 0x72be5d74, 0x80deb1fe, 0x9bdc06a7, 0xc19bf174,\n        0xe49b69c1, 0xefbe4786, 0x0fc19dc6, 0x240ca1cc, 0x2de92c6f, 0x4a7484aa, 0x5cb0a9dc, 0x76f988da,\n        0x983e5152, 0xa831c66d, 0xb00327c8, 0xbf597fc7, 0xc6e00bf3, 0xd5a79147, 0x06ca6351, 0x14292967,\n        0x27b70a85, 0x2e1b2138, 0x4d2c6dfc, 0x53380d13, 0x650a7354, 0x766a0abb, 0x81c2c92e, 0x92722c85,\n        0xa2bfe8a1, 0xa81a664b, 0xc24b8b70, 0xc76c51a3, 0xd192e819, 0xd6990624, 0xf40e3585, 0x106aa070,\n        0x19a4c116, 0x1e376c08, 0x2748774c, 0x34b0bcb5, 0x391c0cb3, 0x4ed8aa4a, 0x5b9cca4f, 0x682e6ff3,\n        0x748f82ee, 0x78a5636f, 0x84c87814, 0x8cc70208, 0x90befffa, 0xa4506ceb, 0xbef9a3f7, 0xc67178f2 ];\n    // initial hash value [§5.3.1]\n    var H = [\n        0x6a09e667, 0xbb67ae85, 0x3c6ef372, 0xa54ff53a, 0x510e527f, 0x9b05688c, 0x1f83d9ab, 0x5be0cd19 ];\n\n    // PREPROCESSING \n \n    msg += String.fromCharCode(0x80);  // add trailing '1' bit (+ 0's padding) to string [§5.1.1]\n\n    // convert string msg into 512-bit/16-integer blocks arrays of ints [§5.2.1]\n    var l = msg.length/4 + 2; // length (in 32-bit integers) of msg + ‘1’ + appended length\n    var N = Math.ceil(l/16);  // number of 16-integer-blocks required to hold 'l' ints\n    var M = new Array(N);\n\n    for (var i=0; i<N; i++) {\n        M[i] = new Array(16);\n        for (var j=0; j<16; j++) {  // encode 4 chars per integer, big-endian encoding\n            M[i][j] = (msg.charCodeAt(i*64+j*4)<<24) | (msg.charCodeAt(i*64+j*4+1)<<16) | \n                      (msg.charCodeAt(i*64+j*4+2)<<8) | (msg.charCodeAt(i*64+j*4+3));\n        } // note running off the end of msg is ok 'cos bitwise ops on NaN return 0\n    }\n    // add length (in bits) into final pair of 32-bit integers (big-endian) [§5.1.1]\n    // note: most significant word would be (len-1)*8 >>> 32, but since JS converts\n    // bitwise-op args to 32 bits, we need to simulate this by arithmetic operators\n    M[N-1][14] = ((msg.length-1)*8) / Math.pow(2, 32); M[N-1][14] = Math.floor(M[N-1][14]);\n    M[N-1][15] = ((msg.length-1)*8) & 0xffffffff;\n\n\n    // HASH COMPUTATION [§6.1.2]\n\n    var W = new Array(64); var a, b, c, d, e, f, g, h;\n    for (var i=0; i<N; i++) {\n\n        // 1 - prepare message schedule 'W'\n        for (var t=0;  t<16; t++) W[t] = M[i][t];\n        for (var t=16; t<64; t++) W[t] = (Sha256.σ1(W[t-2]) + W[t-7] + Sha256.σ0(W[t-15]) + W[t-16]) & 0xffffffff;\n\n        // 2 - initialise working variables a, b, c, d, e, f, g, h with previous hash value\n        a = H[0]; b = H[1]; c = H[2]; d = H[3]; e = H[4]; f = H[5]; g = H[6]; h = H[7];\n\n        // 3 - main loop (note 'addition modulo 2^32')\n        for (var t=0; t<64; t++) {\n            var T1 = h + Sha256.Σ1(e) + Sha256.Ch(e, f, g) + K[t] + W[t];\n            var T2 =     Sha256.Σ0(a) + Sha256.Maj(a, b, c);\n            h = g;\n            g = f;\n            f = e;\n            e = (d + T1) & 0xffffffff;\n            d = c;\n            c = b;\n            b = a;\n            a = (T1 + T2) & 0xffffffff;\n        }\n         // 4 - compute the new intermediate hash value (note 'addition modulo 2^32')\n        H[0] = (H[0]+a) & 0xffffffff;\n        H[1] = (H[1]+b) & 0xffffffff; \n        H[2] = (H[2]+c) & 0xffffffff; \n        H[3] = (H[3]+d) & 0xffffffff; \n        H[4] = (H[4]+e) & 0xffffffff;\n        H[5] = (H[5]+f) & 0xffffffff;\n        H[6] = (H[6]+g) & 0xffffffff; \n        H[7] = (H[7]+h) & 0xffffffff; \n    }\n\n    return Sha256.toHexStr(H[0]) + Sha256.toHexStr(H[1]) + Sha256.toHexStr(H[2]) + Sha256.toHexStr(H[3]) + \n           Sha256.toHexStr(H[4]) + Sha256.toHexStr(H[5]) + Sha256.toHexStr(H[6]) + Sha256.toHexStr(H[7]);\n};\n\n\n/**\n * Rotates right (circular right shift) value x by n positions [§3.2.4].\n * @private\n */\nSha256.ROTR = function(n, x) {\n    return (x >>> n) | (x << (32-n));\n};\n\n/**\n * Logical functions [§4.1.2].\n * @private\n */\nSha256.Σ0  = function(x) { return Sha256.ROTR(2,  x) ^ Sha256.ROTR(13, x) ^ Sha256.ROTR(22, x); };\nSha256.Σ1  = function(x) { return Sha256.ROTR(6,  x) ^ Sha256.ROTR(11, x) ^ Sha256.ROTR(25, x); };\nSha256.σ0  = function(x) { return Sha256.ROTR(7,  x) ^ Sha256.ROTR(18, x) ^ (x>>>3);  };\nSha256.σ1  = function(x) { return Sha256.ROTR(17, x) ^ Sha256.ROTR(19, x) ^ (x>>>10); };\nSha256.Ch  = function(x, y, z) { return (x & y) ^ (~x & z); };\nSha256.Maj = function(x, y, z) { return (x & y) ^ (x & z) ^ (y & z); };\n\n\n/**\n * Hexadecimal representation of a number.\n * @private\n */\nSha256.toHexStr = function(n) {\n    // note can't use toString(16) as it is implementation-dependant,\n    // and in IE returns signed numbers when used on full words\n    var s='', v;\n    for (var i=7; i>=0; i--) { v = (n>>>(i*4)) & 0xf; s += v.toString(16); }\n    return s;\n};\n\n\n/* - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -  */\n\n\n/** Extend String object with method to encode multi-byte string to utf8\n *  - monsur.hossa.in/2012/07/20/utf-8-in-javascript.html */\nif (typeof String.prototype.utf8Encode == 'undefined') {\n    String.prototype.utf8Encode = function() {\n        return unescape( encodeURIComponent( this ) );\n    };\n}\n\n/** Extend String object with method to decode utf8 string to multi-byte */\nif (typeof String.prototype.utf8Decode == 'undefined') {\n    String.prototype.utf8Decode = function() {\n        try {\n            return decodeURIComponent( escape( this ) );\n        } catch (e) {\n            return this; // invalid UTF-8? return as-is\n        }\n    };\n}\n\n\n/* - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -  */\nif (typeof module != 'undefined' && module.exports) module.exports = Sha256; // CommonJs export\nif (typeof define == 'function' && define.amd) define([], function() { return Sha256; }); // AMD\n\n////////////////////////////////////////////////////////////////////\n///////////// IdentityServer JS Code Starts here ///////////////////\n////////////////////////////////////////////////////////////////////\n\n        function getCookies() {\n            var allCookies = document.cookie;\n            var cookies = allCookies.split(';');\n            return cookies.map(function(value) {\n                var parts = value.trim().split('=');\n                if (parts.length === 2) {\n                    return {\n                        name: parts[0].trim(),\n                        value: parts[1].trim()\n                    };\n                }\n            }).filter(function(item) {\n                return item && item.name && item.value;\n            });\n        }\n\n        function getBrowserSessionId() {\n            var cookies = getCookies().filter(function(cookie) {\n                return (cookie.name === cookieName);\n            });\n            // empty string represents anonymous sid\n            return (cookies[0] && cookies[0].value) || '';\n        }\n\n        /*! (c) Tom Wu | http://www-cs-students.stanford.edu/~tjw/jsbn/ */\n        var b64map = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/';\n        var b64pad = '=';\n\n        function hex2b64(h) {\n            var i;\n            var c;\n            var ret = '';\n            for (i = 0; i + 3 <= h.length; i += 3) {\n                c = parseInt(h.substring(i, i + 3), 16);\n                ret += b64map.charAt(c >> 6) + b64map.charAt(c & 63);\n            }\n            if (i + 1 == h.length) {\n                c = parseInt(h.substring(i, i + 1), 16);\n                ret += b64map.charAt(c << 2);\n            }\n            else if (i + 2 == h.length) {\n                c = parseInt(h.substring(i, i + 2), 16);\n                ret += b64map.charAt(c >> 2) + b64map.charAt((c & 3) << 4);\n            }\n            if (b64pad) while ((ret.length & 3) > 0) ret += b64pad;\n            return ret;\n        }\n\n        function base64UrlEncode(s){\n            var val = hex2b64(s);\n\n            val = val.replace(/=/g, ''); // Remove any trailing '='s\n            val = val.replace(/\\+/g, '-'); // '+' => '-'\n            val = val.replace(/\\//g, '_'); // '/' => '_'\n\n            return val;\n        }\n\n        function hash(value) {\n            var hash = Sha256.hash(value);\n            return base64UrlEncode(hash);\n        }\n\n        function computeSessionStateHash(clientId, origin, sessionId, salt) {\n            return hash(clientId + origin + sessionId + salt);\n        }\n\n        function calculateSessionStateResult(origin, message) {\n            try {\n                if (!origin || !message) {\n                    return 'error';\n                }\n\n                var idx = message.lastIndexOf(' ');\n                if (idx < 0 || idx >= message.length) {\n                    return 'error';\n                }\n\n                var clientId = message.substring(0, idx);\n                var sessionState = message.substring(idx + 1);\n\n                if (!clientId || !sessionState) {\n                    return 'error';\n                }\n\n                var sessionStateParts = sessionState.split('.');\n                if (sessionStateParts.length !== 2) {\n                    return 'error';\n                }\n\n                var clientHash = sessionStateParts[0];\n                var salt = sessionStateParts[1];\n                if (!clientHash || !salt) {\n                    return 'error';\n                }\n\n                var currentSessionId = getBrowserSessionId();\n                var expectedHash = computeSessionStateHash(clientId, origin, currentSessionId, salt);\n                return clientHash === expectedHash ? 'unchanged' : 'changed';\n            }\n            catch (e) {\n                return 'error';\n            }\n        }\n\n        var cookieNameElem = document.getElementById('cookie-name');\n        if (cookieNameElem) {\n            var cookieName = cookieNameElem.textContent.trim();\n        }\n\n        if (cookieName && window.parent !== window) {\n            window.addEventListener('message', function(e) {\n                if (window === e.source) {\n                    // ignore browser extensions that are sending messages.\n                    return;\n                }\n\n                if (typeof e.data !== 'string') {\n                    return;\n                }\n\n                var result = calculateSessionStateResult(e.origin, e.data);\n                e.source.postMessage(result, e.origin);\n            }, false);\n        }\n    </script>\n</body>\n</html>\n\";\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/ConsentPageResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\n/// <summary>\n/// Result for consent page\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointResult\" />\npublic class ConsentPageResult : IEndpointResult\n{\n    private readonly ValidatedAuthorizeRequest _request;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ConsentPageResult\"/> class.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <exception cref=\"System.ArgumentNullException\">request</exception>\n    public ConsentPageResult(ValidatedAuthorizeRequest request)\n    {\n        _request = request ?? throw new ArgumentNullException(nameof(request));\n    }\n\n    internal ConsentPageResult(\n        ValidatedAuthorizeRequest request,\n        IdentityServerOptions options,\n        IAuthorizationParametersMessageStore authorizationParametersMessageStore = null) \n        : this(request)\n    {\n        _options = options;\n        _authorizationParametersMessageStore = authorizationParametersMessageStore;\n    }\n\n    private IdentityServerOptions _options;\n    private IAuthorizationParametersMessageStore _authorizationParametersMessageStore;\n\n    private void Init(HttpContext context)\n    {\n        _options = _options ?? context.RequestServices.GetRequiredService<IdentityServerOptions>();\n        _authorizationParametersMessageStore = _authorizationParametersMessageStore ?? context.RequestServices.GetService<IAuthorizationParametersMessageStore>();\n    }\n\n    /// <summary>\n    /// Executes the result.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        Init(context);\n\n        var returnUrl = context.GetIdentityServerBasePath().EnsureTrailingSlash() + Constants.ProtocolRoutePaths.AuthorizeCallback;\n        if (_authorizationParametersMessageStore != null)\n        {\n            var msg = new Message<IDictionary<string, string[]>>(_request.Raw.ToFullDictionary());\n            var id = await _authorizationParametersMessageStore.WriteAsync(msg);\n            returnUrl = returnUrl.AddQueryString(Constants.AuthorizationParamsStore.MessageStoreIdParameterName, id);\n        }\n        else\n        {\n            returnUrl = returnUrl.AddQueryString(_request.Raw.ToQueryString());\n        }\n\n        var consentUrl = _options.UserInteraction.ConsentUrl;\n        if (!consentUrl.IsLocalUrl())\n        {\n            // this converts the relative redirect path to an absolute one if we're \n            // redirecting to a different server\n            returnUrl = context.GetIdentityServerHost().EnsureTrailingSlash() + returnUrl.RemoveLeadingSlash();\n        }\n\n        var url = consentUrl.AddQueryString(_options.UserInteraction.ConsentReturnUrlParameter, returnUrl);\n        context.Response.RedirectToAbsoluteUrl(url);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/CustomRedirectResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\n/// <summary>\n/// Result for a custom redirect\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointResult\" />\npublic class CustomRedirectResult : IEndpointResult\n{\n    private readonly ValidatedAuthorizeRequest _request;\n    private readonly string _url;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"CustomRedirectResult\"/> class.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"url\">The URL.</param>\n    /// <exception cref=\"System.ArgumentNullException\">\n    /// request\n    /// or\n    /// url\n    /// </exception>\n    public CustomRedirectResult(ValidatedAuthorizeRequest request, string url)\n    {\n        if (request == null) throw new ArgumentNullException(nameof(request));\n        if (url.IsMissing()) throw new ArgumentNullException(nameof(url));\n\n        _request = request;\n        _url = url;\n    }\n\n    internal CustomRedirectResult(\n        ValidatedAuthorizeRequest request,\n        string url,\n        IdentityServerOptions options) \n        : this(request, url)\n    {\n        _options = options;\n    }\n\n    private IdentityServerOptions _options;\n\n    private void Init(HttpContext context)\n    {\n        _options = _options ?? context.RequestServices.GetRequiredService<IdentityServerOptions>();\n    }\n\n    /// <summary>\n    /// Executes the result.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public Task ExecuteAsync(HttpContext context)\n    {\n        Init(context);\n\n        var returnUrl = context.GetIdentityServerBasePath().EnsureTrailingSlash() + Constants.ProtocolRoutePaths.Authorize;\n        returnUrl = returnUrl.AddQueryString(_request.Raw.ToQueryString());\n\n        if (!_url.IsLocalUrl())\n        {\n            // this converts the relative redirect path to an absolute one if we're \n            // redirecting to a different server\n            returnUrl = context.GetIdentityServerBaseUrl().EnsureTrailingSlash() + returnUrl.RemoveLeadingSlash();\n        }\n\n        var url = _url.AddQueryString(_options.UserInteraction.CustomRedirectReturnUrlParameter, returnUrl);\n        context.Response.RedirectToAbsoluteUrl(url);\n\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/DeviceAuthorizationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\ninternal class DeviceAuthorizationResult : IEndpointResult\n{\n    public DeviceAuthorizationResponse Response { get; }\n\n    public DeviceAuthorizationResult(DeviceAuthorizationResponse response)\n    {\n        Response = response ?? throw new ArgumentNullException(nameof(response));\n    }\n\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        context.Response.SetNoCache();\n\n        var dto = new ResultDto\n        {\n            device_code = Response.DeviceCode,\n            user_code = Response.UserCode,\n            verification_uri = Response.VerificationUri,\n            verification_uri_complete = Response.VerificationUriComplete,\n            expires_in = Response.DeviceCodeLifetime,\n            interval = Response.Interval\n        };\n\n        await context.Response.WriteJsonAsync(dto);\n    }\n\n    internal class ResultDto\n    {\n        public string device_code { get; set; }\n        public string user_code { get; set; }\n        public string verification_uri { get; set; }\n        public string verification_uri_complete { get; set; }\n        public int expires_in { get; set; }\n        public int interval { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/DiscoveryDocumentResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\n/// <summary>\n/// Result for a discovery document\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointResult\" />\npublic class DiscoveryDocumentResult : IEndpointResult\n{\n    /// <summary>\n    /// Gets the entries.\n    /// </summary>\n    /// <value>\n    /// The entries.\n    /// </value>\n    public Dictionary<string, object> Entries { get; }\n\n    /// <summary>\n    /// Gets the maximum age.\n    /// </summary>\n    /// <value>\n    /// The maximum age.\n    /// </value>\n    public int? MaxAge { get; }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DiscoveryDocumentResult\" /> class.\n    /// </summary>\n    /// <param name=\"entries\">The entries.</param>\n    /// <param name=\"maxAge\">The maximum age.</param>\n    /// <exception cref=\"System.ArgumentNullException\">entries</exception>\n    public DiscoveryDocumentResult(Dictionary<string, object> entries, int? maxAge)\n    {\n        Entries = entries ?? throw new ArgumentNullException(nameof(entries));\n        MaxAge = maxAge;\n    }\n\n    /// <summary>\n    /// Executes the result.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public Task ExecuteAsync(HttpContext context)\n    {\n        if (MaxAge.HasValue && MaxAge.Value >= 0)\n        {\n            context.Response.SetCache(MaxAge.Value, \"Origin\");\n        }\n\n        return context.Response.WriteJsonAsync(Entries);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/EndSessionCallbackResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\ninternal class EndSessionCallbackResult : IEndpointResult\n{\n    private readonly EndSessionCallbackValidationResult _result;\n\n    public EndSessionCallbackResult(EndSessionCallbackValidationResult result)\n    {\n        _result = result ?? throw new ArgumentNullException(nameof(result));\n    }\n\n    internal EndSessionCallbackResult(\n        EndSessionCallbackValidationResult result,\n        IdentityServerOptions options)\n        : this(result)\n    {\n        _options = options;\n    }\n\n    private IdentityServerOptions _options;\n\n    private void Init(HttpContext context)\n    {\n        _options = _options ?? context.RequestServices.GetRequiredService<IdentityServerOptions>();\n    }\n\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        Init(context);\n\n        if (_result.IsError)\n        {\n            context.Response.StatusCode = (int)HttpStatusCode.BadRequest;\n        }\n        else\n        {\n            context.Response.SetNoCache();\n            AddCspHeaders(context);\n\n            var html = GetHtml();\n            await context.Response.WriteHtmlAsync(html);\n        }\n    }\n\n    private void AddCspHeaders(HttpContext context)\n    {\n        if (_options.Authentication.RequireCspFrameSrcForSignout)\n        {\n            string frameSources = null;\n            var origins = _result.FrontChannelLogoutUrls?.Select(x => x.GetOrigin());\n            if (origins != null && origins.Any())\n            {\n                frameSources = origins.Distinct().Aggregate((x, y) => $\"{x} {y}\");\n            }\n\n            // the hash matches the embedded style element being used below\n            context.Response.AddStyleCspHeaders(_options.Csp, \"sha256-u+OupXgfekP+x/f6rMdoEAspPCYUtca912isERnoEjY=\", frameSources);\n        }\n    }\n\n    private string GetHtml()\n    {\n        string framesHtml = null;\n\n        if (_result.FrontChannelLogoutUrls != null && _result.FrontChannelLogoutUrls.Any())\n        {\n            var frameUrls = _result.FrontChannelLogoutUrls.Select(url => $\"<iframe src='{HtmlEncoder.Default.Encode(url)}'></iframe>\");\n            framesHtml = frameUrls.Aggregate((x, y) => x + y);\n        }\n\n        return $\"<!DOCTYPE html><html><style>iframe{{display:none;width:0;height:0;}}</style><body>{framesHtml}</body></html>\";\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/EndSessionResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\n/// <summary>\n/// Result for endsession\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointResult\" />\npublic class EndSessionResult : IEndpointResult\n{\n    private readonly EndSessionValidationResult _result;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"EndSessionResult\"/> class.\n    /// </summary>\n    /// <param name=\"result\">The result.</param>\n    /// <exception cref=\"System.ArgumentNullException\">result</exception>\n    public EndSessionResult(EndSessionValidationResult result)\n    {\n        _result = result ?? throw new ArgumentNullException(nameof(result));\n    }\n\n    internal EndSessionResult(\n        EndSessionValidationResult result,\n        IdentityServerOptions options,\n        ISystemClock clock,\n        IMessageStore<LogoutMessage> logoutMessageStore)\n        : this(result)\n    {\n        _options = options;\n        _clock = clock;\n        _logoutMessageStore = logoutMessageStore;\n    }\n\n    private IdentityServerOptions _options;\n    private ISystemClock _clock;\n    private IMessageStore<LogoutMessage> _logoutMessageStore;\n\n    private void Init(HttpContext context)\n    {\n        _options = _options ?? context.RequestServices.GetRequiredService<IdentityServerOptions>();\n        _clock = _clock ?? context.RequestServices.GetRequiredService<ISystemClock>();\n        _logoutMessageStore = _logoutMessageStore ?? context.RequestServices.GetRequiredService<IMessageStore<LogoutMessage>>();\n    }\n\n    /// <summary>\n    /// Executes the result.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        Init(context);\n\n        var validatedRequest = _result.IsError ? null : _result.ValidatedRequest;\n\n        string id = null;\n\n        if (validatedRequest != null)\n        {\n            var logoutMessage = new LogoutMessage(validatedRequest);\n            if (logoutMessage.ContainsPayload)\n            {\n                var msg = new Message<LogoutMessage>(logoutMessage, _clock.UtcNow.UtcDateTime);\n                id = await _logoutMessageStore.WriteAsync(msg);\n            }\n        }\n\n        var redirect = _options.UserInteraction.LogoutUrl;\n\n        if (redirect.IsLocalUrl())\n        {\n            redirect = context.GetIdentityServerRelativeUrl(redirect);\n        }\n\n        if (id != null)\n        {\n            redirect = redirect.AddQueryString(_options.UserInteraction.LogoutIdParameter, id);\n        }\n\n        context.Response.RedirectIfAllowed(redirect);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/IntrospectionResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\n/// <summary>\n/// Result for introspection\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointResult\" />\npublic class IntrospectionResult : IEndpointResult\n{\n    /// <summary>\n    /// Gets the result.\n    /// </summary>\n    /// <value>\n    /// The result.\n    /// </value>\n    public Dictionary<string, object> Entries { get; }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IntrospectionResult\"/> class.\n    /// </summary>\n    /// <param name=\"entries\">The result.</param>\n    /// <exception cref=\"System.ArgumentNullException\">result</exception>\n    public IntrospectionResult(Dictionary<string, object> entries)\n    {\n        Entries = entries ?? throw new ArgumentNullException(nameof(entries));\n    }\n\n    /// <summary>\n    /// Executes the result.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public Task ExecuteAsync(HttpContext context)\n    {\n        context.Response.SetNoCache();\n        \n        return context.Response.WriteJsonAsync(Entries);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/JsonWebKeysResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\n/// <summary>\n/// Result for the jwks document\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointResult\" />\npublic class JsonWebKeysResult : IEndpointResult\n{\n    /// <summary>\n    /// Gets the web keys.\n    /// </summary>\n    /// <value>\n    /// The web keys.\n    /// </value>\n    public IEnumerable<JsonWebKey> WebKeys { get; }\n\n    /// <summary>\n    /// Gets the maximum age.\n    /// </summary>\n    /// <value>\n    /// The maximum age.\n    /// </value>\n    public int? MaxAge { get; }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"JsonWebKeysResult\" /> class.\n    /// </summary>\n    /// <param name=\"webKeys\">The web keys.</param>\n    /// <param name=\"maxAge\">The maximum age.</param>\n    public JsonWebKeysResult(IEnumerable<JsonWebKey> webKeys, int? maxAge)\n    {\n        WebKeys = webKeys ?? throw new ArgumentNullException(nameof(webKeys));\n        MaxAge = maxAge;\n    }\n\n    /// <summary>\n    /// Executes the result.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public Task ExecuteAsync(HttpContext context)\n    {\n        if (MaxAge.HasValue && MaxAge.Value >= 0)\n        {\n            context.Response.SetCache(MaxAge.Value, \"Origin\");\n        }\n\n        return context.Response.WriteJsonAsync(new { keys = WebKeys }, \"application/json; charset=UTF-8\");\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/LoginPageResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\n/// <summary>\n/// Result for login page\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointResult\" />\npublic class LoginPageResult : IEndpointResult\n{\n    private readonly ValidatedAuthorizeRequest _request;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"LoginPageResult\"/> class.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <exception cref=\"System.ArgumentNullException\">request</exception>\n    public LoginPageResult(ValidatedAuthorizeRequest request)\n    {\n        _request = request ?? throw new ArgumentNullException(nameof(request));\n    }\n\n    internal LoginPageResult(\n        ValidatedAuthorizeRequest request,\n        IdentityServerOptions options,\n        IAuthorizationParametersMessageStore authorizationParametersMessageStore = null) \n        : this(request)\n    {\n        _options = options;\n        _authorizationParametersMessageStore = authorizationParametersMessageStore;\n    }\n\n    private IdentityServerOptions _options;\n    private IAuthorizationParametersMessageStore _authorizationParametersMessageStore;\n\n    private void Init(HttpContext context)\n    {\n        _options = _options ?? context.RequestServices.GetRequiredService<IdentityServerOptions>();\n        _authorizationParametersMessageStore = _authorizationParametersMessageStore ?? context.RequestServices.GetService<IAuthorizationParametersMessageStore>();\n    }\n\n    /// <summary>\n    /// Executes the result.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        Init(context);\n\n        var returnUrl = context.GetIdentityServerBasePath().EnsureTrailingSlash() + Constants.ProtocolRoutePaths.AuthorizeCallback;\n        if (_authorizationParametersMessageStore != null)\n        {\n            var msg = new Message<IDictionary<string, string[]>>(_request.Raw.ToFullDictionary());\n            var id = await _authorizationParametersMessageStore.WriteAsync(msg);\n            returnUrl = returnUrl.AddQueryString(Constants.AuthorizationParamsStore.MessageStoreIdParameterName, id);\n        }\n        else\n        {\n            returnUrl = returnUrl.AddQueryString(_request.Raw.ToQueryString());\n        }\n\n        var loginUrl = _options.UserInteraction.LoginUrl;\n        if (!loginUrl.IsLocalUrl())\n        {\n            // this converts the relative redirect path to an absolute one if we're \n            // redirecting to a different server\n            returnUrl = context.GetIdentityServerHost().EnsureTrailingSlash() + returnUrl.RemoveLeadingSlash();\n        }\n\n        var url = loginUrl.AddQueryString(_options.UserInteraction.LoginReturnUrlParameter, returnUrl);\n        context.Response.RedirectToAbsoluteUrl(url);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/ProtectedResourceErrorResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.Net.Http.Headers;\n\nnamespace IdentityServer8.Endpoints.Results;\n\ninternal class ProtectedResourceErrorResult : IEndpointResult\n{\n    public string Error;\n    public string ErrorDescription;\n\n    public ProtectedResourceErrorResult(string error, string errorDescription = null)\n    {\n        Error = error;\n        ErrorDescription = errorDescription;\n    }\n\n    public Task ExecuteAsync(HttpContext context)\n    {\n        context.Response.StatusCode = 401;\n        context.Response.SetNoCache();\n\n        if (Constants.ProtectedResourceErrorStatusCodes.ContainsKey(Error))\n        {\n            context.Response.StatusCode = Constants.ProtectedResourceErrorStatusCodes[Error];\n        }\n\n        if (Error == OidcConstants.ProtectedResourceErrors.ExpiredToken)\n        {\n            Error = OidcConstants.ProtectedResourceErrors.InvalidToken;\n            ErrorDescription = \"The access token expired\";\n        }\n\n        var errorString = string.Format($\"error=\\\"{Error}\\\"\");\n        if (ErrorDescription.IsMissing())\n        {\n            context.Response.Headers.Append(HeaderNames.WWWAuthenticate, new StringValues(new[] { \"Bearer realm=\\\"IdentityServer\\\"\", errorString }).ToString());\n        }\n        else\n        {\n            var errorDescriptionString = string.Format($\"error_description=\\\"{ErrorDescription}\\\"\");\n            context.Response.Headers.Append(HeaderNames.WWWAuthenticate, new StringValues(new[] { \"Bearer realm=\\\"IdentityServer\\\"\", errorString, errorDescriptionString }).ToString());\n        }\n\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/StatusCodeResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\n/// <summary>\n/// Result for a raw HTTP status code\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointResult\" />\npublic class StatusCodeResult : IEndpointResult\n{\n    /// <summary>\n    /// Gets the status code.\n    /// </summary>\n    /// <value>\n    /// The status code.\n    /// </value>\n    public int StatusCode { get; }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"StatusCodeResult\"/> class.\n    /// </summary>\n    /// <param name=\"statusCode\">The status code.</param>\n    public StatusCodeResult(HttpStatusCode statusCode)\n    {\n        StatusCode = (int)statusCode;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"StatusCodeResult\"/> class.\n    /// </summary>\n    /// <param name=\"statusCode\">The status code.</param>\n    public StatusCodeResult(int statusCode)\n    {\n        StatusCode = statusCode;\n    }\n\n    /// <summary>\n    /// Executes the result.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public Task ExecuteAsync(HttpContext context)\n    {\n        context.Response.StatusCode = StatusCode;\n\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/TokenErrorResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing JsonExtensionDataAttribute = System.Text.Json.Serialization.JsonExtensionDataAttribute;\n\n\nnamespace IdentityServer8.Endpoints.Results;\n\ninternal class TokenErrorResult : IEndpointResult\n{\n    public TokenErrorResponse Response { get; }\n\n    public TokenErrorResult(TokenErrorResponse error)\n    {\n        if (error.Error.IsMissing()) throw new ArgumentNullException(nameof(error.Error), \"Error must be set\");\n\n        Response = error;\n    }\n\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        context.Response.StatusCode = 400;\n        context.Response.SetNoCache();\n\n        var dto = new ResultDto\n        {\n            error = Response.Error,\n            error_description = Response.ErrorDescription,\n            \n            custom = Response.Custom\n        };\n\n        await context.Response.WriteJsonAsync(dto);\n    }\n\n    internal class ResultDto\n    {\n        public string error { get; set; }\n        public string error_description { get; set; }\n\n        [JsonExtensionData]\n        public Dictionary<string, object> custom { get; set; }\n    }    \n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/TokenResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing JsonExtensionDataAttribute = System.Text.Json.Serialization.JsonExtensionDataAttribute;\nusing JsonSerializer = System.Text.Json.JsonSerializer;\n\nnamespace IdentityServer8.Endpoints.Results;\n\ninternal class TokenResult : IEndpointResult\n{\n    public TokenResponse Response { get; set; }\n\n    public TokenResult(TokenResponse response)\n    {\n        Response = response ?? throw new ArgumentNullException(nameof(response));\n    }\n\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        context.Response.SetNoCache();\n\n        var dto = new ResultDto\n        {\n            id_token = Response.IdentityToken,\n            access_token = Response.AccessToken,\n            refresh_token = Response.RefreshToken,\n            expires_in = Response.AccessTokenLifetime,\n            token_type = OidcConstants.TokenResponse.BearerTokenType,\n            scope = Response.Scope,\n\n            Custom = Response.Custom\n        };\n\n        await context.Response.WriteJsonAsync(dto);\n    }\n\n    internal class ResultDto\n    {\n        public string id_token { get; set; }\n        public string access_token { get; set; }\n        public int expires_in { get; set; }\n        public string token_type { get; set; }\n        public string refresh_token { get; set; }\n        public string scope { get; set; }\n\n        [JsonExtensionData]\n        public Dictionary<string, object>? Custom { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/TokenRevocationErrorResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\n/// <summary>\n/// Result for revocation error\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointResult\" />\npublic class TokenRevocationErrorResult : IEndpointResult\n{\n    /// <summary>\n    /// Gets or sets the error.\n    /// </summary>\n    /// <value>\n    /// The error.\n    /// </value>\n    public string Error { get; set; }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenRevocationErrorResult\"/> class.\n    /// </summary>\n    /// <param name=\"error\">The error.</param>\n    public TokenRevocationErrorResult(string error)\n    {\n        Error = error;\n    }\n\n    /// <summary>\n    /// Executes the result.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public Task ExecuteAsync(HttpContext context)\n    {\n        context.Response.StatusCode = (int)HttpStatusCode.BadRequest;\n        return context.Response.WriteJsonAsync(new { error = Error });\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/Results/UserInfoResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints.Results;\n\ninternal class UserInfoResult : IEndpointResult\n{\n    public Dictionary<string, object> Claims;\n\n    public UserInfoResult(Dictionary<string, object> claims)\n    {\n        Claims = claims;\n    }\n\n    public async Task ExecuteAsync(HttpContext context)\n    {\n        context.Response.SetNoCache();\n        await context.Response.WriteJsonAsync(Claims);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/TokenEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\n/// <summary>\n/// The token endpoint\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointHandler\" />\ninternal class TokenEndpoint : IEndpointHandler\n{\n    private readonly IClientSecretValidator _clientValidator;\n    private readonly ITokenRequestValidator _requestValidator;\n    private readonly ITokenResponseGenerator _responseGenerator;\n    private readonly IEventService _events;\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenEndpoint\" /> class.\n    /// </summary>\n    /// <param name=\"clientValidator\">The client validator.</param>\n    /// <param name=\"requestValidator\">The request validator.</param>\n    /// <param name=\"responseGenerator\">The response generator.</param>\n    /// <param name=\"events\">The events.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public TokenEndpoint(\n        IClientSecretValidator clientValidator, \n        ITokenRequestValidator requestValidator, \n        ITokenResponseGenerator responseGenerator, \n        IEventService events, \n        ILogger<TokenEndpoint> logger)\n    {\n        _clientValidator = clientValidator;\n        _requestValidator = requestValidator;\n        _responseGenerator = responseGenerator;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Processes the request.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        _logger.LogTrace(\"Processing token request.\");\n\n        // validate HTTP\n        if (!HttpMethods.IsPost(context.Request.Method) || !context.Request.HasApplicationFormContentType())\n        {\n            _logger.LogWarning(\"Invalid HTTP request for token endpoint\");\n            return Error(OidcConstants.TokenErrors.InvalidRequest);\n        }\n\n        return await ProcessTokenRequestAsync(context);\n    }\n\n    private async Task<IEndpointResult> ProcessTokenRequestAsync(HttpContext context)\n    {\n        _logger.LogDebug(\"Start token request.\");\n\n        // validate client\n        var clientResult = await _clientValidator.ValidateAsync(context);\n\n        if (clientResult.Client == null)\n        {\n            return Error(OidcConstants.TokenErrors.InvalidClient);\n        }\n\n        // validate request\n        var form = (await context.Request.ReadFormAsync()).AsNameValueCollection();\n        _logger.LogTrace(\"Calling into token request validator: {type}\", _requestValidator.GetType().FullName);\n        var requestResult = await _requestValidator.ValidateRequestAsync(form, clientResult);\n\n        if (requestResult.IsError)\n        {\n            await _events.RaiseAsync(new TokenIssuedFailureEvent(requestResult));\n            return Error(requestResult.Error, requestResult.ErrorDescription, requestResult.CustomResponse);\n        }\n\n        // create response\n        _logger.LogTrace(\"Calling into token request response generator: {type}\", _responseGenerator.GetType().FullName);\n        var response = await _responseGenerator.ProcessAsync(requestResult);\n\n        await _events.RaiseAsync(new TokenIssuedSuccessEvent(response, requestResult));\n        LogTokens(response, requestResult);\n\n        // return result\n        _logger.LogDebug(\"Token request success.\");\n        return new TokenResult(response);\n    }\n\n    private TokenErrorResult Error(string error, string errorDescription = null, Dictionary<string, object> custom = null)\n    {\n        var response = new TokenErrorResponse\n        {\n            Error = error,\n            ErrorDescription = errorDescription,\n            Custom = custom\n        };\n\n        return new TokenErrorResult(response);\n    }\n\n    private void LogTokens(TokenResponse response, TokenRequestValidationResult requestResult)\n    {\n        var clientId = $\"{requestResult.ValidatedRequest.Client.ClientId} ({requestResult.ValidatedRequest.Client?.ClientName ?? \"no name set\"})\";\n        var subjectId = requestResult.ValidatedRequest.Subject?.GetSubjectId() ?? \"no subject\";\n\n        if (response.IdentityToken != null)\n        {\n            _logger.LogTrace(\"Identity token issued for {clientId} / {subjectId}: {token}\", clientId, subjectId, response.IdentityToken);\n        }\n        if (response.RefreshToken != null)\n        {\n            _logger.LogTrace(\"Refresh token issued for {clientId} / {subjectId}: {token}\", clientId, subjectId, response.RefreshToken);\n        }\n        if (response.AccessToken != null)\n        {\n            _logger.LogTrace(\"Access token issued for {clientId} / {subjectId}: {token}\", clientId, subjectId, response.AccessToken);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/TokenRevocationEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\n/// <summary>\n/// The revocation endpoint\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointHandler\" />\ninternal class TokenRevocationEndpoint : IEndpointHandler\n{\n    private readonly ILogger _logger;\n    private readonly IClientSecretValidator _clientValidator;\n    private readonly ITokenRevocationRequestValidator _requestValidator;\n    private readonly ITokenRevocationResponseGenerator _responseGenerator;\n    private readonly IEventService _events;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenRevocationEndpoint\" /> class.\n    /// </summary>\n    /// <param name=\"logger\">The logger.</param>\n    /// <param name=\"clientValidator\">The client validator.</param>\n    /// <param name=\"requestValidator\">The request validator.</param>\n    /// <param name=\"responseGenerator\">The response generator.</param>\n    /// <param name=\"events\">The events.</param>\n    public TokenRevocationEndpoint(ILogger<TokenRevocationEndpoint> logger,\n        IClientSecretValidator clientValidator,\n        ITokenRevocationRequestValidator requestValidator,\n        ITokenRevocationResponseGenerator responseGenerator,\n        IEventService events)\n    {\n        _logger = logger;\n        _clientValidator = clientValidator;\n        _requestValidator = requestValidator;\n        _responseGenerator = responseGenerator;\n\n        _events = events;\n    }\n\n    /// <summary>\n    /// Processes the request.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        _logger.LogTrace(\"Processing revocation request.\");\n\n        if (!HttpMethods.IsPost(context.Request.Method))\n        {\n            _logger.LogWarning(\"Invalid HTTP method\");\n            return new StatusCodeResult(HttpStatusCode.MethodNotAllowed);\n        }\n\n        if (!context.Request.HasApplicationFormContentType())\n        {\n            _logger.LogWarning(\"Invalid media type\");\n            return new StatusCodeResult(HttpStatusCode.UnsupportedMediaType);\n        }\n\n        var response = await ProcessRevocationRequestAsync(context);\n\n        return response;\n    }\n\n    private async Task<IEndpointResult> ProcessRevocationRequestAsync(HttpContext context)\n    {\n        _logger.LogDebug(\"Start revocation request.\");\n\n        // validate client\n        var clientValidationResult = await _clientValidator.ValidateAsync(context);\n\n        if (clientValidationResult.IsError)\n        {\n            return new TokenRevocationErrorResult(OidcConstants.TokenErrors.InvalidClient);\n        }\n\n        _logger.LogTrace(\"Client validation successful\");\n\n        // validate the token request\n        var form = (await context.Request.ReadFormAsync()).AsNameValueCollection();\n\n        _logger.LogTrace(\"Calling into token revocation request validator: {type}\", _requestValidator.GetType().FullName);\n        var requestValidationResult = await _requestValidator.ValidateRequestAsync(form, clientValidationResult.Client);\n\n        if (requestValidationResult.IsError)\n        {\n            return new TokenRevocationErrorResult(requestValidationResult.Error);\n        }\n\n        _logger.LogTrace(\"Calling into token revocation response generator: {type}\", _responseGenerator.GetType().FullName);\n        var response = await _responseGenerator.ProcessAsync(requestValidationResult);\n\n        if (response.Success)\n        {\n            _logger.LogInformation(\"Token revocation complete\");\n            await _events.RaiseAsync(new TokenRevokedSuccessEvent(requestValidationResult, requestValidationResult.Client));\n        }\n        else\n        {\n            _logger.LogInformation(\"No matching token found\");\n        }\n\n        if (response.Error.IsPresent()) return new TokenRevocationErrorResult(response.Error);\n\n        return new StatusCodeResult(HttpStatusCode.OK);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Endpoints/UserInfoEndpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Endpoints;\n\n/// <summary>\n/// The userinfo endpoint\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Hosting.IEndpointHandler\" />\ninternal class UserInfoEndpoint : IEndpointHandler\n{\n    private readonly BearerTokenUsageValidator _tokenUsageValidator;\n    private readonly IUserInfoRequestValidator _requestValidator;\n    private readonly IUserInfoResponseGenerator _responseGenerator;\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"UserInfoEndpoint\" /> class.\n    /// </summary>\n    /// <param name=\"tokenUsageValidator\">The token usage validator.</param>\n    /// <param name=\"requestValidator\">The request validator.</param>\n    /// <param name=\"responseGenerator\">The response generator.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public UserInfoEndpoint(\n        BearerTokenUsageValidator tokenUsageValidator, \n        IUserInfoRequestValidator requestValidator, \n        IUserInfoResponseGenerator responseGenerator, \n        ILogger<UserInfoEndpoint> logger)\n    {\n        _tokenUsageValidator = tokenUsageValidator;\n        _requestValidator = requestValidator;\n        _responseGenerator = responseGenerator;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Processes the request.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public async Task<IEndpointResult> ProcessAsync(HttpContext context)\n    {\n        if (!HttpMethods.IsGet(context.Request.Method) && !HttpMethods.IsPost(context.Request.Method))\n        {\n            _logger.LogWarning(\"Invalid HTTP method for userinfo endpoint.\");\n            return new StatusCodeResult(HttpStatusCode.MethodNotAllowed);\n        }\n\n        return await ProcessUserInfoRequestAsync(context);\n    }\n\n    private async Task<IEndpointResult> ProcessUserInfoRequestAsync(HttpContext context)\n    {\n        _logger.LogDebug(\"Start userinfo request\");\n\n        // userinfo requires an access token on the request\n        var tokenUsageResult = await _tokenUsageValidator.ValidateAsync(context);\n        if (tokenUsageResult.TokenFound == false)\n        {\n            var error = \"No access token found.\";\n\n            _logger.LogError(error);\n            return Error(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        // validate the request\n        _logger.LogTrace(\"Calling into userinfo request validator: {type}\", _requestValidator.GetType().FullName);\n        var validationResult = await _requestValidator.ValidateRequestAsync(tokenUsageResult.Token);\n\n        if (validationResult.IsError)\n        {\n            //_logger.LogError(\"Error validating  validationResult.Error);\n            return Error(validationResult.Error);\n        }\n\n        // generate response\n        _logger.LogTrace(\"Calling into userinfo response generator: {type}\", _responseGenerator.GetType().FullName);\n        var response = await _responseGenerator.ProcessAsync(validationResult);\n\n        _logger.LogDebug(\"End userinfo request\");\n        return new UserInfoResult(response);\n    }\n\n    private IEndpointResult Error(string error, string description = null)\n    {\n        return new ProtectedResourceErrorResult(error, description);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/ApiAuthenticationFailureEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for failed API authentication\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class ApiAuthenticationFailureEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiAuthenticationFailureEvent\"/> class.\n    /// </summary>\n    /// <param name=\"apiName\">Name of the API.</param>\n    /// <param name=\"message\">The message.</param>\n    public ApiAuthenticationFailureEvent(string apiName, string message)\n        : base(EventCategories.Authentication, \n              \"API Authentication Failure\",\n              EventTypes.Failure, \n              EventIds.ApiAuthenticationFailure, \n              message)\n    {\n        ApiName = apiName;\n    }\n\n    /// <summary>\n    /// Gets or sets the name of the API.\n    /// </summary>\n    /// <value>\n    /// The name of the API.\n    /// </value>\n    public string ApiName { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/ApiAuthenticationSuccessEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for successful API authentication\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class ApiAuthenticationSuccessEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiAuthenticationSuccessEvent\"/> class.\n    /// </summary>\n    /// <param name=\"apiName\">Name of the API.</param>\n    /// <param name=\"authenticationMethod\">The authentication method.</param>\n    public ApiAuthenticationSuccessEvent(string apiName, string authenticationMethod)\n        : base(EventCategories.Authentication, \n              \"API Authentication Success\",\n              EventTypes.Success, \n              EventIds.ApiAuthenticationSuccess)\n    {\n        ApiName = apiName;\n        AuthenticationMethod = authenticationMethod;\n    }\n\n    /// <summary>\n    /// Gets or sets the name of the API.\n    /// </summary>\n    /// <value>\n    /// The name of the API.\n    /// </value>\n    public string ApiName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the authentication method.\n    /// </summary>\n    /// <value>\n    /// The authentication method.\n    /// </value>\n    public string AuthenticationMethod { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/ClientAuthenticationFailureEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for failed client authentication\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class ClientAuthenticationFailureEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ClientAuthenticationFailureEvent\"/> class.\n    /// </summary>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <param name=\"message\">The message.</param>\n    public ClientAuthenticationFailureEvent(string clientId, string message)\n        : base(EventCategories.Authentication, \n              \"Client Authentication Failure\",\n              EventTypes.Failure, \n              EventIds.ClientAuthenticationFailure, \n              message)\n    {\n        ClientId = clientId;\n    }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/ClientAuthenticationSuccessEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for successful client authentication\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class ClientAuthenticationSuccessEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ClientAuthenticationSuccessEvent\"/> class.\n    /// </summary>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <param name=\"authenticationMethod\">The authentication method.</param>\n    public ClientAuthenticationSuccessEvent(string clientId, string authenticationMethod)\n        : base(EventCategories.Authentication, \n              \"Client Authentication Success\",\n              EventTypes.Success, \n              EventIds.ClientAuthenticationSuccess)\n    {\n        ClientId = clientId;\n        AuthenticationMethod = authenticationMethod;\n    }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the authentication method.\n    /// </summary>\n    /// <value>\n    /// The authentication method.\n    /// </value>\n    public string AuthenticationMethod { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/ConsentDeniedEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for denied consent.\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class ConsentDeniedEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ConsentDeniedEvent\" /> class.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <param name=\"requestedScopes\">The requested scopes.</param>\n    public ConsentDeniedEvent(string subjectId, string clientId, IEnumerable<string> requestedScopes)\n        : base(EventCategories.Grants,\n              \"Consent denied\",\n              EventTypes.Information,\n              EventIds.ConsentDenied)\n    {\n        SubjectId = subjectId;\n        ClientId = clientId;\n        RequestedScopes = requestedScopes;\n    }\n\n    /// <summary>\n    /// Gets or sets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client ID.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the requested scopes.\n    /// </summary>\n    /// <value>\n    /// The requested scopes.\n    /// </value>\n    public IEnumerable<string> RequestedScopes { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/ConsentGrantedEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for granted consent.\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class ConsentGrantedEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ConsentGrantedEvent\" /> class.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <param name=\"requestedScopes\">The requested scopes.</param>\n    /// <param name=\"grantedScopes\">The granted scopes.</param>\n    /// <param name=\"consentRemembered\">if set to <c>true</c> consent was remembered.</param>\n    public ConsentGrantedEvent(string subjectId, string clientId, IEnumerable<string> requestedScopes, IEnumerable<string> grantedScopes, bool consentRemembered)\n        : base(EventCategories.Grants,\n              \"Consent granted\",\n              EventTypes.Information,\n              EventIds.ConsentGranted)\n    {\n        SubjectId = subjectId;\n        ClientId = clientId;\n        RequestedScopes = requestedScopes;\n        GrantedScopes = grantedScopes;\n        ConsentRemembered = consentRemembered;\n    }\n\n    /// <summary>\n    /// Gets or sets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client ID.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the requested scopes.\n    /// </summary>\n    /// <value>\n    /// The requested scopes.\n    /// </value>\n    public IEnumerable<string> RequestedScopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the granted scopes.\n    /// </summary>\n    /// <value>\n    /// The granted scopes.\n    /// </value>\n    public IEnumerable<string> GrantedScopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether consent was remembered.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if consent was remembered; otherwise, <c>false</c>.\n    /// </value>\n    public bool ConsentRemembered { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/DeviceAuthorizationFailureEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for device authorization failure\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class DeviceAuthorizationFailureEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DeviceAuthorizationFailureEvent\"/> class.\n    /// </summary>\n    /// <param name=\"result\">The result.</param>\n    public DeviceAuthorizationFailureEvent(DeviceAuthorizationRequestValidationResult result)\n        : this()\n    {\n        if (result.ValidatedRequest != null)\n        {\n            ClientId = result.ValidatedRequest.Client?.ClientId;\n            ClientName = result.ValidatedRequest.Client?.ClientName;\n            Scopes = result.ValidatedRequest.RequestedScopes?.ToSpaceSeparatedString();\n            \n        }\n\n        Endpoint = Constants.EndpointNames.DeviceAuthorization;\n        Error = result.Error;\n        ErrorDescription = result.ErrorDescription;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DeviceAuthorizationFailureEvent\"/> class.\n    /// </summary>\n    public DeviceAuthorizationFailureEvent()\n        : base(EventCategories.DeviceFlow,\n            \"Device Authorization Failure\",\n            EventTypes.Failure,\n            EventIds.DeviceAuthorizationFailure)\n    {\n    }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the name of the client.\n    /// </summary>\n    /// <value>\n    /// The name of the client.\n    /// </value>\n    public string ClientName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the endpoint.\n    /// </summary>\n    /// <value>\n    /// The endpoint.\n    /// </value>\n    public string Endpoint { get; set; }\n\n    /// <summary>\n    /// Gets or sets the scopes.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public string Scopes { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the error.\n    /// </summary>\n    /// <value>\n    /// The error.\n    /// </value>\n    public string Error { get; set; }\n\n    /// <summary>\n    /// Gets or sets the error description.\n    /// </summary>\n    /// <value>\n    /// The error description.\n    /// </value>\n    public string ErrorDescription { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/DeviceAuthorizationSuccessEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for device authorization failure\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class DeviceAuthorizationSuccessEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DeviceAuthorizationSuccessEvent\"/> class.\n    /// </summary>\n    /// <param name=\"response\">The response.</param>\n    /// <param name=\"request\">The request.</param>\n    public DeviceAuthorizationSuccessEvent(DeviceAuthorizationResponse response, DeviceAuthorizationRequestValidationResult request)\n        : this()\n    {\n        ClientId = request.ValidatedRequest.Client?.ClientId;\n        ClientName = request.ValidatedRequest.Client?.ClientName;\n        Endpoint = Constants.EndpointNames.DeviceAuthorization;\n        Scopes = request.ValidatedRequest.ValidatedResources?.RawScopeValues.ToSpaceSeparatedString();\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DeviceAuthorizationSuccessEvent\"/> class.\n    /// </summary>\n    protected DeviceAuthorizationSuccessEvent()\n        : base(EventCategories.DeviceFlow,\n            \"Device Authorization Success\",\n            EventTypes.Success,\n            EventIds.DeviceAuthorizationSuccess)\n    {\n    }\n\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the name of the client.\n    /// </summary>\n    /// <value>\n    /// The name of the client.\n    /// </value>\n    public string ClientName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the endpoint.\n    /// </summary>\n    /// <value>\n    /// The endpoint.\n    /// </value>\n    public string Endpoint { get; set; }\n\n    /// <summary>\n    /// Gets or sets the scopes.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public string Scopes { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/GrantsRevokedEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for revoked grants.\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class GrantsRevokedEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"GrantsRevokedEvent\" /> class.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    public GrantsRevokedEvent(string subjectId, string clientId)\n        : base(EventCategories.Grants,\n              \"Grants revoked\",\n              EventTypes.Information,\n              EventIds.GrantsRevoked)\n    {\n        SubjectId = subjectId;\n        ClientId = clientId;\n    }\n\n    /// <summary>\n    /// Gets or sets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client ID.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/Infrastructure/Event.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Models base class for events raised from IdentityServer.\n/// </summary>\npublic abstract class Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"Event\" /> class.\n    /// </summary>\n    /// <param name=\"category\">The category.</param>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"type\">The type.</param>\n    /// <param name=\"id\">The identifier.</param>\n    /// <param name=\"message\">The message.</param>\n    /// <exception cref=\"System.ArgumentNullException\">category</exception>\n    protected Event(string category, string name, EventTypes type, int id, string message = null)\n    {\n        Category = category ?? throw new ArgumentNullException(nameof(category));\n        Name = name ?? throw new ArgumentNullException(nameof(name));\n\n        EventType = type;\n        Id = id;\n        Message = message;\n    }\n\n    /// <summary>\n    /// Allows implementing custom initialization logic.\n    /// </summary>\n    /// <returns></returns>\n    protected internal virtual Task PrepareAsync()\n    {\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Gets or sets the category.\n    /// </summary>\n    /// <value>\n    /// The category.\n    /// </value>\n    public string Category { get; set; }\n\n    /// <summary>\n    /// Gets or sets the name.\n    /// </summary>\n    /// <value>\n    /// The name.\n    /// </value>\n    public string Name { get; set; }\n\n    /// <summary>\n    /// Gets or sets the event type.\n    /// </summary>\n    /// <value>\n    /// The type of the event.\n    /// </value>\n    public EventTypes EventType { get; set; }\n\n    /// <summary>\n    /// Gets or sets the identifier.\n    /// </summary>\n    /// <value>\n    /// The identifier.\n    /// </value>\n    public int Id { get; set; }\n\n    /// <summary>\n    /// Gets or sets the event message.\n    /// </summary>\n    /// <value>\n    /// The message.\n    /// </value>\n    public string Message { get; set; }\n\n    /// <summary>\n    /// Gets or sets the per-request activity identifier.\n    /// </summary>\n    /// <value>\n    /// The activity identifier.\n    /// </value>\n    public string ActivityId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the time stamp when the event was raised.\n    /// </summary>\n    /// <value>\n    /// The time stamp.\n    /// </value>\n    public DateTime TimeStamp { get; set; }\n\n    /// <summary>\n    /// Gets or sets the server process identifier.\n    /// </summary>\n    /// <value>\n    /// The process identifier.\n    /// </value>\n    public int ProcessId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the local ip address of the current request.\n    /// </summary>\n    /// <value>\n    /// The local ip address.\n    /// </value>\n    public string LocalIpAddress { get; set; }\n\n    /// <summary>\n    /// Gets or sets the remote ip address of the current request.\n    /// </summary>\n    /// <value>\n    /// The remote ip address.\n    /// </value>\n    public string RemoteIpAddress { get; set; }\n\n    /// <summary>\n    /// Obfuscates a token.\n    /// </summary>\n    /// <param name=\"value\">The token.</param>\n    /// <returns></returns>\n    protected static string Obfuscate(string value)\n    {\n        var last4Chars = \"****\";\n        if (value.IsPresent() && value.Length > 4)\n        {\n            last4Chars = value.Substring(value.Length - 4);\n        }\n\n        return \"****\" + last4Chars;\n    }\n\n    /// <inheritdoc/>\n    public override string ToString()\n    {\n        return LogSerializer.Serialize(this);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/Infrastructure/EventCategories.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Categories for events\n/// </summary>\npublic static class EventCategories\n{\n    /// <summary>\n    /// Authentication related events\n    /// </summary>\n    public const string Authentication = \"Authentication\";\n\n    /// <summary>\n    /// Token related events\n    /// </summary>\n    public const string Token = \"Token\";\n\n    /// <summary>\n    /// Grants related events\n    /// </summary>\n    public const string Grants = \"Grants\";\n\n    /// <summary>\n    /// Error related events\n    /// </summary>\n    public const string Error = \"Error\";\n\n    /// <summary>\n    /// Device flow related events\n    /// </summary>\n    public const string DeviceFlow = \"Device\";\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/Infrastructure/EventIds.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Events;\n\npublic static class EventIds\n{\n    //////////////////////////////////////////////////////\n    /// Authentication related events\n    //////////////////////////////////////////////////////\n    private const int AuthenticationEventsStart = 1000;\n\n    public const int UserLoginSuccess = AuthenticationEventsStart + 0;\n    public const int UserLoginFailure = AuthenticationEventsStart + 1;\n    public const int UserLogoutSuccess = AuthenticationEventsStart + 2;\n\n    public const int ClientAuthenticationSuccess = AuthenticationEventsStart + 10;\n    public const int ClientAuthenticationFailure = AuthenticationEventsStart + 11;\n    \n    public const int ApiAuthenticationSuccess = AuthenticationEventsStart + 20;\n    public const int ApiAuthenticationFailure = AuthenticationEventsStart + 21;\n\n    //////////////////////////////////////////////////////\n    /// Token related events\n    //////////////////////////////////////////////////////\n    private const int TokenEventsStart = 2000;\n\n    public const int TokenIssuedSuccess = TokenEventsStart + 0;\n    public const int TokenIssuedFailure = TokenEventsStart + 1;\n\n    public const int TokenRevokedSuccess = TokenEventsStart + 10;\n\n    public const int TokenIntrospectionSuccess = TokenEventsStart + 20;\n    public const int TokenIntrospectionFailure = TokenEventsStart + 21;\n    \n    //////////////////////////////////////////////////////\n    /// Error related events\n    //////////////////////////////////////////////////////\n    private const int ErrorEventsStart = 3000;\n\n    public const int UnhandledException = ErrorEventsStart + 0;\n    public const int InvalidClientConfiguration = ErrorEventsStart + 1;\n\n    //////////////////////////////////////////////////////\n    /// Grants related events\n    //////////////////////////////////////////////////////\n    private const int GrantsEventsStart = 4000;\n\n    public const int ConsentGranted = GrantsEventsStart + 0;\n    public const int ConsentDenied = GrantsEventsStart + 1;\n    public const int GrantsRevoked = GrantsEventsStart + 2;\n\n    private const int DeviceFlowEventsStart = 5000;\n\n    public const int DeviceAuthorizationSuccess = DeviceFlowEventsStart + 0;\n    public const int DeviceAuthorizationFailure = DeviceFlowEventsStart + 1;\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/Infrastructure/EventType.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Indicates if the event is a success or fail event.\n/// </summary>\npublic enum EventTypes\n{\n    /// <summary>\n    /// Success event\n    /// </summary>\n    Success = 1,\n\n    /// <summary>\n    /// Failure event\n    /// </summary>\n    Failure = 2,\n\n    /// <summary>\n    /// Information event\n    /// </summary>\n    Information = 3,\n    \n    /// <summary>\n    /// Error event\n    /// </summary>\n    Error = 4\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/InvalidClientConfiguration.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for unhandled exceptions\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class InvalidClientConfigurationEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"UnhandledExceptionEvent\" /> class.\n    /// </summary>\n    /// <param name=\"client\">The client.</param>\n    /// <param name=\"errorMessage\">The error message.</param>\n    public InvalidClientConfigurationEvent(Client client, string errorMessage)\n        : base(EventCategories.Error,\n              \"Invalid Client Configuration\",\n              EventTypes.Error, \n              EventIds.InvalidClientConfiguration,\n              errorMessage)\n    {\n        ClientId = client.ClientId;\n        ClientName = client.ClientName ?? \"unknown name\";\n    }\n\n    /// <summary>\n    /// Gets or sets the client ID.\n    /// </summary>\n    /// <value>\n    /// The details.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the name of the client.\n    /// </summary>\n    /// <value>\n    /// The name of the client.\n    /// </value>\n    public string ClientName { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/TokenIntrospectionFailureEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for failed token introspection\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class TokenIntrospectionFailureEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenIntrospectionSuccessEvent\" /> class.\n    /// </summary>\n    /// <param name=\"apiName\">Name of the API.</param>\n    /// <param name=\"errorMessage\">The error message.</param>\n    /// <param name=\"token\">The token.</param>\n    /// <param name=\"apiScopes\">The API scopes.</param>\n    /// <param name=\"tokenScopes\">The token scopes.</param>\n    public TokenIntrospectionFailureEvent(string apiName, string errorMessage, string token = null, IEnumerable<string> apiScopes = null, IEnumerable<string> tokenScopes = null)\n        : base(EventCategories.Token,\n              \"Token Introspection Failure\",\n              EventTypes.Failure,\n              EventIds.TokenIntrospectionFailure,\n              errorMessage)\n    {\n        ApiName = apiName;\n\n        if (token.IsPresent())\n        {\n            Token = Obfuscate(token);\n        }\n\n        if (apiScopes != null)\n        {\n            ApiScopes = apiScopes;\n        }\n\n        if (tokenScopes != null)\n        {\n            TokenScopes = tokenScopes;\n        }\n    }\n\n    /// <summary>\n    /// Gets or sets the name of the API.\n    /// </summary>\n    /// <value>\n    /// The name of the API.\n    /// </value>\n    public string ApiName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the token.\n    /// </summary>\n    /// <value>\n    /// The token.\n    /// </value>\n    public string Token { get; set; }\n\n    /// <summary>\n    /// Gets or sets the API scopes.\n    /// </summary>\n    /// <value>\n    /// The API scopes.\n    /// </value>\n    public IEnumerable<string> ApiScopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the token scopes.\n    /// </summary>\n    /// <value>\n    /// The token scopes.\n    /// </value>\n    public IEnumerable<string> TokenScopes { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/TokenIntrospectionSuccessEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for successful token introspection\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class TokenIntrospectionSuccessEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenIntrospectionSuccessEvent\" /> class.\n    /// </summary>\n    /// <param name=\"result\">The result.</param>\n    public TokenIntrospectionSuccessEvent(IntrospectionRequestValidationResult result)\n        : base(EventCategories.Token,\n              \"Token Introspection Success\",\n              EventTypes.Success,\n              EventIds.TokenIntrospectionSuccess)\n    {\n        ApiName = result.Api.Name;\n        IsActive = result.IsActive;\n\n        if (result.Token.IsPresent())\n        {\n            Token = Obfuscate(result.Token);\n        }\n        \n        if (!result.Claims.EnumerableIsNullOrEmpty())\n        {\n            ClaimTypes = result.Claims.Select(c => c.Type).Distinct();\n            TokenScopes = result.Claims.Where(c => c.Type == \"scope\").Select(c => c.Value);\n        }\n    }\n\n    /// <summary>\n    /// Gets or sets the name of the API.\n    /// </summary>\n    /// <value>\n    /// The name of the API.\n    /// </value>\n    public string ApiName { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether this instance is active.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if this instance is active; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsActive { get; set; }\n\n    /// <summary>\n    /// Gets or sets the token.\n    /// </summary>\n    /// <value>\n    /// The token.\n    /// </value>\n    public string Token { get; set; }\n\n    /// <summary>\n    /// Gets or sets the claim types.\n    /// </summary>\n    /// <value>\n    /// The claim types.\n    /// </value>\n    public IEnumerable<string> ClaimTypes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the token scopes.\n    /// </summary>\n    /// <value>\n    /// The token scopes.\n    /// </value>\n    public IEnumerable<string> TokenScopes { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/TokenIssuedFailureEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for failed token issuance\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class TokenIssuedFailureEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenIssuedFailureEvent\"/> class.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"error\">The error.</param>\n    /// <param name=\"description\">The description.</param>\n    public TokenIssuedFailureEvent(ValidatedAuthorizeRequest request, string error, string description)\n        : this()\n    {\n        if (request != null)\n        {\n            ClientId = request.ClientId;\n            ClientName = request.Client?.ClientName;\n            RedirectUri = request.RedirectUri;\n            Scopes = request.RequestedScopes?.ToSpaceSeparatedString();\n            GrantType = request.GrantType;\n\n            if (request.Subject != null && request.Subject.Identity.IsAuthenticated)\n            {\n                SubjectId = request.Subject?.GetSubjectId();\n            }\n        }\n\n        Endpoint = EndpointNames.Authorize;\n        Error = error;\n        ErrorDescription = description;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenIssuedFailureEvent\"/> class.\n    /// </summary>\n    /// <param name=\"result\">The result.</param>\n    public TokenIssuedFailureEvent(TokenRequestValidationResult result)\n        : this()\n    {\n        if (result.ValidatedRequest != null)\n        {\n            ClientId = result.ValidatedRequest.Client.ClientId;\n            ClientName = result.ValidatedRequest.Client.ClientName;\n            GrantType = result.ValidatedRequest.GrantType;\n            Scopes = result.ValidatedRequest.RequestedScopes?.ToSpaceSeparatedString();\n\n            if (result.ValidatedRequest.Subject != null && result.ValidatedRequest.Subject.Identity.IsAuthenticated)\n            {\n                SubjectId = result.ValidatedRequest.Subject.GetSubjectId();\n            }\n        }\n\n        Endpoint = EndpointNames.Token;\n        Error = result.Error;\n        ErrorDescription = result.ErrorDescription;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenIssuedFailureEvent\"/> class.\n    /// </summary>\n    protected TokenIssuedFailureEvent()\n        : base(EventCategories.Token,\n              \"Token Issued Failure\",\n              EventTypes.Failure,\n              EventIds.TokenIssuedFailure)\n    {\n    }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the name of the client.\n    /// </summary>\n    /// <value>\n    /// The name of the client.\n    /// </value>\n    public string ClientName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the redirect URI.\n    /// </summary>\n    /// <value>\n    /// The redirect URI.\n    /// </value>\n    public string RedirectUri { get; set; }\n\n    /// <summary>\n    /// Gets or sets the endpoint.\n    /// </summary>\n    /// <value>\n    /// The endpoint.\n    /// </value>\n    public string Endpoint { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the scopes.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public string Scopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the grant type.\n    /// </summary>\n    /// <value>\n    /// The grant type.\n    /// </value>\n    public string GrantType { get; set; }\n\n    /// <summary>\n    /// Gets or sets the error.\n    /// </summary>\n    /// <value>\n    /// The error.\n    /// </value>\n    public string Error { get; set; }\n\n    /// <summary>\n    /// Gets or sets the error description.\n    /// </summary>\n    /// <value>\n    /// The error description.\n    /// </value>\n    public string ErrorDescription { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/TokenIssuedSuccessEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for successful token issuance\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class TokenIssuedSuccessEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenIssuedSuccessEvent\"/> class.\n    /// </summary>\n    /// <param name=\"response\">The response.</param>\n    public TokenIssuedSuccessEvent(AuthorizeResponse response)\n        : this()\n    {\n        ClientId = response.Request.ClientId;\n        ClientName = response.Request.Client.ClientName;\n        RedirectUri = response.RedirectUri;\n        Endpoint = EndpointNames.Authorize;\n        SubjectId = response.Request.Subject.GetSubjectId();\n        Scopes = response.Scope;\n        GrantType = response.Request.GrantType;\n\n        var tokens = new List<Token>();\n        if (response.IdentityToken != null)\n        {\n            tokens.Add(new Token(OidcConstants.TokenTypes.IdentityToken, response.IdentityToken));\n        }\n        if (response.Code != null)\n        {\n            tokens.Add(new Token(OidcConstants.ResponseTypes.Code, response.Code));\n        }\n        if (response.AccessToken != null)\n        {\n            tokens.Add(new Token(OidcConstants.TokenTypes.AccessToken, response.AccessToken));\n        }\n        Tokens = tokens;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenIssuedSuccessEvent\"/> class.\n    /// </summary>\n    /// <param name=\"response\">The response.</param>\n    /// <param name=\"request\">The request.</param>\n    public TokenIssuedSuccessEvent(TokenResponse response, TokenRequestValidationResult request)\n        : this()\n    {\n        ClientId = request.ValidatedRequest.Client.ClientId;\n        ClientName = request.ValidatedRequest.Client.ClientName;\n        Endpoint = EndpointNames.Token;\n        SubjectId = request.ValidatedRequest.Subject?.GetSubjectId();\n        GrantType = request.ValidatedRequest.GrantType;\n\n        if (GrantType == OidcConstants.GrantTypes.RefreshToken)\n        {\n            Scopes = request.ValidatedRequest.RefreshToken.AccessToken.Scopes.ToSpaceSeparatedString();\n        }\n        else if (GrantType == OidcConstants.GrantTypes.AuthorizationCode)\n        {\n            Scopes = request.ValidatedRequest.AuthorizationCode.RequestedScopes.ToSpaceSeparatedString();\n        }\n        else\n        {\n            Scopes = request.ValidatedRequest.ValidatedResources?.RawScopeValues.ToSpaceSeparatedString();\n        }\n\n        var tokens = new List<Token>();\n        if (response.IdentityToken != null)\n        {\n            tokens.Add(new Token(OidcConstants.TokenTypes.IdentityToken, response.IdentityToken));\n        }\n        if (response.RefreshToken != null)\n        {\n            tokens.Add(new Token(OidcConstants.TokenTypes.RefreshToken, response.RefreshToken));\n        }\n        if (response.AccessToken != null)\n        {\n            tokens.Add(new Token(OidcConstants.TokenTypes.AccessToken, response.AccessToken));\n        }\n        Tokens = tokens;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenIssuedSuccessEvent\"/> class.\n    /// </summary>\n    protected TokenIssuedSuccessEvent()\n        : base(EventCategories.Token,\n              \"Token Issued Success\",\n              EventTypes.Success,\n              EventIds.TokenIssuedSuccess)\n    {\n    }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the name of the client.\n    /// </summary>\n    /// <value>\n    /// The name of the client.\n    /// </value>\n    public string ClientName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the redirect URI.\n    /// </summary>\n    /// <value>\n    /// The redirect URI.\n    /// </value>\n    public string RedirectUri { get; set; }\n\n    /// <summary>\n    /// Gets or sets the endpoint.\n    /// </summary>\n    /// <value>\n    /// The endpoint.\n    /// </value>\n    public string Endpoint { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the scopes.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public string Scopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the grant type.\n    /// </summary>\n    /// <value>\n    /// The grant type.\n    /// </value>\n    public string GrantType { get; set; }\n\n    /// <summary>\n    /// Gets or sets the tokens.\n    /// </summary>\n    /// <value>\n    /// The tokens.\n    /// </value>\n    public IEnumerable<Token> Tokens { get; set; }\n\n    /// <summary>\n    /// Data structure serializing issued tokens\n    /// </summary>\n    public class Token\n    {\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"Token\"/> class.\n        /// </summary>\n        /// <param name=\"type\">The type.</param>\n        /// <param name=\"value\">The value.</param>\n        public Token(string type, string value)\n        {\n            TokenType = type;\n            TokenValue = Obfuscate(value);\n        }\n\n        /// <summary>\n        /// Gets the type of the token.\n        /// </summary>\n        /// <value>\n        /// The type of the token.\n        /// </value>\n        public string TokenType { get; }\n\n        /// <summary>\n        /// Gets the token value.\n        /// </summary>\n        /// <value>\n        /// The token value.\n        /// </value>\n        public string TokenValue { get; }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/TokenRevokedSuccessEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for successful token revocation\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class TokenRevokedSuccessEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenRevokedSuccessEvent\"/> class.\n    /// </summary>\n    /// <param name=\"requestResult\">The request result.</param>\n    /// <param name=\"client\">The client.</param>\n    public TokenRevokedSuccessEvent(TokenRevocationRequestValidationResult requestResult, Client client)\n        : base(EventCategories.Token,\n              \"Token Revoked Success\",\n              EventTypes.Success,\n              EventIds.TokenRevokedSuccess)\n    {\n        ClientId = client.ClientId;\n        ClientName = client.ClientName;\n        TokenType = requestResult.TokenTypeHint;\n        Token = Obfuscate(requestResult.Token);\n    }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the name of the client.\n    /// </summary>\n    /// <value>\n    /// The name of the client.\n    /// </value>\n    public string ClientName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the type of the token.\n    /// </summary>\n    /// <value>\n    /// The type of the token.\n    /// </value>\n    public string TokenType { get; set; }\n\n    /// <summary>\n    /// Gets or sets the token.\n    /// </summary>\n    /// <value>\n    /// The token.\n    /// </value>\n    public string Token { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/UnhandledExceptionEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for unhandled exceptions\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class UnhandledExceptionEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"UnhandledExceptionEvent\"/> class.\n    /// </summary>\n    /// <param name=\"ex\">The ex.</param>\n    public UnhandledExceptionEvent(Exception ex)\n        : base(EventCategories.Error,\n              \"Unhandled Exception\",\n              EventTypes.Error, \n              EventIds.UnhandledException,\n              ex.Message)\n    {\n        Details = ex.ToString();\n    }\n\n    /// <summary>\n    /// Gets or sets the details.\n    /// </summary>\n    /// <value>\n    /// The details.\n    /// </value>\n    public string Details { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/UserLoginFailureEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for failed user authentication\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class UserLoginFailureEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"T:IdentityServer8.Events.UserLoginFailureEvent\" /> class.\n    /// </summary>\n    /// <param name=\"username\">The username.</param>\n    /// <param name=\"error\">The error.</param>\n    /// <param name=\"interactive\">Specifies if login was interactive</param>\n    /// <param name=\"clientId\">The client id</param>\n    public UserLoginFailureEvent(string username, string error, bool interactive = true, string clientId = null)\n        : base(EventCategories.Authentication,\n              \"User Login Failure\",\n              EventTypes.Failure, \n              EventIds.UserLoginFailure,\n              error)\n    {\n        Username = username;\n        ClientId = clientId;\n\n        if (interactive)\n        {\n            Endpoint = \"UI\";\n        }\n        else\n        {\n            Endpoint = EndpointNames.Token;\n        }\n    }\n\n    /// <summary>\n    /// Gets or sets the username.\n    /// </summary>\n    /// <value>\n    /// The username.\n    /// </value>\n    public string Username { get; set; }\n\n    /// <summary>\n    /// Gets or sets the endpoint.\n    /// </summary>\n    /// <value>\n    /// The endpoint.\n    /// </value>\n    public string Endpoint { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client id.\n    /// </summary>\n    /// <value>\n    /// The client id.\n    /// </value>\n    public string ClientId { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/UserLoginSuccessEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for successful user authentication\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class UserLoginSuccessEvent : Event\n{\n    // todo: consolidate ctors in 3.0\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"UserLoginSuccessEvent\"/> class.\n    /// </summary>\n    /// <param name=\"provider\">The provider.</param>\n    /// <param name=\"providerUserId\">The provider user identifier.</param>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"interactive\">if set to <c>true</c> [interactive].</param>\n    /// <param name=\"clientId\">The client id.</param>\n    public UserLoginSuccessEvent(string provider, string providerUserId, string subjectId, string name, bool interactive = true, string clientId = null)\n        : this()\n    {\n        Provider = provider;\n        ProviderUserId = providerUserId;\n        SubjectId = subjectId;\n        DisplayName = name;\n        if (interactive)\n        {\n            Endpoint = \"UI\";\n        }\n        else\n        {\n            Endpoint = EndpointNames.Token;\n        }\n        ClientId = clientId;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"UserLoginSuccessEvent\"/> class.\n    /// </summary>\n    /// <param name=\"username\">The username.</param>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"interactive\">if set to <c>true</c> [interactive].</param>\n    /// <param name=\"clientId\">The client id.</param>\n    public UserLoginSuccessEvent(string username, string subjectId, string name, bool interactive = true, string clientId = null)\n        : this()\n    {\n        Username = username;\n        SubjectId = subjectId;\n        DisplayName = name;\n        ClientId = clientId;\n\n        if (interactive)\n        {\n            Endpoint = \"UI\";\n        }\n        else\n        {\n            Endpoint = EndpointNames.Token;\n        }\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"UserLoginSuccessEvent\"/> class.\n    /// </summary>\n    protected UserLoginSuccessEvent()\n        : base(EventCategories.Authentication,\n              \"User Login Success\",\n              EventTypes.Success,\n              EventIds.UserLoginSuccess)\n    {\n    }\n\n    /// <summary>\n    /// Gets or sets the username.\n    /// </summary>\n    /// <value>\n    /// The username.\n    /// </value>\n    public string Username { get; set; }\n\n    /// <summary>\n    /// Gets or sets the provider.\n    /// </summary>\n    /// <value>\n    /// The provider.\n    /// </value>\n    public string Provider { get; set; }\n\n    /// <summary>\n    /// Gets or sets the provider user identifier.\n    /// </summary>\n    /// <value>\n    /// The provider user identifier.\n    /// </value>\n    public string ProviderUserId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the display name.\n    /// </summary>\n    /// <value>\n    /// The display name.\n    /// </value>\n    public string DisplayName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the endpoint.\n    /// </summary>\n    /// <value>\n    /// The endpoint.\n    /// </value>\n    public string Endpoint { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the client id.\n    /// </summary>\n    /// <value>\n    /// The client id.\n    /// </value>\n    public string ClientId { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Events/UserLogoutSuccessEvent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// Event for successful user logout\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Events.Event\" />\npublic class UserLogoutSuccessEvent : Event\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"UserLogoutSuccessEvent\"/> class.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"name\">The name.</param>\n    public UserLogoutSuccessEvent(string subjectId, string name)\n        : base(EventCategories.Authentication, \n              \"User Logout Success\",\n              EventTypes.Success, \n              EventIds.UserLogoutSuccess)\n    {\n        SubjectId = subjectId;\n        DisplayName = name;\n    }\n\n    /// <summary>\n    /// Gets or sets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the display name.\n    /// </summary>\n    /// <value>\n    /// The display name.\n    /// </value>\n    public string DisplayName { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/AuthenticationPropertiesExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Extensions;\n\n/// <summary>\n/// Extensions for AuthenticationProperties\n/// </summary>\npublic static class AuthenticationPropertiesExtensions\n{\n    internal const string SessionIdKey = \"session_id\";\n    internal const string ClientListKey = \"client_list\";\n\n    /// <summary>\n    /// Gets the user's session identifier.\n    /// </summary>\n    /// <param name=\"properties\"></param>\n    /// <returns></returns>\n    public static string GetSessionId(this AuthenticationProperties properties)\n    {\n        if (properties?.Items.ContainsKey(SessionIdKey) == true)\n        {\n            return properties.Items[SessionIdKey];\n        }\n\n        return null;\n    }\n\n    /// <summary>\n    /// Sets the user's session identifier.\n    /// </summary>\n    /// <param name=\"properties\"></param>\n    /// <param name=\"sid\">The session id</param>\n    /// <returns></returns>\n    public static void SetSessionId(this AuthenticationProperties properties, string sid)\n    {\n        properties.Items[SessionIdKey] = sid;\n    }\n\n    /// <summary>\n    /// Gets the list of client ids the user has signed into during their session.\n    /// </summary>\n    /// <param name=\"properties\"></param>\n    /// <returns></returns>\n    public static IEnumerable<string> GetClientList(this AuthenticationProperties properties)\n    {\n        if (properties?.Items.ContainsKey(ClientListKey) == true)\n        {\n            var value = properties.Items[ClientListKey];\n            return DecodeList(value);\n        }\n\n        return Enumerable.Empty<string>();\n    }\n\n    /// <summary>\n    /// Removes the list of client ids.\n    /// </summary>\n    /// <param name=\"properties\"></param>\n    public static void RemoveClientList(this AuthenticationProperties properties)\n    {\n        properties?.Items.Remove(ClientListKey);\n    }\n\n    /// <summary>\n    /// Adds a client to the list of clients the user has signed into during their session.\n    /// </summary>\n    /// <param name=\"properties\"></param>\n    /// <param name=\"clientId\"></param>\n    public static void AddClientId(this AuthenticationProperties properties, string clientId)\n    {\n        if (clientId == null) throw new ArgumentNullException(nameof(clientId));\n\n        var clients = properties.GetClientList();\n        if (!clients.Contains(clientId))\n        {\n            var update = clients.ToList();\n            update.Add(clientId);\n\n            var value = EncodeList(update);\n            if (value == null)\n            {\n                properties.Items.Remove(ClientListKey);\n            }\n            else\n            {\n                properties.Items[ClientListKey] = value;\n            }\n        }\n    }\n\n\n    private static IEnumerable<string> DecodeList(string value)\n    {\n        if (value.IsPresent())\n        {\n            var bytes = Base64Url.Decode(value);\n            value = Encoding.UTF8.GetString(bytes);\n            return ObjectSerializer.FromString<string[]>(value);\n        }\n\n        return Enumerable.Empty<string>();\n    }\n\n    private static string EncodeList(IEnumerable<string> list)\n    {\n        if (list != null && list.Any())\n        {\n            var value = ObjectSerializer.ToString(list);\n            var bytes = Encoding.UTF8.GetBytes(value);\n            value = Base64Url.Encode(bytes);\n            return value;\n        }\n\n        return null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/AuthorizeResponseExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\ninternal static class AuthorizeResponseExtensions\n{\n    public static NameValueCollection ToNameValueCollection(this AuthorizeResponse response)\n    {\n        var collection = new NameValueCollection();\n\n        if (response.IsError)\n        {\n            if (response.Error.IsPresent())\n            {\n                collection.Add(\"error\", response.Error);\n            }\n            if (response.ErrorDescription.IsPresent())\n            {\n                collection.Add(\"error_description\", response.ErrorDescription);\n            }\n        }\n        else\n        {\n            if (response.Code.IsPresent())\n            {\n                collection.Add(\"code\", response.Code);\n            }\n\n            if (response.IdentityToken.IsPresent())\n            {\n                collection.Add(\"id_token\", response.IdentityToken);\n            }\n\n            if (response.AccessToken.IsPresent())\n            {\n                collection.Add(\"access_token\", response.AccessToken);\n                collection.Add(\"token_type\", \"Bearer\");\n                collection.Add(\"expires_in\", response.AccessTokenLifetime.ToString());\n            }\n\n            if (response.Scope.IsPresent())\n            {\n                collection.Add(\"scope\", response.Scope);\n            }\n        }\n\n        if (response.State.IsPresent())\n        {\n            collection.Add(\"state\", response.State);\n        }\n        \n        if (response.SessionState.IsPresent())\n        {\n            collection.Add(\"session_state\", response.SessionState);\n        }\n\n        return collection;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/ClaimsExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Extensions;\n\ninternal static class ClaimsExtensions\n{\n    public static Dictionary<string, object> ToClaimsDictionary(this IEnumerable<Claim> claims)\n    {\n        var d = new Dictionary<string, object>();\n\n        if (claims == null)\n        {\n            return d;\n        }\n\n        var distinctClaims = claims.Distinct(new ClaimComparer());\n\n        foreach (var claim in distinctClaims)\n        {\n            if (!d.ContainsKey(claim.Type))\n            {\n                d.Add(claim.Type, GetValue(claim));\n            }\n            else\n            {\n                var value = d[claim.Type];\n\n                if (value is List<object> list)\n                {\n                    list.Add(GetValue(claim));\n                }\n                else\n                {\n                    d.Remove(claim.Type);\n                    d.Add(claim.Type, new List<object> { value, GetValue(claim) });\n                }\n            }\n        }\n\n        return d;\n    }\n\n    private static object GetValue(Claim claim)\n    {\n        if (claim.ValueType == ClaimValueTypes.Integer ||\n            claim.ValueType == ClaimValueTypes.Integer32)\n        {\n            if (Int32.TryParse(claim.Value, out int value))\n            {\n                return value;\n            }\n        }\n\n        if (claim.ValueType == ClaimValueTypes.Integer64)\n        {\n            if (Int64.TryParse(claim.Value, out long value))\n            {\n                return value;\n            }\n        }\n\n        if (claim.ValueType == ClaimValueTypes.Boolean)\n        {\n            if (bool.TryParse(claim.Value, out bool value))\n            {\n                return value;\n            }\n        }\n\n        if (claim.ValueType == IdentityServerConstants.ClaimValueTypes.Json)\n        {\n            try\n            {\n                return System.Text.Json.JsonSerializer.Deserialize<JsonElement>(claim.Value);\n            }\n            catch { }\n        }\n\n        return claim.Value;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/ClientExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Extension methods for client.\n/// </summary>\npublic static class ClientExtensions\n{\n    /// <summary>\n    /// Returns true if the client is an implicit-only client.\n    /// </summary>\n    public static bool IsImplicitOnly(this Client client)\n    {\n        return client != null &&\n            client.AllowedGrantTypes != null &&\n            client.AllowedGrantTypes.Count == 1 &&\n            client.AllowedGrantTypes.First() == GrantType.Implicit;\n    }\n\n    /// <summary>\n    /// Constructs a list of SecurityKey from a Secret collection\n    /// </summary>\n    /// <param name=\"secrets\">The secrets</param>\n    /// <returns></returns>\n    public static Task<List<SecurityKey>> GetKeysAsync(this IEnumerable<Secret> secrets)\n    {\n        var secretList = secrets.ToList().AsReadOnly();\n        var keys = new List<SecurityKey>();\n\n        var certificates = GetCertificates(secretList)\n                            .Select(c => (SecurityKey)new X509SecurityKey(c))\n                            .ToList();\n        keys.AddRange(certificates);\n\n        var jwks = secretList\n                    .Where(s => s.Type == IdentityServerConstants.SecretTypes.JsonWebKey)\n                    .Select(s => new Microsoft.IdentityModel.Tokens.JsonWebKey(s.Value))\n                    .ToList();\n        keys.AddRange(jwks);\n\n        return Task.FromResult(keys);\n    }\n\n    private static List<X509Certificate2> GetCertificates(IEnumerable<Secret> secrets)\n    {\n        return secrets\n            .Where(s => s.Type == IdentityServerConstants.SecretTypes.X509CertificateBase64)\n            .Select(s => new X509Certificate2(Convert.FromBase64String(s.Value)))\n            .Where(c => c != null)\n            .ToList();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/DateTimeExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Extensions;\n\ninternal static class DateTimeExtensions\n{\n    [DebuggerStepThrough]\n    public static bool HasExceeded(this DateTime creationTime, int seconds, DateTime now)\n    {\n        return (now > creationTime.AddSeconds(seconds));\n    }\n\n    [DebuggerStepThrough]\n    public static int GetLifetimeInSeconds(this DateTime creationTime, DateTime now)\n    {\n        return ((int)(now - creationTime).TotalSeconds);\n    }\n\n    [DebuggerStepThrough]\n    public static bool HasExpired(this DateTime? expirationTime, DateTime now)\n    {\n        if (expirationTime.HasValue &&\n            expirationTime.Value.HasExpired(now))\n        {\n            return true;\n        }\n\n        return false;\n    }\n\n    [DebuggerStepThrough]\n    public static bool HasExpired(this DateTime expirationTime, DateTime now)\n    {\n        if (now > expirationTime)\n        {\n            return true;\n        }\n\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/EndpointOptionsExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Endpoint = IdentityServer8.Hosting.Endpoint;\n\nnamespace IdentityServer8.Extensions;\n\ninternal static class EndpointOptionsExtensions\n{\n    public static bool IsEndpointEnabled(this EndpointsOptions options, Endpoint endpoint)\n    {\n        return endpoint?.Name switch\n        {\n            EndpointNames.Authorize => options.EnableAuthorizeEndpoint,\n            EndpointNames.CheckSession => options.EnableCheckSessionEndpoint,\n            EndpointNames.DeviceAuthorization => options.EnableDeviceAuthorizationEndpoint,\n            EndpointNames.Discovery => options.EnableDiscoveryEndpoint,\n            EndpointNames.EndSession => options.EnableEndSessionEndpoint,\n            EndpointNames.Introspection => options.EnableIntrospectionEndpoint,\n            EndpointNames.Revocation => options.EnableTokenRevocationEndpoint,\n            EndpointNames.Token => options.EnableTokenEndpoint,\n            EndpointNames.UserInfo => options.EnableUserInfoEndpoint,\n            _ => true\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/HashExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Extension methods for hashing strings\n/// </summary>\npublic static class HashExtensions\n{\n    /// <summary>\n    /// Creates a SHA256 hash of the specified input.\n    /// </summary>\n    /// <param name=\"input\">The input.</param>\n    /// <returns>A hash</returns>\n    public static string Sha256(this string input)\n    {\n        if (input.IsMissing()) return string.Empty;\n\n        using (var sha = SHA256.Create())\n        {\n            var bytes = Encoding.UTF8.GetBytes(input);\n            var hash = sha.ComputeHash(bytes);\n\n            return Convert.ToBase64String(hash);\n        }\n    }\n\n    /// <summary>\n    /// Creates a SHA256 hash of the specified input.\n    /// </summary>\n    /// <param name=\"input\">The input.</param>\n    /// <returns>A hash.</returns>\n    public static byte[] Sha256(this byte[] input)\n    {\n        if (input == null)\n        {\n            return null;\n        }\n\n        using (var sha = SHA256.Create())\n        {\n            return sha.ComputeHash(input);\n        }\n    }\n\n    /// <summary>\n    /// Creates a SHA512 hash of the specified input.\n    /// </summary>\n    /// <param name=\"input\">The input.</param>\n    /// <returns>A hash</returns>\n    public static string Sha512(this string input)\n    {\n        if (input.IsMissing()) return string.Empty;\n\n        using (var sha = SHA512.Create())\n        {\n            var bytes = Encoding.UTF8.GetBytes(input);\n            var hash = sha.ComputeHash(bytes);\n\n            return Convert.ToBase64String(hash);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/HttpContextAuthenticationExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.AspNetCore.Http;\n\n/// <summary>\n/// Extension methods for signin/out using the IdentityServer authentication scheme.\n/// </summary>\npublic static class AuthenticationManagerExtensions\n{\n    /// <summary>\n    /// Signs the user in.\n    /// </summary>\n    /// <param name=\"context\">The manager.</param>\n    /// <param name=\"user\">The IdentityServer user.</param>\n    /// <returns></returns>\n    public static async Task SignInAsync(this HttpContext context, IdentityServerUser user)\n    {\n        await context.SignInAsync(await context.GetCookieAuthenticationSchemeAsync(), user.CreatePrincipal());\n    }\n\n    /// <summary>\n    /// Signs the user in.\n    /// </summary>\n    /// <param name=\"context\">The manager.</param>\n    /// <param name=\"user\">The IdentityServer user.</param>\n    /// <param name=\"properties\">The authentication properties.</param>\n    /// <returns></returns>\n    public static async Task SignInAsync(this HttpContext context, IdentityServerUser user, AuthenticationProperties properties)\n    {\n        await context.SignInAsync(await context.GetCookieAuthenticationSchemeAsync(), user.CreatePrincipal(), properties);\n    }\n\n    internal static ISystemClock GetClock(this HttpContext context)\n    {\n        return context.RequestServices.GetRequiredService<ISystemClock>();\n    }\n\n    internal static async Task<string> GetCookieAuthenticationSchemeAsync(this HttpContext context)\n    {\n        var options = context.RequestServices.GetRequiredService<IdentityServerOptions>();\n        if (options.Authentication.CookieAuthenticationScheme != null)\n        {\n            return options.Authentication.CookieAuthenticationScheme;\n        }\n\n        var schemes = context.RequestServices.GetRequiredService<IAuthenticationSchemeProvider>();\n        var scheme = await schemes.GetDefaultAuthenticateSchemeAsync();\n        if (scheme == null)\n        {\n            throw new InvalidOperationException(\"No DefaultAuthenticateScheme found or no CookieAuthenticationScheme configured on IdentityServerOptions.\");\n        }\n\n        return scheme.Name;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/HttpContextExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\n\nnamespace IdentityServer8.Extensions;\n\npublic static class HttpContextExtensions\n{\n    public static async Task<bool> GetSchemeSupportsSignOutAsync(this HttpContext context, string scheme)\n    {\n        var provider = context.RequestServices.GetRequiredService<IAuthenticationHandlerProvider>();\n        var handler = await provider.GetHandlerAsync(context, scheme);\n        return (handler is IAuthenticationSignOutHandler);\n    }\n\n    public static void SetIdentityServerOrigin(this HttpContext context, string value)\n    {\n        if (context == null) throw new ArgumentNullException(nameof(context));\n        if (value == null) throw new ArgumentNullException(nameof(value));\n\n        var split = value.Split(new[] { \"://\" }, StringSplitOptions.RemoveEmptyEntries);\n\n        var request = context.Request;\n        request.Scheme = split.First();\n        request.Host = new HostString(split.Last());\n    }\n\n    public static void SetIdentityServerBasePath(this HttpContext context, string value)\n    {\n        if (context == null) throw new ArgumentNullException(nameof(context));\n\n        context.Items[Constants.EnvironmentKeys.IdentityServerBasePath] = value;\n    }\n\n    public static string GetIdentityServerOrigin(this HttpContext context)\n    {\n        var options = context.RequestServices.GetRequiredService<IdentityServerOptions>();\n        var request = context.Request;\n        \n        if (options.MutualTls.Enabled && options.MutualTls.DomainName.IsPresent())\n        {\n            if (!options.MutualTls.DomainName.Contains(\".\"))\n            {\n                if (request.Host.Value.StartsWith(options.MutualTls.DomainName, StringComparison.OrdinalIgnoreCase))\n                {\n                    return request.Scheme + \"://\" +\n                           request.Host.Value.Substring(options.MutualTls.DomainName.Length + 1);\n                }\n            }\n        }\n        \n        return request.Scheme + \"://\" + request.Host.Value;\n    }\n\n\n    internal static void SetSignOutCalled(this HttpContext context)\n    {\n        if (context == null) throw new ArgumentNullException(nameof(context));\n        context.Items[Constants.EnvironmentKeys.SignOutCalled] = \"true\";\n    }\n\n    internal static bool GetSignOutCalled(this HttpContext context)\n    {\n        return context.Items.ContainsKey(Constants.EnvironmentKeys.SignOutCalled);\n    }\n\n    /// <summary>\n    /// Gets the host name of IdentityServer.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public static string GetIdentityServerHost(this HttpContext context)\n    {\n        var request = context.Request;\n        return request.Scheme + \"://\" + request.Host.ToUriComponent();\n    }\n\n    /// <summary>\n    /// Gets the base path of IdentityServer.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public static string GetIdentityServerBasePath(this HttpContext context)\n    {\n        return context.Items[Constants.EnvironmentKeys.IdentityServerBasePath] as string;\n    }\n\n    /// <summary>\n    /// Gets the public base URL for IdentityServer.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public static string GetIdentityServerBaseUrl(this HttpContext context)\n    {\n        return context.GetIdentityServerHost() + context.GetIdentityServerBasePath();\n    }\n\n    /// <summary>\n    /// Gets the identity server relative URL.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <param name=\"path\">The path.</param>\n    /// <returns></returns>\n    public static string GetIdentityServerRelativeUrl(this HttpContext context, string path)\n    {\n        if (!path.IsLocalUrl())\n        {\n            return null;\n        }\n\n        if (path.StartsWith(\"~/\")) path = path.Substring(1);\n        path = context.GetIdentityServerBaseUrl().EnsureTrailingSlash() + path.RemoveLeadingSlash();\n        return path;\n    }\n\n    /// <summary>\n    /// Gets the identity server issuer URI.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.ArgumentNullException\">context</exception>\n    public static string GetIdentityServerIssuerUri(this HttpContext context)\n    {\n        if (context == null) throw new ArgumentNullException(nameof(context));\n\n        // if they've explicitly configured a URI then use it,\n        // otherwise dynamically calculate it\n        var options = context.RequestServices.GetRequiredService<IdentityServerOptions>();\n        var uri = options.IssuerUri;\n        if (uri.IsMissing())\n        {\n            uri = context.GetIdentityServerOrigin() + context.GetIdentityServerBasePath();\n            if (uri.EndsWith(\"/\")) uri = uri.Substring(0, uri.Length - 1);\n            if (options.LowerCaseIssuerUri)\n            {\n                uri = uri.ToLowerInvariant();\n            }\n        }\n\n        return uri;\n    }\n\n    internal static async Task<string> GetIdentityServerSignoutFrameCallbackUrlAsync(this HttpContext context, LogoutMessage logoutMessage = null)\n    {\n        var userSession = context.RequestServices.GetRequiredService<IUserSession>();\n        var user = await userSession.GetUserAsync();\n        var currentSubId = user?.GetSubjectId();\n\n        LogoutNotificationContext endSessionMsg = null;\n\n        // if we have a logout message, then that take precedence over the current user\n        if (logoutMessage?.ClientIds?.Any() == true)\n        {\n            var clientIds = logoutMessage?.ClientIds;\n\n            // check if current user is same, since we might have new clients (albeit unlikely)\n            if (currentSubId == logoutMessage?.SubjectId)\n            {\n                clientIds = clientIds.Union(await userSession.GetClientListAsync());\n                clientIds = clientIds.Distinct();\n            }\n\n            endSessionMsg = new LogoutNotificationContext\n            {\n                SubjectId = logoutMessage.SubjectId,\n                SessionId = logoutMessage.SessionId,\n                ClientIds = clientIds\n            };\n        }\n        else if (currentSubId != null)\n        {\n            // see if current user has any clients they need to signout of \n            var clientIds = await userSession.GetClientListAsync();\n            if (clientIds.Any())\n            {\n                endSessionMsg = new LogoutNotificationContext\n                {\n                    SubjectId = currentSubId,\n                    SessionId = await userSession.GetSessionIdAsync(),\n                    ClientIds = clientIds\n                };\n            }\n        }\n\n        if (endSessionMsg != null)\n        {\n            var clock = context.RequestServices.GetRequiredService<ISystemClock>();\n            var msg = new Message<LogoutNotificationContext>(endSessionMsg, clock.UtcNow.UtcDateTime);\n\n            var endSessionMessageStore = context.RequestServices.GetRequiredService<IMessageStore<LogoutNotificationContext>>();\n            var id = await endSessionMessageStore.WriteAsync(msg);\n\n            var signoutIframeUrl = context.GetIdentityServerBaseUrl().EnsureTrailingSlash() + Constants.ProtocolRoutePaths.EndSessionCallback;\n            signoutIframeUrl = signoutIframeUrl.AddQueryString(Constants.UIConstants.DefaultRoutePathParams.EndSessionCallback, id);\n\n            return signoutIframeUrl;\n        }\n\n        // no sessions, so nothing to cleanup\n        return null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/HttpRequestExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\n\nusing System.Net.Http.Headers;\n\nnamespace IdentityServer8.Extensions;\n\npublic static class HttpRequestExtensions\n{\n    public static string GetCorsOrigin(this HttpRequest request)\n    {\n        var origin = request.Headers[\"Origin\"].FirstOrDefault();\n        var thisOrigin = request.Scheme + \"://\" + request.Host;\n\n        // see if the Origin is different than this server's origin. if so\n        // that indicates a proper CORS request. some browsers send Origin\n        // on POST requests.\n        if (origin != null && origin != thisOrigin)\n        {\n            return origin;\n        }\n\n        return null;\n    }\n    \n    internal static bool HasApplicationFormContentType(this HttpRequest request)\n    {\n        if (request.ContentType is null) return false;\n        \n        if (MediaTypeHeaderValue.TryParse(request.ContentType, out var header))\n        {\n            // Content-Type: application/x-www-form-urlencoded; charset=utf-8\n            return header.MediaType.Equals(\"application/x-www-form-urlencoded\", StringComparison.OrdinalIgnoreCase);\n        }\n\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/HttpResponseExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\n\nnamespace IdentityServer8.Extensions;\n\npublic static class HttpResponseExtensions\n{\n    public static async Task WriteJsonAsync(this HttpResponse response, object o, string contentType = null)\n    {\n        var json = ObjectSerializer.ToString(o);\n        await response.WriteJsonAsync(json, contentType);\n        await response.Body.FlushAsync();\n    }\n\n    public static async Task WriteJsonAsync(this HttpResponse response, string json, string contentType = null)\n    {\n        response.ContentType = contentType ?? \"application/json; charset=UTF-8\";\n        await response.WriteAsync(json);\n        await response.Body.FlushAsync();\n    }\n\n    public static void SetCache(this HttpResponse response, int maxAge, params string[] varyBy)\n    {\n        if (maxAge == 0)\n        {\n            SetNoCache(response);\n        }\n        else if (maxAge > 0)\n        {\n            if (!response.Headers.ContainsKey(\"Cache-Control\"))\n            {\n                response.Headers.Append(\"Cache-Control\", $\"max-age={maxAge}\");\n            }\n\n            if (varyBy?.Any() == true)\n            {\n                var vary = varyBy.Aggregate((x, y) => x + \",\" + y);\n                if (response.Headers.ContainsKey(\"Vary\"))\n                {\n                    vary = response.Headers[\"Vary\"].ToString() + \",\" + vary;\n                }\n                response.Headers[\"Vary\"] = vary;\n            }\n        }\n    }\n\n    public static void SetNoCache(this HttpResponse response)\n    {\n        if (!response.Headers.ContainsKey(\"Cache-Control\"))\n        {\n            response.Headers.Append(\"Cache-Control\", \"no-store, no-cache, max-age=0\");\n        }\n        else\n        {\n            response.Headers[\"Cache-Control\"] = \"no-store, no-cache, max-age=0\";\n        }\n\n        if (!response.Headers.ContainsKey(\"Pragma\"))\n        {\n            response.Headers.Append(\"Pragma\", \"no-cache\");\n        }\n    }\n\n    public static async Task WriteHtmlAsync(this HttpResponse response, string html)\n    {\n        response.ContentType = \"text/html; charset=UTF-8\";\n        await response.WriteAsync(html, Encoding.UTF8);\n        await response.Body.FlushAsync();\n    }\n\n    public static void RedirectToAbsoluteUrl(this HttpResponse response, string url)\n    {\n        if (url.IsLocalUrl())\n        {\n            if (url.StartsWith(\"~/\")) url = url.Substring(1);\n            url = response.HttpContext.GetIdentityServerBaseUrl().EnsureTrailingSlash() + url.RemoveLeadingSlash();\n        }\n        response.RedirectIfAllowed(url);\n    }\n\n    public static void AddScriptCspHeaders(this HttpResponse response, CspOptions options, string hash)\n    {\n        var csp1part = options.Level == CspLevel.One ? \"'unsafe-inline' \" : string.Empty;\n        var cspHeader = $\"default-src 'none'; script-src {csp1part}'{hash}'\";\n\n        AddCspHeaders(response.Headers, options, cspHeader);\n    }\n\n    public static void AddStyleCspHeaders(this HttpResponse response, CspOptions options, string hash, string frameSources)\n    {\n        var csp1part = options.Level == CspLevel.One ? \"'unsafe-inline' \" : string.Empty;\n        var cspHeader = $\"default-src 'none'; style-src {csp1part}'{hash}'\";\n\n        if (!string.IsNullOrEmpty(frameSources))\n        {\n            cspHeader += $\"; frame-src {frameSources}\";\n        }\n\n        AddCspHeaders(response.Headers, options, cspHeader);\n    }\n\n    public static void AddCspHeaders(IHeaderDictionary headers, CspOptions options, string cspHeader)\n    {\n        if (!headers.ContainsKey(\"Content-Security-Policy\"))\n        {\n            headers.Append(\"Content-Security-Policy\", cspHeader);\n        }\n        if (options.AddDeprecatedHeader && !headers.ContainsKey(\"X-Content-Security-Policy\"))\n        {\n            headers.Append(\"X-Content-Security-Policy\", cspHeader);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/ICacheExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Extensions;\n\n/// <summary>\n/// Extensions for ICache\n/// </summary>\npublic static class ICacheExtensions\n{\n    /// <summary>\n    /// Attempts to get an item from the cache. If the item is not found, the <c>get</c> function is used to\n    /// obtain the item and populate the cache.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"cache\">The cache.</param>\n    /// <param name=\"key\">The key.</param>\n    /// <param name=\"duration\">The duration.</param>\n    /// <param name=\"get\">The get function.</param>\n    /// <param name=\"logger\">The logger.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.ArgumentNullException\">cache\n    /// or\n    /// get</exception>\n    /// <exception cref=\"ArgumentNullException\">cache\n    /// or\n    /// get</exception>\n    public static async Task<T> GetAsync<T>(this ICache<T> cache, string key, TimeSpan duration, Func<Task<T>> get, ILogger logger)\n        where T : class\n    {\n        if (cache == null) throw new ArgumentNullException(nameof(cache));\n        if (get == null) throw new ArgumentNullException(nameof(get));\n        if (key == null) return null;\n\n        var item = await cache.GetAsync(key);\n\n        if (item == null)\n        {\n            logger.LogTrace(\"Cache miss for {cacheKey}\", Ioc.Sanitizer.Log.Sanitize(key));\n\n            item = await get();\n\n            if (item != null)\n            {\n                logger.LogTrace(\"Setting item in cache for {cacheKey}\", Ioc.Sanitizer.Log.Sanitize(key));\n                await cache.SetAsync(key, item, duration);\n            }\n        }\n        else\n        {\n            logger.LogTrace(\"Cache hit for {cacheKey}\", Ioc.Sanitizer.Log.Sanitize(key));\n        }\n\n        return item;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/IClientStoreExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Extension for IClientStore\n/// </summary>\npublic static class IClientStoreExtensions\n{\n    /// <summary>\n    /// Finds the enabled client by identifier.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    public static async Task<Client> FindEnabledClientByIdAsync(this IClientStore store, string clientId)\n    {\n        var client = await store.FindClientByIdAsync(clientId);\n        if (client != null && client.Enabled) return client;\n\n        return null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/IEnumerableExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Extensions;\n\npublic static class IEnumerableExtensions\n{\n    [DebuggerStepThrough]\n    public static bool EnumerableIsNullOrEmpty<T>(this IEnumerable<T> list)\n    {\n        if (list == null)\n        {\n            return true;\n        }\n\n        if (!list.Any())\n        {\n            return true;\n        }\n\n        return false;\n    }\n\n    public static bool HasDuplicates<T, TProp>(this IEnumerable<T> list, Func<T, TProp> selector)\n    {\n        var d = new HashSet<TProp>();\n        foreach (var t in list)\n        {\n            if (!d.Add(selector(t)))\n            {\n                return true;\n            }\n        }\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/IReadableStringCollectionExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Extensions;\n\npublic static class IReadableStringCollectionExtensions\n{\n    [DebuggerStepThrough]\n    public static NameValueCollection AsNameValueCollection(this IEnumerable<KeyValuePair<string, StringValues>> collection)\n    {\n        var nv = new NameValueCollection();\n\n        foreach (var field in collection)\n        {\n            nv.Add(field.Key, field.Value.First());\n        }\n\n        return nv;\n    }\n\n    [DebuggerStepThrough]\n    public static NameValueCollection AsNameValueCollection(this IDictionary<string, StringValues> collection)\n    {\n        var nv = new NameValueCollection();\n\n        foreach (var field in collection)\n        {\n            nv.Add(field.Key, field.Value.First());\n        }\n\n        return nv;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/IResourceStoreExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Extensions for IResourceStore\n/// </summary>\npublic static class IResourceStoreExtensions\n{\n    /// <summary>\n    /// Finds the resources by scope.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"scopeNames\">The scope names.</param>\n    /// <returns></returns>\n    public static async Task<Resources> FindResourcesByScopeAsync(this IResourceStore store, IEnumerable<string> scopeNames)\n    {\n        var identity = await store.FindIdentityResourcesByScopeNameAsync(scopeNames);\n        var apiResources = await store.FindApiResourcesByScopeNameAsync(scopeNames);\n        var scopes = await store.FindApiScopesByNameAsync(scopeNames);\n\n        Validate(identity, apiResources, scopes);\n\n        var resources = new Resources(identity, apiResources, scopes)\n        {\n            OfflineAccess = scopeNames.Contains(IdentityServerConstants.StandardScopes.OfflineAccess)\n        };\n\n        return resources;\n    }\n\n    private static void Validate(IEnumerable<IdentityResource> identity, IEnumerable<ApiResource> apiResources, IEnumerable<ApiScope> apiScopes)\n    {\n        // attempt to detect invalid configuration. this is about the only place\n        // we can do this, since it's hard to get the values in the store.\n        var identityScopeNames = identity.Select(x => x.Name).ToArray();\n        var dups = GetDuplicates(identityScopeNames);\n        if (dups.Any())\n        {\n            var names = dups.Aggregate((x, y) => x + \", \" + y);\n            throw new Exception(\n                $\"Duplicate identity scopes found. This is an invalid configuration. Use different names for identity scopes. Scopes found: {names}\");\n        }\n\n        var apiNames = apiResources.Select(x => x.Name);\n        dups = GetDuplicates(apiNames);\n        if (dups.Any())\n        {\n            var names = dups.Aggregate((x, y) => x + \", \" + y);\n            throw new Exception(\n                $\"Duplicate api resources found. This is an invalid configuration. Use different names for API resources. Names found: {names}\");\n        }\n        \n        var scopesNames = apiScopes.Select(x => x.Name);\n        dups = GetDuplicates(scopesNames);\n        if (dups.Any())\n        {\n            var names = dups.Aggregate((x, y) => x + \", \" + y);\n            throw new Exception(\n                $\"Duplicate scopes found. This is an invalid configuration. Use different names for scopes. Names found: {names}\");\n        }\n\n        var overlap = identityScopeNames.Intersect(scopesNames).ToArray();\n        if (overlap.Any())\n        {\n            var names = overlap.Aggregate((x, y) => x + \", \" + y);\n            throw new Exception(\n                $\"Found identity scopes and API scopes that use the same names. This is an invalid configuration. Use different names for identity scopes and API scopes. Scopes found: {names}\");\n        }\n    }\n\n    private static IEnumerable<string> GetDuplicates(IEnumerable<string> names)\n    {\n        var duplicates = names\n                        .GroupBy(x => x)\n                        .Where(g => g.Count() > 1)\n                        .Select(y => y.Key)\n                        .ToArray();\n        return duplicates.ToArray();\n    }\n\n    /// <summary>\n    /// Finds the enabled resources by scope.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"scopeNames\">The scope names.</param>\n    /// <returns></returns>\n    public static async Task<Resources> FindEnabledResourcesByScopeAsync(this IResourceStore store, IEnumerable<string> scopeNames)\n    {\n        return (await store.FindResourcesByScopeAsync(scopeNames)).FilterEnabled();\n    }\n\n    /// <summary>\n    /// Creates a resource validation result.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"parsedScopesResult\">The parsed scopes.</param>\n    /// <returns></returns>\n    public static async Task<ResourceValidationResult> CreateResourceValidationResult(this IResourceStore store, ParsedScopesResult parsedScopesResult)\n    {\n        var validScopeValues = parsedScopesResult.ParsedScopes;\n        var scopes = validScopeValues.Select(x => x.ParsedName).ToArray();\n        var resources = await store.FindEnabledResourcesByScopeAsync(scopes);\n        return new ResourceValidationResult(resources, validScopeValues);\n    }\n\n    /// <summary>\n    /// Gets all enabled resources.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <returns></returns>\n    public static async Task<Resources> GetAllEnabledResourcesAsync(this IResourceStore store)\n    {\n        var resources = await store.GetAllResourcesAsync();\n        Validate(resources.IdentityResources, resources.ApiResources, resources.ApiScopes);\n\n        return resources.FilterEnabled();\n    }\n\n    /// <summary>\n    /// Finds the enabled identity resources by scope.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"scopeNames\">The scope names.</param>\n    /// <returns></returns>\n    public static async Task<IEnumerable<IdentityResource>> FindEnabledIdentityResourcesByScopeAsync(this IResourceStore store, IEnumerable<string> scopeNames)\n    {\n        return (await store.FindIdentityResourcesByScopeNameAsync(scopeNames)).Where(x => x.Enabled).ToArray();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/IUserSessionExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Extension for IUserSession.\n/// </summary>\npublic static class IUserSessionExtensions\n{\n    /// <summary>\n    /// Creates a LogoutNotificationContext for the current user session.\n    /// </summary>\n    /// <returns></returns>\n    public static async Task<LogoutNotificationContext> GetLogoutNotificationContext(this IUserSession session)\n    {\n        var clientIds = await session.GetClientListAsync();\n\n        if (clientIds.Any())\n        {\n            var user = await session.GetUserAsync();\n            var sub = user.GetSubjectId();\n            var sid = await session.GetSessionIdAsync();\n\n            return new LogoutNotificationContext\n            {\n                SubjectId = sub,\n                SessionId = sid,\n                ClientIds = clientIds\n            };\n        }\n\n        return null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/IdentityServerToolsExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8;\n\n/// <summary>\n/// Extensions for IdentityServerTools\n/// </summary>\npublic static class IdentityServerToolsExtensions\n{\n    /// <summary>\n    /// Issues the client JWT.\n    /// </summary>\n    /// <param name=\"tools\">The tools.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <param name=\"lifetime\">The lifetime.</param>\n    /// <param name=\"scopes\">The scopes.</param>\n    /// <param name=\"audiences\">The audiences.</param>\n    /// <param name=\"additionalClaims\">Additional claims</param>\n    /// <returns></returns>\n    public static async Task<string> IssueClientJwtAsync(this IdentityServerTools tools,\n        string clientId,\n        int lifetime,\n        IEnumerable<string> scopes = null,\n        IEnumerable<string> audiences = null,\n        IEnumerable<Claim> additionalClaims = null)\n    {\n        var claims = new HashSet<Claim>(new ClaimComparer());\n        var context = tools.ContextAccessor.HttpContext;\n        var options = context.RequestServices.GetRequiredService<IdentityServerOptions>();\n        \n        if (additionalClaims != null)\n        {\n            foreach (var claim in additionalClaims)\n            {\n                claims.Add(claim);\n            }\n        }\n\n        claims.Add(new Claim(JwtClaimTypes.ClientId, clientId));\n\n        if (!scopes.EnumerableIsNullOrEmpty())\n        {\n            foreach (var scope in scopes)\n            {\n                claims.Add(new Claim(JwtClaimTypes.Scope, scope));\n            }\n        }\n\n        if (options.EmitStaticAudienceClaim)\n        {\n            claims.Add(new Claim(JwtClaimTypes.Audience, string.Format(IdentityServerConstants.AccessTokenAudience, tools.ContextAccessor.HttpContext.GetIdentityServerIssuerUri().EnsureTrailingSlash())));\n        }\n        \n        if (!audiences.EnumerableIsNullOrEmpty())\n        {\n            foreach (var audience in audiences)\n            {\n                claims.Add(new Claim(JwtClaimTypes.Audience, audience));\n            }\n        }\n\n        return await tools.IssueJwtAsync(lifetime, claims);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/JsonExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing JsonSerializer = System.Text.Json.JsonSerializer;\n\nnamespace IdentityServer8.Extensions;\n\ninternal static partial class JsonExtensions\n{\n    [DebuggerStepThrough]\n    public static T ToObject<T>(this JsonElement element, JsonSerializerOptions options = null)\n    {\n        var bufferWriter = new ArrayBufferWriter<byte>();\n        using (var writer = new Utf8JsonWriter(bufferWriter))\n            element.WriteTo(writer);\n        return JsonSerializer.Deserialize<T>(bufferWriter.WrittenSpan, options);\n    }\n\n    [DebuggerStepThrough]\n    public static T ToObject<T>(this JsonDocument document, JsonSerializerOptions options = null)\n    {\n        if (document == null)\n            throw new ArgumentNullException(nameof(document));\n        return document.RootElement.ToObject<T>(options);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/NameValueCollectionExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Extensions;\n\ninternal static class NameValueCollectionExtensions\n{\n    public static IDictionary<string, string[]> ToFullDictionary(this NameValueCollection source)\n    {\n        return source.AllKeys.ToDictionary(k => k, k => source.GetValues(k));\n    }\n\n    public static NameValueCollection FromFullDictionary(this IDictionary<string, string[]> source)\n    {\n        var nvc = new NameValueCollection();\n\n        foreach ((string key, string[] strings) in source)\n        {\n            foreach (var value in strings)\n            {\n                nvc.Add(key, value);\n            }\n        }\n\n        return nvc;\n    }\n    \n    public static string ToQueryString(this NameValueCollection collection)\n    {\n        if (collection.Count == 0)\n        {\n            return String.Empty;\n        }\n\n        var builder = new StringBuilder(128);\n        var first = true;\n        foreach (string name in collection)\n        {\n            var values = collection.GetValues(name);\n            if (values == null || values.Length == 0)\n            {\n                first = AppendNameValuePair(builder, first, true, name, String.Empty);\n            }\n            else\n            {\n                foreach (var value in values)\n                {\n                    first = AppendNameValuePair(builder, first, true, name, value);\n                }\n            }\n        }\n\n        return builder.ToString();\n    }\n\n    public static string ToFormPost(this NameValueCollection collection)\n    {\n        var builder = new StringBuilder(128);\n        const string inputFieldFormat = \"<input type='hidden' name='{0}' value='{1}' />\\n\";\n\n        foreach (string name in collection)\n        {\n            var values = collection.GetValues(name);\n            var value = values.First();\n            value = HtmlEncoder.Default.Encode(value);\n            builder.AppendFormat(inputFieldFormat, name, value);\n        }\n\n        return builder.ToString();\n    }\n\n    public static NameValueCollection ToNameValueCollection(this Dictionary<string, string> data)\n    {\n        var result = new NameValueCollection();\n\n        if (data == null || data.Count == 0)\n        {\n            return result;\n        }\n\n        foreach (var name in data.Keys)\n        {\n            var value = data[name];\n            if (value != null)\n            {\n                result.Add(name, value);\n            }\n        }\n\n        return result;\n    }\n\n    public static Dictionary<string, string> ToDictionary(this NameValueCollection collection)\n    {\n        return collection.ToScrubbedDictionary();\n    }\n\n    public static Dictionary<string, string> ToScrubbedDictionary(this NameValueCollection collection, params string[] nameFilter)\n    {\n        var dict = new Dictionary<string, string>();\n\n        if (collection == null || collection.Count == 0)\n        {\n            return dict;\n        }\n\n        foreach (string name in collection)\n        {\n            var value = collection.Get(name);\n            if (value != null)\n            {\n                if (nameFilter.Contains(name, StringComparer.OrdinalIgnoreCase))\n                {\n                    value = \"***REDACTED***\";\n                }\n                dict.Add(name, value);\n            }\n        }\n\n        return dict;\n    }\n\n    internal static string ConvertFormUrlEncodedSpacesToUrlEncodedSpaces(string str)\n    {\n        if ((str != null) && (str.IndexOf('+') >= 0))\n        {\n            str = str.Replace(\"+\", \"%20\");\n        }\n        return str;\n    }\n\n    private static bool AppendNameValuePair(StringBuilder builder, bool first, bool urlEncode, string name, string value)\n    {\n        var effectiveName = name ?? String.Empty;\n        var encodedName = urlEncode ? UrlEncoder.Default.Encode(effectiveName) : effectiveName;\n\n        var effectiveValue = value ?? String.Empty;\n        var encodedValue = urlEncode ? UrlEncoder.Default.Encode(effectiveValue) : effectiveValue;\n        encodedValue = ConvertFormUrlEncodedSpacesToUrlEncodedSpaces(encodedValue);\n\n        if (first)\n        {\n            first = false;\n        }\n        else\n        {\n            builder.Append(\"&\");\n        }\n\n        builder.Append(encodedName);\n        if (!String.IsNullOrEmpty(encodedValue))\n        {\n            builder.Append(\"=\");\n            builder.Append(encodedValue);\n        }\n        return first;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/PrincipalExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Extensions;\n\n/// <summary>\n/// Extension methods for <see cref=\"System.Security.Principal.IPrincipal\"/> and <see cref=\"System.Security.Principal.IIdentity\"/> .\n/// </summary>\npublic static class PrincipalExtensions\n{\n    /// <summary>\n    /// Gets the authentication time.\n    /// </summary>\n    /// <param name=\"principal\">The principal.</param>\n    /// <returns></returns>\n    [DebuggerStepThrough]\n    public static DateTime GetAuthenticationTime(this IPrincipal principal)\n    {\n        return DateTimeOffset.FromUnixTimeSeconds(principal.GetAuthenticationTimeEpoch()).UtcDateTime;\n    }\n\n    /// <summary>\n    /// Gets the authentication epoch time.\n    /// </summary>\n    /// <param name=\"principal\">The principal.</param>\n    /// <returns></returns>\n    [DebuggerStepThrough]\n    public static long GetAuthenticationTimeEpoch(this IPrincipal principal)\n    {\n        return principal.Identity.GetAuthenticationTimeEpoch();\n    }\n\n    /// <summary>\n    /// Gets the authentication epoch time.\n    /// </summary>\n    /// <param name=\"identity\">The identity.</param>\n    /// <returns></returns>\n    [DebuggerStepThrough]\n    public static long GetAuthenticationTimeEpoch(this IIdentity identity)\n    {\n        var id = identity as ClaimsIdentity;\n        var claim = id.FindFirst(JwtClaimTypes.AuthenticationTime);\n\n        if (claim == null) throw new InvalidOperationException(\"auth_time is missing.\");\n       \n        return long.Parse(claim.Value);\n    }\n\n    /// <summary>\n    /// Gets the subject identifier.\n    /// </summary>\n    /// <param name=\"principal\">The principal.</param>\n    /// <returns></returns>\n    [DebuggerStepThrough]\n    public static string GetSubjectId(this IPrincipal principal)\n    {\n        return principal.Identity.GetSubjectId();\n    }\n\n    /// <summary>\n    /// Gets the subject identifier.\n    /// </summary>\n    /// <param name=\"identity\">The identity.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.InvalidOperationException\">sub claim is missing</exception>\n    [DebuggerStepThrough]\n    public static string GetSubjectId(this IIdentity identity)\n    {\n        var id = identity as ClaimsIdentity;\n        var claim = id.FindFirst(JwtClaimTypes.Subject);\n\n        if (claim == null) throw new InvalidOperationException(\"sub claim is missing\");\n        return claim.Value;\n    }\n\n    /// <summary>\n    /// Gets the name.\n    /// </summary>\n    /// <param name=\"principal\">The principal.</param>\n    /// <returns></returns>\n    [DebuggerStepThrough]\n    [Obsolete(\"This method will be removed in a future version. Use GetDisplayName instead.\")]\n    public static string GetName(this IPrincipal principal)\n    {\n        return principal.Identity.GetName();\n    }\n\n    /// <summary>\n    /// Gets the name.\n    /// </summary>\n    /// <param name=\"principal\">The principal.</param>\n    /// <returns></returns>\n    [DebuggerStepThrough]\n    public static string GetDisplayName(this ClaimsPrincipal principal)\n    {\n        var name = principal.Identity.Name;\n        if (name.IsPresent()) return name;\n\n        var sub = principal.FindFirst(JwtClaimTypes.Subject);\n        if (sub != null) return sub.Value;\n\n        return string.Empty;\n    }\n\n    /// <summary>\n    /// Gets the name.\n    /// </summary>\n    /// <param name=\"identity\">The identity.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.InvalidOperationException\">name claim is missing</exception>\n    [DebuggerStepThrough]\n    [Obsolete(\"This method will be removed in a future version. Use GetDisplayName instead.\")]\n    public static string GetName(this IIdentity identity)\n    {\n        var id = identity as ClaimsIdentity;\n        var claim = id.FindFirst(JwtClaimTypes.Name);\n\n        if (claim == null) throw new InvalidOperationException(\"name claim is missing\");\n        return claim.Value;\n    }\n\n    /// <summary>\n    /// Gets the authentication method.\n    /// </summary>\n    /// <param name=\"principal\">The principal.</param>\n    /// <returns></returns>\n    [DebuggerStepThrough]\n    public static string GetAuthenticationMethod(this IPrincipal principal)\n    {\n        return principal.Identity.GetAuthenticationMethod();\n    }\n\n    /// <summary>\n    /// Gets the authentication method claims.\n    /// </summary>\n    /// <param name=\"principal\">The principal.</param>\n    /// <returns></returns>\n    [DebuggerStepThrough]\n    public static IEnumerable<Claim> GetAuthenticationMethods(this IPrincipal principal)\n    {\n        return principal.Identity.GetAuthenticationMethods();\n    }\n\n    /// <summary>\n    /// Gets the authentication method.\n    /// </summary>\n    /// <param name=\"identity\">The identity.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.InvalidOperationException\">amr claim is missing</exception>\n    [DebuggerStepThrough]\n    public static string GetAuthenticationMethod(this IIdentity identity)\n    {\n        var id = identity as ClaimsIdentity;\n        var claim = id.FindFirst(JwtClaimTypes.AuthenticationMethod);\n\n        if (claim == null) throw new InvalidOperationException(\"amr claim is missing\");\n        return claim.Value;\n    }\n\n    /// <summary>\n    /// Gets the authentication method claims.\n    /// </summary>\n    /// <param name=\"identity\">The identity.</param>\n    /// <returns></returns>\n    [DebuggerStepThrough]\n    public static IEnumerable<Claim> GetAuthenticationMethods(this IIdentity identity)\n    {\n        var id = identity as ClaimsIdentity;\n        return id.FindAll(JwtClaimTypes.AuthenticationMethod);\n    }\n\n    /// <summary>\n    /// Gets the identity provider.\n    /// </summary>\n    /// <param name=\"principal\">The principal.</param>\n    /// <returns></returns>\n    [DebuggerStepThrough]\n    public static string GetIdentityProvider(this IPrincipal principal)\n    {\n        return principal.Identity.GetIdentityProvider();\n    }\n\n    /// <summary>\n    /// Gets the identity provider.\n    /// </summary>\n    /// <param name=\"identity\">The identity.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.InvalidOperationException\">idp claim is missing</exception>\n    [DebuggerStepThrough]\n    public static string GetIdentityProvider(this IIdentity identity)\n    {\n        var id = identity as ClaimsIdentity;\n        var claim = id.FindFirst(JwtClaimTypes.IdentityProvider);\n\n        if (claim == null) throw new InvalidOperationException(\"idp claim is missing\");\n        return claim.Value;\n    }\n\n    /// <summary>\n    /// Determines whether this instance is authenticated.\n    /// </summary>\n    /// <param name=\"principal\">The principal.</param>\n    /// <returns>\n    ///   <c>true</c> if the specified principal is authenticated; otherwise, <c>false</c>.\n    /// </returns>\n    [DebuggerStepThrough]\n    public static bool IsAuthenticated(this IPrincipal principal)\n    {\n        return principal != null && principal.Identity != null && principal.Identity.IsAuthenticated;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/ProfileDataRequestContextExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Extensions for ProfileDataRequestContext\n/// </summary>\npublic static class ProfileDataRequestContextExtensions\n{\n    /// <summary>\n    /// Filters the claims based on requested claim types.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <param name=\"claims\">The claims.</param>\n    /// <returns></returns>\n    public static List<Claim> FilterClaims(this ProfileDataRequestContext context, IEnumerable<Claim> claims)\n    {\n        if (context == null) throw new ArgumentNullException(nameof(context));\n        if (claims == null) throw new ArgumentNullException(nameof(claims));\n\n        return claims.Where(x => context.RequestedClaimTypes.Contains(x.Type)).ToList();\n    }\n\n    /// <summary>\n    /// Filters the claims based on the requested claim types and then adds them to the IssuedClaims collection.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <param name=\"claims\">The claims.</param>\n    public static void AddRequestedClaims(this ProfileDataRequestContext context, IEnumerable<Claim> claims)\n    {\n        if (context.RequestedClaimTypes.Any())\n        {\n            context.IssuedClaims.AddRange(context.FilterClaims(claims));\n        }\n    }\n\n    /// <summary>\n    /// Logs the profile request.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public static void LogProfileRequest(this ProfileDataRequestContext context, ILogger logger)\n    {\n        logger.LogDebug(\"Get profile called for subject {subject} from client {client} with claim types {claimTypes} via {caller}\",\n            context.Subject.GetSubjectId(),\n            context.Client.ClientName ?? context.Client.ClientId,\n            context.RequestedClaimTypes,\n            context.Caller);\n    }\n\n    /// <summary>\n    /// Logs the issued claims.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public static void LogIssuedClaims(this ProfileDataRequestContext context, ILogger logger)\n    {\n        logger.LogDebug(\"Issued claims: {claims}\", context.IssuedClaims.Select(c => c.Type));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/ResourceExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Extensions for Resource\n/// </summary>\npublic static class ResourceExtensions\n{\n    /// <summary>\n    /// Returns the collection of scope values that are required.\n    /// </summary>\n    /// <param name=\"resourceValidationResult\"></param>\n    /// <returns></returns>\n    public static IEnumerable<string> GetRequiredScopeValues(this ResourceValidationResult resourceValidationResult)\n    {\n        var names = resourceValidationResult.Resources.IdentityResources.Where(x => x.Required).Select(x => x.Name).ToList();\n        names.AddRange(resourceValidationResult.Resources.ApiScopes.Where(x => x.Required).Select(x => x.Name));\n\n        var values = resourceValidationResult.ParsedScopes.Where(x => names.Contains(x.ParsedName)).Select(x => x.RawValue);\n        return values;\n    }\n\n    /// <summary>\n    /// Converts to scope names.\n    /// </summary>\n    /// <param name=\"resources\">The resources.</param>\n    /// <returns></returns>\n    public static IEnumerable<string> ToScopeNames(this Resources resources)\n    {\n        var names = resources.IdentityResources.Select(x => x.Name).ToList();\n        names.AddRange(resources.ApiScopes.Select(x => x.Name));\n        if (resources.OfflineAccess)\n        {\n            names.Add(IdentityServerConstants.StandardScopes.OfflineAccess);\n        }\n        \n        return names;\n    }\n\n    /// <summary>\n    /// Finds the IdentityResource that matches the scope.\n    /// </summary>\n    /// <param name=\"resources\">The resources.</param>\n    /// <param name=\"name\">The name.</param>\n    /// <returns></returns>\n    public static IdentityResource FindIdentityResourcesByScope(this Resources resources, string name)\n    {\n        var q = from id in resources.IdentityResources\n                where id.Name == name\n                select id;\n        return q.FirstOrDefault();\n    }\n\n    /// <summary>\n    /// Finds the API resources that contain the scope.\n    /// </summary>\n    /// <param name=\"resources\">The resources.</param>\n    /// <param name=\"name\">The name.</param>\n    /// <returns></returns>\n    public static IEnumerable<ApiResource> FindApiResourcesByScope(this Resources resources, string name)\n    {\n        var q = from api in resources.ApiResources\n                where api.Scopes != null && api.Scopes.Contains(name)\n                select api;\n        return q.ToArray();\n    }\n\n    /// <summary>\n    /// Finds the API scope.\n    /// </summary>\n    /// <param name=\"resources\">The resources.</param>\n    /// <param name=\"name\">The name.</param>\n    /// <returns></returns>\n    public static ApiScope FindApiScope(this Resources resources, string name)\n    {\n        var q = from scope in resources.ApiScopes\n                where scope.Name == name\n                select scope;\n        return q.FirstOrDefault();\n    }\n\n    internal static Resources FilterEnabled(this Resources resources)\n    {\n        if (resources == null) return new Resources();\n\n        return new Resources(\n            resources.IdentityResources.Where(x => x.Enabled),\n            resources.ApiResources.Where(x => x.Enabled),\n            resources.ApiScopes.Where(x => x.Enabled))\n        {\n            OfflineAccess = resources.OfflineAccess\n        };\n    }\n\n    internal static ICollection<string> FindMatchingSigningAlgorithms(this IEnumerable<ApiResource> apiResources)\n    {\n        var apis = apiResources.ToList();\n\n        if (apis.EnumerableIsNullOrEmpty())\n        {\n            return new List<string>();\n        }\n\n        // only one API resource request, forward the allowed signing algorithms (if any)\n        if (apis.Count == 1)\n        {\n            return apis.First().AllowedAccessTokenSigningAlgorithms;\n        }\n        \n        var allAlgorithms = apis.Where(r => r.AllowedAccessTokenSigningAlgorithms.Any()).Select(r => r.AllowedAccessTokenSigningAlgorithms).ToList();\n\n        // resources need to agree on allowed signing algorithms\n        if (allAlgorithms.Any())\n        {\n            var allowedAlgorithms = IntersectLists(allAlgorithms);\n\n            if (allowedAlgorithms.Any())\n            {\n                return allowedAlgorithms.ToHashSet();\n            }\n\n            throw new InvalidOperationException(\"Signing algorithms requirements for requested resources are not compatible.\");\n        }\n\n        return new List<string>();\n    }\n\n    private static IEnumerable<T> IntersectLists<T>(IEnumerable<IEnumerable<T>> lists)\n    {\n        return lists.Aggregate((l1, l2) => l1.Intersect(l2));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/ScopeExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\ninternal static class ScopeExtensions\n{\n    [DebuggerStepThrough]\n    public static string ToSpaceSeparatedString(this IEnumerable<ApiScope> apiScopes)\n    {\n        var scopeNames = from s in apiScopes\n                         select s.Name;\n\n        return string.Join(\" \", scopeNames.ToArray());\n    }\n\n    [DebuggerStepThrough]\n    public static IEnumerable<string> ToStringList(this IEnumerable<ApiScope> apiScopes)\n    {\n        var scopeNames = from s in apiScopes\n                         select s.Name;\n\n        return scopeNames;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/StringsExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Extensions;\n\n\ninternal static class StringExtensions\n{\n    [DebuggerStepThrough]\n    public static string ToSpaceSeparatedString(this IEnumerable<string> list)\n    {\n        if (list == null)\n        {\n            return string.Empty;\n        }\n\n        var sb = new StringBuilder(100);\n\n        foreach (var element in list)\n        {\n            sb.Append(element + \" \");\n        }\n\n        return sb.ToString().Trim();\n    }\n\n    [DebuggerStepThrough]\n    public static IEnumerable<string> FromSpaceSeparatedString(this string input)\n    {\n        input = input.Trim();\n        return input.Split(new[] { ' ' }, StringSplitOptions.RemoveEmptyEntries).ToList();\n    }\n\n    public static List<string> ParseScopesString(this string scopes)\n    {\n        if (scopes.IsMissing())\n        {\n            return null;\n        }\n\n        scopes = scopes.Trim();\n        var parsedScopes = scopes.Split(new[] { ' ' }, StringSplitOptions.RemoveEmptyEntries).Distinct().ToList();\n\n        if (parsedScopes.Any())\n        {\n            parsedScopes.Sort();\n            return parsedScopes;\n        }\n\n        return null;\n    }\n\n    [DebuggerStepThrough]\n    public static bool IsMissing(this string value)\n    {\n        return string.IsNullOrWhiteSpace(value);\n    }\n\n    [DebuggerStepThrough]\n    public static bool IsMissingOrTooLong(this string value, int maxLength)\n    {\n        if (string.IsNullOrWhiteSpace(value))\n        {\n            return true;\n        }\n        if (value.Length > maxLength)\n        {\n            return true;\n        }\n\n        return false;\n    }\n\n    [DebuggerStepThrough]\n    public static bool IsPresent(this string value)\n    {\n        return !string.IsNullOrWhiteSpace(value);\n    }\n\n    [DebuggerStepThrough]\n    public static string EnsureLeadingSlash(this string url)\n    {\n        if (url != null && !url.StartsWith(\"/\"))\n        {\n            return \"/\" + url;\n        }\n\n        return url;\n    }\n\n    [DebuggerStepThrough]\n    public static string EnsureTrailingSlash(this string url)\n    {\n        if (url != null && !url.EndsWith(\"/\"))\n        {\n            return url + \"/\";\n        }\n\n        return url;\n    }\n\n    [DebuggerStepThrough]\n    public static string RemoveLeadingSlash(this string url)\n    {\n        if (url != null && url.StartsWith(\"/\"))\n        {\n            url = url.Substring(1);\n        }\n\n        return url;\n    }\n\n    [DebuggerStepThrough]\n    public static string RemoveTrailingSlash(this string url)\n    {\n        if (url != null && url.EndsWith(\"/\"))\n        {\n            url = url.Substring(0, url.Length - 1);\n        }\n\n        return url;\n    }\n\n    [DebuggerStepThrough]\n    public static string CleanUrlPath(this string url)\n    {\n        if (String.IsNullOrWhiteSpace(url)) url = \"/\";\n\n        if (url != \"/\" && url.EndsWith(\"/\"))\n        {\n            url = url.Substring(0, url.Length - 1);\n        }\n\n        return url;\n    }\n\n    [DebuggerStepThrough]\n    public static bool IsLocalUrl(this string url)\n    {\n        if (string.IsNullOrEmpty(url))\n        {\n            return false;\n        }\n\n        // Allows \"/\" or \"/foo\" but not \"//\" or \"/\\\".\n        if (url[0] == '/')\n        {\n            // url is exactly \"/\"\n            if (url.Length == 1)\n            {\n                return true;\n            }\n\n            // url doesn't start with \"//\" or \"/\\\"\n            if (url[1] != '/' && url[1] != '\\\\')\n            {\n                return true;\n            }\n\n            return false;\n        }\n\n        // Allows \"~/\" or \"~/foo\" but not \"~//\" or \"~/\\\".\n        if (url[0] == '~' && url.Length > 1 && url[1] == '/')\n        {\n            // url is exactly \"~/\"\n            if (url.Length == 2)\n            {\n                return true;\n            }\n\n            // url doesn't start with \"~//\" or \"~/\\\"\n            if (url[2] != '/' && url[2] != '\\\\')\n            {\n                return true;\n            }\n\n            return false;\n        }\n\n        return false;\n    }\n\n    [DebuggerStepThrough]\n    public static string AddQueryString(this string url, string query)\n    {\n        if (!url.Contains(\"?\"))\n        {\n            url += \"?\";\n        }\n        else if (!url.EndsWith(\"&\"))\n        {\n            url += \"&\";\n        }\n\n        return url + query;\n    }\n\n    [DebuggerStepThrough]\n    public static string AddQueryString(this string url, string name, string value)\n    {\n        return url.AddQueryString(name + \"=\" + UrlEncoder.Default.Encode(value));\n    }\n\n    [DebuggerStepThrough]\n    public static string AddHashFragment(this string url, string query)\n    {\n        if (!url.Contains(\"#\"))\n        {\n            url += \"#\";\n        }\n\n        return url + query;\n    }\n\n    [DebuggerStepThrough]\n    public static NameValueCollection ReadQueryStringAsNameValueCollection(this string url)\n    {\n        if (url != null)\n        {\n            var idx = url.IndexOf('?');\n            if (idx >= 0)\n            {\n                url = url.Substring(idx + 1);\n            }\n            var query = QueryHelpers.ParseNullableQuery(url);\n            if (query != null)\n            {\n                return query.AsNameValueCollection();\n            }\n        }\n\n        return new NameValueCollection();\n    }\n\n    public static string GetOrigin(this string url)\n    {\n        if (url != null)\n        {\n            Uri uri;\n            try\n            {\n                uri = new Uri(url);\n            }\n            catch (Exception)\n            {\n                return null;\n            }\n\n            if (uri.Scheme == \"http\" || uri.Scheme == \"https\")\n            {\n                return $\"{uri.Scheme}://{uri.Authority}\";\n            }\n        }\n\n        return null;\n    }\n\n    public static string Obfuscate(this string value)\n    {\n        var last4Chars = \"****\";\n        if (value.IsPresent() && value.Length > 4)\n        {\n            last4Chars = value.Substring(value.Length - 4);\n        }\n\n        return \"****\" + last4Chars;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/TokenExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Extensions;\n\n/// <summary>\n/// Extensions for Token\n/// </summary>\npublic static class TokenExtensions\n{\n    /// <summary>\n    /// Creates the default JWT payload.\n    /// </summary>\n    /// <param name=\"token\">The token.</param>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"options\">The options</param>\n    /// <param name=\"logger\">The logger.</param>\n    /// <returns></returns>\n    /// <exception cref=\"Exception\">\n    /// </exception>\n    public static JwtPayload CreateJwtPayload(this Token token, ISystemClock clock, IdentityServerOptions options, ILogger logger)\n    {\n        var payload = new JwtPayload(\n            token.Issuer,\n            null,\n            null,\n            clock.UtcNow.UtcDateTime,\n            clock.UtcNow.UtcDateTime.AddSeconds(token.Lifetime));\n\n        foreach (var aud in token.Audiences)\n        {\n            payload.AddClaim(new Claim(JwtClaimTypes.Audience, aud));\n        }\n\n        var amrClaims = token.Claims.Where(x => x.Type == JwtClaimTypes.AuthenticationMethod).ToArray();\n        var scopeClaims = token.Claims.Where(x => x.Type == JwtClaimTypes.Scope).ToArray();\n        var jsonClaims = token.Claims.Where(x => x.ValueType == IdentityServerConstants.ClaimValueTypes.Json).ToList();\n        \n        // add confirmation claim if present (it's JSON valued)\n        if (token.Confirmation.IsPresent())\n        {\n            jsonClaims.Add(new Claim(JwtClaimTypes.Confirmation, token.Confirmation, IdentityServerConstants.ClaimValueTypes.Json));\n        }\n\n        var normalClaims = token.Claims\n            .Except(amrClaims)\n            .Except(jsonClaims)\n            .Except(scopeClaims);\n\n        payload.AddClaims(normalClaims);\n\n        // scope claims\n        if (!scopeClaims.EnumerableIsNullOrEmpty())\n        {\n            var scopeValues = scopeClaims.Select(x => x.Value).ToArray();\n\n            if (options.EmitScopesAsSpaceDelimitedStringInJwt)\n            {\n                payload.Add(JwtClaimTypes.Scope, string.Join(\" \", scopeValues));\n            }\n            else\n            {\n                payload.Add(JwtClaimTypes.Scope, scopeValues);\n            }\n        }\n\n        // amr claims\n        if (!amrClaims.EnumerableIsNullOrEmpty())\n        {\n            var amrValues = amrClaims.Select(x => x.Value).Distinct().ToArray();\n            payload.Add(JwtClaimTypes.AuthenticationMethod, amrValues);\n        }\n        \n        // deal with json types\n        // calling ToArray() to trigger JSON parsing once and so later \n        // collection identity comparisons work for the anonymous type\n        try\n        {\n            var jsonTokens = jsonClaims.Select(x => new { x.Type, JsonValue = JRaw.Parse(x.Value) }).ToArray();\n\n            var jsonObjects = jsonTokens.Where(x => x.JsonValue.Type == JTokenType.Object).ToArray();\n            var jsonObjectGroups = jsonObjects.GroupBy(x => x.Type).ToArray();\n            foreach (var group in jsonObjectGroups)\n            {\n                if (payload.ContainsKey(group.Key))\n                {\n                    throw new Exception($\"Can't add two claims where one is a JSON object and the other is not a JSON object ({group.Key})\");\n                }\n\n                if (group.Skip(1).Any())\n                {\n                    // add as array\n                    payload.Add(group.Key, group.Select(x => x.JsonValue).ToArray());\n                }\n                else\n                {\n                    // add just one\n                    payload.Add(group.Key, group.First().JsonValue);\n                }\n            }\n\n            var jsonArrays = jsonTokens.Where(x => x.JsonValue.Type == JTokenType.Array).ToArray();\n            var jsonArrayGroups = jsonArrays.GroupBy(x => x.Type).ToArray();\n            foreach (var group in jsonArrayGroups)\n            {\n                if (payload.ContainsKey(group.Key))\n                {\n                    throw new Exception(\n                        $\"Can't add two claims where one is a JSON array and the other is not a JSON array ({group.Key})\");\n                }\n\n                var newArr = new List<JToken>();\n                foreach (var arrays in group)\n                {\n                    var arr = (JArray)arrays.JsonValue;\n                    newArr.AddRange(arr);\n                }\n\n                // add just one array for the group/key/claim type\n                payload.Add(group.Key, newArr.ToArray());\n            }\n\n            var unsupportedJsonTokens = jsonTokens.Except(jsonObjects).Except(jsonArrays).ToArray();\n            var unsupportedJsonClaimTypes = unsupportedJsonTokens.Select(x => x.Type).Distinct().ToArray();\n            if (unsupportedJsonClaimTypes.Any())\n            {\n                throw new Exception(\n                    $\"Unsupported JSON type for claim types: {unsupportedJsonClaimTypes.Aggregate((x, y) => x + \", \" + y)}\");\n            }\n\n            return payload;\n        }\n        catch (Exception ex)\n        {\n            logger.LogCritical(ex, \"Error creating a JSON valued claim\");\n            throw;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/ValidatedAuthorizeRequestExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Validation;\n\npublic static class ValidatedAuthorizeRequestExtensions\n{\n    public static void RemovePrompt(this ValidatedAuthorizeRequest request)\n    {\n        request.PromptModes = Enumerable.Empty<string>();\n        request.Raw.Remove(OidcConstants.AuthorizeRequest.Prompt);\n    }\n\n    public static string GetPrefixedAcrValue(this ValidatedAuthorizeRequest request, string prefix)\n    {\n        var value = request.AuthenticationContextReferenceClasses\n            .FirstOrDefault(x => x.StartsWith(prefix));\n\n        if (value != null)\n        {\n            value = value.Substring(prefix.Length);\n        }\n\n        return value;\n    }\n\n    public static void RemovePrefixedAcrValue(this ValidatedAuthorizeRequest request, string prefix)\n    {\n        request.AuthenticationContextReferenceClasses.RemoveAll(acr => acr.StartsWith(prefix, StringComparison.Ordinal));\n        var acr_values = request.AuthenticationContextReferenceClasses.ToSpaceSeparatedString();\n        if (acr_values.IsPresent())\n        {\n            request.Raw[OidcConstants.AuthorizeRequest.AcrValues] = acr_values;\n        }\n        else\n        {\n            request.Raw.Remove(OidcConstants.AuthorizeRequest.AcrValues);\n        }\n    }\n\n    public static string GetIdP(this ValidatedAuthorizeRequest request)\n    {\n        return request.GetPrefixedAcrValue(Constants.KnownAcrValues.HomeRealm);\n    }\n\n    public static void RemoveIdP(this ValidatedAuthorizeRequest request)\n    {\n        request.RemovePrefixedAcrValue(Constants.KnownAcrValues.HomeRealm);\n    }\n\n    public static string GetTenant(this ValidatedAuthorizeRequest request)\n    {\n        return request.GetPrefixedAcrValue(Constants.KnownAcrValues.Tenant);\n    }\n\n    public static IEnumerable<string> GetAcrValues(this ValidatedAuthorizeRequest request)\n    {\n        return request\n            .AuthenticationContextReferenceClasses\n            .Where(acr => !Constants.KnownAcrValues.All.Any(well_known => acr.StartsWith(well_known)))\n            .Distinct()\n            .ToArray();\n    }\n\n    public static void RemoveAcrValue(this ValidatedAuthorizeRequest request, string value)\n    {\n        request.AuthenticationContextReferenceClasses.RemoveAll(x => x.Equals(value, StringComparison.Ordinal));\n        var acr_values = request.AuthenticationContextReferenceClasses.ToSpaceSeparatedString();\n        if (acr_values.IsPresent())\n        {\n            request.Raw[OidcConstants.AuthorizeRequest.AcrValues] = acr_values;\n        }\n        else\n        {\n            request.Raw.Remove(OidcConstants.AuthorizeRequest.AcrValues);\n        }\n    }\n\n    public static void AddAcrValue(this ValidatedAuthorizeRequest request, string value)\n    {\n        if (String.IsNullOrWhiteSpace(value)) throw new ArgumentNullException(nameof(value));\n\n        request.AuthenticationContextReferenceClasses.Add(value);\n        var acr_values = request.AuthenticationContextReferenceClasses.ToSpaceSeparatedString();\n        request.Raw[OidcConstants.AuthorizeRequest.AcrValues] = acr_values;\n    }\n\n    public static string GenerateSessionStateValue(this ValidatedAuthorizeRequest request)\n    {\n        if (request == null) return null;\n        if (!request.IsOpenIdRequest) return null;\n        \n        if (request.SessionId == null) return null;\n\n        if (request.ClientId.IsMissing()) return null;\n        if (request.RedirectUri.IsMissing()) return null;\n\n        var clientId = request.ClientId;\n        var sessionId = request.SessionId;\n        var salt = CryptoRandom.CreateUniqueId(16, CryptoRandom.OutputFormat.Hex);\n\n        var uri = new Uri(request.RedirectUri);\n        var origin = uri.Scheme + \"://\" + uri.Host;\n        if (!uri.IsDefaultPort)\n        {\n            origin += \":\" + uri.Port;\n        }\n\n        var bytes = Encoding.UTF8.GetBytes(clientId + origin + sessionId + salt);\n        byte[] hash;\n\n        using (var sha = SHA256.Create())\n        {\n            hash = sha.ComputeHash(bytes);\n        }\n\n        return Base64Url.Encode(hash) + \".\" + salt;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Extensions/X509CertificateExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing JsonSerializer = System.Text.Json.JsonSerializer;\n\nnamespace IdentityServer8.Extensions;\n\n/// <summary>\n/// Extensions methods for X509Certificate2\n/// </summary>\npublic static class X509CertificateExtensions\n{\n    /// <summary>\n    /// Create the value of a thumbprint-based cnf claim\n    /// </summary>\n    /// <param name=\"certificate\"></param>\n    /// <returns></returns>\n    public static string CreateThumbprintCnf(this X509Certificate2 certificate)\n    {\n        var hash = certificate.GetCertHash(HashAlgorithmName.SHA256);\n                        \n        var values = new Dictionary<string, string>\n        {\n            { \"x5t#S256\", Base64Url.Encode(hash) }\n        };\n\n        return JsonSerializer.Serialize(values);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8;\nglobal using IdentityServer8.Configuration;\nglobal using IdentityServer8.Configuration.DependencyInjection;\nglobal using IdentityServer8.Endpoints;\nglobal using IdentityServer8.Endpoints.Results;\nglobal using IdentityServer8.Events;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Hosting;\nglobal using IdentityServer8.Hosting.FederatedSignOut;\nglobal using IdentityServer8.Hosting.LocalApiAuthentication;\nglobal using IdentityServer8.Infrastructure;\nglobal using IdentityServer8.Logging;\nglobal using IdentityServer8.Logging.Models;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.ResponseHandling;\nglobal using IdentityServer8.Services;\nglobal using IdentityServer8.Services.Default;\nglobal using IdentityServer8.Stores;\nglobal using IdentityServer8.Stores.Serialization;\nglobal using IdentityServer8.Test;\nglobal using IdentityServer8.Validation;\nglobal using Microsoft.AspNetCore.Authentication;\nglobal using Microsoft.AspNetCore.Authentication.Cookies;\nglobal using Microsoft.AspNetCore.Authentication.OpenIdConnect;\nglobal using Microsoft.AspNetCore.Builder;\nglobal using Microsoft.AspNetCore.Cors.Infrastructure;\n//global using Microsoft.AspNetCore.DataProtection;\nglobal using Microsoft.AspNetCore.Http;\nglobal using Microsoft.AspNetCore.WebUtilities;\nglobal using Microsoft.Extensions.Caching.Distributed;\nglobal using Microsoft.Extensions.Caching.Memory;\nglobal using Microsoft.Extensions.Configuration;\nglobal using Microsoft.Extensions.DependencyInjection;\nglobal using Microsoft.Extensions.DependencyInjection.Extensions;\nglobal using Microsoft.Extensions.Logging;\nglobal using Microsoft.Extensions.Options;\nglobal using Microsoft.Extensions.Primitives;\n//global using Microsoft.IdentityModel.Tokens;\n//global using Microsoft.Net.Http.Headers;\nglobal using Newtonsoft.Json;\nglobal using Newtonsoft.Json.Linq;\nglobal using System.Buffers;\nglobal using System.Collections.Concurrent;\nglobal using System.Collections.Specialized;\nglobal using System.Diagnostics;\nglobal using System.Globalization;\nglobal using System.IdentityModel.Tokens.Jwt;\nglobal using System.Net;\nglobal using System.Reflection;\nglobal using System.Runtime.CompilerServices;\nglobal using System.Security.Claims;\nglobal using System.Security.Cryptography;\nglobal using System.Security.Cryptography.X509Certificates;\nglobal using System.Security.Principal;\nglobal using System.Text;\nglobal using System.Text.Encodings.Web;\nglobal using System.Text.Json;\nglobal using System.Text.Json.Serialization;\nglobal using static IdentityServer8.Constants;\nglobal using static IdentityServer8.IdentityServerConstants;\nglobal using ClaimValueTypes = System.Security.Claims.ClaimValueTypes;\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/BaseUrlMiddleware.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Hosting;\n\npublic class BaseUrlMiddleware\n{\n    private readonly RequestDelegate _next;\n    private readonly IdentityServerOptions _options;\n\n    public BaseUrlMiddleware(RequestDelegate next, IdentityServerOptions options)\n    {\n        _next = next;\n        _options = options;\n    }\n\n    public async Task Invoke(HttpContext context)\n    {\n        var request = context.Request;\n        \n        context.SetIdentityServerBasePath(request.PathBase.Value.RemoveTrailingSlash());\n\n        await _next(context);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/CorsMiddleware.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Hosting;\n\npublic static class CorsMiddlewareExtensions\n{\n    public static void ConfigureCors(this IApplicationBuilder app)\n    {\n        var options = app.ApplicationServices.GetRequiredService<IdentityServerOptions>();\n        app.UseCors(options.Cors.CorsPolicyName);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/CorsPolicyProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting;\n\ninternal class CorsPolicyProvider : ICorsPolicyProvider\n{\n    private readonly ILogger _logger;\n    private readonly ICorsPolicyProvider _inner;\n    private readonly IdentityServerOptions _options;\n    private readonly IHttpContextAccessor _httpContext;\n\n    public CorsPolicyProvider(\n        ILogger<CorsPolicyProvider> logger,\n        Decorator<ICorsPolicyProvider> inner,\n        IdentityServerOptions options,\n        IHttpContextAccessor httpContext)\n    {\n        _logger = logger;\n        _inner = inner.Instance;\n        _options = options;\n        _httpContext = httpContext;\n    }\n\n    public Task<CorsPolicy> GetPolicyAsync(HttpContext context, string policyName)\n    {\n        if (_options.Cors.CorsPolicyName == policyName)\n        {\n            return ProcessAsync(context);\n        }\n        else\n        {\n            return _inner.GetPolicyAsync(context, policyName);\n        }\n    }\n    private async Task<CorsPolicy> ProcessAsync(HttpContext context)\n    {\n        var origin = context.Request.GetCorsOrigin();\n        if (origin != null)\n        {\n            var path = context.Request.Path;\n            if (IsPathAllowed(path))\n            {\n                var sanitizedOrigin = origin.SanitizeForLog();\n                _logger.LogDebug(\"CORS request made for path: {path} from origin: {origin}\", path.SanitizeForLog(), sanitizedOrigin);\n\n                // manually resolving this from DI because this: \n                // https://github.com/aspnet/CORS/issues/105\n                var corsPolicyService = _httpContext.HttpContext.RequestServices.GetRequiredService<ICorsPolicyService>();\n\n                if (await corsPolicyService.IsOriginAllowedAsync(origin))\n                {\n                    _logger.LogDebug(\"CorsPolicyService allowed origin: {origin}\", sanitizedOrigin);\n                    return Allow(origin);\n                }\n                else\n                {\n                    _logger.LogWarning(\"CorsPolicyService did not allow origin: {origin}\", sanitizedOrigin);\n                }\n            }\n            else\n            {\n                _logger.LogDebug(\"CORS request made for path: {path} from origin: {origin} but was ignored because path was not for an allowed IdentityServer CORS endpoint\", Ioc.Sanitizer.Log.Sanitize(path), Ioc.Sanitizer.Log.Sanitize(origin));\n            }\n        }\n\n        return null;\n    }\n\n    private CorsPolicy Allow(string origin)\n    {\n        var policyBuilder = new CorsPolicyBuilder()\n            .WithOrigins(origin)\n            .AllowAnyHeader()\n            .AllowAnyMethod();\n\n        if (_options.Cors.PreflightCacheDuration.HasValue)\n        {\n            policyBuilder.SetPreflightMaxAge(_options.Cors.PreflightCacheDuration.Value);\n        }\n\n        return policyBuilder.Build();\n    }\n\n    private bool IsPathAllowed(PathString path)\n    {\n        return _options.Cors.CorsPaths.Any(x => path == x);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/Endpoint.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\n\nnamespace IdentityServer8.Hosting;\n\npublic class Endpoint\n{\n    public Endpoint(string name, string path, Type handlerType)\n    {\n        Name = name;\n        Path = path;\n        Handler = handlerType;\n    }\n\n    /// <summary>\n    /// Gets or sets the name.\n    /// </summary>\n    /// <value>\n    /// The name.\n    /// </value>\n    public string Name { get; set; }\n\n    /// <summary>\n    /// Gets or sets the path.\n    /// </summary>\n    /// <value>\n    /// The path.\n    /// </value>\n    public PathString Path { get; set; }\n\n    /// <summary>\n    /// Gets or sets the handler.\n    /// </summary>\n    /// <value>\n    /// The handler.\n    /// </value>\n    public Type Handler { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/EndpointRouter.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting;\n\ninternal class EndpointRouter : IEndpointRouter\n{\n    private readonly IEnumerable<Endpoint> _endpoints;\n    private readonly IdentityServerOptions _options;\n    private readonly ILogger _logger;\n\n    public EndpointRouter(IEnumerable<Endpoint> endpoints, IdentityServerOptions options, ILogger<EndpointRouter> logger)\n    {\n        _endpoints = endpoints;\n        _options = options;\n        _logger = logger;\n    }\n\n    public IEndpointHandler Find(HttpContext context)\n    {\n        if (context == null) throw new ArgumentNullException(nameof(context));\n\n        foreach(var endpoint in _endpoints)\n        {\n            var path = endpoint.Path;\n            if (context.Request.Path.Equals(path, StringComparison.OrdinalIgnoreCase))\n            {\n                var endpointName = endpoint.Name;\n                _logger.LogDebug(\"Request path {path} matched to endpoint type {endpoint}\", Ioc.Sanitizer.Log.Sanitize(context.Request.Path), endpointName);\n\n                return GetEndpointHandler(endpoint, context);\n            }\n        }\n\n        _logger.LogTrace(\"No endpoint entry found for request path: {path}\", Ioc.Sanitizer.Log.Sanitize(context.Request.Path));\n\n        return null;\n    }\n\n    private IEndpointHandler GetEndpointHandler(Endpoint endpoint, HttpContext context)\n    {\n        if (_options.Endpoints.IsEndpointEnabled(endpoint))\n        {\n            if (context.RequestServices.GetService(endpoint.Handler) is IEndpointHandler handler)\n            {\n                _logger.LogDebug(\"Endpoint enabled: {endpoint}, successfully created handler: {endpointHandler}\", endpoint.Name, endpoint.Handler.FullName);\n                return handler;\n            }\n\n            _logger.LogDebug(\"Endpoint enabled: {endpoint}, failed to create handler: {endpointHandler}\", endpoint.Name, endpoint.Handler.FullName);\n        }\n        else\n        {\n            _logger.LogWarning(\"Endpoint disabled: {endpoint}\", endpoint.Name);\n        }\n\n        return null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/FederatedSignOut/AuthenticationRequestHandlerWrapper.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting.FederatedSignOut;\n\ninternal class AuthenticationRequestHandlerWrapper : IAuthenticationRequestHandler\n{\n    private const string IframeHtml = \"<iframe style='display:none' width='0' height='0' src='{0}'></iframe>\";\n\n    private readonly IAuthenticationRequestHandler _inner;\n    private readonly HttpContext _context;\n    private readonly ILogger _logger;\n\n    public AuthenticationRequestHandlerWrapper(IAuthenticationRequestHandler inner, IHttpContextAccessor httpContextAccessor)\n    {\n        _inner = inner;\n        _context = httpContextAccessor.HttpContext;\n\n        var factory = (ILoggerFactory)_context.RequestServices.GetService(typeof(ILoggerFactory));\n        _logger = factory?.CreateLogger(GetType());\n    }\n\n    public Task InitializeAsync(AuthenticationScheme scheme, HttpContext context)\n    {\n        return _inner.InitializeAsync(scheme, context);\n    }\n\n    public async Task<bool> HandleRequestAsync()\n    {\n        var result = await _inner.HandleRequestAsync();\n\n        if (result && _context.GetSignOutCalled() && _context.Response.StatusCode == 200)\n        {\n            // given that this runs prior to the authentication middleware running\n            // we need to explicitly trigger authentication so we can have our \n            // session service populated with the current user info\n            await _context.AuthenticateAsync();\n\n            // now we can do our processing to render the iframe (if needed)\n            await ProcessFederatedSignOutRequestAsync();\n        }\n\n        return result;\n    }\n\n    public Task<AuthenticateResult> AuthenticateAsync()\n    {\n        return _inner.AuthenticateAsync();\n    }\n\n    public Task ChallengeAsync(AuthenticationProperties properties)\n    {\n        return _inner.ChallengeAsync(properties);\n    }\n\n    public Task ForbidAsync(AuthenticationProperties properties)\n    {\n        return _inner.ForbidAsync(properties);\n    }\n\n    private async Task ProcessFederatedSignOutRequestAsync()\n    {\n        _logger?.LogDebug(\"Processing federated signout\");\n\n        var iframeUrl = await _context.GetIdentityServerSignoutFrameCallbackUrlAsync();\n        if (iframeUrl != null)\n        {\n            _logger?.LogDebug(\"Rendering signout callback iframe\");\n            await RenderResponseAsync(iframeUrl);\n        }\n        else\n        {\n            _logger?.LogDebug(\"No signout callback iframe to render\");\n        }\n    }\n\n    private async Task RenderResponseAsync(string iframeUrl)\n    {\n        _context.Response.SetNoCache();\n\n        if (_context.Response.Body.CanWrite)\n        {\n            var iframe = String.Format(IframeHtml, iframeUrl);\n            _context.Response.ContentType = \"text/html\";\n            await _context.Response.WriteAsync(iframe);\n            await _context.Response.Body.FlushAsync();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/FederatedSignOut/AuthenticationRequestSignInHandlerWrapper.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting.FederatedSignOut;\n\ninternal class AuthenticationRequestSignInHandlerWrapper : AuthenticationRequestSignOutHandlerWrapper, IAuthenticationSignInHandler\n{\n    private readonly IAuthenticationSignInHandler _inner;\n\n    public AuthenticationRequestSignInHandlerWrapper(IAuthenticationSignInHandler inner, IHttpContextAccessor httpContextAccessor)\n        : base(inner, httpContextAccessor)\n    {\n        _inner = inner;\n    }\n\n    public Task SignInAsync(ClaimsPrincipal user, AuthenticationProperties properties)\n    {\n        return _inner.SignInAsync(user, properties);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/FederatedSignOut/AuthenticationRequestSignOutHandlerWrapper.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting.FederatedSignOut;\n\ninternal class AuthenticationRequestSignOutHandlerWrapper : AuthenticationRequestHandlerWrapper, IAuthenticationSignOutHandler\n{\n    private readonly IAuthenticationSignOutHandler _inner;\n\n    public AuthenticationRequestSignOutHandlerWrapper(IAuthenticationSignOutHandler inner, IHttpContextAccessor httpContextAccessor)\n        : base((IAuthenticationRequestHandler)inner, httpContextAccessor)\n    {\n        _inner = inner;\n    }\n\n    public Task SignOutAsync(AuthenticationProperties properties)\n    {\n        return _inner.SignOutAsync(properties);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/FederatedSignOut/FederatedSignoutAuthenticationHandlerProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting.FederatedSignOut;\n\n// this intercepts IAuthenticationRequestHandler authentication handlers\n// to detect when they are handling federated signout. when they are invoked,\n// call signout on the default authentication scheme, and return 200 then \n// we assume they are handling the federated signout in an iframe. \n// based on this assumption, we then render our federated signout iframes \n// to any current clients.\ninternal class FederatedSignoutAuthenticationHandlerProvider : IAuthenticationHandlerProvider\n{\n    private readonly IAuthenticationHandlerProvider _provider;\n    private readonly IHttpContextAccessor _httpContextAccessor;\n\n    public FederatedSignoutAuthenticationHandlerProvider(\n        Decorator<IAuthenticationHandlerProvider> decorator, \n        IHttpContextAccessor httpContextAccessor)\n    {\n        _provider = decorator.Instance;\n        _httpContextAccessor = httpContextAccessor;\n    }\n\n    public async Task<IAuthenticationHandler> GetHandlerAsync(HttpContext context, string authenticationScheme)\n    {\n        var handler = await _provider.GetHandlerAsync(context, authenticationScheme);\n        if (handler is IAuthenticationRequestHandler requestHandler)\n        {\n            if (requestHandler is IAuthenticationSignInHandler signinHandler)\n            {\n                return new AuthenticationRequestSignInHandlerWrapper(signinHandler, _httpContextAccessor);\n            }\n\n            if (requestHandler is IAuthenticationSignOutHandler signoutHandler)\n            {\n                return new AuthenticationRequestSignOutHandlerWrapper(signoutHandler, _httpContextAccessor);\n            }\n\n            return new AuthenticationRequestHandlerWrapper(requestHandler, _httpContextAccessor);\n        }\n\n        return handler;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/IEndpointHandler.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting;\n\n/// <summary>\n/// Endpoint handler\n/// </summary>\npublic interface IEndpointHandler\n{\n    /// <summary>\n    /// Processes the request.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    Task<IEndpointResult> ProcessAsync(HttpContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/IEndpointResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting;\n\n/// <summary>\n/// Endpoint result\n/// </summary>\npublic interface IEndpointResult\n{\n    /// <summary>\n    /// Executes the result.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    Task ExecuteAsync(HttpContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/IEndpointRouter.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting;\n\n/// <summary>\n/// The endpoint router\n/// </summary>\npublic interface IEndpointRouter\n{\n    /// <summary>\n    /// Finds a matching endpoint.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    IEndpointHandler Find(HttpContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/IdentityServerAuthenticationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting;\n\n// this decorates the real authentication service to detect when the \n// user is being signed in. this allows us to ensure the user has\n// the claims needed for identity server to do its job. it also allows\n// us to track signin/signout so we can issue/remove the session id\n// cookie used for check session iframe for session management spec.\n// finally, we track if signout is called to collaborate with the \n// FederatedSignoutAuthenticationHandlerProvider for federated signout.\ninternal class IdentityServerAuthenticationService : IAuthenticationService\n{\n    private readonly IAuthenticationService _inner;\n    private readonly IAuthenticationSchemeProvider _schemes;\n    private readonly ISystemClock _clock;\n    private readonly IUserSession _session;\n    private readonly IBackChannelLogoutService _backChannelLogoutService;\n    private readonly IdentityServerOptions _options;\n    private readonly ILogger<IdentityServerAuthenticationService> _logger;\n\n    public IdentityServerAuthenticationService(\n        Decorator<IAuthenticationService> decorator,\n        IAuthenticationSchemeProvider schemes,\n        ISystemClock clock,\n        IUserSession session,\n        IBackChannelLogoutService backChannelLogoutService,\n        IdentityServerOptions options,\n        ILogger<IdentityServerAuthenticationService> logger)\n    {\n        _inner = decorator.Instance;\n        \n        _schemes = schemes;\n        _clock = clock;\n        _session = session;\n        _backChannelLogoutService = backChannelLogoutService;\n        _options = options;\n        _logger = logger;\n    }\n\n    public async Task SignInAsync(HttpContext context, string scheme, ClaimsPrincipal principal, AuthenticationProperties properties)\n    {\n        var defaultScheme = await _schemes.GetDefaultSignInSchemeAsync();\n        var cookieScheme = await context.GetCookieAuthenticationSchemeAsync();\n\n        if ((scheme == null && defaultScheme?.Name == cookieScheme) || scheme == cookieScheme)\n        {\n            AugmentPrincipal(principal);\n\n            properties ??= new AuthenticationProperties();\n            await _session.CreateSessionIdAsync(principal, properties);\n        }\n\n        await _inner.SignInAsync(context, scheme, principal, properties);\n    }\n\n    private void AugmentPrincipal(ClaimsPrincipal principal)\n    {\n        _logger.LogDebug(\"Augmenting SignInContext\");\n\n        AssertRequiredClaims(principal);\n        AugmentMissingClaims(principal, _clock.UtcNow.UtcDateTime);\n    }\n\n    public async Task SignOutAsync(HttpContext context, string scheme, AuthenticationProperties properties)\n    {\n        var defaultScheme = await _schemes.GetDefaultSignOutSchemeAsync();\n        var cookieScheme = await context.GetCookieAuthenticationSchemeAsync();\n\n        if ((scheme == null && defaultScheme?.Name == cookieScheme) || scheme == cookieScheme)\n        {\n            // this sets a flag used by middleware to do post-signout work.\n            context.SetSignOutCalled();\n        }\n\n        await _inner.SignOutAsync(context, scheme, properties);\n    }\n\n    public Task<AuthenticateResult> AuthenticateAsync(HttpContext context, string scheme)\n    {\n        return _inner.AuthenticateAsync(context, scheme);\n    }\n\n    public Task ChallengeAsync(HttpContext context, string scheme, AuthenticationProperties properties)\n    {\n        return _inner.ChallengeAsync(context, scheme, properties);\n    }\n\n    public Task ForbidAsync(HttpContext context, string scheme, AuthenticationProperties properties)\n    {\n        return _inner.ForbidAsync(context, scheme, properties);\n    }\n\n    private void AssertRequiredClaims(ClaimsPrincipal principal)\n    {\n        // for now, we don't allow more than one identity in the principal/cookie\n        if (principal.Identities.Count() != 1) throw new InvalidOperationException(\"only a single identity supported\");\n        if (principal.FindFirst(JwtClaimTypes.Subject) == null) throw new InvalidOperationException(\"sub claim is missing\");\n    }\n\n    private void AugmentMissingClaims(ClaimsPrincipal principal, DateTime authTime)\n    {\n        var identity = principal.Identities.First();\n\n        // ASP.NET Identity issues this claim type and uses the authentication middleware name\n        // such as \"Google\" for the value. this code is trying to correct/convert that for\n        // our scenario. IOW, we take their old AuthenticationMethod value of \"Google\"\n        // and issue it as the idp claim. we then also issue a amr with \"external\"\n        var amr = identity.FindFirst(ClaimTypes.AuthenticationMethod);\n        if (amr != null &&\n            identity.FindFirst(JwtClaimTypes.IdentityProvider) == null &&\n            identity.FindFirst(JwtClaimTypes.AuthenticationMethod) == null)\n        {\n            _logger.LogDebug(\"Removing amr claim with value: {value}\", amr.Value);\n            identity.RemoveClaim(amr);\n\n            _logger.LogDebug(\"Adding idp claim with value: {value}\", amr.Value);\n            identity.AddClaim(new Claim(JwtClaimTypes.IdentityProvider, amr.Value));\n\n            _logger.LogDebug(\"Adding amr claim with value: {value}\", Constants.ExternalAuthenticationMethod);\n            identity.AddClaim(new Claim(JwtClaimTypes.AuthenticationMethod, Constants.ExternalAuthenticationMethod));\n        }\n\n        if (identity.FindFirst(JwtClaimTypes.IdentityProvider) == null)\n        {\n            _logger.LogDebug(\"Adding idp claim with value: {value}\", IdentityServerConstants.LocalIdentityProvider);\n            identity.AddClaim(new Claim(JwtClaimTypes.IdentityProvider, IdentityServerConstants.LocalIdentityProvider));\n        }\n\n        if (identity.FindFirst(JwtClaimTypes.AuthenticationMethod) == null)\n        {\n            if (identity.FindFirst(JwtClaimTypes.IdentityProvider).Value == IdentityServerConstants.LocalIdentityProvider)\n            {\n                _logger.LogDebug(\"Adding amr claim with value: {value}\", OidcConstants.AuthenticationMethods.Password);\n                identity.AddClaim(new Claim(JwtClaimTypes.AuthenticationMethod, OidcConstants.AuthenticationMethods.Password));\n            }\n            else\n            {\n                _logger.LogDebug(\"Adding amr claim with value: {value}\", Constants.ExternalAuthenticationMethod);\n                identity.AddClaim(new Claim(JwtClaimTypes.AuthenticationMethod, Constants.ExternalAuthenticationMethod));\n            }\n        }\n\n        if (identity.FindFirst(JwtClaimTypes.AuthenticationTime) == null)\n        {\n            var time = new DateTimeOffset(authTime).ToUnixTimeSeconds().ToString();\n\n            _logger.LogDebug(\"Adding auth_time claim with value: {value}\", time);\n            identity.AddClaim(new Claim(JwtClaimTypes.AuthenticationTime, time, ClaimValueTypes.Integer64));\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/IdentityServerMiddleware.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting;\n\n/// <summary>\n/// IdentityServer middleware\n/// </summary>\npublic class IdentityServerMiddleware\n{\n    private readonly RequestDelegate _next;\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IdentityServerMiddleware\"/> class.\n    /// </summary>\n    /// <param name=\"next\">The next.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public IdentityServerMiddleware(RequestDelegate next, ILogger<IdentityServerMiddleware> logger)\n    {\n        _next = next;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Invokes the middleware.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <param name=\"router\">The router.</param>\n    /// <param name=\"session\">The user session.</param>\n    /// <param name=\"events\">The event service.</param>\n    /// <param name=\"backChannelLogoutService\"></param>\n    /// <returns></returns>\n    public async Task Invoke(HttpContext context, IEndpointRouter router, IUserSession session, IEventService events, IBackChannelLogoutService backChannelLogoutService)\n    {\n        // this will check the authentication session and from it emit the check session\n        // cookie needed from JS-based signout clients.\n        await session.EnsureSessionIdCookieAsync();\n\n        context.Response.OnStarting(async () =>\n        {\n            if (context.GetSignOutCalled())\n            {\n                _logger.LogDebug(\"SignOutCalled set; processing post-signout session cleanup.\");\n\n                // this clears our session id cookie so JS clients can detect the user has signed out\n                await session.RemoveSessionIdCookieAsync();\n\n                // back channel logout\n                var logoutContext = await session.GetLogoutNotificationContext();\n                if (logoutContext != null)\n                {\n                    await backChannelLogoutService.SendLogoutNotificationsAsync(logoutContext);\n                }\n            }\n        });\n\n        try\n        {\n            var endpoint = router.Find(context);\n            if (endpoint != null)\n            {\n                _logger.LogInformation(\"Invoking IdentityServer endpoint: {endpointType} for {url}\", endpoint.GetType().FullName, context.Request.Path.ToString());\n\n                var result = await endpoint.ProcessAsync(context);\n\n                if (result != null)\n                {\n                    _logger.LogTrace(\"Invoking result: {type}\", result.GetType().FullName);\n                    await result.ExecuteAsync(context);\n                }\n\n                return;\n            }\n        }\n        catch (Exception ex)\n        {\n            await events.RaiseAsync(new UnhandledExceptionEvent(ex));\n            _logger.LogCritical(ex, \"Unhandled exception: {exception}\", ex.Message);\n            throw;\n        }\n\n        await _next(context);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/LocalApiAuthentication/LocalApiAuthenticationEvents.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting.LocalApiAuthentication;\n\n/// <summary>\n/// Events for local API authentication\n/// </summary>\npublic class LocalApiAuthenticationEvents\n{\n    /// <summary>\n    /// Invoked after the security token has passed validation and a ClaimsIdentity has been generated.\n    /// </summary>\n    public Func<ClaimsTransformationContext, Task> OnClaimsTransformation { get; set; } = context => Task.CompletedTask;\n\n    /// <summary>\n    /// Invoked after the security token has passed validation and a ClaimsIdentity has been generated.\n    /// </summary>\n    public virtual Task ClaimsTransformation(ClaimsTransformationContext context) => OnClaimsTransformation(context);\n\n}\n\n/// <summary>\n/// Context class for local API claims transformation\n/// </summary>\npublic class ClaimsTransformationContext\n{\n    /// <summary>\n    /// The principal\n    /// </summary>\n    public ClaimsPrincipal Principal { get; set; }\n\n    /// <summary>\n    /// the HTTP context\n    /// </summary>\n    public HttpContext HttpContext { get; internal set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/LocalApiAuthentication/LocalApiAuthenticationExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// Extensions for registering the local access token authentication handler\n/// </summary>\npublic static class LocalApiAuthenticationExtensions\n{\n    /// <summary>\n    /// Adds support for local APIs\n    /// </summary>\n    /// <param name=\"services\">The service collection</param>\n    /// <param name=\"transformationFunc\">Function to transform the resulting principal</param>\n    /// <returns></returns>\n    public static IServiceCollection AddLocalApiAuthentication(this IServiceCollection services, Func<ClaimsPrincipal, Task<ClaimsPrincipal>> transformationFunc = null)\n    {\n        services.AddAuthentication()\n            .AddLocalApi(options =>\n            {\n                options.ExpectedScope = IdentityServerConstants.LocalApi.ScopeName;\n\n                if (transformationFunc != null)\n                {\n                    options.Events = new LocalApiAuthenticationEvents\n                    {\n                        OnClaimsTransformation = async e =>\n                        {\n                            e.Principal = await transformationFunc(e.Principal);\n                        }\n                    };\n                }\n            });\n\n        services.AddAuthorization(options =>\n        {\n            options.AddPolicy(IdentityServerConstants.LocalApi.PolicyName, policy =>\n            {\n                policy.AddAuthenticationSchemes(IdentityServerConstants.LocalApi.AuthenticationScheme);\n                policy.RequireAuthenticatedUser();\n            });\n        });\n\n        return services;\n    }\n\n    /// <summary>\n    /// Registers the authentication handler for local APIs.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <returns></returns>\n    public static AuthenticationBuilder AddLocalApi(this AuthenticationBuilder builder)\n        => builder.AddLocalApi(IdentityServerConstants.LocalApi.AuthenticationScheme, _ => { });\n\n    /// <summary>\n    /// Registers the authentication handler for local APIs.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"configureOptions\">The configure options.</param>\n    /// <returns></returns>\n    public static AuthenticationBuilder AddLocalApi(this AuthenticationBuilder builder, Action<LocalApiAuthenticationOptions> configureOptions)\n        => builder.AddLocalApi(IdentityServerConstants.LocalApi.AuthenticationScheme, configureOptions);\n\n    /// <summary>\n    /// Registers the authentication handler for local APIs.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"authenticationScheme\">The authentication scheme.</param>\n    /// <param name=\"configureOptions\">The configure options.</param>\n    /// <returns></returns>\n    public static AuthenticationBuilder AddLocalApi(this AuthenticationBuilder builder, string authenticationScheme, Action<LocalApiAuthenticationOptions> configureOptions)\n        => builder.AddLocalApi(authenticationScheme, displayName: null, configureOptions: configureOptions);\n\n    /// <summary>\n    /// Registers the authentication handler for local APIs.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"authenticationScheme\">The authentication scheme.</param>\n    /// <param name=\"displayName\">The display name of this scheme.</param>\n    /// <param name=\"configureOptions\">The configure options.</param>\n    /// <returns></returns>\n    public static AuthenticationBuilder AddLocalApi(this AuthenticationBuilder builder, string authenticationScheme, string displayName, Action<LocalApiAuthenticationOptions> configureOptions)\n    {\n        return builder.AddScheme<LocalApiAuthenticationOptions, LocalApiAuthenticationHandler>(authenticationScheme, displayName, configureOptions);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/LocalApiAuthentication/LocalApiAuthenticationHandler.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting.LocalApiAuthentication;\n\n/// <summary>\n/// Authentication handler for validating access token from the local IdentityServer\n/// </summary>\npublic class LocalApiAuthenticationHandler : AuthenticationHandler<LocalApiAuthenticationOptions>\n{\n    private readonly ITokenValidator _tokenValidator;\n    private readonly ILogger _logger;\n\n    /// <inheritdoc />\n    public LocalApiAuthenticationHandler(IOptionsMonitor<LocalApiAuthenticationOptions> options, ILoggerFactory logger, UrlEncoder encoder, ISystemClock clock, ITokenValidator tokenValidator)\n        : base(options, logger, encoder, clock)\n    {\n        _tokenValidator = tokenValidator;\n        _logger = logger.CreateLogger<LocalApiAuthenticationHandler>();\n    }\n\n    /// <summary>\n    /// The handler calls methods on the events which give the application control at certain points where processing is occurring. \n    /// If it is not provided a default instance is supplied which does nothing when the methods are called.\n    /// </summary>\n    protected new LocalApiAuthenticationEvents Events\n    {\n        get => (LocalApiAuthenticationEvents)base.Events;\n        set => base.Events = value;\n    }\n\n    /// <inheritdoc/>\n    protected override Task<object> CreateEventsAsync() => Task.FromResult<object>(new LocalApiAuthenticationEvents());\n\n    /// <inheritdoc />\n    protected override async Task<AuthenticateResult> HandleAuthenticateAsync()\n    {\n        _logger.LogTrace(\"HandleAuthenticateAsync called\");\n\n        string token = null;\n\n        string authorization = Request.Headers[\"Authorization\"];\n\n        if (string.IsNullOrEmpty(authorization))\n        {\n            return AuthenticateResult.NoResult();\n        }\n\n        if (authorization.StartsWith(\"Bearer \", StringComparison.OrdinalIgnoreCase))\n        {\n            token = authorization.Substring(\"Bearer \".Length).Trim();\n        }\n\n        if (string.IsNullOrEmpty(token))\n        {\n            return AuthenticateResult.Fail(\"No Access Token is sent.\");\n        }\n\n        _logger.LogTrace(\"Token found: {token}\", Ioc.Sanitizer.Log.Sanitize(token));\n\n        TokenValidationResult result = await _tokenValidator.ValidateAccessTokenAsync(token, Options.ExpectedScope);\n\n        if (result.IsError)\n        {\n            _logger.LogTrace(\"Failed to validate the token\");\n\n            return AuthenticateResult.Fail(result.Error);\n        }\n\n        _logger.LogTrace(\"Successfully validated the token.\");\n\n        ClaimsIdentity claimsIdentity = new ClaimsIdentity(result.Claims, Scheme.Name, JwtClaimTypes.Name, JwtClaimTypes.Role);\n        ClaimsPrincipal claimsPrincipal = new ClaimsPrincipal(claimsIdentity);\n        AuthenticationProperties authenticationProperties = new AuthenticationProperties();\n\n        if (Options.SaveToken)\n        {\n            authenticationProperties.StoreTokens(new[]\n            {\n                new AuthenticationToken { Name = \"access_token\", Value = token }\n            });\n        }\n\n        var claimsTransformationContext = new ClaimsTransformationContext\n        {\n            Principal = claimsPrincipal,\n            HttpContext = Context\n        };\n\n        await Events.ClaimsTransformation(claimsTransformationContext);\n\n        AuthenticationTicket authenticationTicket = new AuthenticationTicket(claimsTransformationContext.Principal, authenticationProperties, Scheme.Name);\n        return AuthenticateResult.Success(authenticationTicket);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/LocalApiAuthentication/LocalApiAuthenticationOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting.LocalApiAuthentication;\n\n/// <summary>\n/// Options for local API authentication\n/// </summary>\n/// <seealso cref=\"Microsoft.AspNetCore.Authentication.AuthenticationSchemeOptions\" />\npublic class LocalApiAuthenticationOptions : AuthenticationSchemeOptions\n{\n    /// <summary>\n    /// Allows setting a specific required scope (optional)\n    /// </summary>\n    public string ExpectedScope { get; set; }\n\n    /// <summary>\n    /// Specifies whether the token should be saved in the authentication properties\n    /// </summary>\n    public bool SaveToken { get; set; } = true;\n\n    /// <summary>\n    /// Allows implementing events\n    /// </summary>\n    public new LocalApiAuthenticationEvents Events\n    {\n        get { return (LocalApiAuthenticationEvents)base.Events; }\n        set { base.Events = value; }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Hosting/MutualTlsEndpointMiddleware.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Hosting;\n\n/// <summary>\n///     Middleware for re-writing the MTLS enabled endpoints to the standard protocol endpoints\n/// </summary>\npublic class MutualTlsEndpointMiddleware\n{\n    private readonly ILogger<MutualTlsEndpointMiddleware> _logger;\n    private readonly RequestDelegate _next;\n    private readonly IdentityServerOptions _options;\n\n    /// <summary>\n    ///     ctor\n    /// </summary>\n    /// <param name=\"next\"></param>\n    /// <param name=\"options\"></param>\n    /// <param name=\"logger\"></param>\n    public MutualTlsEndpointMiddleware(RequestDelegate next, IdentityServerOptions options,\n        ILogger<MutualTlsEndpointMiddleware> logger)\n    {\n        _next = next;\n        _options = options;\n        _logger = logger;\n    }\n\n    /// <inheritdoc />\n    public async Task Invoke(HttpContext context, IAuthenticationSchemeProvider schemes)\n    {\n        if (_options.MutualTls.Enabled)\n        {\n            // domain-based MTLS\n            if (_options.MutualTls.DomainName.IsPresent())\n            {\n                // separate domain\n                if (_options.MutualTls.DomainName.Contains(\".\"))\n                {\n                    if (context.Request.Host.Host.Equals(_options.MutualTls.DomainName,\n                        StringComparison.OrdinalIgnoreCase))\n                    {\n                        var result = await TriggerCertificateAuthentication(context);\n                        if (!result.Succeeded)\n                        {\n                            return;\n                        }\n                    }\n                }\n                // sub-domain\n                else\n                {\n                    if (context.Request.Host.Host.StartsWith(_options.MutualTls.DomainName + \".\", StringComparison.OrdinalIgnoreCase))\n                    {\n                        var result = await TriggerCertificateAuthentication(context);\n                        if (!result.Succeeded)\n                        {\n                            return;\n                        }\n                    }\n                }\n            }\n            // path based MTLS\n            else if (context.Request.Path.StartsWithSegments(Constants.ProtocolRoutePaths.MtlsPathPrefix.EnsureLeadingSlash(), out var subPath))\n            {\n                var result = await TriggerCertificateAuthentication(context);\n\n                if (result.Succeeded)\n                {\n                    var path = Constants.ProtocolRoutePaths.ConnectPathPrefix +\n                               subPath.ToString().EnsureLeadingSlash();\n                    path = path.EnsureLeadingSlash();\n\n                    _logger.LogDebug(\"Rewriting MTLS request from: {oldPath} to: {newPath}\",\n                        context.Request.Path.ToString(), path);\n                    context.Request.Path = path;\n                }\n                else\n                {\n                    return;\n                }\n            }\n        }\n        \n        await _next(context);\n    }\n\n    private async Task<AuthenticateResult> TriggerCertificateAuthentication(HttpContext context)\n    {\n        var x509AuthResult =\n            await context.AuthenticateAsync(_options.MutualTls.ClientCertificateAuthenticationScheme);\n\n        if (!x509AuthResult.Succeeded)\n        {\n            _logger.LogDebug(\"MTLS authentication failed, error: {error}.\",\n                x509AuthResult.Failure?.Message);\n            await context.ForbidAsync(_options.MutualTls.ClientCertificateAuthenticationScheme);\n        }\n\n        return x509AuthResult;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/IdentityServer8.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n    <PropertyGroup>\n        <IsPackable>true</IsPackable>\n        <GeneratePackageOnBuild>true</GeneratePackageOnBuild>\n    </PropertyGroup>\n\n    <PropertyGroup>\n        <ContinuousIntegrationBuild Condition=\"'$(TF_BUILD)' == 'true'\">True</ContinuousIntegrationBuild>\n        <ContinuousIntegrationBuild Condition=\"'$(GITHUB_ACTIONS)' == 'true'\">True</ContinuousIntegrationBuild>\n    </PropertyGroup>\n\n    <ItemGroup>\n        <PackageReference Include=\"IdentityModel\" />\n        <PackageReference Include=\"Microsoft.IdentityModel.Protocols.OpenIdConnect\" />\n        <PackageReference Include=\"Microsoft.AspNetCore.Authentication.OpenIdConnect\" />\n    </ItemGroup>\n\n    <ItemGroup>\n        <ProjectReference Include=\"..\\..\\Security\\IdentityServer8.Security\\IdentityServer8.Security.csproj\" />\n        <ProjectReference Include=\"..\\..\\Storage\\src\\IdentityServer8.Storage.csproj\" />\n    </ItemGroup>\n</Project>"
  },
  {
    "path": "src/IdentityServer8/src/IdentityServerConstants.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8;\n\npublic static class IdentityServerConstants\n{\n    public const string LocalIdentityProvider = \"local\";\n    public const string DefaultCookieAuthenticationScheme = \"idsrv\";\n    public const string SignoutScheme = \"idsrv\";\n    public const string ExternalCookieAuthenticationScheme = \"idsrv.external\";\n    public const string DefaultCheckSessionCookieName = \"idsrv.session\";\n    public const string AccessTokenAudience = \"{0}resources\";\n\n    public const string JwtRequestClientKey = \"idsrv.jwtrequesturi.client\";\n\n    /// <summary>\n    /// Constants for local IdentityServer access token authentication.\n    /// </summary>\n    public static class LocalApi\n    {\n        /// <summary>\n        /// The authentication scheme when using the AddLocalApi helper.\n        /// </summary>\n        public const string AuthenticationScheme = \"IdentityServerAccessToken\";\n\n        /// <summary>\n        /// The API scope name when using the AddLocalApiAuthentication helper.\n        /// </summary>\n        public const string ScopeName = \"IdentityServerApi\";\n\n        /// <summary>\n        /// The authorization policy name when using the AddLocalApiAuthentication helper.\n        /// </summary>\n        public const string PolicyName = AuthenticationScheme;\n    }\n\n    public static class ProtocolTypes\n    {\n        public const string OpenIdConnect = \"oidc\";\n        public const string WsFederation = \"wsfed\";\n        public const string Saml2p = \"saml2p\";\n    }\n\n    public static class TokenTypes\n    {\n        public const string IdentityToken = \"id_token\";\n        public const string AccessToken = \"access_token\";\n    }\n\n    public static class ClaimValueTypes\n    {\n        public const string Json = \"json\";\n    }\n\n    public static class ParsedSecretTypes\n    {\n        public const string NoSecret = \"NoSecret\";\n        public const string SharedSecret = \"SharedSecret\";\n        public const string X509Certificate = \"X509Certificate\";\n        public const string JwtBearer = \"urn:ietf:params:oauth:client-assertion-type:jwt-bearer\";\n    }\n\n    public static class SecretTypes\n    {\n        public const string SharedSecret = \"SharedSecret\";\n        public const string X509CertificateThumbprint = \"X509Thumbprint\";\n        public const string X509CertificateName = \"X509Name\";\n        public const string X509CertificateBase64 = \"X509CertificateBase64\";\n        public const string JsonWebKey = \"JWK\";\n    }\n\n    public static class ProfileDataCallers\n    {\n        public const string UserInfoEndpoint = \"UserInfoEndpoint\";\n        public const string ClaimsProviderIdentityToken = \"ClaimsProviderIdentityToken\";\n        public const string ClaimsProviderAccessToken = \"ClaimsProviderAccessToken\";\n    }\n\n    public static class ProfileIsActiveCallers\n    {\n        public const string AuthorizeEndpoint = \"AuthorizeEndpoint\";\n        public const string IdentityTokenValidation = \"IdentityTokenValidation\";\n        public const string AccessTokenValidation = \"AccessTokenValidation\";\n        public const string ResourceOwnerValidation = \"ResourceOwnerValidation\";\n        public const string ExtensionGrantValidation = \"ExtensionGrantValidation\";\n        public const string RefreshTokenValidation = \"RefreshTokenValidation\";\n        public const string AuthorizationCodeValidation = \"AuthorizationCodeValidation\";\n        public const string UserInfoRequestValidation = \"UserInfoRequestValidation\";\n        public const string DeviceCodeValidation = \"DeviceCodeValidation\";\n    }\n\n    public static IEnumerable<string> SupportedSigningAlgorithms = new List<string>\n    {\n        SecurityAlgorithms.RsaSha256,\n        SecurityAlgorithms.RsaSha384,\n        SecurityAlgorithms.RsaSha512,\n\n        SecurityAlgorithms.RsaSsaPssSha256,\n        SecurityAlgorithms.RsaSsaPssSha384,\n        SecurityAlgorithms.RsaSsaPssSha512,\n\n        SecurityAlgorithms.EcdsaSha256,\n        SecurityAlgorithms.EcdsaSha384,\n        SecurityAlgorithms.EcdsaSha512\n    };\n\n    public enum RsaSigningAlgorithm\n    {\n        RS256,\n        RS384,\n        RS512,\n\n        PS256,\n        PS384,\n        PS512\n    }\n\n    public enum ECDsaSigningAlgorithm\n    {\n        ES256,\n        ES384,\n        ES512\n    }\n\n    public static class StandardScopes\n    {\n        /// <summary>REQUIRED. Informs the Authorization Server that the Client is making an OpenID Connect request. If the <c>openid</c> scope value is not present, the behavior is entirely unspecified.</summary>\n        public const string OpenId = \"openid\";\n        /// <summary>OPTIONAL. This scope value requests access to the End-User's default profile Claims, which are: <c>name</c>, <c>family_name</c>, <c>given_name</c>, <c>middle_name</c>, <c>nickname</c>, <c>preferred_username</c>, <c>profile</c>, <c>picture</c>, <c>website</c>, <c>gender</c>, <c>birthdate</c>, <c>zoneinfo</c>, <c>locale</c>, and <c>updated_at</c>.</summary>\n        public const string Profile = \"profile\";\n        /// <summary>OPTIONAL. This scope value requests access to the <c>email</c> and <c>email_verified</c> Claims.</summary>\n        public const string Email = \"email\";\n        /// <summary>OPTIONAL. This scope value requests access to the <c>address</c> Claim.</summary>\n        public const string Address = \"address\";\n        /// <summary>OPTIONAL. This scope value requests access to the <c>phone_number</c> and <c>phone_number_verified</c> Claims.</summary>\n        public const string Phone = \"phone\";\n        /// <summary>This scope value MUST NOT be used with the OpenID Connect Implicit Client Implementer's Guide 1.0. See the OpenID Connect Basic Client Implementer's Guide 1.0 (http://openid.net/specs/openid-connect-implicit-1_0.html#OpenID.Basic) for its usage in that subset of OpenID Connect.</summary>\n        public const string OfflineAccess = \"offline_access\";\n    }\n\n    public static class PersistedGrantTypes\n    {\n        public const string AuthorizationCode = \"authorization_code\";\n        public const string ReferenceToken = \"reference_token\";\n        public const string RefreshToken = \"refresh_token\";\n        public const string UserConsent = \"user_consent\";\n        public const string DeviceCode = \"device_code\";\n        public const string UserCode = \"user_code\";\n    }\n\n    public static class UserCodeTypes\n    {\n        public const string Numeric = \"Numeric\";\n    }\n\n    public static class HttpClients\n    {\n        public const int DefaultTimeoutSeconds = 10;\n        public const string JwtRequestUriHttpClient = \"IdentityServer:JwtRequestUriClient\";\n        public const string BackChannelLogoutHttpClient = \"IdentityServer:BackChannelLogoutClient\";\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/IdentityServerTools.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8;\n\n/// <summary>\n/// Class for useful helpers for interacting with IdentityServer\n/// </summary>\npublic class IdentityServerTools\n{\n    internal readonly IHttpContextAccessor ContextAccessor;\n    private readonly ITokenCreationService _tokenCreation;\n    private readonly ISystemClock _clock;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IdentityServerTools\" /> class.\n    /// </summary>\n    /// <param name=\"contextAccessor\">The context accessor.</param>\n    /// <param name=\"tokenCreation\">The token creation service.</param>\n    /// <param name=\"clock\">The clock.</param>\n    public IdentityServerTools(IHttpContextAccessor contextAccessor, ITokenCreationService tokenCreation, ISystemClock clock)\n    {\n        ContextAccessor = contextAccessor;\n        _tokenCreation = tokenCreation;\n        _clock = clock;\n    }\n\n    /// <summary>\n    /// Issues a JWT.\n    /// </summary>\n    /// <param name=\"lifetime\">The lifetime.</param>\n    /// <param name=\"claims\">The claims.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.ArgumentNullException\">claims</exception>\n    public virtual async Task<string> IssueJwtAsync(int lifetime, IEnumerable<Claim> claims)\n    {\n        if (claims == null) throw new ArgumentNullException(nameof(claims));\n\n        var issuer = ContextAccessor.HttpContext.GetIdentityServerIssuerUri();\n\n        var token = new Token\n        {\n            CreationTime = _clock.UtcNow.UtcDateTime,\n            Issuer = issuer,\n            Lifetime = lifetime,\n\n            Claims = new HashSet<Claim>(claims, new ClaimComparer())\n        };\n\n        return await _tokenCreation.CreateTokenAsync(token);\n    }\n\n    /// <summary>\n    /// Issues a JWT.\n    /// </summary>\n    /// <param name=\"lifetime\">The lifetime.</param>\n    /// <param name=\"issuer\">The issuer.</param>\n    /// <param name=\"claims\">The claims.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.ArgumentNullException\">claims</exception>\n    public virtual async Task<string> IssueJwtAsync(int lifetime, string issuer, IEnumerable<Claim> claims)\n    {\n        if (String.IsNullOrWhiteSpace(issuer)) throw new ArgumentNullException(nameof(issuer));\n        if (claims == null) throw new ArgumentNullException(nameof(claims));\n\n        var token = new Token\n        {\n            CreationTime = _clock.UtcNow.UtcDateTime,\n            Issuer = issuer,\n            Lifetime = lifetime,\n\n            Claims = new HashSet<Claim>(claims, new ClaimComparer())\n        };\n\n        return await _tokenCreation.CreateTokenAsync(token);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/IdentityServerUser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8;\n\n/// <summary>\n/// Model properties of an IdentityServer user\n/// </summary>\npublic class IdentityServerUser\n{\n    /// <summary>\n    /// Subject ID (mandatory)\n    /// </summary>\n    public string SubjectId { get; }\n\n    /// <summary>\n    /// Display name (optional)\n    /// </summary>\n    public string DisplayName { get; set; }\n\n    /// <summary>\n    /// Identity provider (optional)\n    /// </summary>\n    public string IdentityProvider { get; set; }\n\n    /// <summary>\n    /// Authentication methods\n    /// </summary>\n    public ICollection<string> AuthenticationMethods { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Authentication time\n    /// </summary>\n    public DateTime? AuthenticationTime { get; set; }\n\n    /// <summary>\n    /// Additional claims\n    /// </summary>\n    public ICollection<Claim> AdditionalClaims { get; set; } = new HashSet<Claim>(new ClaimComparer());\n\n    /// <summary>\n    /// Initializes a user identity\n    /// </summary>\n    /// <param name=\"subjectId\">The subject ID</param>\n    public IdentityServerUser(string subjectId)\n    {\n        if (subjectId.IsMissing()) throw new ArgumentException(\"SubjectId is mandatory\", nameof(subjectId));\n\n        SubjectId = subjectId;\n    }\n\n    /// <summary>\n    /// Creates an IdentityServer claims principal\n    /// </summary>\n    /// <returns></returns>\n    /// <exception cref=\"ArgumentNullException\"></exception>\n    public ClaimsPrincipal CreatePrincipal()\n    {\n        if (SubjectId.IsMissing()) throw new ArgumentException(\"SubjectId is mandatory\", nameof(SubjectId));\n        var claims = new List<Claim> { new Claim(JwtClaimTypes.Subject, SubjectId) };\n\n        if (DisplayName.IsPresent())\n        {\n            claims.Add(new Claim(JwtClaimTypes.Name, DisplayName));\n        }\n\n        if (IdentityProvider.IsPresent())\n        {\n            claims.Add(new Claim(JwtClaimTypes.IdentityProvider, IdentityProvider));\n        }\n\n        if (AuthenticationTime.HasValue)\n        {\n            claims.Add(new Claim(JwtClaimTypes.AuthenticationTime, new DateTimeOffset(AuthenticationTime.Value).ToUnixTimeSeconds().ToString()));\n        }\n\n        if (AuthenticationMethods.Any())\n        {\n            foreach (var amr in AuthenticationMethods)\n            {\n                claims.Add(new Claim(JwtClaimTypes.AuthenticationMethod, amr));\n            }\n        }\n\n        claims.AddRange(AdditionalClaims);\n\n        var id = new ClaimsIdentity(claims.Distinct(new ClaimComparer()), Constants.IdentityServerAuthenticationType, JwtClaimTypes.Name, JwtClaimTypes.Role);\n        return new ClaimsPrincipal(id);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Infrastructure/DistributedCacheStateDataFormatter.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore.DataProtection;\n\nnamespace IdentityServer8.Infrastructure;\n\n/// <summary>\n/// State formatter using IDistributedCache\n/// </summary>\npublic class DistributedCacheStateDataFormatter : ISecureDataFormat<AuthenticationProperties>\n{\n    private readonly IHttpContextAccessor _httpContext;\n    private readonly string _name;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DistributedCacheStateDataFormatter\"/> class.\n    /// </summary>\n    /// <param name=\"httpContext\">The HTTP context accessor.</param>\n    /// <param name=\"name\">The scheme name.</param>\n    public DistributedCacheStateDataFormatter(IHttpContextAccessor httpContext, string name)\n    {\n        _httpContext = httpContext;\n        _name = name;\n    }\n\n    private string CacheKeyPrefix => \"DistributedCacheStateDataFormatter\";\n\n    private IDistributedCache Cache => _httpContext.HttpContext.RequestServices.GetRequiredService<IDistributedCache>();\n    private IDataProtector Protector => _httpContext.HttpContext.RequestServices.GetRequiredService<IDataProtectionProvider>().CreateProtector(CacheKeyPrefix, _name);\n\n    /// <summary>\n    /// Protects the specified data.\n    /// </summary>\n    /// <param name=\"data\">The data.</param>\n    /// <returns></returns>\n    public string Protect(AuthenticationProperties data)\n    {\n        return Protect(data, null);\n    }\n\n    /// <summary>\n    /// Protects the specified data.\n    /// </summary>\n    /// <param name=\"data\">The data.</param>\n    /// <param name=\"purpose\">The purpose.</param>\n    /// <returns></returns>\n    public string Protect(AuthenticationProperties data, string purpose)\n    {\n        var key = Guid.NewGuid().ToString();\n        var cacheKey = $\"{CacheKeyPrefix}-{_name}-{purpose}-{key}\";\n        var json = ObjectSerializer.ToString(data.Items);\n\n        var options = new DistributedCacheEntryOptions();\n        if (data.ExpiresUtc.HasValue)\n        {\n            options.SetAbsoluteExpiration(data.ExpiresUtc.Value);\n        }\n        else\n        {\n            options.SetSlidingExpiration(Constants.DefaultCacheDuration);\n        }\n        \n        // Rather than encrypt the full AuthenticationProperties\n        // cache the data and encrypt the key that points to the data\n        Cache.SetString(cacheKey, json, options);\n\n        return Protector.Protect(key);\n    }\n\n    /// <summary>\n    /// Unprotects the specified protected text.\n    /// </summary>\n    /// <param name=\"protectedText\">The protected text.</param>\n    /// <returns></returns>\n    public AuthenticationProperties Unprotect(string protectedText)\n    {\n        return Unprotect(protectedText, null);\n    }\n\n    /// <summary>\n    /// Unprotects the specified protected text.\n    /// </summary>\n    /// <param name=\"protectedText\">The protected text.</param>\n    /// <param name=\"purpose\">The purpose.</param>\n    /// <returns></returns>\n    public AuthenticationProperties Unprotect(string protectedText, string purpose)\n    {\n        if (String.IsNullOrWhiteSpace(protectedText))\n        {\n            return null;\n        }\n\n        // Decrypt the key and retrieve the data from the cache.\n        var key = Protector.Unprotect(protectedText);\n        var cacheKey = $\"{CacheKeyPrefix}-{_name}-{purpose}-{key}\";\n        var json = Cache.GetString(cacheKey);\n\n        if (json == null)\n        {\n            return null;\n        }\n\n        var items = ObjectSerializer.FromString<Dictionary<string, string>>(json);\n        var props = new AuthenticationProperties(items);\n        return props;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Infrastructure/MessageCookie.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore.DataProtection;\n\nnamespace IdentityServer8;\n\ninternal class MessageCookie<TModel>\n{\n    private readonly ILogger _logger;\n    private readonly IdentityServerOptions _options;\n    private readonly IHttpContextAccessor _context;\n    private readonly IDataProtector _protector;\n\n    public MessageCookie(\n        ILogger<MessageCookie<TModel>> logger, \n        IdentityServerOptions options,\n        IHttpContextAccessor context, \n        IDataProtectionProvider provider)\n    {\n        _logger = logger;\n        _options = options;\n        _context = context;\n        _protector = provider.CreateProtector(MessageType);\n    }\n\n    private string MessageType => typeof(TModel).Name;\n\n    private string Protect(Message<TModel> message)\n    {\n        var json = ObjectSerializer.ToString(message);\n        _logger.LogTrace(\"Protecting message: {0}\", json);\n\n        return _protector.Protect(json);\n    }\n\n    private Message<TModel> Unprotect(string data)\n    {\n        var json = _protector.Unprotect(data);\n        var message = ObjectSerializer.FromString<Message<TModel>>(json);\n        return message;\n    }\n\n    private string CookiePrefix => MessageType + \".\";\n\n    private string GetCookieFullName(string id)\n    {\n        return CookiePrefix + id;\n    }\n\n    private string CookiePath => _context.HttpContext.GetIdentityServerBasePath().CleanUrlPath();\n\n    private IEnumerable<string> GetCookieNames()\n    {\n        var key = CookiePrefix;\n        foreach ((string name, var _) in _context.HttpContext.Request.Cookies)\n        {\n            if (name.StartsWith(key))\n            {\n                yield return name;\n            }\n        }\n    }\n\n    private bool Secure => _context.HttpContext.Request.IsHttps;\n\n    public void Write(string id, Message<TModel> message)\n    {\n        ClearOverflow();\n\n        if (message == null) throw new ArgumentNullException(nameof(message));\n\n        var name = GetCookieFullName(id);\n        var data = Protect(message);\n\n        _context.HttpContext.Response.Cookies.Append(\n            name,\n            data,\n            new CookieOptions\n            {\n                HttpOnly = true,\n                Secure = Secure,\n                Path = CookiePath,\n                IsEssential = true\n                // don't need to set same-site since cookie is expected to be sent\n                // to only another page in this host. \n            });\n    }\n\n    public Message<TModel> Read(string id)\n    {\n        if (id.IsMissing()) return null;\n\n        var name = GetCookieFullName(id);\n        return ReadByCookieName(name);\n    }\n\n    private Message<TModel> ReadByCookieName(string name)\n    {\n        var data = _context.HttpContext.Request.Cookies[name];\n        if (data.IsPresent())\n        {\n            try\n            {\n                return Unprotect(data);\n            }\n            catch(Exception ex)\n            {\n                _logger.LogError(ex, \"Error unprotecting message cookie\");\n                ClearByCookieName(name);\n            }\n        }\n        return null;\n    }\n\n    protected internal void Clear(string id)\n    {\n        var name = GetCookieFullName(id);\n        ClearByCookieName(name);\n    }\n\n    private void ClearByCookieName(string name)\n    {\n        _context.HttpContext.Response.Cookies.Append(\n            name,\n            \".\",\n            new CookieOptions\n            {\n                Expires = new DateTime(2000, 1, 1),\n                HttpOnly = true,\n                Secure = Secure,\n                Path = CookiePath,\n                IsEssential = true\n            });\n    }\n\n    private long GetCookieRank(string name)\n    {   \n        // empty and invalid cookies are considered to be the oldest:\n        var rank = DateTime.MinValue.Ticks;\n\n        try\n        {\n            var message = ReadByCookieName(name);\n            if (message != null)\n            {\n                // valid cookies are ranked based on their creation time:\n                rank = message.Created;\n            }\n        }\n        catch (CryptographicException e)\n        {   \n            // cookie was protected with a different key/algorithm\n            _logger.LogDebug(e, \"Unable to unprotect cookie {0}\", name);\n        }\n        \n        return rank;\n    }\n\n    private void ClearOverflow()\n    {\n        var names = GetCookieNames();\n        var toKeep = _options.UserInteraction.CookieMessageThreshold;\n\n        if (names.Count() >= toKeep)\n        {\n            var rankedCookieNames =\n                from name in names\n                let rank = GetCookieRank(name)\n                orderby rank descending\n                select name;\n\n            var purge = rankedCookieNames.Skip(Math.Max(0, toKeep - 1));\n            foreach (var name in purge)\n            {\n                _logger.LogTrace(\"Purging stale cookie: {cookieName}\", name);\n                ClearByCookieName(name);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Infrastructure/ObjectSerializer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing JsonSerializer = System.Text.Json.JsonSerializer;\n\nnamespace IdentityServer8;\n\ninternal static class ObjectSerializer\n{\n    private static readonly JsonSerializerOptions Options = new JsonSerializerOptions\n    {\n        IgnoreNullValues = true\n    };\n    \n    public static string ToString(object o)\n    {\n        return JsonSerializer.Serialize(o, Options);\n    }\n\n    public static T FromString<T>(string value)\n    {\n        return JsonSerializer.Deserialize<T>(value, Options);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Logging/LogSerializer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing JsonSerializer = System.Text.Json.JsonSerializer;\n\nnamespace IdentityServer8.Logging;\n\n/// <summary>\n/// Helper to JSON serialize object data for logging.\n/// </summary>\ninternal static class LogSerializer\n{\n    static readonly JsonSerializerOptions Options = new JsonSerializerOptions\n    {\n        IgnoreNullValues = true,\n        WriteIndented = true\n    };\n\n    static LogSerializer()\n    {\n        Options.Converters.Add(new JsonStringEnumConverter());\n    }\n\n    /// <summary>\n    /// Serializes the specified object.\n    /// </summary>\n    /// <param name=\"logObject\">The object.</param>\n    /// <returns></returns>\n    public static string Serialize(object logObject)\n    {\n        return JsonSerializer.Serialize(logObject, Options);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Logging/Models/AuthorizeRequestValidationLog.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Logging.Models;\n\ninternal class AuthorizeRequestValidationLog\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string RedirectUri { get; set; }\n    public IEnumerable<string> AllowedRedirectUris { get; set; }\n    public string SubjectId { get; set; }\n\n    public string ResponseType { get; set; }\n    public string ResponseMode { get; set; }\n    public string GrantType { get; set; }\n    public string RequestedScopes { get; set; }\n\n    public string State { get; set; }\n    public string UiLocales { get; set; }\n    public string Nonce { get; set; }\n    public IEnumerable<string> AuthenticationContextReferenceClasses { get; set; }\n    public string DisplayMode { get; set; }\n    public string PromptMode { get; set; }\n    public int? MaxAge { get; set; }\n    public string LoginHint { get; set; }\n    public string SessionId { get; set; }\n\n    public Dictionary<string, string> Raw { get; set; }\n\n    public AuthorizeRequestValidationLog(ValidatedAuthorizeRequest request, IEnumerable<string> sensitiveValuesFilter)\n    {\n        Raw = request.Raw.ToScrubbedDictionary(sensitiveValuesFilter.ToArray());\n\n        if (request.Client != null)\n        {\n            ClientId = request.Client.ClientId;\n            ClientName = request.Client.ClientName;\n\n            AllowedRedirectUris = request.Client.RedirectUris;\n        }\n\n        if (request.Subject != null)\n        {\n            var subjectClaim = request.Subject.FindFirst(JwtClaimTypes.Subject);\n            if (subjectClaim != null)\n            {\n                SubjectId = subjectClaim.Value;\n            }\n            else\n            {\n                SubjectId = \"anonymous\";\n            }\n        }\n\n        if (request.AuthenticationContextReferenceClasses.Any())\n        {\n            AuthenticationContextReferenceClasses = request.AuthenticationContextReferenceClasses;\n        }\n\n        RedirectUri = request.RedirectUri;\n        ResponseType = request.ResponseType;\n        ResponseMode = request.ResponseMode;\n        GrantType = request.GrantType;\n        RequestedScopes = request.RequestedScopes.ToSpaceSeparatedString();\n        State = request.State;\n        UiLocales = request.UiLocales;\n        Nonce = request.Nonce;\n\n        DisplayMode = request.DisplayMode;\n        PromptMode = request.PromptModes.ToSpaceSeparatedString();\n        LoginHint = request.LoginHint;\n        MaxAge = request.MaxAge;\n        SessionId = request.SessionId;\n    }\n\n    public override string ToString()\n    {\n        return LogSerializer.Serialize(this);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Logging/Models/AuthorizeResponseLog.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Logging.Models;\n\ninternal class AuthorizeResponseLog\n{\n    public string SubjectId { get; set; }\n    public string ClientId { get; set; }\n    public string RedirectUri { get; set; }\n    public string State { get; set; }\n\n    public string Scope { get; set; }\n    public string Error { get; set; }\n    public string ErrorDescription { get; set; }\n\n\n    public AuthorizeResponseLog(AuthorizeResponse response)\n    {\n        ClientId = response.Request?.Client?.ClientId;\n        SubjectId = response.Request?.Subject?.GetSubjectId();\n        RedirectUri = response.RedirectUri;\n        State = response.State;\n        Scope = response.Scope;\n        Error = response.Error;\n        ErrorDescription = response.ErrorDescription;\n    }\n\n    public override string ToString()\n    {\n        return LogSerializer.Serialize(this);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Logging/Models/DeviceAuthorizationRequestValidationLog.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Logging;\n\ninternal class DeviceAuthorizationRequestValidationLog\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string Scopes { get; set; }\n\n    public Dictionary<string, string> Raw { get; set; }\n\n    private static readonly string[] SensitiveValuesFilter = {\n        OidcConstants.TokenRequest.ClientSecret,\n        OidcConstants.TokenRequest.ClientAssertion\n    };\n\n    public DeviceAuthorizationRequestValidationLog(ValidatedDeviceAuthorizationRequest request)\n    {\n        Raw = request.Raw.ToScrubbedDictionary(SensitiveValuesFilter);\n\n        if (request.Client != null)\n        {\n            ClientId = request.Client.ClientId;\n            ClientName = request.Client.ClientName;\n        }\n\n        if (request.RequestedScopes != null)\n        {\n            Scopes = request.RequestedScopes.ToSpaceSeparatedString();\n        }\n    }\n\n    public override string ToString()\n    {\n        return LogSerializer.Serialize(this);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Logging/Models/EndSessionRequestValidationLog.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Logging.Models;\n\ninternal class EndSessionRequestValidationLog\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string SubjectId { get; set; }\n\n    public string PostLogOutUri { get; set; }\n    public string State { get; set; }\n\n    public Dictionary<string, string> Raw { get; set; }\n\n    public EndSessionRequestValidationLog(ValidatedEndSessionRequest request)\n    {\n        Raw = request.Raw.ToScrubbedDictionary(OidcConstants.EndSessionRequest.IdTokenHint);\n\n        SubjectId = \"unknown\";\n        \n        var subjectClaim = request.Subject?.FindFirst(JwtClaimTypes.Subject);\n        if (subjectClaim != null)\n        {\n            SubjectId = subjectClaim.Value;\n        }\n\n        if (request.Client != null)\n        {\n            ClientId = request.Client.ClientId;\n            ClientName = request.Client.ClientName;\n        }\n\n        PostLogOutUri = request.PostLogOutUri;\n        State = request.State;\n    }\n\n    public override string ToString()\n    {\n        return LogSerializer.Serialize(this);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Logging/Models/TokenRequestValidationLog.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Logging.Models;\n\ninternal class TokenRequestValidationLog\n{\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public string GrantType { get; set; }\n    public string Scopes { get; set; }\n\n    public string AuthorizationCode { get; set; }\n    public string RefreshToken { get; set; }\n\n    public string UserName { get; set; }\n    public IEnumerable<string> AuthenticationContextReferenceClasses { get; set; }\n    public string Tenant { get; set; }\n    public string IdP { get; set; }\n\n    public Dictionary<string, string> Raw { get; set; }\n\n    public TokenRequestValidationLog(ValidatedTokenRequest request, IEnumerable<string> sensitiveValuesFilter)\n    {\n        Raw = request.Raw.ToScrubbedDictionary(sensitiveValuesFilter.ToArray());\n\n        if (request.Client != null)\n        {\n            ClientId = request.Client.ClientId;\n            ClientName = request.Client.ClientName;\n        }\n\n        if (request.RequestedScopes != null)\n        {\n            Scopes = request.RequestedScopes.ToSpaceSeparatedString();\n        }\n\n        GrantType = request.GrantType;\n        AuthorizationCode = request.AuthorizationCodeHandle.Obfuscate();\n        RefreshToken = request.RefreshTokenHandle.Obfuscate();\n        UserName = request.UserName;\n    }\n\n    public override string ToString()\n    {\n        return LogSerializer.Serialize(this);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Logging/Models/TokenValidationLog.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Logging.Models;\n\ninternal class TokenValidationLog\n{\n    // identity token\n    public string ClientId { get; set; }\n    public string ClientName { get; set; }\n    public bool ValidateLifetime { get; set; }\n\n    // access token\n    public string AccessTokenType { get; set; }\n    public string ExpectedScope { get; set; }\n    public string TokenHandle { get; set; }\n    public string JwtId { get; set; }\n\n    // both\n    public Dictionary<string, object> Claims { get; set; }\n\n    public override string ToString()\n    {\n        return LogSerializer.Serialize(this);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/Contexts/IsActiveContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Context describing the is-active check\n/// </summary>\npublic class IsActiveContext\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IsActiveContext\"/> class.\n    /// </summary>\n    public IsActiveContext(ClaimsPrincipal subject, Client client, string caller)\n    {\n        if (subject == null) throw new ArgumentNullException(nameof(subject));\n        if (client == null) throw new ArgumentNullException(nameof(client));\n        if (caller.IsMissing()) throw new ArgumentNullException(nameof(caller));\n\n        Subject = subject;\n        Client = client;\n        Caller = caller;\n        \n        IsActive = true;\n    }\n\n    /// <summary>\n    /// Gets or sets the subject.\n    /// </summary>\n    /// <value>\n    /// The subject.\n    /// </value>\n    public ClaimsPrincipal Subject { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client.\n    /// </summary>\n    /// <value>\n    /// The client.\n    /// </value>\n    public Client Client { get; set; }\n\n    /// <summary>\n    /// Gets or sets the caller.\n    /// </summary>\n    /// <value>\n    /// The caller.\n    /// </value>\n    public string Caller { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the subject is active and can recieve tokens.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if the subject is active; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsActive { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/Contexts/LogoutNotificationContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Provides the context necessary to construct a logout notificaiton.\n/// </summary>\npublic class LogoutNotificationContext\n{\n    /// <summary>\n    ///  The SubjectId of the user.\n    /// </summary>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// The session Id of the user's authentication session.\n    /// </summary>\n    public string SessionId { get; set; }\n\n    /// <summary>\n    /// The list of client Ids that the user has authenticated to.\n    /// </summary>\n    public IEnumerable<string> ClientIds { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/Contexts/ProfileDataRequestContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Class describing the profile data request\n/// </summary>\npublic class ProfileDataRequestContext\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ProfileDataRequestContext\"/> class.\n    /// </summary>\n    public ProfileDataRequestContext()\n    { }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ProfileDataRequestContext\" /> class.\n    /// </summary>\n    /// <param name=\"subject\">The subject.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <param name=\"caller\">The caller.</param>\n    /// <param name=\"requestedClaimTypes\">The requested claim types.</param>\n    public ProfileDataRequestContext(ClaimsPrincipal subject, Client client, string caller, IEnumerable<string> requestedClaimTypes)\n    {\n        Subject = subject ?? throw new ArgumentNullException(nameof(subject));\n        Client = client ?? throw new ArgumentNullException(nameof(client));\n        Caller = caller ?? throw new ArgumentNullException(nameof(caller));\n        RequestedClaimTypes = requestedClaimTypes ?? throw new ArgumentNullException(nameof(requestedClaimTypes));\n    }\n\n    /// <summary>\n    /// Gets or sets the validatedRequest.\n    /// </summary>\n    /// <value>\n    /// The validatedRequest.\n    /// </value>\n    public ValidatedRequest ValidatedRequest { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject.\n    /// </summary>\n    /// <value>\n    /// The subject.\n    /// </value>\n    public ClaimsPrincipal Subject { get; set; }\n\n    /// <summary>\n    /// Gets or sets the requested claim types.\n    /// </summary>\n    /// <value>\n    /// The requested claim types.\n    /// </value>\n    public IEnumerable<string> RequestedClaimTypes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client id.\n    /// </summary>\n    /// <value>\n    /// The client id.\n    /// </value>\n    public Client Client { get; set; }\n\n    /// <summary>\n    /// Gets or sets the caller.\n    /// </summary>\n    /// <value>\n    /// The caller.\n    /// </value>\n    public string Caller { get; set; }\n\n    /// <summary>\n    /// Gets or sets the requested resources (if available).\n    /// </summary>\n    /// <value>\n    /// The resources.\n    /// </value>\n    public ResourceValidationResult RequestedResources { get; set; }\n\n    /// <summary>\n    /// Gets or sets the issued claims.\n    /// </summary>\n    /// <value>\n    /// The issued claims.\n    /// </value>\n    public List<Claim> IssuedClaims { get; set; } = new List<Claim>();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/DeviceFlowAuthorizationRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Represents contextual information about a device flow authorization request.\n/// </summary>\npublic class DeviceFlowAuthorizationRequest\n{\n    /// <summary>\n    /// Gets or sets the client.\n    /// </summary>\n    /// <value>\n    /// The client.\n    /// </value>\n    public Client Client { get; set; }\n\n    /// <summary>\n    /// Gets or sets the validated resources.\n    /// </summary>\n    /// <value>\n    /// The scopes requested.\n    /// </value>\n    public ResourceValidationResult ValidatedResources { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/DeviceFlowInteractionResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Request object for device flow interaction\n/// </summary>\npublic class DeviceFlowInteractionResult\n{\n    /// <summary>\n    /// Gets or sets the error description.\n    /// </summary>\n    /// <value>\n    /// The error description.\n    /// </value>\n    public string ErrorDescription { get; private set; }\n\n    /// <summary>\n    /// Gets a value indicating whether this instance is error.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if this instance is error; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsError { get; private set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether this instance is access denied.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if this instance is access denied; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsAccessDenied { get; set; }\n\n    /// <summary>\n    /// Create failure result\n    /// </summary>\n    /// <param name=\"errorDescription\">The error description.</param>\n    /// <returns></returns>\n    public static DeviceFlowInteractionResult Failure(string errorDescription = null)\n    {\n        return new DeviceFlowInteractionResult\n        {\n            IsError = true,\n            ErrorDescription = errorDescription\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/DiscoveryDocument.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Models;\n\npublic class DiscoveryDocument\n{\n    public string issuer { get; set; }\n    public string jwks_uri { get; set; }\n    public string authorization_endpoint { get; set; }\n    public string token_endpoint { get; set; }\n    public string userinfo_endpoint { get; set; }\n    public string end_session_endpoint { get; set; }\n    public string check_session_iframe { get; set; }\n    public string revocation_endpoint { get; set; }\n    public string introspection_endpoint { get; set; }\n    public bool? frontchannel_logout_supported { get; set; }\n    public bool? frontchannel_logout_session_supported { get; set; }\n    public string[] scopes_supported { get; set; }\n    public string[] claims_supported { get; set; }\n    public string[] response_types_supported { get; set; }\n    public string[] response_modes_supported { get; set; }\n    public string[] grant_types_supported { get; set; }\n    public string[] subject_types_supported { get; set; }\n    public string[] id_token_signing_alg_values_supported { get; set; }\n    public string[] token_endpoint_auth_methods_supported { get; set; }\n    public string[] code_challenge_methods_supported { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/Grant.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models a grant the user has given.\n/// </summary>\npublic class Grant\n{\n    /// <summary>\n    /// Gets or sets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets the description the user assigned to the device being authorized.\n    /// </summary>\n    /// <value>\n    /// The description.\n    /// </value>\n    public string Description { get; set; }\n\n    /// <summary>\n    /// Gets or sets the scopes.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public IEnumerable<string> Scopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the creation time.\n    /// </summary>\n    /// <value>\n    /// The creation time.\n    /// </value>\n    public DateTime CreationTime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the expiration.\n    /// </summary>\n    /// <value>\n    /// The expiration.\n    /// </value>\n    public DateTime? Expiration { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/GrantTypes.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Models;\n\npublic class GrantTypes\n{\n    public static ICollection<string> Implicit =>\n        new[] { GrantType.Implicit };\n\n    public static ICollection<string> ImplicitAndClientCredentials =>\n        new[]  { GrantType.Implicit, GrantType.ClientCredentials };\n\n    public static ICollection<string> Code =>\n        new[] { GrantType.AuthorizationCode };\n\n    public static ICollection<string> CodeAndClientCredentials =>\n        new[] { GrantType.AuthorizationCode, GrantType.ClientCredentials };\n\n    public static ICollection<string> Hybrid =>\n        new[] { GrantType.Hybrid };\n\n    public static ICollection<string> HybridAndClientCredentials =>\n        new[] { GrantType.Hybrid, GrantType.ClientCredentials };\n\n    public static ICollection<string> ClientCredentials =>\n        new[] { GrantType.ClientCredentials };\n\n    public static ICollection<string> ResourceOwnerPassword =>\n        new[] { GrantType.ResourceOwnerPassword };\n\n    public static ICollection<string> ResourceOwnerPasswordAndClientCredentials =>\n        new[] { GrantType.ResourceOwnerPassword, GrantType.ClientCredentials };\n\n    public static ICollection<string> DeviceFlow =>\n        new[] { GrantType.DeviceFlow };\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/IdentityResources.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Convenience class that defines standard identity resources.\n/// </summary>\npublic static class IdentityResources\n{\n    /// <summary>\n    /// Models the standard openid scope\n    /// </summary>\n    /// <seealso cref=\"IdentityServer8.Models.IdentityResource\" />\n    public class OpenId : IdentityResource\n    {\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"OpenId\"/> class.\n        /// </summary>\n        public OpenId()\n        {\n            Name = IdentityServerConstants.StandardScopes.OpenId;\n            DisplayName = \"Your user identifier\";\n            Required = true;\n            UserClaims.Add(JwtClaimTypes.Subject);\n        }\n    }\n\n    /// <summary>\n    /// Models the standard profile scope\n    /// </summary>\n    /// <seealso cref=\"IdentityServer8.Models.IdentityResource\" />\n    public class Profile : IdentityResource\n    {\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"Profile\"/> class.\n        /// </summary>\n        public Profile()\n        {\n            Name = IdentityServerConstants.StandardScopes.Profile;\n            DisplayName = \"User profile\";\n            Description = \"Your user profile information (first name, last name, etc.)\";\n            Emphasize = true;\n            UserClaims = Constants.ScopeToClaimsMapping[IdentityServerConstants.StandardScopes.Profile].ToList();\n        }\n    }\n\n    /// <summary>\n    /// Models the standard email scope\n    /// </summary>\n    /// <seealso cref=\"IdentityServer8.Models.IdentityResource\" />\n    public class Email : IdentityResource\n    {\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"Email\"/> class.\n        /// </summary>\n        public Email()\n        {\n            Name = IdentityServerConstants.StandardScopes.Email;\n            DisplayName = \"Your email address\";\n            Emphasize = true;\n            UserClaims = (Constants.ScopeToClaimsMapping[IdentityServerConstants.StandardScopes.Email].ToList());\n        }\n    }\n\n    /// <summary>\n    /// Models the standard phone scope\n    /// </summary>\n    /// <seealso cref=\"IdentityServer8.Models.IdentityResource\" />\n    public class Phone : IdentityResource\n    {\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"Phone\"/> class.\n        /// </summary>\n        public Phone()\n        {\n            Name = IdentityServerConstants.StandardScopes.Phone;\n            DisplayName = \"Your phone number\";\n            Emphasize = true;\n            UserClaims = Constants.ScopeToClaimsMapping[IdentityServerConstants.StandardScopes.Phone].ToList();\n        }\n    }\n\n    /// <summary>\n    /// Models the standard address scope\n    /// </summary>\n    /// <seealso cref=\"IdentityServer8.Models.IdentityResource\" />\n    public class Address : IdentityResource\n    {\n        /// <summary>\n        /// Initializes a new instance of the <see cref=\"Address\"/> class.\n        /// </summary>\n        public Address()\n        {\n            Name = IdentityServerConstants.StandardScopes.Address;\n            DisplayName = \"Your postal address\";\n            Emphasize = true;\n            UserClaims = Constants.ScopeToClaimsMapping[IdentityServerConstants.StandardScopes.Address].ToList();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/JsonWebKey.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Models;\n\npublic class JsonWebKey\n{\n    public string kty { get; set; }\n    public string use { get; set; }\n    public string kid { get; set; }\n    public string x5t { get; set; }\n    public string e { get; set; }\n    public string n { get; set; }\n    public string[] x5c { get; set; }\n    public string alg { get; set; }\n\n    public string x { get; set; }\n    public string y { get; set; }\n    public string crv { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/Messages/AuthorizationRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Represents contextual information about a authorization request.\n/// </summary>\npublic class AuthorizationRequest\n{\n    /// <summary>\n    /// The client.\n    /// </summary>\n    public Client Client { get; set; }\n\n    /// <summary>\n    /// The display mode passed from the authorization request.\n    /// </summary>\n    /// <value>\n    /// The display mode.\n    /// </value>\n    public string DisplayMode { get; set; }\n\n    /// <summary>\n    /// Gets or sets the redirect URI.\n    /// </summary>\n    /// <value>\n    /// The redirect URI.\n    /// </value>\n    public string RedirectUri { get; set; }\n\n    /// <summary>\n    /// The UI locales passed from the authorization request.\n    /// </summary>\n    /// <value>\n    /// The UI locales.\n    /// </value>\n    public string UiLocales { get; set; }\n\n    /// <summary>\n    /// The external identity provider requested. This is used to bypass home realm \n    /// discovery (HRD). This is provided via the <c>\"idp:\"</c> prefix to the <c>acr</c> \n    /// parameter on the authorize request.\n    /// </summary>\n    /// <value>\n    /// The external identity provider identifier.\n    /// </value>\n    public string IdP { get; set; }\n\n    /// <summary>\n    /// The tenant requested. This is provided via the <c>\"tenant:\"</c> prefix to \n    /// the <c>acr</c> parameter on the authorize request.\n    /// </summary>\n    /// <value>\n    /// The tenant.\n    /// </value>\n    public string Tenant { get; set; }\n\n    /// <summary>\n    /// The expected username the user will use to login. This is requested from the client \n    /// via the <c>login_hint</c> parameter on the authorize request.\n    /// </summary>\n    /// <value>\n    /// The LoginHint.\n    /// </value>\n    public string LoginHint { get; set; }\n\n    /// <summary>\n    /// Gets or sets the collection of prompt modes.\n    /// </summary>\n    /// <value>\n    /// The collection of prompt modes.\n    /// </value>\n    public IEnumerable<string> PromptModes { get; set; } = Enumerable.Empty<string>();\n\n    /// <summary>\n    /// The acr values passed from the authorization request.\n    /// </summary>\n    /// <value>\n    /// The acr values.\n    /// </value>\n    public IEnumerable<string> AcrValues { get; set; }\n\n    /// <summary>\n    /// The validated resources.\n    /// </summary>\n    public ResourceValidationResult ValidatedResources { get; set; }\n\n    /// <summary>\n    /// Gets the entire parameter collection.\n    /// </summary>\n    /// <value>\n    /// The parameters.\n    /// </value>\n    public NameValueCollection Parameters { get; }\n\n    /// <summary>\n    /// Gets the validated contents of the request object (if present)\n    /// </summary>\n    /// <value>\n    /// The request object values\n    /// </value>\n    public Dictionary<string, string> RequestObjectValues { get; } = new Dictionary<string, string>();\n\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"AuthorizationRequest\"/> class.\n    /// </summary>\n    public AuthorizationRequest()\n    {\n        // public for testing\n        Parameters = new NameValueCollection();\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"AuthorizationRequest\"/> class.\n    /// </summary>\n    internal AuthorizationRequest(ValidatedAuthorizeRequest request)\n    {\n        Client = request.Client;\n        RedirectUri = request.RedirectUri;\n        DisplayMode = request.DisplayMode;\n        UiLocales = request.UiLocales;\n        IdP = request.GetIdP();\n        Tenant = request.GetTenant();\n        LoginHint = request.LoginHint;\n        PromptModes = request.PromptModes;\n        AcrValues = request.GetAcrValues();\n        ValidatedResources = request.ValidatedResources;\n        Parameters = request.Raw;\n        RequestObjectValues = request.RequestObjectValues;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/Messages/ConsentRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models the parameters to identify a request for consent.\n/// </summary>\npublic class ConsentRequest\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ConsentRequest\"/> class.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"subject\">The subject.</param>\n    public ConsentRequest(AuthorizationRequest request, string subject)\n    {\n        ClientId = request.Client.ClientId;\n        Nonce = request.Parameters[OidcConstants.AuthorizeRequest.Nonce];\n        ScopesRequested = request.Parameters[OidcConstants.AuthorizeRequest.Scope].ParseScopesString();\n        Subject = subject;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ConsentRequest\"/> class.\n    /// </summary>\n    /// <param name=\"parameters\">The parameters.</param>\n    /// <param name=\"subject\">The subject.</param>\n    public ConsentRequest(NameValueCollection parameters, string subject)\n    {\n        ClientId = parameters[OidcConstants.AuthorizeRequest.ClientId];\n        Nonce = parameters[OidcConstants.AuthorizeRequest.Nonce];\n        ScopesRequested = parameters[OidcConstants.AuthorizeRequest.Scope].ParseScopesString();\n        Subject = subject;\n    }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the nonce.\n    /// </summary>\n    /// <value>\n    /// The nonce.\n    /// </value>\n    public string Nonce { get; set; }\n\n    /// <summary>\n    /// Gets or sets the scopes requested.\n    /// </summary>\n    /// <value>\n    /// The scopes requested.\n    /// </value>\n    public IEnumerable<string> ScopesRequested { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject.\n    /// </summary>\n    /// <value>\n    /// The subject.\n    /// </value>\n    public string Subject { get; set; }\n\n    /// <summary>\n    /// Gets the identifier.\n    /// </summary>\n    /// <value>\n    /// The identifier.\n    /// </value>\n    public string Id\n    {\n        get\n        {\n            var normalizedScopes = ScopesRequested?.OrderBy(x => x).Distinct().Aggregate((x, y) => x + \",\" + y);\n            var value = $\"{ClientId}:{Subject}:{Nonce}:{normalizedScopes}\";\n\n            using (var sha = SHA256.Create())\n            {\n                var bytes = Encoding.UTF8.GetBytes(value);\n                var hash = sha.ComputeHash(bytes);\n\n                return Base64Url.Encode(hash);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/Messages/ConsentResponse.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models the user's response to the consent screen.\n/// </summary>\npublic class ConsentResponse\n{\n    /// <summary>\n    /// Error, if any, for the consent response.\n    /// </summary>\n    public AuthorizationError? Error { get; set; }\n\n    /// <summary>\n    /// Error description.\n    /// </summary>\n    public string ErrorDescription { get; set; }\n\n    /// <summary>\n    /// Gets if consent was granted.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if consent was granted; otherwise, <c>false</c>.\n    /// </value>\n    public bool Granted => ScopesValuesConsented != null && ScopesValuesConsented.Any() && Error == null;\n\n    /// <summary>\n    /// Gets or sets the scope values consented to.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public IEnumerable<string> ScopesValuesConsented { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the user wishes the consent to be remembered.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if consent is to be remembered; otherwise, <c>false</c>.\n    /// </value>\n    public bool RememberConsent { get; set; }\n\n    /// <summary>\n    /// Gets the description of the device.\n    /// </summary>\n    /// <value>\n    /// The description of the device.\n    /// </value>\n    public string Description { get; set; }\n}\n\n/// <summary>\n/// Enum to model interaction authorization errors.\n/// </summary>\npublic enum AuthorizationError\n{\n    /// <summary>\n    /// Access denied\n    /// </summary>\n    AccessDenied,\n\n    /// <summary>\n    /// Interaction required\n    /// </summary>\n    InteractionRequired,\n\n    /// <summary>\n    /// Login required\n    /// </summary>\n    LoginRequired,\n\n    /// <summary>\n    /// Account selection required\n    /// </summary>\n    AccountSelectionRequired,\n\n    /// <summary>\n    /// Consent required\n    /// </summary>\n    ConsentRequired\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/Messages/ErrorMessage.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models the data for the error page.\n/// </summary>\npublic class ErrorMessage\n{\n    /// <summary>\n    /// The display mode passed from the authorization request.\n    /// </summary>\n    /// <value>\n    /// The display mode.\n    /// </value>\n    public string DisplayMode { get; set; }\n\n    /// <summary>\n    /// The UI locales passed from the authorization request.\n    /// </summary>\n    /// <value>\n    /// The UI locales.\n    /// </value>\n    public string UiLocales { get; set; }\n\n    /// <summary>\n    /// Gets or sets the error code.\n    /// </summary>\n    /// <value>\n    /// The error code.\n    /// </value>\n    public string Error { get; set; }\n\n    /// <summary>\n    /// Gets or sets the error description.\n    /// </summary>\n    /// <value>\n    /// The error description.\n    /// </value>\n    public string ErrorDescription { get; set; }\n\n    /// <summary>\n    /// The per-request identifier. This can be used to display to the end user and can be used in diagnostics.\n    /// </summary>\n    /// <value>\n    /// The request identifier.\n    /// </value>\n    public string RequestId { get; set; }\n\n    /// <summary>\n    /// The redirect URI.\n    /// </summary>\n    public string RedirectUri { get; set; }\n    \n    /// <summary>\n    /// The response mode.\n    /// </summary>\n    public string ResponseMode { get; set; }\n\n    /// <summary>\n    /// The client id making the request (if available).\n    /// </summary>\n    public string ClientId { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/Messages/LogoutRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models the validated singout context.\n/// </summary>\npublic class LogoutMessage\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"LogoutMessage\"/> class.\n    /// </summary>\n    public LogoutMessage()\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"LogoutMessage\"/> class.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    public LogoutMessage(ValidatedEndSessionRequest request)\n    {\n        if (request != null)\n        {\n            if (request.Raw != null)\n            {\n                Parameters = request.Raw.ToFullDictionary();\n            }\n\n            // optimize params sent to logout page, since we'd like to send them in URL (not as cookie)\n            Parameters.Remove(OidcConstants.EndSessionRequest.IdTokenHint);\n            Parameters.Remove(OidcConstants.EndSessionRequest.PostLogoutRedirectUri);\n            Parameters.Remove(OidcConstants.EndSessionRequest.State);\n\n            ClientId = request.Client?.ClientId;\n            ClientName = request.Client?.ClientName;\n            SubjectId = request.Subject?.GetSubjectId();\n            SessionId = request.SessionId;\n            ClientIds = request.ClientIds;\n\n            if (request.PostLogOutUri != null)\n            {\n                PostLogoutRedirectUri = request.PostLogOutUri;\n                if (request.State != null)\n                {\n                    PostLogoutRedirectUri = PostLogoutRedirectUri.AddQueryString(OidcConstants.EndSessionRequest.State, request.State);\n                }\n            }\n        }\n    }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client name.\n    /// </summary>\n    public string ClientName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the post logout redirect URI.\n    /// </summary>\n    public string PostLogoutRedirectUri { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject identifier for the user at logout time.\n    /// </summary>\n    public string SubjectId { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the session identifier for the user at logout time.\n    /// </summary>\n    public string SessionId { get; set; }\n\n    /// <summary>\n    ///  Ids of clients known to have an authentication session for user at end session time\n    /// </summary>\n    public IEnumerable<string> ClientIds { get; set; }\n\n    /// <summary>\n    /// Gets the entire parameter collection.\n    /// </summary>\n    public IDictionary<string, string[]> Parameters { get; set; } = new Dictionary<string, string[]>();\n\n    /// <summary>\n    ///  Flag to indicate if the payload contains useful information or not to avoid serailization.\n    /// </summary>\n    internal bool ContainsPayload => ClientId.IsPresent() || ClientIds?.Any() == true;\n}\n\n/// <summary>\n/// Models the request from a client to sign the user out.\n/// </summary>\npublic class LogoutRequest\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"LogoutRequest\"/> class.\n    /// </summary>\n    /// <param name=\"iframeUrl\">The iframe URL.</param>\n    /// <param name=\"message\">The message.</param>\n    public LogoutRequest(string iframeUrl, LogoutMessage message)\n    {\n        if (message != null)\n        {\n            ClientId = message.ClientId;\n            ClientName = message.ClientName;\n            PostLogoutRedirectUri = message.PostLogoutRedirectUri;\n            SubjectId = message.SubjectId;\n            SessionId = message.SessionId;\n            ClientIds = message.ClientIds;\n            Parameters = message.Parameters.FromFullDictionary();\n        }\n\n        SignOutIFrameUrl = iframeUrl;\n    }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client name.\n    /// </summary>\n    public string ClientName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the post logout redirect URI.\n    /// </summary>\n    public string PostLogoutRedirectUri { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject identifier for the user at logout time.\n    /// </summary>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the session identifier for the user at logout time.\n    /// </summary>\n    public string SessionId { get; set; }\n\n    /// <summary>\n    ///  Ids of clients known to have an authentication session for user at end session time\n    /// </summary>\n    public IEnumerable<string> ClientIds { get; set; }\n\n    /// <summary>\n    /// Gets the entire parameter collection.\n    /// </summary>\n    public NameValueCollection Parameters { get; } = new NameValueCollection();\n\n    /// <summary>\n    /// Gets or sets the sign out iframe URL.\n    /// </summary>\n    /// <value>\n    /// The sign out iframe URL.\n    /// </value>\n    public string SignOutIFrameUrl { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the user should be prompted for signout.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if the signout prompt should be shown; otherwise, <c>false</c>.\n    /// </value>\n    public bool ShowSignoutPrompt => ClientId.IsMissing();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/Messages/Message.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Base class for data that needs to be written out as cookies.\n/// </summary>\npublic class Message<TModel>\n{\n    /// <summary>\n    /// Should only be used from unit tests\n    /// </summary>\n    /// <param name=\"data\"></param>\n    internal Message(TModel data) : this(data, DateTime.UtcNow)\n    {\n    }\n\n    /// <summary>\n    /// For JSON serializer. \n    /// System.Text.Json.JsonSerializer requires public, parameterless constructor\n    /// </summary>\n    public Message()\n    {\n    }\n    \n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"Message{TModel}\"/> class.\n    /// </summary>\n    /// <param name=\"data\">The data.</param>\n    /// <param name=\"now\">The current UTC date/time.</param>\n    public Message(TModel data, DateTime now)\n    {\n        Created = now.Ticks;\n        Data = data;\n    }\n\n    /// <summary>\n    /// Gets or sets the UTC ticks the <see cref=\"Message{TModel}\" /> was created.\n    /// </summary>\n    /// <value>\n    /// The created UTC ticks.\n    /// </value>\n    public long Created { get; set; }\n\n    /// <summary>\n    /// Gets or sets the data.\n    /// </summary>\n    /// <value>\n    /// The data.\n    /// </value>\n    public TModel Data { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/ParsedSecret.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Represents a secret extracted from the HttpContext\n/// </summary>\npublic class ParsedSecret\n{\n    /// <summary>\n    /// Gets or sets the identifier associated with this secret\n    /// </summary>\n    /// <value>\n    /// The identifier.\n    /// </value>\n    public string Id { get; set; }\n\n    /// <summary>\n    /// Gets or sets the credential to verify the secret\n    /// </summary>\n    /// <value>\n    /// The credential.\n    /// </value>\n    public object Credential { get; set; }\n\n    /// <summary>\n    /// Gets or sets the type of the secret\n    /// </summary>\n    /// <value>\n    /// The type.\n    /// </value>\n    public string Type { get; set; }\n\n    /// <summary>\n    /// Gets or sets additional properties.\n    /// </summary>\n    /// <value>\n    /// The properties.\n    /// </value>\n    public Dictionary<string, string> Properties { get; set; } = new Dictionary<string, string>();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/SecurityKeyInfo.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Information about a security key\n/// </summary>\npublic class SecurityKeyInfo\n{\n    /// <summary>\n    /// The key\n    /// </summary>\n    public SecurityKey Key { get; set; }\n\n    /// <summary>\n    /// The signing algorithm\n    /// </summary>\n    public string SigningAlgorithm { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/TokenCreationRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models the data to create a token from a validated request.\n/// </summary>\npublic class TokenCreationRequest\n{\n    /// <summary>\n    /// Gets or sets the subject.\n    /// </summary>\n    /// <value>\n    /// The subject.\n    /// </value>\n    public ClaimsPrincipal Subject { get; set; }\n\n    /// <summary>\n    /// Gets or sets the validated resources.\n    /// </summary>\n    /// <value>\n    /// The resources.\n    /// </value>\n    public ResourceValidationResult ValidatedResources { get; set; }\n\n    /// <summary>\n    /// Gets or sets the validated request.\n    /// </summary>\n    /// <value>\n    /// The validated request.\n    /// </value>\n    public ValidatedRequest ValidatedRequest { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether [include all identity claims].\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if [include all identity claims]; otherwise, <c>false</c>.\n    /// </value>\n    public bool IncludeAllIdentityClaims { get; set; }\n\n    /// <summary>\n    /// Gets or sets the access token to hash.\n    /// </summary>\n    /// <value>\n    /// The access token to hash.\n    /// </value>\n    public string AccessTokenToHash { get; set; }\n\n    /// <summary>\n    /// Gets or sets the authorization code to hash.\n    /// </summary>\n    /// <value>\n    /// The authorization code to hash.\n    /// </value>\n    public string AuthorizationCodeToHash { get; set; }\n\n    /// <summary>\n    /// Gets or sets pre-hashed state\n    /// </summary>\n    /// <value>\n    /// The pre-hashed state\n    /// </value>\n    public string StateHash { get; set; }\n\n    /// <summary>\n    /// Gets or sets the nonce.\n    /// </summary>\n    /// <value>\n    /// The nonce.\n    /// </value>\n    public string Nonce { get; set; }\n\n    /// <summary>\n    /// Gets the description the user assigned to the device being authorized.\n    /// </summary>\n    /// <value>\n    /// The description.\n    /// </value>\n    public string Description { get; set; }\n\n    /// <summary>\n    /// Called to validate the <see cref=\"TokenCreationRequest\"/> before it is processed.\n    /// </summary>\n    public void Validate()\n    {\n        if (ValidatedResources == null) throw new ArgumentNullException(nameof(ValidatedResources));\n        if (ValidatedRequest == null) throw new ArgumentNullException(nameof(ValidatedRequest));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Models/TokenRequestErrors.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Token request errors\n/// </summary>\npublic enum TokenRequestErrors\n{\n    /// <summary>\n    /// invalid_request\n    /// </summary>\n    InvalidRequest,\n\n    /// <summary>\n    /// invalid_client\n    /// </summary>\n    InvalidClient,\n\n    /// <summary>\n    /// invalid_grant\n    /// </summary>\n    InvalidGrant,\n\n    /// <summary>\n    /// unauthorized_client\n    /// </summary>\n    UnauthorizedClient,\n\n    /// <summary>\n    /// unsupported_grant_type\n    /// </summary>\n    UnsupportedGrantType,\n\n    /// <summary>\n    /// invalid_scope\n    /// </summary>\n    InvalidScope,\n\n    /// <summary>\n    /// invalid_target\n    /// </summary>\n    InvalidTarget\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Properties/AssemblyInfo.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n[assembly: InternalsVisibleTo(\"IdentityServer.UnitTests, PublicKey = 002400000480000094000000060200000024000052534131000400000100010057b24455efc2a317afb0644a2169c05644e439985c42cf4eb98706779651801add1da073da8b5e253e8d4335d59b3197bb941ebe943c63f7efbc3005c428f0d69b809e86bdc828fa431fae4b71005f26b52a26a3ee5cf0f6fdf744d4534a7a503683123f58e1082828b018245d2e40d8542f72a623c01490d73a5d3ff94a88c5\")]\n[assembly: InternalsVisibleTo(\"IdentityServer.IntegrationTests, PublicKey = 002400000480000094000000060200000024000052534131000400000100010057b24455efc2a317afb0644a2169c05644e439985c42cf4eb98706779651801add1da073da8b5e253e8d4335d59b3197bb941ebe943c63f7efbc3005c428f0d69b809e86bdc828fa431fae4b71005f26b52a26a3ee5cf0f6fdf744d4534a7a503683123f58e1082828b018245d2e40d8542f72a623c01490d73a5d3ff94a88c5\")]\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Default/AuthorizeInteractionResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Default logic for determining if user must login or consent when making requests to the authorization endpoint.\n/// </summary>\n/// <seealso cref=\"IdentityServer8.ResponseHandling.IAuthorizeInteractionResponseGenerator\" />\npublic class AuthorizeInteractionResponseGenerator : IAuthorizeInteractionResponseGenerator\n{\n    /// <summary>\n    /// The logger.\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// The consent service.\n    /// </summary>\n    protected readonly IConsentService Consent;\n\n    /// <summary>\n    /// The profile service.\n    /// </summary>\n    protected readonly IProfileService Profile;\n\n    /// <summary>\n    /// The clock\n    /// </summary>\n    protected readonly ISystemClock Clock;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"AuthorizeInteractionResponseGenerator\"/> class.\n    /// </summary>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"logger\">The logger.</param>\n    /// <param name=\"consent\">The consent.</param>\n    /// <param name=\"profile\">The profile.</param>\n    public AuthorizeInteractionResponseGenerator(\n        ISystemClock clock,\n        ILogger<AuthorizeInteractionResponseGenerator> logger,\n        IConsentService consent, \n        IProfileService profile)\n    {\n        Clock = clock;\n        Logger = logger;\n        Consent = consent;\n        Profile = profile;\n    }\n\n    /// <summary>\n    /// Processes the interaction logic.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"consent\">The consent.</param>\n    /// <returns></returns>\n    public virtual async Task<InteractionResponse> ProcessInteractionAsync(ValidatedAuthorizeRequest request, ConsentResponse consent = null)\n    {\n        Logger.LogTrace(\"ProcessInteractionAsync\");\n\n        if (consent != null && consent.Granted == false && consent.Error.HasValue && request.Subject.IsAuthenticated() == false)\n        {\n            // special case when anonymous user has issued an error prior to authenticating\n            Logger.LogInformation(\"Error: User consent result: {error}\", consent.Error);\n\n            var error = consent.Error switch\n            {\n                AuthorizationError.AccountSelectionRequired => OidcConstants.AuthorizeErrors.AccountSelectionRequired,\n                AuthorizationError.ConsentRequired => OidcConstants.AuthorizeErrors.ConsentRequired,\n                AuthorizationError.InteractionRequired => OidcConstants.AuthorizeErrors.InteractionRequired,\n                AuthorizationError.LoginRequired => OidcConstants.AuthorizeErrors.LoginRequired,\n                _ => OidcConstants.AuthorizeErrors.AccessDenied\n            };\n            \n            return new InteractionResponse\n            {\n                Error = error,\n                ErrorDescription = consent.ErrorDescription\n            };\n        }\n\n        var result = await ProcessLoginAsync(request);\n        \n        if (!result.IsLogin && !result.IsError && !result.IsRedirect)\n        {\n            result = await ProcessConsentAsync(request, consent);\n        }\n\n        if ((result.IsLogin || result.IsConsent || result.IsRedirect) && request.PromptModes.Contains(OidcConstants.PromptModes.None))\n        {\n            // prompt=none means do not show the UI\n            Logger.LogInformation(\"Changing response to LoginRequired: prompt=none was requested\");\n            result = new InteractionResponse\n            {\n                Error = result.IsLogin ? OidcConstants.AuthorizeErrors.LoginRequired :\n                            result.IsConsent ? OidcConstants.AuthorizeErrors.ConsentRequired : \n                                OidcConstants.AuthorizeErrors.InteractionRequired\n            };\n        }\n\n        return result;\n    }\n\n    /// <summary>\n    /// Processes the login logic.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    protected internal virtual async Task<InteractionResponse> ProcessLoginAsync(ValidatedAuthorizeRequest request)\n    {\n        if (request.PromptModes.Contains(OidcConstants.PromptModes.Login) ||\n            request.PromptModes.Contains(OidcConstants.PromptModes.SelectAccount))\n        {\n            Logger.LogInformation(\"Showing login: request contains prompt={0}\", request.PromptModes.ToSpaceSeparatedString());\n\n            // remove prompt so when we redirect back in from login page\n            // we won't think we need to force a prompt again\n            request.RemovePrompt();\n            \n            return new InteractionResponse { IsLogin = true };\n        }\n\n        // unauthenticated user\n        var isAuthenticated = request.Subject.IsAuthenticated();\n        \n        // user de-activated\n        bool isActive = false;\n\n        if (isAuthenticated)\n        {\n            var isActiveCtx = new IsActiveContext(request.Subject, request.Client, IdentityServerConstants.ProfileIsActiveCallers.AuthorizeEndpoint);\n            await Profile.IsActiveAsync(isActiveCtx);\n            \n            isActive = isActiveCtx.IsActive;\n        }\n\n        if (!isAuthenticated || !isActive)\n        {\n            if (!isAuthenticated)\n            {\n                Logger.LogInformation(\"Showing login: User is not authenticated\");\n            }\n            else if (!isActive)\n            {\n                Logger.LogInformation(\"Showing login: User is not active\");\n            }\n\n            return new InteractionResponse { IsLogin = true };\n        }\n\n        // check current idp\n        var currentIdp = request.Subject.GetIdentityProvider();\n\n        // check if idp login hint matches current provider\n        var idp = request.GetIdP();\n        if (idp.IsPresent())\n        {\n            if (idp != currentIdp)\n            {\n                Logger.LogInformation(\"Showing login: Current IdP ({currentIdp}) is not the requested IdP ({idp})\", currentIdp, idp);\n                return new InteractionResponse { IsLogin = true };\n            }\n        }\n\n        // check authentication freshness\n        if (request.MaxAge.HasValue)\n        {\n            var authTime = request.Subject.GetAuthenticationTime();\n            if (Clock.UtcNow > authTime.AddSeconds(request.MaxAge.Value))\n            {\n                Logger.LogInformation(\"Showing login: Requested MaxAge exceeded.\");\n\n                return new InteractionResponse { IsLogin = true };\n            }\n        }\n\n        // check local idp restrictions\n        if (currentIdp == IdentityServerConstants.LocalIdentityProvider)\n        {\n            if (!request.Client.EnableLocalLogin)\n            {\n                Logger.LogInformation(\"Showing login: User logged in locally, but client does not allow local logins\");\n                return new InteractionResponse { IsLogin = true };\n            }\n        }\n        // check external idp restrictions if user not using local idp\n        else if (request.Client.IdentityProviderRestrictions != null && \n            request.Client.IdentityProviderRestrictions.Any() &&\n            !request.Client.IdentityProviderRestrictions.Contains(currentIdp))\n        {\n            Logger.LogInformation(\"Showing login: User is logged in with idp: {idp}, but idp not in client restriction list.\", currentIdp);\n            return new InteractionResponse { IsLogin = true };\n        }\n\n        // check client's user SSO timeout\n        if (request.Client.UserSsoLifetime.HasValue)\n        {\n            var authTimeEpoch = request.Subject.GetAuthenticationTimeEpoch();\n            var nowEpoch = Clock.UtcNow.ToUnixTimeSeconds();\n\n            var diff = nowEpoch - authTimeEpoch;\n            if (diff > request.Client.UserSsoLifetime.Value)\n            {\n                Logger.LogInformation(\"Showing login: User's auth session duration: {sessionDuration} exceeds client's user SSO lifetime: {userSsoLifetime}.\", diff, request.Client.UserSsoLifetime);\n                return new InteractionResponse { IsLogin = true };\n            }\n        }\n\n        return new InteractionResponse();\n    }\n\n    /// <summary>\n    /// Processes the consent logic.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"consent\">The consent.</param>\n    /// <returns></returns>\n    /// <exception cref=\"ArgumentNullException\"></exception>\n    /// <exception cref=\"ArgumentException\">Invalid PromptMode</exception>\n    protected internal virtual async Task<InteractionResponse> ProcessConsentAsync(ValidatedAuthorizeRequest request, ConsentResponse consent = null)\n    {\n        if (request == null) throw new ArgumentNullException(nameof(request));\n\n        if (request.PromptModes.Any() &&\n            !request.PromptModes.Contains(OidcConstants.PromptModes.None) &&\n            !request.PromptModes.Contains(OidcConstants.PromptModes.Consent))\n        {\n            Logger.LogError(\"Invalid prompt mode: {promptMode}\", request.PromptModes.ToSpaceSeparatedString());\n            throw new ArgumentException(\"Invalid PromptMode\");\n        }\n\n        var consentRequired = await Consent.RequiresConsentAsync(request.Subject, request.Client, request.ValidatedResources.ParsedScopes);\n\n        if (consentRequired && request.PromptModes.Contains(OidcConstants.PromptModes.None))\n        {\n            Logger.LogInformation(\"Error: prompt=none requested, but consent is required.\");\n\n            return new InteractionResponse\n            {\n                Error = OidcConstants.AuthorizeErrors.ConsentRequired\n            };\n        }\n\n        if (request.PromptModes.Contains(OidcConstants.PromptModes.Consent) || consentRequired)\n        {\n            var response = new InteractionResponse();\n\n            // did user provide consent\n            if (consent == null)\n            {\n                // user was not yet shown conset screen\n                response.IsConsent = true;\n                Logger.LogInformation(\"Showing consent: User has not yet consented\");\n            }\n            else\n            {\n                request.WasConsentShown = true;\n                Logger.LogTrace(\"Consent was shown to user\");\n\n                // user was shown consent -- did they say yes or no\n                if (consent.Granted == false)\n                {\n                    // no need to show consent screen again\n                    // build error to return to client\n                    Logger.LogInformation(\"Error: User consent result: {error}\", consent.Error);\n\n                    var error = consent.Error switch\n                    {\n                        AuthorizationError.AccountSelectionRequired => OidcConstants.AuthorizeErrors.AccountSelectionRequired,\n                        AuthorizationError.ConsentRequired => OidcConstants.AuthorizeErrors.ConsentRequired,\n                        AuthorizationError.InteractionRequired => OidcConstants.AuthorizeErrors.InteractionRequired,\n                        AuthorizationError.LoginRequired => OidcConstants.AuthorizeErrors.LoginRequired,\n                        _ => OidcConstants.AuthorizeErrors.AccessDenied\n                    };\n                    \n                    response.Error = error;\n                    response.ErrorDescription = consent.ErrorDescription;\n                }\n                else\n                {\n                    // double check that required scopes are in the list of consented scopes\n                    var requiredScopes = request.ValidatedResources.GetRequiredScopeValues();\n                    var valid = requiredScopes.All(x => consent.ScopesValuesConsented.Contains(x));\n                    if (valid == false)\n                    {\n                        response.Error = OidcConstants.AuthorizeErrors.AccessDenied;\n                        Logger.LogInformation(\"Error: User denied consent to required scopes\");\n                    }\n                    else\n                    {\n                        // they said yes, set scopes they chose\n                        request.Description = consent.Description;\n                        request.ValidatedResources = request.ValidatedResources.Filter(consent.ScopesValuesConsented);\n                        Logger.LogInformation(\"User consented to scopes: {scopes}\", consent.ScopesValuesConsented);\n\n                        if (request.Client.AllowRememberConsent)\n                        {\n                            // remember consent\n                            var parsedScopes = Enumerable.Empty<ParsedScopeValue>();\n                            if (consent.RememberConsent)\n                            {\n                                // remember what user actually selected\n                                parsedScopes = request.ValidatedResources.ParsedScopes;\n                                Logger.LogDebug(\"User indicated to remember consent for scopes: {scopes}\", request.ValidatedResources.RawScopeValues);\n                            }\n\n                            await Consent.UpdateConsentAsync(request.Subject, request.Client, parsedScopes);\n                        }\n                    }\n                }\n            }\n\n            return response;\n        }\n\n        return new InteractionResponse();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Default/AuthorizeResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// The authorize response generator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.ResponseHandling.IAuthorizeResponseGenerator\" />\npublic class AuthorizeResponseGenerator : IAuthorizeResponseGenerator\n{\n    /// <summary>\n    /// The token service\n    /// </summary>\n    protected readonly ITokenService TokenService;\n\n    /// <summary>\n    /// The authorization code store\n    /// </summary>\n    protected readonly IAuthorizationCodeStore AuthorizationCodeStore;\n\n    /// <summary>\n    /// The event service\n    /// </summary>\n    protected readonly IEventService Events;\n\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// The clock\n    /// </summary>\n    protected readonly ISystemClock Clock;\n\n    /// <summary>\n    /// The key material service\n    /// </summary>\n    protected readonly IKeyMaterialService KeyMaterialService;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"AuthorizeResponseGenerator\"/> class.\n    /// </summary>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"logger\">The logger.</param>\n    /// <param name=\"tokenService\">The token service.</param>\n    /// <param name=\"keyMaterialService\"></param>\n    /// <param name=\"authorizationCodeStore\">The authorization code store.</param>\n    /// <param name=\"events\">The events.</param>\n    public AuthorizeResponseGenerator(\n        ISystemClock clock,\n        ITokenService tokenService,\n        IKeyMaterialService keyMaterialService,\n        IAuthorizationCodeStore authorizationCodeStore,\n        ILogger<AuthorizeResponseGenerator> logger,\n        IEventService events)\n    {\n        Clock = clock;\n        TokenService = tokenService;\n        KeyMaterialService = keyMaterialService;\n        AuthorizationCodeStore = authorizationCodeStore;\n        Events = events;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Creates the response\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.InvalidOperationException\">invalid grant type: \" + request.GrantType</exception>\n    public virtual async Task<AuthorizeResponse> CreateResponseAsync(ValidatedAuthorizeRequest request)\n    {\n        if (request.GrantType == GrantType.AuthorizationCode)\n        {\n            return await CreateCodeFlowResponseAsync(request);\n        }\n        if (request.GrantType == GrantType.Implicit)\n        {\n            return await CreateImplicitFlowResponseAsync(request);\n        }\n        if (request.GrantType == GrantType.Hybrid)\n        {\n            return await CreateHybridFlowResponseAsync(request);\n        }\n\n        Logger.LogError(\"Unsupported grant type: \" + request.GrantType);\n        throw new InvalidOperationException(\"invalid grant type: \" + request.GrantType);\n    }\n\n    /// <summary>\n    /// Creates the response for a hybrid flow request\n    /// </summary>\n    /// <param name=\"request\"></param>\n    /// <returns></returns>\n    protected virtual async Task<AuthorizeResponse> CreateHybridFlowResponseAsync(ValidatedAuthorizeRequest request)\n    {\n        Logger.LogDebug(\"Creating Hybrid Flow response.\");\n\n        var code = await CreateCodeAsync(request);\n        var id = await AuthorizationCodeStore.StoreAuthorizationCodeAsync(code);\n\n        var response = await CreateImplicitFlowResponseAsync(request, id);\n        response.Code = id;\n\n        return response;\n    }\n\n    /// <summary>\n    /// Creates the response for a code flow request\n    /// </summary>\n    /// <param name=\"request\"></param>\n    /// <returns></returns>\n    protected virtual async Task<AuthorizeResponse> CreateCodeFlowResponseAsync(ValidatedAuthorizeRequest request)\n    {\n        Logger.LogDebug(\"Creating Authorization Code Flow response.\");\n\n        var code = await CreateCodeAsync(request);\n        var id = await AuthorizationCodeStore.StoreAuthorizationCodeAsync(code);\n\n        var response = new AuthorizeResponse\n        {\n            Request = request,\n            Code = id,\n            SessionState = request.GenerateSessionStateValue()\n        };\n\n        return response;\n    }\n\n    /// <summary>\n    /// Creates the response for a implicit flow request\n    /// </summary>\n    /// <param name=\"request\"></param>\n    /// <param name=\"authorizationCode\"></param>\n    /// <returns></returns>\n    protected virtual async Task<AuthorizeResponse> CreateImplicitFlowResponseAsync(ValidatedAuthorizeRequest request, string authorizationCode = null)\n    {\n        Logger.LogDebug(\"Creating Implicit Flow response.\");\n\n        string accessTokenValue = null;\n        int accessTokenLifetime = 0;\n\n        var responseTypes = request.ResponseType.FromSpaceSeparatedString();\n\n        if (responseTypes.Contains(OidcConstants.ResponseTypes.Token))\n        {\n            var tokenRequest = new TokenCreationRequest\n            {\n                Subject = request.Subject,\n                ValidatedResources = request.ValidatedResources,\n\n                ValidatedRequest = request\n            };\n\n            var accessToken = await TokenService.CreateAccessTokenAsync(tokenRequest);\n            accessTokenLifetime = accessToken.Lifetime;\n\n            accessTokenValue = await TokenService.CreateSecurityTokenAsync(accessToken);\n        }\n\n        string jwt = null;\n        if (responseTypes.Contains(OidcConstants.ResponseTypes.IdToken))\n        {\n            string stateHash = null;\n            if (request.State.IsPresent())\n            {\n                var credential = await KeyMaterialService.GetSigningCredentialsAsync(request.Client.AllowedIdentityTokenSigningAlgorithms);\n                if (credential == null)\n                {\n                    throw new InvalidOperationException(\"No signing credential is configured.\");\n                }\n\n                var algorithm = credential.Algorithm;\n                stateHash = CryptoHelper.CreateHashClaimValue(request.State, algorithm);\n            }\n\n            var tokenRequest = new TokenCreationRequest\n            {\n                ValidatedRequest = request,\n                Subject = request.Subject,\n                ValidatedResources = request.ValidatedResources,\n                Nonce = request.Raw.Get(OidcConstants.AuthorizeRequest.Nonce),\n                IncludeAllIdentityClaims = !request.AccessTokenRequested,\n                AccessTokenToHash = accessTokenValue,\n                AuthorizationCodeToHash = authorizationCode,\n                StateHash = stateHash\n            };\n\n            var idToken = await TokenService.CreateIdentityTokenAsync(tokenRequest);\n            jwt = await TokenService.CreateSecurityTokenAsync(idToken);\n        }\n\n        var response = new AuthorizeResponse\n        {\n            Request = request,\n            AccessToken = accessTokenValue,\n            AccessTokenLifetime = accessTokenLifetime,\n            IdentityToken = jwt,\n            SessionState = request.GenerateSessionStateValue()\n        };\n\n        return response;\n    }\n\n    /// <summary>\n    /// Creates an authorization code\n    /// </summary>\n    /// <param name=\"request\"></param>\n    /// <returns></returns>\n    protected virtual async Task<AuthorizationCode> CreateCodeAsync(ValidatedAuthorizeRequest request)\n    {\n        string stateHash = null;\n        if (request.State.IsPresent())\n        {\n            var credential = await KeyMaterialService.GetSigningCredentialsAsync(request.Client.AllowedIdentityTokenSigningAlgorithms);\n            if (credential == null)\n            {\n                throw new InvalidOperationException(\"No signing credential is configured.\");\n            }\n\n            var algorithm = credential.Algorithm;\n            stateHash = CryptoHelper.CreateHashClaimValue(request.State, algorithm);\n        }\n\n        var code = new AuthorizationCode\n        {\n            CreationTime = Clock.UtcNow.UtcDateTime,\n            ClientId = request.Client.ClientId,\n            Lifetime = request.Client.AuthorizationCodeLifetime,\n            Subject = request.Subject,\n            SessionId = request.SessionId,\n            Description = request.Description,\n            CodeChallenge = request.CodeChallenge.Sha256(),\n            CodeChallengeMethod = request.CodeChallengeMethod,\n\n            IsOpenId = request.IsOpenIdRequest,\n            RequestedScopes = request.ValidatedResources.RawScopeValues,\n            RedirectUri = request.RedirectUri,\n            Nonce = request.Nonce,\n            StateHash = stateHash,\n\n            WasConsentShown = request.WasConsentShown\n        };\n\n        return code;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Default/DeviceAuthorizationResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// The device authorizaiton response generator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.ResponseHandling.IDeviceAuthorizationResponseGenerator\" />\npublic class DeviceAuthorizationResponseGenerator : IDeviceAuthorizationResponseGenerator\n{\n    /// <summary>\n    /// The options\n    /// </summary>\n    protected readonly IdentityServerOptions Options;\n\n    /// <summary>\n    /// The user code service\n    /// </summary>\n    protected readonly IUserCodeService UserCodeService;\n\n    /// <summary>\n    /// The device flow code service\n    /// </summary>\n    protected readonly IDeviceFlowCodeService DeviceFlowCodeService;\n\n    /// <summary>\n    /// The clock\n    /// </summary>\n    protected readonly ISystemClock Clock;\n\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DeviceAuthorizationResponseGenerator\"/> class.\n    /// </summary>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"userCodeService\">The user code service.</param>\n    /// <param name=\"deviceFlowCodeService\">The device flow code service.</param>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DeviceAuthorizationResponseGenerator(IdentityServerOptions options, IUserCodeService userCodeService, IDeviceFlowCodeService deviceFlowCodeService, ISystemClock clock, ILogger<DeviceAuthorizationResponseGenerator> logger)\n    {\n        Options = options;\n        UserCodeService = userCodeService;\n        DeviceFlowCodeService = deviceFlowCodeService;\n        Clock = clock;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Processes the response.\n    /// </summary>\n    /// <param name=\"validationResult\">The validation result.</param>\n    /// <param name=\"baseUrl\">The base URL.</param>\n    /// <returns></returns>\n    /// <exception cref=\"ArgumentNullException\">validationResult or Client</exception>\n    /// <exception cref=\"ArgumentException\">Value cannot be null or whitespace. - baseUrl</exception>\n    public virtual async Task<DeviceAuthorizationResponse> ProcessAsync(DeviceAuthorizationRequestValidationResult validationResult, string baseUrl)\n    {\n        if (validationResult == null) throw new ArgumentNullException(nameof(validationResult));\n        if (validationResult.ValidatedRequest.Client == null) throw new ArgumentNullException(nameof(validationResult.ValidatedRequest.Client));\n        if (string.IsNullOrWhiteSpace(baseUrl)) throw new ArgumentException(\"Value cannot be null or whitespace.\", nameof(baseUrl));\n\n        Logger.LogTrace(\"Creating response for device authorization request\");\n\n        var response = new DeviceAuthorizationResponse();\n        \n        // generate user_code\n        var userCodeGenerator = await UserCodeService.GetGenerator(\n            validationResult.ValidatedRequest.Client.UserCodeType ??\n            Options.DeviceFlow.DefaultUserCodeType);\n        \n        var retryCount = 0;\n\n        while (retryCount < userCodeGenerator.RetryLimit)\n        {\n            var userCode = await userCodeGenerator.GenerateAsync();\n            \n            var deviceCode = await DeviceFlowCodeService.FindByUserCodeAsync(userCode);\n            if (deviceCode == null)\n            {\n                response.UserCode = userCode;\n                break;\n            }\n\n            retryCount++;\n        }\n\n        if (response.UserCode == null)\n        {\n            throw new InvalidOperationException(\"Unable to create unique device flow user code\");\n        }\n\n        // generate verification URIs\n        response.VerificationUri = Options.UserInteraction.DeviceVerificationUrl;\n        if (response.VerificationUri.IsLocalUrl())\n        {\n            // if url is relative, parse absolute URL\n            response.VerificationUri = baseUrl.RemoveTrailingSlash() + Options.UserInteraction.DeviceVerificationUrl;\n        }\n        \n        if (!string.IsNullOrWhiteSpace(Options.UserInteraction.DeviceVerificationUserCodeParameter))\n        {\n            response.VerificationUriComplete =\n                $\"{response.VerificationUri}?{Options.UserInteraction.DeviceVerificationUserCodeParameter}={response.UserCode}\";\n        }\n\n        // expiration\n        response.DeviceCodeLifetime = validationResult.ValidatedRequest.Client.DeviceCodeLifetime;\n\n        // interval\n        response.Interval = Options.DeviceFlow.Interval;\n\n        // store device request (device code & user code)\n        response.DeviceCode = await DeviceFlowCodeService.StoreDeviceAuthorizationAsync(response.UserCode, new DeviceCode\n        {\n            Description = validationResult.ValidatedRequest.Description,\n            ClientId = validationResult.ValidatedRequest.Client.ClientId,\n            IsOpenId = validationResult.ValidatedRequest.IsOpenIdRequest,\n            Lifetime = response.DeviceCodeLifetime,\n            CreationTime = Clock.UtcNow.UtcDateTime,\n            RequestedScopes = validationResult.ValidatedRequest.ValidatedResources.RawScopeValues\n        });\n\n        return response;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Default/DiscoveryResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\nusing JsonWebKey = Microsoft.IdentityModel.Tokens.JsonWebKey;\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Default implementation of the discovery endpoint response generator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.ResponseHandling.IDiscoveryResponseGenerator\" />\npublic class DiscoveryResponseGenerator : IDiscoveryResponseGenerator\n{\n    /// <summary>\n    /// The options\n    /// </summary>\n    protected readonly IdentityServerOptions Options;\n\n    /// <summary>\n    /// The extension grants validator\n    /// </summary>\n    protected readonly ExtensionGrantValidator ExtensionGrants;\n\n    /// <summary>\n    /// The key material service\n    /// </summary>\n    protected readonly IKeyMaterialService Keys;\n\n    /// <summary>\n    /// The resource owner validator\n    /// </summary>\n    protected readonly IResourceOwnerPasswordValidator ResourceOwnerValidator;\n\n    /// <summary>\n    /// The resource store\n    /// </summary>\n    protected readonly IResourceStore ResourceStore;\n\n    /// <summary>\n    /// The secret parsers\n    /// </summary>\n    protected readonly ISecretsListParser SecretParsers;\n\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DiscoveryResponseGenerator\"/> class.\n    /// </summary>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"resourceStore\">The resource store.</param>\n    /// <param name=\"keys\">The keys.</param>\n    /// <param name=\"extensionGrants\">The extension grants.</param>\n    /// <param name=\"secretParsers\">The secret parsers.</param>\n    /// <param name=\"resourceOwnerValidator\">The resource owner validator.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DiscoveryResponseGenerator(\n        IdentityServerOptions options,\n        IResourceStore resourceStore,\n        IKeyMaterialService keys,\n        ExtensionGrantValidator extensionGrants,\n        ISecretsListParser secretParsers,\n        IResourceOwnerPasswordValidator resourceOwnerValidator,\n        ILogger<DiscoveryResponseGenerator> logger)\n    {\n        Options = options;\n        ResourceStore = resourceStore;\n        Keys = keys;\n        ExtensionGrants = extensionGrants;\n        SecretParsers = secretParsers;\n        ResourceOwnerValidator = resourceOwnerValidator;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Creates the discovery document.\n    /// </summary>\n    /// <param name=\"baseUrl\">The base URL.</param>\n    /// <param name=\"issuerUri\">The issuer URI.</param>\n    public virtual async Task<Dictionary<string, object>> CreateDiscoveryDocumentAsync(string baseUrl, string issuerUri)\n    {\n        var entries = new Dictionary<string, object>\n        {\n            { OidcConstants.Discovery.Issuer, issuerUri }\n        };\n\n        // jwks\n        if (Options.Discovery.ShowKeySet)\n        {\n            if ((await Keys.GetValidationKeysAsync()).Any())\n            {\n                entries.Add(OidcConstants.Discovery.JwksUri, baseUrl + Constants.ProtocolRoutePaths.DiscoveryWebKeys);\n            }\n        }\n\n        // endpoints\n        if (Options.Discovery.ShowEndpoints)\n        {\n            if (Options.Endpoints.EnableAuthorizeEndpoint)\n            {\n                entries.Add(OidcConstants.Discovery.AuthorizationEndpoint, baseUrl + Constants.ProtocolRoutePaths.Authorize);\n            }\n\n            if (Options.Endpoints.EnableTokenEndpoint)\n            {\n                entries.Add(OidcConstants.Discovery.TokenEndpoint, baseUrl + Constants.ProtocolRoutePaths.Token);\n            }\n\n            if (Options.Endpoints.EnableUserInfoEndpoint)\n            {\n                entries.Add(OidcConstants.Discovery.UserInfoEndpoint, baseUrl + Constants.ProtocolRoutePaths.UserInfo);\n            }\n\n            if (Options.Endpoints.EnableEndSessionEndpoint)\n            {\n                entries.Add(OidcConstants.Discovery.EndSessionEndpoint, baseUrl + Constants.ProtocolRoutePaths.EndSession);\n            }\n\n            if (Options.Endpoints.EnableCheckSessionEndpoint)\n            {\n                entries.Add(OidcConstants.Discovery.CheckSessionIframe, baseUrl + Constants.ProtocolRoutePaths.CheckSession);\n            }\n\n            if (Options.Endpoints.EnableTokenRevocationEndpoint)\n            {\n                entries.Add(OidcConstants.Discovery.RevocationEndpoint, baseUrl + Constants.ProtocolRoutePaths.Revocation);\n            }\n\n            if (Options.Endpoints.EnableIntrospectionEndpoint)\n            {\n                entries.Add(OidcConstants.Discovery.IntrospectionEndpoint, baseUrl + Constants.ProtocolRoutePaths.Introspection);\n            }\n\n            if (Options.Endpoints.EnableDeviceAuthorizationEndpoint)\n            {\n                entries.Add(OidcConstants.Discovery.DeviceAuthorizationEndpoint, baseUrl + Constants.ProtocolRoutePaths.DeviceAuthorization);\n            }\n\n            if (Options.MutualTls.Enabled)\n            {\n                var mtlsEndpoints = new Dictionary<string, string>();\n\n                if (Options.Endpoints.EnableTokenEndpoint)\n                {\n                    mtlsEndpoints.Add(OidcConstants.Discovery.TokenEndpoint, ConstructMtlsEndpoint(Constants.ProtocolRoutePaths.Token));\n                }\n                if (Options.Endpoints.EnableTokenRevocationEndpoint)\n                {\n                    mtlsEndpoints.Add(OidcConstants.Discovery.RevocationEndpoint, ConstructMtlsEndpoint(Constants.ProtocolRoutePaths.Revocation));\n                }\n                if (Options.Endpoints.EnableIntrospectionEndpoint)\n                {\n                    mtlsEndpoints.Add(OidcConstants.Discovery.IntrospectionEndpoint, ConstructMtlsEndpoint(Constants.ProtocolRoutePaths.Introspection));\n                }\n                if (Options.Endpoints.EnableDeviceAuthorizationEndpoint)\n                {\n                    mtlsEndpoints.Add(OidcConstants.Discovery.DeviceAuthorizationEndpoint, ConstructMtlsEndpoint(Constants.ProtocolRoutePaths.DeviceAuthorization));\n                }\n\n                if (mtlsEndpoints.Any())\n                {\n                    entries.Add(OidcConstants.Discovery.MtlsEndpointAliases, mtlsEndpoints);\n                }\n\n                string ConstructMtlsEndpoint(string endpoint)\n                {\n                    // path based\n                    if (Options.MutualTls.DomainName.IsMissing())\n                    {\n                        return baseUrl + endpoint.Replace(Constants.ProtocolRoutePaths.ConnectPathPrefix, Constants.ProtocolRoutePaths.MtlsPathPrefix);\n                    }\n\n                    // domain based\n                    if (Options.MutualTls.DomainName.Contains(\".\"))\n                    {\n                        return $\"https://{Options.MutualTls.DomainName}/{endpoint}\";\n                    }\n                    // sub-domain based\n                    else\n                    {\n                        var parts = baseUrl.Split(\"://\");\n                        return $\"https://{Options.MutualTls.DomainName}.{parts[1]}{endpoint}\";\n                    }\n                }\n            }\n        }\n\n        // logout\n        if (Options.Endpoints.EnableEndSessionEndpoint)\n        {\n            entries.Add(OidcConstants.Discovery.FrontChannelLogoutSupported, true);\n            entries.Add(OidcConstants.Discovery.FrontChannelLogoutSessionSupported, true);\n            entries.Add(OidcConstants.Discovery.BackChannelLogoutSupported, true);\n            entries.Add(OidcConstants.Discovery.BackChannelLogoutSessionSupported, true);\n        }\n\n        // scopes and claims\n        if (Options.Discovery.ShowIdentityScopes ||\n            Options.Discovery.ShowApiScopes ||\n            Options.Discovery.ShowClaims)\n        {\n            var resources = await ResourceStore.GetAllEnabledResourcesAsync();\n            var scopes = new List<string>();\n\n            // scopes\n            if (Options.Discovery.ShowIdentityScopes)\n            {\n                scopes.AddRange(resources.IdentityResources.Where(x => x.ShowInDiscoveryDocument).Select(x => x.Name));\n            }\n\n            if (Options.Discovery.ShowApiScopes)\n            {\n                var apiScopes = from scope in resources.ApiScopes\n                                where scope.ShowInDiscoveryDocument\n                                select scope.Name;\n\n                scopes.AddRange(apiScopes);\n                scopes.Add(IdentityServerConstants.StandardScopes.OfflineAccess);\n            }\n\n            if (scopes.Any())\n            {\n                entries.Add(OidcConstants.Discovery.ScopesSupported, scopes.ToArray());\n            }\n\n            // claims\n            if (Options.Discovery.ShowClaims)\n            {\n                var claims = new List<string>();\n\n                // add non-hidden identity scopes related claims\n                claims.AddRange(resources.IdentityResources.Where(x => x.ShowInDiscoveryDocument).SelectMany(x => x.UserClaims));\n                claims.AddRange(resources.ApiResources.Where(x => x.ShowInDiscoveryDocument).SelectMany(x => x.UserClaims));\n                claims.AddRange(resources.ApiScopes.Where(x => x.ShowInDiscoveryDocument).SelectMany(x => x.UserClaims));\n\n                entries.Add(OidcConstants.Discovery.ClaimsSupported, claims.Distinct().ToArray());\n            }\n        }\n\n        // grant types\n        if (Options.Discovery.ShowGrantTypes)\n        {\n            var standardGrantTypes = new List<string>\n            {\n                OidcConstants.GrantTypes.AuthorizationCode,\n                OidcConstants.GrantTypes.ClientCredentials,\n                OidcConstants.GrantTypes.RefreshToken,\n                OidcConstants.GrantTypes.Implicit\n            };\n\n            if (!(ResourceOwnerValidator is NotSupportedResourceOwnerPasswordValidator))\n            {\n                standardGrantTypes.Add(OidcConstants.GrantTypes.Password);\n            }\n\n            if (Options.Endpoints.EnableDeviceAuthorizationEndpoint)\n            {\n                standardGrantTypes.Add(OidcConstants.GrantTypes.DeviceCode);\n            }\n\n            var showGrantTypes = new List<string>(standardGrantTypes);\n\n            if (Options.Discovery.ShowExtensionGrantTypes)\n            {\n                showGrantTypes.AddRange(ExtensionGrants.GetAvailableGrantTypes());\n            }\n\n            entries.Add(OidcConstants.Discovery.GrantTypesSupported, showGrantTypes.ToArray());\n        }\n\n        // response types\n        if (Options.Discovery.ShowResponseTypes)\n        {\n            entries.Add(OidcConstants.Discovery.ResponseTypesSupported, Constants.SupportedResponseTypes.ToArray());\n        }\n\n        // response modes\n        if (Options.Discovery.ShowResponseModes)\n        {\n            entries.Add(OidcConstants.Discovery.ResponseModesSupported, Constants.SupportedResponseModes.ToArray());\n        }\n\n        // misc\n        if (Options.Discovery.ShowTokenEndpointAuthenticationMethods)\n        {\n            var types = SecretParsers.GetAvailableAuthenticationMethods().ToList();\n            if (Options.MutualTls.Enabled)\n            {\n                types.Add(OidcConstants.EndpointAuthenticationMethods.TlsClientAuth);\n                types.Add(OidcConstants.EndpointAuthenticationMethods.SelfSignedTlsClientAuth);\n            }\n\n            entries.Add(OidcConstants.Discovery.TokenEndpointAuthenticationMethodsSupported, types);\n        }\n\n        var signingCredentials = await Keys.GetAllSigningCredentialsAsync();\n        if (signingCredentials.Any())\n        {\n            var signingAlgorithms = signingCredentials.Select(c => c.Algorithm).Distinct();\n            entries.Add(OidcConstants.Discovery.IdTokenSigningAlgorithmsSupported, signingAlgorithms);\n        }\n\n        entries.Add(OidcConstants.Discovery.SubjectTypesSupported, new[] { \"public\" });\n        entries.Add(OidcConstants.Discovery.CodeChallengeMethodsSupported, new[] { OidcConstants.CodeChallengeMethods.Plain, OidcConstants.CodeChallengeMethods.Sha256 });\n\n        if (Options.Endpoints.EnableAuthorizeEndpoint)\n        {\n            entries.Add(OidcConstants.Discovery.RequestParameterSupported, true);\n\n            if (Options.Endpoints.EnableJwtRequestUri)\n            {\n                entries.Add(OidcConstants.Discovery.RequestUriParameterSupported, true);\n            }\n        }\n\n        if (Options.MutualTls.Enabled)\n        {\n            entries.Add(OidcConstants.Discovery.TlsClientCertificateBoundAccessTokens, true);\n        }\n\n        // custom entries\n        if (!Options.Discovery.CustomEntries.EnumerableIsNullOrEmpty())\n        {\n            foreach ((string key, object value) in Options.Discovery.CustomEntries)\n            {\n                if (entries.ContainsKey(key))\n                {\n                    Logger.LogError(\"Discovery custom entry {key} cannot be added, because it already exists.\", key);\n                }\n                else\n                {\n                    if (value is string customValueString)\n                    {\n                        if (customValueString.StartsWith(\"~/\") && Options.Discovery.ExpandRelativePathsInCustomEntries)\n                        {\n                            entries.Add(key, baseUrl + customValueString.Substring(2));\n                            continue;\n                        }\n                    }\n\n                    entries.Add(key, value);\n                }\n            }\n        }\n\n        return entries;\n    }\n\n    /// <summary>\n    /// Creates the JWK document.\n    /// </summary>\n    public virtual async Task<IEnumerable<Models.JsonWebKey>> CreateJwkDocumentAsync()\n    {\n        var webKeys = new List<Models.JsonWebKey>();\n\n        foreach (var key in await Keys.GetValidationKeysAsync())\n        {\n            if (key.Key is X509SecurityKey x509Key)\n            {\n                var cert64 = Convert.ToBase64String(x509Key.Certificate.RawData);\n                var thumbprint = Base64Url.Encode(x509Key.Certificate.GetCertHash());\n\n                if (x509Key.PublicKey is RSA rsa)\n                {\n                    var parameters = rsa.ExportParameters(false);\n                    var exponent = Base64Url.Encode(parameters.Exponent);\n                    var modulus = Base64Url.Encode(parameters.Modulus);\n\n                    var rsaJsonWebKey = new Models.JsonWebKey\n                    {\n                        kty = \"RSA\",\n                        use = \"sig\",\n                        kid = x509Key.KeyId,\n                        x5t = thumbprint,\n                        e = exponent,\n                        n = modulus,\n                        x5c = new[] { cert64 },\n                        alg = key.SigningAlgorithm\n                    };\n                    webKeys.Add(rsaJsonWebKey);\n                }\n                else if (x509Key.PublicKey is ECDsa ecdsa)\n                {\n                    var parameters = ecdsa.ExportParameters(false);\n                    var x = Base64Url.Encode(parameters.Q.X);\n                    var y = Base64Url.Encode(parameters.Q.Y);\n\n                    var ecdsaJsonWebKey = new Models.JsonWebKey\n                    {\n                        kty = \"EC\",\n                        use = \"sig\",\n                        kid = x509Key.KeyId,\n                        x5t = thumbprint,\n                        x = x,\n                        y = y,\n                        crv = CryptoHelper.GetCrvValueFromCurve(parameters.Curve),\n                        x5c = new[] { cert64 },\n                        alg = key.SigningAlgorithm\n                    };\n                    webKeys.Add(ecdsaJsonWebKey);\n                }\n                else\n                {\n                    throw new InvalidOperationException($\"key type: {x509Key.PublicKey.GetType().Name} not supported.\");\n                }\n            }\n            else if (key.Key is RsaSecurityKey rsaKey)\n            {\n                var parameters = rsaKey.Rsa?.ExportParameters(false) ?? rsaKey.Parameters;\n                var exponent = Base64Url.Encode(parameters.Exponent);\n                var modulus = Base64Url.Encode(parameters.Modulus);\n\n                var webKey = new Models.JsonWebKey\n                {\n                    kty = \"RSA\",\n                    use = \"sig\",\n                    kid = rsaKey.KeyId,\n                    e = exponent,\n                    n = modulus,\n                    alg = key.SigningAlgorithm\n                };\n\n                webKeys.Add(webKey);\n            }\n            else if (key.Key is ECDsaSecurityKey ecdsaKey)\n            {\n                var parameters = ecdsaKey.ECDsa.ExportParameters(false);\n                var x = Base64Url.Encode(parameters.Q.X);\n                var y = Base64Url.Encode(parameters.Q.Y);\n\n                var ecdsaJsonWebKey = new Models.JsonWebKey\n                {\n                    kty = \"EC\",\n                    use = \"sig\",\n                    kid = ecdsaKey.KeyId,\n                    x = x,\n                    y = y,\n                    crv = CryptoHelper.GetCrvValueFromCurve(parameters.Curve),\n                    alg = key.SigningAlgorithm\n                };\n                webKeys.Add(ecdsaJsonWebKey);\n            }\n            else if (key.Key is JsonWebKey jsonWebKey)\n            {\n                var webKey = new Models.JsonWebKey\n                {\n                    kty = jsonWebKey.Kty,\n                    use = jsonWebKey.Use ?? \"sig\",\n                    kid = jsonWebKey.Kid,\n                    x5t = jsonWebKey.X5t,\n                    e = jsonWebKey.E,\n                    n = jsonWebKey.N,\n                    x5c = jsonWebKey.X5c?.Count == 0 ? null : jsonWebKey.X5c.ToArray(),\n                    alg = jsonWebKey.Alg,\n                    crv = jsonWebKey.Crv,\n                    x = jsonWebKey.X,\n                    y = jsonWebKey.Y\n                };\n\n                webKeys.Add(webKey);\n            }\n        }\n\n        return webKeys;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Default/IntrospectionResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// The introspection response generator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.ResponseHandling.IIntrospectionResponseGenerator\" />\npublic class IntrospectionResponseGenerator : IIntrospectionResponseGenerator\n{\n    /// <summary>\n    /// Gets the events.\n    /// </summary>\n    /// <value>\n    /// The events.\n    /// </value>\n    protected readonly IEventService Events;\n\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IntrospectionResponseGenerator\" /> class.\n    /// </summary>\n    /// <param name=\"events\">The events.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public IntrospectionResponseGenerator(IEventService events, ILogger<IntrospectionResponseGenerator> logger)\n    {\n        Events = events;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Processes the response.\n    /// </summary>\n    /// <param name=\"validationResult\">The validation result.</param>\n    /// <returns></returns>\n    public virtual async Task<Dictionary<string, object>> ProcessAsync(IntrospectionRequestValidationResult validationResult)\n    {\n        Logger.LogTrace(\"Creating introspection response\");\n\n        // standard response\n        var response = new Dictionary<string, object>\n        {\n            { \"active\", false }\n        };\n\n        // token is invalid\n        if (validationResult.IsActive == false)\n        {\n            Logger.LogDebug(\"Creating introspection response for inactive token.\");\n            await Events.RaiseAsync(new TokenIntrospectionSuccessEvent(validationResult));\n\n            return response;\n        }\n\n        // expected scope not present\n        if (await AreExpectedScopesPresentAsync(validationResult) == false)\n        {\n            return response;\n        }\n\n        Logger.LogDebug(\"Creating introspection response for active token.\");\n\n        // get all claims (without scopes)\n        response = validationResult.Claims.Where(c => c.Type != JwtClaimTypes.Scope).ToClaimsDictionary();\n\n        // add active flag\n        response.Add(\"active\", true);\n\n        // calculate scopes the caller is allowed to see\n        var allowedScopes = validationResult.Api.Scopes;\n        var scopes = validationResult.Claims.Where(c => c.Type == JwtClaimTypes.Scope).Select(x => x.Value);\n        scopes = scopes.Where(x => allowedScopes.Contains(x));\n        response.Add(\"scope\", scopes.ToSpaceSeparatedString());\n\n        await Events.RaiseAsync(new TokenIntrospectionSuccessEvent(validationResult));\n        return response;\n    }\n\n    /// <summary>\n    /// Checks if the API resource is allowed to introspect the scopes.\n    /// </summary>\n    /// <param name=\"validationResult\">The validation result.</param>\n    /// <returns></returns>\n    protected virtual async Task<bool> AreExpectedScopesPresentAsync(IntrospectionRequestValidationResult validationResult)\n    {\n        var apiScopes = validationResult.Api.Scopes;\n        var tokenScopes = validationResult.Claims.Where(c => c.Type == JwtClaimTypes.Scope);\n\n        var tokenScopesThatMatchApi = tokenScopes.Where(c => apiScopes.Contains(c.Value));\n\n        var result = false;\n\n        if (tokenScopesThatMatchApi.Any())\n        {\n            // at least one of the scopes the API supports is in the token\n            result = true;\n        }\n        else\n        {\n            // no scopes for this API are found in the token\n            Logger.LogError(\"Expected scope {scopes} is missing in token\", apiScopes);\n            await Events.RaiseAsync(new TokenIntrospectionFailureEvent(validationResult.Api.Name, \"Expected scopes are missing\", validationResult.Token, apiScopes, tokenScopes.Select(s => s.Value)));\n        }\n\n        return result;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Default/TokenResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// The default token response generator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.ResponseHandling.ITokenResponseGenerator\" />\npublic class TokenResponseGenerator : ITokenResponseGenerator\n{\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// The token service\n    /// </summary>\n    protected readonly ITokenService TokenService;\n\n    /// <summary>\n    /// The refresh token service\n    /// </summary>\n    protected readonly IRefreshTokenService RefreshTokenService;\n\n    /// <summary>\n    /// The scope parser\n    /// </summary>\n    public IScopeParser ScopeParser { get; }\n\n    /// <summary>\n    /// The resource store\n    /// </summary>\n    protected readonly IResourceStore Resources;\n\n    /// <summary>\n    /// The clients store\n    /// </summary>\n    protected readonly IClientStore Clients;\n\n    /// <summary>\n    ///  The clock\n    /// </summary>\n    protected readonly ISystemClock Clock;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenResponseGenerator\" /> class.\n    /// </summary>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"tokenService\">The token service.</param>\n    /// <param name=\"refreshTokenService\">The refresh token service.</param>\n    /// <param name=\"scopeParser\">The scope parser.</param>\n    /// <param name=\"resources\">The resources.</param>\n    /// <param name=\"clients\">The clients.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public TokenResponseGenerator(ISystemClock clock, ITokenService tokenService, IRefreshTokenService refreshTokenService, IScopeParser scopeParser, IResourceStore resources, IClientStore clients, ILogger<TokenResponseGenerator> logger)\n    {\n        Clock = clock;\n        TokenService = tokenService;\n        RefreshTokenService = refreshTokenService;\n        ScopeParser = scopeParser;\n        Resources = resources;\n        Clients = clients;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Processes the response.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    public virtual async Task<TokenResponse> ProcessAsync(TokenRequestValidationResult request)\n    {\n        switch (request.ValidatedRequest.GrantType)\n        {\n            case OidcConstants.GrantTypes.ClientCredentials:\n                return await ProcessClientCredentialsRequestAsync(request);\n            case OidcConstants.GrantTypes.Password:\n                return await ProcessPasswordRequestAsync(request);\n            case OidcConstants.GrantTypes.AuthorizationCode:\n                return await ProcessAuthorizationCodeRequestAsync(request);\n            case OidcConstants.GrantTypes.RefreshToken:\n                return await ProcessRefreshTokenRequestAsync(request);\n            case OidcConstants.GrantTypes.DeviceCode:\n                return await ProcessDeviceCodeRequestAsync(request);\n            default:\n                return await ProcessExtensionGrantRequestAsync(request);\n        }\n    }\n\n    /// <summary>\n    /// Creates the response for an client credentials request.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    protected virtual Task<TokenResponse> ProcessClientCredentialsRequestAsync(TokenRequestValidationResult request)\n    {\n        Logger.LogTrace(\"Creating response for client credentials request\");\n\n        return ProcessTokenRequestAsync(request);\n    }\n\n    /// <summary>\n    /// Creates the response for a password request.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    protected virtual Task<TokenResponse> ProcessPasswordRequestAsync(TokenRequestValidationResult request)\n    {\n        Logger.LogTrace(\"Creating response for password request\");\n\n        return ProcessTokenRequestAsync(request);\n    }\n\n    /// <summary>\n    /// Creates the response for an authorization code request.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.InvalidOperationException\">Client does not exist anymore.</exception>\n    protected virtual async Task<TokenResponse> ProcessAuthorizationCodeRequestAsync(TokenRequestValidationResult request)\n    {\n        Logger.LogTrace(\"Creating response for authorization code request\");\n\n        //////////////////////////\n        // access token\n        /////////////////////////\n        var (accessToken, refreshToken) = await CreateAccessTokenAsync(request.ValidatedRequest);\n        var response = new TokenResponse\n        {\n            AccessToken = accessToken,\n            AccessTokenLifetime = request.ValidatedRequest.AccessTokenLifetime,\n            Custom = request.CustomResponse,\n            Scope = request.ValidatedRequest.AuthorizationCode.RequestedScopes.ToSpaceSeparatedString()\n        };\n\n        //////////////////////////\n        // refresh token\n        /////////////////////////\n        if (refreshToken.IsPresent())\n        {\n            response.RefreshToken = refreshToken;\n        }\n\n        //////////////////////////\n        // id token\n        /////////////////////////\n        if (request.ValidatedRequest.AuthorizationCode.IsOpenId)\n        {\n            // load the client that belongs to the authorization code\n            Client client = null;\n            if (request.ValidatedRequest.AuthorizationCode.ClientId != null)\n            {\n                client = await Clients.FindEnabledClientByIdAsync(request.ValidatedRequest.AuthorizationCode.ClientId);\n            }\n            if (client == null)\n            {\n                throw new InvalidOperationException(\"Client does not exist anymore.\");\n            }\n\n            var parsedScopesResult = ScopeParser.ParseScopeValues(request.ValidatedRequest.AuthorizationCode.RequestedScopes);\n            var validatedResources = await Resources.CreateResourceValidationResult(parsedScopesResult);\n\n            var tokenRequest = new TokenCreationRequest\n            {\n                Subject = request.ValidatedRequest.AuthorizationCode.Subject,\n                ValidatedResources = validatedResources,\n                Nonce = request.ValidatedRequest.AuthorizationCode.Nonce,\n                AccessTokenToHash = response.AccessToken,\n                StateHash = request.ValidatedRequest.AuthorizationCode.StateHash,\n                ValidatedRequest = request.ValidatedRequest\n            };\n\n            var idToken = await TokenService.CreateIdentityTokenAsync(tokenRequest);\n            var jwt = await TokenService.CreateSecurityTokenAsync(idToken);\n            response.IdentityToken = jwt;\n        }\n\n        return response;\n    }\n\n    /// <summary>\n    /// Creates the response for a refresh token request.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    protected virtual async Task<TokenResponse> ProcessRefreshTokenRequestAsync(TokenRequestValidationResult request)\n    {\n        Logger.LogTrace(\"Creating response for refresh token request\");\n\n        var oldAccessToken = request.ValidatedRequest.RefreshToken.AccessToken;\n        string accessTokenString;\n\n        if (request.ValidatedRequest.Client.UpdateAccessTokenClaimsOnRefresh)\n        {\n            var subject = request.ValidatedRequest.RefreshToken.Subject;\n\n            // todo: do we want to just parse here and build up validated result\n            // or do we want to fully re-run validation here.\n            var parsedScopesResult = ScopeParser.ParseScopeValues(oldAccessToken.Scopes);\n            var validatedResources = await Resources.CreateResourceValidationResult(parsedScopesResult);\n\n            var creationRequest = new TokenCreationRequest\n            {\n                Subject = subject,\n                Description = request.ValidatedRequest.RefreshToken.Description,\n                ValidatedRequest = request.ValidatedRequest,\n                ValidatedResources = validatedResources\n            };\n\n            var newAccessToken = await TokenService.CreateAccessTokenAsync(creationRequest);\n            accessTokenString = await TokenService.CreateSecurityTokenAsync(newAccessToken);\n        }\n        else\n        {\n            oldAccessToken.CreationTime = Clock.UtcNow.UtcDateTime;\n            oldAccessToken.Lifetime = request.ValidatedRequest.AccessTokenLifetime;\n\n            accessTokenString = await TokenService.CreateSecurityTokenAsync(oldAccessToken);\n        }\n\n        var handle = await RefreshTokenService.UpdateRefreshTokenAsync(request.ValidatedRequest.RefreshTokenHandle, request.ValidatedRequest.RefreshToken, request.ValidatedRequest.Client);\n\n        return new TokenResponse\n        {\n            IdentityToken = await CreateIdTokenFromRefreshTokenRequestAsync(request.ValidatedRequest, accessTokenString),\n            AccessToken = accessTokenString,\n            AccessTokenLifetime = request.ValidatedRequest.AccessTokenLifetime,\n            RefreshToken = handle,\n            Custom = request.CustomResponse,\n            Scope = request.ValidatedRequest.RefreshToken.Scopes.ToSpaceSeparatedString()\n        };\n    }\n\n    /// <summary>\n    /// Processes the response for device code grant request.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    protected virtual async Task<TokenResponse> ProcessDeviceCodeRequestAsync(TokenRequestValidationResult request)\n    {\n        Logger.LogTrace(\"Creating response for device code request\");\n\n        //////////////////////////\n        // access token\n        /////////////////////////\n        var (accessToken, refreshToken) = await CreateAccessTokenAsync(request.ValidatedRequest);\n        var response = new TokenResponse\n        {\n            AccessToken = accessToken,\n            AccessTokenLifetime = request.ValidatedRequest.AccessTokenLifetime,\n            Custom = request.CustomResponse,\n            Scope = request.ValidatedRequest.DeviceCode.AuthorizedScopes.ToSpaceSeparatedString()\n        };\n\n        //////////////////////////\n        // refresh token\n        /////////////////////////\n        if (refreshToken.IsPresent())\n        {\n            response.RefreshToken = refreshToken;\n        }\n\n        //////////////////////////\n        // id token\n        /////////////////////////\n        if (request.ValidatedRequest.DeviceCode.IsOpenId)\n        {\n            // load the client that belongs to the device code\n            Client client = null;\n            if (request.ValidatedRequest.DeviceCode.ClientId != null)\n            {\n                client = await Clients.FindEnabledClientByIdAsync(request.ValidatedRequest.DeviceCode.ClientId);\n            }\n            if (client == null)\n            {\n                throw new InvalidOperationException(\"Client does not exist anymore.\");\n            }\n\n            var parsedScopesResult = ScopeParser.ParseScopeValues(request.ValidatedRequest.DeviceCode.AuthorizedScopes);\n            var validatedResources = await Resources.CreateResourceValidationResult(parsedScopesResult);\n            \n            var tokenRequest = new TokenCreationRequest\n            {\n                Subject = request.ValidatedRequest.DeviceCode.Subject,\n                ValidatedResources = validatedResources,\n                AccessTokenToHash = response.AccessToken,\n                ValidatedRequest = request.ValidatedRequest\n            };\n\n            var idToken = await TokenService.CreateIdentityTokenAsync(tokenRequest);\n            var jwt = await TokenService.CreateSecurityTokenAsync(idToken);\n            response.IdentityToken = jwt;\n        }\n\n        return response;\n    }\n\n    /// <summary>\n    /// Creates the response for an extension grant request.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    protected virtual Task<TokenResponse> ProcessExtensionGrantRequestAsync(TokenRequestValidationResult request)\n    {\n        Logger.LogTrace(\"Creating response for extension grant request\");\n\n        return ProcessTokenRequestAsync(request);\n    }\n\n    /// <summary>\n    /// Creates the response for a token request.\n    /// </summary>\n    /// <param name=\"validationResult\">The validation result.</param>\n    /// <returns></returns>\n    protected virtual async Task<TokenResponse> ProcessTokenRequestAsync(TokenRequestValidationResult validationResult)\n    {\n        (var accessToken, var refreshToken) = await CreateAccessTokenAsync(validationResult.ValidatedRequest);\n        var response = new TokenResponse\n        {\n            AccessToken = accessToken,\n            AccessTokenLifetime = validationResult.ValidatedRequest.AccessTokenLifetime,\n            Custom = validationResult.CustomResponse,\n            Scope = validationResult.ValidatedRequest.ValidatedResources.RawScopeValues.ToSpaceSeparatedString()\n        };\n\n        if (refreshToken.IsPresent())\n        {\n            response.RefreshToken = refreshToken;\n        }\n\n        return response;\n    }\n\n    /// <summary>\n    /// Creates the access/refresh token.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.InvalidOperationException\">Client does not exist anymore.</exception>\n    protected virtual async Task<(string accessToken, string refreshToken)> CreateAccessTokenAsync(ValidatedTokenRequest request)\n    {\n        TokenCreationRequest tokenRequest;\n        bool createRefreshToken;\n\n        if (request.AuthorizationCode != null)\n        {\n            createRefreshToken = request.AuthorizationCode.RequestedScopes.Contains(IdentityServerConstants.StandardScopes.OfflineAccess);\n\n            // load the client that belongs to the authorization code\n            Client client = null;\n            if (request.AuthorizationCode.ClientId != null)\n            {\n                client = await Clients.FindEnabledClientByIdAsync(request.AuthorizationCode.ClientId);\n            }\n            if (client == null)\n            {\n                throw new InvalidOperationException(\"Client does not exist anymore.\");\n            }\n\n            var parsedScopesResult = ScopeParser.ParseScopeValues(request.AuthorizationCode.RequestedScopes);\n            var validatedResources = await Resources.CreateResourceValidationResult(parsedScopesResult);\n\n            tokenRequest = new TokenCreationRequest\n            {\n                Subject = request.AuthorizationCode.Subject,\n                Description = request.AuthorizationCode.Description,\n                ValidatedResources = validatedResources,\n                ValidatedRequest = request\n            };\n        }\n        else if (request.DeviceCode != null)\n        {\n            createRefreshToken = request.DeviceCode.AuthorizedScopes.Contains(IdentityServerConstants.StandardScopes.OfflineAccess);\n\n            Client client = null;\n            if (request.DeviceCode.ClientId != null)\n            {\n                client = await Clients.FindEnabledClientByIdAsync(request.DeviceCode.ClientId);\n            }\n            if (client == null)\n            {\n                throw new InvalidOperationException(\"Client does not exist anymore.\");\n            }\n\n            var parsedScopesResult = ScopeParser.ParseScopeValues(request.DeviceCode.AuthorizedScopes);\n            var validatedResources = await Resources.CreateResourceValidationResult(parsedScopesResult);\n\n            tokenRequest = new TokenCreationRequest\n            {\n                Subject = request.DeviceCode.Subject,\n                Description = request.DeviceCode.Description,\n                ValidatedResources = validatedResources,\n                ValidatedRequest = request\n            };\n        }\n        else\n        {\n            createRefreshToken = request.ValidatedResources.Resources.OfflineAccess;\n\n            tokenRequest = new TokenCreationRequest\n            {\n                Subject = request.Subject,\n                ValidatedResources = request.ValidatedResources,\n                ValidatedRequest = request\n            };\n        }\n\n        var at = await TokenService.CreateAccessTokenAsync(tokenRequest);\n        var accessToken = await TokenService.CreateSecurityTokenAsync(at);\n\n        if (createRefreshToken)\n        {\n            var refreshToken = await RefreshTokenService.CreateRefreshTokenAsync(tokenRequest.Subject, at, request.Client);\n            return (accessToken, refreshToken);\n        }\n\n        return (accessToken, null);\n    }\n\n    /// <summary>\n    /// Creates an id_token for a refresh token request if identity resources have been requested.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"newAccessToken\">The new access token.</param>\n    /// <returns></returns>\n    protected virtual async Task<string> CreateIdTokenFromRefreshTokenRequestAsync(ValidatedTokenRequest request, string newAccessToken)\n    {\n        // todo: can we just check for \"openid\" scope?\n        //var identityResources = await Resources.FindEnabledIdentityResourcesByScopeAsync(request.RefreshToken.Scopes);\n        //if (identityResources.Any())\n        \n        if (request.RefreshToken.Scopes.Contains(OidcConstants.StandardScopes.OpenId))\n        {\n            var oldAccessToken = request.RefreshToken.AccessToken;\n\n            var parsedScopesResult = ScopeParser.ParseScopeValues(oldAccessToken.Scopes);\n            var validatedResources = await Resources.CreateResourceValidationResult(parsedScopesResult);\n\n            var tokenRequest = new TokenCreationRequest\n            {\n                Subject = request.RefreshToken.Subject,\n                ValidatedResources = validatedResources,\n                ValidatedRequest = request,\n                AccessTokenToHash = newAccessToken\n            };\n\n            var idToken = await TokenService.CreateIdentityTokenAsync(tokenRequest);\n            return await TokenService.CreateSecurityTokenAsync(idToken);\n        }\n\n        return null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Default/TokenRevocationResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Default revocation response generator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.ResponseHandling.ITokenRevocationResponseGenerator\" />\npublic class TokenRevocationResponseGenerator : ITokenRevocationResponseGenerator\n{\n    /// <summary>\n    /// Gets the reference token store.\n    /// </summary>\n    /// <value>\n    /// The reference token store.\n    /// </value>\n    protected readonly IReferenceTokenStore ReferenceTokenStore;\n\n    /// <summary>\n    /// Gets the refresh token store.\n    /// </summary>\n    /// <value>\n    /// The refresh token store.\n    /// </value>\n    protected readonly IRefreshTokenStore RefreshTokenStore;\n\n    /// <summary>\n    /// Gets the logger.\n    /// </summary>\n    /// <value>\n    /// The logger.\n    /// </value>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenRevocationResponseGenerator\" /> class.\n    /// </summary>\n    /// <param name=\"referenceTokenStore\">The reference token store.</param>\n    /// <param name=\"refreshTokenStore\">The refresh token store.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public TokenRevocationResponseGenerator(IReferenceTokenStore referenceTokenStore, IRefreshTokenStore refreshTokenStore, ILogger<TokenRevocationResponseGenerator> logger)\n    {\n        ReferenceTokenStore = referenceTokenStore;\n        RefreshTokenStore = refreshTokenStore;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Creates the revocation endpoint response and processes the revocation request.\n    /// </summary>\n    /// <param name=\"validationResult\">The userinfo request validation result.</param>\n    /// <returns></returns>\n    public virtual async Task<TokenRevocationResponse> ProcessAsync(TokenRevocationRequestValidationResult validationResult)\n    {\n        var response = new TokenRevocationResponse\n        {\n            Success = false,\n            TokenType = validationResult.TokenTypeHint\n        };\n\n        // revoke tokens\n        if (validationResult.TokenTypeHint == Constants.TokenTypeHints.AccessToken)\n        {\n            Logger.LogTrace(\"Hint was for access token\");\n            response.Success = await RevokeAccessTokenAsync(validationResult);\n        }\n        else if (validationResult.TokenTypeHint == Constants.TokenTypeHints.RefreshToken)\n        {\n            Logger.LogTrace(\"Hint was for refresh token\");\n            response.Success = await RevokeRefreshTokenAsync(validationResult);\n        }\n        else\n        {\n            Logger.LogTrace(\"No hint for token type\");\n\n            response.Success = await RevokeAccessTokenAsync(validationResult);\n\n            if (!response.Success)\n            {\n                response.Success = await RevokeRefreshTokenAsync(validationResult);\n                response.TokenType = Constants.TokenTypeHints.RefreshToken;\n            }\n            else\n            {\n                response.TokenType = Constants.TokenTypeHints.AccessToken;\n            }\n        }\n\n        return response;\n    }\n\n    /// <summary>\n    /// Revoke access token only if it belongs to client doing the request.\n    /// </summary>\n    protected virtual async Task<bool> RevokeAccessTokenAsync(TokenRevocationRequestValidationResult validationResult)\n    {\n        var token = await ReferenceTokenStore.GetReferenceTokenAsync(validationResult.Token);\n\n        if (token != null)\n        {\n            if (token.ClientId == validationResult.Client.ClientId)\n            {\n                Logger.LogDebug(\"Access token revoked\");\n                await ReferenceTokenStore.RemoveReferenceTokenAsync(validationResult.Token);\n            }\n            else\n            {\n                Logger.LogWarning(\"Client {clientId} denied from revoking access token belonging to Client {tokenClientId}\", validationResult.Client.ClientId, token.ClientId);\n            }\n\n            return true;\n        }\n\n        return false;\n    }\n\n    /// <summary>\n    /// Revoke refresh token only if it belongs to client doing the request\n    /// </summary>\n    protected virtual async Task<bool> RevokeRefreshTokenAsync(TokenRevocationRequestValidationResult validationResult)\n    {\n        var token = await RefreshTokenStore.GetRefreshTokenAsync(validationResult.Token);\n\n        if (token != null)\n        {\n            if (token.ClientId == validationResult.Client.ClientId)\n            {\n                Logger.LogDebug(\"Refresh token revoked\");\n                await RefreshTokenStore.RemoveRefreshTokenAsync(validationResult.Token);\n                await ReferenceTokenStore.RemoveReferenceTokensAsync(token.SubjectId, token.ClientId);\n            }\n            else\n            {\n                Logger.LogWarning(\"Client {clientId} denied from revoking a refresh token belonging to Client {tokenClientId}\", validationResult.Client.ClientId, token.ClientId);\n            }\n\n            return true;\n        }\n\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Default/UserInfoResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// The userinfo response generator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.ResponseHandling.IUserInfoResponseGenerator\" />\npublic class UserInfoResponseGenerator : IUserInfoResponseGenerator\n{\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// The profile service\n    /// </summary>\n    protected readonly IProfileService Profile;\n\n    /// <summary>\n    /// The resource store\n    /// </summary>\n    protected readonly IResourceStore Resources;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"UserInfoResponseGenerator\"/> class.\n    /// </summary>\n    /// <param name=\"profile\">The profile.</param>\n    /// <param name=\"resourceStore\">The resource store.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public UserInfoResponseGenerator(IProfileService profile, IResourceStore resourceStore, ILogger<UserInfoResponseGenerator> logger)\n    {\n        Profile = profile;\n        Resources = resourceStore;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Creates the response.\n    /// </summary>\n    /// <param name=\"validationResult\">The userinfo request validation result.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.InvalidOperationException\">Profile service returned incorrect subject value</exception>\n    public virtual async Task<Dictionary<string, object>> ProcessAsync(UserInfoRequestValidationResult validationResult)\n    {\n        Logger.LogDebug(\"Creating userinfo response\");\n\n        // extract scopes and turn into requested claim types\n        var scopes = validationResult.TokenValidationResult.Claims.Where(c => c.Type == JwtClaimTypes.Scope).Select(c => c.Value);\n\n        var validatedResources = await GetRequestedResourcesAsync(scopes);\n        var requestedClaimTypes = await GetRequestedClaimTypesAsync(validatedResources);\n\n        Logger.LogDebug(\"Requested claim types: {claimTypes}\", requestedClaimTypes.ToSpaceSeparatedString());\n\n        // call profile service\n        var context = new ProfileDataRequestContext(\n            validationResult.Subject,\n            validationResult.TokenValidationResult.Client,\n            IdentityServerConstants.ProfileDataCallers.UserInfoEndpoint,\n            requestedClaimTypes);\n        context.RequestedResources = validatedResources;\n\n        await Profile.GetProfileDataAsync(context);\n        var profileClaims = context.IssuedClaims;\n\n        // construct outgoing claims\n        var outgoingClaims = new List<Claim>();\n\n        if (profileClaims == null)\n        {\n            Logger.LogInformation(\"Profile service returned no claims (null)\");\n        }\n        else\n        {\n            outgoingClaims.AddRange(profileClaims);\n            Logger.LogInformation(\"Profile service returned the following claim types: {types}\", profileClaims.Select(c => c.Type).ToSpaceSeparatedString());\n        }\n\n        var subClaim = outgoingClaims.SingleOrDefault(x => x.Type == JwtClaimTypes.Subject);\n        if (subClaim == null)\n        {\n            outgoingClaims.Add(new Claim(JwtClaimTypes.Subject, validationResult.Subject.GetSubjectId()));\n        }\n        else if (subClaim.Value != validationResult.Subject.GetSubjectId())\n        {\n            Logger.LogError(\"Profile service returned incorrect subject value: {sub}\", subClaim);\n            throw new InvalidOperationException(\"Profile service returned incorrect subject value\");\n        }\n\n        return outgoingClaims.ToClaimsDictionary();\n    }\n\n    /// <summary>\n    ///  Gets the identity resources from the scopes.\n    /// </summary>\n    /// <param name=\"scopes\"></param>\n    /// <returns></returns>\n    protected internal virtual async Task<ResourceValidationResult> GetRequestedResourcesAsync(IEnumerable<string> scopes)\n    {\n        if (scopes == null || !scopes.Any())\n        {\n            return null;\n        }\n\n        var scopeString = string.Join(\" \", scopes);\n        Logger.LogDebug(\"Scopes in access token: {scopes}\", scopeString);\n\n        // if we ever parameterize identity scopes, then we would need to invoke the resource validator's parse API here\n        var identityResources = await Resources.FindEnabledIdentityResourcesByScopeAsync(scopes);\n        \n        var resources = new Resources(identityResources, Enumerable.Empty<ApiResource>(), Enumerable.Empty<ApiScope>());\n        var result = new ResourceValidationResult(resources);\n        \n        return result;\n    }\n\n    /// <summary>\n    /// Gets the requested claim types.\n    /// </summary>\n    /// <param name=\"resourceValidationResult\"></param>\n    /// <returns></returns>\n    protected internal virtual Task<IEnumerable<string>> GetRequestedClaimTypesAsync(ResourceValidationResult resourceValidationResult)\n    {\n        IEnumerable<string> result = null;\n\n        if (resourceValidationResult == null)\n        {\n            result = Enumerable.Empty<string>();\n        }\n        else\n        {\n            var identityResources = resourceValidationResult.Resources.IdentityResources;\n            result = identityResources.SelectMany(x => x.UserClaims).Distinct();\n        }\n\n        return Task.FromResult(result);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/IAuthorizeInteractionResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Interface for determining if user must login or consent when making requests to the authorization endpoint.\n/// </summary>\npublic interface IAuthorizeInteractionResponseGenerator\n{\n    /// <summary>\n    /// Processes the interaction logic.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"consent\">The consent.</param>\n    /// <returns></returns>\n    Task<InteractionResponse> ProcessInteractionAsync(ValidatedAuthorizeRequest request, ConsentResponse consent = null);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/IAuthorizeResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Interface for the authorize response generator\n/// </summary>\npublic interface IAuthorizeResponseGenerator\n{\n    /// <summary>\n    /// Creates the response\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    Task<AuthorizeResponse> CreateResponseAsync(ValidatedAuthorizeRequest request);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/IDeviceAuthorizationResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Interface for the device authorization response generator\n/// </summary>\npublic interface IDeviceAuthorizationResponseGenerator\n{\n    /// <summary>\n    /// Processes the response.\n    /// </summary>\n    /// <param name=\"validationResult\">The validation result.</param>\n    /// <param name=\"baseUrl\">The base URL.</param>\n    /// <returns></returns>\n    Task<DeviceAuthorizationResponse> ProcessAsync(DeviceAuthorizationRequestValidationResult validationResult, string baseUrl);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/IDiscoveryResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Interface for discovery endpoint response generator\n/// </summary>\npublic interface IDiscoveryResponseGenerator\n{\n    /// <summary>\n    /// Creates the discovery document.\n    /// </summary>\n    /// <param name=\"baseUrl\">The base URL.</param>\n    /// <param name=\"issuerUri\">The issuer URI.</param>\n    Task<Dictionary<string, object>> CreateDiscoveryDocumentAsync(string baseUrl, string issuerUri);\n\n    /// <summary>\n    /// Creates the JWK document.\n    /// </summary>\n    Task<IEnumerable<JsonWebKey>> CreateJwkDocumentAsync();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/IIntrospectionResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Interface for introspection response generator\n/// </summary>\npublic interface IIntrospectionResponseGenerator\n{\n    /// <summary>\n    /// Processes the response.\n    /// </summary>\n    /// <param name=\"validationResult\">The validation result.</param>\n    /// <returns></returns>\n    Task<Dictionary<string, object>> ProcessAsync(IntrospectionRequestValidationResult validationResult);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/ITokenResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Interface the token response generator\n/// </summary>\npublic interface ITokenResponseGenerator\n{\n    /// <summary>\n    /// Processes the response.\n    /// </summary>\n    /// <param name=\"validationResult\">The validation result.</param>\n    /// <returns></returns>\n    Task<TokenResponse> ProcessAsync(TokenRequestValidationResult validationResult);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/ITokenRevocationResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Interface for the userinfo response generator\n/// </summary>\npublic interface ITokenRevocationResponseGenerator\n{\n    /// <summary>\n    /// Creates the revocation endpoint response and processes the revocation request.\n    /// </summary>\n    /// <param name=\"validationResult\">The userinfo request validation result.</param>\n    /// <returns></returns>\n    Task<TokenRevocationResponse> ProcessAsync(TokenRevocationRequestValidationResult validationResult);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/IUserInfoResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Interface for the userinfo response generator\n/// </summary>\npublic interface IUserInfoResponseGenerator\n{\n    /// <summary>\n    /// Creates the response.\n    /// </summary>\n    /// <param name=\"validationResult\">The userinfo request validation result.</param>\n    /// <returns></returns>\n    Task<Dictionary<string, object>> ProcessAsync(UserInfoRequestValidationResult validationResult);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Models/AuthorizeResponse.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.ResponseHandling;\n\npublic class AuthorizeResponse\n{\n    public ValidatedAuthorizeRequest Request { get; set; }\n    public string RedirectUri => Request?.RedirectUri;\n    public string State => Request?.State;\n    public string Scope => Request?.ValidatedResources?.RawScopeValues.ToSpaceSeparatedString();\n\n    public string IdentityToken { get; set; }\n    public string AccessToken { get; set; }\n    public int AccessTokenLifetime { get; set; }\n    public string Code { get; set; }\n    public string SessionState { get; set; }\n\n    public string Error { get; set; }\n    public string ErrorDescription { get; set; }\n    public bool IsError => Error.IsPresent();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Models/DeviceAuthorizationResponse.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.ResponseHandling;\n\npublic class DeviceAuthorizationResponse\n{\n    public string DeviceCode { get; set; }\n    public string UserCode { get; set; }\n    public string VerificationUri { get; set; }\n\n    public string VerificationUriComplete { get; set; }\n    public int DeviceCodeLifetime { get; set; }\n    public int Interval { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Models/InteractionResponse.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Indicates interaction outcome for user on authorization endpoint.\n/// </summary>\npublic class InteractionResponse\n{\n    /// <summary>\n    /// Gets or sets a value indicating whether the user must login.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if this instance is login; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsLogin { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the user must consent.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if this instance is consent; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsConsent { get; set; }\n\n    /// <summary>\n    /// Gets a value indicating whether the result is an error.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if this instance is error; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsError => Error != null;\n\n    /// <summary>\n    /// Gets or sets the error.\n    /// </summary>\n    /// <value>\n    /// The error.\n    /// </value>\n    public string Error { get; set; }\n\n    /// <summary>\n    /// Gets or sets the error description.\n    /// </summary>\n    /// <value>\n    /// The error description.\n    /// </value>\n    public string ErrorDescription { get; set; }\n\n    /// <summary>\n    /// Gets a value indicating whether the user must be redirected to a custom page.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if this instance is redirect; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsRedirect => RedirectUrl.IsPresent();\n\n    /// <summary>\n    /// Gets or sets the URL for the custom page.\n    /// </summary>\n    /// <value>\n    /// The redirect URL.\n    /// </value>\n    public string RedirectUrl { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Models/TokenErrorResponse.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Models a token error response\n/// </summary>\npublic class TokenErrorResponse\n{\n    /// <summary>\n    /// Gets or sets the error.\n    /// </summary>\n    /// <value>\n    /// The error.\n    /// </value>\n    public string Error { get; set; } = OidcConstants.TokenErrors.InvalidRequest;\n\n    /// <summary>\n    /// Gets or sets the error description.\n    /// </summary>\n    /// <value>\n    /// The error description.\n    /// </value>\n    public string ErrorDescription { get; set; }\n\n    /// <summary>\n    /// Gets or sets the custom entries.\n    /// </summary>\n    /// <value>\n    /// The custom.\n    /// </value>\n    public Dictionary<string, object> Custom { get; set; } = new Dictionary<string, object>();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Models/TokenResponse.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Models a token response\n/// </summary>\npublic class TokenResponse\n{\n    /// <summary>\n    /// Gets or sets the identity token.\n    /// </summary>\n    /// <value>\n    /// The identity token.\n    /// </value>\n    public string IdentityToken { get; set; }\n\n    /// <summary>\n    /// Gets or sets the access token.\n    /// </summary>\n    /// <value>\n    /// The access token.\n    /// </value>\n    public string AccessToken { get; set; }\n\n    /// <summary>\n    /// Gets or sets the access token lifetime.\n    /// </summary>\n    /// <value>\n    /// The access token lifetime.\n    /// </value>\n    public int AccessTokenLifetime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the refresh token.\n    /// </summary>\n    /// <value>\n    /// The refresh token.\n    /// </value>\n    public string RefreshToken { get; set; }\n\n    /// <summary>\n    /// Gets or sets the scope.\n    /// </summary>\n    /// <value>\n    /// The scope.\n    /// </value>\n    public string Scope { get; set; }\n\n    /// <summary>\n    /// Gets or sets the custom entries.\n    /// </summary>\n    /// <value>\n    /// The custom entries.\n    /// </value>\n    public Dictionary<string, object> Custom { get; set; } = new Dictionary<string, object>();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/ResponseHandling/Models/TokenRevocationResponse.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.ResponseHandling;\n\n/// <summary>\n/// Models a token revocation response\n/// </summary>\npublic class TokenRevocationResponse\n{\n    /// <summary>\n    /// Gets or sets a value indicating whether the token revocation was successful.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if success; otherwise, <c>false</c>.\n    /// </value>\n    public bool Success { get; set; }\n\n    /// <summary>\n    /// Gets or sets the type of the token that was revoked.\n    /// </summary>\n    /// <value>\n    /// The type of the token.\n    /// </value>\n    public string TokenType { get; set; }\n\n    /// <summary>\n    /// Gets or sets an error (if present).\n    /// </summary>\n    /// <value>\n    /// The error.\n    /// </value>\n    public string Error { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/BackChannelLogoutHttpClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Models making HTTP requests for back-channel logout notification.\n/// </summary>\npublic class DefaultBackChannelLogoutHttpClient : IBackChannelLogoutHttpClient\n{\n    private readonly HttpClient _client;\n    private readonly ILogger<DefaultBackChannelLogoutHttpClient> _logger;\n\n    /// <summary>\n    /// Constructor for BackChannelLogoutHttpClient.\n    /// </summary>\n    /// <param name=\"client\"></param>\n    /// <param name=\"loggerFactory\"></param>\n    public DefaultBackChannelLogoutHttpClient(HttpClient client, ILoggerFactory loggerFactory)\n    {\n        _client = client;\n        _logger = loggerFactory.CreateLogger<DefaultBackChannelLogoutHttpClient>();\n    }\n\n    /// <summary>\n    /// Posts the payload to the url.\n    /// </summary>\n    /// <param name=\"url\"></param>\n    /// <param name=\"payload\"></param>\n    /// <returns></returns>\n    public async Task PostAsync(string url, Dictionary<string, string> payload)\n    {\n        try\n        {\n            var response = await _client.PostAsync(url, new FormUrlEncodedContent(payload));\n            if (response.IsSuccessStatusCode)\n            {\n                _logger.LogDebug(\"Response from back-channel logout endpoint: {url} status code: {status}\", url, (int)response.StatusCode);\n            }\n            else\n            {\n                _logger.LogWarning(\"Response from back-channel logout endpoint: {url} status code: {status}\", url, (int)response.StatusCode);\n            }\n        }\n        catch (Exception ex)\n        {\n            _logger.LogError(ex, \"Exception invoking back-channel logout for url: {url}\", url);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultBackChannelLogoutService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default back-channel logout notification implementation.\n/// </summary>\npublic class DefaultBackChannelLogoutService : IBackChannelLogoutService\n{\n    /// <summary>\n    /// Default value for the back-channel JWT lifetime.\n    /// </summary>\n    protected const int DefaultLogoutTokenLifetime = 5 * 60;\n\n    /// <summary>\n    /// The system clock;\n    /// </summary>\n    protected ISystemClock Clock { get; }\n    \n    /// <summary>\n    /// The IdentityServerTools used to create and the JWT.\n    /// </summary>\n    protected IdentityServerTools Tools { get; }\n\n    /// <summary>\n    /// The ILogoutNotificationService to build the back channel logout requests.\n    /// </summary>\n    public ILogoutNotificationService LogoutNotificationService { get; }\n\n    /// <summary>\n    /// HttpClient to make the outbound HTTP calls.\n    /// </summary>\n    protected IBackChannelLogoutHttpClient HttpClient { get; }\n\n    /// <summary>\n    /// The logger.\n    /// </summary>\n    protected ILogger<IBackChannelLogoutService> Logger { get; }\n\n    /// <summary>\n    /// Constructor.\n    /// </summary>\n    /// <param name=\"clock\"></param>\n    /// <param name=\"tools\"></param>\n    /// <param name=\"logoutNotificationService\"></param>\n    /// <param name=\"backChannelLogoutHttpClient\"></param>\n    /// <param name=\"logger\"></param>\n    public DefaultBackChannelLogoutService(\n        ISystemClock clock,\n        IdentityServerTools tools,\n        ILogoutNotificationService logoutNotificationService,\n        IBackChannelLogoutHttpClient backChannelLogoutHttpClient,\n        ILogger<IBackChannelLogoutService> logger)\n    {\n        Clock = clock;\n        Tools = tools;\n        LogoutNotificationService = logoutNotificationService;\n        HttpClient = backChannelLogoutHttpClient;\n        Logger = logger;\n    }\n\n    /// <inheritdoc/>\n    public virtual async Task SendLogoutNotificationsAsync(LogoutNotificationContext context)\n    {\n        var backChannelRequests = await LogoutNotificationService.GetBackChannelLogoutNotificationsAsync(context);\n        if (backChannelRequests.Any())\n        {\n            await SendLogoutNotificationsAsync(backChannelRequests);\n        }\n    }\n\n    /// <summary>\n    /// Sends the logout notifications for the collection of clients.\n    /// </summary>\n    /// <param name=\"requests\"></param>\n    /// <returns></returns>\n    protected virtual Task SendLogoutNotificationsAsync(IEnumerable<BackChannelLogoutRequest> requests)\n    {\n        requests = requests ?? Enumerable.Empty<BackChannelLogoutRequest>();\n        var tasks = requests.Select(SendLogoutNotificationAsync).ToArray();\n        return Task.WhenAll(tasks);\n    }\n\n    /// <summary>\n    /// Performs the back-channel logout for a single client.\n    /// </summary>\n    /// <param name=\"request\"></param>\n    protected virtual async Task SendLogoutNotificationAsync(BackChannelLogoutRequest request)\n    {\n        var data = await CreateFormPostPayloadAsync(request);\n        await PostLogoutJwt(request, data);\n    }\n\n    /// <summary>\n    /// Performs the HTTP POST of the logout payload to the client.\n    /// </summary>\n    /// <param name=\"client\"></param>\n    /// <param name=\"data\"></param>\n    /// <returns></returns>\n    protected virtual Task PostLogoutJwt(BackChannelLogoutRequest client, Dictionary<string, string> data)\n    {\n        return HttpClient.PostAsync(client.LogoutUri, data);\n    }\n\n    /// <summary>\n    /// Creates the form-url-encoded payload (as a dictionary) to send to the client.\n    /// </summary>\n    /// <param name=\"request\"></param>\n    /// <returns></returns>\n    protected async Task<Dictionary<string, string>> CreateFormPostPayloadAsync(BackChannelLogoutRequest request)\n    {\n        var token = await CreateTokenAsync(request);\n\n        var data = new Dictionary<string, string>\n        {\n            { OidcConstants.BackChannelLogoutRequest.LogoutToken, token }\n        };\n        return data;\n    }\n\n    /// <summary>\n    /// Creates the JWT used for the back-channel logout notification.\n    /// </summary>\n    /// <param name=\"request\"></param>\n    /// <returns>The token.</returns>\n    protected virtual async Task<string> CreateTokenAsync(BackChannelLogoutRequest request)\n    {\n        var claims = await CreateClaimsForTokenAsync(request);\n        if (claims.Any(x => x.Type == JwtClaimTypes.Nonce))\n        {\n            throw new InvalidOperationException(\"nonce claim is not allowed in the back-channel signout token.\");\n        }\n\n        return await Tools.IssueJwtAsync(DefaultLogoutTokenLifetime, claims);\n    }\n\n    /// <summary>\n    /// Create the claims to be used in the back-channel logout token.\n    /// </summary>\n    /// <param name=\"request\"></param>\n    /// <returns>The claims to include in the token.</returns>\n    protected Task<IEnumerable<Claim>> CreateClaimsForTokenAsync(BackChannelLogoutRequest request)\n    {\n        if (request.SessionIdRequired && request.SessionId == null)\n        {\n            throw new ArgumentException(\"Client requires SessionId\", nameof(request.SessionId));\n        }\n\n        var json = \"{\\\"\" + OidcConstants.Events.BackChannelLogout + \"\\\":{} }\";\n\n        var claims = new List<Claim>\n        {\n            new Claim(JwtClaimTypes.Subject, request.SubjectId),\n            new Claim(JwtClaimTypes.Audience, request.ClientId),\n            new Claim(JwtClaimTypes.IssuedAt, Clock.UtcNow.ToUnixTimeSeconds().ToString(), ClaimValueTypes.Integer64),\n            new Claim(JwtClaimTypes.JwtId, CryptoRandom.CreateUniqueId(16, CryptoRandom.OutputFormat.Hex)),\n            new Claim(JwtClaimTypes.Events, json, IdentityServerConstants.ClaimValueTypes.Json)\n        };\n\n        if (request.SessionId != null)\n        {\n            claims.Add(new Claim(JwtClaimTypes.SessionId, request.SessionId));\n        }\n\n        return Task.FromResult(claims.AsEnumerable());\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultCache.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// IMemoryCache-based implementation of the cache\n/// </summary>\n/// <typeparam name=\"T\"></typeparam>\n/// <seealso cref=\"IdentityServer8.Services.ICache{T}\" />\npublic class DefaultCache<T> : ICache<T>\n    where T : class\n{\n    private const string KeySeparator = \":\";\n\n    private readonly IMemoryCache _cache;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultCache{T}\"/> class.\n    /// </summary>\n    /// <param name=\"cache\">The cache.</param>\n    public DefaultCache(IMemoryCache cache)\n    {\n        _cache = cache;\n    }\n\n    private string GetKey(string key)\n    {\n        return typeof(T).FullName + KeySeparator + key;\n    }\n\n    /// <summary>\n    /// Gets the cached data based upon a key index.\n    /// </summary>\n    /// <param name=\"key\">The key.</param>\n    /// <returns>\n    /// The cached item, or <c>null</c> if no item matches the key.\n    /// </returns>\n    public Task<T> GetAsync(string key)\n    {\n        key = GetKey(key);\n        var item = _cache.Get<T>(key);\n        return Task.FromResult(item);\n    }\n\n    /// <summary>\n    /// Caches the data based upon a key\n    /// </summary>\n    /// <param name=\"key\">The key.</param>\n    /// <param name=\"item\">The item.</param>\n    /// <param name=\"expiration\">The expiration.</param>\n    /// <returns></returns>\n    public Task SetAsync(string key, T item, TimeSpan expiration)\n    {\n        key = GetKey(key);\n        _cache.Set(key, item, expiration);\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultClaimsService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default claims provider implementation\n/// </summary>\npublic class DefaultClaimsService : IClaimsService\n{\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// The user service\n    /// </summary>\n    protected readonly IProfileService Profile;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultClaimsService\"/> class.\n    /// </summary>\n    /// <param name=\"profile\">The profile service</param>\n    /// <param name=\"logger\">The logger</param>\n    public DefaultClaimsService(IProfileService profile, ILogger<DefaultClaimsService> logger)\n    {\n        Logger = logger;\n        Profile = profile;\n    }\n\n    /// <summary>\n    /// Returns claims for an identity token\n    /// </summary>\n    /// <param name=\"subject\">The subject</param>\n    /// <param name=\"resources\">The requested resources</param>\n    /// <param name=\"includeAllIdentityClaims\">Specifies if all claims should be included in the token, or if the userinfo endpoint can be used to retrieve them</param>\n    /// <param name=\"request\">The raw request</param>\n    /// <returns>\n    /// Claims for the identity token\n    /// </returns>\n    public virtual async Task<IEnumerable<Claim>> GetIdentityTokenClaimsAsync(ClaimsPrincipal subject, ResourceValidationResult resources, bool includeAllIdentityClaims, ValidatedRequest request)\n    {\n        Logger.LogDebug(\"Getting claims for identity token for subject: {subject} and client: {clientId}\",\n            subject.GetSubjectId(),\n            request.Client.ClientId);\n\n        var outputClaims = new List<Claim>(GetStandardSubjectClaims(subject));\n        outputClaims.AddRange(GetOptionalClaims(subject));\n\n        // fetch all identity claims that need to go into the id token\n        if (includeAllIdentityClaims || request.Client.AlwaysIncludeUserClaimsInIdToken)\n        {\n            var additionalClaimTypes = new List<string>();\n\n            foreach (var identityResource in resources.Resources.IdentityResources)\n            {\n                foreach (var userClaim in identityResource.UserClaims)\n                {\n                    additionalClaimTypes.Add(userClaim);\n                }\n            }\n\n            // filter so we don't ask for claim types that we will eventually filter out\n            additionalClaimTypes = FilterRequestedClaimTypes(additionalClaimTypes).ToList();\n\n            var context = new ProfileDataRequestContext(\n                subject,\n                request.Client,\n                IdentityServerConstants.ProfileDataCallers.ClaimsProviderIdentityToken,\n                additionalClaimTypes)\n            {\n                RequestedResources = resources,\n                ValidatedRequest = request\n            };\n\n            await Profile.GetProfileDataAsync(context);\n\n            var claims = FilterProtocolClaims(context.IssuedClaims);\n            if (claims != null)\n            {\n                outputClaims.AddRange(claims);\n            }\n        }\n        else\n        {\n            Logger.LogDebug(\"In addition to an id_token, an access_token was requested. No claims other than sub are included in the id_token. To obtain more user claims, either use the user info endpoint or set AlwaysIncludeUserClaimsInIdToken on the client configuration.\");\n        }\n\n        return outputClaims;\n    }\n\n    /// <summary>\n    /// Returns claims for an access token.\n    /// </summary>\n    /// <param name=\"subject\">The subject.</param>\n    /// <param name=\"resourceResult\">The validated resource result</param>\n    /// <param name=\"request\">The raw request.</param>\n    /// <returns>\n    /// Claims for the access token\n    /// </returns>\n    public virtual async Task<IEnumerable<Claim>> GetAccessTokenClaimsAsync(ClaimsPrincipal subject, ResourceValidationResult resourceResult, ValidatedRequest request)\n    {\n        Logger.LogDebug(\"Getting claims for access token for client: {clientId}\", request.Client.ClientId);\n\n        var outputClaims = new List<Claim>\n        {\n            new Claim(JwtClaimTypes.ClientId, request.ClientId)\n        };\n\n        // log if client ID is overwritten\n        if (!string.Equals(request.ClientId, request.Client.ClientId))\n        {\n            Logger.LogDebug(\"Client {clientId} is impersonating {impersonatedClientId}\", request.Client.ClientId, request.ClientId);\n        }\n\n        // check for client claims\n        if (request.ClientClaims != null && request.ClientClaims.Any())\n        {\n            if (subject == null || request.Client.AlwaysSendClientClaims)\n            {\n                foreach (var claim in request.ClientClaims)\n                {\n                    var claimType = claim.Type;\n\n                    if (request.Client.ClientClaimsPrefix.IsPresent())\n                    {\n                        claimType = request.Client.ClientClaimsPrefix + claimType;\n                    }\n\n                    outputClaims.Add(new Claim(claimType, claim.Value, claim.ValueType));\n                }\n            }\n        }\n\n        // add scopes (filter offline_access)\n        // we use the ScopeValues collection rather than the Resources.Scopes because we support dynamic scope values \n        // from the request, so this issues those in the token.\n        foreach (var scope in resourceResult.RawScopeValues.Where(x => x != IdentityServerConstants.StandardScopes.OfflineAccess))\n        {\n            outputClaims.Add(new Claim(JwtClaimTypes.Scope, scope));\n        }\n\n        // a user is involved\n        if (subject != null)\n        {\n            if (resourceResult.Resources.OfflineAccess)\n            {\n                outputClaims.Add(new Claim(JwtClaimTypes.Scope, IdentityServerConstants.StandardScopes.OfflineAccess));\n            }\n\n            Logger.LogDebug(\"Getting claims for access token for subject: {subject}\", subject.GetSubjectId());\n\n            outputClaims.AddRange(GetStandardSubjectClaims(subject));\n            outputClaims.AddRange(GetOptionalClaims(subject));\n\n            // fetch all resource claims that need to go into the access token\n            var additionalClaimTypes = new List<string>();\n            foreach (var api in resourceResult.Resources.ApiResources)\n            {\n                // add claims configured on api resource\n                if (api.UserClaims != null)\n                {\n                    foreach (var claim in api.UserClaims)\n                    {\n                        additionalClaimTypes.Add(claim);\n                    }\n                }\n            }\n\n            foreach(var scope in resourceResult.Resources.ApiScopes)\n            {\n                // add claims configured on scopes\n                if (scope.UserClaims != null)\n                {\n                    foreach (var claim in scope.UserClaims)\n                    {\n                        additionalClaimTypes.Add(claim);\n                    }\n                }\n            }\n\n            // filter so we don't ask for claim types that we will eventually filter out\n            additionalClaimTypes = FilterRequestedClaimTypes(additionalClaimTypes).ToList();\n\n            var context = new ProfileDataRequestContext(\n                subject,\n                request.Client,\n                IdentityServerConstants.ProfileDataCallers.ClaimsProviderAccessToken,\n                additionalClaimTypes.Distinct())\n            {\n                RequestedResources = resourceResult,\n                ValidatedRequest = request\n            };\n\n            await Profile.GetProfileDataAsync(context);\n\n            var claims = FilterProtocolClaims(context.IssuedClaims);\n            if (claims != null)\n            {\n                outputClaims.AddRange(claims);\n            }\n        }\n\n        return outputClaims;\n    }\n\n    /// <summary>\n    /// Gets the standard subject claims.\n    /// </summary>\n    /// <param name=\"subject\">The subject.</param>\n    /// <returns>A list of standard claims</returns>\n    protected virtual IEnumerable<Claim> GetStandardSubjectClaims(ClaimsPrincipal subject)\n    {\n        var claims = new List<Claim>\n        {\n            new Claim(JwtClaimTypes.Subject, subject.GetSubjectId()),\n            new Claim(JwtClaimTypes.AuthenticationTime, subject.GetAuthenticationTimeEpoch().ToString(), ClaimValueTypes.Integer64),\n            new Claim(JwtClaimTypes.IdentityProvider, subject.GetIdentityProvider())\n        };\n\n        claims.AddRange(subject.GetAuthenticationMethods());\n\n        return claims;\n    }\n\n    /// <summary>\n    /// Gets additional (and optional) claims from the cookie or incoming subject.\n    /// </summary>\n    /// <param name=\"subject\">The subject.</param>\n    /// <returns>Additional claims</returns>\n    protected virtual IEnumerable<Claim> GetOptionalClaims(ClaimsPrincipal subject)\n    {\n        var claims = new List<Claim>();\n\n        var acr = subject.FindFirst(JwtClaimTypes.AuthenticationContextClassReference);\n        if (acr != null) claims.Add(acr);\n\n        return claims;\n    }\n\n    /// <summary>\n    /// Filters out protocol claims like amr, nonce etc..\n    /// </summary>\n    /// <param name=\"claims\">The claims.</param>\n    /// <returns></returns>\n    protected virtual IEnumerable<Claim> FilterProtocolClaims(IEnumerable<Claim> claims)\n    {\n        var claimsToFilter = claims.Where(x => Constants.Filters.ClaimsServiceFilterClaimTypes.Contains(x.Type));\n        if (claimsToFilter.Any())\n        {\n            var types = claimsToFilter.Select(x => x.Type);\n            Logger.LogDebug(\"Claim types from profile service that were filtered: {claimTypes}\", types);\n        }\n        return claims.Except(claimsToFilter);\n    }\n\n    /// <summary>\n    /// Filters out protocol claims like amr, nonce etc..\n    /// </summary>\n    /// <param name=\"claimTypes\">The claim types.</param>\n    protected virtual IEnumerable<string> FilterRequestedClaimTypes(IEnumerable<string> claimTypes)\n    {\n        var claimTypesToFilter = claimTypes.Where(x => Constants.Filters.ClaimsServiceFilterClaimTypes.Contains(x));\n        return claimTypes.Except(claimTypesToFilter);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultConsentService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default consent service\n/// </summary>\npublic class DefaultConsentService : IConsentService\n{\n    /// <summary>\n    /// The user consent store\n    /// </summary>\n    protected readonly IUserConsentStore UserConsentStore;\n\n    /// <summary>\n    ///  The clock\n    /// </summary>\n    protected readonly ISystemClock Clock;\n\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger<DefaultConsentService> Logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultConsentService\" /> class.\n    /// </summary>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"userConsentStore\">The user consent store.</param>\n    /// <param name=\"logger\">The logger.</param>\n    /// <exception cref=\"System.ArgumentNullException\">store</exception>\n    public DefaultConsentService(ISystemClock clock, IUserConsentStore userConsentStore, ILogger<DefaultConsentService> logger)\n    {\n        Clock = clock;\n        UserConsentStore = userConsentStore;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Checks if consent is required.\n    /// </summary>\n    /// <param name=\"subject\">The user.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <param name=\"parsedScopes\">The parsed scopes.</param>\n    /// <returns>\n    /// Boolean if consent is required.\n    /// </returns>\n    /// <exception cref=\"System.ArgumentNullException\">\n    /// client\n    /// or\n    /// subject\n    /// </exception>\n    public virtual async Task<bool> RequiresConsentAsync(ClaimsPrincipal subject, Client client, IEnumerable<ParsedScopeValue> parsedScopes)\n    {\n        if (client == null) throw new ArgumentNullException(nameof(client));\n        if (subject == null) throw new ArgumentNullException(nameof(subject));\n\n        if (!client.RequireConsent)\n        {\n            Logger.LogDebug(\"Client is configured to not require consent, no consent is required\");\n            return false;\n        }\n\n        if (parsedScopes == null || !parsedScopes.Any())\n        {\n            Logger.LogDebug(\"No scopes being requested, no consent is required\");\n            return false;\n        }\n\n        if (!client.AllowRememberConsent)\n        {\n            Logger.LogDebug(\"Client is configured to not allow remembering consent, consent is required\");\n            return true;\n        }\n        \n        if (parsedScopes.Any(x => x.ParsedName != x.RawValue))\n        {\n            Logger.LogDebug(\"Scopes contains parameterized values, consent is required\");\n            return true;\n        }\n\n        var scopes = parsedScopes.Select(x => x.RawValue).ToArray();\n\n        // we always require consent for offline access if\n        // the client has not disabled RequireConsent \n        if (scopes.Contains(IdentityServerConstants.StandardScopes.OfflineAccess))\n        {\n            Logger.LogDebug(\"Scopes contains offline_access, consent is required\");\n            return true;\n        }\n\n        var consent = await UserConsentStore.GetUserConsentAsync(subject.GetSubjectId(), client.ClientId);\n\n        if (consent == null)\n        {\n            Logger.LogDebug(\"Found no prior consent from consent store, consent is required\");\n            return true;\n        }\n\n        if (consent.Expiration.HasExpired(Clock.UtcNow.UtcDateTime))\n        {\n            Logger.LogDebug(\"Consent found in consent store is expired, consent is required\");\n            await UserConsentStore.RemoveUserConsentAsync(consent.SubjectId, consent.ClientId);\n            return true;\n        }\n\n        if (consent.Scopes != null)\n        {\n            var intersect = scopes.Intersect(consent.Scopes);\n            var different = scopes.Count() != intersect.Count();\n\n            if (different)\n            {\n                Logger.LogDebug(\"Consent found in consent store is different than current request, consent is required\");\n            }\n            else\n            {\n                Logger.LogDebug(\"Consent found in consent store is same as current request, consent is not required\");\n            }\n\n            return different;\n        }\n\n        Logger.LogDebug(\"Consent found in consent store has no scopes, consent is required\");\n\n        return true;\n    }\n\n    /// <summary>\n    /// Updates the consent asynchronous.\n    /// </summary>\n    /// <param name=\"client\">The client.</param>\n    /// <param name=\"subject\">The subject.</param>\n    /// <param name=\"parsedScopes\">The parsed scopes.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.ArgumentNullException\">\n    /// client\n    /// or\n    /// subject\n    /// </exception>\n    public virtual async Task UpdateConsentAsync(ClaimsPrincipal subject, Client client, IEnumerable<ParsedScopeValue> parsedScopes)\n    {\n        if (client == null) throw new ArgumentNullException(nameof(client));\n        if (subject == null) throw new ArgumentNullException(nameof(subject));\n\n        if (client.AllowRememberConsent)\n        {\n            var subjectId = subject.GetSubjectId();\n            var clientId = client.ClientId;\n\n            var scopes = parsedScopes?.Select(x => x.RawValue).ToArray();\n            if (scopes != null && scopes.Any())\n            {\n                Logger.LogDebug(\"Client allows remembering consent, and consent given. Updating consent store for subject: {subject}\", subject.GetSubjectId());\n\n                var consent = new Consent\n                {\n                    CreationTime = Clock.UtcNow.UtcDateTime,\n                    SubjectId = subjectId,\n                    ClientId = clientId,\n                    Scopes = scopes\n                };\n\n                if (client.ConsentLifetime.HasValue)\n                {\n                    consent.Expiration = consent.CreationTime.AddSeconds(client.ConsentLifetime.Value);\n                }\n\n                await UserConsentStore.StoreUserConsentAsync(consent);\n            }\n            else\n            {\n                Logger.LogDebug(\"Client allows remembering consent, and no scopes provided. Removing consent from consent store for subject: {subject}\", subject.GetSubjectId());\n\n                await UserConsentStore.RemoveUserConsentAsync(subjectId, clientId);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultCorsPolicyService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default CORS policy service.\n/// </summary>\npublic class DefaultCorsPolicyService : ICorsPolicyService\n{\n    /// <summary>\n    /// Logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultCorsPolicyService\"/> class.\n    /// </summary>\n    public DefaultCorsPolicyService(ILogger<DefaultCorsPolicyService> logger)\n    {\n        Logger = logger;\n        AllowedOrigins = new HashSet<string>();\n    }\n\n    /// <summary>\n    /// The list allowed origins that are allowed.\n    /// </summary>\n    /// <value>\n    /// The allowed origins.\n    /// </value>\n    public ICollection<string> AllowedOrigins { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether all origins are allowed.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if allow all; otherwise, <c>false</c>.\n    /// </value>\n    public bool AllowAll { get; set; }\n\n    /// <summary>\n    /// Determines whether the origin allowed.\n    /// </summary>\n    /// <param name=\"origin\">The origin.</param>\n    /// <returns></returns>\n    public virtual Task<bool> IsOriginAllowedAsync(string origin)\n    {\n        if (!String.IsNullOrWhiteSpace(origin))\n        {\n            if (AllowAll)\n            {\n                Logger.LogDebug(\"AllowAll true, so origin: {0} is allowed\", Ioc.Sanitizer.Log.Sanitize(origin));\n                return Task.FromResult(true);\n            }\n\n            if (AllowedOrigins != null)\n            {\n                if (AllowedOrigins.Contains(origin, StringComparer.OrdinalIgnoreCase))\n                {\n                    Logger.LogDebug(\"AllowedOrigins configured and origin {0} is allowed\", Ioc.Sanitizer.Log.Sanitize(origin));\n                    return Task.FromResult(true);\n                }\n                else\n                {\n                    Logger.LogDebug(\"AllowedOrigins configured and origin {0} is not allowed\", Ioc.Sanitizer.Log.Sanitize(origin));\n                }\n            }\n\n            Logger.LogDebug(\"Exiting; origin {0} is not allowed\", Ioc.Sanitizer.Log.Sanitize(origin));\n        }\n\n        return Task.FromResult(false);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultDeviceFlowCodeService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services.Default;\n\n/// <summary>\n/// Default wrapper service for IDeviceFlowStore, handling key hashing\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.IDeviceFlowCodeService\" />\npublic class DefaultDeviceFlowCodeService : IDeviceFlowCodeService\n{\n    private readonly IDeviceFlowStore _store;\n    private readonly IHandleGenerationService _handleGenerationService;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultDeviceFlowCodeService\"/> class.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"handleGenerationService\">The handle generation service.</param>\n    public DefaultDeviceFlowCodeService(IDeviceFlowStore store,\n        IHandleGenerationService handleGenerationService)\n    {\n        _store = store;\n        _handleGenerationService = handleGenerationService;\n    }\n\n    /// <summary>\n    /// Stores the device authorization request.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <param name=\"data\">The data.</param>\n    /// <returns></returns>\n    public async Task<string> StoreDeviceAuthorizationAsync(string userCode, DeviceCode data)\n    {\n        var deviceCode = await _handleGenerationService.GenerateAsync();\n\n        await _store.StoreDeviceAuthorizationAsync(deviceCode.Sha256(), userCode.Sha256(), data);\n\n        return deviceCode;\n    }\n\n    /// <summary>\n    /// Finds device authorization by user code.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <returns></returns>\n    public Task<DeviceCode> FindByUserCodeAsync(string userCode)\n    {\n        return _store.FindByUserCodeAsync(userCode.Sha256());\n    }\n\n    /// <summary>\n    /// Finds device authorization by device code.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    /// <returns></returns>\n    public Task<DeviceCode> FindByDeviceCodeAsync(string deviceCode)\n    {\n        return _store.FindByDeviceCodeAsync(deviceCode.Sha256());\n    }\n\n    /// <summary>\n    /// Updates device authorization, searching by user code.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <param name=\"data\">The data.</param>\n    /// <returns></returns>\n    public Task UpdateByUserCodeAsync(string userCode, DeviceCode data)\n    {\n        return _store.UpdateByUserCodeAsync(userCode.Sha256(), data);\n    }\n\n    /// <summary>\n    /// Removes the device authorization, searching by device code.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    /// <returns></returns>\n    public Task RemoveByDeviceCodeAsync(string deviceCode)\n    {\n        return _store.RemoveByDeviceCodeAsync(deviceCode.Sha256());\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultDeviceFlowInteractionService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\ninternal class DefaultDeviceFlowInteractionService : IDeviceFlowInteractionService\n{\n    private readonly IClientStore _clients;\n    private readonly IUserSession _session;\n    private readonly IDeviceFlowCodeService _devices;\n    private readonly IResourceStore _resourceStore;\n    private readonly IScopeParser _scopeParser;\n    private readonly ILogger<DefaultDeviceFlowInteractionService> _logger;\n\n    public DefaultDeviceFlowInteractionService(\n        IClientStore clients,\n        IUserSession session,\n        IDeviceFlowCodeService devices,\n        IResourceStore resourceStore,\n        IScopeParser scopeParser,\n        ILogger<DefaultDeviceFlowInteractionService> logger)\n    {\n        _clients = clients;\n        _session = session;\n        _devices = devices;\n        _resourceStore = resourceStore;\n        _scopeParser = scopeParser;\n        _logger = logger;\n    }\n\n    public async Task<DeviceFlowAuthorizationRequest> GetAuthorizationContextAsync(string userCode)\n    {\n        var deviceAuth = await _devices.FindByUserCodeAsync(userCode);\n        if (deviceAuth == null) return null;\n\n        var client = await _clients.FindClientByIdAsync(deviceAuth.ClientId);\n        if (client == null) return null;\n\n        var parsedScopesResult = _scopeParser.ParseScopeValues(deviceAuth.RequestedScopes);\n        var validatedResources = await _resourceStore.CreateResourceValidationResult(parsedScopesResult);\n\n        return new DeviceFlowAuthorizationRequest\n        {\n            Client = client,\n            ValidatedResources = validatedResources\n        };\n    }\n\n    public async Task<DeviceFlowInteractionResult> HandleRequestAsync(string userCode, ConsentResponse consent)\n    {\n        if (userCode == null) throw new ArgumentNullException(nameof(userCode));\n        if (consent == null) throw new ArgumentNullException(nameof(consent));\n        \n        var deviceAuth = await _devices.FindByUserCodeAsync(userCode);\n        if (deviceAuth == null) return LogAndReturnError(\"Invalid user code\", \"Device authorization failure - user code is invalid\");\n\n        var client = await _clients.FindClientByIdAsync(deviceAuth.ClientId);\n        if (client == null) return LogAndReturnError(\"Invalid client\", \"Device authorization failure - requesting client is invalid\");\n\n        var subject = await _session.GetUserAsync();\n        if (subject == null) return LogAndReturnError(\"No user present in device flow request\", \"Device authorization failure - no user found\");\n        \n        var sid = await _session.GetSessionIdAsync();\n\n        deviceAuth.IsAuthorized = true;\n        deviceAuth.Subject = subject;\n        deviceAuth.SessionId = sid;\n        deviceAuth.Description = consent.Description;\n        deviceAuth.AuthorizedScopes = consent.ScopesValuesConsented;\n\n        // TODO: Device Flow - Record consent template\n        if (consent.RememberConsent)\n        {\n            //var consentRequest = new ConsentRequest(request, subject);\n            //await _consentMessageStore.WriteAsync(consentRequest.Id, new Message<ConsentResponse>(consent, _clock.UtcNow.UtcDateTime));\n        }\n\n        await _devices.UpdateByUserCodeAsync(userCode, deviceAuth);\n\n        return new DeviceFlowInteractionResult();\n    }\n\n    private DeviceFlowInteractionResult LogAndReturnError(string error, string errorDescription = null)\n    {\n        _logger.LogError(errorDescription);\n        return DeviceFlowInteractionResult.Failure(error);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultEventService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Events;\n\n/// <summary>\n/// The default event service\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.IEventService\" />\npublic class DefaultEventService : IEventService\n{\n    /// <summary>\n    /// The options\n    /// </summary>\n    protected readonly IdentityServerOptions Options;\n\n    /// <summary>\n    /// The context\n    /// </summary>\n    protected readonly IHttpContextAccessor Context;\n\n    /// <summary>\n    /// The sink\n    /// </summary>\n    protected readonly IEventSink Sink;\n\n    /// <summary>\n    /// The clock\n    /// </summary>\n    protected readonly ISystemClock Clock;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultEventService\"/> class.\n    /// </summary>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"context\">The context.</param>\n    /// <param name=\"sink\">The sink.</param>\n    /// <param name=\"clock\">The clock.</param>\n    public DefaultEventService(IdentityServerOptions options, IHttpContextAccessor context, IEventSink sink, ISystemClock clock)\n    {\n        Options = options;\n        Context = context;\n        Sink = sink;\n        Clock = clock;\n    }\n\n    /// <summary>\n    /// Raises the specified event.\n    /// </summary>\n    /// <param name=\"evt\">The event.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.ArgumentNullException\">evt</exception>\n    public async Task RaiseAsync(Event evt)\n    {\n        if (evt == null) throw new ArgumentNullException(nameof(evt));\n\n        if (CanRaiseEvent(evt))\n        {\n            await PrepareEventAsync(evt);\n            await Sink.PersistAsync(evt);\n        }\n    }\n\n    /// <summary>\n    /// Indicates if the type of event will be persisted.\n    /// </summary>\n    /// <param name=\"evtType\"></param>\n    /// <returns></returns>\n    /// <exception cref=\"System.ArgumentOutOfRangeException\"></exception>\n    public bool CanRaiseEventType(EventTypes evtType)\n    {\n        switch (evtType)\n        {\n            case EventTypes.Failure:\n                return Options.Events.RaiseFailureEvents;\n            case EventTypes.Information:\n                return Options.Events.RaiseInformationEvents;\n            case EventTypes.Success:\n                return Options.Events.RaiseSuccessEvents;\n            case EventTypes.Error:\n                return Options.Events.RaiseErrorEvents;\n            default:\n                throw new ArgumentOutOfRangeException(nameof(evtType));\n        }\n    }\n\n    /// <summary>\n    /// Determines whether this event would be persisted.\n    /// </summary>\n    /// <param name=\"evt\">The evt.</param>\n    /// <returns>\n    ///   <c>true</c> if this event would be persisted; otherwise, <c>false</c>.\n    /// </returns>\n    protected virtual bool CanRaiseEvent(Event evt)\n    {\n        return CanRaiseEventType(evt.EventType);\n    }\n\n    /// <summary>\n    /// Prepares the event.\n    /// </summary>\n    /// <param name=\"evt\">The evt.</param>\n    /// <returns></returns>\n    protected virtual async Task PrepareEventAsync(Event evt)\n    {\n        evt.ActivityId = Context.HttpContext.TraceIdentifier;\n        evt.TimeStamp = Clock.UtcNow.UtcDateTime;\n        evt.ProcessId = Process.GetCurrentProcess().Id;\n\n        if (Context.HttpContext.Connection.LocalIpAddress != null)\n        {\n            evt.LocalIpAddress = Context.HttpContext.Connection.LocalIpAddress.ToString() + \":\" + Context.HttpContext.Connection.LocalPort;\n        }\n        else\n        {\n            evt.LocalIpAddress = \"unknown\";\n        }\n\n        if (Context.HttpContext.Connection.RemoteIpAddress != null)\n        {\n            evt.RemoteIpAddress = Context.HttpContext.Connection.RemoteIpAddress.ToString();\n        }\n        else\n        {\n            evt.RemoteIpAddress = \"unknown\";\n        }\n\n        await evt.PrepareAsync();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultEventSink.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default implementation of the event service. Write events raised to the log.\n/// </summary>\npublic class DefaultEventSink : IEventSink\n{\n    /// <summary>\n    /// The logger\n    /// </summary>\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultEventSink\"/> class.\n    /// </summary>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultEventSink(ILogger<DefaultEventService> logger)\n    {\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Raises the specified event.\n    /// </summary>\n    /// <param name=\"evt\">The event.</param>\n    /// <exception cref=\"System.ArgumentNullException\">evt</exception>\n    public virtual Task PersistAsync(Event evt)\n    {\n        if (evt == null) throw new ArgumentNullException(nameof(evt));\n\n        _logger.LogInformation(\"{@event}\", evt);\n\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultHandleGenerationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default handle generation service\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.IHandleGenerationService\" />\npublic class DefaultHandleGenerationService : IHandleGenerationService\n{\n    /// <summary>\n    /// Generates a handle.\n    /// </summary>\n    /// <param name=\"length\">The length.</param>\n    /// <returns></returns>\n    public Task<string> GenerateAsync(int length)\n    {\n        return Task.FromResult(CryptoRandom.CreateUniqueId(length, CryptoRandom.OutputFormat.Hex));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultIdentityServerInteractionService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\ninternal class DefaultIdentityServerInteractionService : IIdentityServerInteractionService\n{\n    private readonly ISystemClock _clock;\n    private readonly IHttpContextAccessor _context;\n    private readonly IMessageStore<LogoutMessage> _logoutMessageStore;\n    private readonly IMessageStore<ErrorMessage> _errorMessageStore;\n    private readonly IConsentMessageStore _consentMessageStore;\n    private readonly IPersistedGrantService _grants;\n    private readonly IUserSession _userSession;\n    private readonly ILogger _logger;\n    private readonly ReturnUrlParser _returnUrlParser;\n\n    public DefaultIdentityServerInteractionService(\n        ISystemClock clock,\n        IHttpContextAccessor context,\n        IMessageStore<LogoutMessage> logoutMessageStore,\n        IMessageStore<ErrorMessage> errorMessageStore,\n        IConsentMessageStore consentMessageStore,\n        IPersistedGrantService grants,\n        IUserSession userSession,\n        ReturnUrlParser returnUrlParser,\n        ILogger<DefaultIdentityServerInteractionService> logger)\n    {\n        _clock = clock;\n        _context = context;\n        _logoutMessageStore = logoutMessageStore;\n        _errorMessageStore = errorMessageStore;\n        _consentMessageStore = consentMessageStore;\n        _grants = grants;\n        _userSession = userSession;\n        _returnUrlParser = returnUrlParser;\n        _logger = logger;\n    }\n\n    public async Task<AuthorizationRequest> GetAuthorizationContextAsync(string returnUrl)\n    {\n        var result = await _returnUrlParser.ParseAsync(returnUrl);\n\n        if (result != null)\n        {\n            _logger.LogTrace(\"AuthorizationRequest being returned\");\n        }\n        else\n        {\n            _logger.LogTrace(\"No AuthorizationRequest being returned\");\n        }\n\n        return result;\n    }\n\n    public async Task<LogoutRequest> GetLogoutContextAsync(string logoutId)\n    {\n        var msg = await _logoutMessageStore.ReadAsync(logoutId);\n        var iframeUrl = await _context.HttpContext.GetIdentityServerSignoutFrameCallbackUrlAsync(msg?.Data);\n        return new LogoutRequest(iframeUrl, msg?.Data);\n    }\n\n    public async Task<string> CreateLogoutContextAsync()\n    {\n        var user = await _userSession.GetUserAsync();\n        if (user != null)\n        {\n            var clientIds = await _userSession.GetClientListAsync();\n            if (clientIds.Any())\n            {\n                var sid = await _userSession.GetSessionIdAsync();\n                var msg = new Message<LogoutMessage>(new LogoutMessage\n                {\n                    SubjectId = user?.GetSubjectId(),\n                    SessionId = sid,\n                    ClientIds = clientIds\n                }, _clock.UtcNow.UtcDateTime);\n                var id = await _logoutMessageStore.WriteAsync(msg);\n                return id;\n            }\n        }\n\n        return null;\n    }\n\n    public async Task<ErrorMessage> GetErrorContextAsync(string errorId)\n    {\n        if (errorId != null)\n        { \n            var result = await _errorMessageStore.ReadAsync(errorId);\n            var data = result?.Data;\n            if (data != null)\n            {\n                _logger.LogTrace(\"Error context loaded\");\n            }\n            else\n            {\n                _logger.LogTrace(\"No error context found\");\n            }\n            return data;\n        }\n\n        _logger.LogTrace(\"No error context found\");\n\n        return null;\n    }\n\n    public async Task GrantConsentAsync(AuthorizationRequest request, ConsentResponse consent, string subject = null)\n    {\n        if (subject == null)\n        {\n            var user = await _userSession.GetUserAsync();\n            subject = user?.GetSubjectId();\n        }\n\n        if (subject == null && consent.Granted)\n        {\n            throw new ArgumentNullException(nameof(subject), \"User is not currently authenticated, and no subject id passed\");\n        }\n\n        var consentRequest = new ConsentRequest(request, subject);\n        await _consentMessageStore.WriteAsync(consentRequest.Id, new Message<ConsentResponse>(consent, _clock.UtcNow.UtcDateTime));\n    }\n\n    public Task DenyAuthorizationAsync(AuthorizationRequest request, AuthorizationError error, string errorDescription = null)\n    {\n        var response = new ConsentResponse \n        {\n            Error = error,\n            ErrorDescription = errorDescription\n        };\n        return GrantConsentAsync(request, response);\n    }\n\n    public bool IsValidReturnUrl(string returnUrl)\n    {\n        var result = _returnUrlParser.IsValidReturnUrl(returnUrl);\n\n        if (result)\n        {\n            _logger.LogTrace(\"IsValidReturnUrl true\");\n        }\n        else\n        {\n            _logger.LogTrace(\"IsValidReturnUrl false\");\n        }\n\n        return result;\n    }\n\n    public async Task<IEnumerable<Grant>> GetAllUserGrantsAsync()\n    {\n        var user = await _userSession.GetUserAsync();\n        if (user != null)\n        {\n            var subject = user.GetSubjectId();\n            return await _grants.GetAllGrantsAsync(subject);\n        }\n\n        return Enumerable.Empty<Grant>();\n    }\n\n    public async Task RevokeUserConsentAsync(string clientId)\n    {\n        var user = await _userSession.GetUserAsync();\n        if (user != null)\n        {\n            var subject = user.GetSubjectId();\n            await _grants.RemoveAllGrantsAsync(subject, clientId);\n        }\n    }\n\n    public async Task RevokeTokensForCurrentSessionAsync()\n    {\n        var user = await _userSession.GetUserAsync();\n        if (user != null)\n        {\n            var subject = user.GetSubjectId();\n            var sessionId = await _userSession.GetSessionIdAsync();\n            await _grants.RemoveAllGrantsAsync(subject, sessionId: sessionId);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultJwtRequestUriHttpClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default JwtRequest client\n/// </summary>\npublic class DefaultJwtRequestUriHttpClient : IJwtRequestUriHttpClient\n{\n    private readonly HttpClient _client;\n    private readonly IdentityServerOptions _options;\n    private readonly ILogger<DefaultJwtRequestUriHttpClient> _logger;\n\n    /// <summary>\n    /// ctor\n    /// </summary>\n    /// <param name=\"client\">An HTTP client</param>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"loggerFactory\">The logger factory</param>\n    public DefaultJwtRequestUriHttpClient(HttpClient client, IdentityServerOptions options, ILoggerFactory loggerFactory)\n    {\n        _client = client;\n        _options = options;\n        _logger = loggerFactory.CreateLogger<DefaultJwtRequestUriHttpClient>();\n    }\n\n\n    /// <inheritdoc />\n    public async Task<string> GetJwtAsync(string url, Client client)\n    {\n        var req = new HttpRequestMessage(HttpMethod.Get, url);\n        req.Properties.Add(IdentityServerConstants.JwtRequestClientKey, client);\n\n        var response = await _client.SendAsync(req);\n        if (response.StatusCode == System.Net.HttpStatusCode.OK)\n        {\n            if (_options.StrictJarValidation)\n            {\n                if (!string.Equals(response.Content.Headers.ContentType.MediaType,\n                    $\"application/{JwtClaimTypes.JwtTypes.AuthorizationRequest}\", StringComparison.Ordinal))\n                {\n                    _logger.LogError(\"Invalid content type {type} from jwt url {url}\", response.Content.Headers.ContentType.MediaType, url);\n                    return null;\n                }\n            }\n\n            _logger.LogDebug(\"Success http response from jwt url {url}\", url);\n            \n            var json = await response.Content.ReadAsStringAsync();\n            return json;\n        }\n            \n        _logger.LogError(\"Invalid http status code {status} from jwt url {url}\", response.StatusCode, url);\n        return null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultKeyMaterialService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// The default key material service\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.IKeyMaterialService\" />\npublic class DefaultKeyMaterialService : IKeyMaterialService\n{\n    private readonly IEnumerable<ISigningCredentialStore> _signingCredentialStores;\n    private readonly IEnumerable<IValidationKeysStore> _validationKeysStores;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultKeyMaterialService\"/> class.\n    /// </summary>\n    /// <param name=\"validationKeysStores\">The validation keys stores.</param>\n    /// <param name=\"signingCredentialStores\">The signing credential store.</param>\n    public DefaultKeyMaterialService(IEnumerable<IValidationKeysStore> validationKeysStores, IEnumerable<ISigningCredentialStore> signingCredentialStores)\n    {\n        _signingCredentialStores = signingCredentialStores;\n        _validationKeysStores = validationKeysStores;\n    }\n\n    /// <inheritdoc/>\n    public async Task<SigningCredentials> GetSigningCredentialsAsync(IEnumerable<string> allowedAlgorithms = null)\n    {\n        if (_signingCredentialStores.Any())\n        {\n            if (allowedAlgorithms.EnumerableIsNullOrEmpty())\n            {\n                return await _signingCredentialStores.First().GetSigningCredentialsAsync();\n            }\n\n            var credential = (await GetAllSigningCredentialsAsync()).FirstOrDefault(c => allowedAlgorithms.Contains(c.Algorithm));\n            if (credential is null)\n            {\n                throw new InvalidOperationException($\"No signing credential for algorithms ({allowedAlgorithms.ToSpaceSeparatedString()}) registered.\");\n            }\n\n            return credential;\n        }\n\n        return null;\n    }\n\n    /// <inheritdoc/>\n    public async Task<IEnumerable<SigningCredentials>> GetAllSigningCredentialsAsync()\n    {\n        var credentials = new List<SigningCredentials>();\n\n        foreach (var store in _signingCredentialStores)\n        {\n            credentials.Add(await store.GetSigningCredentialsAsync());\n        }\n\n        return credentials;\n    }\n\n    /// <inheritdoc/>\n    public async Task<IEnumerable<SecurityKeyInfo>> GetValidationKeysAsync()\n    {\n        var keys = new List<SecurityKeyInfo>();\n\n        foreach (var store in _validationKeysStores)\n        {\n            keys.AddRange(await store.GetValidationKeysAsync());\n        }\n\n        return keys;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultPersistedGrantService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default persisted grant service\n/// </summary>\npublic class DefaultPersistedGrantService : IPersistedGrantService\n{\n    private readonly ILogger _logger;\n    private readonly IPersistedGrantStore _store;\n    private readonly IPersistentGrantSerializer _serializer;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultPersistedGrantService\"/> class.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"serializer\">The serializer.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultPersistedGrantService(IPersistedGrantStore store, \n        IPersistentGrantSerializer serializer,\n        ILogger<DefaultPersistedGrantService> logger)\n    {\n        _store = store;\n        _serializer = serializer;\n        _logger = logger;\n    }\n\n    /// <inheritdoc/>\n    public async Task<IEnumerable<Grant>> GetAllGrantsAsync(string subjectId)\n    {\n        if (String.IsNullOrWhiteSpace(subjectId)) throw new ArgumentNullException(nameof(subjectId));\n        \n        var grants = (await _store.GetAllAsync(new PersistedGrantFilter { SubjectId = subjectId })).ToArray();\n\n        try\n        {\n            var consents = grants.Where(x => x.Type == IdentityServerConstants.PersistedGrantTypes.UserConsent)\n                .Select(x => _serializer.Deserialize<Consent>(x.Data))\n                .Select(x => new Grant \n                {\n                    ClientId = x.ClientId,\n                    SubjectId = subjectId,\n                    Scopes = x.Scopes,\n                    CreationTime = x.CreationTime,\n                    Expiration = x.Expiration\n                });\n\n            var codes = grants.Where(x => x.Type == IdentityServerConstants.PersistedGrantTypes.AuthorizationCode)\n                .Select(x => _serializer.Deserialize<AuthorizationCode>(x.Data))\n                .Select(x => new Grant\n                {\n                    ClientId = x.ClientId,\n                    SubjectId = subjectId,\n                    Description = x.Description,\n                    Scopes = x.RequestedScopes,\n                    CreationTime = x.CreationTime,\n                    Expiration = x.CreationTime.AddSeconds(x.Lifetime)\n                });\n\n            var refresh = grants.Where(x => x.Type == IdentityServerConstants.PersistedGrantTypes.RefreshToken)\n                .Select(x => _serializer.Deserialize<RefreshToken>(x.Data))\n                .Select(x => new Grant\n                {\n                    ClientId = x.ClientId,\n                    SubjectId = subjectId,\n                    Description = x.Description,\n                    Scopes = x.Scopes,\n                    CreationTime = x.CreationTime,\n                    Expiration = x.CreationTime.AddSeconds(x.Lifetime)\n                });\n\n            var access = grants.Where(x => x.Type == IdentityServerConstants.PersistedGrantTypes.ReferenceToken)\n                .Select(x => _serializer.Deserialize<Token>(x.Data))\n                .Select(x => new Grant\n                {\n                    ClientId = x.ClientId,\n                    SubjectId = subjectId,\n                    Description = x.Description,\n                    Scopes = x.Scopes,\n                    CreationTime = x.CreationTime,\n                    Expiration = x.CreationTime.AddSeconds(x.Lifetime)\n                });\n\n            consents = Join(consents, codes);\n            consents = Join(consents, refresh);\n            consents = Join(consents, access);\n\n            return consents.ToArray();\n        }\n        catch (Exception ex)\n        {\n            _logger.LogError(ex, \"Failed processing results from grant store.\");\n        }\n\n        return Enumerable.Empty<Grant>();\n    }\n\n    private IEnumerable<Grant> Join(IEnumerable<Grant> first, IEnumerable<Grant> second)\n    {\n        var list = first.ToList();\n\n        foreach(var other in second)\n        {\n            var match = list.FirstOrDefault(x => x.ClientId == other.ClientId);\n            if (match != null)\n            {\n                match.Scopes = match.Scopes.Union(other.Scopes).Distinct();\n\n                if (match.CreationTime > other.CreationTime)\n                {\n                    // show the earlier creation time\n                    match.CreationTime = other.CreationTime;\n                }\n\n                if (match.Expiration == null || other.Expiration == null)\n                {\n                    // show that there is no expiration to one of the grants\n                    match.Expiration = null;\n                }\n                else if (match.Expiration < other.Expiration)\n                {\n                    // show the latest expiration\n                    match.Expiration = other.Expiration;\n                }\n\n                match.Description = match.Description ?? other.Description;\n            }\n            else\n            {\n                list.Add(other);\n            }\n        }\n\n        return list;\n    }\n\n    /// <inheritdoc/>\n    public Task RemoveAllGrantsAsync(string subjectId, string clientId = null, string sessionId = null)\n    {\n        if (String.IsNullOrWhiteSpace(subjectId)) throw new ArgumentNullException(nameof(subjectId));\n\n        return _store.RemoveAllAsync(new PersistedGrantFilter {\n            SubjectId = subjectId,\n            ClientId = clientId,\n            SessionId = sessionId\n        });\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultProfileService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default profile service implementation.\n/// This implementation sources all claims from the current subject (e.g. the cookie).\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.IProfileService\" />\npublic class DefaultProfileService : IProfileService\n{\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultProfileService\"/> class.\n    /// </summary>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultProfileService(ILogger<DefaultProfileService> logger)\n    {\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// This method is called whenever claims about the user are requested (e.g. during token creation or via the userinfo endpoint)\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public virtual Task GetProfileDataAsync(ProfileDataRequestContext context)\n    {\n        context.LogProfileRequest(Logger);\n        context.AddRequestedClaims(context.Subject.Claims);\n        context.LogIssuedClaims(Logger);\n\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// This method gets called whenever identity server needs to determine if the user is valid or active (e.g. if the user's account has been deactivated since they logged in).\n    /// (e.g. during token issuance or validation).\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public virtual Task IsActiveAsync(IsActiveContext context)\n    {\n        Logger.LogDebug(\"IsActive called from: {caller}\", context.Caller);\n\n        context.IsActive = true;\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultRefreshTokenService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default refresh token service\n/// </summary>\npublic class DefaultRefreshTokenService : IRefreshTokenService\n{\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// The refresh token store\n    /// </summary>\n    protected IRefreshTokenStore RefreshTokenStore { get; }\n\n    /// <summary>\n    /// The profile service\n    /// </summary>\n    protected IProfileService Profile { get; }\n\n    /// <summary>\n    /// The clock\n    /// </summary>\n    protected ISystemClock Clock { get; }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultRefreshTokenService\" /> class.\n    /// </summary>\n    /// <param name=\"refreshTokenStore\">The refresh token store</param>\n    /// <param name=\"profile\"></param>\n    /// <param name=\"clock\">The clock</param>\n    /// <param name=\"logger\">The logger</param>\n    public DefaultRefreshTokenService(IRefreshTokenStore refreshTokenStore, IProfileService profile,\n        ISystemClock clock,\n        ILogger<DefaultRefreshTokenService> logger)\n    {\n        RefreshTokenStore = refreshTokenStore;\n        Profile = profile;\n        Clock = clock;\n\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Validates a refresh token\n    /// </summary>\n    /// <param name=\"tokenHandle\">The token handle.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns></returns>\n    public virtual async Task<TokenValidationResult> ValidateRefreshTokenAsync(string tokenHandle, Client client)\n    {\n        var invalidGrant = new TokenValidationResult\n        {\n            IsError = true, Error = OidcConstants.TokenErrors.InvalidGrant\n        };\n\n        Logger.LogTrace(\"Start refresh token validation\");\n\n        /////////////////////////////////////////////\n        // check if refresh token is valid\n        /////////////////////////////////////////////\n        var refreshToken = await RefreshTokenStore.GetRefreshTokenAsync(tokenHandle);\n        if (refreshToken == null)\n        {\n            Logger.LogWarning(\"Invalid refresh token\");\n            return invalidGrant;\n        }\n\n        /////////////////////////////////////////////\n        // check if refresh token has expired\n        /////////////////////////////////////////////\n        if (refreshToken.CreationTime.HasExceeded(refreshToken.Lifetime, Clock.UtcNow.DateTime))\n        {\n            Logger.LogWarning(\"Refresh token has expired.\");\n            return invalidGrant;\n        }\n        \n        /////////////////////////////////////////////\n        // check if client belongs to requested refresh token\n        /////////////////////////////////////////////\n        if (client.ClientId != refreshToken.ClientId)\n        {\n            Logger.LogError(\"{0} tries to refresh token belonging to {1}\", client.ClientId, refreshToken.ClientId);\n            return invalidGrant;\n        }\n\n        /////////////////////////////////////////////\n        // check if client still has offline_access scope\n        /////////////////////////////////////////////\n        if (!client.AllowOfflineAccess)\n        {\n            Logger.LogError(\"{clientId} does not have access to offline_access scope anymore\", client.ClientId);\n            return invalidGrant;\n        }\n        \n        /////////////////////////////////////////////\n        // check if refresh token has been consumed\n        /////////////////////////////////////////////\n        if (refreshToken.ConsumedTime.HasValue)\n        {\n            if ((await AcceptConsumedTokenAsync(refreshToken)) == false)\n            {\n                Logger.LogWarning(\"Rejecting refresh token because it has been consumed already.\");\n                return invalidGrant;\n            }\n        }\n        \n        /////////////////////////////////////////////\n        // make sure user is enabled\n        /////////////////////////////////////////////\n        var isActiveCtx = new IsActiveContext(\n            refreshToken.Subject,\n            client,\n            IdentityServerConstants.ProfileIsActiveCallers.RefreshTokenValidation);\n\n        await Profile.IsActiveAsync(isActiveCtx);\n\n        if (isActiveCtx.IsActive == false)\n        {\n            Logger.LogError(\"{subjectId} has been disabled\", refreshToken.Subject.GetSubjectId());\n            return invalidGrant;\n        }\n        \n        return new TokenValidationResult\n        {\n            IsError = false, \n            RefreshToken = refreshToken, \n            Client = client\n        };\n    }\n\n    /// <summary>\n    /// Callback to decide if an already consumed token should be accepted.\n    /// </summary>\n    /// <param name=\"refreshToken\"></param>\n    /// <returns></returns>\n    protected virtual Task<bool> AcceptConsumedTokenAsync(RefreshToken refreshToken)\n    {\n        // by default we will not accept consumed tokens\n        // change the behavior here to implement a time window\n        // you can also implement additional revocation logic here\n        return Task.FromResult(false);\n    }\n\n    /// <summary>\n    /// Creates the refresh token.\n    /// </summary>\n    /// <param name=\"subject\">The subject.</param>\n    /// <param name=\"accessToken\">The access token.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns>\n    /// The refresh token handle\n    /// </returns>\n    public virtual async Task<string> CreateRefreshTokenAsync(ClaimsPrincipal subject, Token accessToken,\n        Client client)\n    {\n        Logger.LogDebug(\"Creating refresh token\");\n\n        int lifetime;\n        if (client.RefreshTokenExpiration == TokenExpiration.Absolute)\n        {\n            Logger.LogDebug(\"Setting an absolute lifetime: {absoluteLifetime}\",\n                client.AbsoluteRefreshTokenLifetime);\n            lifetime = client.AbsoluteRefreshTokenLifetime;\n        }\n        else\n        {\n            lifetime = client.SlidingRefreshTokenLifetime;\n            if (client.AbsoluteRefreshTokenLifetime > 0 && lifetime > client.AbsoluteRefreshTokenLifetime)\n            {\n                Logger.LogWarning(\n                    \"Client {clientId}'s configured \" + nameof(client.SlidingRefreshTokenLifetime) +\n                    \" of {slidingLifetime} exceeds its \" + nameof(client.AbsoluteRefreshTokenLifetime) +\n                    \" of {absoluteLifetime}. The refresh_token's sliding lifetime will be capped to the absolute lifetime\",\n                    client.ClientId, lifetime, client.AbsoluteRefreshTokenLifetime);\n                lifetime = client.AbsoluteRefreshTokenLifetime;\n            }\n\n            Logger.LogDebug(\"Setting a sliding lifetime: {slidingLifetime}\", lifetime);\n        }\n\n        var refreshToken = new RefreshToken\n        {\n            CreationTime = Clock.UtcNow.UtcDateTime, Lifetime = lifetime, AccessToken = accessToken\n        };\n\n        var handle = await RefreshTokenStore.StoreRefreshTokenAsync(refreshToken);\n        return handle;\n    }\n\n    /// <summary>\n    /// Updates the refresh token.\n    /// </summary>\n    /// <param name=\"handle\">The handle.</param>\n    /// <param name=\"refreshToken\">The refresh token.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns>\n    /// The refresh token handle\n    /// </returns>\n    public virtual async Task<string> UpdateRefreshTokenAsync(string handle, RefreshToken refreshToken,\n        Client client)\n    {\n        Logger.LogDebug(\"Updating refresh token\");\n\n        bool needsCreate = false;\n        bool needsUpdate = false;\n\n        if (client.RefreshTokenUsage == TokenUsage.OneTimeOnly)\n        {\n            Logger.LogDebug(\"Token usage is one-time only. Setting current handle as consumed, and generating new handle\");\n\n            // flag as consumed\n            if (refreshToken.ConsumedTime == null)\n            {\n                refreshToken.ConsumedTime = Clock.UtcNow.UtcDateTime;\n                await RefreshTokenStore.UpdateRefreshTokenAsync(handle, refreshToken);\n            }\n\n            // create new one\n            needsCreate = true;\n        }\n\n        if (client.RefreshTokenExpiration == TokenExpiration.Sliding)\n        {\n            Logger.LogDebug(\"Refresh token expiration is sliding - extending lifetime\");\n\n            // if absolute exp > 0, make sure we don't exceed absolute exp\n            // if absolute exp = 0, allow indefinite slide\n            var currentLifetime = refreshToken.CreationTime.GetLifetimeInSeconds(Clock.UtcNow.UtcDateTime);\n            Logger.LogDebug(\"Current lifetime: {currentLifetime}\", currentLifetime.ToString());\n\n            var newLifetime = currentLifetime + client.SlidingRefreshTokenLifetime;\n            Logger.LogDebug(\"New lifetime: {slidingLifetime}\", newLifetime.ToString());\n\n            // zero absolute refresh token lifetime represents unbounded absolute lifetime\n            // if absolute lifetime > 0, cap at absolute lifetime\n            if (client.AbsoluteRefreshTokenLifetime > 0 && newLifetime > client.AbsoluteRefreshTokenLifetime)\n            {\n                newLifetime = client.AbsoluteRefreshTokenLifetime;\n                Logger.LogDebug(\"New lifetime exceeds absolute lifetime, capping it to {newLifetime}\",\n                    newLifetime.ToString());\n            }\n\n            refreshToken.Lifetime = newLifetime;\n            needsUpdate = true;\n        }\n\n        if (needsCreate)\n        {\n            // set it to null so that we save non-consumed token\n            refreshToken.ConsumedTime = null;\n            handle = await RefreshTokenStore.StoreRefreshTokenAsync(refreshToken);\n            Logger.LogDebug(\"Created refresh token in store\");\n        }\n        else if (needsUpdate)\n        {\n            await RefreshTokenStore.UpdateRefreshTokenAsync(handle, refreshToken);\n            Logger.LogDebug(\"Updated refresh token in store\");\n        }\n        else\n        {\n            Logger.LogDebug(\"No updates to refresh token done\");\n        }\n\n        return handle;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultReplayCache.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default implementation of the replay cache using IDistributedCache\n/// </summary>\npublic class DefaultReplayCache : IReplayCache\n{\n    private const string Prefix = nameof(DefaultReplayCache) + \":\";\n    \n    private readonly IDistributedCache _cache;\n    \n    /// <summary>\n    /// ctor\n    /// </summary>\n    /// <param name=\"cache\"></param>\n    public DefaultReplayCache(IDistributedCache cache)\n    {\n        _cache = cache;\n    }\n    \n    /// <inheritdoc />\n    public async Task AddAsync(string purpose, string handle, DateTimeOffset expiration)\n    {\n        var options = new DistributedCacheEntryOptions\n        {\n            AbsoluteExpiration = expiration\n        };\n        \n        await _cache.SetAsync(Prefix + purpose + handle, new byte[] { }, options);\n    }\n\n    /// <inheritdoc />\n    public async Task<bool> ExistsAsync(string purpose, string handle)\n    {\n        return (await _cache.GetAsync(Prefix + purpose + handle, default)) != null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultTokenCreationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default token creation service\n/// </summary>\npublic class DefaultTokenCreationService : ITokenCreationService\n{\n    /// <summary>\n    /// The key service\n    /// </summary>\n    protected readonly IKeyMaterialService Keys;\n\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    ///  The clock\n    /// </summary>\n    protected readonly ISystemClock Clock;\n\n    /// <summary>\n    /// The options\n    /// </summary>\n    protected readonly IdentityServerOptions Options;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultTokenCreationService\"/> class.\n    /// </summary>\n    /// <param name=\"clock\">The options.</param>\n    /// <param name=\"keys\">The keys.</param>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultTokenCreationService(\n        ISystemClock clock,\n        IKeyMaterialService keys,\n        IdentityServerOptions options,\n        ILogger<DefaultTokenCreationService> logger)\n    {\n        Clock = clock;\n        Keys = keys;\n        Options = options;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Creates the token.\n    /// </summary>\n    /// <param name=\"token\">The token.</param>\n    /// <returns>\n    /// A protected and serialized security token\n    /// </returns>\n    public virtual async Task<string> CreateTokenAsync(Token token)\n    {\n        var header = await CreateHeaderAsync(token);\n        var payload = await CreatePayloadAsync(token);\n\n        return await CreateJwtAsync(new JwtSecurityToken(header, payload));\n    }\n\n    /// <summary>\n    /// Creates the JWT header\n    /// </summary>\n    /// <param name=\"token\">The token.</param>\n    /// <returns>The JWT header</returns>\n    protected virtual async Task<JwtHeader> CreateHeaderAsync(Token token)\n    {\n        var credential = await Keys.GetSigningCredentialsAsync(token.AllowedSigningAlgorithms);\n\n        if (credential == null)\n        {\n            throw new InvalidOperationException(\"No signing credential is configured. Can't create JWT token\");\n        }\n\n        var header = new JwtHeader(credential);\n\n        // emit x5t claim for backwards compatibility with v4 of MS JWT library\n        if (credential.Key is X509SecurityKey x509Key)\n        {\n            var cert = x509Key.Certificate;\n            if (Clock.UtcNow.UtcDateTime > cert.NotAfter)\n            {\n                Logger.LogWarning(\"Certificate {subjectName} has expired on {expiration}\", cert.Subject, cert.NotAfter.ToString(CultureInfo.InvariantCulture));\n            }\n\n            header[\"x5t\"] = Base64Url.Encode(cert.GetCertHash());\n        }\n\n        if (token.Type == TokenTypes.AccessToken)\n        {\n            if (Options.AccessTokenJwtType.IsPresent())\n            {\n                header[\"typ\"] = Options.AccessTokenJwtType;\n            }\n        }\n\n        return header;\n    }\n\n    /// <summary>\n    /// Creates the JWT payload\n    /// </summary>\n    /// <param name=\"token\">The token.</param>\n    /// <returns>The JWT payload</returns>\n    protected virtual Task<JwtPayload> CreatePayloadAsync(Token token)\n    {\n        var payload = token.CreateJwtPayload(Clock, Options, Logger);\n        return Task.FromResult(payload);\n    }\n\n    /// <summary>\n    /// Applies the signature to the JWT\n    /// </summary>\n    /// <param name=\"jwt\">The JWT object.</param>\n    /// <returns>The signed JWT</returns>\n    protected virtual Task<string> CreateJwtAsync(JwtSecurityToken jwt)\n    {\n        var handler = new JwtSecurityTokenHandler();\n        return Task.FromResult(handler.WriteToken(jwt));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultTokenService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default token service\n/// </summary>\npublic class DefaultTokenService : ITokenService\n{\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// The HTTP context accessor\n    /// </summary>\n    protected readonly IHttpContextAccessor ContextAccessor;\n\n    /// <summary>\n    /// The claims provider\n    /// </summary>\n    protected readonly IClaimsService ClaimsProvider;\n\n    /// <summary>\n    /// The reference token store\n    /// </summary>\n    protected readonly IReferenceTokenStore ReferenceTokenStore;\n\n    /// <summary>\n    /// The signing service\n    /// </summary>\n    protected readonly ITokenCreationService CreationService;\n\n    /// <summary>\n    /// The clock\n    /// </summary>\n    protected readonly ISystemClock Clock;\n\n    /// <summary>\n    /// The key material service\n    /// </summary>\n    protected readonly IKeyMaterialService KeyMaterialService;\n\n    /// <summary>\n    /// The IdentityServer options\n    /// </summary>\n    protected readonly IdentityServerOptions Options;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultTokenService\" /> class.\n    /// </summary>\n    /// <param name=\"claimsProvider\">The claims provider.</param>\n    /// <param name=\"referenceTokenStore\">The reference token store.</param>\n    /// <param name=\"creationService\">The signing service.</param>\n    /// <param name=\"contextAccessor\">The HTTP context accessor.</param>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"keyMaterialService\"></param>\n    /// <param name=\"options\">The IdentityServer options</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultTokenService(\n        IClaimsService claimsProvider,\n        IReferenceTokenStore referenceTokenStore,\n        ITokenCreationService creationService,\n        IHttpContextAccessor contextAccessor,\n        ISystemClock clock,\n        IKeyMaterialService keyMaterialService,\n        IdentityServerOptions options,\n        ILogger<DefaultTokenService> logger)\n    {\n        ContextAccessor = contextAccessor;\n        ClaimsProvider = claimsProvider;\n        ReferenceTokenStore = referenceTokenStore;\n        CreationService = creationService;\n        Clock = clock;\n        KeyMaterialService = keyMaterialService;\n        Options = options;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Creates an identity token.\n    /// </summary>\n    /// <param name=\"request\">The token creation request.</param>\n    /// <returns>\n    /// An identity token\n    /// </returns>\n    public virtual async Task<Token> CreateIdentityTokenAsync(TokenCreationRequest request)\n    {\n        Logger.LogTrace(\"Creating identity token\");\n        request.Validate();\n\n        // todo: Dom, add a test for this. validate the at and c hashes are correct for the id_token when the client's alg doesn't match the server default.\n        var credential = await KeyMaterialService.GetSigningCredentialsAsync(request.ValidatedRequest.Client.AllowedIdentityTokenSigningAlgorithms);\n        if (credential == null)\n        {\n            throw new InvalidOperationException(\"No signing credential is configured.\");\n        }\n\n        var signingAlgorithm = credential.Algorithm;\n\n        // host provided claims\n        var claims = new List<Claim>();\n\n        // if nonce was sent, must be mirrored in id token\n        if (request.Nonce.IsPresent())\n        {\n            claims.Add(new Claim(JwtClaimTypes.Nonce, request.Nonce));\n        }\n\n        // add iat claim\n        claims.Add(new Claim(JwtClaimTypes.IssuedAt, Clock.UtcNow.ToUnixTimeSeconds().ToString(), ClaimValueTypes.Integer64));\n\n        // add at_hash claim\n        if (request.AccessTokenToHash.IsPresent())\n        {\n            claims.Add(new Claim(JwtClaimTypes.AccessTokenHash, CryptoHelper.CreateHashClaimValue(request.AccessTokenToHash, signingAlgorithm)));\n        }\n\n        // add c_hash claim\n        if (request.AuthorizationCodeToHash.IsPresent())\n        {\n            claims.Add(new Claim(JwtClaimTypes.AuthorizationCodeHash, CryptoHelper.CreateHashClaimValue(request.AuthorizationCodeToHash, signingAlgorithm)));\n        }\n\n        // add s_hash claim\n        if (request.StateHash.IsPresent())\n        {\n            claims.Add(new Claim(JwtClaimTypes.StateHash, request.StateHash));\n        }\n\n        // add sid if present\n        if (request.ValidatedRequest.SessionId.IsPresent())\n        {\n            claims.Add(new Claim(JwtClaimTypes.SessionId, request.ValidatedRequest.SessionId));\n        }\n\n        claims.AddRange(await ClaimsProvider.GetIdentityTokenClaimsAsync(\n            request.Subject,\n            request.ValidatedResources,\n            request.IncludeAllIdentityClaims,\n            request.ValidatedRequest));\n\n        var issuer = ContextAccessor.HttpContext.GetIdentityServerIssuerUri();\n\n        var token = new Token(OidcConstants.TokenTypes.IdentityToken)\n        {\n            CreationTime = Clock.UtcNow.UtcDateTime,\n            Audiences = { request.ValidatedRequest.Client.ClientId },\n            Issuer = issuer,\n            Lifetime = request.ValidatedRequest.Client.IdentityTokenLifetime,\n            Claims = claims.Distinct(new ClaimComparer()).ToList(),\n            ClientId = request.ValidatedRequest.Client.ClientId,\n            AccessTokenType = request.ValidatedRequest.AccessTokenType,\n            AllowedSigningAlgorithms = request.ValidatedRequest.Client.AllowedIdentityTokenSigningAlgorithms\n        };\n\n        return token;\n    }\n\n    /// <summary>\n    /// Creates an access token.\n    /// </summary>\n    /// <param name=\"request\">The token creation request.</param>\n    /// <returns>\n    /// An access token\n    /// </returns>\n    public virtual async Task<Token> CreateAccessTokenAsync(TokenCreationRequest request)\n    {\n        Logger.LogTrace(\"Creating access token\");\n        request.Validate();\n\n        var claims = new List<Claim>();\n        claims.AddRange(await ClaimsProvider.GetAccessTokenClaimsAsync(\n            request.Subject,\n            request.ValidatedResources,\n            request.ValidatedRequest));\n\n        if (request.ValidatedRequest.Client.IncludeJwtId)\n        {\n            claims.Add(new Claim(JwtClaimTypes.JwtId, CryptoRandom.CreateUniqueId(16, CryptoRandom.OutputFormat.Hex)));\n        }\n\n        if (request.ValidatedRequest.SessionId.IsPresent())\n        {\n            claims.Add(new Claim(JwtClaimTypes.SessionId, request.ValidatedRequest.SessionId));\n        }\n        \n        // iat claim as required by JWT profile\n        claims.Add(new Claim(JwtClaimTypes.IssuedAt, Clock.UtcNow.ToUnixTimeSeconds().ToString(),\n            ClaimValueTypes.Integer64));\n\n        var issuer = ContextAccessor.HttpContext.GetIdentityServerIssuerUri();\n        var token = new Token(OidcConstants.TokenTypes.AccessToken)\n        {\n            CreationTime = Clock.UtcNow.UtcDateTime,\n            Issuer = issuer,\n            Lifetime = request.ValidatedRequest.AccessTokenLifetime,\n            Claims = claims.Distinct(new ClaimComparer()).ToList(),\n            ClientId = request.ValidatedRequest.Client.ClientId,\n            Description = request.Description,\n            AccessTokenType = request.ValidatedRequest.AccessTokenType,\n            AllowedSigningAlgorithms = request.ValidatedResources.Resources.ApiResources.FindMatchingSigningAlgorithms()\n        };\n\n        // add aud based on ApiResources in the validated request\n        foreach (var aud in request.ValidatedResources.Resources.ApiResources.Select(x => x.Name).Distinct())\n        {\n            token.Audiences.Add(aud);\n        }\n\n        if (Options.EmitStaticAudienceClaim)\n        {\n            token.Audiences.Add(string.Format(IdentityServerConstants.AccessTokenAudience, issuer.EnsureTrailingSlash()));\n        }\n\n        // add cnf if present\n        if (request.ValidatedRequest.Confirmation.IsPresent())\n        {\n            token.Confirmation = request.ValidatedRequest.Confirmation;\n        }\n        else\n        {\n            if (Options.MutualTls.AlwaysEmitConfirmationClaim)\n            {\n                var clientCertificate = await ContextAccessor.HttpContext.Connection.GetClientCertificateAsync();\n                if (clientCertificate != null)\n                {\n                    token.Confirmation = clientCertificate.CreateThumbprintCnf();\n                }\n            }\n        }\n        \n        return token;\n    }\n\n    /// <summary>\n    /// Creates a serialized and protected security token.\n    /// </summary>\n    /// <param name=\"token\">The token.</param>\n    /// <returns>\n    /// A security token in serialized form\n    /// </returns>\n    /// <exception cref=\"System.InvalidOperationException\">Invalid token type.</exception>\n    public virtual async Task<string> CreateSecurityTokenAsync(Token token)\n    {\n        string tokenResult;\n\n        if (token.Type == OidcConstants.TokenTypes.AccessToken)\n        {\n            if (token.AccessTokenType == AccessTokenType.Jwt)\n            {\n                Logger.LogTrace(\"Creating JWT access token\");\n\n                tokenResult = await CreationService.CreateTokenAsync(token);\n            }\n            else\n            {\n                Logger.LogTrace(\"Creating reference access token\");\n\n                var handle = await ReferenceTokenStore.StoreReferenceTokenAsync(token);\n\n                tokenResult = handle;\n            }\n        }\n        else if (token.Type == OidcConstants.TokenTypes.IdentityToken)\n        {\n            Logger.LogTrace(\"Creating JWT identity token\");\n\n            tokenResult = await CreationService.CreateTokenAsync(token);\n        }\n        else\n        {\n            throw new InvalidOperationException(\"Invalid token type.\");\n        }\n\n        return tokenResult;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultUserCodeService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default user code service implementation.\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.IUserCodeService\" />\npublic class DefaultUserCodeService : IUserCodeService\n{\n    private readonly IEnumerable<IUserCodeGenerator> _generators;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultUserCodeService\"/> class.\n    /// </summary>\n    /// <param name=\"generators\">The generators.</param>\n    /// <exception cref=\"ArgumentNullException\">generators</exception>\n    public DefaultUserCodeService(IEnumerable<IUserCodeGenerator> generators)\n    {\n        _generators = generators ?? throw new ArgumentNullException(nameof(generators));\n    }\n\n    /// <summary>\n    /// Gets the user code generator.\n    /// </summary>\n    /// <param name=\"userCodeType\">Type of user code.</param>\n    /// <returns></returns>\n    public Task<IUserCodeGenerator> GetGenerator(string userCodeType) =>\n        Task.FromResult(_generators.FirstOrDefault(x => x.UserCodeType == userCodeType));\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DefaultUserSession.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Cookie-based session implementation\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.IUserSession\" />\npublic class DefaultUserSession : IUserSession\n{\n    /// <summary>\n    /// The HTTP context accessor\n    /// </summary>\n    protected readonly IHttpContextAccessor HttpContextAccessor;\n\n    /// <summary>\n    /// The handlers\n    /// </summary>\n    protected readonly IAuthenticationHandlerProvider Handlers;\n\n    /// <summary>\n    /// The options\n    /// </summary>\n    protected readonly IdentityServerOptions Options;\n\n    /// <summary>\n    /// The clock\n    /// </summary>\n    protected readonly ISystemClock Clock;\n\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// Gets the HTTP context.\n    /// </summary>\n    /// <value>\n    /// The HTTP context.\n    /// </value>\n    protected HttpContext HttpContext => HttpContextAccessor.HttpContext;\n\n    /// <summary>\n    /// Gets the name of the check session cookie.\n    /// </summary>\n    /// <value>\n    /// The name of the check session cookie.\n    /// </value>\n    protected string CheckSessionCookieName => Options.Authentication.CheckSessionCookieName;\n    \n    /// <summary>\n    /// Gets the domain of the check session cookie.\n    /// </summary>\n    /// <value>\n    /// The domain of the check session cookie.\n    /// </value>\n    protected string CheckSessionCookieDomain => Options.Authentication.CheckSessionCookieDomain;\n\n    /// <summary>\n    /// Gets the SameSite mode of the check session cookie.\n    /// </summary>\n    /// <value>\n    /// The SameSite mode of the check session cookie.\n    /// </value>\n    protected SameSiteMode CheckSessionCookieSameSiteMode => Options.Authentication.CheckSessionCookieSameSiteMode;\n\n    /// <summary>\n    /// The principal\n    /// </summary>\n    protected ClaimsPrincipal Principal;\n\n    /// <summary>\n    /// The properties\n    /// </summary>\n    protected AuthenticationProperties Properties;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultUserSession\"/> class.\n    /// </summary>\n    /// <param name=\"httpContextAccessor\">The HTTP context accessor.</param>\n    /// <param name=\"handlers\">The handlers.</param>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultUserSession(\n        IHttpContextAccessor httpContextAccessor,\n        IAuthenticationHandlerProvider handlers,\n        IdentityServerOptions options,\n        ISystemClock clock,\n        ILogger<IUserSession> logger)\n    {\n        HttpContextAccessor = httpContextAccessor;\n        Handlers = handlers;\n        Options = options;\n        Clock = clock;\n        Logger = logger;\n    }\n\n    // we need this helper (and can't call HttpContext.AuthenticateAsync) so we don't run\n    // claims transformation when we get the principal. this also ensures that we don't\n    // re-issue a cookie that includes the claims from claims transformation.\n    //\n    // also, by caching the _principal/_properties it allows someone to issue a new\n    // cookie (via HttpContext.SignInAsync) and we'll use those new values, rather than\n    // just reading the incoming cookie\n    //\n    // this design requires this to be in DI as scoped\n\n    /// <summary>\n    /// Authenticates the authentication cookie for the current HTTP request and caches the user and properties results.\n    /// </summary>\n    protected virtual async Task AuthenticateAsync()\n    {\n        if (Principal == null || Properties == null)\n        {\n            var scheme = await HttpContext.GetCookieAuthenticationSchemeAsync();\n\n            var handler = await Handlers.GetHandlerAsync(HttpContext, scheme);\n            if (handler == null)\n            {\n                throw new InvalidOperationException($\"No authentication handler is configured to authenticate for the scheme: {scheme}\");\n            }\n\n            var result = await handler.AuthenticateAsync();\n            if (result != null && result.Succeeded)\n            {\n                Principal = result.Principal;\n                Properties = result.Properties;\n            }\n        }\n    }\n\n    /// <summary>\n    /// Creates a session identifier for the signin context and issues the session id cookie.\n    /// </summary>\n    /// <param name=\"principal\"></param>\n    /// <param name=\"properties\"></param>\n    /// <returns></returns>\n    /// <exception cref=\"ArgumentNullException\">\n    /// principal\n    /// or\n    /// properties\n    /// </exception>\n    public virtual async Task<string> CreateSessionIdAsync(ClaimsPrincipal principal, AuthenticationProperties properties)\n    {\n        if (principal == null) throw new ArgumentNullException(nameof(principal));\n        if (properties == null) throw new ArgumentNullException(nameof(properties));\n\n        var currentSubjectId = (await GetUserAsync())?.GetSubjectId();\n        var newSubjectId = principal.GetSubjectId();\n\n        if (properties.GetSessionId() == null || currentSubjectId != newSubjectId)\n        {\n            properties.SetSessionId(CryptoRandom.CreateUniqueId(16, CryptoRandom.OutputFormat.Hex));\n        }\n\n        var sid = properties.GetSessionId();\n        IssueSessionIdCookie(sid);\n\n        Principal = principal;\n        Properties = properties;\n\n        return sid;\n    }\n\n    /// <summary>\n    /// Gets the current authenticated user.\n    /// </summary>\n    /// <returns></returns>\n    public virtual async Task<ClaimsPrincipal> GetUserAsync()\n    {\n        await AuthenticateAsync();\n\n        return Principal;\n    }\n\n    /// <summary>\n    /// Gets the current session identifier.\n    /// </summary>\n    /// <returns></returns>\n    public virtual async Task<string> GetSessionIdAsync()\n    {\n        await AuthenticateAsync();\n\n        return Properties?.GetSessionId();\n    }\n\n    /// <summary>\n    /// Ensures the session identifier cookie asynchronous.\n    /// </summary>\n    /// <returns></returns>\n    public virtual async Task EnsureSessionIdCookieAsync()\n    {\n        var sid = await GetSessionIdAsync();\n        if (sid != null)\n        {\n            IssueSessionIdCookie(sid);\n        }\n        else\n        {\n            await RemoveSessionIdCookieAsync();\n        }\n    }\n\n    /// <summary>\n    /// Removes the session identifier cookie.\n    /// </summary>\n    /// <returns></returns>\n    public virtual Task RemoveSessionIdCookieAsync()\n    {\n        if (HttpContext.Request.Cookies.ContainsKey(CheckSessionCookieName))\n        {\n            // only remove it if we have it in the request\n            var options = CreateSessionIdCookieOptions();\n            options.Expires = Clock.UtcNow.UtcDateTime.AddYears(-1);\n\n            HttpContext.Response.Cookies.Append(CheckSessionCookieName, \".\", options);\n        }\n\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Creates the options for the session cookie.\n    /// </summary>\n    public virtual CookieOptions CreateSessionIdCookieOptions()\n    {\n        var secure = HttpContext.Request.IsHttps;\n        var path = HttpContext.GetIdentityServerBasePath().CleanUrlPath();\n\n        var options = new CookieOptions\n        {\n            HttpOnly = false,\n            Secure = secure,\n            Path = path,\n            IsEssential = true,\n            Domain = CheckSessionCookieDomain,\n            SameSite = CheckSessionCookieSameSiteMode\n        };\n\n        return options;\n    }\n\n    /// <summary>\n    /// Issues the cookie that contains the session id.\n    /// </summary>\n    /// <param name=\"sid\"></param>\n    public virtual void IssueSessionIdCookie(string sid)\n    {\n        if (Options.Endpoints.EnableCheckSessionEndpoint)\n        {\n            if (HttpContext.Request.Cookies[CheckSessionCookieName] != sid)\n            {\n                HttpContext.Response.Cookies.Append(\n                    Options.Authentication.CheckSessionCookieName,\n                    sid,\n                    CreateSessionIdCookieOptions());\n            }\n        }\n    }\n\n    /// <summary>\n    /// Adds a client to the list of clients the user has signed into during their session.\n    /// </summary>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    /// <exception cref=\"ArgumentNullException\">clientId</exception>\n    public virtual async Task AddClientIdAsync(string clientId)\n    {\n        if (clientId == null) throw new ArgumentNullException(nameof(clientId));\n\n        await AuthenticateAsync();\n        if (Properties != null)\n        {\n            var clientIds = Properties.GetClientList();\n            if (!clientIds.Contains(clientId))\n            {\n                Properties.AddClientId(clientId);\n                await UpdateSessionCookie();\n            }\n        }\n    }\n\n    /// <summary>\n    /// Gets the list of clients the user has signed into during their session.\n    /// </summary>\n    /// <returns></returns>\n    public virtual async Task<IEnumerable<string>> GetClientListAsync()\n    {\n        await AuthenticateAsync();\n\n        if (Properties != null)\n        {\n            try\n            {\n                return Properties.GetClientList();\n            }\n            catch (Exception ex)\n            {\n                Logger.LogError(ex, \"Error decoding client list\");\n                // clear so we don't keep failing\n                Properties.RemoveClientList();\n                await UpdateSessionCookie();\n            }\n        }\n\n        return Enumerable.Empty<string>();\n    }\n\n    // client list helpers\n    private async Task UpdateSessionCookie()\n    {\n        await AuthenticateAsync();\n\n        if (Principal == null || Properties == null) throw new InvalidOperationException(\"User is not currently authenticated\");\n\n        var scheme = await HttpContext.GetCookieAuthenticationSchemeAsync();\n        await HttpContext.SignInAsync(scheme, Principal, Properties);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/DistributedDeviceFlowThrottlingService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// The default device flow throttling service using IDistributedCache.\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.IDeviceFlowThrottlingService\" />\npublic class DistributedDeviceFlowThrottlingService : IDeviceFlowThrottlingService\n{\n    private readonly IDistributedCache _cache;\n    private readonly ISystemClock _clock;\n    private readonly IdentityServerOptions _options;\n\n    private const string KeyPrefix = \"devicecode_\";\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DistributedDeviceFlowThrottlingService\"/> class.\n    /// </summary>\n    /// <param name=\"cache\">The cache.</param>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"options\">The options.</param>\n    public DistributedDeviceFlowThrottlingService(\n        IDistributedCache cache,\n        ISystemClock clock,\n        IdentityServerOptions options)\n    {\n        _cache = cache;\n        _clock = clock;\n        _options = options;\n    }\n\n    /// <summary>\n    /// Decides if the requesting client and device code needs to slow down.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    /// <param name=\"details\">The device code details.</param>\n    /// <returns></returns>\n    /// <exception cref=\"ArgumentNullException\">deviceCode</exception>\n    public async Task<bool> ShouldSlowDown(string deviceCode, DeviceCode details)\n    {\n        if (deviceCode == null) throw new ArgumentNullException(nameof(deviceCode));\n        \n        var key = KeyPrefix + deviceCode;\n        var options = new DistributedCacheEntryOptions {AbsoluteExpiration = _clock.UtcNow.AddSeconds(details.Lifetime)};\n\n        var lastSeenAsString = await _cache.GetStringAsync(key);\n\n        // record new\n        if (lastSeenAsString == null)\n        {\n            await _cache.SetStringAsync(key, _clock.UtcNow.ToString(\"O\"), options);\n            return false;\n        }\n\n        // check interval\n        if (DateTime.TryParse(lastSeenAsString, out var lastSeen))\n        {\n            if (_clock.UtcNow < lastSeen.AddSeconds(_options.DeviceFlow.Interval))\n            {\n                await _cache.SetStringAsync(key, _clock.UtcNow.ToString(\"O\"), options);\n                return true;\n            }\n        }\n\n        // store current and continue\n        await _cache.SetStringAsync(key, _clock.UtcNow.ToString(\"O\"), options);\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/LogoutNotificationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Default implementation of logout notification service.\n/// </summary>\npublic class LogoutNotificationService : ILogoutNotificationService\n{\n    private readonly IClientStore _clientStore;\n    private readonly IHttpContextAccessor _httpContextAccessor;\n    private readonly ILogger<LogoutNotificationService> _logger;\n\n\n    /// <summary>\n    /// Ctor.\n    /// </summary>\n    public LogoutNotificationService(\n        IClientStore clientStore,\n        IHttpContextAccessor httpContextAccessor, \n        ILogger<LogoutNotificationService> logger)\n    {\n        _clientStore = clientStore;\n        _httpContextAccessor = httpContextAccessor;\n        _logger = logger;\n    }\n\n    /// <inheritdoc/>\n    public async Task<IEnumerable<string>> GetFrontChannelLogoutNotificationsUrlsAsync(LogoutNotificationContext context)\n    {\n        var frontChannelUrls = new List<string>();\n        foreach (var clientId in context.ClientIds)\n        {\n            var client = await _clientStore.FindEnabledClientByIdAsync(clientId);\n            if (client != null)\n            {\n                if (client.FrontChannelLogoutUri.IsPresent())\n                {\n                    var url = client.FrontChannelLogoutUri;\n\n                    // add session id if required\n                    if (client.ProtocolType == IdentityServerConstants.ProtocolTypes.OpenIdConnect)\n                    {\n                        if (client.FrontChannelLogoutSessionRequired)\n                        {\n                            url = url.AddQueryString(OidcConstants.EndSessionRequest.Sid, context.SessionId);\n                            url = url.AddQueryString(OidcConstants.EndSessionRequest.Issuer, _httpContextAccessor.HttpContext.GetIdentityServerIssuerUri());\n                        }\n                    }\n                    else if (client.ProtocolType == IdentityServerConstants.ProtocolTypes.WsFederation)\n                    {\n                        url = url.AddQueryString(Constants.WsFedSignOut.LogoutUriParameterName, Constants.WsFedSignOut.LogoutUriParameterValue);\n                    }\n\n                    frontChannelUrls.Add(url);\n                }\n            }\n        }\n\n        if (frontChannelUrls.Any())\n        {\n            var msg = frontChannelUrls.Aggregate((x, y) => x + \", \" + y);\n            _logger.LogDebug(\"Client front-channel logout URLs: {0}\", Ioc.Sanitizer.Log.Sanitize(msg));\n        }\n        else\n        {\n            _logger.LogDebug(\"No client front-channel logout URLs\");\n        }\n\n        return frontChannelUrls;\n    }\n\n    /// <inheritdoc/>\n    public async Task<IEnumerable<BackChannelLogoutRequest>> GetBackChannelLogoutNotificationsAsync(LogoutNotificationContext context)\n    {\n        var backChannelLogouts = new List<BackChannelLogoutRequest>();\n        foreach (var clientId in context.ClientIds)\n        {\n            var client = await _clientStore.FindEnabledClientByIdAsync(clientId);\n            if (client != null)\n            {\n                if (client.BackChannelLogoutUri.IsPresent())\n                {\n                    var back = new BackChannelLogoutRequest\n                    {\n                        ClientId = clientId,\n                        LogoutUri = client.BackChannelLogoutUri,\n                        SubjectId = context.SubjectId,\n                        SessionId = context.SessionId,\n                        SessionIdRequired = client.BackChannelLogoutSessionRequired\n                    };\n\n                    backChannelLogouts.Add(back);\n                }\n            }\n        }\n\n        if (backChannelLogouts.Any())\n        {\n            var msg = backChannelLogouts.Select(x => x.LogoutUri).Aggregate((x, y) => x + \", \" + y);\n            _logger.LogDebug(\"Client back-channel logout URLs: {0}\", msg);\n        }\n        else\n        {\n            _logger.LogDebug(\"No client back-channel logout URLs\");\n        }\n\n        return backChannelLogouts;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/NumericUserCodeGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// User code generator using 9 digit number\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.IUserCodeGenerator\" />\npublic class NumericUserCodeGenerator : IUserCodeGenerator\n{\n    /// <summary>\n    /// Gets the type of the user code.\n    /// </summary>\n    /// <value>\n    /// The type of the user code.\n    /// </value>\n    public string UserCodeType => IdentityServerConstants.UserCodeTypes.Numeric;\n\n    /// <summary>\n    /// Gets the retry limit.\n    /// </summary>\n    /// <value>\n    /// The retry limit for getting a unique value.\n    /// </value>\n    public int RetryLimit => 5;\n\n    /// <summary>\n    /// Generates the user code.\n    /// </summary>\n    /// <returns></returns>\n    public Task<string> GenerateAsync()\n    {\n        var next = Next(100000000, 999999999);\n        return Task.FromResult(next.ToString());\n    }\n\n    private int Next(int minValue, int maxValue)\n    {\n        if (minValue > maxValue) throw new ArgumentOutOfRangeException(nameof(minValue));\n        if (minValue == maxValue) return minValue;\n        long diff = maxValue - minValue;\n\n        var uint32Buffer = new byte[8];\n\n        using (var rng = new RNGCryptoServiceProvider())\n        {\n            while (true)\n            {\n                rng.GetBytes(uint32Buffer);\n                var rand = BitConverter.ToUInt32(uint32Buffer, 0);\n\n                const long max = 1 + (long)uint.MaxValue;\n                var remainder = max % diff;\n                if (rand < max - remainder)\n                {\n                    return (int)(minValue + rand % diff);\n                }\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/OidcReturnUrlParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\ninternal class OidcReturnUrlParser : IReturnUrlParser\n{\n    private readonly IAuthorizeRequestValidator _validator;\n    private readonly IUserSession _userSession;\n    private readonly ILogger _logger;\n    private readonly IAuthorizationParametersMessageStore _authorizationParametersMessageStore;\n\n    public OidcReturnUrlParser(\n        IAuthorizeRequestValidator validator,\n        IUserSession userSession,\n        ILogger<OidcReturnUrlParser> logger,\n        IAuthorizationParametersMessageStore authorizationParametersMessageStore = null)\n    {\n        _validator = validator;\n        _userSession = userSession;\n        _logger = logger;\n        _authorizationParametersMessageStore = authorizationParametersMessageStore;\n    }\n\n    public async Task<AuthorizationRequest> ParseAsync(string returnUrl)\n    {\n        if (IsValidReturnUrl(returnUrl))\n        {\n            var parameters = returnUrl.ReadQueryStringAsNameValueCollection();\n            if (_authorizationParametersMessageStore != null)\n            {\n                var messageStoreId = parameters[Constants.AuthorizationParamsStore.MessageStoreIdParameterName];\n                var entry = await _authorizationParametersMessageStore.ReadAsync(messageStoreId);\n                parameters = entry?.Data.FromFullDictionary() ?? new NameValueCollection();\n            }\n\n            var user = await _userSession.GetUserAsync();\n            var result = await _validator.ValidateAsync(parameters, user);\n            if (!result.IsError)\n            {\n                _logger.LogTrace(\"AuthorizationRequest being returned\");\n                return new AuthorizationRequest(result.ValidatedRequest);\n            }\n        }\n\n        _logger.LogTrace(\"No AuthorizationRequest being returned\");\n        return null;\n    }\n\n    public bool IsValidReturnUrl(string returnUrl)\n    {\n        if (returnUrl.IsLocalUrl())\n        {\n            var index = returnUrl.IndexOf('?');\n            if (index >= 0)\n            {\n                returnUrl = returnUrl.Substring(0, index);\n            }\n\n            if (returnUrl.EndsWith(Constants.ProtocolRoutePaths.Authorize, StringComparison.Ordinal) ||\n                returnUrl.EndsWith(Constants.ProtocolRoutePaths.AuthorizeCallback, StringComparison.Ordinal))\n            {\n                _logger.LogTrace(\"returnUrl is valid\");\n                return true;\n            }\n        }\n\n        _logger.LogTrace(\"returnUrl is not valid\");\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/Default/ReturnUrlParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Parses a return URL using all registered URL parsers\n/// </summary>\npublic class ReturnUrlParser\n{\n    private readonly IEnumerable<IReturnUrlParser> _parsers;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ReturnUrlParser\"/> class.\n    /// </summary>\n    /// <param name=\"parsers\">The parsers.</param>\n    public ReturnUrlParser(IEnumerable<IReturnUrlParser> parsers)\n    {\n        _parsers = parsers;\n    }\n\n    /// <summary>\n    /// Parses the return URL.\n    /// </summary>\n    /// <param name=\"returnUrl\">The return URL.</param>\n    /// <returns></returns>\n    public virtual async Task<AuthorizationRequest> ParseAsync(string returnUrl)\n    {\n        foreach (var parser in _parsers)\n        {\n            var result = await parser.ParseAsync(returnUrl);\n            if (result != null)\n            {\n                return result;\n            }\n        }\n\n        return null;            \n    }\n\n    /// <summary>\n    /// Determines whether a return URL is valid.\n    /// </summary>\n    /// <param name=\"returnUrl\">The return URL.</param>\n    /// <returns>\n    ///   <c>true</c> if the return URL is valid; otherwise, <c>false</c>.\n    /// </returns>\n    public virtual bool IsValidReturnUrl(string returnUrl)\n    {\n        foreach (var parser in _parsers)\n        {\n            if (parser.IsValidReturnUrl(returnUrl))\n            {\n                return true;\n            }\n        }\n\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IBackChannelLogoutHttpClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Models making HTTP requests for back-channel logout notification.\n/// </summary>\npublic interface IBackChannelLogoutHttpClient\n{\n    /// <summary>\n    /// Performs HTTP POST.\n    /// </summary>\n    /// <param name=\"url\"></param>\n    /// <param name=\"payload\"></param>\n    /// <returns></returns>\n    Task PostAsync(string url, Dictionary<string, string> payload);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IBackChannelLogoutService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// The service responsible for performing back-channel logout notification.\n/// </summary>\npublic interface IBackChannelLogoutService\n{\n    /// <summary>\n    /// Performs http back-channel logout notification.\n    /// </summary>\n    /// <param name=\"context\">The context of the back channel logout notification.</param>\n    Task SendLogoutNotificationsAsync(LogoutNotificationContext context);\n}\n\n\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/ICache.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Abstract interface to model data caching\n/// </summary>\n/// <typeparam name=\"T\">The data type to be cached</typeparam>\npublic interface ICache<T>\n    where T : class\n{\n    /// <summary>\n    /// Gets the cached data based upon a key index.\n    /// </summary>\n    /// <param name=\"key\">The key.</param>\n    /// <returns>The cached item, or <c>null</c> if no item matches the key.</returns>\n    Task<T> GetAsync(string key);\n\n    /// <summary>\n    /// Caches the data based upon a key\n    /// </summary>\n    /// <param name=\"key\">The key.</param>\n    /// <param name=\"item\">The item.</param>\n    /// <param name=\"expiration\">The expiration.</param>\n    /// <returns></returns>\n    Task SetAsync(string key, T item, TimeSpan expiration);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IClaimsService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// The claims service is responsible for determining which claims to include in tokens\n/// </summary>\npublic interface IClaimsService\n{\n    /// <summary>\n    /// Returns claims for an identity token\n    /// </summary>\n    /// <param name=\"subject\">The subject</param>\n    /// <param name=\"resources\">The resources.</param>\n    /// <param name=\"includeAllIdentityClaims\">Specifies if all claims should be included in the token, or if the userinfo endpoint can be used to retrieve them</param>\n    /// <param name=\"request\">The raw request</param>\n    /// <returns>\n    /// Claims for the identity token\n    /// </returns>\n    Task<IEnumerable<Claim>> GetIdentityTokenClaimsAsync(ClaimsPrincipal subject, ResourceValidationResult resources, bool includeAllIdentityClaims, ValidatedRequest request);\n\n    /// <summary>\n    /// Returns claims for an access token.\n    /// </summary>\n    /// <param name=\"subject\">The subject.</param>\n    /// <param name=\"resources\">The resources.</param>\n    /// <param name=\"request\">The raw request.</param>\n    /// <returns>\n    /// Claims for the access token\n    /// </returns>\n    Task<IEnumerable<Claim>> GetAccessTokenClaimsAsync(ClaimsPrincipal subject, ResourceValidationResult resources, ValidatedRequest request);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IConsentService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Service to retrieve and update consent.\n/// </summary>\npublic interface IConsentService\n{\n    /// <summary>\n    /// Checks if consent is required.\n    /// </summary>\n    /// <param name=\"subject\">The user.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <param name=\"parsedScopes\">The parsed scopes.</param>\n    /// <returns>\n    /// Boolean if consent is required.\n    /// </returns>\n    Task<bool> RequiresConsentAsync(ClaimsPrincipal subject, Client client, IEnumerable<ParsedScopeValue> parsedScopes);\n\n    /// <summary>\n    /// Updates the consent.\n    /// </summary>\n    /// <param name=\"subject\">The subject.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <param name=\"parsedScopes\">The parsed scopes.</param>\n    /// <returns></returns>\n    Task UpdateConsentAsync(ClaimsPrincipal subject, Client client, IEnumerable<ParsedScopeValue> parsedScopes);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IDeviceFlowCodeService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Wrapper service for IDeviceFlowStore.\n/// </summary>\npublic interface IDeviceFlowCodeService\n{\n    /// <summary>\n    /// Stores the device authorization request.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <param name=\"data\">The data.</param>\n    Task<string> StoreDeviceAuthorizationAsync(string userCode, DeviceCode data);\n\n    /// <summary>\n    /// Finds device authorization by user code.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <returns></returns>\n    Task<DeviceCode> FindByUserCodeAsync(string userCode);\n\n    /// <summary>\n    /// Finds device authorization by device code.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    Task<DeviceCode> FindByDeviceCodeAsync(string deviceCode);\n\n    /// <summary>\n    /// Updates device authorization, searching by user code.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <param name=\"data\">The data.</param>\n    Task UpdateByUserCodeAsync(string userCode, DeviceCode data);\n\n    /// <summary>\n    /// Removes the device authorization, searching by device code.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    Task RemoveByDeviceCodeAsync(string deviceCode);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IDeviceFlowInteractionService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n///  Provide services be used by the user interface to communicate with IdentityServer.\n/// </summary>\npublic interface IDeviceFlowInteractionService\n{\n    /// <summary>\n    /// Gets the authorization context asynchronous.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <returns></returns>\n    Task<DeviceFlowAuthorizationRequest> GetAuthorizationContextAsync(string userCode);\n\n    /// <summary>\n    /// Handles the request asynchronous.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <param name=\"consent\">The consent.</param>\n    /// <returns></returns>\n    Task<DeviceFlowInteractionResult> HandleRequestAsync(string userCode, ConsentResponse consent);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IDeviceFlowThrottlingService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// The device flow throttling service.\n/// </summary>\npublic interface IDeviceFlowThrottlingService\n{\n    /// <summary>\n    /// Decides if the requesting client and device code needs to slow down.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    /// <param name=\"details\">The device code details.</param>\n    /// <returns></returns>\n    Task<bool> ShouldSlowDown(string deviceCode, DeviceCode details);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IEventService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Interface for the event service\n/// </summary>\npublic interface IEventService\n{\n    /// <summary>\n    /// Raises the specified event.\n    /// </summary>\n    /// <param name=\"evt\">The event.</param>\n    Task RaiseAsync(Event evt);\n\n    /// <summary>\n    /// Indicates if the type of event will be persisted.\n    /// </summary>\n    bool CanRaiseEventType(EventTypes evtType);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IEventSink.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Models persistence of events\n/// </summary>\npublic interface IEventSink\n{\n    /// <summary>\n    /// Raises the specified event.\n    /// </summary>\n    /// <param name=\"evt\">The event.</param>\n    Task PersistAsync(Event evt);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IHandleGenerationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Interface for the handle generation service\n/// </summary>\npublic interface IHandleGenerationService\n{\n    /// <summary>\n    /// Generates a handle.\n    /// </summary>\n    /// <param name=\"length\">The length.</param>\n    /// <returns></returns>\n    Task<string> GenerateAsync(int length = 32);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IIdentityServerInteractionService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n///  Provide services be used by the user interface to communicate with IdentityServer.\n/// </summary>\npublic interface IIdentityServerInteractionService\n{\n    /// <summary>\n    /// Gets the authorization context.\n    /// </summary>\n    /// <param name=\"returnUrl\">The return URL.</param>\n    Task<AuthorizationRequest> GetAuthorizationContextAsync(string returnUrl);\n\n    /// <summary>\n    /// Indicates if the returnUrl is a valid URL for redirect after login or consent.\n    /// </summary>\n    /// <param name=\"returnUrl\">The return URL.</param>\n    bool IsValidReturnUrl(string returnUrl);\n\n    /// <summary>\n    /// Gets the error context.\n    /// </summary>\n    /// <param name=\"errorId\">The error identifier.</param>\n    Task<ErrorMessage> GetErrorContextAsync(string errorId);\n\n    /// <summary>\n    /// Gets the logout context.\n    /// </summary>\n    /// <param name=\"logoutId\">The logout identifier.</param>\n    Task<LogoutRequest> GetLogoutContextAsync(string logoutId);\n\n    /// <summary>\n    /// Used to create a logoutId if there is not one presently.\n    /// </summary>\n    /// <returns></returns>\n    Task<string> CreateLogoutContextAsync();\n\n    /// <summary>\n    /// Informs IdentityServer of the user's consent.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"consent\">The consent.</param>\n    /// <param name=\"subject\">The subject.</param>\n    Task GrantConsentAsync(AuthorizationRequest request, ConsentResponse consent, string subject = null);\n\n    /// <summary>\n    /// Triggers error back to the client for the authorization request.\n    /// This API is a simpler helper on top of GrantConsentAsync.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"error\"></param>\n    /// <param name=\"errorDescription\"></param>\n    Task DenyAuthorizationAsync(AuthorizationRequest request, AuthorizationError error, string errorDescription = null);\n\n    /// <summary>\n    /// Returns a collection representing all of the user's consents and grants.\n    /// </summary>\n    Task<IEnumerable<Grant>> GetAllUserGrantsAsync();\n\n    /// <summary>\n    /// Revokes all a user's consents and grants for a client.\n    /// </summary>\n    /// <param name=\"clientId\">The client identifier.</param>\n    Task RevokeUserConsentAsync(string clientId);\n\n    /// <summary>\n    /// Revokes all of a user's consents and grants for clients the user has signed into during their current session.\n    /// </summary>\n    Task RevokeTokensForCurrentSessionAsync();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IJwtRequestUriHttpClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Models making HTTP requests for JWTs from the authorize endpoint.\n/// </summary>\npublic interface IJwtRequestUriHttpClient\n{\n    /// <summary>\n    /// Gets a JWT from the url.\n    /// </summary>\n    /// <param name=\"url\"></param>\n    /// <param name=\"client\"></param>\n    /// <returns></returns>\n    Task<string> GetJwtAsync(string url, Client client);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IKeyMaterialService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Interface for the key material service\n/// </summary>\npublic interface IKeyMaterialService\n{\n    /// <summary>\n    /// Gets all validation keys.\n    /// </summary>\n    /// <returns></returns>\n    Task<IEnumerable<SecurityKeyInfo>> GetValidationKeysAsync();\n\n    /// <summary>\n    /// Gets the signing credentials.\n    /// </summary>\n    /// <param name=\"allowedAlgorithms\">Collection of algorithms used to filter the server supported algorithms. \n    /// A value of null or empty indicates that the server default should be returned.</param>\n    /// <returns></returns>\n    Task<SigningCredentials> GetSigningCredentialsAsync(IEnumerable<string> allowedAlgorithms = null);\n\n    /// <summary>\n    /// Gets all signing credentials.\n    /// </summary>\n    /// <returns></returns>\n    Task<IEnumerable<SigningCredentials>> GetAllSigningCredentialsAsync();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/ILogoutNotificationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Provides features for OIDC signout notifications.\n/// </summary>\npublic interface ILogoutNotificationService\n{\n    /// <summary>\n    /// Builds the URLs needed for front-channel logout notification.\n    /// </summary>\n    /// <param name=\"context\">The context for the logout notification.</param>\n    Task<IEnumerable<string>> GetFrontChannelLogoutNotificationsUrlsAsync(LogoutNotificationContext context);\n\n    /// <summary>\n    /// Builds the http back-channel logout request data for the collection of clients.\n    /// </summary>\n    /// <param name=\"context\">The context for the logout notification.</param>\n    Task<IEnumerable<BackChannelLogoutRequest>> GetBackChannelLogoutNotificationsAsync(LogoutNotificationContext context);\n}\n\n/// <summary>\n/// Information necessary to make a back-channel logout request to a client.\n/// </summary>\npublic class BackChannelLogoutRequest\n{\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets the subject identifier.\n    /// </summary>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the session identifier.\n    /// </summary>\n    public string SessionId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the back channel logout URI.\n    /// </summary>\n    public string LogoutUri { get; set; }\n\n    /// <summary>\n    /// Gets a value indicating whether the session identifier is required.\n    /// </summary>\n    public bool SessionIdRequired { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IPersistedGrantService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Implements persisted grant logic\n/// </summary>\npublic interface IPersistedGrantService\n{\n    /// <summary>\n    /// Gets all grants for a given subject ID.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <returns></returns>\n    Task<IEnumerable<Grant>> GetAllGrantsAsync(string subjectId);\n\n    /// <summary>\n    /// Removes all grants for a given subject id, and optionally client id and session id combination.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier (optional).</param>\n    /// <param name=\"sessionId\">The sesion id (optional).</param>\n    /// <returns></returns>\n    Task RemoveAllGrantsAsync(string subjectId, string clientId = null, string sessionId = null);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IProfileService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// This interface allows IdentityServer to connect to your user and profile store.\n/// </summary>\npublic interface IProfileService\n{\n    /// <summary>\n    /// This method is called whenever claims about the user are requested (e.g. during token creation or via the userinfo endpoint)\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    Task GetProfileDataAsync(ProfileDataRequestContext context);\n\n    /// <summary>\n    /// This method gets called whenever identity server needs to determine if the user is valid or active (e.g. if the user's account has been deactivated since they logged in).\n    /// (e.g. during token issuance or validation).\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    Task IsActiveAsync(IsActiveContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IRefreshTokenService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Implements refresh token creation and validation\n/// </summary>\npublic interface IRefreshTokenService\n{\n    /// <summary>\n    /// Validates a refresh token.\n    /// </summary>\n    /// <param name=\"token\">The refresh token.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns></returns>\n    Task<TokenValidationResult> ValidateRefreshTokenAsync(string token, Client client);\n    \n    /// <summary>\n    /// Creates the refresh token.\n    /// </summary>\n    /// <param name=\"subject\">The subject.</param>\n    /// <param name=\"accessToken\">The access token.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns>\n    /// The refresh token handle\n    /// </returns>\n    Task<string> CreateRefreshTokenAsync(ClaimsPrincipal subject, Token accessToken, Client client);\n\n    /// <summary>\n    /// Updates the refresh token.\n    /// </summary>\n    /// <param name=\"handle\">The handle.</param>\n    /// <param name=\"refreshToken\">The refresh token.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns>\n    /// The refresh token handle\n    /// </returns>\n    Task<string> UpdateRefreshTokenAsync(string handle, RefreshToken refreshToken, Client client);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IReplayCache.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Interface for replay cache implementations\n/// </summary>\npublic interface IReplayCache\n{\n    /// <summary>\n    /// Adds a handle to the cache \n    /// </summary>\n    /// <param name=\"purpose\"></param>\n    /// <param name=\"handle\"></param>\n    /// <param name=\"expiration\"></param>\n    /// <returns></returns>\n    Task AddAsync(string purpose, string handle, DateTimeOffset expiration);\n\n\n    /// <summary>\n    /// Checks if a cached handle exists \n    /// </summary>\n    /// <param name=\"purpose\"></param>\n    /// <param name=\"handle\"></param>\n    /// <returns></returns>\n    Task<bool> ExistsAsync(string purpose, string handle);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IReturnUrlParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Interface for the return URL parser\n/// </summary>\npublic interface IReturnUrlParser\n{\n    /// <summary>\n    /// Parses a return URL.\n    /// </summary>\n    /// <param name=\"returnUrl\">The return URL.</param>\n    /// <returns></returns>\n    Task<AuthorizationRequest> ParseAsync(string returnUrl);\n\n    /// <summary>\n    /// Determines whether the return URL is valid.\n    /// </summary>\n    /// <param name=\"returnUrl\">The return URL.</param>\n    /// <returns>\n    ///   <c>true</c> if the return URL is valid; otherwise, <c>false</c>.\n    /// </returns>\n    bool IsValidReturnUrl(string returnUrl);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/ITokenCreationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Logic for creating security tokens\n/// </summary>\npublic interface ITokenCreationService\n{\n    /// <summary>\n    /// Creates a token.\n    /// </summary>\n    /// <param name=\"token\">The token description.</param>\n    /// <returns>A protected and serialized security token</returns>\n    Task<string> CreateTokenAsync(Token token);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/ITokenService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Logic for creating security tokens\n/// </summary>\npublic interface ITokenService\n{\n    /// <summary>\n    /// Creates an identity token.\n    /// </summary>\n    /// <param name=\"request\">The token creation request.</param>\n    /// <returns>An identity token</returns>\n    Task<Token> CreateIdentityTokenAsync(TokenCreationRequest request);\n\n    /// <summary>\n    /// Creates an access token.\n    /// </summary>\n    /// <param name=\"request\">The token creation request.</param>\n    /// <returns>An access token</returns>\n    Task<Token> CreateAccessTokenAsync(TokenCreationRequest request);\n\n    /// <summary>\n    /// Creates a serialized and protected security token.\n    /// </summary>\n    /// <param name=\"token\">The token.</param>\n    /// <returns>A security token in serialized form</returns>\n    Task<string> CreateSecurityTokenAsync(Token token);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IUserCodeGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Implements device flow user code generation\n/// </summary>\npublic interface IUserCodeGenerator\n{\n    /// <summary>\n    /// Gets the type of the user code.\n    /// </summary>\n    /// <value>\n    /// The type of the user code.\n    /// </value>\n    string UserCodeType { get; }\n\n    /// <summary>\n    /// Gets the retry limit.\n    /// </summary>\n    /// <value>\n    /// The retry limit for getting a unique value.\n    /// </value>\n    int RetryLimit { get; }\n\n    /// <summary>\n    /// Generates the user code.\n    /// </summary>\n    /// <returns></returns>\n    Task<string> GenerateAsync();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IUserCodeService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Implements user code generation\n/// </summary>\npublic interface IUserCodeService\n{\n    /// <summary>\n    /// Gets the user code generator.\n    /// </summary>\n    /// <param name=\"userCodeType\">Type of user code.</param>\n    /// <returns></returns>\n    Task<IUserCodeGenerator> GetGenerator(string userCodeType);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/IUserSession.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Models a user's authentication session\n/// </summary>\npublic interface IUserSession\n{\n    /// <summary>\n    /// Creates a session identifier for the signin context and issues the session id cookie.\n    /// </summary>\n    Task<string> CreateSessionIdAsync(ClaimsPrincipal principal, AuthenticationProperties properties);\n\n    /// <summary>\n    /// Gets the current authenticated user.\n    /// </summary>\n    Task<ClaimsPrincipal> GetUserAsync();\n\n    /// <summary>\n    /// Gets the current session identifier.\n    /// </summary>\n    /// <returns></returns>\n    Task<string> GetSessionIdAsync();\n\n    /// <summary>\n    /// Ensures the session identifier cookie asynchronous.\n    /// </summary>\n    /// <returns></returns>\n    Task EnsureSessionIdCookieAsync();\n\n    /// <summary>\n    /// Removes the session identifier cookie.\n    /// </summary>\n    Task RemoveSessionIdCookieAsync();\n\n    /// <summary>\n    /// Adds a client to the list of clients the user has signed into during their session.\n    /// </summary>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    Task AddClientIdAsync(string clientId);\n\n    /// <summary>\n    /// Gets the list of clients the user has signed into during their session.\n    /// </summary>\n    /// <returns></returns>\n    Task<IEnumerable<string>> GetClientListAsync();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Services/InMemory/InMemoryCorsPolicyService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// CORS policy service that configures the allowed origins from a list of clients' redirect URLs.\n/// </summary>\npublic class InMemoryCorsPolicyService : ICorsPolicyService\n{\n    /// <summary>\n    /// Logger\n    /// </summary>\n    protected readonly ILogger Logger;\n    /// <summary>\n    /// Clients applications list\n    /// </summary>\n    protected readonly IEnumerable<Client> Clients;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"InMemoryCorsPolicyService\"/> class.\n    /// </summary>\n    /// <param name=\"logger\">The logger</param>\n    /// <param name=\"clients\">The clients.</param>\n    public InMemoryCorsPolicyService(ILogger<InMemoryCorsPolicyService> logger, IEnumerable<Client> clients)\n    {\n        Logger = logger;\n        Clients = clients ?? Enumerable.Empty<Client>();\n    }\n\n    /// <summary>\n    /// Determines whether origin is allowed.\n    /// </summary>\n    /// <param name=\"origin\">The origin.</param>\n    /// <returns></returns>\n    public virtual Task<bool> IsOriginAllowedAsync(string origin)\n    {\n        var query =\n            from client in Clients\n            from url in client.AllowedCorsOrigins\n            select url.GetOrigin();\n\n        var result = query.Contains(origin, StringComparer.OrdinalIgnoreCase);\n\n        if (result)\n        {\n            Logger.LogDebug(\"Client list checked and origin: {0} is allowed\", Ioc.Sanitizer.Log.Sanitize(origin));\n        }\n        else\n        {\n            Logger.LogDebug(\"Client list checked and origin: {0} is not allowed\", Ioc.Sanitizer.Log.Sanitize(origin));\n        }\n\n        return Task.FromResult(result);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Caching/CachingClientStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Cache decorator for IClientStore\n/// </summary>\n/// <typeparam name=\"T\"></typeparam>\n/// <seealso cref=\"IdentityServer8.Stores.IClientStore\" />\npublic class CachingClientStore<T> : IClientStore\n    where T : IClientStore\n{\n    private readonly IdentityServerOptions _options;\n    private readonly ICache<Client> _cache;\n    private readonly IClientStore _inner;\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"CachingClientStore{T}\"/> class.\n    /// </summary>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"inner\">The inner.</param>\n    /// <param name=\"cache\">The cache.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public CachingClientStore(IdentityServerOptions options, T inner, ICache<Client> cache, ILogger<CachingClientStore<T>> logger)\n    {\n        _options = options;\n        _inner = inner;\n        _cache = cache;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Finds a client by id\n    /// </summary>\n    /// <param name=\"clientId\">The client id</param>\n    /// <returns>\n    /// The client\n    /// </returns>\n    public async Task<Client> FindClientByIdAsync(string clientId)\n    {\n        var client = await _cache.GetAsync(clientId,\n            _options.Caching.ClientStoreExpiration,\n            async () => await _inner.FindClientByIdAsync(clientId),\n            _logger);\n\n        return client;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Caching/CachingCorsPolicyService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Caching decorator for ICorsPolicyService\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.ICorsPolicyService\" />\npublic class CachingCorsPolicyService<T> : ICorsPolicyService\n    where T : ICorsPolicyService\n{\n    /// <summary>\n    /// Class to model entries in CORS origin cache.\n    /// </summary>\n    public class CorsCacheEntry\n    {\n        /// <summary>\n        /// Ctor.\n        /// </summary>\n        public CorsCacheEntry(bool allowed)\n        {\n            Allowed = allowed;\n        }\n\n        /// <summary>\n        /// Is origin allowed.\n        /// </summary>\n        public bool Allowed { get; }\n    }\n\n    private readonly IdentityServerOptions Options;\n    private readonly ICache<CorsCacheEntry> CorsCache;\n    private readonly ICorsPolicyService Inner;\n    private readonly ILogger Logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"CachingResourceStore{T}\"/> class.\n    /// </summary>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"inner\">The inner.</param>\n    /// <param name=\"corsCache\">The CORS origin cache.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public CachingCorsPolicyService(IdentityServerOptions options,\n        T inner,\n        ICache<CorsCacheEntry> corsCache,\n        ILogger<CachingCorsPolicyService<T>> logger)\n    {\n        Options = options;\n        Inner = inner;\n        CorsCache = corsCache;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Determines whether origin is allowed.\n    /// </summary>\n    /// <param name=\"origin\">The origin.</param>\n    /// <returns></returns>\n    public virtual async Task<bool> IsOriginAllowedAsync(string origin)\n    {\n        var entry = await CorsCache.GetAsync(origin,\n                      Options.Caching.CorsExpiration,\n                      async () => new CorsCacheEntry(await Inner.IsOriginAllowedAsync(origin)),\n                      Logger);\n\n        return entry.Allowed;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Caching/CachingResourceStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Caching decorator for IResourceStore\n/// </summary>\n/// <typeparam name=\"T\"></typeparam>\n/// <seealso cref=\"IdentityServer8.Stores.IResourceStore\" />\npublic class CachingResourceStore<T> : IResourceStore\n    where T : IResourceStore\n{\n    private const string AllKey = \"__all__\";\n\n    private readonly IdentityServerOptions _options;\n    \n    private readonly ICache<IEnumerable<IdentityResource>> _identityCache;\n    private readonly ICache<IEnumerable<ApiResource>> _apiByScopeCache;\n    private readonly ICache<IEnumerable<ApiScope>> _apiScopeCache;\n    private readonly ICache<IEnumerable<ApiResource>> _apiResourceCache;\n    private readonly ICache<Resources> _allCache;\n    \n    private readonly IResourceStore _inner;\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"CachingResourceStore{T}\"/> class.\n    /// </summary>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"inner\">The inner.</param>\n    /// <param name=\"identityCache\">The identity cache.</param>\n    /// <param name=\"apiByScopeCache\">The API by scope cache.</param>\n    /// <param name=\"apisCache\">The API cache.</param>\n    /// <param name=\"scopeCache\"></param>\n    /// <param name=\"allCache\">All cache.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public CachingResourceStore(IdentityServerOptions options, T inner, \n        ICache<IEnumerable<IdentityResource>> identityCache, \n        ICache<IEnumerable<ApiResource>> apiByScopeCache,\n        ICache<IEnumerable<ApiResource>> apisCache,\n        ICache<IEnumerable<ApiScope>> scopeCache,\n        ICache<Resources> allCache,\n        ILogger<CachingResourceStore<T>> logger)\n    {\n        _options = options;\n        _inner = inner;\n        _identityCache = identityCache;\n        _apiByScopeCache = apiByScopeCache;\n        _apiResourceCache = apisCache;\n        _apiScopeCache = scopeCache;\n        _allCache = allCache;\n        _logger = logger;\n    }\n\n    private string GetKey(IEnumerable<string> names)\n    {\n        if (names == null || !names.Any()) return string.Empty;\n        return names.OrderBy(x => x).Aggregate((x, y) => x + \",\" + y);\n    }\n\n    /// <inheritdoc/>\n    public async Task<Resources> GetAllResourcesAsync()\n    {\n        var key = AllKey;\n\n        var all = await _allCache.GetAsync(key,\n            _options.Caching.ResourceStoreExpiration,\n            async () => await _inner.GetAllResourcesAsync(),\n            _logger);\n\n        return all;\n    }\n\n    /// <inheritdoc/>\n    public async Task<IEnumerable<ApiResource>> FindApiResourcesByNameAsync(IEnumerable<string> apiResourceNames)\n    {\n        var key = GetKey(apiResourceNames);\n\n        var apis = await _apiResourceCache.GetAsync(key,\n            _options.Caching.ResourceStoreExpiration,\n            async () => await _inner.FindApiResourcesByNameAsync(apiResourceNames),\n            _logger);\n\n        return apis;\n    }\n\n    /// <inheritdoc/>\n    public async Task<IEnumerable<IdentityResource>> FindIdentityResourcesByScopeNameAsync(IEnumerable<string> names)\n    {\n        var key = GetKey(names);\n\n        var identities = await _identityCache.GetAsync(key,\n            _options.Caching.ResourceStoreExpiration,\n            async () => await _inner.FindIdentityResourcesByScopeNameAsync(names),\n            _logger);\n\n        return identities;\n    }\n\n    /// <inheritdoc/>\n    public async Task<IEnumerable<ApiResource>> FindApiResourcesByScopeNameAsync(IEnumerable<string> names)\n    {\n        var key = GetKey(names);\n\n        var apis = await _apiByScopeCache.GetAsync(key,\n            _options.Caching.ResourceStoreExpiration,\n            async () => await _inner.FindApiResourcesByScopeNameAsync(names),\n            _logger);\n\n        return apis;\n    }\n\n    /// <inheritdoc/>\n    public async Task<IEnumerable<ApiScope>> FindApiScopesByNameAsync(IEnumerable<string> scopeNames)\n    {\n        var key = GetKey(scopeNames);\n\n        var apis = await _apiScopeCache.GetAsync(key,\n            _options.Caching.ResourceStoreExpiration,\n            async () => await _inner.FindApiScopesByNameAsync(scopeNames),\n            _logger);\n\n        return apis;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Default/ConsentMessageStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\ninternal class ConsentMessageStore : IConsentMessageStore\n{\n    protected readonly MessageCookie<ConsentResponse> Cookie;\n\n    public ConsentMessageStore(MessageCookie<ConsentResponse> cookie)\n    {\n        Cookie = cookie;\n    }\n\n    public virtual Task DeleteAsync(string id)\n    {\n        Cookie.Clear(id);\n        return Task.CompletedTask;\n    }\n\n    public virtual Task<Message<ConsentResponse>> ReadAsync(string id)\n    {\n        return Task.FromResult(Cookie.Read(id));\n    }\n\n    public virtual Task WriteAsync(string id, Message<ConsentResponse> message)\n    {\n        Cookie.Write(id, message);\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Default/DefaultAuthorizationCodeStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Default authorization code store.\n/// </summary>\npublic class DefaultAuthorizationCodeStore : DefaultGrantStore<AuthorizationCode>, IAuthorizationCodeStore\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultAuthorizationCodeStore\"/> class.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"serializer\">The serializer.</param>\n    /// <param name=\"handleGenerationService\">The handle generation service.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultAuthorizationCodeStore(\n        IPersistedGrantStore store,\n        IPersistentGrantSerializer serializer,\n        IHandleGenerationService handleGenerationService,\n        ILogger<DefaultAuthorizationCodeStore> logger)\n        : base(IdentityServerConstants.PersistedGrantTypes.AuthorizationCode, store, serializer, handleGenerationService, logger)\n    {\n    }\n\n    /// <summary>\n    /// Stores the authorization code asynchronous.\n    /// </summary>\n    /// <param name=\"code\">The code.</param>\n    /// <returns></returns>\n    public Task<string> StoreAuthorizationCodeAsync(AuthorizationCode code)\n    {\n        return CreateItemAsync(code, code.ClientId, code.Subject.GetSubjectId(), code.SessionId, code.Description, code.CreationTime, code.Lifetime);\n    }\n\n    /// <summary>\n    /// Gets the authorization code asynchronous.\n    /// </summary>\n    /// <param name=\"code\">The code.</param>\n    /// <returns></returns>\n    public Task<AuthorizationCode> GetAuthorizationCodeAsync(string code)\n    {\n        return GetItemAsync(code);\n    }\n\n    /// <summary>\n    /// Removes the authorization code asynchronous.\n    /// </summary>\n    /// <param name=\"code\">The code.</param>\n    /// <returns></returns>\n    public Task RemoveAuthorizationCodeAsync(string code)\n    {\n        return RemoveItemAsync(code);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Default/DefaultGrantStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Base class for persisting grants using the IPersistedGrantStore.\n/// </summary>\n/// <typeparam name=\"T\"></typeparam>\npublic class DefaultGrantStore<T>\n{\n    /// <summary>\n    /// The grant type being stored.\n    /// </summary>\n    protected string GrantType { get; }\n\n    /// <summary>\n    /// The logger.\n    /// </summary>\n    protected ILogger Logger { get; }\n\n    /// <summary>\n    /// The PersistedGrantStore.\n    /// </summary>\n    protected IPersistedGrantStore Store { get; }\n\n    /// <summary>\n    /// The PersistentGrantSerializer;\n    /// </summary>\n    protected IPersistentGrantSerializer Serializer { get; }\n\n    /// <summary>\n    /// The HandleGenerationService.\n    /// </summary>\n    protected IHandleGenerationService HandleGenerationService { get; }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultGrantStore{T}\"/> class.\n    /// </summary>\n    /// <param name=\"grantType\">Type of the grant.</param>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"serializer\">The serializer.</param>\n    /// <param name=\"handleGenerationService\">The handle generation service.</param>\n    /// <param name=\"logger\">The logger.</param>\n    /// <exception cref=\"System.ArgumentNullException\">grantType</exception>\n    protected DefaultGrantStore(string grantType,\n        IPersistedGrantStore store,\n        IPersistentGrantSerializer serializer,\n        IHandleGenerationService handleGenerationService,\n        ILogger logger)\n    {\n        if (grantType.IsMissing()) throw new ArgumentNullException(nameof(grantType));\n\n        GrantType = grantType;\n        Store = store;\n        Serializer = serializer;\n        HandleGenerationService = handleGenerationService;\n        Logger = logger;\n    }\n\n    private const string KeySeparator = \":\";\n\n    /// <summary>\n    /// Gets the hashed key.\n    /// </summary>\n    /// <param name=\"value\">The value.</param>\n    /// <returns></returns>\n    protected virtual string GetHashedKey(string value)\n    {\n        return (value + KeySeparator + GrantType).Sha256();\n    }\n\n    /// <summary>\n    /// Gets the item.\n    /// </summary>\n    /// <param name=\"key\">The key.</param>\n    /// <returns></returns>\n    protected virtual async Task<T> GetItemAsync(string key)\n    {\n        var hashedKey = GetHashedKey(key);\n\n        var grant = await Store.GetAsync(hashedKey);\n        if (grant != null && grant.Type == GrantType)\n        {\n            try\n            {\n                return Serializer.Deserialize<T>(grant.Data);\n            }\n            catch (Exception ex)\n            {\n                Logger.LogError(ex, \"Failed to deserialize JSON from grant store.\");\n            }\n        }\n        else\n        {\n            Logger.LogDebug(\"{grantType} grant with value: {key} not found in store.\", GrantType, Ioc.Sanitizer.Log.Sanitize(key));\n        }\n\n        return default;\n    }\n\n    /// <summary>\n    /// Creates the item.\n    /// </summary>\n    /// <param name=\"item\">The item.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"sessionId\">The session identifier.</param>\n    /// <param name=\"description\">The description.</param>\n    /// <param name=\"created\">The created.</param>\n    /// <param name=\"lifetime\">The lifetime.</param>\n    /// <returns></returns>\n    protected virtual async Task<string> CreateItemAsync(T item, string clientId, string subjectId, string sessionId, string description, DateTime created, int lifetime)\n    {\n        var handle = await HandleGenerationService.GenerateAsync();\n        await StoreItemAsync(handle, item, clientId, subjectId, sessionId, description, created, created.AddSeconds(lifetime));\n        return handle;\n    }\n\n    /// <summary>\n    /// Stores the item.\n    /// </summary>\n    /// <param name=\"key\">The key.</param>\n    /// <param name=\"item\">The item.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"sessionId\">The session identifier.</param>\n    /// <param name=\"description\">The description.</param>\n    /// <param name=\"created\">The created time.</param>\n    /// <param name=\"expiration\">The expiration.</param>\n    /// <param name=\"consumedTime\">The consumed time.</param>\n    /// <returns></returns>\n    protected virtual async Task StoreItemAsync(string key, T item, string clientId, string subjectId, string sessionId, string description, DateTime created, DateTime? expiration, DateTime? consumedTime = null)\n    {\n        key = GetHashedKey(key);\n\n        var json = Serializer.Serialize(item);\n\n        var grant = new PersistedGrant\n        {\n            Key = key,\n            Type = GrantType,\n            ClientId = clientId,\n            SubjectId = subjectId,\n            SessionId = sessionId,\n            Description = description,\n            CreationTime = created,\n            Expiration = expiration,\n            ConsumedTime = consumedTime,\n            Data = json\n        };\n\n        await Store.StoreAsync(grant);\n    }\n\n    /// <summary>\n    /// Removes the item.\n    /// </summary>\n    /// <param name=\"key\">The key.</param>\n    /// <returns></returns>\n    protected virtual async Task RemoveItemAsync(string key)\n    {\n        key = GetHashedKey(key);\n        await Store.RemoveAsync(key);\n    }\n\n    /// <summary>\n    /// Removes all items for a subject id / cliend id combination.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    protected virtual async Task RemoveAllAsync(string subjectId, string clientId)\n    {\n        await Store.RemoveAllAsync(new PersistedGrantFilter\n        {\n            SubjectId = subjectId,\n            ClientId = clientId,\n            Type = GrantType\n        });\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Default/DefaultReferenceTokenStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Default reference token store.\n/// </summary>\npublic class DefaultReferenceTokenStore : DefaultGrantStore<Token>, IReferenceTokenStore\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultReferenceTokenStore\"/> class.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"serializer\">The serializer.</param>\n    /// <param name=\"handleGenerationService\">The handle generation service.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultReferenceTokenStore(\n        IPersistedGrantStore store, \n        IPersistentGrantSerializer serializer,\n        IHandleGenerationService handleGenerationService,\n        ILogger<DefaultReferenceTokenStore> logger) \n        : base(IdentityServerConstants.PersistedGrantTypes.ReferenceToken, store, serializer, handleGenerationService, logger)\n    {\n    }\n\n    /// <summary>\n    /// Stores the reference token asynchronous.\n    /// </summary>\n    /// <param name=\"token\">The token.</param>\n    /// <returns></returns>\n    public Task<string> StoreReferenceTokenAsync(Token token)\n    {\n        return CreateItemAsync(token, token.ClientId, token.SubjectId, token.SessionId, token.Description, token.CreationTime, token.Lifetime);\n    }\n\n    /// <summary>\n    /// Gets the reference token asynchronous.\n    /// </summary>\n    /// <param name=\"handle\">The handle.</param>\n    /// <returns></returns>\n    public Task<Token> GetReferenceTokenAsync(string handle)\n    {\n        return GetItemAsync(handle);\n    }\n\n    /// <summary>\n    /// Removes the reference token asynchronous.\n    /// </summary>\n    /// <param name=\"handle\">The handle.</param>\n    /// <returns></returns>\n    public Task RemoveReferenceTokenAsync(string handle)\n    {\n        return RemoveItemAsync(handle);\n    }\n\n    /// <summary>\n    /// Removes the reference tokens asynchronous.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    public Task RemoveReferenceTokensAsync(string subjectId, string clientId)\n    {\n        return RemoveAllAsync(subjectId, clientId);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Default/DefaultRefreshTokenStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Default refresh token store.\n/// </summary>\npublic class DefaultRefreshTokenStore : DefaultGrantStore<RefreshToken>, IRefreshTokenStore\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultRefreshTokenStore\"/> class.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"serializer\">The serializer.</param>\n    /// <param name=\"handleGenerationService\">The handle generation service.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultRefreshTokenStore(\n        IPersistedGrantStore store, \n        IPersistentGrantSerializer serializer, \n        IHandleGenerationService handleGenerationService,\n        ILogger<DefaultRefreshTokenStore> logger) \n        : base(IdentityServerConstants.PersistedGrantTypes.RefreshToken, store, serializer, handleGenerationService, logger)\n    {\n    }\n\n    /// <summary>\n    /// Stores the refresh token.\n    /// </summary>\n    /// <param name=\"refreshToken\">The refresh token.</param>\n    /// <returns></returns>\n    public async Task<string> StoreRefreshTokenAsync(RefreshToken refreshToken)\n    {\n        return await CreateItemAsync(refreshToken, refreshToken.ClientId, refreshToken.SubjectId, refreshToken.SessionId, refreshToken.Description, refreshToken.CreationTime, refreshToken.Lifetime);\n    }\n\n    /// <summary>\n    /// Updates the refresh token.\n    /// </summary>\n    /// <param name=\"handle\">The handle.</param>\n    /// <param name=\"refreshToken\">The refresh token.</param>\n    /// <returns></returns>\n    public Task UpdateRefreshTokenAsync(string handle, RefreshToken refreshToken)\n    {\n        return StoreItemAsync(handle, refreshToken, refreshToken.ClientId, refreshToken.SubjectId, refreshToken.SessionId, refreshToken.Description, refreshToken.CreationTime, refreshToken.CreationTime.AddSeconds(refreshToken.Lifetime), refreshToken.ConsumedTime);\n    }\n\n    /// <summary>\n    /// Gets the refresh token.\n    /// </summary>\n    /// <param name=\"refreshTokenHandle\">The refresh token handle.</param>\n    /// <returns></returns>\n    public Task<RefreshToken> GetRefreshTokenAsync(string refreshTokenHandle)\n    {\n        return GetItemAsync(refreshTokenHandle);\n    }\n\n    /// <summary>\n    /// Removes the refresh token.\n    /// </summary>\n    /// <param name=\"refreshTokenHandle\">The refresh token handle.</param>\n    /// <returns></returns>\n    public Task RemoveRefreshTokenAsync(string refreshTokenHandle)\n    {\n        return RemoveItemAsync(refreshTokenHandle);\n    }\n\n    /// <summary>\n    /// Removes the refresh tokens.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    public Task RemoveRefreshTokensAsync(string subjectId, string clientId)\n    {\n        return RemoveAllAsync(subjectId, clientId);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Default/DefaultUserConsentStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Default user consent store.\n/// </summary>\npublic class DefaultUserConsentStore : DefaultGrantStore<Consent>, IUserConsentStore\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultUserConsentStore\"/> class.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"serializer\">The serializer.</param>\n    /// <param name=\"handleGenerationService\">The handle generation service.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultUserConsentStore(\n        IPersistedGrantStore store, \n        IPersistentGrantSerializer serializer,\n        IHandleGenerationService handleGenerationService,\n        ILogger<DefaultUserConsentStore> logger) \n        : base(IdentityServerConstants.PersistedGrantTypes.UserConsent, store, serializer, handleGenerationService, logger)\n    {\n    }\n\n    private string GetConsentKey(string subjectId, string clientId)\n    {\n        return clientId + \"|\" + subjectId;\n    }\n\n    /// <summary>\n    /// Stores the user consent asynchronous.\n    /// </summary>\n    /// <param name=\"consent\">The consent.</param>\n    /// <returns></returns>\n    public Task StoreUserConsentAsync(Consent consent)\n    {\n        var key = GetConsentKey(consent.SubjectId, consent.ClientId);\n        return StoreItemAsync(key, consent, consent.ClientId, consent.SubjectId, null, null, consent.CreationTime, consent.Expiration);\n    }\n\n    /// <summary>\n    /// Gets the user consent asynchronous.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    public Task<Consent> GetUserConsentAsync(string subjectId, string clientId)\n    {\n        var key = GetConsentKey(subjectId, clientId);\n        return GetItemAsync(key);\n    }\n\n    /// <summary>\n    /// Removes the user consent asynchronous.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    public Task RemoveUserConsentAsync(string subjectId, string clientId)\n    {\n        var key = GetConsentKey(subjectId, clientId);\n        return RemoveItemAsync(key);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Default/DistributedCacheAuthorizationParametersMessageStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores.Default;\n\n/// <summary>\n/// Implementation of IAuthorizationParametersMessageStore that uses the IDistributedCache.\n/// </summary>\npublic class DistributedCacheAuthorizationParametersMessageStore : IAuthorizationParametersMessageStore\n{\n    private readonly IDistributedCache _distributedCache;\n    private readonly IHandleGenerationService _handleGenerationService;\n\n    /// <summary>\n    /// Ctor.\n    /// </summary>\n    /// <param name=\"distributedCache\"></param>\n    /// <param name=\"handleGenerationService\"></param>\n    public DistributedCacheAuthorizationParametersMessageStore(IDistributedCache distributedCache, IHandleGenerationService handleGenerationService)\n    {\n        _distributedCache = distributedCache;\n        _handleGenerationService = handleGenerationService;\n    }\n\n    private string CacheKeyPrefix => \"DistributedCacheAuthorizationParametersMessageStore\";\n    \n    /// <inheritdoc/>\n    public async Task<string> WriteAsync(Message<IDictionary<string, string[]>> message)\n    {\n        // since this store is trusted and the JWT request processing has provided redundant entries\n        // in the NameValueCollection, we are removing the JWT \"request_uri\" param so that when they\n        // are reloaded/revalidated we don't re-trigger outbound requests. we could possibly do the\n        // same for the \"request\" param, but it's less of a concern (as it's just a signature check).\n        message.Data.Remove(OidcConstants.AuthorizeRequest.RequestUri);\n\n        var key = await _handleGenerationService.GenerateAsync();\n        var cacheKey = $\"{CacheKeyPrefix}-{key}\";\n        \n        var json = ObjectSerializer.ToString(message);\n\n        var options = new DistributedCacheEntryOptions();\n        options.SetSlidingExpiration(Constants.DefaultCacheDuration);\n\n        await _distributedCache.SetStringAsync(cacheKey, json, options);\n\n        return key;\n    }\n\n    /// <inheritdoc/>\n    public async Task<Message<IDictionary<string, string[]>>> ReadAsync(string id)\n    {\n        var cacheKey = $\"{CacheKeyPrefix}-{id}\";\n        var json = await _distributedCache.GetStringAsync(cacheKey);\n\n        if (json == null)\n        {\n            return new Message<IDictionary<string, string[]>>(new Dictionary<string, string[]>());\n        }\n\n        return ObjectSerializer.FromString<Message<IDictionary<string, string[]>>>(json);\n    }\n\n    /// <inheritdoc/>\n    public Task DeleteAsync(string id)\n    {\n        return _distributedCache.RemoveAsync(id);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Default/ProtectedDataMessageStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore.DataProtection;\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// IMessageStore implementation that uses data protection to protect message.\n/// </summary>\n/// <typeparam name=\"TModel\"></typeparam>\npublic class ProtectedDataMessageStore<TModel> : IMessageStore<TModel>\n{\n    private const string Purpose = \"IdentityServer8.Stores.ProtectedDataMessageStore\";\n\n    /// <summary>\n    /// The data protector.\n    /// </summary>\n    protected readonly IDataProtector Protector;\n\n    /// <summary>\n    /// The logger.\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// Ctor\n    /// </summary>\n    /// <param name=\"provider\"></param>\n    /// <param name=\"logger\"></param>\n    public ProtectedDataMessageStore(IDataProtectionProvider provider, ILogger<ProtectedDataMessageStore<TModel>> logger)\n    {\n        Protector = provider.CreateProtector(Purpose);\n        Logger = logger;\n    }\n\n    /// <inheritdoc />\n    public virtual Task<Message<TModel>> ReadAsync(string value)\n    {\n        Message<TModel> result = null;\n\n        if (!String.IsNullOrWhiteSpace(value))\n        {\n            try\n            {\n                var bytes = Base64Url.Decode(value);\n                bytes = Protector.Unprotect(bytes);\n                var json = Encoding.UTF8.GetString(bytes);\n                result = ObjectSerializer.FromString<Message<TModel>>(json);\n            }\n            catch(Exception ex)\n            {\n                Logger.LogError(ex, \"Exception reading protected message\");\n            }\n        }\n\n        return Task.FromResult(result);\n    }\n\n    /// <inheritdoc />\n    public virtual Task<string> WriteAsync(Message<TModel> message)\n    {\n        string value = null;\n\n        try\n        {\n            var json = ObjectSerializer.ToString(message);\n            var bytes = Encoding.UTF8.GetBytes(json);\n            bytes = Protector.Protect(bytes);\n            value = Base64Url.Encode(bytes);\n        }\n        catch(Exception ex)\n        {\n            Logger.LogError(ex, \"Exception writing protected message\");\n        }\n\n        return Task.FromResult(value);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/Default/QueryStringAuthorizationParametersMessageStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n// internal just for testing\ninternal class QueryStringAuthorizationParametersMessageStore : IAuthorizationParametersMessageStore\n{\n    public Task<string> WriteAsync(Message<IDictionary<string, string[]>> message)\n    {\n        var queryString = message.Data.FromFullDictionary().ToQueryString();\n        return Task.FromResult(queryString);\n    }\n\n    public Task<Message<IDictionary<string, string[]>>> ReadAsync(string id)\n    {\n        var values = id.ReadQueryStringAsNameValueCollection();\n        var msg = new Message<IDictionary<string, string[]>>(values.ToFullDictionary());\n        return Task.FromResult(msg);\n    }\n\n    public Task DeleteAsync(string id)\n    {\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/IAuthorizationParametersMessageStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for authorization request messages that are sent from the authorization endpoint to the login and consent UI.\n/// </summary>\npublic interface IAuthorizationParametersMessageStore\n{\n    /// <summary>\n    /// Writes the authorization parameters.\n    /// </summary>\n    /// <param name=\"message\">The message.</param>\n    /// <returns>The identifier for the stored message.</returns>\n    Task<string> WriteAsync(Message<IDictionary<string, string[]>> message);\n\n    /// <summary>\n    /// Reads the authorization parameters.\n    /// </summary>\n    /// <param name=\"id\">The identifier.</param>\n    /// <returns></returns>\n    Task<Message<IDictionary<string, string[]>>> ReadAsync(string id);\n\n    /// <summary>\n    /// Deletes the authorization parameters.\n    /// </summary>\n    /// <param name=\"id\">The identifier.</param>\n    /// <returns></returns>\n    Task DeleteAsync(string id);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/IConsentMessageStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for consent messages that are sent from the consent UI to the authorization endpoint.\n/// </summary>\npublic interface IConsentMessageStore\n{\n    /// <summary>\n    /// Writes the consent response message.\n    /// </summary>\n    /// <param name=\"id\">The id for the message.</param>\n    /// <param name=\"message\">The message.</param>\n    Task WriteAsync(string id, Message<ConsentResponse> message);\n\n    /// <summary>\n    /// Reads the consent response message.\n    /// </summary>\n    /// <param name=\"id\">The identifier.</param>\n    /// <returns></returns>\n    Task<Message<ConsentResponse>> ReadAsync(string id);\n\n    /// <summary>\n    /// Deletes the consent response message.\n    /// </summary>\n    /// <param name=\"id\">The identifier.</param>\n    /// <returns></returns>\n    Task DeleteAsync(string id);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/IMessageStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for a message store\n/// </summary>\n/// <typeparam name=\"TModel\">The type of the model.</typeparam>\npublic interface IMessageStore<TModel>\n{\n    /// <summary>\n    /// Writes the message.\n    /// </summary>\n    /// <param name=\"message\">The message.</param>\n    /// <returns>An identifier for the message</returns>\n    Task<string> WriteAsync(Message<TModel> message);\n\n    /// <summary>\n    /// Reads the message.\n    /// </summary>\n    /// <param name=\"id\">The identifier.</param>\n    /// <returns></returns>\n    Task<Message<TModel>> ReadAsync(string id);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/ISigningCredentialStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for a signing credential store\n/// </summary>\npublic interface ISigningCredentialStore\n{\n    /// <summary>\n    /// Gets the signing credentials.\n    /// </summary>\n    /// <returns></returns>\n    Task<SigningCredentials> GetSigningCredentialsAsync();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/IValidationKeysStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for the validation key store\n/// </summary>\npublic interface IValidationKeysStore\n{\n    /// <summary>\n    /// Gets all validation keys.\n    /// </summary>\n    /// <returns></returns>\n    Task<IEnumerable<SecurityKeyInfo>> GetValidationKeysAsync();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/InMemory/InMemoryClientStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// In-memory client store\n/// </summary>\npublic class InMemoryClientStore : IClientStore\n{\n    private readonly IEnumerable<Client> _clients;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"InMemoryClientStore\"/> class.\n    /// </summary>\n    /// <param name=\"clients\">The clients.</param>\n    public InMemoryClientStore(IEnumerable<Client> clients)\n    {\n        if (clients.HasDuplicates(m => m.ClientId))\n        {\n            throw new ArgumentException(\"Clients must not contain duplicate ids\");\n        }\n        _clients = clients;\n    }\n\n    /// <summary>\n    /// Finds a client by id\n    /// </summary>\n    /// <param name=\"clientId\">The client id</param>\n    /// <returns>\n    /// The client\n    /// </returns>\n    public Task<Client> FindClientByIdAsync(string clientId)\n    {\n        var query =\n            from client in _clients\n            where client.ClientId == clientId\n            select client;\n        \n        return Task.FromResult(query.SingleOrDefault());\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/InMemory/InMemoryDeviceFlowStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// In-memory device flow store\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Stores.IDeviceFlowStore\" />\npublic class InMemoryDeviceFlowStore : IDeviceFlowStore\n{\n    private readonly List<InMemoryDeviceAuthorization> _repository = new List<InMemoryDeviceAuthorization>();\n\n    /// <summary>\n    /// Stores the device authorization request.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <param name=\"data\">The data.</param>\n    /// <returns></returns>\n    public Task StoreDeviceAuthorizationAsync(string deviceCode, string userCode, DeviceCode data)\n    {\n        lock (_repository)\n        {\n            _repository.Add(new InMemoryDeviceAuthorization(deviceCode, userCode, data));\n        }\n        \n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Finds device authorization by user code.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    public Task<DeviceCode> FindByUserCodeAsync(string userCode)\n    {\n        DeviceCode foundDeviceCode;\n\n        lock (_repository)\n        {\n            foundDeviceCode = _repository.FirstOrDefault(x => x.UserCode == userCode)?.Data;\n        }\n\n        return Task.FromResult(foundDeviceCode);\n    }\n\n    /// <summary>\n    /// Finds device authorization by device code.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    public Task<DeviceCode> FindByDeviceCodeAsync(string deviceCode)\n    {\n        DeviceCode foundDeviceCode;\n\n        lock (_repository)\n        {\n            foundDeviceCode = _repository.FirstOrDefault(x => x.DeviceCode == deviceCode)?.Data;\n        }\n\n        return Task.FromResult(foundDeviceCode);\n    }\n\n    /// <summary>\n    /// Updates device authorization, searching by user code.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <param name=\"data\">The data.</param>\n    public Task UpdateByUserCodeAsync(string userCode, DeviceCode data)\n    {\n        lock (_repository)\n        {\n            var foundData = _repository.FirstOrDefault(x => x.UserCode == userCode);\n\n            if (foundData != null)\n            {\n                foundData.Data = data;\n            }\n        }\n\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Removes the device authorization, searching by device code.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    /// <returns></returns>\n    public Task RemoveByDeviceCodeAsync(string deviceCode)\n    {\n        lock (_repository)\n        {\n            var foundData = _repository.FirstOrDefault(x => x.DeviceCode == deviceCode);\n\n            if (foundData != null)\n            {\n                _repository.Remove(foundData);\n            }\n        }\n\n\n        return Task.CompletedTask;\n    }\n\n    private class InMemoryDeviceAuthorization\n    {\n        public InMemoryDeviceAuthorization(string deviceCode, string userCode, DeviceCode data)\n        {\n            DeviceCode = deviceCode;\n            UserCode = userCode;\n            Data = data;\n        }\n\n        public string DeviceCode { get; }\n        public string UserCode { get; }\n        public DeviceCode Data { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/InMemory/InMemoryPersistedGrantStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// In-memory persisted grant store\n/// </summary>\npublic class InMemoryPersistedGrantStore : IPersistedGrantStore\n{\n    private readonly ConcurrentDictionary<string, PersistedGrant> _repository = new ConcurrentDictionary<string, PersistedGrant>();\n\n    /// <inheritdoc/>\n    public Task StoreAsync(PersistedGrant grant)\n    {\n        _repository[grant.Key] = grant;\n\n        return Task.CompletedTask;\n    }\n\n    /// <inheritdoc/>\n    public Task<PersistedGrant> GetAsync(string key)\n    {\n        if (_repository.TryGetValue(key, out PersistedGrant token))\n        {\n            return Task.FromResult(token);\n        }\n\n        return Task.FromResult<PersistedGrant>(null);\n    }\n\n    /// <inheritdoc/>\n    public Task<IEnumerable<PersistedGrant>> GetAllAsync(PersistedGrantFilter filter)\n    {\n        filter.Validate();\n        \n        var items = Filter(filter);\n        \n        return Task.FromResult(items);\n    }\n\n    /// <inheritdoc/>\n    public Task RemoveAsync(string key)\n    {\n        _repository.TryRemove(key, out _);\n\n        return Task.CompletedTask;\n    }\n\n    /// <inheritdoc/>\n    public Task RemoveAllAsync(PersistedGrantFilter filter)\n    {\n        filter.Validate();\n\n        var items = Filter(filter);\n        \n        foreach (var item in items)\n        {\n            _repository.TryRemove(item.Key, out _);\n        }\n\n        return Task.CompletedTask;\n    }\n\n    private IEnumerable<PersistedGrant> Filter(PersistedGrantFilter filter)\n    {\n        var query =\n            from item in _repository\n            select item.Value;\n\n        if (!String.IsNullOrWhiteSpace(filter.ClientId))\n        {\n            query = query.Where(x => x.ClientId == filter.ClientId);\n        }\n        if (!String.IsNullOrWhiteSpace(filter.SessionId))\n        {\n            query = query.Where(x => x.SessionId == filter.SessionId);\n        }\n        if (!String.IsNullOrWhiteSpace(filter.SubjectId))\n        {\n            query = query.Where(x => x.SubjectId == filter.SubjectId);\n        }\n        if (!String.IsNullOrWhiteSpace(filter.Type))\n        {\n            query = query.Where(x => x.Type == filter.Type);\n        }\n\n        var items = query.ToArray().AsEnumerable();\n        return items;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/InMemory/InMemoryResourcesStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// In-memory resource store\n/// </summary>\npublic class InMemoryResourcesStore : IResourceStore\n{\n    private readonly IEnumerable<IdentityResource> _identityResources;\n    private readonly IEnumerable<ApiResource> _apiResources;\n    private readonly IEnumerable<ApiScope> _apiScopes;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"InMemoryResourcesStore\" /> class.\n    /// </summary>\n    public InMemoryResourcesStore(\n        IEnumerable<IdentityResource> identityResources = null, \n        IEnumerable<ApiResource> apiResources = null, \n        IEnumerable<ApiScope> apiScopes = null)\n    {\n        if (identityResources?.HasDuplicates(m => m.Name) == true)\n        {\n            throw new ArgumentException(\"Identity resources must not contain duplicate names\");\n        }\n\n        if (apiResources?.HasDuplicates(m => m.Name) == true)\n        {\n            throw new ArgumentException(\"Api resources must not contain duplicate names\");\n        }\n        \n        if (apiScopes?.HasDuplicates(m => m.Name) == true)\n        {\n            throw new ArgumentException(\"Scopes must not contain duplicate names\");\n        }\n\n        _identityResources = identityResources ?? Enumerable.Empty<IdentityResource>();\n        _apiResources = apiResources ?? Enumerable.Empty<ApiResource>();\n        _apiScopes = apiScopes ?? Enumerable.Empty<ApiScope>();\n    }\n\n    /// <inheritdoc/>\n    public Task<Resources> GetAllResourcesAsync()\n    {\n        var result = new Resources(_identityResources, _apiResources, _apiScopes);\n        return Task.FromResult(result);\n    }\n\n    /// <inheritdoc/>\n    public Task<IEnumerable<ApiResource>> FindApiResourcesByNameAsync(IEnumerable<string> apiResourceNames)\n    {\n        if (apiResourceNames == null) throw new ArgumentNullException(nameof(apiResourceNames));\n\n        var query = from a in _apiResources\n                    where apiResourceNames.Contains(a.Name)\n                    select a;\n        return Task.FromResult(query);\n    }\n\n    /// <inheritdoc/>\n    public Task<IEnumerable<IdentityResource>> FindIdentityResourcesByScopeNameAsync(IEnumerable<string> scopeNames)\n    {\n        if (scopeNames == null) throw new ArgumentNullException(nameof(scopeNames));\n\n        var identity = from i in _identityResources\n                       where scopeNames.Contains(i.Name)\n                       select i;\n\n        return Task.FromResult(identity);\n    }\n\n    /// <inheritdoc/>\n    public Task<IEnumerable<ApiResource>> FindApiResourcesByScopeNameAsync(IEnumerable<string> scopeNames)\n    {\n        if (scopeNames == null) throw new ArgumentNullException(nameof(scopeNames));\n\n        var query = from a in _apiResources\n                    where a.Scopes.Any(x => scopeNames.Contains(x))\n                    select a;\n\n        return Task.FromResult(query);\n    }\n\n    /// <inheritdoc/>\n    public Task<IEnumerable<ApiScope>> FindApiScopesByNameAsync(IEnumerable<string> scopeNames)\n    {\n        if (scopeNames == null) throw new ArgumentNullException(nameof(scopeNames));\n\n        var query =\n            from x in _apiScopes\n            where scopeNames.Contains(x.Name)\n            select x;\n        \n        return Task.FromResult(query);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/InMemory/InMemorySigningCredentialsStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Default signing credentials store\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Stores.ISigningCredentialStore\" />\npublic class InMemorySigningCredentialsStore : ISigningCredentialStore\n{\n    private readonly SigningCredentials _credential;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"InMemorySigningCredentialsStore\"/> class.\n    /// </summary>\n    /// <param name=\"credential\">The credential.</param>\n    public InMemorySigningCredentialsStore(SigningCredentials credential)\n    {\n        _credential = credential;\n    }\n\n    /// <summary>\n    /// Gets the signing credentials.\n    /// </summary>\n    /// <returns></returns>\n    public Task<SigningCredentials> GetSigningCredentialsAsync()\n    {\n        return Task.FromResult(_credential);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/InMemory/InMemoryValidationKeysStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// The default validation key store\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Stores.IValidationKeysStore\" />\npublic class InMemoryValidationKeysStore : IValidationKeysStore\n{\n    private readonly IEnumerable<SecurityKeyInfo> _keys;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"InMemoryValidationKeysStore\"/> class.\n    /// </summary>\n    /// <param name=\"keys\">The keys.</param>\n    /// <exception cref=\"System.ArgumentNullException\">keys</exception>\n    public InMemoryValidationKeysStore(IEnumerable<SecurityKeyInfo> keys)\n    {\n        _keys = keys ?? throw new ArgumentNullException(nameof(keys));\n    }\n\n    /// <summary>\n    /// Gets all validation keys.\n    /// </summary>\n    /// <returns></returns>\n    public Task<IEnumerable<SecurityKeyInfo>> GetValidationKeysAsync()\n    {\n        return Task.FromResult(_keys);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Stores/ValidatingClientStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Client store decorator for running runtime configuration validation checks\n/// </summary>\npublic class ValidatingClientStore<T> : IClientStore\n    where T : IClientStore\n{\n    private readonly IClientStore _inner;\n    private readonly IClientConfigurationValidator _validator;\n    private readonly IEventService _events;\n    private readonly ILogger<ValidatingClientStore<T>> _logger;\n    private readonly string _validatorType;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ValidatingClientStore{T}\" /> class.\n    /// </summary>\n    /// <param name=\"inner\">The inner.</param>\n    /// <param name=\"validator\">The validator.</param>\n    /// <param name=\"events\">The events.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public ValidatingClientStore(T inner, IClientConfigurationValidator validator, IEventService events, ILogger<ValidatingClientStore<T>> logger)\n    {\n        _inner = inner;\n        _validator = validator;\n        _events = events;\n        _logger = logger;\n\n        _validatorType = validator.GetType().FullName;\n    }\n\n    /// <summary>\n    /// Finds a client by id (and runs the validation logic)\n    /// </summary>\n    /// <param name=\"clientId\">The client id</param>\n    /// <returns>\n    /// The client or an InvalidOperationException\n    /// </returns>\n    public async Task<Client> FindClientByIdAsync(string clientId)\n    {\n        var client = await _inner.FindClientByIdAsync(clientId);\n\n        if (client != null)\n        {\n            _logger.LogTrace(\"Calling into client configuration validator: {validatorType}\", _validatorType);\n\n            var context = new ClientConfigurationValidationContext(client);\n            await _validator.ValidateAsync(context);\n\n            if (context.IsValid)\n            {\n                _logger.LogDebug(\"client configuration validation for client {clientId} succeeded.\", client.ClientId);\n                return client;\n            }\n\n            _logger.LogError(\"Invalid client configuration for client {clientId}: {errorMessage}\", client.ClientId, context.ErrorMessage);\n            await _events.RaiseAsync(new InvalidClientConfigurationEvent(client, context.ErrorMessage));\n                \n            return null;\n        }\n\n        return null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Test/IdentityServerBuilderExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\n/// <summary>\n/// Extension methods for the IdentityServer builder\n/// </summary>\npublic static class IdentityServerBuilderExtensions\n{\n    /// <summary>\n    /// Adds test users.\n    /// </summary>\n    /// <param name=\"builder\">The builder.</param>\n    /// <param name=\"users\">The users.</param>\n    /// <returns></returns>\n    public static IIdentityServerBuilder AddTestUsers(this IIdentityServerBuilder builder, List<TestUser> users)\n    {\n        builder.Services.AddSingleton(new TestUserStore(users));\n        builder.AddProfileService<TestUserProfileService>();\n        builder.AddResourceOwnerValidator<TestUserResourceOwnerPasswordValidator>();\n\n        return builder;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Test/TestUser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Test;\n\n/// <summary>\n/// In-memory user object for testing. Not intended for modeling users in production.\n/// </summary>\npublic class TestUser\n{\n    /// <summary>\n    /// Gets or sets the subject identifier.\n    /// </summary>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the username.\n    /// </summary>\n    public string Username { get; set; }\n\n    /// <summary>\n    /// Gets or sets the password.\n    /// </summary>\n    public string Password { get; set; }\n\n    /// <summary>\n    /// Gets or sets the provider name.\n    /// </summary>\n    public string ProviderName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the provider subject identifier.\n    /// </summary>\n    public string ProviderSubjectId { get; set; }\n\n    /// <summary>\n    /// Gets or sets if the user is active.\n    /// </summary>\n    public bool IsActive { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets the claims.\n    /// </summary>\n    public ICollection<Claim> Claims { get; set; } = new HashSet<Claim>(new ClaimComparer());\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Test/TestUserProfileService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Test;\n\n/// <summary>\n/// Profile service for test users\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Services.IProfileService\" />\npublic class TestUserProfileService : IProfileService\n{\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n    \n    /// <summary>\n    /// The users\n    /// </summary>\n    protected readonly TestUserStore Users;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TestUserProfileService\"/> class.\n    /// </summary>\n    /// <param name=\"users\">The users.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public TestUserProfileService(TestUserStore users, ILogger<TestUserProfileService> logger)\n    {\n        Users = users;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// This method is called whenever claims about the user are requested (e.g. during token creation or via the userinfo endpoint)\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public virtual Task GetProfileDataAsync(ProfileDataRequestContext context)\n    {\n        context.LogProfileRequest(Logger);\n\n        if (context.RequestedClaimTypes.Any())\n        {\n            var user = Users.FindBySubjectId(context.Subject.GetSubjectId());\n            if (user != null)\n            {\n                context.AddRequestedClaims(user.Claims);\n            }\n        }\n\n        context.LogIssuedClaims(Logger);\n\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// This method gets called whenever identity server needs to determine if the user is valid or active (e.g. if the user's account has been deactivated since they logged in).\n    /// (e.g. during token issuance or validation).\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public virtual Task IsActiveAsync(IsActiveContext context)\n    {\n        Logger.LogDebug(\"IsActive called from: {caller}\", context.Caller);\n\n        var user = Users.FindBySubjectId(context.Subject.GetSubjectId());\n        context.IsActive = user?.IsActive == true;\n\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Test/TestUserResourceOwnerPasswordValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Test;\n\n/// <summary>\n/// Resource owner password validator for test users\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.IResourceOwnerPasswordValidator\" />\npublic class TestUserResourceOwnerPasswordValidator : IResourceOwnerPasswordValidator\n{\n    private readonly TestUserStore _users;\n    private readonly ISystemClock _clock;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TestUserResourceOwnerPasswordValidator\"/> class.\n    /// </summary>\n    /// <param name=\"users\">The users.</param>\n    /// <param name=\"clock\">The clock.</param>\n    public TestUserResourceOwnerPasswordValidator(TestUserStore users, ISystemClock clock)\n    {\n        _users = users;\n        _clock = clock;\n    }\n\n    /// <summary>\n    /// Validates the resource owner password credential\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public Task ValidateAsync(ResourceOwnerPasswordValidationContext context)\n    {\n        if (_users.ValidateCredentials(context.UserName, context.Password))\n        {\n            var user = _users.FindByUsername(context.UserName);\n            context.Result = new GrantValidationResult(\n                user.SubjectId ?? throw new ArgumentException(\"Subject ID not set\", nameof(user.SubjectId)), \n                OidcConstants.AuthenticationMethods.Password, _clock.UtcNow.UtcDateTime, \n                user.Claims);\n        }\n\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Test/TestUserStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Test;\n\n/// <summary>\n/// Store for test users\n/// </summary>\npublic class TestUserStore\n{\n    private readonly List<TestUser> _users;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TestUserStore\"/> class.\n    /// </summary>\n    /// <param name=\"users\">The users.</param>\n    public TestUserStore(List<TestUser> users)\n    {\n        _users = users;\n    }\n\n    /// <summary>\n    /// Validates the credentials.\n    /// </summary>\n    /// <param name=\"username\">The username.</param>\n    /// <param name=\"password\">The password.</param>\n    /// <returns></returns>\n    public bool ValidateCredentials(string username, string password)\n    {\n        var user = FindByUsername(username);\n        \n        if (user != null)\n        {\n            if (string.IsNullOrWhiteSpace(user.Password) && string.IsNullOrWhiteSpace(password))\n            {\n                return true;\n            }\n            \n            return user.Password.Equals(password);\n        }\n        \n        return false;\n    }\n\n    /// <summary>\n    /// Finds the user by subject identifier.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <returns></returns>\n    public TestUser FindBySubjectId(string subjectId)\n    {\n        return _users.FirstOrDefault(x => x.SubjectId == subjectId);\n    }\n\n    /// <summary>\n    /// Finds the user by username.\n    /// </summary>\n    /// <param name=\"username\">The username.</param>\n    /// <returns></returns>\n    public TestUser FindByUsername(string username)\n    {\n        return _users.FirstOrDefault(x => x.Username.Equals(username, StringComparison.OrdinalIgnoreCase));\n    }\n\n    /// <summary>\n    /// Finds the user by external provider.\n    /// </summary>\n    /// <param name=\"provider\">The provider.</param>\n    /// <param name=\"userId\">The user identifier.</param>\n    /// <returns></returns>\n    public TestUser FindByExternalProvider(string provider, string userId)\n    {\n        return _users.FirstOrDefault(x =>\n            x.ProviderName == provider &&\n            x.ProviderSubjectId == userId);\n    }\n\n    /// <summary>\n    /// Automatically provisions a user.\n    /// </summary>\n    /// <param name=\"provider\">The provider.</param>\n    /// <param name=\"userId\">The user identifier.</param>\n    /// <param name=\"claims\">The claims.</param>\n    /// <returns></returns>\n    public TestUser AutoProvisionUser(string provider, string userId, List<Claim> claims)\n    {\n        // create a list of claims that we want to transfer into our store\n        var filtered = new List<Claim>();\n\n        foreach (var claim in claims)\n        {\n            // if the external system sends a display name - translate that to the standard OIDC name claim\n            if (claim.Type == ClaimTypes.Name)\n            {\n                filtered.Add(new Claim(JwtClaimTypes.Name, claim.Value));\n            }\n            // if the JWT handler has an outbound mapping to an OIDC claim use that\n            else if (JwtSecurityTokenHandler.DefaultOutboundClaimTypeMap.ContainsKey(claim.Type))\n            {\n                filtered.Add(new Claim(JwtSecurityTokenHandler.DefaultOutboundClaimTypeMap[claim.Type], claim.Value));\n            }\n            // copy the claim as-is\n            else\n            {\n                filtered.Add(claim);\n            }\n        }\n\n        // if no display name was provided, try to construct by first and/or last name\n        if (!filtered.Any(x => x.Type == JwtClaimTypes.Name))\n        {\n            var first = filtered.FirstOrDefault(x => x.Type == JwtClaimTypes.GivenName)?.Value;\n            var last = filtered.FirstOrDefault(x => x.Type == JwtClaimTypes.FamilyName)?.Value;\n            if (first != null && last != null)\n            {\n                filtered.Add(new Claim(JwtClaimTypes.Name, first + \" \" + last));\n            }\n            else if (first != null)\n            {\n                filtered.Add(new Claim(JwtClaimTypes.Name, first));\n            }\n            else if (last != null)\n            {\n                filtered.Add(new Claim(JwtClaimTypes.Name, last));\n            }\n        }\n\n        // create a new unique subject id\n        var sub = CryptoRandom.CreateUniqueId(format: CryptoRandom.OutputFormat.Hex);\n\n        // check if a display name is available, otherwise fallback to subject id\n        var name = filtered.FirstOrDefault(c => c.Type == JwtClaimTypes.Name)?.Value ?? sub;\n\n        // create new user\n        var user = new TestUser\n        {\n            SubjectId = sub,\n            Username = name,\n            ProviderName = provider,\n            ProviderSubjectId = userId,\n            Claims = filtered\n        };\n\n        // add user to in-memory store\n        _users.Add(user);\n\n        return user;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Contexts/ClientConfigurationValidationContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Context for client configuration validation.\n/// </summary>\npublic class ClientConfigurationValidationContext\n{\n    /// <summary>\n    /// Gets or sets the client.\n    /// </summary>\n    /// <value>\n    /// The client.\n    /// </value>\n    public Client Client { get; }\n\n    /// <summary>\n    /// Returns true if client configuration is valid.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if this instance is valid; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsValid { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets the error message.\n    /// </summary>\n    /// <value>\n    /// The error message.\n    /// </value>\n    public string ErrorMessage { get; set; }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ClientConfigurationValidationContext\"/> class.\n    /// </summary>\n    /// <param name=\"client\">The client.</param>\n    public ClientConfigurationValidationContext(Client client)\n    {\n        Client = client;\n    }\n\n    /// <summary>\n    /// Sets a validation error.\n    /// </summary>\n    /// <param name=\"message\">The message.</param>\n    public void SetError(string message)\n    {\n        IsValid = false;\n        ErrorMessage = message;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Contexts/CustomAuthorizeRequestValidationContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Context for custom authorize request validation.\n/// </summary>\npublic class CustomAuthorizeRequestValidationContext\n{\n    /// <summary>\n    /// The result of custom validation. \n    /// </summary>\n    public AuthorizeRequestValidationResult Result { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Contexts/CustomTokenRequestValidationContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Context class for custom token request validation\n/// </summary>\npublic class CustomTokenRequestValidationContext\n{\n    /// <summary>\n    /// Gets or sets the result.\n    /// </summary>\n    /// <value>\n    /// The result.\n    /// </value>\n    public TokenRequestValidationResult Result { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Contexts/ExtensionGrantValidationContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Class describing the extension grant validation context\n/// </summary>\npublic class ExtensionGrantValidationContext\n{\n    /// <summary>\n    /// Gets or sets the request.\n    /// </summary>\n    /// <value>\n    /// The request.\n    /// </value>\n    public ValidatedTokenRequest Request { get; set; }\n\n    /// <summary>\n    /// Gets or sets the result.\n    /// </summary>\n    /// <value>\n    /// The result.\n    /// </value>\n    public GrantValidationResult Result { get; set; } = new GrantValidationResult(TokenRequestErrors.InvalidGrant);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Contexts/ResourceOwnerPasswordValidationContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Class describing the resource owner password validation context\n/// </summary>\npublic class ResourceOwnerPasswordValidationContext\n{\n    /// <summary>\n    /// Gets or sets the name of the user.\n    /// </summary>\n    /// <value>\n    /// The name of the user.\n    /// </value>\n    public string UserName { get; set; }\n\n    /// <summary>\n    /// Gets or sets the password.\n    /// </summary>\n    /// <value>\n    /// The password.\n    /// </value>\n    public string Password { get; set; }\n\n    /// <summary>\n    /// Gets or sets the request.\n    /// </summary>\n    /// <value>\n    /// The request.\n    /// </value>\n    public ValidatedTokenRequest Request { get; set; }\n\n    /// <summary>\n    /// Gets or sets the result.\n    /// </summary>\n    /// <value>\n    /// The result.\n    /// </value>\n    public GrantValidationResult Result { get; set; } = new GrantValidationResult(TokenRequestErrors.InvalidGrant);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Contexts/ResourceValidationContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Class describing the resource validation context\n/// </summary>\npublic class ResourceValidationContext\n{\n    /// <summary>\n    /// Gets or sets the result.\n    /// </summary>\n    /// <value>\n    /// The result.\n    /// </value>\n    public GrantValidationResult Result { get; set; } = new GrantValidationResult(TokenRequestErrors.InvalidGrant);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/ApiSecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates API secrets using the registered secret validators and parsers\n/// </summary>\npublic class ApiSecretValidator : IApiSecretValidator\n{\n    private readonly ILogger _logger;\n    private readonly IResourceStore _resources;\n    private readonly IEventService _events;\n    private readonly ISecretsListParser _parser;\n    private readonly ISecretsListValidator _validator;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiSecretValidator\"/> class.\n    /// </summary>\n    /// <param name=\"resources\">The resources.</param>\n    /// <param name=\"parsers\">The parsers.</param>\n    /// <param name=\"validator\">The validator.</param>\n    /// <param name=\"events\">The events.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public ApiSecretValidator(IResourceStore resources, ISecretsListParser parsers, ISecretsListValidator validator, IEventService events, ILogger<ApiSecretValidator> logger)\n    {\n        _resources = resources;\n        _parser = parsers;\n        _validator = validator;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates the secret on the current request.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public async Task<ApiSecretValidationResult> ValidateAsync(HttpContext context)\n    {\n        _logger.LogTrace(\"Start API validation\");\n\n        var fail = new ApiSecretValidationResult\n        {\n            IsError = true\n        };\n\n        var parsedSecret = await _parser.ParseAsync(context);\n        if (parsedSecret == null)\n        {\n            await RaiseFailureEventAsync(\"unknown\", \"No API id or secret found\");\n\n            _logger.LogError(\"No API secret found\");\n            return fail;\n        }\n\n        // load API resource\n        var apis = await _resources.FindApiResourcesByNameAsync(new[] { parsedSecret.Id });\n        if (apis == null || !apis.Any())\n        {\n            await RaiseFailureEventAsync(parsedSecret.Id, \"Unknown API resource\");\n\n            _logger.LogError(\"No API resource with that name found. aborting\");\n            return fail;\n        }\n\n        if (apis.Count() > 1)\n        {\n            await RaiseFailureEventAsync(parsedSecret.Id, \"Invalid API resource\");\n\n            _logger.LogError(\"More than one API resource with that name found. aborting\");\n            return fail;\n        }\n\n        var api = apis.Single();\n\n        if (api.Enabled == false)\n        {\n            await RaiseFailureEventAsync(parsedSecret.Id, \"API resource not enabled\");\n\n            _logger.LogError(\"API resource not enabled. aborting.\");\n            return fail;\n        }\n\n        var result = await _validator.ValidateAsync(api.ApiSecrets, parsedSecret);\n        if (result.Success)\n        {\n            _logger.LogDebug(\"API resource validation success\");\n\n            var success = new ApiSecretValidationResult\n            {\n                IsError = false,\n                Resource = api\n            };\n\n            await RaiseSuccessEventAsync(api.Name, parsedSecret.Type);\n            return success;\n        }\n\n        await RaiseFailureEventAsync(api.Name, \"Invalid API secret\");\n        _logger.LogError(\"API validation failed.\");\n\n        return fail;\n    }\n\n    private Task RaiseSuccessEventAsync(string clientId, string authMethod)\n    {\n        return _events.RaiseAsync(new ApiAuthenticationSuccessEvent(clientId, authMethod));\n    }\n\n    private Task RaiseFailureEventAsync(string clientId, string message)\n    {\n        return _events.RaiseAsync(new ApiAuthenticationFailureEvent(clientId, message));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/AuthorizeRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\ninternal class AuthorizeRequestValidator : IAuthorizeRequestValidator\n{\n    private readonly IdentityServerOptions _options;\n    private readonly IClientStore _clients;\n    private readonly ICustomAuthorizeRequestValidator _customValidator;\n    private readonly IRedirectUriValidator _uriValidator;\n    private readonly IResourceValidator _resourceValidator;\n    private readonly IUserSession _userSession;\n    private readonly JwtRequestValidator _jwtRequestValidator;\n    private readonly IJwtRequestUriHttpClient _jwtRequestUriHttpClient;\n    private readonly ILogger _logger;\n\n    private readonly ResponseTypeEqualityComparer\n        _responseTypeEqualityComparer = new ResponseTypeEqualityComparer();\n\n    public AuthorizeRequestValidator(\n        IdentityServerOptions options,\n        IClientStore clients,\n        ICustomAuthorizeRequestValidator customValidator,\n        IRedirectUriValidator uriValidator,\n        IResourceValidator resourceValidator,\n        IUserSession userSession,\n        JwtRequestValidator jwtRequestValidator,\n        IJwtRequestUriHttpClient jwtRequestUriHttpClient,\n        ILogger<AuthorizeRequestValidator> logger)\n    {\n        _options = options;\n        _clients = clients;\n        _customValidator = customValidator;\n        _uriValidator = uriValidator;\n        _resourceValidator = resourceValidator;\n        _jwtRequestValidator = jwtRequestValidator;\n        _userSession = userSession;\n        _jwtRequestUriHttpClient = jwtRequestUriHttpClient;\n        _logger = logger;\n    }\n\n    public async Task<AuthorizeRequestValidationResult> ValidateAsync(NameValueCollection parameters, ClaimsPrincipal subject = null)\n    {\n        _logger.LogDebug(\"Start authorize request protocol validation\");\n\n        var request = new ValidatedAuthorizeRequest\n        {\n            Options = _options,\n            Subject = subject ?? Principal.Anonymous,\n            Raw = parameters ?? throw new ArgumentNullException(nameof(parameters))\n        };\n        \n        // load client_id\n        // client_id must always be present on the request\n        var loadClientResult = await LoadClientAsync(request);\n        if (loadClientResult.IsError)\n        {\n            return loadClientResult;\n        }\n\n        // load request object\n        var roLoadResult = await LoadRequestObjectAsync(request);\n        if (roLoadResult.IsError)\n        {\n            return roLoadResult;\n        }\n\n        // validate request object\n        var roValidationResult = await ValidateRequestObjectAsync(request);\n        if (roValidationResult.IsError)\n        {\n            return roValidationResult;\n        }\n\n        // validate client_id and redirect_uri\n        var clientResult = await ValidateClientAsync(request);\n        if (clientResult.IsError)\n        {\n            return clientResult;\n        }\n\n        // state, response_type, response_mode\n        var mandatoryResult = ValidateCoreParameters(request);\n        if (mandatoryResult.IsError)\n        {\n            return mandatoryResult;\n        }\n\n        // scope, scope restrictions and plausability\n        var scopeResult = await ValidateScopeAsync(request);\n        if (scopeResult.IsError)\n        {\n            return scopeResult;\n        }\n\n        // nonce, prompt, acr_values, login_hint etc.\n        var optionalResult = await ValidateOptionalParametersAsync(request);\n        if (optionalResult.IsError)\n        {\n            return optionalResult;\n        }\n\n        // custom validator\n        _logger.LogDebug(\"Calling into custom validator: {type}\", _customValidator.GetType().FullName);\n        var context = new CustomAuthorizeRequestValidationContext\n        {\n            Result = new AuthorizeRequestValidationResult(request)\n        };\n        await _customValidator.ValidateAsync(context);\n\n        var customResult = context.Result;\n        if (customResult.IsError)\n        {\n            LogError(\"Error in custom validation\", customResult.Error, request);\n            return Invalid(request, customResult.Error, customResult.ErrorDescription);\n        }\n\n        _logger.LogTrace(\"Authorize request protocol validation successful\");\n\n        return Valid(request);\n    }\n\n    private async Task<AuthorizeRequestValidationResult> LoadRequestObjectAsync(ValidatedAuthorizeRequest request)\n    {\n        var jwtRequest = request.Raw.Get(OidcConstants.AuthorizeRequest.Request);\n        var jwtRequestUri = request.Raw.Get(OidcConstants.AuthorizeRequest.RequestUri);\n\n        if (jwtRequest.IsPresent() && jwtRequestUri.IsPresent())\n        {\n            LogError(\"Both request and request_uri are present\", request);\n            return Invalid(request, description: \"Only one request parameter is allowed\");\n        }\n\n        if (_options.Endpoints.EnableJwtRequestUri)\n        {\n            if (jwtRequestUri.IsPresent())\n            {\n                // 512 is from the spec\n                if (jwtRequestUri.Length > 512)\n                {\n                    LogError(\"request_uri is too long\", request);\n                    return Invalid(request, error: OidcConstants.AuthorizeErrors.InvalidRequestUri, description: \"request_uri is too long\");\n                }\n\n                var jwt = await _jwtRequestUriHttpClient.GetJwtAsync(jwtRequestUri, request.Client);\n                if (jwt.IsMissing())\n                {\n                    LogError(\"no value returned from request_uri\", request);\n                    return Invalid(request, error: OidcConstants.AuthorizeErrors.InvalidRequestUri, description: \"no value returned from request_uri\");\n                }\n\n                jwtRequest = jwt;\n            }\n        }\n        else if (jwtRequestUri.IsPresent())\n        {\n            LogError(\"request_uri present but config prohibits\", request);\n            return Invalid(request, error: OidcConstants.AuthorizeErrors.RequestUriNotSupported);\n        }\n\n        // check length restrictions\n        if (jwtRequest.IsPresent())\n        {\n            if (jwtRequest.Length >= _options.InputLengthRestrictions.Jwt)\n            {\n                LogError(\"request value is too long\", request);\n                return Invalid(request, error: OidcConstants.AuthorizeErrors.InvalidRequestObject, description: \"Invalid request value\");\n            }\n        }\n\n        request.RequestObject = jwtRequest;\n        return Valid(request);\n    }\n\n    private async Task<AuthorizeRequestValidationResult> LoadClientAsync(ValidatedAuthorizeRequest request)\n    {\n        //////////////////////////////////////////////////////////\n        // client_id must be present\n        /////////////////////////////////////////////////////////\n        var clientId = request.Raw.Get(OidcConstants.AuthorizeRequest.ClientId);\n\n        if (clientId.IsMissingOrTooLong(_options.InputLengthRestrictions.ClientId))\n        {\n            LogError(\"client_id is missing or too long\", request);\n            return Invalid(request, description: \"Invalid client_id\");\n        }\n\n        request.ClientId = clientId;\n\n        //////////////////////////////////////////////////////////\n        // check for valid client\n        //////////////////////////////////////////////////////////\n        var client = await _clients.FindEnabledClientByIdAsync(request.ClientId);\n        if (client == null)\n        {\n            LogError(\"Unknown client or not enabled\", request.ClientId, request);\n            return Invalid(request, OidcConstants.AuthorizeErrors.UnauthorizedClient, \"Unknown client or client not enabled\");\n        }\n\n        request.SetClient(client);\n\n        return Valid(request);\n    }\n\n    private async Task<AuthorizeRequestValidationResult> ValidateRequestObjectAsync(ValidatedAuthorizeRequest request)\n    {\n        //////////////////////////////////////////////////////////\n        // validate request object\n        /////////////////////////////////////////////////////////\n        if (request.RequestObject.IsPresent())\n        {\n            // validate the request JWT for this client\n            var jwtRequestValidationResult = await _jwtRequestValidator.ValidateAsync(request.Client, request.RequestObject);\n            if (jwtRequestValidationResult.IsError)\n            {\n                LogError(\"request JWT validation failure\", request);\n                return Invalid(request, error: OidcConstants.AuthorizeErrors.InvalidRequestObject, description: \"Invalid JWT request\");\n            }\n\n            // validate response_type match\n            var responseType = request.Raw.Get(OidcConstants.AuthorizeRequest.ResponseType);\n            if (responseType != null)\n            {\n                if (jwtRequestValidationResult.Payload.TryGetValue(OidcConstants.AuthorizeRequest.ResponseType, out var payloadResponseType))\n                {\n                    if (payloadResponseType != responseType)\n                    {\n                        LogError(\"response_type in JWT payload does not match response_type in request\", request);\n                        return Invalid(request, description: \"Invalid JWT request\");\n                    }\n                }\n            }\n\n            // validate client_id mismatch\n            if (jwtRequestValidationResult.Payload.TryGetValue(OidcConstants.AuthorizeRequest.ClientId, out var payloadClientId))\n            {\n                if (!string.Equals(request.Client.ClientId, payloadClientId, StringComparison.Ordinal))\n                {\n                    LogError(\"client_id in JWT payload does not match client_id in request\", request);\n                    return Invalid(request, description: \"Invalid JWT request\");\n                }\n            }\n            else\n            {\n                LogError(\"client_id is missing in JWT payload\", request);\n                return Invalid(request, error: OidcConstants.AuthorizeErrors.InvalidRequestObject, description: \"Invalid JWT request\");\n            }\n\n            var ignoreKeys = new[]\n            {\n                JwtClaimTypes.Issuer,\n                JwtClaimTypes.Audience\n            };\n\n            // merge jwt payload values into original request parameters\n            foreach (var key in jwtRequestValidationResult.Payload.Keys)\n            {\n                if (ignoreKeys.Contains(key)) continue;\n                \n                var value = jwtRequestValidationResult.Payload[key];\n                \n                var qsValue = request.Raw.Get(key);\n                if (qsValue != null)\n                {\n                    if (!string.Equals(value, qsValue, StringComparison.Ordinal))\n                    {\n                        LogError(\"parameter mismatch between request object and query string parameter.\", request);\n                        return Invalid(request, description: \"Parameter mismatch in JWT request\");\n                    }\n                }\n\n                request.Raw.Set(key, value);\n            }\n\n            request.RequestObjectValues = jwtRequestValidationResult.Payload;\n        }\n\n        return Valid(request);\n    }\n\n    private async Task<AuthorizeRequestValidationResult> ValidateClientAsync(ValidatedAuthorizeRequest request)\n    {\n        //////////////////////////////////////////////////////////\n        // check request object requirement\n        //////////////////////////////////////////////////////////\n        if (request.Client.RequireRequestObject)\n        {\n            if (!request.RequestObjectValues.Any())\n            {\n                return Invalid(request, description: \"Client must use request object, but no request or request_uri parameter present\");\n            }\n        }\n\n        //////////////////////////////////////////////////////////\n        // redirect_uri must be present, and a valid uri\n        //////////////////////////////////////////////////////////\n        var redirectUri = request.Raw.Get(OidcConstants.AuthorizeRequest.RedirectUri);\n\n        if (redirectUri.IsMissingOrTooLong(_options.InputLengthRestrictions.RedirectUri))\n        {\n            LogError(\"redirect_uri is missing or too long\", request);\n            return Invalid(request, description: \"Invalid redirect_uri\");\n        }\n\n        if (!Uri.TryCreate(redirectUri, UriKind.Absolute, out _))\n        {\n            LogError(\"malformed redirect_uri\", redirectUri, request);\n            return Invalid(request, description: \"Invalid redirect_uri\");\n        }\n\n        //////////////////////////////////////////////////////////\n        // check if client protocol type is oidc\n        //////////////////////////////////////////////////////////\n        if (request.Client.ProtocolType != IdentityServerConstants.ProtocolTypes.OpenIdConnect)\n        {\n            LogError(\"Invalid protocol type for OIDC authorize endpoint\", request.Client.ProtocolType, request);\n            return Invalid(request, OidcConstants.AuthorizeErrors.UnauthorizedClient, description: \"Invalid protocol\");\n        }\n\n        //////////////////////////////////////////////////////////\n        // check if redirect_uri is valid\n        //////////////////////////////////////////////////////////\n        if (await _uriValidator.IsRedirectUriValidAsync(redirectUri, request.Client) == false)\n        {\n            LogError(\"Invalid redirect_uri\", redirectUri, request);\n            return Invalid(request, OidcConstants.AuthorizeErrors.InvalidRequest, \"Invalid redirect_uri\");\n        }\n\n        request.RedirectUri = redirectUri;\n\n        return Valid(request);\n    }\n\n    private AuthorizeRequestValidationResult ValidateCoreParameters(ValidatedAuthorizeRequest request)\n    {\n        //////////////////////////////////////////////////////////\n        // check state\n        //////////////////////////////////////////////////////////\n        var state = request.Raw.Get(OidcConstants.AuthorizeRequest.State);\n        if (state.IsPresent())\n        {\n            request.State = state;\n        }\n\n        //////////////////////////////////////////////////////////\n        // response_type must be present and supported\n        //////////////////////////////////////////////////////////\n        var responseType = request.Raw.Get(OidcConstants.AuthorizeRequest.ResponseType);\n        if (responseType.IsMissing())\n        {\n            LogError(\"Missing response_type\", request);\n            return Invalid(request, OidcConstants.AuthorizeErrors.UnsupportedResponseType, \"Missing response_type\");\n        }\n\n        // The responseType may come in in an unconventional order.\n        // Use an IEqualityComparer that doesn't care about the order of multiple values.\n        // Per https://tools.ietf.org/html/rfc6749#section-3.1.1 -\n        // 'Extension response types MAY contain a space-delimited (%x20) list of\n        // values, where the order of values does not matter (e.g., response\n        // type \"a b\" is the same as \"b a\").'\n        // http://openid.net/specs/oauth-v2-multiple-response-types-1_0-03.html#terminology -\n        // 'If a response type contains one of more space characters (%20), it is compared\n        // as a space-delimited list of values in which the order of values does not matter.'\n        if (!Constants.SupportedResponseTypes.Contains(responseType, _responseTypeEqualityComparer))\n        {\n            LogError(\"Response type not supported\", responseType, request);\n            return Invalid(request, OidcConstants.AuthorizeErrors.UnsupportedResponseType, \"Response type not supported\");\n        }\n\n        // Even though the responseType may have come in in an unconventional order,\n        // we still need the request's ResponseType property to be set to the\n        // conventional, supported response type.\n        request.ResponseType = Constants.SupportedResponseTypes.First(\n            supportedResponseType => _responseTypeEqualityComparer.Equals(supportedResponseType, responseType));\n\n        //////////////////////////////////////////////////////////\n        // match response_type to grant type\n        //////////////////////////////////////////////////////////\n        request.GrantType = Constants.ResponseTypeToGrantTypeMapping[request.ResponseType];\n\n        // set default response mode for flow; this is needed for any client error processing below\n        request.ResponseMode = Constants.AllowedResponseModesForGrantType[request.GrantType].First();\n\n        //////////////////////////////////////////////////////////\n        // check if flow is allowed at authorize endpoint\n        //////////////////////////////////////////////////////////\n        if (!Constants.AllowedGrantTypesForAuthorizeEndpoint.Contains(request.GrantType))\n        {\n            LogError(\"Invalid grant type\", request.GrantType, request);\n            return Invalid(request, description: \"Invalid response_type\");\n        }\n\n        //////////////////////////////////////////////////////////\n        // check if PKCE is required and validate parameters\n        //////////////////////////////////////////////////////////\n        if (request.GrantType == GrantType.AuthorizationCode || request.GrantType == GrantType.Hybrid)\n        {\n            _logger.LogDebug(\"Checking for PKCE parameters\");\n\n            /////////////////////////////////////////////////////////////////////////////\n            // validate code_challenge and code_challenge_method\n            /////////////////////////////////////////////////////////////////////////////\n            var proofKeyResult = ValidatePkceParameters(request);\n\n            if (proofKeyResult.IsError)\n            {\n                return proofKeyResult;\n            }\n        }\n\n        //////////////////////////////////////////////////////////\n        // check response_mode parameter and set response_mode\n        //////////////////////////////////////////////////////////\n\n        // check if response_mode parameter is present and valid\n        var responseMode = request.Raw.Get(OidcConstants.AuthorizeRequest.ResponseMode);\n        if (responseMode.IsPresent())\n        {\n            if (Constants.SupportedResponseModes.Contains(responseMode))\n            {\n                if (Constants.AllowedResponseModesForGrantType[request.GrantType].Contains(responseMode))\n                {\n                    request.ResponseMode = responseMode;\n                }\n                else\n                {\n                    LogError(\"Invalid response_mode for response_type\", responseMode, request);\n                    return Invalid(request, OidcConstants.AuthorizeErrors.InvalidRequest, description: \"Invalid response_mode for response_type\");\n                }\n            }\n            else\n            {\n                LogError(\"Unsupported response_mode\", responseMode, request);\n                return Invalid(request, OidcConstants.AuthorizeErrors.UnsupportedResponseType, description: \"Invalid response_mode\");\n            }\n        }\n\n\n        //////////////////////////////////////////////////////////\n        // check if grant type is allowed for client\n        //////////////////////////////////////////////////////////\n        if (!request.Client.AllowedGrantTypes.Contains(request.GrantType))\n        {\n            LogError(\"Invalid grant type for client\", request.GrantType, request);\n            return Invalid(request, OidcConstants.AuthorizeErrors.UnauthorizedClient, \"Invalid grant type for client\");\n        }\n\n        //////////////////////////////////////////////////////////\n        // check if response type contains an access token,\n        // and if client is allowed to request access token via browser\n        //////////////////////////////////////////////////////////\n        var responseTypes = responseType.FromSpaceSeparatedString();\n        if (responseTypes.Contains(OidcConstants.ResponseTypes.Token))\n        {\n            if (!request.Client.AllowAccessTokensViaBrowser)\n            {\n                LogError(\"Client requested access token - but client is not configured to receive access tokens via browser\", request);\n                return Invalid(request, description: \"Client not configured to receive access tokens via browser\");\n            }\n        }\n\n        return Valid(request);\n    }\n\n    private AuthorizeRequestValidationResult ValidatePkceParameters(ValidatedAuthorizeRequest request)\n    {\n        var fail = Invalid(request);\n\n        var codeChallenge = request.Raw.Get(OidcConstants.AuthorizeRequest.CodeChallenge);\n        if (codeChallenge.IsMissing())\n        {\n            if (request.Client.RequirePkce)\n            {\n                LogError(\"code_challenge is missing\", request);\n                fail.ErrorDescription = \"code challenge required\";\n            }\n            else\n            {\n                _logger.LogDebug(\"No PKCE used.\");\n                return Valid(request);\n            }\n\n            return fail;\n        }\n\n        if (codeChallenge.Length < _options.InputLengthRestrictions.CodeChallengeMinLength ||\n            codeChallenge.Length > _options.InputLengthRestrictions.CodeChallengeMaxLength)\n        {\n            LogError(\"code_challenge is either too short or too long\", request);\n            fail.ErrorDescription = \"Invalid code_challenge\";\n            return fail;\n        }\n\n        request.CodeChallenge = codeChallenge;\n\n        var codeChallengeMethod = request.Raw.Get(OidcConstants.AuthorizeRequest.CodeChallengeMethod);\n        if (codeChallengeMethod.IsMissing())\n        {\n            _logger.LogDebug(\"Missing code_challenge_method, defaulting to plain\");\n            codeChallengeMethod = OidcConstants.CodeChallengeMethods.Plain;\n        }\n\n        if (!Constants.SupportedCodeChallengeMethods.Contains(codeChallengeMethod))\n        {\n            LogError(\"Unsupported code_challenge_method\", codeChallengeMethod, request);\n            fail.ErrorDescription = \"Transform algorithm not supported\";\n            return fail;\n        }\n\n        // check if plain method is allowed\n        if (codeChallengeMethod == OidcConstants.CodeChallengeMethods.Plain)\n        {\n            if (!request.Client.AllowPlainTextPkce)\n            {\n                LogError(\"code_challenge_method of plain is not allowed\", request);\n                fail.ErrorDescription = \"Transform algorithm not supported\";\n                return fail;\n            }\n        }\n\n        request.CodeChallengeMethod = codeChallengeMethod;\n\n        return Valid(request);\n    }\n\n    private async Task<AuthorizeRequestValidationResult> ValidateScopeAsync(ValidatedAuthorizeRequest request)\n    {\n        //////////////////////////////////////////////////////////\n        // scope must be present\n        //////////////////////////////////////////////////////////\n        var scope = request.Raw.Get(OidcConstants.AuthorizeRequest.Scope);\n        if (scope.IsMissing())\n        {\n            LogError(\"scope is missing\", request);\n            return Invalid(request, description: \"Invalid scope\");\n        }\n\n        if (scope.Length > _options.InputLengthRestrictions.Scope)\n        {\n            LogError(\"scopes too long.\", request);\n            return Invalid(request, description: \"Invalid scope\");\n        }\n\n        request.RequestedScopes = scope.FromSpaceSeparatedString().Distinct().ToList();\n\n        if (request.RequestedScopes.Contains(IdentityServerConstants.StandardScopes.OpenId))\n        {\n            request.IsOpenIdRequest = true;\n        }\n\n        //////////////////////////////////////////////////////////\n        // check scope vs response_type plausability\n        //////////////////////////////////////////////////////////\n        var requirement = Constants.ResponseTypeToScopeRequirement[request.ResponseType];\n        if (requirement == Constants.ScopeRequirement.Identity ||\n            requirement == Constants.ScopeRequirement.IdentityOnly)\n        {\n            if (request.IsOpenIdRequest == false)\n            {\n                LogError(\"response_type requires the openid scope\", request);\n                return Invalid(request, description: \"Missing openid scope\");\n            }\n        }\n\n        //////////////////////////////////////////////////////////\n        // check if scopes are valid/supported and check for resource scopes\n        //////////////////////////////////////////////////////////\n        var validatedResources = await _resourceValidator.ValidateRequestedResourcesAsync(new ResourceValidationRequest\n        {\n            Client = request.Client,\n            Scopes = request.RequestedScopes\n        });\n\n        if (!validatedResources.Succeeded)\n        {\n            return Invalid(request, OidcConstants.AuthorizeErrors.InvalidScope, \"Invalid scope\");\n        }\n\n        if (validatedResources.Resources.IdentityResources.Any() && !request.IsOpenIdRequest)\n        {\n            LogError(\"Identity related scope requests, but no openid scope\", request);\n            return Invalid(request, OidcConstants.AuthorizeErrors.InvalidScope, \"Identity scopes requested, but openid scope is missing\");\n        }\n\n        if (validatedResources.Resources.ApiScopes.Any())\n        {\n            request.IsApiResourceRequest = true;\n        }\n\n        //////////////////////////////////////////////////////////\n        // check id vs resource scopes and response types plausability\n        //////////////////////////////////////////////////////////\n        var responseTypeValidationCheck = true;\n        switch (requirement)\n        {\n            case Constants.ScopeRequirement.Identity:\n                if (!validatedResources.Resources.IdentityResources.Any())\n                {\n                    _logger.LogError(\"Requests for id_token response type must include identity scopes\");\n                    responseTypeValidationCheck = false;\n                }\n                break;\n            case Constants.ScopeRequirement.IdentityOnly:\n                if (!validatedResources.Resources.IdentityResources.Any() || validatedResources.Resources.ApiScopes.Any())\n                {\n                    _logger.LogError(\"Requests for id_token response type only must not include resource scopes\");\n                    responseTypeValidationCheck = false;\n                }\n                break;\n            case Constants.ScopeRequirement.ResourceOnly:\n                if (validatedResources.Resources.IdentityResources.Any() || !validatedResources.Resources.ApiScopes.Any())\n                {\n                    _logger.LogError(\"Requests for token response type only must include resource scopes, but no identity scopes.\");\n                    responseTypeValidationCheck = false;\n                }\n                break;\n        }\n\n        if (!responseTypeValidationCheck)\n        {\n            return Invalid(request, OidcConstants.AuthorizeErrors.InvalidScope, \"Invalid scope for response type\");\n        }\n\n        request.ValidatedResources = validatedResources;\n\n        return Valid(request);\n    }\n\n    private async Task<AuthorizeRequestValidationResult> ValidateOptionalParametersAsync(ValidatedAuthorizeRequest request)\n    {\n        //////////////////////////////////////////////////////////\n        // check nonce\n        //////////////////////////////////////////////////////////\n        var nonce = request.Raw.Get(OidcConstants.AuthorizeRequest.Nonce);\n        if (nonce.IsPresent())\n        {\n            if (nonce.Length > _options.InputLengthRestrictions.Nonce)\n            {\n                LogError(\"Nonce too long\", request);\n                return Invalid(request, description: \"Invalid nonce\");\n            }\n\n            request.Nonce = nonce;\n        }\n        else\n        {\n            if (request.GrantType == GrantType.Implicit ||\n                request.GrantType == GrantType.Hybrid)\n            {\n                // only openid requests require nonce\n                if (request.IsOpenIdRequest)\n                {\n                    LogError(\"Nonce required for implicit and hybrid flow with openid scope\", request);\n                    return Invalid(request, description: \"Invalid nonce\");\n                }\n            }\n        }\n\n\n        //////////////////////////////////////////////////////////\n        // check prompt\n        //////////////////////////////////////////////////////////\n        var prompt = request.Raw.Get(OidcConstants.AuthorizeRequest.Prompt);\n        if (prompt.IsPresent())\n        {\n            var prompts = prompt.Split(' ', StringSplitOptions.RemoveEmptyEntries);\n            if (prompts.All(p => Constants.SupportedPromptModes.Contains(p)))\n            {\n                if (prompts.Contains(OidcConstants.PromptModes.None) && prompts.Length > 1)\n                {\n                    LogError(\"prompt contains 'none' and other values. 'none' should be used by itself.\", request);\n                    return Invalid(request, description: \"Invalid prompt\");\n                }\n\n                request.PromptModes = prompts;\n            }\n            else\n            {\n                _logger.LogDebug(\"Unsupported prompt mode - ignored: \" + prompt);\n            }\n        }\n\n        //////////////////////////////////////////////////////////\n        // check ui locales\n        //////////////////////////////////////////////////////////\n        var uilocales = request.Raw.Get(OidcConstants.AuthorizeRequest.UiLocales);\n        if (uilocales.IsPresent())\n        {\n            if (uilocales.Length > _options.InputLengthRestrictions.UiLocale)\n            {\n                LogError(\"UI locale too long\", request);\n                return Invalid(request, description: \"Invalid ui_locales\");\n            }\n\n            request.UiLocales = uilocales;\n        }\n\n        //////////////////////////////////////////////////////////\n        // check display\n        //////////////////////////////////////////////////////////\n        var display = request.Raw.Get(OidcConstants.AuthorizeRequest.Display);\n        if (display.IsPresent())\n        {\n            if (Constants.SupportedDisplayModes.Contains(display))\n            {\n                request.DisplayMode = display;\n            }\n\n            _logger.LogDebug(\"Unsupported display mode - ignored: \" + display);\n        }\n\n        //////////////////////////////////////////////////////////\n        // check max_age\n        //////////////////////////////////////////////////////////\n        var maxAge = request.Raw.Get(OidcConstants.AuthorizeRequest.MaxAge);\n        if (maxAge.IsPresent())\n        {\n            if (int.TryParse(maxAge, out var seconds))\n            {\n                if (seconds >= 0)\n                {\n                    request.MaxAge = seconds;\n                }\n                else\n                {\n                    LogError(\"Invalid max_age.\", request);\n                    return Invalid(request, description: \"Invalid max_age\");\n                }\n            }\n            else\n            {\n                LogError(\"Invalid max_age.\", request);\n                return Invalid(request, description: \"Invalid max_age\");\n            }\n        }\n\n        //////////////////////////////////////////////////////////\n        // check login_hint\n        //////////////////////////////////////////////////////////\n        var loginHint = request.Raw.Get(OidcConstants.AuthorizeRequest.LoginHint);\n        if (loginHint.IsPresent())\n        {\n            if (loginHint.Length > _options.InputLengthRestrictions.LoginHint)\n            {\n                LogError(\"Login hint too long\", request);\n                return Invalid(request, description: \"Invalid login_hint\");\n            }\n\n            request.LoginHint = loginHint;\n        }\n\n        //////////////////////////////////////////////////////////\n        // check acr_values\n        //////////////////////////////////////////////////////////\n        var acrValues = request.Raw.Get(OidcConstants.AuthorizeRequest.AcrValues);\n        if (acrValues.IsPresent())\n        {\n            if (acrValues.Length > _options.InputLengthRestrictions.AcrValues)\n            {\n                LogError(\"Acr values too long\", request);\n                return Invalid(request, description: \"Invalid acr_values\");\n            }\n\n            request.AuthenticationContextReferenceClasses = acrValues.FromSpaceSeparatedString().Distinct().ToList();\n        }\n\n        //////////////////////////////////////////////////////////\n        // check custom acr_values: idp\n        //////////////////////////////////////////////////////////\n        var idp = request.GetIdP();\n        if (idp.IsPresent())\n        {\n            // if idp is present but client does not allow it, strip it from the request message\n            if (request.Client.IdentityProviderRestrictions != null && request.Client.IdentityProviderRestrictions.Any())\n            {\n                if (!request.Client.IdentityProviderRestrictions.Contains(idp))\n                {\n                    _logger.LogWarning(\"idp requested ({idp}) is not in client restriction list.\", idp);\n                    request.RemoveIdP();\n                }\n            }\n        }\n\n        //////////////////////////////////////////////////////////\n        // check session cookie\n        //////////////////////////////////////////////////////////\n        if (_options.Endpoints.EnableCheckSessionEndpoint)\n        {\n            if (request.Subject.IsAuthenticated())\n            {\n                var sessionId = await _userSession.GetSessionIdAsync();\n                if (sessionId.IsPresent())\n                {\n                    request.SessionId = sessionId;\n                }\n                else\n                {\n                    LogError(\"Check session endpoint enabled, but SessionId is missing\", request);\n                }\n            }\n            else\n            {\n                request.SessionId = \"\"; // empty string for anonymous users\n            }\n        }\n\n        return Valid(request);\n    }\n\n    private AuthorizeRequestValidationResult Invalid(ValidatedAuthorizeRequest request, string error = OidcConstants.AuthorizeErrors.InvalidRequest, string description = null)\n    {\n        return new AuthorizeRequestValidationResult(request, error, description);\n    }\n\n    private AuthorizeRequestValidationResult Valid(ValidatedAuthorizeRequest request)\n    {\n        return new AuthorizeRequestValidationResult(request);\n    }\n\n    private void LogError(string message, ValidatedAuthorizeRequest request)\n    {\n        var requestDetails = new AuthorizeRequestValidationLog(request, _options.Logging.AuthorizeRequestSensitiveValuesFilter);\n        _logger.LogError(message + \"\\n{@requestDetails}\", requestDetails);\n    }\n\n    private void LogError(string message, string detail, ValidatedAuthorizeRequest request)\n    {\n        var requestDetails = new AuthorizeRequestValidationLog(request, _options.Logging.AuthorizeRequestSensitiveValuesFilter);\n        _logger.LogError(message + \": {detail}\\n{@requestDetails}\", detail, requestDetails);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/BasicAuthenticationSecretParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Parses a Basic Authentication header\n/// </summary>\npublic class BasicAuthenticationSecretParser : ISecretParser\n{\n    private readonly ILogger _logger;\n    private readonly IdentityServerOptions _options;\n\n    /// <summary>\n    /// Creates the parser with a reference to identity server options\n    /// </summary>\n    /// <param name=\"options\">IdentityServer options</param>\n    /// <param name=\"logger\">The logger</param>\n    public BasicAuthenticationSecretParser(IdentityServerOptions options, ILogger<BasicAuthenticationSecretParser> logger)\n    {\n        _options = options;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Returns the authentication method name that this parser implements\n    /// </summary>\n    /// <value>\n    /// The authentication method.\n    /// </value>\n    public string AuthenticationMethod => OidcConstants.EndpointAuthenticationMethods.BasicAuthentication;\n\n    /// <summary>\n    /// Tries to find a secret that can be used for authentication\n    /// </summary>\n    /// <returns>\n    /// A parsed secret\n    /// </returns>\n    public Task<ParsedSecret> ParseAsync(HttpContext context)\n    {\n        _logger.LogDebug(\"Start parsing Basic Authentication secret\");\n\n        var notfound = Task.FromResult<ParsedSecret>(null);\n        var authorizationHeader = context.Request.Headers[\"Authorization\"].FirstOrDefault();\n\n        if (authorizationHeader.IsMissing())\n        {\n            return notfound;\n        }\n\n        if (!authorizationHeader.StartsWith(\"Basic \", StringComparison.OrdinalIgnoreCase))\n        {\n            return notfound;\n        }\n\n        var parameter = authorizationHeader.Substring(\"Basic \".Length);\n\n        string pair;\n        try\n        {\n            pair = Encoding.UTF8.GetString(\n                Convert.FromBase64String(parameter));\n        }\n        catch (FormatException)\n        {\n            _logger.LogWarning(\"Malformed Basic Authentication credential.\");\n            return notfound;\n        }\n        catch (ArgumentException)\n        {\n            _logger.LogWarning(\"Malformed Basic Authentication credential.\");\n            return notfound;\n        }\n\n        var ix = pair.IndexOf(':');\n        if (ix == -1)\n        {\n            _logger.LogWarning(\"Malformed Basic Authentication credential.\");\n            return notfound;\n        }\n\n        var clientId = pair.Substring(0, ix);\n        var secret = pair.Substring(ix + 1);\n\n        if (clientId.IsPresent())\n        {\n            if (clientId.Length > _options.InputLengthRestrictions.ClientId)\n            {\n                _logger.LogError(\"Client ID exceeds maximum length.\");\n                return notfound;\n            }\n\n            if (secret.IsPresent())\n            {\n                if (secret.Length > _options.InputLengthRestrictions.ClientSecret)\n                {\n                    _logger.LogError(\"Client secret exceeds maximum length.\");\n                    return notfound;\n                }\n\n                var parsedSecret = new ParsedSecret\n                {\n                    Id = Decode(clientId),\n                    Credential = Decode(secret),\n                    Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n                };\n\n                return Task.FromResult(parsedSecret);\n            }\n            else\n            {\n                // client secret is optional\n                _logger.LogDebug(\"client id without secret found\");\n\n                var parsedSecret = new ParsedSecret\n                {\n                    Id = Decode(clientId),\n                    Type = IdentityServerConstants.ParsedSecretTypes.NoSecret\n                };\n\n                return Task.FromResult(parsedSecret);\n            }\n        }\n\n        _logger.LogDebug(\"No Basic Authentication secret found\");\n        return notfound;\n    }\n\n    // RFC6749 says individual values must be application/x-www-form-urlencoded\n    // 2.3.1\n    private string Decode(string value)\n    {\n        if (value.IsMissing()) return string.Empty;\n\n        return Uri.UnescapeDataString(value.Replace(\"+\", \"%20\"));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/BearerTokenUsageValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates a request that uses a bearer token for authentication\n/// </summary>\ninternal class BearerTokenUsageValidator\n{\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"BearerTokenUsageValidator\"/> class.\n    /// </summary>\n    /// <param name=\"logger\">The logger.</param>\n    public BearerTokenUsageValidator(ILogger<BearerTokenUsageValidator> logger)\n    {\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates the request.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public async Task<BearerTokenUsageValidationResult> ValidateAsync(HttpContext context)\n    {\n        var result = ValidateAuthorizationHeader(context);\n        if (result.TokenFound)\n        {\n            _logger.LogDebug(\"Bearer token found in header\");\n            return result;\n        }\n\n        if (context.Request.HasApplicationFormContentType())\n        {\n            result = await ValidatePostBodyAsync(context);\n            if (result.TokenFound)\n            {\n                _logger.LogDebug(\"Bearer token found in body\");\n                return result;\n            }\n        }\n\n        _logger.LogDebug(\"Bearer token not found\");\n        return new BearerTokenUsageValidationResult();\n    }\n\n    /// <summary>\n    /// Validates the authorization header.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public BearerTokenUsageValidationResult ValidateAuthorizationHeader(HttpContext context)\n    {\n        var authorizationHeader = context.Request.Headers[\"Authorization\"].FirstOrDefault();\n        if (authorizationHeader.IsPresent())\n        {\n            var header = authorizationHeader.Trim();\n            if (header.StartsWith(OidcConstants.AuthenticationSchemes.AuthorizationHeaderBearer))\n            {\n                var value = header.Substring(OidcConstants.AuthenticationSchemes.AuthorizationHeaderBearer.Length).Trim();\n                if (value.IsPresent())\n                {\n                    return new BearerTokenUsageValidationResult\n                    {\n                        TokenFound = true,\n                        Token = value,\n                        UsageType = BearerTokenUsageType.AuthorizationHeader\n                    };\n                }\n            }\n            else\n            {\n                _logger.LogTrace(\"Unexpected header format: {header}\", Ioc.Sanitizer.Log.Sanitize(header));\n            }\n        }\n\n        return new BearerTokenUsageValidationResult();\n    }\n\n    /// <summary>\n    /// Validates the post body.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public async Task<BearerTokenUsageValidationResult> ValidatePostBodyAsync(HttpContext context)\n    {\n        var token = (await context.Request.ReadFormAsync())[\"access_token\"].FirstOrDefault();\n        if (token.IsPresent())\n        {\n            return new BearerTokenUsageValidationResult\n            {\n                TokenFound = true,\n                Token = token,\n                UsageType = BearerTokenUsageType.PostBody\n            };\n        }\n\n        return new BearerTokenUsageValidationResult();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/ClientSecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates a client secret using the registered secret validators and parsers\n/// </summary>\npublic class ClientSecretValidator : IClientSecretValidator\n{\n    private readonly ILogger _logger;\n    private readonly IClientStore _clients;\n    private readonly IEventService _events;\n    private readonly ISecretsListValidator _validator;\n    private readonly ISecretsListParser _parser;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ClientSecretValidator\"/> class.\n    /// </summary>\n    /// <param name=\"clients\">The clients.</param>\n    /// <param name=\"parser\">The parser.</param>\n    /// <param name=\"validator\">The validator.</param>\n    /// <param name=\"events\">The events.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public ClientSecretValidator(IClientStore clients, ISecretsListParser parser, ISecretsListValidator validator, IEventService events, ILogger<ClientSecretValidator> logger)\n    {\n        _clients = clients;\n        _parser = parser;\n        _validator = validator;\n        _events = events;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates the current request.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public async Task<ClientSecretValidationResult> ValidateAsync(HttpContext context)\n    {\n        _logger.LogDebug(\"Start client validation\");\n\n        var fail = new ClientSecretValidationResult\n        {\n            IsError = true\n        };\n\n        var parsedSecret = await _parser.ParseAsync(context);\n        if (parsedSecret == null)\n        {\n            await RaiseFailureEventAsync(\"unknown\", \"No client id found\");\n\n            _logger.LogError(\"No client identifier found\");\n            return fail;\n        }\n\n        // load client\n        var client = await _clients.FindEnabledClientByIdAsync(parsedSecret.Id);\n        if (client == null)\n        {\n            await RaiseFailureEventAsync(parsedSecret.Id, \"Unknown client\");\n\n            _logger.LogError(\"No client with id '{clientId}' found. aborting\", Ioc.Sanitizer.Log.Sanitize(parsedSecret.Id));\n            return fail;\n        }\n\n        SecretValidationResult secretValidationResult = null;\n        if (!client.RequireClientSecret || client.IsImplicitOnly())\n        {\n            _logger.LogDebug(\"Public Client - skipping secret validation success\");\n        }\n        else\n        {\n            secretValidationResult = await _validator.ValidateAsync(client.ClientSecrets, parsedSecret);\n            if (secretValidationResult.Success == false)\n            {\n                await RaiseFailureEventAsync(client.ClientId, \"Invalid client secret\");\n                _logger.LogError(\"Client secret validation failed for client: {clientId}.\", client.ClientId);\n\n                return fail;\n            }\n        }\n\n        _logger.LogDebug(\"Client validation success\");\n\n        var success = new ClientSecretValidationResult\n        {\n            IsError = false,\n            Client = client,\n            Secret = parsedSecret,\n            Confirmation = secretValidationResult?.Confirmation\n        };\n\n        await RaiseSuccessEventAsync(client.ClientId, parsedSecret.Type);\n        return success;\n    }\n\n    private Task RaiseSuccessEventAsync(string clientId, string authMethod)\n    {\n        return _events.RaiseAsync(new ClientAuthenticationSuccessEvent(clientId, authMethod));\n    }\n\n    private Task RaiseFailureEventAsync(string clientId, string message)\n    {\n        return _events.RaiseAsync(new ClientAuthenticationFailureEvent(clientId, message));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/DefaultClientConfigurationValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Default client configuration validator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.IClientConfigurationValidator\" />\npublic class DefaultClientConfigurationValidator : IClientConfigurationValidator\n{\n    private readonly IdentityServerOptions _options;\n\n    /// <summary>\n    /// Constructor for DefaultClientConfigurationValidator\n    /// </summary>\n    public DefaultClientConfigurationValidator(IdentityServerOptions options)\n    {\n        _options = options;\n    }\n\n    /// <summary>\n    /// Determines whether the configuration of a client is valid.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public async Task ValidateAsync(ClientConfigurationValidationContext context)\n    {\n        if (context.Client.ProtocolType == IdentityServerConstants.ProtocolTypes.OpenIdConnect)\n        {\n            await ValidateGrantTypesAsync(context);\n            if (context.IsValid == false) return;\n\n            await ValidateLifetimesAsync(context);\n            if (context.IsValid == false) return;\n\n            await ValidateRedirectUriAsync(context);\n            if (context.IsValid == false) return;\n\n            await ValidateAllowedCorsOriginsAsync(context);\n            if (context.IsValid == false) return;\n\n            await ValidateUriSchemesAsync(context);\n            if (context.IsValid == false) return;\n\n            await ValidateSecretsAsync(context);\n            if (context.IsValid == false) return;\n\n            await ValidatePropertiesAsync(context);\n            if (context.IsValid == false) return;\n        }\n    }\n\n    /// <summary>\n    /// Validates grant type related configuration settings.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    protected virtual Task ValidateGrantTypesAsync(ClientConfigurationValidationContext context)\n    {\n        if (context.Client.AllowedGrantTypes?.Any() != true)\n        {\n            context.SetError(\"no allowed grant type specified\");\n        }\n\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Validates lifetime related configuration settings.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    protected virtual Task ValidateLifetimesAsync(ClientConfigurationValidationContext context)\n    {\n        if (context.Client.AccessTokenLifetime <= 0)\n        {\n            context.SetError(\"access token lifetime is 0 or negative\");\n            return Task.CompletedTask;\n        }\n\n        if (context.Client.IdentityTokenLifetime <= 0)\n        {\n            context.SetError(\"identity token lifetime is 0 or negative\");\n            return Task.CompletedTask;\n        }\n\n        if (context.Client.AllowedGrantTypes?.Contains(GrantType.DeviceFlow) == true\n            && context.Client.DeviceCodeLifetime <= 0)\n        {\n            context.SetError(\"device code lifetime is 0 or negative\");\n        }\n\n        // 0 means unlimited lifetime\n        if (context.Client.AbsoluteRefreshTokenLifetime < 0)\n        {\n            context.SetError(\"absolute refresh token lifetime is negative\");\n            return Task.CompletedTask;\n        }\n\n        // 0 might mean that sliding is disabled\n        if (context.Client.SlidingRefreshTokenLifetime < 0)\n        {\n            context.SetError(\"sliding refresh token lifetime is negative\");\n            return Task.CompletedTask;\n        }\n\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Validates redirect URI related configuration.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    protected virtual Task ValidateRedirectUriAsync(ClientConfigurationValidationContext context)\n    {\n        if (context.Client.AllowedGrantTypes?.Any() == true)\n        {\n            if (context.Client.AllowedGrantTypes.Contains(GrantType.AuthorizationCode) ||\n                context.Client.AllowedGrantTypes.Contains(GrantType.Hybrid) ||\n                context.Client.AllowedGrantTypes.Contains(GrantType.Implicit))\n            {\n                if (context.Client.RedirectUris?.Any() == false)\n                {\n                    context.SetError(\"No redirect URI configured.\");\n                }\n            }\n        }\n\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Validates allowed CORS origins for valid format.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    protected virtual Task ValidateAllowedCorsOriginsAsync(ClientConfigurationValidationContext context)\n    {\n        if (context.Client.AllowedCorsOrigins?.Any() == true)\n        {\n            foreach (var origin in context.Client.AllowedCorsOrigins)\n            {\n                var fail = true;\n\n                if (!string.IsNullOrWhiteSpace(origin) && Uri.TryCreate(origin, UriKind.Absolute, out var uri))\n                {\n                    if (uri.AbsolutePath == \"/\" && !origin.EndsWith(\"/\"))\n                    {\n                        fail = false;\n                    }\n                }\n\n                if (fail)\n                {\n                    if (!string.IsNullOrWhiteSpace(origin))\n                    {\n                        context.SetError($\"AllowedCorsOrigins contains invalid origin: {origin}\");\n                    }\n                    else\n                    {\n                        context.SetError($\"AllowedCorsOrigins contains invalid origin. There is an empty value.\");\n                    }\n                    return Task.CompletedTask;\n                }\n            }\n        }\n\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Validates that URI schemes is not in the list of invalid URI scheme prefixes, as controlled by the ValidationOptions.\n    /// </summary>\n    /// <param name=\"context\"></param>\n    /// <returns></returns>\n    protected virtual Task ValidateUriSchemesAsync(ClientConfigurationValidationContext context)\n    {\n        if (context.Client.RedirectUris?.Any() == true)\n        {\n            foreach (var uri in context.Client.RedirectUris)\n            {\n                if (_options.Validation.InvalidRedirectUriPrefixes\n                        .Any(scheme => uri?.StartsWith(scheme, StringComparison.OrdinalIgnoreCase) == true))\n                {\n                    context.SetError($\"RedirectUri '{uri}' uses invalid scheme. If this scheme should be allowed, then configure it via ValidationOptions.\");\n                }\n            }\n        }\n\n        if (context.Client.PostLogoutRedirectUris?.Any() == true)\n        {\n            foreach (var uri in context.Client.PostLogoutRedirectUris)\n            {\n                if (_options.Validation.InvalidRedirectUriPrefixes\n                        .Any(scheme => uri?.StartsWith(scheme, StringComparison.OrdinalIgnoreCase) == true))\n                {\n                    context.SetError($\"PostLogoutRedirectUri '{uri}' uses invalid scheme. If this scheme should be allowed, then configure it via ValidationOptions.\");\n                }\n            }\n        }\n\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Validates secret related configuration.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    protected virtual Task ValidateSecretsAsync(ClientConfigurationValidationContext context)\n    {\n        if (context.Client.AllowedGrantTypes?.Any() == true)\n        {\n            foreach (var grantType in context.Client.AllowedGrantTypes)\n            {\n                if (!string.Equals(grantType, GrantType.Implicit))\n                {\n                    if (context.Client.RequireClientSecret && context.Client.ClientSecrets.Count == 0)\n                    {\n                        context.SetError($\"Client secret is required for {grantType}, but no client secret is configured.\");\n                        return Task.CompletedTask;\n                    }\n                }\n            }\n        }\n\n        return Task.CompletedTask;\n    }\n\n    /// <summary>\n    /// Validates properties related configuration settings.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    protected virtual Task ValidatePropertiesAsync(ClientConfigurationValidationContext context)\n    {\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/DefaultCustomAuthorizeRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Default custom request validator\n/// </summary>\ninternal class DefaultCustomAuthorizeRequestValidator : ICustomAuthorizeRequestValidator\n{\n    /// <summary>\n    /// Custom validation logic for the authorize request.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    public Task ValidateAsync(CustomAuthorizeRequestValidationContext context)\n    {\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/DefaultCustomTokenRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Default custom request validator\n/// </summary>\ninternal class DefaultCustomTokenRequestValidator : ICustomTokenRequestValidator\n{\n    /// <summary>\n    /// Custom validation logic for a token request.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns>\n    /// The validation result\n    /// </returns>\n    public Task ValidateAsync(CustomTokenRequestValidationContext context)\n    {\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/DefaultCustomTokenValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Default custom token validator\n/// </summary>\npublic class DefaultCustomTokenValidator : ICustomTokenValidator\n{\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    /// The user service\n    /// </summary>\n    protected readonly IProfileService Profile;\n\n    /// <summary>\n    /// The client store\n    /// </summary>\n    protected readonly IClientStore Clients;\n\n    /// <summary>\n    /// Custom validation logic for access tokens.\n    /// </summary>\n    /// <param name=\"result\">The validation result so far.</param>\n    /// <returns>\n    /// The validation result\n    /// </returns>\n    public virtual Task<TokenValidationResult> ValidateAccessTokenAsync(TokenValidationResult result)\n    {\n        return Task.FromResult(result);\n    }\n\n    /// <summary>\n    /// Custom validation logic for identity tokens.\n    /// </summary>\n    /// <param name=\"result\">The validation result so far.</param>\n    /// <returns>\n    /// The validation result\n    /// </returns>\n    public virtual Task<TokenValidationResult> ValidateIdentityTokenAsync(TokenValidationResult result)\n    {\n        return Task.FromResult(result);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/DefaultResourceValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Default implementation of IResourceValidator.\n/// </summary>\npublic class DefaultResourceValidator : IResourceValidator\n{\n    private readonly ILogger _logger;\n    private readonly IScopeParser _scopeParser;\n    private readonly IResourceStore _store;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DefaultResourceValidator\"/> class.\n    /// </summary>\n    /// <param name=\"store\">The store.</param>\n    /// <param name=\"scopeParser\"></param>\n    /// <param name=\"logger\">The logger.</param>\n    public DefaultResourceValidator(IResourceStore store, IScopeParser scopeParser, ILogger<DefaultResourceValidator> logger)\n    {\n        _logger = logger;\n        _scopeParser = scopeParser;\n        _store = store;\n    }\n\n    /// <inheritdoc/>\n    public virtual async Task<ResourceValidationResult> ValidateRequestedResourcesAsync(ResourceValidationRequest request)\n    {\n        if (request == null) throw new ArgumentNullException(nameof(request));\n\n        var parsedScopesResult = _scopeParser.ParseScopeValues(request.Scopes);\n\n        var result = new ResourceValidationResult();\n        \n        if (!parsedScopesResult.Succeeded)\n        {\n            foreach (var invalidScope in parsedScopesResult.Errors)\n            {\n                _logger.LogError(\"Invalid parsed scope {scope}, message: {error}\", Ioc.Sanitizer.Log.Sanitize(invalidScope.RawValue), Ioc.Sanitizer.Log.Sanitize(invalidScope.Error));\n                result.InvalidScopes.Add(invalidScope.RawValue);\n            }\n\n            return result;\n        }\n\n        var scopeNames = parsedScopesResult.ParsedScopes.Select(x => x.ParsedName).Distinct().ToArray();\n        var resourcesFromStore = await _store.FindEnabledResourcesByScopeAsync(scopeNames);\n\n        foreach (var scope in parsedScopesResult.ParsedScopes)\n        {\n            await ValidateScopeAsync(request.Client, resourcesFromStore, scope, result);\n        }\n\n        if (result.InvalidScopes.Count > 0)\n        {\n            result.Resources.IdentityResources.Clear();\n            result.Resources.ApiResources.Clear();\n            result.Resources.ApiScopes.Clear();\n            result.ParsedScopes.Clear();\n        }\n\n        return result;\n    }\n\n    /// <summary>\n    /// Validates that the requested scopes is contained in the store, and the client is allowed to request it.\n    /// </summary>\n    /// <param name=\"client\"></param>\n    /// <param name=\"resourcesFromStore\"></param>\n    /// <param name=\"requestedScope\"></param>\n    /// <param name=\"result\"></param>\n    /// <returns></returns>\n    protected virtual async Task ValidateScopeAsync(\n        Client client, \n        Resources resourcesFromStore, \n        ParsedScopeValue requestedScope, \n        ResourceValidationResult result)\n    {\n        if (requestedScope.ParsedName == IdentityServerConstants.StandardScopes.OfflineAccess)\n        {\n            if (await IsClientAllowedOfflineAccessAsync(client))\n            {\n                result.Resources.OfflineAccess = true;\n                result.ParsedScopes.Add(new ParsedScopeValue(IdentityServerConstants.StandardScopes.OfflineAccess));\n            }\n            else\n            {\n                result.InvalidScopes.Add(IdentityServerConstants.StandardScopes.OfflineAccess);\n            }\n        }\n        else\n        {\n            var identity = resourcesFromStore.FindIdentityResourcesByScope(requestedScope.ParsedName);\n            if (identity != null)\n            {\n                if (await IsClientAllowedIdentityResourceAsync(client, identity))\n                {\n                    result.ParsedScopes.Add(requestedScope);\n                    result.Resources.IdentityResources.Add(identity);\n                }\n                else\n                {\n                    result.InvalidScopes.Add(requestedScope.RawValue);\n                }\n            }\n            else\n            {\n                var apiScope = resourcesFromStore.FindApiScope(requestedScope.ParsedName);\n                if (apiScope != null)\n                {\n                    if (await IsClientAllowedApiScopeAsync(client, apiScope))\n                    {\n                        result.ParsedScopes.Add(requestedScope);\n                        result.Resources.ApiScopes.Add(apiScope);\n\n                        var apis = resourcesFromStore.FindApiResourcesByScope(apiScope.Name);\n                        foreach (var api in apis)\n                        {\n                            result.Resources.ApiResources.Add(api);\n                        }\n                    }\n                    else\n                    {\n                        result.InvalidScopes.Add(requestedScope.RawValue);\n                    }\n                }\n                else\n                {\n                    _logger.LogError(\"Scope {scope} not found in store.\", requestedScope.ParsedName);\n                    result.InvalidScopes.Add(requestedScope.RawValue);\n                }\n            }\n        }\n    }\n\n    /// <summary>\n    /// Determines if client is allowed access to the identity scope.\n    /// </summary>\n    /// <param name=\"client\"></param>\n    /// <param name=\"identity\"></param>\n    /// <returns></returns>\n    protected virtual Task<bool> IsClientAllowedIdentityResourceAsync(Client client, IdentityResource identity)\n    {\n        var allowed = client.AllowedScopes.Contains(identity.Name);\n        if (!allowed)\n        {\n            _logger.LogError(\"Client {client} is not allowed access to scope {scope}.\", client.ClientId, identity.Name);\n        }\n        return Task.FromResult(allowed);\n    }\n\n    /// <summary>\n    /// Determines if client is allowed access to the API scope.\n    /// </summary>\n    /// <param name=\"client\"></param>\n    /// <param name=\"apiScope\"></param>\n    /// <returns></returns>\n    protected virtual Task<bool> IsClientAllowedApiScopeAsync(Client client, ApiScope apiScope)\n    {\n        var allowed = client.AllowedScopes.Contains(apiScope.Name);\n        if (!allowed)\n        {\n            _logger.LogError(\"Client {client} is not allowed access to scope {scope}.\", client.ClientId, apiScope.Name);\n        }\n        return Task.FromResult(allowed);\n    }\n\n    /// <summary>\n    /// Validates if the client is allowed offline_access.\n    /// </summary>\n    /// <param name=\"client\"></param>\n    /// <returns></returns>\n    protected virtual Task<bool> IsClientAllowedOfflineAccessAsync(Client client)\n    {\n        var allowed = client.AllowOfflineAccess;\n        if (!allowed)\n        {\n            _logger.LogError(\"Client {client} is not allowed access to scope offline_access (via AllowOfflineAccess setting).\", client.ClientId);\n        }\n        return Task.FromResult(allowed);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/DefaultScopeParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Default implementation of IScopeParser.\n/// </summary>\npublic class DefaultScopeParser : IScopeParser\n{\n    private readonly ILogger<DefaultScopeParser> _logger;\n\n    /// <summary>\n    /// Ctor.\n    /// </summary>\n    /// <param name=\"logger\"></param>\n    public DefaultScopeParser(ILogger<DefaultScopeParser> logger)\n    {\n        _logger = logger;\n    }\n\n    /// <inheritdoc/>\n    public ParsedScopesResult ParseScopeValues(IEnumerable<string> scopeValues)\n    {\n        if (scopeValues == null) throw new ArgumentNullException(nameof(scopeValues));\n\n        var result = new ParsedScopesResult();\n\n        foreach (var scopeValue in scopeValues)\n        {\n            var ctx = new ParseScopeContext(scopeValue);\n            ParseScopeValue(ctx);\n            \n            if (ctx.Succeeded)\n            {\n                var parsedScope = ctx.ParsedName != null ?\n                    new ParsedScopeValue(ctx.RawValue, ctx.ParsedName, ctx.ParsedParameter) :\n                    new ParsedScopeValue(ctx.RawValue);\n\n                result.ParsedScopes.Add(parsedScope);\n            }\n            else if (!ctx.Ignore)\n            {\n                result.Errors.Add(new ParsedScopeValidationError(scopeValue, ctx.Error));\n            }\n            else\n            {\n                _logger.LogDebug(\"Scope parsing ignoring scope {scope}\", Ioc.Sanitizer.Log.Sanitize(scopeValue));\n            }\n        }\n\n        return result;\n    }\n\n    /// <summary>\n    /// Parses a scope value.\n    /// </summary>\n    /// <param name=\"scopeContext\"></param>\n    /// <returns></returns>\n    public virtual void ParseScopeValue(ParseScopeContext scopeContext)\n    {\n        // nop leaves the raw scope value as a success result.\n    }\n\n    /// <summary>\n    /// Models the context for parsing a scope.\n    /// </summary>\n    public class ParseScopeContext\n    {\n        /// <summary>\n        /// The original (raw) value of the scope.\n        /// </summary>\n        public string RawValue { get; }\n\n        /// <summary>\n        /// The parsed name of the scope. \n        /// </summary>\n        public string ParsedName { get; private set; }\n\n        /// <summary>\n        /// The parsed parameter value of the scope. \n        /// </summary>\n        public string ParsedParameter { get; private set; }\n\n        /// <summary>\n        /// The error encountered parsing the scope.\n        /// </summary>\n        public string Error { get; private set; }\n        \n        /// <summary>\n        /// Indicates if the scope should be excluded from the parsed results.\n        /// </summary>\n        public bool Ignore { get; private set; }\n\n        /// <summary>\n        /// Indicates if parsing the scope was successful.\n        /// </summary>\n        public bool Succeeded => !Ignore && Error == null;\n\n\n        /// <summary>\n        /// Ctor. Indicates success, but the scope should not be included in result.\n        /// </summary>\n        internal ParseScopeContext(string rawScopeValue)\n        {\n            RawValue = rawScopeValue;\n        }\n\n        /// <summary>\n        /// Sets the parsed name and parsed parameter value for the scope.\n        /// </summary>\n        /// <param name=\"parsedName\"></param>\n        /// <param name=\"parsedParameter\"></param>\n        public void SetParsedValues(string parsedName, string parsedParameter)\n        {\n            if (String.IsNullOrWhiteSpace(parsedName))\n            {\n                throw new ArgumentNullException(nameof(parsedName));\n            }\n            if (String.IsNullOrWhiteSpace(parsedParameter))\n            {\n                throw new ArgumentNullException(nameof(parsedParameter));\n            }\n\n            ParsedName = parsedName;\n            ParsedParameter = parsedParameter;\n            Error = null;\n            Ignore = false;\n        }\n\n        /// <summary>\n        /// Set the error encountered parsing the scope.\n        /// </summary>\n        /// <param name=\"error\"></param>\n        public void SetError(string error)\n        {\n            ParsedName = null;\n            ParsedParameter = null;\n            Error = error;\n            Ignore = false;\n        }\n\n        /// <summary>\n        /// Sets that the scope is to be ignore/excluded from the parsed results.\n        /// </summary>\n        public void SetIgnore()\n        {\n            ParsedName = null;\n            ParsedParameter = null;\n            Error = null;\n            Ignore = true;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/DeviceAuthorizationRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\ninternal class DeviceAuthorizationRequestValidator : IDeviceAuthorizationRequestValidator\n{\n    private readonly IdentityServerOptions _options;\n    private readonly IResourceValidator _resourceValidator;\n    private readonly ILogger<DeviceAuthorizationRequestValidator> _logger;\n    \n    public DeviceAuthorizationRequestValidator(\n        IdentityServerOptions options,\n        IResourceValidator resourceValidator,\n        ILogger<DeviceAuthorizationRequestValidator> logger)\n    {\n        _options = options;\n        _resourceValidator = resourceValidator;\n        _logger = logger;\n    }\n\n    public async Task<DeviceAuthorizationRequestValidationResult> ValidateAsync(NameValueCollection parameters, ClientSecretValidationResult clientValidationResult)\n    {\n        _logger.LogDebug(\"Start device authorization request validation\");\n\n        var request = new ValidatedDeviceAuthorizationRequest\n        {\n            Raw = parameters ?? throw new ArgumentNullException(nameof(parameters)),\n            Options = _options\n        };\n\n        var clientResult = ValidateClient(request, clientValidationResult);\n        if (clientResult.IsError)\n        {\n            return clientResult;\n        }\n\n        var scopeResult = await ValidateScopeAsync(request);\n        if (scopeResult.IsError)\n        {\n            return scopeResult;\n        }\n\n        _logger.LogDebug(\"{clientId} device authorization request validation success\", request.Client.ClientId);\n        return Valid(request);\n    }\n\n    private DeviceAuthorizationRequestValidationResult Valid(ValidatedDeviceAuthorizationRequest request)\n    {\n        return new DeviceAuthorizationRequestValidationResult(request);\n    }\n\n    private DeviceAuthorizationRequestValidationResult Invalid(ValidatedDeviceAuthorizationRequest request, string error = OidcConstants.AuthorizeErrors.InvalidRequest, string description = null)\n    {\n        return new DeviceAuthorizationRequestValidationResult(request, error, description);\n    }\n\n    private void LogError(string message, ValidatedDeviceAuthorizationRequest request)\n    {\n        var requestDetails = new DeviceAuthorizationRequestValidationLog(request);\n        _logger.LogError(message + \"\\n{requestDetails}\", requestDetails);\n    }\n\n    private void LogError(string message, string detail, ValidatedDeviceAuthorizationRequest request)\n    {\n        var requestDetails = new DeviceAuthorizationRequestValidationLog(request);\n        _logger.LogError(message + \": {detail}\\n{requestDetails}\", detail, requestDetails);\n    }\n\n    private DeviceAuthorizationRequestValidationResult ValidateClient(ValidatedDeviceAuthorizationRequest request, ClientSecretValidationResult clientValidationResult)\n    {\n        //////////////////////////////////////////////////////////\n        // set client & secret\n        //////////////////////////////////////////////////////////\n        if (clientValidationResult == null) throw new ArgumentNullException(nameof(clientValidationResult));\n        request.SetClient(clientValidationResult.Client, clientValidationResult.Secret);\n\n        //////////////////////////////////////////////////////////\n        // check if client protocol type is oidc\n        //////////////////////////////////////////////////////////\n        if (request.Client.ProtocolType != IdentityServerConstants.ProtocolTypes.OpenIdConnect)\n        {\n            LogError(\"Invalid protocol type for OIDC authorize endpoint\", request.Client.ProtocolType, request);\n            return Invalid(request, OidcConstants.AuthorizeErrors.UnauthorizedClient, \"Invalid protocol\");\n        }\n\n        //////////////////////////////////////////////////////////\n        // check if client allows device flow\n        //////////////////////////////////////////////////////////\n        if (!request.Client.AllowedGrantTypes.Contains(GrantType.DeviceFlow))\n        {\n            LogError(\"Client not configured for device flow\", GrantType.DeviceFlow, request);\n            return Invalid(request, OidcConstants.AuthorizeErrors.UnauthorizedClient);\n        }\n\n        return Valid(request);\n    }\n\n    private async Task<DeviceAuthorizationRequestValidationResult> ValidateScopeAsync(ValidatedDeviceAuthorizationRequest request)\n    {\n        //////////////////////////////////////////////////////////\n        // scope must be present\n        //////////////////////////////////////////////////////////\n        var scope = request.Raw.Get(OidcConstants.AuthorizeRequest.Scope);\n        if (scope.IsMissing())\n        {\n            _logger.LogTrace(\"Client provided no scopes - checking allowed scopes list\");\n\n            if (!request.Client.AllowedScopes.EnumerableIsNullOrEmpty())\n            {\n                var clientAllowedScopes = new List<string>(request.Client.AllowedScopes);\n                if (request.Client.AllowOfflineAccess)\n                {\n                    clientAllowedScopes.Add(IdentityServerConstants.StandardScopes.OfflineAccess);\n                }\n                scope = clientAllowedScopes.ToSpaceSeparatedString();\n                _logger.LogTrace(\"Defaulting to: {scopes}\", scope);\n            }\n            else\n            {\n                LogError(\"No allowed scopes configured for client\", request);\n                return Invalid(request, OidcConstants.AuthorizeErrors.InvalidScope);\n            }\n        }\n\n        if (scope.Length > _options.InputLengthRestrictions.Scope)\n        {\n            LogError(\"scopes too long.\", request);\n            return Invalid(request, description: \"Invalid scope\");\n        }\n\n        request.RequestedScopes = scope.FromSpaceSeparatedString().Distinct().ToList();\n\n        if (request.RequestedScopes.Contains(IdentityServerConstants.StandardScopes.OpenId))\n        {\n            request.IsOpenIdRequest = true;\n        }\n\n        //////////////////////////////////////////////////////////\n        // check if scopes are valid/supported\n        //////////////////////////////////////////////////////////\n        var validatedResources = await _resourceValidator.ValidateRequestedResourcesAsync(new ResourceValidationRequest{\n            Client = request.Client, \n            Scopes = request.RequestedScopes\n        });\n\n        if (!validatedResources.Succeeded)\n        {\n            if (validatedResources.InvalidScopes.Count > 0)\n            {\n                return Invalid(request, OidcConstants.AuthorizeErrors.InvalidScope);\n            }\n            \n            return Invalid(request, OidcConstants.AuthorizeErrors.UnauthorizedClient, \"Invalid scope\");\n        }\n\n        if (validatedResources.Resources.IdentityResources.Any() && !request.IsOpenIdRequest)\n        {\n            LogError(\"Identity related scope requests, but no openid scope\", request);\n            return Invalid(request, OidcConstants.AuthorizeErrors.InvalidScope);\n        }\n\n        request.ValidatedResources = validatedResources;\n        \n        return Valid(request);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/DeviceCodeValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates an incoming token request using the device flow\n/// </summary>\ninternal class DeviceCodeValidator : IDeviceCodeValidator\n{\n    private readonly IDeviceFlowCodeService _devices;\n    private readonly IProfileService _profile;\n    private readonly IDeviceFlowThrottlingService _throttlingService;\n    private readonly ISystemClock _systemClock;\n    private readonly ILogger<DeviceCodeValidator> _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DeviceCodeValidator\"/> class.\n    /// </summary>\n    /// <param name=\"devices\">The devices.</param>\n    /// <param name=\"profile\">The profile.</param>\n    /// <param name=\"throttlingService\">The throttling service.</param>\n    /// <param name=\"systemClock\">The system clock.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public DeviceCodeValidator(\n        IDeviceFlowCodeService devices,\n        IProfileService profile,\n        IDeviceFlowThrottlingService throttlingService,\n        ISystemClock systemClock,\n        ILogger<DeviceCodeValidator> logger)\n    {\n        _devices = devices;\n        _profile = profile;\n        _throttlingService = throttlingService;\n        _systemClock = systemClock;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates the device code.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public async Task ValidateAsync(DeviceCodeValidationContext context)\n    {\n        var deviceCode = await _devices.FindByDeviceCodeAsync(context.DeviceCode);\n\n        if (deviceCode == null)\n        {\n            _logger.LogError(\"Invalid device code\");\n            context.Result = new TokenRequestValidationResult(context.Request, OidcConstants.TokenErrors.InvalidGrant);\n            return;\n        }\n        \n        // validate client binding\n        if (deviceCode.ClientId != context.Request.Client.ClientId)\n        {\n            _logger.LogError(\"Client {0} is trying to use a device code from client {1}\", context.Request.Client.ClientId, deviceCode.ClientId);\n            context.Result = new TokenRequestValidationResult(context.Request, OidcConstants.TokenErrors.InvalidGrant);\n            return;\n        }\n\n        if (await _throttlingService.ShouldSlowDown(context.DeviceCode, deviceCode))\n        {\n            _logger.LogError(\"Client {0} is polling too fast\", deviceCode.ClientId);\n            context.Result = new TokenRequestValidationResult(context.Request, OidcConstants.TokenErrors.SlowDown);\n            return;\n        }\n\n        // validate lifetime\n        if (deviceCode.CreationTime.AddSeconds(deviceCode.Lifetime) < _systemClock.UtcNow)\n        {\n            _logger.LogError(\"Expired device code\");\n            context.Result = new TokenRequestValidationResult(context.Request, OidcConstants.TokenErrors.ExpiredToken);\n            return;\n        }\n\n        // denied\n        if (deviceCode.IsAuthorized\n            && (deviceCode.AuthorizedScopes == null || deviceCode.AuthorizedScopes.Any() == false))\n        {\n            _logger.LogError(\"No scopes authorized for device authorization. Access denied\");\n            context.Result = new TokenRequestValidationResult(context.Request, OidcConstants.TokenErrors.AccessDenied);\n            return;\n        }\n\n        // make sure code is authorized\n        if (!deviceCode.IsAuthorized || deviceCode.Subject == null)\n        {\n            context.Result = new TokenRequestValidationResult(context.Request, OidcConstants.TokenErrors.AuthorizationPending);\n            return;\n        }\n\n        // make sure user is enabled\n        var isActiveCtx = new IsActiveContext(deviceCode.Subject, context.Request.Client, IdentityServerConstants.ProfileIsActiveCallers.DeviceCodeValidation);\n        await _profile.IsActiveAsync(isActiveCtx);\n\n        if (isActiveCtx.IsActive == false)\n        {\n            _logger.LogError(\"User has been disabled: {subjectId}\", deviceCode.Subject.GetSubjectId());\n            context.Result = new TokenRequestValidationResult(context.Request, OidcConstants.TokenErrors.InvalidGrant);\n            return;\n        }\n\n        context.Request.DeviceCode = deviceCode;\n        context.Request.SessionId = deviceCode.SessionId;\n\n        context.Result = new TokenRequestValidationResult(context.Request);\n        await _devices.RemoveByDeviceCodeAsync(context.DeviceCode);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/EndSessionRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates requests to the end session endpoint.\n/// </summary>\npublic class EndSessionRequestValidator : IEndSessionRequestValidator\n{\n    /// <summary>\n    /// The logger.\n    /// </summary>\n    protected readonly ILogger Logger;\n\n    /// <summary>\n    ///  The IdentityServer options.\n    /// </summary>\n    protected readonly IdentityServerOptions Options;\n\n    /// <summary>\n    /// The token validator.\n    /// </summary>\n    protected readonly ITokenValidator TokenValidator;\n\n    /// <summary>\n    /// The URI validator.\n    /// </summary>\n    protected readonly IRedirectUriValidator UriValidator;\n\n    /// <summary>\n    /// The user session service.\n    /// </summary>\n    protected readonly IUserSession UserSession;\n\n    /// <summary>\n    /// The logout notification service.\n    /// </summary>\n    public ILogoutNotificationService LogoutNotificationService { get; }\n\n    /// <summary>\n    /// The end session message store.\n    /// </summary>\n    protected readonly IMessageStore<LogoutNotificationContext> EndSessionMessageStore;\n\n    /// <summary>\n    /// The HTTP context accessor.\n    /// </summary>\n    protected readonly IHttpContextAccessor Context;\n\n    /// <summary>\n    /// Creates a new instance of the EndSessionRequestValidator.\n    /// </summary>\n    /// <param name=\"context\"></param>\n    /// <param name=\"options\"></param>\n    /// <param name=\"tokenValidator\"></param>\n    /// <param name=\"uriValidator\"></param>\n    /// <param name=\"userSession\"></param>\n    /// <param name=\"logoutNotificationService\"></param>\n    /// <param name=\"endSessionMessageStore\"></param>\n    /// <param name=\"logger\"></param>\n    public EndSessionRequestValidator(\n        IHttpContextAccessor context,\n        IdentityServerOptions options,\n        ITokenValidator tokenValidator,\n        IRedirectUriValidator uriValidator,\n        IUserSession userSession,\n        ILogoutNotificationService logoutNotificationService,\n        IMessageStore<LogoutNotificationContext> endSessionMessageStore,\n        ILogger<EndSessionRequestValidator> logger)\n    {\n        Context = context;\n        Options = options;\n        TokenValidator = tokenValidator;\n        UriValidator = uriValidator;\n        UserSession = userSession;\n        LogoutNotificationService = logoutNotificationService;\n        EndSessionMessageStore = endSessionMessageStore;\n        Logger = logger;\n    }\n\n    /// <inheritdoc />\n    public async Task<EndSessionValidationResult> ValidateAsync(NameValueCollection parameters, ClaimsPrincipal subject)\n    {\n        Logger.LogDebug(\"Start end session request validation\");\n\n        var isAuthenticated = subject.IsAuthenticated();\n\n        if (!isAuthenticated && Options.Authentication.RequireAuthenticatedUserForSignOutMessage)\n        {\n            return Invalid(\"User is anonymous. Ignoring end session parameters\");\n        }\n\n        var validatedRequest = new ValidatedEndSessionRequest\n        {\n            Raw = parameters\n        };\n\n        var idTokenHint = parameters.Get(OidcConstants.EndSessionRequest.IdTokenHint);\n        if (idTokenHint.IsPresent())\n        {\n            // validate id_token - no need to validate token life time\n            var tokenValidationResult = await TokenValidator.ValidateIdentityTokenAsync(idTokenHint, null, false);\n            if (tokenValidationResult.IsError)\n            {\n                return Invalid(\"Error validating id token hint\", validatedRequest);\n            }\n\n            validatedRequest.Client = tokenValidationResult.Client;\n\n            // validate sub claim against currently logged on user\n            var subClaim = tokenValidationResult.Claims.FirstOrDefault(c => c.Type == JwtClaimTypes.Subject);\n            if (subClaim != null && isAuthenticated)\n            {\n                if (subject.GetSubjectId() != subClaim.Value)\n                {\n                    return Invalid(\"Current user does not match identity token\", validatedRequest);\n                }\n\n                validatedRequest.Subject = subject;\n                validatedRequest.SessionId = await UserSession.GetSessionIdAsync();\n                validatedRequest.ClientIds = await UserSession.GetClientListAsync();\n            }\n\n            var redirectUri = parameters.Get(OidcConstants.EndSessionRequest.PostLogoutRedirectUri);\n            if (redirectUri.IsPresent())\n            {\n                if (await UriValidator.IsPostLogoutRedirectUriValidAsync(redirectUri, validatedRequest.Client))\n                {\n                    validatedRequest.PostLogOutUri = redirectUri;\n                }\n                else\n                {\n                    Logger.LogWarning(\"Invalid PostLogoutRedirectUri: {postLogoutRedirectUri}\", redirectUri);\n                }\n            }\n\n            if (validatedRequest.PostLogOutUri != null)\n            {\n                var state = parameters.Get(OidcConstants.EndSessionRequest.State);\n                if (state.IsPresent())\n                {\n                    validatedRequest.State = state;\n                }\n            }\n        }\n        else\n        {\n            // no id_token to authenticate the client, but we do have a user and a user session\n            validatedRequest.Subject = subject;\n            validatedRequest.SessionId = await UserSession.GetSessionIdAsync();\n            validatedRequest.ClientIds = await UserSession.GetClientListAsync();\n        }\n\n        LogSuccess(validatedRequest);\n\n        return new EndSessionValidationResult\n        {\n            ValidatedRequest = validatedRequest,\n            IsError = false\n        };\n    }\n\n    /// <summary>\n    /// Creates a result that indicates an error.\n    /// </summary>\n    /// <param name=\"message\"></param>\n    /// <param name=\"request\"></param>\n    /// <returns></returns>\n    protected virtual EndSessionValidationResult Invalid(string message, ValidatedEndSessionRequest request = null)\n    {\n        message = \"End session request validation failure: \" + message;\n        if (request != null)\n        {\n            var log = new EndSessionRequestValidationLog(request);\n            Logger.LogInformation(message + Environment.NewLine + \"{@details}\", log);\n        }\n        else\n        {\n            Logger.LogInformation(message);\n        }\n\n        return new EndSessionValidationResult\n        {\n            IsError = true,\n            Error = \"Invalid request\",\n            ErrorDescription = message\n        };\n    }\n\n    /// <summary>\n    /// Logs a success result.\n    /// </summary>\n    /// <param name=\"request\"></param>\n    protected virtual void LogSuccess(ValidatedEndSessionRequest request)\n    {\n        var log = new EndSessionRequestValidationLog(request);\n        Logger.LogInformation(\"End session request validation success\" + Environment.NewLine + \"{@details}\", log);\n    }\n\n    /// <inheritdoc />\n    public async Task<EndSessionCallbackValidationResult> ValidateCallbackAsync(NameValueCollection parameters)\n    {\n        var result = new EndSessionCallbackValidationResult\n        {\n            IsError = true\n        };\n\n        var endSessionId = parameters[Constants.UIConstants.DefaultRoutePathParams.EndSessionCallback];\n        var endSessionMessage = await EndSessionMessageStore.ReadAsync(endSessionId);\n        if (endSessionMessage?.Data?.ClientIds?.Any() == true)\n        {\n            result.IsError = false;\n            result.FrontChannelLogoutUrls = await LogoutNotificationService.GetFrontChannelLogoutNotificationsUrlsAsync(endSessionMessage.Data);\n        }\n        else\n        {\n            result.Error = \"Failed to read end session callback message\";\n        }\n\n        return result;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/ExtensionGrantValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates an extension grant request using the registered validators\n/// </summary>\npublic class ExtensionGrantValidator\n{\n    private readonly ILogger _logger;\n    private readonly IEnumerable<IExtensionGrantValidator> _validators;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ExtensionGrantValidator\"/> class.\n    /// </summary>\n    /// <param name=\"validators\">The validators.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public ExtensionGrantValidator(IEnumerable<IExtensionGrantValidator> validators, ILogger<ExtensionGrantValidator> logger)\n    {\n        if (validators == null)\n        {\n            _validators = Enumerable.Empty<IExtensionGrantValidator>();\n        }\n        else\n        {\n            _validators = validators;\n        }\n\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Gets the available grant types.\n    /// </summary>\n    /// <returns></returns>\n    public IEnumerable<string> GetAvailableGrantTypes()\n    {\n        return _validators.Select(v => v.GrantType);\n    }\n\n    /// <summary>\n    /// Validates the request.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <returns></returns>\n    public async Task<GrantValidationResult> ValidateAsync(ValidatedTokenRequest request)\n    {\n        var validator = _validators.FirstOrDefault(v => v.GrantType.Equals(request.GrantType, StringComparison.Ordinal));\n\n        if (validator == null)\n        {\n            _logger.LogError(\"No validator found for grant type\");\n            return new GrantValidationResult(TokenRequestErrors.UnsupportedGrantType);\n        }\n\n        try\n        {\n            _logger.LogTrace(\"Calling into custom grant validator: {type}\", validator.GetType().FullName);\n\n            var context = new ExtensionGrantValidationContext\n            {\n                Request = request\n            };\n        \n            await validator.ValidateAsync(context);\n            return context.Result;\n        }\n        catch (Exception e)\n        {\n            _logger.LogError(1, e, \"Grant validation error: {message}\", e.Message);\n            return new GrantValidationResult(TokenRequestErrors.InvalidGrant);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/HashedSharedSecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Secret = IdentityServer8.Models.Secret;\n\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates a shared secret stored in SHA256 or SHA512\n/// </summary>\npublic class HashedSharedSecretValidator : ISecretValidator\n{\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"HashedSharedSecretValidator\"/> class.\n    /// </summary>\n    /// <param name=\"logger\">The logger.</param>\n    public HashedSharedSecretValidator(ILogger<HashedSharedSecretValidator> logger)\n    {\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates a secret\n    /// </summary>\n    /// <param name=\"secrets\">The stored secrets.</param>\n    /// <param name=\"parsedSecret\">The received secret.</param>\n    /// <returns>\n    /// A validation result\n    /// </returns>\n    /// <exception cref=\"System.ArgumentNullException\">Id or cedential</exception>\n    public Task<SecretValidationResult> ValidateAsync(IEnumerable<Secret> secrets, ParsedSecret parsedSecret)\n    {\n        var fail = Task.FromResult(new SecretValidationResult { Success = false });\n        var success = Task.FromResult(new SecretValidationResult { Success = true });\n\n        if (parsedSecret.Type != IdentityServerConstants.ParsedSecretTypes.SharedSecret)\n        {\n            _logger.LogDebug(\"Hashed shared secret validator cannot process {type}\", parsedSecret.Type ?? \"null\");\n            return fail;\n        }\n\n        var sharedSecrets = secrets.Where(s => s.Type == IdentityServerConstants.SecretTypes.SharedSecret);\n        if (!sharedSecrets.Any())\n        {\n            _logger.LogDebug(\"No shared secret configured for client.\");\n            return fail;\n        }\n\n        var sharedSecret = parsedSecret.Credential as string;\n\n        if (parsedSecret.Id.IsMissing() || sharedSecret.IsMissing())\n        {\n            throw new ArgumentException(\"Id or Credential is missing.\");\n        }\n\n        var secretSha256 = sharedSecret.Sha256();\n        var secretSha512 = sharedSecret.Sha512();\n\n        foreach (var secret in sharedSecrets)\n        {\n            var secretDescription = string.IsNullOrEmpty(secret.Description) ? \"no description\" : secret.Description;\n\n            bool isValid = false;\n            byte[] secretBytes;\n\n            try\n            {\n                secretBytes = Convert.FromBase64String(secret.Value);\n            }\n            catch (FormatException)\n            {\n                _logger.LogInformation(\"Secret: {description} uses invalid hashing algorithm.\", secretDescription);\n                return fail;\n            }\n            catch (ArgumentNullException)\n            {\n                _logger.LogInformation(\"Secret: {description} is null.\", secretDescription);\n                return fail;\n            }\n\n            if (secretBytes.Length == 32)\n            {\n                isValid = TimeConstantComparer.IsEqual(secret.Value, secretSha256);\n            }\n            else if (secretBytes.Length == 64)\n            {\n                isValid = TimeConstantComparer.IsEqual(secret.Value, secretSha512);\n            }\n            else\n            {\n                _logger.LogInformation(\"Secret: {description} uses invalid hashing algorithm.\", secretDescription);\n                return fail;\n            }\n\n            if (isValid)\n            {\n                return success;\n            }\n        }\n\n        _logger.LogDebug(\"No matching hashed secret found.\");\n        return fail;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/IntrospectionRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// The introspection request validator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.IIntrospectionRequestValidator\" />\ninternal class IntrospectionRequestValidator : IIntrospectionRequestValidator\n{\n    private readonly ILogger _logger;\n    private readonly ITokenValidator _tokenValidator;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IntrospectionRequestValidator\"/> class.\n    /// </summary>\n    /// <param name=\"tokenValidator\">The token validator.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public IntrospectionRequestValidator(ITokenValidator tokenValidator, ILogger<IntrospectionRequestValidator> logger)\n    {\n        _tokenValidator = tokenValidator;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates the request.\n    /// </summary>\n    /// <param name=\"parameters\">The parameters.</param>\n    /// <param name=\"api\">The API.</param>\n    /// <returns></returns>\n    public async Task<IntrospectionRequestValidationResult> ValidateAsync(NameValueCollection parameters, ApiResource api)\n    {\n        _logger.LogDebug(\"Introspection request validation started.\");\n\n        // retrieve required token\n        var token = parameters.Get(\"token\");\n        if (token == null)\n        {\n            _logger.LogError(\"Token is missing\");\n\n            return new IntrospectionRequestValidationResult\n            {\n                IsError = true,\n                Api = api,\n                Error = \"missing_token\",\n                Parameters = parameters\n            };\n        }\n\n        // validate token\n        var tokenValidationResult = await _tokenValidator.ValidateAccessTokenAsync(token);\n\n        // invalid or unknown token\n        if (tokenValidationResult.IsError)\n        {\n            _logger.LogDebug(\"Token is invalid.\");\n\n            return new IntrospectionRequestValidationResult\n            {\n                IsActive = false,\n                IsError = false,\n                Token = token,\n                Api = api,\n                Parameters = parameters\n            };\n        }\n\n        _logger.LogDebug(\"Introspection request validation successful.\");\n\n        // valid token\n        return new IntrospectionRequestValidationResult\n        {\n            IsActive = true,\n            IsError = false,\n            Token = token,\n            Claims = tokenValidationResult.Claims,\n            Api = api,\n            Parameters = parameters\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/JwtBearerClientAssertionSecretParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Parses a POST body for a JWT bearer client assertion\n/// </summary>\npublic class JwtBearerClientAssertionSecretParser : ISecretParser\n{\n    private readonly IdentityServerOptions _options;\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"JwtBearerClientAssertionSecretParser\"/> class.\n    /// </summary>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public JwtBearerClientAssertionSecretParser(IdentityServerOptions options, ILogger<JwtBearerClientAssertionSecretParser> logger)\n    {\n        _options = options;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Returns the authentication method name that this parser implements\n    /// </summary>\n    /// <value>\n    /// The authentication method.\n    /// </value>\n    public string AuthenticationMethod => OidcConstants.EndpointAuthenticationMethods.PrivateKeyJwt;\n\n    /// <summary>\n    /// Tries to find a JWT client assertion token in the request body that can be used for authentication\n    /// Used for \"private_key_jwt\" client authentication method as defined in http://openid.net/specs/openid-connect-core-1_0.html#ClientAuthentication\n    /// </summary>\n    /// <param name=\"context\">The HTTP context</param>\n    /// <returns>\n    /// A parsed secret\n    /// </returns>\n    public async Task<ParsedSecret> ParseAsync(HttpContext context)\n    {\n        _logger.LogDebug(\"Start parsing for JWT client assertion in post body\");\n\n        if (!context.Request.HasApplicationFormContentType())\n        {\n            _logger.LogDebug(\"Content type is not a form\");\n            return null;\n        }\n\n        var body = await context.Request.ReadFormAsync();\n\n        if (body != null)\n        {\n            var clientAssertionType = body[OidcConstants.TokenRequest.ClientAssertionType].FirstOrDefault();\n            var clientAssertion = body[OidcConstants.TokenRequest.ClientAssertion].FirstOrDefault();\n\n            if (clientAssertion.IsPresent()\n                && clientAssertionType == OidcConstants.ClientAssertionTypes.JwtBearer)\n            {\n                if (clientAssertion.Length > _options.InputLengthRestrictions.Jwt)\n                {\n                    _logger.LogError(\"Client assertion token exceeds maximum length.\");\n                    return null;\n                }\n\n                var clientId = GetClientIdFromToken(clientAssertion);\n                if (!clientId.IsPresent())\n                {\n                    return null;\n                }\n\n                if (clientId.Length > _options.InputLengthRestrictions.ClientId)\n                {\n                    _logger.LogError(\"Client ID exceeds maximum length.\");\n                    return null;\n                }\n\n                var parsedSecret = new ParsedSecret\n                {\n                    Id = clientId,\n                    Credential = clientAssertion,\n                    Type = IdentityServerConstants.ParsedSecretTypes.JwtBearer\n                };\n\n                return parsedSecret;\n            }\n        }\n\n        _logger.LogDebug(\"No JWT client assertion found in post body\");\n        return null;\n    }\n\n    private string GetClientIdFromToken(string token)\n    {\n        try\n        {\n            var jwt = new JwtSecurityToken(token);\n            return jwt.Subject;\n        }\n        catch (Exception e)\n        {\n            _logger.LogWarning(\"Could not parse client assertion: {e}\", e);\n            return null;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/JwtRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates JWT authorization request objects\n/// </summary>\npublic class JwtRequestValidator\n{\n    private readonly string _audienceUri;\n    private readonly IHttpContextAccessor _httpContextAccessor;\n    \n    /// <summary>\n    /// JWT handler\n    /// </summary>\n    protected JwtSecurityTokenHandler Handler = new JwtSecurityTokenHandler\n    {\n        MapInboundClaims = false\n    };\n\n    /// <summary>\n    /// The audience URI to use\n    /// </summary>\n    protected string AudienceUri\n    {\n        get\n        {\n            if (_audienceUri.IsPresent())\n            {\n                return _audienceUri;\n            }\n\n            return _httpContextAccessor.HttpContext.GetIdentityServerIssuerUri();\n        }\n    }\n\n    /// <summary>\n    /// The logger\n    /// </summary>\n    protected readonly ILogger Logger;\n    \n    /// <summary>\n    /// The optione\n    /// </summary>\n    protected readonly IdentityServerOptions Options;\n\n    /// <summary>\n    /// Instantiates an instance of private_key_jwt secret validator\n    /// </summary>\n    public JwtRequestValidator(IHttpContextAccessor contextAccessor, IdentityServerOptions options, ILogger<JwtRequestValidator> logger)\n    {\n        _httpContextAccessor = contextAccessor;\n        \n        Options = options;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Instantiates an instance of private_key_jwt secret validator (used for testing)\n    /// </summary>\n    internal JwtRequestValidator(string audience, ILogger<JwtRequestValidator> logger)\n    {\n        _audienceUri = audience;\n        Logger = logger;\n    }\n\n    /// <summary>\n    /// Validates a JWT request object\n    /// </summary>\n    /// <param name=\"client\">The client</param>\n    /// <param name=\"jwtTokenString\">The JWT</param>\n    /// <returns></returns>\n    public virtual async Task<JwtRequestValidationResult> ValidateAsync(Client client, string jwtTokenString)\n    {\n        if (client == null) throw new ArgumentNullException(nameof(client));\n        if (String.IsNullOrWhiteSpace(jwtTokenString)) throw new ArgumentNullException(nameof(jwtTokenString));\n\n        var fail = new JwtRequestValidationResult { IsError = true };\n\n        List<SecurityKey> trustedKeys;\n        try\n        {\n            trustedKeys = await GetKeysAsync(client);\n        }\n        catch (Exception e)\n        {\n            Logger.LogError(e, \"Could not parse client secrets\");\n            return fail;\n        }\n\n        if (!trustedKeys.Any())\n        {\n            Logger.LogError(\"There are no keys available to validate JWT.\");\n            return fail;\n        }\n\n        JwtSecurityToken jwtSecurityToken;\n        try\n        {\n            jwtSecurityToken = await ValidateJwtAsync(jwtTokenString, trustedKeys, client);\n        }\n        catch (Exception e)\n        {\n            Logger.LogError(e, \"JWT token validation error\");\n            return fail;\n        }\n\n        if (jwtSecurityToken.Payload.ContainsKey(OidcConstants.AuthorizeRequest.Request) ||\n            jwtSecurityToken.Payload.ContainsKey(OidcConstants.AuthorizeRequest.RequestUri))\n        {\n            Logger.LogError(\"JWT payload must not contain request or request_uri\");\n            return fail;\n        }\n\n        var payload = await ProcessPayloadAsync(jwtSecurityToken);\n\n        var result = new JwtRequestValidationResult\n        {\n            IsError = false,\n            Payload = payload\n        };\n\n        Logger.LogDebug(\"JWT request object validation success.\");\n        return result;\n    }\n\n    /// <summary>\n    /// Retrieves keys for a given client\n    /// </summary>\n    /// <param name=\"client\">The client</param>\n    /// <returns></returns>\n    protected virtual Task<List<SecurityKey>> GetKeysAsync(Client client)\n    {\n        return client.ClientSecrets.GetKeysAsync();\n    }\n\n    /// <summary>\n    /// Validates the JWT token\n    /// </summary>\n    /// <param name=\"jwtTokenString\">JWT as a string</param>\n    /// <param name=\"keys\">The keys</param>\n    /// <param name=\"client\">The client</param>\n    /// <returns></returns>\n    protected virtual Task<JwtSecurityToken> ValidateJwtAsync(string jwtTokenString, IEnumerable<SecurityKey> keys, Client client)\n    {\n        var tokenValidationParameters = new TokenValidationParameters\n        {\n            IssuerSigningKeys = keys,\n            ValidateIssuerSigningKey = true,\n\n            ValidIssuer = client.ClientId,\n            ValidateIssuer = true,\n\n            ValidAudience = AudienceUri,\n            ValidateAudience = true,\n\n            RequireSignedTokens = true,\n            RequireExpirationTime = true\n        };\n\n        if (Options.StrictJarValidation)\n        {\n            tokenValidationParameters.ValidTypes = new[] { JwtClaimTypes.JwtTypes.AuthorizationRequest };\n        }\n\n        Handler.ValidateToken(jwtTokenString, tokenValidationParameters, out var token);\n        \n        return Task.FromResult((JwtSecurityToken)token);\n    }\n\n    /// <summary>\n    /// Processes the JWT contents\n    /// </summary>\n    /// <param name=\"token\">The JWT token</param>\n    /// <returns></returns>\n    protected virtual Task<Dictionary<string, string>> ProcessPayloadAsync(JwtSecurityToken token)\n    {\n        // filter JWT validation values\n        var payload = new Dictionary<string, string>();\n        foreach (var key in token.Payload.Keys)\n        {\n            if (!Constants.Filters.JwtRequestClaimTypesFilter.Contains(key))\n            {\n                var value = token.Payload[key];\n\n                switch (value)\n                {\n                    case string s:\n                        payload.Add(key, s);\n                        break;\n                    case JObject jobj:\n                        payload.Add(key, jobj.ToString(Formatting.None));\n                        break;\n                    case JArray jarr:\n                        payload.Add(key, jarr.ToString(Formatting.None));\n                        break;\n                }\n            }\n        }\n\n        return Task.FromResult(payload);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/MutualTlsSecretParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Parses secret according to MTLS spec\n/// </summary>\npublic class MutualTlsSecretParser : ISecretParser\n{\n    private readonly IdentityServerOptions _options;\n    private readonly ILogger<MutualTlsSecretParser> _logger;\n\n    /// <summary>\n    /// ctor\n    /// </summary>\n    /// <param name=\"options\"></param>\n    /// <param name=\"logger\"></param>\n    public MutualTlsSecretParser(IdentityServerOptions options, ILogger<MutualTlsSecretParser> logger)\n    {\n        _options = options;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Name of authentication method (blank to suppress in discovery since we do special handling)\n    /// </summary>\n    public string AuthenticationMethod => String.Empty;\n\n    /// <summary>\n    /// Parses the HTTP context\n    /// </summary>\n    /// <param name=\"context\"></param>\n    /// <returns></returns>\n    public async Task<ParsedSecret> ParseAsync(HttpContext context)\n    {\n        _logger.LogDebug(\"Start parsing for client id in post body\");\n\n        if (!context.Request.HasApplicationFormContentType())\n        {\n            _logger.LogDebug(\"Content type is not a form\");\n            return null;\n        }\n\n        var body = await context.Request.ReadFormAsync();\n\n        if (body != null)\n        {\n            var id = body[\"client_id\"].FirstOrDefault();\n\n            // client id must be present\n            if (!String.IsNullOrWhiteSpace(id))\n            {\n                if (id.Length > _options.InputLengthRestrictions.ClientId)\n                {\n                    _logger.LogError(\"Client ID exceeds maximum length.\");\n                    return null;\n                }\n                \n                var clientCertificate = await context.Connection.GetClientCertificateAsync();\n                \n                if (clientCertificate is null)\n                {\n                    _logger.LogDebug(\"Client certificate not present\");\n                    return null;\n                }\n                \n                return new ParsedSecret\n                {\n                    Id = id,\n                    Credential = clientCertificate,\n                    Type = IdentityServerConstants.ParsedSecretTypes.X509Certificate\n                };\n            }\n        }\n\n        _logger.LogDebug(\"No post body found\");\n        return null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/NopClientConfigurationValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// No-op client configuration validator (for backwards-compatibility).\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.IClientConfigurationValidator\" />\npublic class NopClientConfigurationValidator : IClientConfigurationValidator\n{\n    /// <summary>\n    /// Determines whether the configuration of a client is valid.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public Task ValidateAsync(ClientConfigurationValidationContext context)\n    {\n        context.IsValid = true;\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/NotSupportedResouceOwnerCredentialValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Default resource owner password validator (no implementation == not supported)\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.IResourceOwnerPasswordValidator\" />\npublic class NotSupportedResourceOwnerPasswordValidator : IResourceOwnerPasswordValidator\n{\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"NotSupportedResourceOwnerPasswordValidator\"/> class.\n    /// </summary>\n    /// <param name=\"logger\">The logger.</param>\n    public NotSupportedResourceOwnerPasswordValidator(ILogger<NotSupportedResourceOwnerPasswordValidator> logger)\n    {\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates the resource owner password credential\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    public Task ValidateAsync(ResourceOwnerPasswordValidationContext context)\n    {\n        context.Result = new GrantValidationResult(TokenRequestErrors.UnsupportedGrantType);\n\n        _logger.LogInformation(\"Resource owner password credential type not supported. Configure an IResourceOwnerPasswordValidator.\");\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/PlainTextSharedSecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates a secret stored in plain text\n/// </summary>\npublic class PlainTextSharedSecretValidator : ISecretValidator\n{\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"PlainTextSharedSecretValidator\"/> class.\n    /// </summary>\n    /// <param name=\"logger\">The logger.</param>\n    public PlainTextSharedSecretValidator(ILogger<PlainTextSharedSecretValidator> logger)\n    {\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates a secret\n    /// </summary>\n    /// <param name=\"secrets\">The stored secrets.</param>\n    /// <param name=\"parsedSecret\">The received secret.</param>\n    /// <returns>\n    /// A validation result\n    /// </returns>\n    /// <exception cref=\"System.ArgumentException\">id or credential is missing.</exception>\n    public Task<SecretValidationResult> ValidateAsync(IEnumerable<Secret> secrets, ParsedSecret parsedSecret)\n    {\n        var fail = Task.FromResult(new SecretValidationResult { Success = false });\n        var success = Task.FromResult(new SecretValidationResult { Success = true });\n\n        if (parsedSecret.Type != IdentityServerConstants.ParsedSecretTypes.SharedSecret)\n        {\n            _logger.LogError(\"Parsed secret should not be of type: {type}\", parsedSecret.Type ?? \"null\");\n            return fail;\n        }\n\n        var sharedSecrets = secrets.Where(s => s.Type == IdentityServerConstants.SecretTypes.SharedSecret);\n        if (!sharedSecrets.Any())\n        {\n            _logger.LogDebug(\"No shared secret configured for client.\");\n            return fail;\n        }\n\n        var sharedSecret = parsedSecret.Credential as string;\n\n        if (parsedSecret.Id.IsMissing() || sharedSecret.IsMissing())\n        {\n            throw new ArgumentException(\"Id or Credential is missing.\");\n        }\n\n        foreach (var secret in sharedSecrets)\n        {\n            // use time constant string comparison\n            var isValid = TimeConstantComparer.IsEqual(sharedSecret, secret.Value);\n\n            if (isValid)\n            {\n                return success;\n            }\n        }\n\n        _logger.LogDebug(\"No matching plain text secret found.\");\n        return fail;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/PostBodySecretParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Parses a POST body for secrets\n/// </summary>\npublic class PostBodySecretParser : ISecretParser\n{\n    private readonly ILogger _logger;\n    private readonly IdentityServerOptions _options;\n\n    /// <summary>\n    /// Creates the parser with options\n    /// </summary>\n    /// <param name=\"options\">IdentityServer options</param>\n    /// <param name=\"logger\">Logger</param>\n    public PostBodySecretParser(IdentityServerOptions options, ILogger<PostBodySecretParser> logger)\n    {\n        _logger = logger;\n        _options = options;\n    }\n\n    /// <summary>\n    /// Returns the authentication method name that this parser implements\n    /// </summary>\n    /// <value>\n    /// The authentication method.\n    /// </value>\n    public string AuthenticationMethod => OidcConstants.EndpointAuthenticationMethods.PostBody;\n\n    /// <summary>\n    /// Tries to find a secret on the context that can be used for authentication\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns>\n    /// A parsed secret\n    /// </returns>\n    public async Task<ParsedSecret> ParseAsync(HttpContext context)\n    {\n        _logger.LogDebug(\"Start parsing for secret in post body\");\n\n        if (!context.Request.HasApplicationFormContentType())\n        {\n            _logger.LogDebug(\"Content type is not a form\");\n            return null;\n        }\n\n        var body = await context.Request.ReadFormAsync();\n\n        if (body != null)\n        {\n            var id = body[\"client_id\"].FirstOrDefault();\n            var secret = body[\"client_secret\"].FirstOrDefault();\n\n            // client id must be present\n            if (id.IsPresent())\n            {\n                if (id.Length > _options.InputLengthRestrictions.ClientId)\n                {\n                    _logger.LogError(\"Client ID exceeds maximum length.\");\n                    return null;\n                }\n\n                if (secret.IsPresent())\n                {\n                    if (secret.Length > _options.InputLengthRestrictions.ClientSecret)\n                    {\n                        _logger.LogError(\"Client secret exceeds maximum length.\");\n                        return null;\n                    }\n\n                    return new ParsedSecret\n                    {\n                        Id = id,\n                        Credential = secret,\n                        Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n                    };\n                }\n                else\n                {\n                    // client secret is optional\n                    _logger.LogDebug(\"client id without secret found\");\n\n                    return new ParsedSecret\n                    {\n                        Id = id,\n                        Type = IdentityServerConstants.ParsedSecretTypes.NoSecret\n                    };\n                }\n            }\n        }\n\n        _logger.LogDebug(\"No secret in post body found\");\n        return null;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/PrivateKeyJwtSecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates a secret based on RS256 signed JWT token\n/// </summary>\npublic class PrivateKeyJwtSecretValidator : ISecretValidator\n{\n    private readonly IHttpContextAccessor _contextAccessor;\n    private readonly IReplayCache _replayCache;\n    private readonly ILogger _logger;\n\n    private const string Purpose = nameof(PrivateKeyJwtSecretValidator);\n    \n    /// <summary>\n    /// Instantiates an instance of private_key_jwt secret validator\n    /// </summary>\n    public PrivateKeyJwtSecretValidator(IHttpContextAccessor contextAccessor, IReplayCache replayCache, ILogger<PrivateKeyJwtSecretValidator> logger)\n    {\n        _contextAccessor = contextAccessor;\n        _replayCache = replayCache;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates a secret\n    /// </summary>\n    /// <param name=\"secrets\">The stored secrets.</param>\n    /// <param name=\"parsedSecret\">The received secret.</param>\n    /// <returns>\n    /// A validation result\n    /// </returns>\n    /// <exception cref=\"System.ArgumentException\">ParsedSecret.Credential is not a JWT token</exception>\n    public async Task<SecretValidationResult> ValidateAsync(IEnumerable<Secret> secrets, ParsedSecret parsedSecret)\n    {\n        var fail = new SecretValidationResult { Success = false };\n        var success = new SecretValidationResult { Success = true };\n\n        if (parsedSecret.Type != IdentityServerConstants.ParsedSecretTypes.JwtBearer)\n        {\n            return fail;\n        }\n\n        if (!(parsedSecret.Credential is string jwtTokenString))\n        {\n            _logger.LogError(\"ParsedSecret.Credential is not a string.\");\n            return fail;\n        }\n\n        List<SecurityKey> trustedKeys;\n        try\n        {\n            trustedKeys = await secrets.GetKeysAsync();\n        }\n        catch (Exception e)\n        {\n            _logger.LogError(e, \"Could not parse secrets\");\n            return fail;\n        }\n\n        if (!trustedKeys.Any())\n        {\n            _logger.LogError(\"There are no keys available to validate client assertion.\");\n            return fail;\n        }\n\n        var validAudiences = new[]\n        {\n            // issuer URI (tbd)\n            //_contextAccessor.HttpContext.GetIdentityServerIssuerUri(),\n            \n            // token endpoint URL\n            string.Concat(_contextAccessor.HttpContext.GetIdentityServerIssuerUri().EnsureTrailingSlash(),\n                Constants.ProtocolRoutePaths.Token)\n        };\n        \n        var tokenValidationParameters = new TokenValidationParameters\n        {\n            IssuerSigningKeys = trustedKeys,\n            ValidateIssuerSigningKey = true,\n\n            ValidIssuer = parsedSecret.Id,\n            ValidateIssuer = true,\n\n            ValidAudiences = validAudiences,\n            ValidateAudience = true,\n\n            RequireSignedTokens = true,\n            RequireExpirationTime = true,\n            \n            ClockSkew = TimeSpan.FromMinutes(5)\n        };\n        try\n        {\n            var handler = new JwtSecurityTokenHandler();\n            handler.ValidateToken(jwtTokenString, tokenValidationParameters, out var token);\n\n            var jwtToken = (JwtSecurityToken)token;\n            if (jwtToken.Subject != jwtToken.Issuer)\n            {\n                _logger.LogError(\"Both 'sub' and 'iss' in the client assertion token must have a value of client_id.\");\n                return fail;\n            }\n            \n            var exp = jwtToken.Payload.Exp;\n            if (!exp.HasValue)\n            {\n                _logger.LogError(\"exp is missing.\");\n                return fail;\n            }\n            \n            var jti = jwtToken.Payload.Jti;\n            if (jti.IsMissing())\n            {\n                _logger.LogError(\"jti is missing.\");\n                return fail;\n            }\n\n            if (await _replayCache.ExistsAsync(Purpose, jti))\n            {\n                _logger.LogError(\"jti is found in replay cache. Possible replay attack.\");\n                return fail;\n            }\n            else\n            {\n                await _replayCache.AddAsync(Purpose, jti, DateTimeOffset.FromUnixTimeSeconds(exp.Value).AddMinutes(5));\n            }\n\n            return success;\n        }\n        catch (Exception e)\n        {\n            _logger.LogError(e, \"JWT token validation error\");\n            return fail;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/ResponseTypeEqualityComparer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Compares resource_type strings, where the order of space-delimited values is insignificant.\n/// </summary>\n/// <remarks>\n/// <para>\n/// This is to handle the fact that the order of multi-valued response_type lists is\n/// insignificant, per the <see href=\"https://tools.ietf.org/html/rfc6749#section-3.1.1\">OAuth2 spec</see>\n/// and the \n/// (<see href=\"http://openid.net/specs/oauth-v2-multiple-response-types-1_0-03.html#terminology\">OAuth \n/// 2.0 Multiple Response Type Encoding Practices draft </see>).\n/// </para>\n/// </remarks>\npublic class ResponseTypeEqualityComparer : IEqualityComparer<string>\n{\n    /// <summary>\n    /// Determines whether the specified values are equal.\n    /// </summary>\n    /// <param name=\"x\">The first string to compare.</param>\n    /// <param name=\"y\">The second string to compare.</param>\n    /// <returns>true if the specified values are equal; otherwise, false.</returns>\n    public bool Equals(string x, string y)\n    {\n        if (x == y) return true;\n\n        if (x == null || y == null) return false;\n\n        if (x.Length != y.Length) return false;\n\n        var xValues = x.Split(' ');\n        var yValues = y.Split(' ');\n\n        if (xValues.Length != yValues.Length)\n        {\n            return false;\n        }\n\n        Array.Sort(xValues);\n        Array.Sort(yValues);\n\n        for (var i = 0; i < xValues.Length; i++)\n        {\n            if (xValues[i] != yValues[i])\n            {\n                return false;\n            }\n        }\n\n        return true;\n    }\n\n    /// <summary>\n    /// Returns a hash code for the value.\n    /// </summary>\n    /// <param name=\"value\">The value for which a hash code is to be returned.</param>\n    /// <returns>A hash code for the value, suitable for use in hashing algorithms and data structures like a hash table.</returns>\n    public int GetHashCode(string value)\n    {\n        if (value == null) return 0;\n\n        var values = value.Split(' ');\n        if (values.Length == 1)\n        {\n            // Only one value, so just spit out the hash code of the whole string\n            return value.GetHashCode();\n        }\n\n        Array.Sort(values);\n\n        // Using Skeet's answer here: http://stackoverflow.com/a/7244729/208990\n        // Licensed under Creative Commons CC-BY-SA from SO: https://stackoverflow.com/legal/terms-of-service#licensing\n        // Creative Commons CC-BY-SA https://creativecommons.org/licenses/by-sa/4.0/\n        var hash = 17;\n        foreach (var element in values)\n        {\n            // changed to use StringComparer.Ordinal, rather than StringComparer.InvariantCulture\n            hash = hash * 31 + StringComparer.Ordinal.GetHashCode(element);\n        }\n        return hash;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/SecretParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Uses the registered secret parsers to parse a secret on the current request\n/// </summary>\npublic class SecretParser : ISecretsListParser\n{\n    private readonly ILogger _logger;\n    private readonly IEnumerable<ISecretParser> _parsers;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"SecretParser\"/> class.\n    /// </summary>\n    /// <param name=\"parsers\">The parsers.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public SecretParser(IEnumerable<ISecretParser> parsers, ILogger<ISecretsListParser> logger)\n    {\n        _parsers = parsers;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Checks the context to find a secret.\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns></returns>\n    public async Task<ParsedSecret> ParseAsync(HttpContext context)\n    {\n        // see if a registered parser finds a secret on the request\n        ParsedSecret bestSecret = null;\n        foreach (var parser in _parsers)\n        {\n            var parsedSecret = await parser.ParseAsync(context);\n            if (parsedSecret != null)\n            {\n                _logger.LogDebug(\"Parser found secret: {type}\", parser.GetType().Name);\n\n                bestSecret = parsedSecret;\n\n                if (parsedSecret.Type != IdentityServerConstants.ParsedSecretTypes.NoSecret)\n                {\n                    break;\n                }\n            }\n        }\n\n        if (bestSecret != null)\n        {\n            _logger.LogDebug(\"Secret id found: {id}\", Ioc.Sanitizer.Log.Sanitize(bestSecret.Id));\n            return bestSecret;\n        }\n\n        _logger.LogDebug(\"Parser found no secret\");\n        return null;\n    }\n\n    /// <summary>\n    /// Gets all available authentication methods.\n    /// </summary>\n    /// <returns></returns>\n    public IEnumerable<string> GetAvailableAuthenticationMethods()\n    {\n        return _parsers.Select(p => p.AuthenticationMethod).Where(p => !String.IsNullOrWhiteSpace(p));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/SecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates secrets using the registered validators\n/// </summary>\npublic class SecretValidator : ISecretsListValidator\n{\n    private readonly ILogger _logger;\n    private readonly IEnumerable<ISecretValidator> _validators;\n    private readonly ISystemClock _clock;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"SecretValidator\"/> class.\n    /// </summary>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"validators\">The validators.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public SecretValidator(ISystemClock clock, IEnumerable<ISecretValidator> validators, ILogger<ISecretsListValidator> logger)\n    {\n        _clock = clock;\n        _validators = validators;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates the secret.\n    /// </summary>\n    /// <param name=\"parsedSecret\">The parsed secret.</param>\n    /// <param name=\"secrets\">The secrets.</param>\n    /// <returns></returns>\n    public async Task<SecretValidationResult> ValidateAsync(IEnumerable<Secret> secrets, ParsedSecret parsedSecret)\n    {\n        var secretsArray = secrets as Secret[] ?? secrets.ToArray();\n\n        var expiredSecrets = secretsArray.Where(s => s.Expiration.HasExpired(_clock.UtcNow.UtcDateTime)).ToList();\n        if (expiredSecrets.Any())\n        {\n            expiredSecrets.ForEach(\n                ex => _logger.LogInformation(\"Secret [{description}] is expired\", ex.Description ?? \"no description\"));\n        }\n\n        var currentSecrets = secretsArray.Where(s => !s.Expiration.HasExpired(_clock.UtcNow.UtcDateTime)).ToArray();\n\n        // see if a registered validator can validate the secret\n        foreach (var validator in _validators)\n        {\n            var secretValidationResult = await validator.ValidateAsync(currentSecrets, parsedSecret);\n\n            if (secretValidationResult.Success)\n            {\n                _logger.LogDebug(\"Secret validator success: {0}\", validator.GetType().Name);\n                return secretValidationResult;\n            }\n        }\n\n        _logger.LogDebug(\"Secret validators could not validate secret\");\n        return new SecretValidationResult { Success = false };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/StrictRedirectUriValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Default implementation of redirect URI validator. Validates the URIs against\n/// the client's configured URIs.\n/// </summary>\npublic class StrictRedirectUriValidator : IRedirectUriValidator\n{\n    /// <summary>\n    /// Checks if a given URI string is in a collection of strings (using ordinal ignore case comparison)\n    /// </summary>\n    /// <param name=\"uris\">The uris.</param>\n    /// <param name=\"requestedUri\">The requested URI.</param>\n    /// <returns></returns>\n    protected bool StringCollectionContainsString(IEnumerable<string> uris, string requestedUri)\n    {\n        if (uris.EnumerableIsNullOrEmpty()) return false;\n\n        return uris.Contains(requestedUri, StringComparer.OrdinalIgnoreCase);\n    }\n\n    /// <summary>\n    /// Determines whether a redirect URI is valid for a client.\n    /// </summary>\n    /// <param name=\"requestedUri\">The requested URI.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns>\n    ///   <c>true</c> is the URI is valid; <c>false</c> otherwise.\n    /// </returns>\n    public virtual Task<bool> IsRedirectUriValidAsync(string requestedUri, Client client)\n    {\n        return Task.FromResult(StringCollectionContainsString(client.RedirectUris, requestedUri));\n    }\n\n    /// <summary>\n    /// Determines whether a post logout URI is valid for a client.\n    /// </summary>\n    /// <param name=\"requestedUri\">The requested URI.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns>\n    ///   <c>true</c> is the URI is valid; <c>false</c> otherwise.\n    /// </returns>\n    public virtual Task<bool> IsPostLogoutRedirectUriValidAsync(string requestedUri, Client client)\n    {\n        return Task.FromResult(StringCollectionContainsString(client.PostLogoutRedirectUris, requestedUri));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/StrictRedirectUriValidatorAppAuth.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Implementation of strict redirect URI validator that allows a random port if 127.0.0.1 is used.\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.StrictRedirectUriValidator\" />\npublic class StrictRedirectUriValidatorAppAuth : StrictRedirectUriValidator\n{\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"StrictRedirectUriValidatorAppAuth\"/> class.\n    /// </summary>\n    /// <param name=\"logger\">The logger.</param>\n    public StrictRedirectUriValidatorAppAuth(ILogger<StrictRedirectUriValidatorAppAuth> logger)\n    {\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Determines whether a redirect URI is valid for a client.\n    /// </summary>\n    /// <param name=\"requestedUri\">The requested URI.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns>\n    /// <c>true</c> is the URI is valid; <c>false</c> otherwise.\n    /// </returns>\n    public override async Task<bool> IsRedirectUriValidAsync(string requestedUri, Client client)\n    {\n        var isAllowed = await base.IsRedirectUriValidAsync(requestedUri, client);\n        if (isAllowed) return isAllowed;\n\n        // since this is appauth specific, we can require pkce\n        if (client.RequirePkce && client.RedirectUris.Contains(\"http://127.0.0.1\")) return IsLoopback(requestedUri);\n\n        return false;\n    }\n\n    /// <summary>\n    /// Determines whether a post logout URI is valid for a client.\n    /// </summary>\n    /// <param name=\"requestedUri\">The requested URI.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns>\n    /// <c>true</c> is the URI is valid; <c>false</c> otherwise.\n    /// </returns>\n    public override async Task<bool> IsPostLogoutRedirectUriValidAsync(string requestedUri, Client client)\n    {\n        var isAllowed = await base.IsPostLogoutRedirectUriValidAsync(requestedUri, client);\n        if (isAllowed) return isAllowed;\n\n        // since this is appauth specific, we can require pkce\n        if (client.RequirePkce && client.RedirectUris.Contains(\"http://127.0.0.1\")) return IsLoopback(requestedUri);\n\n        return false;\n    }\n\n    /// <summary>\n    /// Check if <paramref name=\"requestedUri\"/> is of the form http://127.0.0.1:port/path.\n    /// </summary>\n    /// <param name=\"requestedUri\">The requested URI.</param>\n    /// <returns>\n    /// <c>true</c> if <paramref name=\"requestedUri\"/> is a valid Loopback URI; <c>false</c> otherwise.\n    /// </returns>\n    internal bool IsLoopback(string requestedUri)\n    {\n        _logger.LogDebug(\"Checking for 127.0.0.1 redirect URI\");\n\n        // Validate that the requestedUri is not null or empty.\n        if (string.IsNullOrEmpty(requestedUri))\n        {\n            _logger.LogDebug(\"'requestedUri' is null or empty\");\n            return false;\n        }\n\n        var parts = requestedUri.Split(':');\n\n        if (parts.Length != 3)\n        {\n            _logger.LogDebug(\"invalid format - http://127.0.0.1:port is required.\");\n            return false;\n        }\n\n        if (!string.Equals(parts[0], \"http\", StringComparison.Ordinal) ||\n            !string.Equals(parts[1], \"//127.0.0.1\", StringComparison.Ordinal))\n        {\n            _logger.LogDebug(\"invalid format - http://127.0.0.1:port is required.\");\n            return false;\n        }\n\n        string portAsString;\n        int indexOfPathSeparator = parts[2].IndexOfAny(new[] { '/', '?', '#' });\n        if (indexOfPathSeparator > 0)\n        {\n            portAsString = parts[2].Substring(0, indexOfPathSeparator);\n        }\n        else\n        {\n            portAsString = parts[2];\n        }\n\n        // Valid port range is 0 through 65535.\n        if (int.TryParse(portAsString, out var port))\n        {\n            if (port >= 0 && port < 65536)\n            {\n                return true;\n            }\n        }\n\n        _logger.LogDebug(\"invalid port\");\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/TokenRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\ninternal class TokenRequestValidator : ITokenRequestValidator\n{\n    private readonly IdentityServerOptions _options;\n    private readonly IAuthorizationCodeStore _authorizationCodeStore;\n    private readonly ExtensionGrantValidator _extensionGrantValidator;\n    private readonly ICustomTokenRequestValidator _customRequestValidator;\n    private readonly IResourceValidator _resourceValidator;\n    private readonly IResourceStore _resourceStore;\n    private readonly ITokenValidator _tokenValidator;\n    private readonly IRefreshTokenService _refreshTokenService;\n    private readonly IEventService _events;\n    private readonly IResourceOwnerPasswordValidator _resourceOwnerValidator;\n    private readonly IProfileService _profile;\n    private readonly IDeviceCodeValidator _deviceCodeValidator;\n    private readonly ISystemClock _clock;\n    private readonly ILogger _logger;\n\n    private ValidatedTokenRequest _validatedRequest;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenRequestValidator\" /> class.\n    /// </summary>\n    /// <param name=\"options\">The options.</param>\n    /// <param name=\"authorizationCodeStore\">The authorization code store.</param>\n    /// <param name=\"resourceOwnerValidator\">The resource owner validator.</param>\n    /// <param name=\"profile\">The profile.</param>\n    /// <param name=\"deviceCodeValidator\">The device code validator.</param>\n    /// <param name=\"extensionGrantValidator\">The extension grant validator.</param>\n    /// <param name=\"customRequestValidator\">The custom request validator.</param>\n    /// <param name=\"resourceValidator\">The resource validator.</param>\n    /// <param name=\"resourceStore\">The resource store.</param>\n    /// <param name=\"tokenValidator\">The token validator.</param>\n    /// <param name=\"refreshTokenService\"></param>\n    /// <param name=\"events\">The events.</param>\n    /// <param name=\"clock\">The clock.</param>\n    /// <param name=\"logger\">The logger.</param>\n    public TokenRequestValidator(IdentityServerOptions options, \n        IAuthorizationCodeStore authorizationCodeStore, \n        IResourceOwnerPasswordValidator resourceOwnerValidator, \n        IProfileService profile, \n        IDeviceCodeValidator deviceCodeValidator, \n        ExtensionGrantValidator extensionGrantValidator, \n        ICustomTokenRequestValidator customRequestValidator,\n        IResourceValidator resourceValidator,\n        IResourceStore resourceStore,\n        ITokenValidator tokenValidator, \n        IRefreshTokenService refreshTokenService,\n        IEventService events, \n        ISystemClock clock, \n        ILogger<TokenRequestValidator> logger)\n    {\n        _logger = logger;\n        _options = options;\n        _clock = clock;\n        _authorizationCodeStore = authorizationCodeStore;\n        _resourceOwnerValidator = resourceOwnerValidator;\n        _profile = profile;\n        _deviceCodeValidator = deviceCodeValidator;\n        _extensionGrantValidator = extensionGrantValidator;\n        _customRequestValidator = customRequestValidator;\n        _resourceValidator = resourceValidator;\n        _resourceStore = resourceStore;\n        _tokenValidator = tokenValidator;\n        _refreshTokenService = refreshTokenService;\n        _events = events;\n    }\n\n    /// <summary>\n    /// Validates the request.\n    /// </summary>\n    /// <param name=\"parameters\">The parameters.</param>\n    /// <param name=\"clientValidationResult\">The client validation result.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.ArgumentNullException\">\n    /// parameters\n    /// or\n    /// client\n    /// </exception>\n    public async Task<TokenRequestValidationResult> ValidateRequestAsync(NameValueCollection parameters, ClientSecretValidationResult clientValidationResult)\n    {\n        _logger.LogDebug(\"Start token request validation\");\n\n        _validatedRequest = new ValidatedTokenRequest\n        {\n            Raw = parameters ?? throw new ArgumentNullException(nameof(parameters)),\n            Options = _options\n        };\n\n        if (clientValidationResult == null) throw new ArgumentNullException(nameof(clientValidationResult));\n\n        _validatedRequest.SetClient(clientValidationResult.Client, clientValidationResult.Secret, clientValidationResult.Confirmation);\n\n        /////////////////////////////////////////////\n        // check client protocol type\n        /////////////////////////////////////////////\n        if (_validatedRequest.Client.ProtocolType != IdentityServerConstants.ProtocolTypes.OpenIdConnect)\n        {\n            LogError(\"Invalid protocol type for client\",\n                new\n                {\n                    clientId = _validatedRequest.Client.ClientId,\n                    expectedProtocolType = IdentityServerConstants.ProtocolTypes.OpenIdConnect,\n                    actualProtocolType = _validatedRequest.Client.ProtocolType\n                });\n\n            return Invalid(OidcConstants.TokenErrors.InvalidClient);\n        }\n\n        /////////////////////////////////////////////\n        // check grant type\n        /////////////////////////////////////////////\n        var grantType = parameters.Get(OidcConstants.TokenRequest.GrantType);\n        if (grantType.IsMissing())\n        {\n            LogError(\"Grant type is missing\");\n            return Invalid(OidcConstants.TokenErrors.UnsupportedGrantType);\n        }\n\n        if (grantType.Length > _options.InputLengthRestrictions.GrantType)\n        {\n            LogError(\"Grant type is too long\");\n            return Invalid(OidcConstants.TokenErrors.UnsupportedGrantType);\n        }\n\n        _validatedRequest.GrantType = grantType;\n\n        switch (grantType)\n        {\n            case OidcConstants.GrantTypes.AuthorizationCode:\n                return await RunValidationAsync(ValidateAuthorizationCodeRequestAsync, parameters);\n            case OidcConstants.GrantTypes.ClientCredentials:\n                return await RunValidationAsync(ValidateClientCredentialsRequestAsync, parameters);\n            case OidcConstants.GrantTypes.Password:\n                return await RunValidationAsync(ValidateResourceOwnerCredentialRequestAsync, parameters);\n            case OidcConstants.GrantTypes.RefreshToken:\n                return await RunValidationAsync(ValidateRefreshTokenRequestAsync, parameters);\n            case OidcConstants.GrantTypes.DeviceCode:\n                return await RunValidationAsync(ValidateDeviceCodeRequestAsync, parameters);\n            default:\n                return await RunValidationAsync(ValidateExtensionGrantRequestAsync, parameters);\n        }\n    }\n\n    private async Task<TokenRequestValidationResult> RunValidationAsync(Func<NameValueCollection, Task<TokenRequestValidationResult>> validationFunc, NameValueCollection parameters)\n    {\n        // run standard validation\n        var result = await validationFunc(parameters);\n        if (result.IsError)\n        {\n            return result;\n        }\n\n        // run custom validation\n        _logger.LogTrace(\"Calling into custom request validator: {type}\", _customRequestValidator.GetType().FullName);\n\n        var customValidationContext = new CustomTokenRequestValidationContext { Result = result };\n        await _customRequestValidator.ValidateAsync(customValidationContext);\n\n        if (customValidationContext.Result.IsError)\n        {\n            if (customValidationContext.Result.Error.IsPresent())\n            {\n                LogError(\"Custom token request validator\", new { error = customValidationContext.Result.Error });\n            }\n            else\n            {\n                LogError(\"Custom token request validator error\");\n            }\n\n            return customValidationContext.Result;\n        }\n\n        LogSuccess();\n        return customValidationContext.Result;\n    }\n\n    private async Task<TokenRequestValidationResult> ValidateAuthorizationCodeRequestAsync(NameValueCollection parameters)\n    {\n        _logger.LogDebug(\"Start validation of authorization code token request\");\n\n        /////////////////////////////////////////////\n        // check if client is authorized for grant type\n        /////////////////////////////////////////////\n        if (!_validatedRequest.Client.AllowedGrantTypes.ToList().Contains(GrantType.AuthorizationCode) &&\n            !_validatedRequest.Client.AllowedGrantTypes.ToList().Contains(GrantType.Hybrid))\n        {\n            LogError(\"Client not authorized for code flow\");\n            return Invalid(OidcConstants.TokenErrors.UnauthorizedClient);\n        }\n\n        /////////////////////////////////////////////\n        // validate authorization code\n        /////////////////////////////////////////////\n        var code = parameters.Get(OidcConstants.TokenRequest.Code);\n        if (code.IsMissing())\n        {\n            LogError(\"Authorization code is missing\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        if (code.Length > _options.InputLengthRestrictions.AuthorizationCode)\n        {\n            LogError(\"Authorization code is too long\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        _validatedRequest.AuthorizationCodeHandle = code;\n\n        var authZcode = await _authorizationCodeStore.GetAuthorizationCodeAsync(code);\n        if (authZcode == null)\n        {\n            LogError(\"Invalid authorization code\", new { code });\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n        \n        /////////////////////////////////////////////\n        // validate client binding\n        /////////////////////////////////////////////\n        if (authZcode.ClientId != _validatedRequest.Client.ClientId)\n        {\n            LogError(\"Client is trying to use a code from a different client\", new { clientId = _validatedRequest.Client.ClientId, codeClient = authZcode.ClientId });\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        // remove code from store\n        // todo: set to consumed in the future?\n        await _authorizationCodeStore.RemoveAuthorizationCodeAsync(code);\n\n        if (authZcode.CreationTime.HasExceeded(authZcode.Lifetime, _clock.UtcNow.UtcDateTime))\n        {\n            LogError(\"Authorization code expired\", new { code });\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        /////////////////////////////////////////////\n        // populate session id\n        /////////////////////////////////////////////\n        if (authZcode.SessionId.IsPresent())\n        {\n            _validatedRequest.SessionId = authZcode.SessionId;\n        }\n\n        /////////////////////////////////////////////\n        // validate code expiration\n        /////////////////////////////////////////////\n        if (authZcode.CreationTime.HasExceeded(_validatedRequest.Client.AuthorizationCodeLifetime, _clock.UtcNow.UtcDateTime))\n        {\n            LogError(\"Authorization code is expired\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        _validatedRequest.AuthorizationCode = authZcode;\n        _validatedRequest.Subject = authZcode.Subject;\n\n        /////////////////////////////////////////////\n        // validate redirect_uri\n        /////////////////////////////////////////////\n        var redirectUri = parameters.Get(OidcConstants.TokenRequest.RedirectUri);\n        if (redirectUri.IsMissing())\n        {\n            LogError(\"Redirect URI is missing\");\n            return Invalid(OidcConstants.TokenErrors.UnauthorizedClient);\n        }\n\n        if (redirectUri.Equals(_validatedRequest.AuthorizationCode.RedirectUri, StringComparison.Ordinal) == false)\n        {\n            LogError(\"Invalid redirect_uri\", new { redirectUri, expectedRedirectUri = _validatedRequest.AuthorizationCode.RedirectUri });\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        /////////////////////////////////////////////\n        // validate scopes are present\n        /////////////////////////////////////////////\n        if (_validatedRequest.AuthorizationCode.RequestedScopes == null ||\n            !_validatedRequest.AuthorizationCode.RequestedScopes.Any())\n        {\n            LogError(\"Authorization code has no associated scopes\");\n            return Invalid(OidcConstants.TokenErrors.InvalidRequest);\n        }\n\n        /////////////////////////////////////////////\n        // validate PKCE parameters\n        /////////////////////////////////////////////\n        var codeVerifier = parameters.Get(OidcConstants.TokenRequest.CodeVerifier);\n        if (_validatedRequest.Client.RequirePkce || _validatedRequest.AuthorizationCode.CodeChallenge.IsPresent())\n        {\n            _logger.LogDebug(\"Client required a proof key for code exchange. Starting PKCE validation\");\n\n            var proofKeyResult = ValidateAuthorizationCodeWithProofKeyParameters(codeVerifier, _validatedRequest.AuthorizationCode);\n            if (proofKeyResult.IsError)\n            {\n                return proofKeyResult;\n            }\n\n            _validatedRequest.CodeVerifier = codeVerifier;\n        }\n        else\n        {\n            if (codeVerifier.IsPresent())\n            {\n                LogError(\"Unexpected code_verifier: {codeVerifier}. This happens when the client is trying to use PKCE, but it is not enabled. Set RequirePkce to true.\", codeVerifier);\n                return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n            }\n        }\n\n        /////////////////////////////////////////////\n        // make sure user is enabled\n        /////////////////////////////////////////////\n        var isActiveCtx = new IsActiveContext(_validatedRequest.AuthorizationCode.Subject, _validatedRequest.Client, IdentityServerConstants.ProfileIsActiveCallers.AuthorizationCodeValidation);\n        await _profile.IsActiveAsync(isActiveCtx);\n\n        if (isActiveCtx.IsActive == false)\n        {\n            LogError(\"User has been disabled\", new { subjectId = _validatedRequest.AuthorizationCode.Subject.GetSubjectId() });\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        _logger.LogDebug(\"Validation of authorization code token request success\");\n\n        return Valid();\n    }\n\n    private async Task<TokenRequestValidationResult> ValidateClientCredentialsRequestAsync(NameValueCollection parameters)\n    {\n        _logger.LogDebug(\"Start client credentials token request validation\");\n\n        /////////////////////////////////////////////\n        // check if client is authorized for grant type\n        /////////////////////////////////////////////\n        if (!_validatedRequest.Client.AllowedGrantTypes.ToList().Contains(GrantType.ClientCredentials))\n        {\n            LogError(\"Client not authorized for client credentials flow, check the AllowedGrantTypes setting\", new { clientId = _validatedRequest.Client.ClientId });\n            return Invalid(OidcConstants.TokenErrors.UnauthorizedClient);\n        }\n\n        /////////////////////////////////////////////\n        // check if client is allowed to request scopes\n        /////////////////////////////////////////////\n        if (!await ValidateRequestedScopesAsync(parameters, ignoreImplicitIdentityScopes: true, ignoreImplicitOfflineAccess: true))\n        {\n            return Invalid(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        if (_validatedRequest.ValidatedResources.Resources.IdentityResources.Any())\n        {\n            LogError(\"Client cannot request OpenID scopes in client credentials flow\", new { clientId = _validatedRequest.Client.ClientId });\n            return Invalid(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        if (_validatedRequest.ValidatedResources.Resources.OfflineAccess)\n        {\n            LogError(\"Client cannot request a refresh token in client credentials flow\", new { clientId = _validatedRequest.Client.ClientId });\n            return Invalid(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        _logger.LogDebug(\"{clientId} credentials token request validation success\", _validatedRequest.Client.ClientId);\n        return Valid();\n    }\n\n    private async Task<TokenRequestValidationResult> ValidateResourceOwnerCredentialRequestAsync(NameValueCollection parameters)\n    {\n        _logger.LogDebug(\"Start resource owner password token request validation\");\n\n        /////////////////////////////////////////////\n        // check if client is authorized for grant type\n        /////////////////////////////////////////////\n        if (!_validatedRequest.Client.AllowedGrantTypes.Contains(GrantType.ResourceOwnerPassword))\n        {\n            LogError(\"Client not authorized for resource owner flow, check the AllowedGrantTypes setting\", new { client_id = _validatedRequest.Client.ClientId });\n            return Invalid(OidcConstants.TokenErrors.UnauthorizedClient);\n        }\n\n        /////////////////////////////////////////////\n        // check if client is allowed to request scopes\n        /////////////////////////////////////////////\n        if (!(await ValidateRequestedScopesAsync(parameters)))\n        {\n            return Invalid(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        /////////////////////////////////////////////\n        // check resource owner credentials\n        /////////////////////////////////////////////\n        var userName = parameters.Get(OidcConstants.TokenRequest.UserName);\n        var password = parameters.Get(OidcConstants.TokenRequest.Password);\n\n        if (userName.IsMissing())\n        {\n            LogError(\"Username is missing\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        if (password.IsMissing())\n        {\n            password = \"\";\n        }\n\n        if (userName.Length > _options.InputLengthRestrictions.UserName ||\n            password.Length > _options.InputLengthRestrictions.Password)\n        {\n            LogError(\"Username or password too long\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        _validatedRequest.UserName = userName;\n\n\n        /////////////////////////////////////////////\n        // authenticate user\n        /////////////////////////////////////////////\n        var resourceOwnerContext = new ResourceOwnerPasswordValidationContext\n        {\n            UserName = userName,\n            Password = password,\n            Request = _validatedRequest\n        };\n        await _resourceOwnerValidator.ValidateAsync(resourceOwnerContext);\n\n        if (resourceOwnerContext.Result.IsError)\n        {\n            // protect against bad validator implementations\n            resourceOwnerContext.Result.Error ??= OidcConstants.TokenErrors.InvalidGrant;\n\n            if (resourceOwnerContext.Result.Error == OidcConstants.TokenErrors.UnsupportedGrantType)\n            {\n                LogError(\"Resource owner password credential grant type not supported\");\n                await RaiseFailedResourceOwnerAuthenticationEventAsync(userName, \"password grant type not supported\", resourceOwnerContext.Request.Client.ClientId);\n\n                return Invalid(OidcConstants.TokenErrors.UnsupportedGrantType, customResponse: resourceOwnerContext.Result.CustomResponse);\n            }\n\n            var errorDescription = \"invalid_username_or_password\";\n\n            if (resourceOwnerContext.Result.ErrorDescription.IsPresent())\n            {\n                errorDescription = resourceOwnerContext.Result.ErrorDescription;\n            }\n\n            LogInformation(\"User authentication failed: \", errorDescription ?? resourceOwnerContext.Result.Error);\n            await RaiseFailedResourceOwnerAuthenticationEventAsync(userName, errorDescription, resourceOwnerContext.Request.Client.ClientId);\n\n            return Invalid(resourceOwnerContext.Result.Error, errorDescription, resourceOwnerContext.Result.CustomResponse);\n        }\n\n        if (resourceOwnerContext.Result.Subject == null)\n        {\n            var error = \"User authentication failed: no principal returned\";\n            LogError(error);\n            await RaiseFailedResourceOwnerAuthenticationEventAsync(userName, error, resourceOwnerContext.Request.Client.ClientId);\n\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        /////////////////////////////////////////////\n        // make sure user is enabled\n        /////////////////////////////////////////////\n        var isActiveCtx = new IsActiveContext(resourceOwnerContext.Result.Subject, _validatedRequest.Client, IdentityServerConstants.ProfileIsActiveCallers.ResourceOwnerValidation);\n        await _profile.IsActiveAsync(isActiveCtx);\n\n        if (isActiveCtx.IsActive == false)\n        {\n            LogError(\"User has been disabled\", new { subjectId = resourceOwnerContext.Result.Subject.GetSubjectId() });\n            await RaiseFailedResourceOwnerAuthenticationEventAsync(userName, \"user is inactive\", resourceOwnerContext.Request.Client.ClientId);\n\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        _validatedRequest.UserName = userName;\n        _validatedRequest.Subject = resourceOwnerContext.Result.Subject;\n\n        await RaiseSuccessfulResourceOwnerAuthenticationEventAsync(userName, resourceOwnerContext.Result.Subject.GetSubjectId(), resourceOwnerContext.Request.Client.ClientId);\n        _logger.LogDebug(\"Resource owner password token request validation success.\");\n        return Valid(resourceOwnerContext.Result.CustomResponse);\n    }\n\n    private async Task<TokenRequestValidationResult> ValidateRefreshTokenRequestAsync(NameValueCollection parameters)\n    {\n        _logger.LogDebug(\"Start validation of refresh token request\");\n\n        var refreshTokenHandle = parameters.Get(OidcConstants.TokenRequest.RefreshToken);\n        if (refreshTokenHandle.IsMissing())\n        {\n            LogError(\"Refresh token is missing\");\n            return Invalid(OidcConstants.TokenErrors.InvalidRequest);\n        }\n\n        if (refreshTokenHandle.Length > _options.InputLengthRestrictions.RefreshToken)\n        {\n            LogError(\"Refresh token too long\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        var result = await _refreshTokenService.ValidateRefreshTokenAsync(refreshTokenHandle, _validatedRequest.Client);\n\n        if (result.IsError)\n        {\n            LogWarning(\"Refresh token validation failed. aborting\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        _validatedRequest.RefreshToken = result.RefreshToken;\n        _validatedRequest.RefreshTokenHandle = refreshTokenHandle;\n        _validatedRequest.Subject = result.RefreshToken.Subject;\n\n        _logger.LogDebug(\"Validation of refresh token request success\");\n        // todo: more logging - similar to TokenValidator before\n        \n        return Valid();\n    }\n\n    private async Task<TokenRequestValidationResult> ValidateDeviceCodeRequestAsync(NameValueCollection parameters)\n    {\n        _logger.LogDebug(\"Start validation of device code request\");\n\n        /////////////////////////////////////////////\n        // check if client is authorized for grant type\n        /////////////////////////////////////////////\n        if (!_validatedRequest.Client.AllowedGrantTypes.ToList().Contains(GrantType.DeviceFlow))\n        {\n            LogError(\"Client not authorized for device flow\");\n            return Invalid(OidcConstants.TokenErrors.UnauthorizedClient);\n        }\n\n        /////////////////////////////////////////////\n        // validate device code parameter\n        /////////////////////////////////////////////\n        var deviceCode = parameters.Get(OidcConstants.TokenRequest.DeviceCode);\n        if (deviceCode.IsMissing())\n        {\n            LogError(\"Device code is missing\");\n            return Invalid(OidcConstants.TokenErrors.InvalidRequest);\n        }\n\n        if (deviceCode.Length > _options.InputLengthRestrictions.DeviceCode)\n        {\n            LogError(\"Device code too long\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        /////////////////////////////////////////////\n        // validate device code\n        /////////////////////////////////////////////\n        var deviceCodeContext = new DeviceCodeValidationContext { DeviceCode = deviceCode, Request = _validatedRequest };\n        await _deviceCodeValidator.ValidateAsync(deviceCodeContext);\n\n        if (deviceCodeContext.Result.IsError) return deviceCodeContext.Result;\n\n        _logger.LogDebug(\"Validation of authorization code token request success\");\n\n        return Valid();\n    }\n\n    private async Task<TokenRequestValidationResult> ValidateExtensionGrantRequestAsync(NameValueCollection parameters)\n    {\n        _logger.LogDebug(\"Start validation of custom grant token request\");\n\n        /////////////////////////////////////////////\n        // check if client is allowed to use grant type\n        /////////////////////////////////////////////\n        if (!_validatedRequest.Client.AllowedGrantTypes.Contains(_validatedRequest.GrantType))\n        {\n            LogError(\"Client does not have the custom grant type in the allowed list, therefore requested grant is not allowed\", new { clientId = _validatedRequest.Client.ClientId });\n            return Invalid(OidcConstants.TokenErrors.UnsupportedGrantType);\n        }\n\n        /////////////////////////////////////////////\n        // check if a validator is registered for the grant type\n        /////////////////////////////////////////////\n        if (!_extensionGrantValidator.GetAvailableGrantTypes().Contains(_validatedRequest.GrantType, StringComparer.Ordinal))\n        {\n            LogError(\"No validator is registered for the grant type\", new { grantType = _validatedRequest.GrantType });\n            return Invalid(OidcConstants.TokenErrors.UnsupportedGrantType);\n        }\n\n        /////////////////////////////////////////////\n        // check if client is allowed to request scopes\n        /////////////////////////////////////////////\n        if (!await ValidateRequestedScopesAsync(parameters))\n        {\n            return Invalid(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        /////////////////////////////////////////////\n        // validate custom grant type\n        /////////////////////////////////////////////\n        var result = await _extensionGrantValidator.ValidateAsync(_validatedRequest);\n\n        if (result == null)\n        {\n            LogError(\"Invalid extension grant\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        if (result.IsError)\n        {\n            if (result.Error.IsPresent())\n            {\n                LogError(\"Invalid extension grant\", new { error = result.Error });\n                return Invalid(result.Error, result.ErrorDescription, result.CustomResponse);\n            }\n            else\n            {\n                LogError(\"Invalid extension grant\");\n                return Invalid(OidcConstants.TokenErrors.InvalidGrant, customResponse: result.CustomResponse);\n            }\n        }\n\n        if (result.Subject != null)\n        {\n            /////////////////////////////////////////////\n            // make sure user is enabled\n            /////////////////////////////////////////////\n            var isActiveCtx = new IsActiveContext(\n                result.Subject,\n                _validatedRequest.Client,\n                IdentityServerConstants.ProfileIsActiveCallers.ExtensionGrantValidation);\n\n            await _profile.IsActiveAsync(isActiveCtx);\n\n            if (isActiveCtx.IsActive == false)\n            {\n                // todo: raise event?\n\n                LogError(\"User has been disabled\", new { subjectId = result.Subject.GetSubjectId() });\n                return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n            }\n\n            _validatedRequest.Subject = result.Subject;\n        }\n\n        _logger.LogDebug(\"Validation of extension grant token request success\");\n        return Valid(result.CustomResponse);\n    }\n\n    // todo: do we want to rework the semantics of these ignore params?\n    // also seems like other workflows other than CC clients can omit scopes?\n    private async Task<bool> ValidateRequestedScopesAsync(NameValueCollection parameters, bool ignoreImplicitIdentityScopes = false, bool ignoreImplicitOfflineAccess = false)\n    {\n        var scopes = parameters.Get(OidcConstants.TokenRequest.Scope);\n        if (scopes.IsMissing())\n        {\n            _logger.LogTrace(\"Client provided no scopes - checking allowed scopes list\");\n\n            if (!_validatedRequest.Client.AllowedScopes.EnumerableIsNullOrEmpty())\n            {\n                // this finds all the scopes the client is allowed to access\n                var clientAllowedScopes = new List<string>();\n                if (!ignoreImplicitIdentityScopes)\n                {\n                    var resources = await _resourceStore.FindResourcesByScopeAsync(_validatedRequest.Client.AllowedScopes);\n                    clientAllowedScopes.AddRange(resources.ToScopeNames().Where(x => _validatedRequest.Client.AllowedScopes.Contains(x)));\n                }\n                else\n                {\n                    var apiScopes = await _resourceStore.FindApiScopesByNameAsync(_validatedRequest.Client.AllowedScopes);\n                    clientAllowedScopes.AddRange(apiScopes.Select(x => x.Name));\n                }\n\n                if (!ignoreImplicitOfflineAccess)\n                {\n                    if (_validatedRequest.Client.AllowOfflineAccess)\n                    {\n                        clientAllowedScopes.Add(IdentityServerConstants.StandardScopes.OfflineAccess);\n                    }\n                }\n\n                scopes = clientAllowedScopes.Distinct().ToSpaceSeparatedString();\n                _logger.LogTrace(\"Defaulting to: {scopes}\", scopes);\n            }\n            else\n            {\n                LogError(\"No allowed scopes configured for client\", new { clientId = _validatedRequest.Client.ClientId });\n                return false;\n            }\n        }\n\n        if (scopes.Length > _options.InputLengthRestrictions.Scope)\n        {\n            LogError(\"Scope parameter exceeds max allowed length\");\n            return false;\n        }\n\n        var requestedScopes = scopes.ParseScopesString();\n\n        if (requestedScopes == null)\n        {\n            LogError(\"No scopes found in request\");\n            return false;\n        }\n\n        var resourceValidationResult = await _resourceValidator.ValidateRequestedResourcesAsync(new ResourceValidationRequest { \n            Client = _validatedRequest.Client,\n            Scopes = requestedScopes\n        });\n\n        if (!resourceValidationResult.Succeeded)\n        {\n            if (resourceValidationResult.InvalidScopes.Any())\n            {\n                LogError(\"Invalid scopes requested\");\n            }\n            else\n            {\n                LogError(\"Invalid scopes for client requested\");\n            }\n\n            return false;\n        }\n\n        _validatedRequest.RequestedScopes = requestedScopes;\n        _validatedRequest.ValidatedResources = resourceValidationResult;\n        \n        return true;\n    }\n\n    private TokenRequestValidationResult ValidateAuthorizationCodeWithProofKeyParameters(string codeVerifier, AuthorizationCode authZcode)\n    {\n        if (authZcode.CodeChallenge.IsMissing() || authZcode.CodeChallengeMethod.IsMissing())\n        {\n            LogError(\"Client is missing code challenge or code challenge method\", new { clientId = _validatedRequest.Client.ClientId });\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        if (codeVerifier.IsMissing())\n        {\n            LogError(\"Missing code_verifier\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        if (codeVerifier.Length < _options.InputLengthRestrictions.CodeVerifierMinLength ||\n            codeVerifier.Length > _options.InputLengthRestrictions.CodeVerifierMaxLength)\n        {\n            LogError(\"code_verifier is too short or too long\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        if (Constants.SupportedCodeChallengeMethods.Contains(authZcode.CodeChallengeMethod) == false)\n        {\n            LogError(\"Unsupported code challenge method\", new { codeChallengeMethod = authZcode.CodeChallengeMethod });\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        if (ValidateCodeVerifierAgainstCodeChallenge(codeVerifier, authZcode.CodeChallenge, authZcode.CodeChallengeMethod) == false)\n        {\n            LogError(\"Transformed code verifier does not match code challenge\");\n            return Invalid(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        return Valid();\n    }\n\n    private bool ValidateCodeVerifierAgainstCodeChallenge(string codeVerifier, string codeChallenge, string codeChallengeMethod)\n    {\n        if (codeChallengeMethod == OidcConstants.CodeChallengeMethods.Plain)\n        {\n            return TimeConstantComparer.IsEqual(codeVerifier.Sha256(), codeChallenge);\n        }\n\n        var codeVerifierBytes = Encoding.ASCII.GetBytes(codeVerifier);\n        var hashedBytes = codeVerifierBytes.Sha256();\n        var transformedCodeVerifier = Base64Url.Encode(hashedBytes);\n\n        return TimeConstantComparer.IsEqual(transformedCodeVerifier.Sha256(), codeChallenge);\n    }\n\n    private TokenRequestValidationResult Valid(Dictionary<string, object> customResponse = null)\n    {\n        return new TokenRequestValidationResult(_validatedRequest, customResponse);\n    }\n\n    private TokenRequestValidationResult Invalid(string error, string errorDescription = null, Dictionary<string, object> customResponse = null)\n    {\n        return new TokenRequestValidationResult(_validatedRequest, error, errorDescription, customResponse);\n    }\n\n    private void LogError(string message = null, object values = null)\n    {\n        LogWithRequestDetails(LogLevel.Error, message, values);\n    }\n\n    private void LogWarning(string message = null, object values = null)\n    {\n        LogWithRequestDetails(LogLevel.Warning, message, values);\n    }\n\n    private void LogInformation(string message = null, object values = null)\n    {\n        LogWithRequestDetails(LogLevel.Information, message, values);\n    }\n\n    private void LogWithRequestDetails(LogLevel logLevel, string message = null, object values = null)\n    {\n        var details = new TokenRequestValidationLog(_validatedRequest, _options.Logging.TokenRequestSensitiveValuesFilter);\n\n        if (message.IsPresent())\n        {\n            try\n            {\n                if (values == null)\n                {\n                    _logger.Log(logLevel, message + \", {@details}\", details);\n                }\n                else\n                {\n                    _logger.Log(logLevel, message + \"{@values}, details: {@details}\", values, details);\n                }\n\n            }\n            catch (Exception ex)\n            {\n                _logger.LogError(\"Error logging {exception}, request details: {@details}\", ex.Message, details);\n            }\n        }\n        else\n        {\n            _logger.Log(logLevel, \"{@details}\", details);\n        }\n    }\n\n    private void LogSuccess()\n    {\n        LogWithRequestDetails(LogLevel.Information, \"Token request validation success\");\n    }\n\n    private Task RaiseSuccessfulResourceOwnerAuthenticationEventAsync(string userName, string subjectId, string clientId)\n    {\n        return _events.RaiseAsync(new UserLoginSuccessEvent(userName, subjectId, null, interactive: false, clientId));\n    }\n\n    private Task RaiseFailedResourceOwnerAuthenticationEventAsync(string userName, string error, string clientId)\n    {\n        return _events.RaiseAsync(new UserLoginFailureEvent(userName, error, interactive: false, clientId: clientId));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/TokenRevocationRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// The token revocation request validator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.ITokenRevocationRequestValidator\" />\ninternal class TokenRevocationRequestValidator : ITokenRevocationRequestValidator\n{\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenRevocationRequestValidator\"/> class.\n    /// </summary>\n    /// <param name=\"logger\">The logger.</param>\n    public TokenRevocationRequestValidator(ILogger<TokenRevocationRequestValidator> logger)\n    {\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates the request.\n    /// </summary>\n    /// <param name=\"parameters\">The parameters.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.ArgumentNullException\">\n    /// parameters\n    /// or\n    /// client\n    /// </exception>\n    public Task<TokenRevocationRequestValidationResult> ValidateRequestAsync(NameValueCollection parameters, Client client)\n    {\n        _logger.LogTrace(\"ValidateRequestAsync called\");\n\n        if (parameters == null)\n        {\n            _logger.LogError(\"no parameters passed\");\n            throw new ArgumentNullException(nameof(parameters));\n        }\n\n        if (client == null)\n        {\n            _logger.LogError(\"no client passed\");\n            throw new ArgumentNullException(nameof(client));\n        }\n\n        ////////////////////////////\n        // make sure token is present\n        ///////////////////////////\n        var token = parameters.Get(\"token\");\n        if (token.IsMissing())\n        {\n            _logger.LogError(\"No token found in request\");\n            return Task.FromResult(new TokenRevocationRequestValidationResult\n            {\n                IsError = true,\n                Error = OidcConstants.TokenErrors.InvalidRequest\n            });\n        }\n\n        var result = new TokenRevocationRequestValidationResult\n        {\n            IsError = false,\n            Token = token,\n            Client = client\n        };\n\n        ////////////////////////////\n        // check token type hint\n        ///////////////////////////\n        var hint = parameters.Get(\"token_type_hint\");\n        if (hint.IsPresent())\n        {\n            if (Constants.SupportedTokenTypeHints.Contains(hint))\n            {\n                _logger.LogDebug(\"Token type hint found in request: {tokenTypeHint}\", hint);\n                result.TokenTypeHint = hint;\n            }\n            else\n            {\n                _logger.LogError(\"Invalid token type hint: {tokenTypeHint}\", hint);\n                result.IsError = true;\n                result.Error = Constants.RevocationErrors.UnsupportedTokenType;\n            }\n        }\n\n        _logger.LogDebug(\"ValidateRequestAsync result: {validateRequestResult}\", result);\n\n        return Task.FromResult(result);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/TokenValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer8.Validation;\n\ninternal class TokenValidator : ITokenValidator\n{\n    private readonly ILogger _logger;\n    private readonly IdentityServerOptions _options;\n    private readonly IHttpContextAccessor _context;\n    private readonly IReferenceTokenStore _referenceTokenStore;\n    private readonly ICustomTokenValidator _customValidator;\n    private readonly IClientStore _clients;\n    private readonly IProfileService _profile;\n    private readonly IKeyMaterialService _keys;\n    private readonly ISystemClock _clock;\n    private readonly TokenValidationLog _log;\n\n    public TokenValidator(\n        IdentityServerOptions options,\n        IHttpContextAccessor context,\n        IClientStore clients,\n        IProfileService profile,\n        IReferenceTokenStore referenceTokenStore,\n        IRefreshTokenStore refreshTokenStore,\n        ICustomTokenValidator customValidator,\n        IKeyMaterialService keys,\n        ISystemClock clock,\n        ILogger<TokenValidator> logger)\n    {\n        _options = options;\n        _context = context;\n        _clients = clients;\n        _profile = profile;\n        _referenceTokenStore = referenceTokenStore;\n        _customValidator = customValidator;\n        _keys = keys;\n        _clock = clock;\n        _logger = logger;\n\n        _log = new TokenValidationLog();\n    }\n\n    public async Task<TokenValidationResult> ValidateIdentityTokenAsync(string token, string clientId = null, bool validateLifetime = true)\n    {\n        _logger.LogDebug(\"Start identity token validation\");\n\n        if (token.Length > _options.InputLengthRestrictions.Jwt)\n        {\n            _logger.LogError(\"JWT too long\");\n            return Invalid(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        if (clientId.IsMissing())\n        {\n            clientId = GetClientIdFromJwt(token);\n\n            if (clientId.IsMissing())\n            {\n                _logger.LogError(\"No clientId supplied, can't find id in identity token.\");\n                return Invalid(OidcConstants.ProtectedResourceErrors.InvalidToken);\n            }\n        }\n\n        _log.ClientId = clientId;\n        _log.ValidateLifetime = validateLifetime;\n\n        var client = await _clients.FindEnabledClientByIdAsync(clientId);\n        if (client == null)\n        {\n            _logger.LogError(\"Unknown or disabled client: {clientId}.\", clientId);\n            return Invalid(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        _log.ClientName = client.ClientName;\n        _logger.LogDebug(\"Client found: {clientId} / {clientName}\", client.ClientId, client.ClientName);\n\n        var keys = await _keys.GetValidationKeysAsync();\n        var result = await ValidateJwtAsync(token, keys, audience: clientId, validateLifetime: validateLifetime);\n\n        result.Client = client;\n\n        if (result.IsError)\n        {\n            LogError(\"Error validating JWT\");\n            return result;\n        }\n\n        _logger.LogDebug(\"Calling into custom token validator: {type}\", _customValidator.GetType().FullName);\n        var customResult = await _customValidator.ValidateIdentityTokenAsync(result);\n\n        if (customResult.IsError)\n        {\n            LogError(\"Custom validator failed: \" + (customResult.Error ?? \"unknown\"));\n            return customResult;\n        }\n\n        _log.Claims = customResult.Claims.ToClaimsDictionary();\n\n        LogSuccess();\n        return customResult;\n    }\n\n    public async Task<TokenValidationResult> ValidateAccessTokenAsync(string token, string expectedScope = null)\n    {\n        _logger.LogTrace(\"Start access token validation\");\n\n        _log.ExpectedScope = expectedScope;\n        _log.ValidateLifetime = true;\n\n        TokenValidationResult result;\n\n        if (token.Contains(\".\"))\n        {\n            if (token.Length > _options.InputLengthRestrictions.Jwt)\n            {\n                _logger.LogError(\"JWT too long\");\n\n                return new TokenValidationResult\n                {\n                    IsError = true,\n                    Error = OidcConstants.ProtectedResourceErrors.InvalidToken,\n                    ErrorDescription = \"Token too long\"\n                };\n            }\n\n            _log.AccessTokenType = AccessTokenType.Jwt.ToString();\n            result = await ValidateJwtAsync(\n                token,\n                await _keys.GetValidationKeysAsync());\n        }\n        else\n        {\n            if (token.Length > _options.InputLengthRestrictions.TokenHandle)\n            {\n                _logger.LogError(\"token handle too long\");\n\n                return new TokenValidationResult\n                {\n                    IsError = true,\n                    Error = OidcConstants.ProtectedResourceErrors.InvalidToken,\n                    ErrorDescription = \"Token too long\"\n                };\n            }\n\n            _log.AccessTokenType = AccessTokenType.Reference.ToString();\n            result = await ValidateReferenceAccessTokenAsync(token);\n        }\n\n        _log.Claims = result.Claims.ToClaimsDictionary();\n\n        if (result.IsError)\n        {\n            return result;\n        }\n\n        // make sure client is still active (if client_id claim is present)\n        var clientClaim = result.Claims.FirstOrDefault(c => c.Type == JwtClaimTypes.ClientId);\n        if (clientClaim != null)\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(clientClaim.Value);\n            if (client == null)\n            {\n                _logger.LogError(\"Client deleted or disabled: {clientId}\", clientClaim.Value);\n\n                result.IsError = true;\n                result.Error = OidcConstants.ProtectedResourceErrors.InvalidToken;\n                result.Claims = null;\n\n                return result;\n            }\n        }\n\n        // make sure user is still active (if sub claim is present)\n        var subClaim = result.Claims.FirstOrDefault(c => c.Type == JwtClaimTypes.Subject);\n        if (subClaim != null)\n        {\n            var principal = Principal.Create(\"tokenvalidator\", result.Claims.ToArray());\n\n            if (result.ReferenceTokenId.IsPresent())\n            {\n                principal.Identities.First().AddClaim(new Claim(JwtClaimTypes.ReferenceTokenId, result.ReferenceTokenId));\n            }\n\n            var isActiveCtx = new IsActiveContext(principal, result.Client, IdentityServerConstants.ProfileIsActiveCallers.AccessTokenValidation);\n            await _profile.IsActiveAsync(isActiveCtx);\n\n            if (isActiveCtx.IsActive == false)\n            {\n                _logger.LogError(\"User marked as not active: {subject}\", subClaim.Value);\n\n                result.IsError = true;\n                result.Error = OidcConstants.ProtectedResourceErrors.InvalidToken;\n                result.Claims = null;\n\n                return result;\n            }\n        }\n\n        // check expected scope(s)\n        if (expectedScope.IsPresent())\n        {\n            var scope = result.Claims.FirstOrDefault(c => c.Type == JwtClaimTypes.Scope && c.Value == expectedScope);\n            if (scope == null)\n            {\n                LogError($\"Checking for expected scope {expectedScope} failed\");\n                return Invalid(OidcConstants.ProtectedResourceErrors.InsufficientScope);\n            }\n        }\n\n        _logger.LogDebug(\"Calling into custom token validator: {type}\", _customValidator.GetType().FullName);\n        var customResult = await _customValidator.ValidateAccessTokenAsync(result);\n\n        if (customResult.IsError)\n        {\n            LogError(\"Custom validator failed: \" + (customResult.Error ?? \"unknown\"));\n            return customResult;\n        }\n\n        // add claims again after custom validation\n        _log.Claims = customResult.Claims.ToClaimsDictionary();\n\n        LogSuccess();\n        return customResult;\n    }\n\n    private async Task<TokenValidationResult> ValidateJwtAsync(string jwt, IEnumerable<SecurityKeyInfo> validationKeys, bool validateLifetime = true, string audience = null)\n    {\n        var handler = new JwtSecurityTokenHandler();\n        handler.InboundClaimTypeMap.Clear();\n\n        var parameters = new TokenValidationParameters\n        {\n            ValidIssuer = _context.HttpContext.GetIdentityServerIssuerUri(),\n            IssuerSigningKeys = validationKeys.Select(k => k.Key),\n            ValidateLifetime = validateLifetime\n        };\n\n        if (audience.IsPresent())\n        {\n            parameters.ValidAudience = audience;\n        }\n        else\n        {\n            parameters.ValidateAudience = false;\n        }\n\n        try\n        {\n            var id = handler.ValidateToken(jwt, parameters, out var securityToken);\n            var jwtSecurityToken = securityToken as JwtSecurityToken;\n\n            // if no audience is specified, we make at least sure that it is an access token\n            if (audience.IsMissing())\n            {\n                if (_options.AccessTokenJwtType.IsPresent())\n                {\n                    var type = jwtSecurityToken.Header.Typ;\n                    if (!string.Equals(type, _options.AccessTokenJwtType))\n                    {\n                        return new TokenValidationResult\n                        {\n                            IsError = true,\n                            Error = \"invalid JWT token type\"\n                        };\n                    }\n\n                }\n            }\n            \n            // if access token contains an ID, log it\n            var jwtId = id.FindFirst(JwtClaimTypes.JwtId);\n            if (jwtId != null)\n            {\n                _log.JwtId = jwtId.Value;\n            }\n\n            // load the client that belongs to the client_id claim\n            Client client = null;\n            var clientId = id.FindFirst(JwtClaimTypes.ClientId);\n            if (clientId != null)\n            {\n                client = await _clients.FindEnabledClientByIdAsync(clientId.Value);\n                if (client == null)\n                {\n                    throw new InvalidOperationException(\"Client does not exist anymore.\");\n                }\n            }\n\n            var claims = id.Claims.ToList();\n            \n            // check the scope format (array vs space delimited string)\n            var scopes = claims.Where(c => c.Type == JwtClaimTypes.Scope).ToArray();\n            if (scopes.Any())\n            {\n                foreach (var scope in scopes)\n                {\n                    if (scope.Value.Contains(\" \"))\n                    {\n                        claims.Remove(scope);\n                        \n                        var values = scope.Value.Split(' ', StringSplitOptions.RemoveEmptyEntries);\n                        foreach (var value in values)\n                        {\n                            claims.Add(new Claim(JwtClaimTypes.Scope, value));\n                        }\n                    }\n                }\n            }\n\n            return new TokenValidationResult\n            {\n                IsError = false,\n\n                Claims = claims,\n                Client = client,\n                Jwt = jwt\n            };\n        }\n        catch (SecurityTokenExpiredException expiredException)\n        {\n            _logger.LogInformation(expiredException, \"JWT token validation error: {exception}\", expiredException.Message);\n            return Invalid(OidcConstants.ProtectedResourceErrors.ExpiredToken);\n        }\n        catch (Exception ex)\n        {\n            _logger.LogError(ex, \"JWT token validation error: {exception}\", ex.Message);\n            return Invalid(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n    }\n\n    private async Task<TokenValidationResult> ValidateReferenceAccessTokenAsync(string tokenHandle)\n    {\n        _log.TokenHandle = tokenHandle;\n        var token = await _referenceTokenStore.GetReferenceTokenAsync(tokenHandle);\n\n        if (token == null)\n        {\n            LogError(\"Invalid reference token.\");\n            return Invalid(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        if (token.CreationTime.HasExceeded(token.Lifetime, _clock.UtcNow.UtcDateTime))\n        {\n            LogError(\"Token expired.\");\n\n            await _referenceTokenStore.RemoveReferenceTokenAsync(tokenHandle);\n            return Invalid(OidcConstants.ProtectedResourceErrors.ExpiredToken);\n        }\n\n        // load the client that is defined in the token\n        Client client = null;\n        if (token.ClientId != null)\n        {\n            client = await _clients.FindEnabledClientByIdAsync(token.ClientId);\n        }\n\n        if (client == null)\n        {\n            LogError($\"Client deleted or disabled: {token.ClientId}\");\n            return Invalid(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        return new TokenValidationResult\n        {\n            IsError = false,\n\n            Client = client,\n            Claims = ReferenceTokenToClaims(token),\n            ReferenceToken = token,\n            ReferenceTokenId = tokenHandle\n        };\n    }\n\n    private IEnumerable<Claim> ReferenceTokenToClaims(Token token)\n    {\n        var claims = new List<Claim>\n        {\n            new Claim(JwtClaimTypes.Issuer, token.Issuer),\n            new Claim(JwtClaimTypes.NotBefore, new DateTimeOffset(token.CreationTime).ToUnixTimeSeconds().ToString(), ClaimValueTypes.Integer64),\n            new Claim(JwtClaimTypes.Expiration, new DateTimeOffset(token.CreationTime).AddSeconds(token.Lifetime).ToUnixTimeSeconds().ToString(), ClaimValueTypes.Integer64)\n        };\n\n        foreach (var aud in token.Audiences)\n        {\n            claims.Add(new Claim(JwtClaimTypes.Audience, aud));\n        }\n\n        claims.AddRange(token.Claims);\n        return claims;\n    }\n\n    private string GetClientIdFromJwt(string token)\n    {\n        try\n        {\n            var jwt = new JwtSecurityToken(token);\n            var clientId = jwt.Audiences.FirstOrDefault();\n\n            return clientId;\n        }\n        catch (Exception ex)\n        {\n            _logger.LogError(ex, \"Malformed JWT token: {exception}\", ex.Message);\n            return null;\n        }\n    }\n\n    private TokenValidationResult Invalid(string error)\n    {\n        return new TokenValidationResult\n        {\n            IsError = true,\n            Error = error\n        };\n    }\n\n    private void LogError(string message)\n    {\n        _logger.LogError(message + \"\\n{@logMessage}\", _log);\n    }\n\n    private void LogSuccess()\n    {\n        _logger.LogDebug(\"Token validation success\\n{@logMessage}\", _log);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/UserInfoRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Default userinfo request validator\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.IUserInfoRequestValidator\" />\ninternal class UserInfoRequestValidator : IUserInfoRequestValidator\n{\n    private readonly ITokenValidator _tokenValidator;\n    private readonly IProfileService _profile;\n    private readonly ILogger _logger;\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"UserInfoRequestValidator\" /> class.\n    /// </summary>\n    /// <param name=\"tokenValidator\">The token validator.</param>\n    /// <param name=\"profile\">The profile service</param>\n    /// <param name=\"logger\">The logger.</param>\n    public UserInfoRequestValidator(\n        ITokenValidator tokenValidator, \n        IProfileService profile,\n        ILogger<UserInfoRequestValidator> logger)\n    {\n        _tokenValidator = tokenValidator;\n        _profile = profile;\n        _logger = logger;\n    }\n\n    /// <summary>\n    /// Validates a userinfo request.\n    /// </summary>\n    /// <param name=\"accessToken\">The access token.</param>\n    /// <returns></returns>\n    /// <exception cref=\"System.NotImplementedException\"></exception>\n    public async Task<UserInfoRequestValidationResult> ValidateRequestAsync(string accessToken)\n    {\n        // the access token needs to be valid and have at least the openid scope\n        var tokenResult = await _tokenValidator.ValidateAccessTokenAsync(\n            accessToken,\n            IdentityServerConstants.StandardScopes.OpenId);\n\n        if (tokenResult.IsError)\n        {\n            return new UserInfoRequestValidationResult\n            {\n                IsError = true,\n                Error = tokenResult.Error\n            };\n        }\n\n        // the token must have a one sub claim\n        var subClaim = tokenResult.Claims.SingleOrDefault(c => c.Type == JwtClaimTypes.Subject);\n        if (subClaim == null)\n        {\n            _logger.LogError(\"Token contains no sub claim\");\n\n            return new UserInfoRequestValidationResult\n            {\n                IsError = true,\n                Error = OidcConstants.ProtectedResourceErrors.InvalidToken\n            };\n        }\n\n        // create subject from incoming access token\n        var claims = tokenResult.Claims.Where(x => !Constants.Filters.ProtocolClaimsFilter.Contains(x.Type));\n        var subject = Principal.Create(\"UserInfo\", claims.ToArray());\n\n        // make sure user is still active\n        var isActiveContext = new IsActiveContext(subject, tokenResult.Client, IdentityServerConstants.ProfileIsActiveCallers.UserInfoRequestValidation);\n        await _profile.IsActiveAsync(isActiveContext);\n\n        if (isActiveContext.IsActive == false)\n        {\n            _logger.LogError(\"User is not active: {sub}\", subject.GetSubjectId());\n\n            return new UserInfoRequestValidationResult\n            {\n                IsError = true,\n                Error = OidcConstants.ProtectedResourceErrors.InvalidToken\n            };\n        }\n\n        return new UserInfoRequestValidationResult\n        {\n            IsError = false,\n            TokenValidationResult = tokenResult,\n            Subject = subject\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/X509NameSecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validator for an X.509 certificate based client secret using the common name\n/// </summary>\npublic class X509NameSecretValidator : ISecretValidator\n{\n    private readonly ILogger<X509NameSecretValidator> _logger;\n\n    /// <summary>\n    /// ctor\n    /// </summary>\n    /// <param name=\"logger\"></param>\n    public X509NameSecretValidator(ILogger<X509NameSecretValidator> logger)\n    {\n        _logger = logger;\n    }\n\n    /// <inheritdoc/>\n    public Task<SecretValidationResult> ValidateAsync(IEnumerable<Secret> secrets, ParsedSecret parsedSecret)\n    {\n        var fail = Task.FromResult(new SecretValidationResult { Success = false });\n\n        if (parsedSecret.Type != ParsedSecretTypes.X509Certificate)\n        {\n            _logger.LogDebug(\"X509 name secret validator cannot process {type}\", parsedSecret.Type ?? \"null\");\n            return fail;\n        }\n\n        if (!(parsedSecret.Credential is X509Certificate2 cert))\n        {\n            throw new InvalidOperationException(\"Credential is not a x509 certificate.\");\n        }\n\n        var name = cert.Subject;\n        if (name == null)\n        {\n            _logger.LogWarning(\"No subject/name found in X509 certificate.\");\n            return fail;\n        }\n\n        var nameSecrets = secrets.Where(s => s.Type == SecretTypes.X509CertificateName);\n        if (!nameSecrets.Any())\n        {\n            _logger.LogDebug(\"No x509 name secrets configured for client.\");\n            return fail;\n        }\n\n        foreach (var nameSecret in nameSecrets)\n        {\n            if (name.Equals(nameSecret.Value, StringComparison.Ordinal))\n            {\n                var result = new SecretValidationResult\n                {\n                    Success = true,\n                    Confirmation = cert.CreateThumbprintCnf()\n                };\n\n                return Task.FromResult(result);\n            }\n        }\n\n        _logger.LogDebug(\"No matching x509 name secret found.\");\n        return fail;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Default/X509ThumbprintSecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validator for an X.509 certificate based client secret using the thumbprint\n/// </summary>\npublic class X509ThumbprintSecretValidator : ISecretValidator\n{\n    private readonly ILogger<X509ThumbprintSecretValidator> _logger;\n\n    /// <summary>\n    /// ctor\n    /// </summary>\n    /// <param name=\"logger\"></param>\n    public X509ThumbprintSecretValidator(ILogger<X509ThumbprintSecretValidator> logger)\n    {\n        _logger = logger;\n    }\n\n    /// <inheritdoc/>\n    public Task<SecretValidationResult> ValidateAsync(IEnumerable<Secret> secrets, ParsedSecret parsedSecret)\n    {\n        var fail = Task.FromResult(new SecretValidationResult { Success = false });\n\n        if (parsedSecret.Type != ParsedSecretTypes.X509Certificate)\n        {\n            _logger.LogDebug(\"X509 thumbprint secret validator cannot process {type}\", parsedSecret.Type ?? \"null\");\n            return fail;\n        }\n\n        if (!(parsedSecret.Credential is X509Certificate2 cert))\n        {\n            throw new InvalidOperationException(\"Credential is not a x509 certificate.\");\n        }\n\n        var thumbprint = cert.Thumbprint;\n        if (thumbprint == null)\n        {\n            _logger.LogWarning(\"No thumbprint found in X509 certificate.\");\n            return fail;\n        }\n\n        var thumbprintSecrets = secrets.Where(s => s.Type == SecretTypes.X509CertificateThumbprint);\n        if (!thumbprintSecrets.Any())\n        {\n            _logger.LogDebug(\"No thumbprint secrets configured for client.\");\n            return fail;\n        }\n\n        foreach (var thumbprintSecret in thumbprintSecrets)\n        {\n            if (thumbprint.Equals(thumbprintSecret.Value, StringComparison.OrdinalIgnoreCase))\n            {\n                var result = new SecretValidationResult\n                {\n                    Success = true,\n                    Confirmation = cert.CreateThumbprintCnf()\n                };\n\n                return Task.FromResult(result);\n            }\n        }\n\n        _logger.LogDebug(\"No matching x509 thumbprint secret found.\");\n        return fail;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IApiSecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validator for handling API client authentication.\n/// </summary>\npublic interface IApiSecretValidator\n{\n    /// <summary>\n    /// Tries to authenticate an API client based on the incoming request\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    Task<ApiSecretValidationResult> ValidateAsync(HttpContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IAuthorizeRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n///  Authorize endpoint request validator.\n/// </summary>\npublic interface IAuthorizeRequestValidator\n{\n    /// <summary>\n    ///  Validates authorize request parameters.\n    /// </summary>\n    /// <param name=\"parameters\"></param>\n    /// <param name=\"subject\"></param>\n    /// <returns></returns>\n    Task<AuthorizeRequestValidationResult> ValidateAsync(NameValueCollection parameters, ClaimsPrincipal subject = null);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IClientConfigurationValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validator for handling client authentication\n/// </summary>\npublic interface IClientConfigurationValidator\n{\n    /// <summary>\n    /// Determines whether the configuration of a client is valid.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    Task ValidateAsync(ClientConfigurationValidationContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IClientSecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validator for handling client authentication\n/// </summary>\npublic interface IClientSecretValidator\n{\n    /// <summary>\n    /// Tries to authenticate a client based on the incoming request\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    Task<ClientSecretValidationResult> ValidateAsync(HttpContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/ICustomAuthorizeRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Allows inserting custom validation logic into authorize and token requests\n/// </summary>\npublic interface ICustomAuthorizeRequestValidator\n{\n    /// <summary>\n    /// Custom validation logic for the authorize request.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    Task ValidateAsync(CustomAuthorizeRequestValidationContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/ICustomTokenRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Allows inserting custom validation logic into token requests\n/// </summary>\npublic interface ICustomTokenRequestValidator\n{\n    /// <summary>\n    /// Custom validation logic for a token request.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns>\n    /// The validation result\n    /// </returns>\n    Task ValidateAsync(CustomTokenRequestValidationContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/ICustomTokenValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Allows inserting custom token validation logic\n/// </summary>\npublic interface ICustomTokenValidator\n{\n    /// <summary>\n    /// Custom validation logic for access tokens.\n    /// </summary>\n    /// <param name=\"result\">The validation result so far.</param>\n    /// <returns>The validation result</returns>\n    Task<TokenValidationResult> ValidateAccessTokenAsync(TokenValidationResult result);\n\n    /// <summary>\n    /// Custom validation logic for identity tokens.\n    /// </summary>\n    /// <param name=\"result\">The validation result so far.</param>\n    /// <returns>The validation result</returns>\n    Task<TokenValidationResult> ValidateIdentityTokenAsync(TokenValidationResult result);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IDeviceAuthorizationRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n///  Device authorization endpoint request validator.\n/// </summary>\npublic interface IDeviceAuthorizationRequestValidator\n{\n    /// <summary>\n    ///  Validates authorize request parameters.\n    /// </summary>\n    /// <param name=\"parameters\"></param>\n    /// <param name=\"clientValidationResult\"></param>\n    /// <returns></returns>\n    Task<DeviceAuthorizationRequestValidationResult> ValidateAsync(NameValueCollection parameters, ClientSecretValidationResult clientValidationResult);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IDeviceCodeValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// The device code validator\n/// </summary>\npublic interface IDeviceCodeValidator\n{\n    /// <summary>\n    /// Validates the device code.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns></returns>\n    Task ValidateAsync(DeviceCodeValidationContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IEndSessionRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n///  Validates end session requests.\n/// </summary>\npublic interface IEndSessionRequestValidator\n{\n    /// <summary>\n    /// Validates end session endpoint requests.\n    /// </summary>\n    /// <param name=\"parameters\"></param>\n    /// <param name=\"subject\"></param>\n    /// <returns></returns>\n    Task<EndSessionValidationResult> ValidateAsync(NameValueCollection parameters, ClaimsPrincipal subject);\n\n    /// <summary>\n    ///  Validates requests from logout page iframe to trigger single signout.\n    /// </summary>\n    /// <param name=\"parameters\"></param>\n    /// <returns></returns>\n    Task<EndSessionCallbackValidationResult> ValidateCallbackAsync(NameValueCollection parameters);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IExtensionGrantValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Handles validation of token requests using custom grant types\n/// </summary>\npublic interface IExtensionGrantValidator\n{\n    /// <summary>\n    /// Validates the custom grant request.\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    /// <returns>\n    /// A principal\n    /// </returns>\n    Task ValidateAsync(ExtensionGrantValidationContext context);\n\n    /// <summary>\n    /// Returns the grant type this validator can deal with\n    /// </summary>\n    /// <value>\n    /// The type of the grant.\n    /// </value>\n    string GrantType { get; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IIntrospectionRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Interface for the introspection request validator\n/// </summary>\npublic interface IIntrospectionRequestValidator\n{\n    /// <summary>\n    /// Validates the request.\n    /// </summary>\n    /// <param name=\"parameters\">The parameters.</param>\n    /// <param name=\"api\">The API.</param>\n    /// <returns></returns>\n    Task<IntrospectionRequestValidationResult> ValidateAsync(NameValueCollection parameters, ApiResource api);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IRedirectUriValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models the logic when validating redirect and post logout redirect URIs.\n/// </summary>\npublic interface IRedirectUriValidator\n{\n    /// <summary>\n    /// Determines whether a redirect URI is valid for a client.\n    /// </summary>\n    /// <param name=\"requestedUri\">The requested URI.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns><c>true</c> is the URI is valid; <c>false</c> otherwise.</returns>\n    Task<bool> IsRedirectUriValidAsync(string requestedUri, Client client);\n    \n    /// <summary>\n    /// Determines whether a post logout URI is valid for a client.\n    /// </summary>\n    /// <param name=\"requestedUri\">The requested URI.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns><c>true</c> is the URI is valid; <c>false</c> otherwise.</returns>\n    Task<bool> IsPostLogoutRedirectUriValidAsync(string requestedUri, Client client);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IResourceOwnerPasswordValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Handles validation of resource owner password credentials\n/// </summary>\npublic interface IResourceOwnerPasswordValidator\n{\n    /// <summary>\n    /// Validates the resource owner password credential\n    /// </summary>\n    /// <param name=\"context\">The context.</param>\n    Task ValidateAsync(ResourceOwnerPasswordValidationContext context);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IResourceValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validates requested resources (scopes and resource indicators)\n/// </summary>\npublic interface IResourceValidator\n{\n    // todo: should this be used anywhere we re-create tokens? do we need to re-run scope validation?\n\n    /// <summary>\n    /// Validates the requested resources for the client.\n    /// </summary>\n    Task<ResourceValidationResult> ValidateRequestedResourcesAsync(ResourceValidationRequest request);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IScopeParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Allows parsing raw scopes values into structured scope values.\n/// </summary>\npublic interface IScopeParser\n{\n    // todo: test return no error, and no parsed scopes. how do callers behave?\n    /// <summary>\n    /// Parses the requested scopes.\n    /// </summary>\n    ParsedScopesResult ParseScopeValues(IEnumerable<string> scopeValues);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/ISecretParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// A service for parsing secrets found on the request\n/// </summary>\npublic interface ISecretParser\n{\n    /// <summary>\n    /// Tries to find a secret on the context that can be used for authentication\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns>\n    /// A parsed secret\n    /// </returns>\n    Task<ParsedSecret> ParseAsync(HttpContext context);\n\n    /// <summary>\n    /// Returns the authentication method name that this parser implements\n    /// </summary>\n    /// <value>\n    /// The authentication method.\n    /// </value>\n    string AuthenticationMethod { get; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/ISecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Service for validating a received secret against a stored secret\n/// </summary>\npublic interface ISecretValidator\n{\n    /// <summary>\n    /// Validates a secret\n    /// </summary>\n    /// <param name=\"secrets\">The stored secrets.</param>\n    /// <param name=\"parsedSecret\">The received secret.</param>\n    /// <returns>A validation result</returns>\n    Task<SecretValidationResult> ValidateAsync(IEnumerable<Secret> secrets, ParsedSecret parsedSecret);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/ISecretsListParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Parser for finding the best secret in an Enumerable List\n/// </summary>\npublic interface ISecretsListParser\n{\n    /// <summary>\n    /// Tries to find the best secret on the context that can be used for authentication\n    /// </summary>\n    /// <param name=\"context\">The HTTP context.</param>\n    /// <returns>\n    /// A parsed secret\n    /// </returns>\n    Task<ParsedSecret> ParseAsync(HttpContext context);\n\n    /// <summary>\n    /// Gets all available authentication methods.\n    /// </summary>\n    /// <returns></returns>\n    IEnumerable<string> GetAvailableAuthenticationMethods();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/ISecretsListValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validator for an Enumerable List of Secrets\n/// </summary>\npublic interface ISecretsListValidator\n{\n    /// <summary>\n    /// Validates a list of secrets\n    /// </summary>\n    /// <param name=\"secrets\">The stored secrets.</param>\n    /// <param name=\"parsedSecret\">The received secret.</param>\n    /// <returns>A validation result</returns>\n    Task<SecretValidationResult> ValidateAsync(IEnumerable<Secret> secrets, ParsedSecret parsedSecret);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/ITokenRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Interface for the token request validator\n/// </summary>\npublic interface ITokenRequestValidator\n{\n    /// <summary>\n    /// Validates the request.\n    /// </summary>\n    /// <param name=\"parameters\">The parameters.</param>\n    /// <param name=\"clientValidationResult\">The client validation result.</param>\n    /// <returns></returns>\n    Task<TokenRequestValidationResult> ValidateRequestAsync(NameValueCollection parameters, ClientSecretValidationResult clientValidationResult);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/ITokenRevocationRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Interface for the token revocation request validator\n/// </summary>\npublic interface ITokenRevocationRequestValidator\n{\n    /// <summary>\n    /// Validates the request.\n    /// </summary>\n    /// <param name=\"parameters\">The parameters.</param>\n    /// <param name=\"client\">The client.</param>\n    /// <returns></returns>\n    Task<TokenRevocationRequestValidationResult> ValidateRequestAsync(NameValueCollection parameters, Client client);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/ITokenValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Interface for the token validator\n/// </summary>\npublic interface ITokenValidator\n{\n    /// <summary>\n    /// Validates an access token.\n    /// </summary>\n    /// <param name=\"token\">The access token.</param>\n    /// <param name=\"expectedScope\">The expected scope.</param>\n    /// <returns></returns>\n    Task<TokenValidationResult> ValidateAccessTokenAsync(string token, string expectedScope = null);\n    \n    /// <summary>\n    /// Validates an identity token.\n    /// </summary>\n    /// <param name=\"token\">The token.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <param name=\"validateLifetime\">if set to <c>true</c> the lifetime gets validated. Otherwise not.</param>\n    /// <returns></returns>\n    Task<TokenValidationResult> ValidateIdentityTokenAsync(string token, string clientId = null, bool validateLifetime = true);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/IUserInfoRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validator for userinfo requests\n/// </summary>\npublic interface IUserInfoRequestValidator\n{\n    /// <summary>\n    /// Validates a userinfo request.\n    /// </summary>\n    /// <param name=\"accessToken\">The access token.</param>\n    /// <returns></returns>\n    Task<UserInfoRequestValidationResult> ValidateRequestAsync(string accessToken);\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/AuthorizeRequestValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for authorize requests\n/// </summary>\npublic class AuthorizeRequestValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"AuthorizeRequestValidationResult\"/> class.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    public AuthorizeRequestValidationResult(ValidatedAuthorizeRequest request)\n    {\n        ValidatedRequest = request;\n        IsError = false;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"AuthorizeRequestValidationResult\" /> class.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"error\">The error.</param>\n    /// <param name=\"errorDescription\">The error description.</param>\n    public AuthorizeRequestValidationResult(ValidatedAuthorizeRequest request, string error, string errorDescription = null)\n    {\n        ValidatedRequest = request;\n        IsError = true;\n        Error = error;\n        ErrorDescription = errorDescription;\n    }\n\n    /// <summary>\n    /// Gets or sets the validated request.\n    /// </summary>\n    /// <value>\n    /// The validated request.\n    /// </value>\n    public ValidatedAuthorizeRequest ValidatedRequest { get; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/BearerTokenUsageType.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Validation;\n\npublic enum BearerTokenUsageType\n{\n    AuthorizationHeader = 0,\n    PostBody = 1,\n    QueryString = 2\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/BearerTokenUsageValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models usage of a bearer token\n/// </summary>\npublic class BearerTokenUsageValidationResult\n{\n    /// <summary>\n    /// Gets or sets a value indicating whether the token was found.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if the token was found; otherwise, <c>false</c>.\n    /// </value>\n    public bool TokenFound { get; set; }\n\n    /// <summary>\n    /// Gets or sets the token.\n    /// </summary>\n    /// <value>\n    /// The token.\n    /// </value>\n    public string Token { get; set; }\n\n    /// <summary>\n    /// Gets or sets the usage type.\n    /// </summary>\n    /// <value>\n    /// The type of the usage.\n    /// </value>\n    public BearerTokenUsageType UsageType { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ClientSecretValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for client validation\n/// </summary>\npublic class ClientSecretValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Gets or sets the client.\n    /// </summary>\n    /// <value>\n    /// The client.\n    /// </value>\n    public Client Client { get; set; }\n\n    /// <summary>\n    /// Gets or sets the secret used to authenticate the client.\n    /// </summary>\n    /// <value>\n    /// The secret.\n    /// </value>\n    public ParsedSecret Secret { get; set; }\n\n    /// <summary>\n    /// Gets or sets the value of the confirmation method (will become the cnf claim). Must be a JSON object.\n    /// </summary>\n    /// <value>\n    /// The confirmation.\n    /// </value>\n    public string Confirmation { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/DeviceAuthorizationRequestValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for device authorization requests\n/// </summary>\npublic class DeviceAuthorizationRequestValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DeviceAuthorizationRequestValidationResult\"/> class.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    public DeviceAuthorizationRequestValidationResult(ValidatedDeviceAuthorizationRequest request)\n    {\n        IsError = false;\n\n        ValidatedRequest = request;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"DeviceAuthorizationRequestValidationResult\"/> class.\n    /// </summary>\n    /// <param name=\"request\">The request.</param>\n    /// <param name=\"error\">The error.</param>\n    /// <param name=\"errorDescription\">The error description.</param>\n    public DeviceAuthorizationRequestValidationResult(ValidatedDeviceAuthorizationRequest request, string error, string errorDescription = null)\n    {\n        IsError = true;\n\n        Error = error;\n        ErrorDescription = errorDescription;\n        ValidatedRequest = request;\n    }\n\n    /// <summary>\n    /// Gets the validated request.\n    /// </summary>\n    /// <value>\n    /// The validated request.\n    /// </value>\n    public ValidatedDeviceAuthorizationRequest ValidatedRequest { get; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/DeviceCodeValidationContext.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for device code validation request.\n/// </summary>\npublic class DeviceCodeValidationContext\n{\n    /// <summary>\n    /// Gets or sets the device code.\n    /// </summary>\n    /// <value>\n    /// The device code.\n    /// </value>\n    public string DeviceCode { get; set; }\n\n    /// <summary>\n    /// Gets or sets the request.\n    /// </summary>\n    /// <value>\n    /// The request.\n    /// </value>\n    public ValidatedTokenRequest Request { get; set; }\n\n    /// <summary>\n    /// Gets or sets the result.\n    /// </summary>\n    /// <value>\n    /// The result.\n    /// </value>\n    public TokenRequestValidationResult Result { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/EndSessionCallbackValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for end session callback requests.\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.ValidationResult\" />\npublic class EndSessionCallbackValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Gets the client front-channel logout urls.\n    /// </summary>\n    public IEnumerable<string> FrontChannelLogoutUrls { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/EndSessionValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for end session requests\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.ValidationResult\" />\npublic class EndSessionValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Gets or sets the validated request.\n    /// </summary>\n    /// <value>\n    /// The validated request.\n    /// </value>\n    public ValidatedEndSessionRequest ValidatedRequest { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/GrantValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models the result of custom grant validation.\n/// </summary>\npublic class GrantValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Gets or sets the principal which represents the result of the validation.\n    /// </summary>\n    /// <value>\n    /// The principal.\n    /// </value>\n    public ClaimsPrincipal Subject { get; set; }\n\n    /// <summary>\n    /// Custom fields for the token response\n    /// </summary>\n    public Dictionary<string, object> CustomResponse { get; set; } = new Dictionary<string, object>();\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"GrantValidationResult\"/> class with no subject.\n    /// Warning: the resulting access token will only contain the client identity.\n    /// </summary>\n    public GrantValidationResult(Dictionary<string, object> customResponse = null)\n    {\n        IsError = false;\n        CustomResponse = customResponse;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"GrantValidationResult\"/> class with a given principal.\n    /// Warning: the principal needs to include the required claims - it is recommended to use the other constructor that does validation.\n    /// </summary>\n    public GrantValidationResult(ClaimsPrincipal principal, Dictionary<string, object> customResponse = null)\n    {\n        IsError = false;\n\n        if (principal.Identities.Count() != 1) throw new InvalidOperationException(\"only a single identity supported\");\n        if (principal.FindFirst(JwtClaimTypes.Subject) == null) throw new InvalidOperationException(\"sub claim is missing\");\n        if (principal.FindFirst(JwtClaimTypes.IdentityProvider) == null) throw new InvalidOperationException(\"idp claim is missing\");\n        if (principal.FindFirst(JwtClaimTypes.AuthenticationMethod) == null) throw new InvalidOperationException(\"amr claim is missing\");\n        if (principal.FindFirst(JwtClaimTypes.AuthenticationTime) == null) throw new InvalidOperationException(\"auth_time claim is missing\");\n\n        Subject = principal;\n        CustomResponse = customResponse;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"GrantValidationResult\"/> class with an error and description.\n    /// </summary>\n    /// <param name=\"error\">The error.</param>\n    /// <param name=\"errorDescription\">The error description.</param>\n    /// <param name=\"customResponse\">Custom response elements</param>\n    public GrantValidationResult(TokenRequestErrors error, string errorDescription = null, Dictionary<string, object> customResponse = null)\n    {\n        Error = ConvertTokenErrorEnumToString(error);\n        ErrorDescription = errorDescription;\n        CustomResponse = customResponse;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"GrantValidationResult\" /> class.\n    /// </summary>\n    /// <param name=\"subject\">The subject claim used to uniquely identifier the user.</param>\n    /// <param name=\"authenticationMethod\">The authentication method which describes the custom grant type.</param>\n    /// <param name=\"claims\">Additional claims that will be maintained in the principal. \n    /// If you want these claims to appear in token, you need to add them explicitly in your custom implementation of <see cref=\"Services.IProfileService\"/> service.</param>\n    /// <param name=\"identityProvider\">The identity provider.</param>\n    /// <param name=\"customResponse\">The custom response.</param>\n    public GrantValidationResult(\n        string subject,\n        string authenticationMethod,\n        IEnumerable<Claim> claims = null,\n        string identityProvider = IdentityServerConstants.LocalIdentityProvider,\n        Dictionary<string, object> customResponse = null)\n        : this(subject, authenticationMethod, DateTime.UtcNow, claims, identityProvider, customResponse)\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"GrantValidationResult\" /> class.\n    /// </summary>\n    /// <param name=\"subject\">The subject claim used to uniquely identifier the user.</param>\n    /// <param name=\"authenticationMethod\">The authentication method which describes the custom grant type.</param>\n    /// <param name=\"authTime\">The UTC date/time of authentication.</param>\n    /// <param name=\"claims\">Additional claims that will be maintained in the principal.\n    /// If you want these claims to appear in token, you need to add them explicitly in your custom implementation of <see cref=\"Services.IProfileService\"/> service.</param>\n    /// <param name=\"identityProvider\">The identity provider.</param>\n    /// <param name=\"customResponse\">The custom response.</param>\n    public GrantValidationResult(\n        string subject,\n        string authenticationMethod,\n        DateTime authTime,\n        IEnumerable<Claim> claims = null,\n        string identityProvider = IdentityServerConstants.LocalIdentityProvider,\n        Dictionary<string, object> customResponse = null)\n    {\n        IsError = false;\n\n        var resultClaims = new List<Claim>\n        {\n            new Claim(JwtClaimTypes.Subject, subject),\n            new Claim(JwtClaimTypes.AuthenticationMethod, authenticationMethod),\n            new Claim(JwtClaimTypes.IdentityProvider, identityProvider),\n            new Claim(JwtClaimTypes.AuthenticationTime, new DateTimeOffset(authTime).ToUnixTimeSeconds().ToString(), ClaimValueTypes.Integer64)\n        };\n\n        if (!claims.EnumerableIsNullOrEmpty())\n        {\n            resultClaims.AddRange(claims);\n        }\n\n        var id = new ClaimsIdentity(authenticationMethod);\n        id.AddClaims(resultClaims.Distinct(new ClaimComparer()));\n\n        Subject = new ClaimsPrincipal(id);\n        CustomResponse = customResponse;\n    }\n\n    private string ConvertTokenErrorEnumToString(TokenRequestErrors error)\n    {\n        return error switch\n        {\n            TokenRequestErrors.InvalidClient => OidcConstants.TokenErrors.InvalidClient,\n            TokenRequestErrors.InvalidGrant => OidcConstants.TokenErrors.InvalidGrant,\n            TokenRequestErrors.InvalidRequest => OidcConstants.TokenErrors.InvalidRequest,\n            TokenRequestErrors.InvalidScope => OidcConstants.TokenErrors.InvalidScope,\n            TokenRequestErrors.UnauthorizedClient => OidcConstants.TokenErrors.UnauthorizedClient,\n            TokenRequestErrors.UnsupportedGrantType => OidcConstants.TokenErrors.UnsupportedGrantType,\n            TokenRequestErrors.InvalidTarget => OidcConstants.TokenErrors.InvalidTarget,\n            _ => throw new InvalidOperationException(\"invalid token error\")\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/IntrospectionRequestValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for introspection request\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Validation.ValidationResult\" />\npublic class IntrospectionRequestValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Gets or sets the request parameters.\n    /// </summary>\n    /// <value>\n    /// The parameters.\n    /// </value>\n    public NameValueCollection Parameters { get; set; }\n\n    /// <summary>\n    /// Gets or sets the API.\n    /// </summary>\n    /// <value>\n    /// The API.\n    /// </value>\n    public ApiResource Api { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the token is active.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if the token is active; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsActive { get; set; }\n\n    /// <summary>\n    /// Gets or sets the claims.\n    /// </summary>\n    /// <value>\n    /// The claims.\n    /// </value>\n    public IEnumerable<Claim> Claims { get; set; }\n\n    /// <summary>\n    /// Gets or sets the token.\n    /// </summary>\n    /// <value>\n    /// The token.\n    /// </value>\n    public string Token { get; set; }\n}\n\n/// <summary>\n/// Failure reasons for introspection request\n/// </summary>\npublic enum IntrospectionRequestValidationFailureReason\n{\n    /// <summary>\n    /// none\n    /// </summary>\n    None,\n\n    /// <summary>\n    /// missing token\n    /// </summary>\n    MissingToken,\n\n    /// <summary>\n    /// invalid token\n    /// </summary>\n    InvalidToken,\n\n    /// <summary>\n    /// invalid scope\n    /// </summary>\n    InvalidScope\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/JwtRequestValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models the result of JWT request validation.\n/// </summary>\npublic class JwtRequestValidationResult : ValidationResult\n{\n    /// <summary>\n    /// The key/value pairs from the JWT payload of a successfuly validated request.\n    /// </summary>\n    public Dictionary<string, string> Payload { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ParsedScopeValidationError.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models an error parsing a scope.\n/// </summary>\npublic class ParsedScopeValidationError\n{\n    /// <summary>\n    /// Ctor\n    /// </summary>\n    /// <param name=\"rawValue\"></param>\n    /// <param name=\"error\"></param>\n    public ParsedScopeValidationError(string rawValue, string error)\n    {\n        if (String.IsNullOrWhiteSpace(rawValue))\n        {\n            throw new ArgumentNullException(nameof(rawValue));\n        }\n\n        if (String.IsNullOrWhiteSpace(error))\n        {\n            throw new ArgumentNullException(nameof(error));\n        }\n\n        RawValue = rawValue;\n        Error = error;\n    }\n\n    /// <summary>\n    /// The original (raw) value of the scope.\n    /// </summary>\n    public string RawValue { get; set; }\n\n    /// <summary>\n    /// Error message describing why the raw scope failed to be parsed.\n    /// </summary>\n    public string Error { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ParsedScopeValue.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models a parsed scope value.\n/// </summary>\npublic class ParsedScopeValue\n{\n    /// <summary>\n    /// Ctor\n    /// </summary>\n    /// <param name=\"rawValue\"></param>\n    public ParsedScopeValue(string rawValue)\n        : this(rawValue, rawValue, null)\n    {\n    }\n\n    /// <summary>\n    /// Ctor\n    /// </summary>\n    /// <param name=\"rawValue\"></param>\n    /// <param name=\"parsedName\"></param>\n    /// <param name=\"parsedParameter\"></param>\n    public ParsedScopeValue(string rawValue, string parsedName, string parsedParameter)\n    {\n        if (String.IsNullOrWhiteSpace(rawValue))\n        {\n            throw new ArgumentNullException(nameof(rawValue));\n        }\n\n        if (String.IsNullOrWhiteSpace(parsedName))\n        {\n            throw new ArgumentNullException(nameof(parsedName));\n        }\n\n        RawValue = rawValue;\n        ParsedName = parsedName;\n        ParsedParameter = parsedParameter;\n    }\n\n    /// <summary>\n    /// The original (raw) value of the scope.\n    /// </summary>\n    public string RawValue { get; set; }\n\n    /// <summary>\n    /// The parsed name of the scope. If the scope has no structure, the parsed name will be the same as the raw value.\n    /// </summary>\n    public string ParsedName { get; set; }\n\n    // future: maybe this should be something w/ more structure? dictionary?\n    /// <summary>\n    /// The parameter value of the parsed scope. If the scope has no structure, then the value will be null.\n    /// </summary>\n    public string ParsedParameter { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ParsedScopesResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Represents the result of scope parsing.\n/// </summary>\npublic class ParsedScopesResult\n{\n    /// <summary>\n    /// The valid parsed scopes.\n    /// </summary>\n    public ICollection<ParsedScopeValue> ParsedScopes { get; set; } = new HashSet<ParsedScopeValue>();\n\n    /// <summary>\n    /// The errors encountered while parsing.\n    /// </summary>\n    public ICollection<ParsedScopeValidationError> Errors { get; set; } = new HashSet<ParsedScopeValidationError>();\n\n    /// <summary>\n    /// Indicates if the result of parsing the scopes was successful.\n    /// </summary>\n    public bool Succeeded => Errors == null || !Errors.Any();\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ResourceValidationRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models the request to validate scopes and resource indicators for a client.\n/// </summary>\npublic class ResourceValidationRequest\n{\n    /// <summary>\n    /// The client.\n    /// </summary>\n    public Client Client { get; set; }\n\n    /// <summary>\n    /// The requested scope values.\n    /// </summary>\n    public IEnumerable<string> Scopes { get; set; }\n\n    // /// <summary>\n    // /// The requested resource indicators.\n    // /// </summary>\n    //  todo: add back when we support resource indicators\n    // public IEnumerable<string> ResourceIndicators { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ResourceValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Result of validation of requested scopes and resource indicators.\n/// </summary>\npublic class ResourceValidationResult\n{\n    /// <summary>\n    /// Ctor\n    /// </summary>\n    public ResourceValidationResult()\n    {\n    }\n\n    /// <summary>\n    /// Ctor\n    /// </summary>\n    /// <param name=\"resources\"></param>\n    public ResourceValidationResult(Resources resources)\n    {\n        Resources = resources;\n        ParsedScopes = resources.ToScopeNames().Select(x => new ParsedScopeValue(x)).ToList();\n    }\n\n    /// <summary>\n    /// Ctor\n    /// </summary>\n    /// <param name=\"resources\"></param>\n    /// <param name=\"parsedScopeValues\"></param>\n    public ResourceValidationResult(Resources resources, IEnumerable<ParsedScopeValue> parsedScopeValues)\n    {\n        Resources = resources;\n        ParsedScopes = parsedScopeValues.ToList();\n    }\n\n    /// <summary>\n    /// Indicates if the result was successful.\n    /// </summary>\n    public bool Succeeded => ParsedScopes.Any() && !InvalidScopes.Any();\n\n    /// <summary>\n    /// The resources of the result.\n    /// </summary>\n    public Resources Resources { get; set; } = new Resources();\n\n    /// <summary>\n    /// The parsed scopes represented by the result.\n    /// </summary>\n    public ICollection<ParsedScopeValue> ParsedScopes { get; set; } = new HashSet<ParsedScopeValue>();\n\n    /// <summary>\n    /// The original (raw) scope values represented by the validated result.\n    /// </summary>\n    public IEnumerable<string> RawScopeValues => ParsedScopes.Select(x => x.RawValue);\n\n    /// <summary>\n    /// The requested scopes that are invalid.\n    /// </summary>\n    public ICollection<string> InvalidScopes { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Returns new result filted by the scope values.\n    /// </summary>\n    /// <param name=\"scopeValues\"></param>\n    /// <returns></returns>\n    public ResourceValidationResult Filter(IEnumerable<string> scopeValues)\n    {\n        scopeValues ??= Enumerable.Empty<string>();\n\n        var offline = scopeValues.Contains(IdentityServerConstants.StandardScopes.OfflineAccess);\n\n        var parsedScopesToKeep = ParsedScopes.Where(x => scopeValues.Contains(x.RawValue)).ToArray();\n        var parsedScopeNamesToKeep = parsedScopesToKeep.Select(x => x.ParsedName).ToArray();\n\n        var identityToKeep = Resources.IdentityResources.Where(x => parsedScopeNamesToKeep.Contains(x.Name));\n        var apiScopesToKeep = Resources.ApiScopes.Where(x => parsedScopeNamesToKeep.Contains(x.Name));\n\n        var apiScopesNamesToKeep = apiScopesToKeep.Select(x => x.Name).ToArray();\n        var apiResourcesToKeep = Resources.ApiResources.Where(x => x.Scopes.Any(y => apiScopesNamesToKeep.Contains(y)));\n\n        var resources = new Resources(identityToKeep, apiResourcesToKeep, apiScopesToKeep)\n        {\n            OfflineAccess = offline\n        };\n        \n        return new ResourceValidationResult()\n        {\n            Resources = resources,\n            ParsedScopes = parsedScopesToKeep\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ScopeSecretValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for API validation\n/// </summary>\npublic class ApiSecretValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Gets or sets the resource.\n    /// </summary>\n    /// <value>\n    /// The resource.\n    /// </value>\n    public ApiResource Resource { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/SecretValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for secrets\n/// </summary>\npublic class SecretValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Gets or sets a value indicating whether the secret validation was successful.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if success; otherwise, <c>false</c>.\n    /// </value>\n    public bool Success { get; set; }\n\n    /// <summary>\n    /// Gets or sets the value of the confirmation method (will become the cnf claim). Must be a JSON object.\n    /// </summary>\n    /// <value>\n    /// The confirmation.\n    /// </value>\n    public string Confirmation { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/TokenRequestValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for token requests\n/// </summary>\npublic class TokenRequestValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenRequestValidationResult\"/> class.\n    /// </summary>\n    /// <param name=\"validatedRequest\">The validated request.</param>\n    /// <param name=\"customResponse\">The custom response.</param>\n    public TokenRequestValidationResult(ValidatedTokenRequest validatedRequest, Dictionary<string, object> customResponse = null)\n    {\n        IsError = false;\n\n        ValidatedRequest = validatedRequest;\n        CustomResponse = customResponse;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"TokenRequestValidationResult\"/> class.\n    /// </summary>\n    /// <param name=\"validatedRequest\">The validated request.</param>\n    /// <param name=\"error\">The error.</param>\n    /// <param name=\"errorDescription\">The error description.</param>\n    /// <param name=\"customResponse\">The custom response.</param>\n    public TokenRequestValidationResult(ValidatedTokenRequest validatedRequest, string error, string errorDescription = null, Dictionary<string, object> customResponse = null)\n    {\n        IsError = true;\n\n        Error = error;\n        ErrorDescription = errorDescription;\n        ValidatedRequest = validatedRequest;\n        CustomResponse = customResponse;\n    }\n\n    /// <summary>\n    /// Gets the validated request.\n    /// </summary>\n    /// <value>\n    /// The validated request.\n    /// </value>\n    public ValidatedTokenRequest ValidatedRequest { get; }\n\n    /// <summary>\n    /// Gets or sets the custom response.\n    /// </summary>\n    /// <value>\n    /// The custom response.\n    /// </value>\n    public Dictionary<string, object> CustomResponse { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/TokenRevocationRequestValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models the validation result of access tokens and id tokens.\n/// </summary>\npublic class TokenRevocationRequestValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Gets or sets the token type hint.\n    /// </summary>\n    /// <value>\n    /// The token type hint.\n    /// </value>\n    public string TokenTypeHint { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the token.\n    /// </summary>\n    /// <value>\n    /// The token.\n    /// </value>\n    public string Token { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client.\n    /// </summary>\n    /// <value>\n    /// The client.\n    /// </value>\n    public Client Client { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/TokenValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models the validation result of access tokens and id tokens.\n/// </summary>\npublic class TokenValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Gets or sets the claims.\n    /// </summary>\n    /// <value>\n    /// The claims.\n    /// </value>\n    public IEnumerable<Claim> Claims { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the JWT.\n    /// </summary>\n    /// <value>\n    /// The JWT.\n    /// </value>\n    public string Jwt { get; set; }\n\n    /// <summary>\n    /// Gets or sets the reference token (in case of access token validation).\n    /// </summary>\n    /// <value>\n    /// The reference token.\n    /// </value>\n    public Token ReferenceToken { get; set; }\n\n    /// <summary>\n    /// Gets or sets the reference token identifier (in case of access token validation).\n    /// </summary>\n    /// <value>\n    /// The reference token identifier.\n    /// </value>\n    public string ReferenceTokenId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the refresh token (in case of refresh token validation).\n    /// </summary>\n    /// <value>\n    /// The reference token identifier.\n    /// </value>\n    public RefreshToken RefreshToken { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client.\n    /// </summary>\n    /// <value>\n    /// The client.\n    /// </value>\n    public Client Client { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/UserInfoRequestValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Validation result for userinfo requests\n/// </summary>\npublic class UserInfoRequestValidationResult : ValidationResult\n{\n    /// <summary>\n    /// Gets or sets the token validation result.\n    /// </summary>\n    /// <value>\n    /// The token validation result.\n    /// </value>\n    public TokenValidationResult TokenValidationResult { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject.\n    /// </summary>\n    /// <value>\n    /// The subject.\n    /// </value>\n    public ClaimsPrincipal Subject { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ValidatedAuthorizeRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models a validated request to the authorize endpoint.\n/// </summary>\npublic class ValidatedAuthorizeRequest : ValidatedRequest\n{\n    /// <summary>\n    /// Gets or sets the type of the response.\n    /// </summary>\n    /// <value>\n    /// The type of the response.\n    /// </value>\n    public string ResponseType { get; set; }\n\n    /// <summary>\n    /// Gets or sets the response mode.\n    /// </summary>\n    /// <value>\n    /// The response mode.\n    /// </value>\n    public string ResponseMode { get; set; }\n\n    /// <summary>\n    /// Gets or sets the grant type.\n    /// </summary>\n    /// <value>\n    /// The grant type.\n    /// </value>\n    public string GrantType { get; set; }\n\n    /// <summary>\n    /// Gets or sets the redirect URI.\n    /// </summary>\n    /// <value>\n    /// The redirect URI.\n    /// </value>\n    public string RedirectUri { get; set; }\n\n    /// <summary>\n    /// Gets or sets the requested scopes.\n    /// </summary>\n    /// <value>\n    /// The requested scopes.\n    /// </value>\n    // todo: consider replacing with extension method to access Raw collection; would neeed to be done wholesale for all props.\n    public List<string> RequestedScopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether consent was shown.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if consent was shown; otherwise, <c>false</c>.\n    /// </value>\n    public bool WasConsentShown { get; set; }\n\n    /// <summary>\n    /// Gets the description the user assigned to the device being authorized.\n    /// </summary>\n    /// <value>\n    /// The description.\n    /// </value>\n    public string Description { get; set; }\n\n    /// <summary>\n    /// Gets or sets the state.\n    /// </summary>\n    /// <value>\n    /// The state.\n    /// </value>\n    public string State { get; set; }\n\n    /// <summary>\n    /// Gets or sets the UI locales.\n    /// </summary>\n    /// <value>\n    /// The UI locales.\n    /// </value>\n    public string UiLocales { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the request was an OpenID Connect request.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the request was an OpenID Connect request; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsOpenIdRequest { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether this instance is API resource request.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if this instance is API resource request; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsApiResourceRequest { get; set; }\n\n    /// <summary>\n    /// Gets or sets the nonce.\n    /// </summary>\n    /// <value>\n    /// The nonce.\n    /// </value>\n    public string Nonce { get; set; }\n\n    /// <summary>\n    /// Gets or sets the authentication context reference classes.\n    /// </summary>\n    /// <value>\n    /// The authentication context reference classes.\n    /// </value>\n    public List<string> AuthenticationContextReferenceClasses { get; set; }\n\n    /// <summary>\n    /// Gets or sets the display mode.\n    /// </summary>\n    /// <value>\n    /// The display mode.\n    /// </value>\n    public string DisplayMode { get; set; }\n\n    /// <summary>\n    /// Gets or sets the collection of prompt modes.\n    /// </summary>\n    /// <value>\n    /// The collection of prompt modes.\n    /// </value>\n    public IEnumerable<string> PromptModes { get; set; } = Enumerable.Empty<string>();\n\n    /// <summary>\n    /// Gets or sets the maximum age.\n    /// </summary>\n    /// <value>\n    /// The maximum age.\n    /// </value>\n    public int? MaxAge { get; set; }\n\n    /// <summary>\n    /// Gets or sets the login hint.\n    /// </summary>\n    /// <value>\n    /// The login hint.\n    /// </value>\n    public string LoginHint { get; set; }\n\n    /// <summary>\n    /// Gets or sets the code challenge\n    /// </summary>\n    /// <value>\n    /// The code challenge\n    /// </value>\n    public string CodeChallenge { get; set; }\n\n    /// <summary>\n    /// Gets or sets the code challenge method\n    /// </summary>\n    /// <value>\n    /// The code challenge method\n    /// </value>\n    public string CodeChallengeMethod { get; set; }\n\n    /// <summary>\n    /// Gets or sets the validated contents of the request object (if present)\n    /// </summary>\n    /// <value>\n    /// The request object values\n    /// </value>\n    public Dictionary<string, string> RequestObjectValues { get; set; } = new Dictionary<string, string>();\n\n    /// <summary>\n    /// Gets or sets the request object (either passed by value or retrieved by reference)\n    /// </summary>\n    /// <value>\n    /// The request object\n    /// </value>\n    public string RequestObject { get; set; }\n    \n    /// <summary>\n    /// Gets a value indicating whether an access token was requested.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if an access token was requested; otherwise, <c>false</c>.\n    /// </value>\n    public bool AccessTokenRequested => ResponseType == OidcConstants.ResponseTypes.IdTokenToken ||\n                                        ResponseType == OidcConstants.ResponseTypes.Code ||\n                                        ResponseType == OidcConstants.ResponseTypes.CodeIdToken ||\n                                        ResponseType == OidcConstants.ResponseTypes.CodeToken ||\n                                        ResponseType == OidcConstants.ResponseTypes.CodeIdTokenToken;\n\n\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ValidatedAuthorizeRequest\"/> class.\n    /// </summary>\n    public ValidatedAuthorizeRequest()\n    {\n        RequestedScopes = new List<string>();\n        AuthenticationContextReferenceClasses = new List<string>();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ValidatedDeviceAuthorizationRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models a validated request to the device authorization endpoint.\n/// </summary>\npublic class ValidatedDeviceAuthorizationRequest : ValidatedRequest\n{\n    /// <summary>\n    /// Gets or sets the requested scopes.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public IEnumerable<string> RequestedScopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether this instance is open identifier request.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if this instance is open identifier request; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsOpenIdRequest { get; set; }\n\n    /// <summary>\n    /// Gets the description the user assigned to the device being authorized.\n    /// </summary>\n    /// <value>\n    /// The description.\n    /// </value>\n    public string Description { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ValidatedEndSessionRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Represents a validated end session (logout) request\n/// </summary>\npublic class ValidatedEndSessionRequest : ValidatedRequest\n{\n    /// <summary>\n    /// Gets a value indicating whether this instance is authenticated.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if this instance is authenticated; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsAuthenticated => Client != null;\n\n    /// <summary>\n    /// Gets or sets the post-logout URI.\n    /// </summary>\n    /// <value>\n    /// The post-logout URI.\n    /// </value>\n    public string PostLogOutUri { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the state.\n    /// </summary>\n    /// <value>\n    /// The state.\n    /// </value>\n    public string State { get; set; }\n\n    /// <summary>\n    ///  Ids of clients known to have an authentication session for user at end session time\n    /// </summary>\n    public IEnumerable<string> ClientIds { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ValidatedRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Base class for a validate authorize or token request\n/// </summary>\npublic class ValidatedRequest\n{\n    /// <summary>\n    /// Gets or sets the raw request data\n    /// </summary>\n    /// <value>\n    /// The raw.\n    /// </value>\n    public NameValueCollection Raw { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client.\n    /// </summary>\n    /// <value>\n    /// The client.\n    /// </value>\n    public Client Client { get; set; }\n\n    /// <summary>\n    /// Gets or sets the secret used to authenticate the client.\n    /// </summary>\n    /// <value>\n    /// The parsed secret.\n    /// </value>\n    public ParsedSecret Secret { get; set; }\n\n    /// <summary>\n    /// Gets or sets the effective access token lifetime for the current request.\n    /// This value is initally read from the client configuration but can be modified in the request pipeline\n    /// </summary>\n    public int AccessTokenLifetime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client claims for the current request.\n    /// This value is initally read from the client configuration but can be modified in the request pipeline\n    /// </summary>\n    public ICollection<Claim> ClientClaims { get; set; } = new HashSet<Claim>(new ClaimComparer());\n\n    /// <summary>\n    /// Gets or sets the effective access token type for the current request.\n    /// This value is initally read from the client configuration but can be modified in the request pipeline\n    /// </summary>\n    public AccessTokenType AccessTokenType { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject.\n    /// </summary>\n    /// <value>\n    /// The subject.\n    /// </value>\n    public ClaimsPrincipal Subject { get; set; }\n\n    /// <summary>\n    /// Gets or sets the session identifier.\n    /// </summary>\n    /// <value>\n    /// The session identifier.\n    /// </value>\n    public string SessionId { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the identity server options.\n    /// </summary>\n    /// <value>\n    /// The options.\n    /// </value>\n    public IdentityServerOptions Options { get; set; }\n\n    /// <summary>\n    /// Gets or sets the validated resources for the request.\n    /// </summary>\n    /// <value>\n    /// The validated resources.\n    /// </value>\n    public ResourceValidationResult ValidatedResources { get; set; } = new ResourceValidationResult();\n\n    /// <summary>\n    /// Gets or sets the value of the confirmation method (will become the cnf claim). Must be a JSON object.\n    /// </summary>\n    /// <value>\n    /// The confirmation.\n    /// </value>\n    public string Confirmation { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client ID that should be used for the current request (this is useful for token exchange scenarios)\n    /// </summary>\n    /// <value>\n    /// The client ID\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Sets the client and the appropriate request specific settings.\n    /// </summary>\n    /// <param name=\"client\">The client.</param>\n    /// <param name=\"secret\">The client secret (optional).</param>\n    /// <param name=\"confirmation\">The confirmation.</param>\n    /// <exception cref=\"ArgumentNullException\">client</exception>\n    public void SetClient(Client client, ParsedSecret secret = null, string confirmation = \"\")\n    {\n        Client = client ?? throw new ArgumentNullException(nameof(client));\n        Secret = secret;\n        Confirmation = confirmation;\n        ClientId = client.ClientId;\n\n        AccessTokenLifetime = client.AccessTokenLifetime;\n        AccessTokenType = client.AccessTokenType;\n        ClientClaims = client.Claims.Select(c => new Claim(c.Type, c.Value, c.ValueType)).ToList();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ValidatedTokenRequest.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Models a validated request to the token endpoint.\n/// </summary>\npublic class ValidatedTokenRequest : ValidatedRequest\n{\n    /// <summary>\n    /// Gets or sets the type of the grant.\n    /// </summary>\n    /// <value>\n    /// The type of the grant.\n    /// </value>\n    public string GrantType { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the scopes.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public IEnumerable<string> RequestedScopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the username used in the request.\n    /// </summary>\n    /// <value>\n    /// The name of the user.\n    /// </value>\n    public string UserName { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the refresh token.\n    /// </summary>\n    /// <value>\n    /// The refresh token.\n    /// </value>\n    public RefreshToken RefreshToken { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the refresh token handle.\n    /// </summary>\n    /// <value>\n    /// The refresh token handle.\n    /// </value>\n    public string RefreshTokenHandle { get; set; }\n\n    /// <summary>\n    /// Gets or sets the authorization code.\n    /// </summary>\n    /// <value>\n    /// The authorization code.\n    /// </value>\n    public AuthorizationCode AuthorizationCode { get; set; }\n\n    /// <summary>\n    /// Gets or sets the authorization code handle.\n    /// </summary>\n    /// <value>\n    /// The authorization code handle.\n    /// </value>\n    public string AuthorizationCodeHandle { get; set; }\n\n    /// <summary>\n    /// Gets or sets the code verifier.\n    /// </summary>\n    /// <value>\n    /// The code verifier.\n    /// </value>\n    public string CodeVerifier { get; set; }\n\n    /// <summary>\n    /// Gets or sets the device code.\n    /// </summary>\n    /// <value>\n    /// The device code.\n    /// </value>\n    public DeviceCode DeviceCode { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/src/Validation/Models/ValidationResult.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Validation;\n\n/// <summary>\n/// Minimal validation result class (base-class for more complext validation results)\n/// </summary>\npublic class ValidationResult\n{\n    /// <summary>\n    /// Gets or sets a value indicating whether the validation was successful.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if the validation is failed; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsError { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets the error.\n    /// </summary>\n    /// <value>\n    /// The error.\n    /// </value>\n    public string Error { get; set; }\n\n    /// <summary>\n    /// Gets or sets the error description.\n    /// </summary>\n    /// <value>\n    /// The error description.\n    /// </value>\n    public string ErrorDescription { get; set; }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/ClientAssertionClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing IdentityServer.IntegrationTests.Common;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing Microsoft.IdentityModel.Tokens;\nusing System.IdentityModel.Tokens.Jwt;\nusing System.Security.Claims;\nusing System.Text;\nusing System.Text.Json;\nusing Xunit;\n\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class ClientAssertionClient\n{\n    private const string TokenEndpoint = \"https://idsvr8/connect/token\";\n    private const string ClientId = \"certificate_base64_valid\";\n\n    private readonly HttpClient _client;\n\n    public ClientAssertionClient()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Valid_client_with_manual_payload_should_succeed()\n    {\n        var token = CreateToken(ClientId);\n        var requestBody = new FormUrlEncodedContent(new Dictionary<string, string>\n            {\n                { \"client_id\", ClientId },\n                { \"client_assertion_type\", \"urn:ietf:params:oauth:client-assertion-type:jwt-bearer\" },\n                { \"client_assertion\", token },\n                { \"grant_type\", \"client_credentials\" },\n                { \"scope\", \"api1\" }\n            });\n\n        var response = await GetToken(requestBody);\n\n        AssertValidToken(response);\n    }\n\n    [Fact]\n    public async Task Valid_client_should_succeed()\n    {\n        var token = CreateToken(ClientId);\n\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientCredentialStyle = ClientCredentialStyle.PostBody,\n            GrantType = \"client_credentials\",\n            ClientId = ClientId,\n            ClientAssertion =\n            {\n                Type = OidcConstants.ClientAssertionTypes.JwtBearer,\n                Value = token\n            },\n\n            Scope = \"api1\"\n        });\n\n        AssertValidToken(response);\n    }\n\n    [Fact]\n    public async Task Valid_client_with_implicit_clientId_should_succeed()\n    {\n        var token = CreateToken(ClientId);\n\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientCredentialStyle = ClientCredentialStyle.PostBody,\n            GrantType = \"client_credentials\",\n            ClientAssertion =\n            {\n                Type = OidcConstants.ClientAssertionTypes.JwtBearer,\n                Value = token\n            },\n\n            Scope = \"api1\"\n        });\n\n        AssertValidToken(response);\n    }\n\n    [Fact]\n    public async Task Valid_client_with_token_replay_should_fail()\n    {\n        var token = CreateToken(ClientId);\n\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientCredentialStyle = ClientCredentialStyle.PostBody,\n            GrantType = \"client_credentials\",\n            ClientId = ClientId,\n            ClientAssertion =\n            {\n                Type = OidcConstants.ClientAssertionTypes.JwtBearer,\n                Value = token\n            },\n\n            Scope = \"api1\"\n        });\n\n        AssertValidToken(response);\n\n        // replay\n        response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientCredentialStyle = ClientCredentialStyle.PostBody,\n            GrantType = \"client_credentials\",\n            ClientId = ClientId,\n            ClientAssertion =\n            {\n                Type = OidcConstants.ClientAssertionTypes.JwtBearer,\n                Value = token\n            },\n\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().BeTrue();\n        response.Error.Should().Be(\"invalid_client\");\n    }\n\n    [Fact]\n    public async Task Client_with_invalid_secret_should_fail()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"client_credentials\",\n            ClientCredentialStyle = ClientCredentialStyle.PostBody,\n            ClientId = ClientId,\n\n            ClientAssertion =\n            {\n                Type = OidcConstants.ClientAssertionTypes.JwtBearer,\n                Value = \"invalid\"\n            },\n\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.Error.Should().Be(OidcConstants.TokenErrors.InvalidClient);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n    }\n\n    [Fact]\n    public async Task Invalid_client_should_fail()\n    {\n        const string clientId = \"certificate_base64_invalid\";\n        var token = CreateToken(clientId);\n\n        var tokenRequest = new ClientCredentialsTokenRequest();\n        tokenRequest.Address = TokenEndpoint;\n        tokenRequest.ClientId = clientId;\n        tokenRequest.GrantType = \"client_credentials\";\n        tokenRequest.ClientAssertion.Type = OidcConstants.ClientAssertionTypes.JwtBearer;\n        tokenRequest.ClientAssertion.Value = token;\n        tokenRequest.Scope = \"api1\";\n        tokenRequest.ClientCredentialStyle = ClientCredentialStyle.PostBody;\n        var response = await _client.RequestTokenAsync(tokenRequest);\n\n\n        response.IsError.Should().Be(true);\n        response.Error.Should().Be(OidcConstants.TokenErrors.InvalidClient);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n    }\n\n    private async Task<TokenResponse> GetToken(FormUrlEncodedContent body)\n    {\n        var response = await _client.PostAsync(TokenEndpoint, body);\n        return await ProtocolResponse.FromHttpResponseAsync<TokenResponse>(response);\n    }\n\n    private void AssertValidToken(TokenResponse response)\n    {\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(8);\n\n        payload.Keys.Should().Contain(\"iss\");\n        payload.Keys.Should().Contain(\"client_id\");\n\n        payload[\"iss\"].ValueKind.Should().Be(JsonValueKind.String);\n        payload[\"client_id\"].ValueKind.Should().Be(JsonValueKind.String);\n        payload[\"iss\"].ToString().Should().Be(\"https://idsvr8\");\n        payload[\"client_id\"].ToString().Should().Be(ClientId);\n\n\n\n        payload[\"scope\"].ValueKind.Should().Be(JsonValueKind.Array);\n\n\n        var scopes = payload[\"scope\"].EnumerateArray();\n        scopes.First().ToString().Should().Be(\"api1\");\n\n        payload[\"aud\"].ToString().Should().Be(\"api\");\n    }\n\n    private Dictionary<string, JsonElement> GetPayload(TokenResponse response)\n    {\n        var token = response.AccessToken.Split('.').Skip(1).Take(1).First();\n        var dictionary = JsonSerializer.Deserialize<Dictionary<string, JsonElement>>(\n            Encoding.UTF8.GetString(Base64Url.Decode(token)));\n\n        return dictionary;\n    }\n\n    private string CreateToken(string clientId, DateTime? nowOverride = null)\n    {\n        var certificate = TestCert.Load();\n        var now = nowOverride ?? DateTime.UtcNow;\n\n        var token = new JwtSecurityToken(\n                clientId,\n                TokenEndpoint,\n                new List<Claim>()\n                {\n                    new Claim(\"jti\", Guid.NewGuid().ToString()),\n                    new Claim(JwtClaimTypes.Subject, clientId),\n                    new Claim(JwtClaimTypes.IssuedAt, new DateTimeOffset(now).ToUnixTimeSeconds().ToString(), ClaimValueTypes.Integer64)\n                },\n                now,\n                now.AddMinutes(1),\n                new SigningCredentials(\n                    new X509SecurityKey(certificate),\n                    SecurityAlgorithms.RsaSha256\n                )\n            );\n\n        var tokenHandler = new JwtSecurityTokenHandler();\n        return tokenHandler.WriteToken(token);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/ClientCredentialsAndResourceOwnerClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class ClientCredentialsandResourceOwnerClient\n{\n    private const string TokenEndpoint = \"https://server/connect/token\";\n\n    private readonly HttpClient _client;\n\n    public ClientCredentialsandResourceOwnerClient()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Resource_scope_should_be_requestable_via_client_credentials()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client.and.ro\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().Be(false);\n    }\n\n    [Fact]\n    public async Task Openid_scope_should_not_be_requestable_via_client_credentials()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client.and.ro\",\n            ClientSecret = \"secret\",\n            Scope = \"openid api1\"\n        });\n\n        response.IsError.Should().Be(true);\n    }\n\n    [Fact]\n    public async Task Openid_scope_should_be_requestable_via_password()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client.and.ro\",\n            ClientSecret = \"secret\",\n            Scope = \"openid\",\n\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().Be(false);\n    }\n\n    [Fact]\n    public async Task Openid_and_resource_scope_should_be_requestable_via_password()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client.and.ro\",\n            ClientSecret = \"secret\",\n            Scope = \"openid api1\",\n\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().Be(false);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/ClientCredentialsClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing System.Net;\nusing System.Text;\nusing System.Text.Json;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class ClientCredentialsClient\n{\n    private const string TokenEndpoint = \"https://server/connect/token\";\n\n    private readonly HttpClient _client;\n\n    public ClientCredentialsClient()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Invalid_endpoint_should_return_404()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint + \"invalid\",\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Http);\n        response.Error.Should().Be(\"Not Found\");\n        response.HttpStatusCode.Should().Be(HttpStatusCode.NotFound);\n    }\n\n    [Fact]\n    public async Task Valid_request_single_audience_should_return_expected_payload()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(8);\n\n        payload[\"iss\"].ToString().Should().Be(\"https://idsvr8\");\n        payload[\"client_id\"].ToString().Should().Be(\"client\");\n\n        payload[\"aud\"].ToString().Should().Be(\"api\");\n        payload.Keys.Should().Contain(\"jti\");\n        payload.Keys.Should().Contain(\"iat\");\n        \n        payload[\"aud\"].ToString().Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"].EnumerateArray().Select(x => x.GetString());\n        scopes.First().ToString().Should().Be(\"api1\");\n    }\n\n    [Fact]\n    public async Task Valid_request_multiple_audiences_should_return_expected_payload()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"api1 other_api\"\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(8);\n\n        payload[\"iss\"].ToString().Should().Be(\"https://idsvr8\");\n        payload[\"client_id\"].ToString().Should().Be(\"client\");\n\n     \n        payload.Keys.Should().Contain(\"jti\");\n        payload.Keys.Should().Contain(\"iat\");\n\n        var audiences = payload[\"aud\"].EnumerateArray().Select(x => x.GetString());\n        audiences.Count().Should().Be(2);\n        audiences.Should().Contain(\"api\");\n        audiences.Should().Contain(\"other_api\");\n\n        var scopes = payload[\"scope\"].EnumerateArray().Select(x => x.ToString());\n        scopes.First().ToString().Should().Be(\"api1\");\n    }\n\n    [Fact]\n    public async Task Valid_request_with_confirmation_should_return_expected_payload()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client.cnf\",\n            ClientSecret = \"foo\",\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(9);\n\n\n        payload[\"iss\"].ToString().Should().Be(\"https://idsvr8\");\n        payload[\"client_id\"].ToString().Should().Be(\"client.cnf\");\n\n        payload[\"aud\"].ToString().Should().Be(\"api\");\n\n\n        payload.Keys.Should().Contain(\"jti\");\n        payload.Keys.Should().Contain(\"iat\");\n\n\n\n        var scopes = payload[\"scope\"].EnumerateArray().Select(x => x.GetString());\n        scopes.First().ToString().Should().Be(\"api1\");\n\n        payload[\"cnf\"].ValueKind.Should().Be(JsonValueKind.Array);\n        var cnfArray = payload[\"cnf\"].EnumerateArray().ToList();\n        cnfArray.Count.Should().Be(1);\n        var elArray= cnfArray.First().EnumerateArray().ToList();\n        elArray.Count.Should().Be(1);\n        elArray.First().GetString().Should().Be(\"foo\");\n\n    }\n\n    [Fact]\n    public async Task Requesting_multiple_scopes_should_return_expected_payload()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"api1 api2\"\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(8);\n\n        payload[\"iss\"].ToString().Should().Be(\"https://idsvr8\");\n        payload[\"client_id\"].ToString().Should().Be(\"client\");\n\n        payload[\"aud\"].ToString().Should().Be(\"api\");\n        payload.Keys.Should().Contain(\"jti\");\n        payload.Keys.Should().Contain(\"iat\");\n        \n\n\n        var scopes = payload[\"scope\"].EnumerateArray().Select(x => x.GetString());\n        scopes.Count().Should().Be(2);\n        scopes.First().ToString().Should().Be(\"api1\");\n        scopes.Skip(1).First().ToString().Should().Be(\"api2\");\n    }\n\n    [Fact]\n    public async Task Request_with_no_explicit_scopes_should_return_expected_payload()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientSecret = \"secret\"\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(8);\n\n\n\n        payload[\"iss\"].ToString().Should().Be(\"https://idsvr8\");\n        payload[\"client_id\"].ToString().Should().Be(\"client\");\n\n\n\n        var scopes = payload[\"scope\"].EnumerateArray().Select(x => x.GetString());\n\n\n        payload.Keys.Should().Contain(\"jti\");\n        payload.Keys.Should().Contain(\"iat\");\n\n        var audiences = payload[\"aud\"].EnumerateArray().Select(x=> x.GetString());\n        audiences.Count().Should().Be(2);\n        audiences.Should().Contain(\"api\");\n        audiences.Should().Contain(\"other_api\");\n\n\n        scopes.Count().Should().Be(3);\n        scopes.Should().Contain(\"api1\");\n        scopes.Should().Contain(\"api2\");\n        scopes.Should().Contain(\"other_api\");\n    }\n\n    [Fact]\n    public async Task Client_without_default_scopes_skipping_scope_parameter_should_return_error()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client.no_default_scopes\",\n            ClientSecret = \"secret\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ExpiresIn.Should().Be(0);\n        response.TokenType.Should().BeNull();\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n        response.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n    }\n\n    [Fact]\n    public async Task Request_posting_client_secret_in_body_should_succeed()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\",\n\n            ClientCredentialStyle = ClientCredentialStyle.PostBody\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n\n        payload[\"iss\"].ToString().Should().Be(\"https://idsvr8\");\n        payload[\"client_id\"].ToString().Should().Be(\"client\");\n\n        payload[\"aud\"].ToString().Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"].EnumerateArray();\n        scopes.First().ToString().Should().Be(\"api1\");\n    }\n\n\n    [Fact]\n    public async Task Request_For_client_with_no_secret_and_basic_authentication_should_succeed()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client.no_secret\",\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n        \n        payload[\"iss\"].ToString().Should().Be(\"https://idsvr8\");\n        payload[\"client_id\"].ToString().Should().Be(\"client.no_secret\");\n\n        var scopes = payload[\"scope\"].EnumerateArray();\n        scopes.First().ToString().Should().Be(\"api1\");\n    }\n\n    [Fact]\n    public async Task Request_with_invalid_client_secret_should_fail()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientSecret = \"invalid\",\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.Error.Should().Be(\"invalid_client\");\n    }\n\n    [Fact]\n    public async Task Unknown_client_should_fail()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"invalid\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"invalid_client\");\n    }\n\n    [Fact]\n    public async Task Implicit_client_should_not_use_client_credential_grant()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"implicit\",\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"unauthorized_client\");\n    }\n\n    [Fact]\n    public async Task Implicit_and_client_creds_client_should_not_use_client_credential_grant_without_secret()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"implicit_and_client_creds\",\n            ClientSecret = \"invalid\",\n            Scope = \"api1\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"invalid_client\");\n    }\n\n\n    [Fact]\n    public async Task Requesting_unknown_scope_should_fail()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"unknown\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"invalid_scope\");\n    }\n\n    [Fact]\n    public async Task Client_explicitly_requesting_identity_scope_should_fail()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client.identityscopes\",\n            ClientSecret = \"secret\",\n            Scope = \"openid api1\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"invalid_scope\");\n    }\n\n    [Fact]\n    public async Task Client_explicitly_requesting_offline_access_should_fail()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"api1 offline_access\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"invalid_scope\");\n    }\n\n    [Fact]\n    public async Task Requesting_unauthorized_scope_should_fail()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"api3\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"invalid_scope\");\n    }\n\n    [Fact]\n    public async Task Requesting_authorized_and_unauthorized_scopes_should_fail()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"api1 api3\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"invalid_scope\");\n    }\n\n    private Dictionary<string, JsonElement> GetPayload(TokenResponse response)\n    {\n        var token = response.AccessToken.Split('.').Skip(1).Take(1).First();\n        var dictionary = JsonSerializer.Deserialize<Dictionary<string, JsonElement>>(\n            Encoding.UTF8.GetString(Base64Url.Decode(token)));\n\n        return dictionary;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/CustomTokenRequestValidatorClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing IdentityServer8.Extensions;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing System.Text.Json;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class CustomTokenRequestValidatorClient\n{\n    private const string TokenEndpoint = \"https://server/connect/token\";\n\n    private readonly HttpClient _client;\n\n    public CustomTokenRequestValidatorClient()\n    {\n        var val = new TestCustomTokenRequestValidator();\n        Startup.CustomTokenRequestValidator = val;\n\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Client_credentials_request_should_contain_custom_response()\n    {\n        var response = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n\n            ClientId = \"client\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\"\n        });\n        ValidateCustomFields(response);\n    }\n\n    [Fact]\n    public async Task Resource_owner_credentials_request_should_contain_custom_response()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\",\n\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        ValidateCustomFields(response);\n    }\n\n    [Fact]\n    public async Task Refreshing_a_token_should_contain_custom_response()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n            Scope = \"api1 offline_access\",\n\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response = await _client.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            RefreshToken = response.RefreshToken\n        });\n\n        ValidateCustomFields(response);\n    }\n\n    [Fact]\n    public async Task Extension_grant_request_should_contain_custom_response()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"custom\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api1\" },\n                { \"custom_credential\", \"custom credential\"}\n            }\n        });\n\n        ValidateCustomFields(response);\n    }\n\n     private Dictionary<string, JsonElement> GetFields(JsonElement json)\n    {\n        return json.ToObject<Dictionary<string, JsonElement>>();\n    }\n    private void ValidateCustomFields(TokenResponse response)\n    {\n        var fields = GetFields(response.Json);\n        fields[\"custom\"].ToString().Should().Be(\"custom\");\n\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/CustomTokenResponseClients.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing IdentityServer8.Extensions;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing Newtonsoft.Json;\nusing Newtonsoft.Json.Linq;\nusing System.Text;\nusing System.Text.Json;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class CustomTokenResponseClients\n{\n    private const string TokenEndpoint = \"https://server/connect/token\";\n\n    private readonly HttpClient _client;\n\n    public CustomTokenResponseClients()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<StartupWithCustomTokenResponses>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Resource_owner_success_should_return_custom_response()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            UserName = \"bob\",\n            Password = \"bob\",\n            Scope = \"api1\"\n        });\n\n        // raw fields\n        var fields = GetFields(response);\n        fields[\"string_value\"].GetString().Should().Be(\"some_string\");\n        fields[\"int_value\"].GetInt64().Should().Be(42);\n\n        JsonElement temp;\n        fields.TryGetValue(\"identity_token\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"refresh_token\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"error\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"error_description\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"token_type\", out temp).Should().BeTrue();\n        fields.TryGetValue(\"expires_in\", out temp).Should().BeTrue();\n\n        var responseObject = fields[\"dto\"];\n        responseObject.Should().NotBeNull();\n\n        var responseDto = GetDto(responseObject);\n        var dto = CustomResponseDto.Create;\n\n        responseDto.string_value.Should().Be(dto.string_value);\n        responseDto.int_value.Should().Be(dto.int_value);\n        responseDto.nested.string_value.Should().Be(dto.nested.string_value);\n        responseDto.nested.int_value.Should().Be(dto.nested.int_value);\n\n\n        // token client response\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n\n        // token content\n        var payload = GetPayload(response);\n        payload.Count().Should().Be(12);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"roclient\");\n        payload.Should().Contain(\"sub\", \"bob\");\n        payload.Should().Contain(\"idp\", \"local\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"] as JArray;\n        scopes.First().ToString().Should().Be(\"api1\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"password\");\n    }\n\n    [Fact]\n    public async Task Resource_owner_failure_should_return_custom_error_response()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            UserName = \"bob\",\n            Password = \"invalid\",\n            Scope = \"api1\"\n        });\n\n        // raw fields\n        var fields = GetFields(response);\n        fields[\"string_value\"].ToString().Should().Be(\"some_string\");\n        fields[\"int_value\"].GetInt64().Should().Be(42);\n\n        JsonElement temp;\n        fields.TryGetValue(\"identity_token\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"refresh_token\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"error\", out temp).Should().BeTrue();\n        fields.TryGetValue(\"error_description\", out temp).Should().BeTrue();\n        fields.TryGetValue(\"token_type\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"expires_in\", out temp).Should().BeFalse();\n\n        var responseObject = fields[\"dto\"];\n        responseObject.Should().NotBeNull();\n\n        var responseDto = GetDto(responseObject);\n        var dto = CustomResponseDto.Create;\n\n        responseDto.string_value.Should().Be(dto.string_value);\n        responseDto.int_value.Should().Be(dto.int_value);\n        responseDto.nested.string_value.Should().Be(dto.nested.string_value);\n        responseDto.nested.int_value.Should().Be(dto.nested.int_value);\n\n\n        // token client response\n        response.IsError.Should().Be(true);\n        response.Error.Should().Be(\"invalid_grant\");\n        response.ErrorDescription.Should().Be(\"invalid_credential\");\n        response.ExpiresIn.Should().Be(0);\n        response.TokenType.Should().BeNull();\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n    }\n\n    [Fact]\n    public async Task Extension_grant_success_should_return_custom_response()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"custom\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api1\" },\n                { \"outcome\", \"succeed\"}\n            }\n        });\n\n\n        // raw fields\n        var fields = GetFields(response);\n        fields[\"string_value\"].ToString().Should().Be(\"some_string\");\n        fields[\"int_value\"].GetInt64().Should().Be(42);\n\n        JsonElement temp;\n        fields.TryGetValue(\"identity_token\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"refresh_token\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"error\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"error_description\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"token_type\", out temp).Should().BeTrue();\n        fields.TryGetValue(\"expires_in\", out temp).Should().BeTrue();\n\n        var responseObject = fields[\"dto\"];\n        responseObject.Should().NotBeNull();\n\n        var responseDto = GetDto(responseObject);\n        var dto = CustomResponseDto.Create;\n\n        responseDto.string_value.Should().Be(dto.string_value);\n        responseDto.int_value.Should().Be(dto.int_value);\n        responseDto.nested.string_value.Should().Be(dto.nested.string_value);\n        responseDto.nested.int_value.Should().Be(dto.nested.int_value);\n\n\n        // token client response\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n\n        // token content\n        var payload = GetPayload(response);\n        payload.Count().Should().Be(12);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"client.custom\");\n        payload.Should().Contain(\"sub\", \"bob\");\n        payload.Should().Contain(\"idp\", \"local\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"] as JArray;\n        scopes.First().ToString().Should().Be(\"api1\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"custom\");\n\n    }\n\n    [Fact]\n    public async Task Extension_grant_failure_should_return_custom_error_response()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"custom\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api1\" },\n                { \"outcome\", \"fail\"}\n            }\n        });\n\n        var s = response.Json.ToString();\n        var fd = GetFieldsD(response);\n        // raw fields\n        var fields = GetFields(response);\n        fields[\"string_value\"].ToString().Should().Be(\"some_string\");\n        fields[\"int_value\"].GetInt64().Should().Be(42);\n\n        JsonElement temp;\n        fields.TryGetValue(\"identity_token\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"refresh_token\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"error\", out temp).Should().BeTrue();\n        fields.TryGetValue(\"error_description\", out temp).Should().BeTrue();\n        fields.TryGetValue(\"token_type\", out temp).Should().BeFalse();\n        fields.TryGetValue(\"expires_in\", out temp).Should().BeFalse();\n\n        var responseObject = fields[\"dto\"];\n        responseObject.Should().NotBeNull();\n\n        var responseDto = GetDto(responseObject);\n        var dto = CustomResponseDto.Create;\n\n        responseDto.string_value.Should().Be(dto.string_value);\n        responseDto.int_value.Should().Be(dto.int_value);\n        responseDto.nested.string_value.Should().Be(dto.nested.string_value);\n        responseDto.nested.int_value.Should().Be(dto.nested.int_value);\n\n\n        // token client response\n        response.IsError.Should().Be(true);\n        response.Error.Should().Be(\"invalid_grant\");\n        response.ErrorDescription.Should().Be(\"invalid_credential\");\n        response.ExpiresIn.Should().Be(0);\n        response.TokenType.Should().BeNull();\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n    }\n\n    private CustomResponseDto GetDto(JsonElement responseObject)\n    {\n        return responseObject.ToObject<CustomResponseDto>();\n    }\n\n    private Dictionary<string, object> GetFieldsD(TokenResponse response)\n    {\n        return response.Json.ToObject<Dictionary<string, object>>();\n    }\n\n\n    private Dictionary<string, JsonElement> GetFields(TokenResponse response)\n    {\n        return GetFields(response.Json);\n    }\n\n    private Dictionary<string, JsonElement> GetFields(JsonElement json)\n    {\n        return json.ToObject<Dictionary<string, JsonElement>>();\n    }\n\n    private Dictionary<string, object> GetPayload(TokenResponse response)\n    {\n        var token = response.AccessToken.Split('.').Skip(1).Take(1).First();\n        var dictionary = JsonConvert.DeserializeObject<Dictionary<string, object>>(\n            Encoding.UTF8.GetString(Base64Url.Decode(token)));\n\n        return dictionary;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/DiscoveryClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class DiscoveryClientTests\n{\n    private const string DiscoveryEndpoint = \"https://server/.well-known/openid-configuration\";\n\n    private readonly HttpClient _client;\n\n    public DiscoveryClientTests()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Discovery_document_should_have_expected_values()\n    {\n        var doc = await _client.GetDiscoveryDocumentAsync(new DiscoveryDocumentRequest\n        {\n            Address = DiscoveryEndpoint,\n            Policy =\n            {\n                ValidateIssuerName = false\n            }\n        });\n\n        // endpoints\n        doc.TokenEndpoint.Should().Be(\"https://server/connect/token\");\n        doc.AuthorizeEndpoint.Should().Be(\"https://server/connect/authorize\");\n        doc.IntrospectionEndpoint.Should().Be(\"https://server/connect/introspect\");\n        doc.EndSessionEndpoint.Should().Be(\"https://server/connect/endsession\");\n\n        // jwk\n        doc.KeySet.Keys.Count.Should().Be(1);\n        doc.KeySet.Keys.First().E.Should().NotBeNull();\n        doc.KeySet.Keys.First().N.Should().NotBeNull();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/ExtensionGrantClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing Newtonsoft.Json;\nusing Newtonsoft.Json.Linq;\nusing System.IdentityModel.Tokens.Jwt;\nusing System.Net;\nusing System.Text;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class ExtensionGrantClient\n{\n    private const string TokenEndpoint = \"https://server/connect/token\";\n\n    private readonly HttpClient _client;\n\n    public ExtensionGrantClient()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Valid_client_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"custom\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"custom_credential\", \"custom credential\"},\n                { \"scope\", \"api1\" }\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        var unixNow = DateTimeOffset.UtcNow.ToUnixTimeSeconds();\n        var exp = Int64.Parse(payload[\"exp\"].ToString());\n        exp.Should().BeLessThan(unixNow + 3605);\n        exp.Should().BeGreaterThan(unixNow + 3595);\n\n        payload.Count().Should().Be(12);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"client.custom\");\n        payload.Should().Contain(\"sub\", \"818727\");\n        payload.Should().Contain(\"idp\", \"local\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"] as JArray;\n        scopes.First().ToString().Should().Be(\"api1\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"custom\");\n    }\n\n    [Fact]\n    public async Task Valid_client_with_extra_claim_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"custom\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"custom_credential\", \"custom credential\"},\n                { \"extra_claim\", \"extra_value\" },\n                { \"scope\", \"api1\" }\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        var unixNow = DateTimeOffset.UtcNow.ToUnixTimeSeconds();\n        var exp = Int64.Parse(payload[\"exp\"].ToString());\n        exp.Should().BeLessThan(unixNow + 3605);\n        exp.Should().BeGreaterThan(unixNow + 3595);\n\n        payload.Count().Should().Be(13);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"client.custom\");\n        payload.Should().Contain(\"sub\", \"818727\");\n        payload.Should().Contain(\"idp\", \"local\");\n        payload.Should().Contain(\"extra_claim\", \"extra_value\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"] as JArray;\n        scopes.First().ToString().Should().Be(\"api1\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"custom\");\n    }\n\n    [Fact]\n    public async Task Valid_client_with_refreshed_extra_claim_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"custom\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"custom_credential\", \"custom credential\"},\n                { \"extra_claim\", \"extra_value\" },\n                { \"scope\", \"api1 offline_access\" }\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        var refreshResponse = await _client.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = TokenEndpoint,\n            \n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            RefreshToken = response.RefreshToken\n        });\n\n        refreshResponse.IsError.Should().BeFalse();\n        refreshResponse.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        refreshResponse.ExpiresIn.Should().Be(3600);\n        refreshResponse.TokenType.Should().Be(\"Bearer\");\n        refreshResponse.IdentityToken.Should().BeNull();\n        refreshResponse.RefreshToken.Should().NotBeNull();\n\n        var payload = GetPayload(refreshResponse);\n\n        var unixNow = DateTimeOffset.UtcNow.ToUnixTimeSeconds();\n        var exp = Int64.Parse(payload[\"exp\"].ToString());\n        exp.Should().BeLessThan(unixNow + 3605);\n        exp.Should().BeGreaterThan(unixNow + 3595);\n\n        payload.Count().Should().Be(13);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"client.custom\");\n        payload.Should().Contain(\"sub\", \"818727\");\n        payload.Should().Contain(\"idp\", \"local\");\n        payload.Should().Contain(\"extra_claim\", \"extra_value\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"] as JArray;\n        scopes.First().ToString().Should().Be(\"api1\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"custom\");\n    }\n\n    [Fact]\n    public async Task Valid_client_no_subject_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"custom.nosubject\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"custom_credential\", \"custom credential\"},\n                { \"scope\", \"api1\" }\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(8);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"client.custom\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"] as JArray;\n        scopes.First().ToString().Should().Be(\"api1\");\n    }\n\n    [Fact]\n    public async Task Valid_client_with_default_scopes_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"custom\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"custom_credential\", \"custom credential\"}\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(12);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"client.custom\");\n        payload.Should().Contain(\"sub\", \"818727\");\n        payload.Should().Contain(\"idp\", \"local\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"custom\");\n\n        var scopes = payload[\"scope\"] as JArray;\n        scopes.Count().Should().Be(3);\n        scopes.First().ToString().Should().Be(\"api1\");\n        scopes.Skip(1).First().ToString().Should().Be(\"api2\");\n        scopes.Skip(2).First().ToString().Should().Be(\"offline_access\");\n    }\n\n    [Fact]\n    public async Task Valid_client_missing_grant_specific_data_should_fail()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"custom\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api1\" }\n            }\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        response.ErrorDescription.Should().Be(\"invalid_custom_credential\");\n    }\n\n    [Fact]\n    public async Task Valid_client_using_unsupported_grant_type_should_fail()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"invalid\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"custom_credential\", \"custom credential\"},\n                { \"scope\", \"api1\" }\n            }\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"unsupported_grant_type\");\n    }\n\n    [Fact]\n    public async Task Valid_client_using_unauthorized_grant_type_should_fail()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"custom2\",\n\n            ClientId = \"client.custom\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"custom_credential\", \"custom credential\"},\n                { \"scope\", \"api1\" }\n            }\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"unsupported_grant_type\");\n    }\n\n    [Fact(Skip = \"needs improvement\")]\n    public async Task Dynamic_lifetime_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"dynamic\",\n\n            ClientId = \"client.dynamic\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api1\" },\n\n                { \"lifetime\", \"5000\"},\n                { \"sub\",  \"818727\"}\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(5000);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        var unixNow = DateTimeOffset.UtcNow.ToUnixTimeSeconds();\n        var exp = Int64.Parse(payload[\"exp\"].ToString());\n        exp.Should().BeLessThan(unixNow + 5005);\n        exp.Should().BeGreaterThan(unixNow + 4995);\n\n        payload.Count().Should().Be(10);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"client.dynamic\");\n        payload.Should().Contain(\"sub\", \"818727\");\n        payload.Should().Contain(\"idp\", \"local\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"] as JArray;\n        scopes.First().ToString().Should().Be(\"api1\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"delegation\");\n    }\n\n    [Fact]\n    public async Task Dynamic_token_type_jwt_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"dynamic\",\n\n            ClientId = \"client.dynamic\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api1\" },\n\n                { \"type\", \"jwt\"},\n                { \"sub\",  \"818727\"}\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        response.AccessToken.Should().Contain(\".\");\n    }\n\n    [Fact]\n    public async Task Impersonate_client_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"dynamic\",\n\n            ClientId = \"client.dynamic\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api1\" },\n\n                { \"type\", \"jwt\"},\n                { \"impersonated_client\", \"impersonated_client_id\"},\n                { \"sub\",  \"818727\"}\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        response.AccessToken.Should().Contain(\".\");\n\n        var jwt = new JwtSecurityToken(response.AccessToken);\n        jwt.Payload[\"client_id\"].Should().Be(\"impersonated_client_id\");\n    }\n\n    [Fact]\n    public async Task Dynamic_token_type_reference_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"dynamic\",\n\n            ClientId = \"client.dynamic\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api1\" },\n\n                { \"type\", \"reference\"},\n                { \"sub\",  \"818727\"}\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        response.AccessToken.Should().NotContain(\".\");\n    }\n\n    [Fact]\n    public async Task Dynamic_client_claims_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"dynamic\",\n\n            ClientId = \"client.dynamic\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api1\" },\n\n                { \"claim\", \"extra_claim\"},\n                { \"sub\",  \"818727\"}\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(13);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"client.dynamic\");\n        payload.Should().Contain(\"sub\", \"818727\");\n        payload.Should().Contain(\"idp\", \"local\");\n\n        payload.Should().Contain(\"client_extra\", \"extra_claim\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"] as JArray;\n        scopes.First().ToString().Should().Be(\"api1\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"delegation\");\n    }\n\n    [Fact]\n    public async Task Dynamic_client_claims_no_sub_should_succeed()\n    {\n        var response = await _client.RequestTokenAsync(new TokenRequest\n        {\n            Address = TokenEndpoint,\n            GrantType = \"dynamic\",\n\n            ClientId = \"client.dynamic\",\n            ClientSecret = \"secret\",\n\n            Parameters =\n            {\n                { \"scope\", \"api1\" },\n\n                { \"claim\", \"extra_claim\"},\n            }\n        });\n\n        response.IsError.Should().BeFalse();\n        response.HttpStatusCode.Should().Be(HttpStatusCode.OK);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(9);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"client.dynamic\");\n        payload.Should().Contain(\"client_extra\", \"extra_claim\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var scopes = payload[\"scope\"] as JArray;\n        scopes.First().ToString().Should().Be(\"api1\");\n    }\n\n    private Dictionary<string, object> GetPayload(TokenResponse response)\n    {\n        var token = response.AccessToken.Split('.').Skip(1).Take(1).First();\n        var dictionary = JsonConvert.DeserializeObject<Dictionary<string, object>>(\n            Encoding.UTF8.GetString(Base64Url.Decode(token)));\n\n        return dictionary;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/RefreshTokenClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class RefreshTokenClient\n{\n    private const string TokenEndpoint = \"https://server/connect/token\";\n    private const string RevocationEndpoint = \"https://server/connect/revocation\";\n\n    private readonly HttpClient _client;\n\n    public RefreshTokenClient()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Requesting_a_refresh_token_without_identity_scopes_should_return_expected_results()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api1 offline_access\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        response = await _client.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            RefreshToken = response.RefreshToken\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n    }\n\n    [Fact]\n    public async Task Requesting_a_refresh_token_with_identity_scopes_should_return_expected_results()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid api1 offline_access\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        response = await _client.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            RefreshToken = response.RefreshToken\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().NotBeNull();\n        response.RefreshToken.Should().NotBeNull();\n    }\n\n    [Fact]\n    public async Task Refreshing_a_refresh_token_with_reuse_should_return_same_refresh_token()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient.reuse\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid api1 offline_access\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        var rt1 = response.RefreshToken;\n\n        response = await _client.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient.reuse\",\n            ClientSecret = \"secret\",\n\n            RefreshToken = response.RefreshToken\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().NotBeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        var rt2 = response.RefreshToken;\n\n        rt1.Should().BeEquivalentTo(rt2);\n    }\n    \n    [Fact]\n    public async Task Refreshing_a_refresh_token_with_one_time_only_should_return_different_refresh_token()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid api1 offline_access\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        var rt1 = response.RefreshToken;\n\n        response = await _client.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            RefreshToken = response.RefreshToken\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().NotBeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        var rt2 = response.RefreshToken;\n\n        rt1.Should().NotBeEquivalentTo(rt2);\n    }\n    \n    [Fact]\n    public async Task Replaying_a_rotated_token_should_fail()\n    {\n        // request initial token\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid api1 offline_access\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        var rt1 = response.RefreshToken;\n\n        // refresh token\n        response = await _client.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            RefreshToken = response.RefreshToken\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().NotBeNull();\n        response.RefreshToken.Should().NotBeNull();\n        \n        // refresh token (again)\n        response = await _client.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            RefreshToken = rt1\n        });\n\n        response.IsError.Should().BeTrue();\n        response.Error.Should().Be(\"invalid_grant\");\n    }\n    \n    [Fact]\n    public async Task Using_a_valid_refresh_token_should_succeed()\n    {\n        // request initial token\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid api1 offline_access\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        var rt1 = response.RefreshToken;\n\n        // refresh token\n        response = await _client.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            RefreshToken = rt1\n        });\n\n        response.IsError.Should().BeFalse();\n    }\n    \n    [Fact]\n    public async Task Using_a_revoked_refresh_token_should_fail()\n    {\n        // request initial token\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid api1 offline_access\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        var rt1 = response.RefreshToken;\n\n        // revoke refresh token\n        var revocationResponse = await _client.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = RevocationEndpoint,\n\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Token = rt1,\n            TokenTypeHint = \"refresh_token\"\n        });\n\n        revocationResponse.IsError.Should().Be(false);\n        \n        // refresh token\n        response = await _client.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            RefreshToken = rt1\n        });\n\n        response.IsError.Should().BeTrue();\n        response.Error.Should().Be(\"invalid_grant\");\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/ResourceOwnerClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing Newtonsoft.Json;\nusing Newtonsoft.Json.Linq;\nusing System.Net;\nusing System.Text;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class ResourceOwnerClient\n{\n    private const string TokenEndpoint = \"https://server/connect/token\";\n\n    private readonly HttpClient _client;\n\n    public ResourceOwnerClient()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Valid_user_should_succeed_with_expected_response_payload()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api1\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(12);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"roclient\");\n        payload.Should().Contain(\"sub\", \"88421113\");\n        payload.Should().Contain(\"idp\", \"local\");\n        payload.Keys.Should().Contain(\"jti\");\n        payload.Keys.Should().Contain(\"iat\");\n        \n        payload[\"aud\"].Should().Be(\"api\");\n\n        var scopes = ((JArray)payload[\"scope\"]).Select(x => x.ToString());\n        scopes.Count().Should().Be(1);\n        scopes.Should().Contain(\"api1\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"pwd\");\n    }\n\n    [Fact]\n    public async Task Request_with_no_explicit_scopes_should_return_allowed_scopes()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNull();\n\n        var payload = GetPayload(response);\n        \n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"roclient\");\n        payload.Should().Contain(\"sub\", \"88421113\");\n        payload.Should().Contain(\"idp\", \"local\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"pwd\");\n\n        var scopes = ((JArray)payload[\"scope\"]).Select(x => x.ToString());\n        scopes.Count().Should().Be(8);\n\n        // {[  \"address\",  \"api1\",  \"api2\", \"api4.with.roles\", \"email\",  \"offline_access\",  \"openid\", \"role\"]}\n\n        scopes.Should().Contain(\"address\");\n        scopes.Should().Contain(\"api1\");\n        scopes.Should().Contain(\"api2\");\n        scopes.Should().Contain(\"api4.with.roles\");\n        scopes.Should().Contain(\"email\");\n        scopes.Should().Contain(\"offline_access\");\n        scopes.Should().Contain(\"openid\");\n        scopes.Should().Contain(\"roles\");\n    }\n\n    [Fact]\n    public async Task Request_containing_identity_scopes_should_return_expected_payload()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid email api1\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().BeNull();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(12);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"roclient\");\n        payload.Should().Contain(\"sub\", \"88421113\");\n        payload.Should().Contain(\"idp\", \"local\");\n        payload.Keys.Should().Contain(\"jti\");\n        payload.Keys.Should().Contain(\"iat\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"pwd\");\n\n        var scopes = ((JArray)payload[\"scope\"]).Select(x=>x.ToString());\n        scopes.Count().Should().Be(3);\n        scopes.Should().Contain(\"api1\");\n        scopes.Should().Contain(\"email\");\n        scopes.Should().Contain(\"openid\");\n    }\n\n    [Fact]\n    public async Task Request_for_refresh_token_should_return_expected_payload()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid email api1 offline_access\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().Be(false);\n        response.ExpiresIn.Should().Be(3600);\n        response.TokenType.Should().Be(\"Bearer\");\n        response.IdentityToken.Should().BeNull();\n        response.RefreshToken.Should().NotBeNullOrWhiteSpace();\n\n        var payload = GetPayload(response);\n\n        payload.Count().Should().Be(12);\n        payload.Should().Contain(\"iss\", \"https://idsvr8\");\n        payload.Should().Contain(\"client_id\", \"roclient\");\n        payload.Should().Contain(\"sub\", \"88421113\");\n        payload.Should().Contain(\"idp\", \"local\");\n        payload.Keys.Should().Contain(\"jti\");\n        payload.Keys.Should().Contain(\"iat\");\n\n        payload[\"aud\"].Should().Be(\"api\");\n\n        var amr = payload[\"amr\"] as JArray;\n        amr.Count().Should().Be(1);\n        amr.First().ToString().Should().Be(\"pwd\");\n\n        var scopes = ((JArray)payload[\"scope\"]).Select(x => x.ToString());\n        scopes.Count().Should().Be(4);\n        scopes.Should().Contain(\"api1\");\n        scopes.Should().Contain(\"email\");\n        scopes.Should().Contain(\"offline_access\");\n        scopes.Should().Contain(\"openid\");\n    }\n\n    [Fact]\n    public async Task Unknown_user_should_fail()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api1\",\n            UserName = \"unknown\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"invalid_grant\");\n    }\n    \n    [Fact]\n    public async Task User_with_empty_password_should_succeed()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api1\",\n            UserName = \"bob_no_password\"\n        });\n\n        response.IsError.Should().Be(false);\n    }\n\n    [Theory]\n    [InlineData(\"invalid\")]\n    [InlineData(\"\")]\n    public async Task User_with_invalid_password_should_fail(string password)\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api1\",\n            UserName = \"bob\",\n            Password = password\n        });\n\n        response.IsError.Should().Be(true);\n        response.ErrorType.Should().Be(ResponseErrorType.Protocol);\n        response.HttpStatusCode.Should().Be(HttpStatusCode.BadRequest);\n        response.Error.Should().Be(\"invalid_grant\");\n    }\n\n\n    private static Dictionary<string, object> GetPayload(IdentityModel.Client.TokenResponse response)\n    {\n        var token = response.AccessToken.Split('.').Skip(1).Take(1).First();\n        var dictionary = JsonConvert.DeserializeObject<Dictionary<string, object>>(\n            Encoding.UTF8.GetString(Base64Url.Decode(token)));\n\n        return dictionary;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/RevocationClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Net.Http;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class RevocationClient\n{\n    private const string TokenEndpoint = \"https://server/connect/token\";\n    private const string RevocationEndpoint = \"https://server/connect/revocation\";\n    private const string IntrospectionEndpoint = \"https://server/connect/introspect\";\n\n    private readonly HttpClient _client;\n\n    public RevocationClient()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Revoking_reference_token_should_invalidate_token()\n    {\n        // request acccess token\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient.reference\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api1\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n\n        // introspect - should be active\n        var introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api\",\n            ClientSecret = \"secret\",\n\n            Token = response.AccessToken\n        });\n\n        introspectionResponse.IsActive.Should().Be(true);\n\n        // revoke access token\n        var revocationResponse = await _client.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = RevocationEndpoint,\n            ClientId = \"roclient.reference\",\n            ClientSecret = \"secret\",\n\n            Token = response.AccessToken\n        });\n\n        // introspect - should be inactive\n        introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api\",\n            ClientSecret = \"secret\",\n\n            Token = response.AccessToken\n        });\n\n        introspectionResponse.IsActive.Should().Be(false);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/Clients.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Security.Cryptography.X509Certificates;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Models;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\ninternal class Clients\n{\n    public static IEnumerable<Client> Get()\n    {\n        return new List<Client>\n        {\n            ///////////////////////////////////////////\n            // Console Client Credentials Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client\",\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowOfflineAccess = true,\n\n                AllowedScopes =\n                {\n                    \"api1\", \"api2\", \"other_api\"\n                }\n            },\n            new Client\n            {\n                ClientId = \"client.cnf\",\n                ClientSecrets =\n                {\n                    new Secret\n                    {\n                        Type = \"confirmation.test\",\n                        Description = \"Test for cnf claim\",\n                        Value = \"foo\"\n                    }\n                },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowOfflineAccess = true,\n\n                AllowedScopes =\n                {\n                    \"api1\", \"api2\"\n                }\n            },\n            new Client\n            {\n                ClientId = \"client.and.ro\",\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPasswordAndClientCredentials,\n\n                AllowedScopes =\n                {\n                    \"openid\",\n                    \"api1\", \"api2\"\n                }\n            },\n            new Client\n            {\n                ClientId = \"client.identityscopes\",\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n\n                AllowedScopes =\n                {\n                    \"openid\", \"profile\",\n                    \"api1\", \"api2\"\n                }\n            },\n            new Client\n            {\n                ClientId = \"client.no_default_scopes\",\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials\n            },\n            new Client\n            {\n                ClientId = \"client.no_secret\",\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                RequireClientSecret = false,\n                AllowedScopes = { \"api1\" }\n            },\n\n            ///////////////////////////////////////////\n            // Console Resource Owner Flow Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient\",\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                RefreshTokenUsage = TokenUsage.OneTimeOnly,\n\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Email,\n                    IdentityServerConstants.StandardScopes.Address,\n                    \"roles\",\n                    \"api1\", \"api2\", \"api4.with.roles\"\n                }\n            },\n            new Client\n            {\n                ClientId = \"roclient.reuse\",\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    IdentityServerConstants.StandardScopes.OpenId,\n                    IdentityServerConstants.StandardScopes.Email,\n                    IdentityServerConstants.StandardScopes.Address,\n                    \"roles\",\n                    \"api1\", \"api2\", \"api4.with.roles\"\n                },\n\n                RefreshTokenUsage = TokenUsage.ReUse\n            },\n\n            /////////////////////////////////////////\n            // Console Custom Grant Flow Sample\n            ////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"client.custom\",\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = { \"custom\", \"custom.nosubject\" },\n\n                AllowedScopes =\n                {\n                    \"api1\", \"api2\"\n                },\n\n                AllowOfflineAccess = true\n            },\n            new Client\n            {\n                ClientId = \"client.dynamic\",\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = { \"dynamic\" },\n\n                AllowedScopes =\n                {\n                    \"api1\", \"api2\"\n                },\n\n                AlwaysSendClientClaims = true\n            },\n\n            ///////////////////////////////////////////\n            // Introspection Client Sample\n            //////////////////////////////////////////\n            new Client\n            {\n                ClientId = \"roclient.reference\",\n                ClientSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n\n                AllowOfflineAccess = true,\n                AllowedScopes =\n                {\n                    \"api1\", \"api2\"\n                },\n\n                AccessTokenType = AccessTokenType.Reference\n            },\n\n            new Client\n            {\n                ClientName = \"Client with Base64 encoded X509 Certificate\",\n                ClientId = \"certificate_base64_valid\",\n                Enabled = true,\n\n                ClientSecrets =\n                {\n                    new Secret\n                    {\n                        Type = IdentityServerConstants.SecretTypes.X509CertificateBase64,\n                        Value = Convert.ToBase64String(TestCert.Load().Export(X509ContentType.Cert))\n                    }\n                },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n\n                AllowedScopes = new List<string>\n                {\n                    \"api1\", \"api2\"\n                }\n            },\n\n            new Client\n            {\n                ClientId = \"implicit\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                AllowedScopes = {\"api1\"},\n                RedirectUris = { \"http://implicit\" }\n            },\n            new Client\n            {\n                ClientId = \"implicit_and_client_creds\",\n                AllowedGrantTypes = GrantTypes.ImplicitAndClientCredentials,\n                AllowedScopes = {\"api1\"},\n                RedirectUris = { \"http://implicit_and_client_creds\" }\n            }\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/ConfirmationSecretValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Newtonsoft.Json;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class ConfirmationSecretValidator : ISecretValidator\n{\n    public Task<SecretValidationResult> ValidateAsync(IEnumerable<Secret> secrets, ParsedSecret parsedSecret)\n    {\n        if (secrets.Any())\n        {\n            if (secrets.First().Type == \"confirmation.test\")\n            {\n                var cnf = new Dictionary<string, string>\n                {\n                    { \"x5t#S256\", \"foo\" }\n                };\n\n                var result = new SecretValidationResult\n                {\n                    Success = true,\n                    Confirmation = JsonConvert.SerializeObject(cnf)\n                };\n\n                return Task.FromResult(result);\n            }\n        }\n\n        return Task.FromResult(new SecretValidationResult { Success = false });\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/CustomProfileService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Microsoft.Extensions.Logging;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\nclass CustomProfileService : TestUserProfileService\n{\n    public CustomProfileService(TestUserStore users, ILogger<TestUserProfileService> logger) : base(users, logger)\n    { }\n\n    public override async Task GetProfileDataAsync(ProfileDataRequestContext context)\n    {\n        await base.GetProfileDataAsync(context);\n\n        if (context.Subject.Identity.AuthenticationType == \"custom\")\n        {\n            var extraClaim = context.Subject.FindFirst(\"extra_claim\");\n            if (extraClaim != null)\n            {\n                context.IssuedClaims.Add(extraClaim);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/CustomResponseDto.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class CustomResponseDto\n{\n    public string string_value { get; set; }\n    public int int_value { get; set; }\n\n    public CustomResponseDto nested { get; set; }\n\n    public static CustomResponseDto Create\n    {\n        get\n        {\n            return new CustomResponseDto\n            {\n                string_value = \"dto_string\",\n                int_value = 43,\n                nested = new CustomResponseDto\n                {\n                    string_value = \"dto_nested_string\",\n                    int_value = 44\n                }\n            };\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/CustomResponseExtensionGrantValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class CustomResponseExtensionGrantValidator : IExtensionGrantValidator\n{\n    public Task ValidateAsync(ExtensionGrantValidationContext context)\n    {\n        var response = new Dictionary<string, object>\n        {\n            { \"string_value\", \"some_string\" },\n            { \"int_value\", 42 },\n            { \"dto\",  CustomResponseDto.Create }\n        };\n\n        var credential = context.Request.Raw.Get(\"outcome\");\n\n        if (credential == \"succeed\")\n        {\n            context.Result = new GrantValidationResult(\"bob\", \"custom\", customResponse: response);\n        }\n        else\n        {\n            context.Result = new GrantValidationResult(TokenRequestErrors.InvalidGrant, \"invalid_credential\", response);\n        }\n\n        return Task.CompletedTask;\n    }\n\n    public string GrantType\n    {\n        get { return \"custom\"; }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/CustomResponseResourceOwnerValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class CustomResponseResourceOwnerValidator : IResourceOwnerPasswordValidator\n{\n    public Task ValidateAsync(ResourceOwnerPasswordValidationContext context)\n    {\n        var response = new Dictionary<string, object>\n        {\n            { \"string_value\", \"some_string\" },\n            { \"int_value\", 42 },\n            { \"dto\",  CustomResponseDto.Create }\n        };\n\n        if (context.UserName == context.Password)\n        {\n            context.Result = new GrantValidationResult(context.UserName, \"password\", customResponse: response);\n        }\n        else\n        {\n            context.Result = new GrantValidationResult(TokenRequestErrors.InvalidGrant, \"invalid_credential\", response);\n        }\n\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/DynamicParameterExtensionGrantValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class DynamicParameterExtensionGrantValidator : IExtensionGrantValidator\n{\n    public Task ValidateAsync(ExtensionGrantValidationContext context)\n    {\n        var impersonatedClient = context.Request.Raw.Get(\"impersonated_client\");\n        var lifetime = context.Request.Raw.Get(\"lifetime\");\n        var extraClaim = context.Request.Raw.Get(\"claim\");\n        var tokenType = context.Request.Raw.Get(\"type\");\n        var sub = context.Request.Raw.Get(\"sub\");\n\n        if (!string.IsNullOrEmpty(impersonatedClient))\n        {\n            context.Request.ClientId = impersonatedClient;\n        }\n\n        if (!string.IsNullOrEmpty(lifetime))\n        {\n            context.Request.AccessTokenLifetime = int.Parse(lifetime);\n        }\n\n        if (!string.IsNullOrEmpty(tokenType))\n        {\n            if (tokenType == \"jwt\")\n            {\n                context.Request.AccessTokenType = AccessTokenType.Jwt;\n            }\n            else if (tokenType == \"reference\")\n            {\n                context.Request.AccessTokenType = AccessTokenType.Reference;\n            }\n        }\n\n        if (!string.IsNullOrEmpty(extraClaim))\n        {\n            context.Request.ClientClaims.Add(new Claim(\"extra\", extraClaim));\n        }\n\n        if (!string.IsNullOrEmpty(sub))\n        {\n            context.Result = new GrantValidationResult(sub, \"delegation\");\n        }\n        else\n        {\n            context.Result = new GrantValidationResult();\n        }\n\n        return Task.CompletedTask;\n    }\n\n    public string GrantType => \"dynamic\";\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/ExtensionGrantValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class ExtensionGrantValidator : IExtensionGrantValidator\n{\n    public Task ValidateAsync(ExtensionGrantValidationContext context)\n    {\n        var credential = context.Request.Raw.Get(\"custom_credential\");\n        var extraClaim = context.Request.Raw.Get(\"extra_claim\");\n\n        if (credential != null)\n        {\n            if (extraClaim != null)\n            {\n                context.Result = new GrantValidationResult(\n                    subject: \"818727\",\n                    claims: new[] { new Claim(\"extra_claim\", extraClaim) },\n                    authenticationMethod: GrantType);\n            }\n            else\n            {\n                context.Result = new GrantValidationResult(subject: \"818727\", authenticationMethod: GrantType);\n            }\n        }\n        else\n        {\n            // custom error message\n            context.Result = new GrantValidationResult(TokenRequestErrors.InvalidGrant, \"invalid_custom_credential\");\n        }\n\n        return Task.CompletedTask;\n    }\n\n    public string GrantType =>  \"custom\";\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/ExtensionGrantValidator2.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class ExtensionGrantValidator2 : IExtensionGrantValidator\n{\n    public Task ValidateAsync(ExtensionGrantValidationContext context)\n    {\n        var credential = context.Request.Raw.Get(\"custom_credential\");\n\n        if (credential != null)\n        {\n            // valid credential\n            context.Result = new GrantValidationResult(\"818727\", \"custom\");\n        }\n        else\n        {\n            // custom error message\n            context.Result = new GrantValidationResult(IdentityServer8.Models.TokenRequestErrors.InvalidGrant, \"invalid custom credential\");\n        }\n\n        return Task.CompletedTask;\n    }\n\n    public string GrantType => \"custom2\";\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/NoSubjectExtensionGrantValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class NoSubjectExtensionGrantValidator : IExtensionGrantValidator\n{\n    public Task ValidateAsync(ExtensionGrantValidationContext context)\n    {\n        var credential = context.Request.Raw.Get(\"custom_credential\");\n\n        if (credential != null)\n        {\n            context.Result = new GrantValidationResult();\n        }\n        else\n        {\n            // custom error message\n            context.Result = new GrantValidationResult(TokenRequestErrors.InvalidGrant, \"invalid custom credential\");\n        }\n\n        return Task.CompletedTask;\n    }\n\n    public string GrantType => \"custom.nosubject\";\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/Scopes.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing IdentityServer8.Models;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\ninternal class Scopes\n{\n    public static IEnumerable<IdentityResource> GetIdentityScopes()\n    {\n        return new IdentityResource[]\n        {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Email(),\n            new IdentityResources.Address(),\n            new IdentityResource(\"roles\", new[] { \"role\" })\n        };\n    }\n\n    public static IEnumerable<ApiResource> GetApiResources()\n    {\n        return new List<ApiResource>\n        {\n            new ApiResource\n            {\n                Name = \"api\",\n                ApiSecrets =\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n                Scopes = { \"api1\", \"api2\", \"api3\", \"api4.with.roles\" }\n            },\n            new ApiResource(\"other_api\")\n            {\n                Scopes = { \"other_api\" }\n            }\n        };\n    }\n\n    public static IEnumerable<ApiScope> GetApiScopes()\n    {\n        return new ApiScope[]\n        {\n            new ApiScope\n            {\n                Name = \"api1\"\n            },\n            new ApiScope\n            {\n                Name = \"api2\"\n            },\n            new ApiScope\n            {\n                Name = \"api3\"\n            },\n            new ApiScope\n            {\n                Name = \"api4.with.roles\",\n                UserClaims = { \"role\" }\n            },\n            new ApiScope\n            {\n                Name = \"other_api\",\n            },\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Builder;\nusing Microsoft.Extensions.DependencyInjection;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class Startup\n{\n    static public ICustomTokenRequestValidator CustomTokenRequestValidator { get; set; } \n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        services.AddAuthentication();\n\n        var builder = services.AddIdentityServer(options =>\n        {\n            options.IssuerUri = \"https://idsvr8\";\n\n            options.Events = new EventsOptions\n            {\n                RaiseErrorEvents = true,\n                RaiseFailureEvents = true,\n                RaiseInformationEvents = true,\n                RaiseSuccessEvents = true\n            };\n        });\n\n        builder.AddInMemoryClients(Clients.Get());\n        builder.AddInMemoryIdentityResources(Scopes.GetIdentityScopes());\n        builder.AddInMemoryApiResources(Scopes.GetApiResources());\n        builder.AddInMemoryApiScopes(Scopes.GetApiScopes());\n        builder.AddTestUsers(Users.Get());\n\n        builder.AddDeveloperSigningCredential(persistKey: false);\n\n        builder.AddExtensionGrantValidator<ExtensionGrantValidator>();\n        builder.AddExtensionGrantValidator<ExtensionGrantValidator2>();\n        builder.AddExtensionGrantValidator<NoSubjectExtensionGrantValidator>();\n        builder.AddExtensionGrantValidator<DynamicParameterExtensionGrantValidator>();\n\n        builder.AddProfileService<CustomProfileService>();\n\n        builder.AddJwtBearerClientAuthentication();\n        builder.AddSecretValidator<ConfirmationSecretValidator>();\n\n        // add a custom token request validator if set\n        if (CustomTokenRequestValidator != null)\n        {\n            builder.Services.AddTransient(r => CustomTokenRequestValidator);\n        }\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n        app.UseIdentityServer();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/StartupWithCustomTokenResponses.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Builder;\nusing Microsoft.Extensions.DependencyInjection;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class StartupWithCustomTokenResponses\n{\n    public void ConfigureServices(IServiceCollection services)\n    {\n        services.AddAuthentication();\n\n        var builder = services.AddIdentityServer(options =>\n        {\n            options.IssuerUri = \"https://idsvr8\";\n\n            options.Events = new EventsOptions\n            {\n                RaiseErrorEvents = true,\n                RaiseFailureEvents = true,\n                RaiseInformationEvents = true,\n                RaiseSuccessEvents = true\n            };\n        });\n\n        builder.AddInMemoryClients(Clients.Get());\n        builder.AddInMemoryIdentityResources(Scopes.GetIdentityScopes());\n        builder.AddInMemoryApiResources(Scopes.GetApiResources());\n        builder.AddInMemoryApiScopes(Scopes.GetApiScopes());\n\n        builder.AddDeveloperSigningCredential(persistKey: false);\n\n        services.AddTransient<IResourceOwnerPasswordValidator, CustomResponseResourceOwnerValidator>();\n        builder.AddExtensionGrantValidator<CustomResponseExtensionGrantValidator>();\n    }\n\n    public void Configure(IApplicationBuilder app)\n    {\n        app.UseIdentityServer();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/TestCustomTokenRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\npublic class TestCustomTokenRequestValidator : ICustomTokenRequestValidator\n{\n    public Task ValidateAsync(CustomTokenRequestValidationContext context)\n    {\n        context.Result.CustomResponse = new Dictionary<string, object>\n        {\n            {\"custom\", \"custom\" }\n        };\n\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/Setup/Users.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Security.Claims;\nusing IdentityModel;\nusing IdentityServer8;\nusing IdentityServer8.Test;\n\nnamespace IdentityServer.IntegrationTests.Clients.Setup;\n\ninternal static class Users\n{\n    public static List<TestUser> Get()\n    {\n        var users = new List<TestUser>\n        {\n            new TestUser{SubjectId = \"818727\", Username = \"alice\", Password = \"alice\", \n                Claims = new Claim[]\n                {\n                    new Claim(JwtClaimTypes.Name, \"Alice Smith\"),\n                    new Claim(JwtClaimTypes.GivenName, \"Alice\"),\n                    new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                    new Claim(JwtClaimTypes.Email, \"AliceSmith@email.com\"),\n                    new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                    new Claim(JwtClaimTypes.Role, \"Admin\"),\n                    new Claim(JwtClaimTypes.Role, \"Geek\"),\n                    new Claim(JwtClaimTypes.WebSite, \"http://alice.com\"),\n                    new Claim(JwtClaimTypes.Address, @\"{ 'street_address': 'One Hacker Way', 'locality': 'Heidelberg', 'postal_code': 69118, 'country': 'Germany' }\", IdentityServerConstants.ClaimValueTypes.Json)\n                }\n            },\n            new TestUser{SubjectId = \"88421113\", Username = \"bob\", Password = \"bob\", \n                Claims = new Claim[]\n                {\n                    new Claim(JwtClaimTypes.Name, \"Bob Smith\"),\n                    new Claim(JwtClaimTypes.GivenName, \"Bob\"),\n                    new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                    new Claim(JwtClaimTypes.Email, \"BobSmith@email.com\"),\n                    new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                    new Claim(JwtClaimTypes.Role, \"Developer\"),\n                    new Claim(JwtClaimTypes.Role, \"Geek\"),\n                    new Claim(JwtClaimTypes.WebSite, \"http://bob.com\"),\n                    new Claim(JwtClaimTypes.Address, @\"{ 'street_address': 'One Hacker Way', 'locality': 'Heidelberg', 'postal_code': 69118, 'country': 'Germany' }\", IdentityServerConstants.ClaimValueTypes.Json)\n                }\n            },\n            new TestUser{SubjectId = \"88421113\", Username = \"bob_no_password\", \n                Claims = new Claim[]\n                {\n                    new Claim(JwtClaimTypes.Name, \"Bob Smith\"),\n                    new Claim(JwtClaimTypes.GivenName, \"Bob\"),\n                    new Claim(JwtClaimTypes.FamilyName, \"Smith\"),\n                    new Claim(JwtClaimTypes.Email, \"BobSmith@email.com\"),\n                    new Claim(JwtClaimTypes.EmailVerified, \"true\", ClaimValueTypes.Boolean),\n                    new Claim(JwtClaimTypes.Role, \"Developer\"),\n                    new Claim(JwtClaimTypes.Role, \"Geek\"),\n                    new Claim(JwtClaimTypes.WebSite, \"http://bob.com\"),\n                    new Claim(JwtClaimTypes.Address, @\"{ 'street_address': 'One Hacker Way', 'locality': 'Heidelberg', 'postal_code': 69118, 'country': 'Germany' }\", IdentityServerConstants.ClaimValueTypes.Json)\n                }\n            }\n        };\n\n        return users;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Clients/UserInfoClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Net;\nusing System.Net.Http;\nusing System.Text;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Clients.Setup;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing Newtonsoft.Json;\nusing Newtonsoft.Json.Linq;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Clients;\n\npublic class UserInfoEndpointClient\n{\n    private const string TokenEndpoint = \"https://server/connect/token\";\n    private const string UserInfoEndpoint = \"https://server/connect/userinfo\";\n\n    private readonly HttpClient _client;\n\n    public UserInfoEndpointClient()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    public async Task Valid_client_with_GET_should_succeed()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid email api1\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n\n        var userInfo = await _client.GetUserInfoAsync(new UserInfoRequest\n        {\n            Address = UserInfoEndpoint,\n            Token = response.AccessToken\n        });\n\n        userInfo.IsError.Should().BeFalse();\n        userInfo.Claims.Count().Should().Be(3);\n\n        userInfo.Claims.Should().Contain(c => c.Type == \"sub\" && c.Value == \"88421113\");\n        userInfo.Claims.Should().Contain(c => c.Type == \"email\" && c.Value == \"BobSmith@email.com\");\n        userInfo.Claims.Should().Contain(c => c.Type == \"email_verified\" && c.Value == \"true\");\n    }\n\n    [Fact]\n    public async Task Request_address_scope_should_return_expected_response()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid address\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n\n        var userInfo = await _client.GetUserInfoAsync(new UserInfoRequest\n        {\n            Address = UserInfoEndpoint,\n            Token = response.AccessToken\n        });\n\n        userInfo.IsError.Should().BeFalse();\n        userInfo.Claims.First().Value.Should().Be(\"{ 'street_address': 'One Hacker Way', 'locality': 'Heidelberg', 'postal_code': 69118, 'country': 'Germany' }\");\n    }\n\n    [Fact]\n    public async Task Using_a_token_with_no_identity_scope_should_fail()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api1\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n\n        var userInfo = await _client.GetUserInfoAsync(new UserInfoRequest\n        {\n            Address = UserInfoEndpoint,\n            Token = response.AccessToken\n        });\n\n        userInfo.IsError.Should().BeTrue();\n        userInfo.HttpStatusCode.Should().Be(HttpStatusCode.Forbidden);\n    }\n\n    [Fact]\n    public async Task Using_a_token_with_an_identity_scope_but_no_openid_should_fail()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"email api1\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n\n        var userInfo = await _client.GetUserInfoAsync(new UserInfoRequest\n        {\n            Address = UserInfoEndpoint,\n            Token = response.AccessToken\n        });\n\n        userInfo.IsError.Should().BeTrue();\n        userInfo.HttpStatusCode.Should().Be(HttpStatusCode.Forbidden);\n    }\n\n    [Fact]\n    public async Task Invalid_token_should_fail()\n    {\n        var userInfo = await _client.GetUserInfoAsync(new UserInfoRequest\n        {\n            Address = UserInfoEndpoint,\n            Token = \"invalid\"\n        });\n\n        userInfo.IsError.Should().BeTrue();\n        userInfo.HttpStatusCode.Should().Be(HttpStatusCode.Unauthorized);\n    }\n\n    [Fact]\n    public async Task Complex_json_should_be_correct()\n    {\n        var response = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"roclient\",\n            ClientSecret = \"secret\",\n\n            Scope = \"openid email api1 api4.with.roles roles\",\n            UserName = \"bob\",\n            Password = \"bob\"\n        });\n\n        response.IsError.Should().BeFalse();\n\n        var payload = GetPayload(response);\n\n        var scopes = ((JArray) payload[\"scope\"]).Select(x => x.ToString()).ToArray();\n        scopes.Length.Should().Be(5);\n        scopes.Should().Contain(\"openid\");\n        scopes.Should().Contain(\"email\");\n        scopes.Should().Contain(\"api1\");\n        scopes.Should().Contain(\"api4.with.roles\");\n        scopes.Should().Contain(\"roles\");\n\n        var roles = ((JArray) payload[\"role\"]).Select(x => x.ToString()).ToArray();\n        roles.Length.Should().Be(2);\n        roles.Should().Contain(\"Geek\");\n        roles.Should().Contain(\"Developer\");\n\n        var userInfo = await _client.GetUserInfoAsync(new UserInfoRequest\n        {\n            Address = UserInfoEndpoint,\n            Token = response.AccessToken\n        });\n\n        //roles = ((JArray)userInfo.Json[\"role\"]).Select(x => x.ToString()).ToArray();\n        roles = userInfo.Json.TryGetStringArray(\"role\").ToArray();\n        roles.Length.Should().Be(2);\n        roles.Should().Contain(\"Geek\");\n        roles.Should().Contain(\"Developer\");\n    }\n\n    private Dictionary<string, object> GetPayload(TokenResponse response)\n    {\n        var token = response.AccessToken.Split('.').Skip(1).Take(1).First();\n        var dictionary = JsonConvert.DeserializeObject<Dictionary<string, object>>(\n            Encoding.UTF8.GetString(Base64Url.Decode(token)));\n\n        return dictionary;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Common/BrowserClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Net.Http;\n\nnamespace IdentityServer.IntegrationTests.Common;\n\npublic class BrowserClient : HttpClient\n{\n    public BrowserClient(BrowserHandler browserHandler)\n        : base(browserHandler)\n    {\n        BrowserHandler = browserHandler;\n    }\n\n    public BrowserHandler BrowserHandler { get; private set; }\n\n    public bool AllowCookies\n    {\n        get { return BrowserHandler.AllowCookies; }\n        set { BrowserHandler.AllowCookies = value; }\n    }\n    public bool AllowAutoRedirect\n    {\n        get { return BrowserHandler.AllowAutoRedirect; }\n        set { BrowserHandler.AllowAutoRedirect = value; }\n    }\n    public int ErrorRedirectLimit\n    {\n        get { return BrowserHandler.ErrorRedirectLimit; }\n        set { BrowserHandler.ErrorRedirectLimit = value; }\n    }\n    public int StopRedirectingAfter\n    {\n        get { return BrowserHandler.StopRedirectingAfter; }\n        set { BrowserHandler.StopRedirectingAfter = value; }\n    }\n\n    internal void RemoveCookie(string uri, string name)\n    {\n        BrowserHandler.RemoveCookie(uri, name);\n    }\n\n    internal System.Net.Cookie GetCookie(string uri, string name)\n    {\n        return BrowserHandler.GetCookie(uri, name);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Common/BrowserHandler.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Linq;\nusing System.Net;\nusing System.Net.Http;\nusing System.Threading;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.IntegrationTests.Common;\n\n// thanks to Damian Hickey for this awesome sample\n// https://github.com/damianh/OwinHttpMessageHandler/blob/master/src/OwinHttpMessageHandler/OwinHttpMessageHandler.cs\npublic class BrowserHandler : DelegatingHandler\n{\n    private CookieContainer _cookieContainer = new CookieContainer();\n\n    public bool AllowCookies { get; set; } = true;\n    public bool AllowAutoRedirect { get; set; } = true;\n    public int ErrorRedirectLimit { get; set; } = 20;\n    public int StopRedirectingAfter { get; set; } = Int32.MaxValue;\n\n    public BrowserHandler(HttpMessageHandler next)\n        : base(next)\n    {\n    }\n\n    protected async override Task<HttpResponseMessage> SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)\n    {\n        var response = await SendCookiesAsync(request, cancellationToken);\n\n        int redirectCount = 0;\n\n        while (AllowAutoRedirect && \n            (300 <= (int)response.StatusCode && (int)response.StatusCode < 400) &&\n            redirectCount < StopRedirectingAfter)\n        {\n            if (redirectCount >= ErrorRedirectLimit)\n            {\n                throw new InvalidOperationException(string.Format(\"Too many redirects. Error limit = {0}\", redirectCount));\n            }\n\n            var location = response.Headers.Location;\n            if (!location.IsAbsoluteUri)\n            {\n                location = new Uri(response.RequestMessage.RequestUri, location);\n            }\n\n            request = new HttpRequestMessage(HttpMethod.Get, location);\n\n            response = await SendCookiesAsync(request, cancellationToken).ConfigureAwait(false);\n\n            redirectCount++;\n        }\n\n        return response;\n    }\n\n    internal Cookie GetCookie(string uri, string name)\n    {\n        return _cookieContainer.GetCookies(new Uri(uri)).Cast<Cookie>().Where(x => x.Name == name).FirstOrDefault();\n    }\n\n    internal void RemoveCookie(string uri, string name)\n    {\n        var cookie = _cookieContainer.GetCookies(new Uri(uri)).Cast<Cookie>().Where(x=>x.Name == name).FirstOrDefault();\n        if (cookie != null)\n        {\n            cookie.Expired = true;\n        }\n    }\n\n    protected async Task<HttpResponseMessage> SendCookiesAsync(HttpRequestMessage request, CancellationToken cancellationToken)\n    {\n        if (AllowCookies)\n        {\n            string cookieHeader = _cookieContainer.GetCookieHeader(request.RequestUri);\n            if (!string.IsNullOrEmpty(cookieHeader))\n            {\n                request.Headers.Add(\"Cookie\", cookieHeader);\n            }\n        }\n\n        var response = await base.SendAsync(request, cancellationToken);\n\n        if (AllowCookies && response.Headers.Contains(\"Set-Cookie\"))\n        {\n            var responseCookieHeader = string.Join(\",\", response.Headers.GetValues(\"Set-Cookie\"));\n            _cookieContainer.SetCookies(request.RequestUri, responseCookieHeader);\n        }\n\n        return response;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Common/IdentityServerPipeline.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Net;\nusing System.Net.Http;\nusing System.Security.Claims;\nusing System.Threading;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Test;\nusing Microsoft.AspNetCore.Authentication;\nusing Microsoft.AspNetCore.Builder;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.AspNetCore.TestHost;\nusing Microsoft.Extensions.DependencyInjection;\nusing Microsoft.Extensions.Logging;\n\nnamespace IdentityServer.IntegrationTests.Common;\n\npublic class IdentityServerPipeline\n{\n    public const string BaseUrl = \"https://server\";\n    public const string LoginPage = BaseUrl + \"/account/login\";\n    public const string ConsentPage = BaseUrl + \"/account/consent\";\n    public const string ErrorPage = BaseUrl + \"/home/error\";\n\n    public const string DeviceAuthorization = BaseUrl + \"/connect/deviceauthorization\";\n    public const string DiscoveryEndpoint = BaseUrl + \"/.well-known/openid-configuration\";\n    public const string DiscoveryKeysEndpoint = BaseUrl + \"/.well-known/openid-configuration/jwks\";\n    public const string AuthorizeEndpoint = BaseUrl + \"/connect/authorize\";\n    public const string TokenEndpoint = BaseUrl + \"/connect/token\";\n    public const string RevocationEndpoint = BaseUrl + \"/connect/revocation\";\n    public const string UserInfoEndpoint = BaseUrl + \"/connect/userinfo\";\n    public const string IntrospectionEndpoint = BaseUrl + \"/connect/introspect\";\n    public const string IdentityTokenValidationEndpoint = BaseUrl + \"/connect/identityTokenValidation\";\n    public const string EndSessionEndpoint = BaseUrl + \"/connect/endsession\";\n    public const string EndSessionCallbackEndpoint = BaseUrl + \"/connect/endsession/callback\";\n    public const string CheckSessionEndpoint = BaseUrl + \"/connect/checksession\";\n\n    public const string FederatedSignOutPath = \"/signout-oidc\";\n    public const string FederatedSignOutUrl = BaseUrl + FederatedSignOutPath;\n\n    public IdentityServerOptions Options { get; set; }\n    public List<Client> Clients { get; set; } = new List<Client>();\n    public List<IdentityResource> IdentityScopes { get; set; } = new List<IdentityResource>();\n    public List<ApiResource> ApiResources { get; set; } = new List<ApiResource>();\n    public List<ApiScope> ApiScopes { get; set; } = new List<ApiScope>();\n    public List<TestUser> Users { get; set; } = new List<TestUser>();\n\n    public TestServer Server { get; set; }\n    public HttpMessageHandler Handler { get; set; }\n\n    public BrowserClient BrowserClient { get; set; }\n    public HttpClient BackChannelClient { get; set; }\n\n    public MockMessageHandler BackChannelMessageHandler { get; set; } = new MockMessageHandler();\n    public MockMessageHandler JwtRequestMessageHandler { get; set; } = new MockMessageHandler();\n\n    public event Action<IServiceCollection> OnPreConfigureServices = services => { };\n    public event Action<IServiceCollection> OnPostConfigureServices = services => { };\n    public event Action<IApplicationBuilder> OnPreConfigure = app => { };\n    public event Action<IApplicationBuilder> OnPostConfigure = app => { };\n\n    public Func<HttpContext, Task<bool>> OnFederatedSignout;\n\n    public void Initialize(string basePath = null, bool enableLogging = false)\n    {\n        var builder = new WebHostBuilder();\n        builder.ConfigureServices(ConfigureServices);\n        builder.Configure(app =>\n        {\n            if (basePath != null)\n            {\n                app.Map(basePath, map =>\n                {\n                    ConfigureApp(map);\n                });\n            }\n            else\n            {\n                ConfigureApp(app);\n            }\n        });\n\n        if (enableLogging)\n        {\n            builder.ConfigureLogging((ctx, b) => b.AddConsole());\n        }\n\n        Server = new TestServer(builder);\n        Handler = Server.CreateHandler();\n\n        BrowserClient = new BrowserClient(new BrowserHandler(Handler));\n        BackChannelClient = new HttpClient(Handler);\n    }\n\n    public void ConfigureServices(IServiceCollection services)\n    {\n        OnPreConfigureServices(services);\n\n        services.AddAuthentication(opts =>\n        {\n            opts.AddScheme(\"external\", scheme =>\n            {\n                scheme.DisplayName = \"External\";\n                scheme.HandlerType = typeof(MockExternalAuthenticationHandler);\n            });\n        });\n        services.AddTransient<MockExternalAuthenticationHandler>(svcs =>\n        {\n            var handler = new MockExternalAuthenticationHandler(svcs.GetRequiredService<IHttpContextAccessor>());\n            if (OnFederatedSignout != null) handler.OnFederatedSignout = OnFederatedSignout;\n            return handler;\n        });\n\n        services.AddIdentityServer(options =>\n        {\n            Options = options;\n\n            options.Events = new EventsOptions\n            {\n                RaiseErrorEvents = true,\n                RaiseFailureEvents = true,\n                RaiseInformationEvents = true,\n                RaiseSuccessEvents = true\n            };\n        })\n        .AddInMemoryClients(Clients)\n        .AddInMemoryIdentityResources(IdentityScopes)\n        .AddInMemoryApiResources(ApiResources)\n        .AddInMemoryApiScopes(ApiScopes)\n        .AddTestUsers(Users)\n        .AddDeveloperSigningCredential(persistKey: false);\n\n        services.AddHttpClient(IdentityServerConstants.HttpClients.BackChannelLogoutHttpClient)\n            .AddHttpMessageHandler(() => BackChannelMessageHandler);\n\n        services.AddHttpClient(IdentityServerConstants.HttpClients.JwtRequestUriHttpClient)\n            .AddHttpMessageHandler(() => JwtRequestMessageHandler);\n\n        OnPostConfigureServices(services);\n    }\n\n    public void ConfigureApp(IApplicationBuilder app)\n    {\n        OnPreConfigure(app);\n\n        app.UseIdentityServer();\n\n        // UI endpoints\n        app.Map(Constants.UIConstants.DefaultRoutePaths.Login.EnsureLeadingSlash(), path =>\n        {\n            path.Run(ctx => OnLogin(ctx));\n        });\n        app.Map(Constants.UIConstants.DefaultRoutePaths.Logout.EnsureLeadingSlash(), path =>\n        {\n            path.Run(ctx => OnLogout(ctx));\n        });\n        app.Map(Constants.UIConstants.DefaultRoutePaths.Consent.EnsureLeadingSlash(), path =>\n        {\n            path.Run(ctx => OnConsent(ctx));\n        });\n        app.Map(Constants.UIConstants.DefaultRoutePaths.Error.EnsureLeadingSlash(), path =>\n        {\n            path.Run(ctx => OnError(ctx));\n        });\n\n        OnPostConfigure(app);\n    }\n\n    public bool LoginWasCalled { get; set; }\n    public AuthorizationRequest LoginRequest { get; set; }\n    public ClaimsPrincipal Subject { get; set; }\n    public bool FollowLoginReturnUrl { get; set; }\n\n    private async Task OnLogin(HttpContext ctx)\n    {\n        LoginWasCalled = true;\n        await ReadLoginRequest(ctx);\n        await IssueLoginCookie(ctx);\n    }\n\n    private async Task ReadLoginRequest(HttpContext ctx)\n    {\n        var interaction = ctx.RequestServices.GetRequiredService<IIdentityServerInteractionService>();\n        LoginRequest = await interaction.GetAuthorizationContextAsync(ctx.Request.Query[\"returnUrl\"].FirstOrDefault());\n    }\n\n    private async Task IssueLoginCookie(HttpContext ctx)\n    {\n        if (Subject != null)\n        {\n            var props = new AuthenticationProperties();\n            await ctx.SignInAsync(Subject, props);\n            Subject = null;\n            var url = ctx.Request.Query[Options.UserInteraction.LoginReturnUrlParameter].FirstOrDefault();\n            if (url != null)\n            {\n                ctx.Response.RedirectIfAllowed(url);\n            }\n        }\n    }\n\n    public bool LogoutWasCalled { get; set; }\n    public LogoutRequest LogoutRequest { get; set; }\n\n    private async Task OnLogout(HttpContext ctx)\n    {\n        LogoutWasCalled = true;\n        await ReadLogoutRequest(ctx);\n        await ctx.SignOutAsync();\n    }\n\n    private async Task ReadLogoutRequest(HttpContext ctx)\n    {\n        var interaction = ctx.RequestServices.GetRequiredService<IIdentityServerInteractionService>();\n        LogoutRequest = await interaction.GetLogoutContextAsync(ctx.Request.Query[\"logoutId\"].FirstOrDefault());\n    }\n\n    public bool ConsentWasCalled { get; set; }\n    public AuthorizationRequest ConsentRequest { get; set; }\n    public ConsentResponse ConsentResponse { get; set; }\n\n    private async Task OnConsent(HttpContext ctx)\n    {\n        ConsentWasCalled = true;\n        await ReadConsentMessage(ctx);\n        await CreateConsentResponse(ctx);\n    }\n\n    private async Task ReadConsentMessage(HttpContext ctx)\n    {\n        var interaction = ctx.RequestServices.GetRequiredService<IIdentityServerInteractionService>();\n        ConsentRequest = await interaction.GetAuthorizationContextAsync(ctx.Request.Query[\"returnUrl\"].FirstOrDefault());\n    }\n\n    private async Task CreateConsentResponse(HttpContext ctx)\n    {\n        if (ConsentRequest != null && ConsentResponse != null)\n        {\n            var interaction = ctx.RequestServices.GetRequiredService<IIdentityServerInteractionService>();\n            await interaction.GrantConsentAsync(ConsentRequest, ConsentResponse);\n            ConsentResponse = null;\n\n            var url = ctx.Request.Query[Options.UserInteraction.ConsentReturnUrlParameter].FirstOrDefault();\n            if (url != null)\n            {\n                ctx.Response.RedirectIfAllowed(url);\n            }\n        }\n    }\n\n    public bool ErrorWasCalled { get; set; }\n    public ErrorMessage ErrorMessage { get; set; }\n\n    private async Task OnError(HttpContext ctx)\n    {\n        ErrorWasCalled = true;\n        await ReadErrorMessage(ctx);\n    }\n\n    private async Task ReadErrorMessage(HttpContext ctx)\n    {\n        var interaction = ctx.RequestServices.GetRequiredService<IIdentityServerInteractionService>();\n        ErrorMessage = await interaction.GetErrorContextAsync(ctx.Request.Query[\"errorId\"].FirstOrDefault());\n    }\n\n    /* helpers */\n    public async Task LoginAsync(ClaimsPrincipal subject)\n    {\n        var old = BrowserClient.AllowAutoRedirect;\n        BrowserClient.AllowAutoRedirect = false;\n\n        Subject = subject;\n        await BrowserClient.GetAsync(LoginPage);\n\n        BrowserClient.AllowAutoRedirect = old;\n    }\n\n    public async Task LoginAsync(string subject)\n    {\n        await LoginAsync(new IdentityServerUser(subject).CreatePrincipal());\n    }\n\n    public void RemoveLoginCookie()\n    {\n        BrowserClient.RemoveCookie(BaseUrl, IdentityServerConstants.DefaultCookieAuthenticationScheme);\n    }\n    public void RemoveSessionCookie()\n    {\n        BrowserClient.RemoveCookie(BaseUrl, IdentityServerConstants.DefaultCheckSessionCookieName);\n    }\n    public Cookie GetSessionCookie()\n    {\n        return BrowserClient.GetCookie(BaseUrl, IdentityServerConstants.DefaultCheckSessionCookieName);\n    }\n\n    public string CreateAuthorizeUrl(\n        string clientId = null,\n        string responseType = null,\n        string scope = null,\n        string redirectUri = null,\n        string state = null,\n        string nonce = null,\n        string loginHint = null,\n        string acrValues = null,\n        string responseMode = null,\n        string codeChallenge = null,\n        string codeChallengeMethod = null,\n        object extra = null)\n    {\n        Parameters prms = extra is null ? null : Parameters.FromObject(extra);\n        var url = new RequestUrl(AuthorizeEndpoint).CreateAuthorizeUrl(\n            clientId: clientId,\n            responseType: responseType,\n            scope: scope,\n            redirectUri: redirectUri,\n            state: state,\n            nonce: nonce,\n            loginHint: loginHint,\n            acrValues: acrValues,\n            responseMode: responseMode,\n            codeChallenge: codeChallenge,\n            codeChallengeMethod: codeChallengeMethod,\n            extra: prms);\n        return url;\n    }\n\n    public AuthorizeResponse ParseAuthorizationResponseUrl(string url)\n    {\n        return new AuthorizeResponse(url);\n    }\n\n    public async Task<AuthorizeResponse> RequestAuthorizationEndpointAsync(\n        string clientId,\n        string responseType,\n        string scope = null,\n        string redirectUri = null,\n        string state = null,\n        string nonce = null,\n        string loginHint = null,\n        string acrValues = null,\n        string responseMode = null,\n        string codeChallenge = null,\n        string codeChallengeMethod = null,\n        object extra = null)\n    {\n        var old = BrowserClient.AllowAutoRedirect;\n        BrowserClient.AllowAutoRedirect = false;\n\n        var url = CreateAuthorizeUrl(clientId, responseType, scope, redirectUri, state, nonce, loginHint, acrValues, responseMode, codeChallenge, codeChallengeMethod, extra);\n        var result = await BrowserClient.GetAsync(url);\n        result.StatusCode.Should().Be(HttpStatusCode.Found);\n\n        BrowserClient.AllowAutoRedirect = old;\n\n        var redirect = result.Headers.Location.ToString();\n        if (redirect.StartsWith(IdentityServerPipeline.ErrorPage))\n        {\n            // request error page in pipeline so we can get error info\n            await BrowserClient.GetAsync(redirect);\n\n            // no redirect to client\n            return null;\n        }\n\n        return new AuthorizeResponse(redirect);\n    }\n}\n\npublic class MockMessageHandler : DelegatingHandler\n{\n    public bool InvokeWasCalled { get; set; }\n    public Func<HttpRequestMessage, Task> OnInvoke { get; set; }\n    public HttpResponseMessage Response { get; set; } = new HttpResponseMessage(HttpStatusCode.OK);\n\n    protected override async Task<HttpResponseMessage> SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)\n    {\n        InvokeWasCalled = true;\n\n        if (OnInvoke != null)\n        {\n            await OnInvoke.Invoke(request);\n        }\n        return Response;\n    }\n}\n\npublic class MockExternalAuthenticationHandler :\n    IAuthenticationHandler,\n    IAuthenticationSignInHandler,\n    IAuthenticationRequestHandler\n{\n    private readonly IHttpContextAccessor _httpContextAccessor;\n    private HttpContext HttpContext => _httpContextAccessor.HttpContext;\n\n    public Func<HttpContext, Task<bool>> OnFederatedSignout =\n        async context =>\n        {\n            await context.SignOutAsync();\n            return true;\n        };\n\n    public MockExternalAuthenticationHandler(IHttpContextAccessor httpContextAccessor)\n    {\n        _httpContextAccessor = httpContextAccessor;\n    }\n\n    public async Task<bool> HandleRequestAsync()\n    {\n        if (HttpContext.Request.Path == IdentityServerPipeline.FederatedSignOutPath)\n        {\n            return await OnFederatedSignout(HttpContext);\n        }\n\n        return false;\n    }\n\n    public Task<AuthenticateResult> AuthenticateAsync()\n    {\n        return Task.FromResult(AuthenticateResult.NoResult());\n    }\n\n    public Task ChallengeAsync(AuthenticationProperties properties)\n    {\n        return Task.CompletedTask;\n    }\n\n    public Task ForbidAsync(AuthenticationProperties properties)\n    {\n        return Task.CompletedTask;\n    }\n\n    public Task InitializeAsync(AuthenticationScheme scheme, HttpContext context)\n    {\n        return Task.CompletedTask;\n    }\n\n    public Task SignInAsync(ClaimsPrincipal user, AuthenticationProperties properties)\n    {\n        return Task.CompletedTask;\n    }\n\n    public Task SignOutAsync(AuthenticationProperties properties)\n    {\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Common/MessageHandlerWrapper.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Net.Http;\nusing System.Threading;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.IntegrationTests.Common;\n\npublic class MessageHandlerWrapper : DelegatingHandler\n{\n    public HttpResponseMessage Response { get; set; }\n\n    public MessageHandlerWrapper(HttpMessageHandler handler)\n        : base(handler)\n    {\n    }\n\n    protected async override Task<HttpResponseMessage> SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)\n    {\n        Response = await base.SendAsync(request, cancellationToken);\n        return Response;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Common/NetworkHandler.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Net;\nusing System.Net.Http;\nusing System.Threading;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.IntegrationTests.Common;\n\npublic class NetworkHandler : HttpMessageHandler\n{\n    enum Behavior\n    {\n        Throw,\n        ReturnError,\n        ReturnDocument\n    }\n\n    private readonly Exception _exception;\n    private readonly Behavior _behavior;\n    private readonly HttpStatusCode _statusCode;\n    private readonly string _reason;\n    private readonly string _document;\n    private readonly Func<HttpRequestMessage, string> _selector;\n    private readonly Func<HttpRequestMessage, HttpResponseMessage> _action;\n\n    public HttpRequestMessage Request { get; set; }\n    public string Body { get; set; }\n\n    public NetworkHandler(Exception exception)\n    {\n        _exception = exception;\n        _behavior = Behavior.Throw;\n    }\n\n    public NetworkHandler(HttpStatusCode statusCode, string reason)\n    {\n        _statusCode = statusCode;\n        _reason = reason;\n\n        _behavior = Behavior.ReturnError;\n    }\n\n    public NetworkHandler(string document, HttpStatusCode statusCode)\n    {\n        _statusCode = statusCode;\n        _document = document;\n        _behavior = Behavior.ReturnDocument;\n    }\n\n    public NetworkHandler(Func<HttpRequestMessage, string> documentSelector, HttpStatusCode statusCode)\n    {\n        _statusCode = statusCode;\n        _selector = documentSelector;\n        _behavior = Behavior.ReturnDocument;\n    }\n\n    public NetworkHandler(Func<HttpRequestMessage, HttpResponseMessage> action)\n    {\n        _action = action;\n    }\n\n    protected override async Task<HttpResponseMessage> SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)\n    {\n        Request = request;\n        Body = await SafeReadContentFrom(request);\n\n        if (_action != null)\n        {\n            return _action(request);\n        }\n\n        if (_behavior == Behavior.Throw) throw _exception;\n\n        var response = new HttpResponseMessage(_statusCode);\n\n        if (_behavior == Behavior.ReturnError)\n        {\n            response.ReasonPhrase = _reason;\n        }\n\n        if (_behavior == Behavior.ReturnDocument)\n        {\n            if (_selector != null)\n            {\n                response.Content = new StringContent(_selector(request));\n            }\n            else\n            {\n                response.Content = new StringContent(_document);\n            }\n        }\n\n        return response;\n    }\n\n    private async Task<string> SafeReadContentFrom(HttpRequestMessage request)\n    {\n        if (request.Content == null) return null;\n\n        return await request.Content.ReadAsStringAsync();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Common/TestCert.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.IO;\nusing System.Security.Cryptography.X509Certificates;\n\nnamespace IdentityServer.IntegrationTests.Common;\n\ninternal static class TestCert\n{\n    public static X509Certificate2 Load()\n    {\n        var cert = Path.Combine(System.AppContext.BaseDirectory, \"identityserver_testing.pfx\");\n        return new X509Certificate2(cert, \"password\");\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Conformance/Basic/ClientAuthenticationTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Net.Http;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Conformance.Basic;\n\npublic class ClientAuthenticationTests \n{\n    private const string Category = \"Conformance.Basic.ClientAuthenticationTests\";\n\n    private IdentityServerPipeline _pipeline = new IdentityServerPipeline();\n\n    public ClientAuthenticationTests()\n    {\n        _pipeline.IdentityScopes.Add(new IdentityResources.OpenId());\n        _pipeline.Clients.Add(new Client\n        {\n            Enabled = true,\n            ClientId = \"code_pipeline.Client\",\n            ClientSecrets = new List<Secret>\n            {\n                new Secret(\"secret\".Sha512())\n            },\n\n            AllowedGrantTypes = GrantTypes.Code,\n            AllowedScopes = { \"openid\" },\n\n            RequireConsent = false,\n            RequirePkce = false,\n            RedirectUris = new List<string>\n            {\n                \"https://code_pipeline.Client/callback\",\n                \"https://code_pipeline.Client/callback?foo=bar&baz=quux\"\n            }\n        });\n\n        _pipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n               {\n                    new Claim(\"name\", \"Bob Loblaw\"),\n                    new Claim(\"email\", \"bob@loblaw.com\"),\n                    new Claim(\"role\", \"Attorney\")\n               }\n        });\n\n        _pipeline.Initialize();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Token_endpoint_supports_client_authentication_with_basic_authentication_with_POST()\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n\n        _pipeline.BrowserClient.AllowAutoRedirect = false;\n        var url = _pipeline.CreateAuthorizeUrl(\n                       clientId: \"code_pipeline.Client\",\n                       responseType: \"code\",\n                       scope: \"openid\",\n                       redirectUri: \"https://code_pipeline.Client/callback?foo=bar&baz=quux\",\n                       nonce: nonce);\n        var response = await _pipeline.BrowserClient.GetAsync(url);\n\n        var authorization = _pipeline.ParseAuthorizationResponseUrl(response.Headers.Location.ToString());\n        authorization.Code.Should().NotBeNull();\n\n        var code = authorization.Code;\n\n        // backchannel client\n        var wrapper = new MessageHandlerWrapper(_pipeline.Handler);\n        var tokenClient = new HttpClient(wrapper);\n        var tokenResult = await tokenClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = \"code_pipeline.Client\",\n            ClientSecret = \"secret\",\n\n            Code = code,\n            RedirectUri = \"https://code_pipeline.Client/callback?foo=bar&baz=quux\"\n        });\n\n        tokenResult.IsError.Should().BeFalse();\n        tokenResult.HttpErrorReason.Should().Be(\"OK\");\n        tokenResult.TokenType.Should().Be(\"Bearer\");\n        tokenResult.AccessToken.Should().NotBeNull();\n        tokenResult.ExpiresIn.Should().BeGreaterThan(0);\n        tokenResult.IdentityToken.Should().NotBeNull();\n\n        wrapper.Response.Headers.CacheControl.NoCache.Should().BeTrue();\n        wrapper.Response.Headers.CacheControl.NoStore.Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Token_endpoint_supports_client_authentication_with_form_encoded_authentication_in_POST_body()\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n\n        _pipeline.BrowserClient.AllowAutoRedirect = false;\n        var url = _pipeline.CreateAuthorizeUrl(\n                       clientId: \"code_pipeline.Client\",\n                       responseType: \"code\",\n                       scope: \"openid\",\n                       redirectUri: \"https://code_pipeline.Client/callback?foo=bar&baz=quux\",\n                       nonce: nonce);\n        var response = await _pipeline.BrowserClient.GetAsync(url);\n\n        var authorization = _pipeline.ParseAuthorizationResponseUrl(response.Headers.Location.ToString());\n        authorization.Code.Should().NotBeNull();\n\n        var code = authorization.Code;\n\n        // backchannel client\n        var wrapper = new MessageHandlerWrapper(_pipeline.Handler);\n        var tokenClient = new HttpClient(wrapper);\n        var tokenResult = await tokenClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = \"code_pipeline.Client\",\n            ClientSecret = \"secret\",\n            ClientCredentialStyle = ClientCredentialStyle.PostBody,\n\n            Code = code,\n            RedirectUri = \"https://code_pipeline.Client/callback?foo=bar&baz=quux\"\n        });\n\n        tokenResult.IsError.Should().BeFalse();\n        tokenResult.HttpErrorReason.Should().Be(\"OK\");\n        tokenResult.TokenType.Should().Be(\"Bearer\");\n        tokenResult.AccessToken.Should().NotBeNull();\n        tokenResult.ExpiresIn.Should().BeGreaterThan(0);\n        tokenResult.IdentityToken.Should().NotBeNull();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Conformance/Basic/CodeFlowTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.IdentityModel.Tokens.Jwt;\nusing System.Linq;\nusing System.Net.Http;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Conformance.Basic;\n\npublic class CodeFlowTests \n{\n    private const string Category = \"Conformance.Basic.CodeFlowTests\";\n\n    private IdentityServerPipeline _pipeline = new IdentityServerPipeline();\n\n    public CodeFlowTests()\n    {\n        _pipeline.IdentityScopes.Add(new IdentityResources.OpenId());\n        _pipeline.Clients.Add(new Client\n        {\n            Enabled = true,\n            ClientId = \"code_pipeline.Client\",\n            ClientSecrets = new List<Secret>\n            {\n                new Secret(\"secret\".Sha512())\n            },\n\n            AllowedGrantTypes = GrantTypes.Code,\n            AllowedScopes = { \"openid\" },\n\n            RequireConsent = false,\n            RequirePkce = false,\n            RedirectUris = new List<string>\n            {\n                \"https://code_pipeline.Client/callback\",\n                \"https://code_pipeline.Client/callback?foo=bar&baz=quux\"\n            }\n        });\n\n        _pipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n               {\n                    new Claim(\"name\", \"Bob Loblaw\"),\n                    new Claim(\"email\", \"bob@loblaw.com\"),\n                    new Claim(\"role\", \"Attorney\")\n               }\n        });\n\n        _pipeline.Initialize();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task No_state_should_not_result_in_shash()\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n\n        _pipeline.BrowserClient.AllowAutoRedirect = false;\n        var url = _pipeline.CreateAuthorizeUrl(\n                       clientId: \"code_pipeline.Client\",\n                       responseType: \"code\",\n                       scope: \"openid\",\n                       redirectUri: \"https://code_pipeline.Client/callback?foo=bar&baz=quux\",\n                       nonce: nonce);\n        var response = await _pipeline.BrowserClient.GetAsync(url);\n\n        var authorization = _pipeline.ParseAuthorizationResponseUrl(response.Headers.Location.ToString());\n        authorization.Code.Should().NotBeNull();\n\n        var code = authorization.Code;\n\n        // backchannel client\n        var wrapper = new MessageHandlerWrapper(_pipeline.Handler);\n        var tokenClient = new HttpClient(wrapper);\n        var tokenResult = await tokenClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = \"code_pipeline.Client\",\n            ClientSecret = \"secret\",\n\n            Code = code,\n            RedirectUri = \"https://code_pipeline.Client/callback?foo=bar&baz=quux\"\n        });\n\n        tokenResult.IsError.Should().BeFalse();\n        tokenResult.HttpErrorReason.Should().Be(\"OK\");\n        tokenResult.TokenType.Should().Be(\"Bearer\");\n        tokenResult.AccessToken.Should().NotBeNull();\n        tokenResult.ExpiresIn.Should().BeGreaterThan(0);\n        tokenResult.IdentityToken.Should().NotBeNull();\n\n        var token = new JwtSecurityToken(tokenResult.IdentityToken);\n        \n        var s_hash = token.Claims.FirstOrDefault(c => c.Type == \"s_hash\");\n        s_hash.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task State_should_result_in_shash()\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n\n        _pipeline.BrowserClient.AllowAutoRedirect = false;\n        var url = _pipeline.CreateAuthorizeUrl(\n                       clientId: \"code_pipeline.Client\",\n                       responseType: \"code\",\n                       scope: \"openid\",\n                       redirectUri: \"https://code_pipeline.Client/callback?foo=bar&baz=quux\",\n                       state: \"state\",\n                       nonce: nonce);\n        var response = await _pipeline.BrowserClient.GetAsync(url);\n\n        var authorization = _pipeline.ParseAuthorizationResponseUrl(response.Headers.Location.ToString());\n        authorization.Code.Should().NotBeNull();\n\n        var code = authorization.Code;\n\n        // backchannel client\n        var wrapper = new MessageHandlerWrapper(_pipeline.Handler);\n        var tokenClient = new HttpClient(wrapper);\n        var tokenResult = await tokenClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = \"code_pipeline.Client\",\n            ClientSecret = \"secret\",\n\n            Code = code,\n            RedirectUri = \"https://code_pipeline.Client/callback?foo=bar&baz=quux\"\n        });\n\n        tokenResult.IsError.Should().BeFalse();\n        tokenResult.HttpErrorReason.Should().Be(\"OK\");\n        tokenResult.TokenType.Should().Be(\"Bearer\");\n        tokenResult.AccessToken.Should().NotBeNull();\n        tokenResult.ExpiresIn.Should().BeGreaterThan(0);\n        tokenResult.IdentityToken.Should().NotBeNull();\n\n        var token = new JwtSecurityToken(tokenResult.IdentityToken);\n        \n        var s_hash = token.Claims.FirstOrDefault(c => c.Type == \"s_hash\");\n        s_hash.Should().NotBeNull();\n        s_hash.Value.Should().Be(CryptoHelper.CreateHashClaimValue(\"state\", \"RS256\"));\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Conformance/Basic/RedirectUriTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Net;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Conformance.Basic;\n\npublic class RedirectUriTests\n{\n    private const string Category = \"Conformance.Basic.RedirectUriTests\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    public RedirectUriTests()\n    {\n        _mockPipeline.Initialize();\n\n        _mockPipeline.Clients.Add(new Client\n        {\n            Enabled = true,\n            ClientId = \"code_client\",\n            ClientSecrets = new List<Secret>\n            {\n                new Secret(\"secret\".Sha512())\n            },\n\n            AllowedGrantTypes = GrantTypes.Code,\n            AllowedScopes = { \"openid\" },\n\n            RequireConsent = false,\n            RequirePkce = false,\n            RedirectUris = new List<string>\n            {\n                \"https://code_client/callback\",\n                \"https://code_client/callback?foo=bar&baz=quux\"\n            }\n        });\n\n        _mockPipeline.IdentityScopes.Add(new IdentityResources.OpenId());\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n                {\n                    new Claim(\"name\", \"Bob Loblaw\"),\n                    new Claim(\"email\", \"bob@loblaw.com\"),\n                    new Claim(\"role\", \"Attorney\")\n                }\n        });\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Reject_redirect_uri_not_matching_registered_redirect_uri()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var state = Guid.NewGuid().ToString();\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n                       clientId: \"code_client\",\n                       responseType: \"code\",\n                       scope: \"openid\",\n                       redirectUri: \"https://bad\",\n                       state: state,\n                       nonce: nonce);\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Reject_request_without_redirect_uri_when_multiple_registered()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var state = Guid.NewGuid().ToString();\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n                      clientId: \"code_client\",\n                      responseType: \"code\",\n                      scope: \"openid\",\n                      // redirectUri deliberately absent \n                      redirectUri: null,\n                      state: state,\n                      nonce: nonce);\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Preserves_query_parameters_in_redirect_uri()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var state = Guid.NewGuid().ToString();\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var url = _mockPipeline.CreateAuthorizeUrl(\n                       clientId: \"code_client\",\n                       responseType: \"code\",\n                       scope: \"openid\",\n                       redirectUri: \"https://code_client/callback?foo=bar&baz=quux\",\n                       state: state,\n                       nonce: nonce);\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"https://code_client/callback?\");\n        var authorization = _mockPipeline.ParseAuthorizationResponseUrl(response.Headers.Location.ToString());\n        authorization.Code.Should().NotBeNull();\n        authorization.State.Should().Be(state);\n        var query = Microsoft.AspNetCore.WebUtilities.QueryHelpers.ParseQuery(response.Headers.Location.Query);\n        query[\"foo\"].ToString().Should().Be(\"bar\");\n        query[\"baz\"].ToString().Should().Be(\"quux\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Rejects_redirect_uri_when_query_parameter_does_not_match()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var state = Guid.NewGuid().ToString();\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n                       clientId: \"code_client\",\n                       responseType: \"code\",\n                       scope: \"openid\",\n                       redirectUri: \"https://code_client/callback?baz=quux&foo=bar\",\n                       state: state,\n                       nonce: nonce);\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request\");\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Conformance/Basic/ResponseTypeResponseModeTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Net;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Conformance.Basic;\n\npublic class ResponseTypeResponseModeTests\n{\n    private const string Category = \"Conformance.Basic.ResponseTypeResponseModeTests\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    public ResponseTypeResponseModeTests()\n    {\n        _mockPipeline.Initialize();\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        _mockPipeline.Clients.Add(new Client\n        {\n            Enabled = true,\n            ClientId = \"code_client\",\n            ClientSecrets = new List<Secret>\n            {\n                new Secret(\"secret\".Sha512())\n            },\n\n            AllowedGrantTypes = GrantTypes.Code,\n            AllowedScopes = { \"openid\" },\n\n            RequireConsent = false,\n            RequirePkce = false,\n            RedirectUris = new List<string>\n            {\n                \"https://code_client/callback\"\n            }\n        });\n\n        _mockPipeline.IdentityScopes.Add(new IdentityResources.OpenId());\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n                {\n                    new Claim(\"name\", \"Bob Loblaw\"),\n                    new Claim(\"email\", \"bob@loblaw.com\"),\n                    new Claim(\"role\", \"Attorney\")\n                }\n        });\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Request_with_response_type_code_supported()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var metadata = await _mockPipeline.BackChannelClient.GetAsync(IdentityServerPipeline.DiscoveryEndpoint);\n        metadata.StatusCode.Should().Be(HttpStatusCode.OK);\n\n        var state = Guid.NewGuid().ToString();\n        var nonce = Guid.NewGuid().ToString();\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n                       clientId: \"code_client\",\n                       responseType: \"code\",\n                       scope: \"openid\",\n                       redirectUri: \"https://code_client/callback\",\n                       state: state,\n                       nonce: nonce);\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        response.StatusCode.Should().Be(HttpStatusCode.Found);\n\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IsError.Should().BeFalse();\n        authorization.Code.Should().NotBeNull();\n        authorization.State.Should().Be(state);\n    }\n\n    // this might not be in sync with the actual conformance tests\n    // since we dead-end on the error page due to changes \n    // to follow the RFC to address open redirect in original OAuth RFC\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Request_missing_response_type_rejected()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var state = Guid.NewGuid().ToString();\n        var nonce = Guid.NewGuid().ToString();\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"code_client\",\n            responseType: null, // missing\n            scope: \"openid\",\n            redirectUri: \"https://code_client/callback\",\n            state: state,\n            nonce: nonce);\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"unsupported_response_type\");\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Conformance/Pkce/PkceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Security.Claims;\nusing System.Text;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Conformance.Pkce;\n\npublic class PkceTests\n{\n    private const string Category = \"PKCE\";\n\n    private IdentityServerPipeline _pipeline = new IdentityServerPipeline();\n\n    private Client client;\n\n    private const string client_id = \"code_client\";\n    private const string client_id_optional = \"code_client_optional\";\n    private const string client_id_plain = \"code_plain_client\";\n    private const string client_id_pkce = \"codewithproofkey_client\";\n    private const string client_id_pkce_plain = \"codewithproofkey_plain_client\";\n\n\n    private string redirect_uri = \"https://code_client/callback\";\n    private string code_verifier = \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\";\n    private string client_secret = \"secret\";\n    private string response_type = \"code\";\n\n    public PkceTests()\n    {\n        _pipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n            {\n                    new Claim(\"name\", \"Bob Loblaw\"),\n                    new Claim(\"email\", \"bob@loblaw.com\"),\n                    new Claim(\"role\", \"Attorney\")\n            }\n        });\n        _pipeline.IdentityScopes.Add(new IdentityResources.OpenId());\n\n        _pipeline.Clients.Add(client = new Client\n        {\n            Enabled = true,\n            ClientId = client_id,\n            ClientSecrets = new List<Secret>\n            {\n                new Secret(client_secret.Sha256())\n            },\n\n            AllowedGrantTypes = GrantTypes.Code,\n            RequirePkce = true,\n\n            AllowedScopes = { \"openid\" },\n\n            RequireConsent = false,\n            RedirectUris = new List<string>\n            {\n                redirect_uri\n            }\n        });\n        _pipeline.Clients.Add(client = new Client\n        {\n            Enabled = true,\n            ClientId = client_id_optional,\n            ClientSecrets = new List<Secret>\n            {\n                new Secret(client_secret.Sha256())\n            },\n\n            AllowedGrantTypes = GrantTypes.Code,\n            RequirePkce = false,\n\n            AllowedScopes = { \"openid\" },\n\n            RequireConsent = false,\n            RedirectUris = new List<string>\n            {\n                redirect_uri\n            }\n        });\n        _pipeline.Clients.Add(client = new Client\n        {\n            Enabled = true,\n            ClientId = client_id_pkce,\n            ClientSecrets = new List<Secret>\n            {\n                new Secret(client_secret.Sha256())\n            },\n\n            AllowedGrantTypes = GrantTypes.Code,\n            RequirePkce = true,\n\n            AllowedScopes = { \"openid\" },\n\n            RequireConsent = false,\n            RedirectUris = new List<string>\n            {\n                redirect_uri\n            }\n        });\n\n        // allow plain text PKCE\n        _pipeline.Clients.Add(client = new Client\n        {\n            Enabled = true,\n            ClientId = client_id_plain,\n            ClientSecrets = new List<Secret>\n            {\n                new Secret(client_secret.Sha256())\n            },\n\n            AllowedGrantTypes = GrantTypes.Code,\n            RequirePkce = true,\n            AllowPlainTextPkce = true,\n\n            AllowedScopes = { \"openid\" },\n\n            RequireConsent = false,\n            RedirectUris = new List<string>\n            {\n                redirect_uri\n            }\n        });\n        _pipeline.Clients.Add(client = new Client\n        {\n            Enabled = true,\n            ClientId = client_id_pkce_plain,\n            ClientSecrets = new List<Secret>\n            {\n                new Secret(client_secret.Sha256())\n            },\n\n            AllowedGrantTypes = GrantTypes.Code,\n            RequirePkce = true,\n            AllowPlainTextPkce = true,\n\n            AllowedScopes = { \"openid\" },\n\n            RequireConsent = false,\n            RedirectUris = new List<string>\n            {\n                redirect_uri\n            }\n        });\n\n        _pipeline.Initialize();\n    }\n\n    [Theory]\n    [InlineData(client_id)]\n    [InlineData(client_id_pkce)]\n    [Trait(\"Category\", Category)]\n    public async Task Client_cannot_use_plain_code_challenge_method(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var code_challenge = code_verifier;\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce,\n            codeChallenge: code_challenge,\n            codeChallengeMethod: OidcConstants.CodeChallengeMethods.Plain);\n\n        _pipeline.ErrorWasCalled.Should().BeTrue();\n        _pipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n    }\n\n    [Theory]\n    [InlineData(client_id_plain)]\n    [InlineData(client_id_pkce_plain)]\n    [Trait(\"Category\", Category)]\n    public async Task Client_can_use_plain_code_challenge_method(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var code_challenge = code_verifier;\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce,\n            codeChallenge: code_challenge,\n            codeChallengeMethod: OidcConstants.CodeChallengeMethods.Plain);\n\n        authorizeResponse.IsError.Should().BeFalse();\n\n        var code = authorizeResponse.Code;\n\n        var tokenResponse = await _pipeline.BackChannelClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = clientId,\n            ClientSecret = client_secret,\n\n            Code = code,\n            RedirectUri = redirect_uri,\n            CodeVerifier = code_verifier\n        });\n\n        tokenResponse.IsError.Should().BeFalse();\n        tokenResponse.TokenType.Should().Be(\"Bearer\");\n        tokenResponse.AccessToken.Should().NotBeNull();\n        tokenResponse.IdentityToken.Should().NotBeNull();\n        tokenResponse.ExpiresIn.Should().BeGreaterThan(0);\n    }\n\n    [Theory]\n    [InlineData(client_id)]\n    [InlineData(client_id_pkce)]\n    [Trait(\"Category\", Category)]\n    public async Task Client_can_use_sha256_code_challenge_method(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var code_challenge = Sha256OfCodeVerifier(code_verifier);\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce,\n            codeChallenge: code_challenge,\n            codeChallengeMethod: OidcConstants.CodeChallengeMethods.Sha256);\n\n        authorizeResponse.IsError.Should().BeFalse();\n\n        var code = authorizeResponse.Code;\n\n        var tokenResponse = await _pipeline.BackChannelClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = clientId,\n            ClientSecret = client_secret,\n\n            Code = code,\n            RedirectUri = redirect_uri,\n            CodeVerifier = code_verifier\n        });\n\n        tokenResponse.IsError.Should().BeFalse();\n        tokenResponse.TokenType.Should().Be(\"Bearer\");\n        tokenResponse.AccessToken.Should().NotBeNull();\n        tokenResponse.IdentityToken.Should().NotBeNull();\n        tokenResponse.ExpiresIn.Should().BeGreaterThan(0);\n    }\n\n    [Theory]\n    [InlineData(client_id_pkce)]\n    [InlineData(client_id_pkce_plain)]\n    [Trait(\"Category\", Category)]\n    public async Task Authorize_request_needs_code_challenge(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce);\n\n        authorizeResponse.Should().BeNull();\n    }\n    \n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Code_verifier_should_not_be_accepted_if_no_code_challenge_was_used()\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(client_id_optional,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce);\n\n        authorizeResponse.IsError.Should().BeFalse();\n\n        var code = authorizeResponse.Code;\n\n        var tokenResponse = await _pipeline.BackChannelClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = client_id_optional,\n            ClientSecret = client_secret,\n\n            Code = code,\n            RedirectUri = redirect_uri,\n            CodeVerifier = code_verifier\n        });\n\n        tokenResponse.IsError.Should().BeTrue();\n    }\n\n    [Theory]\n    [InlineData(client_id)]\n    [InlineData(client_id_plain)]\n    [InlineData(client_id_pkce)]\n    [InlineData(client_id_pkce_plain)]\n    [Trait(\"Category\", Category)]\n    public async Task Authorize_request_code_challenge_cannot_be_too_short(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var code_challenge = code_verifier;\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce,\n            codeChallenge:\"a\");\n\n        _pipeline.ErrorWasCalled.Should().BeTrue();\n        _pipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n    }\n\n    [Theory]\n    [InlineData(client_id)]\n    [InlineData(client_id_plain)]\n    [InlineData(client_id_pkce)]\n    [InlineData(client_id_pkce_plain)]\n    [Trait(\"Category\", Category)]\n    public async Task Authorize_request_code_challenge_cannot_be_too_long(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var code_challenge = code_verifier;\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce,\n            codeChallenge: new string('a', _pipeline.Options.InputLengthRestrictions.CodeChallengeMaxLength + 1)\n        );\n\n        _pipeline.ErrorWasCalled.Should().BeTrue();\n        _pipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n    }\n\n    [Theory]\n    [InlineData(client_id)]\n    [InlineData(client_id_plain)]\n    [InlineData(client_id_pkce)]\n    [InlineData(client_id_pkce_plain)]\n    [Trait(\"Category\", Category)]\n    public async Task Authorize_request_needs_supported_code_challenge_method(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var code_challenge = code_verifier;\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce,\n            codeChallenge: code_challenge,\n            codeChallengeMethod: \"unknown_code_challenge_method\"\n        );\n\n        authorizeResponse.Should().BeNull();\n    }\n\n    [Theory]\n    [InlineData(client_id_plain)]\n    [InlineData(client_id_pkce_plain)]\n    [Trait(\"Category\", Category)]\n    public async Task Token_request_needs_code_verifier(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var code_challenge = code_verifier;\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce,\n            codeChallenge: code_challenge,\n            codeChallengeMethod: OidcConstants.CodeChallengeMethods.Plain);\n\n        authorizeResponse.IsError.Should().BeFalse();\n\n        var code = authorizeResponse.Code;\n\n        var tokenResponse = await _pipeline.BackChannelClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = clientId,\n            ClientSecret = client_secret,\n\n            Code = code,\n            RedirectUri = redirect_uri,\n        });\n\n        tokenResponse.IsError.Should().BeTrue();\n        tokenResponse.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n    }\n\n    [Theory]\n    [InlineData(client_id_plain)]\n    [InlineData(client_id_pkce_plain)]\n    [Trait(\"Category\", Category)]\n    public async Task Token_request_code_verifier_cannot_be_too_short(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var code_challenge = code_verifier;\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce,\n            codeChallenge: code_challenge,\n            codeChallengeMethod: OidcConstants.CodeChallengeMethods.Plain);\n\n        authorizeResponse.IsError.Should().BeFalse();\n\n        var code = authorizeResponse.Code;\n\n        var tokenResponse = await _pipeline.BackChannelClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = clientId,\n            ClientSecret = client_secret,\n\n            Code = code,\n            RedirectUri = redirect_uri,\n            CodeVerifier = \"a\"\n        });\n\n        tokenResponse.IsError.Should().BeTrue();\n        tokenResponse.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n    }\n\n    [Theory]\n    [InlineData(client_id_plain)]\n    [InlineData(client_id_pkce_plain)]\n    [Trait(\"Category\", Category)]\n    public async Task Token_request_code_verifier_cannot_be_too_long(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var code_challenge = code_verifier;\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce,\n            codeChallenge: code_challenge,\n            codeChallengeMethod: OidcConstants.CodeChallengeMethods.Plain);\n\n        authorizeResponse.IsError.Should().BeFalse();\n\n        var code = authorizeResponse.Code;\n\n        var tokenResponse = await _pipeline.BackChannelClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = clientId,\n            ClientSecret = client_secret,\n\n            Code = code,\n            RedirectUri = redirect_uri,\n            CodeVerifier = new string('a', _pipeline.Options.InputLengthRestrictions.CodeVerifierMaxLength + 1)\n        });\n\n        tokenResponse.IsError.Should().BeTrue();\n        tokenResponse.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n    }\n\n    [Theory]\n    [InlineData(client_id_plain)]\n    [InlineData(client_id_pkce_plain)]\n    [Trait(\"Category\", Category)]\n    public async Task Token_request_code_verifier_must_match_with_code_chalenge(string clientId)\n    {\n        await _pipeline.LoginAsync(\"bob\");\n\n        var nonce = Guid.NewGuid().ToString();\n        var code_challenge = code_verifier;\n        var authorizeResponse = await _pipeline.RequestAuthorizationEndpointAsync(clientId,\n            response_type,\n            IdentityServerConstants.StandardScopes.OpenId,\n            redirect_uri,\n            nonce: nonce,\n            codeChallenge: code_challenge,\n            codeChallengeMethod: OidcConstants.CodeChallengeMethods.Plain);\n\n        authorizeResponse.IsError.Should().BeFalse();\n\n        var code = authorizeResponse.Code;\n\n        var tokenResponse = await _pipeline.BackChannelClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = clientId,\n            ClientSecret = client_secret,\n\n            Code = code,\n            RedirectUri = redirect_uri,\n            CodeVerifier = \"mismatched_code_verifier\"\n        });\n\n        tokenResponse.IsError.Should().BeTrue();\n        tokenResponse.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n    }\n\n    private static string Sha256OfCodeVerifier(string codeVerifier)\n    {\n        var codeVerifierBytes = Encoding.ASCII.GetBytes(codeVerifier);\n        var hashedBytes = codeVerifierBytes.Sha256();\n        var transformedCodeVerifier = Base64Url.Encode(hashedBytes);\n\n        return transformedCodeVerifier;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Authorize/AuthorizeTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Net;\nusing System.Net.Http;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Stores.Default;\nusing IdentityServer8.Test;\nusing Microsoft.Extensions.DependencyInjection;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Authorize;\n\npublic class AuthorizeTests\n{\n    private const string Category = \"Authorize endpoint\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    private Client _client1;\n\n    public AuthorizeTests()\n    {\n        _mockPipeline.Clients.AddRange(new Client[] {\n            _client1 = new Client\n            {\n                ClientId = \"client1\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = false,\n\n                AllowedScopes = new List<string> { \"openid\", \"profile\" },\n                RedirectUris = new List<string> { \"https://client1/callback\" },\n                AllowAccessTokensViaBrowser = true\n            },\n            new Client\n            {\n                ClientId = \"client2\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = true,\n\n                AllowedScopes = new List<string> { \"openid\", \"profile\", \"api1\", \"api2\" },\n                RedirectUris = new List<string> { \"https://client2/callback\" },\n                AllowAccessTokensViaBrowser = true\n            },\n            new Client\n            {\n                ClientId = \"client3\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = false,\n\n                AllowedScopes = new List<string> { \"openid\", \"profile\", \"api1\", \"api2\" },\n                RedirectUris = new List<string> { \"https://client3/callback\" },\n                AllowAccessTokensViaBrowser = true,\n                EnableLocalLogin = false,\n                IdentityProviderRestrictions = new List<string> { \"google\" }\n            },\n            new Client\n            {\n                ClientId = \"client4\",\n                AllowedGrantTypes = GrantTypes.Code,\n                RequireClientSecret = false,\n                RequireConsent = false,\n                RequirePkce = false,\n                AllowedScopes = new List<string> { \"openid\", \"profile\", \"api1\", \"api2\" },\n                RedirectUris = new List<string> { \"https://client4/callback\" },\n            },\n\n        });\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n            {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n            }\n        });\n\n        _mockPipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n            new IdentityResources.Email()\n        });\n        _mockPipeline.ApiResources.AddRange(new ApiResource[] {\n            new ApiResource\n            {\n                Name = \"api\",\n                Scopes = { \"api1\", \"api2\" }\n            }\n        });\n        _mockPipeline.ApiScopes.AddRange(new ApiScope[] {\n            new ApiScope\n            {\n                Name = \"api1\"\n            },\n            new ApiScope\n            {\n                Name = \"api2\"\n            }\n        });\n\n        _mockPipeline.Initialize();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task get_request_should_not_return_404()\n    {\n        var response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.AuthorizeEndpoint);\n\n        response.StatusCode.Should().NotBe(HttpStatusCode.NotFound);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task post_request_without_form_should_return_415()\n    {\n        var response = await _mockPipeline.BrowserClient.PostAsync(IdentityServerPipeline.AuthorizeEndpoint, new StringContent(\"foo\"));\n\n        response.StatusCode.Should().Be(HttpStatusCode.UnsupportedMediaType);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task post_request_should_return_200()\n    {\n        var response = await _mockPipeline.BrowserClient.PostAsync(IdentityServerPipeline.AuthorizeEndpoint,\n            new FormUrlEncodedContent(\n                new Dictionary<string, string> { }));\n\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task get_request_should_not_return_500()\n    {\n        var response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.AuthorizeEndpoint);\n\n        ((int) response.StatusCode).Should().BeLessThan(500);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task anonymous_user_should_be_redirected_to_login_page()\n    {\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginWasCalled.Should().BeTrue();\n    }\n\n    [Theory]\n    [InlineData((Type) null)]\n    [InlineData(typeof(QueryStringAuthorizationParametersMessageStore))]\n    [InlineData(typeof(DistributedCacheAuthorizationParametersMessageStore))]\n    [Trait(\"Category\", Category)]\n    public async Task signin_request_should_have_authorization_params(Type storeType)\n    {\n        if (storeType != null)\n        {\n            _mockPipeline.OnPostConfigureServices += services =>\n            {\n                services.AddTransient(typeof(IAuthorizationParametersMessageStore), storeType);\n            };\n            _mockPipeline.Initialize();\n        }\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            loginHint: \"login_hint_value\",\n            acrValues: \"acr_1 acr_2 tenant:tenant_value idp:idp_value\",\n            extra: new\n            {\n                display = \"popup\", // must use a valid value from the spec for display\n                ui_locales = \"ui_locale_value\",\n                custom_foo = \"foo_value\"\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url + \"&foo=bar\");\n\n        _mockPipeline.LoginRequest.Should().NotBeNull();\n        _mockPipeline.LoginRequest.Client.ClientId.Should().Be(\"client1\");\n        _mockPipeline.LoginRequest.DisplayMode.Should().Be(\"popup\");\n        _mockPipeline.LoginRequest.UiLocales.Should().Be(\"ui_locale_value\");\n        _mockPipeline.LoginRequest.IdP.Should().Be(\"idp_value\");\n        _mockPipeline.LoginRequest.Tenant.Should().Be(\"tenant_value\");\n        _mockPipeline.LoginRequest.LoginHint.Should().Be(\"login_hint_value\");\n        _mockPipeline.LoginRequest.AcrValues.Should().BeEquivalentTo(new string[] { \"acr_2\", \"acr_1\" });\n        _mockPipeline.LoginRequest.Parameters.AllKeys.Should().Contain(\"foo\");\n        _mockPipeline.LoginRequest.Parameters[\"foo\"].Should().Be(\"bar\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task signin_response_should_allow_successful_authorization_response()\n    {\n        _mockPipeline.Subject = new IdentityServerUser(\"bob\").CreatePrincipal();\n        _mockPipeline.BrowserClient.StopRedirectingAfter = 2;\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"https://client1/callback\");\n\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IsError.Should().BeFalse();\n        authorization.IdentityToken.Should().NotBeNull();\n        authorization.State.Should().Be(\"123_state\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authenticated_user_with_valid_request_should_receive_authorization_response()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"https://client1/callback\");\n\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IsError.Should().BeFalse();\n        authorization.IdentityToken.Should().NotBeNull();\n        authorization.State.Should().Be(\"123_state\");\n    }\n\n    [Theory]\n    [InlineData((Type) null)]\n    [InlineData(typeof(QueryStringAuthorizationParametersMessageStore))]\n    [InlineData(typeof(DistributedCacheAuthorizationParametersMessageStore))]\n    [Trait(\"Category\", Category)]\n    public async Task login_response_and_consent_response_should_receive_authorization_response(Type storeType)\n    {\n        if (storeType != null)\n        {\n            _mockPipeline.OnPostConfigureServices += services =>\n            {\n                services.AddTransient(typeof(IAuthorizationParametersMessageStore), storeType);\n            };\n            _mockPipeline.Initialize();\n        }\n\n        _mockPipeline.Subject = new IdentityServerUser(\"bob\").CreatePrincipal();\n\n        _mockPipeline.ConsentResponse = new ConsentResponse()\n        {\n            ScopesValuesConsented = new string[] { \"openid\", \"api1\", \"profile\" }\n        };\n\n        _mockPipeline.BrowserClient.StopRedirectingAfter = 4;\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client2\",\n            responseType: \"id_token token\",\n            scope: \"openid profile api1 api2\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"https://client2/callback\");\n\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IsError.Should().BeFalse();\n        authorization.IdentityToken.Should().NotBeNull();\n        authorization.State.Should().Be(\"123_state\");\n        var scopes = authorization.Scope.Split(' ');\n        scopes.Should().BeEquivalentTo(new string[] { \"profile\", \"api1\", \"openid\" });\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task idp_should_be_passed_to_login_page()\n    {\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client3\",\n            responseType: \"id_token\",\n            scope: \"openid profile\",\n            redirectUri: \"https://client3/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            acrValues: \"idp:google\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginWasCalled.Should().BeTrue();\n        _mockPipeline.LoginRequest.IdP.Should().Be(\"google\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task idp_not_allowed_by_client_should_not_be_passed_to_login_page()\n    {\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client3\",\n            responseType: \"id_token\",\n            scope: \"openid profile\",\n            redirectUri: \"https://client3/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            acrValues: \"idp:facebook\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginWasCalled.Should().BeTrue();\n        _mockPipeline.LoginRequest.IdP.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task user_idp_not_allowed_by_client_should_cause_login_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client3\",\n            responseType: \"id_token\",\n            scope: \"openid profile\",\n            redirectUri: \"https://client3/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginWasCalled.Should().BeTrue();\n        _mockPipeline.LoginRequest.IdP.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task for_invalid_client_error_page_should_not_receive_client_id()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: null,\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://invalid\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.ClientId.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task error_page_should_receive_client_id()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://invalid\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.ClientId.Should().Be(\"client1\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_redirect_uri_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://invalid\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"redirect_uri\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_redirect_uri_should_not_pass_return_url_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://invalid\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.RedirectUri.Should().BeNull();\n        _mockPipeline.ErrorMessage.ResponseMode.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_client_id_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1_invalid\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_client_id_should_not_pass_return_url_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1_invalid\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.RedirectUri.Should().BeNull();\n        _mockPipeline.ErrorMessage.ResponseMode.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task missing_redirect_uri_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1_invalid\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            //redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"client\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task missing_redirect_uri_should_not_pass_return_url_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1_invalid\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            //redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.RedirectUri.Should().BeNull();\n        _mockPipeline.ErrorMessage.ResponseMode.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task malformed_redirect_uri_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1_invalid\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"invalid-uri\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"client\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task disabled_client_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        _client1.Enabled = false;\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task disabled_client_should_not_pass_return_url_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        _client1.Enabled = false;\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.RedirectUri.Should().BeNull();\n        _mockPipeline.ErrorMessage.ResponseMode.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_protocol_for_client_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        _client1.ProtocolType = \"invalid\";\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"protocol\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_protocol_for_client_should_not_pass_return_url_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        _client1.ProtocolType = \"invalid\";\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.RedirectUri.Should().BeNull();\n        _mockPipeline.ErrorMessage.ResponseMode.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_response_type_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"invalid\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.UnsupportedResponseType);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_response_type_should_not_pass_return_url_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"invalid\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.RedirectUri.Should().BeNull();\n        _mockPipeline.ErrorMessage.ResponseMode.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_response_mode_for_flow_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            responseMode: \"query\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"response_mode\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_response_mode_for_flow_should_pass_return_url_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            responseMode: \"query\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_response_mode_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            responseMode: \"invalid\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.UnsupportedResponseType);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"response_mode\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_response_mode_should_pass_return_url_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            responseMode: \"invalid\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task missing_scope_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            //scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"scope\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task missing_scope_should_pass_return_url_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            //scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task explicit_response_mode_should_be_passed_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            responseMode: \"form_post\",\n            //scope: \"openid\", // this will cause the error\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"form_post\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task scope_too_long_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: new string('x', 500),\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"scope\");\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task missing_openid_scope_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"profile\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"scope\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"openid\");\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task client_not_allowed_access_to_scope_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid email\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidScope);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"scope\");\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task missing_nonce_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\"\n        //nonce: \"123_nonce\"\n        );\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"nonce\");\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task nonce_too_long_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: new string('x', 500));\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"nonce\");\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task locale_too_long_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            extra: new { ui_locales = new string('x', 500) });\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"ui_locales\");\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task invalid_max_age_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            extra: new { max_age = \"invalid\" });\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"max_age\");\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task negative_max_age_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            extra: new { max_age = \"-10\" });\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"max_age\");\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task login_hint_too_long_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            loginHint: new string('x', 500));\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"login_hint\");\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task acr_values_too_long_should_show_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            acrValues: new string('x', 500));\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Contain(\"acr_values\");\n        _mockPipeline.ErrorMessage.RedirectUri.Should().StartWith(\"https://client1/callback\");\n        _mockPipeline.ErrorMessage.ResponseMode.Should().Be(\"fragment\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task overlapping_identity_scopes_and_api_scopes_should_show_error_page()\n    {\n        _mockPipeline.IdentityScopes.Add(new IdentityResource(\"foo\", \"Foo\", new string[] { \"name\" }));\n        _mockPipeline.IdentityScopes.Add(new IdentityResource(\"bar\", \"Bar\", new string[] { \"name\" }));\n        _mockPipeline.ApiScopes.Add(new ApiScope(\"foo\", \"Foo\"));\n        _mockPipeline.ApiScopes.Add(new ApiScope(\"bar\", \"Bar\"));\n\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid foo bar\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n\n        Func<Task> a = async () => await _mockPipeline.BrowserClient.GetAsync(url);\n        await a.Should().ThrowAsync<Exception>();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task ui_locales_should_be_passed_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            acrValues: new string('x', 500),\n            extra: new { ui_locales = \"fr-FR\" });\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.UiLocales.Should().Be(\"fr-FR\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task display_mode_should_be_passed_to_error_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            acrValues: new string('x', 500),\n            extra: new { display = \"popup\" });\n        await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.ErrorMessage.DisplayMode.Should().Be(\"popup\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task unicode_values_in_url_should_be_processed_correctly()\n    {\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        url = url.Replace(IdentityServerPipeline.BaseUrl, \"https://грант.рф\");\n\n        var result = await _mockPipeline.BackChannelClient.GetAsync(url);\n        result.Headers.Location.Authority.Should().Be(\"xn--80af5akm.xn--p1ai\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task code_flow_with_fragment_response_type_should_be_allowed()\n    {\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client4\",\n            responseType: \"code\",\n            responseMode: \"fragment\",\n            scope: \"openid\",\n            redirectUri: \"https://client4/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        _mockPipeline.LoginWasCalled.Should().BeTrue();\n    }\n\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task prompt_login_should_show_login_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client3\",\n            responseType: \"id_token\",\n            scope: \"openid profile\",\n            redirectUri: \"https://client3/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            extra: new { prompt = \"login\" }\n        );\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginWasCalled.Should().BeTrue();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Authorize/ConsentTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Net;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Stores.Default;\nusing IdentityServer8.Test;\nusing Microsoft.Extensions.DependencyInjection;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Authorize;\n\npublic class ConsentTests\n{\n    private const string Category = \"Authorize and consent tests\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    public ConsentTests()\n    {\n        _mockPipeline.Clients.AddRange(new Client[] {\n            new Client\n            {\n                ClientId = \"client1\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = false,\n                AllowedScopes = new List<string> { \"openid\", \"profile\" },\n                RedirectUris = new List<string> { \"https://client1/callback\" },\n                AllowAccessTokensViaBrowser = true\n            },\n            new Client\n            {\n                ClientId = \"client2\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = true,\n                AllowedScopes = new List<string> { \"openid\", \"profile\", \"api1\", \"api2\" },\n                RedirectUris = new List<string> { \"https://client2/callback\" },\n                AllowAccessTokensViaBrowser = true\n            },\n            new Client\n            {\n                ClientId = \"client3\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = false,\n                AllowedScopes = new List<string> { \"openid\", \"profile\", \"api1\", \"api2\" },\n                RedirectUris = new List<string> { \"https://client3/callback\" },\n                AllowAccessTokensViaBrowser = true,\n                IdentityProviderRestrictions = new List<string> { \"google\" }\n            }\n        });\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n            {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n            }\n        });\n\n        _mockPipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n            new IdentityResources.Email()\n        });\n        _mockPipeline.ApiResources.AddRange(new ApiResource[] {\n            new ApiResource\n            {\n                Name = \"api\",\n                Scopes = { \"api1\", \"api2\" }\n            }\n        });\n\n        _mockPipeline.ApiScopes.AddRange(new ApiScope[]\n        {\n            new ApiScope\n            {\n                Name = \"api1\"\n            },\n            new ApiScope\n            {\n                Name = \"api2\"\n            }\n        });\n\n        _mockPipeline.Initialize();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task client_requires_consent_should_show_consent_page()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client2\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\"\n        );\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ConsentWasCalled.Should().BeTrue();\n    }\n\n    [Theory]\n    [InlineData((Type)null)]\n    [InlineData(typeof(QueryStringAuthorizationParametersMessageStore))]\n    [InlineData(typeof(DistributedCacheAuthorizationParametersMessageStore))]\n    [Trait(\"Category\", Category)]\n    public async Task consent_page_should_have_authorization_params(Type storeType)\n    {\n        if (storeType != null)\n        {\n            _mockPipeline.OnPostConfigureServices += services =>\n            {\n                services.AddTransient(typeof(IAuthorizationParametersMessageStore), storeType);\n            };\n            _mockPipeline.Initialize();\n        }\n\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client2\",\n            responseType: \"id_token token\",\n            scope: \"openid api1 api2\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\",\n            acrValues: \"acr_1 acr_2 tenant:tenant_value\",\n            extra: new\n            {\n                display = \"popup\", // must use a valid value form the spec for display\n                ui_locales = \"ui_locale_value\",\n                custom_foo = \"foo_value\"\n            }\n        );\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ConsentRequest.Should().NotBeNull();\n        _mockPipeline.ConsentRequest.Client.ClientId.Should().Be(\"client2\");\n        _mockPipeline.ConsentRequest.DisplayMode.Should().Be(\"popup\");\n        _mockPipeline.ConsentRequest.UiLocales.Should().Be(\"ui_locale_value\");\n        _mockPipeline.ConsentRequest.Tenant.Should().Be(\"tenant_value\");\n        _mockPipeline.ConsentRequest.AcrValues.Should().BeEquivalentTo(new string[] { \"acr_2\", \"acr_1\" });\n        _mockPipeline.ConsentRequest.Parameters.AllKeys.Should().Contain(\"custom_foo\");\n        _mockPipeline.ConsentRequest.Parameters[\"custom_foo\"].Should().Be(\"foo_value\");\n        _mockPipeline.ConsentRequest.ValidatedResources.RawScopeValues.Should().BeEquivalentTo(new string[] { \"api2\", \"openid\", \"api1\" });\n    }\n\n    [Theory]\n    [InlineData((Type)null)]\n    [InlineData(typeof(QueryStringAuthorizationParametersMessageStore))]\n    [InlineData(typeof(DistributedCacheAuthorizationParametersMessageStore))]\n    [Trait(\"Category\", Category)]\n    public async Task consent_response_should_allow_successful_authorization_response(Type storeType)\n    {\n        if (storeType != null)\n        {\n            _mockPipeline.OnPostConfigureServices += services =>\n            {\n                services.AddTransient(typeof(IAuthorizationParametersMessageStore), storeType);\n            };\n            _mockPipeline.Initialize();\n        }\n\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        _mockPipeline.ConsentResponse = new ConsentResponse()\n        {\n            ScopesValuesConsented = new string[] { \"openid\", \"api2\" }\n        };\n        _mockPipeline.BrowserClient.StopRedirectingAfter = 2;\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client2\",\n            responseType: \"id_token token\",\n            scope: \"openid profile api1 api2\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"https://client2/callback\");\n\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IsError.Should().BeFalse();\n        authorization.IdentityToken.Should().NotBeNull();\n        authorization.State.Should().Be(\"123_state\");\n        var scopes = authorization.Scope.Split(' ');\n        scopes.Should().BeEquivalentTo(new string[] { \"api2\", \"openid\" });\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task consent_response_should_reject_modified_request_params()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        _mockPipeline.ConsentResponse = new ConsentResponse()\n        {\n            ScopesValuesConsented = new string[] { \"openid\", \"api2\" }\n        };\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client2\",\n            responseType: \"id_token token\",\n            scope: \"openid profile api2\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"https://server/consent\");\n\n        response = await _mockPipeline.BrowserClient.GetAsync(response.Headers.Location.ToString());\n\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"/connect/authorize/callback\");\n\n        var modifiedAuthorizeCallback = \"https://server\" + response.Headers.Location.ToString();\n        modifiedAuthorizeCallback = modifiedAuthorizeCallback.Replace(\"api2\", \"api1%20api2\");\n\n        response = await _mockPipeline.BrowserClient.GetAsync(modifiedAuthorizeCallback);\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"https://server/consent\");\n    }\n\n    [Fact()]\n    [Trait(\"Category\", Category)]\n    public async Task consent_response_missing_required_scopes_should_error()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        _mockPipeline.ConsentResponse = new ConsentResponse()\n        {\n            ScopesValuesConsented = new string[] { \"api2\" }\n        };\n        _mockPipeline.BrowserClient.StopRedirectingAfter = 2;\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client2\",\n            responseType: \"id_token token\",\n            scope: \"openid profile api1 api2\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"https://client2/callback\");\n\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IsError.Should().BeTrue();\n        authorization.Error.Should().Be(\"access_denied\");\n        authorization.State.Should().Be(\"123_state\");\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Authorize/JwtRequestAuthorizeTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.IdentityModel.Tokens.Jwt;\nusing System.Net.Http;\nusing System.Net.Http.Headers;\nusing System.Security.Claims;\nusing System.Security.Cryptography.X509Certificates;\nusing System.Text.Json;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Microsoft.IdentityModel.Logging;\nusing Microsoft.IdentityModel.Tokens;\nusing Xunit;\nusing JsonWebKey = Microsoft.IdentityModel.Tokens.JsonWebKey;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Authorize;\n\npublic class JwtRequestAuthorizeTests\n{\n    private const string Category = \"Authorize endpoint with JWT requests\";\n\n    private readonly IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n    private readonly Client _client;\n\n    private readonly string _symmetricJwk = @\"{ \"\"kty\"\": \"\"oct\"\", \"\"use\"\": \"\"sig\"\", \"\"kid\"\": \"\"1\"\", \"\"k\"\": \"\"nYA-IFt8xTsdBHe9hunvizcp3Dt7f6qGqudq18kZHNtvqEGjJ9Ud-9x3kbQ-LYfLHS3xM2MpFQFg1JzT_0U_F8DI40oby4TvBDGszP664UgA8_5GjB7Flnrlsap1NlitvNpgQX3lpyTvC2zVuQ-UVsXbBDAaSBUSlnw7SE4LM8Ye2WYZrdCCXL8yAX9vIR7vf77yvNTEcBCI6y4JlvZaqMB4YKVSfygs8XqGGCHjLpE5bvI-A4ESbAUX26cVFvCeDg9pR6HK7BmwPMlO96krgtKZcXEJtUELYPys6-rbwAIdmxJxKxpgRpt0FRv_9fm6YPwG7QivYBX-vRwaodL1TA\"\", \"\"alg\"\": \"\"HS256\"\"}\";\n    private readonly RsaSecurityKey _rsaKey;\n\n    public JwtRequestAuthorizeTests()\n    {\n        IdentityModelEventSource.ShowPII = true;\n\n        _rsaKey = CryptoHelper.CreateRsaSecurityKey();\n\n        _mockPipeline.Clients.AddRange(new Client[]\n        {\n            _client = new Client\n            {\n                ClientName = \"Client with keys\",\n                ClientId = \"client\",\n                Enabled = true,\n                RequireRequestObject = true,\n\n                RedirectUris = { \"https://client/callback\" },\n\n                ClientSecrets =\n                {\n                    new Secret\n                    {\n                        // x509 cert as base64 string\n                        Type = IdentityServerConstants.SecretTypes.X509CertificateBase64,\n                        Value = Convert.ToBase64String(TestCert.Load().Export(X509ContentType.Cert))\n                    },\n                    new Secret\n                    {\n                        // symmetric key as JWK\n                        Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                        Value = _symmetricJwk\n                    },\n                    new Secret\n                    {\n                        // RSA key as JWK\n                        Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                        Value = JsonSerializer.Serialize(JsonWebKeyConverter.ConvertFromRSASecurityKey(_rsaKey))\n                    },\n                    new Secret\n                    {\n                        // x509 cert as JWK\n                        Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                        Value = JsonSerializer.Serialize(JsonWebKeyConverter.ConvertFromX509SecurityKey(new X509SecurityKey(TestCert.Load())))\n                    }\n                },\n\n                AllowedGrantTypes = GrantTypes.Implicit,\n\n                AllowedScopes = new List<string>\n                {\n                    \"openid\", \"profile\", \"api1\", \"api2\"\n                }\n            },\n            _client = new Client\n            {\n                ClientName = \"Client with keys\",\n                ClientId = \"client2\",\n                Enabled = true,\n                RequireRequestObject = true,\n\n                RedirectUris = { \"https://client/callback\" },\n\n                ClientSecrets =\n                {\n                    new Secret\n                    {\n                        // x509 cert as base64 string\n                        Type = IdentityServerConstants.SecretTypes.X509CertificateBase64,\n                        Value = Convert.ToBase64String(TestCert.Load().Export(X509ContentType.Cert))\n                    },\n                    new Secret\n                    {\n                        // symmetric key as JWK\n                        Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                        Value = _symmetricJwk\n                    },\n                    new Secret\n                    {\n                        // RSA key as JWK\n                        Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                        Value = JsonSerializer.Serialize(JsonWebKeyConverter.ConvertFromRSASecurityKey(_rsaKey))\n                    },\n                    new Secret\n                    {\n                        // x509 cert as JWK\n                        Type = IdentityServerConstants.SecretTypes.JsonWebKey,\n                        Value = JsonSerializer.Serialize(JsonWebKeyConverter.ConvertFromX509SecurityKey(new X509SecurityKey(TestCert.Load())))\n                    }\n                },\n\n                AllowedGrantTypes = GrantTypes.Implicit,\n\n                AllowedScopes = new List<string>\n                {\n                    \"openid\", \"profile\", \"api1\", \"api2\"\n                }\n            },\n        });\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n            {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n            }\n        });\n\n        _mockPipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n            new IdentityResources.Email()\n        });\n        _mockPipeline.ApiResources.AddRange(new ApiResource[] {\n            new ApiResource\n            {\n                Name = \"api\",\n                Scopes = { \"api1\", \"api2\" }\n            }\n        });\n        _mockPipeline.ApiScopes.AddRange(new ApiScope[] {\n            new ApiScope\n            {\n                Name = \"api1\"\n            },\n            new ApiScope\n            {\n                Name = \"api2\"\n            }\n        });\n\n        _mockPipeline.Initialize();\n    }\n\n    string CreateRequestJwt(string issuer, string audience, SigningCredentials credential, Claim[] claims, bool setJwtTyp = false)\n    {\n        var handler = new JwtSecurityTokenHandler();\n        handler.OutboundClaimTypeMap.Clear();\n\n        var token = handler.CreateJwtSecurityToken(\n            issuer: issuer,\n            audience: audience,\n            signingCredentials: credential,\n            subject: Identity.Create(\"pwd\", claims));\n\n        if (setJwtTyp)\n        {\n            token.Header[\"typ\"] = JwtClaimTypes.JwtTypes.AuthorizationRequest;\n        }\n\n        return handler.WriteToken(token);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task missing_request_object_should_fail()\n    {\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            scope: \"openid profile\",\n            state: \"123state\",\n            nonce: \"123nonce\",\n            redirectUri: \"https://client/callback\");\n\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Be(\"Client must use request object, but no request or request_uri parameter present\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_accept_valid_JWT_request_object_parameters_using_X509_certificate()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginRequest.Should().NotBeNull();\n        _mockPipeline.LoginRequest.Client.ClientId.Should().Be(_client.ClientId);\n        _mockPipeline.LoginRequest.DisplayMode.Should().Be(\"popup\");\n        _mockPipeline.LoginRequest.UiLocales.Should().Be(\"ui_locale_value\");\n        _mockPipeline.LoginRequest.IdP.Should().Be(\"idp_value\");\n        _mockPipeline.LoginRequest.Tenant.Should().Be(\"tenant_value\");\n        _mockPipeline.LoginRequest.LoginHint.Should().Be(\"login_hint_value\");\n        _mockPipeline.LoginRequest.AcrValues.Should().BeEquivalentTo(new string[] { \"acr_2\", \"acr_1\" });\n\n        _mockPipeline.LoginRequest.Parameters.AllKeys.Should().Contain(\"foo\");\n        _mockPipeline.LoginRequest.Parameters[\"foo\"].Should().Be(\"123foo\");\n\n        _mockPipeline.LoginRequest.RequestObjectValues.Count.Should().Be(11);\n        _mockPipeline.LoginRequest.RequestObjectValues.Should().ContainKey(\"foo\");\n        _mockPipeline.LoginRequest.RequestObjectValues[\"foo\"].Should().Be(\"123foo\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_accept_valid_JWT_request_object_parameters_using_symmetric_jwk()\n    {\n        var jwk = new Microsoft.IdentityModel.Tokens.JsonWebKey(_symmetricJwk);\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new SigningCredentials(jwk, \"HS256\"),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginRequest.Should().NotBeNull();\n        _mockPipeline.LoginRequest.Client.ClientId.Should().Be(_client.ClientId);\n        _mockPipeline.LoginRequest.DisplayMode.Should().Be(\"popup\");\n        _mockPipeline.LoginRequest.UiLocales.Should().Be(\"ui_locale_value\");\n        _mockPipeline.LoginRequest.IdP.Should().Be(\"idp_value\");\n        _mockPipeline.LoginRequest.Tenant.Should().Be(\"tenant_value\");\n        _mockPipeline.LoginRequest.LoginHint.Should().Be(\"login_hint_value\");\n        _mockPipeline.LoginRequest.AcrValues.Should().BeEquivalentTo(new string[] { \"acr_2\", \"acr_1\" });\n\n        _mockPipeline.LoginRequest.Parameters.AllKeys.Should().Contain(\"foo\");\n        _mockPipeline.LoginRequest.Parameters[\"foo\"].Should().Be(\"123foo\");\n\n        _mockPipeline.LoginRequest.RequestObjectValues.Count.Should().Be(11);\n        _mockPipeline.LoginRequest.RequestObjectValues.Should().ContainKey(\"foo\");\n        _mockPipeline.LoginRequest.RequestObjectValues[\"foo\"].Should().Be(\"123foo\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_accept_valid_JWT_request_object_parameters_using_rsa_jwk()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new SigningCredentials(_rsaKey, \"RS256\"),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginRequest.Should().NotBeNull();\n        _mockPipeline.LoginRequest.Client.ClientId.Should().Be(_client.ClientId);\n        _mockPipeline.LoginRequest.DisplayMode.Should().Be(\"popup\");\n        _mockPipeline.LoginRequest.UiLocales.Should().Be(\"ui_locale_value\");\n        _mockPipeline.LoginRequest.IdP.Should().Be(\"idp_value\");\n        _mockPipeline.LoginRequest.Tenant.Should().Be(\"tenant_value\");\n        _mockPipeline.LoginRequest.LoginHint.Should().Be(\"login_hint_value\");\n        _mockPipeline.LoginRequest.AcrValues.Should().BeEquivalentTo(new string[] { \"acr_2\", \"acr_1\" });\n\n        _mockPipeline.LoginRequest.Parameters.AllKeys.Should().Contain(\"foo\");\n        _mockPipeline.LoginRequest.Parameters[\"foo\"].Should().Be(\"123foo\");\n\n        _mockPipeline.LoginRequest.RequestObjectValues.Count.Should().Be(11);\n        _mockPipeline.LoginRequest.RequestObjectValues.Should().ContainKey(\"foo\");\n        _mockPipeline.LoginRequest.RequestObjectValues[\"foo\"].Should().Be(\"123foo\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task correct_jwt_typ_should_pass_strict_validation()\n    {\n        _mockPipeline.Options.StrictJarValidation = true;\n\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new SigningCredentials(_rsaKey, \"RS256\"),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        }, setJwtTyp: true);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginRequest.Should().NotBeNull();\n        _mockPipeline.LoginRequest.Client.ClientId.Should().Be(_client.ClientId);\n        _mockPipeline.LoginRequest.DisplayMode.Should().Be(\"popup\");\n        _mockPipeline.LoginRequest.UiLocales.Should().Be(\"ui_locale_value\");\n        _mockPipeline.LoginRequest.IdP.Should().Be(\"idp_value\");\n        _mockPipeline.LoginRequest.Tenant.Should().Be(\"tenant_value\");\n        _mockPipeline.LoginRequest.LoginHint.Should().Be(\"login_hint_value\");\n        _mockPipeline.LoginRequest.AcrValues.Should().BeEquivalentTo(new string[] { \"acr_2\", \"acr_1\" });\n\n        _mockPipeline.LoginRequest.Parameters.AllKeys.Should().Contain(\"foo\");\n        _mockPipeline.LoginRequest.Parameters[\"foo\"].Should().Be(\"123foo\");\n\n        _mockPipeline.LoginRequest.RequestObjectValues.Count.Should().Be(11);\n        _mockPipeline.LoginRequest.RequestObjectValues.Should().ContainKey(\"foo\");\n        _mockPipeline.LoginRequest.RequestObjectValues[\"foo\"].Should().Be(\"123foo\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task missing_jwt_typ_should_error()\n    {\n        _mockPipeline.Options.StrictJarValidation = true;\n\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new SigningCredentials(_rsaKey, \"RS256\"),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request_object\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task mismatch_in_jwt_values_should_error()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new SigningCredentials(_rsaKey, \"RS256\"),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            scope: \"bad\",\n            state: \"bad\",\n            nonce: \"bad\",\n            redirectUri: \"bad\",\n            acrValues: \"bad\",\n            loginHint: \"bad\",\n            extra: new\n            {\n                display = \"bad\",\n                ui_locales = \"bad\",\n                foo = \"bad\",\n                request = requestJwt\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Be(\"Parameter mismatch in JWT request\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_accept_complex_objects_in_request_object()\n    {\n        var someObj = new { foo = new { bar = \"bar\" }, baz = \"baz\" };\n        var someObjJson = JsonSerializer.Serialize(someObj);\n        var someArr = new[] { \"a\", \"b\", \"c\" };\n        var someArrJson = JsonSerializer.Serialize(someArr);\n\n\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n                new Claim(\"someObj\", someObjJson),\n                new Claim(\"someArr\", someArrJson),\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginRequest.Should().NotBeNull();\n\n        _mockPipeline.LoginRequest.Parameters[\"someObj\"].Should().NotBeNull();\n        var someObj2 = JsonSerializer.Deserialize(_mockPipeline.LoginRequest.Parameters[\"someObj\"], someObj.GetType());\n        someObj.Should().BeEquivalentTo(someObj2);\n        _mockPipeline.LoginRequest.Parameters[\"someArr\"].Should().NotBeNull();\n        var someArr2 =JsonSerializer.Deserialize<string[]>(_mockPipeline.LoginRequest.Parameters[\"someArr\"]);\n        someArr2.Should().Contain(new[] { \"a\", \"c\", \"b\" });\n        someArr2.Length.Should().Be(3);\n\n        _mockPipeline.LoginRequest.RequestObjectValues.Count.Should().Be(13);\n        _mockPipeline.LoginRequest.RequestObjectValues[\"someObj\"].Should().NotBeNull();\n        someObj2 =JsonSerializer.Deserialize(_mockPipeline.LoginRequest.RequestObjectValues[\"someObj\"], someObj.GetType());\n        someObj.Should().BeEquivalentTo(someObj2);\n        _mockPipeline.LoginRequest.RequestObjectValues[\"someArr\"].Should().NotBeNull();\n        someArr2 =JsonSerializer.Deserialize<string[]>(_mockPipeline.LoginRequest.Parameters[\"someArr\"]);\n        someArr2.Should().Contain(new[] { \"a\", \"c\", \"b\" });\n        someArr2.Length.Should().Be(3);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_reject_jwt_request_without_client_id()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Be(\"Invalid client_id\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_reject_jwt_request_without_client_id_in_jwt()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n            });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request_object\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Be(\"Invalid JWT request\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_reject_jwt_request_if_audience_is_incorrect()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: \"invalid\",\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request_object\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Be(\"Invalid JWT request\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_reject_jwt_request_if_issuer_does_not_match_client_id()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: \"invalid\",\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request_object\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Be(\"Invalid JWT request\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_reject_jwt_request_that_includes_request_param()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n                new Claim(\"request\", \"request\")\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request_object\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Be(\"Invalid JWT request\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_reject_jwt_request_that_includes_request_uri_param()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n                new Claim(\"request_uri\", \"request_uri\")\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request_object\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Be(\"Invalid JWT request\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_reject_jwt_request_if_response_type_does_not_match()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"response_type\", \"id_token token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\")\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Be(\"Invalid JWT request\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_reject_jwt_request_if_client_id_does_not_match()\n    {\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"client_id\", \"client\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\")\n        });\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client2\",\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt\n            });\n\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request\");\n        _mockPipeline.ErrorMessage.ErrorDescription.Should().Be(\"Invalid JWT request\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_ignore_request_uri_when_feature_is_disabled()\n    {\n        _mockPipeline.Options.Endpoints.EnableJwtRequestUri = false;\n\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n        _mockPipeline.JwtRequestMessageHandler.OnInvoke = req =>\n        {\n            req.RequestUri.Should().Be(new Uri(\"http://client_jwt\"));\n            return Task.CompletedTask;\n        };\n        _mockPipeline.JwtRequestMessageHandler.Response.Content = new StringContent(requestJwt);\n\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request_uri = \"http://client_jwt\"\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n\n        _mockPipeline.JwtRequestMessageHandler.InvokeWasCalled.Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_accept_request_uri_with_valid_jwt()\n    {\n        _mockPipeline.Options.Endpoints.EnableJwtRequestUri = true;\n\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n        _mockPipeline.JwtRequestMessageHandler.OnInvoke = req =>\n        {\n            req.RequestUri.Should().Be(new Uri(\"http://client_jwt\"));\n            return Task.CompletedTask;\n        };\n        _mockPipeline.JwtRequestMessageHandler.Response.Content = new StringContent(requestJwt);\n\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request_uri = \"http://client_jwt\"\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginRequest.Should().NotBeNull();\n        _mockPipeline.LoginRequest.Client.ClientId.Should().Be(_client.ClientId);\n        _mockPipeline.LoginRequest.DisplayMode.Should().Be(\"popup\");\n        _mockPipeline.LoginRequest.UiLocales.Should().Be(\"ui_locale_value\");\n        _mockPipeline.LoginRequest.IdP.Should().Be(\"idp_value\");\n        _mockPipeline.LoginRequest.Tenant.Should().Be(\"tenant_value\");\n        _mockPipeline.LoginRequest.LoginHint.Should().Be(\"login_hint_value\");\n        _mockPipeline.LoginRequest.AcrValues.Should().BeEquivalentTo(new string[] { \"acr_2\", \"acr_1\" });\n        _mockPipeline.LoginRequest.Parameters.AllKeys.Should().Contain(\"foo\");\n        _mockPipeline.LoginRequest.Parameters[\"foo\"].Should().Be(\"123foo\");\n\n        _mockPipeline.JwtRequestMessageHandler.InvokeWasCalled.Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_accept_request_uri_with_valid_jwt_and_strict_validation()\n    {\n        _mockPipeline.Options.Endpoints.EnableJwtRequestUri = true;\n        _mockPipeline.Options.StrictJarValidation = true;\n\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        }, setJwtTyp: true);\n        _mockPipeline.JwtRequestMessageHandler.OnInvoke = req =>\n        {\n            req.RequestUri.Should().Be(new Uri(\"http://client_jwt\"));\n            return Task.CompletedTask;\n        };\n        _mockPipeline.JwtRequestMessageHandler.Response.Content = new StringContent(requestJwt);\n        _mockPipeline.JwtRequestMessageHandler.Response.Content.Headers.ContentType = new MediaTypeHeaderValue($\"application/{JwtClaimTypes.JwtTypes.AuthorizationRequest}\");\n\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request_uri = \"http://client_jwt\"\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginRequest.Should().NotBeNull();\n        _mockPipeline.LoginRequest.Client.ClientId.Should().Be(_client.ClientId);\n        _mockPipeline.LoginRequest.DisplayMode.Should().Be(\"popup\");\n        _mockPipeline.LoginRequest.UiLocales.Should().Be(\"ui_locale_value\");\n        _mockPipeline.LoginRequest.IdP.Should().Be(\"idp_value\");\n        _mockPipeline.LoginRequest.Tenant.Should().Be(\"tenant_value\");\n        _mockPipeline.LoginRequest.LoginHint.Should().Be(\"login_hint_value\");\n        _mockPipeline.LoginRequest.AcrValues.Should().BeEquivalentTo(new string[] { \"acr_2\", \"acr_1\" });\n        _mockPipeline.LoginRequest.Parameters.AllKeys.Should().Contain(\"foo\");\n        _mockPipeline.LoginRequest.Parameters[\"foo\"].Should().Be(\"123foo\");\n\n        _mockPipeline.JwtRequestMessageHandler.InvokeWasCalled.Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task authorize_should_reject_request_uri_with_valid_jwt_and_strict_validation_but_invalid_content_type()\n    {\n        _mockPipeline.Options.Endpoints.EnableJwtRequestUri = true;\n        _mockPipeline.Options.StrictJarValidation = true;\n\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        }, setJwtTyp: true);\n        _mockPipeline.JwtRequestMessageHandler.OnInvoke = req =>\n        {\n            req.RequestUri.Should().Be(new Uri(\"http://client_jwt\"));\n            return Task.CompletedTask;\n        };\n        _mockPipeline.JwtRequestMessageHandler.Response.Content = new StringContent(requestJwt);\n\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request_uri = \"http://client_jwt\"\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorMessage.Error.Should().Be(\"invalid_request_uri\");\n        _mockPipeline.LoginRequest.Should().BeNull();\n        _mockPipeline.JwtRequestMessageHandler.InvokeWasCalled.Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task request_uri_response_returns_500_should_fail()\n    {\n        _mockPipeline.Options.Endpoints.EnableJwtRequestUri = true;\n\n        _mockPipeline.JwtRequestMessageHandler.Response = new HttpResponseMessage(System.Net.HttpStatusCode.InternalServerError);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request_uri = \"http://client_jwt\"\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.LoginRequest.Should().BeNull();\n\n        _mockPipeline.JwtRequestMessageHandler.InvokeWasCalled.Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task request_uri_response_returns_404_should_fail()\n    {\n        _mockPipeline.Options.Endpoints.EnableJwtRequestUri = true;\n\n        _mockPipeline.JwtRequestMessageHandler.Response = new HttpResponseMessage(System.Net.HttpStatusCode.NotFound);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request_uri = \"http://client_jwt\"\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.LoginRequest.Should().BeNull();\n\n        _mockPipeline.JwtRequestMessageHandler.InvokeWasCalled.Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task request_uri_length_too_long_should_fail()\n    {\n        _mockPipeline.Options.Endpoints.EnableJwtRequestUri = true;\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request_uri = \"http://\" + new string('x', 512)\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.LoginRequest.Should().BeNull();\n\n        _mockPipeline.JwtRequestMessageHandler.InvokeWasCalled.Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task both_request_and_request_uri_params_should_fail()\n    {\n        _mockPipeline.Options.Endpoints.EnableJwtRequestUri = true;\n\n        var requestJwt = CreateRequestJwt(\n            issuer: _client.ClientId,\n            audience: IdentityServerPipeline.BaseUrl,\n            credential: new X509SigningCredentials(TestCert.Load()),\n            claims: new[] {\n                new Claim(\"client_id\", _client.ClientId),\n                new Claim(\"response_type\", \"id_token\"),\n                new Claim(\"scope\", \"openid profile\"),\n                new Claim(\"state\", \"123state\"),\n                new Claim(\"nonce\", \"123nonce\"),\n                new Claim(\"redirect_uri\", \"https://client/callback\"),\n                new Claim(\"acr_values\", \"acr_1 acr_2 tenant:tenant_value idp:idp_value\"),\n                new Claim(\"login_hint\", \"login_hint_value\"),\n                new Claim(\"display\", \"popup\"),\n                new Claim(\"ui_locales\", \"ui_locale_value\"),\n                new Claim(\"foo\", \"123foo\"),\n        });\n        _mockPipeline.JwtRequestMessageHandler.Response.Content = new StringContent(requestJwt);\n\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: _client.ClientId,\n            responseType: \"id_token\",\n            extra: new\n            {\n                request = requestJwt,\n                request_uri = \"http://client_jwt\"\n            });\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n        _mockPipeline.LoginRequest.Should().BeNull();\n\n        _mockPipeline.JwtRequestMessageHandler.InvokeWasCalled.Should().BeFalse();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Authorize/RestrictAccessTokenViaBrowserTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Net;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Authorize;\n\npublic class RestrictAccessTokenViaBrowserTests\n{\n    private const string Category = \"RestrictAccessTokenViaBrowserTests\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    private ClaimsPrincipal _user = new IdentityServerUser(\"bob\").CreatePrincipal();\n\n    public RestrictAccessTokenViaBrowserTests()\n    {\n        _mockPipeline.Clients.AddRange(new Client[] {\n            new Client\n            {\n                ClientId = \"client1\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = false,\n                AllowedScopes = new List<string> { \"openid\" },\n                RedirectUris = new List<string> { \"https://client1/callback\" },\n                AllowAccessTokensViaBrowser = true\n            },\n            new Client\n            {\n                ClientId = \"client2\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = false,\n                AllowedScopes = new List<string> { \"openid\" },\n                RedirectUris = new List<string> { \"https://client2/callback\" },\n                AllowAccessTokensViaBrowser = false\n            },\n            new Client\n            {\n                ClientId = \"client3\",\n                AllowedGrantTypes = GrantTypes.Hybrid,\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n                RequireConsent = false,\n                RequirePkce = false,\n                AllowedScopes = new List<string> { \"openid\" },\n                RedirectUris = new List<string> { \"https://client3/callback\" },\n                AllowAccessTokensViaBrowser = true\n            },\n            new Client\n            {\n                ClientId = \"client4\",\n                AllowedGrantTypes = GrantTypes.Hybrid,\n                ClientSecrets = { new Secret(\"secret\".Sha256()) },\n                RequireConsent = false,\n                RequirePkce = false,\n                AllowedScopes = new List<string> { \"openid\" },\n                RedirectUris = new List<string> { \"https://client4/callback\" },\n                AllowAccessTokensViaBrowser = false\n            }\n        });\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n            {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n            }\n        });\n\n        _mockPipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId()\n        });\n\n        _mockPipeline.Initialize();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Unrestricted_implicit_client_can_request_IdToken()\n    {\n        await _mockPipeline.LoginAsync(_user);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\"client1\",\n            \"id_token\", \"openid\", \"https://client1/callback\", \"state\", \"nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Found);\n        response.Headers.Location.AbsoluteUri.Should().StartWith(\"https://client1/callback\");\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IdentityToken.Should().NotBeNull();\n        authorization.AccessToken.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Unrestricted_implicit_client_can_request_IdTokenToken()\n    {\n        await _mockPipeline.LoginAsync(_user);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\"client1\",\n            \"id_token token\", \"openid\", \"https://client1/callback\", \"state\", \"nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Found);\n        response.Headers.Location.AbsoluteUri.Should().StartWith(\"https://client1/callback\");\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IdentityToken.Should().NotBeNull();\n        authorization.AccessToken.Should().NotBeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Restricted_implicit_client_can_request_IdToken()\n    {\n        await _mockPipeline.LoginAsync(_user);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\"client2\",\n            \"id_token\", \"openid\", \"https://client2/callback\", \"state\", \"nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Found);\n        response.Headers.Location.AbsoluteUri.Should().StartWith(\"https://client2/callback\");\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IdentityToken.Should().NotBeNull();\n        authorization.AccessToken.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Restricted_implicit_client_cannot_request_IdTokenToken()\n    {\n        await _mockPipeline.LoginAsync(_user);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\"client2\",\n            \"id_token token\", \"openid\", \"https://client2/callback\", \"state\", \"nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Unrestricted_hybrid_client_can_request_CodeIdToken()\n    {\n        await _mockPipeline.LoginAsync(_user);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\"client3\",\n            \"code id_token\", \"openid\", \"https://client3/callback\", \"state\", \"nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Found);\n        response.Headers.Location.AbsoluteUri.Should().StartWith(\"https://client3/callback\");\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IdentityToken.Should().NotBeNull();\n        authorization.AccessToken.Should().BeNull();\n        authorization.Code.Should().NotBeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Unrestricted_hybrid_client_can_request_CodeIdTokenToken()\n    {\n        await _mockPipeline.LoginAsync(_user);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\"client3\",\n            \"code id_token token\", \"openid\", \"https://client3/callback\", \"state\", \"nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Found);\n        response.Headers.Location.AbsoluteUri.Should().StartWith(\"https://client3/callback\");\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IdentityToken.Should().NotBeNull();\n        authorization.AccessToken.Should().NotBeNull();\n        authorization.Code.Should().NotBeNull();\n    }\n\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Restricted_hybrid_client_can_request_CodeIdToken()\n    {\n        await _mockPipeline.LoginAsync(_user);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\"client4\",\n            \"code id_token\", \"openid\", \"https://client4/callback\", \"state\", \"nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Found);\n        response.Headers.Location.AbsoluteUri.Should().StartWith(\"https://client4/callback\");\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IdentityToken.Should().NotBeNull();\n        authorization.AccessToken.Should().BeNull();\n        authorization.Code.Should().NotBeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Restricted_hybrid_client_cannot_request_CodeIdTokenToken()\n    {\n        await _mockPipeline.LoginAsync(_user);\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\"client4\",\n            \"code id_token token\", \"openid\", \"https://client4/callback\", \"state\", \"nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        _mockPipeline.ErrorWasCalled.Should().BeTrue();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Authorize/SessionIdTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Authorize;\n\npublic class SessionIdTests\n{\n    private const string Category = \"SessionIdTests\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    public SessionIdTests()\n    {\n        _mockPipeline.Clients.AddRange(new Client[] {\n            new Client\n            {\n                ClientId = \"client1\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = false,\n                AllowedScopes = new List<string> { \"openid\", \"profile\" },\n                RedirectUris = new List<string> { \"https://client1/callback\" },\n                AllowAccessTokensViaBrowser = true\n            },\n            new Client\n            {\n                ClientId = \"client2\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = true,\n                AllowedScopes = new List<string> { \"openid\", \"profile\", \"api1\", \"api2\" },\n                RedirectUris = new List<string> { \"https://client2/callback\" },\n                AllowAccessTokensViaBrowser = true\n            }\n        });\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n            {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n            }\n        });\n\n        _mockPipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n            new IdentityResources.Email()\n        });\n        _mockPipeline.ApiResources.AddRange(new ApiResource[] {\n            new ApiResource\n            {\n                Name = \"api\",\n            }\n        });\n        _mockPipeline.ApiScopes.AddRange(new ApiScope[] {\n            new ApiScope\n            {\n                Name = \"api1\"\n            },\n            new ApiScope\n            {\n                Name = \"api2\"\n            }\n        });\n\n        _mockPipeline.Initialize();\n    }\n\n    [Fact]\n    public async Task session_id_should_be_reissued_if_session_cookie_absent()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n        var sid1 = _mockPipeline.GetSessionCookie().Value;\n        sid1.Should().NotBeNull();\n\n        _mockPipeline.RemoveSessionCookie();\n\n        await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.DiscoveryEndpoint);\n\n        var sid2 = _mockPipeline.GetSessionCookie().Value;\n        sid2.Should().Be(sid1);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/CheckSession/CheckSessionTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Net;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.IntegrationTests.Common;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.CheckSession;\n\npublic class CheckSessionTests\n{\n    private const string Category = \"Check session endpoint\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    public CheckSessionTests()\n    {\n        _mockPipeline.Initialize();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task get_request_should_not_return_404()\n    {\n        var response = await _mockPipeline.BackChannelClient.GetAsync(IdentityServerPipeline.CheckSessionEndpoint);\n\n        response.StatusCode.Should().NotBe(HttpStatusCode.NotFound);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/DeviceAuthorization/DeviceAuthorizationTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.IO;\nusing System.Net;\nusing System.Net.Http;\nusing System.Text;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing Newtonsoft.Json;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.DeviceAuthorization;\n\npublic class DeviceAuthorizationTests\n{\n    private const string Category = \"Device authorization endpoint\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    public DeviceAuthorizationTests()\n    {\n        _mockPipeline.Clients.Add(new Client\n        {\n            ClientId = \"client1\",\n            ClientSecrets = {new Secret(\"secret\".Sha256())},\n            AllowedGrantTypes = GrantTypes.DeviceFlow,\n            AllowedScopes = {\"openid\"}\n        });\n\n        _mockPipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId()\n        });\n\n        _mockPipeline.Initialize();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task get_should_return_InvalidRequest()\n    {\n        var response = await _mockPipeline.BackChannelClient.GetAsync(IdentityServerPipeline.DeviceAuthorization);\n        response.StatusCode.Should().Be(HttpStatusCode.BadRequest);\n\n        var resultDto = ParseJsonBody<ErrorResultDto>(await response.Content.ReadAsStreamAsync());\n\n        resultDto.Should().NotBeNull();\n        resultDto.error.Should().Be(OidcConstants.TokenErrors.InvalidRequest);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task wrong_content_type_return_InvalidRequest()\n    {\n        var form = new Dictionary<string, string>\n        {\n            {\"client_id\", Guid.NewGuid().ToString()}\n        };\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.DeviceAuthorization,\n            new StringContent(@\"{\"\"client_id\"\": \"\"client1\"\"}\", Encoding.UTF8, \"application/json\"));\n\n        response.StatusCode.Should().Be(HttpStatusCode.BadRequest);\n\n        var resultDto = ParseJsonBody<ErrorResultDto>(await response.Content.ReadAsStreamAsync());\n\n        resultDto.Should().NotBeNull();\n        resultDto.error.Should().Be(OidcConstants.TokenErrors.InvalidRequest);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task empty_request_should_return_InvalidClient()\n    {\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.DeviceAuthorization,\n            new FormUrlEncodedContent(new Dictionary<string, string>()));\n\n        response.StatusCode.Should().Be(HttpStatusCode.BadRequest);\n\n        var resultDto = ParseJsonBody<ErrorResultDto>(await response.Content.ReadAsStreamAsync());\n\n        resultDto.Should().NotBeNull();\n        resultDto.error.Should().Be(OidcConstants.TokenErrors.InvalidClient);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task unknown_client_should_return_InvalidClient()\n    {\n        var form = new Dictionary<string, string>\n        {\n            {\"client_id\", \"client1\"}\n        };\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.DeviceAuthorization, new FormUrlEncodedContent(form));\n\n        response.StatusCode.Should().Be(HttpStatusCode.BadRequest);\n\n        var resultDto = ParseJsonBody<ErrorResultDto>(await response.Content.ReadAsStreamAsync());\n\n        resultDto.Should().NotBeNull();\n        resultDto.error.Should().Be(OidcConstants.TokenErrors.InvalidClient);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task valid_should_return_json()\n    {\n        var form = new Dictionary<string, string>\n        {\n            {\"client_id\", \"client1\"},\n            {\"client_secret\", \"secret\" }\n        };\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.DeviceAuthorization, new FormUrlEncodedContent(form));\n\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n        response.Content.Headers.ContentType.MediaType.Should().Be(\"application/json\");\n        \n        var resultDto = ParseJsonBody<ResultDto>(await response.Content.ReadAsStreamAsync());\n\n        resultDto.Should().NotBeNull();\n\n        resultDto.Should().NotBeNull();\n        resultDto.device_code.Should().NotBeNull();\n        resultDto.user_code.Should().NotBeNull();\n        resultDto.verification_uri.Should().NotBeNull();\n        resultDto.verification_uri_complete.Should().NotBeNull();\n        resultDto.expires_in.Should().BeGreaterThan(0);\n        resultDto.interval.Should().BeGreaterThan(0);\n    }\n\n    private T ParseJsonBody<T>(Stream streamBody)\n    {\n        streamBody.Position = 0;\n        using (var reader = new StreamReader(streamBody))\n        {\n            var jsonString = reader.ReadToEnd();\n            return JsonConvert.DeserializeObject<T>(jsonString);\n        }\n    }\n\n    internal class ResultDto\n    {\n        public string device_code { get; set; }\n        public string user_code { get; set; }\n        public string verification_uri { get; set; }\n        public string verification_uri_complete { get; set; }\n        public int expires_in { get; set; }\n        public int interval { get; set; }\n    }\n\n    internal class ErrorResultDto\n    {\n        public string error { get; set; }\n        public string error_description { get; set; }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Discovery/DiscoveryEndpointTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing Microsoft.Extensions.DependencyInjection;\nusing Microsoft.IdentityModel.Tokens;\nusing Newtonsoft.Json.Linq;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing Xunit;\nusing JsonWebKey = Microsoft.IdentityModel.Tokens.JsonWebKey;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Discovery;\n\npublic class DiscoveryEndpointTests\n{\n    private const string Category = \"Discovery endpoint\";\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Issuer_uri_should_be_lowercase()\n    {\n        IdentityServerPipeline pipeline = new IdentityServerPipeline();\n        pipeline.Initialize(\"/ROOT\");\n\n        var result = await pipeline.BackChannelClient.GetAsync(\"HTTPS://SERVER/ROOT/.WELL-KNOWN/OPENID-CONFIGURATION\");\n\n        var json = await result.Content.ReadAsStringAsync();\n        var data = JObject.Parse(json);\n        var issuer = data[\"issuer\"].ToString();\n\n        issuer.Should().Be(\"https://server/root\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task when_lower_case_issuer_option_disabled_issuer_uri_should_be_preserved()\n    {\n        IdentityServerPipeline pipeline = new IdentityServerPipeline();\n        pipeline.Initialize(\"/ROOT\");\n\n        pipeline.Options.LowerCaseIssuerUri = false;\n\n        var result = await pipeline.BackChannelClient.GetAsync(\"HTTPS://SERVER/ROOT/.WELL-KNOWN/OPENID-CONFIGURATION\");\n\n        var json = await result.Content.ReadAsStringAsync();\n        var data = JObject.Parse(json);\n        var issuer = data[\"issuer\"].ToString();\n\n        issuer.Should().Be(\"https://server/ROOT\");\n    }\n\n    private void Pipeline_OnPostConfigureServices(IServiceCollection obj)\n    {\n        throw new System.NotImplementedException();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Algorithms_supported_should_match_signing_key()\n    {\n        var key = CryptoHelper.CreateECDsaSecurityKey(JsonWebKeyECTypes.P256);\n        var expectedAlgorithm = SecurityAlgorithms.EcdsaSha256;\n\n        IdentityServerPipeline pipeline = new IdentityServerPipeline();\n        pipeline.OnPostConfigureServices += services =>\n        {\n            // add key to standard RSA key\n            services.AddIdentityServerBuilder()\n                .AddSigningCredential(key, expectedAlgorithm);\n        };\n        pipeline.Initialize(\"/ROOT\");\n\n        var result = await pipeline.BackChannelClient.GetAsync(\"https://server/root/.well-known/openid-configuration\");\n\n        var json = await result.Content.ReadAsStringAsync();\n        var data = JObject.Parse(json);\n        var algorithmsSupported = data[\"id_token_signing_alg_values_supported\"];\n\n        algorithmsSupported.Count().Should().Be(2);\n\n        algorithmsSupported.Values().Should().Contain(SecurityAlgorithms.RsaSha256);\n        algorithmsSupported.Values().Should().Contain(SecurityAlgorithms.EcdsaSha256);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Jwks_entries_should_countain_crv()\n    {\n        var ecdsaKey = CryptoHelper.CreateECDsaSecurityKey(JsonWebKeyECTypes.P256);\n        var parameters = ecdsaKey.ECDsa.ExportParameters(true);\n\n        IdentityServerPipeline pipeline = new IdentityServerPipeline();\n\n        var jsonWebKeyFromECDsa = new JsonWebKey()\n        {\n            Kty = JsonWebAlgorithmsKeyTypes.EllipticCurve,\n            Use = \"sig\",\n            Kid = ecdsaKey.KeyId,\n            KeyId = ecdsaKey.KeyId,\n            X = Base64UrlEncoder.Encode(parameters.Q.X),\n            Y = Base64UrlEncoder.Encode(parameters.Q.Y),\n            D = Base64UrlEncoder.Encode(parameters.D),\n            Crv = JsonWebKeyECTypes.P256,\n            Alg = SecurityAlgorithms.EcdsaSha256\n        };\n        pipeline.OnPostConfigureServices += services =>\n        {\n            // add ECDsa as JsonWebKey\n            services.AddIdentityServerBuilder()\n                .AddSigningCredential(jsonWebKeyFromECDsa, SecurityAlgorithms.EcdsaSha256);\n        };\n\n        pipeline.Initialize(\"/ROOT\");\n\n        var result = await pipeline.BackChannelClient.GetAsync(\"https://server/root/.well-known/openid-configuration/jwks\");\n\n        var json = await result.Content.ReadAsStringAsync();\n        var data = JObject.Parse(json);\n\n        var keys = data[\"keys\"];\n        keys.Should().NotBeNull();\n\n        var key = keys[1];\n        key.Should().NotBeNull();\n\n        var crv = key[\"crv\"];\n        crv.Should().NotBeNull();\n\n        crv.Value<string>().Should().Be(JsonWebKeyECTypes.P256);\n\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Jwks_entries_should_contain_alg()\n    {\n        IdentityServerPipeline pipeline = new IdentityServerPipeline();\n        pipeline.Initialize(\"/ROOT\");\n\n        var result = await pipeline.BackChannelClient.GetAsync(\"https://server/root/.well-known/openid-configuration/jwks\");\n\n        var json = await result.Content.ReadAsStringAsync();\n        var data = JObject.Parse(json);\n\n        var keys = data[\"keys\"];\n        keys.Should().NotBeNull();\n\n        var key = keys[0];\n        key.Should().NotBeNull();\n\n        var alg = key[\"alg\"];\n        alg.Should().NotBeNull();\n\n        alg.Value<string>().Should().Be(Constants.SigningAlgorithms.RSA_SHA_256);\n    }\n\n    [Theory]\n    [InlineData(JsonWebKeyECTypes.P256, SecurityAlgorithms.EcdsaSha256)]\n    [InlineData(JsonWebKeyECTypes.P384, SecurityAlgorithms.EcdsaSha384)]\n    [InlineData(JsonWebKeyECTypes.P521, SecurityAlgorithms.EcdsaSha512)]\n    [Trait(\"Category\", Category)]\n    public async Task Jwks_with_ecdsa_should_have_parsable_key(string crv, string alg)\n    {\n        var key = CryptoHelper.CreateECDsaSecurityKey(crv);\n\n        IdentityServerPipeline pipeline = new IdentityServerPipeline();\n        pipeline.OnPostConfigureServices += services =>\n        {\n            services.AddIdentityServerBuilder()\n                .AddSigningCredential(key, alg);\n        };\n        pipeline.Initialize(\"/ROOT\");\n\n        var result = await pipeline.BackChannelClient.GetAsync(\"https://server/root/.well-known/openid-configuration/jwks\");\n\n        var json = await result.Content.ReadAsStringAsync();\n        var jwks = new JsonWebKeySet(json);\n        var parsedKeys = jwks.GetSigningKeys();\n\n        var matchingKey = parsedKeys.FirstOrDefault(x => x.KeyId == key.KeyId);\n        matchingKey.Should().NotBeNull();\n        matchingKey.Should().BeOfType<ECDsaSecurityKey>();\n    }\n\n    [Fact]\n    public async Task Jwks_with_two_key_using_different_algs_expect_different_alg_values()\n    {\n        var ecdsaKey = CryptoHelper.CreateECDsaSecurityKey();\n        var rsaKey = CryptoHelper.CreateRsaSecurityKey();\n\n        IdentityServerPipeline pipeline = new IdentityServerPipeline();\n        pipeline.OnPostConfigureServices += services =>\n        {\n            services.AddIdentityServerBuilder()\n                .AddSigningCredential(ecdsaKey, \"ES256\")\n                .AddValidationKey(new SecurityKeyInfo { Key = rsaKey, SigningAlgorithm = \"RS256\" });\n        };\n        pipeline.Initialize(\"/ROOT\");\n\n        var result = await pipeline.BackChannelClient.GetAsync(\"https://server/root/.well-known/openid-configuration/jwks\");\n\n        var json = await result.Content.ReadAsStringAsync();\n        var jwks = new JsonWebKeySet(json);\n\n        jwks.Keys.Should().Contain(x => x.KeyId == ecdsaKey.KeyId && x.Alg == \"ES256\");\n        jwks.Keys.Should().Contain(x => x.KeyId == rsaKey.KeyId && x.Alg == \"RS256\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Unicode_values_in_url_should_be_processed_correctly()\n    {\n        var pipeline = new IdentityServerPipeline();\n        pipeline.Initialize();\n\n        var result = await pipeline.BackChannelClient.GetDiscoveryDocumentAsync(new DiscoveryDocumentRequest\n        {\n            Address = \"https://грант.рф\",\n            Policy =\n            {\n                ValidateIssuerName = false,\n                ValidateEndpoints = false,\n                RequireHttps = false,\n                RequireKeySet = false\n            }\n        });\n\n        result.Issuer.Should().Be(\"https://грант.рф\");\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/EndSession/EndSessionTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Net;\nusing System.Net.Http;\nusing System.Security.Claims;\nusing System.Text;\nusing System.Text.Encodings.Web;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Microsoft.AspNetCore.WebUtilities;\nusing Newtonsoft.Json.Linq;\nusing Xunit;\nusing static IdentityServer8.IdentityServerConstants;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.EndSession;\n\npublic class EndSessionTests\n{\n    private const string Category = \"End session endpoint\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n    private Client _wsfedClient;\n\n    public EndSessionTests()\n    {\n        _mockPipeline.Clients.Add(new Client\n        {\n            ClientId = \"client1\",\n            AllowedGrantTypes = GrantTypes.Implicit,\n            RequireConsent = false,\n            AllowedScopes = new List<string> { \"openid\" },\n            RedirectUris = new List<string> { \"https://client1/callback\" },\n            FrontChannelLogoutUri = \"https://client1/signout\",\n            PostLogoutRedirectUris = new List<string> { \"https://client1/signout-callback\" },\n            AllowAccessTokensViaBrowser = true\n        });\n\n        _mockPipeline.Clients.Add(new Client\n        {\n            ClientId = \"client2\",\n            AllowedGrantTypes = GrantTypes.Implicit,\n            RequireConsent = false,\n            AllowedScopes = new List<string> { \"openid\" },\n            RedirectUris = new List<string> { \"https://client2/callback\" },\n            FrontChannelLogoutUri = \"https://client2/signout\",\n            PostLogoutRedirectUris = new List<string> {\n                \"https://client2/signout-callback\",\n                \"https://client2/signout-callback2\"\n            },\n            AllowAccessTokensViaBrowser = true\n        });\n\n        _mockPipeline.Clients.Add(new Client\n        {\n            ClientId = \"client3\",\n            AllowedGrantTypes = GrantTypes.Implicit,\n            RequireConsent = false,\n            AllowedScopes = new List<string> { \"openid\" },\n            RedirectUris = new List<string> { \"https://client3/callback\" },\n            BackChannelLogoutUri = \"https://client3/signout\",\n            AllowAccessTokensViaBrowser = true\n        });\n\n        _mockPipeline.Clients.Add(_wsfedClient = new Client\n        {\n            ClientId = \"client4\",\n            AllowedGrantTypes = GrantTypes.Implicit,\n            RequireConsent = false,\n            AllowedScopes = new List<string> { \"openid\" },\n            RedirectUris = new List<string> { \"https://client4/callback\" },\n            FrontChannelLogoutUri = \"https://client4/signout\",\n            AllowAccessTokensViaBrowser = true\n        });\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n            {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n            }\n        });\n\n        _mockPipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId()\n        });\n\n        _mockPipeline.Initialize();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task get_request_should_not_return_404()\n    {\n        var response = await _mockPipeline.BackChannelClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint);\n\n        response.StatusCode.Should().NotBe(HttpStatusCode.NotFound);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task signout_request_should_redirect_to_logout_page()\n    {\n        var response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint);\n\n        _mockPipeline.LogoutWasCalled.Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task get_request_should_redirect_to_configured_logout_path()\n    {\n        _mockPipeline.Options.UserInteraction.LogoutUrl = \"/logout\";\n        _mockPipeline.Options.UserInteraction.LogoutIdParameter = \"id\";\n\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        var id_token = authorization.IdentityToken;\n\n        response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint +\n            \"?id_token_hint=\" + id_token +\n            \"&post_logout_redirect_uri=https://client1/signout-callback\");\n\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"https://server/logout?id=\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task logout_request_with_params_should_pass_values_in_logout_context()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var authorization = await _mockPipeline.RequestAuthorizationEndpointAsync(\n            clientId: \"client2\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        var id_token = authorization.IdentityToken;\n\n        var response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint +\n            \"?id_token_hint=\" + id_token +\n            \"&post_logout_redirect_uri=https://client2/signout-callback2\");\n\n        _mockPipeline.LogoutWasCalled.Should().BeTrue();\n        _mockPipeline.LogoutRequest.Should().NotBeNull();\n        _mockPipeline.LogoutRequest.ClientId.Should().Be(\"client2\");\n        _mockPipeline.LogoutRequest.PostLogoutRedirectUri.Should().Be(\"https://client2/signout-callback2\");\n\n        var parts = _mockPipeline.LogoutRequest.SignOutIFrameUrl.Split('?');\n        parts[0].Should().Be(IdentityServerPipeline.EndSessionCallbackEndpoint);\n        var iframeUrl = QueryHelpers.ParseNullableQuery(parts[1]);\n        iframeUrl[\"endSessionId\"].FirstOrDefault().Should().NotBeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task logout_request_with_params_but_user_no_longer_authenticated_should_pass_redirect_info_to_logout()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var authorization = await _mockPipeline.RequestAuthorizationEndpointAsync(\n            clientId: \"client2\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        var id_token = authorization.IdentityToken;\n\n        _mockPipeline.RemoveLoginCookie();\n\n        var response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint +\n            \"?id_token_hint=\" + id_token +\n            \"&post_logout_redirect_uri=https://client2/signout-callback2\");\n\n        _mockPipeline.LogoutWasCalled.Should().BeTrue();\n        _mockPipeline.LogoutRequest.Should().NotBeNull();\n        _mockPipeline.LogoutRequest.ClientId.Should().Be(\"client2\");\n        _mockPipeline.LogoutRequest.PostLogoutRedirectUri.Should().Be(\"https://client2/signout-callback2\");\n        _mockPipeline.LogoutRequest.SignOutIFrameUrl.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task signout_should_support_POST()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        var id_token = authorization.IdentityToken;\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n\n        var values = new List<KeyValuePair<string, string>>();\n        values.Add(new KeyValuePair<string, string>(\"id_token_hint\", id_token));\n        values.Add(new KeyValuePair<string, string>(\"post_logout_redirect_uri\", \"https://client1/signout-callback\"));\n        var content = new FormUrlEncodedContent(values);\n        response = await _mockPipeline.BrowserClient.PostAsync(IdentityServerPipeline.EndSessionEndpoint, content);\n\n        _mockPipeline.LogoutWasCalled.Should().BeTrue();\n        _mockPipeline.LogoutRequest.Should().NotBeNull();\n        _mockPipeline.LogoutRequest.ClientId.Should().Be(\"client1\");\n        _mockPipeline.LogoutRequest.PostLogoutRedirectUri.Should().Be(\"https://client1/signout-callback\");\n\n        var parts = _mockPipeline.LogoutRequest.SignOutIFrameUrl.Split('?');\n        parts[0].Should().Be(IdentityServerPipeline.EndSessionCallbackEndpoint);\n        var iframeUrl = QueryHelpers.ParseNullableQuery(parts[1]);\n        iframeUrl[\"endSessionId\"].FirstOrDefault().Should().NotBeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task signout_callback_without_params_should_return_400()\n    {\n        var response = await _mockPipeline.BackChannelClient.GetAsync(IdentityServerPipeline.EndSessionCallbackEndpoint);\n\n        response.StatusCode.Should().Be(HttpStatusCode.BadRequest);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task signout_callback_with_mismatched_post_logout_redirect_uri_should_not_pass_along_logout_uri()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        var id_token = authorization.IdentityToken;\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n        response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint +\n            \"?id_token_hint=\" + id_token +\n            \"&post_logout_redirect_uri=https://client1/signout-callback-not-valid\");\n\n        var signoutFrameUrl = _mockPipeline.LogoutRequest.SignOutIFrameUrl;\n\n        response = await _mockPipeline.BrowserClient.GetAsync(signoutFrameUrl);\n\n        _mockPipeline.LogoutRequest.ClientId.Should().NotBeNull();\n        _mockPipeline.LogoutRequest.PostLogoutRedirectUri.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task signout_callback_with_mismatched_id_token_hint_should_not_pass_along_logout_message()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        var id_token = authorization.IdentityToken;\n\n        await _mockPipeline.LoginAsync(\"alice\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n        response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint +\n            \"?id_token_hint=\" + id_token +\n            \"&post_logout_redirect_uri=https://client1/signout-callback\");\n\n        _mockPipeline.LogoutRequest.ClientId.Should().BeNull();\n        _mockPipeline.LogoutRequest.PostLogoutRedirectUri.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task valid_signout_callback_should_return_200_html()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n        response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint);\n\n        var signoutFrameUrl = _mockPipeline.LogoutRequest.SignOutIFrameUrl;\n\n        response = await _mockPipeline.BrowserClient.GetAsync(signoutFrameUrl);\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n        response.Content.Headers.ContentType.MediaType.Should().Be(\"text/html\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task valid_signout_callback_should_render_iframes_for_all_clients()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n        var sid = _mockPipeline.GetSessionCookie().Value;\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        var url2 = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client2\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response2 = await _mockPipeline.BrowserClient.GetAsync(url2);\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n        response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint);\n\n        var signoutFrameUrl = _mockPipeline.LogoutRequest.SignOutIFrameUrl;\n\n        response = await _mockPipeline.BrowserClient.GetAsync(signoutFrameUrl);\n        var html = await response.Content.ReadAsStringAsync();\n        html.Should().Contain(HtmlEncoder.Default.Encode(\"https://client1/signout?sid=\" + sid + \"&iss=\" + UrlEncoder.Default.Encode(\"https://server\")));\n        html.Should().Contain(HtmlEncoder.Default.Encode(\"https://client2/signout?sid=\" + sid + \"&iss=\" + UrlEncoder.Default.Encode(\"https://server\")));\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task signout_callback_should_use_signoutcleanup_for_wsfed_client()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n        var sid = _mockPipeline.GetSessionCookie().Value;\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client4\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client4/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n        response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint);\n\n        var signoutFrameUrl = _mockPipeline.LogoutRequest.SignOutIFrameUrl;\n\n        // since we don't have real ws-fed, we used OIDC to signin, but fooling this\n        // at signout to use ws-fed so we can test the iframe params\n        _wsfedClient.ProtocolType = ProtocolTypes.WsFederation;\n\n        response = await _mockPipeline.BrowserClient.GetAsync(signoutFrameUrl);\n        var html = await response.Content.ReadAsStringAsync();\n        html.Should().Contain(\"https://client4/signout?wa=wsignoutcleanup1.0\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task valid_id_token_hint_but_no_post_logout_redirect_uri_should_not_use_single_registered_post_logout_redirect_uri()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        var id_token = authorization.IdentityToken;\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n        response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint + \n            \"?id_token_hint=\" + id_token);\n\n        _mockPipeline.LogoutRequest.PostLogoutRedirectUri.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task valid_id_token_hint_but_no_post_logout_redirect_uri_should_not_use_any_of_multiple_registered_post_logout_redirect_uri()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"client2\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        var id_token = authorization.IdentityToken;\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = true;\n        response = await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint +\n            \"?id_token_hint=\" + id_token);\n\n        _mockPipeline.LogoutRequest.PostLogoutRedirectUri.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task logout_with_clients_should_render_signout_callback_iframe()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var response = await _mockPipeline.RequestAuthorizationEndpointAsync(\n            clientId: \"client2\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client2/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        response.Should().NotBeNull();\n\n        await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint);\n\n        _mockPipeline.LogoutWasCalled.Should().BeTrue();\n        _mockPipeline.LogoutRequest.SignOutIFrameUrl.Should().NotBeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task logout_without_clients_should_not_render_signout_callback_iframe()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint);\n\n        _mockPipeline.LogoutWasCalled.Should().BeTrue();\n        _mockPipeline.LogoutRequest.SignOutIFrameUrl.Should().BeNull();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task logout_should_invoke_back_channel_logout()\n    {\n        _mockPipeline.BackChannelMessageHandler.OnInvoke = async req =>\n        {\n            req.RequestUri.ToString().Should().StartWith(\"https://client3/signout\");\n\n            var form = await req.Content.ReadAsStringAsync();\n            form.Should().Contain(OidcConstants.BackChannelLogoutRequest.LogoutToken);\n\n            var token = form.Split('=')[1];\n            var parts = token.Split('.');\n            parts.Length.Should().Be(3);\n\n            var bytes = Base64Url.Decode(parts[1]);\n            var json = Encoding.UTF8.GetString(bytes);\n            var payload = JObject.Parse(json);\n            payload[\"iss\"].ToString().Should().Be(\"https://server\");\n            payload[\"sub\"].ToString().Should().Be(\"bob\");\n            payload[\"aud\"].ToString().Should().Be(\"client3\");\n            payload[\"iat\"].Should().NotBeNull();\n            payload[\"jti\"].Should().NotBeNull();\n            payload[\"sid\"].Should().NotBeNull();\n            payload[\"events\"].Type.Should().Be(JTokenType.Object);\n\n            var events = (JObject)payload[\"events\"];\n            events.Count.Should().Be(1);\n            events[\"http://schemas.openid.net/event/backchannel-logout\"].Should().NotBeNull();\n            events[\"http://schemas.openid.net/event/backchannel-logout\"].Type.Should().Be(JTokenType.Object);\n\n            var evt = (JObject)events[\"http://schemas.openid.net/event/backchannel-logout\"];\n            evt.Count.Should().Be(0);\n        };\n\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var response = await _mockPipeline.RequestAuthorizationEndpointAsync(\n            clientId: \"client3\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client3/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        response.Should().NotBeNull();\n\n        await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint);\n\n        _mockPipeline.BackChannelMessageHandler.InvokeWasCalled.Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task back_channel_logout_should_not_affect_end_session_callback()\n    {\n        _mockPipeline.BackChannelMessageHandler.OnInvoke = req => throw new Exception(\"boom!\");\n\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var response = await _mockPipeline.RequestAuthorizationEndpointAsync(\n            clientId: \"client3\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client3/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        response.Should().NotBeNull();\n\n        await _mockPipeline.BrowserClient.GetAsync(IdentityServerPipeline.EndSessionEndpoint);\n\n        _mockPipeline.BackChannelMessageHandler.InvokeWasCalled.Should().BeTrue();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Introspection/IntrospectionTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Net;\nusing System.Net.Http;\nusing System.Text;\nusing System.Text.Json;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Endpoints.Introspection.Setup;\nusing IdentityServer8.Extensions;\nusing Microsoft.AspNetCore.Hosting;\nusing Microsoft.AspNetCore.TestHost;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Introspection;\n\npublic class IntrospectionTests\n{\n    private const string Category = \"Introspection endpoint\";\n    private const string IntrospectionEndpoint = \"https://server/connect/introspect\";\n    private const string TokenEndpoint = \"https://server/connect/token\";\n\n    private readonly HttpClient _client;\n    private readonly HttpMessageHandler _handler;\n\n    public IntrospectionTests()\n    {\n        var builder = new WebHostBuilder()\n            .UseStartup<Startup>();\n        var server = new TestServer(builder);\n\n        _handler = server.CreateHandler();\n        _client = server.CreateClient();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Empty_request_should_fail()\n    {\n        var form = new Dictionary<string, string>();\n\n        var response = await _client.PostAsync(IntrospectionEndpoint, new FormUrlEncodedContent(form));\n\n        response.StatusCode.Should().Be(HttpStatusCode.Unauthorized);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Unknown_scope_should_fail()\n    {\n        var form = new Dictionary<string, string>();\n\n        _client.SetBasicAuthentication(\"unknown\", \"invalid\");\n        var response = await _client.PostAsync(IntrospectionEndpoint, new FormUrlEncodedContent(form));\n\n        response.StatusCode.Should().Be(HttpStatusCode.Unauthorized);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Invalid_scope_secret_should_fail()\n    {\n        var form = new Dictionary<string, string>();\n\n        _client.SetBasicAuthentication(\"api1\", \"invalid\");\n        var response = await _client.PostAsync(IntrospectionEndpoint, new FormUrlEncodedContent(form));\n\n        response.StatusCode.Should().Be(HttpStatusCode.Unauthorized);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Missing_token_should_fail()\n    {\n        var form = new Dictionary<string, string>();\n\n        _client.SetBasicAuthentication(\"api1\", \"secret\");\n        var response = await _client.PostAsync(IntrospectionEndpoint, new FormUrlEncodedContent(form));\n\n        response.StatusCode.Should().Be(HttpStatusCode.BadRequest);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Invalid_token_should_fail()\n    {\n        var introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api1\",\n            ClientSecret = \"secret\",\n\n            Token = \"invalid\"\n        });\n\n        introspectionResponse.IsActive.Should().Be(false);\n        introspectionResponse.IsError.Should().Be(false);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Invalid_Content_type_should_fail()\n    {\n        var tokenResponse = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client1\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\"\n        });\n\n        var data = new\n        {\n            client_id = \"api1\",\n            client_secret = \"secret\",\n            token = tokenResponse.AccessToken\n        };\n        var json = JsonSerializer.Serialize(data);\n\n        var client = new HttpClient(_handler);\n        var response = await client.PostAsync(IntrospectionEndpoint, new StringContent(json, Encoding.UTF8, \"application/json\"));\n        response.StatusCode.Should().Be(HttpStatusCode.UnsupportedMediaType);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Valid_token_and_valid_scope_should_succeed()\n    {\n        var tokenResponse = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client1\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\"\n        });\n\n        var introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api1\",\n            ClientSecret = \"secret\",\n\n            Token = tokenResponse.AccessToken\n        });\n\n        introspectionResponse.IsActive.Should().Be(true);\n        introspectionResponse.IsError.Should().Be(false);\n\n        var scopes = from c in introspectionResponse.Claims\n                     where c.Type == \"scope\"\n                     select c;\n\n        scopes.Count().Should().Be(1);\n        scopes.First().Value.Should().Be(\"api1\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Response_data_should_be_valid_using_single_scope()\n    {\n        var tokenResponse = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client1\",\n            ClientSecret = \"secret\",\n            Scope = \"api1\"\n        });\n\n        var introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api1\",\n            ClientSecret = \"secret\",\n\n            Token = tokenResponse.AccessToken\n        });\n\n        var values = introspectionResponse.Json.ToObject<Dictionary<string, JsonElement>>();\n\n        values[\"aud\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"iss\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"nbf\"].ValueKind.Should().Be(JsonValueKind.Number); \n        values[\"exp\"].ValueKind.Should().Be(JsonValueKind.Number); \n        values[\"client_id\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"active\"].ValueKind.Should().Be(JsonValueKind.True); \n        values[\"scope\"].ValueKind.Should().Be(JsonValueKind.String);\n\n        values[\"scope\"].ToString().Should().Be(\"api1\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Response_data_with_user_authentication_should_be_valid_using_single_scope()\n    {\n        var tokenResponse = await _client.RequestPasswordTokenAsync(new PasswordTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"ro.client\",\n            ClientSecret = \"secret\",\n            UserName = \"bob\",\n            Password = \"bob\",\n\n            Scope = \"api1\",\n        });\n\n        tokenResponse.IsError.Should().BeFalse();\n\n        var introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api1\",\n            ClientSecret = \"secret\",\n\n            Token = tokenResponse.AccessToken\n        });\n\n        var values = introspectionResponse.Json.ToObject<Dictionary<string, JsonElement>>();\n\n        values[\"aud\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"iss\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"nbf\"].ValueKind.Should().Be(JsonValueKind.Number); \n        values[\"exp\"].ValueKind.Should().Be(JsonValueKind.Number); \n        values[\"auth_time\"].ValueKind.Should().Be(JsonValueKind.Number); \n        values[\"client_id\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"sub\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"active\"].ValueKind.Should().Be(JsonValueKind.True); \n        values[\"scope\"].ValueKind.Should().Be(JsonValueKind.String);\n\n        values[\"scope\"].ToString().Should().Be(\"api1\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Response_data_should_be_valid_using_multiple_scopes_multiple_audiences()\n    {\n        var tokenResponse = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client1\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api2 api3-a api3-b\",\n        });\n\n        tokenResponse.IsError.Should().BeFalse();\n\n        var introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api3\",\n            ClientSecret = \"secret\",\n\n            Token = tokenResponse.AccessToken\n        });\n\n        var values = introspectionResponse.Json.ToObject<Dictionary<string, JsonElement>>();\n\n\n        values[\"aud\"].GetType().Name.Should().Be(\"JsonElement\");\n        values[\"aud\"].ValueKind.Should().Be(JsonValueKind.Array);\n\n        // Access the 'aud' array\n        var audiences = values[\"aud\"].EnumerateArray();\n        foreach (var aud in audiences)\n        {\n            // Check each audience value to ensure it's a string\n            aud.ValueKind.Should().Be(JsonValueKind.String);\n        }\n\n        values[\"iss\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"iss\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"nbf\"].ValueKind.Should().Be(JsonValueKind.Number);\n        values[\"exp\"].ValueKind.Should().Be(JsonValueKind.Number);\n        values[\"client_id\"].ValueKind.Should().Be(JsonValueKind.String);\n        var activeKind= values[\"active\"].ValueKind;\n        values[\"active\"].ValueKind.Should().Be(JsonValueKind.True);\n        values[\"scope\"].ValueKind.Should().Be(JsonValueKind.String);\n\n        var scopes = values[\"scope\"].ToString();\n        scopes.Should().Be(\"api3-a api3-b\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Response_data_should_be_valid_using_multiple_scopes_single_audience()\n    {\n        var tokenResponse = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client1\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api3-a api3-b\",\n        });\n\n        tokenResponse.IsError.Should().BeFalse();\n\n        var introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api3\",\n            ClientSecret = \"secret\",\n\n            Token = tokenResponse.AccessToken\n        });\n\n        var values = introspectionResponse.Json.ToObject<Dictionary<string, JsonElement>>();\n        values[\"aud\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"aud\"].ValueKind.Should().Be(JsonValueKind.String);\n        values[\"iss\"].ValueKind.Should().Be(JsonValueKind.String); \n        values[\"nbf\"].ValueKind.Should().Be(JsonValueKind.Number);  \n        values[\"exp\"].ValueKind.Should().Be(JsonValueKind.Number);  \n        values[\"client_id\"].ValueKind.Should().Be(JsonValueKind.String); \n        values[\"active\"].ValueKind.Should().Be(JsonValueKind.True); \n        values[\"scope\"].ValueKind.Should().Be(JsonValueKind.String);\n\n        var scopes = values[\"scope\"].ToString();\n        scopes.Should().Be(\"api3-a api3-b\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Token_with_many_scopes_but_api_should_only_see_its_own_scopes()\n    {\n        var tokenResponse = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client3\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api1 api2 api3-a\",\n        });\n\n        tokenResponse.IsError.Should().BeFalse();\n\n        var introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api3\",\n            ClientSecret = \"secret\",\n\n            Token = tokenResponse.AccessToken\n        });\n\n        introspectionResponse.IsActive.Should().BeTrue();\n        introspectionResponse.IsError.Should().BeFalse();\n\n        var scopes = from c in introspectionResponse.Claims\n                     where c.Type == \"scope\"\n                     select c.Value;\n\n        scopes.Count().Should().Be(1);\n        scopes.First().Should().Be(\"api3-a\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Valid_token_with_valid_multiple_scopes()\n    {\n        var tokenResponse = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client1\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api1 api2\",\n        });\n\n        var introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api1\",\n            ClientSecret = \"secret\",\n\n            Token = tokenResponse.AccessToken\n        });\n\n        introspectionResponse.IsActive.Should().Be(true);\n        introspectionResponse.IsError.Should().Be(false);\n\n        var scopes = from c in introspectionResponse.Claims\n                     where c.Type == \"scope\"\n                     select c;\n\n        scopes.Count().Should().Be(1);\n        scopes.First().Value.Should().Be(\"api1\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Valid_token_with_invalid_scopes_should_fail()\n    {\n        var tokenResponse = await _client.RequestClientCredentialsTokenAsync(new ClientCredentialsTokenRequest\n        {\n            Address = TokenEndpoint,\n            ClientId = \"client1\",\n            ClientSecret = \"secret\",\n\n            Scope = \"api1\",\n        });\n\n        var introspectionResponse = await _client.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IntrospectionEndpoint,\n            ClientId = \"api2\",\n            ClientSecret = \"secret\",\n\n            Token = tokenResponse.AccessToken\n        });\n\n        introspectionResponse.IsActive.Should().Be(false);\n        introspectionResponse.IsError.Should().Be(false);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Introspection/Setup/Clients.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing IdentityServer8.Models;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Introspection.Setup;\n\ninternal class Clients\n{\n    public static IEnumerable<Client> Get()\n    {\n        return new List<Client>\n        {\n            new Client\n            {\n                ClientId = \"client1\",\n                ClientSecrets = new List<Secret>\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"api1\", \"api2\", \"api3-a\", \"api3-b\" },\n                AccessTokenType = AccessTokenType.Reference\n            },\n            new Client\n            {\n                ClientId = \"client2\",\n                ClientSecrets = new List<Secret>\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"api1\", \"api2\", \"api3-a\", \"api3-b\" },\n                AccessTokenType = AccessTokenType.Reference\n            },\n            new Client\n            {\n                ClientId = \"client3\",\n                ClientSecrets = new List<Secret>\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"api1\", \"api2\", \"api3-a\", \"api3-b\" },\n                AccessTokenType = AccessTokenType.Reference\n            },\n            new Client\n            {\n                ClientId = \"ro.client\",\n                ClientSecrets = new List<Secret>\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                AllowedScopes = { \"api1\", \"api2\", \"api3-a\", \"api3-b\" },\n                AccessTokenType = AccessTokenType.Reference\n            }\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Introspection/Setup/Scopes.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing IdentityServer8.Models;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Introspection.Setup;\n\ninternal class Scopes\n{\n    public static IEnumerable<ApiResource> GetApis()\n    {\n        return new ApiResource[]\n        {\n            new ApiResource\n            {\n                Name = \"api1\",\n                ApiSecrets = new List<Secret>\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n                Scopes = { \"api1\" }\n            },\n            new ApiResource\n            {\n                Name = \"api2\",\n                ApiSecrets = new List<Secret>\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n                Scopes = { \"api2\" }\n            },\n             new ApiResource\n            {\n                Name = \"api3\",\n                ApiSecrets = new List<Secret>\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n                Scopes = { \"api3-a\", \"api3-b\" }\n            }\n        };\n    }\n    public static IEnumerable<ApiScope> GetScopes()\n    {\n        return new ApiScope[]\n        {\n            new ApiScope\n            {\n                Name = \"api1\"\n            },\n            new ApiScope\n            {\n                Name = \"api2\"\n            },\n            new ApiScope\n            {\n                Name = \"api3-a\"\n            },\n            new ApiScope\n            {\n                Name = \"api3-b\"\n            }\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Introspection/Setup/Startup.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore.Builder;\nusing Microsoft.Extensions.DependencyInjection;\nusing Microsoft.Extensions.Logging;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Introspection.Setup;\n\npublic class Startup\n{\n    public void ConfigureServices(IServiceCollection services)\n    {\n        var builder = services.AddIdentityServer(options =>\n        {\n            options.IssuerUri = \"https://idsvr8\";\n            options.Endpoints.EnableAuthorizeEndpoint = false;\n        });\n\n        builder.AddInMemoryClients(Clients.Get());\n        builder.AddInMemoryApiResources(Scopes.GetApis());\n        builder.AddInMemoryApiScopes(Scopes.GetScopes());\n        builder.AddTestUsers(Users.Get());\n        builder.AddDeveloperSigningCredential(persistKey: false);\n    }\n\n    public void Configure(IApplicationBuilder app, ILoggerFactory loggerFactory)\n    {\n        app.UseIdentityServer();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Introspection/Setup/Users.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing IdentityServer8.Test;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Introspection.Setup;\n\npublic static class Users\n{\n    public static List<TestUser> Get()\n    {\n        return new List<TestUser>\n        {\n            new TestUser\n            {\n                SubjectId = \"1\",\n                Username = \"bob\",\n                Password = \"bob\"\n            }\n        };\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Revocation/RevocationTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Net;\nusing System.Net.Http;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Revocation;\n\npublic class RevocationTests\n{\n    private const string Category = \"RevocationTests endpoint\";\n\n    private string client_id = \"client\";\n    private string client_secret = \"secret\";\n    private string redirect_uri = \"https://client/callback\";\n\n    private string scope_name = \"api\";\n    private string scope_secret = \"api_secret\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    public RevocationTests()\n    {\n        _mockPipeline.Clients.Add(new Client\n        {\n            ClientId = client_id,\n            ClientSecrets = new List<Secret> { new Secret(client_secret.Sha256()) },\n            AllowedGrantTypes = GrantTypes.Code,\n            RequireConsent = false,\n            RequirePkce = false,\n            AllowOfflineAccess = true,\n            AllowedScopes = new List<string> { \"api\" },\n            RedirectUris = new List<string> { redirect_uri },\n            AllowAccessTokensViaBrowser = true,\n            AccessTokenType = AccessTokenType.Reference,\n            RefreshTokenUsage = TokenUsage.ReUse\n        });\n        _mockPipeline.Clients.Add(new Client\n        {\n            ClientId = \"implicit\",\n            AllowedGrantTypes = GrantTypes.Implicit,\n            RequireConsent = false,\n            AllowedScopes = new List<string> { \"api\" },\n            RedirectUris = new List<string> { redirect_uri },\n            AllowAccessTokensViaBrowser = true,\n            AccessTokenType = AccessTokenType.Reference\n        });\n        _mockPipeline.Clients.Add(new Client\n        {\n            ClientId = \"implicit_and_client_creds\",\n            AllowedGrantTypes = GrantTypes.ImplicitAndClientCredentials,\n            ClientSecrets = { new Secret(\"secret\".Sha256()) },\n            RequireConsent = false,\n            AllowedScopes = new List<string> { \"api\" },\n            RedirectUris = new List<string> { redirect_uri },\n            AllowAccessTokensViaBrowser = true,\n            AccessTokenType = AccessTokenType.Reference\n        });\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n            {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n            }\n        });\n\n        _mockPipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId()\n        });\n\n        _mockPipeline.ApiResources.AddRange(new ApiResource[] {\n            new ApiResource\n            {\n                Name = \"api\",\n                ApiSecrets = new List<Secret> { new Secret(scope_secret.Sha256()) },\n                Scopes = { scope_name }\n            }\n        });\n\n        _mockPipeline.ApiScopes.AddRange(new ApiScope[]\n        {\n            new ApiScope\n            {\n                Name = scope_name\n            }\n        });\n\n        _mockPipeline.Initialize();\n    }\n\n    private class Tokens\n    {\n        public Tokens(TokenResponse response)\n        {\n            AccessToken = response.AccessToken;\n            RefreshToken = response.RefreshToken;\n        }\n\n        public string AccessToken { get; set; }\n        public string RefreshToken { get; set; }\n    }\n\n    private async Task<Tokens> GetTokensAsync()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var authorizationResponse = await _mockPipeline.RequestAuthorizationEndpointAsync(\n            client_id,\n            \"code\",\n            \"api offline_access\",\n            \"https://client/callback\");\n\n        authorizationResponse.IsError.Should().BeFalse();\n        authorizationResponse.Code.Should().NotBeNull();\n\n        var tokenResponse = await _mockPipeline.BackChannelClient.RequestAuthorizationCodeTokenAsync(new AuthorizationCodeTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = client_id,\n            ClientSecret = client_secret,\n\n            Code = authorizationResponse.Code,\n            RedirectUri = redirect_uri\n        });\n\n        tokenResponse.IsError.Should().BeFalse();\n        tokenResponse.AccessToken.Should().NotBeNull();\n        tokenResponse.RefreshToken.Should().NotBeNull();\n\n        return new Tokens(tokenResponse);\n    }\n\n    private async Task<string> GetAccessTokenForImplicitClientAsync(string clientId)\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var authorizationResponse = await _mockPipeline.RequestAuthorizationEndpointAsync(\n            clientId,\n            \"token\",\n            \"api\",\n            \"https://client/callback\");\n\n        authorizationResponse.IsError.Should().BeFalse();\n        authorizationResponse.AccessToken.Should().NotBeNull();\n\n        return authorizationResponse.AccessToken;\n    }\n\n    private Task<bool> IsAccessTokenValidAsync(Tokens tokens)\n    {\n        return IsAccessTokenValidAsync(tokens.AccessToken);\n    }\n\n    private async Task<bool> IsAccessTokenValidAsync(string token)\n    {\n        var response = await _mockPipeline.BackChannelClient.IntrospectTokenAsync(new TokenIntrospectionRequest\n        {\n            Address = IdentityServerPipeline.IntrospectionEndpoint,\n            ClientId = scope_name,\n            ClientSecret = scope_secret,\n\n            Token = token,\n            TokenTypeHint = IdentityModel.OidcConstants.TokenTypes.AccessToken\n        });\n\n        return response.IsError == false && response.IsActive;\n    }\n\n    private async Task<bool> UseRefreshTokenAsync(Tokens tokens)\n    {\n        var response = await _mockPipeline.BackChannelClient.RequestRefreshTokenAsync(new RefreshTokenRequest\n        {\n            Address = IdentityServerPipeline.TokenEndpoint,\n            ClientId = client_id,\n            ClientSecret = client_secret,\n\n            RefreshToken = tokens.RefreshToken\n        });\n\n        if (response.IsError)\n        {\n            return false;\n        }\n\n        tokens.AccessToken = response.AccessToken;\n        return true;\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Get_request_should_return_405()\n    {\n        var response = await _mockPipeline.BackChannelClient.GetAsync(IdentityServerPipeline.RevocationEndpoint);\n\n        response.StatusCode.Should().Be(HttpStatusCode.MethodNotAllowed);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Post_without_form_urlencoded_should_return_415()\n    {\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.RevocationEndpoint, null);\n\n        response.StatusCode.Should().Be(HttpStatusCode.UnsupportedMediaType);\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Revoke_valid_access_token_should_return_success()\n    {\n        var tokens = await GetTokensAsync();\n        (await IsAccessTokenValidAsync(tokens)).Should().BeTrue();\n\n        var result = await _mockPipeline.BackChannelClient.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = IdentityServerPipeline.RevocationEndpoint,\n            ClientId = client_id,\n            ClientSecret = client_secret,\n\n            Token = tokens.AccessToken\n        });\n\n        result.IsError.Should().BeFalse();\n        (await IsAccessTokenValidAsync(tokens)).Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Revoke_valid_access_token_belonging_to_another_client_should_return_success_but_not_revoke_token()\n    {\n        var tokens = await GetTokensAsync();\n        (await IsAccessTokenValidAsync(tokens)).Should().BeTrue();\n\n        var result = await _mockPipeline.BackChannelClient.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = IdentityServerPipeline.RevocationEndpoint,\n            ClientId = \"implicit\",\n            ClientSecret = client_secret,\n\n            Token = tokens.AccessToken\n        });\n\n        result.IsError.Should().BeFalse();\n        (await IsAccessTokenValidAsync(tokens)).Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Revoke_valid_refresh_token_should_return_success()\n    {\n        var tokens = await GetTokensAsync();\n        (await UseRefreshTokenAsync(tokens)).Should().BeTrue();\n\n        var result = await _mockPipeline.BackChannelClient.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = IdentityServerPipeline.RevocationEndpoint,\n            ClientId = client_id,\n            ClientSecret = client_secret,\n\n            Token = tokens.RefreshToken\n        });\n\n        result.IsError.Should().BeFalse();\n\n        (await UseRefreshTokenAsync(tokens)).Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Revoke_valid_refresh_token_belonging_to_another_client_should_return_success_but_not_revoke_token()\n    {\n        var tokens = await GetTokensAsync();\n        (await UseRefreshTokenAsync(tokens)).Should().BeTrue();\n\n        var result = await _mockPipeline.BackChannelClient.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = IdentityServerPipeline.RevocationEndpoint,\n            ClientId = \"implicit\",\n            ClientSecret = client_secret,\n\n            Token = tokens.RefreshToken\n        });\n\n        result.IsError.Should().BeFalse();\n\n        (await UseRefreshTokenAsync(tokens)).Should().BeTrue();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Revoke_invalid_access_token_should_return_success()\n    {\n        var tokens = await GetTokensAsync();\n        (await IsAccessTokenValidAsync(tokens)).Should().BeTrue();\n\n        var result = await _mockPipeline.BackChannelClient.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = IdentityServerPipeline.RevocationEndpoint,\n            ClientId = client_id,\n            ClientSecret = client_secret,\n\n            Token = tokens.AccessToken\n        });\n\n        result.IsError.Should().BeFalse();\n\n        (await IsAccessTokenValidAsync(tokens)).Should().BeFalse();\n\n        result = await _mockPipeline.BackChannelClient.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = IdentityServerPipeline.RevocationEndpoint,\n            ClientId = client_id,\n            ClientSecret = client_secret,\n\n            Token = tokens.AccessToken\n        });\n\n        result.IsError.Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Revoke_invalid_refresh_token_should_return_success()\n    {\n        var tokens = await GetTokensAsync();\n        (await UseRefreshTokenAsync(tokens)).Should().BeTrue();\n\n        var result = await _mockPipeline.BackChannelClient.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = IdentityServerPipeline.RevocationEndpoint,\n            ClientId = client_id,\n            ClientSecret = client_secret,\n\n            Token = tokens.RefreshToken\n        });\n\n        result.IsError.Should().BeFalse();\n\n        (await UseRefreshTokenAsync(tokens)).Should().BeFalse();\n\n        result = await _mockPipeline.BackChannelClient.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = IdentityServerPipeline.RevocationEndpoint,\n            ClientId = client_id,\n            ClientSecret = client_secret,\n\n            Token = tokens.RefreshToken\n        });\n\n        result.IsError.Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Invalid_client_id_should_return_error()\n    {\n        var tokens = await GetTokensAsync();\n        (await IsAccessTokenValidAsync(tokens)).Should().BeTrue();\n\n        var result = await _mockPipeline.BackChannelClient.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = IdentityServerPipeline.RevocationEndpoint,\n            ClientId = \"not_valid\",\n            ClientSecret = client_secret,\n\n            Token = tokens.AccessToken\n        });\n\n        result.IsError.Should().BeTrue();\n        result.Error.Should().Be(\"invalid_client\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Invalid_credentials_should_return_error()\n    {\n        var tokens = await GetTokensAsync();\n        (await IsAccessTokenValidAsync(tokens)).Should().BeTrue();\n\n        var result = await _mockPipeline.BackChannelClient.RevokeTokenAsync(new TokenRevocationRequest\n        {\n            Address = IdentityServerPipeline.RevocationEndpoint,\n            ClientId = client_id,\n            ClientSecret = \"not_valid\",\n\n            Token = tokens.AccessToken\n        });\n\n        result.IsError.Should().BeTrue();\n        result.Error.Should().Be(\"invalid_client\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Missing_token_should_return_error()\n    {\n        var data = new Dictionary<string, string>\n        {\n            { \"client_id\", client_id },\n            { \"client_secret\", client_secret }\n        };\n\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.RevocationEndpoint, new FormUrlEncodedContent(data));\n        response.StatusCode.Should().Be(HttpStatusCode.BadRequest);\n\n        var result = await ProtocolResponse.FromHttpResponseAsync<TokenRevocationResponse>(response);\n        result.IsError.Should().BeTrue();\n        result.Error.Should().Be(\"invalid_request\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Invalid_token_type_hint_should_return_error()\n    {\n        var tokens = await GetTokensAsync();\n        (await IsAccessTokenValidAsync(tokens)).Should().BeTrue();\n\n        var data = new Dictionary<string, string>\n        {\n            { \"client_id\", client_id },\n            { \"client_secret\", client_secret },\n            { \"token\", tokens.AccessToken },\n            { \"token_type_hint\", \"not_valid\" }\n        };\n\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.RevocationEndpoint, new FormUrlEncodedContent(data));\n        response.StatusCode.Should().Be(HttpStatusCode.BadRequest);\n\n        var result = await ProtocolResponse.FromHttpResponseAsync<TokenRevocationResponse>(response);\n        result.IsError.Should().BeTrue();\n        result.Error.Should().Be(\"unsupported_token_type\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Valid_access_token_but_missing_token_type_hint_should_succeed()\n    {\n        var tokens = await GetTokensAsync();\n        (await IsAccessTokenValidAsync(tokens)).Should().BeTrue();\n\n        var data = new Dictionary<string, string>\n        {\n            { \"client_id\", client_id },\n            { \"client_secret\", client_secret },\n            { \"token\", tokens.AccessToken }\n        };\n\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.RevocationEndpoint, new FormUrlEncodedContent(data));\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n\n        (await IsAccessTokenValidAsync(tokens)).Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Valid_refresh_token_but_missing_token_type_hint_should_succeed()\n    {\n        var tokens = await GetTokensAsync();\n        (await UseRefreshTokenAsync(tokens)).Should().BeTrue();\n\n        var data = new Dictionary<string, string>\n        {\n            { \"client_id\", client_id },\n            { \"client_secret\", client_secret },\n            { \"token\", tokens.RefreshToken }\n        };\n\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.RevocationEndpoint, new FormUrlEncodedContent(data));\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n\n        (await UseRefreshTokenAsync(tokens)).Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Implicit_client_without_secret_revoking_token_should_succeed()\n    {\n        var token = await GetAccessTokenForImplicitClientAsync(\"implicit\");\n\n        var data = new Dictionary<string, string>\n        {\n            { \"client_id\", \"implicit\" },\n            { \"token\", token }\n        };\n\n        (await IsAccessTokenValidAsync(token)).Should().BeTrue();\n\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.RevocationEndpoint, new FormUrlEncodedContent(data));\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n        (await IsAccessTokenValidAsync(token)).Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task Implicit_and_client_creds_client_without_secret_revoking_token_should_fail()\n    {\n        var token = await GetAccessTokenForImplicitClientAsync(\"implicit_and_client_creds\");\n\n        var data = new Dictionary<string, string>\n        {\n            { \"client_id\", \"implicit_and_client_creds\" },\n            { \"token\", token }\n        };\n\n        (await IsAccessTokenValidAsync(token)).Should().BeTrue();\n\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.RevocationEndpoint, new FormUrlEncodedContent(data));\n        response.StatusCode.Should().Be(HttpStatusCode.BadRequest);\n        (await IsAccessTokenValidAsync(token)).Should().BeTrue();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Endpoints/Token/TokenEndpointTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Newtonsoft.Json.Linq;\nusing System.Collections.Generic;\nusing System.Net;\nusing System.Net.Http;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing IdentityServer.IntegrationTests.Common;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Endpoints.Token;\n\npublic class TokenEndpointTests\n{\n    private const string Category = \"Token endpoint\";\n\n    private string client_id = \"client\";\n    private string client_secret = \"secret\";\n\n    private string scope_name = \"api\";\n    private string scope_secret = \"api_secret\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    public TokenEndpointTests()\n    {\n        _mockPipeline.Clients.Add(new Client\n        {\n            ClientId = client_id,\n            ClientSecrets = new List<Secret> { new Secret(client_secret.Sha256()) },\n            AllowedGrantTypes = { GrantType.ClientCredentials, GrantType.ResourceOwnerPassword },\n            AllowedScopes = new List<string> { \"api\" },\n        });\n\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Password = \"password\",\n            Claims = new Claim[]\n            {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n            }\n        });\n\n        _mockPipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId()\n        });\n\n        _mockPipeline.ApiResources.AddRange(new ApiResource[] {\n            new ApiResource\n            {\n                Name = \"api\",\n                ApiSecrets = new List<Secret> { new Secret(scope_secret.Sha256()) },\n                Scopes = {scope_name}\n            }\n        });\n\n        _mockPipeline.ApiScopes.AddRange(new[] {\n            new ApiScope\n            {\n                Name = scope_name\n            }\n        });\n\n        _mockPipeline.Initialize();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task client_credentials_request_with_funny_headers_should_not_hang()\n    {\n        var data = new Dictionary<string, string>\n        {\n            { \"grant_type\", \"client_credentials\" },\n            { \"client_id\", client_id },\n            { \"client_secret\", client_secret },\n            { \"scope\", scope_name },\n        };\n        var form = new FormUrlEncodedContent(data);\n        _mockPipeline.BackChannelClient.DefaultRequestHeaders.Add(\"Referer\", \"http://127.0.0.1:33086/appservice/appservice?t=1564165664142?load\");\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.TokenEndpoint, form);\n\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n        var json = await response.Content.ReadAsStringAsync();\n        var result = JObject.Parse(json);\n        result.ContainsKey(\"error\").Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task resource_owner_request_with_funny_headers_should_not_hang()\n    {\n        var data = new Dictionary<string, string>\n        {\n            { \"grant_type\", \"password\" },\n            { \"username\", \"bob\" },\n            { \"password\", \"password\" },\n            { \"client_id\", client_id },\n            { \"client_secret\", client_secret },\n            { \"scope\", scope_name },\n        };\n        var form = new FormUrlEncodedContent(data);\n        _mockPipeline.BackChannelClient.DefaultRequestHeaders.Add(\"Referer\", \"http://127.0.0.1:33086/appservice/appservice?t=1564165664142?load\");\n        var response = await _mockPipeline.BackChannelClient.PostAsync(IdentityServerPipeline.TokenEndpoint, form);\n\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n        var json = await response.Content.ReadAsStringAsync();\n        var result = JObject.Parse(json);\n        result.ContainsKey(\"error\").Should().BeFalse();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Extensibility/CustomProfileServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Net;\nusing System.Security.Claims;\nusing System.Text;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing Microsoft.Extensions.DependencyInjection;\nusing Newtonsoft.Json.Linq;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Extensibility;\n\npublic class CustomProfileServiceTests\n{\n    private const string Category = \"Authorize endpoint\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    public CustomProfileServiceTests()\n    {\n        _mockPipeline.OnPostConfigureServices += svcs =>\n        {\n            svcs.AddTransient<IProfileService, CustomProfileService>();\n        };\n\n        _mockPipeline.Clients.Add(new Client\n        {\n            ClientId = \"implicit\",\n            AllowedGrantTypes = GrantTypes.Implicit,\n            RedirectUris = { \"https://client/callback\" },\n            RequireConsent = false,\n            AllowedScopes = { \"openid\", \"custom_identity\" }\n        });\n\n        _mockPipeline.IdentityScopes.Add(new IdentityResources.OpenId());\n        _mockPipeline.IdentityScopes.Add(new IdentityResource(\"custom_identity\", new string[] { \"foo\" }));\n\n        _mockPipeline.Users.Add(new IdentityServer8.Test.TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Password = \"password\",\n        });\n\n        _mockPipeline.Initialize();\n    }\n\n    [Fact]\n    public async Task custom_profile_should_return_claims_for_implicit_client()\n    {\n        await _mockPipeline.LoginAsync(\"bob\");\n\n        var url = _mockPipeline.CreateAuthorizeUrl(\n            clientId: \"implicit\",\n            responseType: \"id_token\",\n            scope: \"openid custom_identity\",\n            redirectUri: \"https://client/callback\",\n            state: \"state\",\n            nonce: \"nonce\");\n\n        _mockPipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Headers.Location.ToString().Should().StartWith(\"https://client/callback\");\n\n        var authorization = new IdentityModel.Client.AuthorizeResponse(response.Headers.Location.ToString());\n        authorization.IsError.Should().BeFalse();\n        authorization.IdentityToken.Should().NotBeNull();\n\n        var payload = authorization.IdentityToken.Split('.')[1];\n        var json = Encoding.UTF8.GetString(Base64Url.Decode(payload));\n        var obj = JObject.Parse(json);\n\n        obj.GetValue(\"foo\").Should().NotBeNull();\n        obj[\"foo\"].ToString().Should().Be(\"bar\");\n    }\n}\n\npublic class CustomProfileService : IProfileService\n{\n    public Task GetProfileDataAsync(ProfileDataRequestContext context)\n    {\n        var claims = new Claim[]\n        {\n            new Claim(\"foo\", \"bar\")\n        };\n        context.AddRequestedClaims(claims);\n        return Task.CompletedTask;\n    }\n\n    public Task IsActiveAsync(IsActiveContext context)\n    {\n        context.IsActive = true;\n        return Task.CompletedTask;\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/IdentityServer.IntegrationTests.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n  <PropertyGroup>\n    <AssemblyOriginatorKeyFile>../../../../key.snk</AssemblyOriginatorKeyFile>\n    <SignAssembly>true</SignAssembly>\n    <PublicSign Condition=\"'$(OS)' != 'Windows_NT'\">true</PublicSign>\n  </PropertyGroup>\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.NET.Test.Sdk\" />\n    <PackageReference Include=\"Microsoft.AspNetCore.TestHost\" />\n    <PackageReference Include=\"System.IdentityModel.Tokens.Jwt\" />\n    \n    <PackageReference Include=\"xunit\" />\n    <PackageReference Include=\"xunit.runner.visualstudio\" PrivateAssets=\"All\" />\n    <PackageReference Include=\"FluentAssertions\" />\n    <PackageReference Include=\"coverlet.collector\" GeneratePathProperty=\"true\">\n        <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n        <PrivateAssets>all</PrivateAssets>\n    </PackageReference>     \n  </ItemGroup>\n\n  <ItemGroup>\n    <None Update=\"identityserver_testing.cer\">\n      <CopyToOutputDirectory>Always</CopyToOutputDirectory>\n    </None>\n    <None Update=\"identityserver_testing.pfx\">\n      <CopyToOutputDirectory>Always</CopyToOutputDirectory>\n    </None>\n    <None Update=\"xunit.runner.json\">\n      <CopyToOutputDirectory>PreserveNewest</CopyToOutputDirectory>\n    </None>\n  </ItemGroup>\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\..\\src\\IdentityServer8.csproj\" />\n  </ItemGroup>\n\n</Project>"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Pipeline/CorsTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Net;\nusing System.Net.Http;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Test;\nusing Microsoft.Extensions.DependencyInjection;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Pipeline;\n\npublic class CorsTests\n{\n    private const string Category = \"CORS Integration\";\n\n    private IdentityServerPipeline _pipeline = new IdentityServerPipeline();\n\n    public CorsTests()\n    {\n        _pipeline.Clients.AddRange(new Client[] {\n            new Client\n            {\n                ClientId = \"client\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = true,\n                AllowedScopes = new List<string> { \"openid\", \"profile\", \"api1\", \"api2\" },\n                RedirectUris = new List<string> { \"https://client/callback\" },\n                AllowedCorsOrigins = new List<string> { \"https://client\" }\n            }\n        });\n\n        _pipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n            {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n            }\n        });\n\n        _pipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n            new IdentityResources.Email()\n        });\n        _pipeline.ApiResources.AddRange(new ApiResource[] {\n            new ApiResource\n            {\n                Name = \"api\",\n                Scopes = { \"api1\", \"api2\" }\n            }\n        });\n        _pipeline.ApiScopes.AddRange(new[] {\n            new ApiScope\n            {\n                Name = \"api1\"\n            },\n            new ApiScope\n            {\n                Name = \"api2\"\n            }\n        });\n\n        _pipeline.Initialize();\n    }\n\n    [Theory]\n    [InlineData(IdentityServerPipeline.DiscoveryEndpoint)]\n    [InlineData(IdentityServerPipeline.DiscoveryKeysEndpoint)]\n    [InlineData(IdentityServerPipeline.TokenEndpoint)]\n    [InlineData(IdentityServerPipeline.UserInfoEndpoint)]\n    [InlineData(IdentityServerPipeline.RevocationEndpoint)]\n    [Trait(\"Category\", Category)]\n    public async Task cors_request_to_allowed_endpoints_should_succeed(string url)\n    {\n        _pipeline.BackChannelClient.DefaultRequestHeaders.Add(\"Origin\", \"https://client\");\n        _pipeline.BackChannelClient.DefaultRequestHeaders.Add(\"Access-Control-Request-Method\", \"GET\");\n        \n        var message = new HttpRequestMessage(HttpMethod.Options, url);\n        var response = await _pipeline.BackChannelClient.SendAsync(message);\n\n        response.StatusCode.Should().Be(HttpStatusCode.NoContent);\n        response.Headers.Contains(\"Access-Control-Allow-Origin\").Should().BeTrue();\n    }\n\n    [Theory]\n    [InlineData(IdentityServerPipeline.AuthorizeEndpoint)]\n    [InlineData(IdentityServerPipeline.EndSessionEndpoint)]\n    [InlineData(IdentityServerPipeline.CheckSessionEndpoint)]\n    [InlineData(IdentityServerPipeline.LoginPage)]\n    [InlineData(IdentityServerPipeline.ConsentPage)]\n    [InlineData(IdentityServerPipeline.ErrorPage)]\n    [Trait(\"Category\", Category)]\n    public async Task cors_request_to_restricted_endpoints_should_not_succeed(string url)\n    {\n        _pipeline.BackChannelClient.DefaultRequestHeaders.Add(\"Origin\", \"https://client\");\n        _pipeline.BackChannelClient.DefaultRequestHeaders.Add(\"Access-Control-Request-Method\", \"GET\");\n\n        var message = new HttpRequestMessage(HttpMethod.Options, url);\n        var response = await _pipeline.BackChannelClient.SendAsync(message);\n\n        response.Headers.Contains(\"Access-Control-Allow-Origin\").Should().BeFalse();\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task custom_cors_policy_provider_should_be_used()\n    {\n        var policy = new StubCorePolicyProvider();\n        _pipeline.OnPreConfigureServices += services =>\n        {\n            services.AddSingleton<ICorsPolicyService>(policy);\n        };\n        _pipeline.Initialize();\n\n        _pipeline.BackChannelClient.DefaultRequestHeaders.Add(\"Origin\", \"https://client\");\n        _pipeline.BackChannelClient.DefaultRequestHeaders.Add(\"Access-Control-Request-Method\", \"GET\");\n\n        var message = new HttpRequestMessage(HttpMethod.Options, IdentityServerPipeline.DiscoveryEndpoint);\n        var response = await _pipeline.BackChannelClient.SendAsync(message);\n\n        policy.WasCalled.Should().BeTrue();\n    }\n}\n\npublic class StubCorePolicyProvider : ICorsPolicyService\n{\n    public bool Result;\n    public bool WasCalled;\n\n    public Task<bool> IsOriginAllowedAsync(string origin)\n    {\n        WasCalled = true;\n        return Task.FromResult(Result);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Pipeline/FederatedSignoutTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Net;\nusing System.Net.Http;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Microsoft.AspNetCore.Authentication;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Pipeline;\n\npublic class FederatedSignoutTests\n{\n    private const string Category = \"Federated Signout\";\n\n    private IdentityServerPipeline _pipeline = new IdentityServerPipeline();\n    private ClaimsPrincipal _user;\n\n    public FederatedSignoutTests()\n    {\n        _user = new IdentityServerUser(\"bob\")\n        {\n            AdditionalClaims = { new Claim(JwtClaimTypes.SessionId, \"123\") }\n        }.CreatePrincipal();\n\n        _pipeline = new IdentityServerPipeline();\n\n        _pipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId()\n        });\n\n        _pipeline.Clients.Add(new Client\n        {\n            ClientId = \"client1\",\n            AllowedGrantTypes = GrantTypes.Implicit,\n            RequireConsent = false,\n            AllowedScopes = new List<string> { \"openid\" },\n            RedirectUris = new List<string> { \"https://client1/callback\" },\n            FrontChannelLogoutUri = \"https://client1/signout\",\n            PostLogoutRedirectUris = new List<string> { \"https://client1/signout-callback\" },\n            AllowAccessTokensViaBrowser = true\n        });\n\n        _pipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n           {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n           }\n        });\n\n        _pipeline.Initialize();\n    }\n\n    [Fact]\n    public async Task valid_request_to_federated_signout_endpoint_should_render_page_with_iframe()\n    {\n        await _pipeline.LoginAsync(_user);\n\n        await _pipeline.RequestAuthorizationEndpointAsync(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        var response = await _pipeline.BrowserClient.GetAsync(IdentityServerPipeline.FederatedSignOutUrl + \"?sid=123\");\n\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n        response.Content.Headers.ContentType.MediaType.Should().Be(\"text/html\");\n        var html = await response.Content.ReadAsStringAsync();\n        html.Should().Contain(\"https://server/connect/endsession/callback?endSessionId=\");\n    }\n\n    [Fact]\n    public async Task valid_POST_request_to_federated_signout_endpoint_should_render_page_with_iframe()\n    {\n        await _pipeline.LoginAsync(_user);\n\n        await _pipeline.RequestAuthorizationEndpointAsync(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        var response = await _pipeline.BrowserClient.PostAsync(IdentityServerPipeline.FederatedSignOutUrl, new FormUrlEncodedContent(new Dictionary<string, string> { { \"sid\", \"123\" } }));\n\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n        response.Content.Headers.ContentType.MediaType.Should().Be(\"text/html\");\n        var html = await response.Content.ReadAsStringAsync();\n        html.Should().Contain(\"https://server/connect/endsession/callback?endSessionId=\");\n    }\n\n    [Fact]\n    public async Task no_clients_signed_into_should_not_render_page_with_iframe()\n    {\n        await _pipeline.LoginAsync(_user);\n\n        var response = await _pipeline.BrowserClient.GetAsync(IdentityServerPipeline.FederatedSignOutUrl + \"?sid=123\");\n\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n        response.Content.Headers.ContentType.Should().BeNull();\n        var html = await response.Content.ReadAsStringAsync();\n        html.Should().Be(String.Empty);\n    }\n\n    [Fact]\n    public async Task no_authenticated_user_should_not_render_page_with_iframe()\n    {\n        var response = await _pipeline.BrowserClient.GetAsync(IdentityServerPipeline.FederatedSignOutUrl + \"?sid=123\");\n\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n        response.Content.Headers.ContentType.Should().BeNull();\n        var html = await response.Content.ReadAsStringAsync();\n        html.Should().Be(String.Empty);\n    }\n\n    [Fact]\n    public async Task user_not_signed_out_should_not_render_page_with_iframe()\n    {\n        _pipeline.OnFederatedSignout = ctx =>\n        {\n            return Task.FromResult(true);\n        };\n\n        await _pipeline.LoginAsync(_user);\n\n        await _pipeline.RequestAuthorizationEndpointAsync(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        var response = await _pipeline.BrowserClient.GetAsync(IdentityServerPipeline.FederatedSignOutUrl + \"?sid=123\");\n\n        response.StatusCode.Should().Be(HttpStatusCode.OK);\n        response.Content.Headers.ContentType.Should().BeNull();\n        var html = await response.Content.ReadAsStringAsync();\n        html.Should().Be(String.Empty);\n    }\n\n    [Fact]\n    public async Task non_200_should_not_render_page_with_iframe()\n    {\n        _pipeline.OnFederatedSignout = async ctx =>\n        {\n            await ctx.SignOutAsync(); // even if we signout, we should not see iframes\n            ctx.Response.Redirect(\"http://foo\");\n            return true;\n        };\n\n        await _pipeline.LoginAsync(_user);\n\n        await _pipeline.RequestAuthorizationEndpointAsync(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n\n        _pipeline.BrowserClient.AllowAutoRedirect = false;\n        var response = await _pipeline.BrowserClient.GetAsync(IdentityServerPipeline.FederatedSignOutUrl + \"?sid=123\");\n\n        response.StatusCode.Should().Be(HttpStatusCode.Redirect);\n        response.Content.Headers.ContentType.Should().BeNull();\n        var html = await response.Content.ReadAsStringAsync();\n        html.Should().Be(String.Empty);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/Pipeline/SubpathHosting.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel.Client;\nusing IdentityServer.IntegrationTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Test;\nusing Xunit;\n\nnamespace IdentityServer.IntegrationTests.Pipeline;\n\npublic class SubpathHosting\n{\n    private const string Category = \"Subpath endpoint\";\n\n    private IdentityServerPipeline _mockPipeline = new IdentityServerPipeline();\n\n    private Client _client1;\n\n    public SubpathHosting()\n    {\n        _mockPipeline.Clients.AddRange(new Client[] {\n            _client1 = new Client\n            {\n                ClientId = \"client1\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RequireConsent = false,\n                AllowedScopes = new List<string> { \"openid\", \"profile\" },\n                RedirectUris = new List<string> { \"https://client1/callback\" },\n                AllowAccessTokensViaBrowser = true\n            }\n        });\n\n        _mockPipeline.Users.Add(new TestUser\n        {\n            SubjectId = \"bob\",\n            Username = \"bob\",\n            Claims = new Claim[]\n            {\n                new Claim(\"name\", \"Bob Loblaw\"),\n                new Claim(\"email\", \"bob@loblaw.com\"),\n                new Claim(\"role\", \"Attorney\")\n            }\n        });\n\n        _mockPipeline.IdentityScopes.AddRange(new IdentityResource[] {\n            new IdentityResources.OpenId(),\n            new IdentityResources.Profile(),\n            new IdentityResources.Email()\n        });\n        \n        _mockPipeline.Initialize(\"/subpath\");\n    }\n\n    [Fact]\n    [Trait(\"Category\", Category)]\n    public async Task anonymous_user_should_be_redirected_to_login_page()\n    {\n        var url = new RequestUrl(\"https://server/subpath/connect/authorize\").CreateAuthorizeUrl(\n            clientId: \"client1\",\n            responseType: \"id_token\",\n            scope: \"openid\",\n            redirectUri: \"https://client1/callback\",\n            state: \"123_state\",\n            nonce: \"123_nonce\");\n        var response = await _mockPipeline.BrowserClient.GetAsync(url);\n\n        _mockPipeline.LoginWasCalled.Should().BeTrue();\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/identityserver_testing.cer",
    "content": "-----BEGIN CERTIFICATE-----\nMIIDQTCCAimgAwIBAgIQO+9qzaJY9I5Ewq81kNEKWTANBgkqhkiG9w0BAQsFADAh\nMR8wHQYDVQQDDBZpZGVudGl0eXNlcnZlcl90ZXN0aW5nMCAXDTIwMDEyMjIzMTYz\nOFoYDzIxMDMwNTIyMjMyNjM5WjAhMR8wHQYDVQQDDBZpZGVudGl0eXNlcnZlcl90\nZXN0aW5nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuyZQvE+6gEoB\na+LV3dxjk/Xj4DRJ/tefQKR2AZoYAAfKN4ditFmEfRC1A6rckBpMVihTeb1kwwQT\n7H4HTS6O/ERHVjOdghoOjEsVakWhAkvh8gphC4IU0upXlYqMh2WzgXEXwYRFB9Tk\n7zoHb1/zjEEAhCf2Xbi6YslBoU71bFWyAaeOTl859wV6WaiBIK5L8nJUaIaq4zmC\nk8caPZq5E867mZiMdL4TcW9/YoAAO96Wa/W9o6OiuZrP414TlEjVuccpLXvjk0hB\nU5OZD2bTvD3MQZu1n1QMLwXfaOBrcv1/RqYJkK7vpP6Pp1YYlo7b2PBDVAIrRSVT\nlaViBP0owQIDAQABo3MwcTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYB\nBQUHAwIGCCsGAQUFBwMBMCEGA1UdEQQaMBiCFmlkZW50aXR5c2VydmVyX3Rlc3Rp\nbmcwHQYDVR0OBBYEFCVXNpKp8QlHywXEBFfpXxWcOMcsMA0GCSqGSIb3DQEBCwUA\nA4IBAQBsEAzwyN6V6N5ggN9G1O0ZpviSjixGkWtySNCBjbGXAhOvfW4M3ysNkDwZ\nltk/Q17ihZzw135MrDCmnr5pRiN4CbEGbe1qsb+Z0uCCn8/WcIVYYooW66H/Jez+\ndg5RxUukA67ZDnjzRskIer7L2t1C4pDqpvPVcneUxkiYDSgcKpTuCVjkPNQKQTIw\nSm98NkQG8G8V8+ENIU837ytkiC5nqQa4zDRHexzWrYhiuayWWxJKcNRVF9YaE8ts\nvp5N1ewmWbSgF8caJuKraVOISj9R4iqf0XuhfSpW/7eIWYmXfqy/UloeqlALfP5C\n2d2FdDSfsQ4Jgc3ebrECAQaCC3Gq\n-----END CERTIFICATE-----\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.IntegrationTests/xunit.runner.json",
    "content": "﻿{\n  \"methodDisplay\":\"classAndMethod\"\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/IAuthenticationSchemeHandler.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal interface IAuthenticationSchemeHandler\n    {\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockAuthenticationHandler.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing Microsoft.AspNetCore.Authentication;\nusing Microsoft.AspNetCore.Http;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal class MockAuthenticationHandler : IAuthenticationHandler\n    {\n        public AuthenticateResult Result { get; set; } = AuthenticateResult.NoResult();\n\n        public Task<AuthenticateResult> AuthenticateAsync()\n        {\n            return Task.FromResult(Result);\n        }\n\n        public Task ChallengeAsync(AuthenticationProperties properties)\n        {\n            return Task.CompletedTask;\n        }\n\n        public Task ForbidAsync(AuthenticationProperties properties)\n        {\n            return Task.CompletedTask;\n        }\n\n        public Task InitializeAsync(AuthenticationScheme scheme, HttpContext context)\n        {\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockAuthenticationHandlerProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing Microsoft.AspNetCore.Authentication;\nusing Microsoft.AspNetCore.Http;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal class MockAuthenticationHandlerProvider : IAuthenticationHandlerProvider\n    {\n        public IAuthenticationHandler Handler { get; set; }\n\n        public Task<IAuthenticationHandler> GetHandlerAsync(HttpContext context, string authenticationScheme)\n        {\n            return Task.FromResult(Handler);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockAuthenticationSchemeProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing Microsoft.AspNetCore.Authentication;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal class MockAuthenticationSchemeProvider : IAuthenticationSchemeProvider\n    {\n        public string Default { get; set; } = \"scheme\";\n        public List<AuthenticationScheme> Schemes { get; set; } = new List<AuthenticationScheme>()\n        {\n            new AuthenticationScheme(\"scheme\", null, typeof(MockAuthenticationHandler))\n        };\n\n        public void AddScheme(AuthenticationScheme scheme)\n        {\n            Schemes.Add(scheme);\n        }\n\n        public Task<IEnumerable<AuthenticationScheme>> GetAllSchemesAsync()\n        {\n            return Task.FromResult(Schemes.AsEnumerable());\n        }\n\n        public Task<AuthenticationScheme> GetDefaultAuthenticateSchemeAsync()\n        {\n            var scheme = Schemes.Where(x => x.Name == Default).FirstOrDefault();\n            return Task.FromResult(scheme);\n        }\n\n        public Task<AuthenticationScheme> GetDefaultChallengeSchemeAsync()\n        {\n            return GetDefaultAuthenticateSchemeAsync();\n        }\n\n        public Task<AuthenticationScheme> GetDefaultForbidSchemeAsync()\n        {\n            return GetDefaultAuthenticateSchemeAsync();\n        }\n\n        public Task<AuthenticationScheme> GetDefaultSignInSchemeAsync()\n        {\n            return GetDefaultAuthenticateSchemeAsync();\n        }\n\n        public Task<AuthenticationScheme> GetDefaultSignOutSchemeAsync()\n        {\n            return GetDefaultAuthenticateSchemeAsync();\n        }\n\n        public Task<IEnumerable<AuthenticationScheme>> GetRequestHandlerSchemesAsync()\n        {\n            return Task.FromResult(Schemes.AsEnumerable());\n        }\n\n        public Task<AuthenticationScheme> GetSchemeAsync(string name)\n        {\n            return Task.FromResult(Schemes.Where(x => x.Name == name).FirstOrDefault());\n        }\n\n        public void RemoveScheme(string name)\n        {\n            var scheme = Schemes.Where(x => x.Name == name).FirstOrDefault();\n            if (scheme != null)\n            {\n                Schemes.Remove(scheme);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockAuthenticationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing Microsoft.AspNetCore.Authentication;\nusing Microsoft.AspNetCore.Http;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal class MockAuthenticationService : IAuthenticationService\n    {\n        public AuthenticateResult Result { get; set; }\n\n        public Task<AuthenticateResult> AuthenticateAsync(HttpContext context, string scheme)\n        {\n            return Task.FromResult(Result);\n        }\n\n        public Task ChallengeAsync(HttpContext context, string scheme, AuthenticationProperties properties)\n        {\n            return Task.CompletedTask;\n        }\n\n        public Task ForbidAsync(HttpContext context, string scheme, AuthenticationProperties properties)\n        {\n            return Task.CompletedTask;\n        }\n\n        public Task SignInAsync(HttpContext context, string scheme, ClaimsPrincipal principal, AuthenticationProperties properties)\n        {\n            return Task.CompletedTask;\n        }\n\n        public Task SignOutAsync(HttpContext context, string scheme, AuthenticationProperties properties)\n        {\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockClaimsService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Services;\nusing IdentityServer8.Validation;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    class MockClaimsService : IClaimsService\n    {\n        public List<Claim> IdentityTokenClaims { get; set; } = new List<Claim>();\n        public List<Claim> AccessTokenClaims { get; set; } = new List<Claim>();\n\n        public Task<IEnumerable<Claim>> GetIdentityTokenClaimsAsync(ClaimsPrincipal subject, ResourceValidationResult resources, bool includeAllIdentityClaims, ValidatedRequest request)\n        {\n            return Task.FromResult(IdentityTokenClaims.AsEnumerable());\n        }\n\n        public Task<IEnumerable<Claim>> GetAccessTokenClaimsAsync(ClaimsPrincipal subject, ResourceValidationResult resources, ValidatedRequest request)\n        {\n            return Task.FromResult(AccessTokenClaims.AsEnumerable());\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockClientSessionService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer.UnitTests.Common\n{\n    //class MockClientSessionService : IClientSessionService\n    //{\n    //    public List<string> Clients = new List<string>();\n\n    //    public bool RemoveCookieWasCalled { get; private set; }\n\n    //    public Task AddClientIdAsync(string clientId)\n    //    {\n    //        Clients.Add(clientId);\n    //        return Task.CompletedTask;\n    //    }\n\n    //    public Task EnsureClientListCookieAsync(string sid)\n    //    {\n    //        return Task.CompletedTask;\n    //    }\n\n    //    public Task<IEnumerable<string>> GetClientListAsync()\n    //    {\n    //        return Task.FromResult<IEnumerable<string>>(Clients);\n    //    }\n\n    //    public IEnumerable<string> GetClientListFromCookie(string sid)\n    //    {\n    //        return Clients;\n    //    }\n\n    //    public void RemoveCookie(string sid)\n    //    {\n    //        RemoveCookieWasCalled = true;\n    //        Clients.Clear();\n    //    }\n    //}\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockConsentMessageStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class MockConsentMessageStore : IConsentMessageStore\n    {\n        public Dictionary<string, Message<ConsentResponse>> Messages { get; set; } = new Dictionary<string, Message<ConsentResponse>>();\n\n        public Task DeleteAsync(string id)\n        {\n            if (id != null && Messages.ContainsKey(id))\n            {\n                Messages.Remove(id);\n            }\n            return Task.CompletedTask;\n        }\n\n        public Task<Message<ConsentResponse>> ReadAsync(string id)\n        {\n            Message<ConsentResponse> val = null;\n            if (id != null)\n            {\n                Messages.TryGetValue(id, out val);\n            }\n            return Task.FromResult(val);\n        }\n\n        public Task WriteAsync(string id, Message<ConsentResponse> message)\n        {\n            Messages[id] = message;\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockConsentService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class MockConsentService : IConsentService\n    {\n        public bool RequiresConsentResult { get; set; }\n\n        public Task<bool> RequiresConsentAsync(ClaimsPrincipal subject, Client client, IEnumerable<ParsedScopeValue> parsedScopes)\n        {\n            return Task.FromResult(RequiresConsentResult);\n        }\n\n        public ClaimsPrincipal ConsentSubject { get; set; }\n        public Client ConsentClient { get; set; }\n        public IEnumerable<string> ConsentScopes { get; set; }\n\n        public Task UpdateConsentAsync(ClaimsPrincipal subject, Client client, IEnumerable<ParsedScopeValue> parsedScopes)\n        {\n            ConsentSubject = subject;\n            ConsentClient = client;\n            ConsentScopes = parsedScopes?.Select(x => x.RawValue);\n\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockHttpContextAccessor.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Stores;\nusing Microsoft.AspNetCore.Authentication;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.Extensions.DependencyInjection;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal class MockHttpContextAccessor : IHttpContextAccessor\n    {\n        private HttpContext _context = new DefaultHttpContext();\n        public MockAuthenticationService AuthenticationService { get; set; } = new MockAuthenticationService();\n\n        public MockAuthenticationSchemeProvider Schemes { get; set; } = new MockAuthenticationSchemeProvider();\n\n        public MockHttpContextAccessor(\n            IdentityServerOptions options = null,\n            IUserSession userSession = null,\n            IMessageStore<LogoutNotificationContext> endSessionStore = null)\n        {\n            options = options ?? TestIdentityServerOptions.Create();\n\n            var services = new ServiceCollection();\n            services.AddSingleton(options);\n\n            services.AddSingleton<IAuthenticationSchemeProvider>(Schemes);\n            services.AddSingleton<IAuthenticationService>(AuthenticationService);\n\n            services.AddAuthentication(auth =>\n            {\n                auth.DefaultAuthenticateScheme = Schemes.Default;\n            });\n\n            if (userSession == null)\n            {\n                services.AddScoped<IUserSession, DefaultUserSession>();\n            }\n            else\n            {\n                services.AddSingleton(userSession);\n            }\n\n            if (endSessionStore == null)\n            {\n                services.AddTransient<IMessageStore<LogoutNotificationContext>, ProtectedDataMessageStore<LogoutNotificationContext>>();\n            }\n            else\n            {\n                services.AddSingleton(endSessionStore);\n            }\n\n            _context.RequestServices = services.BuildServiceProvider();\n        }\n\n        public HttpContext HttpContext\n        {\n            get\n            {\n                return _context;\n            }\n\n            set\n            {\n                _context = value;\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockKeyMaterialService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing Microsoft.IdentityModel.Tokens;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    class MockKeyMaterialService : IKeyMaterialService\n    {\n        public List<SigningCredentials> SigningCredentials = new List<SigningCredentials>();\n        public List<SecurityKeyInfo> ValidationKeys = new List<SecurityKeyInfo>();\n\n        public Task<IEnumerable<SigningCredentials>> GetAllSigningCredentialsAsync()\n        {\n            return Task.FromResult(SigningCredentials.AsEnumerable());\n        }\n\n        public Task<SigningCredentials> GetSigningCredentialsAsync(IEnumerable<string> allowedAlgorithms = null)\n        {\n            return Task.FromResult(SigningCredentials.FirstOrDefault());\n        }\n\n        public Task<IEnumerable<SecurityKeyInfo>> GetValidationKeysAsync()\n        {\n            return Task.FromResult(ValidationKeys.AsEnumerable());\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockLogoutNotificationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class MockLogoutNotificationService : ILogoutNotificationService\n    {\n        public bool GetFrontChannelLogoutNotificationsUrlsCalled { get; set; }\n        public List<string> FrontChannelLogoutNotificationsUrls { get; set; } = new List<string>();\n\n        public bool SendBackChannelLogoutNotificationsCalled { get; set; }\n        public List<BackChannelLogoutRequest> BackChannelLogoutRequests { get; set; } = new List<BackChannelLogoutRequest>();\n\n        public Task<IEnumerable<string>> GetFrontChannelLogoutNotificationsUrlsAsync(LogoutNotificationContext context)\n        {\n            GetFrontChannelLogoutNotificationsUrlsCalled = true;\n            return Task.FromResult(FrontChannelLogoutNotificationsUrls.AsEnumerable());\n        }\n\n        public Task<IEnumerable<BackChannelLogoutRequest>> GetBackChannelLogoutNotificationsAsync(LogoutNotificationContext context)\n        {\n            SendBackChannelLogoutNotificationsCalled = true;\n            return Task.FromResult(BackChannelLogoutRequests.AsEnumerable());\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockMessageStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class MockMessageStore<TModel> : IMessageStore<TModel>\n    {\n        public Dictionary<string, Message<TModel>> Messages { get; set; } = new Dictionary<string, Message<TModel>>();\n\n        public Task<Message<TModel>> ReadAsync(string id)\n        {\n            Message<TModel> val = null;\n            if (id != null)\n            {\n                Messages.TryGetValue(id, out val);\n            }\n            return Task.FromResult(val);\n        }\n\n        public Task<string> WriteAsync(Message<TModel> message)\n        {\n            var id = Guid.NewGuid().ToString();\n            Messages[id] = message;\n            return Task.FromResult(id);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockPersistedGrantService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class MockPersistedGrantService : IPersistedGrantService\n    {\n        public IEnumerable<Grant> GetAllGrantsResult { get; set; }\n        public bool RemoveAllGrantsWasCalled { get; set; }\n\n        public Task<IEnumerable<Grant>> GetAllGrantsAsync(string subjectId)\n        {\n            return Task.FromResult(GetAllGrantsResult ?? Enumerable.Empty<Grant>());\n        }\n\n        public Task RemoveAllGrantsAsync(string subjectId, string clientId, string sessionId = null)\n        {\n            RemoveAllGrantsWasCalled = true;\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockProfileService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class MockProfileService : IProfileService\n    {\n        public ICollection<Claim> ProfileClaims { get; set; } = new HashSet<Claim>();\n        public bool IsActive { get; set; } = true;\n\n        public bool GetProfileWasCalled => ProfileContext != null;\n        public ProfileDataRequestContext ProfileContext { get; set; }\n\n        public bool IsActiveWasCalled => ActiveContext != null;\n        public IsActiveContext ActiveContext { get; set; }\n\n        public Task GetProfileDataAsync(ProfileDataRequestContext context)\n        {\n            ProfileContext = context;\n            context.IssuedClaims = ProfileClaims.ToList();\n            return Task.CompletedTask;\n        }\n\n        public Task IsActiveAsync(IsActiveContext context)\n        {\n            ActiveContext = context;\n            context.IsActive = IsActive;\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockReferenceTokenStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing System;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    class MockReferenceTokenStore : IReferenceTokenStore\n    {\n        public Task<Token> GetReferenceTokenAsync(string handle)\n        {\n            throw new NotImplementedException();\n        }\n\n        public Task RemoveReferenceTokenAsync(string handle)\n        {\n            throw new NotImplementedException();\n        }\n\n        public Task RemoveReferenceTokensAsync(string subjectId, string clientId)\n        {\n            throw new NotImplementedException();\n        }\n\n        public Task<string> StoreReferenceTokenAsync(Token token)\n        {\n            throw new NotImplementedException();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockResourceValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Validation;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    class MockResourceValidator : IResourceValidator\n    {\n        public ResourceValidationResult Result { get; set; } = new ResourceValidationResult();\n\n        public Task<IEnumerable<ParsedScopeValue>> ParseRequestedScopesAsync(IEnumerable<string> scopeValues)\n        {\n            return Task.FromResult(scopeValues.Select(x => new ParsedScopeValue(x)));\n        }\n\n        public Task<ResourceValidationResult> ValidateRequestedResourcesAsync(ResourceValidationRequest request)\n        {\n            return Task.FromResult(Result);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockReturnUrlParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Linq;\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class MockReturnUrlParser : ReturnUrlParser\n    {\n        public AuthorizationRequest AuthorizationRequestResult { get; set; }\n        public bool IsValidReturnUrlResult { get; set; }\n\n        public MockReturnUrlParser() : base(Enumerable.Empty<IReturnUrlParser>())\n        {\n        }\n\n        public override Task<AuthorizationRequest> ParseAsync(string returnUrl)\n        {\n            return Task.FromResult(AuthorizationRequestResult);\n        }\n\n        public override bool IsValidReturnUrl(string returnUrl)\n        {\n            return IsValidReturnUrlResult;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockSessionIdService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer.UnitTests.Common\n{\n    //public class MockSessionIdService : ISessionIdService\n    //{\n    //    public bool RemoveCookieWasCalled { get; private set; }\n    //    public string SessionId { get; set; } = \"session_id\";\n\n    //    public void CreateSessionId(SignInContext context)\n    //    {\n    //    }\n\n    //    public Task EnsureSessionCookieAsync()\n    //    {\n    //        return Task.CompletedTask;\n    //    }\n\n    //    public string GetCookieName()\n    //    {\n    //        return \"sessionid\";\n    //    }\n\n    //    public string GetCookieValue()\n    //    {\n    //        return SessionId;\n    //    }\n\n    //    public Task<string> GetCurrentSessionIdAsync()\n    //    {\n    //        return Task.FromResult(SessionId);\n    //    }\n\n    //    public void RemoveCookie()\n    //    {\n    //        RemoveCookieWasCalled = true;\n    //        SessionId = null;\n    //    }\n    //}\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockSystemClock.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.AspNetCore.Authentication;\nusing System;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    class MockSystemClock : ISystemClock\n    {\n        public DateTimeOffset Now { get; set; }\n\n        public DateTimeOffset UtcNow\n        {\n            get\n            {\n                return Now;\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockTokenCreationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    class MockTokenCreationService : ITokenCreationService\n    {\n        public string Token { get; set; }\n\n        public Task<string> CreateTokenAsync(Token token)\n        {\n            return Task.FromResult(Token);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/MockUserSession.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing IdentityServer8.Services;\nusing Microsoft.AspNetCore.Authentication;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class MockUserSession : IUserSession\n    {\n        public List<string> Clients = new List<string>();\n\n        public bool EnsureSessionIdCookieWasCalled { get; set; }\n        public bool RemoveSessionIdCookieWasCalled { get; set; }\n        public bool CreateSessionIdWasCalled { get; set; }\n\n        public ClaimsPrincipal User { get; set; }\n        public string SessionId { get; set; }\n        public AuthenticationProperties Properties { get; set; }\n\n\n        public Task<string> CreateSessionIdAsync(ClaimsPrincipal principal, AuthenticationProperties properties)\n        {\n            CreateSessionIdWasCalled = true;\n            User = principal;\n            SessionId = Guid.NewGuid().ToString();\n            return Task.FromResult(SessionId);\n        }\n\n        public Task<ClaimsPrincipal> GetUserAsync()\n        {\n            return Task.FromResult(User);\n        }\n\n        Task<string> IUserSession.GetSessionIdAsync()\n        {\n            return Task.FromResult(SessionId);\n        }\n\n        public Task EnsureSessionIdCookieAsync()\n        {\n            EnsureSessionIdCookieWasCalled = true;\n            return Task.CompletedTask;\n        }\n\n        public Task RemoveSessionIdCookieAsync()\n        {\n            RemoveSessionIdCookieWasCalled = true;\n            return Task.CompletedTask;\n        }\n\n        public Task<IEnumerable<string>> GetClientListAsync()\n        {\n            return Task.FromResult<IEnumerable<string>>(Clients);\n        }\n\n        public Task AddClientIdAsync(string clientId)\n        {\n            Clients.Add(clientId);\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/NetworkHandler.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Net;\nusing System.Net.Http;\nusing System.Threading;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class NetworkHandler : HttpMessageHandler\n    {\n        enum Behavior\n        {\n            Throw,\n            ReturnError,\n            ReturnDocument\n        }\n\n        private readonly Exception _exception;\n        private readonly Behavior _behavior;\n        private readonly HttpStatusCode _statusCode;\n        private readonly string _reason;\n        private readonly string _document;\n        private readonly Func<HttpRequestMessage, string> _selector;\n        private readonly Func<HttpRequestMessage, HttpResponseMessage> _action;\n\n        public HttpRequestMessage Request { get; set; }\n        public string Body { get; set; }\n\n        public NetworkHandler(Exception exception)\n        {\n            _exception = exception;\n            _behavior = Behavior.Throw;\n        }\n\n        public NetworkHandler(HttpStatusCode statusCode, string reason)\n        {\n            _statusCode = statusCode;\n            _reason = reason;\n\n            _behavior = Behavior.ReturnError;\n        }\n\n        public NetworkHandler(string document, HttpStatusCode statusCode)\n        {\n            _statusCode = statusCode;\n            _document = document;\n            _behavior = Behavior.ReturnDocument;\n        }\n\n        public NetworkHandler(Func<HttpRequestMessage, string> documentSelector, HttpStatusCode statusCode)\n        {\n            _statusCode = statusCode;\n            _selector = documentSelector;\n            _behavior = Behavior.ReturnDocument;\n        }\n\n        public NetworkHandler(Func<HttpRequestMessage, HttpResponseMessage> action)\n        {\n            _action = action;\n        }\n\n        protected override async Task<HttpResponseMessage> SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)\n        {\n            Request = request;\n            Body = await SafeReadContentFrom(request);\n\n            if (_action != null)\n            {\n                return _action(request);\n            }\n\n            if (_behavior == Behavior.Throw) throw _exception;\n\n            var response = new HttpResponseMessage(_statusCode);\n\n            if (_behavior == Behavior.ReturnError)\n            {\n                response.ReasonPhrase = _reason;\n            }\n\n            if (_behavior == Behavior.ReturnDocument)\n            {\n                if (_selector != null)\n                {\n                    response.Content = new StringContent(_selector(request));\n                }\n                else\n                {\n                    response.Content = new StringContent(_document);\n                }\n            }\n\n            return response;\n        }\n\n        private async Task<string> SafeReadContentFrom(HttpRequestMessage request)\n        {\n            if (request.Content == null) return null;\n\n            return await request.Content.ReadAsStringAsync();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/StubAuthorizeResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.ResponseHandling;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal class StubAuthorizeResponseGenerator : IAuthorizeResponseGenerator\n    {\n        public AuthorizeResponse Response { get; set; } = new AuthorizeResponse();\n\n        public Task<AuthorizeResponse> CreateResponseAsync(ValidatedAuthorizeRequest request)\n        {\n            return Task.FromResult(Response);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/StubClock.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing Microsoft.AspNetCore.Authentication;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal class StubClock : ISystemClock\n    {\n        public Func<DateTime> UtcNowFunc = () => DateTime.UtcNow;\n        public DateTimeOffset UtcNow => new DateTimeOffset(UtcNowFunc());\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/StubHandleGenerationService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Services;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class StubHandleGenerationService : DefaultHandleGenerationService, IHandleGenerationService\n    {\n        public string Handle { get; set; }\n\n        public new Task<string> GenerateAsync(int length)\n        {\n            if (Handle != null) return Task.FromResult(Handle);\n            return base.GenerateAsync(length);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/TestCert.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.IO;\nusing System.Security.Cryptography.X509Certificates;\nusing Microsoft.IdentityModel.Tokens;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal static class TestCert\n    {\n        public static X509Certificate2 Load()\n        {\n            var cert = Path.Combine(System.AppContext.BaseDirectory, \"identityserver_testing.pfx\");\n            return new X509Certificate2(cert, \"password\");\n        }\n\n        public static SigningCredentials LoadSigningCredentials()\n        {\n            var cert = Load();\n            return new SigningCredentials(new X509SecurityKey(cert), \"RS256\");\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/TestEventService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer8.Events;\nusing IdentityServer8.Services;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class TestEventService : IEventService\n    {\n        private Dictionary<Type, object> _events = new Dictionary<Type, object>();\n\n        public Task RaiseAsync(Event evt)\n        {\n            _events.Add(evt.GetType(), evt);\n            return Task.CompletedTask;\n        }\n\n        public T AssertEventWasRaised<T>()\n            where T : class\n        {\n            _events.ContainsKey(typeof(T)).Should().BeTrue();\n            return (T)_events.Where(x => x.Key == typeof(T)).Select(x=>x.Value).First();\n        }\n\n        public bool CanRaiseEventType(EventTypes evtType)\n        {\n            return true;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/TestExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Linq;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal static class TestExtensions\n    {\n        public static string Repeat(this string value, int count)\n        {\n            var parts = new string[count];\n            return parts.Aggregate((x, y) => (x ?? value) + value);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/TestIdentityServerOptions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Configuration;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    internal class TestIdentityServerOptions\n    {\n        public static IdentityServerOptions Create()\n        {\n            var options = new IdentityServerOptions\n            {\n                IssuerUri = \"https://idsvr.com\"\n            };\n\n            return options;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/TestLogger.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.Extensions.Logging;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public static class TestLogger\n    {\n        public static ILogger<T> Create<T>()\n        {\n            return new LoggerFactory().CreateLogger<T>();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Common/TestUserConsentStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Stores.Serialization;\n\nnamespace IdentityServer.UnitTests.Common\n{\n    public class TestUserConsentStore : IUserConsentStore\n    {\n        private DefaultUserConsentStore _userConsentStore;\n        private InMemoryPersistedGrantStore _grantStore = new InMemoryPersistedGrantStore();\n\n        public TestUserConsentStore()\n        {\n            _userConsentStore = new DefaultUserConsentStore(\n               _grantStore,\n               new PersistentGrantSerializer(),\n                new DefaultHandleGenerationService(),\n               TestLogger.Create<DefaultUserConsentStore>());\n        }\n\n        public Task StoreUserConsentAsync(Consent consent)\n        {\n            return _userConsentStore.StoreUserConsentAsync(consent);\n        }\n\n        public Task<Consent> GetUserConsentAsync(string subjectId, string clientId)\n        {\n            return _userConsentStore.GetUserConsentAsync(subjectId, clientId);\n        }\n\n        public Task RemoveUserConsentAsync(string subjectId, string clientId)\n        {\n            return _userConsentStore.RemoveUserConsentAsync(subjectId, clientId);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Cors/MockCorsPolicyProvider.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing Microsoft.AspNetCore.Cors.Infrastructure;\nusing Microsoft.AspNetCore.Http;\n\nnamespace IdentityServer.UnitTests.Cors\n{\n    public class MockCorsPolicyProvider : ICorsPolicyProvider\n    {\n        public bool WasCalled { get; set; }\n        public CorsPolicy Response { get; set; }\n\n        public Task<CorsPolicy> GetPolicyAsync(HttpContext context, string policyName)\n        {\n            WasCalled = true;\n            return Task.FromResult(Response);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Cors/MockCorsPolicyService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Services;\n\nnamespace IdentityServer.UnitTests.Cors\n{\n    public class MockCorsPolicyService : ICorsPolicyService\n    {\n        public bool WasCalled { get; set; }\n        public bool Response { get; set; }\n\n        public Task<bool> IsOriginAllowedAsync(string origin)\n        {\n            WasCalled = true;\n            return Task.FromResult(Response);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Cors/PolicyProviderTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Configuration.DependencyInjection;\nusing IdentityServer8.Hosting;\nusing IdentityServer8.Services;\nusing Microsoft.AspNetCore.Cors.Infrastructure;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.Extensions.DependencyInjection;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Cors\n{\n    public class PolicyProviderTests\n    {\n        private const string Category = \"PolicyProvider\";\n\n        private CorsPolicyProvider _subject;\n        private List<string> _allowedPaths = new List<string>();\n\n        private MockCorsPolicyProvider _mockInner = new MockCorsPolicyProvider();\n        private MockCorsPolicyService _mockPolicy = new MockCorsPolicyService();\n        private IdentityServerOptions _options;\n\n        public PolicyProviderTests()\n        {\n            Init();\n        }\n\n        internal void Init()\n        {\n            _options = new IdentityServerOptions();\n            _options.Cors.CorsPaths.Clear();\n            foreach(var path in _allowedPaths)\n            {\n                _options.Cors.CorsPaths.Add(new PathString(path));\n            }\n\n            var ctx = new DefaultHttpContext();\n            var svcs = new ServiceCollection();\n            svcs.AddSingleton<ICorsPolicyService>(_mockPolicy);\n            ctx.RequestServices = svcs.BuildServiceProvider();\n            var ctxAccessor = new HttpContextAccessor();\n            ctxAccessor.HttpContext = ctx;\n\n            _subject = new CorsPolicyProvider(\n                TestLogger.Create<CorsPolicyProvider>(),\n                new Decorator<ICorsPolicyProvider>(_mockInner),\n                _options,\n                ctxAccessor);\n        }\n\n        [Theory]\n        [InlineData(\"/foo\")]\n        [InlineData(\"/bar/\")]\n        [InlineData(\"/baz/quux\")]\n        [InlineData(\"/baz/quux/\")]\n        [Trait(\"Category\", Category)]\n        public async Task valid_paths_should_call_policy_service(string path)\n        {\n            _allowedPaths.AddRange(new string[] {\n                \"/foo\",\n                \"/bar/\",\n                \"/baz/quux\",\n                \"/baz/quux/\"\n            });\n            Init();\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Scheme = \"https\";\n            ctx.Request.Host = new HostString(\"server\");\n            ctx.Request.Path = new PathString(path);\n            ctx.Request.Headers.Append(\"Origin\", \"http://notserver\");\n\n            var response = await _subject.GetPolicyAsync(ctx, _options.Cors.CorsPolicyName);\n\n            _mockPolicy.WasCalled.Should().BeTrue();\n            _mockInner.WasCalled.Should().BeFalse();\n        }\n\n        [Theory]\n        [InlineData(\"/foo/\")]\n        [InlineData(\"/xoxo\")]\n        [InlineData(\"/xoxo/\")]\n        [InlineData(\"/foo/xoxo\")]\n        [InlineData(\"/baz/quux/xoxo\")]\n        [Trait(\"Category\", Category)]\n        public async Task invalid_paths_should_not_call_policy_service(string path)\n        {\n            _allowedPaths.AddRange(new string[] {\n                \"/foo\",\n                \"/bar\",\n                \"/baz/quux\"\n            });\n            Init();\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Scheme = \"https\";\n            ctx.Request.Host = new HostString(\"server\");\n            ctx.Request.Path = new PathString(path);\n            ctx.Request.Headers.Append(\"Origin\", \"http://notserver\");\n\n            var response = await _subject.GetPolicyAsync(ctx, _options.Cors.CorsPolicyName);\n\n            _mockPolicy.WasCalled.Should().BeFalse();\n            _mockInner.WasCalled.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task different_policy_name_should_call_inner_policy_service()\n        {\n            _allowedPaths.AddRange(new string[] {\n                \"/foo\",\n                \"/bar\",\n                \"/baz/quux\"\n            });\n            Init();\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Scheme = \"https\";\n            ctx.Request.Host = new HostString(\"server\");\n            ctx.Request.Path = new PathString(\"/foo\");\n            ctx.Request.Headers.Append(\"Origin\", \"http://notserver\");\n\n            var response = await _subject.GetPolicyAsync(ctx, \"wrong_name\");\n\n            _mockPolicy.WasCalled.Should().BeFalse();\n            _mockInner.WasCalled.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task origin_same_as_server_should_not_call_policy()\n        {\n            _allowedPaths.AddRange(new string[] {\n                \"/foo\"\n            });\n            Init();\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Scheme = \"https\";\n            ctx.Request.Host = new HostString(\"server\");\n            ctx.Request.Path = new PathString(\"/foo\");\n            ctx.Request.Headers.Append(\"Origin\", \"https://server\");\n\n            var response = await _subject.GetPolicyAsync(ctx, _options.Cors.CorsPolicyName);\n\n            _mockPolicy.WasCalled.Should().BeFalse();\n            _mockInner.WasCalled.Should().BeFalse();\n        }\n\n        [Theory]\n        [InlineData(\"https://notserver\")]\n        [InlineData(\"http://server\")]\n        [Trait(\"Category\", Category)]\n        public async Task origin_not_same_as_server_should_call_policy(string origin)\n        {\n            _allowedPaths.AddRange(new string[] {\n                \"/foo\"\n            });\n            Init();\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Scheme = \"https\";\n            ctx.Request.Host = new HostString(\"server\");\n            ctx.Request.Path = new PathString(\"/foo\");\n            ctx.Request.Headers.Append(\"Origin\", origin);\n\n            var response = await _subject.GetPolicyAsync(ctx, _options.Cors.CorsPolicyName);\n\n            _mockPolicy.WasCalled.Should().BeTrue();\n            _mockInner.WasCalled.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/Authorize/AuthorizeCallbackEndpointTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Endpoints;\nusing IdentityServer8.Endpoints.Results;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.Extensions.Logging;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Endpoints.Authorize\n{\n    public class AuthorizeCallbackEndpointTests\n    {\n        private const string Category = \"Authorize Endpoint\";\n\n        private HttpContext _context;\n\n        private TestEventService _fakeEventService = new TestEventService();\n\n        private ILogger<AuthorizeCallbackEndpoint> _fakeLogger = TestLogger.Create<AuthorizeCallbackEndpoint>();\n\n        private IdentityServerOptions _options = new IdentityServerOptions();\n\n        private MockConsentMessageStore _mockUserConsentResponseMessageStore = new MockConsentMessageStore();\n\n        private MockUserSession _mockUserSession = new MockUserSession();\n\n        private NameValueCollection _params = new NameValueCollection();\n\n        private StubAuthorizeRequestValidator _stubAuthorizeRequestValidator = new StubAuthorizeRequestValidator();\n\n        private StubAuthorizeResponseGenerator _stubAuthorizeResponseGenerator = new StubAuthorizeResponseGenerator();\n\n        private StubAuthorizeInteractionResponseGenerator _stubInteractionGenerator = new StubAuthorizeInteractionResponseGenerator();\n\n        private AuthorizeCallbackEndpoint _subject;\n\n        private ClaimsPrincipal _user = new IdentityServerUser(\"bob\").CreatePrincipal();\n\n        private ValidatedAuthorizeRequest _validatedAuthorizeRequest;\n\n        public AuthorizeCallbackEndpointTests()\n        {\n            Init();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ProcessAsync_authorize_after_consent_path_should_return_authorization_result()\n        {\n            var parameters = new NameValueCollection()\n            {\n                { \"client_id\", \"client\" },\n                { \"nonce\", \"some_nonce\" },\n                { \"scope\", \"api1 api2\" }\n            };\n            var request = new ConsentRequest(parameters, _user.GetSubjectId());\n            _mockUserConsentResponseMessageStore.Messages.Add(request.Id, new Message<ConsentResponse>(new ConsentResponse()));\n\n            _mockUserSession.User = _user;\n\n            _context.Request.Method = \"GET\";\n            _context.Request.Path = new PathString(\"/connect/authorize/callback\");\n            _context.Request.QueryString = new QueryString(\"?\" + parameters.ToQueryString());\n\n            var result = await _subject.ProcessAsync(_context);\n\n            result.Should().BeOfType<AuthorizeResult>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ProcessAsync_authorize_after_login_path_should_return_authorization_result()\n        {\n            _context.Request.Method = \"GET\";\n            _context.Request.Path = new PathString(\"/connect/authorize/callback\");\n            _mockUserSession.User = _user;\n\n            var result = await _subject.ProcessAsync(_context);\n\n            result.Should().BeOfType<AuthorizeResult>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ProcessAsync_consent_missing_consent_data_should_return_error_page()\n        {\n            var parameters = new NameValueCollection()\n            {\n                { \"client_id\", \"client\" },\n                { \"nonce\", \"some_nonce\" },\n                { \"scope\", \"api1 api2\" }\n            };\n            var request = new ConsentRequest(parameters, _user.GetSubjectId());\n            _mockUserConsentResponseMessageStore.Messages.Add(request.Id, new Message<ConsentResponse>(null));\n\n            _mockUserSession.User = _user;\n\n            _context.Request.Method = \"GET\";\n            _context.Request.Path = new PathString(\"/connect/authorize/callback\");\n            _context.Request.QueryString = new QueryString(\"?\" + parameters.ToQueryString());\n\n            var result = await _subject.ProcessAsync(_context);\n\n            result.Should().BeOfType<AuthorizeResult>();\n            ((AuthorizeResult)result).Response.IsError.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ProcessAsync_no_consent_message_should_return_redirect_for_consent()\n        {\n            _stubInteractionGenerator.Response.IsConsent = true;\n\n            var parameters = new NameValueCollection()\n            {\n                { \"client_id\", \"client\" },\n                { \"nonce\", \"some_nonce\" },\n                { \"scope\", \"api1 api2\" }\n            };\n            var request = new ConsentRequest(parameters, _user.GetSubjectId());\n            _mockUserConsentResponseMessageStore.Messages.Add(request.Id, null);\n\n            _mockUserSession.User = _user;\n\n            _context.Request.Method = \"GET\";\n            _context.Request.Path = new PathString(\"/connect/authorize/callback\");\n            _context.Request.QueryString = new QueryString(\"?\" + parameters.ToQueryString());\n\n            var result = await _subject.ProcessAsync(_context);\n\n            result.Should().BeOfType<ConsentPageResult>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ProcessAsync_post_to_entry_point_should_return_405()\n        {\n            _context.Request.Method = \"POST\";\n\n            var result = await _subject.ProcessAsync(_context);\n\n            var statusCode = result as StatusCodeResult;\n            statusCode.Should().NotBeNull();\n            statusCode.StatusCode.Should().Be(405);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ProcessAsync_valid_consent_message_should_cleanup_consent_cookie()\n        {\n            var parameters = new NameValueCollection()\n            {\n                { \"client_id\", \"client\" },\n                { \"nonce\", \"some_nonce\" },\n                { \"scope\", \"api1 api2\" }\n            };\n            var request = new ConsentRequest(parameters, _user.GetSubjectId());\n            _mockUserConsentResponseMessageStore.Messages.Add(request.Id, new Message<ConsentResponse>(new ConsentResponse() { ScopesValuesConsented = new string[] { \"api1\", \"api2\" } }));\n\n            _mockUserSession.User = _user;\n\n            _context.Request.Method = \"GET\";\n            _context.Request.Path = new PathString(\"/connect/authorize/callback\");\n            _context.Request.QueryString = new QueryString(\"?\" + parameters.ToQueryString());\n\n            var result = await _subject.ProcessAsync(_context);\n\n            _mockUserConsentResponseMessageStore.Messages.Count.Should().Be(0);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ProcessAsync_valid_consent_message_should_return_authorize_result()\n        {\n            var parameters = new NameValueCollection()\n            {\n                { \"client_id\", \"client\" },\n                { \"nonce\", \"some_nonce\" },\n                { \"scope\", \"api1 api2\" }\n            };\n            var request = new ConsentRequest(parameters, _user.GetSubjectId());\n            _mockUserConsentResponseMessageStore.Messages.Add(request.Id, new Message<ConsentResponse>(new ConsentResponse() { ScopesValuesConsented = new string[] { \"api1\", \"api2\" } }));\n\n            _mockUserSession.User = _user;\n\n            _context.Request.Method = \"GET\";\n            _context.Request.Path = new PathString(\"/connect/authorize/callback\");\n            _context.Request.QueryString = new QueryString(\"?\" + parameters.ToQueryString());\n\n            var result = await _subject.ProcessAsync(_context);\n\n            result.Should().BeOfType<AuthorizeResult>();\n        }\n\n        internal void Init()\n        {\n            _context = new MockHttpContextAccessor().HttpContext;\n\n            _validatedAuthorizeRequest = new ValidatedAuthorizeRequest()\n            {\n                RedirectUri = \"http://client/callback\",\n                State = \"123\",\n                ResponseMode = \"fragment\",\n                ClientId = \"client\",\n                Client = new Client\n                {\n                    ClientId = \"client\",\n                    ClientName = \"Test Client\"\n                },\n                Raw = _params,\n                Subject = _user\n            };\n            _stubAuthorizeResponseGenerator.Response.Request = _validatedAuthorizeRequest;\n\n            _stubAuthorizeRequestValidator.Result = new AuthorizeRequestValidationResult(_validatedAuthorizeRequest);\n\n            _subject = new AuthorizeCallbackEndpoint(\n                _fakeEventService,\n                _fakeLogger,\n                _options,\n                _stubAuthorizeRequestValidator,\n                _stubInteractionGenerator,\n                _stubAuthorizeResponseGenerator,\n                _mockUserSession,\n                _mockUserConsentResponseMessageStore);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/Authorize/AuthorizeEndpointBaseTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Endpoints;\nusing IdentityServer8.Endpoints.Results;\nusing IdentityServer8.Hosting;\nusing IdentityServer8.Models;\nusing IdentityServer8.ResponseHandling;\nusing IdentityServer8.Services;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.Extensions.Logging;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Endpoints.Authorize\n{\n    public class AuthorizeEndpointBaseTests\n    {\n        private const string Category = \"Authorize Endpoint\";\n\n        private HttpContext _context;\n\n        private TestEventService _fakeEventService = new TestEventService();\n\n        private ILogger<TestAuthorizeEndpoint> _fakeLogger = TestLogger.Create<TestAuthorizeEndpoint>();\n\n        private IdentityServerOptions _options = new IdentityServerOptions();\n\n        private MockUserSession _mockUserSession = new MockUserSession();\n\n        private NameValueCollection _params = new NameValueCollection();\n\n        private StubAuthorizeRequestValidator _stubAuthorizeRequestValidator = new StubAuthorizeRequestValidator();\n\n        private StubAuthorizeResponseGenerator _stubAuthorizeResponseGenerator = new StubAuthorizeResponseGenerator();\n\n        private StubAuthorizeInteractionResponseGenerator _stubInteractionGenerator = new StubAuthorizeInteractionResponseGenerator();\n\n        private TestAuthorizeEndpoint _subject;\n\n        private ClaimsPrincipal _user = new IdentityServerUser(\"bob\").CreatePrincipal();\n\n        private ValidatedAuthorizeRequest _validatedAuthorizeRequest;\n\n        public AuthorizeEndpointBaseTests()\n        {\n            Init();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task error_resurect_with_prompt_none_should_include_session_state_in_response()\n        {\n            _params.Add(\"prompt\", \"none\");\n            _stubAuthorizeRequestValidator.Result.ValidatedRequest.IsOpenIdRequest = true;\n            _stubAuthorizeRequestValidator.Result.ValidatedRequest.ClientId = \"client\";\n            _stubAuthorizeRequestValidator.Result.ValidatedRequest.SessionId = \"some_session\";\n            _stubAuthorizeRequestValidator.Result.ValidatedRequest.RedirectUri = \"http://redirect\";\n            _stubAuthorizeRequestValidator.Result.IsError = true;\n            _stubAuthorizeRequestValidator.Result.Error = \"login_required\";\n\n            var result = await _subject.ProcessAuthorizeRequestAsync(_params, _user, null);\n\n            result.Should().BeOfType<AuthorizeResult>();\n            ((AuthorizeResult)result).Response.IsError.Should().BeTrue();\n            ((AuthorizeResult)result).Response.SessionState.Should().NotBeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task authorize_request_validation_produces_error_should_display_error_page()\n        {\n            _stubAuthorizeRequestValidator.Result.IsError = true;\n            _stubAuthorizeRequestValidator.Result.Error = \"some_error\";\n\n            var result = await _subject.ProcessAuthorizeRequestAsync(_params, _user, null);\n\n            result.Should().BeOfType<AuthorizeResult>();\n            ((AuthorizeResult)result).Response.IsError.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task interaction_generator_consent_produces_consent_should_show_consent_page()\n        {\n            _stubInteractionGenerator.Response.IsConsent = true;\n\n            var result = await _subject.ProcessAuthorizeRequestAsync(_params, _user, null);\n\n            result.Should().BeOfType<ConsentPageResult>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task interaction_produces_error_should_show_error_page()\n        {\n            _stubInteractionGenerator.Response.Error = \"error\";\n\n            var result = await _subject.ProcessAuthorizeRequestAsync(_params, _user, null);\n\n            result.Should().BeOfType<AuthorizeResult>();\n            ((AuthorizeResult)result).Response.IsError.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task interaction_produces_error_should_show_error_page_with_error_description_if_present()\n        {\n            var errorDescription = \"some error description\";\n\n             _stubInteractionGenerator.Response.Error = \"error\";\n            _stubInteractionGenerator.Response.ErrorDescription = errorDescription;\n\n             var result = await _subject.ProcessAuthorizeRequestAsync(_params, _user, null);\n\n             result.Should().BeOfType<AuthorizeResult>();\n            var authorizeResult = ((AuthorizeResult)result);\n            authorizeResult.Response.IsError.Should().BeTrue();\n            authorizeResult.Response.ErrorDescription.Should().Be(errorDescription);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task interaction_produces_login_result_should_trigger_login()\n        {\n            _stubInteractionGenerator.Response.IsLogin = true;\n\n            var result = await _subject.ProcessAuthorizeRequestAsync(_params, _user, null);\n\n            result.Should().BeOfType<LoginPageResult>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ProcessAuthorizeRequestAsync_custom_interaction_redirect_result_should_issue_redirect()\n        {\n            _mockUserSession.User = _user;\n            _stubInteractionGenerator.Response.RedirectUrl = \"http://foo.com\";\n\n            var result = await _subject.ProcessAuthorizeRequestAsync(_params, _user, null);\n\n            result.Should().BeOfType<CustomRedirectResult>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task successful_authorization_request_should_generate_authorize_result()\n        {\n            var result = await _subject.ProcessAuthorizeRequestAsync(_params, _user, null);\n\n            result.Should().BeOfType<AuthorizeResult>();\n        }\n\n        internal void Init()\n        {\n            _context = new MockHttpContextAccessor().HttpContext;\n\n            _validatedAuthorizeRequest = new ValidatedAuthorizeRequest()\n            {\n                RedirectUri = \"http://client/callback\",\n                State = \"123\",\n                ResponseMode = \"fragment\",\n                ClientId = \"client\",\n                Client = new Client\n                {\n                    ClientId = \"client\",\n                    ClientName = \"Test Client\"\n                },\n                Raw = _params,\n                Subject = _user\n            };\n            _stubAuthorizeResponseGenerator.Response.Request = _validatedAuthorizeRequest;\n\n            _stubAuthorizeRequestValidator.Result = new AuthorizeRequestValidationResult(_validatedAuthorizeRequest);\n\n            _subject = new TestAuthorizeEndpoint(\n                _fakeEventService,\n                _fakeLogger,\n                _options,\n                _stubAuthorizeRequestValidator,\n                _stubInteractionGenerator,\n                _stubAuthorizeResponseGenerator,\n                _mockUserSession);\n        }\n\n        internal class TestAuthorizeEndpoint : AuthorizeEndpointBase\n        {\n            public TestAuthorizeEndpoint(\n              IEventService events,\n              ILogger<TestAuthorizeEndpoint> logger,\n              IdentityServerOptions options,\n              IAuthorizeRequestValidator validator,\n              IAuthorizeInteractionResponseGenerator interactionGenerator,\n              IAuthorizeResponseGenerator authorizeResponseGenerator,\n              IUserSession userSession)\n            : base(events, logger, options, validator, interactionGenerator, authorizeResponseGenerator, userSession)\n            {\n            }\n\n            public override Task<IEndpointResult> ProcessAsync(HttpContext context)\n            {\n                throw new System.NotImplementedException();\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/Authorize/AuthorizeEndpointTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Endpoints;\nusing IdentityServer8.Endpoints.Results;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.Extensions.Logging;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Endpoints.Authorize\n{\n    public class AuthorizeEndpointTests\n    {\n        private const string Category = \"Authorize Endpoint\";\n\n        private HttpContext _context;\n\n        private TestEventService _fakeEventService = new TestEventService();\n\n        private ILogger<AuthorizeEndpoint> _fakeLogger = TestLogger.Create<AuthorizeEndpoint>();\n\n        private IdentityServerOptions _options = new IdentityServerOptions();\n\n        private MockUserSession _mockUserSession = new MockUserSession();\n\n        private NameValueCollection _params = new NameValueCollection();\n\n        private StubAuthorizeRequestValidator _stubAuthorizeRequestValidator = new StubAuthorizeRequestValidator();\n\n        private StubAuthorizeResponseGenerator _stubAuthorizeResponseGenerator = new StubAuthorizeResponseGenerator();\n\n        private StubAuthorizeInteractionResponseGenerator _stubInteractionGenerator = new StubAuthorizeInteractionResponseGenerator();\n\n        private AuthorizeEndpoint _subject;\n\n        private ClaimsPrincipal _user = new IdentityServerUser(\"bob\").CreatePrincipal();\n\n        private ValidatedAuthorizeRequest _validatedAuthorizeRequest;\n\n        public AuthorizeEndpointTests()\n        {\n            Init();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ProcessAsync_authorize_path_should_return_authorization_result()\n        {\n            _context.Request.Method = \"GET\";\n            _context.Request.Path = new PathString(\"/connect/authorize\");\n            _mockUserSession.User = _user;\n\n            var result = await _subject.ProcessAsync(_context);\n\n            result.Should().BeOfType<AuthorizeResult>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ProcessAsync_post_without_form_content_type_should_return_415()\n        {\n            _context.Request.Method = \"POST\";\n\n            var result = await _subject.ProcessAsync(_context);\n\n            var statusCode = result as StatusCodeResult;\n            statusCode.Should().NotBeNull();\n            statusCode.StatusCode.Should().Be(415);\n        }\n\n        internal void Init()\n        {\n            _context = new MockHttpContextAccessor().HttpContext;\n\n            _validatedAuthorizeRequest = new ValidatedAuthorizeRequest()\n            {\n                RedirectUri = \"http://client/callback\",\n                State = \"123\",\n                ResponseMode = \"fragment\",\n                ClientId = \"client\",\n                Client = new Client\n                {\n                    ClientId = \"client\",\n                    ClientName = \"Test Client\"\n                },\n                Raw = _params,\n                Subject = _user\n            };\n            _stubAuthorizeResponseGenerator.Response.Request = _validatedAuthorizeRequest;\n\n            _stubAuthorizeRequestValidator.Result = new AuthorizeRequestValidationResult(_validatedAuthorizeRequest);\n\n            _subject = new AuthorizeEndpoint(\n                _fakeEventService,\n                _fakeLogger,\n                _options,\n                _stubAuthorizeRequestValidator,\n                _stubInteractionGenerator,\n                _stubAuthorizeResponseGenerator,\n                _mockUserSession);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/Authorize/StubAuthorizeInteractionResponseGenerator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.ResponseHandling;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Endpoints.Authorize\n{\n    internal class StubAuthorizeInteractionResponseGenerator : IAuthorizeInteractionResponseGenerator\n    {\n        internal InteractionResponse Response { get; set; } = new InteractionResponse();\n\n        public Task<InteractionResponse> ProcessInteractionAsync(ValidatedAuthorizeRequest request, ConsentResponse consent = null)\n        {\n            return Task.FromResult(Response);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/Authorize/StubAuthorizeRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Endpoints.Authorize\n{\n    public class StubAuthorizeRequestValidator : IAuthorizeRequestValidator\n    {\n        public AuthorizeRequestValidationResult Result { get; set; }\n\n        public Task<AuthorizeRequestValidationResult> ValidateAsync(NameValueCollection parameters, ClaimsPrincipal subject = null)\n        {\n            return Task.FromResult(Result);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/EndSession/EndSessionCallbackEndpointTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Endpoints;\nusing Microsoft.Extensions.Logging;\n\nnamespace IdentityServer.UnitTests.Endpoints.EndSession\n{\n    public class EndSessionCallbackEndpointTests\n    {\n        private const string Category = \"End Session Callback Endpoint\";\n\n        StubEndSessionRequestValidator _stubEndSessionRequestValidator = new StubEndSessionRequestValidator();\n        EndSessionCallbackEndpoint _subject;\n\n        public EndSessionCallbackEndpointTests()\n        {\n            _subject = new EndSessionCallbackEndpoint(\n                _stubEndSessionRequestValidator,\n                new LoggerFactory().CreateLogger<EndSessionCallbackEndpoint>());\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/EndSession/EndSessionCallbackResultTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Endpoints.Results;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Endpoints.EndSession\n{\n    public class EndSessionCallbackResultTests\n    {\n        private const string Category = \"End Session Callback Result\";\n\n        private readonly EndSessionCallbackValidationResult _validationResult;\n        private readonly IdentityServerOptions _options;\n        private readonly EndSessionCallbackResult _subject;\n\n        public EndSessionCallbackResultTests()\n        {\n            _validationResult = new EndSessionCallbackValidationResult()\n            {\n                IsError = false,\n            };\n            _options = new IdentityServerOptions();\n            _subject = new EndSessionCallbackResult(_validationResult, _options);\n        }\n\n        [Fact]\n        public async Task default_options_should_emit_frame_src_csp_headers()\n        {\n            _validationResult.FrontChannelLogoutUrls = new[] { \"http://foo\" };\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"GET\";\n\n            await _subject.ExecuteAsync(ctx);\n\n            ctx.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"frame-src http://foo\");\n        }\n\n        [Fact]\n        public async Task relax_csp_options_should_prevent_frame_src_csp_headers()\n        {\n            _options.Authentication.RequireCspFrameSrcForSignout = false;\n            _validationResult.FrontChannelLogoutUrls = new[] { \"http://foo\" };\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"GET\";\n\n            await _subject.ExecuteAsync(ctx);\n\n            ctx.Response.Headers[\"Content-Security-Policy\"].FirstOrDefault().Should().BeNull();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/EndSession/StubBackChannelLogoutClient.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\n\nnamespace IdentityServer.UnitTests.Endpoints.EndSession\n{\n    internal class StubBackChannelLogoutClient : IBackChannelLogoutService\n    {\n        public bool SendLogoutsWasCalled { get; set; }\n\n        public Task SendLogoutNotificationsAsync(LogoutNotificationContext context)\n        {\n            SendLogoutsWasCalled = true;\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/EndSession/StubEndSessionRequestValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Endpoints.EndSession\n{\n    class StubEndSessionRequestValidator : IEndSessionRequestValidator\n    {\n        public EndSessionValidationResult EndSessionValidationResult { get; set; } = new EndSessionValidationResult();\n        public EndSessionCallbackValidationResult EndSessionCallbackValidationResult { get; set; } = new EndSessionCallbackValidationResult();\n\n        public Task<EndSessionValidationResult> ValidateAsync(NameValueCollection parameters, ClaimsPrincipal subject)\n        {\n            return Task.FromResult(EndSessionValidationResult);\n        }\n\n        public Task<EndSessionCallbackValidationResult> ValidateCallbackAsync(NameValueCollection parameters)\n        {\n            return Task.FromResult(EndSessionCallbackValidationResult);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/Results/AuthorizeResultTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.IO;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Endpoints.Results;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing IdentityServer8.ResponseHandling;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.AspNetCore.WebUtilities;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Endpoints.Results\n{\n    public class AuthorizeResultTests\n    {\n        private AuthorizeResult _subject;\n\n        private AuthorizeResponse _response = new AuthorizeResponse();\n        private IdentityServerOptions _options = new IdentityServerOptions();\n        private MockUserSession _mockUserSession = new MockUserSession();\n        private MockMessageStore<IdentityServer8.Models.ErrorMessage> _mockErrorMessageStore = new MockMessageStore<IdentityServer8.Models.ErrorMessage>();\n\n        private DefaultHttpContext _context = new DefaultHttpContext();\n\n        public AuthorizeResultTests()\n        {\n            _context.SetIdentityServerOrigin(\"https://server\");\n            _context.SetIdentityServerBasePath(\"/\");\n            _context.Response.Body = new MemoryStream();\n\n            _options.UserInteraction.ErrorUrl = \"~/error\";\n            _options.UserInteraction.ErrorIdParameter = \"errorId\";\n\n            _subject = new AuthorizeResult(_response, _options, _mockUserSession, _mockErrorMessageStore, new StubClock());\n        }\n\n        [Fact]\n        public async Task error_should_redirect_to_error_page_and_passs_info()\n        {\n            _response.Error = \"some_error\";\n\n            await _subject.ExecuteAsync(_context);\n\n            _mockErrorMessageStore.Messages.Count.Should().Be(1);\n            _context.Response.StatusCode.Should().Be(302);\n            var location = _context.Response.Headers[\"Location\"].First();\n            location.Should().StartWith(\"https://server/error\");\n            var query = QueryHelpers.ParseQuery(new Uri(location).Query);\n            query[\"errorId\"].First().Should().Be(_mockErrorMessageStore.Messages.First().Key);\n        }\n\n        [Theory]\n        [InlineData(OidcConstants.AuthorizeErrors.AccountSelectionRequired)]\n        [InlineData(OidcConstants.AuthorizeErrors.LoginRequired)]\n        [InlineData(OidcConstants.AuthorizeErrors.ConsentRequired)]\n        [InlineData(OidcConstants.AuthorizeErrors.InteractionRequired)]\n        public async Task prompt_none_errors_should_return_to_client(string error)\n        {\n            _response.Error = error;\n            _response.Request = new ValidatedAuthorizeRequest\n            {\n                ResponseMode = OidcConstants.ResponseModes.Query,\n                RedirectUri = \"http://client/callback\",\n                PromptModes = new[] { \"none\" }\n            };\n\n            await _subject.ExecuteAsync(_context);\n\n            _mockUserSession.Clients.Count.Should().Be(0);\n            _context.Response.StatusCode.Should().Be(302);\n            var location = _context.Response.Headers[\"Location\"].First();\n            location.Should().StartWith(\"http://client/callback\");\n        }\n\n        [Theory]\n        [InlineData(OidcConstants.AuthorizeErrors.AccountSelectionRequired)]\n        [InlineData(OidcConstants.AuthorizeErrors.LoginRequired)]\n        [InlineData(OidcConstants.AuthorizeErrors.ConsentRequired)]\n        [InlineData(OidcConstants.AuthorizeErrors.InteractionRequired)]\n        public async Task prompt_none_errors_for_anonymous_users_should_include_session_state(string error)\n        {\n            _response.Error = error;\n            _response.Request = new ValidatedAuthorizeRequest\n            {\n                ResponseMode = OidcConstants.ResponseModes.Query,\n                RedirectUri = \"http://client/callback\",\n                PromptModes = new[] { \"none\" },\n            };\n            _response.SessionState = \"some_session_state\";\n\n            await _subject.ExecuteAsync(_context);\n\n            _mockUserSession.Clients.Count.Should().Be(0);\n            _context.Response.StatusCode.Should().Be(302);\n            var location = _context.Response.Headers[\"Location\"].First();\n            location.Should().Contain(\"session_state=some_session_state\");\n        }\n\n        [Fact]\n        public async Task access_denied_should_return_to_client()\n        {\n            const string errorDescription = \"some error description\";\n\n            _response.Error = OidcConstants.AuthorizeErrors.AccessDenied;\n            _response.ErrorDescription = errorDescription;\n            _response.Request = new ValidatedAuthorizeRequest\n            {\n                ResponseMode = OidcConstants.ResponseModes.Query,\n                RedirectUri = \"http://client/callback\"\n            };\n\n            await _subject.ExecuteAsync(_context);\n\n            _mockUserSession.Clients.Count.Should().Be(0);\n            _context.Response.StatusCode.Should().Be(302);\n            var location = _context.Response.Headers[\"Location\"].First();\n            location.Should().StartWith(\"http://client/callback\");\n\n            var queryString = new Uri(location).Query;\n            var queryParams = QueryHelpers.ParseQuery(queryString);\n\n            queryParams[\"error\"].Should().Equal(OidcConstants.AuthorizeErrors.AccessDenied);\n            queryParams[\"error_description\"].Should().Equal(errorDescription);\n        }\n\n        [Fact]\n        public async Task success_should_add_client_to_client_list()\n        {\n            _response.Request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"client\",\n                ResponseMode = OidcConstants.ResponseModes.Query,\n                RedirectUri = \"http://client/callback\"\n            };\n\n            await _subject.ExecuteAsync(_context);\n\n            _mockUserSession.Clients.Should().Contain(\"client\");\n        }\n\n        [Fact]\n        public async Task query_mode_should_pass_results_in_query()\n        {\n            _response.Request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"client\",\n                ResponseMode = OidcConstants.ResponseModes.Query,\n                RedirectUri = \"http://client/callback\",\n                State = \"state\"\n            };\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.StatusCode.Should().Be(302);\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"no-store\");\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"no-cache\");\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"max-age=0\");\n            var location = _context.Response.Headers[\"Location\"].First();\n            location.Should().StartWith(\"http://client/callback\");\n            location.Should().Contain(\"?state=state\");\n        }\n\n        [Fact]\n        public async Task fragment_mode_should_pass_results_in_fragment()\n        {\n            _response.Request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"client\",\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                RedirectUri = \"http://client/callback\",\n                State = \"state\"\n            };\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.StatusCode.Should().Be(302);\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"no-store\");\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"no-cache\");\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"max-age=0\");\n            var location = _context.Response.Headers[\"Location\"].First();\n            location.Should().StartWith(\"http://client/callback\");\n            location.Should().Contain(\"#state=state\");\n        }\n\n        [Fact]\n        public async Task form_post_mode_should_pass_results_in_body()\n        {\n            _response.Request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"client\",\n                ResponseMode = OidcConstants.ResponseModes.FormPost,\n                RedirectUri = \"http://client/callback\",\n                State = \"state\"\n            };\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.StatusCode.Should().Be(200);\n            _context.Response.ContentType.Should().StartWith(\"text/html\");\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"no-store\");\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"no-cache\");\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"max-age=0\");\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"default-src 'none';\");\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"script-src 'sha256-orD0/VhH8hLqrLxKHD/HUEMdwqX6/0ve7c5hspX5VJ8='\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].First().Should().Contain(\"default-src 'none';\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].First().Should().Contain(\"script-src 'sha256-orD0/VhH8hLqrLxKHD/HUEMdwqX6/0ve7c5hspX5VJ8='\");\n            _context.Response.Body.Seek(0, SeekOrigin.Begin);\n            using (var rdr = new StreamReader(_context.Response.Body))\n            {\n                var html = rdr.ReadToEnd();\n                html.Should().Contain(\"<base target='_self'/>\");\n                html.Should().Contain(\"<form method='post' action='http://client/callback'>\");\n                html.Should().Contain(\"<input type='hidden' name='state' value='state' />\");\n            }\n        }\n\n        [Fact]\n        public async Task form_post_mode_should_add_unsafe_inline_for_csp_level_1()\n        {\n            _response.Request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"client\",\n                ResponseMode = OidcConstants.ResponseModes.FormPost,\n                RedirectUri = \"http://client/callback\",\n                State = \"state\"\n            };\n\n            _options.Csp.Level = CspLevel.One;\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"script-src 'unsafe-inline' 'sha256-orD0/VhH8hLqrLxKHD/HUEMdwqX6/0ve7c5hspX5VJ8='\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].First().Should().Contain(\"script-src 'unsafe-inline' 'sha256-orD0/VhH8hLqrLxKHD/HUEMdwqX6/0ve7c5hspX5VJ8='\");\n        }\n\n        [Fact]\n        public async Task form_post_mode_should_not_add_deprecated_header_when_it_is_disabled()\n        {\n            _response.Request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"client\",\n                ResponseMode = OidcConstants.ResponseModes.FormPost,\n                RedirectUri = \"http://client/callback\",\n                State = \"state\"\n            };\n\n            _options.Csp.AddDeprecatedHeader = false;\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"script-src 'sha256-orD0/VhH8hLqrLxKHD/HUEMdwqX6/0ve7c5hspX5VJ8='\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].Should().BeEmpty();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/Results/CheckSessionResultTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.IO;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Endpoints.Results;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing Microsoft.AspNetCore.Http;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Endpoints.Results\n{\n    public class CheckSessionResultTests\n    {\n        private CheckSessionResult _subject;\n\n        private IdentityServerOptions _options = new IdentityServerOptions();\n\n        private DefaultHttpContext _context = new DefaultHttpContext();\n\n        public CheckSessionResultTests()\n        {\n            _context.SetIdentityServerOrigin(\"https://server\");\n            _context.SetIdentityServerBasePath(\"/\");\n            _context.Response.Body = new MemoryStream();\n\n            _options.Authentication.CheckSessionCookieName = \"foobar\";\n\n            _subject = new CheckSessionResult(_options);\n        }\n\n        [Fact]\n        public async Task should_pass_results_in_body()\n        {\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.StatusCode.Should().Be(200);\n            _context.Response.ContentType.Should().StartWith(\"text/html\");\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"default-src 'none';\");\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"script-src 'sha256-fa5rxHhZ799izGRP38+h4ud5QXNT0SFaFlh4eqDumBI='\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].First().Should().Contain(\"default-src 'none';\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].First().Should().Contain(\"script-src 'sha256-fa5rxHhZ799izGRP38+h4ud5QXNT0SFaFlh4eqDumBI='\");\n            _context.Response.Body.Seek(0, SeekOrigin.Begin);\n            using (var rdr = new StreamReader(_context.Response.Body))\n            {\n                var html = rdr.ReadToEnd();\n                html.Should().Contain(\"<script id='cookie-name' type='application/json'>foobar</script>\");\n            }\n        }\n\n        [Fact]\n        public async Task form_post_mode_should_add_unsafe_inline_for_csp_level_1()\n        {\n            _options.Csp.Level = CspLevel.One;\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"script-src 'unsafe-inline' 'sha256-fa5rxHhZ799izGRP38+h4ud5QXNT0SFaFlh4eqDumBI='\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].First().Should().Contain(\"script-src 'unsafe-inline' 'sha256-fa5rxHhZ799izGRP38+h4ud5QXNT0SFaFlh4eqDumBI='\");\n        }\n\n        [Fact]\n        public async Task form_post_mode_should_not_add_deprecated_header_when_it_is_disabled()\n        {\n            _options.Csp.AddDeprecatedHeader = false;\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"script-src 'sha256-fa5rxHhZ799izGRP38+h4ud5QXNT0SFaFlh4eqDumBI='\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].Should().BeEmpty();\n        }\n\n        [Theory]\n        [InlineData(\"foobar\")]\n        [InlineData(\"morefoobar\")]\n\n        public async Task can_change_cached_cookiename(string cookieName)\n        {\n            _options.Authentication.CheckSessionCookieName = cookieName;\n            await _subject.ExecuteAsync(_context);\n            _context.Response.Body.Seek(0, SeekOrigin.Begin);\n            using (var rdr = new StreamReader(_context.Response.Body))\n            {\n                var html = rdr.ReadToEnd();\n                html.Should().Contain($\"<script id='cookie-name' type='application/json'>{cookieName}</script>\");\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/Results/EndSessionCallbackResultTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.IO;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Endpoints.Results;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Endpoints.Results\n{\n    public class EndSessionCallbackResultTests\n    {\n        private EndSessionCallbackResult _subject;\n\n        private EndSessionCallbackValidationResult _result = new EndSessionCallbackValidationResult();\n        private IdentityServerOptions _options = TestIdentityServerOptions.Create();\n\n        private DefaultHttpContext _context = new DefaultHttpContext();\n\n        public EndSessionCallbackResultTests()\n        {\n            _context.SetIdentityServerOrigin(\"https://server\");\n            _context.SetIdentityServerBasePath(\"/\");\n            _context.Response.Body = new MemoryStream();\n\n            _subject = new EndSessionCallbackResult(_result, _options);\n        }\n\n        [Fact]\n        public async Task error_should_return_400()\n        {\n            _result.IsError = true;\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.StatusCode.Should().Be(400);\n        }\n\n        [Fact]\n        public async Task success_should_render_html_and_iframes()\n        {\n            _result.IsError = false;\n            _result.FrontChannelLogoutUrls = new string[] { \"http://foo.com\", \"http://bar.com\" };\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.ContentType.Should().StartWith(\"text/html\");\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"no-store\");\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"no-cache\");\n            _context.Response.Headers[\"Cache-Control\"].First().Should().Contain(\"max-age=0\");\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"default-src 'none';\");\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"style-src 'sha256-u+OupXgfekP+x/f6rMdoEAspPCYUtca912isERnoEjY=';\");\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"frame-src http://foo.com http://bar.com\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].First().Should().Contain(\"default-src 'none';\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].First().Should().Contain(\"style-src 'sha256-u+OupXgfekP+x/f6rMdoEAspPCYUtca912isERnoEjY=';\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].First().Should().Contain(\"frame-src http://foo.com http://bar.com\");\n            _context.Response.Body.Seek(0, SeekOrigin.Begin);\n            using (var rdr = new StreamReader(_context.Response.Body))\n            {\n                var html = rdr.ReadToEnd();\n                html.Should().Contain(\"<iframe src='http://foo.com'></iframe>\");\n                html.Should().Contain(\"<iframe src='http://bar.com'></iframe>\");\n            }\n        }\n\n        [Fact]\n        public async Task fsuccess_should_add_unsafe_inline_for_csp_level_1()\n        {\n            _result.IsError = false;\n\n            _options.Csp.Level = CspLevel.One;\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"style-src 'unsafe-inline' 'sha256-u+OupXgfekP+x/f6rMdoEAspPCYUtca912isERnoEjY='\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].First().Should().Contain(\"style-src 'unsafe-inline' 'sha256-u+OupXgfekP+x/f6rMdoEAspPCYUtca912isERnoEjY='\");\n        }\n\n        [Fact]\n        public async Task form_post_mode_should_not_add_deprecated_header_when_it_is_disabled()\n        {\n            _result.IsError = false;\n\n            _options.Csp.AddDeprecatedHeader = false;\n\n            await _subject.ExecuteAsync(_context);\n\n            _context.Response.Headers[\"Content-Security-Policy\"].First().Should().Contain(\"style-src 'sha256-u+OupXgfekP+x/f6rMdoEAspPCYUtca912isERnoEjY='\");\n            _context.Response.Headers[\"X-Content-Security-Policy\"].Should().BeEmpty();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Endpoints/Results/EndSessionResultTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Endpoints.Results;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.AspNetCore.WebUtilities;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Endpoints.Results\n{\n    public class EndSessionResultTests\n    {\n        private EndSessionResult _subject;\n\n        private EndSessionValidationResult _result = new EndSessionValidationResult();\n        private IdentityServerOptions _options = new IdentityServerOptions();\n        private MockMessageStore<LogoutMessage> _mockLogoutMessageStore = new MockMessageStore<LogoutMessage>();\n\n        private DefaultHttpContext _context = new DefaultHttpContext();\n\n        public EndSessionResultTests()\n        {\n            _context.SetIdentityServerOrigin(\"https://server\");\n            _context.SetIdentityServerBasePath(\"/\");\n\n            _options.UserInteraction.LogoutUrl = \"~/logout\";\n            _options.UserInteraction.LogoutIdParameter = \"logoutId\";\n\n            _subject = new EndSessionResult(_result, _options, new StubClock(), _mockLogoutMessageStore);\n        }\n\n        [Fact]\n        public async Task validated_signout_should_pass_logout_message()\n        {\n            _result.IsError = false;\n            _result.ValidatedRequest = new ValidatedEndSessionRequest\n            {\n                Client = new Client\n                {\n                    ClientId = \"client\"\n                },\n                PostLogOutUri = \"http://client/post-logout-callback\"\n            };\n\n            await _subject.ExecuteAsync(_context);\n\n            _mockLogoutMessageStore.Messages.Count.Should().Be(1);\n            var location = _context.Response.Headers[\"Location\"].Single();\n            var query = QueryHelpers.ParseQuery(new Uri(location).Query);\n\n            location.Should().StartWith(\"https://server/logout\");\n            query[\"logoutId\"].First().Should().Be(_mockLogoutMessageStore.Messages.First().Key);\n        }\n\n        [Fact]\n        public async Task unvalidated_signout_should_not_pass_logout_message()\n        {\n            _result.IsError = false;\n\n            await _subject.ExecuteAsync(_context);\n\n            _mockLogoutMessageStore.Messages.Count.Should().Be(0);\n            var location = _context.Response.Headers[\"Location\"].Single();\n            var query = QueryHelpers.ParseQuery(new Uri(location).Query);\n\n            location.Should().StartWith(\"https://server/logout\");\n            query.Count.Should().Be(0);\n        }\n\n        [Fact]\n        public async Task error_result_should_not_pass_logout_message()\n        {\n            _result.IsError = true;\n            _result.ValidatedRequest = new ValidatedEndSessionRequest\n            {\n                Client = new Client\n                {\n                    ClientId = \"client\"\n                },\n                PostLogOutUri = \"http://client/post-logout-callback\"\n            };\n\n            await _subject.ExecuteAsync(_context);\n\n            _mockLogoutMessageStore.Messages.Count.Should().Be(0);\n            var location = _context.Response.Headers[\"Location\"].Single();\n            var query = QueryHelpers.ParseQuery(new Uri(location).Query);\n\n            location.Should().StartWith(\"https://server/logout\");\n            query.Count.Should().Be(0);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Extensions/ApiResourceSigningAlgorithmSelectionTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing FluentAssertions;\nusing IdentityServer8.Models;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Extensions\n{\n    public class ApiResourceSigningAlgorithmSelectionTests\n    {\n        [Fact]\n        public void Single_resource_no_allowed_algorithms_set_should_return_empty_list()\n        {\n            var resource = new ApiResource();\n\n            var allowedAlgorithms = new List<ApiResource> { resource }.FindMatchingSigningAlgorithms();\n\n            allowedAlgorithms.Count().Should().Be(0);\n        }\n        \n        [Fact]\n        public void Two_resources_no_allowed_algorithms_set_should_return_empty_list()\n        {\n            var resource1 = new ApiResource();\n            var resource2 = new ApiResource();\n\n            var allowedAlgorithms = new List<ApiResource> { resource1, resource2 }.FindMatchingSigningAlgorithms();\n\n            allowedAlgorithms.Count().Should().Be(0);\n        }\n        \n        [Theory]\n        [InlineData(new [] { \"A\" }, new [] { \"A\" }, \n                    new [] { \"A\" })]\n        [InlineData(new [] { \"A\", \"B\" }, new [] { \"A\", \"B\" }, \n                    new [] { \"A\", \"B\" })]\n        [InlineData(new [] { \"A\", \"B\", \"C\" }, new [] { \"A\", \"B\", \"C\" }, \n                    new [] { \"A\", \"B\", \"C\" })]\n\n        [InlineData(new [] { \"A\", \"B\" }, new [] { \"A\", \"D\" }, \n                    new [] { \"A\" })]\n        [InlineData(new [] { \"A\", \"B\", \"C\" }, new [] { \"A\", \"B\", \"Z\" }, \n                    new [] { \"A\", \"B\" })]\n\n        [InlineData(new string[] { }, new [] { \"B\" },\n                    new string[] { \"B\" })]\n        [InlineData(new string[] { }, new [] { \"C\", \"D\" },\n                    new string[] { \"C\", \"D\" })]\n\n        [InlineData(new [] { \"A\" }, new [] { \"B\" }, \n                    new string[] { })]\n        [InlineData(new [] { \"A\", \"B\" }, new [] { \"C\", \"D\" }, \n                    new string[] { })]\n        public void Two_resources_with_allowed_algorithms_set_should_return_right_values(\n            string[] resource1Algorithms, string[] resource2Algorithms, \n            string[] expectedAlgorithms)\n        {\n            var resource1 = new ApiResource()\n            {\n                AllowedAccessTokenSigningAlgorithms = resource1Algorithms\n            };\n            \n            var resource2 = new ApiResource\n            {\n                AllowedAccessTokenSigningAlgorithms = resource2Algorithms\n            };\n\n            if (expectedAlgorithms.Any())\n            {\n                var allowedAlgorithms = new List<ApiResource> { resource1, resource2 }.FindMatchingSigningAlgorithms();\n                allowedAlgorithms.Should().BeEquivalentTo(expectedAlgorithms);\n            }\n            else\n            {\n                Action act = () => new List<ApiResource> { resource1, resource2 }.FindMatchingSigningAlgorithms();\n                act.Should().Throw<InvalidOperationException>();\n            }\n        }\n        \n        [Theory]\n        [InlineData(new [] { \"A\" }, new [] { \"A\" }, new [] { \"A\" }, \n            new [] { \"A\" })]\n        [InlineData(new [] { \"A\", \"B\" }, new [] { \"A\", \"B\" }, new [] { \"A\", \"B\" }, \n            new [] { \"A\", \"B\" })]\n        [InlineData(new [] { \"A\", \"B\", \"C\" }, new [] { \"A\", \"B\", \"C\" }, new [] { \"A\", \"B\", \"C\" }, \n            new [] { \"A\", \"B\", \"C\" })]\n        \n        [InlineData(new [] { \"A\", \"B\" }, new [] { \"A\", \"D\" }, new [] { \"A\", \"E\" } ,\n                    new [] { \"A\" })]\n        [InlineData(new [] { \"A\", \"B\", \"X\" }, new [] { \"A\", \"B\", \"Y\" }, new [] { \"A\", \"B\", \"Z\" },\n                    new [] { \"A\", \"B\" })]\n        [InlineData(new [] { \"A\", \"B\", \"X\" }, new [] { \"C\", \"D\", \"X\" }, new [] { \"E\", \"F\", \"X\" },\n                    new [] { \"X\" })]\n\n        [InlineData(new[] { \"A\", \"B\" }, new[] { \"A\", \"D\" }, new string[] { },\n                    new[] { \"A\" })]\n        [InlineData(new[] { \"A\", \"B\" }, new[] { \"A\", \"C\", \"B\" }, new string[] { },\n                    new[] { \"A\", \"B\" })]\n        [InlineData(new[] { \"A\", \"B\" }, new string[] { }, new string[] { },\n                    new[] { \"A\", \"B\" })]\n\n        [InlineData(new [] { \"A\" }, new [] { \"B\" }, new [] { \"C\" }, \n            new string[] { })]\n        [InlineData(new [] { \"A\", \"B\" }, new [] { \"C\", \"D\" }, new [] { \"X\", \"Y\" }, \n            new string[] { })]\n        [InlineData(new [] { \"A\", \"B\", \"C\" }, new [] { \"C\", \"D\", \"E\" }, new [] { \"E\", \"F\", \"G\" },\n                    new string[] { })]\n        public void Three_resources_with_allowed_algorithms_set_should_return_right_values(\n            string[] resource1Algorithms, string[] resource2Algorithms, string[] resource3Algorithms, \n            string[] expectedAlgorithms)\n        {\n            var resource1 = new ApiResource()\n            {\n                AllowedAccessTokenSigningAlgorithms = resource1Algorithms\n            };\n            \n            var resource2 = new ApiResource\n            {\n                AllowedAccessTokenSigningAlgorithms = resource2Algorithms\n            };\n            \n            var resource3 = new ApiResource\n            {\n                AllowedAccessTokenSigningAlgorithms = resource3Algorithms\n            };\n\n            if (expectedAlgorithms.Any())\n            {\n                var allowedAlgorithms = new List<ApiResource> {resource1, resource2, resource3}.FindMatchingSigningAlgorithms();\n                allowedAlgorithms.Should().BeEquivalentTo(expectedAlgorithms);\n            }\n            else\n            {\n                Action act = () => new List<ApiResource> {resource1, resource2, resource3}.FindMatchingSigningAlgorithms();\n                act.Should().Throw<InvalidOperationException>();\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Extensions/EndpointOptionsExtensionsTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Hosting;\nusing Xunit;\nusing static IdentityServer8.Constants;\n\nnamespace IdentityServer.UnitTests.Extensions\n{\n    public class EndpointOptionsExtensionsTests\n    {\n        private readonly EndpointsOptions _options = new EndpointsOptions();\n\n        [Theory]\n        [InlineData(true)]\n        [InlineData(false)]\n        public void IsEndpointEnabledShouldReturnExpectedForAuthorizeEndpoint(bool expectedIsEndpointEnabled)\n        {\n            _options.EnableAuthorizeEndpoint = expectedIsEndpointEnabled;\n\n            Assert.Equal(\n                expectedIsEndpointEnabled,\n                _options.IsEndpointEnabled(\n                    CreateTestEndpoint(EndpointNames.Authorize)));\n        }\n\n        [Theory]\n        [InlineData(true)]\n        [InlineData(false)]\n        public void IsEndpointEnabledShouldReturnExpectedForCheckSessionEndpoint(bool expectedIsEndpointEnabled)\n        {\n            _options.EnableCheckSessionEndpoint = expectedIsEndpointEnabled;\n\n            Assert.Equal(\n                expectedIsEndpointEnabled,\n                _options.IsEndpointEnabled(\n                    CreateTestEndpoint(EndpointNames.CheckSession)));\n        }\n\n        [Theory]\n        [InlineData(true)]\n        [InlineData(false)]\n        public void IsEndpointEnabledShouldReturnExpectedForDeviceAuthorizationEndpoint(bool expectedIsEndpointEnabled)\n        {\n            _options.EnableDeviceAuthorizationEndpoint = expectedIsEndpointEnabled;\n\n            Assert.Equal(\n                expectedIsEndpointEnabled,\n                _options.IsEndpointEnabled(\n                    CreateTestEndpoint(EndpointNames.DeviceAuthorization)));\n        }\n\n        [Theory]\n        [InlineData(true)]\n        [InlineData(false)]\n        public void IsEndpointEnabledShouldReturnExpectedForDiscoveryEndpoint(bool expectedIsEndpointEnabled)\n        {\n            _options.EnableDiscoveryEndpoint = expectedIsEndpointEnabled;\n\n            Assert.Equal(\n                expectedIsEndpointEnabled,\n                _options.IsEndpointEnabled(\n                    CreateTestEndpoint(EndpointNames.Discovery)));\n        }\n\n        [Theory]\n        [InlineData(true)]\n        [InlineData(false)]\n        public void IsEndpointEnabledShouldReturnExpectedForEndSessionEndpoint(bool expectedIsEndpointEnabled)\n        {\n            _options.EnableEndSessionEndpoint = expectedIsEndpointEnabled;\n\n            Assert.Equal(\n                expectedIsEndpointEnabled,\n                _options.IsEndpointEnabled(\n                    CreateTestEndpoint(EndpointNames.EndSession)));\n        }\n\n        [Theory]\n        [InlineData(true)]\n        [InlineData(false)]\n        public void IsEndpointEnabledShouldReturnExpectedForIntrospectionEndpoint(bool expectedIsEndpointEnabled)\n        {\n            _options.EnableIntrospectionEndpoint = expectedIsEndpointEnabled;\n\n            Assert.Equal(\n                expectedIsEndpointEnabled,\n                _options.IsEndpointEnabled(\n                    CreateTestEndpoint(EndpointNames.Introspection)));\n        }\n\n        [Theory]\n        [InlineData(true)]\n        [InlineData(false)]\n        public void IsEndpointEnabledShouldReturnExpectedForTokenEndpoint(bool expectedIsEndpointEnabled)\n        {\n            _options.EnableTokenEndpoint = expectedIsEndpointEnabled;\n\n            Assert.Equal(\n                expectedIsEndpointEnabled,\n                _options.IsEndpointEnabled(\n                    CreateTestEndpoint(EndpointNames.Token)));\n        }\n\n        [Theory]\n        [InlineData(true)]\n        [InlineData(false)]\n        public void IsEndpointEnabledShouldReturnExpectedForRevocationEndpoint(bool expectedIsEndpointEnabled)\n        {\n            _options.EnableTokenRevocationEndpoint = expectedIsEndpointEnabled;\n\n            Assert.Equal(\n                expectedIsEndpointEnabled,\n                _options.IsEndpointEnabled(\n                    CreateTestEndpoint(EndpointNames.Revocation)));\n        }\n\n        [Theory]\n        [InlineData(true)]\n        [InlineData(false)]\n        public void IsEndpointEnabledShouldReturnExpectedForUserInfoEndpoint(bool expectedIsEndpointEnabled)\n        {\n            _options.EnableUserInfoEndpoint = expectedIsEndpointEnabled;\n\n            Assert.Equal(\n                expectedIsEndpointEnabled,\n                _options.IsEndpointEnabled(\n                    CreateTestEndpoint(EndpointNames.UserInfo)));\n        }\n\n        private Endpoint CreateTestEndpoint(string name)\n        {\n            return new Endpoint(name, \"\", null);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Extensions/HttpRequestExtensionsTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityServer8.Extensions;\nusing Microsoft.AspNetCore.Http;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Extensions\n{\n    public class HttpRequestExtensionsTests\n    {\n        [Fact]\n        public void GetCorsOrigin_valid_cors_request_should_return_cors_origin()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Scheme = \"http\";\n            ctx.Request.Host = new HostString(\"foo\");\n            ctx.Request.Headers.Append(\"Origin\", \"http://bar\");\n\n            ctx.Request.GetCorsOrigin().Should().Be(\"http://bar\");\n        }\n\n        [Fact]\n        public void GetCorsOrigin_origin_from_same_host_should_not_return_cors_origin()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Scheme = \"http\";\n            ctx.Request.Host = new HostString(\"foo\");\n            ctx.Request.Headers.Append(\"Origin\", \"http://foo\");\n\n            ctx.Request.GetCorsOrigin().Should().BeNull();\n        }\n\n        [Fact]\n        public void GetCorsOrigin_no_origin_should_not_return_cors_origin()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Scheme = \"http\";\n            ctx.Request.Host = new HostString(\"foo\");\n\n            ctx.Request.GetCorsOrigin().Should().BeNull();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Extensions/IResourceStoreExtensionsTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Extensions\n{\n    public class IResourceStoreExtensionsTests\n    {\n        [Fact]\n        public async Task GetAllEnabledResourcesAsync_on_duplicate_identity_scopes_should_fail()\n        {\n            var store = new MockResourceStore()\n            {\n                IdentityResources = {\n                    new IdentityResource { Name = \"A\" },\n                    new IdentityResource { Name = \"A\" } }\n            };\n\n            Func<Task> a = async () => await store.GetAllEnabledResourcesAsync();\n            (await a.Should().ThrowAsync<Exception>()).And.Message.ToLowerInvariant().Should().Contain(\"duplicate\").And.Contain(\"identity scopes\");\n        }\n\n        [Fact]\n        public async Task GetAllEnabledResourcesAsync_without_duplicate_identity_scopes_should_succeed()\n        {\n            var store = new MockResourceStore()\n            {\n                IdentityResources = {\n                    new IdentityResource { Name = \"A\" },\n                    new IdentityResource { Name = \"B\" } }\n            };\n\n            await store.GetAllEnabledResourcesAsync();\n        }\n\n        [Fact]\n        public async Task GetAllEnabledResourcesAsync_on_duplicate_api_resources_should_fail()\n        {\n            var store = new MockResourceStore()\n            {\n                ApiResources = { new ApiResource { Name = \"a\" }, new ApiResource { Name = \"a\" } }\n            };\n\n            Func<Task> a = async () => await store.GetAllEnabledResourcesAsync();\n            (await a.Should().ThrowAsync<Exception>())\n                .And.Message.ToLowerInvariant().Should().Contain(\"duplicate\").And.Contain(\"api resources\");\n        }\n\n        [Fact]\n        public async Task GetAllEnabledResourcesAsync_without_duplicate_api_scopes_should_succeed()\n        {\n            var store = new MockResourceStore()\n            {\n                ApiResources = { new ApiResource(\"A\"), new ApiResource(\"B\") }\n            };\n\n            await store.GetAllEnabledResourcesAsync();\n        }\n\n        [Fact]\n        public async Task FindResourcesByScopeAsync_on_duplicate_identity_scopes_should_fail()\n        {\n            var store = new MockResourceStore()\n            {\n                IdentityResources = {\n                    new IdentityResource { Name = \"A\" },\n                    new IdentityResource { Name = \"A\" } }\n            };\n\n            Func<Task> a = async () => await store.FindResourcesByScopeAsync(new string[] { \"A\" });\n            (await a.Should().ThrowAsync<Exception>()).And.Message.ToLowerInvariant().Should().Contain(\"duplicate\").And.Contain(\"identity scopes\");\n        }\n\n        [Fact]\n        public async Task FindResourcesByScopeAsync_without_duplicate_identity_scopes_should_succeed()\n        {\n            var store = new MockResourceStore()\n            {\n                IdentityResources = {\n                    new IdentityResource { Name = \"A\" },\n                    new IdentityResource { Name = \"B\" } }\n            };\n\n            await store.FindResourcesByScopeAsync(new string[] { \"A\" });\n        }\n\n        [Fact]\n        public async Task FindResourcesByScopeAsync_on_duplicate_api_scopes_should_succeed()\n        {\n            var store = new MockResourceStore()\n            {\n                ApiResources = { \n                    new ApiResource { Name = \"api1\", Scopes = { \"a\" } },\n                    new ApiResource() { Name = \"api2\", Scopes = { \"a\" } },\n                },\n                ApiScopes = { \n                    new ApiScope(\"a\") \n                } \n            };\n\n            var result = await store.FindResourcesByScopeAsync(new string[] { \"a\" });\n            result.ApiResources.Count.Should().Be(2);\n            result.ApiScopes.Count.Should().Be(1);\n            result.ApiResources.Select(x => x.Name).Should().BeEquivalentTo(new[] { \"api1\", \"api2\" });\n            result.ApiScopes.Select(x => x.Name).Should().BeEquivalentTo(new[] { \"a\" });\n        }\n\n        [Fact]\n        public async Task FindResourcesByScopeAsync_without_duplicate_api_scopes_should_succeed()\n        {\n            var store = new MockResourceStore()\n            {\n                ApiResources = { new ApiResource(\"A\"), new ApiResource(\"B\") }\n            };\n\n            await store.FindResourcesByScopeAsync(new string[] { \"A\" });\n        }\n\n        [Fact]\n        public async Task FindResourcesByScopeAsync_with_duplicate_api_scopes_on_single_api_resource_should_succeed_and_only_reuturn_one_resource()\n        {\n            var store = new MockResourceStore()\n            {\n                ApiResources = { \n                    new ApiResource { \n                        Name = \"api1\", Scopes = { \"a\", \"a\" }\n                    }\n                },\n                ApiScopes = {\n                    new ApiScope(\"a\"),\n                }\n            };\n\n            var result = await store.FindResourcesByScopeAsync(new string[] { \"a\" });\n            result.ApiResources.Count.Should().Be(1);\n        }\n\n        public class MockResourceStore : IResourceStore\n        {\n            public List<IdentityResource> IdentityResources { get; set; } = new List<IdentityResource>();\n            public List<ApiResource> ApiResources { get; set; } = new List<ApiResource>();\n            public List<ApiScope> ApiScopes { get; set; } = new List<ApiScope>();\n\n            public Task<IEnumerable<ApiResource>> FindApiResourcesByNameAsync(IEnumerable<string> names)\n            {\n                var apis = from a in ApiResources\n                          where names.Contains(a.Name)\n                          select a;\n                return Task.FromResult(apis);\n            }\n\n            public Task<IEnumerable<ApiResource>> FindApiResourcesByScopeNameAsync(IEnumerable<string> names)\n            {\n                if (names == null) throw new ArgumentNullException(nameof(names));\n\n                var api = from a in ApiResources\n                          where a.Scopes.Any(x => names.Contains(x))\n                          select a;\n\n                return Task.FromResult(api);\n            }\n\n            public Task<IEnumerable<IdentityResource>> FindIdentityResourcesByScopeNameAsync(IEnumerable<string> names)\n            {\n                if (names == null) throw new ArgumentNullException(nameof(names));\n\n                var identity = from i in IdentityResources\n                               where names.Contains(i.Name)\n                               select i;\n\n                return Task.FromResult(identity);\n            }\n\n            public Task<IEnumerable<ApiScope>> FindApiScopesByNameAsync(IEnumerable<string> scopeNames)\n            {\n                var q = from x in ApiScopes\n                        where scopeNames.Contains(x.Name)\n                        select x;\n                return Task.FromResult(q);\n            }\n\n            public Task<Resources> GetAllResourcesAsync()\n            {\n                var result = new Resources(IdentityResources, ApiResources, ApiScopes);\n                return Task.FromResult(result);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Extensions/IdentityServerBuilderExtensionsCacheStoreTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Microsoft.Extensions.DependencyInjection;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Extensions\n{\n    public class IdentityServerBuilderExtensionsCacheStoreTests\n    {\n        private class CustomClientStore: IClientStore\n        {\n            public Task<Client> FindClientByIdAsync(string clientId)\n            {\n                throw new System.NotImplementedException();\n            }\n        }\n\n        private class CustomResourceStore : IResourceStore\n        {\n            public Task<IEnumerable<IdentityResource>> FindIdentityResourcesByScopeNameAsync(IEnumerable<string> scopeNames)\n            {\n                throw new System.NotImplementedException();\n            }\n\n            public Task<IEnumerable<ApiResource>> FindApiResourcesByScopeNameAsync(IEnumerable<string> scopeNames)\n            {\n                throw new System.NotImplementedException();\n            }\n\n            public Task<IEnumerable<ApiResource>> FindApiResourcesByNameAsync(IEnumerable<string> names)\n            {\n                throw new System.NotImplementedException();\n            }\n\n            public Task<Resources> GetAllResourcesAsync()\n            {\n                throw new System.NotImplementedException();\n            }\n\n            public Task<IEnumerable<ApiScope>> FindApiScopesByNameAsync(IEnumerable<string> scopeNames)\n            {\n                throw new System.NotImplementedException();\n            }\n        }\n\n        [Fact]\n        public void AddClientStoreCache_should_add_concrete_iclientstore_implementation()\n        {\n            var services = new ServiceCollection();\n            var identityServerBuilder = new IdentityServerBuilder(services);\n\n            identityServerBuilder.AddClientStoreCache<CustomClientStore>();\n\n            services.Any(x => x.ImplementationType == typeof(CustomClientStore)).Should().BeTrue();\n        }\n\n        [Fact]\n        public void AddResourceStoreCache_should_attempt_to_register_iresourcestore_implementation()\n        {\n            var services = new ServiceCollection();\n            var identityServerBuilder = new IdentityServerBuilder(services);\n\n            identityServerBuilder.AddResourceStoreCache<CustomResourceStore>();\n\n            services.Any(x => x.ImplementationType == typeof(CustomResourceStore)).Should().BeTrue();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Extensions/IdentityServerBuilderExtensionsCryptoTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing Microsoft.Extensions.DependencyInjection;\nusing Microsoft.IdentityModel.Tokens;\nusing System;\nusing System.IO;\nusing System.Security.Cryptography;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Extensions\n{\n    public class IdentityServerBuilderExtensionsCryptoTests\n    {\n        [Fact]\n        public void AddSigningCredential_with_json_web_key_containing_asymmetric_key_should_succeed()\n        {\n            IServiceCollection services = new ServiceCollection();\n            IIdentityServerBuilder identityServerBuilder = new IdentityServerBuilder(services);\n\n            String json =\n            @\"{\n                \"\"alg\"\" : \"\"RS256\"\",\n                \"\"kty\"\" : \"\"RSA\"\",\n                \"\"use\"\" : \"\"sig\"\",\n                \"\"d\"\" : \"\"KGGNkbbgm2hNMqW6fP1fmcWwEBy77WOJIPAXnDJ0KxNTtqDF8K5ULj7EElHO1A8ZnNl1Ey/x//G9lJCOQUU9wmj010dOSsW0NBbR5NtRtLLuVbkVdyft53PGeTQs+1S3c51fz9jojtNqmlfXSANPFOH6QhxmzpTx3KLsf/TpCzblkSrEGOOqCCvVdl7ybTcB230jNhh3JoL7po1rvxKtoOM4a/Bs0NtKj7e+VaHcf0GLnBPJYetsHu43ZfNejJeDoouaXZzeVEklY3B0pe10OTCIOu0JUKGZxNekklRIo1WSEYdL+CJfrSKWIv8bLj6xSr5zrASvWODyH443LN6ZvQ==\"\",\n                \"\"e\"\" : \"\"AQAB\"\",\n                \"\"n\"\" : \"\"q7mZfquRq8tzg/5slbNdQmrosNN/mFXS25dbSPm11qEDCgZa452KkO8+hvMtqa92QaqdlmalSF8+FRDOz3grDR5NtmnXZxuKnp+raKfzpC6hCvh2JSIe/J9enmsMM4YeI4d1FOSDwhJlZIYMdMnqG/VJtO1LSHjOaF3XN31ANKF0nPAsmr2/WysiQlxnxxiikLEnsFuNdS615ODDXFGTQ1E+zc4zVur4/Ox0cllPwHPA4PqoIgdPJPL+xM9IOIXuAGtsp4CYoxT6VWaRrALIZXXDY806WGTuctq4KKot6FGL9HQte2hRLl4E/r8SzIK86U3wRwrBe7saK+XUXoP0gQ=\"\",\n\t\t        \"\"p\"\" :\t\"\"25dkucyCSqxRcJpRrhl7PXqw7wqBZeLQgYlZLpK493PdM8pFfq+/LK1hFtxIjdFKqXS/TOikB4YCBMEH0Im3HZ8Lo0dub3SWNhdegJyRjMbcoO+A9YSODEj7DFaNpZtdmtDi1n6etJm66ctPSR20NNpzoYZuaJ92fVQiKiOh6Qs=\"\",\n                \"\"q\"\" : \"\"yDKBrS8l1DOx4dwP9hdwhqZJ3XahidiIZSL7m46I/6+cjaki/1mtNiA60MOgqTKegP7Fo7jAYvliqQwnvVGmQvLv19cfKywlIuKN9DdkLHnKh75hfo7aakEbO7GJ5zVgsNnKOdf8wvpclfvIuRDEVva4cksPzsJy6K7C8ENCSCM=\"\",\n                \"\"dp\"\" :  \"\"GlYJ6o6wgawxCEQ5z5uWwETau5CS/Fk7kI2ceI14SZVHzlJQC2WglAcnQcqhmQCk57Xsy5iLM6vKyi8sdMJPh+nvR2HlyNA+w7YBy4L7odqn01VmLgv7zVVjZpNq4ZXEoDC1Q+xjtF1LoYaUt7wsRLp+a7znuPyHBXj1sAAeBwk=\"\",\n                \"\"dq\"\" :  \"\"W8OK3S83T8VCTBzq1Ap6cb3XLcQq11yBaJpYaj0zXr/IKsbUW+dnFeBAFWEWS3gAX3Bod1tAFB3rs0D3FjhO1XE1ruHUT520iAEAwGiDaj+JLh994NzqELo3GW2PoIM/BtFNeKYgHd9UgQsgPnQJCzOb6Aev/z3yHeW9RRQPVbE=\"\",\n                \"\"qi\"\" :  \"\"w4KdmiDN1GtK71JxaasqmEKPNfV3v2KZDXKnfyhUsdx/idKbdTVjvMOkxFPJ4FqV4yIVn06f3QHTm4NEG18Diqxsrzd6kXQIHOa858tLsCcmt9FoGfrgCFgVceh3K/Zah/r8rl9Y61u0Z1kZumwMvFpFE+mVU01t9HgTEAVkHTc=\"\"\n            }\";\n\n            JsonWebKey jsonWebKey = new JsonWebKey(json);\n            SigningCredentials credentials = new SigningCredentials(jsonWebKey, jsonWebKey.Alg);\n            identityServerBuilder.AddSigningCredential(credentials);\n        }\n\n        [Fact]\n        public void AddSigningCredential_with_json_web_key_containing_symmetric_key_should_throw_exception()\n        {\n            IServiceCollection services = new ServiceCollection();\n            IIdentityServerBuilder identityServerBuilder = new IdentityServerBuilder(services);\n\n            String json =\n            @\"{\n                \"\"alg\"\" : \"\"HS256\"\",\n                \"\"kty\"\" : \"\"oct\"\",\n                \"\"use\"\" : \"\"sig\"\",\n                \"\"k\"\" : \"\"y5FHaQFtC294HLAtPXAcMkxZ5gHzCq24223vSYQUrDuu-3CUw7UzPru-AX30ubeB2IM_gUsNQ80bX22wwSk_3LC6XxYxqeGJZSeoQqHG0VNbaWCVkqeuB_HOiL1-ksPfGT-o8_A_Uv-6zi2NaEOYpnIyff5LpdW__LhiE-bhIenaw7GhoXSAfsGEZfNZpUUOU35NAiN2dv0T5vptb87wkL1I2zLhV0pdLvWsDWgQPINEa8bbCA_mseBYpB1eioZvt0TZbp6CL9tiEoiikYV_F3IutrJ2SOWYtDNFeQ3sbyYP7zTzh9a2eyaM8ca5_q3qosI92AbZ7WpEFLa9cZ_O7g\"\"\n            }\";\n\n            JsonWebKey jsonWebKey = new JsonWebKey(json);\n            SigningCredentials credentials = new SigningCredentials(jsonWebKey, jsonWebKey.Alg);\n            Assert.Throws<InvalidOperationException>(() => identityServerBuilder.AddSigningCredential(credentials));\n        }\n\n        [Fact]\n        public void AddDeveloperSigningCredential_should_succeed()\n        {\n            IServiceCollection services = new ServiceCollection();\n            IIdentityServerBuilder identityServerBuilder = new IdentityServerBuilder(services);\n\n            identityServerBuilder.AddDeveloperSigningCredential();\n\n            //clean up... delete stored rsa key\n            var filename = Path.Combine(Directory.GetCurrentDirectory(), \"tempkey.rsa\");\n\n            if (File.Exists(filename))\n                File.Delete(filename);\n        }\n\n        [Fact]\n        public void AddDeveloperSigningCredential_should_succeed_when_called_multiple_times()\n        {\n            IServiceCollection services = new ServiceCollection();\n            IIdentityServerBuilder identityServerBuilder = new IdentityServerBuilder(services);\n\n            try\n            {\n                identityServerBuilder.AddDeveloperSigningCredential();\n\n                //calling a second time will try to load the saved rsa key from disk. An exception will be throw if the private key is not serialized properly.\n                identityServerBuilder.AddDeveloperSigningCredential();\n            }\n            finally\n            {\n                //clean up... delete stored rsa key\n                var filename = Path.Combine(Directory.GetCurrentDirectory(), \"tempkey.rsa\");\n\n                if (File.Exists(filename))\n                    File.Delete(filename);\n            }\n        }\n\n        [Theory]\n        [InlineData(Constants.CurveOids.P256, SecurityAlgorithms.EcdsaSha256)]\n        [InlineData(Constants.CurveOids.P384, SecurityAlgorithms.EcdsaSha384)]\n        [InlineData(Constants.CurveOids.P521, SecurityAlgorithms.EcdsaSha512)]\n        public void AddSigningCredential_with_valid_curve_should_succeed(string curveOid, string alg)\n        {\n            IServiceCollection services = new ServiceCollection();\n            IIdentityServerBuilder identityServerBuilder = new IdentityServerBuilder(services);\n\n            var key = new ECDsaSecurityKey(ECDsa.Create(\n                ECCurve.CreateFromOid(Oid.FromOidValue(curveOid, OidGroup.All))));\n\n            identityServerBuilder.AddSigningCredential(key, alg);\n        }\n\n        [Theory]\n        [InlineData(Constants.CurveOids.P256, SecurityAlgorithms.EcdsaSha512)]\n        [InlineData(Constants.CurveOids.P384, SecurityAlgorithms.EcdsaSha512)]\n        [InlineData(Constants.CurveOids.P521, SecurityAlgorithms.EcdsaSha256)]\n        public void AddSigningCredential_with_invalid_curve_should_throw_exception(string curveOid, string alg)\n        {\n            IServiceCollection services = new ServiceCollection();\n            IIdentityServerBuilder identityServerBuilder = new IdentityServerBuilder(services);\n\n            var key = new ECDsaSecurityKey(ECDsa.Create(\n                ECCurve.CreateFromOid(Oid.FromOidValue(curveOid, OidGroup.All))));\n\n            Assert.Throws<InvalidOperationException>(() => identityServerBuilder.AddSigningCredential(key, alg));\n        }\n\n\n\n        [Theory]\n        [InlineData(Constants.CurveOids.P256, SecurityAlgorithms.EcdsaSha256, JsonWebKeyECTypes.P256)]\n        [InlineData(Constants.CurveOids.P384, SecurityAlgorithms.EcdsaSha384, JsonWebKeyECTypes.P384)]\n        [InlineData(Constants.CurveOids.P521, SecurityAlgorithms.EcdsaSha512, JsonWebKeyECTypes.P521)]\n        public void AddSigningCredential_with_invalid_crv_value_should_throw_exception(string curveOid, string alg, string crv)\n        {\n            IServiceCollection services = new ServiceCollection();\n            IIdentityServerBuilder identityServerBuilder = new IdentityServerBuilder(services);\n\n            var key = new ECDsaSecurityKey(ECDsa.Create(\n                ECCurve.CreateFromOid(Oid.FromOidValue(curveOid, OidGroup.All))));\n            var parameters = key.ECDsa.ExportParameters(true);\n\n            var jsonWebKeyFromECDsa = new JsonWebKey()\n            {\n                Kty = JsonWebAlgorithmsKeyTypes.EllipticCurve,\n                Use = \"sig\",\n                Kid = key.KeyId,\n                KeyId = key.KeyId,\n                X = Base64UrlEncoder.Encode(parameters.Q.X),\n                Y = Base64UrlEncoder.Encode(parameters.Q.Y),\n                D = Base64UrlEncoder.Encode(parameters.D),\n                Crv = crv.Replace(\"-\", string.Empty),\n                Alg = SecurityAlgorithms.EcdsaSha256\n            };\n            Assert.Throws<InvalidOperationException>(() => identityServerBuilder.AddSigningCredential(jsonWebKeyFromECDsa, alg));\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Extensions/JwtPayloadCreationTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Security.Claims;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing Microsoft.AspNetCore.Authentication;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Extensions\n{\n    public class JwtPayloadCreationTests\n    {\n        private Token _token;\n        \n        public JwtPayloadCreationTests()\n        {\n            var claims = new List<Claim>\n            {\n                new Claim(JwtClaimTypes.Scope, \"scope1\"),\n                new Claim(JwtClaimTypes.Scope, \"scope2\"),\n                new Claim(JwtClaimTypes.Scope, \"scope3\"),\n            };\n            \n            _token = new Token(OidcConstants.TokenTypes.AccessToken)\n            {\n                CreationTime = DateTime.UtcNow,\n                Issuer = \"issuer\",\n                Lifetime = 60,\n                Claims = claims.Distinct(new ClaimComparer()).ToList(),\n                ClientId = \"client\"\n            };\n        }\n        \n        [Fact]\n        public void Should_create_scopes_as_array_by_default()\n        {\n            var options = new IdentityServerOptions();\n            var payload = _token.CreateJwtPayload(new SystemClock(), options, TestLogger.Create<JwtPayloadCreationTests>());\n\n            payload.Should().NotBeNull();\n            var scopes = payload.Claims.Where(c => c.Type == JwtClaimTypes.Scope).ToArray();\n            scopes.Count().Should().Be(3);\n            scopes[0].Value.Should().Be(\"scope1\");\n            scopes[1].Value.Should().Be(\"scope2\");\n            scopes[2].Value.Should().Be(\"scope3\");\n        }\n        \n        [Fact]\n        public void Should_create_scopes_as_string()\n        {\n            var options = new IdentityServerOptions\n            {\n                EmitScopesAsSpaceDelimitedStringInJwt = true\n            };\n            \n            var payload = _token.CreateJwtPayload(new SystemClock(), options, TestLogger.Create<JwtPayloadCreationTests>());\n\n            payload.Should().NotBeNull();\n            var scopes = payload.Claims.Where(c => c.Type == JwtClaimTypes.Scope).ToList();\n            scopes.Count().Should().Be(1);\n            scopes.First().Value.Should().Be(\"scope1 scope2 scope3\");\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Extensions/StringExtensionsTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Extensions;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Extensions\n{\n    public class StringExtensionsTests\n    {\n        private void CheckOrigin(string inputUrl, string expectedOrigin)\n        {\n            var actualOrigin = inputUrl.GetOrigin();\n            Assert.Equal(expectedOrigin, actualOrigin);\n        }\n\n        [Fact]\n        public void TestGetOrigin()\n        {\n            CheckOrigin(\"http://idsvr.com\", \"http://idsvr.com\");\n            CheckOrigin(\"http://idsvr.com/\", \"http://idsvr.com\");\n            CheckOrigin(\"http://idsvr.com/test\", \"http://idsvr.com\");\n            CheckOrigin(\"http://idsvr.com/test/resource\", \"http://idsvr.com\");\n            CheckOrigin(\"http://idsvr.com:8080\", \"http://idsvr.com:8080\");\n            CheckOrigin(\"http://idsvr.com:8080/\", \"http://idsvr.com:8080\");\n            CheckOrigin(\"http://idsvr.com:8080/test\", \"http://idsvr.com:8080\");\n            CheckOrigin(\"http://idsvr.com:8080/test/resource\", \"http://idsvr.com:8080\");\n            CheckOrigin(\"http://127.0.0.1\", \"http://127.0.0.1\");\n            CheckOrigin(\"http://127.0.0.1/\", \"http://127.0.0.1\");\n            CheckOrigin(\"http://127.0.0.1/test\", \"http://127.0.0.1\");\n            CheckOrigin(\"http://127.0.0.1/test/resource\", \"http://127.0.0.1\");\n            CheckOrigin(\"http://127.0.0.1:8080\", \"http://127.0.0.1:8080\");\n            CheckOrigin(\"http://127.0.0.1:8080/\", \"http://127.0.0.1:8080\");\n            CheckOrigin(\"http://127.0.0.1:8080/test\", \"http://127.0.0.1:8080\");\n            CheckOrigin(\"http://127.0.0.1:8080/test/resource\", \"http://127.0.0.1:8080\");\n            CheckOrigin(\"http://localhost\", \"http://localhost\");\n            CheckOrigin(\"http://localhost/\", \"http://localhost\");\n            CheckOrigin(\"http://localhost/test\", \"http://localhost\");\n            CheckOrigin(\"http://localhost/test/resource\", \"http://localhost\");\n            CheckOrigin(\"http://localhost:8080\", \"http://localhost:8080\");\n            CheckOrigin(\"http://localhost:8080/\", \"http://localhost:8080\");\n            CheckOrigin(\"http://localhost:8080/test\", \"http://localhost:8080\");\n            CheckOrigin(\"http://localhost:8080/test/resource\", \"http://localhost:8080\");\n            CheckOrigin(\"https://idsvr.com\", \"https://idsvr.com\");\n            CheckOrigin(\"https://idsvr.com/\", \"https://idsvr.com\");\n            CheckOrigin(\"https://idsvr.com/test\", \"https://idsvr.com\");\n            CheckOrigin(\"https://idsvr.com/test/resource\", \"https://idsvr.com\");\n            CheckOrigin(\"https://idsvr.com:8080\", \"https://idsvr.com:8080\");\n            CheckOrigin(\"https://idsvr.com:8080/\", \"https://idsvr.com:8080\");\n            CheckOrigin(\"https://idsvr.com:8080/test\", \"https://idsvr.com:8080\");\n            CheckOrigin(\"https://idsvr.com:8080/test/resource\", \"https://idsvr.com:8080\");\n            CheckOrigin(\"https://127.0.0.1\", \"https://127.0.0.1\");\n            CheckOrigin(\"https://127.0.0.1/\", \"https://127.0.0.1\");\n            CheckOrigin(\"https://127.0.0.1/test\", \"https://127.0.0.1\");\n            CheckOrigin(\"https://127.0.0.1/test/resource\", \"https://127.0.0.1\");\n            CheckOrigin(\"https://127.0.0.1:8080\", \"https://127.0.0.1:8080\");\n            CheckOrigin(\"https://127.0.0.1:8080/\", \"https://127.0.0.1:8080\");\n            CheckOrigin(\"https://127.0.0.1:8080/test\", \"https://127.0.0.1:8080\");\n            CheckOrigin(\"https://127.0.0.1:8080/test/resource\", \"https://127.0.0.1:8080\");\n            CheckOrigin(\"https://localhost\", \"https://localhost\");\n            CheckOrigin(\"https://localhost/\", \"https://localhost\");\n            CheckOrigin(\"https://localhost/test\", \"https://localhost\");\n            CheckOrigin(\"https://localhost/test/resource\", \"https://localhost\");\n            CheckOrigin(\"https://localhost:8080\", \"https://localhost:8080\");\n            CheckOrigin(\"https://localhost:8080/\", \"https://localhost:8080\");\n            CheckOrigin(\"https://localhost:8080/test\", \"https://localhost:8080\");\n            CheckOrigin(\"https://localhost:8080/test/resource\", \"https://localhost:8080\");\n            CheckOrigin(\"test://idsvr.com\", null);\n            CheckOrigin(\"test://idsvr.com/\", null);\n            CheckOrigin(\"test://idsvr.com/test\", null);\n            CheckOrigin(\"test://idsvr.com/test/resource\", null);\n            CheckOrigin(\"test://idsvr.com:8080\", null);\n            CheckOrigin(\"test://idsvr.com:8080/\", null);\n            CheckOrigin(\"test://idsvr.com:8080/test\", null);\n            CheckOrigin(\"test://idsvr.com:8080/test/resource\", null);\n            CheckOrigin(\"test://127.0.0.1\", null);\n            CheckOrigin(\"test://127.0.0.1/\", null);\n            CheckOrigin(\"test://127.0.0.1/test\", null);\n            CheckOrigin(\"test://127.0.0.1/test/resource\", null);\n            CheckOrigin(\"test://127.0.0.1:8080\", null);\n            CheckOrigin(\"test://127.0.0.1:8080/\", null);\n            CheckOrigin(\"test://127.0.0.1:8080/test\", null);\n            CheckOrigin(\"test://127.0.0.1:8080/test/resource\", null);\n            CheckOrigin(\"test://localhost\", null);\n            CheckOrigin(\"test://localhost/\", null);\n            CheckOrigin(\"test://localhost/test\", null);\n            CheckOrigin(\"test://localhost/test/resource\", null);\n            CheckOrigin(\"test://localhost:8080\", null);\n            CheckOrigin(\"test://localhost:8080/\", null);\n            CheckOrigin(\"test://localhost:8080/test\", null);\n            CheckOrigin(\"test://localhost:8080/test/resource\", null);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Extensions/ValidatedAuthorizeRequestExtensionsTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Extensions\n{\n    public class ValidatedAuthorizeRequestExtensionsTests\n    {\n        [Fact]\n        public void GetAcrValues_should_return_snapshot_of_values()\n        {\n            var request = new ValidatedAuthorizeRequest()\n            {\n                Raw = new System.Collections.Specialized.NameValueCollection()\n            };\n            request.AuthenticationContextReferenceClasses.Add(\"a\");\n            request.AuthenticationContextReferenceClasses.Add(\"b\");\n            request.AuthenticationContextReferenceClasses.Add(\"c\");\n\n            var acrs = request.GetAcrValues();\n            foreach(var acr in acrs)\n            {\n                request.RemoveAcrValue(acr);\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Hosting/EndpointRouterTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Hosting;\nusing Microsoft.AspNetCore.Http;\nusing Xunit;\nusing static IdentityServer8.Constants;\n\nnamespace IdentityServer.UnitTests.Hosting\n{\n    public class EndpointRouterTests\n    {\n        private Dictionary<string, IdentityServer8.Hosting.Endpoint> _pathMap;\n        private List<IdentityServer8.Hosting.Endpoint> _endpoints;\n        private IdentityServerOptions _options;\n        private EndpointRouter _subject;\n\n        public EndpointRouterTests()\n        {\n            _pathMap = new Dictionary<string, IdentityServer8.Hosting.Endpoint>();\n            _endpoints = new List<IdentityServer8.Hosting.Endpoint>();\n            _options = new IdentityServerOptions();\n            _subject = new EndpointRouter(_endpoints, _options, TestLogger.Create<EndpointRouter>());\n        }\n\n        [Fact]\n        public void Endpoint_ctor_requires_path_to_start_with_slash()\n        {\n            Action a = () => new IdentityServer8.Hosting.Endpoint(\"ep1\", \"ep1\", typeof(MyEndpointHandler));\n            a.Should().Throw<ArgumentException>();\n        }\n\n        [Fact]\n        public void Find_should_return_null_for_incorrect_path()\n        {\n            _endpoints.Add(new IdentityServer8.Hosting.Endpoint(\"ep1\", \"/ep1\", typeof(MyEndpointHandler)));\n            _endpoints.Add(new IdentityServer8.Hosting.Endpoint(\"ep2\", \"/ep2\", typeof(MyOtherEndpointHandler)));\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Path = new PathString(\"/wrong\");\n            ctx.RequestServices = new StubServiceProvider();\n\n            var result = _subject.Find(ctx);\n            result.Should().BeNull();\n        }\n\n        [Fact]\n        public void Find_should_find_path()\n        {\n            _endpoints.Add(new IdentityServer8.Hosting.Endpoint(\"ep1\", \"/ep1\", typeof(MyEndpointHandler)));\n            _endpoints.Add(new IdentityServer8.Hosting.Endpoint(\"ep2\", \"/ep2\", typeof(MyOtherEndpointHandler)));\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Path = new PathString(\"/ep1\");\n            ctx.RequestServices = new StubServiceProvider();\n\n            var result = _subject.Find(ctx);\n            result.Should().BeOfType<MyEndpointHandler>();\n        }\n\n        [Fact]\n        public void Find_should_not_find_nested_paths()\n        {\n            _endpoints.Add(new IdentityServer8.Hosting.Endpoint(\"ep1\", \"/ep1\", typeof(MyEndpointHandler)));\n            _endpoints.Add(new IdentityServer8.Hosting.Endpoint(\"ep2\", \"/ep2\", typeof(MyOtherEndpointHandler)));\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Path = new PathString(\"/ep1/subpath\");\n            ctx.RequestServices = new StubServiceProvider();\n\n            var result = _subject.Find(ctx);\n            result.Should().BeNull();\n        }\n\n        [Fact]\n        public void Find_should_find_first_registered_mapping()\n        {\n            _endpoints.Add(new IdentityServer8.Hosting.Endpoint(\"ep1\", \"/ep1\", typeof(MyEndpointHandler)));\n            _endpoints.Add(new IdentityServer8.Hosting.Endpoint(\"ep1\", \"/ep1\", typeof(MyOtherEndpointHandler)));\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Path = new PathString(\"/ep1\");\n            ctx.RequestServices = new StubServiceProvider();\n\n            var result = _subject.Find(ctx);\n            result.Should().BeOfType<MyEndpointHandler>();\n        }\n\n        [Fact]\n        public void Find_should_return_null_for_disabled_endpoint()\n        {\n            _endpoints.Add(new IdentityServer8.Hosting.Endpoint(EndpointNames.Authorize, \"/ep1\", typeof(MyEndpointHandler)));\n            _endpoints.Add(new IdentityServer8.Hosting.Endpoint(\"ep2\", \"/ep2\", typeof(MyOtherEndpointHandler)));\n\n            _options.Endpoints.EnableAuthorizeEndpoint = false;\n\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Path = new PathString(\"/ep1\");\n            ctx.RequestServices = new StubServiceProvider();\n\n            var result = _subject.Find(ctx);\n            result.Should().BeNull();\n        }\n\n        private class MyEndpointHandler : IEndpointHandler\n        {\n            public Task<IEndpointResult> ProcessAsync(HttpContext context)\n            {\n                throw new NotImplementedException();\n            }\n        }\n\n        private class MyOtherEndpointHandler : IEndpointHandler\n        {\n            public Task<IEndpointResult> ProcessAsync(HttpContext context)\n            {\n                throw new NotImplementedException();\n            }\n        }\n\n        private class StubServiceProvider : IServiceProvider\n        {\n            public object GetService(Type serviceType)\n            {\n                if (serviceType == typeof(MyEndpointHandler)) return new MyEndpointHandler();\n                if (serviceType == typeof(MyOtherEndpointHandler)) return new MyOtherEndpointHandler();\n\n                throw new InvalidOperationException();\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/IdentityServer.UnitTests.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n\n  <PropertyGroup>\n    <AssemblyOriginatorKeyFile>../../../../key.snk</AssemblyOriginatorKeyFile>\n    <SignAssembly>true</SignAssembly>\n    <PublicSign Condition=\"'$(OS)' != 'Windows_NT'\">true</PublicSign>\n  </PropertyGroup>\n\n \n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.NET.Test.Sdk\" />\n\n    <PackageReference Include=\"xunit\" />\n    <PackageReference Include=\"xunit.runner.visualstudio\" PrivateAssets=\"All\" />\n    <PackageReference Include=\"FluentAssertions\" />\n    <PackageReference Include=\"coverlet.collector\" GeneratePathProperty=\"true\">\n      <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n      <PrivateAssets>all</PrivateAssets>\n    </PackageReference>\n  </ItemGroup>\n\n  <ItemGroup>\n    <None Update=\"identityserver_testing.cer\">\n      <CopyToOutputDirectory>Always</CopyToOutputDirectory>\n    </None>\n    <None Update=\"identityserver_testing.pfx\">\n      <CopyToOutputDirectory>Always</CopyToOutputDirectory>\n    </None>\n  </ItemGroup>\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\..\\src\\IdentityServer8.csproj\" />\n  </ItemGroup>\n</Project>\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Infrastructure/ObjectSerializerTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing FluentAssertions;\nusing IdentityServer8.Models;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Infrastructure\n{\n    public class ObjectSerializerTests\n    {\n        public ObjectSerializerTests()\n        {\n        }\n\n        [Fact]\n        public void Can_be_deserialize_message()\n        {\n            Action a = () => IdentityServer8.ObjectSerializer.FromString<Message<ErrorMessage>>(\"{\\\"created\\\":0, \\\"data\\\": {\\\"error\\\": \\\"error\\\"}}\");\n            a.Should().NotThrow();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/ResponseHandling/AuthorizeInteractionResponseGenerator/AuthorizeInteractionResponseGeneratorTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Xunit;\nusing static IdentityModel.OidcConstants;\n\nnamespace IdentityServer.UnitTests.ResponseHandling.AuthorizeInteractionResponseGenerator\n{\n    public class AuthorizeInteractionResponseGeneratorTests\n    {\n        private IdentityServerOptions _options = new IdentityServerOptions();\n        private IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator _subject;\n        private MockConsentService _mockConsentService = new MockConsentService();\n        private StubClock _clock = new StubClock();\n\n        public AuthorizeInteractionResponseGeneratorTests()\n        {\n            _subject = new IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator(\n                _clock,\n                TestLogger.Create<IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator>(),\n                _mockConsentService,\n                new MockProfileService());\n        }\n\n\n        [Fact]\n        public async Task Authenticated_User_with_restricted_current_Idp_with_prompt_none_must_error()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal(),\n                Client = new Client\n                {\n                    EnableLocalLogin = false,\n                    IdentityProviderRestrictions = new List<string>\n                    {\n                        \"some_idp\"\n                    }\n                },\n                PromptModes = new[] { PromptModes.None },\n            };\n\n            var result = await _subject.ProcessInteractionAsync(request);\n\n            result.IsError.Should().BeTrue();\n            result.IsLogin.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Authenticated_User_with_maxage_with_prompt_none_must_error()\n        {\n            _clock.UtcNowFunc = () => new DateTime(2020, 02, 03, 9, 0, 0);\n\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    AuthenticationTime = new DateTime(2020, 02, 01, 9, 0, 0),\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal(),\n                Client = new Client\n                {\n                    EnableLocalLogin = true,\n                },\n                PromptModes = new[] { PromptModes.None },\n                MaxAge = 3600\n            };\n\n            var result = await _subject.ProcessInteractionAsync(request);\n\n            result.IsError.Should().BeTrue();\n            result.IsLogin.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Authenticated_User_with_different_requested_Idp_with_prompt_none_must_error()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Client = new Client(),\n                AuthenticationContextReferenceClasses = new List<string>{\n                    \"idp:some_idp\"\n                },\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal(),\n                PromptModes = new[] { PromptModes.None }\n            };\n\n            var result = await _subject.ProcessInteractionAsync(request);\n\n            result.IsError.Should().BeTrue();\n            result.IsLogin.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Authenticated_User_beyond_client_user_sso_lifetime_with_prompt_none_should_error()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Client = new Client()\n                {\n                    UserSsoLifetime = 3600 // 1h\n                },\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = \"local\",\n                    AuthenticationTime = _clock.UtcNow.UtcDateTime.Subtract(TimeSpan.FromSeconds(3700))\n                }.CreatePrincipal(),\n                PromptModes = new[] { PromptModes.None }\n            };\n\n            var result = await _subject.ProcessInteractionAsync(request);\n\n            result.IsError.Should().BeTrue();\n            result.IsLogin.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task locally_authenticated_user_but_client_does_not_allow_local_with_prompt_none_should_error()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Client = new Client()\n                {\n                    EnableLocalLogin = false\n                },\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal(),\n                PromptModes = new[] { PromptModes.None }\n            };\n\n            var result = await _subject.ProcessInteractionAsync(request);\n\n            result.IsError.Should().BeTrue();\n            result.IsLogin.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/ResponseHandling/AuthorizeInteractionResponseGenerator/AuthorizeInteractionResponseGeneratorTests_Consent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.ResponseHandling.AuthorizeInteractionResponseGenerator\n{\n    public class AuthorizeInteractionResponseGeneratorTests_Consent\n    {\n        private IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator _subject;\n        private IdentityServerOptions _options = new IdentityServerOptions();\n        private MockConsentService _mockConsent = new MockConsentService();\n        private MockProfileService _fakeUserService = new MockProfileService();\n\n        private void RequiresConsent(bool value)\n        {\n            _mockConsent.RequiresConsentResult = value;\n        }\n\n        private void AssertUpdateConsentNotCalled()\n        {\n            _mockConsent.ConsentClient.Should().BeNull();\n            _mockConsent.ConsentSubject.Should().BeNull();\n            _mockConsent.ConsentScopes.Should().BeNull();\n        }\n\n        private void AssertUpdateConsentCalled(Client client, ClaimsPrincipal user, params string[] scopes)\n        {\n            _mockConsent.ConsentClient.Should().BeSameAs(client);\n            _mockConsent.ConsentSubject.Should().BeSameAs(user);\n            _mockConsent.ConsentScopes.Should().BeEquivalentTo(scopes);\n        }\n\n        private static IEnumerable<IdentityResource> GetIdentityScopes()\n        {\n            return new IdentityResource[]\n            {\n                new IdentityResources.OpenId(),\n                new IdentityResources.Profile(),\n                new IdentityResources.Email()\n            };\n        }\n\n        private static IEnumerable<ApiResource> GetApiResources()\n        {\n            return new ApiResource[]\n            {\n                new ApiResource\n                {\n                    Name = \"api\",\n                    Scopes = { \"read\", \"write\", \"forbidden\" }\n                }\n             };\n        }\n\n        private static IEnumerable<ApiScope> GetScopes()\n        {\n            return new ApiScope[]\n            {\n                new ApiScope\n                {\n                    Name = \"read\",\n                    DisplayName = \"Read data\",\n                    Emphasize = false\n                },\n                new ApiScope\n                {\n                    Name = \"write\",\n                    DisplayName = \"Write data\",\n                    Emphasize = true\n                },\n                new ApiScope\n                {\n                    Name = \"forbidden\",\n                    DisplayName = \"Forbidden scope\",\n                    Emphasize = true\n                }\n             };\n        }\n\n        public AuthorizeInteractionResponseGeneratorTests_Consent()\n        {\n            _subject = new IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator(\n                new StubClock(),\n                TestLogger.Create<IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator>(),\n                _mockConsent,\n                _fakeUserService);\n        }\n\n        private static ResourceValidationResult GetValidatedResources(params string[] scopes)\n        {\n            var resources = new Resources(GetIdentityScopes(), GetApiResources(), GetScopes());\n            return new ResourceValidationResult(resources).Filter(scopes);\n        }\n\n\n        [Fact]\n        public async Task ProcessConsentAsync_NullRequest_Throws()\n        {\n            Func<Task> act = async () => await _subject.ProcessConsentAsync(null, new ConsentResponse());\n\n            (await act.Should().ThrowAsync<ArgumentNullException>())\n                .And.ParamName.Should().Be(\"request\");\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_AllowsNullConsent()\n        {\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                PromptModes = new[] { OidcConstants.PromptModes.Consent },\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n            await _subject.ProcessConsentAsync(request, null);\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_PromptModeIsLogin_Throws()\n        {\n            RequiresConsent(true);\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                PromptModes = new[] { OidcConstants.PromptModes.Login },\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n\n            Func<Task> act = async () => await _subject.ProcessConsentAsync(request);\n\n            (await act.Should().ThrowAsync<ArgumentException>())\n                .And.Message.Should().Contain(\"PromptMode\");\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_PromptModeIsSelectAccount_Throws()\n        {\n            RequiresConsent(true);\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                PromptModes = new[] { OidcConstants.PromptModes.SelectAccount },\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n\n            Func<Task> act = async () => await _subject.ProcessConsentAsync(request);\n\n            (await act.Should().ThrowAsync<ArgumentException>())\n                 .And.Message.Should().Contain(\"PromptMode\");\n        }\n\n\n        [Fact]\n        public async Task ProcessConsentAsync_RequiresConsentButPromptModeIsNone_ReturnsErrorResult()\n        {\n            RequiresConsent(true);\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                PromptModes = new[] { OidcConstants.PromptModes.None },\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n            var result = await _subject.ProcessConsentAsync(request);\n\n            request.WasConsentShown.Should().BeFalse();\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.ConsentRequired);\n            AssertUpdateConsentNotCalled();\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_PromptModeIsConsent_NoPriorConsent_ReturnsConsentResult()\n        {\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                PromptModes = new[] { OidcConstants.PromptModes.Consent },\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n            var result = await _subject.ProcessConsentAsync(request);\n            request.WasConsentShown.Should().BeFalse();\n            result.IsConsent.Should().BeTrue();\n            AssertUpdateConsentNotCalled();\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_NoPromptMode_ConsentServiceRequiresConsent_NoPriorConsent_ReturnsConsentResult()\n        {\n            RequiresConsent(true);\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                PromptModes = new[] { OidcConstants.PromptModes.Consent },\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n            var result = await _subject.ProcessConsentAsync(request);\n            request.WasConsentShown.Should().BeFalse();\n            result.IsConsent.Should().BeTrue();\n            AssertUpdateConsentNotCalled();\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_PromptModeIsConsent_ConsentNotGranted_ReturnsErrorResult()\n        {\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                PromptModes = new[] { OidcConstants.PromptModes.Consent },\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n\n            var consent = new ConsentResponse\n            {\n                RememberConsent = false,\n                ScopesValuesConsented = new string[] { }\n            };\n            var result = await _subject.ProcessConsentAsync(request, consent);\n            request.WasConsentShown.Should().BeTrue();\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.AccessDenied);\n            AssertUpdateConsentNotCalled();\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_NoPromptMode_ConsentServiceRequiresConsent_ConsentNotGranted_ReturnsErrorResult()\n        {\n            RequiresConsent(true);\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n            var consent = new ConsentResponse\n            {\n                RememberConsent = false,\n                ScopesValuesConsented = new string[] { }\n            };\n            var result = await _subject.ProcessConsentAsync(request, consent);\n            request.WasConsentShown.Should().BeTrue();\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.AccessDenied);\n            AssertUpdateConsentNotCalled();\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_NoPromptMode_ConsentServiceRequiresConsent_ConsentGrantedButMissingRequiredScopes_ReturnsErrorResult()\n        {\n            RequiresConsent(true);\n            var client = new Client { };\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n                Client = client\n            };\n\n            var consent = new ConsentResponse\n            {\n                RememberConsent = false,\n                ScopesValuesConsented = new string[] { \"read\" }\n            };\n\n            var result = await _subject.ProcessConsentAsync(request, consent);\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.AccessDenied);\n            AssertUpdateConsentNotCalled();\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_NoPromptMode_ConsentServiceRequiresConsent_ConsentGranted_ScopesSelected_ReturnsConsentResult()\n        {\n            RequiresConsent(true);\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                Client = new Client\n                {\n                    AllowRememberConsent = false\n                },\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n            var consent = new ConsentResponse\n            {\n                RememberConsent = false,\n                ScopesValuesConsented = new string[] { \"openid\", \"read\" }\n            };\n            var result = await _subject.ProcessConsentAsync(request, consent);\n            request.ValidatedResources.Resources.IdentityResources.Count().Should().Be(1);\n            request.ValidatedResources.Resources.ApiScopes.Count().Should().Be(1);\n            \"openid\".Should().Be(request.ValidatedResources.Resources.IdentityResources.Select(x => x.Name).First());\n            \"read\".Should().Be(request.ValidatedResources.Resources.ApiScopes.First().Name);\n            request.WasConsentShown.Should().BeTrue();\n            result.IsConsent.Should().BeFalse();\n            AssertUpdateConsentNotCalled();\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_PromptModeConsent_ConsentGranted_ScopesSelected_ReturnsConsentResult()\n        {\n            RequiresConsent(true);\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                Client = new Client\n                {\n                    AllowRememberConsent = false\n                },\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n            var consent = new ConsentResponse\n            {\n                RememberConsent = false,\n                ScopesValuesConsented = new string[] { \"openid\", \"read\" }\n            };\n            var result = await _subject.ProcessConsentAsync(request, consent);\n            request.ValidatedResources.Resources.IdentityResources.Count().Should().Be(1);\n            request.ValidatedResources.Resources.ApiScopes.Count().Should().Be(1);\n            \"read\".Should().Be(request.ValidatedResources.Resources.ApiScopes.First().Name);\n            request.WasConsentShown.Should().BeTrue();\n            result.IsConsent.Should().BeFalse();\n            AssertUpdateConsentNotCalled();\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_AllowConsentSelected_SavesConsent()\n        {\n            RequiresConsent(true);\n            var client = new Client { AllowRememberConsent = true };\n            var user = new ClaimsPrincipal();\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                Client = client,\n                Subject = user,\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n            var consent = new ConsentResponse\n            {\n                RememberConsent = true,\n                ScopesValuesConsented = new string[] { \"openid\", \"read\" }\n            };\n            var result = await _subject.ProcessConsentAsync(request, consent);\n            AssertUpdateConsentCalled(client, user, \"openid\", \"read\");\n        }\n\n        [Fact]\n        public async Task ProcessConsentAsync_NotRememberingConsent_DoesNotSaveConsent()\n        {\n            RequiresConsent(true);\n            var client = new Client { AllowRememberConsent = true };\n            var user = new ClaimsPrincipal();\n            var request = new ValidatedAuthorizeRequest()\n            {\n                ResponseMode = OidcConstants.ResponseModes.Fragment,\n                State = \"12345\",\n                RedirectUri = \"https://client.com/callback\",\n                Client = client,\n                Subject = user,\n                RequestedScopes = new List<string> { \"openid\", \"read\", \"write\" },\n                ValidatedResources = GetValidatedResources(\"openid\", \"read\", \"write\"),\n            };\n            var consent = new ConsentResponse\n            {\n                RememberConsent = false,\n                ScopesValuesConsented = new string[] { \"openid\", \"read\" }\n            };\n            var result = await _subject.ProcessConsentAsync(request, consent);\n            AssertUpdateConsentCalled(client, user);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/ResponseHandling/AuthorizeInteractionResponseGenerator/AuthorizeInteractionResponseGeneratorTests_Custom.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.ResponseHandling;\nusing IdentityServer8.Services;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Authentication;\nusing Microsoft.Extensions.Logging;\nusing Xunit;\nusing static IdentityModel.OidcConstants;\n\nnamespace IdentityServer.UnitTests.ResponseHandling.AuthorizeInteractionResponseGenerator\n{\n    public class CustomAuthorizeInteractionResponseGenerator : IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator\n    {\n        public CustomAuthorizeInteractionResponseGenerator(ISystemClock clock, ILogger<IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator> logger, IConsentService consent, IProfileService profile) : base(clock, logger, consent, profile)\n        {\n        }\n\n        public InteractionResponse ProcessLoginResponse { get; set; }\n        protected internal override Task<InteractionResponse> ProcessLoginAsync(ValidatedAuthorizeRequest request)\n        {\n            if (ProcessLoginResponse != null)\n            {\n                return Task.FromResult(ProcessLoginResponse);\n            }\n\n            return base.ProcessLoginAsync(request);\n        }\n\n        public InteractionResponse ProcessConsentResponse { get; set; }\n        protected internal override Task<InteractionResponse> ProcessConsentAsync(ValidatedAuthorizeRequest request, ConsentResponse consent = null)\n        {\n            if (ProcessConsentResponse != null)\n            {\n                return Task.FromResult(ProcessConsentResponse);\n            }\n            return base.ProcessConsentAsync(request, consent);\n        }\n    }\n\n    public class AuthorizeInteractionResponseGeneratorTests_Custom\n    {\n        private IdentityServerOptions _options = new IdentityServerOptions();\n        private CustomAuthorizeInteractionResponseGenerator _subject;\n        private MockConsentService _mockConsentService = new MockConsentService();\n        private StubClock _clock = new StubClock();\n\n        public AuthorizeInteractionResponseGeneratorTests_Custom()\n        {\n            _subject = new CustomAuthorizeInteractionResponseGenerator(\n                _clock,\n                TestLogger.Create<IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator>(),\n                _mockConsentService,\n                new MockProfileService());\n        }\n\n\n        [Fact]\n        public async Task ProcessInteractionAsync_with_overridden_login_returns_redirect_should_return_redirect()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal(),\n                Client = new Client\n                {\n                },\n            };\n\n            _subject.ProcessLoginResponse = new InteractionResponse\n            {\n                RedirectUrl = \"/custom\"\n            };\n\n            var result = await _subject.ProcessInteractionAsync(request);\n\n            result.IsRedirect.Should().BeTrue();\n            result.RedirectUrl.Should().Be(\"/custom\");\n        }\n\n        [Fact]\n        public async Task ProcessInteractionAsync_with_prompt_none_and_login_returns_login_should_return_error()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal(),\n                Client = new Client\n                {\n                },\n                PromptModes = new[] { PromptModes.None },\n            };\n\n            _subject.ProcessLoginResponse = new InteractionResponse\n            {\n                IsLogin = true\n            };\n\n            var result = await _subject.ProcessInteractionAsync(request);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(\"login_required\");\n        }\n\n        [Fact]\n        public async Task ProcessInteractionAsync_with_prompt_none_and_login_returns_redirect_should_return_error()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal(),\n                Client = new Client\n                {\n                },\n                PromptModes = new[] { PromptModes.None },\n            };\n\n            _subject.ProcessLoginResponse = new InteractionResponse\n            {\n                RedirectUrl = \"/custom\"\n            };\n\n            var result = await _subject.ProcessInteractionAsync(request);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(\"interaction_required\");\n            result.RedirectUrl.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task ProcessInteractionAsync_with_prompt_none_and_consent_returns_consent_should_return_error()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal(),\n                Client = new Client\n                {\n                },\n                PromptModes = new[] { PromptModes.None },\n            };\n\n            _subject.ProcessConsentResponse = new InteractionResponse\n            {\n                IsConsent = true\n            };\n\n            var result = await _subject.ProcessInteractionAsync(request);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(\"consent_required\");\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/ResponseHandling/AuthorizeInteractionResponseGenerator/AuthorizeInteractionResponseGeneratorTests_Login.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.ResponseHandling.AuthorizeInteractionResponseGenerator\n{\n    public class AuthorizeInteractionResponseGeneratorTests_Login\n    {\n        private IdentityServerOptions _options = new IdentityServerOptions();\n        private IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator _subject;\n        private MockConsentService _mockConsentService = new MockConsentService();\n        private StubClock _clock = new StubClock();\n\n        public AuthorizeInteractionResponseGeneratorTests_Login()\n        {\n            _subject = new IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator(\n                _clock,\n                TestLogger.Create<IdentityServer8.ResponseHandling.AuthorizeInteractionResponseGenerator>(),\n                _mockConsentService,\n                new MockProfileService());\n        }\n\n        [Fact]\n        public async Task Anonymous_User_must_SignIn()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = Principal.Anonymous\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            result.IsLogin.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task Authenticated_User_must_not_SignIn()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Client = new Client(),\n                ValidatedResources = new ResourceValidationResult(),\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal()\n            };\n\n            var result = await _subject.ProcessInteractionAsync(request);\n\n            result.IsLogin.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Authenticated_User_with_allowed_current_Idp_must_not_SignIn()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\") {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal(),\n                Client = new Client \n                {\n                    IdentityProviderRestrictions = new List<string> \n                    {\n                        IdentityServerConstants.LocalIdentityProvider\n                    }\n                }\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            result.IsLogin.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Authenticated_User_with_restricted_current_Idp_must_SignIn()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal(),\n                Client = new Client\n                {\n                    EnableLocalLogin = false,\n                    IdentityProviderRestrictions = new List<string> \n                    {\n                        \"some_idp\"\n                    }\n                }\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            result.IsLogin.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task Authenticated_User_with_allowed_requested_Idp_must_not_SignIn()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Client = new Client(),\n                 AuthenticationContextReferenceClasses = new List<string>{\n                    \"idp:\" + IdentityServerConstants.LocalIdentityProvider\n                },\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal()\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            result.IsLogin.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Authenticated_User_with_different_requested_Idp_must_SignIn()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Client = new Client(),\n                AuthenticationContextReferenceClasses = new List<string>{\n                    \"idp:some_idp\"\n                },\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal()\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            result.IsLogin.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task Authenticated_User_within_client_user_sso_lifetime_should_not_signin()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Client = new Client() {\n                    UserSsoLifetime = 3600 // 1h\n                },\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = \"local\",\n                    AuthenticationTime = _clock.UtcNow.UtcDateTime.Subtract(TimeSpan.FromSeconds(10))\n                }.CreatePrincipal()\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            result.IsLogin.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Authenticated_User_beyond_client_user_sso_lifetime_should_signin()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Client = new Client()\n                {\n                    UserSsoLifetime = 3600 // 1h\n                },\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = \"local\",\n                    AuthenticationTime = _clock.UtcNow.UtcDateTime.Subtract(TimeSpan.FromSeconds(3700))\n                }.CreatePrincipal()\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            result.IsLogin.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task locally_authenticated_user_but_client_does_not_allow_local_should_sign_in()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Client = new Client()\n                {\n                    EnableLocalLogin = false\n                },\n                Subject = new IdentityServerUser(\"123\")\n                {\n                    IdentityProvider = IdentityServerConstants.LocalIdentityProvider\n                }.CreatePrincipal()\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            result.IsLogin.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task prompt_login_should_sign_in()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                PromptModes = new[] { OidcConstants.PromptModes.Login },\n                Raw = new NameValueCollection()\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            result.IsLogin.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task prompt_select_account_should_sign_in()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                PromptModes = new[] { OidcConstants.PromptModes.SelectAccount },\n                Raw = new NameValueCollection()\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            result.IsLogin.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task prompt_for_signin_should_remove_prompt_from_raw_url()\n        {\n            var request = new ValidatedAuthorizeRequest\n            {\n                ClientId = \"foo\",\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                PromptModes = new[] { OidcConstants.PromptModes.Login },\n                Raw = new NameValueCollection\n                {\n                    { OidcConstants.AuthorizeRequest.Prompt, OidcConstants.PromptModes.Login }\n                }\n            };\n\n            var result = await _subject.ProcessLoginAsync(request);\n\n            request.Raw.AllKeys.Should().NotContain(OidcConstants.AuthorizeRequest.Prompt);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/ResponseHandling/DeviceAuthorizationResponseGeneratorTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.ResponseHandling;\nusing IdentityServer8.Services;\nusing IdentityServer8.Services.Default;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing Microsoft.Extensions.Logging.Abstractions;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.ResponseHandling\n{\n    public class DeviceAuthorizationResponseGeneratorTests\n    {\n        private readonly List<IdentityResource> identityResources = new List<IdentityResource> {new IdentityResources.OpenId(), new IdentityResources.Profile()};\n        private readonly List<ApiResource> apiResources = new List<ApiResource> { new ApiResource(\"resource\") { Scopes = {\"api1\" } } };\n        private readonly List<ApiScope> scopes = new List<ApiScope> { new ApiScope(\"api1\") };\n\n        private readonly FakeUserCodeGenerator fakeUserCodeGenerator = new FakeUserCodeGenerator();\n        private readonly IDeviceFlowCodeService deviceFlowCodeService = new DefaultDeviceFlowCodeService(new InMemoryDeviceFlowStore(), new StubHandleGenerationService());\n        private readonly IdentityServerOptions options = new IdentityServerOptions();\n        private readonly StubClock clock = new StubClock();\n        \n        private readonly DeviceAuthorizationResponseGenerator generator;\n        private readonly DeviceAuthorizationRequestValidationResult testResult;\n        private const string TestBaseUrl = \"http://localhost:5000/\";\n\n        public DeviceAuthorizationResponseGeneratorTests()\n        {\n            testResult = new DeviceAuthorizationRequestValidationResult(new ValidatedDeviceAuthorizationRequest\n            {\n                Client = new Client {ClientId = Guid.NewGuid().ToString()},\n                IsOpenIdRequest = true,\n                ValidatedResources = new ResourceValidationResult()\n            });\n\n            generator = new DeviceAuthorizationResponseGenerator(\n                options,\n                new DefaultUserCodeService(new IUserCodeGenerator[] {new NumericUserCodeGenerator(), fakeUserCodeGenerator }),\n                deviceFlowCodeService,\n                clock,\n                new NullLogger<DeviceAuthorizationResponseGenerator>());\n        }\n\n        [Fact]\n        public async Task ProcessAsync_when_valiationresult_null_exect_exception()\n        {\n            Func<Task> act = async () => await generator.ProcessAsync(null, TestBaseUrl);\n            await act.Should().ThrowAsync<ArgumentNullException>();\n        }\n\n        [Fact]\n        public void ProcessAsync_when_valiationresult_client_null_exect_exception()\n        {\n            var validationResult = new DeviceAuthorizationRequestValidationResult(new ValidatedDeviceAuthorizationRequest());\n            Func <Task> act = () => generator.ProcessAsync(validationResult, TestBaseUrl);\n            act.Should().ThrowAsync<ArgumentNullException>();\n        }\n\n        [Fact]\n        public void ProcessAsync_when_baseurl_null_exect_exception()\n        {\n            Func<Task> act = () => generator.ProcessAsync(testResult, null);\n            act.Should().ThrowAsync<ArgumentException>();\n        }\n\n        [Fact]\n        public async Task ProcessAsync_when_user_code_collision_expect_retry()\n        {\n            var creationTime = DateTime.UtcNow;\n            clock.UtcNowFunc = () => creationTime;\n\n            testResult.ValidatedRequest.Client.UserCodeType = FakeUserCodeGenerator.UserCodeTypeValue;\n            await deviceFlowCodeService.StoreDeviceAuthorizationAsync(FakeUserCodeGenerator.TestCollisionUserCode, new DeviceCode());\n\n            var response = await generator.ProcessAsync(testResult, TestBaseUrl);\n\n            response.UserCode.Should().Be(FakeUserCodeGenerator.TestUniqueUserCode);\n        }\n\n        [Fact]\n        public async Task ProcessAsync_when_user_code_collision_retry_limit_reached_expect_error()\n        {\n            var creationTime = DateTime.UtcNow;\n            clock.UtcNowFunc = () => creationTime;\n\n            fakeUserCodeGenerator.RetryLimit = 1;\n            testResult.ValidatedRequest.Client.UserCodeType = FakeUserCodeGenerator.UserCodeTypeValue;\n            await deviceFlowCodeService.StoreDeviceAuthorizationAsync(FakeUserCodeGenerator.TestCollisionUserCode, new DeviceCode());\n\n            await Assert.ThrowsAsync<InvalidOperationException>(() => generator.ProcessAsync(testResult, TestBaseUrl));\n        }\n\n        [Fact]\n        public async Task ProcessAsync_when_generated_expect_user_code_stored()\n        {\n            var creationTime = DateTime.UtcNow;\n            clock.UtcNowFunc = () => creationTime;\n\n            testResult.ValidatedRequest.RequestedScopes = new List<string> { \"openid\", \"api1\" };\n            testResult.ValidatedRequest.ValidatedResources = new ResourceValidationResult(new Resources(\n                identityResources.Where(x=>x.Name == \"openid\"), \n                apiResources.Where(x=>x.Name == \"resource\"), \n                scopes.Where(x=>x.Name == \"api1\")));\n\n            var response = await generator.ProcessAsync(testResult, TestBaseUrl);\n\n            response.UserCode.Should().NotBeNullOrWhiteSpace();\n\n            var userCode = await deviceFlowCodeService.FindByUserCodeAsync(response.UserCode);\n            userCode.Should().NotBeNull();\n            userCode.ClientId.Should().Be(testResult.ValidatedRequest.Client.ClientId);\n            userCode.Lifetime.Should().Be(testResult.ValidatedRequest.Client.DeviceCodeLifetime);\n            userCode.CreationTime.Should().Be(creationTime);\n            userCode.Subject.Should().BeNull();\n            userCode.AuthorizedScopes.Should().BeNull();\n\n            userCode.RequestedScopes.Should().Contain(testResult.ValidatedRequest.RequestedScopes);\n        }\n\n        [Fact]\n        public async Task ProcessAsync_when_generated_expect_device_code_stored()\n        {\n            var creationTime = DateTime.UtcNow;\n            clock.UtcNowFunc = () => creationTime;\n\n            var response = await generator.ProcessAsync(testResult, TestBaseUrl);\n\n            response.DeviceCode.Should().NotBeNullOrWhiteSpace();\n            response.Interval.Should().Be(options.DeviceFlow.Interval);\n            \n            var deviceCode = await deviceFlowCodeService.FindByDeviceCodeAsync(response.DeviceCode);\n            deviceCode.Should().NotBeNull();\n            deviceCode.ClientId.Should().Be(testResult.ValidatedRequest.Client.ClientId);\n            deviceCode.IsOpenId.Should().Be(testResult.ValidatedRequest.IsOpenIdRequest);\n            deviceCode.Lifetime.Should().Be(testResult.ValidatedRequest.Client.DeviceCodeLifetime);\n            deviceCode.CreationTime.Should().Be(creationTime);\n            deviceCode.Subject.Should().BeNull();\n            deviceCode.AuthorizedScopes.Should().BeNull();\n            \n            response.DeviceCodeLifetime.Should().Be(deviceCode.Lifetime);\n        }\n\n        [Fact]\n        public async Task ProcessAsync_when_DeviceVerificationUrl_is_relative_uri_expect_correct_VerificationUris()\n        {\n            const string baseUrl = \"http://localhost:5000/\";\n            options.UserInteraction.DeviceVerificationUrl = \"/device\";\n            options.UserInteraction.DeviceVerificationUserCodeParameter = \"userCode\";\n\n            var response = await generator.ProcessAsync(testResult, baseUrl);\n\n            response.VerificationUri.Should().Be(\"http://localhost:5000/device\");\n            response.VerificationUriComplete.Should().StartWith(\"http://localhost:5000/device?userCode=\");\n        }\n\n        [Fact]\n        public async Task ProcessAsync_when_DeviceVerificationUrl_is_absolute_uri_expect_correct_VerificationUris()\n        {\n            const string baseUrl = \"http://localhost:5000/\";\n            options.UserInteraction.DeviceVerificationUrl = \"http://short/device\";\n            options.UserInteraction.DeviceVerificationUserCodeParameter = \"userCode\";\n\n            var response = await generator.ProcessAsync(testResult, baseUrl);\n\n            response.VerificationUri.Should().Be(\"http://short/device\");\n            response.VerificationUriComplete.Should().StartWith(\"http://short/device?userCode=\");\n        }\n    }\n\n    internal class FakeUserCodeGenerator : IUserCodeGenerator\n    {\n        public const string UserCodeTypeValue = \"Collider\";\n        public const string TestUniqueUserCode = \"123\";\n        public const string TestCollisionUserCode = \"321\";\n        private int tryCount = 0;\n        private int retryLimit = 2;\n\n\n        public string UserCodeType => UserCodeTypeValue;\n\n        public int RetryLimit\n        {\n            get => retryLimit;\n            set => retryLimit = value;\n        }\n\n        public Task<string> GenerateAsync()\n        {\n            if (tryCount == 0)\n            {\n                tryCount++;\n                return Task.FromResult(TestCollisionUserCode);\n            }\n\n            tryCount++;\n            return Task.FromResult(TestUniqueUserCode);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/ResponseHandling/UserInfoResponseGeneratorTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Security.Claims;\nusing System.Text.Json;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.ResponseHandling;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.ResponseHandling\n{\n    public class UserInfoResponseGeneratorTests\n    {\n        private UserInfoResponseGenerator _subject;\n        private MockProfileService _mockProfileService = new MockProfileService();\n        private ClaimsPrincipal _user;\n        private Client _client;\n\n        private InMemoryResourcesStore _resourceStore;\n        private List<IdentityResource> _identityResources = new List<IdentityResource>();\n        private List<ApiResource> _apiResources = new List<ApiResource>();\n        private List<ApiScope> _apiScopes = new List<ApiScope>();\n\n        public UserInfoResponseGeneratorTests()\n        {\n            _client = new Client\n            {\n                ClientId = \"client\"\n            };\n\n            _user = new IdentityServerUser(\"bob\")\n            {\n                AdditionalClaims =\n                {\n                    new Claim(\"foo\", \"foo1\"),\n                    new Claim(\"foo\", \"foo2\"),\n                    new Claim(\"bar\", \"bar1\"),\n                    new Claim(\"bar\", \"bar2\")\n                }\n            }.CreatePrincipal();\n\n            _resourceStore = new InMemoryResourcesStore(_identityResources, _apiResources, _apiScopes);\n            _subject = new UserInfoResponseGenerator(_mockProfileService, _resourceStore, TestLogger.Create<UserInfoResponseGenerator>());\n        }\n\n        [Fact]\n        public async Task GetRequestedClaimTypesAsync_when_no_scopes_requested_should_return_empty_claim_types()\n        {\n            var resources = await _subject.GetRequestedResourcesAsync(null);\n            var claims = await _subject.GetRequestedClaimTypesAsync(resources);\n            claims.Should().BeEquivalentTo(new string[] { });\n        }\n\n        [Fact]\n        public async Task GetRequestedClaimTypesAsync_should_return_correct_identity_claims()\n        {\n            _identityResources.Add(new IdentityResource(\"id1\", new[] { \"c1\", \"c2\" }));\n            _identityResources.Add(new IdentityResource(\"id2\", new[] { \"c2\", \"c3\" }));\n\n            var resources = await _subject.GetRequestedResourcesAsync(new[] { \"id1\", \"id2\", \"id3\" });\n            var claims = await _subject.GetRequestedClaimTypesAsync(resources);\n            claims.Should().BeEquivalentTo(new string[] { \"c1\", \"c2\", \"c3\" });\n        }\n\n        [Fact]\n        public async Task GetRequestedClaimTypesAsync_should_only_return_enabled_identity_claims()\n        {\n            _identityResources.Add(new IdentityResource(\"id1\", new[] { \"c1\", \"c2\" }) { Enabled = false });\n            _identityResources.Add(new IdentityResource(\"id2\", new[] { \"c2\", \"c3\" }));\n\n            var resources = await _subject.GetRequestedResourcesAsync(new[] { \"id1\", \"id2\", \"id3\" });\n            var claims = await _subject.GetRequestedClaimTypesAsync(resources);\n            claims.Should().BeEquivalentTo(new string[] { \"c2\", \"c3\" });\n        }\n\n        [Fact]\n        public async Task ProcessAsync_should_call_profile_service_with_requested_claim_types()\n        {\n            _identityResources.Add(new IdentityResource(\"id1\", new[] { \"foo\" }));\n            _identityResources.Add(new IdentityResource(\"id2\", new[] { \"bar\" }));\n\n            var result = new UserInfoRequestValidationResult\n            {\n                Subject = _user,\n                TokenValidationResult = new TokenValidationResult\n                {\n                    Claims = new List<Claim>\n                    {\n                        { new Claim(\"scope\", \"id1\") },\n                        { new Claim(\"scope\", \"id2\") },\n                        { new Claim(\"scope\", \"id3\") }\n                    },\n                    Client = _client\n                }\n            };\n\n            var claims = await _subject.ProcessAsync(result);\n\n            _mockProfileService.GetProfileWasCalled.Should().BeTrue();\n            _mockProfileService.ProfileContext.RequestedClaimTypes.Should().BeEquivalentTo(new[] { \"foo\", \"bar\" });\n        }\n\n        [Fact]\n        public async Task ProcessAsync_should_return_claims_issued_by_profile_service()\n        {\n            _identityResources.Add(new IdentityResource(\"id1\", new[] { \"foo\" }));\n            _identityResources.Add(new IdentityResource(\"id2\", new[] { \"bar\" }));\n            \n            var address = new\n            {\n                street_address = \"One Hacker Way\",\n                locality = \"Heidelberg\",\n                postal_code = 69118,\n                country = \"Germany\"\n            };\n            \n            _mockProfileService.ProfileClaims = new[]\n            {\n                new Claim(\"email\", \"fred@gmail.com\"),\n                new Claim(\"name\", \"fred jones\"),\n                new Claim(\"address\", @\"{ 'street_address': 'One Hacker Way', 'locality': 'Heidelberg', 'postal_code': 69118, 'country': 'Germany' }\", IdentityServerConstants.ClaimValueTypes.Json),\n                new Claim(\"address2\", JsonSerializer.Serialize(address), IdentityServerConstants.ClaimValueTypes.Json)\n            };\n\n            var result = new UserInfoRequestValidationResult\n            {\n                Subject = _user,\n                TokenValidationResult = new TokenValidationResult\n                {\n                    Claims = new List<Claim>\n                    {\n                        { new Claim(\"scope\", \"id1\") },\n                        { new Claim(\"scope\", \"id2\") },\n                        { new Claim(\"scope\", \"id3\") }\n                    },\n                    Client = _client\n                }\n            };\n\n            var claims = await _subject.ProcessAsync(result);\n\n            claims.Should().ContainKey(\"email\");\n            claims[\"email\"].Should().Be(\"fred@gmail.com\");\n            claims.Should().ContainKey(\"name\");\n            claims[\"name\"].Should().Be(\"fred jones\");\n            \n            // this will be treated as a string because this is not valid JSON from the System.Text library point of view\n            claims.Should().ContainKey(\"address\");\n            claims[\"address\"].Should().Be(\"{ 'street_address': 'One Hacker Way', 'locality': 'Heidelberg', 'postal_code': 69118, 'country': 'Germany' }\");\n            \n            // this is a JsonElement\n            claims.Should().ContainKey(\"address2\");\n            claims[\"address2\"].ToString().Should().Be(\"{\\\"street_address\\\":\\\"One Hacker Way\\\",\\\"locality\\\":\\\"Heidelberg\\\",\\\"postal_code\\\":69118,\\\"country\\\":\\\"Germany\\\"}\");\n        }\n\n        [Fact]\n        public async Task ProcessAsync_should_return_sub_from_user()\n        {\n            _identityResources.Add(new IdentityResource(\"id1\", new[] { \"foo\" }));\n            _identityResources.Add(new IdentityResource(\"id2\", new[] { \"bar\" }));\n\n            var result = new UserInfoRequestValidationResult\n            {\n                Subject = _user,\n                TokenValidationResult = new TokenValidationResult\n                {\n                    Claims = new List<Claim>\n                    {\n                        { new Claim(\"scope\", \"id1\") },\n                        { new Claim(\"scope\", \"id2\") },\n                        { new Claim(\"scope\", \"id3\") }\n                    },\n                    Client = _client\n                }\n            };\n\n            var claims = await _subject.ProcessAsync(result);\n\n            claims.Should().ContainKey(\"sub\");\n            claims[\"sub\"].Should().Be(\"bob\");\n        }\n\n        [Fact]\n        public async Task ProcessAsync_should_throw_if_incorrect_sub_issued_by_profile_service()\n        {\n            _identityResources.Add(new IdentityResource(\"id1\", new[] { \"foo\" }));\n            _identityResources.Add(new IdentityResource(\"id2\", new[] { \"bar\" }));\n            _mockProfileService.ProfileClaims = new[]\n            {\n                new Claim(\"sub\", \"fred\")\n            };\n\n            var result = new UserInfoRequestValidationResult\n            {\n                Subject = _user,\n                TokenValidationResult = new TokenValidationResult\n                {\n                    Claims = new List<Claim>\n                    {\n                        { new Claim(\"scope\", \"id1\") },\n                        { new Claim(\"scope\", \"id2\") },\n                        { new Claim(\"scope\", \"id3\") }\n                    },\n                    Client = _client\n                }\n            };\n\n            Func<Task> act = async () => await _subject.ProcessAsync(result);\n\n            (await act.Should().ThrowAsync<InvalidOperationException>())\n                .And.Message.Should().Contain(\"subject\");\n        }\n\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/Default/DefaultClaimsServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Linq;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.Default\n{\n    public class DefaultClaimsServiceTests\n    {\n        private DefaultClaimsService _subject;\n        private MockProfileService _mockMockProfileService = new MockProfileService();\n\n        private ClaimsPrincipal _user;\n        private Client _client;\n        private ValidatedRequest _validatedRequest;\n        private Resources _resources = new Resources();\n\n        public ResourceValidationResult ResourceValidationResult => new ResourceValidationResult(_resources);\n\n        public DefaultClaimsServiceTests()\n        {\n            _client = new Client\n            {\n                ClientId = \"client\",\n                Claims = { new ClientClaim(\"some_claim\", \"some_claim_value\") }\n            };\n\n            _user = new IdentityServerUser(\"bob\")\n            {\n                IdentityProvider = \"idp\",\n                AuthenticationMethods = { OidcConstants.AuthenticationMethods.Password },\n                AuthenticationTime = new System.DateTime(2000, 1, 1),\n                AdditionalClaims =\n                {\n                    new Claim(\"foo\", \"foo1\"),\n                    new Claim(\"foo\", \"foo2\"),\n                    new Claim(\"bar\", \"bar1\"),\n                    new Claim(\"bar\", \"bar2\"),\n                    new Claim(JwtClaimTypes.AuthenticationContextClassReference, \"acr1\")\n                }\n            }.CreatePrincipal();\n\n            _subject = new DefaultClaimsService(_mockMockProfileService, TestLogger.Create<DefaultClaimsService>());\n\n            _validatedRequest = new ValidatedRequest();\n            _validatedRequest.Options = new IdentityServerOptions();\n            _validatedRequest.SetClient(_client);\n        }\n\n        [Fact]\n        public async Task GetIdentityTokenClaimsAsync_should_return_standard_user_claims()\n        {\n            var claims = await _subject.GetIdentityTokenClaimsAsync(_user, ResourceValidationResult, false, _validatedRequest);\n\n            var types = claims.Select(x => x.Type);\n            types.Should().Contain(JwtClaimTypes.Subject);\n            types.Should().Contain(JwtClaimTypes.AuthenticationTime);\n            types.Should().Contain(JwtClaimTypes.IdentityProvider);\n            types.Should().Contain(JwtClaimTypes.AuthenticationMethod);\n            types.Should().Contain(JwtClaimTypes.AuthenticationContextClassReference);\n        }\n\n        [Fact]\n        public async Task GetIdentityTokenClaimsAsync_should_return_minimal_claims_when_includeAllIdentityClaims_is_false()\n        {\n            _resources.IdentityResources.Add(new IdentityResource(\"id_scope\", new[] { \"foo\" }));\n\n            var claims = await _subject.GetIdentityTokenClaimsAsync(_user, ResourceValidationResult, false, _validatedRequest);\n\n            _mockMockProfileService.GetProfileWasCalled.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task GetIdentityTokenClaimsAsync_should_return_all_claims_when_includeAllIdentityClaims_is_true()\n        {\n            _resources.IdentityResources.Add(new IdentityResource(\"id_scope\", new[] { \"foo\" }));\n            _mockMockProfileService.ProfileClaims.Add(new Claim(\"foo\", \"foo1\"));\n\n            var claims = await _subject.GetIdentityTokenClaimsAsync(_user, ResourceValidationResult, true, _validatedRequest);\n\n            _mockMockProfileService.GetProfileWasCalled.Should().BeTrue();\n            _mockMockProfileService.ProfileContext.RequestedClaimTypes.Should().Contain(\"foo\");\n        }\n\n        [Fact]\n        public async Task GetIdentityTokenClaimsAsync_should_return_all_claims_when_client_configured_for_always_include_all_claims_in_id_token()\n        {\n            _client.AlwaysIncludeUserClaimsInIdToken = true;\n\n            _resources.IdentityResources.Add(new IdentityResource(\"id_scope\", new[] { \"foo\" }));\n            _mockMockProfileService.ProfileClaims.Add(new Claim(\"foo\", \"foo1\"));\n\n            var claims = await _subject.GetIdentityTokenClaimsAsync(_user, ResourceValidationResult, false, _validatedRequest);\n\n            _mockMockProfileService.GetProfileWasCalled.Should().BeTrue();\n            _mockMockProfileService.ProfileContext.RequestedClaimTypes.Should().Contain(\"foo\");\n        }\n\n        [Fact]\n        public async Task GetIdentityTokenClaimsAsync_should_filter_protocol_claims_from_profile_service()\n        {\n            _resources.IdentityResources.Add(new IdentityResource(\"id_scope\", new[] { \"foo\" }));\n            _mockMockProfileService.ProfileClaims.Add(new Claim(\"aud\", \"bar\"));\n\n            var claims = await _subject.GetIdentityTokenClaimsAsync(_user, ResourceValidationResult, true, _validatedRequest);\n\n            claims.Count(x => x.Type == \"aud\" && x.Value == \"bar\").Should().Be(0);\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_contain_client_id()\n        {\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            claims.Count(x => x.Type == JwtClaimTypes.ClientId && x.Value == _client.ClientId).Should().Be(1);\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_client_claims_should_be_prefixed_with_default_value()\n        {\n            var claims = await _subject.GetAccessTokenClaimsAsync(null, ResourceValidationResult, _validatedRequest);\n\n            claims.Count(x => x.Type == \"client_some_claim\" && x.Value == \"some_claim_value\").Should().Be(1);\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_client_claims_should_be_prefixed_with_custom_value()\n        {\n            _validatedRequest.Client.ClientClaimsPrefix = \"custom_prefix_\";\n            var claims = await _subject.GetAccessTokenClaimsAsync(null, ResourceValidationResult, _validatedRequest);\n\n            claims.Count(x => x.Type == \"custom_prefix_some_claim\" && x.Value == \"some_claim_value\").Should().Be(1);\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_contain_client_claims_when_no_subject()\n        {\n            _validatedRequest.Client.ClientClaimsPrefix = null;\n            var claims = await _subject.GetAccessTokenClaimsAsync(null, ResourceValidationResult, _validatedRequest);\n\n            claims.Count(x => x.Type == \"some_claim\" && x.Value == \"some_claim_value\").Should().Be(1);\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_contain_client_claims_when_configured_to_send_client_claims()\n        {\n            _validatedRequest.Client.ClientClaimsPrefix = null;\n            _validatedRequest.Client.AlwaysSendClientClaims = true;\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            claims.Count(x => x.Type == \"some_claim\" && x.Value == \"some_claim_value\").Should().Be(1);\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_contain_scopes()\n        {\n            _resources.IdentityResources.Add(new IdentityResource(\"id1\", new[] { \"foo\" }));\n            _resources.IdentityResources.Add(new IdentityResource(\"id2\", new[] { \"bar\" }));\n            _resources.ApiScopes.Add(new ApiScope(\"api1\"));\n            _resources.ApiScopes.Add(new ApiScope(\"api2\"));\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            var scopes = claims.Where(x => x.Type == JwtClaimTypes.Scope).Select(x => x.Value);\n            scopes.Count().Should().Be(4);\n            scopes.ToArray().Should().BeEquivalentTo(new string[] { \"api1\", \"api2\", \"id1\", \"id2\" });\n        }\n        \n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_contain_parameterized_scope_values()\n        {\n            _resources.ApiScopes.Add(new ApiScope(\"api\"));\n            var resourceResult = new ResourceValidationResult()\n            {\n                Resources = _resources,\n                ParsedScopes = { new ParsedScopeValue(\"api:123\", \"api\", \"123\") }\n            };\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, resourceResult, _validatedRequest);\n\n            var scopes = claims.Where(x => x.Type == JwtClaimTypes.Scope).Select(x => x.Value);\n            scopes.Count().Should().Be(1);\n            scopes.ToArray().Should().BeEquivalentTo(new string[] { \"api:123\" });\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_when_no_ApiScopes_should_not_contain_scopes()\n        {\n            _resources.ApiResources.Add(new ApiResource(\"api1\"));\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            var scopes = claims.Where(x => x.Type == JwtClaimTypes.Scope).Select(x => x.Value);\n            scopes.Count().Should().Be(0);\n        }\n        \n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_only_consider_parsed_scope_values_and_not_ApiScope()\n        {\n            // arguably, if this situation arises, then the ResourceValidationResult was not populated properly\n            // with ParsedScopes matching ApiScopes\n            _resources.ApiScopes.Add(new ApiScope(\"api1\"));\n            var resourceResult = new ResourceValidationResult()\n            {\n                Resources = _resources,\n                ParsedScopes = { new ParsedScopeValue(\"api2\") }\n            };\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, resourceResult, _validatedRequest);\n\n            var scopes = claims.Where(x => x.Type == JwtClaimTypes.Scope).Select(x => x.Value);\n            scopes.Count().Should().Be(1);\n            scopes.ToArray().Should().BeEquivalentTo(new string[] { \"api2\" });\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_when_multiple_resources_with_same_scope_should_contain_scope_once()\n        {\n            _resources.OfflineAccess = false;\n            _resources.IdentityResources.Clear();\n            _resources.ApiResources.Clear();\n            _resources.ApiScopes.Clear();\n\n            _resources.ApiResources.Add(new ApiResource { Name = \"api1\", Scopes = { \"resource\" } });\n            _resources.ApiResources.Add(new ApiResource { Name = \"api2\", Scopes = { \"resource\" } });\n            _resources.ApiResources.Add(new ApiResource { Name = \"api3\", Scopes = { \"resource\" } });\n            _resources.ApiScopes.Add(new ApiScope(\"resource\"));\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            var scopes = claims.Where(x => x.Type == JwtClaimTypes.Scope).Select(x => x.Value);\n            scopes.Count().Should().Be(1);\n            scopes.ToArray().Should().BeEquivalentTo(new string[] { \"resource\" });\n        }\n        \n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_contain_offline_scope()\n        {\n            _resources.IdentityResources.Add(new IdentityResource(\"id1\", new[] { \"foo\" }));\n            _resources.IdentityResources.Add(new IdentityResource(\"id2\", new[] { \"bar\" }));\n            _resources.ApiResources.Add(new ApiResource(\"api1\"));\n            _resources.ApiResources.Add(new ApiResource(\"api2\"));\n            _resources.OfflineAccess = true;\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            var scopes = claims.Where(x => x.Type == JwtClaimTypes.Scope).Select(x => x.Value);\n            scopes.Should().Contain(IdentityServerConstants.StandardScopes.OfflineAccess);\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_not_contain_offline_scope_if_no_user()\n        {\n            _resources.IdentityResources.Add(new IdentityResource(\"id1\", new[] { \"foo\" }));\n            _resources.IdentityResources.Add(new IdentityResource(\"id2\", new[] { \"bar\" }));\n            _resources.ApiResources.Add(new ApiResource(\"api1\"));\n            _resources.ApiResources.Add(new ApiResource(\"api2\"));\n            _resources.OfflineAccess = true;\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(null, ResourceValidationResult, _validatedRequest);\n\n            var scopes = claims.Where(x => x.Type == JwtClaimTypes.Scope).Select(x => x.Value);\n            scopes.Should().NotContain(IdentityServerConstants.StandardScopes.OfflineAccess);\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_return_standard_user_claims()\n        {\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            var types = claims.Select(x => x.Type);\n            types.Should().Contain(JwtClaimTypes.Subject);\n            types.Should().Contain(JwtClaimTypes.AuthenticationTime);\n            types.Should().Contain(JwtClaimTypes.IdentityProvider);\n            types.Should().Contain(JwtClaimTypes.AuthenticationMethod);\n            types.Should().Contain(JwtClaimTypes.AuthenticationContextClassReference);\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_only_contain_api_claims()\n        {\n            _resources.IdentityResources.Add(new IdentityResource(\"id1\", new[] { \"foo\" }));\n            _resources.ApiResources.Add(new ApiResource(\"api1\", new string[] { \"bar\" }));\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            _mockMockProfileService.GetProfileWasCalled.Should().BeTrue();\n            _mockMockProfileService.ProfileContext.RequestedClaimTypes.Should().NotContain(\"foo\");\n            _mockMockProfileService.ProfileContext.RequestedClaimTypes.Should().Contain(\"bar\");\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_filter_protocol_claims_from_profile_service()\n        {\n            _resources.ApiResources.Add(new ApiResource(\"api1\", new[] { \"foo\" }));\n            _mockMockProfileService.ProfileClaims.Add(new Claim(\"aud\", \"bar\"));\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            claims.Count(x => x.Type == \"aud\" && x.Value == \"bar\").Should().Be(0);\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_request_api_claims()\n        {\n            _resources.ApiResources.Add(new ApiResource(\"api1\", new[] { \"foo\" }));\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            _mockMockProfileService.ProfileContext.RequestedClaimTypes.Should().Contain(\"foo\");\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_request_api_scope_claims()\n        {\n            _resources.ApiResources.Add(\n                new ApiResource(\"api\")\n                {\n                    Scopes = { \"api1\" }\n                }\n            );\n            _resources.ApiScopes.Add(\n                new ApiScope(\"api1\")\n                {\n                    UserClaims = { \"foo\" }\n                }\n            );\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            _mockMockProfileService.ProfileContext.RequestedClaimTypes.Should().Contain(\"foo\");\n        }\n\n        [Fact]\n        public async Task GetAccessTokenClaimsAsync_should_request_both_api_and_api_scope_claims()\n        {\n            _resources.ApiResources.Add(\n                new ApiResource(\"api\")\n                {\n                    UserClaims = { \"foo\" },\n                    Scopes = { \"api1\" } \n                }\n            );\n            _resources.ApiScopes.Add(\n                new ApiScope(\"api1\")\n                {\n                    UserClaims = { \"bar\" }\n                }\n            );\n\n            var claims = await _subject.GetAccessTokenClaimsAsync(_user, ResourceValidationResult, _validatedRequest);\n\n            _mockMockProfileService.ProfileContext.RequestedClaimTypes.Should().Contain(\"foo\");\n            _mockMockProfileService.ProfileContext.RequestedClaimTypes.Should().Contain(\"bar\");\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/Default/DefaultConsentServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Linq;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.Default\n{\n    public class DefaultConsentServiceTests\n    {\n        private DefaultConsentService _subject;\n        private MockProfileService _mockMockProfileService = new MockProfileService();\n\n        private ClaimsPrincipal _user;\n        private Client _client;\n        private TestUserConsentStore _userConsentStore = new TestUserConsentStore();\n        private StubClock _clock = new StubClock();\n\n        private DateTime now;\n\n        public DefaultConsentServiceTests()\n        {\n            _clock.UtcNowFunc = () => UtcNow;\n\n            _client = new Client\n            {\n                ClientId = \"client\",\n                RequireConsent = true,\n                RequirePkce = false\n            };\n\n            _user = new IdentityServerUser(\"bob\")\n            {\n                AdditionalClaims =\n                {\n                    new Claim(\"foo\", \"foo1\"),\n                    new Claim(\"foo\", \"foo2\"),\n                    new Claim(\"bar\", \"bar1\"),\n                    new Claim(\"bar\", \"bar2\"),\n                    new Claim(JwtClaimTypes.AuthenticationContextClassReference, \"acr1\")\n                }\n            }.CreatePrincipal();\n\n            _subject = new DefaultConsentService(_clock, _userConsentStore, TestLogger.Create<DefaultConsentService>());\n        }\n\n        public DateTime UtcNow\n        {\n            get\n            {\n                if (now > DateTime.MinValue) return now;\n                return DateTime.UtcNow;\n            }\n        }\n\n        [Fact]\n        public async Task UpdateConsentAsync_when_client_does_not_allow_remember_consent_should_not_update_store()\n        {\n            _client.AllowRememberConsent = false;\n\n            await _subject.UpdateConsentAsync(_user, _client, new [] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"scope2\") });\n\n            var consent = await _userConsentStore.GetUserConsentAsync(_user.GetSubjectId(), _client.ClientId);\n            consent.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task UpdateConsentAsync_should_persist_consent()\n        {\n            await _subject.UpdateConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"scope2\") });\n\n            var consent = await _userConsentStore.GetUserConsentAsync(_user.GetSubjectId(), _client.ClientId);\n            consent.Scopes.Count().Should().Be(2);\n            consent.Scopes.Should().Contain(\"scope1\");\n            consent.Scopes.Should().Contain(\"scope2\");\n        }\n\n        [Fact]\n        public async Task UpdateConsentAsync_empty_scopes_should_should_remove_consent()\n        {\n            await _subject.UpdateConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"scope2\") });\n\n            await _subject.UpdateConsentAsync(_user, _client, new ParsedScopeValue[] { });\n\n            var consent = await _userConsentStore.GetUserConsentAsync(_user.GetSubjectId(), _client.ClientId);\n            consent.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task RequiresConsentAsync_client_does_not_require_consent_should_not_require_consent()\n        {\n            _client.RequireConsent = false;\n\n            var result = await _subject.RequiresConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"scope2\") });\n\n            result.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task RequiresConsentAsync_client_does_not_allow_remember_consent_should_require_consent()\n        {\n            _client.AllowRememberConsent = false;\n\n            var result = await _subject.RequiresConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"scope2\") });\n\n            result.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task RequiresConsentAsync_no_scopes_should_not_require_consent()\n        {\n            var result = await _subject.RequiresConsentAsync(_user, _client, new ParsedScopeValue[] { });\n\n            result.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task RequiresConsentAsync_offline_access_should_require_consent()\n        {\n            var result = await _subject.RequiresConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"offline_access\") });\n\n            result.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task RequiresConsentAsync_no_prior_consent_should_require_consent()\n        {\n            var result = await _subject.RequiresConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"scope2\") });\n\n            result.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task RequiresConsentAsync_prior_consent_should_not_require_consent()\n        {\n            await _subject.UpdateConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"scope2\") });\n\n            var result = await _subject.RequiresConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"scope2\") });\n\n            result.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task RequiresConsentAsync_prior_consent_with_more_scopes_should_not_require_consent()\n        {\n            await _subject.UpdateConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"scope2\"), new ParsedScopeValue(\"scope3\") });\n\n            var result = await _subject.RequiresConsentAsync(_user, _client, new [] { new ParsedScopeValue(\"scope2\") });\n\n            result.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task RequiresConsentAsync_prior_consent_with_too_few_scopes_should_require_consent()\n        {\n            await _subject.UpdateConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope2\"), new ParsedScopeValue(\"scope3\") });\n\n            var result = await _subject.RequiresConsentAsync(_user, _client, new[] { new ParsedScopeValue(\"scope1\"), new ParsedScopeValue(\"scope2\") });\n\n            result.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task RequiresConsentAsync_expired_consent_should_require_consent()\n        {\n            now = DateTime.UtcNow;\n\n            var scopes = new[] { new ParsedScopeValue(\"foo\"), new ParsedScopeValue(\"bar\") };\n            _client.ConsentLifetime = 2;\n\n            await _subject.UpdateConsentAsync(_user, _client, scopes);\n\n            now = now.AddSeconds(3);\n\n            var result = await _subject.RequiresConsentAsync(_user, _client, scopes);\n\n            result.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task RequiresConsentAsync_expired_consent_should_remove_consent()\n        {\n            now = DateTime.UtcNow;\n\n            var scopes = new[] { new ParsedScopeValue(\"foo\"), new ParsedScopeValue(\"bar\") };\n            _client.ConsentLifetime = 2;\n\n            await _subject.UpdateConsentAsync(_user, _client, scopes);\n\n            now = now.AddSeconds(3);\n\n            await _subject.RequiresConsentAsync(_user, _client, scopes);\n\n            var result = await _userConsentStore.GetUserConsentAsync(_user.GetSubjectId(), _client.ClientId);\n\n            result.Should().BeNull();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/Default/DefaultCorsPolicyServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Services;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.Default\n{\n    public class DefaultCorsPolicyServiceTests\n    {\n        private const string Category = \"DefaultCorsPolicyService\";\n\n        private DefaultCorsPolicyService subject;\n\n        public DefaultCorsPolicyServiceTests()\n        {\n            subject = new DefaultCorsPolicyService(TestLogger.Create<DefaultCorsPolicyService>());\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task IsOriginAllowed_null_param_ReturnsFalse()\n        {\n            (await subject.IsOriginAllowedAsync(null)).Should().Be(false);\n            (await subject.IsOriginAllowedAsync(String.Empty)).Should().Be(false);\n            (await subject.IsOriginAllowedAsync(\"    \")).Should().Be(false);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task IsOriginAllowed_OriginIsAllowed_ReturnsTrue()\n        {\n            subject.AllowedOrigins.Add(\"http://foo\");\n            (await subject.IsOriginAllowedAsync(\"http://foo\")).Should().Be(true);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task IsOriginAllowed_OriginIsNotAllowed_ReturnsFalse()\n        {\n            subject.AllowedOrigins.Add(\"http://foo\");\n            (await subject.IsOriginAllowedAsync(\"http://bar\")).Should().Be(false);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task IsOriginAllowed_OriginIsInAllowedList_ReturnsTrue()\n        {\n            subject.AllowedOrigins.Add(\"http://foo\");\n            subject.AllowedOrigins.Add(\"http://bar\");\n            subject.AllowedOrigins.Add(\"http://baz\");\n            (await subject.IsOriginAllowedAsync(\"http://bar\")).Should().Be(true);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task IsOriginAllowed_OriginIsNotInAllowedList_ReturnsFalse()\n        {\n            subject.AllowedOrigins.Add(\"http://foo\");\n            subject.AllowedOrigins.Add(\"http://bar\");\n            subject.AllowedOrigins.Add(\"http://baz\");\n            (await subject.IsOriginAllowedAsync(\"http://quux\")).Should().Be(false);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task  IsOriginAllowed_AllowAllTrue_ReturnsTrue()\n        {\n            subject.AllowAll = true;\n            (await subject.IsOriginAllowedAsync(\"http://foo\")).Should().Be(true);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/Default/DefaultIdentityServerInteractionServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.Default\n{\n    public class DefaultIdentityServerInteractionServiceTests\n    {\n        private DefaultIdentityServerInteractionService _subject;\n\n        private IdentityServerOptions _options = new IdentityServerOptions();\n        private MockHttpContextAccessor _mockMockHttpContextAccessor;\n        private MockMessageStore<LogoutNotificationContext> _mockEndSessionStore = new MockMessageStore<LogoutNotificationContext>();\n        private MockMessageStore<LogoutMessage> _mockLogoutMessageStore = new MockMessageStore<LogoutMessage>();\n        private MockMessageStore<ErrorMessage> _mockErrorMessageStore = new MockMessageStore<ErrorMessage>();\n        private MockConsentMessageStore _mockConsentStore = new MockConsentMessageStore();\n        private MockPersistedGrantService _mockPersistedGrantService = new MockPersistedGrantService();\n        private MockUserSession _mockUserSession = new MockUserSession();\n        private MockReturnUrlParser _mockReturnUrlParser = new MockReturnUrlParser();\n\n        private ResourceValidationResult _resourceValidationResult;\n\n        public DefaultIdentityServerInteractionServiceTests()\n        {\n            _mockMockHttpContextAccessor = new MockHttpContextAccessor(_options, _mockUserSession, _mockEndSessionStore);\n\n            _subject = new DefaultIdentityServerInteractionService(new StubClock(), \n                _mockMockHttpContextAccessor,\n                _mockLogoutMessageStore,\n                _mockErrorMessageStore,\n                _mockConsentStore,\n                _mockPersistedGrantService,\n                _mockUserSession,\n                _mockReturnUrlParser,\n                TestLogger.Create<DefaultIdentityServerInteractionService>()\n            );\n\n            _resourceValidationResult = new ResourceValidationResult();\n            _resourceValidationResult.Resources.IdentityResources.Add(new IdentityResources.OpenId());\n            _resourceValidationResult.ParsedScopes.Add(new ParsedScopeValue(\"openid\"));\n        }\n        \n        [Fact]\n        public async Task GetLogoutContextAsync_valid_session_and_logout_id_should_not_provide_signout_iframe()\n        {\n            // for this, we're just confirming that since the session has changed, there's not use in doing the iframe and thsu SLO\n            _mockUserSession.SessionId = null;\n            _mockLogoutMessageStore.Messages.Add(\"id\", new Message<LogoutMessage>(new LogoutMessage() { SessionId = \"session\" }));\n\n            var context = await _subject.GetLogoutContextAsync(\"id\");\n\n            context.SignOutIFrameUrl.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task GetLogoutContextAsync_valid_session_no_logout_id_should_provide_iframe()\n        {\n            _mockUserSession.Clients.Add(\"foo\");\n            _mockUserSession.SessionId = \"session\";\n            _mockUserSession.User = new IdentityServerUser(\"123\").CreatePrincipal();\n\n            var context = await _subject.GetLogoutContextAsync(null);\n\n            context.SignOutIFrameUrl.Should().NotBeNull();\n        }\n\n        [Fact]\n        public async Task GetLogoutContextAsync_without_session_should_not_provide_iframe()\n        {\n            _mockUserSession.SessionId = null;\n            _mockLogoutMessageStore.Messages.Add(\"id\", new Message<LogoutMessage>(new LogoutMessage()));\n\n            var context = await _subject.GetLogoutContextAsync(\"id\");\n\n            context.SignOutIFrameUrl.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task CreateLogoutContextAsync_without_session_should_not_create_session()\n        {\n            var context = await _subject.CreateLogoutContextAsync();\n\n            context.Should().BeNull();\n            _mockLogoutMessageStore.Messages.Should().BeEmpty();\n        }\n\n        [Fact]\n        public async Task CreateLogoutContextAsync_with_session_should_create_session()\n        {\n            _mockUserSession.Clients.Add(\"foo\");\n            _mockUserSession.User = new IdentityServerUser(\"123\").CreatePrincipal();\n            _mockUserSession.SessionId = \"session\";\n\n            var context = await _subject.CreateLogoutContextAsync();\n\n            context.Should().NotBeNull();\n            _mockLogoutMessageStore.Messages.Should().NotBeEmpty();\n        }\n\n        [Fact]\n        public async Task GrantConsentAsync_should_throw_if_granted_and_no_subject()\n        {\n            Func<Task> act = async () => await _subject.GrantConsentAsync(\n                new AuthorizationRequest(), \n                new ConsentResponse() { ScopesValuesConsented = new[] { \"openid\" } }, \n                null);\n\n            (await act.Should().ThrowAsync<ArgumentNullException>())\n                .And.Message.Should().Contain(\"subject\");\n        }\n\n        [Fact]\n        public async Task GrantConsentAsync_should_allow_deny_for_anonymous_users()\n        {\n            var req = new AuthorizationRequest()\n            {\n                Client = new Client { ClientId = \"client\" },\n                ValidatedResources = _resourceValidationResult\n            };\n            await _subject.GrantConsentAsync(req, new ConsentResponse { Error = AuthorizationError.AccessDenied }, null);\n        }\n\n        [Fact]\n        public async Task GrantConsentAsync_should_use_current_subject_and_create_message()\n        {\n            _mockUserSession.User = new IdentityServerUser(\"bob\").CreatePrincipal();\n\n            var req = new AuthorizationRequest() { \n                Client = new Client { ClientId = \"client\" },\n                ValidatedResources = _resourceValidationResult\n            };\n            await _subject.GrantConsentAsync(req, new ConsentResponse(), null);\n\n            _mockConsentStore.Messages.Should().NotBeEmpty();\n            var consentRequest = new ConsentRequest(req, \"bob\");\n            _mockConsentStore.Messages.First().Key.Should().Be(consentRequest.Id);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/Default/DefaultPersistedGrantServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Stores.Serialization;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.Default\n{\n    public class DefaultPersistedGrantServiceTests\n    {\n        private DefaultPersistedGrantService _subject;\n        private InMemoryPersistedGrantStore _store = new InMemoryPersistedGrantStore();\n        private IAuthorizationCodeStore _codes;\n        private IRefreshTokenStore _refreshTokens;\n        private IReferenceTokenStore _referenceTokens;\n        private IUserConsentStore _userConsent;\n\n        private ClaimsPrincipal _user = new IdentityServerUser(\"123\").CreatePrincipal();\n\n        public DefaultPersistedGrantServiceTests()\n        {\n            _subject = new DefaultPersistedGrantService(\n                _store, \n                new PersistentGrantSerializer(), \n                TestLogger.Create<DefaultPersistedGrantService>());\n            _codes = new DefaultAuthorizationCodeStore(_store,\n                new PersistentGrantSerializer(),\n                new DefaultHandleGenerationService(),\n                TestLogger.Create<DefaultAuthorizationCodeStore>());\n            _refreshTokens = new DefaultRefreshTokenStore(_store,\n                new PersistentGrantSerializer(),\n                new DefaultHandleGenerationService(),\n                TestLogger.Create<DefaultRefreshTokenStore>());\n            _referenceTokens = new DefaultReferenceTokenStore(_store,\n                new PersistentGrantSerializer(),\n                new DefaultHandleGenerationService(),\n                TestLogger.Create<DefaultReferenceTokenStore>());\n            _userConsent = new DefaultUserConsentStore(_store,\n                new PersistentGrantSerializer(),\n                new DefaultHandleGenerationService(),\n                TestLogger.Create<DefaultUserConsentStore>());\n        }\n\n        [Fact]\n        public async Task GetAllGrantsAsync_should_return_all_grants()\n        {\n            await _userConsent.StoreUserConsentAsync(new Consent()\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = \"client1\",\n                SubjectId = \"123\",\n                Scopes = new string[] { \"foo1\", \"foo2\" }\n            });\n            await _userConsent.StoreUserConsentAsync(new Consent()\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = \"client2\",\n                SubjectId = \"123\",\n                Scopes = new string[] { \"foo3\" }\n            });\n            await _userConsent.StoreUserConsentAsync(new Consent()\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = \"client1\",\n                SubjectId = \"456\",\n                Scopes = new string[] { \"foo3\" }\n            });\n\n            var handle1 = await _referenceTokens.StoreReferenceTokenAsync(new Token()\n            {\n                ClientId = \"client1\",\n                Audiences = { \"aud\" },\n                CreationTime = DateTime.UtcNow,\n                Type = \"type\",\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"123\"),\n                    new Claim(\"scope\", \"bar1\"),\n                    new Claim(\"scope\", \"bar2\")\n                }\n            });\n\n            var handle2 = await _referenceTokens.StoreReferenceTokenAsync(new Token()\n            {\n                ClientId = \"client2\",\n                Audiences = { \"aud\" },\n                CreationTime = DateTime.UtcNow,\n                Type = \"type\",\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"123\"),\n                    new Claim(\"scope\", \"bar3\")\n                }\n            });\n\n            var handle3 = await _referenceTokens.StoreReferenceTokenAsync(new Token()\n            {\n                ClientId = \"client1\",\n                Audiences = { \"aud\" },\n                CreationTime = DateTime.UtcNow,\n                Type = \"type\",\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"456\"),\n                    new Claim(\"scope\", \"bar3\")\n                }\n            });\n\n            var handle4 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = \"client1\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Type = \"type\",\n                    Claims = new List<Claim>\n                    {\n                        new Claim(\"sub\", \"123\"),\n                        new Claim(\"scope\", \"baz1\"),\n                        new Claim(\"scope\", \"baz2\")\n                    }\n                },\n                Version = 1\n            });\n            var handle5 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = \"client1\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Type = \"type\",\n                    Claims = new List<Claim>\n                    {\n                        new Claim(\"sub\", \"456\"),\n                        new Claim(\"scope\", \"baz3\")\n                    }\n                },\n                Version = 1\n            });\n            var handle6 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = \"client2\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Type = \"type\",\n                    Claims = new List<Claim>\n                    {\n                        new Claim(\"sub\", \"123\"),\n                        new Claim(\"scope\", \"baz3\")\n                    }\n                },\n                Version = 1\n            });\n\n            var handle7 = await _codes.StoreAuthorizationCodeAsync(new AuthorizationCode()\n            {\n                ClientId = \"client1\",\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Subject = _user,\n                CodeChallenge = \"challenge\",\n                RedirectUri = \"http://client/cb\",\n                Nonce = \"nonce\",\n                RequestedScopes = new string[] { \"quux1\", \"quux2\" }\n            });\n\n            var handle8 = await _codes.StoreAuthorizationCodeAsync(new AuthorizationCode()\n            {\n                ClientId = \"client2\",\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Subject = _user,\n                CodeChallenge = \"challenge\",\n                RedirectUri = \"http://client/cb\",\n                Nonce = \"nonce\",\n                RequestedScopes = new string[] { \"quux3\" }\n            });\n\n            var handle9 = await _codes.StoreAuthorizationCodeAsync(new AuthorizationCode()\n            {\n                ClientId = \"client1\",\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Subject = new IdentityServerUser(\"456\").CreatePrincipal(),\n                CodeChallenge = \"challenge\",\n                RedirectUri = \"http://client/cb\",\n                Nonce = \"nonce\",\n                RequestedScopes = new string[] { \"quux3\" }\n            });\n\n            var grants = await _subject.GetAllGrantsAsync(\"123\");\n\n            grants.Count().Should().Be(2);\n            var grant1 = grants.First(x => x.ClientId == \"client1\");\n            grant1.SubjectId.Should().Be(\"123\");\n            grant1.ClientId.Should().Be(\"client1\");\n            grant1.Scopes.Should().BeEquivalentTo(new string[] { \"foo1\", \"foo2\", \"bar1\", \"bar2\", \"baz1\", \"baz2\", \"quux1\", \"quux2\" });\n\n            var grant2 = grants.First(x => x.ClientId == \"client2\");\n            grant2.SubjectId.Should().Be(\"123\");\n            grant2.ClientId.Should().Be(\"client2\");\n            grant2.Scopes.Should().BeEquivalentTo(new string[] { \"foo3\", \"bar3\", \"baz3\", \"quux3\" });\n        }\n\n        [Fact]\n        public async Task RemoveAllGrantsAsync_should_remove_all_grants()\n        {\n            await _userConsent.StoreUserConsentAsync(new Consent()\n            {\n                ClientId = \"client1\",\n                SubjectId = \"123\",\n                Scopes = new string[] { \"foo1\", \"foo2\" }\n            });\n            await _userConsent.StoreUserConsentAsync(new Consent()\n            {\n                ClientId = \"client2\",\n                SubjectId = \"123\",\n                Scopes = new string[] { \"foo3\" }\n            });\n            await _userConsent.StoreUserConsentAsync(new Consent()\n            {\n                ClientId = \"client1\",\n                SubjectId = \"456\",\n                Scopes = new string[] { \"foo3\" }\n            });\n\n            var handle1 = await _referenceTokens.StoreReferenceTokenAsync(new Token()\n            {\n                ClientId = \"client1\",\n                Audiences = { \"aud\" },\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Type = \"type\",\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"123\"),\n                    new Claim(\"scope\", \"bar1\"),\n                    new Claim(\"scope\", \"bar2\")\n                }\n            });\n\n            var handle2 = await _referenceTokens.StoreReferenceTokenAsync(new Token()\n            {\n                ClientId = \"client2\",\n                Audiences = { \"aud\" },\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Type = \"type\",\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"123\"),\n                    new Claim(\"scope\", \"bar3\")\n                }\n            });\n\n            var handle3 = await _referenceTokens.StoreReferenceTokenAsync(new Token()\n            {\n                ClientId = \"client1\",\n                Audiences = { \"aud\" },\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Type = \"type\",\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"456\"),\n                    new Claim(\"scope\", \"bar3\")\n                }\n            });\n\n            var handle4 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = \"client1\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Type = \"type\",\n                    Claims = new List<Claim>\n                    {\n                        new Claim(\"sub\", \"123\"),\n                        new Claim(\"scope\", \"baz1\"),\n                        new Claim(\"scope\", \"baz2\")\n                    }\n                },\n                Version = 1\n            });\n            var handle5 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = \"client1\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Type = \"type\",\n                    Claims = new List<Claim>\n                    {\n                        new Claim(\"sub\", \"456\"),\n                        new Claim(\"scope\", \"baz3\")\n                    }\n                },\n                Version = 1\n            });\n            var handle6 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = \"client2\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Type = \"type\",\n                    Claims = new List<Claim>\n                    {\n                        new Claim(\"sub\", \"123\"),\n                        new Claim(\"scope\", \"baz3\")\n                    }\n                },\n                Version = 1\n            });\n\n            var handle7 = await _codes.StoreAuthorizationCodeAsync(new AuthorizationCode()\n            {\n                ClientId = \"client1\",\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Subject = _user,\n                CodeChallenge = \"challenge\",\n                RedirectUri = \"http://client/cb\",\n                Nonce = \"nonce\",\n                RequestedScopes = new string[] { \"quux1\", \"quux2\" }\n            });\n\n            var handle8 = await _codes.StoreAuthorizationCodeAsync(new AuthorizationCode()\n            {\n                ClientId = \"client2\",\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Subject = _user,\n                CodeChallenge = \"challenge\",\n                RedirectUri = \"http://client/cb\",\n                Nonce = \"nonce\",\n                RequestedScopes = new string[] { \"quux3\" }\n            });\n\n            var handle9 = await _codes.StoreAuthorizationCodeAsync(new AuthorizationCode()\n            {\n                ClientId = \"client1\",\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Subject = new IdentityServerUser(\"456\").CreatePrincipal(),\n                CodeChallenge = \"challenge\",\n                RedirectUri = \"http://client/cb\",\n                Nonce = \"nonce\",\n                RequestedScopes = new string[] { \"quux3\" }\n            });\n\n            await _subject.RemoveAllGrantsAsync(\"123\", \"client1\");\n\n            (await _referenceTokens.GetReferenceTokenAsync(handle1)).Should().BeNull();\n            (await _referenceTokens.GetReferenceTokenAsync(handle2)).Should().NotBeNull();\n            (await _referenceTokens.GetReferenceTokenAsync(handle3)).Should().NotBeNull();\n            (await _refreshTokens.GetRefreshTokenAsync(handle4)).Should().BeNull();\n            (await _refreshTokens.GetRefreshTokenAsync(handle5)).Should().NotBeNull();\n            (await _refreshTokens.GetRefreshTokenAsync(handle6)).Should().NotBeNull();\n            (await _codes.GetAuthorizationCodeAsync(handle7)).Should().BeNull();\n            (await _codes.GetAuthorizationCodeAsync(handle8)).Should().NotBeNull();\n            (await _codes.GetAuthorizationCodeAsync(handle9)).Should().NotBeNull();\n        }\n        [Fact]\n        public async Task RemoveAllGrantsAsync_should_filter_on_session_id()\n        {\n            {\n                var handle1 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client1\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session1\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                var handle2 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client2\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session1\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                var handle3 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client3\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session3\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n\n                await _subject.RemoveAllGrantsAsync(\"123\");\n\n                (await _refreshTokens.GetRefreshTokenAsync(handle1)).Should().BeNull();\n                (await _refreshTokens.GetRefreshTokenAsync(handle2)).Should().BeNull();\n                (await _refreshTokens.GetRefreshTokenAsync(handle3)).Should().BeNull();\n                await _refreshTokens.RemoveRefreshTokenAsync(handle1);\n                await _refreshTokens.RemoveRefreshTokenAsync(handle2);\n                await _refreshTokens.RemoveRefreshTokenAsync(handle3);\n            }\n            {\n                var handle1 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client1\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session1\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                var handle2 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client2\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session1\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                var handle3 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client3\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session3\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n\n                await _subject.RemoveAllGrantsAsync(\"123\", \"client1\");\n\n                (await _refreshTokens.GetRefreshTokenAsync(handle1)).Should().BeNull();\n                (await _refreshTokens.GetRefreshTokenAsync(handle2)).Should().NotBeNull();\n                (await _refreshTokens.GetRefreshTokenAsync(handle3)).Should().NotBeNull();\n                await _refreshTokens.RemoveRefreshTokenAsync(handle1);\n                await _refreshTokens.RemoveRefreshTokenAsync(handle2);\n                await _refreshTokens.RemoveRefreshTokenAsync(handle3);\n            }\n            {\n                var handle1 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client1\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session1\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                var handle2 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client2\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session1\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                var handle3 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client3\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session1\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                var handle4 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client1\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session2\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                await _subject.RemoveAllGrantsAsync(\"123\", \"client1\", \"session1\");\n\n                (await _refreshTokens.GetRefreshTokenAsync(handle1)).Should().BeNull();\n                (await _refreshTokens.GetRefreshTokenAsync(handle2)).Should().NotBeNull();\n                (await _refreshTokens.GetRefreshTokenAsync(handle3)).Should().NotBeNull();\n                (await _refreshTokens.GetRefreshTokenAsync(handle4)).Should().NotBeNull();\n                await _refreshTokens.RemoveRefreshTokenAsync(handle1);\n                await _refreshTokens.RemoveRefreshTokenAsync(handle2);\n                await _refreshTokens.RemoveRefreshTokenAsync(handle3);\n                await _refreshTokens.RemoveRefreshTokenAsync(handle4);\n            }\n            {\n                var handle1 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client1\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session1\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                var handle2 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client2\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session1\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                var handle3 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client3\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session1\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                var handle4 = await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n                {\n                    CreationTime = DateTime.UtcNow,\n                    Lifetime = 10,\n                    AccessToken = new Token\n                    {\n                        ClientId = \"client1\",\n                        Audiences = { \"aud\" },\n                        CreationTime = DateTime.UtcNow,\n                        Type = \"type\",\n                        Claims = new List<Claim>\n                        {\n                            new Claim(\"sub\", \"123\"),\n                            new Claim(\"sid\", \"session2\"),\n                            new Claim(\"scope\", \"baz\")\n                        }\n                    },\n                    Version = 1\n                });\n                await _subject.RemoveAllGrantsAsync(\"123\", sessionId:\"session1\");\n\n                (await _refreshTokens.GetRefreshTokenAsync(handle1)).Should().BeNull();\n                (await _refreshTokens.GetRefreshTokenAsync(handle2)).Should().BeNull();\n                (await _refreshTokens.GetRefreshTokenAsync(handle3)).Should().BeNull();\n                (await _refreshTokens.GetRefreshTokenAsync(handle4)).Should().NotBeNull();\n                await _refreshTokens.RemoveRefreshTokenAsync(handle1);\n                await _refreshTokens.RemoveRefreshTokenAsync(handle2);\n                await _refreshTokens.RemoveRefreshTokenAsync(handle3);\n                await _refreshTokens.RemoveRefreshTokenAsync(handle4);\n            }\n        }\n\n        [Fact]\n        public async Task GetAllGrantsAsync_should_aggregate_correctly()\n        {\n            await _userConsent.StoreUserConsentAsync(new Consent()\n            {\n                ClientId = \"client1\",\n                SubjectId = \"123\",\n                Scopes = new string[] { \"foo1\", \"foo2\" }\n            });\n\n            var grants = await _subject.GetAllGrantsAsync(\"123\");\n\n            grants.Count().Should().Be(1);\n            grants.First().Scopes.Should().Contain(new string[] { \"foo1\", \"foo2\" });\n\n            var handle9 = await _codes.StoreAuthorizationCodeAsync(new AuthorizationCode()\n            {\n                ClientId = \"client1\",\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                CodeChallenge = \"challenge\",\n                RedirectUri = \"http://client/cb\",\n                Nonce = \"nonce\",\n                RequestedScopes = new string[] { \"quux3\" }\n            });\n\n            grants = await _subject.GetAllGrantsAsync(\"123\");\n\n            grants.Count().Should().Be(1);\n            grants.First().Scopes.Should().Contain(new string[] { \"foo1\", \"foo2\", \"quux3\" });\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/Default/DefaultRefreshTokenServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Stores.Serialization;\nusing System;\nusing System.Collections.Generic;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.Default\n{\n    public class DefaultRefreshTokenServiceTests\n    {\n        private DefaultRefreshTokenService _subject;\n        private DefaultRefreshTokenStore _store;\n\n        private ClaimsPrincipal _user = new IdentityServerUser(\"123\").CreatePrincipal();\n        private StubClock _clock = new StubClock();\n\n        public DefaultRefreshTokenServiceTests()\n        {\n            _store = new DefaultRefreshTokenStore(\n                new InMemoryPersistedGrantStore(),\n                new PersistentGrantSerializer(),\n                new DefaultHandleGenerationService(),\n                TestLogger.Create<DefaultRefreshTokenStore>());\n\n            _subject = new DefaultRefreshTokenService(\n                _store, \n                new TestProfileService(),\n                _clock, \n                TestLogger.Create<DefaultRefreshTokenService>());\n        }\n\n        [Fact]\n        public async Task CreateRefreshToken_token_exists_in_store()\n        {\n            var client = new Client();\n            var accessToken = new Token();\n\n            var handle = await _subject.CreateRefreshTokenAsync(_user, accessToken, client);\n\n            (await _store.GetRefreshTokenAsync(handle)).Should().NotBeNull();\n        }\n\n        [Fact]\n        public async Task CreateRefreshToken_should_match_absolute_lifetime()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.ReUse,\n                RefreshTokenExpiration = TokenExpiration.Absolute,\n                AbsoluteRefreshTokenLifetime = 10\n            };\n\n            var handle = await _subject.CreateRefreshTokenAsync(_user, new Token(), client);\n\n            var refreshToken = (await _store.GetRefreshTokenAsync(handle));\n\n            refreshToken.Should().NotBeNull();\n            refreshToken.Lifetime.Should().Be(client.AbsoluteRefreshTokenLifetime);\n        }\n\n        [Fact]\n        public async Task CreateRefreshToken_should_cap_sliding_lifetime_that_exceeds_absolute_lifetime()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.ReUse,\n                RefreshTokenExpiration = TokenExpiration.Sliding,\n                SlidingRefreshTokenLifetime  = 100,\n                AbsoluteRefreshTokenLifetime = 10\n            };\n\n            var handle = await _subject.CreateRefreshTokenAsync(_user, new Token(), client);\n\n            var refreshToken = (await _store.GetRefreshTokenAsync(handle));\n\n            refreshToken.Should().NotBeNull();\n            refreshToken.Lifetime.Should().Be(client.AbsoluteRefreshTokenLifetime);\n        }\n\n        [Fact]\n        public async Task CreateRefreshToken_should_match_sliding_lifetime()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.ReUse,\n                RefreshTokenExpiration = TokenExpiration.Sliding,\n                SlidingRefreshTokenLifetime = 10\n            };\n\n            var handle = await _subject.CreateRefreshTokenAsync(_user, new Token(), client);\n\n            var refreshToken = (await _store.GetRefreshTokenAsync(handle));\n\n            refreshToken.Should().NotBeNull();\n            refreshToken.Lifetime.Should().Be(client.SlidingRefreshTokenLifetime);\n        }\n\n        [Fact]\n        public async Task UpdateRefreshToken_one_time_use_should_create_new_token()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.OneTimeOnly\n            };\n\n            var refreshToken = new RefreshToken\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = client.ClientId,\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            };\n\n            var handle = await _store.StoreRefreshTokenAsync(refreshToken);\n\n            (await _subject.UpdateRefreshTokenAsync(handle, refreshToken, client))\n                .Should().NotBeNull()\n                .And\n                .NotBe(handle);\n        }\n\n        [Fact]\n        public async Task UpdateRefreshToken_sliding_with_non_zero_absolute_should_update_lifetime()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.ReUse,\n                RefreshTokenExpiration = TokenExpiration.Sliding,\n                SlidingRefreshTokenLifetime = 10,\n                AbsoluteRefreshTokenLifetime = 100\n            };\n\n            var now = DateTime.UtcNow;\n            _clock.UtcNowFunc = () => now;\n\n            var handle = await _store.StoreRefreshTokenAsync(new RefreshToken\n            {\n                CreationTime = now.AddSeconds(-10),\n                AccessToken = new Token\n                {\n                    ClientId = client.ClientId,\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            });\n\n            var refreshToken = await _store.GetRefreshTokenAsync(handle);\n            var newHandle = await _subject.UpdateRefreshTokenAsync(handle, refreshToken, client);\n\n            newHandle.Should().NotBeNull().And.Be(handle);\n\n            var newRefreshToken = await _store.GetRefreshTokenAsync(newHandle);\n\n            newRefreshToken.Should().NotBeNull();\n            newRefreshToken.Lifetime.Should().Be((int)(now - newRefreshToken.CreationTime).TotalSeconds + client.SlidingRefreshTokenLifetime);\n        }\n\n        [Fact]\n        public async Task UpdateRefreshToken_lifetime_exceeds_absolute_should_be_absolute_lifetime()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.ReUse,\n                RefreshTokenExpiration = TokenExpiration.Sliding,\n                SlidingRefreshTokenLifetime = 10,\n                AbsoluteRefreshTokenLifetime = 1000\n            };\n\n            var now = DateTime.UtcNow;\n            _clock.UtcNowFunc = () => now;\n\n            var handle = await _store.StoreRefreshTokenAsync(new RefreshToken\n            {\n                CreationTime = now.AddSeconds(-1000),\n                AccessToken = new Token\n                {\n                    ClientId = client.ClientId,\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            });\n\n            var refreshToken = await _store.GetRefreshTokenAsync(handle);\n            var newHandle = await _subject.UpdateRefreshTokenAsync(handle, refreshToken, client);\n\n            newHandle.Should().NotBeNull().And.Be(handle);\n\n            var newRefreshToken = await _store.GetRefreshTokenAsync(newHandle);\n\n            newRefreshToken.Should().NotBeNull();\n            newRefreshToken.Lifetime.Should().Be(client.AbsoluteRefreshTokenLifetime);\n        }\n\n        [Fact]\n        public async Task UpdateRefreshToken_sliding_with_zero_absolute_should_update_lifetime()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.ReUse,\n                RefreshTokenExpiration = TokenExpiration.Sliding,\n                SlidingRefreshTokenLifetime = 10,\n                AbsoluteRefreshTokenLifetime = 0\n            };\n\n            var now = DateTime.UtcNow;\n            _clock.UtcNowFunc = () => now;\n\n            var handle = await _store.StoreRefreshTokenAsync(new RefreshToken\n            {\n                CreationTime = now.AddSeconds(-1000),\n                AccessToken = new Token\n                {\n                    ClientId = client.ClientId,\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            });\n\n            var refreshToken = await _store.GetRefreshTokenAsync(handle);\n            var newHandle = await _subject.UpdateRefreshTokenAsync(handle, refreshToken, client);\n\n            newHandle.Should().NotBeNull().And.Be(handle);\n\n            var newRefreshToken = await _store.GetRefreshTokenAsync(newHandle);\n\n            newRefreshToken.Should().NotBeNull();\n            newRefreshToken.Lifetime.Should().Be((int)(now - newRefreshToken.CreationTime).TotalSeconds + client.SlidingRefreshTokenLifetime);\n        }\n\n        [Fact]\n        public async Task UpdateRefreshToken_for_onetime_and_sliding_with_zero_absolute_should_update_lifetime()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.OneTimeOnly,\n                RefreshTokenExpiration = TokenExpiration.Sliding,\n                SlidingRefreshTokenLifetime = 10,\n                AbsoluteRefreshTokenLifetime = 0\n            };\n\n            var now = DateTime.UtcNow;\n            _clock.UtcNowFunc = () => now;\n\n            var handle = await _store.StoreRefreshTokenAsync(new RefreshToken\n            {\n                CreationTime = now.AddSeconds(-1000),\n                AccessToken = new Token\n                {\n                    ClientId = client.ClientId,\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            });\n\n            var refreshToken = await _store.GetRefreshTokenAsync(handle);\n            var newHandle = await _subject.UpdateRefreshTokenAsync(handle, refreshToken, client);\n\n            newHandle.Should().NotBeNull().And.NotBe(handle);\n\n            var newRefreshToken = await _store.GetRefreshTokenAsync(newHandle);\n\n            newRefreshToken.Should().NotBeNull();\n            newRefreshToken.Lifetime.Should().Be((int)(now - newRefreshToken.CreationTime).TotalSeconds + client.SlidingRefreshTokenLifetime);\n        }\n\n        [Fact]\n        public async Task UpdateRefreshToken_one_time_use_should_consume_token_and_create_new_one_with_correct_dates()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.OneTimeOnly\n            };\n\n            var refreshToken = new RefreshToken\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = client.ClientId,\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            };\n\n            var handle = await _store.StoreRefreshTokenAsync(refreshToken);\n\n            var now = DateTime.UtcNow;\n            _clock.UtcNowFunc = () => now;\n\n            var newHandle = await _subject.UpdateRefreshTokenAsync(handle, refreshToken, client);\n\n            var oldToken = await _store.GetRefreshTokenAsync(handle);\n            var newToken = await _store.GetRefreshTokenAsync(newHandle);\n\n            oldToken.ConsumedTime.Should().Be(now);\n            newToken.ConsumedTime.Should().BeNull();\n        }\n        \n        [Fact]\n        public async Task ValidateRefreshToken_invalid_token_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.OneTimeOnly\n            };\n\n            var result = await _subject.ValidateRefreshTokenAsync(\"invalid\", client);\n\n            result.IsError.Should().BeTrue();\n        }\n        \n        [Fact]\n        public async Task ValidateRefreshToken_client_without_allow_offline_access_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                RefreshTokenUsage = TokenUsage.OneTimeOnly\n            };\n\n            var refreshToken = new RefreshToken\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = client.ClientId,\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            };\n\n            var handle = await _store.StoreRefreshTokenAsync(refreshToken);\n\n            var now = DateTime.UtcNow;\n            _clock.UtcNowFunc = () => now;\n\n            var result = await _subject.ValidateRefreshTokenAsync(handle, client);\n\n            result.IsError.Should().BeTrue();\n        }\n        \n        [Fact]\n        public async Task ValidateRefreshToken_invalid_client_binding_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                AllowOfflineAccess = true,\n                RefreshTokenUsage = TokenUsage.OneTimeOnly\n            };\n\n            var refreshToken = new RefreshToken\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = \"client2\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            };\n\n            var handle = await _store.StoreRefreshTokenAsync(refreshToken);\n\n            var now = DateTime.UtcNow;\n            _clock.UtcNowFunc = () => now;\n\n            var result = await _subject.ValidateRefreshTokenAsync(handle, client);\n\n            result.IsError.Should().BeTrue();\n        }\n        \n        [Fact]\n        public async Task ValidateRefreshToken_expired_token_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                AllowOfflineAccess = true,\n                RefreshTokenUsage = TokenUsage.OneTimeOnly\n            };\n\n            var refreshToken = new RefreshToken\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = client.ClientId,\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            };\n\n            var handle = await _store.StoreRefreshTokenAsync(refreshToken);\n\n            var now = DateTime.UtcNow.AddSeconds(20);\n            _clock.UtcNowFunc = () => now;\n\n            var result = await _subject.ValidateRefreshTokenAsync(handle, client);\n\n            result.IsError.Should().BeTrue();\n        }\n        \n        [Fact]\n        public async Task ValidateRefreshToken_consumed_token_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                AllowOfflineAccess = true,\n                RefreshTokenUsage = TokenUsage.OneTimeOnly\n            };\n\n            var refreshToken = new RefreshToken\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                ConsumedTime = DateTime.UtcNow,\n                \n                AccessToken = new Token\n                {\n                    ClientId = client.ClientId,\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            };\n\n            var handle = await _store.StoreRefreshTokenAsync(refreshToken);\n\n            var now = DateTime.UtcNow;\n            _clock.UtcNowFunc = () => now;\n\n            var result = await _subject.ValidateRefreshTokenAsync(handle, client);\n\n            result.IsError.Should().BeTrue();\n        }\n        \n        [Fact]\n        public async Task ValidateRefreshToken_valid_token_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"client1\",\n                AllowOfflineAccess = true,\n                RefreshTokenUsage = TokenUsage.OneTimeOnly\n            };\n\n            var refreshToken = new RefreshToken\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = client.ClientId,\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Claims = new List<Claim>()\n                    {\n                        new Claim(\"sub\", \"123\")\n                    }\n                }\n            };\n\n            var handle = await _store.StoreRefreshTokenAsync(refreshToken);\n\n            var now = DateTime.UtcNow;\n            _clock.UtcNowFunc = () => now;\n\n            var result = await _subject.ValidateRefreshTokenAsync(handle, client);\n\n            result.IsError.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/Default/DefaultTokenServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.Extensions.DependencyInjection;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.Default\n{\n    public class DefaultTokenServiceTests\n    {\n        private DefaultTokenService _subject;\n\n        MockClaimsService _mockClaimsService = new MockClaimsService();\n        MockReferenceTokenStore _mockReferenceTokenStore = new MockReferenceTokenStore();\n        MockTokenCreationService _mockTokenCreationService = new MockTokenCreationService();\n        DefaultHttpContext _httpContext = new DefaultHttpContext();\n        MockSystemClock _mockSystemClock = new MockSystemClock();\n        MockKeyMaterialService _mockKeyMaterialService = new MockKeyMaterialService();\n        IdentityServerOptions _options = new IdentityServerOptions();\n\n        public DefaultTokenServiceTests()\n        {\n            _options.IssuerUri = \"https://test.identityserver8.io\";\n\n            var svcs = new ServiceCollection();\n            svcs.AddSingleton(_options);\n            _httpContext.RequestServices = svcs.BuildServiceProvider();\n\n            _subject = new DefaultTokenService(\n                _mockClaimsService,\n                _mockReferenceTokenStore,\n                _mockTokenCreationService,\n                new HttpContextAccessor { HttpContext = _httpContext },\n                _mockSystemClock,\n                _mockKeyMaterialService,\n                _options,\n                TestLogger.Create<DefaultTokenService>());\n        }\n\n        [Fact]\n        public async Task CreateAccessTokenAsync_should_include_aud_for_each_ApiResource()\n        {\n            var request = new TokenCreationRequest { \n                ValidatedResources = new ResourceValidationResult()\n                {\n                    Resources = new Resources()\n                    {\n                        ApiResources = \n                        {\n                            new ApiResource(\"api1\"){ Scopes = { \"scope1\" } },\n                            new ApiResource(\"api2\"){ Scopes = { \"scope2\" } },\n                            new ApiResource(\"api3\"){ Scopes = { \"scope3\" } },\n                        },\n                    },\n                    ParsedScopes =\n                    {\n                        new ParsedScopeValue(\"scope1\"),\n                        new ParsedScopeValue(\"scope2\"),\n                        new ParsedScopeValue(\"scope3\"),\n                    }\n                },\n                ValidatedRequest = new ValidatedRequest()\n                {\n                    Client = new Client { }\n                }\n            };\n\n            var result = await _subject.CreateAccessTokenAsync(request);\n\n            result.Audiences.Count.Should().Be(3);\n            result.Audiences.Should().BeEquivalentTo(new[] { \"api1\", \"api2\", \"api3\" });\n        }\n\n        [Fact]\n        public async Task CreateAccessTokenAsync_when_no_apiresources_should_not_include_any_aud()\n        {\n            var request = new TokenCreationRequest\n            {\n                ValidatedResources = new ResourceValidationResult()\n                {\n                    Resources = new Resources()\n                    {\n                        ApiScopes =\n                        {\n                            new ApiScope(\"scope1\"),\n                            new ApiScope(\"scope2\"),\n                            new ApiScope(\"scope3\"),\n                        },\n                    },\n                    ParsedScopes =\n                    {\n                        new ParsedScopeValue(\"scope1\"),\n                        new ParsedScopeValue(\"scope2\"),\n                        new ParsedScopeValue(\"scope3\"),\n                    }\n                },\n                ValidatedRequest = new ValidatedRequest()\n                {\n                    Client = new Client { }\n                }\n            };\n\n            var result = await _subject.CreateAccessTokenAsync(request);\n\n            result.Audiences.Count.Should().Be(0);\n        }\n\n\n        [Fact]\n        public async Task CreateAccessTokenAsync_when_no_session_should_not_include_sid()\n        {\n            var request = new TokenCreationRequest\n            {\n                ValidatedResources = new ResourceValidationResult(),\n                ValidatedRequest = new ValidatedRequest()\n                {\n                    Client = new Client { },\n                    SessionId = null\n                }\n            };\n\n            var result = await _subject.CreateAccessTokenAsync(request);\n\n            result.Claims.SingleOrDefault(x => x.Type == JwtClaimTypes.SessionId).Should().BeNull();\n        }\n        [Fact]\n        public async Task CreateAccessTokenAsync_when_session_should_include_sid()\n        {\n            var request = new TokenCreationRequest\n            {\n                ValidatedResources = new ResourceValidationResult(),\n                ValidatedRequest = new ValidatedRequest()\n                {\n                    Client = new Client { },\n                    SessionId = \"123\"\n                }\n            };\n\n            var result = await _subject.CreateAccessTokenAsync(request);\n\n            result.Claims.SingleOrDefault(x => x.Type == JwtClaimTypes.SessionId).Value.Should().Be(\"123\");\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/Default/DefaultUserSessionTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Linq;\nusing System.Net;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Services;\nusing Microsoft.AspNetCore.Authentication;\nusing Microsoft.AspNetCore.Http;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.Default\n{\n    public class DefaultUserSessionTests\n    {\n        private DefaultUserSession _subject;\n        private MockHttpContextAccessor _mockHttpContext = new MockHttpContextAccessor();\n        private MockAuthenticationHandlerProvider _mockAuthenticationHandlerProvider = new MockAuthenticationHandlerProvider();\n        private MockAuthenticationHandler _mockAuthenticationHandler = new MockAuthenticationHandler();\n\n        private IdentityServerOptions _options = new IdentityServerOptions();\n        private ClaimsPrincipal _user;\n        private AuthenticationProperties _props = new AuthenticationProperties();\n\n        public DefaultUserSessionTests()\n        {\n            _mockAuthenticationHandlerProvider.Handler = _mockAuthenticationHandler;\n\n            _user = new IdentityServerUser(\"123\").CreatePrincipal();\n            _subject = new DefaultUserSession(\n                _mockHttpContext, \n                _mockAuthenticationHandlerProvider,\n                _options,\n                new StubClock(), \n                TestLogger.Create<DefaultUserSession>());\n        }\n\n        [Fact]\n        public async Task CreateSessionId_when_user_is_anonymous_should_generate_new_sid()\n        {\n            await _subject.CreateSessionIdAsync(_user, _props);\n\n            _props.GetSessionId().Should().NotBeNull();\n        }\n\n        [Fact]\n        public async Task CreateSessionId_when_user_is_authenticated_should_not_generate_new_sid()\n        {\n            // this test is needed to allow same session id when cookie is slid\n            // IOW, if UI layer passes in same properties dictionary, then we assume it's the same user\n\n            _props.SetSessionId(\"999\");\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            await _subject.CreateSessionIdAsync(_user, _props);\n\n            _props.GetSessionId().Should().NotBeNull();\n            _props.GetSessionId().Should().Be(\"999\");\n        }\n\n        [Fact]\n        public async Task CreateSessionId_when_props_does_not_contain_key_should_generate_new_sid()\n        {\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            _props.GetSessionId().Should().BeNull();\n\n            await _subject.CreateSessionIdAsync(_user, _props);\n\n            _props.GetSessionId().Should().NotBeNull();\n        }\n\n        [Fact]\n        public async Task CreateSessionId_when_user_is_authenticated_but_different_sub_should_create_new_sid()\n        {\n            _props.SetSessionId(\"999\");\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            await _subject.CreateSessionIdAsync(new IdentityServerUser(\"alice\").CreatePrincipal(), _props);\n\n            _props.GetSessionId().Should().NotBeNull();\n            _props.GetSessionId().Should().NotBe(\"999\");\n        }\n\n        [Fact]\n        public async Task CreateSessionId_should_issue_session_id_cookie()\n        {\n            await _subject.CreateSessionIdAsync(_user, _props);\n\n            var cookieContainer = new CookieContainer();\n            var cookies = _mockHttpContext.HttpContext.Response.Headers.Where(x => x.Key.Equals(\"Set-Cookie\", StringComparison.OrdinalIgnoreCase)).Select(x => x.Value);\n            cookieContainer.SetCookies(new Uri(\"http://server\"), string.Join(\",\", cookies));\n            _mockHttpContext.HttpContext.Response.Headers.Clear();\n\n            var cookie = cookieContainer.GetCookies(new Uri(\"http://server\")).Cast<Cookie>().Where(x => x.Name == _options.Authentication.CheckSessionCookieName).FirstOrDefault();\n            cookie.Value.Should().Be(_props.GetSessionId());\n        }\n\n        [Fact]\n        public async Task EnsureSessionIdCookieAsync_should_add_cookie()\n        {\n            _props.SetSessionId(\"999\");\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            await _subject.EnsureSessionIdCookieAsync();\n\n            var cookieContainer = new CookieContainer();\n            var cookies = _mockHttpContext.HttpContext.Response.Headers.Where(x => x.Key.Equals(\"Set-Cookie\", StringComparison.OrdinalIgnoreCase)).Select(x => x.Value);\n            cookieContainer.SetCookies(new Uri(\"http://server\"), string.Join(\",\", cookies));\n            _mockHttpContext.HttpContext.Response.Headers.Clear();\n\n            var cookie = cookieContainer.GetCookies(new Uri(\"http://server\")).Cast<Cookie>().Where(x => x.Name == _options.Authentication.CheckSessionCookieName).FirstOrDefault();\n            cookie.Value.Should().Be(\"999\");\n        }\n\n        [Fact]\n        public async Task EnsureSessionIdCookieAsync_should_not_add_cookie_if_no_sid()\n        {\n            await _subject.EnsureSessionIdCookieAsync();\n\n            var cookieContainer = new CookieContainer();\n            var cookies = _mockHttpContext.HttpContext.Response.Headers.Where(x => x.Key.Equals(\"Set-Cookie\", StringComparison.OrdinalIgnoreCase)).Select(x => x.Value);\n            cookieContainer.SetCookies(new Uri(\"http://server\"), string.Join(\",\", cookies));\n            _mockHttpContext.HttpContext.Response.Headers.Clear();\n\n            var cookie = cookieContainer.GetCookies(new Uri(\"http://server\")).Cast<Cookie>().Where(x => x.Name == _options.Authentication.CheckSessionCookieName).FirstOrDefault();\n            cookie.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task RemoveSessionIdCookie_should_remove_cookie()\n        {\n            _props.SetSessionId(\"999\");\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            await _subject.EnsureSessionIdCookieAsync();\n\n            var cookieContainer = new CookieContainer();\n            var cookies = _mockHttpContext.HttpContext.Response.Headers.Where(x => x.Key.Equals(\"Set-Cookie\", StringComparison.OrdinalIgnoreCase)).Select(x => x.Value);\n            cookieContainer.SetCookies(new Uri(\"http://server\"), string.Join(\",\", cookies));\n            _mockHttpContext.HttpContext.Response.Headers.Clear();\n\n            string cookie = cookieContainer.GetCookieHeader(new Uri(\"http://server\"));\n            _mockHttpContext.HttpContext.Request.Headers.Append(\"Cookie\", cookie);\n\n            await _subject.RemoveSessionIdCookieAsync();\n\n            cookies = _mockHttpContext.HttpContext.Response.Headers.Where(x => x.Key.Equals(\"Set-Cookie\", StringComparison.OrdinalIgnoreCase)).Select(x => x.Value);\n            cookieContainer.SetCookies(new Uri(\"http://server\"), string.Join(\",\", cookies));\n\n            var query = cookieContainer.GetCookies(new Uri(\"http://server\")).Cast<Cookie>().Where(x => x.Name == _options.Authentication.CheckSessionCookieName);\n            query.Count().Should().Be(0);\n        }\n\n        [Fact]\n        public async Task GetCurrentSessionIdAsync_when_user_is_authenticated_should_return_sid()\n        {\n            _props.SetSessionId(\"999\");\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            var sid = await _subject.GetSessionIdAsync();\n            sid.Should().Be(\"999\");\n        }\n\n        [Fact]\n        public async Task GetCurrentSessionIdAsync_when_user_is_anonymous_should_return_null()\n        {\n            var sid = await _subject.GetSessionIdAsync();\n            sid.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task adding_client_should_set_item_in_cookie_properties()\n        {\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            _props.Items.Count.Should().Be(0);\n            await _subject.AddClientIdAsync(\"client\");\n            _props.Items.Count.Should().Be(1);\n        }\n\n        [Fact]\n        public async Task when_authenticated_GetIdentityServerUserAsync_should_should_return_authenticated_user()\n        {\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            var user = await _subject.GetUserAsync();\n            user.GetSubjectId().Should().Be(\"123\");\n        }\n\n        [Fact]\n        public async Task when_anonymous_GetIdentityServerUserAsync_should_should_return_null()\n        {\n            var user = await _subject.GetUserAsync();\n            user.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task corrupt_properties_entry_should_clear_entry()\n        {\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            await _subject.AddClientIdAsync(\"client\");\n            var item = _props.Items.First();\n            _props.Items[item.Key] = \"junk\";\n\n            var clients = await _subject.GetClientListAsync();\n            clients.Should().BeEmpty();\n            _props.Items.Count.Should().Be(0);\n        }\n\n        [Fact]\n        public async Task adding_client_should_be_able_to_read_client()\n        {\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            await _subject.AddClientIdAsync(\"client\");\n            var clients = await _subject.GetClientListAsync();\n            clients.Should().Contain(new string[] { \"client\" });\n        }\n\n        [Fact]\n        public async Task adding_clients_should_be_able_to_read_clients()\n        {\n            _mockAuthenticationHandler.Result = AuthenticateResult.Success(new AuthenticationTicket(_user, _props, \"scheme\"));\n\n            await _subject.AddClientIdAsync(\"client1\");\n            await _subject.AddClientIdAsync(\"client2\");\n            var clients = await _subject.GetClientListAsync();\n            clients.Should().Contain(new string[] { \"client2\", \"client1\" });\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/Default/DistributedDeviceFlowThrottlingServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Text;\nusing System.Threading;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing Microsoft.Extensions.Caching.Distributed;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.Default\n{\n    public class DistributedDeviceFlowThrottlingServiceTests\n    {\n        private TestCache cache = new TestCache();\n\n        private readonly IdentityServerOptions options = new IdentityServerOptions {DeviceFlow = new DeviceFlowOptions {Interval = 5}};\n        private readonly DeviceCode deviceCode = new DeviceCode\n        {\n            Lifetime = 300,\n            CreationTime = DateTime.UtcNow\n        };\n\n        private const string CacheKey = \"devicecode_\";\n        private readonly DateTime testDate = new DateTime(2018, 06, 28, 13, 37, 42);\n\n        [Fact]\n        public async Task First_Poll()\n        {\n            var handle = Guid.NewGuid().ToString();\n            var service = new DistributedDeviceFlowThrottlingService(cache, new StubClock {UtcNowFunc = () => testDate}, options);\n\n            var result = await service.ShouldSlowDown(handle, deviceCode);\n\n            result.Should().BeFalse();\n\n            CheckCacheEntry(handle);\n        }\n\n        [Fact]\n        public async Task Second_Poll_Too_Fast()\n        {\n            var handle = Guid.NewGuid().ToString();\n            var service = new DistributedDeviceFlowThrottlingService(cache, new StubClock { UtcNowFunc = () => testDate }, options);\n\n            cache.Set(CacheKey + handle, Encoding.UTF8.GetBytes(testDate.AddSeconds(-1).ToString(\"O\")));\n\n            var result = await service.ShouldSlowDown(handle, deviceCode);\n\n            result.Should().BeTrue();\n            \n            CheckCacheEntry(handle);\n        }\n\n        [Fact]\n        public async Task Second_Poll_After_Interval()\n        {\n            var handle = Guid.NewGuid().ToString();\n            \n            var service = new DistributedDeviceFlowThrottlingService(cache, new StubClock { UtcNowFunc = () => testDate }, options);\n\n            cache.Set($\"devicecode_{handle}\", Encoding.UTF8.GetBytes(testDate.AddSeconds(-deviceCode.Lifetime - 1).ToString(\"O\")));\n\n            var result = await service.ShouldSlowDown(handle, deviceCode);\n\n            result.Should().BeFalse();\n\n            CheckCacheEntry(handle);\n        }\n\n        /// <summary>\n        /// Addresses race condition from #3860\n        /// </summary>\n        [Fact]\n        public async Task Expired_Device_Code_Should_Not_Have_Expiry_in_Past()\n        {\n            var handle = Guid.NewGuid().ToString();\n            deviceCode.CreationTime = testDate.AddSeconds(-deviceCode.Lifetime * 2);\n\n            var service = new DistributedDeviceFlowThrottlingService(cache, new StubClock { UtcNowFunc = () => testDate }, options);\n\n            var result = await service.ShouldSlowDown(handle, deviceCode);\n            \n            result.Should().BeFalse();\n\n            cache.Items.TryGetValue(CacheKey + handle, out var values).Should().BeTrue();\n            values?.Item2.AbsoluteExpiration.Should().BeOnOrAfter(testDate);\n        }\n\n        private void CheckCacheEntry(string handle)\n        {\n            cache.Items.TryGetValue(CacheKey + handle, out var values).Should().BeTrue();\n\n            var dateTimeAsString = Encoding.UTF8.GetString(values?.Item1);\n            var dateTime = DateTime.Parse(dateTimeAsString);\n            dateTime.Should().Be(testDate);\n\n            values?.Item2.AbsoluteExpiration.Should().BeCloseTo(testDate.AddSeconds(deviceCode.Lifetime), TimeSpan.FromMilliseconds(100));\n        }\n    }\n\n    internal class TestCache : IDistributedCache\n    {\n        public readonly Dictionary<string, Tuple<byte[], DistributedCacheEntryOptions>> Items =\n            new Dictionary<string, Tuple<byte[], DistributedCacheEntryOptions>>();\n\n        public byte[] Get(string key)\n        {\n            if (Items.TryGetValue(key, out var value)) return value.Item1;\n            return null;\n        }\n\n        public Task<byte[]> GetAsync(string key, CancellationToken token = new CancellationToken())\n        {\n            return Task.FromResult(Get(key));\n        }\n\n        public void Set(string key, byte[] value, DistributedCacheEntryOptions options)\n        {\n            Items.Remove(key);\n\n            Items.Add(key, new Tuple<byte[], DistributedCacheEntryOptions>(value, options));\n        }\n\n        public Task SetAsync(string key, byte[] value, DistributedCacheEntryOptions options, CancellationToken token = new CancellationToken())\n        {\n            Set(key, value, options);\n            return Task.CompletedTask;\n        }\n\n        public void Refresh(string key)\n        {\n            throw new NotImplementedException();\n        }\n\n        public Task RefreshAsync(string key, CancellationToken token = new CancellationToken())\n        {\n            throw new NotImplementedException();\n        }\n\n        public void Remove(string key)\n        {\n            throw new NotImplementedException();\n        }\n\n        public Task RemoveAsync(string key, CancellationToken token = new CancellationToken())\n        {\n            throw new NotImplementedException();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/Default/NumericUserCodeServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer8.Services;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.Default\n{\n    public class NumericUserCodeGeneratorTests\n    {\n        [Fact]\n        public async Task GenerateAsync_should_return_expected_code()\n        {\n            var sut = new NumericUserCodeGenerator();\n\n            var userCode = await sut.GenerateAsync();\n            var userCodeInt = int.Parse(userCode);\n\n            userCodeInt.Should().BeGreaterOrEqualTo(100000000);\n            userCodeInt.Should().BeLessOrEqualTo(999999999);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Services/InMemory/InMemoryCorsPolicyService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Services.InMemory\n{\n    public class InMemoryCorsPolicyServiceTests\n    {\n        private const string Category = \"InMemoryCorsPolicyService\";\n\n        private InMemoryCorsPolicyService _subject;\n        private List<Client> _clients = new List<Client>();\n\n        public InMemoryCorsPolicyServiceTests()\n        {\n            _subject = new InMemoryCorsPolicyService(TestLogger.Create<InMemoryCorsPolicyService>(), _clients);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task client_has_origin_should_allow_origin()\n        {\n            _clients.Add(new Client\n            {\n                AllowedCorsOrigins = new List<string>\n                {\n                    \"http://foo\"\n                }\n            });\n\n            (await _subject.IsOriginAllowedAsync(\"http://foo\")).Should().BeTrue();\n        }\n\n        [Theory]\n        [InlineData(\"http://foo\")]\n        [InlineData(\"https://bar\")]\n        [InlineData(\"http://bar-baz\")]\n        [Trait(\"Category\", Category)]\n        public async Task client_does_not_has_origin_should_not_allow_origin(string clientOrigin)\n        {\n            _clients.Add(new Client\n            {\n                AllowedCorsOrigins = new List<string>\n                {\n                    clientOrigin\n                }\n            });\n            (await _subject.IsOriginAllowedAsync(\"http://bar\")).Should().Be(false);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task client_has_many_origins_and_origin_is_in_list_should_allow_origin()\n        {\n            _clients.Add(new Client\n            {\n                AllowedCorsOrigins = new List<string>\n                {\n                    \"http://foo\",\n                    \"http://bar\",\n                    \"http://baz\"\n                }\n            });\n            (await _subject.IsOriginAllowedAsync(\"http://bar\")).Should().Be(true);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task client_has_many_origins_and_origin_is_in_not_list_should_not_allow_origin()\n        {\n            _clients.Add(new Client\n            {\n                AllowedCorsOrigins = new List<string>\n                {\n                    \"http://foo\",\n                    \"http://bar\",\n                    \"http://baz\"\n                }\n            });\n            (await _subject.IsOriginAllowedAsync(\"http://quux\")).Should().Be(false);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task many_clients_have_same_origins_should_allow_origin()\n        {\n            _clients.AddRange(new Client[] {\n                new Client\n                {\n                    AllowedCorsOrigins = new List<string>\n                    {\n                        \"http://foo\"\n                    }\n                },\n                new Client\n                {\n                    AllowedCorsOrigins = new List<string>\n                    {\n                        \"http://foo\"\n                    }\n                }\n            });\n            (await _subject.IsOriginAllowedAsync(\"http://foo\")).Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task handle_invalid_cors_origin_format_exception()\n        {\n            _clients.AddRange(new Client[] {\n                new Client\n                {\n                    AllowedCorsOrigins = new List<string>\n                    {\n                        \"http://foo\",\n                        \"http://ba z\"\n                    }\n                },\n                new Client\n                {\n                    AllowedCorsOrigins = new List<string>\n                    {\n                        \"http://foo\",\n                        \"http://bar\"\n                    }\n                }\n            });\n            (await _subject.IsOriginAllowedAsync(\"http://bar\")).Should().BeTrue();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Stores/Default/DefaultPersistedGrantStoreTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Stores.Serialization;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Stores.Default\n{\n    public class DefaultPersistedGrantStoreTests\n    {\n        private InMemoryPersistedGrantStore _store = new InMemoryPersistedGrantStore();\n        private IAuthorizationCodeStore _codes;\n        private IRefreshTokenStore _refreshTokens;\n        private IReferenceTokenStore _referenceTokens;\n        private IUserConsentStore _userConsent;\n        private StubHandleGenerationService _stubHandleGenerationService = new StubHandleGenerationService();\n\n        private ClaimsPrincipal _user = new IdentityServerUser(\"123\").CreatePrincipal();\n\n        public DefaultPersistedGrantStoreTests()\n        {\n            _codes = new DefaultAuthorizationCodeStore(_store,\n                new PersistentGrantSerializer(),\n                _stubHandleGenerationService,\n                TestLogger.Create<DefaultAuthorizationCodeStore>());\n            _refreshTokens = new DefaultRefreshTokenStore(_store,\n                new PersistentGrantSerializer(),\n                _stubHandleGenerationService,\n                TestLogger.Create<DefaultRefreshTokenStore>());\n            _referenceTokens = new DefaultReferenceTokenStore(_store,\n                new PersistentGrantSerializer(),\n                _stubHandleGenerationService,\n                TestLogger.Create<DefaultReferenceTokenStore>());\n            _userConsent = new DefaultUserConsentStore(_store,\n                new PersistentGrantSerializer(),\n                _stubHandleGenerationService,\n                TestLogger.Create<DefaultUserConsentStore>());\n        }\n        \n        [Fact]\n        public async Task StoreAuthorizationCodeAsync_should_persist_grant()\n        {\n            var code1 = new AuthorizationCode()\n            {\n                ClientId = \"test\",\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Subject = _user,\n                CodeChallenge = \"challenge\",\n                RedirectUri = \"http://client/cb\",\n                Nonce = \"nonce\",\n                RequestedScopes = new string[] { \"scope1\", \"scope2\" }\n            };\n\n            var handle = await _codes.StoreAuthorizationCodeAsync(code1);\n            var code2 = await _codes.GetAuthorizationCodeAsync(handle);\n\n            code1.ClientId.Should().Be(code2.ClientId);\n            code1.CreationTime.Should().Be(code2.CreationTime);\n            code1.Lifetime.Should().Be(code2.Lifetime);\n            code1.Subject.GetSubjectId().Should().Be(code2.Subject.GetSubjectId());\n            code1.CodeChallenge.Should().Be(code2.CodeChallenge);\n            code1.RedirectUri.Should().Be(code2.RedirectUri);\n            code1.Nonce.Should().Be(code2.Nonce);\n            code1.RequestedScopes.Should().BeEquivalentTo(code2.RequestedScopes);\n        }\n\n        [Fact]\n        public async Task RemoveAuthorizationCodeAsync_should_remove_grant()\n        {\n            var code1 = new AuthorizationCode()\n            {\n                ClientId = \"test\",\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Subject = _user,\n                CodeChallenge = \"challenge\",\n                RedirectUri = \"http://client/cb\",\n                Nonce = \"nonce\",\n                RequestedScopes = new string[] { \"scope1\", \"scope2\" }\n            };\n\n            var handle = await _codes.StoreAuthorizationCodeAsync(code1);\n            await _codes.RemoveAuthorizationCodeAsync(handle);\n            var code2 = await _codes.GetAuthorizationCodeAsync(handle);\n            code2.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task StoreRefreshTokenAsync_should_persist_grant()\n        {\n            var token1 = new RefreshToken()\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = \"client\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Type = \"type\",\n                    Claims = new List<Claim>\n                    {\n                        new Claim(\"sub\", \"123\"),\n                        new Claim(\"scope\", \"foo\")\n                    }\n                },\n                Version = 1\n            };\n\n            var handle = await _refreshTokens.StoreRefreshTokenAsync(token1);\n            var token2 = await _refreshTokens.GetRefreshTokenAsync(handle);\n\n            token1.ClientId.Should().Be(token2.ClientId);\n            token1.CreationTime.Should().Be(token2.CreationTime);\n            token1.Lifetime.Should().Be(token2.Lifetime);\n            token1.Subject.GetSubjectId().Should().Be(token2.Subject.GetSubjectId());\n            token1.Version.Should().Be(token2.Version);\n            token1.AccessToken.Audiences.Count.Should().Be(1);\n            token1.AccessToken.Audiences.First().Should().Be(\"aud\");\n            token1.AccessToken.ClientId.Should().Be(token2.AccessToken.ClientId);\n            token1.AccessToken.CreationTime.Should().Be(token2.AccessToken.CreationTime);\n            token1.AccessToken.Type.Should().Be(token2.AccessToken.Type);\n        }\n\n        [Fact]\n        public async Task RemoveRefreshTokenAsync_should_remove_grant()\n        {\n            var token1 = new RefreshToken()\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = \"client\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Type = \"type\",\n                    Claims = new List<Claim>\n                    {\n                        new Claim(\"sub\", \"123\"),\n                        new Claim(\"scope\", \"foo\")\n                    }\n                },\n                Version = 1\n            };\n\n\n            var handle = await _refreshTokens.StoreRefreshTokenAsync(token1);\n            await _refreshTokens.RemoveRefreshTokenAsync(handle);\n            var token2 = await _refreshTokens.GetRefreshTokenAsync(handle);\n            token2.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task RemoveRefreshTokenAsync_by_sub_and_client_should_remove_grant()\n        {\n            var token1 = new RefreshToken()\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                AccessToken = new Token\n                {\n                    ClientId = \"client\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Type = \"type\",\n                    Claims = new List<Claim>\n                    {\n                        new Claim(\"sub\", \"123\"),\n                        new Claim(\"scope\", \"foo\")\n                    }\n                },\n                Version = 1\n            };\n\n            var handle1 = await _refreshTokens.StoreRefreshTokenAsync(token1);\n            var handle2 = await _refreshTokens.StoreRefreshTokenAsync(token1);\n            await _refreshTokens.RemoveRefreshTokensAsync(\"123\", \"client\");\n\n            var token2 = await _refreshTokens.GetRefreshTokenAsync(handle1);\n            token2.Should().BeNull();\n            token2 = await _refreshTokens.GetRefreshTokenAsync(handle2);\n            token2.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task StoreReferenceTokenAsync_should_persist_grant()\n        {\n            var token1 = new Token()\n            {\n                ClientId = \"client\",\n                Audiences = { \"aud\" },\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Type = \"type\",\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"123\"),\n                    new Claim(\"scope\", \"foo\")\n                },\n                Version = 1\n            };\n\n            var handle = await _referenceTokens.StoreReferenceTokenAsync(token1);\n            var token2 = await _referenceTokens.GetReferenceTokenAsync(handle);\n\n            token1.ClientId.Should().Be(token2.ClientId);\n            token1.Audiences.Count.Should().Be(1);\n            token1.Audiences.First().Should().Be(\"aud\");\n            token1.CreationTime.Should().Be(token2.CreationTime);\n            token1.Type.Should().Be(token2.Type);\n            token1.Lifetime.Should().Be(token2.Lifetime);\n            token1.Version.Should().Be(token2.Version);\n        }\n\n        [Fact]\n        public async Task RemoveReferenceTokenAsync_should_remove_grant()\n        {\n            var token1 = new Token()\n            {\n                ClientId = \"client\",\n                Audiences = { \"aud\" },\n                CreationTime = DateTime.UtcNow,\n                Type = \"type\",\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"123\"),\n                    new Claim(\"scope\", \"foo\")\n                },\n                Version = 1\n            };\n\n            var handle = await _referenceTokens.StoreReferenceTokenAsync(token1);\n            await _referenceTokens.RemoveReferenceTokenAsync(handle);\n            var token2 = await _referenceTokens.GetReferenceTokenAsync(handle);\n            token2.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task RemoveReferenceTokenAsync_by_sub_and_client_should_remove_grant()\n        {\n            var token1 = new Token()\n            {\n                ClientId = \"client\",\n                Audiences = { \"aud\" },\n                CreationTime = DateTime.UtcNow,\n                Type = \"type\",\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"123\"),\n                    new Claim(\"scope\", \"foo\")\n                },\n                Version = 1\n            };\n\n            var handle1 = await _referenceTokens.StoreReferenceTokenAsync(token1);\n            var handle2 = await _referenceTokens.StoreReferenceTokenAsync(token1);\n            await _referenceTokens.RemoveReferenceTokensAsync(\"123\", \"client\");\n\n            var token2 = await _referenceTokens.GetReferenceTokenAsync(handle1);\n            token2.Should().BeNull();\n            token2 = await _referenceTokens.GetReferenceTokenAsync(handle2);\n            token2.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task StoreUserConsentAsync_should_persist_grant()\n        {\n            var consent1 = new Consent()\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = \"client\",\n                SubjectId = \"123\",\n                Scopes = new string[] { \"foo\", \"bar\" }\n            };\n\n            await _userConsent.StoreUserConsentAsync(consent1);\n            var consent2 = await _userConsent.GetUserConsentAsync(\"123\", \"client\");\n\n            consent2.ClientId.Should().Be(consent1.ClientId);\n            consent2.SubjectId.Should().Be(consent1.SubjectId);\n            consent2.Scopes.Should().BeEquivalentTo(new string[] { \"bar\", \"foo\" });\n        }\n\n        [Fact]\n        public async Task RemoveUserConsentAsync_should_remove_grant()\n        {\n            var consent1 = new Consent()\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = \"client\",\n                SubjectId = \"123\",\n                Scopes = new string[] { \"foo\", \"bar\" }\n            };\n\n            await _userConsent.StoreUserConsentAsync(consent1);\n            await _userConsent.RemoveUserConsentAsync(\"123\", \"client\");\n            var consent2 = await _userConsent.GetUserConsentAsync(\"123\", \"client\");\n            consent2.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task same_key_for_different_grant_types_should_not_interfere_with_each_other()\n        {\n            _stubHandleGenerationService.Handle = \"key\";\n\n            await _referenceTokens.StoreReferenceTokenAsync(new Token()\n            {\n                ClientId = \"client1\",\n                Audiences = { \"aud\" },\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 10,\n                Type = \"type\",\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"123\"),\n                    new Claim(\"scope\", \"bar1\"),\n                    new Claim(\"scope\", \"bar2\")\n                }\n            });\n\n            await _refreshTokens.StoreRefreshTokenAsync(new RefreshToken()\n            {\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 20,\n                AccessToken = new Token\n                {\n                    ClientId = \"client1\",\n                    Audiences = { \"aud\" },\n                    CreationTime = DateTime.UtcNow,\n                    Type = \"type\",\n                    Claims = new List<Claim>\n                    {\n                        new Claim(\"sub\", \"123\"),\n                        new Claim(\"scope\", \"baz1\"),\n                        new Claim(\"scope\", \"baz2\")\n                    }\n                },\n                Version = 1\n            });\n\n            await _codes.StoreAuthorizationCodeAsync(new AuthorizationCode()\n            {\n                ClientId = \"client1\",\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 30,\n                Subject = _user,\n                CodeChallenge = \"challenge\",\n                RedirectUri = \"http://client/cb\",\n                Nonce = \"nonce\",\n                RequestedScopes = new string[] { \"quux1\", \"quux2\" }\n            });\n\n            (await _codes.GetAuthorizationCodeAsync(\"key\")).Lifetime.Should().Be(30);\n            (await _refreshTokens.GetRefreshTokenAsync(\"key\")).Lifetime.Should().Be(20);\n            (await _referenceTokens.GetReferenceTokenAsync(\"key\")).Lifetime.Should().Be(10);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Stores/InMemoryClientStoreTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing System;\nusing System.Collections.Generic;\nusing Xunit;\nusing FluentAssertions;\n\nnamespace IdentityServer.UnitTests.Stores\n{\n    public class InMemoryClientStoreTests\n    {\n        [Fact]\n        public void InMemoryClient_should_throw_if_contain_duplicate_client_ids()\n        {\n            List<Client> clients = new List<Client>\n            {\n                new Client { ClientId = \"1\"},\n                new Client { ClientId = \"1\"},\n                new Client { ClientId = \"3\"}\n            };\n\n            Action act = () => new InMemoryClientStore(clients);\n            act.Should().Throw<ArgumentException>();\n        }\n\n        [Fact]\n        public void InMemoryClient_should_not_throw_if_does_not_contain_duplicate_client_ids()\n        {\n            List<Client> clients = new List<Client>\n            {\n                new Client { ClientId = \"1\"},\n                new Client { ClientId = \"2\"},\n                new Client { ClientId = \"3\"}\n            };\n\n            new InMemoryClientStore(clients);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Stores/InMemoryDeviceFlowStoreTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Stores\n{\n    public class InMemoryDeviceFlowStoreTests\n    {\n        private InMemoryDeviceFlowStore _store = new InMemoryDeviceFlowStore();\n\n        [Fact]\n        public async Task StoreDeviceAuthorizationAsync_should_persist_data_by_user_code()\n        {\n            var deviceCode = Guid.NewGuid().ToString();\n            var userCode = Guid.NewGuid().ToString();\n            var data = new DeviceCode\n            {\n                ClientId = Guid.NewGuid().ToString(),\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 300,\n                IsAuthorized = false,\n                IsOpenId = true,\n                Subject = null,\n                RequestedScopes = new[] {\"scope1\", \"scope2\"}\n            };\n\n            await _store.StoreDeviceAuthorizationAsync(deviceCode, userCode, data);\n            var foundData = await _store.FindByUserCodeAsync(userCode);\n\n            foundData.ClientId.Should().Be(data.ClientId);\n            foundData.CreationTime.Should().Be(data.CreationTime);\n            foundData.Lifetime.Should().Be(data.Lifetime);\n            foundData.IsAuthorized.Should().Be(data.IsAuthorized);\n            foundData.IsOpenId.Should().Be(data.IsOpenId);\n            foundData.Subject.Should().Be(data.Subject);\n            foundData.RequestedScopes.Should().BeEquivalentTo(data.RequestedScopes);\n        }\n\n        [Fact]\n        public async Task StoreDeviceAuthorizationAsync_should_persist_data_by_device_code()\n        {\n            var deviceCode = Guid.NewGuid().ToString();\n            var userCode = Guid.NewGuid().ToString();\n            var data = new DeviceCode\n            {\n                ClientId = Guid.NewGuid().ToString(),\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 300,\n                IsAuthorized = false,\n                IsOpenId = true,\n                Subject = null,\n                RequestedScopes = new[] {\"scope1\", \"scope2\"}\n            };\n\n            await _store.StoreDeviceAuthorizationAsync(deviceCode, userCode, data);\n            var foundData = await _store.FindByDeviceCodeAsync(deviceCode);\n\n            foundData.ClientId.Should().Be(data.ClientId);\n            foundData.CreationTime.Should().Be(data.CreationTime);\n            foundData.Lifetime.Should().Be(data.Lifetime);\n            foundData.IsAuthorized.Should().Be(data.IsAuthorized);\n            foundData.IsOpenId.Should().Be(data.IsOpenId);\n            foundData.Subject.Should().Be(data.Subject);\n            foundData.RequestedScopes.Should().BeEquivalentTo(data.RequestedScopes);\n        }\n\n        [Fact]\n        public async Task UpdateByUserCodeAsync_should_update_data()\n        {\n            var deviceCode = Guid.NewGuid().ToString();\n            var userCode = Guid.NewGuid().ToString();\n            var initialData = new DeviceCode\n            {\n                ClientId = Guid.NewGuid().ToString(),\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 300,\n                IsAuthorized = false,\n                IsOpenId = true,\n                Subject = null,\n                RequestedScopes = new[] {\"scope1\", \"scope2\"}\n            };\n\n            await _store.StoreDeviceAuthorizationAsync(deviceCode, userCode, initialData);\n\n            var updatedData = new DeviceCode\n            {\n                ClientId = Guid.NewGuid().ToString(),\n                CreationTime = initialData.CreationTime.AddHours(2),\n                Lifetime = initialData.Lifetime + 600,\n                IsAuthorized = !initialData.IsAuthorized,\n                IsOpenId = !initialData.IsOpenId,\n                Subject = new ClaimsPrincipal(new ClaimsIdentity(new List<Claim> {new Claim(\"sub\", \"123\")})),\n                RequestedScopes = new[] {\"api1\", \"api2\"}\n            };\n\n            await _store.UpdateByUserCodeAsync(userCode, updatedData);\n\n            var foundData = await _store.FindByUserCodeAsync(userCode);\n\n            foundData.ClientId.Should().Be(updatedData.ClientId);\n            foundData.CreationTime.Should().Be(updatedData.CreationTime);\n            foundData.Lifetime.Should().Be(updatedData.Lifetime);\n            foundData.IsAuthorized.Should().Be(updatedData.IsAuthorized);\n            foundData.IsOpenId.Should().Be(updatedData.IsOpenId);\n            foundData.Subject.Should().BeEquivalentTo(updatedData.Subject);\n            foundData.RequestedScopes.Should().BeEquivalentTo(updatedData.RequestedScopes);\n        }\n\n        [Fact]\n        public async Task RemoveByDeviceCodeAsync_should_update_data()\n        {\n            var deviceCode = Guid.NewGuid().ToString();\n            var userCode = Guid.NewGuid().ToString();\n            var data = new DeviceCode\n            {\n                ClientId = Guid.NewGuid().ToString(),\n                CreationTime = DateTime.UtcNow,\n                Lifetime = 300,\n                IsAuthorized = false,\n                IsOpenId = true,\n                Subject = null,\n                RequestedScopes = new[] { \"scope1\", \"scope2\" }\n            };\n\n            await _store.StoreDeviceAuthorizationAsync(deviceCode, userCode, data);\n            await _store.RemoveByDeviceCodeAsync(deviceCode);\n            var foundData = await _store.FindByUserCodeAsync(userCode);\n\n            foundData.Should().BeNull();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Stores/InMemoryPersistedGrantStoreTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\nusing FluentAssertions;\nusing System.Threading.Tasks;\nusing System.Linq;\n\nnamespace IdentityServer.UnitTests.Stores\n{\n    public class InMemoryPersistedGrantStoreTests\n    {\n        InMemoryPersistedGrantStore _subject;\n\n        public InMemoryPersistedGrantStoreTests()\n        {\n            _subject = new InMemoryPersistedGrantStore();\n        }\n\n        [Fact]\n        public async Task Store_should_persist_value()\n        {\n            {\n                var item = await _subject.GetAsync(\"key1\");\n                item.Should().BeNull();\n            }\n\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key1\" });\n\n            {\n                var item = await _subject.GetAsync(\"key1\");\n                item.Should().NotBeNull();\n            }\n        }\n\n        [Fact]\n        public async Task GetAll_should_filter()\n        {\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key1\", SubjectId = \"sub1\", ClientId = \"client1\", SessionId = \"session1\" });\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key2\", SubjectId = \"sub1\", ClientId = \"client2\", SessionId = \"session1\" });\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key3\", SubjectId = \"sub1\", ClientId = \"client1\", SessionId = \"session2\" });\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key4\", SubjectId = \"sub1\", ClientId = \"client3\", SessionId = \"session2\" });\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key5\", SubjectId = \"sub1\", ClientId = \"client4\", SessionId = \"session3\" });\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key6\", SubjectId = \"sub1\", ClientId = \"client4\", SessionId = \"session4\" });\n\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key7\", SubjectId = \"sub2\", ClientId = \"client4\", SessionId = \"session4\" });\n\n\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key1\", \"key2\", \"key3\", \"key4\", \"key5\", \"key6\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub2\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key7\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub3\"\n            }))\n            .Select(x => x.Key).Should().BeEmpty();\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client1\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key1\", \"key3\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client2\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key2\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client3\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key4\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client4\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key5\", \"key6\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client5\"\n            }))\n            .Select(x => x.Key).Should().BeEmpty();\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub2\",\n                ClientId = \"client1\"\n            }))\n            .Select(x => x.Key).Should().BeEmpty();\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub2\",\n                ClientId = \"client4\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key7\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub3\",\n                ClientId = \"client1\"\n            }))\n            .Select(x => x.Key).Should().BeEmpty();\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client1\",\n                SessionId = \"session1\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key1\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client1\",\n                SessionId = \"session2\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key3\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client1\",\n                SessionId = \"session3\"\n            }))\n            .Select(x => x.Key).Should().BeEmpty();\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client2\",\n                SessionId = \"session1\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key2\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client2\",\n                SessionId = \"session2\"\n            }))\n            .Select(x => x.Key).Should().BeEmpty();\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub1\",\n                ClientId = \"client4\",\n                SessionId = \"session4\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key6\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub2\",\n                ClientId = \"client4\",\n                SessionId = \"session4\"\n            }))\n            .Select(x => x.Key).Should().BeEquivalentTo(new[] { \"key7\" });\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub2\",\n                ClientId = \"client4\",\n                SessionId = \"session1\"\n            }))\n            .Select(x => x.Key).Should().BeEmpty();\n\n            (await _subject.GetAllAsync(new PersistedGrantFilter\n            {\n                SubjectId = \"sub2\",\n                ClientId = \"client4\",\n                SessionId = \"session5\"\n            }))\n            .Select(x => x.Key).Should().BeEmpty();\n        }\n\n        [Fact]\n        public async Task RemoveAll_should_filter()\n        {\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().BeNull();\n                (await _subject.GetAsync(\"key2\")).Should().BeNull();\n                (await _subject.GetAsync(\"key3\")).Should().BeNull();\n                (await _subject.GetAsync(\"key4\")).Should().BeNull();\n                (await _subject.GetAsync(\"key5\")).Should().BeNull();\n                (await _subject.GetAsync(\"key6\")).Should().BeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub2\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().BeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub3\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client1\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().BeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().BeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client2\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().BeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client3\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().BeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client4\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().BeNull();\n                (await _subject.GetAsync(\"key6\")).Should().BeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client5\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub2\",\n                    ClientId = \"client1\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client4\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().BeNull();\n                (await _subject.GetAsync(\"key6\")).Should().BeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub3\",\n                    ClientId = \"client1\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client1\",\n                    SessionId = \"session1\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().BeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client1\",\n                    SessionId = \"session2\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().BeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client1\",\n                    SessionId = \"session3\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client2\",\n                    SessionId = \"session1\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().BeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client2\",\n                    SessionId = \"session2\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub1\",\n                    ClientId = \"client4\",\n                    SessionId = \"session4\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().BeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub2\",\n                    ClientId = \"client4\",\n                    SessionId = \"session4\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().BeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub2\",\n                    ClientId = \"client4\",\n                    SessionId = \"session1\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub2\",\n                    ClientId = \"client4\",\n                    SessionId = \"session5\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n            {\n                await Populate();\n                await _subject.RemoveAllAsync(new PersistedGrantFilter\n                {\n                    SubjectId = \"sub3\",\n                    ClientId = \"client1\",\n                    SessionId = \"session1\"\n                });\n                (await _subject.GetAsync(\"key1\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key2\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key3\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key4\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key5\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key6\")).Should().NotBeNull();\n                (await _subject.GetAsync(\"key7\")).Should().NotBeNull();\n            }\n        }\n\n        private async Task Populate()\n        {\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key1\", SubjectId = \"sub1\", ClientId = \"client1\", SessionId = \"session1\" });\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key2\", SubjectId = \"sub1\", ClientId = \"client2\", SessionId = \"session1\" });\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key3\", SubjectId = \"sub1\", ClientId = \"client1\", SessionId = \"session2\" });\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key4\", SubjectId = \"sub1\", ClientId = \"client3\", SessionId = \"session2\" });\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key5\", SubjectId = \"sub1\", ClientId = \"client4\", SessionId = \"session3\" });\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key6\", SubjectId = \"sub1\", ClientId = \"client4\", SessionId = \"session4\" });\n\n            await _subject.StoreAsync(new PersistedGrant() { Key = \"key7\", SubjectId = \"sub2\", ClientId = \"client4\", SessionId = \"session4\" });\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Stores/InMemoryResourcesStoreTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing System;\nusing System.Collections.Generic;\nusing Xunit;\nusing FluentAssertions;\n\nnamespace IdentityServer.UnitTests.Stores\n{\n    public class InMemoryResourcesStoreTests\n    {\n        [Fact]\n        public void InMemoryResourcesStore_should_throw_if_contains_duplicate_names()\n        {\n            List<IdentityResource> identityResources = new List<IdentityResource>\n            {\n                new IdentityResource { Name = \"A\" },\n                new IdentityResource { Name = \"A\" },\n                new IdentityResource { Name = \"C\" }\n            };\n\n            List<ApiResource> apiResources = new List<ApiResource>\n            {\n                new ApiResource { Name = \"B\" },\n                new ApiResource { Name = \"B\" },\n                new ApiResource { Name = \"C\" }\n            };\n\n            List<ApiScope> scopes = new List<ApiScope>\n            {\n                new ApiScope { Name = \"B\" },\n                new ApiScope { Name = \"C\" },\n                new ApiScope { Name = \"C\" },\n            };\n\n            Action act = () => new InMemoryResourcesStore(identityResources, null, null);\n            act.Should().Throw<ArgumentException>();\n\n            act = () => new InMemoryResourcesStore(null, apiResources, null);\n            act.Should().Throw<ArgumentException>();\n            \n            act = () => new InMemoryResourcesStore(null, null, scopes);\n            act.Should().Throw<ArgumentException>();\n        }\n\n        [Fact]\n        public void InMemoryResourcesStore_should_not_throw_if_does_not_contains_duplicate_names()\n        {\n            List<IdentityResource> identityResources = new List<IdentityResource>\n            {\n                new IdentityResource { Name = \"A\" },\n                new IdentityResource { Name = \"B\" },\n                new IdentityResource { Name = \"C\" }\n            };\n\n            List<ApiResource> apiResources = new List<ApiResource>\n            {\n                new ApiResource { Name = \"A\" },\n                new ApiResource { Name = \"B\" },\n                new ApiResource { Name = \"C\" }\n            };\n\n            List<ApiScope> apiScopes = new List<ApiScope>\n            {\n                new ApiScope { Name = \"A\" },\n                new ApiScope { Name = \"B\" },\n                new ApiScope { Name = \"C\" },\n            };\n            \n            new InMemoryResourcesStore(identityResources, null, null);\n            new InMemoryResourcesStore(null, apiResources, null);\n            new InMemoryResourcesStore(null, null, apiScopes);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/AccessTokenValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.IdentityModel.Tokens.Jwt;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class AccessTokenValidation\n    {\n        private const string Category = \"Access token validation\";\n\n        private IClientStore _clients = Factory.CreateClientStore();\n        private IdentityServerOptions _options = new IdentityServerOptions();\n        private StubClock _clock = new StubClock();\n\n        static AccessTokenValidation()\n        {\n            JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();\n        }\n\n        private DateTime now;\n        public DateTime UtcNow\n        {\n            get\n            {\n                if (now > DateTime.MinValue) return now;\n                return DateTime.UtcNow;\n            }\n        }\n\n        public AccessTokenValidation()\n        {\n            _clock.UtcNowFunc = () => UtcNow;\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Reference_Token()\n        {\n            var store = Factory.CreateReferenceTokenStore();\n            var validator = Factory.CreateTokenValidator(store);\n\n            var token = TokenFactory.CreateAccessToken(new Client { ClientId = \"roclient\" }, \"valid\", 600, \"read\", \"write\");\n\n            var handle = await store.StoreReferenceTokenAsync(token);\n\n            var result = await validator.ValidateAccessTokenAsync(handle);\n\n            result.IsError.Should().BeFalse();\n            result.Claims.Count().Should().Be(8);\n            result.Claims.First(c => c.Type == JwtClaimTypes.ClientId).Value.Should().Be(\"roclient\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Reference_Token_with_required_Scope()\n        {\n            var store = Factory.CreateReferenceTokenStore();\n            var validator = Factory.CreateTokenValidator(store);\n\n            var token = TokenFactory.CreateAccessToken(new Client { ClientId = \"roclient\" }, \"valid\", 600, \"read\", \"write\");\n\n            var handle = await store.StoreReferenceTokenAsync(token);\n\n            var result = await validator.ValidateAccessTokenAsync(handle, \"read\");\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Reference_Token_with_missing_Scope()\n        {\n            var store = Factory.CreateReferenceTokenStore();\n            var validator = Factory.CreateTokenValidator(store);\n\n            var token = TokenFactory.CreateAccessToken(new Client { ClientId = \"roclient\" }, \"valid\", 600, \"read\", \"write\");\n\n            var handle = await store.StoreReferenceTokenAsync(token);\n\n            var result = await validator.ValidateAccessTokenAsync(handle, \"missing\");\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.InsufficientScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Unknown_Reference_Token()\n        {\n            var validator = Factory.CreateTokenValidator();\n\n            var result = await validator.ValidateAccessTokenAsync(\"unknown\");\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Reference_Token_Too_Long()\n        {\n            var validator = Factory.CreateTokenValidator();\n            var options = new IdentityServerOptions();\n\n            var longToken = \"x\".Repeat(options.InputLengthRestrictions.TokenHandle + 1);\n            var result = await validator.ValidateAccessTokenAsync(longToken);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Expired_Reference_Token()\n        {\n            now = DateTime.UtcNow;\n\n            var store = Factory.CreateReferenceTokenStore();\n            var validator = Factory.CreateTokenValidator(store, clock:_clock);\n\n            var token = TokenFactory.CreateAccessToken(new Client { ClientId = \"roclient\" }, \"valid\", 2, \"read\", \"write\");\n            token.CreationTime = now;\n\n            var handle = await store.StoreReferenceTokenAsync(token);\n\n            now = now.AddSeconds(3);\n\n            var result = await validator.ValidateAccessTokenAsync(handle);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.ExpiredToken);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Malformed_JWT_Token()\n        {\n            var validator = Factory.CreateTokenValidator();\n\n            var result = await validator.ValidateAccessTokenAsync(\"unk.nown\");\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_JWT_Token()\n        {\n            var signer = Factory.CreateDefaultTokenCreator();\n            var jwt = await signer.CreateTokenAsync(TokenFactory.CreateAccessToken(new Client { ClientId = \"roclient\" }, \"valid\", 600, \"read\", \"write\"));\n\n            var validator = Factory.CreateTokenValidator(null);\n            var result = await validator.ValidateAccessTokenAsync(jwt);\n\n            result.IsError.Should().BeFalse();\n        }\n        \n        [Theory]\n        [InlineData(true)]\n        [InlineData(false)]\n        [Trait(\"Category\", Category)]\n        public async Task JWT_Token_with_scopes_have_expected_claims(bool flag)\n        {\n            var options = TestIdentityServerOptions.Create();\n            options.EmitScopesAsSpaceDelimitedStringInJwt = flag;\n            \n            var signer = Factory.CreateDefaultTokenCreator(options);\n            var jwt = await signer.CreateTokenAsync(TokenFactory.CreateAccessToken(new Client { ClientId = \"roclient\" }, \"valid\", 600, \"read\", \"write\"));\n\n            var validator = Factory.CreateTokenValidator(null);\n            var result = await validator.ValidateAccessTokenAsync(jwt);\n\n            result.IsError.Should().BeFalse();\n            result.Jwt.Should().NotBeNullOrEmpty();\n            result.Client.ClientId.Should().Be(\"roclient\");\n\n            result.Claims.Count().Should().Be(8);\n            var scopes = result.Claims.Where(c => c.Type == \"scope\").Select(c => c.Value).ToArray();\n            scopes.Count().Should().Be(2);\n            scopes[0].Should().Be(\"read\");\n            scopes[1].Should().Be(\"write\");\n        }\n        \n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task JWT_Token_invalid_Issuer()\n        {\n            var signer = Factory.CreateDefaultTokenCreator();\n            var token = TokenFactory.CreateAccessToken(new Client { ClientId = \"roclient\" }, \"valid\", 600, \"read\", \"write\");\n            token.Issuer = \"invalid\";\n            var jwt = await signer.CreateTokenAsync(token);\n\n            var validator = Factory.CreateTokenValidator(null);\n            var result = await validator.ValidateAccessTokenAsync(jwt);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task JWT_Token_Too_Long()\n        {\n            var signer = Factory.CreateDefaultTokenCreator();\n            var jwt = await signer.CreateTokenAsync(TokenFactory.CreateAccessTokenLong(new Client { ClientId = \"roclient\" }, \"valid\", 600, 1000, \"read\", \"write\"));\n            \n            var validator = Factory.CreateTokenValidator(null);\n            var result = await validator.ValidateAccessTokenAsync(jwt);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_AccessToken_but_Client_not_active()\n        {\n            var store = Factory.CreateReferenceTokenStore();\n            var validator = Factory.CreateTokenValidator(store);\n\n            var token = TokenFactory.CreateAccessToken(new Client { ClientId = \"unknown\" }, \"valid\", 600, \"read\", \"write\");\n\n            var handle = await store.StoreReferenceTokenAsync(token);\n\n            var result = await validator.ValidateAccessTokenAsync(handle);\n\n            result.IsError.Should().BeTrue();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/AuthorizeRequest Validation/Authorize_ClientValidation_Code.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Configuration;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.AuthorizeRequest_Validation\n{\n    public class Authorize_ClientValidation_Code\n    {\n        private IdentityServerOptions _options = TestIdentityServerOptions.Create();\n\n        [Fact]\n        [Trait(\"Category\", \"AuthorizeRequest Client Validation - Code\")]\n        public async Task Code_Request_Unknown_Scope()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"unknown\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", \"AuthorizeRequest Client Validation - Code\")]\n        public async Task OpenId_Code_Request_Invalid_RedirectUri()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://invalid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", \"AuthorizeRequest Client Validation - Code\")]\n        public async Task OpenId_Code_Request_Invalid_IdToken_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", \"AuthorizeRequest Client Validation - Code\")]\n        public async Task OpenId_Code_Request_Invalid_IdTokenToken_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdTokenToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", \"AuthorizeRequest Client Validation - Code\")]\n        public async Task OpenId_Code_Request_With_Unknown_Client()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"unknown\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", \"AuthorizeRequest Client Validation - Code\")]\n        public async Task OpenId_Code_Request_With_Restricted_Scope()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient_restricted\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid profile\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidScope);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/AuthorizeRequest Validation/Authorize_ClientValidation_IdToken.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Configuration;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.AuthorizeRequest_Validation\n{\n\n    public class Authorize_ClientValidation_IdToken\n    {\n        private IdentityServerOptions _options = TestIdentityServerOptions.Create();\n\n        [Fact]\n        [Trait(\"Category\", \"AuthorizeRequest Client Validation - IdToken\")]\n        public async Task Mixed_IdToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidScope);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/AuthorizeRequest Validation/Authorize_ClientValidation_Invalid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Configuration;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.AuthorizeRequest_Validation\n{\n    public class Authorize_ClientValidation_Invalid\n    {\n        private const string Category = \"AuthorizeRequest Client Validation - Invalid\";\n\n        private IdentityServerOptions _options = TestIdentityServerOptions.Create();\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Protocol_Client()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"wsfed\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://wsfed/callback\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdToken);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/AuthorizeRequest Validation/Authorize_ClientValidation_Token.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Configuration;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.AuthorizeRequest_Validation\n{\n    public class Authorize_ClientValidation_Token\n    {\n        private const string Category = \"AuthorizeRequest Client Validation - Token\";\n\n        private IdentityServerOptions _options = TestIdentityServerOptions.Create();\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Mixed_Token_Request_Without_OpenId_Scope()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"resource profile\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Token);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task IdTokenToken_Request_with_no_AAVB()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient_no_aavb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdTokenToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task CodeIdTokenToken_Request_with_no_AAVB()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"hybridclient_no_aavb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"nonce\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.CodeIdTokenToken);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/AuthorizeRequest Validation/Authorize_ClientValidation_Valid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Configuration;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.AuthorizeRequest_Validation\n{\n    public class Authorize_ClientValidation_Valid\n    {\n        private const string Category = \"AuthorizeRequest Client Validation - Valid\";\n\n        private IdentityServerOptions _options = TestIdentityServerOptions.Create();\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_OpenId_Code_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Resource_Code_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Mixed_Code_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Mixed_Code_Request_Multiple_Scopes()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid profile resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_OpenId_CodeIdToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"hybridclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"nonce\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.CodeIdToken);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_OpenId_CodeIdTokenToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"hybridclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"nonce\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.CodeIdTokenToken);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Mixed_CodeIdToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"hybridclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"nonce\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.CodeIdToken);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Mixed_CodeIdTokenToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"hybridclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"nonce\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.CodeIdTokenToken);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_OpenId_IdTokenToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdTokenToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Mixed_IdTokenToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdTokenToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Mixed_IdTokenToken_Request_Multiple_Scopes()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid profile resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdTokenToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Resource_Token_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Token);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n            \n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", \"AuthorizeRequest Client Validation - Valid\")]\n        public async Task Valid_OpenId_TokenIdToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, \"token id_token\"); // Unconventional order\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/AuthorizeRequest Validation/Authorize_ProtocolValidation_CustomValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.AuthorizeRequest_Validation\n{\n    public class Authorize_ProtocolValidation_CustomValidator\n    {\n        private const string Category = \"AuthorizeRequest Protocol Validation\";\n\n        private StubAuthorizeRequestValidator _stubAuthorizeRequestValidator = new StubAuthorizeRequestValidator();\n        private AuthorizeRequestValidator _subject;\n\n        public Authorize_ProtocolValidation_CustomValidator()\n        {\n            _subject = Factory.CreateAuthorizeRequestValidator(customValidator: _stubAuthorizeRequestValidator);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task should_call_custom_validator()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var result = await _subject.ValidateAsync(parameters);\n\n            _stubAuthorizeRequestValidator.WasCalled.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task should_return_error_info_from_custom_validator()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            _stubAuthorizeRequestValidator.Callback = ctx =>\n            {\n                ctx.Result = new AuthorizeRequestValidationResult(ctx.Result.ValidatedRequest, \"foo\", \"bar\");\n            };\n            var result = await _subject.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(\"foo\");\n            result.ErrorDescription.Should().Be(\"bar\");\n        }\n    }\n\n    public class StubAuthorizeRequestValidator : ICustomAuthorizeRequestValidator\n    {\n        public Action<CustomAuthorizeRequestValidationContext> Callback;\n        public bool WasCalled { get; set; }\n\n        public Task ValidateAsync(CustomAuthorizeRequestValidationContext context)\n        {\n            WasCalled = true;\n            Callback?.Invoke(context);\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/AuthorizeRequest Validation/Authorize_ProtocolValidation_Invalid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.AuthorizeRequest_Validation\n{\n    public class Authorize_ProtocolValidation_Invalid\n    {\n        private const string Category = \"AuthorizeRequest Protocol Validation\";\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void Null_Parameter()\n        {\n            var validator = Factory.CreateAuthorizeRequestValidator();\n\n            Func<Task> act = () => validator.ValidateAsync(null);\n\n            act.Should().ThrowAsync<ArgumentNullException>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Empty_Parameters()\n        {\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(new NameValueCollection());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        // fails because openid scope is requested, but no response type that indicates an identity token\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task OpenId_Token_Only_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, IdentityServerConstants.StandardScopes.OpenId);\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Token);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Resource_Only_IdToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Mixed_Token_Only_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Token);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task OpenId_IdToken_Request_Nonce_Missing()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdToken);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_ClientId()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/callback\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_Scope()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_RedirectUri()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"client\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Malformed_RedirectUri()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"client\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"malformed\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Malformed_RedirectUri_Triple_Slash()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"client\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https:///attacker.com\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.UnsupportedResponseType);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Unknown_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, \"unknown\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.UnsupportedResponseType);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_ResponseMode_For_IdToken_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Query);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_ResponseMode_For_IdTokenToken_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdTokenToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Query);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_ResponseMode_For_CodeToken_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"hybridclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.CodeToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Query);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_ResponseMode_For_CodeIdToken_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"hybridclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.CodeIdToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Query);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_ResponseMode_For_CodeIdTokenToken_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"hybridclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.CodeIdTokenToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Query);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Malformed_MaxAge()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n            parameters.Add(OidcConstants.AuthorizeRequest.MaxAge, \"malformed\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Negative_MaxAge()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n            parameters.Add(OidcConstants.AuthorizeRequest.MaxAge, \"-1\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_ResponseMode_For_TokenIdToken_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, \"token id_token\"); // Unconventional order\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Query);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_ResponseMode_For_IdTokenCodeToken_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"hybridclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, \"id_token code token\"); // Unconventional ordering\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Query);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task prompt_none_and_other_values_should_fail()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Fragment);\n            parameters.Add(OidcConstants.AuthorizeRequest.Prompt, \"none login\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/AuthorizeRequest Validation/Authorize_ProtocolValidation_PKCE.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Configuration;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.AuthorizeRequest_Validation\n{\n    public class Authorize_ProtocolValidation_Valid_PKCE\n    {\n        private const string Category = \"AuthorizeRequest Protocol Validation - PKCE\";\n\n        private InputLengthRestrictions lengths = new InputLengthRestrictions();\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient\")]\n        [Trait(\"Category\", Category)]\n        public async Task valid_openid_code_request_with_challenge_and_plain_method_should_be_forbidden_if_plain_is_forbidden(string clientId)\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, clientId);\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallenge, \"x\".Repeat(lengths.CodeChallengeMinLength));\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallengeMethod, OidcConstants.CodeChallengeMethods.Plain);\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().Be(true);\n            result.ErrorDescription.Should().Be(\"Transform algorithm not supported\");\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient\")]\n        [Trait(\"Category\", Category)]\n        public async Task valid_openid_code_request_with_challenge_and_sh256_method_should_be_allowed(string clientId)\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, clientId);\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallenge, \"x\".Repeat(lengths.CodeChallengeMinLength));\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallengeMethod, OidcConstants.CodeChallengeMethods.Sha256);\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().Be(false);\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce.plain\")]\n        [InlineData(\"codeclient.plain\")]\n        [Trait(\"Category\", Category)]\n        public async Task valid_openid_code_request_with_challenge_and_missing_method_should_be_allowed_if_plain_is_allowed(string clientId)\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, clientId);\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallenge, \"x\".Repeat(lengths.CodeChallengeMinLength));\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().Be(false);\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient\")]\n        [Trait(\"Category\", Category)]\n        public async Task valid_openid_code_request_with_challenge_and_missing_method_should_be_forbidden_if_plain_is_forbidden(string clientId)\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, clientId);\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallenge, \"x\".Repeat(lengths.CodeChallengeMinLength));\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().Be(true);\n            result.ErrorDescription.Should().Be(\"Transform algorithm not supported\");\n        }\n\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task openid_code_request_missing_challenge_should_be_rejected()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient.pkce\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().Be(true);\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n            result.ErrorDescription.Should().Be(\"code challenge required\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task openid_hybrid_request_missing_challenge_should_be_rejected()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"hybridclient.pkce\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.CodeIdToken);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().Be(true);\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n            result.ErrorDescription.Should().Be(\"code challenge required\");\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient.pkce.plain\")]\n        [InlineData(\"codeclient\")]\n        [InlineData(\"codeclient.plain\")]\n        [Trait(\"Category\", Category)]\n        public async Task openid_code_request_with_challenge_and_invalid_method_should_be_rejected(string clientId)\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, clientId);\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallenge, \"x\".Repeat(lengths.CodeChallengeMinLength));\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallengeMethod, \"invalid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().Be(true);\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n            result.ErrorDescription.Should().Be(\"Transform algorithm not supported\");\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient.pkce.plain\")]\n        [InlineData(\"codeclient\")]\n        [InlineData(\"codeclient.plain\")]\n        [Trait(\"Category\", Category)]\n        public async Task openid_code_request_with_too_short_challenge_should_be_rejected(string clientId)\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, clientId);\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallenge, \"x\".Repeat(lengths.CodeChallengeMinLength - 1));\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallengeMethod, OidcConstants.CodeChallengeMethods.Plain);\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().Be(true);\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient.pkce.plain\")]\n        [InlineData(\"codeclient\")]\n        [InlineData(\"codeclient.plain\")]\n        [Trait(\"Category\", Category)]\n        public async Task openid_code_request_with_too_long_challenge_should_be_rejected(string clientId)\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, clientId);\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallenge, \"x\".Repeat(lengths.CodeChallengeMaxLength + 1));\n            parameters.Add(OidcConstants.AuthorizeRequest.CodeChallengeMethod, OidcConstants.CodeChallengeMethods.Plain);\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().Be(true);\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidRequest);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/AuthorizeRequest Validation/Authorize_ProtocolValidation_Valid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.AuthorizeRequest_Validation\n{\n    public class Authorize_ProtocolValidation_Valid\n    {\n        private const string Category = \"AuthorizeRequest Protocol Validation - Valid\";\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_OpenId_Code_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().Be(false);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Resource_Code_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Mixed_Code_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Resource_Token_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Token);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_OpenId_IdToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Mixed_IdTokenToken_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdTokenToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_OpenId_IdToken_With_FormPost_ResponseMode_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, IdentityServerConstants.StandardScopes.OpenId);\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.FormPost);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_OpenId_IdToken_Token_With_FormPost_ResponseMode_Request()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"implicitclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid resource\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"oob://implicit/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.IdTokenToken);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.FormPost);\n            parameters.Add(OidcConstants.AuthorizeRequest.Nonce, \"abc\");\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_ResponseMode_For_Code_ResponseType()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Fragment);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task anonymous_user_should_produce_session_state_value()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Fragment);\n            parameters.Add(OidcConstants.AuthorizeRequest.Prompt, OidcConstants.PromptModes.None);\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.ValidatedRequest.SessionId.Should().NotBeNull();\n        }\n        \n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task multiple_prompt_values_should_be_accepted()\n        {\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.AuthorizeRequest.ClientId, \"codeclient\");\n            parameters.Add(OidcConstants.AuthorizeRequest.Scope, \"openid\");\n            parameters.Add(OidcConstants.AuthorizeRequest.RedirectUri, \"https://server/cb\");\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseType, OidcConstants.ResponseTypes.Code);\n            parameters.Add(OidcConstants.AuthorizeRequest.ResponseMode, OidcConstants.ResponseModes.Fragment);\n            parameters.Add(OidcConstants.AuthorizeRequest.Prompt, OidcConstants.PromptModes.Consent.ToString() + \" \" + OidcConstants.PromptModes.Login.ToString());\n\n            var validator = Factory.CreateAuthorizeRequestValidator();\n            var result = await validator.ValidateAsync(parameters);\n\n            result.ValidatedRequest.PromptModes.Count().Should().Be(2);\n            result.ValidatedRequest.PromptModes.Should().Contain(OidcConstants.PromptModes.Login);\n            result.ValidatedRequest.PromptModes.Should().Contain(OidcConstants.PromptModes.Consent);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/BearerTokenUsageValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.IO;\nusing System.Text;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class BearerTokenUsageValidation\n    {\n        private const string Category = \"BearerTokenUsageValidator Tests\";\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task No_Header_no_Body_Get()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"GET\";\n\n            var validator = new BearerTokenUsageValidator(TestLogger.Create< BearerTokenUsageValidator>());\n            var result = await validator.ValidateAsync(ctx);\n\n            result.TokenFound.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task No_Header_no_Body_Post()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"POST\";\n\n            var validator = new BearerTokenUsageValidator(TestLogger.Create<BearerTokenUsageValidator>());\n            var result = await validator.ValidateAsync(ctx);\n\n            result.TokenFound.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Non_Bearer_Scheme_Header()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"GET\";\n            ctx.Request.Headers.Append(\"Authorization\", new string[] { \"Foo Bar\" });\n\n            var validator = new BearerTokenUsageValidator(TestLogger.Create<BearerTokenUsageValidator>());\n            var result = await validator.ValidateAsync(ctx);\n\n            result.TokenFound.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Empty_Bearer_Scheme_Header()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"GET\";\n            ctx.Request.Headers.Append(\"Authorization\", new string[] { \"Bearer\" });\n\n            var validator = new BearerTokenUsageValidator(TestLogger.Create<BearerTokenUsageValidator>());\n            var result = await validator.ValidateAsync(ctx);\n\n            result.TokenFound.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Whitespaces_Bearer_Scheme_Header()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"GET\";\n            ctx.Request.Headers.Append(\"Authorization\", new string[] { \"Bearer           \" });\n\n            var validator = new BearerTokenUsageValidator(TestLogger.Create<BearerTokenUsageValidator>());\n            var result = await validator.ValidateAsync(ctx);\n\n            result.TokenFound.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Bearer_Scheme_Header()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"GET\";\n            ctx.Request.Headers.Append(\"Authorization\", new string[] { \"Bearer token\" });\n\n            var validator = new BearerTokenUsageValidator(TestLogger.Create<BearerTokenUsageValidator>());\n            var result = await validator.ValidateAsync(ctx);\n\n            result.TokenFound.Should().BeTrue();\n            result.Token.Should().Be(\"token\");\n            result.UsageType.Should().Be(BearerTokenUsageType.AuthorizationHeader);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Body_Post()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"POST\";\n            ctx.Request.ContentType = \"application/x-www-form-urlencoded\";\n            var body = \"access_token=token\";\n            ctx.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n\n            var validator = new BearerTokenUsageValidator(TestLogger.Create<BearerTokenUsageValidator>());\n            var result = await validator.ValidateAsync(ctx);\n\n            result.TokenFound.Should().BeTrue();\n            result.Token.Should().Be(\"token\");\n            result.UsageType.Should().Be(BearerTokenUsageType.PostBody);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Body_Post_empty_Token()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"POST\";\n            ctx.Request.ContentType = \"application/x-www-form-urlencoded\";\n            var body = \"access_token=\";\n            ctx.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n\n            var validator = new BearerTokenUsageValidator(TestLogger.Create<BearerTokenUsageValidator>());\n            var result = await validator.ValidateAsync(ctx);\n\n            result.TokenFound.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Body_Post_Whitespace_Token()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"POST\";\n            ctx.Request.ContentType = \"application/x-www-form-urlencoded\";\n            var body = \"access_token=                \";\n            ctx.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n\n            var validator = new BearerTokenUsageValidator(TestLogger.Create<BearerTokenUsageValidator>());\n            var result = await validator.ValidateAsync(ctx);\n\n            result.TokenFound.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Body_Post_no_Token()\n        {\n            var ctx = new DefaultHttpContext();\n            ctx.Request.Method = \"POST\";\n            ctx.Request.ContentType = \"application/x-www-form-urlencoded\";\n            var body = \"foo=bar\";\n            ctx.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n\n            var validator = new BearerTokenUsageValidator(TestLogger.Create<BearerTokenUsageValidator>());\n            var result = await validator.ValidateAsync(ctx);\n\n            result.TokenFound.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/ClientConfigurationValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing System;\nusing System.Threading.Tasks;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class ClientConfigurationValidation\n    {\n        private const string Category = \"Client Configuration Validation Tests\";\n        private IClientConfigurationValidator _validator;\n        IdentityServerOptions _options;\n\n        public ClientConfigurationValidation()\n        {\n            _options = new IdentityServerOptions();\n            _validator = new DefaultClientConfigurationValidator(_options);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Standard_clients_should_succeed()\n        {\n            foreach (var client in TestClients.Get())\n            {\n                // deliberate invalid configuration\n                if (client.ClientId == \"implicit_and_client_creds\") continue;\n\n                var context = await ValidateAsync(client);\n\n                if (!context.IsValid)\n                {\n                    throw new System.Exception($\"client {client.ClientId} failed configuration validation: {context.ErrorMessage}\");\n                }\n\n            }\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_access_token_lifetime_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                RequireClientSecret = false,\n                AllowedScopes = { \"foo\" },\n\n                AccessTokenLifetime = 0\n            };\n\n            await ShouldFailAsync(client, \"access token lifetime is 0 or negative\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_identity_token_lifetime_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                RequireClientSecret = false,\n                AllowedScopes = { \"foo\" },\n\n                IdentityTokenLifetime = 0\n            };\n\n            await ShouldFailAsync(client, \"identity token lifetime is 0 or negative\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_absolute_refresh_token_lifetime_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                RequireClientSecret = false,\n                AllowedScopes = { \"foo\" },\n\n                AbsoluteRefreshTokenLifetime = -1\n            };\n\n            await ShouldFailAsync(client, \"absolute refresh token lifetime is negative\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_sliding_refresh_token_lifetime_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                RequireClientSecret = false,\n                AllowedScopes = { \"foo\" },\n\n                SlidingRefreshTokenLifetime = -1\n            };\n\n            await ShouldFailAsync(client, \"sliding refresh token lifetime is negative\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_allowed_grant_type_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                RequireClientSecret = false,\n                AllowedScopes = { \"foo\" },\n            };\n\n            await ShouldFailAsync(client, \"no allowed grant type specified\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_client_secret_for_client_credentials_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                AllowedScopes = { \"foo\" },\n            };\n\n            await ShouldFailAsync(client, \"Client secret is required for client_credentials, but no client secret is configured.\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_client_secret_for_implicit_and_client_credentials_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ImplicitAndClientCredentials,\n                RedirectUris = { \"https://foo\" },\n                AllowedScopes = { \"foo\" },\n            };\n\n            await ShouldFailAsync(client, \"Client secret is required for client_credentials, but no client secret is configured.\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_client_secret_for_hybrid_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Hybrid,\n                RedirectUris = { \"https://foo\" },\n                AllowedScopes = { \"foo\" },\n            };\n\n            await ShouldFailAsync(client, \"Client secret is required for hybrid, but no client secret is configured.\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_client_secret_for_code_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Code,\n                RedirectUris = { \"https://foo\" },\n                AllowedScopes = { \"foo\" },\n            };\n\n            await ShouldFailAsync(client, \"Client secret is required for authorization_code, but no client secret is configured.\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Not_required_client_secret_for_hybrid_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Hybrid,\n                RequireClientSecret = false,\n                RedirectUris = { \"https://foo\" },\n                AllowedScopes = { \"foo\" },\n            };\n\n            var context = await ValidateAsync(client);\n            context.IsValid.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_client_secret_for_implicit_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                AllowedScopes = { \"foo\" },\n                RedirectUris = { \"https://foo\" }\n            };\n\n            var context = await ValidateAsync(client);\n            context.IsValid.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task empty_grant_types_collection_should_fail()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = { },\n                AllowedScopes = { \"foo\" },\n                RedirectUris = { \"https://foo\" }\n            };\n\n            var context = await ValidateAsync(client);\n            await ShouldFailAsync(client, \"no allowed grant type specified\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task null_redirect_uris_collection_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                ClientSecrets = { new Secret(\"hash\") },\n                AllowedScopes = { \"foo\" },\n                RedirectUris = null,\n            };\n\n            var context = await ValidateAsync(client);\n            context.IsValid.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task null_post_logout_redirect_uris_collection_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                ClientSecrets = { new Secret(\"hash\") },\n                AllowedScopes = { \"foo\" },\n                PostLogoutRedirectUris = null\n            };\n\n            var context = await ValidateAsync(client);\n            context.IsValid.Should().BeTrue();\n        }\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task null_redirect_uris_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                ClientSecrets = { new Secret(\"hash\") },\n                AllowedScopes = { \"foo\" },\n                RedirectUris = { null }\n            };\n\n            var context = await ValidateAsync(client);\n            context.IsValid.Should().BeTrue();\n        }\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task null_post_logout_redirect_uris_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                ClientSecrets = { new Secret(\"hash\") },\n                AllowedScopes = { \"foo\" },\n                PostLogoutRedirectUris = { null }\n            };\n\n            var context = await ValidateAsync(client);\n            context.IsValid.Should().BeTrue();\n        }\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task empty_redirect_uris_collection_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                ClientSecrets = { new Secret(\"hash\") },\n                AllowedScopes = { \"foo\" },\n                RedirectUris = { },\n            };\n\n            var context = await ValidateAsync(client);\n            context.IsValid.Should().BeTrue();\n        }\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task empty_post_logout_redirect_uris_collection_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.ClientCredentials,\n                ClientSecrets = { new Secret(\"hash\") },\n                AllowedScopes = { \"foo\" },\n                PostLogoutRedirectUris = { },\n            };\n\n            var context = await ValidateAsync(client);\n            context.IsValid.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ValidateUriSchemesAsync_for_invalid_redirecturi_scheme_should_fail()\n        {\n            _options.Validation.InvalidRedirectUriPrefixes.Add(\"custom\");\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                AllowedScopes = { \"foo\" },\n                RedirectUris = { \"http://callback\", \"custom://callback\" }\n            };\n\n            var result = await ValidateAsync(client);\n            await ShouldFailAsync(client, \"RedirectUri 'custom://callback' uses invalid scheme. If this scheme should be allowed, then configure it via ValidationOptions.\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ValidateUriSchemesAsync_for_null_redirecturi_scheme_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                AllowedScopes = { \"foo\" },\n                RedirectUris = null\n            };\n\n            var result = await ValidateAsync(client);\n            result.IsValid.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ValidateUriSchemesAsync_for_valid_redirect_uri_scheme_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                AllowedScopes = { \"foo\" },\n                RedirectUris = { \"http://callback\", \"custom://callback\" }\n            };\n\n            var result = await ValidateAsync(client);\n            result.IsValid.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ValidateUriSchemesAsync_for_invalid_post_logout_redirect_uri_scheme_should_fail()\n        {\n            _options.Validation.InvalidRedirectUriPrefixes.Add(\"custom\");\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                AllowedScopes = { \"foo\" },\n                RedirectUris = { \"http://callback\" },\n                PostLogoutRedirectUris = { \"http://postcallback\", \"custom://postcallback\" }\n            };\n\n            var result = await ValidateAsync(client);\n            await ShouldFailAsync(client, \"PostLogoutRedirectUri 'custom://postcallback' uses invalid scheme. If this scheme should be allowed, then configure it via ValidationOptions.\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task ValidateUriSchemesAsync_for_valid_post_logout_redirect_uri_scheme_should_succeed()\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                AllowedScopes = { \"foo\" },\n                RedirectUris = { \"http://callback\" },\n                PostLogoutRedirectUris = { \"http://postcallback\", \"custom://postcallback\" }\n            };\n\n            var result = await ValidateAsync(client);\n            result.IsValid.Should().BeTrue();\n        }\n\n        [Theory]\n        [Trait(\"Category\", Category)]\n        [InlineData(\"bad\")]\n        [InlineData(\"urn:foo\")]\n        [InlineData(\"urn:foo:123\")]\n        [InlineData(\"http://foo/\")]\n        [InlineData(\"http://foo:80/path\")]\n        [InlineData(\"http://foo/path\")]\n        [InlineData(\"http://foo:123/path\")]\n        [InlineData(\"https://foo:443/path\")]\n        [InlineData(\"custom://foo/\")]\n        [InlineData(\"custom://foo/path\")]\n        [InlineData(\"custom://foo:443/\")]\n        [InlineData(\"custom://foo:443/path\")]\n        [InlineData(\"\")]\n        [InlineData(\"   \")]\n        [InlineData((string)null)]\n        public async Task ValidateAllowedCorsOriginsAsync_should_report_invalid_URL_format(string origin)\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RedirectUris = { \"http://client\" },\n                AllowedCorsOrigins = { origin }\n            };\n\n            var result = await ValidateAsync(client);\n            result.IsValid.Should().BeFalse();\n            result.ErrorMessage.Should().Contain(\"invalid origin\");\n            if (!String.IsNullOrWhiteSpace(origin))\n            {\n                result.ErrorMessage.Should().Contain(origin);\n            }\n            else\n            {\n                result.ErrorMessage.Should().Contain(\"empty value\");\n            }\n        }\n\n        [Theory]\n        [Trait(\"Category\", Category)]\n        [InlineData(\"http://foo\")]\n        [InlineData(\"http://foo:80\")]\n        [InlineData(\"https://foo\")]\n        [InlineData(\"http://foo:123\")]\n        [InlineData(\"https://foo:456\")]\n        [InlineData(\"https://foo:443\")]\n        [InlineData(\"custom://foo\")]\n        [InlineData(\"custom://foo:443\")]\n        public async Task ValidateAllowedCorsOriginsAsync_should_allow_valid_formats(string origin)\n        {\n            var client = new Client\n            {\n                ClientId = \"id\",\n                AllowedGrantTypes = GrantTypes.Implicit,\n                RedirectUris = { \"http://client\" },\n                AllowedCorsOrigins = { origin }\n            };\n\n            var result = await ValidateAsync(client);\n            result.IsValid.Should().BeTrue();\n        }\n\n\n        private async Task<ClientConfigurationValidationContext> ValidateAsync(Client client)\n        {\n            var context = new ClientConfigurationValidationContext(client);\n            await _validator.ValidateAsync(context);\n\n            return context;\n        }\n\n        private async Task ShouldFailAsync(Client client, string expectedError)\n        {\n            var context = await ValidateAsync(client);\n\n            context.IsValid.Should().BeFalse();\n            context.ErrorMessage.Should().Be(expectedError);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/DeviceAuthorizationRequestValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Specialized;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class DeviceAuthorizationRequestValidation\n    {\n        private const string Category = \"Device authorization request validation\";\n\n        private readonly NameValueCollection testParameters = new NameValueCollection { { \"scope\", \"resource\" } };\n        private readonly Client testClient = new Client\n        {\n            ClientId = \"device_flow\",\n            AllowedGrantTypes = GrantTypes.DeviceFlow,\n            AllowedScopes = {\"openid\", \"profile\", \"resource\"},\n            AllowOfflineAccess = true\n        };\n        \n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void Null_Parameter()\n        {\n            var validator = Factory.CreateDeviceAuthorizationRequestValidator();\n\n            Func<Task> act = () => validator.ValidateAsync(null, null);\n\n            act.Should().ThrowAsync<ArgumentNullException>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Protocol_Client()\n        {\n            testClient.ProtocolType = IdentityServerConstants.ProtocolTypes.WsFederation;\n\n            var validator = Factory.CreateDeviceAuthorizationRequestValidator();\n            var result = await validator.ValidateAsync(testParameters, new ClientSecretValidationResult {Client = testClient});\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Grant_Type()\n        {\n            testClient.AllowedGrantTypes = GrantTypes.Implicit;\n\n            var validator = Factory.CreateDeviceAuthorizationRequestValidator();\n            var result = await validator.ValidateAsync(testParameters, new ClientSecretValidationResult {Client = testClient});\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.UnauthorizedClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Unauthorized_Scope()\n        {\n            var parameters = new NameValueCollection {{\"scope\", \"resource2\"}};\n\n            var validator = Factory.CreateDeviceAuthorizationRequestValidator();\n            var result = await validator.ValidateAsync(parameters, new ClientSecretValidationResult {Client = testClient});\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Unknown_Scope()\n        {\n            var parameters = new NameValueCollection {{\"scope\", Guid.NewGuid().ToString()}};\n\n            var validator = Factory.CreateDeviceAuthorizationRequestValidator();\n            var result = await validator.ValidateAsync(parameters, new ClientSecretValidationResult {Client = testClient});\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_OpenId_Request()\n        {\n            var parameters = new NameValueCollection {{\"scope\", \"openid\"}};\n\n            var validator = Factory.CreateDeviceAuthorizationRequestValidator();\n            var result = await validator.ValidateAsync(parameters, new ClientSecretValidationResult {Client = testClient});\n\n            result.IsError.Should().BeFalse();\n            result.ValidatedRequest.IsOpenIdRequest.Should().BeTrue();\n            result.ValidatedRequest.RequestedScopes.Should().Contain(\"openid\");\n\n            result.ValidatedRequest.ValidatedResources.Resources.IdentityResources.Should().Contain(x => x.Name == \"openid\");\n            result.ValidatedRequest.ValidatedResources.Resources.ApiResources.Should().BeEmpty();\n            result.ValidatedRequest.ValidatedResources.Resources.OfflineAccess.Should().BeFalse();\n\n            result.ValidatedRequest.ValidatedResources.Resources.IdentityResources.Any().Should().BeTrue();\n            result.ValidatedRequest.ValidatedResources.Resources.ApiResources.Any().Should().BeFalse();\n            result.ValidatedRequest.ValidatedResources.Resources.OfflineAccess.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Resource_Request()\n        {\n            var parameters = new NameValueCollection { { \"scope\", \"resource\" } };\n\n            var validator = Factory.CreateDeviceAuthorizationRequestValidator();\n            var result = await validator.ValidateAsync(parameters, new ClientSecretValidationResult { Client = testClient });\n\n            result.IsError.Should().BeFalse();\n            result.ValidatedRequest.IsOpenIdRequest.Should().BeFalse();\n            result.ValidatedRequest.RequestedScopes.Should().Contain(\"resource\");\n\n            result.ValidatedRequest.ValidatedResources.Resources.IdentityResources.Should().BeEmpty();\n            result.ValidatedRequest.ValidatedResources.Resources.ApiResources.Should().Contain(x => x.Name == \"api\");\n            result.ValidatedRequest.ValidatedResources.Resources.ApiScopes.Should().Contain(x => x.Name == \"resource\");\n            result.ValidatedRequest.ValidatedResources.Resources.OfflineAccess.Should().BeFalse();\n\n            result.ValidatedRequest.ValidatedResources.Resources.IdentityResources.Any().Should().BeFalse();\n            result.ValidatedRequest.ValidatedResources.Resources.ApiResources.Any().Should().BeTrue();\n            result.ValidatedRequest.ValidatedResources.Resources.ApiScopes.Any().Should().BeTrue();\n            result.ValidatedRequest.ValidatedResources.Resources.OfflineAccess.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Mixed_Request()\n        {\n            var parameters = new NameValueCollection { { \"scope\", \"openid resource offline_access\" } };\n\n            var validator = Factory.CreateDeviceAuthorizationRequestValidator();\n            var result = await validator.ValidateAsync(parameters, new ClientSecretValidationResult { Client = testClient });\n\n            result.IsError.Should().BeFalse();\n            result.ValidatedRequest.IsOpenIdRequest.Should().BeTrue();\n            result.ValidatedRequest.RequestedScopes.Should().Contain(\"openid\");\n            result.ValidatedRequest.RequestedScopes.Should().Contain(\"resource\");\n            result.ValidatedRequest.RequestedScopes.Should().Contain(\"offline_access\");\n\n            result.ValidatedRequest.ValidatedResources.Resources.IdentityResources.Should().Contain(x => x.Name == \"openid\");\n            result.ValidatedRequest.ValidatedResources.Resources.ApiResources.Should().Contain(x => x.Name == \"api\");\n            result.ValidatedRequest.ValidatedResources.Resources.ApiScopes.Should().Contain(x => x.Name == \"resource\");\n            result.ValidatedRequest.ValidatedResources.Resources.OfflineAccess.Should().BeTrue();\n\n            result.ValidatedRequest.ValidatedResources.Resources.IdentityResources.Any().Should().BeTrue();\n            result.ValidatedRequest.ValidatedResources.Resources.ApiResources.Any().Should().BeTrue();\n            result.ValidatedRequest.ValidatedResources.Resources.ApiScopes.Any().Should().BeTrue();\n            result.ValidatedRequest.ValidatedResources.Resources.OfflineAccess.Should().BeTrue();\n        }\n\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_Scopes_Expect_Client_Scopes()\n        {\n            var validator = Factory.CreateDeviceAuthorizationRequestValidator();\n\n            var result = await validator.ValidateAsync(\n                new NameValueCollection(),\n                new ClientSecretValidationResult { Client = testClient });\n\n            result.IsError.Should().BeFalse();\n            result.ValidatedRequest.RequestedScopes.Should().Contain(testClient.AllowedScopes);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_Scopes_And_Client_Scopes_Empty()\n        {\n            testClient.AllowedScopes.Clear();\n            var validator = Factory.CreateDeviceAuthorizationRequestValidator();\n\n            var result = await validator.ValidateAsync(\n                new NameValueCollection(),\n                new ClientSecretValidationResult { Client = testClient });\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.AuthorizeErrors.InvalidScope);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/DeviceCodeValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class DeviceCodeValidation\n    {\n        private const string Category = \"Device code validation\";\n\n        private readonly IClientStore _clients = Factory.CreateClientStore();\n\n        private readonly DeviceCode deviceCode = new DeviceCode\n        {\n            ClientId = \"device_flow\",\n            IsAuthorized = true,\n            Subject = new IdentityServerUser(\"bob\").CreatePrincipal(),\n            IsOpenId = true,\n            Lifetime = 300,\n            CreationTime = DateTime.UtcNow,\n            AuthorizedScopes = new[] { \"openid\", \"profile\", \"resource\" }\n        };\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task DeviceCode_Missing()\n        {\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n            var service = Factory.CreateDeviceCodeService();\n\n            var validator = Factory.CreateDeviceCodeValidator(service);\n\n            var request = new ValidatedTokenRequest();\n            request.SetClient(client);\n\n            var context = new DeviceCodeValidationContext { DeviceCode = null, Request = request };\n\n            await validator.ValidateAsync(context);\n\n            context.Result.IsError.Should().BeTrue();\n            context.Result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task DeviceCode_From_Different_Client()\n        {\n            var badActor = await _clients.FindClientByIdAsync(\"codeclient\");\n            var service = Factory.CreateDeviceCodeService();\n\n            var handle = await service.StoreDeviceAuthorizationAsync(Guid.NewGuid().ToString(), deviceCode);\n\n            var validator = Factory.CreateDeviceCodeValidator(service);\n\n            var request = new ValidatedTokenRequest();\n            request.SetClient(badActor);\n\n            var context = new DeviceCodeValidationContext { DeviceCode = handle, Request = request };\n\n            await validator.ValidateAsync(context);\n\n            context.Result.IsError.Should().BeTrue();\n            context.Result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Expired_DeviceCode()\n        {\n            deviceCode.CreationTime = DateTime.UtcNow.AddDays(-10);\n            deviceCode.Lifetime = 300;\n\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n            var service = Factory.CreateDeviceCodeService();\n\n            var handle = await service.StoreDeviceAuthorizationAsync(Guid.NewGuid().ToString(), deviceCode);\n\n            var validator = Factory.CreateDeviceCodeValidator(service);\n\n            var request = new ValidatedTokenRequest();\n            request.SetClient(client);\n\n            var context = new DeviceCodeValidationContext { DeviceCode = handle, Request = request };\n\n            await validator.ValidateAsync(context);\n\n            context.Result.IsError.Should().BeTrue();\n            context.Result.Error.Should().Be(OidcConstants.TokenErrors.ExpiredToken);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Access_Denied()\n        {\n            deviceCode.AuthorizedScopes = new List<string>();\n\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n            var service = Factory.CreateDeviceCodeService();\n\n            var handle = await service.StoreDeviceAuthorizationAsync(Guid.NewGuid().ToString(), deviceCode);\n\n            var validator = Factory.CreateDeviceCodeValidator(service);\n\n            var request = new ValidatedTokenRequest();\n            request.SetClient(client);\n\n            var context = new DeviceCodeValidationContext { DeviceCode = handle, Request = request };\n\n            await validator.ValidateAsync(context);\n\n            context.Result.IsError.Should().BeTrue();\n            context.Result.Error.Should().Be(OidcConstants.TokenErrors.AccessDenied);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task DeviceCode_Not_Yet_Authorized()\n        {\n            deviceCode.IsAuthorized = false;\n\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n            var service = Factory.CreateDeviceCodeService();\n\n            var handle = await service.StoreDeviceAuthorizationAsync(Guid.NewGuid().ToString(), deviceCode);\n\n            var validator = Factory.CreateDeviceCodeValidator(service);\n\n            var request = new ValidatedTokenRequest();\n            request.SetClient(client);\n\n            var context = new DeviceCodeValidationContext { DeviceCode = handle, Request = request };\n\n            await validator.ValidateAsync(context);\n\n            context.Result.IsError.Should().BeTrue();\n            context.Result.Error.Should().Be(OidcConstants.TokenErrors.AuthorizationPending);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task DeviceCode_Missing_Subject()\n        {\n            deviceCode.Subject = null;\n\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n            var service = Factory.CreateDeviceCodeService();\n\n            var handle = await service.StoreDeviceAuthorizationAsync(Guid.NewGuid().ToString(), deviceCode);\n\n            var validator = Factory.CreateDeviceCodeValidator(service);\n\n            var request = new ValidatedTokenRequest();\n            request.SetClient(client);\n\n            var context = new DeviceCodeValidationContext { DeviceCode = handle, Request = request };\n\n            await validator.ValidateAsync(context);\n\n            context.Result.IsError.Should().BeTrue();\n            context.Result.Error.Should().Be(OidcConstants.TokenErrors.AuthorizationPending);\n        }\n\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task User_Disabled()\n        {\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n            var service = Factory.CreateDeviceCodeService();\n\n            var handle = await service.StoreDeviceAuthorizationAsync(Guid.NewGuid().ToString(), deviceCode);\n\n            var validator = Factory.CreateDeviceCodeValidator(service, new TestProfileService(false));\n\n            var request = new ValidatedTokenRequest();\n            request.SetClient(client);\n\n            var context = new DeviceCodeValidationContext { DeviceCode = handle, Request = request };\n\n            await validator.ValidateAsync(context);\n\n            context.Result.IsError.Should().BeTrue();\n            context.Result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task DeviceCode_Polling_Too_Fast()\n        {\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n            var service = Factory.CreateDeviceCodeService();\n\n            var handle = await service.StoreDeviceAuthorizationAsync(Guid.NewGuid().ToString(), deviceCode);\n\n            var validator = Factory.CreateDeviceCodeValidator(service, throttlingService: new TestDeviceFlowThrottlingService(true));\n\n            var request = new ValidatedTokenRequest();\n            request.SetClient(client);\n\n            var context = new DeviceCodeValidationContext { DeviceCode = handle, Request = request };\n\n            await validator.ValidateAsync(context);\n\n            context.Result.IsError.Should().BeTrue();\n            context.Result.Error.Should().Be(OidcConstants.TokenErrors.SlowDown);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_DeviceCode()\n        {\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n            var service = Factory.CreateDeviceCodeService();\n\n            var handle = await service.StoreDeviceAuthorizationAsync(Guid.NewGuid().ToString(), deviceCode);\n\n            var validator = Factory.CreateDeviceCodeValidator(service);\n\n            var request = new ValidatedTokenRequest();\n            request.SetClient(client);\n\n            var context = new DeviceCodeValidationContext {DeviceCode = handle, Request = request};\n\n            await validator.ValidateAsync(context);\n            \n            context.Result.IsError.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/EndSessionRequestValidation/EndSessionRequestValidatorTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Collections.Specialized;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.EndSessionRequestValidation\n{\n    public class EndSessionRequestValidatorTests\n    {\n        private EndSessionRequestValidator _subject;\n        private IdentityServerOptions _options;\n        private StubTokenValidator _stubTokenValidator = new StubTokenValidator();\n        private StubRedirectUriValidator _stubRedirectUriValidator = new StubRedirectUriValidator();\n        private MockHttpContextAccessor _context = new MockHttpContextAccessor();\n        private MockUserSession _userSession = new MockUserSession();\n        private MockLogoutNotificationService _mockLogoutNotificationService = new MockLogoutNotificationService();\n        private MockMessageStore<LogoutNotificationContext> _mockEndSessionMessageStore = new MockMessageStore<LogoutNotificationContext>();\n\n        private ClaimsPrincipal _user;\n\n        public EndSessionRequestValidatorTests()\n        {\n            _user = new IdentityServerUser(\"alice\").CreatePrincipal();\n\n            _options = TestIdentityServerOptions.Create();\n            _subject = new EndSessionRequestValidator(\n                _context,\n                _options,\n                _stubTokenValidator,\n                _stubRedirectUriValidator,\n                _userSession,\n                _mockLogoutNotificationService,\n                _mockEndSessionMessageStore,\n                TestLogger.Create<EndSessionRequestValidator>());\n        }\n\n        [Fact]\n        public async Task anonymous_user_when_options_require_authenticated_user_should_return_error()\n        {\n            _options.Authentication.RequireAuthenticatedUserForSignOutMessage = true;\n\n            var parameters = new NameValueCollection();\n            var result = await _subject.ValidateAsync(parameters, null);\n            result.IsError.Should().BeTrue();\n\n            result = await _subject.ValidateAsync(parameters, new ClaimsPrincipal());\n            result.IsError.Should().BeTrue();\n\n            result = await _subject.ValidateAsync(parameters, new ClaimsPrincipal(new ClaimsIdentity()));\n            result.IsError.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task valid_params_should_return_success()\n        {\n            _stubTokenValidator.IdentityTokenValidationResult = new TokenValidationResult()\n            {\n                IsError = false,\n                Claims = new Claim[] { new Claim(\"sub\", _user.GetSubjectId()) },\n                Client = new Client() { ClientId = \"client\"}\n            };\n            _stubRedirectUriValidator.IsPostLogoutRedirectUriValid = true;\n\n            var parameters = new NameValueCollection();\n            parameters.Add(\"id_token_hint\", \"id_token\");\n            parameters.Add(\"post_logout_redirect_uri\", \"http://client/signout-cb\");\n            parameters.Add(\"client_id\", \"client1\");\n            parameters.Add(\"state\", \"foo\");\n\n            var result = await _subject.ValidateAsync(parameters, _user);\n            result.IsError.Should().BeFalse();\n\n            result.ValidatedRequest.Client.ClientId.Should().Be(\"client\");\n            result.ValidatedRequest.PostLogOutUri.Should().Be(\"http://client/signout-cb\");\n            result.ValidatedRequest.State.Should().Be(\"foo\");\n            result.ValidatedRequest.Subject.GetSubjectId().Should().Be(_user.GetSubjectId());\n        }\n\n        [Fact]\n        public async Task no_post_logout_redirect_uri_should_not_use_single_registered_uri()\n        {\n            _stubTokenValidator.IdentityTokenValidationResult = new TokenValidationResult()\n            {\n                IsError = false,\n                Claims = new Claim[] { new Claim(\"sub\", _user.GetSubjectId()) },\n                Client = new Client() { ClientId = \"client1\", PostLogoutRedirectUris = new List<string> { \"foo\" } }\n            };\n            _stubRedirectUriValidator.IsPostLogoutRedirectUriValid = true;\n\n            var parameters = new NameValueCollection();\n            parameters.Add(\"id_token_hint\", \"id_token\");\n\n            var result = await _subject.ValidateAsync(parameters, _user);\n            result.IsError.Should().BeFalse();\n            result.ValidatedRequest.PostLogOutUri.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task no_post_logout_redirect_uri_should_not_use_multiple_registered_uri()\n        {\n            _stubTokenValidator.IdentityTokenValidationResult = new TokenValidationResult()\n            {\n                IsError = false,\n                Claims = new Claim[] { new Claim(\"sub\", _user.GetSubjectId()) },\n                Client = new Client() { ClientId = \"client1\", PostLogoutRedirectUris = new List<string> { \"foo\", \"bar\" } }\n            };\n            _stubRedirectUriValidator.IsPostLogoutRedirectUriValid = true;\n\n            var parameters = new NameValueCollection();\n            parameters.Add(\"id_token_hint\", \"id_token\");\n\n            var result = await _subject.ValidateAsync(parameters, _user);\n            result.IsError.Should().BeFalse();\n            result.ValidatedRequest.PostLogOutUri.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task post_logout_uri_fails_validation_should_not_honor_logout_uri()\n        {\n            _stubTokenValidator.IdentityTokenValidationResult = new TokenValidationResult()\n            {\n                IsError = false,\n                Claims = new Claim[] { new Claim(\"sub\", _user.GetSubjectId()) },\n                Client = new Client() { ClientId = \"client\" }\n            };\n            _stubRedirectUriValidator.IsPostLogoutRedirectUriValid = false;\n\n            var parameters = new NameValueCollection();\n            parameters.Add(\"id_token_hint\", \"id_token\");\n            parameters.Add(\"post_logout_redirect_uri\", \"http://client/signout-cb\");\n            parameters.Add(\"client_id\", \"client1\");\n            parameters.Add(\"state\", \"foo\");\n\n            var result = await _subject.ValidateAsync(parameters, _user);\n            result.IsError.Should().BeFalse();\n\n            result.ValidatedRequest.Client.ClientId.Should().Be(\"client\");\n            result.ValidatedRequest.Subject.GetSubjectId().Should().Be(_user.GetSubjectId());\n            \n            result.ValidatedRequest.State.Should().BeNull();\n            result.ValidatedRequest.PostLogOutUri.Should().BeNull();\n        }\n\n        [Fact]\n        public async Task subject_mismatch_should_return_error()\n        {\n            _stubTokenValidator.IdentityTokenValidationResult = new TokenValidationResult()\n            {\n                IsError = false,\n                Claims = new Claim[] { new Claim(\"sub\", \"xoxo\") },\n                Client = new Client() { ClientId = \"client\" }\n            };\n            _stubRedirectUriValidator.IsPostLogoutRedirectUriValid = true;\n\n            var parameters = new NameValueCollection();\n            parameters.Add(\"id_token_hint\", \"id_token\");\n            parameters.Add(\"post_logout_redirect_uri\", \"http://client/signout-cb\");\n            parameters.Add(\"client_id\", \"client1\");\n            parameters.Add(\"state\", \"foo\");\n\n            var result = await _subject.ValidateAsync(parameters, _user);\n            result.IsError.Should().BeTrue();\n        }\n\n        [Fact]\n        public async Task successful_request_should_return_inputs()\n        {\n            var parameters = new NameValueCollection();\n\n            var result = await _subject.ValidateAsync(parameters, _user);\n            result.IsError.Should().BeFalse();\n            result.ValidatedRequest.Raw.Should().BeSameAs(parameters);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/EndSessionRequestValidation/StubRedirectUriValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Validation.EndSessionRequestValidation\n{\n    public class StubRedirectUriValidator : IRedirectUriValidator\n    {\n        public bool IsRedirectUriValid { get; set; }\n        public bool IsPostLogoutRedirectUriValid { get; set; }\n\n        public Task<bool> IsPostLogoutRedirectUriValidAsync(string requestedUri, Client client)\n        {\n            return Task.FromResult(IsPostLogoutRedirectUriValid);\n        }\n\n        public Task<bool> IsRedirectUriValidAsync(string requestedUri, Client client)\n        {\n            return Task.FromResult(IsRedirectUriValid);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/EndSessionRequestValidation/StubTokenValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Validation.EndSessionRequestValidation\n{\n    public class StubTokenValidator : ITokenValidator\n    {\n        public TokenValidationResult AccessTokenValidationResult { get; set; } = new TokenValidationResult();\n        public TokenValidationResult IdentityTokenValidationResult { get; set; } = new TokenValidationResult();\n\n        public Task<TokenValidationResult> ValidateAccessTokenAsync(string token, string expectedScope = null)\n        {\n            return Task.FromResult(AccessTokenValidationResult);\n        }\n\n        public Task<TokenValidationResult> ValidateIdentityTokenAsync(string token, string clientId = null, bool validateLifetime = true)\n        {\n            return Task.FromResult(IdentityTokenValidationResult);\n        }\n\n        public Task<TokenValidationResult> ValidateRefreshTokenAsync(string token, Client client)\n        {\n            throw new System.NotImplementedException();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/GrantTypesValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing FluentAssertions;\nusing IdentityServer8.Models;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class GrantTypesValidation\n    {\n        private const string Category = \"Grant Types Validation\";\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void empty_should_be_allowed()\n        {\n            var client = new Client();\n            client.AllowedGrantTypes = new List<string>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void implicit_should_be_allowed()\n        {\n            var client = new Client();\n            client.AllowedGrantTypes = GrantTypes.Implicit;\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void custom_should_be_allowed()\n        {\n            var client = new Client();\n            client.AllowedGrantTypes = new[] { \"custom\" };\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void custom_should_be_allowed_raw()\n        {\n            var client = new Client();\n            client.AllowedGrantTypes = new[] { \"custom\" };\n        }\n        \n        [Theory]\n        [Trait(\"Category\", Category)]\n        [InlineData(GrantType.Implicit, GrantType.Hybrid)]\n        [InlineData(GrantType.Implicit, GrantType.AuthorizationCode)]\n        [InlineData(GrantType.AuthorizationCode, GrantType.Hybrid)]\n        public void forbidden_grant_type_combinations_should_throw(string type1, string type2)\n        {\n            var client = new Client();\n\n            Action act = () => client.AllowedGrantTypes = new[] { type1, type2 };\n\n            act.Should().Throw<InvalidOperationException>();            \n        }\n\n        [Theory]\n        [Trait(\"Category\", Category)]\n        [InlineData(GrantType.Implicit, GrantType.Hybrid)]\n        [InlineData(GrantType.Implicit, GrantType.AuthorizationCode)]\n        [InlineData(GrantType.AuthorizationCode, GrantType.Hybrid)]\n        public void custom_and_forbidden_grant_type_combinations_should_throw(string type1, string type2)\n        {\n            var client = new Client();\n\n            Action act = () => client.AllowedGrantTypes = new[] { \"custom1\", type2, \"custom2\", type1 };\n\n            act.Should().Throw<InvalidOperationException>();\n        }\n\n        [Fact]\n        public void duplicate_values_should_throw()\n        {\n            var client = new Client();\n\n            Action act = () => client.AllowedGrantTypes = new[] { \"custom1\", \"custom2\", \"custom1\" };\n\n            act.Should().Throw<InvalidOperationException>();\n        }\n\n        [Fact]\n        public void null_grant_type_list_should_throw_single()\n        {\n            var client = new Client();\n\n            Action act = () => client.AllowedGrantTypes = null;\n\n            act.Should().Throw<ArgumentNullException>();\n        }\n\n        [Fact]\n        public void grant_type_with_space_should_throw_single()\n        {\n            var client = new Client();\n\n            Action act = () => client.AllowedGrantTypes = new[] { \"custo m2\" };\n\n            act.Should().Throw<InvalidOperationException>();\n        }\n\n        [Fact]\n        public void grant_type_with_space_should_throw_multiple()\n        {\n            var client = new Client();\n\n            Action act = () => client.AllowedGrantTypes = new[] { \"custom1\", \"custo m2\", \"custom1\" };\n\n            act.Should().Throw<InvalidOperationException>();\n        }\n\n        [Fact]\n        public void adding_invalid_value_to_collection_should_throw()\n        {\n            var client = new Client()\n            {\n                AllowedGrantTypes = { \"implicit\" }\n            };\n\n            Action act = () => client.AllowedGrantTypes.Add(\"authorization_code\");\n\n            act.Should().Throw<InvalidOperationException>();\n        }\n\n        [Fact]\n        public void adding_valid_value_to_collection_should_succeed()\n        {\n            var client = new Client()\n            {\n                AllowedGrantTypes = { \"implicit\" }\n            };\n\n            client.AllowedGrantTypes.Add(\"custom\");\n\n            client.AllowedGrantTypes.Count.Should().Be(2);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/IdentityTokenValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.IdentityModel.Tokens.Jwt;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class IdentityTokenValidation\n    {\n        private const string Category = \"Identity token validation\";\n\n        static IdentityTokenValidation()\n        {\n            JwtSecurityTokenHandler.DefaultInboundClaimTypeMap.Clear();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_IdentityToken_DefaultKeyType()\n        {\n            var creator = Factory.CreateDefaultTokenCreator();\n            var token = TokenFactory.CreateIdentityToken(\"roclient\", \"valid\");\n            var jwt = await creator.CreateTokenAsync(token);\n\n            var validator = Factory.CreateTokenValidator();\n            var result = await validator.ValidateIdentityTokenAsync(jwt, \"roclient\");\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_IdentityToken_DefaultKeyType_no_ClientId_supplied()\n        {\n            var creator = Factory.CreateDefaultTokenCreator();\n            var jwt = await creator.CreateTokenAsync(TokenFactory.CreateIdentityToken(\"roclient\", \"valid\"));\n            var validator = Factory.CreateTokenValidator();\n\n            var result = await validator.ValidateIdentityTokenAsync(jwt, \"roclient\");\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_IdentityToken_no_ClientId_supplied()\n        {\n            var creator = Factory.CreateDefaultTokenCreator();\n            var jwt = await creator.CreateTokenAsync(TokenFactory.CreateIdentityToken(\"roclient\", \"valid\"));\n            var validator = Factory.CreateTokenValidator();\n\n            var result = await validator.ValidateIdentityTokenAsync(jwt);\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task IdentityToken_InvalidClientId()\n        {\n            var creator = Factory.CreateDefaultTokenCreator();\n            var jwt = await creator.CreateTokenAsync(TokenFactory.CreateIdentityToken(\"roclient\", \"valid\"));\n            var validator = Factory.CreateTokenValidator();\n\n            var result = await validator.ValidateIdentityTokenAsync(jwt, \"invalid\");\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task IdentityToken_Too_Long()\n        {\n            var creator = Factory.CreateDefaultTokenCreator();\n            var jwt = await creator.CreateTokenAsync(TokenFactory.CreateIdentityTokenLong(\"roclient\", \"valid\", 1000));\n            var validator = Factory.CreateTokenValidator();\n\n            var result = await validator.ValidateIdentityTokenAsync(jwt, \"roclient\");\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/IntrospectionRequestValidatorTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Specialized;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class IntrospectionRequestValidatorTests\n    {\n        private const string Category = \"Introspection request validation\";\n\n        private IntrospectionRequestValidator _subject;\n        private IReferenceTokenStore _referenceTokenStore;\n\n        public IntrospectionRequestValidatorTests()\n        {\n            _referenceTokenStore = Factory.CreateReferenceTokenStore();\n            var tokenValidator = Factory.CreateTokenValidator(_referenceTokenStore);\n\n            _subject = new IntrospectionRequestValidator(tokenValidator, TestLogger.Create<IntrospectionRequestValidator>());\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task valid_token_should_successfully_validate()\n        {\n            var token = new Token {\n                CreationTime = DateTime.UtcNow,\n                Issuer = \"http://op\",\n                ClientId = \"codeclient\",\n                Lifetime = 1000,\n                Claims =\n                {\n                    new System.Security.Claims.Claim(\"scope\", \"a\"),\n                    new System.Security.Claims.Claim(\"scope\", \"b\")\n                }\n            };\n            var handle = await _referenceTokenStore.StoreReferenceTokenAsync(token);\n            \n            var param = new NameValueCollection()\n            {\n                { \"token\", handle}\n            };\n\n            var result = await _subject.ValidateAsync(param, null);\n\n            result.IsError.Should().Be(false);\n            result.IsActive.Should().Be(true);\n            result.Claims.Count().Should().Be(5);\n            result.Token.Should().Be(handle);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task missing_token_should_error()\n        {\n            var param = new NameValueCollection();\n            \n            var result = await _subject.ValidateAsync(param, null);\n\n            result.IsError.Should().Be(true);\n            result.Error.Should().Be(\"missing_token\");\n            result.IsActive.Should().Be(false);\n            result.Claims.Should().BeNull();\n            result.Token.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task invalid_token_should_return_inactive()\n        {\n            var param = new NameValueCollection()\n            {\n                { \"token\", \"invalid\" }\n            };\n\n            var result = await _subject.ValidateAsync(param, null);\n\n            result.IsError.Should().Be(false);\n            result.IsActive.Should().Be(false);\n            result.Claims.Should().BeNull();\n            result.Token.Should().Be(\"invalid\");\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/ResourceValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Extensions;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class ResourceValidation\n    {\n        private const string Category = \"Resource Validation\";\n\n        private List<IdentityResource> _identityResources = new List<IdentityResource>\n        {\n            new IdentityResource\n            {\n                Name = \"openid\",\n                Required = true\n            },\n            new IdentityResource\n            {\n                Name = \"email\"\n            }\n        };\n\n        private List<ApiResource> _apiResources = new List<ApiResource>\n        {\n            new ApiResource\n            {\n                Name = \"api\",\n                Scopes = { \"resource1\", \"resource2\" }\n            },\n            new ApiResource\n            {\n                Name = \"disabled_api\",\n                Enabled = false,\n                Scopes = { \"disabled\" }\n            }\n        };\n\n        private List<ApiScope> _scopes = new List<ApiScope> {\n            new ApiScope\n            {\n                Name = \"resource1\",\n                Required = true\n            },\n            new ApiScope\n            {\n                Name = \"resource2\"\n            }\n        };\n\n        private Client _restrictedClient = new Client\n        {\n            ClientId = \"restricted\",\n\n            AllowedScopes = new List<string>\n                {\n                    \"openid\",\n                    \"resource1\",\n                    \"disabled\"\n                }\n        };\n\n        private IResourceStore _store;\n\n        public ResourceValidation()\n        {\n            _store = new InMemoryResourcesStore(_identityResources, _apiResources, _scopes);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void Parse_Scopes_with_Empty_Scope_List()\n        {\n            var scopes = string.Empty.ParseScopesString();\n\n            scopes.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void Parse_Scopes_with_Sorting()\n        {\n            var scopes = \"scope3 scope2 scope1\".ParseScopesString();\n\n            scopes.Count.Should().Be(3);\n\n            scopes[0].Should().Be(\"scope1\");\n            scopes[1].Should().Be(\"scope2\");\n            scopes[2].Should().Be(\"scope3\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void Parse_Scopes_with_Extra_Spaces()\n        {\n            var scopes = \"   scope3     scope2     scope1   \".ParseScopesString();\n\n            scopes.Count.Should().Be(3);\n\n            scopes[0].Should().Be(\"scope1\");\n            scopes[1].Should().Be(\"scope2\");\n            scopes[2].Should().Be(\"scope3\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void Parse_Scopes_with_Duplicate_Scope()\n        {\n            var scopes = \"scope2 scope1 scope2\".ParseScopesString();\n\n            scopes.Count.Should().Be(2);\n\n            scopes[0].Should().Be(\"scope1\");\n            scopes[1].Should().Be(\"scope2\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Only_Offline_Access_Requested()\n        {\n            var scopes = \"offline_access\".ParseScopesString();\n\n\n            var validator = Factory.CreateResourceValidator(_store);\n            var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n            {\n                Client = _restrictedClient,\n                Scopes = scopes\n            });\n\n            result.Succeeded.Should().BeFalse();\n            result.InvalidScopes.Should().Contain(\"offline_access\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task All_Scopes_Valid()\n        {\n            var scopes = \"openid resource1\".ParseScopesString();\n\n            var validator = Factory.CreateResourceValidator(_store);\n            var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n            {\n                Client = _restrictedClient,\n                Scopes = scopes\n            });\n\n            result.Succeeded.Should().BeTrue();\n            result.InvalidScopes.Should().BeEmpty();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Scope()\n        {\n            {\n                var scopes = \"openid email resource1 unknown\".ParseScopesString();\n\n                var validator = Factory.CreateResourceValidator(_store);\n                var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n                {\n                    Client = _restrictedClient,\n                    Scopes = scopes\n                });\n\n                result.Succeeded.Should().BeFalse();\n                result.InvalidScopes.Should().Contain(\"unknown\");\n                result.InvalidScopes.Should().Contain(\"email\");\n            }\n            {\n                var scopes = \"openid resource1 resource2\".ParseScopesString();\n\n                var validator = Factory.CreateResourceValidator(_store);\n                var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n                {\n                    Client = _restrictedClient,\n                    Scopes = scopes\n                });\n\n                result.Succeeded.Should().BeFalse();\n                result.InvalidScopes.Should().Contain(\"resource2\");\n            }\n            {\n                var scopes = \"openid email resource1\".ParseScopesString();\n\n                var validator = Factory.CreateResourceValidator(_store);\n                var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n                {\n                    Client = _restrictedClient,\n                    Scopes = scopes\n                });\n\n                result.Succeeded.Should().BeFalse();\n                result.InvalidScopes.Should().Contain(\"email\");\n            }\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Disabled_Scope()\n        {\n            var scopes = \"openid resource1 disabled\".ParseScopesString();\n\n            var validator = Factory.CreateResourceValidator(_store);\n            var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n            {\n                Client = _restrictedClient,\n                Scopes = scopes\n            });\n\n            result.Succeeded.Should().BeFalse();\n            result.InvalidScopes.Should().Contain(\"disabled\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task All_Scopes_Allowed_For_Restricted_Client()\n        {\n            var scopes = \"openid resource1\".ParseScopesString();\n\n            var validator = Factory.CreateResourceValidator(_store);\n            var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n            {\n                Client = _restrictedClient,\n                Scopes = scopes\n            });\n\n            result.Succeeded.Should().BeTrue();\n            result.InvalidScopes.Should().BeEmpty();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Restricted_Scopes()\n        {\n            var scopes = \"openid email resource1 resource2\".ParseScopesString();\n\n            var validator = Factory.CreateResourceValidator(_store);\n            var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n            {\n                Client = _restrictedClient,\n                Scopes = scopes\n            });\n\n            result.Succeeded.Should().BeFalse();\n            result.InvalidScopes.Should().Contain(\"email\");\n            result.InvalidScopes.Should().Contain(\"resource2\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Contains_Resource_and_Identity_Scopes()\n        {\n            var scopes = \"openid resource1\".ParseScopesString();\n\n            var validator = Factory.CreateResourceValidator(_store);\n            var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n            {\n                Client = _restrictedClient,\n                Scopes = scopes\n            });\n\n            result.Succeeded.Should().BeTrue();\n            result.Resources.IdentityResources.SelectMany(x => x.Name).Should().Contain(\"openid\");\n            result.Resources.ApiScopes.Select(x => x.Name).Should().Contain(\"resource1\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Contains_Resource_Scopes_Only()\n        {\n            var scopes = \"resource1\".ParseScopesString();\n\n            var validator = Factory.CreateResourceValidator(_store);\n            var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n            {\n                Client = _restrictedClient,\n                Scopes = scopes\n            });\n\n            result.Succeeded.Should().BeTrue();\n            result.Resources.IdentityResources.Should().BeEmpty();\n            result.Resources.ApiScopes.Select(x => x.Name).Should().Contain(\"resource1\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Contains_Identity_Scopes_Only()\n        {\n            var scopes = \"openid\".ParseScopesString();\n\n            var validator = Factory.CreateResourceValidator(_store);\n            var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n            {\n                Client = _restrictedClient,\n                Scopes = scopes\n            });\n\n            result.Succeeded.Should().BeTrue();\n            result.Resources.IdentityResources.SelectMany(x => x.Name).Should().Contain(\"openid\");\n            result.Resources.ApiResources.Should().BeEmpty();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Scope_matches_multipls_apis_should_succeed()\n        {\n            _apiResources.Clear();\n            _apiResources.Add(new ApiResource { Name = \"api1\", Scopes = { \"resource\" } });\n            _apiResources.Add(new ApiResource { Name = \"api2\", Scopes = { \"resource\" } });\n            _scopes.Clear();\n            _scopes.Add(new ApiScope(\"resource\"));\n\n            var validator = Factory.CreateResourceValidator(_store);\n            var result = await validator.ValidateRequestedResourcesAsync(new IdentityServer8.Validation.ResourceValidationRequest\n            {\n                Client = new Client { AllowedScopes = { \"resource\" } },\n                Scopes = new[] { \"resource\" }\n            });\n\n            result.Succeeded.Should().BeTrue();\n            result.Resources.ApiResources.Count.Should().Be(2);\n            result.Resources.ApiResources.Select(x => x.Name).Should().BeEquivalentTo(new[] { \"api1\", \"api2\" });\n            result.RawScopeValues.Count().Should().Be(1);\n            result.RawScopeValues.Should().BeEquivalentTo(new[] { \"resource\" });\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/ResponseTypeEqualityComparison.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    /// <summary>\n    /// Tests for ResponseTypeEqualityComparer\n    /// </summary>\n    /// <remarks>\n    /// Some of these are pretty fundamental equality checks, but the purpose here is to ensure the\n    /// important property: that the order is insignificant when multiple values are\n    /// sent in a space-delimited string.  We want to ensure that property holds and at the same time\n    /// the basic equality function works as well.\n    /// </remarks>\n    public class ResponseTypeEqualityComparison\n    {\n        /// <summary>\n        /// These tests ensure that single-value strings compare with the\n        /// same behavior as default string comparisons.\n        /// </summary>\n        public class SingleValueStringComparisons\n        {\n            [Fact]\n            public void Both_null()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = null;\n                string y = null;\n                var result = comparer.Equals(x, y);\n                var expected = (x == y);\n                result.Should().Be(expected);\n            }\n\n            [Fact]\n            public void Left_null_other_not()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = null;\n                string y = string.Empty;\n                var result = comparer.Equals(x, y);\n                var expected = (x == y);\n                result.Should().Be(expected);\n            }\n\n            [Fact]\n            public void Right_null_other_not()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = string.Empty;\n                string y = null;\n                var result = comparer.Equals(x, y);\n                var expected = (x == y);\n                result.Should().Be(expected);\n            }\n\n            [Fact]\n            public void token_token()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"token\";\n                string y = \"token\";\n                var result = comparer.Equals(x, y);\n                var expected = (x == y);\n                result.Should().Be(expected);\n            }\n\n            [Fact]\n            public void id_token_id_token()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"id_token\";\n                string y = \"id_token\";\n                var result = comparer.Equals(x, y);\n                var expected = (x == y);\n                result.Should().Be(expected);\n            }\n\n            [Fact]\n            public void id_token_token()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"id_token\";\n                string y = \"token\";\n                var result = comparer.Equals(x, y);\n                var expected = (x == y);\n                result.Should().Be(expected);\n            }\n        }\n\n        /// <summary>\n        /// These tests ensure the property demanded by the \n        /// <see href=\"https://tools.ietf.org/html/rfc6749#section-3.1.1\">OAuth2 spec</see>\n        /// where, in a space-delimited list of values, the order is not important.\n        /// </summary>\n        public class MultipleValueStringComparisons\n        {\n            [Fact]\n            public void id_token_token_both_ways()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"id_token token\";\n                string y = \"token id_token\";\n                var result = comparer.Equals(x, y);\n                result.Should().BeTrue();\n            }\n\n            [Fact]\n            public void code_id_token_both_ways()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"code id_token\";\n                string y = \"id_token code\";\n                var result = comparer.Equals(x, y);\n                result.Should().BeTrue();\n            }\n\n            [Fact]\n            public void code_token_both_ways()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"code token\";\n                string y = \"token code\";\n                var result = comparer.Equals(x, y);\n                result.Should().BeTrue();\n            }\n\n            [Fact]\n            public void code_id_token_token_combo1()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"code id_token token\";\n                string y = \"id_token code token\";\n                var result = comparer.Equals(x, y);\n                result.Should().BeTrue();\n            }\n\n            [Fact]\n            public void code_id_token_token_combo2()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"code id_token token\";\n                string y = \"token id_token code\";\n                var result = comparer.Equals(x, y);\n                result.Should().BeTrue();\n            }\n\n            [Fact]\n            public void code_id_token_token_missing_code()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"code id_token token\";\n                string y = \"id_token token\";\n                var result = comparer.Equals(x, y);\n                result.Should().BeFalse();\n            }\n\n            [Fact]\n            public void code_id_token_token_missing_code_and_token()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"code id_token token\";\n                string y = \"id_token\";\n                var result = comparer.Equals(x, y);\n                result.Should().BeFalse();\n            }\n\n            [Fact]\n            public void Totally_different_words()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"blerg smoo\";\n                string y = \"token code\";\n                var result = comparer.Equals(x, y);\n                result.Should().BeFalse();\n            }\n\n            [Fact]\n            public void Same_length_different_count()\n            {\n                ResponseTypeEqualityComparer comparer = new ResponseTypeEqualityComparer();\n                string x = \"code id_token token\";\n                string y = \"tokenizer bleegerfi\";\n                var result = comparer.Equals(x, y);\n                result.Should().BeFalse();\n            }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/RevocationRequestValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class RevocationRequestValidation\n    {\n        private const string Category = \"Revocation Request Validation Tests\";\n\n        private ITokenRevocationRequestValidator _validator;\n        private Client _client;\n\n        public RevocationRequestValidation()\n        {\n            _validator = new TokenRevocationRequestValidator(TestLogger.Create<TokenRevocationRequestValidator>());\n            _client = new Client\n            {\n                ClientName = \"Code Client\",\n                Enabled = true,\n                ClientId = \"codeclient\",\n                ClientSecrets = new List<Secret>\n                {\n                    new Secret(\"secret\".Sha256())\n                },\n\n                AllowedGrantTypes = GrantTypes.Code,\n\n                RequireConsent = false,\n\n                RedirectUris = new List<string>\n                {\n                    \"https://server/cb\"\n                },\n\n                AuthorizationCodeLifetime = 60\n            };\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Empty_Parameters()\n        {\n            var parameters = new NameValueCollection();\n\n            var result = await _validator.ValidateRequestAsync(parameters, _client);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_Token_Valid_Hint()\n        {\n            var parameters = new NameValueCollection\n            {\n                { \"token_type_hint\", \"access_token\" }\n            };\n\n            var result = await _validator.ValidateRequestAsync(parameters, _client);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidRequest);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Token_And_AccessTokenHint()\n        {\n            var parameters = new NameValueCollection\n            {\n                { \"token\", \"foo\" },\n                { \"token_type_hint\", \"access_token\" }\n            };\n\n            var result = await _validator.ValidateRequestAsync(parameters, _client);\n\n            result.IsError.Should().BeFalse();\n            result.Token.Should().Be(\"foo\");\n            result.TokenTypeHint.Should().Be(\"access_token\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Token_and_RefreshTokenHint()\n        {\n            var parameters = new NameValueCollection\n            {\n                { \"token\", \"foo\" },\n                { \"token_type_hint\", \"refresh_token\" }\n            };\n\n            var result = await _validator.ValidateRequestAsync(parameters, _client);\n\n            result.IsError.Should().BeFalse();\n            result.Token.Should().Be(\"foo\");\n            result.TokenTypeHint.Should().Be(\"refresh_token\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Token_And_Missing_Hint()\n        {\n            var parameters = new NameValueCollection\n            {\n                { \"token\", \"foo\" }\n            };\n\n            var result = await _validator.ValidateRequestAsync(parameters, _client);\n\n            result.IsError.Should().BeFalse();\n            result.Token.Should().Be(\"foo\");\n            result.TokenTypeHint.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Token_And_Invalid_Hint()\n        {\n            var parameters = new NameValueCollection\n            {\n                { \"token\", \"foo\" },\n                { \"token_type_hint\", \"invalid\" }\n            };\n\n            var result = await _validator.ValidateRequestAsync(parameters, _client);\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(Constants.RevocationErrors.UnsupportedTokenType);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Secrets/BasicAuthenticationCredentialParsing.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Text;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.Extensions.Primitives;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.Secrets\n{\n    public class BasicAuthenticationSecretParsing\n    {\n        private const string Category = \"Secrets - Basic Authentication Secret Parsing\";\n\n        private IdentityServerOptions _options;\n        private BasicAuthenticationSecretParser _parser;\n\n        public BasicAuthenticationSecretParsing()\n        {\n            _options = new IdentityServerOptions();\n            _parser = new BasicAuthenticationSecretParser(_options, TestLogger.Create<BasicAuthenticationSecretParser>());\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void EmptyContext()\n        {\n            var context = new DefaultHttpContext();\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void Valid_BasicAuthentication_Request()\n        {\n            var context = new DefaultHttpContext();\n\n            var headerValue = string.Format(\"Basic {0}\",\n                Convert.ToBase64String(Encoding.UTF8.GetBytes(\"client:secret\")));\n            context.Request.Headers.Append(\"Authorization\", new StringValues(headerValue));\n\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Type.Should().Be(IdentityServerConstants.ParsedSecretTypes.SharedSecret);\n            secret.Id.Should().Be(\"client\");\n            secret.Credential.Should().Be(\"secret\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void Valid_BasicAuthentication_Request_With_UserName_Only_And_Colon_For_Optional_ClientSecret()\n        {\n            var context = new DefaultHttpContext();\n\n            var headerValue = string.Format(\"Basic {0}\",\n                Convert.ToBase64String(Encoding.UTF8.GetBytes(\"client:\")));\n            context.Request.Headers.Append(\"Authorization\", new StringValues(headerValue));\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Type.Should().Be(IdentityServerConstants.ParsedSecretTypes.NoSecret);\n            secret.Id.Should().Be(\"client\");\n            secret.Credential.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void BasicAuthentication_Request_With_Empty_Basic_Header()\n        {\n            var context = new DefaultHttpContext();\n\n            context.Request.Headers.Append(\"Authorization\", new StringValues(string.Empty));\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void Valid_BasicAuthentication_Request_ClientId_Too_Long()\n        {\n            var context = new DefaultHttpContext();\n\n            var longClientId = \"x\".Repeat(_options.InputLengthRestrictions.ClientId + 1);\n            var credential = string.Format(\"{0}:secret\", longClientId);\n\n            var headerValue = string.Format(\"Basic {0}\",\n                Convert.ToBase64String(Encoding.UTF8.GetBytes(credential)));\n            context.Request.Headers.Append(\"Authorization\", new StringValues(headerValue));\n\n            var secret = await _parser.ParseAsync(context);\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void Valid_BasicAuthentication_Request_ClientSecret_Too_Long()\n        {\n            var context = new DefaultHttpContext();\n\n            var longClientSecret = \"x\".Repeat(_options.InputLengthRestrictions.ClientSecret + 1);\n            var credential = string.Format(\"client:{0}\", longClientSecret);\n\n            var headerValue = string.Format(\"Basic {0}\",\n                Convert.ToBase64String(Encoding.UTF8.GetBytes(credential)));\n            context.Request.Headers.Append(\"Authorization\", new StringValues(headerValue));\n\n            var secret = await _parser.ParseAsync(context);\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void BasicAuthentication_Request_With_Empty_Basic_Header_Variation()\n        {\n            var context = new DefaultHttpContext();\n\n            context.Request.Headers.Append(\"Authorization\", new StringValues(\"Basic \"));\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void BasicAuthentication_Request_With_Unknown_Scheme()\n        {\n            var context = new DefaultHttpContext();\n\n            context.Request.Headers.Append(\"Authorization\", new StringValues(\"Unknown\"));\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void BasicAuthentication_Request_With_Malformed_Credentials_NoBase64_Encoding()\n        {\n            var context = new DefaultHttpContext();\n\n            context.Request.Headers.Append(\"Authorization\", new StringValues(\"Basic somerandomdata\"));\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void BasicAuthentication_Request_With_Malformed_Credentials_Base64_Encoding_UserName_Only()\n        {\n            var context = new DefaultHttpContext();\n\n            var headerValue = string.Format(\"Basic {0}\",\n                Convert.ToBase64String(Encoding.UTF8.GetBytes(\"client\")));\n            context.Request.Headers.Append(\"Authorization\", new StringValues(headerValue));\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Secrets/ClientAssertionSecretParsing.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.IdentityModel.Tokens.Jwt;\nusing System.IO;\nusing System.Security.Claims;\nusing System.Text;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.Extensions.Logging;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.Secrets\n{\n    public class ClientAssertionSecretParsing\n    {\n        private IdentityServerOptions _options;\n        private JwtBearerClientAssertionSecretParser _parser;\n\n        public ClientAssertionSecretParsing()\n        {\n            _options = new IdentityServerOptions();\n            _parser = new JwtBearerClientAssertionSecretParser(_options, new LoggerFactory().CreateLogger<JwtBearerClientAssertionSecretParser>());\n        }\n\n        [Fact]\n        public async void EmptyContext()\n        {\n            var context = new DefaultHttpContext();\n            context.Request.Body = new MemoryStream();\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        public async void Valid_ClientAssertion()\n        {\n            var context = new DefaultHttpContext();\n\n            var token = new JwtSecurityToken(issuer: \"issuer\", claims: new[] { new Claim(\"sub\", \"client\") });\n            var tokenString = new JwtSecurityTokenHandler().WriteToken(token);\n\n            var body = \"client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer&client_assertion=\" + tokenString;\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().NotBeNull();\n            secret.Type.Should().Be(IdentityServerConstants.ParsedSecretTypes.JwtBearer);\n            secret.Id.Should().Be(\"client\");\n            secret.Credential.Should().Be(tokenString);\n        }\n\n        [Fact]\n        public async void Missing_ClientAssertionType()\n        {\n            var context = new DefaultHttpContext();\n\n            var body = \"client_id=client&client_assertion=token\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        public async void Missing_ClientAssertion()\n        {\n            var context = new DefaultHttpContext();\n\n            var body = \"client_id=client&client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        public async void Malformed_PostBody()\n        {\n            var context = new DefaultHttpContext();\n            var body = \"malformed\";\n            \n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        public async void ClientId_TooLong()\n        {\n            var context = new DefaultHttpContext();\n\n            var longClientId = \"x\".Repeat(_options.InputLengthRestrictions.ClientId + 1);\n            var body = $\"client_id={longClientId}&client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer&client_assertion=token\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        public async void ClientAssertion_TooLong()\n        {\n            var context = new DefaultHttpContext();\n\n            var longToken = \"x\".Repeat(_options.InputLengthRestrictions.Jwt + 1);\n            var body = $\"client_id=client&client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer&client_assertion={longToken}\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Secrets/ClientSecretValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.IO;\nusing System.Text;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing Microsoft.AspNetCore.Http;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.Secrets\n{\n    public class ClientSecretValidation\n    {\n        private const string Category = \"Secrets - Client Secret Validator\";\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task confidential_client_with_correct_secret_should_be_able_to_request_token()\n        {\n            var validator = Factory.CreateClientSecretValidator();\n\n            var context = new DefaultHttpContext();\n            var body = \"client_id=roclient&client_secret=secret\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var result = await validator.ValidateAsync(context);\n\n            result.IsError.Should().BeFalse();\n            result.Client.ClientId.Should().Be(\"roclient\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task confidential_client_with_incorrect_secret_should_not_be_able_to_request_token()\n        {\n            var validator = Factory.CreateClientSecretValidator();\n\n            var context = new DefaultHttpContext();\n            var body = \"client_id=roclient&client_secret=invalid\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var result = await validator.ValidateAsync(context);\n\n            result.IsError.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task public_client_without_secret_should_be_able_to_request_token()\n        {\n            var validator = Factory.CreateClientSecretValidator();\n\n            var context = new DefaultHttpContext();\n            var body = \"client_id=roclient.public\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var result = await validator.ValidateAsync(context);\n\n            result.IsError.Should().BeFalse();\n            result.Client.ClientId.Should().Be(\"roclient.public\");\n            result.Client.RequireClientSecret.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task implicit_client_without_secret_should_be_able_to_authenticate()\n        {\n            var validator = Factory.CreateClientSecretValidator();\n\n            var context = new DefaultHttpContext();\n            var body = \"client_id=client.implicit\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var result = await validator.ValidateAsync(context);\n\n            result.IsError.Should().BeFalse();\n            result.Client.ClientId.Should().Be(\"client.implicit\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task implicit_client_and_client_creds_without_secret_should_not_be_able_to_authenticate()\n        {\n            var validator = Factory.CreateClientSecretValidator();\n\n            var context = new DefaultHttpContext();\n            var body = \"client_id=implicit_and_client_creds\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var result = await validator.ValidateAsync(context);\n\n            result.IsError.Should().BeTrue();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Secrets/FormPostCredentialParsing.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.IO;\nusing System.Text;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Http;\nusing Microsoft.Extensions.Logging;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.Secrets\n{\n    public class FormPostCredentialExtraction\n    {\n        private const string Category = \"Secrets - Form Post Secret Parsing\";\n\n        private IdentityServerOptions _options;\n        private PostBodySecretParser _parser;\n\n        public FormPostCredentialExtraction()\n        {\n            _options = new IdentityServerOptions();\n            _parser = new PostBodySecretParser(_options, new LoggerFactory().CreateLogger<PostBodySecretParser>());\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void EmptyContext()\n        {\n            var context = new DefaultHttpContext();\n            context.Request.Body = new MemoryStream();\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void Valid_PostBody()\n        {\n            var context = new DefaultHttpContext();\n\n            var body = \"client_id=client&client_secret=secret\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Type.Should().Be(IdentityServerConstants.ParsedSecretTypes.SharedSecret);\n            secret.Id.Should().Be(\"client\");\n            secret.Credential.Should().Be(\"secret\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void ClientId_Too_Long()\n        {\n            var context = new DefaultHttpContext();\n\n            var longClientId = \"x\".Repeat(_options.InputLengthRestrictions.ClientId + 1);\n            var body = string.Format(\"client_id={0}&client_secret=secret\", longClientId);\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void ClientSecret_Too_Long()\n        {\n            var context = new DefaultHttpContext();\n\n            var longClientSecret = \"x\".Repeat(_options.InputLengthRestrictions.ClientSecret + 1);\n            var body = string.Format(\"client_id=client&client_secret={0}\", longClientSecret);\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void Missing_ClientId()\n        {\n            var context = new DefaultHttpContext();\n\n            var body = \"client_secret=secret\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void Missing_ClientSecret()\n        {\n            var context = new DefaultHttpContext();\n\n            var body = \"client_id=client\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().NotBeNull();\n            secret.Type.Should().Be(IdentityServerConstants.ParsedSecretTypes.NoSecret);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async void Malformed_PostBody()\n        {\n            var context = new DefaultHttpContext();\n\n            var body = \"malformed\";\n\n            context.Request.Body = new MemoryStream(Encoding.UTF8.GetBytes(body));\n            context.Request.ContentType = \"application/x-www-form-urlencoded\";\n\n            var secret = await _parser.ParseAsync(context);\n\n            secret.Should().BeNull();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Secrets/HashedSharedSecretValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing Microsoft.Extensions.Logging;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.Secrets\n{\n    public class HashedSharedSecretValidation\n    {\n        private const string Category = \"Secrets - Hashed Shared Secret Validation\";\n\n        private ISecretValidator _validator = new HashedSharedSecretValidator(new Logger<HashedSharedSecretValidator>(new LoggerFactory()));\n        private IClientStore _clients = new InMemoryClientStore(ClientValidationTestClients.Get());\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Single_Secret()\n        {\n            var clientId = \"single_secret_hashed_no_expiration\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Credential_Type()\n        {\n            var clientId = \"single_secret_hashed_no_expiration\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = \"invalid\"\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Multiple_Secrets()\n        {\n            var clientId = \"multiple_secrets_hashed\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n\n            secret.Credential = \"foobar\";\n            result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n\n            secret.Credential = \"quux\";\n            result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n\n            secret.Credential = \"notexpired\";\n            result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Single_Secret()\n        {\n            var clientId = \"single_secret_hashed_no_expiration\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"invalid\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Multiple_Secrets()\n        {\n            var clientId = \"multiple_secrets_hashed\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"invalid\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Client_with_no_Secret_Should_Fail()\n        {\n            var clientId = \"no_secret_client\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Client_with_null_Secret_Should_Fail()\n        {\n            var clientId = \"null_secret_client\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret,\n                Credential = \"secret\"\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Secrets/MutualTlsSecretValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing Microsoft.Extensions.Logging;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.Secrets\n{\n    public class MutualTlsSecretValidation\n    {\n        private const string Category = \"Secrets - MutualTls Secret Validation\";\n\n        private IClientStore _clients = new InMemoryClientStore(ClientValidationTestClients.Get());\n\n        ///////////////////\n        // thumbprints\n        ///////////////////\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Thumbprint_invalid_secret_type_should_not_match()\n        {\n            ISecretValidator validator = new X509ThumbprintSecretValidator(new Logger<X509ThumbprintSecretValidator>(new LoggerFactory()));\n\n            var clientId = \"mtls_client_invalid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Thumbprint_missing_cert_should_throw()\n        {\n            ISecretValidator validator = new X509ThumbprintSecretValidator(new Logger<X509ThumbprintSecretValidator>(new LoggerFactory()));\n\n            var clientId = \"mtls_client_invalid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = IdentityServerConstants.ParsedSecretTypes.X509Certificate\n            };\n\n            Func<Task> act = async () => await validator.ValidateAsync(client.ClientSecrets, secret);\n            await act.Should().ThrowAsync<InvalidOperationException>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Thumbprint_invalid_secret_should_not_match()\n        {\n            ISecretValidator validator = new X509ThumbprintSecretValidator(new Logger<X509ThumbprintSecretValidator>(new LoggerFactory()));\n\n            var clientId = \"mtls_client_invalid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = TestCert.Load(),\n                Type = IdentityServerConstants.ParsedSecretTypes.X509Certificate\n            };\n\n            var result = await validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Thumbprint_valid_secret_should_match()\n        {\n            ISecretValidator validator = new X509ThumbprintSecretValidator(new Logger<X509ThumbprintSecretValidator>(new LoggerFactory()));\n\n            var clientId = \"mtls_client_valid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = TestCert.Load(),\n                Type = IdentityServerConstants.ParsedSecretTypes.X509Certificate\n            };\n\n            var result = await validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeTrue();\n        }\n\n        ///////////////////\n        // names\n        ///////////////////\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Name_invalid_secret_type_should_not_match()\n        {\n            ISecretValidator validator = new X509NameSecretValidator(new Logger<X509NameSecretValidator>(new LoggerFactory()));\n\n            var clientId = \"mtls_client_invalid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Name_missing_cert_should_throw()\n        {\n            ISecretValidator validator = new X509NameSecretValidator(new Logger<X509NameSecretValidator>(new LoggerFactory()));\n\n            var clientId = \"mtls_client_invalid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = IdentityServerConstants.ParsedSecretTypes.X509Certificate\n            };\n\n            Func<Task> act = async () => await validator.ValidateAsync(client.ClientSecrets, secret);\n            await act.Should().ThrowAsync<InvalidOperationException>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Name_invalid_secret_should_not_match()\n        {\n            ISecretValidator validator = new X509NameSecretValidator(new Logger<X509NameSecretValidator>(new LoggerFactory()));\n\n            var clientId = \"mtls_client_invalid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = TestCert.Load(),\n                Type = IdentityServerConstants.ParsedSecretTypes.X509Certificate\n            };\n\n            var result = await validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Name_valid_secret_should_match()\n        {\n            ISecretValidator validator = new X509NameSecretValidator(new Logger<X509NameSecretValidator>(new LoggerFactory()));\n\n            var clientId = \"mtls_client_valid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = TestCert.Load(),\n                Type = IdentityServerConstants.ParsedSecretTypes.X509Certificate\n            };\n\n            var result = await validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeTrue();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Secrets/PlainTextClientSecretValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing Microsoft.Extensions.Logging;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.Secrets\n{\n    public class PlainTextClientSecretValidation\n    {\n        private const string Category = \"Secrets - PlainText Shared Secret Validation\";\n\n        private ISecretValidator _validator = new PlainTextSharedSecretValidator(new Logger<PlainTextSharedSecretValidator>(new LoggerFactory()));\n        private IClientStore _clients = new InMemoryClientStore(ClientValidationTestClients.Get());\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Single_Secret()\n        {\n            var clientId = \"single_secret_no_protection_no_expiration\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Credential_Type()\n        {\n            var clientId = \"single_secret_no_protection_no_expiration\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = \"invalid\"\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Multiple_Secrets_No_Protection()\n        {\n            var clientId = \"multiple_secrets_no_protection\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n\n            secret.Credential = \"foobar\";\n            result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n\n            secret.Credential = \"quux\";\n            result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n\n            secret.Credential = \"notexpired\";\n            result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Single_Secret()\n        {\n            var clientId = \"single_secret_no_protection_no_expiration\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"invalid\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Multiple_Secrets()\n        {\n            var clientId = \"multiple_secrets_no_protection\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"invalid\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Client_with_no_Secret_Should_Fail()\n        {\n            var clientId = \"no_secret_client\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Client_with_null_Secret_Should_Fail()\n        {\n            var clientId = \"null_secret_client\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret,\n                Credential = \"secret\"\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Secrets/PrivateKeyJwtSecretValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.IdentityModel.Tokens.Jwt;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Services.Default;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing Microsoft.Extensions.Logging;\nusing Microsoft.IdentityModel.Tokens;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.Secrets\n{\n    public class PrivateKeyJwtSecretValidation\n    {\n        private readonly ISecretValidator _validator;\n        private readonly IClientStore _clients;\n\n        public PrivateKeyJwtSecretValidation()\n        {\n            _validator = new PrivateKeyJwtSecretValidator(\n                new MockHttpContextAccessor(\n                    new IdentityServerOptions()\n                        {\n                            IssuerUri = \"https://idsrv3.com\"\n                        }\n                    ),\n                    new DefaultReplayCache(new TestCache()), \n                    new LoggerFactory().CreateLogger<PrivateKeyJwtSecretValidator>()\n                );\n            _clients = new InMemoryClientStore(ClientValidationTestClients.Get());\n        }\n\n        private JwtSecurityToken CreateToken(string clientId, DateTime? nowOverride = null)\n        {\n            var certificate = TestCert.Load();\n            var now = nowOverride ?? DateTime.UtcNow;\n\n            var token = new JwtSecurityToken(\n                    clientId,\n                    \"https://idsrv3.com/connect/token\",\n                    new List<Claim>()\n                    {\n                        new Claim(\"jti\", Guid.NewGuid().ToString()),\n                        new Claim(JwtClaimTypes.Subject, clientId),\n                        new Claim(JwtClaimTypes.IssuedAt, new DateTimeOffset(now).ToUnixTimeSeconds().ToString(), ClaimValueTypes.Integer64)\n                    },\n                    now,\n                    now.AddMinutes(1),\n                    new SigningCredentials(\n                        new X509SecurityKey(certificate),\n                        SecurityAlgorithms.RsaSha256\n                    )\n                );\n            return token;\n        }\n\n        [Fact]\n        public async Task Invalid_Certificate_X5t_Only_Requires_Full_Certificate()\n        {\n            var clientId = \"certificate_valid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var token = CreateToken(clientId);\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = new JwtSecurityTokenHandler().WriteToken(token),\n                Type = IdentityServerConstants.ParsedSecretTypes.JwtBearer\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Invalid_Certificate_Thumbprint()\n        {\n            var clientId = \"certificate_invalid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = new JwtSecurityTokenHandler().WriteToken(CreateToken(clientId)),\n                Type = IdentityServerConstants.ParsedSecretTypes.JwtBearer\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Valid_Certificate_Base64()\n        {\n            var clientId = \"certificate_base64_valid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = new JwtSecurityTokenHandler().WriteToken(CreateToken(clientId)),\n                Type = IdentityServerConstants.ParsedSecretTypes.JwtBearer\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeTrue();\n        }\n        \n        [Fact]\n        public async Task Invalid_Replay()\n        {\n            var clientId = \"certificate_base64_valid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n            var token = new JwtSecurityTokenHandler().WriteToken(CreateToken(clientId));\n            \n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = token,\n                Type = IdentityServerConstants.ParsedSecretTypes.JwtBearer\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n            \n            result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Invalid_Certificate_Base64()\n        {\n            var clientId = \"certificate_base64_invalid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = new JwtSecurityTokenHandler().WriteToken(CreateToken(clientId)),\n                Type = IdentityServerConstants.ParsedSecretTypes.JwtBearer\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Invalid_Issuer()\n        {\n            var clientId = \"certificate_valid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var token = CreateToken(clientId);\n            token.Payload.Remove(JwtClaimTypes.Issuer);\n            token.Payload.Add(JwtClaimTypes.Issuer, \"invalid\");\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = new JwtSecurityTokenHandler().WriteToken(token),\n                Type = IdentityServerConstants.ParsedSecretTypes.JwtBearer\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Invalid_Subject()\n        {\n            var clientId = \"certificate_valid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var token = CreateToken(clientId);\n            token.Payload.Remove(JwtClaimTypes.Subject);\n            token.Payload.Add(JwtClaimTypes.Subject, \"invalid\");\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = new JwtSecurityTokenHandler().WriteToken(token),\n                Type = IdentityServerConstants.ParsedSecretTypes.JwtBearer\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Invalid_Expired_Token()\n        {\n            var clientId = \"certificate_valid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var token = CreateToken(clientId, DateTime.UtcNow.AddHours(-1));\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = new JwtSecurityTokenHandler().WriteToken(token),\n                Type = IdentityServerConstants.ParsedSecretTypes.JwtBearer\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        public async Task Invalid_Unsigned_Token()\n        {\n            var clientId = \"certificate_valid\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var token = CreateToken(clientId);\n            token.Header.Remove(\"alg\");\n            token.Header.Add(\"alg\", \"none\");\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = new JwtSecurityTokenHandler().WriteToken(token),\n                Type = IdentityServerConstants.ParsedSecretTypes.JwtBearer\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Secrets/SecretValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing Microsoft.Extensions.Logging;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.Secrets\n{\n    public class SecretValidation\n    {\n        private const string Category = \"Secrets - Secret Validator\";\n\n        private ISecretValidator _hashedSecretValidator = new HashedSharedSecretValidator(new Logger<HashedSharedSecretValidator>(new LoggerFactory()));\n        private IClientStore _clients = new InMemoryClientStore(ClientValidationTestClients.Get());\n        private SecretValidator _validator;\n        private IdentityServerOptions _options = new IdentityServerOptions();\n\n        public SecretValidation()\n        {\n            _validator = new SecretValidator(\n                new StubClock(),\n                new[] { _hashedSecretValidator }, \n                new Logger<SecretValidator>(new LoggerFactory()));\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Single_Secret()\n        {\n            var clientId = \"single_secret_hashed_no_expiration\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Credential_Type()\n        {\n            var clientId = \"single_secret_hashed_no_expiration\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = \"invalid\"\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_Multiple_Secrets()\n        {\n            var clientId = \"multiple_secrets_hashed\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"secret\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n\n            secret.Credential = \"foobar\";\n            result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n\n            secret.Credential = \"quux\";\n            result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n\n            secret.Credential = \"notexpired\";\n            result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Single_Secret()\n        {\n            var clientId = \"single_secret_hashed_no_expiration\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"invalid\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Expired_Secret()\n        {\n            var clientId = \"multiple_secrets_hashed\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"expired\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Multiple_Secrets()\n        {\n            var clientId = \"multiple_secrets_hashed\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Credential = \"invalid\",\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n\n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Client_with_no_Secret_Should_Fail()\n        {\n            var clientId = \"no_secret_client\";\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n\n            var secret = new ParsedSecret\n            {\n                Id = clientId,\n                Type = IdentityServerConstants.ParsedSecretTypes.SharedSecret\n            };\n            \n            var result = await _validator.ValidateAsync(client.ClientSecrets, secret);\n            result.Success.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/ClientValidationTestClients.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Security.Cryptography.X509Certificates;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing static IdentityServer8.IdentityServerConstants;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    internal static class ClientValidationTestClients\n    {\n        public static List<Client> Get()\n        {\n            return new List<Client>\n            {\n                new Client\n                {\n                    ClientName = \"Disabled client\",\n                    ClientId = \"disabled_client\",\n                    Enabled = false,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret(\"secret\")\n                    }\n                },\n\n                new Client\n                {\n                    ClientName = \"Client with no secret set\",\n                    ClientId = \"no_secret_client\",\n                    Enabled = true\n                },\n\n                new Client\n                {\n                    ClientName = \"Client with null secret set\",\n                    ClientId = \"null_secret_client\",\n                    Enabled = true,\n                    ClientSecrets = { new Secret(null) }\n                },\n\n                new Client\n                {\n                    ClientName = \"Client with single secret, no protection, no expiration\",\n                    ClientId = \"single_secret_no_protection_no_expiration\",\n                    Enabled = true,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret(\"secret\")\n                    }\n                },\n\n                new Client\n                {\n                    ClientName = \"Client with X509 Certificate\",\n                    ClientId = \"certificate_valid\",\n                    Enabled = true,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret\n                        {\n                            Type = IdentityServerConstants.SecretTypes.X509CertificateThumbprint,\n                            Value = TestCert.Load().Thumbprint\n                        }\n                    }\n                },\n\n                new Client\n                {\n                    ClientName = \"Client with X509 Certificate\",\n                    ClientId = \"certificate_invalid\",\n                    Enabled = true,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret\n                        {\n                            Type = IdentityServerConstants.SecretTypes.X509CertificateThumbprint,\n                            Value = \"invalid\"\n                        }\n                    }\n                },\n\n                new Client\n                {\n                    ClientName = \"Client with Base64 encoded X509 Certificate\",\n                    ClientId = \"certificate_base64_valid\",\n                    Enabled = true,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret\n                        {\n                            Type = IdentityServerConstants.SecretTypes.X509CertificateBase64,\n                            Value = Convert.ToBase64String(TestCert.Load().Export(X509ContentType.Cert))\n                        }\n                    }\n                },\n\n                new Client\n                {\n                    ClientName = \"Client with Base64 encoded X509 Certificate\",\n                    ClientId = \"certificate_base64_invalid\",\n                    Enabled = true,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret\n                        {\n                            Type = IdentityServerConstants.SecretTypes.X509CertificateBase64,\n                            Value = \"invalid\"\n                        }\n                    }\n                },\n\n                new Client\n                {\n                    ClientName = \"Client with single secret, hashed, no expiration\",\n                    ClientId = \"single_secret_hashed_no_expiration\",\n                    Enabled = true,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        // secret\n                        new Secret(\"secret\".Sha256())\n                    }\n                },\n\n                new Client\n                {\n                    ClientName = \"Client with multiple secrets, no protection\",\n                    ClientId = \"multiple_secrets_no_protection\",\n                    Enabled = true,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret(\"secret\"),\n                        new Secret(\"foobar\", \"some description\"),\n                        new Secret(\"quux\"),\n                        new Secret(\"notexpired\", DateTime.UtcNow.AddDays(1)),\n                        new Secret(\"expired\", DateTime.UtcNow.AddDays(-1))\n                    }\n                },\n\n                new Client\n                {\n                    ClientName = \"Client with multiple secrets, hashed\",\n                    ClientId = \"multiple_secrets_hashed\",\n                    Enabled = true,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        // secret\n                        new Secret(\"secret\".Sha256()),\n                        // foobar\n                        new Secret(\"foobar\".Sha256(), \"some description\"),\n                        // quux\n                        new Secret(\"quux\".Sha512()),\n                        // notexpired\n                        new Secret(\"notexpired\".Sha256(), DateTime.UtcNow.AddDays(1)),\n                        // expired\n                        new Secret(\"expired\".Sha512(), DateTime.UtcNow.AddDays(-1))\n                    },\n                },\n\n                new Client\n                {\n                    ClientName = \"MTLS Client with invalid secrets\",\n                    ClientId = \"mtls_client_invalid\",\n                    Enabled = true,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret(@\"CN=invalid\", \"mtls.test\")\n                        {\n                            Type = SecretTypes.X509CertificateName\n                        },\n                        new Secret(\"invalid\", \"mtls.test\")\n                        {\n                            Type = SecretTypes.X509CertificateThumbprint\n                        },\n                    }\n                },\n\n                new Client\n                {\n                    ClientName = \"MTLS Client with valid secrets\",\n                    ClientId = \"mtls_client_valid\",\n                    Enabled = true,\n\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret(@\"CN=identityserver_testing\", \"mtls.test\")\n                        {\n                            Type = SecretTypes.X509CertificateName\n                        },\n                        new Secret(\"4B5FE072C7AD8A9B5DCFDD1A20608BB54DE0954F\", \"mtls.test\")\n                        {\n                            Type = SecretTypes.X509CertificateThumbprint\n                        },\n                    }\n                }\n            };\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/Factory.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Net.Http;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\nusing IdentityServer8.Services.Default;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Stores.Serialization;\nusing IdentityServer8.Validation;\nusing Microsoft.AspNetCore.Authentication;\nusing Microsoft.Extensions.Logging;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    internal static class Factory\n    {\n        public static IClientStore CreateClientStore()\n        {\n            return new InMemoryClientStore(TestClients.Get());\n        }\n\n        public static TokenRequestValidator CreateTokenRequestValidator(\n            IdentityServerOptions options = null,\n            IResourceStore resourceStore = null,\n            IAuthorizationCodeStore authorizationCodeStore = null,\n            IRefreshTokenStore refreshTokenStore = null,\n            IResourceOwnerPasswordValidator resourceOwnerValidator = null,\n            IProfileService profile = null,\n            IDeviceCodeValidator deviceCodeValidator = null,\n            IEnumerable<IExtensionGrantValidator> extensionGrantValidators = null,\n            ICustomTokenRequestValidator customRequestValidator = null,\n            ITokenValidator tokenValidator = null,\n            IRefreshTokenService refreshTokenService = null,\n            IResourceValidator resourceValidator = null)\n        {\n            if (options == null)\n            {\n                options = TestIdentityServerOptions.Create();\n            }\n\n            if (resourceStore == null)\n            {\n                resourceStore = new InMemoryResourcesStore(TestScopes.GetIdentity(), TestScopes.GetApis(), TestScopes.GetScopes());\n            }\n\n            if (resourceOwnerValidator == null)\n            {\n                resourceOwnerValidator = new TestResourceOwnerPasswordValidator();\n            }\n\n            if (profile == null)\n            {\n                profile = new TestProfileService();\n            }\n            \n            if (deviceCodeValidator == null)\n            {\n                deviceCodeValidator = new TestDeviceCodeValidator();\n            }\n\n            if (customRequestValidator == null)\n            {\n                customRequestValidator = new DefaultCustomTokenRequestValidator();\n            }\n\n            ExtensionGrantValidator aggregateExtensionGrantValidator;\n            if (extensionGrantValidators == null)\n            {\n                aggregateExtensionGrantValidator = new ExtensionGrantValidator(new[] { new TestGrantValidator() }, TestLogger.Create<ExtensionGrantValidator>());\n            }\n            else\n            {\n                aggregateExtensionGrantValidator = new ExtensionGrantValidator(extensionGrantValidators, TestLogger.Create<ExtensionGrantValidator>());\n            }\n\n            if (authorizationCodeStore == null)\n            {\n                authorizationCodeStore = CreateAuthorizationCodeStore();\n            }\n\n            if (refreshTokenStore == null)\n            {\n                refreshTokenStore = CreateRefreshTokenStore();\n            }\n\n            if (resourceValidator == null)\n            {\n                resourceValidator = CreateResourceValidator(resourceStore);\n            }\n            \n            if (tokenValidator == null)\n            {\n                tokenValidator = CreateTokenValidator(refreshTokenStore: refreshTokenStore, profile: profile);\n            }\n\n            if (refreshTokenService == null)\n            {\n                refreshTokenService = CreateRefreshTokenService(\n                    refreshTokenStore,\n                    profile);\n            }\n\n            return new TokenRequestValidator(\n                options,\n                authorizationCodeStore,\n                resourceOwnerValidator,\n                profile,\n                deviceCodeValidator,\n                aggregateExtensionGrantValidator,\n                customRequestValidator,\n                resourceValidator,\n                resourceStore,\n                tokenValidator,\n                refreshTokenService,\n                new TestEventService(), \n                new StubClock(), \n                TestLogger.Create<TokenRequestValidator>());\n        }\n\n        private static IRefreshTokenService CreateRefreshTokenService(IRefreshTokenStore store, IProfileService profile)\n        {\n            var service = new DefaultRefreshTokenService(\n                store,\n                profile,\n                new StubClock(),\n                TestLogger.Create<DefaultRefreshTokenService>());\n\n            return service;\n        }\n\n        internal static IResourceValidator CreateResourceValidator(IResourceStore store = null)\n        {\n            store = store ?? new InMemoryResourcesStore(TestScopes.GetIdentity(), TestScopes.GetApis(), TestScopes.GetScopes());\n            return new DefaultResourceValidator(store, new DefaultScopeParser(TestLogger.Create<DefaultScopeParser>()), TestLogger.Create<DefaultResourceValidator>());\n        }\n\n        internal static ITokenCreationService CreateDefaultTokenCreator(IdentityServerOptions options = null)\n        {\n            return new DefaultTokenCreationService(\n                new StubClock(),\n                new DefaultKeyMaterialService(new IValidationKeysStore[] { },\n                    new ISigningCredentialStore[] { new InMemorySigningCredentialsStore(TestCert.LoadSigningCredentials()) }),\n                options ?? TestIdentityServerOptions.Create(),\n                TestLogger.Create<DefaultTokenCreationService>());\n        }\n\n        public static DeviceAuthorizationRequestValidator CreateDeviceAuthorizationRequestValidator(\n            IdentityServerOptions options = null,\n            IResourceStore resourceStore = null,\n            IResourceValidator resourceValidator = null)\n        {\n            if (options == null)\n            {\n                options = TestIdentityServerOptions.Create();\n            }\n            \n            if (resourceStore == null)\n            {\n                resourceStore = new InMemoryResourcesStore(TestScopes.GetIdentity(), TestScopes.GetApis(), TestScopes.GetScopes());\n            }\n\n            if (resourceValidator == null)\n            {\n                resourceValidator = CreateResourceValidator(resourceStore);\n            }\n\n\n            return new DeviceAuthorizationRequestValidator(\n                options,\n                resourceValidator,\n                TestLogger.Create<DeviceAuthorizationRequestValidator>());\n        }\n\n        public static AuthorizeRequestValidator CreateAuthorizeRequestValidator(\n            IdentityServerOptions options = null,\n            IResourceStore resourceStore = null,\n            IClientStore clients = null,\n            IProfileService profile = null,\n            ICustomAuthorizeRequestValidator customValidator = null,\n            IRedirectUriValidator uriValidator = null,\n            IResourceValidator resourceValidator = null,\n            JwtRequestValidator jwtRequestValidator = null,\n            IJwtRequestUriHttpClient jwtRequestUriHttpClient = null)\n        {\n            if (options == null)\n            {\n                options = TestIdentityServerOptions.Create();\n            }\n\n            if (resourceStore == null)\n            {\n                resourceStore = new InMemoryResourcesStore(TestScopes.GetIdentity(), TestScopes.GetApis(), TestScopes.GetScopes());\n            }\n\n            if (clients == null)\n            {\n                clients = new InMemoryClientStore(TestClients.Get());\n            }\n\n            if (customValidator == null)\n            {\n                customValidator = new DefaultCustomAuthorizeRequestValidator();\n            }\n\n            if (uriValidator == null)\n            {\n                uriValidator = new StrictRedirectUriValidator();\n            }\n\n            if (resourceValidator == null)\n            {\n                resourceValidator = CreateResourceValidator(resourceStore);\n            }\n\n            if (jwtRequestValidator == null)\n            {\n                jwtRequestValidator = new JwtRequestValidator(\"https://identityserver\", new LoggerFactory().CreateLogger<JwtRequestValidator>());\n            }\n\n            if (jwtRequestUriHttpClient == null)\n            {\n                jwtRequestUriHttpClient = new DefaultJwtRequestUriHttpClient(new HttpClient(new NetworkHandler(new Exception(\"no jwt request uri response configured\"))), options, new LoggerFactory());\n            }\n\n\n            var userSession = new MockUserSession();\n\n            return new AuthorizeRequestValidator(\n                options,\n                clients,\n                customValidator,\n                uriValidator,\n                resourceValidator,\n                userSession,\n                jwtRequestValidator,\n                jwtRequestUriHttpClient,\n                TestLogger.Create<AuthorizeRequestValidator>());\n        }\n\n        public static TokenValidator CreateTokenValidator(\n            IReferenceTokenStore store = null, \n            IRefreshTokenStore refreshTokenStore = null,\n            IProfileService profile = null, \n            IdentityServerOptions options = null, ISystemClock clock = null)\n        {\n            if (options == null)\n            {\n                options = TestIdentityServerOptions.Create();\n            }\n\n            if (profile == null)\n            {\n                profile = new TestProfileService();\n            }\n\n            if (store == null)\n            {\n                store = CreateReferenceTokenStore();\n            }\n\n            clock = clock ?? new StubClock();\n\n            if (refreshTokenStore == null)\n            {\n                refreshTokenStore = CreateRefreshTokenStore();\n            }\n\n            var clients = CreateClientStore();\n            var context = new MockHttpContextAccessor(options);\n            var logger = TestLogger.Create<TokenValidator>();\n\n            var keyInfo = new SecurityKeyInfo\n            {\n                Key = TestCert.LoadSigningCredentials().Key,\n                SigningAlgorithm = \"RS256\"\n            };\n\n            var validator = new TokenValidator(\n                clients: clients,\n                clock: clock,\n                profile: profile,\n                referenceTokenStore: store,\n                refreshTokenStore: refreshTokenStore,\n                customValidator: new DefaultCustomTokenValidator(),\n                    keys: new DefaultKeyMaterialService(new[] { new InMemoryValidationKeysStore(new[] { keyInfo }) }, Enumerable.Empty<ISigningCredentialStore>()),\n                logger: logger,\n                options: options,\n                context: context);\n\n            return validator;\n        }\n\n        public static IDeviceCodeValidator CreateDeviceCodeValidator(\n            IDeviceFlowCodeService service,\n            IProfileService profile = null,\n            IDeviceFlowThrottlingService throttlingService = null,\n            ISystemClock clock = null)\n        {\n            profile = profile ?? new TestProfileService();\n            throttlingService = throttlingService ?? new TestDeviceFlowThrottlingService();\n            clock = clock ?? new StubClock();\n            \n            var validator = new DeviceCodeValidator(service, profile, throttlingService, clock, TestLogger.Create<DeviceCodeValidator>());\n\n            return validator;\n        }\n\n        public static IClientSecretValidator CreateClientSecretValidator(IClientStore clients = null, SecretParser parser = null, SecretValidator validator = null, IdentityServerOptions options = null)\n        {\n            options = options ?? TestIdentityServerOptions.Create();\n\n            if (clients == null) clients = new InMemoryClientStore(TestClients.Get());\n\n            if (parser == null)\n            {\n                var parsers = new List<ISecretParser>\n                {\n                    new BasicAuthenticationSecretParser(options, TestLogger.Create<BasicAuthenticationSecretParser>()),\n                    new PostBodySecretParser(options, TestLogger.Create<PostBodySecretParser>())\n                };\n\n                parser = new SecretParser(parsers, TestLogger.Create<SecretParser>());\n            }\n\n            if (validator == null)\n            {\n                var validators = new List<ISecretValidator>\n                {\n                    new HashedSharedSecretValidator(TestLogger.Create<HashedSharedSecretValidator>()),\n                    new PlainTextSharedSecretValidator(TestLogger.Create<PlainTextSharedSecretValidator>())\n                };\n\n                validator = new SecretValidator(new StubClock(), validators, TestLogger.Create<SecretValidator>());\n            }\n\n            return new ClientSecretValidator(clients, parser, validator, new TestEventService(), TestLogger.Create<ClientSecretValidator>());\n        }\n\n        public static IAuthorizationCodeStore CreateAuthorizationCodeStore()\n        {\n            return new DefaultAuthorizationCodeStore(new InMemoryPersistedGrantStore(),\n                new PersistentGrantSerializer(),\n                new DefaultHandleGenerationService(),\n                TestLogger.Create<DefaultAuthorizationCodeStore>());\n        }\n        \n        public static IRefreshTokenStore CreateRefreshTokenStore()\n        {\n            return new DefaultRefreshTokenStore(new InMemoryPersistedGrantStore(),\n                new PersistentGrantSerializer(),\n                new DefaultHandleGenerationService(),\n                TestLogger.Create<DefaultRefreshTokenStore>());\n        }\n        \n        public static IReferenceTokenStore CreateReferenceTokenStore()\n        {\n            return new DefaultReferenceTokenStore(new InMemoryPersistedGrantStore(),\n                new PersistentGrantSerializer(),\n                new DefaultHandleGenerationService(),\n                TestLogger.Create<DefaultReferenceTokenStore>());\n        }\n\n        public static IDeviceFlowCodeService CreateDeviceCodeService()\n        {\n            return new DefaultDeviceFlowCodeService(new InMemoryDeviceFlowStore(), new DefaultHandleGenerationService());\n        }\n        \n        public static IUserConsentStore CreateUserConsentStore()\n        {\n            return new DefaultUserConsentStore(new InMemoryPersistedGrantStore(),\n                new PersistentGrantSerializer(),\n                new DefaultHandleGenerationService(),\n                TestLogger.Create<DefaultUserConsentStore>());\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/TestClients.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing IdentityServer8;\nusing IdentityServer8.Models;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    internal class TestClients\n    {\n        public static IEnumerable<Client> Get()\n        {\n            return new List<Client>\n            {\n                new Client\n                {\n                    ClientName = \"Code Client\",\n                    Enabled = true,\n                    ClientId = \"codeclient\",\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret(\"secret\".Sha256())\n                    },\n\n                    AllowedGrantTypes = GrantTypes.Code,\n                    AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n\n                    RequireConsent = false,\n                    RequirePkce = false,\n\n                    RedirectUris = new List<string>\n                    {\n                        \"https://server/cb\"\n                    },\n\n                    AuthorizationCodeLifetime = 60\n                },\n                new Client\n                {\n                    ClientName = \"Code Client (allows plain text PKCE)\",\n                    Enabled = true,\n                    ClientId = \"codeclient.plain\",\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret(\"secret\".Sha256())\n                    },\n\n                    AllowedGrantTypes = GrantTypes.Code,\n                    AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n                    AllowPlainTextPkce = true,\n\n                    RequireConsent = false,\n\n                    RedirectUris = new List<string>\n                    {\n                        \"https://server/cb\"\n                    },\n\n                    AuthorizationCodeLifetime = 60\n                },\n                new Client\n                {\n                    ClientName = \"Code Client with PKCE\",\n                    Enabled = true,\n                    ClientId = \"codeclient.pkce\",\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret(\"secret\".Sha256())\n                    },\n\n                    AllowedGrantTypes = GrantTypes.Code,\n                    RequirePkce = true,\n                    AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n\n                    RequireConsent = false,\n\n                    RedirectUris = new List<string>\n                    {\n                        \"https://server/cb\"\n                    },\n\n                    AuthorizationCodeLifetime = 60\n                },\n                new Client\n                {\n                    ClientName = \"Code Client with PKCE and plain allowed\",\n                    Enabled = true,\n                    ClientId = \"codeclient.pkce.plain\",\n                    ClientSecrets = new List<Secret>\n                    {\n                        new Secret(\"secret\".Sha256())\n                    },\n\n                    AllowedGrantTypes = GrantTypes.Code,\n                    RequirePkce = true,\n                    AllowPlainTextPkce = true,\n                    AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n\n                    RequireConsent = false,\n\n                    RedirectUris = new List<string>\n                    {\n                        \"https://server/cb\"\n                    },\n\n                    AuthorizationCodeLifetime = 60\n                },\n                new Client\n                {\n                        ClientName = \"Hybrid Client\",\n                        Enabled = true,\n                        ClientId = \"hybridclient\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.Hybrid,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n                        AllowAccessTokensViaBrowser = true,\n\n                        RequireConsent = false,\n                        RequirePkce = false,\n\n                        RedirectUris = new List<string>\n                        {\n                            \"https://server/cb\"\n                        },\n\n                        AuthorizationCodeLifetime = 60\n                    },\n                    new Client\n                    {\n                        ClientName = \"Hybrid Client with PKCE\",\n                        Enabled = true,\n                        ClientId = \"hybridclient.pkce\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.Hybrid,\n                        RequirePkce = true,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n                        AllowAccessTokensViaBrowser = true,\n\n                        RequireConsent = false,\n\n                        RedirectUris = new List<string>\n                        {\n                            \"https://server/cb\"\n                        },\n\n                        AuthorizationCodeLifetime = 60\n                    },\n                    new Client\n                    {\n                        ClientName = \"Hybrid Client\",\n                        Enabled = true,\n                        ClientId = \"hybridclient_no_aavb\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.Hybrid,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n                        AllowAccessTokensViaBrowser = false,\n\n                        RequireConsent = false,\n                        RequirePkce = false,\n\n                        RedirectUris = new List<string>\n                        {\n                            \"https://server/cb\"\n                        },\n\n                        AuthorizationCodeLifetime = 60\n                    },\n                    new Client\n                    {\n                        ClientName = \"Implicit Client\",\n                        ClientId = \"implicitclient\",\n\n                        AllowedGrantTypes = GrantTypes.Implicit,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n                        AllowAccessTokensViaBrowser = true,\n\n                        RequireConsent = false,\n\n                        RedirectUris = new List<string>\n                        {\n                            \"oob://implicit/cb\"\n                        }\n                    },\n                    new Client\n                    {\n                        ClientName = \"Implicit Client\",\n                        ClientId = \"implicitclient_no_aavb\",\n\n                        AllowedGrantTypes = GrantTypes.Implicit,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n                        AllowAccessTokensViaBrowser = false,\n\n                        RequireConsent = false,\n\n                        RedirectUris = new List<string>\n                        {\n                            \"oob://implicit/cb\"\n                        }\n                    },\n                    new Client\n                    {\n                        ClientName = \"Implicit and Client Credentials Client\",\n                        Enabled = true,\n                        ClientId = \"implicit_and_client_creds_client\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ImplicitAndClientCredentials,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n                        RequireConsent = false,\n\n                        RedirectUris = new List<string>\n                        {\n                            \"oob://implicit/cb\"\n                        }\n                    },\n                    new Client\n                    {\n                        ClientName = \"Code Client with Scope Restrictions\",\n                        Enabled = true,\n                        ClientId = \"codeclient_restricted\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.Code,\n                        RequireConsent = false,\n                        RequirePkce = false,\n\n                        AllowedScopes = new List<string>\n                        {\n                            \"openid\"\n                        },\n\n                        RedirectUris = new List<string>\n                        {\n                            \"https://server/cb\"\n                        }\n                    },\n                    new Client\n                    {\n                        ClientName = \"Client Credentials Client\",\n                        Enabled = true,\n                        ClientId = \"client\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ClientCredentials,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n\n                        AllowOfflineAccess = true,\n\n                        AccessTokenType = AccessTokenType.Jwt\n                    },\n                    new Client\n                    {\n                        ClientName = \"Client Credentials Client (restricted)\",\n                        Enabled = true,\n                        ClientId = \"client_restricted\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ClientCredentials,\n\n                        AllowedScopes = new List<string>\n                        {\n                            \"resource\"\n                        }\n                    },\n                    new Client\n                    {\n                        ClientName = \"Resource Owner Client\",\n                        Enabled = true,\n                        ClientId = \"roclient\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n                        AllowOfflineAccess = true\n                    },\n                    new Client\n                    {\n                        ClientName = \"Resource Owner Client - Public\",\n                        Enabled = true,\n                        ClientId = \"roclient.public\",\n                        RequireClientSecret = false,\n\n                        AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" }\n                    },\n                    new Client\n                    {\n                        ClientName = \"Resource Owner Client\",\n                        Enabled = true,\n                        ClientId = \"roclient_absolute_refresh_expiration_one_time_only\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n\n                        RefreshTokenExpiration = TokenExpiration.Absolute,\n                        RefreshTokenUsage = TokenUsage.OneTimeOnly,\n                        AbsoluteRefreshTokenLifetime = 200\n                    },\n                    new Client\n                    {\n                        ClientName = \"Resource Owner Client\",\n                        Enabled = true,\n                        ClientId = \"roclient_absolute_refresh_expiration_reuse\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n\n                        RefreshTokenExpiration = TokenExpiration.Absolute,\n                        RefreshTokenUsage = TokenUsage.ReUse,\n                        AbsoluteRefreshTokenLifetime = 200\n                    },\n                    new Client\n                    {\n                        ClientName = \"Resource Owner Client\",\n                        Enabled = true,\n                        ClientId = \"roclient_sliding_refresh_expiration_one_time_only\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n\n                        RefreshTokenExpiration = TokenExpiration.Sliding,\n                        RefreshTokenUsage = TokenUsage.OneTimeOnly,\n                        AbsoluteRefreshTokenLifetime = 10,\n                        SlidingRefreshTokenLifetime = 4\n                    },\n                    new Client\n                    {\n                        ClientName = \"Resource Owner Client\",\n                        Enabled = true,\n                        ClientId = \"roclient_sliding_refresh_expiration_reuse\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n\n                        RefreshTokenExpiration = TokenExpiration.Sliding,\n                        RefreshTokenUsage = TokenUsage.ReUse,\n                        AbsoluteRefreshTokenLifetime = 200,\n                        SlidingRefreshTokenLifetime = 100\n                    },\n                    new Client\n                    {\n                        ClientName = \"Resource Owner Client (restricted)\",\n                        Enabled = true,\n                        ClientId = \"roclient_restricted\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n\n                        AllowedScopes = new List<string>\n                        {\n                            \"resource\"\n                        }\n                    },\n                    new Client\n                    {\n                        ClientName = \"Resource Owner Client (restricted with refresh)\",\n                        Enabled = true,\n                        ClientId = \"roclient_restricted_refresh\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,\n\n                        AllowOfflineAccess = true,\n                        AllowedScopes = new List<string>\n                        {\n                            \"resource\"\n                        }\n                    },\n\n                    new Client\n                    {\n                        ClientName = \"Custom Grant Client\",\n                        Enabled = true,\n                        ClientId = \"customgrantclient\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = { \"custom_grant\" },\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" }\n                    },\n\n                    new Client\n                    {\n                        ClientName = \"Disabled Client\",\n                        Enabled = false,\n                        ClientId = \"disabled\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"invalid\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.ClientCredentials,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" }\n                    },\n                    new Client\n                    {\n                        ClientName = \"Reference Token Client\",\n\n                        Enabled = true,\n                        ClientId = \"referencetokenclient\",\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n\n                        AllowedGrantTypes = GrantTypes.Implicit,\n                        RedirectUris = { \"https://notused\" },\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n\n                        AccessTokenType = AccessTokenType.Reference\n                    },\n                    new Client\n                    {\n                        ClientId = \"wsfed\",\n                        ClientName = \"WS-Fed Client\",\n                        ProtocolType = IdentityServerConstants.ProtocolTypes.WsFederation,\n                        AllowedGrantTypes = GrantTypes.Implicit,\n                        Enabled = true,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" },\n                        RedirectUris = { \"http://wsfed/callback\"  }\n                    },\n                    new Client\n                    {\n                        ClientId = \"client.cred.wsfed\",\n                        ClientName = \"WS-Fed Client\",\n                        ProtocolType = IdentityServerConstants.ProtocolTypes.WsFederation,\n                        AllowedGrantTypes = GrantTypes.ClientCredentials,\n                        ClientSecrets = { new Secret(\"secret\".Sha256()) },\n\n                        Enabled = true,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" }\n                    },\n                    new Client\n                    {\n                        ClientId = \"client.implicit\",\n                        ClientName = \"Implicit Client\",\n                        AllowedGrantTypes = GrantTypes.Implicit,\n                        RedirectUris = { \"https://notused\" },\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\", \"resource2\" }\n                    },\n                    new Client\n                    {\n                        ClientId = \"implicit_and_client_creds\",\n                        AllowedGrantTypes = GrantTypes.ImplicitAndClientCredentials,\n                        RedirectUris = { \"https://notused\" },\n                        AllowedScopes = {\"api1\"}\n                    },\n                    new Client\n                    {\n                        ClientId = \"device_flow\",\n                        ClientName = \"Device Flow Client\",\n                        AllowedGrantTypes = GrantTypes.DeviceFlow,\n                        AllowedScopes = { \"openid\", \"profile\", \"resource\" },\n                        AllowOfflineAccess = true,\n                        ClientSecrets = new List<Secret>\n                        {\n                            new Secret(\"secret\".Sha256())\n                        },\n                    }\n            };\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/TestDeviceCodeValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    public class TestDeviceCodeValidator : IDeviceCodeValidator\n    {\n        private readonly bool shouldError;\n\n        public TestDeviceCodeValidator(bool shouldError = false)\n        {\n            this.shouldError = shouldError;\n        }\n\n        public Task ValidateAsync(DeviceCodeValidationContext context)\n        {\n            if (shouldError) context.Result = new TokenRequestValidationResult(context.Request, \"error\");\n            else context.Result = new TokenRequestValidationResult(context.Request);\n\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/TestDeviceFlowThrottlingService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    public class TestDeviceFlowThrottlingService : IDeviceFlowThrottlingService\n    {\n        private readonly bool shouldSlownDown;\n\n        public TestDeviceFlowThrottlingService(bool shouldSlownDown = false)\n        {\n            this.shouldSlownDown = shouldSlownDown;\n        }\n\n        public Task<bool> ShouldSlowDown(string deviceCode, DeviceCode details) => Task.FromResult(shouldSlownDown);\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/TestGrantValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    internal class TestGrantValidator : IExtensionGrantValidator\n    {\n        private readonly bool _isInvalid;\n        private readonly string _errorDescription;\n\n        public TestGrantValidator(bool isInvalid = false, string errorDescription = null)\n        {\n            _isInvalid = isInvalid;\n            _errorDescription = errorDescription;\n        }\n\n        public Task<GrantValidationResult> ValidateAsync(ValidatedTokenRequest request)\n        {\n            if (_isInvalid)\n            {\n                return Task.FromResult(new GrantValidationResult(TokenRequestErrors.InvalidGrant, _errorDescription));\n            }\n\n            return Task.FromResult(new GrantValidationResult(\"bob\", \"CustomGrant\"));\n        }\n\n        public Task ValidateAsync(ExtensionGrantValidationContext context)\n        {\n            if (_isInvalid)\n            {\n                context.Result = new GrantValidationResult(TokenRequestErrors.InvalidGrant, _errorDescription);\n            }\n            else\n            {\n                context.Result = new GrantValidationResult(\"bob\", \"CustomGrant\");\n            }\n\n            return Task.CompletedTask;\n        }\n\n        public string GrantType\n        {\n            get { return \"custom_grant\"; }\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/TestProfileService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Services;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    internal class TestProfileService : IProfileService\n    {\n        private bool _shouldBeActive;\n\n        public TestProfileService(bool shouldBeActive = true)\n        {\n            _shouldBeActive = shouldBeActive;\n        }\n\n        public Task GetProfileDataAsync(ProfileDataRequestContext context)\n        {\n            return Task.CompletedTask;\n        }\n\n        public Task IsActiveAsync(IsActiveContext context)\n        {\n            context.IsActive = _shouldBeActive;\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/TestResourceOwnerPasswordValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Threading.Tasks;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    public class TestResourceOwnerPasswordValidator : IResourceOwnerPasswordValidator\n    {\n        private string _erroDescription;\n        private TokenRequestErrors _error;\n        private readonly bool _sendError;\n\n        public TestResourceOwnerPasswordValidator()\n        { }\n\n        public TestResourceOwnerPasswordValidator(TokenRequestErrors error, string errorDescription = null)\n        {\n            _sendError = true;\n            _error = error;\n            _erroDescription = errorDescription;\n        }\n\n        public Task ValidateAsync(ResourceOwnerPasswordValidationContext context)\n        {\n            if (_sendError)\n            {\n                context.Result = new GrantValidationResult(_error, _erroDescription);\n                return Task.CompletedTask;\n            }\n\n            if (context.UserName == context.Password)\n            {\n                context.Result = new GrantValidationResult(context.UserName, \"password\");\n            }\n            \n            if (context.UserName == \"bob_no_password\" && context.Password == \"\")\n            {\n                context.Result = new GrantValidationResult(context.UserName, \"password\");\n            }\n\n            return Task.CompletedTask;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/TestScopes.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Generic;\nusing IdentityServer8.Models;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    internal class TestScopes\n    {\n        public static IEnumerable<IdentityResource> GetIdentity()\n        {\n            return new IdentityResource[]\n            {\n                new IdentityResources.OpenId(),\n                new IdentityResources.Profile()\n            };\n        }\n\n        public static IEnumerable<ApiResource> GetApis()\n        {\n            return new ApiResource[]\n            {\n                new ApiResource\n                {\n                    Name = \"api\",\n                    Scopes =  { \"resource\", \"resource2\" }\n                }\n            };\n        }\n\n        public static IEnumerable<ApiScope> GetScopes()\n        {\n            return new ApiScope[]\n            {\n                new ApiScope\n                {\n                    Name = \"resource\",\n                    Description = \"resource scope\"\n                },\n                new ApiScope\n                {\n                    Name = \"resource2\",\n                    Description = \"resource scope\"\n                }\n            };\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/TestTokenValidator.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing System.Threading.Tasks;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    class TestTokenValidator : ITokenValidator\n    {\n        private readonly TokenValidationResult _result;\n\n        public TestTokenValidator(TokenValidationResult result)\n        {\n            _result = result;\n        }\n\n        public Task<TokenValidationResult> ValidateAccessTokenAsync(string token, string expectedScope = null)\n        {\n            return Task.FromResult(_result);\n        }\n\n        public Task<TokenValidationResult> ValidateIdentityTokenAsync(string token, string clientId = null, bool validateLifetime = true)\n        {\n            return Task.FromResult(_result);\n        }\n\n        public Task<TokenValidationResult> ValidateRefreshTokenAsync(string token, Client client = null)\n        {\n            return Task.FromResult(_result);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/TokenFactory.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Linq;\nusing System.Security.Claims;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Models;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{\n    internal static class TokenFactory\n    {\n        public static Token CreateAccessToken(Client client, string subjectId, int lifetime, params string[] scopes)\n        {\n            var claims = new List<Claim> \n            {\n                new Claim(\"client_id\", client.ClientId),\n                new Claim(\"sub\", subjectId)\n            };\n\n            scopes.ToList().ForEach(s => claims.Add(new Claim(\"scope\", s)));\n\n            var token = new Token(OidcConstants.TokenTypes.AccessToken)\n            {\n                CreationTime = DateTime.UtcNow,\n                Audiences = { \"https://idsvr.com/resources\" },\n                Issuer = \"https://idsvr.com\",\n                Lifetime = lifetime,\n                Claims = claims,\n                ClientId = client.ClientId,\n                AccessTokenType = client.AccessTokenType\n            };\n\n            return token;\n        }\n\n        public static Token CreateAccessTokenLong(Client client, string subjectId, int lifetime, int count, params string[] scopes)\n        {\n            var claims = new List<Claim>\n            {\n                new Claim(\"client_id\", client.ClientId),\n                new Claim(\"sub\", subjectId)\n            };\n\n            for (int i = 0; i < count; i++)\n            {\n                claims.Add(new Claim(\"junk\", \"x\".Repeat(100)));\n            }\n\n            scopes.ToList().ForEach(s => claims.Add(new Claim(\"scope\", s)));\n\n            var token = new Token(OidcConstants.TokenTypes.AccessToken)\n            {\n                CreationTime = DateTime.UtcNow,\n                Audiences = { \"https://idsvr.com/resources\" },\n                Issuer = \"https://idsvr.com\",\n                Lifetime = lifetime,\n                Claims = claims,\n                ClientId = client.ClientId,\n                AccessTokenType = client.AccessTokenType\n            };\n\n            return token;\n        }\n\n        public static Token CreateIdentityToken(string clientId, string subjectId)\n        {\n            var clients = Factory.CreateClientStore();\n\n            var claims = new List<Claim> \n            {\n                new Claim(\"sub\", subjectId)\n            };\n\n            var token = new Token(OidcConstants.TokenTypes.IdentityToken)\n            {\n                CreationTime = DateTime.UtcNow,\n                Audiences = { clientId },\n                ClientId = clientId,\n                Issuer = \"https://idsvr.com\",\n                Lifetime = 600,\n                Claims = claims\n            };\n\n            return token;\n        }\n\n        public static Token CreateIdentityTokenLong(string clientId, string subjectId, int count)\n        {\n            var clients = Factory.CreateClientStore();\n\n            var claims = new List<Claim>\n            {\n                new Claim(\"sub\", subjectId)\n            };\n\n            for (int i = 0; i < count; i++)\n            {\n                claims.Add(new Claim(\"junk\", \"x\".Repeat(100)));\n            }\n\n            var token = new Token(OidcConstants.TokenTypes.IdentityToken)\n            {\n                CreationTime = DateTime.UtcNow,\n                Audiences = { clientId },\n                ClientId = clientId,\n                Issuer = \"https://idsvr.com\",\n                Lifetime = 600,\n                Claims = claims\n            };\n\n            return token;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/Setup/ValidationExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\n\nnamespace IdentityServer.UnitTests.Validation.Setup\n{ \n    public static class ValidationExtensions\n    {\n        public static ClientSecretValidationResult ToValidationResult(this Client client, ParsedSecret secret = null)\n        {\n            return new ClientSecretValidationResult\n            {\n                Client = client,\n                Secret = secret\n            };\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/StrictRedirectUriValidatorAppAuthValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer8.Models;\nusing IdentityServer8.Validation;\nusing System.Collections.Generic;\nusing System.Threading.Tasks;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class StrictRedirectUriValidatorAppAuthValidation\n    {\n        private const string Category = \"Strict Redirect Uri Validator AppAuth Validation Tests\";\n\n        private Client clientWithValidLoopbackRedirectUri = new Client\n        {\n            RequirePkce = true,\n            RedirectUris = new List<string>\n            {\n                \"http://127.0.0.1\"\n            }\n        };\n\n        private Client clientWithNoRedirectUris = new Client\n        {\n            RequirePkce = true\n        };\n\n        [Theory]\n        [Trait(\"Category\", Category)]\n        [InlineData(\"http://127.0.0.1\")] // This is in the clients redirect URIs\n        [InlineData(\"http://127.0.0.1:0\")]\n        [InlineData(\"http://127.0.0.1:80\")]\n        [InlineData(\"http://127.0.0.1:65535\")]\n        [InlineData(\"http://127.0.0.1:123/a/b\")]\n        [InlineData(\"http://127.0.0.1:123?q=123\")]\n        [InlineData(\"http://127.0.0.1:443/?q=123\")]\n        [InlineData(\"http://127.0.0.1:443/a/b?q=123\")]\n        [InlineData(\"http://127.0.0.1:443#abc\")]\n        [InlineData(\"http://127.0.0.1:443/a/b?q=123#abc\")]\n        public async Task Loopback_Redirect_URIs_Should_Be_AllowedAsync(string requestedUri)\n        {\n            var strictRedirectUriValidatorAppAuthValidator = new StrictRedirectUriValidatorAppAuth(TestLogger.Create<StrictRedirectUriValidatorAppAuth>());\n\n            var result = await strictRedirectUriValidatorAppAuthValidator.IsRedirectUriValidAsync(requestedUri, clientWithValidLoopbackRedirectUri);\n\n            result.Should().BeTrue();\n        }\n\n        [Theory]\n        [Trait(\"Category\", Category)]\n        [InlineData(null)]\n        [InlineData(\"\")]\n        [InlineData(\"http:\")]\n        [InlineData(\"127.0.0.1\")]\n        [InlineData(\"//127.0.0.1\")]\n        [InlineData(\"https://127.0.0.1:123\")]\n        [InlineData(\"http://127.0.0.1:\")]\n        [InlineData(\"http://127.0.0.1:-1\")]\n        [InlineData(\"http://127.0.0.2:65536\")]\n        [InlineData(\"http://127.0.0.1:443a\")]\n        [InlineData(\"http://127.0.0.1:a443\")]\n        [InlineData(\"http://127.0.0.1:443a/\")]\n        [InlineData(\"http://127.0.0.1:443a?\")]\n        [InlineData(\"http://127.0.0.2:443\")]\n        [InlineData(\"http://127.0.0.1#abc\")]\n        [InlineData(\"http://127.0.0.1:#abc\")]\n        public async Task Loopback_Redirect_URIs_Should_Not_Be_AllowedAsync(string requestedUri)\n        {\n            var strictRedirectUriValidatorAppAuthValidator = new StrictRedirectUriValidatorAppAuth(TestLogger.Create<StrictRedirectUriValidatorAppAuth>());\n\n            var result = await strictRedirectUriValidatorAppAuthValidator.IsRedirectUriValidAsync(requestedUri, clientWithValidLoopbackRedirectUri);\n\n            result.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/TokenRequest Validation/TokenRequestValidation_ClientCredentials_Invalid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Linq;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.TokenRequest_Validation\n{\n    public class TokenRequestValidation_ClientCredentials_Invalid\n    {\n        private const string Category = \"TokenRequest Validation - ClientCredentials - Invalid\";\n\n        private IClientStore _clients = Factory.CreateClientStore();\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_GrantType_For_Client()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.UnauthorizedClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Request_should_succeed_even_with_allowed_identity_scopes_because_they_are_filtered_out()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection\n            {\n                { OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials }\n            };\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n            result.ValidatedRequest.ValidatedResources.Resources.ApiResources.Count.Should().Be(1);\n            result.ValidatedRequest.ValidatedResources.Resources.ApiResources.First().Name.Should().Be(\"api\");\n\n            result.ValidatedRequest.ValidatedResources.Resources.ApiScopes.Count.Should().Be(2);\n            result.ValidatedRequest.ValidatedResources.Resources.ApiScopes.Select(x=>x.Name).Should().BeEquivalentTo(new[] { \"resource\", \"resource2\" });\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Unknown_Scope()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client\");\n            var validator = Factory.CreateTokenRequestValidator();\n            \n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"unknown\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Unknown_Scope_Multiple()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource unknown\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Restricted_Scope()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client_restricted\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource2\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Restricted_Scope_Multiple()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client_restricted\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource resource2\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Identity_scope_is_not_allowed_for_client_credentials_when_specified_explicitly()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection\n            {\n                { OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials },\n                { OidcConstants.TokenRequest.Scope, \"openid\" }\n            };\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Resource_and_Refresh_Token()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource offline_access\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/TokenRequest Validation/TokenRequestValidation_Code_Invalid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Collections.Specialized;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.TokenRequest_Validation\n{\n    public class TokenRequestValidation_Code_Invalid\n    {\n        private IClientStore _clients = Factory.CreateClientStore();\n        private const string Category = \"TokenRequest Validation - AuthorizationCode - Invalid\";\n\n        private ClaimsPrincipal _subject = new IdentityServerUser(\"bob\").CreatePrincipal();\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_AuthorizationCode()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_AuthorizationCode()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, \"invalid\");\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task AuthorizationCodeTooLong()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n            var options = new IdentityServerOptions();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n            var longCode = \"x\".Repeat(options.InputLengthRestrictions.AuthorizationCode + 1);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, longCode);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task No_Scopes_for_AuthorizationCode()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            OidcConstants.TokenErrors.InvalidRequest.Should().Be(result.Error);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Client_Not_Authorized_For_AuthorizationCode_Flow()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"implicitclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.UnauthorizedClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Client_Trying_To_Request_Token_Using_Another_Clients_Code()\n        {\n            var client1 = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var client2 = await _clients.FindEnabledClientByIdAsync(\"codeclient_restricted\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client1.ClientId,\n                Lifetime = client1.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client2.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_RedirectUri()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.UnauthorizedClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Different_RedirectUri_Between_Authorize_And_Token_Request()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server1/cb\",\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server2/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Expired_AuthorizationCode()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                CreationTime = DateTime.UtcNow.AddSeconds(-100),\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Reused_AuthorizationCode()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                RequestedScopes = new List<string>\n                {\n                    \"openid\"\n                }\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            // request first time\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n\n            // request second time\n            validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n            \n            result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Code_Request_with_disabled_User()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                RedirectUri = \"https://server/cb\",\n                RequestedScopes = new List<string>\n                {\n                    \"openid\"\n                }\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store,\n                profile: new TestProfileService(shouldBeActive: false));\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/TokenRequest Validation/TokenRequestValidation_DeviceCode_Invalid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.TokenRequest_Validation\n{\n    public class TokenRequestValidation_DeviceCode_Invalid\n    {\n        private const string Category = \"TokenRequest Validation - DeviceCode - Invalid\";\n\n        private readonly IClientStore _clients = Factory.CreateClientStore();\n\n        private readonly DeviceCode deviceCode = new DeviceCode\n        {\n            ClientId = \"device_flow\",\n            IsAuthorized = true,\n            Subject = new IdentityServerUser(\"bob\").CreatePrincipal(),\n            IsOpenId = true,\n            Lifetime = 300,\n            CreationTime = DateTime.UtcNow,\n            AuthorizedScopes = new[] {\"openid\", \"profile\", \"resource\"}\n        };\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_DeviceCode()\n        {\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection\n            {\n                {OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.DeviceCode}\n            };\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidRequest);\n        }\n        \n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task DeviceCode_Too_Long()\n        {\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n\n            var longCode = \"x\".Repeat(new IdentityServerOptions().InputLengthRestrictions.AuthorizationCode + 1);\n            \n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection\n            {\n                {OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.DeviceCode},\n                {\"device_code\", longCode}\n            };\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Grant_For_Client()\n        {\n            var client = await _clients.FindClientByIdAsync(\"codeclient\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection\n            {\n                {OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.DeviceCode},\n                {\"device_code\", Guid.NewGuid().ToString()}\n            };\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.UnauthorizedClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task DeviceCodeValidator_Failure()\n        {\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n\n            var validator = Factory.CreateTokenRequestValidator(deviceCodeValidator: new TestDeviceCodeValidator(true));\n\n            var parameters = new NameValueCollection\n            {\n                {OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.DeviceCode},\n                {\"device_code\", Guid.NewGuid().ToString()}\n            };\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n            result.IsError.Should().BeTrue();\n            result.Error.Should().NotBeNull();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/TokenRequest Validation/TokenRequestValidation_ExtensionGrants_Invalid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.TokenRequest_Validation\n{\n    public class TokenRequestValidation_ExtensionGrants_Invalid\n    {\n        private const string Category = \"TokenRequest Validation - Extension Grants - Invalid\";\n\n        private IClientStore _clients = Factory.CreateClientStore();\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Extension_Grant_Type_For_Client_Credentials_Client()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection\n            {\n                { OidcConstants.TokenRequest.GrantType, \"customGrant\" },\n                { OidcConstants.TokenRequest.Scope, \"resource\" }\n            };\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.UnsupportedGrantType);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Restricted_Extension_Grant_Type()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"customgrantclient\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection\n            {\n                { OidcConstants.TokenRequest.GrantType, \"unknown_grant_type\" },\n                { OidcConstants.TokenRequest.Scope, \"resource\" }\n            };\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.UnsupportedGrantType);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Customer_Error_and_Description_Extension_Grant_Type()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"customgrantclient\");\n\n            var validator = Factory.CreateTokenRequestValidator(extensionGrantValidators: new[] { new TestGrantValidator(isInvalid: true, errorDescription: \"custom error description\") });\n\n            var parameters = new NameValueCollection\n            {\n                { OidcConstants.TokenRequest.GrantType, \"custom_grant\" },\n                { OidcConstants.TokenRequest.Scope, \"resource\" }\n            };\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n            result.ErrorDescription.Should().Be(\"custom error description\");\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task inactive_user_should_fail()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"customgrantclient\");\n\n            var validator = Factory.CreateTokenRequestValidator(\n                profile: new TestProfileService(shouldBeActive: false));\n\n            var parameters = new NameValueCollection\n            {\n                { OidcConstants.TokenRequest.GrantType, \"custom_grant\" },\n                { OidcConstants.TokenRequest.Scope, \"resource\" }\n            };\n\n            var result = await validator.ValidateRequestAsync(\n                parameters, \n                client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/TokenRequest Validation/TokenRequestValidation_General_Invalid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Specialized;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.TokenRequest_Validation\n{\n    public class TokenRequestValidation_General_Invalid\n    {\n        private const string Category = \"TokenRequest Validation - General - Invalid\";\n\n        private IClientStore _clients = new InMemoryClientStore(TestClients.Get());\n        private ClaimsPrincipal _subject = new IdentityServerUser(\"bob\").CreatePrincipal();\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void Parameters_Null()\n        {\n            var validator = Factory.CreateTokenRequestValidator();\n\n            Func<Task> act = () => validator.ValidateRequestAsync(null, null);\n\n            act.Should().ThrowAsync<ArgumentNullException>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public void Client_Null()\n        {\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, \"valid\");\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            Func<Task> act = () => validator.ValidateRequestAsync(parameters, null);\n\n            act.Should().ThrowAsync<ArgumentNullException>();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Unknown_Grant_Type()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"unknown\");\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.UnsupportedGrantType);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_Protocol_Type()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client.cred.wsfed\");\n            var codeStore = Factory.CreateAuthorizationCodeStore();\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore:codeStore);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"client_credentials\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_Grant_Type()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var store = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                IsOpenId = true,\n                RedirectUri = \"https://server/cb\",\n                Subject = _subject\n            };\n\n            var handle = await store.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: store);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.UnsupportedGrantType);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/TokenRequest Validation/TokenRequestValidation_PKCE.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Collections.Specialized;\nusing System.Text;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.TokenRequest_Validation\n{\n    public class TokenRequestValidation_PKCE\n    {\n        private const string Category = \"TokenRequest Validation - PKCE\";\n\n        private IClientStore _clients = Factory.CreateClientStore();\n        private InputLengthRestrictions lengths = new InputLengthRestrictions();\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient\")]\n        [Trait(\"Category\", Category)]\n        public async Task valid_pkce_token_request_with_plain_method_should_succeed(string clientId)\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n            var grants = Factory.CreateAuthorizationCodeStore();\n            var verifier = \"x\".Repeat(lengths.CodeVerifierMinLength);\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                Subject = new IdentityServerUser(\"bob\").CreatePrincipal(),\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                RedirectUri = \"https://server/cb\",\n                CodeChallenge = verifier.Sha256(),\n                CodeChallengeMethod = OidcConstants.CodeChallengeMethods.Plain,\n\n                RequestedScopes = new List<string>\n                {\n                    \"openid\"\n                }\n            };\n\n            var handle = await grants.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.CodeVerifier, verifier);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task valid_pkce_token_request_with_plain_method_should_succeed_hybrid()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"hybridclient.pkce\");\n            var grants = Factory.CreateAuthorizationCodeStore();\n            var verifier = \"x\".Repeat(lengths.CodeVerifierMinLength);\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                RedirectUri = \"https://server/cb\",\n                CodeChallenge = verifier.Sha256(),\n                CodeChallengeMethod = OidcConstants.CodeChallengeMethods.Plain,\n\n                RequestedScopes = new List<string>\n                {\n                    \"openid\"\n                }\n            };\n\n            var handle = await grants.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.CodeVerifier, verifier);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient\")]\n        [Trait(\"Category\", Category)]\n        public async Task valid_pkce_token_request_with_sha256_method_should_succeed(string clientId)\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n            var grants = Factory.CreateAuthorizationCodeStore();\n\n            var verifier = \"x\".Repeat(lengths.CodeVerifierMinLength);\n            var challenge = VerifierToSha256CodeChallenge(verifier);\n            \n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                RedirectUri = \"https://server/cb\",\n                CodeChallenge = challenge.Sha256(),\n                CodeChallengeMethod = OidcConstants.CodeChallengeMethods.Sha256,\n\n                RequestedScopes = new List<string>\n                {\n                    \"openid\"\n                }\n            };\n\n            var handle = await grants.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.CodeVerifier, verifier);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [Trait(\"Category\", Category)]\n        public async Task token_request_with_missing_code_challenge_and_verifier_should_fail(string clientId)\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n            var grants = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                RedirectUri = \"https://server/cb\",\n                RequestedScopes = new List<string>\n                {\n                    \"openid\"\n                }\n            };\n\n            var handle = await grants.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient\")]\n        [Trait(\"Category\", Category)]\n        public async Task token_request_with_missing_code_challenge_should_fail(string clientId)\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n            var grants = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                RedirectUri = \"https://server/cb\",\n\n                RequestedScopes = new List<string>\n                {\n                    \"openid\"\n                }\n            };\n\n            var handle = await grants.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.CodeVerifier, \"x\".Repeat(lengths.CodeVerifierMinLength));\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient\")]\n        [Trait(\"Category\", Category)]\n        public async Task token_request_with_invalid_verifier_plain_method_should_fail(string clientId)\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n            var grants = Factory.CreateAuthorizationCodeStore();\n            var verifier = \"x\".Repeat(lengths.CodeVerifierMinLength);\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                RedirectUri = \"https://server/cb\",\n                CodeChallenge = verifier.Sha256(),\n                CodeChallengeMethod = OidcConstants.CodeChallengeMethods.Plain,\n\n                RequestedScopes = new List<string>\n                {\n                    \"openid\"\n                }\n            };\n\n            var handle = await grants.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.CodeVerifier, verifier + \"invalid\");\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Theory]\n        [InlineData(\"codeclient.pkce\")]\n        [InlineData(\"codeclient\")]\n        [Trait(\"Category\", Category)]\n        public async Task token_request_with_invalid_verifier_sha256_method_should_fail(string clientId)\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(clientId);\n            var grants = Factory.CreateAuthorizationCodeStore();\n\n            var verifier = \"x\".Repeat(lengths.CodeVerifierMinLength);\n            var challenge = VerifierToSha256CodeChallenge(verifier);\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                RedirectUri = \"https://server/cb\",\n                CodeChallenge = challenge.Sha256(),\n                CodeChallengeMethod = OidcConstants.CodeChallengeMethods.Sha256,\n\n                RequestedScopes = new List<string>\n                {\n                    \"openid\"\n                }\n            };\n\n            var handle = await grants.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.CodeVerifier, verifier + \"invalid\");\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        private static string VerifierToSha256CodeChallenge(string codeVerifier)\n        {\n            var codeVerifierBytes = Encoding.ASCII.GetBytes(codeVerifier);\n            var hashedBytes = codeVerifierBytes.Sha256();\n            var transformedCodeVerifier = Base64Url.Encode(hashedBytes);\n\n            return transformedCodeVerifier;\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/TokenRequest Validation/TokenRequestValidation_RefreshToken_Invalid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Collections.Specialized;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Configuration;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.TokenRequest_Validation\n{\n    public class TokenRequestValidation_RefreshToken_Invalid\n    {\n        private const string Category = \"TokenRequest Validation - RefreshToken - Invalid\";\n\n        private IClientStore _clients = Factory.CreateClientStore();\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Non_existing_RefreshToken()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"refresh_token\");\n            parameters.Add(OidcConstants.TokenRequest.RefreshToken, \"nonexistent\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task RefreshTokenTooLong()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var options = new IdentityServerOptions();\n\n            var validator = Factory.CreateTokenRequestValidator();\n            var longRefreshToken = \"x\".Repeat(options.InputLengthRestrictions.RefreshToken + 1);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"refresh_token\");\n            parameters.Add(OidcConstants.TokenRequest.RefreshToken, longRefreshToken);\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Expired_RefreshToken()\n        {\n            var refreshToken = new RefreshToken\n            {\n                AccessToken = new Token(\"access_token\") { ClientId = \"roclient\" },\n                Lifetime = 10,\n                CreationTime = DateTime.UtcNow.AddSeconds(-15)\n            };\n\n            var grants = Factory.CreateRefreshTokenStore();\n            var handle = await grants.StoreRefreshTokenAsync(refreshToken);\n\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n\n            var validator = Factory.CreateTokenRequestValidator(\n                refreshTokenStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"refresh_token\");\n            parameters.Add(OidcConstants.TokenRequest.RefreshToken, handle);\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Wrong_Client_Binding_RefreshToken_Request()\n        {\n            var refreshToken = new RefreshToken\n            {\n                AccessToken = new Token(\"access_token\")\n                {\n                    ClientId = \"otherclient\",\n                    Lifetime = 600,\n                    CreationTime = DateTime.UtcNow\n                }\n            };\n\n            var grants = Factory.CreateRefreshTokenStore();\n            var handle = await grants.StoreRefreshTokenAsync(refreshToken);\n\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n\n            var validator = Factory.CreateTokenRequestValidator(\n                refreshTokenStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"refresh_token\");\n            parameters.Add(OidcConstants.TokenRequest.RefreshToken, handle);\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Client_has_no_OfflineAccess_Scope_anymore_at_RefreshToken_Request()\n        {\n            var refreshToken = new RefreshToken\n            {\n                AccessToken = new Token(\"access_token\")\n                {\n                    ClientId = \"roclient_restricted\"\n                },\n                Lifetime = 600,\n                CreationTime = DateTime.UtcNow\n            };\n\n            var grants = Factory.CreateRefreshTokenStore();\n            var handle = await grants.StoreRefreshTokenAsync(refreshToken);\n\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient_restricted\");\n\n            var validator = Factory.CreateTokenRequestValidator(\n                refreshTokenStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"refresh_token\");\n            parameters.Add(OidcConstants.TokenRequest.RefreshToken, handle);\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task RefreshToken_Request_with_disabled_User()\n        {\n            var subjectClaim = new Claim(JwtClaimTypes.Subject, \"foo\");\n\n            var refreshToken = new RefreshToken\n            {\n                AccessToken = new Token(\"access_token\")\n                {\n                    Claims = new List<Claim> { subjectClaim },\n                    ClientId = \"roclient\"\n                },\n                Lifetime = 600,\n                CreationTime = DateTime.UtcNow\n            };\n\n            var grants = Factory.CreateRefreshTokenStore();\n            var handle = await grants.StoreRefreshTokenAsync(refreshToken);\n\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n\n            var validator = Factory.CreateTokenRequestValidator(\n                refreshTokenStore: grants,\n                profile: new TestProfileService(shouldBeActive: false));\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"refresh_token\");\n            parameters.Add(OidcConstants.TokenRequest.RefreshToken, handle);\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/TokenRequest Validation/TokenRequestValidation_ResourceOwner_Invalid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System.Collections.Specialized;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Common;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.TokenRequest_Validation\n{\n    public class TokenRequestValidation_ResourceOwner_Invalid\n    {\n        private const string Category = \"TokenRequest Validation - ResourceOwner - Invalid\";\n\n        private IClientStore _clients = Factory.CreateClientStore();\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_GrantType_For_Client()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.UnauthorizedClient);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Unknown_Scope()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"unknown\");\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"bob\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Unknown_Scope_Multiple()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource unknown\");\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"bob\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Restricted_Scope()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient_restricted\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource2\");\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"bob\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Restricted_Scope_Multiple()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient_restricted\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource resource2\");\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"bob\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidScope);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task No_ResourceOwnerCredentials()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_ResourceOwner_UserName()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"bob\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Invalid_ResourceOwner_Credentials()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"notbob\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n            result.ErrorDescription.Should().Be(\"invalid_username_or_password\");\n        }\n        \n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_ResourceOwner_password_for_user_with_password_should_fail()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob_with_password\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Password_GrantType_Not_Supported()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator(resourceOwnerValidator: new NotSupportedResourceOwnerPasswordValidator(TestLogger.Create<NotSupportedResourceOwnerPasswordValidator>()));\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"bob\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.UnsupportedGrantType);\n            result.ErrorDescription.Should().BeNull();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Inactive_ResourceOwner()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator(profile: new TestProfileService(shouldBeActive: false));\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"bob\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Password_GrantType_With_Custom_ErrorDescription()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator(resourceOwnerValidator: new TestResourceOwnerPasswordValidator(TokenRequestErrors.InvalidGrant, \"custom error description\"));\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"notbob\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.TokenErrors.InvalidGrant);\n            result.ErrorDescription.Should().Be(\"custom error description\");\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/TokenRequest Validation/TokenRequestValidation_Valid.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing System;\nusing System.Collections.Generic;\nusing System.Collections.Specialized;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8;\nusing IdentityServer8.Models;\nusing IdentityServer8.Stores;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation.TokenRequest_Validation\n{\n    public class TokenRequestValidation_Valid\n    {\n        private const string Category = \"TokenRequest Validation - General - Valid\";\n\n        private IClientStore _clients = Factory.CreateClientStore();\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Missing_ResourceOwner_password_for_user_with_no_password_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob_no_password\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n            result.ValidatedRequest.UserName.Should().Be(\"bob_no_password\");\n        }\n        \n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_code_request_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var grants = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                RedirectUri = \"https://server/cb\",\n                RequestedScopes = new List<string>\n                {\n                    \"openid\"\n                }\n            };\n\n            var handle = await grants.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_code_request_with_refresh_token_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"codeclient\");\n            var grants = Factory.CreateAuthorizationCodeStore();\n\n            var code = new AuthorizationCode\n            {\n                CreationTime = DateTime.UtcNow,\n                ClientId = client.ClientId,\n                Lifetime = client.AuthorizationCodeLifetime,\n                Subject = new IdentityServerUser(\"123\").CreatePrincipal(),\n                RedirectUri = \"https://server/cb\",\n                RequestedScopes = new List<string>\n                {\n                    \"openid\",\n                    \"offline_access\"\n                }\n            };\n\n            var handle = await grants.StoreAuthorizationCodeAsync(code);\n\n            var validator = Factory.CreateTokenRequestValidator(\n                authorizationCodeStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.AuthorizationCode);\n            parameters.Add(OidcConstants.TokenRequest.Code, handle);\n            parameters.Add(OidcConstants.TokenRequest.RedirectUri, \"https://server/cb\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_client_credentials_request_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_client_credentials_request_with_default_scopes_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client_restricted\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials);\n            \n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_client_credentials_request_for_implicit_and_client_credentials_client_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"implicit_and_client_creds_client\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_client_credentials_request_restricted_client_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"client_restricted\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.ClientCredentials);\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_resource_owner_request_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_resource_wwner_request_with_refresh_token_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource offline_access\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_resource_owner_request_restricted_client_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient_restricted\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.Password);\n            parameters.Add(OidcConstants.TokenRequest.UserName, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Password, \"bob\");\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task valid_extension_grant_request_should_succeed()\n        {\n            var client = await _clients.FindEnabledClientByIdAsync(\"customgrantclient\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"custom_grant\");\n            parameters.Add(OidcConstants.TokenRequest.Scope, \"resource\");\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_refresh_token_request_should_succeed()\n        {\n            var subjectClaim = new Claim(JwtClaimTypes.Subject, \"foo\");\n\n            var refreshToken = new RefreshToken\n            {\n                AccessToken = new Token(\"access_token\")\n                {\n                    Claims = new List<Claim> { subjectClaim },\n                    ClientId = \"roclient\"\n                },\n                Lifetime = 600,\n                CreationTime = DateTime.UtcNow\n            };\n\n            var grants = Factory.CreateRefreshTokenStore();\n            var handle = await grants.StoreRefreshTokenAsync(refreshToken);\n\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient\");\n\n            var validator = Factory.CreateTokenRequestValidator(\n                refreshTokenStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"refresh_token\");\n            parameters.Add(OidcConstants.TokenRequest.RefreshToken, handle);\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_refresh_token_request_using_restricted_client_should_succeed()\n        {\n            var subjectClaim = new Claim(JwtClaimTypes.Subject, \"foo\");\n\n            var refreshToken = new RefreshToken\n            {\n                AccessToken = new Token(\"access_token\")\n                {\n                    Claims = new List<Claim> { subjectClaim },\n                    ClientId = \"roclient_restricted_refresh\"\n                },\n\n                Lifetime = 600,\n                CreationTime = DateTime.UtcNow\n            };\n\n            var grants = Factory.CreateRefreshTokenStore();\n            var handle = await grants.StoreRefreshTokenAsync(refreshToken);\n\n            var client = await _clients.FindEnabledClientByIdAsync(\"roclient_restricted_refresh\");\n\n            var validator = Factory.CreateTokenRequestValidator(\n                refreshTokenStore: grants);\n\n            var parameters = new NameValueCollection();\n            parameters.Add(OidcConstants.TokenRequest.GrantType, \"refresh_token\");\n            parameters.Add(OidcConstants.TokenRequest.RefreshToken, handle);\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n\n            result.IsError.Should().BeFalse();\n        }\n        \n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task Valid_device_code_request_should_succeed()\n        {\n            var deviceCode = new DeviceCode\n            {\n                ClientId = \"device_flow\",\n                IsAuthorized = true,\n                Subject = new IdentityServerUser(\"bob\").CreatePrincipal(),\n                IsOpenId = true,\n                Lifetime = 300,\n                CreationTime = DateTime.UtcNow,\n                AuthorizedScopes = new[] { \"openid\", \"profile\", \"resource\" }\n            };\n\n            var client = await _clients.FindClientByIdAsync(\"device_flow\");\n\n            var validator = Factory.CreateTokenRequestValidator();\n\n            var parameters = new NameValueCollection\n            {\n                {OidcConstants.TokenRequest.GrantType, OidcConstants.GrantTypes.DeviceCode},\n                {\"device_code\", Guid.NewGuid().ToString()}\n            };\n\n            var result = await validator.ValidateRequestAsync(parameters, client.ToValidationResult());\n            result.IsError.Should().BeFalse();\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/Validation/UserInfoRequestValidation.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing IdentityModel;\nusing IdentityServer.UnitTests.Validation.Setup;\nusing IdentityServer8.Stores;\nusing IdentityServer8.Validation;\nusing System.Collections.Generic;\nusing System.Security.Claims;\nusing System.Threading.Tasks;\nusing IdentityServer.UnitTests.Common;\nusing Xunit;\n\nnamespace IdentityServer.UnitTests.Validation\n{\n    public class UserInfoRequestValidation\n    {\n        private const string Category = \"UserInfo Request Validation Tests\";\n        private IClientStore _clients = new InMemoryClientStore(TestClients.Get());\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task token_without_sub_should_fail()\n        {\n            var tokenResult = new TokenValidationResult\n            {\n                IsError = false,\n                Client = await _clients.FindEnabledClientByIdAsync(\"codeclient\"),\n                Claims = new List<Claim>()\n            };\n\n            var validator = new UserInfoRequestValidator(\n                new TestTokenValidator(tokenResult),\n                new TestProfileService(shouldBeActive: true),\n                TestLogger.Create<UserInfoRequestValidator>());\n\n            var result = await validator.ValidateRequestAsync(\"token\");\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task active_user_should_succeed()\n        {\n            var tokenResult = new TokenValidationResult\n            {\n                IsError = false,\n                Client = await _clients.FindEnabledClientByIdAsync(\"codeclient\"),\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"123\")\n                },\n            };\n\n            var validator = new UserInfoRequestValidator(\n                new TestTokenValidator(tokenResult),\n                new TestProfileService(shouldBeActive: true),\n                TestLogger.Create<UserInfoRequestValidator>());\n\n            var result = await validator.ValidateRequestAsync(\"token\");\n\n            result.IsError.Should().BeFalse();\n        }\n\n        [Fact]\n        [Trait(\"Category\", Category)]\n        public async Task inactive_user_should_fail()\n        {\n            var tokenResult = new TokenValidationResult\n            {\n                IsError = false,\n                Client = await _clients.FindEnabledClientByIdAsync(\"codeclient\"),\n                Claims = new List<Claim>\n                {\n                    new Claim(\"sub\", \"123\")\n                },\n            };\n\n            var validator = new UserInfoRequestValidator(\n                new TestTokenValidator(tokenResult),\n                new TestProfileService(shouldBeActive: false),\n                TestLogger.Create<UserInfoRequestValidator>());\n\n            var result = await validator.ValidateRequestAsync(\"token\");\n\n            result.IsError.Should().BeTrue();\n            result.Error.Should().Be(OidcConstants.ProtectedResourceErrors.InvalidToken);\n        }\n    }\n}\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/identityserver_testing.cer",
    "content": "-----BEGIN CERTIFICATE-----\nMIIDQTCCAimgAwIBAgIQO+9qzaJY9I5Ewq81kNEKWTANBgkqhkiG9w0BAQsFADAh\nMR8wHQYDVQQDDBZpZGVudGl0eXNlcnZlcl90ZXN0aW5nMCAXDTIwMDEyMjIzMTYz\nOFoYDzIxMDMwNTIyMjMyNjM5WjAhMR8wHQYDVQQDDBZpZGVudGl0eXNlcnZlcl90\nZXN0aW5nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuyZQvE+6gEoB\na+LV3dxjk/Xj4DRJ/tefQKR2AZoYAAfKN4ditFmEfRC1A6rckBpMVihTeb1kwwQT\n7H4HTS6O/ERHVjOdghoOjEsVakWhAkvh8gphC4IU0upXlYqMh2WzgXEXwYRFB9Tk\n7zoHb1/zjEEAhCf2Xbi6YslBoU71bFWyAaeOTl859wV6WaiBIK5L8nJUaIaq4zmC\nk8caPZq5E867mZiMdL4TcW9/YoAAO96Wa/W9o6OiuZrP414TlEjVuccpLXvjk0hB\nU5OZD2bTvD3MQZu1n1QMLwXfaOBrcv1/RqYJkK7vpP6Pp1YYlo7b2PBDVAIrRSVT\nlaViBP0owQIDAQABo3MwcTAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYB\nBQUHAwIGCCsGAQUFBwMBMCEGA1UdEQQaMBiCFmlkZW50aXR5c2VydmVyX3Rlc3Rp\nbmcwHQYDVR0OBBYEFCVXNpKp8QlHywXEBFfpXxWcOMcsMA0GCSqGSIb3DQEBCwUA\nA4IBAQBsEAzwyN6V6N5ggN9G1O0ZpviSjixGkWtySNCBjbGXAhOvfW4M3ysNkDwZ\nltk/Q17ihZzw135MrDCmnr5pRiN4CbEGbe1qsb+Z0uCCn8/WcIVYYooW66H/Jez+\ndg5RxUukA67ZDnjzRskIer7L2t1C4pDqpvPVcneUxkiYDSgcKpTuCVjkPNQKQTIw\nSm98NkQG8G8V8+ENIU837ytkiC5nqQa4zDRHexzWrYhiuayWWxJKcNRVF9YaE8ts\nvp5N1ewmWbSgF8caJuKraVOISj9R4iqf0XuhfSpW/7eIWYmXfqy/UloeqlALfP5C\n2d2FdDSfsQ4Jgc3ebrECAQaCC3Gq\n-----END CERTIFICATE-----\n"
  },
  {
    "path": "src/IdentityServer8/test/IdentityServer.UnitTests/xunit.runner.json",
    "content": "﻿{\n  \"methodDisplay\":\"classAndMethod\"\n}\n"
  },
  {
    "path": "src/IdentityServer8.sln",
    "content": "Microsoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio Version 17\nVisualStudioVersion = 17.8.34322.80\nMinimumVisualStudioVersion = 10.0.40219.1\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{5461C61B-B06E-46BA-B206-925B660BE727}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"test\", \"test\", \"{45C22EDD-91B1-4AEF-8620-77F4E3E7C544}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8\", \"IdentityServer8\\src\\IdentityServer8.csproj\", \"{407C030E-60E6-41F7-AF43-0AC48EDCC17D}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Host\", \"IdentityServer8\\host\\Host.csproj\", \"{784B3C88-30FA-415D-B99E-584063064508}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer.UnitTests\", \"IdentityServer8\\test\\IdentityServer.UnitTests\\IdentityServer.UnitTests.csproj\", \"{4291820C-735F-4776-8BC4-6527433BC683}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer.IntegrationTests\", \"IdentityServer8\\test\\IdentityServer.IntegrationTests\\IdentityServer.IntegrationTests.csproj\", \"{94501373-478A-478D-8C17-6AC52E3438CF}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.EntityFramework.Storage\", \"EntityFramework.Storage\\src\\IdentityServer8.EntityFramework.Storage.csproj\", \"{5302DAB3-1662-4956-97AA-5EA5E85B10F6}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.EntityFramework.UnitTests\", \"EntityFramework.Storage\\test\\UnitTests\\IdentityServer8.EntityFramework.UnitTests.csproj\", \"{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.EntityFramework.IntegrationTests\", \"EntityFramework.Storage\\test\\IntegrationTests\\IdentityServer8.EntityFramework.IntegrationTests.csproj\", \"{E90F7470-C7F8-464B-9C28-87C474085812}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"migrations\", \"migrations\", \"{E3EF31E0-6658-4899-8BDA-FF84355E2FDD}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"SqlServer\", \"EntityFramework.Storage\\migrations\\SqlServer\\SqlServer.csproj\", \"{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"host\", \"host\", \"{07C56E10-A807-4372-ACD9-ADED2D099BC8}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"ConsoleHost\", \"EntityFramework.Storage\\host\\ConsoleHost\\ConsoleHost.csproj\", \"{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"IdentityServer\", \"IdentityServer\", \"{37FCD1F7-B8CB-4D7B-A2E8-0AE458652314}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"EntityFramework.Storage\", \"EntityFramework.Storage\", \"{28C914A4-BC3B-4D55-8799-C8A4A6AD724E}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"IdentityServer\", \"IdentityServer\", \"{E5F41733-E9B8-4EA8-A5A3-620827B68340}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"EntityFramework.Storage\", \"EntityFramework.Storage\", \"{6F2785D9-4208-4A9F-85B0-674185D393C5}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Storage\", \"Storage\", \"{19B12297-DCC0-4529-A04C-5B0E2C0F01B9}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Storage\", \"Storage\", \"{6CB8A0D7-77D4-411B-953C-A4AB50F56205}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.Storage\", \"Storage\\src\\IdentityServer8.Storage.csproj\", \"{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.AspNetIdentity\", \"AspNetIdentity\\src\\IdentityServer8.AspNetIdentity.csproj\", \"{A2CDBE15-5898-4A04-94DC-133EE03A78B3}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Host\", \"AspNetIdentity\\host\\Host.csproj\", \"{B7FBA07C-A462-4869-AF94-5E36DFC3742D}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"SqlServer\", \"AspNetIdentity\\migrations\\SqlServer\\SqlServer.csproj\", \"{DD44B9E9-C32E-4F89-92C9-25444A709BBB}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.EntityFramework\", \"EntityFramework\\src\\IdentityServer8.EntityFramework.csproj\", \"{AB83F911-8B78-4973-A3A9-2A2D85581F25}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"SqlServer\", \"EntityFramework\\migrations\\SqlServer\\SqlServer.csproj\", \"{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.EntityFramework.Tests\", \"EntityFramework\\test\\IdentityServer8.EntityFramework.Tests\\IdentityServer8.EntityFramework.Tests.csproj\", \"{E3685B06-F135-4318-B841-889C35479D5C}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Solution Files\", \"Solution Files\", \"{29DC1E06-3EC5-4F52-9EC1-0363BD571369}\"\n\tProjectSection(SolutionItems) = preProject\n\t\t..\\.gitignore = ..\\.gitignore\n\t\t..\\Directory.Build.props = ..\\Directory.Build.props\n\t\t..\\Directory.Build.targets = ..\\Directory.Build.targets\n\t\tDirectory.BuildOld.targets = Directory.BuildOld.targets\n\t\t..\\Directory.Packages.props = ..\\Directory.Packages.props\n\t\t..\\global.json = ..\\global.json\n\t\t..\\IdentityServer8.DotNet.ruleset = ..\\IdentityServer8.DotNet.ruleset\n\t\t..\\LICENSE = ..\\LICENSE\n\t\t..\\LicenseHeader.txt = ..\\LicenseHeader.txt\n\t\t..\\NuGet.config = ..\\NuGet.config\n\t\t..\\README.md = ..\\README.md\n\t\t..\\SECURITY.MD = ..\\SECURITY.MD\n\t\t..\\SPONSORS.md = ..\\SPONSORS.md\n\t\t..\\version.json = ..\\version.json\n\tEndProjectSection\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"AspNetIdentity\", \"AspNetIdentity\", \"{7849D7DE-FD6A-4A5B-A793-5DCFFCDDC944}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"EntityFramework\", \"EntityFramework\", \"{06FC2C45-FCD6-469C-8F2D-3E1A750D1EF9}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"EntityFramework\", \"EntityFramework\", \"{39F7E2E8-1EAB-4163-8E4D-43CBB23AB871}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \".github\", \".github\", \"{A7171FEC-FEC1-4AF0-9625-E69D93F08A42}\"\n\tProjectSection(SolutionItems) = preProject\n\t\t..\\.github\\CONTRIBUTING.md = ..\\.github\\CONTRIBUTING.md\n\t\t..\\.github\\dependabot.yml = ..\\.github\\dependabot.yml\n\t\t..\\.github\\FUNDING.yml = ..\\.github\\FUNDING.yml\n\t\t..\\.github\\PULL_REQUEST_TEMPLATE.md = ..\\.github\\PULL_REQUEST_TEMPLATE.md\n\tEndProjectSection\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"issuetemplate\", \"issuetemplate\", \"{0BC5E76A-A280-49C8-8E96-A43FEA357A4B}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"workflows\", \"workflows\", \"{C5474352-0715-41C0-92C2-BABA1A4103A0}\"\n\tProjectSection(SolutionItems) = preProject\n\t\t..\\.github\\workflows\\codeql.yml = ..\\.github\\workflows\\codeql.yml\n\t\t..\\.github\\workflows\\develop.yml = ..\\.github\\workflows\\develop.yml\n\t\t..\\.github\\workflows\\master.yml = ..\\.github\\workflows\\master.yml\n\t\t..\\.github\\workflows\\pre-release.yml = ..\\.github\\workflows\\pre-release.yml\n\t\t..\\.github\\workflows\\release.yml = ..\\.github\\workflows\\release.yml\n\tEndProjectSection\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"docs\", \"docs\", \"{21B3EAAF-1A7D-4D46-AB3F-843296EDBDC2}\"\n\tProjectSection(SolutionItems) = preProject\n\t\t..\\docs\\CHANGELOG.md = ..\\docs\\CHANGELOG.md\n\tEndProjectSection\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Security\", \"Security\", \"{9B9C47C4-560E-4F2E-8F53-97F9FDE46008}\"\nEndProject\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"Security\", \"Security\", \"{19B652D0-0AA1-415C-AA62-065EE8C77182}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.Security\", \"Security\\IdentityServer8.Security\\IdentityServer8.Security.csproj\", \"{284DF9E0-8007-4E84-949D-5B610D76B1CF}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.Sanitizer.Tests\", \"Security\\test\\IdentityServer8.Santizer.Tests\\IdentityServer8.Sanitizer.Tests.csproj\", \"{00BDF864-B06A-4A48-B8B4-85C219B33CD1}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"Host\", \"EntityFramework\\host\\Host.csproj\", \"{C7939ADD-36C9-444F-A773-28EC81587831}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tRelease|Any CPU = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{407C030E-60E6-41F7-AF43-0AC48EDCC17D}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{407C030E-60E6-41F7-AF43-0AC48EDCC17D}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{407C030E-60E6-41F7-AF43-0AC48EDCC17D}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{407C030E-60E6-41F7-AF43-0AC48EDCC17D}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{784B3C88-30FA-415D-B99E-584063064508}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{784B3C88-30FA-415D-B99E-584063064508}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{784B3C88-30FA-415D-B99E-584063064508}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{784B3C88-30FA-415D-B99E-584063064508}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{4291820C-735F-4776-8BC4-6527433BC683}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{4291820C-735F-4776-8BC4-6527433BC683}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{4291820C-735F-4776-8BC4-6527433BC683}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{4291820C-735F-4776-8BC4-6527433BC683}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{94501373-478A-478D-8C17-6AC52E3438CF}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{94501373-478A-478D-8C17-6AC52E3438CF}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{94501373-478A-478D-8C17-6AC52E3438CF}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{94501373-478A-478D-8C17-6AC52E3438CF}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{A2CDBE15-5898-4A04-94DC-133EE03A78B3}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{A2CDBE15-5898-4A04-94DC-133EE03A78B3}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{A2CDBE15-5898-4A04-94DC-133EE03A78B3}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{A2CDBE15-5898-4A04-94DC-133EE03A78B3}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{B7FBA07C-A462-4869-AF94-5E36DFC3742D}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{B7FBA07C-A462-4869-AF94-5E36DFC3742D}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{B7FBA07C-A462-4869-AF94-5E36DFC3742D}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{B7FBA07C-A462-4869-AF94-5E36DFC3742D}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{DD44B9E9-C32E-4F89-92C9-25444A709BBB}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{DD44B9E9-C32E-4F89-92C9-25444A709BBB}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{DD44B9E9-C32E-4F89-92C9-25444A709BBB}.Release|Any CPU.ActiveCfg = Release|Any CPU\t\t\n\t\t{AB83F911-8B78-4973-A3A9-2A2D85581F25}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{AB83F911-8B78-4973-A3A9-2A2D85581F25}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{AB83F911-8B78-4973-A3A9-2A2D85581F25}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{AB83F911-8B78-4973-A3A9-2A2D85581F25}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{E3685B06-F135-4318-B841-889C35479D5C}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{E3685B06-F135-4318-B841-889C35479D5C}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{E3685B06-F135-4318-B841-889C35479D5C}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{E3685B06-F135-4318-B841-889C35479D5C}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{284DF9E0-8007-4E84-949D-5B610D76B1CF}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{284DF9E0-8007-4E84-949D-5B610D76B1CF}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{284DF9E0-8007-4E84-949D-5B610D76B1CF}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{284DF9E0-8007-4E84-949D-5B610D76B1CF}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{00BDF864-B06A-4A48-B8B4-85C219B33CD1}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{00BDF864-B06A-4A48-B8B4-85C219B33CD1}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{00BDF864-B06A-4A48-B8B4-85C219B33CD1}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{00BDF864-B06A-4A48-B8B4-85C219B33CD1}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{C7939ADD-36C9-444F-A773-28EC81587831}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{C7939ADD-36C9-444F-A773-28EC81587831}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{C7939ADD-36C9-444F-A773-28EC81587831}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{C7939ADD-36C9-444F-A773-28EC81587831}.Release|Any CPU.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{407C030E-60E6-41F7-AF43-0AC48EDCC17D} = {E5F41733-E9B8-4EA8-A5A3-620827B68340}\n\t\t{784B3C88-30FA-415D-B99E-584063064508} = {E5F41733-E9B8-4EA8-A5A3-620827B68340}\n\t\t{4291820C-735F-4776-8BC4-6527433BC683} = {37FCD1F7-B8CB-4D7B-A2E8-0AE458652314}\n\t\t{94501373-478A-478D-8C17-6AC52E3438CF} = {37FCD1F7-B8CB-4D7B-A2E8-0AE458652314}\n\t\t{5302DAB3-1662-4956-97AA-5EA5E85B10F6} = {6F2785D9-4208-4A9F-85B0-674185D393C5}\n\t\t{8239FC82-46A3-4F21-8D05-1F0BE0B1B1FC} = {28C914A4-BC3B-4D55-8799-C8A4A6AD724E}\n\t\t{E90F7470-C7F8-464B-9C28-87C474085812} = {28C914A4-BC3B-4D55-8799-C8A4A6AD724E}\n\t\t{E3EF31E0-6658-4899-8BDA-FF84355E2FDD} = {6F2785D9-4208-4A9F-85B0-674185D393C5}\n\t\t{A93A59EC-D75D-44E1-9720-F75D9EF95BC3} = {E3EF31E0-6658-4899-8BDA-FF84355E2FDD}\n\t\t{07C56E10-A807-4372-ACD9-ADED2D099BC8} = {6F2785D9-4208-4A9F-85B0-674185D393C5}\n\t\t{2AA5AC6B-531B-426E-AD38-5B03F1949CF5} = {07C56E10-A807-4372-ACD9-ADED2D099BC8}\n\t\t{37FCD1F7-B8CB-4D7B-A2E8-0AE458652314} = {45C22EDD-91B1-4AEF-8620-77F4E3E7C544}\n\t\t{28C914A4-BC3B-4D55-8799-C8A4A6AD724E} = {45C22EDD-91B1-4AEF-8620-77F4E3E7C544}\n\t\t{E5F41733-E9B8-4EA8-A5A3-620827B68340} = {5461C61B-B06E-46BA-B206-925B660BE727}\n\t\t{6F2785D9-4208-4A9F-85B0-674185D393C5} = {5461C61B-B06E-46BA-B206-925B660BE727}\n\t\t{19B12297-DCC0-4529-A04C-5B0E2C0F01B9} = {5461C61B-B06E-46BA-B206-925B660BE727}\n\t\t{6CB8A0D7-77D4-411B-953C-A4AB50F56205} = {45C22EDD-91B1-4AEF-8620-77F4E3E7C544}\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7} = {19B12297-DCC0-4529-A04C-5B0E2C0F01B9}\n\t\t{A2CDBE15-5898-4A04-94DC-133EE03A78B3} = {7849D7DE-FD6A-4A5B-A793-5DCFFCDDC944}\n\t\t{B7FBA07C-A462-4869-AF94-5E36DFC3742D} = {7849D7DE-FD6A-4A5B-A793-5DCFFCDDC944}\n\t\t{DD44B9E9-C32E-4F89-92C9-25444A709BBB} = {7849D7DE-FD6A-4A5B-A793-5DCFFCDDC944}\n\t\t{AB83F911-8B78-4973-A3A9-2A2D85581F25} = {06FC2C45-FCD6-469C-8F2D-3E1A750D1EF9}\n\t\t{D9FABEC8-09DC-4B0D-80D7-86FA6C5D9C69} = {06FC2C45-FCD6-469C-8F2D-3E1A750D1EF9}\n\t\t{E3685B06-F135-4318-B841-889C35479D5C} = {39F7E2E8-1EAB-4163-8E4D-43CBB23AB871}\n\t\t{7849D7DE-FD6A-4A5B-A793-5DCFFCDDC944} = {5461C61B-B06E-46BA-B206-925B660BE727}\n\t\t{06FC2C45-FCD6-469C-8F2D-3E1A750D1EF9} = {5461C61B-B06E-46BA-B206-925B660BE727}\n\t\t{39F7E2E8-1EAB-4163-8E4D-43CBB23AB871} = {45C22EDD-91B1-4AEF-8620-77F4E3E7C544}\n\t\t{A7171FEC-FEC1-4AF0-9625-E69D93F08A42} = {29DC1E06-3EC5-4F52-9EC1-0363BD571369}\n\t\t{0BC5E76A-A280-49C8-8E96-A43FEA357A4B} = {A7171FEC-FEC1-4AF0-9625-E69D93F08A42}\n\t\t{C5474352-0715-41C0-92C2-BABA1A4103A0} = {A7171FEC-FEC1-4AF0-9625-E69D93F08A42}\n\t\t{21B3EAAF-1A7D-4D46-AB3F-843296EDBDC2} = {29DC1E06-3EC5-4F52-9EC1-0363BD571369}\n\t\t{9B9C47C4-560E-4F2E-8F53-97F9FDE46008} = {5461C61B-B06E-46BA-B206-925B660BE727}\n\t\t{19B652D0-0AA1-415C-AA62-065EE8C77182} = {45C22EDD-91B1-4AEF-8620-77F4E3E7C544}\n\t\t{284DF9E0-8007-4E84-949D-5B610D76B1CF} = {9B9C47C4-560E-4F2E-8F53-97F9FDE46008}\n\t\t{00BDF864-B06A-4A48-B8B4-85C219B33CD1} = {19B652D0-0AA1-415C-AA62-065EE8C77182}\n\t\t{C7939ADD-36C9-444F-A773-28EC81587831} = {06FC2C45-FCD6-469C-8F2D-3E1A750D1EF9}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {176723F7-4A9B-4F05-A9F3-3BA715E4BDC3}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "src/IdentityServer8.sln.licenseheader",
    "content": "extensions: designer.cs generated.cs\nextensions: .cs \n/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n"
  },
  {
    "path": "src/Security/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "src/Security/IdentityServer8.Security/Extensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\npublic class Ioc\n{\n    static Ioc()\n    {\n        var services = new ServiceCollection();\n        services.AddLogging();\n        services.AddSanitizers();\n        services.AddAllowAnyRedirectService();\n        services.AddSingleton<IRedirectService, AllowAnyRedirectService>();\n        ServiceProvider = services.BuildServiceProvider();\n        var sanitizer = ServiceProvider.GetRequiredService<ISanitizer>();\n        Sanitizer = sanitizer;\n        var redirectService = ServiceProvider.GetRequiredService<IRedirectService>();\n        RedirectService = redirectService;\n    }\n\n    public static ServiceProvider ServiceProvider { get; }\n    public static ISanitizer Sanitizer { get; }\n    public static IRedirectService RedirectService { get; }\n\n}\n"
  },
  {
    "path": "src/Security/IdentityServer8.Security/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityServer8.Security;\nglobal using Microsoft.AspNetCore.Http;\nglobal using Microsoft.Extensions.DependencyInjection;\nglobal using Microsoft.Extensions.Logging;\nglobal using System.Net;\nglobal using System.Web;\n"
  },
  {
    "path": "src/Security/IdentityServer8.Security/IdentityServer8.Security.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n    <PropertyGroup>\n        <Description>Security package for user input sanitzation IdentityServer8 services and packages.</Description>\n        <IsPackable>true</IsPackable>\n        <GeneratePackageOnBuild>true</GeneratePackageOnBuild>\n        <ImplicitUsings>enable</ImplicitUsings>\n        <Nullable>enable</Nullable>\n    </PropertyGroup>\n\n    <ItemGroup>\n        <PackageReference Include=\"Microsoft.AspNetCore.Http.Abstractions\" />\n        <PackageReference Include=\"Microsoft.AspNetCore.Mvc.Abstractions\" />\n        <PackageReference Include=\"Microsoft.Extensions.DependencyInjection\" />\n        <PackageReference Include=\"Microsoft.Extensions.DependencyInjection.Abstractions\" />\n        <PackageReference Include=\"Microsoft.Extensions.Logging.Abstractions\" />\n        <PackageReference Include=\"Microsoft.Extensions.Logging\" />\n    </ItemGroup>\n\n</Project>\n"
  },
  {
    "path": "src/Security/IdentityServer8.Security/RedirectService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Security;\n\npublic interface IRedirectService\n{\n    bool IsRedirectAllowed(string redirectUrl);\n}\n\n\npublic class RuleMatcher\n{\n    public bool IsMatch(string url, RedirectRule rule)\n    {\n        throw new NotImplementedException();\n    }\n}\npublic class RedirectRule\n{\n    public static RedirectRule AllowAny\n        => new RedirectRule();\n\n    public RedirectRule()\n    {\n        AllowedFragment = Fragment.Any;\n        AllowedPath = Path.Any;\n        AllowedPort = Port.Any;\n        AllowedQuery = Query.Any;\n        AllowedScheme = Scheme.Any;\n        AllowedHost = Host.Any;\n    }\n    public Scheme AllowedScheme { get; set; }\n    public Host AllowedHost { get; set; }\n    public Port AllowedPort { get; set; }\n    public Path AllowedPath { get; set; }\n    public Query AllowedQuery { get; set; }\n    public Fragment AllowedFragment { get; set; }\n}\n\npublic class Scheme\n{\n    public Scheme(string name) { Name = name; }\n    public string Name { get; }\n\n    public static readonly Scheme Http = new Scheme(\"http\");\n    public static readonly Scheme Https = new Scheme(\"https\");\n    public static readonly Scheme Any = new Scheme(\"*\");\n\n    public static Scheme Parse(string schemeName)\n    {\n        if (string.IsNullOrWhiteSpace(schemeName))\n        {\n            throw new ArgumentException(\"Scheme name cannot be null or empty\");\n        }\n        else if (schemeName.Equals(\"http\", StringComparison.OrdinalIgnoreCase))\n        {\n            return Http;\n        }\n        else if (schemeName.Equals(\"https\", StringComparison.OrdinalIgnoreCase))\n        {\n            return Https;\n        }\n        else if (schemeName.Equals(\"*\", StringComparison.OrdinalIgnoreCase))\n        {\n            return Any;\n        }\n        else\n        {\n            throw new ArgumentException(\"Invalid scheme name\");\n        }\n\n    }\n\n    public override string ToString()\n    {\n        return Name;\n    }\n}\n\npublic class Host\n{\n    public Host(string value)\n    {\n        Value = ((value ?? \"\").ToLower().Trim() ?? \"\");\n        var domainParts = Value.Split('.');\n        domainParts = domainParts.Where(x => !string.IsNullOrEmpty(x)).ToArray();\n        HostParts = new List<string>(domainParts);\n    }\n    public List<string> HostParts;\n\n    public string Value { get; }\n\n    public static readonly Host Any = new Host(\"*\");\n\n    public static Host Create(string hostname) => new Host(hostname);\n\n    public bool HasWildcard => Value.Contains(\"*.\");\n    public bool IsAny => Value == \"*\";\n    public bool IsLocalhost => Value.Equals(\"localhost\", StringComparison.OrdinalIgnoreCase) || Value.Equals(\"127.0.0.1\");\n    public bool IsIpAddress => Uri.CheckHostName(Value) == UriHostNameType.IPv4 || Uri.CheckHostName(Value) == UriHostNameType.IPv6;\n    public bool IsLocalNetwork => IsLocalhost || IsIpAddress;\n    public bool IsFullQualifiedDomainName => !IsLocalNetwork && !HasWildcard && !IsAny && Value.IndexOf('.') > -1;\n\n}\n\npublic class Port\n{\n    public Port(int value) { Value = value; }\n    public int Value { get; }\n\n    public static readonly Port Any = new Port(-1); // Assuming -1 signifies any port\n\n    public static Port Create(int portNumber) => new Port(portNumber);\n}\n\npublic class Path\n{\n    public Path(string value) { Value = value; }\n    public string Value { get; }\n\n    public static readonly Path Any = new Path(\"*\");\n\n    public static Path Create(string path) => new Path(path);\n}\n\npublic class Query\n{\n    public Query(string value) { Value = value; }\n    public string Value { get; }\n\n    public static readonly Query Any = new Query(\"*\");\n\n    public static Query Create(string query) => new Query(query);\n}\n\npublic class Fragment\n{\n    public Fragment(string value) { Value = value; }\n    public string Value { get; }\n\n    public static readonly Fragment Any = new Fragment(\"*\");\n\n    public static Fragment Create(string fragment) => new Fragment(fragment);\n}\n\n\npublic class RedirectValidition\n{\n    static RedirectValidition()\n    {\n        var provider = new ServiceCollection()\n            .AddLogging()\n            .AddSingleton<IRedirectService, RedirectService>()\n            .AddSanitizers()\n            .BuildServiceProvider();\n        ServiceProvider = provider;\n\n    }\n\n    public static ServiceProvider ServiceProvider { get; }\n}\n\npublic static class RedirectServiceExtensions\n{\n\n    public static IServiceCollection AddAllowAnyRedirectService(this IServiceCollection services)\n    {\n        services.AddSingleton<AllowAnyRedirectService>();\n        return services;\n    }\n}\n\npublic class AllowAnyRedirectService : RedirectService\n{\n    public AllowAnyRedirectService(ILogger<RedirectService> logger, ISanitizer sanitizer) : base(logger, sanitizer)\n    {\n        AddRedirectRule(RedirectRule.AllowAny);\n    }\n}\n\npublic class RedirectService : IRedirectService\n{\n    public RedirectService(ILogger<RedirectService> logger, ISanitizer sanitizer)\n    {\n        _logger = logger;\n        _sanitizer = sanitizer;\n    }\n    private readonly List<RedirectRule> _rules = new List<RedirectRule>();\n    private readonly ILogger<RedirectService> _logger;\n    private readonly ISanitizer _sanitizer;\n\n    public IRedirectService AddRedirectRule(RedirectRule rule)\n    {\n        _rules.Add(rule);\n        return this;\n    }\n    public IRedirectService ClearRules()\n    {\n        _rules.Clear();\n        return this;\n    }\n\n    public IRedirectService AddRule(RedirectRule rule)\n    {\n        _rules.Add(rule);\n        return this;\n    }\n\n    public IRedirectService RemoveRule(RedirectRule rule)\n    {\n        _rules.Remove(rule);\n        return this;\n    }\n    public IRedirectService AddRules(IEnumerable<RedirectRule> rules)\n    {\n        _rules.AddRange(rules);\n        return this;\n    }\n    public IRedirectService RemoveRules(IEnumerable<RedirectRule> rules)\n    {\n        foreach (var rule in rules)\n        {\n            RemoveRule(rule);\n        }\n        return this;\n    }\n\n    public virtual bool IsRedirectAllowed(string redirectUrl)\n    {\n        if (!Uri.TryCreate(redirectUrl, UriKind.RelativeOrAbsolute, out var uri))\n        {\n            _logger.LogWarning(\"Invalid URL: {redirectUrl}\", redirectUrl.SanitizeForLog());\n            return false;\n        }\n\n        // If the URL is relative, assume it's allowed, or handle according to your policy\n        if (!uri.IsAbsoluteUri)\n        {\n            // Handle relative URLs based on your specific requirements.\n            // For example, we might always allow them, check them against a specific set of rules,\n            // or reject them outright.\n            return HandleRelativeUrl(uri);\n        }\n\n        foreach (var rule in _rules)\n        {\n            if (IsRuleMatch(uri, rule))\n            {\n                return true;\n            }\n        }\n\n        return false;\n    }\n\n    public bool HandleRelativeUrl(Uri uri)\n    {\n        // Implement logic for handling relative URLs on local server.\n        // This is a placeholder as restricting redirect URLs on the local server is not a common scenario.\n        // For now: return true to allow all relative URLs\n        return true;\n    }\n\n\n    public bool IsRuleMatch(Uri uri, RedirectRule rule)\n    {\n        return IsSchemeMatch(uri, rule.AllowedScheme) &&\n               IsHostMatch(uri, rule.AllowedHost) &&\n               IsPortMatch(uri, rule.AllowedPort) &&\n               IsPathMatch(uri, rule.AllowedPath) &&\n               IsQueryMatch(uri, rule.AllowedQuery) &&\n               IsFragmentMatch(uri, rule.AllowedFragment);\n    }\n\n    public bool IsSchemeMatch(Uri uri, Scheme allowedScheme)\n    {\n        return allowedScheme == Scheme.Any || uri.Scheme.Equals(allowedScheme.Name, StringComparison.OrdinalIgnoreCase);\n    }\n\n    public bool IsHostMatch(string url, Host allowedHost)\n    {\n        if (string.IsNullOrWhiteSpace(url))\n        {\n            return false;\n        }\n\n        if (allowedHost == Host.Any)\n        {\n            return true;\n        }\n\n        // Check if URL already has a valid scheme; if not, prepend \"http://\" as a default\n        if (!url.StartsWith(\"http://\", StringComparison.OrdinalIgnoreCase) &&\n            !url.StartsWith(\"https://\", StringComparison.OrdinalIgnoreCase))\n        {\n            url = \"http://\" + url;\n        }\n\n        // Attempt to parse the URL into a Uri object\n        if (Uri.TryCreate(url, UriKind.Absolute, out var uri))\n        {\n            // Delegate to the existing IsHostMatch method that takes a Uri object\n            return IsHostMatch(uri, allowedHost);\n        }\n        else\n        {\n            // Log error or handle invalid URL format as needed\n            return false;\n        }\n    }\n\n\n    public bool IsHostMatch(Uri uri, Host allowedHost)\n    {\n        // Handle the case where any host is allowed\n        if (allowedHost == Host.Any)\n        {\n            return true;\n        }\n\n        string uriHost = uri.Host;\n        string allowedHostValue = allowedHost.Value;\n\n        // Direct match or wildcard match\n        if (uriHost.Equals(allowedHostValue, StringComparison.OrdinalIgnoreCase) ||\n            allowedHostValue == \"*\")\n        {\n            return true;\n        }\n\n        // Check for wildcard subdomain match\n        if (allowedHostValue.StartsWith(\"*.\"))\n        {\n            string allowedDomain = allowedHostValue.Substring(2);\n            if (uriHost.EndsWith(allowedDomain, StringComparison.OrdinalIgnoreCase) &&\n                // Additional check to ensure we're matching subdomains and not just any part of the host\n                (uriHost.Count(c => c == '.') == allowedDomain.Count(c => c == '.') + 1))\n            {\n                return true;\n            }\n        }\n\n        return false;\n    }\n\n    public bool IsPortMatch(Uri uri, Port allowedPort)\n    {\n        return allowedPort == Port.Any || uri.Port == allowedPort.Value;\n    }\n\n    public bool IsPathMatch(Uri uri, Path allowedPath)\n    {\n        return allowedPath == Path.Any || uri.AbsolutePath.Equals(allowedPath.Value, StringComparison.OrdinalIgnoreCase);\n    }\n\n    public bool IsQueryMatch(Uri uri, Query allowedQuery)\n    {\n        return allowedQuery == Query.Any || uri.Query.Equals(allowedQuery.Value, StringComparison.OrdinalIgnoreCase);\n    }\n\n    public bool IsFragmentMatch(Uri uri, Fragment allowedFragment)\n    {\n        return allowedFragment == Fragment.Any || uri.Fragment.Equals(allowedFragment.Value, StringComparison.OrdinalIgnoreCase);\n    }\n\n}\n\n\npublic class RedirectUrlValidator\n{\n    private readonly IRedirectService _redirectService;\n\n    public RedirectUrlValidator(IRedirectService redirectService)\n    {\n        _redirectService = redirectService;\n    }\n\n    public bool IsRedirectUrlValid(string redirectUrl)\n    {\n        return _redirectService.IsRedirectAllowed(redirectUrl);\n    }\n}\n"
  },
  {
    "path": "src/Security/IdentityServer8.Security/RedirectUrlParser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Security;\n\npublic readonly ref struct RedirectUrlS\n{\n    private readonly ReadOnlySpan<char> _input;\n\n    public RedirectUrlS(string input)\n    {\n        _input = input.AsSpan();\n    }\n\n    //public RedirectUrlS Parse()\n    //{\n    //    // Default values representing wildcards\n    //    var scheme = Scheme.Any;\n    //    var host = Host.Any;\n    //    var port = Port.Any;\n    //    var path = Path.Any;\n    //    var query = Query.Any;\n    //    var fragment = Fragment.Any;\n    //    int offset = 0;\n    //    int schemeEnd = _input.IndexOf(\"://\");\n    //    if (schemeEnd != -1)\n    //    {\n    //        scheme = new Scheme(_input.Slice(0, schemeEnd).ToString());\n    //        offset = schemeEnd + 3;\n    //    }\n\n    //    int pathStart = _input.IndexOf('/');\n    //    int portEnd = _input.Slice(0, pathStart != -1 ? pathStart : _input.Length).IndexOf(':');\n\n    //    if (portEnd != -1)\n    //    {\n    //        host = new Host(_input.Slice(0, portEnd).ToString());\n    //        port = new Port(int.Parse(_input.Slice(portEnd + 1, pathStart - portEnd - 1).ToString()));\n    //    }\n    //    else if (pathStart != -1)\n    //    {\n    //        host = new Host(_input.Slice(0, pathStart).ToString());\n    //    }\n    //    else\n    //    {\n    //        host = new Host(_input.ToString());\n    //    }\n\n    //    if (pathStart != -1)\n    //    {\n    //        offset = pathStart;\n    //        int queryStart = _input.IndexOf('?');\n    //        int fragmentStart = _input.IndexOf('#');\n\n    //        if (queryStart != -1)\n    //        {\n    //            path = new Path(_input.Slice(0, queryStart).ToString());\n    //            offset = queryStart + 1;\n\n\n    //            if (fragmentStart != -1)\n    //            {\n    //                query = new Query(_input.Slice(0, fragmentStart - queryStart - 1).ToString());\n    //                fragment = new Fragment(_input.Slice(fragmentStart + 1).ToString());\n    //            }\n    //            else\n    //            {\n    //                query = new Query(_input.ToString());\n    //            }\n    //        }\n    //        else if (fragmentStart != -1)\n    //        {\n    //            path = new Path(_input.Slice(0, fragmentStart).ToString());\n    //            fragment = new Fragment(_input.Slice(fragmentStart + 1).ToString());\n    //        }\n    //        else\n    //        {\n    //            path = new Path(_input.ToString());\n    //        }\n    //    }\n\n    //    return new RedirectUrl\n    //    {\n    //        Scheme = scheme,\n    //        Host = host,\n    //        Port = port,\n    //        Path = path,\n    //        Query = query,\n    //        Fragment = fragment\n    //    };\n    //}\n}\n\npublic class RedirectUrlParser\n{\n    public static UrlParts Parse(string redirectUrl)\n    {\n        // extract scheme, host, port, path, query, and fragment from the redirectUrl\n        // and return a RedirectUrl object\n        // expand: example.com to *://**.example.com:*/**?**#*\n        // expand: example.com/path to *://**.example.com:*/path?**#*\n        // expand: example.com/* to *://**.example.com:*/**?**#*\n        // expand: example.com/path/* to *://**.example.com:*/path/*?**#*\n        // expand: example.com/path/** to *://**.example.com:*/path/**?**#*\n        // expand: example.com/path/1/* to *://**.example.com:*/path/1/*?query#fragment\n        // expand: example.com/path/1/** to *://**.example.com:*/path/1/**?query#fragment\n        // expand: example.com/path/** to *://**.example.com:*/path/**?**#*\n        // expand: example.com/path/1/path/2?quru to *://**.example.com:*/path?query#fragment\n\n        var schemeParts = redirectUrl.Split(\"://\");\n        var originalScheme = schemeParts.Length == 1 ? \"\" : schemeParts[0];\n        var scheme = schemeParts.Length == 1 ? Scheme.Any : Scheme.Parse(schemeParts[0]);\n\n\n        var tail = redirectUrl.Substring(schemeParts.Length == 1 ? 0 : schemeParts[0].Length + 3);\n        var idx = tail.IndexOf(\"/\");\n        var hostAndPort = tail.Substring(0, idx);\n        var portDelimiter = hostAndPort.IndexOf(\":\");\n        var host = portDelimiter > 0 ? hostAndPort.Substring(0, portDelimiter) : hostAndPort;\n        var port = portDelimiter > 0 ? hostAndPort.Substring(portDelimiter + 1) : \"\";\n        int portNumber = 0;\n        if(int.TryParse(port, out var parsedPort))\n        {\n            portNumber = parsedPort;\n        }\n        else\n        {\n            //TODO: Modify port to accept wildcards, multiple ports, and ranges\n            //port = \"\";\n        }\n        var domainParts = host.Split(\".\");\n\n        var absolutePath = idx > -1 ? tail.Substring(idx) : \"\";\n        var pathParts = absolutePath.Split(\"?\");\n        var path = pathParts[0];\n        var query = pathParts.Length == 1 ? \"\" : pathParts[1];\n        var queryParts = query.Split(\"#\");\n        var queryString = queryParts[0];\n        var queryStringParts = queryString.Split(\"&\");\n\n        var fragment = queryParts.Length == 1 ? \"\" : queryParts[1];\n        var fragmentParts = fragment.Split(\"#\");\n\n        return new UrlParts\n        {\n\n            Scheme = scheme,\n            Host = Host.Create(host),\n            Port = Port.Create(portNumber),\n            Path = Path.Create(path),\n            Query = Query.Create(queryString),\n            Fragment = Fragment.Create(fragment)\n        };\n\n    }\n\n}\npublic class UrlParts\n{\n    public UrlParts()\n    {\n        Scheme= Scheme.Any;\n        Host = Host.Any;\n        Port = Port.Any;\n        Path = Path.Any;\n        Query = Query.Any;\n        Fragment = Fragment.Any;\n\n    }\n    public UrlParts(Scheme scheme, Host host, Port port, Path path, Query query, Fragment fragment)\n    {\n        Scheme = scheme;\n        Host = host;\n        Port = port;\n        Path = path;\n        Query = query;\n        Fragment = fragment;\n    }\n    public Scheme Scheme { get; set; }\n    public Host Host { get; set; }\n    public Port Port { get; set; }\n    public Path Path { get; set; }\n    public Query Query { get; set; }\n    public Fragment Fragment { get; set; }\n}\n"
  },
  {
    "path": "src/Security/IdentityServer8.Security/RedirectUrlServiceExtensions.cs",
    "content": "﻿/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\n\npublic static class RedirectUrlServiceExtensions\n{\n    public static bool IsAllowedRedirect(this string redirectUrl)\n    {\n        return Ioc.RedirectService.IsRedirectAllowed(redirectUrl);\n    }\n    public static bool IsAllowedRedirect(this Uri uri)\n    {\n        return Ioc.RedirectService.IsRedirectAllowed(uri.ToString());\n    }\n\n    public static void RedirectIfAllowed(this HttpResponse response, string url)\n    {\n        if (IsAllowedRedirect(url))\n            response.Redirect(url.SanitizeForRedirect());\n        else\n            SetRedirectNotAllowed(response);\n    }\n\n    public static void SetRedirectNotAllowed(this HttpResponse response)\n    {\n        response.StatusCode = (int) HttpStatusCode.Forbidden;\n    }\n\n    public static void SetRedirectNotAllowed(this HttpContext ctx)\n    {\n        ctx.Response.SetRedirectNotAllowed();\n    }\n\n}\n"
  },
  {
    "path": "src/Security/IdentityServer8.Security/Sanitizer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Security;\n\npublic enum SanitizerType\n{\n    Unknown = 0,\n    HtmlSanitizer,\n    XmlSanitizer,\n    JsonSanitizer,\n    UrlSanitizer,\n    CssSanitizer,\n    ScriptSanitizer,\n    StyleSanitizer,\n    SqlSanitizer,\n    LogSanitizer\n}\npublic enum SanitizerMode\n{\n    Debug,\n    Clean,\n    Mask,\n    Full\n}\npublic interface IInputSanitizer\n{\n    public string? Sanitize(string? input, SanitizerMode mode = SanitizerMode.Clean);\n}\npublic interface ISanitizerFactory\n{\n    TSanitizer Create<TSanitizer>()\n        where TSanitizer : IInputSanitizer;\n\n    IInputSanitizer Create(SanitizerType type);\n}\npublic interface IHtmlSanitizer : IInputSanitizer\n{\n}\npublic interface IXmlSanitizer : IInputSanitizer\n{\n}\npublic interface IJsonSanitizer : IInputSanitizer\n{\n}\npublic interface IUrlSanitizer : IInputSanitizer\n{\n}\npublic interface ICssSanitizer : IInputSanitizer\n{\n}\npublic interface IScriptSanitizer : IInputSanitizer\n{\n}\npublic interface IStyleSanitizer : IInputSanitizer\n{\n}\npublic interface ISqlSanitizer : IInputSanitizer\n{\n}\npublic interface ILogSanitizer : IInputSanitizer\n{\n}\n\npublic interface ISanitizerService\n{\n    string? Sanitize(string? input, SanitizerType type, SanitizerMode mode);\n}\n\npublic abstract class SanitizerServiceBase : ISanitizerService\n{\n    public abstract string? Sanitize(string? input, SanitizerType type, SanitizerMode mode);\n}\npublic class SanitizerService : SanitizerServiceBase\n{\n    private readonly ISanitizerFactory _sanitizerFactory;\n\n    public SanitizerService(ISanitizerFactory sanitizerFactory)\n    {\n        _sanitizerFactory = sanitizerFactory;\n    }\n    public override string? Sanitize(string? input, SanitizerType type, SanitizerMode mode)\n    {\n        var sanitizer = _sanitizerFactory.Create(type);\n        return sanitizer.Sanitize(input, mode);\n    }\n\n\n}\n\npublic class SanitizerBase : IInputSanitizer\n{\n    private Func<string?, string?> _sanitize;\n\n    public SanitizerBase() : this(HttpUtility.HtmlEncode)\n    {\n    }\n\n    public SanitizerBase(Func<string?, string?> sanitizer)\n    {\n        _sanitize = sanitizer;\n    }\n\n    public virtual string? Sanitize(string? input, SanitizerMode mode = SanitizerMode.Debug)\n    {\n        switch (mode)\n        {\n            case SanitizerMode.Debug:\n                return input;\n            case SanitizerMode.Clean:\n                return Clean(input);\n            case SanitizerMode.Mask:\n            case SanitizerMode.Full:\n                var result = _sanitize(input) ?? \"\";\n                switch (mode)\n                {\n                    case SanitizerMode.Mask:\n                        return Mask(result);\n                    case SanitizerMode.Full:\n                        return result;\n                    default:\n                        throw new NotImplementedException();\n                }\n            default:\n                throw new NotImplementedException();\n        }\n    }\n\n\n    public string? Mask(string? input, int unmaskedChars = 4, bool unmaskFirst = false)\n    {\n        if (string.IsNullOrEmpty(input))\n            return input;\n        if (unmaskedChars == 0)\n        {\n            return \"********\";\n        }\n\n        input = Clean(input);\n        if (input.Length <= unmaskedChars)\n        {\n            return new string('*', input.Length);\n        }\n        else if (unmaskFirst)\n        {\n            return input.Substring(0, unmaskedChars) + new string('*', input.Length - unmaskedChars);\n        }\n        else\n        {\n            return new string('*', input.Length - unmaskedChars) + input.Substring(input.Length - unmaskedChars);\n        }\n    }\n\n    public string Clean(string? input)\n    {\n        input = input ?? string.Empty;\n        input = input.Replace(\"\\r\", \" \").Replace(\"\\n\", \" \");\n        var idx = input.IndexOf(\"  \");\n        while (idx > -1)\n        {\n            input = input.Replace(\"  \", \" \");\n            idx = input.IndexOf(\"  \");\n        }\n        input = _sanitize(input) ?? \"\";\n\n        //unescape ' and \" and space\n        input = input.Replace(\"&#39;\", \"'\");\n        input = input.Replace(\"&#34;\", \"\\\"\");\n        input = input.Replace(\"&#20;\", \" \");\n        input = input.Replace(\"&apos;\", \"'\");\n        input = input.Replace(\"&quot;\", \"\\\"\");\n        input = input.Replace(\"&nbsp;\", \" \");\n\n\n\n        return input.Trim() ?? \"\";\n    }\n}\n\n\npublic class HtmlSanitizer : SanitizerBase, IHtmlSanitizer\n{\n    public HtmlSanitizer() : base()\n    {\n\n    }\n}\npublic class XmlSanitizer : SanitizerBase, IXmlSanitizer\n{\n    public XmlSanitizer() : base(HttpUtility.HtmlEncode)\n    {\n\n    }\n}\npublic class JsonSanitizer : SanitizerBase, IJsonSanitizer\n{\n    public JsonSanitizer() : base(HttpUtility.JavaScriptStringEncode)\n    {\n\n    }\n\n}\npublic class UrlSanitizer : SanitizerBase, IUrlSanitizer\n{\n    public UrlSanitizer() : base(x => Uri.EscapeUriString(x?.ToString() ?? \"\"))\n    {\n\n    }\n}\npublic class CssSanitizer : SanitizerBase, ICssSanitizer\n{\n    public CssSanitizer() : base()\n    {\n\n    }\n}\npublic class ScriptSanitizer : SanitizerBase, IScriptSanitizer\n{\n    public ScriptSanitizer() : base(x => Uri.EscapeDataString(x?.ToString() ?? \"\"))\n    {\n\n    }\n}\npublic class StyleSanitizer : SanitizerBase, IStyleSanitizer\n{\n    public StyleSanitizer() : base()\n    {\n\n    }\n}\npublic class SqlSanitizer : SanitizerBase, ISqlSanitizer\n{\n    public SqlSanitizer() : base()\n    {\n\n    }\n}\npublic class LogSanitizer : SanitizerBase, ILogSanitizer\n{\n    public LogSanitizer() : base(HttpUtility.HtmlEncode)\n    {\n\n    }\n    public override string? Sanitize(string? input, SanitizerMode mode)\n    {\n        if (input is null)\n            return input;\n\n        switch (mode)\n        {\n            case SanitizerMode.Debug:\n                return base.Mask(input, input.Length);\n            case SanitizerMode.Clean:\n                return base.Clean(input);\n            case SanitizerMode.Mask:\n                return base.Mask(input);\n            case SanitizerMode.Full:\n                return base.Mask(input, 0);\n            default:\n                throw new NotImplementedException();\n        }\n    }\n}\npublic class SanitizerFactory : ISanitizerFactory\n{\n    public TInputSanitizer Create<TInputSanitizer>() where TInputSanitizer : IInputSanitizer\n    {\n\n        var type = Enum.Parse<SanitizerType>(typeof(TInputSanitizer).Name.Substring(1));\n        return (TInputSanitizer) Create(type);\n    }\n\n    public IInputSanitizer Create(SanitizerType type)\n    {\n        switch (type)\n        {\n            case SanitizerType.HtmlSanitizer:\n                return new HtmlSanitizer();\n            case SanitizerType.XmlSanitizer:\n                return new XmlSanitizer();\n            case SanitizerType.JsonSanitizer:\n                return new JsonSanitizer();\n            case SanitizerType.UrlSanitizer:\n                return new UrlSanitizer();\n            case SanitizerType.CssSanitizer:\n                return new CssSanitizer();\n            case SanitizerType.ScriptSanitizer:\n                return new ScriptSanitizer();\n            case SanitizerType.StyleSanitizer:\n                return new StyleSanitizer();\n            case SanitizerType.SqlSanitizer:\n                return new SqlSanitizer();\n            case SanitizerType.LogSanitizer:\n                return new LogSanitizer();\n            default:\n                throw new NotImplementedException();\n        }\n    }\n}\n\npublic interface ISanitizer\n{\n    public IHtmlSanitizer Html { get; }\n    public IXmlSanitizer Xml { get; }\n    public IJsonSanitizer Json { get; }\n    public IUrlSanitizer Url { get; }\n    public ICssSanitizer Css { get; }\n    public IScriptSanitizer Script { get; }\n    public IStyleSanitizer Style { get; }\n    public ISqlSanitizer Sql { get; }\n    public ILogSanitizer Log { get; }\n\n}\npublic class Sanitizer : ISanitizer\n{\n    public Sanitizer(ISanitizerFactory sanitizerFactory)\n    {\n        Html = sanitizerFactory.Create<IHtmlSanitizer>();\n        Xml = sanitizerFactory.Create<IXmlSanitizer>();\n        Json = sanitizerFactory.Create<IJsonSanitizer>();\n        Url = sanitizerFactory.Create<IUrlSanitizer>();\n        Css = sanitizerFactory.Create<ICssSanitizer>();\n        Script = sanitizerFactory.Create<IScriptSanitizer>();\n        Style = sanitizerFactory.Create<IStyleSanitizer>();\n        Sql = sanitizerFactory.Create<ISqlSanitizer>();\n        Log = sanitizerFactory.Create<ILogSanitizer>();\n    }\n\n\n    public IHtmlSanitizer Html { get; }\n    public IXmlSanitizer Xml { get; }\n    public IJsonSanitizer Json { get; }\n    public IUrlSanitizer Url { get; }\n    public ICssSanitizer Css { get; }\n    public IScriptSanitizer Script { get; }\n    public IStyleSanitizer Style { get; }\n    public ISqlSanitizer Sql { get; }\n    public ILogSanitizer Log { get; }\n}\n\n"
  },
  {
    "path": "src/Security/IdentityServer8.Security/SanitizerServiceExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace Microsoft.Extensions.DependencyInjection;\npublic static class SanitizerServiceExtensions\n{\n    public static IServiceCollection AddSanitizers(this IServiceCollection services)\n    {\n        var factory = new SanitizerFactory();\n        services.AddSingleton(factory);\n        services.AddSingleton<ISanitizerFactory>(factory);\n        services.AddSingleton<ISanitizerService, SanitizerService>();\n        services.AddSingleton<ISanitizer, Sanitizer>();\n\n        var props = typeof(ISanitizer).GetProperties();\n        foreach (var prop in props)\n        {\n            var type = Enum.Parse<SanitizerType>(prop.PropertyType.Name.Substring(1));\n            var sanitizer = factory.Create(type);\n            services.AddSingleton(prop.PropertyType, sanitizer);\n            services.AddSingleton(sanitizer);\n        }\n\n        return services;\n    }\n\n    public static string? SanitizeForLog(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        return Ioc.Sanitizer.Log.Sanitize(input?.ToString(), mode);\n    }\n\n    public static string? SanitizeForHtml(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        return Ioc.Sanitizer.Html.Sanitize(input?.ToString(), mode);\n    }\n\n    public static string? SanitizeForXml(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        return Ioc.Sanitizer.Xml.Sanitize(input?.ToString(), mode);\n    }\n\n    public static string? SanitizeForJson(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        return Ioc.Sanitizer.Json.Sanitize(input?.ToString(), mode);\n    }\n\n    public static string SanitizeForRedirect(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        var rawUrl = input?.ToString() ?? \"\";\n        if (string.IsNullOrEmpty(rawUrl))\n            return rawUrl;\n        else\n        {\n            if (Uri.TryCreate(rawUrl, UriKind.RelativeOrAbsolute, out var uri))\n            {\n                var parsedUrl = uri.ToString();\n                if (parsedUrl == rawUrl.ToString())\n                    return parsedUrl;\n                else\n                {\n                    return uri.ToString().SanitizeForLog() ?? \"\";\n                }\n\n            }\n            else\n            {\n                throw new ArgumentException(\"Invalid URL\", nameof(input));\n            }\n        }\n\n    }\n\n    public static string? SanitizeForUrl(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        return Ioc.Sanitizer.Url.Sanitize(input?.ToString(), mode);\n    }\n\n    public static string? SanitizeForCss(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        return Ioc.Sanitizer.Css.Sanitize(input?.ToString(), mode);\n    }\n\n    public static string? SanitizeForScript(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        return Ioc.Sanitizer.Script.Sanitize(input?.ToString(), mode);\n    }\n\n    public static string? SanitizeForStyle(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        return Ioc.Sanitizer.Style.Sanitize(input?.ToString(), mode);\n    }\n\n    public static string? SanitizeForSql(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        return Ioc.Sanitizer.Sql.Sanitize(input?.ToString(), mode);\n    }\n\n    public static string? SantizeForRedirect(this object? input, SanitizerMode mode = SanitizerMode.Clean)\n    {\n        var decoded = Uri.UnescapeDataString(input?.ToString() ?? \"\");\n        decoded.SanitizeForHtml();\n        var escaped = Uri.EscapeDataString(decoded);\n        return escaped;\n    }\n\n}\n"
  },
  {
    "path": "src/Security/test/IdentityServer8.Santizer.Tests/IdentityServer8.Sanitizer.Tests.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n  <PropertyGroup>\n    <IsPackable>false</IsPackable>\n  </PropertyGroup>\n\n  <ItemGroup>\n    <PackageReference Include=\"Microsoft.NET.Test.Sdk\" />\n    <PackageReference Include=\"xunit\" />\n    <PackageReference Include=\"xunit.runner.visualstudio\" />\n    <PackageReference Include=\"FluentAssertions\" />\n     <PackageReference Include=\"Microsoft.Extensions.Logging\" />\n    <PackageReference Include=\"coverlet.collector\" GeneratePathProperty=\"true\">\n      <IncludeAssets>runtime; build; native; contentfiles; analyzers; buildtransitive</IncludeAssets>\n      <PrivateAssets>all</PrivateAssets>\n    </PackageReference>   \n  </ItemGroup>\n\n  <ItemGroup>\n    <ProjectReference Include=\"..\\..\\IdentityServer8.Security\\IdentityServer8.Security.csproj\" />\n  </ItemGroup>\n  \n  \n\n</Project>\n"
  },
  {
    "path": "src/Security/test/IdentityServer8.Santizer.Tests/RedirectServiceTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing Microsoft.Extensions.DependencyInjection;\nusing Xunit;\n\n\nnamespace IdentityServer8.Security.Tests;\n\npublic class DependencyInjection\n{\n    static DependencyInjection()\n    {\n        var provider = new ServiceCollection()\n            .AddLogging()\n            .AddAllowAnyRedirectService()\n            .AddSingleton<IRedirectService, RedirectService>()\n            .AddSanitizers()\n            .BuildServiceProvider();\n        ServiceProvider = provider;\n\n    }\n\n    public static ServiceProvider ServiceProvider { get; }\n}\n\n\n\npublic class AllowAnyTests \n{\n    private readonly RedirectService _redirectService;\n\n    public AllowAnyTests()\n    {\n        var redirectService = DependencyInjection.ServiceProvider.GetRequiredService<AllowAnyRedirectService>();\n        _redirectService = redirectService;\n    }\n\n\n    [Theory]\n    [InlineData(\"http://example.com\",  true)]\n    [InlineData(\"http://a.example.com\", true)]\n    [InlineData(\"http://a.b.example.com\", true)]\n    [InlineData(\"https://example.com\", true)]\n    [InlineData(\"https://a.example.com\", true)]\n    [InlineData(\"https://a.b.example.com\", true)]\n    [InlineData(\"http://localhost\", true)]\n    [InlineData(\"https://localhost\", true)]\n\n\n\n\n    public void AllowAnyShouldReturnTrue(string uriString, bool expectedResult)\n    {\n        var result = _redirectService.IsRedirectAllowed(uriString);\n\n        Assert.Equal(expectedResult, result);\n    }\n}\npublic class RedirectServiceTests\n{\n    private readonly RedirectService _redirectService;\n\n    public RedirectServiceTests()\n    {\n        var redirectService = DependencyInjection.ServiceProvider.GetService<IRedirectService>();\n        _redirectService = redirectService as RedirectService;\n    }\n\n    [Theory]\n    [InlineData(\"http://example.com\", \"example.com\", true)]\n    [InlineData(\"http://example.com\", \"*\", true)]\n    [InlineData(\"http://example.com\", \"another.com\", false)]\n    [InlineData(\"example.com\", \"example.com\", true)]\n    [InlineData(\"example.com\", \"*\", true)]\n    [InlineData(\"example.com\", \"another.com\", false)]\n    [InlineData(\"*.example.com\", \"example.com\", false)]\n    [InlineData(\"*.example.com\", \"*\", true)]\n    [InlineData(\"*.example.com\", \"another.com\", false)]\n    public void IsHostMatch_ShouldCorrectlyMatchHost(string uriString, string allowedHostName, bool expectedResult)\n    {\n\n        var allowedHost = allowedHostName == \"*\" ? Host.Any : Host.Create(allowedHostName);\n\n        // Assuming IsHostMatch is made internal for testing and accessible here\n        var result = _redirectService.IsHostMatch(uriString, allowedHost);\n\n        Assert.Equal(expectedResult, result);\n    }\n\n    [Fact()]\n    public void RedirectServiceTest()\n    {\n\n    }\n\n    [Fact()]\n    public void AddARedirectRuleTest()\n    {\n\n    }\n\n    [Fact()]\n    public void IsRedirectAllowedTest()\n    {\n\n    }\n}\n"
  },
  {
    "path": "src/Security/test/IdentityServer8.Santizer.Tests/Services/SanitizerTests.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nusing FluentAssertions;\nusing Microsoft.Extensions.DependencyInjection;\nusing System.Diagnostics;\nusing System.Text.Json;\nusing Xunit;\n\nnamespace IdentityServer8.Security.Tests;\n\n\npublic class SanitizerTests\n{\n    public SanitizerTests()\n    {\n\n    }\n\n\n    [Fact]\n    public void SanitizerFactory()\n    {\n        var factory = Ioc.ServiceProvider.GetRequiredService<ISanitizerFactory>();\n        Assert.NotNull(factory);\n    }\n\n    [Fact]\n    public void SanitizerService()\n    {\n        var service = Ioc.ServiceProvider.GetRequiredService<ISanitizerService>();\n        Assert.NotNull(service);\n    }\n    [Fact]\n    public void Sanitizer()\n    {\n        var sanitizer = Ioc.ServiceProvider.GetRequiredService<ISanitizer>();\n        Assert.NotNull(sanitizer);\n    }\n\n\n    [Fact]\n    public void HtmlSanitizer()\n    {\n        var sanitizer = Ioc.ServiceProvider.GetRequiredService<IHtmlSanitizer>();\n        Assert.NotNull(sanitizer);\n\n        var input = \"<div><script>alert('xss')</script></div>\";\n        var output = sanitizer.Sanitize(input);\n        var expected = \"&lt;div&gt;&lt;script&gt;alert('xss')&lt;/script&gt;&lt;/div&gt;\";\n\n        Validate(expected, output);\n    }\n    [Fact]\n    public void XmlSanitizer()\n    {\n        var sanitizer = Ioc.ServiceProvider.GetRequiredService<IXmlSanitizer>();\n        Assert.NotNull(sanitizer);\n\n        var input = \"<div><script>alert('xss')</script></div>\";\n        var output = sanitizer.Sanitize(input);\n        var expected = \"&lt;div&gt;&lt;script&gt;alert('xss')&lt;/script&gt;&lt;/div&gt;\";\n\n        Validate(expected, output);\n    }\n    [Fact]\n    public void JsonSanitizer()\n    {\n        var sanitizer = Ioc.ServiceProvider.GetRequiredService<IJsonSanitizer>();\n        Assert.NotNull(sanitizer);\n\n        var input = JsonSerializer.Serialize(new { test = \"test\", value = \"<div><script>alert('xss')</script></div>\" });\n        var output = sanitizer.Sanitize(input);\n        var expected = @\"{\\\"\"test\\\"\":\\\"\"test\\\"\",\\\"\"value\\\"\":\\\"\"\\\\u003Cdiv\\\\u003E\\\\u003Cscript\\\\u003Ealert(\\\\u0027xss\\\\u0027)\\\\u003C/script\\\\u003E\\\\u003C/div\\\\u003E\\\"\"}\";\n\n\n        Validate(expected, output);\n    }\n    [Fact]\n    public void UrlSanitizer()\n    {\n        var sanitizer = Ioc.ServiceProvider.GetRequiredService<IUrlSanitizer>();\n        Assert.NotNull(sanitizer);\n\n        var input = \"http://test.com?test=<div><script>alert('xss')</script></div>\";\n        var output = sanitizer.Sanitize(input);\n        var expected = \"http://test.com?test=%3Cdiv%3E%3Cscript%3Ealert('xss')%3C/script%3E%3C/div%3E\";\n\n        Validate(expected, output);\n    }\n    [Fact]\n    public void CssSanitizer()\n    {\n        var sanitizer = Ioc.ServiceProvider.GetRequiredService<ICssSanitizer>();\n        Assert.NotNull(sanitizer);\n\n        var input = \"div { background-url('<script>alert('xss')</script>') }\";\n        var output = sanitizer.Sanitize(input);\n        var expected = \"div { background-url('&lt;script&gt;alert('xss')&lt;/script&gt;') }\";\n        Validate(expected, output);\n    }\n    [Fact]\n    public void ScriptSanitizer()\n    {\n        var sanitizer = Ioc.ServiceProvider.GetRequiredService<IJsonSanitizer>();\n        Assert.NotNull(sanitizer);\n\n        var input = JsonSerializer.Serialize(new { test = \"test\", value = \"<div><script>alert('xss')</script></div>\" });\n        var output = sanitizer.Sanitize(input);\n        var expected = @\"{\\\"\"test\\\"\":\\\"\"test\\\"\",\\\"\"value\\\"\":\\\"\"\\\\u003Cdiv\\\\u003E\\\\u003Cscript\\\\u003Ealert(\\\\u0027xss\\\\u0027)\\\\u003C/script\\\\u003E\\\\u003C/div\\\\u003E\\\"\"}\";\n\n\n        Validate(expected, output);\n    }\n    [Fact]\n    public void StyleSanitizer()\n    {\n        var sanitizer = Ioc.ServiceProvider.GetRequiredService<IStyleSanitizer>();\n        Assert.NotNull(sanitizer);\n        var input = \"div { background-url('<script>alert('xss')</script>') }\";\n        var output = sanitizer.Sanitize(input);\n        var expected = \"div { background-url('&lt;script&gt;alert('xss')&lt;/script&gt;') }\";\n\n        Validate(expected, output);\n    }\n    [Fact]\n    public void SqlSanitizer()\n    {\n        var sanitizer = Ioc.ServiceProvider.GetRequiredService<ISqlSanitizer>();\n        Assert.NotNull(sanitizer);\n\n        var input = \"update table set value='<script>alert('xss')</script>' where 1=1;\";\n        var output = sanitizer.Sanitize(input);\n        var expected = \"update table set value='&lt;script&gt;alert('xss')&lt;/script&gt;' where 1=1;\";\n\n        Validate(expected, output);\n    }\n    [Fact]\n    public void LogSanitizer()\n    {\n        var sanitizer = Ioc.ServiceProvider.GetRequiredService<ILogSanitizer>();\n        Assert.NotNull(sanitizer);\n\n        var input = @\"log\npoisoning\ntest\n\n<script>alert('xss')</script>\n\";\n        var output = sanitizer.Sanitize(input);\n\n\n        var expected = \"log poisoning test &lt;script&gt;alert('xss')&lt;/script&gt;\";\n        Validate(expected, output);\n\n\n        output = sanitizer.Sanitize(\"mypassword\", SanitizerMode.Mask);\n        expected = \"******word\";\n        Validate(expected, output);\n\n\n        output = sanitizer.Sanitize(\"mypassword\", SanitizerMode.Full);\n        expected = \"********\";\n        Validate(expected, output);\n\n    }\n\n    void Validate(string expected, string output)\n    {\n        Console.WriteLine(\"Expected: \" + expected);\n        Console.WriteLine(\"Output: \" + output);\n        Debug.WriteLine(\"Expected: \" + expected);\n        Debug.WriteLine(\"Output: \" + output);\n        output.Should().Be(expected);\n    }\n\n    private void Log(string expected, string output)\n    {\n        Console.WriteLine(\"Expected: \" + expected);\n        Console.WriteLine(\"Output: \" + output);\n        Debug.WriteLine(\"Expected: \" + expected);\n        Debug.WriteLine(\"Output: \" + output);\n    }\n}\n"
  },
  {
    "path": "src/Storage/Directory.Build.props",
    "content": "<Project>\n  <ImportGroup>\n\t <Import Project=\"../Directory.Build.props\" />\n  </ImportGroup>\n</Project>"
  },
  {
    "path": "src/Storage/IdentityServer8.Storage.sln",
    "content": "\nMicrosoft Visual Studio Solution File, Format Version 12.00\n# Visual Studio 15\nVisualStudioVersion = 15.0.26124.0\nMinimumVisualStudioVersion = 15.0.26124.0\nProject(\"{2150E333-8FDC-42A3-9474-1A3956D46DE8}\") = \"src\", \"src\", \"{2EEC146C-3C96-4871-BBAF-8341719BD533}\"\nEndProject\nProject(\"{9A19103F-16F7-4668-BE54-9A1E7A4F7556}\") = \"IdentityServer8.Storage\", \"src\\IdentityServer8.Storage.csproj\", \"{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}\"\nEndProject\nGlobal\n\tGlobalSection(SolutionConfigurationPlatforms) = preSolution\n\t\tDebug|Any CPU = Debug|Any CPU\n\t\tDebug|x64 = Debug|x64\n\t\tDebug|x86 = Debug|x86\n\t\tRelease|Any CPU = Release|Any CPU\n\t\tRelease|x64 = Release|x64\n\t\tRelease|x86 = Release|x86\n\tEndGlobalSection\n\tGlobalSection(ProjectConfigurationPlatforms) = postSolution\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Debug|Any CPU.ActiveCfg = Debug|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Debug|Any CPU.Build.0 = Debug|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Debug|x64.ActiveCfg = Debug|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Debug|x64.Build.0 = Debug|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Debug|x86.ActiveCfg = Debug|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Debug|x86.Build.0 = Debug|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Release|Any CPU.ActiveCfg = Release|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Release|Any CPU.Build.0 = Release|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Release|x64.ActiveCfg = Release|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Release|x64.Build.0 = Release|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Release|x86.ActiveCfg = Release|Any CPU\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7}.Release|x86.Build.0 = Release|Any CPU\n\tEndGlobalSection\n\tGlobalSection(SolutionProperties) = preSolution\n\t\tHideSolutionNode = FALSE\n\tEndGlobalSection\n\tGlobalSection(NestedProjects) = preSolution\n\t\t{A5E2B0DD-9C88-42B5-BCEC-7ED701504FF7} = {2EEC146C-3C96-4871-BBAF-8341719BD533}\n\tEndGlobalSection\n\tGlobalSection(ExtensibilityGlobals) = postSolution\n\t\tSolutionGuid = {AFF22F24-FEA5-4A1D-AFE6-942789486D59}\n\tEndGlobalSection\nEndGlobal\n"
  },
  {
    "path": "src/Storage/README.md",
    "content": "# IdentityServer8.Storage\n\nIdentityServer8.Storage contains all the models and storage interfaces for IdentityServer 4 configuration data."
  },
  {
    "path": "src/Storage/build/Program.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace build\n{\n    partial class Program\n    {\n        private const string Prefix = \"Storage\";\n    }\n}\n"
  },
  {
    "path": "src/Storage/build/build.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n  <PropertyGroup>\n    <OutputType>Exe</OutputType>\n  </PropertyGroup>\n\n  <ItemGroup>\n    <Compile Include=\"..\\..\\build\\Program.Partial.cs\" Link=\"Program.Partial.cs\" />\n  </ItemGroup>\n\n  <ItemGroup>\n    <PackageReference Include=\"Bullseye\" />\n    <PackageReference Include=\"SimpleExec\" />\n  </ItemGroup>\n  \n</Project>\n"
  },
  {
    "path": "src/Storage/build.cmd",
    "content": "@echo off\ndotnet run --project build -- %*"
  },
  {
    "path": "src/Storage/build.ps1",
    "content": "$ErrorActionPreference = \"Stop\";\ndotnet run --project build -- $args"
  },
  {
    "path": "src/Storage/build.sh",
    "content": "#!/usr/bin/env bash\nset -euo pipefail\ndotnet run --project build -- \"$@\""
  },
  {
    "path": "src/Storage/src/Constants.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8;\n\ninternal static class Constants\n{\n    public const string IdentityServerName               = \"IdentityServer8\";\n    public const string IdentityServerAuthenticationType = IdentityServerName;\n}\n"
  },
  {
    "path": "src/Storage/src/Extensions/IEnumerableExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Extensions;\n\ninternal static class IEnumerableExtensions\n{\n    [DebuggerStepThrough]\n    public static bool IsNullOrEmpty<T>(this IEnumerable<T> list)\n    {\n        if (list == null)\n        {\n            return true;\n        }\n\n        if (!list.Any())\n        {\n            return true;\n        }\n\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/Extensions/PersistedGrantFilterExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Extensions;\n\n/// <summary>\n/// Extensions for PersistedGrantFilter.\n/// </summary>\npublic static class PersistedGrantFilterExtensions\n{\n    /// <summary>\n    /// Validates the PersistedGrantFilter and throws if invalid.\n    /// </summary>\n    /// <param name=\"filter\"></param>\n    public static void Validate(this PersistedGrantFilter filter)\n    {\n        if (filter == null) throw new ArgumentNullException(nameof(filter));\n\n        if (String.IsNullOrWhiteSpace(filter.ClientId) &&\n            String.IsNullOrWhiteSpace(filter.SessionId) &&\n            String.IsNullOrWhiteSpace(filter.SubjectId) &&\n            String.IsNullOrWhiteSpace(filter.Type))\n        {\n            throw new ArgumentException(\"No filter values set.\", nameof(filter));\n        }\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/Extensions/StringsExtensions.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Extensions;\n\ninternal static class StringExtensions\n{\n    [DebuggerStepThrough]\n    public static bool IsMissing(this string value)\n    {\n        return string.IsNullOrWhiteSpace(value);\n    }\n\n    [DebuggerStepThrough]\n    public static bool IsPresent(this string value)\n    {\n        return !string.IsNullOrWhiteSpace(value);\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/GlobalUsings.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nglobal using IdentityModel;\nglobal using IdentityServer8.Extensions;\nglobal using IdentityServer8.Models;\nglobal using IdentityServer8.Stores;\nglobal using Newtonsoft.Json;\nglobal using Newtonsoft.Json.Serialization;\nglobal using System.Collections;\nglobal using System.Diagnostics;\nglobal using System.Security.Claims;\n"
  },
  {
    "path": "src/Storage/src/IdentityServer8.Storage.csproj",
    "content": "<Project Sdk=\"Microsoft.NET.Sdk\">\n\n    <PropertyGroup>\n\n        <Description>Storage interfaces and models for IdentityServer8</Description>\n        <IsPackable>true</IsPackable>\n        <GeneratePackageOnBuild>True</GeneratePackageOnBuild>\n    </PropertyGroup>\n\n    <PropertyGroup>\n        <ContinuousIntegrationBuild Condition=\"'$(TF_BUILD)' == 'true'\">True</ContinuousIntegrationBuild>\n        <ContinuousIntegrationBuild Condition=\"'$(GITHUB_ACTIONS)' == 'true'\">True</ContinuousIntegrationBuild>\n\n    </PropertyGroup>\n\n    <ItemGroup>\n      <None Include=\"..\\..\\..\\icon.jpg\">\n        <Pack>True</Pack>\n        <PackagePath>\\</PackagePath>\n      </None>\n    </ItemGroup>\n\n\n    <ItemGroup>\n        <PackageReference Include=\"IdentityModel\" />\n        <PackageReference Include=\"Newtonsoft.Json\" />\n    </ItemGroup>\n\n</Project>"
  },
  {
    "path": "src/Storage/src/IdentityServerConstants.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8;\n\ninternal static class IdentityServerConstants\n{\n    public static class ProtocolTypes\n    {\n        public const string OpenIdConnect = \"oidc\";\n    }\n\n    public static class SecretTypes\n    {\n        public const string SharedSecret = \"SharedSecret\";\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/IdentityServerUser.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8;\n\n/// <summary>\n/// Model properties of an IdentityServer user\n/// </summary>\ninternal class IdentityServerUser\n{\n    /// <summary>\n    /// Subject ID (mandatory)\n    /// </summary>\n    public string SubjectId { get; }\n\n    /// <summary>\n    /// Display name (optional)\n    /// </summary>\n    public string DisplayName { get; set; }\n\n    /// <summary>\n    /// Identity provider (optional)\n    /// </summary>\n    public string IdentityProvider { get; set; }\n\n    /// <summary>\n    /// Authentication methods\n    /// </summary>\n    public ICollection<string> AuthenticationMethods { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Authentication time\n    /// </summary>\n    public DateTime? AuthenticationTime { get; set; }\n\n    /// <summary>\n    /// Additional claims\n    /// </summary>\n    public ICollection<Claim> AdditionalClaims { get; set; } = new HashSet<Claim>(new ClaimComparer());\n\n    /// <summary>\n    /// Initializes a user identity\n    /// </summary>\n    /// <param name=\"subjectId\">The subject ID</param>\n    public IdentityServerUser(string subjectId)\n    {\n        if (subjectId.IsMissing()) throw new ArgumentException(\"SubjectId is mandatory\", nameof(subjectId));\n\n        SubjectId = subjectId;\n    }\n\n    /// <summary>\n    /// Creates an IdentityServer claims principal\n    /// </summary>\n    /// <returns></returns>\n    /// <exception cref=\"ArgumentNullException\"></exception>\n    public ClaimsPrincipal CreatePrincipal()\n    {\n        if (SubjectId.IsMissing()) throw new ArgumentException(\"SubjectId is mandatory\", nameof(SubjectId));\n        var claims = new List<Claim> { new Claim(JwtClaimTypes.Subject, SubjectId) };\n\n        if (DisplayName.IsPresent())\n        {\n            claims.Add(new Claim(JwtClaimTypes.Name, DisplayName));\n        }\n\n        if (IdentityProvider.IsPresent())\n        {\n            claims.Add(new Claim(JwtClaimTypes.IdentityProvider, IdentityProvider));\n        }\n\n        if (AuthenticationTime.HasValue)\n        {\n            claims.Add(new Claim(JwtClaimTypes.AuthenticationTime, new DateTimeOffset(AuthenticationTime.Value).ToUnixTimeSeconds().ToString()));\n        }\n\n        if (AuthenticationMethods.Any())\n        {\n            foreach (var amr in AuthenticationMethods)\n            {\n                claims.Add(new Claim(JwtClaimTypes.AuthenticationMethod, amr));\n            }\n        }\n\n        claims.AddRange(AdditionalClaims);\n\n        var id = new ClaimsIdentity(claims.Distinct(new ClaimComparer()), Constants.IdentityServerAuthenticationType, JwtClaimTypes.Name, JwtClaimTypes.Role);\n        return new ClaimsPrincipal(id);\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/Models/ApiResource.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models a web API resource.\n/// </summary>\n[DebuggerDisplay(\"{\" + nameof(DebuggerDisplay) + \",nq}\")]\npublic class ApiResource : Resource\n{\n    private string DebuggerDisplay => Name ?? $\"{{{typeof(ApiResource)}}}\";\n    \n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiResource\"/> class.\n    /// </summary>\n    public ApiResource()\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiResource\"/> class.\n    /// </summary>\n    /// <param name=\"name\">The name.</param>\n    public ApiResource(string name)\n        : this(name, name, null)\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiResource\"/> class.\n    /// </summary>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"displayName\">The display name.</param>\n    public ApiResource(string name, string displayName)\n        : this(name, displayName, null)\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiResource\"/> class.\n    /// </summary>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"userClaims\">List of associated user claims that should be included when this resource is requested.</param>\n    public ApiResource(string name, IEnumerable<string> userClaims)\n        : this(name, name, userClaims)\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiResource\"/> class.\n    /// </summary>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"displayName\">The display name.</param>\n    /// <param name=\"userClaims\">List of associated user claims that should be included when this resource is requested.</param>\n    /// <exception cref=\"System.ArgumentNullException\">name</exception>\n    public ApiResource(string name, string displayName, IEnumerable<string> userClaims)\n    {\n        if (name.IsMissing()) throw new ArgumentNullException(nameof(name));\n\n        Name = name;\n        DisplayName = displayName;\n\n        if (!userClaims.IsNullOrEmpty())\n        {\n            foreach (var type in userClaims)\n            {\n                UserClaims.Add(type);\n            }\n        }\n    }\n\n    /// <summary>\n    /// The API secret is used for the introspection endpoint. The API can authenticate with introspection using the API name and secret.\n    /// </summary>\n    public ICollection<Secret> ApiSecrets { get; set; } = new HashSet<Secret>();\n\n    /// <summary>\n    /// Models the scopes this API resource allows.\n    /// </summary>\n    public ICollection<string> Scopes { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Signing algorithm for access token. If empty, will use the server default signing algorithm.\n    /// </summary>\n    public ICollection<string> AllowedAccessTokenSigningAlgorithms { get; set; } = new HashSet<string>();\n}\n"
  },
  {
    "path": "src/Storage/src/Models/ApiScope.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models access to an API scope\n/// </summary>\n[DebuggerDisplay(\"{\" + nameof(DebuggerDisplay) + \",nq}\")]\npublic class ApiScope : Resource\n{\n    private string DebuggerDisplay => Name ?? $\"{{{typeof(ApiScope)}}}\";\n    \n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiScope\"/> class.\n    /// </summary>\n    public ApiScope()\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiScope\"/> class.\n    /// </summary>\n    /// <param name=\"name\">The name.</param>\n    public ApiScope(string name)\n        : this(name, name, null)\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiScope\"/> class.\n    /// </summary>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"displayName\">The display name.</param>\n    public ApiScope(string name, string displayName)\n        : this(name, displayName, null)\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiScope\"/> class.\n    /// </summary>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"userClaims\">List of associated user claims that should be included when this resource is requested.</param>\n    public ApiScope(string name, IEnumerable<string> userClaims)\n        : this(name, name, userClaims)\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"ApiScope\"/> class.\n    /// </summary>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"displayName\">The display name.</param>\n    /// <param name=\"userClaims\">List of associated user claims that should be included when this resource is requested.</param>\n    /// <exception cref=\"System.ArgumentNullException\">name</exception>\n    public ApiScope(string name, string displayName, IEnumerable<string> userClaims)\n    {\n        if (name.IsMissing()) throw new ArgumentNullException(nameof(name));\n\n        Name = name;\n        DisplayName = displayName;\n\n        if (!userClaims.IsNullOrEmpty())\n        {\n            foreach (var type in userClaims)\n            {\n                UserClaims.Add(type);\n            }\n        }\n    }\n\n    /// <summary>\n    /// Specifies whether the user can de-select the scope on the consent screen. Defaults to false.\n    /// </summary>\n    public bool Required { get; set; } = false;\n\n    /// <summary>\n    /// Specifies whether the consent screen will emphasize this scope. Use this setting for sensitive or important scopes. Defaults to false.\n    /// </summary>\n    public bool Emphasize { get; set; } = false;\n}\n"
  },
  {
    "path": "src/Storage/src/Models/AuthorizationCode.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models an authorization code.\n/// </summary>\npublic class AuthorizationCode\n{\n    /// <summary>\n    /// Gets or sets the creation time.\n    /// </summary>\n    /// <value>\n    /// The creation time.\n    /// </value>\n    public DateTime CreationTime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the life time in seconds.\n    /// </summary>\n    /// <value>\n    /// The life time.\n    /// </value>\n    public int Lifetime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the ID of the client.\n    /// </summary>\n    /// <value>\n    /// The ID of the client.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject.\n    /// </summary>\n    /// <value>\n    /// The subject.\n    /// </value>\n    public ClaimsPrincipal Subject { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether this code is an OpenID Connect code.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if this instance is open identifier; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsOpenId { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the requested scopes.\n    /// </summary>\n    /// <value>\n    /// The requested scopes.\n    /// </value>\n    // todo: brock, change to parsed scopes\n    public IEnumerable<string> RequestedScopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the redirect URI.\n    /// </summary>\n    /// <value>\n    /// The redirect URI.\n    /// </value>\n    public string RedirectUri { get; set; }\n\n    /// <summary>\n    /// Gets or sets the nonce.\n    /// </summary>\n    /// <value>\n    /// The nonce.\n    /// </value>\n    public string Nonce { get; set; }\n\n    /// <summary>\n    /// Gets or sets the hashed state (to output s_hash claim).\n    /// </summary>\n    /// <value>\n    /// The hashed state.\n    /// </value>\n    public string StateHash { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether consent was shown.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if consent was shown; otherwise, <c>false</c>.\n    /// </value>\n    public bool WasConsentShown { get; set; }\n\n    /// <summary>\n    /// Gets or sets the session identifier.\n    /// </summary>\n    /// <value>\n    /// The session identifier.\n    /// </value>\n    public string SessionId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the code challenge.\n    /// </summary>\n    /// <value>\n    /// The code challenge.\n    /// </value>\n    public string CodeChallenge { get; set; }\n\n    /// <summary>\n    /// Gets or sets the code challenge method.\n    /// </summary>\n    /// <value>\n    /// The code challenge method\n    /// </value>\n    public string CodeChallengeMethod { get; set; }\n\n    /// <summary>\n    /// Gets the description the user assigned to the device being authorized.\n    /// </summary>\n    /// <value>\n    /// The description.\n    /// </value>\n    public string Description { get; set; }\n\n    /// <summary>\n    /// Gets or sets properties\n    /// </summary>\n    /// <value>\n    /// The properties\n    /// </value>\n    public IDictionary<string, string> Properties { get; set; } = new Dictionary<string, string>();\n}\n"
  },
  {
    "path": "src/Storage/src/Models/Client.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models an OpenID Connect or OAuth2 client\n/// </summary>\n[DebuggerDisplay(\"{\" + nameof(DebuggerDisplay) + \",nq}\")]\npublic class Client\n{\n    // setting grant types should be atomic\n    private ICollection<string> _allowedGrantTypes = new GrantTypeValidatingHashSet();\n\n    private string DebuggerDisplay => ClientId ?? $\"{{{typeof(Client)}}}\";\n\n    /// <summary>\n    /// Specifies if client is enabled (defaults to <c>true</c>)\n    /// </summary>\n    public bool Enabled { get; set; } = true;\n\n    /// <summary>\n    /// Unique ID of the client\n    /// </summary>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the protocol type.\n    /// </summary>\n    /// <value>\n    /// The protocol type.\n    /// </value>\n    public string ProtocolType { get; set; } = IdentityServerConstants.ProtocolTypes.OpenIdConnect;\n\n    /// <summary>\n    /// Client secrets - only relevant for flows that require a secret\n    /// </summary>\n    public ICollection<Secret> ClientSecrets { get; set; } = new HashSet<Secret>();\n\n    /// <summary>\n    /// If set to false, no client secret is needed to request tokens at the token endpoint (defaults to <c>true</c>)\n    /// </summary>\n    public bool RequireClientSecret { get; set; } = true;\n\n    /// <summary>\n    /// Client display name (used for logging and consent screen)\n    /// </summary>\n    public string ClientName { get; set; }\n\n    /// <summary>\n    /// Description of the client.\n    /// </summary>\n    public string Description { get; set; }\n\n    /// <summary>\n    /// URI to further information about client (used on consent screen)\n    /// </summary>\n    public string ClientUri { get; set; }\n\n    /// <summary>\n    /// URI to client logo (used on consent screen)\n    /// </summary>\n    public string LogoUri { get; set; }\n\n    /// <summary>\n    /// Specifies whether a consent screen is required (defaults to <c>false</c>)\n    /// </summary>\n    public bool RequireConsent { get; set; } = false;\n\n    /// <summary>\n    /// Specifies whether user can choose to store consent decisions (defaults to <c>true</c>)\n    /// </summary>\n    public bool AllowRememberConsent { get; set; } = true;\n\n    /// <summary>\n    /// Specifies the allowed grant types (legal combinations of AuthorizationCode, Implicit, Hybrid, ResourceOwner, ClientCredentials).\n    /// </summary>\n    public ICollection<string> AllowedGrantTypes\n    {\n        get { return _allowedGrantTypes; }\n        set\n        {\n            ValidateGrantTypes(value);\n            _allowedGrantTypes = new GrantTypeValidatingHashSet(value);\n        }\n    }\n\n    /// <summary>\n    /// Specifies whether a proof key is required for authorization code based token requests (defaults to <c>true</c>).\n    /// </summary>\n    public bool RequirePkce { get; set; } = true;\n\n    /// <summary>\n    /// Specifies whether a proof key can be sent using plain method (not recommended and defaults to <c>false</c>.)\n    /// </summary>\n    public bool AllowPlainTextPkce { get; set; } = false;\n\n    /// <summary>\n    /// Specifies whether the client must use a request object on authorize requests (defaults to <c>false</c>.)\n    /// </summary>\n    public bool RequireRequestObject { get; set; } = false;\n    \n    /// <summary>\n    /// Controls whether access tokens are transmitted via the browser for this client (defaults to <c>false</c>).\n    /// This can prevent accidental leakage of access tokens when multiple response types are allowed.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if access tokens can be transmitted via the browser; otherwise, <c>false</c>.\n    /// </value>\n    public bool AllowAccessTokensViaBrowser { get; set; } = false;\n\n    /// <summary>\n    /// Specifies allowed URIs to return tokens or authorization codes to\n    /// </summary>\n    public ICollection<string> RedirectUris { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Specifies allowed URIs to redirect to after logout\n    /// </summary>\n    public ICollection<string> PostLogoutRedirectUris { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Specifies logout URI at client for HTTP front-channel based logout.\n    /// </summary>\n    public string FrontChannelLogoutUri { get; set; }\n\n    /// <summary>\n    /// Specifies if the user's session id should be sent to the FrontChannelLogoutUri. Defaults to <c>true</c>.\n    /// </summary>\n    public bool FrontChannelLogoutSessionRequired { get; set; } = true;\n\n    /// <summary>\n    /// Specifies logout URI at client for HTTP back-channel based logout.\n    /// </summary>\n    public string BackChannelLogoutUri { get; set; }\n\n    /// <summary>\n    /// Specifies if the user's session id should be sent to the BackChannelLogoutUri. Defaults to <c>true</c>.\n    /// </summary>\n    public bool BackChannelLogoutSessionRequired { get; set; } = true;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether [allow offline access]. Defaults to <c>false</c>.\n    /// </summary>\n    public bool AllowOfflineAccess { get; set; } = false;\n\n    /// <summary>\n    /// Specifies the api scopes that the client is allowed to request. If empty, the client can't access any scope\n    /// </summary>\n    public ICollection<string> AllowedScopes { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// When requesting both an id token and access token, should the user claims always be added to the id token instead of requiring the client to use the userinfo endpoint.\n    /// Defaults to <c>false</c>.\n    /// </summary>\n    public bool AlwaysIncludeUserClaimsInIdToken { get; set; } = false;\n\n    /// <summary>\n    /// Lifetime of identity token in seconds (defaults to 300 seconds / 5 minutes)\n    /// </summary>\n    public int IdentityTokenLifetime { get; set; } = 300;\n\n    /// <summary>\n    /// Signing algorithm for identity token. If empty, will use the server default signing algorithm.\n    /// </summary>\n    public ICollection<string> AllowedIdentityTokenSigningAlgorithms { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Lifetime of access token in seconds (defaults to 3600 seconds / 1 hour)\n    /// </summary>\n    public int AccessTokenLifetime { get; set; } = 3600;\n\n    /// <summary>\n    /// Lifetime of authorization code in seconds (defaults to 300 seconds / 5 minutes)\n    /// </summary>\n    public int AuthorizationCodeLifetime { get; set; } = 300;\n\n    /// <summary>\n    /// Maximum lifetime of a refresh token in seconds. Defaults to 2592000 seconds / 30 days\n    /// </summary>\n    public int AbsoluteRefreshTokenLifetime { get; set; } = 2592000;\n\n    /// <summary>\n    /// Sliding lifetime of a refresh token in seconds. Defaults to 1296000 seconds / 15 days\n    /// </summary>\n    public int SlidingRefreshTokenLifetime { get; set; } = 1296000;\n\n    /// <summary>\n    /// Lifetime of a user consent in seconds. Defaults to null (no expiration)\n    /// </summary>\n    public int? ConsentLifetime { get; set; } = null;\n\n    /// <summary>\n    /// ReUse: the refresh token handle will stay the same when refreshing tokens\n    /// OneTime: the refresh token handle will be updated when refreshing tokens\n    /// </summary>\n    public TokenUsage RefreshTokenUsage { get; set; } = TokenUsage.OneTimeOnly;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the access token (and its claims) should be updated on a refresh token request.\n    /// Defaults to <c>false</c>.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if the token should be updated; otherwise, <c>false</c>.\n    /// </value>\n    public bool UpdateAccessTokenClaimsOnRefresh { get; set; } = false;\n\n    /// <summary>\n    /// Absolute: the refresh token will expire on a fixed point in time (specified by the AbsoluteRefreshTokenLifetime)\n    /// Sliding: when refreshing the token, the lifetime of the refresh token will be renewed (by the amount specified in SlidingRefreshTokenLifetime). The lifetime will not exceed AbsoluteRefreshTokenLifetime.\n    /// </summary>        \n    public TokenExpiration RefreshTokenExpiration { get; set; } = TokenExpiration.Absolute;\n\n    /// <summary>\n    /// Specifies whether the access token is a reference token or a self contained JWT token (defaults to Jwt).\n    /// </summary>\n    public AccessTokenType AccessTokenType { get; set; } = AccessTokenType.Jwt;\n\n    /// <summary>\n    /// Gets or sets a value indicating whether the local login is allowed for this client. Defaults to <c>true</c>.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if local logins are enabled; otherwise, <c>false</c>.\n    /// </value>\n    public bool EnableLocalLogin { get; set; } = true;\n\n    /// <summary>\n    /// Specifies which external IdPs can be used with this client (if list is empty all IdPs are allowed). Defaults to empty.\n    /// </summary>\n    public ICollection<string> IdentityProviderRestrictions { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Gets or sets a value indicating whether JWT access tokens should include an identifier. Defaults to <c>true</c>.\n    /// </summary>\n    /// <value>\n    /// <c>true</c> to add an id; otherwise, <c>false</c>.\n    /// </value>\n    public bool IncludeJwtId { get; set; } = true;\n\n    /// <summary>\n    /// Allows settings claims for the client (will be included in the access token).\n    /// </summary>\n    /// <value>\n    /// The claims.\n    /// </value>\n    public ICollection<ClientClaim> Claims { get; set; } = new HashSet<ClientClaim>();\n\n    /// <summary>\n    /// Gets or sets a value indicating whether client claims should be always included in the access tokens - or only for client credentials flow.\n    /// Defaults to <c>false</c>\n    /// </summary>\n    /// <value>\n    /// <c>true</c> if claims should always be sent; otherwise, <c>false</c>.\n    /// </value>\n    public bool AlwaysSendClientClaims { get; set; } = false;\n\n    /// <summary>\n    /// Gets or sets a value to prefix it on client claim types. Defaults to <c>client_</c>.\n    /// </summary>\n    /// <value>\n    /// Any non empty string if claims should be prefixed with the value; otherwise, <c>null</c>.\n    /// </value>\n    public string ClientClaimsPrefix { get; set; } = \"client_\";\n\n    /// <summary>\n    /// Gets or sets a salt value used in pair-wise subjectId generation for users of this client.\n    /// </summary>\n    public string PairWiseSubjectSalt { get; set; }\n\n    /// <summary>\n    /// The maximum duration (in seconds) since the last time the user authenticated.\n    /// </summary>\n    public int? UserSsoLifetime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the type of the device flow user code.\n    /// </summary>\n    /// <value>\n    /// The type of the device flow user code.\n    /// </value>\n    public string UserCodeType { get; set; }\n\n    /// <summary>\n    /// Gets or sets the device code lifetime.\n    /// </summary>\n    /// <value>\n    /// The device code lifetime.\n    /// </value>\n    public int DeviceCodeLifetime { get; set; } = 300;\n\n    /// <summary>\n    /// Gets or sets the allowed CORS origins for JavaScript clients.\n    /// </summary>\n    /// <value>\n    /// The allowed CORS origins.\n    /// </value>\n    public ICollection<string> AllowedCorsOrigins { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Gets or sets the custom properties for the client.\n    /// </summary>\n    /// <value>\n    /// The properties.\n    /// </value>\n    public IDictionary<string, string> Properties { get; set; } = new Dictionary<string, string>();\n\n    /// <summary>\n    /// Validates the grant types.\n    /// </summary>\n    /// <param name=\"grantTypes\">The grant types.</param>\n    /// <exception cref=\"System.InvalidOperationException\">\n    /// Grant types list is empty\n    /// or\n    /// Grant types cannot contain spaces\n    /// or\n    /// Grant types list contains duplicate values\n    /// </exception>\n    public static void ValidateGrantTypes(IEnumerable<string> grantTypes)\n    {\n        if (grantTypes == null)\n        {\n            throw new ArgumentNullException(nameof(grantTypes));\n        }\n\n        // spaces are not allowed in grant types\n        foreach (var type in grantTypes)\n        {\n            if (type.Contains(' '))\n            {\n                throw new InvalidOperationException(\"Grant types cannot contain spaces\");\n            }\n        }\n\n        // single grant type, seems to be fine\n        if (grantTypes.Count() == 1) return;\n\n        // don't allow duplicate grant types\n        if (grantTypes.Count() != grantTypes.Distinct().Count())\n        {\n            throw new InvalidOperationException(\"Grant types list contains duplicate values\");\n        }\n\n        // would allow response_type downgrade attack from code to token\n        DisallowGrantTypeCombination(GrantType.Implicit, GrantType.AuthorizationCode, grantTypes);\n        DisallowGrantTypeCombination(GrantType.Implicit, GrantType.Hybrid, grantTypes);\n\n        DisallowGrantTypeCombination(GrantType.AuthorizationCode, GrantType.Hybrid, grantTypes);\n    }\n\n    private static void DisallowGrantTypeCombination(string value1, string value2, IEnumerable<string> grantTypes)\n    {\n        if (grantTypes.Contains(value1, StringComparer.Ordinal) &&\n            grantTypes.Contains(value2, StringComparer.Ordinal))\n        {\n            throw new InvalidOperationException($\"Grant types list cannot contain both {value1} and {value2}\");\n        }\n    }\n\n    internal class GrantTypeValidatingHashSet : ICollection<string>\n    {\n        private readonly ICollection<string> _inner;\n\n        public GrantTypeValidatingHashSet()\n        {\n            _inner = new HashSet<string>();\n        }\n\n        public GrantTypeValidatingHashSet(IEnumerable<string> values)\n        {\n            _inner = new HashSet<string>(values);\n        }\n\n        private ICollection<string> Clone()\n        {\n            return new HashSet<string>(this);\n        }\n\n        private ICollection<string> CloneWith(params string[] values)\n        {\n            var clone = Clone();\n            foreach (var item in values) clone.Add(item);\n            return clone;\n        }\n\n        public int Count => _inner.Count;\n\n        public bool IsReadOnly => _inner.IsReadOnly;\n\n        public void Add(string item)\n        {\n            ValidateGrantTypes(CloneWith(item));\n            _inner.Add(item);\n        }\n\n        public void Clear()\n        {\n            _inner.Clear();\n        }\n\n        public bool Contains(string item)\n        {\n            return _inner.Contains(item);\n        }\n\n        public void CopyTo(string[] array, int arrayIndex)\n        {\n            _inner.CopyTo(array, arrayIndex);\n        }\n\n        public IEnumerator<string> GetEnumerator()\n        {\n            return _inner.GetEnumerator();\n        }\n\n        public bool Remove(string item)\n        {\n            return _inner.Remove(item);\n        }\n\n        IEnumerator IEnumerable.GetEnumerator()\n        {\n            return _inner.GetEnumerator();\n        }\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/Models/ClientClaim.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// A client claim\n/// </summary>\npublic class ClientClaim\n{\n    /// <summary>\n    /// The claim type\n    /// </summary>\n    public string Type { get; set; }\n    \n    /// <summary>\n    /// The claim value\n    /// </summary>\n    public string Value { get; set; }\n\n    /// <summary>\n    /// The claim value type\n    /// </summary>\n    public string ValueType { get; set; } = ClaimValueTypes.String;\n\n    /// <summary>\n    /// ctor\n    /// </summary>\n    public ClientClaim()\n    {\n    }\n\n    /// <summary>\n    /// ctor\n    /// </summary>\n    /// <param name=\"type\"></param>\n    /// <param name=\"value\"></param>\n    public ClientClaim(string type, string value)\n    {\n        Type = type;\n        Value = value;\n    }\n\n    /// <summary>\n    /// ctor\n    /// </summary>\n    /// <param name=\"type\"></param>\n    /// <param name=\"value\"></param>\n    /// <param name=\"valueType\"></param>\n    public ClientClaim(string type, string value, string valueType)\n    {\n        Type = type;\n        Value = value;\n        ValueType = valueType;\n    }\n\n    /// <inheritdoc/>\n    public override int GetHashCode()\n    {\n        unchecked \n        {\n            int hash = 17;\n\n            hash = hash * 23 + Value.GetHashCode();\n            hash = hash * 23 + Type.GetHashCode();\n            hash = hash * 23 + ValueType.GetHashCode();\n            return hash;\n        }\n    }\n\n    /// <inheritdoc/>\n    public override bool Equals(object obj)\n    {\n        if (obj is null) return false;\n        if (obj is ClientClaim c)\n        {\n            return (string.Equals(Type, c.Type, StringComparison.Ordinal) &&\n                    string.Equals(Value, c.Value, StringComparison.Ordinal) &&\n                    string.Equals(ValueType, c.ValueType, StringComparison.Ordinal));\n        }\n\n        return false;\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/Models/Consent.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Represents the permissions (in terms of scopes) granted to a client by a subject\n/// </summary>\npublic class Consent\n{\n    /// <summary>\n    /// Gets or sets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the scopes.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public IEnumerable<string> Scopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the creation time.\n    /// </summary>\n    /// <value>\n    /// The creation time.\n    /// </value>\n    public DateTime CreationTime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the expiration.\n    /// </summary>\n    /// <value>\n    /// The expiration.\n    /// </value>\n    public DateTime? Expiration { get; set; }\n}\n"
  },
  {
    "path": "src/Storage/src/Models/DeviceCode.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Represents data needed for device flow.\n/// </summary>\npublic class DeviceCode\n{\n    /// <summary>\n    /// Gets or sets the creation time.\n    /// </summary>\n    /// <value>\n    /// The creation time.\n    /// </value>\n    public DateTime CreationTime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the lifetime.\n    /// </summary>\n    /// <value>\n    /// The lifetime.\n    /// </value>\n    public int Lifetime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets the description the user assigned to the device being authorized.\n    /// </summary>\n    /// <value>\n    /// The description.\n    /// </value>\n    public string Description { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether this instance is open identifier.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if this instance is open identifier; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsOpenId { get; set; }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether this instance is authorized.\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if this instance is authorized; otherwise, <c>false</c>.\n    /// </value>\n    public bool IsAuthorized { get; set; }\n\n    /// <summary>\n    /// Gets or sets the requested scopes.\n    /// </summary>\n    /// <value>\n    /// The authorized scopes.\n    /// </value>\n    public IEnumerable<string> RequestedScopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the authorized scopes.\n    /// </summary>\n    /// <value>\n    /// The authorized scopes.\n    /// </value>\n    public IEnumerable<string> AuthorizedScopes { get; set; }\n\n    /// <summary>\n    /// Gets or sets the subject.\n    /// </summary>\n    /// <value>\n    /// The subject.\n    /// </value>\n    public ClaimsPrincipal Subject { get; set; }\n\n    /// <summary>\n    /// Gets or sets the session identifier.\n    /// </summary>\n    /// <value>\n    /// The session identifier.\n    /// </value>\n    public string SessionId { get; set; }\n}\n"
  },
  {
    "path": "src/Storage/src/Models/Enums.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// OpenID Connect subject types.\n/// </summary>\npublic enum SubjectTypes\n{\n    /// <summary>\n    /// global - use the native subject id\n    /// </summary>\n    Global = 0,\n\n    /// <summary>\n    /// ppid - scope the subject id to the client\n    /// </summary>\n    Ppid = 1\n}\n\n/// <summary>\n/// Access token types.\n/// </summary>\npublic enum AccessTokenType\n{\n    /// <summary>\n    /// Self-contained Json Web Token\n    /// </summary>\n    Jwt = 0,\n\n    /// <summary>\n    /// Reference token\n    /// </summary>\n    Reference = 1\n}\n\n/// <summary>\n/// Token usage types.\n/// </summary>\npublic enum TokenUsage\n{\n    /// <summary>\n    /// Re-use the refresh token handle\n    /// </summary>\n    ReUse = 0,\n\n    /// <summary>\n    /// Issue a new refresh token handle every time\n    /// </summary>\n    OneTimeOnly = 1\n}\n\n/// <summary>\n/// Token expiration types.\n/// </summary>\npublic enum TokenExpiration\n{\n    /// <summary>\n    /// Sliding token expiration\n    /// </summary>\n    Sliding = 0,\n\n    /// <summary>\n    /// Absolute token expiration\n    /// </summary>\n    Absolute = 1\n}\n\n/// <summary>\n/// Content Security Policy Level\n/// </summary>\npublic enum CspLevel\n{\n    /// <summary>\n    /// Level 1\n    /// </summary>\n    One = 0,\n\n    /// <summary>\n    /// Level 2\n    /// </summary>\n    Two = 1\n}\n"
  },
  {
    "path": "src/Storage/src/Models/GrantType.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Models;\n\npublic static class GrantType\n{\n    public const string Implicit = \"implicit\";\n    public const string Hybrid = \"hybrid\";\n    public const string AuthorizationCode = \"authorization_code\";\n    public const string ClientCredentials = \"client_credentials\";\n    public const string ResourceOwnerPassword = \"password\";\n    public const string DeviceFlow = \"urn:ietf:params:oauth:grant-type:device_code\";\n}\n"
  },
  {
    "path": "src/Storage/src/Models/IdentityResource.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models a user identity resource.\n/// </summary>\n[DebuggerDisplay(\"{\" + nameof(DebuggerDisplay) + \",nq}\")]\npublic class IdentityResource : Resource\n{\n    private string DebuggerDisplay => Name ?? $\"{{{typeof(IdentityResource)}}}\";\n    \n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IdentityResource\"/> class.\n    /// </summary>\n    public IdentityResource()\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IdentityResource\"/> class.\n    /// </summary>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"userClaims\">List of associated user claims that should be included when this resource is requested.</param>\n    public IdentityResource(string name, IEnumerable<string> userClaims)\n        : this(name, name, userClaims)\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"IdentityResource\"/> class.\n    /// </summary>\n    /// <param name=\"name\">The name.</param>\n    /// <param name=\"displayName\">The display name.</param>\n    /// <param name=\"userClaims\">List of associated user claims that should be included when this resource is requested.</param>\n    /// <exception cref=\"System.ArgumentNullException\">name</exception>\n    /// <exception cref=\"System.ArgumentException\">Must provide at least one claim type - claimTypes</exception>\n    public IdentityResource(string name, string displayName, IEnumerable<string> userClaims)\n    {\n        if (name.IsMissing()) throw new ArgumentNullException(nameof(name));\n        if (userClaims.IsNullOrEmpty()) throw new ArgumentException(\"Must provide at least one claim type\", nameof(userClaims));\n\n        Name = name;\n        DisplayName = displayName;\n\n        foreach(var type in userClaims)\n        {\n            UserClaims.Add(type);\n        }\n    }\n\n    /// <summary>\n    /// Specifies whether the user can de-select the scope on the consent screen (if the consent screen wants to implement such a feature). Defaults to false.\n    /// </summary>\n    public bool Required { get; set; } = false;\n\n    /// <summary>\n    /// Specifies whether the consent screen will emphasize this scope (if the consent screen wants to implement such a feature). \n    /// Use this setting for sensitive or important scopes. Defaults to false.\n    /// </summary>\n    public bool Emphasize { get; set; } = false;\n}\n"
  },
  {
    "path": "src/Storage/src/Models/PersistedGrant.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// A model for a persisted grant\n/// </summary>\npublic class PersistedGrant\n{\n    /// <summary>\n    /// Gets or sets the key.\n    /// </summary>\n    /// <value>\n    /// The key.\n    /// </value>\n    public string Key { get; set; }\n\n    /// <summary>\n    /// Gets the type.\n    /// </summary>\n    /// <value>\n    /// The type.\n    /// </value>\n    public string Type { get; set; }\n\n    /// <summary>\n    /// Gets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId { get; set; }\n\n    /// <summary>\n    /// Gets the session identifier.\n    /// </summary>\n    /// <value>\n    /// The session identifier.\n    /// </value>\n    public string SessionId { get; set; }\n    \n    /// <summary>\n    /// Gets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets the description the user assigned to the device being authorized.\n    /// </summary>\n    /// <value>\n    /// The description.\n    /// </value>\n    public string Description { get; set; }\n\n    /// <summary>\n    /// Gets or sets the creation time.\n    /// </summary>\n    /// <value>\n    /// The creation time.\n    /// </value>\n    public DateTime CreationTime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the expiration.\n    /// </summary>\n    /// <value>\n    /// The expiration.\n    /// </value>\n    public DateTime? Expiration { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the consumed time.\n    /// </summary>\n    /// <value>\n    /// The consumed time.\n    /// </value>\n    public DateTime? ConsumedTime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the data.\n    /// </summary>\n    /// <value>\n    /// The data.\n    /// </value>\n    public string Data { get; set; }\n}\n"
  },
  {
    "path": "src/Storage/src/Models/RefreshToken.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models a refresh token.\n/// </summary>\npublic class RefreshToken\n{\n    /// <summary>\n    /// Gets or sets the creation time.\n    /// </summary>\n    /// <value>\n    /// The creation time.\n    /// </value>\n    public DateTime CreationTime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the life time.\n    /// </summary>\n    /// <value>\n    /// The life time.\n    /// </value>\n    public int Lifetime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the consumed time.\n    /// </summary>\n    /// <value>\n    /// The consumed time.\n    /// </value>\n    public DateTime? ConsumedTime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the access token.\n    /// </summary>\n    /// <value>\n    /// The access token.\n    /// </value>\n    public Token AccessToken { get; set; }\n\n    /// <summary>\n    /// Gets or sets the original subject that requiested the token.\n    /// </summary>\n    /// <value>\n    /// The subject.\n    /// </value>\n    public ClaimsPrincipal Subject\n    {\n        get\n        {\n            var user = new IdentityServerUser(SubjectId);\n            if (AccessToken.Claims != null)\n            {\n                foreach (var claim in AccessToken.Claims)\n                {\n                    user.AdditionalClaims.Add(claim);\n                }\n            }\n            return user.CreatePrincipal();\n        }\n    }\n\n    /// <summary>\n    /// Gets or sets the version number.\n    /// </summary>\n    /// <value>\n    /// The version.\n    /// </value>\n    public int Version { get; set; } = 4;\n\n    /// <summary>\n    /// Gets the client identifier.\n    /// </summary>\n    /// <value>\n    /// The client identifier.\n    /// </value>\n    public string ClientId => AccessToken.ClientId;\n\n    /// <summary>\n    /// Gets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId => AccessToken.SubjectId;\n\n    /// <summary>\n    /// Gets the session identifier.\n    /// </summary>\n    /// <value>\n    /// The session identifier.\n    /// </value>\n    public string SessionId => AccessToken.SessionId;\n\n    /// <summary>\n    /// Gets the description the user assigned to the device being authorized.\n    /// </summary>\n    /// <value>\n    /// The description.\n    /// </value>\n    public string Description => AccessToken.Description;\n\n    /// <summary>\n    /// Gets the scopes.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public IEnumerable<string> Scopes => AccessToken.Scopes;\n}\n"
  },
  {
    "path": "src/Storage/src/Models/Resource.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models the common data of API and identity resources.\n/// </summary>\n[DebuggerDisplay(\"{DebuggerDisplay,nq}\")]\npublic abstract class Resource\n{\n    private string DebuggerDisplay => Name ?? $\"{{{typeof(Resource)}}}\";\n\n    /// <summary>\n    /// Indicates if this resource is enabled. Defaults to true.\n    /// </summary>\n    public bool Enabled { get; set; } = true;\n\n    /// <summary>\n    /// The unique name of the resource.\n    /// </summary>\n    public string Name { get; set; }\n\n    /// <summary>\n    /// Display name of the resource.\n    /// </summary>\n    public string DisplayName { get; set; }\n    \n    /// <summary>\n    /// Description of the resource.\n    /// </summary>\n    public string Description { get; set; }\n\n    /// <summary>\n    /// Specifies whether this scope is shown in the discovery document. Defaults to true.\n    /// </summary>\n    public bool ShowInDiscoveryDocument { get; set; } = true;\n\n    /// <summary>\n    /// List of associated user claims that should be included when this resource is requested.\n    /// </summary>\n    public ICollection<string> UserClaims { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Gets or sets the custom properties for the resource.\n    /// </summary>\n    /// <value>\n    /// The properties.\n    /// </value>\n    public IDictionary<string, string> Properties { get; set; } = new Dictionary<string, string>();\n}\n"
  },
  {
    "path": "src/Storage/src/Models/Resources.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models a collection of identity and API resources.\n/// </summary>\npublic class Resources\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"Resources\"/> class.\n    /// </summary>\n    public Resources()\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"Resources\"/> class.\n    /// </summary>\n    /// <param name=\"other\">The other.</param>\n    public Resources(Resources other)\n        : this(other.IdentityResources, other.ApiResources, other.ApiScopes)\n    {\n        OfflineAccess = other.OfflineAccess;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"Resources\"/> class.\n    /// </summary>\n    /// <param name=\"identityResources\">The identity resources.</param>\n    /// <param name=\"apiResources\">The API resources.</param>\n    /// <param name=\"apiScopes\">The API scopes.</param>\n    public Resources(IEnumerable<IdentityResource> identityResources, IEnumerable<ApiResource> apiResources, IEnumerable<ApiScope> apiScopes)\n    {\n        if (identityResources?.Any() == true)\n        {\n            IdentityResources = new HashSet<IdentityResource>(identityResources.ToArray());\n        }\n        if (apiResources?.Any() == true)\n        {\n            ApiResources = new HashSet<ApiResource>(apiResources.ToArray());\n        }\n        if (apiScopes?.Any() == true)\n        {\n            ApiScopes = new HashSet<ApiScope>(apiScopes.ToArray());\n        }\n    }\n\n    /// <summary>\n    /// Gets or sets a value indicating whether [offline access].\n    /// </summary>\n    /// <value>\n    ///   <c>true</c> if [offline access]; otherwise, <c>false</c>.\n    /// </value>\n    public bool OfflineAccess { get; set; }\n\n    /// <summary>\n    /// Gets or sets the identity resources.\n    /// </summary>\n    public ICollection<IdentityResource> IdentityResources { get; set; } = new HashSet<IdentityResource>();\n\n    /// <summary>\n    /// Gets or sets the API resources.\n    /// </summary>\n    public ICollection<ApiResource> ApiResources { get; set; } = new HashSet<ApiResource>();\n    \n    /// <summary>\n    /// Gets or sets the API scopes.\n    /// </summary>\n    public ICollection<ApiScope> ApiScopes { get; set; } = new HashSet<ApiScope>();\n}\n"
  },
  {
    "path": "src/Storage/src/Models/Secret.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models a client secret with identifier and expiration\n/// </summary>\npublic class Secret\n{\n    /// <summary>\n    /// Gets or sets the description.\n    /// </summary>\n    /// <value>\n    /// The description.\n    /// </value>\n    public string Description { get; set; }\n\n    /// <summary>\n    /// Gets or sets the value.\n    /// </summary>\n    /// <value>\n    /// The value.\n    /// </value>\n    public string Value { get; set; }\n\n    /// <summary>\n    /// Gets or sets the expiration.\n    /// </summary>\n    /// <value>\n    /// The expiration.\n    /// </value>\n    public DateTime? Expiration { get; set; }\n\n    /// <summary>\n    /// Gets or sets the type of the client secret.\n    /// </summary>\n    /// <value>\n    /// The type of the client secret.\n    /// </value>\n    public string Type { get; set; }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"Secret\"/> class.\n    /// </summary>\n    public Secret()\n    {\n        Type = IdentityServerConstants.SecretTypes.SharedSecret;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"Secret\"/> class.\n    /// </summary>\n    /// <param name=\"value\">The value.</param>\n    /// <param name=\"expiration\">The expiration.</param>\n    public Secret(string value, DateTime? expiration = null)\n        : this()\n    {\n        Value = value;\n        Expiration = expiration;\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"Secret\" /> class.\n    /// </summary>\n    /// <param name=\"value\">The value.</param>\n    /// <param name=\"description\">The description.</param>\n    /// <param name=\"expiration\">The expiration.</param>\n    public Secret(string value, string description, DateTime? expiration = null)\n        : this()\n    {\n        Description = description;\n        Value = value;\n        Expiration = expiration;\n    }\n\n    /// <summary>\n    /// Returns a hash code for this instance.\n    /// </summary>\n    /// <returns>\n    /// A hash code for this instance, suitable for use in hashing algorithms and data structures like a hash table. \n    /// </returns>\n    public override int GetHashCode()\n    {\n        unchecked\n        {\n            var hash = 17;\n            hash = hash * 23 + (Value?.GetHashCode() ?? 0);\n            hash = hash * 23 + (Type?.GetHashCode() ?? 0);\n\n            return hash;\n        }\n    }\n\n    /// <summary>\n    /// Determines whether the specified <see cref=\"System.Object\" />, is equal to this instance.\n    /// </summary>\n    /// <param name=\"obj\">The <see cref=\"System.Object\" /> to compare with this instance.</param>\n    /// <returns>\n    ///   <c>true</c> if the specified <see cref=\"System.Object\" /> is equal to this instance; otherwise, <c>false</c>.\n    /// </returns>\n    public override bool Equals(object obj)\n    {\n        if (obj == null) return false;\n        var other = obj as Secret;\n        if (other == null) return false;\n        if (ReferenceEquals(other, this)) return true;\n\n        return String.Equals(other.Type, Type, StringComparison.Ordinal) && \n            String.Equals(other.Value, Value, StringComparison.Ordinal);\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/Models/Token.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Models;\n\n/// <summary>\n/// Models a token.\n/// </summary>\npublic class Token\n{\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"Token\"/> class.\n    /// </summary>\n    public Token()\n    {\n    }\n\n    /// <summary>\n    /// Initializes a new instance of the <see cref=\"Token\"/> class.\n    /// </summary>\n    /// <param name=\"tokenType\">Type of the token.</param>\n    public Token(string tokenType)\n    {\n        Type = tokenType;\n    }\n\n    /// <summary>\n    /// A list of allowed algorithm for signing the token. If null or empty, will use the default algorithm.\n    /// </summary>\n    public ICollection<string> AllowedSigningAlgorithms { get; set; } = new HashSet<string>();\n\n    /// <summary>\n    /// Specifies the confirmation method of the token. This value, if set, will become the cnf claim.\n    /// </summary>\n    public string Confirmation { get; set; }\n\n    /// <summary>\n    /// Gets or sets the audiences.\n    /// </summary>\n    /// <value>\n    /// The audiences.\n    /// </value>\n    public ICollection<string> Audiences { get; set; } = new HashSet<string>();\n    \n    /// <summary>\n    /// Gets or sets the issuer.\n    /// </summary>\n    /// <value>\n    /// The issuer.\n    /// </value>\n    public string Issuer { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the creation time.\n    /// </summary>\n    /// <value>\n    /// The creation time.\n    /// </value>\n    public DateTime CreationTime { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the lifetime.\n    /// </summary>\n    /// <value>\n    /// The lifetime.\n    /// </value>\n    public int Lifetime { get; set; }\n\n    /// <summary>\n    /// Gets or sets the type.\n    /// </summary>\n    /// <value>\n    /// The type.\n    /// </value>\n    public string Type { get; set; } = OidcConstants.TokenTypes.AccessToken;\n\n    /// <summary>\n    /// Gets or sets the ID of the client.\n    /// </summary>\n    /// <value>\n    /// The ID of the client.\n    /// </value>\n    public string ClientId { get; set; }\n\n    /// <summary>\n    /// Gets or sets the type of access token of the client\n    /// </summary>\n    /// <value>\n    /// The access token type specified by the client.\n    /// </value>\n    public AccessTokenType AccessTokenType { get; set; }\n\n    /// <summary>\n    /// Gets the description the user assigned to the device being authorized.\n    /// </summary>\n    /// <value>\n    /// The description.\n    /// </value>\n    public string Description { get; set; }\n    \n    /// <summary>\n    /// Gets or sets the claims.\n    /// </summary>\n    /// <value>\n    /// The claims.\n    /// </value>\n    public ICollection<Claim> Claims { get; set; } = new HashSet<Claim>(new ClaimComparer());\n\n    /// <summary>\n    /// Gets or sets the version.\n    /// </summary>\n    /// <value>\n    /// The version.\n    /// </value>\n    public int Version { get; set; } = 4;\n\n    /// <summary>\n    /// Gets the subject identifier.\n    /// </summary>\n    /// <value>\n    /// The subject identifier.\n    /// </value>\n    public string SubjectId => Claims.Where(x => x.Type == JwtClaimTypes.Subject).Select(x => x.Value).SingleOrDefault();\n\n    /// <summary>\n    /// Gets the session identifier.\n    /// </summary>\n    /// <value>\n    /// The session identifier.\n    /// </value>\n    public string SessionId => Claims.Where(x => x.Type == JwtClaimTypes.SessionId).Select(x => x.Value).SingleOrDefault();\n\n    /// <summary>\n    /// Gets the scopes.\n    /// </summary>\n    /// <value>\n    /// The scopes.\n    /// </value>\n    public IEnumerable<string> Scopes => Claims.Where(x => x.Type == JwtClaimTypes.Scope).Select(x => x.Value);\n}\n"
  },
  {
    "path": "src/Storage/src/Services/ICorsPolicyService.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Services;\n\n/// <summary>\n/// Service that determines if CORS is allowed.\n/// </summary>\npublic interface ICorsPolicyService\n{\n    /// <summary>\n    /// Determines whether origin is allowed.\n    /// </summary>\n    /// <param name=\"origin\">The origin.</param>\n    /// <returns></returns>\n    Task<bool> IsOriginAllowedAsync(string origin);\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/IAuthorizationCodeStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for the authorization code store\n/// </summary>\npublic interface IAuthorizationCodeStore\n{\n    /// <summary>\n    /// Stores the authorization code.\n    /// </summary>\n    /// <param name=\"code\">The code.</param>\n    /// <returns></returns>\n    Task<string> StoreAuthorizationCodeAsync(AuthorizationCode code);\n\n    /// <summary>\n    /// Gets the authorization code.\n    /// </summary>\n    /// <param name=\"code\">The code.</param>\n    /// <returns></returns>\n    Task<AuthorizationCode> GetAuthorizationCodeAsync(string code);\n\n    /// <summary>\n    /// Removes the authorization code.\n    /// </summary>\n    /// <param name=\"code\">The code.</param>\n    /// <returns></returns>\n    Task RemoveAuthorizationCodeAsync(string code);\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/IClientStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Retrieval of client configuration\n/// </summary>\npublic interface IClientStore\n{\n    /// <summary>\n    /// Finds a client by id\n    /// </summary>\n    /// <param name=\"clientId\">The client id</param>\n    /// <returns>The client</returns>\n    Task<Client> FindClientByIdAsync(string clientId);\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/IDeviceFlowStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for the device flow store\n/// </summary>\npublic interface IDeviceFlowStore\n{\n    /// <summary>\n    /// Stores the device authorization request.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <param name=\"data\">The data.</param>\n    /// <returns></returns>\n    Task StoreDeviceAuthorizationAsync(string deviceCode, string userCode, DeviceCode data);\n\n    /// <summary>\n    /// Finds device authorization by user code.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <returns></returns>\n    Task<DeviceCode> FindByUserCodeAsync(string userCode);\n\n    /// <summary>\n    /// Finds device authorization by device code.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    Task<DeviceCode> FindByDeviceCodeAsync(string deviceCode);\n\n    /// <summary>\n    /// Updates device authorization, searching by user code.\n    /// </summary>\n    /// <param name=\"userCode\">The user code.</param>\n    /// <param name=\"data\">The data.</param>\n    Task UpdateByUserCodeAsync(string userCode, DeviceCode data);\n\n    /// <summary>\n    /// Removes the device authorization, searching by device code.\n    /// </summary>\n    /// <param name=\"deviceCode\">The device code.</param>\n    Task RemoveByDeviceCodeAsync(string deviceCode);\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/IPersistedGrantStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for persisting any type of grant.\n/// </summary>\npublic interface IPersistedGrantStore\n{\n    /// <summary>\n    /// Stores the grant.\n    /// </summary>\n    /// <param name=\"grant\">The grant.</param>\n    /// <returns></returns>\n    Task StoreAsync(PersistedGrant grant);\n\n    /// <summary>\n    /// Gets the grant.\n    /// </summary>\n    /// <param name=\"key\">The key.</param>\n    /// <returns></returns>\n    Task<PersistedGrant> GetAsync(string key);\n\n    /// <summary>\n    /// Gets all grants based on the filter.\n    /// </summary>\n    /// <param name=\"filter\">The filter.</param>\n    /// <returns></returns>\n    Task<IEnumerable<PersistedGrant>> GetAllAsync(PersistedGrantFilter filter);\n\n    /// <summary>\n    /// Removes the grant by key.\n    /// </summary>\n    /// <param name=\"key\">The key.</param>\n    /// <returns></returns>\n    Task RemoveAsync(string key);\n\n    /// <summary>\n    /// Removes all grants based on the filter.\n    /// </summary>\n    /// <param name=\"filter\">The filter.</param>\n    /// <returns></returns>\n    Task RemoveAllAsync(PersistedGrantFilter filter);\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/IReferenceTokenStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for reference token storage\n/// </summary>\npublic interface IReferenceTokenStore\n{\n    /// <summary>\n    /// Stores the reference token.\n    /// </summary>\n    /// <param name=\"token\">The token.</param>\n    /// <returns></returns>\n    Task<string> StoreReferenceTokenAsync(Token token);\n\n    /// <summary>\n    /// Gets the reference token.\n    /// </summary>\n    /// <param name=\"handle\">The handle.</param>\n    /// <returns></returns>\n    Task<Token> GetReferenceTokenAsync(string handle);\n\n    /// <summary>\n    /// Removes the reference token.\n    /// </summary>\n    /// <param name=\"handle\">The handle.</param>\n    /// <returns></returns>\n    Task RemoveReferenceTokenAsync(string handle);\n\n    /// <summary>\n    /// Removes the reference tokens.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    Task RemoveReferenceTokensAsync(string subjectId, string clientId);\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/IRefreshTokenStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for refresh token storage\n/// </summary>\npublic interface IRefreshTokenStore\n{\n    /// <summary>\n    /// Stores the refresh token.\n    /// </summary>\n    /// <param name=\"refreshToken\">The refresh token.</param>\n    /// <returns></returns>\n    Task<string> StoreRefreshTokenAsync(RefreshToken refreshToken);\n\n    /// <summary>\n    /// Updates the refresh token.\n    /// </summary>\n    /// <param name=\"handle\">The handle.</param>\n    /// <param name=\"refreshToken\">The refresh token.</param>\n    /// <returns></returns>\n    Task UpdateRefreshTokenAsync(string handle, RefreshToken refreshToken);\n\n    /// <summary>\n    /// Gets the refresh token.\n    /// </summary>\n    /// <param name=\"refreshTokenHandle\">The refresh token handle.</param>\n    /// <returns></returns>\n    Task<RefreshToken> GetRefreshTokenAsync(string refreshTokenHandle);\n\n    /// <summary>\n    /// Removes the refresh token.\n    /// </summary>\n    /// <param name=\"refreshTokenHandle\">The refresh token handle.</param>\n    /// <returns></returns>\n    Task RemoveRefreshTokenAsync(string refreshTokenHandle);\n\n    /// <summary>\n    /// Removes the refresh tokens.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    Task RemoveRefreshTokensAsync(string subjectId, string clientId);\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/IResourceStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Resource retrieval\n/// </summary>\npublic interface IResourceStore\n{\n    /// <summary>\n    /// Gets identity resources by scope name.\n    /// </summary>\n    Task<IEnumerable<IdentityResource>> FindIdentityResourcesByScopeNameAsync(IEnumerable<string> scopeNames);\n\n    /// <summary>\n    /// Gets API scopes by scope name.\n    /// </summary>\n    Task<IEnumerable<ApiScope>> FindApiScopesByNameAsync(IEnumerable<string> scopeNames);\n    \n    /// <summary>\n    /// Gets API resources by scope name.\n    /// </summary>\n    Task<IEnumerable<ApiResource>> FindApiResourcesByScopeNameAsync(IEnumerable<string> scopeNames);\n\n    /// <summary>\n    /// Gets API resources by API resource name.\n    /// </summary>\n    Task<IEnumerable<ApiResource>> FindApiResourcesByNameAsync(IEnumerable<string> apiResourceNames);\n\n    /// <summary>\n    /// Gets all resources.\n    /// </summary>\n    Task<Resources> GetAllResourcesAsync();\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/IUserConsentStore.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Interface for user consent storage\n/// </summary>\npublic interface IUserConsentStore\n{\n    /// <summary>\n    /// Stores the user consent.\n    /// </summary>\n    /// <param name=\"consent\">The consent.</param>\n    /// <returns></returns>\n    Task StoreUserConsentAsync(Consent consent);\n\n    /// <summary>\n    /// Gets the user consent.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    Task<Consent> GetUserConsentAsync(string subjectId, string clientId);\n\n    /// <summary>\n    /// Removes the user consent.\n    /// </summary>\n    /// <param name=\"subjectId\">The subject identifier.</param>\n    /// <param name=\"clientId\">The client identifier.</param>\n    /// <returns></returns>\n    Task RemoveUserConsentAsync(string subjectId, string clientId);\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/PersistedGrantFilter.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores;\n\n/// <summary>\n/// Represents a filter used when accessing the persisted grants store. \n/// Setting multiple properties is interpreted as a logical 'AND' to further filter the query.\n/// At least one value must be supplied.\n/// </summary>\npublic class PersistedGrantFilter\n{\n    /// <summary>\n    /// Subject id of the user.\n    /// </summary>\n    public string SubjectId { get; set; }\n    \n    /// <summary>\n    /// Session id used for the grant.\n    /// </summary>\n    public string SessionId { get; set; }\n    \n    /// <summary>\n    /// Client id the grant was issued to.\n    /// </summary>\n    public string ClientId { get; set; }\n    \n    /// <summary>\n    /// The type of grant.\n    /// </summary>\n    public string Type { get; set; }\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/Serialization/ClaimConverter.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Stores.Serialization;\n\npublic class ClaimConverter : JsonConverter\n{\n    public override bool CanConvert(Type objectType)\n    {\n        return typeof(Claim) == objectType;\n    }\n\n    public override object ReadJson(JsonReader reader, Type objectType, object existingValue, JsonSerializer serializer)\n    {\n        var source = serializer.Deserialize<ClaimLite>(reader);\n        var target = new Claim(source.Type, source.Value, source.ValueType);\n        return target;\n    }\n\n    public override void WriteJson(JsonWriter writer, object value, JsonSerializer serializer)\n    {\n        var source = (Claim)value;\n\n        var target = new ClaimLite\n        {\n            Type = source.Type,\n            Value = source.Value,\n            ValueType = source.ValueType\n        };\n\n        serializer.Serialize(writer, target);\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/Serialization/ClaimLite.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Stores.Serialization;\n\npublic class ClaimLite\n{\n    public string Type { get; set; }\n    public string Value { get; set; }\n    public string ValueType { get; set; }\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/Serialization/ClaimsPrincipalConverter.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Stores.Serialization;\n\npublic class ClaimsPrincipalConverter : JsonConverter\n{\n    public override bool CanConvert(Type objectType)\n    {\n        return typeof(ClaimsPrincipal) == objectType;\n    }\n\n    public override object ReadJson(JsonReader reader, Type objectType, object existingValue, JsonSerializer serializer)\n    {\n        var source = serializer.Deserialize<ClaimsPrincipalLite>(reader);\n        if (source == null) return null;\n\n        var claims = source.Claims.Select(x => new Claim(x.Type, x.Value, x.ValueType));\n        var id = new ClaimsIdentity(claims, source.AuthenticationType, JwtClaimTypes.Name, JwtClaimTypes.Role);\n        var target = new ClaimsPrincipal(id);\n        return target;\n    }\n\n    public override void WriteJson(JsonWriter writer, object value, JsonSerializer serializer)\n    {\n        var source = (ClaimsPrincipal)value;\n\n        var target = new ClaimsPrincipalLite\n        {\n            AuthenticationType = source.Identity.AuthenticationType,\n            Claims = source.Claims.Select(x => new ClaimLite { Type = x.Type, Value = x.Value, ValueType = x.ValueType }).ToArray()\n        };\n        serializer.Serialize(writer, target);\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/Serialization/ClaimsPrincipalLite.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Stores.Serialization;\n\npublic class ClaimsPrincipalLite\n{\n    public string AuthenticationType { get; set; }\n    public ClaimLite[] Claims { get; set; }\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/Serialization/CustomContractResolver.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\n#pragma warning disable 1591\n\nnamespace IdentityServer8.Stores.Serialization;\n\npublic class CustomContractResolver: DefaultContractResolver\n{\n    protected override IList<JsonProperty> CreateProperties(Type type, MemberSerialization memberSerialization)\n    {\n        var props = base.CreateProperties(type, memberSerialization);\n        return props.Where(p => p.Writable).ToList();\n    }\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/Serialization/IPersistentGrantSerializer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores.Serialization;\n\n/// <summary>\n/// Interface for persisted grant serialization\n/// </summary>\npublic interface IPersistentGrantSerializer\n{\n    /// <summary>\n    /// Serializes the specified value.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"value\">The value.</param>\n    /// <returns></returns>\n    string Serialize<T>(T value);\n\n    /// <summary>\n    /// Deserializes the specified string.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"json\">The json.</param>\n    /// <returns></returns>\n    T Deserialize<T>(string json);\n}\n"
  },
  {
    "path": "src/Storage/src/Stores/Serialization/PersistentGrantSerializer.cs",
    "content": "/*\n Copyright (c) 2024 HigginsSoft, Alexander Higgins - https://github.com/alexhiggins732/ \n\n Copyright (c) 2018, Brock Allen & Dominick Baier. All rights reserved.\n\n Licensed under the Apache License, Version 2.0. See LICENSE in the project root for license information. \n Source code and license this software can be found \n\n The above copyright notice and this permission notice shall be included in all\n copies or substantial portions of the Software.\n*/\n\nnamespace IdentityServer8.Stores.Serialization;\n\n/// <summary>\n/// JSON-based persisted grant serializer\n/// </summary>\n/// <seealso cref=\"IdentityServer8.Stores.Serialization.IPersistentGrantSerializer\" />\npublic class PersistentGrantSerializer : IPersistentGrantSerializer\n{\n    private static readonly JsonSerializerSettings _settings;\n\n    static PersistentGrantSerializer()\n    {\n        _settings = new JsonSerializerSettings\n        {\n            ContractResolver = new CustomContractResolver()\n        };\n        _settings.Converters.Add(new ClaimConverter());\n        _settings.Converters.Add(new ClaimsPrincipalConverter());\n    }\n\n    /// <summary>\n    /// Serializes the specified value.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"value\">The value.</param>\n    /// <returns></returns>\n    public string Serialize<T>(T value)\n    {\n        return JsonConvert.SerializeObject(value, _settings);\n    }\n\n    /// <summary>\n    /// Deserializes the specified string.\n    /// </summary>\n    /// <typeparam name=\"T\"></typeparam>\n    /// <param name=\"json\">The json.</param>\n    /// <returns></returns>\n    public T Deserialize<T>(string json)\n    {\n        return JsonConvert.DeserializeObject<T>(json, _settings);\n    }\n}\n"
  },
  {
    "path": "version.json",
    "content": "{\n  \"$schema\": \"https://raw.githubusercontent.com/dotnet/Nerdbank.GitVersioning/main/src/NerdBank.GitVersioning/version.schema.json\",\n  \"version\": \"8.0.4-beta.4\",\n  \"nugetPackageVersion\": {\n    \"semVer\": 2, // optional. Set to either 1 or 2 to control how the NuGet package version string is generated. Default is 1.\n    \"precision\": \"revision\"\n  },\n  \"semVer1NumericIdentifierPadding\": 4,\n  \"pathFilters\": [\n    // optional list of paths to consider when calculating version height.\n    \"!docs\",\n    \"!.git\",\n    \"!.vs\",\n    \"!.config\",\n    \"!.github\",\n    \"!.config\",\n    \"!Directory.Build.props\",\n    \"!Directory.Build.targets\",\n    \"!Directory.Packages.props\",\n    \"docker-compose.yml\",\n    \"docker-compose.override.yml\",\n    \"docker-compose.vs.debug.yml\",\n    \"docker-compose.vs.release.yml\",\n    \"docker-compose.dcrpoj\",\n    \"src/IdentityServer8.sln\",\n    \"!global.json\",\n    \"!IdentityServer8.DotNet.ruleset\",\n    \"!LICENSCE\",\n    \"!Nuget.config\",\n    \"!SECURITY.md\",\n    \"!SPONSORS.md\",\n    \"!README.md\",\n    \"!samples\",\n    \"!nuget\"\n  ],\n  \"publicReleaseRefSpec\": [\n    \"^refs/heads/master$\", // we release out of master\n    \"^refs/tags/v\\\\d+\\\\.\\\\d+\", // we also release tags starting with vN.N\n    \"^refs/heads/develop$\", // we release alpha out of develop\n    \"^refs/heads/release/*\" // we release beta out of release\n  ],\n  \"cloudBuild\": {\n    \"setVersionVariables\": true,\n    \"buildNumber\": {\n      \"enabled\": true,\n      \"includeCommitId\": {\n        \"when\": \"always\",\n        \"where\": \"buildMetadata\"\n      }\n    }\n  },\n  \"release\": {\n    \"tagName\": \"v{version}\",\n    \"branchName\": \"v{version}\",\n    \"versionIncrement\": \"minor\",\n    \"firstUnstableTag\": \"alpha\"\n  }\n}\n"
  }
]